Ë
    M/Åep>  ã                   ó  — d Z ddlZddlZddlZddlZddlmZ ddlmZ ddlmZ ddlm	Z	 ddlm
Z
 ddlmZ dd	lmZ dd
lmZ ddlmZ ddlmZ ddlmZ ddlmZ ddlmZ ddlmZ ddlmZ ddlmZ ddlmZ ddlmZ ddlmZ ddlmZ ddlm Z! ddl"m#Z# ddl"m Z  ddl$m%Z%  ejL                  e'«      Z(dZ)ddgZ* G d„ de#jV                  ejX                  «      Z, G d„ d ejZ                  «      Z. G d!„ d"ejZ                  «      Z/d#e0d$e0fd%„Z1y)&zWebroot plugin.é    N)ÚAny)ÚCallable)ÚDefaultDict)ÚDict)ÚIterable)ÚList)ÚOptional)ÚSequence)ÚSet)ÚType)ÚUnion)Ú
challenges)Úcrypto_util)Úerrors)Ú
interfaces)Úcli)ÚAnnotatedChallenge)Ú
filesystem)Úos)Úops)Úutil)Úcommon)Ú	safe_opena!  <?xml version="1.0" encoding="UTF-8" ?>
<!--Generated by Certbot-->
<configuration>
  <system.webServer>
      <staticContent>
          <remove fileExtension="."/>
          <mimeMap fileExtension="." mimeType="text/plain" />
      </staticContent>
  </system.webServer>
</configuration>
Ú@20c5ca1bd58fa8ad5f07a2f1be8b7cbb707c20fcb607a8fc8db9393952846a97Ú@8d31383d3a079d2098a9d0c0921f4ab87e708b9868dc3f314d54094c2fe70336c                   óª  ‡ — e Zd ZdZdZdZdefd„Zede	d   ddfd	„«       Z
d
ee   defd„Zdedeeej"                        fd„Zdededdfˆ fd„Zd d„Zdee   deej,                     fd„Zdee   ddfd„Zdedee   dee   fd„Zdedee   dee   fd„Zd!dededee   fd„Zd d„Zdededefd„Zdedej,                  fd„Z dee   ddfd„Z!ˆ xZ"S )"ÚAuthenticatorzWebroot Authenticator.zñSaves the necessary validation files to a .well-known/acme-challenge/ directory within the nominated webroot path. A seperate HTTP server must be running and serving files from the webroot path. HTTP challenge only (wildcards not supported).zôAuthenticator plugin that performs http-01 challenge by saving
necessary validation resources to appropriate paths on the file
system. It expects that there is some other HTTP server configured
to serve all files under specified web root ({0}).Úreturnc                 óV   — | j                   j                  | j                  d«      «      S )NÚpath)Ú	MORE_INFOÚformatÚconf©Úselfs    úC/usr/lib/python3/dist-packages/certbot/_internal/plugins/webroot.pyÚ	more_infozAuthenticator.more_infoF   s    € Ø�~‰~×$Ñ$ T§Y¡Y¨vÓ%6Ó7Ð7ó    Úadd).NNc                 óF   —  |ddg t         d¬«        |di t        d¬«       y )Nr    z-wa  public_html / webroot path. This can be specified multiple times to handle different domains; each domain will have the webroot path that preceded it.  For instance: `-w /var/www/example -d example.com -d www.example.com -w /var/www/thing -d thing.net -d m.thing.net` (default: Ask))ÚdefaultÚactionÚhelpÚmapa—  JSON dictionary mapping domains to webroot paths; this implies -d for each entry. You may need to escape this from your shell. E.g.: --webroot-map '{"eg1.is,m.eg1.is":"/www/eg1/", "eg2.is":"/www/eg2"}' This option is merged with, but takes precedence over, -w / -d entries. At present, if you put webroot-map in a config file, it needs to be on a single line, like: webroot-map = {"example.com":"/var/www"}.)Ú_WebrootPathActionÚ_WebrootMapAction)Úclsr)   s     r&   Úadd_parser_argumentsz"Authenticator.add_parser_argumentsI   s0   € áˆF�D "Ô-?ðNõ	Oñ 	ˆE˜2Ô&7ð/ö	0r(   Úfailed_achallsc                  ó   — y)Nz÷The Certificate Authority failed to download the temporary challenge files created by Certbot. Ensure that the listed domains serve their content from the provided --webroot-path/-w and that files created there can be downloaded from the internet.© )r%   r3   s     r&   Ú	auth_hintzAuthenticator.auth_hint[   s   € ð%r(   Údomainc                 ó$   — t         j                  gS ©N)r   ÚHTTP01)r%   r7   s     r&   Úget_chall_prefzAuthenticator.get_chall_prefa   s   € ä×!Ñ!Ð"Ð"r(   ÚargsÚkwargsc                 ó|   •— t        ‰| �  |i |¤Ž i | _        t        j                  t
        «      | _        g | _        y r9   )ÚsuperÚ__init__Ú
full_rootsÚcollectionsÚdefaultdictÚsetÚ	performedÚ_created_dirs©r%   r<   r=   Ú	__class__s      €r&   r@   zAuthenticator.__init__e   s7   ø€ Ü‰Ñ˜$Ð) &Ò)Ø*,ˆŒÜDO×D[ÑD[Ô\_ÓD`ˆŒà(*ˆÕr(   c                  ó   — y r9   r5   r$   s    r&   ÚpreparezAuthenticator.preparel   s   € Ør(   Úachallsc                 óŒ   — | j                  |«       | j                  «        |D �cg c]  }| j                  |«      ‘Œ c}S c c}w r9   )Ú_set_webrootsÚ_create_challenge_dirsÚ_perform_single)r%   rK   Úachalls      r&   ÚperformzAuthenticator.performo   s;   € Ø×Ñ˜7Ô#à×#Ñ#Ô%à;BÖC°�×$Ñ$ VÕ,ÒCÐCùÒCs   ¦Ac                 óf  — | j                  d«      r]| j                  d«      d   }t        j                  d|«       |D ]-  }| j                  d«      j                  |j                  |«       Œ/ y t        t        | j                  d«      j                  «       «      «      }|D ]~  }|j                  | j                  d«      vsŒ!| j                  |j                  |«      }	 |j                  |«       |j                  d|«       || j                  d«      |j                  <   Œ€ y # t        $ r Y Œ>w xY w)Nr    éÿÿÿÿz4Using the webroot path %s for all unmatched domains.r.   r   )r#   ÚloggerÚinfoÚ
setdefaultr7   ÚlistrD   ÚvaluesÚ_prompt_for_webrootÚremoveÚ
ValueErrorÚinsert)r%   rK   Úwebroot_pathrP   Úknown_webrootsÚnew_webroots         r&   rM   zAuthenticator._set_webrootsv   s  € Ø�9‰9�VÔØŸ9™9 VÓ,¨RÑ0ˆLÜ�K‰KÐNØ$ô&à!ò I�Ø—	‘	˜%Ó ×+Ñ+¨F¯M©M¸<ÕHñIô "¤# d§i¡i°Ó&6×&=Ñ&=Ó&?Ó"@ÓAˆNØ!ò B�Ø—=‘=¨¯	©	°%Ó(8Ò8Ø"&×":Ñ":¸6¿=¹=Ø;Ió#K�KðØ&×-Ñ-¨kÔ:ð #×)Ñ)¨!¨[Ô9Ø6A�D—I‘I˜eÓ$ V§]¡]Ò3ñBøô &ò Ùðús   Ã D$Ä$	D0Ä/D0r^   c                 óˆ   — d }|€=|r&| j                  ||«      }|€$| j                  |«      }n| j                  |d«      }|€Œ=|S )NT)Ú_prompt_with_webroot_listÚ_prompt_for_new_webroot)r%   r7   r^   Úwebroots       r&   rY   z!Authenticator._prompt_for_webrootŒ   sX   € ØˆàˆoÙà×8Ñ8¸ÀÓP�Ø�?Ø"×:Ñ:¸6ÓB‘Gð ×6Ñ6°v¸tÓD�ð ‰oð ˆr(   c                 óø   — d| j                  d«      z   }	 t        j                  dj                  |«      dg|z   |d¬«      \  }}|t        j                  k(  rt        j                  d«      ‚|dk(  rd S ||d	z
     S )
Nz--r    TzSelect the webroot for {0}:zEnter a new webroot)Úcli_flagÚforce_interactiveúIEvery requested domain must have a webroot when using the webroot plugin.r   é   )Úoption_nameÚdisplay_utilÚmenur"   ÚCANCELr   ÚPluginError)r%   r7   r^   Ú	path_flagÚcodeÚindexs         r&   ra   z'Authenticator._prompt_with_webroot_list›   s�   € à˜4×+Ñ+¨FÓ3Ñ3ˆ	àÜ&×+Ñ+Ø-×4Ñ4°VÓ<Ø&Ð'¨.Ñ8Ø"°dô<‰KˆD�%ð ”|×*Ñ*Ò*Ü×(Ñ(ð=ó>ð >ð ! Aš:�4ÐD¨>¸%À!¹)Ñ+DÐDr(   Ú
allowraisec                 óÊ   — t        j                  t        dj                  |«      d¬«      \  }}|t        j
                  k(  r|sy t        j                  d«      ‚t        |«      S )NzInput the webroot for {0}:T)rf   rg   )r   Úvalidated_directoryÚ_validate_webrootr"   rj   rl   r   rm   )r%   r7   rq   ro   rc   s        r&   rb   z%Authenticator._prompt_for_new_webrootª   se   € Ü×/Ñ/ÜØ(×/Ñ/°Ó7Ø"ô$‰ˆˆgð ”<×&Ñ&Ò&ÙØÜ×$Ñ$ð9ó:ð :ô ! Ó)Ð)r(   c           
      óð  — | j                  d«      }|st        j                  d«      ‚|j                  «       D �]"  \  }}t        j
                  j                  |t        j
                  j                  t        j                  j                  «      «      | j                  |<   t        j                  d| j                  |   «       t        j                  d«      5  t!        t#        j$                  | j                  |   «      d d t&        ¬«      D ]o  }t        j
                  j)                  |«      rŒ#	 t        j*                  |d«       | j,                  j/                  |«       	 t        j0                  ||ddd¬	«       Œq 	 d d d «       t        j:                  r�Œct        j
                  j                  | j                  |   d«      }t        j
                  j=                  |«      r%t        j?                  d| j                  |   «       �ŒÔt        j?                  d| j                  |   «       tA        |dd¬«      5 }|jC                  tD        «       d d d «       �Œ% y # t2        t4        f$ r6}t        j7                  d
«       t        j                  d|«       Y d }~�Œ!d }~ww xY w# t2        $ r*}t        j                  dj9                  ||«      «      ‚d }~ww xY w# 1 sw Y   �Œ^xY w# 1 sw Y   �Œ¼xY w)Nr.   z�Missing parts of webroot configuration; please set either --webroot-path and --domains, or --webroot-map. Run with  --help webroot for examples.z-Creating root challenges validation dir at %sé   rS   )Úkeyií  T)Ú	copy_userÚ
copy_groupz3Unable to change owner and uid of webroot directoryúError was: %sz=Couldn't create root for {0} http-01 challenge responses: {1}ú
web.configzPA web.config file has not been created in %s because another one already exists.zGCreating a web.config file in %s to allow IIS to serve challenge files.Úwé¤  ©ÚmodeÚchmod)#r#   r   rm   Úitemsr   r    ÚjoinÚnormcaser   r:   ÚURI_ROOT_PATHrA   rT   Údebugr   Ú
temp_umaskÚsortedr   Úget_prefixesÚlenÚisdirÚmkdirrF   ÚappendÚcopy_ownership_and_apply_modeÚOSErrorÚAttributeErrorÚwarningr"   Ú
POSIX_MODEÚexistsrU   r   ÚwriteÚ_WEB_CONFIG_CONTENT)r%   Úpath_mapÚnamer    ÚprefixÚ	exceptionÚweb_config_pathÚ
web_configs           r&   rN   z$Authenticator._create_challenge_dirs·   sƒ  € Ø—9‘9˜UÓ#ˆÙÜ×$Ñ$ð0ó1ð 1ð #Ÿ.™.Ó*ó .	:‰JˆD�$Ü$&§G¡G§L¡L°´r·w±w×7GÑ7GÜ×!Ñ!×/Ñ/ó81ó %2ˆD�O‰O˜DÑ!ä�L‰LÐHØŸ™¨Ñ.ô0ô ×&Ñ& uÓ-ñ Pô %¤T×%6Ñ%6°t·±ÀtÑ7LÓ%MÈcÈrÐ%RÔX[Ô\ò P�FÜ—w‘w—}‘} VÔ,ð !ðPô
 #×(Ñ(¨°Ô7Ø×*Ñ*×1Ñ1°&Ô9ðEÜ&×DÑDØ $ f¨e¸tÐPTõVøñP÷Pô8 ×(Ô(Ü"$§'¡'§,¡,¨t¯©¸tÑ/DÀlÓ"S�Ü—7‘7—>‘> /Ô2Ü—K‘Kð !IØJNÏ/É/ÐZ^ÑJ_ôaáÜ—‘ð 8Ø9=¿¹ÈÑ9NôPä˜°SÀÔFð :È*Ø×$Ñ$Ô%8Ô9÷:ñ :ñ[.	:øô6 !(¬Ð8ò EÜ"ŸN™NÐ+`ÔaÜ"ŸL™L¨¸)×DÒDûðEûô #ò PÜ$×0Ñ0ð7ß7=±v¸dÀIÓ7NóPð PûðPú÷+Pñ Pú÷H:ñ :úsa   ÃAKÄ31J(Å%I Å?KÈ>K+É J%	É/+J 	ÊJ(Ê J%	Ê%J(Ê(	K	Ê1%K	ËK	ËKËK(	Ë+K5	Ú	root_pathrP   c                 ót   — t         j                  j                  ||j                  j	                  d«      «      S )NÚtoken)r   r    r‚   ÚchallÚencode)r%   r›   rP   s      r&   Ú_get_validation_pathz"Authenticator._get_validation_pathî   s&   € Ü�w‰w�|‰|˜I v§|¡|×':Ñ':¸7Ó'CÓDÐDr(   c                 óÂ  — |j                  «       \  }}| j                  |j                     }| j                  ||«      }t        j                  d|«       t        j                  d«      5  t        |dd¬«      5 }|j                  |j                  «       «       d d d «       d d d «       | j                  |   j                  |«       |S # 1 sw Y   Œ1xY w# 1 sw Y   Œ5xY w)Nz#Attempting to save validation to %srv   Úwbr}   r~   )Úresponse_and_validationrA   r7   r    rT   r…   r   r†   r   r“   rŸ   rE   r)   )r%   rP   ÚresponseÚ
validationr›   Úvalidation_pathÚvalidation_files          r&   rO   zAuthenticator._perform_singleñ   sÅ   € Ø%×=Ñ=Ó?Ñˆ�*à—O‘O F§M¡MÑ2ˆ	Ø×3Ñ3°I¸vÓFˆÜ�‰Ð:¸OÔLô ×"Ñ" 5Ó)ñ 	;Ü˜?°¸UÔCð ;ÀØ×%Ñ% j×&7Ñ&7Ó&9Ô:÷;÷	;ð 	�‰�yÑ!×%Ñ% fÔ-Øˆ÷	;ð ;ú÷	;ð 	;ús$   Á*CÁ9 C	ÂCÃ	C	ÃCÃCc                 óö  — |D �]8  }| j                   j                  |j                  d «      }|€Œ-| j                  ||«      }t        j                  d|«       t        j                  |«       | j                  |   j                  |«       t        j                  rŒ™t        j                  j                  |d«      }t        j                  j                  |«      sŒÙt        j                  |«      }|t         v r-t        j#                  d|«       t        j                  |«       �Œ#t        j#                  d|«       �Œ; g }| j$                  r=| j$                  j'                  «       }	 t        j(                  |«       | j$                  rŒ=|| _        t        j                  d«       y # t*        $ rH}	|j-                  d|«       t        j#                  d|«       t        j                  d|	«       Y d }	~	Œvd }	~	ww xY w)	NzRemoving %sr{   z4Cleaning web.config file generated by Certbot in %s.zQNot cleaning up the web.config file in %s because it is not generated by Certbot.r   z3Challenge directory %s was not empty, didn't removerz   zAll challenges cleaned up)rA   Úgetr7   r    rT   r…   r   rZ   rE   r   r‘   r    r‚   r’   r   Ú	sha256sumÚ_WEB_CONFIG_SHA256SUMSrU   rF   ÚpopÚrmdirrŽ   r\   )
r%   rK   rP   r›   r¦   r™   rª   Únot_removedr    Úexcs
             r&   ÚcleanupzAuthenticator.cleanup   s‰  € Øó 	^ˆFØŸ™×+Ñ+¨F¯M©M¸4Ó@ˆIØÑ$Ø"&×";Ñ";¸IÀvÓ"N�Ü—‘˜]¨OÔ<Ü—	‘	˜/Ô*Ø—‘˜yÑ)×0Ñ0°Ô8ä!×,Ó,Ü&(§g¡g§l¡l°9¸lÓ&K�OÜ—w‘w—~‘~ oÕ6Ü$/×$9Ñ$9¸/Ó$J˜	Ø$Ô(>Ñ>Ü"ŸK™KÐ(^Ø(1ô3äŸI™I oÖ6ä"ŸK™Kð )RØS\ö^ð#	^ð( "$ˆØ× Ò Ø×%Ñ%×)Ñ)Ó+ˆDð3Ü—‘˜”ð × Ó ð )ˆÔÜ�‰Ð0Õ1øô ò 3Ø×"Ñ" 1 dÔ+Ü—‘ÐQÐSWÔXÜ—‘˜_¨c×2Ñ2ûð3ús   Å(F' Æ'	G8Æ0>G3Ç3G8)r   N)F)#Ú__name__Ú
__module__Ú__qualname__Ú__doc__Údescriptionr!   Ústrr'   Úclassmethodr   r2   r   r   r6   r   r   r   Ú	Challenger;   r   r@   rJ   ÚChallengeResponserQ   rM   r	   rY   ra   Úboolrb   rN   r    rO   r°   Ú__classcell__©rH   s   @r&   r   r   8   s«  ø„ Ù ð@€Kð
6€Ið8˜3ó 8ð ð0 x°	Ñ':ð 0¸tò 0ó ð0ð"&¨Ð-?Ñ(@ð &ÀSó &ð# Sð #¨X°d¸:×;OÑ;OÑ6PÑ-Qó #ð+˜cð +¨Sð +°Tõ +óðD˜tÐ$6Ñ7ð D¸DÀ×A]ÑA]Ñ<^ó DðB XÐ.@Ñ%Að BÀdó Bð,¨#ð ¸tÀC¹yð ÈXÐVYÉ]ó ðE°ð EØ26°s±)ðEØ@HÈÁóEñ*¨cð *¸tð *ÐPXÐY\ÑP]ó *ó5:ðnE¨cð EÐ;Mð EÐRUó EðÐ&8ð ¸Z×=YÑ=Yó ð2˜tÐ$6Ñ7ð 2¸D÷ 2r(   r   c                   óp   — e Zd ZdZ	 d	dej
                  dej                  deee	e
   df   dee   ddf
d„Zy)
r0   z%Action class for parsing webroot_map.NÚparserÚ	namespaceÚwebroot_mapÚoption_stringr   c                 óú   ‡— |€y t        j                  t        |«      «      j                  «       D ]H  \  }Št	        ‰«      Š|j
                  j                  ˆfd„t        j                  ||«      D «       «       ŒJ y )Nc              3   ó&   •K  — | ]  }|‰f–— Œ
 y ­wr9   r5   )Ú.0Údr]   s     €r&   ú	<genexpr>z-_WebrootMapAction.__call__.<locals>.<genexpr>,  s   øè ø€ ò )PØ&'��LÔ!ñ)Pùs   ƒ)	ÚjsonÚloadsr¶   r�   rt   rÀ   Úupdater   Úadd_domains)r%   r¾   r¿   rÀ   rÁ   Údomainsr]   s         @r&   Ú__call__z_WebrootMapAction.__call__%  st   ø€ ð ÐØÜ%)§Z¡Z´°KÓ0@Ó%A×%GÑ%GÓ%Iò 	PÑ!ˆG�\Ü,¨\Ó:ˆLØ×!Ñ!×(Ñ(ó )PÜ+.¯?©?¸9ÀgÓ+Nô)Põ Pñ	Pr(   r9   )r±   r²   r³   r´   ÚargparseÚArgumentParserÚ	Namespacer   r¶   r
   r   r	   rÌ   r5   r(   r&   r0   r0   "  s[   „ Ù/ð 15ñP˜x×6Ñ6ð PÀ8×CUÑCUð PØ# C¨°#©¸Ð$<Ñ=ðPà (¨¡ðPà9=ôPr(   r0   c                   ó�   ‡ — e Zd ZdZdededdfˆ fd„Z	 ddej                  dej                  d	e	e
ee   df   d
ee
   ddf
d„Zˆ xZS )r/   z&Action class for parsing webroot_path.r<   r=   r   Nc                 ó2   •— t        ‰| �  |i |¤Ž d| _        y )NF)r?   r@   Ú_domain_before_webrootrG   s      €r&   r@   z_WebrootPathAction.__init__3  s   ø€ Ü‰Ñ˜$Ð) &Ò)Ø&+ˆÕ#r(   r¾   r¿   r]   rÁ   c                 ó^  — |€y | j                   rt        j                  d«      ‚|j                  r=|j                  d   }|j                  D ]  }|j
                  j                  ||«       Œ  n|j                  rd| _         |j                  j                  t        t        |«      «      «       y )NzPIf you specify multiple webroot paths, one of them must precede all domain flagsrS   T)
rÒ   r   rm   r]   rË   rÀ   rV   rŒ   rt   r¶   )r%   r¾   r¿   r]   rÁ   Úprev_webrootr7   s          r&   rÌ   z_WebrootPathAction.__call__7  s¨   € ð ÐØØ×&Ò&Ü×$Ñ$ð<ó=ð =ð ×!Ò!ð %×1Ñ1°"Ñ5ˆLØ#×+Ñ+ò G�Ø×%Ñ%×0Ñ0°¸ÕFñGà×ÒØ*.ˆDÔ'à×Ñ×%Ñ%Ô&7¼¸LÓ8IÓ&JÕKr(   r9   )r±   r²   r³   r´   r   r@   rÍ   rÎ   rÏ   r   r¶   r
   r	   rÌ   r»   r¼   s   @r&   r/   r/   0  sv   ø„ Ù0ð,˜cð ,¨Sð ,°Tõ ,ð 15ñL˜x×6Ñ6ð LÀ8×CUÑCUð LØ$ S¨(°3©-¸Ð%=Ñ>ðLà (¨¡ðLà9=÷Lr(   r/   r]   r   c                 ó®   — t         j                  j                  | «      st        j                  | dz   «      ‚t         j                  j                  | «      S )z·Validates and returns the absolute path of webroot_path.

    :param str webroot_path: path to the webroot directory

    :returns: absolute path of webroot_path
    :rtype: str

    z% does not exist or is not a directory)r   r    rŠ   r   rm   Úabspath)r]   s    r&   rt   rt   M  s>   € ô �7‰7�=‰=˜Ô&Ü× Ñ  Ð0WÑ!WÓXÐXä�7‰7�?‰?˜<Ó(Ð(r(   )2r´   rÍ   rB   rÇ   ÚloggingÚtypingr   r   r   r   r   r   r	   r
   r   r   r   Úacmer   Úcertbotr   r   r   Úcertbot._internalr   Úcertbot.achallengesr   Úcertbot.compatr   r   Úcertbot.displayr   r   rj   Úcertbot.pluginsr   Úcertbot.utilr   Ú	getLoggerr±   rT   r”   r«   ÚPluginr   ÚActionr0   r/   r¶   rt   r5   r(   r&   ú<module>rä      sÙ   ðÙ Û Û Û Û Ý Ý Ý Ý Ý Ý Ý Ý Ý Ý Ý å Ý Ý Ý Ý !Ý 2Ý %Ý Ý Ý 0Ý "Ý  Ý "à	ˆ×	Ñ	˜8Ó	$€ðÐ ð  GØFðÐ ôg2�F—M‘M :×#;Ñ#;ô g2ôTP˜Ÿ™ô PôL˜Ÿ™ô Lð:) Cð )¨Cô )r(   