On the flip side of this, any reasonably sized environment should be running their own ntp pool for their servers to use. Being down one stratum is usually not that big of a deal for most environments.
When authentication is down and you can’t figure out the DNS issue, it’s probably time.
You’re absolutely correct; time is like open source software in that it’s just there and works, and corporations don’t consider paying for it or hosting themselves.
important to note:
This is a long‐term commitment. You can remove yourself from the pool whenever you like, but due to misbehaving NTP clients and misguided configurers resolving a singular pool IP once and hardcoding it in a fleet of devices, it can take months, years, or forever for the traffic to stop. (I e‐mailed Dave Plonka about the 2003 Netgear–University of Wisconsin incident recently, and apparently they still see a bit of traffic from these routers.) For a long time after removing yourself from the NTP Pool, you will continue to get hammered on UDP 123 for years.
The warning section is a good call-out, because it’s one of the services where there’s a good chance your ISP won’t like it.
My opnsense router is configured to send itself as the local NTP server via DHCP and devices are configured to use it for NTP. I don’t have any time critical services like Kerberos auth though. That can give you a starting point for running NTP.



