network time default, f23

Reindl Harald h.reindl at thelounge.net
Tue Sep 1 11:01:44 UTC 2015


Am 01.09.2015 um 11:26 schrieb Miroslav Lichvar:
> chronyd doesn't implement server rate limiting (yet). It's not a high
> priority. It may sound like a useful feature, but it often actually
> increases the network traffic, because clients that send too many
> requests are often the ones that will quickly send another request
> when there is no reply from the server or it's told to reduce its
> polling rate.

it's a matter of security in case of amplification attacks to third 
parties since NTP is UDP like DNS and so *not* low priority

-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 181 bytes
Desc: OpenPGP digital signature
URL: <http://lists.fedoraproject.org/pipermail/server/attachments/20150901/34ae9faa/attachment.sig>


More information about the server mailing list