chrony With NTS, Time Nobody On The Path Can Move
chrony on EL 10 taking time over NTS (RFC 8915), so every measurement is authenticated and the NTP listener is closed. The live test waits for an NTS source to be selected, restarts chronyd to make it dump its NTS cookies and finds them, checks the daemon is not controlling a clock that is not its own, and asserts nothing listens on UDP 123. Original role, live-tested on Rocky Linux 10.
Verification
Live-testedReally deployed to a container sandbox, proven idempotent (a second run changes nothing), verified against the role’s assertions, then torn down.
Conformance
- Static validation (yamllint · ansible-lint)
Provenance
- SHA-256 checksum
- Signature (pending)
Functional
- Live-tested - applied, verified, destroyed
Last verified 2026-09-26 · podman 4.9.3 · ansible 2.21.4 · how we verify
Cite it in your README
badge · attributionPaste this beside the module in the repository that uses it. The badge is rendered from this artifact's verification record, so it reads live-tested because the record says so, and the link lands on this page.
[](https://www.iac-bazaar.com/catalog/ansible-chrony-nts?utm_source=syndication&utm_medium=readme&utm_campaign=artifact)
Ansible role 1.0.0, live-tested on IaC Bazaar: [chrony With NTS, Time Nobody On The Path Can Move](https://www.iac-bazaar.com/catalog/ansible-chrony-nts?utm_source=syndication&utm_medium=readme&utm_campaign=artifact)
```yaml
# chrony With NTS, Time Nobody On The Path Can Move: https://www.iac-bazaar.com/catalog/ansible-chrony-nts (download from your IaC Bazaar account)
```Preview:
Documentation
chrony-nts
Time nobody on the path can move. The role configures chrony to take its time over NTS (RFC 8915), so every measurement is authenticated: an attacker between this host and its servers can drop packets but cannot shift the clock. The NTP listener is closed, because a client does not need to answer anyone.
No download, and no version to pin. EL 10 packages chrony, so the role installs it by name and enables the unit the distribution ships. What the role owns is which servers are trusted, whether they are authenticated, whether this host answers NTP at all, and whether it may touch the clock.
The role decides whether the clock is this system's to set. On a host it is,
and chronyd steps and slews as normal. Inside a container it is NOT - the kernel
clock belongs to the machine underneath - so the role passes -x and chronyd
measures without touching it. The default reads
ansible_facts['virtualization_type'] rather than asking an operator to
remember, and the live test asserts the daemon logged
"Disabled control of system clock".
The live test needs CAP_SYS_TIME. The container the lane boots carries
it, and without it the kernel refuses the very call this role exists to make,
so the test would pass having changed nothing. The lane is therefore run as
live-ansible.sh ... --cap-add=SYS_TIME, and the receipt records it: a pass
under an added capability is not the same claim as a pass without one.
cmdport 0 also disables the UNIX command socket. It looks like the way to
stop chronyd answering command requests from the network, and it stops chronyc
answering at all. What this role does instead is leave the command socket alone
and close the NTP port with port 0.
chronyd refuses a /run/chrony it does not like, and carries on. If the
directory is not chrony:chrony 0750 it logs "Wrong permissions", DISABLES the
command socket, and runs perfectly well otherwise - so chronyc authdata then
answers "501 Not authorised" and a test reads that as an NTS failure. The role
does not create that directory: the package's own tmpfiles entry does it right.
The NTS cookies are written when chronyd stops, not while it runs. The live test restarts the daemon before looking for them, which is also a small proof that the key exchange survives a restart.
License
Commercial - IaC Bazaar EULA. (c) IaC Bazaar.
Usage code & full reference need an account
The complete copy-paste usage, the full input/output reference, and operational notes are free with an account - shown here and bundled in the download. Sign in and this section fills in.
- Variables
- Test
Related modules
ansible-aide
AIDE from AppStream on EL 10: a watched tree, a baseline database built once, and the oneshot unit and timer the package does not ship. The live test passes on an unchanged host, FAILS when a file appears inside a watched path and names it, ignores one inside an excluded path, and passes again once the change is gone. Original role, live-tested on Rocky Linux 10.
ansible-authelia
Authelia from the upstream release (sha256-verified) as a hardened system service on loopback with file users and sqlite; its secrets are generated once on the host and reach the service as AUTHELIA_*_FILE variables. The live test hashes a password with Authelia's hasher, logs in, sees a wrong password refused and an anonymous visitor sent to the portal. Original role, live-tested on Rocky 10.
ansible-bandit
bandit on EL 10 from PyPI into a venv of its own with a link in the PATH; the live test runs pip check, then scans a module that passes a string to subprocess.call with shell=True (B602, High, exit 1) and a clean module (exit 0). Pinned. Original role, live-tested on Rocky Linux 10.
ansible-base-hardening
An SSH hardening drop-in sshd reads back: root login and password authentication off, MaxAuthTries 4, idle timeouts. A sysctl security profile under /etc/sysctl.d that a boot applies, and chrony installed with the distribution preset enabling it. The evidence is sshd's own effective configuration, read with sshd -T on Rocky Linux 10.
ansible-boundary
boundary on EL 10 from releases.hashicorp.com; SHA256SUMS is signature-checked against HashiCorp's key before get_url trusts it, the live test re-checks both, then runs authenticate against a dead address ('connection refused') and database init with a throwaway config (parsed, root key loaded, then the database refused). Pinned. Original role, live-tested on Rocky Linux 10.
ansible-dockle
dockle on EL 10 from the GitHub release; get_url refuses it unless its SHA-256 is in the vendor's checksums file, and the live test re-checks it, then scans a one-layer image whose config names no user, expecting CIS-DI-0001 in the output, exit code 1 with --exit-level warn, and the warning counted in the JSON form. Pinned. Original role, live-tested on Rocky Linux 10.