NTS update

Hal Murray hmurray at megapathdsl.net
Mon Mar 25 04:38:53 UTC 2019


> My slower RasPi have random startup crashes.  Goes away when I do not make
> them NTS clients.  Feels like another mysyslog() thing?

I'd expect garbage in the log files rather than crashes.

There is a known bug:  nts doesn't work with IP Addresses.  Gets a segfault.  
That case might make sense for testing with noval but anything with noval is 
insecure.  Better to use old shared key authentication.

> The waf install, or runtime, or both, need to make /var/lib/ntp if missing.
> Not quite sure...

What OS/distro?  NetBSD uses /var/db/ rather than /var/lib/
You can fix it in your ntp.conf
  nts cookie <filename>


> When I set a server cert, is that used as the client cert too?

There is no code for client certs.


> As the hackathon showed, we'll need cert pinning sooner rather than later. 

Please say more?  (start a new thread)



-- 
These are my opinions.  I hate spam.





More information about the devel mailing list