o
    x[h­"  ã                
   @   sl  U d Z ddlZddlZddlmZmZmZ ddlmZ ddl	m
Z
 ddlmZ ddlmZ e e¡Zddd	d
dgdœZdddddgdœdddddgdœdddddgdœdddddgdœdddddgdœdœZdD ]Zed ee< qhdD ]Zed ee< qsg d¢Zdeed d!gd"œZeed#< d$d%„ Zd&d'„ Zd(d)„ Zd*d+„ Zd,d-„ Zd.d/„ Zd0ed1e
d2ed3ed4df
d5d6„Z dS )7zCA Certs: Add ca certificates.é    N)Ú	lifecycleÚsubpÚutil)ÚCloud)ÚConfig)Ú
MetaSchema)ÚPER_INSTANCEz!/usr/local/share/ca-certificates/z#cloud-init-ca-cert-{cert_index}.crtz/etc/ca-certificates.confzupdate-ca-certificates)Úca_cert_pathÚca_cert_local_pathÚca_cert_filenameÚca_cert_configÚca_cert_update_cmdz/etc/ssl/certs/z#cloud-init-ca-cert-{cert_index}.pemz+/etc/ca-certificates/conf.d/cloud-init.confzupdate-ca-bundlez/etc/pki/ca-trust/z/usr/share/pki/ca-trust-source/z+anchors/cloud-init-ca-cert-{cert_index}.crtzupdate-ca-trustz/etc/pki/trust/z/usr/share/pki/trust/z/etc/pki/tls/certs/zrehash_ca_certificates.sh)ÚaoscÚfedoraÚrhelÚopensuseÚphoton)úopensuse-microosúopensuse-tumbleweedúopensuse-leapÚsle_hpcú	sle-microÚslesr   )Ú	almalinuxÚ
cloudlinuxr   )r   r   r   ÚalpineÚdebianr   r   r   r   r   r   r   r   r   Úubuntur   Úcc_ca_certsÚca_certsúca-certs)ÚidÚdistrosÚ	frequencyÚactivate_by_schema_keysÚmetac                 C   s*   t  | t¡}tj |d |d ¡|d< |S )z²Return a distro-specific ca_certs config dictionary

    @param distro_name: String providing the distro class name.
    @returns: Dict of distro configurations for ca_cert.
    r
   r   Úca_cert_full_path)ÚDISTRO_OVERRIDESÚgetÚDEFAULT_CONFIGÚosÚpathÚjoin)Údistro_nameÚcfg© r/   ú>/usr/lib/python3/dist-packages/cloudinit/config/cc_ca_certs.pyÚ_distro_ca_certs_configsj   s
   ÿr1   c                 C   s   t j | d dd� dS )zŽ
    Updates the CA certificate cache on the current machine.

    @param distro_cfg: A hash providing _distro_ca_certs_configs function.
    r   F)ÚcaptureN)r   ©Ú
distro_cfgr/   r/   r0   Úupdate_ca_certsw   s   r5   c                 C   sH   |sdS t |dƒD ]\}}t|ƒ}| d j|d�}tj||dd� q	dS )a-  
    Adds certificates to the system. To actually apply the new certificates
    you must also call the appropriate distro-specific utility such as
    L{update_ca_certs}.

    @param distro_cfg: A hash providing _distro_ca_certs_configs function.
    @param certs: A list of certificate strings.
    Né   r&   )Ú
cert_indexi¤  )Úmode)Ú	enumerateÚstrÚformatr   Ú
write_file)r4   Úcertsr7   ÚcÚcert_file_contentsÚcert_file_namer/   r/   r0   Úadd_ca_certs€   s   	ÿúrA   c                 C   sJ   | dv r
t |ƒ dS | dv r!t|ƒ | dv r#d}tjd|d� dS dS dS )a.  
    Disables all default trusted CA certificates. For Alpine, Debian and
    Ubuntu to actually apply the changes you must also call
    L{update_ca_certs}.

    @param distro_name: String providing the distro class name.
    @param distro_cfg: A hash providing _distro_ca_certs_configs function.
    )r   r   )r   r   r   r   )r   r   z8ca-certificates ca-certificates/trust_new_crts select no)zdebconf-set-selectionsú-)ÚdataN)Úremove_default_ca_certsÚdisable_system_ca_certsr   )r-   r4   Údebconf_selr/   r/   r0   Údisable_default_ca_certs•   s   	ÿùrG   c                 C   sÆ   | d }|rt j |¡sdS d}d}t  |¡jrat |¡}g }| ¡ D ].}||kr1d}| |¡ q#|dks;|d dv rA| |¡ q#|sJ| |¡ d}| d	| ¡ q#tj	|d
 
|¡d
 dd� dS dS )z¸
    For every entry in the CA_CERT_CONFIG file prefix the entry with a "!"
    in order to disable it.

    @param distro_cfg: A hash providing _distro_ca_certs_configs function.
    r   Nz;# Modified by cloud-init to deselect certs due to user-dataFTÚ r   )ú#ú!rJ   Ú
Úwb)Úomode)r*   r+   ÚexistsÚstatÚst_sizer   Úload_text_fileÚ
splitlinesÚappendr<   r,   )r4   Úca_cert_cfg_fnÚheader_commentÚadded_headerÚorigÚ	out_linesÚliner/   r/   r0   rE   ª   s.   ÿ


ÿñrE   c                 C   s:   | d du rdS t  d¡ t | d ¡ t | d ¡ dS )z’
    Removes all default trusted CA certificates from the system.

    @param distro_cfg: A hash providing _distro_ca_certs_configs function.
    r	   NzDeleting system CA certificatesr
   )ÚLOGÚdebugr   Údelete_dir_contentsr3   r/   r/   r0   rD   Ñ   s
   
rD   Únamer.   ÚcloudÚargsÚreturnc                 C   sö   d|v rt jdddd� nd|vrt d| ¡ dS d|v r&d|v r&t d	¡ | d| d¡¡}t|jjƒ}d
|v rAt jdddd� | d| d
d¡¡rWt d¡ t	|jj|ƒ d|v rpt
 |d¡}|rpt dt|ƒ¡ t||ƒ t d¡ t|ƒ dS )au  
    Call to handle ca_cert sections in cloud-config file.

    @param name: The module name "ca_cert" from cloud.cfg
    @param cfg: A nested dict containing the entire cloud config contents.
    @param cloud: The L{CloudInit} object in use.
    @param log: Pre-initialized Python logger object to use for logging.
    @param args: Any module arguments from cloud.cfg
    r    zKey 'ca-certs'z22.1zUse 'ca_certs' instead.)Ú
deprecatedÚdeprecated_versionÚextra_messager   z<Skipping module named %s, no 'ca_certs' key in configurationNzMFound both ca-certs (deprecated) and ca_certs config keys. Ignoring ca-certs.zremove-defaultszKey 'remove-defaults'zUse 'remove_defaults' instead.Úremove_defaultsFz'Disabling/removing default certificatesÚtrustedzAdding %d certificateszUpdating certificates)r   Ú	deprecaterZ   r[   Úwarningr(   r1   Údistror]   rG   r   Úget_cfg_option_listÚlenrA   r5   )r]   r.   r^   r_   Úca_cert_cfgr4   Útrusted_certsr/   r/   r0   Úhandleß   sH   
ýþÿýÿ


rm   )!Ú__doc__Úloggingr*   Ú	cloudinitr   r   r   Úcloudinit.cloudr   Úcloudinit.configr   Úcloudinit.config.schemar   Úcloudinit.settingsr   Ú	getLoggerÚ__name__rZ   r)   r'   rh   r"   r%   Ú__annotations__r1   r5   rA   rG   rE   rD   r:   Úlistrm   r/   r/   r/   r0   Ú<module>   s~   
û	ûûûûûã&ü	'"