STIGUI
V-286491CAT II — Medium severitySV-286491r1274035_rule

WTM must authenticate Network Time Protocol (NTP) sources using authentication that is cryptographically based.

Rule version AWTM-NM-000036 · STIG v1 · 2026-09-14

Discussion

If NTP is not authenticated, an attacker can introduce a rogue NTP server. This rogue server can then be used to send incorrect time information to network devices, which will make log timestamps inaccurate and affect scheduled actions. NTP authentication is used to prevent this tampering by authenticating the time source.

Satisfies: SRG-APP-000395-NDM-000347, SRG-APP-000925-NDM-000330

Check

1. Log in to the WTM Web UI. 2. Navigate to System Configuration >> Date and Time. 3. Verify the clock source is configured as NTP. 4. Verify there are at least two NTP servers configured. 5. Verify SHA1 authentication keys are used.

If compliant NTP sources using authentication that is cryptographically based are not configured, this is a finding.

Fix

1. Log in to the WTM Web UI. 2. Navigate to System Configuration >> Date and Time. 3. Under clock source, select "NTP". 4. Under poll interval enter "300". 5. Under "Configure Symmetric Key," click "Add". 6. Enter the ID number of the key from the NTP server under "key ID". 7. Under "algorithm" select "sha1". 8. Under "type", select "ASCII". 9. Under "key", enter the plain text or hexadecimal key. 10. Under "Configure NTP Server," enter a name. 11. Then enter the IPv4 address, or hostname, of the NTP server. 12. Select "Server" for Assoc-Type. 13. Select the previous configured key ID for symmetric key. 14. Click the preferred checkbox for the priority server to use; uncheck it for the secondary server. 15. Click the checkbox for "iburst". 16. Click "Commit". 17. Click "Update Now" and monitor for proper time sync.

Identifiers

Group ID
V-286491
Group title
SRG-APP-000395-NDM-000347
Rule ID
SV-286491r1274035_rule
Check ID
C-91173r1273752_chk
Fix ID
F-91078r1274034_fix