nanog mailing list archives
Re: ntp config tech note
From: "C. Jon Larsen" <jlarsen () richweb com>
Date: Thu, 20 May 2004 23:41:38 -0400 (EDT)
On Fri, 21 May 2004, Adrian Chadd wrote:
Isn't that a lot safer anyway than running a daemon (ntpd) as root ? I do this on my systems (run ntpdate from cron), even though the xntpd docs IIRC specifically advised against this hack. One less vulnerability waiting to be exploited ... is the way I see it.Kind of. ntpdate just sets the time. ntpd will actually notice your clock running fast/slow and slowly step your kernel time to deal with your bad clock frequency. man ntpd. Its quite fascinating.
I know what ntpd is supposed to do. Its what its *not* supposed to do that worries me - i.e. when someone finds that next flaw and exploits it. My personal feeling was that for most systems its better to not have the daemon running - i.e. the benefit of smaller more frequent clock adjustments does not outweigh the cost of another service running, especially as root or even as a jailed non-root user. I checked and the cron job usually adjusts the clock by about 0.2 to 0.3 sec every hour. Sure thats probably more than ntpd would adjust it in any one iteration were ntpd running ... according to: http://www.eecis.udel.edu/~mills/ntp/html/ntpdate.html its not too kooky or dangerous to use ntpdate + cron rather than ntpd; 0.5 sec is given as a cutoff for it being less disruptive when making clock adjustments. Its interesting to hear what other folks are doing. I had assumed folks normally don't run ntpd on each and every server and that ntpdate + cron was much preferred; maybe I am off-base.
Current thread:
- Re: ntp config tech note, (continued)
- Re: ntp config tech note bmanning (May 20)
- Re: ntp config tech note Kevin Oberman (May 20)
- Re: ntp config tech note Robert E. Seastrom (May 20)
- Re: ntp config tech note Simon Lockhart (May 20)
- Re: ntp config tech note Randy Bush (May 20)
- Re: ntp config tech note Jared Mauch (May 20)
- Re: ntp config tech note James Edwards (May 20)
- Re: ntp config tech note C. Jon Larsen (May 20)
- Re: ntp config tech note Jared Mauch (May 20)
- Re: ntp config tech note Adrian Chadd (May 20)
- Re: ntp config tech note C. Jon Larsen (May 20)
- Re: ntp config tech note Adrian Chadd (May 20)
- Re: ntp config tech note Randy Bush (May 20)
- Re: ntp config tech note sthaug (May 21)
- Re: ntp config tech note C. Jon Larsen (May 21)
- Re: ntp config tech note Eric A. Hall (May 21)
- Re: ntp config tech note Mike Leber (May 24)
- Re: ntp config tech note Crist Clark (May 21)
- Re: ntp config tech note james edwards (May 21)
- Re: ntp config tech note Charles Sprickman (May 20)
- Re: ntp config tech note Pekka Savola (May 21)
