Files

36 lines
1.2 KiB
Go

package checkrunner
import (
"context"
"crypto/tls"
"net"
"strconv"
"time"
)
// TLSHandshake performs a real TLS handshake (not just a TCP connect)
// against host:port and reports success if it completes within timeout.
// Certificate validation is intentionally skipped: the target is a bare
// candidate IP under test before any DNS/hostname is attached to it, so
// there's neither a hostname to validate the cert against nor any reason
// to expect a signed cert yet. This checks "is there a real TLS listener
// here", not "is its certificate valid" — same scope-limiting principle
// SSHBanner already applies (banner only, no auth handshake).
func TLSHandshake(host string, port int, timeout time.Duration) func(ctx context.Context) Result {
target := net.JoinHostPort(host, strconv.Itoa(port))
checkType := "tls-" + strconv.Itoa(port)
return run(checkType, target, func(ctx context.Context) error {
ctx, cancel := context.WithTimeout(ctx, timeout)
defer cancel()
d := tls.Dialer{
NetDialer: &net.Dialer{Timeout: timeout},
Config: &tls.Config{InsecureSkipVerify: true},
}
conn, err := d.DialContext(ctx, "tcp", target)
if err != nil {
return err
}
return conn.Close()
})
}