3 ms·
how does this relate to alternative implementations like openNTPd ? this guy maintains the reference implementation of the protocol I guess ?
by tech-no-logical 12y ago
how does this relate to alternative implementations like openNTPd ? this guy maintains the reference implementation of the protocol I guess ?
- noselasd 12y agontpd (http://www.ntp.org/ http://www.ntp.org/) is the reference implementation.
- slasaus 12y agoFrom [1] I get that PHK decided not to use privilege separation because it's not portable enough. AFAIK that's one of the main differences between OpenNTPD and Ntimed. Well, that and precision of course. OpenNTPDs accuracy is "only" around milliseconds [2] (which is probably good enough for anyone not using dedicated time hardware like a stratum server). The portable version missed the frequency adjustment code for years, but recently this has been added to the portable version as well. I've also read a discussion with PHK somewhere that he didn't like OpenNTPD because it had no auth (sorry, can't find the source again). I guess this complaint has been mitigated recently now that TLS auth is supported in OpenNTPD [3]. /edit: not sure if it's clear but I was comparing OpenNTPD to Ntimed. But the named differences still exist when compared to ntp4. [1] http://phk.freebsd.dk/_downloads/FOSDEM_2015.pdf http://phk.freebsd.dk/_downloads/FOSDEM_2015.pdf page 13 and 14 [2] http://www.bsdnow.tv/episodes/2015_02_11-time_for_a_change http://www.bsdnow.tv/episodes/2015_02_11-time_for_a_change at 30:30 and 34:00 [3] http://undeadly.org/cgi?action=article&sid=20150210103656 http://undeadly.org/cgi?action=article&sid=20150210103656
- floatboth 12y agontimed is a weird project IMO, because it's not different enough from OpenNTPD: both are small NTP daemons written in C. He could've created a fork of OpenNTPD with more precision and without privilege separation instead. If ntimed was written in Rust though... THAT would've been excellent.
- gpvos 12y agoOpenNTPD is only a client. ntimed is currently only a client, but is intended to grow to a complete replacement of ntpd.
- slasaus 12y agoThat is not true. OpenNTPD is a server as well. Just put the following line in your /etc/ntpd.conf: listen on * See ntpd.conf(5) for all options: http://www.openbsd.org/cgi-bin/man.cgi/OpenBSD-current/man5/ntpd.conf.5?query=ntpd.conf/man5/ntpd.conf.5?query=ntpd.conf http://www.openbsd.org/cgi-bin/man.cgi/OpenBSD-current/man5/...
- feld 12y ago> I've also read a discussion with PHK somewhere that he didn't like OpenNTPD > because it had no auth (sorry, can't find the source again). I guess this > complaint has been mitigated recently now that TLS auth is supported in > OpenNTPD [3]. That's a completely new invention. It is not compatible with the NTP auth as specified in NTPv4 which uses a public key mechanism to ensure the NTP packets are not being spoofed. Instead, this is just pointing your NTP server at an HTTPS server you trust so it can use the timestamps returned in the TLS packets as another highly trusted time source to make sure spoofed NTP packets can't skew your time. It's clever, that's for sure.