You are not logged in.

#1 2009-08-07 22:41:01

graysky
Wiki Maintainer
From: :wq
Registered: 2008-12-01
Posts: 10,597
Website

openntpd config question - security in /etc/ntpd.conf

I read the NTP wiki page and installed openntpd.  It wasn't clear to me from the page if the default /etc/ntpd.conf was secure or if securing it requires additional lines.  Right now I'm using the default /etc/ntpd.conf which only contains a 'servers' line.  Are there any recommended lines to add security to this daemon or is this one-line config file sufficient security-wise?

Thanks!

Last edited by graysky (2009-08-07 22:41:48)


CPU-optimized Linux-ck packages @ Repo-ck  • AUR packagesZsh and other configs

Offline

#2 2009-08-08 00:24:18

djszapi
Member
From: Cambridge, United Kingdom
Registered: 2009-06-14
Posts: 1,439
Website

Re: openntpd config question - security in /etc/ntpd.conf

Hello graysky!

For what kind of security do you think ?

Offline

#3 2009-08-08 01:53:49

majiq
Member
Registered: 2009-03-06
Posts: 259

Re: openntpd config question - security in /etc/ntpd.conf

If I understand correctly: A) the security section on that page is for ntp and not openntp and B) It's only a security issue if you're using it to act as a server and not just as a client (the default config is for it to just be a client, so it shouldn't be a hazard)

Offline

#4 2009-08-08 07:01:03

djszapi
Member
From: Cambridge, United Kingdom
Registered: 2009-06-14
Posts: 1,439
Website

Re: openntpd config question - security in /etc/ntpd.conf

It can be really off-topic, but ntp security model:
www.ece.udel.edu/~mills/database/brief/autokey/autokey.ppt

Offline

#5 2009-08-08 10:44:05

graysky
Wiki Maintainer
From: :wq
Registered: 2008-12-01
Posts: 10,597
Website

Re: openntpd config question - security in /etc/ntpd.conf

majiq wrote:

If I understand correctly: A) the security section on that page is for ntp and not openntp and B) It's only a security issue if you're using it to act as a server and not just as a client (the default config is for it to just be a client, so it shouldn't be a hazard)

A) Right, I made a slight modification to the wiki page
B) Okay, thanks for the clarification


CPU-optimized Linux-ck packages @ Repo-ck  • AUR packagesZsh and other configs

Offline

Board footer

Powered by FluxBB