Time Synchronization with Chrony on RHEL

By LinuxCert.Guru Team·

Objective

This guide covers system time synchronization using Chrony on Red Hat Enterprise Linux. By the end, you will know how to:

  • Understand why accurate time synchronization matters for production Linux systems
  • Configure NTP time sources in /etc/chrony.conf
  • Enable and manage the chronyd service
  • Verify synchronization status using chronyc sources, sourcestats, and tracking
  • Check system-wide NTP status using timedatectl
  • Configure and verify the system timezone
  • Troubleshoot synchronization problems using logs and Chrony diagnostics
  • Apply these skills to RHCSA exam tasks involving time configuration

Time synchronization is one of those topics that feels trivial until something goes wrong. Log entries from two servers with clocks even a few seconds apart become impossible to correlate during an incident. Kerberos authentication fails silently when clock skew exceeds five minutes. Cron jobs run at the wrong time. Certificates show as invalid due to time drift. Chrony prevents all of this by keeping the system clock aligned with accurate network time sources continuously and automatically.

Why Accurate Time Matters

System Function What Happens Without Accurate Time
Log correlation Events on different servers appear out of order, making incident investigation difficult or impossible
Kerberos authentication Authentication fails when clock skew between client and server exceeds 5 minutes
TLS/SSL certificates Certificates appear expired or not-yet-valid if the system clock is wrong
Scheduled jobs Cron jobs and systemd timers run at the wrong time or not at all
Distributed systems Databases, clusters, and microservices can fail or produce inconsistent results when nodes disagree on time
Security auditing Audit logs lose their evidentiary value when timestamps cannot be trusted

Chrony vs ntpd: Why Chrony Is the Default on RHEL

RHEL replaced ntpd with Chrony as the default NTP implementation starting with RHEL 7. Chrony was designed to handle the conditions that ntpd struggled with:

  • Systems that are frequently suspended or disconnected: Chrony handles large time jumps and intermittent connectivity better than ntpd
    • Important for laptops, VMs, and cloud instances that are regularly started and stopped
  • Faster synchronization: the iburst option sends a burst of packets at startup, achieving initial synchronization much faster than ntpd
  • Better accuracy: Chrony uses more sophisticated algorithms to estimate and compensate for clock drift
  • Works as both client and server: the same chronyd service can synchronize from upstream NTP servers and serve time to other hosts on the local network

On RHEL 8, 9, and 10, chronyd is installed and enabled by default. You configure it, you don't install it.

Key Concepts

Term What It Is
chronyd The background daemon that continuously synchronizes and maintains the system clock
chronyc The command-line client used to monitor and manage the running chronyd service
NTP source A server or pool that provides accurate time to your system. Defined with server or pool in /etc/chrony.conf
iburst An option that sends a burst of NTP packets at startup for faster initial synchronization
Drift file Stores the measured frequency error of the hardware clock so Chrony can compensate for it immediately on startup
Clock offset The difference between the system clock and the reference time source. Chrony works to keep this as close to zero as possible.
Stratum A number indicating distance from the authoritative time source. Stratum 1 = directly connected to atomic clock. Stratum 2 = synchronized from a Stratum 1 server.

Step 1: Check Current Time and Synchronization Status

Before configuring anything, check what the system is currently doing with time:

# Check current system time, timezone, and NTP synchronization status
timedatectl

# Sample output:
#                Local time: Wed 2026-06-15 14:30:00 UTC
#            Universal time: Wed 2026-06-15 14:30:00 UTC
#                  RTC time: Wed 2026-06-15 14:30:00
#                 Time zone: UTC (UTC, +0000)
# System clock synchronized: yes
#               NTP service: active
#           RTC in local TZ: no

# Check if chronyd is running
systemctl status chronyd

# Check what NTP servers are currently configured
grep -E "^(server|pool)" /etc/chrony.conf

Step 2: Configure NTP Time Sources

The main Chrony configuration file is /etc/chrony.conf. This is where you define which NTP servers your system synchronizes from.

# View the current configuration
cat /etc/chrony.conf

# Default RHEL configuration uses the RHEL NTP pool
# pool 2.rhel.pool.ntp.org iburst
# Example: Configure a specific NTP server
# Edit /etc/chrony.conf and add or modify time sources

# Using a pool (recommended: automatically selects multiple servers)
pool 2.rhel.pool.ntp.org iburst

# Using specific servers (useful when you control your own NTP infrastructure)
server ntp1.example.com iburst
server ntp2.example.com iburst
server ntp3.example.com iburst

# Using public pool servers
pool 0.pool.ntp.org iburst
pool 1.pool.ntp.org iburst

A complete minimal /etc/chrony.conf with important directives explained:

# /etc/chrony.conf

# Time source: pool selects multiple servers automatically
pool 2.rhel.pool.ntp.org iburst

# Record the rate at which the system clock gains/loses time
driftfile /var/lib/chrony/drift

# Allow the system clock to be stepped in the first 3 updates
# if the offset is larger than 1 second (useful at initial startup)
makestep 1.0 3

# Enable hardware timestamping on all interfaces that support it
hwtimestamp *

# Sync hardware clock (RTC) to system clock periodically
rtcsync

# Allow NTP client access from the local network
# allow 192.168.0.0/24

# Log files location
logdir /var/log/chrony

After editing the configuration file, restart chronyd to apply the changes:

# Restart chronyd to pick up configuration changes
systemctl restart chronyd

# Enable chronyd to start automatically at boot
systemctl enable chronyd

# Verify the service is running
systemctl status chronyd

Step 3: Verify Time Sources with chronyc

The chronyc command is your main tool for checking synchronization status. Three commands cover most monitoring needs:

chronyc sources: Check Connected Time Sources

# List all NTP sources and their status
chronyc sources

# Sample output:
# MS Name/IP address         Stratum Poll Reach LastRx Last sample
# ===============================================================================
# ^* ntp1.example.com              2   6   377    45   +12us[ +34us] +/-  456us
# ^- ntp2.example.com              2   6   377    46   -567us[-545us] +/- 1345us
# ^? ntp3.example.com              0   8     0     -     +0ns[   +0ns] +/-    0ns

# Use -v for verbose output with column explanations
chronyc sources -v

Reading the output:

  • Mode column (first character):
    • ^ means a server (as opposed to a peer)
    • * means this is the currently selected best source
    • + means a good source that could be used but isn't currently selected
    • - means excluded from use by the combining algorithm
    • ? means the source is not reachable or has not been heard from
  • Reach: an octal value representing the last 8 poll attempts. 377 means all 8 succeeded. Anything less means some polls failed.
  • Last sample: the measured time offset between your clock and this source

chronyc sourcestats: Time Source Statistics

# Show statistics for each time source
chronyc sourcestats

# Sample output:
# Name/IP Address            NP  NR  Span  Frequency  Freq Skew  Offset  Std Dev
# ==============================================================================
# ntp1.example.com           16  10   26m     -0.014      0.341   +15us   123us
# ntp2.example.com            8   5   13m     +0.023      0.892  -543us   456us
  • NP: number of sample points used for the regression calculation
  • NR: number of sample runs that passed the regression test
  • Frequency: estimated rate at which the clock would gain or lose time without correction
  • Std Dev: estimated standard deviation of the time offset: lower is better

chronyc tracking: Clock Tracking Information

# Show detailed clock tracking information
chronyc tracking

# Sample output:
# Reference ID    : C0A80001 (ntp1.example.com)
# Stratum         : 3
# Ref time (UTC)  : Wed Jun 15 14:30:00 2026
# System time     : 0.000034521 seconds fast of NTP time
# Last offset     : +0.000034521 seconds
# RMS offset      : 0.000089234 seconds
# Frequency       : 2.347 ppm fast
# Residual freq   : +0.001 ppm
# Skew            : 0.234 ppm
# Root delay      : 0.001234567 seconds
# Root dispersion : 0.000345678 seconds
# Update interval : 64.2 seconds
# Leap status     : Normal
  • Reference ID: the NTP source currently being used as the reference
  • Stratum: your system's stratum level (one higher than the reference source)
  • System time: the current offset between your clock and the reference. "fast" means your clock is ahead; "slow" means it is behind.
  • Frequency: the measured drift of your hardware clock in parts per million (ppm). Chrony compensates for this automatically.
  • Leap status: Normal means no leap second is pending. This changes near the end of June and December when leap seconds are scheduled.

Step 4: Configure and Verify the System Timezone

NTP synchronization always uses UTC internally. The timezone setting controls how that UTC time is displayed as local time. Changing the timezone does not affect synchronization at all.

# List all available timezones
timedatectl list-timezones

# Filter to find your region
timedatectl list-timezones | grep America
timedatectl list-timezones | grep Europe
timedatectl list-timezones | grep Asia

# Set the system timezone
timedatectl set-timezone America/New_York
timedatectl set-timezone Europe/London
timedatectl set-timezone Asia/Kolkata

# Verify the timezone change
timedatectl

# Alternative: check the timezone symlink directly
ls -la /etc/localtime

# The timezone is stored as a symlink to the timezone data file
# /etc/localtime -> ../usr/share/zoneinfo/America/New_York

Step 5: Verify Full Synchronization Status

# Complete verification sequence

# 1. Check system time and NTP status
timedatectl

# 2. Confirm chronyd is running and enabled
systemctl is-active chronyd
systemctl is-enabled chronyd

# 3. Check which time source is being used
chronyc sources

# 4. Confirm synchronization is happening
chronyc tracking

# 5. Check that the system clock is marked as synchronized
timedatectl show | grep NTPSynchronized

The key line to look for in timedatectl output is:

System clock synchronized: yes
NTP service: active

Both must show the expected values. "NTP service: active" means chronyd is running. "System clock synchronized: yes" means it has actually achieved synchronization with a time source.

Troubleshooting Synchronization Problems

Check the System Journal for Chrony Messages

# View recent chronyd log entries
journalctl -u chronyd --since "1 hour ago"

# Follow chronyd logs in real time
journalctl -u chronyd -f

# Check for any errors or warnings in chrony's own log
cat /var/log/chrony/statistics.log

Check Chrony Activity

# Check if chronyd is currently online or in offline mode
chronyc activity

# Sample output:
# 3 sources online
# 0 sources offline
# 0 sources doing burst (return to online)
# 0 sources doing burst (return to offline)
# 0 sources with unknown address

# Force an immediate synchronization attempt
chronyc makestep

# Check if the NTP port is accessible (firewall troubleshooting)
ss -ulnp | grep 123

Common Problems and Solutions

Symptom Likely Cause How to Fix
chronyc sources shows all sources as ? Cannot reach NTP servers: network issue or firewall blocking UDP port 123 Check network connectivity, open UDP port 123 in firewalld
System clock synchronized: no in timedatectl chronyd is running but hasn't achieved synchronization yet, or no reachable sources Wait a few minutes after starting chronyd, then run chronyc makestep
Clock drifts significantly between reboots Drift file not being written or hardware clock issues Verify driftfile path in /etc/chrony.conf is writable
Large initial offset warning in journal Clock was significantly wrong at startup makestep 1.0 3 in config handles this on startup. Run chronyc makestep manually for immediate correction.
Kerberos authentication failures Clock skew between client and server exceeds 5 minutes Force immediate sync with chronyc makestep and verify both client and server use the same NTP source
NTP service: inactive in timedatectl chronyd is not running systemctl start chronyd and systemctl enable chronyd

Firewall Configuration for NTP

# NTP uses UDP port 123
# If this system needs to reach external NTP servers, the outbound port must be open
# If this system acts as an NTP server for other hosts, the inbound port must be open

# Allow NTP through firewalld
firewall-cmd --permanent --add-service=ntp
firewall-cmd --reload

# Verify NTP is allowed
firewall-cmd --list-services

Configuring Chrony as an NTP Server

A single host with internet access can synchronize from upstream NTP servers and serve time to other hosts on the local network. This is useful in environments where internal hosts cannot reach the internet directly.

# Add to /etc/chrony.conf on the server that will serve time locally

# Synchronize from upstream sources
pool 2.rhel.pool.ntp.org iburst

# Allow hosts on the local network to synchronize from this server
allow 192.168.1.0/24

# On client machines, point to the local NTP server
# server 192.168.1.10 iburst

Quick Reference: chronyc Commands

Command What It Shows When to Use
chronyc sources All configured NTP sources, their status, reachability, and offset First check when verifying synchronization is working
chronyc sources -v Same as above with column header explanations When you need to understand what each column means
chronyc sourcestats Statistical information about each NTP source including frequency drift and standard deviation When assessing the quality of time sources
chronyc tracking Current reference clock, system time offset, frequency error, and synchronization quality Detailed view of how well the clock is synchronized right now
chronyc activity Count of sources that are online, offline, or unreachable Quick check of how many sources are reachable
chronyc makestep Forces an immediate step correction of the system clock When the clock is significantly wrong and needs immediate correction

Chrony and the RHCSA Exam

Time synchronization with Chrony is a direct RHCSA exam objective. Exam tasks in this area typically require:

  • Configuring a specific NTP server or pool in /etc/chrony.conf
  • Ensuring chronyd is running and enabled to start at boot
  • Verifying synchronization is active using chronyc sources and timedatectl
  • Setting the correct system timezone using timedatectl set-timezone
  • The configuration must survive a reboot: both enable and correct /etc/chrony.conf are required

The most common exam failure pattern: editing /etc/chrony.conf but forgetting to restart chronyd afterward, or starting the service but not enabling it. The exam verifies the result after a reboot, so both steps are always required.

Practice This in a Real Environment

Time synchronization is one of those topics where hands-on practice matters more than reading. The chronyc sources output looks different from what you expect until you have seen it on a working system and on a broken one. The difference between a * and a ? next to a source becomes immediately clear the first time you have to diagnose a synchronization problem.

LinuxCert.Guru has a dedicated hands-on lab for this topic: Time Synchronization with Chrony. It covers NTP source configuration, service management, chronyc verification commands, timezone configuration, and troubleshooting on real RHEL hosts with auto-graded tasks.

Practice the Time Synchronization with Chrony lab at LinuxCert.Guru → https://linuxcert.guru/?name=rh134-time-sync-chrony

Conclusion

Chrony is the default and recommended NTP implementation on RHEL, and configuring it correctly is both a practical production skill and an RHCSA exam objective. The workflow is straightforward once you know the right sequence:

  • Configure your NTP sources in /etc/chrony.conf using server or pool directives with iburst
  • Restart chronyd after editing the configuration: systemctl restart chronyd
  • Enable chronyd at boot: systemctl enable chronyd
  • Verify sources are reachable: chronyc sources should show * next to the selected source
  • Confirm synchronization: chronyc tracking shows the current offset and reference
  • Check system-wide status: timedatectl should show both NTP service active and system clock synchronized
  • Set the correct timezone: timedatectl set-timezone Region/City
  • For immediate correction of a badly drifted clock: chronyc makestep

 

$_
Ready to go beyond reading? Manage Local Users and Groupsfree · auto-graded RHCSA lab, nothing to install Not sure where you stand? Take the 10-min RHCSA skill check →
Open lab →