<imgsrc="pic/flatheads.gif"alt="gif"align="left"><ahref="http://www.eecis.udel.edu/~mills/pictures.html">from <i>Alice's Adventures in Wonderland</i>, Lewis Carroll</a>
<p>You have come here because you found a cryptic message in the system log. This page by no means lists all messages that might be found, since new ones come and old ones go. Generally, however, the most common ones will be found here. They are listed by program module and log severity code in bold: <tt><b>LOG_ERR</b></tt>, <b><tt>LOG_NOTICE</tt></b> and <tt><b>LOG_INFO</b></tt>.</p>
<p>Most of the time <b><tt>LOG_ERR</tt></b> messages are fatal, but often <tt>ntpd</tt> limps onward in the hopes of discovering more errors. The <tt><b>LOG_NOTICE</b></tt> messages usually mean the time has changed or some other condition that probably should be noticed. The <tt><b>LOG_INFO</b></tt> messages usually say something about the system operations, but do not affect the time.</p>
<p>In the following a '?' character stands for text in the message. The meaning should be clear from context.</p>
<h4>Protocol Module</h4>
<p><tt><b>LOG_ERR</b></tt></p>
<dl>
<dt><tt>buffer overflow ? </tt></dt>
<dd>Fatal error. An input packet is too long for processing.</dd>
</dl>
<p><tt><b>LOG_NOTICE</b></tt></p>
<dl>
<dt><tt>no reply; clock not set</tt></dt>
<dd>In <tt>ntpdate</tt> mode no servers have been found. The server(s) and/or network may be down. Standard debugging procedures apply.</dd>
</dl>
<p><tt><b>LOG_INFO</b></tt></p>
<dl>
<dt><tt>proto_config: illegal item ?, value ?</tt></dt>
<dd>Program error. Bugs can be reported <ahref="bugs.html">here</a>.</dd>
<dd>Configuration error on the <tt>broadcastclient</tt> command.</dd>
<dt><tt>receive: server <i>server</i> maaximum rate exceeded</tt></dt>
<dd>A kiss-o'death packet has been received. The transmit rate is automatically reduced.</dd>
<dt><tt>pps sync enabled</tt></dt>
<dd>The PPS signal has been detected and enabled.</dd>
<dt><tt>transmit: encryption key ? not found</tt></dt>
<dd>The encryption key is not defined or not trusted.</dd>
<dt><tt>precision = ? usec </tt></dt>
<dd>This reports the precision measured for this machine.</dd>
<dt><tt>using 10ms tick adjustments</tt></dt>
<dd>Gotcha for some machines with dirty rotten clock hardware.</dd>
<dt><tt>no servers reachable</tt></dt>
<dd>The system clock is running on internal batteries. The server(s) and/or network may be down.</dd>
</dl>
<h4>Clock Discipline Module</h4>
<p><tt><b>LOG_ERR</b></tt></p>
<dl>
<dt><tt>time correction of ? seconds exceeds sanity limit (?); set clock manually to the correct UTC time</tt>.</dt>
<dd>Fatal error. Better do what it says, then restart the daemon. Be advised NTP and Unix know nothing about local time zones. The clock must be set to Coordinated Universal Time (UTC). Believe it; by international agreement abbreviations are in French and descriptions are in English.</dd>
<dt><tt>sigaction() fails to save SIGSYS trap: ?<br>
</tt><tt>sigaction() fails to restore SIGSYS trap: ?</tt></dt>
<dt>Program error. Bugs can be reported <ahref="bugs.html">here</a>.</dt>
<dd>The hardware clock frequency error exceeds the rate the kernel can correct. This could be a hardware or a kernel problem.</dd>
<dt><tt>time slew ? s</tt></dt>
<dd>The time error exceeds the step threshold and is being slewed to the correct time. You may have to wait a very long time.</dd>
<dt><tt>time reset ? s</tt></dt>
<dd>The time error exceeds the step threshold and has been reset to the correct time. Computer scientists don't like this, but they can set the <tt>ntpd -x</tt> option and wait forever.</dd>
<dt><tt>kernel time sync disabled ?</tt></dt>
<dd>The kernel reports an error. See the codes in the <tt>timex.h</tt> file.</dd>
<dt><tt>pps sync disabled</tt></dt>
<dd>The PPS signal has died, probably due to a dead radio, broken wire or loose connector.</dd>
</dl>
<p><tt><b>LOG_INFO</b></tt></p>
<dl>
<dt><tt>kernel time sync status ? </tt></dt>
<dd>For information only. See the codes in the <tt>timex.h</tt> file.</dd>
</dl>
<h4>Cryptographic Module</h4>
<p><tt><b>LOG_ERR</b></tt></p>
<dl>
<dt><tt>cert_parse ?<br>
</tt><tt>cert_sign ?<br>
</tt><tt>crypto_cert ?<br>
</tt><tt>crypto_encrypt ?<br>
</tt><tt>crypto_gq ?<br>
</tt><tt>crypto_iff ?<br>
</tt><tt>crypto_key ?<br>
</tt><tt>crypto_mv ?<br>
</tt><tt>crypto_setup ?<br>
</tt><tt>make_keys ?</tt></dt>
<dd>Usually fatal errors. These messages display error codes returned from the OpenSSL library. See the OpenSSL documentation for explanation.</dd>
<dt><tt>crypto_setup: certificate ? is trusted, but not self signed.<br>
</tt><tt>crypto_setup: certificate ? not for this host<br>
</tt><tt>crypto_setup: certificate file ? not found or corrupt<br>
</tt><tt>crypto_setup: host key file ? not found or corrupt<br>
</tt><tt>crypto_setup: host key is not RSA key type<br>
</tt><tt>crypto_setup: random seed file ? not found<br>
</tt><tt>rypto_setup: random seed file not specified</tt></dt>
<dd>Fatal errors. These messages show problems during the initialization procedure.</dd>
</dl>
<p><tt><b>LOG_INFO</b></tt></p>
<dl>
<dt><tt>cert_parse: expired ?<br>
</tt><tt>cert_parse: invalid issuer ?<br>
</tt><tt>cert_parse: invalid signature ?<br>
</tt><tt>cert_parse: invalid subject ?</tt></dt>
<dd>There is a problem with a certificate. Operation cannot proceed untill the problem is fixed. If the certificate is local, it can be regenerated using the <tt>ntp-keygen</tt> program. If it is held somewhere else, it must be fixed by the holder.</dd>
<dt><tt>crypto_?: defective key<br>
</tt><tt>crypto_?: invalid filestamp<br>
</tt><tt>crypto_?: missing challenge<br>
</tt><tt>crypto_?: scheme unavailable</tt></dt>
<dd>There is a problem with the identity scheme. Operation cannot proceed untill the problem is fixed. Usually errors are due to misconfiguration or an orphan association. If the latter, <tt>ntpd</tt> will usually time out and recover by itself.</dd>
<dt><tt>crypto_cert: wrong PEM type ?</tt></dt>
<dd>The certificate does not have MIME type <tt>CERTIFICATE</tt>. You are probably using the wrong type from OpenSSL or an external certificate authority.</dd>
<dt><tt>crypto_ident: no compatible identity scheme found</tt></dt>
<dd>Configuration error. The server and client identity schemes are incompatible.</dd>
<dt><tt>crypto_tai: kernel TAI update failed</tt></dt>
<dd>The kernel does not support this function. You may need a new kernel or patch.</dd>