[Forgot Password]
Login  Register Subscribe

30480

 
 

423868

 
 

254492

 
 

909

 
 

198541

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

Configure DNS over HTTPS (DoH) name resolution

ID: oval:org.secpod.oval:def:79738Date: (C)2022-05-07   (M)2023-05-09
Class: COMPLIANCEFamily: windows




Specifies if the DNS client will perform name resolution over DNS over HTTPS (DoH). By default, the DNS client will do classic DNS name resolution (over UDP or TCP). This setting can enhance the DNS client to use DoH protocol to resolve domain names. To use this policy setting, click Enabled, and then select one of the following options from the drop-down list: Prohibit DoH: No DoH name resolution will be performed. Allow DoH: Perform DoH queries if the configured DNS servers support it. If they don't support it, try classic name resolution. Require DoH: Allow only DoH name resolution. If there are no DoH capable DNS servers configured, name resolution will fail. If you disable this policy setting, or if you do not configure this policy setting, computers will use locally configured settings. Fix: (1) GPO: Computer Configuration\Administrative Templates\Network\DNS Client\Configure DNS over HTTPS (DoH) name resolution (2) REG: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows NT\DNSClient!DoHPolicy

Platform:
Microsoft Windows 11
Reference:
CCE-97097-0
CPE    1
cpe:/o:microsoft:windows_11:21h2::x64
CCE    1
CCE-97097-0
XCCDF    3
xccdf_org.secpod_benchmark_general_Windows_11
xccdf_org.secpod_benchmark_NIST_800_53_r5_Windows_11
xccdf_org.secpod_benchmark_NIST_800_171_R2_Windows_11

© SecPod Technologies