Microsoft PKI – Port Requirements for Firewalls

Pretty basic, although the high ports are a gotcha.

Application protocolProtocolPorts
RPCTCP135
SMBTCP445, 139
Randomly allocated high portsTCPRandom port numbers between 49152 – 65535

For the web-based portions of PKI, you will also need the standard web ports:

Application protocolProtocolPorts
WebTCP80
Web SSLTCP443