Model: MTS200 (1U)
Doc. Ref. no. : - m08/om/201
Issue no.: 03
Page 133 of 195
User’s Manual
As the IFF parameter key file in independent of keys and certificates, the private and public key at each
normal NTP server and NTP clients can be refreshed or recreated as needed.
There will be only one MTS200 device in complete NTP group which will act as Trusted Authority with
trusted server functionality. Other MTS200 units in same NTP network will only be acting as trusted
server mode.
In below explanation, Group Key in IFF scheme refers to IFF parameter key which should be shared
among Trusted NTP servers, NTP servers and NTP clients.
Procedure to Generate NTP Autokey IFF Scheme keys in MTS200 which will act as Trusted
Authority in NTP network:
User can generate Autokey for PC and IFF scheme in MTS200 using webserver only. To generate PC
schemes keys, user need to go device webserver page Security, in which NTP Autokey section is
provided.
Step 1:
Then, user need to select IFF
option in field “Identity Scheme” and mark Certificate Type as
“Trusted Server”. Autokey IFF scheme need password to be entered for generate private key and
private certificate. User need to remember this password to set in ntp client ntp.conf file while
starting IFF scheme based ntp associations between server and client.
Figure 11-7 NTP Autokey
– IFF Scheme Settings on Webserver
Step 2
: After password is entered, click on “Submit Password”. This option will configure the crypto
password in MTS200
ntp configuration file automatically. “Generate NTP Autokey” option will only
be enable after “Submit Password” is done.
Step 3
: Selecting
“Generate NTP Autokey” option, it will generate the NTP Autokey IFF scheme private
key, private certificate and group key automatically. While the keys are being generated, the
background of webserver will be hidden till all keys are generated.