6.4 Securing Time Service NTP
The time service NTP provides an authenticated and integrity secured packet transmission. Currently, NTP
autokey is considered to be not as secure as the symmetric key procedure. Therefore, this guide will use
the symmetric key configuration. The chapter "LTOS Management and Monitoring
→
Via Web GUI
→
" describes all configuration options in detail.
To configure a connection, the system needs a key. Either use newly generated or add existing keys in the key
file over the button Edit NTP Keys under "NTP
→
NTP Symmetric Keys". If you automatically generate the
keys by the system, MD5 and SHA1 keys will exist in the key file. However, for the highest security currently
available, AES128-CMAC keys have to be used. These cannot be generated automatically yet.
Figure
shows example keys. The key IDs have to be added to the trusted keys on "General Settings"
menu point of NTP tab (see Figure
). On "NTP Restrictions" menu you can deactivate mode 6 and 7 packet
support. Optionally, activate access restriction here to grant access only to known IP addresses. The symmetric
keys are used for every connection type, i.e. server to client, external NTP server, broadcasting, multicasting
and manycasting.
Figure 6.16: Generated symmetric NTP keys
Figure 6.17: Trusted key IDs
26
Date: 2nd July 2020
LANTIME CPU Expansion Shelf
Summary of Contents for LCES
Page 2: ......