o
    îRµi0n  ã                   @   sJ  d dl Z d dlZd dlZd dlZd dlmZ d dlmZmZ d dl	m
Z
 d dlmZmZ d dlmZmZmZmZmZ d dlmZmZmZ d dlmZ d d	lmZ e d
dd¡ZG dd„ deƒZdedeje fdd„Z dedejej!ee"f  fdd„Z#dejdejfdd„Z$G dd„ dej%ƒZ&G dd„ deƒZ'G dd„ de j(d �Z)G d!d"„ d"e j(d �Z*G d#d$„ d$e j(d �Z+G d%d&„ d&e j(d �Z,d>d'e"de)fd(d)„Z-d>d'e"de)fd*d+„Z.d>d'e"de,fd,d-„Z/d>d'e"de,fd.d/„Z0d>d'e"de+fd0d1„Z1d>d'e"de+fd2d3„Z2G d4d5„ d5e3ƒZ4G d6d7„ d7e3ƒZ5G d8d9„ d9e3ƒZ6G d:d;„ d;e3ƒZ7de8fd<d=„Z9dS )?é    N)Úutils)Ú_PRIVATE_KEY_TYPESÚ_PUBLIC_KEY_TYPES)Ú_get_backend)ÚhashesÚserialization)ÚdsaÚecÚed25519Úed448Úrsa)Ú	ExtensionÚExtensionTypeÚ
Extensions)ÚName)ÚObjectIdentifieriž  é   c                       ó   e Zd Z‡ fdd„Z‡  ZS )ÚAttributeNotFoundc                    ó   t t| ƒ |¡ || _d S ©N)Úsuperr   Ú__init__Úoid)ÚselfÚmsgr   ©Ú	__class__© ú8/usr/lib/python3/dist-packages/cryptography/x509/base.pyr      ó   
zAttributeNotFound.__init__©Ú__name__Ú
__module__Ú__qualname__r   Ú__classcell__r   r   r   r   r      ó    r   Ú	extensionÚ
extensionsc                 C   s"   |D ]}|j | j krtdƒ‚qd S )Nz$This extension has already been set.)r   Ú
ValueError)r'   r(   Úer   r   r   Ú_reject_duplicate_extension$   s
   ÿÿr+   r   Ú
attributesc                 C   s"   |D ]\}}|| krt dƒ‚qd S )Nz$This attribute has already been set.)r)   )r   r,   Úattr_oidÚ_r   r   r   Ú_reject_duplicate_attribute-   s
   ÿÿr/   ÚtimeÚreturnc                 C   s6   | j dur|  ¡ }|r|nt ¡ }| jdd�| S | S )z’Normalizes a datetime to a naive datetime in UTC.

    time -- datetime to normalize. Assumed to be in UTC if not timezone
            aware.
    N)Útzinfo)r2   Ú	utcoffsetÚdatetimeÚ	timedeltaÚreplace)r0   Úoffsetr   r   r   Ú_convert_to_naive_utc_time7   s
   
r8   c                   @   s   e Zd ZdZdZdS )ÚVersionr   é   N)r"   r#   r$   Úv1Úv3r   r   r   r   r9   E   s    r9   c                       r   )ÚInvalidVersionc                    r   r   )r   r=   r   Úparsed_version)r   r   r>   r   r   r   r   K   r    zInvalidVersion.__init__r!   r   r   r   r   r=   J   r&   r=   c                   @   s€  e Zd Zejdejdefdd„ƒZej	de
fdd„ƒZej	defdd„ƒZejdefd	d
„ƒZej	dejfdd„ƒZej	dejfdd„ƒZej	defdd„ƒZej	defdd„ƒZej	dejej fdd„ƒZej	defdd„ƒZej	defdd„ƒZej	defdd„ƒZej	defdd„ƒZejdede fdd„ƒZ!ejdede fd d!„ƒZ"ejde
fd"d#„ƒZ#ejd$e$j%defd%d&„ƒZ&d'S )(ÚCertificateÚ	algorithmr1   c                 C   ó   dS ©z4
        Returns bytes using digest passed.
        Nr   ©r   r@   r   r   r   ÚfingerprintQ   ó    zCertificate.fingerprintc                 C   rA   )z3
        Returns certificate serial number
        Nr   ©r   r   r   r   Úserial_numberW   rE   zCertificate.serial_numberc                 C   rA   )z1
        Returns the certificate version
        Nr   rF   r   r   r   Úversion]   rE   zCertificate.versionc                 C   rA   ©z(
        Returns the public key
        Nr   rF   r   r   r   Ú
public_keyc   rE   zCertificate.public_keyc                 C   rA   )z?
        Not before time (represented as UTC datetime)
        Nr   rF   r   r   r   Únot_valid_beforei   rE   zCertificate.not_valid_beforec                 C   rA   )z>
        Not after time (represented as UTC datetime)
        Nr   rF   r   r   r   Únot_valid_aftero   rE   zCertificate.not_valid_afterc                 C   rA   )z1
        Returns the issuer name object.
        Nr   rF   r   r   r   Úissueru   rE   zCertificate.issuerc                 C   rA   ©z2
        Returns the subject name object.
        Nr   rF   r   r   r   Úsubject{   rE   zCertificate.subjectc                 C   rA   ©zt
        Returns a HashAlgorithm corresponding to the type of the digest signed
        in the certificate.
        Nr   rF   r   r   r   Úsignature_hash_algorithm�   rE   z$Certificate.signature_hash_algorithmc                 C   rA   ©zJ
        Returns the ObjectIdentifier of the signature algorithm.
        Nr   rF   r   r   r   Úsignature_algorithm_oidŠ   rE   z#Certificate.signature_algorithm_oidc                 C   rA   )z/
        Returns an Extensions object.
        Nr   rF   r   r   r   r(   �   rE   zCertificate.extensionsc                 C   rA   ©z.
        Returns the signature bytes.
        Nr   rF   r   r   r   Ú	signature–   rE   zCertificate.signaturec                 C   rA   )zR
        Returns the tbsCertificate payload bytes as defined in RFC 5280.
        Nr   rF   r   r   r   Útbs_certificate_bytesœ   rE   z!Certificate.tbs_certificate_bytesÚotherc                 C   rA   ©z"
        Checks equality.
        Nr   ©r   rW   r   r   r   Ú__eq__¢   rE   zCertificate.__eq__c                 C   rA   ©z#
        Checks not equal.
        Nr   rY   r   r   r   Ú__ne__¨   rE   zCertificate.__ne__c                 C   rA   ©z"
        Computes a hash.
        Nr   rF   r   r   r   Ú__hash__®   rE   zCertificate.__hash__Úencodingc                 C   rA   )zB
        Serializes the certificate to PEM or DER format.
        Nr   ©r   r_   r   r   r   Úpublic_bytes´   rE   zCertificate.public_bytesN)'r"   r#   r$   ÚabcÚabstractmethodr   ÚHashAlgorithmÚbytesrD   ÚabstractpropertyÚintrG   r9   rH   r   rJ   r4   rK   rL   r   rM   rO   ÚtypingÚOptionalrQ   r   rS   r   r(   rU   rV   ÚobjectÚboolrZ   r\   r^   r   ÚEncodingra   r   r   r   r   r?   P   sJ    
þr?   )Ú	metaclassc                   @   sJ   e Zd Zejdefdd„ƒZejdejfdd„ƒZejde	fdd„ƒZ
dS )	ÚRevokedCertificater1   c                 C   rA   )zG
        Returns the serial number of the revoked certificate.
        Nr   rF   r   r   r   rG   ¼   rE   z RevokedCertificate.serial_numberc                 C   rA   )zH
        Returns the date of when this certificate was revoked.
        Nr   rF   r   r   r   Úrevocation_dateÂ   rE   z"RevokedCertificate.revocation_datec                 C   rA   )zW
        Returns an Extensions object containing a list of Revoked extensions.
        Nr   rF   r   r   r   r(   È   rE   zRevokedCertificate.extensionsN)r"   r#   r$   rb   rf   rg   rG   r4   ro   r   r(   r   r   r   r   rn   »   s    rn   c                   @   s|  e Zd Zejdejdefdd„ƒZejde	j
defdd„ƒZejdedeje fd	d
„ƒZejde	j
fdd„ƒZejdefdd„ƒZejdefdd„ƒZejdejfdd„ƒZejdejfdd„ƒZejdefdd„ƒZejdefdd„ƒZejdefdd„ƒZejdedefdd„ƒZ ejdedefdd„ƒZ!ejdefd d!„ƒZ"ejd"d#„ ƒZ#ejd$d%„ ƒZ$ejd&e%defd'd(„ƒZ&d)S )*ÚCertificateRevocationListr_   r1   c                 C   rA   )z:
        Serializes the CRL to PEM or DER format.
        Nr   r`   r   r   r   ra   Ð   rE   z&CertificateRevocationList.public_bytesr@   c                 C   rA   rB   r   rC   r   r   r   rD   Ö   rE   z%CertificateRevocationList.fingerprintrG   c                 C   rA   )zs
        Returns an instance of RevokedCertificate or None if the serial_number
        is not in the CRL.
        Nr   )r   rG   r   r   r   Ú(get_revoked_certificate_by_serial_numberÜ   rE   zBCertificateRevocationList.get_revoked_certificate_by_serial_numberc                 C   rA   rP   r   rF   r   r   r   rQ   å   rE   z2CertificateRevocationList.signature_hash_algorithmc                 C   rA   rR   r   rF   r   r   r   rS   ì   rE   z1CertificateRevocationList.signature_algorithm_oidc                 C   rA   )zC
        Returns the X509Name with the issuer of this CRL.
        Nr   rF   r   r   r   rM   ò   rE   z CertificateRevocationList.issuerc                 C   rA   )z?
        Returns the date of next update for this CRL.
        Nr   rF   r   r   r   Únext_updateø   rE   z%CertificateRevocationList.next_updatec                 C   rA   )z?
        Returns the date of last update for this CRL.
        Nr   rF   r   r   r   Úlast_updateþ   rE   z%CertificateRevocationList.last_updatec                 C   rA   )zS
        Returns an Extensions object containing a list of CRL extensions.
        Nr   rF   r   r   r   r(     rE   z$CertificateRevocationList.extensionsc                 C   rA   rT   r   rF   r   r   r   rU   
  rE   z#CertificateRevocationList.signaturec                 C   rA   )zO
        Returns the tbsCertList payload bytes as defined in RFC 5280.
        Nr   rF   r   r   r   Útbs_certlist_bytes  rE   z,CertificateRevocationList.tbs_certlist_bytesrW   c                 C   rA   rX   r   rY   r   r   r   rZ     rE   z CertificateRevocationList.__eq__c                 C   rA   r[   r   rY   r   r   r   r\     rE   z CertificateRevocationList.__ne__c                 C   rA   )z<
        Number of revoked certificates in the CRL.
        Nr   rF   r   r   r   Ú__len__"  rE   z!CertificateRevocationList.__len__c                 C   rA   )zS
        Returns a revoked certificate (or slice of revoked certificates).
        Nr   )r   Úidxr   r   r   Ú__getitem__(  rE   z%CertificateRevocationList.__getitem__c                 C   rA   )z8
        Iterator over the revoked certificates
        Nr   rF   r   r   r   Ú__iter__.  rE   z"CertificateRevocationList.__iter__rJ   c                 C   rA   )zQ
        Verifies signature of revocation list against given public key.
        Nr   )r   rJ   r   r   r   Úis_signature_valid4  rE   z,CertificateRevocationList.is_signature_validN)'r"   r#   r$   rb   rc   r   rl   re   ra   r   rd   rD   rg   rh   ri   rn   rq   rf   rQ   r   rS   r   rM   r4   rr   rs   r   r(   rU   rt   rj   rk   rZ   r\   ru   rw   rx   r   ry   r   r   r   r   rp   Ï   sN    ÿþ

rp   c                   @   s$  e Zd Zejdedefdd„ƒZejdedefdd„ƒZejde	fdd„ƒZ
ejdefd	d
„ƒZejdefdd„ƒZejdejfdd„ƒZejdefdd„ƒZejdefdd„ƒZejdejdefdd„ƒZejdefdd„ƒZejdefdd„ƒZejdefdd„ƒZejdedefdd„ƒZdS ) ÚCertificateSigningRequestrW   r1   c                 C   rA   rX   r   rY   r   r   r   rZ   <  rE   z CertificateSigningRequest.__eq__c                 C   rA   r[   r   rY   r   r   r   r\   B  rE   z CertificateSigningRequest.__ne__c                 C   rA   r]   r   rF   r   r   r   r^   H  rE   z"CertificateSigningRequest.__hash__c                 C   rA   rI   r   rF   r   r   r   rJ   N  rE   z$CertificateSigningRequest.public_keyc                 C   rA   rN   r   rF   r   r   r   rO   T  rE   z!CertificateSigningRequest.subjectc                 C   rA   rP   r   rF   r   r   r   rQ   Z  rE   z2CertificateSigningRequest.signature_hash_algorithmc                 C   rA   rR   r   rF   r   r   r   rS   a  rE   z1CertificateSigningRequest.signature_algorithm_oidc                 C   rA   )z@
        Returns the extensions in the signing request.
        Nr   rF   r   r   r   r(   g  rE   z$CertificateSigningRequest.extensionsr_   c                 C   rA   )z;
        Encodes the request to PEM or DER format.
        Nr   r`   r   r   r   ra   m  rE   z&CertificateSigningRequest.public_bytesc                 C   rA   rT   r   rF   r   r   r   rU   s  rE   z#CertificateSigningRequest.signaturec                 C   rA   )zd
        Returns the PKCS#10 CertificationRequestInfo bytes as defined in RFC
        2986.
        Nr   rF   r   r   r   Útbs_certrequest_bytesy  rE   z/CertificateSigningRequest.tbs_certrequest_bytesc                 C   rA   )z8
        Verifies signature of signing request.
        Nr   rF   r   r   r   ry   €  rE   z,CertificateSigningRequest.is_signature_validr   c                 C   rA   )z:
        Get the attribute value for a given OID.
        Nr   )r   r   r   r   r   Úget_attribute_for_oid†  rE   z/CertificateSigningRequest.get_attribute_for_oidN)r"   r#   r$   rb   rc   rj   rk   rZ   r\   rg   r^   r   rJ   rf   r   rO   r   rd   rQ   r   rS   r   r(   r   rl   re   ra   rU   r{   ry   r|   r   r   r   r   rz   ;  s6    rz   Údatac                 C   ó   t |ƒ}| | ¡S r   )r   Úload_pem_x509_certificate©r}   Úbackendr   r   r   r   �  ó   
r   c                 C   r~   r   )r   Úload_der_x509_certificater€   r   r   r   rƒ   ’  r‚   rƒ   c                 C   r~   r   )r   Úload_pem_x509_csrr€   r   r   r   r„   —  r‚   r„   c                 C   r~   r   )r   Úload_der_x509_csrr€   r   r   r   r…   œ  r‚   r…   c                 C   r~   r   )r   Úload_pem_x509_crlr€   r   r   r   r†   ¡  r‚   r†   c                 C   r~   r   )r   Úload_der_x509_crlr€   r   r   r   r‡   ¦  r‚   r‡   c                   @   sj   e Zd Zdg g fdd„Zdefdd„Zdedefd	d
„Zde	de
fdd„Z	ddedejdefdd„ZdS )Ú CertificateSigningRequestBuilderNc                 C   s   || _ || _|| _dS )zB
        Creates an empty X.509 certificate request (v1).
        N)Ú_subject_nameÚ_extensionsÚ_attributes)r   Úsubject_namer(   r,   r   r   r   r   ¬  s   
z)CertificateSigningRequestBuilder.__init__Únamec                 C   s4   t |tƒs	tdƒ‚| jdurtdƒ‚t|| j| jƒS )zF
        Sets the certificate requestor's distinguished name.
        úExpecting x509.Name object.Nú&The subject name may only be set once.)Ú
isinstancer   Ú	TypeErrorr‰   r)   rˆ   rŠ   r‹   ©r   r�   r   r   r   rŒ   ´  s   


ÿz-CertificateSigningRequestBuilder.subject_nameÚextvalÚcriticalc                 C   sD   t |tƒs	tdƒ‚t|j||ƒ}t|| jƒ t| j| j|g | j	ƒS )zE
        Adds an X.509 extension to the certificate request.
        ú"extension must be an ExtensionType)
r�   r   r‘   r   r   r+   rŠ   rˆ   r‰   r‹   ©r   r“   r”   r'   r   r   r   Úadd_extensionÀ  s   

ýz.CertificateSigningRequestBuilder.add_extensionr   Úvaluec                 C   sL   t |tƒs	tdƒ‚t |tƒstdƒ‚t|| jƒ t| j| j| j||fg ƒS )zK
        Adds an X.509 attribute with an OID and associated value.
        zoid must be an ObjectIdentifierzvalue must be bytes)	r�   r   r‘   re   r/   r‹   rˆ   r‰   rŠ   )r   r   r˜   r   r   r   Úadd_attributeÐ  s   

ýz.CertificateSigningRequestBuilder.add_attributeÚprivate_keyr@   r1   c                 C   s(   t |ƒ}| jdu rtdƒ‚| | ||¡S )zF
        Signs the request using the requestor's private key.
        Nz/A CertificateSigningRequest must have a subject)r   r‰   r)   Úcreate_x509_csr©r   rš   r@   r�   r   r   r   Úsignâ  s   	
z%CertificateSigningRequestBuilder.signr   )r"   r#   r$   r   r   rŒ   r   rk   r—   r   re   r™   r   r   rd   rz   r�   r   r   r   r   rˆ   «  s    üþýûrˆ   c                   @   sª   e Zd Zddddddg fdd„Zdefdd„Zdefdd„Zd	efd
d„Zde	fdd„Z
dejfdd„Zdejfdd„Zdedefdd„Z	ddedejdefdd„ZdS )ÚCertificateBuilderNc                 C   s6   t j| _|| _|| _|| _|| _|| _|| _|| _	d S r   )
r9   r<   Ú_versionÚ_issuer_namer‰   Ú_public_keyÚ_serial_numberÚ_not_valid_beforeÚ_not_valid_afterrŠ   )r   Úissuer_namerŒ   rJ   rG   rK   rL   r(   r   r   r   r   ò  s   

zCertificateBuilder.__init__r�   c                 C   sD   t |tƒs	tdƒ‚| jdurtdƒ‚t|| j| j| j| j	| j
| jƒS )z3
        Sets the CA's distinguished name.
        rŽ   Nú%The issuer name may only be set once.)r�   r   r‘   r    r)   rž   r‰   r¡   r¢   r£   r¤   rŠ   r’   r   r   r   r¥     s   

ùzCertificateBuilder.issuer_namec                 C   sD   t |tƒs	tdƒ‚| jdurtdƒ‚t| j|| j| j| j	| j
| jƒS )z:
        Sets the requestor's distinguished name.
        rŽ   Nr�   )r�   r   r‘   r‰   r)   rž   r    r¡   r¢   r£   r¤   rŠ   r’   r   r   r   rŒ     s   

ùzCertificateBuilder.subject_nameÚkeyc                 C   sX   t |tjtjtjtjt	j
fƒstdƒ‚| jdurtdƒ‚t| j| j|| j| j| j| jƒS )zT
        Sets the requestor's public key (as found in the signing request).
        zhExpecting one of DSAPublicKey, RSAPublicKey, EllipticCurvePublicKey, Ed25519PublicKey or Ed448PublicKey.Nz$The public key may only be set once.)r�   r   ÚDSAPublicKeyr   ÚRSAPublicKeyr	   ÚEllipticCurvePublicKeyr
   ÚEd25519PublicKeyr   ÚEd448PublicKeyr‘   r¡   r)   rž   r    r‰   r¢   r£   r¤   rŠ   )r   r§   r   r   r   rJ   )  s.   ûþ
ÿ
ùzCertificateBuilder.public_keyÚnumberc                 C   sh   t |tƒs	tdƒ‚| jdurtdƒ‚|dkrtdƒ‚| ¡ dkr$tdƒ‚t| j| j| j	|| j
| j| jƒS )z5
        Sets the certificate serial number.
        ú'Serial number must be of integral type.Nú'The serial number may only be set once.r   z%The serial number should be positive.é    ú3The serial number should not be more than 159 bits.)r�   rg   r‘   r¢   r)   Ú
bit_lengthrž   r    r‰   r¡   r£   r¤   rŠ   ©r   r­   r   r   r   rG   K  s&   

ÿùz CertificateBuilder.serial_numberr0   c                 C   sz   t |tjƒs
tdƒ‚| jdurtdƒ‚t|ƒ}|tk rtdƒ‚| jdur-|| jkr-tdƒ‚t| j	| j
| j| j|| j| jƒS )z7
        Sets the certificate activation time.
        úExpecting datetime object.Nz*The not valid before may only be set once.z>The not valid before date must be on or after 1950 January 1).zBThe not valid before date must be before the not valid after date.)r�   r4   r‘   r£   r)   r8   Ú_EARLIEST_UTC_TIMEr¤   rž   r    r‰   r¡   r¢   rŠ   ©r   r0   r   r   r   rK   f  s,   
ÿÿùz#CertificateBuilder.not_valid_beforec                 C   sz   t |tjƒs
tdƒ‚| jdurtdƒ‚t|ƒ}|tk rtdƒ‚| jdur-|| jk r-tdƒ‚t| j	| j
| j| j| j|| jƒS )z7
        Sets the certificate expiration time.
        r´   Nz)The not valid after may only be set once.z<The not valid after date must be on or after 1950 January 1.zAThe not valid after date must be after the not valid before date.)r�   r4   r‘   r¤   r)   r8   rµ   r£   rž   r    r‰   r¡   r¢   rŠ   r¶   r   r   r   rL   ƒ  s.   
ÿ

ÿùz"CertificateBuilder.not_valid_afterr“   r”   c              	   C   sT   t |tƒs	tdƒ‚t|j||ƒ}t|| jƒ t| j| j	| j
| j| j| j| j|g ƒS )z=
        Adds an X.509 extension to the certificate.
        r•   )r�   r   r‘   r   r   r+   rŠ   rž   r    r‰   r¡   r¢   r£   r¤   r–   r   r   r   r—   £  s   

ùz CertificateBuilder.add_extensionrš   r@   r1   c                 C   s‚   t |ƒ}| jdu rtdƒ‚| jdu rtdƒ‚| jdu rtdƒ‚| jdu r(tdƒ‚| jdu r1tdƒ‚| jdu r:tdƒ‚| | ||¡S )zC
        Signs the certificate using the CA's private key.
        Nz&A certificate must have a subject namez&A certificate must have an issuer namez'A certificate must have a serial numberz/A certificate must have a not valid before timez.A certificate must have a not valid after timez$A certificate must have a public key)	r   r‰   r)   r    r¢   r£   r¤   r¡   Úcreate_x509_certificaterœ   r   r   r   r�   ·  s   	





zCertificateBuilder.signr   )r"   r#   r$   r   r   r¥   rŒ   r   rJ   rg   rG   r4   rK   rL   r   rk   r—   r   r   rd   r?   r�   r   r   r   r   rž   ñ  s4    
ø
þ" üþýûrž   c                   @   sŠ   e Zd Zdddg g fdd„Zdefdd„Zdejfdd	„Zd
ejfdd„Zde	de
fdd„Zdefdd„Z	ddedejdefdd„ZdS )Ú CertificateRevocationListBuilderNc                 C   s"   || _ || _|| _|| _|| _d S r   )r    Ú_last_updateÚ_next_updaterŠ   Ú_revoked_certificates)r   r¥   rs   rr   r(   Úrevoked_certificatesr   r   r   r   ×  s
   
z)CertificateRevocationListBuilder.__init__r¥   c                 C   s<   t |tƒs	tdƒ‚| jd urtdƒ‚t|| j| j| j| j	ƒS )NrŽ   r¦   )
r�   r   r‘   r    r)   r¸   r¹   rº   rŠ   r»   )r   r¥   r   r   r   r¥   å  s   

ûz,CertificateRevocationListBuilder.issuer_namers   c                 C   sr   t |tjƒs
tdƒ‚| jd urtdƒ‚t|ƒ}|tk rtdƒ‚| jd ur-|| jkr-tdƒ‚t| j	|| j| j
| jƒS )Nr´   ú!Last update may only be set once.ú8The last update date must be on or after 1950 January 1.z9The last update date must be before the next update date.)r�   r4   r‘   r¹   r)   r8   rµ   rº   r¸   r    rŠ   r»   )r   rs   r   r   r   rs   ò  s(   
ÿÿûz,CertificateRevocationListBuilder.last_updaterr   c                 C   sr   t |tjƒs
tdƒ‚| jd urtdƒ‚t|ƒ}|tk rtdƒ‚| jd ur-|| jk r-tdƒ‚t| j	| j|| j
| jƒS )Nr´   r½   r¾   z8The next update date must be after the last update date.)r�   r4   r‘   rº   r)   r8   rµ   r¹   r¸   r    rŠ   r»   )r   rr   r   r   r   rr     s(   
ÿÿûz,CertificateRevocationListBuilder.next_updater“   r”   c                 C   sL   t |tƒs	tdƒ‚t|j||ƒ}t|| jƒ t| j| j	| j
| j|g | jƒS )zM
        Adds an X.509 extension to the certificate revocation list.
        r•   )r�   r   r‘   r   r   r+   rŠ   r¸   r    r¹   rº   r»   r–   r   r   r   r—     s   

ûz.CertificateRevocationListBuilder.add_extensionÚrevoked_certificatec                 C   s2   t |tƒs	tdƒ‚t| j| j| j| j| j|g ƒS )z8
        Adds a revoked certificate to the CRL.
        z)Must be an instance of RevokedCertificate)	r�   rn   r‘   r¸   r    r¹   rº   rŠ   r»   )r   r¿   r   r   r   Úadd_revoked_certificate/  s   

ûz8CertificateRevocationListBuilder.add_revoked_certificaterš   r@   r1   c                 C   sL   t |ƒ}| jd u rtdƒ‚| jd u rtdƒ‚| jd u rtdƒ‚| | ||¡S )NzA CRL must have an issuer namez"A CRL must have a last update timez"A CRL must have a next update time)r   r    r)   r¹   rº   Úcreate_x509_crlrœ   r   r   r   r�   >  s   


z%CertificateRevocationListBuilder.signr   )r"   r#   r$   r   r   r¥   r4   rs   rr   r   rk   r—   rn   rÀ   r   r   rd   rp   r�   r   r   r   r   r¸   Ö  s(    
úüþýûr¸   c                   @   s\   e Zd Zddg fdd„Zdefdd„Zdejfdd	„Zd
ede	fdd„Z
ddefdd„ZdS )ÚRevokedCertificateBuilderNc                 C   s   || _ || _|| _d S r   )r¢   Ú_revocation_daterŠ   )r   rG   ro   r(   r   r   r   r   R  s   
z"RevokedCertificateBuilder.__init__r­   c                 C   sX   t |tƒs	tdƒ‚| jd urtdƒ‚|dkrtdƒ‚| ¡ dkr$tdƒ‚t|| j| jƒS )Nr®   r¯   r   z$The serial number should be positiver°   r±   )	r�   rg   r‘   r¢   r)   r²   rÂ   rÃ   rŠ   r³   r   r   r   rG   Y  s   

ÿ
ÿz'RevokedCertificateBuilder.serial_numberr0   c                 C   sN   t |tjƒs
tdƒ‚| jd urtdƒ‚t|ƒ}|tk rtdƒ‚t| j|| j	ƒS )Nr´   z)The revocation date may only be set once.z7The revocation date must be on or after 1950 January 1.)
r�   r4   r‘   rÃ   r)   r8   rµ   rÂ   r¢   rŠ   r¶   r   r   r   ro   k  s   
ÿ
ÿz)RevokedCertificateBuilder.revocation_dater“   r”   c                 C   sD   t |tƒs	tdƒ‚t|j||ƒ}t|| jƒ t| j| j	| j|g ƒS )Nr•   )
r�   r   r‘   r   r   r+   rŠ   rÂ   r¢   rÃ   r–   r   r   r   r—   y  s   

ýz'RevokedCertificateBuilder.add_extensionr1   c                 C   s6   t |ƒ}| jd u rtdƒ‚| jd u rtdƒ‚| | ¡S )Nz/A revoked certificate must have a serial numberz1A revoked certificate must have a revocation date)r   r¢   r)   rÃ   Úcreate_x509_revoked_certificate)r   r�   r   r   r   Úbuild…  s   

ÿ
zRevokedCertificateBuilder.buildr   )r"   r#   r$   r   rg   rG   r4   ro   r   rk   r—   rn   rÅ   r   r   r   r   rÂ   Q  s    
ÿrÂ   c                   C   s   t  t d¡d¡d? S )Né   Úbigr   )rg   Ú
from_bytesÚosÚurandomr   r   r   r   Úrandom_serial_number‘  s   rË   r   ):rb   r4   rÉ   rh   Úcryptographyr   Úcryptography.hazmat._typesr   r   Úcryptography.hazmat.backendsr   Úcryptography.hazmat.primitivesr   r   Ú)cryptography.hazmat.primitives.asymmetricr   r	   r
   r   r   Úcryptography.x509.extensionsr   r   r   Úcryptography.x509.namer   Úcryptography.x509.oidr   rµ   Ú	Exceptionr   ÚListr+   ÚTuplere   r/   r8   ÚEnumr9   r=   ÚABCMetar?   rn   rp   rz   r   rƒ   r„   r…   r†   r‡   rj   rˆ   rž   r¸   rÂ   rg   rË   r   r   r   r   Ú<module>   sV   ÿ
ÿ	ÿ
þ
klRF f{@