Skip to content

Configure and Verify Linux Time with chrony

Accurate time supports log correlation, Kerberos, certificates, and scheduled jobs. chrony synchronizes the system clock with configured sources. In managed networks, use approved internal NTP sources; do not add public pools where policy requires an enterprise time hierarchy.


01

Check the Current Time Service

Baseline

Before installing anything, check whether chrony, systemd-timesyncd, or another time service is already active. Avoid running multiple competing clock synchronizers.

Terminal window
timedatectl status
systemctl is-active chronyd chrony systemd-timesyncd 2>/dev/null
❯ View Expected Console Output
System clock synchronized: yes
NTP service: active

02

Install chrony for Your Distribution

Package Setup

Install the package with the system package manager. On Debian and Ubuntu the service is usually named chrony; Fedora and RHEL family systems typically use chronyd. If another time synchronizer is active, choose one service and follow the distribution’s procedure to disable the competing service.

Terminal window
# Debian or Ubuntu
sudo apt update
sudo apt install chrony
sudo systemctl enable --now chrony
# Fedora or RHEL family
sudo dnf install chrony
sudo systemctl enable --now chronyd
❯ View Expected Console Output
Created symlink ... chrony.service (or chronyd.service)

03

Set Approved Time Sources

Source Policy

Inspect the existing configuration before editing. Debian/Ubuntu commonly use /etc/chrony/chrony.conf; Fedora/RHEL commonly use /etc/chrony.conf. Keep the distribution’s existing settings where appropriate, and replace the sample server name with an approved NTP source.

Terminal window
# Inspect existing sources/config before editing:
grep -E '^(pool|server|sourcedir|makestep)' \
/etc/chrony/chrony.conf /etc/chrony.conf 2>/dev/null
# Example directive for an approved internal source:
# server ntp01.example.net iburst
❯ View Expected Console Output
server ntp01.example.net iburst

04

Restart chrony and Check Sources

Verification

Restart the correct service name after a reviewed config edit. Then use chrony’s client utility to see which sources are reachable and selected.

Terminal window
# Choose the service name for your distribution:
sudo systemctl restart chrony # Debian or Ubuntu
# sudo systemctl restart chronyd # Fedora or RHEL family
chronyc sources -v
chronyc tracking
❯ View Expected Console Output
MS Name/IP address Stratum Poll Reach LastRx Last sample
^* ntp01.example.net 3 6 377 25 -120us[ -180us] +/- 12ms
Reference ID : ...
Leap status : Normal

05

Check System Clock and Logs

Troubleshooting

Confirm the system clock is synchronized and inspect service logs if sources are unreachable. Verify DNS resolution, routing, UDP/123 firewall policy, and the upstream server’s health.

Terminal window
timedatectl show -p NTPSynchronized -p TimeUSec
systemctl --no-pager --full status chrony 2>/dev/null || \
systemctl --no-pager --full status chronyd
journalctl -u chrony -u chronyd --since '30 minutes ago' --no-pager
❯ View Expected Console Output
NTPSynchronized=yes
Leap status: Normal
Linux terminal showing chronyc sources with one selected NTP source and normal tracking status

Terminal: Check the selected source, reachability, stratum, and leap status.

Further reading: chrony documentation.

Comments