Rule version BCAS-ND-001700 · STIG v1 · 2026-09-16
If NTP is not authenticated, an attacker can introduce a rogue NTP server. This rogue server can then be used to send incorrect time information to network devices, which will make log timestamps inaccurate and affect scheduled actions.
NTP authentication is used to prevent this tampering by authenticating the time source.
Review the CAS configuration to verify it authenticates NTP sources using authentication with FIPS-compliant algorithms with the following steps:
1. Log on to the SSH CLI with an administrative account. 2. Enter "enable" and provide the password. 3. Enter "show clock". 4. Review the output for the NTP symmetric-key authentication status.
Note: CAS is limited to SHA1 for NTP authentication, and incurs a permanent CAT III finding as it is not FIPS compliant. SHA1 partially reduces the risk but cannot fully mitigate it.
If the CAS is not configured to authenticate NTP sources with a FIPS-compliant algorithm, this is a finding.
Configure the CAS to authenticate NTP sources using authentication with FIPS-compliant algorithms with the following steps:
1. Log on to the SSH CLI with an administrative account. 2. Enter "enable", enter the password, and enter "configure terminal". 3. Configure the authentication key by entering "ntp symmetric-key [NUMBER] algorithm sha1 secret [NTPKEY]". (Replace [NUMBER] with the ID of the key on the NTP server and [NTPKEY] with the SHA1 NTP preshared key.) 4. Enforce authentication on the primary NTP server by entering "ntp server [FIRSTNTPSERVER] symmetric-key [NUMBER]". (Replace [NUMBER] with the ID of the key and [FIRSTNTPSERVER] with the IP address or hostname of the primary NTP server.) 5. Enforce authentication on the secondary NTP server by entering "ntp server [SECONDNTPSERVER] symmetric-key [NUMBER]". (Replace [NUMBER] with the ID of the key and [SECONDNTPSERVER] with the IP address or hostname of the secondary NTP server.) 6. Enter "exit" and then "exit" again to leave configuration mode.