Skip to content

Chrony Instead of ntpd

Chrony has replaced ntpd as the default NTP client in most modern Linux distributions. It converges to accurate time faster, handles intermittent network connections better, and consumes fewer resources. If your machine still runs ntpd, switching takes only a few minutes.

Installation

On RHEL-based systems:

sudo dnf install chrony -y
sudo systemctl enable --now chronyd

On Debian/Ubuntu:

sudo apt install chrony -y
sudo systemctl enable --now chronyd

If ntpd was running on this machine before, stop and disable it to avoid port conflicts:

sudo systemctl stop ntpd
sudo systemctl disable ntpd

makestep Configuration

The key directive in /etc/chrony/chrony.conf (or /etc/chrony.conf on RHEL) is makestep. It controls how chronyd behaves at startup — whether to correct time gradually or in a single step.

makestep 1.0 3
makestep

Format: makestep <max_offset> <max_updates>. If the offset exceeds <max_offset> seconds and the number of updates hasn’t exceeded <max_updates>, chrony applies a sudden correction instead of gradual slewing. The default makestep 1.0 3 allows up to a 1-second jump three times during the first synchronizations.

A common mistake is setting makestep -1 1 and expecting a server with a large initial offset to correct instantly. In practice, negative values only work under specific conditions. For reliable startup, use a positive number and limit the number of steps.

allow Directive

By default, chronyd operates only as a client. To let other hosts synchronize through this server, add allow:

allow 10.0.0.0/24
allow

You can specify individual IPs, subnets, or multiple allow lines for different networks. Without this directive, the machine accepts requests only from localhost.

To block a specific host, use deny — it takes effect after allow and overrides it:

allow 10.0.0.0/24
deny 10.0.0.42

After changing the configuration, restart the service:

sudo systemctl restart chronyd

Verification with timedatectl

timedatectl shows the current synchronization state and time source:

timedatectl

Example output:

               Local time: Wed 2025-01-15 14:23:01 MSK
           Universal time: Wed 2025-01-15 11:23:01 UTC
                 RTC time: Wed 2025-01-15 11:23:01
                Time zone: Europe/Moscow (MSK, +0300)
System clock synchronized: yes
              NTP service: active
          RTC in local TZ: no

Key fields for diagnostics:

FieldProblem ValueMeaning
System clock synchronizednochrony hasn’t caught up yet
NTP serviceinactiveservice not running or not enabled
RTC in local TZyeshardware clock in local timezone — common issue on VMs

For detailed information about current sources:

chronyc sources -v

If NTP service: active and System clock synchronized: yes, everything is working. If not, check sudo systemctl status chronyd and network access to NTP servers (UDP port 123).