INNER CODE UNIT · Python

_TLSServer

cipi-sh/cipi · lib/cipi-crowdsec-rescue.py:188

class _TLSServer(ThreadingMixIn, HTTPServer):
    """HTTP over TLS with the handshake in the worker thread.

    Wrapping the *listening* socket (the obvious way) makes accept() perform the
    handshake, so one peer that opens a connection and never sends a ClientHello
    stops the accept loop for as long as it holds the socket — the break-glass
    path is then closed by anyone who can reach the port, which is everyone.
    """

    daemon_threads = True
    allow_reuse_address = True
    ssl_context: ssl.SSLContext

    def get_request(self):
        sock, addr = super().get_request()
        sock.settimeout(HANDSHAKE_TIMEOUT)
        return sock, addr

View source record →

📰 Research Paper
Loading…
⏳ Fetching content…