Chrony Instead of ntpd
Chrony has replaced ntpd as the default NTP client in most modern Linux distributions. It converges to accurate time faster, handles intermittent network connections better, and consumes fewer resources. If your machine still runs ntpd, switching takes only a few minutes.
Installation
On RHEL-based systems:
On Debian/Ubuntu:
If ntpd was running on this machine before, stop and disable it to avoid port conflicts:
makestep Configuration
The key directive in /etc/chrony/chrony.conf (or /etc/chrony.conf on RHEL) is makestep. It controls how chronyd behaves at startup — whether to correct time gradually or in a single step.
Format: makestep <max_offset> <max_updates>. If the offset exceeds <max_offset> seconds and the number of updates hasn’t exceeded <max_updates>, chrony applies a sudden correction instead of gradual slewing. The default makestep 1.0 3 allows up to a 1-second jump three times during the first synchronizations.
A common mistake is setting makestep -1 1 and expecting a server with a large initial offset to correct instantly. In practice, negative values only work under specific conditions. For reliable startup, use a positive number and limit the number of steps.
allow Directive
By default, chronyd operates only as a client. To let other hosts synchronize through this server, add allow:
You can specify individual IPs, subnets, or multiple allow lines for different networks. Without this directive, the machine accepts requests only from localhost.
To block a specific host, use deny — it takes effect after allow and overrides it:
After changing the configuration, restart the service:
Verification with timedatectl
timedatectl shows the current synchronization state and time source:
Example output:
Key fields for diagnostics:
| Field | Problem Value | Meaning |
|---|---|---|
System clock synchronized | no | chrony hasn’t caught up yet |
NTP service | inactive | service not running or not enabled |
RTC in local TZ | yes | hardware clock in local timezone — common issue on VMs |
For detailed information about current sources:
If NTP service: active and System clock synchronized: yes, everything is working. If not, check sudo systemctl status chronyd and network access to NTP servers (UDP port 123).