Time Synchronization with Chrony on RHEL
Objective
This guide covers system time synchronization using Chrony on Red Hat Enterprise Linux. By the end, you will know how to:
- Understand why accurate time synchronization matters for production Linux systems
- Configure NTP time sources in
/etc/chrony.conf - Enable and manage the
chronydservice - Verify synchronization status using
chronyc sources,sourcestats, andtracking - Check system-wide NTP status using
timedatectl - Configure and verify the system timezone
- Troubleshoot synchronization problems using logs and Chrony diagnostics
- Apply these skills to RHCSA exam tasks involving time configuration
Time synchronization is one of those topics that feels trivial until something goes wrong. Log entries from two servers with clocks even a few seconds apart become impossible to correlate during an incident. Kerberos authentication fails silently when clock skew exceeds five minutes. Cron jobs run at the wrong time. Certificates show as invalid due to time drift. Chrony prevents all of this by keeping the system clock aligned with accurate network time sources continuously and automatically.
Why Accurate Time Matters
| System Function | What Happens Without Accurate Time |
|---|---|
| Log correlation | Events on different servers appear out of order, making incident investigation difficult or impossible |
| Kerberos authentication | Authentication fails when clock skew between client and server exceeds 5 minutes |
| TLS/SSL certificates | Certificates appear expired or not-yet-valid if the system clock is wrong |
| Scheduled jobs | Cron jobs and systemd timers run at the wrong time or not at all |
| Distributed systems | Databases, clusters, and microservices can fail or produce inconsistent results when nodes disagree on time |
| Security auditing | Audit logs lose their evidentiary value when timestamps cannot be trusted |
Chrony vs ntpd: Why Chrony Is the Default on RHEL
RHEL replaced ntpd with Chrony as the default NTP implementation starting with RHEL 7. Chrony was designed to handle the conditions that ntpd struggled with:
- Systems that are frequently suspended or disconnected: Chrony handles large time jumps and intermittent connectivity better than
ntpd- Important for laptops, VMs, and cloud instances that are regularly started and stopped
- Faster synchronization: the
iburstoption sends a burst of packets at startup, achieving initial synchronization much faster thanntpd - Better accuracy: Chrony uses more sophisticated algorithms to estimate and compensate for clock drift
- Works as both client and server: the same
chronydservice can synchronize from upstream NTP servers and serve time to other hosts on the local network
On RHEL 8, 9, and 10, chronyd is installed and enabled by default. You configure it, you don't install it.
Key Concepts
| Term | What It Is |
|---|---|
chronyd |
The background daemon that continuously synchronizes and maintains the system clock |
chronyc |
The command-line client used to monitor and manage the running chronyd service |
| NTP source | A server or pool that provides accurate time to your system. Defined with server or pool in /etc/chrony.conf |
iburst |
An option that sends a burst of NTP packets at startup for faster initial synchronization |
| Drift file | Stores the measured frequency error of the hardware clock so Chrony can compensate for it immediately on startup |
| Clock offset | The difference between the system clock and the reference time source. Chrony works to keep this as close to zero as possible. |
| Stratum | A number indicating distance from the authoritative time source. Stratum 1 = directly connected to atomic clock. Stratum 2 = synchronized from a Stratum 1 server. |
Step 1: Check Current Time and Synchronization Status
Before configuring anything, check what the system is currently doing with time:
# Check current system time, timezone, and NTP synchronization status
timedatectl
# Sample output:
# Local time: Wed 2026-06-15 14:30:00 UTC
# Universal time: Wed 2026-06-15 14:30:00 UTC
# RTC time: Wed 2026-06-15 14:30:00
# Time zone: UTC (UTC, +0000)
# System clock synchronized: yes
# NTP service: active
# RTC in local TZ: no
# Check if chronyd is running
systemctl status chronyd
# Check what NTP servers are currently configured
grep -E "^(server|pool)" /etc/chrony.conf
Step 2: Configure NTP Time Sources
The main Chrony configuration file is /etc/chrony.conf. This is where you define which NTP servers your system synchronizes from.
# View the current configuration
cat /etc/chrony.conf
# Default RHEL configuration uses the RHEL NTP pool
# pool 2.rhel.pool.ntp.org iburst
# Example: Configure a specific NTP server
# Edit /etc/chrony.conf and add or modify time sources
# Using a pool (recommended: automatically selects multiple servers)
pool 2.rhel.pool.ntp.org iburst
# Using specific servers (useful when you control your own NTP infrastructure)
server ntp1.example.com iburst
server ntp2.example.com iburst
server ntp3.example.com iburst
# Using public pool servers
pool 0.pool.ntp.org iburst
pool 1.pool.ntp.org iburst
A complete minimal /etc/chrony.conf with important directives explained:
# /etc/chrony.conf
# Time source: pool selects multiple servers automatically
pool 2.rhel.pool.ntp.org iburst
# Record the rate at which the system clock gains/loses time
driftfile /var/lib/chrony/drift
# Allow the system clock to be stepped in the first 3 updates
# if the offset is larger than 1 second (useful at initial startup)
makestep 1.0 3
# Enable hardware timestamping on all interfaces that support it
hwtimestamp *
# Sync hardware clock (RTC) to system clock periodically
rtcsync
# Allow NTP client access from the local network
# allow 192.168.0.0/24
# Log files location
logdir /var/log/chrony
After editing the configuration file, restart chronyd to apply the changes:
# Restart chronyd to pick up configuration changes
systemctl restart chronyd
# Enable chronyd to start automatically at boot
systemctl enable chronyd
# Verify the service is running
systemctl status chronyd
Step 3: Verify Time Sources with chronyc
The chronyc command is your main tool for checking synchronization status. Three commands cover most monitoring needs:
chronyc sources: Check Connected Time Sources
# List all NTP sources and their status
chronyc sources
# Sample output:
# MS Name/IP address Stratum Poll Reach LastRx Last sample
# ===============================================================================
# ^* ntp1.example.com 2 6 377 45 +12us[ +34us] +/- 456us
# ^- ntp2.example.com 2 6 377 46 -567us[-545us] +/- 1345us
# ^? ntp3.example.com 0 8 0 - +0ns[ +0ns] +/- 0ns
# Use -v for verbose output with column explanations
chronyc sources -v
Reading the output:
- Mode column (first character):
^means a server (as opposed to a peer)*means this is the currently selected best source+means a good source that could be used but isn't currently selected-means excluded from use by the combining algorithm?means the source is not reachable or has not been heard from
- Reach: an octal value representing the last 8 poll attempts.
377means all 8 succeeded. Anything less means some polls failed. - Last sample: the measured time offset between your clock and this source
chronyc sourcestats: Time Source Statistics
# Show statistics for each time source
chronyc sourcestats
# Sample output:
# Name/IP Address NP NR Span Frequency Freq Skew Offset Std Dev
# ==============================================================================
# ntp1.example.com 16 10 26m -0.014 0.341 +15us 123us
# ntp2.example.com 8 5 13m +0.023 0.892 -543us 456us
- NP: number of sample points used for the regression calculation
- NR: number of sample runs that passed the regression test
- Frequency: estimated rate at which the clock would gain or lose time without correction
- Std Dev: estimated standard deviation of the time offset: lower is better
chronyc tracking: Clock Tracking Information
# Show detailed clock tracking information
chronyc tracking
# Sample output:
# Reference ID : C0A80001 (ntp1.example.com)
# Stratum : 3
# Ref time (UTC) : Wed Jun 15 14:30:00 2026
# System time : 0.000034521 seconds fast of NTP time
# Last offset : +0.000034521 seconds
# RMS offset : 0.000089234 seconds
# Frequency : 2.347 ppm fast
# Residual freq : +0.001 ppm
# Skew : 0.234 ppm
# Root delay : 0.001234567 seconds
# Root dispersion : 0.000345678 seconds
# Update interval : 64.2 seconds
# Leap status : Normal
- Reference ID: the NTP source currently being used as the reference
- Stratum: your system's stratum level (one higher than the reference source)
- System time: the current offset between your clock and the reference. "fast" means your clock is ahead; "slow" means it is behind.
- Frequency: the measured drift of your hardware clock in parts per million (ppm). Chrony compensates for this automatically.
- Leap status: Normal means no leap second is pending. This changes near the end of June and December when leap seconds are scheduled.
Step 4: Configure and Verify the System Timezone
NTP synchronization always uses UTC internally. The timezone setting controls how that UTC time is displayed as local time. Changing the timezone does not affect synchronization at all.
# List all available timezones
timedatectl list-timezones
# Filter to find your region
timedatectl list-timezones | grep America
timedatectl list-timezones | grep Europe
timedatectl list-timezones | grep Asia
# Set the system timezone
timedatectl set-timezone America/New_York
timedatectl set-timezone Europe/London
timedatectl set-timezone Asia/Kolkata
# Verify the timezone change
timedatectl
# Alternative: check the timezone symlink directly
ls -la /etc/localtime
# The timezone is stored as a symlink to the timezone data file
# /etc/localtime -> ../usr/share/zoneinfo/America/New_York
Step 5: Verify Full Synchronization Status
# Complete verification sequence
# 1. Check system time and NTP status
timedatectl
# 2. Confirm chronyd is running and enabled
systemctl is-active chronyd
systemctl is-enabled chronyd
# 3. Check which time source is being used
chronyc sources
# 4. Confirm synchronization is happening
chronyc tracking
# 5. Check that the system clock is marked as synchronized
timedatectl show | grep NTPSynchronized
The key line to look for in timedatectl output is:
System clock synchronized: yes
NTP service: active
Both must show the expected values. "NTP service: active" means chronyd is running. "System clock synchronized: yes" means it has actually achieved synchronization with a time source.
Troubleshooting Synchronization Problems
Check the System Journal for Chrony Messages
# View recent chronyd log entries
journalctl -u chronyd --since "1 hour ago"
# Follow chronyd logs in real time
journalctl -u chronyd -f
# Check for any errors or warnings in chrony's own log
cat /var/log/chrony/statistics.log
Check Chrony Activity
# Check if chronyd is currently online or in offline mode
chronyc activity
# Sample output:
# 3 sources online
# 0 sources offline
# 0 sources doing burst (return to online)
# 0 sources doing burst (return to offline)
# 0 sources with unknown address
# Force an immediate synchronization attempt
chronyc makestep
# Check if the NTP port is accessible (firewall troubleshooting)
ss -ulnp | grep 123
Common Problems and Solutions
| Symptom | Likely Cause | How to Fix |
|---|---|---|
chronyc sources shows all sources as ? |
Cannot reach NTP servers: network issue or firewall blocking UDP port 123 | Check network connectivity, open UDP port 123 in firewalld |
System clock synchronized: no in timedatectl |
chronyd is running but hasn't achieved synchronization yet, or no reachable sources | Wait a few minutes after starting chronyd, then run chronyc makestep |
| Clock drifts significantly between reboots | Drift file not being written or hardware clock issues | Verify driftfile path in /etc/chrony.conf is writable |
| Large initial offset warning in journal | Clock was significantly wrong at startup | makestep 1.0 3 in config handles this on startup. Run chronyc makestep manually for immediate correction. |
| Kerberos authentication failures | Clock skew between client and server exceeds 5 minutes | Force immediate sync with chronyc makestep and verify both client and server use the same NTP source |
NTP service: inactive in timedatectl |
chronyd is not running | systemctl start chronyd and systemctl enable chronyd |
Firewall Configuration for NTP
# NTP uses UDP port 123
# If this system needs to reach external NTP servers, the outbound port must be open
# If this system acts as an NTP server for other hosts, the inbound port must be open
# Allow NTP through firewalld
firewall-cmd --permanent --add-service=ntp
firewall-cmd --reload
# Verify NTP is allowed
firewall-cmd --list-services
Configuring Chrony as an NTP Server
A single host with internet access can synchronize from upstream NTP servers and serve time to other hosts on the local network. This is useful in environments where internal hosts cannot reach the internet directly.
# Add to /etc/chrony.conf on the server that will serve time locally
# Synchronize from upstream sources
pool 2.rhel.pool.ntp.org iburst
# Allow hosts on the local network to synchronize from this server
allow 192.168.1.0/24
# On client machines, point to the local NTP server
# server 192.168.1.10 iburst
Quick Reference: chronyc Commands
| Command | What It Shows | When to Use |
|---|---|---|
chronyc sources |
All configured NTP sources, their status, reachability, and offset | First check when verifying synchronization is working |
chronyc sources -v |
Same as above with column header explanations | When you need to understand what each column means |
chronyc sourcestats |
Statistical information about each NTP source including frequency drift and standard deviation | When assessing the quality of time sources |
chronyc tracking |
Current reference clock, system time offset, frequency error, and synchronization quality | Detailed view of how well the clock is synchronized right now |
chronyc activity |
Count of sources that are online, offline, or unreachable | Quick check of how many sources are reachable |
chronyc makestep |
Forces an immediate step correction of the system clock | When the clock is significantly wrong and needs immediate correction |
Chrony and the RHCSA Exam
Time synchronization with Chrony is a direct RHCSA exam objective. Exam tasks in this area typically require:
- Configuring a specific NTP server or pool in
/etc/chrony.conf - Ensuring
chronydis running and enabled to start at boot - Verifying synchronization is active using
chronyc sourcesandtimedatectl - Setting the correct system timezone using
timedatectl set-timezone - The configuration must survive a reboot: both
enableand correct/etc/chrony.confare required
The most common exam failure pattern: editing /etc/chrony.conf but forgetting to restart chronyd afterward, or starting the service but not enabling it. The exam verifies the result after a reboot, so both steps are always required.
Practice This in a Real Environment
Time synchronization is one of those topics where hands-on practice matters more than reading. The chronyc sources output looks different from what you expect until you have seen it on a working system and on a broken one. The difference between a * and a ? next to a source becomes immediately clear the first time you have to diagnose a synchronization problem.
LinuxCert.Guru has a dedicated hands-on lab for this topic: Time Synchronization with Chrony. It covers NTP source configuration, service management, chronyc verification commands, timezone configuration, and troubleshooting on real RHEL hosts with auto-graded tasks.
Practice the Time Synchronization with Chrony lab at LinuxCert.Guru → https://linuxcert.guru/?name=rh134-time-sync-chrony
Conclusion
Chrony is the default and recommended NTP implementation on RHEL, and configuring it correctly is both a practical production skill and an RHCSA exam objective. The workflow is straightforward once you know the right sequence:
- Configure your NTP sources in
/etc/chrony.confusingserverorpooldirectives withiburst - Restart
chronydafter editing the configuration:systemctl restart chronyd - Enable
chronydat boot:systemctl enable chronyd - Verify sources are reachable:
chronyc sourcesshould show*next to the selected source - Confirm synchronization:
chronyc trackingshows the current offset and reference - Check system-wide status:
timedatectlshould show both NTP service active and system clock synchronized - Set the correct timezone:
timedatectl set-timezone Region/City - For immediate correction of a badly drifted clock:
chronyc makestep