2.3.1.4 Set 'key' for each 'ntp server'

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

Specifies the authentication key for NTP.

Rationale:

This authentication feature provides protection against accidentally synchronizing the ntp system to another system that is not trusted, because the other system must know the correct authentication key.

Solution

Configure each NTP Server to use a key ring using the following command.


hostname(config)#ntp server {ntp-server_ip_address}{key ntp_key_id}

Impact:

Organizations should establish three Network Time Protocol (NTP) hosts to set consistent time across the enterprise. Enabling the 'ntp server key' command enforces encrypted authentication between NTP hosts.

Default Value:

No NTP key is set by default

See Also

https://workbench.cisecurity.org/files/2585

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-8(1), 800-53|AU-8(2), CSCv6|6.1

Plugin: Cisco

Control ID: 7309a6e77eaee6d36144207521c83dc54d1edfab1a971b1113a6c7bb995ba78e