Skip to content

Replace small NTS servers with authoritative providers#52

Merged
kvinwang merged 2 commits intomainfrom
fix/nts-servers
Mar 20, 2026
Merged

Replace small NTS servers with authoritative providers#52
kvinwang merged 2 commits intomainfrom
fix/nts-servers

Conversation

@kvinwang
Copy link
Copy Markdown
Collaborator

Summary

  • Remove community-run NTS servers (ntp1/ntp2.glypnod.com, nts.teambelgium.net, a.st1.ntp.br, time.bolha.one) that complained about excessive NTS-KE traffic from our fleet
  • Replace with authoritative Stratum 1 NTS servers from major institutions:
    • PTB (German national metrology institute): ptbtime2.ptb.de, ptbtime3.ptb.de
    • Netnod (Swedish internet infrastructure): nts.netnod.se, nts.ntp.se
    • SIDN Labs (Dutch .nl registry): ntppool1.time.nl
  • Keep existing time.cloudflare.com, ptbtime1.ptb.de, virginia.time.system76.com

All new servers have been tested and verified working with NTS-KE from our network.

Test plan

  • Verified all new NTS servers respond correctly with TLS 1.3 NTS-KE handshake
  • Confirmed Stratum 1 sync from all PTB, Netnod, and SIDN servers
  • Deploy to a test VM and confirm chronyc authdata shows NTS authentication for all sources

Remove ntp1/ntp2.glypnod.com, nts.teambelgium.net, a.st1.ntp.br,
and time.bolha.one. Replace with PTB (German national metrology
institute), Netnod (Swedish internet infrastructure), and SIDN Labs
(Dutch .nl registry) NTS servers.

This addresses abuse complaints about excessive NTS-KE traffic from
our fleet to small community-run NTS servers.
@kvinwang kvinwang merged commit 430659d into main Mar 20, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant