Check: GEN000240
SUSE Linux Enterprise Server v11 for System z STIG:
GEN000240
(in versions v1 r12 through v1 r9)
Title
The system clock must be synchronized to an authoritative DoD time source. (Cat II impact)
Discussion
To assure the accuracy of the system clock, it must be synchronized with an authoritative time source within DoD. Many system functions, including time-based login and activity restrictions, automated reports, system logs, and audit records depend on an accurate system clock. If there is no confidence in the correctness of the system clock, time-based functions may not operate as intended and records may be of diminished value. Authoritative time sources include authorized time servers within the enclave that synchronize with upstream authoritative sources. Specific requirements for the upstream synchronization of network time protocol (NTP) servers are covered in the Network Other Devices STIG. For systems located on isolated or closed networks, it is not necessary to synchronize with a global authoritative time source. If a global authoritative time source is not available to systems on an isolated network, a local authoritative time source must be established on this network and used by the systems connected to this network. This is necessary to provide the ability to correlate events and allow for the correct operation of time-dependent protocols between systems on the isolated network. If the system is completely isolated (i.e., it has no connections to networks or other systems), time synchronization is not required as no correlation of events between systems will be necessary. If the system is completely isolated, this requirement is not applicable.
Check Content
Check if NTP running: # ps -ef | egrep "xntpd|ntpd" Check if "ntpd -qg" is scheduled to run: # grep "ntpd -qg" /var/spool/cron/* # grep "ntpd -qg" /var/spool/cron/tabs/* # grep "ntpd -qg" /etc/cron.d/* # grep "ntpd -qg" /etc/cron.daily/* # grep "ntpd -qg" /etc/cron.hourly/* # grep "ntpd -qg" /etc/cron.monthly/* # grep "ntpd -qg" /etc/cron.weekly/* If NTP is running or "ntpd -qg" is found: # more /etc/ntp.conf Confirm the timeservers and peers or multicast client (as applicable) are local or authoritative U.S. DoD sources appropriate for the level of classification which the network operates. If a non-local/non-authoritative time-server is used, this is a finding.
Fix Text
Use an authoritative time server operated by the U.S. government. Ensure all systems in the facility feed from one or more local time servers feed from the authoritative time server.
Additional Identifiers
Rule ID: SV-44771r1_rule
Vulnerability ID: V-4301
Group Title: GEN000240
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-001492 |
The organization defines an authoritative time source for the synchronization of internal information system clocks. |
Controls
Number | Title |
---|---|
AU-8 (1) |
Synchronization With Authoritative Time Source |