ntpd: Added option to disable strict ACLs for isc-ntpd

This commit is contained in:
Ossi Salmi 2013-06-13 12:28:38 +03:00
parent 7a335ec644
commit 246816f417
2 changed files with 20 additions and 2 deletions

View file

@ -6,6 +6,11 @@
# Array of NTP servers using [] will disable external servers. # Array of NTP servers using [] will disable external servers.
# Defaults to pool.ntp.org. # Defaults to pool.ntp.org.
# #
# $ntp_strict:
# When set to "false", permit time synchronization by default. Required
# for pool.ntp.org or similar server names which have multiple addresses.
# Defaults to "true".
#
# $ntp_client_networks: # $ntp_client_networks:
# Array of networks that are allowed to query this server in format # Array of networks that are allowed to query this server in format
# [ "192.168.1.0/255.255.255.0", "192.168.2.0/255.255.255.0", ] or # [ "192.168.1.0/255.255.255.0", "192.168.2.0/255.255.255.0", ] or
@ -17,6 +22,10 @@ class ntpd {
$ntp_server = ["pool.ntp.org"] $ntp_server = ["pool.ntp.org"]
} }
if !$ntp_strict {
$ntp_strict = "true"
}
case $::operatingsystem { case $::operatingsystem {
"fedora": { "fedora": {
case $::operatingsystemrelease { case $::operatingsystemrelease {

View file

@ -3,13 +3,20 @@
tinker panic 0 tinker panic 0
<% end -%> <% end -%>
<% if @ntp_strict == "true" -%>
# By default deny everything. # By default deny everything.
restrict -4 default ignore restrict -4 default ignore
restrict -6 default ignore restrict -6 default ignore
<% else -%>
# Permit time synchronization with our time source, but do not
# permit the source to query or modify the service on this system.
restrict -4 default nomodify notrap nopeer noquery
restrict -6 default nomodify notrap nopeer noquery
<% end -%>
# Local users may interrogate the ntp server more closely. # Local users may interrogate the ntp server more closely.
restrict 127.0.0.1 restrict 127.0.0.1 nomodify
restrict ::1 restrict ::1 nomodify
# Drift file. # Drift file.
driftfile /var/lib/ntp/ntp.drift driftfile /var/lib/ntp/ntp.drift
@ -17,7 +24,9 @@ driftfile /var/lib/ntp/ntp.drift
# Remote servers. # Remote servers.
<% @ntp_server.each do |server| -%> <% @ntp_server.each do |server| -%>
server <%= server %> server <%= server %>
<% if @ntp_strict == "true" -%>
restrict <%= server %> nomodify notrap nopeer noquery restrict <%= server %> nomodify notrap nopeer noquery
<% end -%>
<% end -%> <% end -%>
<% if @is_virtual == "false" -%> <% if @is_virtual == "false" -%>