3 ms·
That's the point, if you can't trust the connection, stop trying to come up with more complicated ways to use the untrustable connection and accept that there i
by yetanotherloss 3y ago
That's the point, if you can't trust the connection, stop trying to come up with more complicated ways to use the untrustable connection and accept that there is no safe way to update time.
- deepsun 3y agoOk, so the system should fail to boot, right?
- yetanotherloss 3y agoIf for some reason an invalid time causes boot failure? Sure. There are some instrumented devices I work with that will alarm and cease operation if they lose their serial connection to a satellite clock, but those are few and far between. But since the vast majority of them do not fail in that matter if the normal, configured methods of determining time aren't working, using TLS parameters that have been deliberately randomized by standard for like what, a decade now?, can not possibly be a more straightforward failure mode than logging errors and waiting for operator input. If it's that critically important, embed a fixed signature for a set of known time sources and query those as a last resort. Microsoft certainly has the resources to set up a few to do this the much more obvious and predictable way.
- oskarw85 3y agoThat means your server could not serve HTTPS traffic at all, because you need valid timestamp for that.