Let’s Encrypt has transitioned to the NTP server ntpd-rs, written in the Rust programming language.

The nonprofit certificate authority Let's Encrypt, community-controlled and providing certificates at no cost to all, has announced its transition to using the NTP server ntpd-rs, written in Rust with a focus on security and stability. The project is distributed under Apache 2.0 and MIT licenses, fully supports NTP and NTS (Network Time Security) protocols at both client and server levels, and can serve as a replacement for NTP servers like chrony, ntpd, and NTPsec.

The ntpd-rs package was developed within the Prossimo project, which operates under the aegis of the ISRG (Internet Security Research Group), the founding organization of Let's Encrypt, and promotes HTTPS along with the development of technologies to enhance internet security. In addition to ntpd-rs, the project is also developing the TLS library Rustls, the DNS server Hickory, the reverse proxy River, the utility sudo-rs, and components for the Linux kernel in Rust.

The use of ntpd-rs is expected to enhance the security of Let's Encrypt's infrastructure and reduce the likelihood of vulnerabilities caused by memory management errors. Furthermore, the security and reliability of precise time synchronization systems are crucial, as attackers manipulating the system time can exploit this to compromise time-sensitive protocols, such as TLS. For instance, altering the time can lead to misinterpretation of event data. for TLS certificates.

The certificate authority Let's Encrypt issues over four million new certificates daily. The number of active certificates stands at 372 million (each certificate is valid for three months). These certificates cover more than 128 million registered domains and 428 million fully qualified domain names (FQDN). In April, ntpd-rs was deployed in a test environment at Let's Encrypt, and it has now been transitioned to the primary operational systems. Let's Encrypt plans to continue its implementation of systems written in Rust, particularly aiming to replace OpenSSL with Rustls. domain names The aim is to implement Hickory as the DNS server, replace Nginx with River, and substitute sudo with sudo-rs.
The nonprofit certificate authority Let's Encrypt, community-controlled and providing certificates at no cost to all, has announced its transition to using the NTP server ntpd-rs, written in Rust.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster