• theit8514@lemmy.world
    link
    fedilink
    English
    arrow-up
    4
    ·
    15 days ago

    On the flip side of this, any reasonably sized environment should be running their own ntp pool for their servers to use. Being down one stratum is usually not that big of a deal for most environments.

    • CompactFlax@discuss.tchncs.de
      link
      fedilink
      English
      arrow-up
      4
      ·
      edit-2
      15 days ago

      When authentication is down and you can’t figure out the DNS issue, it’s probably time.

      You’re absolutely correct; time is like open source software in that it’s just there and works, and corporations don’t consider paying for it or hosting themselves.

  • Otter@lemmy.ca
    link
    fedilink
    English
    arrow-up
    2
    ·
    15 days ago

    important to note:

    This is a long‐term commitment. You can remove yourself from the pool whenever you like, but due to misbehaving NTP clients and misguided configurers resolving a singular pool IP once and hardcoding it in a fleet of devices, it can take months, years, or forever for the traffic to stop. (I e‐mailed Dave Plonka about the 2003 Netgear–University of Wisconsin incident recently, and apparently they still see a bit of traffic from these routers.) For a long time after removing yourself from the NTP Pool, you will continue to get hammered on UDP 123 for years.

  • CompactFlax@discuss.tchncs.de
    link
    fedilink
    English
    arrow-up
    2
    ·
    15 days ago

    The warning section is a good call-out, because it’s one of the services where there’s a good chance your ISP won’t like it.

    My opnsense router is configured to send itself as the local NTP server via DHCP and devices are configured to use it for NTP. I don’t have any time critical services like Kerberos auth though. That can give you a starting point for running NTP.