STIGhubSTIGhub
STIGhub— A free STIG search and compliance tool·STIGs updated 12 hours ago
Powered by Pylon·Privacy·Terms·Feedback·© 2026 Beacon Cloud Solutions, Inc.
← Back to Infoblox NIOS 9.x Security Technical Implementation Guide

V-285267

CAT II (Medium)

The Infoblox DNS service member implementation must maintain the integrity of information during reception.

Rule ID

SV-285267r1258965_rule

STIG

Infoblox NIOS 9.x Security Technical Implementation Guide

Version

V1R1

CCIs

CCI-002420CCI-002422

Discussion

Information can be either unintentionally or maliciously disclosed or modified during reception, including, for example, during aggregation, at protocol transformation points, and during packing/unpacking. These unauthorized disclosures or modifications compromise the confidentiality or integrity of the information. Confidentiality is not an objective of DNS, but integrity is. DNS is responsible for maintaining the integrity of DNS information while it is being received. Satisfies: SRG-APP-000441-DNS-000066, SRG-APP-000442-DNS-000067

Check Content

Verify Infoblox is configured to maintain the integrity of information during preparation for transmission.

1. Navigate to Data Management >> DNS tab >> Grid DNS Properties (Toolbar menu) >> DNSSEC tab.
2. Toggle "Advanced Mode" and verify DNSSEC and DNSSEC Validation are enabled.
3. Navigate to Data Management >> DNS >> Zones. 
4. For all external-facing authoritative zones, review all external authoritative zones. 

Note: To add "Signed" column, select an existing column >> down arrow >> Columns >> Edit Columns. Set the "Signed" checkbox to "Visible" and select "Apply". DNSSEC signing status will be displayed in the Zones tab. Verify external authoritative zones are DNSSEC signed.

If DNSSEC is not used for authoritative DNS, this is a finding.

Note: DNSSEC is intended for third-party authenticity determination. Attempting to utilize DNSSEC internally was never an intended use case as it would require every consumer to have a third-party validating resolver installed along with a mechanism for periodic trust anchor distribution/update.

Fix Text

Note: To avoid signing with an unapproved configuration, ensure DNSSEC is configured on all external-facing zones to meet all other STIG requirements prior to signing a zone. 

Note: DNSSEC is intended for third-party authenticity determination. Attempting to utilize DNSSEC internally was never an intended use case, as it would require every consumer to have a third-party validating resolver installed along with a mechanism for periodic trust anchor distribution/update.

1. Navigate to Data Management >> DNS tab >> Grid DNS Properties (Toolbar menu). 
2. Toggle "Advanced Mode" and select the "DNSSEC" tab.
3. Configure DNSSEC validation by selecting the checkbox for "Enable DNSSEC".
4. Configure the Trust Anchors.
5. When complete, click "Save & Close" to save the changes and exit the "Properties" screen. 
6. Perform a service restart if necessary.
7. Select an external zone that needs to be signed.
8. Click the dropdown in the toolbar next to DNSSEC, and select "Sign Zones".
9. Click "Sign Zones", then click "Yes".