2.2.1.3 Ensure chrony is configured - NTP server

Information

chrony is a daemon which implements the Network Time Protocol (NTP) is designed to
synchronize system clocks across a variety of systems and use a source that is highly
accurate. More information on chrony can be found at http://chrony.tuxfamily.org/. chrony
can be configured to be a client and/or a server.

Rationale:

If chrony is in use on the system proper configuration is vital to ensuring time
synchronization is working properly.

This recommendation only applies if chrony is in use on the system.

Solution

Add or edit server or pool lines to /etc/chrony.conf as appropriate:

server <remote-server>

Configure chrony to run as the chrony user by configuring the appropriate startup script
for your distribution. Startup scripts are typically stored in /etc/init.d or /etc/systemd.

See Also

https://workbench.cisecurity.org/files/2420

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-8, CSCv6|6.1, CSCv7|6.1

Plugin: Unix

Control ID: 17ee9bbdb57e30bb833ec2c8486f1d21a734638ac6fa0080641886cd53aea76c