Authentication
The time kept on a machine is a critical resource, so it is highly recommended to use the encrypted authentication mechanism.
NTP can be configured to provide cryptographic authentication of messages with the clients and peers, and with its upstream time server. A symmetric key scheme is supported for authentication. The scheme uses an MD5 keyed hash algorithm.
The authentication can be enabled using the
authenticate
command. The symmetric key and key string set is specified using the authentication-key command.
If authentication is enabled, NTP packets not having a valid MAC address are dropped.
If the NTP server or peer is configured without authentication keys, the NTP request is not sent to the configured server or peer.