2014-08-26 17:33:55 +02:00
#!/bin/sh
#################################################################################
#
# Lynis
# ------------------
#
2016-03-13 16:00:39 +01:00
# Copyright 2007-2013, Michael Boelen
2021-01-07 15:22:19 +01:00
# Copyright 2007-2021, CISOfy
2016-03-13 16:00:39 +01:00
#
# Website : https://cisofy.com
# Blog : http://linux-audit.com
# GitHub : https://github.com/CISOfy/lynis
2014-08-26 17:33:55 +02:00
#
# Lynis comes with ABSOLUTELY NO WARRANTY. This is free software, and you are
# welcome to redistribute it under the terms of the GNU General Public License.
# See LICENSE file for usage of this software.
#
#################################################################################
#
# Time
#
#################################################################################
#
2020-10-22 00:13:42 +02:00
InsertSection "${SECTION_TIME_AND_SYNCHRONIZATION}"
2014-08-26 17:33:55 +02:00
#
#################################################################################
#
2017-04-23 20:06:24 +02:00
CRON_DIRS="${ROOTDIR}etc/cron.d ${ROOTDIR}etc/cron.hourly ${ROOTDIR}etc/cron.daily ${ROOTDIR}etc/cron.weekly ${ROOTDIR}etc/cron.monthly ${ROOTDIR}var/spool/crontabs"
2016-10-19 11:28:20 +02:00
CHRONY_CONF_FILE=""
2014-08-26 17:33:55 +02:00
NTP_DAEMON=""
NTP_DAEMON_RUNNING=0
NTP_CONFIG_FOUND=0
NTP_CONFIG_TYPE_DAEMON=0
NTP_CONFIG_TYPE_SCHEDULED=0
NTP_CONFIG_TYPE_EVENTBASED=0
NTP_CONFIG_TYPE_STARTUP=0
2015-07-22 17:37:11 +02:00
NTPD_RUNNING=0 # Specific for ntpd
2020-01-08 18:53:15 +01:00
OPENNTPD_COMMUNICATION=0 # if ntpctl can communicate
2015-05-25 17:33:51 +02:00
SYSTEMD_NTP_ENABLED=0
2014-08-26 17:33:55 +02:00
#
#################################################################################
#
# Test : TIME-3104
# Description : Check for a running NTP daemon
if [ -f /sys/hypervisor/type ]; then
2016-10-19 11:28:20 +02:00
# TODO: Skip NTP tests if we are in a DomU xen instance
2016-09-01 17:33:18 +02:00
FIND=$(cat /sys/hypervisor/type)
if [ "${FIND}" = "xen" ]; then PREQS_MET="NO"; else PREQS_MET="YES"; fi
2017-03-06 08:41:21 +01:00
elif [ -f /sbin/sysctl ] && [ "$(/sbin/sysctl -n security.jail.jailed 2>/dev/null || echo 0)" -eq 1 ]; then
2016-09-22 11:39:55 +02:00
# Skip NTP tests if we're in a FreeBSD jail
PREQS_MET="NO"
2016-09-01 17:33:18 +02:00
else
PREQS_MET="YES"
2014-08-26 17:33:55 +02:00
fi
2016-07-24 17:22:00 +02:00
Register --test-no TIME-3104 --preqs-met ${PREQS_MET} --weight L --network NO --category security --description "Check for running NTP daemon or client"
2014-08-26 17:33:55 +02:00
if [ ${SKIPTEST} -eq 0 ]; then
2015-05-25 17:33:51 +02:00
# Linux/FreeBSD (ntpdate), OpenBSD (ntpd, rdate), Chrony, systemd-timesyncd
2015-12-21 21:17:15 +01:00
LogText "Test: Searching for a running NTP daemon or available client"
2014-08-26 17:33:55 +02:00
FOUND=0
2016-10-19 11:28:20 +02:00
SEARCH_FILES="${ROOTDIR}etc/chrony.conf ${ROOTDIR}etc/chrony/chrony.conf"
for FILE in ${SEARCH_FILES}; do
if [ -f ${FILE} ]; then LogText "result: found chrony configuration: ${FILE}"; CHRONY_CONF_FILE="${FILE}"; fi
done
2019-07-16 13:20:30 +02:00
if [ -n "${CHRONY_CONF_FILE}" ]; then
2019-07-26 11:32:48 +02:00
if IsRunning "chronyd"; then
2015-05-25 17:45:41 +02:00
FOUND=1; NTP_DAEMON_RUNNING=1; NTP_CONFIG_TYPE_DAEMON=1; NTP_DAEMON="chronyd"
2016-06-18 11:14:01 +02:00
Display --indent 2 --text "- NTP daemon found: chronyd" --result "${STATUS_FOUND}" --color GREEN
2016-10-19 11:28:20 +02:00
else
LogText "Result: found chrony configuration, but no running daemon"
2015-05-25 17:45:41 +02:00
fi
2016-10-19 11:28:20 +02:00
else
LogText "Result: no chrony configuration found"
2015-05-25 17:33:51 +02:00
fi
# Check time daemon (eg DragonFly BSD)
2019-07-26 11:32:48 +02:00
if IsRunning "dntpd"; then
2015-05-25 17:33:51 +02:00
FOUND=1; NTP_DAEMON_RUNNING=1; NTP_CONFIG_TYPE_DAEMON=1; NTP_DAEMON="dntpd"
2016-06-18 11:14:01 +02:00
Display --indent 2 --text "- NTP daemon found: dntpd" --result "${STATUS_FOUND}" --color GREEN
2015-05-25 17:33:51 +02:00
fi
2020-01-08 18:53:15 +01:00
# Check for OpenNTPD, ntpctl comes with a "regular" install
2020-03-25 19:33:55 +01:00
if [ -n "${NTPCTLBINARY}" ]; then
2020-01-08 18:53:15 +01:00
# In contrast to timectl, "synchronised: yes" is not grepped.
# Reason: openntpd syncs only if large time corrections are not required or -s is passed.
# This might be not intended by the administrator (-s is NOT the default!)
FIND=$(${PSBINARY} ax | ${GREPBINARY} "ntpd: ntp engine" | ${GREPBINARY} -v "grep")
2020-11-09 05:17:05 +01:00
# Status code 0 is when communication over the socket is successful
2020-07-10 00:40:36 +02:00
if ${NTPCTLBINARY} -s status > /dev/null 2> /dev/null; then
2020-01-08 18:53:15 +01:00
FOUND=1; NTP_DAEMON_RUNNING=1; NTP_CONFIG_TYPE_DAEMON=1; NTP_DAEMON="openntpd"
LogText "result: found openntpd (method: ntpctl)"
OPENNTPD_COMMUNICATION=1
elif [ -n "${FIND}" ] ; then
# Reasons for ntpctl to fail might be someone spawned a new process thus overwriting the socket,
# then ended it, but another openntpd process is still running
FOUND=1; NTP_DAEMON_RUNNING=1; NTP_CONFIG_TYPE_DAEMON=1; NTP_DAEMON="openntpd"
LogText "result: found openntpd (method: ps)"
else
2020-11-09 05:16:52 +01:00
LogText "result: running openntpd not found, but ntpctl is installed"
2020-01-08 18:53:15 +01:00
fi
2020-07-10 00:41:45 +02:00
if [ "${NTP_DAEMON}" = "openntpd" ]; then
2020-01-08 18:53:15 +01:00
Display --indent 2 --text "- NTP daemon found: OpenNTPD" --result "${STATUS_FOUND}" --color GREEN
fi
fi
# Check running processes (ntpd from ntp.org)
2020-11-09 05:16:33 +01:00
# As checking by process name is ambiguous (openntpd has the same process name),
2020-01-08 18:53:15 +01:00
# this check will be skipped if openntpd has been found.
FIND=$(${PSBINARY} ax | ${GREPBINARY} "ntpd" | ${GREPBINARY} -v "dntpd" | ${GREPBINARY} -v "ntpd: " | ${GREPBINARY} -v "grep")
if [ "${NTP_DAEMON}" != "openntpd" ] && [ -n "${FIND}" ]; then
2014-08-26 17:33:55 +02:00
FOUND=1; NTPD_RUNNING=1; NTP_DAEMON_RUNNING=1; NTP_CONFIG_TYPE_DAEMON=1
NTP_DAEMON="ntpd"
2015-12-21 21:17:15 +01:00
LogText "Result: found running NTP daemon in process list"
2016-06-18 11:14:01 +02:00
Display --indent 2 --text "- NTP daemon found: ntpd" --result "${STATUS_FOUND}" --color GREEN
2014-08-26 17:33:55 +02:00
fi
# Check time daemon (eg NetBSD)
2019-07-26 11:32:48 +02:00
if IsRunning "timed"; then
2014-08-26 17:33:55 +02:00
FOUND=1; NTP_DAEMON_RUNNING=1; NTP_CONFIG_TYPE_DAEMON=1; NTP_DAEMON="timed"
2016-06-18 11:14:01 +02:00
Display --indent 2 --text "- NTP daemon found: timed" --result "${STATUS_FOUND}" --color GREEN
2014-08-26 17:33:55 +02:00
fi
2014-09-12 17:24:29 +02:00
# Check timedate daemon (systemd)
2020-07-09 18:19:35 +02:00
FIND=$(${PSBINARY} ax | ${GREPBINARY} "systemd-timesyncd" | ${GREPBINARY} -v "grep")
if [ -n "${FIND}" ]; then
FOUND=1; NTP_DAEMON_RUNNING=1; NTP_CONFIG_TYPE_DAEMON=1; NTP_DAEMON="systemd-timesyncd"
Display --indent 2 --text "- NTP daemon found: systemd (timesyncd)" --result "${STATUS_FOUND}" --color GREEN
LogText "Result: Found running systemd-timesyncd in process list"
2014-08-26 17:33:55 +02:00
fi
# Check crontab for OpenBSD/FreeBSD
# Check anacrontab for Linux
CRONTAB_FILES="/etc/anacrontab /etc/crontab"
2020-07-10 00:29:35 +02:00
# Regex for matching multiple time synchronisation binaries
# Partial sanity check for sntp and ntpdig, but this does not consider all corner cases
CRONTAB_REGEX='ntpdate|rdate|sntp.+-(s|j|--adj)|ntpdig.+-(S|s)'
2014-08-26 17:33:55 +02:00
for I in ${CRONTAB_FILES}; do
if [ -f ${I} ]; then
2020-07-10 00:29:35 +02:00
LogText "Test: checking for ntpdate, rdate, sntp or ntpdig in crontab file ${I}"
2023-04-23 23:38:21 +02:00
FIND=$(${GREPBINARY} -E "${CRONTAB_REGEX}" ${I} | ${GREPBINARY} -v '^#')
2019-07-16 13:20:30 +02:00
if [ -n "${FIND}" ]; then
2014-10-13 19:19:40 +02:00
FOUND=1; NTP_CONFIG_TYPE_SCHEDULED=1
2016-06-18 11:14:01 +02:00
Display --indent 2 --text "- Checking NTP client in crontab file (${I})" --result "${STATUS_FOUND}" --color GREEN
2020-07-10 00:29:35 +02:00
LogText "Result: found ntpdate, rdate, sntp or ntpdig reference in crontab file ${I}"
2016-09-01 17:33:18 +02:00
else
2016-06-18 11:14:01 +02:00
#Display --indent 2 --text "- Checking NTP client in crontab file (${I})" --result "${STATUS_NOT_FOUND}" --color WHITE
2020-07-10 00:29:35 +02:00
LogText "Result: no ntpdate, rdate, sntp or ntpdig reference found in crontab file ${I}"
2014-08-26 17:33:55 +02:00
fi
2016-09-01 17:33:18 +02:00
else
2015-12-21 21:17:15 +01:00
LogText "Result: crontab file ${I} not found"
2015-05-25 17:45:41 +02:00
fi
2014-08-26 17:33:55 +02:00
done
2020-04-01 16:16:31 +02:00
# Notes: only test for normal files. File /etc/cron.d/FIFO on solaris is a special file and test may hang
# Linux systems may have a .placeholder file
2014-08-26 17:33:55 +02:00
FOUND_IN_CRON=0
# Check cron jobs
for I in ${CRON_DIRS}; do
2020-07-10 00:29:35 +02:00
for J in "${I}"/*; do # iterate over folders in a safe way
# Check: regular file, readable and not called .placeholder
2023-04-23 23:38:21 +02:00
FIND=$(echo "${J}" | ${GREPBINARY} -E '/.placeholder$')
2020-07-10 00:29:35 +02:00
if [ -f "${J}" ] && [ -r "${J}" ] && [ -z "${FIND}" ]; then
LogText "Test: checking for ntpdate, rdate, sntp or ntpdig in ${J}"
2023-08-08 11:11:02 +02:00
FIND=$("${GREPBINARY}" -E "${CRONTAB_REGEX}" "${J}" | "${GREPBINARY}" -v "^#")
2019-07-16 13:20:30 +02:00
if [ -n "${FIND}" ]; then
2020-07-10 00:29:35 +02:00
FOUND=1; FOUND_IN_CRON=1; NTP_CONFIG_TYPE_SCHEDULED=1
LogText "Result: found ntpdate, rdate, sntp or ntpdig in ${J}"
2017-03-13 11:59:05 +01:00
fi
2014-08-26 17:33:55 +02:00
fi
2020-07-10 00:29:35 +02:00
done
2014-08-26 17:33:55 +02:00
done
if [ ${FOUND_IN_CRON} -eq 1 ]; then
2016-06-18 11:14:01 +02:00
Display --indent 2 --text "- Checking NTP client in cron files" --result "${STATUS_FOUND}" --color GREEN
2015-12-21 21:17:15 +01:00
LogText "Result: found ntpdate or rdate in cron directory"
2016-09-01 17:33:18 +02:00
else
2015-12-21 21:17:15 +01:00
LogText "Result: no ntpdate or rdate found in cron directories"
2014-08-26 17:33:55 +02:00
fi
# Checking if ntpdate is performed by event
2015-12-21 21:17:15 +01:00
LogText "Test: checking for file /etc/network/if-up.d/ntpdate"
2014-08-26 17:33:55 +02:00
if [ -f /etc/network/if-up.d/ntpdate ]; then
2015-12-21 21:17:15 +01:00
LogText "Result: found ntpdate action when network interface comes up"
2014-08-26 17:33:55 +02:00
FOUND=1
NTP_CONFIG_TYPE_EVENTBASED=1
2016-06-18 11:14:01 +02:00
Display --indent 2 --text "- Checking event based ntpdate (if-up)" --result "${STATUS_FOUND}" --color GREEN
2016-09-01 17:33:18 +02:00
else
2015-12-21 21:17:15 +01:00
LogText "Result: file /etc/network/if-up.d/ntpdate does not exist"
2014-08-26 17:33:55 +02:00
fi
2014-12-08 23:57:47 +01:00
# Configuration file for *BSD
if [ -f /etc/rc.conf ]; then
2016-09-01 17:33:18 +02:00
LogText "Test: Checking if ntpdate is enabled at startup in *BSD"
FIND=$(${GREPBINARY} 'ntpdate_enable="YES"' /etc/rc.conf)
2019-07-16 13:20:30 +02:00
if [ -n "${FIND}" ]; then
2016-09-01 17:33:18 +02:00
LogText "Result: ntpdate is enabled in rc.conf"
FOUND=1
NTP_CONFIG_TYPE_STARTUP=1
# Only show suggestion when ntpdate is enabled, however ntpd is not running
if [ ${NTP_DAEMON_RUNNING} -eq 0 ]; then
2019-12-18 12:17:46 +01:00
ReportSuggestion "${TEST_NO}" "Although ntpdate is enabled in rc.conf, it is advised to run it at least daily or use a NTP daemon"
2014-08-26 17:33:55 +02:00
fi
2016-09-01 17:33:18 +02:00
else
LogText "Result: ntpdate is not enabled in rc.conf"
fi
2014-08-26 17:33:55 +02:00
fi
if [ ${FOUND} -eq 0 ]; then
2014-12-08 23:57:47 +01:00
if [ ${ISVIRTUALMACHINE} -eq 1 ]; then
2015-12-21 21:17:15 +01:00
LogText "Result: Skipping display warning, as virtual machines usually don't need time synchronization in the VM itself"
2016-09-01 17:33:18 +02:00
else
2016-06-18 11:14:01 +02:00
Display --indent 2 --text "- Checking for a running NTP daemon or client" --result "${STATUS_WARNING}" --color RED
2015-12-21 21:17:15 +01:00
LogText "Result: Could not find a NTP daemon or client"
2019-12-18 12:17:46 +01:00
ReportSuggestion "${TEST_NO}" "Use NTP daemon or NTP client to prevent time issues."
2014-12-08 23:57:47 +01:00
AddHP 0 2
fi
2016-09-01 17:33:18 +02:00
else
2016-06-18 11:14:01 +02:00
Display --indent 2 --text "- Checking for a running NTP daemon or client" --result "${STATUS_OK}" --color GREEN
2015-12-21 21:17:15 +01:00
LogText "Result: Found a time syncing daemon/client."
2014-08-26 17:33:55 +02:00
AddHP 3 3
fi
fi
#
#################################################################################
2015-05-25 17:33:51 +02:00
#
# Test : TIME-3106
# Description : Check status of systemd time synchronization
2019-07-16 13:20:30 +02:00
if [ ${SYSTEMD_NTP_ENABLED} -eq 1 -a -n "${TIMEDATECTL}" ]; then PREQS_MET="YES"; else PREQS_MET="NO"; fi
2016-07-24 17:22:00 +02:00
Register --test-no TIME-3106 --preqs-met ${PREQS_MET} --weight L --network NO --category security --description "Check systemd NTP time synchronization status"
2015-05-25 17:33:51 +02:00
if [ ${SKIPTEST} -eq 0 ]; then
2015-12-21 21:17:15 +01:00
LogText "Test: Check the status of time synchronization via timedatectl"
2023-04-23 23:38:21 +02:00
FIND=$(${TIMEDATECTL} status | ${GREPBINARY} -E "(NTP|System clock) synchronized: yes")
2016-09-01 17:33:18 +02:00
if [ -z "${FIND}" ]; then
2015-12-21 21:17:15 +01:00
LogText "Result: time not synchronized via NTP"
2019-09-21 16:31:06 +02:00
ReportSuggestion "${TEST_NO}" "Check timedatectl output. Synchronization via NTP is enabled, but status reflects it is not synchronized"
2015-05-25 17:33:51 +02:00
fi
fi
#
#################################################################################
2014-08-26 17:33:55 +02:00
#
# Test : TIME-3112
# Description : Check for valid associations from ntpq peers list
2019-07-16 13:20:30 +02:00
if [ ${NTPD_RUNNING} -eq 1 -a -n "${NTPQBINARY}" ]; then PREQS_MET="YES"; else PREQS_MET="NO"; fi
2016-07-24 17:22:00 +02:00
Register --test-no TIME-3112 --preqs-met ${PREQS_MET} --weight L --network NO --category security --description "Check active NTP associations ID's"
2014-08-26 17:33:55 +02:00
if [ ${SKIPTEST} -eq 0 ]; then
2015-12-21 21:17:15 +01:00
LogText "Test: Checking for NTP association ID's from ntpq peers list"
2016-09-01 17:33:18 +02:00
FIND=$(${NTPQBINARY} -p -n | ${GREPBINARY} "No association ID's returned")
if [ -z "${FIND}" ]; then
2016-06-18 11:14:01 +02:00
Display --indent 2 --text "- Checking valid association ID's" --result "${STATUS_FOUND}" --color GREEN
2015-12-21 21:17:15 +01:00
LogText "Result: Found one or more association ID's"
2016-09-01 17:33:18 +02:00
else
2016-06-18 11:14:01 +02:00
Display --indent 2 --text "- Checking valid association ID's" --result "${STATUS_WARNING}" --color RED
2019-12-18 12:17:46 +01:00
ReportSuggestion "${TEST_NO}" "Check ntp.conf for properly configured NTP servers and a correctly functioning name service."
2014-08-26 17:33:55 +02:00
fi
fi
#
#################################################################################
#
# Test : TIME-3116
# Description : Check for stratum 16 peers
2019-07-16 13:20:30 +02:00
if [ ${NTPD_RUNNING} -eq 1 -a -n "${NTPQBINARY}" ]; then PREQS_MET="YES"; else PREQS_MET="NO"; fi
2016-07-24 17:22:00 +02:00
Register --test-no TIME-3116 --preqs-met ${PREQS_MET} --weight L --network NO --category security --description "Check peers with stratum value of 16"
2014-08-26 17:33:55 +02:00
if [ ${SKIPTEST} -eq 0 ]; then
2017-04-30 17:59:35 +02:00
COUNT=0
2015-12-21 21:17:15 +01:00
LogText "Test: Checking stratum 16 sources from ntpq peers list"
2017-02-18 14:28:56 +01:00
FIND=$(${NTPQBINARY} -p -n | ${AWKBINARY} '{ if ($2!=".POOL." && $3=="16") { print $1 }}')
2017-03-13 11:59:05 +01:00
if [ -z "${FIND}" ]; then
2016-06-18 11:14:01 +02:00
Display --indent 2 --text "- Checking high stratum ntp peers" --result "${STATUS_OK}" --color GREEN
2015-12-21 21:17:15 +01:00
LogText "Result: All peers are lower than stratum 16"
2016-09-01 17:33:18 +02:00
else
2017-04-30 17:59:35 +02:00
for ITEM in ${FIND}; do
LogText "Found stratum 16 peer: ${ITEM}"
2023-04-23 23:38:21 +02:00
FIND2=$(${GREPBINARY} -E "^ntp-ignore-stratum-16-peer=${ITEM}" ${PROFILE})
2017-04-30 17:59:35 +02:00
if IsEmpty "${FIND2}"; then
COUNT=$((COUNT + 1))
Report "ntp_stratum_16_peer[]=${ITEM}"
2016-09-01 17:33:18 +02:00
else
2017-04-30 17:59:35 +02:00
LogText "Output: host ${ITEM} ignored by profile"
2014-08-26 17:33:55 +02:00
fi
done
# Check if one or more high stratum time servers are found
2017-04-30 17:59:35 +02:00
if [ ${COUNT} -eq 0 ]; then
2016-06-18 11:14:01 +02:00
Display --indent 2 --text "- Checking high stratum ntp peers" --result "${STATUS_OK}" --color GREEN
2015-12-21 21:17:15 +01:00
LogText "Result: all non local servers are lower than stratum 16, or whitelisted within the scan profile"
2016-09-01 17:33:18 +02:00
else
2016-06-18 11:14:01 +02:00
Display --indent 2 --text "- Checking high stratum ntp peers" --result "${STATUS_WARNING}" --color RED
2017-04-30 17:59:35 +02:00
LogText "Result: Found ${COUNT} high stratum (16) peers)"
2019-12-18 12:17:46 +01:00
ReportSuggestion "${TEST_NO}" "Check ntpq peers output for stratum 16 peers"
2014-08-26 17:33:55 +02:00
fi
fi
fi
#
#################################################################################
#
# Test : TIME-3120
# Description : Check unreliable peers from peer list
# Notes : Items with # are too far away (network distance)
2017-03-06 08:41:21 +01:00
# Items with - are not chosen due clustering algorithm
2019-07-16 13:20:30 +02:00
if [ ${NTPD_RUNNING} -eq 1 -a -n "${NTPQBINARY}" ]; then PREQS_MET="YES"; else PREQS_MET="NO"; fi
2016-07-24 17:22:00 +02:00
Register --test-no TIME-3120 --preqs-met ${PREQS_MET} --weight L --network NO --category security --description "Check unreliable NTP peers"
2014-08-26 17:33:55 +02:00
if [ ${SKIPTEST} -eq 0 ]; then
2015-12-21 21:17:15 +01:00
LogText "Test: Checking unreliable ntp peers"
2023-04-23 23:38:21 +02:00
FIND=$(${NTPQBINARY} -p -n | ${GREPBINARY} -E "^(-|#)" | ${AWKBINARY} '{ print $1 }' | ${SEDBINARY} 's/^-//g')
2017-03-13 11:59:05 +01:00
if [ -z "${FIND}" ]; then
2016-06-18 11:14:01 +02:00
Display --indent 2 --text "- Checking unreliable ntp peers" --result "${STATUS_NONE}" --color GREEN
2015-12-21 21:17:15 +01:00
LogText "Result: No unreliable peers found"
2017-03-13 11:59:05 +01:00
else
2016-06-18 11:14:01 +02:00
Display --indent 2 --text "- Checking unreliable ntp peers" --result "${STATUS_FOUND}" --color YELLOW
2015-12-21 21:17:15 +01:00
LogText "Result: Found one or more unreliable peers (marked with a minus or dash sign)"
2014-08-26 17:33:55 +02:00
for I in ${FIND}; do
2015-12-21 21:17:15 +01:00
LogText "Unreliable peer: ${I}"
2016-04-28 08:51:43 +02:00
Report "ntp_unreliable_peer[]=${I}"
2014-08-26 17:33:55 +02:00
done
2019-12-18 12:17:46 +01:00
ReportSuggestion "${TEST_NO}" "Check ntpq peers output for unreliable ntp peers and correct/replace them"
2014-08-26 17:33:55 +02:00
fi
fi
#
#################################################################################
#
# Test : TIME-3124
# Description : Check selected time source
2019-07-16 13:20:30 +02:00
if [ ${NTPD_RUNNING} -eq 1 -a -n "${NTPQBINARY}" ]; then PREQS_MET="YES"; else PREQS_MET="NO"; fi
2016-07-24 17:22:00 +02:00
Register --test-no TIME-3124 --preqs-met ${PREQS_MET} --weight L --network NO --category security --description "Check selected time source"
2014-08-26 17:33:55 +02:00
if [ ${SKIPTEST} -eq 0 ]; then
2015-12-21 21:17:15 +01:00
LogText "Test: Checking selected time source"
2016-09-01 17:33:18 +02:00
FIND=$(${NTPQBINARY} -p -n | ${GREPBINARY} '^*' | ${AWKBINARY} '{ if ($4=="l") { print $1 } }')
FIND2=$(${NTPQBINARY} -p -n | ${GREPBINARY} '^*' | ${AWKBINARY} '{ print $1 }')
2019-07-16 13:20:30 +02:00
if [ -z "${FIND}" -a -n "${FIND2}" ]; then
2016-06-18 11:14:01 +02:00
Display --indent 2 --text "- Checking selected time source" --result "${STATUS_OK}" --color GREEN
2017-03-06 08:41:21 +01:00
FIND2=$(echo ${FIND2} | ${SEDBINARY} 's/*//g')
2015-12-21 21:17:15 +01:00
LogText "Result: Found selected time source (value: ${FIND2})"
2016-09-01 17:33:18 +02:00
else
2016-06-18 11:14:01 +02:00
Display --indent 2 --text "- Checking selected time source" --result "${STATUS_WARNING}" --color RED
2015-12-21 21:17:15 +01:00
LogText "Result: Found local source as selected time source. This could indicate that no external sources are available to sync with."
LogText "Local source: ${FIND}"
2019-12-18 12:17:46 +01:00
ReportSuggestion "${TEST_NO}" "Check ntpq peers output for selected time source"
2014-08-26 17:33:55 +02:00
fi
fi
#
#################################################################################
#
# Test : TIME-3128
# Description : Check time source candidates
2019-07-16 13:20:30 +02:00
if [ ${NTPD_RUNNING} -eq 1 -a -n "${NTPQBINARY}" ]; then PREQS_MET="YES"; else PREQS_MET="NO"; fi
2016-10-19 11:17:33 +02:00
Register --test-no TIME-3128 --preqs-met ${PREQS_MET} --weight L --network NO --category security --description "Check preferred time source"
2014-08-26 17:33:55 +02:00
if [ ${SKIPTEST} -eq 0 ]; then
2015-12-21 21:17:15 +01:00
LogText "Test: Checking preferred time source"
2016-09-01 17:33:18 +02:00
FIND=$(${NTPQBINARY} -p -n | ${GREPBINARY} '^+' | ${AWKBINARY} '{ print $1 }')
if [ -z "${FIND}" ]; then
2016-06-18 11:14:01 +02:00
Display --indent 2 --text "- Checking time source candidates" --result "${STATUS_NONE}" --color YELLOW
2015-12-21 21:17:15 +01:00
LogText "Result: No other time source candidates found"
2019-12-18 12:17:46 +01:00
ReportSuggestion "${TEST_NO}" "Check ntpq peers output for time source candidates"
2016-09-01 17:33:18 +02:00
else
2016-06-18 11:14:01 +02:00
Display --indent 2 --text "- Checking time source candidates" --result "${STATUS_OK}" --color GREEN
2015-12-21 21:17:15 +01:00
LogText "Result: Found one or more candidates to synchronize time with."
2016-09-01 17:33:18 +02:00
for I in ${FIND}; do
2016-09-08 21:04:17 +02:00
I=$(echo ${I} | ${SEDBINARY} 's/+//g')
2015-12-21 21:17:15 +01:00
LogText "Candidate found: ${I}"
2014-08-26 17:33:55 +02:00
done
fi
fi
#
#################################################################################
#
# Test : TIME-3132
# Description : Check ntpq falsetickers
2019-07-16 13:20:30 +02:00
if [ ${NTPD_RUNNING} -eq 1 -a -n "${NTPQBINARY}" ]; then PREQS_MET="YES"; else PREQS_MET="NO"; fi
2016-07-24 17:22:00 +02:00
Register --test-no TIME-3132 --preqs-met ${PREQS_MET} --weight L --network NO --category security --description "Check NTP falsetickers"
2014-08-26 17:33:55 +02:00
if [ ${SKIPTEST} -eq 0 ]; then
2015-12-21 21:17:15 +01:00
LogText "Test: Checking preferred time source"
2023-04-23 23:38:21 +02:00
FIND=$(${NTPQBINARY} -p -n | ${GREPBINARY} -E '^x')
2016-09-01 17:33:18 +02:00
if [ -z "${FIND}" ]; then
2016-06-18 11:14:01 +02:00
Display --indent 2 --text "- Checking falsetickers" --result "${STATUS_OK}" --color GREEN
2018-04-23 10:54:44 +02:00
LogText "Result: No falsetickers found (items preceding with an 'x')"
2016-09-01 17:33:18 +02:00
else
2016-06-18 11:14:01 +02:00
Display --indent 2 --text "- Checking falsetickers" --result "${STATUS_NONE}" --color YELLOW
2018-04-23 10:54:44 +02:00
LogText "Result: Found one or more falsetickers (items preceding with an 'x')"
2014-08-26 17:33:55 +02:00
for I in ${FIND}; do
2016-09-08 21:04:17 +02:00
I=$(echo ${I} | ${SEDBINARY} 's/x//g')
2015-12-21 21:17:15 +01:00
LogText "Falseticker found: ${I}"
2016-04-28 08:51:43 +02:00
Report "ntp_falseticker[]=${I}"
2014-08-26 17:33:55 +02:00
done
2019-12-18 12:17:46 +01:00
ReportSuggestion "${TEST_NO}" "Check ntpq peers output for falsetickers"
2014-08-26 17:33:55 +02:00
fi
fi
#
#################################################################################
#
# Test : TIME-3136
# Description : Check ntpq reported ntp version (Linux)
2019-07-16 13:20:30 +02:00
if [ ${NTPD_RUNNING} -eq 1 -a -n "${NTPQBINARY}" ]; then PREQS_MET="YES"; else PREQS_MET="NO"; fi
2016-07-24 17:22:00 +02:00
Register --test-no TIME-3136 --os Linux --preqs-met ${PREQS_MET} --weight L --network NO --category security --description "Check NTP protocol version"
2014-08-26 17:33:55 +02:00
if [ ${SKIPTEST} -eq 0 ]; then
2015-12-21 21:17:15 +01:00
LogText "Test: Checking NTP protocol version (ntpq -c ntpversion)"
2016-09-01 17:33:18 +02:00
FIND=$(${NTPQBINARY} -c ntpversion | ${AWKBINARY} '{ if ($1=="NTP" && $2=="version" && $5=="is") { print $6 } }')
if [ -z "${FIND}" ]; then
2016-06-18 11:14:01 +02:00
Display --indent 2 --text "- Checking NTP version" --result "${STATUS_UNKNOWN}" --color YELLOW
2015-12-21 21:17:15 +01:00
LogText "Result: No NTP version found"
2019-12-18 12:17:46 +01:00
ReportSuggestion "${TEST_NO}" "Check ntpq output for NTP protocol version"
2016-09-01 17:33:18 +02:00
else
2016-06-18 11:14:01 +02:00
Display --indent 2 --text "- Checking NTP version" --result "${STATUS_FOUND}" --color GREEN
2015-12-21 21:17:15 +01:00
LogText "Result: Found NTP version ${FIND}"
Report "ntp_version=${FIND}"
2014-08-26 17:33:55 +02:00
fi
fi
#
#################################################################################
#
# Test : TIME-3146
# Description : Check /etc/default/ntpdate (Linux)
# Notes : ntpdate-debian binary
2019-07-16 13:20:30 +02:00
#if [ ${NTPD_RUNNING} -eq 1 -a -n "${NTPQBINARY}" ]; then PREQS_MET="YES"; else PREQS_MET="NO"; fi
2016-07-24 17:22:00 +02:00
#Register --test-no TIME-3146 --os Linux --preqs-met ${PREQS_MET} --weight L --network NO --category security --description "Check /etc/default/ntpdate"
2014-08-26 17:33:55 +02:00
#if [ ${SKIPTEST} -eq 0 ]; then
#
#################################################################################
2017-02-22 15:06:19 +01:00
#
# Test : TIME-3148
# Description : Check if TZ variable is set (Linux)
# Notes : without TZ variable set, a lot of unneeded calls might be performed.
Register --test-no TIME-3148 --os Linux --weight L --network NO --category performance --description "Check TZ variable"
if [ ${SKIPTEST} -eq 0 ]; then
2017-04-23 20:06:24 +02:00
LogText "Test: testing for TZ variable"
FIND="${TZ:=notset}"
LogText "Result: found TZ variable with value ${FIND}"
if [ "${FIND}" = "notset" ]; then
2017-02-22 15:06:19 +01:00
Report "tz_variable_empty=1"
fi
fi
#
#################################################################################
2014-08-26 17:33:55 +02:00
#
# Test : TIME-3160
# Description : Check empty NTP step-tickers
# Notes : Mostly applies to Red Hat and clones
2018-03-10 12:26:09 +01:00
FILE="${ROOTDIR}etc/ntp/step-tickers"
2019-07-16 13:20:30 +02:00
if [ "${NTPD_RUNNING}" -eq 1 -a -n "${NTPQBINARY}" -a -f "${FILE}" ]; then PREQS_MET="YES"; else PREQS_MET="NO"; fi
2016-07-24 17:22:00 +02:00
Register --test-no TIME-3160 --os Linux --preqs-met ${PREQS_MET} --weight L --network NO --category security --description "Check empty NTP step-tickers"
2014-08-26 17:33:55 +02:00
if [ ${SKIPTEST} -eq 0 ]; then
FOUND=0
2018-03-10 12:26:09 +01:00
OUTPUT=$(${AWKBINARY} '/^[a-z0-9]/ { print $1 }' ${FILE})
if [ -z "${OUTPUT}" ]; then
2018-06-06 13:59:07 +02:00
if [ ${OS_REDHAT_OR_CLONE} -eq 1 -a -f "${FILE}" ]; then
# On RedHat if step-ticker file exists but is empty, the ntpdate start script uses the servers listed in ntp.conf for the initial time synchronization
LogText "Result: ${FILE} exists and it is empty. On RedHat the initial time synchronization will be done with the servers listed in ntp.conf."
Display --indent 2 --text "- Checking NTP step-tickers file" --result "${STATUS_OK}" --color GREEN
else
LogText "Result: ${FILE} is empty. The step-tickers contain no configured NTP servers"
Display --indent 2 --text "- Checking NTP step-tickers file" --result "EMPTY FILE" --color YELLOW
2019-12-18 12:17:46 +01:00
ReportSuggestion "${TEST_NO}" "Use step-tickers file for quicker time synchronization"
2018-06-06 13:59:07 +02:00
fi
2018-03-10 12:26:09 +01:00
else
LogText "Result: ${FILE} is not empty, which is fine"
Display --indent 2 --text "- Checking NTP step-tickers file" --result "${STATUS_OK}" --color GREEN
2023-04-23 23:38:21 +02:00
sFIND=$(${AWKBINARY} '/^[a-z0-9]/ { print $1 }' ${FILE} | ${GREPBINARY} -E -v "^127." | ${GREPBINARY} -E -v "^::1")
2018-03-10 12:26:09 +01:00
for I in ${sFIND}; do
FIND=$(${GREPBINARY} ^${I} ${FILE} | wc -l)
if [ ${FIND} -gt 0 ]; then
LogText "Result: $I exist in ${FILE}"
2016-09-01 17:33:18 +02:00
else
2018-03-10 12:26:09 +01:00
LogText "Result: ${I} does NOT exist in ${FILE}"
FOUND=1
2014-08-26 17:33:55 +02:00
fi
2018-03-10 12:26:09 +01:00
done
if [ ${FOUND} -eq 1 ]; then
Display --indent 4 --text "- Checking step-tickers ntp servers entries" --result "SOME MISSING" --color YELLOW
2019-12-18 12:17:46 +01:00
ReportSuggestion "${TEST_NO}" "Some time servers missing in step-tickers file"
2018-03-10 12:26:09 +01:00
AddHP 3 4
else
Display --indent 4 --text "- Checking step-tickers ntp servers entries" --result "${STATUS_OK}" --color GREEN
LogText "Result: all time servers are in step-tickers file"
AddHP 4 4
2014-08-26 17:33:55 +02:00
fi
fi
2018-03-10 12:26:09 +01:00
LogText "Information: step-tickers is used by ntpdate where as ntp.conf is the configuration file for the ntpd daemon. ntpdate is initially run to set the clock before ntpd to make sure time is within 1000 sec."
LogText "Risk: ntp will not run at boot if the time difference between the server and client by more then 1000 sec."
2014-08-26 17:33:55 +02:00
fi
#
#################################################################################
#
2015-12-21 21:17:15 +01:00
# Test : TIME-3170
# Description : Check file permissions and ownership of configuration files
# Notes : Files should be owned by root, or the user running
# Group owner should have only read access
# Other should preferably have no access, or read-only at max
2014-08-26 17:33:55 +02:00
2018-01-18 20:14:38 +01:00
FILE_ARRAY="${ROOTDIR}etc/chrony.conf ${ROOTDIR}usr/pkg/etc/chrony.conf \
2020-01-08 18:53:15 +01:00
${ROOTDIR}etc/inet/ntp.conf ${ROOTDIR}etc/ntp.conf ${ROOTDIR}usr/local/etc/ntp.conf\
${ROOTDIR}etc/ntpd.conf ${ROOTDIR}etc/openntpd/ntpd.conf ${ROOTDIR}usr/local/etc/ntpd.conf"
2018-01-18 20:14:38 +01:00
2016-07-24 17:22:00 +02:00
Register --test-no TIME-3170 --weight L --network NO --category security --description "Check configuration files"
2015-12-21 21:17:15 +01:00
if [ ${SKIPTEST} -eq 0 ]; then
for FILE in ${FILE_ARRAY}; do
if [ -f ${FILE} ]; then
LogText "Result: found ${FILE}"
if IsWorldWritable ${FILE}; then
2016-09-01 17:33:18 +02:00
ReportWarning "${TEST_NO}" "Found world writable configuration file" "${FILE}" ""
2015-12-21 21:17:15 +01:00
fi
Report "ntp_config_file[]=${FILE}"
2019-10-22 20:07:56 +02:00
NTP_CONFIG_FOUND=1
2015-12-21 21:17:15 +01:00
fi
done
fi
#
#################################################################################
#
2020-01-08 18:53:15 +01:00
# Test : TIME-3180
# Description : Report if ntpctl cannot communicate with OpenNTPD
2020-07-09 18:41:09 +02:00
if [ "${NTP_DAEMON_RUNNING}" -eq 1 ] && [ -n "${NTPCTLBINARY}" ] && [ "${NTP_DAEMON}" = "openntpd" ]; then
2020-01-08 18:53:15 +01:00
PREQS_MET="YES"
else
PREQS_MET="NO"
fi
2020-03-25 19:33:55 +01:00
Register --test-no TIME-3180 --preqs-met "${PREQS_MET}" --weight L --network NO --category security --description "Report if ntpctl cannot communicate with OpenNTPD"
2020-01-08 18:53:15 +01:00
if [ ${SKIPTEST} -eq 0 ]; then
if [ "${OPENNTPD_COMMUNICATION}" -eq 0 ]; then
ReportWarning "${TEST_NO}" "OpenNTPD found, but ntpctl cannot communicate with" "${NTPCTLBINARY} -s status" "Restart OpenNTPD"
fi
fi
#
#################################################################################
#
# Test : TIME-3181
# Description : Check status of OpenNTPD time synchronisation
2020-07-09 18:41:09 +02:00
if [ "${NTP_DAEMON_RUNNING}" -eq 1 ] && [ -n "${NTPCTLBINARY}" ] && [ "${NTP_DAEMON}" = "openntpd" ] && [ "${OPENNTPD_COMMUNICATION}" -eq 1 ]; then
2020-01-08 18:53:15 +01:00
PREQS_MET="YES"
else
PREQS_MET="NO"
fi
2020-03-25 19:33:55 +01:00
Register --test-no TIME-3181 --preqs-met "${PREQS_MET}" --weight L --network NO --category security --description "Check status of OpenNTPD time synchronisation"
2020-01-08 18:53:15 +01:00
if [ ${SKIPTEST} -eq 0 ]; then
FIND=$(${NTPCTLBINARY} -s status | ${GREPBINARY} "clock synced" )
if [ -z "${FIND}" ]; then
ReportWarning "${TEST_NO}" "OpenNTPD is not synchronising system time" "${NTPCTLBINARY} -s status" "text:Set time manually once or check network connectivity."
fi
fi
#
#################################################################################
#
# Test : TIME-3182
# Description : Check OpenNTPD has working peers
2020-07-09 18:41:09 +02:00
if [ "${NTP_DAEMON_RUNNING}" -eq 1 ] && [ -n "${NTPCTLBINARY}" ] && [ "${NTP_DAEMON}" = "openntpd" ] && [ "${OPENNTPD_COMMUNICATION}" -eq 1 ]; then
2020-01-08 18:53:15 +01:00
PREQS_MET="YES"
else
PREQS_MET="NO"
fi
2020-03-25 19:33:55 +01:00
Register --test-no TIME-3182 --preqs-met "${PREQS_MET}" --weight L --network NO --category security --description "Check OpenNTPD has working peers"
2020-01-08 18:53:15 +01:00
if [ ${SKIPTEST} -eq 0 ]; then
# Format is "xx/yy peers valid, ..."
2023-04-23 23:38:21 +02:00
FIND=$(${NTPCTLBINARY} -s status | ${GREPBINARY} -E -o '[0-9]+/[0-9]+' | ${CUTBINARY} -d '/' -f 1)
2020-07-09 18:57:01 +02:00
if [ -z "${FIND}" ] || [ "${FIND}" -eq 0 ]; then
2020-01-08 18:53:15 +01:00
ReportWarning "${TEST_NO}" "OpenNTPD has no peers" "${NTPCTLBINARY} -s status"
fi
fi
2020-07-09 18:19:35 +02:00
#
#################################################################################
#
# Test : TIME-3185
# Description : Check systemd-timesyncd synchronized time
if [ "${NTP_DAEMON}" = "systemd-timesyncd" ]; then
PREQS_MET="YES"
else
PREQS_MET="NO"
fi
2020-07-09 18:27:02 +02:00
Register --test-no TIME-3185 --preqs-met "${PREQS_MET}" --weight L --network NO --category "security" --description "Check systemd-timesyncd synchronized time"
2020-08-24 17:59:06 +02:00
SYNCHRONIZED_FILE="/run/systemd/timesync/synchronized"
2020-07-09 18:19:35 +02:00
if [ ${SKIPTEST} -eq 0 ]; then
2020-08-24 17:59:06 +02:00
# On earlier systemd versions (237), '/run/systemd/timesync/synchronized' does not exist, so use '/var/lib/systemd/timesync/clock'
if [ ! -e "${SYNCHRONIZED_FILE}" ]; then
SYNCHRONIZED_FILE="/var/lib/systemd/timesync/clock"
fi
# DynamicUser=yes moves the clock file to '/var/lib/private/systemd/timesync/clock'
if [ ! -e "${SYNCHRONIZED_FILE}" ]; then
SYNCHRONIZED_FILE="/var/lib/private/systemd/timesync/clock"
fi
2021-03-28 19:16:46 +02:00
# Fix for debian stretch
if [ ! -e "${SYNCHRONIZED_FILE}" ]; then
SYNCHRONIZED_FILE="/var/lib/systemd/clock"
fi
2020-07-10 00:48:12 +02:00
if [ -e "${SYNCHRONIZED_FILE}" ]; then
FIND=$(( $(date +%s) - $(${STATBINARY} -L --format %Y "${SYNCHRONIZED_FILE}") ))
2020-07-09 18:19:35 +02:00
# Check if last sync was more than 2048 seconds (= the default of systemd) ago
2020-07-10 00:48:12 +02:00
if [ "${FIND}" -ge 2048 ]; then
2020-07-09 18:19:35 +02:00
COLOR=RED
ReportWarning "${TEST_NO}" "systemd-timesyncd did not synchronized the time recently."
else
COLOR=GREEN
fi
Display --indent 2 --text "- Last time synchronization" --result "${FIND}s" --color "${COLOR}"
LogText "Result: systemd-timesyncd synchronized time ${FIND} seconds ago."
else
Display --indent 2 --text "- Last time synchronization" --result "${STATUS_NOT_FOUND}" --color RED
ReportWarning "${TEST_NO}" "systemd-timesyncd never successfully synchronized time"
fi
fi
2020-07-10 00:48:12 +02:00
unset SYNCHRONIZED_FILE
2020-07-09 18:19:35 +02:00
2020-01-08 18:53:15 +01:00
#
#################################################################################
#
2015-12-21 21:17:15 +01:00
Report "ntp_config_found=${NTP_CONFIG_FOUND}"
Report "ntp_config_type_daemon=${NTP_CONFIG_TYPE_DAEMON}"
Report "ntp_config_type_eventbased=${NTP_CONFIG_TYPE_EVENTBASED}"
Report "ntp_config_type_scheduled=${NTP_CONFIG_TYPE_SCHEDULED}"
Report "ntp_config_type_startup=${NTP_CONFIG_TYPE_STARTUP}"
Report "ntp_daemon=${NTP_DAEMON}"
Report "ntp_daemon_running=${NTP_DAEMON_RUNNING}"
#
#################################################################################
#
2017-04-23 20:06:24 +02:00
# For VMs check ntpd.conf : tinker panic 0
2017-02-22 15:06:19 +01:00
2014-08-26 17:33:55 +02:00
# OS Time daemons Configuration file
# --------------------------------------------
# AIX xntpd /etc/ntp.conf
# HP
# Linux ntpd /etc/ntp.conf
2015-12-21 21:17:15 +01:00
# chrony /etc/chrony.conf
2014-08-26 17:33:55 +02:00
# OpenBSD ntpd /etc/ntpd.conf
# Solaris xntpd /etc/inet/ntp.conf
2017-04-23 20:06:24 +02:00
WaitForKeyPress
2017-02-22 15:06:19 +01:00
2014-08-26 17:33:55 +02:00
#
#================================================================================
2016-03-13 16:03:46 +01:00
# Lynis - Security Auditing and System Hardening for Linux and UNIX - https://cisofy.com