X-Git-Url: https://git.adam-barratt.org.uk/?a=blobdiff_plain;f=modules%2Fntp%2Ftemplates%2Fntp.conf;h=406d2f6d4387ac7331b2c6a1b413ecf7b8e66553;hb=24d8633d73a566d1b6f50c75c1aa82222d22231d;hp=8cc742a613c5c45b012ccc7ceda5b9f8680e238c;hpb=adeba5f271ffdf3638fa4ec3a7ae025dca24a0e8;p=mirror%2Fdsa-puppet.git diff --git a/modules/ntp/templates/ntp.conf b/modules/ntp/templates/ntp.conf index 8cc742a61..406d2f6d4 100644 --- a/modules/ntp/templates/ntp.conf +++ b/modules/ntp/templates/ntp.conf @@ -21,42 +21,29 @@ server 1.debian.pool.ntp.org iburst dynamic server 2.debian.pool.ntp.org iburst dynamic server 3.debian.pool.ntp.org iburst dynamic -leapfile /var/lib/ntp/leap-seconds.list -<% if fqdn == "orff.debian.org" -%> -server ntp.grnet.gr iburst dynamic -server chronos.duth.gr iburst -<% end -%> -<% elsif fqdn == "ancina.debian.org" -%> -server ntp.ugent.be iburst dynamic +leapfile /usr/share/zoneinfo/leap-seconds.list <% elsif scope.lookupvar('site::nodeinfo')['misc']['natted'] -%> # autokey doesn't work behind nat -# czerny's, bm-bl2's, and dijkstra's ipv4 IP, hard coded for the benefit of +# czerny's, and bm-bl2's ipv4 IP, hard coded for the benefit of # hosts that do not have RTC's (since they won't be able to do DNS until # they have a reasonable clock). server 82.195.75.109 iburst server 5.153.231.242 iburst -server 206.12.19.218 iburst server czerny.debian.org iburst server clementi.debian.org iburst server bm-bl1.debian.org iburst server bm-bl2.debian.org iburst -server dijkstra.debian.org iburst -server luchesi.debian.org iburst <% else -%> server czerny.debian.org iburst autokey server clementi.debian.org iburst autokey server bm-bl1.debian.org iburst autokey server bm-bl2.debian.org iburst autokey -server dijkstra.debian.org iburst autokey -server luchesi.debian.org iburst autokey restrict czerny.debian.org notrust nomodify notrap ntpport restrict clementi.debian.org notrust nomodify notrap ntpport restrict bm-bl1.debian.org notrust nomodify notrap ntpport restrict bm-bl2.debian.org notrust nomodify notrap ntpport -restrict dijkstra.debian.org notrust nomodify notrap ntpport -restrict luchesi.debian.org notrust nomodify notrap ntpport <% end -%> restrict -4 default kod notrap nomodify nopeer noquery