Ë
    M/Åe¥H  ã                   ó’  — d Z ddlZddlZddlZddlZddlmZ ddlmZ ddlmZ ddlm	Z	 ddlm
Z
 ddlmZ dd	lmZ dd
lmZ ddlZddlmZ ddlmZ ddlmZ ddlmZ ddlmZ ddlmZ ddlmZ ddlmZ  ej6                  e«      Zdej<                  ddfd„Zdej<                  ddfd„Z dej<                  ddfd„Z!dej<                  ddfd„Z"dej<                  de#de
ejH                     fd„Z%dej<                  de#de
e	e#      fd„Z&dej<                  de	e#   dee
ejH                     e
ejH                     f   fd„Z'dejH                  de#de
e	e#      fd „Z(de	eeejH                  ge#f   eejH                  ge
e	e#      f   f      fd!„Z)dej<                  de#fd"„Z*dej<                  d#eeeejH                  ge#f   eejH                  ge
e	e#      f   f      d$eejH                  ge#f   d%eejH                  ge#f   de	e#   f
d&„Z+	 d:dej<                  d'ejH                  d(e,de
e#   fd)„Z-	 	 d;dej<                  d*e#d+e,d,e
e#   de	e#   f
d-„Z.d.ee#   de#fd/„Z/dej<                  d0eejH                     de#fd1„Z0dej<                  d0eejH                     d2ee#   ddfd3„Z1 ed4«      Z2dej<                  d5ed6e2f   d7e2d8ede2f
d9„Z3y)<z Tools for managing certificates.é    N)ÚAny)ÚCallable)ÚIterable)ÚList)ÚOptional)ÚTuple)ÚTypeVar)ÚUnion)Úconfiguration)Úcrypto_util)Úerrors)Úocsp)Úutil)Ústorage)ÚosÚconfigÚreturnc                 óh   — t        j                  | «      D ]  }t        j                  || d¬«       Œ y)aj  Update the certificate file family symlinks to use archive_dir.

    Use the information in the config file to make symlinks point to
    the correct archive directory.

    .. note:: This assumes that the installation is using a Reverter object.

    :param config: Configuration.
    :type config: :class:`certbot._internal.configuration.NamespaceConfig`

    T)Úupdate_symlinksN)r   Úrenewal_conf_filesÚRenewableCert)r   Úrenewal_files     ú@/usr/lib/python3/dist-packages/certbot/_internal/cert_manager.pyÚupdate_live_symlinksr   !   s2   € ô  ×2Ñ2°6Ó:ò JˆÜ×Ñ˜l¨FÀDÖIñJó    c                 óÄ  — t        | d«      d   }| j                  }|sSt        j                  dj	                  |«      d¬«      \  }}|t        j
                  k7  s|st        j                  d«      ‚t        | |«      }|s$t        j                  dj	                  |«      «      ‚t        j                  ||| «       t        j                  dj	                  ||«      d	¬
«       y)z¡Rename the specified lineage to the new name.

    :param config: Configuration.
    :type config: :class:`certbot._internal.configuration.NamespaceConfig`

    Úrenamer   z&Enter the new name for certificate {0}T)Úforce_interactiveúUser ended interaction.z,No existing certificate with name {0} found.z Successfully renamed {0} to {1}.F)ÚpauseN)Úget_certnamesÚnew_certnameÚdisplay_utilÚ
input_textÚformatÚOKr   ÚErrorÚlineage_for_certnameÚConfigurationErrorr   Úrename_renewal_configÚnotification)r   Úcertnamer"   ÚcodeÚlineages        r   Úrename_lineager/   1   sÌ   € ô ˜V XÓ.¨qÑ1€Hà×&Ñ&€LÙÜ)×4Ñ4Ø4×;Ñ;¸HÓEØ"ô$Ñˆˆlð ”<—?‘?Ò"©,Ü—,‘,Ð8Ó9Ð9ä" 6¨8Ó4€GÙÜ×'Ñ'ð )ß™ Ó)ó+ð 	+ä×!Ñ! (¨L¸&ÔAÜ×ÑÐ@ß"(¡&¨°<Ó"@ÈöOr   c                 ó   — g }g }t        j                  | «      D ]?  }	 t        j                  || «      }t        j                  |«       |j                  |«       ŒA t        | ||«       y# t        $ rZ}t        j                  d||«       t        j                  dt        j                  «       «       |j                  |«       Y d}~Œ®d}~ww xY w)zªDisplay information about certs configured with Certbot

    :param config: Configuration.
    :type config: :class:`certbot._internal.configuration.NamespaceConfig`
    zIRenewal configuration file %s produced an unexpected error: %s. Skipping.úTraceback was:
%sN)r   r   r   r   Úverify_renewable_certÚappendÚ	ExceptionÚloggerÚwarningÚdebugÚ	tracebackÚ
format_excÚ_describe_certs)r   Úparsed_certsÚparse_failuresr   Úrenewal_candidateÚes         r   Úcertificatesr?   K   s¾   € ð €LØ€NÜ×2Ñ2°6Ó:ò 	0ˆð	0Ü '× 5Ñ 5°lÀFÓ KÐÜ×-Ñ-Ð.?Ô@Ø×ÑÐ 1Õ2ð		0ô �F˜L¨.Õ9øô ò 	0Ü�N‰Nð =Ø>JÈAôOä�L‰LÐ-¬y×/CÑ/CÓ/EÔFØ×!Ñ! ,×/Ñ/ûð		0ús   ž<A*Á*	CÁ3ACÃCc                 óš  — t        | dd¬«      }dg}|D ]  }|j                  d|z   «       Œ |j                  d«       |j                  d«       t        j                  dj	                  |«      d¬	«      st
        j                  d
«       y|D ]<  }t        j                  | |«       t        j                  dj                  |«      «       Œ> y)z;Delete Certbot files associated with a certificate lineage.ÚdeleteT)Úallow_multiplez8The following certificate(s) are selected for deletion:
z  * aP  
WARNING: Before continuing, ensure that the listed certificates are not being used by any installed server software (e.g. Apache, nginx, mail servers). Deleting a certificate that is still being used will cause the server software to stop working. See https://certbot.org/deleting-certs for information on deleting certificates safely.z:
Are you sure you want to delete the above certificate(s)?ú
)Údefaultz$Deletion of certificate(s) canceled.Nz.Deleted all files relating to certificate {0}.)r!   r3   r#   ÚyesnoÚjoinr5   Úinfor   Údelete_filesÚnotifyr%   )r   Ú	certnamesÚmsgr,   s       r   rA   rA   b   s»   € ä˜f h¸tÔD€IØFÐ
G€CØò &ˆØ�
‰
�6˜HÑ$Õ%ð&à‡J�Jð	bôð ‡J�JÐLÔMÜ×Ñ˜dŸi™i¨›n°dÕ;Ü�‰Ð:Ô;ØØò /ˆÜ×Ñ˜V XÔ.Ü×ÑÐLß#™V HÓ-õ	/ñ/r   Ú
cli_configr,   c                 ó�  — | j                   }t        j                  |d¬«       	 t        j                  | |«      }	 t        j                  || «      S # t
        j                  $ r Y yw xY w# t
        j                  t        f$ rA t        j                  d|«       t        j                  dt        j                  «       «       Y yw xY w)z)Find a lineage object with name certname.éí  ©ÚmodeNzRenewal conf file %s is broken.r1   )Úrenewal_configs_dirr   Úmake_or_verify_dirr   Úrenewal_file_for_certnamer   ÚCertStorageErrorr   ÚIOErrorr5   r7   r8   r9   )rL   r,   Úconfigs_dirr   s       r   r(   r(   |   s­   € ð ×0Ñ0€Kä×Ñ˜K¨eÕ4ðÜ×8Ñ8¸ÀXÓNˆðÜ×$Ñ$ \°:Ó>Ð>øô ×"Ñ"ò Ùðûô ×#Ñ#¤WÐ-ò Ü�‰Ð6¸ÔEÜ�‰Ð)¬9×+?Ñ+?Ó+AÔBÙðús#   ¥A ¼A+ ÁA(Á'A(Á+ACÃCc                 óB   — t        | |«      }|r|j                  «       S dS )z0Find the domains in the cert with name certname.N)r(   Únames)r   r,   r.   s      r   Údomains_for_certnamerY   Ž   s#   € ô # 6¨8Ó4€GÙ%ˆ7�=‰=‹?Ð/¨4Ð/r   Údomainsc           	      ó"  ‡— dt         j                  dt        t        t         j                     t        t         j                     f   dt        t        t         j                     t        t         j                     f   fˆfd„}d}t	        | ||«      S )aˆ  Find existing certs that match the given domain names.

    This function searches for certificates whose domains are equal to
    the `domains` parameter and certificates whose domains are a subset
    of the domains in the `domains` parameter. If multiple certificates
    are found whose names are a subset of `domains`, the one whose names
    are the largest subset of `domains` is returned.

    If multiple certificates' domains are an exact match or equally
    sized subsets, which matching certificates are returned is
    undefined.

    :param config: Configuration.
    :type config: :class:`certbot._internal.configuration.NamespaceConfig`
    :param domains: List of domain names
    :type domains: `list` of `str`

    :returns: lineages representing the identically matching cert and the
        largest subset if they exist
    :rtype: `tuple` of `storage.RenewableCert` or `None`

    Úcandidate_lineageÚrvr   c                 ó  •— |\  }}t        | j                  «       «      }|t        ‰«      k(  r| }||fS |j                  t        ‰«      «      r/|€| }||fS t        |«      t        |j                  «       «      kD  r| }||fS )zsReturn cert as identical_names_cert if it matches,
           or subset_names_cert if it matches as subset
        )ÚsetrX   ÚissubsetÚlen)r\   r]   Úidentical_names_certÚsubset_names_certÚcandidate_namesrZ   s        €r   Úupdate_certs_for_domain_matchesz?find_duplicative_certs.<locals>.update_certs_for_domain_matches®   s¥   ø€ ð 35Ñ/ÐÐ/ÜÐ/×5Ñ5Ó7Ó8ˆØœc '›lÒ*Ø#4Ð ð %Ð&7Ð8Ð8ð ×%Ñ%¤c¨'£lÔ3ð !Ð(Ø$5Ð!ð %Ð&7Ð8Ð8ô �_Ó%¬Ð,=×,CÑ,CÓ,EÓ(FÒFØ$5Ð!Ø$Ð&7Ð8Ð8r   )NN)r   r   r   r   Ú_search_lineages)r   rZ   re   Úinits    `  r   Úfind_duplicative_certsrh   •   sŽ   ø€ ð29¼7×;PÑ;Pð 9Ü,1´(¼7×;PÑ;PÑ2QÜ2:¼7×;PÑ;PÑ2Qð3Rñ -Sð9ô .3´8¼G×<QÑ<QÑ3RÜ3;¼G×<QÑ<QÑ3Rð4Sñ .Tõ9ð. Ua€Dä˜FÐ$CÀTÓJÐJr   r\   Úfiletypec                 óø   — | j                   }t        j                  |«      D �cg c]G  }t        j                  dj                  |«      |«      r t        j                  j                  ||«      ‘ŒI }}|r|S yc c}w )aJ   In order to match things like:
        /etc/letsencrypt/archive/example.com/chain1.pem.

        Anonymous functions which call this function are eventually passed (in a list) to
        `match_and_check_overlaps` to help specify the acceptable_matches.

        :param `.storage.RenewableCert` candidate_lineage: Lineage whose archive dir is to
            be searched.
        :param str filetype: main file name prefix e.g. "fullchain" or "chain".

        :returns: Files in candidate_lineage's archive dir that match the provided filetype.
        :rtype: list of str or None
    z{0}[0-9]*.pemN)Úarchive_dirr   ÚlistdirÚreÚmatchr%   ÚpathrF   )r\   ri   rk   ÚfÚpatterns        r   Ú_archive_filesrr   Ê   sp   € ð $×/Ñ/€KÜ57·Z±ZÀÓ5Lö F°Ü—x‘x × 6Ñ 6°xÓ @À!ÔDô �w‰w�|‰|˜K¨Õ+ð F€Gð FáØˆØùò	Fs   ¤AA7c                  ó   — d„ d„ d„ d„ gS )zª Generates the list that's passed to match_and_check_overlaps. Is its own function to
    make unit testing easier.

    :returns: list of functions
    :rtype: list
    c                 ó   — | j                   S ©N)Úfullchain_path©Úxs    r   ú<lambda>z%_acceptable_matches.<locals>.<lambda>è   s   € �a×&Ñ&€ r   c                 ó   — | j                   S ru   ©Ú	cert_pathrw   s    r   ry   z%_acceptable_matches.<locals>.<lambda>è   s
   € °!·+±+€ r   c                 ó   — t        | d«      S )NÚcert©rr   rw   s    r   ry   z%_acceptable_matches.<locals>.<lambda>é   s   € ”n Q¨Ó/€ r   c                 ó   — t        | d«      S )NÚ	fullchainr   rw   s    r   ry   z%_acceptable_matches.<locals>.<lambda>é   s   € ¼>È!È[Ó;Y€ r   © r‚   r   r   Ú_acceptable_matchesrƒ   à   s   € ñ 'Ñ(=Ù/Ñ1Yð[ð [r   c                 óF   ‡ — t        «       }t        ‰ |ˆ fd„d„ «      }|d   S )a“   If config.cert_path is defined, try to find an appropriate value for config.certname.

    :param `configuration.NamespaceConfig` cli_config: parsed command line arguments

    :returns: a lineage name
    :rtype: str

    :raises `errors.Error`: If the specified cert path can't be matched to a lineage name.
    :raises `errors.OverlappingMatchFound`: If the matched lineage's archive is shared.
    c                 ó   •— ‰j                   S ru   r{   )rx   rL   s    €r   ry   z&cert_path_to_lineage.<locals>.<lambda>ù   s   ø€ ¨z×/CÑ/C€ r   c                 ó   — | j                   S ru   )Úlineagenamerw   s    r   ry   z&cert_path_to_lineage.<locals>.<lambda>ù   s
   € ÈqÏ}É}€ r   r   )rƒ   Úmatch_and_check_overlaps)rL   Úacceptable_matchesrn   s   `  r   Úcert_path_to_lineagerŠ   ì   s-   ø€ ô -Ó.ÐÜ$ ZÐ1CÛ%CÑE\ó^€Eà�‰8€Or   r‰   Ú
match_funcÚrv_funcc                 óÆ  ‡‡— dt         j                  dt        t           dt        t
        t        t         j                  gt        f   t        t         j                  gt        t        t              f   f      dt        t           fˆˆfd„}t        | |g |«      }|s#t        j                  d| j                  › d�«      ‚t        |«      dkD  rt        j                  «       ‚|S )	a   Searches through all lineages for a match, and checks for duplicates.
    If a duplicate is found, an error is raised, as performing operations on lineages
    that have their properties incorrectly duplicated elsewhere is probably a bad idea.

    :param `configuration.NamespaceConfig` cli_config: parsed command line arguments
    :param list acceptable_matches: a list of functions that specify acceptable matches
    :param function match_func: specifies what to match
    :param function rv_func: specifies what to return

    r\   Úreturn_valuer‰   r   c                 óè   •— |D �cg c]
  } || «      ‘Œ }}g }|D ],  }t        |t        «      r||z  }Œ|sŒ|j                  |«       Œ.  ‰| «      }||v r|j                   ‰	| «      «       |S c c}w )z1Returns a list of matches using _search_lineages.)Ú
isinstanceÚlistr3   )
r\   rŽ   r‰   ÚfuncÚacceptable_matches_resolvedÚacceptable_matches_rvÚitemrn   r‹   rŒ   s
           €€r   Úfind_matchesz.match_and_check_overlaps.<locals>.find_matches  s’   ø€ ð
 L^Ö&^À4¡tÐ,=Õ'>Ð&^Ð#Ð&^Ø+-ÐØ/ò 	3ˆDÜ˜$¤Ô%Ø%¨Ñ-Ñ%ÚØ%×,Ñ,¨TÕ2ð		3ñ
 Ð,Ó-ˆØÐ)Ñ)Ø×Ñ¡Ð(9Ó :Ô;ØÐùò '_s   †A/zNo match found for cert-path ú!é   )r   r   r   Ústrr   r
   r   r   rf   r   r'   r|   ra   ÚOverlappingMatchFound)rL   r‰   r‹   rŒ   r–   Úmatcheds     ``  r   rˆ   rˆ   ý   sÛ   ù€ ð ¬×(=Ñ(=ð ÌTÔRUÉYð Ü)1´%Ü!¤7×#8Ñ#8Ð"9¼3Ð">Ñ?Ü!¤7×#8Ñ#8Ð"9¼8ÄDÌÁIÑ;NÐ"NÑOðPñ3Qñ *Rðô W[Ô[^ÑV_öô" *¨*°lÀBÐHZÓ[€GÙÜ�l‰lÐ:¸:×;OÑ;OÐ:PÐPQÐRÓSÐSÜ	ˆW‹˜Ò	Ü×*Ñ*Ó,Ð,Ø€Nr   r~   Úskip_filter_checksc                 ór  — g }t        j                  «       }| j                  r|j                  | j                  k7  r|sy| j                  r3t        | j                  «      j                  |j                  «       «      syt        j                  j                  t        j                  «      }g }|j                  r|j                  d«       |j                  |k  r|j                  d«       n"|j                  |«      r|j                  d«       |rddj!                  |«      z   }nT|j                  |z
  }|j"                  dk(  rd}n3|j"                  dk  rd	|j$                  d
z  › d�}nd	|j"                  › d�}dj'                  |j                  |«      }	t'        t)        j*                  |j,                  «      d«      }
|j                  d|j                  › d|
› d|j.                  › ddj!                  |j                  «       «      › d|	› d|j0                  › d|j2                  › �«       dj!                  |«      S )zJ Returns a human readable description of info about a RenewableCert objectNÚ	TEST_CERTÚEXPIREDÚREVOKEDz	INVALID: z, r˜   zVALID: 1 dayzVALID: i  z hour(s)z daysz	{0} ({1})rx   z  Certificate Name: z
    Serial Number: z
    Key Type: z
    Domains: ú z
    Expiry Date: z
    Certificate Path: z
    Private Key Path: Ú )r   ÚRevocationCheckerr,   r‡   rZ   r_   r`   rX   ÚdatetimeÚnowÚpytzÚUTCÚis_test_certr3   Útarget_expiryÚocsp_revokedrF   ÚdaysÚsecondsr%   r   Úget_serial_from_certr|   Úprivate_key_typer�   Úprivkey)r   r~   rœ   ÚcertinfoÚcheckerr¥   ÚreasonsÚstatusÚdiffÚvalid_stringÚserials              r   Úhuman_readable_cert_infor·   &  sí  € ð €HÜ×$Ñ$Ó&€Gà‡‚˜4×+Ñ+¨v¯©Ò>ÑGYØØ‡~‚~œc &§.¡.Ó1×:Ñ:¸4¿:¹:»<ÔHØÜ
×
Ñ
×
Ñ
¤§¡Ó
)€Cà€GØ×ÒØ�‰�{Ô#Ø×Ñ˜SÒ Ø�‰�yÕ!Ø	×	Ñ	˜dÔ	#Ø�‰�yÔ!áØ˜tŸy™y¨Ó1Ñ1‰à×!Ñ! CÑ'ˆØ�9‰9˜Š>Ø#‰FØ�Y‰Y˜Š]Ø˜tŸ|™|¨tÑ3Ð4°HÐ=‰Fà˜tŸy™y˜k¨Ð/ˆFà×%Ñ% d×&8Ñ&8¸&ÓA€LÜ”K×4Ñ4°T·^±^ÓDÀcÓJ€FØ‡O�OÐ*¨4×+;Ñ+;Ð*<ð =*Ø*0¨ð 2%Ø%)×%:Ñ%:Ð$;ð <$Ø$'§H¡H¨T¯Z©Z«\Ó$:Ð#;ð <(Ø(4 ~ð 6-Ø-1¯^©^Ð,<ð =-Ø-1¯\©\¨Nð<ô =ð �7‰7�8ÓÐr   ÚverbrB   Úcustom_promptc                 ó|  — | j                   }|r|g}|S t        j                  | «      }|D �cg c]  }t        j                  |«      ‘Œ }}|st	        j
                  d«      ‚|r\|sdj                  |«      }	n|}	t        j                  |	|dd¬«      \  }
}|
t        j                  k7  rt	        j
                  d«      ‚|S |sdj                  |«      }	n|}	t        j                  |	|dd¬«      \  }
}|
t        j                  k7  s|t        dt        |«      «      vrt	        j
                  d«      ‚||   g}|S c c}w )	z4Get certname from flag, interactively, or error out.zNo existing certificates found.z+Which certificate(s) would you like to {0}?z--cert-nameT)Úcli_flagr   r   z(Which certificate would you like to {0}?r   )r,   r   r   Úlineagename_for_filenamer   r'   r%   r#   Ú	checklistr&   ÚmenuÚrangera   )r   r¸   rB   r¹   r,   rJ   Ú	filenamesÚnameÚchoicesÚpromptr-   Úindexs               r   r!   r!   Q  s?  € ð �‰€HÙØ�Jˆ	ð6 Ðô3 ×.Ñ.¨vÓ6ˆ	ØFOÖP¸d”7×3Ñ3°DÕ9ÐPˆÐPÙÜ—,‘,Ð@ÓAÐAÙÙ ØF×MÑMÈdÓS‘à&�Ü*×4Ñ4Ø˜¨-È4ôQ‰OˆD�)à”|—‘Ò&Ü—l‘lÐ#<Ó=Ð=ð Ðñ !ØC×JÑJÈ4ÓP‘à&�ä&×+Ñ+Ø˜¨-È4ôQ‰KˆD�%ð ”|—‘Ò&¨%´u¸QÄÀGÃÓ7MÑ*MÜ—l‘lÐ#<Ó=Ð=Ø  ™Ð(ˆIØÐùò1 Qs   ­D9Úmsgsc                 ó8   — ddj                  d„ | D «       «      z   S )zFFormat a results report for a category of single-line renewal outcomesz  z
  c              3   ó2   K  — | ]  }t        |«      –— Œ y ­wru   )r™   )Ú.0rK   s     r   ú	<genexpr>z _report_lines.<locals>.<genexpr>z  s   è ø€ Ò7¨3œc #ŸhÑ7ùs   ‚)rF   )rÅ   s    r   Ú_report_linesrÊ   x  s   € à�&—+‘+Ñ7°$Ô7Ó7Ñ7Ð7r   r;   c                 óv   — g }|D ]"  }t        | |«      }|€Œ|j                  |«       Œ$ dj                  |«      S )z)Format a results report for a parsed certrC   )r·   r3   rF   )r   r;   r°   r~   Ú	cert_infos        r   Ú_report_human_readablerÍ   }  sG   € ð €HØò 'ˆÜ,¨V°TÓ:ˆ	ØÑ Ø�O‰O˜IÕ&ð'ð �9‰9�XÓÐr   r<   c                 óL  — g }|j                   }|s|s	 |d«       nb|rE| j                  s| j                  rdnd} |dj                  |«      «        |t	        | |«      «       |r |d«        |t        |«      «       t        j                  dj                  |«      dd¬«       y	)
z/Print information about the certs we know aboutzNo certificates found.z	matching r¢   zFound the following {0}certs:z3
The following renewal configurations were invalid:rC   F)r    ÚwrapN)	r3   r,   rZ   r%   rÍ   rÊ   r#   r+   rF   )r   r;   r<   ÚoutrI   rn   s         r   r:   r:   ˆ  s‘   € ð €Cà�Z‰Z€Fá¡ÙÐ'Õ(áØ#)§?¢?°f·n²n‘KÈ"ˆEÙÐ2×9Ñ9¸%Ó@ÔAÙÔ)¨&°,Ó?Ô@ÙÙð ô  á”= Ó0Ô1ä×Ñ˜dŸi™i¨›n°EÀÖFr   ÚTr’   .Ú
initial_rvÚargsc                 ó€  — | j                   }t        j                  |d¬«       |}t        j                  | «      D ]#  }	 t        j
                  || «      } |||g|¢­Ž }Œ% |S # t        j                  t        f$ rA t        j                  d|«       t        j                  dt        j                  «       «       Y Œ�w xY w)aâ  Iterate func over unbroken lineages, allowing custom return conditions.

    Allows flexible customization of return values, including multiple
    return values and complex checks.

    :param `configuration.NamespaceConfig` cli_config: parsed command line arguments
    :param function func: function used while searching over lineages
    :param initial_rv: initial return value of the function (any type)

    :returns: Whatever was specified by `func` if a match is found.
    rN   rO   z)Renewal conf file %s is broken. Skipping.r1   )rQ   r   rR   r   r   r   r   rT   rU   r5   r7   r8   r9   )rL   r’   rÒ   rÓ   rV   r]   r   r\   s           r   rf   rf   ¡  s·   € ð ×0Ñ0€Kä×Ñ˜K¨eÕ4à	€BÜ×2Ñ2°:Ó>ò 0ˆð	Ü '× 5Ñ 5°lÀJÓ OÐñ
 Ð# RÐ/¨$Ò/‰ð0ð €Iøô ×'Ñ'¬Ð1ò 	Ü�L‰LÐDÀlÔSÜ�L‰LÐ-¬y×/CÑ/CÓ/EÔFÙð	ús   ¿A#Á#AB=Â<B=)F)FN)4Ú__doc__r¤   Úloggingrm   r8   Útypingr   r   r   r   r   r   r	   r
   r¦   Úcertbotr   r   r   r   r   Úcertbot._internalr   Úcertbot.compatr   Úcertbot.displayr#   Ú	getLoggerÚ__name__r5   ÚNamespaceConfigr   r/   r?   rA   r™   r   r(   rY   rh   rr   rƒ   rŠ   rˆ   Úboolr·   r!   rÊ   rÍ   r:   rÑ   rf   r‚   r   r   ú<module>rà      s  ðÙ &Û Û Û 	Û Ý Ý Ý Ý Ý Ý Ý Ý ã å !Ý Ý Ý Ý Ý %Ý Ý 0à	ˆ×	Ñ	˜8Ó	$€ðJ ×!>Ñ!>ð JÀ4ó Jð O˜=×8Ñ8ð O¸Tó Oð4:˜×6Ñ6ð :¸4ó :ð./�=×0Ñ0ð /°Tó /ð4 ]×%BÑ%Bð Ø#&ðØ+3°G×4IÑ4IÑ+Jóð$0 ×!>Ñ!>ð 0Ø#&ð0Ø+3°D¸±IÑ+>ó0ð2K =×#@Ñ#@ð 2KØ$(¨¡Ið2KØ27¸À×AVÑAVÑ8WØ8@À×AVÑAVÑ8Wð9Xñ 3Yó2Kðj g×&;Ñ&;ð Àsð ÈxÐX\Ð]`ÑXaÑObó ð,	[˜T %¨°'×2GÑ2GÐ1HÈ#Ð1MÑ(NØ(0°'×2GÑ2GÐ1HÈ(ÐSWÐX[ÑS\ÑJ]Ð1]Ñ(^ð)_ñ #`ñ aó 	[ð ]×%BÑ%Bð Àsó ð"&¨×)FÑ)Fð &Ø19¸%Ø!)¨7×+@Ñ+@Ð*AÀ3Ð*FÑ!GØ!)¨7×+@Ñ+@Ð*AÀ8ÈDÐQTÉIÑCVÐ*VÑ!Wð"Xñ;Yñ 2Zð&ð *2°7×3HÑ3HÐ2IÈ3Ð2NÑ)Oð	&ð
 '/°×0EÑ0EÐ/FÈÐ/KÑ&Lð&ð
 RVÐVYÑQZó&ðT 9>ñ( ]×%BÑ%Bð (È'×J_ÑJ_ð (Ø15ð(ØBJÈ3Á-ó(ðV \aØ15ñ ˜-×7Ñ7ð  ¸sð  ÐTXð  Ø!)¨#¡ð Ø:>¸s¹)ó ðN8˜ ™ð 8¨#ó 8ð
 =×#@Ñ#@ð Ø)1°'×2GÑ2GÑ)HðØMPóðG˜M×9Ñ9ð GØ"*¨7×+@Ñ+@Ñ"AðGà$,¨S¡MðGà6:óGñ. ˆCƒL€ð ×!>Ñ!>ð ÀhÈsÐTUÈvÑFVð Ø!"ðØ+.ðØ34ôr   