Public bug reported:

The TLS certificate used for Network Time Security (NTS) on
1.ntp.ubuntu.com:4460 and 2.ntp.ubuntu.com:4460 expired on August 25,
2026 at 16:36:32 GMT.

As a result, NTS clients (such as ntpd-rs and chrony with NTS enabled)
fail certificate verification during key exchange with:
InvalidCertificate(ExpiredContext { not_after: Aug 25 16:36:32 2026 GMT
})

$ openssl s_client -connect 1.ntp.ubuntu.com:4460 -servername 1.ntp.ubuntu.com 
</dev/null
depth=0 CN = 1.ntp.ubuntu.com
verify error:num=10:certificate has expired
notAfter=Aug 25 16:36:32 2026 GMT
Verify return code: 10 (certificate has expired)

$ openssl s_client -connect 2.ntp.ubuntu.com:4460 -servername 2.ntp.ubuntu.com 
</dev/null
depth=0 CN = 2.ntp.ubuntu.com
verify error:num=10:certificate has expired
notAfter=Aug 25 16:36:32 2026 GMT
Verify return code: 10 (certificate has expired)

Please renew the TLS certificates for the NTS service on
1.ntp.ubuntu.com and 2.ntp.ubuntu.com.

** Affects: ntp (Ubuntu)
     Importance: Undecided
         Status: New

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2165163

Title:
  NTS TLS certificate expired on 1.ntp.ubuntu.com and 2.ntp.ubuntu.com
  (port 4460)

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/ntp/+bug/2165163/+subscriptions


-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to