Public bug reported:
The TLS certificate used for Network Time Security (NTS) on
1.ntp.ubuntu.com:4460 and 2.ntp.ubuntu.com:4460 expired on August 25,
2026 at 16:36:32 GMT.
As a result, NTS clients (such as ntpd-rs and chrony with NTS enabled)
fail certificate verification during key exchange with:
InvalidCertificate(ExpiredContext { not_after: Aug 25 16:36:32 2026 GMT
})
$ openssl s_client -connect 1.ntp.ubuntu.com:4460 -servername 1.ntp.ubuntu.com
</dev/null
depth=0 CN = 1.ntp.ubuntu.com
verify error:num=10:certificate has expired
notAfter=Aug 25 16:36:32 2026 GMT
Verify return code: 10 (certificate has expired)
$ openssl s_client -connect 2.ntp.ubuntu.com:4460 -servername 2.ntp.ubuntu.com
</dev/null
depth=0 CN = 2.ntp.ubuntu.com
verify error:num=10:certificate has expired
notAfter=Aug 25 16:36:32 2026 GMT
Verify return code: 10 (certificate has expired)
Please renew the TLS certificates for the NTS service on
1.ntp.ubuntu.com and 2.ntp.ubuntu.com.
** Affects: ntp (Ubuntu)
Importance: Undecided
Status: New
--
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2165163
Title:
NTS TLS certificate expired on 1.ntp.ubuntu.com and 2.ntp.ubuntu.com
(port 4460)
To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/ntp/+bug/2165163/+subscriptions
--
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs