NTP users are strongly urged to take immediate action to ensure that their NTP daemons are not susceptible to being used in distributed denial-of-service (DDoS) attacks. Please also take this opportunity to defeat denial-of-service attacks by implementing Ingress and Egress filtering through BCP38.
ntp-4.2.8p15 was released on 23 June 2020. It addresses 1 medium-severity security issue in ntpd, and provides 13 non-security bugfixes over 4.2.8p13.
Are you using Autokey in production? If so, please contact Harlan - he's got some questions for you.
For many years, the NTP source code was kept in a frequently-backed-up directory on a machine. The only "snapshots" we had of previous releases were whatever tarballs we kept of previous releases. In early '99, Harlan and Dave came to an agreement about how a code repository would have to behave and Harlan was finally able to import the codebase into CVS (knowing full well what the limitations of CVS were).
In less than a year, the pains of using CVS were becoming unbearable, and the search began for a replacement. Over a period of 2 years' time, all opensource Source Code Management (SCM) Systems were explored and tested and several commercial solutions were examined (to various degrees) as well. Fairly quickly, it became obvious that BitMover's BitKeeper
product was, hands-down and very clearly, the best SCM available for NTP. Its features included:
- distributed (and disconnected) operation
- integration areas
- useful triggers/hooks
- great merge capability
- the ability to have multiple active repositories (eg, one repo per bugfix)
- good performance
- rock-solid stability
- great support
- quick, simple and easy to use
- behaves well and, generally, "as expected"
Originally, the complete
software/executable was available to anybody who wanted to use it to work on opensource projects. A series of events happened that resulted in increased restrictions on the ability of many opensource projects to continue to use BitKeeper. Harlan remains Very Pleased that NTP managed to stay clear of that situation, and believes the NTP Project has benefited greatly from its use of BitKeeper.