# NTP Support SHA2 or not

**URL:** <https://community.ntppool.org/t/ntp-support-sha2-or-not/913>\
**Category:** Client Configuration and Development\
**Created:** [September 29, 2018, 8:48pm UTC](https://community.ntppool.org/t/ntp-support-sha2-or-not/913 "2018-09-29T20:48:36Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![sachin](https://avatars.discourse-cdn.com/v4/letter/s/c77e96/32.png) [@sachin](https://community.ntppool.org/u/sachin)\
**Post date:** [September 29, 2018, 8:48pm UTC](https://community.ntppool.org/t/ntp-support-sha2-or-not/913/1 "2018-09-29T20:48:36Z")

</div>

Hi,

We are using ntp-4.2.6p5-28.el7, Please let us know whether the NTP support SHA2 with FIPS enable and disable?

Regards

---

<div class="post-metadata">

**Author:** ![littlejason99](https://sea2.discourse-cdn.com/flex016/user_avatar/community.ntppool.org/littlejason99/32/242_2.png) [@littlejason99](https://community.ntppool.org/u/littlejason99)\
**Post date:** [September 30, 2018, 9:31pm UTC](https://community.ntppool.org/t/ntp-support-sha2-or-not/913/2 "2018-09-30T21:31:19Z")

</div>

You probably want to post on the regular NTP questions list… This is for the NTP “pool” and related…

[http://lists.ntp.org/listinfo/questions](http://lists.ntp.org/listinfo/questions)

^^^ That is the main NTP questions…

---

<div class="post-metadata">

**Author:** ![sachin](https://avatars.discourse-cdn.com/v4/letter/s/c77e96/32.png) [@sachin](https://community.ntppool.org/u/sachin)\
**Post date:** [October 1, 2018, 12:28pm UTC](https://community.ntppool.org/t/ntp-support-sha2-or-not/913/3 "2018-10-01T12:28:03Z")

</div>

Hi,

How to raise query on above link which you provided?

Regards  
Sachin

---

<div class="post-metadata">

**Author:** ![erayd](https://sea2.discourse-cdn.com/flex016/user_avatar/community.ntppool.org/erayd/32/85_2.png) [@erayd](https://community.ntppool.org/u/erayd)\
**Post date:** [October 4, 2018, 1:44am UTC](https://community.ntppool.org/t/ntp-support-sha2-or-not/913/4 "2018-10-04T01:44:50Z")

</div>

The archives are available publicly [here](http://lists.ntp.org/pipermail/questions/). If you can’t find a previous thread which answers your question, then you can simply email your question to the list (note you will need to [join it first](http://lists.ntp.org/listinfo/questions)).

---

<div class="post-metadata">

**Author:** ![sachin](https://avatars.discourse-cdn.com/v4/letter/s/c77e96/32.png) [@sachin](https://community.ntppool.org/u/sachin)\
**Post date:** [October 9, 2018, 9:10am UTC](https://community.ntppool.org/t/ntp-support-sha2-or-not/913/5 "2018-10-09T09:10:31Z")

</div>

I already checked this, but didnt find any answer relevant answer yet.

Regards  
Sachin

---

<div class="post-metadata">

**Author:** ![littlejason99](https://sea2.discourse-cdn.com/flex016/user_avatar/community.ntppool.org/littlejason99/32/242_2.png) [@littlejason99](https://community.ntppool.org/u/littlejason99)\
**Post date:** [October 9, 2018, 2:28pm UTC](https://community.ntppool.org/t/ntp-support-sha2-or-not/913/6 "2018-10-09T14:28:02Z")

</div>

I would look at the man page of ntp-keygen on your system as it specifically shows what encryption is supported.

Or…

> **[ntp-keygen - generate public and private keys](http://doc.ntp.org/documentation/4.2.2-series/keygen/)**
>
> from Alice’s Adventures in Wonderland, Lewis Carroll
> Alice holds the key.
> Table of Contents Synopsis Description Running the program Trusted Hosts and Groups Identity Schemes Command Line Options Random Seed File Cryptographic Data Files Bugs ...

Relevant part:

> When used to generate message digest keys, the program produces a file containing ten pseudo-random printable ASCII strings suitable for the MD5 message digest algorithm included in the distribution. If the OpenSSL library is installed, it produces an additional ten hex-encoded random bit strings suitable for the SHA1 and other message digest algorithms. Printable ASCII keys can have length from one to 20 characters, inclusive. Bit string keys have length 20 octets (40 hex characters). All keys are 160 bits in length.
> 
> The file can be edited later with purpose-chosen passwords for the ntpq and ntpdc programs. Each line of the file contains three fields, first an integer between 1 and 65534, inclusive, representing the key identifier used in the server and peer configuration commands. Next is the key type for the message digest algorithm, which in the absence of the OpenSSL library should be the string MD5 to designate the MD5 message digest algorithm. If the OpenSSL library is installed, the key type can be any message digest algorithm supported by that library. However, if compatibility with FIPS 140-2 is required, the key type must be either SHA or SHA1.Finally is the key itself as a printable ASCII string excluding the space and # characters. If not greater than 20 characters in length, the string is the key itself; otherwise, it is interpreted as a hex-encoded bit string. As is custom, # and the remaining characters on the line are ignored. Later, this file can be edited to include the passwords for the ntpq and ntpdc utilities. If this is the only need, run ntp-keygen with the -M option and disregard the remainder of this page.

So my interpretation of that is no, NTP does not support SHA2, because the max support is 160 bits and the smallest SHA2 is 224 bits.

---

<div class="post-metadata">

**Author:** ![sachin](https://avatars.discourse-cdn.com/v4/letter/s/c77e96/32.png) [@sachin](https://community.ntppool.org/u/sachin)\
**Post date:** [October 15, 2018, 6:48am UTC](https://community.ntppool.org/t/ntp-support-sha2-or-not/913/7 "2018-10-15T06:48:41Z")

</div>

ok, thanks for information 🙂
