fhg
Volume 9, Number 38 -- October 21, 2009

Setting Up SNTP Time Synchronization on an i5/OS Box

Published: October 21, 2009

Hey, Joe:

For PCI Data Security Standard (PCI DSS) auditing, I need to ensure that my System i 550 time is synchronized with other network system clocks. How do I set up time synchronization on an i5/OS V5R4 box?

--Len


PCI DSS is a security standard being pushed by the credit card providers to encourage companies to adopt consistent security measures for protecting customer account data. Requirement 10.4 of the standard specifies that all critical system clocks and times must be synchronized. For an iSeries, System i, or Power i box, this means that your partitions must automatically synchronize their system clocks with a Network Time Protocol (NTP) server. i5/OS performs NTP time synchronization through its built-in Synchronized Network Time Protocol (SNTP) server. It's easy to configure an i5/OS partition for time synchronization through SNTP. Here's how to do it.

  1. If your machine resides behind a firewall and you're connecting to an external NTP server for updates, be sure the firewall is configured to pass User Datagram Protocol (UDP) packets through port 123.
  2. An i5/OS box can be set up as an SNTP client (where the partition synchronizes its clock with an external server), an SNTP server (where the partition serves as an NTP server for synchronizing other machine's clocks) or as both an SNTP client and a server. For our purposes, we are only configuring your partition as an SNTP client. The instructions here have only been tested for an i5/OS V5R4 machine.
  3. From a green-screen 5250 command line, enter the Change SNTP Attributes command (CHGNTPA) and press the F4 key to prompt for its parameters. This screen will be displayed.


For this example, I've filled in the following parameters for setting up your partition as an SNTP client.

Remote system (RMTSYS)--Specifies the TCP/IP address, host name, or URL of the NTP server(s) to synchronize time with. You can enter up to three different NTP system addresses. The SNTP client will select the first remote system that provides NTP time service.

Client autostart (AUTOSTART)--Specifies whether you want the TCP/IP SNTP client job to start whenever TCP/IP starts. Enter *YES.

Client Poll Interval (POLLITV)--Specifies how often the SNTP client will contact the NTP server for updates. The default is 60 minutes.

Client Activity Log (ACTLOG)--Specifies which NTP activities are written to the SNTP activity log. The default value is *NONE (no logging). I usually set ACTLOG value to *CHANGE, which creates log entries whenever the system clock is changed.

Leave all the other settings at their defaults. Press ENTER to save your settings. To start the SNTP client server, enter the following Start TCP/IP Server (STRTCPSVR) command from a command line.

STRTCPSVR SERVER(*NTP) NTPSRV(*CLIENT)

1. To configure the SNTP client from iSeries Navigator (OpsNav), open the Network→Servers→TCP/IP node for your partition in OpsNav, right-click on the SNTP entry on the right-hand side of the screen and select Properties from the pop-up menu that appears. This displays the SNTP Properties panel. Select the Client tab to display the following screen.



Adjust the SNTP client properties just as you did on the green-screen.

To ensure that the SNTP client starts whenever TCP/IP is started, select the General tab from the SNTP Properties screen. Make sure that the Client check box is checked under "SNTP services to start when TCP/IP is started." Click on OK to save your changes.



Be sure to start the SNTP TCP/IP client server after configuring the client. The server is started in OpsNav by right-clicking on the SNTP entry under Network→Servers→TCP/IP and selecting Start→Client from the pop-up menu.

2. After starting SNTP, the following messages will appear in the partition's History Log. Use the Display Log (DSPLOG) command to view these messages.

TCP9105 -- SNTP Activity Log is active.

The TCP9105 message informs you that SNTP logging has been started. It also displays the name and location of the audit file that stores system time changes. This file is usually stored in the /QIBM/USERDATA/OS400/TCPIP/NTP folder in the AS/400 IFS.

CPF1806 -- System value QTIMADJ changed from *NONE to QIBM_OS400_SNTP. 

CPF1806 tells you that the Time Adjustment (QTIMADJ) system value has been set to QIBM_OS400_SNTP, which specifies that SNTP will be responsible for synchronizing the system clock with an external time source. This value will revert to *NONE whenever you end the SNTP server.

And that's all there is to configuring and starting SNTP on an i5/OS machine.

HTH

--Joe




                     Post this story to del.icio.us
               Post this story to Digg
    Post this story to Slashdot


Sponsored By
TWIN DATA

Full system console control for multiple AS/400s and LPARs from
anywhere on your LAN, WAN, VPN, even over the Internet!

Perform certain System Maintenance and Configuration Procedures while in "Restricted State." Execute certain types of System Backups (SAVSYS) and respond to "System Console Only" messages.

Call for details about this IP Console Solution: 800-597-2525
www.twindata.com


Senior Technical Editor: Ted Holt
Technical Editor: Joe Hertvik
Contributing Technical Editors: Erwin Earley, Brian Kelly, Michael Sansoterra
Publisher and Advertising Director: Jenny Thomas
Advertising Sales Representative: Kim Reed
Contact the Editors: To contact anyone on the IT Jungle Team
Go to our contacts page and send us a message.

Sponsored Links

Infor:  Visit the first System i Virtual Conference hosted by Infor and IBM. View on-demand Webinar.
CCSS:  Need Pro-Active Management of Your IBM® i Server? We can help.
Patrick Townsend Security Solutions:  Get a customized state privacy law compliance report


 

IT Jungle Store Top Book Picks

Easy Steps to Internet Programming for AS/400, iSeries, and System i: List Price, $49.95
The iSeries Express Web Implementer's Guide: List Price, $49.95
The System i RPG & RPG IV Tutorial and Lab Exercises: List Price, $59.95
The System i Pocket RPG & RPG IV Guide: List Price, $69.95
The iSeries Pocket Database Guide: List Price, $59.00
The iSeries Pocket SQL Guide: List Price, $59.00
The iSeries Pocket Query Guide: List Price, $49.00
The iSeries Pocket WebFacing Primer: List Price, $39.00
Migrating to WebSphere Express for iSeries: List Price, $49.00
Getting Started With WebSphere Development Studio Client for iSeries: List Price, $89.00
Getting Started with WebSphere Express for iSeries: List Price, $49.00
Can the AS/400 Survive IBM?: List Price, $49.00
Chip Wars: List Price, $29.95


 
The Four Hundred
IBM Dynamic Infrastructure Announcements Due October 20

Steady as She Goes for IBM's Third Quarter

IBM i Access to Support Windows 7 on December 1

Mad Dog 21/21: Oy, Cloudy Us!

IBM Slashes i Compiler and Rational Tool Prices

Four Hundred Stuff
Jarman Flashes Clues on Future DB2 and RPG Directions

i365 Launches New EVault Backup Appliance, Cloud Storage Service

nuBridges Delivers Major Upgrade to MFT Solution

Info Builders Prophesizes World Series Winner with Predictive Analytics

Oracle Encourages JD Edwards Customers to Hang Tight

Four Hundred Monitor
Four Hundred Monitor's
Full iSeries Events Calendar

System i PTF Guide
October 17, 2009: Volume 11, Number 42

October 10, 2009: Volume 11, Number 41

October 3, 2009: Volume 11, Number 40

September 26, 2009: Volume 11, Number 39

September 19, 2009: Volume 11, Number 38

September 12, 2009: Volume 11, Number 37

September 5, 2009: Volume 11, Number 36

TPM at The Register
Gartner: IT spending growth next year

BMC eats Tideway for discovery tools

IBM installs temp server GM after insider trading furore

Boffins fawn over dirt cheap server clusters

Ellison whips out his Sparc TPC-C test

Sun tunes its VirtualBox

IBM, Intel execs arrested over alleged insider trading

US boffins use Obama dough to study clouds

IBM: Power7 to rollout throughout 2010

HP peddles app stress-testing cloud

IBM wrings more profits out of declining Q3

Oracle revs Xen VM to 2.2

THIS ISSUE SPONSORED BY:

Halcyon Software
ProData Computer Services
Twin Data


Printer Friendly Version


TABLE OF CONTENTS
Getting the Message, Part 2

Passing an Entire Result Set as a Parameter, Part 2

Setting Up SNTP Time Synchronization on an i5/OS Box

Four Hundred Guru

BACK ISSUES




 
Subscription Information:
You can unsubscribe, change your email address, or sign up for any of IT Jungle's free e-newsletters through our Web site at http://www.itjungle.com/sub/subscribe.html.

Copyright © 1996-2009 Guild Companies, Inc. All Rights Reserved.
Guild Companies, Inc., 50 Park Terrace East, Suite 8F, New York, NY 10034

Privacy Statement