Network Time Protocol Version 4: Port Randomization
RFC 9109, “Network Time Protocol Version 4: Port Randomization”, is a Proposed Standard document published in August 2021 by F. Gont, G. Gont, M. Lichvar. It updates RFC 5905. The canonical text is published by the RFC Editor.
Abstract
The Network Time Protocol (NTP) can operate in several modes. Some of these modes are based on the receipt of unsolicited packets and therefore require the use of a well-known port as the local port. However, in the case of NTP modes where the use of a well-known port is not required, employing such a well-known port unnecessarily facilitates the ability of attackers to perform blind/off-path attacks. This document formally updates RFC 5905, recommending the use of transport-protocol ephemeral port randomization for those modes where use of the NTP well-known port is not required.
What “Proposed Standard” means
An entry-level standards-track specification: stable, peer-reviewed and a solid basis for implementation, though it may still evolve before becoming an Internet Standard.
The canonical text of RFC 9109 is hosted at rfc-editor.org. Available in HTML,TXT,PDF,XML.
- RFC 9108 YANG Types for DNS Classes and Resource Record Types
- RFC 9107 BGP Optimal Route Reflection
- RFC 9106 Argon2 Memory-Hard Function for Password Hashing and Proof-of-Work Applications
- RFC 9105 A YANG Data Model for Terminal Access Controller Access-Control System Plus
- RFC 9104 Distribution of Traffic Engineering Extended Administrative Groups Using the Border Gateway Protocol - Link State
- RFC 9103 DNS Zone Transfer over TLS
- RFC 9115 An Automatic Certificate Management Environment Profile for Generating Delegated Certificates
- RFC 9102 TLS DNSSEC Chain Extension