2.3.1.2 Set 'ntp authentication-key'

Information

Define an authentication key for Network Time Protocol (NTP).

Using an authentication key provides a higher degree of security as only authenticated NTP servers will be able to update time for the Cisco device.

Solution

Configure at the NTP key ring and encryption key using the following command

hostname(config)#ntp authentication-key {ntp_key_id} md5 {ntp_key_hash}

Impact:

Organizations should establish three Network Time Protocol (NTP) hosts to set consistent time across the enterprise. Enabling the 'ntp authentication-key' command enforces encrypted authentication between NTP hosts.

See Also

https://workbench.cisecurity.org/benchmarks/12917

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-7, 800-53|AU-8, CSCv7|6.1

Plugin: Cisco

Control ID: 06df304b7b47d895affe2ebb4b1400b84bda5c2495bde59a515b633d6dc59d67