Team Ai
Datasetpublic

codekingpro/portable-devtools

sourceHugging Faceupdated 5mo agoView on Hugging Face
1likes15kdownloads
crypto.cpython-313.pyc990 linesDownload Raw Back to __pycache__
1�

2��j����%SSKJr SSKrSSKrSSKrSSKrSSKrSSKJr SSK	J3r4 SSKJr SSKJrJ
r
Jr \RS:�aSSKJr O.\RS	:a\R$"S55rSLSjrOSSKJr SSKJrJr SS
KJrJrJrJrJr SSKJr SSKJ r! SSKJ"r# SSKJ$r% SSKJ&r' SSKJ(r) SSKJ*r+ /SQr,\\RZ\R\\R^\R`\Rb4r2\\Rf\Rh\Rj\Rl\Rn4r8\\2\84r9\\:\
S\:44r;\'Rxr=S\>S'\'R~r@S\>S'SrA\'R�rCS\>S'\'R�rES\>S'\'R�rGS\>S'\'R�rIS\>S'"SS \J5rK\"\#\K5rL\)"\K5rMSMSNS!jjrNSOS"jrOSPS#jrPSQS$jrQSRS%jrR"S&S'5rS"S(S)5rT"S*S+5rU\"S,5SSS-j5rV\"S.5STS/j5rW\R�"S0S155rY\"S25"S3S455rZ"S5S65r["S7S85r\"S9S:5r]"S;S<\J5r^"S=S>5r_SUS?jr`SVS@jraSWSAjrbSXSYSBjjrc"SCSD5rdSZSEjreSMS[SFjjrfS\SGjrg\grh\R""\g\iS2\jSHSI9 S]SJjrk\krl\R""\k\iS2\jSKSI9 g)^�)�annotationsN)�	b16encode)�Sequence)�partial)�Any�Callable�Union)��
)�6deprecated)r7��Tc��S$)Nc��U$�N�)�fs �TD:\code\apps\devtools\python\user_packages\Python313\site-packages\OpenSSL/crypto.py�<lambda>�deprecated.<locals>.<lambda>s���r)�msg�kwargss  rrrs���r)�utils�x509)�dsa�ec�ed448�ed25519�rsa)�StrOrBytesPath)�byte_string)�exception_from_error_queue)�ffi)�lib)�make_assert)�8path_bytes)�
FILETYPE_ASN1�FILETYPE_PEM�
FILETYPE_TEXT�TYPE_DSA�TYPE_RSA�X509�Error�PKey�X509Name�X509Req�	X509Store�X509StoreContext�X509StoreContextError�X509StoreFlags�dump_certificate�dump_certificate_request�dump_privatekey�dump_publickey�get_elliptic_curve�get_elliptic_curves�load_certificate�load_certificate_request�load_privatekey�load_publickey.�intr)r(i��r,r+�TYPE_DH�TYPE_ECc��\rSrSrSrSrg)r.�rz/9An error occurred in an `OpenSSL.crypto` API.10rN)�__name__�11__module__�__qualname__�__firstlineno__�__doc__�__static_attributes__rrrr.r.rs��rr.c�b�Uc:[R"[R"55n[RnO?[R12"SU5n[R"U[U55nU4SSjjn[U[R:g5 [R"X5nU$)z�13Allocate a new OpenSSL memory BIO.14 15Arrange for the garbage collector to clean it up automatically.16 17:param buffer: None or some bytes to use to put into the BIO so that they18    can be read out.19�char[]c�.�[R"U5$r)�_lib�BIO_free)�bio�refs  r�free�_new_mem_buf.<locals>.free�s���=�=��%�%r)rPrrQr�returnr)rN�BIO_new�	BIO_s_memrO�_ffi�new�BIO_new_mem_buf�len�_openssl_assert�NULL�gc)�bufferrPrR�datas    r�_new_mem_bufr`|s}���~��l�l�4�>�>�+�,���}�}���x�x��&�)���"�"�4��V��5��'+�	&��C�4�9�9�$�%�20�'�'�#�21�C��Jrc��[R"S5n[R"X5n[R"USU5SS$)zG22Copy the contents of an OpenSSL BIO object into a Python byte string.23zchar**rN)rWrXrN�BIO_get_mem_datar^)rP�
result_buffer�
buffer_lengths   r�_bio_to_stringre�s=���H�H�X�&�M��)�)�#�=�M��;�;�}�Q�'��7��:�:rc���[U[5(d[S5e[U[R24:g5 [R"X5nUS:Xa[S5eg)a�25The the time value of an ASN1 time object.26 27@param boundary: An ASN1_TIME pointer (or an object safely28    castable to that type) which will have its value set.29@param when: A string representation of the desired time value.30 31@raise TypeError: If C{when} is not a L{bytes} string.32@raise ValueError: If C{when} does not represent a time in the required33    format.34@raise RuntimeError: If the time value cannot be set for some other35    (unspecified) reason.36zwhen must be a byte stringrzInvalid stringN)	�37isinstance�bytes�	TypeErrorr[rWr\rN�ASN1_TIME_set_string�38ValueError)�boundary�when�39set_results   r�_set_asn1_timero�sX���d�E�"�"��4�5�5��H��	�	�)�*��*�*�8�:�J��Q���)�*�*�rc���[R"5n[U[R:g5 [R40"U[R5n[X5 U$)al41Behaves like _set_asn1_time but returns a new ASN1_TIME object.42 43@param when: A string representation of the desired time value.44 45@raise TypeError: If C{when} is not a L{bytes} string.46@raise ValueError: If C{when} does not represent a time in the required47    format.48@raise RuntimeError: If the time value cannot be set for some other49    (unspecified) reason.50)rN�
ASN1_TIME_newr[rWr\r]�ASN1_TIME_freero)rm�rets  r�_new_asn1_timert�sF���51�52�53�C��C�4�9�9�$�%�54�'�'�#�t�*�*�55+�C��3���Jrc�b�[R"SU5n[R"U5S:Xag[R"U5[R56:Xa*[R"[R"U55$[R"S5n[R"X5 [US[R:g5 [R"SUS5n[R"U5n[R"U5n[R"US5 U$)aE57Retrieve the time value of an ASN1 time object.58 59@param timestamp: An ASN1_GENERALIZEDTIME* (or an object safely castable to60    that type) from which the time value will be retrieved.61 62@return: The time value from C{timestamp} as a L{bytes} string in a certain63    format.  Or C{None} if the object contains no time value.64zASN1_STRING*rNzASN1_GENERALIZEDTIME**)
rW�castrN�ASN1_STRING_length�ASN1_STRING_type�V_ASN1_GENERALIZEDTIME�string�ASN1_STRING_get0_datarX�ASN1_TIME_to_generalizedtimer[r\�ASN1_GENERALIZEDTIME_free)�	timestamp�string_timestamp�generalized_timestamp�string_data�
string_results     r�_get_asn1_timer��s����y�y���;�����/�0�A�5�����.�/�4�3N�3N�N��{�{�4�5�5�6F�G�H�H� $���)A� B���)�)�)�K��-�a�0�D�I�I�=�>��9�9�^�5J�1�5M�N���0�0�1A�B�����K�0�
��&�&�'<�Q�'?�@��rc�2�\rSrSrSSjrSSjrSSjrSrg)	�_X509NameInvalidator��c��/Ulgr��_names��selfs r�__init__�_X509NameInvalidator.__init__�s	��&(��rc�:�URRU5 gr)r��append�r��names  r�add�_X509NameInvalidator.add�s�������4� rc�.�URHnU?M gr)r��_namer�s  r�clear�_X509NameInvalidator.clear�s���K�K�D��65� rr�N�rT�None�r�r0rTr�)rErFrGrHr�r�r�rJrrrr�r��s��)�!�rr�c�p�\rSrSrSrSrSrSSjrSSjr\	SSj5r66SSjrSS	jrSS67jr
SSjrSrg
)r/��z<68A class representing an DSA or RSA public key or key pair.69FTc��[R"5n[R"U[R5UlSUlg)NF)rN�EVP_PKEY_newrWr]�
EVP_PKEY_free�_pkey�_initialized�r��pkeys  rr��
PKey.__init__�s0��� � �"���W�W�T�4�#5�#5�6��70�!��rc���SSKJnJn UR(a1[	[71U5n[R"[U"U55$[[72U5n[R"[U"USS95$)z�73Export as a ``cryptography`` key.74 75:rtype: One of ``cryptography``'s `key interfaces`_.76 77.. _key interfaces: https://cryptography.io/en/latest/hazmat/            primitives/asymmetric/rsa/#key-interfaces78 79.. versionadded:: 16.1.080r)�load_der_private_key�load_der_public_keyN)�password)81�,cryptography.hazmat.primitives.serializationr�r��_only_publicr9r(�typingrv�_Keyr8)r�r�r��ders    r�to_cryptography_key�PKey.to_cryptography_keysZ��	82�83��� ���5�C��;�;�t�%8��%=�>�>�!�-��6�C��;�;�t�%9�#��%M�N�Nrc
��[U[R[R[R84[R[R[R[R[R[R[R4855(d[!S5eSSKJnJnJnJn [U[R[R[R[R[R45(a4[-[.UR1UR2UR455$UR7UR2UR8U"55n[;[.U5$)z�86Construct based on a ``cryptography`` *crypto_key*.87 88:param crypto_key: A ``cryptography`` key.89:type crypto_key: One of ``cryptography``'s `key interfaces`_.90 91:rtype: PKey92 93.. versionadded:: 16.1.094zUnsupported key typer)�Encoding�NoEncryption�
PrivateFormat�PublicFormat)rgr�
DSAPrivateKey�DSAPublicKeyr�EllipticCurvePrivateKey�EllipticCurvePublicKeyr�Ed25519PrivateKey�Ed25519PublicKeyr�Ed448PrivateKey�Ed448PublicKeyr �
RSAPrivateKey�RSAPublicKeyrir�r�r�r�r�r?r(�public_bytes�DER�SubjectPublicKeyInfo�
private_bytes�PKCS8r>)�cls�95crypto_keyr�r�r�r�r�s       r�from_cryptography_key�PKey.from_cryptography_keys2�����!�!�� � ��*�*��)�)��)�)��(�(��%�%��$�$��!�!�� � �
�96�97��2�3�3�	98�	99���� � ��)�)��(�(��$�$�� � �
�	100�	101�"���'�'��L�L�,�"C�"C���
��*�*����m�1�1�<�>��C�#�=�#�6�6rc	��[U[5(d[S5e[U[5(d[S5eU[:Xa�US::a[	S5e[102R"5n[R"U[103R5n[104R"U[105R5 [106R"5n[107R"XBU[R5n[US:H5 [108R "UR"U5n[US:H5 GOU[$:XGa[109R&"5n[U[R:g5 [R"U[110R(5n[111R*"Xb[RS[R[R[R5n[US:H5 [[112R,"U5S:H5 [[113R."UR"U5S:H5 O[1S5eSUlg)	a�114Generate a key pair of the given type, with the given number of bits.115 116This generates a key "into" the this object.117 118:param type: The key type.119:type type: :py:data:`TYPE_RSA` or :py:data:`TYPE_DSA`120:param bits: The number of bits.121:type bits: :py:data:`int` ``>= 0``122:raises TypeError: If :py:data:`type` or :py:data:`bits` isn't123    of the appropriate type.124:raises ValueError: If the number of bits isn't an integer of125    the appropriate size.126:return: ``None``127ztype must be an integerzbits must be an integerrzInvalid number of bits�zNo such key typeTN)rgr@rir,rkrN�BN_newrWr]�BN_free�BN_set_word�RSA_F4�RSA_new�RSA_generate_key_exr\r[�EVP_PKEY_assign_RSAr�r+�DSA_new�DSA_free�DSA_generate_parameters_ex�DSA_generate_key�EVP_PKEY_set1_DSAr.r�)r��type�bits�exponentr �resultr�ress        r�generate_key�PKey.generate_keySs��� �$��$�$��5�6�6��$��$�$��5�6�6��8���q�y� �!9�:�:��{�{�}�H��w�w�x����6�H����X�t�{�{�3��,�,�.�C��-�-�c��4�9�9�M�F��F�a�K�(��-�-�d�j�j�#�>�F��F�a�K�(�
�X�
��,�,�.�C��C�4�9�9�,�-��'�'�#�t�}�}�-�C��1�1��4�9�9�a����D�I�I�t�y�y��C�
�C�1�H�%��D�1�1�#�6�!�;�<��D�2�2�4�:�:�s�C�q�H�I��*�+�+� ��rc��UR(a[S5e[R"UR	55[R128:wa[S5e[R"UR5n[R"U[R5n[R"U5nUS:Xag[5 g)a@129Check the consistency of an RSA private key.130 131This is the Python equivalent of OpenSSL's ``RSA_check_key``.132 133:return: ``True`` if key is consistent.134 135:raise OpenSSL.crypto.Error: if the key is inconsistent.136 137:raise TypeError: if the key is of a type which cannot be checked.138    Only RSA keys can currently be checked.139zpublic key onlyz'Only RSA keys can currently be checked.r�TN)
r�rirN�
EVP_PKEY_typer��EVP_PKEY_RSA�EVP_PKEY_get1_RSAr�rWr]�RSA_free�
RSA_check_key�_raise_current_error)r�r r�s   r�check�140PKey.check�s�������-�.�.����d�i�i�k�*�d�.?�.?�?��E�F�F��$�$�T�Z�Z�0���g�g�c�4�=�=�)���#�#�C�(���Q�;���rc�B�[R"UR5$)z<141Returns the type of the key142 143:return: The type of the key.144)rN�EVP_PKEY_idr�r�s rr��	PKey.type�s������145�146�+�+rc�B�[R"UR5$)zP147Returns the number of bits of the key148 149:return: The number of bits of the key.150)rN�
EVP_PKEY_bitsr�r�s rr��	PKey.bits�s���!�!�$�*�*�-�-r)r�r�Nr�)rTr�)r�r�rTr/)r�r@r�r@rTr��rT�bool�rTr@)rErFrGrHrIr�r�r�r��classmethodr�r�r�r�r�rJrrrr/r/�sH����L��L�"�151O�.�77��77�r6!�p�4,�.rr/c�^�\rSrSrSrSrSU4Sjjr\S
Sj5r\S
Sj5r	\SSj5r152SSjrSS	jrSS153jr
SrU=r$)�_EllipticCurvei�aB154A representation of a supported elliptic curve.155 156@cvar _curves: :py:obj:`None` until an attempt is made to load the curves.157    Thereafter, a :py:type:`set` containing :py:type:`_EllipticCurve`158    instances each of which represents one curve supported by the system.159@type _curves: :py:type:`NoneType` or :py:type:`set`160Nc�X>�[U[5(a[TU]
U5$[$)z�161Implement cooperation with the right-hand side argument of ``!=``.162 163Python 3 seems to have dropped this cooperation in this very narrow164circumstance.165)rgr��super�__ne__�NotImplemented)r��other�	__class__s  �rr��_EllipticCurve.__ne__�s'����e�^�,�,��7�>�%�(�(��rc��^^�TR[RS5n[R"SU5nTRX25 [	UU4SjU55$)z�166Get the curves supported by OpenSSL.167 168:param lib: The OpenSSL library binding object.169 170:return: A :py:type:`set` of ``cls`` instances giving the names of the171    elliptic curves the underlying library supports.172rzEC_builtin_curve[]c3�\># �UH!nTRTUR5v� M# g7fr)�from_nid�nid)�.0�cr�r%s  ��r�	<genexpr>�7_EllipticCurve._load_elliptic_curves.<locals>.<genexpr>�s#����D�^��3�<�<��Q�U�U�+�+�^�s�),)�EC_get_builtin_curvesrWr\rX�set)r�r%�173num_curves�builtin_curvess``  r�_load_elliptic_curves�$_EllipticCurve._load_elliptic_curves�sM����.�.�t�y�y�!�<�174����"6�175�C��	�!�!�.�=��D�^�D�D�Drc�`�URcURU5UlUR$)z�176Get, cache, and return the curves supported by OpenSSL.177 178:param lib: The OpenSSL library binding object.179 180:return: A :py:type:`set` of ``cls`` instances giving the names of the181    elliptic curves the underlying library supports.182)�_curvesr)r�r%s  r�_get_elliptic_curves�#_EllipticCurve._get_elliptic_curves�s*���;�;���3�3�C�8�C�K��{�{�rc	�x�U"X[R"URU55RS55$)a�183Instantiate a new :py:class:`_EllipticCurve` associated with the given184OpenSSL NID.185 186:param lib: The OpenSSL library binding object.187 188:param nid: The OpenSSL NID the resulting curve object will represent.189    This must be a curve NID (and not, for example, a hash NID) or190    subsequent operations will fail in unpredictable ways.191:type nid: :py:class:`int`192 193:return: The curve object.194�ascii)rWrz�195OBJ_nid2sn�decode)r�r%r�s   rr��_EllipticCurve.from_nid�s.���3�T�[�[�����)<�=�D�D�W�M�N�Nrc�(�XlX lX0lg)aA196:param _lib: The :py:mod:`cryptography` binding instance used to197    interface with OpenSSL.198 199:param _nid: The OpenSSL NID identifying the curve this object200    represents.201:type _nid: :py:class:`int`202 203:param name: The OpenSSL short name identifying the curve this object204    represents.205:type name: :py:class:`unicode`206N�rN�_nidr�)r�r%r�r�s    rr��_EllipticCurve.__init__�s���	��	��	rc�$�SUR<S3$)Nz<Curve �>�r�r�s r�__repr__�_EllipticCurve.__repr__s������
�Q�'�'rc��URRUR5n[R"U[R2075$)z�208Create a new OpenSSL EC_KEY structure initialized to use this curve.209 210The structure is automatically garbage collected when the Python object211is garbage collected.212)rN�EC_KEY_new_by_curve_namerrWr]�EC_KEY_free)r��keys  r�213_to_EC_KEY�_EllipticCurve._to_EC_KEYs3���i�i�0�0����;���w�w�s�D�,�,�-�-rr�r�rrTr�)r%rrT�set[_EllipticCurve])r%rr�r@rTr�)r%rr�r@r��strrTr��rTr!�rTr)rErFrGrHrIrr�r�rr	r�r�rrrJ�
__classcell__�r�s@rr�r��sh�����G�	��E��E�"�����O��O� �"(�.�.rr�zSget_elliptic_curves is deprecated. You should use the APIs in cryptography instead.c�4�[R[5$)as214Return a set of objects representing the elliptic curves supported in the215OpenSSL build in use.216 217The curve objects have a :py:class:`unicode` ``name`` attribute by which218they identify themselves.219 220The curve objects are useful as values for the argument accepted by221:py:meth:`Context.set_tmp_ecdh` to specify which elliptical curve should be222used for ECDHE key exchange.223)r�r	rNrrrr;r;s�� �.�.�t�4�4rzRget_elliptic_curve is deprecated. You should use the APIs in cryptography instead.c�d�[5HnURU:XdMUs $ [SU5e)a8224Return a single curve object selected by name.225 226See :py:func:`get_elliptic_curves` for information about curve objects.227 228:param name: The OpenSSL short name identifying the curve object to229    retrieve.230:type name: :py:class:`unicode`231 232If the named curve is not supported then :py:class:`ValueError` is raised.233zunknown curve name)r;r�rk)r��curves  rr:r:0s2�� %�&���:�:����L�'��)�4�2340�0rc�^�\rSrSrSrS
SjrSU4SjjrSSjrSSjrSSjr	SSjr235SS	jrSS236jrSSjr
SrU=r$)r0iFa�237An X.509 Distinguished Name.238 239:ivar countryName: The country of the entity.240:ivar C: Alias for  :py:attr:`countryName`.241 242:ivar stateOrProvinceName: The state or province of the entity.243:ivar ST: Alias for :py:attr:`stateOrProvinceName`.244 245:ivar localityName: The locality of the entity.246:ivar L: Alias for :py:attr:`localityName`.247 248:ivar organizationName: The organization name of the entity.249:ivar O: Alias for :py:attr:`organizationName`.250 251:ivar organizationalUnitName: The organizational unit of the entity.252:ivar OU: Alias for :py:attr:`organizationalUnitName`253 254:ivar commonName: The common name of the entity.255:ivar CN: Alias for :py:attr:`commonName`.256 257:ivar emailAddress: The e-mail address of the entity.258c��[R"UR5n[R"U[R2595Ulg)z~260Create a new X509Name, copying the given X509Name instance.261 262:param name: The name to copy.263:type name: :py:class:`X509Name`264N)rN�
X509_NAME_dupr�rWr]�X509_NAME_freer�s  rr��X509Name.__init__`s0���!�!�$�*�*�-���'�'�$��(;�(;�<��265rc	��>�URS5(a[T	U]	X5$[U5[La#[S[U5RSS35e[R"[U55nU[R:Xa[5 [S5e[[R"UR 55H�n[R""UR U5n[R$"U5n[R&"U5nX7:XdMW[R("UR U5n[R*"U5  O [-U[5(aUR/S5n[R0"UR U[R2U[5U5SS5nU(d[5 gg![a GNIf=f)	N�_z$attribute name must be string, not 'z.200�'�No such attribute�utf-8�����r)�266startswithr��__setattr__r�r!rirErN�OBJ_txt2nid�_byte_string�	NID_undefr�r.�AttributeError�range�X509_NAME_entry_countr��X509_NAME_get_entry�X509_NAME_ENTRY_get_object�OBJ_obj2nid�X509_NAME_delete_entry�X509_NAME_ENTRY_freerg�encode�X509_NAME_add_entry_by_NID�
MBSTRING_UTF8rZ)267r�r��valuer��i�ent�ent_obj�ent_nid�268add_resultr�s269         �rr5�X509Name.__setattr__js�����?�?�3����7�&�t�3�3���:�S� �����K�(�(��.�a�1��
�270���|�D�1�2���$�.�.� �
�$�&�!�!4�5�5��t�1�1�$�*�*�=�>�A��*�*�4�:�:�q�9�C��5�5�c�:�G��&�&�w�/�G��~��1�1�$�*�*�a�@���)�)�#�.��?��e�S�!�!��L�L��)�E��4�4��J�J��T�/�/���E�271�B��272�273�� �"���)�
��
�s�274G�275G$�#G$c��[R"[U55nU[R:Xa[	5 [
S5e[R"URUS5nUS:Xag[R"URU5n[R"U5n[R"S5n[R"Xe5n[US:�5 [R"USU5SSR!S5n[R""US5 U$![276a N�f=f![R""US5 f=f)z�277Find attribute. An X509Name object has the following attributes:278countryName (alias C), stateOrProvince (alias ST), locality (alias L),279organization (alias O), organizationalUnit (alias OU), commonName280(alias CN) and more...281r1r3N�unsigned char**rr2)rNr6r7r8r�r.r9�X509_NAME_get_index_by_NIDr�r<�X509_NAME_ENTRY_get_datarWrX�ASN1_STRING_to_UTF8r[r^r�OPENSSL_free)	r�r�r��entry_index�entryr_rc�data_lengthr�s	         r�__getattr__�X509Name.__getattr__�s$�����|�D�1�2���$�.�.� �
�$�&�!�!4�5�5��5�5�d�j�j�#�r�J���"����(�(����[�A���,�,�U�3�����!2�3�
��.�.�}�C����q�(�)�	0��[�[��q�!1�;�?��B�I�I���F�282
���m�A�.�/��
��-�
��
��*
���m�A�.�/�s�283D,�%,D<�,284D9�8D9�<Ec��[U[5(d[$[R"UR285UR2865S:H$�Nr�rgr0r�rN�
X509_NAME_cmpr��r�r�s  r�__eq__�X509Name.__eq__�s5���%��*�*�!�!��!�!�$�*�*�e�k�k�:�a�?�?rc��[U[5(d[$[R"UR287UR2885S:$rWrXrZs  r�__lt__�X509Name.__lt__�s5���%��*�*�!�!��!�!�$�*�*�e�k�k�:�Q�>�>rc�&�[R"SS5n[R"URU[U55n[
U[R:g5 SR[R"U5RS55$)z&289String representation of an X509Name290rLiz<X509Name object '{}'>r2)rWrXrN�X509_NAME_oneliner�rZr[r\�formatrzr)r�rc�
format_results   rr�X509Name.__repr__�sq������3�/�
��.�.��J�J�
�s�=�'9�291�
�	�
����2�3�'�.�.��K�K�
�&�-�-�g�6�292�	293rc�B�[R"UR5$)z�294Return an integer representation of the first four bytes of the295MD5 digest of the DER representation of the name.296 297This is the Python equivalent of OpenSSL's ``X509_NAME_hash``.298 299:return: The (integer) hash of this name.300:rtype: :py:class:`int`301)rN�X509_NAME_hashr�r�s r�hash�
X509Name.hash�s���"�"�4�:�:�.�.rc���[R"S5n[R"URU5n[US:�5 [R"USU5SSn[R"US5 U$)zn302Return the DER encoding of this name.303 304:return: The DER encoded form of this name.305:rtype: :py:class:`bytes`306rLrN)rWrXrN�
i2d_X509_NAMEr�r[r^rP)r�rc�
encode_resultr�s    rr��X509Name.der�si�����!2�3�
��*�*�4�:�:�}�E�
��
��*�+����M�!�$4�m�D�Q�G�
����-��*�+��rc�.�/n[[R"UR55H�n[R"URU5n[R307"U5n[R"U5n[R"U5n[R"U5n[R"[R"U5[R"U55SSnUR[R"U5U45 M� U$)z�308Returns the components of this name, as a sequence of 2-tuples.309 310:return: The components of this name.311:rtype: :py:class:`list` of ``name, value`` tuples.312N)r:rNr;r�r<r=rNr>r
rWr^r{rwr�rz)	r�r�rErF�fname�fvalr�r�rDs	         r�get_components�X509Name.get_components�s������t�1�1�$�*�*�=�>�A��*�*�4�:�:�q�9�C��3�3�C�8�E��0�0��5�D��"�"�5�)�C��?�?�3�'�D��K�K��*�*�4�0�$�2I�2I�$�2O����E�
�M�M�4�;�;�t�,�e�4�5�?� �
r)r�r�)r�r!rDrrTr�)r�r!rT�313str | Nonerr"r��rTrh)rTzlist[tuple[bytes, bytes]])rErFrGrHrIr�r5rTr[r^rrgr�rprJr$r%s@rr0r0Fs=����0=�%#�N&�P@�?�314�315/�
��rr0zPCSR support in pyOpenSSL is deprecated. You should use the APIs in cryptography.c��\rSrSrSrSSjrSSjr\SSj5rSSjr	SSjr316SSjrSS	jrSS317jr
SSjrSSjrS
rg)r1i	z~318An X.509 certificate signing requests.319 320.. deprecated:: 24.2.0321   Use `cryptography.x509.CertificateSigningRequest` instead.322c��[R"5n[R"U[R5UlUR
S5 grW)rN�X509_REQ_newrWr]�
X509_REQ_free�_req�set_version)r��reqs  rr��X509Req.__init__s6�����!���G�G�C��!3�!3�4��	�����rc�>�SSKJn [[U5nU"U5$)z�323Export as a ``cryptography`` certificate signing request.324 325:rtype: ``cryptography.x509.CertificateSigningRequest``326 327.. versionadded:: 17.1.0328r)�load_der_x509_csr)�cryptography.x509r}�"_dump_certificate_request_internalr()r�r}r�s   r�to_cryptography�X509Req.to_cryptographys��	8�0���E�� ��%�%rc��[U[R5(d[S5eSSKJn UR
UR5n[[U5$)z�329Construct based on a ``cryptography`` *crypto_req*.330 331:param crypto_req: A ``cryptography`` X.509 certificate signing request332:type crypto_req: ``cryptography.x509.CertificateSigningRequest``333 334:rtype: X509Req335 336.. versionadded:: 17.1.0337z%Must be a certificate signing requestr�r�)338rgr�CertificateSigningRequestrir�r�r�r��"_load_certificate_request_internalr()r��339crypto_reqr�r�s    r�from_cryptography�X509Req.from_cryptography)sG���*�d�&D�&D�E�E��C�D�D�I��%�%�h�l�l�3��1�-��E�Erc�v�[R"URUR5n[	US:H5 g)z�340Set the public key of the certificate signing request.341 342:param pkey: The public key to use.343:type pkey: :py:class:`PKey`344 345:return: ``None``346r�N)rN�X509_REQ_set_pubkeyrxr�r[�r�r�rns   r�347set_pubkey�X509Req.set_pubkey?s*���-�-�d�i�i����D�348��349�a��(rc�D�[R[5n[R"UR5Ul[
UR350[R:g5 [R"UR351[R5UlSUlU$)zk352Get the public key of the certificate signing request.353 354:return: The public key.355:rtype: :py:class:`PKey`356T)r/�__new__rN�X509_REQ_get_pubkeyrxr�r[rWr\r]r�r�r�s  r�357get_pubkey�X509Req.get_pubkeyKsf���|�|�D�!���-�-�d�i�i�8��358���359�360�d�i�i�/�0��W�W�T�Z�Z��);�);�<��361� ����rc���[U[5(d[S5eUS:wa[S5e[R362"URU5n[US:H5 g)z�363Set the version subfield (RFC 2986, section 4.1) of the certificate364request.365 366:param int version: The version number.367:return: ``None``368zversion must be an intrz9Invalid version. The only valid version for X509Req is 0.r�N)rgr@rirkrN�X509_REQ_set_versionrxr[)r��versionrns   rry�X509Req.set_versionYsX���'�3�'�'��4�5�5��a�<��K��
��.�.�t�y�y�'�B�369��370�a��(rc�B�[R"UR5$)z�371Get the version subfield (RFC 2459, section 4.1.2.1) of the certificate372request.373 374:return: The value of the version subfield.375:rtype: :py:class:`int`376)rN�X509_REQ_get_versionrxr�s r�get_version�X509Req.get_versionjs���(�(����3�3rc���[R[5n[R"UR5Ul[
UR377[R:g5 Xl	U$)a�378Return the subject of this certificate signing request.379 380This creates a new :class:`X509Name` that wraps the underlying subject381name field on the certificate signing request. Modifying it will modify382the underlying signing request, and will have the effect of modifying383any other :class:`X509Name` that refers to this subject.384 385:return: The subject of this certificate signing request.386:rtype: :class:`X509Name`387)388r0r�rN�X509_REQ_get_subject_namerxr�r[rWr\�_ownerr�s  r�get_subject�X509Req.get_subjecttsK������)���3�3�D�I�I�>��389���390�391�d�i�i�/�0����rc�d�UR(a[S5eUR(d[S5e[R"[U55nU[R:Xa[S5e[R"URURU5n[US:�5 g)a!392Sign the certificate signing request with this key and digest type.393 394:param pkey: The key pair to sign with.395:type pkey: :py:class:`PKey`396:param digest: The name of the message digest to use for the signature,397    e.g. :py:data:`"sha256"`.398:type digest: :py:class:`str`399:return: ``None``400zKey has only public part�Key is uninitialized�No such digest methodrN)r�rkr�rN�EVP_get_digestbynamer7rWr\�
X509_REQ_signrxr�r[)r�r��digest�401digest_obj�sign_results     r�sign�X509Req.sign�s�������7�8�8�� � ��3�4�4��.�.�|�F�/C�D�402�����"��4�5�5��(�(����D�J�J�403�K����a��(rc��[U[5(d[S5e[R"UR404UR5nUS::a405[5 U$)a406Verifies the signature on this certificate signing request.407 408:param PKey key: A public key.409 410:return: ``True`` if the signature is correct.411:rtype: bool412 413:raises OpenSSL.crypto.Error: If the signature is invalid or there is a414    problem verifying the signature.415�pkey must be a PKey instancer)rgr/rirN�X509_REQ_verifyrxr�r�)r�r�r�s   r�verify�X509Req.verify�sI���$��%�%��:�;�;��%�%�d�i�i����<���Q�;� �"��
r)rxNr�)rT�x509.CertificateSigningRequest)r�r�rTr1�r�r/rTr��rTr/�r�r@rTr�r��rTr0�r�r/r�r!rTr�)r�r/rTr�)rErFrGrHrIr�r�r�r�r�r�ryr�r�r�r�rJrrrr1r1	s\��416��&��F�7�F�	�F��F�*417)��)�"4��,)�0rr1c�d�\rSrSrSrS#Sjr\S$Sj5rS%Sjr\S&Sj5r	S'Sjr418S(SjrS)S	jrS*S419jr
S+SjrS,SjrS-S
jrS(SjrS.SjrS(SjrS/SjrS/SjrS0SjrS1SjrS2SjrS3SjrS4SjrS2SjrS4SjrS5SjrS6SjrS7SjrS8Sjr S7Sjr!S9Sjr"S(S jr#S!r$g"):r-i�z420An X.509 certificate.421c���[R"5n[U[R:g5 [R422"U[R5Ul[5Ul	[5Ul423gr)rN�X509_newr[rWr\r]�	X509_free�_x509r��_issuer_invalidator�_subject_invalidator)r�rs  rr��
X509.__init__�sJ���}�}������	�	�)�*��W�W�T�4�>�>�2��424�#7�#9�� �$8�$:��!rc��URU5n[R"U[R5Ul[
5Ul[
5UlU$r)	r�rWr]rNr�r�r�r�r�)r�r�certs   r�_from_raw_x509_ptr�X509._from_raw_x509_ptr�sA���{�{�3����W�W�T�4�>�>�2��425�#7�#9�� �$8�$:��!��rc�>�SSKJn [[U5nU"U5$)zp426Export as a ``cryptography`` certificate.427 428:rtype: ``cryptography.x509.Certificate``429 430.. versionadded:: 17.1.0431r)�load_der_x509_certificate)r~r�r6r()r�r�r�s   rr��X509.to_cryptography�s��	@��}�d�3��(��-�-rc��[U[R5(d[S5eSSKJn UR
UR5n[[U5$)z�432Construct based on a ``cryptography`` *crypto_cert*.433 434:param crypto_key: A ``cryptography`` X.509 certificate.435:type crypto_key: ``cryptography.x509.Certificate``436 437:rtype: X509438 439.. versionadded:: 17.1.0440zMust be a certificaterr�)441rgr�Certificaterir�r�r�r�r<r()r��crypto_certr�r�s    rr��X509.from_cryptography�sG���+�t�'7�'7�8�8��3�4�4�I��&�&�x�|�|�4���
�s�3�3rc��[U[5(d[S5e[[R442"URU5S:H5 g)z�443Set the version number of the certificate. Note that the444version value is zero-based, eg. a value of 0 is V1.445 446:param version: The version number of the certificate.447:type version: :py:class:`int`448 449:return: ``None``450zversion must be an integerr�N)rgr@rir[rN�X509_set_versionr�)r�r�s  rry�X509.set_version�s;���'�3�'�'��8�9�9���-�-�d�j�j�'�B�a�G�Hrc�B�[R"UR5$)zx451Return the version number of the certificate.452 453:return: The version number of the certificate.454:rtype: :py:class:`int`455)rN�X509_get_versionr�r�s rr��X509.get_version�s���$�$�T�Z�Z�0�0rc�H�[R[5n[R"UR5UlUR456[R:Xa457[5 [R"UR458[R5UlSUlU$)z[459Get the public key of the certificate.460 461:return: The public key.462:rtype: :py:class:`PKey`463T)r/r�rN�X509_get_pubkeyr�r�rWr\r�r]r�r�r�s  rr��X509.get_pubkeysg���|�|�D�!���)�)�$�*�*�5��464��:�:����"� �"��W�W�T�Z�Z��);�);�<��465� ����rc��[U[5(d[S5e[R"UR466UR5n[US:H5 g)z}467Set the public key of the certificate.468 469:param pkey: The public key.470:type pkey: :py:class:`PKey`471 472:return: :py:data:`None`473r�r�N)rgr/rirN�X509_set_pubkeyr�r�r[r�s   rr��X509.set_pubkeysC���$��%�%��:�;�;��)�)�$�*�*�d�j�j�A�474��475�a��(rc��[U[5(d[S5eUR(a[	S5eUR476(d[	S5e[R"[U55nU[R:Xa[	S5e[R"URURU5n[US:�5 g)z�477Sign the certificate with this key and digest type.478 479:param pkey: The key to sign with.480:type pkey: :py:class:`PKey`481 482:param digest: The name of the message digest to use.483:type digest: :py:class:`str`484 485:return: :py:data:`None`486r�zKey only has public partr�r�rN)rgr/rir�rkr�rNr�r7rWr\�	X509_signr�r�r[)r�r�r��evp_mdr�s     rr��	X509.sign$s����$��%�%��:�;�;�����7�8�8�� � ��3�4�4��*�*�<��+?�@���T�Y�Y���4�5�5��n�n�T�Z�Z����V�D����a��(rc��[R"UR5n[R"S5n[R487"U[R[RU5 [R"US5nU[R:Xa[S5e[R"[R"U55$)z�488Return the signature algorithm used in the certificate.489 490:return: The name of the algorithm.491:rtype: :py:class:`bytes`492 493:raises ValueError: If the signature algorithm is undefined.494 495.. versionadded:: 0.13496zASN1_OBJECT **rzUndefined signature algorithm)rN�X509_get0_tbs_sigalgr�rWrX�X509_ALGOR_get0r\r>r8rkrz�497OBJ_nid2ln)r��sig_alg�algr�s    r�get_signature_algorithm�X509.get_signature_algorithm@s����+�+�D�J�J�7���h�h�'�(�����S�$�)�)�T�Y�Y��@����s�1�v�&���$�.�.� ��<�=�=��{�{�4�?�?�3�/�0�0rc��[R"[U55nU[R:Xa[S5e[R"S[R5n[R"SS5n[U5US'[R"URX#U5n[US:H5 SR[R"X4S5Vs/sHn[U5R5PM sn5$s snf)z�498Return the digest of the X509 object.499 500:param digest_name: The name of the digest algorithm to use.501:type digest_name: :py:class:`str`502 503:return: The digest of the object, formatted as504    :py:const:`b":"`-delimited hex pairs.505:rtype: :py:class:`bytes`506r�zunsigned char[]zunsigned int[]r�r�:)rNr�r7rWr\rkrX�EVP_MAX_MD_SIZErZ�X509_digestr�r[�joinr^r�upper)r��digest_namer�rc�
result_length�
digest_result�chs       rr��X509.digestSs����*�*�<��+D�E���T�Y�Y���4�5�5����!2�D�4H�4H�I�
����!1�1�5�
��}�-�
�a���(�(��J�J��}�507�
�	�
��*�+��y�y��+�+�m�1�5E�F�
�F�B��"�
�#�#�%�F�
�508�	509��
s�#D	c�B�[R"UR5$)za510Return the hash of the X509 subject.511 512:return: The hash of the subject.513:rtype: :py:class:`int`514)rN�X509_subject_name_hashr�r�s r�subject_name_hash�X509.subject_name_hashrs���*�*�4�:�:�6�6rc�t�[U[5(d[S5e[U5SSnUR	S5n[515R"S5n[R"XC5n[U[516R:g5 [R"US[517R5n[R"US5 [U[518R:g5 [519R"U[R5n[R"UR U5n[US:H5 g)z�520Set the serial number of the certificate.521 522:param serial: The new serial number.523:type serial: :py:class:`int`524 525:return: :py:data`None`526zserial must be an integer�NrzBIGNUM**rr�)rgr@ri�hexrArWrXrN�	BN_hex2bnr[r\�BN_to_ASN1_INTEGERr�r]�ASN1_INTEGER_free�X509_set_serialNumberr�)r��serial�527hex_serial�hex_serial_bytes�
bignum_serialr��asn1_serialrns        r�set_serial_number�X509.set_serial_number{s����&�#�&�&��7�8�8���[���_�528�%�,�,�W�5������,�
����
�@����$�)�)�+�,��-�-�m�A�.>��	�	�J�����]�1�%�&���t�y�y�0�1��g�g�k�4�+A�+A�B���/�/��529�530�K�H�531��532�a��(rc���[R"UR5n[R"U[R5335n[R"U5n[R"U5n[US5nU[R"U5 [R"U5 $![R"U5 f=f![R"U5 f=f)zX534Return the serial number of this certificate.535 536:return: The serial number.537:rtype: int538�)rN�X509_get_serialNumberr��ASN1_INTEGER_to_BNrWr\�	BN_bn2hexrzr@rPr�)r�r�r�r��hexstring_serialr�s      r�get_serial_number�X509.get_serial_number�s����0�0����<���/�/��T�Y�Y�G�
�		(����
�6�J�
.�#'�;�;�z�#:� ��-�r�2����!�!�*�-��L�L��'���!�!�*�-���L�L��'�s$�C	�#B.�C	�.C�C	�	C!c��[U[5(d[S5e[R"UR5395n[R"X!5 g)z�540Adjust the time stamp on which the certificate stops being valid.541 542:param int amount: The number of seconds by which to adjust the543    timestamp.544:return: ``None``545�amount must be an integerN)rgr@rirN�X509_getm_notAfterr��X509_gmtime_adj)r��amount�notAfters   r�gmtime_adj_notAfter�X509.gmtime_adj_notAfter�s?���&�#�&�&��7�8�8��*�*�4�:�:�6�����X�.rc��[U[5(d[S5e[R"UR5465n[R"X!5 g)z�547Adjust the timestamp on which the certificate starts being valid.548 549:param amount: The number of seconds by which to adjust the timestamp.550:return: ``None``551rN)rgr@rirN�X509_getm_notBeforer�r)r�r	�	notBefores   r�gmtime_adj_notBefore�X509.gmtime_adj_notBefore�s?���&�#�&�&��7�8�8��,�,�T�Z�Z�8�	����Y�/rc�4�UR5nUc[S5eURS5n[RR	US5n[R552Rn[RRU5RSS9nX5:$)z�553Check whether the certificate has expired.554 555:return: ``True`` if the certificate has expired, ``False`` otherwise.556:rtype: bool557NzUnable to determine notAfterr2z
%Y%m%d%H%M%SZ)�tzinfo)	�get_notAfterrkr�datetime�strptime�timezone�utc�now�replace)r��558time_bytes�time_string�	not_after�UTC�utcnows      r�has_expired�X509.has_expired�s����&�&�(�559����;�<�<� �'�'��0���%�%�.�.�{�O�L�	����#�#���"�"�&�&�s�+�3�3�4�3�@���!�!rc�8�[U"UR55$r)r�r�)r��whichs  r�_get_boundary_time�X509._get_boundary_time�s���e�D�J�J�/�0�0rc�@�UR[R5$)z�560Get the timestamp at which the certificate starts being valid.561 562The timestamp is formatted as an ASN.1 TIME::563 564    YYYYMMDDhhmmssZ565 566:return: A timestamp string, or ``None`` if there is none.567:rtype: bytes or NoneType568)r$rNrr�s r�
get_notBefore�X509.get_notBefore�s���&�&�t�'?�'?�@�@rc�:�[U"UR5U5$r)ror�)r�r#rms   r�_set_boundary_time�X509._set_boundary_time�s���e�D�J�J�/��6�6rc�B�UR[RU5$)z�569Set the timestamp at which the certificate starts being valid.570 571The timestamp is formatted as an ASN.1 TIME::572 573    YYYYMMDDhhmmssZ574 575:param bytes when: A timestamp string.576:return: ``None``577)r*rNr�r�rms  r�
set_notBefore�X509.set_notBefore�s���&�&�t�'?�'?��F�Frc�@�UR[R5$)z�578Get the timestamp at which the certificate stops being valid.579 580The timestamp is formatted as an ASN.1 TIME::581 582    YYYYMMDDhhmmssZ583 584:return: A timestamp string, or ``None`` if there is none.585:rtype: bytes or NoneType586)r$rNrr�s rr�X509.get_notAfter�s���&�&�t�'>�'>�?�?rc�B�UR[RU5$)z�587Set the timestamp at which the certificate stops being valid.588 589The timestamp is formatted as an ASN.1 TIME::590 591    YYYYMMDDhhmmssZ592 593:param bytes when: A timestamp string.594:return: ``None``595)r*rNrr-s  r�set_notAfter�X509.set_notAfters���&�&�t�'>�'>��E�Erc��[R[5nU"UR5Ul[	UR[596R:g5 XlU$r)r0r�r�r�r[rWr\r�)r�r#r�s   r�	_get_name�X509._get_namesC������)���4�:�:�&��597���598�599�d�i�i�/�0����rc��[U[5(d[S5eU"URUR5n[US:H5 g)Nzname must be an X509Namer�)rgr0rir�r�r[)r�r#r�rns    r�	_set_name�X509._set_names;���$��)�)��6�7�7��4�:�:�t�z�z�2�600��601�a��(rc�z�UR[R5nURR	U5 U$)ae602Return the issuer of this certificate.603 604This creates a new :class:`X509Name` that wraps the underlying issuer605name field on the certificate. Modifying it will modify the underlying606certificate, and will have the effect of modifying any other607:class:`X509Name` that refers to this issuer.608 609:return: The issuer of this certificate.610:rtype: :class:`X509Name`611)r6rN�X509_get_issuer_namer�r�r�s  r�612get_issuer�X509.get_issuer$s1���~�~�d�7�7�8��� � �$�$�T�*��rc�x�UR[RU5 URR	5 g)zw613Set the issuer of this certificate.614 615:param issuer: The issuer.616:type issuer: :py:class:`X509Name`617 618:return: ``None``619N)r9rN�X509_set_issuer_namer�r�)r��issuers  r�620set_issuer�X509.set_issuer4s*��	
���t�0�0�&�9�� � �&�&�(rc�z�UR[R5nURR	U5 U$)ai621Return the subject of this certificate.622 623This creates a new :class:`X509Name` that wraps the underlying subject624name field on the certificate. Modifying it will modify the underlying625certificate, and will have the effect of modifying any other626:class:`X509Name` that refers to this subject.627 628:return: The subject of this certificate.629:rtype: :class:`X509Name`630)r6rN�X509_get_subject_namer�r�r�s  rr��X509.get_subject@s1���~�~�d�8�8�9���!�!�%�%�d�+��rc�x�UR[RU5 URR	5 g)z{631Set the subject of this certificate.632 633:param subject: The subject.634:type subject: :py:class:`X509Name`635 636:return: ``None``637N)r9rN�X509_set_subject_namer�r�)r��subjects  r�set_subject�X509.set_subjectPs*��	
���t�1�1�7�;��!�!�'�'�)rc�B�[R"UR5$)z�638Get the number of extensions on this certificate.639 640:return: The number of extensions.641:rtype: :py:class:`int`642 643.. versionadded:: 0.12644)rN�X509_get_ext_countr�r�s r�get_extension_count�X509.get_extension_count\s���&�&�t�z�z�2�2r)r�r�r�Nr�)rrrTr-)rT�x509.Certificate)r�rPrTr-r�r�r�r�r�rs)r�r!rTrh)r�r@rTr�)r	r@rTr�r�)r#rrT�bytes | None)rTrQ)r#zCallable[..., Any]rmrhrTr�)rmrhrTr�)r#rrTr0)r#rr�r0rTr�r�)rAr0rTr�)rIr0rTr�)%rErFrGrHrIr�r�r�r�r�ryr�r�r�r�r�r�r�r�rrrr r$r'r*r.rr3r6r9r=rBr�rJrNrJrrrr-r-�s����;�����.��4��4�&
I�1�
�
)�)�81�&645�>7�)�8(�(/�0�"�"1�A�7�'�7�/4�7�	
�7�646G�@�F�	�)�� 647)�� 648*�	3rr-c�n�\rSrSr%Sr\RrS\S'\Rr649S\S'\RrS\S'\RrS\S'\RrS\S'\R"rS\S	'\R&rS\S650'\R*rS\S'\R.rS\S'\R2rS\S
'Srg)r5ihz�651Flags for X509 verification, used to change the behavior of652:class:`X509Store`.653 654See `OpenSSL Verification Flags`_ for details.655 656.. _OpenSSL Verification Flags:657    https://www.openssl.org/docs/manmaster/man3/X509_VERIFY_PARAM_set_flags.html658r@�	CRL_CHECK�
CRL_CHECK_ALL�IGNORE_CRITICAL�X509_STRICT�ALLOW_PROXY_CERTS�POLICY_CHECK�EXPLICIT_POLICY�INHIBIT_MAP�CHECK_SS_SIGNATURE�
PARTIAL_CHAINrN)rErFrGrHrIrN�X509_V_FLAG_CRL_CHECKrS�__annotations__�X509_V_FLAG_CRL_CHECK_ALLrT�X509_V_FLAG_IGNORE_CRITICALrU�X509_V_FLAG_X509_STRICTrV�X509_V_FLAG_ALLOW_PROXY_CERTSrW�X509_V_FLAG_POLICY_CHECKrX�X509_V_FLAG_EXPLICIT_POLICYrY�X509_V_FLAG_INHIBIT_MAPrZ�X509_V_FLAG_CHECK_SS_SIGNATUREr[�X509_V_FLAG_PARTIAL_CHAINr\rJrrrr5r5hs�����/�/�I�s�/��7�7�M�3�7��;�;�O�S�;��3�3�K��3�!�?�?��s�?��5�5�L�#�5��;�;�O�S�;��3�3�K��3�"�A�A���A��7�7�M�3�7rr5c�d�\rSrSrSrSSjrSSjrS
SjrSSjrSSjr	SSS	jjr659S660rg)r2ia�661An X.509 store.662 663An X.509 store is used to describe a context in which to verify a664certificate. A description of a context may include a set of certificates665to trust, a set of certificate revocation lists, verification flags and666more.667 668An X.509 store, being only a description, cannot be used by itself to669verify a certificate. To carry out the actual verification process, see670:class:`X509StoreContext`.671c��[R"5n[R"U[R5Ulgr)rN�X509_STORE_newrWr]�X509_STORE_free�_store�r��stores  rr��X509Store.__init__�s(���#�#�%���g�g�e�T�%9�%9�:��rc��[U[5(d672[5e[R"UR673UR5n[US:H5 g)a�674Adds a trusted certificate to this store.675 676Adding a certificate with this method adds this certificate as a677*trusted* certificate.678 679:param X509 cert: The certificate to add to this store.680 681:raises TypeError: If the certificate is not an :class:`X509`.682 683:raises OpenSSL.crypto.Error: If OpenSSL was unhappy with your684    certificate.685 686:return: ``None`` if the certificate was added successfully.687r�N)rgr-rirN�X509_STORE_add_certrlr�r[)r�r�r�s   r�add_cert�X509Store.add_cert�s?�� �$��%�%��+���&�&�t�{�{�D�J�J�?����q��!rc���[U[R5(a�SSKJn [UR
UR55n[R"U[R5n[U[R:g5 [R"U[R5nO[S5e[[R "UR"U5S:g5 g)a�688Add a certificate revocation list to this store.689 690The certificate revocation lists added to a store will only be used if691the associated flags are configured to check certificate revocation692lists.693 694.. versionadded:: 16.1.0695 696:param crl: The certificate revocation list to add to this store.697:type crl: ``cryptography.x509.CertificateRevocationList``698:return: ``None`` if the certificate revocation list was added699    successfully.700rr�z?CRL must be of type cryptography.x509.CertificateRevocationListN)rgr�CertificateRevocationListr�r�r`r�r�rN�d2i_X509_CRL_biorWr\r[r]�
X509_CRL_freeri�X509_STORE_add_crlrl)r��crlr�rP�openssl_crls     r�add_crl�X509Store.add_crl�s����c�4�9�9�:�:�M��s�/�/����=�>�C��/�/��T�Y�Y�?�K��K�4�9�9�4�5��'�'�+�t�'9�'9�:�C��>��
�701	��/�/����S�A�Q�F�Grc�^�[[R"URU5S:g5 g)ab702Set verification flags to this store.703 704Verification flags can be combined by oring them together.705 706.. note::707 708  Setting a verification flag sometimes requires clients to add709  additional information to the store, otherwise a suitable error will710  be raised.711 712  For example, in setting flags to enable CRL checking a713  suitable CRL must be added to the store otherwise an error will be714  raised.715 716.. versionadded:: 16.1.0717 718:param int flags: The verification flags to set on this store.719    See :class:`X509StoreFlags` for available constants.720:return: ``None`` if the verification flags were successfully set.721rN)r[rN�X509_STORE_set_flagsrl)r��flagss  r�	set_flags�X509Store.set_flags�s"��,	��1�1�$�+�+�u�E��J�Krc�D�[R"5n[R"U[R5n[R722"U[R"UR555 [[R"URU5S:g5 g)a\723Set the time against which the certificates are verified.724 725Normally the current time is used.726 727.. note::728 729  For example, you can determine if a certificate was valid at a given730  time.731 732.. versionadded:: 17.0.0733 734:param datetime vfy_time: The verification time to set on this store.735:return: ``None`` if the verification time was successfully set.736rN)rN�X509_VERIFY_PARAM_newrWr]�X509_VERIFY_PARAM_free�X509_VERIFY_PARAM_set_time�calendar�timegm�	timetupler[�X509_STORE_set1_paramrl)r��vfy_time�params   r�set_time�X509Store.set_time�sm�� �*�*�,������t�:�:�;���'�'��8�?�?�8�#5�#5�#7�8�	737�	��2�2�4�;�;��F�!�K�LrNc���Uc[RnO[U5nUc[RnO[U5n[R"UR738X5nU(d[
5 gg)a�739Let X509Store know where we can find trusted certificates for the740certificate chain.  Note that the certificates have to be in PEM741format.742 743If *capath* is passed, it must be a directory prepared using the744``c_rehash`` tool included with OpenSSL.  Either, but not both, of745*cafile* or *capath* may be ``None``.746 747.. note::748 749  Both *cafile* and *capath* may be set simultaneously.750 751  Call this method multiple times to add more than one location.752  For example, CA certificates, and certificate revocation list bundles753  may be passed in *cafile* in subsequent calls to this method.754 755.. versionadded:: 20.0756 757:param cafile: In which file we can find the certificates (``bytes`` or758               ``unicode``).759:param capath: In which directory we can find the certificates760               (``bytes`` or ``unicode``).761 762:return: ``None`` if the locations were set successfully.763 764:raises OpenSSL.crypto.Error: If both *cafile* and *capath* is ``None``765    or the locations could not be set for any reason.766 767N)rWr\�_path_bytesrN�X509_STORE_load_locationsrlr�)r��cafile�capath�load_results    r�load_locations�X509Store.load_locations�s^��F�>��Y�Y�F� ��(�F��>��Y�Y�F� ��(�F��4�4��K�K��768��� �"�r�rlr�)r�r-rTr�)ryzx509.CertificateRevocationListrTr�)rr@rTr�)r�zdatetime.datetimerTr�r)r��StrOrBytesPath | Noner�r�rTr�)rErFrGrHrIr�rrr{r�r�r�rJrrrr2r2sN���;�"�,H�<L�0M�6)-�1#�%�1#�&�1#�769�	1#�1#rr2c�@^�\rSrSrSrSU4SjjrSrU=r$)r4i)z�770An exception raised when an error occurred while verifying a certificate771using `OpenSSL.X509StoreContext.verify_certificate`.772 773:ivar certificate: The certificate which caused verificate failure.774:type certificate: :class:`X509`775c�<>�[TU]U5 X lX0lgr)r�r��errors�certificate)r��messager�r�r�s    �rr��X509StoreContextError.__init__2s���	����!���&�r)r�r�)r�r!r�z	list[Any]r�r-rTr�)rErFrGrHrIr�rJr$r%s@rr4r4)s2����'��'�$-�'�<@�'�	
�'�'rr4c��\rSrSrSrSS
Sjjr\SSj5r\SSj5rSSjr	SSjr776SS	jrSS777jrSr
g)r3i:a
778An X.509 store context.779 780An X.509 store context is used to carry out the actual verification process781of a certificate in a described context. For describing such a context, see782:class:`X509Store`.783 784:param X509Store store: The certificates which will be trusted for the785    purposes of any verifications.786:param X509 certificate: The certificate to be verified.787:param chain: List of untrusted certificates that may be used for building788    the certificate chain. May be ``None``.789:type chain: :class:`list` of :class:`X509`790Nc�H�XlX lURU5Ulgr)rl�_cert�_build_certificate_stack�_chain)r�rnr��chains    rr��X509StoreContext.__init__Js ���� �791��3�3�E�:��rc�,�SSjnUb[U5S:Xa[R$[R"5n[U[R:g5 [R"X!5nUH�n[U[5(d[S5e[[R"UR5S:�5 [R"X#R5S::dMu[R"UR5 [5 M� U$)Nc���[[R"U55H/n[R"X5n[R"U5 M1 [R792"U5 gr)r:rN�sk_X509_num�
sk_X509_valuer��sk_X509_free)�srE�xs   r�cleanup�:X509StoreContext._build_certificate_stack.<locals>.cleanupXsJ���4�+�+�A�.�/���&�&�q�,�����q�!�0�
���a� rrz+One of the elements is not an X509 instance)r�rrTr�)rZrWr\rN�sk_X509_new_nullr[r]rgr-ri�X509_up_refr��sk_X509_pushr�r�)�certificatesr��stackr�s    rr��)X509StoreContext._build_certificate_stackTs���	!���3�|�#4��#9��9�9���%�%�'�������*�+�����'�� �D��d�D�)�)�� M�N�N��D�,�,�T�Z�Z�8�1�<�=�� � ��793�794�3�q�8����t�z�z�*�$�&�!��rc��[R"[R"[R"U555RS5n[R"U5[R"U5U/n[R"U5n[R"U5n[RU5n[XU5$)z�795Convert an OpenSSL native context error failure into a Python796exception.797 798When a call to native OpenSSL X509_verify_cert fails, additional799information about the failure can be obtained from the store context.800r2)rWrzrN�X509_verify_cert_error_string�X509_STORE_CTX_get_errorr�X509_STORE_CTX_get_error_depth�X509_STORE_CTX_get_current_cert�X509_dupr-r�r4)�	store_ctxr�r�r�r��pycerts      r�_exception_from_context�(X509StoreContext._exception_from_contextrs����+�+��.�.��-�-�i�8�
�801��&��/�		�
�)�)�)�4��/�/�	�:��802���4�4�Y�?���
�
�e�$���(�(��/��$�W�f�=�=rc��[R"5n[U[R:g5 [R803"U[R5n[R"XRRURRUR5n[US:H5 [R"U5nUS::aURU5eU$)a804Verifies the certificate and runs an X509_STORE_CTX containing the805results.806 807:raises X509StoreContextError: If an error occurred when validating a808  certificate in the context. Sets ``certificate`` attribute to809  indicate which certificate caused the error.810r�r)rN�X509_STORE_CTX_newr[rWr\r]�X509_STORE_CTX_free�X509_STORE_CTX_initrlr�r�r��X509_verify_certr�)r�r�rss   r�_verify_certificate�$X509StoreContext._verify_certificate�s����+�+�-�	��	�T�Y�Y�.�/��G�G�I�t�'?�'?�@�	��&�&��{�{�)�)�4�:�:�+;�+;�T�[�[�811��	��q��!��#�#�I�.���!�8��.�.�y�9�9��rc��Xlg)z�812Set the context's X.509 store.813 814.. versionadded:: 0.15815 816:param X509Store store: The store description which will be used for817    the purposes of any *future* verifications.818Nr�rms  r�	set_store�X509StoreContext.set_store�s	���rc�$�UR5 g)z�819Verify a certificate in a context.820 821.. versionadded:: 0.15822 823:raises X509StoreContextError: If an error occurred when validating a824  certificate in the context. Sets ``certificate`` attribute to825  indicate which certificate caused the error.826N)r�r�s r�verify_certificate�#X509StoreContext.verify_certificate�s��	
� � �"rc��UR5n[R"U5n[U[R827:g5 /n[
[R"U55H[n[R"X$5n[U[R828:g5 [RU5nURU5 M] [R"U5 U$)a829Verify a certificate in a context and return the complete validated830chain.831 832:raises X509StoreContextError: If an error occurred when validating a833  certificate in the context. Sets ``certificate`` attribute to834  indicate which certificate caused the error.835 836.. versionadded:: 20.0837)
r�rN�X509_STORE_CTX_get1_chainr[rWr\r:r�r�r-r�r�r�)r�r��838cert_stackr�rEr�r�s       r�get_verified_chain�#X509StoreContext.get_verified_chain�s����,�,�.�	��3�3�I�>�839��840�d�i�i�/�0����t�'�'�841�3�4�A��%�%�j�4�D��D�D�I�I�-�.��,�,�T�2�F��M�M�&�!�	5�	
���*�%��
r)r�r�rlr)rnr2r�r-r��Sequence[X509] | NonerTr�)r�r�rTr�)r�rrTr4r#)rnr2rTr�r�)rTz842list[X509])rErFrGrHrIr��staticmethodr�r�r�r�r�r�rJrrrr3r3:s���
�&(,�	;��;��;�%�	;�843844�;���+��	
����:�>��>�2�0	�845#�rr3c���[U[5(aURS5n[U5nU[:XaD[846R"U[R[R[R5nO;U[:Xa&[847R"U[R5nO[S5eU[R:Xa848[5 [RU5$)z�849Load a certificate (X509) from the string *buffer* encoded with the850type *type*.851 852:param type: The file type (one of FILETYPE_PEM, FILETYPE_ASN1)853 854:param bytes buffer: The buffer the certificate is stored in855 856:return: The X509 object857r�3type argument must be FILETYPE_PEM or FILETYPE_ASN1)rgr!rAr`r)rN�PEM_read_bio_X509rWr\r(�d2i_X509_biorkr�r-r�)r�r^rPrs    rr<r<�s����&�#������w�'��858�v�859�C��|���%�%�c�4�9�9�d�i�i����K��	
��	�� � ��d�i�i�0���N�O�O��t�y�y�����"�"�4�(�(rc�d�[5nU[:Xa![R"X!R5nOcU[860:Xa![R"X!R5nO8U[:Xa#[R"X!RSS5nO[S5e[US:H5 [U5$)z�861Dump the certificate *cert* into a buffer string encoded with the type862*type*.863 864:param type: The file type (one of FILETYPE_PEM, FILETYPE_ASN1, or865    FILETYPE_TEXT)866:param cert: The certificate to dump867:return: The buffer with the dumped certificate in868r�Ctype argument must be FILETYPE_PEM, FILETYPE_ASN1, or FILETYPE_TEXTr�)r`r)rN�PEM_write_bio_X509r�r(�i2d_X509_bior*�
X509_print_exrkr[re)r�r�rP�result_codes    rr6r6�s����.�C��|���-�-�c�:�:�>��	
��	��'�'��Z�Z�8��	
��	��(�(��j�j�!�Q�?���
�869�	870�871�K�1�$�%��#��rc���[5nU[:Xa[RnO&U[:Xa[R872nO[
S5eU"X!R5nUS:wa873[5 [U5$)z�874Dump a public key to a buffer.875 876:param type: The file type (one of :data:`FILETYPE_PEM` or877    :data:`FILETYPE_ASN1`).878:param PKey pkey: The public key to dump879:return: The buffer with the dumped key in it.880:rtype: bytes881r�r�)882r`r)rN�PEM_write_bio_PUBKEYr(�i2d_PUBKEY_biorkr�r�re)r�r�rP�	write_bior�s     rr9r9sd���.�C��|���-�-�	�	
��	��'�'�	��N�O�O��C���,�K��a�����#��rc	���[5n[U[5(d[S5eUbMUc[S5e[R883"[
U55nU[R:Xa[S5eO[Rn[X5nU[:XaY[R"UURU[RSURUR5nUR!5 O�U[":Xa![R$"XAR5nO�U[&:Xa�[R("UR5[R*:wa[S5e[R,"[R."UR5[R05n[R2"XHS5nO[S5e[5US:g5 [7U5$)aU884Dump the private key *pkey* into a buffer string encoded with the type885*type*.  Optionally (if *type* is :const:`FILETYPE_PEM`) encrypting it886using *cipher* and *passphrase*.887 888:param type: The file type (one of :const:`FILETYPE_PEM`,889    :const:`FILETYPE_ASN1`, or :const:`FILETYPE_TEXT`)890:param PKey pkey: The PKey to dump891:param cipher: (optional) if encrypted PEM format, the cipher to use892:param passphrase: (optional) if encrypted PEM format, this can be either893    the passphrase to use, or a callback for providing the passphrase.894 895:return: The buffer with the dumped key in896:rtype: bytes897zpkey must be a PKeyzDif a value is given for cipher one must also be given for passphrasezInvalid cipher namerz-Only RSA keys are supported for FILETYPE_TEXTr�)r`rgr/rirN�EVP_get_cipherbynamer7rWr\rk�_PassphraseHelperr)�PEM_write_bio_PrivateKeyr��callback�
callback_args�raise_if_problemr(�i2d_PrivateKey_bior*r�r�r]r�r��	RSA_printr[re)	r�r��cipher�898passphraserP�899cipher_obj�helperr�r s	         rr8r8*s���*�.�C��d�D�!�!��-�.�.�
�����8��
��.�.�|�F�/C�D�900�����"��2�3�3�#��Y�Y�901�
�t�
0�F��|���3�3���J�J���I�I�
��O�O�� � �902��	���!�	
��	��-�-�c�:�:�>��	
��	����D�J�J�'�4�+<�+<�<��K�L�L��g�g�d�,�,�T�Z�Z�8�$�-�-�H���n�n�S�q�1���
�903�	904�905�K�1�$�%��#��rc��\rSrSrS	S906Sjjr\SSj5r\SSj5r\4SSjjr	S
Sjr907Srg)r�ioc�f�U[:waUb[S5eX lX0lX@l/Ulg)Nz0only FILETYPE_PEM key format supports encryption)r)rk�_passphrase�908_more_args�	_truncate�	_problems)r�r�r��	more_args�truncates     rr��_PassphraseHelper.__init__ps:���<��J�$:��B��
�&��#��!��*,��rc��URc[R$[UR[5(d[UR5(a![R"SUR5$[S5e)N�pem_password_cb�2Last argument must be a byte string or a callable.)	r�rWr\rgrh�callabler��_read_passphraserir�s rr��_PassphraseHelper.callback�sc�����#��9�9��
��(�(�%�
0�
0�H�T�=M�=M�4N�4N��=�=�!2�D�4I�4I�J�J��D��
rc���URc[R$[UR[5(d[UR5(a[R$[
S5e)Nr�)r�rWr\rgrhr�rir�s rr��_PassphraseHelper.callback_args�sU�����#��9�9��
��(�(�%�
0�
0�H�T�=M�=M�4N�4N��9�9���D��
rc��UR(a'[U5 URRS5eg!Ua N$f=frW)r��_exception_from_error_queue�pop)r��
exceptionTypes  rr��"_PassphraseHelper.raise_if_problem�sF���>�>�
�+�M�:��.�.�$�$�Q�'�'���!�
��
�s�:�A�Ac�>�[UR5(a6UR(aURX#U5nO-URU5nOURceURn[U[5(d[S5e[
U5U:�a"UR(aUSUnO[S5e[[
U55HnXVUS-X'M [
U5$![a%nURRU5 SnAgSnAff=f)NzBytes expectedz+passphrase returned by callback is too longr�r)r�r�r�rgrhrkrZr�r:�	Exceptionr�r�)r��buf�size�rwflag�userdatar�rE�es        rr��"_PassphraseHelper._read_passphrase�s���	���(�(�)�)��?�?�!�-�-�d�H�E�F�!�-�-�f�5�F��'�'�3�3�3��)�)���f�e�,�,� �!1�2�2��6�{�T�!��>�>�#�E�T�]�F�$�E����3�v�;�'���A��E�*���(��v�;����	��N�N�!�!�!�$���	�s�C*C-�-909D�7D�D)r�r�r�r�N)FF)910r�r@r��PassphraseCallableT | Noner�r�r�r�rTr�r#)rztype[Exception]rTr�)911rrrr@rrrrrTr@)rErFrGrHr��propertyr�r�r.r�r�rJrrrr�r�os���912 ��-��-�/�-��	-�913�-�914�
-� ��������AF�(����!��+.��:=��	�rr�c�J�[U[5(aURS5n[U5nU[:XaD[915R"U[R[R[R5nO;U[:Xa&[916R"U[R5nO[S5eU[R:Xa917[5 [R[5n[R"U[918R 5UlSUlU$)a919Load a public key from a buffer.920 921:param type: The file type (one of :data:`FILETYPE_PEM`,922    :data:`FILETYPE_ASN1`).923:param buffer: The buffer the key is stored in.924:type buffer: A Python string object, either unicode or bytestring.925:return: The PKey object.926:rtype: :class:`PKey`927rr�T)rgr!rAr`r)rN�PEM_read_bio_PUBKEYrWr\r(�d2i_PUBKEY_biorkr�r/r�r]r�r�r�)r�r^rP�evp_pkeyr�s     rr?r?�s����&�#������w�'��928�v�929�C��|���+�+�����D�I�I�t�y�y�930��931��	��&�&�s�D�I�I�6���N�O�O��4�9�9�����<�<���D�����4�#5�#5�6�D�J��D���Krc�b�[U[5(aURS5n[U5n[	X5nU[932:XaL[R"U[RURUR5nUR5 O;U[:Xa&[R"U[R5nO[S5eU[R:Xa933[!5 ["R%["5n[R&"U[R(5UlU$)a�934Load a private key (PKey) from the string *buffer* encoded with the type935*type*.936 937:param type: The file type (one of FILETYPE_PEM, FILETYPE_ASN1)938:param buffer: The buffer the key is stored in939:param passphrase: (optional) if encrypted PEM format, this can be940                   either the passphrase to use, or a callback for941                   providing the passphrase.942 943:return: The PKey object944rr�)rgr!rAr`r�r)rN�PEM_read_bio_PrivateKeyrWr\r�r�r�r(�d2i_PrivateKey_biorkr�r/r�r]r�r�)r�r^r�rPr�rr�s       rr>r>�s���"�&�#������w�'��945�v�946�C�
�t�
0�F��|���/�/�����F�O�O�V�-A�-A�947��	���!�	
��	��*�*�3��	�	�:���N�O�O��4�9�9�����<�<���D�����4�#5�#5�6�D�J��Krc�d�[5nU[:Xa![R"X!R5nOcU[948:Xa![R"X!R5nO8U[:Xa#[R"X!RSS5nO[S5e[US:g5 [U5$)aV949Dump the certificate request *req* into a buffer string encoded with the950type *type*.951 952:param type: The file type (one of FILETYPE_PEM, FILETYPE_ASN1)953:param req: The certificate request to dump954:return: The buffer with the dumped certificate request in955 956 957.. deprecated:: 24.2.0958   Use `cryptography.x509.CertificateSigningRequest` instead.959rr�)r`r)rN�PEM_write_bio_X509_REQrxr(�i2d_X509_REQ_bior*�X509_REQ_print_exrkr[re)r�rzrPr�s    rr7r7s����.�C��|���1�1�#�x�x�@��	
��	��+�+�C���:��	
��	��,�,�S�(�(�A�q�A���
�960�	961�962�K�1�$�%��#��rr7rc�8�[U[5(aURS5n[U5nU[:XaD[963R"U[R[R[R5nO;U[:Xa&[964R"U[R5nO[S5e[U[R:g5 [R[5n[R"U[965R 5UlU$)as966Load a certificate request (X509Req) from the string *buffer* encoded with967the type *type*.968 969:param type: The file type (one of FILETYPE_PEM, FILETYPE_ASN1)970:param buffer: The buffer the certificate request is stored in971:return: The X509Req object972 973.. deprecated:: 24.2.0974   Use `cryptography.x509.load_der_x509_csr` or975   `cryptography.x509.load_pem_x509_csr` instead.976rr�)rgr!rAr`r)rN�PEM_read_bio_X509_REQrWr\r(�d2i_X509_REQ_biorkr[r1r�r]rwrx)r�r^rPrz�x509reqs     rr=r=6s����&�#������w�'��977�v�978�C��|���(�(��d�i�i����D�I�I�N��	
��	��#�#�C����3���N�O�O��C�4�9�9�$�%��o�o�g�&�G��7�7�3�� 2� 2�3�G�L��Nrr=)rr!r�objectrTzCallable[[_T], _T]r)r^rQrTr)rPrrTrh)rlrrmrhrTr�)rmrhrTr)r~rrTrQ)rTr )r�r!rTr�)r�r@r^rhrTr-)r�r@r�r-rTrh)r�r@r�r/rTrh)NN)979r�r@r�r/r�rrr�rrTrh)r�r@r^�str | bytesrTr/)r�r@r^rr�rrTr/)r�r@rzr1rTrh)r�r@r^rhrTr1)m�980__future__rr�r�	functools�sysr��base64r�collections.abcrrrrr	�version_info�warningsr�TypeVar�_T�typing_extensions�cryptographyrr�)cryptography.hazmat.primitives.asymmetricrrrrr �
OpenSSL._utilr!r"r7r#r�r$rWr%rNr&�_make_assertr'r��__all__r�r�r�r�r��_PrivateKeyr�r�r�r�r��981_PublicKeyr�rh�PassphraseCallableT�SSL_FILETYPE_PEMr)r^�SSL_FILETYPE_ASN1r(r*r�r,�EVP_PKEY_DSAr+�EVP_PKEY_DHrA�EVP_PKEY_ECrBrr.r�r[r`rerortr�r�r/r�r;r:�total_orderingr0r1r-r5r2r4r3r<r6r9r8r�r?r>r7rrE�DeprecationWarningr=r�rrr�<module>r7s���"����982�
��$�������w��#������	����	�B��-�$���)���������8����������	������	�������������	������	��983�
�[�*�
$�%���E�8�C��J�#7�7�8���)�)��c�)��+�+�
�s�+��
��!�!��#�!��!�!��#�!��������������I���:�E�B���u�%���4;�+�2�&�:984�985�~.�~.�Bd.�d.�N���5�	�5����1�	�1�$�������D���h�h�	�h�Vm3�m3�`
8�8�.g#�g#�T'�I�'�"[�[�|)�:�8�8�-1�	B�986
�B�987�B�
�B�+�	B�988�B�JK�K�\�J.2�&�989
�&��&�+�&�990�	&�R�@&>�"������	��	#�	��@&>�"������	��	#�	r
codekingpro/portable-devtools · Team Ai