7.3 Disable the dnssec-accept-expired Option

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

The dnssec-accept-expired option allows BIND to accept expired signatures during validation. The option should be disabled so that expired signatures will not be accepted.

Rationale:

Allowing expired signatures would leave the server vulnerable to replay attacks.

Solution

Change the dnssec-accept-expired option to have a value of "no", or remove the option from the configuration files.

Default Value:

The dnssec-accept-expired option is disabled by default.

8 Operations - Logging, Monitoring and Maintenance

This section provides recommendations for the BIND server configurations related to operations, updates, logging and monitoring.

See Also

https://benchmarks.cisecurity.org/downloads/show-single/?file=bind.300