AZLX-23-002560 - Amazon Linux 2023 chrony must be configured with a maximum interval of 24 hours between requests sent to a USNO server or a time server designated for the appropriate DOD network.

Information

Inaccurate time stamps make it more difficult to correlate events and can lead to an inaccurate analysis. Determining the correct time a particular event occurred on a system is critical when conducting forensic analysis and investigating system events. Sources outside the configured acceptable allowance (drift) may be inaccurate.

Solution

Configure Amazon Linux 2023 to compare internal information system clocks at least every 24 hours with an NTP server. Ensure the following line is added or updated in /etc/chrony.conf:

server DOD.ntp.server iburst maxpoll 16

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Amazon_Linux_2023_V1R1_STIG.zip

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-8(1), CAT|II, CCI|CCI-004923, Rule-ID|SV-274174r1120510_rule, STIG-ID|AZLX-23-002560, Vuln-ID|V-274174

Plugin: Unix

Control ID: db56735122d4e04ca3de32d2df0f5d38af39d80c71263f6bdf4cc70b12ab7aea