What is best practice here?

Do not run {x}ntpd in the zones.

Actually there is a use-case for doing so - given that it's a
network-facing appliction, one might want to run xntpd in a non-global
zone for isolation reasons.


It would be a great idea to have a easy solution to give these privileges to a zone.

