Przejdź do treści

Konfigurowanie serwera NTP na Mediation Controller

Użycie serwera NTP pozwala zsynchronizować zegary twoich maszyn z zegarem serwera NTP.
Ta dokumentacja opisuje konfigurację serwera NTP dla serwera Mediation Controller CyberElements Bastion.

Wymagania wstępne

Wymagany jest dostęp przez SSH lub konsolę oraz możliwość użycia konta superużytkownika na maszynie. Ponadto musisz upewnić się, że serwer Mediation Controller ma otwarty port UDP 123 do wybranego serwera lub serwerów NTP.

Konfigurację serwera lub serwerów NTP dla serwera Mediation Controller CyberElements Bastion ustawia się w pliku /etc/ntpsec/ntp.conf. Domyślnie jako serwery NTP używane są serwery Debiana.

Aby dostosować serwer lub serwery NTP, które mają być używane, zacznij od zakomentowania (dodaj # na początku wiersza) użycia serwerów NTP Debiana w wierszach 34-37:

31
32
33
34
35
36
37
# pool.ntp.org maps to about 1000 low-stratum NTP servers.  Your server will
# pick a different set every time it starts up.  Please consider joining the
# pool: <http://www.pool.ntp.org/join.html>
#pool 0.debian.pool.ntp.org iburst
#pool 1.debian.pool.ntp.org iburst
#pool 2.debian.pool.ntp.org iburst
#pool 3.debian.pool.ntp.org iburst

Następnie, począwszy od wiersza 27, dodaj jeden lub więcej serwerów NTP. Na każdy wiersz należy dodać jeden serwer, w następującym formacie: server IP_ou_DNS_NTP.

Przykład

Aby użyć serwerów ntp1.systancia.local i 172.16.20.20, plik należałoby zmienić następująco:

26
27
28
29
30
31
32
33
34
35
36
37
38
39
# Specify one or more NTP servers.
server ntp1.systancia.local
server 172.16.20.20

# Public NTP servers supporting Network Time Security:
# server time.cloudflare.com nts

# pool.ntp.org maps to about 1000 low-stratum NTP servers.  Your server will
# pick a different set every time it starts up.  Please consider joining the
# pool: <http://www.pool.ntp.org/join.html>
#pool 0.debian.pool.ntp.org iburst
#pool 1.debian.pool.ntp.org iburst
#pool 2.debian.pool.ntp.org iburst
#pool 3.debian.pool.ntp.org iburst

Informacja

Więcej informacji o konfiguracji tego pliku można uzyskać poleceniem man ntp.conf.

Uwaga!

Jeśli zdefiniujesz mniej niż 3 serwery NTP, parametr minsane w wierszu 24 trzeba obniżyć do liczby serwerów NTP.
Bez tej zmiany ntpsec nie skoryguje czasu maszyny.

Example

Jeśli zdefiniowany jest tylko jeden serwer NTP, wiersz 24 trzeba zmienić tak, aby wartość minsane wynosiła 1:

24
tos minclock 4 minsane 1

Biorąc powyższy przykład konfiguracji z dwoma skonfigurowanymi serwerami NTP, a więc z wartością minsane równą 2, mielibyśmy następujące ustawienia globalne:

22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
# Comment this out if you have a refclock and want it to be able to discipline
# the clock by itself (e.g. if the system is not connected to the network).
tos minclock 4 minsane 2

# Specify one or more NTP servers.
server ntp1.systancia.local
server 172.16.20.20

# Public NTP servers supporting Network Time Security:
# server time.cloudflare.com nts

# pool.ntp.org maps to about 1000 low-stratum NTP servers.  Your server will
# pick a different set every time it starts up.  Please consider joining the
# pool: <http://www.pool.ntp.org/join.html>
#pool 0.debian.pool.ntp.org iburst
#pool 1.debian.pool.ntp.org iburst
#pool 2.debian.pool.ntp.org iburst
#pool 3.debian.pool.ntp.org iburst

Po zapisaniu nowej konfiguracji trzeba ponownie uruchomić usługę ntpsec:

1
systemctl restart ntpsec