KX509, which trades a Kerberos ticket for a short-lived X.509 certificate — UDP only; TCP 9878 is Reserved.
RFC 6717 documents kx509 as deployed in 2012: a client sends a single UDP request containing a Kerberos service ticket and a public key, and a Kerberized certificate authority replies with a matching X.509 certificate. IANA registers UDP 9878 as kca-service and explicitly marks TCP 9878 as Reserved, so a TCP listener here is not KX509. Deployment was largely university campuses bridging Kerberos realms to PKI-based services; clients can also find the KCA through _kca._udp.REALM SRV records.
Do not expose
This is a certificate authority endpoint. It authenticates callers with Kerberos, but a CA's issuance interface belongs inside the realm it serves, not on a public address.
$ nc -vzu TARGET 9878Seen this on your network? Beige Box scans your Wi-Fi and shows every open port on every device — and its Ports tool links straight back here.
Get Beige Box →also available as JSON · Markdown
Corrections or a missing port? Reply @rimrocksystems.