STIGhubSTIGhub
STIGhub— A free STIG search and compliance tool·STIGs updated 12 hours ago
Powered by Pylon·Privacy·Terms·Feedback·© 2026 Beacon Cloud Solutions, Inc.
← Back to Infoblox NIOS 9.x Security Technical Implementation Guide

V-285253

CAT II (Medium)

CNAME records must not point to a zone with lesser security for more than six months.

Rule ID

SV-285253r1258957_rule

STIG

Infoblox NIOS 9.x Security Technical Implementation Guide

Version

V1R1

CCIs

CCI-000366

Discussion

The use of CNAME records for exercises, tests, or zone-spanning aliases should be temporary (e.g., to facilitate a migration). When a host name is an alias for a record in another zone, an adversary has two points of attack: the zone in which the alias is defined and the zone authoritative for the alias's canonical name. This configuration also reduces the speed of client resolution because it requires a second look up after obtaining the canonical name. Furthermore, in the case of an authoritative name server, this information is promulgated throughout the enterprise to caching servers and thus compounds the vulnerability.

Check Content

Verify zone-spanning CNAME records are no older than six months.

1. Navigate to Administration >> Logs >> Audit Log. Click "Show Filter" (if it is not already displayed). 
2. Create a new search using "Object Type", "equals", and "CNAME Record". 
3. Click the plus (+) symbol to add a second search parameter. 
4. Create an additional search parameter, "Timestamp before YYYY-MM-DD", using the calendar selection box to choose the appropriate date six months prior to the current date. 
5. Click "Apply" to display CNAME records created more than six months ago. 

If there are zone-spanning CNAME records older than six months and the CNAME records resolve to anything other than fully qualified domain names for glue records supporting zone delegations, CNAME records supporting a system migration, or CNAME records that point to third-party Content Delivery Networks (CDN) or cloud computing platforms with an authorizing official (AO)-approved and documented mission need, this is a finding.

Fix Text

1. Navigate to Data Management >> DNS >> Zones. 
2. Edit the zone containing CNAME records discovered during review of the Audit Log.
3. Remove any zone-spanning CNAME records that have been active for more than six months that resolve to anything other than fully qualified domain names for glue records supporting zone delegations, CNAME records supporting a system migration, or CNAME records that point to third-party CDN or cloud computing platforms with an authorizing official (AO)-approved and documented mission need.