Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #181878 > unrolled thread

NTP.conf pool vs server

Started byray <ray@aarden.us>
First post2017-06-07 15:20 +0200
Last post2017-06-07 17:00 +0200
Articles 20 on this page of 43 — 19 participants

Back to article view | Back to linux.debian.user


Contents

  NTP.conf   pool vs server ray <ray@aarden.us> - 2017-06-07 15:20 +0200
    Re: NTP.conf   pool vs server Greg Wooledge <wooledg@eeg.ccf.org> - 2017-06-07 15:30 +0200
      Re: NTP.conf   pool vs server Gene Heskett <gheskett@shentel.net> - 2017-06-07 16:50 +0200
    Re: NTP.conf   pool vs server Gene Heskett <gheskett@shentel.net> - 2017-06-07 16:40 +0200
      Re: NTP.conf   pool vs server Greg Wooledge <wooledg@eeg.ccf.org> - 2017-06-07 17:00 +0200
      Re: NTP.conf   pool vs server Darac Marjal <mailinglist@darac.org.uk> - 2017-06-07 17:00 +0200
        Re: NTP.conf   pool vs server Greg Wooledge <wooledg@eeg.ccf.org> - 2017-06-07 17:10 +0200
          Re: NTP.conf pool vs server Joshua Schaeffer <jschaeffer0922@gmail.com> - 2017-06-07 17:30 +0200
            Re: NTP.conf pool vs server Greg Wooledge <wooledg@eeg.ccf.org> - 2017-06-07 17:50 +0200
          Re: NTP.conf   pool vs server Henrique de Moraes Holschuh <hmh@debian.org> - 2017-06-07 18:10 +0200
        Re: NTP.conf   pool vs server Darac Marjal <mailinglist@darac.org.uk> - 2017-06-07 17:20 +0200
        Re: NTP.conf   pool vs server Gene Heskett <gheskett@shentel.net> - 2017-06-08 01:10 +0200
          Re: NTP.conf   pool vs server Darac Marjal <mailinglist@darac.org.uk> - 2017-06-08 14:30 +0200
            Re: https_port "Adiel Plasencia Herrera" <adielp@estereocentro.icrt.cu> - 2017-06-08 14:50 +0200
              Re: https_port Darac Marjal <mailinglist@darac.org.uk> - 2017-06-08 15:30 +0200
                Re: https_port Henrique de Moraes Holschuh <hmh@debian.org> - 2017-06-08 17:00 +0200
                  Re: https_port "Adiel Plasencia Herrera" <adielp@estereocentro.icrt.cu> - 2017-06-08 17:20 +0200
                    Re: https_port Darac Marjal <mailinglist@darac.org.uk> - 2017-06-08 17:30 +0200
                      Re: https_port Greg Wooledge <wooledg@eeg.ccf.org> - 2017-06-08 17:40 +0200
                        Re: https_port Darac Marjal <mailinglist@darac.org.uk> - 2017-06-08 17:50 +0200
                          Re: https_port "Adiel Plasencia Herrera" <adielp@estereocentro.icrt.cu> - 2017-06-08 18:00 +0200
                            Re: https_port Jim Ohlstein <jim@mailman-hosting.com> - 2017-06-08 19:10 +0200
                            Re: https_port Charlie Kravetz <cjk@teamcharliesangels.com> - 2017-06-09 16:40 +0200
                              Reply-to-all or reply-to-list again (was: https_port) Nicolas George <george@nsup.org> - 2017-06-09 16:50 +0200
                                Re: Reply-to-all or reply-to-list again (was: https_port) Fungi4All <fungilife@protonmail.com> - 2017-06-09 17:20 +0200
                                Re: Reply-to-all or reply-to-list again The Wanderer <wanderer@fastmail.fm> - 2017-06-09 17:20 +0200
                                  Re: Reply-to-all or reply-to-list again Nicolas George <george@nsup.org> - 2017-06-09 18:00 +0200
                                    Re: Reply-to-all or reply-to-list again The Wanderer <wanderer@fastmail.fm> - 2017-06-09 21:20 +0200
                                    Re: Reply-to-all or reply-to-list again Joel Rees <joel.rees@gmail.com> - 2017-06-10 04:20 +0200
                                      Re: Reply-to-all or reply-to-list again Fungi4All <fungilife@protonmail.com> - 2017-06-10 16:00 +0200
                                        Re: Reply-to-all or reply-to-list again Joel Rees <joel.rees@gmail.com> - 2017-06-10 16:30 +0200
                                          Re: Reply-to-all or reply-to-list again Fungi4All <fungilife@protonmail.com> - 2017-06-10 18:00 +0200
                                Re: Reply-to-all or reply-to-list again (was: https_port) Gene Heskett <gheskett@shentel.net> - 2017-06-09 17:30 +0200
            Re: NTP.conf   pool vs server Gene Heskett <gheskett@shentel.net> - 2017-06-08 16:10 +0200
      Re: NTP.conf   pool vs server John Hasler <jhasler@newsguy.com> - 2017-06-07 18:10 +0200
        Re: NTP.conf   pool vs server Brian <ad44@cityscape.co.uk> - 2017-06-07 18:30 +0200
          Re: NTP.conf   pool vs server David Wright <deblis@lionunicorn.co.uk> - 2017-06-11 18:00 +0200
            Re: NTP.conf   pool vs server Brian <ad44@cityscape.co.uk> - 2017-06-11 19:30 +0200
        Re: NTP.conf   pool vs server Teemu Likonen <tlikonen@iki.fi> - 2017-06-08 08:40 +0200
          Re: NTP.conf   pool vs server Curt <curty@free.fr> - 2017-06-08 09:20 +0200
          Re: NTP.conf   pool vs server Gene Heskett <gheskett@shentel.net> - 2017-06-08 15:40 +0200
      Re: NTP.conf   pool vs server Jim Ohlstein <jim@mailman-hosting.com> - 2017-06-07 18:40 +0200
    Re: NTP.conf   pool vs server Kushal Kumaran <kushal@locationd.net> - 2017-06-07 17:00 +0200

Page 1 of 3  [1] 2 3  Next page →


#181878 — NTP.conf pool vs server

Fromray <ray@aarden.us>
Date2017-06-07 15:20 +0200
SubjectNTP.conf pool vs server
Message-ID<tPJ2q-77i-15@gated-at.bofh.it>
I would like to know the correct syntax for entering a server entry for stretch.

All the documentation I find says to list the ntp servers in the file as:
server 0.XX.pool.ntp.org 
server 1.XX.pool.ntp.org 

An example source from 2017 is https://wiki.debian.org/DateTime

When I open /etc/ntp.conf on my new stretch installation, I find this format:
pool 0.debian.pool.ntp.org iburst
pool 1.debian.pool.ntp.org iburst

The latest Debian doc says to start the line with 'server'.
The latest Debian implementation starts the line with 'pool'.

Are these interchangeable?

Additionally, there is a parameter 'iburst' which I did not find in the Debian docs but found at http://doc.ntp.org/4.1.1/confopt.htm


Thanks,
Ray

[toc] | [next] | [standalone]


#181881

FromGreg Wooledge <wooledg@eeg.ccf.org>
Date2017-06-07 15:30 +0200
Message-ID<tPJc6-7aN-23@gated-at.bofh.it>
In reply to#181878
On Wed, Jun 07, 2017 at 05:56:59AM -0700, ray wrote:
> The latest Debian doc says to start the line with 'server'.
> The latest Debian implementation starts the line with 'pool'.
> 
> Are these interchangeable?
> 
> Additionally, there is a parameter 'iburst' which I did not find in the Debian docs but found at http://doc.ntp.org/4.1.1/confopt.htm

For whatever it's worth, "iburst" is in ntp.conf(5) but "pool" is not.

[toc] | [prev] | [next] | [standalone]


#181884

FromGene Heskett <gheskett@shentel.net>
Date2017-06-07 16:50 +0200
Message-ID<tPKrv-7Vi-3@gated-at.bofh.it>
In reply to#181881
On Wednesday 07 June 2017 09:27:19 Greg Wooledge wrote:

> On Wed, Jun 07, 2017 at 05:56:59AM -0700, ray wrote:
> > The latest Debian doc says to start the line with 'server'.
> > The latest Debian implementation starts the line with 'pool'.
> >
> > Are these interchangeable?
> >
> > Additionally, there is a parameter 'iburst' which I did not find in
> > the Debian docs but found at http://doc.ntp.org/4.1.1/confopt.htm
>
> For whatever it's worth, "iburst" is in ntp.conf(5) but "pool" is not.

pool is normally a round robin server setup where any machine in 
the "pool" of machines can answer the query.  Its part of the net 
address, not a keyword to ntp(date). If you ping -c1 pool.ntp.org, 
you'll see the machines address that answered that ping, but you may not 
get a reply from that same machine the next time you ping it.

Cheers, Gene Heskett
-- 
"There are four boxes to be used in defense of liberty:
 soap, ballot, jury, and ammo. Please use in that order."
-Ed Howdershelt (Author)
Genes Web page <http://geneslinuxbox.net:6309/gene>

[toc] | [prev] | [next] | [standalone]


#181883

FromGene Heskett <gheskett@shentel.net>
Date2017-06-07 16:40 +0200
Message-ID<tPKhP-7Rr-5@gated-at.bofh.it>
In reply to#181878
On Wednesday 07 June 2017 08:56:59 ray wrote:

> I would like to know the correct syntax for entering a server entry
> for stretch.
>
> All the documentation I find says to list the ntp servers in the file
> as: server 0.XX.pool.ntp.org
> server 1.XX.pool.ntp.org
>
> An example source from 2017 is https://wiki.debian.org/DateTime
>
> When I open /etc/ntp.conf on my new stretch installation, I find this
> format: pool 0.debian.pool.ntp.org iburst
> pool 1.debian.pool.ntp.org iburst
>
> The latest Debian doc says to start the line with 'server'.
> The latest Debian implementation starts the line with 'pool'.
>
> Are these interchangeable?
>
> Additionally, there is a parameter 'iburst' which I did not find in
> the Debian docs but found at http://doc.ntp.org/4.1.1/confopt.htm
>
>
> Thanks,
> Ray

Begin rant:

From someone who is currently battling a fresh jessie install that didn't 
even come with ntpdate installed, and which using the above format 
in /etc/ntp.conf is still about 12 hours off on an rpi-3.

Installing ntpdate and attempting to start it gets me a no servers found 
message, yet they are defined as discussed above, and the network is 
fully accessible to all other forms of communication.  

That doc on www.ntp.org is nice, but worthless to someone who just wants 
it to work. I have quite a zoo of machines here, and I see little 
advantage to each one banging on a network server, when it needs an 
update.  But does it give even a hint of how to make this machine, or 
heaven forbid, my router, which keeps time via ntp, and which I believe 
has the time broadcast enabled, (its dd-wrt in a buffalo box) into a 
server that the rest of my machines can listen to to get the correct 
time. If I could achieve that, it would reduce the loading on the time 
servers at debian or pool.ntp.org by a factor of 5 or 6 just from my 
home network.

But a manpage that actually tells us how to do that must be sick bird, 
because its not been written yet.  Man page writers please get real, and 
tell us how to do something like getting our home networks all 
synchronized to our routers which can then broadcast it to the rest of 
our network.

Such a scheme can easily keep us on time with any errors within a few 
milliseconds, more than adequate enough for the girls I go with. While 
reducing the load on the servers by at least 80%.

So how about a manpage that tells us how to do that?  If its not illegal 
according to some rfc that is.

Rant off.

Thanks for reading.

Cheers, Gene Heskett
-- 
"There are four boxes to be used in defense of liberty:
 soap, ballot, jury, and ammo. Please use in that order."
-Ed Howdershelt (Author)
Genes Web page <http://geneslinuxbox.net:6309/gene>

[toc] | [prev] | [next] | [standalone]


#181885

FromGreg Wooledge <wooledg@eeg.ccf.org>
Date2017-06-07 17:00 +0200
Message-ID<tPKBd-7Z0-37@gated-at.bofh.it>
In reply to#181883
On Wed, Jun 07, 2017 at 10:35:23AM -0400, Gene Heskett wrote:
> Begin rant:
> 
> From someone who is currently battling a fresh jessie install that didn't 
> even come with ntpdate installed, and which using the above format 
> in /etc/ntp.conf is still about 12 hours off on an rpi-3.

The ntpdate package has been deprecated for some time now, in Debian.
You don't need it.  Simply install the ntp package, and configure the
/etc/ntp.conf file (which admittedly is not clearly documented).

Current versions of Debian have folded the ntpdate functionality into
ntp.  The /etc/default/ntp file has (or should have!) this:

NTPD_OPTS='-g'

This starts ntpd with the -g option, which tells it that it's allowed
to slam the clock forward or backward exactly once when it starts up,
mimicking what ntpdate used to do.

> Installing ntpdate and attempting to start it gets me a no servers found 
> message, yet they are defined as discussed above, and the network is 
> fully accessible to all other forms of communication.  

Sounds like something is misconfigured, though we can't tell what it is
without additional info.

> But a manpage that actually tells us how to do that must be sick bird, 
> because its not been written yet.  Man page writers please get real, and 
> tell us how to do something like getting our home networks all 
> synchronized to our routers which can then broadcast it to the rest of 
> our network.

On the machine that you want to act as your local network's time server:

server 0.debian.pool.ntp.org iburst
server 1.debian.pool.ntp.org iburst
server 2.debian.pool.ntp.org iburst
server 3.debian.pool.ntp.org iburst

And make sure you didn't change the lines under the comment that says
"By default, exchange time with everybody, but don't allow configuration."

On your other machines:

server your.time.server

That's basically it.  Make sure the hostname is resolvable.  If you have
issues with name resolution not being available sometimes, then you might
want to add your.time.server to /etc/hosts.

To verify that things are running, use ntpq -p:

svr5:~$ ntpq -p
     remote           refid      st t when poll reach   delay   offset  jitter
==============================================================================
-104.245.32.240  162.213.2.253    2 u  776 1024  377   80.415   -8.341   0.239
*clocka.ntpjs.or 18.26.4.105      2 u  250 1024  377    9.780    0.361   0.556
+up2.com         195.219.14.21    2 u  490 1024  377   31.761   -1.224   0.474
+jarvis.arlen.io 17.253.2.253     2 u  477 1024  377   36.764   -2.368   4.547

And that's why you use multiple public time servers -- they aren't very
accurate, so you need lots of them.  The daemon can decide which ones
to ignore, and so on.

The output of this -p thing is not documented, so you have to guess what
it means.  I think the "-" in column 1 means "this server sucks, so I'm
not really paying attention to it", and "+" means "pretty good", and "*"
means "this is my favorite".  But that's just a guess.  There's nothing
in the ntpq man page about it at all.

[toc] | [prev] | [next] | [standalone]


#181887

FromDarac Marjal <mailinglist@darac.org.uk>
Date2017-06-07 17:00 +0200
Message-ID<tPKBf-7Z0-79@gated-at.bofh.it>
In reply to#181883

[Multipart message — attachments visible in raw view] — view raw

On Wed, Jun 07, 2017 at 10:35:23AM -0400, Gene Heskett wrote:
>On Wednesday 07 June 2017 08:56:59 ray wrote:
>
>> I would like to know the correct syntax for entering a server entry
>> for stretch.
>>
>> All the documentation I find says to list the ntp servers in the file
>> as: server 0.XX.pool.ntp.org
>> server 1.XX.pool.ntp.org
>>
>> An example source from 2017 is https://wiki.debian.org/DateTime
>>
>> When I open /etc/ntp.conf on my new stretch installation, I find this
>> format: pool 0.debian.pool.ntp.org iburst
>> pool 1.debian.pool.ntp.org iburst
>>
>> The latest Debian doc says to start the line with 'server'.
>> The latest Debian implementation starts the line with 'pool'.
>>
>> Are these interchangeable?

As I understand it "server" will do name resolution once and pick an IP
from the result. "pool" will periodically refresh the name and cycle to
a different member of the pool.

>>
>> Additionally, there is a parameter 'iburst' which I did not find in
>> the Debian docs but found at http://doc.ntp.org/4.1.1/confopt.htm

Did you install ntp-doc? Did you check there?

>>
>>
>> Thanks,
>> Ray
>
>Begin rant:
>
>From someone who is currently battling a fresh jessie install that didn't
>even come with ntpdate installed, and which using the above format
>in /etc/ntp.conf is still about 12 hours off on an rpi-3.
>
>Installing ntpdate and attempting to start it gets me a no servers found
>message, yet they are defined as discussed above, and the network is
>fully accessible to all other forms of communication.
>
>That doc on www.ntp.org is nice, but worthless to someone who just wants
>it to work. I have quite a zoo of machines here, and I see little
>advantage to each one banging on a network server, when it needs an
>update.  But does it give even a hint of how to make this machine, or
>heaven forbid, my router, which keeps time via ntp, and which I believe
>has the time broadcast enabled, (its dd-wrt in a buffalo box) into a
>server that the rest of my machines can listen to to get the correct
>time. If I could achieve that, it would reduce the loading on the time
>servers at debian or pool.ntp.org by a factor of 5 or 6 just from my
>home network.

By a factor of 5 or 6? You think you own 5 or 6 times more servers than
everyone else combined? (I think you just mean "reduce [...] by 5 or
6").

Does your router inform other devices on the network that it should be
used as a time server? In the DHCP specification there is an option
called "time-servers". The idea is that a network administrator sets
this to be the approved time servers for the network and clients
synchronise to that. In debian, this is facilitated by
/etc/dchp/dhclient-exit-hooks.d/ntp (at least, if you use the ISC DHCP
client). That script will read the "time-servers" option from the DHCP
packet, write /var/lib/ntp/ntp.conf.dhcp and ensure that file is
included from your main ntp.conf. As far as I'm aware, this is default
behaviour.

>
>But a manpage that actually tells us how to do that must be sick bird,
>because its not been written yet.  Man page writers please get real, and
>tell us how to do something like getting our home networks all
>synchronized to our routers which can then broadcast it to the rest of
>our network.

There's an XY problem here. You probably shouldn't put this information
into the NTP man pages, as it's not NTP that's doing the work. The
information about the "time-servers" option *is* in the DHCP manpage,
but probably there's no information about the specific hook being
included.

If the NTP hook is Debian-specific, then... I don't know where that
should be documented. If it's upstream, then... Well, if every project
documented every decision for creating every file, then there'd be a lot
to wade through.

>
>Such a scheme can easily keep us on time with any errors within a few
>milliseconds, more than adequate enough for the girls I go with. While
>reducing the load on the servers by at least 80%.
>
>So how about a manpage that tells us how to do that?  If its not illegal
>according to some rfc that is.
>
>Rant off.
>
>Thanks for reading.
>
>Cheers, Gene Heskett
>-- 
>"There are four boxes to be used in defense of liberty:
> soap, ballot, jury, and ammo. Please use in that order."
>-Ed Howdershelt (Author)
>Genes Web page <http://geneslinuxbox.net:6309/gene>
>

-- 
For more information, please reread.

[toc] | [prev] | [next] | [standalone]


#181888

FromGreg Wooledge <wooledg@eeg.ccf.org>
Date2017-06-07 17:10 +0200
Message-ID<tPKKS-8hH-19@gated-at.bofh.it>
In reply to#181887
On Wed, Jun 07, 2017 at 03:54:26PM +0100, Darac Marjal wrote:
> As I understand it "server" will do name resolution once and pick an IP
> from the result. "pool" will periodically refresh the name and cycle to
> a different member of the pool.

Really?  Why isn't this documented?  Is it simply urban legend passed
from user to user?

I largely agree with Gene.  The man pages are incredibly silly.  They
don't tell you how to do the Most Basic Common Thing.  Instead they
talk about "type s and r addresses" and "a preemptable association
is mobilized" and "mobilizes a persistent  symmetric-active  mode
association" and "type b and m addresses" and other such gibberish.

I guess Ill try changing one of my intranet time servers from "server"
to "pool" and see what happens.

[toc] | [prev] | [next] | [standalone]


#181890 — Re: NTP.conf pool vs server

FromJoshua Schaeffer <jschaeffer0922@gmail.com>
Date2017-06-07 17:30 +0200
SubjectRe: NTP.conf pool vs server
Message-ID<tPL4e-8ou-9@gated-at.bofh.it>
In reply to#181888

[Multipart message — attachments visible in raw view] — view raw

On Wed, Jun 7, 2017 at 9:06 AM, Greg Wooledge <wooledg@eeg.ccf.org> wrote:

> I largely agree with Gene.  The man pages are incredibly silly.  They
> don't tell you how to do the Most Basic Common Thing.  Instead they
> talk about "type s and r addresses" and "a preemptable association
> is mobilized" and "mobilizes a persistent  symmetric-active  mode
> association" and "type b and m addresses" and other such gibberish.
>

That is one of the ideas behind the info pages. Man pages have always been
technically oriented and are generally very focused. They don't really
offer context. Now, I'm not saying that info pages accomplish this (some
do, some don't), but that was one of the original ideas behind info pages,
is to be more real world and comprehensive. There are trade offs to both
approaches.

You typically get a dichotomy of groups about man pages and documentation
in general. Some people prefer the more technical nature of the man pages,
while others find it frustrating. Can be further exacerbated by the fact
that people tell other people to RTFM, but even reading a man page top to
bottom doesn't help when it actually comes to setting up a piece of
software (as you probably experienced yourself).

In general man pages are more helpful when you already understand the
software in question and are looking for specific information.

Thanks,
Joshua Schaeffer

[toc] | [prev] | [next] | [standalone]


#181891 — Re: NTP.conf pool vs server

FromGreg Wooledge <wooledg@eeg.ccf.org>
Date2017-06-07 17:50 +0200
SubjectRe: NTP.conf pool vs server
Message-ID<tPLnA-8w9-11@gated-at.bofh.it>
In reply to#181890
Hey look, there's already a bug open:

<https://bugs.debian.org/803709> "ntp: Please document 'pool' in ntp.conf"

Filed November 1, 2015.

Except... it's not open.  It's been closed.  They sat on it for two
years until the stretch freeze, and then "fixed" it in experimental.
So we won't even get it in stretch.

[toc] | [prev] | [next] | [standalone]


#181892

FromHenrique de Moraes Holschuh <hmh@debian.org>
Date2017-06-07 18:10 +0200
Message-ID<tPLGW-rD-11@gated-at.bofh.it>
In reply to#181888
On Wed, 07 Jun 2017, Greg Wooledge wrote:
> On Wed, Jun 07, 2017 at 03:54:26PM +0100, Darac Marjal wrote:
> > As I understand it "server" will do name resolution once and pick an IP
> > from the result. "pool" will periodically refresh the name and cycle to
> > a different member of the pool.
> 
> Really?  Why isn't this documented?  Is it simply urban legend passed

It is.  In the full documentation, package ntp-doc.

-- 
  Henrique Holschuh

[toc] | [prev] | [next] | [standalone]


#181889

FromDarac Marjal <mailinglist@darac.org.uk>
Date2017-06-07 17:20 +0200
Message-ID<tPKUx-8kV-5@gated-at.bofh.it>
In reply to#181887

[Multipart message — attachments visible in raw view] — view raw

On Wed, Jun 07, 2017 at 03:54:26PM +0100, Darac Marjal wrote:
>On Wed, Jun 07, 2017 at 10:35:23AM -0400, Gene Heskett wrote:
>>On Wednesday 07 June 2017 08:56:59 ray wrote:
>>
>>>I would like to know the correct syntax for entering a server entry
>>>for stretch.
>>>
>>>All the documentation I find says to list the ntp servers in the file
>>>as: server 0.XX.pool.ntp.org
>>>server 1.XX.pool.ntp.org
>>>
>>>An example source from 2017 is https://wiki.debian.org/DateTime
>>>
>>>When I open /etc/ntp.conf on my new stretch installation, I find this
>>>format: pool 0.debian.pool.ntp.org iburst
>>>pool 1.debian.pool.ntp.org iburst
>>>
>>>The latest Debian doc says to start the line with 'server'.
>>>The latest Debian implementation starts the line with 'pool'.
>>>
>>>Are these interchangeable?
>
>As I understand it "server" will do name resolution once and pick an IP
>from the result. "pool" will periodically refresh the name and cycle to
>a different member of the pool.

See also https://www.eecis.udel.edu/~mills/ntp/html/confopt.html#pool


>
>>>
>>>Additionally, there is a parameter 'iburst' which I did not find in
>>>the Debian docs but found at http://doc.ntp.org/4.1.1/confopt.htm
>
>Did you install ntp-doc? Did you check there?
>
>>>
>>>
>>>Thanks,
>>>Ray
>>
>>Begin rant:
>>
>>From someone who is currently battling a fresh jessie install that didn't
>>even come with ntpdate installed, and which using the above format
>>in /etc/ntp.conf is still about 12 hours off on an rpi-3.
>>
>>Installing ntpdate and attempting to start it gets me a no servers found
>>message, yet they are defined as discussed above, and the network is
>>fully accessible to all other forms of communication.
>>
>>That doc on www.ntp.org is nice, but worthless to someone who just wants
>>it to work. I have quite a zoo of machines here, and I see little
>>advantage to each one banging on a network server, when it needs an
>>update.  But does it give even a hint of how to make this machine, or
>>heaven forbid, my router, which keeps time via ntp, and which I believe
>>has the time broadcast enabled, (its dd-wrt in a buffalo box) into a
>>server that the rest of my machines can listen to to get the correct
>>time. If I could achieve that, it would reduce the loading on the time
>>servers at debian or pool.ntp.org by a factor of 5 or 6 just from my
>>home network.
>
>By a factor of 5 or 6? You think you own 5 or 6 times more servers than
>everyone else combined? (I think you just mean "reduce [...] by 5 or
>6").
>
>Does your router inform other devices on the network that it should be
>used as a time server? In the DHCP specification there is an option
>called "time-servers". The idea is that a network administrator sets
>this to be the approved time servers for the network and clients
>synchronise to that. In debian, this is facilitated by
>/etc/dchp/dhclient-exit-hooks.d/ntp (at least, if you use the ISC DHCP
>client). That script will read the "time-servers" option from the DHCP
>packet, write /var/lib/ntp/ntp.conf.dhcp and ensure that file is
>included from your main ntp.conf. As far as I'm aware, this is default
>behaviour.
>
>>
>>But a manpage that actually tells us how to do that must be sick bird,
>>because its not been written yet.  Man page writers please get real, and
>>tell us how to do something like getting our home networks all
>>synchronized to our routers which can then broadcast it to the rest of
>>our network.
>
>There's an XY problem here. You probably shouldn't put this information
>into the NTP man pages, as it's not NTP that's doing the work. The
>information about the "time-servers" option *is* in the DHCP manpage,
>but probably there's no information about the specific hook being
>included.

My mistake, the correct option is "ntp-servers".

https://support.ntp.org/bin/view/Support/ConfiguringNTP#Section_6.12.

>
>If the NTP hook is Debian-specific, then... I don't know where that
>should be documented. If it's upstream, then... Well, if every project
>documented every decision for creating every file, then there'd be a lot
>to wade through.
>
>>
>>Such a scheme can easily keep us on time with any errors within a few
>>milliseconds, more than adequate enough for the girls I go with. While
>>reducing the load on the servers by at least 80%.
>>
>>So how about a manpage that tells us how to do that?  If its not illegal
>>according to some rfc that is.
>>
>>Rant off.
>>
>>Thanks for reading.
>>
>>Cheers, Gene Heskett
>>-- 
>>"There are four boxes to be used in defense of liberty:
>>soap, ballot, jury, and ammo. Please use in that order."
>>-Ed Howdershelt (Author)
>>Genes Web page <http://geneslinuxbox.net:6309/gene>
>>
>
>-- 
>For more information, please reread.



-- 
For more information, please reread.

[toc] | [prev] | [next] | [standalone]


#181902

FromGene Heskett <gheskett@shentel.net>
Date2017-06-08 01:10 +0200
Message-ID<tPSfs-4Fa-121@gated-at.bofh.it>
In reply to#181887
On Wednesday 07 June 2017 10:54:26 Darac Marjal wrote:

> On Wed, Jun 07, 2017 at 10:35:23AM -0400, Gene Heskett wrote:
> >On Wednesday 07 June 2017 08:56:59 ray wrote:
> >> I would like to know the correct syntax for entering a server entry
> >> for stretch.
> >>
> >> All the documentation I find says to list the ntp servers in the
> >> file as: server 0.XX.pool.ntp.org
> >> server 1.XX.pool.ntp.org
> >>
> >> An example source from 2017 is https://wiki.debian.org/DateTime
> >>
> >> When I open /etc/ntp.conf on my new stretch installation, I find
> >> this format: pool 0.debian.pool.ntp.org iburst
> >> pool 1.debian.pool.ntp.org iburst
> >>
> >> The latest Debian doc says to start the line with 'server'.
> >> The latest Debian implementation starts the line with 'pool'.
> >>
> >> Are these interchangeable?
>
> As I understand it "server" will do name resolution once and pick an
> IP from the result. "pool" will periodically refresh the name and
> cycle to a different member of the pool.
>
> >> Additionally, there is a parameter 'iburst' which I did not find in
> >> the Debian docs but found at http://doc.ntp.org/4.1.1/confopt.htm
>
> Did you install ntp-doc? Did you check there?

I haven't gotten around to checking that, its on a raspberry pi3b, which 
has a fan on its heat sinks, but isn't terribly stable, I've locked it 
up tight at least a dozen times so far today with my horsing around.

But I did appear to get ntp to do its job, by adding "server " in front 
of the fqdn's in /etc/ntp.conf.

[...]

Now, if I could just make it use the routers broadcasts. Or could at 
least prove it is broadcasting. Yes it is, I caught a broadcast at 
xx.xx.xx.255:

14:16:14.760909 IP coyote.coyote.den.ntp > xx.xx.xx.255.ntp: NTPv4, 
Broadcast, length 48

So it is broadcasting. Now the trick is to make the rest of my machines 
use it.  Hints & examnples welcomed.

And I did install ntp-doc just now. A wee bit more verbose, but still no 
examples.

Cheers, Gene Heskett
-- 
"There are four boxes to be used in defense of liberty:
 soap, ballot, jury, and ammo. Please use in that order."
-Ed Howdershelt (Author)
Genes Web page <http://geneslinuxbox.net:6309/gene>

[toc] | [prev] | [next] | [standalone]


#181921

FromDarac Marjal <mailinglist@darac.org.uk>
Date2017-06-08 14:30 +0200
Message-ID<tQ4JA-4eB-17@gated-at.bofh.it>
In reply to#181902

[Multipart message — attachments visible in raw view] — view raw

On Wed, Jun 07, 2017 at 07:00:52PM -0400, Gene Heskett wrote:
>On Wednesday 07 June 2017 10:54:26 Darac Marjal wrote:
>
>> On Wed, Jun 07, 2017 at 10:35:23AM -0400, Gene Heskett wrote:
>> >On Wednesday 07 June 2017 08:56:59 ray wrote:
>> >> I would like to know the correct syntax for entering a server entry
>> >> for stretch.
>> >>
>> >> All the documentation I find says to list the ntp servers in the
>> >> file as: server 0.XX.pool.ntp.org
>> >> server 1.XX.pool.ntp.org
>> >>
>> >> An example source from 2017 is https://wiki.debian.org/DateTime
>> >>
>> >> When I open /etc/ntp.conf on my new stretch installation, I find
>> >> this format: pool 0.debian.pool.ntp.org iburst
>> >> pool 1.debian.pool.ntp.org iburst
>> >>
>> >> The latest Debian doc says to start the line with 'server'.
>> >> The latest Debian implementation starts the line with 'pool'.
>> >>
>> >> Are these interchangeable?
>>
>> As I understand it "server" will do name resolution once and pick an
>> IP from the result. "pool" will periodically refresh the name and
>> cycle to a different member of the pool.
>>
>> >> Additionally, there is a parameter 'iburst' which I did not find in
>> >> the Debian docs but found at http://doc.ntp.org/4.1.1/confopt.htm
>>
>> Did you install ntp-doc? Did you check there?
>
>I haven't gotten around to checking that, its on a raspberry pi3b, which
>has a fan on its heat sinks, but isn't terribly stable, I've locked it
>up tight at least a dozen times so far today with my horsing around.
>
>But I did appear to get ntp to do its job, by adding "server " in front
>of the fqdn's in /etc/ntp.conf.
>
>[...]
>
>Now, if I could just make it use the routers broadcasts. Or could at
>least prove it is broadcasting. Yes it is, I caught a broadcast at
>xx.xx.xx.255:

Apparently, the word "broadcastclient" in ntp.conf is what you want:

  broadcastclient
	Enable reception of broadcast server messages to any local interface
	(type	b address). Ordinarily, upon receiving a broadcast message
	for the first time, the broadcast client measures the nominal server
	propagation delay using a brief client/server exchange, after which
	it continues in listen-only mode. If a nonzero value is specified in
	the broadcastdelay command, the value becomes the delay and the
	volley is not executed. Note: the novolley option has been
	deprecated for future enhancements. Note that, in order to avoid
	accidental or malicious disruption in this mode, both the server and
	client should operate using symmetric key or public key
	authentication as described in the Authentication Options page. Note
	that the volley is required with public key authentication in order
	to run the Autokey protocol.

This information IS in the ntp.conf manpage, and fairly apparent if
searching that for the work "broadcast".

>
>14:16:14.760909 IP coyote.coyote.den.ntp > xx.xx.xx.255.ntp: NTPv4,
>Broadcast, length 48
>
>So it is broadcasting. Now the trick is to make the rest of my machines
>use it.  Hints & examnples welcomed.
>
>And I did install ntp-doc just now. A wee bit more verbose, but still no
>examples.
>
>Cheers, Gene Heskett
>-- 
>"There are four boxes to be used in defense of liberty:
> soap, ballot, jury, and ammo. Please use in that order."
>-Ed Howdershelt (Author)
>Genes Web page <http://geneslinuxbox.net:6309/gene>
>

-- 
For more information, please reread.

[toc] | [prev] | [next] | [standalone]


#181922 — Re: https_port

From"Adiel Plasencia Herrera" <adielp@estereocentro.icrt.cu>
Date2017-06-08 14:50 +0200
SubjectRe: https_port
Message-ID<tQ52V-4l3-1@gated-at.bofh.it>
In reply to#181921

[Multipart message — attachments visible in raw view] — view raw

How to generate the certificate and the key to make a very basic 
configuration of the https connection.

As basic as possible.
regards






On 08/06/17 03:28, Adiel Plasencia Herrera wrote:
>>Hello,>>They would help me with a configuration of my squid that I want 
to>implement.>>My proxy passes all traffic to a parent proxy and I want 
clients to>connect to my proxy via https.>>Can you help me how to implement 
the connection to my proxy via https?>>To better explain what I want 
attached 2 pictures. The image with>1.jpg name shows my proxy configuration 
with type HTTp that connects>well to internet.>>What I want is for the 
connection to my proxy to be by the form of the>2.jpg image that uses the 
HTTPS type.>>Or if it is possible then leave the 2 forms.
What operating system are you using, and what applications are you 
wanting to use this proxy connection?

The normal configuration is simply to add an https_port line with cert= 
parameter to your squid.conf. More details on that below.


>>>This is my current configuration:>acl trabajadores src 10.5.7.3 
10.5.7.5><snip>
>>http_access allow trabajadores>http_access deny !Safe_ports>http_access 
deny CONNECT !SSL_ports
You custom http_access rules ("allow trabajadores") should be down here 
after the basic security checks.

>http_access deny all>>>http_port 3128

Date: Thu, 8 Jun 2017 01:04:31 +1200
From: Amos Jeffries <squid3@treenet.co.nz>
To: squid-users@lists.squid-cache.org
Subject: Re: [squid-users] https_port
Message-ID: <764ecd5f-6f6c-0eb5-90b4-5591ab5e1920@treenet.co.nz>
Content-Type: text/plain; charset=utf-8; format=flowed

The above port is for receiving plain-text connections to the proxy. 
Most software supports this, with a few exceptions (usually Java apps).


To accept TLS connections to the proxy (not HTTPS *over* the proxy), 
what you do is add an https_port line here. That https_port line needs a 
cert= parameter containing the proxy server certificate. You may need 
other TLS/SSL parameters to fine tune what the TLS does, but just start 
with getting that basic setup to work.
  <http://www.squid-cache.org/Doc/config/https_port/ 
[http://www.squid-cache.org/Doc/config/https_port/]>

For example:
   https_port 3129 cert=/etc/squid/proxy.pem

(the proxy.pem file here contains both the public server cert and 
private server key for that cert).

Many GUI applications (most notably browsers) do not support this type 
of connection to a proxy (or not well if they do). Which is where the 
Q's about your OS and applications come in. You may need to setup 
environment variables or PAC files to get the applications to work.


Note that this is *very* different situation to intercepting port 443 
traffic. Much more different than port 3128 vs. intercepted port 80. 
HTTPS traffic goes through these TLS proxy connections with 
double-layered encryption, so this setup does *not* magically make the 
proxy able to see inside HTTPS if that is what you are really after.

Amos

[toc] | [prev] | [next] | [standalone]


#181925 — Re: https_port

FromDarac Marjal <mailinglist@darac.org.uk>
Date2017-06-08 15:30 +0200
SubjectRe: https_port
Message-ID<tQ5FE-4OD-13@gated-at.bofh.it>
In reply to#181922

[Multipart message — attachments visible in raw view] — view raw

On Thu, Jun 08, 2017 at 08:41:14AM -0700, Adiel Plasencia Herrera wrote:
> How to generate the certificate and the key to make a very
> basic  configuration of the https connection.

NTP doesn't use HTTPS. It uses its own port, it's own protocol and
implements standard cryptography in a manner more suited to the
protocol.

See https://www.eecis.udel.edu/~mills/ntp/html/autokey.html for more
details.

>
> As
> basic as possible.
> regards
>
>
>
>
>
>
> On 08/06/17 03:28, Adiel Plasencia Herrera wrote:
> > > Hello, > > They would help me with a
> configuration of my squid that I want to  > implement. >
> > My proxy passes all traffic to a parent proxy and I want clients
> to  > connect to my proxy via https. > > Can
> you help me how to implement the connection to my proxy via https?
> > > To better explain what I want attached 2 pictures. The
> image with  > 1.jpg name shows my proxy configuration with type
> HTTp that connects  > well to internet. > >
> What I want is for the connection to my proxy to be by the form of the
> > 2.jpg image that uses the HTTPS type. > > Or if
> it is possible then leave the 2 forms.
> What operating system are you using, and what applications are you
> wanting to use this proxy connection?
>
> The normal configuration is simply to add an https_port line with cert=
> parameter to your squid.conf. More details on that below.
>
>
> > > > This is my current configuration: >
>  acl trabajadores src 10.5.7.3 10.5.7.5 > <snip>
> > > http_access allow trabajadores > http_access
> deny !Safe_ports > http_access deny CONNECT !SSL_ports
> You custom http_access rules ("allow trabajadores") should be down
> here
> after the basic security checks.
>
> > http_access deny all > > > http_port
> 3128
>
> Date: Thu, 8 Jun 2017 01:04:31 +1200
> From: Amos Jeffries <squid3@treenet.co.nz>
> To: squid-users@lists.squid-cache.org
> Subject: Re: [squid-users] https_port
> Message-ID: <764ecd5f-6f6c-0eb5-90b4-5591ab5e1920@treenet.co.nz
> >
> Content-Type: text/plain; charset=utf-8; format=flowed
> The above port is for receiving plain-text connections to the proxy.
> Most software supports this, with a few exceptions (usually Java apps).
>
>
> To accept TLS connections to the proxy (not HTTPS *over* the proxy),
> what you do is add an https_port line here. That https_port line needs a
> cert= parameter containing the proxy server certificate. You may need
> other TLS/SSL parameters to fine tune what the TLS does, but just start
> with getting that basic setup to work.
>   <
> [1]http://www.squid-cache.org/Doc/config/https_port/>
>
> For example:
>    https_port 3129 cert=/etc/squid/proxy.pem
>
> (the proxy.pem file here contains both the public server cert and
> private server key for that cert).
>
> Many GUI applications (most notably browsers) do not support this type
> of connection to a proxy (or not well if they do). Which is where the
> Q's about your OS and applications come in. You may need to setup
> environment variables or PAC files to get the applications to work.
>
>
> Note that this is *very* different situation to intercepting port 443
> traffic. Much more different than port 3128 vs. intercepted port 80.
> HTTPS traffic goes through these TLS proxy connections with
> double-layered encryption, so this setup does *not* magically make the
> proxy able to see inside HTTPS if that is what you are really after.
>
> Amos
>
>References
>
>   Visible links
>   1. http://www.squid-cache.org/Doc/config/https_port/

-- 
For more information, please reread.

[toc] | [prev] | [next] | [standalone]


#181933 — Re: https_port

FromHenrique de Moraes Holschuh <hmh@debian.org>
Date2017-06-08 17:00 +0200
SubjectRe: https_port
Message-ID<tQ74J-5AT-5@gated-at.bofh.it>
In reply to#181925
On Thu, 08 Jun 2017, Darac Marjal wrote:
> On Thu, Jun 08, 2017 at 08:41:14AM -0700, Adiel Plasencia Herrera wrote:
> >How to generate the certificate and the key to make a very
> >basic  configuration of the https connection.
> 
> NTP doesn't use HTTPS. It uses its own port, it's own protocol and
> implements standard cryptography in a manner more suited to the
> protocol.
> 
> See https://www.eecis.udel.edu/~mills/ntp/html/autokey.html for more
> details.

Don't bother with autokey, it is not worth the pain.  If you can use ntp
symmetric key authentication, that one should take care of your servers
well enough.

There is no security for anything that is based on SNTP, though (that
"S" is for Simple, not Secure), you'd have to do it in a lower layer
(local firewall, IPSEC AH, whatever).

-- 
  Henrique Holschuh

[toc] | [prev] | [next] | [standalone]


#181934 — Re: https_port

From"Adiel Plasencia Herrera" <adielp@estereocentro.icrt.cu>
Date2017-06-08 17:20 +0200
SubjectRe: https_port
Message-ID<tQ7o6-5X8-9@gated-at.bofh.it>
In reply to#181933

[Multipart message — attachments visible in raw view] — view raw

Hello,
I 
do not look for security, is that having no real internet ip in my 
company I need certain programs to go to the internet and for that I use
 proxycap (http://www.proxycap.com/) that makes me this function 
perfectly through the proxy . What happens is 
that with HTTP does not work and I need to pass my squid to use HTTPS 
authentication for the program (proxycap) to work well.

A friend told me that for https_port to work I needed validated 
certificates, not self-generated ones. I
 do not know to what extent this has to be so because the configuration I
 need is customized for me only and would be internal to my company that
 does not have visibility to the internet because this squid is a child 
of another that is the one that has the real internet ip .

I need the help to correctly create those certificates and the options to 
put in the line https_port.

I am very novice in squid and linux.

Thank you


-----Original Message-----

From: Henrique de Moraes Holschuh <hmh@debian.org>

To: debian-user@lists.debian.org

Date: Thu, 8 Jun 2017 11:55:38 -0300

Subject: Re: https_port




On Thu, 08 Jun 2017, Darac Marjal wrote:

> On Thu, Jun 08, 2017 at 08:41:14AM -0700, Adiel Plasencia Herrera wrote:

> >How to generate the certificate and the key to make a very

> >basic  configuration of the https connection.

> 

> NTP doesn't use HTTPS. It uses its own port, it's own protocol and

> implements standard cryptography in a manner more suited to the

> protocol.

> 

> See https://www.eecis.udel.edu/~mills/ntp/html/autokey.html 
[https://www.eecis.udel.edu/~mills/ntp/html/autokey.html] for more

> details.



Don't bother with autokey, it is not worth the pain.  If you can use ntp

symmetric key authentication, that one should take care of your servers

well enough.



There is no security for anything that is based on SNTP, though (that

"S" is for Simple, not Secure), you'd have to do it in a lower layer

(local firewall, IPSEC AH, whatever).



-- 

  Henrique Holschuh

[toc] | [prev] | [next] | [standalone]


#181935 — Re: https_port

FromDarac Marjal <mailinglist@darac.org.uk>
Date2017-06-08 17:30 +0200
SubjectRe: https_port
Message-ID<tQ7xN-60p-43@gated-at.bofh.it>
In reply to#181934

[Multipart message — attachments visible in raw view] — view raw

On Thu, Jun 08, 2017 at 11:18:16AM -0700, Adiel Plasencia Herrera wrote:
>   Hello,
>   I do not look for security, is that having no real internet ip in my
>   company I need certain programs to go to the internet and for that I
>   use proxycap (http://www.proxycap.com/) that makes me this function
>   perfectly through the proxy . What happens is that with HTTP does not
>   work and I need to pass my squid to use HTTPS authentication for the
>   program (proxycap) to work well.

I don't think squid works with NTP at all, but it's been a few years
since I played with Squid, so maybe someone else will be able to give
better advice.

>
>   A friend told me that for https_port to work I needed validated
>   certificates, not self-generated ones. I do not know to what extent
>   this has to be so because the configuration I need is customized for
>   me only and would be internal to my company that does not have
>   visibility to the internet because this squid is a child of another
>   that is the one that has the real internet ip .
>
>   I need the help to correctly create those certificates and the
>   options to put in the line https_port.
>
>   I am very novice in squid and linux.
>
>   Thank you
>
>     -----Original Message-----
>     From: Henrique de Moraes Holschuh <hmh@debian.org>
>     To: debian-user@lists.debian.org
>     Date: Thu, 8 Jun 2017 11:55:38 -0300
>     Subject: Re: https_port
>
>     On Thu, 08 Jun 2017, Darac Marjal wrote:
>     > On Thu, Jun 08, 2017 at 08:41:14AM -0700, Adiel Plasencia Herrera
>     wrote:
>     > >How to generate the certificate and the key to make a very
>     > >basic  configuration of the https connection.
>     >
>     > NTP doesn't use HTTPS. It uses its own port, it's own protocol
>     and
>     > implements standard cryptography in a manner more suited to the
>     > protocol.
>     >
>     > See [1]https://www.eecis.udel.edu/~mills/ntp/html/autokey.html
>     for more
>     > details.
>
>     Don't bother with autokey, it is not worth the pain.  If you can
>     use ntp
>     symmetric key authentication, that one should take care of your
>     servers
>     well enough.
>
>     There is no security for anything that is based on SNTP, though
>     (that
>     "S" is for Simple, not Secure), you'd have to do it in a lower
>     layer
>     (local firewall, IPSEC AH, whatever).
>
>     --
>       Henrique Holschuh
>
>References
>
>   Visible links
>   1. https://www.eecis.udel.edu/~mills/ntp/html/autokey.html

-- 
For more information, please reread.

[toc] | [prev] | [next] | [standalone]


#181936 — Re: https_port

FromGreg Wooledge <wooledg@eeg.ccf.org>
Date2017-06-08 17:40 +0200
SubjectRe: https_port
Message-ID<tQ7Hs-63v-21@gated-at.bofh.it>
In reply to#181935
On Thu, Jun 08, 2017 at 04:25:11PM +0100, Darac Marjal wrote:
> On Thu, Jun 08, 2017 at 11:18:16AM -0700, Adiel Plasencia Herrera wrote:
> >  Hello,
> >  I do not look for security, is that having no real internet ip in my
> >  company I need certain programs to go to the internet and for that I
> >  use proxycap (http://www.proxycap.com/) that makes me this function
> >  perfectly through the proxy . What happens is that with HTTP does not
> >  work and I need to pass my squid to use HTTPS authentication for the
> >  program (proxycap) to work well.
> 
> I don't think squid works with NTP at all, but it's been a few years
> since I played with Squid, so maybe someone else will be able to give
> better advice.

I don't think he's *asking* about NTP at all.

[toc] | [prev] | [next] | [standalone]


#181937 — Re: https_port

FromDarac Marjal <mailinglist@darac.org.uk>
Date2017-06-08 17:50 +0200
SubjectRe: https_port
Message-ID<tQ7R8-66J-19@gated-at.bofh.it>
In reply to#181936

[Multipart message — attachments visible in raw view] — view raw

On Thu, Jun 08, 2017 at 11:34:20AM -0400, Greg Wooledge wrote:
>On Thu, Jun 08, 2017 at 04:25:11PM +0100, Darac Marjal wrote:
>> On Thu, Jun 08, 2017 at 11:18:16AM -0700, Adiel Plasencia Herrera wrote:
>> >  Hello,
>> >  I do not look for security, is that having no real internet ip in my
>> >  company I need certain programs to go to the internet and for that I
>> >  use proxycap (http://www.proxycap.com/) that makes me this function
>> >  perfectly through the proxy . What happens is that with HTTP does not
>> >  work and I need to pass my squid to use HTTPS authentication for the
>> >  program (proxycap) to work well.
>>
>> I don't think squid works with NTP at all, but it's been a few years
>> since I played with Squid, so maybe someone else will be able to give
>> better advice.
>
>I don't think he's *asking* about NTP at all.
>

Ah. You mean he's a politician (replying to a topic by introducing one's
own, unrelated, topic)?


-- 
For more information, please reread.

[toc] | [prev] | [next] | [standalone]


Page 1 of 3  [1] 2 3  Next page →

Back to top | Article view | linux.debian.user


csiph-web