join
donate

Configuration and Authorization Levels for ntpd

Background and History

Analysis

BrianUtterback suggests we need to classify operations on data types as follows:

  • public-read-only
  • private-read-only
  • safe-write
  • unsafe-write

Proposals

In the context of prior discussions, safe-write would be any ntpq/ntpdc operation that changes the ntpd state, such as ntpq -c ":config tos minsane 3" except those segregated as particularly dangerous, risking not just timekeeping but the system on which it runs, including:

ntpq -c "saveconfig /path/to/overwrite"
ntpq -c ":config logfile /path/to/appendfile"
ntpq -c ":config enable stats"
ntpq -c ":config filegen ..."

-- DaveHart - 16 Sep 2009

Do we need a table of ntpq and ntpdc directives and state which category they fall under?

-- HarlanStenn - 16 Sep 2009

 


This topic: Dev > WebHome > DevelopmentIssues > ConfigurationAndAuthorizationLevelsForNtpd
Topic revision: r3 - 2009-09-16 - 06:23:21 - HarlanStenn
 
SSL security by CAcert
Get the CAcert Root Certificate
This site is powered by the TWiki collaboration platform
IPv6 Ready
Copyright & 1999-2020 by the contributing authors. All material on this collaboration platform is the property of the contributing authors. Ideas, requests, problems regarding the site? Send feedback