2.3.1.2 Ensure chrony is enabled and running

Information

chrony is a daemon for synchronizing the system clock across the network

chrony needs to be enabled and running in order to synchronize the system to a timeserver.

Time synchronization is important to support time sensitive security mechanisms and to ensure log files have consistent time records across the enterprise to aid in forensic investigations

Note:

- If systemd-timesyncd is being used, chrony should be removed and this section skipped
- Only one time synchronization method should be in use on the system

Solution

- IF - chrony is in use on the system, run the following commands:

Run the following command to unmask chronyd.service :

# systemctl unmask chronyd.service

Run the following command to enable and start chronyd.service :

# systemctl --now enable chronyd.service

- OR -

If another time synchronization service is in use on the system, run the following command to remove chrony :

# zypper remove chrony

See Also

https://workbench.cisecurity.org/benchmarks/26236

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-7, 800-53|AU-8, CSCv7|6.1

Plugin: Unix

Control ID: 01c871a12973b6b6ac6f29d1babd2c606a06111310550b958b6d4557af406e0f