Install and Configure Chrony NTP server on Amazon Linux 2

Posted on 106 views

A server will use the Network Time Protocol (NTP) to synchronize its time with internet standard reference clocks via a hierarchy of NTP servers. The two common NTP daemon server implementations are ntpd and chronyd. Chrony is known to be much faster in time synchronization in comparison to the traditional NTP. Chrony can also handle intermittent network connections and bandwidth saturation.

The Chrony RPM package is available from the standard Amazon Linux 2 repositories. You can quickly install the package by running the following commands:

sudo yum -y install chronyd

There is a daemon for Chrony called chronyd, which runs in the background to monitor system time and status of the time server specified in the chrony.conf file.

Configure Chrony NTP Server on Amazon Linux 2

The server configuration file is /etc/chrony.conf. Edit this file to set NTP Servers where time synchronization reference will happen.

sudo vim /etc/chrony.conf

Set the NTP servers to synchronize. Please replace the values here with your own timezone NTP servers.

pool iburst
pool iburst
pool iburst

Use public servers from the project. You can get all zonal Pool Servers.

Once the file is updated with servers to reference for time updates, restart chronyd service.

sudo systemctl restart chronyd
sudo systemctl enable chronyd

Check service status:

$ systemctl status chronyd
● chronyd.service - NTP client/server
   Loaded: loaded (/usr/lib/systemd/system/chronyd.service; enabled; vendor preset: enabled)
   Active: active (running) since Fri 2020-10-23 05:17:16 UTC; 23s ago
     Docs: man:chronyd(8)
 Main PID: 29890 (chronyd)
   CGroup: /system.slice/chronyd.service
           └─29890 /usr/sbin/chronyd

Oct 23 05:17:16 systemd[1]: Starting NTP client/server...
Oct 23 05:17:16 chronyd[29890]: chronyd version 3.2 starting (+CMDMON +NTP +REFCLOCK +RTC +PRIVDROP +SCFILTER ...DEBUG)
Oct 23 05:17:16 chronyd[29890]: Frequency 13.093 +/- 0.052 ppm read from /var/lib/chrony/drift
Oct 23 05:17:16 systemd[1]: Started NTP client/server.
Oct 23 05:17:25 chronyd[29890]: Selected source

If you have a running firewalld service and the server will serve as NTP Server to other clients, you may have to allow in the firewall.

sudo firewall-cmd --add-service=ntp --permanent
sudo firewall-cmd --reload

If you prefer allowing from specific subnet.

sudo firewall-cmd --remove-service=ntp --permanent
sudo firewall-cmd --add-rich-rule 'rule family="ipv4" service name="ssh" source address="" accept' --permanent
sudo firewall-cmd --reload

Where is the source address where NTP protocol is allowed for incoming traffic.

$ firewall-cmd --list-rich-rules
rule family="ipv4" source address="" service name="ssh" accept

Verify Chrony is working by pulling correct time.

$ sudo chronyc sources
210 Number of sources = 12
MS Name/IP address         Stratum Poll Reach LastRx Last sample
^+               2   6   377    64  +1643us[+1379us] +/-  119ms
^+             2   6   377    64  +3552us[+3288us] +/-  112ms
^+            2   6   377    65   +665us[ +401us] +/-  195ms
^+                  2   6   375     1  +1074us[+1074us] +/-  126ms
^+                 2   6   377    64   +827us[ +827us] +/-  134ms
^+          2   6   377     1  +2071us[+2071us] +/-  129ms
^+               2   6   377     4  +3273us[+3273us] +/-  121ms
^+                    2   6   377    64   +706us[ +706us] +/-  148ms
^-       2   6   377    66    +24ms[  +24ms] +/-  277ms
^-                2   6   377     1  +7376us[+7557us] +/-  267ms
^*               2   6   377     1  -3843us[-3661us] +/-   96ms
^+             2   6   377    68  -2247us[-2321us] +/-   94ms

Chrony Client Configurations

On your client machines install chrony package:

sudo yum -y install chrony

Modify configuration file and add your NTP Server.

$ sudo vim /etc/chrony.conf
pool iburst

Set your machine timezone:

sudo timedatectl set-timezone Africa/Nairobi

Start and enable Chronyd Service.

sudo systemctl enable --now chronyd

Test with the command below.

sudo chronyc sources

Check your system date to confirm if it is correct:

$ date
Fri Oct 23 08:34:54 EAT 2020



Gravatar Image
A systems engineer with excellent skills in systems administration, cloud computing, systems deployment, virtualization, containers, and a certified ethical hacker.