More Info:

Ensure that DNSSEC is enabled for Cloud DNS.

Risk Level

Medium

Address

Security

Compliance Standards

CISGCP, CBP

Triage and Remediation

Remediation

To remediate the DNSSEC misconfiguration in GCP using the GCP console, follow these steps:

  1. Open the GCP console and navigate to the Cloud DNS page.

  2. Select the DNS zone for which you want to enable DNSSEC.

  3. Click on the “DNSSEC” tab.

  4. Click on the “Enable DNSSEC” button.

  5. Enter the KSK (Key Signing Key) and ZSK (Zone Signing Key) values. You can either generate these keys yourself or use the default values provided by GCP.

  6. Click on the “Enable” button to enable DNSSEC for the selected DNS zone.

  7. Once DNSSEC is enabled, you can verify it by checking the “DNSSEC Status” column on the Cloud DNS page. It should show “Enabled” for the selected DNS zone.

That’s it! You have successfully remediated the DNSSEC misconfiguration in GCP using the GCP console.