o
    �À\"  ã                   @   s¶   d Z ddlmZmZmZ ddlZddlZddlmZ ddl	m
Z
 ddlmZ ddlmZ dd	lmZmZmZmZmZmZmZmZ dd
lmZ dgZdd„ Zdd„ ZedƒZdd„ ZdS )zA
`pyOpenSSL <https://github.com/pyca/pyopenssl>`_-specific code.
é    )Úabsolute_importÚdivisionÚprint_functionN)Údecode)Ú	IA5String)ÚObjectIdentifier)ÚGeneralNamesé   )ÚDNS_IDÚCertificateErrorÚ
DNSPatternÚIPAddress_IDÚIPAddressPatternÚ
SRVPatternÚ
URIPatternÚverify_service_identity)ÚSubjectAltNameWarningÚverify_hostnamec                 C   ó    t t|  ¡ ƒt|ƒgg d� dS )a?  
    Verify whether the certificate of *connection* is valid for *hostname*.

    :param OpenSSL.SSL.Connection connection: A pyOpenSSL connection object.
    :param unicode hostname: The hostname that *connection* should be connected
        to.

    :raises service_identity.VerificationError: If *connection* does not
        provide a certificate that is valid for *hostname*.
    :raises service_identity.CertificateError: If the certificate chain of
        *connection* contains a certificate that contains invalid/unexpected
        data.

    :returns: ``None``
    ©Úcert_patternsÚobligatory_idsÚoptional_idsN)r   Úextract_idsÚget_peer_certificater
   )Ú
connectionÚhostname© r   ú</usr/lib/python3/dist-packages/service_identity/pyopenssl.pyr       s
   

ýc                 C   r   )a†  
    Verify whether the certificate of *connection* is valid for *ip_address*.

    :param OpenSSL.SSL.Connection connection: A pyOpenSSL connection object.
    :param unicode ip_address: The IP address that *connection* should be
        connected to.  Can be an IPv4 or IPv6 address.

    :raises service_identity.VerificationError: If *connection* does not
        provide a certificate that is valid for *ip_address*.
    :raises service_identity.CertificateError: If the certificate chain of
        *connection* contains a certificate that contains invalid/unexpected
        data.

    :returns: ``None``

    .. versionadded:: 18.1.0
    r   N)r   r   r   r   )r   Ú
ip_addressr   r   r   Úverify_ip_address7   s
   

ýr    z1.3.6.1.5.5.7.8.7c                 C   sp  g }t j |  ¡ ¡D ]‚}|  |¡}| ¡ dkrŒt| ¡ tƒ d�\}}|D ]g}| 	¡ }|dkr:| 
t| ¡  ¡ ƒ¡ q$|dkrK| 
t | ¡  ¡ ¡¡ q$|dkr[| 
t| ¡  ¡ ƒ¡ q$|dkrŠ| ¡ }| d¡}	|	tkrˆt| d¡ƒ\}
}t|
tƒr„| 
t|
 ¡ ƒ¡ q$td	ƒ‚	 q$	 q$q
|s¶d
d„ |  ¡  ¡ D ƒ}tt|ƒdƒ}dd„ |D ƒ}tjd| d¡f tdd� |S )a  
    Extract all valid IDs from a certificate for service verification.

    If *cert* doesn't contain any identifiers, the ``CN``s are used as DNS-IDs
    as fallback.

    :param OpenSSL.SSL.X509 cert: The certificate to be dissected.

    :return: List of IDs.
    s   subjectAltName)Úasn1SpecÚdNSNameÚ	iPAddressÚuniformResourceIdentifierÚ	otherNamer   r	   zUnexpected certificate content.c                 S   s    g | ]}|d  dkr|d ‘qS )r   s   CNr	   r   ©Ú.0Úcr   r   r   Ú
<listcomp>„   s    zextract_ids.<locals>.<listcomp>s   <not given>c                 S   s   g | ]}t |ƒ‘qS r   )r   r&   r   r   r   r)   ˆ   s    zîCertificate with CN '%s' has no `subjectAltName`, falling back to check for a `commonName` for now.  This feature is being removed by major browsers and deprecated by RFC 2818.  service_identity will remove the support for it in mid-2018.zutf-8é   )Ú
stacklevel)ÚsixÚmovesÚrangeÚget_extension_countÚget_extensionÚget_short_namer   Úget_datar   ÚgetNameÚappendr   ÚgetComponentÚasOctetsr   Ú
from_bytesr   ÚgetComponentByPositionÚID_ON_DNS_SRVÚ
isinstancer   r   r   Úget_subjectÚget_componentsÚnextÚiterÚwarningsÚwarnr   )ÚcertÚidsÚiÚextÚnamesÚ_ÚnÚname_stringÚcompÚoidÚsrvÚ
componentsÚcnr   r   r   r   S   sX   

ÿÿ

ÿ€
ÿ
üù	r   )Ú__doc__Ú
__future__r   r   r   r?   r,   Úpyasn1.codec.der.decoderr   Úpyasn1.type.charr   Úpyasn1.type.univr   Úpyasn1_modules.rfc2459r   Ú_commonr
   r   r   r   r   r   r   r   Ú
exceptionsr   Ú__all__r   r    r9   r   r   r   r   r   Ú<module>   s    (
