Skip to content

Commit 63a9a09

Browse files
authored
Merge pull request #1840 from ddpbsd/unbound
Unbound DNSSEC failure rules
2 parents 424395b + 95ceeb3 commit 63a9a09

File tree

3 files changed

+14
-0
lines changed

3 files changed

+14
-0
lines changed

etc/ossec.conf

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -33,6 +33,7 @@
3333
<include>opensmtpd_rules.xml</include>
3434
<include>openbsd-dhcpd_rules.xml</include>
3535
<include>nsd_rules.xml</include>
36+
<include>unbound_rules.xml</include>
3637
</rules>
3738

3839
<syscheck>

etc/rules/unbound_rules.xml

Lines changed: 12 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -50,4 +50,16 @@
5050
<description>Maybe critical URL requested</description>
5151
</rule>
5252

53+
<rule id="53774" level="0">
54+
<if_sid>53760</if_sid>
55+
<match>info: validation failure</match>
56+
<description>DNSSEC validation failure</description>
57+
</rule>
58+
59+
<rule id="53775" level="1">
60+
<if_sid>53774</if_sid>
61+
<match>no keys have a DS with algorithm</match>
62+
<description>Algorithm mismatch.</description>
63+
</rule>
64+
5365
</group>

etc/templates/config/rules.template

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -66,5 +66,6 @@
6666
<include>openbsd-dhcpd_rules.xml</include>
6767
<include>dnsmasq_rules.xml</include>
6868
<include>nsd_rules.xml</include>
69+
<include>unbound_rules.xml</include>
6970
<include>local_rules.xml</include>
7071
</rules>

0 commit comments

Comments
 (0)