Skip to main content

Firewall Rules

These rules should be considered in a firewalled environment:

Inbound Rules

PurposeProtocol NamePort NumberTransport Layer Protocol
Used for redirecting HTTP traffic to HTTPS for secure communicationHTTP80TCP
Enables secure connections to the Passbolt server using SSL/TLSHTTPS443TCP

Outbound Rules

PurposeProtocol NamePort NumberTransport Layer Protocol
Used for legacy systems or specific cases where HTTPS is not supportedHTTP80TCP
Facilitates secure outbound connections for various services, including:
  • Passbolt's online resources:
    • fullBaseUrl for self-referencing healthcheck
    • download.passbolt.com
  • Secure package repositories
  • Bitbucket
  • Operating system and software updates
HTTPS443TCP
Connects to Unique DUO authentication endpointHTTPS443TCP
Connects to Yubico API endpoints:
  • api.yubico.com
  • api2.yubico.com
  • api3.yubico.com
  • api4.yubico.com
  • api5.yubico.com
HTTPS443TCP
Connects to other APIs and services: HTTPS443TCP
Sends email notifications through your configured SMTP serverSMTPUsually 587TCP
Resolves domain names for SMTP servers and updates from download.passbolt.comDNS53UDP
Synchronizes server time with an NTP server, essential for GPG and MFA/OTP functionalityNTP123UDP
Retrieves GPG keys securely from key servers:
  • keys.mailvelope.com
  • keys.openpgp.org
  • pgp.mit.edu
HKPS11371TCP