U
    ÈZjè>  ã                   @   sX  d Z ddlmZmZmZmZ ddlZddlmZ ddl	m
Z
mZmZmZmZmZmZmZmZ ddlmZmZmZmZmZmZmZmZ G dd	„ d	eƒZG d
d„ deƒZG dd„ deƒZG dd„ deƒZG dd„ deƒZ G dd„ deƒZ!G dd„ deƒZ"G dd„ deƒZ#G dd„ deƒZ$G dd„ deƒZ%G dd„ deƒZ&G dd„ deƒZ'G d d!„ d!eƒZ(dS )"z¹
ASN.1 type classes for certificate revocation lists (CRL). Exports the
following items:

 - CertificateList()

Other type classes are defined that help compose the types listed above.
é    )Úunicode_literalsÚdivisionÚabsolute_importÚprint_functionNé   )ÚSignedDigestAlgorithm)	ÚBooleanÚ
EnumeratedÚGeneralizedTimeÚIntegerÚObjectIdentifierÚOctetBitStringÚParsableOctetStringÚSequenceÚ
SequenceOf)ÚAuthorityInfoAccessSyntaxÚAuthorityKeyIdentifierÚCRLDistributionPointsÚDistributionPointNameÚGeneralNamesÚNameÚReasonFlagsÚTimec                   @   s   e Zd ZddddœZdS )ÚVersionZv1Zv2Zv3)r   r   é   N©Ú__name__Ú
__module__Ú__qualname__Ú_map© r    r    úQ/var/www/html/TRUCKING_PROJECT/venv/lib/python3.8/site-packages/asn1crypto/crl.pyr   +   s   ýr   c                
   @   sd   e Zd Zdedddœfdedddœfd	ed
ddœfdedddœfdedddœfdedddœfgZdS )ÚIssuingDistributionPointÚdistribution_pointr   T©ÚexplicitÚoptionalZonly_contains_user_certsr   F)ÚimplicitÚdefaultZonly_contains_ca_certsr   Zonly_some_reasonsé   )r'   r&   Zindirect_crlé   Zonly_contains_attribute_certsé   N)r   r   r   r   r   r   Ú_fieldsr    r    r    r!   r"   3   s   úr"   c                   @   s    e Zd ZddddddddœZd	S )
ÚTBSCertListExtensionIdÚissuer_alt_nameÚ
crl_numberÚdelta_crl_indicatorÚissuing_distribution_pointÚauthority_key_identifierÚfreshest_crlÚauthority_information_access)z	2.5.29.18z	2.5.29.20z	2.5.29.27z	2.5.29.28z	2.5.29.35z	2.5.29.46z1.3.6.1.5.5.7.1.1Nr   r    r    r    r!   r-   >   s   ùr-   c                   @   s@   e Zd ZdefdeddifdefgZdZee	e	e
eeedœZdS )	ÚTBSCertListExtensionÚextn_idÚcriticalr(   FÚ
extn_value©r6   r8   )r.   r/   r0   r1   r2   r3   r4   N)r   r   r   r-   r   r   r,   Ú	_oid_pairr   r   r"   r   r   r   Ú
_oid_specsr    r    r    r!   r5   J   s   ýùr5   c                   @   s   e Zd ZeZdS )ÚTBSCertListExtensionsN)r   r   r   r5   Ú_child_specr    r    r    r!   r<   ]   s   r<   c                   @   s2   e Zd Zddddddddd	d
dœ
Zedd„ ƒZdS )Ú	CRLReasonÚunspecifiedÚkey_compromiseÚca_compromiseÚaffiliation_changedÚ
supersededÚcessation_of_operationÚcertificate_holdÚremove_from_crlÚprivilege_withdrawnÚaa_compromise)
r   r   r   r)   r*   r+   é   é   é	   é
   c                 C   s    ddddddddd	d
dœ
| j  S )a  
        :return:
            A unicode string with revocation description that is suitable to
            show to end-users. Starts with a lower case letter and phrased in
            such a way that it makes sense after the phrase "because of" or
            "due to".
        zan unspecified reasonza compromised keyzthe CA being compromisedzan affiliation changezcertificate supersessionza cessation of operationza certificate holdzremoval from the CRLzprivilege withdrawlzthe AA being compromised)
r?   r@   rA   rB   rC   rD   rE   rF   rG   rH   ©Únative©Úselfr    r    r!   Úhuman_friendlyo   s    öõzCRLReason.human_friendlyN)r   r   r   r   ÚpropertyrQ   r    r    r    r!   r>   a   s   ör>   c                   @   s   e Zd ZdddddœZdS )ÚCRLEntryExtensionIdÚ
crl_reasonÚhold_instruction_codeÚinvalidity_dateÚcertificate_issuer)z	2.5.29.21z	2.5.29.23z	2.5.29.24z	2.5.29.29Nr   r    r    r    r!   rS   ‡   s
   ürS   c                   @   s:   e Zd ZdefdeddifdefgZdZee	e
edœZdS )	ÚCRLEntryExtensionr6   r7   r(   Fr8   r9   )rT   rU   rV   rW   N)r   r   r   rS   r   r   r,   r:   r>   r   r
   r   r;   r    r    r    r!   rX   �   s   ýürX   c                   @   s   e Zd ZeZdS )ÚCRLEntryExtensionsN)r   r   r   rX   r=   r    r    r    r!   rY       s   rY   c                   @   s„   e Zd ZdefdefdeddifgZdZdZdZ	dZ
dZdZdd	„ Zed
d„ ƒZedd„ ƒZedd„ ƒZedd„ ƒZedd„ ƒZdS )ÚRevokedCertificateZuser_certificateZrevocation_dateÚcrl_entry_extensionsr&   TFNc                 C   sd   t ƒ | _| d D ]H}|d j}d| }t| |ƒrBt| ||d jƒ |d jr| j |¡ qd| _dS )úv
        Sets common named extensions to private attributes and creates a list
        of critical extensions
        r[   r6   ú	_%s_valuer8   r7   TN©ÚsetÚ_critical_extensionsrN   ÚhasattrÚsetattrÚparsedÚaddÚ_processed_extensions©rP   Ú	extensionÚnameZattribute_namer    r    r!   Ú_set_extensions²   s    


z"RevokedCertificate._set_extensionsc                 C   s   | j s|  ¡  | jS ©z²
        Returns a set of the names (or OID if not a known extension) of the
        extensions marked as critical

        :return:
            A set of unicode strings
        ©re   ri   r`   rO   r    r    r!   Úcritical_extensionsÄ   s    
z&RevokedCertificate.critical_extensionsc                 C   s   | j dkr|  ¡  | jS )zŽ
        This extension indicates the reason that a certificate was revoked.

        :return:
            None or a CRLReason object
        F)re   ri   Ú_crl_reason_valuerO   r    r    r!   Úcrl_reason_valueÒ   s    	
z#RevokedCertificate.crl_reason_valuec                 C   s   | j dkr|  ¡  | jS )a=  
        This extension indicates the suspected date/time the private key was
        compromised or the certificate became invalid. This would usually be
        before the revocation date, which is when the CA processed the
        revocation.

        :return:
            None or a GeneralizedTime object
        F)re   ri   Ú_invalidity_date_valuerO   r    r    r!   Úinvalidity_date_valueß   s    
z(RevokedCertificate.invalidity_date_valuec                 C   s   | j dkr|  ¡  | jS )a  
        This extension indicates the issuer of the certificate in question,
        and is used in indirect CRLs. CRL entries without this extension are
        for certificates issued from the last seen issuer.

        :return:
            None or an x509.GeneralNames object
        F)re   ri   Ú_certificate_issuer_valuerO   r    r    r!   Úcertificate_issuer_valueï   s    
z+RevokedCertificate.certificate_issuer_valuec                 C   s>   | j dkr8d| _ | jr8| jD ]}|jdkr|j| _  q8q| j S )zi
        :return:
            None, or an asn1crypto.x509.Name object for the issuer of the cert
        FNZdirectory_name)Ú_issuer_namerr   rh   Úchosen)rP   Úgeneral_namer    r    r!   Úissuer_nameþ   s    


zRevokedCertificate.issuer_name)r   r   r   r   r   rY   r,   re   r`   rm   ro   rq   rs   ri   rR   rl   rn   rp   rr   rv   r    r    r    r!   rZ   ¤   s*   ý



rZ   c                   @   s   e Zd ZeZdS )ÚRevokedCertificatesN)r   r   r   rZ   r=   r    r    r    r!   rw     s   rw   c                   @   sT   e Zd Zdeddifdefdefdefdeddifdeddifd	ed
ddœfgZ	dS )ÚTbsCertListÚversionr&   TÚ	signatureÚissuerZthis_updateZnext_updateZrevoked_certificatesÚcrl_extensionsr   r$   N)
r   r   r   r   r   r   r   rw   r<   r,   r    r    r    r!   rx     s   ùrx   c                   @   s  e Zd ZdefdefdefgZdZdZdZ	dZ
dZdZdZdZdZdZdZdZdZdd„ Zedd	„ ƒZed
d„ ƒZedd„ ƒZedd„ ƒZedd„ ƒZedd„ ƒZedd„ ƒZedd„ ƒZedd„ ƒZedd„ ƒZedd„ ƒZ edd„ ƒZ!ed d!„ ƒZ"ed"d#„ ƒZ#ed$d%„ ƒZ$dS )&ÚCertificateListÚtbs_cert_listZsignature_algorithmrz   FNc                 C   sh   t ƒ | _| d d D ]H}|d j}d| }t| |ƒrFt| ||d jƒ |d jr| j |¡ qd| _dS )	r\   r~   r|   r6   r]   r8   r7   TNr^   rf   r    r    r!   ri   4  s    


zCertificateList._set_extensionsc                 C   s   | j s|  ¡  | jS rj   rk   rO   r    r    r!   rl   F  s    
z#CertificateList.critical_extensionsc                 C   s   | j dkr|  ¡  | jS )z·
        This extension allows associating one or more alternative names with
        the issuer of the CRL.

        :return:
            None or an x509.GeneralNames object
        F)re   ri   Ú_issuer_alt_name_valuerO   r    r    r!   Úissuer_alt_name_valueT  s    

z%CertificateList.issuer_alt_name_valuec                 C   s   | j dkr|  ¡  | jS )zÌ
        This extension adds a monotonically increasing number to the CRL and is
        used to distinguish different versions of the CRL.

        :return:
            None or an Integer object
        F)re   ri   Ú_crl_number_valuerO   r    r    r!   Úcrl_number_valueb  s    

z CertificateList.crl_number_valuec                 C   s   | j dkr|  ¡  | jS )zÅ
        This extension indicates a CRL is a delta CRL, and contains the CRL
        number of the base CRL that it is a delta from.

        :return:
            None or an Integer object
        F)re   ri   Ú_delta_crl_indicator_valuerO   r    r    r!   Údelta_crl_indicator_valuep  s    

z)CertificateList.delta_crl_indicator_valuec                 C   s   | j dkr|  ¡  | jS )zÌ
        This extension includes information about what types of revocations
        and certificates are part of the CRL.

        :return:
            None or an IssuingDistributionPoint object
        F)re   ri   Ú!_issuing_distribution_point_valuerO   r    r    r!   Ú issuing_distribution_point_value~  s    

z0CertificateList.issuing_distribution_point_valuec                 C   s   | j dkr|  ¡  | jS )zÇ
        This extension helps in identifying the public key with which to
        validate the authenticity of the CRL.

        :return:
            None or an AuthorityKeyIdentifier object
        F)re   ri   Ú_authority_key_identifier_valuerO   r    r    r!   Úauthority_key_identifier_valueŒ  s    

z.CertificateList.authority_key_identifier_valuec                 C   s   | j dkr|  ¡  | jS )z´
        This extension is used in complete CRLs to indicate where a delta CRL
        may be located.

        :return:
            None or a CRLDistributionPoints object
        F)re   ri   Ú_freshest_crl_valuerO   r    r    r!   Úfreshest_crl_valueš  s    

z"CertificateList.freshest_crl_valuec                 C   s   | j dkr|  ¡  | jS )zÉ
        This extension is used to provide a URL with which to download the
        certificate used to sign this CRL.

        :return:
            None or an AuthorityInfoAccessSyntax object
        F)re   ri   Ú#_authority_information_access_valuerO   r    r    r!   Ú"authority_information_access_value¨  s    

z2CertificateList.authority_information_access_valuec                 C   s   | d d S )z_
        :return:
            An asn1crypto.x509.Name object for the issuer of the CRL
        r~   r{   r    rO   r    r    r!   r{   ¶  s    zCertificateList.issuerc                 C   s   | j s
dS | j d jS )zŠ
        :return:
            None or a byte string of the key_identifier from the authority key
            identifier extension
        NZkey_identifier)rˆ   rN   rO   r    r    r!   r2   ¿  s    z(CertificateList.authority_key_identifierc                 C   sp   | j dkrjg | _ | jrj| jD ]L}|d jdkr|d }|jdkrBq|j}| ¡ dd… dkr| j  |¡ q| j S )	zì
        :return:
            A list of unicode strings that are URLs that should contain either
            an individual DER-encoded X.509 certificate, or a DER-encoded CMS
            message containing multiple certificates
        NZaccess_methodZ
ca_issuersZaccess_locationÚuniform_resource_identifierr   é   zhttp://)Ú_issuer_cert_urlsrŒ   rN   rh   ÚlowerÚappend)rP   ÚentryÚlocationÚurlr    r    r!   Úissuer_cert_urlsÌ  s    	


z CertificateList.issuer_cert_urlsc                 C   sb   | j dkr\g | _ | jdk	r\| jD ]:}|d }|jdkr8q |jD ]}|jdkr>| j  |¡ q>q | j S )z—
        Returns delta CRL URLs - only applies to complete CRLs

        :return:
            A list of zero or more DistributionPoint objects
        Nr#   Zname_relative_to_crl_issuerr�   )Ú_delta_crl_distribution_pointsrŠ   rh   rt   r‘   )rP   r#   Zdistribution_point_nameru   r    r    r!   Údelta_crl_distribution_pointsâ  s    	





z-CertificateList.delta_crl_distribution_pointsc                 C   s
   | d j S )zE
        :return:
            A byte string of the signature
        rz   rM   rO   r    r    r!   rz   û  s    zCertificateList.signaturec                 C   s$   | j dkrt |  ¡ ¡ ¡ | _ | j S )zf
        :return:
            The SHA1 hash of the DER-encoded bytes of this certificate list
        N)Ú_sha1ÚhashlibÚsha1ÚdumpÚdigestrO   r    r    r!   rš     s    
zCertificateList.sha1c                 C   s$   | j dkrt |  ¡ ¡ ¡ | _ | j S )zi
        :return:
            The SHA-256 hash of the DER-encoded bytes of this certificate list
        N)Ú_sha256r™   Úsha256r›   rœ   rO   r    r    r!   rž     s    
zCertificateList.sha256)%r   r   r   rx   r   r   r,   re   r`   r   r�   rƒ   r…   r‡   r‰   r‹   r�   r–   r˜   r�   ri   rR   rl   r€   r‚   r„   r†   rˆ   rŠ   rŒ   r{   r2   r•   r—   rz   rš   rž   r    r    r    r!   r}     s`   ý














r}   ))Ú__doc__Ú
__future__r   r   r   r   r™   Zalgosr   Úcorer   r	   r
   r   r   r   r   r   r   Úx509r   r   r   r   r   r   r   r   r   r"   r-   r5   r<   r>   rS   rX   rY   rZ   rw   rx   r}   r    r    r    r!   Ú<module>   s$   	,(&	k