Skip to content
Snippets Groups Projects
  1. Jul 07, 2017
  2. Oct 17, 2016
  3. May 04, 2015
    • Bill MacAllister's avatar
      base::ntp: Restrict incoming ntp connections, fragment cleanup · 373709be
      Bill MacAllister authored
      The ntp iptables rules date from the days when Unix Systems actually
      ran ntp servers on Linux hosts.  Since the ntp service is now provided
      by hardware appliances there is no need to allow inbound ntp
      connections.  Remove the iptables rules allow inbound ntp connections
      at Rob Riepel's suggestion.
      
      Similarly remove restrict entries from ntp.conf that point at hosts
      that are no longer ntp servers.  Be a bit more conservative and leave
      the restrict to the current ntp servers.
      
      Remove some iptables fragments that are no longer used to reduce
      confusion.
      373709be
  4. Jan 15, 2014
    • Russ Allbery's avatar
      Disable monlist in all ntp.conf files · 9d504206
      Russ Allbery authored
      Globally disable monlist in all the ntp.conf variations to protect
      against use of monlist to launch UDP-based DoS attacks.  This was
      probably already prevented by firewall rules, but may as well make
      sure.
      9d504206
  5. Jan 07, 2014
  6. Apr 30, 2013
    • Adam Lewenberg's avatar
      master branch commit · e80a6b1e
      Adam Lewenberg authored
      This is the (old) master branch along with the fixes to the
      cron file permissions that Russ made.
      e80a6b1e
Loading