STIGQter STIGQter: STIG Summary: Oracle Linux 9 Security Technical Implementation Guide Version: 1 Release: 6 Benchmark Date: 01 Jul 2026:

OL 9 must securely compare internal information system clocks at least every 24 hours.

DISA Rule

SV-271699r1091809_rule

Vulnerability Number

V-271699

Group Title

SRG-OS-000355-GPOS-00143

Rule Version

OL09-00-002323

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure OL 9 to securely compare internal information system clocks at least every 24 hours with an NTP server by adding/modifying the following line in the /etc/chrony.conf file.

server [ntp.server.name] iburst maxpoll 16

Check Contents

Verify that OL 9 securely compares internal information system clocks at least every 24 hours with an NTP server with the following command:

$ grep maxpoll /etc/chrony.conf
server 0.us.pool.ntp.mil iburst maxpoll 16

If the "maxpoll" option is set to a number greater than 16 or the line is commented out, this is a finding.

Verify the "chrony.conf" file is configured to an authoritative DOD time source by running the following command:

$ grep -i server /etc/chrony.conf
server 0.us.pool.ntp.mil

If the parameter "server" is not set or is not set to an authoritative DOD time source, this is a finding.

Vulnerability Number

V-271699

Documentable

False

Rule Version

OL09-00-002323

Severity Override Guidance

Verify that OL 9 securely compares internal information system clocks at least every 24 hours with an NTP server with the following command:

$ grep maxpoll /etc/chrony.conf
server 0.us.pool.ntp.mil iburst maxpoll 16

If the "maxpoll" option is set to a number greater than 16 or the line is commented out, this is a finding.

Verify the "chrony.conf" file is configured to an authoritative DOD time source by running the following command:

$ grep -i server /etc/chrony.conf
server 0.us.pool.ntp.mil

If the parameter "server" is not set or is not set to an authoritative DOD time source, this is a finding.

Check Content Reference

M

Target Key

5680