On Mon, 2009-11-09 at 15:00 +0100, Kai Hauser wrote: 
> As you can see something went terribly wrong with this server :)
> My question now is how can we avoid our servers accepting wrong time
> informations.

Hmm... the point of selecting more than one NTP server is to reduce the
chance of this happening.  It looks like you've done so.  The software
on your end should detect that the bad server is an outlier and ignore
it.  ntpd does this quite well, but I haven't used chrony in awhile.
Might be worth checking the documentation to see if there's a setting...

Of course, in the "long run" the bad server will be automatically
removed from the pool, but that takes a relatively long time and won't
help those with long-running NTP daemons.  At an average of 30
queries/second, a lot of people would enjoy a very bad time if my server
goes nuts!  -rt

-- 
Ryan Tucker <[email protected]>

Attachment: signature.asc
Description: This is a digitally signed message part

_______________________________________________
timekeepers mailing list
[email protected]
https://fortytwo.ch/mailman/cgi-bin/listinfo/timekeepers

Reply via email to