SRG-APP-000176 Controls

STIG IDVersionTitleProduct
SRG-APP-000176-DNS-000017V4R2The DNS server implementation, when using PKI-based authentication, must enforce authorized access to the corresponding private key.Security Requirements Guide - Domain Name Service
SRG-APP-000176-DNS-000018V4R2The key file must be owned by the account under which the name server software is run.Security Requirements Guide - Domain Name Service
SRG-APP-000176-DNS-000019V4R2Read/Write access to the key file must be restricted to the account that runs the name server software only.Security Requirements Guide - Domain Name Service
SRG-APP-000176-DNS-000094V4R2Only the private key corresponding to the ZSK alone must be kept on the name server that does support dynamic updates.Security Requirements Guide - Domain Name Service
SRG-APP-000176-DNS-000096V4R2Signature generation using the KSK must be done off-line, using the KSK-private stored off-line.Security Requirements Guide - Domain Name Service
SRG-APP-000176-MFP-000243V3R4The Mainframe Product, when using PKI-based authentication, must enforce authorized access to the corresponding private key.Security Requirements Guide - Mainframe Product
SRG-APP-000176-WSR-000096V4R4Only authenticated system administrators or the designated PKI Sponsor for the web server must have access to the web servers private key.Security Requirements Guide - Web Server