Skip to main content

Port Details

Port
8443
Transport
TCP
Service
HTTPS alternate
IANA service name
pcsync-https
Range
User port (1024-49151)
Related ports

Security Exposure

CISA BOD 23-02 directs federal agencies to remove networked management interfaces, including those reached over HTTPS, from the public internet or to place them behind an access control enforcement point separate from the interface. Anything listening on 8443 carries the vulnerabilities of the specific product behind it.

Hardening

  • +Inventory every listener on 8443 and identify the product and owner behind it.
  • +Restrict management consoles on 8443 to internal administration networks or put them behind an access proxy that enforces authentication.
  • +Use a trusted certificate and current TLS versions on the connector rather than a default self-signed certificate.
  • +Patch the application server or appliance that serves the port on the vendor's schedule.

Monitoring

Track which hosts expose 8443 externally with periodic scans, and review web access logs on those hosts for authentication failures and requests to administrative paths.

Tools for Auditing and Monitoring HTTPS alternate

ZAP

Open Source
Application Security Tools

Open-source web application security scanner and intercepting proxy for detecting web flaws during development and testing.

LicenseApache-2.0
PlatformLinux, Windows, macOS

Nmap

Free / Commercial
Penetration Testing Tools

Network discovery scanner and port auditor for discovering live hosts, open ports, running services, and OS fingerprints.

LicenseNPSL-0.95 (Nmap Public Source License, not OSI-approved)
PlatformLinux, macOS, Windows

Nuclei

Free / Commercial
Vulnerability Scanning

Fast vulnerability scanner powered by community YAML templates to scan web applications, networks, and cloud targets for known defects.

LicenseMIT
PlatformLinux, macOS, Windows

Frequently Asked Questions

Is port 8443 the same as 443?→

Both normally carry HTTPS. 443 is the standard HTTPS port, and 8443 is a common alternate; Tomcat uses 8443 in its examples because ports below 1024 need special setup on many systems.

What is port 8443 registered for?→

IANA lists 8443 over TCP and UDP as pcsync-https (PCsync HTTPS). Nmap's service list notes it as a common alternative HTTPS port.

Is it safe to expose port 8443?→

It depends on the service. Management interfaces on 8443 fall under the guidance in CISA BOD 23-02, which calls for removing them from the internet or protecting them with separate access controls.

Sources

Port assignments from the IANA Service Name and Transport Protocol Port Number Registry. Services can be configured to run on any port, so traffic on port 8443 is not guaranteed to be HTTPS alternate. Exploited-in-the-wild data from the CISA KEV catalog (CC0).