More Info:

Ensure that Cloud DNS Managed Zones use secure algorithm for encryption.

Risk Level

High

Address

Security

Compliance Standards

SOC2, NISTCSF

Triage and Remediation

Remediation

To remediate the misconfiguration “GCP DNS Managed Zones Should Use Secure Algorithm” for GCP using GCP console, follow these steps:

  1. Open the GCP console and select the project where the DNS Managed Zone is located.

  2. In the left-hand navigation menu, click on “Network services” and select “Cloud DNS”.

  3. In the Cloud DNS dashboard, select the DNS Managed Zone that needs to be remediated.

  4. Click on the “Edit” button at the top of the page.

  5. In the “Zone details” section, select the “Advanced” tab.

  6. In the “DNSSEC” section, select the “Enable DNSSEC” checkbox.

  7. Select the “Algorithm” dropdown and choose a secure algorithm such as “RSASHA256”.

  8. Click on the “Save” button at the bottom of the page to save the changes.

  9. Verify that the DNS Managed Zone is now using a secure algorithm by checking the “DNSSEC” section of the “Zone details” page.

By following these steps, you have successfully remediated the misconfiguration “GCP DNS Managed Zones Should Use Secure Algorithm” for GCP using GCP console.

Additional Reading: