Ë
    Õ¦e  ã                  óò   — d Z ddlmZ ddlZddlmZ ddlmZmZm	Z	m
Z
mZmZmZ ddlmZ ddlmZ ddlmZ d	d
lmZ d	dlmZmZmZmZmZmZmZmZ dgZ	 	 	 	 	 	 dd„Z 	 	 	 	 	 	 dd„Z! ed«      Z"dd„Z#dd„Z$y)zL
`cryptography.x509 <https://github.com/pyca/cryptography>`_-specific code.
é    )ÚannotationsN)ÚSequence)ÚCertificateÚDNSNameÚExtensionOIDÚ	IPAddressÚObjectIdentifierÚ	OtherNameÚUniformResourceIdentifier)ÚExtensionNotFound)Údecode)Ú	IA5Stringé   )ÚCertificateError)ÚDNS_IDÚCertificatePatternÚ
DNSPatternÚIPAddress_IDÚIPAddressPatternÚ
SRVPatternÚ
URIPatternÚverify_service_identityÚverify_certificate_hostnamec                óF   — t        t        | «      t        |«      gg ¬«       y)a¤  
    Verify whether *certificate* is valid for *hostname*.

    .. note::
        Nothing is verified about the *authority* of the certificate;
        the caller must verify that the certificate chains to an appropriate
        trust root themselves.

    Args:
        certificate: A *cryptography* X509 certificate object.

        hostname: The hostname that *certificate* should be valid for.

    Raises:
        service_identity.VerificationError:
            If *certificate* is not valid for *hostname*.

        service_identity.CertificateError:
            If *certificate* contains invalid / unexpected data. This includes
            the case where the certificate contains no `subjectAltName`\ s.

    .. versionchanged:: 24.1.0
        :exc:`~service_identity.CertificateError` is raised if the certificate
        contains no ``subjectAltName``\ s instead of
        :exc:`~service_identity.VerificationError`.
    ©Úcert_patternsÚobligatory_idsÚoptional_idsN)r   Úextract_patternsr   )ÚcertificateÚhostnames     ú?/usr/lib/python3/dist-packages/service_identity/cryptography.pyr   r   (   s"   € ô: Ü& {Ó3Ü˜xÓ(Ð)Øöó    c                óF   — t        t        | «      t        |«      gg ¬«       y)a  
    Verify whether *certificate* is valid for *ip_address*.

    .. note::
        Nothing is verified about the *authority* of the certificate;
        the caller must verify that the certificate chains to an appropriate
        trust root themselves.

    Args:
        certificate: A *cryptography* X509 certificate object.

        ip_address:
            The IP address that *connection* should be valid for.  Can be an
            IPv4 or IPv6 address.

    Raises:
        service_identity.VerificationError:
            If *certificate* is not valid for *ip_address*.

        service_identity.CertificateError:
            If *certificate* contains invalid / unexpected data. This includes
            the case where the certificate contains no ``subjectAltName``\ s.

    .. versionadded:: 18.1.0

    .. versionchanged:: 24.1.0
        :exc:`~service_identity.CertificateError` is raised if the certificate
        contains no ``subjectAltName``\ s instead of
        :exc:`~service_identity.VerificationError`.
    r   N)r   r   r   )r    Ú
ip_addresss     r"   Úverify_certificate_ip_addressr&   L   s#   € ôB Ü& {Ó3Ü$ ZÓ0Ð1Øör#   z1.3.6.1.5.5.7.8.7c           
     óØ  — g }	 | j                   j                  t        j                  «      }|j	                  |j
                  j                  t        «      D �cg c]&  }t        j                  |j                  d«      «      ‘Œ( c}«       |j	                  |j
                  j                  t        «      D �cg c]&  }t        j                  |j                  d«      «      ‘Œ( c}«       |j	                  |j
                  j                  t        «      D �cg c]  }t        |«      ‘Œ c}«       |j
                  j                  t        «      D ]{  }|j                   t"        k(  sŒt%        |j
                  «      \  }}t'        |t(        «      r3|j+                  t-        j                  |j/                  «       «      «       Œrt1        d«      ‚ |S c c}w c c}w c c}w # t2        $ r Y |S w xY w)a
  
    Extract all valid ID patterns from a certificate for service verification.

    Args:
        cert: The certificate to be dissected.

    Returns:
        List of IDs.

    .. versionchanged:: 23.1.0
       ``commonName`` is not used as a fallback anymore.
    zutf-8zUnexpected certificate content.)Ú
extensionsÚget_extension_for_oidr   ÚSUBJECT_ALTERNATIVE_NAMEÚextendÚvalueÚget_values_for_typer   r   Ú
from_bytesÚencoder   r   r   r   r
   Útype_idÚID_ON_DNS_SRVr   Ú
isinstancer   Úappendr   ÚasOctetsr   r   )	ÚcertÚidsÚextÚnameÚuriÚipÚotherÚsrvÚ_s	            r"   r   r   w   sŸ  € ð %'€Cð!NØ�o‰o×3Ñ3Ü×1Ñ1ó
ˆð 	�
‰
ð  ŸI™I×9Ñ9¼'ÓBöàô ×%Ñ% d§k¡k°'Ó&:Õ;òô	
ð 	�
‰
ð Ÿ9™9×8Ñ8Ü-óöàô ×%Ñ% c§j¡j°Ó&9Õ:òô	
ð 	�
‰
ð Ÿ)™)×7Ñ7¼	ÓBöàô ! Õ$òô	
ð —Y‘Y×2Ñ2´9Ó=ò 	NˆEØ�}‰}¤Ó-Ü §¡Ó,‘��QÜ˜c¤9Ô-Ø—J‘Jœz×4Ñ4°S·\±\³^ÓDÕEä*Ð+LÓMÐMð	Nð €Jùò7ùòùòøô% ò Øð< €Jð?ús#   „)G Á+GÂ7+GÄGÇ	G)Ç(G)c                óP   — t        j                  t        dd¬«       t        | «      S )zm
    Deprecated and never public API.  Use :func:`extract_patterns` instead.

    .. deprecated:: 23.1.0
    z?`extract_ids()` is deprecated, please use `extract_patterns()`.é   )ÚcategoryÚmessageÚ
stacklevel)ÚwarningsÚwarnÚDeprecationWarningr   )r5   s    r"   Úextract_idsrF   «   s&   € ô ‡M�MÜ#ØQØõô
 ˜DÓ!Ð!r#   )r    r   r!   ÚstrÚreturnÚNone)r    r   r%   rG   rH   rI   )r5   r   rH   zSequence[CertificatePattern])%Ú__doc__Ú
__future__r   rC   Útypingr   Úcryptography.x509r   r   r   r   r	   r
   r   Úcryptography.x509.extensionsr   Úpyasn1.codec.der.decoderr   Úpyasn1.type.charr   Ú
exceptionsr   Úhazmatr   r   r   r   r   r   r   r   Ú__all__r   r&   r1   r   rF   © r#   r"   ú<module>rU      sŸ   ðñõ #ã å ÷÷ ñ õ ;Ý +Ý &å (÷	÷ 	ó 	ð )Ð
)€ð!Øð!Ø(+ð!à	ó!ðH%Øð%Ø*-ð%à	ó%ñP !Ð!4Ó5€ó1ôh"r#   