Release of the NTP Server NTPsec 1.2.4

After more than a year of development, the release of the NTPsec time synchronization server 1.2.4 has been published. The project was created as a fork of the reference implementation of the NTPv4 protocol (NTP Classic 4.3.34), focused on restructuring the codebase to enhance security. The NTPsec source code is distributed under BSD, MIT, and NTP licenses.

NTPsec is developed under the guidance of Eric Raymond with the involvement of some developers from the original NTP Classic, engineers from Hewlett Packard and Akamai Technologies, as well as the GPSD and RTEMS projects. Key differences from NTP Classic include the addition of support for the NTS (Network Time Security) protocol, a reduction in the codebase size by more than half (removing outdated features and unnecessary platforms), implementation of an offline mode, use of attack prevention methods (such as system call filtering), and a shift to secure functions for memory and string handling.

In the new version:

  • An 'extra port xxxx' setting has been added to receive requests on an additional network port, besides the primary port configured via 'nts port xxxx'. The additional port may be useful for bypassing blocks on accessing external NTP servers set by firewalls.
  • Added support for building on Linux systems with armhf architecture.
  • Support for running ntpd on FIPS mode systems has been ensured.
  • The Waf build system has been updated to version 2.1.4. In Debian, the installation of utilities written in Python, such as ntpq and ntpmon, now occurs in the '/usr/local/lib/python3.xx/site-packages' directory instead of '/usr/local/lib/python3.xx/dist-packages'. The 'waf install' command now includes testing of installed executables, and through the 'waf configure --enable-Werror' command, it is now possible to treat compiler warnings as errors.
  • The minimum version of Python specified is release 2.7. Support for Python 2 is planned to be discontinued in the next version.
  • By default, the '--disable-fuzz' option has been applied, disabling the 'Clock fuzzing' mechanism (which introduces millisecond random offsets to the time provided to clients, not affecting overall accuracy but preventing attackers from predicting the actual time value).
  • Code remnants related to operation in broadcast and multicast modes have been removed.
  • In ntpdig, an option has been added to bind to the specified IP address.
  • The NTS-KE configuration now includes an option to set the preferred encryption algorithms for TLS.
  • The ntp_gettime call has been used instead of ntp_adjtime.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster