23 - Enable GSS-TSIG

Information

BIND 9.5.0 introduced support for the proprietary GSS-TSIG algorithm that is used by Microsoft's DNS solution. It is recommended that GSS-TSIG be utilized to integrate service with Microsoft DNS whenever possible.

Rationale:

GSS-TSIG provides support for authenticated transactions between BIND and Windows DHCP servers. This use of this mechanism reduces the probability of an attacker compromising the integrity of the DNS cache.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

1. GSS-TSIG can be enable in BIND through the use of the following options in named.conf:
2. Create the Kerberos key and include it in a key statement and use the key in the zone statements: