36 lines
1.2 KiB
Go
36 lines
1.2 KiB
Go
package checkrunner
|
|
|
|
import (
|
|
"context"
|
|
"crypto/tls"
|
|
"net"
|
|
"strconv"
|
|
"time"
|
|
)
|
|
|
|
// TLSHandshake performs a real TLS handshake (not just a TCP connect)
|
|
// against host:port and reports success if it completes within timeout.
|
|
// Certificate validation is intentionally skipped: the target is a bare
|
|
// candidate IP under test before any DNS/hostname is attached to it, so
|
|
// there's neither a hostname to validate the cert against nor any reason
|
|
// to expect a signed cert yet. This checks "is there a real TLS listener
|
|
// here", not "is its certificate valid" — same scope-limiting principle
|
|
// SSHBanner already applies (banner only, no auth handshake).
|
|
func TLSHandshake(host string, port int, timeout time.Duration) func(ctx context.Context) Result {
|
|
target := net.JoinHostPort(host, strconv.Itoa(port))
|
|
checkType := "tls-" + strconv.Itoa(port)
|
|
return run(checkType, target, func(ctx context.Context) error {
|
|
ctx, cancel := context.WithTimeout(ctx, timeout)
|
|
defer cancel()
|
|
d := tls.Dialer{
|
|
NetDialer: &net.Dialer{Timeout: timeout},
|
|
Config: &tls.Config{InsecureSkipVerify: true},
|
|
}
|
|
conn, err := d.DialContext(ctx, "tcp", target)
|
|
if err != nil {
|
|
return err
|
|
}
|
|
return conn.Close()
|
|
})
|
|
}
|