NTP - Autokey Client
After using the GENERATE button, select the individual key or certificate files and click SAVE
AS to download them to a secure location.
For the PC scheme, save both the server host key and certificate files to a secure location
and install them on the Autokey clients. For the IFF and GQ schemes, save the group key file
to a secure location and install it on the Autokey clients.
After downloading the keys, click the RESTART button to make the key(s) active on the NTP
server.
Note: NTP Autokeys are not active until the user clicks RESTART.
Also see: Using Autokey (on page 163)
RESTART Button
After changing the NTP configuration, click the RESTART button to put the new configuration
into effect. While the NTP daemon restarts, its services are temporarily unavailable, and it
generates the following alarm events: NTP Stratum Change, NTP System Peer Change,
NTP Leap Change.
Se e"R EST ART Bu tton"on pa ge4 9
NTP - Autokey Client
Use this page to manage (add or remove) Autokey keys for NTP associations where the Syn-
cServer is an NTP client.
Note: MD5 and Autokey cannot be used on the SyncServer concurrently. Configuring one
method erases the keys or certificates of the other.
Configuration of SyncServer as Autokey Client
Removal of Existing Client Relationship
To remove keys, select the checkbox of the key(s), and click the DELETE button. Existing keys
are identified by their Scheme and Filename. Click RESTART to complete the removal process.
Upon completing the removal process, the SyncServer will not be able to authenticate NTP
packets from NTP servers that use those keys.
NTP Autokeys are not fully removed until the user clicks RESTART.
Addition of New Client Relationship
To add keys, use the following fields as described.
Select the Identity Scheme of the key.
n
For PC and GQ identity schemes, enter the Server Password, the same password used
while generating the keys or certificates on the Autokey server (using the NTP - Autokey
page).
n
For the PC scheme, use BROWSE to locate the Server Host Key File and Server Certificate
File at a secure location. For IFF and GQ, use BROWSE to locate the group key file from a
secure location.
Enter the Server Password, if needed.
997-01520-02 Rev. F1.......................................................................... Page 49