Port 4460Network Time Security Key Establishment (NTS-KE)

TCP 4460 carries the TLS-protected negotiation that provisions keys and cookies for Network Time Security over NTP.

transport
tcp

single transport

in transit
encrypted

payload protected on the wire

assignment
official

registered with iana

risk
3/10

caution

lookups
0

rank 993 of 5,197 · top 19%

also known as ntske

Technical Details

what runs on :4460

NTS-KE uses TCP port 4460 and requires TLS 1.2 or later. After the TLS handshake, client and server exchange NTS-KE records to negotiate the next protocol (typically NTP) and an authenticated-encryption algorithm; the server also supplies cookies and the NTP server port. Both sides derive NTS keys from the TLS exporter, then close the TCP connection and use the negotiated parameters in subsequent NTP exchanges, usually over UDP port 123. NTS protects NTP exchanges against tampering and forgery; it does not encrypt the NTP packets themselves.

Security Information

exposure of :4460

risk score

3/ 10caution

worth attention. how exposed you are depends on configuration — don't leave it reachable from the internet without a reason.

security averages 3.1 across 372 ports — this one sits 0.1 below.

in transit

encrypted

payloads are protected on the wire

assignment

official

registered with iana for this service — scanners fingerprint it by number

reachable over

tcp

every listening transport is another surface to filter at the edge

security overview

The key-establishment exchange is protected by TLS, and the service is intended to be reachable by clients seeking NTS-protected time service. Internet exposure is normal for a public NTS server, but the TLS listener still adds implementation attack surface and can be targeted for connection or resource-exhaustion abuse; keep its TLS stack patched and limit exposure if it is not meant to serve public clients.

the 8 most looked-up other ports in security — 372 ports carry that label.

risk mix of the 8 listed

  • caution100%

2 of 8 encrypted