Re: [chrony-users] rejecting one of two trusted hosts |
[ Thread Index |
Date Index
| More chrony.tuxfamily.org/chrony-users Archives
]
- To: chrony-users@xxxxxxxxxxxxxxxxxxxx
- Subject: Re: [chrony-users] rejecting one of two trusted hosts
- From: Miroslav Lichvar <mlichvar@xxxxxxxxxx>
- Date: Mon, 14 Feb 2022 09:21:48 +0100
- Authentication-results: relay.mimecast.com; auth=pass smtp.auth=CUSA124A263 smtp.mailfrom=mlichvar@xxxxxxxxxx
- Dkim-signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1644826914; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: in-reply-to:in-reply-to:references:references; bh=ecO/M1tLxMO5q76ptVe0rkRaPDV9fEURCmXIJhlPgZM=; b=WC8vMgQDaoz67X+a5rEITfrwypHb7kuPLPK4MweSdCue4MrfkdMkbujJev07FCOZEEqn3p vV+lL37avkLpAcLMlUyoO4/MWRhXAtgDBNYTuM1a4RCUxRIa5YE4wfVWeXFqZuZEZHSz/a BHeH2VuT6GaSoiibeZ8CklDki4x3APk=
On Thu, Feb 10, 2022 at 03:05:46PM -0500, Aaron Ball wrote:
> server tick minpoll 3 maxpoll 4 trust prefer iburst
> server tock minpoll 3 maxpoll 4 trust prefer iburst
> server time-alt1 minpoll 3 maxpoll 4
> ...
>
> If (say) tick starts sending bad time, we want chrony to declare it a
> falseticker on the basis of a majority made up of tock + time-alt1 + [other
> selectable servers] and continue to synchronize. We think this
> configuration used to do that on 3.2, and it looks like it doesn't anymore
> on 4.1.
This changed in 4.0 to better support configuration with NTS sources.
A majority is required among trusted sources to agree in order to pass
the selection. If we have two trusted sources and they don't agree
with each other, we know (at least) one of them is wrong, but I don't
think we should trust an untrusted source to decide which one.
It's the classic case of the man with two watches who doesn't know
what time it is. You need to add a third trusted source. If you are
willing to accept a majority with time-alt1, why is it not trusted?
--
Miroslav Lichvar
--
To unsubscribe email chrony-users-request@xxxxxxxxxxxxxxxxxxxx
with "unsubscribe" in the subject.
For help email chrony-users-request@xxxxxxxxxxxxxxxxxxxx
with "help" in the subject.
Trouble? Email listmaster@xxxxxxxxxxxxxxxxxxxx.