STIGUI
V-285267CAT II — Medium severitySV-285267r1258965_rule

The Infoblox DNS service member implementation must maintain the integrity of information during reception.

Rule version IDNS-9X-000650 · STIG v1 · 2026-08-14

Discussion

Information can be either unintentionally or maliciously disclosed or modified during reception, including, for example, during aggregation, at protocol transformation points, and during packing/unpacking. These unauthorized disclosures or modifications compromise the confidentiality or integrity of the information.

Confidentiality is not an objective of DNS, but integrity is. DNS is responsible for maintaining the integrity of DNS information while it is being received.

Satisfies: SRG-APP-000441-DNS-000066, SRG-APP-000442-DNS-000067

Check

Verify Infoblox is configured to maintain the integrity of information during preparation for transmission.

1. Navigate to Data Management >> DNS tab >> Grid DNS Properties (Toolbar menu) >> DNSSEC tab. 2. Toggle "Advanced Mode" and verify DNSSEC and DNSSEC Validation are enabled. 3. Navigate to Data Management >> DNS >> Zones. 4. For all external-facing authoritative zones, review all external authoritative zones.

Note: To add "Signed" column, select an existing column >> down arrow >> Columns >> Edit Columns. Set the "Signed" checkbox to "Visible" and select "Apply". DNSSEC signing status will be displayed in the Zones tab. Verify external authoritative zones are DNSSEC signed.

If DNSSEC is not used for authoritative DNS, this is a finding.

Note: DNSSEC is intended for third-party authenticity determination. Attempting to utilize DNSSEC internally was never an intended use case as it would require every consumer to have a third-party validating resolver installed along with a mechanism for periodic trust anchor distribution/update.

Fix

Note: To avoid signing with an unapproved configuration, ensure DNSSEC is configured on all external-facing zones to meet all other STIG requirements prior to signing a zone.

Note: DNSSEC is intended for third-party authenticity determination. Attempting to utilize DNSSEC internally was never an intended use case, as it would require every consumer to have a third-party validating resolver installed along with a mechanism for periodic trust anchor distribution/update.

1. Navigate to Data Management >> DNS tab >> Grid DNS Properties (Toolbar menu). 2. Toggle "Advanced Mode" and select the "DNSSEC" tab. 3. Configure DNSSEC validation by selecting the checkbox for "Enable DNSSEC". 4. Configure the Trust Anchors. 5. When complete, click "Save & Close" to save the changes and exit the "Properties" screen. 6. Perform a service restart if necessary. 7. Select an external zone that needs to be signed. 8. Click the dropdown in the toolbar next to DNSSEC, and select "Sign Zones". 9. Click "Sign Zones", then click "Yes".

Identifiers

Group ID
V-285267
Group title
SRG-APP-000441-DNS-000066
Rule ID
SV-285267r1258965_rule
Check ID
C-89836r1258712_chk
Fix ID
F-89741r1258964_fix