U
    ÈZjuy  ã                   @   s   d ddddgZ ddlZddlZddlmZ ddlmZmZmZ dd	l	m
Z
mZ dd
lmZ ddlmZ ddlmZmZmZ ddlmZmZmZ G dd„ deƒZd#dd „Zd$dd„Zdd„ Zdd„ Zdd„ Zdd„ Zdd„ Z dd„ Z!dd „ Z"d%d!d„Z#e#Z$d"Z%dS )&ÚgenerateÚ	constructÚ
import_keyÚRsaKeyÚoidé    N)ÚRandom)ÚtobytesÚbordÚtostr)ÚDerSequenceÚDerNull)Úbytes_to_long)ÚInteger)Útest_probable_primeÚgenerate_probable_primeÚ	COMPOSITE)Ú_expand_subject_public_key_infoÚ_create_subject_public_key_infoÚ _extract_subject_public_key_infoc                   @   sR  e Zd ZdZdd„ Zedd„ ƒZedd„ ƒZedd	„ ƒZed
d„ ƒZ	edd„ ƒZ
edd„ ƒZedd„ ƒZedd„ ƒZedd„ ƒZedd„ ƒZdd„ Zdd„ Zdd„ Zdd„ Zd d!„ Zd"d#„ Zd$d%„ Zd&d'„ Zd(d)„ Zd*d+„ Zd,d-„ Zd.d/„ Zd0d1„ Zd2d3„ ZdKd7d8„Zd9d:„ Zd;d<„ Z d=d>„ Z!d?d@„ Z"dAdB„ Z#dCdD„ Z$dEdF„ Z%dGdH„ Z&dIdJ„ Z'd5S )Lr   a×  Class defining an RSA key, private or public.
    Do not instantiate directly.
    Use :func:`generate`, :func:`construct` or :func:`import_key` instead.

    :ivar n: RSA modulus
    :vartype n: integer

    :ivar e: RSA public exponent
    :vartype e: integer

    :ivar d: RSA private exponent
    :vartype d: integer

    :ivar p: First factor of the RSA modulus
    :vartype p: integer

    :ivar q: Second factor of the RSA modulus
    :vartype q: integer

    :ivar invp: Chinese remainder component (:math:`p^{-1} \text{mod } q`)
    :vartype invp: integer

    :ivar invq: Chinese remainder component (:math:`q^{-1} \text{mod } p`)
    :vartype invq: integer

    :ivar u: Same as ``invp``
    :vartype u: integer
    c                 K   sŒ   t | ¡ ƒ}t dƒ}|t dƒB }|||fkr4tdƒ‚| ¡ D ]\}}t| d| |ƒ q<||krˆ| j| jd  | _| j| jd  | _	d| _
dS )a.  Build an RSA key.

        :Keywords:
          n : integer
            The modulus.
          e : integer
            The public exponent.
          d : integer
            The private exponent. Only required for private keys.
          p : integer
            The first factor of the modulus. Only required for private keys.
          q : integer
            The second factor of the modulus. Only required for private keys.
          u : integer
            The CRT coefficient (inverse of p modulo q). Only required for
            private keys.
        ©ÚnÚe)ÚpÚqÚdÚuzSome RSA components are missingÚ_é   N)ÚsetÚkeysÚ
ValueErrorÚitemsÚsetattrÚ_dÚ_pÚ_dpÚ_qÚ_dqÚ_invq)ÚselfÚkwargsZ	input_setZ
public_setZprivate_setÚ	componentÚvalue© r-   úW/var/www/html/TRUCKING_PROJECT/venv/lib/python3.8/site-packages/Crypto/PublicKey/RSA.pyÚ__init__R   s    zRsaKey.__init__c                 C   s
   t | jƒS ©N)ÚintÚ_n©r)   r-   r-   r.   r   q   s    zRsaKey.nc                 C   s
   t | jƒS r0   )r1   Ú_er3   r-   r-   r.   r   u   s    zRsaKey.ec                 C   s   |   ¡ stdƒ‚t| jƒS )Nz-No private exponent available for public keys)Úhas_privateÚAttributeErrorr1   r#   r3   r-   r-   r.   r   y   s    zRsaKey.dc                 C   s   |   ¡ stdƒ‚t| jƒS )Nz.No CRT component 'p' available for public keys)r5   r6   r1   r$   r3   r-   r-   r.   r      s    zRsaKey.pc                 C   s   |   ¡ stdƒ‚t| jƒS )Nz.No CRT component 'q' available for public keys)r5   r6   r1   r&   r3   r-   r-   r.   r   …   s    zRsaKey.qc                 C   s   |   ¡ stdƒ‚t| jƒS )Nz/No CRT component 'dp' available for public keys)r5   r6   r1   r%   r3   r-   r-   r.   Údp‹   s    z	RsaKey.dpc                 C   s   |   ¡ stdƒ‚t| jƒS )Nz/No CRT component 'dq' available for public keys)r5   r6   r1   r'   r3   r-   r-   r.   Údq‘   s    z	RsaKey.dqc                 C   s4   |   ¡ stdƒ‚| jd kr*| j | j¡| _t| jƒS )Nz1No CRT component 'invq' available for public keys)r5   r6   r(   r&   Úinverser$   r1   r3   r-   r-   r.   Úinvq—   s
    
zRsaKey.invqc                 C   s   | j S r0   )r   r3   r-   r-   r.   ÚinvpŸ   s    zRsaKey.invpc                 C   s   |   ¡ stdƒ‚t| jƒS )Nz.No CRT component 'u' available for public keys)r5   r6   r1   Ú_ur3   r-   r-   r.   r   £   s    zRsaKey.uc                 C   s
   | j  ¡ S )zSize of the RSA modulus in bits©r2   Úsize_in_bitsr3   r-   r-   r.   r>   ©   s    zRsaKey.size_in_bitsc                 C   s   | j  ¡ d d d S )z9The minimal amount of bytes that can hold the RSA modulusr   é   r=   r3   r-   r-   r.   Úsize_in_bytes­   s    zRsaKey.size_in_bytesc                 C   s8   d|  kr| j k s n tdƒ‚ttt|ƒ| j| j ƒƒS )Nr   zPlaintext too large)r2   r    r1   Úpowr   r4   )r)   Ú	plaintextr-   r-   r.   Ú_encrypt±   s    zRsaKey._encryptc           	      C   s¼   d|  kr| j k s n tdƒ‚|  ¡ s0tdƒ‚tjd| j d�}t|ƒt|| j| j ƒ | j  }t|| j| j	ƒ}t|| j
| jƒ}|| | j | j }|| j	 | }t | | j ¡|| j ¡}|S )Nr   zCiphertext too largezThis is not a private keyr   )Zmin_inclusiveZmax_exclusive)r2   r    r5   Ú	TypeErrorr   Zrandom_rangerA   r4   r%   r$   r'   r&   r<   Z_mult_modulo_bytesr9   )	r)   Ú
ciphertextÚrÚcpÚm1Úm2ÚhÚmpÚresultr-   r-   r.   Ú_decrypt_to_bytes¶   s     
ýzRsaKey._decrypt_to_bytesc                 C   s   t |  |¡ƒS )zLegacy private method)r   rM   ©r)   rE   r-   r-   r.   Ú_decryptÏ   s    zRsaKey._decryptc                 C   s
   t | dƒS )z"Whether this is an RSA private keyr#   )Úhasattrr3   r-   r-   r.   r5   Ô   s    zRsaKey.has_privatec                 C   s   dS ©NTr-   r3   r-   r-   r.   Úcan_encryptÙ   s    zRsaKey.can_encryptc                 C   s   dS rQ   r-   r3   r-   r-   r.   Úcan_signÜ   s    zRsaKey.can_signc                 C   s   t | j| jd�S )z^A matching RSA public key.

        Returns:
            a new :class:`RsaKey` object
        r   )r   r2   r4   r3   r-   r-   r.   Ú
public_keyß   s    zRsaKey.public_keyc                 C   sH   |   ¡ |  ¡ krdS | j|jks,| j|jkr0dS |   ¡ s<dS | j|jkS )NFT)r5   r   r   r   ©r)   Úotherr-   r-   r.   Ú__eq__ç   s    zRsaKey.__eq__c                 C   s
   | |k S r0   r-   rU   r-   r-   r.   Ú__ne__ð   s    zRsaKey.__ne__c                 C   s   ddl m} |‚d S )Nr   )ÚPicklingError)ÚpicklerY   )r)   rY   r-   r-   r.   Ú__getstate__ó   s    zRsaKey.__getstate__c                 C   sP   |   ¡ r2dt| jƒt| jƒt| jƒt| jƒf }nd}dt| jƒt| jƒ|f S )Nz, d=%d, p=%d, q=%d, u=%dÚ zRsaKey(n=%d, e=%d%s))r5   r1   r#   r$   r&   r<   r2   r4   )r)   Úextrar-   r-   r.   Ú__repr__ø   s     ÿzRsaKey.__repr__c                 C   s"   |   ¡ rd}nd}d|t| ƒf S )NZPrivateZPublicz%s RSA key at 0x%X)r5   Úid)r)   Úkey_typer-   r-   r.   Ú__str__   s    zRsaKey.__str__ÚPEMNr   c                 C   s  |dk	rt |ƒ}|dkrtj}|dkr¤dd„ | j| jfD ƒ\}}t|d ƒd@ rXd| }t|d ƒd@ rpd| }d||g}	d	 d
d„ |	D ƒ¡}
dt |
¡dd…  S |  	¡ �r˜t
d| j| j| j| j| j| j| jd  | j| jd  t| jƒ | j¡g	ƒ ¡ }|dk�r$d}|dk�r–|�r–tdƒ‚nrddlm} |dk�r^|dk�r^d}|j|tdtƒ d�}n8d}|�sz|�rvtdƒ‚d}|j|t|||tƒ d�}d}nd}ttt
| j| jgƒtƒ ƒ}|dk�rÄ|S |dk�ròddlm} | ||||¡}t |ƒS td| ƒ‚dS )aØ  Export this RSA key.

        Keyword Args:
          format (string):
            The desired output format:

            - ``'PEM'``. (default) Text output, according to `RFC1421`_/`RFC1423`_.
            - ``'DER'``. Binary output.
            - ``'OpenSSH'``. Text output, according to the OpenSSH specification.
              Only suitable for public keys (not private keys).

            Note that PEM contains a DER structure.

          passphrase (bytes or string):
            (*Private keys only*) The passphrase to protect the
            private key.

          pkcs (integer):
            (*Private keys only*) The standard to use for
            serializing the key: PKCS#1 or PKCS#8.

            With ``pkcs=1`` (*default*), the private key is encoded with a
            simple `PKCS#1`_ structure (``RSAPrivateKey``). The key cannot be
            securely encrypted.

            With ``pkcs=8``, the private key is encoded with a `PKCS#8`_ structure
            (``PrivateKeyInfo``). PKCS#8 offers the best ways to securely
            encrypt the key.

            .. note::
                This parameter is ignored for a public key.
                For DER and PEM, the output is always an
                ASN.1 DER ``SubjectPublicKeyInfo`` structure.

          protection (string):
            (*For private keys only*)
            The encryption scheme to use for protecting the private key
            using the passphrase.

            You can only specify a value if ``pkcs=8``.
            For all possible protection schemes,
            refer to :ref:`the encryption parameters of PKCS#8<enc_params>`.
            The recommended value is
            ``'PBKDF2WithHMAC-SHA512AndAES256-CBC'``.

            If ``None`` (default), the behavior depends on :attr:`format`:

            - if ``format='PEM'``, the obsolete PEM encryption scheme is used.
              It is based on MD5 for key derivation, and 3DES for encryption.

            - if ``format='DER'``, the ``'PBKDF2WithHMAC-SHA1AndDES-EDE3-CBC'``
              scheme is used.

          prot_params (dict):
            (*For private keys only*)

            The parameters to use to derive the encryption key
            from the passphrase. ``'protection'`` must be also specified.
            For all possible values,
            refer to :ref:`the encryption parameters of PKCS#8<enc_params>`.
            The recommendation is to use ``{'iteration_count':21000}`` for PBKDF2,
            and ``{'iteration_count':131072}`` for scrypt.

          randfunc (callable):
            A function that provides random bytes. Only used for PEM encoding.
            The default is :func:`Crypto.Random.get_random_bytes`.

        Returns:
          bytes: the encoded key

        Raises:
          ValueError:when the format is unknown or when you try to encrypt a private
            key with *DER* format and PKCS#1.

        .. warning::
            If you don't provide a pass phrase, the private key will be
            exported in the clear!

        .. _RFC1421:    http://www.ietf.org/rfc/rfc1421.txt
        .. _RFC1423:    http://www.ietf.org/rfc/rfc1423.txt
        .. _`PKCS#1`:   http://www.ietf.org/rfc/rfc3447.txt
        .. _`PKCS#8`:   http://www.ietf.org/rfc/rfc5208.txt
        NZOpenSSHc                 S   s   g | ]}|  ¡ ‘qS r-   )Úto_bytes©Ú.0Úxr-   r-   r.   Ú
<listcomp>d  s     z%RsaKey.export_key.<locals>.<listcomp>r   é€   ó    s   ssh-rsaó    c                 S   s    g | ]}t  d t|ƒ¡| ‘qS )ú>I)ÚstructÚpackÚlen)re   Úkpr-   r-   r.   rg   j  s     ó   ssh-rsa éÿÿÿÿr   zRSA PRIVATE KEYZDERz&PKCS#1 private key cannot be encrypted©ÚPKCS8rb   zPRIVATE KEY)Ú
key_paramszENCRYPTED PRIVATE KEYz"'protection' parameter must be setz"PBKDF2WithHMAC-SHA1AndDES-EDE3-CBC)Úprot_paramsrt   z
PUBLIC KEY©rb   z3Unknown key format '%s'. Cannot export the RSA key.)r   r   Úget_random_bytesr4   r2   r	   ÚjoinÚbinasciiÚ
b2a_base64r5   r   r   r   r   r   r   r   r9   Úencoder    Ú	Crypto.IOrs   Úwrapr   r   r   rb   )r)   ÚformatÚ
passphraseZpkcsZ
protectionÚrandfuncru   Ze_bytesZn_bytesÚkeypartsÚ	keystringZ
binary_keyr`   rs   rb   Zpem_strr-   r-   r.   Ú
export_key  sx    V

ø




ÿ ýÿý

zRsaKey.export_keyc                 O   s   | j ||ŽS ©ú:meta private:)rƒ   )r)   Úargsr*   r-   r-   r.   Ú	exportKey£  s    zRsaKey.exportKeyc                 C   s   |   ¡ S r„   )rT   r3   r-   r-   r.   Ú	publickey§  s    zRsaKey.publickeyc                 C   s   t dƒ‚dS ©r…   z,Use module Crypto.Signature.pkcs1_15 insteadN©ÚNotImplementedError)r)   ÚMÚKr-   r-   r.   Úsign¬  s    zRsaKey.signc                 C   s   t dƒ‚dS r‰   rŠ   )r)   rŒ   Ú	signaturer-   r-   r.   Úverify°  s    zRsaKey.verifyc                 C   s   t dƒ‚dS ©r…   z+Use module Crypto.Cipher.PKCS1_OAEP insteadNrŠ   )r)   rB   r�   r-   r-   r.   Úencrypt´  s    zRsaKey.encryptc                 C   s   t dƒ‚dS r‘   rŠ   rN   r-   r-   r.   Údecrypt¸  s    zRsaKey.decryptc                 C   s   t ‚dS ©r…   NrŠ   ©r)   rŒ   ÚBr-   r-   r.   Úblind¼  s    zRsaKey.blindc                 C   s   t ‚dS r”   rŠ   r•   r-   r-   r.   ÚunblindÀ  s    zRsaKey.unblindc                 C   s   t ‚dS r”   rŠ   r3   r-   r-   r.   ÚsizeÄ  s    zRsaKey.size)rb   Nr   NNN)(Ú__name__Ú
__module__Ú__qualname__Ú__doc__r/   Úpropertyr   r   r   r   r   r7   r8   r:   r;   r   r>   r@   rC   rM   rO   r5   rR   rS   rT   rW   rX   r[   r^   ra   rƒ   r‡   rˆ   rŽ   r�   r’   r“   r—   r˜   r™   r-   r-   r-   r.   r   4   sf   









	      ÿ
 é  c                    sb  | dk rt dƒ‚ˆ d dks$ˆ dk r,t dƒ‚|dkr:tj}tdƒ }}tˆ ƒ‰ | ¡ | k�r0|d| d > k �r0| d }| | }tdƒd| d >  ¡  ‰‰||krºtdƒd| d >  ¡ ‰‡ ‡fd	d
„}t|||d�‰tdƒ| d d > ‰‡ ‡‡‡fdd„}t|||d�}	ˆ|	 }ˆd  |	d ¡}
ˆ  |
¡}qNˆ|	k�rD|	ˆ ‰}	ˆ |	¡}t	|ˆ |ˆ|	|d�S )aB  Create a new RSA key pair.

    The algorithm closely follows NIST `FIPS 186-4`_ in its
    sections B.3.1 and B.3.3. The modulus is the product of
    two non-strong probable primes.
    Each prime passes a suitable number of Miller-Rabin tests
    with random bases and a single Lucas test.

    Args:
      bits (integer):
        Key length, or size (in bits) of the RSA modulus.
        It must be at least 1024, but **2048 is recommended.**
        The FIPS standard only defines 1024, 2048 and 3072.
    Keyword Args:
      randfunc (callable):
        Function that returns random bytes.
        The default is :func:`Crypto.Random.get_random_bytes`.
      e (integer):
        Public RSA exponent. It must be an odd positive integer.
        It is typically a small number with very few ones in its
        binary representation.
        The FIPS standard requires the public exponent to be
        at least 65537 (the default).

    Returns: an RSA key object (:class:`RsaKey`, with private key).

    .. _FIPS 186-4: http://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.186-4.pdf
    i   z"RSA modulus length must be >= 1024é   r   é   zBRSA public exponent must be a positive, odd integer larger than 2.Nr   c                    s   | ˆko| d   ˆ ¡dkS ©Nr   )Úgcd©Ú	candidate)r   Úmin_pr-   r.   Úfilter_pý  s    zgenerate.<locals>.filter_p)Z
exact_bitsr€   Zprime_filteréd   c                    s*   | ˆko(| d   ˆ ¡dko(t| ˆ ƒˆkS r¢   )r£   Úabsr¤   )r   Úmin_distanceÚmin_qr   r-   r.   Úfilter_q  s
    ÿþzgenerate.<locals>.filter_q©r   r   r   r   r   r   )
r    r   rw   r   r>   Úsqrtr   Úlcmr9   r   )Úbitsr€   r   r   r   Zsize_qZsize_pr§   r¬   r   r¯   r   r-   )r   rª   r¦   r«   r   r.   r   É  s@     þþ


Tc                 C   sî  G dd„ dt ƒ}|ƒ }td| ƒD ]\}}t||t|ƒƒ q |j}|j}t|dƒs`t||d�}�n0|j}	t|dƒr~|j	}
|j
}nà|	| d }|}|d d	kr¤|d }qŽd
}tdƒ}|�s6|dk �r6t|ƒ}||k �r,t|||ƒ}|dk�r"||d k�r"t|d|ƒdk�r"t|ƒ |d ¡}
d}�q,|d9 }qÈ|d7 }q°|�sDtdƒ‚||
 d	k�sVt‚||
 }t|dƒ�rr|j}n
|
 |¡}t|||	|
||d�}|�rê|dk�sª||k�r²tdƒ‚t|ƒ |¡dk�rÎtdƒ‚|d@ �sàtdƒ‚| ¡ �rê|	dk�sþ|	|k�rtdƒ‚t|ƒ |	¡dk�r"tdƒ‚|
| |k�r8tdƒ‚t|
ƒtk�rNtdƒ‚t|ƒtk�rdtdƒ‚|
d |d  }||
d  |d ¡ }||	 t|ƒ dk�r¨tdƒ‚t|dƒ�rê|dk�sÈ||k�rÐtdƒ‚|
| | dk�rêtdƒ‚|S )a3  Construct an RSA key from a tuple of valid RSA components.

    The modulus **n** must be the product of two primes.
    The public exponent **e** must be odd and larger than 1.

    In case of a private key, the following equations must apply:

    .. math::

        \begin{align}
        p*q &= n \\
        e*d &\equiv 1 ( \text{mod lcm} [(p-1)(q-1)]) \\
        p*u &\equiv 1 ( \text{mod } q)
        \end{align}

    Args:
        rsa_components (tuple):
            A tuple of integers, with at least 2 and no
            more than 6 items. The items come in the following order:

            1. RSA modulus *n*.
            2. Public exponent *e*.
            3. Private exponent *d*.
               Only required if the key is private.
            4. First factor of *n* (*p*).
               Optional, but the other factor *q* must also be present.
            5. Second factor of *n* (*q*). Optional.
            6. CRT coefficient *q*, that is :math:`p^{-1} \text{mod }q`. Optional.

    Keyword Args:
        consistency_check (boolean):
            If ``True``, the library will verify that the provided components
            fulfil the main RSA properties.

    Raises:
        ValueError: when the key being imported fails the most basic RSA validity checks.

    Returns: An RSA key object (:class:`RsaKey`).
    c                   @   s   e Zd ZdS )zconstruct.<locals>.InputCompsN)rš   r›   rœ   r-   r-   r-   r.   Ú
InputCompsD  s   r±   r­   r   r   r   r   r    r   Fr¨   Tz2Unable to compute factors p and q from exponent d.r   zInvalid RSA public exponentz-RSA public exponent is not coprime to moduluszRSA modulus is not oddzInvalid RSA private exponentz.RSA private exponent is not coprime to modulusz RSA factors do not match moduluszRSA factor p is compositezRSA factor q is compositezInvalid RSA conditionzInvalid RSA component uzInvalid RSA component u with p)ÚobjectÚzipr"   r   r   r   rP   r   r   r   r   rA   r£   r    ÚAssertionErrorr   r9   r5   r   r   r1   )Zrsa_componentsZconsistency_checkr±   Zinput_compsÚcompr,   r   r   Úkeyr   r   r   ZktotÚtZspottedÚaÚkÚcandr   Úphir¯   r-   r-   r.   r     s€    )



*




c                 G   sN   t ƒ j| ddd�}|d dkr&tdƒ‚t|dd… t|d ƒ |d	 ¡g ƒS )
Né	   T©Znr_elementsZonly_ints_expectedr   z(No PKCS#1 encoding of an RSA private keyr   é   é   é   )r   Údecoder    r   r   r9   ©Úencodedr*   Úderr-   r-   r.   Ú_import_pkcs1_private«  s    rÅ   c                 G   s   t ƒ j| ddd�}t|ƒS )Nr    Tr½   )r   rÁ   r   rÂ   r-   r-   r.   Ú_import_pkcs1_public¿  s    rÆ   c                 G   s6   t df}t| ƒ\}}}||ks&|d k	r.tdƒ‚t|ƒS )Nú1.2.840.113549.1.1.10zNo RSA subjectPublicKeyInfo)r   r   r    rÆ   )rÃ   r*   ÚoidsZalgoidZencoded_keyÚparamsr-   r-   r.   Ú_import_subjectPublicKeyInfoÈ  s
    rÊ   c                 G   s   t | ƒ}t|ƒS r0   )r   rÊ   )rÃ   r*   Zsp_infor-   r-   r.   Ú_import_x509_certÒ  s    rË   c                 C   sB   ddl m} tdf}| | |¡}|d |kr4tdƒ‚t|d |ƒS )Nr   rr   rÇ   zNo PKCS#8 encoded RSA keyr   )r|   rs   r   Úunwrapr    Ú_import_keyDER)rÃ   r   rs   rÈ   r¹   r-   r-   r.   Ú_import_pkcs8Ø  s    rÎ   c              	   C   sJ   t ttttf}|D ]*}z|| |ƒW   S  tk
r:   Y qX qtdƒ‚dS )z@Import an RSA key (public or private half), encoded in DER form.úRSA key format is not supportedN)rÅ   rÆ   rÊ   rË   rÎ   r    )Ú
extern_keyr   Z	decodingsZdecodingr-   r-   r.   rÍ   ã  s    ürÍ   c                 C   s´   ddl m}m}m}m} || |ƒ\}}|dkr6tdƒ‚||ƒ\}}||ƒ\}	}||ƒ\}
}||ƒ\}}||ƒ\}}||ƒ\}}||ƒ\}}||ƒ dd„ ||	|
|||fD ƒ}t|ƒS )Nr   )Úimport_openssh_private_genericÚ
read_bytesÚread_stringÚcheck_paddingzssh-rsazThis SSH key is not RSAc                 S   s   g | ]}t  |¡‘qS r-   )r   Ú
from_bytesrd   r-   r-   r.   rg   	  s     z/_import_openssh_private_rsa.<locals>.<listcomp>)Z_opensshrÑ   rÒ   rÓ   rÔ   r    r   )ÚdataÚpasswordrÑ   rÒ   rÓ   rÔ   Zssh_nameZ	decryptedr   r   r   Ziqmpr   r   r   ÚpaddedÚbuildr-   r-   r.   Ú_import_openssh_private_rsaõ  s    rÚ   c                 C   sV  ddl m} t| ƒ} |dk	r$t|ƒ}|  d¡rVt| ƒ}| ||¡\}}}t||ƒ}|S |  d¡rˆ| t| ƒ|¡\}}}|r~d}t||ƒS |  d¡�r t 	|  
d¡d ¡}	g }
t|	ƒd	krøt d
|	dd	… ¡d }|
 |	d	d	| … ¡ |	d	| d… }	q¬t |
d ¡}t |
d ¡}t||gƒS t| ƒdk�rJt| d ƒdk�rJt| |ƒS tdƒ‚dS )aé  Import an RSA key (public or private).

    Args:
      extern_key (string or byte string):
        The RSA key to import.

        The following formats are supported for an RSA **public key**:

        - X.509 certificate (binary or PEM format)
        - X.509 ``subjectPublicKeyInfo`` DER SEQUENCE (binary or PEM
          encoding)
        - `PKCS#1`_ ``RSAPublicKey`` DER SEQUENCE (binary or PEM encoding)
        - An OpenSSH line (e.g. the content of ``~/.ssh/id_ecdsa``, ASCII)

        The following formats are supported for an RSA **private key**:

        - PKCS#1 ``RSAPrivateKey`` DER SEQUENCE (binary or PEM encoding)
        - `PKCS#8`_ ``PrivateKeyInfo`` or ``EncryptedPrivateKeyInfo``
          DER SEQUENCE (binary or PEM encoding)
        - OpenSSH (text format, introduced in `OpenSSH 6.5`_)

        For details about the PEM encoding, see `RFC1421`_/`RFC1423`_.

      passphrase (string or byte string):
        For private keys only, the pass phrase that encrypts the key.

    Returns: An RSA key object (:class:`RsaKey`).

    Raises:
      ValueError/IndexError/TypeError:
        When the given key cannot be parsed (possibly because the pass
        phrase is wrong).

    .. _RFC1421: http://www.ietf.org/rfc/rfc1421.txt
    .. _RFC1423: http://www.ietf.org/rfc/rfc1423.txt
    .. _`PKCS#1`: http://www.ietf.org/rfc/rfc3447.txt
    .. _`PKCS#8`: http://www.ietf.org/rfc/rfc5208.txt
    .. _`OpenSSH 6.5`: https://flak.tedunangst.com/post/new-openssh-key-format-and-bcrypt-pbkdf
    r   rv   Ns   -----BEGIN OPENSSH PRIVATE KEYs   -----rp   ó    r   r¿   rk   r    é0   rÏ   )r|   rb   r   Ú
startswithr
   rÁ   rÚ   rÍ   ry   Ú
a2b_base64Úsplitrn   rl   ÚunpackÚappendr   rÕ   r   r	   r    )rÐ   r   rb   Ztext_encodedZopenssh_encodedÚmarkerZenc_flagrL   rÄ   r‚   r�   Úlengthr   r   r-   r-   r.   r     s6    )



 
z1.2.840.113549.1.1.1)NrŸ   )T)N)&Ú__all__ry   rl   ZCryptor   ZCrypto.Util.py3compatr   r	   r
   ZCrypto.Util.asn1r   r   ZCrypto.Util.numberr   ZCrypto.Math.Numbersr   ZCrypto.Math.Primalityr   r   r   ZCrypto.PublicKeyr   r   r   r²   r   r   r   rÅ   rÆ   rÊ   rË   rÎ   rÍ   rÚ   r   Z	importKeyr   r-   r-   r-   r.   Ú<module>    s:    ÿ   
R
 	

P
