More Info:

Ensure that Cloud DNS key uses secure algorithm for encryption.

Risk Level

High

Address

Security

Compliance Standards

CBP

Triage and Remediation

Remediation

To remediate the misconfiguration “GCP DNS Key Should Use Secure Algorithm” in GCP using GCP console, follow the below steps:

  1. Login to GCP console and navigate to the Cloud DNS page.

  2. Click on the name of the DNS zone for which you want to remediate the misconfiguration.

  3. In the left-hand menu, click on the “DNSSEC” tab.

  4. Check the “DNSSEC” box to enable DNSSEC for the selected DNS zone.

  5. Click on the “Create” button to create a new DNSSEC key.

  6. In the “Algorithm” drop-down list, select an algorithm that is considered secure. For example, you can choose “RSASHA256” or “RSASHA512”.

  7. Click on the “Create” button to create the new key.

  8. Once the key is created, click on the “Activate” button to activate DNSSEC for the selected DNS zone.

  9. Wait for the DNSSEC activation to complete. This may take a few minutes.

  10. Once the activation is complete, verify that the DNSSEC status for the selected DNS zone is “Active”.

By following these steps, you have successfully remediated the misconfiguration “GCP DNS Key Should Use Secure Algorithm” in GCP using GCP console.

Additional Reading: