Port 9878KX509 Kerberized Certificate Issuance Protocol

KX509 uses Kerberos to support certificate issuance over UDP port 9878.

transport
udp

single transport

in transit
cleartext

payload readable on path

assignment
official

registered with iana

risk
4/10

caution

lookups
0

rank 993 of 4,631 · top 21%

also known as kca-service

Technical Details

what runs on :9878

KX509 uses UDP port 9878 for client-to-KCA certificate issuance exchanges. A client presents Kerberos authentication material together with a public-key certificate request; the KCA validates the Kerberos identity and returns an X.509 certificate, typically with a short lifetime. The service is datagram-based and has no universal TCP companion or TLS-style application stream; deployments normally use the 9878/udp default. The historical implementation and service name are often identified as kca_service.

Security Information

exposure of :9878

risk score

4/ 10caution

worth attention. how exposed you are depends on configuration — don't leave it reachable from the internet without a reason.

security averages 3.1 across 353 ports — this one sits 0.9 above.

in transit

cleartext

credentials and payloads are readable by anyone on path

assignment

official

registered with iana for this service — scanners fingerprint it by number

reachable over

udp

udp is connectionless — source addresses are trivially spoofed and it is a reflection favourite

security overview

The service is intended for clients that already possess valid Kerberos credentials, so an unauthenticated Internet user should not be able to obtain a certificate. Nevertheless, exposing a KCA directly to the Internet increases attack surface and can enable abuse if Kerberos authentication or authorization is misconfigured; restrict it to trusted networks or known Kerberos clients. The protocol authenticates the requester, but operators should not assume that every part of the UDP exchange has the confidentiality properties of TLS.

the 8 most looked-up other ports in security — 353 ports carry that label.

risk mix of the 8 listed

  • caution100%

2 of 8 encrypted