chrony-4.0-pre1 released

Miroslav Lichvar <[email protected]> Mon, 16 Mar 2020 17:29:06 +0100
Newsgroups gmane.comp.time.chrony.announce
Message-ID <20200316162906.GA31477__43745.6977366068$1584376701$gmane$org@localhost>
--PNTmBPCT7hxwcZjr
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable

The first prerelease for chrony-4.0 is now available.

The main new feature is support for the Network Time Security (NTS)
authentication mechanism based on TLS and AEAD, which enables NTP
servers to securely provide time to a large number of clients (no need
to share keys in the key file). GnuTLS and Nettle are required for the
NTS support. Please note that the specification is not finalised yet
and some values like the NTS-KE port number are expected to change.

Cloudflare and Netnod run public NTP servers with NTS. They can be
specified in chrony.conf with:
server time.cloudflare.com nts ntsport 1234 iburst                         =
                                              =20
server nts.ntp.se nts ntsport 4443 iburst                                  =
                                              =20

The source code can be downloaded here:
https://download.tuxfamily.org/chrony/chrony-4.0-pre1.tar.gz

SHA256 sum:
c89c4e91e9f16ae815c70120a0b72050cc6838b2467ff43a1f4057573df0529b

Changes since version 3.5:

Enhancements
------------
* Add support for Network Time Security (NTS) authentication
* Add support for AES-CMAC keys (AES128, AES256) with Nettle
* Add support for maxsamples of 1 for faster update with -q/-Q option
* Add -L option to limit log messages by severity
* Avoid replacing NTP sources with unreachable addresses
* Improve NTP loop test to prevent synchronisation to itself
* Update clock synchronisation status and leap status more frequently
* Update seccomp filter
* Add "add pool" command
* Add -N option and sourcename command to print original names of sources
* Add -a option to source/sourcestats command to print unresolved sources
* Add reset command to drop all measurements

Bug fixes
---------
* Handle RTCs that don't support interrupts
* Respond to command requests with correct address on multihomed hosts

Removed features
----------------
* Drop support for RIPEMD keys (RMD128, RMD160, RMD256, RMD320)

--=20
Miroslav Lichvar

--PNTmBPCT7hxwcZjr
Content-Type: application/pgp-signature; name="signature.asc"

-----BEGIN PGP SIGNATURE-----

iF0EABECAB0WIQSLH0qa2nPUAeMIWgtf8G8puh4BOwUCXm+pTAAKCRBf8G8puh4B
OypXAJwIVNV27nMgNIaGuLZCJBbFKHUZXQCaAhwoD55vr8sJLEu0r4crox9JOwQ=
=valx
-----END PGP SIGNATURE-----

--PNTmBPCT7hxwcZjr--


-- 
To unsubscribe email chrony-announce-request-kWFZVVI9zxvPqho9SqqRMmD2FQJk+8+b@public.gmane.org with "unsubscribe" in the subject.
For help email chrony-announce-request-kWFZVVI9zxvPqho9SqqRMmD2FQJk+8+b@public.gmane.org with "help" in the subject.
Trouble?  Email [email protected]