Re: NTP to Chrony migration issue with NTP authentication with symmetric keys

Michael Krell <[email protected]>
Newsgroups gmane.comp.time.chrony.user
Message-ID <CA+bk9uq=xuYSdhaRa4QSkH8XpgXt82Aon-OQyrWsA4j+-OLowA@mail.gmail.com>
I've modified the value in the chrony.keys file to include "HEX:";
retesting "chronyd -dd", now the output does not show the
"(NCR_ProcessRxUnknown)" log message.  There is still a "Receive timeout"
notice in the logs, and time synchronization is still not occurring.

Updated /etc/chrony.keys :

20      SHA1    HEX:421b67770525bde2e926354a88ae2f81c7c76108


I'm going to debug the NTP server side next and see if I can identify if it
is throwing any errors.

-Mike









On Mon, Nov 6, 2023 at 9:36 AM Miroslav Lichvar <[email protected]> wrote:

> On Mon, Nov 06, 2023 at 09:00:18AM -0600, Michael Krell wrote:
> > Our implementation currently uses ASCII keys, and follows the 'optional'
> > usage for ASCII (Per the man page for chrony.conf : " The key can be
> > specified as a string of ASCII characters not containing white space with
> > an optional *ASCII:* prefix, or...".
>
> > /etc/chrony.keys :
> >
> > 20      SHA1    421b67770525bde2e926354a88ae2f81c7c76108
>
> > /etc/ntp.keys:
> >
> > 20 SHA1 421b67770525bde2e926354a88ae2f81c7c76108  #RSA-SHA1-compliant
>
> This is not an ASCII key. ntpd interprets keys longer than 20
> characters as hexadecimal values, so you need to add HEX: to the key
> in chrony.keys.
>
> --
> Miroslav Lichvar
>
>
> --
> To unsubscribe email chrony-users-request-kWFZVVI9zxvPqho9SqqRMmD2FQJk+8+b@public.gmane.org
> with "unsubscribe" in the subject.
> For help email chrony-users-request-kWFZVVI9zxvPqho9SqqRMmD2FQJk+8+b@public.gmane.org
> with "help" in the subject.
> Trouble?  Email [email protected]
>
>
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.