Ë
    M/Åe¾.  ã                   ód  — d Z ddlZddlmZ ddlmZ ddlmZ ddlmZ ddlmZ ddlmZ dd	lm	Z	 dd
l
mZ ddlmZ ddlmZ ddlmZ ddlmZ ddlmZ ddlmZ ddlmZ ddlmZ ddlmZ ddlmZ ddlmZ ddlmZ  ej>                  e «      Z! G d„ dejD                  ejF                  «      Z#y)zManual authenticator pluginé    N)ÚAny)ÚCallable)ÚDict)ÚIterable)ÚList)ÚTuple)ÚType)Ú
challenges)Úachallenges)Úerrors)Ú
interfaces)Úreverter)Úutil)Úhooks)Úcli_constants)Úmisc)Úos)Úops)Úcommonc                   óà  ‡ — e Zd ZdZdZdZdZdZdZdZ	dZ
d	Zd
ededdfˆ fd„Zeded   ddfd„«       Zd#d„Zd#d„Zdefd„Zdeej.                     defd„Zdedeeej6                        fd„Zdeej.                     deej<                     fd„Zdej.                  deej.                     ddfd„Z 	 d$dej.                  de!ddfd„Z"deej.                     ddfd„Z#d ed!ede$eef   fd"„Z%ˆ xZ&S )%ÚAuthenticatorzÔManual authenticator

    This plugin allows the user to perform the domain validation
    challenge(s) themselves. This either be done manually by the user or
    through shell scripts provided to Certbot.

    z2Manual configuration or run your own shell scriptsTaš  Authenticate through manual configuration or custom shell scripts. When using shell scripts, an authenticator script must be provided. The environment variables available to this script depend on the type of challenge. $CERTBOT_DOMAIN will always contain the domain being authenticated. For HTTP-01 and DNS-01, $CERTBOT_VALIDATION is the validation string, and $CERTBOT_TOKEN is the filename of the resource requested when performing an HTTP-01 challenge. An additional cleanup script can also be provided and can use the additional variable $CERTBOT_AUTH_OUTPUT which contains the stdout output from the auth script. For both authenticator and cleanup script, on HTTP-01 and DNS-01 challenges, $CERTBOT_REMAINING_CHALLENGES will be equal to the number of challenges that remain after the current one, and $CERTBOT_ALL_DOMAINS contains a comma-separated list of all domains that are challenged for the current certificate.zcPlease deploy a DNS TXT record under the name:

{domain}.

with the following value:

{validation}
a¨  
Before continuing, verify the TXT record has been deployed. Depending on the DNS
provider, this may take some time, from a few seconds to multiple minutes. You can
check if it has finished deploying with aid of online tools, such as the Google
Admin Toolbox: https://toolbox.googleapps.com/apps/dig/#TXT/{domain}.
Look for one or more bolded line(s) below the line ';ANSWER'. It should show the
value(s) you've just added.
zuCreate a file containing just this data:

{validation}

And make it available on your web server at this URL:

{uri}
z�
(This must be set up in addition to the previous challenges; do not remove,
replace, or undo the previous challenge tasks yet.)
zþ
(This must be set up in addition to the previous challenges; do not remove,
replace, or undo the previous challenge tasks yet. Note that you might be
asked to create multiple distinct TXT records with the same name. This is
permitted by DNS standards.)
ÚargsÚkwargsÚreturnNc                 óÊ   •— t        ‰| �  |i |¤Ž t        j                  | j                  «      | _        | j                  j                  «        i | _        d| _        d| _        y )NF)	ÚsuperÚ__init__r   ÚReverterÚconfigÚrecovery_routineÚenvÚsubsequent_dns_challengeÚsubsequent_any_challenge)Úselfr   r   Ú	__class__s      €úB/usr/lib/python3/dist-packages/certbot/_internal/plugins/manual.pyr   zAuthenticator.__init__a   sR   ø€ Ü‰Ñ˜$Ð) &Ò)Ü ×)Ñ)¨$¯+©+Ó6ˆŒØ�‰×&Ñ&Ô(ØIKˆŒØ(-ˆÔ%Ø(-ˆÕ%ó    Úadd).Nc                 óZ   —  |dd¬«        |dd¬«       t        j                  |dd«       y )Nú	auth-hookz8Path or command to execute for the authentication script)Úhelpúcleanup-hookz1Path or command to execute for the cleanup scriptzpublic-ip-logging-okr   )r   Úadd_deprecated_argument)Úclsr(   s     r&   Úadd_parser_argumentsz"Authenticator.add_parser_argumentsi   s1   € áˆKØKõ	MáˆNØDõ	Fä×$Ñ$ SÐ*@À!ÕDr'   c                 óØ   — | j                   j                  rD| j                  d«      s3t        j                  dj                  | j                  d«      «      «      ‚| j                  «        y )Nr*   zdAn authentication script must be provided with --{0} when using the manual plugin non-interactively.)r   Únoninteractive_modeÚconfr   ÚPluginErrorÚformatÚoption_nameÚ_validate_hooks©r$   s    r&   ÚpreparezAuthenticator.prepareq   sX   € Ø�;‰;×*Ò*°4·9±9¸[Ô3IÜ×$Ñ$ð=ß=C¹VØ×$Ñ$ [Ó1ó>3ó4ð 4ð 	×ÑÕr'   c                 óÐ   — | j                   j                  rPdD ]J  }| j                  |«      }|€Œ| j                  |«      d t	        d«        }t        j                  ||«       ŒL y y )N)r*   r,   z-hook)r   Úvalidate_hooksr2   r5   Úlenr   Úvalidate_hook)r$   ÚnameÚhookÚhook_prefixs       r&   r6   zAuthenticator._validate_hooksy   sc   € Ø�;‰;×%Ò%Ø5ò ;�Ø—y‘y “�ØÑ#Ø"&×"2Ñ"2°4Ó"8¸¼3¸w»<¸-Ð"H�KÜ×'Ñ'¨¨kÕ:ñ	;ð &r'   c                  ó   — 	 y)Nz¦This plugin allows the user to customize setup for domain validation challenges either through shell scripts provided by the user or by performing the setup manually.© r7   s    r&   Ú	more_infozAuthenticator.more_info�   s   € ð<ð	=r'   Úfailed_achallsc                 ó  ‡— dt         t        j                     dt        fˆfd„} |t        j                  «      }t        j                  dt        j
                  dt        j                  di}dj                  t        |j                  «       D ��cg c]  \  }} ||«      sŒ|‘Œ c}}«      «      }| j                  d«      r+d	j                  t        j                  ||rd
¬«      S d¬«      S dj                  ||rd¬«      S d¬«      S c c}}w )Nr.   r   c                 ó.   •‡ — t        ˆ fd„‰D «       «      S )Nc              3   óJ   •K  — | ]  }t        |j                  ‰«      –— Œ y ­w©N)Ú
isinstanceÚchall)Ú.0Úachallr.   s     €r&   ú	<genexpr>z=Authenticator.auth_hint.<locals>.has_chall.<locals>.<genexpr>‰   s   øè ø€ ÒR¸”z &§,¡,°×4ÑRùs   ƒ #)Úany)r.   rC   s   `€r&   Ú	has_challz*Authenticator.auth_hint.<locals>.has_challˆ   s   ù€ ÜÓRÀ>ÔRÓRÐRr'   zDNS TXT recordszchallenge fileszTLS-ALPN certificatesz and r*   zÖThe Certificate Authority failed to verify the {resources} created by the --manual-auth-hook. Ensure that this hook is functioning correctly{dns_hint}. Refer to "{certbot} --help manual" and the Certbot User Guide.zD and that it waits a sufficient duration of time for DNS propagationÚ )ÚcertbotÚ	resourcesÚdns_hintz�The Certificate Authority failed to verify the manually created {resources}. Ensure that you created these in the correct location{dns_hint}.z?, or try waiting longer for DNS propagation on the next attempt)rQ   rR   )r	   r
   Ú	ChallengeÚboolÚDNS01ÚHTTP01Ú	TLSALPN01ÚjoinÚsortedÚitemsr2   r4   r   Úcli_command)r$   rC   rN   Úhas_dnsÚresource_namesÚkÚvrQ   s    `      r&   Ú	auth_hintzAuthenticator.auth_hint‡   s,  ø€ ð	Sœ4¤
× 4Ñ 4Ñ5ð 	S¼$õ 	Sñ œJ×,Ñ,Ó-ˆä×ÑÐ/Ü×ÑÐ0Ü× Ñ Ð"9ð
ˆð
 —L‘L¤°~×7KÑ7KÓ7M×(^©t¨q°!ÑQZÐ[\ÕQ]ªÓ(^Ó!_Ó`ˆ	à�9‰9�[Ô!ðQ÷ ‘Ü)×5Ñ5Ø'ñ !ð _ð	 ó ð	ð ')ð ó ð	ðSç‘Ø'ñ "ð Zð ó ð	ð (*ð	 ó ð	ùó! )_s   ÂD	Â!D	Údomainc                 óB   — t         j                  t         j                  gS rG   )r
   rV   rU   )r$   ra   s     r&   Úget_chall_prefzAuthenticator.get_chall_pref¬   s   € ä×!Ñ!¤:×#3Ñ#3Ð4Ð4r'   Úachallsc                 ón  — g }d}t        |«      D ],  \  }}t        |j                  t        j                  «      sŒ+|}Œ. t        |«      D ]h  \  }}| j                  d«      r| j                  ||«       n| j                  |||k(  «       |j                  |j                  |j                  «      «       Œj |S )Nr   r*   )Ú	enumeraterH   rI   r
   rU   r2   Ú_perform_achall_with_scriptÚ_perform_achall_manuallyÚappendÚresponseÚaccount_key)r$   rd   Ú	responsesÚlast_dns_achallÚirK   s         r&   ÚperformzAuthenticator.perform°   s¯   € àˆ	ØˆÜ" 7Ó+ò 	$‰IˆAˆvÜ˜&Ÿ,™,¬
×(8Ñ(8Õ9Ø"#‘ð	$ô # 7Ó+ò 	B‰IˆAˆvØ�y‰y˜Ô%Ø×0Ñ0°¸ÕAà×-Ñ-¨f°a¸?Ñ6JÔKØ×Ñ˜VŸ_™_¨V×-?Ñ-?Ó@ÕAð	Bð Ðr'   rK   c           	      óX  — |j                   |j                  |j                  «      dj                  d„ |D «       «      t	        t        |«      |j                  |«      z
  dz
  «      dœ}t        |j                  t        j                  «      r|j                  j                  d«      |d<   n t        j                  j                  dd «       t        j                  j                  |«       | j!                  d|j                   «      \  }}|j#                  «       |d<   || j$                  |<   y )	Nú,c              3   ó4   K  — | ]  }|j                   –— Œ y ­wrG   ©ra   )rJ   Ú
one_achalls     r&   rL   z<Authenticator._perform_achall_with_script.<locals>.<genexpr>Ä   s   è ø€ Ò+XÀ*¨J×,=Õ,=Ñ+Xùs   ‚é   )ÚCERTBOT_DOMAINÚCERTBOT_VALIDATIONÚCERTBOT_ALL_DOMAINSÚCERTBOT_REMAINING_CHALLENGESÚtokenÚCERTBOT_TOKENr*   ÚCERTBOT_AUTH_OUTPUT)ra   Ú
validationrk   rX   Ústrr;   ÚindexrH   rI   r
   rV   Úencoder   ÚenvironÚpopÚupdateÚ_execute_hookÚstripr!   )r$   rK   rd   r!   Ú_Úouts         r&   rg   z)Authenticator._perform_achall_with_script¿   så   € ð %Ÿm™mØ"(×"3Ñ"3°F×4FÑ4FÓ"GØ#&§8¡8Ñ+XÐPWÔ+XÓ#XÜ,/´°G³¸w¿}¹}ÈVÓ?TÑ0TÐWXÑ0XÓ,Yñ	
ˆô �f—l‘l¤J×$5Ñ$5Ô6Ø#)§<¡<×#6Ñ#6°wÓ#?ˆC�Ò ä�J‰J�N‰N˜?¨DÔ1Ü
�
‰
×Ñ˜#ÔØ×#Ñ# K°·±Ó?‰ˆˆ3Ø%(§Y¡Y£[ˆÐ!Ñ"Øˆ�‰�Òr'   rm   c                 óÊ  — |j                  |j                  «      }t        |j                  t        j
                  «      rq| j                  j                  ||j                  j                  d«      | j                  j                  |j                  j                  |j                  «      |¬«      }n\t        |j                  t        j                  «      sJ ‚| j                  j                  |j                  |j                  «      |¬«      }t        |j                  t        j                  «      ry| j                   r|| j"                  z  }n| j$                  r|| j&                  z  }d| _        |rT|| j(                  j                  |j                  |j                  «      ¬«      z  }n| j$                  r|| j&                  z  }t+        j,                  |dd¬«       d| _        y )Nrz   )rK   Úencoded_tokenÚportÚurir}   )ra   r}   Trs   F)ÚwrapÚforce_interactive)r}   rk   rH   rI   r
   rV   Ú_HTTP_INSTRUCTIONSr4   r€   r   Úhttp01_portr‹   ra   rU   Ú_DNS_INSTRUCTIONSÚvalidation_domain_namer"   Ú&_SUBSEQUENT_DNS_CHALLENGE_INSTRUCTIONSr#   Ú"_SUBSEQUENT_CHALLENGE_INSTRUCTIONSÚ_DNS_VERIFY_INSTRUCTIONSÚdisplay_utilÚnotification)r$   rK   rm   r}   Úmsgs        r&   rh   z&Authenticator._perform_achall_manuallyÐ   s‹  € à×&Ñ& v×'9Ñ'9Ó:ˆ
Ü�f—l‘l¤J×$5Ñ$5Ô6Ø×)Ñ)×0Ñ0Ø¨V¯\©\×-@Ñ-@ÀÓ-IØ—[‘[×,Ñ,Ø—L‘L×$Ñ$ V§]¡]Ó3À
ð 1ó L‰Cô
 ˜fŸl™l¬J×,<Ñ,<Ô=Ð=Ð=Ø×(Ñ(×/Ñ/Ø×4Ñ4°V·]±]ÓCØ%ð 0ó 'ˆCô �f—l‘l¤J×$4Ñ$4Ô5Ø×,Ò,à�t×BÑBÑB‘Ø×.Ò.ð �t×>Ñ>Ñ>�Ø,0ˆDÔ)Ùà�t×4Ñ4×;Ñ;Ø!×8Ñ8¸¿¹ÓGð <ó Iñ I‘à×*Ò*à�4×:Ñ:Ñ:ˆCÜ×!Ñ! #¨EÀTÕJØ(,ˆÕ%r'   c                 ó\  — | j                  d«      r�|D ]|  }| j                  j                  |«      }d|vr t        j                  j                  dd «       t        j                  j                  |«       | j                  d|j                  «       Œ~ | j                  j                  «        y )Nr,   r{   )
r2   r!   r‚   r   r�   rƒ   r„   ra   r   r    )r$   rd   rK   r!   s       r&   ÚcleanupzAuthenticator.cleanupð   sƒ   € Ø�9‰9�^Ô$Ø!ò B�Ø—h‘h—l‘l 6Ó*�Ø"¨#Ñ-Ü—J‘J—N‘N ?°DÔ9Ü—
‘
×!Ñ! #Ô&Ø×"Ñ" >°6·=±=ÕAðBð 	�‰×&Ñ&Õ(r'   Ú	hook_nameÚachall_domainc                 óÞ   — t        j                  | j                  |«      | j                  |«      t	        j
                  «       ¬«      \  }}}t        j                  d|› d|› �|||«       ||fS )N)r!   zHook '--manual-z' for )r   Úexecute_command_statusr5   r2   r   Úenv_no_snap_for_external_callsÚdisplay_opsÚreport_executed_command)r$   rš   r›   Ú
returncodeÚerrr‡   s         r&   r„   zAuthenticator._execute_hookú   sq   € Ü#×:Ñ:Ø×Ñ˜YÓ'¨¯©°9Ó)=Ü×3Ñ3Ó5ô 
Ñˆ
�C˜ô
 	×+Ñ+Ø˜i˜[¨¨}¨oÐ>À
ÈCÐQTô	Vð �Cˆxˆr'   )r   N)F)'Ú__name__Ú
__module__Ú__qualname__Ú__doc__ÚdescriptionÚhiddenÚlong_descriptionr�   r”   rŽ   r“   r’   r   r   Úclassmethodr   r/   r8   r6   r~   rB   r   r   ÚAnnotatedChallenger`   r	   r
   rS   rc   r   ÚChallengeResponsero   rg   rT   rh   r™   r   r„   Ú__classcell__)r%   s   @r&   r   r      s¥  ø„ ñð G€KØ€Fð	Oð ð*Ðð ÐðÐð*Ð&ð.Ð*ð.˜cð .¨Sð .°Tõ .ð ðE x°	Ñ':ð E¸tò Eó ðEóó;ð=˜3ó =ð#¨°×1OÑ1OÑ(Pð #ÐUXó #ðJ5 Sð 5¨X°d¸:×;OÑ;OÑ6PÑ-Qó 5ð˜t K×$BÑ$BÑCð Ø˜*×6Ñ6Ñ7óð°+×2PÑ2Pð Ø-1°+×2PÑ2PÑ-QðØVZóð$ :?ñ-¨{×/MÑ/Mð -Ø26ð-ØCGó-ð@)˜x¨×(FÑ(FÑGð )ÈDó )ð	 sð 	¸3ð 	À5ÈÈcÈÁ?÷ 	r'   r   )$r¦   ÚloggingÚtypingr   r   r   r   r   r   r	   Úacmer
   rP   r   r   r   r   r   Úcertbot._internalr   Úcertbot._internal.clir   Úcertbot.compatr   r   Úcertbot.displayr   rŸ   r•   Úcertbot.pluginsr   Ú	getLoggerr£   ÚloggerÚPluginr   rA   r'   r&   ú<module>r¹      ss   ðÙ !Û Ý Ý Ý Ý Ý Ý Ý å Ý Ý Ý Ý Ý Ý #Ý /Ý Ý Ý .Ý 0Ý "à	ˆ×	Ñ	˜8Ó	$€ôg�F—M‘M :×#;Ñ#;õ gr'   