MyBox

   :: 首页  :: 新随笔  :: 联系 :: 订阅 订阅  :: 管理

在CentOS6.4中:

#临时关闭selinux setenforce 0 #彻底关闭selinux(重启生效) sed -i "s/SELINUX=enforcing/SELINUX=disabled/g" `grep SELINUX=enforcing -rl /etc/selinux/config` #临时关闭iptable防火墙 /etc/init.d/iptables stop #彻底关闭iptable防火墙 chkconfig --level 35 iptables off #开启SSH服务 service sshd restart #开机自启动SSH服务 chkconfig --level 35 sshd on #检查是否安装了NTP #rpm -qa |grep ntp #卸载NTP #yum remove ntp -y #安装NTP #yum install ntp -y #替换配置文件 #\cp -f ./ntp.conf.sample /etc/ntp.conf
 
#服务器配置-修改配置文件/etc/sysconfig/ntpd:
#SYNC_HWCLOCK=yes     # 改成 yes ,则BIOS 的时间也会跟着一起改变(centos)
#开机自启动NTP服务 chkconfig --level 35 ntpd on #立即启动NTP服务 service ntpd restart #查看NTP运行情况 watch ntpq -p date && hwclock
 
NTP服务器地址
域名 地理位置 负责人 邮件 电话
0 ntp.api.bz 服务器集群      
1 s1a.time.edu.cn 北京邮电大学 王振华 wzhdl at bupt.edu.cn 010-62283044-8003
1 s1b.time.edu.cn 清华大学 尹惠实 yhs at cernet.edu.cn 010-62795818-6105
1 s1c.time.edu.cn 北京大学 马皓 mah at pku.edu.cn 010-62753007
1 s1d.time.edu.cn 东南大学 徐加羚 jlxu at njnet.edu.cn 025-3794342-309
1 s1e.time.edu.cn 清华大学 尹惠实 yhs at cernet.edu.cn 010-62795818-6105
2 s2a.time.edu.cn 清华大学 尹惠实 yhs at cernet.edu.cn 010-62795818-6105
2 s2b.time.edu.cn 清华大学 尹惠实 yhs at cernet.edu.cn 010-62795818-6105
2 s2c.time.edu.cn 北京邮电大学 王振华 wzhdl at bupt.edu.cn 010-62283044-8003
2 s2d.time.edu.cn 西南地区网络中心 刘瑶 nic at cdnet.edu.cn  
2 s2e.time.edu.cn 西北地区网络中心 丁惠宁 dhn at xanet.edu.cn 029-2669037
2 s2f.time.edu.cn 东北地区网络中心 毛宇 maoy at neu.edu.cn 024-23966854
2 s2g.time.edu.cn 华东南地区网络中心 瞿庆海 qqh at sjtu.edu.cn 021-62932901-8101
2 s2h.time.edu.cn 四川大学网络管理中心 郑炳伦 zhengbl at scu.edu.cn 028-85414820
2 s2j.time.edu.cn 大连理工大学网络中心 于广辉 ygh at dlut.edu.cn 0411-4708642
2 s2k.time.edu.cn CERNET桂林主节点 胡进坤 jinkun at   mailbox.gxnu.edu.cn 0773-5845246
2 s2m.time.edu.cn 北京大学 马皓 mah at pku.edu.cn 010-62753007
 
 
服务器端配置文件:

# For more information about this file, see the man pages # ntp.conf(5), ntp_acc(5), ntp_auth(5), ntp_clock(5), ntp_misc(5), ntp_mon(5).

driftfile /var/lib/ntp/drift

# Permit time synchronization with our time source, but do not # permit the source to query or modify the service on this system. restrict default kod nomodify notrap nopeer noquery restrict -6 default kod nomodify notrap nopeer noquery

# Permit all access over the loopback interface.  This could # be tightened as well, but to do so would effect some of # the administrative functions. restrict 127.0.0.1 restrict -6 ::1

# Hosts on local network are less restricted. restrict 192.168.0.0 mask 255.255.0.0 nomodify notrap

# Use public servers from the pool.ntp.org project. # Please consider joining the pool (http://www.pool.ntp.org/join.html). server ntp.api.bz prefer #服务器集群 server s1a.time.edu.cn #北京邮电大学 server s1b.time.edu.cn #清华大学 server s1c.time.edu.cn #北京大学 server s1d.time.edu.cn #东南大学 server s1e.time.edu.cn #清华大学 server s2a.time.edu.cn #清华大学 server s2b.time.edu.cn #清华大学 server s2c.time.edu.cn #北京邮电大学 server s2d.time.edu.cn #西南地区网络中心 server s2e.time.edu.cn #西北地区网络中心 server s2f.time.edu.cn #东北地区网络中心 server s2g.time.edu.cn #华东南地区网络中心 server s2h.time.edu.cn #四川大学网络管理中心 server s2j.time.edu.cn #大连理工大学网络中心 server s2k.time.edu.cn #CERNET桂林主节点 server s2m.time.edu.cn #北京大学

#broadcast 192.168.1.255 autokey # broadcast server #broadcastclient   # broadcast client #broadcast 224.0.1.1 autokey  # multicast server #multicastclient 224.0.1.1  # multicast client #manycastserver 239.255.254.254  # manycast server #manycastclient 239.255.254.254 autokey # manycast client

# Undisciplined Local Clock. This is a fake driver intended for backup # and when no outside source of synchronized time is available. #server 127.127.1.0 # local clock #fudge 127.127.1.0 stratum 10 

# Enable public key cryptography. #crypto

includefile /etc/ntp/crypto/pw

# Key file containing the keys and key identifiers used when operating # with symmetric key cryptography. keys /etc/ntp/keys

# Specify the key identifiers which are trusted. #trustedkey 4 8 42

# Specify the key identifier to use with the ntpdc utility. #requestkey 8

# Specify the key identifier to use with the ntpq utility. #controlkey 8

# Enable writing of statistics records. #statistics clockstats cryptostats loopstats peerstats

logfile /var/log/ntp

 

 

 

客户端配置文件:

################################################################################ ## /etc/ntp.conf ## ## Sample NTP configuration file. ## See package 'ntp-doc' for documentation, Mini-HOWTO and FAQ. ## Copyright (c) 1998 S.u.S.E. GmbH Fuerth, Germany. ## ## Author: Michael Andres,  <ma@suse.de> ## ################################################################################

## ## Radio and modem clocks by convention have addresses in the ## form 127.127.t.u, where t is the clock type and u is a unit ## number in the range 0-3. ## ## Most of these clocks require support in the form of a ## serial port or special bus peripheral. The particular  ## device is normally specified by adding a soft link ## /dev/device-u to the particular hardware device involved, ## where u correspond to the unit number above. ## ## Generic DCF77 clock on serial port (Conrad DCF77) ## Address:     127.127.8.u ## Serial Port: /dev/refclock-u ##  ## (create soft link /dev/refclock-0 to the particular ttyS?) ## # server 127.127.8.0 mode 5 prefer server 192.168.1.46 prefer

## ## Undisciplined Local Clock. This is a fake driver intended for backup ## and when no outside source of synchronized time is available. ## #server 127.127.1.0  # local clock (LCL) fudge  127.127.1.0 stratum 10 # LCL is unsynchronized

## ## Outside source of synchronized time ## ## server xx.xx.xx.xx  # IP address of server

## ## Miscellaneous stuff ##

driftfile /var/lib/ntp/drift/ntp.drift # path for drift file

logfile   /var/log/ntp  # alternate log file # logconfig =syncstatus + sysevents # logconfig =all

# statsdir /tmp/  # directory for statistics files # filegen peerstats  file peerstats  type day enable # filegen loopstats  file loopstats  type day enable # filegen clockstats file clockstats type day enable

# # Authentication stuff # # keys /etc/ntp.keys  # path for keys file # trustedkey 1 2 3 4 5 6 14 15 # define trusted keys # requestkey 15   # key (7) for accessing server variables # controlkey 15   # key (6) for accessing server variables

posted on 2013-11-04 14:03  MyBox  阅读(737)  评论(0)    收藏  举报