o
    "“i)7 ã                   @  s¾  U d dl mZ d dlZd dlZd dlZd dlZd dlZd dlZd dlm	Z	 d dl
mZmZ d dlmZ d dlmZmZmZ ejdkrId dlmZ nejd	k rYe d
¡Zdwdd„Znd dlmZ d dlmZmZ d dlmZmZmZmZmZ d dlm Z  d dlm!Z" d dlm#Z$ d dlm%Z& d dlm'Z( d dlm)Z* d dlm+Z, g d¢Z-eej.ej/ej0ej1ej2f Z3eej4ej5ej6ej7ej8f Z9ee3e9f Z:ee;ede;f f Z<e(j=Z>de?d< e(j@ZAde?d < d!ZBe(jCZDde?d"< e(jEZFde?d#< e(jGZHde?d$< e(jIZJde?d%< G d&d'„ d'eKƒZLee$eLƒZMe*eLƒZNdxdyd+d,„ZOdzd/d0„ZPd{d4d5„ZQd|d6d7„ZRd}d9d:„ZSG d;d<„ d<ƒZTG d=d>„ d>ƒZUG d?d@„ d@ƒZVedAƒd~dCdD„ƒZWedEƒddGdH„ƒZXejYG dIdJ„ dJƒƒZZedKƒG dLdM„ dMƒƒZ[edNƒG dOdP„ dPƒƒZ\G dQdR„ dRƒZ]G dSdT„ dTƒZ^G dUdV„ dVƒZ_G dWdX„ dXeKƒZ`G dYdZ„ dZƒZad€d\d]„Zbd�d_d`„Zcd‚dbdc„Zd		dƒd„dhdi„ZeG djdk„ dkƒZfd…dmdn„Zg	dxd†dodp„Zhd‡drds„ZieiZjejeiekdNeldsdt� dˆdudv„ZmemZnejemekdNeldvdt� dS )‰é    )ÚannotationsN)Ú	b16encode)ÚIterableÚSequence)Úpartial)ÚAnyÚCallableÚUnion)é   é   )Ú
deprecated)r
   é   ÚTÚmsgÚstrÚkwargsÚobjectÚreturnúCallable[[_T], _T]c                 K  s   dd„ S )Nc                 S  s   | S ©N© )Úfr   r   úN/var/www/html/premium_crap/venv/lib/python3.10/site-packages/OpenSSL/crypto.pyÚ<lambda>   s    zdeprecated.<locals>.<lambda>r   )r   r   r   r   r   r      s   r   )ÚutilsÚx509)ÚdsaÚecÚed448Úed25519Úrsa)ÚStrOrBytesPath)Úbyte_string)Úexception_from_error_queue)Úffi)Úlib)Úmake_assert)Ú
path_bytes)ÚFILETYPE_ASN1ÚFILETYPE_PEMÚFILETYPE_TEXTÚTYPE_DSAÚTYPE_RSAÚX509ÚErrorÚPKeyÚX509ExtensionÚX509NameÚX509ReqÚ	X509StoreÚX509StoreContextÚX509StoreContextErrorÚX509StoreFlagsÚdump_certificateÚdump_certificate_requestÚdump_privatekeyÚdump_publickeyÚget_elliptic_curveÚget_elliptic_curvesÚload_certificateÚload_certificate_requestÚload_privatekeyÚload_publickey.Úintr)   r(   iÿÿ  r,   r+   ÚTYPE_DHÚTYPE_ECc                   @  s   e Zd ZdZdS )r.   z7
    An error occurred in an `OpenSSL.crypto` API.
    N)Ú__name__Ú
__module__Ú__qualname__Ú__doc__r   r   r   r   r.   t   s    r.   Úbufferúbytes | Noner   c                 C  sf   | du rt  t  ¡ ¡}t j}nt d| ¡}t  |t| ƒ¡}|fd	dd„}t|tj	kƒ t 
||¡}|S )
zÙ
    Allocate a new OpenSSL memory BIO.

    Arrange for the garbage collector to clean it up automatically.

    :param buffer: None or some bytes to use to put into the BIO so that they
        can be read out.
    Núchar[]Úbior   Úrefr   c                 S  s
   t  | ¡S r   )Ú_libÚBIO_free)rK   rL   r   r   r   Úfree�   ó   
z_new_mem_buf.<locals>.free)rK   r   rL   r   r   r   )rM   ÚBIO_newÚ	BIO_s_memrN   Ú_ffiÚnewÚBIO_new_mem_bufÚlenÚ_openssl_assertÚNULLÚgc)rH   rK   rO   Údatar   r   r   Ú_new_mem_buf~   s   	r[   rK   Úbytesc                 C  s.   t  d¡}t | |¡}t  |d |¡dd… S )zO
    Copy the contents of an OpenSSL BIO object into a Python byte string.
    zchar**r   N)rS   rT   rM   ÚBIO_get_mem_datarH   )rK   Úresult_bufferÚbuffer_lengthr   r   r   Ú_bio_to_string˜   s   
r`   ÚboundaryÚwhenÚNonec                 C  s@   t |tƒs	tdƒ‚t| tjkƒ t | |¡}|dkrtdƒ‚dS )aô  
    The the time value of an ASN1 time object.

    @param boundary: An ASN1_TIME pointer (or an object safely
        castable to that type) which will have its value set.
    @param when: A string representation of the desired time value.

    @raise TypeError: If C{when} is not a L{bytes} string.
    @raise ValueError: If C{when} does not represent a time in the required
        format.
    @raise RuntimeError: If the time value cannot be set for some other
        (unspecified) reason.
    zwhen must be a byte stringr   zInvalid stringN)	Ú
isinstancer\   Ú	TypeErrorrW   rS   rX   rM   ÚASN1_TIME_set_stringÚ
ValueError)ra   rb   Ú
set_resultr   r   r   Ú_set_asn1_time¡   s   
ÿri   c                 C  s2   t  ¡ }t|tjkƒ t |t j¡}t|| ƒ |S )aŒ  
    Behaves like _set_asn1_time but returns a new ASN1_TIME object.

    @param when: A string representation of the desired time value.

    @raise TypeError: If C{when} is not a L{bytes} string.
    @raise ValueError: If C{when} does not represent a time in the required
        format.
    @raise RuntimeError: If the time value cannot be set for some other
        (unspecified) reason.
    )rM   ÚASN1_TIME_newrW   rS   rX   rY   ÚASN1_TIME_freeri   )rb   Úretr   r   r   Ú_new_asn1_timeº   s
   
rm   Ú	timestampc                 C  sœ   t  d| ¡}t |¡dkrdS t |¡tjkrt  t |¡¡S t  d¡}t 	| |¡ t
|d t jkƒ t  d|d ¡}t |¡}t  |¡}t |d ¡ |S )a]  
    Retrieve the time value of an ASN1 time object.

    @param timestamp: An ASN1_GENERALIZEDTIME* (or an object safely castable to
        that type) from which the time value will be retrieved.

    @return: The time value from C{timestamp} as a L{bytes} string in a certain
        format.  Or C{None} if the object contains no time value.
    úASN1_STRING*r   NzASN1_GENERALIZEDTIME**)rS   ÚcastrM   ÚASN1_STRING_lengthÚASN1_STRING_typeÚV_ASN1_GENERALIZEDTIMEÚstringÚASN1_STRING_get0_datarT   ÚASN1_TIME_to_generalizedtimerW   rX   ÚASN1_GENERALIZEDTIME_free)rn   Ústring_timestampÚgeneralized_timestampÚstring_dataÚstring_resultr   r   r   Ú_get_asn1_timeÍ   s   



r|   c                   @  s*   e Zd Zddd„Zddd„Zdd	d
„ZdS )Ú_X509NameInvalidatorr   rc   c                 C  s
   g | _ d S r   )Ú_names©Úselfr   r   r   Ú__init__ë   rP   z_X509NameInvalidator.__init__Únamer1   c                 C  s   | j  |¡ d S r   )r~   Úappend©r€   r‚   r   r   r   Úaddî   s   z_X509NameInvalidator.addc                 C  s   | j D ]}|`qd S r   )r~   Ú_namer„   r   r   r   Úclearñ   s   
þz_X509NameInvalidator.clearN©r   rc   ©r‚   r1   r   rc   )rD   rE   rF   r�   r…   r‡   r   r   r   r   r}   ê   s    

r}   c                   @  sb   e Zd ZdZdZdZddd„Zdd	d
„Zeddd„ƒZ	ddd„Z
ddd„Zd dd„Zd dd„ZdS )!r/   zD
    A class representing an DSA or RSA public key or key pair.
    FTr   rc   c                 C  s"   t  ¡ }t |t j¡| _d| _d S )NF)rM   ÚEVP_PKEY_newrS   rY   ÚEVP_PKEY_freeÚ_pkeyÚ_initialized©r€   Úpkeyr   r   r   r�   ÿ   s   
zPKey.__init__Ú_Keyc                 C  sN   ddl m}m} | jrtt| ƒ}t t||ƒ¡S t	t| ƒ}t t||dd�¡S )a  
        Export as a ``cryptography`` key.

        :rtype: One of ``cryptography``'s `key interfaces`_.

        .. _key interfaces: https://cryptography.io/en/latest/hazmat/            primitives/asymmetric/rsa/#key-interfaces

        .. versionadded:: 16.1.0
        r   )Úload_der_private_keyÚload_der_public_keyN)Úpassword)
Ú,cryptography.hazmat.primitives.serializationr‘   r’   Ú_only_publicr:   r(   Útypingrp   r�   r9   )r€   r‘   r’   Úderr   r   r   Úto_cryptography_key  s   

zPKey.to_cryptography_keyÚ
crypto_keyc                 C  s¤   t |tjtjtjtjtjtj	t
jt
jtjtjf
ƒstdƒ‚ddlm}m}m}m} t |tjtjtj	t
jtjfƒrCtt| |j|j¡ƒS | |j|j|ƒ ¡}tt|ƒS )zø
        Construct based on a ``cryptography`` *crypto_key*.

        :param crypto_key: A ``cryptography`` key.
        :type crypto_key: One of ``cryptography``'s `key interfaces`_.

        :rtype: PKey

        .. versionadded:: 16.1.0
        zUnsupported key typer   )ÚEncodingÚNoEncryptionÚPrivateFormatÚPublicFormat)rd   r   ÚDSAPrivateKeyÚDSAPublicKeyr   ÚEllipticCurvePrivateKeyÚEllipticCurvePublicKeyr   ÚEd25519PrivateKeyÚEd25519PublicKeyr   ÚEd448PrivateKeyÚEd448PublicKeyr    ÚRSAPrivateKeyÚRSAPublicKeyre   r”   rš   r›   rœ   r�   r@   r(   Úpublic_bytesÚDERÚSubjectPublicKeyInfoÚprivate_bytesÚPKCS8r?   )Úclsr™   rš   r›   rœ   r�   r—   r   r   r   Úfrom_cryptography_key  sF   öþûþ
ÿþÿ
zPKey.from_cryptography_keyÚtyperA   Úbitsc              	   C  s4  t |tƒs	tdƒ‚t |tƒstdƒ‚|tkrQ|dkrtdƒ‚t ¡ }t |tj	¡}t 
|tj¡ t ¡ }t |||tj¡}t|dkƒ t | j|¡}t|dkƒ nD|tkr‘t ¡ }t|tjkƒ t |tj¡}t ||tjdtjtjtj¡}t|dkƒ tt |¡dkƒ tt | j|¡dkƒ ntdƒ‚d| _dS )	a3  
        Generate a key pair of the given type, with the given number of bits.

        This generates a key "into" the this object.

        :param type: The key type.
        :type type: :py:data:`TYPE_RSA` or :py:data:`TYPE_DSA`
        :param bits: The number of bits.
        :type bits: :py:data:`int` ``>= 0``
        :raises TypeError: If :py:data:`type` or :py:data:`bits` isn't
            of the appropriate type.
        :raises ValueError: If the number of bits isn't an integer of
            the appropriate size.
        :return: ``None``
        ztype must be an integerzbits must be an integerr   zInvalid number of bitsé   zNo such key typeTN)rd   rA   re   r,   rg   rM   ÚBN_newrS   rY   ÚBN_freeÚBN_set_wordÚRSA_F4ÚRSA_newÚRSA_generate_key_exrX   rW   ÚEVP_PKEY_assign_RSArŒ   r+   ÚDSA_newÚDSA_freeÚDSA_generate_parameters_exÚDSA_generate_keyÚEVP_PKEY_set1_DSAr.   r�   )r€   r¯   r°   Úexponentr    Úresultr   Úresr   r   r   Úgenerate_keyU  s6   

ÿ
zPKey.generate_keyÚboolc                 C  sd   | j rtdƒ‚t |  ¡ ¡tjkrtdƒ‚t | j¡}t 	|tj
¡}t |¡}|dkr-dS tƒ  dS )ax  
        Check the consistency of an RSA private key.

        This is the Python equivalent of OpenSSL's ``RSA_check_key``.

        :return: ``True`` if key is consistent.

        :raise OpenSSL.crypto.Error: if the key is inconsistent.

        :raise TypeError: if the key is of a type which cannot be checked.
            Only RSA keys can currently be checked.
        zpublic key onlyz'Only RSA keys can currently be checked.r±   TN)r•   re   rM   ÚEVP_PKEY_typer¯   ÚEVP_PKEY_RSAÚEVP_PKEY_get1_RSArŒ   rS   rY   ÚRSA_freeÚRSA_check_keyÚ_raise_current_error)r€   r    r¿   r   r   r   Úcheck�  s   

z
PKey.checkc                 C  ó   t  | j¡S )zT
        Returns the type of the key

        :return: The type of the key.
        )rM   ÚEVP_PKEY_idrŒ   r   r   r   r   r¯   §  ó   z	PKey.typec                 C  rÊ   )zh
        Returns the number of bits of the key

        :return: The number of bits of the key.
        )rM   ÚEVP_PKEY_bitsrŒ   r   r   r   r   r°   ¯  rÌ   z	PKey.bitsNrˆ   )r   r�   )r™   r�   r   r/   )r¯   rA   r°   rA   r   rc   ©r   rÂ   ©r   rA   )rD   rE   rF   rG   r•   r�   r�   r˜   Úclassmethodr®   rÁ   rÉ   r¯   r°   r   r   r   r   r/   ÷   s    


9
8
r/   c                      sn   e Zd ZdZdZd‡ fdd„Zeddd„ƒZeddd„ƒZeddd„ƒZ	ddd„Z
d dd„Zd!dd„Z‡  ZS )"Ú_EllipticCurveaZ  
    A representation of a supported elliptic curve.

    @cvar _curves: :py:obj:`None` until an attempt is made to load the curves.
        Thereafter, a :py:type:`set` containing :py:type:`_EllipticCurve`
        instances each of which represents one curve supported by the system.
    @type _curves: :py:type:`NoneType` or :py:type:`set`
    NÚotherr   r   rÂ   c                   s   t |tƒrtƒ  |¡S tS )z·
        Implement cooperation with the right-hand side argument of ``!=``.

        Python 3 seems to have dropped this cooperation in this very narrow
        circumstance.
        )rd   rÑ   ÚsuperÚ__ne__ÚNotImplemented©r€   rÒ   ©Ú	__class__r   r   rÔ   Ä  s   
z_EllipticCurve.__ne__r%   úset[_EllipticCurve]c                   s>   ˆ  tjd¡}t d|¡}ˆ  ||¡ t‡ ‡fdd„|D ƒƒS )zü
        Get the curves supported by OpenSSL.

        :param lib: The OpenSSL library binding object.

        :return: A :py:type:`set` of ``cls`` instances giving the names of the
            elliptic curves the underlying library supports.
        r   zEC_builtin_curve[]c                 3  s   � | ]
}ˆ   ˆ|j¡V  qd S r   )Úfrom_nidÚnid)Ú.0Úc©r­   r%   r   r   Ú	<genexpr>ß  s   € z7_EllipticCurve._load_elliptic_curves.<locals>.<genexpr>)ÚEC_get_builtin_curvesrS   rX   rT   Úset)r­   r%   Ú
num_curvesÚbuiltin_curvesr   rÞ   r   Ú_load_elliptic_curvesÏ  s   
z$_EllipticCurve._load_elliptic_curvesc                 C  s   | j du r|  |¡| _ | j S )a  
        Get, cache, and return the curves supported by OpenSSL.

        :param lib: The OpenSSL library binding object.

        :return: A :py:type:`set` of ``cls`` instances giving the names of the
            elliptic curves the underlying library supports.
        N)Ú_curvesrä   rÞ   r   r   r   Ú_get_elliptic_curvesá  s   

z#_EllipticCurve._get_elliptic_curvesrÛ   rA   c                 C  s   | ||t  | |¡¡ d¡ƒS )aË  
        Instantiate a new :py:class:`_EllipticCurve` associated with the given
        OpenSSL NID.

        :param lib: The OpenSSL library binding object.

        :param nid: The OpenSSL NID the resulting curve object will represent.
            This must be a curve NID (and not, for example, a hash NID) or
            subsequent operations will fail in unpredictable ways.
        :type nid: :py:class:`int`

        :return: The curve object.
        Úascii)rS   rt   Ú
OBJ_nid2snÚdecode)r­   r%   rÛ   r   r   r   rÚ   ï  s   z_EllipticCurve.from_nidr‚   r   rc   c                 C  s   || _ || _|| _dS )a‰  
        :param _lib: The :py:mod:`cryptography` binding instance used to
            interface with OpenSSL.

        :param _nid: The OpenSSL NID identifying the curve this object
            represents.
        :type _nid: :py:class:`int`

        :param name: The OpenSSL short name identifying the curve this object
            represents.
        :type name: :py:class:`unicode`
        N)rM   Ú_nidr‚   )r€   r%   rÛ   r‚   r   r   r   r�      s   
z_EllipticCurve.__init__c                 C  s   d| j ›d�S )Nz<Curve ú>©r‚   r   r   r   r   Ú__repr__  ó   z_EllipticCurve.__repr__c                 C  s   | j  | j¡}t |t j¡S )zÅ
        Create a new OpenSSL EC_KEY structure initialized to use this curve.

        The structure is automatically garbage collected when the Python object
        is garbage collected.
        )rM   ÚEC_KEY_new_by_curve_namerê   rS   rY   ÚEC_KEY_free)r€   Úkeyr   r   r   Ú
_to_EC_KEY  s   z_EllipticCurve._to_EC_KEY©rÒ   r   r   rÂ   )r%   r   r   rÙ   )r%   r   rÛ   rA   r   rÑ   )r%   r   rÛ   rA   r‚   r   r   rc   ©r   r   ©r   r   )rD   rE   rF   rG   rå   rÔ   rÐ   rä   ræ   rÚ   r�   rí   rò   Ú__classcell__r   r   r×   r   rÑ   ¸  s    	

rÑ   zSget_elliptic_curves is deprecated. You should use the APIs in cryptography instead.rÙ   c                   C  s
   t  t¡S )a“  
    Return a set of objects representing the elliptic curves supported in the
    OpenSSL build in use.

    The curve objects have a :py:class:`unicode` ``name`` attribute by which
    they identify themselves.

    The curve objects are useful as values for the argument accepted by
    :py:meth:`Context.set_tmp_ecdh` to specify which elliptical curve should be
    used for ECDHE key exchange.
    )rÑ   ræ   rM   r   r   r   r   r<     s   
r<   zRget_elliptic_curve is deprecated. You should use the APIs in cryptography instead.r‚   c                 C  s(   t ƒ D ]}|j| kr|  S qtd| ƒ‚)aT  
    Return a single curve object selected by name.

    See :py:func:`get_elliptic_curves` for information about curve objects.

    :param name: The OpenSSL short name identifying the curve object to
        retrieve.
    :type name: :py:class:`unicode`

    If the named curve is not supported then :py:class:`ValueError` is raised.
    zunknown curve name)r<   r‚   rg   )r‚   Úcurver   r   r   r;   2  s
   

ÿ
r;   c                      sr   e Zd ZdZd dd„Zd!‡ fd
d„Zd"dd„Zd#dd„Zd#dd„Zd$dd„Z	d%dd„Z
d&dd„Zd'dd„Z‡  ZS )(r1   a  
    An X.509 Distinguished Name.

    :ivar countryName: The country of the entity.
    :ivar C: Alias for  :py:attr:`countryName`.

    :ivar stateOrProvinceName: The state or province of the entity.
    :ivar ST: Alias for :py:attr:`stateOrProvinceName`.

    :ivar localityName: The locality of the entity.
    :ivar L: Alias for :py:attr:`localityName`.

    :ivar organizationName: The organization name of the entity.
    :ivar O: Alias for :py:attr:`organizationName`.

    :ivar organizationalUnitName: The organizational unit of the entity.
    :ivar OU: Alias for :py:attr:`organizationalUnitName`

    :ivar commonName: The common name of the entity.
    :ivar CN: Alias for :py:attr:`commonName`.

    :ivar emailAddress: The e-mail address of the entity.
    r‚   r   rc   c                 C  s    t  |j¡}t |t j¡| _dS )zž
        Create a new X509Name, copying the given X509Name instance.

        :param name: The name to copy.
        :type name: :py:class:`X509Name`
        N)rM   ÚX509_NAME_dupr†   rS   rY   ÚX509_NAME_freer„   r   r   r   r�   b  s   zX509Name.__init__r   Úvaluer   c           	   	     s  |  d¡rtƒ  ||¡S t|ƒturtdt|ƒjd›d�ƒ‚t t	|ƒ¡}|tj
kr?ztƒ  W tdƒ‚ ty>   Y tdƒ‚w tt | j¡ƒD ]%}t | j|¡}t |¡}t |¡}||krlt | j|¡}t |¡  nqGt|tƒrw| d¡}t | j|tj|ddd¡}|s‹tƒ  d S d S )	NÚ_z$attribute name must be string, not 'z.200ú'úNo such attributeúutf-8éÿÿÿÿr   )Ú
startswithrÓ   Ú__setattr__r¯   r   re   rD   rM   ÚOBJ_txt2nidÚ_byte_stringÚ	NID_undefrÈ   r.   ÚAttributeErrorÚrangeÚX509_NAME_entry_countr†   ÚX509_NAME_get_entryÚX509_NAME_ENTRY_get_objectÚOBJ_obj2nidÚX509_NAME_delete_entryÚX509_NAME_ENTRY_freerd   ÚencodeÚX509_NAME_add_entry_by_NIDÚMBSTRING_UTF8)	r€   r‚   rú   rÛ   ÚiÚentÚent_objÚent_nidÚ
add_resultr×   r   r   r  l  sD   

ÿÿ
þþ


ý

ÿ
ÿzX509Name.__setattr__ú
str | Nonec           	   
   C  sÜ   t  t|ƒ¡}|t jkr!ztƒ  W tdƒ‚ ty    Y tdƒ‚w t  | j|d¡}|dkr/dS t  	| j|¡}t  
|¡}t d¡}t  ||¡}t|dkƒ zt |d |¡dd…  d¡}W t  |d ¡ |S t  |d ¡ w )a
  
        Find attribute. An X509Name object has the following attributes:
        countryName (alias C), stateOrProvince (alias ST), locality (alias L),
        organization (alias O), organizationalUnit (alias OU), commonName
        (alias CN) and more...
        rý   rÿ   Núunsigned char**r   rþ   )rM   r  r  r  rÈ   r.   r  ÚX509_NAME_get_index_by_NIDr†   r  ÚX509_NAME_ENTRY_get_datarS   rT   ÚASN1_STRING_to_UTF8rW   rH   ré   ÚOPENSSL_free)	r€   r‚   rÛ   Úentry_indexÚentryrZ   r^   Údata_lengthr¿   r   r   r   Ú__getattr__“  s0   
þþ

ÿÿzX509Name.__getattr__rÒ   rÂ   c                 C  s"   t |tƒstS t | j|j¡dkS ©Nr   ©rd   r1   rÕ   rM   ÚX509_NAME_cmpr†   rÖ   r   r   r   Ú__eq__»  ó   
zX509Name.__eq__c                 C  s"   t |tƒstS t | j|j¡dk S r  r   rÖ   r   r   r   Ú__lt__Á  r#  zX509Name.__lt__c                 C  sD   t  dd¡}t | j|t|ƒ¡}t|t jkƒ d t  	|¡ 
d¡¡S )z6
        String representation of an X509Name
        rJ   i   z<X509Name object '{}'>rþ   )rS   rT   rM   ÚX509_NAME_oneliner†   rV   rW   rX   Úformatrt   ré   )r€   r^   Úformat_resultr   r   r   rí   Ç  s   ÿÿzX509Name.__repr__rA   c                 C  rÊ   )a&  
        Return an integer representation of the first four bytes of the
        MD5 digest of the DER representation of the name.

        This is the Python equivalent of OpenSSL's ``X509_NAME_hash``.

        :return: The (integer) hash of this name.
        :rtype: :py:class:`int`
        )rM   ÚX509_NAME_hashr†   r   r   r   r   ÚhashÕ  ó   
zX509Name.hashr\   c                 C  sN   t  d¡}t | j|¡}t|dkƒ t  |d |¡dd… }t |d ¡ |S )zŽ
        Return the DER encoding of this name.

        :return: The DER encoded form of this name.
        :rtype: :py:class:`bytes`
        r  r   N)rS   rT   rM   Úi2d_X509_NAMEr†   rW   rH   r  )r€   r^   Úencode_resultr{   r   r   r   r—   á  s   
zX509Name.derúlist[tuple[bytes, bytes]]c           	      C  sˆ   g }t t | j¡ƒD ]7}t | j|¡}t |¡}t |¡}t |¡}t |¡}t	 
t |¡t |¡¡dd… }| t	 |¡|f¡ q
|S )z¼
        Returns the components of this name, as a sequence of 2-tuples.

        :return: The components of this name.
        :rtype: :py:class:`list` of ``name, value`` tuples.
        N)r  rM   r  r†   r  r	  r  r
  rè   rS   rH   ru   rq   rƒ   rt   )	r€   r¿   r  r  ÚfnameÚfvalrÛ   r‚   rú   r   r   r   Úget_componentsð  s   



ÿþzX509Name.get_componentsr‰   )r‚   r   rú   r   r   rc   )r‚   r   r   r  ró   rô   rÏ   ©r   r\   )r   r-  )rD   rE   rF   rG   r�   r  r  r"  r$  rí   r)  r—   r0  rö   r   r   r×   r   r1   H  s    


'
(



r1   zZX509Extension support in pyOpenSSL is deprecated. You should use the APIs in cryptography.c                   @  s€   e Zd ZU dZ		d"d#dd„Zed$dd„ƒZejdej	dej
diZded< d%dd„Zd%dd„Zd&dd„Zd'dd„Zd'd d!„ZdS )(r0   zu
    An X.509 v3 certificate extension.

    .. deprecated:: 23.3.0
       Use cryptography's X509 APIs instead.
    NÚ	type_namer\   ÚcriticalrÂ   rú   ÚsubjectúX509 | NoneÚissuerr   rc   c                 C  s¶   t  d¡}t |t jt jt jt jd¡ t |¡ |dur)t|tƒs%tdƒ‚|j	|_
|dur:t|tƒs6tdƒ‚|j	|_|r@d| }t t j|||¡}|t jkrQtƒ  t  |tj¡| _dS )aÝ  
        Initializes an X509 extension.

        :param type_name: The name of the type of extension_ to create.
        :type type_name: :py:data:`bytes`

        :param bool critical: A flag indicating whether this is a critical
            extension.

        :param value: The OpenSSL textual representation of the extension's
            value.
        :type value: :py:data:`bytes`

        :param subject: Optional X509 certificate to use as subject.
        :type subject: :py:class:`X509`

        :param issuer: Optional X509 certificate to use as issuer.
        :type issuer: :py:class:`X509`

        .. _extension: https://www.openssl.org/docs/manmaster/man5/
            x509v3_config.html#STANDARD-EXTENSIONS
        zX509V3_CTX*r   Nzissuer must be an X509 instancez subject must be an X509 instances	   critical,)rS   rT   rM   ÚX509V3_set_ctxrX   ÚX509V3_set_ctx_nodbrd   r-   re   Ú_x509Úissuer_certÚsubject_certÚX509V3_EXT_nconfrÈ   rY   ÚX509_EXTENSION_freeÚ
_extension)r€   r2  r3  rú   r4  r6  ÚctxÚ	extensionr   r   r   r�     s"   




zX509Extension.__init__r   c                 C  s   t  t  | j¡¡S r   )rM   r
  ÚX509_EXTENSION_get_objectr>  r   r   r   r   rê   \  s   
ÿzX509Extension._nidÚemailÚDNSÚURIztyping.ClassVar[dict[int, str]]Ú	_prefixesr   c              	   C  sÒ   t  dt | j¡¡}t  |tj¡}g }tt |¡ƒD ]I}t 	||¡}z| j
|j }W n tyF   tƒ }t ||¡ | t|ƒ d¡¡ Y qw t  |jjj|jjj¡d d …  d¡}| |d | ¡ qd |¡S )NzGENERAL_NAMES*rþ   ú:z, )rS   rp   rM   ÚX509V3_EXT_d2ir>  rY   ÚGENERAL_NAMES_freer  Úsk_GENERAL_NAME_numÚsk_GENERAL_NAME_valuerE  r¯   ÚKeyErrorr[   ÚGENERAL_NAME_printrƒ   r`   ré   rH   ÚdÚia5rZ   ÚlengthÚjoin)r€   ÚnamesÚpartsr  r‚   ÚlabelrK   rú   r   r   r   Ú_subjectAltNameStringh  s*   ÿýÿþ
z#X509Extension._subjectAltNameStringc                 C  sF   t j| jkr
|  ¡ S tƒ }t  || jdd¡}t|dkƒ t|ƒ 	d¡S )zF
        :return: a nice text representation of the extension
        r   rþ   )
rM   ÚNID_subject_alt_namerê   rT  r[   ÚX509V3_EXT_printr>  rW   r`   ré   )r€   rK   Úprint_resultr   r   r   Ú__str__~  s   zX509Extension.__str__c                 C  rÊ   )zk
        Returns the critical field of this X.509 extension.

        :return: The critical field.
        )rM   ÚX509_EXTENSION_get_criticalr>  r   r   r   r   Úget_critical‹  rÌ   zX509Extension.get_criticalc                 C  s8   t  | j¡}t  |¡}t  |¡}|tjkrt |¡S dS )zü
        Returns the short type name of this X.509 extension.

        The result is a byte string such as :py:const:`b"basicConstraints"`.

        :return: The short type name.
        :rtype: :py:data:`bytes`

        .. versionadded:: 0.12
        s   UNDEF)rM   rA  r>  r
  rè   rS   rX   rt   )r€   ÚobjrÛ   Úbufr   r   r   Úget_short_name“  s   



zX509Extension.get_short_namec                 C  s@   t  | j¡}t d|¡}t  |¡}t  |¡}t ||¡dd… S )zÍ
        Returns the data of the X509 extension, encoded as ASN.1.

        :return: The ASN.1 encoded data of this X509 extension.
        :rtype: :py:data:`bytes`

        .. versionadded:: 0.12
        ro   N)rM   ÚX509_EXTENSION_get_datar>  rS   rp   ru   rq   rH   )r€   Úoctet_resultr{   Úchar_resultÚresult_lengthr   r   r   Úget_data©  s
   	

zX509Extension.get_data©NN)r2  r\   r3  rÂ   rú   r\   r4  r5  r6  r5  r   rc   rõ   rô   rÎ   r1  )rD   rE   rF   rG   r�   Úpropertyrê   rM   Ú	GEN_EMAILÚGEN_DNSÚGEN_URIrE  Ú__annotations__rT  rX  rZ  r]  rb  r   r   r   r   r0     s    
 úEý



r0   zPCSR support in pyOpenSSL is deprecated. You should use the APIs in cryptography.c                   @  sŒ   e Zd ZdZd*dd„Zd+dd„Zed,d
d„ƒZd-dd„Zd.dd„Z	d/dd„Z
d0dd„Zd1dd„Zd2dd„Zd3d d!„Zd4d$d%„Zd5d'd(„Zd)S )6r2   zŽ
    An X.509 certificate signing requests.

    .. deprecated:: 24.2.0
       Use `cryptography.x509.CertificateSigningRequest` instead.
    r   rc   c                 C  s&   t  ¡ }t |t j¡| _|  d¡ d S r  )rM   ÚX509_REQ_newrS   rY   ÚX509_REQ_freeÚ_reqÚset_version)r€   Úreqr   r   r   r�   Å  s   zX509Req.__init__úx509.CertificateSigningRequestc                 C  ó   ddl m} tt| ƒ}||ƒS )z®
        Export as a ``cryptography`` certificate signing request.

        :rtype: ``cryptography.x509.CertificateSigningRequest``

        .. versionadded:: 17.1.0
        r   )Úload_der_x509_csr)Úcryptography.x509rp  Ú"_dump_certificate_request_internalr(   )r€   rp  r—   r   r   r   Úto_cryptographyË  s   
zX509Req.to_cryptographyÚ
crypto_reqc                 C  ó6   t |tjƒs
tdƒ‚ddlm} | |j¡}tt	|ƒS )a  
        Construct based on a ``cryptography`` *crypto_req*.

        :param crypto_req: A ``cryptography`` X.509 certificate signing request
        :type crypto_req: ``cryptography.x509.CertificateSigningRequest``

        :rtype: X509Req

        .. versionadded:: 17.1.0
        z%Must be a certificate signing requestr   ©rš   )
rd   r   ÚCertificateSigningRequestre   r”   rš   r¨   r©   Ú"_load_certificate_request_internalr(   )r­   rt  rš   r—   r   r   r   Úfrom_cryptographyÙ  s
   
zX509Req.from_cryptographyr�   r/   c                 C  s    t  | j|j¡}t|dkƒ dS )zµ
        Set the public key of the certificate signing request.

        :param pkey: The public key to use.
        :type pkey: :py:class:`PKey`

        :return: ``None``
        r±   N)rM   ÚX509_REQ_set_pubkeyrk  rŒ   rW   ©r€   r�   rh   r   r   r   Ú
set_pubkeyï  s   	zX509Req.set_pubkeyc                 C  sD   t  t ¡}t | j¡|_t|jtjkƒ t 	|jtj
¡|_d|_|S )z‹
        Get the public key of the certificate signing request.

        :return: The public key.
        :rtype: :py:class:`PKey`
        T)r/   Ú__new__rM   ÚX509_REQ_get_pubkeyrk  rŒ   rW   rS   rX   rY   r‹   r•   rŽ   r   r   r   Ú
get_pubkeyû  s   
zX509Req.get_pubkeyÚversionrA   c                 C  s@   t |tƒs	tdƒ‚|dkrtdƒ‚t | j|¡}t|dkƒ dS )z±
        Set the version subfield (RFC 2986, section 4.1) of the certificate
        request.

        :param int version: The version number.
        :return: ``None``
        zversion must be an intr   z9Invalid version. The only valid version for X509Req is 0.r±   N)rd   rA   re   rg   rM   ÚX509_REQ_set_versionrk  rW   )r€   r€  rh   r   r   r   rl  	  s   
ÿzX509Req.set_versionc                 C  rÊ   )z¿
        Get the version subfield (RFC 2459, section 4.1.2.1) of the certificate
        request.

        :return: The value of the version subfield.
        :rtype: :py:class:`int`
        )rM   ÚX509_REQ_get_versionrk  r   r   r   r   Úget_version  s   zX509Req.get_versionr1   c                 C  s2   t  t ¡}t | j¡|_t|jtjkƒ | |_	|S )aÝ  
        Return the subject of this certificate signing request.

        This creates a new :class:`X509Name` that wraps the underlying subject
        name field on the certificate signing request. Modifying it will modify
        the underlying signing request, and will have the effect of modifying
        any other :class:`X509Name` that refers to this subject.

        :return: The subject of this certificate signing request.
        :rtype: :class:`X509Name`
        )
r1   r}  rM   ÚX509_REQ_get_subject_namerk  r†   rW   rS   rX   Ú_ownerr„   r   r   r   Úget_subject$  s
   
zX509Req.get_subjectÚ
extensionsúIterable[X509Extension]c                 C  s|   t jdtdd� t ¡ }t|tjkƒ t |tj	¡}|D ]}t
|tƒs'tdƒ‚t ||j¡ qt | j|¡}t|dkƒ dS )z×
        Add extensions to the certificate signing request.

        :param extensions: The X.509 extensions to add.
        :type extensions: iterable of :py:class:`X509Extension`
        :return: ``None``
        úƒThis API is deprecated and will be removed in a future version of pyOpenSSL. You should use pyca/cryptography's X.509 APIs instead.é   ©Ú
stacklevelú+One of the elements is not an X509Extensionr±   N)ÚwarningsÚwarnÚDeprecationWarningrM   Úsk_X509_EXTENSION_new_nullrW   rS   rX   rY   Úsk_X509_EXTENSION_freerd   r0   rg   Úsk_X509_EXTENSION_pushr>  ÚX509_REQ_add_extensionsrk  )r€   r‡  ÚstackÚextr  r   r   r   Úadd_extensions:  s   ù

zX509Req.add_extensionsúlist[X509Extension]c                 C  s~   t jdtdd� g }t | j¡}t |dd„ ¡}tt 	|¡ƒD ]}t
 t
¡}t t ||¡¡}t |tj¡|_| |¡ q|S )zé
        Get X.509 extensions in the certificate signing request.

        :return: The X.509 extensions in this request.
        :rtype: :py:class:`list` of :py:class:`X509Extension` objects.

        .. versionadded:: 0.15
        r‰  rŠ  r‹  c                 S  s   t  | t t jd¡¡S )Nr=  )rM   Úsk_X509_EXTENSION_pop_freerS   Ú	addressofÚ_original_lib)Úxr   r   r   r   r  s    þz(X509Req.get_extensions.<locals>.<lambda>)rŽ  r�  r�  rM   ÚX509_REQ_get_extensionsrk  rS   rY   r  Úsk_X509_EXTENSION_numr0   r}  ÚX509_EXTENSION_dupÚsk_X509_EXTENSION_valuer=  r>  rƒ   )r€   ÚextsÚnative_exts_objr  r–  r@  r   r   r   Úget_extensions[  s&   	ù
þ

ÿzX509Req.get_extensionsÚdigestr   c                 C  s^   |j rtdƒ‚|jstdƒ‚t t|ƒ¡}|tjkrtdƒ‚t | j	|j
|¡}t|dkƒ dS )aa  
        Sign the certificate signing request with this key and digest type.

        :param pkey: The key pair to sign with.
        :type pkey: :py:class:`PKey`
        :param digest: The name of the message digest to use for the signature,
            e.g. :py:data:`"sha256"`.
        :type digest: :py:class:`str`
        :return: ``None``
        zKey has only public partúKey is uninitializedúNo such digest methodr   N)r•   rg   r�   rM   ÚEVP_get_digestbynamer  rS   rX   ÚX509_REQ_signrk  rŒ   rW   )r€   r�   r¤  Ú
digest_objÚsign_resultr   r   r   Úsign�  s   
zX509Req.signrÂ   c                 C  s4   t |tƒs	tdƒ‚t | j|j¡}|dkrtƒ  |S )a@  
        Verifies the signature on this certificate signing request.

        :param PKey key: A public key.

        :return: ``True`` if the signature is correct.
        :rtype: bool

        :raises OpenSSL.crypto.Error: If the signature is invalid or there is a
            problem verifying the signature.
        úpkey must be a PKey instancer   )rd   r/   re   rM   ÚX509_REQ_verifyrk  rŒ   rÈ   )r€   r�   r¿   r   r   r   Úverify™  s   
zX509Req.verifyNrˆ   )r   rn  )rt  rn  r   r2   ©r�   r/   r   rc   ©r   r/   ©r€  rA   r   rc   rÏ   ©r   r1   ©r‡  rˆ  r   rc   )r   r˜  ©r�   r/   r¤  r   r   rc   )r�   r/   r   rÂ   )rD   rE   rF   rG   r�   rs  rÐ   ry  r|  r  rl  rƒ  r†  r—  r£  r«  r®  r   r   r   r   r2   ¹  s    









!
&r2   c                   @  sX  e Zd ZdZd`dd„Zedadd	„ƒZdbdd„Zedcdd„ƒZdddd„Z	dedd„Z
dfdd„Zdgdd„Zdhdd„Zdid!d"„Zdjd$d%„Zded&d'„Zdkd)d*„Zded+d,„Zdld.d/„Zdld0d1„Zdmd3d4„Zdnd7d8„Zdod9d:„Zdpd=d>„Zdqd?d@„ZdodAdB„ZdqdCdD„ZdrdFdG„ZdsdIdJ„ZdtdKdL„ZdudNdO„ZdtdPdQ„Z dvdSdT„Z!dedUdV„Z"dwdYdZ„Z#dxd]d^„Z$d_S )yr-   z
    An X.509 certificate.
    r   rc   c                 C  s:   t  ¡ }t|tjkƒ t |t j¡| _tƒ | _	tƒ | _
d S r   )rM   ÚX509_newrW   rS   rX   rY   Ú	X509_freer9  r}   Ú_issuer_invalidatorÚ_subject_invalidator)r€   r   r   r   r   r�   ´  s
   zX509.__init__r   r   c                 C  s.   |   | ¡}t |tj¡|_tƒ |_tƒ |_|S r   )	r}  rS   rY   rM   r¶  r9  r}   r·  r¸  )r­   r   Úcertr   r   r   Ú_from_raw_x509_ptr¼  s
   
zX509._from_raw_x509_ptrúx509.Certificatec                 C  ro  )z�
        Export as a ``cryptography`` certificate.

        :rtype: ``cryptography.x509.Certificate``

        .. versionadded:: 17.1.0
        r   )Úload_der_x509_certificate)rq  r¼  r7   r(   )r€   r¼  r—   r   r   r   rs  Ä  s   
zX509.to_cryptographyÚcrypto_certc                 C  ru  )zü
        Construct based on a ``cryptography`` *crypto_cert*.

        :param crypto_key: A ``cryptography`` X.509 certificate.
        :type crypto_key: ``cryptography.x509.Certificate``

        :rtype: X509

        .. versionadded:: 17.1.0
        zMust be a certificater   rv  )
rd   r   ÚCertificatere   r”   rš   r¨   r©   r=   r(   )r­   r½  rš   r—   r   r   r   ry  Ñ  s
   
zX509.from_cryptographyr€  rA   c                 C  s,   t |tƒs	tdƒ‚tt | j|¡dkƒ dS )a	  
        Set the version number of the certificate. Note that the
        version value is zero-based, eg. a value of 0 is V1.

        :param version: The version number of the certificate.
        :type version: :py:class:`int`

        :return: ``None``
        zversion must be an integerr±   N)rd   rA   re   rW   rM   ÚX509_set_versionr9  )r€   r€  r   r   r   rl  å  s   

zX509.set_versionc                 C  rÊ   )z˜
        Return the version number of the certificate.

        :return: The version number of the certificate.
        :rtype: :py:class:`int`
        )rM   ÚX509_get_versionr9  r   r   r   r   rƒ  ô  ó   zX509.get_versionr/   c                 C  sF   t  t ¡}t | j¡|_|jtjkrtƒ  t 	|jtj
¡|_d|_|S )z{
        Get the public key of the certificate.

        :return: The public key.
        :rtype: :py:class:`PKey`
        T)r/   r}  rM   ÚX509_get_pubkeyr9  rŒ   rS   rX   rÈ   rY   r‹   r•   rŽ   r   r   r   r  ý  s   
zX509.get_pubkeyr�   c                 C  s2   t |tƒs	tdƒ‚t | j|j¡}t|dkƒ dS )z¥
        Set the public key of the certificate.

        :param pkey: The public key.
        :type pkey: :py:class:`PKey`

        :return: :py:data:`None`
        r¬  r±   N)rd   r/   re   rM   ÚX509_set_pubkeyr9  rŒ   rW   r{  r   r   r   r|    s   
	zX509.set_pubkeyr¤  r   c                 C  sp   t |tƒs	tdƒ‚|jrtdƒ‚|jstdƒ‚t t|ƒ¡}|t	j
kr'tdƒ‚t | j|j|¡}t|dkƒ dS )a  
        Sign the certificate with this key and digest type.

        :param pkey: The key to sign with.
        :type pkey: :py:class:`PKey`

        :param digest: The name of the message digest to use.
        :type digest: :py:class:`str`

        :return: :py:data:`None`
        r¬  zKey only has public partr¥  r¦  r   N)rd   r/   re   r•   rg   r�   rM   r§  r  rS   rX   Ú	X509_signr9  rŒ   rW   )r€   r�   r¤  Úevp_mdrª  r   r   r   r«    s   

z	X509.signr\   c                 C  sZ   t  | j¡}t d¡}t  |tjtj|¡ t  |d ¡}|t jkr%t	dƒ‚t 
t  |¡¡S )zþ
        Return the signature algorithm used in the certificate.

        :return: The name of the algorithm.
        :rtype: :py:class:`bytes`

        :raises ValueError: If the signature algorithm is undefined.

        .. versionadded:: 0.13
        zASN1_OBJECT **r   zUndefined signature algorithm)rM   ÚX509_get0_tbs_sigalgr9  rS   rT   ÚX509_ALGOR_get0rX   r
  r  rg   rt   Ú
OBJ_nid2ln)r€   Úsig_algÚalgrÛ   r   r   r   Úget_signature_algorithm7  s   

zX509.get_signature_algorithmÚdigest_namec                 C  s„   t  t|ƒ¡}|tjkrtdƒ‚t dt j¡}t dd¡}t|ƒ|d< t  	| j
|||¡}t|dkƒ d dd„ t ||d ¡D ƒ¡S )	a5  
        Return the digest of the X509 object.

        :param digest_name: The name of the digest algorithm to use.
        :type digest_name: :py:class:`str`

        :return: The digest of the object, formatted as
            :py:const:`b":"`-delimited hex pairs.
        :rtype: :py:class:`bytes`
        r¦  zunsigned char[]zunsigned int[]r±   r   ó   :c                 S  s   g | ]}t |ƒ ¡ ‘qS r   )r   Úupper)rÜ   Úchr   r   r   Ú
<listcomp>c  s    
ÿÿzX509.digest.<locals>.<listcomp>)rM   r§  r  rS   rX   rg   rT   ÚEVP_MAX_MD_SIZErV   ÚX509_digestr9  rW   rP  rH   )r€   rÌ  r¤  r^   ra  Údigest_resultr   r   r   r¤  J  s   

ÿþÿzX509.digestc                 C  rÊ   )z�
        Return the hash of the X509 subject.

        :return: The hash of the subject.
        :rtype: :py:class:`int`
        )rM   ÚX509_subject_name_hashr9  r   r   r   r   Úsubject_name_hashi  rÁ  zX509.subject_name_hashÚserialc                 C  sª   t |tƒs	tdƒ‚t|ƒdd… }| d¡}t d¡}t ||¡}t	|tj
kƒ t |d tj
¡}t |d ¡ t	|tj
kƒ t |tj¡}t | j|¡}t	|dkƒ dS )z±
        Set the serial number of the certificate.

        :param serial: The new serial number.
        :type serial: :py:class:`int`

        :return: :py:data`None`
        zserial must be an integerrŠ  Nrç   zBIGNUM**r   r±   )rd   rA   re   Úhexr  rS   rT   rM   Ú	BN_hex2bnrW   rX   ÚBN_to_ASN1_INTEGERr³   rY   ÚASN1_INTEGER_freeÚX509_set_serialNumberr9  )r€   rÖ  Ú
hex_serialÚhex_serial_bytesÚbignum_serialr¿   Úasn1_serialrh   r   r   r   Úset_serial_numberr  s   
	

zX509.set_serial_numberc              	   C  sp   t  | j¡}t  |tj¡}z$t  |¡}zt |¡}t|dƒ}|W t  	|¡ W t  
|¡ S t  	|¡ w t  
|¡ w )zx
        Return the serial number of this certificate.

        :return: The serial number.
        :rtype: int
        é   )rM   ÚX509_get_serialNumberr9  ÚASN1_INTEGER_to_BNrS   rX   Ú	BN_bn2hexrt   rA   r  r³   )r€   rß  rÞ  rÜ  Úhexstring_serialrÖ  r   r   r   Úget_serial_numberŽ  s   


þzX509.get_serial_numberÚamountc                 C  ó.   t |tƒs	tdƒ‚t | j¡}t ||¡ dS )zÍ
        Adjust the time stamp on which the certificate stops being valid.

        :param int amount: The number of seconds by which to adjust the
            timestamp.
        :return: ``None``
        úamount must be an integerN)rd   rA   re   rM   ÚX509_getm_notAfterr9  ÚX509_gmtime_adj)r€   rç  ÚnotAfterr   r   r   Úgmtime_adj_notAfter¢  s   
zX509.gmtime_adj_notAfterc                 C  rè  )z½
        Adjust the timestamp on which the certificate starts being valid.

        :param amount: The number of seconds by which to adjust the timestamp.
        :return: ``None``
        ré  N)rd   rA   re   rM   ÚX509_getm_notBeforer9  rë  )r€   rç  Ú	notBeforer   r   r   Úgmtime_adj_notBefore°  s   
zX509.gmtime_adj_notBeforerÂ   c                 C  sT   |   ¡ }|du rtdƒ‚| d¡}tj |d¡}tjj}tj |¡jdd�}||k S )z¡
        Check whether the certificate has expired.

        :return: ``True`` if the certificate has expired, ``False`` otherwise.
        :rtype: bool
        NzUnable to determine notAfterrþ   z%Y%m%d%H%M%SZ)Útzinfo)	Úget_notAfterrg   ré   ÚdatetimeÚstrptimeÚtimezoneÚutcÚnowÚreplace)r€   Ú
time_bytesÚtime_stringÚ	not_afterÚUTCÚutcnowr   r   r   Úhas_expired½  s   
zX509.has_expiredÚwhichrI   c                 C  s   t || jƒƒS r   )r|   r9  )r€   rÿ  r   r   r   Ú_get_boundary_timeÎ  rî   zX509._get_boundary_timec                 C  ó   |   tj¡S )a
  
        Get the timestamp at which the certificate starts being valid.

        The timestamp is formatted as an ASN.1 TIME::

            YYYYMMDDhhmmssZ

        :return: A timestamp string, or ``None`` if there is none.
        :rtype: bytes or NoneType
        )r   rM   rî  r   r   r   r   Úget_notBeforeÑ  ó   zX509.get_notBeforeúCallable[..., Any]rb   c                 C  s   t || jƒ|ƒS r   )ri   r9  )r€   rÿ  rb   r   r   r   Ú_set_boundary_timeÞ  s   zX509._set_boundary_timec                 C  ó   |   tj|¡S )zî
        Set the timestamp at which the certificate starts being valid.

        The timestamp is formatted as an ASN.1 TIME::

            YYYYMMDDhhmmssZ

        :param bytes when: A timestamp string.
        :return: ``None``
        )r  rM   rî  ©r€   rb   r   r   r   Úset_notBeforeã  ó   zX509.set_notBeforec                 C  r  )a	  
        Get the timestamp at which the certificate stops being valid.

        The timestamp is formatted as an ASN.1 TIME::

            YYYYMMDDhhmmssZ

        :return: A timestamp string, or ``None`` if there is none.
        :rtype: bytes or NoneType
        )r   rM   rê  r   r   r   r   rò  ð  r  zX509.get_notAfterc                 C  r  )zí
        Set the timestamp at which the certificate stops being valid.

        The timestamp is formatted as an ASN.1 TIME::

            YYYYMMDDhhmmssZ

        :param bytes when: A timestamp string.
        :return: ``None``
        )r  rM   rê  r  r   r   r   Úset_notAfterý  r	  zX509.set_notAfterr1   c                 C  s0   t  t ¡}|| jƒ|_t|jtjkƒ | |_|S r   )r1   r}  r9  r†   rW   rS   rX   r…  )r€   rÿ  r‚   r   r   r   Ú	_get_name
  s
   
zX509._get_namer‚   c                 C  s0   t |tƒs	tdƒ‚|| j|jƒ}t|dkƒ d S )Nzname must be an X509Namer±   )rd   r1   re   r9  r†   rW   )r€   rÿ  r‚   rh   r   r   r   Ú	_set_name  s   
zX509._set_namec                 C  ó   |   tj¡}| j |¡ |S )a¥  
        Return the issuer of this certificate.

        This creates a new :class:`X509Name` that wraps the underlying issuer
        name field on the certificate. Modifying it will modify the underlying
        certificate, and will have the effect of modifying any other
        :class:`X509Name` that refers to this issuer.

        :return: The issuer of this certificate.
        :rtype: :class:`X509Name`
        )r  rM   ÚX509_get_issuer_namer·  r…   r„   r   r   r   Ú
get_issuer  ó   zX509.get_issuerr6  c                 C  ó   |   tj|¡ | j ¡  dS )zŸ
        Set the issuer of this certificate.

        :param issuer: The issuer.
        :type issuer: :py:class:`X509Name`

        :return: ``None``
        N)r  rM   ÚX509_set_issuer_namer·  r‡   )r€   r6  r   r   r   Ú
set_issuer+  ó   	zX509.set_issuerc                 C  r  )a©  
        Return the subject of this certificate.

        This creates a new :class:`X509Name` that wraps the underlying subject
        name field on the certificate. Modifying it will modify the underlying
        certificate, and will have the effect of modifying any other
        :class:`X509Name` that refers to this subject.

        :return: The subject of this certificate.
        :rtype: :class:`X509Name`
        )r  rM   ÚX509_get_subject_namer¸  r…   r„   r   r   r   r†  7  r  zX509.get_subjectr4  c                 C  r  )z£
        Set the subject of this certificate.

        :param subject: The subject.
        :type subject: :py:class:`X509Name`

        :return: ``None``
        N)r  rM   ÚX509_set_subject_namer¸  r‡   )r€   r4  r   r   r   Úset_subjectG  r  zX509.set_subjectc                 C  rÊ   )z¯
        Get the number of extensions on this certificate.

        :return: The number of extensions.
        :rtype: :py:class:`int`

        .. versionadded:: 0.12
        )rM   ÚX509_get_ext_countr9  r   r   r   r   Úget_extension_countS  s   	zX509.get_extension_countr‡  rˆ  c                 C  sN   t jdtdd� |D ]}t|tƒstdƒ‚t | j|j	d¡}t
|dkƒ q
dS )zÍ
        Add extensions to the certificate.

        :param extensions: The extensions to add.
        :type extensions: An iterable of :py:class:`X509Extension` objects.
        :return: ``None``
        r‰  rŠ  r‹  r�  rÿ   r±   N)rŽ  r�  r�  rd   r0   rg   rM   ÚX509_add_extr9  r>  rW   )r€   r‡  r–  r  r   r   r   r—  ^  s   ù

ûzX509.add_extensionsÚindexr0   c                 C  s^   t jdtdd� t t¡}t | j|¡|_|jt	j
krtdƒ‚t |j¡}t	 |tj¡|_|S )aÏ  
        Get a specific extension of the certificate by index.

        Extensions on a certificate are kept in order. The index
        parameter selects which extension will be returned.

        :param int index: The index of the extension to retrieve.
        :return: The extension at the specified index.
        :rtype: :py:class:`X509Extension`
        :raises IndexError: If the extension index was out of bounds.

        .. versionadded:: 0.12
        r‰  rŠ  r‹  zextension index out of bounds)rŽ  r�  r�  r0   r}  rM   ÚX509_get_extr9  r>  rS   rX   Ú
IndexErrorrŸ  rY   r=  )r€   r  r–  r@  r   r   r   Úget_extensionw  s   ù

zX509.get_extensionNrˆ   )r   r   r   r-   )r   r»  )r½  r»  r   r-   r±  rÏ   r°  r¯  r´  r1  )rÌ  r   r   r\   )rÖ  rA   r   rc   )rç  rA   r   rc   rÎ   )rÿ  r   r   rI   )r   rI   )rÿ  r  rb   r\   r   rc   )rb   r\   r   rc   )rÿ  r   r   r1   )rÿ  r   r‚   r1   r   rc   r²  )r6  r1   r   rc   )r4  r1   r   rc   r³  )r  rA   r   r0   )%rD   rE   rF   rG   r�   rÐ   rº  rs  ry  rl  rƒ  r  r|  r«  rË  r¤  rÕ  rà  ræ  rí  rð  rþ  r   r  r  r  rò  r
  r  r  r  r  r†  r  r  r—  r  r   r   r   r   r-   ¯  sH    




	





	

















r-   c                   @  sž   e Zd ZU dZejZded< ejZ	ded< ej
Zded< ejZded< ejZded< ejZded< ejZded	< ejZded
< ejZded< ejZded< dS )r6   a  
    Flags for X509 verification, used to change the behavior of
    :class:`X509Store`.

    See `OpenSSL Verification Flags`_ for details.

    .. _OpenSSL Verification Flags:
        https://www.openssl.org/docs/manmaster/man3/X509_VERIFY_PARAM_set_flags.html
    rA   Ú	CRL_CHECKÚCRL_CHECK_ALLÚIGNORE_CRITICALÚX509_STRICTÚALLOW_PROXY_CERTSÚPOLICY_CHECKÚEXPLICIT_POLICYÚINHIBIT_MAPÚCHECK_SS_SIGNATUREÚPARTIAL_CHAINN)rD   rE   rF   rG   rM   ÚX509_V_FLAG_CRL_CHECKr  rh  ÚX509_V_FLAG_CRL_CHECK_ALLr   ÚX509_V_FLAG_IGNORE_CRITICALr!  ÚX509_V_FLAG_X509_STRICTr"  ÚX509_V_FLAG_ALLOW_PROXY_CERTSr#  ÚX509_V_FLAG_POLICY_CHECKr$  ÚX509_V_FLAG_EXPLICIT_POLICYr%  ÚX509_V_FLAG_INHIBIT_MAPr&  ÚX509_V_FLAG_CHECK_SS_SIGNATUREr'  ÚX509_V_FLAG_PARTIAL_CHAINr(  r   r   r   r   r6   ™  s   
 
r6   c                   @  sP   e Zd ZdZddd„Zddd	„Zddd„Zddd„Zd dd„Z	d!d"dd„Z	dS )#r3   aº  
    An X.509 store.

    An X.509 store is used to describe a context in which to verify a
    certificate. A description of a context may include a set of certificates
    to trust, a set of certificate revocation lists, verification flags and
    more.

    An X.509 store, being only a description, cannot be used by itself to
    verify a certificate. To carry out the actual verification process, see
    :class:`X509StoreContext`.
    r   rc   c                 C  s   t  ¡ }t |t j¡| _d S r   )rM   ÚX509_STORE_newrS   rY   ÚX509_STORE_freeÚ_store©r€   Ústorer   r   r   r�   ¾  s   zX509Store.__init__r¹  r-   c                 C  s0   t |tƒstƒ ‚t | j|j¡}t|dkƒ dS )aÔ  
        Adds a trusted certificate to this store.

        Adding a certificate with this method adds this certificate as a
        *trusted* certificate.

        :param X509 cert: The certificate to add to this store.

        :raises TypeError: If the certificate is not an :class:`X509`.

        :raises OpenSSL.crypto.Error: If OpenSSL was unhappy with your
            certificate.

        :return: ``None`` if the certificate was added successfully.
        r±   N)rd   r-   re   rM   ÚX509_STORE_add_certr5  r9  rW   )r€   r¹  rÀ   r   r   r   Úadd_certÂ  s   
zX509Store.add_certÚcrlúx509.CertificateRevocationListc                 C  sv   t |tjƒr*ddlm} t| |j¡ƒ}t 	|t
j¡}t|t
jkƒ t
 |tj¡}ntdƒ‚tt | j|¡dkƒ dS )aþ  
        Add a certificate revocation list to this store.

        The certificate revocation lists added to a store will only be used if
        the associated flags are configured to check certificate revocation
        lists.

        .. versionadded:: 16.1.0

        :param crl: The certificate revocation list to add to this store.
        :type crl: ``cryptography.x509.CertificateRevocationList``
        :return: ``None`` if the certificate revocation list was added
            successfully.
        r   rv  z?CRL must be of type cryptography.x509.CertificateRevocationListN)rd   r   ÚCertificateRevocationListr”   rš   r[   r¨   r©   rM   Úd2i_X509_CRL_biorS   rX   rW   rY   ÚX509_CRL_freere   ÚX509_STORE_add_crlr5  )r€   r:  rš   rK   Úopenssl_crlr   r   r   Úadd_crlØ  s   ÿzX509Store.add_crlÚflagsrA   c                 C  s   t t | j|¡dkƒ dS )aÒ  
        Set verification flags to this store.

        Verification flags can be combined by oring them together.

        .. note::

          Setting a verification flag sometimes requires clients to add
          additional information to the store, otherwise a suitable error will
          be raised.

          For example, in setting flags to enable CRL checking a
          suitable CRL must be added to the store otherwise an error will be
          raised.

        .. versionadded:: 16.1.0

        :param int flags: The verification flags to set on this store.
            See :class:`X509StoreFlags` for available constants.
        :return: ``None`` if the verification flags were successfully set.
        r   N)rW   rM   ÚX509_STORE_set_flagsr5  )r€   rB  r   r   r   Ú	set_flagsö  s   zX509Store.set_flagsÚvfy_timeúdatetime.datetimec                 C  sF   t  ¡ }t |t j¡}t  |t | ¡ ¡¡ t	t  
| j|¡dkƒ dS )a¤  
        Set the time against which the certificates are verified.

        Normally the current time is used.

        .. note::

          For example, you can determine if a certificate was valid at a given
          time.

        .. versionadded:: 17.0.0

        :param datetime vfy_time: The verification time to set on this store.
        :return: ``None`` if the verification time was successfully set.
        r   N)rM   ÚX509_VERIFY_PARAM_newrS   rY   ÚX509_VERIFY_PARAM_freeÚX509_VERIFY_PARAM_set_timeÚcalendarÚtimegmÚ	timetuplerW   ÚX509_STORE_set1_paramr5  )r€   rE  Úparamr   r   r   Úset_time  s   ÿzX509Store.set_timeNÚcafileúStrOrBytesPath | NoneÚcapathc                 C  sR   |du rt j}nt|ƒ}|du rt j}nt|ƒ}t | j||¡}|s'tƒ  dS dS )aˆ  
        Let X509Store know where we can find trusted certificates for the
        certificate chain.  Note that the certificates have to be in PEM
        format.

        If *capath* is passed, it must be a directory prepared using the
        ``c_rehash`` tool included with OpenSSL.  Either, but not both, of
        *cafile* or *capath* may be ``None``.

        .. note::

          Both *cafile* and *capath* may be set simultaneously.

          Call this method multiple times to add more than one location.
          For example, CA certificates, and certificate revocation list bundles
          may be passed in *cafile* in subsequent calls to this method.

        .. versionadded:: 20.0

        :param cafile: In which file we can find the certificates (``bytes`` or
                       ``unicode``).
        :param capath: In which directory we can find the certificates
                       (``bytes`` or ``unicode``).

        :return: ``None`` if the locations were set successfully.

        :raises OpenSSL.crypto.Error: If both *cafile* and *capath* is ``None``
            or the locations could not be set for any reason.

        N)rS   rX   Ú_path_bytesrM   ÚX509_STORE_load_locationsr5  rÈ   )r€   rP  rR  Úload_resultr   r   r   Úload_locations&  s   #ÿ
ÿzX509Store.load_locationsrˆ   )r¹  r-   r   rc   )r:  r;  r   rc   )rB  rA   r   rc   )rE  rF  r   rc   r   )rP  rQ  rR  rQ  r   rc   )
rD   rE   rF   rG   r�   r9  rA  rD  rO  rV  r   r   r   r   r3   °  s    




ýr3   c                      s"   e Zd ZdZd‡ fd
d„Z‡  ZS )r5   zù
    An exception raised when an error occurred while verifying a certificate
    using `OpenSSL.X509StoreContext.verify_certificate`.

    :ivar certificate: The certificate which caused verificate failure.
    :type certificate: :class:`X509`
    Úmessager   Úerrorsú	list[Any]Úcertificater-   r   rc   c                   s   t ƒ  |¡ || _|| _d S r   )rÓ   r�   rX  rZ  )r€   rW  rX  rZ  r×   r   r   r�   c  s   
zX509StoreContextError.__init__)rW  r   rX  rY  rZ  r-   r   rc   )rD   rE   rF   rG   r�   rö   r   r   r×   r   r5   Z  s    r5   c                   @  sb   e Zd ZdZ	dddd„Zed dd„ƒZed!dd„ƒZd"dd„Zd#dd„Z	d$dd„Z
d%dd„ZdS )&r4   a9  
    An X.509 store context.

    An X.509 store context is used to carry out the actual verification process
    of a certificate in a described context. For describing such a context, see
    :class:`X509Store`.

    :param X509Store store: The certificates which will be trusted for the
        purposes of any verifications.
    :param X509 certificate: The certificate to be verified.
    :param chain: List of untrusted certificates that may be used for building
        the certificate chain. May be ``None``.
    :type chain: :class:`list` of :class:`X509`
    Nr7  r3   rZ  r-   ÚchainúSequence[X509] | Noner   rc   c                 C  s   || _ || _|  |¡| _d S r   )r5  Ú_certÚ_build_certificate_stackÚ_chain)r€   r7  rZ  r[  r   r   r   r�   {  s   zX509StoreContext.__init__Úcertificatesc                 C  sž   d	dd„}| d u st | ƒdkrtjS t ¡ }t|tjkƒ t ||¡}| D ]'}t|tƒs0t	dƒ‚tt 
|j¡dkƒ t ||j¡dkrLt |j¡ tƒ  q%|S )
NÚsr   r   rc   c                 S  s8   t t | ¡ƒD ]}t | |¡}t |¡ qt | ¡ d S r   )r  rM   Úsk_X509_numÚsk_X509_valuer¶  Úsk_X509_free)ra  r  rœ  r   r   r   Úcleanup‰  s   z:X509StoreContext._build_certificate_stack.<locals>.cleanupr   z+One of the elements is not an X509 instance)ra  r   r   rc   )rV   rS   rX   rM   Úsk_X509_new_nullrW   rY   rd   r-   re   ÚX509_up_refr9  Úsk_X509_pushr¶  rÈ   )r`  re  r•  r¹  r   r   r   r^  …  s   

€z)X509StoreContext._build_certificate_stackÚ	store_ctxr   r5   c                 C  s\   t  t t | ¡¡¡ d¡}t | ¡t | ¡|g}t | ¡}t |¡}t	 
|¡}t|||ƒS )zú
        Convert an OpenSSL native context error failure into a Python
        exception.

        When a call to native OpenSSL X509_verify_cert fails, additional
        information about the failure can be obtained from the store context.
        rþ   )rS   rt   rM   ÚX509_verify_cert_error_stringÚX509_STORE_CTX_get_errorré   ÚX509_STORE_CTX_get_error_depthÚX509_STORE_CTX_get_current_certÚX509_dupr-   rº  r5   )ri  rW  rX  r9  r]  Úpycertr   r   r   Ú_exception_from_context£  s   	ÿÿüý


z(X509StoreContext._exception_from_contextc                 C  sj   t  ¡ }t|tjkƒ t |t j¡}t  || jj| j	j
| j¡}t|dkƒ t  |¡}|dkr3|  |¡‚|S )a3  
        Verifies the certificate and runs an X509_STORE_CTX containing the
        results.

        :raises X509StoreContextError: If an error occurred when validating a
          certificate in the context. Sets ``certificate`` attribute to
          indicate which certificate caused the error.
        r±   r   )rM   ÚX509_STORE_CTX_newrW   rS   rX   rY   ÚX509_STORE_CTX_freeÚX509_STORE_CTX_initr5  r]  r9  r_  ÚX509_verify_certrp  )r€   ri  rl   r   r   r   Ú_verify_certificate½  s   	ÿ

z$X509StoreContext._verify_certificatec                 C  s
   || _ dS )zÖ
        Set the context's X.509 store.

        .. versionadded:: 0.15

        :param X509Store store: The store description which will be used for
            the purposes of any *future* verifications.
        N)r5  r6  r   r   r   Ú	set_storeÕ  s   
	zX509StoreContext.set_storec                 C  s   |   ¡  dS )a"  
        Verify a certificate in a context.

        .. versionadded:: 0.15

        :raises X509StoreContextError: If an error occurred when validating a
          certificate in the context. Sets ``certificate`` attribute to
          indicate which certificate caused the error.
        N)ru  r   r   r   r   Úverify_certificateà  r*  z#X509StoreContext.verify_certificateú
list[X509]c                 C  st   |   ¡ }t |¡}t|tjkƒ g }tt |¡ƒD ]}t ||¡}t|tjkƒ t	 
|¡}| |¡ qt |¡ |S )aR  
        Verify a certificate in a context and return the complete validated
        chain.

        :raises X509StoreContextError: If an error occurred when validating a
          certificate in the context. Sets ``certificate`` attribute to
          indicate which certificate caused the error.

        .. versionadded:: 20.0
        )ru  rM   ÚX509_STORE_CTX_get1_chainrW   rS   rX   r  rb  rc  r-   rº  rƒ   rd  )r€   ri  Ú
cert_stackr¿   r  r¹  ro  r   r   r   Úget_verified_chainì  s   


z#X509StoreContext.get_verified_chainr   )r7  r3   rZ  r-   r[  r\  r   rc   )r`  r\  r   rc   )ri  r   r   r5   rõ   )r7  r3   r   rc   rˆ   )r   rx  )rD   rE   rF   rG   r�   Ústaticmethodr^  rp  ru  rv  rw  r{  r   r   r   r   r4   k  s    ü



r4   r¯   c                 C  sv   t |tƒr
| d¡}t|ƒ}| tkrt |tjtjtj¡}n| t	kr*t 
|tj¡}ntdƒ‚|tjkr6tƒ  t |¡S )a  
    Load a certificate (X509) from the string *buffer* encoded with the
    type *type*.

    :param type: The file type (one of FILETYPE_PEM, FILETYPE_ASN1)

    :param bytes buffer: The buffer the certificate is stored in

    :return: The X509 object
    rç   ú3type argument must be FILETYPE_PEM or FILETYPE_ASN1)rd   r   r  r[   r)   rM   ÚPEM_read_bio_X509rS   rX   r(   Úd2i_X509_biorg   rÈ   r-   rº  )r¯   rH   rK   r   r   r   r   r=   	  s   



r=   r¹  c                 C  sn   t ƒ }| tkrt ||j¡}n| tkrt ||j¡}n| tkr)t ||jdd¡}nt	dƒ‚t
|dkƒ t|ƒS )a  
    Dump the certificate *cert* into a buffer string encoded with the type
    *type*.

    :param type: The file type (one of FILETYPE_PEM, FILETYPE_ASN1, or
        FILETYPE_TEXT)
    :param cert: The certificate to dump
    :return: The buffer with the dumped certificate in
    r   úCtype argument must be FILETYPE_PEM, FILETYPE_ASN1, or FILETYPE_TEXTr±   )r[   r)   rM   ÚPEM_write_bio_X509r9  r(   Úi2d_X509_bior*   ÚX509_print_exrg   rW   r`   )r¯   r¹  rK   Úresult_coder   r   r   r7   &  s   
ÿr7   r�   c                 C  sP   t ƒ }| tkrtj}n| tkrtj}ntdƒ‚|||jƒ}|dkr$tƒ  t	|ƒS )zú
    Dump a public key to a buffer.

    :param type: The file type (one of :data:`FILETYPE_PEM` or
        :data:`FILETYPE_ASN1`).
    :param PKey pkey: The public key to dump
    :return: The buffer with the dumped key in it.
    :rtype: bytes
    r}  r±   )
r[   r)   rM   ÚPEM_write_bio_PUBKEYr(   Úi2d_PUBKEY_biorg   rŒ   rÈ   r`   )r¯   r�   rK   Ú	write_bior„  r   r   r   r:   B  s   
r:   Úcipherr  Ú
passphraseúPassphraseCallableT | Nonec           	   	   C  s  t ƒ }t|tƒstdƒ‚|dur)|du rtdƒ‚t t|ƒ¡}|tjkr(t	dƒ‚ntj}t
| |ƒ}| tkrIt ||j|tjd|j|j¡}| ¡  n4| tkrUt ||j¡}n(| tkryt |j¡tjkrftdƒ‚t t |j¡tj¡}t ||d¡}nt	dƒ‚t|dkƒ t|ƒS )a…  
    Dump the private key *pkey* into a buffer string encoded with the type
    *type*.  Optionally (if *type* is :const:`FILETYPE_PEM`) encrypting it
    using *cipher* and *passphrase*.

    :param type: The file type (one of :const:`FILETYPE_PEM`,
        :const:`FILETYPE_ASN1`, or :const:`FILETYPE_TEXT`)
    :param PKey pkey: The PKey to dump
    :param cipher: (optional) if encrypted PEM format, the cipher to use
    :param passphrase: (optional) if encrypted PEM format, this can be either
        the passphrase to use, or a callback for providing the passphrase.

    :return: The buffer with the dumped key in
    :rtype: bytes
    zpkey must be a PKeyNzDif a value is given for cipher one must also be given for passphrasezInvalid cipher namer   z-Only RSA keys are supported for FILETYPE_TEXTr€  )r[   rd   r/   re   rM   ÚEVP_get_cipherbynamer  rS   rX   rg   Ú_PassphraseHelperr)   ÚPEM_write_bio_PrivateKeyrŒ   ÚcallbackÚcallback_argsÚraise_if_problemr(   Úi2d_PrivateKey_bior*   rË   rÄ   rY   rÅ   rÆ   Ú	RSA_printrW   r`   )	r¯   r�   rˆ  r‰  rK   Ú
cipher_objÚhelperr„  r    r   r   r   r9   [  sJ   
ÿ
ÿ
ù
	ÿr9   c                   @  sP   e Zd Z		dddd„Zeddd„ƒZeddd„ƒZefd dd„Zd!dd„Z	dS )"rŒ  Fr¯   rA   r‰  rŠ  Ú	more_argsrÂ   Útruncater   rc   c                 C  s4   |t kr|d urtdƒ‚|| _|| _|| _g | _d S )Nz0only FILETYPE_PEM key format supports encryption)r)   rg   Ú_passphraseÚ
_more_argsÚ	_truncateÚ	_problems)r€   r¯   r‰  r•  r–  r   r   r   r�   ¡  s   ÿ
z_PassphraseHelper.__init__r   c                 C  s<   | j d u rtjS t| j tƒst| j ƒrt d| j¡S tdƒ‚)NÚpem_password_cbú2Last argument must be a byte string or a callable.)	r—  rS   rX   rd   r\   ÚcallablerŽ  Ú_read_passphrasere   r   r   r   r   rŽ  ±  s   
ÿz_PassphraseHelper.callbackc                 C  s4   | j d u rtjS t| j tƒst| j ƒrtjS tdƒ‚)Nrœ  )r—  rS   rX   rd   r\   r�  re   r   r   r   r   r�  ¼  s   
ÿz_PassphraseHelper.callback_argsÚexceptionTypeútype[Exception]c                 C  s6   | j rzt|ƒ W n	 |y   Y nw | j  d¡‚d S r  )rš  Ú_exception_from_error_queueÚpop)r€   rŸ  r   r   r   r�  Ç  s   ÿùz"_PassphraseHelper.raise_if_problemr\  ÚsizeÚrwflagÚuserdatac              
   C  sÞ   zUt | jƒr| jr|  |||¡}n|  |¡}n
| jd usJ ‚| j}t|tƒs*tdƒ‚t|ƒ|kr>| jr:|d |… }ntdƒ‚tt|ƒƒD ]}|||d … ||< qDt|ƒW S  t	yn } z| j
 |¡ W Y d }~dS d }~ww )NzBytes expectedz+passphrase returned by callback is too longr±   r   )r�  r—  r˜  rd   r\   rg   rV   r™  r  Ú	Exceptionrš  rƒ   )r€   r\  r£  r¤  r¥  r¿   r  Úer   r   r   rž  Ñ  s.   

ÿ
€þz"_PassphraseHelper._read_passphraseN)FF)
r¯   rA   r‰  rŠ  r•  rÂ   r–  rÂ   r   rc   rõ   )rŸ  r   r   rc   )
r\  r   r£  rA   r¤  r   r¥  r   r   rA   )
rD   rE   rF   r�   rd  rŽ  r�  r.   r�  rž  r   r   r   r   rŒ     s    û


rŒ  ústr | bytesc                 C  s�   t |tƒr
| d¡}t|ƒ}| tkrt |tjtjtj¡}n| t	kr*t 
|tj¡}ntdƒ‚|tjkr6tƒ  t t¡}t |tj¡|_d|_|S )a<  
    Load a public key from a buffer.

    :param type: The file type (one of :data:`FILETYPE_PEM`,
        :data:`FILETYPE_ASN1`).
    :param buffer: The buffer the key is stored in.
    :type buffer: A Python string object, either unicode or bytestring.
    :return: The PKey object.
    :rtype: :class:`PKey`
    rç   r}  T)rd   r   r  r[   r)   rM   ÚPEM_read_bio_PUBKEYrS   rX   r(   Úd2i_PUBKEY_biorg   rÈ   r/   r}  rY   r‹   rŒ   r•   )r¯   rH   rK   Úevp_pkeyr�   r   r   r   r@   î  s    

ÿ

r@   c                 C  sœ   t |tƒr
| d¡}t|ƒ}t| |ƒ}| tkr't |tj	|j
|j¡}| ¡  n| tkr3t |tj	¡}ntdƒ‚|tj	kr?tƒ  t t¡}t |tj¡|_|S )a³  
    Load a private key (PKey) from the string *buffer* encoded with the type
    *type*.

    :param type: The file type (one of FILETYPE_PEM, FILETYPE_ASN1)
    :param buffer: The buffer the key is stored in
    :param passphrase: (optional) if encrypted PEM format, this can be
                       either the passphrase to use, or a callback for
                       providing the passphrase.

    :return: The PKey object
    rç   r}  )rd   r   r  r[   rŒ  r)   rM   ÚPEM_read_bio_PrivateKeyrS   rX   rŽ  r�  r�  r(   Úd2i_PrivateKey_biorg   rÈ   r/   r}  rY   r‹   rŒ   )r¯   rH   r‰  rK   r”  r«  r�   r   r   r   r?   	  s"   


ÿ


r?   rm  c                 C  sn   t ƒ }| tkrt ||j¡}n| tkrt ||j¡}n| tkr)t ||jdd¡}nt	dƒ‚t
|dkƒ t|ƒS )av  
    Dump the certificate request *req* into a buffer string encoded with the
    type *type*.

    :param type: The file type (one of FILETYPE_PEM, FILETYPE_ASN1)
    :param req: The certificate request to dump
    :return: The buffer with the dumped certificate request in


    .. deprecated:: 24.2.0
       Use `cryptography.x509.CertificateSigningRequest` instead.
    r   r€  )r[   r)   rM   ÚPEM_write_bio_X509_REQrk  r(   Úi2d_X509_REQ_bior*   ÚX509_REQ_print_exrg   rW   r`   )r¯   rm  rK   r„  r   r   r   r8   9	  s   ÿr8   rì   c                 C  sˆ   t |tƒr
| d¡}t|ƒ}| tkrt |tjtjtj¡}n| t	kr*t 
|tj¡}ntdƒ‚t|tjkƒ t t¡}t |tj¡|_|S )a—  
    Load a certificate request (X509Req) from the string *buffer* encoded with
    the type *type*.

    :param type: The file type (one of FILETYPE_PEM, FILETYPE_ASN1)
    :param buffer: The buffer the certificate request is stored in
    :return: The X509Req object

    .. deprecated:: 24.2.0
       Use `cryptography.x509.load_der_x509_csr` or
       `cryptography.x509.load_pem_x509_csr` instead.
    rç   r}  )rd   r   r  r[   r)   rM   ÚPEM_read_bio_X509_REQrS   rX   r(   Úd2i_X509_REQ_biorg   rW   r2   r}  rY   rj  rk  )r¯   rH   rK   rm  Úx509reqr   r   r   r>   g	  s   


r>   )r   r   r   r   r   r   r   )rH   rI   r   r   )rK   r   r   r\   )ra   r   rb   r\   r   rc   )rb   r\   r   r   )rn   r   r   rI   )r   rÙ   )r‚   r   r   rÑ   )r¯   rA   rH   r\   r   r-   )r¯   rA   r¹  r-   r   r\   )r¯   rA   r�   r/   r   r\   rc  )
r¯   rA   r�   r/   rˆ  r  r‰  rŠ  r   r\   )r¯   rA   rH   r¨  r   r/   )r¯   rA   rH   r¨  r‰  rŠ  r   r/   )r¯   rA   rm  r2   r   r\   )r¯   rA   rH   r\   r   r2   )oÚ
__future__r   rJ  ró  Ú	functoolsÚsysr–   rŽ  Úbase64r   Úcollections.abcr   r   r   r   r   r	   Úversion_infor   ÚTypeVarÚ_TÚtyping_extensionsÚcryptographyr   r   Ú)cryptography.hazmat.primitives.asymmetricr   r   r   r   r    ÚOpenSSL._utilr!   r"   r  r#   r¡  r$   rS   r%   rM   r&   Ú_make_assertr'   rS  Ú__all__rž   r    r¢   r¤   r¦   Ú_PrivateKeyrŸ   r¡   r£   r¥   r§   Ú
_PublicKeyr�   r\   ÚPassphraseCallableTÚSSL_FILETYPE_PEMr)   rh  ÚSSL_FILETYPE_ASN1r(   r*   rÄ   r,   ÚEVP_PKEY_DSAr+   ÚEVP_PKEY_DHrB   ÚEVP_PKEY_ECrC   r¦  r.   rÈ   rW   r[   r`   ri   rm   r|   r}   r/   rÑ   r<   r;   Útotal_orderingr1   r0   r2   r-   r6   r3   r5   r4   r=   r7   r:   r9   rŒ  r@   r?   r8   rr  rD   r�  r>   rx  r   r   r   r   Ú<module>   sö    


üÿüÿ


	

 Bgÿÿ Cÿ +ÿ s   m + 


üE
N%ý
) ø
 
ø