Re: [chrony-dev] Using Linux Capabilities |
[ Thread Index |
Date Index
| More chrony.tuxfamily.org/chrony-dev Archives
]
- To: chrony-dev@xxxxxxxxxxxxxxxxxxxx
- Subject: Re: [chrony-dev] Using Linux Capabilities
- From: Bryan Christianson <bryan@xxxxxxxxxxxxx>
- Date: Thu, 9 Nov 2017 11:23:52 +1300
- Dkim-signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=smtpcorp.com; s=a1-4; h=Feedback-ID:X-Smtpcorp-Track:Message-Id:To:Date: Subject:From:Reply-To:Sender:List-Unsubscribe; bh=X5ZIg5z63Qi3XfAmty66T9tyo51RtnFreQHf42wRXR8=; b=AhsmErEZG/qb6OYBg5oVSpzou4 F9TgcGqSj+Em4EbAkCdQ98BHMELSoBwNYNHWElXPNwQL15umHDRT22ixU+77S7P9cyas6igwexXMH Drs3H3+HMqJLFEeoYU1ypuD/tK3I8ch0ls1oZtD9oOMySLbzLKYOEBB9wCMQpWrVabdOhV7FeNfmW UyucsK7sLHRcx5GkhqxZy9nyZM6RLhR/XXmArxRqkSzQPkwNWoYV4aGTr/VmLD5IdhFxgKSDZ7+vq Y9a3g64k/roI7n16lADosYHBucejeea00LppGHtHQG/EvDO7x+naeXh20QJmrJMT4osTnLGY7UqB4 A6QaS8zw==;
- Feedback-id: 149811m:149811acx33YQ:149811s2YkkcSp7i:SMTPCORP
> On 9/11/2017, at 11:17 AM, Michael Cashwell <chronyd@xxxxxxxxxxxx> wrote:
>
>
> It sounds like a “more standard” approach would be:
>
> 1: chronyd is started by the OS at boot in local mode (eg: no upstream time sources) and in an inert state where it WILL NOT respond to NTP requests on the LAN because is has not been told that the system time is “good”.
>
> 2: At some point after boot up my parent process invokes chronyc (again as non-root) to bless the system time as good and thus enable NTP requests to be answered.
>
> If that’s possible without source code changes that’s fine with me.
>
Maybe you could just start chronyd but with the listening port (123) blocked in your firewall. When your system clock has been set by the external source and chronyc is reporting it as OK, then open the port to allow external requests.
Bryan Christianson
bryan@xxxxxxxxxxxxx
--
To unsubscribe email chrony-dev-request@xxxxxxxxxxxxxxxxxxxx with "unsubscribe" in the subject.
For help email chrony-dev-request@xxxxxxxxxxxxxxxxxxxx with "help" in the subject.
Trouble? Email listmaster@xxxxxxxxxxxxxxxxxxxx.