您好,欢迎光临本网站![请登录][注册会员]  
文件名称: CIS_ISC_BIND_DNS_Server_9.9_Benchmark_v3.0.1.pdf
  所属分类: 其它
  开发工具:
  文件大小: 624kb
  下载次数: 0
  上传时间: 2019-09-11
  提 供 者: lz***
 详细说明: BIND9 安全加固。 Table of Contents Overview ...................................................................................................................................................................... 4 Intended Audience ........................................................................................................... ................................... 4 Consensus Guidance ........................................................................................................................................... 5 Typographical Conventions ............................................................................................................................ 6 Scoring Information ............................................................................................................................................ 6 Profile Definitions ................................................................................................................................................ 7 Acknowledgements ............................................................................................................................................. 8 Recommendations .................................................................................................................................................... 9 1 Planning and Architecture ........................................................................................................................... 9 1.1 Use a Split-Horizon Architecture (Not Scored) ..................................................................... 9 1.2 Do Not Install a Multi-Use System (Not Scored) ................................................................ 11 1.3 Dedicated Name Server Role (Scored) ................................................................................... 13 1.4 Use Secure Upstream Caching DNS Servers (Not Scored) ............................................. 15 1.5 Installing ISC BIND 9 (Scored) ................................................................................................... 17 2 Restricting Permissions and Ownership ............................................................................................. 19 2.1 Run BIND as a non-root User (Scored) .................................................................................. 19 2.2 Give the BIND User Account an Invalid Shell (Scored) ................................................... 21 2.3 Lock the BIND User Account (Scored) .................................................................................... 22 2.4 Set root Ownership of BIND Directories (Scored) ............................................................ 23 2.5 Set root Ownership of BIND Configuration Files (Scored) ............................................ 25 2.6 Set Group named or root for BIND Directories and Files (Scored) ............................ 27 2.7 Set Group and Other Permissions Read-Only for BIND Non-Runtime Directories (Scored) ....................................................................................................................................................... 29 2.8 Set Group and Other Permissions Read-Only for All BIND Files (Scored) .............. 31 2.9 Isolate BIND with chrooted Subdirectory (Scored) ........................................................ 33 3 Restricting Queries ....................................................................................................................................... 35 3.1 Ignore Erroneous or Unwanted Queries (Scored) ............................................................ 35 3.2 Restrict Recursive Queries (Scored) ....................................................................................... 37 3.3 Restrict Query Origins (Not Scored) ....................................................................................... 39
(系统自动生成,下载前可以参看下载内容)

下载文件列表

相关说明

  • 本站资源为会员上传分享交流与学习,如有侵犯您的权益,请联系我们删除.
  • 本站是交换下载平台,提供交流渠道,下载内容来自于网络,除下载问题外,其它问题请自行百度
  • 本站已设置防盗链,请勿用迅雷、QQ旋风等多线程下载软件下载资源,下载后用WinRAR最新版进行解压.
  • 如果您发现内容无法下载,请稍后再次尝试;或者到消费记录里找到下载记录反馈给我们.
  • 下载后发现下载的内容跟说明不相乎,请到消费记录里找到下载记录反馈给我们,经确认后退回积分.
  • 如下载前有疑问,可以通过点击"提供者"的名字,查看对方的联系方式,联系对方咨询.
 相关搜索:
 输入关键字,在本站1000多万海量源码库中尽情搜索: