The Certificate Authority solution adds the following port requirements.

Incoming traffic to Certificate Authority

In all the installation nodes, check that the following ports are accessible for incoming traffic to Cryptographic Security Platform.

Target Port

Protocol

Source

Target Service

4443

TCP/HTTPS

CAs

Green deployment testing

7443

TCP/HTTPS

CAs

Internal CA Gateway

8880

TCP/HTTP

CAs

Green deployment testing

The deployment of the Certificate Authority solution automatically opens these ports in the firewall of the machines hosting Cryptographic Security Platform.

Outgoing traffic from Certificate Authority

In all the installation nodes, check that the following ports are accessible for outgoing traffic from Cryptographic Security Platform.

Target Port

Protocol

Source

Target Service

1792

NTLS

CAs

Luna Network HSM (if any)

9000-9004

TCP/HTTPS

CAs

nShield HSM (if any)