U
    ÈZjRn ã                   @   st  d Z ddlmZmZmZmZ ddlmZ ddlm	Z	 ddl
Z
ddlZddlZddlZddlZddlZddlmZ ddlmZmZ dd	lmZ dd
lmZmZmZ ddlmZmZmZmZ ddl m!Z!m"Z"m#Z#m$Z$m%Z%m&Z&m'Z'm(Z(m)Z)m*Z*m+Z+m,Z,m-Z-m.Z.m/Z/m0Z0m1Z1m2Z2m3Z3m4Z4m5Z5m6Z6m7Z7m8Z8m9Z9m:Z:m;Z;m<Z< ddl=m>Z> ddl?m@Z@mAZAmBZBmCZC G dd„ de*ƒZDG dd„ de*ƒZEG dd„ de*ƒZFG dd„ de0ƒZGG dd„ de3ƒZHG dd„ de4ƒZIG dd„ de"ƒZJG dd„ de3ƒZKG dd „ d e7ƒZLed!d"„ ƒZMG d#d$„ d$e%ƒZNG d%d&„ d&e.ƒZOG d'd(„ d(e3ƒZPG d)d*„ d*e6ƒZQG d+d,„ d,e4ƒZRG d-d.„ d.e%ƒZSG d/d0„ d0e3ƒZTG d1d2„ d2e%ƒZUG d3d4„ d4e%ƒZVG d5d6„ d6e%ƒZWG d7d8„ d8e5ƒZXG d9d:„ d:e5ƒZYG d;d<„ d<e4ƒZZG d=d>„ d>e4ƒZ[G d?d@„ d@e3ƒZ\G dAdB„ dBe3ƒZ]G dCdD„ dDe4ƒZ^G dEdF„ dFe3ƒZ_G dGdH„ dHe4ƒZ`G dIdJ„ dJe%ƒZaG dKdL„ dLe%ƒZbG dMdN„ dNe5ƒZcG dOdP„ dPe4ƒZdG dQdR„ dRe5ƒZeG dSdT„ dTe3ƒZfG dUdV„ dVe6ƒZgG dWdX„ dXe3ƒZhG dYdZ„ dZe%ƒZiG d[d\„ d\e+ƒZjG d]d^„ d^e+ƒZkG d_d`„ d`e3ƒZlG dadb„ dbe4ƒZmG dcdd„ dde3ƒZnG dedf„ dfe3ƒZoG dgdh„ dhe%ƒZpG didj„ dje4ƒZqG dkdl„ dle%ƒZrG dmdn„ dne3ƒZsG dodp„ dpe3ƒZtG dqdr„ dre3ƒZuG dsdt„ dte%ƒZvG dudv„ dve"ƒZwG dwdx„ dxe3ƒZxG dydz„ dze4ƒZyG d{d|„ d|e3ƒZzG d}d~„ d~e3ƒZ{G dd€„ d€e4ƒZ|G d�d‚„ d‚e%ƒZ}G dƒd„„ d„e4ƒZ~G d…d†„ d†e3ƒZG d‡dˆ„ dˆe3ƒZ€G d‰dŠ„ dŠe.ƒZ�G d‹dŒ„ dŒe3ƒZ‚G d�dŽ„ dŽe4ƒZƒG d�d�„ d�e.ƒZ„G d‘d’„ d’e3ƒZ…G d“d”„ d”e4ƒZ†G d•d–„ d–e3ƒZ‡G d—d˜„ d˜e4ƒZˆG d™dš„ dše3ƒZ‰G d›dœ„ dœe.ƒZŠG d�dž„ dže4ƒZ‹G dŸd „ d e.ƒZŒG d¡d¢„ d¢e3ƒZ�G d£d¤„ d¤e4ƒZŽG d¥d¦„ d¦e4ƒZ�G d§d¨„ d¨e4ƒZ�G d©dª„ dªe3ƒZ‘G d«d¬„ d¬e"ƒZ’G d­d®„ d®e+ƒZ“G d¯d°„ d°e3ƒZ”G d±d²„ d²e6ƒZ•G d³d´„ d´e3ƒZ–G dµd¶„ d¶e3ƒZ—G d·d¸„ d¸e6ƒZ˜G d¹dº„ dºe'ƒZ™G d»d¼„ d¼e'ƒZšG d½d¾„ d¾e'ƒZ›G d¿dÀ„ dÀe'ƒZœG dÁdÂ„ dÂe'ƒZ�G dÃdÄ„ dÄe'ƒZžG dÅdÆ„ dÆe3ƒZŸG dÇdÈ„ dÈe3ƒZ G dÉdÊ„ dÊe'ƒZ¡G dËdÌ„ dÌe3ƒZ¢G dÍdÎ„ dÎe3ƒZ£G dÏdÐ„ dÐe6ƒZ¤G dÑdÒ„ dÒe.ƒZ¥G dÓdÔ„ dÔe6ƒZ¦G dÕdÖ„ dÖe6ƒZ§G d×dØ„ dØe6ƒZ¨G dÙdÚ„ dÚe3ƒZ©G dÛdÜ„ dÜe6ƒZªG dÝdÞ„ dÞe3ƒZ«G dßdà„ dàe4ƒZ¬G dádâ„ dâe.ƒZ­G dãdä„ däe3ƒZ®G dådæ„ dæe4ƒZ¯G dçdè„ dèe3ƒZ°G dédê„ dêe3ƒZ±G dëdì„ dìe4ƒZ²G dídî„ dîe4ƒZ³G dïdð„ dðe3ƒZ´G dñdò„ dòe&ƒZµdS )ózò
ASN.1 type classes for X.509 certificates. Exports the following items:

 - Attributes()
 - Certificate()
 - Extensions()
 - GeneralName()
 - GeneralNames()
 - Name()

Other type classes are defined that help compose the types listed above.
é    )Úunicode_literalsÚdivisionÚabsolute_importÚprint_function)Úcontextmanager)ÚidnaNé   )Úunwrap)Ú
iri_to_uriÚ
uri_to_iri)ÚOrderedDict)Ú	type_nameÚstr_clsÚbytes_to_list)ÚAlgorithmIdentifierÚAnyAlgorithmIdentifierÚDigestAlgorithmÚSignedDigestAlgorithm)ÚAnyÚ	BitStringÚ	BMPStringÚBooleanÚChoiceÚConcatÚ
EnumeratedÚGeneralizedTimeÚGeneralStringÚ	IA5StringÚIntegerÚNullÚNumericStringÚObjectIdentifierÚOctetBitStringÚOctetStringÚParsableOctetStringÚPrintableStringÚSequenceÚ
SequenceOfÚSetÚSetOfÚTeletexStringÚUniversalStringÚUTCTimeÚ
UTF8StringÚVisibleStringÚVOID)ÚPublicKeyInfo)Úint_to_bytesÚint_from_bytesÚ	inet_ntopÚ	inet_ptonc                   @   s,   e Zd ZdZdZdd„ Zdd„ Zdd„ Zd	S )
ÚDNSNamer   ©é   é   c                 C   s
   | |k S ©N© ©ÚselfÚotherr:   r:   úR/var/www/html/TRUCKING_PROJECT/venv/lib/python3.8/site-packages/asn1crypto/x509.pyÚ__ne__L   s    zDNSName.__ne__c                 C   s&   t |tƒsdS |  ¡  ¡ | ¡  ¡ kS )zº
        Equality as defined by https://tools.ietf.org/html/rfc5280#section-7.2

        :param other:
            Another DNSName object

        :return:
            A boolean
        F)Ú
isinstancer5   Ú__unicode__Úlowerr;   r:   r:   r>   Ú__eq__O   s    
zDNSName.__eq__c                 C   sx   t |tƒs"ttdt| ƒt|ƒƒƒ‚| d¡rFd|dd…  | j¡ }n| | j¡}|| _|| _	d| _
| jdkrtd| _dS )zd
        Sets the value of the DNS name

        :param value:
            A unicode string
        úK
                %s value must be a unicode string, not %s
                Ú.ó   .r   Nó    )r@   r   Ú	TypeErrorr	   r   Ú
startswithÚencodeÚ	_encodingÚ_unicodeÚcontentsÚ_headerÚ_trailer)r<   ÚvalueÚencoded_valuer:   r:   r>   Úset_   s    
û

zDNSName.setN)Ú__name__Ú
__module__Ú__qualname__rK   Ú_bad_tagr?   rC   rR   r:   r:   r:   r>   r5   G   s
   r5   c                   @   s,   e Zd Zdd„ Zdd„ Zdd„ Zdd„ Zd	S )
ÚURIc                 C   sL   t |tƒs"ttdt| ƒt|ƒƒƒ‚|| _t|ƒ| _d| _| j	dkrHd| _	dS )úb
        Sets the value of the string

        :param value:
            A unicode string
        rD   NrG   )
r@   r   rH   r	   r   rL   r
   rM   rN   rO   ©r<   rP   r:   r:   r>   rR   ~   s    
û

zURI.setc                 C   s
   | |k S r9   r:   r;   r:   r:   r>   r?   •   s    z
URI.__ne__c                 C   s&   t |tƒsdS t| jdƒt|jdƒkS )z¶
        Equality as defined by https://tools.ietf.org/html/rfc5280#section-7.4

        :param other:
            Another URI object

        :return:
            A boolean
        FT)r@   rW   r
   Únativer;   r:   r:   r>   rC   ˜   s    
z
URI.__eq__c                 C   s,   | j dkrdS | jdkr&t|  ¡ ƒ| _| jS ©ú7
        :return:
            A unicode string
        NÚ )rM   rL   r   Ú_merge_chunks©r<   r:   r:   r>   rA   ¨   s
    

zURI.__unicode__N)rS   rT   rU   rR   r?   rC   rA   r:   r:   r:   r>   rW   |   s   rW   c                   @   sR   e Zd ZdZdZdZedd„ ƒZejdd„ ƒZdd„ Z	d	d
„ Z
dd„ Zdd„ ZdS )ÚEmailAddressNFr6   c                 C   s   | j S )z`
        :return:
            A byte string of the DER-encoded contents of the sequence
        )Ú	_contentsr_   r:   r:   r>   rM   ¿   s    zEmailAddress.contentsc                 C   s   d| _ || _dS )ze
        :param value:
            A byte string of the DER-encoded contents of the sequence
        FN)Ú_normalizedra   rY   r:   r:   r>   rM   È   s    c                 C   s�   t |tƒs"ttdt| ƒt|ƒƒƒ‚| d¡dkrZ| dd¡\}}| d¡d | d¡ }n
| d¡}d| _|| _	|| _
d	| _| jd
krŒd
| _d	S )rX   rD   ú@éÿÿÿÿr   Úasciió   @r   TNrG   )r@   r   rH   r	   r   ÚfindÚrsplitrJ   rb   rL   rM   rN   rO   )r<   rP   ÚmailboxÚhostnamerQ   r:   r:   r>   rR   Ò   s     
û

zEmailAddress.setc                 C   s^   | j dkrX|  ¡ }| d¡dkr.| d¡| _ n*| dd¡\}}| d¡d | d¡ | _ | j S )r\   Nrf   rd   Úcp1252r   rc   r   )rL   r^   rg   Údecoderh   )r<   rM   ri   rj   r:   r:   r>   rA   ð   s    
zEmailAddress.__unicode__c                 C   s
   | |k S r9   r:   r;   r:   r:   r>   r?     s    zEmailAddress.__ne__c                 C   s¦   t |tƒsdS | js |  | j¡ |js2| |j¡ | j d¡dksR|j d¡dkr^| j|jkS |j dd¡\}}| j dd¡\}}||krŽdS | ¡ | ¡ kr¢dS dS )z¿
        Equality as defined by https://tools.ietf.org/html/rfc5280#section-7.5

        :param other:
            Another EmailAddress object

        :return:
            A boolean
        Frf   rd   r   T)	r@   r`   rb   rR   rZ   ra   rg   rh   rB   )r<   r=   Zother_mailboxZother_hostnameri   rj   r:   r:   r>   rC     s    
 zEmailAddress.__eq__)rS   rT   rU   ra   rb   rV   ÚpropertyrM   ÚsetterrR   rA   r?   rC   r:   r:   r:   r>   r`   µ   s   

	r`   c                   @   s:   e Zd Zddd„Zdd„ Zedd„ ƒZdd	„ Zd
d„ ZdS )Ú	IPAddressNc                 C   s   t tdƒƒ‚dS )z?
        This method is not applicable to IP addresses
        z=
            IP address values can not be parsed
            N)Ú
ValueErrorr	   )r<   ÚspecZspec_paramsr:   r:   r>   Úparse'  s    ÿzIPAddress.parsec           
      C   sT  t |tƒs"ttdt| ƒt|ƒƒƒ‚|}| d¡dk}d}|rv| dd¡}|d }t|d ƒ}|dk rvttdt| ƒƒƒ‚| d¡dkrªt	j
}|dkr¤ttd	t| ƒƒƒ‚d}n$t	j}|d
krÊttdt| ƒƒƒ‚d
}d}|�rd| }	|	d|t|	ƒ  7 }	tt|	dƒƒ}d|d t|ƒ  | }|| _t||ƒ| | _| j| _d| _| jdk�rPd| _dS )zÌ
        Sets the value of the object

        :param value:
            A unicode string containing an IPv4 address, IPv4 address with CIDR,
            an IPv6 address or IPv6 address with CIDR
        rD   ú/rd   r   r   zT
                    %s value contains a CIDR range less than 0
                    ú:é€   z“
                    %s value contains a CIDR range bigger than 128, the maximum
                    value for an IPv6 address
                    é    z’
                    %s value contains a CIDR range bigger than 32, the maximum
                    value for an IPv4 address
                    rG   Ú1Ú0é   ó    é   N)r@   r   rH   r	   r   rg   ÚsplitÚintrp   ÚsocketÚAF_INET6ÚAF_INETÚlenr1   Ú_nativer4   rM   Z_bytesrN   rO   )
r<   rP   Úoriginal_valueZhas_cidrÚcidrÚpartsÚfamilyZ	cidr_sizeZ
cidr_bytesZ	cidr_maskr:   r:   r>   rR   2  sZ    	
ûüûûzIPAddress.setc                 C   sæ   | j dkrdS | jdkrà|  ¡ }t|ƒ}d}d}|tddgƒkrnttj|dd… ƒ}|dkrªt|dd… ƒ}n<|tddgƒkrªttj	|dd… ƒ}|dkrªt|dd… ƒ}|dk	rÚd 
|¡}t| d¡ƒ}|d	 t|ƒ }|| _| jS )
z€
        The native Python datatype representation of this value

        :return:
            A unicode string or None
        Nrv   é   r   r{   é   z{0:b}rx   rs   )rM   r‚   Ú	__bytes__r�   rR   r3   r~   r   r2   r€   ÚformatÚrstripr   )r<   Zbyte_stringZbyte_lenrP   Zcidr_intZ	cidr_bitsr„   r:   r:   r>   rZ   y  s*    	


zIPAddress.nativec                 C   s
   | |k S r9   r:   r;   r:   r:   r>   r?   ™  s    zIPAddress.__ne__c                 C   s   t |tƒsdS |  ¡ | ¡ kS )zl
        :param other:
            Another IPAddress object

        :return:
            A boolean
        F)r@   ro   r‰   r;   r:   r:   r>   rC   œ  s    	
zIPAddress.__eq__)NN)	rS   rT   rU   rr   rR   rm   rZ   r?   rC   r:   r:   r:   r>   ro   &  s   
G
ro   c                   @   s"   e Zd ZdefdedeifgZdS )Ú	AttributeÚtypeÚvaluesrq   N)rS   rT   rU   r!   r)   r   Ú_fieldsr:   r:   r:   r>   rŒ   «  s   þrŒ   c                   @   s   e Zd ZeZdS )Ú
AttributesN)rS   rT   rU   rŒ   Ú_child_specr:   r:   r:   r>   r�   ²  s   r�   c                
   @   s$   e Zd Zddddddddd	d
œ	ZdS )ÚKeyUsageZdigital_signatureZnon_repudiationZkey_enciphermentZdata_enciphermentZkey_agreementZkey_cert_signZcrl_signZencipher_onlyZdecipher_only©	r   r   ry   é   rˆ   é   é   é   r{   N©rS   rT   rU   Ú_mapr:   r:   r:   r>   r’   ¶  s   ÷r’   c                   @   s,   e Zd ZdedddœfdedddœfgZdS )ÚPrivateKeyUsagePeriodÚ
not_beforer   T©ÚimplicitÚoptionalÚ	not_afterr   N)rS   rT   rU   r   r�   r:   r:   r:   r>   rš   Ä  s   þrš   c                   @   s   e Zd ZdZdZdd„ ZdS )ÚNotReallyTeletexStringa6  
    OpenSSL (and probably some other libraries) puts ISO-8859-1
    into TeletexString instead of ITU T.61. We use Windows-1252 when
    decoding since it is a superset of ISO-8859-1, and less likely to
    cause encoding issues, but we stay strict with encoding to prevent
    us from creating bad data.
    rk   c                 C   s0   | j dkrdS | jdkr*|  ¡  | j¡| _| jS r[   )rM   rL   r^   rl   Ú_decoding_encodingr_   r:   r:   r>   rA   Ö  s
    

z"NotReallyTeletexString.__unicode__N)rS   rT   rU   Ú__doc__r¡   rA   r:   r:   r:   r>   r    Ë  s   r    c                   c   s   zdt _d V  W 5 dt _X d S )Nrk   Úteletex)r    r¡   r:   r:   r:   r>   Ústrict_teletexã  s    
r¤   c                   @   s4   e Zd ZdefdefdefdefdefdefgZ	dS )ÚDirectoryStringÚteletex_stringÚprintable_stringZuniversal_stringÚutf8_stringÚ
bmp_stringÚ
ia5_stringN)
rS   rT   rU   r    r%   r+   r-   r   r   Ú_alternativesr:   r:   r:   r>   r¥   ì  s   ùr¥   c                #   @   s´   e Zd Zddddddddd	d
dddddddddddddddddddddd d!d"d#œ"Zdddddddddddd	d
dd dddddddddd!d"dddddddg!Zed$d%„ ƒZed&d'„ ƒZd(S ))ÚNameTypeÚcommon_nameÚsurnameÚserial_numberÚcountry_nameÚlocality_nameÚstate_or_province_nameÚstreet_addressÚorganization_nameÚorganizational_unit_nameÚtitleÚbusiness_categoryÚpostal_codeÚtelephone_numberÚnameÚ
given_nameÚinitialsÚgeneration_qualifierÚunique_identifierÚdn_qualifierÚ	pseudonymÚorganization_identifierÚtpm_manufacturerÚ	tpm_modelÚtpm_versionÚplatform_manufacturerÚplatform_modelÚplatform_versionÚemail_addressÚincorporation_localityÚincorporation_state_or_provinceÚincorporation_countryÚuser_idÚdomain_componentÚname_distinguisher)"z2.5.4.3z2.5.4.4z2.5.4.5z2.5.4.6z2.5.4.7z2.5.4.8z2.5.4.9z2.5.4.10z2.5.4.11z2.5.4.12z2.5.4.15z2.5.4.17z2.5.4.20z2.5.4.41z2.5.4.42z2.5.4.43z2.5.4.44z2.5.4.45z2.5.4.46z2.5.4.65z2.5.4.97z2.23.133.2.1z2.23.133.2.2z2.23.133.2.3z2.23.133.2.4z2.23.133.2.5z2.23.133.2.6z1.2.840.113549.1.9.1z1.3.6.1.4.1.311.60.2.1.1z1.3.6.1.4.1.311.60.2.1.2z1.3.6.1.4.1.311.60.2.1.3z0.9.2342.19200300.100.1.1z0.9.2342.19200300.100.1.25z0.2.262.1.10.7.20c                 C   s4   |   |¡}|| jkr"| j |¡}n
t| jƒ}||fS )zÍ
        Returns an ordering value for a particular attribute key.

        Unrecognized attributes and OIDs will be sorted lexically at the end.

        :return:
            An orderable value.

        )ÚmapÚpreferred_orderÚindexr�   )ÚclsÚ	attr_nameZordinalr:   r:   r>   Úpreferred_ordinalK  s
    


zNameType.preferred_ordinalc              #   C   sV   ddddddddd	d
dddddddddddddddddddddd d!d"d#œ"  | j| j¡S )$zZ
        :return:
            A human-friendly unicode string to display to users
        zCommon NameZSurnamezSerial NumberÚCountryZLocalityzState/ProvincezStreet AddressZOrganizationzOrganizational UnitZTitlezBusiness CategoryzPostal CodezTelephone NumberÚNamez
Given NameZInitialszGeneration QualifierzUnique IdentifierzDN QualifierZ	PseudonymzEmail AddresszIncorporation LocalityzIncorporation State/ProvincezIncorporation CountryzDomain ComponentzName DistinguisherzOrganization IdentifierzTPM Manufacturerz	TPM ModelzTPM VersionzPlatform ManufacturerzPlatform ModelzPlatform VersionzUser ID©"r­   r®   r¯   r°   r±   r²   r³   r´   rµ   r¶   r·   r¸   r¹   rº   r»   r¼   r½   r¾   r¿   rÀ   rÈ   rÉ   rÊ   rË   rÍ   rÎ   rÁ   rÂ   rÃ   rÄ   rÅ   rÆ   rÇ   rÌ   )ÚgetrZ   r_   r:   r:   r>   Úhuman_friendly_  sL    Þ# ÝzNameType.human_friendlyN)	rS   rT   rU   r™   rÐ   ÚclassmethodrÔ   rm   rÙ   r:   r:   r:   r>   r¬   ø  s’   Ø/ß$
r¬   c                #   @   s’   e Zd ZdefdefgZdZeeeeeeeeeeeeeeeeee	eee
eeeeeeeeeeeeedœ"ZdZedd„ ƒZdd	„ Zd
d„ Zdd„ ZdS )ÚNameTypeAndValuer�   rP   ©r�   rP   r×   Nc                 C   s"   | j dkr|  | d j¡| _ | j S )zµ
        Returns the value after being processed by the internationalized string
        preparation as specified by RFC 5280

        :return:
            A unicode string
        NrP   )Ú_preppedÚ_ldap_string_preprZ   r_   r:   r:   r>   Úprepped_value¼  s    

zNameTypeAndValue.prepped_valuec                 C   s
   | |k S r9   r:   r;   r:   r:   r>   r?   Ê  s    zNameTypeAndValue.__ne__c                 C   s2   t |tƒsdS |d j| d jkr&dS |j| jkS )zÃ
        Equality as defined by https://tools.ietf.org/html/rfc5280#section-7.1

        :param other:
            Another NameTypeAndValue object

        :return:
            A boolean
        Fr�   )r@   rÛ   rZ   rß   r;   r:   r:   r>   rC   Í  s
    
zNameTypeAndValue.__eq__c                 C   s¬  t  dd|¡}t  dd|¡}tjdkr6t  dd|¡}nt  dd|¡}t  dd|¡}| d	d¡}t  d
d|¡}d ttj|ƒ¡}t	 
d|¡}|D ]ˆ}t |¡r¨ttdƒƒ‚t |¡r¾ttdƒƒ‚t |¡rÔttdƒƒ‚t |¡rêttdƒƒ‚t |¡�rttdƒƒ‚|dkrŽttdƒƒ‚qŽd}d}|D ](}t |¡�r:d}nt |¡�r$d}�q$|�rŽt |d ¡}t |d ¡}|�s‚|�r‚|�sŽttdƒƒ‚dt  dd|¡ ¡  d }|S )a"  
        Implements the internationalized string preparation algorithm from
        RFC 4518. https://tools.ietf.org/html/rfc4518#section-2

        :param string:
            A unicode string to prepare

        :return:
            A prepared unicode string, ready for comparison
        u   [Â­á †Í�á ‹-á �ï¸�-ï¼€ï¿¼]+r]   u	   [	
Â…]ú iÿÿ  u   í ´[íµ³-íµº]|í­€[í° -í±¿]|ó €�u   [ð�…³-ð�…ºó € -ó �¿ó €�]u?   [ ---Â„Â†-ÂŸÛ�Ü�á Žâ€Œ-â€�â€ª-â€®â� -â�£â�ª-â�¯ï»¿ï¿¹-ï¿»]+u   â€‹u   [Â áš€â€€-â€Šâ€¨-â€©â€¯â�Ÿã€€]ÚNFKCzc
                    X.509 Name objects may not contain unassigned code points
                    zŒ
                    X.509 Name objects may not contain change display or
                    zzzzdeprecated characters
                    zc
                    X.509 Name objects may not contain private use characters
                    zf
                    X.509 Name objects may not contain non-character code points
                    zb
                    X.509 Name objects may not contain surrogate code points
                    u   ï¿½zf
                    X.509 Name objects may not contain the replacement character
                    FTr   rd   z{
                    X.509 Name object contains a malformed bidirectional
                    sequence
                    z +z  )ÚreÚsubÚsysÚ
maxunicodeÚreplaceÚjoinrÏ   Ú
stringprepÚmap_table_b2ÚunicodedataÚ	normalizeÚin_table_a1rp   r	   Úin_table_c8Úin_table_c3Úin_table_c4Úin_table_c5Úin_table_d1Úin_table_d2Ústrip)r<   ÚstringÚcharZhas_r_and_al_catZ	has_l_catZfirst_is_r_and_alZlast_is_r_and_alr:   r:   r>   rÞ   à  sn    
ü
ÿ
ÿ
ÿ
ÿÿÿÿz"NameTypeAndValue._ldap_string_prep)rS   rT   rU   r¬   r   r�   Ú	_oid_pairr¥   r%   r"   r`   r5   r-   Ú
_oid_specsrÝ   rm   rß   r?   rC   rÞ   r:   r:   r:   r>   rÛ   Œ  sZ   þÜ'
rÛ   c                   @   s<   e Zd ZeZedd„ ƒZdd„ Zdd„ Zdd„ Z	d	d
„ Z
dS )ÚRelativeDistinguishedNamec                 C   s@   g }|   | ¡}t| ¡ ƒD ]}| d||| f ¡ qd |¡S )úb
        :return:
            A unicode string that can be used as a dict key or in a set
        ú%s: %sú)Ú_get_valuesÚsortedÚkeysÚappendrç   )r<   ÚoutputrŽ   Úkeyr:   r:   r>   ÚhashableP  s
    
z"RelativeDistinguishedName.hashablec                 C   s
   | |k S r9   r:   r;   r:   r:   r>   r?   `  s    z RelativeDistinguishedName.__ne__c                 C   sz   t |tƒsdS t| ƒt|ƒkr"dS |  | ¡}|  |¡}||krBdS |  | ¡}|  |¡}|D ]}|| || krZ dS qZdS )zÌ
        Equality as defined by https://tools.ietf.org/html/rfc5280#section-7.1

        :param other:
            Another RelativeDistinguishedName object

        :return:
            A boolean
        FT)r@   rø   r�   Ú
_get_typesrü   )r<   r=   Z
self_typesZother_typesZself_valuesZother_valuesZ
type_name_r:   r:   r>   rC   c  s    




z RelativeDistinguishedName.__eq__c                 C   s   t dd„ |D ƒƒS )zò
        Returns a set of types contained in an RDN

        :param rdn:
            A RelativeDistinguishedName object

        :return:
            A set object with unicode strings of NameTypeAndValue type field
            values
        c                 S   s   g | ]}|d  j ‘qS ©r�   ©rZ   ©Ú.0Zntvr:   r:   r>   Ú
<listcomp>�  s     z8RelativeDistinguishedName._get_types.<locals>.<listcomp>)rR   ©r<   Úrdnr:   r:   r>   r  ƒ  s    z$RelativeDistinguishedName._get_typesc                    s   i ‰ ‡ fdd„|D ƒ ˆ S )a$  
        Returns a dict of prepped values contained in an RDN

        :param rdn:
            A RelativeDistinguishedName object

        :return:
            A dict object with unicode strings of NameTypeAndValue value field
            values that have been prepped for comparison
        c                    s$   g | ]}ˆ   |d  j|jfg¡‘qS r  )ÚupdaterZ   rß   r  ©r   r:   r>   r  ž  s     z9RelativeDistinguishedName._get_values.<locals>.<listcomp>r:   r	  r:   r  r>   rü   ‘  s    z%RelativeDistinguishedName._get_valuesN)rS   rT   rU   rÛ   r‘   rm   r  r?   rC   r  rü   r:   r:   r:   r>   rø   M  s   
 rø   c                   @   s,   e Zd ZeZedd„ ƒZdd„ Zdd„ ZdS )ÚRDNSequencec                 C   s   d  dd„ | D ƒ¡S )rù   úc                 s   s   | ]}|j V  qd S r9   )r  )r  r
  r:   r:   r>   Ú	<genexpr>¯  s     z'RDNSequence.hashable.<locals>.<genexpr>)rç   r_   r:   r:   r>   r  ¥  s    
zRDNSequence.hashablec                 C   s
   | |k S r9   r:   r;   r:   r:   r>   r?   ±  s    zRDNSequence.__ne__c                 C   sJ   t |tƒsdS t| ƒt|ƒkr"dS t| ƒD ]\}}|| |kr* dS q*dS )z¾
        Equality as defined by https://tools.ietf.org/html/rfc5280#section-7.1

        :param other:
            Another RDNSequence object

        :return:
            A boolean
        FT)r@   r  r�   Ú	enumerate)r<   r=   rÑ   Zself_rdnr:   r:   r>   rC   ´  s    
zRDNSequence.__eq__N)	rS   rT   rU   rø   r‘   rm   r  r?   rC   r:   r:   r:   r>   r  ¢  s
   
r  c                   @   sŒ   e Zd ZdefgZdZdZdZeddd„ƒZ	e
dd„ ƒZdd	„ Zd
d„ Zdd„ Ze
dd„ ƒZe
dd„ ƒZdd„ Ze
dd„ ƒZe
dd„ ƒZdS )rÖ   r]   NFc           	      C   sÐ   g }|sd}t }nd}t}tt| ¡ dd„ d�ƒ}| ¡ D ]„\}}t |¡}|dkr^t|ƒ}nF|dkrpt|ƒ}n4|t	dd	d
gƒkr”t
dt|ƒd�}nt
|||ƒd�}| tt||dœƒgƒ¡ q:| dt|ƒd�S )aY  
        Creates a Name object from a dict of unicode string keys and values.
        The keys should be from NameType._map, or a dotted-integer OID unicode
        string.

        :param name_dict:
            A dict of name information, e.g. {"common_name": "Will Bond",
            "country_name": "US", "organization_name": "Codex Non Sufficit LC"}

        :param use_printable:
            A bool - if PrintableString should be used for encoding instead of
            UTF8String. This is for backwards compatibility with old software.

        :return:
            An x509.Name object
        r¨   r§   c                 S   s   t  | d ¡S )Nr   )r¬   rÔ   )Úitemr:   r:   r>   Ú<lambda>ô  rG   zName.build.<locals>.<lambda>)r  rÈ   rÍ   r¿   r°   r¯   )rº   rP   rÜ   r]   )r-   r%   r   rý   Úitemsr¬   rÏ   r`   r5   rR   r¥   rÿ   rø   rÛ   r  )	rÒ   Z	name_dictZuse_printableZrdnsZencoding_nameZencoding_classÚattribute_nameZattribute_valuerP   r:   r:   r>   ÚbuildÕ  sD    þÿ


þþþÿ
z
Name.buildc                 C   s   | j jS )rù   )Úchosenr  r_   r:   r:   r>   r    s    zName.hashablec                 C   s
   t | jƒS r9   )r�   r  r_   r:   r:   r>   Ú__len__  s    zName.__len__c                 C   s
   | |k S r9   r:   r;   r:   r:   r>   r?     s    zName.__ne__c                 C   s   t |tƒsdS | j|jkS )z·
        Equality as defined by https://tools.ietf.org/html/rfc5280#section-7.1

        :param other:
            Another Name object

        :return:
            A boolean
        F)r@   rÖ   r  r;   r:   r:   r>   rC   !  s    
zName.__eq__c                 C   s„   | j d kr~tƒ | _ | jjD ]b}|D ]X}|d }|| j krl| j | }t|tƒs\|g }| j |< | |d ¡ q"|d | j |< q"q| j S )Nr�   rP   )r‚   r   r  rZ   r@   Úlistrÿ   )r<   r
  Útype_valÚ
field_nameÚexistingr:   r:   r>   rZ   0  s    



zName.nativec                 C   s
  | j dk�rtƒ }d}| jD ]R}|D ]H}|d j}|}||kr`|| g||< ||  |d ¡ q$|d ||< q$qg }| ¡ }|dkr�tt|ƒƒ}|D ](}|| }	|  |	¡}
| d||
f ¡ q”d}|D ]}| 	d¡dkrÆd	} qâqÆ|sêd
nd}| 
|ddd… ¡| _ | j S )zg
        :return:
            A human-friendly unicode string containing the parts of the name
        Nr�   rP   rÕ   rú   Fú,rd   Tú, z; )Ú_human_friendlyr   r  rÙ   rÿ   rþ   Úreversedr  Ú_recursive_humanizerg   rç   )r<   ÚdataZ
last_fieldr
  r  r  Zto_joinrþ   r  rP   Znative_valueZ	has_commaÚelementÚ	separatorr:   r:   r>   rÙ   @  s6    


zName.human_friendlyc                    s,   t |tƒr&d t‡ fdd„|D ƒƒ¡S |jS )zÑ
        Recursively serializes data compiled from the RDNSequence

        :param value:
            An Asn1Value object, or a list of Asn1Value objects

        :return:
            A unicode string
        r  c                    s   g | ]}ˆ   |¡‘qS r:   )r   )r  Z	sub_valuer_   r:   r>   r  t  s     z,Name._recursive_humanize.<locals>.<listcomp>)r@   r  rç   r  rZ   rY   r:   r_   r>   r   g  s
    
ÿzName._recursive_humanizec                 C   s$   | j dkrt |  ¡ ¡ ¡ | _ | j S )zZ
        :return:
            The SHA1 hash of the DER-encoded bytes of this name
        N©Ú_sha1ÚhashlibÚsha1ÚdumpÚdigestr_   r:   r:   r>   r'  x  s    
z	Name.sha1c                 C   s$   | j dkrt |  ¡ ¡ ¡ | _ | j S )z]
        :return:
            The SHA-256 hash of the DER-encoded bytes of this name
        N©Ú_sha256r&  Úsha256r(  r)  r_   r:   r:   r>   r,  ƒ  s    
zName.sha256)F)rS   rT   rU   r  r«   r  r%  r+  rÚ   r  rm   r  r  r?   rC   rZ   rÙ   r   r'  r,  r:   r:   r:   r>   rÖ   Ì  s*   ÿ<


&

rÖ   c                   @   s"   e Zd ZdefdeddifgZdS )ÚAnotherNameZtype_idrP   Úexplicitr   N)rS   rT   rU   r!   r   r�   r:   r:   r:   r>   r-  �  s   þr-  c                   @   s$   e Zd ZdZdZdefdefgZdS )ÚCountryNamer   Úx121_dcc_codeÚiso_3166_alpha2_codeN©rS   rT   rU   Úclass_Útagr    r%   r«   r:   r:   r:   r>   r/  –  s
   þr/  c                   @   s$   e Zd ZdZdZdefdefgZdS )ÚAdministrationDomainNamer   ry   ÚnumericÚ	printableNr2  r:   r:   r:   r>   r5     s
   þr5  c                   @   s   e Zd ZdefdefgZdS )ÚPrivateDomainNamer6  r7  N©rS   rT   rU   r    r%   r«   r:   r:   r:   r>   r8  ª  s   þr8  c                   @   sF   e Zd Zdeddifdedddœfded	ddœfd
edddœfgZdS )ÚPersonalNamer®   r�   r   r»   r   Trœ   r¼   ry   r½   r”   N©rS   rT   rU   r%   r�   r:   r:   r:   r>   r:  ±  s
   ür:  c                   @   sF   e Zd Zdeddifdedddœfded	ddœfd
edddœfgZdS )ÚTeletexPersonalNamer®   r�   r   r»   r   Trœ   r¼   ry   r½   r”   N©rS   rT   rU   r*   r�   r:   r:   r:   r>   r<  º  s
   ür<  c                   @   s   e Zd ZeZdS )ÚOrganizationalUnitNamesN©rS   rT   rU   r%   r‘   r:   r:   r:   r>   r>  Ã  s   r>  c                   @   s   e Zd ZeZdS )ÚTeletexOrganizationalUnitNamesN)rS   rT   rU   r*   r‘   r:   r:   r:   r>   r@  Ç  s   r@  c                   @   sŠ   e Zd Zdeddifdeddifdedddœfded	ddœfd
edddœfdedddœfdedddœfdedddœfde	dddœfg	Z
dS )ÚBuiltInStandardAttributesr°   rž   TZadministration_domain_nameÚnetwork_addressr   rœ   Zterminal_identifierr   Zprivate_domain_namery   ©r.  rž   r´   r”   Znumeric_user_identifierrˆ   Zpersonal_namer•   Zorganizational_unit_namesr–   N)rS   rT   rU   r/  r5  r    r%   r8  r:  r>  r�   r:   r:   r:   r>   rA  Ë  s   ÷rA  c                   @   s   e Zd ZdefdefgZdS )ÚBuiltInDomainDefinedAttributer�   rP   Nr;  r:   r:   r:   r>   rD  Ù  s   þrD  c                   @   s   e Zd ZeZdS )ÚBuiltInDomainDefinedAttributesN)rS   rT   rU   rD  r‘   r:   r:   r:   r>   rE  à  s   rE  c                   @   s   e Zd ZdefdefgZdS )ÚTeletexDomainDefinedAttributer�   rP   Nr=  r:   r:   r:   r>   rF  ä  s   þrF  c                   @   s   e Zd ZeZdS )ÚTeletexDomainDefinedAttributesN)rS   rT   rU   rF  r‘   r:   r:   r:   r>   rG  ë  s   rG  c                   @   s   e Zd ZdefdefgZdS )ÚPhysicalDeliveryCountryNamer0  r1  Nr9  r:   r:   r:   r>   rH  ï  s   þrH  c                   @   s   e Zd ZdefdefgZdS )Ú
PostalCodeZnumeric_codeZprintable_codeNr9  r:   r:   r:   r>   rI  ö  s   þrI  c                   @   s(   e Zd ZdeddifdeddifgZdS )ÚPDSParameterr§   rž   Tr¦   N)rS   rT   rU   r%   r*   r�   r:   r:   r:   r>   rJ  ý  s   þrJ  c                   @   s   e Zd ZeZdS )ÚPrintableAddressNr?  r:   r:   r:   r>   rK    s   rK  c                   @   s(   e Zd ZdeddifdeddifgZdS )ÚUnformattedPostalAddressZprintable_addressrž   Tr¦   N)rS   rT   rU   rK  r*   r�   r:   r:   r:   r>   rL    s   þrL  c                   @   s*   e Zd ZdeddifdedddœfgZdS )	ÚE1634AddressÚnumberr�   r   Zsub_addressr   Trœ   N)rS   rT   rU   r    r�   r:   r:   r:   r>   rM    s   þrM  c                   @   s   e Zd ZeZdS )Ú
NAddressesN)rS   rT   rU   r#   r‘   r:   r:   r:   r>   rO    s   rO  c                   @   sF   e Zd Zdedddœfdedddœfdedddœfd	ed
difgZdS )ÚPresentationAddressZ
p_selectorr   TrC  Z
s_selectorr   Z
t_selectorry   Zn_addressesr.  r”   N)rS   rT   rU   r#   rO  r�   r:   r:   r:   r>   rP    s
   ürP  c                   @   s"   e Zd ZdefdeddifgZdS )ÚExtendedNetworkAddressZe163_4_addressZpsap_addressr�   r   N)rS   rT   rU   rM  rP  r«   r:   r:   r:   r>   rQ  #  s   þrQ  c                   @   s   e Zd ZdddddddœZdS )	ÚTerminalTypeZtelexr£   Zg3_facsimileZg4_facsimileZia5_terminalZvideotex)r”   rˆ   r•   r–   r—   r{   Nr˜   r:   r:   r:   r>   rR  *  s   úrR  c                   @   s@   e Zd Zddddddddd	d
ddddddddddddddœZdS )ÚExtensionAttributeTyper­   Úteletex_common_nameÚteletex_organization_nameÚteletex_personal_nameÚteletex_organization_unit_namesÚ!teletex_domain_defined_attributesÚpds_nameÚphysical_delivery_country_namer¸   Úphysical_delivery_office_nameÚphysical_delivery_office_numberÚextension_of_address_componentsÚphysical_delivery_personal_nameÚ#physical_delivery_organization_nameÚ.extension_physical_delivery_address_componentsÚunformatted_postal_addressr³   Úpost_office_box_addressÚposte_restante_addressÚunique_postal_nameÚlocal_postal_attributesÚextended_network_addressÚterminal_type)r   ry   r”   rˆ   r•   r–   r—   r{   é	   é
   é   r7   é   é   é   r‡   é   é   r8   é   é   é   é   Nr˜   r:   r:   r:   r>   rS  5  s0   érS  c                   @   s`   e Zd ZdeddifdeddifgZdZeeee	e
eeeeeeeeeeeeeeeeeedœZd	S )
ÚExtensionAttributeÚextension_attribute_typer�   r   Úextension_attribute_valuer.  r   )ru  rv  )r­   rT  rU  rV  rW  rX  rY  rZ  r¸   r[  r\  r]  r^  r_  r`  ra  r³   rb  rc  rd  re  rf  rg  N)rS   rT   rU   rS  r   r�   rö   r%   r*   r<  r@  rG  rH  rI  rJ  rL  rQ  rR  r÷   r:   r:   r:   r>   rt  Q  s8   þért  c                   @   s   e Zd ZeZdS )ÚExtensionAttributesN)rS   rT   rU   rt  r‘   r:   r:   r:   r>   rw  s  s   rw  c                   @   s.   e Zd ZdefdeddifdeddifgZdS )Ú	ORAddressZbuilt_in_standard_attributesZ"built_in_domain_defined_attributesrž   TZextension_attributesN)rS   rT   rU   rA  rE  rw  r�   r:   r:   r:   r>   rx  w  s   ýrx  c                   @   s*   e Zd ZdedddœfdeddifgZdS )	ÚEDIPartyNameZname_assignerr   Trœ   Z
party_namer�   r   N)rS   rT   rU   r¥   r�   r:   r:   r:   r>   ry    s   þry  c                   @   sŒ   e Zd Zdeddifdeddifdeddifdedd	ifd
eddifdeddifde	ddifde
ddifdeddifg	Zdd„ Zdd„ ZdS )ÚGeneralNameÚ
other_namer�   r   Zrfc822_namer   Údns_namery   Úx400_addressr”   Zdirectory_namer.  rˆ   Úedi_party_namer•   Úuniform_resource_identifierr–   Ú
ip_addressr—   Zregistered_idr{   c                 C   s
   | |k S r9   r:   r;   r:   r:   r>   r?   “  s    zGeneralName.__ne__c                 C   sP   | j dkrttd| j ƒƒ‚|j dkr4ttd|j ƒƒ‚| j |j krDdS | j|jkS )z¼
        Does not support other_name, x400_address or edi_party_name

        :param other:
            The other GeneralName to compare to

        :return:
            A boolean
        )r{  r}  r~  zr
                Comparison is not supported for GeneralName objects of
                choice %s
                za
                Comparison is not supported for GeneralName objects of choice
                %sF)rº   rp   r	   r  r;   r:   r:   r>   rC   –  s    
û
üzGeneralName.__eq__N)rS   rT   rU   r-  r`   r5   rx  rÖ   ry  rW   ro   r!   r«   r?   rC   r:   r:   r:   r>   rz  †  s   ÷rz  c                   @   s   e Zd ZeZdS )ÚGeneralNamesN)rS   rT   rU   rz  r‘   r:   r:   r:   r>   r�  ¸  s   r�  c                   @   s   e Zd ZdefdefgZdS )ÚTimeZutc_timeZgeneral_timeN)rS   rT   rU   r,   r   r«   r:   r:   r:   r>   r‚  ¼  s   þr‚  c                   @   s   e Zd ZdefdefgZdS )ÚValidityr›   rŸ   N)rS   rT   rU   r‚  r�   r:   r:   r:   r>   rƒ  Ã  s   þrƒ  c                   @   s(   e Zd ZdeddifdeddifgZdS )ÚBasicConstraintsÚcaÚdefaultFÚpath_len_constraintrž   TN)rS   rT   rU   r   r   r�   r:   r:   r:   r>   r„  Ê  s   þr„  c                   @   s:   e Zd ZdedddœfdedddœfdedddœfgZd	S )
ÚAuthorityKeyIdentifierÚkey_identifierr   Trœ   Úauthority_cert_issuerr   Úauthority_cert_serial_numberry   N)rS   rT   rU   r#   r�  r   r�   r:   r:   r:   r>   rˆ  Ñ  s   ýrˆ  c                   @   s(   e Zd ZdeddifdeddifgZdS )ÚDistributionPointNameÚ	full_namer�   r   Úname_relative_to_crl_issuerr   N)rS   rT   rU   r�  rø   r«   r:   r:   r:   r>   rŒ  Ù  s   þrŒ  c                
   @   s$   e Zd Zddddddddd	d
œ	ZdS )ÚReasonFlagsZunusedZkey_compromiseZca_compromiseZaffiliation_changedZ
supersededZcessation_of_operationZcertificate_holdZprivilege_withdrawnZaa_compromiser“   Nr˜   r:   r:   r:   r>   r�  à  s   ÷r�  c                   @   s2   e Zd ZdefdedddœfdedddœfgZd	S )
ÚGeneralSubtreeÚbaseÚminimumr   ©r�   r†  Úmaximumr   Trœ   N)rS   rT   rU   rz  r   r�   r:   r:   r:   r>   r�  î  s   ýr�  c                   @   s   e Zd ZeZdS )ÚGeneralSubtreesN)rS   rT   rU   r�  r‘   r:   r:   r:   r>   r•  ö  s   r•  c                   @   s,   e Zd ZdedddœfdedddœfgZdS )ÚNameConstraintsZpermitted_subtreesr   Trœ   Zexcluded_subtreesr   N)rS   rT   rU   r•  r�   r:   r:   r:   r>   r–  ú  s   þr–  c                   @   sJ   e Zd Zdedddœfdedddœfded	ddœfgZd
Zedd„ ƒZ	dS )ÚDistributionPointÚdistribution_pointr   TrC  Úreasonsr   rœ   Z
crl_issuerry   Fc                 C   sh   | j dkrbd| _ | d }|jdkr.ttdƒƒ‚|jD ],}|jdkr4|j}| ¡  d¡r4|| _  qbq4| j S )z_
        :return:
            None or a unicode string of the distribution point's URL
        FNr˜  r�  z‡
                    CRL distribution points that are relative to the issuer are
                    not supported
                    r  ©zhttp://zhttps://zldap://zldaps://)Ú_urlrº   rp   r	   r  rZ   rB   rI   )r<   rº   Úgeneral_nameÚurlr:   r:   r>   r�  
  s    

ÿ

zDistributionPoint.urlN)
rS   rT   rU   rŒ  r�  r�  r�   r›  rm   r�  r:   r:   r:   r>   r—    s   ýr—  c                   @   s   e Zd ZeZdS )ÚCRLDistributionPointsN)rS   rT   rU   r—  r‘   r:   r:   r:   r>   rž  &  s   rž  c                   @   s(   e Zd ZdefdefdefdefgZdS )ÚDisplayTextrª   Zvisible_stringr©   r¨   N)rS   rT   rU   r   r.   r   r-   r«   r:   r:   r:   r>   rŸ  *  s
   ürŸ  c                   @   s   e Zd ZeZdS )ÚNoticeNumbersN©rS   rT   rU   r   r‘   r:   r:   r:   r>   r   3  s   r   c                   @   s   e Zd ZdefdefgZdS )ÚNoticeReferenceZorganizationZnotice_numbersN)rS   rT   rU   rŸ  r   r�   r:   r:   r:   r>   r¢  7  s   þr¢  c                   @   s(   e Zd ZdeddifdeddifgZdS )Ú
UserNoticeZ
notice_refrž   TZexplicit_textN)rS   rT   rU   r¢  rŸ  r�   r:   r:   r:   r>   r£  >  s   þr£  c                   @   s   e Zd ZdddœZdS )ÚPolicyQualifierIdÚ certification_practice_statementÚuser_notice)z1.3.6.1.5.5.7.2.1z1.3.6.1.5.5.7.2.2Nr˜   r:   r:   r:   r>   r¤  E  s   þr¤  c                   @   s*   e Zd ZdefdefgZdZeedœZ	dS )ÚPolicyQualifierInfoÚpolicy_qualifier_idÚ	qualifier)r¨  r©  )r¥  r¦  N)
rS   rT   rU   r¤  r   r�   rö   r   r£  r÷   r:   r:   r:   r>   r§  L  s   þþr§  c                   @   s   e Zd ZeZdS )ÚPolicyQualifierInfosN)rS   rT   rU   r§  r‘   r:   r:   r:   r>   rª  Y  s   rª  c                   @   s   e Zd ZddiZdS )ÚPolicyIdentifierz2.5.29.32.0Z
any_policyNr˜   r:   r:   r:   r>   r«  ]  s    ÿr«  c                   @   s"   e Zd ZdefdeddifgZdS )ÚPolicyInformationZpolicy_identifierZpolicy_qualifiersrž   TN)rS   rT   rU   r«  rª  r�   r:   r:   r:   r>   r¬  c  s   þr¬  c                   @   s   e Zd ZeZdS )ÚCertificatePoliciesN)rS   rT   rU   r¬  r‘   r:   r:   r:   r>   r­  j  s   r­  c                   @   s   e Zd ZdefdefgZdS )ÚPolicyMappingZissuer_domain_policyZsubject_domain_policyN)rS   rT   rU   r«  r�   r:   r:   r:   r>   r®  n  s   þr®  c                   @   s   e Zd ZeZdS )ÚPolicyMappingsN)rS   rT   rU   r®  r‘   r:   r:   r:   r>   r¯  u  s   r¯  c                   @   s,   e Zd ZdedddœfdedddœfgZdS )ÚPolicyConstraintsZrequire_explicit_policyr   Trœ   Zinhibit_policy_mappingr   N©rS   rT   rU   r   r�   r:   r:   r:   r>   r°  y  s   þr°  c                V   @   s¼   e Zd Zddddddddd	d
dddddddddddddddddddddd d!d"d#d$d%d&d'd(d)d*d+d,d-d.d/d0d1d2d3d4d5d6d7d8d9d:d;d<d=d>d?d@dAdBdCdDdEdFdGdHdIdJdKdLdMdNdOdPdQdRdSdTdUdVœUZdWS )XÚKeyPurposeIdZany_extended_key_usageZserver_authZclient_authZcode_signingZemail_protectionZipsec_end_systemZipsec_tunnelZ
ipsec_userÚtime_stampingZocsp_signingZdvcsZeap_over_pppZeap_over_lanZscvp_serverZscvp_clientZ	ipsec_ikeZ	capwap_acZ
capwap_wtpZ
sip_domainZsecure_shell_clientZsecure_shell_serverZsend_routerZsend_proxied_routerZ
send_ownerZsend_proxied_ownerZcmc_caZcmc_raZcmc_archiveZbgpspec_routerZike_intermediateZmicrosoft_trust_list_signingZmicrosoft_time_stamp_signingZmicrosoft_server_gatedZmicrosoft_serializedZmicrosoft_efsZmicrosoft_efs_recoveryZmicrosoft_whqlZmicrosoft_nt5Zmicrosoft_oem_whqlZmicrosoft_embedded_ntZmicrosoft_root_list_signerZ!microsoft_qualified_subordinationZmicrosoft_key_recoveryZmicrosoft_document_signingZmicrosoft_lifetime_signingZ microsoft_mobile_device_softwareZmicrosoft_smart_card_logonZapple_x509_basicZ	apple_sslZapple_local_cert_genZapple_csr_genZapple_revocation_crlZapple_revocation_ocspZapple_smimeZ	apple_eapZapple_software_update_signingZapple_ipsecZapple_ichatZapple_resource_signingZapple_pkinit_clientZapple_pkinit_serverZapple_code_signingZapple_package_signingZapple_id_validationZapple_time_stampingZapple_revocationZapple_passbook_signingZapple_mobile_storeZapple_escrow_serviceZapple_profile_signerZapple_qa_profile_signerZapple_test_mobile_storeZapple_otapki_signerZapple_test_otapki_signerZ)apple_id_validation_record_signing_policyZapple_smp_encryptionZapple_test_smp_encryptionZapple_server_authenticationZapple_pcs_escrow_serviceZpiv_card_authenticationZpiv_content_signingZpkinit_kpclientauthZpkinit_kpkdcZadobe_authentic_documents_trustZfpki_pivi_content_signing)Uz2.5.29.37.0z1.3.6.1.5.5.7.3.1z1.3.6.1.5.5.7.3.2z1.3.6.1.5.5.7.3.3z1.3.6.1.5.5.7.3.4z1.3.6.1.5.5.7.3.5z1.3.6.1.5.5.7.3.6z1.3.6.1.5.5.7.3.7z1.3.6.1.5.5.7.3.8z1.3.6.1.5.5.7.3.9z1.3.6.1.5.5.7.3.10z1.3.6.1.5.5.7.3.13z1.3.6.1.5.5.7.3.14z1.3.6.1.5.5.7.3.15z1.3.6.1.5.5.7.3.16z1.3.6.1.5.5.7.3.17z1.3.6.1.5.5.7.3.18z1.3.6.1.5.5.7.3.19z1.3.6.1.5.5.7.3.20z1.3.6.1.5.5.7.3.21z1.3.6.1.5.5.7.3.22z1.3.6.1.5.5.7.3.23z1.3.6.1.5.5.7.3.24z1.3.6.1.5.5.7.3.25z1.3.6.1.5.5.7.3.26z1.3.6.1.5.5.7.3.27z1.3.6.1.5.5.7.3.28z1.3.6.1.5.5.7.3.29z1.3.6.1.5.5.7.3.30z1.3.6.1.5.5.8.2.2z1.3.6.1.4.1.311.10.3.1z1.3.6.1.4.1.311.10.3.2z1.3.6.1.4.1.311.10.3.3z1.3.6.1.4.1.311.10.3.3.1z1.3.6.1.4.1.311.10.3.4z1.3.6.1.4.1.311.10.3.4.1z1.3.6.1.4.1.311.10.3.5z1.3.6.1.4.1.311.10.3.6z1.3.6.1.4.1.311.10.3.7z1.3.6.1.4.1.311.10.3.8z1.3.6.1.4.1.311.10.3.9z1.3.6.1.4.1.311.10.3.10z1.3.6.1.4.1.311.10.3.11z1.3.6.1.4.1.311.10.3.12z1.3.6.1.4.1.311.10.3.13z1.3.6.1.4.1.311.10.3.14z1.3.6.1.4.1.311.20.2.2z1.2.840.113635.100.1.2z1.2.840.113635.100.1.3z1.2.840.113635.100.1.4z1.2.840.113635.100.1.5z1.2.840.113635.100.1.6z1.2.840.113635.100.1.7z1.2.840.113635.100.1.8z1.2.840.113635.100.1.9z1.2.840.113635.100.1.10z1.2.840.113635.100.1.11z1.2.840.113635.100.1.12z1.2.840.113635.100.1.13z1.2.840.113635.100.1.14z1.2.840.113635.100.1.15z1.2.840.113635.100.1.16z1.2.840.113635.100.1.17z1.2.840.113635.100.1.18z1.2.840.113635.100.1.20z1.2.840.113635.100.1.21z1.2.840.113635.100.1.22z1.2.840.113635.100.1.23z1.2.840.113635.100.1.24z1.2.840.113635.100.1.25z1.2.840.113635.100.1.26z1.2.840.113635.100.1.27z1.2.840.113635.100.1.28z1.2.840.113635.100.1.29z1.2.840.113625.100.1.30z1.2.840.113625.100.1.31z1.2.840.113625.100.1.32z1.2.840.113635.100.1.33z1.2.840.113635.100.1.34z2.16.840.1.101.3.6.8z2.16.840.1.101.3.6.7z1.3.6.1.5.2.3.4z1.3.6.1.5.2.3.5z1.2.840.113583.1.1.5z2.16.840.1.101.3.8.7Nr˜   r:   r:   r:   r>   r²  €  s¬   •r²  c                   @   s   e Zd ZeZdS )ÚExtKeyUsageSyntaxN©rS   rT   rU   r²  r‘   r:   r:   r:   r>   r´  ð  s   r´  c                   @   s   e Zd ZdddddœZdS )ÚAccessMethodÚocspZ
ca_issuersr³  Zca_repository)z1.3.6.1.5.5.7.48.1z1.3.6.1.5.5.7.48.2z1.3.6.1.5.5.7.48.3z1.3.6.1.5.5.7.48.5Nr˜   r:   r:   r:   r>   r¶  ô  s
   ür¶  c                   @   s   e Zd ZdefdefgZdS )ÚAccessDescriptionÚaccess_methodÚaccess_locationN)rS   rT   rU   r¶  rz  r�   r:   r:   r:   r>   r¸  ý  s   þr¸  c                   @   s   e Zd ZeZdS )ÚAuthorityInfoAccessSyntaxN©rS   rT   rU   r¸  r‘   r:   r:   r:   r>   r»    s   r»  c                   @   s   e Zd ZeZdS )ÚSubjectInfoAccessSyntaxNr¼  r:   r:   r:   r>   r½    s   r½  c                   @   s   e Zd ZeZdS )ÚFeaturesNr¡  r:   r:   r:   r>   r¾    s   r¾  c                   @   s   e Zd ZdefdefgZdS )ÚEntrustVersionInfoZentrust_versZentrust_info_flagsN)rS   rT   rU   r   r   r�   r:   r:   r:   r>   r¿    s   þr¿  c                	   @   s"   e Zd Zddddddddd	œZd
S )ÚNetscapeCertificateTypeZ
ssl_clientZ
ssl_serverÚemailZobject_signingÚreservedZssl_caZemail_caZobject_signing_ca)r   r   ry   r”   rˆ   r•   r–   r—   Nr˜   r:   r:   r:   r>   rÀ    s   ørÀ  c                   @   s   e Zd ZddddœZdS )ÚVersionÚv1Zv2Zv3©r   r   ry   Nr˜   r:   r:   r:   r>   rÃ  %  s   ýrÃ  c                   @   s"   e Zd ZdefdefdefgZdS )ÚTPMSpecificationr†   ÚlevelÚrevisionN)rS   rT   rU   r-   r   r�   r:   r:   r:   r>   rÆ  -  s   ýrÆ  c                   @   s   e Zd ZeZdS )ÚSetOfTPMSpecificationN)rS   rT   rU   rÆ  r‘   r:   r:   r:   r>   rÉ  5  s   rÉ  c                   @   s"   e Zd ZdefdefdefgZdS )ÚTCGSpecificationVersionÚmajor_versionÚminor_versionrÈ  Nr±  r:   r:   r:   r>   rÊ  9  s   ýrÊ  c                   @   s   e Zd ZdefdefgZdS )ÚTCGPlatformSpecificationÚversionZplatform_classN)rS   rT   rU   rÊ  r#   r�   r:   r:   r:   r>   rÍ  A  s   þrÍ  c                   @   s   e Zd ZeZdS )ÚSetOfTCGPlatformSpecificationN)rS   rT   rU   rÍ  r‘   r:   r:   r:   r>   rÏ  H  s   rÏ  c                   @   s   e Zd ZdddddœZdS )ÚEKGenerationTypeZinternalZinjectedZinternal_revocableZinjected_revocable)r   r   ry   r”   Nr˜   r:   r:   r:   r>   rÐ  L  s
   ürÐ  c                   @   s   e Zd ZddddœZdS )ÚEKGenerationLocationrÂ   rÅ   Úek_cert_signerrÅ  Nr˜   r:   r:   r:   r>   rÑ  U  s   ýrÑ  c                   @   s   e Zd ZddddœZdS )ÚEKCertificateGenerationLocationrÂ   rÅ   rÒ  rÅ  Nr˜   r:   r:   r:   r>   rÓ  ]  s   ýrÓ  c                   @   s    e Zd ZddddddddœZd	S )
ÚEvaluationAssuranceLevelÚlevel1Úlevel2Úlevel3Úlevel4Zlevel5Zlevel6Zlevel7)r   ry   r”   rˆ   r•   r–   r—   Nr˜   r:   r:   r:   r>   rÔ  e  s   ùrÔ  c                   @   s   e Zd ZddddœZdS )ÚEvaluationStatusZdesigned_to_meetZevaluation_in_progressZevaluation_completedrÅ  Nr˜   r:   r:   r:   r>   rÙ  q  s   ýrÙ  c                   @   s   e Zd ZddddœZdS )ÚStrengthOfFunctionÚbasicZmediumÚhighrÅ  Nr˜   r:   r:   r:   r>   rÚ  y  s   ýrÚ  c                   @   s.   e Zd ZdefdeddifdeddifgZdS )ÚURIReferencer  Zhash_algorithmrž   TÚ
hash_valueN)rS   rT   rU   r   r   r   r�   r:   r:   r:   r>   rÝ  �  s   ýrÝ  c                   @   st   e Zd Zdefdefdefdeddifdedd	d
œfdedd	d
œfde	dd	d
œfdedd	d
œfde	dd	d
œfg	Z
dS )ÚCommonCriteriaMeasuresrÎ  Zassurance_levelZevaluation_statusÚplusr†  FZstrengh_of_functionr   Trœ   Zprofile_oidr   Zprofile_urlry   Z
target_oidr”   Z
target_urirˆ   N)rS   rT   rU   r   rÔ  rÙ  r   rÚ  r!   rÝ  r�   r:   r:   r:   r>   rß  ‰  s   ÷rß  c                   @   s   e Zd ZdddddœZdS )ÚSecurityLevelrÕ  rÖ  r×  rØ  )r   ry   r”   rˆ   Nr˜   r:   r:   r:   r>   rá  —  s
   ürá  c                   @   s(   e Zd ZdefdefdeddifgZdS )Ú	FIPSLevelrÎ  rÇ  rà  r†  FN)rS   rT   rU   r   rá  r   r�   r:   r:   r:   r>   râ     s   ýrâ  c                   @   sˆ   e Zd Zdeddifdeddifdeddd	œfd
eddd	œfdeddd	œfdeddd	œfde	ddd	œfdedddœfde
ddifg	ZdS )ÚTPMSecurityAssertionsrÎ  r†  rÄ  Zfield_upgradableFZek_generation_typer   Trœ   Zek_generation_locationr   Z"ek_certificate_generation_locationry   Zcc_infor”   Z
fips_levelrˆ   Ziso_9000_certifiedr•   r“  Ziso_9000_urirž   N)rS   rT   rU   rÃ  r   rÐ  rÑ  rÓ  rß  râ  r   r�   r:   r:   r:   r>   rã  ¨  s   ÷rã  c                   @   s   e Zd ZeZdS )ÚSetOfTPMSecurityAssertionsN)rS   rT   rU   rã  r‘   r:   r:   r:   r>   rä  ¶  s   rä  c                   @   s&   e Zd Zddddddddd	d
dœ
ZdS )ÚSubjectDirectoryAttributeIdÚsupported_algorithmsÚtpm_specificationÚtcg_platform_specificationÚtpm_security_assertionsÚpda_date_of_birthÚpda_place_of_birthÚ
pda_genderÚpda_country_of_citizenshipÚpda_country_of_residenceZentrust_user_role)
z2.5.4.52z2.23.133.2.16z2.23.133.2.17z2.23.133.2.18z1.3.6.1.5.5.7.9.1z1.3.6.1.5.5.7.9.2z1.3.6.1.5.5.7.9.3z1.3.6.1.5.5.7.9.4z1.3.6.1.5.5.7.9.5z1.2.840.113533.7.68.29Nr˜   r:   r:   r:   r>   rå  º  s   òrå  c                   @   s   e Zd ZeZdS )ÚSetOfGeneralizedTimeN)rS   rT   rU   r   r‘   r:   r:   r:   r>   rï  Í  s   rï  c                   @   s   e Zd ZeZdS )ÚSetOfDirectoryStringN)rS   rT   rU   r¥   r‘   r:   r:   r:   r>   rð  Ñ  s   rð  c                   @   s   e Zd ZeZdS )ÚSetOfPrintableStringNr?  r:   r:   r:   r>   rñ  Õ  s   rñ  c                   @   s2   e Zd ZdefdedddœfdedddœfgZdS )	ÚSupportedAlgorithmZalgorithm_identifierZintended_usager   TrC  Zintended_certificate_policiesr   N)rS   rT   rU   r   r’   r­  r�   r:   r:   r:   r>   rò  Ù  s   ýrò  c                   @   s   e Zd ZeZdS )ÚSetOfSupportedAlgorithmN)rS   rT   rU   rò  r‘   r:   r:   r:   r>   ró  á  s   ró  c                
   @   sH   e Zd ZdefdefgZdZeee	e
eeeeedœ	Zdd„ ZdeiZdS )ÚSubjectDirectoryAttributer�   rŽ   )r�   rŽ   )	ræ  rç  rè  ré  rê  rë  rì  rí  rî  c                 C   s"   | d j }|| jkr| j| S tS )Nr�   )rZ   r÷   r)   )r<   Útype_r:   r:   r>   Ú_values_specø  s    


z&SubjectDirectoryAttribute._values_specN)rS   rT   rU   rå  r   r�   rö   ró  rÉ  rÏ  rä  rï  rð  rñ  r÷   rö  Z_spec_callbacksr:   r:   r:   r>   rô  å  s$   þ÷ ÿrô  c                   @   s   e Zd ZeZdS )ÚSubjectDirectoryAttributesN)rS   rT   rU   rô  r‘   r:   r:   r:   r>   r÷    s   r÷  c                   @   sB   e Zd Zddddddddd	d
dddddddddddddddœZdS )ÚExtensionIdÚsubject_directory_attributesr‰  Ú	key_usageÚprivate_key_usage_periodÚsubject_alt_nameÚissuer_alt_nameÚbasic_constraintsÚname_constraintsÚcrl_distribution_pointsÚcertificate_policiesÚpolicy_mappingsÚauthority_key_identifierÚpolicy_constraintsÚextended_key_usageÚfreshest_crlÚinhibit_any_policyÚauthority_information_accessÚsubject_information_accessÚtls_featureÚocsp_no_checkÚentrust_version_extensionÚnetscape_certificate_typeÚ!signed_certificate_timestamp_listÚmicrosoft_enroll_certtype)z2.5.29.9z	2.5.29.14z	2.5.29.15z	2.5.29.16z	2.5.29.17z	2.5.29.18z	2.5.29.19z	2.5.29.30z	2.5.29.31z	2.5.29.32z	2.5.29.33z	2.5.29.35z	2.5.29.36z	2.5.29.37z	2.5.29.46z	2.5.29.54z1.3.6.1.5.5.7.1.1z1.3.6.1.5.5.7.1.11z1.3.6.1.5.5.7.1.24z1.3.6.1.5.5.7.48.1.5z1.2.840.113533.7.65.0z2.16.840.1.113730.1.1z1.3.6.1.4.1.11129.2.4.2z1.3.6.1.4.1.311.20.2Nr˜   r:   r:   r:   r>   rø    s2   årø  c                   @   sb   e Zd ZdefdeddifdefgZdZee	e
eeeeeeeeeeeeeeeeeeee	edœZdS )	Ú	ExtensionÚextn_idÚcriticalr†  FÚ
extn_value)r  r  )rù  r‰  rú  rû  rü  rý  rþ  rÿ  r   r  r  r  r  r  r  r  r  r	  r
  r  r  r  r  r  N)rS   rT   rU   rø  r   r$   r�   rö   r÷  r#   r’   rš   r�  r„  r–  rž  r­  r¯  rˆ  r°  r´  r   r»  r½  r¾  r   r¿  rÀ  r   r÷   r:   r:   r:   r>   r  '  s<   ýær  c                   @   s   e Zd ZeZdS )Ú
ExtensionsN)rS   rT   rU   r  r‘   r:   r:   r:   r>   r  M  s   r  c                   @   sl   e Zd Zdedddœfdefdefdefdefd	efd
efde	dddœfde	dddœfde
dddœfg
ZdS )ÚTbsCertificaterÎ  r   rÄ  )r.  r†  r¯   Ú	signatureÚissuerÚvalidityÚsubjectÚsubject_public_key_infoZissuer_unique_idr   Trœ   Zsubject_unique_idry   Ú
extensionsr”   rC  N)rS   rT   rU   rÃ  r   r   rÖ   rƒ  r0   r"   r  r�   r:   r:   r:   r>   r  Q  s   ör  c                   @   sþ  e Zd ZdefdefdefgZdZdZdZ	dZ
dZdZdZdZdZdZdZdZdZdZdZdZdZdZdZdZdZdZdZdZdZdZ dZ!dZ"dZ#dZ$dZ%dZ&dd„ Z'e(dd	„ ƒZ)e(d
d„ ƒZ*e(dd„ ƒZ+e(dd„ ƒZ,e(dd„ ƒZ-e(dd„ ƒZ.e(dd„ ƒZ/e(dd„ ƒZ0e(dd„ ƒZ1e(dd„ ƒZ2e(dd„ ƒZ3e(dd„ ƒZ4e(d d!„ ƒZ5e(d"d#„ ƒZ6e(d$d%„ ƒZ7e(d&d'„ ƒZ8e(d(d)„ ƒZ9e(d*d+„ ƒZ:e(d,d-„ ƒZ;e(d.d/„ ƒZ<e(d0d1„ ƒZ=e(d2d3„ ƒZ>e(d4d5„ ƒZ?e(d6d7„ ƒZ@e(d8d9„ ƒZAe(d:d;„ ƒZBe(d<d=„ ƒZCe(d>d?„ ƒZDe(d@dA„ ƒZEe(dBdC„ ƒZFe(dDdE„ ƒZGe(dFdG„ ƒZHe(dHdI„ ƒZIe(dJdK„ ƒZJe(dLdM„ ƒZKe(dNdO„ ƒZLdPdQ„ ZMe(dRdS„ ƒZNe(dTdU„ ƒZOe(dVdW„ ƒZPe(dXdY„ ƒZQe(dZd[„ ƒZRe(d\d]„ ƒZSe(d^d_„ ƒZTe(d`da„ ƒZUe(dbdc„ ƒZVe(ddde„ ƒZWe(dfdg„ ƒZXdhdi„ ZYdjdk„ ZZdldm„ Z[dS )nÚCertificateÚtbs_certificateÚsignature_algorithmÚsignature_valueFNc                 C   sh   t ƒ | _| d d D ]H}|d j}d| }t| |ƒrFt| ||d jƒ |d jr| j |¡ qd| _dS )	zv
        Sets common named extensions to private attributes and creates a list
        of critical extensions
        r  r  r  z	_%s_valuer  r  TN)rR   Ú_critical_extensionsrZ   ÚhasattrÚsetattrÚparsedÚaddÚ_processed_extensions)r<   Ú	extensionrº   r  r:   r:   r>   Ú_set_extensionsˆ  s    


zCertificate._set_extensionsc                 C   s   | j s|  ¡  | jS )z²
        Returns a set of the names (or OID if not a known extension) of the
        extensions marked as critical

        :return:
            A set of unicode strings
        )r%  r'  r   r_   r:   r:   r>   Úcritical_extensionsš  s    
zCertificate.critical_extensionsc                 C   s   | j s|  ¡  | jS )z¼
        This extension is used to constrain the period over which the subject
        private key may be used

        :return:
            None or a PrivateKeyUsagePeriod object
        )r%  r'  Ú_private_key_usage_period_valuer_   r:   r:   r>   Úprivate_key_usage_period_value¨  s    
z*Certificate.private_key_usage_period_valuec                 C   s   | j s|  ¡  | jS )z½
        This extension is used to contain additional identification attributes
        about the subject.

        :return:
            None or a SubjectDirectoryAttributes object
        )r%  r'  Ú#_subject_directory_attributes_valuer_   r:   r:   r>   Ú"subject_directory_attributes_value¶  s    
z.Certificate.subject_directory_attributes_valuec                 C   s   | j s|  ¡  | jS )zü
        This extension is used to help in creating certificate validation paths.
        It contains an identifier that should generally, but is not guaranteed
        to, be unique.

        :return:
            None or an OctetString object
        )r%  r'  Ú_key_identifier_valuer_   r:   r:   r>   Úkey_identifier_valueÄ  s    z Certificate.key_identifier_valuec                 C   s   | j s|  ¡  | jS )z«
        This extension is used to define the purpose of the public key
        contained within the certificate.

        :return:
            None or a KeyUsage
        )r%  r'  Ú_key_usage_valuer_   r:   r:   r>   Úkey_usage_valueÓ  s    
zCertificate.key_usage_valuec                 C   s   | j s|  ¡  | jS )aT  
        This extension allows for additional names to be associate with the
        subject of the certificate. While it may contain a whole host of
        possible names, it is usually used to allow certificates to be used
        with multiple different domain names.

        :return:
            None or a GeneralNames object
        )r%  r'  Ú_subject_alt_name_valuer_   r:   r:   r>   Úsubject_alt_name_valueá  s    z"Certificate.subject_alt_name_valuec                 C   s   | j s|  ¡  | jS )z¿
        This extension allows associating one or more alternative names with
        the issuer of the certificate.

        :return:
            None or an x509.GeneralNames object
        )r%  r'  Ú_issuer_alt_name_valuer_   r:   r:   r>   Úissuer_alt_name_valueñ  s    
z!Certificate.issuer_alt_name_valuec                 C   s   | j s|  ¡  | jS )a'  
        This extension is used to determine if the subject of the certificate
        is a CA, and if so, what the maximum number of intermediate CA certs
        after this are, before an end-entity certificate is found.

        :return:
            None or a BasicConstraints object
        )r%  r'  Ú_basic_constraints_valuer_   r:   r:   r>   Úbasic_constraints_valueÿ  s    z#Certificate.basic_constraints_valuec                 C   s   | j s|  ¡  | jS )zÃ
        This extension is used in CA certificates, and is used to limit the
        possible names of certificates issued.

        :return:
            None or a NameConstraints object
        )r%  r'  Ú_name_constraints_valuer_   r:   r:   r>   Úname_constraints_value	  s    
z"Certificate.name_constraints_valuec                 C   s   | j s|  ¡  | jS )zµ
        This extension is used to help in locating the CRL for this certificate.

        :return:
            None or a CRLDistributionPoints object
            extension
        )r%  r'  Ú_crl_distribution_points_valuer_   r:   r:   r>   Úcrl_distribution_points_value	  s    
z)Certificate.crl_distribution_points_valuec                 C   s   | j s|  ¡  | jS )a;  
        This extension defines policies in CA certificates under which
        certificates may be issued. In end-entity certificates, the inclusion
        of a policy indicates the issuance of the certificate follows the
        policy.

        :return:
            None or a CertificatePolicies object
        )r%  r'  Ú_certificate_policies_valuer_   r:   r:   r>   Úcertificate_policies_value*	  s    z&Certificate.certificate_policies_valuec                 C   s   | j s|  ¡  | jS )zû
        This extension allows mapping policy OIDs to other OIDs. This is used
        to allow different policies to be treated as equivalent in the process
        of validation.

        :return:
            None or a PolicyMappings object
        )r%  r'  Ú_policy_mappings_valuer_   r:   r:   r>   Úpolicy_mappings_value:	  s    z!Certificate.policy_mappings_valuec                 C   s   | j s|  ¡  | jS )zÏ
        This extension helps in identifying the public key with which to
        validate the authenticity of the certificate.

        :return:
            None or an AuthorityKeyIdentifier object
        )r%  r'  Ú_authority_key_identifier_valuer_   r:   r:   r>   Úauthority_key_identifier_valueI	  s    
z*Certificate.authority_key_identifier_valuec                 C   s   | j s|  ¡  | jS )z¹
        This extension is used to control if policy mapping is allowed and
        when policies are required.

        :return:
            None or a PolicyConstraints object
        )r%  r'  Ú_policy_constraints_valuer_   r:   r:   r>   Úpolicy_constraints_valueW	  s    
z$Certificate.policy_constraints_valuec                 C   s   | j s|  ¡  | jS )z–
        This extension is used to help locate any available delta CRLs

        :return:
            None or an CRLDistributionPoints object
        )r%  r'  Ú_freshest_crl_valuer_   r:   r:   r>   Úfreshest_crl_valuee	  s    	zCertificate.freshest_crl_valuec                 C   s   | j s|  ¡  | jS )z¥
        This extension is used to prevent mapping of the any policy to
        specific requirements

        :return:
            None or a Integer object
        )r%  r'  Ú_inhibit_any_policy_valuer_   r:   r:   r>   Úinhibit_any_policy_valuer	  s    
z$Certificate.inhibit_any_policy_valuec                 C   s   | j s|  ¡  | jS )zÖ
        This extension is used to define additional purposes for the public key
        beyond what is contained in the basic constraints.

        :return:
            None or an ExtKeyUsageSyntax object
        )r%  r'  Ú_extended_key_usage_valuer_   r:   r:   r>   Úextended_key_usage_value€	  s    
z$Certificate.extended_key_usage_valuec                 C   s   | j s|  ¡  | jS )zâ
        This extension is used to locate the CA certificate used to sign this
        certificate, or the OCSP responder for this certificate.

        :return:
            None or an AuthorityInfoAccessSyntax object
        )r%  r'  Ú#_authority_information_access_valuer_   r:   r:   r>   Ú"authority_information_access_valueŽ	  s    
z.Certificate.authority_information_access_valuec                 C   s   | j s|  ¡  | jS )z´
        This extension is used to access information about the subject of this
        certificate.

        :return:
            None or a SubjectInfoAccessSyntax object
        )r%  r'  Ú!_subject_information_access_valuer_   r:   r:   r>   Ú subject_information_access_valueœ	  s    
z,Certificate.subject_information_access_valuec                 C   s   | j s|  ¡  | jS )zÍ
        This extension is used to list the TLS features a server must respond
        with if a client initiates a request supporting them.

        :return:
            None or a Features object
        )r%  r'  Ú_tls_feature_valuer_   r:   r:   r>   Útls_feature_valueª	  s    
zCertificate.tls_feature_valuec                 C   s   | j s|  ¡  | jS )a-  
        This extension is used on certificates of OCSP responders, indicating
        that revocation information for the certificate should never need to
        be verified, thus preventing possible loops in path validation.

        :return:
            None or a Null object (if present)
        )r%  r'  Ú_ocsp_no_check_valuer_   r:   r:   r>   Úocsp_no_check_value¸	  s    zCertificate.ocsp_no_check_valuec                 C   s
   | d j S )zE
        :return:
            A byte string of the signature
        r  r  r_   r:   r:   r>   r  Ç	  s    zCertificate.signaturec                 C   s
   | d j S )zj
        :return:
            A unicode string of "rsassa_pkcs1v15", "rsassa_pss", "dsa", "ecdsa"
        r  )Úsignature_algor_   r:   r:   r>   rQ  Ð	  s    zCertificate.signature_algoc                 C   s
   | d j S )zŸ
        :return:
            A unicode string of "md2", "md5", "sha1", "sha224", "sha256",
            "sha384", "sha512", "sha512_224", "sha512_256"
        r  )Ú	hash_algor_   r:   r:   r>   rR  Ù	  s    zCertificate.hash_algoc                 C   s   | d d S )zT
        :return:
            The PublicKeyInfo object for this certificate
        r  r  r:   r_   r:   r:   r>   Ú
public_keyã	  s    zCertificate.public_keyc                 C   s   | d d S )zZ
        :return:
            The Name object for the subject of this certificate
        r  r  r:   r_   r:   r:   r>   r  ì	  s    zCertificate.subjectc                 C   s   | d d S )zY
        :return:
            The Name object for the issuer of this certificate
        r  r  r:   r_   r:   r:   r>   r  õ	  s    zCertificate.issuerc                 C   s   | d d j S )zT
        :return:
            An integer of the certificate's serial number
        r  r¯   r  r_   r:   r:   r>   r¯   þ	  s    zCertificate.serial_numberc                 C   s   | j s
dS | j jS )zŽ
        :return:
            None or a byte string of the certificate's key identifier from the
            key identifier extension
        N)r.  rZ   r_   r:   r:   r>   r‰  
  s    zCertificate.key_identifierc                 C   s.   | j dkr(| jjd t| jƒ d¡ | _ | j S )zÐ
        :return:
            A byte string of the SHA-256 hash of the issuer concatenated with
            the ascii character ":", concatenated with the serial number as
            an ascii string
        Nó   :re   )Ú_issuer_serialr  r,  r   r¯   rJ   r_   r:   r:   r>   Úissuer_serial
  s    	
zCertificate.issuer_serialc                 C   s   | d d d j S )zd
        :return:
            A datetime of latest time when the certificate is still valid
        r  r  rŸ   r  r_   r:   r:   r>   Únot_valid_after!
  s    zCertificate.not_valid_afterc                 C   s   | d d d j S )zd
        :return:
            A datetime of the earliest time when the certificate is valid
        r  r  r›   r  r_   r:   r:   r>   Únot_valid_before)
  s    zCertificate.not_valid_beforec                 C   s   | j s
dS | j d jS )zŠ
        :return:
            None or a byte string of the key_identifier from the authority key
            identifier extension
        Nr‰  )r@  rZ   r_   r:   r:   r>   r  1
  s    z$Certificate.authority_key_identifierc                 C   sj   | j dkrd| j}|r^|d jr^| jd d j}| ¡ }| jd j}|jd t|ƒ d¡ | _ nd| _ | j S )a;  
        :return:
            None or a byte string of the SHA-256 hash of the isser from the
            authority key identifier extension concatenated with the ascii
            character ":", concatenated with the serial number from the
            authority key identifier extension as an ascii string
        FrŠ  r   r‹  rT  re   N)Ú_authority_issuer_serialr@  rZ   r  Zuntagr,  r   rJ   )r<   Zakivr  Zauthority_serialr:   r:   r>   Úauthority_issuer_serial>
  s    

z#Certificate.authority_issuer_serialc                 C   s   | j dkr|  | j¡| _ | j S )z˜
        Returns complete CRL URLs - does not include delta CRLs

        :return:
            A list of zero or more DistributionPoint objects
        N)Ú_crl_distribution_pointsÚ!_get_http_crl_distribution_pointsr:  r_   r:   r:   r>   r   T
  s    	
z#Certificate.crl_distribution_pointsc                 C   s   | j dkr|  | j¡| _ | j S )z˜
        Returns delta CRL URLs - does not include complete CRLs

        :return:
            A list of zero or more DistributionPoint objects
        N)Ú_delta_crl_distribution_pointsr\  rD  r_   r:   r:   r>   Údelta_crl_distribution_pointsa
  s    	
z)Certificate.delta_crl_distribution_pointsc                 C   s\   g }|dkrg S |D ]B}|d }|t kr*q|jdkr6q|jD ]}|jdkr<| |¡ q<q|S )a?  
        Fetches the DistributionPoint object for non-relative, HTTP CRLs
        referenced by the certificate

        :param crl_distribution_points:
            A CRLDistributionPoints object to grab the DistributionPoints from

        :return:
            A list of zero or more DistributionPoint objects
        Nr˜  rŽ  r  )r/   rº   r  rÿ   )r<   r   r   r˜  Zdistribution_point_namerœ  r:   r:   r>   r\  n
  s    


z-Certificate._get_http_crl_distribution_pointsc                 C   s^   | j s
g S g }| j D ]D}|d jdkr|d }|jdkr:q|j}| ¡  d¡r| |¡ q|S )zx
        :return:
            A list of zero or more unicode strings of the OCSP URLs for this
            cert
        r¹  r·  rº  r  rš  )rJ  rZ   rº   rB   rI   rÿ   )r<   r   ÚentryÚlocationr�  r:   r:   r>   Ú	ocsp_urls�
  s    

zCertificate.ocsp_urlsc                 C   sž   | j dkr˜g | _ | jrH| jD ](}|jdkr|j| j kr| j  |j¡ qnPt d¡}| jjD ]<}|D ]2}|d jdkrb|d j}| 	|¡rb| j  |¡ qbqZ| j S )z»
        :return:
            A list of unicode strings of valid domain names for the certificate.
            Wildcard certificates will have a domain in the form: *.example.com
        Nr|  zE^(\*\.)?(?:[a-zA-Z0-9](?:[a-zA-Z0-9\-]*[a-zA-Z0-9])?\.)+[a-zA-Z]{2,}$r�   r­   rP   )
Ú_valid_domainsr2  rº   rZ   rÿ   râ   Úcompiler  r  Úmatch)r<   rœ  Úpatternr
  Zname_type_valuerP   r:   r:   r>   Úvalid_domains£
  s    




zCertificate.valid_domainsc                 C   s@   | j dkr:g | _ | jr:| jD ]}|jdkr| j  |j¡ q| j S )zj
        :return:
            A list of unicode strings of valid IP addresses for the certificate
        Nr€  )Ú
_valid_ipsr2  rº   rÿ   rZ   )r<   rœ  r:   r:   r>   Ú	valid_ipsÆ
  s    


zCertificate.valid_ipsc                 C   s   | j o| j d jS )zW
        :return;
            A boolean - if the certificate is marked as a CA
        r…  )r6  rZ   r_   r:   r:   r>   r…  ×
  s    zCertificate.cac                 C   s   | j s
dS | jd jS )zT
        :return;
            None or an integer of the maximum path length
        Nr‡  )r…  r6  rZ   r_   r:   r:   r>   Úmax_path_lengthà
  s    zCertificate.max_path_lengthc                 C   s   | j dkr| j| jk| _ | j S )zx
        :return:
            A boolean - if the certificate is self-issued, as defined by RFC
            5280
        N)Ú_self_issuedr  r  r_   r:   r:   r>   Úself_issuedë
  s    
zCertificate.self_issuedc                 C   sJ   | j dkrDd| _ | jrD| jr>| js*d| _ qD| j| jkrDd| _ nd| _ | j S )aõ  
        :return:
            A unicode string of "no" or "maybe". The "maybe" result will
            be returned if the certificate issuer and subject are the same.
            If a key identifier and authority key identifier are present,
            they will need to match otherwise "no" will be returned.

            To verify is a certificate is truly self-signed, the signature
            will need to be verified. See the certvalidator package for
            one possible solution.
        NÚnoÚmaybe)Ú_self_signedrk  r‰  r  r_   r:   r:   r>   Úself_signed÷
  s    
zCertificate.self_signedc                 C   s$   | j dkrt |  ¡ ¡ ¡ | _ | j S )zk
        :return:
            The SHA-1 hash of the DER-encoded bytes of this complete certificate
        Nr$  r_   r:   r:   r>   r'    s    
zCertificate.sha1c                 C   s   d  dd„ t| jƒD ƒ¡S )z¯
        :return:
            A unicode string of the SHA-1 hash, formatted using hex encoding
            with a space between each pair of characters, all uppercase
        rà   c                 s   s   | ]}d | V  qdS ©z%02XNr:   ©r  Úcr:   r:   r>   r  $  s     z/Certificate.sha1_fingerprint.<locals>.<genexpr>)rç   r   r'  r_   r:   r:   r>   Úsha1_fingerprint  s    zCertificate.sha1_fingerprintc                 C   s$   | j dkrt |  ¡ ¡ ¡ | _ | j S )zy
        :return:
            The SHA-256 hash of the DER-encoded bytes of this complete
            certificate
        Nr*  r_   r:   r:   r>   r,  &  s    
zCertificate.sha256c                 C   s   d  dd„ t| jƒD ƒ¡S )z±
        :return:
            A unicode string of the SHA-256 hash, formatted using hex encoding
            with a space between each pair of characters, all uppercase
        rà   c                 s   s   | ]}d | V  qdS rp  r:   rq  r:   r:   r>   r  :  s     z1Certificate.sha256_fingerprint.<locals>.<genexpr>)rç   r   r,  r_   r:   r:   r>   Úsha256_fingerprint2  s    zCertificate.sha256_fingerprintc                 C   sN  t |tƒsttdt|ƒƒƒ‚| d¡ d¡ ¡ }| d¡dk}| oNt	 
d|¡}| oZ| }|râ| jsjdS | d¡}| jD ]b}| d¡ d¡ ¡ }| d¡}	t|	ƒt|ƒkr®qz|	|kr¼ d	S |  |¡}
|
rz|  ||	¡rz d	S qzdS | jsìdS |rötjntj}t||ƒ}| jD ]<}| d¡dk�r&tjntj}t||ƒ}||k�r d	S �qdS )
a  
        Check if a domain name or IP address is valid according to the
        certificate

        :param domain_ip:
            A unicode string of a domain name or IP address

        :return:
            A boolean - if the domain or IP is valid for the certificate
        zL
                domain_ip must be a unicode string, not %s
                r   re   rt   rd   z^\d+\.\d+\.\d+\.\d+$FrE   T)r@   r   rH   r	   r   rJ   rl   rB   rg   râ   rd  rf  r|   r�   Ú_is_wildcard_domainÚ_is_wildcard_matchrh  r~   r€   r   r4   )r<   Z	domain_ipZencoded_domain_ipÚis_ipv6Zis_ipv4Z	is_domainÚdomain_labelsZvalid_domainZencoded_valid_domainÚvalid_domain_labelsZis_wildcardr†   Znormalized_ipZvalid_ipZvalid_familyZnormalized_valid_ipr:   r:   r>   Úis_valid_domain_ip<  sD    
ü








zCertificate.is_valid_domain_ipc                 C   sZ   |  d¡dkrdS | ¡  d¡}|s(dS |d  d¡dkr>dS |d dd… dkrVdS d	S )
af  
        Checks if a domain is a valid wildcard according to
        https://tools.ietf.org/html/rfc6125#section-6.4.3

        :param domain:
            A unicode string of the domain name, where any U-labels from an IDN
            have been converted to A-labels

        :return:
            A boolean - if the domain is a valid wildcard domain
        Ú*r   FrE   r   rd   rˆ   zxn--T)ÚcountrB   r|   rg   )r<   ÚdomainÚlabelsr:   r:   r>   ru  ~  s    zCertificate._is_wildcard_domainc                 C   sl   |d }|dd… }|d }|dd… }||kr4dS |dkr@dS t  d| dd¡ d	 ¡}| |¡rhdS dS )
aÿ  
        Determines if the labels in a domain are a match for labels from a
        wildcard valid domain name

        :param domain_labels:
            A list of unicode strings, with A-label form for IDNs, of the labels
            in the domain name to check

        :param valid_domain_labels:
            A list of unicode strings, with A-label form for IDNs, of the labels
            in a wildcard domain pattern

        :return:
            A boolean - if the domain matches the valid domain
        r   r   NFr{  Tú^z.*ú$)râ   rc  ræ   rd  )r<   rx  ry  Zfirst_domain_labelZother_domain_labelsZwildcard_labelZother_valid_domain_labelsZwildcard_regexr:   r:   r>   rv  Ÿ  s    
zCertificate._is_wildcard_match)\rS   rT   rU   r  r   r"   r�   r%  r   r+  r-  r/  r1  r3  r5  r7  r9  r;  r=  r?  rA  rC  rE  rG  rI  rK  r)  rM  rO  rU  rY  r[  r]  rb  rg  rj  rn  r%  r+  r'  rm   r(  r*  r,  r.  r0  r2  r4  r6  r8  r:  r<  r>  r@  rB  rD  rF  rH  rJ  rL  rN  rP  r  rQ  rR  rS  r  r  r¯   r‰  rV  rW  rX  r  rZ  r   r^  r\  ra  rf  rh  r…  ri  rk  ro  r'  rs  r,  rt  rz  ru  rv  r:   r:   r:   r>   r  `  s  ý























	













"








	

	B!r  c                   @   s   e Zd ZeZdS )ÚKeyPurposeIdentifiersNrµ  r:   r:   r:   r>   r�  É  s   r�  c                   @   s   e Zd ZeZdS )ÚSequenceOfAlgorithmIdentifiersN)rS   rT   rU   r   r‘   r:   r:   r:   r>   r‚  Í  s   r‚  c                	   @   sP   e Zd Zdeddifdedddœfdeddifdeddifd	ed
ddœfgZdS )ÚCertificateAuxÚtrustrž   TZrejectr   rœ   ÚaliasZkeyidr=   r   N)rS   rT   rU   r�  r-   r#   r‚  r�   r:   r:   r:   r>   rƒ  Ñ  s   ûrƒ  c                   @   s   e Zd ZeegZdS )ÚTrustedCertificateN)rS   rT   rU   r  rƒ  Z_child_specsr:   r:   r:   r>   r†  Û  s   r†  )¶r¢   Ú
__future__r   r   r   r   Ú
contextlibr   Ú	encodingsr   r&  râ   r~   rè   rä   rê   Ú_errorsr	   Z_irir
   r   Z_ordereddictr   Ú_typesr   r   r   Zalgosr   r   r   r   Úcorer   r   r   r   r   r   r   r   r   r   r   r   r    r!   r"   r#   r$   r%   r&   r'   r(   r)   r*   r+   r,   r-   r.   r/   rþ   r0   Úutilr1   r2   r3   r4   r5   rW   r`   ro   rŒ   r�   r’   rš   r    r¤   r¥   r¬   rÛ   rø   r  rÖ   r-  r/  r5  r8  r:  r<  r>  r@  rA  rD  rE  rF  rG  rH  rI  rJ  rK  rL  rM  rO  rP  rQ  rR  rS  rt  rw  rx  ry  rz  r�  r‚  rƒ  r„  rˆ  rŒ  r�  r�  r•  r–  r—  rž  rŸ  r   r¢  r£  r¤  r§  rª  r«  r¬  r­  r®  r¯  r°  r²  r´  r¶  r¸  r»  r½  r¾  r¿  rÀ  rÃ  rÆ  rÉ  rÊ  rÍ  rÏ  rÐ  rÑ  rÓ  rÔ  rÙ  rÚ  rÝ  rß  rá  râ  rã  rä  rå  rï  rð  rñ  rò  ró  rô  r÷  rø  r  r  r  r  r�  r‚  rƒ  r†  r:   r:   r:   r>   Ú<module>   s  x59q 
  BU* D

			"2%	p			 &      o
