MECM 2111 - port 10123

Bojan Zivkovic 21 Reputation points
2022-02-16T17:30:16.387+00:00

Hi, can tcp port 10123 be disabled in site properties without causing some issues? I have vulnerability reported by Rapid7 saying self-signed certificate being used for communication on tcp port 10123 and I am struggling to remediate this.

If port should not be disabled any idea how to remediate this vulnerability? Thank you in advance.

Not Monitored
Not Monitored
Tag not monitored by Microsoft.
36,216 questions
0 comments No comments
{count} votes

6 answers

Sort by: Most helpful
  1. Jason Sandys 31,166 Reputation points Microsoft Employee
    2022-02-16T19:04:47.14+00:00

    You can't specifically disable it no, but if the port is not open, clients will fallback to 80 or 443 for client notification. This will cause an increased load on the MP(s) though.

    I would seek an exception here though because in this case, although the cert is self-signed, it is created and controlled by ConfigMgr and not just a randomly generated cert.

    1 person found this answer helpful.
    0 comments No comments

  2. Bojan Zivkovic 21 Reputation points
    2022-02-17T08:03:53.997+00:00

    If InfoSec reject my request how can I replace that certificate with one issued by CA?

    0 comments No comments

  3. Jason Sandys 31,166 Reputation points Microsoft Employee
    2022-02-17T15:44:03.377+00:00

    You cannot. As noted, the most you can do is allow the port to be blocked and the clients will fallback to 80 or 443.

    0 comments No comments

  4. Bojan Zivkovic 21 Reputation points
    2022-02-17T16:48:08.427+00:00

    What about unchecking port 10123 in site properties (client communication)? That would block it?

    0 comments No comments

  5. Jason Sandys 31,166 Reputation points Microsoft Employee
    2022-02-17T16:58:05.88+00:00

    I've honestly never thought about doing that and don't know the full ramifications of doing so. You can certainly try though and validate that client notification is still working. The client notification logs will show you the ports being used.

    0 comments No comments