Summary
- NTP's Kiss-o'-Death response carried no usable time: stratum zero invalidated the sample while a four-character Reference Identifier explained refusal, restriction, rate pressure or transient state.
- The mechanism was advice inside a client-server relationship, not remote enforcement. A valid outstanding-request match, cautious local limits and actual client cooperation mattered; unauthenticated KoD could itself become a denial-of-service tool.
In the history of Internet protocols, success is often shown by a useful answer: an address returned, a route selected, a clock corrected. Kiss-o'-Death began with the opposite event. The server answered, but the answer was not time.
That distinction was designed into two small fields. An NTP packet already carried an eight-bit Stratum value and a four-octet Reference Identifier. In RFC 1305, published in 1992, stratum zero was “unspecified”; for strata zero and one, the Reference Identifier could be rendered as four ASCII characters. RFC 2030, the 1996 SNTP version 4 specification, retained the shape. Neither document yet gave a stratum-zero reply the later vocabulary of refusal and pressure.
The fields existed before the instruction. That is important. A packet layout can reserve space without deciding what power its contents will have. KoD emerged only when operational experience supplied a reason and later specifications supplied a state machine.
A default became somebody else's permanent workload
RFC 4330 records the incident that made the missing behavior hard to ignore. Large numbers of home and office routers had been configured to use one university time server. Some sent a packet every second. As the installed population grew, the traffic increase became dramatic, and the server operator was driven to extreme defensive measures.
The failure was not just an aggressive timer. It was a distribution of authority without a matching distribution of cost. A manufacturer chose a default once. Every device then repeated that choice for its operating life. The server operator had no relationship with each owner and no practical way to edit the embedded clients. A tiny configuration decision upstream became a durable claim on someone else's capacity.
Dropping packets could protect the server, but it could not tell a well-behaved client whether the loss meant congestion, refusal or an instruction to slow down. RFC 4330 therefore assigned semantics to the formerly unspecified case. A response with stratum zero and a four-character Reference Identifier became a Kiss-o'-Death packet. The code could say that access was denied, restricted by policy, limited by rate or temporarily unavailable while the server initialized or stepped its clock.
This did not make the server a central scheduler. It created a narrow language for one endpoint to describe its side of one relationship.
The packet deliberately withheld the measurement
The design can be misunderstood if KoD is treated as a low-quality time sample. It is not. RFC 5905 makes a stratum-zero packet invalid for synchronization and interprets its Reference Identifier as a kiss code. Its receive and transmit timestamps are undefined and must be discarded. A client cannot calculate a meaningful offset or delay from the reply and then merely lower its confidence.
The packet changes categories. Ordinary NTP data says, in effect, “here is evidence from which you may estimate time.” KoD says, “do not use this as time; interpret the relationship state instead.” The familiar envelope survives so the response can travel through the existing exchange, but the evidentiary purpose is different.
That separation narrows the server's claim. A RATE response does not tell the client what UTC is. A DENY response does not prove that the policy is fair. A four-character code does not certify the sender's identity. Each code names a requested local transition, and the client remains responsible for deciding whether the packet has standing.
One corrected verb decided whether pressure rose or fell
The three most consequential codes are short enough to look self-explanatory. Their state changes are not interchangeable.
DENY and RSTR mean that the association should be demobilized and the client should stop sending to that server. A client with alternatives can select another source. RATE means that a threshold has been crossed and the client should ask less often.
The published text of RFC 5905 contained a dangerous directional error: it said a RATE response should reduce the polling interval. A shorter interval means more frequent packets, precisely the wrong reaction to rate pressure. Verified Errata ID 3007 corrects the instruction to increase the polling interval.
The erratum is more than editorial housekeeping. It shows why protocol meaning must be tested against the causal mechanism. The label RATE, the packet format and the registry entry could all be correct while one verb in client logic turned feedback into amplification. Running behavior, not the apparent authority of a published sentence, decides whether load falls.
A reply needed a live question
A client must not obey every stratum-zero packet that arrives. RFC 8633, the NTP Best Current Practice, requires a valid Origin Timestamp before a KoD is accepted. In an NTP reply, that value corresponds to the transmit timestamp of the client's request. The check ties the response to an exchange the client actually has outstanding.
That is transactional relevance, not complete authentication. If a packet matches no current request, it has no standing and can be discarded. If it does match, it may still have been forged when the exchange is unprotected. An observer that learns suitable request material, or an attacker with the necessary position and timing, can attempt to manufacture a plausible refusal.
The distinction matters for records and incident reports. “Received KoD” says only that bytes arrived. “Matched outstanding request” says the reply belonged to current client state. “Authenticated server response” is a stronger claim. “Client demobilized the association” is an observed effect. Collapsing these into one event gives a four-character string more authority than the protocol earned.
Cooperation was the control surface—and the weakness
KoD can reduce traffic only through client cooperation. A correct client validates the reply, distinguishes permanent refusal from rate pressure, changes its poll state and emits fewer packets. A broken client can ignore the response. A worse implementation can follow the uncorrected RATE direction and send faster.
The server cannot force remote firmware to execute a branch. RFC 8633 therefore warns that implementations may ignore or mishandle KoD and says a server needs defenses outside the exchange, including dropping packets. Rate filters, queue protection and capacity limits remain necessary because feedback is not enforcement.
Even a cooperative client needs a local boundary. If it blindly accepts an arbitrarily large poll value suggested by a server, a forged or faulty reply can silence queries for an excessive period. RFC 8633 discusses a reasonable upper bound no greater than poll exponent 13—about two hours. The exact local policy may differ, but the constitutional point is stable: the server can report pressure; it does not receive an unlimited lease over the client's future schedule.
This also explains why a spoofed KoD can cause denial of service without ever lying about the time. A forged DENY or RSTR removes a useful source. A forged RATE delays the next opportunity to collect evidence. The attacker acts on the client's search for time, not necessarily on its clock value.
NTS needed an escape from stale security state
Network Time Security adds cryptographic protection, but it also creates a recovery problem. If a server can no longer validate the client's cookies or authenticator material, it cannot produce the ordinary protected response that would explain the failure. RFC 8915 defines a special kiss code, NTSN, for that condition.
The exception is deliberately narrow. The server should send NTSN and must omit the normal NTS Cookie and NTS Authenticator and Encrypted Extension Fields. A client that previously received authentic responses from that server requires a Unique Identifier matching an outstanding request. It does not instantly discard all old state and begin an unbounded handshake loop.
Instead, the client waits until the next normal polling opportunity. If no valid protected response arrives, it re-runs NTS key establishment, rate-limits retries and continues using its old polling parameters until the new exchange succeeds. The signal is unauthenticated because the failure prevents normal authentication, but its correlation and consequences are tightly scoped.
NTSN therefore does not prove that every KoD became secure. It demonstrates a more useful design discipline: when recovery must cross an authentication failure, narrow the unauthenticated message, correlate it to live state and delay expensive action until ordinary evidence remains unavailable.
A registry names possibilities, not obedience
Four characters create a small commons. Without coordination, two specifications could assign the same code to different transitions. RFC 5905 created an IANA registry, and RFC 9748 later tightened its governance. Current codes use up to four ASCII characters, shorter values are padded with zero octets, names beginning with X are reserved for experimentation, and new assignments use uppercase letters and digits under Specification Required review.
The registry makes codes discoverable and reduces semantic collision. It does not deploy them. Expert review does not authenticate a packet, certify a client, validate a server's policy or require an operator to continue serving a device. Registry governance stops at the vocabulary boundary.
That is the design's durable restraint. NTP did not solve an accidental request flood by creating a global rate authority. It let a server express a bounded refusal or pressure signal. The client kept the code, timers and choice of alternative sources. The operator kept filters when cooperation failed. The standards body kept the meaning of the shared wire message, not ownership of the endpoints.
The earlier BTW history of NTP followed four timestamps, source disagreement and local clock discipline. KoD sits beside that mechanism, not inside its selection algorithm. It begins only after the server declines to supply a usable measurement. Its achievement was to make that absence legible—without pretending that legibility was command.
Member Briefing
Deeper Profile Context
Sign in with the right membership level to unlock the full briefing and source notes.
Only for Strategic Circle
Strategic Circle
Open to all readers. Unlock profile briefings after joining and signing in.
Join Strategic CircleOnly for Leadership Alliance
Leadership Alliance
For qualified IP-asset owners and management; sign in to unlock alliance briefings.
Join Leadership Alliance
