Informative article but it meanders about for way too long.
- In some circumstances, Windows resets its clock based on the ServerUnixTime field of incoming TLS handshakes, for reasons that are not completely clear
- OpenSSL puts random numbers in ServerUnixTime
- Problem!
- Disable via
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\W32Time\SecureTimeLimits
See? That didn't take long.