The chronyd service must be enabled.
DISA Rule
SV-269533r1050416_rule
Vulnerability Number
V-269533
Group Title
SRG-OS-000355-GPOS-00143
Rule Version
ALMA-09-055130
Severity
CAT II
CCI(s)
- CCI-004923 - Compare the internal system clocks on an organization-defined frequency with organization-defined authoritative time source.
- CCI-001890 - Record time stamps for audit records that use Coordinated Universal Time, have a fixed local time offset from Coordinated Universal Time, or that include the local time offset as part of the time stamp.
Weight
10
Fix Recommendation
To enable the chronyd service run the following command:
$ systemctl enable --now chronyd
Check Contents
Verify the chronyd service is active with the following command:
$ systemctl is-active chronyd
active
If the chronyd service is not active, this is a finding.
Vulnerability Number
V-269533
Documentable
False
Rule Version
ALMA-09-055130
Severity Override Guidance
Verify the chronyd service is active with the following command:
$ systemctl is-active chronyd
active
If the chronyd service is not active, this is a finding.
Check Content Reference
M
Target Key
5664