Toolman

Port 389 — LDAP

TCP well-known

What runs on port 389

Directory services — user and group lookups, including Active Directory.

Security considerations

Unencrypted. Use LDAPS on 636 or StartTLS, otherwise credentials are readable on the wire.

Checking whether something is listening

# Linux / macOS — what is bound to the port
sudo lsof -i :389
sudo ss -lntp | grep :389

# Windows
netstat -ano | findstr :389
Get-NetTCPConnection -LocalPort 389

# is it reachable from outside?
nc -zv example.com 389
curl -v telnet://example.com:389

Freeing the port

# find the process, then stop it
sudo lsof -ti :389 | xargs kill        # Linux / macOS
netstat -ano | findstr :389            # note the PID, then:
taskkill /PID <pid> /F                    # Windows

Should this port be open to the internet?

Usually not. Expose it only if a specific external client needs it, and restrict by source address where you can.

Quick reference

Port389
ProtocolTCP
ServiceLDAP
RangeWell-known (0–1023) — binding requires root on Unix

Frequently asked questions

What is port 389 used for?

Directory services — user and group lookups, including Active Directory.

Is it safe to open port 389?

Unencrypted. Use LDAPS on 636 or StartTLS, otherwise credentials are readable on the wire.

How do I check if port 389 is open?

Locally, sudo lsof -i :389 on macOS or Linux, or netstat -ano | findstr :389 on Windows. From outside, nc -zv host 389 tells you whether anything answers.

Why do I get "address already in use" on port 389?

Another process is bound to it — often a previous run of your own program that did not exit cleanly. Find it with lsof -ti :389 and stop it, or configure your application to use a different port.

Can I change the port this service uses?

Almost always yes, in the service's configuration. Moving off a default port reduces automated scan noise, but it is obfuscation rather than security — a real attacker scans all 65,535.

Other common ports

All port numbers