£Á°èZ¨Ä…–K§‚«“ô4“ÒÙ´dîfUÙÃÅ WKbyÊ¦•êŽ…È®FÒ¿ÊÎóCozá¬S@6{Í:›œêZÌ:Š•_%:¢¾¾~;‘Ã~èŠ©ÊÇí`ÔÑ©úë™µ'5I¿fš×WO%ø9¾«¾DK|€ùÍD”Ýs]nHÕ¶ê×Ó¼ãžªéUWŸÈË%DÒÕ¬ï‘]/Åcx  ‰ï2ß]ä6G[]S£ÔÏ¯rs{úëóµmÒï#UQxo·õÞCe]"±/aÙ&Eã4ú9Jé_ÞåëdãöKë)AÞ                  ¯¹ægƒÛowÐø^d™ý½ßB7áyMä9ÜÖUã
!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
<html>
3
l_6                 @   s   d dl mZmZmZ d dlZd dlmZmZ d dlm	Z	 d dl
mZmZmZmZmZmZ d dlmZ d dlmZ d dlmZmZmZmZmZmZmZ d	d
 Zdd Zdd Zdd Z dd Z!ej"eG dd de#Z$ej"eG dd de#Z%dS )    )absolute_importdivisionprint_functionN)utilsx509)UnsupportedAlgorithm)_CRL_ENTRY_REASON_CODE_TO_ENUM_asn1_integer_to_int_asn1_string_to_bytes_decode_x509_name_obj2txt_parse_asn1_generalized_time)_Certificate)serialization)OCSPCertStatusOCSPRequestOCSPResponseOCSPResponseStatus_CERT_STATUS_TO_ENUM_OIDS_TO_HASH_RESPONSE_STATUS_TO_ENUMc                s   t j  fdd}|S )Nc                s(   | j tjkrtdn | f| S d S )NzCOCSP response status is not successful so the property has no value)response_statusr   
SUCCESSFUL
ValueError)selfargs)func /usr/lib64/python3.6/ocsp.pywrapper!   s    z._requires_successful_response.<locals>.wrapper)	functoolswraps)r   r   r   )r   r   _requires_successful_response    s    
r"   c             C   s^   | j jd}| jj| j j| j j|| j j|}| j|dk | j|d | j jk t| |d S )NzASN1_OCTET_STRING **   r   )_ffinew_libOCSP_id_get0_infoNULLopenssl_assertr
   )backendcert_idZkey_hashresr   r   r   _issuer_key_hash.   s    r-   c             C   s^   | j jd}| jj|| j j| j j| j j|}| j|dk | j|d | j jk t| |d S )NzASN1_OCTET_STRING **r#   r   )r$   r%   r&   r'   r(   r)   r
   )r*   r+   Z	name_hashr,   r   r   r   _issuer_name_hash<   s    r.   c             C   s^   | j jd}| jj| j j| j j| j j||}| j|dk | j|d | j jk t| |d S )NzASN1_INTEGER **r#   r   )r$   r%   r&   r'   r(   r)   r	   )r*   r+   numr,   r   r   r   _serial_numberJ   s    r0   c             C   s   | j jd}| jj| j j|| j j| j j|}| j|dk | j|d | j jk t| |d }yt| S  tk
r   t	dj
|Y nX d S )NzASN1_OBJECT **r#   r   z*Signature algorithm OID: {} not recognized)r$   r%   r&   r'   r(   r)   r   r   KeyErrorr   format)r*   r+   Zasn1objr,   oidr   r   r   _hash_algorithmT   s    r4   c               @   sb  e Zd Zdd ZejdZeedd Z	eedd Z
eedd	 Zeed
d Zeedd Zeedd Zeedd Zdd Zeedd Zeedd Zeedd Zeedd Zeedd Zeedd Zeed d! Zeed"d# Zeed$d% Zeed&d' Zejed(d) Zejed*d+ Zd,d- Zd.S )/_OCSPResponsec             C   s   || _ || _| j jj| j}| j j|tk t| | _| jtjkr| j jj	| j}| j j|| j j
jk | j j
j|| j jj| _| j jj| j}|dkrtdj|| j jj| jd| _| j j| j| j j
jk | j jj| j| _| j j| j| j j
jk d S )Nr#   zhOCSP response contains more than one SINGLERESP structure, which this library does not support. {} foundr   )_backend_ocsp_responser&   ZOCSP_response_statusr)   r   _statusr   r   ZOCSP_response_get1_basicr$   r(   gcZOCSP_BASICRESP_free_basicZOCSP_resp_countr   r2   ZOCSP_resp_get0_singleZOCSP_SINGLERESP_get0_id_cert_id)r   r*   Zocsp_responsestatusZbasicZnum_respr   r   r   __init__j   s.    

z_OCSPResponse.__init__r8   c             C   s>   | j jj| j}| j j|| j jjk t| j |j}t	j
|S )N)r6   r&   ZOCSP_resp_get0_tbs_sigalgr:   r)   r$   r(   r   	algorithmr   ZObjectIdentifier)r   Zalgr3   r   r   r   signature_algorithm_oid   s    z%_OCSPResponse.signature_algorithm_oidc             C   s8   | j }y
tj| S  tk
r2   tdj|Y nX d S )Nz)Signature algorithm OID:{} not recognized)r@   r   Z_SIG_OIDS_TO_HASHr1   r   r2   )r   r3   r   r   r   signature_hash_algorithm   s    
z&_OCSPResponse.signature_hash_algorithmc             C   s2   | j jj| j}| j j|| j jjk t| j |S )N)r6   r&   ZOCSP_resp_get0_signaturer:   r)   r$   r(   r
   )r   Zsigr   r   r   	signature   s    z_OCSPResponse.signaturec                s    j jj j} j j| j jjk  j jjd} j jj||} j j|d  j jjk  j jj	| fdd} j j|dk  j jj
|d |d d  S )Nzunsigned char **r   c                s    j jj| d S )Nr   )r6   r&   ZOPENSSL_free)Zpointer)r   r   r   <lambda>   s    z2_OCSPResponse.tbs_response_bytes.<locals>.<lambda>)r6   r&   ZOCSP_resp_get0_respdatar:   r)   r$   r(   r%   Zi2d_OCSP_RESPDATAr9   buffer)r   ZrespdataZppr,   r   )r   r   tbs_response_bytes   s    z _OCSPResponse.tbs_response_bytesc             C   sz   | j jj| j}| j jj|}g }xRt|D ]F}| j jj||}| j j|| j jj	k t
| j |}| |_|j| q,W |S )N)r6   r&   ZOCSP_resp_get0_certsr:   Zsk_X509_numrangeZsk_X509_valuer)   r$   r(   r   Z
_ocsp_respappend)r   Zsk_x509r/   Zcertsir   Zcertr   r   r   certificates   s    z_OCSPResponse.certificatesc             C   s.   | j  \}}|| jjjkrd S t| j|S d S )N)_responder_key_namer6   r$   r(   r
   )r   _asn1_stringr   r   r   responder_key_hash   s    z _OCSPResponse.responder_key_hashc             C   s.   | j  \}}|| jjjkrd S t| j|S d S )N)rJ   r6   r$   r(   r   )r   	x509_namerK   r   r   r   responder_name   s    z_OCSPResponse.responder_namec             C   sP   | j jjd}| j jjd}| j jj| j||}| j j|dk |d |d fS )NzASN1_OCTET_STRING **zX509_NAME **r#   r   )r6   r$   r%   r&   ZOCSP_resp_get0_idr:   r)   )r   rL   rN   r,   r   r   r   rJ      s    z!_OCSPResponse._responder_key_namec             C   s   | j jj| j}t| j |S )N)r6   r&   ZOCSP_resp_get0_produced_atr:   r   )r   produced_atr   r   r   rP      s    z_OCSPResponse.produced_atc             C   sH   | j jj| j| j jj| j jj| j jj| j jj}| j j|tk t| S )N)r6   r&   OCSP_single_get0_statusr;   r$   r(   r)   r   )r   r=   r   r   r   certificate_status   s    z _OCSPResponse.certificate_statusc             C   sr   | j tjk	rd S | jjjd}| jjj| j| jjj	|| jjj	| jjj	 | jj
|d | jjj	k t| j|d S )NzASN1_GENERALIZEDTIME **r   )rR   r   REVOKEDr6   r$   r%   r&   rQ   r;   r(   r)   r   )r   	asn1_timer   r   r   revocation_time   s    z_OCSPResponse.revocation_timec             C   s|   | j tjk	rd S | jjjd}| jjj| j|| jjj	| jjj	| jjj	 |d dkrXd S | jj
|d tk t|d  S d S )Nzint *r   r#   )rR   r   rS   r6   r$   r%   r&   rQ   r;   r(   r)   r   )r   Z
reason_ptrr   r   r   revocation_reason  s    z_OCSPResponse.revocation_reasonc             C   sb   | j jjd}| j jj| j| j jj| j jj|| j jj | j j|d | j jjk t| j |d S )NzASN1_GENERALIZEDTIME **r   )	r6   r$   r%   r&   rQ   r;   r(   r)   r   )r   rT   r   r   r   this_update  s    z_OCSPResponse.this_updatec             C   sb   | j jjd}| j jj| j| j jj| j jj| j jj| |d | j jjkrZt| j |d S d S d S )NzASN1_GENERALIZEDTIME **r   )r6   r$   r%   r&   rQ   r;   r(   r   )r   rT   r   r   r   next_update,  s    z_OCSPResponse.next_updatec             C   s   t | j| jS )N)r-   r6   r<   )r   r   r   r   issuer_key_hash<  s    z_OCSPResponse.issuer_key_hashc             C   s   t | j| jS )N)r.   r6   r<   )r   r   r   r   issuer_name_hashA  s    z_OCSPResponse.issuer_name_hashc             C   s   t | j| jS )N)r4   r6   r<   )r   r   r   r   hash_algorithmF  s    z_OCSPResponse.hash_algorithmc             C   s   t | j| jS )N)r0   r6   r<   )r   r   r   r   serial_numberK  s    z_OCSPResponse.serial_numberc             C   s   | j jj| jS )N)r6   Z_ocsp_basicresp_ext_parserparser:   )r   r   r   r   
extensionsP  s    z_OCSPResponse.extensionsc             C   s   | j jj| jS )N)r6   Z_ocsp_singleresp_ext_parserr^   r;   )r   r   r   r   single_extensionsU  s    z_OCSPResponse.single_extensionsc             C   sL   |t jjk	rtd| jj }| jjj|| j}| jj	|dk | jj
|S )Nz/The only allowed encoding value is Encoding.DERr   )r   EncodingDERr   r6   _create_mem_bio_gcr&   Zi2d_OCSP_RESPONSE_bior7   r)   _read_mem_bio)r   encodingbior,   r   r   r   public_bytesZ  s    

z_OCSPResponse.public_bytesN)__name__
__module____qualname__r>   r   Zread_only_propertyr   propertyr"   r@   rA   rB   rE   rI   rM   rO   rJ   rP   rR   rU   rW   rX   rY   rZ   r[   r\   r]   cached_propertyr_   r`   rg   r   r   r   r   r5   h   sT    

	r5   c               @   sZ   e Zd Zdd Zedd Zedd Zedd Zed	d
 Ze	j
dd Zdd ZdS )_OCSPRequestc             C   s~   |j j|dkrtd|| _|| _| jj j| jd| _| jj| j| jjj	k | jj j
| j| _| jj| j| jjj	k d S )Nr#   z+OCSP request contains more than one requestr   )r&   ZOCSP_request_onereq_countNotImplementedErrorr6   _ocsp_requestZOCSP_request_onereq_get0Z_requestr)   r$   r(   ZOCSP_onereq_get0_idr<   )r   r*   Zocsp_requestr   r   r   r>   h  s    z_OCSPRequest.__init__c             C   s   t | j| jS )N)r-   r6   r<   )r   r   r   r   rZ   v  s    z_OCSPRequest.issuer_key_hashc             C   s   t | j| jS )N)r.   r6   r<   )r   r   r   r   r[   z  s    z_OCSPRequest.issuer_name_hashc             C   s   t | j| jS )N)r0   r6   r<   )r   r   r   r   r]   ~  s    z_OCSPRequest.serial_numberc             C   s   t | j| jS )N)r4   r6   r<   )r   r   r   r   r\     s    z_OCSPRequest.hash_algorithmc             C   s   | j jj| jS )N)r6   Z_ocsp_req_ext_parserr^   ro   )r   r   r   r   r_     s    z_OCSPRequest.extensionsc             C   sL   |t jjk	rtd| jj }| jjj|| j}| jj	|dk | jj
|S )Nz/The only allowed encoding value is Encoding.DERr   )r   ra   rb   r   r6   rc   r&   Zi2d_OCSP_REQUEST_bioro   r)   rd   )r   re   rf   r,   r   r   r   rg     s    
z_OCSPRequest.public_bytesN)rh   ri   rj   r>   rk   rZ   r[   r]   r\   r   rl   r_   rg   r   r   r   r   rm   f  s   rm   )&Z
__future__r   r   r   r    Zcryptographyr   r   Zcryptography.exceptionsr   Z0cryptography.hazmat.backends.openssl.decode_asn1r   r	   r
   r   r   r   Z)cryptography.hazmat.backends.openssl.x509r   Zcryptography.hazmat.primitivesr   Zcryptography.x509.ocspr   r   r   r   r   r   r   r"   r-   r.   r0   r4   Zregister_interfaceobjectr5   rm   r   r   r   r   <module>   s"    $
 ~