11     # when supported, initstepslew may have to be replaced by:
 
  12     # waitsync 60 0.01 100 1
 
  13     # See https://chrony-project.org/doc/4.7/chrony.conf.html
 
  18     enableRTCTrimming = true;
 
  19     servers = config.networking.timeServers;
 
  20     serverOption = lib.mkDefault "iburst";
 
  24       maxdistance 10000000000000
 
  27   systemd.services.chronyd = {
 
  28     # ExplanationNote: disable DNSSEC in systemd-resolved
 
  29     # to resolve NTP server names.
 
  30     environment.SYSTEMD_NSS_RESOLVE_VALIDATE = "0";
 
  32   networking.nftables.ruleset = ''
 
  35         udp dport ntp skuid ${toString config.users.users.chrony.name} counter accept comment "chrony: NTP"