Port 8443: Alternate HTTPS port (HTTP over TLS)
IANA registers 8443 as pcsync-https (PCsync HTTPS), and Nmap's service list labels 8443/tcp https-alt and describes it as a common alternative HTTPS port. Apache Tomcat's SSL/TLS configuration examples define the secure connector on 8443 because binding to ports below 1024, such as the standard 443, needs special setup on many operating systems.
Port Details
Security Exposure
CISA BOD 23-02 directs federal agencies to remove networked management interfaces, including those reached over HTTPS, from the public internet or to place them behind an access control enforcement point separate from the interface. Anything listening on 8443 carries the vulnerabilities of the specific product behind it.
Hardening
- +Inventory every listener on 8443 and identify the product and owner behind it.
- +Restrict management consoles on 8443 to internal administration networks or put them behind an access proxy that enforces authentication.
- +Use a trusted certificate and current TLS versions on the connector rather than a default self-signed certificate.
- +Patch the application server or appliance that serves the port on the vendor's schedule.
Monitoring
Track which hosts expose 8443 externally with periodic scans, and review web access logs on those hosts for authentication failures and requests to administrative paths.
Tools for Auditing and Monitoring HTTPS alternate
ZAP
Open SourceOpen-source web application security scanner and intercepting proxy for detecting web flaws during development and testing.
Nmap
Free / CommercialNetwork discovery scanner and port auditor for discovering live hosts, open ports, running services, and OS fingerprints.
Nuclei
Free / CommercialFast vulnerability scanner powered by community YAML templates to scan web applications, networks, and cloud targets for known defects.
Related Tool Categories
Static source analysis, dynamic scanners, and dependency vulnerability checkers.
Zero trust access, secure web gateways, firewalls, and perimeter enforcement platforms.
Infrastructure scanners, CVE audit engines, container image inspectors, and exposure management platforms.
Frequently Asked Questions
Is port 8443 the same as 443?→
Both normally carry HTTPS. 443 is the standard HTTPS port, and 8443 is a common alternate; Tomcat uses 8443 in its examples because ports below 1024 need special setup on many systems.
What is port 8443 registered for?→
IANA lists 8443 over TCP and UDP as pcsync-https (PCsync HTTPS). Nmap's service list notes it as a common alternative HTTPS port.
Is it safe to expose port 8443?→
It depends on the service. Management interfaces on 8443 fall under the guidance in CISA BOD 23-02, which calls for removing them from the internet or protecting them with separate access controls.
Sources
Port assignments from the IANA Service Name and Transport Protocol Port Number Registry. Services can be configured to run on any port, so traffic on port 8443 is not guaranteed to be HTTPS alternate. Exploited-in-the-wild data from the CISA KEV catalog (CC0).