Re: [chrony-users] Chronyd does not use non-nts servers |
[ Thread Index |
Date Index
| More chrony.tuxfamily.org/chrony-users Archives
]
- To: chrony-users@xxxxxxxxxxxxxxxxxxxx
- Subject: Re: [chrony-users] Chronyd does not use non-nts servers
- From: Miroslav Lichvar <mlichvar@xxxxxxxxxx>
- Date: Thu, 29 Oct 2020 11:43:19 +0100
- Authentication-results: relay.mimecast.com; auth=pass smtp.auth=CUSA124A263 smtp.mailfrom=mlichvar@xxxxxxxxxx
- Dkim-signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1603968207; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: in-reply-to:in-reply-to:references:references; bh=7l39ZPW+9xpmN0m/6swPJOros0z9bYItQ73afK7VmtQ=; b=gIvcK5NkHZTxaajLBJ/UMFMyVa+r227R9gkuy8T52o60KejW8q58sWQT6EqcwpFkG4MnDC JOhW9IJMNayMPSQ727KKo8yAja3ipiIfVeQO/+D+247tyK/rY1jpyzsBTxqC/axIVsw/cO jqxAvAIgn3qRZhPLPxbUbe2pf+CGsvs=
On Thu, Oct 29, 2020 at 04:09:32AM -0400, William Holmes wrote:
> [root@hostname /tmp]# date +%Y%m%d -s '19900101'
> Jan 1 00:00:21 hostname chronyd[44348]: TLS handshake with
> 194.58.202.218:4460 (nts.sth2.ntp.se) failed : Error in the certificate
> verification. The certificate is NOT trusted. The certificate chain uses
> not yet valid certificate.
Unfortunately, this is a chicken-and-egg problem with NTS. It needs
the clock to be reasonably close to the true time (say within days or
weeks) to be able to verify the certificates. The whole point of NTS
is to synchronize the clock securely, so it cannot just fall back to
unauthenticated NTP.
Most computers have an RTC backed up by a battery. Once corrected
manually, it should be good enough to keep NTS working even if the
machine is turned off for years at a time.
With no RTC or battery, you can use the -s option to restore the time
from the previous shutdown/reboot. That should work well for machines
that are not turned off for too long.
As a last resort, you can disable the certificate time checks with the
nocerttimecheck directive in chrony.conf, but it has an impact on
security.
--
Miroslav Lichvar
--
To unsubscribe email chrony-users-request@xxxxxxxxxxxxxxxxxxxx
with "unsubscribe" in the subject.
For help email chrony-users-request@xxxxxxxxxxxxxxxxxxxx
with "help" in the subject.
Trouble? Email listmaster@xxxxxxxxxxxxxxxxxxxx.