3 ms·
The problem with this solution is that it's very expensive. Imagine couple hundreds of millions of computers making a TLS connection every few minutes. For NTP
by mlichvar 11y ago
The problem with this solution is that it's very expensive. Imagine couple hundreds of millions of computers making a TLS connection every few minutes.
For NTP there is Autokey (RFC 5906), which allows authentication of the servers with public-key crypto. It has various problems, one of them is that it's insecure.
The NTP working group is currently preparing a Network Time Security specification and its implementation in NTP, which is supposed to replace Autokey.
https://datatracker.ietf.org/wg/ntp/documents/ https://datatracker.ietf.org/wg/ntp/documents/