Ubuntu 25.10 defaults to Chrony instead of systemd-timesyncd.

The developers of Ubuntu Linux have planned to transition to using the Chrony project for precise time synchronization in all Ubuntu 25.10 builds by default. Previously, Ubuntu used the systemd-timesyncd service, which is set to be replaced in favor of leveraging the NTS (Network Time Security) protocol for cryptographic protection of time synchronization.

The Chrony project provides an independent implementation of the NTP client and server, already employed for precise time synchronization in Fedora, SUSE/openSUSE, and RHEL. NTS ensures that the client interacts with the target NTP server rather than a spoofed one. Spoofing an NTP server poses risks, as setting incorrect time can be used to compromise the security of other time-sensitive protocols, such as TLS and DNSSEC. Time alteration can lead to misinterpretation of certificate validity data.

The NTS protocol uses elements of public key infrastructure (PKI) to establish an encrypted communication channel, allowing the use of TLS and authenticated encryption AEAD (Authenticated Encryption with Associated Data) to protect users from attacks mimicking an NTP server. NTS consists of two separate protocols: NTS-KE (NTS Key Establishment), which handles initial authentication and key agreement over TLS, and NTS-EF (NTS Extension Fields), responsible for encrypting and authenticating the time synchronization session. NTS adds several extended fields to the NTP packets and keeps all state information only on the client side using a cookie-passing mechanism. The NTS protocol operates over network port 4460.

The Chrony package is already included in the main repository and is used by default in some Ubuntu editions for cloud systems. The transition from systemd-timesyncd to Chrony will begin on June 2. Including Chrony in builds will introduce an additional dependency on ‘libedit2’ and increase the image size by 803 KB. To replace systemd-timesyncd with Chrony in Ubuntu 25.04, use the command ‘apt-mark auto systemd-timesyncd && apt install chrony’, and to revert to systemd-timesyncd, use ‘apt-mark auto chrony && apt install systemd-timesyncd’.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster