<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "http://bugs.gentoo.org/bugzilla.dtd">

<bugzilla version="2.22.7"
          urlbase="http://bugs.gentoo.org/"
          maintainer="bugzilla@gentoo.org"
>

    <bug>
          <bug_id>17492</bug_id>
          
          <creation_ts>2003-03-14 06:02 0000</creation_ts>
          <short_desc>/net-misc/ntp extended ntp.conf to include access restrictions</short_desc>
          <delta_ts>2003-07-23 18:08:13 0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>Gentoo Linux</product>
          <component>Ebuilds</component>
          <version>unspecified</version>
          <rep_platform>All</rep_platform>
          <op_sys>Linux</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          
          
          
          <priority>P2</priority>
          <bug_severity>normal</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          
          <everconfirmed>1</everconfirmed>
          <reporter>gentoo-bugs@seyffer.de</reporter>
          <assigned_to>seemant@gentoo.org</assigned_to>
          

      

      
          <long_desc isprivate="0">
            <who>gentoo-bugs@seyffer.de</who>
            <bug_when>2003-03-14 06:02:19 0000</bug_when>
            <thetext>Hello,

I just emerged ntp and found that the included config template is a bit
&quot;minimalistic&quot; as it does not include any access restrictions or hints to
configure them at all.

So please find attached a suggestion for an updated ntpd.conf template.

Thanks.
Daniel

PS: By the way...trivial but also check the einfo output of the ebuild - or is
this meant to stress &quot;RTFM&quot;? ;-)

--- Quote ---
[...]
 * Please run etc-update and then read all the comments
 * all the comments in /etc/ntp.conf and
[...]
--- /Quote ---


Reproducible: Always
Steps to Reproduce:
1.
2.
3.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>gentoo-bugs@seyffer.de</who>
            <bug_when>2003-03-14 06:04:07 0000</bug_when>
            <thetext>Created an attachment (id=9374)
Suggestion for an updated ntp.conf template.

Diff:
*** /usr/share/ntp/ntp.conf	Fri Mar 14 11:43:12 2003
--- ntp.conf	Fri Mar 14 11:42:30 2003
***************
*** 19,21 ****
--- 19,53 ----
  # you should not need to modify the following paths
  logfile		/var/log/ntpd.log
  driftfile	/var/lib/misc/ntp.drift
+
+
+ # Warning: Using default NTP settings will leave your NTP
+ #	     server accessible to all hosts on the Internet.
+
+ #
+ # If you want to deny all machines from accessing
+ # your NTP server, uncomment:
+ #
+ #restrict default ignore
+
+
+ # To only deny other machines from changing the
+ # configuration but allow localhost uncomment:
+ #
+ #restrict default notrust nomodify
+ #restrict 127.0.0.1
+
+
+ # To allow machines within your network to synchronize
+ # their clocks with your server, but ensure they are
+ # not allowed to configure the server or used as peers
+ # to synchronize against, uncomment this line.
+ #
+ #restrict 192.168.1.0 mask 255.255.255.0 notrust nomodify notrap
+
+
+ # To only deny other machines from changing the
+ # configuration but allow localhost uncomment:
+ #
+ #restrict default notrust nomodify
+ #restrict 127.0.0.1
</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>seemant@gentoo.org</who>
            <bug_when>2003-03-14 06:12:17 0000</bug_when>
            <thetext>thanks daniel, will look into this
</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>gentoo-bugs@seyffer.de</who>
            <bug_when>2003-03-14 06:34:11 0000</bug_when>
            <thetext>Another but rather trivial suggestion that just came to my mind, would be to consider 
adding an example for setting a &quot;prefer&quot; statement to the server part of the 
configuration when using multiple servers, similar to: 
 
  #server ntplocal.example.com prefer 
  #server timeserver.example.org 
 
Thanks. :-) </thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>seemant@gentoo.org</who>
            <bug_when>2003-03-18 02:20:15 0000</bug_when>
            <thetext>changed in portage, thanks Daniel</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>vapier@gentoo.org</who>
            <bug_when>2003-07-23 18:08:13 0000</bug_when>
            <thetext>the extra einfo is a &apos;rtfm&apos; msg simply because people were not doing so and were 
filing bugs/complaining on mailing lists + forums 
 
i added the einfo so as to quiet them ;) </thetext>
          </long_desc>
      
          <attachment
              isobsolete="0"
              ispatch="0"
              isprivate="0"
          >
            <attachid>9374</attachid>
            <date>2003-03-14 06:04 0000</date>
            <desc>Suggestion for an updated ntp.conf template.</desc>
            <filename>ntp.conf</filename>
            <type>text/plain</type>
            <data encoding="base64">IyBOT1RFUzoKIyAgLSB5b3Ugc2hvdWxkIG9ubHkgaGF2ZSB0byB1cGRhdGUgdGhlIHNlcnZlciBs
aW5lIGJlbG93CiMgIC0gaWYgeW91IHN0YXJ0IGdldHRpbmcgbGluZXMgbGlrZSAncmVzdHJpY3Qn
IGFuZCAnZnVkZ2UnCiMgICAgYW5kIHlvdSBkaWRudCBhZGQgdGhlbSwgQU5EIHlvdSBydW4gZGhj
cGNkIG9uIHlvdXIKIyAgICBuZXR3b3JrIGludGVyZmFjZXMsIGJlIHN1cmUgdG8gYWRkICctWSAt
TicgdG8gdGhlCiMgICAgZGhjcGNkX2V0aFggdmFyaWFibGVzIGluIC9ldGMvY29uZi5kL25ldAoK
IyBOYW1lIG9mIHRoZSBzZXJ2ZXJzIG50cGQgc2hvdWxkIHN5bmMgd2l0aAojIFBsZWFzZSByZXNw
ZWN0IHRoZSBhY2Nlc3MgcG9saWN5IGFzIHN0YXRlZCBieSB0aGUgcmVzcG9uc2libGUgcGVyc29u
Lgojc2VydmVyCQludHAuZXhhbXBsZS50bGQJCWlidXJzdAoKIyMKIyBBIGxpc3Qgb2YgYXZhaWxh
YmxlIHNlcnZlcnMgaXMgYXZhaWxhYmxlIGhlcmU6CiMgaHR0cDovL3d3dy5lZWNpcy51ZGVsLmVk
dS9+bWlsbHMvbnRwL3NlcnZlcnMuaHRtbAojIFBsZWFzZSBmb2xsb3cgdGhlIHJ1bGVzIG9mIGVu
Z2FnZW1lbnQgYW5kIHVzZSBhCiMgU3RyYXR1bSAyIHNlcnZlciAodW5sZXNzIHlvdSBxdWFsaWZ5
IGZvciBTdHJhdHVtIDEpCiMjCgojIHlvdSBzaG91bGQgbm90IG5lZWQgdG8gbW9kaWZ5IHRoZSBm
b2xsb3dpbmcgcGF0aHMKbG9nZmlsZQkJL3Zhci9sb2cvbnRwZC5sb2cKZHJpZnRmaWxlCS92YXIv
bGliL21pc2MvbnRwLmRyaWZ0CgoKIyBXYXJuaW5nOiBVc2luZyBkZWZhdWx0IE5UUCBzZXR0aW5n
cyB3aWxsIGxlYXZlIHlvdXIgTlRQIAojICAgICAgICAgIHNlcnZlciBhY2Nlc3NpYmxlIHRvIGFs
bCBob3N0cyBvbiB0aGUgSW50ZXJuZXQuCgojCiMgSWYgeW91IHdhbnQgdG8gZGVueSBhbGwgbWFj
aGluZXMgZnJvbSBhY2Nlc3NpbmcgCiMgeW91ciBOVFAgc2VydmVyLCB1bmNvbW1lbnQ6CiMKI3Jl
c3RyaWN0IGRlZmF1bHQgaWdub3JlCgoKIyBUbyBvbmx5IGRlbnkgb3RoZXIgbWFjaGluZXMgZnJv
bSBjaGFuZ2luZyB0aGUKIyBjb25maWd1cmF0aW9uIGJ1dCBhbGxvdyBsb2NhbGhvc3QgdW5jb21t
ZW50OgojCiNyZXN0cmljdCBkZWZhdWx0IG5vdHJ1c3Qgbm9tb2RpZnkKI3Jlc3RyaWN0IDEyNy4w
LjAuMQoKCiMgVG8gYWxsb3cgbWFjaGluZXMgd2l0aGluIHlvdXIgbmV0d29yayB0byBzeW5jaHJv
bml6ZQojIHRoZWlyIGNsb2NrcyB3aXRoIHlvdXIgc2VydmVyLCBidXQgZW5zdXJlIHRoZXkgYXJl
CiMgbm90IGFsbG93ZWQgdG8gY29uZmlndXJlIHRoZSBzZXJ2ZXIgb3IgdXNlZCBhcyBwZWVycwoj
IHRvIHN5bmNocm9uaXplIGFnYWluc3QsIHVuY29tbWVudCB0aGlzIGxpbmUuCiMKI3Jlc3RyaWN0
IDE5Mi4xNjguMS4wIG1hc2sgMjU1LjI1NS4yNTUuMCBub3RydXN0IG5vbW9kaWZ5IG5vdHJhcAoK
CiMgVG8gb25seSBkZW55IG90aGVyIG1hY2hpbmVzIGZyb20gY2hhbmdpbmcgdGhlCiMgY29uZmln
dXJhdGlvbiBidXQgYWxsb3cgbG9jYWxob3N0IHVuY29tbWVudDoKIwojcmVzdHJpY3QgZGVmYXVs
dCBub3RydXN0IG5vbW9kaWZ5CiNyZXN0cmljdCAxMjcuMC4wLjEK
</data>        

          </attachment>
    </bug>

</bugzilla>