<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<style type="text/css" style="display:none;"> P {margin-top:0;margin-bottom:0;} </style>
</head>
<body dir="ltr">
<div class="elementToProof" style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
The NTPsec Project is pleased to announce the tagging of version 1.2.5</div>
<div class="elementToProof" style="direction: ltr; margin-top: 1em; margin-bottom: 1em; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
Note: Python 2 and OpenSSL 1.1.0 support will be removed in the next release.</div>
<ul data-sourcepos="3:1-7:309" style="direction: ltr;">
<li style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
A new <code>ntskelog</code> statistic file has been added to the stats file collection. NTS-KE transactions are now routed here to reduce clutter in the main system log.</li><li style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
Link-Time Optimization (LTO) is now enabled by default on Linux and FreeBSD when <code>
--disable-debug-gdb</code> is configured. It remains disabled on NetBSD due to upstream toolchain breakages.</li><li style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
The <code>pool</code> configuration command now natively supports the <code>nts</code> security flag (<code>pool <server> nts</code>).</li><li style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
The server counting logic for <code>maxclock</code> (<code>tos maxclock</code>) has been corrected to skip dynamic
<code>POOL</code> slots as well as any remote servers configured with the <code>noselect</code> flag.</li><li style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
The HPGPS reference clock driver received a major update, featuring a new configuration option for listen mode, a fix for the Z3801A GPS Week Number Rollover (WNRO) glitch, the removal of the raw
<code>scpi ></code> string from <code>clockstats</code>, and the addition of several new internal tracking variables to
<code>clockstats</code>.</li></ul>
<div id="user-content-security-fixes" class="elementToProof">
<div class="elementToProof" style="direction: ltr; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<b>Security Fixes:</b></div>
</div>
<ul data-sourcepos="11:1-16:206" style="direction: ltr;">
<li style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
Fixed a buffer overflow in the Zyfer reference clock driver that could occur when processing continuation chunks (CVE-2026-18321).</li><li style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
Fixed a NULL-pointer dereference crash in the NTS-KE client when <code>SSL_new()</code> fails.</li><li style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<code>ntpd</code> now uses a cryptographically strong RNG instead of the weak libc
<code>random()</code> for association IDs, poll-time dispersal, and mode6 response padding.</li><li style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
Fixed an off-by-one boundary error in <code>ntp_RAND_bytes()</code> that could cause an out-of-bounds read.</li><li style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
Fixed an out-of-bounds read in NTS client extension parsing caused by unchecked nonce/ciphertext lengths.</li><li style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
Fixed NTS pool peers losing their NTS-KE hostname and NTS configuration on cookie renewal, which caused certificate validation to run against the peer's bare IP address instead of its configured hostname.</li></ul>
<div id="user-content-administrative-and-scripting-changes" class="elementToProof">
<div class="elementToProof" style="direction: ltr; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<b>Administrative and Scripting Changes:</b></div>
</div>
<ul data-sourcepos="20:1-27:136" style="direction: ltr;">
<li style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
The <code>ntpleapfetch</code> tool has been hardened with parameter quoting to prevent potential shell execution vulnerabilities.</li><li style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
The statistics directory argument (<code>-s PATH</code>) has been fixed and its default behavior adjusted.</li><li style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<code>ntpd</code> now explicitly logs a syslog entry when searching for supplemental configuration files inside
<code>/etc/ntpsec/ntp.d</code>.</li><li style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<code>ntpd</code> now logs an explicit message when extra pool servers are actively dropped.</li><li style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<code>ntpleapfetch</code> now correctly parses the <code>leapfile</code> directive with quoted paths and tab/space-delimited values (<a href="/NTPsec/ntpsec/-/work_items/883" id="OWAa6878818-e039-d8ec-f387-a8dce36afbf3" class="gfm gfm-issue OWAAutoLink" title="ntpleapfetch mis-parses ntp.conf" data-original="NTPsec/ntpsec#883" data-link="false" data-link-reference="false" data-issue="190218734" data-project="553594" data-iid="883" data-namespace-path="NTPsec/ntpsec" data-project-path="NTPsec/ntpsec" data-issue-type="issue" data-container="body" data-placement="top" data-reference-type="issue" data-popover-listener-added="true">#883</a>).</li><li style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
waf has been upgraded to 2.1.9, fixing a bug where <code>libntpc.so</code> was installed to the default library path instead of the location given via
<code>--libdir</code> (<a href="/NTPsec/ntpsec/-/work_items/870" id="OWA42d5cd0c-d8fa-c3ea-d67c-4057abd7da65" class="gfm gfm-issue OWAAutoLink" title="waf 2.1.4 does not honour --libdir" data-original="NTPsec/ntpsec#870" data-link="false" data-link-reference="false" data-issue="174515820" data-project="553594" data-iid="870" data-namespace-path="NTPsec/ntpsec" data-project-path="NTPsec/ntpsec" data-issue-type="issue" data-container="body" data-placement="top" data-reference-type="issue" data-popover-listener-added="true">#870
 (closed)</a>).</li><li style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
Added missing i386 time64 and mDNS/DNS-SD syscalls to the seccomp sandbox allow-list, fixing potential sandbox kills on i386 and mDNS-enabled builds.</li><li style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
Added missing <code>clock_nanosleep</code>, <code>readlink</code>, and <code>readlinkat</code> syscalls to the AMD64 seccomp sandbox allow-list, fixing SIGSYS crashes.</li></ul>
<div id="user-content-nts-and-nts-ke-fixes" class="elementToProof">
<div class="elementToProof" style="direction: ltr; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<b>NTS and NTS-KE Fixes:</b></div>
</div>
<ul data-sourcepos="31:1-41:148" style="direction: ltr;">
<li style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
NTS-KE requests and responses split across multiple TCP/TLS reads are now correctly reassembled instead of failing on the first partial chunk (<a href="/NTPsec/ntpsec/-/work_items/858" id="OWA23ee43f6-4a56-6908-d958-c1c133d18302" class="gfm gfm-issue OWAAutoLink" title="NTS-KE parsing incorrectly expects request/response to be received in one recv call" data-original="NTPsec/ntpsec#858" data-link="false" data-link-reference="false" data-issue="171054745" data-project="553594" data-iid="858" data-namespace-path="NTPsec/ntpsec" data-project-path="NTPsec/ntpsec" data-issue-type="issue" data-container="body" data-placement="top" data-reference-type="issue" data-popover-listener-added="true">#858
 (closed)</a>).</li><li style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
Fixed the NTS client failing to reset cookie length when switching to a new cookie length from a key-exchange response (<a href="/NTPsec/ntpsec/-/work_items/877" id="OWA5ecac2fc-555c-6e3f-d2c2-d4101daad66d" class="gfm gfm-issue OWAAutoLink" title="NTS client can't switch to new cookie lengths" data-original="NTPsec/ntpsec#877" data-link="false" data-link-reference="false" data-issue="178363021" data-project="553594" data-iid="877" data-namespace-path="NTPsec/ntpsec" data-project-path="NTPsec/ntpsec" data-issue-type="issue" data-container="body" data-placement="top" data-reference-type="issue" data-popover-listener-added="true">#877</a>).</li><li style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
The NTS-KE client now sets the TLS SNI field during the handshake, improving compatibility with name-based TLS proxies and load balancers.</li><li style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
Fixed NTS-KE hostname parsing to strip brackets from IPv6 literal addresses before certificate hostname validation.</li><li style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
Fixed an NTS-KE response containing more cookies than the client can store being misparsed and the entire response rejected, instead of just discarding the extras.</li><li style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
Fixed an NTS-KE connection that completes synchronously (rather than asynchronously) being wrongly treated as a connection failure.</li><li style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
NTS-KE certificate hostname/IP validation now uses the non-deprecated OpenSSL 4.0 APIs (<code>SSL_set1_ipaddr</code>/<code>SSL_set1_dnsname</code>).</li><li style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
The NTS-KE client no longer rejects a server response solely for an unrecognized non-critical record type.</li><li style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<code>ntpd</code> now validates the <code>aead</code> parameter in both per-server and global NTS configuration and logs an error instead of silently accepting an invalid value (<a href="/NTPsec/ntpsec/-/work_items/880" id="OWA6c41d0ac-5af6-caca-501a-17331527cf11" class="gfm gfm-issue OWAAutoLink" title="Bug in parsing nts aead values" data-original="NTPsec/ntpsec#880" data-link="false" data-link-reference="false" data-issue="184191230" data-project="553594" data-iid="880" data-namespace-path="NTPsec/ntpsec" data-project-path="NTPsec/ntpsec" data-issue-type="issue" data-container="body" data-placement="top" data-reference-type="issue" data-popover-listener-added="true">#880</a>).</li><li style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
NTS-KE client logging has been improved to emit one detailed message per connection attempt; the client now parses bracketed IPv6 literal addresses, applies a send timeout in addition to the existing receive timeout, and skips already-tried addresses from multi-homed
 NTS-KE servers.</li><li style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
Fixed a bug where a failed DNS-lookup thread creation or join could leave a peer's DNS/NTS resolution permanently stuck, blocking further lookups.</li></ul>
<div id="user-content-bug-fixes-and-protocol-refinements" class="elementToProof">
<div class="elementToProof" style="direction: ltr; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<b>Bug Fixes and Protocol Refinements:</b></div>
</div>
<ul data-sourcepos="45:1-59:122" style="direction: ltr;">
<li style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
Fixed a critical issue where NTPsec failed to declare itself out of sync under specific error and drift conditions.</li><li style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
Fixed a state machine bug (<a href="/NTPsec/ntpsec/-/work_items/848" id="OWA32c8dba6-e62d-a945-0767-766df5be2524" class="gfm gfm-issue OWAAutoLink" title="ntpd clears STA_UNSYNC on start" data-original="NTPsec/ntpsec#848" data-link="false" data-link-reference="false" data-issue="166400804" data-project="553594" data-iid="848" data-namespace-path="NTPsec/ntpsec" data-project-path="NTPsec/ntpsec" data-issue-type="issue" data-container="body" data-placement="top" data-reference-type="issue" data-popover-listener-added="true">#848
 (closed)</a>) where the <code>STA_UNSYNC</code> flag was prematurely cleared at system startup.</li><li style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
Fixed an interactive interface crash in <code>ntpmon</code> triggered by hitting the minus (<code>-</code>) key.</li><li style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
Added native <code>.webp</code> image encoding support to the <code>ntpviz</code> graphing tool.</li><li style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
Fixed <code>ntpd</code> silently ignoring mode 1 (symmetric active) requests, e.g. from Windows clients; they are now answered like ordinary client requests.</li><li style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
Fixed a regression where <code>ntpd</code> failed to clear peer state on interface change, delaying resynchronization after network changes.</li><li style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
Fixed NTP extension-field parsing to stop treating unrecognized non-critical fields as fatal; they are now ignored instead of causing packet rejection.</li><li style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<code>socktoa()</code> no longer formats <code>AF_UNSPEC</code> addresses as IPv4, correcting address display in
<code>ntpq</code> and <code>ntpmon</code>.</li><li style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
mode6 control protocol responses now omit peer addresses that are empty or otherwise unprintable instead of emitting malformed data.</li><li style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
Fixed <code>ntpdig</code> to build a fresh request packet (timestamp/MAC) for each destination address tried, instead of resending the same packet.</li><li style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
Fixed <code>ntpdig</code> crashing with an unhandled <code>UnicodeError</code> when a configured server name with non-ASCII characters fails DNS resolution.</li><li style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
Fixed a crash in <code>ntpq</code>'s interactive <code>noflake</code> command (<a href="/NTPsec/ntpsec/-/work_items/863" id="OWA381fec69-b504-b5a7-a227-c65d111957d6" class="gfm gfm-issue OWAAutoLink" title="ntpq noflake" data-original="NTPsec/ntpsec#863" data-link="false" data-link-reference="false" data-issue="173370485" data-project="553594" data-iid="863" data-namespace-path="NTPsec/ntpsec" data-project-path="NTPsec/ntpsec" data-issue-type="issue" data-container="body" data-placement="top" data-reference-type="issue" data-popover-listener-added="true">#863
 (closed)</a>).</li><li style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
Fixed a crash (<code>NameError</code>) in <code>ntpq</code> under Python 2 caused by referencing the Python-3-only
<code>BrokenPipeError</code>.</li><li style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
Fixed a crash in <code>ntpq</code> and <code>ntpmon</code> when a peer's source address is empty, e.g. NXDOMAIN or a POOL association.</li><li style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<code>sys_var_list</code> is no longer marked as a default variable, so it is excluded from
<code>ntpq</code>'s default <code>rv</code> (readvar) output.</li></ul>
<div id="user-content-removed" class="elementToProof">
<div class="elementToProof" style="direction: ltr; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<b>Removed:</b></div>
</div>
<ul data-sourcepos="63:1-63:267" style="direction: ltr;">
<li style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
Removed the undocumented <code>-s</code>/<code>--srcname</code> and <code>-S</code>/<code>--srcnumber</code> display options, and the
<code>hostname</code>/<code>hostnum</code> arguments to ntpq's <code>hostnames</code> command, from
<code>ntpq</code> and <code>ntpmon</code>. This shipped in 1.2.4 but was never documented in NEWS and has now been fully reverted.</li></ul>
<div class="elementToProof" style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div class="elementToProof" style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
For other changes since the previous release, please consult the project</div>
<div class="elementToProof" style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
NEWS.adoc file at https://gitlab.com/NTPsec/ntpsec/-/blob/master/NEWS.adoc</div>
<div class="elementToProof" style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div class="elementToProof" style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
Getting this release:</div>
<div class="elementToProof" style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
You can clone the git repo from https://gitlab.com/NTPsec/ntpsec.git and you</div>
<div class="elementToProof" style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
can download the release tarballs with sums and signatures from</div>
<div class="elementToProof" style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
https://ftp.ntpsec.org/pub/releases/</div>
<div class="elementToProof" style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div class="elementToProof" style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
This release is signed with the GPG key id</div>
<div class="elementToProof" style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
E57235D22764129FA4F2F4D17F52608ED0E49D76</div>
<div class="elementToProof" style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div class="elementToProof" style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div class="elementToProof" style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
-- </div>
<div class="elementToProof" style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
Matt Selsky</div>
<div class="elementToProof" style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
Release Manager</div>
<div class="elementToProof" style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
NTPsec Project</div>
<div class="elementToProof" style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
</body>
</html>