NTP users are strongly urged to take immediate action to ensure that their NTP daemons are not susceptible to being used in distributed denial-of-service (DDoS) attacks. Please also take this opportunity to defeat denial-of-service attacks by implementing Ingress and Egress filtering through BCP38.

ntp-4.2.8p13 was released on 07 March 2019. It addresses 1 medium-severity security issue in ntpd, and provides 17 non-security bugfixes and 1 other improvements over 4.2.8p12.

Please see the NTP Security Notice for vulnerability and mitigation details.

Are you using Autokey in production? If so, please contact Harlan - he's got some questions for you.

NTP Pool Time Servers

pool.ntp.org uses DNS round robin to make a random selection from a pool of time servers who have volunteered to be in the pool. This is often good enough for end-users. The minimal ntpd configuration file (e.g. /etc/ntpd.conf) for using pool.ntp.org is:

driftfile /var/lib/ntp/ntp.drift

server 0.pool.ntp.org
server 1.pool.ntp.org
server 2.pool.ntp.org
server pool.ntp.org

If you use only one pool server, we recommend you use the "bare" zone without a number, but if you use several, then use the numbered ones first.

ALERT! Any questions about the pool.ntp.org server pool should be directed either to the timekeepers@fortytwo.ch mailing list or to the comp.protocols.time.ntp usenet newsgroup.

IDEA! Time server operators are encouraged to visit the pool.ntp.org web-site to find out how they can join the NTP pool.

To make it possible to select a timeserver which is geographically close, we have sub-zones of pool.ntp.org. The "continent" ones are:

Area: HostName:
Worldwide pool.ntp.org
Asia asia.pool.ntp.org
Europe europe.pool.ntp.org
North America north-america.pool.ntp.org
Oceania oceania.pool.ntp.org
South America south-america.pool.ntp.org

There are also sub-zones for many countries. Click on your continent to see which country-zones are available there.

When using the by-country zones, be careful: some of them currently contain only one or two servers, so you are probably better off using either the zone of a nearby country, or using the continent or global zone (This is also valid if you live in a big country. For example, jp.pool.ntp.org has only one server!).

