Port 5318Certificate Management over CMS (CMC)

Certificate enrollment and management messages using CMS, typically exchanged between PKI clients and certificate authorities.

transport
tcp

single transport

in transit
cleartext

payload readable on path

assignment
official

registered with iana

risk
2/10

safe

lookups
0

rank 993 of 5,437 · top 18%

also known as pkix-cmc, CMC

Technical Details

what runs on :5318

CMC carries certificate-management operations in ASN.1 CMS structures, including client requests and CA responses. The protocol is transport-independent; TCP port 5318 is its registered endpoint, but the port alone does not guarantee a particular message framing or indicate that HTTP or TLS is in use. CMC can also be transported using mechanisms such as HTTP, and its CMS messages may be signed without being encrypted.

Security Information

exposure of :5318

risk score

2/ 10safe

routine exposure. this port is rarely the way in on its own — keep it patched and logged and move on.

security averages 3.0 across 388 ports — this one sits 1.0 below.

in transit

cleartext

credentials and payloads are readable by anyone on path

assignment

official

registered with iana for this service — scanners fingerprint it by number

reachable over

tcp

every listening transport is another surface to filter at the edge

security overview

A CMC endpoint can expose sensitive certificate issuance or revocation functions, so access should be limited to intended PKI clients and operations protected by appropriate authentication and authorization. CMS signatures and proof-of-possession help authenticate requests but do not by themselves encrypt traffic; use a protected transport where confidentiality is required. Public exposure is unusual and should be reviewed as part of the CA's security boundary.

the 8 most looked-up other ports in security — 388 ports carry that label.

risk mix of the 8 listed

  • caution100%

2 of 8 encrypted