U
    ÒZj–„  ã                   @   sÌ  d dl Z d dlZd dlZd dlZd dlmZ d dlmZ d dl	m
Z
mZ d dlmZmZmZmZmZmZmZ d dlmZmZmZ d dlmZmZmZmZ d dlmZmZ d d	l m!Z! e d
dd¡Z"G dd„ de#ƒZ$ee ej%ee  ddœdd„Z&e!ej%ej'e!e(ej)e* f  ddœdd„Z+ejejdœdd„Z,G dd„ dƒZ-G dd„ dƒZ.G dd„ dej/ƒZ0G dd„ de#ƒZ1G dd „ d e j2d!�Z3e3 4ej3¡ G d"d#„ d#e j2d!�Z5e5 4ej5¡ G d$d%„ d%e5ƒZ6G d&d'„ d'e j2d!�Z7e7 4ej7¡ G d(d)„ d)e j2d!�Z8e8 4ej8¡ dBe(ej9e3d*œd+d,„Z:dCe(ej9e3d*œd-d.„Z;dDe(ej9e8d*œd/d0„Z<dEe(ej9e8d*œd1d2„Z=dFe(ej9e7d*œd3d4„Z>dGe(ej9e7d*œd5d6„Z?G d7d8„ d8ƒZ@G d9d:„ d:ƒZAG d;d<„ d<ƒZBG d=d>„ d>ƒZCe*d?œd@dA„ZDdS )Hé    N)Úutils)Úx509)ÚhashesÚserialization)ÚdsaÚecÚed25519Úed448ÚrsaÚx25519Úx448)Ú#CERTIFICATE_ISSUER_PUBLIC_KEY_TYPESÚCERTIFICATE_PRIVATE_KEY_TYPESÚCERTIFICATE_PUBLIC_KEY_TYPES)Ú	ExtensionÚExtensionTypeÚ
ExtensionsÚ_make_sequence_methods)ÚNameÚ	_ASN1Type)ÚObjectIdentifieriž  é   c                       s&   e Zd Zeeddœ‡ fdd„Z‡  ZS )ÚAttributeNotFoundN)ÚmsgÚoidÚreturnc                    s   t t| ƒ |¡ || _d S ©N)Úsuperr   Ú__init__r   )Úselfr   r   ©Ú	__class__© úY/var/www/html/TRUCKING_PROJECT/venv/lib/python3.8/site-packages/cryptography/x509/base.pyr   *   s    zAttributeNotFound.__init__)Ú__name__Ú
__module__Ú__qualname__Ústrr   r   Ú__classcell__r"   r"   r    r#   r   )   s   r   )Ú	extensionÚ
extensionsr   c                 C   s"   |D ]}|j | j krtdƒ‚qd S )Nz$This extension has already been set.)r   Ú
ValueError)r)   r*   Úer"   r"   r#   Ú_reject_duplicate_extension/   s    r-   )r   Ú
attributesr   c                 C   s$   |D ]\}}}|| krt dƒ‚qd S )Nz$This attribute has already been set.)r+   )r   r.   Zattr_oidÚ_r"   r"   r#   Ú_reject_duplicate_attribute9   s    r0   ©Útimer   c                 C   s:   | j dk	r2|  ¡ }|r|nt ¡ }| jdd�| S | S dS )z’Normalizes a datetime to a naive datetime in UTC.

    time -- datetime to normalize. Assumed to be in UTC if not timezone
            aware.
    N)Útzinfo)r3   Ú	utcoffsetÚdatetimeÚ	timedeltaÚreplace)r2   Úoffsetr"   r"   r#   Ú_convert_to_naive_utc_timeE   s
    
r9   c                   @   sx   e Zd Zejjfeeeddœdd„Z	e
edœdd„ƒZe
edœdd	„ƒZedœd
d„Zeedœdd„Zedœdd„ZdS )Ú	AttributeN)r   ÚvalueÚ_typer   c                 C   s   || _ || _|| _d S r   )Ú_oidÚ_valuer<   )r   r   r;   r<   r"   r"   r#   r   T   s    zAttribute.__init__©r   c                 C   s   | j S r   )r=   ©r   r"   r"   r#   r   ^   s    zAttribute.oidc                 C   s   | j S r   )r>   r@   r"   r"   r#   r;   b   s    zAttribute.valuec                 C   s   d  | j| j¡S )Nz<Attribute(oid={}, value={!r})>)Úformatr   r;   r@   r"   r"   r#   Ú__repr__f   s    zAttribute.__repr__©Úotherr   c                 C   s2   t |tƒstS | j|jko0| j|jko0| j|jkS r   )Ú
isinstancer:   ÚNotImplementedr   r;   r<   ©r   rD   r"   r"   r#   Ú__eq__i   s    

ÿ
ýzAttribute.__eq__c                 C   s   t | j| j| jfƒS r   )Úhashr   r;   r<   r@   r"   r"   r#   Ú__hash__s   s    zAttribute.__hash__)r$   r%   r&   r   Z
UTF8Stringr;   r   ÚbytesÚintr   Úpropertyr   r'   rB   ÚobjectÚboolrH   rJ   r"   r"   r"   r#   r:   S   s   üû

r:   c                   @   sN   e Zd Zeje ddœdd„Zedƒ\ZZ	Z
edœdd„Zeed	œd
d„ZdS )Ú
AttributesN)r.   r   c                 C   s   t |ƒ| _d S r   )ÚlistÚ_attributes)r   r.   r"   r"   r#   r   x   s    zAttributes.__init__rR   r?   c                 C   s   d  | j¡S )Nz<Attributes({})>)rA   rR   r@   r"   r"   r#   rB   €   s    zAttributes.__repr__©r   r   c                 C   s0   | D ]}|j |kr|  S qtd |¡|ƒ‚d S )NzNo {} attribute was found)r   r   rA   )r   r   Úattrr"   r"   r#   Úget_attribute_for_oidƒ   s    

z Attributes.get_attribute_for_oid)r$   r%   r&   ÚtypingÚIterabler:   r   r   Ú__len__Ú__iter__Ú__getitem__r'   rB   r   rU   r"   r"   r"   r#   rP   w   s   ýrP   c                   @   s   e Zd ZdZdZdS )ÚVersionr   é   N)r$   r%   r&   Zv1Úv3r"   r"   r"   r#   r[   ‹   s   r[   c                       s&   e Zd Zeeddœ‡ fdd„Z‡  ZS )ÚInvalidVersionN)r   Úparsed_versionr   c                    s   t t| ƒ |¡ || _d S r   )r   r^   r   r_   )r   r   r_   r    r"   r#   r   ‘   s    zInvalidVersion.__init__)r$   r%   r&   r'   rL   r   r(   r"   r"   r    r#   r^   �   s   r^   c                   @   sv  e Zd Zejejedœdd„ƒZej	e
dœdd„ƒZej	edœdd„ƒZejedœd	d
„ƒZej	ejdœdd„ƒZej	ejdœdd„ƒZej	edœdd„ƒZej	edœdd„ƒZej	ejej dœdd„ƒZej	edœdd„ƒZej	edœdd„ƒZej	edœdd„ƒZej	edœdd„ƒZej	edœdd„ƒZeje e!dœd d!„ƒZ"eje
dœd"d#„ƒZ#eje$j%ed$œd%d&„ƒZ&d'S )(ÚCertificate©Ú	algorithmr   c                 C   s   dS ©z4
        Returns bytes using digest passed.
        Nr"   ©r   rb   r"   r"   r#   Úfingerprint—   s    zCertificate.fingerprintr?   c                 C   s   dS )z3
        Returns certificate serial number
        Nr"   r@   r"   r"   r#   Úserial_number�   s    zCertificate.serial_numberc                 C   s   dS )z1
        Returns the certificate version
        Nr"   r@   r"   r"   r#   Úversion£   s    zCertificate.versionc                 C   s   dS ©z(
        Returns the public key
        Nr"   r@   r"   r"   r#   Ú
public_key©   s    zCertificate.public_keyc                 C   s   dS )z?
        Not before time (represented as UTC datetime)
        Nr"   r@   r"   r"   r#   Únot_valid_before¯   s    zCertificate.not_valid_beforec                 C   s   dS )z>
        Not after time (represented as UTC datetime)
        Nr"   r@   r"   r"   r#   Únot_valid_afterµ   s    zCertificate.not_valid_afterc                 C   s   dS )z1
        Returns the issuer name object.
        Nr"   r@   r"   r"   r#   Úissuer»   s    zCertificate.issuerc                 C   s   dS ©z2
        Returns the subject name object.
        Nr"   r@   r"   r"   r#   ÚsubjectÁ   s    zCertificate.subjectc                 C   s   dS ©zt
        Returns a HashAlgorithm corresponding to the type of the digest signed
        in the certificate.
        Nr"   r@   r"   r"   r#   Úsignature_hash_algorithmÇ   s    z$Certificate.signature_hash_algorithmc                 C   s   dS ©zJ
        Returns the ObjectIdentifier of the signature algorithm.
        Nr"   r@   r"   r"   r#   Úsignature_algorithm_oidÐ   s    z#Certificate.signature_algorithm_oidc                 C   s   dS )z/
        Returns an Extensions object.
        Nr"   r@   r"   r"   r#   r*   Ö   s    zCertificate.extensionsc                 C   s   dS ©z.
        Returns the signature bytes.
        Nr"   r@   r"   r"   r#   Ú	signatureÜ   s    zCertificate.signaturec                 C   s   dS )zR
        Returns the tbsCertificate payload bytes as defined in RFC 5280.
        Nr"   r@   r"   r"   r#   Útbs_certificate_bytesâ   s    z!Certificate.tbs_certificate_bytesc                 C   s   dS )zh
        Returns the tbsCertificate payload bytes with the SCT list extension
        stripped.
        Nr"   r@   r"   r"   r#   Útbs_precertificate_bytesè   s    z$Certificate.tbs_precertificate_bytesrC   c                 C   s   dS ©z"
        Checks equality.
        Nr"   rG   r"   r"   r#   rH   ï   s    zCertificate.__eq__c                 C   s   dS ©z"
        Computes a hash.
        Nr"   r@   r"   r"   r#   rJ   õ   s    zCertificate.__hash__©Úencodingr   c                 C   s   dS )zB
        Serializes the certificate to PEM or DER format.
        Nr"   ©r   rz   r"   r"   r#   Úpublic_bytesû   s    zCertificate.public_bytesN)'r$   r%   r&   ÚabcÚabstractmethodr   ÚHashAlgorithmrK   re   ÚabstractpropertyrL   rf   r[   rg   r   ri   r5   rj   rk   r   rl   rn   rV   ÚOptionalrp   r   rr   r   r*   rt   ru   rv   rN   rO   rH   rJ   r   ÚEncodingr|   r"   r"   r"   r#   r`   –   sF   
þr`   )Ú	metaclassc                   @   sJ   e Zd Zejedœdd„ƒZejejdœdd„ƒZeje	dœdd„ƒZ
dS )	ÚRevokedCertificater?   c                 C   s   dS )zG
        Returns the serial number of the revoked certificate.
        Nr"   r@   r"   r"   r#   rf     s    z RevokedCertificate.serial_numberc                 C   s   dS )zH
        Returns the date of when this certificate was revoked.
        Nr"   r@   r"   r"   r#   Úrevocation_date  s    z"RevokedCertificate.revocation_datec                 C   s   dS )zW
        Returns an Extensions object containing a list of Revoked extensions.
        Nr"   r@   r"   r"   r#   r*     s    zRevokedCertificate.extensionsN)r$   r%   r&   r}   r€   rL   rf   r5   r…   r   r*   r"   r"   r"   r#   r„     s   r„   c                   @   sX   e Zd Zeejedœdd„Zeedœdd„ƒZeejdœdd„ƒZ	eedœd	d
„ƒZ
dS )Ú_RawRevokedCertificate©rf   r…   r*   c                 C   s   || _ || _|| _d S r   ©Ú_serial_numberÚ_revocation_dateÚ_extensions©r   rf   r…   r*   r"   r"   r#   r     s    z_RawRevokedCertificate.__init__r?   c                 C   s   | j S r   )r‰   r@   r"   r"   r#   rf   )  s    z$_RawRevokedCertificate.serial_numberc                 C   s   | j S r   )rŠ   r@   r"   r"   r#   r…   -  s    z&_RawRevokedCertificate.revocation_datec                 C   s   | j S r   )r‹   r@   r"   r"   r#   r*   1  s    z!_RawRevokedCertificate.extensionsN)r$   r%   r&   rL   r5   r   r   rM   rf   r…   r*   r"   r"   r"   r#   r†     s   ü
r†   c                   @   sÆ  e Zd Zejejedœdd„ƒZeje	j
edœdd„ƒZejeeje dœdd	„ƒZejeje	j
 d
œdd„ƒZejed
œdd„ƒZejed
œdd„ƒZejejej d
œdd„ƒZejejd
œdd„ƒZejed
œdd„ƒZejed
œdd„ƒZejed
œdd„ƒZejeedœdd„ƒZ ejed
œdd„ƒZ!ej"eed œd!d"„ƒZ#ej"e$ej%e d œd#d"„ƒZ#ejej&ee$f ej&eej%e f d œd$d"„ƒZ#ejej'e d
œd%d&„ƒZ(eje)ed'œd(d)„ƒZ*d*S )+ÚCertificateRevocationListry   c                 C   s   dS )z:
        Serializes the CRL to PEM or DER format.
        Nr"   r{   r"   r"   r#   r|   7  s    z&CertificateRevocationList.public_bytesra   c                 C   s   dS rc   r"   rd   r"   r"   r#   re   =  s    z%CertificateRevocationList.fingerprint)rf   r   c                 C   s   dS )zs
        Returns an instance of RevokedCertificate or None if the serial_number
        is not in the CRL.
        Nr"   )r   rf   r"   r"   r#   Ú(get_revoked_certificate_by_serial_numberC  s    zBCertificateRevocationList.get_revoked_certificate_by_serial_numberr?   c                 C   s   dS ro   r"   r@   r"   r"   r#   rp   L  s    z2CertificateRevocationList.signature_hash_algorithmc                 C   s   dS rq   r"   r@   r"   r"   r#   rr   U  s    z1CertificateRevocationList.signature_algorithm_oidc                 C   s   dS )zC
        Returns the X509Name with the issuer of this CRL.
        Nr"   r@   r"   r"   r#   rl   [  s    z CertificateRevocationList.issuerc                 C   s   dS )z?
        Returns the date of next update for this CRL.
        Nr"   r@   r"   r"   r#   Únext_updatea  s    z%CertificateRevocationList.next_updatec                 C   s   dS )z?
        Returns the date of last update for this CRL.
        Nr"   r@   r"   r"   r#   Úlast_updateg  s    z%CertificateRevocationList.last_updatec                 C   s   dS )zS
        Returns an Extensions object containing a list of CRL extensions.
        Nr"   r@   r"   r"   r#   r*   m  s    z$CertificateRevocationList.extensionsc                 C   s   dS rs   r"   r@   r"   r"   r#   rt   s  s    z#CertificateRevocationList.signaturec                 C   s   dS )zO
        Returns the tbsCertList payload bytes as defined in RFC 5280.
        Nr"   r@   r"   r"   r#   Útbs_certlist_bytesy  s    z,CertificateRevocationList.tbs_certlist_bytesrC   c                 C   s   dS rw   r"   rG   r"   r"   r#   rH     s    z CertificateRevocationList.__eq__c                 C   s   dS )z<
        Number of revoked certificates in the CRL.
        Nr"   r@   r"   r"   r#   rX   …  s    z!CertificateRevocationList.__len__)Úidxr   c                 C   s   d S r   r"   ©r   r’   r"   r"   r#   rZ   ‹  s    z%CertificateRevocationList.__getitem__c                 C   s   d S r   r"   r“   r"   r"   r#   rZ   �  s    c                 C   s   dS )zS
        Returns a revoked certificate (or slice of revoked certificates).
        Nr"   r“   r"   r"   r#   rZ   “  s    c                 C   s   dS )z8
        Iterator over the revoked certificates
        Nr"   r@   r"   r"   r#   rY   ›  s    z"CertificateRevocationList.__iter__)ri   r   c                 C   s   dS )zQ
        Verifies signature of revocation list against given public key.
        Nr"   )r   ri   r"   r"   r#   Úis_signature_valid¡  s    z,CertificateRevocationList.is_signature_validN)+r$   r%   r&   r}   r~   r   r‚   rK   r|   r   r   re   rL   rV   r�   r„   rŽ   r€   rp   r   rr   r   rl   r5   r�   r�   r   r*   rt   r‘   rN   rO   rH   rX   ÚoverloadrZ   ÚsliceÚListÚUnionÚIteratorrY   r   r”   r"   r"   r"   r#   r�   6  sV   þ
þþþr�   c                   @   s   e Zd Zejeedœdd„ƒZejedœdd„ƒZ	eje
dœdd„ƒZejedœd	d
„ƒZejejej dœdd„ƒZejedœdd„ƒZejedœdd„ƒZejedœdd„ƒZejejedœdd„ƒZejedœdd„ƒZejedœdd„ƒZejedœdd„ƒZ ejeedœdd„ƒZ!dS ) ÚCertificateSigningRequestrC   c                 C   s   dS rw   r"   rG   r"   r"   r#   rH   ®  s    z CertificateSigningRequest.__eq__r?   c                 C   s   dS rx   r"   r@   r"   r"   r#   rJ   ´  s    z"CertificateSigningRequest.__hash__c                 C   s   dS rh   r"   r@   r"   r"   r#   ri   º  s    z$CertificateSigningRequest.public_keyc                 C   s   dS rm   r"   r@   r"   r"   r#   rn   À  s    z!CertificateSigningRequest.subjectc                 C   s   dS ro   r"   r@   r"   r"   r#   rp   Æ  s    z2CertificateSigningRequest.signature_hash_algorithmc                 C   s   dS rq   r"   r@   r"   r"   r#   rr   Ï  s    z1CertificateSigningRequest.signature_algorithm_oidc                 C   s   dS )z@
        Returns the extensions in the signing request.
        Nr"   r@   r"   r"   r#   r*   Õ  s    z$CertificateSigningRequest.extensionsc                 C   s   dS )z/
        Returns an Attributes object.
        Nr"   r@   r"   r"   r#   r.   Û  s    z$CertificateSigningRequest.attributesry   c                 C   s   dS )z;
        Encodes the request to PEM or DER format.
        Nr"   r{   r"   r"   r#   r|   á  s    z&CertificateSigningRequest.public_bytesc                 C   s   dS rs   r"   r@   r"   r"   r#   rt   ç  s    z#CertificateSigningRequest.signaturec                 C   s   dS )zd
        Returns the PKCS#10 CertificationRequestInfo bytes as defined in RFC
        2986.
        Nr"   r@   r"   r"   r#   Útbs_certrequest_bytesí  s    z/CertificateSigningRequest.tbs_certrequest_bytesc                 C   s   dS )z8
        Verifies signature of signing request.
        Nr"   r@   r"   r"   r#   r”   ô  s    z,CertificateSigningRequest.is_signature_validrS   c                 C   s   dS )z:
        Get the attribute value for a given OID.
        Nr"   )r   r   r"   r"   r#   rU   ú  s    z/CertificateSigningRequest.get_attribute_for_oidN)"r$   r%   r&   r}   r~   rN   rO   rH   rL   rJ   r   ri   r€   r   rn   rV   r�   r   r   rp   r   rr   r   r*   rP   r.   r   r‚   rK   r|   rt   r›   r”   rU   r"   r"   r"   r#   rš   ­  s6   
þrš   )ÚdataÚbackendr   c                 C   s
   t  | ¡S r   )Ú	rust_x509Úload_pem_x509_certificate©rœ   r�   r"   r"   r#   rŸ     s    rŸ   c                 C   s
   t  | ¡S r   )rž   Úload_der_x509_certificater    r"   r"   r#   r¡     s    r¡   c                 C   s
   t  | ¡S r   )rž   Úload_pem_x509_csrr    r"   r"   r#   r¢     s    r¢   c                 C   s
   t  | ¡S r   )rž   Úload_der_x509_csrr    r"   r"   r#   r£     s    r£   c                 C   s
   t  | ¡S r   )rž   Úload_pem_x509_crlr    r"   r"   r#   r¤   "  s    r¤   c                 C   s
   t  | ¡S r   )rž   Úload_der_x509_crlr    r"   r"   r#   r¥   )  s    r¥   c                	   @   s°   e Zd Zdg g feje ejee  ejej	e
eeje f  dœdd„Zed dœdd„Zeed dœd	d
„Zddœe
eeje d dœdd„Zdeejej ejedœdd„ZdS )Ú CertificateSigningRequestBuilderN)Úsubject_namer*   r.   c                 C   s   || _ || _|| _dS )zB
        Creates an empty X.509 certificate request (v1).
        N)Ú_subject_namer‹   rR   )r   r§   r*   r.   r"   r"   r#   r   0  s    z)CertificateSigningRequestBuilder.__init__©Únamer   c                 C   s4   t |tƒstdƒ‚| jdk	r$tdƒ‚t|| j| jƒS )zF
        Sets the certificate requestor's distinguished name.
        úExpecting x509.Name object.Nú&The subject name may only be set once.)rE   r   Ú	TypeErrorr¨   r+   r¦   r‹   rR   ©r   rª   r"   r"   r#   r§   ?  s    

  ÿz-CertificateSigningRequestBuilder.subject_name©ÚextvalÚcriticalr   c                 C   sD   t |tƒstdƒ‚t|j||ƒ}t|| jƒ t| j| j|g | j	ƒS )zE
        Adds an X.509 extension to the certificate request.
        ú"extension must be an ExtensionType)
rE   r   r­   r   r   r-   r‹   r¦   r¨   rR   ©r   r°   r±   r)   r"   r"   r#   Úadd_extensionK  s    

ýz.CertificateSigningRequestBuilder.add_extension)Ú_tag)r   r;   rµ   r   c                C   s|   t |tƒstdƒ‚t |tƒs$tdƒ‚|dk	r>t |tƒs>tdƒ‚t|| jƒ |dk	rZ|j}nd}t| j	| j
| j|||fg ƒS )zK
        Adds an X.509 attribute with an OID and associated value.
        zoid must be an ObjectIdentifierzvalue must be bytesNztag must be _ASN1Type)rE   r   r­   rK   r   r0   rR   r;   r¦   r¨   r‹   )r   r   r;   rµ   Útagr"   r"   r#   Úadd_attribute]  s    


ýz.CertificateSigningRequestBuilder.add_attribute©Úprivate_keyrb   r�   r   c                 C   s    | j dkrtdƒ‚t | ||¡S )zF
        Signs the request using the requestor's private key.
        Nz/A CertificateSigningRequest must have a subject)r¨   r+   rž   Zcreate_x509_csr©r   r¹   rb   r�   r"   r"   r#   Úsign}  s    	
z%CertificateSigningRequestBuilder.sign)N)r$   r%   r&   rV   r�   r   r—   r   r   ÚTupler   rK   rL   r   r§   rO   r´   r   r·   r   r   r   ÚAnyrš   r»   r"   r"   r"   r#   r¦   /  s:   úÿü þûú$ ü
ûr¦   c                
   @   s  e Zd ZU ejee  ed< ddddddg feje	 eje	 eje
 eje ejej ejej ejee  ddœdd„Ze	d dœdd„Ze	d dœd	d
„Ze
d dœdd„Zed dœdd„Zejd dœdd„Zejd dœdd„Zeed dœdd„Zdeejej ejedœdd„ZdS )ÚCertificateBuilderr‹   N)Úissuer_namer§   ri   rf   rj   rk   r*   r   c                 C   s6   t j| _|| _|| _|| _|| _|| _|| _|| _	d S r   )
r[   r]   Ú_versionÚ_issuer_namer¨   Ú_public_keyr‰   Ú_not_valid_beforeÚ_not_valid_afterr‹   )r   r¿   r§   ri   rf   rj   rk   r*   r"   r"   r#   r   Ž  s    
zCertificateBuilder.__init__r©   c                 C   sD   t |tƒstdƒ‚| jdk	r$tdƒ‚t|| j| j| j| j	| j
| jƒS )z3
        Sets the CA's distinguished name.
        r«   Nú%The issuer name may only be set once.)rE   r   r­   rÁ   r+   r¾   r¨   rÂ   r‰   rÃ   rÄ   r‹   r®   r"   r"   r#   r¿   ¡  s    

ùzCertificateBuilder.issuer_namec                 C   sD   t |tƒstdƒ‚| jdk	r$tdƒ‚t| j|| j| j| j	| j
| jƒS )z:
        Sets the requestor's distinguished name.
        r«   Nr¬   )rE   r   r­   r¨   r+   r¾   rÁ   rÂ   r‰   rÃ   rÄ   r‹   r®   r"   r"   r#   r§   ³  s    

ùzCertificateBuilder.subject_name)Úkeyr   c              	   C   s`   t |tjtjtjtjt	j
tjtjfƒs.tdƒ‚| jdk	r@tdƒ‚t| j| j|| j| j| j| jƒS )zT
        Sets the requestor's public key (as found in the signing request).
        z‰Expecting one of DSAPublicKey, RSAPublicKey, EllipticCurvePublicKey, Ed25519PublicKey, Ed448PublicKey, X25519PublicKey, or X448PublicKey.Nz$The public key may only be set once.)rE   r   ZDSAPublicKeyr
   ZRSAPublicKeyr   ZEllipticCurvePublicKeyr   ZEd25519PublicKeyr	   ZEd448PublicKeyr   ZX25519PublicKeyr   ZX448PublicKeyr­   rÂ   r+   r¾   rÁ   r¨   r‰   rÃ   rÄ   r‹   )r   rÆ   r"   r"   r#   ri   Å  s2    ùþÿ
ùzCertificateBuilder.public_key©Únumberr   c                 C   sh   t |tƒstdƒ‚| jdk	r$tdƒ‚|dkr4tdƒ‚| ¡ dkrHtdƒ‚t| j| j| j	|| j
| j| jƒS )z5
        Sets the certificate serial number.
        ú'Serial number must be of integral type.Nú'The serial number may only be set once.r   z%The serial number should be positive.é    ú3The serial number should not be more than 159 bits.)rE   rL   r­   r‰   r+   Ú
bit_lengthr¾   rÁ   r¨   rÂ   rÃ   rÄ   r‹   ©r   rÈ   r"   r"   r#   rf   ê  s&    

ÿùz CertificateBuilder.serial_numberr1   c                 C   sz   t |tjƒstdƒ‚| jdk	r&tdƒ‚t|ƒ}|tk r>tdƒ‚| jdk	rZ|| jkrZtdƒ‚t| j	| j
| j| j|| j| jƒS )z7
        Sets the certificate activation time.
        úExpecting datetime object.Nz*The not valid before may only be set once.z>The not valid before date must be on or after 1950 January 1).zBThe not valid before date must be before the not valid after date.)rE   r5   r­   rÃ   r+   r9   Ú_EARLIEST_UTC_TIMErÄ   r¾   rÁ   r¨   rÂ   r‰   r‹   ©r   r2   r"   r"   r#   rj     s,    
ÿÿùz#CertificateBuilder.not_valid_beforec                 C   sz   t |tjƒstdƒ‚| jdk	r&tdƒ‚t|ƒ}|tk r>tdƒ‚| jdk	rZ|| jk rZtdƒ‚t| j	| j
| j| j| j|| jƒS )z7
        Sets the certificate expiration time.
        rÏ   Nz)The not valid after may only be set once.z<The not valid after date must be on or after 1950 January 1.zAThe not valid after date must be after the not valid before date.)rE   r5   r­   rÄ   r+   r9   rÐ   rÃ   r¾   rÁ   r¨   rÂ   r‰   r‹   rÑ   r"   r"   r#   rk   $  s2    
ÿÿþÿùz"CertificateBuilder.not_valid_afterr¯   c              	   C   sT   t |tƒstdƒ‚t|j||ƒ}t|| jƒ t| j| j	| j
| j| j| j| j|g ƒS )z=
        Adds an X.509 extension to the certificate.
        r²   )rE   r   r­   r   r   r-   r‹   r¾   rÁ   r¨   rÂ   r‰   rÃ   rÄ   r³   r"   r"   r#   r´   D  s    

ùz CertificateBuilder.add_extensionr¸   c                 C   sz   | j dkrtdƒ‚| jdkr$tdƒ‚| jdkr6tdƒ‚| jdkrHtdƒ‚| jdkrZtdƒ‚| jdkrltdƒ‚t | ||¡S )zC
        Signs the certificate using the CA's private key.
        Nz&A certificate must have a subject namez&A certificate must have an issuer namez'A certificate must have a serial numberz/A certificate must have a not valid before timez.A certificate must have a not valid after timez$A certificate must have a public key)	r¨   r+   rÁ   r‰   rÃ   rÄ   rÂ   rž   Zcreate_x509_certificaterº   r"   r"   r#   r»   Z  s    	





zCertificateBuilder.sign)N)r$   r%   r&   rV   r—   r   r   Ú__annotations__r�   r   r   rL   r5   r   r¿   r§   ri   rf   rj   rk   rO   r´   r   r   r   r½   r`   r»   r"   r"   r"   r#   r¾   ‹  sN   
ø

÷ý%þ! þ ü
ûr¾   c                   @   sì   e Zd ZU ejee  ed< eje ed< dddg g fej	e
 ej	ej ej	ej ejee  eje dœdd„Ze
d dœdd	„Zejd d
œdd„Zejd dœdd„Zeed dœdd„Zed dœdd„Zdeej	ej ejedœdd„ZdS )Ú CertificateRevocationListBuilderr‹   Ú_revoked_certificatesN)r¿   r�   r�   r*   Úrevoked_certificatesc                 C   s"   || _ || _|| _|| _|| _d S r   )rÁ   Ú_last_updateÚ_next_updater‹   rÔ   )r   r¿   r�   r�   r*   rÕ   r"   r"   r#   r   |  s
    z)CertificateRevocationListBuilder.__init__)r¿   r   c                 C   s<   t |tƒstdƒ‚| jd k	r$tdƒ‚t|| j| j| j| j	ƒS )Nr«   rÅ   )
rE   r   r­   rÁ   r+   rÓ   rÖ   r×   r‹   rÔ   )r   r¿   r"   r"   r#   r¿   Š  s    

ûz,CertificateRevocationListBuilder.issuer_name)r�   r   c                 C   sr   t |tjƒstdƒ‚| jd k	r&tdƒ‚t|ƒ}|tk r>tdƒ‚| jd k	rZ|| jkrZtdƒ‚t| j	|| j| j
| jƒS )NrÏ   ú!Last update may only be set once.ú8The last update date must be on or after 1950 January 1.z9The last update date must be before the next update date.)rE   r5   r­   rÖ   r+   r9   rÐ   r×   rÓ   rÁ   r‹   rÔ   )r   r�   r"   r"   r#   r�   ™  s(    
ÿÿûz,CertificateRevocationListBuilder.last_update)r�   r   c                 C   sr   t |tjƒstdƒ‚| jd k	r&tdƒ‚t|ƒ}|tk r>tdƒ‚| jd k	rZ|| jk rZtdƒ‚t| j	| j|| j
| jƒS )NrÏ   rØ   rÙ   z8The next update date must be after the last update date.)rE   r5   r­   r×   r+   r9   rÐ   rÖ   rÓ   rÁ   r‹   rÔ   )r   r�   r"   r"   r#   r�   ±  s(    
ÿÿûz,CertificateRevocationListBuilder.next_updater¯   c                 C   sL   t |tƒstdƒ‚t|j||ƒ}t|| jƒ t| j| j	| j
| j|g | jƒS )zM
        Adds an X.509 extension to the certificate revocation list.
        r²   )rE   r   r­   r   r   r-   r‹   rÓ   rÁ   rÖ   r×   rÔ   r³   r"   r"   r#   r´   É  s    

ûz.CertificateRevocationListBuilder.add_extension)Úrevoked_certificater   c                 C   s2   t |tƒstdƒ‚t| j| j| j| j| j|g ƒS )z8
        Adds a revoked certificate to the CRL.
        z)Must be an instance of RevokedCertificate)	rE   r„   r­   rÓ   rÁ   rÖ   r×   r‹   rÔ   )r   rÚ   r"   r"   r#   Úadd_revoked_certificateÜ  s    

ûz8CertificateRevocationListBuilder.add_revoked_certificater¸   c                 C   sD   | j d krtdƒ‚| jd kr$tdƒ‚| jd kr6tdƒ‚t | ||¡S )NzA CRL must have an issuer namez"A CRL must have a last update timez"A CRL must have a next update time)rÁ   r+   rÖ   r×   rž   Zcreate_x509_crlrº   r"   r"   r#   r»   í  s    


z%CertificateRevocationListBuilder.sign)N)r$   r%   r&   rV   r—   r   r   rÒ   r„   r�   r   r5   r   r¿   r�   r�   rO   r´   rÛ   r   r   r   r½   r�   r»   r"   r"   r"   r#   rÓ   x  sJ   
ú

úþþþ þþ ü
ûrÓ   c                   @   s†   e Zd Zddg feje ejej ejee	  dœdd„Z
ed dœdd„Zejd dœd	d
„Ze	ed dœdd„Zdejedœdd„ZdS )ÚRevokedCertificateBuilderNr‡   c                 C   s   || _ || _|| _d S r   rˆ   rŒ   r"   r"   r#   r      s    z"RevokedCertificateBuilder.__init__rÇ   c                 C   sX   t |tƒstdƒ‚| jd k	r$tdƒ‚|dkr4tdƒ‚| ¡ dkrHtdƒ‚t|| j| jƒS )NrÉ   rÊ   r   z$The serial number should be positiverË   rÌ   )	rE   rL   r­   r‰   r+   rÍ   rÜ   rŠ   r‹   rÎ   r"   r"   r#   rf   
  s    

ÿ  ÿz'RevokedCertificateBuilder.serial_numberr1   c                 C   sN   t |tjƒstdƒ‚| jd k	r&tdƒ‚t|ƒ}|tk r>tdƒ‚t| j|| j	ƒS )NrÏ   z)The revocation date may only be set once.z7The revocation date must be on or after 1950 January 1.)
rE   r5   r­   rŠ   r+   r9   rÐ   rÜ   r‰   r‹   rÑ   r"   r"   r#   r…     s    
ÿ  ÿz)RevokedCertificateBuilder.revocation_dater¯   c                 C   sD   t |tƒstdƒ‚t|j||ƒ}t|| jƒ t| j| j	| j|g ƒS )Nr²   )
rE   r   r­   r   r   r-   r‹   rÜ   r‰   rŠ   r³   r"   r"   r#   r´   ,  s    

ýz'RevokedCertificateBuilder.add_extension)r�   r   c                 C   s:   | j d krtdƒ‚| jd kr$tdƒ‚t| j | jt| jƒƒS )Nz/A revoked certificate must have a serial numberz1A revoked certificate must have a revocation date)r‰   r+   rŠ   r†   r   r‹   )r   r�   r"   r"   r#   Úbuild:  s    

ÿýzRevokedCertificateBuilder.build)N)r$   r%   r&   rV   r�   rL   r5   r—   r   r   r   rf   r…   rO   r´   r½   r„   rÝ   r"   r"   r"   r#   rÜ   ÿ  s"   ü
ü
þ þrÜ   r?   c                   C   s   t  t d¡d¡d? S )Né   Úbigr   )rL   Ú
from_bytesÚosÚurandomr"   r"   r"   r#   Úrandom_serial_numberH  s    rã   )N)N)N)N)N)N)Er}   r5   rá   rV   Zcryptographyr   Z"cryptography.hazmat.bindings._rustr   rž   Zcryptography.hazmat.primitivesr   r   Z)cryptography.hazmat.primitives.asymmetricr   r   r   r	   r
   r   r   Z/cryptography.hazmat.primitives.asymmetric.typesr   r   r   Zcryptography.x509.extensionsr   r   r   r   Zcryptography.x509.namer   r   Zcryptography.x509.oidr   rÐ   Ú	Exceptionr   r—   r-   r¼   rK   r�   rL   r0   r9   r:   rP   ÚEnumr[   r^   ÚABCMetar`   Úregisterr„   r†   r�   rš   r½   rŸ   r¡   r¢   r£   r¤   r¥   r¦   r¾   rÓ   rÜ   rã   r"   r"   r"   r#   Ú<module>   s    $	ýÿû$mtU ÿ þ ÿ þ ÿ þ ÿ þ ÿ þ ÿ þ\ n I