Ë
    M/Åe0f  ã                   ó*  — d Z ddlZddlZddlZddlZddlZddlZddlZddlm	Z	 ddlm
Z
 ddlmZ ddlmZ ddlmZ ddlmZ dd	lmZ dd
lmZ ddlmZ ddlmZ ddlmZ ddlmZ ddlmZ ddlmZ ddlmZ ddlmZ ddlmZ ddlmZ ddlm Z  ddlm!Z! ddlm"Z" ddlm#Z# ddl$m%Z& ddl'm(Z) ddl*m+Z+ ddl,mZ-  ej\                  e/«      Z0g d¢Z1ddgZ2g d¢Z3 e4 ejj                  e3e2e1d «      «      Z6d!ejn                  d"e8d#ee"jr                     fd$„Z:d!ejn                  d%ee8e	f   d#dfd&„Z;d!ejn                  d%ee8e	f   d#dfd'„Z<d!ejn                  d%ee8e	f   d#dfd(„Z=d%ee8e	f   d#e
e8e	f   fd)„Z>d*e8d+eee8   e8f   d#ee8   fd,„Z?d-e8d+e8d#e@fd.„ZAd-e8d+e8d#eBfd/„ZCd-e8d+e8d#ee8   fd0„ZDd!ejn                  d1e"jr                  d#e@fd2„ZEd!ejn                  d1e"jr                  d3e8d#dfd4„ZFd!ejn                  d1e"jr                  d#dfd5„ZGd!ejn                  d6eee8      d7ej�                  d1e"jr                  d#df
d8„ZId9ee8   d:e8d#e8fd;„ZJd!ejn                  d<ee8   d=ee8   d>ee8   d?ee8   d#dfd@„ZKd!ejn                  d#eeLeLf   fdA„ZMdBe8d!ejn                  d#dfdC„ZNy)DzGFunctionality for autorenewal and associated juggling of configurationsé    N)ÚAny)ÚDict)ÚIterable)ÚList)ÚMapping)ÚOptional)ÚTuple)ÚUnion)Údefault_backend)Úec)Úrsa)Úload_pem_private_key)Úconfiguration)Úcrypto_util)Úerrors)Úutil)Úcli)Úclient)Ú	constants)Úhooks)Ústorage)Úupdater)Úobj)Údisco)Úos)Ú
config_dirÚlogs_dirÚwork_dirÚ
user_agentÚserverÚaccountÚauthenticatorÚ	installerÚ
renew_hookÚpre_hookÚ	post_hookÚhttp01_addressÚpreferred_chainÚkey_typeÚelliptic_curveÚrsa_key_sizeÚhttp01_port)Úmust_stapleÚallow_subset_of_namesÚ	reuse_keyÚ	autorenew)Úpref_challsÚconfigÚ	full_pathÚreturnc                 ó  — 	 t        j                  || «      }d|j                  vrt
        j                  d|«       y|j                  d   }d|vrt
        j                  d|«       y|j                  d	d
«      |d	<   t        |«      }	 t        | |«       t        | |«       	 |j%                  «       D �cg c]  }t'        j(                  |«      ‘Œ c}| _        |S # t        j                  t        f$ rg}t
        j                  d|«       t
        j                  dt        |«      «       t
        j                  dt        j                  «       «       Y d}~yd}~ww xY w# t         t        j"                  f$ rR}t
        j                  d|t        |«      «       t
        j                  dt        j                  «       «       Y d}~yd}~ww xY wc c}w # t        j,                  $ r!}t
        j                  d||«       Y d}~yd}~ww xY w)a•  Try to instantiate a RenewableCert, updating config with relevant items.

    This is specifically for use in renewal and enforces several checks
    and policies to ensure that we can try to proceed with the renewal
    request. The config argument is modified by including relevant options
    read from the renewal configuration file.

    :param configuration.NamespaceConfig config: configuration for the
        current lineage
    :param str full_path: Absolute path to the configuration file that
        defines this lineage

    :returns: the RenewableCert object or None if a fatal error occurred
    :rtype: `storage.RenewableCert` or NoneType

    z(Renewal configuration file %s is broken.zThe error was: %s
Skipping.úTraceback was:
%sNÚrenewalparamsz<Renewal configuration file %s lacks renewalparams. Skipping.r"   zJRenewal configuration file %s does not specify an authenticator. Skipping.r)   r   zHAn error occurred while parsing %s. The error was %s. Skipping the file.z{Renewal configuration file %s references a certificate that contains an invalid domain name. The problem was: %s. Skipping.)r   ÚRenewableCertr   ÚCertStorageErrorÚIOErrorÚloggerÚerrorÚstrÚdebugÚ	tracebackÚ
format_excr   ÚgetÚ"_remove_deprecated_config_elementsÚ restore_required_config_elementsÚ_restore_plugin_configsÚ
ValueErrorÚErrorÚnamesr   Úenforce_domain_sanityÚdomainsÚConfigurationError)r2   r3   Úrenewal_candidater<   r7   Úds         ú;/usr/lib/python3/dist-packages/certbot/_internal/renewal.pyÚreconstituterN   9   sÌ  € ð$Ü#×1Ñ1°)¸VÓDÐð Ð/×=Ñ=Ñ=Ü�‰ð 2Ø3<ô	>àØ%×3Ñ3°OÑD€MØ˜mÑ+Ü�‰ð 5Ø6?ô	Aàð !.× 1Ñ 1°*¸eÓ D€M�*Ñô 7°}ÓE€MðÜ(¨°Ô?Ü ¨Ô6ðà#4×#:Ñ#:Ó#<ö>Øô ×4Ñ4°QÕ7ò >ˆŒð ÐøôY ×#Ñ#¤WÐ-ò Ü�‰Ð?ÀÔKÜ�‰Ð3´S¸³ZÔ@Ü�‰Ð)¬9×+?Ñ+?Ó+AÔBÜûð	ûô8 œŸ™Ð%ò Ü�‰ð!Ø"+¬S°«Zô	9ô 	�‰Ð)¬9×+?Ñ+?Ó+AÔBÜûðüò>øä×$Ñ$ò Ü�‰ð ,à-6¸ô	?ô ûð	ús[   ‚C ÂE Â!G Â3G
ÃG ÃEÃ2AEÅEÅGÅ5AGÇGÇ
G ÇHÇ"G>Ç>Hr7   c                 ó®   — d|v r| j                  d«      s
|d   | _        d|v r2| j                  d«      s |d   }t        |t        «      r|g}|| _        yyy)z¥
    webroot_map is, uniquely, a dict, and the general-purpose configuration
    restoring logic is not able to correctly parse it from the serialized
    form.
    Úwebroot_mapÚwebroot_pathN)Úset_by_userrP   Ú
isinstancer=   rQ   )r2   r7   Úwps      rM   Ú_restore_webroot_configrU   |   si   € ð ˜Ñ%¨f×.@Ñ.@ÀÔ.OØ*¨=Ñ9ˆÔð ˜Ñ&¨v×/AÑ/AÀ.Ô/QØ˜>Ñ*ˆÜ�bœ#ÔØ�ˆBØ ˆÕð	 0RÐ&ó    c           	      óì  — g }|d   dk(  rt        | |«       n|j                  |d   «       |j                  d«      �|j                  |d   «       t        |«      D ]–  }|j	                  dd«      }|j                  «       D ]o  \  }}|j                  |dz   «      sŒ| j                  |«      rŒ-|dv rt        | |t        |«      «       ŒHt        j                  |«      }t        | | ||«      «       Œq Œ˜ y)a  Sets plugin specific values in config from renewalparams

    :param configuration.NamespaceConfig config: configuration for the
        current lineage
    :param configobj.Section renewalparams: Parameters from the renewal
        configuration file that defines this lineage

    r"   Úwebrootr#   Nú-Ú_)ÚNoneÚTrueÚFalse)rU   ÚappendrA   ÚsetÚreplaceÚitemsÚ
startswithrR   ÚsetattrÚevalr   Úargparse_type)r2   r7   Úplugin_prefixesÚplugin_prefixÚconfig_itemÚconfig_valueÚcasts          rM   rD   rD   Ž   sþ   € ð( "$€OØ�_Ñ%¨Ò2Ü ¨Õ6à×Ñ˜}¨_Ñ=Ô>à×Ñ˜Ó%Ð1Ø×Ñ˜}¨[Ñ9Ô:ä˜_Ó-ò EˆØ%×-Ñ-¨c°3Ó7ˆØ)6×)<Ñ)<Ó)>ò 
	EÑ%ˆK˜Ø×%Ñ% m°cÑ&9Õ:À6×CUÑCUÐVaÕCbð  Ð#<Ñ<ô ˜F K´°lÓ1CÕDä×,Ñ,¨[Ó9�DÜ˜F K±°lÓ1CÕDñ
	EñErV   c                 óÒ  — i }t        j                  dt        fft        t        t        j
                  t        «      «      t        t        t        j
                  t        «      «      t        t        t        j
                  t        «      «      «      }|D ]-  \  }}||v sŒ| j                  |«      rŒ ||||   «      }|||<   Œ/ |j                  «       D ]  \  }}t        | ||«       Œ y)a  Sets non-plugin specific values in config from renewalparams

    :param configuration.NamespaceConfig config: configuration for the
        current lineage
    :param configobj.Section renewalparams: parameters from the renewal
        configuration file that defines this lineage

    r1   N)Ú	itertoolsÚchainÚ_restore_pref_challsÚzipÚBOOL_CONFIG_ITEMSÚrepeatÚ_restore_boolÚINT_CONFIG_ITEMSÚ_restore_intÚSTR_CONFIG_ITEMSÚ_restore_strrR   ra   rc   )r2   r7   Úupdated_valuesÚrequired_itemsÚ	item_nameÚrestore_funcÚvalueÚkeys           rM   rC   rC   º   sÕ   € ð €NÜ—_‘_Ø
Ô-Ð	.Ð0ÜÔœy×/Ñ/´Ó>Ó?ÜÔœi×.Ñ.¬|Ó<Ó=ÜÔœi×.Ñ.¬|Ó<Ó=ó	?€Nð
 $2ò .Ñˆ	�<Ø˜Ò%¨f×.@Ñ.@ÀÕ.KÙ  ¨M¸)Ñ,DÓEˆEØ(-ˆN˜9Ò%ð.ð %×*Ñ*Ó,ò $‰
ˆˆUÜ�˜˜UÕ#ñ$rV   c                 óz   — | j                  «       D ��ci c]  \  }}|t        j                  vr||“Œ c}}S c c}}w )zàRemoves deprecated config options from the parsed renewalparams.

    :param dict renewalparams: list of parsed renewalparams

    :returns: list of renewalparams with deprecated config options removed
    :rtype: dict

    )ra   r   ÚDEPRECATED_OPTIONS)r7   Úoption_nameÚvs      rM   rB   rB   Ó   sD   € ð 4A×3FÑ3FÓ3H÷ 6Ñ/ ¨QØœc×4Ñ4Ñ4ð ˜‰Nó 6ð 6ùó 6s   ”7Úunused_namer{   c                 óV   — t        |t        «      r|gn|}t        j                  |«      S )a—  Restores preferred challenges from a renewal config file.

    If value is a `str`, it should be a single challenge type.

    :param str unused_name: option name
    :param value: option value
    :type value: `list` of `str` or `str`

    :returns: converted option value to be stored in the runtime config
    :rtype: `list` of `str`

    :raises errors.Error: if value can't be converted to a bool

    )rS   r=   r   Úparse_preferred_challenges)r�   r{   s     rM   rn   rn   à   s'   € ô$ " %¬Ô-ˆU‰G°5€EÜ×)Ñ)¨%Ó0Ð0rV   Únamec                 ój   — |j                  «       }|dvrt        j                  d| › d|› �«      ‚|dk(  S )a#  Restores a boolean key-value pair from a renewal config file.

    :param str name: option name
    :param str value: option value

    :returns: converted option value to be stored in the runtime config
    :rtype: bool

    :raises errors.Error: if value can't be converted to a bool

    )ÚtrueÚfalsezExpected True or False for z but found r†   )Úlowerr   rF   )r„   r{   Úlowercase_values      rM   rr   rr   ö   s@   € ð —k‘k“m€OØÐ/Ñ/Ü�l‰lÐ8¸¸¸kÈ%ÈÐQÓRÐRØ˜fÑ$Ð$rV   c                 óÌ   — | dk(  r/|dk(  r*t         j                  d«       t        j                  d«      S 	 t	        |«      S # t
        $ r t        j                  d| › �«      ‚w xY w)a#  Restores an integer key-value pair from a renewal config file.

    :param str name: option name
    :param str value: option value

    :returns: converted option value to be stored in the runtime config
    :rtype: int

    :raises errors.Error: if value can't be converted to an int

    r,   r[   z!updating legacy http01_port valuezExpected a numeric value for )r;   Úinfor   Úflag_defaultÚintrE   r   rF   ©r„   r{   s     rM   rt   rt     sh   € ð ˆ}Ò ¨&¢Ü�‰Ð7Ô8Ü×Ñ Ó.Ð.ðCÜ�5‹zÐøÜò CÜ�l‰lÐ:¸4¸&ÐAÓBÐBðCús   ¶
A Á"A#c                 óº   — | dk(  rN|t         j                  k(  r;t        j                  dt         j                  d   |«       t         j                  d   S |dk(  rdS |S )zèRestores a string key-value pair from a renewal config file.

    :param str name: option name
    :param str value: option value

    :returns: converted option value to be stored in the runtime config
    :rtype: str or None

    r    z$Using server %s instead of legacy %sr[   N)r   ÚV1_URIr;   r‹   ÚCLI_DEFAULTSrŽ   s     rM   rv   rv     sZ   € ð" ˆxÒ˜E¤Y×%5Ñ%5Ò5Ü�‰Ð:Ü×*Ñ*¨8Ñ4°eô	=ä×%Ñ% hÑ/Ð/à˜F’?ˆ4Ð-¨Ð-rV   Úlineagec                 ó  — | j                   rt        j                  d«       y|j                  «       rt        j	                  d«       y| j
                  rt        j	                  d«       yt        j                  d«       y)zDReturn true if any of the circumstances for automatic renewal apply.z+Auto-renewal forced with --force-renewal...Tz0Certificate is due for renewal, auto-renewing...zCCertificate not due for renewal, but simulating renewal for dry runz#Certificate not yet due for renewalF)Úrenew_by_defaultr;   r>   Úshould_autorenewr‹   Údry_runÚdisplay_utilÚnotify)r2   r’   s     rM   Úshould_renewr™   7  s`   € à×ÒÜ�‰ÐBÔCØØ×ÑÔ!Ü�‰ÐFÔGØØ‡~‚~Ü�‰ÐYÔZØÜ×ÑÐ=Ô>ØrV   Úoriginal_serverc                 óø   — t        j                  | j                  «      r[t        j                  |«      sE| j                  s8dj	                  |j                  «       «      }t        j                  d|› d�«      ‚yyy)z9Do not renew a valid cert with one from a staging server!z, z^You've asked to renew/replace a seemingly valid certificate with a test certificate (domains: z@). We will not do that unless you use the --break-my-certs flag!N)r   Ú
is_stagingr    Úbreak_my_certsÚjoinrG   r   rF   )r2   r’   rš   rG   s       rM   Ú_avoid_invalidating_lineagerŸ   F  su   € ô ‡��v—}‘}Ô%Ü�‰˜Ô/Ø×(Ò(ØŸ	™	 '§-¡-£/Ó2�Ü—l‘lð4Ø49°7ð ;@ð@óAð Að )ð 0ð &rV   c                 óR  ‡ ‡‡— ‰ j                  d«      r‰ j                  sy‰j                  s‰ j                  sy‰ j                  ry‰ j                  j	                  «       Šdˆˆfd„fdˆ ˆˆfd„fdˆ ˆˆfd„fg}|D ](  } |d	   «       sŒt        j                  d
|d   › d�«      ‚ y)z®Don't allow combining --reuse-key with any flags that would conflict
    with key reuse (--key-type, --rsa-key-size, --elliptic-curve), unless
    --new-key is also set.
    r/   Nz
--key-typec                  ó>   •— ‰ ‰j                   j                  «       k7  S ©N)Úprivate_key_typerˆ   )Úktr’   s   €€rM   ú<lambda>z,_avoid_reuse_key_conflicts.<locals>.<lambda>n  s   ø€ ��w×/Ñ/×5Ñ5Ó7Ñ7€ rV   z--rsa-key-sizec                  óD   •— ‰dk(  xr ‰ j                   ‰j                   k7  S )Nr   )r+   ©r2   r¤   r’   s   €€€rM   r¥   z,_avoid_reuse_key_conflicts.<locals>.<lambda>p  s!   ø€ ��u‘ÒL ×!4Ñ!4¸×8LÑ8LÑ!L€ rV   z--elliptic-curvec                  ó˜   •— ‰dk(  xrC ‰j                   xr5 ‰ j                   j                  «       ‰j                   j                  «       k7  S )NÚecdsa)r*   rˆ   r§   s   €€€rM   r¥   z,_avoid_reuse_key_conflicts.<locals>.<lambda>r  sH   ø€ ��w‘ò Q 7×#9Ñ#9ò QØ×&Ñ&×,Ñ,Ó.°'×2HÑ2H×2NÑ2NÓ2PÑPð rV   é   zUnable to change the r   z½ of this certificate because --reuse-key is set. To stop reusing the private key, specify --no-reuse-key. To change the private key this one time and then reuse it in future, add --new-key.)rR   r/   Únew_keyr)   rˆ   r   rF   )r2   r’   Úpotential_conflictsÚconflictr¤   s   ``  @rM   Ú_avoid_reuse_key_conflictsr®   S  sÄ   ú€ ð ×Ñ˜+Ô&¨v×/?Ò/?Øð ×Ò V×%5Ò%5Øð ‡~‚~Øà	�‰×	Ñ	Ó	 €Bð 
Ü	7ð	9à	Ý	Lð	Nà	õ
Qð	RðÐð (ò "ˆØˆ8�A‰;�=Ü—,‘,Ø'¨°© }ð 5!ð !ó"ð "ñ"rV   rI   Ú	le_clientc                 ó"  — |j                   d   }|j                  dt        j                  d«      «      }t	        | ||«       t        | |«       |s|j                  «       }| j                  rB| j                  s6t        j                  j                  |j                  «      }t        || «       nd}|j                  ||«      \  }}}}	| j                  r>t         j#                  dt        j                  j%                  |j&                  «      «       n^|j)                  «       }
|j+                  |
||j,                  || «       |j/                  |j)                  «       «       |j1                  «        t3        j4                  | ||j6                  «       y)zRenew a certificate lineage.r7   r    Nz(Dry run: skipping updating lineage at %s)r   rA   r   rŒ   rŸ   r®   rG   r/   r«   r   ÚpathÚnormpathÚprivkeyÚ_update_renewal_params_from_keyÚobtain_certificater–   r;   r>   ÚdirnameÚcertÚlatest_common_versionÚsave_successorÚpemÚupdate_all_links_toÚtruncater   r$   Úlive_dir)r2   rI   r¯   r’   Úrenewal_paramsrš   r«   Únew_certÚ	new_chainrZ   Úprior_versions              rM   Ú
renew_certrÂ     s6  € ð ×*Ñ*¨?Ñ;€NØ$×(Ñ(¨´3×3CÑ3CÀHÓ3MÓN€OÜ ¨°ÔAÜ˜v wÔ/ÙØ—-‘-“/ˆð ×Ò §¢Ü—'‘'×"Ñ" 7§?¡?Ó3ˆÜ'¨°Õ8àˆØ&/×&BÑ&BÀ7ÈGÓ&TÑ#€Hˆi˜ !Ø‡~‚~Ü�‰Ð?ÄÇÁÇÁÐQX×Q]ÑQ]ÓA^Õ_à×5Ñ5Ó7ˆà×Ñ˜}¨h¸¿¹ÀYÐPVÔWØ×#Ñ# G×$AÑ$AÓ$CÔDØ×ÑÔä	×Ñ�V˜W g×&6Ñ&6Õ7rV   ÚmsgsÚcategoryc                 óB   ‡— ˆfd„| D «       }ddj                  |«      z   S )z:Format a results report for a category of renewal outcomesc              3   ó.   •K  — | ]  }|›d ‰›d�–— Œ y­w)z (ú)N© )Ú.0ÚmrÄ   s     €rM   ú	<genexpr>zreport.<locals>.<genexpr>ž  s   øè ø€ Ò5¨1š!šXÔ&Ñ5ùs   ƒz  z
  )rž   )rÃ   rÄ   Úliness    ` rM   ÚreportrÍ   œ  s!   ø€ ã5°Ô5€EØ�&—+‘+˜eÓ$Ñ$Ð$rV   Úrenew_successesÚrenew_failuresÚrenew_skippedÚparse_failuresc                 ó²  — t         j                  }t        j                  } |dt        j
                  › �«       | j                  rdnd}|r |d«        |t        |d«      «       |s;|s9 |d|› d�«       | j                  €| j                  €| j                  �Œ |d	«       nƒ|r!|s |d
|› d�«        |t        |d«      «       n`|r|s |d|«        |t        |d«      «       n@|r>|r< |d|› d�«        |t        |d«      dz   «        |d|«        |t        |d«      «       |r |d«        |t        |d«      «        |t        j
                  «       y)aÝ  
    Print a report to the terminal about the results of the renewal process.

    :param configuration.NamespaceConfiguration config: Configuration
    :param list renew_successes: list of fullchain paths which were renewed
    :param list renew_failures: list of fullchain paths which failed to be renewed
    :param list renew_skipped: list of messages to print about skipped certificates
    :param list parse_failures: list of renewal parameter paths which had errors
    ú
zsimulated renewalÚrenewalz7The following certificates are not due for renewal yet:ÚskippedzNo zs were attempted.NzNo hooks were run.zCongratulations, all zs succeeded: Úsuccessz@All %ss failed. The following certificates could not be renewed:ÚfailurezThe following zs succeeded:zThe following %ss failed:zB
Additionally, the following renewal configurations were invalid: Ú	parsefail)r—   r˜   r;   r<   Údisplay_objÚ
SIDE_FRAMEr–   rÍ   r%   r$   r&   )r2   rÎ   rÏ   rÐ   rÑ   r˜   Únotify_errorÚrenewal_nouns           rM   Ú_renew_describe_resultsrÝ   ¢  sS  € ô × Ñ €FÜ—<‘<€Lá
ˆR”×&Ñ&Ð'Ð(Ô)à*0¯.ª.Ñ&¸i€LáÙÐHÔIÙŒv�m YÓ/Ô0Ù¡>Ù��\�NÐ"3Ð4Ô5Ø�O‰OÐ'Ø×!Ñ!Ð-°×1AÑ1AÐ1MÙÐ'Õ(Ù	¡ÙÐ& | n°MÐBÔCÙŒv�o yÓ1Õ2Ù	¡Ùð !Ø".ô	0á”V˜N¨IÓ6Õ7Ù	™OÙ� ˜~¨\Ð:Ô;ÙŒv�o yÓ1°DÑ8Ô9ÙÐ0°,Ô?Ù”V˜N¨IÓ6Ô7áÙð  ô 	!áŒv�n kÓ2Ô3á
Œ;×!Ñ!Õ"rV   c                 ó€  ‡ — t        ˆ fd„‰ j                  D «       «      rt        j                  d«      ‚‰ j                  r"t        j                  ‰ ‰ j                  «      g}nt        j                  ‰ «      }g }g }g }g }g }g }t        j                  j                  «        xr ‰ j                  }|D �]¶  }	t        j                  d|	z   d¬«       t        j                  ‰ «      }
t        j                   |	«      }	 t#        |
|	«      }	 |s|j1                  |	«       �nL|j3                  «        d	d
lm} t8        j:                  j=                  «       }t?        |
|«      r“|rCtA        jB                  dd«      }t&        jE                  d|«       tG        jH                  |«       d}|jK                  |
||«       |j1                  |jL                  «       |jO                  |jQ                  «       «       nbtS        jT                  |jW                  d|jY                  «       «      «      }|j1                  |jL                  ›d|j[                  d«      ›�«       t]        j^                  |
||«       �Œ¹ ta        ‰ ||||«       |s|r-t        j                  tc        |«      › dtc        |«      › d�«      ‚t&        j+                  d«       ||fS # t$        $ r\}t&        j)                  d|	||«       t&        j+                  dt-        j.                  «       «       |j1                  |	«       Y d}~�Œsd}~ww xY w# t$        $ r†}t&        j)                  d||«       t&        j+                  dt-        j.                  «       «       |r:|j1                  |jL                  «       |jO                  |jQ                  «       «       Y d}~�Œd}~ww xY w)z5Examine each lineage; renew if due and report resultsc              3   ó:   •K  — | ]  }|‰j                   v–— Œ y ­wr¢   )rP   )rÉ   Údomainr2   s     €rM   rË   z)handle_renewal_request.<locals>.<genexpr>Ö  s   øè ø€ Ò
I°ˆ6˜×+Ñ+Ô+Ñ
Iùs   ƒaf  Currently, the renew verb is capable of either renewing all installed certificates that are due to be renewed or renewing a single certificate specified by its name. If you would like to renew specific certificates by their domains, use the certonly command instead. The renew verb may provide other options for selecting certificates to renew in the future.zProcessing F)ÚpausezTRenewal configuration file %s (cert: %s) produced an unexpected error: %s. Skipping.r6   Nr   )Úmainrª   ià  z3Non-interactive renewal: random delay of %s secondsr·   z expires on z%Y-%m-%dz-Failed to renew certificate %s with error: %sz renew failure(s), z parse failure(s)zno renewal failures)2ÚanyrI   r   rF   Úcertnamer   Úrenewal_file_for_certnameÚrenewal_conf_filesÚsysÚstdinÚisattyÚrandom_sleep_on_renewr—   ÚnotificationÚcopyÚdeepcopyÚlineagename_for_filenamerN   Ú	Exceptionr;   r<   r>   r?   r@   r^   Úensure_deployedÚcertbot._internalrâ   Úplugins_discoÚPluginsRegistryÚfind_allr™   ÚrandomÚuniformr‹   ÚtimeÚsleeprÂ   Ú	fullchainÚextendrG   r   ÚnotAfterÚversionr¸   Ústrftimer   Úrun_generic_updatersrÝ   Úlen)r2   Ú
conf_filesrÎ   rÏ   rÐ   rÑ   Úrenewed_domainsÚfailed_domainsÚapply_random_sleepÚrenewal_fileÚlineage_configÚlineagenamerK   Úerâ   ÚpluginsÚ
sleep_timeÚexpirys   `                 rM   Úhandle_renewal_requestr  Ò  s\  ø€ ô Ó
I¸&¿.¹.Ô
IÔIô �l‰lð Pó Qð 	Qð ‡‚Ü×7Ñ7¸ÀÇÁÓPÐQ‰
ä×/Ñ/°Ó7ˆ
à€OØ€NØ€MØ€Nà€OØ€Nô !ŸY™Y×-Ñ-Ó/Ð/ÒP°F×4PÑ4PÐà"ó <AˆÜ×!Ñ! -°,Ñ">ÀeÕLÜŸ™ vÓ.ˆÜ×6Ñ6°|ÓDˆð	Ü ,¨^¸\Ó JÐð+	AÙ$Ø×%Ñ% lÖ3à!×1Ñ1Ô3Ý2Ü'×7Ñ7×@Ñ@ÓB�Ü Ð0AÔBá)Ü%+§^¡^°A°vÓ%>˜
ÜŸ™Ð$YØ$.ô0äŸ
™
 :Ô.à-2Ð*ð —O‘O N°GÐ=NÔOØ#×*Ñ*Ð+<×+FÑ+FÔGØ#×*Ñ*Ð+<×+BÑ+BÓ+DÕEä(×1Ñ1Ð2C×2KÑ2KØÐ 1× GÑ GÓ Ió3Kó L�Fà!×(Ñ(Ð?P×?ZÓ?ZØ)/¯©¸Ô)Dð*Fô Gô ×,Ñ,¨^Ð=NØ-4ô6ùða<Aô~ ˜F O°^Ø)¨>ô;ñ ™Ü�l‰lÜ�>Ó"Ð#Ð#6´s¸>Ó7JÐ6KÐK\Ð]ó_ð 	_ô
 ‡L�LÐ&Ô'à˜^Ð,Ð,øôC ò 	Ü�L‰Lð Ià'¨°aô9ô �L‰LÐ-¬y×/CÑ/CÓ/EÔFØ×!Ñ! ,Ô/Ýûð	ûôT ò 		Aä�L‰LØ?Ø˜Qôô �L‰LÐ-¬y×/CÑ/CÓ/EÔFÙ Ø×%Ñ%Ð&7×&AÑ&AÔBØ×%Ñ%Ð&7×&=Ñ&=Ó&?Ô@ÿùð		Aús3   Ã<KÄ	E!L.Ë	L+ËAL&Ì&L+Ì.	N=Ì7A;N8Î8N=Úkey_pathc                 ó¶  — t        | d«      5 }t        |j                  «       d t        «       ¬«      }d d d «       t	        t
        j                  «      rd|_        |j                  |_	        y t	        |t        j                  «      r#d|_        |j                  j                  |_        y t        j                   d| › dt#        |«      › d�«      ‚# 1 sw Y   ŒžxY w)NÚrb)ÚpasswordÚbackendr   r©   zKey at z is of an unsupported type: ú.)Úopenr   Úreadr   rS   r   ÚRSAPrivateKeyr)   Úkey_sizer+   r   ÚEllipticCurvePrivateKeyÚcurver„   r*   r   rF   Útype)r  r2   Úfile_hr|   s       rM   r´   r´   B  s­   € Ü	ˆh˜Ó	ð \ Ü" 6§;¡;£=¸4ÌÓIZÔ[ˆ÷\ä�#”s×(Ñ(Ô)ØˆŒØ!Ÿl™lˆÕÜ	�Cœ×3Ñ3Ô	4Ø!ˆŒØ #§	¡	§¡ˆÕä�l‰l˜W X JÐ.JÌ4ÐPSË9È+ÐUVÐWÓXÐX÷\ð \ús   �%CÃC)OÚ__doc__rì   rl   Úloggingrõ   rç   r÷   r?   Útypingr   r   r   r   r   r   r	   r
   Úcryptography.hazmat.backendsr   Ú)cryptography.hazmat.primitives.asymmetricr   r   Ú,cryptography.hazmat.primitives.serializationr   Úcertbotr   r   r   r   rñ   r   r   r   r   r   r   Úcertbot._internal.displayr   rÙ   Úcertbot._internal.pluginsr   rò   Úcertbot.compatr   Úcertbot.displayr—   Ú	getLoggerÚ__name__r;   ru   rs   rp   r_   rm   ÚCONFIG_ITEMSÚNamespaceConfigr=   r8   rN   rU   rD   rC   rB   rn   Úboolrr   r�   rt   rv   r™   rŸ   r®   ÚClientrÂ   rÍ   rÝ   Úlistr  r´   rÈ   rV   rM   ú<module>r,     s£  ðÙ Mã Û Û Û Û 
Û Û Ý Ý Ý Ý Ý Ý Ý Ý å 8Ý 8Ý 9Ý Må !Ý Ý Ý Ý !Ý $Ý 'Ý #Ý %Ý %Ý 8Ý <Ý Ý 0à	ˆ×	Ñ	˜8Ó	$€òEÐ ð # MÐ2Ð ò"Ð ñ �?�9—?‘?ØÐ'Ð)9Ð;KóMó N€ð@˜×6Ñ6ð @Ø ð@Ø%-¨g×.CÑ.CÑ%Dó@ðF! M×$AÑ$Að !Ø+2°3¸°8Ñ+<ð!ØAEó!ð$)E M×$AÑ$Að )EØ+2°3¸°8Ñ+<ð)EØAEó)EðX$¨]×-JÑ-Jð $Ø4;¸CÀ¸HÑ4Eð$ØJNó$ð2
6°g¸cÀ3¸hÑ6Gð 
6ÈDÐQTÐVYÐQYÉNó 
6ð1 cð 1°%¸¸S¹	À3¸Ñ2Gð 1ÈDÐQTÉIó 1ð,%˜ð % Cð %¨Dó %ð$C�sð C 3ð C¨3ó Cð,.�sð . 3ð .¨8°C©=ó .ð2˜×6Ñ6ð À×AVÑAVð Ð[_ó ð
A¨×(EÑ(Eð 
AØ)0×)>Ñ)>ð
AØQTð
AØY]ó
Að)" }×'DÑ'Dð )"Ø(/×(=Ñ(=ð)"ØBFó)"ðX8�}×4Ñ4ð 8¸xÈÈSÉ	Ñ?Rð 8Ø Ÿ-™-ð8Ø29×2GÑ2Gð8ØLPó8ð:%�˜#‘ð %¨#ð %°#ó %ð-# M×$AÑ$Að -#ÐTXÐY\ÑT]ð -#Ø,0°©Ið-#ØFJÈ3Áið-#à,0°©Ið-#à:>ó-#ð`m- =×#@Ñ#@ð m-ÀUÈ4ÐQUÈ:ÑEVó m-ð`
Y¨cð 
Y¸=×;XÑ;Xð 
YÐ]aô 
YrV   