Uname:Linux developmentwebsite.ca 4.18.0-553.168.1.el8_10.x86_64 #1 SMP Thu Sep 24 18:05:46 UTC 2026 x86_64

403WebShell
403Webshell
Server IP : 173.249.148.11  /  Your IP : 216.73.216.179
Web Server : Apache/2.4.68 (AlmaLinux)
System : Linux developmentwebsite.ca 4.18.0-553.168.1.el8_10.x86_64 #1 SMP Thu Sep 24 18:05:46 UTC 2026 x86_64
User : devinter ( 1006)
PHP Version : 8.3.35
Disable Function : NONE
MySQL : ON  |  cURL : ON  |  WGET : ON  |  Perl : ON  |  Python : ON  |  Sudo : ON  |  Pkexec : ON
Directory :  /snap/certbot/5893/lib64/python3.12/site-packages/urllib3/util/__pycache__/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Command :


[ Back ]     

Current File : /snap/certbot/5893/lib64/python3.12/site-packages/urllib3/util/__pycache__/ssl_.cpython-312.pyc
�

��jNE�
�>�UddlmZddlZddlZddlZddlZddlZddlZddlZddl	m
Z
ddlmZm
Z
ddlmZmZdZdZdZdZd	gZeeeeeefZd
D��cic]\}}|ee|d���c}}Z				d(d�Zej:rddlmZdd
lm Z ddl!mZ"Gd�de d��Z#iZ$de%d<	ddlZddlm&Z&mZm'Z'm(Z(m)Z)m*Z*m+Z+m,Z,m-Z-m.Z.m/Z/mZm0Z0e*Z1er
ee)�sdZdD]Z2	ee0e2�e$eede2���<�ddl!mZejjde6dfZ7d)d�Z8d*d�Z9d+d �Z:							d,															d-d!�Z;ejx												d.																											d/d"��Z=ejx												d.																											d0d#��Z=												d1																											d0d$�Z=d2d%�Z>d3d&�Z?	d4									d5d'�Z@ycc}}w#e3$rY��#wxYw#e4$rdZ'dZ(dZ.dZ/dxZ1Z*dZ+dZ,dZ-Y��wxYw)6�)�annotationsN)�	unhexlify�)�ProxySchemeUnsupported�SSLError�)�_BRACELESS_IPV6_ADDRZ_RE�_IPV4_REFzhttp/1.1))� �md5)�(�sha1)�@�sha256c�(�|jd�}|S)NzOpenSSL )�
startswith)�openssl_version�
is_openssls  �M/root/parts/certbot/install/lib/python3.12/site-packages/urllib3/util/ssl_.py�(_is_has_never_check_common_name_reliablers��
!�+�+�J�7�J���)�
VerifyMode)�	TypedDict)�SSLTransportc�,�eZdZUded<ded<ded<y)�_TYPE_PEER_CERT_RET_DICTztuple[tuple[str, str], ...]�subjectAltNamez'tuple[tuple[tuple[str, str], ...], ...]�subject�str�serialNumberN)�__name__�
__module__�__qualname__�__annotations__�rrrr.s��3�3�8�8��rr)�totalzdict[int, int]�_SSL_VERSION_TO_TLS_VERSION)
�
CERT_REQUIRED�HAS_NEVER_CHECK_COMMON_NAME�OP_NO_COMPRESSION�OP_NO_TICKET�OPENSSL_VERSION�PROTOCOL_TLS�PROTOCOL_TLS_CLIENT�VERIFY_X509_PARTIAL_CHAIN�VERIFY_X509_STRICT�OP_NO_SSLv2�OP_NO_SSLv3�
SSLContext�
TLSVersion)�TLSv1�TLSv1_1�TLSv1_2�	PROTOCOL_ii@ii�irc��|�td��|jdd�j�}t|�}|tvrtd|����tj|�}|�td|����t
|j��}||�j�}tj||�s td|�d|j��d	���y)
z�
    Checks if given fingerprint matches the supplied certificate.

    :param cert:
        Certificate as bytes object.
    :param fingerprint:
        Fingerprint as string of hexdigits, can be interspersed by colons.
    NzNo certificate for the peer.�:�zFingerprint of invalid length: zAHash function implementation unavailable for fingerprint length: z&Fingerprints did not match. Expected "z", got "�")r�replace�lower�len�HASHFUNC_MAP�getr�encode�digest�hmac�compare_digest�hex)�cert�fingerprint�
digest_length�hashfunc�fingerprint_bytes�cert_digests      r�assert_fingerprintrNks����|��5�6�6��%�%�c�2�.�4�4�6�K���$�M��L�(��8��
�F�G�G����
�.�H����O�P]��_�
�	
�
"�+�"4�"4�"6�7���4�.�'�'�)�K����{�,=�>��4�[�M��+�/�/�J[�I\�\]�^�
�	
�?rc��|�tSt|t�r(tt|d�}|�ttd|z�}|S|S)a�
    Resolves the argument to a numeric constant, which can be passed to
    the wrap_socket function/method from the ssl module.
    Defaults to :data:`ssl.CERT_REQUIRED`.
    If given a string it is assumed to be the name of the constant in the
    :mod:`ssl` module or its abbreviation.
    (So you can specify `REQUIRED` instead of `CERT_REQUIRED`.
    If it's neither `None` nor a string we assume it is already the numeric
    constant which can directly be passed to wrap_socket.
    N�CERT_)r(�
isinstancer�getattr�ssl��	candidate�ress  r�resolve_cert_reqsrW�sI�������)�S�!��c�9�d�+���;��#�w��2�3�C��
��rc��|�tSt|t�r@tt|d�}|�ttd|z�}tjt|�S|S)z 
    like resolve_cert_reqs
    Nr8)r-rQrrRrS�typing�cast�intrTs  r�resolve_ssl_versionr\�sU�������)�S�!��c�9�d�+���;��#�{�Y�6�7�C��{�{�3��$�$��rc�4�t�td��|dttfvrs|�|�t	d��t
j
|tj�}t
j
|tj�}tjdtd��tt�}|�||_
ntj|_
|�||_|r|j!|�|�t"j$n|}|�&d}|t&z}|t(z}|t*z}|t,z}|xj.|zc_|�'d}t0j2dk\r|t4z}|t6z}|xj8|zc_t;|d	d��d
|_|t"j$k(rt>s||_ d
|_!nd|_!||_ d|_"dtFjHvr=tFjJjMtFjHj
d��}nd}|r||_'|S)
a#Creates and configures an :class:`ssl.SSLContext` instance for use with urllib3.

    :param ssl_version:
        The desired protocol version to use. This will default to
        PROTOCOL_SSLv23 which will negotiate the highest protocol that both
        the server and your installation of OpenSSL support.

        This parameter is deprecated instead use 'ssl_minimum_version'.
    :param ssl_minimum_version:
        The minimum version of TLS to be used. Use the 'ssl.TLSVersion' enum for specifying the value.
    :param ssl_maximum_version:
        The maximum version of TLS to be used. Use the 'ssl.TLSVersion' enum for specifying the value.
        Not recommended to set to anything other than 'ssl.TLSVersion.MAXIMUM_SUPPORTED' which is the
        default value.
    :param cert_reqs:
        Whether to require the certificate verification. This defaults to
        ``ssl.CERT_REQUIRED``.
    :param options:
        Specific OpenSSL options. These default to ``ssl.OP_NO_SSLv2``,
        ``ssl.OP_NO_SSLv3``, ``ssl.OP_NO_COMPRESSION``, and ``ssl.OP_NO_TICKET``.
    :param ciphers:
        Which cipher suites to allow the server to select. Defaults to either system configured
        ciphers if OpenSSL 1.1.1+, otherwise uses a secure default set of ciphers.
    :param verify_flags:
        The flags for certificate verification operations. These default to
        ``ssl.VERIFY_X509_PARTIAL_CHAIN`` and ``ssl.VERIFY_X509_STRICT`` for Python 3.13+.
    :returns:
        Constructed SSLContext object with specified options
    :rtype: SSLContext
    Nz7Can't create an SSLContext object without an ssl modulezZCan't specify both 'ssl_version' and either 'ssl_minimum_version' or 'ssl_maximum_version'zi'ssl_version' option is deprecated and will be removed in urllib3 v3.0. Instead use 'ssl_minimum_version'r)�category�
stacklevelr)��
�post_handshake_authTF�
SSLKEYLOGFILE)(r3�	TypeErrorr-r.�
ValueErrorr'rBr4�MINIMUM_SUPPORTED�MAXIMUM_SUPPORTED�warnings�warn�
FutureWarning�minimum_versionr7�maximum_version�set_ciphersrSr(r1r2r*r+�options�sys�version_infor/r0�verify_flagsrRrb�IS_PYOPENSSL�verify_mode�check_hostname�hostname_checks_common_name�os�environ�path�
expandvars�keylog_filename)	�ssl_version�	cert_reqsrn�ciphers�ssl_minimum_version�ssl_maximum_versionrq�context�
sslkeylogfiles	         r�create_urllib3_contextr��s��N���Q�R�R��4��/B�C�C��*�.A�.M��A��
�#>�"A�"A��Z�9�9�#��#>�"A�"A��Z�9�9�#��
�M�M�M�&��	
��,�-�G��&�"5���",�"4�"4����&�"5�������G�$�&/�%6��!�!�I�I������;����;���	�$�$��
	�<����O�O�w��O��������w�&��5�5�L��.�.�L����L�(���w�-�t�4�@�&*��#��C�%�%�%�l�'���!%���!&���'���*/�G�'��"�*�*�$����*�*�2�:�:�>�>�/�+J�K�
��
��"/����Nrc
��y�Nr%�
�sock�keyfile�certfiler|�ca_certs�server_hostnamer{r}�ssl_context�ca_cert_dir�key_password�ca_cert_data�
tls_in_tlss
             r�ssl_wrap_socketr�Gs��rc
��yr�r%r�s
             rr�r�Ys��(+rc
��|}
|
�t|||��}
|s|	s|r	|
j||	|�n|�t	|
d�r|
j�|r|
�t
|�rtd��|r(|
�|
j||�n|
j|||
�|
jt�t||
||�}|S#t$r}t|�|�d}~wwxYw)a�
    All arguments except for server_hostname, ssl_context, tls_in_tls, ca_cert_data and
    ca_cert_dir have the same meaning as they do when using
    :func:`ssl.create_default_context`, :meth:`ssl.SSLContext.load_cert_chain`,
    :meth:`ssl.SSLContext.set_ciphers` and :meth:`ssl.SSLContext.wrap_socket`.

    :param server_hostname:
        When SNI is supported, the expected hostname of the certificate
    :param ssl_context:
        A pre-made :class:`SSLContext` object. If none is provided, one will
        be created using :func:`create_urllib3_context`.
    :param ciphers:
        A string of ciphers we wish the client to support.
    :param ca_cert_dir:
        A directory containing CA certificates in multiple separate files, as
        supported by OpenSSL's -CApath flag or the capath argument to
        SSLContext.load_verify_locations().
    :param key_password:
        Optional password if the keyfile is encrypted.
    :param ca_cert_data:
        Optional string containing CA certificates in PEM format suitable for
        passing as the cadata parameter to SSLContext.load_verify_locations()
    :param tls_in_tls:
        Use SSLTransport to wrap the existing socket.
    N)r}�load_default_certsz5Client private key is encrypted, password is required)r��load_verify_locations�OSErrorr�hasattrr��_is_key_file_encrypted�load_cert_chain�set_alpn_protocols�ALPN_PROTOCOLS�_ssl_wrap_socket_impl)r�r�r�r|r�r�r{r}r�r�r�r�r�r��e�ssl_socks                rr�r�ks���P�G���)��i��Q���;�,�	%��)�)�(�K��N�
�	���2F�!G��"�"�$�
�<�'�,B�7�,K��N�O�O�����#�#�H�g�6��#�#�H�g�|�D����~�.�$�T�7�J��P�H��O��-�	%��1�+�1�$��	%�s�B5�5	C�>C
�
Cc��t|t�r|jd�}tt	j
|�xst
j
|��S)z�Detects whether the hostname given is an IPv4 or IPv6 address.
    Also detects IPv6 addresses with Zone IDs.

    :param str hostname: Hostname to examine.
    :return: True if the hostname is an IP address, False otherwise.
    �ascii)rQ�bytes�decode�boolr
�matchr	)�hostnames r�is_ipaddressr��sA���(�E�"��?�?�7�+������x�(�T�,D�,J�,J�8�,T�U�Urc�p�t|�5}|D]}d|vs�ddd�y	ddd�y#1swYyxYw)z*Detects if a key file is encrypted or not.�	ENCRYPTEDNTF)�open)�key_file�f�lines   rr�r��sI��	
�h���1��	�D��d�"��	��	���
��s�
,�,�,�5c��|r3tstd��tj|�t|||�S|j||��S)Nz0TLS in TLS requires support for the 'ssl' module)r�)rr�$_validate_ssl_context_for_tls_in_tls�wrap_socket)r�r�r�r�s    rr�r��sO����(�B��
�	�9�9�+�F��D�+��?�?��"�"�4��"�I�Ir)rr�returnr�)rHzbytes | NonerIrr��None)rU�None | int | strr�r)rUr�r�r[)NNNNNNN)r{�
int | Noner|r�rnr�r}�
str | Noner~r�rr�rqr�r��ssl.SSLContext)............)r��
socket.socketr�r�r�r�r|r�r�r�r�r�r{r�r}r�r��ssl.SSLContext | Noner�r�r�r�r��None | str | bytesr�ztyping.Literal[False]r�z
ssl.SSLSocket)r�r�r�r�r�r�r|r�r�r�r�r�r{r�r}r�r�r�r�r�r�r�r�r�r�r�r�� ssl.SSLSocket | SSLTransportType)NNNNNNNNNNNF)r�zstr | bytesr�r�)r�rr�r�r�)
r�r�r�r�r�r�r�r�r�r�)A�
__future__r�hashlibrErv�socketrorYrh�binasciir�
exceptionsrr�urlr	r
r3rr)rrr��tupler[r�_TYPE_VERSION_INFOrRrAr�
TYPE_CHECKINGrSrr�ssltransport�SSLTransportTyperr'r$r(r*r+r,r-r.r/r0r1r2r4�PROTOCOL_SSLv23�attr�AttributeError�ImportError�Unionr��_TYPE_PEER_CERT_RETrNrWr\r��overloadr�r�r�r�)�length�	algorithms00r�<module>r�s���"���	�
�
�
���9�3�
�
���#��������3��S�#�s�2�3��
I����	��G�G�Y��-�-������	��
���� �>��9�E��/1��^�0�.������ #�O�#�+S��,�',�#�0���	�LS��D�M�'���y���5G�(H�I��+��l�l�#=�u�d�#J�K��
�D�.
�"#� ���&*�&*�#�P��P��P��P��	P�
$�P�$�
P��P��P�f�������"%�!��),�!�"�'*�(+��
��
�����	�
�� �
�����'������%��&������"�������"%�!��),�!�"�'*��+�
�+�
�+��+��	+�
�+� �
+��+��+�'�+��+��+�%�+��+�&�+��+�&�� ��"&�"��)-�"�#�'+��G�
�G�
�G��G��	G�
�G� �
G��G��G�'�G��G��G�%�G��G�&�G�T
V��#'�	J�
�J��J��J� �	J�
&�J��k
��B�	��	�������L��K��K�%&�&�O�l��� '�����s<�G/�(5H�G5�4H�5G>�:H�=G>�>H�H�H

Youez - 2016 - github.com/yon3zu
LinuXploit