Network port detail · UDP/TCP

223

Cdc
Protocol(s)
UDP/TCP
Range
System (0-1023)

Summary

// if you see it open
No CVEs, exploit advisories, or internet-wide-scanning studies were found specific to port 223/tcp. It does not appear in Wikipedia's List of TCP and UDP port numbers or in prominent scanning-port references (USENIX Sec'14 internet-wide scanning study; Qualys scanning-port appendix), consistent with a legacy, rarely-deployed registration rather than an actively targeted service. Modern Kerberos does not use this port in any era (88/749 instead), and this port is unrelated to Kerberos entirely — it is tied to DEC's separate SPX protocol — so an open 223 is not evidence of Kerberos activity.
[ 01 ] — Context

About port 223/tcp.

Updated  ·  Confidence: Medium

Port 223 is an IANA-registered System Port assigned under the service name cdc, described simply as "Certificate Distribution Center," with assignee Kannan Alagappan and a blank Reference field — no RFC or other protocol document is cited for it, and the entry is dual-registered for both 223/tcp and 223/udp with identical text on both rows. Kannan Alagappan is a co-author (with Joseph J. Tardo) of Digital Equipment Corporation's SPX authentication paper ("SPX: Global Authentication Using Public Key Certificates," IEEE Symposium on Research in Security and Privacy, 1991), which defines a specialized server application called the Certificate Distribution Center, or CDC, used to distribute public-key certificates and other authentication information ahead of a ubiquitous X.500 directory service — wording that matches the IANA registry description almost verbatim. Corroborating this, the two System Ports immediately adjacent to 223 are explicitly SPX-branded in the live registry itself: 221/tcp,udp is fln-spx ("Berkeley rlogind with SPX auth") and 222/tcp,udp is rsh-spx ("Berkeley rshd with SPX auth"), forming a contiguous block of DEC SPX-related registrations. No single source states outright that port 223 was registered specifically to carry this SPX CDC component, so the link is recorded as a well-corroborated inference — matching assignee, matching component name and description, adjacent SPX-labeled sibling ports — rather than a directly confirmed fact. A prior version of this record instead attributed port 223 to a "pre-Kerberos-v5 / MIT Project Athena" lineage; that claim is retracted here as unsourced, and the SPX paper itself frames SPX as a distinct, competing architecture rather than a Kerberos precursor. Modern Kerberos deployments do not use port 223 at all; they use 88/tcp,udp for the KDC and 749/tcp for the legacy admin server, so an open 223 today is not evidence of Kerberos activity, nor is it necessarily evidence of live SPX activity — SPX itself only ever reached a limited 1991 beta on DEC Ultrix. A widely mirrored third-party port-lookup description ("IBM Advanced Systems Accounting") does not match the IANA registry text and remains excluded as an unverified aggregator artifact. Port 223 is absent from Wikipedia's List of TCP and UDP port numbers and from major internet-wide scanning-port references, consistent with a legacy registration that sees essentially no real-world deployment or scanning attention today.

IANA assignment
service name cdc — "Certificate Distribution Center"; assignee Kannan Alagappan; Reference field blank; dual-registered 223/tcp + 223/udp with identical text [Confirmed — two angles: cached registry CSV + live IANA page fetched 2026-07-17] — https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xhtml?search=223
Range class
well-known / System Port (0–1023) [Confirmed]
IANA RFC/reference
blank — no RFC or protocol document is cited in the registry [Confirmed] — https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xhtml?search=223

Primary use

registered as DEC's SPX "Certificate Distribution Center" (CDC) — corroborated by matching assignee (SPX co-author Kannan Alagappan), a matching component definition in the primary SPX paper, and adjacent SPX-branded sibling ports 221/222 in the live registry; no single source states the port-223-to-SPX link verbatim, so this is a well-corroborated inference rather than a confirmed fact. Supersedes the prior "pre-Kerberos-v5 / MIT Project Athena" attribution, which cited an MIT KDC-ports document that never mentions port 223, CDC, or Project Athena and is retracted as unsourced [Likely] — https://conferences.computer.org/sp/pdfs/sp/1991/00044251.pdf ; https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xhtml?search=223

Exposure/scanning prominence

absent from Wikipedia's List of TCP and UDP port numbers and from the USENIX Sec'14 internet-wide-scanning study and Qualys scanning-port appendix; no CVE or exploit advisory found specific to this port [Unknown] — https://en.wikipedia.org/wiki/List_of_TCP_and_UDP_port_numbers ; https://www.usenix.org/system/files/conference/usenixsecurity14/sec14-paper-durumeric.pdf ; https://docs.qualys.com/en/vm/api/scans/appendix/ports_for_scanning.htm

Not a Kerberos/Project-Athena component
the SPX paper explicitly distinguishes SPX from Kerberos as a separate, competing public-key-based architecture ("SPX uses a hybrid of public and secret key technology, whereas Kerberos uses secret key technology exclusively"), directly contradicting the retracted prior claim
[Confirmed — primary source] — https://conferences.computer.org/sp/pdfs/sp/1991/00044251.pdf
Modern Kerberos relevance
current Kerberos deployments use 88/tcp,udp (KDC) and 749/tcp (legacy admin server), not 223, in any era — an open 223 is not evidence of Kerberos activity [Likely] — https://web.mit.edu/kerberos/krb5-1.5/krb5-1.5.4/doc/krb5-install/Ports-for-the-KDC-and-Admin-Services.html
Common/current software
none identified as commonly listening on 223/tcp today; the only identified historical implementation was a limited 1991 DEC Ultrix beta of SPX among volunteer users [Unknown for current software; Likely for the historical beta] — https://conferences.computer.org/sp/pdfs/sp/1991/00044251.pdf
Unverified third-party description
an aggregator port-lookup description ("IBM Advanced Systems Accounting") circulates but does not match the authoritative IANA registry text; treated as a database artifact, not fact [Unknown — deliberately excluded from JSON]
[ 02 ] — Context

About port 223/udp.

Updated  ·  Confidence: Low

Port 223/udp is registered with IANA under the service name cdc, described as "Certificate Distribution Center," with assignee and contact listed as [Kannan_Alagappan] in the IANA Service Name and Transport Protocol Port Number Registry. The same name, description, and assignee are also registered for 223/tcp, so both transports share an identical entry. The registry's Registration Date, Modification Date, and Reference (RFC) columns are all blank for this entry — no RFC or standards-track document defines the wire protocol, and no registration date is recorded, consistent with many legacy System Port assignments from the registry's early era. Beyond the bare IANA name and assignee, no independently verifiable technical specification, software implementation, or protocol behavior could be confirmed for this pass: searches across port-lookup aggregators (SpeedGuide, t1shopper) simply restate the IANA name and description without adding implementation detail, and no scanning-research literature (GreyNoise, Censys, ISC/SANS) references port 223 as notably exposed or exploited. A low-authority site (auditmypc.com) marks the port as having no known virus/trojan association, but its disclaimer text is templated site-wide and is treated as weak evidence rather than a real finding. Overall, 223/udp reads as an obscure, undocumented legacy registration rather than an actively used service — content should present it that way rather than assert a concrete use case.

IANA assignment
cdc — "Certificate Distribution Center"; reference (blank — no RFC cited in IANA registry); assignee/contact [Kannan_Alagappan] [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry; https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xhtml
Dual registration
identical name/description/assignee also registered for 223/tcp (same row set) [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry
Registration/modification dates
blank in source CSV — left null, not invented [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry
Range class
well-known (0–1023) [Confirmed]
Prevalence
nmap-services observed open-frequency 223/udp ≈ 0.000346 — very low (roughly 3 in 10,000 scanned hosts in the nmap-services sample); the paired 223/tcp row is lower at ≈ 0.000125 [Confirmed] — nmap-services dataset
Related ports
223/tcp (dual registration, identical entry) [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry

Primary use

registry gives only a name and description ("Certificate Distribution Center"); no RFC, reference document, or protocol specification found — actual wire behavior is unconfirmed

[Unknown] — https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xhtml

Other/unofficial uses

no historical or current software implementing a cdc service on port 223 was found; low-authority aggregators (SpeedGuide, t1shopper) only restate the IANA name

[Unknown] — https://www.speedguide.net/port.php?port=223, http://www.t1shopper.com/tools/port-number/223/

Security implications

no scanning-research literature (GreyNoise, Censys, ISC/SANS) references port 223 as notably exposed or exploited; auditmypc.com marks it "Virus/Trojan: No" but that disclaimer is templated across their whole site, so it is treated as weak, single-source boilerplate rather than a real finding

[Unknown/Likely] — https://www.auditmypc.com/udp-port-223.asp

Typically seen on

unknown — no evidence of any deployed service found [Unknown]

// registry data

Service assignments.

2 entries
// IANA / nmap services registry
NameProtocolDescriptionOpen frequency
cdc UDP Certificate Distribution Center 0.03%
cdc TCP Certificate Distribution Center 0.01%
IANA name
cdc
Transport
TCP
Range
System (0-1023)

Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.