Common Criteria compliance requires that NTP servers use SHA-1 authentication. After you apply compliance, NTP service may be interrupted.
When you apply Common Criteria compliance, the following changes are made:
All MD5-authorized NTP peers are deleted from the configuration. MD5 authentication is not supported in FIPS or CC compliance.
Trellix NTP pool servers are removed from the configuration because they do not support SHA-1 authentication.
If your configuration uses only unauthenticated peers or MD5-authenticated peers that are not compliant, no NTP peers remain after you apply compliance. If your configuration includes SHA-1-authorized NTP peers, they are retained.
To restore NTP service, use one of the following options.
Configure your own NTP servers with SHA-1 authorization. This option is fully compliant.
Opt out of full formal compliance by re-enabling the unauthenticated Trellix NTP server pool. Use the
compliance options ntp-default-servers enablecommand.Opt out of full formal compliance by configuring your own NTP servers with MD5 authorization or no authorization.
Set the clock manually using the
clock setcommand. This option is fully compliant but less accurate than the others.Use a non-compliant method such as temporarily enabling
ntpdor running thentpdatecommand one time only. If you want the time synchronized from multiple NTP servers, configure and enable ntp and wait for the time to fully synchronize with all peers, then disable ntpd usingno ntp enableimmediately after the clock is synchronized. If you need the time from only one ntp server, use thentpdatecommand to synchronize the clock with the specified server IP address.