Port 9878KX509 Kerberized Certificate Issuance Protocol
KX509 uses Kerberos to support certificate issuance over UDP port 9878.
- transport
- udp
- in transit
- cleartext
- assignment
- official
- risk
- 4/10
- lookups
- 0
single transport
payload readable on path
registered with iana
caution
rank 993 of 4,631 · top 21%
also known as kca-service
Technical Details
what runs on :9878KX509 uses UDP port 9878 for client-to-KCA certificate issuance exchanges. A client presents Kerberos authentication material together with a public-key certificate request; the KCA validates the Kerberos identity and returns an X.509 certificate, typically with a short lifetime. The service is datagram-based and has no universal TCP companion or TLS-style application stream; deployments normally use the 9878/udp default. The historical implementation and service name are often identified as kca_service.
Security Information
exposure of :9878risk score
4/ 10caution
worth attention. how exposed you are depends on configuration — don't leave it reachable from the internet without a reason.
security averages 3.1 across 353 ports — this one sits 0.9 above.
in transit
cleartext
credentials and payloads are readable by anyone on path
assignment
official
registered with iana for this service — scanners fingerprint it by number
reachable over
udp
udp is connectionless — source addresses are trivially spoofed and it is a reflection favourite
security overview
The service is intended for clients that already possess valid Kerberos credentials, so an unauthenticated Internet user should not be able to obtain a certificate. Nevertheless, exposing a KCA directly to the Internet increases attack surface and can enable abuse if Kerberos authentication or authorization is misconfigured; restrict it to trusted networks or known Kerberos clients. The protocol authenticates the requester, but operators should not assume that every part of the UDP exchange has the confidentiality properties of TLS.
Related Ports
the 8 most looked-up other ports in security — 353 ports carry that label.
| port | service | risk | |||
|---|---|---|---|---|---|
| :8881 | Atlasz Secure Server | TCP | Web Services | caution | 67.6k |
| :443 | HTTPS | TCPtls | Web Services | caution | 65.9k |
| :8291 | Winbox MikroTik Admin | TCP | Security | caution | 62.9k |
| :3268 | Microsoft Global Catalog (GC) | TCPUDP | Security | caution | 54.6k |
| :135 | Microsoft EPMAP | TCPUDP | Security | caution | 51.9k |
| :3128 | Squid Proxy HTTP | TCP | Web Services | caution | 45.8k |
| :8080 | HTTP Alternate | TCP | Web Services | caution | 44.9k |
| :7000 | Vuze HTTPS Tracker | TCPtls | Security | caution | 28.9k |
risk mix of the 8 listed
- caution100%
2 of 8 encrypted