Re: [chrony-dev] Idea: Leapsecond info via DNS |
[ Thread Index |
Date Index
| More chrony.tuxfamily.org/chrony-dev Archives
]
- To: chrony-dev@xxxxxxxxxxxxxxxxxxxx
- Subject: Re: [chrony-dev] Idea: Leapsecond info via DNS
- From: Rune Magnussen <rune@xxxxxxxxx>
- Date: Sun, 18 Sep 2016 10:53:54 +0200
- Dkim-signature: v=1; a=rsa-sha256; c=relaxed/simple; d=knus.info; s=mail; t=1474188834; bh=YvOAzUjU1GCvhULetC6HQvzEtvlqu8488xOGmT2vOB0=; h=Date:From:To:Subject:In-Reply-To:References; b=qYsOfQQDsZynaIcquwrLfzNzDhw6HkWc6mfuvc1aTuoj9BagLAaOB8U/wtl4Hx6EB ge7KPsBrNXhaz+jqqgQ4khqOjnCSsoOyI1v2M73svuUWwpOMsSfgesWFh77yDgaT/O 0y08r3POIOALlkX94PC2LywE7n2mWanFtjvOjvcU=
På Fri, 16 Sep 2016 17:48:29 +0200
Miroslav Lichvar <mlichvar@xxxxxxxxxx> skrev:
> On Wed, Sep 14, 2016 at 11:32:55PM +0200, Rune Magnussen wrote:
> > Hi
> >
> > Poul-Henning Kamp has implemented a system to get leapsecond
> > information via DNS. I wonder if it is feasible to use in chronyd.
> > The benefit would be that there is no need to download and update
> > leapsecond files. On the other hand it adds a dependency on another
> > service. PHK has made a reference implementation in the form of a
> > test program here:
> >
> > http://www.freebsd.dk/time/20151122.html
>
> It's an interesting idea. I like that it announces leap seconds one
>
[cut]
>
> However, I'm not sure if this is the best approach for getting leap
> second information. DNS is normally unsecure, so a MITM attacker could
> inject a false leap second even if all NTP sources were
> authenticated.
Is DNS worse than NTP-packets when it comes to MITM?
>
> I'd rather see chrony to get support for reading leap seconds from the
> "leap-seconds.list" file, which is distributed by multiple servers,
> and recommend running "sleep $[RANDOM] && wget -O ... https://...."
> from cron every month or so.
You would then have to make sure the checksums are downloaded from
another mirror than the file and the best mirrors would depend on where
you are. This seems almost as complicated as adding support for leap
seconds via DNS.
Regards Rune
--
To unsubscribe email chrony-dev-request@xxxxxxxxxxxxxxxxxxxx with "unsubscribe" in the subject.
For help email chrony-dev-request@xxxxxxxxxxxxxxxxxxxx with "help" in the subject.
Trouble? Email listmaster@xxxxxxxxxxxxxxxxxxxx.