SV-31548r2_rule
V-8322
Time Synchronization
DS00.0150_2008
CAT II
10
Ensure the Windows Time Service is configured as follows or install and enable another time synchronization tool.
Registry Hive: HKEY_LOCAL_MACHINE
Registry Path: \System\CurrentControlSet\Services\W32Time\TimeProviders\NtpClient\
Value Name: Enabled
Type: REG_DWORD
Value: 1
Registry Path: \System\CurrentControlSet\Services\W32Time\ Parameters\
Value Name: Type
Type: REG_SZ
Value: NT5DS (preferred), NTP, or Allsync
Determine if a time synchronization tool has been implemented on the Windows domain controller.
If the Windows Time Service is used, verify the following registry values. If they are not configured as specified, this is a finding.
Registry Hive: HKEY_LOCAL_MACHINE
Registry Path: \System\CurrentControlSet\Services\W32Time\TimeProviders\NtpClient\
Value Name: Enabled
Type: REG_DWORD
Value: 1
Registry Path: \System\CurrentControlSet\Services\W32Time\Parameters\
Value Name: Type
Type: REG_SZ
Value: NT5DS (preferred), NTP, or Allsync
If these Windows checks indicate a finding because the NtpClient is not enabled, determine if an alternate time synchronization tool is installed and enabled.
If the Windows Time Service is not enabled and no alternate tool is enabled, this is a finding.
V-8322
False
DS00.0150_2008
Determine if a time synchronization tool has been implemented on the Windows domain controller.
If the Windows Time Service is used, verify the following registry values. If they are not configured as specified, this is a finding.
Registry Hive: HKEY_LOCAL_MACHINE
Registry Path: \System\CurrentControlSet\Services\W32Time\TimeProviders\NtpClient\
Value Name: Enabled
Type: REG_DWORD
Value: 1
Registry Path: \System\CurrentControlSet\Services\W32Time\Parameters\
Value Name: Type
Type: REG_SZ
Value: NT5DS (preferred), NTP, or Allsync
If these Windows checks indicate a finding because the NtpClient is not enabled, determine if an alternate time synchronization tool is installed and enabled.
If the Windows Time Service is not enabled and no alternate tool is enabled, this is a finding.
M
System Administrator
1340