Instalacja

apt update
apt install chrony -y

Konfiguracja

nano /etc/chrony/chrony.conf 
# Welcome to the chrony configuration file. See chrony.conf(5) for more
# information about usable directives.

# Include configuration files found in /etc/chrony/conf.d.
confdir /etc/chrony/conf.d

# Use Debian vendor zone.
pool 2.debian.pool.ntp.org iburst

# Use time sources from DHCP.
sourcedir /run/chrony-dhcp

# Use NTP sources found in /etc/chrony/sources.d.
sourcedir /etc/chrony/sources.d

# This directive specify the location of the file containing ID/key pairs for
# NTP authentication.
keyfile /etc/chrony/chrony.keys

# This directive specify the file into which chronyd will store the rate
# information.
driftfile /var/lib/chrony/chrony.drift

# Save NTS keys and cookies.
ntsdumpdir /var/lib/chrony

# Uncomment the following line to turn logging on.
#log tracking measurements statistics

# Log files location.
logdir /var/log/chrony

# Stop bad estimates upsetting machine clock.
maxupdateskew 100.0

# This directive enables kernel synchronisation (every 11 minutes) of the
# real-time clock. Note that it can't be used along with the 'rtcfile' directive.
rtcsync

# Step the system clock instead of slewing it if the adjustment is larger than
# one second, but only in the first three clock updates.
makestep 1 3

# Get TAI-UTC offset and leap seconds from the system tz database.
# This directive must be commented out when using time sources serving
# leap-smeared time.
leapsectz right/UTC
allow 192.168.12.0/24
local stratum 10

Uprawnienia

chmod 750 /var/lib/samba/ntp_signd
chown root:_chrony /var/lib/samba/ntp_signd
ls -ld /var/lib/samba/ntp_signd

Restart

systemctl restart chrony
systemctl enable chrony
systemctl start samba-ad-dc

Test

chronyc tracking
chronyc sources -v

Uwaga dla LXC (ważne!)

Jeśli Samba AD działa w kontenerze LXC, to chrony może nie startować z błędem:

ConditionCapability=CAP_SYS_TIME unmet

To oznacza, że kontener nie ma uprawnień do zmiany czasu. Dokumentacja Samba-AD potwierdza, że w takim przypadku trzeba dodać opcję -x w /etc/default/chrony

Ale w praktyce (co już u Ciebie wyszło) — trzeba dodać capability sys_time do kontenera LXC.

Na windows

net stop w32time
w32tm /unregister
w32tm /register
net start w32time
w32tm /resync /force
w32tm /resync /nowait
w32tm /query /status

 

Spis treści: