xref: /freebsd/contrib/ntp/ntpd/ntp.keys.5man (revision e8e8c939350bdf3c228a411caa9660c607c27a11)
ntp.keys 5man "07 Apr 2015" "4.2.8p2" "File Formats"

EDIT THIS FILE WITH CAUTION (ntp.man)

It has been AutoGen-ed April 7, 2015 at 04:25:42 AM by AutoGen 5.18.5pre4
From the definitions ntp.keys.def
and the template file agman-file.tpl
.Sh NAME .Nm ntp.keys .Nd NTP symmetric key file format
NAME
ntp.keys - NTP symmetric key file format configuration file . it 1 an-trap . if \\n[.$] \,\\$*\/ ..
SYNOPSIS
\f\*[B-Font] [\f\*[B-Font]--option-name\f[]] [\f\*[B-Font]--option-name\f[] \f\*[I-Font]value\f[]] All arguments must be options.
DESCRIPTION
This document describes the format of an NTP symmetric key file. For a description of the use of this type of file, see the "Authentication Support" section of the ntp.conf(5)\f[] page. ntpd(8)\f[] reads its keys from a file specified using the \f\*[B-Font]-k\f[] command line option or the \f\*[B-Font]keys\f[] statement in the configuration file. While key number 0 is fixed by the NTP standard (as 56 zero bits) and may not be changed, one or more keys numbered between 1 and 65534 may be arbitrarily set in the keys file. The key file uses the same comment conventions as the configuration file. Key entries use a fixed format of the form \f\*[I-Font]keyno\f[] \f\*[I-Font]type\f[] \f\*[I-Font]key\f[] where \f\*[I-Font]keyno\f[] is a positive integer (between 1 and 65534), \f\*[I-Font]type\f[] is the message digest algorithm, and \f\*[I-Font]key\f[] is the key itself. The \f\*[I-Font]key\f[] may be given in a format controlled by the \f\*[I-Font]type\f[] field. The \f\*[I-Font]type\f[] \f[C]MD5\f[] is always supported. If \f[C]ntpd\f[] was built with the OpenSSL library then any digest library supported by that library may be specified. However, if compliance with FIPS 140-2 is required the \f\*[I-Font]type\f[] must be either \f[C]SHA\f[] or \f[C]SHA1\f[]. What follows are some key types, and corresponding formats:

7 .NOP \f[C]MD5\f[] The key is 1 to 16 printable characters terminated by an EOL, whitespace, or a \f[C]#\f[] (which is the "start of comment" character).

.ns

7 .NOP \f[C]SHA\f[]

.ns

7 .NOP \f[C]SHA1\f[]

.ns

7 .NOP \f[C]RMD160\f[] The key is a hex-encoded ASCII string of 40 characters, which is truncated as necessary.

Note that the keys used by the ntpq(8)\f[] and ntpdc(8)\f[] programs are checked against passwords requested by the programs and entered by hand, so it is generally appropriate to specify these keys in ASCII format.

FILES

14 .NOP /etc/ntp.keys\f[] the default name of the configuration file

"SEE ALSO"
ntp.conf(5)\f[], ntpd(1ntpdmdoc)\f[], ntpdate(1ntpdatemdoc)\f[], ntpdc(1ntpdcmdoc)\f[], sntp(1sntpmdoc)\f[]
"AUTHORS"
The University of Delaware and Network Time Foundation
"COPYRIGHT"
Copyright (C) 1992-2015 The University of Delaware and Network Time Foundation all rights reserved. This program is released under the terms of the NTP license, <http://ntp.org/license>.
"BUGS"
Please send bug reports to: http://bugs.ntp.org, bugs@ntp.org
NOTES
This document was derived from FreeBSD. This manual page was AutoGen-erated from the ntp.keys option definitions.