# Cis Ubuntu1804 V220 2 1 2 2

> Ensure chrony is running as user _chrony

- Skill: `cyberstrikeus/cis-ubuntu1804-v220-2-1-2-2` (Agent Skill)
- Install (CLI): `npx skillmds@latest add cyberstrikeus/cis-ubuntu1804-v220-2-1-2-2`
- Raw SKILL.md: https://api.skillmd.com/api/skills/cyberstrikeus/cis-ubuntu1804-v220-2-1-2-2/raw
- Safety review: PASS (external: skill-scanner PASS, skillspector PASS)
- Works with: Claude Code, Claude.ai, OpenAI Codex
- Category: Coding & Dev Tools
- Author: cyberstrikeus (https://skillmd.com/u/cyberstrikeus)
- Updated: 2026-09-17
- Page: https://skillmd.com/skills/cyberstrikeus/cis-ubuntu1804-v220-2-1-2-2

---


# 2.1.2.2 Ensure chrony is running as user \_chrony (Automated)

## Profile

- Level 1 - Server
- Level 1 - Workstation

## Description

The chrony package is installed with a dedicated user account `_chrony`. This account is granted the access required by the chronyd service.

## Rationale

The chronyd service should run with only the required privileges.

## Audit Procedure

### Command Line

IF chrony is in use on the system, run the following command to verify the chronyd service is being run as the `_chrony` user:

```bash
# ps -ef | awk '/[c]hronyd/ && $1!="_chrony") { print $1 }'
```

Nothing should be returned.

## Expected Result

No output (empty result).

## Remediation

### Command Line

Add or edit the `user` line to `/etc/chrony/chrony.conf` or a file ending in `.conf` in `/etc/chrony/conf.d/`:

```
user _chrony
```

OR

If another time synchronization service is in use on the system, run the following command to remove chrony from the system:

```bash
# apt purge chrony
```

## Default Value

user \_chrony

## References

1. NIST SP 800-53 Rev. 5: AU-8

## CIS Controls

- v8: 8.4 - Standardize Time Synchronization
- v7: 6.1 - Utilize Three Synchronized Time Sources

