<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:clearspace="http://www.jivesoftware.com/xmlns/clearspace/rss" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:opensearch="http://a9.com/-/spec/opensearch/1.1/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>VMware Communities: Message List - Hash Algorithm to Authenticate Time Source</title>
    <link>http://communities.vmware.com/community/vmtn/vi/esx3.5?view=discussions</link>
    <description>Most recent forum messages</description>
    <language>en</language>
    <pubDate>Thu, 08 Oct 2009 02:52:05 GMT</pubDate>
    <generator>Clearspace 1.10.12 (http://jivesoftware.com/products/clearspace/)</generator>
    <dc:date>2009-10-08T02:52:05Z</dc:date>
    <dc:language>en</dc:language>
    <item>
      <title>Re: Hash Algorithm to Authenticate Time Source</title>
      <link>http://communities.vmware.com/message/1384254?tstart=0#1384254</link>
      <description>&lt;br /&gt;
In fact I support the DoD, and we use internal NTP servers based on GPS time. However, we still have a requirement to enable NTP hashing for even more security. We are using ESXi and I haven't found a method to enable NTP hashing.</description>
      <pubDate>Thu, 08 Oct 2009 02:52:05 GMT</pubDate>
      <author>DSeaman</author>
      <guid>http://communities.vmware.com/message/1384254?tstart=0#1384254</guid>
      <dc:date>2009-10-08T02:52:05Z</dc:date>
      <clearspace:dateToText>1 month, 2 weeks ago</clearspace:dateToText>
    </item>
    <item>
      <title>Re: Hash Algorithm to Authenticate Time Source</title>
      <link>http://communities.vmware.com/message/1275736?tstart=0#1275736</link>
      <description>Indeed - this idea of running your own clock source on a safe network is probably te best choice..  GPS linked time sources are pretty cheap.&lt;br /&gt;
&lt;br /&gt;
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;--Matt&lt;br /&gt;
VCP, vExpert, Unix Geek</description>
      <pubDate>Mon, 08 Jun 2009 02:10:15 GMT</pubDate>
      <author>mcowger</author>
      <guid>http://communities.vmware.com/message/1275736?tstart=0#1275736</guid>
      <dc:date>2009-06-08T02:10:15Z</dc:date>
      <clearspace:dateToText>5 months, 3 weeks ago</clearspace:dateToText>
      <clearspace:replyCount>1</clearspace:replyCount>
    </item>
    <item>
      <title>Re: Hash Algorithm to Authenticate Time Source</title>
      <link>http://communities.vmware.com/message/1275308?tstart=0#1275308</link>
      <description>&lt;br /&gt;
If security is that much of a concern they better be using internal atomic timekeeping devices for NTP on a secured network.  If someone is able to spoof timekeeping internally, as pointed out earlier, they have MUCH bigger problems...&lt;br /&gt;
&lt;p /&gt;
I've seen alot of exploits, but screwing with log times would only be a concern for someone hacking the pentagon I would expect...the general blow hacker covers their tracks by clearing the logs, not spoofing the time...</description>
      <pubDate>Sun, 07 Jun 2009 04:00:53 GMT</pubDate>
      <author>Rumple</author>
      <guid>http://communities.vmware.com/message/1275308?tstart=0#1275308</guid>
      <dc:date>2009-06-07T04:00:53Z</dc:date>
      <clearspace:dateToText>5 months, 3 weeks ago</clearspace:dateToText>
      <clearspace:replyCount>2</clearspace:replyCount>
    </item>
    <item>
      <title>Re: Hash Algorithm to Authenticate Time Source</title>
      <link>http://communities.vmware.com/message/1275256?tstart=0#1275256</link>
      <description>This is the first time I ever heard that someone wanted to do a hash check on his ntp source.&lt;br /&gt;
&lt;p /&gt;
&lt;p /&gt;
Duncan&lt;br /&gt;
VMware Communities User Moderator | VCP | VCDX&lt;br /&gt;
&lt;hr /&gt;
Blogging: &lt;a class="jive-link-external" href="http://www.yellow-bricks.com"&gt;http://www.yellow-bricks.com&lt;/a&gt;&lt;br /&gt;
Twitter: &lt;a class="jive-link-external" href="http://www.twitter.com/depping"&gt;http://www.twitter.com/depping&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
If you find this information useful, please award points for "correct" or "helpful".</description>
      <pubDate>Sat, 06 Jun 2009 22:03:03 GMT</pubDate>
      <author>depping</author>
      <guid>http://communities.vmware.com/message/1275256?tstart=0#1275256</guid>
      <dc:date>2009-06-06T22:03:03Z</dc:date>
      <clearspace:dateToText>5 months, 3 weeks ago</clearspace:dateToText>
      <clearspace:replyCount>3</clearspace:replyCount>
    </item>
    <item>
      <title>Re: Hash Algorithm to Authenticate Time Source</title>
      <link>http://communities.vmware.com/message/1275219?tstart=0#1275219</link>
      <description>Implement one of the methods here:&lt;br /&gt;
&lt;br /&gt;
&lt;a class="jive-link-external" href="http://support.ntp.org/bin/view/Support/ConfiguringAutokey"&gt;http://support.ntp.org/bin/view/Support/ConfiguringAutokey&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
Though, in all honesty, if you are worried about having your internal NTP servers spoofed, you have much larger problems.&lt;br /&gt;
&lt;br /&gt;
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;--Matt&lt;br /&gt;
VCP, vExpert, Unix Geek</description>
      <pubDate>Sat, 06 Jun 2009 20:54:29 GMT</pubDate>
      <author>mcowger</author>
      <guid>http://communities.vmware.com/message/1275219?tstart=0#1275219</guid>
      <dc:date>2009-06-06T20:54:29Z</dc:date>
      <clearspace:dateToText>5 months, 3 weeks ago</clearspace:dateToText>
      <clearspace:replyCount>4</clearspace:replyCount>
    </item>
    <item>
      <title>Re: Hash Algorithm to Authenticate Time Source</title>
      <link>http://communities.vmware.com/message/1275210?tstart=0#1275210</link>
      <description>Hello,&lt;br /&gt;
&lt;br /&gt;
Moved to ESX 3.5 forum.&lt;br /&gt;
&lt;br /&gt;
&lt;br&gt;Best regards, Edward L. Haletky VMware Communities User Moderator, VMware vExpert 2009&lt;br&gt;Now Available on Rough-Cuts: &lt;a class="jive-link-external" href="http://www.astroarch.com/wiki/index.php/VMware_Virtual_Infrastructure_Security"&gt;'VMware vSphere(TM) and Virtual Infrastructure Security: Securing ESX and the Virtual Environment'&lt;/a&gt;&lt;br&gt;Also available &lt;a class="jive-link-external" href="http://www.astroarch.com/wiki/index.php/VMWare_ESX_Server_in_the_Enterprise"&gt;'VMWare ESX Server in the Enterprise'&lt;/a&gt;&lt;br&gt;&lt;a class="jive-link-external" href="http://www.astroarch.com/wiki/index.php/Blog_Roll"&gt;SearchVMware Pro&lt;/a&gt;|&lt;a class="jive-link-external" href="http://www.astroarch.com/blog"&gt;Blue Gears&lt;/a&gt;|&lt;a class="jive-link-external" href="http://www.astroarch.com/wiki/index.php/Top_Virtualization_Security_Links"&gt;Top Virtualization Security Links&lt;/a&gt;|&lt;a class="jive-link-external" href="http://www.astroarch.com/wiki/index.php/Virtualization_Security_Round_Table_Podcast"&gt;Virtualization Security Round Table Podcast&lt;/a&gt;</description>
      <pubDate>Sat, 06 Jun 2009 19:12:56 GMT</pubDate>
      <author>Texiwill</author>
      <guid>http://communities.vmware.com/message/1275210?tstart=0#1275210</guid>
      <dc:date>2009-06-06T19:12:56Z</dc:date>
      <clearspace:dateToText>5 months, 3 weeks ago</clearspace:dateToText>
    </item>
    <item>
      <title>Re: Hash Algorithm to Authenticate Time Source</title>
      <link>http://communities.vmware.com/message/1274008?tstart=0#1274008</link>
      <description>Ah! This is the Server 2.0 community, not ESX. You'll probably want to contact a moderator to move your post to the right forum so it gets seen by people who are more likely to know the answer. Sorry. I will have a dig around though as I also have VI infrastructure although have never done anything complex (yet) with the NTP settings.</description>
      <pubDate>Fri, 05 Jun 2009 13:34:45 GMT</pubDate>
      <author>guyrleech</author>
      <guid>http://communities.vmware.com/message/1274008?tstart=0#1274008</guid>
      <dc:date>2009-06-05T13:34:45Z</dc:date>
      <clearspace:dateToText>5 months, 3 weeks ago</clearspace:dateToText>
      <clearspace:replyCount>1</clearspace:replyCount>
    </item>
    <item>
      <title>Re: Hash Algorithm to Authenticate Time Source</title>
      <link>http://communities.vmware.com/message/1273931?tstart=0#1273931</link>
      <description>&lt;br /&gt;
I have been locking down ESX servers for a client and one of the requirements is that we must configure all ESX Servers to use a hashing algorithm to authenticate the time source if we are using NTP.&lt;br /&gt;
&lt;p /&gt;
 The exerp is as follows:&lt;br /&gt;
&lt;p /&gt;
"Since NTP is used to ensure accure log file timestamps for information, NTP could pose a security risk if a malicious user were able to falsify NTP information.  Implementing authentication between NTP peers can mitigate this risk.  When hashing authentication is enforced, there is a greater level of assurance that NTP updates are from a trusted source.."&lt;br /&gt;
&lt;p /&gt;
 This is all the information I have.  Any idea what enforcing authentication with NTP actually is or how it is done?  I can't find any information to support this.&lt;br /&gt;
&lt;p /&gt;
&lt;br /&gt;</description>
      <pubDate>Fri, 05 Jun 2009 12:49:42 GMT</pubDate>
      <author>twd711</author>
      <guid>http://communities.vmware.com/message/1273931?tstart=0#1273931</guid>
      <dc:date>2009-06-05T12:49:42Z</dc:date>
      <clearspace:dateToText>5 months, 3 weeks ago</clearspace:dateToText>
      <clearspace:replyCount>7</clearspace:replyCount>
    </item>
    <item>
      <title>Re: Hash Algorithm to Authenticate Time Source</title>
      <link>http://communities.vmware.com/message/1273262?tstart=0#1273262</link>
      <description>Please expand on what you are after here as I, for one, don't understand.&lt;br /&gt;
&lt;p /&gt;
&lt;p /&gt;
Guy Leech&lt;br /&gt;
&lt;img src="http://communities.vmware.com/servlet/JiveServlet/download/1200101-20223/vExpert_logo_100x57.jpg" alt="http://communities.vmware.com/servlet/JiveServlet/download/1200101-20223/vExpert_logo_100x57.jpg" class="jive-image"  /&gt;&lt;br /&gt;
&lt;br /&gt;
---&lt;br /&gt;
If you found this or any other answer useful please consider the use of the Helpful or Correct buttons to award points.</description>
      <pubDate>Thu, 04 Jun 2009 21:24:43 GMT</pubDate>
      <author>guyrleech</author>
      <guid>http://communities.vmware.com/message/1273262?tstart=0#1273262</guid>
      <dc:date>2009-06-04T21:24:43Z</dc:date>
      <clearspace:dateToText>5 months, 3 weeks ago</clearspace:dateToText>
      <clearspace:replyCount>8</clearspace:replyCount>
    </item>
    <item>
      <title>Hash Algorithm to Authenticate Time Source</title>
      <link>http://communities.vmware.com/message/1272847?tstart=0#1272847</link>
      <description>&lt;br /&gt;
Hello,&lt;br /&gt;
&lt;p /&gt;
I had a quick (and I am sure easy) question.  I was wondering how one would go about using a hashing algorithm to authenticate a time source if you wanted to use NTP.  What are the steps to set this up?&lt;br /&gt;
&lt;p /&gt;
 Thanks</description>
      <pubDate>Thu, 04 Jun 2009 17:34:03 GMT</pubDate>
      <author>twd711</author>
      <guid>http://communities.vmware.com/message/1272847?tstart=0#1272847</guid>
      <dc:date>2009-06-04T17:34:03Z</dc:date>
      <clearspace:dateToText>5 months, 3 weeks ago</clearspace:dateToText>
      <clearspace:replyCount>9</clearspace:replyCount>
    </item>
  </channel>
</rss>

