使用 chrony 同步 Ubuntu 系统时间

使用 chrony 同步时间

Ubuntu 使用 chrony 同步时间,从 Ubuntu 25.10 起默认安装它。也可以选择 timedatectl/timesyncd,通过 systemd 同步时间。

检查 chrony 客户端状态

可以使用 systemd 提供的 timedatectl status 命令检查当前时间同步状态。输出如下所示:

               Local time: Mo 2025-06-16 15:21:46 CEST
           Universal time: Mo 2025-06-16 13:21:46 UTC
                 RTC time: Mo 2025-06-16 13:21:46
                Time zone: Europe/Berlin (CEST, +0200)
System clock synchronized: yes
              NTP service: active
          RTC in local TZ: no

要了解更详细的时间精度信息,可以用 chronyc -N tracking 直接查询 chrony,输出如下:

Reference ID    : B97DBE7B (2.ntp.ubuntu.com)
Stratum         : 3
Ref time (UTC)  : Mon Jun 16 13:06:04 2025
System time     : 0.000000004 seconds slow of NTP time
Last offset     : +0.001758954 seconds
RMS offset      : 0.017604901 seconds
Frequency       : 3.889 ppm slow
Residual freq   : +0.202 ppm
Skew            : 1.458 ppm
Root delay      : 0.022837413 seconds
Root dispersion : 0.003050051 seconds
Update interval : 1032.5 seconds
Leap status     : Normal

网络时间安全(NTS)

chrony 支持网络时间安全(Network Time Security,NTS),并默认通过 Ubuntu NTS 池启用它。Ubuntu 池定义在 /etc/chrony/sources.d/ubuntu-ntp-pools.sources 文件中。Ubuntu 使用的默认配置如下:

pool 1.ntp.ubuntu.com iburst maxsources 1 nts prefer
pool 2.ntp.ubuntu.com iburst maxsources 1 nts prefer
pool 3.ntp.ubuntu.com iburst maxsources 1 nts prefer
pool 4.ntp.ubuntu.com iburst maxsources 1 nts prefer
pool ntp-bootstrap.ubuntu.com iburst maxsources 1 nts certset 1

nts 标志强制使用 NTS;在多个有效服务器之间选择时,prefer 将该来源标记为优先时间源。

这一行:

pool ntp-bootstrap.ubuntu.com iburst maxsources 1 nts certset 1

添加了 ntp-bootstrap.ubuntu.com 时间源,使时钟偏差很大的系统仍能安全地校准时间。

一个重要细节是,引导服务器使用由私有 CA 签署的证书链,而不是像 1.ntp.ubuntu.com 等服务器一样使用公共 CA 签署的证书。

查询 1.ntp.ubuntu.com 的服务器证书后,可以从证书中看到签发它的 CA:

$

openssl s_client -connect 1.ntp.ubuntu.com:4460 -servername 1.ntp.ubuntu.com

Server certificate
...
subject=CN=ntp.ubuntu.com
issuer=C=US, O=Let's Encrypt, CN=R13
---

相比之下,ntp-bootstrap.ubuntu.com 的证书如下:

Server certificate
...
subject=CN=ntp-bootstrap.ubuntu.com
issuer=CN=ubuntu

这里的签发者是 ubuntu;它并非像 Let’s Encrypt 一样得到公开认可的证书颁发机构。

这个证书随系统放在 /etc/chrony/nts-bootstrap-ubuntu.crt 中,chrony 通过 /etc/chrony/conf.d/ubuntu-nts.conf 中的配置信任它:

ntstrustedcerts 1 /etc/chrony/nts-bootstrap-ubuntu.crt

要验证 NTS 是否启用,可以运行 chronyc -N sources 列出正在使用的时间源,并根据第一列的 ^* 标记找出当前使用的服务器。接着使用 sudo chronyc -N authdata 检查连接的认证信息。如果客户端成功建立 NTS 连接,输出会显示 Mode: NTS,且 KeyID、Type、KLen 的值均非零:

$

sudo chronyc -N authdata

Name/IP address             Mode KeyID Type KLen Last Atmp  NAK Cook CLen
=========================================================================
1.ntp.ubuntu.com             NTS     6   30  128  14d    0    0    8   64
2.ntp.ubuntu.com             NTS     6   30  128  14d    0    0    8   64
3.ntp.ubuntu.com             NTS     1   30  128  27d    0    0    8   64
4.ntp.ubuntu.com             NTS     2   30  128  20d    0    0    5   64
ntp-bootstrap.ubuntu.com     NTS     3   30  128   7d    0    0    8   64

配置 chrony

管理员可以通过 systemd 提供的常用命令 timedatectl [set-timezone/set-local-rtc],控制时区以及系统时钟与硬件时钟的关系。添加时间源等更具体的操作可以使用 chronyc;详细信息请参阅 man chronyc。

可以编辑 /etc/chrony/sources.d/ 中的配置,添加或删除服务器行。默认配置的服务器如下:

# Use NTS by default
# NTS uses an additional port to negotiate security: 4460/tcp
# The normal NTP port remains in use: 123/udp
pool 1.ntp.ubuntu.com iburst maxsources 1 nts prefer
pool 2.ntp.ubuntu.com iburst maxsources 1 nts prefer
pool 3.ntp.ubuntu.com iburst maxsources 1 nts prefer
pool 4.ntp.ubuntu.com iburst maxsources 1 nts prefer
# The bootstrap server is needed by systems without a hardware clock, or a very
# large initial clock offset. The specified certificate set is defined in
# /etc/chrony/conf.d/ubuntu-nts.conf.
pool ntp-bootstrap.ubuntu.com iburst maxsources 1 nts certset 1

添加或移除时间源后,可以使用 sudo chrony reload sources 重新加载它们。

池中的 2.ubuntu.pool.ntp.org 与 ntp.ubuntu.com 也支持 IPv6。如果需要强制使用 IPv6,还可以使用默认未配置的 ipv6.ntp.ubuntu.com。

DHCP 提供的时间源(选项 42)

chrony 会使用 DHCP 选项 42 提供的时间源,这些时间源可能是传统的、未经认证的 NTP 来源。如果希望覆盖本地 DHCP 管理员的选择,避免使用它们,可以在 /etc/chrony/chrony.conf 中注释掉对应设置:

# Use time sources from DHCP.
# sourcedir /run/chrony-dhcp

chrony 时间守护进程

chronyd 本身是常规系统服务,可以使用下面的命令查看更详细的状态:

$

systemctl status chrony.service

● chrony.service - chrony, an NTP client/server
     Loaded: loaded (/usr/lib/systemd/system/chrony.service; enabled; preset: enabled)
     Active: active (running) since Mon 2025-06-02 11:27:09 CEST; 2 weeks 0 days ago
       Docs: man:chronyd(8)
             man:chronyc(1)
             man:chrony.conf(5)
   Main PID: 36027 (chronyd)
      Tasks: 2 (limit: 28388)
     Memory: 5.8M (peak: 6.8M swap: 604.0K swap peak: 4.5M)
        CPU: 5.038s
     CGroup: /system.slice/chrony.service
             ├─36027 /usr/sbin/chronyd -F 1
             └─36028 /usr/sbin/chronyd -F 1

    Jun 02 11:27:09 questing chronyd[36027]: Using right/UTC timezone to obtain leap second data
    Jun 02 11:27:09 questing chronyd[36027]: Loaded seccomp filter (level 1)
    Jun 02 11:27:09 questing chronyd[36027]: Added pool 1.ntp.ubuntu.com
    Jun 02 11:27:09 questing chronyd[36027]: Added pool 2.ntp.ubuntu.com
    Jun 02 11:27:09 questing chronyd[36027]: Added pool 3.ntp.ubuntu.com
    Jun 02 11:27:09 questing chronyd[36027]: Added pool 4.ntp.ubuntu.com
    Jun 02 11:27:09 questing chronyd[36027]: Added pool ntp-bootstrap.ubuntu.com
    Jun 02 11:27:09 questing systemd[1]: Started chrony.service - chrony, an NTP client/server.

sourcedir、ntsdumpdir、rtcsync 等默认配置位于 /etc/chrony/chrony.conf;附加配置文件可以保存在 /etc/chrony/conf.d/。chrony 用于获取时间的 NTS 服务器定义在 /etc/chrony/sources.d/ubuntu-ntp-pools.sources 中。更多高级选项见 chrony.conf(5) 手册,例如显式指定受信任证书。修改配置文件的任何部分后,需要按下方命令重启 chrony:

$

sudo systemctl restart chrony.service

后续步骤

如果接下来还希望通过 chrony 提供网络时间协议服务,请参阅原文链接中的服务端配置指南。

延伸阅读

  • chronyc(1) 手册

  • chronyd(8) 手册

  • chrony.conf(5) 手册

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享
评论 抢沙发

请登录后发表评论

    暂无评论内容