Rule version AWTM-NM-000036 · STIG v1 · 2026-09-14
If NTP is not authenticated, an attacker can introduce a rogue NTP server. This rogue server can then be used to send incorrect time information to network devices, which will make log timestamps inaccurate and affect scheduled actions. NTP authentication is used to prevent this tampering by authenticating the time source.
Satisfies: SRG-APP-000395-NDM-000347, SRG-APP-000925-NDM-000330
1. Log in to the WTM Web UI. 2. Navigate to System Configuration >> Date and Time. 3. Verify the clock source is configured as NTP. 4. Verify there are at least two NTP servers configured. 5. Verify SHA1 authentication keys are used.
If compliant NTP sources using authentication that is cryptographically based are not configured, this is a finding.
1. Log in to the WTM Web UI. 2. Navigate to System Configuration >> Date and Time. 3. Under clock source, select "NTP". 4. Under poll interval enter "300". 5. Under "Configure Symmetric Key," click "Add". 6. Enter the ID number of the key from the NTP server under "key ID". 7. Under "algorithm" select "sha1". 8. Under "type", select "ASCII". 9. Under "key", enter the plain text or hexadecimal key. 10. Under "Configure NTP Server," enter a name. 11. Then enter the IPv4 address, or hostname, of the NTP server. 12. Select "Server" for Assoc-Type. 13. Select the previous configured key ID for symmetric key. 14. Click the preferred checkbox for the priority server to use; uncheck it for the secondary server. 15. Click the checkbox for "iburst". 16. Click "Commit". 17. Click "Update Now" and monitor for proper time sync.