Bug 61566
Summary: | dateconfig provides unsecure configuration for ntpd | ||
---|---|---|---|
Product: | [Retired] Red Hat Linux | Reporter: | Benjamin Shrom <benjamin_shrom> |
Component: | ntp | Assignee: | Brent Fox <bfox> |
Status: | CLOSED RAWHIDE | QA Contact: | |
Severity: | medium | Docs Contact: | |
Priority: | medium | ||
Version: | 7.2 | CC: | benjamin_shrom |
Target Milestone: | --- | Keywords: | Security |
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | Doc Type: | Bug Fix | |
Doc Text: | Story Points: | --- | |
Clone Of: | Environment: | ||
Last Closed: | 2002-03-25 16:36:49 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: |
Description
Benjamin Shrom
2002-03-21 16:30:04 UTC
Well, dateconfig just modifies the ntp.conf file and then calls 'service ntpd start'. The behavior you are describing is caused by ntpdc (which is part of the NTP RPM), not dateconfig. Changing component of the bug report to 'ntp'. As reported: _dateconfig_ provides _unsecure_ configuration for ntpd, which allows the use of ntpdc from any other host to reconfigure ntpd. This means: you can modify the timeserver remotly!!!! I think authenticate yes would be the best answer Ok, I've modified dateconfig to only change the 'server' line in your ntp.conf file. The dateconfig in Rawhide ( ftp://ftp.redhat.com/pub/redhat/linux/rawhide/i386/RedHat/RPMS/dateconfig-0.7.5-2.i386.rpm) does the right thing. If you have already set up an insecure configuration of ntp (or if the default ntp configuration is insecure) then dateconfig will not change that value. Dateconfig will only change the name of the server in the file. Correction: ftp://ftp.redhat.com/pub/redhat/linux/rawhide/i386/RedHat/RPMS/dateconfig-0.7.5-3.i386.rpm Not dateconfig-0.7.5-2.i386.rpm. Typo on my part. dateconfig-0.7.5-3 is available for IA-64 as well at: ftp://ftp.redhat.com/pub/redhat/linux/rawhide/ia64/RedHat/RPMS/ |