Port 636 — LDAPS
TCP well-known
What runs on port 636
LDAP over TLS.
Security considerations
Preferred over plain LDAP on 389 whenever credentials are involved.
Checking whether something is listening
# Linux / macOS — what is bound to the port
sudo lsof -i :636
sudo ss -lntp | grep :636
# Windows
netstat -ano | findstr :636
Get-NetTCPConnection -LocalPort 636
# is it reachable from outside?
nc -zv example.com 636
curl -v telnet://example.com:636
Freeing the port
# find the process, then stop it
sudo lsof -ti :636 | xargs kill # Linux / macOS
netstat -ano | findstr :636 # note the PID, then:
taskkill /PID <pid> /F # Windows
Should this port be open to the internet?
Usually not. Expose it only if a specific external client needs it, and restrict by source address where you can.
Quick reference
| Port | 636 |
| Protocol | TCP |
| Service | LDAPS |
| Range | Well-known (0–1023) — binding requires root on Unix |
Frequently asked questions
What is port 636 used for?
LDAP over TLS.
Is it safe to open port 636?
Preferred over plain LDAP on 389 whenever credentials are involved.
How do I check if port 636 is open?
Locally, sudo lsof -i :636 on macOS or Linux, or netstat -ano | findstr :636 on Windows. From outside, nc -zv host 636 tells you whether anything answers.
Why do I get "address already in use" on port 636?
Another process is bound to it — often a previous run of your own program that did not exit cleanly. Find it with lsof -ti :636 and stop it, or configure your application to use a different port.
Can I change the port this service uses?
Almost always yes, in the service's configuration. Moving off a default port reduces automated scan noise, but it is obfuscation rather than security — a real attacker scans all 65,535.