2.1.1.4 Ensure ntp is configured (Automated)
Description
ntp is a daemon which implements the Network Time Protocol (NTP). It is designed to synchronize system clocks across a variety of systems and use a source that is highly accurate. More information on NTP can be found at http://www.ntp.org. ntp can be configured to be a client and/or a server.
Notes:
- If chrony or systemd-timesyncd are used, ntp should be removed and this section skipped
- This recommendation only applies if ntp is in use on the system
- Only one time synchronization method should be in use on the system
Rationale
If ntp is in use on the system proper configuration is vital to ensuring time synchronization is working properly.
Audit Procedure
Command Line
Verify that only one time synchronization method is in use on the system:
Run the following command to verify chrony is not in use on the system:
dpkg -s chrony | grep -E '(Status:|not installed)'
Run the following command to verify that systemd-timesyncd is not in use on the system:
systemctl is-enabled systemd-timesyncd
Verify that ntp is configured:
Run the following command and verify output matches:
grep "^restrict" /etc/ntp.conf
Run the following command and verify remote server is configured properly:
grep -E "^(server|pool)" /etc/ntp.conf
Verify that ntp is configured to run as the ntp user by running the following command and verifying output matches:
grep "RUNASUSER=ntp" /etc/init.d/ntp
Expected Result
- chrony should not be installed:
dpkg-query: package 'chrony' is not installed and no information is available - systemd-timesyncd should be
masked /etc/ntp.confshould contain:restrict -4 default kod nomodify notrap nopeer noqueryandrestrict -6 default kod nomodify notrap nopeer noquery- The
-4in the first line is optional and options afterdefaultcan appear in any order. Additional restriction lines may exist - Server/pool lines should be configured:
server <remote-server> - Multiple servers may be configured
/etc/init.d/ntpshould contain:RUNASUSER=ntp
Remediation
Command Line
Remove and/or disable additional time synchronization methods:
Run the following command to remove chrony:
apt purge chrony
Run the following command to stop and mask systemd-timesyncd:
systemctl --now mask systemd-timesyncd
Configure ntp:
Add or edit restrict lines in /etc/ntp.conf to match the following:
restrict -4 default kod nomodify notrap nopeer noquery
restrict -6 default kod nomodify notrap nopeer noquery
Add or edit server or pool lines to /etc/ntp.conf as appropriate:
server <remote-server>
Configure ntp to run as the ntp user by adding or editing the /etc/init.d/ntp file:
RUNASUSER=ntp
Default Value
ntp is not configured by default.
References
- http://www.ntp.org
- CIS Controls v7 - 6.1 Utilize Three Synchronized Time Sources
Profile
- Level 1 - Server
- Level 1 - Workstation