STIGhubSTIGhub
STIGhub— A free STIG search and compliance tool·STIGs updated 12 hours ago
Powered by Pylon·Privacy·Terms·Feedback·© 2026 Beacon Cloud Solutions, Inc.
← Back to Infoblox NIOS 9.x Security Technical Implementation Guide

V-285308

CAT II (Medium)

The Infoblox DNS Server must provide protected storage for cryptographic keys with origination-defined safeguards and/or hardware protected key store.

Rule ID

SV-285308r1258974_rule

STIG

Infoblox NIOS 9.x Security Technical Implementation Guide

Version

V1R1

CCIs

CCI-004910

Discussion

A Trusted Platform Module (TPM) is an example of a hardware-protected data store that can be used to protect cryptographic keys.

Check Content

Verify that HSM signing is configured:

1. Navigate to Data Management >> DNS tab. 
2. Click "Grid DNS Properties" (Toolbar menu).
3. Toggle Advanced Mode (if not enabled). 
4. Click the "DNSSEC" tab.
5. Confirm "Enable DNSSEC" and "Enable HSM Signing" checkboxes are selected.

If "Enable HSM Signing" is not selected, this is a finding.

Fix Text

Configure HSM Group:

1. Navigate to Infoblox Grid >> HSM Group.
2. Click the drop-down next to "Add" and select "Thales Luna Group" or "Entrust nShield Group".
3. Input the configuration information for either group.
4. Click "Save & Close".

Enable HSM Signing:

1. Navigate to Data Management >> DNS tab >> Grid DNS Properties (Toolbar menu).
2. Toggle Advanced Mode (if not selected).
3. Click the "DNSSEC" tab.
4. Confirm "Enable DNSSEC" and "Enable HSM Signing" checkboxes are selected.
5. Configure DNSSEC Parameters. Note that Entrust nShield HSMs do not support DSA.
6. Click "Save & Close".

A Grid can be integrated with third-party, network-attached Hardware Security Modules (HSMs) for secure private key storage and generation, and zone-signing off-loading. Infoblox appliances support integration with either Thales Luna HSMs or Entrust nShield HSMs. When using a network-attached HSM, tight physical access control can be provided, allowing only selected security personnel to physically access the HSM that stores the DNSSEC keys. When this feature is enabled, the HSM performs DNSSEC zone signing, key generation, and key safe keeping.

Refer to Infoblox Documentation for configuring a Thales Luna or Entrust nShield HSM Device.

https://docs.infoblox.com/space/nios90/280664372/About+HSM+Signing