Include Cryptographic Key Files (Scored)
Scanned 9/3/2026
Install to Claude Code
npx -y skills add CyberStrikeus/CyberStrike --skill cis-bind9-v301-4-2 --agent claude-codeInstalls into .claude/skills of the current project.
Are you the author of Cis Bind9 V301 4 2?
Add the live security badge to your README — it updates automatically with every re-scan.
[](https://www.skillsdirectory.com/skills/cyberstrikeus-cis-bind9-v301-4-2)More formats (shields.io, HTML) on the badges page.
---
name: cis-bind9-v301-4-2
description: "Include Cryptographic Key Files (Scored)"
category: cis-bind
version: "3.0.1"
author: cyberstrike-official
tags: [cis, bind, dns, isc-bind, bind9, tsig]
cis_id: "4.2"
cis_benchmark: "CIS ISC BIND DNS Server 9.9 Benchmark v3.0.1"
tech_stack: [bind, isc-bind, dns, linux]
cwe_ids: []
chains_with: []
prerequisites: []
severity_boost: {}
---
# CIS 4.2 — Include Cryptographic Key Files
## Profile Applicability
- Level 1 - Authoritative Name Server
- Level 1 - Caching Only Name Server
## Description
Do not place keys directly in the BIND `named.conf`, but use separate configuration files for the keys and include them into the `named.conf` file, in order to protect the keys from unintentional disclosure.
## Rationale
Although the keys may be placed directly in the named.conf file, putting it in a separate file will limit the number of times it needs to be viewed, and make it independent of viewing and changes to the main configuration file.
## Impact
None noted.
## Audit Procedure
Use the grep command below to search the `named.conf` file to ensure it doesn't have any secret keys placed in the file.
```bash
# grep -C 3 secret /etc/named.conf
key host1-host2.cisecurity.org {
algorithm hmac-sha256;
secret "1R3DP9D81/yWXjqf3hlg2beRpti1883JnZ3s7RVb1HU=";
};
```
## Remediation
Move each key definition statement from the `named.conf` file into its own key file. It is recommended to name both the key and the key file after the two hosts that will be sharing the secret key, in order to avoid confusion. Then include the key files with include statements in the `named.conf`. An example is shown below with the key definition statement moved to a separate key file, however it is also accepted for only the secret statement to be moved to another file.
```bash
# grep -C 1 include /etc/named.conf
// Include the key file used for the host1 and host2 TSIG comms
include "/etc/private/host1-host2.cisecurity.org.key";
# cat /var/named/chroot/etc/private/host1-host2.cisecurity.org.key
key host1-host2.cisecurity.org {
algorithm hmac-sha256;
secret "1R3DP9D81/yWXjqf3hlg2beRpti1883JnZ3s7RVb1HU=";
};
```
## Default Value
During a default install an `rndc` key is generated in a separate file `/etc/rndc.key` and included in the `named.conf`.
## References
None listed.
## CIS Controls
| Controls Version | Control | IG 1 | IG 2 | IG 3 |
| ---------------- | ------------------------------------------------ | ---- | ---- | ---- |
| v6 | 14 - Controlled Access Based on the Need to Know | Y | Y | Y |
## MITRE ATT&CK Mappings
| Tactic | Technique |
| ----------------- | ------------------------------ |
| Credential Access | T1552 - Unsecured Credentials |
| Collection | T1005 - Data from Local System |
## Profile
- Level 1 - Authoritative Name Server
- Level 1 - Caching Only Name Server
Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.
No comments yet. Be the first to comment!