o
    j1                     @  sB  U d dl mZ d dlZd dlZd dlZd dlZd dlZd dlmZ d dl	m
Z
 d dlmZ d dlmZmZmZ ejdkrCd dlmZ nd dlmZ d d	lmZmZ d d
lmZmZmZmZmZ d dlmZ d dlmZ d dlm Z! d dlm"Z# d dlm$Z% d dlm&Z' d dlm(Z) g dZ*eej+ej,ej-ej.ej/f Z0eej1ej2ej3ej4ej5f Z6ee0e6f Z7ee8ede8f f Z9e%j:Z;de<d< e%j=Z>de<d< dZ?e%j@ZAde<d< e%jBZCde<d< e%jDZEde<d< e%jFZGde<d< G dd deHZIee!eIZJe'eIZKdfdgd"d#ZLdhd&d'ZMdid+d,ZNdjd-d.ZOdkd0d1ZPG d2d3 d3ZQG d4d5 d5ZRG d6d7 d7ZSed8dld:d;ZTed<dmd?d@ZUedAejVG dBdC dCZWG dDdE dEZXG dFdG dGZYG dHdI dIZZG dJdK dKeHZ[G dLdM dMZ\dndOdPZ]dodRdSZ^dpdUdVZ_		dqdrd[d\Z`e`Zaeje`ebd]ecd\d^ G d_d` d`ZddsdbdcZe	dfdtdddeZfdS )u    )annotationsN)	b16encode)Sequence)partial)AnyCallableUnion)      )
deprecated)utilsx509)dsaeced448ed25519rsa)StrOrBytesPath)byte_string)exception_from_error_queue)ffi)lib)make_assert)
path_bytes)FILETYPE_ASN1FILETYPE_PEMFILETYPE_TEXTTYPE_DSATYPE_RSAX509ErrorPKeyX509Name	X509StoreX509StoreContextX509StoreContextErrorX509StoreFlagsdump_certificatedump_privatekeydump_publickeyget_elliptic_curveget_elliptic_curvesload_certificateload_privatekeyload_publickey.intr   r   i  r   r   TYPE_DHTYPE_ECc                   @  s   e Zd ZdZdS )r    z7
    An error occurred in an `OpenSSL.crypto` API.
    N)__name__
__module____qualname____doc__ r6   r6   /root/aizidognhua/tmp/workspace/projects/ec89d86c-575f-41c9-af57-ac45cbdbf775/venv/lib/python3.10/site-packages/OpenSSL/crypto.pyr    j   s    r    bufferbytes | Nonereturnr   c                 C  sf   | du rt t  }t j}ntd| }t |t| }|fd	dd}t|tj	k t
||}|S )
z
    Allocate a new OpenSSL memory BIO.

    Arrange for the garbage collector to clean it up automatically.

    :param buffer: None or some bytes to use to put into the BIO so that they
        can be read out.
    Nchar[]bior   refr:   c                 S  s
   t | S N)_libBIO_free)r<   r=   r6   r6   r7   free      
z_new_mem_buf.<locals>.free)r<   r   r=   r   r:   r   )r?   BIO_new	BIO_s_memr@   _ffinewBIO_new_mem_buflen_openssl_assertNULLgc)r8   r<   rA   datar6   r6   r7   _new_mem_buft   s   	rM   r<   bytesc                 C  s.   t d}t| |}t |d |dd S )zO
    Copy the contents of an OpenSSL BIO object into a Python byte string.
    zchar**r   N)rE   rF   r?   BIO_get_mem_datar8   )r<   result_bufferbuffer_lengthr6   r6   r7   _bio_to_string   s   
rR   boundarywhenNonec                 C  s@   t |ts	tdt| tjk t| |}|dkrtddS )a  
    The the time value of an ASN1 time object.

    @param boundary: An ASN1_TIME pointer (or an object safely
        castable to that type) which will have its value set.
    @param when: A string representation of the desired time value.

    @raise TypeError: If C{when} is not a L{bytes} string.
    @raise ValueError: If C{when} does not represent a time in the required
        format.
    @raise RuntimeError: If the time value cannot be set for some other
        (unspecified) reason.
    zwhen must be a byte stringr   zInvalid stringN)	
isinstancerN   	TypeErrorrI   rE   rJ   r?   ASN1_TIME_set_string
ValueError)rS   rT   
set_resultr6   r6   r7   _set_asn1_time   s   
r[   c                 C  s2   t  }t|tjk t|t j}t||  |S )a  
    Behaves like _set_asn1_time but returns a new ASN1_TIME object.

    @param when: A string representation of the desired time value.

    @raise TypeError: If C{when} is not a L{bytes} string.
    @raise ValueError: If C{when} does not represent a time in the required
        format.
    @raise RuntimeError: If the time value cannot be set for some other
        (unspecified) reason.
    )r?   ASN1_TIME_newrI   rE   rJ   rK   ASN1_TIME_freer[   )rT   retr6   r6   r7   _new_asn1_time   s
   
r_   	timestampc                 C  s   t d| }t|dkrdS t|tjkrt t|S t d}t	| | t
|d t jk t d|d }t|}t |}t|d  |S )a]  
    Retrieve the time value of an ASN1 time object.

    @param timestamp: An ASN1_GENERALIZEDTIME* (or an object safely castable to
        that type) from which the time value will be retrieved.

    @return: The time value from C{timestamp} as a L{bytes} string in a certain
        format.  Or C{None} if the object contains no time value.
    zASN1_STRING*r   NzASN1_GENERALIZEDTIME**)rE   castr?   ASN1_STRING_lengthASN1_STRING_typeV_ASN1_GENERALIZEDTIMEstringASN1_STRING_get0_datarF   ASN1_TIME_to_generalizedtimerI   rJ   ASN1_GENERALIZEDTIME_free)r`   string_timestampgeneralized_timestampstring_datastring_resultr6   r6   r7   _get_asn1_time   s   



rm   c                   @  s*   e Zd ZdddZdddZdd	d
ZdS )_X509NameInvalidatorr:   rU   c                 C  s
   g | _ d S r>   )_namesselfr6   r6   r7   __init__   rB   z_X509NameInvalidator.__init__namer"   c                 C  s   | j | d S r>   )ro   appendrq   rs   r6   r6   r7   add   s   z_X509NameInvalidator.addc                 C  s   | j D ]}|`qd S r>   )ro   _nameru   r6   r6   r7   clear   s   
z_X509NameInvalidator.clearNr:   rU   rs   r"   r:   rU   )r2   r3   r4   rr   rv   rx   r6   r6   r6   r7   rn      s    

rn   c                   @  sr   e Zd ZdZdZdZdddZdd	d
ZedddZ	e
dd ddZe
dd!ddZd"ddZd"ddZdS )#r!   zD
    A class representing an DSA or RSA public key or key pair.
    FTr:   rU   c                 C  s"   t  }t|t j| _d| _d S )NF)r?   EVP_PKEY_newrE   rK   EVP_PKEY_free_pkey_initializedrq   pkeyr6   r6   r7   rr      s   
zPKey.__init___Keyc                 C  sN   ddl m}m} | jrtt| }tt||S t	t| }tt||ddS )a  
        Export as a ``cryptography`` key.

        :rtype: One of ``cryptography``'s `key interfaces`_.

        .. _key interfaces: https://cryptography.io/en/latest/hazmat/            primitives/asymmetric/rsa/#key-interfaces

        .. versionadded:: 16.1.0
        r   )load_der_private_keyload_der_public_keyN)password)
,cryptography.hazmat.primitives.serializationr   r   _only_publicr)   r   typingra   r   _dump_privatekey_internal)rq   r   r   derr6   r6   r7   to_cryptography_key   s   

zPKey.to_cryptography_key
crypto_keyc                 C  s   t |tjtjtjtjtjtj	t
jt
jtjtjf
stdddlm}m}m}m} t |tjtjtj	t
jtjfrCtt||j|jS ||j|j| }tt|S )z
        Construct based on a ``cryptography`` *crypto_key*.

        :param crypto_key: A ``cryptography`` key.
        :type crypto_key: One of ``cryptography``'s `key interfaces`_.

        :rtype: PKey

        .. versionadded:: 16.1.0
        zUnsupported key typer   )EncodingNoEncryptionPrivateFormatPublicFormat)rV   r   DSAPrivateKeyDSAPublicKeyr   EllipticCurvePrivateKeyEllipticCurvePublicKeyr   Ed25519PrivateKeyEd25519PublicKeyr   Ed448PrivateKeyEd448PublicKeyr   RSAPrivateKeyRSAPublicKeyrW   r   r   r   r   r   r.   r   public_bytesDERSubjectPublicKeyInfoprivate_bytesPKCS8r-   )clsr   r   r   r   r   r   r6   r6   r7   from_cryptography_key  sF   

zPKey.from_cryptography_keyz`PKey.generate_key is deprecated. You should use the key generation APIs in cryptography instead.typer/   bitsc              	   C  s4  t |ts	tdt |tstd|tkrQ|dkrtdt }t|tj	}t
|tj t }t|||tj}t|dk t| j|}t|dk nD|tkrt }t|tjk t|tj}t||tjdtjtjtj}t|dk tt|dk tt| j|dk ntdd| _dS )	a3  
        Generate a key pair of the given type, with the given number of bits.

        This generates a key "into" the this object.

        :param type: The key type.
        :type type: :py:data:`TYPE_RSA` or :py:data:`TYPE_DSA`
        :param bits: The number of bits.
        :type bits: :py:data:`int` ``>= 0``
        :raises TypeError: If :py:data:`type` or :py:data:`bits` isn't
            of the appropriate type.
        :raises ValueError: If the number of bits isn't an integer of
            the appropriate size.
        :return: ``None``
        ztype must be an integerzbits must be an integerr   zInvalid number of bits   zNo such key typeTN)rV   r/   rW   r   rY   r?   BN_newrE   rK   BN_freeBN_set_wordRSA_F4RSA_newRSA_generate_key_exrJ   rI   EVP_PKEY_assign_RSAr}   r   DSA_newDSA_freeDSA_generate_parameters_exDSA_generate_keyEVP_PKEY_set1_DSAr    r~   )rq   r   r   exponentr   resultr   resr6   r6   r7   generate_keyK  s6   


zPKey.generate_keyzJPKey.check is deprecated. You should use the APIs in cryptography instead.boolc                 C  sd   | j rtdt|  tjkrtdt| j}t	|tj
}t|}|dkr-dS t  dS )ax  
        Check the consistency of an RSA private key.

        This is the Python equivalent of OpenSSL's ``RSA_check_key``.

        :return: ``True`` if key is consistent.

        :raise OpenSSL.crypto.Error: if the key is inconsistent.

        :raise TypeError: if the key is of a type which cannot be checked.
            Only RSA keys can currently be checked.
        zpublic key onlyz'Only RSA keys can currently be checked.r   TN)r   rW   r?   EVP_PKEY_typer   EVP_PKEY_RSAEVP_PKEY_get1_RSAr}   rE   rK   RSA_freeRSA_check_key_raise_current_error)rq   r   r   r6   r6   r7   check  s   

z
PKey.checkc                 C     t | jS )zT
        Returns the type of the key

        :return: The type of the key.
        )r?   EVP_PKEY_idr}   rp   r6   r6   r7   r        z	PKey.typec                 C  r   )zh
        Returns the number of bits of the key

        :return: The number of bits of the key.
        )r?   EVP_PKEY_bitsr}   rp   r6   r6   r7   r     r   z	PKey.bitsNry   )r:   r   )r   r   r:   r!   )r   r/   r   r/   r:   rU   r:   r   r:   r/   )r2   r3   r4   r5   r   r~   rr   r   classmethodr   r   r   r   r   r   r6   r6   r6   r7   r!      s$    

98
r!   c                      sn   e Zd ZdZdZd fddZedddZedddZedddZ	dddZ
d ddZd!ddZ  ZS )"_EllipticCurveaZ  
    A representation of a supported elliptic curve.

    @cvar _curves: :py:obj:`None` until an attempt is made to load the curves.
        Thereafter, a :py:type:`set` containing :py:type:`_EllipticCurve`
        instances each of which represents one curve supported by the system.
    @type _curves: :py:type:`NoneType` or :py:type:`set`
    Notherr   r:   r   c                   s   t |trt |S tS )z
        Implement cooperation with the right-hand side argument of ``!=``.

        Python 3 seems to have dropped this cooperation in this very narrow
        circumstance.
        )rV   r   super__ne__NotImplementedrq   r   	__class__r6   r7   r     s   
z_EllipticCurve.__ne__r   set[_EllipticCurve]c                   s>    tjd}td|} || t fdd|D S )z
        Get the curves supported by OpenSSL.

        :param lib: The OpenSSL library binding object.

        :return: A :py:type:`set` of ``cls`` instances giving the names of the
            elliptic curves the underlying library supports.
        r   zEC_builtin_curve[]c                 3  s    | ]
}  |jV  qd S r>   )from_nidnid).0cr   r   r6   r7   	<genexpr>  s    z7_EllipticCurve._load_elliptic_curves.<locals>.<genexpr>)EC_get_builtin_curvesrE   rJ   rF   set)r   r   
num_curvesbuiltin_curvesr6   r   r7   _load_elliptic_curves  s   
z$_EllipticCurve._load_elliptic_curvesc                 C  s   | j du r| || _ | j S )a  
        Get, cache, and return the curves supported by OpenSSL.

        :param lib: The OpenSSL library binding object.

        :return: A :py:type:`set` of ``cls`` instances giving the names of the
            elliptic curves the underlying library supports.
        N)_curvesr   r   r6   r6   r7   _get_elliptic_curves  s   

z#_EllipticCurve._get_elliptic_curvesr   r/   c                 C  s   | ||t ||dS )a  
        Instantiate a new :py:class:`_EllipticCurve` associated with the given
        OpenSSL NID.

        :param lib: The OpenSSL library binding object.

        :param nid: The OpenSSL NID the resulting curve object will represent.
            This must be a curve NID (and not, for example, a hash NID) or
            subsequent operations will fail in unpredictable ways.
        :type nid: :py:class:`int`

        :return: The curve object.
        ascii)rE   re   
OBJ_nid2sndecode)r   r   r   r6   r6   r7   r     s   z_EllipticCurve.from_nidrs   strrU   c                 C  s   || _ || _|| _dS )a  
        :param _lib: The :py:mod:`cryptography` binding instance used to
            interface with OpenSSL.

        :param _nid: The OpenSSL NID identifying the curve this object
            represents.
        :type _nid: :py:class:`int`

        :param name: The OpenSSL short name identifying the curve this object
            represents.
        :type name: :py:class:`unicode`
        N)r?   _nidrs   )rq   r   r   rs   r6   r6   r7   rr     s   
z_EllipticCurve.__init__c                 C  s   d| j dS )Nz<Curve >rs   rp   r6   r6   r7   __repr__     z_EllipticCurve.__repr__c                 C  s   | j | j}t|t jS )z
        Create a new OpenSSL EC_KEY structure initialized to use this curve.

        The structure is automatically garbage collected when the Python object
        is garbage collected.
        )r?   EC_KEY_new_by_curve_namer   rE   rK   EC_KEY_free)rq   keyr6   r6   r7   
_to_EC_KEY  s   z_EllipticCurve._to_EC_KEYr   r   r:   r   )r   r   r:   r   )r   r   r   r/   r:   r   )r   r   r   r/   rs   r   r:   rU   r:   r   r:   r   )r2   r3   r4   r5   r   r   r   r   r   r   rr   r   r   __classcell__r6   r6   r   r7   r     s    	

r   zSget_elliptic_curves is deprecated. You should use the APIs in cryptography instead.r   c                   C  s
   t tS )a  
    Return a set of objects representing the elliptic curves supported in the
    OpenSSL build in use.

    The curve objects have a :py:class:`unicode` ``name`` attribute by which
    they identify themselves.

    The curve objects are useful as values for the argument accepted by
    :py:meth:`Context.set_tmp_ecdh` to specify which elliptical curve should be
    used for ECDHE key exchange.
    )r   r   r?   r6   r6   r6   r7   r+     s   
r+   zRget_elliptic_curve is deprecated. You should use the APIs in cryptography instead.rs   r   c                 C  s(   t  D ]}|j| kr|  S qtd| )aT  
    Return a single curve object selected by name.

    See :py:func:`get_elliptic_curves` for information about curve objects.

    :param name: The OpenSSL short name identifying the curve object to
        retrieve.
    :type name: :py:class:`unicode`

    If the named curve is not supported then :py:class:`ValueError` is raised.
    zunknown curve name)r+   rs   rY   )rs   curver6   r6   r7   r*   0  s
   


r*   zUX509Name support in pyOpenSSL is deprecated. You should use the APIs in cryptography.c                      sr   e Zd ZdZd ddZd! fd
dZd"ddZd#ddZd#ddZd$ddZ	d%ddZ
d&ddZd'ddZ  ZS )(r"   a  
    An X.509 Distinguished Name.

    :ivar countryName: The country of the entity.
    :ivar C: Alias for  :py:attr:`countryName`.

    :ivar stateOrProvinceName: The state or province of the entity.
    :ivar ST: Alias for :py:attr:`stateOrProvinceName`.

    :ivar localityName: The locality of the entity.
    :ivar L: Alias for :py:attr:`localityName`.

    :ivar organizationName: The organization name of the entity.
    :ivar O: Alias for :py:attr:`organizationName`.

    :ivar organizationalUnitName: The organizational unit of the entity.
    :ivar OU: Alias for :py:attr:`organizationalUnitName`

    :ivar commonName: The common name of the entity.
    :ivar CN: Alias for :py:attr:`commonName`.

    :ivar emailAddress: The e-mail address of the entity.
    rs   r:   rU   c                 C  s    t |j}t|t j| _dS )z
        Create a new X509Name, copying the given X509Name instance.

        :param name: The name to copy.
        :type name: :py:class:`X509Name`
        N)r?   X509_NAME_duprw   rE   rK   X509_NAME_freeru   r6   r6   r7   rr   d  s   zX509Name.__init__r   valuer   c           	   	     s  | drt ||S t|turtdt|jddtt	|}|tj
kr?zt  W td ty>   Y tdw tt| jD ]%}t| j|}t|}t|}||krlt| j|}t|  nqGt|trw|d}t| j|tj|t|dd}|st  d S d S )	N_z$attribute name must be string, not 'z.200'No such attributeutf-8r   )
startswithr   __setattr__r   r   rW   r2   r?   OBJ_txt2nid_byte_string	NID_undefr   r    AttributeErrorrangeX509_NAME_entry_countrw   X509_NAME_get_entryX509_NAME_ENTRY_get_objectOBJ_obj2nidX509_NAME_delete_entryX509_NAME_ENTRY_freerV   encodeX509_NAME_add_entry_by_NIDMBSTRING_UTF8rH   )	rq   rs   r   r   ientent_objent_nid
add_resultr   r6   r7   r   n  sD   








zX509Name.__setattr__
str | Nonec           	   
   C  s   t t|}|t jkr!zt  W td ty    Y tdw t | j|d}|dkr/dS t 	| j|}t 
|}td}t ||}t|dk zt|d |dd d}W t |d  |S t |d  w )a
  
        Find attribute. An X509Name object has the following attributes:
        countryName (alias C), stateOrProvince (alias ST), locality (alias L),
        organization (alias O), organizationalUnit (alias OU), commonName
        (alias CN) and more...
        r   r   Nunsigned char**r   r   )r?   r   r   r   r   r    r   X509_NAME_get_index_by_NIDrw   r   X509_NAME_ENTRY_get_datarE   rF   ASN1_STRING_to_UTF8rI   r8   r   OPENSSL_free)	rq   rs   r   entry_indexentryrL   rP   data_lengthr   r6   r6   r7   __getattr__  s0   


zX509Name.__getattr__r   r   c                 C  s"   t |tstS t| j|jdkS Nr   rV   r"   r   r?   X509_NAME_cmprw   r   r6   r6   r7   __eq__     
zX509Name.__eq__c                 C  s"   t |tstS t| j|jdk S r  r  r   r6   r6   r7   __lt__  r  zX509Name.__lt__c                 C  sD   t dd}t| j|t|}t|t jk dt 	|
dS )z6
        String representation of an X509Name
        r;   i   z<X509Name object '{}'>r   )rE   rF   r?   X509_NAME_onelinerw   rH   rI   rJ   formatre   r   )rq   rP   format_resultr6   r6   r7   r     s   zX509Name.__repr__r/   c                 C  r   )a&  
        Return an integer representation of the first four bytes of the
        MD5 digest of the DER representation of the name.

        This is the Python equivalent of OpenSSL's ``X509_NAME_hash``.

        :return: The (integer) hash of this name.
        :rtype: :py:class:`int`
        )r?   X509_NAME_hashrw   rp   r6   r6   r7   hash     
zX509Name.hashrN   c                 C  sN   t d}t| j|}t|dk t |d |dd }t|d  |S )z
        Return the DER encoding of this name.

        :return: The DER encoded form of this name.
        :rtype: :py:class:`bytes`
        r	  r   N)rE   rF   r?   i2d_X509_NAMErw   rI   r8   r  )rq   rP   encode_resultrl   r6   r6   r7   r     s   
zX509Name.derlist[tuple[bytes, bytes]]c           	      C  s   g }t t| jD ]7}t| j|}t|}t|}t|}t|}t	
t|t|dd }|t	||f q
|S )z
        Returns the components of this name, as a sequence of 2-tuples.

        :return: The components of this name.
        :rtype: :py:class:`list` of ``name, value`` tuples.
        N)r   r?   r   rw   r   r   r  r   r   rE   r8   rf   rb   rt   re   )	rq   r   r  r  fnamefvalr   rs   r   r6   r6   r7   get_components  s   



zX509Name.get_componentsrz   )rs   r   r   r   r:   rU   )rs   r   r:   r  r   r   r   r:   rN   )r:   r   )r2   r3   r4   r5   rr   r   r  r  r  r   r  r   r#  r   r6   r6   r   r7   r"   F  s    


'
(



r"   c                   @  s  e Zd ZdZddddZededd	ZdfddZedgddZe	ddhddZ
diddZdjddZe	ddkddZe	ddld!d"Zdmd$d%Zdnd'd(Zdid)d*Ze	d+dod-d.Zdid/d0Ze	d1dpd3d4Ze	d5dpd6d7Zdqd9d:Zdrd=d>Zdsd?d@ZdtdCdDZe	dEdudFdGZdsdHdIZe	dJdudKdLZdvdNdOZdwdQdRZe	dSdxdTdUZe	dVdydXdYZ e	dZdxd[d\Z!e	d]dzd_d`Z"didadbZ#dcS ){r   z
    An X.509 certificate.
    r:   rU   c                 C  s:   t  }t|tjk t|t j| _t | _	t | _
d S r>   )r?   X509_newrI   rE   rJ   rK   	X509_free_x509rn   _issuer_invalidator_subject_invalidator)rq   r   r6   r6   r7   rr     s
   zX509.__init__r   r   c                 C  s.   |  | }t|tj|_t |_t |_|S r>   )	__new__rE   rK   r?   r&  r'  rn   r(  r)  )r   r   certr6   r6   r7   _from_raw_x509_ptr  s
   
zX509._from_raw_x509_ptrx509.Certificatec                 C  s   ddl m} tt| }||S )z
        Export as a ``cryptography`` certificate.

        :rtype: ``cryptography.x509.Certificate``

        .. versionadded:: 17.1.0
        r   )load_der_x509_certificate)cryptography.x509r.  r'   r   )rq   r.  r   r6   r6   r7   to_cryptography"  s   
zX509.to_cryptographycrypto_certc                 C  s6   t |tjs
tdddlm} ||j}tt	|S )z
        Construct based on a ``cryptography`` *crypto_cert*.

        :param crypto_key: A ``cryptography`` X.509 certificate.
        :type crypto_key: ``cryptography.x509.Certificate``

        :rtype: X509

        .. versionadded:: 17.1.0
        zMust be a certificater   r   )
rV   r   CertificaterW   r   r   r   r   r,   r   )r   r1  r   r   r6   r6   r7   from_cryptography/  s
   
zX509.from_cryptographyzYX509.set_version is deprecated. You should use cryptography's CertificateBuilder instead.versionr/   c                 C  s,   t |ts	tdtt| j|dk dS )a	  
        Set the version number of the certificate. Note that the
        version value is zero-based, eg. a value of 0 is V1.

        :param version: The version number of the certificate.
        :type version: :py:class:`int`

        :return: ``None``
        zversion must be an integerr   N)rV   r/   rW   rI   r?   X509_set_versionr'  )rq   r5  r6   r6   r7   set_versionC  s   
zX509.set_versionc                 C  r   )z
        Return the version number of the certificate.

        :return: The version number of the certificate.
        :rtype: :py:class:`int`
        )r?   X509_get_versionr'  rp   r6   r6   r7   get_versionV     zX509.get_versionr!   c                 C  sF   t t }t| j|_|jtjkrt  t	|jtj
|_d|_|S )z{
        Get the public key of the certificate.

        :return: The public key.
        :rtype: :py:class:`PKey`
        T)r!   r*  r?   X509_get_pubkeyr'  r}   rE   rJ   r   rK   r|   r   r   r6   r6   r7   
get_pubkey_  s   
zX509.get_pubkeyzXX509.set_pubkey is deprecated. You should use cryptography's CertificateBuilder instead.r   c                 C  s2   t |ts	tdt| j|j}t|dk dS )z
        Set the public key of the certificate.

        :param pkey: The public key.
        :type pkey: :py:class:`PKey`

        :return: :py:data:`None`
        pkey must be a PKey instancer   N)rV   r!   rW   r?   X509_set_pubkeyr'  r}   rI   )rq   r   rZ   r6   r6   r7   
set_pubkeyn  s   
zX509.set_pubkeyzRX509.sign is deprecated. You should use cryptography's CertificateBuilder instead.digestr   c                 C  sp   t |ts	td|jrtd|jstdtt|}|t	j
kr'tdt| j|j|}t|dk dS )a  
        Sign the certificate with this key and digest type.

        :param pkey: The key to sign with.
        :type pkey: :py:class:`PKey`

        :param digest: The name of the message digest to use.
        :type digest: :py:class:`str`

        :return: :py:data:`None`
        r=  zKey only has public partzKey is uninitializedNo such digest methodr   N)rV   r!   rW   r   rY   r~   r?   EVP_get_digestbynamer   rE   rJ   	X509_signr'  r}   rI   )rq   r   r@  evp_mdsign_resultr6   r6   r7   sign  s   

z	X509.signrN   c                 C  sZ   t | j}td}t |tjtj| t |d }|t jkr%t	dt
t |S )z
        Return the signature algorithm used in the certificate.

        :return: The name of the algorithm.
        :rtype: :py:class:`bytes`

        :raises ValueError: If the signature algorithm is undefined.

        .. versionadded:: 0.13
        zASN1_OBJECT **r   zUndefined signature algorithm)r?   X509_get0_tbs_sigalgr'  rE   rF   X509_ALGOR_get0rJ   r   r   rY   re   
OBJ_nid2ln)rq   sig_algalgr   r6   r6   r7   get_signature_algorithm  s   

zX509.get_signature_algorithmdigest_namec                 C  s   t t|}|tjkrtdtdt j}tdd}t||d< t 	| j
|||}t|dk ddd t||d D S )	a5  
        Return the digest of the X509 object.

        :param digest_name: The name of the digest algorithm to use.
        :type digest_name: :py:class:`str`

        :return: The digest of the object, formatted as
            :py:const:`b":"`-delimited hex pairs.
        :rtype: :py:class:`bytes`
        rA  zunsigned char[]zunsigned int[]r   r      :c                 S  s   g | ]}t | qS r6   )r   upper)r   chr6   r6   r7   
<listcomp>  s    
zX509.digest.<locals>.<listcomp>)r?   rB  r   rE   rJ   rY   rF   EVP_MAX_MD_SIZErH   X509_digestr'  rI   joinr8   )rq   rM  r@  rP   result_lengthdigest_resultr6   r6   r7   r@    s   

zX509.digestc                 C  r   )z
        Return the hash of the X509 subject.

        :return: The hash of the subject.
        :rtype: :py:class:`int`
        )r?   X509_subject_name_hashr'  rp   r6   r6   r7   subject_name_hash  r:  zX509.subject_name_hashz_X509.set_serial_number is deprecated. You should use cryptography's CertificateBuilder instead.serialc                 C  s   t |ts	tdt|dd }|d}td}t||}t	|tj
k t|d tj
}t|d  t	|tj
k t|tj}t| j|}t	|dk dS )z
        Set the serial number of the certificate.

        :param serial: The new serial number.
        :type serial: :py:class:`int`

        :return: :py:data`None`
        zserial must be an integer   Nr   zBIGNUM**r   r   )rV   r/   rW   hexr   rE   rF   r?   	BN_hex2bnrI   rJ   BN_to_ASN1_INTEGERr   rK   ASN1_INTEGER_freeX509_set_serialNumberr'  )rq   rY  
hex_serialhex_serial_bytesbignum_serialr   asn1_serialrZ   r6   r6   r7   set_serial_number  s   


zX509.set_serial_numberc              	   C  sp   t | j}t |tj}z$t |}zt|}t|d}|W t 	| W t 
| S t 	| w t 
| w )zx
        Return the serial number of this certificate.

        :return: The serial number.
        :rtype: int
           )r?   X509_get_serialNumberr'  ASN1_INTEGER_to_BNrE   rJ   	BN_bn2hexre   r/   r  r   )rq   rc  rb  r`  hexstring_serialrY  r6   r6   r7   get_serial_number  s   


zX509.get_serial_numberzaX509.gmtime_adj_notAfter is deprecated. You should use cryptography's CertificateBuilder instead.amountc                 C  .   t |ts	tdt| j}t|| dS )z
        Adjust the time stamp on which the certificate stops being valid.

        :param int amount: The number of seconds by which to adjust the
            timestamp.
        :return: ``None``
        amount must be an integerN)rV   r/   rW   r?   X509_getm_notAfterr'  X509_gmtime_adj)rq   rk  notAfterr6   r6   r7   gmtime_adj_notAfter  s   
zX509.gmtime_adj_notAfterzbX509.gmtime_adj_notBefore is deprecated. You should use cryptography's CertificateBuilder instead.c                 C  rl  )z
        Adjust the timestamp on which the certificate starts being valid.

        :param amount: The number of seconds by which to adjust the timestamp.
        :return: ``None``
        rm  N)rV   r/   rW   r?   X509_getm_notBeforer'  ro  )rq   rk  	notBeforer6   r6   r7   gmtime_adj_notBefore"  s   
zX509.gmtime_adj_notBeforer   c                 C  sT   |   }|du rtd|d}tj|d}tjj}tj|jdd}||k S )z
        Check whether the certificate has expired.

        :return: ``True`` if the certificate has expired, ``False`` otherwise.
        :rtype: bool
        NzUnable to determine notAfterr   z%Y%m%d%H%M%SZ)tzinfo)	get_notAfterrY   r   datetimestrptimetimezoneutcnowreplace)rq   
time_bytestime_string	not_afterUTCutcnowr6   r6   r7   has_expired3  s   
zX509.has_expiredwhichr9   c                 C  s   t || jS r>   )rm   r'  )rq   r  r6   r6   r7   _get_boundary_timeD  r   zX509._get_boundary_timec                 C     |  tjS )a
  
        Get the timestamp at which the certificate starts being valid.

        The timestamp is formatted as an ASN.1 TIME::

            YYYYMMDDhhmmssZ

        :return: A timestamp string, or ``None`` if there is none.
        :rtype: bytes or NoneType
        )r  r?   rr  rp   r6   r6   r7   get_notBeforeG     zX509.get_notBeforeCallable[..., Any]rT   c                 C  s   t || j|S r>   )r[   r'  )rq   r  rT   r6   r6   r7   _set_boundary_timeT  s   zX509._set_boundary_timez[X509.set_notBefore is deprecated. You should use cryptography's CertificateBuilder instead.c                 C     |  tj|S )z
        Set the timestamp at which the certificate starts being valid.

        The timestamp is formatted as an ASN.1 TIME::

            YYYYMMDDhhmmssZ

        :param bytes when: A timestamp string.
        :return: ``None``
        )r  r?   rr  rq   rT   r6   r6   r7   set_notBeforeY     zX509.set_notBeforec                 C  r  )a	  
        Get the timestamp at which the certificate stops being valid.

        The timestamp is formatted as an ASN.1 TIME::

            YYYYMMDDhhmmssZ

        :return: A timestamp string, or ``None`` if there is none.
        :rtype: bytes or NoneType
        )r  r?   rn  rp   r6   r6   r7   rv  j  r  zX509.get_notAfterzZX509.set_notAfter is deprecated. You should use cryptography's CertificateBuilder instead.c                 C  r  )z
        Set the timestamp at which the certificate stops being valid.

        The timestamp is formatted as an ASN.1 TIME::

            YYYYMMDDhhmmssZ

        :param bytes when: A timestamp string.
        :return: ``None``
        )r  r?   rn  r  r6   r6   r7   set_notAfterw  r  zX509.set_notAfterr"   c                 C  s0   t t}|| j|_t|jtjk | |_|S r>   )	objectr*  r"   r'  rw   rI   rE   rJ   _owner)rq   r  rs   r6   r6   r7   	_get_name  s
   
zX509._get_namers   c                 C  s0   t |ts	td|| j|j}t|dk d S )Nzname must be an X509Namer   )rV   r"   rW   r'  rw   rI   )rq   r  rs   rZ   r6   r6   r7   	_set_name  s   
zX509._set_namezPX509.get_issuer is deprecated. You should use cryptography's X.509 APIs instead.c                 C     |  tj}| j| |S )a  
        Return the issuer of this certificate.

        This creates a new :class:`X509Name` that wraps the underlying issuer
        name field on the certificate. Modifying it will modify the underlying
        certificate, and will have the effect of modifying any other
        :class:`X509Name` that refers to this issuer.

        :return: The issuer of this certificate.
        :rtype: :class:`X509Name`
        )r  r?   X509_get_issuer_namer(  rv   ru   r6   r6   r7   
get_issuer     zX509.get_issuerzXX509.set_issuer is deprecated. You should use cryptography's CertificateBuilder instead.issuerc                 C     |  tj| | j  dS )z
        Set the issuer of this certificate.

        :param issuer: The issuer.
        :type issuer: :py:class:`X509Name`

        :return: ``None``
        N)r  r?   X509_set_issuer_namer(  rx   )rq   r  r6   r6   r7   
set_issuer     zX509.set_issuerzQX509.get_subject is deprecated. You should use cryptography's X.509 APIs instead.c                 C  r  )a  
        Return the subject of this certificate.

        This creates a new :class:`X509Name` that wraps the underlying subject
        name field on the certificate. Modifying it will modify the underlying
        certificate, and will have the effect of modifying any other
        :class:`X509Name` that refers to this subject.

        :return: The subject of this certificate.
        :rtype: :class:`X509Name`
        )r  r?   X509_get_subject_namer)  rv   ru   r6   r6   r7   get_subject  r  zX509.get_subjectzYX509.set_subject is deprecated. You should use cryptography's CertificateBuilder instead.subjectc                 C  r  )z
        Set the subject of this certificate.

        :param subject: The subject.
        :type subject: :py:class:`X509Name`

        :return: ``None``
        N)r  r?   X509_set_subject_namer)  rx   )rq   r  r6   r6   r7   set_subject  r  zX509.set_subjectc                 C  r   )z
        Get the number of extensions on this certificate.

        :return: The number of extensions.
        :rtype: :py:class:`int`

        .. versionadded:: 0.12
        )r?   X509_get_ext_countr'  rp   r6   r6   r7   get_extension_count  s   	zX509.get_extension_countNry   )r   r   r:   r   )r:   r-  )r1  r-  r:   r   )r5  r/   r:   rU   r   )r:   r!   )r   r!   r:   rU   )r   r!   r@  r   r:   rU   r$  )rM  r   r:   rN   )rY  r/   r:   rU   )rk  r/   r:   rU   r   )r  r   r:   r9   )r:   r9   )r  r  rT   rN   r:   rU   )rT   rN   r:   rU   )r  r   r:   r"   )r  r   rs   r"   r:   rU   )r:   r"   )r  r"   r:   rU   )r  r"   r:   rU   )$r2   r3   r4   r5   rr   r   r,  r0  r4  r   r7  r9  r<  r?  rF  rL  r@  rX  rd  rj  rq  rt  r  r  r  r  r  rv  r  r  r  r  r  r  r  r  r6   r6   r6   r7   r     s    



	


	







r   c                   @  s   e Zd ZU dZejZded< ejZ	ded< ej
Zded< ejZded< ejZded< ejZded< ejZded	< ejZded
< ejZded< ejZded< dS )r&   a  
    Flags for X509 verification, used to change the behavior of
    :class:`X509Store`.

    See `OpenSSL Verification Flags`_ for details.

    .. _OpenSSL Verification Flags:
        https://www.openssl.org/docs/manmaster/man3/X509_VERIFY_PARAM_set_flags.html
    r/   	CRL_CHECKCRL_CHECK_ALLIGNORE_CRITICALX509_STRICTALLOW_PROXY_CERTSPOLICY_CHECKEXPLICIT_POLICYINHIBIT_MAPCHECK_SS_SIGNATUREPARTIAL_CHAINN)r2   r3   r4   r5   r?   X509_V_FLAG_CRL_CHECKr  __annotations__X509_V_FLAG_CRL_CHECK_ALLr  X509_V_FLAG_IGNORE_CRITICALr  X509_V_FLAG_X509_STRICTr  X509_V_FLAG_ALLOW_PROXY_CERTSr  X509_V_FLAG_POLICY_CHECKr  X509_V_FLAG_EXPLICIT_POLICYr  X509_V_FLAG_INHIBIT_MAPr  X509_V_FLAG_CHECK_SS_SIGNATUREr  X509_V_FLAG_PARTIAL_CHAINr  r6   r6   r6   r7   r&     s   
 
r&   c                   @  sP   e Zd ZdZdddZddd	ZdddZdddZd ddZ	d!d"ddZ	dS )#r#   a  
    An X.509 store.

    An X.509 store is used to describe a context in which to verify a
    certificate. A description of a context may include a set of certificates
    to trust, a set of certificate revocation lists, verification flags and
    more.

    An X.509 store, being only a description, cannot be used by itself to
    verify a certificate. To carry out the actual verification process, see
    :class:`X509StoreContext`.
    r:   rU   c                 C  s   t  }t|t j| _d S r>   )r?   X509_STORE_newrE   rK   X509_STORE_free_storerq   storer6   r6   r7   rr     s   zX509Store.__init__r+  r   c                 C  s0   t |tst t| j|j}t|dk dS )a  
        Adds a trusted certificate to this store.

        Adding a certificate with this method adds this certificate as a
        *trusted* certificate.

        :param X509 cert: The certificate to add to this store.

        :raises TypeError: If the certificate is not an :class:`X509`.

        :raises OpenSSL.crypto.Error: If OpenSSL was unhappy with your
            certificate.

        :return: ``None`` if the certificate was added successfully.
        r   N)rV   r   rW   r?   X509_STORE_add_certr  r'  rI   )rq   r+  r   r6   r6   r7   add_cert  s   
zX509Store.add_certcrlx509.CertificateRevocationListc                 C  sv   t |tjr*ddlm} t||j}t	|t
j}t|t
jk t
|tj}ntdtt| j|dk dS )a  
        Add a certificate revocation list to this store.

        The certificate revocation lists added to a store will only be used if
        the associated flags are configured to check certificate revocation
        lists.

        .. versionadded:: 16.1.0

        :param crl: The certificate revocation list to add to this store.
        :type crl: ``cryptography.x509.CertificateRevocationList``
        :return: ``None`` if the certificate revocation list was added
            successfully.
        r   r2  z?CRL must be of type cryptography.x509.CertificateRevocationListN)rV   r   CertificateRevocationListr   r   rM   r   r   r?   d2i_X509_CRL_biorE   rJ   rI   rK   X509_CRL_freerW   X509_STORE_add_crlr  )rq   r  r   r<   openssl_crlr6   r6   r7   add_crl.  s   zX509Store.add_crlflagsr/   c                 C  s   t t| j|dk dS )a  
        Set verification flags to this store.

        Verification flags can be combined by oring them together.

        .. note::

          Setting a verification flag sometimes requires clients to add
          additional information to the store, otherwise a suitable error will
          be raised.

          For example, in setting flags to enable CRL checking a
          suitable CRL must be added to the store otherwise an error will be
          raised.

        .. versionadded:: 16.1.0

        :param int flags: The verification flags to set on this store.
            See :class:`X509StoreFlags` for available constants.
        :return: ``None`` if the verification flags were successfully set.
        r   N)rI   r?   X509_STORE_set_flagsr  )rq   r  r6   r6   r7   	set_flagsL  s   zX509Store.set_flagsvfy_timedatetime.datetimec                 C  sF   t  }t|t j}t |t|  t	t 
| j|dk dS )a  
        Set the time against which the certificates are verified.

        Normally the current time is used.

        .. note::

          For example, you can determine if a certificate was valid at a given
          time.

        .. versionadded:: 17.0.0

        :param datetime vfy_time: The verification time to set on this store.
        :return: ``None`` if the verification time was successfully set.
        r   N)r?   X509_VERIFY_PARAM_newrE   rK   X509_VERIFY_PARAM_freeX509_VERIFY_PARAM_set_timecalendartimegm	timetuplerI   X509_STORE_set1_paramr  )rq   r  paramr6   r6   r7   set_timed  s   zX509Store.set_timeNcafileStrOrBytesPath | Nonecapathc                 C  sR   |du rt j}nt|}|du rt j}nt|}t| j||}|s't  dS dS )a  
        Let X509Store know where we can find trusted certificates for the
        certificate chain.  Note that the certificates have to be in PEM
        format.

        If *capath* is passed, it must be a directory prepared using the
        ``c_rehash`` tool included with OpenSSL.  Either, but not both, of
        *cafile* or *capath* may be ``None``.

        .. note::

          Both *cafile* and *capath* may be set simultaneously.

          Call this method multiple times to add more than one location.
          For example, CA certificates, and certificate revocation list bundles
          may be passed in *cafile* in subsequent calls to this method.

        .. versionadded:: 20.0

        :param cafile: In which file we can find the certificates (``bytes`` or
                       ``unicode``).
        :param capath: In which directory we can find the certificates
                       (``bytes`` or ``unicode``).

        :return: ``None`` if the locations were set successfully.

        :raises OpenSSL.crypto.Error: If both *cafile* and *capath* is ``None``
            or the locations could not be set for any reason.

        N)rE   rJ   _path_bytesr?   X509_STORE_load_locationsr  r   )rq   r  r  load_resultr6   r6   r7   load_locations|  s   #
zX509Store.load_locationsry   )r+  r   r:   rU   )r  r  r:   rU   )r  r/   r:   rU   )r  r  r:   rU   r>   )r  r  r  r  r:   rU   )
r2   r3   r4   r5   rr   r  r  r  r  r  r6   r6   r6   r7   r#     s    




r#   c                      s"   e Zd ZdZd fd
dZ  ZS )r%   z
    An exception raised when an error occurred while verifying a certificate
    using `OpenSSL.X509StoreContext.verify_certificate`.

    :ivar certificate: The certificate which caused verificate failure.
    :type certificate: :class:`X509`
    messager   errors	list[Any]certificater   r:   rU   c                   s   t  | || _|| _d S r>   )r   rr   r  r  )rq   r  r  r  r   r6   r7   rr     s   
zX509StoreContextError.__init__)r  r   r  r  r  r   r:   rU   )r2   r3   r4   r5   rr   r   r6   r6   r   r7   r%     s    r%   c                   @  sb   e Zd ZdZ	ddddZed ddZed!ddZd"ddZd#ddZ	d$ddZ
d%ddZdS )&r$   a9  
    An X.509 store context.

    An X.509 store context is used to carry out the actual verification process
    of a certificate in a described context. For describing such a context, see
    :class:`X509Store`.

    :param X509Store store: The certificates which will be trusted for the
        purposes of any verifications.
    :param X509 certificate: The certificate to be verified.
    :param chain: List of untrusted certificates that may be used for building
        the certificate chain. May be ``None``.
    :type chain: :class:`list` of :class:`X509`
    Nr  r#   r  r   chainSequence[X509] | Noner:   rU   c                 C  s   || _ || _| || _d S r>   )r  _cert_build_certificate_stack_chain)rq   r  r  r  r6   r6   r7   rr     s   zX509StoreContext.__init__certificatesc                 C  s   d	dd}| d u st | dkrtjS t }t|tjk t||}| D ]'}t|ts0t	dtt
|jdk t||jdkrLt|j t  q%|S )
Nsr   r:   rU   c                 S  s8   t t| D ]}t| |}t| qt|  d S r>   )r   r?   sk_X509_numsk_X509_valuer&  sk_X509_free)r  r  xr6   r6   r7   cleanup  s   z:X509StoreContext._build_certificate_stack.<locals>.cleanupr   z+One of the elements is not an X509 instance)r  r   r:   rU   )rH   rE   rJ   r?   sk_X509_new_nullrI   rK   rV   r   rW   X509_up_refr'  sk_X509_pushr&  r   )r  r  stackr+  r6   r6   r7   r    s   

z)X509StoreContext._build_certificate_stack	store_ctxr   r%   c                 C  s\   t tt| d}t| t| |g}t| }t|}t	
|}t|||S )z
        Convert an OpenSSL native context error failure into a Python
        exception.

        When a call to native OpenSSL X509_verify_cert fails, additional
        information about the failure can be obtained from the store context.
        r   )rE   re   r?   X509_verify_cert_error_stringX509_STORE_CTX_get_errorr   X509_STORE_CTX_get_error_depthX509_STORE_CTX_get_current_certX509_dupr   r,  r%   )r  r  r  r'  r  pycertr6   r6   r7   _exception_from_context  s   	


z(X509StoreContext._exception_from_contextc                 C  sj   t  }t|tjk t|t j}t || jj| j	j
| j}t|dk t |}|dkr3| ||S )a3  
        Verifies the certificate and runs an X509_STORE_CTX containing the
        results.

        :raises X509StoreContextError: If an error occurred when validating a
          certificate in the context. Sets ``certificate`` attribute to
          indicate which certificate caused the error.
        r   r   )r?   X509_STORE_CTX_newrI   rE   rJ   rK   X509_STORE_CTX_freeX509_STORE_CTX_initr  r  r'  r  X509_verify_certr  )rq   r  r^   r6   r6   r7   _verify_certificate  s   	

z$X509StoreContext._verify_certificatec                 C  s
   || _ dS )z
        Set the context's X.509 store.

        .. versionadded:: 0.15

        :param X509Store store: The store description which will be used for
            the purposes of any *future* verifications.
        N)r  r  r6   r6   r7   	set_store+  s   
	zX509StoreContext.set_storec                 C  s   |    dS )a"  
        Verify a certificate in a context.

        .. versionadded:: 0.15

        :raises X509StoreContextError: If an error occurred when validating a
          certificate in the context. Sets ``certificate`` attribute to
          indicate which certificate caused the error.
        N)r  rp   r6   r6   r7   verify_certificate6  r  z#X509StoreContext.verify_certificate
list[X509]c                 C  st   |   }t|}t|tjk g }tt|D ]}t||}t|tjk t	
|}|| qt| |S )aR  
        Verify a certificate in a context and return the complete validated
        chain.

        :raises X509StoreContextError: If an error occurred when validating a
          certificate in the context. Sets ``certificate`` attribute to
          indicate which certificate caused the error.

        .. versionadded:: 20.0
        )r  r?   X509_STORE_CTX_get1_chainrI   rE   rJ   r   r  r  r   r,  rt   r  )rq   r  
cert_stackr   r  r+  r  r6   r6   r7   get_verified_chainB  s   


z#X509StoreContext.get_verified_chainr>   )r  r#   r  r   r  r  r:   rU   )r  r  r:   rU   )r  r   r:   r%   r   )r  r#   r:   rU   ry   )r:   r  )r2   r3   r4   r5   rr   staticmethodr  r  r  r  r  r  r6   r6   r6   r7   r$     s    



r$   r   c                 C  sv   t |tr
|d}t|}| tkrt|tjtjtj}n| t	kr*t
|tj}ntd|tjkr6t  t|S )a  
    Load a certificate (X509) from the string *buffer* encoded with the
    type *type*.

    :param type: The file type (one of FILETYPE_PEM, FILETYPE_ASN1)

    :param bytes buffer: The buffer the certificate is stored in

    :return: The X509 object
    r   3type argument must be FILETYPE_PEM or FILETYPE_ASN1)rV   r   r   rM   r   r?   PEM_read_bio_X509rE   rJ   r   d2i_X509_biorY   r   r   r,  )r   r8   r<   r   r6   r6   r7   r,   _  s   



r,   r+  c                 C  sn   t  }| tkrt||j}n| tkrt||j}n| tkr)t||jdd}nt	dt
|dk t|S )a  
    Dump the certificate *cert* into a buffer string encoded with the type
    *type*.

    :param type: The file type (one of FILETYPE_PEM, FILETYPE_ASN1, or
        FILETYPE_TEXT)
    :param cert: The certificate to dump
    :return: The buffer with the dumped certificate in
    r   Ctype argument must be FILETYPE_PEM, FILETYPE_ASN1, or FILETYPE_TEXTr   )rM   r   r?   PEM_write_bio_X509r'  r   i2d_X509_bior   X509_print_exrY   rI   rR   )r   r+  r<   result_coder6   r6   r7   r'   |  s   
r'   r   c                 C  sP   t  }| tkrtj}n| tkrtj}ntd|||j}|dkr$t  t	|S )z
    Dump a public key to a buffer.

    :param type: The file type (one of :data:`FILETYPE_PEM` or
        :data:`FILETYPE_ASN1`).
    :param PKey pkey: The public key to dump
    :return: The buffer with the dumped key in it.
    :rtype: bytes
    r  r   )
rM   r   r?   PEM_write_bio_PUBKEYr   i2d_PUBKEY_biorY   r}   r   rR   )r   r   r<   	write_bior  r6   r6   r7   r)     s   
r)   cipherr  
passphrasePassphraseCallableT | Nonec           	   	   C  s  t  }t|tstd|dur)|du rtdtt|}|tjkr(t	dntj}t
| |}| tkrIt||j|tjd|j|j}|  n4| tkrUt||j}n(| tkryt|jtjkrftdtt|jtj}t||d}nt	dt|dk t|S )a  
    Dump the private key *pkey* into a buffer string encoded with the type
    *type*.  Optionally (if *type* is :const:`FILETYPE_PEM`) encrypting it
    using *cipher* and *passphrase*.

    :param type: The file type (one of :const:`FILETYPE_PEM`,
        :const:`FILETYPE_ASN1`, or :const:`FILETYPE_TEXT`)
    :param PKey pkey: The PKey to dump
    :param cipher: (optional) if encrypted PEM format, the cipher to use
    :param passphrase: (optional) if encrypted PEM format, this can be either
        the passphrase to use, or a callback for providing the passphrase.

    :return: The buffer with the dumped key in
    :rtype: bytes

    .. deprecated:: 26.3.0
       Use the serialization APIs on ``cryptography`` private key types
       instead.
    zpkey must be a PKeyNzDif a value is given for cipher one must also be given for passphrasezInvalid cipher namer   z-Only RSA keys are supported for FILETYPE_TEXTr  )rM   rV   r!   rW   r?   EVP_get_cipherbynamer   rE   rJ   rY   _PassphraseHelperr   PEM_write_bio_PrivateKeyr}   callbackcallback_argsraise_if_problemr   i2d_PrivateKey_bior   r   r   rK   r   r   	RSA_printrI   rR   )	r   r   r  r  r<   
cipher_objhelperr  r   r6   r6   r7   r(     sJ   



	r(   zGdump_privatekey is deprecated. You should use the APIs in cryptography.r   c                   @  sP   e Zd Z		ddddZedddZedddZefd ddZd!ddZ	dS )"r  Fr   r/   r  r  	more_argsr   truncater:   rU   c                 C  s4   |t kr|d urtd|| _|| _|| _g | _d S )Nz0only FILETYPE_PEM key format supports encryption)r   rY   _passphrase
_more_args	_truncate	_problems)rq   r   r  r  r  r6   r6   r7   rr   	  s   
z_PassphraseHelper.__init__r   c                 C  s<   | j d u rtjS t| j tst| j rtd| jS td)Npem_password_cb2Last argument must be a byte string or a callable.)	r  rE   rJ   rV   rN   callabler  _read_passphraserW   rp   r6   r6   r7   r    s   
z_PassphraseHelper.callbackc                 C  s4   | j d u rtjS t| j tst| j rtjS td)Nr#  )r  rE   rJ   rV   rN   r$  rW   rp   r6   r6   r7   r  $  s   
z_PassphraseHelper.callback_argsexceptionTypetype[Exception]c                 C  s6   | j rzt| W n	 |y   Y nw | j dd S r  )r!  _exception_from_error_queuepop)rq   r&  r6   r6   r7   r  /  s   z"_PassphraseHelper.raise_if_problembufsizerwflaguserdatac              
   C  s   zUt | jr| jr| |||}n| |}n
| jd usJ | j}t|ts*tdt||kr>| jr:|d | }ntdtt|D ]}|||d  ||< qDt|W S  t	yn } z| j
| W Y d }~dS d }~ww )NzBytes expectedz+passphrase returned by callback is too longr   r   )r$  r  r  rV   rN   rY   rH   r   r   	Exceptionr!  rt   )rq   r*  r+  r,  r-  r   r  er6   r6   r7   r%  9  s.   


z"_PassphraseHelper._read_passphraseN)FF)
r   r/   r  r  r  r   r  r   r:   rU   r   )r&  r'  r:   rU   )
r*  r   r+  r/   r,  r   r-  r   r:   r/   )
r2   r3   r4   rr   propertyr  r  r    r  r%  r6   r6   r6   r7   r    s    


r  str | bytesc                 C  s   t |tr
|d}t|}| tkrt|tjtjtj}n| t	kr*t
|tj}ntd|tjkr6t  tt}t|tj|_d|_|S )a<  
    Load a public key from a buffer.

    :param type: The file type (one of :data:`FILETYPE_PEM`,
        :data:`FILETYPE_ASN1`).
    :param buffer: The buffer the key is stored in.
    :type buffer: A Python string object, either unicode or bytestring.
    :return: The PKey object.
    :rtype: :class:`PKey`
    r   r  T)rV   r   r   rM   r   r?   PEM_read_bio_PUBKEYrE   rJ   r   d2i_PUBKEY_biorY   r   r!   r*  rK   r|   r}   r   )r   r8   r<   evp_pkeyr   r6   r6   r7   r.   V  s    



r.   c                 C  s   t |tr
|d}t|}t| |}| tkr't|tj	|j
|j}|  n| tkr3t|tj	}ntd|tj	kr?t  tt}t|tj|_|S )a  
    Load a private key (PKey) from the string *buffer* encoded with the type
    *type*.

    :param type: The file type (one of FILETYPE_PEM, FILETYPE_ASN1)
    :param buffer: The buffer the key is stored in
    :param passphrase: (optional) if encrypted PEM format, this can be
                       either the passphrase to use, or a callback for
                       providing the passphrase.

    :return: The PKey object
    r   r  )rV   r   r   rM   r  r   r?   PEM_read_bio_PrivateKeyrE   rJ   r  r  r  r   d2i_PrivateKey_biorY   r   r!   r*  rK   r|   r}   )r   r8   r  r<   r  r4  r   r6   r6   r7   r-   x  s"   





r-   r>   )r8   r9   r:   r   )r<   r   r:   rN   )rS   r   rT   rN   r:   rU   )rT   rN   r:   r   )r`   r   r:   r9   )r:   r   )rs   r   r:   r   )r   r/   r8   rN   r:   r   )r   r/   r+  r   r:   rN   )r   r/   r   r!   r:   rN   )NN)
r   r/   r   r!   r  r  r  r  r:   rN   )r   r/   r8   r1  r:   r!   )r   r/   r8   r1  r  r  r:   r!   )g
__future__r   r  rw  	functoolssysr   base64r   collections.abcr   r   r   r   r   version_infowarningsr   typing_extensionscryptographyr   r   )cryptography.hazmat.primitives.asymmetricr   r   r   r   r   OpenSSL._utilr   r   r   r   r(  r   rE   r   r?   r   _make_assertr   r  __all__r   r   r   r   r   _PrivateKeyr   r   r   r   r   
_PublicKeyr   rN   PassphraseCallableTSSL_FILETYPE_PEMr   r  SSL_FILETYPE_ASN1r   r   r   r   EVP_PKEY_DSAr   EVP_PKEY_DHr0   EVP_PKEY_ECr1   r.  r    r   rI   rM   rR   r[   r_   rm   rn   r!   r   r+   r*   total_orderingr"   r   r&   r#   r%   r$   r,   r'   r)   r(   r   r2   DeprecationWarningr  r.   r-   r6   r6   r6   r7   <module>   s    



	

 Jg C   e + 


I
N%