Bug 62238

Summary: default configuration is insecure
Product: [Retired] Red Hat Linux Reporter: Brent Fox <bfox>
Component: ntpAssignee: Harald Hoyer <harald>
Status: CLOSED RAWHIDE QA Contact: Brian Brock <bbrock>
Severity: medium Docs Contact:
Priority: high    
Version: 7.3CC: benjamin_shrom
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: i386   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2002-04-02 08:47:08 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On:    
Bug Blocks: 61901    

Description Brent Fox 2002-03-28 19:01:04 UTC
The default configuration file for ntp.conf has:

authenticate  no

This allows regular users to change the remote timeserver.  We should change the
default to:

authenticate  yes

Comment 1 Benjamin Shrom 2002-03-28 19:12:42 UTC
please, don't forget ia64 :-)

Comment 2 Harald Hoyer 2002-04-02 08:47:04 UTC
Or that one:

# Prohibit general access to this service.
restrict default ignore

# Permit systems on this network to synchronize with this
# time service.  Do not permit those systems to modify the
# configuration of this service.  Also, do not use those
# systems as peers for synchronization.
# restrict 192.168.1.0 mask 255.255.255.0 notrust nomodify notrap

# Permit time synchronization with our time source, but do not
# permit the source to query or modify the service on this system.
# restrict time.stuttgart.redhat.com noquery nomodify notrap

# Permit all access over the loopback interface.  This could
# be tightened as well, but to do so would effect some of
# the administrative functions.
# restrict 127.0.0.1



Comment 3 Harald Hoyer 2002-04-02 15:46:35 UTC
ntp-4.1.0b-6

Comment 4 Benjamin Shrom 2002-06-28 21:37:41 UTC
there is a new NTP package in RH7.3

what about 7.2 ?

It's still a security bug.