3 ms·
> What does a time system have to with system start infrastructure? Accurate time is vital for many cryptographic operations. For example, in the embedded spac
by tkfu 6y ago
> What does a time system have to with system start infrastructure?
Accurate time is vital for many cryptographic operations. For example, in the embedded space you may want to have a check that your current disk image (ideally checked by dm-verity) is actually up to date. And to verify the metadata signing that disk image using Uptane/TUF/SUIT or similar protocols you need verifiable time. Or you might need to contact a provisioning server at boot time, and need to be able to verify that server's TLS cert.
(Now, systemd used to have a bug[1] where time-sync.target would be reached before time was actually synced, and Poettering's response to the bug was the all-too-typical typical "yeah, don't worry about it, it's intended behaviour that the time-sync target doesn't mean that time is synced"[2]. But that did get fixed a couple years ago [3].)
[1] https://github.com/systemd/systemd/issues/5097 https://github.com/systemd/systemd/issues/5097
[2] https://github.com/systemd/systemd/issues/5097#issuecomment-276787961 https://github.com/systemd/systemd/issues/5097#issuecomment-...
[3] https://github.com/systemd/systemd/pull/8494 https://github.com/systemd/systemd/pull/8494
- admax88q 6y agoThats a pretty uncharitable take on what Poettering said. IMO hes right that in many cases you dont want to hold up booting on whether or not time has been synced. I dont want my desktop, or most servers to not boot if the network or NTP server is down. He also suggests what they can add for people who want this behaviour. Oh woe is me that systemd does not support my use case of an embedded system needing to verify disk image with accurate time before booting further, as the _default_.