2.1.4.3 Ensure ntp is running as user ntp

Information

The ntp package is installed with a dedicated user account ntp This account is granted the access required by the ntpd daemon

Note:

- If chrony or systemd-timesyncd are used, ntp should be removed and this section skipped
- This recommendation only applies if ntp is in use on the system
- Only one time synchronization method should be in use on the system

The ntpd daemon should run with only the required privlidge

Solution

Add or edit the following line in /usr/lib/ntp/ntp-systemd-wrapper :

RUNASUSER=ntp

Run the following command to restart ntp.servocee :

# systemctl restart ntp.service

OR

If another time synchronization service is in use on the system, run the following command to remove ntp from the system:

# apt purge ntp

See Also

https://workbench.cisecurity.org/benchmarks/13007

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-7, 800-53|AU-8, CSCv7|6.1

Plugin: Unix

Control ID: 33ecbd71995cae4f90151a0d8414b1819fc4632146a48f0a774918b6c6dd24e4