SV-226434r603265_rule
V-226434
SRG-OS-000355
GEN000240
CAT II
10
Use a local authoritative time server synchronizing to an authorized DoD time source. Ensure all systems in the facility feed from one or more local time servers that feed from the authoritative time server.
NTP must be used and used only in the global zone. Determine the zone that you are currently securing.
# zonename
If the command output is not "global", NTP must be disabled. Check the system for a running NTP daemon.
# svcs ntp | grep online
If the output from "zonename" is "global", NTP must be enabled. Check the system for a running NTP daemon.
# svcs ntp | grep online
If NTP is not online, this is a finding.
If NTP is running confirm the servers and peers or multicast client (as applicable) are local or an authoritative U.S. DoD source.
# more /etc/inet/ntp.conf
If a non-local/non-authoritative (U.S. DoD source) time-server is used, this is a finding.
V-226434
False
GEN000240
NTP must be used and used only in the global zone. Determine the zone that you are currently securing.
# zonename
If the command output is not "global", NTP must be disabled. Check the system for a running NTP daemon.
# svcs ntp | grep online
If the output from "zonename" is "global", NTP must be enabled. Check the system for a running NTP daemon.
# svcs ntp | grep online
If NTP is not online, this is a finding.
If NTP is running confirm the servers and peers or multicast client (as applicable) are local or an authoritative U.S. DoD source.
# more /etc/inet/ntp.conf
If a non-local/non-authoritative (U.S. DoD source) time-server is used, this is a finding.
M
4060