Ë
    oj‡ù  ã                  óÀ  — d Z ddlmZ ddlZddlZddlZddlZddlmZm	Z	m
Z
 ddlmZmZ ddlmZ ddlZddlmZ ddlmZ dd	lmZ dd
lmZmZ ddlmZmZmZmZmZ ddl m!Z!m"Z"m#Z# ddl$m%Z%m&Z& ddlm'Z' ddl(m)Z)m*Z* ddl+m,Z, ddl-m.Z. ddl/m0Z0m1Z1 ddl2m3Z3m4Z4 ddl5m6Z6 	 ddl7m8Z8m9Z9  ejz                  «        ej|                  «        ej~                  «       dœZ@ddddœZAej„                  ZBej†                  ZC G d„ deD«      ZE G d„ deD«      ZF G d „ d!eD«      ZG G d"„ d#eD«      ZH G d$„ d%e4«      ZI G d&„ d'eD«      ZJd(„ ZK G d)„ d*«      ZLd,d+„ZMy# e:$ r ddl7m;Z8m<Z9 Y Œ´w xY w)-z0
Handling of RSA, DSA, ECDSA, and Ed25519 keys.
é    )ÚannotationsN)Ú	b64encodeÚdecodebytesÚencodebytes)Úmd5Úsha256)ÚAny)Úutils)ÚInvalidSignature)Údefault_backend)ÚhashesÚserialization)ÚdsaÚecÚed25519ÚpaddingÚrsa)ÚCipherÚ
algorithmsÚmodes)Úload_pem_private_keyÚload_ssh_public_key)ÚLiteral)ÚcommonÚsexpy)Úint_to_bytes)Ú	randbytes)Ú	iterbytesÚnativeString)ÚNamedConstantÚNames)Ú_mutuallyExclusiveArguments)Údecode_dss_signatureÚencode_dss_signature)Údecode_rfc6979_signatureÚencode_rfc6979_signature)s   ecdsa-sha2-nistp256s   ecdsa-sha2-nistp384s   ecdsa-sha2-nistp521s   nistp256s   nistp384s   nistp521)s	   secp256r1s	   secp384r1s	   secp521r1c                  ó   — e Zd ZdZy)ÚBadKeyErrorzj
    Raised when a key isn't what we expected from it.

    XXX: we really need to check for bad keys
    N©Ú__name__Ú
__module__Ú__qualname__Ú__doc__© ó    ú8/usr/lib/python3/dist-packages/twisted/conch/ssh/keys.pyr(   r(   D   s   „ òr/   r(   c                  ó   — e Zd ZdZy)ÚBadSignatureAlgorithmErrorzi
    Raised when a public key signature algorithm name isn't defined for this
    public key format.
    Nr)   r.   r/   r0   r2   r2   L   ó   „ òr/   r2   c                  ó   — e Zd ZdZy)ÚEncryptedKeyErrorzb
    Raised when an encrypted key is presented to fromString/fromFile without
    a password.
    Nr)   r.   r/   r0   r5   r5   S   r3   r/   r5   c                  ó   — e Zd ZdZy)ÚBadFingerPrintFormatzS
    Raises when unsupported fingerprint formats are presented to fingerprint.
    Nr)   r.   r/   r0   r7   r7   Z   s   „ òr/   r7   c                  ó,   — e Zd ZdZ e«       Z e«       Zy)ÚFingerprintFormatsaä  
    Constants representing the supported formats of key fingerprints.

    @cvar MD5_HEX: Named constant representing fingerprint format generated
        using md5[RFC1321] algorithm in hexadecimal encoding.
    @type MD5_HEX: L{twisted.python.constants.NamedConstant}

    @cvar SHA256_BASE64: Named constant representing fingerprint format
        generated using sha256[RFC4634] algorithm in base64 encoding
    @type SHA256_BASE64: L{twisted.python.constants.NamedConstant}
    N)r*   r+   r,   r-   r    ÚMD5_HEXÚSHA256_BASE64r.   r/   r0   r9   r9   `   s   „ ñ
ñ ‹o€GÙ!“O�Mr/   r9   c                  ó   — e Zd ZdZy)ÚPassphraseNormalizationErrorzŒ
    Raised when a passphrase contains Unicode characters that cannot be
    normalized using the available Unicode character database.
    Nr)   r.   r/   r0   r=   r=   q   r3   r/   r=   c                ó¨   — t        | t        «      rAt        d„ | D «       «      r
t        «       ‚t	        j
                  d| «      j                  d«      S | S )aî  
    Normalize a passphrase, which may be Unicode.

    If the passphrase is Unicode, this follows the requirements of U{NIST
    800-63B, section
    5.1.1.2<https://pages.nist.gov/800-63-3/sp800-63b.html#memsecretver>}
    for Unicode characters in memorized secrets: it applies the
    Normalization Process for Stabilized Strings using NFKC normalization.
    The passphrase is then encoded using UTF-8.

    @type passphrase: L{bytes} or L{unicode} or L{None}
    @param passphrase: The passphrase to normalize.

    @return: The normalized passphrase, if any.
    @rtype: L{bytes} or L{None}
    @raises PassphraseNormalizationError: if the passphrase is Unicode and
    cannot be normalized using the available Unicode character database.
    c              3  óL   K  — | ]  }t        j                  |«      d k(  –— Œ y­w)ÚCnN)ÚunicodedataÚcategory)Ú.0Úcs     r0   ú	<genexpr>z'_normalizePassphrase.<locals>.<genexpr>Ž   s    è ø€ ÒC°1Œ{×#Ñ# AÓ&¨$Õ.ÑCùs   ‚"$ÚNFKCzUTF-8)Ú
isinstanceÚstrÚanyr=   rA   Ú	normalizeÚencode©Ú
passphrases    r0   Ú_normalizePassphraserN   x   sM   € ô& �*œcÔ"ô ÑC¸
ÔCÔCô /Ó0Ð0Ü×$Ñ$ V¨ZÓ8×?Ñ?ÀÓHÐHàÐr/   c                  ó  — e Zd ZdZed.d„«       Zed.d„«       Zed„ «       Zed„ «       Zed„ «       Z	ed„ «       Z
ed	„ «       Zed
„ «       Zed„ «       Zed„ «       Zed„ «       Zed„ «       Zed/d„«       Zed0d„«       Zed0d„«       Zed0d„«       Zed0d„«       Zd„ Zd1d„Zd2d„Zd„ Zd„ Zej8                  fd„Zd3d„Zd„ Zd„ Z d„ Z!d„ Z"d4d„Z#d „ Z$d!„ Z% e&d"d#gd"d$gg«      d/d%„«       Z'd0d&„Z(d.d'„Z)d0d(„Z*d5d)„Z+d*„ Z,d+„ Z-d0d,„Z.d-„ Z/y)6ÚKeyau  
    An object representing a key.  A key can be either a public or
    private key.  A public key can verify a signature; a private key can
    create or verify a signature.  To generate a string that can be stored
    on disk, use the toString method.  If you have a private key, but want
    the string representation of the public key, use Key.public().toString().
    Nc                óˆ   — t        |d«      5 }| j                  |j                  «       ||«      cddd«       S # 1 sw Y   yxY w)aâ  
        Load a key from a file.

        @param filename: The path to load key data from.

        @type type: L{str} or L{None}
        @param type: A string describing the format the key data is in, or
        L{None} to attempt detection of the type.

        @type passphrase: L{bytes} or L{None}
        @param passphrase: The passphrase the key is encrypted with, or L{None}
        if there is no encryption.

        @rtype: L{Key}
        @return: The loaded key.
        ÚrbN)ÚopenÚ
fromStringÚread)ÚclsÚfilenameÚtyperM   Úfs        r0   ÚfromFilezKey.fromFile    s;   € ô$ �(˜DÓ!ð 	> QØ—>‘> !§&¡&£(¨D°*Ó=÷	>÷ 	>ò 	>ús	   �!8¸Ac                ój  — t        |t        «      r|j                  d«      }t        |«      }|€| j	                  |«      }|€t        d|›�«      ‚t        | d|j                  «       › �d«      }|€t        d|› �«      ‚|j                  j                  dk(  r|rt        d«      ‚ ||«      S  |||«      S )a   
        Return a Key object corresponding to the string data.
        type is optionally the type of string, matching a _fromString_*
        method.  Otherwise, the _guessStringType() classmethod will be used
        to guess a type.  If the key is encrypted, passphrase is used as
        the decryption key.

        @type data: L{bytes}
        @param data: The key data.

        @type type: L{str} or L{None}
        @param type: A string describing the format the key data is in, or
        L{None} to attempt detection of the type.

        @type passphrase: L{bytes} or L{None}
        @param passphrase: The passphrase the key is encrypted with, or L{None}
        if there is no encryption.

        @rtype: L{Key}
        @return: The loaded key.
        úutf-8Nzcannot guess the type of Ú_fromString_zno _fromString method for é   zkey not encrypted)
rG   rH   rK   rN   Ú_guessStringTyper(   ÚgetattrÚupperÚ__code__Úco_argcount)rV   ÚdatarX   rM   Úmethods        r0   rT   zKey.fromStringµ   s¾   € ô. �dœCÔ Ø—;‘;˜wÓ'ˆDÜ)¨*Ó5ˆ
Øˆ<Ø×'Ñ'¨Ó-ˆDØˆ<ÜÐ 9¸$¸ÐBÓCÐCÜ˜ ¨T¯Z©Z«\¨NÐ;¸TÓBˆØˆ>ÜÐ :¸4¸&ÐAÓBÐBØ�?‰?×&Ñ&¨!Ò+ÙÜ!Ð"5Ó6Ð6Ù˜$“<Ðá˜$ 
Ó+Ð+r/   c           
     ó¼  — t        j                  |«      \  }}|dk(  rMt        j                  |d«      \  }}} | t        j                  ||«      j                  t        «       «      «      S |dk(  rft        j                  |d«      \  }}}}	} | t        j                  |	t        j                  |||¬«      ¬«      j                  t        «       «      «      S |t        v rD | t        j                  j                  t        |   t        j                  |d«      d   «      «      S |dk(  r)t        j                  |«      \  }
}| j                  |
«      S t        d	|› �«      ‚)
a„  
        Return a public key object corresponding to this public key blob.
        The format of a RSA public key blob is::
            string 'ssh-rsa'
            integer e
            integer n

        The format of a DSA public key blob is::
            string 'ssh-dss'
            integer p
            integer q
            integer g
            integer y

        The format of ECDSA-SHA2-* public key blob is::
            string 'ecdsa-sha2-[identifier]'
            integer x
            integer y

            identifier is the standard NIST curve name.

        The format of an Ed25519 public key blob is::
            string 'ssh-ed25519'
            string a

        @type blob: L{bytes}
        @param blob: The key data.

        @return: A new key.
        @rtype: L{twisted.conch.ssh.keys.Key}
        @raises BadKeyError: if the key type (the first string) is unknown.
        ó   ssh-rsar^   ó   ssh-dssé   ©ÚpÚqÚg©ÚyÚparameter_numbersé   ó   ssh-ed25519úunknown blob type: )r   ÚgetNSÚgetMPr   ÚRSAPublicNumbersÚ
public_keyr   r   ÚDSAPublicNumbersÚDSAParameterNumbersÚ_curveTabler   ÚEllipticCurvePublicKeyÚfrom_encoded_pointÚ_fromEd25519Componentsr(   )rV   ÚblobÚkeyTypeÚrestÚeÚnrk   rl   rm   ro   Úas              r0   Ú_fromString_BLOBzKey._fromString_BLOBÝ   s?  € ôD Ÿ™ TÓ*‰ˆ�Ø�jÒ ÜŸ™ d¨AÓ.‰JˆAˆq�$Ù”s×+Ñ+¨A¨qÓ1×<Ñ<¼_Ó=NÓOÓPÐPØ˜
Ò"Ü%Ÿ|™|¨D°!Ó4ÑˆAˆq�!�Q˜ÙÜ×$Ñ$Ø¬3×+BÑ+BÀQÈ!ÈqÔ+Qôç‘*œ_Ó.Ó/óð ð
 œÑ#ÙÜ×)Ñ)×<Ñ<Ü Ñ(¬&¯,©,°t¸QÓ*?ÀÑ*Bóóð ð
 ˜Ò&Ü—l‘l 4Ó(‰GˆAˆtØ×-Ñ-¨aÓ0Ð0äÐ 3°G°9Ð=Ó>Ð>r/   c                ó¸  — t        j                  |«      \  }}|dk(  r4t        j                  |d«      \  }}}}}}	}| j                  |||||	¬«      S |dk(  r3t        j                  |d«      \  }}	}
}}}| j	                  ||
||	|¬«      S |t
        v r…t
        |   }t        j                  |d«      \  }}	}|t        |j                  j                  d«         k7  rt        d	|›d
|›�«      ‚t        j                  |«      \  }}| j                  |	||¬«      S |dk(  r2t        j                  |d«      \  }}}|dd }| j                  ||¬«      S t        d|› �«      ‚)a6  
        Return a private key object corresponding to this private key blob.
        The blob formats are as follows:

        RSA keys::
            string 'ssh-rsa'
            integer n
            integer e
            integer d
            integer u
            integer p
            integer q

        DSA keys::
            string 'ssh-dss'
            integer p
            integer q
            integer g
            integer y
            integer x

        EC keys::
            string 'ecdsa-sha2-[identifier]'
            string identifier
            string q
            integer privateValue

            identifier is the standard NIST curve name.

        Ed25519 keys::
            string 'ssh-ed25519'
            string a
            string k || a


        @type blob: L{bytes}
        @param blob: The key data.

        @return: A new key.
        @rtype: L{twisted.conch.ssh.keys.Key}
        @raises BadKeyError: if
            * the key type (the first string) is unknown
            * the curve name of an ECDSA key does not match the key type
        rg   é   ©r‚   r�   Údrk   rl   rh   é   ©ro   rm   rk   rl   Úxr^   ÚasciizECDSA curve name z does not match key type )ÚencodedPointÚcurveÚprivateValuerr   Né    )Úkrs   )r   rt   ru   Ú_fromRSAComponentsÚ_fromDSAComponentsrz   Ú
_secToNistÚnamerK   r(   Ú_fromECEncodedPointr}   )rV   r~   r   r€   r‚   r�   rˆ   Úurk   rl   rm   ro   r‹   rŽ   Ú	curveNamer�   rƒ   Úcombinedr‘   s                      r0   Ú_fromString_PRIVATE_BLOBzKey._fromString_PRIVATE_BLOB  s‚  € ô\ Ÿ™ TÓ*‰ˆ�à�jÒ Ü%+§\¡\°$¸Ó%:Ñ"ˆAˆq�!�Q˜˜1˜dØ×)Ñ)¨A°°a¸1ÀÐ)ÓBÐBØ˜
Ò"Ü"(§,¡,¨t°QÓ"7ÑˆAˆq�!�Q˜˜4Ø×)Ñ)¨A°°a¸1ÀÐ)ÓBÐBØœÑ#Ü Ñ(ˆEÜ!'§¡¨d°AÓ!6ÑˆI�q˜$ØœJ u§z¡z×'8Ñ'8¸Ó'AÑBÒBÝ!â!*©Gð5óð ô "(§¡¨dÓ!3ÑˆL˜$Ø×*Ñ*Ø g¸Lð +ó ð ð ˜Ò&ô !'§¡¨T°1Ó 5ÑˆAˆx˜Ø˜˜"�ˆAØ×-Ñ-¨a°1Ð-Ó5Ð5äÐ 3°G°9Ð=Ó>Ð>r/   c                ó²   — |j                  d«      r | t        |t        «       «      «      S t        |j	                  «       d   «      }| j                  |«      S )a”  
        Return a public key object corresponding to this OpenSSH public key
        string.  The format of an OpenSSH public key string is::
            <key type> <base64-encoded public key blob>

        @type data: L{bytes}
        @param data: The key data.

        @return: A new key.
        @rtype: L{twisted.conch.ssh.keys.Key}
        @raises BadKeyError: if the blob type is unknown.
        s
   ecdsa-sha2rq   )Ú
startswithr   r   r   Úsplitr„   )rV   rd   r~   s      r0   Ú_fromString_PUBLIC_OPENSSHzKey._fromString_PUBLIC_OPENSSHa  sK   € ð  �?‰?˜=Ô)ÙÔ*¨4´Ó1BÓCÓDÐDÜ˜4Ÿ:™:›<¨™?Ó+ˆØ×#Ñ# DÓ)Ð)r/   c           	     óì  — |j                  «       j                  «       }t        dj                  |dd «      «      }|j	                  d«      st        d«      ‚|t        d«      d }t        j                  |d«      \  }}}}t        j                  d|dd	 «      d
   }	|	dk7  rt        d«      ‚t        j                  |d	d d«      \  }
}}
|dk7  �r/|st        d«      ‚|dv r&t        j                  }d}t        |dd «      dz  }|}nt        d|›�«      ‚|dk(  rRt        j                  |«      \  }}t        j                  d|dd	 «      d
   }t        j                   ||||z   |d¬«      }nt        d|›�«      ‚t        |«      |z  d
k7  rt        d«      ‚t#         ||d| «      t%        j&                  ||||z    «      t)        «       ¬«      j+                  «       }|j-                  |«      |j/                  «       z   }n|dk7  rt        d|›d�«      ‚|}t        j                  d|dd	 «      d
   }t        j                  d|d	d «      d
   }||k7  rt        d||fz  «      ‚| j1                  |dd «      S )a*  
        Return a private key object corresponding to this OpenSSH private key
        string, in the "openssh-key-v1" format introduced in OpenSSH 6.5.

        The format of an openssh-key-v1 private key string is::
            -----BEGIN OPENSSH PRIVATE KEY-----
            <base64-encoded SSH protocol string>
            -----END OPENSSH PRIVATE KEY-----

        The SSH protocol string is as described in
        U{PROTOCOL.key<https://cvsweb.openbsd.org/cgi-bin/cvsweb/src/usr.bin/ssh/PROTOCOL.key>}.

        @type data: L{bytes}
        @param data: The key data.

        @type passphrase: L{bytes} or L{None}
        @param passphrase: The passphrase the key is encrypted with, or L{None}
        if it is not encrypted.

        @return: A new key.
        @rtype: L{twisted.conch.ssh.keys.Key}
        @raises BadKeyError: if
            * a passphrase is provided for an unencrypted key
            * the SSH protocol encoding is incorrect
        @raises EncryptedKeyError: if
            * a passphrase is not provided for an encrypted key
        r/   rq   éÿÿÿÿó   openssh-key-v1 z"unknown OpenSSH private key formatNé   ú!Lri   r   zDonly OpenSSH private key files containing a single key are supportedr^   ó   noneú0Passphrase must be provided for an encrypted key)s
   aes128-ctrs
   aes192-ctró
   aes256-ctré   r†   é   zunknown encryption type ó   bcryptT)Úignore_few_roundszunknown KDF type zbad padding©Úbackendzprivate key specifies KDF z but no cipherz#check values do not match: %d != %d)ÚstripÚ
splitlinesr   Újoinrœ   r(   Úlenr   rt   ÚstructÚunpackr5   r   ÚAESÚintÚbcryptÚkdfr   r   ÚCTRr   Ú	decryptorÚupdateÚfinalizerš   )rV   rd   rM   ÚlinesÚkeyListÚcipherr¶   Ú
kdfOptionsr€   r‚   Ú_ÚencPrivKeyListÚalgorithmClassÚ	blockSizeÚkeySizeÚivSizeÚsaltÚroundsÚdecKeyr¸   ÚprivKeyListÚcheck1Úcheck2s                          r0   Ú_fromPrivateOpenSSH_v1zKey._fromPrivateOpenSSH_v1v  s¥  € ð: —
‘
“×'Ñ'Ó)ˆÜ˜cŸh™h u¨Q¨r {Ó3Ó4ˆØ×!Ñ!Ð"5Ô6ÜÐBÓCÐCØœ#Ð1Ó2Ð4Ð5ˆÜ(.¯©°W¸aÓ(@Ñ%ˆ��Z Ü�M‰M˜$  R a Ó)¨!Ñ,ˆØ�Š6Üð-óð ô
  &Ÿ|™|¨D°°¨H°aÓ8Ñˆˆ>˜1Ø�WÓÙÜ'ØIóð ð ÐFÑFÜ!+§¡�Ø�	Ü˜f Q q˜kÓ*¨aÑ/�Ø"‘ä!Ð$<¸V¸JÐ"GÓHÐHØ�iÒÜ#Ÿ\™\¨*Ó5‘
��dÜŸ™ t¨T°"°1¨XÓ6°qÑ9�ÜŸ™ØØØ˜fÑ$Øà&*ô‘ô "Ð$5°c°WÐ"=Ó>Ð>Ü�NÓ# iÑ/°AÒ5Ü! -Ó0Ð0ÜÙ˜v h wÐ/Ó0Ü—	‘	˜& ¨7°VÑ+;Ð<Ó=Ü'Ó)ô÷ ‰i‹kð	 ð
 $×*Ñ*¨>Ó:¸Y×=OÑ=OÓ=QÑQ‰Kà�gŠ~Ý!ÚGJÐLóð ð )ˆKÜ—‘˜t [°°! _Ó5°aÑ8ˆÜ—‘˜t [°°1Ð%5Ó6°qÑ9ˆØ�VÒÜÐCÀvÈvÐFVÑVÓWÐWØ×+Ñ+¨K¸¸¨OÓ<Ð<r/   c                ó  — |j                  «       j                  «       }|d   dd }|sd}|dv r	 t        ||t        «       «      } | |«      S t        d|› �«      ‚# t        $ r t        d«      ‚t        $ r t        d«      ‚w xY w)	aÉ  
        Return a private key object corresponding to this OpenSSH private key
        string, in the old PEM-based format.

        The format of a PEM-based OpenSSH private key string is::
            -----BEGIN <key type> PRIVATE KEY-----
            [Proc-Type: 4,ENCRYPTED
            DEK-Info: DES-EDE3-CBC,<initialization value>]
            <base64-encoded ASN.1 structure>
            ------END <key type> PRIVATE KEY------

        The ASN.1 structure of a RSA key is::
            (0, n, e, d, p, q)

        The ASN.1 structure of a DSA key is::
            (0, p, q, g, y, x)

        The ASN.1 structure of a ECDSA key is::
            (ECParameters, OID, NULL)

        @type data: L{bytes}
        @param data: The key data.

        @type passphrase: L{bytes} or L{None}
        @param passphrase: The passphrase the key is encrypted with, or L{None}
        if it is not encrypted.

        @return: A new key.
        @rtype: L{twisted.conch.ssh.keys.Key}
        @raises BadKeyError: if
            * a passphrase is provided for an unencrypted key
            * the ASN.1 encoding is incorrect
        @raises EncryptedKeyError: if
            * a passphrase is not provided for an encrypted key
        r   é   éïÿÿÿN)s   ECs   RSAs   DSAr¥   z&Failed to decode key (Bad Passphrase?)úunknown key type )r­   r®   r   r   Ú	TypeErrorr5   Ú
ValueErrorr(   )rV   rd   rM   r»   ÚkindÚkeys         r0   Ú_fromPrivateOpenSSH_PEMzKey._fromPrivateOpenSSH_PEMÏ  sª   € ðJ —
‘
“×'Ñ'Ó)ˆØ�Q‰x˜˜3Ðˆñ ØˆJØÐ*Ñ*ðLÜ*¨4°¼_Ó=NÓO�ñ �s“8ˆOäÐ 1°$°Ð8Ó9Ð9øô ò Ü'ØFóð ô ò LÜ!Ð"JÓKÐKðLús   °A Á(Bc                ó˜   — |j                  «       j                  «       d   dd dk(  r| j                  ||«      S | j                  ||«      S )aø  
        Return a private key object corresponding to this OpenSSH private key
        string.  If the key is encrypted, passphrase MUST be provided.
        Providing a passphrase for an unencrypted key is an error.

        @type data: L{bytes}
        @param data: The key data.

        @type passphrase: L{bytes} or L{None}
        @param passphrase: The passphrase the key is encrypted with, or L{None}
        if it is not encrypted.

        @return: A new key.
        @rtype: L{twisted.conch.ssh.keys.Key}
        @raises BadKeyError: if
            * a passphrase is provided for an unencrypted key
            * the encoding is incorrect
        @raises EncryptedKeyError: if
            * a passphrase is not provided for an encrypted key
        r   rÍ   rÎ   s   OPENSSH)r­   r®   rË   rÔ   )rV   rd   rM   s      r0   Ú_fromString_PRIVATE_OPENSSHzKey._fromString_PRIVATE_OPENSSH  sO   € ð, �:‰:‹<×"Ñ"Ó$ QÑ'¨¨3Ð/°:Ò=à×-Ñ-¨d°JÓ?Ð?ð ×.Ñ.¨t°ZÓ@Ð@r/   c                ó   — t        j                  t        |dd «      «      }|d   dk(  sJ ‚i }|d   dd D ]3  \  }}t        j                  t        j
                  |«      «      d   ||<   Œ5 |d   d   dk(  r!| j                  |d   |d   |d	   |d
   ¬«      S |d   d   dk(  r| j                  |d   |d   ¬«      S t        d|d   d   › �«      ‚)a  
        Return a public key corresponding to this LSH public key string.
        The LSH public key string format is::
            <s-expression: ('public-key', (<key type>, (<name, <value>)+))>

        The names for a RSA (key type 'rsa-pkcs1-sha1') key are: n, e.
        The names for a DSA (key type 'dsa') key are: y, g, p, q.

        @type data: L{bytes}
        @param data: The key data.

        @return: A new key.
        @rtype: L{twisted.conch.ssh.keys.Key}
        @raises BadKeyError: if the key type is unknown
        rq   r    r   ó
   public-keyNó   dsaó   yó   gó   pó   q©ro   rm   rk   rl   ó   rsa-pkcs1-sha1ó   nó   e©r‚   r�   úunknown lsh key type )	r   Úparser   r   ru   ÚNSr“   r’   r(   ©rV   rd   ÚsexpÚkdr•   s        r0   Ú_fromString_PUBLIC_LSHzKey._fromString_PUBLIC_LSH%  sý   € ô" �{‰{œ; t¨A¨b zÓ2Ó3ˆØ�A‰w˜-Ò'Ð'Ð'ØˆØ˜q™' ! "˜+ò 	8‰JˆD�$Ü—|‘|¤F§I¡I¨d£OÓ4°QÑ7ˆBˆtŠHð	8à�‰7�1‰:˜ÒØ×)Ñ)Ø�T‘(˜b ™h¨"¨T©(°b¸±hð *ó ð ð �!‰W�Q‰ZÐ,Ò,Ø×)Ñ)¨B¨t©H¸¸4¹Ð)ÓAÐAäÐ 5°d¸1±g¸a±j°\ÐBÓCÐCr/   c                óX  — t        j                  |«      }|d   dk(  sJ ‚i }|d   dd D ]3  \  }}t        j                  t        j                  |«      «      d   ||<   Œ5 |d   d   dk(  rCt        |«      dk(  sJ t        |«      «       ‚| j                  |d   |d   |d	   |d
   |d   ¬«      S |d   d   dk(  r_t        |«      dk(  sJ t        |«      «       ‚|d	   |d
   kD  r|d
   |d	   c|d	<   |d
<   | j                  |d   |d   |d   |d	   |d
   ¬«      S t        d|d   d   › �«      ‚)a+  
        Return a private key corresponding to this LSH private key string.
        The LSH private key string format is::
            <s-expression: ('private-key', (<key type>, (<name>, <value>)+))>

        The names for a RSA (key type 'rsa-pkcs1-sha1') key are: n, e, d, p, q.
        The names for a DSA (key type 'dsa') key are: y, g, p, q, x.

        @type data: L{bytes}
        @param data: The key data.

        @return: A new key.
        @rtype: L{twisted.conch.ssh.keys.Key}
        @raises BadKeyError: if the key type is unknown
        r   ó   private-keyrq   NrÙ   r‰   rÚ   rÛ   rÜ   rÝ   ó   xrŠ   ó	   rsa-pkcs1r¨   rà   rá   ó   dr‡   rã   )	r   rä   r   ru   rå   r°   r“   r’   r(   ræ   s        r0   Ú_fromString_PRIVATE_LSHzKey._fromString_PRIVATE_LSHE  sp  € ô" �{‰{˜4Ó ˆØ�A‰w˜.Ò(Ð(Ð(ØˆØ˜q™' ! "˜+ò 	8‰JˆD�$Ü—|‘|¤F§I¡I¨d£OÓ4°QÑ7ˆBˆtŠHð	8à�‰7�1‰:˜ÒÜ�r“7˜a’<Ð(¤ R£Ó(�<Ø×)Ñ)Ø�T‘(˜b ™h¨"¨T©(°b¸±hÀ"ÀTÁ(ð *ó ð ð �!‰W�Q‰Z˜<Ò'Ü�r“7˜a’<Ð(¤ R£Ó(�<Ø�$‰x˜"˜T™(Ò"Ø%'¨¡X¨r°$©xÐ"��4‘˜"˜T™(Ø×)Ñ)Ø�T‘(˜b ™h¨"¨T©(°b¸±hÀ"ÀTÁ(ð *ó ð ô
 Ð 5°d¸1±g¸a±j°\ÐBÓCÐCr/   c                óÌ  — t        j                  |«      \  }}|dk(  rŽt        j                  |«      \  }}t        j                  |«      \  }}t        j                  |«      \  }}t        j                  |«      \  }}t        j                  |«      \  }}| j                  |||||¬«      S |dk(  r§t        j                  |«      \  }}t        j                  |«      \  }	}t        j                  |«      \  }
}t        j                  |«      \  }}t        j                  |«      \  }}t        j                  |«      \  }}| j	                  |
||	|||¬«      S t        d|› �«      ‚)aß  
        Return a private key object corresponsing to the Secure Shell Key
        Agent v3 format.

        The SSH Key Agent v3 format for a RSA key is::
            string 'ssh-rsa'
            integer e
            integer d
            integer n
            integer u
            integer p
            integer q

        The SSH Key Agent v3 format for a DSA key is::
            string 'ssh-dss'
            integer p
            integer q
            integer g
            integer y
            integer x

        @type data: L{bytes}
        @param data: The key data.

        @return: A new key.
        @rtype: L{twisted.conch.ssh.keys.Key}
        @raises BadKeyError: if the key type (the first string) is unknown
        rh   rŠ   rg   ©r‚   r�   rˆ   rk   rl   r—   rÏ   )r   rt   ru   r“   r’   r(   )rV   rd   r   rk   rl   rm   ro   r‹   r�   rˆ   r‚   r—   s               r0   Ú_fromString_AGENTV3zKey._fromString_AGENTV3k  s9  € ô< Ÿ™ TÓ*‰ˆ�Ø�jÒ Ü—l‘l 4Ó(‰GˆAˆtÜ—l‘l 4Ó(‰GˆAˆtÜ—l‘l 4Ó(‰GˆAˆtÜ—l‘l 4Ó(‰GˆAˆtÜ—l‘l 4Ó(‰GˆAˆtØ×)Ñ)¨A°°a¸1ÀÐ)ÓBÐBØ˜
Ò"Ü—l‘l 4Ó(‰GˆAˆtÜ—l‘l 4Ó(‰GˆAˆtÜ—l‘l 4Ó(‰GˆAˆtÜ—l‘l 4Ó(‰GˆAˆtÜ—l‘l 4Ó(‰GˆAˆtÜ—l‘l 4Ó(‰GˆAˆtØ×)Ñ)¨A°°a¸1ÀÀQÐ)ÓGÐGäÐ 1°'°Ð;Ó<Ð<r/   c                ó¢  — |j                  d«      s|j                  d«      ry|j                  d«      ry|j                  d«      ry|j                  d«      ry	|j                  d
«      s"|j                  d«      s|j                  d«      rCt        j                  |«      \  }}d}|r |dz  }t        j                  |«      \  }}|rŒ |dkD  ryyy)z¢
        Guess the type of key in data.  The types map to _fromString_*
        methods.

        @type data: L{bytes}
        @param data: The key data.
        s   ssh-ó   ecdsa-sha2-Úpublic_opensshs
   -----BEGINÚprivate_opensshó   {Ú
public_lshó   (Úprivate_lshs      ssh-s
      ecdsa-s      ssh-ed25519r   rq   ri   Úagentv3r~   N)rœ   r   rt   ru   )rV   rd   Úignoredr€   Úcounts        r0   r_   zKey._guessStringTypeœ  sÀ   € ð �?‰?˜7Ô# t§¡°~Ô'FØ#Ø�_‰_˜]Ô+Ø$Ø�_‰_˜TÔ"ØØ�_‰_˜TÔ"Ø à�O‰OÐ3Ô4Ø�‰Ð8Ô9Ø�‰Ð=Ô>ä"ŸL™L¨Ó.‰MˆG�TØˆEÙØ˜‘
�Ü &§¡¨TÓ 2‘�˜ò ð �qŠyØ àð ?r/   c                óZ  — t        j                  ||¬«      }|€|j                  t        «       «      }nqt        j                  |||t        j
                  ||«      t        j                  ||«      t        j                  ||«      |¬«      }	|	j                  t        «       «      } | |«      S )aÔ  
        Build a key from RSA numerical components.

        @type n: L{int}
        @param n: The 'n' RSA variable.

        @type e: L{int}
        @param e: The 'e' RSA variable.

        @type d: L{int} or L{None}
        @param d: The 'd' RSA variable (optional for a public key).

        @type p: L{int} or L{None}
        @param p: The 'p' RSA variable (optional for a public key).

        @type q: L{int} or L{None}
        @param q: The 'q' RSA variable (optional for a public key).

        @type u: L{int} or L{None}
        @param u: The 'u' RSA variable. Ignored, as its value is determined by
        p and q.

        @rtype: L{Key}
        @return: An RSA key constructed from the values as given.
        )r�   r‚   )rk   rl   rˆ   Údmp1Údmq1ÚiqmpÚpublic_numbers)	r   rv   rw   r   ÚRSAPrivateNumbersÚrsa_crt_dmp1Úrsa_crt_dmq1Úrsa_crt_iqmpÚprivate_key)
rV   r‚   r�   rˆ   rk   rl   r—   ÚpublicNumbersÚ	keyObjectÚprivateNumberss
             r0   r’   zKey._fromRSAComponents¼  s™   € ô6 ×,Ñ,¨q°AÔ6ˆØˆ9à%×0Ñ0´Ó1BÓC‰Iä ×2Ñ2ØØØÜ×%Ñ% a¨Ó+Ü×%Ñ% a¨Ó+Ü×%Ñ% a¨Ó+Ø,ôˆNð '×2Ñ2´?Ó3DÓEˆIá�9‹~Ðr/   c                ó  — t        j                  |t        j                  |||¬«      ¬«      }|€|j                  t	        «       «      }n0t        j
                  ||¬«      }|j                  t	        «       «      } | |«      S )a   
        Build a key from DSA numerical components.

        @type y: L{int}
        @param y: The 'y' DSA variable.

        @type p: L{int}
        @param p: The 'p' DSA variable.

        @type q: L{int}
        @param q: The 'q' DSA variable.

        @type g: L{int}
        @param g: The 'g' DSA variable.

        @type x: L{int} or L{None}
        @param x: The 'x' DSA variable (optional for a public key)

        @rtype: L{Key}
        @return: A DSA key constructed from the values as given.
        rj   rn   )r‹   r  )r   rx   ry   rw   r   ÚDSAPrivateNumbersr  )	rV   ro   rk   rl   rm   r‹   r  r	  r
  s	            r0   r“   zKey._fromDSAComponentsé  sq   € ô. ×,Ñ,Ø¤3×#:Ñ#:¸QÀ!ÀqÔ#Iô
ˆð ˆ9à%×0Ñ0´Ó1BÓC‰Iä ×2Ñ2°QÀ}ÔUˆNØ&×2Ñ2´?Ó3DÓEˆIá�9‹~Ðr/   c                óè   — t        j                  ||t        |   ¬«      }|€|j                  t	        «       «      }n0t        j
                  ||¬«      }|j                  t	        «       «      } | |«      S )a«  
        Build a key from EC components.

        @param x: The affine x component of the public point used for verifying.
        @type x: L{int}

        @param y: The affine y component of the public point used for verifying.
        @type y: L{int}

        @param curve: NIST name of elliptic curve.
        @type curve: L{bytes}

        @param privateValue: The private value.
        @type privateValue: L{int}
        ©r‹   ro   rŽ   )Úprivate_valuer  )r   ÚEllipticCurvePublicNumbersrz   rw   r   ÚEllipticCurvePrivateNumbersr  )rV   r‹   ro   rŽ   r�   r  r	  r
  s           r0   Ú_fromECComponentszKey._fromECComponents  so   € ô$ ×5Ñ5Ø�1œK¨Ñ.ô
ˆð Ðà%×0Ñ0´Ó1BÓC‰Iä×;Ñ;Ø*¸=ôˆNð '×2Ñ2´?Ó3DÓEˆIá�9‹~Ðr/   c                ó²   — |€(t         j                  j                  t        |   |«      }n&t        j                  |t        |   t        «       «      } | |«      S )aa  
        Build a key from an EC encoded point.

        @param encodedPoint: The public point encoded as in SEC 1 v2.0
        section 2.3.3.
        @type encodedPoint: L{bytes}

        @param curve: NIST name of elliptic curve.
        @type curve: L{bytes}

        @param privateValue: The private value.
        @type privateValue: L{int}
        )r   r{   r|   rz   Úderive_private_keyr   )rV   r�   rŽ   r�   r	  s        r0   r–   zKey._fromECEncodedPoint,  sW   € ð  Ðä×1Ñ1×DÑDÜ˜EÑ" Ló‰Iô ×-Ñ-Øœk¨%Ñ0´/Ó2CóˆIñ �9‹~Ðr/   c                óš   — t         �t        €t        d«      ‚|€t         j                  |«      }nt        j	                  |«      } | |«      S )a  Build a key from Ed25519 components.

        @param a: The Ed25519 public key, as defined in RFC 8032 section
            5.1.5.
        @type a: L{bytes}

        @param k: The Ed25519 private key, as defined in RFC 8032 section
            5.1.5.
        @type k: L{bytes}
        z)Ed25519 keys not supported on this system)ÚEd25519PublicKeyÚEd25519PrivateKeyr(   Úfrom_public_bytesÚfrom_private_bytes)rV   rƒ   r‘   r	  s       r0   r}   zKey._fromEd25519ComponentsH  sK   € ô Ð#Ô'8Ð'@ÜÐIÓJÐJàˆ9Ü(×:Ñ:¸1Ó=‰Iä)×<Ñ<¸QÓ?ˆIá�9‹~Ðr/   c                ó   — || _         y)zä
        Initialize with a private or public
        C{cryptography.hazmat.primitives.asymmetric} key.

        @param keyObject: Low level key.
        @type keyObject: C{cryptography.hazmat.primitives.asymmetric} key.
        N)Ú
_keyObject)Úselfr	  s     r0   Ú__init__zKey.__init___  s   € ð $ˆ�r/   c                ó¶   — t        |t        «      rD| j                  «       |j                  «       k(  xr! | j                  «       |j                  «       k(  S t        S )zN
        Return True if other represents an object with the same key.
        )rG   rP   rX   rd   ÚNotImplemented)r  Úothers     r0   Ú__eq__z
Key.__eq__i  sA   € ô �eœSÔ!Ø—9‘9“; %§*¡*£,Ñ.ÒN°4·9±9³;À%Ç*Á*Ã,Ñ3NÐNä!Ð!r/   c                ó”  — | j                  «       dk(  r†| j                  «       }|d   j                  d«      }| j                  «       r
d|dd › d�}n	d|dd › d�}t	        |j                  «       «      D ]  \  }}|dk(  r	|d	|› �z  }Œ|d
|› d|› �z  }Œ  |dz   S dt        | j                  «       «      ›d| j                  «       xr dxs d›d| j                  «       ›d�g}t	        | j                  «       j                  «       «      D ]¢  \  }}|j                  d|› d�«       | j                  «       dk(  r|nt        j                  |«      dd }|sŒK|dd }|dd }d}	t        |«      D ]  }
|	t        |
«      d›d�z   }	Œ t        |«      dk  r|	dd }	|j                  d|	z   «       |rŒXŒ¤ |d   dz   |d<   d
j                  |«      S )z@
        Return a pretty representation of this object.
        ÚECrŽ   r\   z<Elliptic Curve Public Key (éýÿÿÿNz bits)z<Elliptic Curve Private Key (z	
curve:
	ú
z:
	z>
ú<ú z
Public KeyzPrivate Keyz (zattr ú:ÚEd25519ri   é   Ú Ú02xr    ú	ú>)rX   rd   ÚdecodeÚisPublicÚsortedÚitemsr   ÚsizeÚappendr   ÚMPr   Úordr°   r¯   )r  rd   r•   Úoutr‘   Úvr»   ÚbyÚmÚorD   s              r0   Ú__repr__zKey.__repr__r  sð  € ð �9‰9‹;˜$ÒØ—9‘9“;ˆDØ˜‘=×'Ñ'¨Ó0ˆDà�}‰}ŒØ4°T¸"¸#°Y°K¸vÐF‘à5°d¸2¸3°i°[ÀÐG�ä˜tŸz™z›|Ó,ò ,‘��1Ø˜’<Ø˜\¨$¨Ð0Ñ0‘Cà˜R ˜s %¨ sÐ+Ñ+‘Cð	,ð ˜‘;Ðð ô( ! §¡£Õ-Ø—M‘M“OÒ4¨ÒE¸ÑEØ—I‘I•Kð	ðˆEô ˜tŸy™y›{×0Ñ0Ó2Ó3ò +‘��1Ø—‘˜u Q C q˜\Ô*ØŸ)™)›+¨Ò2‘Q¼¿	¹	À!»ÀQÀRÐ8H�ÚØ˜3˜B˜�AØ˜B˜C˜�BØ�AÜ& q›\ò 1˜Ø¤3 q£6¨# ,¨aÐ 0Ñ0™ð1ä˜1“v ’{Ø˜c˜r˜F˜Ø—L‘L ¨¡Ô*ó ð+ð ˜b™	 C™ˆE�"‰IØ—9‘9˜UÓ#Ð#r/   c                ó¦   — t        | j                  t        j                  t        j
                  t        j                  t        j                  f«      S )zl
        Check if this instance is a public key.

        @return: C{True} if this is a public key.
        )
rG   r  r   ÚRSAPublicKeyr   ÚDSAPublicKeyr   r{   r   r  ©r  s    r0   r0  zKey.isPublicž  sA   € ô Ø�O‰Oä× Ñ Ü× Ñ Ü×)Ñ)Ü×(Ñ(ð	ó
ð 	
r/   c                ól   — | j                  «       r| S t        | j                  j                  «       «      S )zä
        Returns a version of this key containing only the public key data.
        If this is a public key, this may or may not be the same object
        as self.

        @rtype: L{Key}
        @return: A public key.
        )r0  rP   r  rw   r@  s    r0   Úpublicz
Key.public®  s*   € ð �=‰=Œ?ØˆKä�t—‘×1Ñ1Ó3Ó4Ð4r/   c           
     ó´  — |t         j                  u r9t        t        t	        | j                  «       «      j                  «       «      «      S |t         j                  u rit        dj                  t        t        | j                  «       «      j                  «       «      D �cg c]  }t        j                  |«      ‘Œ c}«      «      S t        d|› �«      ‚c c}w )aO  
        The fingerprint of a public key consists of the output of the
        message-digest algorithm in the specified format.
        Supported formats include L{FingerprintFormats.MD5_HEX} and
        L{FingerprintFormats.SHA256_BASE64}

        The input to the algorithm is the public key data as specified by [RFC4253].

        The output of sha256[RFC4634] algorithm is presented to the
        user in the form of base64 encoded sha256 hashes.
        Example: C{US5jTUa0kgX5ZxdqaGF0yGRu8EgKXHNmoT8jHKo1StM=}

        The output of the MD5[RFC1321](default) algorithm is presented to the user as
        a sequence of 16 octets printed as hexadecimal with lowercase letters
        and separated by colons.
        Example: C{c1:b1:30:29:d7:b8:de:6c:97:77:10:d7:46:41:63:87}

        @param format: Format for fingerprint generation. Consists
            hash function and representation format.
            Default is L{FingerprintFormats.MD5_HEX}

        @since: 8.2

        @return: the user presentation of this L{Key}'s fingerprint, as a
        string.

        @rtype: L{str}
        ó   :z Unsupported fingerprint format: )r9   r;   r   r   r   r~   Údigestr:   r¯   r   r   ÚbinasciiÚhexlifyr7   )r  Úformatr‹   s      r0   ÚfingerprintzKey.fingerprint¼  s¬   € ð: Ô'×5Ñ5Ñ5Ü¤	¬&°·±³Ó*=×*DÑ*DÓ*FÓ GÓHÐHØÔ)×1Ñ1Ñ1ÜØ—	‘	Ü2;¼CÀÇ	Á	ÃÓ<L×<SÑ<SÓ<UÓ2VÖW¨Q”X×%Ñ% aÕ(ÒWóóð ô 'Ð)IÈ&ÈÐ'RÓSÐSùò	 Xs   Â Cc                óÚ  — t        | j                  t        j                  t        j                  f«      ryt        | j                  t
        j                  t
        j                  f«      ryt        | j                  t        j                  t        j                  f«      ryt        | j                  t        j                  t        j                  f«      ryt        d| j                  ›�«      ‚)zÓ
        Return the type of the object we wrap.  Currently this can only be
        'RSA', 'DSA', 'EC', or 'Ed25519'.

        @rtype: L{str}
        @raises RuntimeError: If the object type is unknown.
        ÚRSAÚDSAr#  r)  zunknown type of object: )rG   r  r   r>  ÚRSAPrivateKeyr   r?  ÚDSAPrivateKeyr   r{   ÚEllipticCurvePrivateKeyr   r  r  ÚRuntimeErrorr@  s    r0   rX   zKey.typeä  s®   € ô �d—o‘o¬×(8Ñ(8¼#×:KÑ:KÐ'LÔMØÜ˜Ÿ™¬#×*:Ñ*:¼C×<MÑ<MÐ)NÔOØÜØ�O‰Oœb×7Ñ7¼×9SÑ9SÐTô
ð ÜØ�O‰Oœg×6Ñ6¼×8QÑ8QÐRô
ð äÐ!9¸$¿/¹/Ð9LÐMÓNÐNr/   c                óÈ   — | j                  «       dk(  r9dt        | j                  j                  j                  j                  d«         z   S ddddœ| j                  «          S )aÇ  
        Get the type of the object we wrap as defined in the SSH protocol,
        defined in RFC 4253, Section 6.6 and RFC 8332, section 4 (this is a
        public key format name, not a public key algorithm name). Currently
        this can only be b'ssh-rsa', b'ssh-dss', b'ecdsa-sha2-[identifier]'
        or b'ssh-ed25519'.

        identifier is the standard NIST curve name

        @return: The key type format.
        @rtype: L{bytes}
        r#  rô   rŒ   rg   rh   rr   )rK  rL  r)  )rX   r”   r  rŽ   r•   rK   r@  s    r0   ÚsshTypezKey.sshTypeû  sd   € ð �9‰9‹;˜$Òà¤¨D¯O©O×,AÑ,A×,FÑ,F×,MÑ,MÈgÓ,VÑ!WÑWðð
 "Ø!Ø)ñð �i‰i‹kñ	ð r/   c                óR   — | j                  «       dk(  rg d¢S | j                  «       gS )zÀ
        Get the public key signature algorithms supported by this key.

        @return: A list of supported public key signature algorithm names.
        @rtype: L{list} of L{bytes}
        rK  )ó   rsa-sha2-512ó   rsa-sha2-256rg   )rX   rR  r@  s    r0   ÚsupportedSignatureAlgorithmsz Key.supportedSignatureAlgorithms  s'   € ð �9‰9‹;˜%ÒÚAÐAà—L‘L“NÐ#Ð#r/   c                óþ  — | j                  «       dk(  rj|| j                  «       k(  rV| j                  «       }|dk  rt        j                  «       S |dk  rt        j
                  «       S t        j                  «       S yt        j                  «       t        j                  «       t        j                  «       t        j                  «       t        j                  «       dœj                  | j                  «       |f«      S )zµ
        Return a hash algorithm for this key type given an SSH signature
        algorithm name, or L{None} if no such hash algorithm is defined for
        this key type.
        r#  é   i€  N))rK  rg   )rK  rU  )rK  rT  )rL  rh   )r)  rr   )	rX   rR  r3  r   ÚSHA256ÚSHA384ÚSHA512ÚSHA1Úget)r  ÚsignatureTyperÃ   s      r0   Ú_getHashAlgorithmzKey._getHashAlgorithm  s°   € ð �9‰9‹;˜$Òà §¡£Ò.ØŸ)™)›+�Ø˜c’>Ü!Ÿ=™=›?Ð*Ø ’^Ü!Ÿ=™=›?Ð*ä!Ÿ=™=›?Ð*àô &,§[¡[£]Ü*0¯-©-«/Ü*0¯-©-«/Ü%+§[¡[£]Ü-3¯]©]«_ñ÷ ‰c�4—9‘9“; Ð.Ó/ð0r/   c                óÖ   — | j                   €y| j                  «       dk(  r | j                   j                  j                  S | j                  «       dk(  ry| j                   j                  S )zv
        Return the size of the object we wrap.

        @return: The size of the key.
        @rtype: L{int}
        r   r#  r)  rX  )r  rX   rŽ   Úkey_sizer@  s    r0   r3  zKey.size:  sV   € ð �?‰?Ð"ØØ�Y‰Y‹[˜DÒ Ø—?‘?×(Ñ(×1Ñ1Ð1Ø�Y‰Y‹[˜IÒ%ØØ�‰×'Ñ'Ð'r/   c           	     óR	  — t        | j                  t        j                  «      r3| j                  j	                  «       }|j
                  |j                  dœS t        | j                  t        j                  «      r‘| j                  j                  «       }|j                  j
                  |j                  j                  |j                  |j                  |j                  t        j                  |j                  |j                  «      dœS t        | j                  t        j                  «      rg| j                  j	                  «       }|j                  |j                   j"                  |j                   j                  |j                   j                  dœS t        | j                  t        j$                  «      rš| j                  j                  «       }|j&                  |j                  j                  |j                  j                   j"                  |j                  j                   j                  |j                  j                   j                  dœS t        | j                  t(        j*                  «      rB| j                  j	                  «       }|j&                  |j                  | j-                  «       dœS t        | j                  t(        j.                  «      ra| j                  j                  «       }|j                  j&                  |j                  j                  |j0                  | j-                  «       dœS t        | j                  t2        j4                  «      rNd| j                  j7                  t8        j:                  j<                  t8        j>                  j<                  «      iS t        | j                  t2        j@                  «      rº| j                  jC                  «       j7                  t8        j:                  j<                  t8        j>                  j<                  «      | j                  jE                  t8        j:                  j<                  t8        jF                  j<                  t9        jH                  «       «      dœS tK        d	| j                  › �«      ‚)
z_
        Return the values of the public key as a dictionary.

        @rtype: L{dict}
        râ   rñ   rÞ   )r‹   ro   rm   rk   rl   r  )r‹   ro   r�   rŽ   rƒ   )rƒ   r‘   zUnexpected key type: )&rG   r  r   r>  r  r‚   r�   rM  Úprivate_numbersrˆ   rk   rl   r  r   r?  ro   rp   rm   rN  r‹   r   r{   rR  rO  r  r   r  Úpublic_bytesr   ÚEncodingÚRawÚPublicFormatr  rw   Úprivate_bytesÚPrivateFormatÚNoEncryptionrP  )r  Úrsa_pub_numbersÚrsa_priv_numbersÚdsa_pub_numbersÚdsa_priv_numbersÚec_pub_numbersÚec_priv_numberss          r0   rd   zKey.dataI  sr  € ô �d—o‘o¤s×'7Ñ'7Ô8Ø"Ÿo™o×<Ñ<Ó>ˆOà$×&Ñ&Ø$×&Ñ&ñð ô ˜Ÿ™¬×):Ñ):Ô;Ø#Ÿ™×>Ñ>Ó@Ðà%×4Ñ4×6Ñ6Ø%×4Ñ4×6Ñ6Ø%×'Ñ'Ø%×'Ñ'Ø%×'Ñ'ä×%Ñ%Ð&6×&8Ñ&8Ð:J×:LÑ:LÓMñð ô ˜Ÿ™¬×)9Ñ)9Ô:Ø"Ÿo™o×<Ñ<Ó>ˆOà$×&Ñ&Ø$×6Ñ6×8Ñ8Ø$×6Ñ6×8Ñ8Ø$×6Ñ6×8Ñ8ñ	ð ô ˜Ÿ™¬×):Ñ):Ô;Ø#Ÿ™×>Ñ>Ó@Ðà%×'Ñ'Ø%×4Ñ4×6Ñ6Ø%×4Ñ4×FÑF×HÑHØ%×4Ñ4×FÑF×HÑHØ%×4Ñ4×FÑF×HÑHñð ô ˜Ÿ™¬×)BÑ)BÔCØ!Ÿ_™_×;Ñ;Ó=ˆNà#×%Ñ%Ø#×%Ñ%ØŸ™›ñð ô
 ˜Ÿ™¬×)CÑ)CÔDØ"Ÿo™o×=Ñ=Ó?ˆOà$×3Ñ3×5Ñ5Ø$×3Ñ3×5Ñ5Ø /× =Ñ =ØŸ™›ñ	ð ô ˜Ÿ™¬×)AÑ)AÔBà�T—_‘_×1Ñ1Ü!×*Ñ*×.Ñ.´×0JÑ0J×0NÑ0Nóðð ô
 ˜Ÿ™¬×)BÑ)BÔCà—_‘_×/Ñ/Ó1×>Ñ>Ü!×*Ñ*×.Ñ.´×0JÑ0J×0NÑ0Nóð —_‘_×2Ñ2Ü!×*Ñ*×.Ñ.Ü!×/Ñ/×3Ñ3Ü!×.Ñ.Ó0óñ		ð 	ô Ð!6°t·±Ð6GÐHÓIÐIr/   c                óª  — | j                  «       }| j                  «       }|dk(  rGt        j                  d«      t        j                  |d   «      z   t        j                  |d   «      z   S |dk(  ryt        j                  d«      t        j                  |d   «      z   t        j                  |d   «      z   t        j                  |d	   «      z   t        j                  |d
   «      z   S |dk(  r¤| j
                  j                  j                  dz   dz  }t        j                  |d   «      t        j                  |d   dd «      z   t        j                  dt        j                  |d   |«      z   t        j                  |d
   |«      z   «      z   S |dk(  r.t        j                  d«      t        j                  |d   «      z   S t        d|› �«      ‚)a•  
        Return the public key blob for this key. The blob is the
        over-the-wire format for public keys.

        SECSH-TRANS RFC 4253 Section 6.6.

        RSA keys::
            string 'ssh-rsa'
            integer e
            integer n

        DSA keys::
            string 'ssh-dss'
            integer p
            integer q
            integer g
            integer y

        EC keys::
            string 'ecdsa-sha2-[identifier]'
            integer x
            integer y

            identifier is the standard NIST curve name

        Ed25519 keys::
            string 'ssh-ed25519'
            string a

        @rtype: L{bytes}
        rK  rg   r�   r‚   rL  rh   rk   rl   rm   ro   r#  é   r¨   rŽ   éøÿÿÿNó   r‹   r)  rr   rƒ   úunknown key type: )rX   rd   r   rå   r5  r  rŽ   ra  r
   r   r(   )r  rX   rd   Ú
byteLengths       r0   r~   zKey.blob•  s¥  € ð@ �y‰y‹{ˆØ�y‰y‹{ˆØ�5Š=Ü—9‘9˜ZÓ(¬6¯9©9°T¸#±YÓ+?Ñ?Ä&Ç)Á)ÈDÐQTÉIÓBVÑVÐVØ�UŠ]ä—	‘	˜*Ó%Ü—)‘)˜D ™IÓ&ñ'ä—)‘)˜D ™IÓ&ñ'ô —)‘)˜D ™IÓ&ñ'ô —)‘)˜D ™IÓ&ñ	'ðð �TŠ\ØŸ/™/×/Ñ/×8Ñ8¸1Ñ<ÀÑBˆJä—	‘	˜$˜w™-Ó(Ü—)‘)˜D ™M¨"¨#Ð.Ó/ñ0ä—)‘)ØÜ×(Ñ(¨¨c©°JÓ?ñ@ä×(Ñ(¨¨c©°JÓ?ñ@óñðð �YÒÜ—9‘9˜^Ó,¬v¯y©y¸¸c¹Ó/CÑCÐCäÐ 2°4°&Ð9Ó:Ð:r/   c                óF  — | j                  «       }| j                  «       }|dk(  rÄt        j                  |d   |d   «      }t	        j
                  d«      t	        j                  |d   «      z   t	        j                  |d   «      z   t	        j                  |d   «      z   t	        j                  |«      z   t	        j                  |d   «      z   t	        j                  |d   «      z   S |dk(  r’t	        j
                  d	«      t	        j                  |d   «      z   t	        j                  |d   «      z   t	        j                  |d
   «      z   t	        j                  |d   «      z   t	        j                  |d   «      z   S |dk(  r½| j                  j                  «       j                  t        j                  j                  t        j                  j                  «      }t	        j
                  |d   «      t	        j
                  |d   dd «      z   t	        j
                  |«      z   t	        j                  |d   «      z   S |dk(  rMt	        j
                  d«      t	        j
                  |d   «      z   t	        j
                  |d   |d   z   «      z   S t        d|› �«      ‚)a1  
        Return the private key blob for this key. The blob is the
        over-the-wire format for private keys:

        Specification in OpenSSH PROTOCOL.agent

        RSA keys::

            string 'ssh-rsa'
            integer n
            integer e
            integer d
            integer u
            integer p
            integer q

        DSA keys::

            string 'ssh-dss'
            integer p
            integer q
            integer g
            integer y
            integer x

        EC keys::

            string 'ecdsa-sha2-[identifier]'
            integer x
            integer y
            integer privateValue

            identifier is the NIST standard curve name.

        Ed25519 keys::

            string 'ssh-ed25519'
            string a
            string k || a
        rK  rk   rl   rg   r‚   r�   rˆ   rL  rh   rm   ro   r‹   r#  rŽ   rs  Nr�   r)  rr   rƒ   r‘   ru  )rX   rd   r   r  r   rå   r5  r  rw   rd  r   re  ÚX962rg  ÚUncompressedPointr(   )r  rX   rd   r  ÚencPubs        r0   ÚprivateBlobzKey.privateBlobÑ  sZ  € ðR �y‰y‹{ˆØ�y‰y‹{ˆØ�5Š=Ü×#Ñ# D¨¡I¨t°C©yÓ9ˆDä—	‘	˜*Ó%Ü—)‘)˜D ™IÓ&ñ'ä—)‘)˜D ™IÓ&ñ'ô —)‘)˜D ™IÓ&ñ'ô —)‘)˜D“/ñ	"ô
 —)‘)˜D ™IÓ&ñ'ô —)‘)˜D ™IÓ&ñ'ðð �UŠ]ä—	‘	˜*Ó%Ü—)‘)˜D ™IÓ&ñ'ä—)‘)˜D ™IÓ&ñ'ô —)‘)˜D ™IÓ&ñ'ô —)‘)˜D ™IÓ&ñ	'ô
 —)‘)˜D ™IÓ&ñ'ðð �TŠ\Ø—_‘_×/Ñ/Ó1×>Ñ>Ü×&Ñ&×+Ñ+Ü×*Ñ*×<Ñ<óˆFô
 —	‘	˜$˜w™-Ó(Ü—)‘)˜D ™M¨"¨#Ð.Ó/ñ0ä—)‘)˜FÓ#ñ$ô —)‘)˜D Ñ0Ó1ñ2ðð �YÒä—	‘	˜.Ó)Ü—)‘)˜D ™IÓ&ñ'ä—)‘)˜D ™I¨¨S©	Ñ1Ó2ñ3ðô Ð 2°4°&Ð9Ó:Ð:r/   ÚextraÚcommentrM   c                ó2  — |�1t        j                  dt        d¬«       | j                  «       r|}n|}t	        |t
        «      r|j                  d«      }t        |«      }t        | d|j                  «       › �d«      }|€t        d|› �«      ‚ ||||¬«      S )	a  
        Create a string representation of this key.  If the key is a private
        key and you want the representation of its public key, use
        C{key.public().toString()}.  type maps to a _toString_* method.

        @param type: The type of string to emit.  Currently supported values
            are C{'OPENSSH'}, C{'LSH'}, and C{'AGENTV3'}.
        @type type: L{str}

        @param extra: Any extra data supported by the selected format which
            is not part of the key itself.  For public OpenSSH keys, this is
            a comment.  For private OpenSSH keys, this is a passphrase to
            encrypt with.  (Deprecated since Twisted 20.3.0; use C{comment}
            or C{passphrase} as appropriate instead.)
        @type extra: L{bytes} or L{unicode} or L{None}

        @param subtype: A subtype of the requested C{type} to emit.  Only
            supported for private OpenSSH keys, for which the currently
            supported subtypes are C{'PEM'} and C{'v1'}.  If not given, an
            appropriate default is used.
        @type subtype: L{str} or L{None}

        @param comment: A comment to include with the key.  Only supported
            for OpenSSH keys.

            Present since Twisted 20.3.0.

        @type comment: L{bytes} or L{unicode} or L{None}

        @param passphrase: A passphrase to encrypt the key with.  Only
            supported for private OpenSSH keys.

            Present since Twisted 20.3.0.

        @type passphrase: L{bytes} or L{unicode} or L{None}

        @rtype: L{bytes}
        Nz„The 'extra' argument to twisted.conch.ssh.keys.Key.toString was deprecated in Twisted 20.3.0; use 'comment' or 'passphrase' instead.r¢   )Ú
stacklevelr\   Ú
_toString_ru  )Úsubtyper}  rM   )ÚwarningsÚwarnÚDeprecationWarningr0  rG   rH   rK   rN   r`   ra   r(   )r  rX   r|  r�  r}  rM   re   s          r0   ÚtoStringzKey.toString$  sž   € ðZ Ðä�M‰MðIô #Øõð �}‰}ŒØ‘à"�
Ü�gœsÔ#Ø—n‘n WÓ-ˆGÜ)¨*Ó5ˆ
Ü˜ ¨D¯J©J«L¨>Ð:¸DÓAˆØˆ>ÜÐ 2°4°&Ð9Ó:Ð:Ù˜g¨wÀ:ÔNÐNr/   c                óž  — | j                  «       dk(  rd|sd}| j                  j                  t        j                  j
                  t        j                  j
                  «      dz   |z   j                  «       S t        | j                  «       «      j                  dd«      }|sd}| j                  «       dz   |z   dz   |z   j                  «       S )a  
        Return a public OpenSSH key string.

        See _fromString_PUBLIC_OPENSSH for the string format.

        @type comment: L{bytes} or L{None}
        @param comment: A comment to include with the key, or L{None} to
        omit the comment.
        r#  r/   ó    ó   
)rX   r  rd  r   re  ÚOpenSSHrg  r­   r   r~   ÚreplacerR  )r  r}  Úb64Datas      r0   Ú_toPublicOpenSSHzKey._toPublicOpenSSHf  s»   € ð �9‰9‹;˜$ÒÙØ�à—‘×,Ñ,Ü!×*Ñ*×2Ñ2´M×4NÑ4N×4VÑ4Vóð ñð ñ	÷
 ‰e‹gðô ˜dŸi™i›kÓ*×2Ñ2°5¸#Ó>ˆÙØˆGØ—‘“ Ñ%¨Ñ/°$Ñ6¸Ñ@×GÑGÓIÐIr/   c           	     óè  — |rkt         j                  }d}d}|j                  dz  }d}|}t        j                  |«      }	d}
t        j                  |	«      t        j                  d|
«      z   }nd}d}d}d}t        j                  d	«      }||z   | j                  «       z   t        j                  |xs d«      z   }d
}t        |«      |z  r&|dz  }|t        |dz  f«      z  }t        |«      |z  rŒ&|r„t        j                  |	z   d«      }t         |d| «      t        j                   ||||z    «      t#        «       ¬«      j%                  «       }|j'                  |«      |j)                  «       z   }n|}dt        j                  |«      z   t        j                  |«      z   t        j                  |«      z   t        j                  dd«      z   t        j                  | j+                  «       «      z   t        j                  |«      z   }t-        |«      j/                  dd«      }dgt1        d
t        |«      d«      D �cg c]
  }|||dz    ‘Œ c}z   dgz   }dj3                  |«      dz   S c c}w )aP  
        Return a private OpenSSH key string, in the "openssh-key-v1" format
        introduced in OpenSSH 6.5.

        See _fromPrivateOpenSSH_v1 for the string format.

        @type passphrase: L{bytes} or L{None}
        @param passphrase: The passphrase to encrypt the key with, or L{None}
        if it is not encrypted.
        r¦   r©   r¨   r�   éd   r£   r¤   r/   ri   r   rq   éÿ   Nr«   r¡   rˆ  s#   -----BEGIN OPENSSH PRIVATE KEY-----é@   s!   -----END OPENSSH PRIVATE KEY-----)r   r³   Ú
block_sizer   ÚsecureRandomr   rå   r±   Úpackr{  r°   Úbytesrµ   r¶   r   r   r·   r   Ú	encryptorr¹   rº   r~   r   rŠ  Úranger¯   )r  r}  rM   r½   Ú
cipherNameÚkdfNamerÂ   rÃ   rÄ   rÅ   rÆ   r¾   ÚcheckrÈ   ÚpadByteÚencKeyr•  rÀ   r~   r‹  Úir»   s                         r0   Ú_toPrivateOpenSSH_v1zKey._toPrivateOpenSSH_v1€  sq  € ñ ô  —^‘^ˆFØ&ˆJØˆGØ×)Ñ)¨QÑ.ˆIØˆGØˆFÜ×)Ñ)¨&Ó1ˆDØˆFÜŸ™ 4›¬6¯;©;°t¸VÓ+DÑD‰Jà ˆJØˆGØˆIØˆJÜ×&Ñ& qÓ)ˆØ˜e‘m d×&6Ñ&6Ó&8Ñ8¼6¿9¹9ÀWÂ^ÐPSÓ;TÑTˆØˆÜ�+Ó Ò*Ø�q‰LˆGØœ5 '¨D¡.Ð!2Ó3Ñ3ˆKô �+Ó Ó*ñ Ü—Z‘Z 
¨D°'¸FÑ2BÀCÓHˆFÜÙ�v˜h˜wÐ'Ó(Ü—	‘	˜& ¨7°VÑ+;Ð<Ó=Ü'Ó)ô÷ ‰i‹kð	 ð
 '×-Ñ-¨kÓ:¸Y×=OÑ=OÓ=QÑQ‰Nà(ˆNàÜ�i‰i˜
Ó#ñ$ä�i‰i˜Ó ñ!ô �i‰i˜
Ó#ñ$ô �k‰k˜$ Ó"ñ	#ô
 �i‰i˜Ÿ	™	›Ó$ñ%ô �i‰i˜Ó'ñ(ð 	ô ˜dÓ#×+Ñ+¨E°3Ó7ˆà3Ð4Ü,1°!´S¸³\À2Ó,FÖG qˆw�q˜1˜r™6Ò"ÒGñHà3Ð4ñ5ð 	ð
 �z‰z˜%Ó  5Ñ(Ð(ùò Hs   ÉI/c                óZ  — |st        j                  «       }nt        j                  |«      }| j                  «       dk7  rM| j                  j                  t         j                  j                  t         j                  j                  |«      S | j                  «       dk(  sJ ‚t        d«      ‚)a,  
        Return a private OpenSSH key string, in the old PEM-based format.

        See _fromPrivateOpenSSH_PEM for the string format.

        @type passphrase: L{bytes} or L{None}
        @param passphrase: The passphrase to encrypt the key with, or L{None}
        if it is not encrypted.
        r)  zBcannot serialize Ed25519 key to OpenSSH PEM format; use v1 instead)r   rj  ÚBestAvailableEncryptionrX   r  rh  re  ÚPEMri  ÚTraditionalOpenSSLrÑ   )r  rM   r•  s      r0   Ú_toPrivateOpenSSH_PEMzKey._toPrivateOpenSSH_PEM¾  s‘   € ñ ä%×2Ñ2Ó4‰Iä%×=Ñ=¸jÓIˆIØ�9‰9‹;˜)Ò#Ø—?‘?×0Ñ0Ü×&Ñ&×*Ñ*Ü×+Ñ+×>Ñ>Øóð ð —9‘9“; )Ò+Ð+Ð+ÜØWóð r/   c                óî   — | j                  «       r| j                  |¬«      S |dk(  s|€&| j                  «       dk(  r| j                  ||¬«      S |�|dk(  r| j	                  |¬«      S t        d|› �«      ‚)ar  
        Return a public or private OpenSSH string.  See
        L{_fromString_PUBLIC_OPENSSH} and L{_fromPrivateOpenSSH_PEM} for the
        string formats.

        @param subtype: A subtype to emit.  Only supported for private keys,
            for which the currently supported subtypes are C{'PEM'} and C{'v1'}.
            If not given, an appropriate default is used.
        @type subtype: L{str} or L{None}

        @param comment: Comment for a public key.
        @type comment: L{bytes}

        @param passphrase: Passphrase for a private key.
        @type passphrase: L{bytes}

        @rtype: L{bytes}
        )r}  Úv1r)  )r}  rM   r   rL   zunknown subtype )r0  rŒ  rX   r�  r¢  rÑ   )r  r�  r}  rM   s       r0   Ú_toString_OPENSSHzKey._toString_OPENSSHÚ  s‚   € ð& �=‰=Œ?Ø×(Ñ(°Ð(Ó9Ð9à˜Š_  °T·Y±Y³[ÀIÒ5MØ×,Ñ,°WÈÐ,ÓTÐTØˆ_ ¨5Ò 0Ø×-Ñ-¸Ð-ÓDÐDäÐ/°¨yÐ9Ó:Ð:r/   c                óD  — | j                  «       }| j                  «       }| j                  «       �r|dk(  rRt        j                  dddt        j                  |d   «      dd gdt        j                  |d	   «      dd gggg«      }n�|d
k(  rŠt        j                  dddt        j                  |d   «      dd gdt        j                  |d   «      dd gdt        j                  |d   «      dd gdt        j                  |d   «      dd gggg«      }nt        d|› �«      ‚dt        |«      j                  dd«      z   dz   S |dk(  �r|d   |d   }}t        j                  ||«      }t        j                  dddt        j                  |d   «      dd gdt        j                  |d	   «      dd gdt        j                  |d   «      dd gdt        j                  |«      dd gdt        j                  |«      dd gdt        j                  |d   |dz
  z  «      dd gdt        j                  |d   |dz
  z  «      dd gd t        j                  |«      dd gg	gg«      S |d
k(  r¥t        j                  dddt        j                  |d   «      dd gdt        j                  |d   «      dd gdt        j                  |d   «      dd gdt        j                  |d   «      dd gd!t        j                  |d"   «      dd gggg«      S t        d|› d#�«      ‚)$z¤
        Return a public or private LSH key.  See _fromString_PUBLIC_LSH and
        _fromString_PRIVATE_LSH for the key formats.

        @rtype: L{bytes}
        rK  rØ   rß   rà   r‚   ri   Nrá   r�   rL  rÙ   rÜ   rk   rÝ   rl   rÛ   rm   rÚ   ro   rÏ   r÷   rˆ  r/   ó   }rë   rí   rî   rˆ   ó   arq   ó   bó   crì   r‹   ú')rd   rX   r0  r   r“  r   r5  r(   r   rŠ  r   r  )r  Úkwargsrd   rX   ÚkeyDatark   rl   r  s           r0   Ú_toString_LSHzKey._toString_LSH÷  se  € ð �y‰y‹{ˆØ�y‰y‹{ˆØ�=‰=�?Ø�uŠ}ÜŸ*™*ð *à 1Ø!%¤v§y¡y°°c±Ó';¸A¸BÐ'?Ð @Ø!%¤v§y¡y°°c±Ó';¸A¸BÐ'?Ð @ððð	ó‘ð ˜’ÜŸ*™*ð *à &Ø!%¤v§y¡y°°c±Ó';¸A¸BÐ'?Ð @Ø!%¤v§y¡y°°c±Ó';¸A¸BÐ'?Ð @Ø!%¤v§y¡y°°c±Ó';¸A¸BÐ'?Ð @Ø!%¤v§y¡y°°c±Ó';¸A¸BÐ'?Ð @ðð	ðó‘ô "Ð$5°d°VÐ"<Ó=Ð=Øœ+ gÓ.×6Ñ6°u¸cÓBÑBÀTÑIÐIà�u‹}Ø˜C‘y $ s¡)�1�Ü×'Ñ'¨¨1Ó-�Ü—z‘zð +à ,Ø!%¤v§y¡y°°c±Ó';¸A¸BÐ'?Ð @Ø!%¤v§y¡y°°c±Ó';¸A¸BÐ'?Ð @Ø!%¤v§y¡y°°c±Ó';¸A¸BÐ'?Ð @Ø!%¤v§y¡y°£|°A°BÐ'7Ð 8Ø!%¤v§y¡y°£|°A°BÐ'7Ð 8Ø!%¤v§y¡y°°c±¸aÀ!¹eÑ1DÓ'EÀaÀbÐ'IÐ JØ!%¤v§y¡y°°c±¸aÀ!¹eÑ1DÓ'EÀaÀbÐ'IÐ JØ!%¤v§y¡y°£°q°rÐ':Ð ;ð
ððóð ð$ ˜’Ü—z‘zð +à &Ø!%¤v§y¡y°°c±Ó';¸A¸BÐ'?Ð @Ø!%¤v§y¡y°°c±Ó';¸A¸BÐ'?Ð @Ø!%¤v§y¡y°°c±Ó';¸A¸BÐ'?Ð @Ø!%¤v§y¡y°°c±Ó';¸A¸BÐ'?Ð @Ø!%¤v§y¡y°°c±Ó';¸A¸BÐ'?Ð @ðð
ðóð ô  "Ð$5°d°V¸1Ð"=Ó>Ð>r/   c                óŒ  — | j                  «       }| j                  «       s¤| j                  «       dk(  r|d   |d   |d   |d   |d   |d   f}n)| j                  «       dk(  r|d   |d   |d	   |d
   |d   f}t        j                  | j                  «       «      dj                  t        t        j                  «      «      z   S y)zŒ
        Return a private Secure Shell Agent v3 key.  See
        _fromString_AGENTV3 for the key format.

        @rtype: L{bytes}
        rK  r�   rˆ   r‚   r—   rk   rl   rL  rm   ro   r‹   r/   N)	rd   r0  rX   r   rå   rR  r¯   Úmapr5  )r  r¬  rd   Úvaluess       r0   Ú_toString_AGENTV3zKey._toString_AGENTV3I  s¾   € ð �y‰y‹{ˆØ�}‰}ŒØ�y‰y‹{˜eÒ#à˜‘IØ˜‘IØ˜‘IØ˜‘IØ˜‘IØ˜‘Ið‘ð —‘“ Ò%Ø˜s™) T¨#¡Y°°S±	¸4À¹9ÀdÈ3ÁiÐP�Ü—9‘9˜TŸ\™\›^Ó,¨s¯x©x¼¼F¿I¹IÀvÓ8NÓ/OÑOÐOð r/   c                ól  — | j                  «       }|€| j                  «       }| j                  |«      }|€t        d|› d|› d�«      ‚|dk(  rF| j                  j                  |t        j                  «       |«      }t        j                  |«      }�n‹|dk(  rX| j                  j                  ||«      }t        |«      \  }}t        j                  t        |d«      t        |d«      z   «      }�n.|dk(  rö| j                  j                  |t        j                  |«      «      }	t        |	«      \  }}t        |«      }
t        |«      }t        |
d   «      t        u rt        |
d   «      }n|
d   }|d	z  rd
|
z   }
t        |d   «      t        u rt        |d   «      }n|d   }|d	z  rd
|z   }t        j                  t        j                  |
«      t        j                  |«      z   «      }n3|dk(  r.t        j                  | j                  j                  |«      «      }t        j                  |«      z   S )a¥  
        Sign some data with this key.

        SECSH-TRANS RFC 4253 Section 6.6.

        @type data: L{bytes}
        @param data: The data to sign.

        @type signatureType: L{bytes}
        @param signatureType: The SSH public key algorithm name to sign this
        data with, or L{None} to use a reasonable default for the key.

        @rtype: L{bytes}
        @return: A signature for the given data.
        zpublic key signature algorithm z is not defined for z keysrK  rL  é   r#  r   é€   ó    r)  )rX   rR  r_  r2   r  Úsignr   ÚPKCS1v15r   rå   r#   r   r   ÚECDSArH   r6  )r  rd   r^  r   ÚhashAlgorithmÚsigÚretÚrÚsÚ	signaturerR   ÚsbÚrcompÚscomps                 r0   r·  zKey.sign_  s÷  € ð  —)‘)“+ˆØÐ ð
 !ŸL™L›NˆMà×.Ñ.¨}Ó=ˆØÐ Ü,Ø1°-°ð AØ&˜i uð.óð ð
 �eÒØ—/‘/×&Ñ& t¬W×-=Ñ-=Ó-?ÀÓOˆCÜ—)‘)˜C“.ŠCà˜ÒØ—/‘/×&Ñ& t¨]Ó;ˆCÜ)¨#Ó.‰FˆQ�ô
 —)‘)œL¨¨BÓ/´,¸qÀ"Ó2EÑEÓFŠCà˜Š_ØŸ™×,Ñ,¨T´2·8±8¸MÓ3JÓKˆIÜ)¨)Ó4‰FˆQ�ä˜a“ˆBÜ˜a“ˆBô �B�q‘E‹{œcÑ!Ü˜B˜q™E›
‘à˜1™�ð �tŠ|Ø˜r‘\�ä�B�q‘E‹{œcÑ!Ü˜B˜q™E›
‘à˜1™�à�tŠ|Ø˜r‘\�ä—)‘)œFŸI™I b›M¬F¯I©I°b«MÑ9Ó:‰Cà˜	Ò!Ü—)‘)˜DŸO™O×0Ñ0°Ó6Ó7ˆCÜ�y‰y˜Ó'¨#Ñ-Ð-r/   c                óà  — t        |«      dk(  rdt        j                  |«      }}nt        j                  |«      \  }}| j	                  |«      }|€y| j                  «       }|dk(  r\| j                  }| j                  «       s|j                  «       }t        j                  |«      d   |t        j                  «       |f}�nŒ|dk(  rˆt        j                  |«      d   }t        j                  |dd d	«      }	t        j                  |dd d	«      }
t        |	|
«      }| j                  }| j                  «       s|j                  «       }|||f}nÿ|d
k(  r¯t        j                  |«      d   }t        j                  |d«      \  }}}t        j                  |d	«      }	t        j                  |d	«      }
t        |	|
«      }| j                  }| j                  «       s|j                  «       }||t        j                  |«      f}nK|dk(  rF| j                  }| j                  «       s|j                  «       }t        j                  |«      d   |f}	  j                   Ž  y# t"        $ r Y yw xY w)a  
        Verify a signature using this key.

        @type signature: L{bytes}
        @param signature: The signature to verify.

        @type data: L{bytes}
        @param data: The signed data.

        @rtype: L{bool}
        @return: C{True} if the signature is valid.
        é(   rh   NFrK  r   rL  r´  Úbigr#  r^   r)  T)r°   r   rå   rt   r_  rX   r  r0  rw   r   r¸  r´   Ú
from_bytesr$   r   r¹  Úverifyr   )r  r¿  rd   r^  rº  r   r‘   ÚargsÚconcatenatedSignaturer½  r¾  ÚrstrÚsstrr€   s                 r0   rÇ  z
Key.verify«  s$  € ô ˆy‹>˜RÒà'1´6·9±9¸YÓ3G˜9‰Mä'-§|¡|°IÓ'>Ñ$ˆM˜9à×.Ñ.¨}Ó=ˆØÐ Øà—)‘)“+ˆØ�eÒØ—‘ˆAØ—=‘=”?Ø—L‘L“N�ä—‘˜YÓ'¨Ñ*ØÜ× Ñ Ó"Øð	ŠDð ˜ÒÜ$*§L¡L°Ó$;¸AÑ$>Ð!Ü—‘Ð4°S°bÐ9¸5ÓAˆAÜ—‘Ð4°R°SÐ9¸5ÓAˆAÜ,¨Q°Ó2ˆIØ—‘ˆAØ—=‘=”?Ø—L‘L“N�Ø˜t ]Ð3‰Dà˜Š_Ü$*§L¡L°Ó$;¸AÑ$>Ð!Ü%Ÿ|™|Ð,AÀ1ÓEÑˆD�$˜Ü—‘˜t UÓ+ˆAÜ—‘˜t UÓ+ˆAÜ,¨Q°Ó2ˆIà—‘ˆAØ—=‘=”?Ø—L‘L“N�à˜t¤R§X¡X¨mÓ%<Ð=‰Dà˜	Ò!Ø—‘ˆAØ—=‘=”?Ø—L‘L“N�Ü—L‘L Ó+¨AÑ.°Ð5ˆDð	ØˆA�H‰H�d‰Oð øô  ò 	Ùð	ús   ÉI! É!	I-É,I-)NN)NNNN)N)r   ÚobjectÚreturnÚbool)rÍ  rH   )rÍ  z&Literal['RSA', 'DSA', 'EC', 'Ed25519'])rÍ  zdict[str, Any])NNN)0r*   r+   r,   r-   ÚclassmethodrZ   rT   r„   rš   rž   rË   rÔ   rÖ   ré   rï   rò   r_   r’   r“   r  r–   r}   r  r!  r<  r0  rB  r9   r:   rI  rX   rR  rV  r_  r3  rd   r~   r{  r"   r…  rŒ  r�  r¢  r¥  r®  r²  r·  rÇ  r.   r/   r0   rP   rP   —   s*  „ ñð ò>ó ð>ð( ò%,ó ð%,ðN ñ6?ó ð6?ðp ñH?ó ðH?ðT ñ*ó ð*ð( ñV=ó ðV=ðp ñ6:ó ð6:ðp ñAó ðAð8 ñDó ðDð> ñ#Dó ð#DðJ ñ.=ó ð.=ð` ñó ðð> ò*ó ð*ðX ò ó ð ðD òó ðð> òó ðð6 òó ðò,$ó"ó*$òX
ò 5ð "4×!;Ñ!;ó &TóPOò.ò0
$ò0ò6(óJJòX:;òxQ;ñf !à�iÐ Ø�lÐ#ð	
óò:Oóð:OóxJó4<)ó|ó8;ò:P?òdPó,J.óXDr/   rP   c                ó0  — | j                  «       j                  d¬«       | j                  «       s‡t        j                  d|t        «       ¬«      }|j                  t        j                  j                  t        j                  j                  t        j                  «       ¬«      }| j                  |«       | j                  d«      5 }t        j                  |j!                  «       dt        «       ¬«      }t#        |«      cddd«       S # 1 sw Y   yxY w)	a¿  
    This function returns a persistent L{Key}.

    The key is loaded from a PEM file in C{location}. If it does not exist, a
    key with the key size of C{keySize} is generated and saved.

    @param location: Where the key is stored.
    @type location: L{twisted.python.filepath.FilePath}

    @param keySize: The size of the key, if it needs to be generated.
    @type keySize: L{int}

    @returns: A persistent key.
    @rtype: L{Key}
    T)ÚignoreExistingDirectoryi  )Úpublic_exponentra  r¬   )ÚencodingrH  Úencryption_algorithmrR   N)Úpasswordr¬   )ÚparentÚmakedirsÚexistsr   Úgenerate_private_keyr   rh  r   re  r   ri  r¡  rj  Ú
setContentrS   r   rU   rP   )ÚlocationrÃ   Ú
privateKeyÚpemÚkeyFiles        r0   Ú_getPersistentRSAKeyrß  ò  sá   € ð  ‡O�OÓ×Ñ°tÐÔ<ð �?‰?ÔÜ×-Ñ-Ø!¨G¼_Ó=Nô
ˆ
ð ×&Ñ&Ü"×+Ñ+×/Ñ/Ü ×.Ñ.×AÑAÜ!.×!;Ñ!;Ó!=ð 'ó 
ˆð 	×Ñ˜CÔ ð 
�‰�tÓ	ð  Ü"×7Ñ7Ø�L‰L‹N T´?Ó3Dô
ˆ
ô �:‹÷	÷ ò ús   Ã	9DÄD)i   )Nr-   Ú
__future__r   rF  r±   rA   r‚  Úbase64r   r   r   Úhashlibr   r   Útypingr	   rµ   Úcryptographyr
   Úcryptography.exceptionsr   Úcryptography.hazmat.backendsr   Úcryptography.hazmat.primitivesr   r   Ú)cryptography.hazmat.primitives.asymmetricr   r   r   r   r   Ú&cryptography.hazmat.primitives.ciphersr   r   r   Ú,cryptography.hazmat.primitives.serializationr   r   r   Útwisted.conch.sshr   r   Útwisted.conch.ssh.commonr   Útwisted.pythonr   Útwisted.python.compatr   r   Útwisted.python.constantsr    r!   Útwisted.python.deprecater"   Ú/cryptography.hazmat.primitives.asymmetric.utilsr#   r$   ÚImportErrorr%   r&   Ú	SECP256R1Ú	SECP384R1Ú	SECP521R1rz   r”   r  r  Ú	Exceptionr(   r2   r5   r7   r9   r=   rN   rP   rß  r.   r/   r0   ú<module>r÷     s9  ðñ
õ #ã Û Û Û ß 6Ñ 6ß Ý ã Ý Ý 4Ý 8ß @ß TÕ Tß LÑ L÷õ ç +Ý 1Ý $ß 9ß 9Ý @ð	÷ð )˜BŸL™L›NØ(˜BŸL™L›NØ(˜BŸL™L›Nñ€ð ØØñ€
ð ×+Ñ+Ð Ø×-Ñ-Ð ô�)ô ô ô ô˜	ô ô˜9ô ô$˜ô $ô" 9ô ò÷>Xñ Xôv2(øðO6 ò ÷ñ ðús   Â E ÅEÅE