4 ms·
Clock skew is a bad enough thing that it's accepted wisdom to not run timing-sensitive authentication authorities (read: Kerberos, mostly) in a hypervisor or VM
by packetized 11y ago
Clock skew is a bad enough thing that it's accepted wisdom to not run timing-sensitive authentication authorities (read: Kerberos, mostly) in a hypervisor or VM container.
- josh2600 11y agoThis has a few of reasons: 1) all abstraction necessarily adds a performance penalty. 2) Hypervisors or VMs have core affinity, but, often, multiple VMs and Hypervisors are pinned to the same core. Since one cpu cannot expose time to two different vm requests at precisely the same time, there is always some variance. 3) Process isolation is pretty good, but total performance isolation is not quite the same. There are a TON of papers written about VM and hypervisor time management. It's all fascinating and hard.
- packetized 11y agoAbsolutely. I'm just surprised that this many people seem to be in the dark about clock synchronicity (or lack thereof) effects on distributed systems.