Network port detail · UDP/TCP

309

Entrusttime
Protocol(s)
UDP/TCP
Range
System (0-1023)

Summary

// typical exposure
Restricted (trusted networks only) — EntrustTime is a legacy, vendor-specific PKI/timestamping component with no evidence of public-facing design; it fits the profile of an enterprise service that should be limited to trusted internal networks rather than exposed to the internet.
// analyst note
sparse documentation overall; an open port 309 is unusual and worth investigating in context rather than assumed benign or malicious.
// if you see it open
No CVE or vendor security advisory found for this port. No known virus/trojan association reported by auditmypc.com. No primary internet-scanning-study evidence (Shodan/Censys/SANS ISC/Shadowserver) found for scanning volume or exposure prevalence. As a PKI-vendor-specific, name-implied timestamping service, it plausibly belongs on trusted internal networks rather than the public internet, though this is inferred from the name rather than confirmed technical documentation.
[ 01 ] — Context

About port 309/tcp.

Updated  ·  Confidence: Low

Port 309/tcp carries entrusttime (EntrustTime), a legacy IANA-registered service tied to Entrust's PKI product line, and it should generally stay internal-only rather than be exposed to the public internet.

The IANA Service Name and Transport Protocol Port Number Registry lists port 309 as entrusttime / "EntrustTime" for both tcp and udp, with identical row content for each transport. The assignee and contact is Peter Whittaker, historically associated with Entrust Technologies. No RFC or other reference document is listed, and the registry's Registration Date, Modification Date, Service Code, and Unauthorized Use Reported fields are all blank for this entry — left as null here rather than fabricated.

Beyond the registry row, no dated vendor documentation describing EntrustTime's actual function was found; the name suggests a timestamping or time-synchronization component of an Entrust PKI product suite (timestamping is a common PKI/certificate-authority function), but this is an inference from the name, not a confirmed technical description. No CVE, security advisory, or scanning-prevalence study specific to port 309 was located.

IANA assignment
entrusttime — "EntrustTime"; reference (blank — no RFC cited in IANA registry); assignee/contact Peter Whittaker (Entrust Technologies); dual-registered 309/tcp + 309/udp, identical row content [Confirmed] — IANA Service Name and Transport Protocol Port Number Registry
Range class
well-known (0–1023)
Registration/modification dates
blank in the IANA registry — not asserted [Confirmed absence]
Related ports
no documented related-port cluster found [Unknown]

Primary use

registered under Entrust's name as "EntrustTime"; likely a timestamping/time-sync component of Entrust's PKI product suite, but the specific protocol/function is not documented in available sources [Unknown]

Other/unofficial uses

none found [Unknown]

Security implications

no CVE or advisory found; no known malware association per auditmypc.com; no scanning-prevalence data found; PKI-vendor-specific service, plausibly enterprise-internal by nature

[Unknown/Likely] — https://www.auditmypc.com/tcp-port-309.asp

Typically seen on

unconfirmed — possibly legacy Entrust PKI deployments [Unknown]

Analyst note
sparse documentation overall; an open port 309 is unusual and worth investigating in context rather than assumed benign or malicious.
[ 02 ] — Context

About port 309/udp.

Updated  ·  Confidence: Medium

Port 309/udp is IANA-registered under the name entrusttime, described only as "EntrustTime" and assigned to Peter Whittaker of Entrust; no protocol specification, RFC, or currently active software has been verified for it, so whether it belongs on the public internet is Unknown rather than something to assume — treat an open 309/udp as worth investigating rather than as a known-safe service.

The registry entry gives no registration date, no IANA reference (RFC), and no modification date — fields that are genuinely blank in both the IANA CSV and the locally cached registry mirror, consistent with a legacy-era assignment rather than a fabricated gap. Port 309/tcp carries an identical dual registration under the same name, assignee, and blank fields, immediately preceding this UDP entry in the registry.

Live scanning telemetry from the SANS Internet Storm Center shows only low-volume, sporadic probes against port 309 — single- or double-digit distinct source IPs on days checked — consistent with routine internet-wide sweeps rather than targeted interest in a live service. No corroborated malware or trojan association exists: a claim on a low-authority port-lookup aggregator (auditmypc.com) is not backed by Gary Kessler's well-regarded "Bad TCP/UDP Ports" reference list, which omits port 309 entirely.

IANA assignment
entrusttime — "EntrustTime"; reference (blank — no RFC cited in IANA registry); assignee Peter Whittaker (Entrust); dual-registered 309/tcp + 309/udp [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry; https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.csv
Range class
well-known (0–1023) [Confirmed]
Registration/modification dates
blank in both the locally cached registry CSV and the live IANA registry (TCP and UDP rows alike) — reported as null, not fabricated [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry
Dual registration
309/tcp registered identically (same service name, description, assignee, and blank trailing fields) [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry

Primary use

Unknown — no linked protocol specification or currently active software verified

[Unknown] — https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xhtml?page=6

Malware/trojan association

uncorroborated claim on a low-credibility aggregator, not supported by a more rigorous reference list

[Likely false/Unconfirmed] — https://www.auditmypc.com/udp-port-309.asp; https://www.garykessler.net/library/bad_ports.html

Typically seen on

Unknown — no verified deployment context or active software found

Scanning exposure
low-volume, sporadic probes (single/double-digit distinct source IPs), consistent with broad internet-wide sweeps [Confirmed] — https://isc.sans.edu/data/port/309 (observed 2026-07-18)
// registry data

Service assignments.

2 entries
// IANA / nmap services registry
NameProtocolDescriptionOpen frequency
entrusttime UDP 0.05%
entrusttime TCP 0.00%
IANA name
entrusttime
Transport
TCP
Range
System (0-1023)

Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.