Chapter 3: Timestamping – NTP and Clock Drift
3.
Initialize drift correction. It is best to do this immediately after stopping the measurement cycle, or it might be
necessary to redo the measurement. This also resets the current time:
lunash:>
sysconf drift init -currentprecisetime
<hh:mm:ss>
4.
You can check the status of drift correction at any time:
lunash:>
sysconf drift status
To set the drift correction rate manually:
1.
Set the drift rate (in seconds per day):
lunash:>
sysconf drift set
2.
Set the current precise time and begin drift correction:
lunash:>
sysconf drift init -currentprecisetime
<hh:mm:ss>
3.
Let drift correction run for at least 3 days, and then check the time against an accurate source to ensure that
the drift correction is effective:
lunash:>
status time
NTP on SafeNet Luna Network HSM
Network Time Protocol (NTP) corrects clock drift by synchronizing the appliance's internal clock with a reliable,
consistent, and accurate time data server. This is the recommended method of keeping an accurate date and
time on the appliance. SafeNet Luna Network HSM uses NTPv4.
NTP is available from a variety of public servers. We recommend using a more secure NTP server that
supports symmetric or public-key authentication, as described in
"Securing Your NTP Connection" on the next
. Alternatively, your organization might have established its own NTP server(s). Contact your IT manager
or security officer for details. For more information about NTP authentication, see
NTP will automatically synchronize with the highest-stratum server you add. If none of these servers are
accessible, NTP will synchronize with the local clock, and may be subject to drift. To make manual drift
corrections, see
"Correcting Clock Drift Manually" on the previous page
For command syntax, see
in the
LunaSH Command Reference Guide
.
Connecting to a Public NTP Server
Connections to public NTP servers are unauthenticated and therefore less secure. See
for authenticated NTP procedures.
To connect to a public NTP server:
1.
Ensure that NTP is enabled on the appliance.
lunash:>
sysconf ntp enable
2.
Add an NTP server.
lunash:>
sysconf ntp addserver
<NTPserver>
3.
Check the NTP connection.
SafeNet Luna Network HSM 7.3 Appliance Administration Guide
007-013576-005 Rev. A 13 December 2019 Copyright 2001-2019 Thales
43