Check: GEN001375
SUSE Linux Enterprise Server v11 for System z STIG:
GEN001375
(in versions v1 r12 through v1 r9)
Title
For systems using DNS resolution, at least two name servers must be configured. (Cat III impact)
Discussion
To provide availability for name resolution services, multiple redundant name servers are mandated. A failure in name resolution could lead to the failure of security functions requiring name resolution, which may include time synchronization, centralized authentication, and remote system logging.
Check Content
Determine if DNS is enabled on the system. # grep dns /etc/nsswitch.conf If no line is returned, or any returned line is commented out, the system does not use DNS, and this is not applicable. Determine the name servers used by the system. # grep nameserver /etc/resolv.conf If less than two lines are returned that are not commented out, this is a finding.
Fix Text
Edit /etc/resolv.conf and add additional "nameserver" lines until at least two are present.
Additional Identifiers
Rule ID: SV-44989r1_rule
Vulnerability ID: V-22331
Group Title: GEN001375
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-001182 |
The information systems that collectively provide name/address resolution service for an organization are fault-tolerant. |
Controls
Number | Title |
---|---|
SC-22 |
Architecture And Provisioning For Name / Address Resolution Service |