package checkrunner import ( "context" "crypto/tls" "net" "strconv" "time" ) // TLSHandshake performs a real TLS handshake (not just a TCP connect) // against host:port and reports success if it completes within timeout. // Certificate validation is intentionally skipped: the target is a bare // candidate IP under test before any DNS/hostname is attached to it, so // there's neither a hostname to validate the cert against nor any reason // to expect a signed cert yet. This checks "is there a real TLS listener // here", not "is its certificate valid" — same scope-limiting principle // SSHBanner already applies (banner only, no auth handshake). func TLSHandshake(host string, port int, timeout time.Duration) func(ctx context.Context) Result { target := net.JoinHostPort(host, strconv.Itoa(port)) checkType := "tls-" + strconv.Itoa(port) return run(checkType, target, func(ctx context.Context) error { ctx, cancel := context.WithTimeout(ctx, timeout) defer cancel() d := tls.Dialer{ NetDialer: &net.Dialer{Timeout: timeout}, Config: &tls.Config{InsecureSkipVerify: true}, } conn, err := d.DialContext(ctx, "tcp", target) if err != nil { return err } return conn.Close() }) }