NTP: time infrastructure

Accurate and consistent time is fundamental to security, auditability and incident resolution. NTP is a tier-0 service whose failure can have cascading effects.

What we typically address

  • design of time resources (redundancy, reliability, on-prem / cloud / hybrid)
  • monitoring of synchronisation and time drift
  • NTP hardening and secure client configurations
  • procedures for incidents caused by incorrect system time

Why is it important?

Accurate time is the basis of security (SSL certificates, Kerberos), auditability and incident resolution. If system time is not synchronised, failures can affect everything from authentication to backups.

Examples: expired SSL certificates due to wrong time, Kerberos authentication failure, incorrectly timestamped incidents and audit discrepancies.

Parts of the design

  • Stratum: choosing reliable sources of time
  • Redundancy: multiple NTP servers and failover strategy
  • Monitoring: drift tracking and anomaly alerts
  • Security: NTP authentication, firewall rules and controls against misuse
  • Tests: verification of synchronisation in production and test environments

Typical problems

  • Without redundancy: one NTP server = risk in case of failure
  • Bad configuration: the firewall blocks traffic or different OSes behave differently
  • Without monitoring: drift may only become apparent during an incident
  • Security flaws: unnecessarily open services and weak access restrictions

Frequently asked questions

How bad is a five-minute time difference?

Very bad. SSL fails, Kerberos doesn't work, and auditing is no longer trusted. In production, time should be synchronised with minimal deviation.

Do we need GPS or Stratum-1 server?

Not always. It depends on the environment, accuracy requirements and the availability of reliable upstream sources. However, they make sense in some scenarios.

How is synchronisation tested?

By checking the state of synchronisation, monitoring the offset and regularly auditing the configuration and behaviour of clients.

How we work

Analysis: we review the existing NTP environment and identify risks.

Design: we will recommend architecture, monitoring and incident procedures.

Stabilisation: we help with configuration, testing, documentation and team training.

Contact

If you are dealing with an NTP infrastructure or want to verify that it is configured correctly, get in touch with us.