o
    ¯bw!  ã                	   @   s†  d Z ddlmZmZmZmZ ddlmZmZm	Z	 ddl
mZ G dd„ deƒZG dd„ deƒZG d	d
„ d
eƒZG dd„ deƒZe	eƒG dd„ dƒƒZe	eƒG dd„ dƒƒZe	eƒG dd„ dƒƒZe	eƒG dd„ dƒƒZe	eƒG dd„ dƒƒZe	eƒG dd„ dƒƒZe	eƒG dd„ dƒƒZe	eƒG dd„ dƒƒZeƒ eƒ eƒ eƒ eƒ eƒ eƒ eƒ dœZdd„ Zd d!„ Zd"d#„ Zd$d%„ Zd&d'„ Zd(d)„ Zd*S )+z
SSH key exchange handling.
é    )Úsha1Úsha256Úsha384Úsha512)Ú	AttributeÚ	InterfaceÚimplementer)Úerrorc                   @   ó    e Zd ZdZedƒZedƒZdS )Ú_IKexAlgorithmzB
    An L{_IKexAlgorithm} describes a key exchange algorithm.
    z‹An L{int} giving the preference of the algorithm when negotiating key exchange. Algorithms with lower precedence values are more preferred.zqA callable hash algorithm constructor (e.g. C{hashlib.sha256}) suitable for use with this key exchange algorithm.N)Ú__name__Ú
__module__Ú__qualname__Ú__doc__r   Ú
preferenceÚhashProcessor© r   r   ú8/usr/lib/python3/dist-packages/twisted/conch/ssh/_kex.pyr      s    ÿÿr   c                   @   r
   )Ú_IFixedGroupKexAlgorithmzu
    An L{_IFixedGroupKexAlgorithm} describes a key exchange algorithm with a
    fixed prime / generator group.
    zdAn L{int} giving the prime number used in Diffie-Hellman key exchange, or L{None} if not applicable.z�An L{int} giving the generator number used in Diffie-Hellman key exchange, or L{None} if not applicable. (This is not related to Python generator functions.)N)r   r   r   r   r   ÚprimeÚ	generatorr   r   r   r   r   "   s    ÿÿr   c                   @   ó   e Zd ZdZdS )Ú#_IEllipticCurveExchangeKexAlgorithmzž
    An L{_IEllipticCurveExchangeKexAlgorithm} describes a key exchange algorithm
    that uses an elliptic curve exchange between the client and server.
    N©r   r   r   r   r   r   r   r   r   4   ó    r   c                   @   r   )Ú_IGroupExchangeKexAlgorithmzõ
    An L{_IGroupExchangeKexAlgorithm} describes a key exchange algorithm
    that uses group exchange between the client and server.

    A prime / generator group should be chosen at run time based on the
    requested size. See RFC 4419.
    Nr   r   r   r   r   r   ;   r   r   c                   @   ó   e Zd ZdZdZeZdS )Ú_Curve25519SHA256z”
    Elliptic Curve Key Exchange using Curve25519 and SHA256. Defined in
    U{https://datatracker.ietf.org/doc/draft-ietf-curdle-ssh-curves/}.
    é   N©r   r   r   r   r   r   r   r   r   r   r   r   E   ó    r   c                   @   r   )Ú_Curve25519SHA256LibSSHzN
    As L{_Curve25519SHA256}, but with a pre-standardized algorithm name.
    é   Nr   r   r   r   r   r!   P   s    r!   c                   @   r   )Ú_ECDH256aX  
    Elliptic Curve Key Exchange with SHA-256 as HASH. Defined in
    RFC 5656.

    Note that C{ecdh-sha2-nistp256} takes priority over nistp384 or nistp512.
    This is the same priority from OpenSSH.

    C{ecdh-sha2-nistp256} is considered preety good cryptography.
    If you need something better consider using C{curve25519-sha256}.
    é   Nr   r   r   r   r   r#   Z   s    r#   c                   @   r   )Ú_ECDH384zT
    Elliptic Curve Key Exchange with SHA-384 as HASH. Defined in
    RFC 5656.
    é   N)r   r   r   r   r   r   r   r   r   r   r   r%   k   r    r%   c                   @   r   )Ú_ECDH512zT
    Elliptic Curve Key Exchange with SHA-512 as HASH. Defined in
    RFC 5656.
    é   N)r   r   r   r   r   r   r   r   r   r   r   r'   v   r    r'   c                   @   r   )Ú_DHGroupExchangeSHA256zc
    Diffie-Hellman Group and Key Exchange with SHA-256 as HASH. Defined in
    RFC 4419, 4.2.
    é   Nr   r   r   r   r   r)   �   r    r)   c                   @   r   )Ú_DHGroupExchangeSHA1za
    Diffie-Hellman Group and Key Exchange with SHA-1 as HASH. Defined in
    RFC 4419, 4.1.
    é   N)r   r   r   r   r   r   r   r   r   r   r   r+   Œ   r    r+   c                   @   s$   e Zd ZdZdZeZedƒZdZ	dS )Ú_DHGroup14SHA1z�
    Diffie-Hellman key exchange with SHA-1 as HASH and Oakley Group 14
    (2048-bit MODP Group). Defined in RFC 4253, 8.2.
    é   Ái  32317006071311007300338913926423828248817941241140239112842009751400741706634354222619689417363569347117901737909704191754605873209195028853758986185622153212175412514901774520270235796078236248884246189477587641105928646099411723245426622522193230540919037680524235519125679715870117001058055877651038861847280257976054903569732561526167081339361799541336476559160368317896729073178384589680639671900977202194168647225871031411336429319536193471636533209717077448227988588565369208645296636077250268955505928362751121174096972998068410554359584866583291642136218231078990999448652468262416972035911852507045361090559r"   N)
r   r   r   r   r   r   r   Úintr   r   r   r   r   r   r-   —   s    ÿr-   )ó   curve25519-sha256s   curve25519-sha256@libssh.orgs$   diffie-hellman-group-exchange-sha256s"   diffie-hellman-group-exchange-sha1s   diffie-hellman-group14-sha1s   ecdh-sha2-nistp256s   ecdh-sha2-nistp384s   ecdh-sha2-nistp521c                 C   s    | t vrt d| › �¡‚t |  S )aY  
    Get a description of a named key exchange algorithm.

    @param kexAlgorithm: The key exchange algorithm name.
    @type kexAlgorithm: L{bytes}

    @return: A description of the key exchange algorithm named by
        C{kexAlgorithm}.
    @rtype: L{_IKexAlgorithm}

    @raises ConchError: if the key exchange algorithm is not found.
    z$Unsupported key exchange algorithm: )Ú_kexAlgorithmsr	   Ú
ConchError©ÚkexAlgorithmr   r   r   ÚgetKex¾   s   r6   c                 C   ó   t  t| ƒ¡S )a  
    Returns C{True} if C{kexAlgorithm} is an elliptic curve.

    @param kexAlgorithm: The key exchange algorithm name.
    @type kexAlgorithm: C{str}

    @return: C{True} if C{kexAlgorithm} is an elliptic curve,
        otherwise C{False}.
    @rtype: C{bool}
    )r   Ú
providedByr6   r4   r   r   r   ÚisEllipticCurveÐ   ó   r9   c                 C   r7   )a+  
    Returns C{True} if C{kexAlgorithm} has a fixed prime / generator group.

    @param kexAlgorithm: The key exchange algorithm name.
    @type kexAlgorithm: L{bytes}

    @return: C{True} if C{kexAlgorithm} has a fixed prime / generator group,
        otherwise C{False}.
    @rtype: L{bool}
    )r   r8   r6   r4   r   r   r   ÚisFixedGroupÞ   r:   r;   c                 C   s   t | ƒ}|jS )a  
    Get the hash algorithm callable to use in key exchange.

    @param kexAlgorithm: The key exchange algorithm name.
    @type kexAlgorithm: L{bytes}

    @return: A callable hash algorithm constructor (e.g. C{hashlib.sha256}).
    @rtype: C{callable}
    )r6   r   ©r5   Úkexr   r   r   ÚgetHashProcessorì   s   
r>   c                 C   s   t | ƒ}|j|jfS )zù
    Get the generator and the prime to use in key exchange.

    @param kexAlgorithm: The key exchange algorithm name.
    @type kexAlgorithm: L{bytes}

    @return: A L{tuple} containing L{int} generator and L{int} prime.
    @rtype: L{tuple}
    )r6   r   r   r<   r   r   r   ÚgetDHGeneratorAndPrimeú   s   
r?   c                     s¦   ddl m}  ddlm} ddlm} | ƒ }t ¡ ‰ tˆ ƒD ]+}| 	d¡r5| 
dd¡}| | ¡ || ¡}n| 	d¡r?| ¡ }nd}|sHˆ  |¡ qtˆ ‡ fd	d
„d�S )z½
    Get a list of supported key exchange algorithm names in order of
    preference.

    @return: A C{list} of supported key exchange algorithm names.
    @rtype: C{list} of L{bytes}
    r   )Údefault_backend)Úec)Ú_curveTables   ecdhs   ecdsar1   Tc                    s
   ˆ |  j S )N)r   r4   ©ÚkexAlgorithmsr   r   Ú<lambda>$  s   
 z*getSupportedKeyExchanges.<locals>.<lambda>)Úkey)Úcryptography.hazmat.backendsr@   Ú)cryptography.hazmat.primitives.asymmetricrA   Útwisted.conch.ssh.keysrB   r2   ÚcopyÚlistÚ
startswithÚreplaceÚ+elliptic_curve_exchange_algorithm_supportedÚECDHÚx25519_supportedÚpopÚsorted)r@   rA   rB   ÚbackendÚkeyAlgorithmÚkeyAlgorithmDsaÚ	supportedr   rC   r   ÚgetSupportedKeyExchanges  s(   
ÿ


€ÿrW   N)r   Úhashlibr   r   r   r   Úzope.interfacer   r   r   Útwisted.conchr	   r   r   r   r   r   r!   r#   r%   r'   r)   r+   r-   r2   r6   r9   r;   r>   r?   rW   r   r   r   r   Ú<module>   sN   

	



ø