Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.user > #181878 > unrolled thread
| Started by | ray <ray@aarden.us> |
|---|---|
| First post | 2017-06-07 15:20 +0200 |
| Last post | 2017-06-07 17:00 +0200 |
| Articles | 20 on this page of 43 — 19 participants |
Back to article view | Back to linux.debian.user
NTP.conf pool vs server ray <ray@aarden.us> - 2017-06-07 15:20 +0200
Re: NTP.conf pool vs server Greg Wooledge <wooledg@eeg.ccf.org> - 2017-06-07 15:30 +0200
Re: NTP.conf pool vs server Gene Heskett <gheskett@shentel.net> - 2017-06-07 16:50 +0200
Re: NTP.conf pool vs server Gene Heskett <gheskett@shentel.net> - 2017-06-07 16:40 +0200
Re: NTP.conf pool vs server Greg Wooledge <wooledg@eeg.ccf.org> - 2017-06-07 17:00 +0200
Re: NTP.conf pool vs server Darac Marjal <mailinglist@darac.org.uk> - 2017-06-07 17:00 +0200
Re: NTP.conf pool vs server Greg Wooledge <wooledg@eeg.ccf.org> - 2017-06-07 17:10 +0200
Re: NTP.conf pool vs server Joshua Schaeffer <jschaeffer0922@gmail.com> - 2017-06-07 17:30 +0200
Re: NTP.conf pool vs server Greg Wooledge <wooledg@eeg.ccf.org> - 2017-06-07 17:50 +0200
Re: NTP.conf pool vs server Henrique de Moraes Holschuh <hmh@debian.org> - 2017-06-07 18:10 +0200
Re: NTP.conf pool vs server Darac Marjal <mailinglist@darac.org.uk> - 2017-06-07 17:20 +0200
Re: NTP.conf pool vs server Gene Heskett <gheskett@shentel.net> - 2017-06-08 01:10 +0200
Re: NTP.conf pool vs server Darac Marjal <mailinglist@darac.org.uk> - 2017-06-08 14:30 +0200
Re: https_port "Adiel Plasencia Herrera" <adielp@estereocentro.icrt.cu> - 2017-06-08 14:50 +0200
Re: https_port Darac Marjal <mailinglist@darac.org.uk> - 2017-06-08 15:30 +0200
Re: https_port Henrique de Moraes Holschuh <hmh@debian.org> - 2017-06-08 17:00 +0200
Re: https_port "Adiel Plasencia Herrera" <adielp@estereocentro.icrt.cu> - 2017-06-08 17:20 +0200
Re: https_port Darac Marjal <mailinglist@darac.org.uk> - 2017-06-08 17:30 +0200
Re: https_port Greg Wooledge <wooledg@eeg.ccf.org> - 2017-06-08 17:40 +0200
Re: https_port Darac Marjal <mailinglist@darac.org.uk> - 2017-06-08 17:50 +0200
Re: https_port "Adiel Plasencia Herrera" <adielp@estereocentro.icrt.cu> - 2017-06-08 18:00 +0200
Re: https_port Jim Ohlstein <jim@mailman-hosting.com> - 2017-06-08 19:10 +0200
Re: https_port Charlie Kravetz <cjk@teamcharliesangels.com> - 2017-06-09 16:40 +0200
Reply-to-all or reply-to-list again (was: https_port) Nicolas George <george@nsup.org> - 2017-06-09 16:50 +0200
Re: Reply-to-all or reply-to-list again (was: https_port) Fungi4All <fungilife@protonmail.com> - 2017-06-09 17:20 +0200
Re: Reply-to-all or reply-to-list again The Wanderer <wanderer@fastmail.fm> - 2017-06-09 17:20 +0200
Re: Reply-to-all or reply-to-list again Nicolas George <george@nsup.org> - 2017-06-09 18:00 +0200
Re: Reply-to-all or reply-to-list again The Wanderer <wanderer@fastmail.fm> - 2017-06-09 21:20 +0200
Re: Reply-to-all or reply-to-list again Joel Rees <joel.rees@gmail.com> - 2017-06-10 04:20 +0200
Re: Reply-to-all or reply-to-list again Fungi4All <fungilife@protonmail.com> - 2017-06-10 16:00 +0200
Re: Reply-to-all or reply-to-list again Joel Rees <joel.rees@gmail.com> - 2017-06-10 16:30 +0200
Re: Reply-to-all or reply-to-list again Fungi4All <fungilife@protonmail.com> - 2017-06-10 18:00 +0200
Re: Reply-to-all or reply-to-list again (was: https_port) Gene Heskett <gheskett@shentel.net> - 2017-06-09 17:30 +0200
Re: NTP.conf pool vs server Gene Heskett <gheskett@shentel.net> - 2017-06-08 16:10 +0200
Re: NTP.conf pool vs server John Hasler <jhasler@newsguy.com> - 2017-06-07 18:10 +0200
Re: NTP.conf pool vs server Brian <ad44@cityscape.co.uk> - 2017-06-07 18:30 +0200
Re: NTP.conf pool vs server David Wright <deblis@lionunicorn.co.uk> - 2017-06-11 18:00 +0200
Re: NTP.conf pool vs server Brian <ad44@cityscape.co.uk> - 2017-06-11 19:30 +0200
Re: NTP.conf pool vs server Teemu Likonen <tlikonen@iki.fi> - 2017-06-08 08:40 +0200
Re: NTP.conf pool vs server Curt <curty@free.fr> - 2017-06-08 09:20 +0200
Re: NTP.conf pool vs server Gene Heskett <gheskett@shentel.net> - 2017-06-08 15:40 +0200
Re: NTP.conf pool vs server Jim Ohlstein <jim@mailman-hosting.com> - 2017-06-07 18:40 +0200
Re: NTP.conf pool vs server Kushal Kumaran <kushal@locationd.net> - 2017-06-07 17:00 +0200
Page 1 of 3 [1] 2 3 Next page →
| From | ray <ray@aarden.us> |
|---|---|
| Date | 2017-06-07 15:20 +0200 |
| Subject | NTP.conf pool vs server |
| Message-ID | <tPJ2q-77i-15@gated-at.bofh.it> |
I would like to know the correct syntax for entering a server entry for stretch. All the documentation I find says to list the ntp servers in the file as: server 0.XX.pool.ntp.org server 1.XX.pool.ntp.org An example source from 2017 is https://wiki.debian.org/DateTime When I open /etc/ntp.conf on my new stretch installation, I find this format: pool 0.debian.pool.ntp.org iburst pool 1.debian.pool.ntp.org iburst The latest Debian doc says to start the line with 'server'. The latest Debian implementation starts the line with 'pool'. Are these interchangeable? Additionally, there is a parameter 'iburst' which I did not find in the Debian docs but found at http://doc.ntp.org/4.1.1/confopt.htm Thanks, Ray
[toc] | [next] | [standalone]
| From | Greg Wooledge <wooledg@eeg.ccf.org> |
|---|---|
| Date | 2017-06-07 15:30 +0200 |
| Message-ID | <tPJc6-7aN-23@gated-at.bofh.it> |
| In reply to | #181878 |
On Wed, Jun 07, 2017 at 05:56:59AM -0700, ray wrote: > The latest Debian doc says to start the line with 'server'. > The latest Debian implementation starts the line with 'pool'. > > Are these interchangeable? > > Additionally, there is a parameter 'iburst' which I did not find in the Debian docs but found at http://doc.ntp.org/4.1.1/confopt.htm For whatever it's worth, "iburst" is in ntp.conf(5) but "pool" is not.
[toc] | [prev] | [next] | [standalone]
| From | Gene Heskett <gheskett@shentel.net> |
|---|---|
| Date | 2017-06-07 16:50 +0200 |
| Message-ID | <tPKrv-7Vi-3@gated-at.bofh.it> |
| In reply to | #181881 |
On Wednesday 07 June 2017 09:27:19 Greg Wooledge wrote: > On Wed, Jun 07, 2017 at 05:56:59AM -0700, ray wrote: > > The latest Debian doc says to start the line with 'server'. > > The latest Debian implementation starts the line with 'pool'. > > > > Are these interchangeable? > > > > Additionally, there is a parameter 'iburst' which I did not find in > > the Debian docs but found at http://doc.ntp.org/4.1.1/confopt.htm > > For whatever it's worth, "iburst" is in ntp.conf(5) but "pool" is not. pool is normally a round robin server setup where any machine in the "pool" of machines can answer the query. Its part of the net address, not a keyword to ntp(date). If you ping -c1 pool.ntp.org, you'll see the machines address that answered that ping, but you may not get a reply from that same machine the next time you ping it. Cheers, Gene Heskett -- "There are four boxes to be used in defense of liberty: soap, ballot, jury, and ammo. Please use in that order." -Ed Howdershelt (Author) Genes Web page <http://geneslinuxbox.net:6309/gene>
[toc] | [prev] | [next] | [standalone]
| From | Gene Heskett <gheskett@shentel.net> |
|---|---|
| Date | 2017-06-07 16:40 +0200 |
| Message-ID | <tPKhP-7Rr-5@gated-at.bofh.it> |
| In reply to | #181878 |
On Wednesday 07 June 2017 08:56:59 ray wrote: > I would like to know the correct syntax for entering a server entry > for stretch. > > All the documentation I find says to list the ntp servers in the file > as: server 0.XX.pool.ntp.org > server 1.XX.pool.ntp.org > > An example source from 2017 is https://wiki.debian.org/DateTime > > When I open /etc/ntp.conf on my new stretch installation, I find this > format: pool 0.debian.pool.ntp.org iburst > pool 1.debian.pool.ntp.org iburst > > The latest Debian doc says to start the line with 'server'. > The latest Debian implementation starts the line with 'pool'. > > Are these interchangeable? > > Additionally, there is a parameter 'iburst' which I did not find in > the Debian docs but found at http://doc.ntp.org/4.1.1/confopt.htm > > > Thanks, > Ray Begin rant: From someone who is currently battling a fresh jessie install that didn't even come with ntpdate installed, and which using the above format in /etc/ntp.conf is still about 12 hours off on an rpi-3. Installing ntpdate and attempting to start it gets me a no servers found message, yet they are defined as discussed above, and the network is fully accessible to all other forms of communication. That doc on www.ntp.org is nice, but worthless to someone who just wants it to work. I have quite a zoo of machines here, and I see little advantage to each one banging on a network server, when it needs an update. But does it give even a hint of how to make this machine, or heaven forbid, my router, which keeps time via ntp, and which I believe has the time broadcast enabled, (its dd-wrt in a buffalo box) into a server that the rest of my machines can listen to to get the correct time. If I could achieve that, it would reduce the loading on the time servers at debian or pool.ntp.org by a factor of 5 or 6 just from my home network. But a manpage that actually tells us how to do that must be sick bird, because its not been written yet. Man page writers please get real, and tell us how to do something like getting our home networks all synchronized to our routers which can then broadcast it to the rest of our network. Such a scheme can easily keep us on time with any errors within a few milliseconds, more than adequate enough for the girls I go with. While reducing the load on the servers by at least 80%. So how about a manpage that tells us how to do that? If its not illegal according to some rfc that is. Rant off. Thanks for reading. Cheers, Gene Heskett -- "There are four boxes to be used in defense of liberty: soap, ballot, jury, and ammo. Please use in that order." -Ed Howdershelt (Author) Genes Web page <http://geneslinuxbox.net:6309/gene>
[toc] | [prev] | [next] | [standalone]
| From | Greg Wooledge <wooledg@eeg.ccf.org> |
|---|---|
| Date | 2017-06-07 17:00 +0200 |
| Message-ID | <tPKBd-7Z0-37@gated-at.bofh.it> |
| In reply to | #181883 |
On Wed, Jun 07, 2017 at 10:35:23AM -0400, Gene Heskett wrote:
> Begin rant:
>
> From someone who is currently battling a fresh jessie install that didn't
> even come with ntpdate installed, and which using the above format
> in /etc/ntp.conf is still about 12 hours off on an rpi-3.
The ntpdate package has been deprecated for some time now, in Debian.
You don't need it. Simply install the ntp package, and configure the
/etc/ntp.conf file (which admittedly is not clearly documented).
Current versions of Debian have folded the ntpdate functionality into
ntp. The /etc/default/ntp file has (or should have!) this:
NTPD_OPTS='-g'
This starts ntpd with the -g option, which tells it that it's allowed
to slam the clock forward or backward exactly once when it starts up,
mimicking what ntpdate used to do.
> Installing ntpdate and attempting to start it gets me a no servers found
> message, yet they are defined as discussed above, and the network is
> fully accessible to all other forms of communication.
Sounds like something is misconfigured, though we can't tell what it is
without additional info.
> But a manpage that actually tells us how to do that must be sick bird,
> because its not been written yet. Man page writers please get real, and
> tell us how to do something like getting our home networks all
> synchronized to our routers which can then broadcast it to the rest of
> our network.
On the machine that you want to act as your local network's time server:
server 0.debian.pool.ntp.org iburst
server 1.debian.pool.ntp.org iburst
server 2.debian.pool.ntp.org iburst
server 3.debian.pool.ntp.org iburst
And make sure you didn't change the lines under the comment that says
"By default, exchange time with everybody, but don't allow configuration."
On your other machines:
server your.time.server
That's basically it. Make sure the hostname is resolvable. If you have
issues with name resolution not being available sometimes, then you might
want to add your.time.server to /etc/hosts.
To verify that things are running, use ntpq -p:
svr5:~$ ntpq -p
remote refid st t when poll reach delay offset jitter
==============================================================================
-104.245.32.240 162.213.2.253 2 u 776 1024 377 80.415 -8.341 0.239
*clocka.ntpjs.or 18.26.4.105 2 u 250 1024 377 9.780 0.361 0.556
+up2.com 195.219.14.21 2 u 490 1024 377 31.761 -1.224 0.474
+jarvis.arlen.io 17.253.2.253 2 u 477 1024 377 36.764 -2.368 4.547
And that's why you use multiple public time servers -- they aren't very
accurate, so you need lots of them. The daemon can decide which ones
to ignore, and so on.
The output of this -p thing is not documented, so you have to guess what
it means. I think the "-" in column 1 means "this server sucks, so I'm
not really paying attention to it", and "+" means "pretty good", and "*"
means "this is my favorite". But that's just a guess. There's nothing
in the ntpq man page about it at all.
[toc] | [prev] | [next] | [standalone]
| From | Darac Marjal <mailinglist@darac.org.uk> |
|---|---|
| Date | 2017-06-07 17:00 +0200 |
| Message-ID | <tPKBf-7Z0-79@gated-at.bofh.it> |
| In reply to | #181883 |
[Multipart message — attachments visible in raw view] — view raw
On Wed, Jun 07, 2017 at 10:35:23AM -0400, Gene Heskett wrote: >On Wednesday 07 June 2017 08:56:59 ray wrote: > >> I would like to know the correct syntax for entering a server entry >> for stretch. >> >> All the documentation I find says to list the ntp servers in the file >> as: server 0.XX.pool.ntp.org >> server 1.XX.pool.ntp.org >> >> An example source from 2017 is https://wiki.debian.org/DateTime >> >> When I open /etc/ntp.conf on my new stretch installation, I find this >> format: pool 0.debian.pool.ntp.org iburst >> pool 1.debian.pool.ntp.org iburst >> >> The latest Debian doc says to start the line with 'server'. >> The latest Debian implementation starts the line with 'pool'. >> >> Are these interchangeable? As I understand it "server" will do name resolution once and pick an IP from the result. "pool" will periodically refresh the name and cycle to a different member of the pool. >> >> Additionally, there is a parameter 'iburst' which I did not find in >> the Debian docs but found at http://doc.ntp.org/4.1.1/confopt.htm Did you install ntp-doc? Did you check there? >> >> >> Thanks, >> Ray > >Begin rant: > >From someone who is currently battling a fresh jessie install that didn't >even come with ntpdate installed, and which using the above format >in /etc/ntp.conf is still about 12 hours off on an rpi-3. > >Installing ntpdate and attempting to start it gets me a no servers found >message, yet they are defined as discussed above, and the network is >fully accessible to all other forms of communication. > >That doc on www.ntp.org is nice, but worthless to someone who just wants >it to work. I have quite a zoo of machines here, and I see little >advantage to each one banging on a network server, when it needs an >update. But does it give even a hint of how to make this machine, or >heaven forbid, my router, which keeps time via ntp, and which I believe >has the time broadcast enabled, (its dd-wrt in a buffalo box) into a >server that the rest of my machines can listen to to get the correct >time. If I could achieve that, it would reduce the loading on the time >servers at debian or pool.ntp.org by a factor of 5 or 6 just from my >home network. By a factor of 5 or 6? You think you own 5 or 6 times more servers than everyone else combined? (I think you just mean "reduce [...] by 5 or 6"). Does your router inform other devices on the network that it should be used as a time server? In the DHCP specification there is an option called "time-servers". The idea is that a network administrator sets this to be the approved time servers for the network and clients synchronise to that. In debian, this is facilitated by /etc/dchp/dhclient-exit-hooks.d/ntp (at least, if you use the ISC DHCP client). That script will read the "time-servers" option from the DHCP packet, write /var/lib/ntp/ntp.conf.dhcp and ensure that file is included from your main ntp.conf. As far as I'm aware, this is default behaviour. > >But a manpage that actually tells us how to do that must be sick bird, >because its not been written yet. Man page writers please get real, and >tell us how to do something like getting our home networks all >synchronized to our routers which can then broadcast it to the rest of >our network. There's an XY problem here. You probably shouldn't put this information into the NTP man pages, as it's not NTP that's doing the work. The information about the "time-servers" option *is* in the DHCP manpage, but probably there's no information about the specific hook being included. If the NTP hook is Debian-specific, then... I don't know where that should be documented. If it's upstream, then... Well, if every project documented every decision for creating every file, then there'd be a lot to wade through. > >Such a scheme can easily keep us on time with any errors within a few >milliseconds, more than adequate enough for the girls I go with. While >reducing the load on the servers by at least 80%. > >So how about a manpage that tells us how to do that? If its not illegal >according to some rfc that is. > >Rant off. > >Thanks for reading. > >Cheers, Gene Heskett >-- >"There are four boxes to be used in defense of liberty: > soap, ballot, jury, and ammo. Please use in that order." >-Ed Howdershelt (Author) >Genes Web page <http://geneslinuxbox.net:6309/gene> > -- For more information, please reread.
[toc] | [prev] | [next] | [standalone]
| From | Greg Wooledge <wooledg@eeg.ccf.org> |
|---|---|
| Date | 2017-06-07 17:10 +0200 |
| Message-ID | <tPKKS-8hH-19@gated-at.bofh.it> |
| In reply to | #181887 |
On Wed, Jun 07, 2017 at 03:54:26PM +0100, Darac Marjal wrote: > As I understand it "server" will do name resolution once and pick an IP > from the result. "pool" will periodically refresh the name and cycle to > a different member of the pool. Really? Why isn't this documented? Is it simply urban legend passed from user to user? I largely agree with Gene. The man pages are incredibly silly. They don't tell you how to do the Most Basic Common Thing. Instead they talk about "type s and r addresses" and "a preemptable association is mobilized" and "mobilizes a persistent symmetric-active mode association" and "type b and m addresses" and other such gibberish. I guess Ill try changing one of my intranet time servers from "server" to "pool" and see what happens.
[toc] | [prev] | [next] | [standalone]
| From | Joshua Schaeffer <jschaeffer0922@gmail.com> |
|---|---|
| Date | 2017-06-07 17:30 +0200 |
| Subject | Re: NTP.conf pool vs server |
| Message-ID | <tPL4e-8ou-9@gated-at.bofh.it> |
| In reply to | #181888 |
[Multipart message — attachments visible in raw view] — view raw
On Wed, Jun 7, 2017 at 9:06 AM, Greg Wooledge <wooledg@eeg.ccf.org> wrote: > I largely agree with Gene. The man pages are incredibly silly. They > don't tell you how to do the Most Basic Common Thing. Instead they > talk about "type s and r addresses" and "a preemptable association > is mobilized" and "mobilizes a persistent symmetric-active mode > association" and "type b and m addresses" and other such gibberish. > That is one of the ideas behind the info pages. Man pages have always been technically oriented and are generally very focused. They don't really offer context. Now, I'm not saying that info pages accomplish this (some do, some don't), but that was one of the original ideas behind info pages, is to be more real world and comprehensive. There are trade offs to both approaches. You typically get a dichotomy of groups about man pages and documentation in general. Some people prefer the more technical nature of the man pages, while others find it frustrating. Can be further exacerbated by the fact that people tell other people to RTFM, but even reading a man page top to bottom doesn't help when it actually comes to setting up a piece of software (as you probably experienced yourself). In general man pages are more helpful when you already understand the software in question and are looking for specific information. Thanks, Joshua Schaeffer
[toc] | [prev] | [next] | [standalone]
| From | Greg Wooledge <wooledg@eeg.ccf.org> |
|---|---|
| Date | 2017-06-07 17:50 +0200 |
| Subject | Re: NTP.conf pool vs server |
| Message-ID | <tPLnA-8w9-11@gated-at.bofh.it> |
| In reply to | #181890 |
Hey look, there's already a bug open: <https://bugs.debian.org/803709> "ntp: Please document 'pool' in ntp.conf" Filed November 1, 2015. Except... it's not open. It's been closed. They sat on it for two years until the stretch freeze, and then "fixed" it in experimental. So we won't even get it in stretch.
[toc] | [prev] | [next] | [standalone]
| From | Henrique de Moraes Holschuh <hmh@debian.org> |
|---|---|
| Date | 2017-06-07 18:10 +0200 |
| Message-ID | <tPLGW-rD-11@gated-at.bofh.it> |
| In reply to | #181888 |
On Wed, 07 Jun 2017, Greg Wooledge wrote: > On Wed, Jun 07, 2017 at 03:54:26PM +0100, Darac Marjal wrote: > > As I understand it "server" will do name resolution once and pick an IP > > from the result. "pool" will periodically refresh the name and cycle to > > a different member of the pool. > > Really? Why isn't this documented? Is it simply urban legend passed It is. In the full documentation, package ntp-doc. -- Henrique Holschuh
[toc] | [prev] | [next] | [standalone]
| From | Darac Marjal <mailinglist@darac.org.uk> |
|---|---|
| Date | 2017-06-07 17:20 +0200 |
| Message-ID | <tPKUx-8kV-5@gated-at.bofh.it> |
| In reply to | #181887 |
[Multipart message — attachments visible in raw view] — view raw
On Wed, Jun 07, 2017 at 03:54:26PM +0100, Darac Marjal wrote: >On Wed, Jun 07, 2017 at 10:35:23AM -0400, Gene Heskett wrote: >>On Wednesday 07 June 2017 08:56:59 ray wrote: >> >>>I would like to know the correct syntax for entering a server entry >>>for stretch. >>> >>>All the documentation I find says to list the ntp servers in the file >>>as: server 0.XX.pool.ntp.org >>>server 1.XX.pool.ntp.org >>> >>>An example source from 2017 is https://wiki.debian.org/DateTime >>> >>>When I open /etc/ntp.conf on my new stretch installation, I find this >>>format: pool 0.debian.pool.ntp.org iburst >>>pool 1.debian.pool.ntp.org iburst >>> >>>The latest Debian doc says to start the line with 'server'. >>>The latest Debian implementation starts the line with 'pool'. >>> >>>Are these interchangeable? > >As I understand it "server" will do name resolution once and pick an IP >from the result. "pool" will periodically refresh the name and cycle to >a different member of the pool. See also https://www.eecis.udel.edu/~mills/ntp/html/confopt.html#pool > >>> >>>Additionally, there is a parameter 'iburst' which I did not find in >>>the Debian docs but found at http://doc.ntp.org/4.1.1/confopt.htm > >Did you install ntp-doc? Did you check there? > >>> >>> >>>Thanks, >>>Ray >> >>Begin rant: >> >>From someone who is currently battling a fresh jessie install that didn't >>even come with ntpdate installed, and which using the above format >>in /etc/ntp.conf is still about 12 hours off on an rpi-3. >> >>Installing ntpdate and attempting to start it gets me a no servers found >>message, yet they are defined as discussed above, and the network is >>fully accessible to all other forms of communication. >> >>That doc on www.ntp.org is nice, but worthless to someone who just wants >>it to work. I have quite a zoo of machines here, and I see little >>advantage to each one banging on a network server, when it needs an >>update. But does it give even a hint of how to make this machine, or >>heaven forbid, my router, which keeps time via ntp, and which I believe >>has the time broadcast enabled, (its dd-wrt in a buffalo box) into a >>server that the rest of my machines can listen to to get the correct >>time. If I could achieve that, it would reduce the loading on the time >>servers at debian or pool.ntp.org by a factor of 5 or 6 just from my >>home network. > >By a factor of 5 or 6? You think you own 5 or 6 times more servers than >everyone else combined? (I think you just mean "reduce [...] by 5 or >6"). > >Does your router inform other devices on the network that it should be >used as a time server? In the DHCP specification there is an option >called "time-servers". The idea is that a network administrator sets >this to be the approved time servers for the network and clients >synchronise to that. In debian, this is facilitated by >/etc/dchp/dhclient-exit-hooks.d/ntp (at least, if you use the ISC DHCP >client). That script will read the "time-servers" option from the DHCP >packet, write /var/lib/ntp/ntp.conf.dhcp and ensure that file is >included from your main ntp.conf. As far as I'm aware, this is default >behaviour. > >> >>But a manpage that actually tells us how to do that must be sick bird, >>because its not been written yet. Man page writers please get real, and >>tell us how to do something like getting our home networks all >>synchronized to our routers which can then broadcast it to the rest of >>our network. > >There's an XY problem here. You probably shouldn't put this information >into the NTP man pages, as it's not NTP that's doing the work. The >information about the "time-servers" option *is* in the DHCP manpage, >but probably there's no information about the specific hook being >included. My mistake, the correct option is "ntp-servers". https://support.ntp.org/bin/view/Support/ConfiguringNTP#Section_6.12. > >If the NTP hook is Debian-specific, then... I don't know where that >should be documented. If it's upstream, then... Well, if every project >documented every decision for creating every file, then there'd be a lot >to wade through. > >> >>Such a scheme can easily keep us on time with any errors within a few >>milliseconds, more than adequate enough for the girls I go with. While >>reducing the load on the servers by at least 80%. >> >>So how about a manpage that tells us how to do that? If its not illegal >>according to some rfc that is. >> >>Rant off. >> >>Thanks for reading. >> >>Cheers, Gene Heskett >>-- >>"There are four boxes to be used in defense of liberty: >>soap, ballot, jury, and ammo. Please use in that order." >>-Ed Howdershelt (Author) >>Genes Web page <http://geneslinuxbox.net:6309/gene> >> > >-- >For more information, please reread. -- For more information, please reread.
[toc] | [prev] | [next] | [standalone]
| From | Gene Heskett <gheskett@shentel.net> |
|---|---|
| Date | 2017-06-08 01:10 +0200 |
| Message-ID | <tPSfs-4Fa-121@gated-at.bofh.it> |
| In reply to | #181887 |
On Wednesday 07 June 2017 10:54:26 Darac Marjal wrote: > On Wed, Jun 07, 2017 at 10:35:23AM -0400, Gene Heskett wrote: > >On Wednesday 07 June 2017 08:56:59 ray wrote: > >> I would like to know the correct syntax for entering a server entry > >> for stretch. > >> > >> All the documentation I find says to list the ntp servers in the > >> file as: server 0.XX.pool.ntp.org > >> server 1.XX.pool.ntp.org > >> > >> An example source from 2017 is https://wiki.debian.org/DateTime > >> > >> When I open /etc/ntp.conf on my new stretch installation, I find > >> this format: pool 0.debian.pool.ntp.org iburst > >> pool 1.debian.pool.ntp.org iburst > >> > >> The latest Debian doc says to start the line with 'server'. > >> The latest Debian implementation starts the line with 'pool'. > >> > >> Are these interchangeable? > > As I understand it "server" will do name resolution once and pick an > IP from the result. "pool" will periodically refresh the name and > cycle to a different member of the pool. > > >> Additionally, there is a parameter 'iburst' which I did not find in > >> the Debian docs but found at http://doc.ntp.org/4.1.1/confopt.htm > > Did you install ntp-doc? Did you check there? I haven't gotten around to checking that, its on a raspberry pi3b, which has a fan on its heat sinks, but isn't terribly stable, I've locked it up tight at least a dozen times so far today with my horsing around. But I did appear to get ntp to do its job, by adding "server " in front of the fqdn's in /etc/ntp.conf. [...] Now, if I could just make it use the routers broadcasts. Or could at least prove it is broadcasting. Yes it is, I caught a broadcast at xx.xx.xx.255: 14:16:14.760909 IP coyote.coyote.den.ntp > xx.xx.xx.255.ntp: NTPv4, Broadcast, length 48 So it is broadcasting. Now the trick is to make the rest of my machines use it. Hints & examnples welcomed. And I did install ntp-doc just now. A wee bit more verbose, but still no examples. Cheers, Gene Heskett -- "There are four boxes to be used in defense of liberty: soap, ballot, jury, and ammo. Please use in that order." -Ed Howdershelt (Author) Genes Web page <http://geneslinuxbox.net:6309/gene>
[toc] | [prev] | [next] | [standalone]
| From | Darac Marjal <mailinglist@darac.org.uk> |
|---|---|
| Date | 2017-06-08 14:30 +0200 |
| Message-ID | <tQ4JA-4eB-17@gated-at.bofh.it> |
| In reply to | #181902 |
[Multipart message — attachments visible in raw view] — view raw
On Wed, Jun 07, 2017 at 07:00:52PM -0400, Gene Heskett wrote: >On Wednesday 07 June 2017 10:54:26 Darac Marjal wrote: > >> On Wed, Jun 07, 2017 at 10:35:23AM -0400, Gene Heskett wrote: >> >On Wednesday 07 June 2017 08:56:59 ray wrote: >> >> I would like to know the correct syntax for entering a server entry >> >> for stretch. >> >> >> >> All the documentation I find says to list the ntp servers in the >> >> file as: server 0.XX.pool.ntp.org >> >> server 1.XX.pool.ntp.org >> >> >> >> An example source from 2017 is https://wiki.debian.org/DateTime >> >> >> >> When I open /etc/ntp.conf on my new stretch installation, I find >> >> this format: pool 0.debian.pool.ntp.org iburst >> >> pool 1.debian.pool.ntp.org iburst >> >> >> >> The latest Debian doc says to start the line with 'server'. >> >> The latest Debian implementation starts the line with 'pool'. >> >> >> >> Are these interchangeable? >> >> As I understand it "server" will do name resolution once and pick an >> IP from the result. "pool" will periodically refresh the name and >> cycle to a different member of the pool. >> >> >> Additionally, there is a parameter 'iburst' which I did not find in >> >> the Debian docs but found at http://doc.ntp.org/4.1.1/confopt.htm >> >> Did you install ntp-doc? Did you check there? > >I haven't gotten around to checking that, its on a raspberry pi3b, which >has a fan on its heat sinks, but isn't terribly stable, I've locked it >up tight at least a dozen times so far today with my horsing around. > >But I did appear to get ntp to do its job, by adding "server " in front >of the fqdn's in /etc/ntp.conf. > >[...] > >Now, if I could just make it use the routers broadcasts. Or could at >least prove it is broadcasting. Yes it is, I caught a broadcast at >xx.xx.xx.255: Apparently, the word "broadcastclient" in ntp.conf is what you want: broadcastclient Enable reception of broadcast server messages to any local interface (type b address). Ordinarily, upon receiving a broadcast message for the first time, the broadcast client measures the nominal server propagation delay using a brief client/server exchange, after which it continues in listen-only mode. If a nonzero value is specified in the broadcastdelay command, the value becomes the delay and the volley is not executed. Note: the novolley option has been deprecated for future enhancements. Note that, in order to avoid accidental or malicious disruption in this mode, both the server and client should operate using symmetric key or public key authentication as described in the Authentication Options page. Note that the volley is required with public key authentication in order to run the Autokey protocol. This information IS in the ntp.conf manpage, and fairly apparent if searching that for the work "broadcast". > >14:16:14.760909 IP coyote.coyote.den.ntp > xx.xx.xx.255.ntp: NTPv4, >Broadcast, length 48 > >So it is broadcasting. Now the trick is to make the rest of my machines >use it. Hints & examnples welcomed. > >And I did install ntp-doc just now. A wee bit more verbose, but still no >examples. > >Cheers, Gene Heskett >-- >"There are four boxes to be used in defense of liberty: > soap, ballot, jury, and ammo. Please use in that order." >-Ed Howdershelt (Author) >Genes Web page <http://geneslinuxbox.net:6309/gene> > -- For more information, please reread.
[toc] | [prev] | [next] | [standalone]
| From | "Adiel Plasencia Herrera" <adielp@estereocentro.icrt.cu> |
|---|---|
| Date | 2017-06-08 14:50 +0200 |
| Subject | Re: https_port |
| Message-ID | <tQ52V-4l3-1@gated-at.bofh.it> |
| In reply to | #181921 |
[Multipart message — attachments visible in raw view] — view raw
How to generate the certificate and the key to make a very basic
configuration of the https connection.
As basic as possible.
regards
On 08/06/17 03:28, Adiel Plasencia Herrera wrote:
>>Hello,>>They would help me with a configuration of my squid that I want
to>implement.>>My proxy passes all traffic to a parent proxy and I want
clients to>connect to my proxy via https.>>Can you help me how to implement
the connection to my proxy via https?>>To better explain what I want
attached 2 pictures. The image with>1.jpg name shows my proxy configuration
with type HTTp that connects>well to internet.>>What I want is for the
connection to my proxy to be by the form of the>2.jpg image that uses the
HTTPS type.>>Or if it is possible then leave the 2 forms.
What operating system are you using, and what applications are you
wanting to use this proxy connection?
The normal configuration is simply to add an https_port line with cert=
parameter to your squid.conf. More details on that below.
>>>This is my current configuration:>acl trabajadores src 10.5.7.3
10.5.7.5><snip>
>>http_access allow trabajadores>http_access deny !Safe_ports>http_access
deny CONNECT !SSL_ports
You custom http_access rules ("allow trabajadores") should be down here
after the basic security checks.
>http_access deny all>>>http_port 3128
Date: Thu, 8 Jun 2017 01:04:31 +1200
From: Amos Jeffries <squid3@treenet.co.nz>
To: squid-users@lists.squid-cache.org
Subject: Re: [squid-users] https_port
Message-ID: <764ecd5f-6f6c-0eb5-90b4-5591ab5e1920@treenet.co.nz>
Content-Type: text/plain; charset=utf-8; format=flowed
The above port is for receiving plain-text connections to the proxy.
Most software supports this, with a few exceptions (usually Java apps).
To accept TLS connections to the proxy (not HTTPS *over* the proxy),
what you do is add an https_port line here. That https_port line needs a
cert= parameter containing the proxy server certificate. You may need
other TLS/SSL parameters to fine tune what the TLS does, but just start
with getting that basic setup to work.
<http://www.squid-cache.org/Doc/config/https_port/
[http://www.squid-cache.org/Doc/config/https_port/]>
For example:
https_port 3129 cert=/etc/squid/proxy.pem
(the proxy.pem file here contains both the public server cert and
private server key for that cert).
Many GUI applications (most notably browsers) do not support this type
of connection to a proxy (or not well if they do). Which is where the
Q's about your OS and applications come in. You may need to setup
environment variables or PAC files to get the applications to work.
Note that this is *very* different situation to intercepting port 443
traffic. Much more different than port 3128 vs. intercepted port 80.
HTTPS traffic goes through these TLS proxy connections with
double-layered encryption, so this setup does *not* magically make the
proxy able to see inside HTTPS if that is what you are really after.
Amos
[toc] | [prev] | [next] | [standalone]
| From | Darac Marjal <mailinglist@darac.org.uk> |
|---|---|
| Date | 2017-06-08 15:30 +0200 |
| Subject | Re: https_port |
| Message-ID | <tQ5FE-4OD-13@gated-at.bofh.it> |
| In reply to | #181922 |
[Multipart message — attachments visible in raw view] — view raw
On Thu, Jun 08, 2017 at 08:41:14AM -0700, Adiel Plasencia Herrera wrote:
> How to generate the certificate and the key to make a very
> basic configuration of the https connection.
NTP doesn't use HTTPS. It uses its own port, it's own protocol and
implements standard cryptography in a manner more suited to the
protocol.
See https://www.eecis.udel.edu/~mills/ntp/html/autokey.html for more
details.
>
> As
> basic as possible.
> regards
>
>
>
>
>
>
> On 08/06/17 03:28, Adiel Plasencia Herrera wrote:
> > > Hello, > > They would help me with a
> configuration of my squid that I want to > implement. >
> > My proxy passes all traffic to a parent proxy and I want clients
> to > connect to my proxy via https. > > Can
> you help me how to implement the connection to my proxy via https?
> > > To better explain what I want attached 2 pictures. The
> image with > 1.jpg name shows my proxy configuration with type
> HTTp that connects > well to internet. > >
> What I want is for the connection to my proxy to be by the form of the
> > 2.jpg image that uses the HTTPS type. > > Or if
> it is possible then leave the 2 forms.
> What operating system are you using, and what applications are you
> wanting to use this proxy connection?
>
> The normal configuration is simply to add an https_port line with cert=
> parameter to your squid.conf. More details on that below.
>
>
> > > > This is my current configuration: >
> acl trabajadores src 10.5.7.3 10.5.7.5 > <snip>
> > > http_access allow trabajadores > http_access
> deny !Safe_ports > http_access deny CONNECT !SSL_ports
> You custom http_access rules ("allow trabajadores") should be down
> here
> after the basic security checks.
>
> > http_access deny all > > > http_port
> 3128
>
> Date: Thu, 8 Jun 2017 01:04:31 +1200
> From: Amos Jeffries <squid3@treenet.co.nz>
> To: squid-users@lists.squid-cache.org
> Subject: Re: [squid-users] https_port
> Message-ID: <764ecd5f-6f6c-0eb5-90b4-5591ab5e1920@treenet.co.nz
> >
> Content-Type: text/plain; charset=utf-8; format=flowed
> The above port is for receiving plain-text connections to the proxy.
> Most software supports this, with a few exceptions (usually Java apps).
>
>
> To accept TLS connections to the proxy (not HTTPS *over* the proxy),
> what you do is add an https_port line here. That https_port line needs a
> cert= parameter containing the proxy server certificate. You may need
> other TLS/SSL parameters to fine tune what the TLS does, but just start
> with getting that basic setup to work.
> <
> [1]http://www.squid-cache.org/Doc/config/https_port/>
>
> For example:
> https_port 3129 cert=/etc/squid/proxy.pem
>
> (the proxy.pem file here contains both the public server cert and
> private server key for that cert).
>
> Many GUI applications (most notably browsers) do not support this type
> of connection to a proxy (or not well if they do). Which is where the
> Q's about your OS and applications come in. You may need to setup
> environment variables or PAC files to get the applications to work.
>
>
> Note that this is *very* different situation to intercepting port 443
> traffic. Much more different than port 3128 vs. intercepted port 80.
> HTTPS traffic goes through these TLS proxy connections with
> double-layered encryption, so this setup does *not* magically make the
> proxy able to see inside HTTPS if that is what you are really after.
>
> Amos
>
>References
>
> Visible links
> 1. http://www.squid-cache.org/Doc/config/https_port/
--
For more information, please reread.
[toc] | [prev] | [next] | [standalone]
| From | Henrique de Moraes Holschuh <hmh@debian.org> |
|---|---|
| Date | 2017-06-08 17:00 +0200 |
| Subject | Re: https_port |
| Message-ID | <tQ74J-5AT-5@gated-at.bofh.it> |
| In reply to | #181925 |
On Thu, 08 Jun 2017, Darac Marjal wrote: > On Thu, Jun 08, 2017 at 08:41:14AM -0700, Adiel Plasencia Herrera wrote: > >How to generate the certificate and the key to make a very > >basic configuration of the https connection. > > NTP doesn't use HTTPS. It uses its own port, it's own protocol and > implements standard cryptography in a manner more suited to the > protocol. > > See https://www.eecis.udel.edu/~mills/ntp/html/autokey.html for more > details. Don't bother with autokey, it is not worth the pain. If you can use ntp symmetric key authentication, that one should take care of your servers well enough. There is no security for anything that is based on SNTP, though (that "S" is for Simple, not Secure), you'd have to do it in a lower layer (local firewall, IPSEC AH, whatever). -- Henrique Holschuh
[toc] | [prev] | [next] | [standalone]
| From | "Adiel Plasencia Herrera" <adielp@estereocentro.icrt.cu> |
|---|---|
| Date | 2017-06-08 17:20 +0200 |
| Subject | Re: https_port |
| Message-ID | <tQ7o6-5X8-9@gated-at.bofh.it> |
| In reply to | #181933 |
[Multipart message — attachments visible in raw view] — view raw
Hello, I do not look for security, is that having no real internet ip in my company I need certain programs to go to the internet and for that I use proxycap (http://www.proxycap.com/) that makes me this function perfectly through the proxy . What happens is that with HTTP does not work and I need to pass my squid to use HTTPS authentication for the program (proxycap) to work well. A friend told me that for https_port to work I needed validated certificates, not self-generated ones. I do not know to what extent this has to be so because the configuration I need is customized for me only and would be internal to my company that does not have visibility to the internet because this squid is a child of another that is the one that has the real internet ip . I need the help to correctly create those certificates and the options to put in the line https_port. I am very novice in squid and linux. Thank you -----Original Message----- From: Henrique de Moraes Holschuh <hmh@debian.org> To: debian-user@lists.debian.org Date: Thu, 8 Jun 2017 11:55:38 -0300 Subject: Re: https_port On Thu, 08 Jun 2017, Darac Marjal wrote: > On Thu, Jun 08, 2017 at 08:41:14AM -0700, Adiel Plasencia Herrera wrote: > >How to generate the certificate and the key to make a very > >basic configuration of the https connection. > > NTP doesn't use HTTPS. It uses its own port, it's own protocol and > implements standard cryptography in a manner more suited to the > protocol. > > See https://www.eecis.udel.edu/~mills/ntp/html/autokey.html [https://www.eecis.udel.edu/~mills/ntp/html/autokey.html] for more > details. Don't bother with autokey, it is not worth the pain. If you can use ntp symmetric key authentication, that one should take care of your servers well enough. There is no security for anything that is based on SNTP, though (that "S" is for Simple, not Secure), you'd have to do it in a lower layer (local firewall, IPSEC AH, whatever). -- Henrique Holschuh
[toc] | [prev] | [next] | [standalone]
| From | Darac Marjal <mailinglist@darac.org.uk> |
|---|---|
| Date | 2017-06-08 17:30 +0200 |
| Subject | Re: https_port |
| Message-ID | <tQ7xN-60p-43@gated-at.bofh.it> |
| In reply to | #181934 |
[Multipart message — attachments visible in raw view] — view raw
On Thu, Jun 08, 2017 at 11:18:16AM -0700, Adiel Plasencia Herrera wrote: > Hello, > I do not look for security, is that having no real internet ip in my > company I need certain programs to go to the internet and for that I > use proxycap (http://www.proxycap.com/) that makes me this function > perfectly through the proxy . What happens is that with HTTP does not > work and I need to pass my squid to use HTTPS authentication for the > program (proxycap) to work well. I don't think squid works with NTP at all, but it's been a few years since I played with Squid, so maybe someone else will be able to give better advice. > > A friend told me that for https_port to work I needed validated > certificates, not self-generated ones. I do not know to what extent > this has to be so because the configuration I need is customized for > me only and would be internal to my company that does not have > visibility to the internet because this squid is a child of another > that is the one that has the real internet ip . > > I need the help to correctly create those certificates and the > options to put in the line https_port. > > I am very novice in squid and linux. > > Thank you > > -----Original Message----- > From: Henrique de Moraes Holschuh <hmh@debian.org> > To: debian-user@lists.debian.org > Date: Thu, 8 Jun 2017 11:55:38 -0300 > Subject: Re: https_port > > On Thu, 08 Jun 2017, Darac Marjal wrote: > > On Thu, Jun 08, 2017 at 08:41:14AM -0700, Adiel Plasencia Herrera > wrote: > > >How to generate the certificate and the key to make a very > > >basic configuration of the https connection. > > > > NTP doesn't use HTTPS. It uses its own port, it's own protocol > and > > implements standard cryptography in a manner more suited to the > > protocol. > > > > See [1]https://www.eecis.udel.edu/~mills/ntp/html/autokey.html > for more > > details. > > Don't bother with autokey, it is not worth the pain. If you can > use ntp > symmetric key authentication, that one should take care of your > servers > well enough. > > There is no security for anything that is based on SNTP, though > (that > "S" is for Simple, not Secure), you'd have to do it in a lower > layer > (local firewall, IPSEC AH, whatever). > > -- > Henrique Holschuh > >References > > Visible links > 1. https://www.eecis.udel.edu/~mills/ntp/html/autokey.html -- For more information, please reread.
[toc] | [prev] | [next] | [standalone]
| From | Greg Wooledge <wooledg@eeg.ccf.org> |
|---|---|
| Date | 2017-06-08 17:40 +0200 |
| Subject | Re: https_port |
| Message-ID | <tQ7Hs-63v-21@gated-at.bofh.it> |
| In reply to | #181935 |
On Thu, Jun 08, 2017 at 04:25:11PM +0100, Darac Marjal wrote: > On Thu, Jun 08, 2017 at 11:18:16AM -0700, Adiel Plasencia Herrera wrote: > > Hello, > > I do not look for security, is that having no real internet ip in my > > company I need certain programs to go to the internet and for that I > > use proxycap (http://www.proxycap.com/) that makes me this function > > perfectly through the proxy . What happens is that with HTTP does not > > work and I need to pass my squid to use HTTPS authentication for the > > program (proxycap) to work well. > > I don't think squid works with NTP at all, but it's been a few years > since I played with Squid, so maybe someone else will be able to give > better advice. I don't think he's *asking* about NTP at all.
[toc] | [prev] | [next] | [standalone]
| From | Darac Marjal <mailinglist@darac.org.uk> |
|---|---|
| Date | 2017-06-08 17:50 +0200 |
| Subject | Re: https_port |
| Message-ID | <tQ7R8-66J-19@gated-at.bofh.it> |
| In reply to | #181936 |
[Multipart message — attachments visible in raw view] — view raw
On Thu, Jun 08, 2017 at 11:34:20AM -0400, Greg Wooledge wrote: >On Thu, Jun 08, 2017 at 04:25:11PM +0100, Darac Marjal wrote: >> On Thu, Jun 08, 2017 at 11:18:16AM -0700, Adiel Plasencia Herrera wrote: >> > Hello, >> > I do not look for security, is that having no real internet ip in my >> > company I need certain programs to go to the internet and for that I >> > use proxycap (http://www.proxycap.com/) that makes me this function >> > perfectly through the proxy . What happens is that with HTTP does not >> > work and I need to pass my squid to use HTTPS authentication for the >> > program (proxycap) to work well. >> >> I don't think squid works with NTP at all, but it's been a few years >> since I played with Squid, so maybe someone else will be able to give >> better advice. > >I don't think he's *asking* about NTP at all. > Ah. You mean he's a politician (replying to a topic by introducing one's own, unrelated, topic)? -- For more information, please reread.
[toc] | [prev] | [next] | [standalone]
Page 1 of 3 [1] 2 3 Next page →
Back to top | Article view | linux.debian.user
csiph-web