[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248392

 
 

909

 
 

195452

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CCE
view XML

CCE-95492-5

Platform: cpe:/o:amazon:linux:2, cpe:/o:centos:centos:7, cpe:/o:oracle:linux:7, cpe:/o:redhat:enterprise_linux:7Date: (C)2021-03-05   (M)2023-07-14



The Network Time Protocol (NTP) is designed to synchronize system clocks across a variety of systems and use a source that is highly accurate. More information on NTP can be found at http://www.ntp.org. NTP can be configured to be a client and/or a server. Rationale: It is recommended that physical systems and virtual guests lacking direct access to the physical hosts clock be configured as NTP clients to synchronize their clocks (especially to support time sensitive security mechanisms like Kerberos). This also ensures log files have consistent time records across the enterprise, which aids in forensic investigations. Fix: install ntp: # yum install ntp Ensure the following lines are in /etc/ntp.conf: restrict -4 default kod nomodify notrap nopeer noquery restrict -6 default kod nomodify notrap nopeer noquery Also, make sure /etc/ntp.conf has at least one NTP server specified: server Note: is the IP address or hostname of a trusted time server. Configuring an NTP server is outside the scope of this benchmark.


Parameter:

[yes/no]


Technical Mechanism:

install ntp: # yum install ntp Ensure the following lines are in /etc/ntp.conf: restrict -4 default kod nomodify notrap nopeer noquery restrict -6 default kod nomodify notrap nopeer noquery Also, make sure /etc/ntp.conf has at least one NTP server specified: server ntp-server Note: ntp-server is the IP address or hostname of a trusted time server. Configuring an NTP server is outside the scope of this benchmark.

CCSS Severity:CCSS Metrics:
CCSS Score : 8.6Attack Vector: NETWORK
Exploit Score: 3.9Attack Complexity: LOW
Impact Score: 4.7Privileges Required: NONE
Severity: HIGHUser Interaction: NONE
Vector: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:LScope: UNCHANGED
 Confidentiality: HIGH
 Integrity: LOW
 Availability: LOW
  

References:
Resource IdReference
SCAP Repo OVAL Definitionoval:org.secpod.oval:def:73043
SCAP Repo OVAL Definitionoval:org.secpod.oval:def:72938
SCAP Repo OVAL Definitionoval:org.secpod.oval:def:72729
SCAP Repo OVAL Definitionoval:org.secpod.oval:def:68643
SCAP Repo OVAL Definitionoval:org.secpod.oval:def:73085
SCAP Repo OVAL Definitionoval:org.secpod.oval:def:73086
SCAP Repo OVAL Definitionoval:org.secpod.oval:def:72832


OVAL    7
oval:org.secpod.oval:def:72938
oval:org.secpod.oval:def:72729
oval:org.secpod.oval:def:72832
oval:org.secpod.oval:def:68643
...
XCCDF    5
xccdf_org.secpod_benchmark_general_Amazon_Linux_AMI
xccdf_org.secpod_benchmark_general_CENTOS_7
xccdf_org.secpod_benchmark_general_Amazon_Linux_2
xccdf_org.secpod_benchmark_general_OEL_7
...

© SecPod Technologies