Skip to content

chronyd fails to start after hardening with stig profile #14563

@matusmarhefka

Description

@matusmarhefka

Description of problem:

After system is hardened with stig profile profile and rebooted, the chronyd complains it can't connect to the pool.

This seems to be caused by STIG hardening configuring NTS in chrony which is not compatible with FIPS:

Warning
NTS is not compatible with the FIPS and OSPP profile. When you enable the FIPS and OSPP profile, chronyd that is configured with NTS can abort with a fatal message. You can disable the OSPP profile and FIPS mode for chronyd service by adding the GNUTLS_FORCE_FIPS_MODE=0 setting to the /etc/sysconfig/chronyd file.

SCAP Security Guide Version:

master

Operating System Version:

RHEL 9, RHEL 10

Steps to Reproduce:

  1. Run /scanning/boot-errors/stig test.

Actual Results:

chronyd: Could not connect to 188.124.59.142:4460 (2.rhel.pool.ntp.org) : Connection refused
chronyd: Could not connect to 46.28.110.153:4460 (2.rhel.pool.ntp.org) : Connection refused

Expected Results:

No failure after hardening.

Metadata

Metadata

Assignees

No one assigned

    Labels

    RHEL10Red Hat Enterprise Linux 10 product related.RHEL9Red Hat Enterprise Linux 9 product related.productization-issueIssue found in upstream stabilization process.triaged

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions