5.
2.7.8.9
NTP Authentication
Since NTP information is distributed across entire networks, NTP poses a security risk: Falsified
NTP time stamps or other NTP-related information can be exploited by an attacker. NTP authen-
tication keys are used to authenticate time synchronization, thus detecting a fake time source
before it can do harm.
NTP Autokey
The NTP version installed on VersaSync supports the Autokey Protocol. The Autokey Protocol
uses the OpenSSL library which provides security capabilities including message digests,
digital signatures and encryption schemes. The Autokey Protocol provides a means for NTP to
authenticate and establish a chain of trusted NTP servers.
NTP Autokey: Support & Limitations
Currently, VersaSync supports only the IFF (Identify Friend or Foe) Autokey Identity Scheme. The
VersaSync product web interface automates the configuration of the IFF using the MD5 digests
and RSA keys and certificates. At this time the configuration of other key types or other digests
is not supported.
NTP Autokey: IFF Autokey Support
The IFF Autokey Support is demonstrated in the figure below. The IFF identity scheme is used
with Multiple Stratum NTP Time Servers. The example below shows 3 Stratum layers. Stratum 1
NTP Servers are close to the physical time references. All Stratum 1 servers can be Trusted
Hosts. One of them is the trusted route used to generate the IFF Group/Client Key. This defines
the IFF Group.
All other group members generate Group Certificate and RSA public/private keys using MD5
digest. Each group member must share the common IFF Group/Client Key. Stratum 2 NTP serv-
ers are also members of the Group. All NTP Stratum 1 servers are Trusted Hosts. The NTP serv-
ers closest to the actual time reference (Stratum 1) should be designated trusted. A single
Stratum 1 NTP server generates the IFF Group/Client Keys. There is NO group name feature
CHAPTER
•
2
VersaSync User Manual Rev. 6.0
"Configuring "NTP Stratum 1" Operation" on page 84.
Note:
Please note that it is not advisable to mark more than one NTP
Peer as
doing so.
Click Submit, or press Enter.
Note:
When you configure NTP Autokey, you must disable the NTP service first,
and then re-enable it after Autokey configuration is completed.
Preferred
, even though VersaSync will not prevent you from
2.7 Configuring Network Settings
93
Need help?
Do you have a question about the VersaSync and is the answer not in the manual?