Hm? Splunk doesn't open port 443 at all unless you configured it to do so in some way. It may listen to ports 9997 (log receiving), 8089 (intra-Splunk-traffic) or 8000 (splunkweb) depending on how you configured it, but 443, no.
Yes. If you do not need splunkweb on the indexer... you can just omit this or set it to 0 or just disable splunkweb.
"splunk disable webserver" and restart.
So we have a setting in our web.conf
httpport = 443
could this be causing it to be open?