I've just noticed that chrony isn't linked with the nettle library despite nettle being enabled as default.
If you look at the build log from poudriere ( http://beefy6.nyi.freebsd.org/data/latest-per-pkg/chrony/3.5/120amd64-default.log ) it shows the port installing nettle but then during the configure stage it says nettle is not found and SECHASH is disabled.
===> chrony-3.5 depends on shared library: libnettle.so - found (/usr/local/lib/libnettle.so)
Checking for nettle : No
Features : +CMDMON +NTP +REFCLOCK -RTC +PRIVDROP -SCFILTER -SIGND +ASYNCDNS +READLINE -SECHASH +IPV6 -DEBUG
Fix ordering of bugs.
*** This bug has been marked as a duplicate of bug 244534 ***
A commit references this bug:
Date: Sun Apr 5 21:20:11 UTC 2020
New revision: 530840
net/chrony: make NETTLE build robust, improve rc script, re-enable NSS
Changes by Colin T.:
* Always require pkgconfig instead of only requiring it for NSS,
because otherwise chrony does not link reliably to nettle. 
* Add pidfile to rc.d script to stop it from complaining when
stopping chronyd. 
* Document chronyd_* options in rc.d script. 
Changes by Matthias Andree:
* Move USES line up to please portlint.
* Add HTMLDOCS option, to build and install HTML docs. IMPLIES DOCS.
Needs textproc/asciidoctor (rubygem) as build requisite.
* Turn CRYPTLIB into a _RADIO to choose at most one from NSS + NETTLE.
* Under WITH_DEBUG, add --enable-debug to CONFIGURE_ARGS.
* Remove @ (silent) from Makefile commands.
* Remove NSS_BROKEN, chrony 3.5 appears to work with NSS. Updates .
PR: 244534 
PR: 242510 
PR: 223840 
Submitted by: Colin T. <firstname.lastname@example.org> 
Reported by: Matt Smith <email@example.com> 
Approved by: maintainer timeout (firstname.lastname@example.org, 36 days)