In particular, the PI Data Archive's port 5450 is not configurable and the PI Asset Framework's port 5457 is not configurable, and both programs require SPNs.
The SPNs that are expected to be assigned to the service account of the PI Data Archive's PI Network Manger are:
PIServer/<host name>
PIServer/<FQDN>
The SPNs that are expected to be assigned to the service account of the PI AF Application Service are:
AFServer/<host name>
AFServer/<FQDN>
I feel that these should instead be:
There are several reasons why I think that this change is good:
It is clearer, more specific, and follows the principle of least privilege
The PI services will not even receive traffic if the wrong port number is used
This futureproofs the PI services if extra functionality is ever added that uses the same service class but different service accounts
If the PI Server install kit tries to register SPNs, then it should use the versions with port numbers. Similarly, the documentation of any PI programs that mention these SPNs (e.g. PI Data Archive, PI Asset Framework, PI Vision, and PI Web API) should use the versions with port numbers. The PI SQL Data Access Server (RTQP Engine) is a good example of using SPNs with port numbers when the port number is not configurable (see this).
However, this suggestion is not just for the SPNs of the PI Data Archive and of the PI Asset Framework. Those are just the examples that come to mind. This suggestion should be implemented whenever SPNs are needed and the ports that are used are not configurable.