Network Time Protocol Version 4: Autokey Specification
RFC 5906, “Network Time Protocol Version 4: Autokey Specification”, is an Informational document published in June 2010 by B. Haberman, D. Mills. It has since been updated by RFC 9748. The canonical text is published by the RFC Editor.
Abstract
This memo describes the Autokey security model for authenticating servers to clients using the Network Time Protocol (NTP) and public key cryptography. Its design is based on the premise that IPsec schemes cannot be adopted intact, since that would preclude stateless servers and severely compromise timekeeping accuracy. In addition, Public Key Infrastructure (PKI) schemes presume authenticated time values are always available to enforce certificate lifetimes; however, cryptographically verified timestamps require interaction between the timekeeping and authentication functions.
This memo includes the Autokey requirements analysis, design principles, and protocol specification. A detailed description of the protocol states, events, and transition functions is included. A prototype of the Autokey design based on this memo has been implemented, tested, and documented in the NTP version 4 (NTPv4) software distribution for the Unix, Windows, and Virtual Memory System (VMS) operating systems at http://www.ntp.org. This document is not an Internet Standards Track specification; it is published for informational purposes.
What “Informational” means
Published for the general information of the community. It does not define an IETF standard and carries no standards-track status.
The canonical text of RFC 5906 is hosted at rfc-editor.org. Available in TXT,HTML.
- RFC 5905 Network Time Protocol Version 4: Protocol and Algorithms Specification
- RFC 5907 Definitions of Managed Objects for Network Time Protocol Version 4
- RFC 5904 RADIUS Attributes for IEEE 802.16 Privacy Key Management Version 1 Protocol Support
- RFC 5908 Network Time Protocol Server Option for DHCPv6
- RFC 5903 Elliptic Curve Groups modulo a Prime for IKE and IKEv2
- RFC 5909 Securing Neighbor Discovery Proxy: Problem Statement
- RFC 5902 IAB Thoughts on IPv6 Network Address Translation
- RFC 5910 Domain Name System Security Extensions Mapping for the Extensible Provisioning Protocol