# Chrony Instead of ntpd

LLMS index: [llms.txt](/en/llms.txt)

---

Chrony has replaced `ntpd` as the default NTP client in most modern Linux distributions. It converges to accurate time faster, handles intermittent network connections better, and consumes fewer resources. If your machine still runs `ntpd`, switching takes only a few minutes.

## Installation

On RHEL-based systems:

```bash
sudo dnf install chrony -y
sudo systemctl enable --now chronyd
```

On Debian/Ubuntu:

```bash
sudo apt install chrony -y
sudo systemctl enable --now chronyd
```

If `ntpd` was running on this machine before, stop and disable it to avoid port conflicts:

```bash
sudo systemctl stop ntpd
sudo systemctl disable ntpd
```

## makestep Configuration

The key directive in `/etc/chrony/chrony.conf` (or `/etc/chrony.conf` on RHEL) is `makestep`. It controls how `chronyd` behaves at startup — whether to correct time gradually or in a single step.

```conf
makestep 1.0 3
```

> [!NOTE] makestep
> Format: `makestep <max_offset> <max_updates>`. If the offset exceeds `<max_offset>` seconds and the number of updates hasn't exceeded `<max_updates>`, chrony applies a sudden correction instead of gradual slewing. The default `makestep 1.0 3` allows up to a 1-second jump three times during the first synchronizations.

A common mistake is setting `makestep -1 1` and expecting a server with a large initial offset to correct instantly. In practice, negative values only work under specific conditions. For reliable startup, use a positive number and limit the number of steps.

## allow Directive

By default, `chronyd` operates only as a client. To let other hosts synchronize through this server, add `allow`:

```conf
allow 10.0.0.0/24
```

> [!TIP] allow
> You can specify individual IPs, subnets, or multiple `allow` lines for different networks. Without this directive, the machine accepts requests only from localhost.

To block a specific host, use `deny` — it takes effect after `allow` and overrides it:

```conf
allow 10.0.0.0/24
deny 10.0.0.42
```

After changing the configuration, restart the service:

```bash
sudo systemctl restart chronyd
```

## Verification with timedatectl

`timedatectl` shows the current synchronization state and time source:

```bash
timedatectl
```

Example output:

```
               Local time: Wed 2025-01-15 14:23:01 MSK
           Universal time: Wed 2025-01-15 11:23:01 UTC
                 RTC time: Wed 2025-01-15 11:23:01
                Time zone: Europe/Moscow (MSK, +0300)
System clock synchronized: yes
              NTP service: active
          RTC in local TZ: no
```

Key fields for diagnostics:

| Field | Problem Value | Meaning |
|---|---|---|
| `System clock synchronized` | `no` | chrony hasn't caught up yet |
| `NTP service` | `inactive` | service not running or not enabled |
| `RTC in local TZ` | `yes` | hardware clock in local timezone — common issue on VMs |

For detailed information about current sources:

```bash
chronyc sources -v
```

If `NTP service: active` and `System clock synchronized: yes`, everything is working. If not, check `sudo systemctl status chronyd` and network access to NTP servers (UDP port 123).
