Install the systemd_timesyncd Service
Description
The systemd_timesyncd service should be installed.
Rationale
Time synchronization (using NTP) is required by almost all network and administrative tasks (syslog, cryptographic based services (authentication, etc.), etc.). systemd_timesyncd is a part of the systemd suite and acts as a NTP client.
Shell script
The following script can be run on the host to remediate the issue.
# Remediation is applicable only in certain platforms
if [ ! -f /.dockerenv ] && [ ! -f /run/.containerenv ]; then
DEBIAN\_FRONTEND=noninteractive apt-get install -y "systemd-timesyncd"
else
>&2 echo 'Remediation is not applicable, nothing was done'
fi
Ansible playbook
The following playbook can be run with Ansible to remediate the issue.
- name: Ensure systemd-timesyncd is installed
package:
name: systemd-timesyncd
state: present
when: ansible\_virtualization\_type not in ["docker", "lxc", "openvz", "podman", "container"]
tags:
- NIST-800-53-CM-6(a)
- PCI-DSS-Req-10.4
- enable\_strategy
- high\_severity
- low\_complexity
- low\_disruption
- no\_reboot\_needed
- package\_timesyncd\_installed