{
    "mode": "man",
    "parameter": "NTPKEYGEN",
    "section": "8",
    "url": "https://www.chedong.com/phpMan.php/man/NTPKEYGEN/8/json",
    "generated": "2026-10-06T11:07:57Z",
    "synopsis": "ntpkeygen [-V]",
    "sections": {
        "NAME": {
            "content": "ntpkeygen - create and manage NTP host keys\n",
            "subsections": []
        },
        "SYNOPSIS": {
            "content": "ntpkeygen [-V]\n",
            "subsections": []
        },
        "DESCRIPTION": {
            "content": "This program generates a file containing keys that can be used in NTP’s symmetric key\ncryptography.\n\nThe program produces a file containing ten pseudo-random printable ASCII strings suitable for\nthe MD5 message digest algorithm. It also produces an additional ten hex-encoded random bit\nstrings suitable for the SHA-1 and other message digest algorithms.\n\nThe keys file must be distributed and stored using secure means beyond the scope of NTP\nitself. The keys can also be used as passwords for the ntpq <ntpq.html> utility program.\n",
            "subsections": []
        },
        "COMMAND LINE OPTIONS": {
            "content": "",
            "subsections": [
                {
                    "name": "-V, --version",
                    "content": "Print the version string and exit.\n",
                    "flag": "-V",
                    "long": "--version"
                }
            ]
        },
        "RUNNING THE PROGRAM": {
            "content": "The simplest way to run the ntpkeygen program is logged in directly as root. The recommended\nprocedure is to change to the keys directory, usually /etc/ntpsec/, then run the program.\nThen chown the output file to ntpsec:ntpsec. It should be mode 400.\n\nWarning\n\nntpkeygen uses the system randomness source. On a POSIX system, this is usually\n/dev/urandom. Immediately after a reboot, on any OS, there may not be sufficient entropy\navailable for this program to perform well. Do not run this program from any startup\nscripts. Only run this program on an active host with a lot of available entropy.\n",
            "subsections": []
        },
        "KEY FILE ACCESS AND LOCATION": {
            "content": "File names begin with the prefix ntpkey and end with the postfix hostname.filestamp, where\nhostname is the owner name, usually the string returned by the Unix gethostname() routine,\nand filestamp is the NTP seconds when the file was generated, in decimal digits.\n\nntpkeygen also makes a soft link from ntp.keys to the generated file. ntp.keys is the normal\nfile used in ntp.conf.\n",
            "subsections": []
        },
        "RANDOM SEED FILE": {
            "content": "All key generation schemes must have means to randomize the entropy seed used to initialize\nthe internal pseudo-random number generator used by the library routines.\n\nIt is important to understand that entropy must be evolved for each generation, for otherwise\nthe random number sequence would be predictable. Various means dependent on external events,\nsuch as keystroke intervals can be used to do this and some systems have built-in entropy\nsources.\n\nThis implementation uses Python’s random.SystemRandom class, which relies on os.urandom().\nThe security of os.urandom() is improved in Python 3.5+\n<https://docs.python.org/library/os.html#os.urandom>.\n",
            "subsections": []
        },
        "CRYPTOGRAPHIC DATA FILES": {
            "content": "Unlike NTP Classic, this implementation generates only AES keys, not MD5 or SHA1.\n\nSince the file contains private shared keys, it should be visible only to root or ntp.\n\nIn order to use a shared key, the line to be used must also be setup on the target server.\n\nThis file is also used to authenticate remote configuration commands used by the ntpq(1)\nutility.\n\nComments may appear in the file and are preceded with the # character.\n\nFollowing any headers the keys are entered one per line in the format:\n┌───────┬───────────────────────────────────┐\n│       │                                   │\n│ Field │ Meaning                           │\n├───────┼───────────────────────────────────┤\n│       │                                   │\n│ keyno │ Positive integer in the range     │\n│       │ 1-65,535                          │\n├───────┼───────────────────────────────────┤\n│       │                                   │\n│ type  │ Type of key (MD5, SHA-1, AES-CMAC │\n│       │ etc). This program generates only │\n│       │ AES.                              │\n├───────┼───────────────────────────────────┤\n│       │                                   │\n│ key   │ the actual key, printable ASCII   │\n│       │ or hex                            │\n└───────┴───────────────────────────────────┘\n\n",
            "subsections": []
        },
        "EXIT STATUS": {
            "content": "One of the following exit values will be returned:\n\n0 (EXITSUCCESS)\nSuccessful program execution.\n\n1 (EXITFAILURE)\nThe operation failed or the command syntax was not valid.\n\nNTPsec                                       2024-04-01                                 NTPKEYGEN(8)",
            "subsections": []
        }
    },
    "summary": "ntpkeygen - create and manage NTP host keys",
    "flags": [],
    "examples": [],
    "see_also": []
}