Using NTP
Using MD5 Keys on a SyncServer
A high level description of how to set up MD5 authentication between two NTP devices:
1. Generate the MD5 keys on one device.
2. Securely transfer the keys to the other device.
3. Configure the relevant NTP association(s) to use MD5 authentication.
Mix and match the sections in this topic with those in
Using MD5 Keys on a generic NTP
device
(on page 162) as needed.
Recommendation: When configuring NTP authentication, log in to the SyncServer securely
by selecting the
Secure
checkbox on the
Login
page. This opens an https session with port
443 on the SyncServer. Also see
Enabling Secure Login
(on page 164).
Generating and downloading MD5 keys
1. Log in to the SyncServer securely.
2. On
NTP - MD5 Keys
page, click the
GENERATE
button. This generates a new set of MD5
keys, overwriting any previous ones.
3. Use the
SAVE AS...
button and save
ntp.keys
to your computer.
4. Click the
RESTART
button. This restarts the NTP daemon, putting all of the keys into
effect.
The SyncServer automatically trusts all of the NTP keys. This is equivalent to the following
command in ntp.conf:
trustekey 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 ...
Enabling MD5 for a particular NTP association
The Role of the association must be
Server
,
Peer
,
Broadcast.
1. Log in to the SyncServer securely.
2. Go to the
NTP - Config
page.
3. Create or edit an NTP association.
4. Set
MD5 Key
to
Key
and select a
key number
. That key number must be a
trustedkey
on
the other device for authentication to work.
5. Click the
SAVE
button.
6. Click the
RESTART
button.
After several minutes go to
NTP - Assoc
and confirm that
Reach
for this association is greater
than 0. If not, authentication isn't working.
Uploading the MD5 keys to a SyncServer
1. Log in to the other SyncServer securely.
2. On the
NTP - MD5 Keys
page, use the
BROWSE
button to locate the files on your computer.
3. Click the
UPLOAD
button. This copies the keys to the SyncServer.
4. Click the
RESTART
button. This restarts the NTP daemon, putting all of the keys into
effect.
997-01520-02 Rev. F1
..........................................................................
Page 161