STIGhubSTIGhub
STIGhub— A free STIG search and compliance tool·STIGs updated 3 hours ago
Powered by Pylon·Privacy·Terms·Feedback·© 2026 Beacon Cloud Solutions, Inc.
← Back to Rancher Government Solutions (RGS) Harvester Government CTR Security Technical Implementation Guide

V-285758

CAT II (Medium)

Harvester Government platform must use internal system clocks to generate audit record time stamps.

Rule ID

SV-285758r1272711_rule

STIG

Rancher Government Solutions (RGS) Harvester Government CTR Security Technical Implementation Guide

Version

V1R1

CCIs

CCI-000159CCI-004922

Discussion

Understanding when the sequence of events for an incident occurred is crucial to understand what may have taken place. Without a common clock, the components generating audit events could be out of synchronization and would then present an incorrect account of the event. To give a clear picture, it is important that Harvester Government platform and its components use a common internal clock. Satisfies: SRG-APP-000116-CTR-000235, SRG-APP-000920-CTR-000320

Check Content

Verify the Harvester Government cluster is configured to use approved and reachable Network Time Protocol (NTP) servers.

1. Access the Harvester management console with appropriate administrative privileges by navigating to Advanced >> Settings.

2. Locate the ntp-servers configuration parameter.

3. Review the configured NTP server entries.

4. Validate connectivity from a Harvester node using a command like "cat /etc/systemd/timesyncd.conf".

If one or more of the following conditions exist, this is a finding:
- No NTP servers are configured.
- Configured NTP servers are not organization approved.
- Configured NTP servers are invalid, unreachable, or nonroutable from cluster nodes.
- The system is not synchronizing time with the configured NTP sources.

Fix Text

Configure the Harvester Government to use approved and reachable NTP servers.

1. Access the Harvester management console with administrative privileges by navigating to Advanced >> Settings.

2. Locate the ntp-servers parameter.

3. Click the ellipses (...) on the right and select "Edit Settings".

4. Configure the parameter with one or more organization-approved NTP servers (e.g., enterprise or authoritative time sources).

5. Save the configuration changes.