Check: RHEL-09-252040
RHEL 9 STIG:
RHEL-09-252040
(in versions v1 r3 through v1 r1)
Title
RHEL 9 must configure a DNS processing mode set be Network Manager. (Cat II impact)
Discussion
In order to ensure that DNS resolver settings are respected, a DNS mode in Network Manager must be configured.
Check Content
Verify that RHEL 9 has a DNS mode configured in Network Manager. $ NetworkManager --print-config [main] dns=none If the dns key under main does not exist or is not set to "none" or "default", this is a finding.
Fix Text
Configure NetworkManager in RHEL 9 to use a DNS mode. In "/etc/NetworkManager/NetworkManager.conf" add the following line in the "[main]" section: dns = none NetworkManager must be reloaded for the change to take effect. $ sudo systemctl reload NetworkManager
Additional Identifiers
Rule ID: SV-257949r925834_rule
Vulnerability ID: V-257949
Group Title: SRG-OS-000480-GPOS-00227
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000366 |
The organization implements the security configuration settings. |
Controls
Number | Title |
---|---|
CM-6 |
Configuration Settings |