What's up with our MAC support?

Eric S. Raymond esr at thyrsus.com
Sat Feb 2 06:19:03 UTC 2019


I was reviewing documentation today and discovered something alarming.

The docs still talk about MD5 and SHA-1, but the comments in ntpkeygen
reference something called AES-128 which doesn't seem to be
referenced at all in the docs or the NTP RFCs.

The last person to work on this seems to have been Hal.

Can someone tell me what is going on here?  Have we broken
compatibility with other NTPv4 implementations using MD5 and SHA-1
MACs?  What was the motivation for this change? Why is it
undocumented?
-- 
		<a href="http://www.catb.org/~esr/">Eric S. Raymond</a>

The end move in politics is always to pick up a gun.
	-- R. Buckminster Fuller


More information about the devel mailing list