I was typing up a response, but yours is great. You nailed it.

The only thing to add is that a tlsdate-like approach will not work consistently with TLS 1.3 as the standard makes time in the handshake OPTIONAL.

It's been a couple of years since I was really immersed in the operational aspects of NTP/PTP - glad to know I can still mostly follow along.

Nice theme on the blog.

Thank you.

