Kuburitswa kwemaseva eNTP NTPsec 1.2.0 uye Chrony 4.0 nerutsigiro rweiyo yakachengeteka NTS protocol.

Iyo IETF (Internet Engineering Task Force) komiti, iyo inovandudza Internet protocol uye zvivakwa, kupera kuumbwa kweRFC yeNTS (Network Time Security) protocol uye yakaburitsa iyo yakabatana yakatarwa pasi pechiziviso. RFC 8915. Iyo RFC yakagamuchira chimiro che "Proposed Standard", mushure mezvo basa richatanga kupa RFC mamiriro eiyo dhizaini mwero (Draft Standard), izvo zvinoreva kudzikamisa kwakakwana kweprotocol uye kufunga nezvese zvataurwa.

Kumisikidza NTS inhanho yakakosha yekuvandudza chengetedzo yenguva yekuyananisa masevhisi uye kudzivirira vashandisi kubva pakurwiswa kunotevedzera sevha yeNTP iyo mutengi anobatana nayo. Kubata kwevanorwisa kuisa nguva isiriyo kunogona kushandiswa kukanganisa kuchengetedzeka kwemamwe maprotocol anoziva nguva, seTLS. Semuyenzaniso, kushandura nguva kunogona kutungamirira mukududzirwa zvisizvo kwedata nezve huchokwadi hwezvitupa zveTLS. Kusvika ikozvino, NTP uye symmetric encryption yenzira dzekutaurirana hazvina kuita kuti zvikwanisike kuvimbisa kuti mutengi anopindirana nechinangwa uye kwete spoofed NTP server, uye kiyi yechokwadi haina kupararira nekuti yakanyanya kuomarara kugadzirisa.

NTS inoshandisa zvinhu zveruzhinji kiyi zvivakwa (PKI) uye inobvumira kushandiswa kweTLS neAEAD (Authenticated Encryption with Associated Data) encryption kuti cryptographically kudzivirira mutengi-server kudyidzana vachishandisa NTP (Network Time Protocol). NTS inosanganisira maviri akapatsanurwa maprotocol: NTS-KE (NTS Kiyi Kugadzwa kwekubata kwekutanga kutendeseka uye kiyi nhaurirano pamusoro peTLS) uye NTS-EF (NTS Extension Fields, ine basa rekunyorera uye kutendeseka kweiyo nguva yekuyananisa chikamu). NTS inowedzera akati wandei akatambanudzwa kumapaketi eNTP uye inochengeta ruzivo rwese rwenyika chete kudivi remutengi uchishandisa cookie mechanism. Network port 4460 yakagoverwa kugadzirisa zvinongedzo kuburikidza neNTS protocol.

Kuburitswa kwemaseva eNTP NTPsec 1.2.0 uye Chrony 4.0 nerutsigiro rweiyo yakachengeteka NTS protocol.

Kuitwa kwekutanga kweiyo yakamisikidzwa NTS kunotsanangurwa mukuburitswa kwazvino kuburitswa NTPsec 1.2.0 ΠΈ Chrony 4.0. Chrony inopa yakazvimiririra yeNTP mutengi uye kusetwa kwesevha iyo inoshandiswa kuwiriranisa nguva pane dzakasiyana siyana dzeLinux kugovera, kusanganisira Fedora, Ubuntu, SUSE/openSUSE, uye RHEL/CentOS. NTPsec inovandudza pasi pehutungamiriri hwaEric S. Raymond uye iforogo yereferensi yekushandiswa kweNTPv4 protocol (NTP Classic 4.3.34), yakatarisana nekugadzirisazve nheyo yekodhi kuitira kuvandudza kuchengeteka (kodha yakasakara yakacheneswa, nzira dzekudzivirira kurwisa uye mabasa akachengetedzwa ekushanda nendangariro uye tambo).

Source: opennet.ru

Voeg