Certichron’s “Meinberg Windows NTP” Mirror
This is the Certichron mirror for the Meinberg Windows NTP Release. The system provides a full windows implementation of the NTP Reference Port project’s master code release.
NTP Security Aler — Please UPGRADE NOW! - If you have not already please upgrade to this new release to patch the MODE-7 flaw in the NTP.ORG Reference Port services for releases prior to 4.2.4P7 — See the notice here DoS_attack_from_certain_NTP_mode
Installation Instructions: Installing the Meinberg NTP service fully replaces the NTP service in the platforn it is installed on with the NTP.ORG reference port of NTP for WIndows. To do this the Meinberg NTP Installer is setup to disable the native Windows Simple NTP Service which is contained in a system called W32TIME.DLL and WTIME.EXE and replace it with the Visual Runtime compiled version of the NTP.ORG master NTP Reference Port. This installation is a full-featured port of NTP and provides all of the key NTP functionality necessary to run as a SecureNTP endpoint. Please install the NTP port before installing the NTP monitor. It also is provided with an unilstaller option which returns the system to the pre-installed default installation. |
|
If you are running NTP as a server it should be run on a stand-alone system. Especially in the context of creating a reference service for Microsoft type deployment models. That way it is not a member of any domains or a leaf thereof but only a system running NTP. Depending on the loading internally this can be a reasonably small or medium performance time server.
The NTP compilation’s runtime system (The visual c redistributable runtime library set) provides kernel level access for time services and Active Directory PDC and PDCe’s running on other platforms will be able to reference this platforms NTP port as an external NTP service.
The network topology rules are simple. NTP needs flat addressing if Autokey is used to secure end-node access. If you can run without Autokey on by placing a two level system in place and only using Autokey on the external system, you can easily serve a Microsoft environment with this topology. If no Autokey is used then NAT works for some types of NTP models as long as there is substantial logging.
In models where an external NTP server is used as an evidence source to periodically query a client’s perimeter NTP server for its accuracy or other systems under management, these services may need flattened routing to properly handle the audit requirements, depending of course on the industry and the types of services they offer.
