2.3.1.2 Set 'ntp authentication-key'

Information

Define an authentication key for Network Time Protocol (NTP).

Rationale:

Using an authentication key provides a higher degree of security as only authenticated NTP servers will be able to update time for the Cisco device.

Solution

Configure at the NTP key ring and encryption key using the following command


hostname(config)#ntp authentication-key {ntp_key_id} md5 {ntp_key_hash}

Impact:

Organizations should establish three Network Time Protocol (NTP) hosts to set consistent time across the enterprise. Enabling the 'ntp authentication-key' command enforces encrypted authentication between NTP hosts.

Default Value:

No authentication key is defined for NTP.

References:

http://www.cisco.com/en/US/docs/ios-xml/ios/bsm/command/bsm-cr-n1.html#GUID-0435BFD1-D7D7-41D4-97AC-7731C11226BC

See Also

https://workbench.cisecurity.org/files/2585

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-2(1), CSCv6|6.1

Plugin: Cisco

Control ID: 7dbaa33391bdfca806896278e405e5315d8c3783953c755c8676cdaff908dfb7