Hello,

I read http://www.openbsd.org/faq/faq6.html#OpenNTPD and also found this
nowhere else.

NTP is not authenticated in OpenBSD by default, right?

That is a major security vulnerability. A MITM can set the clock
severals years back, thus getting the client into using expired/revoked
SSL certificates and provable loads of other issues.

Cheers,
adrelanos

Reply via email to