Linux
chrony — Debian, Ubuntu, AlmaLinux, Rocky, RHEL, Fedora
The configuration file is /etc/chrony/chrony.conf on Debian/Ubuntu and /etc/chrony.conf on the RHEL family. Add this next to the existing pool / server lines:
server time.nerzen.com iburst
sudo systemctl restart chrony # on the RHEL family: chronyd
chronyc sources -v
chronyc trackingWith NTS — recommended
chrony 4.0 and later supports NTS (Ubuntu 22.04+, Debian 11+, RHEL 9+). The only difference is the word nts at the end of the line:
server time.nerzen.com iburst nts ntsdumpdir /var/lib/chrony
systemd-timesyncd
The default on lightweight installations and on Raspberry Pi OS. It does not support NTS.
[Time] NTP=time.nerzen.com
sudo systemctl restart systemd-timesyncd timedatectl timesync-status
ntpd / NTPsec
server time.nerzen.com iburst # NTS with NTPsec: # server time.nerzen.com iburst nts
Windows
Single computer — Command Prompt as administrator
w32tm /config /syncfromflags:manual /manualpeerlist:"time.nerzen.com,0x8" w32tm /config /update w32tm /resync w32tm /query /status
Domain controller — PDC emulator
Computers in a domain take their time from the PDC emulator; configure the external source on that server only.
w32tm /config /manualpeerlist:"time.nerzen.com,0x8" /syncfromflags:manual /reliable:yes /update net stop w32time && net start w32time w32tm /resync /rediscover
macOS
sudo systemsetup -setnetworktimeserver time.nerzen.com sudo systemsetup -setusingnetworktime on
From the interface: System Settings → General → Date & Time → Source → time.nerzen.com.
Network devices
MikroTik RouterOS 7
/system ntp client set enabled=yes /system ntp client servers add address=time.nerzen.com
MikroTik RouterOS 6
/system ntp client set enabled=yes server-dns-names=time.nerzen.com
Cisco IOS / IOS-XE
configure terminal ntp server time.nerzen.com end show ntp associations
Juniper Junos
set system ntp server 141.98.50.237 commit show ntp associations
Junos resolves the hostname only at commit time, so entering an IP address is more predictable here. For IPv6, use 2a0f:bf01:0:1::3.
pfSense / OPNsense
Add time.nerzen.com under Services → NTP → Time Servers and save.
OpenWrt
uci delete system.ntp.server uci add_list system.ntp.server='time.nerzen.com' uci commit system /etc/init.d/sysntpd restart
Virtualisation and storage
VMware ESXi
Host → Manage → System → Time & date → Edit NTP settings → time.nerzen.com, with the service startup policy set to "Start and stop with host". From the command line (7.0 U1+):
esxcli system ntp set -s time.nerzen.com -e true
Proxmox VE
Proxmox VE 7 and later uses chrony; add the chrony line above to /etc/chrony/chrony.conf and run systemctl restart chrony.
KVM / libvirt guests and VPSs
A guest does not follow the host's clock automatically; run chrony or timesyncd inside the guest. VPSs on the Nerzen network get the best results because they are in the same data centre as the server.
Synology DSM
Control Panel → Regional Options → Time → "Synchronize with NTP server" → time.nerzen.com.
QNAP QTS
Control Panel → System → General Settings → Time → "Synchronize with an Internet time server automatically" → time.nerzen.com.
Docker · Podman · LXC · Kubernetes
Containers share the host's kernel clock; do not run NTP inside a container. Configuring the host (or the nodes) is enough.
NTS — authenticated time
Plain NTP responses are unsigned; someone on the path can alter a response and shift your clock. NTS (Network Time Security, RFC 8915) first performs a key exchange over TLS (4460/tcp), then authenticates every NTP response with those keys. The content is not hidden, but it is proven that the response really came from us and was not changed in transit.
Verifying that it works
chronyc -N authdata
# You should see NTS in the Mode column and values greater than zero in the KeyID and Cook columnsConfigure more than one server
A client that depends on a single time server cannot tell when that server is wrong. On production systems, add at least two, preferably three, other independent sources you trust alongside time.nerzen.com; your client will automatically discard whichever one disagrees with the majority.