The Kerberos KDC — where clients get tickets, and the heartbeat of every Active Directory domain.
A Key Distribution Center listens on 88 and answers AS-REQ and TGS-REQ messages, handing out the ticket-granting ticket and then service tickets that authenticate users without sending passwords. Windows domain controllers, MIT krb5 KDCs, Heimdal, and FreeIPA all listen here; Windows clients try UDP first and fall back to TCP when the ticket exceeds the datagram size. On a scan, an open 88 next to 389 and 445 is a domain controller, full stop. macOS also ships a KDC for local Kerberos realms.
Do not expose
The KDC is the root of trust for the whole realm, and an exposed one invites offline password cracking via AS-REP roasting and pre-auth probing. Keep it internal or behind a VPN.
$ nc -vz TARGET 88Seen this on your network? Beige Box scans your Wi-Fi and shows every open port on every device — and its Ports tool links straight back here.
Get Beige Box →also available as JSON · Markdown
Corrections or a missing port? Reply @rimrocksystems.