6.1 General Informations
Before starting with the configuration, take a look at
to identify the possible services that can be
configured to be secure.
In general, a secure management of the LANTIME is possible with SSH, HTTPS and SNMP. If the con-
figuration via SNMP is desired, the usage of version 3 is the only way to get a secure connection to manage
the system. It is a good practice to deactivate all services that are not in use, to minimize the attack surface. So
if possible, only enable one of the services (SNMP has not the full configuration support, but you can activate
the other services over SNMP)!
The delivery of secured time information is only available for NTP. Please note, that the NTP protocol only
supports integrity and authenticity but no confidentiality. PTP does not currently support IT security functions.
These are only planned for the next protocol standard. For this reason, you must still use NTP to ensure secure
time synchronization.
Another important advisory is to use the newest browsers and service clients to support the selection of the
best security algorithms for server and client communication. A timely installation of updates can also close
known vulnerabilities and minimize the risk of a successful attack.
Figure 6.2: The secure protocols in detail
18
Date: 2nd July 2020
LANTIME CPU Expansion Shelf
Summary of Contents for LCES
Page 2: ......