## ## THIS FILE IS UNDER PUPPET CONTROL. DON'T EDIT IT HERE. ## USE: git clone git+ssh://$USER@puppet.debian.org/srv/puppet.debian.org/git/dsa-puppet.git ## driftfile /var/lib/ntp/ntp.drift statsdir /var/log/ntpstats/ statistics loopstats peerstats clockstats cryptostats filegen loopstats file loopstats type day enable filegen peerstats file peerstats type day enable filegen clockstats file clockstats type day enable filegen cryptostats file cryptostats type day enable crypto randfile /dev/urandom keysdir /etc/ntp.keys.d <% if scope.lookupvar('site::nodeinfo')['timeserver'] -%> server 0.debian.pool.ntp.org iburst dynamic server 1.debian.pool.ntp.org iburst dynamic server 2.debian.pool.ntp.org iburst dynamic server 3.debian.pool.ntp.org iburst dynamic <% if @lsbmajdistrelease >= '8' -%> leapfile /usr/share/zoneinfo/leap-seconds.list <% else -%> leapfile /var/lib/ntp/leap-seconds.list <% end -%> <% elsif scope.lookupvar('site::nodeinfo')['misc']['natted'] -%> # autokey doesn't work behind nat # czerny's, bm-bl2's, and dijkstra's ipv4 IP, hard coded for the benefit of # hosts that do not have RTC's (since they won't be able to do DNS until # they have a reasonable clock). server 82.195.75.109 iburst server 5.153.231.242 iburst server 206.12.19.218 iburst server czerny.debian.org iburst server clementi.debian.org iburst server bm-bl1.debian.org iburst server bm-bl2.debian.org iburst server dijkstra.debian.org iburst server luchesi.debian.org iburst <% else -%> server czerny.debian.org iburst autokey server clementi.debian.org iburst autokey server bm-bl1.debian.org iburst autokey server bm-bl2.debian.org iburst autokey server dijkstra.debian.org iburst autokey server luchesi.debian.org iburst autokey restrict czerny.debian.org notrust nomodify notrap ntpport restrict clementi.debian.org notrust nomodify notrap ntpport restrict bm-bl1.debian.org notrust nomodify notrap ntpport restrict bm-bl2.debian.org notrust nomodify notrap ntpport restrict dijkstra.debian.org notrust nomodify notrap ntpport restrict luchesi.debian.org notrust nomodify notrap ntpport <% end -%> restrict -4 default kod notrap nomodify nopeer noquery restrict -6 default kod notrap nomodify nopeer noquery restrict 127.0.0.1 restrict ::1 # vim:set et: # vim:set sts=4 ts=4: # vim:set shiftwidth=4: