11 # when supported, initstepslew may have to be replaced by:
12 # waitsync 60 0.01 100 1
13 # See https://chrony-project.org/doc/4.7/chrony.conf.html
18 enableRTCTrimming = true;
19 servers = config.networking.timeServers;
20 serverOption = lib.mkDefault "iburst";
24 maxdistance 10000000000000
27 systemd.services.chronyd = {
28 # ExplanationNote: disable DNSSEC in systemd-resolved
29 # to resolve NTP server names.
30 environment.SYSTEMD_NSS_RESOLVE_VALIDATE = "0";
32 networking.nftables.ruleset = ''
35 udp dport ntp skuid ${toString config.users.users.chrony.name} counter accept comment "chrony: NTP"