Ë
    Õ¦eÍ  ã                  ó0  — d Z ddlmZ ddlZddlZddlmZ ddlmZ ddl	m
Z
 ddlmZ ddlmZ d	d
lmZ d	dlmZmZmZmZmZmZmZmZ  ej4                  e«      5  ddlmZ ddlmZ ddd«       dgZ dd„Z!dd„Z" ed«      Z#dd„Z$dd„Z%y# 1 sw Y   Œ%xY w)zA
`pyOpenSSL <https://github.com/pyca/pyopenssl>`_-specific code.
é    )ÚannotationsN)ÚSequence)Údecode)Ú	IA5String)ÚObjectIdentifier)ÚGeneralNamesé   )ÚCertificateError)ÚDNS_IDÚCertificatePatternÚ
DNSPatternÚIPAddress_IDÚIPAddressPatternÚ
SRVPatternÚ
URIPatternÚverify_service_identity)ÚX509)Ú
ConnectionÚverify_hostnamec                ób   — t        t        | j                  «       «      t        |«      gg ¬«       y)a;  
    Verify whether the certificate of *connection* is valid for *hostname*.

    Args:
        connection: A pyOpenSSL connection object.

        hostname: The hostname that *connection* should be connected to.

    Raises:
        service_identity.VerificationError:
            If *connection* does not provide a certificate that is valid for
            *hostname*.

        service_identity.CertificateError:
            If certificate provided by *connection* contains invalid /
            unexpected data. This includes the case where the certificate
            contains no ``subjectAltName``\ s.

    .. versionchanged:: 24.1.0
        :exc:`~service_identity.CertificateError` is raised if the certificate
        contains no ``subjectAltName``\ s instead of
        :exc:`~service_identity.VerificationError`.
    ©Úcert_patternsÚobligatory_idsÚoptional_idsN)r   Úextract_patternsÚget_peer_certificater   )Ú
connectionÚhostnames     ú</usr/lib/python3/dist-packages/service_identity/pyopenssl.pyr   r   '   s0   € ô0 Ü&Ø×+Ñ+Ó-ó
ô ˜xÓ(Ð)Øöó    c                ób   — t        t        | j                  «       «      t        |«      gg ¬«       y)aX  
    Verify whether the certificate of *connection* is valid for *ip_address*.

    Args:
        connection: A pyOpenSSL connection object.

        ip_address:
            The IP address that *connection* should be connected to. Can be an
            IPv4 or IPv6 address.

    Raises:
        service_identity.VerificationError:
            If *connection* does not provide a certificate that is valid for
            *ip_address*.

        service_identity.CertificateError:
            If the certificate chain of *connection* contains a certificate
            that contains invalid/unexpected data.

    .. versionadded:: 18.1.0

    .. versionchanged:: 24.1.0
        :exc:`~service_identity.CertificateError` is raised if the certificate
        contains no ``subjectAltName``\ s instead of
        :exc:`~service_identity.VerificationError`.
    r   N)r   r   r   r   )r   Ú
ip_addresss     r   Úverify_ip_addressr#   H   s0   € ô6 Ü&Ø×+Ñ+Ó-ó
ô % ZÓ0Ð1Øör    z1.3.6.1.5.5.7.8.7c                óð  — g }t        | j                  «       «      D �]Ö  }| j                  |«      }|j                  «       dk(  sŒ)t	        |j                  «       t        «       ¬«      \  }}|D �]‚  }|j                  «       }|dk(  rA|j                  t        j                  |j                  «       j                  «       «      «       ŒZ|dk(  rA|j                  t        j                  |j                  «       j                  «       «      «       Œ |dk(  rA|j                  t        j                  |j                  «       j                  «       «      «       Œæ|dk(  r˜|j                  «       }|j                  d«      }	|	t         k(  rlt	        |j                  d«      «      \  }
}t#        |
t$        «      r4|j                  t'        j                  |
j                  «       «      «       �Œvt)        d	«      ‚�Œƒ�Œ… �ŒÙ |S )
a
  
    Extract all valid ID patterns from a certificate for service verification.

    Args:
        cert: The certificate to be dissected.

    Returns:
        List of IDs.

    .. versionchanged:: 23.1.0
       ``commonName`` is not used as a fallback anymore.
    s   subjectAltName)Úasn1SpecÚdNSNameÚ	iPAddressÚuniformResourceIdentifierÚ	otherNamer   r	   zUnexpected certificate content.)ÚrangeÚget_extension_countÚget_extensionÚget_short_namer   Úget_datar   ÚgetNameÚappendr   Ú
from_bytesÚgetComponentÚasOctetsr   r   ÚgetComponentByPositionÚID_ON_DNS_SRVÚ
isinstancer   r   r
   )ÚcertÚidsÚiÚextÚnamesÚ_ÚnÚname_stringÚcompÚoidÚsrvs              r   r   r   o   s¦  € ð %'€CÜ�4×+Ñ+Ó-Ó.ó "ˆØ× Ñ  Ó#ˆØ×ÑÓÐ#4Ó4Ü˜cŸl™l›n´|³~ÔF‰HˆE�1Øó �ØŸi™i›k�Ø )Ò+Ø—J‘JÜ"×-Ñ-¨a¯n©nÓ.>×.GÑ.GÓ.IÓJõð ! KÒ/Ø—J‘JÜ(×3Ñ3ØŸN™NÓ,×5Ñ5Ó7óõð
 !Ð$?Ò?Ø—J‘JÜ"×-Ñ-¨a¯n©nÓ.>×.GÑ.GÓ.IÓJõð ! KÒ/ØŸ>™>Ó+�DØ×5Ñ5°aÓ8�CØœmÒ+Ü!'¨×(CÑ(CÀAÓ(FÓ!G™˜˜QÜ% c¬9Ô5ØŸJ™J¤z×'<Ñ'<¸S¿\¹\»^Ó'LÖMä"2Ø Aó#ð ñ áò=ð	"ðH €Jr    c                óP   — t        j                  t        dd¬«       t        | «      S )zm
    Deprecated and never public API.  Use :func:`extract_patterns` instead.

    .. deprecated:: 23.1.0
    z?`extract_ids()` is deprecated, please use `extract_patterns()`.é   )ÚcategoryÚmessageÚ
stacklevel)ÚwarningsÚwarnÚDeprecationWarningr   )r7   s    r   Úextract_idsrJ   ¤   s&   € ô ‡M�MÜ#ØQØõô
 ˜DÓ!Ð!r    )r   r   r   ÚstrÚreturnÚNone)r   r   r"   rK   rL   rM   )r7   r   rL   zSequence[CertificatePattern])&Ú__doc__Ú
__future__r   Ú
contextlibrG   Útypingr   Úpyasn1.codec.der.decoderr   Úpyasn1.type.charr   Úpyasn1.type.univr   Úpyasn1_modules.rfc2459r   Ú
exceptionsr
   Úhazmatr   r   r   r   r   r   r   r   ÚsuppressÚImportErrorÚOpenSSL.cryptor   ÚOpenSSL.SSLr   Ú__all__r   r#   r5   r   rJ   © r    r   ú<module>r^      s’   ðñõ #ã Û å å +Ý &Ý -Ý /å (÷	÷ 	ó 	ð €Z×Ñ˜Ó%ñ 'å#Ý&÷'ð Ð
€óóB!ñH !Ð!4Ó5€ó2ôj"÷M'ð 'ús   ÁBÂB