[Ntp] Re: NTPv5 Requirements vs. NTPv5 Spec
"Windl, Ulrich" <u.windl@ukr.de> Tue, 24 June 2025 06:21 UTC
Return-Path: <u.windl@ukr.de>
X-Original-To: ntp@mail2.ietf.org
Delivered-To: ntp@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 6AF2A3897ED6 for <ntp@mail2.ietf.org>; Mon, 23 Jun 2025 23:21:04 -0700 (PDT)
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -1.898
X-Spam-Level:
X-Spam-Status: No, score=-1.898 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, RCVD_IN_VALIDITY_SAFE_BLOCKED=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Q8kMsYZ-NDrq for <ntp@mail2.ietf.org>; Mon, 23 Jun 2025 23:21:03 -0700 (PDT)
Received: from mail01.ukr.de (mail01.ukr.de [193.175.194.181]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id F12513897ED1 for <ntp@ietf.org>; Mon, 23 Jun 2025 23:21:02 -0700 (PDT)
X-CSE-ConnectionGUID: pwNzB4FwTamQwr/p9qzLqg==
X-CSE-MsgGUID: 91XMTmgqTHi8yS5r7E9BEA==
X-ThreatScanner-Verdict: Negative
X-IronPort-AV: E=McAfee;i="6800,10657,11473"; a="1731535"
X-IronPort-AV: E=Sophos;i="6.16,260,1744063200"; d="scan'208";a="1731535"
Received: from unknown (HELO ukr-excmb06.ukr.local) ([172.24.2.106]) by dmz-infcsg01.ukr.dmz with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 24 Jun 2025 08:21:00 +0200
Received: from ukr-excmb07.ukr.local (172.24.2.107) by ukr-excmb06.ukr.local (172.24.2.106) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.2.1748.10; Tue, 24 Jun 2025 08:21:00 +0200
Received: from ukr-excmb07.ukr.local ([fe80::4dee:3e0b:b33f:60ac]) by ukr-excmb07.ukr.local ([fe80::4dee:3e0b:b33f:60ac%8]) with mapi id 15.02.1748.010; Tue, 24 Jun 2025 08:21:00 +0200
From: "Windl, Ulrich" <u.windl@ukr.de>
To: Miroslav Lichvar <mlichvar@redhat.com>, Mike Ellis <mike.ellis@npl.co.uk>
Thread-Topic: [Ntp] Re: Re: Re: NTPv5 Requirements vs. NTPv5 Spec
Thread-Index: AdvkzwM29JUQcKmTTUGgqTwuKyo2MQ==
Date: Tue, 24 Jun 2025 06:21:00 +0000
Message-ID: <9234c0f3a66c4ae7b5e5a09354a5a144@ukr.de>
Accept-Language: de-DE, en-US
Content-Language: de-DE
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-originating-ip: [172.24.3.2]
x-tm-as-product-ver: SMEX-14.0.0.3239-9.1.2019-29280.005
x-tm-as-result: No-10--18.712400-5.000000
x-tmase-matchedrid: SIzKuw2hzSsuv++HU7VXr1Y9XYa1m8xA/QJCQ3KSdKjzyBB9yDEICpaw DzBsnt/hR/TlIrsekaBFXCsudh0EiJ2vFMfvZjTGcQ1FQBMySNiB1fO2o4QGcKloHyDFpaEstwj lOkZD5AgrvG1bcEJQ+Vng7dfvCEviH6tQvcqraWOFhGp9GNPDrQ8q6kfeqTRCynr589uIO4c3sZ j4BmnpxC9jpjz13snZHA9o97m6WE9YLNsN2UVSk0u+LBodhvWxjX2cv6V+Ya+ZQOjHxTF/+PgA8 WXCtbOVRnV1i6vbiGerqAIIC4phpBbo4fGnXUiz0RneM2u5ms8schiC3UI5gihTyngBnQHLJqWw 0fPPh61cfKlz8KPRQi+X4PTo99n/oyQv5q9Ag7Ek+VN5SeE/CqzSbgI3g0INWjsaYI4lh3U7nRP 0DvgcK7YURQHAp3zK7WPW/xHv7V9b9O4tSImi9AdkbNa6sM9e0LQutQVABRF1QDU2qdJQJw==
x-tm-as-user-approved-sender: Yes
x-tm-as-user-blocked-sender: No
x-tmase-result: 10--18.712400-5.000000
x-tmase-version: SMEX-14.0.0.3239-9.1.2019-29280.005
x-tm-snts-smtp: BE941925882A45E1B7D909A45CD67F4FF34DEA55A49888CD7CA2CA47CC8837A22000:8
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: base64
MIME-Version: 1.0
Message-ID-Hash: MQOOU6HVRHRU6V46SBXSCYNDN5JRLL3C
X-Message-ID-Hash: MQOOU6HVRHRU6V46SBXSCYNDN5JRLL3C
X-MailFrom: u.windl@ukr.de
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-ntp.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: Tal Mizrahi <tal.mizrahi.phd@gmail.com>, NTP WG <ntp@ietf.org>
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [Ntp] Re: NTPv5 Requirements vs. NTPv5 Spec
List-Id: Network Time Protocol <ntp.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/ntp/PXFyjZcnyDdfwBD-NokCroLj4vQ>
List-Archive: <https://mailarchive.ietf.org/arch/browse/ntp>
List-Help: <mailto:ntp-request@ietf.org?subject=help>
List-Owner: <mailto:ntp-owner@ietf.org>
List-Post: <mailto:ntp@ietf.org>
List-Subscribe: <mailto:ntp-join@ietf.org>
List-Unsubscribe: <mailto:ntp-leave@ietf.org>
> -----Original Message----- > From: Miroslav Lichvar <mlichvar@redhat.com> > Sent: Monday, June 23, 2025 3:24 PM > To: Mike Ellis <mike.ellis@npl.co.uk> > Cc: Windl, Ulrich <u.windl@ukr.de>; Tal Mizrahi > <tal.mizrahi.phd@gmail.com>; NTP WG <ntp@ietf.org> > Subject: [EXT] Re: [Ntp] Re: Re: Re: NTPv5 Requirements vs. NTPv5 Spec > > On Fri, Jun 20, 2025 at 02:09:07PM +0000, Mike Ellis wrote: > > Hi all, > > > > My thoughts, worth all of the nothing you've paid for them... > > > > An NTP server MUST carry out a new DNS lookup for peers after the TTL > has expired. > > I think the DNS TTL is normally way too short to be used like that. [Windl, Ulrich] I disagree: If people set TL to improper values, it's their fault. I don't see why someone would set a TTL to 5 minutes (or similar) for regular operation; it may be appropriate when changes are planned, like replacing a host soon, and then it wold be done ahead of time. Also an expired TTL does not mean the the NTP association has the be replaced; only if the IP used is no longer returned. In the case of pool servers I think that the TTL is a very important element. > This would increase the pool.ntp.org DNS traffic dramatically. Another > problem is that the commonly used system resolver API - getaddrinfo() > doesn't provide the TTL. [Windl, Ulrich] Well, you have the coice: 1) Using outdated IPs that once were part of some pool, but preserving DNS traffic 2) Use up-to-date IPs from the pool, but require more frequent DNS queries. On the TTL per se: I don't think that a TTL of one to three days will cause a lot of traffic, and OTOH I don't think that pool servers change more frequently than daily; if the do, they are not suitable for being pool servers IMHO. > > I'd expect the recommended refresh interval to be at least a week. [Windl, Ulrich] ...and the reason is? > I'm not opposed to have a recommendation like that in the draft. > > > * If the same IP address is returned, carry on using it. > > * If a different IP address is returned AND the new peer claims to share > the same upstream reference, carry on using it. > > * If a different IP address is returned AND the new peer claims a different > upstream reference, start using it, but flush the statistics related to the > previous peer. > > A different address to the same server could be routed differently and > have a different network delay, so I'd suggest to reset the state on > all address changes. [Windl, Ulrich] Isn't that a non-argument as IP datagram routing may change anytime, even when using the same IP? > > -- > Miroslav Lichvar
- [Ntp] Re: [EXT] Re: NTPv5 Requirements vs. NTPv5 … Miroslav Lichvar
- [Ntp] Re: [EXT] NTPv5 Requirements vs. NTPv5 Spec Windl, Ulrich
- [Ntp] Re: [EXT] Re: Re: NTPv5 Requirements vs. NT… Miroslav Lichvar
- [Ntp] Re: [EXT] Re: Re: NTPv5 Requirements vs. NT… Mike Ellis
- [Ntp] Re: NTPv5 Requirements vs. NTPv5 Spec Richard Laager
- [Ntp] NTPv5 Requirements vs. NTPv5 Spec Tal Mizrahi
- [Ntp] Re: [EXT] NTPv5 Requirements vs. NTPv5 Spec Miroslav Lichvar
- [Ntp] Re: [EXT] Re: Re: NTPv5 Requirements vs. NT… Windl, Ulrich
- [Ntp] Re: [EXT] Re: Re: NTPv5 Requirements vs. NT… Tal Mizrahi
- [Ntp] Re: [EXT] Re: NTPv5 Requirements vs. NTPv5 … Windl, Ulrich
- [Ntp] Re: NTPv5 Requirements vs. NTPv5 Spec Windl, Ulrich
- [Ntp] Re: [EXT] Re: NTPv5 Requirements vs. NTPv5 … Miroslav Lichvar
- [Ntp] Re: NTPv5 Requirements vs. NTPv5 Spec Miroslav Lichvar
- [Ntp] Re: [EXT] Re: NTPv5 Requirements vs. NTPv5 … Richard Laager
- [Ntp] Re: [EXT] Re: NTPv5 Requirements vs. NTPv5 … Richard Laager
- [Ntp] Re: [EXT] Re: NTPv5 Requirements vs. NTPv5 … Miroslav Lichvar
- [Ntp] NTP DDoS Attacks (Was: Re: NTPv5 Requiremen… Richard Laager
- [Ntp] Re: [EXT] Re: NTPv5 Requirements vs. NTPv5 … Richard Laager
- [Ntp] Re: [EXT] Re: NTPv5 Requirements vs. NTPv5 … Daniel Franke
- [Ntp] Re: NTP DDoS Attacks (Was: Re: NTPv5 Requir… Dave Hart
- [Ntp] Re: NTP DDoS Attacks (Was: Re: NTPv5 Requir… Richard Laager
- [Ntp] Re: [EXT] Re: Re: NTPv5 Requirements vs. NT… Dave Hart
- [Ntp] Re: [EXT] Re: Re: NTPv5 Requirements vs. NT… Daniel Franke
- [Ntp] Re: NTPv5 Requirements vs. NTPv5 Spec Daniel Franke
- [Ntp] Re: NTP DDoS Attacks (Was: Re: NTPv5 Requir… Dave Hart
- [Ntp] Re: NTP DDoS Attacks (Was: Re: NTPv5 Requir… Richard Laager
- [Ntp] Re: NTP DDoS Attacks (Was: Re: NTPv5 Requir… Dave Hart
- [Ntp] Re: NTP DDoS Attacks (Was: Re: NTPv5 Requir… Richard Laager
- [Ntp] Re: NTP DDoS Attacks (Was: Re: NTPv5 Requir… Dave Hart
- [Ntp] Re: NTP DDoS Attacks (Was: Re: NTPv5 Requir… Hal Murray
- [Ntp] Re: [EXT] Re: Re: Re: Re: NTPv5 Requirement… Windl, Ulrich
- [Ntp] Re: NTP DDoS Attacks (Was: Re: NTPv5 Requir… Miroslav Lichvar
- [Ntp] Re: [EXT] Re: Re: Re: Re: NTPv5 Requirement… Dave Hart
- [Ntp] Re: [EXT] Re: Re: Re: Re: Re: NTPv5 Require… Windl, Ulrich
- [Ntp] Re: NTP DDoS Attacks (Was: Re: NTPv5 Requir… Dave Hart
- [Ntp] Re: [EXT] Re: Re: Re: Re: Re: NTPv5 Require… Dave Hart
- [Ntp] Re: NTP DDoS Attacks Richard Laager
- [Ntp] Re: [EXT] NTP DDoS Attacks (Was: Re: NTPv5 … Windl, Ulrich
- [Ntp] Re: NTP DDoS Attacks Dave Hart