22.12. NTP

´ó¹Æ: Tom Hukins.

22.12.1. ³µÀâ

»þ´Ö¤Î·Ð²á¤È¤È¤â¤Ë¡¢¥³¥ó¥Ô¥å¡¼¥¿¤Î»þ·×¤Ï¤º¤ì¤Æ¤·¤Þ¤¤¤¬¤Á¤Ç¤¹¡£ »þ´Ö¤¬·Ð¤Ä¤È¡¢¥³¥ó¥Ô¥å¡¼¥¿¤Î»þ·×¤ÏÀµ³Î¤Ç¤Ê¤¯¤Ê¤Ã¤Æ¤æ¤­¤Þ¤¹¡£ NTP (Network Time Protocol) ¤Ï»þ·×¤¬Àµ³Î¤Ç¤¢¤ë¤³¤È¤òÊݾڤ¹¤ëÊýË¡¤Î°ì¤Ä¤Ç¤¹¡£

¥¤¥ó¥¿¡¼¥Í¥Ã¥È¥µ¡¼¥Ó¥¹¤Î¿¤¯¤Ï¡¢ ¥³¥ó¥Ô¥å¡¼¥¿¤Î»þ·×¤¬Àµ³Î¤Ç¤¢¤ë¤³¤È¤Ë°Í¸¤·¤Æ¤¤¤ë¤«¡¢ ¤¢¤ë¤¤¤Ï¿¤¯¤òÉé¤Ã¤Æ¤¤¤Þ¤¹¡£ ¤¿¤È¤¨¤Ð web ¥µ¡¼¥Ð ¤Ï¡¢ ¤¢¤ë¥Õ¥¡¥¤¥ë¤¬¤¢¤ë»þ¹ï°Ê¹ß¤Ë½¤Àµ¤µ¤ì¤Æ¤¤¤¿¤é¤½¤Î¥Õ¥¡¥¤¥ë¤òÁ÷¤Ã¤Æ¤Û¤·¤¤¤È¤¤¤¦Í×µá¤ò¼õ¤±¼è¤ë¤«¤â¤·¤ì¤Þ¤»¤ó¡£ cron(8) ¤Î¤è¤¦¤Ê¥µ¡¼¥Ó¥¹¤Ï½êÄê¤Î»þ´Ö¤Ë¥³¥Þ¥ó¥É¤ò¼Â¹Ô¤·¤Þ¤¹¡£ »þ·×¤¬Àµ³Î¤Ç¤Ê¤¤¾ì¹ç¡¢ ¤³¤ì¤é¤Î¥³¥Þ¥ó¥É¤Ï´üÂÔ¤·¤¿¤È¤ª¤ê¤Ë¤Ï¼Â¹Ô¤µ¤ì¤Ê¤¤¤«¤â¤·¤ì¤Þ¤»¤ó¡£

FreeBSD ¤Ï ntpd(8) NTP ¥µ¡¼¥Ð¤òÅëºÜ¤·¤Æ¤¤¤Þ¤¹¡£¤³¤ì¤Ï¡¢ ¥Þ¥·¥ó¤Î»þ·×¤ò¹ç¤ï¤»¤ë¤¿¤á¤Ë¾¤Î NTP ¥µ¡¼¥Ð¤ËÌ䤤¹ç¤ï¤»¤ò¤·¤¿¤ê¡¢ ¾¤Î¥Þ¥·¥ó¤ËÂФ·¤Æ»þ¹ï¤òÊ󤸤뤿¤á¤Ë»ÈÍѤǤ­¤Þ¤¹¡£

22.12.2. ŬÀÚ¤Ê NTP ¥µ¡¼¥Ð¤ÎÁªÂò

»þ¹ï¤òƱ´ü¤¹¤ë¤¿¤á¤ËÍøÍѤ¹¤ë NTP ¥µ¡¼¥Ð¤ò¡¢ °ì¤Ä°Ê¾å¸«¤Ä¤±¤ëɬÍפ¬¤¢¤ê¤Þ¤¹¡£ ¥Í¥Ã¥È¥ï¡¼¥¯´ÉÍý¼Ô¡¢¤Þ¤¿¤Ï ISP ¤Ï¤³¤ÎÌÜŪ¤Î¤¿¤á¤Ë NTP ¥µ¡¼¥Ð¤òÀßÄꤷ¤Æ¤¤¤ë¤«¤â¤·¤ì¤Þ¤»¤ó — ËÜÅö¤Ë¤½¤¦¤Ê¤Î¤«³Î¤«¤á¤ë¤¿¤á¤Ë¥É¥­¥å¥á¥ó¥È¤ò³Îǧ¤·¤Æ¤¯¤À¤µ¤¤¡£ ¤¢¤Ê¤¿¤Î¶á¤¯¤Î NTP ¥µ¡¼¥Ð¤òõ¤»¤ë ¸ø¤Ë¥¢¥¯¥»¥¹²Äǽ¤Ê NTP ¥µ¡¼¥Ð¤Î¥ê¥¹¥È ¤¬¤¢¤ê¤Þ¤¹¡£ ¤É¤Î¥µ¡¼¥Ð¤òÁªÂò¤¹¤ë¤È¤·¤Æ¤â¡¢¤½¤Î¥µ¡¼¥Ð¤Î±¿±Ä¥Ý¥ê¥·¤òÍý²ò¤·¡¢ Í׵ᤵ¤ì¤Æ¤¤¤ë¤Ê¤éÍøÍѵö²Ä¤òµá¤á¤ë¤³¤È¤ò˺¤ì¤Ê¤¤¤Ç¤¯¤À¤µ¤¤¡£

»ÈÍѤ·¤Æ¤¤¤ë¥µ¡¼¥Ð¤Î¤¦¤Á¤Î¤É¤ì¤«¤¬ÅþãÉÔǽ¤Ë¤Ê¤ë¤«¡¢ ¤½¤Î»þ·×¤Î¿®ÍêÀ­¤¬Ä㤤¾ì¹ç¡¢Ìµ´Ø·¸¤Î NTP ¥µ¡¼¥Ð¤ò¤¤¤¯¤Ä¤«ÁªÂò¤¹¤ë¤È¤è¤¤¤Ç¤·¤ç¤¦¡£ ntpd(8) ¤Ï¾¤Î¥µ¡¼¥Ð¤«¤é¼õ¤±¼è¤Ã¤¿±þÅú¤ò¸­¤¯ÍøÍѤ·¤Þ¤¹ — ¿®Íê¤Ç¤­¤Ê¤¤¥µ¡¼¥Ð¤è¤ê¿®Íê¤Ç¤­¤ë¥µ¡¼¥Ð¤ò½Å»ë¤·¤Þ¤¹¡£

22.12.3. ¥Þ¥·¥ó¤ÎÀßÄê

22.12.3.1. ´ðËÜÀßÄê

¥Þ¥·¥ó¤¬µ¯Æ°¤¹¤ë¤È¤­¤À¤±»þ·×¤òƱ´ü¤µ¤»¤¿¤¤¾ì¹ç¤Ï ntpdate(8) ¤¬»È¤¨¤Þ¤¹¡£ÉÑÈˤ˺Ƶ¯Æ°¤µ¤ì¡¢ ¤¿¤Þ¤ËƱ´ü¤¹¤ì¤Ð½½Ê¬¤Ê¥Ç¥¹¥¯¥È¥Ã¥×¥Þ¥·¥ó¤Ë¤ÏŬÀÚ¤«¤â¤·¤ì¤Þ¤»¤ó¡£ ¤·¤«¤·¤Û¤È¤ó¤É¤Î¥Þ¥·¥ó¤Ç¤Ï ntpd(8) ¤ò¼Â¹Ô¤¹¤ë¤Ù¤­¤Ç¤¹¡£

ntpd(8) ¤òÆ°¤«¤·¤Æ¤¤¤ë¥Þ¥·¥ó¤Ç¤â¡¢µ¯Æ°»þ¤Ë ntpdate(8) ¤ò»ÈÍѤ¹¤ë¤Î¤Ï¤è¤¤¹Í¤¨¤Ç¤¹¡£ ntpd(8) ¥×¥í¥°¥é¥à¤Ï»þ·×¤ò½ù¡¹¤ËÊѹ¹¤·¤Þ¤¹¡£¤·¤«¤· ntpdate(8) ¤ÏÀµ¤·¤¤»þ¹ï¤È¸½ºßÀßÄꤵ¤ì¤Æ¤¤¤ë¥Þ¥·¥ó¤Î»þ¹ï¤¬¤É¤ó¤Ê¤ËÎ¥¤ì¤Æ¤¤¤è¤¦¤È¤â»þ·×¤òÀßÄꤷ¤Þ¤¹¡£

µ¯Æ°»þ¤Ë ntpdate(8) ¤òÍ­¸ú¤Ë¤¹¤ë¤¿¤á¤Ë¤Ï¡¢ ntpdate_enable="YES" ¤ò /etc/rc.conf ¤ËÄɲ䷤Ƥ¯¤À¤µ¤¤¡£ ¤µ¤é¤Ë¡¢Æ±´ü¤·¤¿¤¤¤¹¤Ù¤Æ¤Î¥µ¡¼¥Ð¤ª¤è¤Ó¡¢ntpdate(8) ¤ËÅϤ¹¤¢¤é¤æ¤ë¥Õ¥é¥°¤ò ntpdate_flags ¤Ë»ØÄꤹ¤ëɬÍפ¬¤¢¤ë¤Ç¤·¤ç¤¦¡£

22.12.3.2. °ìÈÌÀßÄê

NTP ¤Ï ntp.conf(5) ¤Ëµ­½Ò¤µ¤ì¤¿½ñ¼°¤Î /etc/ntp.conf ¥Õ¥¡¥¤¥ë¤Ë¤è¤Ã¤ÆÀßÄꤵ¤ì¤Þ¤¹¡£ ´Êñ¤ÊÎã¤ò°Ê²¼¤Ë¼¨¤·¤Þ¤¹¡£

server ntplocal.example.com prefer
server timeserver.example.org
server ntp2a.example.net

driftfile /var/db/ntp.drift

server ¥ª¥×¥·¥ç¥ó¤Ï¡¢ »ÈÍѤ¹¤ë¥µ¡¼¥Ð¤ò°ì¹Ô¤Ë°ì¤Ä¤º¤Ä»ØÄꤷ¤Þ¤¹¡£¥µ¡¼¥Ð¤¬¾åµ­¤Î ntplocal.example.com ¤Î¤è¤¦¤Ë prefer °ú¿ô¤È¤È¤â¤Ë»ØÄꤵ¤ì¤¿¾ì¹ç¡¢ ¤³¤Î¥µ¡¼¥Ð¤Ï¾¤Î¥µ¡¼¥Ð¤è¤êÍ¥À褵¤ì¤Þ¤¹¡£ Í¥À褵¤ì¤¿¥µ¡¼¥Ð¤«¤é¤Î±þÅú¤Ï¡¢ ¾¤Î¥µ¡¼¥Ð¤Î±þÅú¤ÈÃø¤·¤¯°Û¤Ê¤ë¾ì¹ç¤ÏÇË´þ¤µ¤ì¤Þ¤¹¤¬¡¢ ¤½¤¦¤Ç¤Ê¤±¤ì¤Ð¾¤Î±þÅú¤ò¹Íθ¤¹¤ë¤³¤È¤Ê¤¯»ÈÍѤµ¤ì¤Þ¤¹¡£ prefer °ú¿ô¤Ï¡¢Ä̾ ÆÃÊ̤ʻþ´Ö¥â¥Ë¥¿¥Ï¡¼¥É¥¦¥§¥¢¤òÈ÷¤¨¤Æ¤¤¤ë¤è¤¦¤ÊÈó¾ï¤ËÀµ³Î¤Ç¤¢¤ë¤È¤µ¤ì¤Æ¤¤¤ë NTP ¥µ¡¼¥Ð¤ËÂФ·¤Æ»ÈÍѤµ¤ì¤Þ¤¹¡£

driftfile ¥ª¥×¥·¥ç¥ó¤Ï¥·¥¹¥Æ¥à»þ·×¤Î¼þÇÈ¿ô¥ª¥Õ¥»¥Ã¥È¤ò³ÊǼ¤¹¤ë¤¿¤á¤Ë»ÈÍѤ¹¤ë¥Õ¥¡¥¤¥ë¤ò»ØÄꤷ¤Þ¤¹¡£ ntpd(8) ¥×¥í¥°¥é¥à¤Ï¡¢ »þ·×¤Î¼«Á³ÊÑÆ°¤ò¼«Æ°Åª¤ËÊäÀµ¤¹¤ë¤¿¤á¤Ë¤³¤ì¤òÍѤ¤¤Þ¤¹¡£ ¤³¤ì¤Ë¤è¤ê¡¢°ìÄê»þ´Ö³°Éô¤Î»þ¹ï¥½¡¼¥¹¤«¤éÀÚ¤êÎ¥¤µ¤ì¤¿¤È¤·¤Æ¤â¡¢ ½½Ê¬Àµ³Î¤Ê»þ¹ï¤ò°Ý»ý¤¹¤ë¤³¤È¤ò²Äǽ¤Ë¤·¤Þ¤¹¡£

driftfile ¥ª¥×¥·¥ç¥ó¤Ï¡¢»ÈÍѤ·¤Æ¤¤¤ë NTP ¥µ¡¼¥Ð¤«¤é²áµî¤Ë¼õ¤±¼è¤Ã¤¿±þÅú¤Ë´Ø¤¹¤ë¾ðÊó¤ò³ÊǼ¤¹¤ë¤¿¤á¤Ë¡¢ ¤É¤Î¥Õ¥¡¥¤¥ë¤¬»ÈÍѤµ¤ì¤ë¤«»ØÄꤷ¤Þ¤¹¡£ ¤³¤Î¥Õ¥¡¥¤¥ë¤Ï NTP ¤Ë´Ø¤¹¤ëÆâÉô¾ðÊó¤ò´Þ¤ó¤Ç¤¤¤Þ¤¹¡£ ¤³¤ì¤Ï¾¤Î¥×¥í¥»¥¹¤Ë¤è¤Ã¤Æ½¤Àµ¤µ¤ì¤Æ¤Ï¤¤¤±¤Þ¤»¤ó¡£

22.12.3.3. ¥µ¡¼¥Ð¤Ø¤Î¥¢¥¯¥»¥¹À©¸æ

¥Ç¥Õ¥©¥ë¥È¤Ç¤Ï NTP ¥µ¡¼¥Ð¤Ï¥¤¥ó¥¿¡¼¥Í¥Ã¥È¾å¤Î¤¹¤Ù¤Æ¤Î¥Û¥¹¥È¤«¤é¥¢¥¯¥»¥¹¤¬²Äǽ¤Ç¤¹¡£ /etc/ntp.conf Æâ¤Ç restrict ¥ª¥×¥·¥ç¥ó¤ò»ØÄꤹ¤ë¤³¤È¤Ë¤è¤Ã¤Æ¡¢ ¤É¤Î¥Þ¥·¥ó¤¬¥µ¡¼¥Ð¤Ë¥¢¥¯¥»¥¹¤Ç¤­¤ë¤«¤òÀ©¸æ¤Ç¤­¤ë¤è¤¦¤Ë¤·¤Þ¤¹¡£

NTP ¥µ¡¼¥Ð¤Ë¥¢¥¯¥»¥¹¤¹¤ë¥Þ¥·¥ó¤Î¤¹¤Ù¤Æ¤òµñÈݤ·¤¿¤¤¤Î¤Ê¤é¡¢ °Ê²¼¤Î¹Ô¤ò /etc/ntp.conf ¤ËÄɲ䷤Ƥ¯¤À¤µ¤¤¡£

restrict default ignore

¤¢¤Ê¤¿¤Î¥Í¥Ã¥È¥ï¡¼¥¯Æâ¤Î¥Þ¥·¥ó¤Ë¤À¤±¥µ¡¼¥Ð¤ËÀܳ¤·¤Æ»þ·×¤òƱ´ü¤¹¤ë¤³¤È¤òǧ¤á¤¿¤¤¤¬¡¢ ¤½¤ì¤é¤«¤é¥µ¡¼¥Ð¤ËÂФ·¤ÆÀßÄê¤ò¹Ô¤¦¤Î¤òµö¤µ¤º¡¢ Ʊ´ü¤¹¤ëüËö¤È¤·¤Æ¤âÍøÍѤµ¤ì¤Ê¤¤¤è¤¦¤Ë¤·¤¿¤¤¤Î¤Ê¤é¡¢ °Ê²¼¤ò²Ã¤¨¤Æ¤¯¤À¤µ¤¤¡£

restrict 192.168.1.0 mask 255.255.255.0 notrust nomodify notrap

192.168.1.0 ¤ò¤¢¤Ê¤¿¤Î¥Í¥Ã¥È¥ï¡¼¥¯¤Î IP ¥¢¥É¥ì¥¹¤Ë 255.255.255.0 ¤ò¤¢¤Ê¤¿¤Î¥Í¥Ã¥È¥ï¡¼¥¯¤Î¥Í¥Ã¥È¥Þ¥¹¥¯¤ËÃÖ¤­´¹¤¨¤Æ¤¯¤À¤µ¤¤¡£

/etc/ntp.conf ¤Ë¤ÏÊ£¿ô¤Î restrict ¥ª¥×¥·¥ç¥ó¤òÃÖ¤±¤Þ¤¹¡£ ¾ÜºÙ¤ËÉÕ¤¤¤Æ¤Ï ntp.conf(5) ¤Î Access Control Support ¥µ¥Ö¥»¥¯¥·¥ç¥ó¤ò»²¾È¤·¤Æ¤¯¤À¤µ¤¤¡£

22.12.4. NTP ¥µ¡¼¥Ð¤Î¼Â¹Ô

NTP ¥µ¡¼¥Ð¤¬µ¯Æ°»þ¤Ë¼Â¹Ô¤µ¤ì¤ë¤³¤È¤òÊݾڤ¹¤ë¤¿¤á¤Ë¡¢ xntpd_enable="YES" ¤ò /etc/rc.conf ¤Ë²Ã¤¨¤Æ¤¯¤À¤µ¤¤¡£ ntpd(8) ¤Ë¥Õ¥é¥°¤òÄɲä·¤¿¤¤¾ì¹ç¤Ï /etc/rc.conf Æâ¤Î xntpd_flags ¥Ñ¥é¥á¡¼¥¿¤òÊÔ½¸¤·¤Æ¤¯¤À¤µ¤¤¡£

¥Þ¥·¥ó¤òºÆµ¯Æ°¤¹¤ë¤³¤È¤Ê¤¯¥µ¡¼¥Ð¤ò¼Â¹Ô¤·¤¿¤¤¤È¤­¤Ï¡¢ /etc/rc.conf Æâ¤Î xntpd_flags ¤ÇÄɲ䵤줿¥Ñ¥é¥á¡¼¥¿¤ò¤¹¤Ù¤Æ»ØÄꤷ¤Æ ntpd ¤ò¼Â¹Ô¤·¤Æ¤¯¤À¤µ¤¤¡£°Ê²¼¤ËÎã¤ò¼¨¤·¤Þ¤¹¡£

# ntpd -p /var/run/ntpd.pid

注意: FreeBSD 5.X ¤Ç¤Ï /etc/rc.conf Æâ¤Î¤µ¤Þ¤¶¤Þ¤Ê¥ª¥×¥·¥ç¥ó¤Î̾Á°¤¬ÊѤï¤ê¤Þ¤·¤¿¡£ ¤·¤¿¤¬¤Ã¤Æ¡¢¾åµ­¤Î xntpd ¤Ë´Ø¤¹¤ë¥ª¥×¥·¥ç¥ó¤Ï ntpd ¤ËÃÖ¤­´¹¤¨¤Æ¤¯¤À¤µ¤¤¡£

22.12.5. °ì»þŪ¤Ê¥¤¥ó¥¿¡¼¥Í¥Ã¥ÈÀܳ¤Ç ntpd ¤ò»ÈÍѤ¹¤ë

ntpd(8) ¥×¥í¥°¥é¥à¤ÏÀµ¤·¤¯µ¡Ç½¤¹¤ë¤¿¤á¤Ë¡¢ ¥¤¥ó¥¿¡¼¥Í¥Ã¥È¤Ø¤Î¾ï»þÀܳ¤òɬÍפȤ·¤Þ¤»¤ó¡£¤·¤«¤·¤Ê¤¬¤é¡¢ ¥ª¥ó¥Ç¥Þ¥ó¥É¤Ç¥À¥¤¥¢¥ë¥¢¥Ã¥×¤µ¤ì¤ë¤è¤¦¤ËÀßÄꤵ¤ì¤¿°ì»þŪ¤ÊÀܳ¤Î¾ì¹ç¡¢ NTP ¥È¥é¥Õ¥£¥Ã¥¯¤¬¥À¥¤¥¢¥ë¤ò°ú¤­µ¯¤³¤·¤¿¤ê¡¢ Àܳ¤ò°Ý»ý¤·Â³¤±¤ë¤è¤¦¤Ê¤³¤È¤òÈò¤±¤ë¤è¤¦¤Ë¤·¤¿Êý¤¬¤è¤¤¤Ç¤·¤ç¤¦¡£ ¥æ¡¼¥¶ PPP ¤ò»ÈÍѤ·¤Æ¤¤¤ë¾ì¹ç¡¢°Ê²¼¤ÎÎã¤Î¤è¤¦¤Ë /etc/ppp/ppp.conf Æâ¤Ç filter ¥Ç¥£¥ì¥¯¥Æ¥£¥Ö¤¬»ÈÍѤǤ­¤Þ¤¹¡£

 set filter dial 0 deny udp src eq 123
 # Prevent NTP traffic from initiating dial out
 set filter dial 1 permit 0 0
 set filter alive 0 deny udp src eq 123
 # Prevent incoming NTP traffic from keeping the connection open
 set filter alive 1 deny udp dst eq 123
 # Prevent outgoing NTP traffic from keeping the connection open
 set filter alive 2 permit 0/0 0/0

¾ÜºÙ¤Ë¤Ä¤¤¤Æ¤Ï ppp(8) Æâ¤Î PACKET FILTERING ¥»¥¯¥·¥ç¥ó¡¢¤ª¤è¤Ó /usr/share/examples/ppp/ Æâ¤ÎÎã¤ò»²¾È¤·¤Æ¤¯¤À¤µ¤¤¡£

注意: ¾®¤µ¤¤ÈÖ¹æ¤Î¥Ý¡¼¥È¤ò¥Ö¥í¥Ã¥¯¤¹¤ë¥¤¥ó¥¿¡¼¥Í¥Ã¥È¥¢¥¯¥»¥¹¥×¥í¥Ð¥¤¥À¤Ç¤Ï¡¢ ±þÅú¤¬¤¢¤Ê¤¿¤Î¥Þ¥·¥ó¤ËÅþ㤷¤Ê¤¤¤Î¤Ç NTP ¤¬¤­¤Á¤ó¤ÈÆ°ºî¤·¤Ê¤¤¾ì¹ç¤â¤¢¤ê¤Þ¤¹¡£

22.12.6. ¤µ¤é¤Ê¤ë¾ðÊó¸»

NTP ¥µ¡¼¥Ð¤Ë´Ø¤¹¤ëʸ½ñ¤Ï HTML ·Á¼°¤Ç /usr/share/doc/ntp/ ¤Ë¤¢¤ê¤Þ¤¹¡£

ËÜʸ½ñ¡¢¤ª¤è¤Ó¾¤Îʸ½ñ¤Ï ftp://ftp.FreeBSD.org/pub/FreeBSD/doc/ ¤«¤é¥À¥¦¥ó¥í¡¼¥É¤Ç¤­¤Þ¤¹¡£

FreeBSD ¤Ë´Ø¤¹¤ë¼ÁÌ䤬¤¢¤ë¾ì¹ç¤Ë¤Ï¡¢¥É¥­¥å¥á¥ó¥È ¤òÆɤó¤À¾å¤Ç <questions@FreeBSD.org> ¤Þ¤Ç (±Ñ¸ì¤Ç) Ï¢Íí¤·¤Æ¤¯¤À¤µ¤¤¡£
ËÜʸ½ñ¤Ë´Ø¤¹¤ë¼ÁÌä¤Ë¤Ä¤¤¤Æ¤Ï¡¢<doc@FreeBSD.org> ¤Þ¤ÇÅŻҥ᡼¥ë¤ò (±Ñ¸ì¤Ç) Á÷¤Ã¤Æ¤¯¤À¤µ¤¤¡£