o
    žÀ\q  ã                   @   sÆ   d Z ddlmZmZmZ ddlZddlmZmZm	Z	m
Z
mZmZmZ ddlmZ ddlmZ ddlmZ dd	lmZmZmZmZmZmZmZmZ dd
lmZ dgZdd„ Z dd„ Z!edƒZ"dd„ Z#dS )zL
`cryptography.x509 <https://github.com/pyca/cryptography>`_-specific code.
é    )Úabsolute_importÚdivisionÚprint_functionN)ÚDNSNameÚExtensionOIDÚ	IPAddressÚNameOIDÚObjectIdentifierÚ	OtherNameÚUniformResourceIdentifier)ÚExtensionNotFound)Údecode)Ú	IA5Stringé   )ÚDNS_IDÚCertificateErrorÚ
DNSPatternÚIPAddress_IDÚIPAddressPatternÚ
SRVPatternÚ
URIPatternÚverify_service_identity)ÚSubjectAltNameWarningÚverify_certificate_hostnamec                 C   ó   t t| ƒt|ƒgg d� dS )a   
    Verify whether *certificate* is valid for *hostname*.

    .. note:: Nothing is verified about the *authority* of the certificate;
       the caller must verify that the certificate chains to an appropriate
       trust root themselves.

    :param cryptography.x509.Certificate certificate: A cryptography X509
        certificate object.
    :param unicode hostname: The hostname that *certificate* should be valid
        for.

    :raises service_identity.VerificationError: If *certificate* is not valid
        for *hostname*.
    :raises service_identity.CertificateError: If *certificate* contains
        invalid/unexpected data.

    :returns: ``None``
    ©Úcert_patternsÚobligatory_idsÚoptional_idsN)r   Úextract_idsr   )ÚcertificateÚhostname© r"   ú?/usr/lib/python3/dist-packages/service_identity/cryptography.pyr   &   s
   
ýc                 C   r   )aæ  
    Verify whether *certificate* is valid for *ip_address*.

    .. note:: Nothing is verified about the *authority* of the certificate;
       the caller must verify that the certificate chains to an appropriate
       trust root themselves.

    :param cryptography.x509.Certificate certificate: A cryptography X509
        certificate object.
    :param unicode ip_address: The IP address that *connection* should be valid
        for.  Can be an IPv4 or IPv6 address.

    :raises service_identity.VerificationError: If *certificate* is not valid
        for *ip_address*.
    :raises service_identity.CertificateError: If *certificate* contains
        invalid/unexpected data.

    :returns: ``None``

    .. versionadded:: 18.1.0
    r   N)r   r   r   )r    Ú
ip_addressr"   r"   r#   Úverify_certificate_ip_addressA   s
   
ýr%   z1.3.6.1.5.5.7.8.7c                 C   s  g }z	| j  tj¡}W n	 ty   Y nSw | dd„ |j t¡D ƒ¡ | dd„ |j t	¡D ƒ¡ | dd„ |j t
¡D ƒ¡ |j t¡D ]!}|jtkrft|jƒ\}}t|tƒrb| t| ¡ ƒ¡ qEtdƒ‚qE|sŒdd„ | j tj¡D ƒ}tt|ƒdƒ}dd„ |D ƒ}t d	 |¡t¡ |S )
a  
    Extract all valid IDs from a certificate for service verification.

    If *cert* doesn't contain any identifiers, the ``CN``s are used as DNS-IDs
    as fallback.

    :param cryptography.x509.Certificate cert: The certificate to be dissected.

    :return: List of IDs.
    c                 S   ó   g | ]	}t | d ¡ƒ‘qS ©zutf-8©r   Úencode)Ú.0Únamer"   r"   r#   Ú
<listcomp>u   ó    ÿÿzextract_ids.<locals>.<listcomp>c                 S   r&   r'   )r   r)   )r*   Úurir"   r"   r#   r,   {   r-   c                 S   s   g | ]}t |ƒ‘qS r"   )r   )r*   Úipr"   r"   r#   r,   ƒ   s    ÿÿzUnexpected certificate content.c                 S   s   g | ]}|j ‘qS r"   )Úvalue©r*   Únr"   r"   r#   r,   •   s    ÿÿs   <not given>c                 S   r&   r'   r(   r1   r"   r"   r#   r,   š   s    z°Certificate with CN {!r} has no `subjectAltName`, falling back to check for a `commonName` for now.  This feature is being removed by major browsers and deprecated by RFC 2818.)Ú
extensionsÚget_extension_for_oidr   ÚSUBJECT_ALTERNATIVE_NAMEr   Úextendr0   Úget_values_for_typer   r   r   r
   Útype_idÚID_ON_DNS_SRVr   Ú
isinstancer   Úappendr   ÚasOctetsr   ÚsubjectÚget_attributes_for_oidr   ÚCOMMON_NAMEÚnextÚiterÚwarningsÚwarnÚformatr   )ÚcertÚidsÚextÚotherÚsrvÚ_ÚcnsÚcnr"   r"   r#   r   a   sX   ÿÿ
þÿÿþÿ
þÿ

ûþür   )$Ú__doc__Ú
__future__r   r   r   rB   Úcryptography.x509r   r   r   r   r	   r
   r   Úcryptography.x509.extensionsr   Úpyasn1.codec.der.decoderr   Úpyasn1.type.charr   Ú_commonr   r   r   r   r   r   r   r   Ú
exceptionsr   Ú__all__r   r%   r9   r   r"   r"   r"   r#   Ú<module>   s    $	(
