使用 chrony 同步时间
Ubuntu 使用 chrony 同步时间,从 Ubuntu 25.10 起默认安装它。也可以选择 timedatectl/timesyncd,通过 systemd 同步时间。
检查 chrony 客户端状态
可以使用 systemd 提供的 timedatectl status 命令检查当前时间同步状态。输出如下所示:
Local time: Mo 2025-06-16 15:21:46 CEST
Universal time: Mo 2025-06-16 13:21:46 UTC
RTC time: Mo 2025-06-16 13:21:46
Time zone: Europe/Berlin (CEST, +0200)
System clock synchronized: yes
NTP service: active
RTC in local TZ: no
要了解更详细的时间精度信息,可以用 chronyc -N tracking 直接查询 chrony,输出如下:
Reference ID : B97DBE7B (2.ntp.ubuntu.com)
Stratum : 3
Ref time (UTC) : Mon Jun 16 13:06:04 2025
System time : 0.000000004 seconds slow of NTP time
Last offset : +0.001758954 seconds
RMS offset : 0.017604901 seconds
Frequency : 3.889 ppm slow
Residual freq : +0.202 ppm
Skew : 1.458 ppm
Root delay : 0.022837413 seconds
Root dispersion : 0.003050051 seconds
Update interval : 1032.5 seconds
Leap status : Normal
网络时间安全(NTS)
chrony 支持网络时间安全(Network Time Security,NTS),并默认通过 Ubuntu NTS 池启用它。Ubuntu 池定义在 /etc/chrony/sources.d/ubuntu-ntp-pools.sources 文件中。Ubuntu 使用的默认配置如下:
pool 1.ntp.ubuntu.com iburst maxsources 1 nts prefer
pool 2.ntp.ubuntu.com iburst maxsources 1 nts prefer
pool 3.ntp.ubuntu.com iburst maxsources 1 nts prefer
pool 4.ntp.ubuntu.com iburst maxsources 1 nts prefer
pool ntp-bootstrap.ubuntu.com iburst maxsources 1 nts certset 1
nts 标志强制使用 NTS;在多个有效服务器之间选择时,prefer 将该来源标记为优先时间源。
这一行:
pool ntp-bootstrap.ubuntu.com iburst maxsources 1 nts certset 1
添加了 ntp-bootstrap.ubuntu.com 时间源,使时钟偏差很大的系统仍能安全地校准时间。
一个重要细节是,引导服务器使用由私有 CA 签署的证书链,而不是像 1.ntp.ubuntu.com 等服务器一样使用公共 CA 签署的证书。
查询 1.ntp.ubuntu.com 的服务器证书后,可以从证书中看到签发它的 CA:
$ openssl s_client -connect 1.ntp.ubuntu.com:4460 -servername 1.ntp.ubuntu.com
Server certificate
...
subject=CN=ntp.ubuntu.com
issuer=C=US, O=Let's Encrypt, CN=R13
---
相比之下,ntp-bootstrap.ubuntu.com 的证书如下:
Server certificate
...
subject=CN=ntp-bootstrap.ubuntu.com
issuer=CN=ubuntu
这里的签发者是 ubuntu;它并非像 Let’s Encrypt 一样得到公开认可的证书颁发机构。
这个证书随系统放在 /etc/chrony/nts-bootstrap-ubuntu.crt 中,chrony 通过 /etc/chrony/conf.d/ubuntu-nts.conf 中的配置信任它:
ntstrustedcerts 1 /etc/chrony/nts-bootstrap-ubuntu.crt
要验证 NTS 是否启用,可以运行 chronyc -N sources 列出正在使用的时间源,并根据第一列的 ^* 标记找出当前使用的服务器。接着使用 sudo chronyc -N authdata 检查连接的认证信息。如果客户端成功建立 NTS 连接,输出会显示 Mode: NTS,且 KeyID、Type、KLen 的值均非零:
$ sudo chronyc -N authdata
Name/IP address Mode KeyID Type KLen Last Atmp NAK Cook CLen
=========================================================================
1.ntp.ubuntu.com NTS 6 30 128 14d 0 0 8 64
2.ntp.ubuntu.com NTS 6 30 128 14d 0 0 8 64
3.ntp.ubuntu.com NTS 1 30 128 27d 0 0 8 64
4.ntp.ubuntu.com NTS 2 30 128 20d 0 0 5 64
ntp-bootstrap.ubuntu.com NTS 3 30 128 7d 0 0 8 64
配置 chrony
管理员可以通过 systemd 提供的常用命令 timedatectl [set-timezone/set-local-rtc],控制时区以及系统时钟与硬件时钟的关系。添加时间源等更具体的操作可以使用 chronyc;详细信息请参阅 man chronyc。
可以编辑 /etc/chrony/sources.d/ 中的配置,添加或删除服务器行。默认配置的服务器如下:
# Use NTS by default
# NTS uses an additional port to negotiate security: 4460/tcp
# The normal NTP port remains in use: 123/udp
pool 1.ntp.ubuntu.com iburst maxsources 1 nts prefer
pool 2.ntp.ubuntu.com iburst maxsources 1 nts prefer
pool 3.ntp.ubuntu.com iburst maxsources 1 nts prefer
pool 4.ntp.ubuntu.com iburst maxsources 1 nts prefer
# The bootstrap server is needed by systems without a hardware clock, or a very
# large initial clock offset. The specified certificate set is defined in
# /etc/chrony/conf.d/ubuntu-nts.conf.
pool ntp-bootstrap.ubuntu.com iburst maxsources 1 nts certset 1
添加或移除时间源后,可以使用 sudo chrony reload sources 重新加载它们。
池中的 2.ubuntu.pool.ntp.org 与 ntp.ubuntu.com 也支持 IPv6。如果需要强制使用 IPv6,还可以使用默认未配置的 ipv6.ntp.ubuntu.com。
DHCP 提供的时间源(选项 42)
chrony 会使用 DHCP 选项 42 提供的时间源,这些时间源可能是传统的、未经认证的 NTP 来源。如果希望覆盖本地 DHCP 管理员的选择,避免使用它们,可以在 /etc/chrony/chrony.conf 中注释掉对应设置:
# Use time sources from DHCP.
# sourcedir /run/chrony-dhcp
chrony 时间守护进程
chronyd 本身是常规系统服务,可以使用下面的命令查看更详细的状态:
$ systemctl status chrony.service
● chrony.service - chrony, an NTP client/server
Loaded: loaded (/usr/lib/systemd/system/chrony.service; enabled; preset: enabled)
Active: active (running) since Mon 2025-06-02 11:27:09 CEST; 2 weeks 0 days ago
Docs: man:chronyd(8)
man:chronyc(1)
man:chrony.conf(5)
Main PID: 36027 (chronyd)
Tasks: 2 (limit: 28388)
Memory: 5.8M (peak: 6.8M swap: 604.0K swap peak: 4.5M)
CPU: 5.038s
CGroup: /system.slice/chrony.service
├─36027 /usr/sbin/chronyd -F 1
└─36028 /usr/sbin/chronyd -F 1
Jun 02 11:27:09 questing chronyd[36027]: Using right/UTC timezone to obtain leap second data
Jun 02 11:27:09 questing chronyd[36027]: Loaded seccomp filter (level 1)
Jun 02 11:27:09 questing chronyd[36027]: Added pool 1.ntp.ubuntu.com
Jun 02 11:27:09 questing chronyd[36027]: Added pool 2.ntp.ubuntu.com
Jun 02 11:27:09 questing chronyd[36027]: Added pool 3.ntp.ubuntu.com
Jun 02 11:27:09 questing chronyd[36027]: Added pool 4.ntp.ubuntu.com
Jun 02 11:27:09 questing chronyd[36027]: Added pool ntp-bootstrap.ubuntu.com
Jun 02 11:27:09 questing systemd[1]: Started chrony.service - chrony, an NTP client/server.
sourcedir、ntsdumpdir、rtcsync 等默认配置位于 /etc/chrony/chrony.conf;附加配置文件可以保存在 /etc/chrony/conf.d/。chrony 用于获取时间的 NTS 服务器定义在 /etc/chrony/sources.d/ubuntu-ntp-pools.sources 中。更多高级选项见 chrony.conf(5) 手册,例如显式指定受信任证书。修改配置文件的任何部分后,需要按下方命令重启 chrony:
$ sudo systemctl restart chrony.service
后续步骤
如果接下来还希望通过 chrony 提供网络时间协议服务,请参阅原文链接中的服务端配置指南。
延伸阅读
-
chronyc(1) 手册
-
chronyd(8) 手册
-
chrony.conf(5) 手册











暂无评论内容