Instalacja
apt update
apt install chrony -yKonfiguracja
nano /etc/chrony/chrony.conf # Welcome to the chrony configuration file. See chrony.conf(5) for more
# information about usable directives.
# Include configuration files found in /etc/chrony/conf.d.
confdir /etc/chrony/conf.d
# Use Debian vendor zone.
pool 2.debian.pool.ntp.org iburst
# Use time sources from DHCP.
sourcedir /run/chrony-dhcp
# Use NTP sources found in /etc/chrony/sources.d.
sourcedir /etc/chrony/sources.d
# This directive specify the location of the file containing ID/key pairs for
# NTP authentication.
keyfile /etc/chrony/chrony.keys
# This directive specify the file into which chronyd will store the rate
# information.
driftfile /var/lib/chrony/chrony.drift
# Save NTS keys and cookies.
ntsdumpdir /var/lib/chrony
# Uncomment the following line to turn logging on.
#log tracking measurements statistics
# Log files location.
logdir /var/log/chrony
# Stop bad estimates upsetting machine clock.
maxupdateskew 100.0
# This directive enables kernel synchronisation (every 11 minutes) of the
# real-time clock. Note that it can't be used along with the 'rtcfile' directive.
rtcsync
# Step the system clock instead of slewing it if the adjustment is larger than
# one second, but only in the first three clock updates.
makestep 1 3
# Get TAI-UTC offset and leap seconds from the system tz database.
# This directive must be commented out when using time sources serving
# leap-smeared time.
leapsectz right/UTC
allow 192.168.12.0/24
local stratum 10Uprawnienia
chmod 750 /var/lib/samba/ntp_signd
chown root:_chrony /var/lib/samba/ntp_signd
ls -ld /var/lib/samba/ntp_signdRestart
systemctl restart chrony
systemctl enable chrony
systemctl start samba-ad-dcTest
chronyc tracking
chronyc sources -v
Uwaga dla LXC (ważne!)
Jeśli Samba AD działa w kontenerze LXC, to chrony może nie startować z błędem:
ConditionCapability=CAP_SYS_TIME unmet
To oznacza, że kontener nie ma uprawnień do zmiany czasu. Dokumentacja Samba-AD potwierdza, że w takim przypadku trzeba dodać opcję -x w /etc/default/chrony
Ale w praktyce (co już u Ciebie wyszło) — trzeba dodać capability sys_time do kontenera LXC.
Na windows
net stop w32time
w32tm /unregister
w32tm /register
net start w32time
w32tm /resync /force
w32tm /resync /nowait
w32tm /query /status