| name | cis-bind9-v301-4-3 |
| description | Use Unique Keys for Each Pair of Hosts (Scored) |
| category | cis-bind |
| version | 3.0.1 |
| author | cyberstrike-official |
| tags | ["cis","bind","dns","isc-bind","bind9","tsig"] |
| cis_id | 4.3 |
| cis_benchmark | CIS ISC BIND DNS Server 9.9 Benchmark v3.0.1 |
| tech_stack | ["bind","isc-bind","dns","linux"] |
| cwe_ids | [] |
| chains_with | [] |
| prerequisites | [] |
| severity_boost | {} |
CIS 4.3 — Use Unique Keys for Each Pair of Hosts
Profile Applicability
- Level 1 - Authoritative Name Server
- Level 1 - Caching Only Name Server
Description
A unique TSIG key should be used for each pair of communicating hosts. For example, if there is one master authoritative name server and three slave authoritative name servers that were updated by the master, then there would need to be a unique TSIG key for at least the following:
- Master <-> Slave1
- Master <-> Slave2
- Master <-> Slave3
Rationale
Each communication channel should have a unique key, to reduce the risk of key disclosure. If one of the TSIG keys or one of the slave servers is compromised, then the remaining TSIG keys are not disclosed.
Impact
None noted.
Audit Procedure
To verify each key is unique, and has unique usage, perform the following:
- The sample command below will extract the secret keys from the configuration files and count the number of occurrences of each key value.
1 secret "R/eBXL/5xso142dGZSGJixKAAW+bO1UHlIpxZAj92Cc=";
2 secret "P3/AuCgxdt3buLyeb/QxRmPe9IfMwsXRrKyNvQSbN1k=";
1 secret "SGNiICKGf86GbhzpDBZOkQ==";
1 secret "gyxEId4g2gB+pVJSKXA=";
The count occurrences preceding each key should be one in the output.
- Search the configuration files for duplicate uses of the same key name. The command below will extract references to key names.
named.conf: allow { 127.0.0.1; } keys { "rndc-key"; };
ns1-ns2.cisecurity.org.key: keys { "ns1-ns2.cisecurity.org"; };
ns1-ns3.cisecurity.org.key: keys { "ns1-ns3.cisecurity.org"; };
Each key name should be referenced only once.
Remediation
Generate unique keys for host to host communication. The command below can be used to generate 2 files, and <name>.key file and a <name>.private file with secret keys of suitable length with base64 encoding. The files themselves are not needed, and should be securely deleted once the values are copied into a key file for including in the named configuration.