| name | cis-ubuntu2004-v300-2-3-1-1 |
| description | Ensure a single time synchronization daemon is in use |
| category | cis-networking |
| version | 3.0.0 |
| author | cyberstrike-official |
| tags | ["cis","ubuntu","linux","ubuntu-20.04","time-sync","systemd-timesyncd","chrony"] |
| cis_id | 2.3.1.1 |
| cis_benchmark | CIS Ubuntu Linux 20.04 LTS Benchmark v3.0.0 |
| tech_stack | ["ubuntu","linux"] |
| cwe_ids | [] |
| chains_with | [] |
| prerequisites | [] |
| severity_boost | {} |
Ensure a single time synchronization daemon is in use
Profile
- Level 1 - Server
- Level 1 - Workstation
Description
System time should be synchronized between all systems in an environment. This is typically done by establishing an authoritative time server or set of servers and having all systems synchronize their clocks to them.
Note:
- On virtual systems where host based time synchronization is available consult your virtualization software documentation and verify that host based synchronization is in use and follows local site policy. In this scenario, this section should be skipped
- Only one time synchronization method should be in use on the system. Configuring multiple time synchronization methods could lead to unexpected or unreliable results
Rationale
Time synchronization is important to support time sensitive security mechanisms and ensures log files have consistent time records across the enterprise, which aids in forensic investigations.
Audit
On physical systems, and virtual systems where host based time synchronization is not available.
One of the two time synchronization daemons should be available; chrony or systemd-timesyncd
Run the following script to verify that a single time synchronization daemon is available on the system:
Command Line
#!/usr/bin/env bash
{
l_output="" l_output2=""
service_not_enabled_chk()
{
l_out2=""
if systemctl is-enabled "$l_service_name" 2>/dev/null | grep -q 'enabled'; then
l_out2="$l_out2\n - Daemon: \"$l_service_name\" is enabled on the system"
fi
if systemctl is-active "$l_service_name" 2>/dev/null | grep -q 'active'; then
l_out2="$l_out2\n - Daemon: \"$l_service_name\" is active on the system"
}
l_service_name=
service_not_enabled_chk
[ -n ];
l_timesyncd=
l_out_tsd=
l_timesyncd=
l_out_tsd=
l_service_name=
service_not_enabled_chk
[ -n ];
l_chrony=
l_out_chrony=
l_chrony=
l_out_chrony=
l_status=
yy)
l_output2=
;;
nn)
l_output2=
;;
yn|ny)
l_output=
;;
*)
l_output2=
;;
[ -z ];
-e
-e
}