More Info:

Ensure that Cloud DNS Managed Zones use key signing key.

Risk Level

Medium

Address

Security

Compliance Standards

CBP

Triage and Remediation

Remediation

To remediate the misconfiguration “GCP DNS Managed Zones Should Use Key Signing Key” for GCP using GCP console, please follow the below steps:

  1. Login to your GCP console.
  2. Navigate to the Cloud DNS page by clicking on the Navigation menu > Network services > Cloud DNS.
  3. Select the DNS zone that you want to remediate.
  4. Click on the “DNSSEC” tab.
  5. Check if the DNSSEC is enabled or not. If not, click on the “Enable DNSSEC” button.
  6. Once the DNSSEC is enabled, you will see the Key Signing Key (KSK) and Zone Signing Key (ZSK) options.
  7. Click on the “Add KSK” button to add a new Key Signing Key.
  8. Enter the required details like algorithm type, key size, and description.
  9. Click on the “Create” button to create a new KSK.
  10. Once the KSK is created, you will see it in the list of KSKs.
  11. Now, select the KSK that you have just created and click on the “Activate” button to activate it.
  12. Once the KSK is activated, it will be used for signing the DNS records in the managed zone.

This completes the remediation of the misconfiguration “GCP DNS Managed Zones Should Use Key Signing Key” for GCP using GCP console.

Additional Reading: