2.2.1.3 Ensure chrony is configured

Information

chrony is a daemon which implements the Network Time Protocol (NTP) and is designed to synchronize system clocks across a variety of systems and use a source that is highly accurate. More information on chrony can be found at:

http://chrony.tuxfamily.org/

. chrony can be configured to be a client and/or a server.

If chrony is in use on the system proper configuration is vital to ensuring time synchronization is working properly.

Note: This recommendation only applies if chrony is in use on the system. If another method of time synchronization is in use on the system, this recommendation can be skipped.

Solution

Add or edit server or pool lines to /etc/chrony.conf as appropriate:

server <remote-server>

Add or edit the OPTIONS in /etc/sysconfig/chronyd to include ' -u chrony ':

OPTIONS="-u chrony"

See Also

https://workbench.cisecurity.org/files/3682

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-7, 800-53|AU-8, CSCv7|6.1

Plugin: Unix

Control ID: 49d0e4acbf4920c2b96b9b5a18dddf1b1613a77c9dd91f06541dacf8d4e18730