Uname:Linux developmentwebsite.ca 4.18.0-553.168.1.el8_10.x86_64 #1 SMP Thu Sep 24 18:05:46 UTC 2026 x86_64

403WebShell
403Webshell
Server IP : 173.249.148.11  /  Your IP : 216.73.216.179
Web Server : Apache/2.4.68 (AlmaLinux)
System : Linux developmentwebsite.ca 4.18.0-553.168.1.el8_10.x86_64 #1 SMP Thu Sep 24 18:05:46 UTC 2026 x86_64
User : devinter ( 1006)
PHP Version : 8.3.35
Disable Function : NONE
MySQL : ON  |  cURL : ON  |  WGET : ON  |  Perl : ON  |  Python : ON  |  Sudo : ON  |  Pkexec : ON
Directory :  /snap/certbot/current/lib/python3.12/site-packages/OpenSSL/__pycache__/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Command :


[ Back ]     

Current File : /snap/certbot/current/lib/python3.12/site-packages/OpenSSL/__pycache__/crypto.cpython-312.pyc
�

��j1���@�UddlmZddlZddlZddlZddlZddlZddlmZddl	m
Z
ddlmZddlmZm
Z
mZejdk\rddlmZnddlmZdd	lmZmZdd
lmZmZmZmZmZddlmZddlmZdd
lm Z!ddlm"Z#ddlm$Z%ddlm&Z'ddlm(Z)gd�Z*eejVejXejZej\ej^fZ0eejbejdejfejhejjfZ6ee0e6fZ7ee8e
de8ffZ9e%jtZ;de<d<e%jzZ>de<d<dZ?e%j�ZAde<d<e%j�ZCde<d<e%j�ZEde<d<e%j�ZGde<d<Gd�deH�ZIee!eI�ZJe'eI�ZKdEdFd�ZLdGd�ZMdHd �ZNdId!�ZOdJd"�ZPGd#�d$�ZQGd%�d&�ZRGd'�d(�ZSed)�dKd*��ZTed+�dLd,��ZUed-�ej�Gd.�d/���ZWGd0�d1�ZXGd2�d3�ZYGd4�d5�ZZGd6�d7eH�Z[Gd8�d9�Z\dMd:�Z]dNd;�Z^dOd<�Z_		dP									dQd=�Z`e`Zaej"e`ebd>ecd?�@�GdA�dB�ZddRdC�Ze	dE							dSdD�Zfy)T�)�annotationsN)�	b16encode)�Sequence)�partial)�Any�Callable�Union)��
)�
deprecated)�utils�x509)�dsa�ec�ed448�ed25519�rsa)�StrOrBytesPath)�byte_string)�exception_from_error_queue)�ffi)�lib)�make_assert)�
path_bytes)�
FILETYPE_ASN1�FILETYPE_PEM�
FILETYPE_TEXT�TYPE_DSA�TYPE_RSA�X509�Error�PKey�X509Name�	X509Store�X509StoreContext�X509StoreContextError�X509StoreFlags�dump_certificate�dump_privatekey�dump_publickey�get_elliptic_curve�get_elliptic_curves�load_certificate�load_privatekey�load_publickey.�intrri��rr�TYPE_DH�TYPE_ECc��eZdZdZy)r!z7
    An error occurred in an `OpenSSL.crypto` API.
    N)�__name__�
__module__�__qualname__�__doc__���J/root/parts/certbot/install/lib/python3.12/site-packages/OpenSSL/crypto.pyr!r!js��r9r!c�T�|�8tjtj��}tj}n;t	j
d|�}tj|t|��}|fdd�}t|tjk7�t	j||�}|S)z�
    Allocate a new OpenSSL memory BIO.

    Arrange for the garbage collector to clean it up automatically.

    :param buffer: None or some bytes to use to put into the BIO so that they
        can be read out.
    �char[]c�,�tj|�S�N)�_lib�BIO_free)�bio�refs  r:�freez_new_mem_buf.<locals>.free�s���=�=��%�%r9)rArrBr�returnr)r?�BIO_new�	BIO_s_memr@�_ffi�new�BIO_new_mem_buf�len�_openssl_assert�NULL�gc)�bufferrArC�datas    r:�_new_mem_bufrPts���~��l�l�4�>�>�+�,���}�}���x�x��&�)���"�"�4��V��5��'+�	&��C�4�9�9�$�%�
�'�'�#�t�
�C��Jr9c��tjd�}tj||�}tj|d|�ddS)zO
    Copy the contents of an OpenSSL BIO object into a Python byte string.
    zchar**rN)rGrHr?�BIO_get_mem_datarN)rA�
result_buffer�
buffer_lengths   r:�_bio_to_stringrU�s?���H�H�X�&�M��)�)�#�}�=�M��;�;�}�Q�'��7��:�:r9c��t|t�std��t|tj
k7�t
j||�}|dk(rtd��y)a�
    The the time value of an ASN1 time object.

    @param boundary: An ASN1_TIME pointer (or an object safely
        castable to that type) which will have its value set.
    @param when: A string representation of the desired time value.

    @raise TypeError: If C{when} is not a L{bytes} string.
    @raise ValueError: If C{when} does not represent a time in the required
        format.
    @raise RuntimeError: If the time value cannot be set for some other
        (unspecified) reason.
    zwhen must be a byte stringrzInvalid stringN)	�
isinstance�bytes�	TypeErrorrKrGrLr?�ASN1_TIME_set_string�
ValueError)�boundary�when�
set_results   r:�_set_asn1_timer_�sW���d�E�"��4�5�5��H��	�	�)�*��*�*�8�T�:�J��Q���)�*�*�r9c���tj�}t|tjk7�tj
|tj�}t||�|S)a�
    Behaves like _set_asn1_time but returns a new ASN1_TIME object.

    @param when: A string representation of the desired time value.

    @raise TypeError: If C{when} is not a L{bytes} string.
    @raise ValueError: If C{when} does not represent a time in the required
        format.
    @raise RuntimeError: If the time value cannot be set for some other
        (unspecified) reason.
    )r?�
ASN1_TIME_newrKrGrLrM�ASN1_TIME_freer_)r]�rets  r:�_new_asn1_timerd�sH���
�
�
�C��C�4�9�9�$�%�
�'�'�#�t�*�*�
+�C��3����Jr9c�J�tjd|�}tj|�dk(rytj|�tj
k(r(tjtj|��Stjd�}tj||�t|dtjk7�tjd|d�}tj|�}tj|�}tj|d�|S)a]
    Retrieve the time value of an ASN1 time object.

    @param timestamp: An ASN1_GENERALIZEDTIME* (or an object safely castable to
        that type) from which the time value will be retrieved.

    @return: The time value from C{timestamp} as a L{bytes} string in a certain
        format.  Or C{None} if the object contains no time value.
    zASN1_STRING*rNzASN1_GENERALIZEDTIME**)
rG�castr?�ASN1_STRING_length�ASN1_STRING_type�V_ASN1_GENERALIZEDTIME�string�ASN1_STRING_get0_datarH�ASN1_TIME_to_generalizedtimerKrL�ASN1_GENERALIZEDTIME_free)�	timestamp�string_timestamp�generalized_timestamp�string_data�
string_results     r:�_get_asn1_timers�s����y�y���;�����/�0�A�5�����.�/�4�3N�3N�N��{�{�4�5�5�6F�G�H�H� $���)A� B���)�)�)�5J�K��-�a�0�D�I�I�=�>��9�9�^�5J�1�5M�N���0�0�1A�B�����K�0�
��&�&�'<�Q�'?�@��r9c�$�eZdZdd�Zdd�Zdd�Zy)�_X509NameInvalidatorc��g|_yr>)�_names��selfs r:�__init__z_X509NameInvalidator.__init__�s	��&(��r9c�:�|jj|�yr>)rw�append�ry�names  r:�addz_X509NameInvalidator.add�s�������4� r9c�*�|jD]}|`�yr>)rw�_namer}s  r:�clearz_X509NameInvalidator.clear�s���K�K�	�D��
�	r9N�rD�None�r~r#rDr�)r4r5r6rzrr�r8r9r:ruru�s��)�!�r9ruc��eZdZdZdZdZdd�Zdd�Zedd��Z	e
d�dd��Ze
d	�dd
��Zdd�Z
dd�Zy
)r"zD
    A class representing an DSA or RSA public key or key pair.
    FTc��tj�}tj|tj�|_d|_y)NF)r?�EVP_PKEY_newrGrM�
EVP_PKEY_free�_pkey�_initialized�ry�pkeys  r:rzz
PKey.__init__�s0��� � �"���W�W�T�4�#5�#5�6��
�!��r9c���ddlm}m}|jr0t	t
|�}t
jt||��Stt
|�}t
jt||d���S)a
        Export as a ``cryptography`` key.

        :rtype: One of ``cryptography``'s `key interfaces`_.

        .. _key interfaces: https://cryptography.io/en/latest/hazmat/            primitives/asymmetric/rsa/#key-interfaces

        .. versionadded:: 16.1.0
        r)�load_der_private_key�load_der_public_keyN)�password)
�,cryptography.hazmat.primitives.serializationr�r��_only_publicr*r�typingrf�_Key�_dump_privatekey_internal)ryr�r��ders    r:�to_cryptography_keyzPKey.to_cryptography_key�sZ��	
�
��� ���5�C��;�;�t�%8��%=�>�>�+�M�4�@�C��;�;�t�%9�#��%M�N�Nr9c
��t|tjtjtj
tjtjtjtjtjtjtjf
�st!d��ddlm}m}m}m}t|tjtjtjtjtjf�r4t-t.|j1|j2|j4��S|j7|j2|j8|��}t;t.|�S)z�
        Construct based on a ``cryptography`` *crypto_key*.

        :param crypto_key: A ``cryptography`` key.
        :type crypto_key: One of ``cryptography``'s `key interfaces`_.

        :rtype: PKey

        .. versionadded:: 16.1.0
        zUnsupported key typer)�Encoding�NoEncryption�
PrivateFormat�PublicFormat)rWr�
DSAPrivateKey�DSAPublicKeyr�EllipticCurvePrivateKey�EllipticCurvePublicKeyr�Ed25519PrivateKey�Ed25519PublicKeyr�Ed448PrivateKey�Ed448PublicKeyr�
RSAPrivateKey�RSAPublicKeyrYr�r�r�r�r�r/r�public_bytes�DER�SubjectPublicKeyInfo�
private_bytes�PKCS8r.)�cls�
crypto_keyr�r�r�r�r�s       r:�from_cryptography_keyzPKey.from_cryptography_keys(�����!�!�� � ��*�*��)�)��)�)��(�(��%�%��$�$��!�!�� � �
�
��2�3�3�	
�	
���� � ��)�)��(�(��$�$�� � �
�	
�"���'�'��L�L�,�"C�"C���
��*�*����m�1�1�<�>��C�#�=�#�6�6r9z`PKey.generate_key is deprecated. You should use the key generation APIs in cryptography instead.c	��t|t�std��t|t�std��|tk(r�|dkrt	d��tj�}tj|t
j�}tj|t
j�tj�}tj|||tj�}t|dk(�tj |j"|�}t|dk(�d|_y|t$k(�r
tj&�}t|tjk7�tj|t
j(�}tj*||tjdtjtjtj�}t|dk(�ttj,|�dk(�ttj.|j"|�dk(�d|_yt1d��)	a3
        Generate a key pair of the given type, with the given number of bits.

        This generates a key "into" the this object.

        :param type: The key type.
        :type type: :py:data:`TYPE_RSA` or :py:data:`TYPE_DSA`
        :param bits: The number of bits.
        :type bits: :py:data:`int` ``>= 0``
        :raises TypeError: If :py:data:`type` or :py:data:`bits` isn't
            of the appropriate type.
        :raises ValueError: If the number of bits isn't an integer of
            the appropriate size.
        :return: ``None``
        ztype must be an integerzbits must be an integerrzInvalid number of bits�zNo such key typeTN)rWr0rYrr[r?�BN_newrGrM�BN_free�BN_set_word�RSA_F4�RSA_new�RSA_generate_key_exrLrK�EVP_PKEY_assign_RSAr�r�DSA_new�DSA_free�DSA_generate_parameters_ex�DSA_generate_key�EVP_PKEY_set1_DSAr!r�)ry�type�bits�exponentr�resultr�ress        r:�generate_keyzPKey.generate_keyKs���(�$��$��5�6�6��$��$��5�6�6��8���q�y� �!9�:�:��{�{�}�H��w�w�x����6�H����X�t�{�{�3��,�,�.�C��-�-�c�4��4�9�9�M�F��F�a�K�(��-�-�d�j�j�#�>�F��F�a�K�(�"!����X�
��,�,�.�C��C�4�9�9�,�-��'�'�#�t�}�}�-�C��1�1��T�4�9�9�a����D�I�I�t�y�y��C�
�C�1�H�%��D�1�1�#�6�!�;�<��D�2�2�4�:�:�s�C�q�H�I�!����*�+�+r9zJPKey.check is deprecated. You should use the APIs in cryptography instead.c��|jrtd��tj|j	��tj
k7rtd��tj|j�}tj|tj�}tj|�}|dk(ryt�y)ax
        Check the consistency of an RSA private key.

        This is the Python equivalent of OpenSSL's ``RSA_check_key``.

        :return: ``True`` if key is consistent.

        :raise OpenSSL.crypto.Error: if the key is inconsistent.

        :raise TypeError: if the key is of a type which cannot be checked.
            Only RSA keys can currently be checked.
        zpublic key onlyz'Only RSA keys can currently be checked.r�TN)
r�rYr?�
EVP_PKEY_typer��EVP_PKEY_RSA�EVP_PKEY_get1_RSAr�rGrM�RSA_free�
RSA_check_key�_raise_current_error)ryrr�s   r:�checkz
PKey.check�s���"����-�.�.����d�i�i�k�*�d�.?�.?�?��E�F�F��$�$�T�Z�Z�0���g�g�c�4�=�=�)���#�#�C�(���Q�;���r9c�@�tj|j�S)zT
        Returns the type of the key

        :return: The type of the key.
        )r?�EVP_PKEY_idr�rxs r:r�z	PKey.type�s������
�
�+�+r9c�@�tj|j�S)zh
        Returns the number of bits of the key

        :return: The number of bits of the key.
        )r?�
EVP_PKEY_bitsr�rxs r:r�z	PKey.bits�s���!�!�$�*�*�-�-r9Nr�)rDr�)r�r�rDr")r�r0r�r0rDr��rD�bool�rDr0)r4r5r6r7r�r�rzr��classmethodr�rr�r�r�r�r8r9r:r"r"�sz����L��L�"�
O�.�77��77�r�	3��6!�	�6!�p�	 ���	��4,�.r9r"c�v��eZdZdZdZd
�fd�Zedd��Zedd��Zedd��Z	d
d�Z
dd�Zdd	�Z�xZ
S)�_EllipticCurveaZ
    A representation of a supported elliptic curve.

    @cvar _curves: :py:obj:`None` until an attempt is made to load the curves.
        Thereafter, a :py:type:`set` containing :py:type:`_EllipticCurve`
        instances each of which represents one curve supported by the system.
    @type _curves: :py:type:`NoneType` or :py:type:`set`
    Nc�N��t|t�rt�|�
|�StS)z�
        Implement cooperation with the right-hand side argument of ``!=``.

        Python 3 seems to have dropped this cooperation in this very narrow
        circumstance.
        )rWr��super�__ne__�NotImplemented)ry�other�	__class__s  �r:r�z_EllipticCurve.__ne__�s$����e�^�,��7�>�%�(�(��r9c�����jtjd�}tjd|�}�j||�t	��fd�|D��S)z�
        Get the curves supported by OpenSSL.

        :param lib: The OpenSSL library binding object.

        :return: A :py:type:`set` of ``cls`` instances giving the names of the
            elliptic curves the underlying library supports.
        rzEC_builtin_curve[]c3�V�K�|] }�j�|j����"y�wr>)�from_nid�nid)�.0�cr�rs  ��r:�	<genexpr>z7_EllipticCurve._load_elliptic_curves.<locals>.<genexpr>�s �����D��3�<�<��Q�U�U�+�D�s�&))�EC_get_builtin_curvesrGrLrH�set)r�r�
num_curves�builtin_curvess``  r:�_load_elliptic_curvesz$_EllipticCurve._load_elliptic_curves�sO����.�.�t�y�y�!�<�
����"6�
�C��	�!�!�.�*�=��D�^�D�D�Dr9c�^�|j�|j|�|_|jS)a
        Get, cache, and return the curves supported by OpenSSL.

        :param lib: The OpenSSL library binding object.

        :return: A :py:type:`set` of ``cls`` instances giving the names of the
            elliptic curves the underlying library supports.
        )�_curvesr�)r�rs  r:�_get_elliptic_curvesz#_EllipticCurve._get_elliptic_curves�s*���;�;���3�3�C�8�C�K��{�{�r9c	�x�|||tj|j|��jd��S)a�
        Instantiate a new :py:class:`_EllipticCurve` associated with the given
        OpenSSL NID.

        :param lib: The OpenSSL library binding object.

        :param nid: The OpenSSL NID the resulting curve object will represent.
            This must be a curve NID (and not, for example, a hash NID) or
            subsequent operations will fail in unpredictable ways.
        :type nid: :py:class:`int`

        :return: The curve object.
        �ascii)rGrj�
OBJ_nid2sn�decode)r�rr�s   r:r�z_EllipticCurve.from_nid�s0���3��T�[�[�����)<�=�D�D�W�M�N�Nr9c�.�||_||_||_y)a�
        :param _lib: The :py:mod:`cryptography` binding instance used to
            interface with OpenSSL.

        :param _nid: The OpenSSL NID identifying the curve this object
            represents.
        :type _nid: :py:class:`int`

        :param name: The OpenSSL short name identifying the curve this object
            represents.
        :type name: :py:class:`unicode`
        N)r?�_nidr~)ryrr�r~s    r:rzz_EllipticCurve.__init__�s����	���	���	r9c�"�d|j�d�S)Nz<Curve �>�r~rxs r:�__repr__z_EllipticCurve.__repr__s������
�Q�'�'r9c��|jj|j�}tj|tj
�S)z�
        Create a new OpenSSL EC_KEY structure initialized to use this curve.

        The structure is automatically garbage collected when the Python object
        is garbage collected.
        )r?�EC_KEY_new_by_curve_namer�rGrM�EC_KEY_free)ry�keys  r:�
_to_EC_KEYz_EllipticCurve._to_EC_KEYs3���i�i�0�0����;���w�w�s�D�,�,�-�-r9�r�rrDr�)rrrD�set[_EllipticCurve])rrr�r0rDr�)rrr�r0r~�strrDr��rDr��rDr)r4r5r6r7r�r�r�r�r�r�rzr�r��
__classcell__�r�s@r:r�r��sc�����G�	��E��E�"�����O��O� �"(�.r9r�zSget_elliptic_curves is deprecated. You should use the APIs in cryptography instead.c�4�tjt�S)a�
    Return a set of objects representing the elliptic curves supported in the
    OpenSSL build in use.

    The curve objects have a :py:class:`unicode` ``name`` attribute by which
    they identify themselves.

    The curve objects are useful as values for the argument accepted by
    :py:meth:`Context.set_tmp_ecdh` to specify which elliptical curve should be
    used for ECDHE key exchange.
    )r�r�r?r8r9r:r,r,s�� �.�.�t�4�4r9zRget_elliptic_curve is deprecated. You should use the APIs in cryptography instead.c�^�t�D]}|j|k(s�|cStd|��)aT
    Return a single curve object selected by name.

    See :py:func:`get_elliptic_curves` for information about curve objects.

    :param name: The OpenSSL short name identifying the curve object to
        retrieve.
    :type name: :py:class:`unicode`

    If the named curve is not supported then :py:class:`ValueError` is raised.
    zunknown curve name)r,r~r[)r~�curves  r:r+r+0s7�� %�&����:�:����L���)�4�
0�0r9zUX509Name support in pyOpenSSL is deprecated. You should use the APIs in cryptography.c�d��eZdZdZdd�Zd�fd�Zd
d�Zdd�Zdd�Zdd�Z	dd�Z
dd	�Zdd
�Z�xZ
S)r#a
    An X.509 Distinguished Name.

    :ivar countryName: The country of the entity.
    :ivar C: Alias for  :py:attr:`countryName`.

    :ivar stateOrProvinceName: The state or province of the entity.
    :ivar ST: Alias for :py:attr:`stateOrProvinceName`.

    :ivar localityName: The locality of the entity.
    :ivar L: Alias for :py:attr:`localityName`.

    :ivar organizationName: The organization name of the entity.
    :ivar O: Alias for :py:attr:`organizationName`.

    :ivar organizationalUnitName: The organizational unit of the entity.
    :ivar OU: Alias for :py:attr:`organizationalUnitName`

    :ivar commonName: The common name of the entity.
    :ivar CN: Alias for :py:attr:`commonName`.

    :ivar emailAddress: The e-mail address of the entity.
    c��tj|j�}tj|tj
�|_y)z�
        Create a new X509Name, copying the given X509Name instance.

        :param name: The name to copy.
        :type name: :py:class:`X509Name`
        N)r?�
X509_NAME_dupr�rGrM�X509_NAME_freer}s  r:rzzX509Name.__init__ds0���!�!�$�*�*�-���'�'�$��(;�(;�<��
r9c	���|jd�rt�	|�	||�St|�tur#tdt|�jd�d���tjt|��}|tjk(r	t�td��ttj|j ��D]�}tj"|j |�}tj$|�}tj&|�}||k(s�Stj(|j |�}tj*|�nt-|t�r|j/d�}tj0|j |tj2|t5|�dd�}|st�yy#t$r
Ytd��wxYw)	N�_z$attribute name must be string, not 'z.200�'�No such attribute�utf-8���r)�
startswithr��__setattr__r�r�rYr4r?�OBJ_txt2nid�_byte_string�	NID_undefr�r!�AttributeError�range�X509_NAME_entry_countr��X509_NAME_get_entry�X509_NAME_ENTRY_get_object�OBJ_obj2nid�X509_NAME_delete_entry�X509_NAME_ENTRY_freerW�encode�X509_NAME_add_entry_by_NID�
MBSTRING_UTF8rJ)
ryr~�valuer��i�ent�ent_obj�ent_nid�
add_resultr�s
         �r:rzX509Name.__setattr__ns�����?�?�3���7�&�t�U�3�3���:�S� �����K�(�(��.�a�1��
�
���|�D�1�2���$�.�.� �
�$�&�!�!4�5�5��t�1�1�$�*�*�=�>�	�A��*�*�4�:�:�q�9�C��5�5�c�:�G��&�&�w�/�G��g�~��1�1�$�*�*�a�@���)�)�#�.��	��e�S�!��L�L��)�E��4�4��J�J��T�/�/���E�
�B��
�
�� �"���)�
�� �!4�5�5�
�s�	
F<�<	G�Gc��tjt|��}|tjk(r	t	�t
d��tj|j|d�}|dk(rytj|j|�}tj|�}tjd�}tj||�}t|dk\�	tj|d|�ddj!d�}tj"|d�|S#t
$r
Yt
d��wxYw#tj"|d�wxYw)a

        Find attribute. An X509Name object has the following attributes:
        countryName (alias C), stateOrProvince (alias ST), locality (alias L),
        organization (alias O), organizationalUnit (alias OU), commonName
        (alias CN) and more...
        rr
N�unsigned char**rr)r?rrrr�r!r�X509_NAME_get_index_by_NIDr�r�X509_NAME_ENTRY_get_datarGrH�ASN1_STRING_to_UTF8rKrNr��OPENSSL_free)	ryr~r��entry_index�entryrOrS�data_lengthr�s	         r:�__getattr__zX509Name.__getattr__�s2�����|�D�1�2���$�.�.� �
�$�&�!�!4�5�5��5�5�d�j�j�#�r�J���"����(�(����[�A���,�,�U�3�����!2�3�
��.�.�}�d�C����q�(�)�	0��[�[��q�!1�;�?��B�I�I���F�

���m�A�.�/��
��-�
�� �!4�5�5�
��*
���m�A�.�/�s�
D#�+D<�#	D9�8D9�<Ec��t|t�stStj|j
|j
�dk(S�Nr�rWr#r�r?�
X509_NAME_cmpr��ryr�s  r:�__eq__zX509Name.__eq__�s2���%��*�!�!��!�!�$�*�*�e�k�k�:�a�?�?r9c��t|t�stStj|j
|j
�dkSr/r0r2s  r:�__lt__zX509Name.__lt__�s2���%��*�!�!��!�!�$�*�*�e�k�k�:�Q�>�>r9c� �tjdd�}tj|j|t|��}t
|tjk7�djtj|�jd��S)z6
        String representation of an X509Name
        r<iz<X509Name object '{}'>r)rGrHr?�X509_NAME_oneliner�rJrKrL�formatrjr�)ryrS�
format_results   r:r�zX509Name.__repr__�sq������3�/�
��.�.��J�J�
�s�=�'9�
�
�	�
����2�3�'�.�.��K�K�
�&�-�-�g�6�
�	
r9c�@�tj|j�S)a&
        Return an integer representation of the first four bytes of the
        MD5 digest of the DER representation of the name.

        This is the Python equivalent of OpenSSL's ``X509_NAME_hash``.

        :return: The (integer) hash of this name.
        :rtype: :py:class:`int`
        )r?�X509_NAME_hashr�rxs r:�hashz
X509Name.hash�s���"�"�4�:�:�.�.r9c���tjd�}tj|j|�}t|dk\�tj|d|�dd}tj|d�|S)z�
        Return the DER encoding of this name.

        :return: The DER encoded form of this name.
        :rtype: :py:class:`bytes`
        r%rN)rGrHr?�
i2d_X509_NAMEr�rKrNr))ryrS�
encode_resultrrs    r:r�zX509Name.der�si�����!2�3�
��*�*�4�:�:�}�E�
��
��*�+����M�!�$4�m�D�Q�G�
����-��*�+��r9c��g}ttj|j��D]�}tj|j|�}tj
|�}tj|�}tj|�}tj|�}tjtj|�tj|��dd}|jtj|�|f���|S)z�
        Returns the components of this name, as a sequence of 2-tuples.

        :return: The components of this name.
        :rtype: :py:class:`list` of ``name, value`` tuples.
        N)rr?rr�rrr'rr�rGrNrkrgr|rj)	ryr�rr �fname�fvalr�r~rs	         r:�get_componentszX509Name.get_components�s������t�1�1�$�*�*�=�>�	6�A��*�*�4�:�:�q�9�C��3�3�C�8�E��0�0��5�D��"�"�5�)�C��?�?�3�'�D��K�K��*�*�4�0�$�2I�2I�$�2O����E�
�M�M�4�;�;�t�,�e�4�5�	6� �
r9r�)r~r�rrrDr�)r~r�rD�
str | Noner�r�r��rDrX)rDzlist[tuple[bytes, bytes]])r4r5r6r7rzrr-r3r5r�r<r�rCr�rs@r:r#r#Fs8����0=�%#�N&�P@�?�
�
/�
�r9r#c�(�eZdZdZd-d�Zed.d��Zd/d�Zed0d��Ze	d�d1d��Z
d2d�Zd3d	�Ze	d
�d4d��Z
e	d�d5d
��Zd6d�Zd7d�Zd2d�Ze	d�d8d��Zd2d�Ze	d�d9d��Ze	d�d9d��Zd:d�Zd;d�Zd<d�Z						d=d�Ze	d�d>d��Zd<d�Ze	d�d>d ��Zd?d!�Zd@d"�Ze	d#�dAd$��Ze	d%�dBd&��Z e	d'�dAd(��Z!e	d)�dCd*��Z"d2d+�Z#y,)Dr z
    An X.509 certificate.
    c���tj�}t|tjk7�tj
|tj�|_t�|_	t�|_
yr>)r?�X509_newrKrGrLrM�	X509_free�_x509ru�_issuer_invalidator�_subject_invalidator)ryrs  r:rzz
X509.__init__sJ���}�}������	�	�)�*��W�W�T�4�>�>�2��
�#7�#9�� �$8�$:��!r9c��|j|�}tj|tj�|_t
�|_t
�|_|Sr>)	�__new__rGrMr?rIrJrurKrL)r�r�certs   r:�_from_raw_x509_ptrzX509._from_raw_x509_ptrsA���{�{�3����W�W�T�4�>�>�2��
�#7�#9�� �$8�$:��!��r9c�>�ddlm}tt|�}||�S)z�
        Export as a ``cryptography`` certificate.

        :rtype: ``cryptography.x509.Certificate``

        .. versionadded:: 17.1.0
        r)�load_der_x509_certificate)�cryptography.x509rRr(r)ryrRr�s   r:�to_cryptographyzX509.to_cryptography"s��	@��}�d�3��(��-�-r9c��t|tj�std��ddlm}|j
|j�}tt|�S)z�
        Construct based on a ``cryptography`` *crypto_cert*.

        :param crypto_key: A ``cryptography`` X.509 certificate.
        :type crypto_key: ``cryptography.x509.Certificate``

        :rtype: X509

        .. versionadded:: 17.1.0
        zMust be a certificater�r�)
rWr�CertificaterYr�r�r�r�r-r)r��crypto_certr�r�s    r:�from_cryptographyzX509.from_cryptography/sD���+�t�'7�'7�8��3�4�4�I��&�&�x�|�|�4���
�s�3�3r9zYX509.set_version is deprecated. You should use cryptography's CertificateBuilder instead.c��t|t�std��tt	j
|j|�dk(�y)a	
        Set the version number of the certificate. Note that the
        version value is zero-based, eg. a value of 0 is V1.

        :param version: The version number of the certificate.
        :type version: :py:class:`int`

        :return: ``None``
        zversion must be an integerr�N)rWr0rYrKr?�X509_set_versionrJ)ry�versions  r:�set_versionzX509.set_versionCs8���'�3�'��8�9�9���-�-�d�j�j�'�B�a�G�Hr9c�@�tj|j�S)z�
        Return the version number of the certificate.

        :return: The version number of the certificate.
        :rtype: :py:class:`int`
        )r?�X509_get_versionrJrxs r:�get_versionzX509.get_versionVs���$�$�T�Z�Z�0�0r9c�B�tjt�}tj|j�|_|j
tjk(r
t�t
j|j
tj�|_d|_|S)z{
        Get the public key of the certificate.

        :return: The public key.
        :rtype: :py:class:`PKey`
        T)r"rNr?�X509_get_pubkeyrJr�rGrLr�rMr�r�r�s  r:�
get_pubkeyzX509.get_pubkey_sg���|�|�D�!���)�)�$�*�*�5��
��:�:����"� �"��W�W�T�Z�Z��);�);�<��
� ����r9zXX509.set_pubkey is deprecated. You should use cryptography's CertificateBuilder instead.c��t|t�std��tj|j
|j�}t|dk(�y)z�
        Set the public key of the certificate.

        :param pkey: The public key.
        :type pkey: :py:class:`PKey`

        :return: :py:data:`None`
        �pkey must be a PKey instancer�N)rWr"rYr?�X509_set_pubkeyrJr�rK)ryr�r^s   r:�
set_pubkeyzX509.set_pubkeyns@���$��%��:�;�;��)�)�$�*�*�d�j�j�A�
��
�a��(r9zRX509.sign is deprecated. You should use cryptography's CertificateBuilder instead.c��t|t�std��|jrt	d��|j
st	d��t
jt|��}|tjk(rt	d��t
j|j|j|�}t|dkD�y)a
        Sign the certificate with this key and digest type.

        :param pkey: The key to sign with.
        :type pkey: :py:class:`PKey`

        :param digest: The name of the message digest to use.
        :type digest: :py:class:`str`

        :return: :py:data:`None`
        rezKey only has public partzKey is uninitialized�No such digest methodrN)rWr"rYr�r[r�r?�EVP_get_digestbynamerrGrL�	X509_signrJr�rK)ryr��digest�evp_md�sign_results     r:�signz	X509.sign�s��� �$��%��:�;�;�����7�8�8�� � ��3�4�4��*�*�<��+?�@���T�Y�Y���4�5�5��n�n�T�Z�Z����V�D����a��(r9c��tj|j�}tjd�}tj
|tjtj|�tj|d�}|tjk(rtd��tjtj|��S)z�
        Return the signature algorithm used in the certificate.

        :return: The name of the algorithm.
        :rtype: :py:class:`bytes`

        :raises ValueError: If the signature algorithm is undefined.

        .. versionadded:: 0.13
        zASN1_OBJECT **rzUndefined signature algorithm)r?�X509_get0_tbs_sigalgrJrGrH�X509_ALGOR_get0rLrrr[rj�
OBJ_nid2ln)ry�sig_alg�algr�s    r:�get_signature_algorithmzX509.get_signature_algorithm�s����+�+�D�J�J�7���h�h�'�(�����S�$�)�)�T�Y�Y��@����s�1�v�&���$�.�.� ��<�=�=��{�{�4�?�?�3�/�0�0r9c��tjt|��}|tjk(rtd��tjdtj�}tjdd�}t|�|d<tj|j|||�}t|dk(�djtj||d�D�cgc]}t|�j���c}�Scc}w)a5
        Return the digest of the X509 object.

        :param digest_name: The name of the digest algorithm to use.
        :type digest_name: :py:class:`str`

        :return: The digest of the object, formatted as
            :py:const:`b":"`-delimited hex pairs.
        :rtype: :py:class:`bytes`
        rizunsigned char[]zunsigned int[]r�r�:)r?rjrrGrLr[rH�EVP_MAX_MD_SIZErJ�X509_digestrJrK�joinrNr�upper)ry�digest_namerlrS�
result_length�
digest_result�chs       r:rlzX509.digest�s����*�*�<��+D�E���T�Y�Y���4�5�5����!2�D�4H�4H�I�
����!1�1�5�
��}�-�
�a���(�(��J�J��
�}�
�
�	�
��*�+��y�y��+�+�m�]�1�5E�F�
���"�
�#�#�%�
�
�	
��
s� Dc�@�tj|j�S)z�
        Return the hash of the X509 subject.

        :return: The hash of the subject.
        :rtype: :py:class:`int`
        )r?�X509_subject_name_hashrJrxs r:�subject_name_hashzX509.subject_name_hash�s���*�*�4�:�:�6�6r9z_X509.set_serial_number is deprecated. You should use cryptography's CertificateBuilder instead.c�`�t|t�std��t|�dd}|j	d�}tjd�}tj||�}t|t
jk7�tj|dt
j�}tj|d�t|t
jk7�tj|tj�}tj|j |�}t|dk(�y)z�
        Set the serial number of the certificate.

        :param serial: The new serial number.
        :type serial: :py:class:`int`

        :return: :py:data`None`
        zserial must be an integer�Nr�zBIGNUM**rr�)rWr0rY�hexrrGrHr?�	BN_hex2bnrKrL�BN_to_ASN1_INTEGERr�rM�ASN1_INTEGER_free�X509_set_serialNumberrJ)ry�serial�
hex_serial�hex_serial_bytes�
bignum_serialr��asn1_serialr^s        r:�set_serial_numberzX509.set_serial_number�s����&�#�&��7�8�8���[���_�
�%�,�,�W�5������,�
����
�/?�@����$�)�)�+�,��-�-�m�A�.>��	�	�J�����]�1�%�&���t�y�y�0�1��g�g�k�4�+A�+A�B���/�/��
�
�K�H�
��
�a��(r9c��tj|j�}tj|tj
�}	tj|�}	t	j|�}t|d�}|tj|�tj|�S#tj|�wxYw#tj|�wxYw)zx
        Return the serial number of this certificate.

        :return: The serial number.
        :rtype: int
        �)r?�X509_get_serialNumberrJ�ASN1_INTEGER_to_BNrGrL�	BN_bn2hexrjr0r)r�)ryr�r�r��hexstring_serialr�s      r:�get_serial_numberzX509.get_serial_number�s����0�0����<���/�/��T�Y�Y�G�
�		(����
�6�J�
.�#'�;�;�z�#:� ��-�r�2����!�!�*�-��L�L��'���!�!�*�-���L�L��'�s$�C�"B(�=C�(B?�?C�CzaX509.gmtime_adj_notAfter is deprecated. You should use cryptography's CertificateBuilder instead.c��t|t�std��tj|j
�}tj||�y)z�
        Adjust the time stamp on which the certificate stops being valid.

        :param int amount: The number of seconds by which to adjust the
            timestamp.
        :return: ``None``
        �amount must be an integerN)rWr0rYr?�X509_getm_notAfterrJ�X509_gmtime_adj)ry�amount�notAfters   r:�gmtime_adj_notAfterzX509.gmtime_adj_notAfters>���&�#�&��7�8�8��*�*�4�:�:�6�����X�v�.r9zbX509.gmtime_adj_notBefore is deprecated. You should use cryptography's CertificateBuilder instead.c��t|t�std��tj|j
�}tj||�y)z�
        Adjust the timestamp on which the certificate starts being valid.

        :param amount: The number of seconds by which to adjust the timestamp.
        :return: ``None``
        r�N)rWr0rYr?�X509_getm_notBeforerJr�)ryr��	notBefores   r:�gmtime_adj_notBeforezX509.gmtime_adj_notBefore"s>���&�#�&��7�8�8��,�,�T�Z�Z�8�	����Y��/r9c�:�|j�}|�td��|jd�}tjj	|d�}tj
j}tjj|�jd��}||kS)z�
        Check whether the certificate has expired.

        :return: ``True`` if the certificate has expired, ``False`` otherwise.
        :rtype: bool
        NzUnable to determine notAfterrz
%Y%m%d%H%M%SZ)�tzinfo)	�get_notAfterr[r��datetime�strptime�timezone�utc�now�replace)ry�
time_bytes�time_string�	not_after�UTC�utcnows      r:�has_expiredzX509.has_expired3s����&�&�(�
����;�<�<� �'�'��0���%�%�.�.�{�O�L�	����#�#���"�"�&�&�s�+�3�3�4�3�@���6�!�!r9c�8�t||j��Sr>)rsrJ)ry�whichs  r:�_get_boundary_timezX509._get_boundary_timeDs���e�D�J�J�/�0�0r9c�@�|jtj�S)a

        Get the timestamp at which the certificate starts being valid.

        The timestamp is formatted as an ASN.1 TIME::

            YYYYMMDDhhmmssZ

        :return: A timestamp string, or ``None`` if there is none.
        :rtype: bytes or NoneType
        )r�r?r�rxs r:�
get_notBeforezX509.get_notBeforeGs���&�&�t�'?�'?�@�@r9c�:�t||j�|�Sr>)r_rJ)ryr�r]s   r:�_set_boundary_timezX509._set_boundary_timeTs���e�D�J�J�/��6�6r9z[X509.set_notBefore is deprecated. You should use cryptography's CertificateBuilder instead.c�B�|jtj|�S)z�
        Set the timestamp at which the certificate starts being valid.

        The timestamp is formatted as an ASN.1 TIME::

            YYYYMMDDhhmmssZ

        :param bytes when: A timestamp string.
        :return: ``None``
        )r�r?r��ryr]s  r:�
set_notBeforezX509.set_notBeforeYs���&�&�t�'?�'?��F�Fr9c�@�|jtj�S)a	
        Get the timestamp at which the certificate stops being valid.

        The timestamp is formatted as an ASN.1 TIME::

            YYYYMMDDhhmmssZ

        :return: A timestamp string, or ``None`` if there is none.
        :rtype: bytes or NoneType
        )r�r?r�rxs r:r�zX509.get_notAfterjs���&�&�t�'>�'>�?�?r9zZX509.set_notAfter is deprecated. You should use cryptography's CertificateBuilder instead.c�B�|jtj|�S)z�
        Set the timestamp at which the certificate stops being valid.

        The timestamp is formatted as an ASN.1 TIME::

            YYYYMMDDhhmmssZ

        :param bytes when: A timestamp string.
        :return: ``None``
        )r�r?r�r�s  r:�set_notAfterzX509.set_notAfterws���&�&�t�'>�'>��E�Er9c��tjt�}||j�|_t|jtjk7�||_|Sr>)	�objectrNr#rJr�rKrGrL�_owner)ryr�r~s   r:�	_get_namezX509._get_name�sE���~�~�h�'���4�:�:�&��
���
�
�d�i�i�/�0�����r9c��t|t�std��||j|j�}t|dk(�y)Nzname must be an X509Namer�)rWr#rYrJr�rK)ryr�r~r^s    r:�	_set_namezX509._set_name�s8���$��)��6�7�7��4�:�:�t�z�z�2�
��
�a��(r9zPX509.get_issuer is deprecated. You should use cryptography's X.509 APIs instead.c�z�|jtj�}|jj	|�|S)a�
        Return the issuer of this certificate.

        This creates a new :class:`X509Name` that wraps the underlying issuer
        name field on the certificate. Modifying it will modify the underlying
        certificate, and will have the effect of modifying any other
        :class:`X509Name` that refers to this issuer.

        :return: The issuer of this certificate.
        :rtype: :class:`X509Name`
        )r�r?�X509_get_issuer_namerKrr}s  r:�
get_issuerzX509.get_issuer�s1�� �~�~�d�7�7�8��� � �$�$�T�*��r9zXX509.set_issuer is deprecated. You should use cryptography's CertificateBuilder instead.c�x�|jtj|�|jj	�y)z�
        Set the issuer of this certificate.

        :param issuer: The issuer.
        :type issuer: :py:class:`X509Name`

        :return: ``None``
        N)r�r?�X509_set_issuer_namerKr�)ry�issuers  r:�
set_issuerzX509.set_issuer�s*��	
���t�0�0�&�9�� � �&�&�(r9zQX509.get_subject is deprecated. You should use cryptography's X.509 APIs instead.c�z�|jtj�}|jj	|�|S)a�
        Return the subject of this certificate.

        This creates a new :class:`X509Name` that wraps the underlying subject
        name field on the certificate. Modifying it will modify the underlying
        certificate, and will have the effect of modifying any other
        :class:`X509Name` that refers to this subject.

        :return: The subject of this certificate.
        :rtype: :class:`X509Name`
        )r�r?�X509_get_subject_namerLrr}s  r:�get_subjectzX509.get_subject�s1�� �~�~�d�8�8�9���!�!�%�%�d�+��r9zYX509.set_subject is deprecated. You should use cryptography's CertificateBuilder instead.c�x�|jtj|�|jj	�y)z�
        Set the subject of this certificate.

        :param subject: The subject.
        :type subject: :py:class:`X509Name`

        :return: ``None``
        N)r�r?�X509_set_subject_namerLr�)ry�subjects  r:�set_subjectzX509.set_subject�s*��	
���t�1�1�7�;��!�!�'�'�)r9c�@�tj|j�S)z�
        Get the number of extensions on this certificate.

        :return: The number of extensions.
        :rtype: :py:class:`int`

        .. versionadded:: 0.12
        )r?�X509_get_ext_countrJrxs r:�get_extension_countzX509.get_extension_count�s���&�&�t�z�z�2�2r9Nr�)rrrDr )rD�x509.Certificate)rXr�rDr )r\r0rDr�r�)rDr")r�r"rDr�)r�r"rlr�rDr�rE)r}r�rDrX)r�r0rDr�)r�r0rDr�r�)r�rrD�bytes | None)rDr�)r�zCallable[..., Any]r]rXrDr�)r]rXrDr�)r�rrDr#)r�rr~r#rDr�)rDr#)r�r#rDr�)r�r#rDr�)$r4r5r6r7rzr�rPrTrYrr]r`rcrgrorvrlr�r�r�r�r�r�r�r�r�r�r�r�r�r�r�r�r�r�r�r8r9r:r r 
s���;�����.��4��4�&�	5��
I�	�
I�1�
��	5��
)�	�
)��	5��)�	�)�81�&
�>7��	5��)�	�)�8(�(�	5��/�	�/��	5��0�	�0�"�"1�A�7�'�7�/4�7�	
�7�
�	5��G�	�G�@��	5��F�	�F��)��	-���	�� �	5��
)�	�
)��	-���	�� �	5��
*�	�
*�	3r9r c�f�eZdZUdZej
Zded<ejZ	ded<ejZded<ejZ
ded<ejZded<ej Zded<ej$Zded	<ej(Zded
<ej,Zded<ej0Zded<y
)r'a
    Flags for X509 verification, used to change the behavior of
    :class:`X509Store`.

    See `OpenSSL Verification Flags`_ for details.

    .. _OpenSSL Verification Flags:
        https://www.openssl.org/docs/manmaster/man3/X509_VERIFY_PARAM_set_flags.html
    r0�	CRL_CHECK�
CRL_CHECK_ALL�IGNORE_CRITICAL�X509_STRICT�ALLOW_PROXY_CERTS�POLICY_CHECK�EXPLICIT_POLICY�INHIBIT_MAP�CHECK_SS_SIGNATURE�
PARTIAL_CHAINN)r4r5r6r7r?�X509_V_FLAG_CRL_CHECKr��__annotations__�X509_V_FLAG_CRL_CHECK_ALLr��X509_V_FLAG_IGNORE_CRITICALr��X509_V_FLAG_X509_STRICTr��X509_V_FLAG_ALLOW_PROXY_CERTSr��X509_V_FLAG_POLICY_CHECKr��X509_V_FLAG_EXPLICIT_POLICYr��X509_V_FLAG_INHIBIT_MAPr��X509_V_FLAG_CHECK_SS_SIGNATUREr��X509_V_FLAG_PARTIAL_CHAINr�r8r9r:r'r'�s�����/�/�I�s�/��7�7�M�3�7��;�;�O�S�;��3�3�K��3�!�?�?��s�?��5�5�L�#�5��;�;�O�S�;��3�3�K��3�"�A�A���A��7�7�M�3�7r9r'c�N�eZdZdZd	d�Zd
d�Zdd�Zdd�Zd
d�Z	d					dd�Z	y)r$a�
    An X.509 store.

    An X.509 store is used to describe a context in which to verify a
    certificate. A description of a context may include a set of certificates
    to trust, a set of certificate revocation lists, verification flags and
    more.

    An X.509 store, being only a description, cannot be used by itself to
    verify a certificate. To carry out the actual verification process, see
    :class:`X509StoreContext`.
    c�~�tj�}tj|tj�|_yr>)r?�X509_STORE_newrGrM�X509_STORE_free�_store�ry�stores  r:rzzX509Store.__init__s(���#�#�%���g�g�e�T�%9�%9�:��r9c��t|t�s
t��tj|j
|j�}t|dk(�y)a�
        Adds a trusted certificate to this store.

        Adding a certificate with this method adds this certificate as a
        *trusted* certificate.

        :param X509 cert: The certificate to add to this store.

        :raises TypeError: If the certificate is not an :class:`X509`.

        :raises OpenSSL.crypto.Error: If OpenSSL was unhappy with your
            certificate.

        :return: ``None`` if the certificate was added successfully.
        r�N)rWr rYr?�X509_STORE_add_certr�rJrK)ryrOr�s   r:�add_certzX509Store.add_certs<�� �$��%��+���&�&�t�{�{�D�J�J�?����q��!r9c���t|tj�r�ddlm}t|j
|j��}tj|tj�}t|tjk7�tj|tj�}ntd��ttj |j"|�dk7�y)a�
        Add a certificate revocation list to this store.

        The certificate revocation lists added to a store will only be used if
        the associated flags are configured to check certificate revocation
        lists.

        .. versionadded:: 16.1.0

        :param crl: The certificate revocation list to add to this store.
        :type crl: ``cryptography.x509.CertificateRevocationList``
        :return: ``None`` if the certificate revocation list was added
            successfully.
        rrVz?CRL must be of type cryptography.x509.CertificateRevocationListN)rWr�CertificateRevocationListr�r�rPr�r�r?�d2i_X509_CRL_biorGrLrKrM�
X509_CRL_freerY�X509_STORE_add_crlr�)ry�crlr�rA�openssl_crls     r:�add_crlzX509Store.add_crl.s����c�4�9�9�:�M��s�/�/����=�>�C��/�/��T�Y�Y�?�K��K�4�9�9�4�5��'�'�+�t�'9�'9�:�C��>��
�
	��/�/����S�A�Q�F�Gr9c�\�ttj|j|�dk7�y)a�
        Set verification flags to this store.

        Verification flags can be combined by oring them together.

        .. note::

          Setting a verification flag sometimes requires clients to add
          additional information to the store, otherwise a suitable error will
          be raised.

          For example, in setting flags to enable CRL checking a
          suitable CRL must be added to the store otherwise an error will be
          raised.

        .. versionadded:: 16.1.0

        :param int flags: The verification flags to set on this store.
            See :class:`X509StoreFlags` for available constants.
        :return: ``None`` if the verification flags were successfully set.
        rN)rKr?�X509_STORE_set_flagsr�)ry�flagss  r:�	set_flagszX509Store.set_flagsLs"��,	��1�1�$�+�+�u�E��J�Kr9c�:�tj�}tj|tj�}tj
|t
j|j���ttj|j|�dk7�y)a�
        Set the time against which the certificates are verified.

        Normally the current time is used.

        .. note::

          For example, you can determine if a certificate was valid at a given
          time.

        .. versionadded:: 17.0.0

        :param datetime vfy_time: The verification time to set on this store.
        :return: ``None`` if the verification time was successfully set.
        rN)r?�X509_VERIFY_PARAM_newrGrM�X509_VERIFY_PARAM_free�X509_VERIFY_PARAM_set_time�calendar�timegm�	timetuplerK�X509_STORE_set1_paramr�)ry�vfy_time�params   r:�set_timezX509Store.set_timedsm�� �*�*�,������t�:�:�;���'�'��8�?�?�8�#5�#5�#7�8�	
�	��2�2�4�;�;��F�!�K�Lr9Nc���|�tj}nt|�}|�tj}nt|�}tj|j
||�}|st
�yy)a�
        Let X509Store know where we can find trusted certificates for the
        certificate chain.  Note that the certificates have to be in PEM
        format.

        If *capath* is passed, it must be a directory prepared using the
        ``c_rehash`` tool included with OpenSSL.  Either, but not both, of
        *cafile* or *capath* may be ``None``.

        .. note::

          Both *cafile* and *capath* may be set simultaneously.

          Call this method multiple times to add more than one location.
          For example, CA certificates, and certificate revocation list bundles
          may be passed in *cafile* in subsequent calls to this method.

        .. versionadded:: 20.0

        :param cafile: In which file we can find the certificates (``bytes`` or
                       ``unicode``).
        :param capath: In which directory we can find the certificates
                       (``bytes`` or ``unicode``).

        :return: ``None`` if the locations were set successfully.

        :raises OpenSSL.crypto.Error: If both *cafile* and *capath* is ``None``
            or the locations could not be set for any reason.

        N)rGrL�_path_bytesr?�X509_STORE_load_locationsr�r�)ry�cafile�capath�load_results    r:�load_locationszX509Store.load_locations|s`��F�>��Y�Y�F� ��(�F��>��Y�Y�F� ��(�F��4�4��K�K���
��� �"�r9r�)rOr rDr�)r�zx509.CertificateRevocationListrDr�)rr0rDr�)rzdatetime.datetimerDr�r>)r�StrOrBytesPath | NonerrrDr�)
r4r5r6r7rzr�r�rrrr8r9r:r$r$sI���;�"�,H�<L�0M�6)-�1#�%�1#�&�1#�
�	1#r9r$c�4��eZdZdZ								d�fd�Z�xZS)r&z�
    An exception raised when an error occurred while verifying a certificate
    using `OpenSSL.X509StoreContext.verify_certificate`.

    :ivar certificate: The certificate which caused verificate failure.
    :type certificate: :class:`X509`
    c�@��t�|�|�||_||_yr>)r�rz�errors�certificate)ry�messagerrr�s    �r:rzzX509StoreContextError.__init__�s!���	����!����&��r9)rr�rz	list[Any]rr rDr�)r4r5r6r7rzr�rs@r:r&r&�s2����'��'�$-�'�<@�'�	
�'�'r9r&c�v�eZdZdZ	d
							dd�Ze				dd��Zed
d��Zdd�Zdd�Z	dd�Z
dd	�Zy)r%a9
    An X.509 store context.

    An X.509 store context is used to carry out the actual verification process
    of a certificate in a described context. For describing such a context, see
    :class:`X509Store`.

    :param X509Store store: The certificates which will be trusted for the
        purposes of any verifications.
    :param X509 certificate: The certificate to be verified.
    :param chain: List of untrusted certificates that may be used for building
        the certificate chain. May be ``None``.
    :type chain: :class:`list` of :class:`X509`
    Nc�L�||_||_|j|�|_yr>)r��_cert�_build_certificate_stack�_chain)ryr�r�chains    r:rzzX509StoreContext.__init__�s$����� ��
��3�3�E�:��r9c��dd�}|�t|�dk(rtjStj�}t|tjk7�tj||�}|D]�}t|t�std��ttj|j�dkD�tj||j�dks�mtj|j�t���|S)Nc���ttj|��D]-}tj||�}tj|��/tj
|�yr>)rr?�sk_X509_num�
sk_X509_valuerI�sk_X509_free)�sr�xs   r:�cleanupz:X509StoreContext._build_certificate_stack.<locals>.cleanup�sQ���4�+�+�A�.�/�
"���&�&�q�!�,�����q�!�
"�
���a� r9rz+One of the elements is not an X509 instance)r'rrDr�)rJrGrLr?�sk_X509_new_nullrKrMrWr rY�X509_up_refrJ�sk_X509_pushrIr�)�certificatesr)�stackrOs    r:rz)X509StoreContext._build_certificate_stack�s���	!���3�|�#4��#9��9�9���%�%�'�������*�+�����w�'�� �	'�D��d�D�)�� M�N�N��D�,�,�T�Z�Z�8�1�<�=�� � ���
�
�3�q�8����t�z�z�*�$�&�	'��r9c��tjtjtj|���jd�}tj|�tj|�|g}tj|�}tj|�}tj|�}t|||�S)z�
        Convert an OpenSSL native context error failure into a Python
        exception.

        When a call to native OpenSSL X509_verify_cert fails, additional
        information about the failure can be obtained from the store context.
        r)rGrjr?�X509_verify_cert_error_string�X509_STORE_CTX_get_errorr��X509_STORE_CTX_get_error_depth�X509_STORE_CTX_get_current_cert�X509_dupr rPr&)�	store_ctxrrrJr�pycerts      r:�_exception_from_contextz(X509StoreContext._exception_from_context�s����+�+��.�.��-�-�i�8�
�
��&��/�		�
�)�)�)�4��/�/�	�:��
���4�4�Y�?���
�
�e�$���(�(��/��$�W�f�f�=�=r9c��tj�}t|tjk7�tj
|tj�}tj||jj|jj|j�}t|dk(�tj|�}|dkr|j|��|S)a3
        Verifies the certificate and runs an X509_STORE_CTX containing the
        results.

        :raises X509StoreContextError: If an error occurred when validating a
          certificate in the context. Sets ``certificate`` attribute to
          indicate which certificate caused the error.
        r�r)r?�X509_STORE_CTX_newrKrGrLrM�X509_STORE_CTX_free�X509_STORE_CTX_initr�rrJr �X509_verify_certr7)ryr5rcs   r:�_verify_certificatez$X509StoreContext._verify_certificates����+�+�-�	��	�T�Y�Y�.�/��G�G�I�t�'?�'?�@�	��&�&��t�{�{�)�)�4�:�:�+;�+;�T�[�[�
��	��q��!��#�#�I�.���!�8��.�.�y�9�9��r9c��||_y)z�
        Set the context's X.509 store.

        .. versionadded:: 0.15

        :param X509Store store: The store description which will be used for
            the purposes of any *future* verifications.
        N)r�r�s  r:�	set_storezX509StoreContext.set_store+s����r9c�$�|j�y)a"
        Verify a certificate in a context.

        .. versionadded:: 0.15

        :raises X509StoreContextError: If an error occurred when validating a
          certificate in the context. Sets ``certificate`` attribute to
          indicate which certificate caused the error.
        N)r=rxs r:�verify_certificatez#X509StoreContext.verify_certificate6s��	
� � �"r9c��|j�}tj|�}t|tj
k7�g}t
tj|��D]Z}tj||�}t|tj
k7�tj|�}|j|��\tj|�|S)aR
        Verify a certificate in a context and return the complete validated
        chain.

        :raises X509StoreContextError: If an error occurred when validating a
          certificate in the context. Sets ``certificate`` attribute to
          indicate which certificate caused the error.

        .. versionadded:: 20.0
        )
r=r?�X509_STORE_CTX_get1_chainrKrGrLrr$r%r rPr|r&)ryr5�
cert_stackr�rrOr6s       r:�get_verified_chainz#X509StoreContext.get_verified_chainBs����,�,�.�	��3�3�I�>�
��
�d�i�i�/�0����t�'�'�
�3�4�	"�A��%�%�j�!�4�D��D�D�I�I�-�.��,�,�T�2�F��M�M�&�!�		"�	
���*�%��
r9r>)r�r$rr r!�Sequence[X509] | NonerDr�)r-rFrDr�)r5rrDr&r�)r�r$rDr�r�)rDz
list[X509])r4r5r6r7rz�staticmethodrr7r=r?rArEr8r9r:r%r%�s���
�&(,�	;��;��;�%�	;�

�;���+��	
����:�>��>�2�0	�
#�r9r%c���t|t�r|jd�}t|�}|tk(rCtj|tjtjtj�}n9|tk(r%tj|tj�}ntd��|tjk(r
t�tj|�S)a
    Load a certificate (X509) from the string *buffer* encoded with the
    type *type*.

    :param type: The file type (one of FILETYPE_PEM, FILETYPE_ASN1)

    :param bytes buffer: The buffer the certificate is stored in

    :return: The X509 object
    r��3type argument must be FILETYPE_PEM or FILETYPE_ASN1)rWr�rrPrr?�PEM_read_bio_X509rGrLr�d2i_X509_bior[r�r rP)r�rNrArs    r:r-r-_s����&�#�����w�'��
�v�
�C��|���%�%�c�4�9�9�d�i�i����K��	
��	�� � ��d�i�i�0���N�O�O��t�y�y�����"�"�4�(�(r9c�^�t�}|tk(r!tj||j�}na|t
k(r!tj||j�}n7|tk(r#tj||jdd�}ntd��t|dk(�t|�S)a
    Dump the certificate *cert* into a buffer string encoded with the type
    *type*.

    :param type: The file type (one of FILETYPE_PEM, FILETYPE_ASN1, or
        FILETYPE_TEXT)
    :param cert: The certificate to dump
    :return: The buffer with the dumped certificate in
    r�Ctype argument must be FILETYPE_PEM, FILETYPE_ASN1, or FILETYPE_TEXTr�)rPrr?�PEM_write_bio_X509rJr�i2d_X509_bior�
X509_print_exr[rKrU)r�rOrA�result_codes    r:r(r(|s����.�C��|���-�-�c�4�:�:�>��	
��	��'�'��T�Z�Z�8��	
��	��(�(��d�j�j�!�Q�?���
�
�	
�
�K�1�$�%��#��r9c���t�}|tk(rtj}n%|tk(rtj
}nt
d��|||j�}|dk7r
t�t|�S)z�
    Dump a public key to a buffer.

    :param type: The file type (one of :data:`FILETYPE_PEM` or
        :data:`FILETYPE_ASN1`).
    :param PKey pkey: The public key to dump
    :return: The buffer with the dumped key in it.
    :rtype: bytes
    rIr�)
rPrr?�PEM_write_bio_PUBKEYr�i2d_PUBKEY_bior[r�r�rU)r�r�rA�	write_biorQs     r:r*r*�sf���.�C��|���-�-�	�	
��	��'�'�	��N�O�O��C����,�K��a�����#��r9c	��t�}t|t�std��|�I|�td��t	j
t
|��}|tjk(rtd��tj}t||�}|tk(rXt	j||j|tjd|j|j�}|j!�n�|t"k(r!t	j$||j�}n�|t&k(r�t	j(|j�tj*k7rtd��tj,t	j.|j�tj0�}t	j2||d�}ntd��t5|dk7�t7|�S)a�
    Dump the private key *pkey* into a buffer string encoded with the type
    *type*.  Optionally (if *type* is :const:`FILETYPE_PEM`) encrypting it
    using *cipher* and *passphrase*.

    :param type: The file type (one of :const:`FILETYPE_PEM`,
        :const:`FILETYPE_ASN1`, or :const:`FILETYPE_TEXT`)
    :param PKey pkey: The PKey to dump
    :param cipher: (optional) if encrypted PEM format, the cipher to use
    :param passphrase: (optional) if encrypted PEM format, this can be either
        the passphrase to use, or a callback for providing the passphrase.

    :return: The buffer with the dumped key in
    :rtype: bytes

    .. deprecated:: 26.3.0
       Use the serialization APIs on ``cryptography`` private key types
       instead.
    zpkey must be a PKeyzDif a value is given for cipher one must also be given for passphrasezInvalid cipher namerz-Only RSA keys are supported for FILETYPE_TEXTrM)rPrWr"rYr?�EVP_get_cipherbynamerrGrLr[�_PassphraseHelperr�PEM_write_bio_PrivateKeyr��callback�
callback_args�raise_if_problemr�i2d_PrivateKey_biorr�r�rMr�r��	RSA_printrKrU)	r�r��cipher�
passphraserA�
cipher_obj�helperrQrs	         r:r)r)�s���2�.�C��d�D�!��-�.�.�
�����8��
��.�.�|�F�/C�D�
�����"��2�3�3��Y�Y�
�
�t�Z�
0�F��|���3�3���J�J���I�I�
��O�O�� � �
��	���!�	
��	��-�-�c�4�:�:�>��	
��	����D�J�J�'�4�+<�+<�<��K�L�L��g�g�d�,�,�T�Z�Z�8�$�-�-�H���n�n�S�#�q�1���
�
�	
�
�K�1�$�%��#��r9zGdump_privatekey is deprecated. You should use the APIs in cryptography.r)r�c�x�eZdZ		d									dd�Zed	d��Zed	d��Zefd
d�Z										dd�Z	y)rXc�h�|tk7r
|�td��||_||_||_g|_y)Nz0only FILETYPE_PEM key format supports encryption)rr[�_passphrase�
_more_args�	_truncate�	_problems)ryr�r`�	more_args�truncates     r:rzz_PassphraseHelper.__init__	s@���<��J�$:��B��
�&���#���!���*,��r9c���|j�tjSt|jt�st|j�r tjd|j�Std��)N�pem_password_cb�2Last argument must be a byte string or a callable.)	rerGrLrWrX�callablerZ�_read_passphraserYrxs r:rZz_PassphraseHelper.callbacks]�����#��9�9��
��(�(�%�
0�H�T�=M�=M�4N��=�=�!2�D�4I�4I�J�J��D��
r9c���|j�tjSt|jt�st|j�rtjSt
d��)Nrm)rerGrLrWrXrnrYrxs r:r[z_PassphraseHelper.callback_args$sO�����#��9�9��
��(�(�%�
0�H�T�=M�=M�4N��9�9���D��
r9c��|jr'	t|�|jjd��y#|$rY�#wxYwr/)rh�_exception_from_error_queue�pop)ry�
exceptionTypes  r:r\z"_PassphraseHelper.raise_if_problem/sF���>�>�
�+�M�:��.�.�$�$�Q�'�'���!�
��
�s�5�=�=c��	t|j�r2|jr|j|||�}n,|j|�}n|j�J�|j}t|t�std��t
|�|kDr|jr|d|}ntd��tt
|��D]
}|||dz||<�t
|�S#t$r%}|jj|�Yd}~yd}~wwxYw)NzBytes expectedz+passphrase returned by callback is too longr�r)rnrerfrWrXr[rJrgr�	Exceptionrhr|)ry�buf�size�rwflag�userdatar�r�es        r:roz"_PassphraseHelper._read_passphrase9s���	���(�(�)��?�?�!�-�-�d�F�H�E�F�!�-�-�f�5�F��'�'�3�3�3��)�)���f�e�,� �!1�2�2��6�{�T�!��>�>�#�E�T�]�F�$�E����3�v�;�'�
+����A��E�*��A��
+��v�;����	��N�N�!�!�!�$���	�s�CC�	D�!D�DN)FF)
r�r0r`�PassphraseCallableT | Nonerir�rjr�rDr�r�)rtztype[Exception]rDr�)
rwrrxr0ryrrzrrDr0)
r4r5r6rz�propertyrZr[r!r\ror8r9r:rXrXs���
 ��-��-�/�-��	-�
�-�
�
-� ��������AF�(����!��+.��:=��	�r9rXc�4�t|t�r|jd�}t|�}|tk(rCtj|tjtjtj�}n9|tk(r%tj|tj�}ntd��|tjk(r
t�tjt�}tj|t
j �|_d|_|S)a<
    Load a public key from a buffer.

    :param type: The file type (one of :data:`FILETYPE_PEM`,
        :data:`FILETYPE_ASN1`).
    :param buffer: The buffer the key is stored in.
    :type buffer: A Python string object, either unicode or bytestring.
    :return: The PKey object.
    :rtype: :class:`PKey`
    r�rIT)rWr�rrPrr?�PEM_read_bio_PUBKEYrGrLr�d2i_PUBKEY_bior[r�r"rNrMr�r�r�)r�rNrA�evp_pkeyr�s     r:r/r/Vs����&�#�����w�'��
�v�
�C��|���+�+�����D�I�I�t�y�y�
��
��	��&�&�s�D�I�I�6���N�O�O��4�9�9�����<�<���D�����4�#5�#5�6�D�J��D���Kr9c�N�t|t�r|jd�}t|�}t	||�}|t
k(rKt
j|tj|j|j�}|j�n9|tk(r%t
j|tj�}ntd��|tjk(r
t!�t"j%t"�}tj&|tj(�|_|S)a�
    Load a private key (PKey) from the string *buffer* encoded with the type
    *type*.

    :param type: The file type (one of FILETYPE_PEM, FILETYPE_ASN1)
    :param buffer: The buffer the key is stored in
    :param passphrase: (optional) if encrypted PEM format, this can be
                       either the passphrase to use, or a callback for
                       providing the passphrase.

    :return: The PKey object
    r�rI)rWr�rrPrXrr?�PEM_read_bio_PrivateKeyrGrLrZr[r\r�d2i_PrivateKey_bior[r�r"rNrMr�r�)r�rNr`rArbr�r�s       r:r.r.xs���"�&�#�����w�'��
�v�
�C�
�t�Z�
0�F��|���/�/�����F�O�O�V�-A�-A�
��	���!�	
��	��*�*�3��	�	�:���N�O�O��4�9�9�����<�<���D�����4�#5�#5�6�D�J��Kr9r>)rNr�rDr)rArrDrX)r\rr]rXrDr�)r]rXrDr)rnrrDr�)rDr�)r~r�rDr�)r�r0rNrXrDr )r�r0rOr rDrX)r�r0r�r"rDrX)NN)
r�r0r�r"r_rDr`r|rDrX)r�r0rN�str | bytesrDr")r�r0rNr�r`r|rDr")g�
__future__rrr��	functools�sysr��base64r�collections.abcrrrrr	�version_info�warningsr�typing_extensions�cryptographyr
r�)cryptography.hazmat.primitives.asymmetricrrrrr�
OpenSSL._utilrrrrrrrrGrr?r�_make_assertrr�__all__r�r�r�r�r��_PrivateKeyr�r�r�r�r��
_PublicKeyr�rX�PassphraseCallableT�SSL_FILETYPE_PEMrr��SSL_FILETYPE_ASN1rrr�r�EVP_PKEY_DSAr�EVP_PKEY_DHr1�EVP_PKEY_ECr2rvr!r�rKrPrUr_rdrsrur"r�r,r+�total_orderingr#r r'r$r&r%r-r(r*r)r�r4�DeprecationWarningrXr/r.r8r9r:�<module>r�sV��"����
�
��$�������w��#�,�$���)���������2����������	������	�������������	������	��
�
�[�*�
$�%���E�8�C��J�#7�7�8���)�)��c�)��+�+�
�s�+��
��!�!��#�!��!�!��#�!��������������I���:�E�B���u�%���4;�+�2�&�:
�
�F.�F.�Rd.�d.�N���5�	�5����1�	�1�$���������	�
�D_3�_3�D8�8�.g#�g#�T'�I�'�"[�[�|)�:�8�8�-1�	F�

�F�
�F�
�F�+�	F�
�F�R,��������	��	�	�K�K�\�J.2�&�

�&��&�+�&�
�	&r9

Youez - 2016 - github.com/yon3zu
LinuXploit