Re: [ntp:questions] Is there something with greater detail on interface besides the manpage?

2013-11-21 Thread David Woolley
On 21/11/13 00:54, John Hasler wrote: The CAcert certificate is included by Debian, most other Linux distributions, and by OpenBSD. It is at least as trustworthy as most commercial certificates. That's mainly because Microsoft accepts so many obscure certifiers by default and. However, as I

Re: [ntp:questions] Pool returns IPv6 address to IPv4 query

2013-11-21 Thread Casper H . S . Dik
Rob nom...@example.com writes: Uwe Klein u...@klein-habertwedt.de wrote: However, what I don't understand is why an IPv6 address does not fit into a struct sockaddr, and why this fact is so badly documented. It took me a lot of time to find why my queried IPv6 addresses were truncated.

Re: [ntp:questions] Pool returns IPv6 address to IPv4 query

2013-11-21 Thread Rob
Uwe Klein u...@klein-habertwedt.de wrote: However, what I don't understand is why an IPv6 address does not fit into a struct sockaddr, and why this fact is so badly documented. It took me a lot of time to find why my queried IPv6 addresses were truncated. struct sockaddr was a catch all and

Re: [ntp:questions] Pool returns IPv6 address to IPv4 query

2013-11-21 Thread Rob
Casper H.S Dik casper@orspamcle.com wrote: Rob nom...@example.com writes: Uwe Klein u...@klein-habertwedt.de wrote: However, what I don't understand is why an IPv6 address does not fit into a struct sockaddr, and why this fact is so badly documented. It took me a lot of time to find why

Re: [ntp:questions] Is there something with greater detail on interface besides the manpage?

2013-11-21 Thread E-Mail Sent to this address will be added to the BlackLists
mike cook wrote: I plugged certificates into the NTF web sites search box and got no hits. Is there a policy doc on this? As a comment to lead OL. We are now in a situation where we can only trust our enemies. CAcert.org is an Australian based org IIRC. They are in the same Trust

Re: [ntp:questions] Public ntp-server and reflection-attacks

2013-11-21 Thread theservman
On Thursday, 21 November 2013 11:42:39 UTC-5, Rudolf E. Steiner wrote: Hi. We have strong reflection-attacks on our public timeserver (ntpd 4.2.6p5). The strange behavior is the server received one packet and sends 100 packets to the target. Incoming packet: -

[ntp:questions] Public ntp-server and reflection-attacks

2013-11-21 Thread Rudolf E. Steiner
Hi. We have strong reflection-attacks on our public timeserver (ntpd 4.2.6p5). The strange behavior is the server received one packet and sends 100 packets to the target. Incoming packet: - begin - Network Time Protocol (NTP Version 2, private) Flags: 0x17 0... = Response bit:

Re: [ntp:questions] Public ntp-server and reflection-attacks

2013-11-21 Thread Michael Sinatra
On 11/21/2013 08:42, Rudolf E. Steiner wrote: Hi. We have strong reflection-attacks on our public timeserver (ntpd 4.2.6p5). The strange behavior is the server received one packet and sends 100 packets to the target. Yes, this is becoming increasingly common, and everyone operating NTP

Re: [ntp:questions] Public ntp-server and reflection-attacks

2013-11-21 Thread theservman
Now that I've had some quality time with Wireshark, I can confirm that I'm seeing exactly what Rudolph was seeing. Since implementing Michael's suggesting, I'm still getting the packets, but not responding to them. That will do for now... Ian ___

Re: [ntp:questions] Public ntp-server and reflection-attacks

2013-11-21 Thread Rudolf E. Steiner
Michael Sinatra wrote: I believe the key command is 'noquery' which means that the server can't be queried for information (it does NOT affect the server's ability to respond to time requests). That's it. To simple. RTFM! :-( I have deleted noquery at the time of installation. I thought it

Re: [ntp:questions] how did ntp service set the maxallowphaseoffset

2013-11-21 Thread xiaoniao112233
在 2013年11月20日星期三UTC+8上午8时17分32秒,David Woolley写道: On 19/11/13 08:41, Brian Inglis wrote: Someone else asked: what are you trying to do by changing this parameter? The defaults have been set based on running and simulating different control algorithms, settings, and scenarios.

Re: [ntp:questions] Is there something with greater detail on interface besides the manpage?

2013-11-21 Thread Richard B. Gilbert
On 11/21/2013 8:27 AM, John Hasler wrote: mike cook writes: As a comment to lead OL. We are now in a situation where we can only trust our enemies. CAcert.org is an Australian based org IIRC. They are in the same Trust league as the US, UK, CAN, all of whom have proved to be woefully lacking in

Re: [ntp:questions] Is there something with greater detail on interface besides the manpage?

2013-11-21 Thread John Hasler
mike cook writes: As a comment to lead OL. We are now in a situation where we can only trust our enemies. CAcert.org is an Australian based org IIRC. They are in the same Trust league as the US, UK, CAN, all of whom have proved to be woefully lacking in probity. Are you afraid that the NSA is

Re: [ntp:questions] Pool returns IPv6 address to IPv4 query

2013-11-21 Thread Rick Jones
Rob nom...@example.com wrote: You need to jump through different hoops now, and the man page will tell you *nothing* about that. Neither will the abundant examples on the net. You will need to bump into exactly the right comment on an obscure forum (as it is today...) to know about

Re: [ntp:questions] Is there something with greater detail on interface besides the manpage?

2013-11-21 Thread John Hasler
David Woolley writes: Actually I would expect the name on their root certificates, the generic Root CA to send warning bells to anyone who was security conscious, but not already familiar with them. Anyone who is really serious about security will accept certificates only in person, by hand

[ntp:questions] False sender addresses

2013-11-21 Thread Steve Kostecke
On 2013-11-21, Greg Troxel g...@ir.bbn.com wrote: From: E-Mail Sent to this address will be added to the BlackLists Null@BlackList.Anitech-Systems.invalid I might have sent this by private mail, but the sender is both stating they will ignore replies and being anonymous. Two

Re: [ntp:questions] Public ntp-server and reflection-attacks

2013-11-21 Thread Steve Kostecke
On 2013-11-21, Michael Sinatra mich...@rancid.berkeley.edu wrote: There are several ways, but having a basic 'restrict' statement in your config like this will help mitigate [reflection attacks]: restrict default noquery nomodify notrap nopeer restrict -6 default noquery nomodify notrap