STIGQter STIGQter: STIG Summary: Solaris 10 SPARC Security Technical Implementation Guide Version: 2 Release: 2 Benchmark Date: 22 Jan 2021:

The system must use at least two time sources for clock synchronization.

DISA Rule

SV-226436r603265_rule

Vulnerability Number

V-226436

Group Title

SRG-OS-000355

Rule Version

GEN000242

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Add an additional server line to /etc/inet/ntp.conf for each additional NTP server.

Check Contents

Determine the zone that you are currently securing.

# zonename

If the command output is not "global", this is not applicable.

Check the NTP daemon configuration for at least two external servers.
# grep '^server' /etc/inet/ntp.conf | egrep -v '(127.127.1.1|127.127.1.0)'
If less than two servers or external reference clocks (127.127.x.x other than 127.127.1.0 or 127.127.1.1) are listed, this is a finding.

Vulnerability Number

V-226436

Documentable

False

Rule Version

GEN000242

Severity Override Guidance

Determine the zone that you are currently securing.

# zonename

If the command output is not "global", this is not applicable.

Check the NTP daemon configuration for at least two external servers.
# grep '^server' /etc/inet/ntp.conf | egrep -v '(127.127.1.1|127.127.1.0)'
If less than two servers or external reference clocks (127.127.x.x other than 127.127.1.0 or 127.127.1.1) are listed, this is a finding.

Check Content Reference

M

Target Key

4060

Comments