In Ubuntu Server and other systemd-based Linux distributions, the ua-timer.timer (also known as ubuntu-advantage.timer in newer releases) is a recurring systemd timer unit managed by the ubuntu-advantage-tools package (now branded as Ubuntu Pro Client). This timer periodically wakes the system to perform automated checks against Canonical’s Ubuntu Pro (formerly Ubuntu Advantage) subscription API, verifying entitlement status, refreshing token metadata, and downloading updated ESM (Extended Security Maintenance) package lists. While essential for organisations actively subscribed to Ubuntu Pro, this recurring timer introduces a significant operational overhead, network exfiltration concern, and compliance liability on air-gapped servers, self-managed infrastructure, or community-edition deployments that have no intention of subscribing to Canonical’s commercial offering. Allowing unauthenticated, periodic outbound HTTPS connections to Canonical’s API endpoints breaches the network isolation requirements of strict zero-trust or SCIF-rated environments.
This guide explains how to completely disable the ua-timer (Ubuntu Pro Client timer) in Ubuntu Server, enforcing an absolute block on automated subscription entitlement checks and eliminating all periodic outbound API traffic to Canonical’s infrastructure.
Stop and Mask the ua-timer Service
Because this timer is deeply integrated into the ubuntu-advantage-tools package and will be re-enabled by package updates or system upgrades, a simple systemctl disable is insufficient to guarantee the timer will never re-activate. To enforce an absolute cryptographic block, we must explicitly mask the unit.
- Log into your Ubuntu Server via SSH using an account with
sudoprivileges. - Stop the timer to halt any currently scheduled or pending execution:
sudo systemctl stop ua-timer.timer - Stop the associated service unit that the timer invokes:
sudo systemctl stop ua-timer.service - Mask both the timer and service units. This symlinks them to
/dev/null, creating a hard block against future activation by package reinstallations, apt triggers, or manual invocations:sudo systemctl mask ua-timer.timer sudo systemctl mask ua-timer.service - Optional but recommended: If the system is running Ubuntu 22.04 LTS or later where the package has been rebranded, also mask the aliased units:
sudo systemctl mask ubuntu-advantage.timer sudo systemctl mask ubuntu-advantage.service
Verify the Service Lockdown
By masking the timer and its associated service, you guarantee that systemd will completely reject any attempt to invoke periodic Ubuntu Pro entitlement checks, eliminating all outbound API traffic to Canonical’s subscription infrastructure.
To verify the lockdown is successful, attempt to start the timer manually:
sudo systemctl start ua-timer.timer
Systemd will return a fatal error stating that the unit is masked (e.g., Failed to start ua-timer.timer: Unit ua-timer.timer is masked). Furthermore, running systemctl list-timers --all will confirm that the ua-timer.timer is completely absent from the active timers list. The server’s outbound network pipeline is now strictly secured against unmanaged subscription telemetry.