Affected versions: CentOS Stream 10

📖 ~1 min read

Table of contents
  1. Symptom & Impact
  2. Environment & Reproduction
  3. Root Cause Analysis
  4. Quick Triage
  5. Step-by-Step Diagnosis
  6. Solution – Primary Fix
  7. Solution – Alternative Approaches
  8. Verification & Acceptance Criteria
  9. Rollback Plan
  10. Prevention & Hardening
  11. Related Errors & Cross-Refs
  12. References & Further Reading

Symptom & Impact

System clock drifts beyond tolerance and Kerberos or TLS fails.

Environment & Reproduction

Occurs in VMs after pause/resume or with blocked NTP egress.

Root Cause Analysis

chronyd cannot reach upstream sources or pool is misconfigured.

Quick Triage

Run chronyc tracking and sources -v to inspect peers.

Step-by-Step Diagnosis

Inspect /var/log/chrony and chronyd journal logs.

Illustrative mockup for centos-stream-10 — chrony_drift_diag
Diagnostic view for chrony-time-drift — Illustrative mockup — Progressive Robot

Solution – Primary Fix

Adjust pool/server lines, allow UDP 123 outbound, and step time with chronyc makestep.

Still having issues? Our IT Solutions & Services team can diagnose and resolve this for you. Get in touch for a free consultation.

Illustrative mockup for centos-stream-10 — chrony_drift_fix
Remediation steps for chrony-time-drift — Illustrative mockup — Progressive Robot

Solution – Alternative Approaches

Switch to systemd-timesyncd in minimal containers as a fallback.

Verification & Acceptance Criteria

chronyc tracking reports offset under 50ms steady state.

Rollback Plan

Restore previous chrony.conf and step backwards if applications break.

Prevention & Hardening

Monitor offset and stratum continuously via node_exporter.

Linked to firewalld ntp service and PTP setups.

Related tutorial: View the step-by-step tutorial for centos-stream-10.

View all centos-stream-10 tutorials on the Tutorials Hub →

Browse all common problems & solutions on the Tutorials Hub.

References & Further Reading

chrony manual and Red Hat time synchronization guide.

Need Expert Help?

If you cannot resolve this yourself, our team offers hands-on Server Management, Managed IT Services, and flexible Support Plans. Contact us today — we respond within one business day.