dnssec constraint doesn't create violation

19 views
Skip to first unread message

Ashish Goel

unread,
Oct 23, 2020, 5:19:35 PM10/23/20
to Forseti Security Discussion
hello, 

i am using below constraint file in Forseti from here with corresponding template file here to get notification in CSCC when a managed DNS public zone is created / exist without DNSSEC set ON. 

kind: GCPDNSSECConstraintV1
metadata:
  name: require_dnssec
  annotations:
    description: Checks that DNSSEC is enabled for a Cloud DNS managed zone.
spec:
  severity: high
  parameters: {}

 Forseti does not though create a violation . do you see any issue with above constraint file. 

thanks in advance

Ash 

Reply all
Reply to author
Forward
0 new messages