Ë
    ojw!  ã            	       ór  — d Z ddlmZmZmZmZ ddlmZmZm	Z	 ddl
mZ  G d„ de«      Z G d„ de«      Z G d	„ d
e«      Z G d„ de«      Z e	e«       G d„ d«      «       Z e	e«       G d„ d«      «       Z e	e«       G d„ d«      «       Z e	e«       G d„ d«      «       Z e	e«       G d„ d«      «       Z e	e«       G d„ d«      «       Z e	e«       G d„ d«      «       Z e	e«       G d„ d«      «       Z e«        e«        e«        e«        e«        e«        e«        e«       dœZd„ Zd„ Zd „ Zd!„ Zd"„ Zd#„ Zy$)%z
SSH key exchange handling.
é    )Úsha1Úsha256Úsha384Úsha512)Ú	AttributeÚ	InterfaceÚimplementer)Úerrorc                   ó0   — e Zd ZdZ ed«      Z ed«      Zy)Ú_IKexAlgorithmzB
    An L{_IKexAlgorithm} describes a key exchange algorithm.
    z‹An L{int} giving the preference of the algorithm when negotiating key exchange. Algorithms with lower precedence values are more preferred.zqA callable hash algorithm constructor (e.g. C{hashlib.sha256}) suitable for use with this key exchange algorithm.N)Ú__name__Ú
__module__Ú__qualname__Ú__doc__r   Ú
preferenceÚhashProcessor© ó    ú8/usr/lib/python3/dist-packages/twisted/conch/ssh/_kex.pyr   r      s)   „ ññ ð	ó€Jñ ð	=ó�Mr   r   c                   ó0   — e Zd ZdZ ed«      Z ed«      Zy)Ú_IFixedGroupKexAlgorithmzu
    An L{_IFixedGroupKexAlgorithm} describes a key exchange algorithm with a
    fixed prime / generator group.
    zdAn L{int} giving the prime number used in Diffie-Hellman key exchange, or L{None} if not applicable.z�An L{int} giving the generator number used in Diffie-Hellman key exchange, or L{None} if not applicable. (This is not related to Python generator functions.)N)r   r   r   r   r   ÚprimeÚ	generatorr   r   r   r   r   "   s)   „ ññ
 ð	2ó€Eñ
 ð	'ó�Ir   r   c                   ó   — e Zd ZdZy)Ú#_IEllipticCurveExchangeKexAlgorithmzž
    An L{_IEllipticCurveExchangeKexAlgorithm} describes a key exchange algorithm
    that uses an elliptic curve exchange between the client and server.
    N©r   r   r   r   r   r   r   r   r   4   s   „ òr   r   c                   ó   — e Zd ZdZy)Ú_IGroupExchangeKexAlgorithmzõ
    An L{_IGroupExchangeKexAlgorithm} describes a key exchange algorithm
    that uses group exchange between the client and server.

    A prime / generator group should be chosen at run time based on the
    requested size. See RFC 4419.
    Nr   r   r   r   r   r   ;   s   „ òr   r   c                   ó   — e Zd ZdZdZeZy)Ú_Curve25519SHA256z”
    Elliptic Curve Key Exchange using Curve25519 and SHA256. Defined in
    U{https://datatracker.ietf.org/doc/draft-ietf-curdle-ssh-curves/}.
    é   N©r   r   r   r   r   r   r   r   r   r   r    r    E   ó   „ ñð
 €JØ�Mr   r    c                   ó   — e Zd ZdZdZeZy)Ú_Curve25519SHA256LibSSHzN
    As L{_Curve25519SHA256}, but with a pre-standardized algorithm name.
    é   Nr"   r   r   r   r%   r%   P   s   „ ñð €JØ�Mr   r%   c                   ó   — e Zd ZdZdZeZy)Ú_ECDH256aX  
    Elliptic Curve Key Exchange with SHA-256 as HASH. Defined in
    RFC 5656.

    Note that C{ecdh-sha2-nistp256} takes priority over nistp384 or nistp512.
    This is the same priority from OpenSSH.

    C{ecdh-sha2-nistp256} is considered preety good cryptography.
    If you need something better consider using C{curve25519-sha256}.
    é   Nr"   r   r   r   r(   r(   Z   s   „ ñ	ð €JØ�Mr   r(   c                   ó   — e Zd ZdZdZeZy)Ú_ECDH384zT
    Elliptic Curve Key Exchange with SHA-384 as HASH. Defined in
    RFC 5656.
    é   N)r   r   r   r   r   r   r   r   r   r   r+   r+   k   r#   r   r+   c                   ó   — e Zd ZdZdZeZy)Ú_ECDH512zT
    Elliptic Curve Key Exchange with SHA-512 as HASH. Defined in
    RFC 5656.
    é   N)r   r   r   r   r   r   r   r   r   r   r.   r.   v   r#   r   r.   c                   ó   — e Zd ZdZdZeZy)Ú_DHGroupExchangeSHA256zc
    Diffie-Hellman Group and Key Exchange with SHA-256 as HASH. Defined in
    RFC 4419, 4.2.
    é   Nr"   r   r   r   r1   r1   �   r#   r   r1   c                   ó   — e Zd ZdZdZeZy)Ú_DHGroupExchangeSHA1za
    Diffie-Hellman Group and Key Exchange with SHA-1 as HASH. Defined in
    RFC 4419, 4.1.
    é   N)r   r   r   r   r   r   r   r   r   r   r4   r4   Œ   s   „ ñð
 €JØ�Mr   r4   c                   ó,   — e Zd ZdZdZeZ ed«      ZdZ	y)Ú_DHGroup14SHA1z�
    Diffie-Hellman key exchange with SHA-1 as HASH and Oakley Group 14
    (2048-bit MODP Group). Defined in RFC 4253, 8.2.
    é   Ái  32317006071311007300338913926423828248817941241140239112842009751400741706634354222619689417363569347117901737909704191754605873209195028853758986185622153212175412514901774520270235796078236248884246189477587641105928646099411723245426622522193230540919037680524235519125679715870117001058055877651038861847280257976054903569732561526167081339361799541336476559160368317896729073178384589680639671900977202194168647225871031411336429319536193471636533209717077448227988588565369208645296636077250268955505928362751121174096972998068410554359584866583291642136218231078990999448652468262416972035911852507045361090559r&   N)
r   r   r   r   r   r   r   Úintr   r   r   r   r   r7   r7   —   s)   „ ñð
 €JØ€Máð
	ó€Eð �Ir   r7   )ó   curve25519-sha256s   curve25519-sha256@libssh.orgs$   diffie-hellman-group-exchange-sha256s"   diffie-hellman-group-exchange-sha1s   diffie-hellman-group14-sha1s   ecdh-sha2-nistp256s   ecdh-sha2-nistp384s   ecdh-sha2-nistp521c                 óT   — | t         vrt        j                  d| › �«      ‚t         |    S )aY  
    Get a description of a named key exchange algorithm.

    @param kexAlgorithm: The key exchange algorithm name.
    @type kexAlgorithm: L{bytes}

    @return: A description of the key exchange algorithm named by
        C{kexAlgorithm}.
    @rtype: L{_IKexAlgorithm}

    @raises ConchError: if the key exchange algorithm is not found.
    z$Unsupported key exchange algorithm: )Ú_kexAlgorithmsr
   Ú
ConchError©ÚkexAlgorithms    r   ÚgetKexrA   ¾   s0   € ð œ>Ñ)Ü×ÑÐ!EÀlÀ^ÐTÓUÐUÜ˜,Ñ'Ð'r   c                 ó>   — t         j                  t        | «      «      S )a  
    Returns C{True} if C{kexAlgorithm} is an elliptic curve.

    @param kexAlgorithm: The key exchange algorithm name.
    @type kexAlgorithm: C{str}

    @return: C{True} if C{kexAlgorithm} is an elliptic curve,
        otherwise C{False}.
    @rtype: C{bool}
    )r   Ú
providedByrA   r?   s    r   ÚisEllipticCurverD   Ð   s   € ô /×9Ñ9¼&ÀÓ:NÓOÐOr   c                 ó>   — t         j                  t        | «      «      S )a+  
    Returns C{True} if C{kexAlgorithm} has a fixed prime / generator group.

    @param kexAlgorithm: The key exchange algorithm name.
    @type kexAlgorithm: L{bytes}

    @return: C{True} if C{kexAlgorithm} has a fixed prime / generator group,
        otherwise C{False}.
    @rtype: L{bool}
    )r   rC   rA   r?   s    r   ÚisFixedGrouprF   Þ   s   € ô $×.Ñ.¬v°lÓ/CÓDÐDr   c                 ó0   — t        | «      }|j                  S )a  
    Get the hash algorithm callable to use in key exchange.

    @param kexAlgorithm: The key exchange algorithm name.
    @type kexAlgorithm: L{bytes}

    @return: A callable hash algorithm constructor (e.g. C{hashlib.sha256}).
    @rtype: C{callable}
    )rA   r   ©r@   Úkexs     r   ÚgetHashProcessorrJ   ì   s   € ô �Ó
€CØ×ÑÐr   c                 óH   — t        | «      }|j                  |j                  fS )zù
    Get the generator and the prime to use in key exchange.

    @param kexAlgorithm: The key exchange algorithm name.
    @type kexAlgorithm: L{bytes}

    @return: A L{tuple} containing L{int} generator and L{int} prime.
    @rtype: L{tuple}
    )rA   r   r   rH   s     r   ÚgetDHGeneratorAndPrimerL   ú   s!   € ô �Ó
€CØ�=‰=˜#Ÿ)™)Ð#Ð#r   c                  óœ  ‡— ddl m}  ddlm} ddlm}  | «       }t        j                  «       Št        ‰«      D ]�  }|j                  d«      r6|j                  dd«      }|j                  |j                  «       ||   «      }n$|j                  d«      r|j                  «       }nd}|rŒq‰j                  |«       Œƒ t        ‰ˆfd	„¬
«      S )z½
    Get a list of supported key exchange algorithm names in order of
    preference.

    @return: A C{list} of supported key exchange algorithm names.
    @rtype: C{list} of L{bytes}
    r   )Údefault_backend)Úec)Ú_curveTables   ecdhs   ecdsar;   Tc                 ó"   •— ‰|    j                   S )N)r   )r@   ÚkexAlgorithmss    €r   ú<lambda>z*getSupportedKeyExchanges.<locals>.<lambda>$  s   ø€ °¸lÑ0K×0VÑ0V€ r   )Úkey)Úcryptography.hazmat.backendsrN   Ú)cryptography.hazmat.primitives.asymmetricrO   Útwisted.conch.ssh.keysrP   r=   ÚcopyÚlistÚ
startswithÚreplaceÚ+elliptic_curve_exchange_algorithm_supportedÚECDHÚx25519_supportedÚpopÚsorted)rN   rO   rP   ÚbackendÚkeyAlgorithmÚkeyAlgorithmDsaÚ	supportedrR   s          @r   ÚgetSupportedKeyExchangesre     sÂ   ø€ õ =Ý<å2áÓ€GÜ"×'Ñ'Ó)€MÜ˜]Ó+ò ,ˆØ×"Ñ" 7Ô+Ø*×2Ñ2°7¸HÓEˆOØ×KÑKØ—‘“	˜; Ñ7ó‰Ið ×$Ñ$Ð%9Ô:Ø×0Ñ0Ó2‰IàˆIÚØ×Ñ˜lÕ+ð,ô ØÓVôð r   N)r   Úhashlibr   r   r   r   Úzope.interfacer   r   r	   Útwisted.conchr
   r   r   r   r   r    r%   r(   r+   r.   r1   r4   r7   r=   rA   rD   rF   rJ   rL   re   r   r   r   ú<module>ri      s™  ðñ
÷
 1Ó 0ç <Ñ <å ô�Yô ô"˜~ô ô$¨.ô ô .ô ñ Ð0Ó1÷ð ó 2ðñ Ð0Ó1÷ð ó 2ðñ Ð0Ó1÷ð ó 2ðñ  Ð0Ó1÷ð ó 2ðñ Ð0Ó1÷ð ó 2ðñ Ð(Ó)÷ð ó *ðñ Ð(Ó)÷ð ó *ðñ Ð%Ó&÷ð ó 'ðñ6 ,Ó-Ù%<Ó%>Ù-CÓ-EÙ+?Ó+AÙ$2Ó$4Ù#›:Ù#›:Ù#›:ñ	€ò(ò$PòEòò$ór   