a
    còfÙ�  ã                	   @  sŠ  d dl mZ d dlZd dlZd dlZd dlZd dlZd dlmZ d dl	m
Z d dlmZmZ d dlmZmZmZmZmZmZmZmZ d dlmZmZmZ d dlmZmZmZm Z  d d	l!m"Z"m#Z# d d
l$m%Z% e ddd¡Z&ej'ej(ej)ej*ej+ej,ej-ej.ej/f Z0G dd„ de1ƒZ2ddddœdd„Z3ddddœdd„Z4dddœdd„Z5G dd„ dƒZ6G d d!„ d!ƒZ7G d"d#„ d#ej8ƒZ9G d$d%„ d%e1ƒZ:G d&d'„ d'ej;d(�Z<e< =ej<¡ G d)d*„ d*ej;d(�Z>e> =ej>¡ G d+d,„ d,e>ƒZ?G d-d.„ d.ej;d(�Z@e@ =ej@¡ G d/d0„ d0ej;d(�ZAeA =ejA¡ ejBZBejCZCejDZDejEZEejFZFejGZGejHZHG d1d2„ d2ƒZIG d3d4„ d4ƒZJG d5d6„ d6ƒZKG d7d8„ d8ƒZLd9d:œd;d<„ZMdS )=é    )ÚannotationsN)Úutils)Úx509)ÚhashesÚserialization)ÚdsaÚecÚed448Úed25519ÚpaddingÚrsaÚx448Úx25519)Ú CertificateIssuerPrivateKeyTypesÚCertificateIssuerPublicKeyTypesÚCertificatePublicKeyTypes)Ú	ExtensionÚ
ExtensionsÚExtensionTypeÚ_make_sequence_methods)ÚNameÚ	_ASN1Type)ÚObjectIdentifieriž  é   c                      s&   e Zd Zddddœ‡ fdd„Z‡  ZS )ÚAttributeNotFoundÚstrr   ÚNone)ÚmsgÚoidÚreturnc                   s   t ƒ  |¡ || _d S ©N)ÚsuperÚ__init__r   )Úselfr   r   ©Ú	__class__© úS/home/httpd/docs/test/DocsMgr/lib/python3.9/site-packages/cryptography/x509/base.pyr"   9   s    zAttributeNotFound.__init__©Ú__name__Ú
__module__Ú__qualname__r"   Ú__classcell__r&   r&   r$   r'   r   8   s   r   zExtension[ExtensionType]úlist[Extension[ExtensionType]]r   )Ú	extensionÚ
extensionsr   c                 C  s"   |D ]}|j | j krtdƒ‚qd S )Nz$This extension has already been set.)r   Ú
ValueError)r.   r/   Úer&   r&   r'   Ú_reject_duplicate_extension>   s    r2   r   ú0list[tuple[ObjectIdentifier, bytes, int | None]])r   Ú
attributesr   c                 C  s$   |D ]\}}}|| krt dƒ‚qd S )Nz$This attribute has already been set.)r0   )r   r4   Zattr_oidÚ_r&   r&   r'   Ú_reject_duplicate_attributeH   s    r6   údatetime.datetime©Útimer   c                 C  s:   | j dur2|  ¡ }|r|nt ¡ }| jdd�| S | S dS )z’Normalizes a datetime to a naive datetime in UTC.

    time -- datetime to normalize. Assumed to be in UTC if not timezone
            aware.
    N©Útzinfo)r;   Ú	utcoffsetÚdatetimeÚ	timedeltaÚreplace)r9   Úoffsetr&   r&   r'   Ú_convert_to_naive_utc_timeR   s
    
rA   c                   @  sx   e Zd Zejjfdddddœdd„Zeddœd	d
„ƒZeddœdd„ƒZddœdd„Z	dddœdd„Z
ddœdd„ZdS )Ú	Attributer   ÚbytesÚintr   )r   ÚvalueÚ_typer   c                 C  s   || _ || _|| _d S r    )Ú_oidÚ_valuerF   )r#   r   rE   rF   r&   r&   r'   r"   a   s    zAttribute.__init__©r   c                 C  s   | j S r    )rG   ©r#   r&   r&   r'   r   k   s    zAttribute.oidc                 C  s   | j S r    )rH   rJ   r&   r&   r'   rE   o   s    zAttribute.valuer   c                 C  s   d| j › d| j›d�S )Nz<Attribute(oid=z, value=ú)>)r   rE   rJ   r&   r&   r'   Ú__repr__s   s    zAttribute.__repr__ÚobjectÚbool©Úotherr   c                 C  s2   t |tƒstS | j|jko0| j|jko0| j|jkS r    )Ú
isinstancerB   ÚNotImplementedr   rE   rF   ©r#   rP   r&   r&   r'   Ú__eq__v   s    

ÿ
ýzAttribute.__eq__c                 C  s   t | j| j| jfƒS r    )Úhashr   rE   rF   rJ   r&   r&   r'   Ú__hash__€   s    zAttribute.__hash__N)r)   r*   r+   r   Z
UTF8StringrE   r"   Úpropertyr   rL   rT   rV   r&   r&   r&   r'   rB   `   s   ü

rB   c                   @  sH   e Zd Zdddœdd„Zedƒ\ZZZddœd	d
„Zdddœdd„Z	dS )Ú
Attributesztyping.Iterable[Attribute]r   )r4   r   c                 C  s   t |ƒ| _d S r    )ÚlistÚ_attributes)r#   r4   r&   r&   r'   r"   …   s    zAttributes.__init__rZ   r   rI   c                 C  s   d| j › d�S )Nz<Attributes(rK   )rZ   rJ   r&   r&   r'   rL   �   s    zAttributes.__repr__r   rB   ©r   r   c                 C  s2   | D ]}|j |kr|  S qtd|› d�|ƒ‚d S )NzNo z attribute was found)r   r   )r#   r   Úattrr&   r&   r'   Úget_attribute_for_oid�   s    

z Attributes.get_attribute_for_oidN)
r)   r*   r+   r"   r   Ú__len__Ú__iter__Ú__getitem__rL   r]   r&   r&   r&   r'   rX   „   s   rX   c                   @  s   e Zd ZdZdZdS )ÚVersionr   é   N)r)   r*   r+   Úv1Úv3r&   r&   r&   r'   ra   ˜   s   ra   c                      s&   e Zd Zddddœ‡ fdd„Z‡  ZS )ÚInvalidVersionr   rD   r   )r   Úparsed_versionr   c                   s   t ƒ  |¡ || _d S r    )r!   r"   rf   )r#   r   rf   r$   r&   r'   r"   ž   s    zInvalidVersion.__init__r(   r&   r&   r$   r'   re   �   s   re   c                   @  s  e Zd Zejdddœdd„ƒZeejddœdd	„ƒƒZeejd
dœdd„ƒƒZejddœdd„ƒZ	eejddœdd„ƒƒZ
eejddœdd„ƒƒZeejddœdd„ƒƒZeejddœdd„ƒƒZeejddœdd„ƒƒZeejddœdd„ƒƒZeejddœdd „ƒƒZeejd!dœd"d#„ƒƒZeejddœd$d%„ƒƒZeejd&dœd'd(„ƒƒZeejd)dœd*d+„ƒƒZeejddœd,d-„ƒƒZeejddœd.d/„ƒƒZeejddœd0d1„ƒƒZejd2d3d4œd5d6„ƒZejddœd7d8„ƒZejd9dd:œd;d<„ƒZejd d=d>œd?d@„ƒZdAS )BÚCertificateúhashes.HashAlgorithmrC   ©Ú	algorithmr   c                 C  s   dS ©z4
        Returns bytes using digest passed.
        Nr&   ©r#   rj   r&   r&   r'   Úfingerprint¤   s    zCertificate.fingerprintrD   rI   c                 C  s   dS )z3
        Returns certificate serial number
        Nr&   rJ   r&   r&   r'   Úserial_numberª   s    zCertificate.serial_numberra   c                 C  s   dS )z1
        Returns the certificate version
        Nr&   rJ   r&   r&   r'   Úversion±   s    zCertificate.versionr   c                 C  s   dS ©z(
        Returns the public key
        Nr&   rJ   r&   r&   r'   Ú
public_key¸   s    zCertificate.public_keyr   c                 C  s   dS )zA
        Returns the ObjectIdentifier of the public key.
        Nr&   rJ   r&   r&   r'   Úpublic_key_algorithm_oid¾   s    z$Certificate.public_key_algorithm_oidr7   c                 C  s   dS )z?
        Not before time (represented as UTC datetime)
        Nr&   rJ   r&   r&   r'   Únot_valid_beforeÅ   s    zCertificate.not_valid_beforec                 C  s   dS )zK
        Not before time (represented as a non-naive UTC datetime)
        Nr&   rJ   r&   r&   r'   Únot_valid_before_utcÌ   s    z Certificate.not_valid_before_utcc                 C  s   dS )z>
        Not after time (represented as UTC datetime)
        Nr&   rJ   r&   r&   r'   Únot_valid_afterÓ   s    zCertificate.not_valid_afterc                 C  s   dS )zJ
        Not after time (represented as a non-naive UTC datetime)
        Nr&   rJ   r&   r&   r'   Únot_valid_after_utcÚ   s    zCertificate.not_valid_after_utcr   c                 C  s   dS )z1
        Returns the issuer name object.
        Nr&   rJ   r&   r&   r'   Úissuerá   s    zCertificate.issuerc                 C  s   dS ©z2
        Returns the subject name object.
        Nr&   rJ   r&   r&   r'   Úsubjectè   s    zCertificate.subjectúhashes.HashAlgorithm | Nonec                 C  s   dS ©zt
        Returns a HashAlgorithm corresponding to the type of the digest signed
        in the certificate.
        Nr&   rJ   r&   r&   r'   Úsignature_hash_algorithmï   s    z$Certificate.signature_hash_algorithmc                 C  s   dS ©zJ
        Returns the ObjectIdentifier of the signature algorithm.
        Nr&   rJ   r&   r&   r'   Úsignature_algorithm_oidù   s    z#Certificate.signature_algorithm_oidú0None | padding.PSS | padding.PKCS1v15 | ec.ECDSAc                 C  s   dS ©z=
        Returns the signature algorithm parameters.
        Nr&   rJ   r&   r&   r'   Úsignature_algorithm_parameters   s    z*Certificate.signature_algorithm_parametersr   c                 C  s   dS )z/
        Returns an Extensions object.
        Nr&   rJ   r&   r&   r'   r/   	  s    zCertificate.extensionsc                 C  s   dS ©z.
        Returns the signature bytes.
        Nr&   rJ   r&   r&   r'   Ú	signature  s    zCertificate.signaturec                 C  s   dS )zR
        Returns the tbsCertificate payload bytes as defined in RFC 5280.
        Nr&   rJ   r&   r&   r'   Útbs_certificate_bytes  s    z!Certificate.tbs_certificate_bytesc                 C  s   dS )zh
        Returns the tbsCertificate payload bytes with the SCT list extension
        stripped.
        Nr&   rJ   r&   r&   r'   Útbs_precertificate_bytes  s    z$Certificate.tbs_precertificate_bytesrM   rN   rO   c                 C  s   dS ©z"
        Checks equality.
        Nr&   rS   r&   r&   r'   rT   &  s    zCertificate.__eq__c                 C  s   dS ©z"
        Computes a hash.
        Nr&   rJ   r&   r&   r'   rV   ,  s    zCertificate.__hash__úserialization.Encoding©Úencodingr   c                 C  s   dS )zB
        Serializes the certificate to PEM or DER format.
        Nr&   ©r#   rŠ   r&   r&   r'   Úpublic_bytes2  s    zCertificate.public_bytesr   )rw   r   c                 C  s   dS )zÕ
        This method verifies that certificate issuer name matches the
        issuer subject name and that the certificate is signed by the
        issuer's private key. No other validation is performed.
        Nr&   )r#   rw   r&   r&   r'   Úverify_directly_issued_by8  s    z%Certificate.verify_directly_issued_byN)r)   r*   r+   ÚabcÚabstractmethodrm   rW   rn   ro   rq   rr   rs   rt   ru   rv   rw   ry   r|   r~   r�   r/   rƒ   r„   r…   rT   rV   rŒ   r�   r&   r&   r&   r'   rg   £   sx   rg   )Ú	metaclassc                   @  sl   e Zd Zeejddœdd„ƒƒZeejddœdd„ƒƒZeejddœdd	„ƒƒZeejd
dœdd„ƒƒZ	dS )ÚRevokedCertificaterD   rI   c                 C  s   dS )zG
        Returns the serial number of the revoked certificate.
        Nr&   rJ   r&   r&   r'   rn   F  s    z RevokedCertificate.serial_numberr7   c                 C  s   dS )zH
        Returns the date of when this certificate was revoked.
        Nr&   rJ   r&   r&   r'   Úrevocation_dateM  s    z"RevokedCertificate.revocation_datec                 C  s   dS )zl
        Returns the date of when this certificate was revoked as a non-naive
        UTC datetime.
        Nr&   rJ   r&   r&   r'   Úrevocation_date_utcT  s    z&RevokedCertificate.revocation_date_utcr   c                 C  s   dS )zW
        Returns an Extensions object containing a list of Revoked extensions.
        Nr&   rJ   r&   r&   r'   r/   \  s    zRevokedCertificate.extensionsN)
r)   r*   r+   rW   rŽ   r�   rn   r’   r“   r/   r&   r&   r&   r'   r‘   E  s   r‘   c                   @  sf   e Zd Zddddœdd„Zeddœdd	„ƒZeddœd
d„ƒZeddœdd„ƒZeddœdd„ƒZdS )Ú_RawRevokedCertificaterD   r7   r   ©rn   r’   r/   c                 C  s   || _ || _|| _d S r    ©Ú_serial_numberÚ_revocation_dateÚ_extensions©r#   rn   r’   r/   r&   r&   r'   r"   i  s    z_RawRevokedCertificate.__init__rI   c                 C  s   | j S r    )r—   rJ   r&   r&   r'   rn   s  s    z$_RawRevokedCertificate.serial_numberc                 C  s   t jdtjdd� | jS )Nuk   Properties that return a naÃ¯ve datetime object have been deprecated. Please switch to revocation_date_utc.rb   )Ú
stacklevel)ÚwarningsÚwarnr   ZDeprecatedIn42r˜   rJ   r&   r&   r'   r’   w  s    üz&_RawRevokedCertificate.revocation_datec                 C  s   | j jtjjd�S )Nr:   )r˜   r?   r=   ÚtimezoneÚutcrJ   r&   r&   r'   r“   �  s    z*_RawRevokedCertificate.revocation_date_utcc                 C  s   | j S r    )r™   rJ   r&   r&   r'   r/   …  s    z!_RawRevokedCertificate.extensionsN)	r)   r*   r+   r"   rW   rn   r’   r“   r/   r&   r&   r&   r'   r”   h  s   
	r”   c                   @  sì  e Zd Zejdddœdd„ƒZejdddœdd	„ƒZejd
ddœdd„ƒZeejddœdd„ƒƒZ	eejddœdd„ƒƒZ
eejddœdd„ƒƒZeejddœdd„ƒƒZeejddœdd„ƒƒZeejddœdd „ƒƒZeejd!dœd"d#„ƒƒZeejd!dœd$d%„ƒƒZeejd&dœd'd(„ƒƒZeejddœd)d*„ƒƒZeejddœd+d,„ƒƒZejd-d.d/œd0d1„ƒZejd
dœd2d3„ƒZejd
d4d5œd6d7„ƒZejd8d9d5œd:d7„ƒZejd;d<d5œd=d7„ƒZejd>dœd?d@„ƒZejdAd.dBœdCdD„ƒZdES )FÚCertificateRevocationListrˆ   rC   r‰   c                 C  s   dS )z:
        Serializes the CRL to PEM or DER format.
        Nr&   r‹   r&   r&   r'   rŒ   ‹  s    z&CertificateRevocationList.public_bytesrh   ri   c                 C  s   dS rk   r&   rl   r&   r&   r'   rm   ‘  s    z%CertificateRevocationList.fingerprintrD   zRevokedCertificate | None)rn   r   c                 C  s   dS )zs
        Returns an instance of RevokedCertificate or None if the serial_number
        is not in the CRL.
        Nr&   )r#   rn   r&   r&   r'   Ú(get_revoked_certificate_by_serial_number—  s    zBCertificateRevocationList.get_revoked_certificate_by_serial_numberrz   rI   c                 C  s   dS r{   r&   rJ   r&   r&   r'   r|      s    z2CertificateRevocationList.signature_hash_algorithmr   c                 C  s   dS r}   r&   rJ   r&   r&   r'   r~   ª  s    z1CertificateRevocationList.signature_algorithm_oidr   c                 C  s   dS r€   r&   rJ   r&   r&   r'   r�   ±  s    z8CertificateRevocationList.signature_algorithm_parametersr   c                 C  s   dS )zC
        Returns the X509Name with the issuer of this CRL.
        Nr&   rJ   r&   r&   r'   rw   º  s    z CertificateRevocationList.issuerúdatetime.datetime | Nonec                 C  s   dS )z?
        Returns the date of next update for this CRL.
        Nr&   rJ   r&   r&   r'   Únext_updateÁ  s    z%CertificateRevocationList.next_updatec                 C  s   dS )zc
        Returns the date of next update for this CRL as a non-naive UTC
        datetime.
        Nr&   rJ   r&   r&   r'   Únext_update_utcÈ  s    z)CertificateRevocationList.next_update_utcr7   c                 C  s   dS )z?
        Returns the date of last update for this CRL.
        Nr&   rJ   r&   r&   r'   Úlast_updateÐ  s    z%CertificateRevocationList.last_updatec                 C  s   dS )zc
        Returns the date of last update for this CRL as a non-naive UTC
        datetime.
        Nr&   rJ   r&   r&   r'   Úlast_update_utc×  s    z)CertificateRevocationList.last_update_utcr   c                 C  s   dS )zS
        Returns an Extensions object containing a list of CRL extensions.
        Nr&   rJ   r&   r&   r'   r/   ß  s    z$CertificateRevocationList.extensionsc                 C  s   dS r‚   r&   rJ   r&   r&   r'   rƒ   æ  s    z#CertificateRevocationList.signaturec                 C  s   dS )zO
        Returns the tbsCertList payload bytes as defined in RFC 5280.
        Nr&   rJ   r&   r&   r'   Útbs_certlist_bytesí  s    z,CertificateRevocationList.tbs_certlist_bytesrM   rN   rO   c                 C  s   dS r†   r&   rS   r&   r&   r'   rT   ô  s    z CertificateRevocationList.__eq__c                 C  s   dS )z<
        Number of revoked certificates in the CRL.
        Nr&   rJ   r&   r&   r'   r^   ú  s    z!CertificateRevocationList.__len__r‘   )Úidxr   c                 C  s   d S r    r&   ©r#   r¨   r&   r&   r'   r`      s    z%CertificateRevocationList.__getitem__Úsliceúlist[RevokedCertificate]c                 C  s   d S r    r&   r©   r&   r&   r'   r`     s    zint | slicez-RevokedCertificate | list[RevokedCertificate]c                 C  s   dS )zS
        Returns a revoked certificate (or slice of revoked certificates).
        Nr&   r©   r&   r&   r'   r`     s    z#typing.Iterator[RevokedCertificate]c                 C  s   dS )z8
        Iterator over the revoked certificates
        Nr&   rJ   r&   r&   r'   r_     s    z"CertificateRevocationList.__iter__r   )rq   r   c                 C  s   dS )zQ
        Verifies signature of revocation list against given public key.
        Nr&   )r#   rq   r&   r&   r'   Úis_signature_valid  s    z,CertificateRevocationList.is_signature_validN)r)   r*   r+   rŽ   r�   rŒ   rm   r¡   rW   r|   r~   r�   rw   r£   r¤   r¥   r¦   r/   rƒ   r§   rT   r^   ÚtypingÚoverloadr`   r_   r¬   r&   r&   r&   r'   r    Š  sj   r    c                   @  sN  e Zd Zejdddœdd„ƒZejddœdd	„ƒZejd
dœdd„ƒZeejddœdd„ƒƒZ	eejddœdd„ƒƒZ
eejddœdd„ƒƒZeejddœdd„ƒƒZeejddœdd„ƒƒZeejddœdd„ƒƒZejdd d!œd"d#„ƒZeejd dœd$d%„ƒƒZeejd dœd&d'„ƒƒZeejddœd(d)„ƒƒZejdd d*œd+d,„ƒZd-S ).ÚCertificateSigningRequestrM   rN   rO   c                 C  s   dS r†   r&   rS   r&   r&   r'   rT   !  s    z CertificateSigningRequest.__eq__rD   rI   c                 C  s   dS r‡   r&   rJ   r&   r&   r'   rV   '  s    z"CertificateSigningRequest.__hash__r   c                 C  s   dS rp   r&   rJ   r&   r&   r'   rq   -  s    z$CertificateSigningRequest.public_keyr   c                 C  s   dS rx   r&   rJ   r&   r&   r'   ry   3  s    z!CertificateSigningRequest.subjectrz   c                 C  s   dS r{   r&   rJ   r&   r&   r'   r|   :  s    z2CertificateSigningRequest.signature_hash_algorithmr   c                 C  s   dS r}   r&   rJ   r&   r&   r'   r~   D  s    z1CertificateSigningRequest.signature_algorithm_oidr   c                 C  s   dS r€   r&   rJ   r&   r&   r'   r�   K  s    z8CertificateSigningRequest.signature_algorithm_parametersr   c                 C  s   dS )z@
        Returns the extensions in the signing request.
        Nr&   rJ   r&   r&   r'   r/   T  s    z$CertificateSigningRequest.extensionsrX   c                 C  s   dS )z/
        Returns an Attributes object.
        Nr&   rJ   r&   r&   r'   r4   [  s    z$CertificateSigningRequest.attributesrˆ   rC   r‰   c                 C  s   dS )z;
        Encodes the request to PEM or DER format.
        Nr&   r‹   r&   r&   r'   rŒ   b  s    z&CertificateSigningRequest.public_bytesc                 C  s   dS r‚   r&   rJ   r&   r&   r'   rƒ   h  s    z#CertificateSigningRequest.signaturec                 C  s   dS )zd
        Returns the PKCS#10 CertificationRequestInfo bytes as defined in RFC
        2986.
        Nr&   rJ   r&   r&   r'   Útbs_certrequest_byteso  s    z/CertificateSigningRequest.tbs_certrequest_bytesc                 C  s   dS )z8
        Verifies signature of signing request.
        Nr&   rJ   r&   r&   r'   r¬   w  s    z,CertificateSigningRequest.is_signature_validr[   c                 C  s   dS )z:
        Get the attribute value for a given OID.
        Nr&   )r#   r   r&   r&   r'   r]   ~  s    z/CertificateSigningRequest.get_attribute_for_oidN)r)   r*   r+   rŽ   r�   rT   rV   rq   rW   ry   r|   r~   r�   r/   r4   rŒ   rƒ   r°   r¬   r]   r&   r&   r&   r'   r¯      sJ   r¯   c                   @  s€   e Zd Zdg g fddddœdd„Zdd d	œd
d„Zddd dœdd„Zddœdddd dœdd„Zd!ddœddddddœdd „ZdS )"Ú CertificateSigningRequestBuilderNúName | Noner-   r3   )Úsubject_namer/   r4   c                 C  s   || _ || _|| _dS )zB
        Creates an empty X.509 certificate request (v1).
        N)Ú_subject_namer™   rZ   )r#   r³   r/   r4   r&   r&   r'   r"   –  s    	z)CertificateSigningRequestBuilder.__init__r   ©Únamer   c                 C  s4   t |tƒstdƒ‚| jdur$tdƒ‚t|| j| jƒS )zF
        Sets the certificate requestor's distinguished name.
        úExpecting x509.Name object.Nú&The subject name may only be set once.)rQ   r   Ú	TypeErrorr´   r0   r±   r™   rZ   ©r#   r¶   r&   r&   r'   r³   £  s    


ÿz-CertificateSigningRequestBuilder.subject_namer   rN   ©ÚextvalÚcriticalr   c                 C  sF   t |tƒstdƒ‚t|j||ƒ}t|| jƒ t| jg | j¢|‘| j	ƒS )zE
        Adds an X.509 extension to the certificate request.
        ú"extension must be an ExtensionType)
rQ   r   r¹   r   r   r2   r™   r±   r´   rZ   ©r#   r¼   r½   r.   r&   r&   r'   Úadd_extension¯  s    
ýz.CertificateSigningRequestBuilder.add_extension)Ú_tagr   rC   z_ASN1Type | None)r   rE   rÁ   r   c                C  s~   t |tƒstdƒ‚t |tƒs$tdƒ‚|dur>t |tƒs>tdƒ‚t|| jƒ |durZ|j}nd}t| j	| j
g | j¢|||f‘ƒS )zK
        Adds an X.509 attribute with an OID and associated value.
        zoid must be an ObjectIdentifierzvalue must be bytesNztag must be _ASN1Type)rQ   r   r¹   rC   r   r6   rZ   rE   r±   r´   r™   )r#   r   rE   rÁ   Útagr&   r&   r'   Úadd_attributeÁ  s    


ýz.CertificateSigningRequestBuilder.add_attribute©Úrsa_paddingr   ú_AllowedHashTypes | Noneú
typing.Anyú%padding.PSS | padding.PKCS1v15 | Noner¯   ©Úprivate_keyrj   ÚbackendrÅ   r   c                C  sX   | j du rtdƒ‚|durHt|tjtjfƒs4tdƒ‚t|tjƒsHtdƒ‚t	 
| |||¡S )zF
        Signs the request using the requestor's private key.
        Nz/A CertificateSigningRequest must have a subjectúPadding must be PSS or PKCS1v15ú&Padding is only supported for RSA keys)r´   r0   rQ   r   ÚPSSÚPKCS1v15r¹   r   ÚRSAPrivateKeyÚ	rust_x509Zcreate_x509_csr©r#   rÊ   rj   rË   rÅ   r&   r&   r'   Úsigná  s    
ÿz%CertificateSigningRequestBuilder.sign)N)r)   r*   r+   r"   r³   rÀ   rÃ   rÓ   r&   r&   r&   r'   r±   •  s   üû$ üúr±   c                
   @  sÒ   e Zd ZU ded< ddddddg fddddddddd	œd
d„Zdd dœdd„Zdd dœdd„Zdd dœdd„Zdd dœdd„Zdd dœdd„Z	dd dœdd„Z
d d!d d"œd#d$„Zd.dd%œd&d'd(d)d*d+œd,d-„ZdS )/ÚCertificateBuilderr-   r™   Nr²   z CertificatePublicKeyTypes | Noneú
int | Noner¢   r   )Úissuer_namer³   rq   rn   rs   ru   r/   r   c                 C  s6   t j| _|| _|| _|| _|| _|| _|| _|| _	d S r    )
ra   rd   Ú_versionÚ_issuer_namer´   Ú_public_keyr—   Ú_not_valid_beforeÚ_not_valid_afterr™   )r#   rÖ   r³   rq   rn   rs   ru   r/   r&   r&   r'   r"   ý  s    
zCertificateBuilder.__init__r   rµ   c                 C  sD   t |tƒstdƒ‚| jdur$tdƒ‚t|| j| j| j| j	| j
| jƒS )z3
        Sets the CA's distinguished name.
        r·   Nú%The issuer name may only be set once.)rQ   r   r¹   rØ   r0   rÔ   r´   rÙ   r—   rÚ   rÛ   r™   rº   r&   r&   r'   rÖ     s    

ùzCertificateBuilder.issuer_namec                 C  sD   t |tƒstdƒ‚| jdur$tdƒ‚t| j|| j| j| j	| j
| jƒS )z:
        Sets the requestor's distinguished name.
        r·   Nr¸   )rQ   r   r¹   r´   r0   rÔ   rØ   rÙ   r—   rÚ   rÛ   r™   rº   r&   r&   r'   r³   "  s    

ùzCertificateBuilder.subject_namer   )Úkeyr   c              	   C  s`   t |tjtjtjtjt	j
tjtjfƒs.tdƒ‚| jdur@tdƒ‚t| j| j|| j| j| j| jƒS )zT
        Sets the requestor's public key (as found in the signing request).
        z‰Expecting one of DSAPublicKey, RSAPublicKey, EllipticCurvePublicKey, Ed25519PublicKey, Ed448PublicKey, X25519PublicKey, or X448PublicKey.Nz$The public key may only be set once.)rQ   r   ZDSAPublicKeyr   ZRSAPublicKeyr   ZEllipticCurvePublicKeyr
   ZEd25519PublicKeyr	   ZEd448PublicKeyr   ZX25519PublicKeyr   ZX448PublicKeyr¹   rÙ   r0   rÔ   rØ   r´   r—   rÚ   rÛ   r™   )r#   rÝ   r&   r&   r'   rq   4  s2    ùþÿ
ùzCertificateBuilder.public_keyrD   ©Únumberr   c                 C  sh   t |tƒstdƒ‚| jdur$tdƒ‚|dkr4tdƒ‚| ¡ dkrHtdƒ‚t| j| j| j	|| j
| j| jƒS )z5
        Sets the certificate serial number.
        ú'Serial number must be of integral type.Nú'The serial number may only be set once.r   z%The serial number should be positive.é    ú3The serial number should not be more than 159 bits.)rQ   rD   r¹   r—   r0   Ú
bit_lengthrÔ   rØ   r´   rÙ   rÚ   rÛ   r™   ©r#   rß   r&   r&   r'   rn   Y  s&    

ÿùz CertificateBuilder.serial_numberr7   r8   c                 C  sz   t |tjƒstdƒ‚| jdur&tdƒ‚t|ƒ}|tk r>tdƒ‚| jdurZ|| jkrZtdƒ‚t| j	| j
| j| j|| j| jƒS )z7
        Sets the certificate activation time.
        úExpecting datetime object.Nz*The not valid before may only be set once.z>The not valid before date must be on or after 1950 January 1).zBThe not valid before date must be before the not valid after date.)rQ   r=   r¹   rÚ   r0   rA   Ú_EARLIEST_UTC_TIMErÛ   rÔ   rØ   r´   rÙ   r—   r™   ©r#   r9   r&   r&   r'   rs   t  s,    
ÿÿùz#CertificateBuilder.not_valid_beforec                 C  sz   t |tjƒstdƒ‚| jdur&tdƒ‚t|ƒ}|tk r>tdƒ‚| jdurZ|| jk rZtdƒ‚t| j	| j
| j| j| j|| jƒS )z7
        Sets the certificate expiration time.
        ræ   Nz)The not valid after may only be set once.z<The not valid after date must be on or after 1950 January 1.zAThe not valid after date must be after the not valid before date.)rQ   r=   r¹   rÛ   r0   rA   rç   rÚ   rÔ   rØ   r´   rÙ   r—   r™   rè   r&   r&   r'   ru   ‘  s2    
ÿÿþÿùz"CertificateBuilder.not_valid_afterr   rN   r»   c              	   C  sV   t |tƒstdƒ‚t|j||ƒ}t|| jƒ t| j| j	| j
| j| j| jg | j¢|‘ƒS )z=
        Adds an X.509 extension to the certificate.
        r¾   )rQ   r   r¹   r   r   r2   r™   rÔ   rØ   r´   rÙ   r—   rÚ   rÛ   r¿   r&   r&   r'   rÀ   ±  s    
ùz CertificateBuilder.add_extensionrÄ   r   rÆ   rÇ   rÈ   rg   rÉ   c                C  s²   | j du rtdƒ‚| jdu r$tdƒ‚| jdu r6tdƒ‚| jdu rHtdƒ‚| jdu rZtdƒ‚| jdu rltdƒ‚|dur¢t|tj	tj
fƒsŽtdƒ‚t|tjƒs¢td	ƒ‚t | |||¡S )
zC
        Signs the certificate using the CA's private key.
        Nz&A certificate must have a subject namez&A certificate must have an issuer namez'A certificate must have a serial numberz/A certificate must have a not valid before timez.A certificate must have a not valid after timez$A certificate must have a public keyrÌ   rÍ   )r´   r0   rØ   r—   rÚ   rÛ   rÙ   rQ   r   rÎ   rÏ   r¹   r   rÐ   rÑ   Zcreate_x509_certificaterÒ   r&   r&   r'   rÓ   Ç  s(    





ÿzCertificateBuilder.sign)N)r)   r*   r+   Ú__annotations__r"   rÖ   r³   rq   rn   rs   ru   rÀ   rÓ   r&   r&   r&   r'   rÔ   ú  s(   
ø%  üúrÔ   c                   @  s°   e Zd ZU ded< ded< dddg g fddddddœd	d
„Zdd dœdd„Zdd dœdd„Zdd dœdd„Zddd dœdd„Zdd dœdd„Z	d(ddœd d!d"d#d$d%œd&d'„Z
dS ))Ú CertificateRevocationListBuilderr-   r™   r«   Ú_revoked_certificatesNr²   r¢   )rÖ   r¥   r£   r/   Úrevoked_certificatesc                 C  s"   || _ || _|| _|| _|| _d S r    )rØ   Ú_last_updateÚ_next_updater™   rë   )r#   rÖ   r¥   r£   r/   rì   r&   r&   r'   r"   ó  s
    z)CertificateRevocationListBuilder.__init__r   )rÖ   r   c                 C  s<   t |tƒstdƒ‚| jd ur$tdƒ‚t|| j| j| j| j	ƒS )Nr·   rÜ   )
rQ   r   r¹   rØ   r0   rê   rí   rî   r™   rë   )r#   rÖ   r&   r&   r'   rÖ     s    

ûz,CertificateRevocationListBuilder.issuer_namer7   )r¥   r   c                 C  sr   t |tjƒstdƒ‚| jd ur&tdƒ‚t|ƒ}|tk r>tdƒ‚| jd urZ|| jkrZtdƒ‚t| j	|| j| j
| jƒS )Nræ   ú!Last update may only be set once.ú8The last update date must be on or after 1950 January 1.z9The last update date must be before the next update date.)rQ   r=   r¹   rí   r0   rA   rç   rî   rê   rØ   r™   rë   )r#   r¥   r&   r&   r'   r¥     s(    
ÿÿûz,CertificateRevocationListBuilder.last_update)r£   r   c                 C  sr   t |tjƒstdƒ‚| jd ur&tdƒ‚t|ƒ}|tk r>tdƒ‚| jd urZ|| jk rZtdƒ‚t| j	| j|| j
| jƒS )Nræ   rï   rð   z8The next update date must be after the last update date.)rQ   r=   r¹   rî   r0   rA   rç   rí   rê   rØ   r™   rë   )r#   r£   r&   r&   r'   r£   (  s(    
ÿÿûz,CertificateRevocationListBuilder.next_updater   rN   r»   c                 C  sN   t |tƒstdƒ‚t|j||ƒ}t|| jƒ t| j| j	| j
g | j¢|‘| jƒS )zM
        Adds an X.509 extension to the certificate revocation list.
        r¾   )rQ   r   r¹   r   r   r2   r™   rê   rØ   rí   rî   rë   r¿   r&   r&   r'   rÀ   @  s    
ûz.CertificateRevocationListBuilder.add_extensionr‘   )Úrevoked_certificater   c                 C  s4   t |tƒstdƒ‚t| j| j| j| jg | j¢|‘ƒS )z8
        Adds a revoked certificate to the CRL.
        z)Must be an instance of RevokedCertificate)	rQ   r‘   r¹   rê   rØ   rí   rî   r™   rë   )r#   rñ   r&   r&   r'   Úadd_revoked_certificateS  s    
ûz8CertificateRevocationListBuilder.add_revoked_certificaterÄ   r   rÆ   rÇ   rÈ   r    rÉ   c                C  s|   | j d u rtdƒ‚| jd u r$tdƒ‚| jd u r6tdƒ‚|d urlt|tjtjfƒsXtdƒ‚t|t	j
ƒsltdƒ‚t | |||¡S )NzA CRL must have an issuer namez"A CRL must have a last update timez"A CRL must have a next update timerÌ   rÍ   )rØ   r0   rí   rî   rQ   r   rÎ   rÏ   r¹   r   rÐ   rÑ   Zcreate_x509_crlrÒ   r&   r&   r'   rÓ   d  s    


ÿz%CertificateRevocationListBuilder.sign)N)r)   r*   r+   ré   r"   rÖ   r¥   r£   rÀ   rò   rÓ   r&   r&   r&   r'   rê   ï  s"   
ú üúrê   c                   @  sj   e Zd Zddg fddddœdd„Zdd d	œd
d„Zdd dœdd„Zddd dœdd„Zddddœdd„ZdS )ÚRevokedCertificateBuilderNrÕ   r¢   r-   r•   c                 C  s   || _ || _|| _d S r    r–   rš   r&   r&   r'   r"   �  s    z"RevokedCertificateBuilder.__init__rD   rÞ   c                 C  sX   t |tƒstdƒ‚| jd ur$tdƒ‚|dkr4tdƒ‚| ¡ dkrHtdƒ‚t|| j| jƒS )Nrà   rá   r   z$The serial number should be positiverâ   rã   )	rQ   rD   r¹   r—   r0   rä   ró   r˜   r™   rå   r&   r&   r'   rn   ‹  s    

ÿ
ÿz'RevokedCertificateBuilder.serial_numberr7   r8   c                 C  sN   t |tjƒstdƒ‚| jd ur&tdƒ‚t|ƒ}|tk r>tdƒ‚t| j|| j	ƒS )Nræ   z)The revocation date may only be set once.z7The revocation date must be on or after 1950 January 1.)
rQ   r=   r¹   r˜   r0   rA   rç   ró   r—   r™   rè   r&   r&   r'   r’   �  s    
ÿ
ÿz)RevokedCertificateBuilder.revocation_dater   rN   r»   c                 C  sF   t |tƒstdƒ‚t|j||ƒ}t|| jƒ t| j| j	g | j¢|‘ƒS )Nr¾   )
rQ   r   r¹   r   r   r2   r™   ró   r—   r˜   r¿   r&   r&   r'   rÀ   ­  s    
ýz'RevokedCertificateBuilder.add_extensionrÇ   r‘   )rË   r   c                 C  s:   | j d u rtdƒ‚| jd u r$tdƒ‚t| j | jt| jƒƒS )Nz/A revoked certificate must have a serial numberz1A revoked certificate must have a revocation date)r—   r0   r˜   r”   r   r™   )r#   rË   r&   r&   r'   Úbuild»  s    

ÿýzRevokedCertificateBuilder.build)N)r)   r*   r+   r"   rn   r’   rÀ   rô   r&   r&   r&   r'   ró   €  s   ü
ró   rD   rI   c                   C  s   t  t d¡d¡d? S )Né   Úbigr   )rD   Ú
from_bytesÚosÚurandomr&   r&   r&   r'   Úrandom_serial_numberÉ  s    rú   )NÚ
__future__r   rŽ   r=   rø   r­   rœ   Zcryptographyr   Z"cryptography.hazmat.bindings._rustr   rÑ   Zcryptography.hazmat.primitivesr   r   Z)cryptography.hazmat.primitives.asymmetricr   r   r	   r
   r   r   r   r   Z/cryptography.hazmat.primitives.asymmetric.typesr   r   r   Zcryptography.x509.extensionsr   r   r   r   Zcryptography.x509.namer   r   Zcryptography.x509.oidr   rç   ÚUnionÚSHA224ÚSHA256ÚSHA384ÚSHA512ZSHA3_224ZSHA3_256ZSHA3_384ZSHA3_512Z_AllowedHashTypesÚ	Exceptionr   r2   r6   rA   rB   rX   ÚEnumra   re   ÚABCMetarg   Úregisterr‘   r”   r    r¯   Zload_pem_x509_certificateZload_der_x509_certificateZload_pem_x509_certificatesZload_pem_x509_csrZload_der_x509_csrZload_pem_x509_crlZload_der_x509_crlr±   rÔ   rê   ró   rú   r&   r&   r&   r'   Ú<module>   st   (
ùÿ

$   " fe v I