U
    ÓZj	`  ã                   @   s   d Z ddlZddlmZ ddlmZmZmZ ddlm	Z	 ddl
mZ ddlmZmZmZ ddlmZ ed	d
ƒ\ZZZZZeddƒ\ZZdd„ ed	d
ƒD ƒ\ZZZZZdd„ eddƒD ƒ\ZZ G dd„ de!ƒZ"G dd„ de"ƒZ#G dd„ de!ƒZ$G dd„ de!ƒZ%dS )aõ  
This module provides GSS-API / SSPI Key Exchange as defined in :rfc:`4462`.

.. note:: Credential delegation is not supported in server mode.

.. note::
    `RFC 4462 Section 2.2
    <https://tools.ietf.org/html/rfc4462.html#section-2.2>`_ says we are not
    required to implement GSS-API error messages. Thus, in many methods within
    this module, if an error occurs an exception will be thrown and the
    connection will be terminated.

.. seealso:: :doc:`/api/ssh_gss`

.. versionadded:: 1.15
é    N)Úsha1)ÚDEBUGÚmax_byteÚ	zero_byte)Úutil)ÚMessage)Úbyte_chrÚ	byte_maskÚbyte_ord)ÚSSHExceptioné   é#   é(   é*   c                 C   s   g | ]}t |ƒ‘qS © ©r   ©Ú.0Úcr   r   úS/var/www/html/TRUCKING_PROJECT/venv/lib/python3.8/site-packages/paramiko/kex_gss.pyÚ
<listcomp>@   s     r   c                 C   s   g | ]}t |ƒ‘qS r   r   r   r   r   r   r   A   s    c                   @   s|   e Zd ZdZdZdZedƒed  Ze	d Z
dZdd	„ Zd
d„ Zdd„ Zdd„ Zdd„ Zdd„ Zdd„ Zdd„ Zdd„ ZdS )ÚKexGSSGroup1zŸ
    GSS-API / SSPI Authenticated Diffie-Hellman Key Exchange as defined in `RFC
    4462 Section 2 <https://tools.ietf.org/html/rfc4462.html#section-2>`_
    lE   ÿÿÿÿ8Ê{3If?ñE yéZô3¢Vý58nÛoP·eõ?a-ûÓtBLèûy3W[�<‘p¨6m5ÂÝPøß&aÌF!Í33*¾w& ãAR‘M;L}. c|&A“@”h\Š&&#-D¨v‡dÿÿÿÿ é   é   é   é   z(gss-group1-sha1-toWM5Slw5Ew8Mqkay+al2g==c                 C   s,   || _ | j j| _d | _d| _d| _d| _d S )Nr   )Ú	transportÚkexgss_ctxtÚkexgssÚgss_hostÚxÚeÚf©Úselfr   r   r   r   Ú__init__S   s    
zKexGSSGroup1.__init__c                 C   s¦   |   ¡  | jjr4t| j| j| jƒ| _| j t	¡ dS t| j| j| jƒ| _
| jj| _tƒ }| t¡ | | jj| jd�¡ | | j
¡ | j |¡ | j tttt¡ dS )zU
        Start the GSS-API / SSPI Authenticated Diffie-Hellman Key Exchange.
        N©Útarget)Ú_generate_xr   Úserver_modeÚpowÚGr    ÚPr"   Ú_expect_packetÚMSG_KEXGSS_INITr!   r   r   Úadd_byteÚc_MSG_KEXGSS_INITÚ
add_stringr   Ússh_init_sec_contextÚ	add_mpintÚ_send_messageÚMSG_KEXGSS_HOSTKEYÚMSG_KEXGSS_CONTINUEÚMSG_KEXGSS_COMPLETEÚMSG_KEXGSS_ERROR©r$   Úmr   r   r   Ú	start_kex[   s$    

üzKexGSSGroup1.start_kexc                 C   s�   | j jr|tkr|  |¡S | j js4|tkr4|  |¡S | j jrN|tkrN|  |¡S | j jsh|tkrh|  	|¡S |t
krz|  |¡S d}t| |¡ƒ‚dS )ú—
        Parse the next packet.

        :param ptype: The (string) type of the incoming packet
        :param `.Message` m: The paket content
        z.GSS KexGroup1 asked to handle packet type {:d}N)r   r)   r.   Ú_parse_kexgss_initr5   Ú_parse_kexgss_hostkeyr6   Ú_parse_kexgss_continuer7   Ú_parse_kexgss_completer8   Ú_parse_kexgss_errorr   Úformat©r$   Úptyper:   Úmsgr   r   r   Ú
parse_nextu   s    




zKexGSSGroup1.parse_nextc                 C   sT   t  d¡}t|d dƒ|dd…  }|dd… }|| j| jfkr qDq t |¡| _dS )ap  
        generate an "x" (1 < x < q), where q is (p-1)/2.
        p is a 128-byte (1024-bit) number, where the first 64 bits are 1.
        therefore q can be approximated as a 2^1023.  we drop the subset of
        potential x where the first 63 bits are 1, because some of those will
        be larger than q (but this is a tiny tiny subset of potential x).
        é€   r   r   é   Nr   )ÚosÚurandomr	   Úb7fffffffffffffffÚb0000000000000000r   Úinflate_longr    )r$   Úx_bytesÚfirstr   r   r   r(   ‹   s    	
zKexGSSGroup1._generate_xc                 C   s8   |  ¡ }|| j_|  ¡ }| j ||¡ | j tt¡ dS )z›
        Parse the SSH2_MSG_KEXGSS_HOSTKEY message (client mode).

        :param `.Message` m: The content of the SSH2_MSG_KEXGSS_HOSTKEY message
        N©Ú
get_stringr   Úhost_keyZ_verify_keyr-   r6   r7   ©r$   r:   rR   Úsigr   r   r   r>   ›   s
    z"KexGSSGroup1._parse_kexgss_hostkeyc                 C   sZ   | j jsV| ¡ }tƒ }| t¡ | | jj| j	|d�¡ | j  
|¡ | j  ttt¡ n dS )z›
        Parse the SSH2_MSG_KEXGSS_CONTINUE message.

        :param `.Message` m: The content of the SSH2_MSG_KEXGSS_CONTINUE
            message
        ©r'   Z
recv_tokenN©r   r)   rQ   r   r/   Úc_MSG_KEXGSS_CONTINUEr1   r   r2   r   Úsend_messager-   r6   r7   r8   ©r$   r:   Ú	srv_tokenr   r   r   r?   ¨   s"    
 ÿÿ  ÿz#KexGSSGroup1._parse_kexgss_continuec                 C   s<  | j jdkrtƒ | j _| ¡ | _| jdk s:| j| jd krBtdƒ‚| ¡ }| ¡ }d}|rb| ¡ }t	| j| j
| jƒ}tƒ }| | j j| j j| j j| j j¡ | | j j ¡ ¡ | | j¡ | | j¡ | |¡ tt|ƒƒ ¡ }| j  ||¡ |dk	�r| jj| j|d� | j ||¡ n| j ||¡ d| j _| j  ¡  dS )z©
        Parse the SSH2_MSG_KEXGSS_COMPLETE message (client mode).

        :param `.Message` m: The content of the
            SSH2_MSG_KEXGSS_COMPLETE message
        NrH   úServer kex "f" is out of rangerU   T)r   rR   ÚNullHostKeyÚ	get_mpintr"   r,   r   rQ   Úget_booleanr*   r    r   ÚaddÚlocal_versionÚremote_versionÚlocal_kex_initÚremote_kex_initr1   Ú__str__r3   r!   r   ÚstrÚdigestÚ_set_K_Hr   r2   r   Ússh_check_micÚgss_kex_usedÚ_activate_outbound©r$   r:   Ú	mic_tokenÚboolrZ   ÚKÚhmÚHr   r   r   r@   ¿   sB    

ü

 ÿz#KexGSSGroup1._parse_kexgss_completec           	      C   sž  |  ¡ }| ¡ | _| jdk s,| j| jd kr4tdƒ‚t| j| j| jƒ}tƒ | j_	| jj	 
¡ }tƒ }| | jj| jj| jj| jj¡ | |¡ | | j¡ | | j¡ | |¡ t| ¡ ƒ ¡ }| j ||¡ | j | j|¡}tƒ }| jj�rj| jj| jjdd�}| t¡ | | j¡ | |¡ |dk	�r@|  d¡ | |¡ n
|  d¡ | j !|¡ d| j_"| j #¡  n0| t$¡ | |¡ | j !|¡ | j %t&t't(¡ dS )z•
        Parse the SSH2_MSG_KEXGSS_INIT message (server mode).

        :param `.Message` m: The content of the SSH2_MSG_KEXGSS_INIT message
        rH   úClient kex "e" is out of rangeT©Zgss_kexNF))rQ   r]   r!   r,   r   r*   r    r\   r   rR   rd   r   r_   ra   r`   rc   rb   r1   r3   r"   r   Úasbytesrf   rg   r   Ússh_accept_sec_contextr   Ú_gss_srv_ctxt_statusÚssh_get_micÚ
session_idr/   Úc_MSG_KEXGSS_COMPLETEÚadd_booleanr4   ri   rj   rW   r-   r6   r7   r8   ©	r$   r:   Zclient_tokenrn   Úkeyro   rp   rZ   rl   r   r   r   r=   ì   s`    

ü

 ÿ
 ÿ






  ÿzKexGSSGroup1._parse_kexgss_initc                 C   s6   |  ¡ }|  ¡ }| ¡ }| ¡  td |||¡ƒ‚dS )aÝ  
        Parse the SSH2_MSG_KEXGSS_ERROR message (client mode).
        The server may send a GSS-API error message. if it does, we display
        the error by throwing an exception (client mode).

        :param `.Message` m: The content of the SSH2_MSG_KEXGSS_ERROR message
        :raise SSHException: Contains GSS-API major and minor status as well as
                             the error message and the language tag of the
                             message
        úCGSS-API Error:
Major Status: {}
Minor Status: {}
Error Message: {}
N©Úget_intrQ   r   rB   ©r$   r:   Z
maj_statusZ
min_statusÚerr_msgr   r   r   rA   $  s      ûÿz KexGSSGroup1._parse_kexgss_errorN)Ú__name__Ú
__module__Ú__qualname__Ú__doc__r,   r+   r   r   rK   r   rL   ÚNAMEr%   r;   rF   r(   r>   r?   r@   r=   rA   r   r   r   r   r   F   s   -8r   c                   @   s   e Zd ZdZdZdZdZdS )ÚKexGSSGroup14z«
    GSS-API / SSPI Authenticated Diffie-Hellman Group14 Key Exchange as defined
    in `RFC 4462 Section 2
    <https://tools.ietf.org/html/rfc4462.html#section-2>`_
    l‰   ÿÿÿÿ�&•U¢G9
tcb0]Q\-¥:¾$•90.`U´_¼b;YS7x]EkŠ`:xds€!,w<Gï8¶qbdR_ÊØhÅÀd«d©ÃY6K–pRT{ÜUÄj¼K­#¹Gt|õL¤ê‹4šS«8Ø ÒFYpw,(.> Â=¶H³G2C’düc_Ÿ.K?&jÚ_†c½}­z[\Vµ_1M.D‰^±/1v5I	ŽjÖV&|ÓŠ/òmVÀlRÓ<6#å{n4ó(EY91ÇTï:Ìg8	H	ÍAp¢cb4BÑBˆj~Hüÿÿÿÿ r   z)gss-group14-sha1-toWM5Slw5Ew8Mqkay+al2g==N)r�   r‚   rƒ   r„   r,   r+   r…   r   r   r   r   r†   >  s   r†   c                   @   sx   e Zd ZdZdZdZdZdZdd„ Zdd	„ Z	d
d„ Z
dd„ Zdd„ Zdd„ Zdd„ Zdd„ Zdd„ Zdd„ Zdd„ ZdS )Ú	KexGSSGexz¡
    GSS-API / SSPI Authenticated Diffie-Hellman Group Exchange as defined in
    `RFC 4462 Section 2 <https://tools.ietf.org/html/rfc4462.html#section-2>`_
    z%gss-gex-sha1-toWM5Slw5Ew8Mqkay+al2g==é   é    i   c                 C   sD   || _ | j j| _d | _d | _d | _d | _d | _d | _d | _	d| _
d S )NF)r   r   r   r   ÚpÚqÚgr    r!   r"   Ú	old_styler#   r   r   r   r%   U  s    
zKexGSSGex.__init__c                 C   sr   | j jr| j  t¡ dS | j j| _tƒ }| t¡ | | j	¡ | | j
¡ | | j¡ | j  |¡ | j  t¡ dS )zV
        Start the GSS-API / SSPI Authenticated Diffie-Hellman Group Exchange
        N)r   r)   r-   ÚMSG_KEXGSS_GROUPREQr   r   r/   Úc_MSG_KEXGSS_GROUPREQÚadd_intÚmin_bitsÚpreferred_bitsÚmax_bitsr4   ÚMSG_KEXGSS_GROUPr9   r   r   r   r;   a  s    

zKexGSSGex.start_kexc                 C   s”   |t kr|  |¡S |tkr$|  |¡S |tkr6|  |¡S |tkrH|  |¡S |tkrZ|  	|¡S |t
krl|  |¡S |tkr~|  |¡S d}t| |¡ƒ‚dS )r<   z'KexGex asked to handle packet type {:d}N)rŽ   Ú_parse_kexgss_groupreqr”   Ú_parse_kexgss_groupr.   Ú_parse_kexgss_gex_initr5   r>   r6   r?   r7   r@   r8   rA   r   rB   rC   r   r   r   rF   t  s     






zKexGSSGex.parse_nextc                 C   sš   | j d d }t |d¡}t|d ƒ}t|ƒ}d}|d@ sL|dK }|dL }q2t |¡}t|d |ƒ|dd …  }t |d¡}|dkrL||k rLq�qL|| _	d S )NrH   r   r   éÿ   rG   )
rŠ   r   Zdeflate_longr
   ÚlenrI   rJ   r	   rM   r    )r$   r‹   ZqnormZqhbyteZ
byte_countZqmaskrN   r    r   r   r   r(   Ž  s    

zKexGSSGex._generate_xc                 C   sî   |  ¡ }|  ¡ }|  ¡ }|| jkr(| j}|| jk r8| j}||krD|}||k rP|}|| _|| _|| _| j ¡ }|dkr|tdƒ‚| j td 	|||¡¡ | 
|||¡\| _| _tƒ }| t¡ | | j¡ | | j¡ | j |¡ | j t¡ dS )z©
        Parse the SSH2_MSG_KEXGSS_GROUPREQ message (server mode).

        :param `.Message` m: The content of the
            SSH2_MSG_KEXGSS_GROUPREQ message
        Nz-Can't do server-side gex with no modulus packzPicking p ({} <= {} <= {} bits))r~   r“   r‘   r’   r   Z_get_modulus_packr   Ú_logr   rB   Zget_modulusrŒ   rŠ   r   r/   Úc_MSG_KEXGSS_GROUPr3   r4   r-   r.   )r$   r:   ZminbitsZpreferredbitsZmaxbitsÚpackr   r   r   r•      s@    


  ÿþ
z KexGSSGex._parse_kexgss_groupreqc                 C   sÂ   |  ¡ | _|  ¡ | _t | j¡}|dk s0|dkr>td |¡ƒ‚| j t	d |¡¡ |  
¡  t| j| j| jƒ| _tƒ }| t¡ | | jj| jd�¡ | | j¡ | j |¡ | j tttt¡ dS )z–
        Parse the SSH2_MSG_KEXGSS_GROUP message (client mode).

        :param `Message` m: The content of the SSH2_MSG_KEXGSS_GROUP message
        rˆ   r‰   z<Server-generated gex p (don't ask) is out of range ({} bits)zGot server p ({} bits)r&   N)r]   rŠ   rŒ   r   Ú
bit_lengthr   rB   r   rš   r   r(   r*   r    r!   r   r/   r0   r1   r   r2   r   r3   r4   r-   r5   r6   r7   r8   )r$   r:   Zbitlenr   r   r   r–   Ì  s4    

ÿÿ ÿ
üzKexGSSGex._parse_kexgss_groupc           	      C   sî  |  ¡ }| ¡ | _| jdk s,| j| jd kr4tdƒ‚|  ¡  t| j| j| jƒ| _	t| j| j| jƒ}t
ƒ | j_| jj ¡ }tƒ }| | jj| jj| jj| jj|¡ | | j¡ | | j¡ | | j¡ | | j¡ | | j¡ | | j¡ | | j	¡ | |¡ t| ¡ ƒ ¡ }| j ||¡ | j | j|¡}tƒ }| jj �rº| jj!| jj"dd�}| #t$¡ | | j	¡ | %|¡ |dk	�r�| &d¡ | %|¡ n
| &d¡ | j '|¡ d| j_(| j )¡  n0| #t*¡ | %|¡ | j '|¡ | j +t,t-t.¡ dS )z”
        Parse the SSH2_MSG_KEXGSS_INIT message (server mode).

        :param `Message` m: The content of the SSH2_MSG_KEXGSS_INIT message
        rH   rq   Trr   NF)/rQ   r]   r!   rŠ   r   r(   r*   rŒ   r    r"   r\   r   rR   rd   r   r_   ra   r`   rc   rb   r�   r‘   r’   r“   r3   r   rs   rf   rg   r   rt   r   ru   rv   rw   r/   rx   r1   ry   r4   ri   rj   rW   r-   r6   r7   r8   rz   r   r   r   r—   í  sn    

û
 ÿ
 ÿ






  ÿz KexGSSGex._parse_kexgss_gex_initc                 C   s8   |  ¡ }|| j_|  ¡ }| j ||¡ | j tt¡ dS )zš
        Parse the SSH2_MSG_KEXGSS_HOSTKEY message (client mode).

        :param `Message` m: The content of the SSH2_MSG_KEXGSS_HOSTKEY message
        NrP   rS   r   r   r   r>   +  s
    zKexGSSGex._parse_kexgss_hostkeyc                 C   sZ   | j jsV| ¡ }tƒ }| t¡ | | jj| j	|d�¡ | j  
|¡ | j  ttt¡ n dS )zŽ
        Parse the SSH2_MSG_KEXGSS_CONTINUE message.

        :param `Message` m: The content of the SSH2_MSG_KEXGSS_CONTINUE message
        rU   NrV   rY   r   r   r   r?   8  s"    
 ÿÿ  ÿz KexGSSGex._parse_kexgss_continuec                 C   s|  | j jdkrtƒ | j _| ¡ | _| ¡ }| ¡ }d}|r@| ¡ }| jdk sZ| j| jd krbtdƒ‚t	| j| j
| jƒ}tƒ }| | j j| j j| j j| j j| j j ¡ ¡ | js¶| | j¡ | | j¡ | jsÔ| | j¡ | | j¡ | | j¡ | | j¡ | | j¡ | |¡ t| ¡ ƒ ¡ }| j  ||¡ |dk	�rX| jj| j |d� | j !||¡ n| j !||¡ d| j _"| j  #¡  dS )zœ
        Parse the SSH2_MSG_KEXGSS_COMPLETE message (client mode).

        :param `Message` m: The content of the SSH2_MSG_KEXGSS_COMPLETE message
        NrH   r[   rU   T)$r   rR   r\   r]   r"   rQ   r^   rŠ   r   r*   r    r   r_   r`   ra   rb   rc   rd   r�   r�   r‘   r’   r“   r3   rŒ   r!   r   rs   rf   rg   r   r2   r   rh   ri   rj   rk   r   r   r   r@   N  sP    


û

 ÿz KexGSSGex._parse_kexgss_completec                 C   s6   |  ¡ }|  ¡ }| ¡ }| ¡  td |||¡ƒ‚dS )aÝ  
        Parse the SSH2_MSG_KEXGSS_ERROR message (client mode).
        The server may send a GSS-API error message. if it does, we display
        the error by throwing an exception (client mode).

        :param `Message` m:  The content of the SSH2_MSG_KEXGSS_ERROR message
        :raise SSHException: Contains GSS-API major and minor status as well as
                             the error message and the language tag of the
                             message
        r|   Nr}   r   r   r   r   rA   €  s      ûÿzKexGSSGex._parse_kexgss_errorN)r�   r‚   rƒ   r„   r…   r‘   r“   r’   r%   r;   rF   r(   r•   r–   r—   r>   r?   r@   rA   r   r   r   r   r‡   J  s    ,!>2r‡   c                   @   s(   e Zd ZdZdd„ Zdd„ Zdd„ ZdS )	r\   z«
    This class represents the Null Host Key for GSS-API Key Exchange as defined
    in `RFC 4462 Section 5
    <https://tools.ietf.org/html/rfc4462.html#section-5>`_
    c                 C   s
   d| _ d S )NÚ ©r{   ©r$   r   r   r   r%   ¡  s    zNullHostKey.__init__c                 C   s   | j S ©NrŸ   r    r   r   r   rd   ¤  s    zNullHostKey.__str__c                 C   s   | j S r¡   rŸ   r    r   r   r   Úget_name§  s    zNullHostKey.get_nameN)r�   r‚   rƒ   r„   r%   rd   r¢   r   r   r   r   r\   š  s   r\   )&r„   rI   Úhashlibr   Zparamiko.commonr   r   r   Zparamikor   Zparamiko.messager   Zparamiko.py3compatr   r	   r
   Zparamiko.ssh_exceptionr   Úranger.   r6   r7   r5   r8   rŽ   r”   r0   rW   rx   Zc_MSG_KEXGSS_HOSTKEYZc_MSG_KEXGSS_ERRORr�   r›   Úobjectr   r†   r‡   r\   r   r   r   r   Ú<module>   s@   	úúÿ
 y  R