403Webshell
Server IP : 178.105.222.151  /  Your IP : 216.73.216.38
Web Server : nginx/1.28.3
System : Linux MNK 7.0.0-15-generic #15-Ubuntu SMP PREEMPT_DYNAMIC Wed Apr 22 16:06:43 UTC 2026 x86_64
User : www-data ( 33)
PHP Version : 8.5.4
Disable Function : NONE
MySQL : OFF  |  cURL : ON  |  WGET : ON  |  Perl : ON  |  Python : OFF  |  Sudo : ON  |  Pkexec : OFF
Directory :  /lib/python3/dist-packages/OpenSSL/__pycache__/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Command :


[ Back ]     

Current File : /lib/python3/dist-packages/OpenSSL/__pycache__/crypto.cpython-314.pyc
+
Hߺi)7��pa�0t$^RIHt^RIt^RIt^RIt^RIt^RIt^RIt^RI	H
t
^RIHtH
t
^RIHt^RIHtHtHt]P$R[8�d^RIHtM0]P$R\8d]P(!R4tR	R
ltM^RIHt^RIHtHt^RIHtHtHtHtHt^R
I H!t!^RI H"t#^RI H$t%^RI H&t'^RI H(t)^RI H*t+^RI H,t-.R]Ot.]]P^]P`]Pb]Pd]Pf3,t4]]Pj]Pl]Pn]Pp]Pr3,t:]]4]:3,t;]]<]R$]<3,3,t=])P|t?R%]@R&])P�tBR%]@R&R^tC])P�tER%]@R&])P�tGR%]@R&])P�tIR%]@R&&])P�tKR%]@R'&!R(R]L4tM]!]%]M4tN]+!]M4tOR_R)R*lltPR+R,ltQR-R.ltRR/R0ltSR1R2ltT!R3R44tU!R5R4tV!R6R74tW]!R84R9R:l4tX]!R;4R<R=l4tY]P�!R>R44t[]!R?4!R@R44t\]!RA4!RBR44t]!RCR4t^!RDR!4t_!RER4t`!RFR ]L4ta!RGR4tbRHRIltcRJRKltdRLRMlteR`RNROlltf!RPRQ4tgRRRSlthR_RTRUlltiRVRWltj]jtk]P&!]j]lRA]mR"RX7RYRZltn]nto]P&!]n]lRA]mR#RX7R#)a�)�annotationsN)�	b16encode)�Iterable�Sequence)�partial)�Any�Callable�Union)�
deprecated�Tc�$�V^8�dQhRRRRRR/#)��msg�str�kwargs�object�returnzCallable[[_T], _T]�)�formats"�0/usr/lib/python3/dist-packages/OpenSSL/crypto.py�__annotate__rs"������v��2D��c��R#)c��V#�Nr)�fs&r�<lambda>�deprecated.<locals>.<lambda>s��rr)rrs&,rrrs���r)�utils�x509)�dsa�ec�ed448�ed25519�rsa)�StrOrBytesPath)�byte_string)�exception_from_error_queue)�ffi)�lib)�make_assert)�
path_bytes�
FILETYPE_ASN1�FILETYPE_PEM�TYPE_DSA�TYPE_RSA�X509�Error�PKey�
X509Extension�X509Name�X509Req�	X509Store�X509StoreContext�X509StoreContextError�X509StoreFlags�dump_certificate_request�load_certificate_request.�int�TYPE_DH�TYPE_ECc��]tRt^ttRtRtR#)r2z/
An error occurred in an `OpenSSL.crypto` API.
rN)�__name__�
__module__�__qualname__�__firstlineno__�__doc__�__static_attributes__rrrr2r2ts��rc� �V^8�dQhRRRR/#)r�buffer�bytes | Nonerrr)rs"rrr~s�������rc�f�Vf;\P!\P!44p\PpM@\P
!RV4p\P!V\V44pV3RRllp\V\P8g4\P!W4pV#)z�
Allocate a new OpenSSL memory BIO.

Arrange for the garbage collector to clean it up automatically.

:param buffer: None or some bytes to use to put into the BIO so that they
    can be read out.
�char[]c�$�V^8�dQhRRRRRR/#)r�bior�refrr)rs"rr�"_new_mem_buf.<locals>.__annotate__�s!��	&�	&�c�	&��	&�s�	&rc�.�\P!V4#r)�_lib�BIO_free)rMrNs&&r�free�_new_mem_buf.<locals>.free�s���=�=��%�%r)rQ�BIO_new�	BIO_s_memrR�_ffi�new�BIO_new_mem_buf�len�_openssl_assert�NULL�gc)rHrMrS�datas&   r�_new_mem_bufr_~s}���~��l�l�4�>�>�+�,���}�}���x�x��&�)���"�"�4��V��5��'+�	&��C�4�9�9�$�%�
�'�'�#�
�C��Jrc� �V^8�dQhRRRR/#)rrMrr�bytesr)rs"rrr�s��;�;��;��;rc��\P!R4p\P!W4p\P!V^,V4R,#)zG
Copy the contents of an OpenSSL BIO object into a Python byte string.
zchar**�NNN)rWrXrQ�BIO_get_mem_datarH)rM�
result_buffer�
buffer_lengths&  r�_bio_to_stringrg�s=���H�H�X�&�M��)�)�#�=�M��;�;�}�Q�'��7��:�:rc�$�V^8�dQhRRRRRR/#)r�boundaryr�whenrar�Noner)rs"rrr�s!��+�+�S�+��+�$�+rc���\V\4'g\R4h\V\P
8g4\P!W4pV^8Xd\R4hR#)a�
The the time value of an ASN1 time object.

@param boundary: An ASN1_TIME pointer (or an object safely
    castable to that type) which will have its value set.
@param when: A string representation of the desired time value.

@raise TypeError: If C{when} is not a L{bytes} string.
@raise ValueError: If C{when} does not represent a time in the required
    format.
@raise RuntimeError: If the time value cannot be set for some other
    (unspecified) reason.
zwhen must be a byte stringzInvalid stringN)	�
isinstancera�	TypeErrorr[rWr\rQ�ASN1_TIME_set_string�
ValueError)rirj�
set_results&& r�_set_asn1_timerr�sX���d�E�"�"��4�5�5��H��	�	�)�*��*�*�8�:�J��Q���)�*�*�rc� �V^8�dQhRRRR/#)rrjrarrr)rs"rrr�s������3�rc���\P!4p\V\P8g4\P
!V\P4p\W4V#)al
Behaves like _set_asn1_time but returns a new ASN1_TIME object.

@param when: A string representation of the desired time value.

@raise TypeError: If C{when} is not a L{bytes} string.
@raise ValueError: If C{when} does not represent a time in the required
    format.
@raise RuntimeError: If the time value cannot be set for some other
    (unspecified) reason.
)rQ�
ASN1_TIME_newr[rWr\r]�ASN1_TIME_freerr)rj�rets& r�_new_asn1_timerx�sF���
�
�
�C��C�4�9�9�$�%�
�'�'�#�t�*�*�
+�C��3���Jrc� �V^8�dQhRRRR/#)r�	timestamprrrIr)rs"rrr�s����c��l�rc��\P!RV4p\P!V4^8XdR#\P!V4\P
8Xd+\P!\P!V44#\P!R4p\P!W4\V^,\P8g4\P!RV^,4p\P!V4p\P!V4p\P!V^,4V#)aE
Retrieve the time value of an ASN1 time object.

@param timestamp: An ASN1_GENERALIZEDTIME* (or an object safely castable to
    that type) from which the time value will be retrieved.

@return: The time value from C{timestamp} as a L{bytes} string in a certain
    format.  Or C{None} if the object contains no time value.
�ASN1_STRING*NzASN1_GENERALIZEDTIME**)
rW�castrQ�ASN1_STRING_length�ASN1_STRING_type�V_ASN1_GENERALIZEDTIME�string�ASN1_STRING_get0_datarX�ASN1_TIME_to_generalizedtimer[r\�ASN1_GENERALIZEDTIME_free)rz�string_timestamp�generalized_timestamp�string_data�
string_results&    r�_get_asn1_timer��s����y�y���;�����/�0�A�5�����.�/�4�3N�3N�N��{�{�4�5�5�6F�G�H�H� $���)A� B���)�)�)�K��-�a�0�D�I�I�=�>��9�9�^�5J�1�5M�N���0�0�1A�B�����K�0�
��&�&�'<�Q�'?�@��rc�:�]tRt^�tRRltRRltRRltRtR#)	�_X509NameInvalidatorc��V^8�dQhRR/#�rrrkr)rs"rr�!_X509NameInvalidator.__annotate__�s��)�)�$�)rc	��.VnR#r��_names��selfs&r�__init__�_X509NameInvalidator.__init__�s	��&(��rc� �V^8�dQhRRRR/#�r�namer5rrkr)rs"rrr��s��!�!��!�T�!rc	�<�VPPV4R#r)r��append�r�r�s&&r�add�_X509NameInvalidator.add�s�������4� rc��V^8�dQhRR/#r�r)rs"rrr��s����t�rc	�0�VPFpV=K	R#r)r��_namer�s& r�clear�_X509NameInvalidator.clear�s���K�K�D��
� rr�N)rArBrCrDr�r�r�rFrrrr�r��s��)�!��rr�c��]tRt^�tRtRtRtRRltRRlt]	RR	l4t
R
RltRR
ltRRlt
RRltRtR#)r3z<
A class representing an DSA or RSA public key or key pair.
FTc��V^8�dQhRR/#r�r)rs"rr�PKey.__annotate__�s��"�"�$�"rc	��\P!4p\P!V\P4VnRVnR#)FN)rQ�EVP_PKEY_newrWr]�
EVP_PKEY_free�_pkey�_initialized�r��pkeys& rr��
PKey.__init__�s0��� � �"���W�W�T�4�#5�#5�6��
�!��rc��V^8�dQhRR/#)rr�_Keyr)rs"rrr�s��O�O�T�Orc
��^RIHpHpVP'd2\	\
V4p\P!\V!V44#\\
V4p\P!\V!VRR74#)z�
Export as a ``cryptography`` key.

:rtype: One of ``cryptography``'s `key interfaces`_.

.. _key interfaces: https://cryptography.io/en/latest/hazmat/            primitives/asymmetric/rsa/#key-interfaces

.. versionadded:: 16.1.0
)�load_der_private_key�load_der_public_keyN)�password)
�,cryptography.hazmat.primitives.serializationr�r��_only_public�dump_publickeyr-�typingr}r��dump_privatekey)r�r�r��ders&   r�to_cryptography_key�PKey.to_cryptography_keys]��	
�
���� ���5�C��;�;�t�%8��%=�>�>�!�-��6�C��;�;�t�%9�#��%M�N�Nrc� �V^8�dQhRRRR/#)r�
crypto_keyr�rr3r)rs"rrr�s��77�77�t�77��77rc

��\V\P\P\P
\P\P\P\P\P\P\P3
4'g\!R4h^RIHpHpHpHp\V\P\P\P\P\P34'd5\-\.VP1VP2VP444#VP7VP2VP8V!44p\;\.V4#)z�
Construct based on a ``cryptography`` *crypto_key*.

:param crypto_key: A ``cryptography`` key.
:type crypto_key: One of ``cryptography``'s `key interfaces`_.

:rtype: PKey

.. versionadded:: 16.1.0
zUnsupported key type)�Encoding�NoEncryption�
PrivateFormat�PublicFormat)rmr!�
DSAPrivateKey�DSAPublicKeyr"�EllipticCurvePrivateKey�EllipticCurvePublicKeyr$�Ed25519PrivateKey�Ed25519PublicKeyr#�Ed448PrivateKey�Ed448PublicKeyr%�
RSAPrivateKey�RSAPublicKeyrnr�r�r�r�r��load_publickeyr-�public_bytes�DER�SubjectPublicKeyInfo�
private_bytes�PKCS8�load_privatekey)�clsr�r�r�r�r�r�s&&     r�from_cryptography_key�PKey.from_cryptography_keys2�����!�!�� � ��*�*��)�)��)�)��(�(��%�%��$�$��!�!�� � �
�
�
��2�3�3�	
�	
���� � ��)�)��(�(��$�$�� � �
�	
�	
�"���'�'��L�L�,�"C�"C���
��*�*����m�1�1�<�>��C�#�=�#�6�6rc�$�V^8�dQhRRRRRR/#)r�typer=�bitsrrkr)rs"rrr�Us!��6!�6!��6!�C�6!�D�6!rc	
��\V\4'g\R4h\V\4'g\R4hV\8Xd�V^8:d\	R4h\
P!4p\P!V\
P4p\
P!V\
P4\
P!4p\
P!WBV\P4p\V^8H4\
P !VP"V4p\V^8H4EMV\$8XEd\
P&!4p\V\P8g4\P!V\
P(4p\
P*!Wb\P^\P\P\P4p\V^8H4\\
P,!V4^8H4\\
P.!VP"V4^8H4M\1R4hRVnR#)a�
Generate a key pair of the given type, with the given number of bits.

This generates a key "into" the this object.

:param type: The key type.
:type type: :py:data:`TYPE_RSA` or :py:data:`TYPE_DSA`
:param bits: The number of bits.
:type bits: :py:data:`int` ``>= 0``
:raises TypeError: If :py:data:`type` or :py:data:`bits` isn't
    of the appropriate type.
:raises ValueError: If the number of bits isn't an integer of
    the appropriate size.
:return: ``None``
ztype must be an integerzbits must be an integerzInvalid number of bitszNo such key typeTN)rmr=rnr0rprQ�BN_newrWr]�BN_free�BN_set_word�RSA_F4�RSA_new�RSA_generate_key_exr\r[�EVP_PKEY_assign_RSAr�r/�DSA_new�DSA_free�DSA_generate_parameters_ex�DSA_generate_key�EVP_PKEY_set1_DSAr2r�)r�r�r��exponentr%�resultr!�ress&&&     r�generate_key�PKey.generate_keyUs��� �$��$�$��5�6�6��$��$�$��5�6�6��8���q�y� �!9�:�:��{�{�}�H��w�w�x����6�H����X�t�{�{�3��,�,�.�C��-�-�c��4�9�9�M�F��F�a�K�(��-�-�d�j�j�#�>�F��F�a�K�(�
�X�
��,�,�.�C��C�4�9�9�,�-��'�'�#�t�}�}�-�C��1�1��4�9�9�a����D�I�I�t�y�y��C�
�C�1�H�%��D�1�1�#�6�!�;�<��D�2�2�4�:�:�s�C�q�H�I��*�+�+� ��rc��V^8�dQhRR/#�rr�boolr)rs"rrr��s����t�rc
��VP'd\R4h\P!VP	44\P
8wd\R4h\P!VP4p\P!V\P4p\P!V4pV^8XdR#\4R#)a@
Check the consistency of an RSA private key.

This is the Python equivalent of OpenSSL's ``RSA_check_key``.

:return: ``True`` if key is consistent.

:raise OpenSSL.crypto.Error: if the key is inconsistent.

:raise TypeError: if the key is of a type which cannot be checked.
    Only RSA keys can currently be checked.
zpublic key onlyz'Only RSA keys can currently be checked.TN)
r�rnrQ�
EVP_PKEY_typer��EVP_PKEY_RSA�EVP_PKEY_get1_RSAr�rWr]�RSA_free�
RSA_check_key�_raise_current_error)r�r%r�s&  r�check�
PKey.check�s��������-�.�.����d�i�i�k�*�d�.?�.?�?��E�F�F��$�$�T�Z�Z�0���g�g�c�4�=�=�)���#�#�C�(���Q�;���rc��V^8�dQhRR/#�rrr=r)rs"rrr��s��,�,�c�,rc
�B�\P!VP4#)z<
Returns the type of the key

:return: The type of the key.
)rQ�EVP_PKEY_idr�r�s&rr��	PKey.type�s������
�
�+�+rc��V^8�dQhRR/#r�r)rs"rrr��s��.�.�c�.rc
�B�\P!VP4#)zP
Returns the number of bits of the key

:return: The number of bits of the key.
)rQ�
EVP_PKEY_bitsr�r�s&rr��	PKey.bits�s���!�!�$�*�*�-�-r)r�r�N)rArBrCrDrEr�r�r�r��classmethodr�r�r�r�r�rFrrrr3r3�sM����L��L�"�
O�.�77��77�r6!�p�4,�.�.rc�a�]tRtRtRtRtRV3Rllt]RRl4t]RR	l4t	]R
Rl4t
RR
ltRRltRRlt
RtV;t#)�_EllipticCurvei�aB
A representation of a supported elliptic curve.

@cvar _curves: :py:obj:`None` until an attempt is made to load the curves.
    Thereafter, a :py:type:`set` containing :py:type:`_EllipticCurve`
    instances each of which represents one curve supported by the system.
@type _curves: :py:type:`NoneType` or :py:type:`set`
Nc� �V^8�dQhRRRR/#�r�otherrrr�r)rs"rr�_EllipticCurve.__annotate__�s��	�	�C�	�D�	rc
�Z<�\V\4'd\SV`
V4#\#)z�
Implement cooperation with the right-hand side argument of ``!=``.

Python 3 seems to have dropped this cooperation in this very narrow
circumstance.
)rmr�super�__ne__�NotImplemented)r�r�	__class__s&&�rr
�_EllipticCurve.__ne__�s'����e�^�,�,��7�>�%�(�(��rc� �V^8�dQhRRRR/#�rr*rr�set[_EllipticCurve]r)rs"rrr�s��E�E��E�0C�Erc
��aa�SP\P^4p\P!RV4pSPW24\	VV3RlV44#)z�
Get the curves supported by OpenSSL.

:param lib: The OpenSSL library binding object.

:return: A :py:type:`set` of ``cls`` instances giving the names of the
    elliptic curves the underlying library supports.
zEC_builtin_curve[]c3�\<"�TF!pSPSVP4x�K#	R#5ir)�from_nid�nid)�.0�cr�r*s& ��r�	<genexpr>�7_EllipticCurve._load_elliptic_curves.<locals>.<genexpr>�s#����D�^��3�<�<��Q�U�U�+�+�^�s�),)�EC_get_builtin_curvesrWr\rX�set)r�r*�
num_curves�builtin_curvessff  r�_load_elliptic_curves�$_EllipticCurve._load_elliptic_curves�sM����.�.�t�y�y�!�<�
����"6�
�C��	�!�!�.�=��D�^�D�D�Drc� �V^8�dQhRRRR/#rr)rs"rrr�s����s��/B�rc
�b�VPfVPV4VnVP#)z�
Get, cache, and return the curves supported by OpenSSL.

:param lib: The OpenSSL library binding object.

:return: A :py:type:`set` of ``cls`` instances giving the names of the
    elliptic curves the underlying library supports.
)�_curvesr)r�r*s&&r�_get_elliptic_curves�#_EllipticCurve._get_elliptic_curves�s*���;�;���3�3�C�8�C�K��{�{�rc�$�V^8�dQhRRRRRR/#)rr*rrr=rrr)rs"rrr�s&��O�O�3�O�S�O�^�Orc	
�x�V!W\P!VPV44PR44#)a�
Instantiate a new :py:class:`_EllipticCurve` associated with the given
OpenSSL NID.

:param lib: The OpenSSL library binding object.

:param nid: The OpenSSL NID the resulting curve object will represent.
    This must be a curve NID (and not, for example, a hash NID) or
    subsequent operations will fail in unpredictable ways.
:type nid: :py:class:`int`

:return: The curve object.
�ascii)rWr��
OBJ_nid2sn�decode)r�r*rs&&&rr�_EllipticCurve.from_nid�s.���3�T�[�[�����)<�=�D�D�W�M�N�Nrc�(�V^8�dQhRRRRRRRR/#)	rr*rrr=r�rrrkr)rs"rrrs(����C��c�����rc
�*�WnW nW0nR#)aA
:param _lib: The :py:mod:`cryptography` binding instance used to
    interface with OpenSSL.

:param _nid: The OpenSSL NID identifying the curve this object
    represents.
:type _nid: :py:class:`int`

:param name: The OpenSSL short name identifying the curve this object
    represents.
:type name: :py:class:`unicode`
N�rQ�_nidr�)r�r*rr�s&&&&rr��_EllipticCurve.__init__s���	��	��	rc��V^8�dQhRR/#�rrrr)rs"rrrs��(�(�#�(rc	�$�RVP:R2#)z<Curve �>�r�r�s&r�__repr__�_EllipticCurve.__repr__s������
�Q�'�'rc��V^8�dQhRR/#�rrrr)rs"rrrs��.�.�C�.rc
��VPPVP4p\P!V\P
4#)z�
Create a new OpenSSL EC_KEY structure initialized to use this curve.

The structure is automatically garbage collected when the Python object
is garbage collected.
)rQ�EC_KEY_new_by_curve_namer-rWr]�EC_KEY_free)r��keys& r�
_to_EC_KEY�_EllipticCurve._to_EC_KEYs3���i�i�0�0����;���w�w�s�D�,�,�-�-rr,)rArBrCrDrEr!r
rrr"rr�r4r<rF�
__classcell__�rs@rrr�sm�����G�	�	��E��E�"�����O��O� �"(�.�.rrzSget_elliptic_curves is deprecated. You should use the APIs in cryptography instead.c��V^8�dQhRR/#)rrrr)rs"rrr#s��5�5�0�5rc�4�\P\4#)as
Return a set of objects representing the elliptic curves supported in the
OpenSSL build in use.

The curve objects have a :py:class:`unicode` ``name`` attribute by which
they identify themselves.

The curve objects are useful as values for the argument accepted by
:py:meth:`Context.set_tmp_ecdh` to specify which elliptical curve should be
used for ECDHE key exchange.
)rr"rQrrr�get_elliptic_curvesrBs�� �.�.�t�4�4rzRget_elliptic_curve is deprecated. You should use the APIs in cryptography instead.c� �V^8�dQhRRRR/#)rr�rrrr)rs"rrr6s��1�1�S�1�^�1rc�f�\4FpVPV8XgKVu#	\RV4h)a8
Return a single curve object selected by name.

See :py:func:`get_elliptic_curves` for information about curve objects.

:param name: The OpenSSL short name identifying the curve object to
    retrieve.
:type name: :py:class:`unicode`

If the named curve is not supported then :py:class:`ValueError` is raised.
zunknown curve name)rBr�rp)r��curves& r�get_elliptic_curverF2s2�� %�&���:�:����L�'��)�4�
0�0rc�a�]tRtRtRtRRltRV3RlltRRltR	R
ltRRlt	R
Rlt
RRltRRltRRlt
RtV;t#)r5iHa�
An X.509 Distinguished Name.

:ivar countryName: The country of the entity.
:ivar C: Alias for  :py:attr:`countryName`.

:ivar stateOrProvinceName: The state or province of the entity.
:ivar ST: Alias for :py:attr:`stateOrProvinceName`.

:ivar localityName: The locality of the entity.
:ivar L: Alias for :py:attr:`localityName`.

:ivar organizationName: The organization name of the entity.
:ivar O: Alias for :py:attr:`organizationName`.

:ivar organizationalUnitName: The organizational unit of the entity.
:ivar OU: Alias for :py:attr:`organizationalUnitName`

:ivar commonName: The common name of the entity.
:ivar CN: Alias for :py:attr:`commonName`.

:ivar emailAddress: The e-mail address of the entity.
c� �V^8�dQhRRRR/#r�r)rs"rr�X509Name.__annotate__bs��=�=�X�=�$�=rc
��\P!VP4p\P!V\P
4VnR#)z~
Create a new X509Name, copying the given X509Name instance.

:param name: The name to copy.
:type name: :py:class:`X509Name`
N)rQ�
X509_NAME_dupr�rWr]�X509_NAME_freer�s&&rr��X509Name.__init__bs0���!�!�$�*�*�-���'�'�$��(;�(;�<��
rc�$�V^8�dQhRRRRRR/#)rr�r�valuerrrkr)rs"rrrIls!��%#�%#��%#�C�%#�D�%#rc		��<�VPR4'd\S	V`	W4#\V4\Jd$\R\V4PR
R24h\P!\V44pV\P8Xd\4\R4h\\P!VP 44F�p\P"!VP V4p\P$!V4p\P&!V4pW78XgKX\P(!VP V4p\P*!V4M	\-V\4'dVP/R4p\P0!VP V\P2VRR^4pV'g
\4R#R# \dELFi;i)�_z$attribute name must be string, not 'z.200�'�No such attribute�utf-8N���)�
startswithr	�__setattr__r�rrnrArQ�OBJ_txt2nid�_byte_string�	NID_undefr�r2�AttributeError�range�X509_NAME_entry_countr��X509_NAME_get_entry�X509_NAME_ENTRY_get_object�OBJ_obj2nid�X509_NAME_delete_entry�X509_NAME_ENTRY_freerm�encode�X509_NAME_add_entry_by_NID�
MBSTRING_UTF8)
r�r�rOr�i�ent�ent_obj�ent_nid�
add_resultrs
&&&      �rrW�X509Name.__setattr__ls�����?�?�3����7�&�t�3�3���:�S� �����K�(�(��.�a�1��
�
���|�D�1�2���$�.�.� �
�$�&�!�!4�5�5��t�1�1�$�*�*�=�>�A��*�*�4�:�:�q�9�C��5�5�c�:�G��&�&�w�/�G��~��1�1�$�*�*�a�@���)�)�#�.��?��e�S�!�!��L�L��)�E��4�4��J�J��T�/�/���B��
�
�� �"���)�
��
�s�
G�G$�#G$c� �V^8�dQhRRRR/#)rr�rr�
str | Noner)rs"rrrI�s��&�&��&�
�&rc
���\P!\V44pV\P8Xd\	4\
R4h\P!VPVR4pVR8XdR#\P!VPV4p\P!V4p\P!R4p\P!We4p\V^8�4\P!V^,V4R,P!R4p\P"!V^,4V# \
dEL	i;i \P"!T^,4i;i)z�
Find attribute. An X509Name object has the following attributes:
countryName (alias C), stateOrProvince (alias ST), locality (alias L),
organization (alias O), organizationalUnit (alias OU), commonName
(alias CN) and more...
rSN�unsigned char**rcrTrU)rQrXrYrZr�r2r[�X509_NAME_get_index_by_NIDr�r^�X509_NAME_ENTRY_get_datarWrX�ASN1_STRING_to_UTF8r[rHr(�OPENSSL_free)	r�r�r�entry_index�entryr^re�data_lengthr�s	&&       r�__getattr__�X509Name.__getattr__�s$�����|�D�1�2���$�.�.� �
�$�&�!�!4�5�5��5�5�d�j�j�#�r�J���"����(�(����[�A���,�,�U�3�����!2�3�
��.�.�}�C����q�(�)�	0��[�[��q�!1�;�?��B�I�I���F�

���m�A�.�/��
��-�
��
��*
���m�A�.�/�s�
D;�(4E
�;E
�	E
�
E,c� �V^8�dQhRRRR/#rr)rs"rrrI�s��@�@�C�@�D�@rc	��\V\4'g\#\P!VP
VP
4^8H#�r�rmr5rrQ�
X509_NAME_cmpr��r�rs&&r�__eq__�X509Name.__eq__�s5���%��*�*�!�!��!�!�$�*�*�e�k�k�:�a�?�?rc� �V^8�dQhRRRR/#rr)rs"rrrI�s��?�?�C�?�D�?rc	��\V\4'g\#\P!VP
VP
4^8#r{r|r~s&&r�__lt__�X509Name.__lt__�s5���%��*�*�!�!��!�!�$�*�*�e�k�k�:�Q�>�>rc��V^8�dQhRR/#r0r)rs"rrrI�s��
�
�#�
rc
�&�\P!RR4p\P!VPV\V44p\
V\P8g4RP\P!V4PR44#)z&
String representation of an X509Name
rKiz<X509Name object '{}'>rT)rWrXrQ�X509_NAME_oneliner�rZr[r\rr�r()r�re�
format_results&  rr4�X509Name.__repr__�sq������3�/�
��.�.��J�J�
�s�=�'9�
�
�	�
����2�3�'�.�.��K�K�
�&�-�-�g�6�
�	
rc��V^8�dQhRR/#r�r)rs"rrrI�s��
/�
/�c�
/rc
�B�\P!VP4#)z�
Return an integer representation of the first four bytes of the
MD5 digest of the DER representation of the name.

This is the Python equivalent of OpenSSL's ``X509_NAME_hash``.

:return: The (integer) hash of this name.
:rtype: :py:class:`int`
)rQ�X509_NAME_hashr�r�s&r�hash�
X509Name.hash�s���"�"�4�:�:�.�.rc��V^8�dQhRR/#�rrrar)rs"rrrI�s��
�
�U�
rc
��\P!R4p\P!VPV4p\V^8�4\P!V^,V4R,p\P!V^,4V#)zn
Return the DER encoding of this name.

:return: The DER encoded form of this name.
:rtype: :py:class:`bytes`
rorc)rWrXrQ�
i2d_X509_NAMEr�r[rHrs)r�re�
encode_resultr�s&   rr��X509Name.der�si�����!2�3�
��*�*�4�:�:�}�E�
��
��*�+����M�!�$4�m�D�Q�G�
����-��*�+��rc��V^8�dQhRR/#)rrzlist[tuple[bytes, bytes]]r)rs"rrrI�s���� 9�rc
�6�.p\\P!VP44F�p\P!VPV4p\P
!V4p\P!V4p\P!V4p\P!V4p\P!\P!V4\P!V44R,pVP\P!V4V34K�	V#)z�
Returns the components of this name, as a sequence of 2-tuples.

:return: The components of this name.
:rtype: :py:class:`list` of ``name, value`` tuples.
rc)r\rQr]r�r^r_rqr`r'rWrHr�r~r�r�)	r�r�rfrg�fname�fvalrr�rOs	&        r�get_components�X509Name.get_components�s������t�1�1�$�*�*�=�>�A��*�*�4�:�:�q�9�C��3�3�C�8�E��0�0��5�D��"�"�5�)�C��?�?�3�'�D��K�K��*�*�4�0�$�2I�2I�$�2O����E�
�M�M�4�;�;�t�,�e�4�5�?� �
r)r�)rArBrCrDrEr�rWrwrr�r4r�r�r�rFr>r?s@rr5r5HsB����0=�%#�%#�N&�P@�?�
�
/�
��rzZX509Extension support in pyOpenSSL is deprecated. You should use the APIs in cryptography.c���]tRtRt$RtRRRllt]RRl4t]PR]PR	]PR
/tR]
R&R
RltRRltRRltRRltRRltRtR#)r4ize
An X.509 v3 certificate extension.

.. deprecated:: 23.3.0
   Use cryptography's X509 APIs instead.
Nc�0�V^8�dQhRRRRRRRRRRR	R
/#)r�	type_namera�criticalr�rO�subjectzX509 | None�issuerrrkr)rs"rr�X509Extension.__annotate__sV��CG�CG��CG��CG��	CG�
�CG��
CG�
�CGrc
���\P!R4p\P!V\P\P\P\P^4\P
!V4Ve3\
V\4'g\R4hVPVn
Ve3\
V\4'g\R4hVPVnV'd
RV,p\P!\PWaV4pV\P8Xd\4\P!V\P4VnR#)ae
Initializes an X509 extension.

:param type_name: The name of the type of extension_ to create.
:type type_name: :py:data:`bytes`

:param bool critical: A flag indicating whether this is a critical
    extension.

:param value: The OpenSSL textual representation of the extension's
    value.
:type value: :py:data:`bytes`

:param subject: Optional X509 certificate to use as subject.
:type subject: :py:class:`X509`

:param issuer: Optional X509 certificate to use as issuer.
:type issuer: :py:class:`X509`

.. _extension: https://www.openssl.org/docs/manmaster/man5/
    x509v3_config.html#STANDARD-EXTENSIONS
zX509V3_CTX*Nzissuer must be an X509 instancez subject must be an X509 instances	critical,)rWrXrQ�X509V3_set_ctxr\�X509V3_set_ctx_nodbrmr1rn�_x509�issuer_cert�subject_cert�X509V3_EXT_nconfr�r]�X509_EXTENSION_free�
_extension)r�r�r�rOr�r��ctx�	extensions&&&&&&  rr��X509Extension.__init__s���<�h�h�}�%��
	
���C����D�I�I�t�y�y�$�)�)�Q�O�	
� � ��%����f�d�+�+�� A�B�B�$�l�l�C�O����g�t�,�,�� B�C�C�&�}�}�C���!�5�(�E��)�)�$�)�)�S�U�K�	���	�	�!� �"��'�'�)�T�-E�-E�F��rc��V^8�dQhRR/#r7r)rs"rrr�]s��
�
�c�
rc	�j�\P!\P!VP44#r)rQr`�X509_EXTENSION_get_objectr�r�s&rr-�X509Extension._nid\s'������*�*�4�?�?�;�
�	
r�email�DNS�URIztyping.ClassVar[dict[int, str]]�	_prefixesc��V^8�dQhRR/#r0r)rs"rrr�hs�� � �s� rc	�X�\P!R\P!VP44p\P
!V\P4p.p\\P!V44F�p\P!W4pVPVP,p\P!VPPPVPPP 4R,P#R4pVP%VR,V,4K�	RP/V4# \&dO\)4p\P*!Yt4TP%\-T4P#R44EK,i;i)zGENERAL_NAMES*rcrT�:z, )rWr}rQ�X509V3_EXT_d2ir�r]�GENERAL_NAMES_freer\�sk_GENERAL_NAME_num�sk_GENERAL_NAME_valuer�r�rH�d�ia5r^�lengthr(r��KeyErrorr_�GENERAL_NAME_printrg�join)r��names�partsrfr��labelrOrMs&       r�_subjectAltNameString�#X509Extension._subjectAltNameStringhs1���	�	��d�1�1�$�/�/�B�
������t�6�6�7�����t�/�/��6�7�A��-�-�e�7�D�

2����t�y�y�1�����D�F�F�J�J�O�O�T�V�V�Z�Z�5F�5F�G����&��/�����U�S�[�5�0�1�8��y�y������
B�"�n���'�'��2����^�C�0�7�7��@�A�A�
B�s�E�AF)�(F)c��V^8�dQhRR/#r0r)rs"rrr�~s��3�3��3rc
��\PVP8XdVP4#\	4p\P
!WP^^4p\V^8g4\V4PR4#)z6
:return: a nice text representation of the extension
rT)
rQ�NID_subject_alt_namer-r�r_�X509V3_EXT_printr�r[rgr()r�rM�print_results&  r�__str__�X509Extension.__str__~sg���$�$��	�	�1��-�-�/�/��n���,�,�S�/�/�1�a�H�����)�*��c�"�)�)�'�2�2rc��V^8�dQhRR/#r�r)rs"rrr��s��A�A�d�Arc
�B�\P!VP4#)zS
Returns the critical field of this X.509 extension.

:return: The critical field.
)rQ�X509_EXTENSION_get_criticalr�r�s&r�get_critical�X509Extension.get_critical�s���/�/����@�@rc��V^8�dQhRR/#r�r)rs"rrr��s�����rc
���\P!VP4p\P!V4p\P!V4pV\
P8wd\
P!V4#R#)z�
Returns the short type name of this X.509 extension.

The result is a byte string such as :py:const:`b"basicConstraints"`.

:return: The short type name.
:rtype: :py:data:`bytes`

.. versionadded:: 0.12
sUNDEF)rQr�r�r`r'rWr\r�)r��objr�bufs&   r�get_short_name�X509Extension.get_short_name�sV���,�,�T�_�_�=�����s�#���o�o�c�"���$�)�)���;�;�s�#�#�rc��V^8�dQhRR/#r�r)rs"rrr��s��
:�
:�%�
:rc
��\P!VP4p\P!RV4p\P
!V4p\P!V4p\P!W44R,#)z�
Returns the data of the X509 extension, encoded as ASN.1.

:return: The ASN.1 encoded data of this X509 extension.
:rtype: :py:data:`bytes`

.. versionadded:: 0.12
r|rc)rQ�X509_EXTENSION_get_datar�rWr}r�r~rH)r��octet_resultr��char_result�
result_lengths&    r�get_data�X509Extension.get_data�s\���3�3�D�O�O�D���	�	�.�,�?�
��0�0��?���/�/�
�>�
��{�{�;�6�q�9�9r)r��NN)rArBrCrDrEr��propertyr-rQ�	GEN_EMAIL�GEN_DNS�GEN_URIr��__annotations__r�r�r�r�r�rFrrrr4r4sn��
�CG�J�
��
�	
�������e����e�2�I�.�� �,3�A��,
:�
:rzPCSR support in pyOpenSSL is deprecated. You should use the APIs in cryptography.c��]tRtRtRtRRltRRlt]RRl4tR	R
lt	RRlt
R
RltRRltRRlt
RRltRRltRRltRRltRtR#)r6i�z~
An X.509 certificate signing requests.

.. deprecated:: 24.2.0
   Use `cryptography.x509.CertificateSigningRequest` instead.
c��V^8�dQhRR/#r�r)rs"rr�X509Req.__annotate__�s����$�rc	��\P!4p\P!V\P4VnVP
^4R#�rN)rQ�X509_REQ_newrWr]�
X509_REQ_free�_req�set_version)r��reqs& rr��X509Req.__init__�s6�����!���G�G�C��!3�!3�4��	�����rc��V^8�dQhRR/#)rr�x509.CertificateSigningRequestr)rs"rrr��s��&�&�!?�&rc
�>�^RIHp\\V4pV!V4#)z�
Export as a ``cryptography`` certificate signing request.

:rtype: ``cryptography.x509.CertificateSigningRequest``

.. versionadded:: 17.1.0
)�load_der_x509_csr)�cryptography.x509r��"_dump_certificate_request_internalr-)r�r�r�s&  r�to_cryptography�X509Req.to_cryptography�s��	8�0���E�� ��%�%rc� �V^8�dQhRRRR/#)r�
crypto_reqr�rr6r)rs"rrr��s ��F�F�7�F�	�Frc
��\V\P4'g\R4h^RIHpVP
VP4p\\V4#)z�
Construct based on a ``cryptography`` *crypto_req*.

:param crypto_req: A ``cryptography`` X.509 certificate signing request
:type crypto_req: ``cryptography.x509.CertificateSigningRequest``

:rtype: X509Req

.. versionadded:: 17.1.0
z%Must be a certificate signing request�r�)
rmr �CertificateSigningRequestrnr�r�r�r��"_load_certificate_request_internalr-)r�r�r�r�s&&  r�from_cryptography�X509Req.from_cryptography�sG���*�d�&D�&D�E�E��C�D�D�I��%�%�h�l�l�3��1�-��E�Erc� �V^8�dQhRRRR/#�rr�r3rrkr)rs"rrr��s��
)�
)�t�
)��
)rc
�x�\P!VPVP4p\	V^8H4R#)z�
Set the public key of the certificate signing request.

:param pkey: The public key to use.
:type pkey: :py:class:`PKey`

:return: ``None``
N)rQ�X509_REQ_set_pubkeyr�r�r[�r�r�rqs&& r�
set_pubkey�X509Req.set_pubkey�s*���-�-�d�i�i����D�
��
�a��(rc��V^8�dQhRR/#�rrr3r)rs"rrr��s����D�rc
�D�\P\4p\P!VP4Vn\
VP
\P8g4\P!VP
\P4VnRVnV#)zk
Get the public key of the certificate signing request.

:return: The public key.
:rtype: :py:class:`PKey`
T)r3�__new__rQ�X509_REQ_get_pubkeyr�r�r[rWr\r]r�r�r�s& r�
get_pubkey�X509Req.get_pubkey�sf���|�|�D�!���-�-�d�i�i�8��
���
�
�d�i�i�/�0��W�W�T�Z�Z��);�);�<��
� ����rc� �V^8�dQhRRRR/#�r�versionr=rrkr)rs"rrr�	s��)�)�3�)�4�)rc
���\V\4'g\R4hV^8wd\R4h\P
!VPV4p\V^8H4R#)z�
Set the version subfield (RFC 2986, section 4.1) of the certificate
request.

:param int version: The version number.
:return: ``None``
zversion must be an intz9Invalid version. The only valid version for X509Req is 0.N)rmr=rnrprQ�X509_REQ_set_versionr�r[)r�rrqs&& rr��X509Req.set_version	sX���'�3�'�'��4�5�5��a�<��K��
��.�.�t�y�y�'�B�
��
�a��(rc��V^8�dQhRR/#r�r)rs"rrr�s��4�4�S�4rc
�B�\P!VP4#)z�
Get the version subfield (RFC 2459, section 4.1.2.1) of the certificate
request.

:return: The value of the version subfield.
:rtype: :py:class:`int`
)rQ�X509_REQ_get_versionr�r�s&r�get_version�X509Req.get_versions���(�(����3�3rc��V^8�dQhRR/#�rrr5r)rs"rrr�$s����X�rc
���\P\4p\P!VP4Vn\
VP
\P8g4Wn	V#)a�
Return the subject of this certificate signing request.

This creates a new :class:`X509Name` that wraps the underlying subject
name field on the certificate signing request. Modifying it will modify
the underlying signing request, and will have the effect of modifying
any other :class:`X509Name` that refers to this subject.

:return: The subject of this certificate signing request.
:rtype: :class:`X509Name`
)
r5r
rQ�X509_REQ_get_subject_namer�r�r[rWr\�_ownerr�s& r�get_subject�X509Req.get_subject$sK������)���3�3�D�I�I�>��
���
�
�d�i�i�/�0����rc� �V^8�dQhRRRR/#�r�
extensionszIterable[X509Extension]rrkr)rs"rrr�:s��)�)�)@�)�T�)rc
���\P!R\^R7\P!4p\V\P8g4\P!V\P4pVFDp\V\4'g\R4h\P!W#P4KF	\P!VP V4p\V^8H4R#)z�
Add extensions to the certificate signing request.

:param extensions: The X.509 extensions to add.
:type extensions: iterable of :py:class:`X509Extension`
:return: ``None``
��This API is deprecated and will be removed in a future version of pyOpenSSL. You should use pyca/cryptography's X.509 APIs instead.��
stacklevel�+One of the elements is not an X509ExtensionN)�warnings�warn�DeprecationWarningrQ�sk_X509_EXTENSION_new_nullr[rWr\r]�sk_X509_EXTENSION_freermr4rp�sk_X509_EXTENSION_pushr��X509_REQ_add_extensionsr�)r�r%�stack�extrjs&&   r�add_extensions�X509Req.add_extensions:s���	�
�
�&�
��	
��/�/�1�������*�+�����t�:�:�;���C��c�=�1�1� �!N�O�O�
�'�'��~�~�>���1�1�$�)�)�U�C�
��
�a��(rc��V^8�dQhRR/#)rrzlist[X509Extension]r)rs"rrr�[s��$�$� 3�$rc
��\P!R\^R7.p\P!VP
4p\P!VR4p\\P!V44F�p\P\4p\P!\P!W#44p\P!V\P4VnVP!V4K�	V#)z�
Get X.509 extensions in the certificate signing request.

:return: The X.509 extensions in this request.
:rtype: :py:class:`list` of :py:class:`X509Extension` objects.

.. versionadded:: 0.15
r'r(c�v�\P!V\P!\PR44#)r�)rQ�sk_X509_EXTENSION_pop_freerW�	addressof�
_original_lib)�xs&rr�(X509Req.get_extensions.<locals>.<lambda>rs'��d�5�5�����t�1�1�3H�I�r)r+r,r-rQ�X509_REQ_get_extensionsr�rWr]r\�sk_X509_EXTENSION_numr4r
�X509_EXTENSION_dup�sk_X509_EXTENSION_valuer�r�r�)r��exts�native_exts_objrfr3r�s&     r�get_extensions�X509Req.get_extensions[s���	�
�
�&�
��	
����6�6�t�y�y�A���'�'��
�
���t�1�1�/�B�C�A��'�'�
�6�C��/�/��,�,�_�@��I�"�W�W�Y��0H�0H�I�C�N��K�K���
D��rc�$�V^8�dQhRRRRRR/#�rr�r3�digestrrrkr)rs"rrr��s!��)�)��)�s�)�t�)rc
�l�VP'd\R4hVP'g\R4h\P!\V44pV\P8Xd\R4h\P!VPVPV4p\V^8�4R#)a!
Sign the certificate signing request with this key and digest type.

:param pkey: The key pair to sign with.
:type pkey: :py:class:`PKey`
:param digest: The name of the message digest to use for the signature,
    e.g. :py:data:`"sha256"`.
:type digest: :py:class:`str`
:return: ``None``
zKey has only public part�Key is uninitialized�No such digest methodN)r�rpr�rQ�EVP_get_digestbynamerYrWr\�
X509_REQ_signr�r�r[)r�r�rH�
digest_obj�sign_results&&&  r�sign�X509Req.sign�s��������7�8�8�� � � ��3�4�4��.�.�|�F�/C�D�
�����"��4�5�5��(�(����D�J�J�
�K����a��(rc� �V^8�dQhRRRR/#)rr�r3rr�r)rs"rrr��s����4��D�rc
��\V\4'g\R4h\P!VP
VP4pV^8:d\4V#)a
Verifies the signature on this certificate signing request.

:param PKey key: A public key.

:return: ``True`` if the signature is correct.
:rtype: bool

:raises OpenSSL.crypto.Error: If the signature is invalid or there is a
    problem verifying the signature.
�pkey must be a PKey instance)rmr3rnrQ�X509_REQ_verifyr�r�r�)r�r�r�s&& r�verify�X509Req.verify�sI���$��%�%��:�;�;��%�%�d�i�i����<���Q�;� �"��
r)r�N)rArBrCrDrEr�r�rrrrr�rr!r4rDrPrVrFrrrr6r6�s[��
��&��F��F�*
)��)�"4��,)�B$�L)�0�rc��]tRtRtRtRRlt]RRl4tRRlt]R	R
l4t	RRlt
R
RltRRltRRlt
RRltRRltRRltRRltRRltRRltRR ltR!R"ltR#R$ltR%R&ltR'R(ltR)R*ltR+R,ltR-R.ltR/R0ltR1R2ltR3R4ltR5R6ltR7R8lt R9R:lt!R;R<lt"R=R>lt#R?R@lt$RARBlt%RCt&RD#)Er1i�z
An X.509 certificate.
c��V^8�dQhRR/#r�r)rs"rr�X509.__annotate__�s��;�;�$�;rc	��\P!4p\V\P8g4\P
!V\P4Vn\4Vn	\4Vn
R#r)rQ�X509_newr[rWr\r]�	X509_freer�r��_issuer_invalidator�_subject_invalidator)r�r s& rr��
X509.__init__�sJ���}�}������	�	�)�*��W�W�T�4�>�>�2��
�#7�#9�� �$8�$:��!rc� �V^8�dQhRRRR/#)rr rrr1r)rs"rrrZ�s����c��d�rc	��VPV4p\P!V\P4Vn\
4Vn\
4VnV#r)	r
rWr]rQr]r�r�r^r_)r�r �certs&& r�_from_raw_x509_ptr�X509._from_raw_x509_ptr�sA���{�{�3����W�W�T�4�>�>�2��
�#7�#9�� �$8�$:��!��rc��V^8�dQhRR/#)rr�x509.Certificater)rs"rrrZ�s��.�.�!1�.rc
�>�^RIHp\\V4pV!V4#)zp
Export as a ``cryptography`` certificate.

:rtype: ``cryptography.x509.Certificate``

.. versionadded:: 17.1.0
)�load_der_x509_certificate)r�ri�dump_certificater-)r�rir�s&  rr��X509.to_cryptography�s��	@��}�d�3��(��-�-rc� �V^8�dQhRRRR/#)r�crypto_certrgrr1r)rs"rrrZ�s��4�4�,<�4��4rc
��\V\P4'g\R4h^RIHpVP
VP4p\\V4#)z�
Construct based on a ``cryptography`` *crypto_cert*.

:param crypto_key: A ``cryptography`` X.509 certificate.
:type crypto_key: ``cryptography.x509.Certificate``

:rtype: X509

.. versionadded:: 17.1.0
zMust be a certificater�)
rmr �Certificaternr�r�r�r��load_certificater-)r�rmr�r�s&&  rr�X509.from_cryptography�sG���+�t�'7�'7�8�8��3�4�4�I��&�&�x�|�|�4���
�s�3�3rc� �V^8�dQhRRRR/#rr)rs"rrrZ�s��
I�
I�3�
I�4�
Irc
��\V\4'g\R4h\\P
!VPV4^8H4R#)z�
Set the version number of the certificate. Note that the
version value is zero-based, eg. a value of 0 is V1.

:param version: The version number of the certificate.
:type version: :py:class:`int`

:return: ``None``
zversion must be an integerN)rmr=rnr[rQ�X509_set_versionr�)r�rs&&rr��X509.set_version�s;���'�3�'�'��8�9�9���-�-�d�j�j�'�B�a�G�Hrc��V^8�dQhRR/#r�r)rs"rrrZ�s��1�1�S�1rc
�B�\P!VP4#)zx
Return the version number of the certificate.

:return: The version number of the certificate.
:rtype: :py:class:`int`
)rQ�X509_get_versionr�r�s&rr�X509.get_version�s���$�$�T�Z�Z�0�0rc��V^8�dQhRR/#rr)rs"rrrZ�s��
�
�D�
rc
�J�\P\4p\P!VP4VnVP
\P8Xd\4\P!VP
\P4VnRVnV#)z[
Get the public key of the certificate.

:return: The public key.
:rtype: :py:class:`PKey`
T)r3r
rQ�X509_get_pubkeyr�r�rWr\r�r]r�r�r�s& rr�X509.get_pubkey�sg���|�|�D�!���)�)�$�*�*�5��
��:�:����"� �"��W�W�T�Z�Z��);�);�<��
� ����rc� �V^8�dQhRRRR/#rr)rs"rrrZs��
)�
)�t�
)��
)rc
��\V\4'g\R4h\P!VP
VP4p\V^8H4R#)z}
Set the public key of the certificate.

:param pkey: The public key.
:type pkey: :py:class:`PKey`

:return: :py:data:`None`
rTN)rmr3rnrQ�X509_set_pubkeyr�r�r[rs&& rr�X509.set_pubkeysC���$��%�%��:�;�;��)�)�$�*�*�d�j�j�A�
��
�a��(rc�$�V^8�dQhRRRRRR/#rGr)rs"rrrZs!��)�)��)�s�)�t�)rc
��\V\4'g\R4hVP'd\	R4hVP
'g\	R4h\P!\V44pV\P8Xd\	R4h\P!VPVPV4p\V^8�4R#)z�
Sign the certificate with this key and digest type.

:param pkey: The key to sign with.
:type pkey: :py:class:`PKey`

:param digest: The name of the message digest to use.
:type digest: :py:class:`str`

:return: :py:data:`None`
rTzKey only has public partrJrKN)rmr3rnr�rpr�rQrLrYrWr\�	X509_signr�r�r[)r�r�rH�evp_mdrOs&&&  rrP�	X509.signs����$��%�%��:�;�;������7�8�8�� � � ��3�4�4��*�*�<��+?�@���T�Y�Y���4�5�5��n�n�T�Z�Z����V�D����a��(rc��V^8�dQhRR/#r�r)rs"rrrZ7s��1�1��1rc
��\P!VP4p\P!R4p\P
!V\P\PV4\P!V^,4pV\P8Xd\R4h\P!\P!V44#)z�
Return the signature algorithm used in the certificate.

:return: The name of the algorithm.
:rtype: :py:class:`bytes`

:raises ValueError: If the signature algorithm is undefined.

.. versionadded:: 0.13
zASN1_OBJECT **zUndefined signature algorithm)rQ�X509_get0_tbs_sigalgr�rWrX�X509_ALGOR_get0r\r`rZrpr��
OBJ_nid2ln)r��sig_alg�algrs&   r�get_signature_algorithm�X509.get_signature_algorithm7s����+�+�D�J�J�7���h�h�'�(�����S�$�)�)�T�Y�Y��@����s�1�v�&���$�.�.� ��<�=�=��{�{�4�?�?�3�/�0�0rc� �V^8�dQhRRRR/#)r�digest_namerrrar)rs"rrrZJs��
�
�#�
�%�
rc
�$�\P!\V44pV\P8Xd\R4h\P!R\P4p\P!R^4p\V4V^&\P!VPW#V4p\V^8H4RP\P!W4^,4Uu.uFp\V4P4NK	up4#uupi)z�
Return the digest of the X509 object.

:param digest_name: The name of the digest algorithm to use.
:type digest_name: :py:class:`str`

:return: The digest of the object, formatted as
    :py:const:`b":"`-delimited hex pairs.
:rtype: :py:class:`bytes`
rKzunsigned char[]zunsigned int[]�:)rQrLrYrWr\rprX�EVP_MAX_MD_SIZErZ�X509_digestr�r[r�rHr�upper)r�r�rHrer��
digest_result�chs&&     rrH�X509.digestJs����*�*�<��+D�E���T�Y�Y���4�5�5����!2�D�4H�4H�I�
����!1�1�5�
��}�-�
�a���(�(��J�J��}�
�
�	�
��*�+��y�y��+�+�m�1�5E�F�
�F�B��"�
�#�#�%�F�
�
�	
��
s�$"D
c��V^8�dQhRR/#r�r)rs"rrrZis��7�7�3�7rc
�B�\P!VP4#)za
Return the hash of the X509 subject.

:return: The hash of the subject.
:rtype: :py:class:`int`
)rQ�X509_subject_name_hashr�r�s&r�subject_name_hash�X509.subject_name_hashis���*�*�4�:�:�6�6rc� �V^8�dQhRRRR/#)r�serialr=rrkr)rs"rrrZrs��)�)��)��)rc
��\V\4'g\R4h\V4R,pVP	R4p\
P!R4p\P!WC4p\V\
P8g4\P!V^,\
P4p\P!V^,4\V\
P8g4\
P!V\P4p\P!VP V4p\V^8H4R#)z�
Set the serial number of the certificate.

:param serial: The new serial number.
:type serial: :py:class:`int`

:return: :py:data`None`
zserial must be an integer:rNNr&zBIGNUM**N)rmr=rn�hexrcrWrXrQ�	BN_hex2bnr[r\�BN_to_ASN1_INTEGERr�r]�ASN1_INTEGER_free�X509_set_serialNumberr�)r�r��
hex_serial�hex_serial_bytes�
bignum_serialr��asn1_serialrqs&&      r�set_serial_number�X509.set_serial_numberrs����&�#�&�&��7�8�8���[��_�
�%�,�,�W�5������,�
����
�@����$�)�)�+�,��-�-�m�A�.>��	�	�J�����]�1�%�&���t�y�y�0�1��g�g�k�4�+A�+A�B���/�/��
�
�K�H�
��
�a��(rc��V^8�dQhRR/#r�r)rs"rrrZ�s��(�(�3�(rc
���\P!VP4p\P!V\P
4p\P!V4p\P!V4p\V^4pV\P!V4\P!V4# \P!T4i;i \P!T4i;i)zX
Return the serial number of this certificate.

:return: The serial number.
:rtype: int
)rQ�X509_get_serialNumberr��ASN1_INTEGER_to_BNrWr\�	BN_bn2hexr�r=rsr�)r�r�r�r��hexstring_serialr�s&     r�get_serial_number�X509.get_serial_number�s����0�0����<���/�/��T�Y�Y�G�
�		(����
�6�J�
.�#'�;�;�z�#:� ��-�r�2����!�!�*�-��L�L��'���!�!�*�-���L�L��'�s$�C	�#B.�C	�.C�C	�	C!c� �V^8�dQhRRRR/#�r�amountr=rrkr)rs"rrrZ�s��/�/�#�/�$�/rc
��\V\4'g\R4h\P!VP
4p\P!W!4R#)z�
Adjust the time stamp on which the certificate stops being valid.

:param int amount: The number of seconds by which to adjust the
    timestamp.
:return: ``None``
�amount must be an integerN)rmr=rnrQ�X509_getm_notAfterr��X509_gmtime_adj)r�r��notAfters&& r�gmtime_adj_notAfter�X509.gmtime_adj_notAfter�s?���&�#�&�&��7�8�8��*�*�4�:�:�6�����X�.rc� �V^8�dQhRRRR/#r�r)rs"rrrZ�s��0�0�3�0�4�0rc
��\V\4'g\R4h\P!VP
4p\P!W!4R#)z�
Adjust the timestamp on which the certificate starts being valid.

:param amount: The number of seconds by which to adjust the timestamp.
:return: ``None``
r�N)rmr=rnrQ�X509_getm_notBeforer�r�)r�r��	notBefores&& r�gmtime_adj_notBefore�X509.gmtime_adj_notBefore�s?���&�#�&�&��7�8�8��,�,�T�Z�Z�8�	����Y�/rc��V^8�dQhRR/#r�r)rs"rrrZ�s��"�"�T�"rc
�<�VP4pVf\R4hVPR4p\PP	VR4p\P
Pp\PPV4PRR7pW58#)z�
Check whether the certificate has expired.

:return: ``True`` if the certificate has expired, ``False`` otherwise.
:rtype: bool
NzUnable to determine notAfterrTz
%Y%m%d%H%M%SZ)�tzinfo)	�get_notAfterrpr(�datetime�strptime�timezone�utc�now�replace)r��
time_bytes�time_string�	not_after�UTC�utcnows&     r�has_expired�X509.has_expired�s����&�&�(�
����;�<�<� �'�'��0���%�%�.�.�{�O�L�	����#�#���"�"�&�&�s�+�3�3�4�3�@���!�!rc� �V^8�dQhRRRR/#)r�whichrrrIr)rs"rrrZ�s��1�1��1��1rc	�8�\V!VP44#r)r�r�)r�r�s&&r�_get_boundary_time�X509._get_boundary_time�s���e�D�J�J�/�0�0rc��V^8�dQhRR/#�rrrIr)rs"rrrZ�s��A�A�|�Arc
�@�VP\P4#)z�
Get the timestamp at which the certificate starts being valid.

The timestamp is formatted as an ASN.1 TIME::

    YYYYMMDDhhmmssZ

:return: A timestamp string, or ``None`` if there is none.
:rtype: bytes or NoneType
)r�rQr�r�s&r�
get_notBefore�X509.get_notBefore�s���&�&�t�'?�'?�@�@rc�$�V^8�dQhRRRRRR/#)rr�zCallable[..., Any]rjrarrkr)rs"rrrZ�s$��7�7�'�7�/4�7�	
�7rc	�:�\V!VP4V4#r)rrr�)r�r�rjs&&&r�_set_boundary_time�X509._set_boundary_time�s���e�D�J�J�/��6�6rc� �V^8�dQhRRRR/#�rrjrarrkr)rs"rrrZ�s��G�G�%�G�D�Grc
�B�VP\PV4#)z�
Set the timestamp at which the certificate starts being valid.

The timestamp is formatted as an ASN.1 TIME::

    YYYYMMDDhhmmssZ

:param bytes when: A timestamp string.
:return: ``None``
)r�rQr��r�rjs&&r�
set_notBefore�X509.set_notBefore�s���&�&�t�'?�'?��F�Frc��V^8�dQhRR/#r�r)rs"rrrZ�s��@�@�l�@rc
�@�VP\P4#)z�
Get the timestamp at which the certificate stops being valid.

The timestamp is formatted as an ASN.1 TIME::

    YYYYMMDDhhmmssZ

:return: A timestamp string, or ``None`` if there is none.
:rtype: bytes or NoneType
)r�rQr�r�s&rr��X509.get_notAfter�s���&�&�t�'>�'>�?�?rc� �V^8�dQhRRRR/#r�r)rs"rrrZ�s��F�F��F�4�Frc
�B�VP\PV4#)z�
Set the timestamp at which the certificate stops being valid.

The timestamp is formatted as an ASN.1 TIME::

    YYYYMMDDhhmmssZ

:param bytes when: A timestamp string.
:return: ``None``
)r�rQr�r�s&&r�set_notAfter�X509.set_notAfter�s���&�&�t�'>�'>��E�Erc� �V^8�dQhRRRR/#)rr�rrr5r)rs"rrrZ
s��	�	�s�	�x�	rc	��\P\4pV!VP4Vn\	VP\
P8g4WnV#r)r5r
r�r�r[rWr\r )r�r�r�s&& r�	_get_name�X509._get_name
sC������)���4�:�:�&��
���
�
�d�i�i�/�0����rc�$�V^8�dQhRRRRRR/#)rr�rr�r5rrkr)rs"rrrZs!��)�)�s�)�(�)�t�)rc	��\V\4'g\R4hV!VPVP4p\V^8H4R#)zname must be an X509NameN)rmr5rnr�r�r[)r�r�r�rqs&&& r�	_set_name�X509._set_names;���$��)�)��6�7�7��4�:�:�t�z�z�2�
��
�a��(rc��V^8�dQhRR/#rr)rs"rrrZs����H�rc
�z�VP\P4pVPP	V4V#)ae
Return the issuer of this certificate.

This creates a new :class:`X509Name` that wraps the underlying issuer
name field on the certificate. Modifying it will modify the underlying
certificate, and will have the effect of modifying any other
:class:`X509Name` that refers to this issuer.

:return: The issuer of this certificate.
:rtype: :class:`X509Name`
)r�rQ�X509_get_issuer_namer^r�r�s& r�
get_issuer�X509.get_issuers1���~�~�d�7�7�8��� � �$�$�T�*��rc� �V^8�dQhRRRR/#)rr�r5rrkr)rs"rrrZ+s��
)�
)��
)�d�
)rc
�z�VP\PV4VPP	4R#)zw
Set the issuer of this certificate.

:param issuer: The issuer.
:type issuer: :py:class:`X509Name`

:return: ``None``
N)r�rQ�X509_set_issuer_namer^r�)r�r�s&&r�
set_issuer�X509.set_issuer+s*��	
���t�0�0�&�9�� � �&�&�(rc��V^8�dQhRR/#rr)rs"rrrZ7s����X�rc
�z�VP\P4pVPP	V4V#)ai
Return the subject of this certificate.

This creates a new :class:`X509Name` that wraps the underlying subject
name field on the certificate. Modifying it will modify the underlying
certificate, and will have the effect of modifying any other
:class:`X509Name` that refers to this subject.

:return: The subject of this certificate.
:rtype: :class:`X509Name`
)r�rQ�X509_get_subject_namer_r�r�s& rr!�X509.get_subject7s1���~�~�d�8�8�9���!�!�%�%�d�+��rc� �V^8�dQhRRRR/#)rr�r5rrkr)rs"rrrZGs��
*�
*�8�
*��
*rc
�z�VP\PV4VPP	4R#)z{
Set the subject of this certificate.

:param subject: The subject.
:type subject: :py:class:`X509Name`

:return: ``None``
N)r�rQ�X509_set_subject_namer_r�)r�r�s&&r�set_subject�X509.set_subjectGs*��	
���t�1�1�7�;��!�!�'�'�)rc��V^8�dQhRR/#r�r)rs"rrrZSs��	3�	3�S�	3rc
�B�\P!VP4#)z�
Get the number of extensions on this certificate.

:return: The number of extensions.
:rtype: :py:class:`int`

.. versionadded:: 0.12
)rQ�X509_get_ext_countr�r�s&r�get_extension_count�X509.get_extension_countSs���&�&�t�z�z�2�2rc� �V^8�dQhRRRR/#r$r)rs"rrrZ^s��-�-�)@�-�T�-rc
��\P!R\^R7VF^p\V\4'g\R4h\P!VPVPR4p\V^8H4K`	R#)z�
Add extensions to the certificate.

:param extensions: The extensions to add.
:type extensions: An iterable of :py:class:`X509Extension` objects.
:return: ``None``
r'r(r*NrU)r+r,r-rmr4rprQ�X509_add_extr�r�r[)r�r%r3rjs&&  rr4�X509.add_extensions^sj��	�
�
�&�
��	
��C��c�=�1�1� �!N�O�O��*�*�4�:�:�s�~�~�r�J�J��J�!�O�,�rc� �V^8�dQhRRRR/#)r�indexr=rr4r)rs"rrrZws����3��=�rc
��\P!R\^R7\P	\4p\
P!VPV4VnVP\P8Xd\R4h\
P!VP4p\P!V\
P4VnV#)a�
Get a specific extension of the certificate by index.

Extensions on a certificate are kept in order. The index
parameter selects which extension will be returned.

:param int index: The index of the extension to retrieve.
:return: The extension at the specified index.
:rtype: :py:class:`X509Extension`
:raises IndexError: If the extension index was out of bounds.

.. versionadded:: 0.12
r'r(zextension index out of bounds)r+r,r-r4r
rQ�X509_get_extr�r�rWr\�
IndexErrorr@r]r�)r�rr3r�s&&  r�
get_extension�X509.get_extensionws���	�
�
�&�
��	
��#�#�M�2���*�*�4�:�:�u�=����>�>�T�Y�Y�&��<�=�=��+�+�C�N�N�;�	�����D�,D�,D�E����
r)r^r_r�N)'rArBrCrDrEr�rrdr�rr�rrrrPr�rHr�r�r�r�r�r�r�r�r�r�r�r�r�r�r�rr!r
rr4rrFrrrr1r1�s����;�����.��4��4�&
I�1�
�
)�)�81�&
�>7�)�8(�(/�0�"�"1�A�7�
G�@�F�	�)�� 
)�� 
*�	3�-�2�rc�p�]tRtRt$Rt]PtR]R&]Pt
R]R&]PtR]R&]PtR]R&]PtR]R&]P"tR]R	&]P&tR]R
&]P*tR]R&]P.tR]R&]P2tR]R
&RtR#)r:i�z�
Flags for X509 verification, used to change the behavior of
:class:`X509Store`.

See `OpenSSL Verification Flags`_ for details.

.. _OpenSSL Verification Flags:
    https://www.openssl.org/docs/manmaster/man3/X509_VERIFY_PARAM_set_flags.html
r=�	CRL_CHECK�
CRL_CHECK_ALL�IGNORE_CRITICAL�X509_STRICT�ALLOW_PROXY_CERTS�POLICY_CHECK�EXPLICIT_POLICY�INHIBIT_MAP�CHECK_SS_SIGNATURE�
PARTIAL_CHAINrN)rArBrCrDrErQ�X509_V_FLAG_CRL_CHECKrr��X509_V_FLAG_CRL_CHECK_ALLr�X509_V_FLAG_IGNORE_CRITICALr�X509_V_FLAG_X509_STRICTr �X509_V_FLAG_ALLOW_PROXY_CERTSr!�X509_V_FLAG_POLICY_CHECKr"�X509_V_FLAG_EXPLICIT_POLICYr#�X509_V_FLAG_INHIBIT_MAPr$�X509_V_FLAG_CHECK_SS_SIGNATUREr%�X509_V_FLAG_PARTIAL_CHAINr&rFrrrr:r:�s�����/�/�I�s�/��7�7�M�3�7��;�;�O�S�;��3�3�K��3�!�?�?��s�?��5�5�L�#�5��;�;�O�S�;��3�3�K��3�"�A�A���A��7�7�M�3�7rc�f�]tRtRtRtRRltRRltRRltR	R
ltRRlt	RRRllt
RtR
#)r7i�a�
An X.509 store.

An X.509 store is used to describe a context in which to verify a
certificate. A description of a context may include a set of certificates
to trust, a set of certificate revocation lists, verification flags and
more.

An X.509 store, being only a description, cannot be used by itself to
verify a certificate. To carry out the actual verification process, see
:class:`X509StoreContext`.
c��V^8�dQhRR/#r�r)rs"rr�X509Store.__annotate__�s��;�;�$�;rc	��\P!4p\P!V\P4VnR#r)rQ�X509_STORE_newrWr]�X509_STORE_free�_store�r��stores& rr��X509Store.__init__�s(���#�#�%���g�g�e�T�%9�%9�:��rc� �V^8�dQhRRRR/#)rrcr1rrkr)rs"rrr3�s��"�"�T�"�d�"rc
��\V\4'g\4h\P!VP
VP4p\V^8H4R#)a�
Adds a trusted certificate to this store.

Adding a certificate with this method adds this certificate as a
*trusted* certificate.

:param X509 cert: The certificate to add to this store.

:raises TypeError: If the certificate is not an :class:`X509`.

:raises OpenSSL.crypto.Error: If OpenSSL was unhappy with your
    certificate.

:return: ``None`` if the certificate was added successfully.
N)rmr1rnrQ�X509_STORE_add_certr7r�r[)r�rcr�s&& r�add_cert�X509Store.add_cert�s?�� �$��%�%��+���&�&�t�{�{�D�J�J�?����q��!rc� �V^8�dQhRRRR/#)r�crlzx509.CertificateRevocationListrrkr)rs"rrr3�s��H�H�9�H�d�Hrc
���\V\P4'd�^RIHp\VP
VP44p\P!V\P4p\V\P8g4\P!V\P4pM\R4h\\P !VP"V4^8g4R#)a�
Add a certificate revocation list to this store.

The certificate revocation lists added to a store will only be used if
the associated flags are configured to check certificate revocation
lists.

.. versionadded:: 16.1.0

:param crl: The certificate revocation list to add to this store.
:type crl: ``cryptography.x509.CertificateRevocationList``
:return: ``None`` if the certificate revocation list was added
    successfully.
r�z?CRL must be of type cryptography.x509.CertificateRevocationListN)rmr �CertificateRevocationListr�r�r_r�r�rQ�d2i_X509_CRL_biorWr\r[r]�
X509_CRL_freern�X509_STORE_add_crlr7)r�rAr�rM�openssl_crls&&   r�add_crl�X509Store.add_crl�s����c�4�9�9�:�:�M��s�/�/����=�>�C��/�/��T�Y�Y�?�K��K�4�9�9�4�5��'�'�+�t�'9�'9�:�C��>��
�
	��/�/����S�A�Q�F�Grc� �V^8�dQhRRRR/#)r�flagsr=rrkr)rs"rrr3�s��L�L�s�L�t�Lrc
�`�\\P!VPV4^8g4R#)ab
Set verification flags to this store.

Verification flags can be combined by oring them together.

.. note::

  Setting a verification flag sometimes requires clients to add
  additional information to the store, otherwise a suitable error will
  be raised.

  For example, in setting flags to enable CRL checking a
  suitable CRL must be added to the store otherwise an error will be
  raised.

.. versionadded:: 16.1.0

:param int flags: The verification flags to set on this store.
    See :class:`X509StoreFlags` for available constants.
:return: ``None`` if the verification flags were successfully set.
N)r[rQ�X509_STORE_set_flagsr7)r�rKs&&r�	set_flags�X509Store.set_flags�s"��,	��1�1�$�+�+�u�E��J�Krc� �V^8�dQhRRRR/#)r�vfy_timezdatetime.datetimerrkr)rs"rrr3s��M�M�!2�M�t�Mrc
�F�\P!4p\P!V\P4p\P
!V\P!VP444\\P!VPV4^8g4R#)a\
Set the time against which the certificates are verified.

Normally the current time is used.

.. note::

  For example, you can determine if a certificate was valid at a given
  time.

.. versionadded:: 17.0.0

:param datetime vfy_time: The verification time to set on this store.
:return: ``None`` if the verification time was successfully set.
N)rQ�X509_VERIFY_PARAM_newrWr]�X509_VERIFY_PARAM_free�X509_VERIFY_PARAM_set_time�calendar�timegm�	timetupler[�X509_STORE_set1_paramr7)r�rQ�params&& r�set_time�X509Store.set_timesm�� �*�*�,������t�:�:�;���'�'��8�?�?�8�#5�#5�#7�8�	
�	��2�2�4�;�;��F�!�K�LrNc�$�V^8�dQhRRRRRR/#)r�cafilezStrOrBytesPath | None�capathrrkr)rs"rrr3&s(��1#�1#�%�1#�&�1#�
�	1#rc
���Vf\PpM\V4pVf\PpM\V4p\P!VP
W4pV'g
\
4R#R#)a�
Let X509Store know where we can find trusted certificates for the
certificate chain.  Note that the certificates have to be in PEM
format.

If *capath* is passed, it must be a directory prepared using the
``c_rehash`` tool included with OpenSSL.  Either, but not both, of
*cafile* or *capath* may be ``None``.

.. note::

  Both *cafile* and *capath* may be set simultaneously.

  Call this method multiple times to add more than one location.
  For example, CA certificates, and certificate revocation list bundles
  may be passed in *cafile* in subsequent calls to this method.

.. versionadded:: 20.0

:param cafile: In which file we can find the certificates (``bytes`` or
               ``unicode``).
:param capath: In which directory we can find the certificates
               (``bytes`` or ``unicode``).

:return: ``None`` if the locations were set successfully.

:raises OpenSSL.crypto.Error: If both *cafile* and *capath* is ``None``
    or the locations could not be set for any reason.

N)rWr\�_path_bytesrQ�X509_STORE_load_locationsr7r�)r�r^r_�load_results&&& r�load_locations�X509Store.load_locations&s^��F�>��Y�Y�F� ��(�F��>��Y�Y�F� ��(�F��4�4��K�K��
��� �"�r�r7r)rArBrCrDrEr�r>rHrNr[rdrFrrrr7r7�s-���;�"�,H�<L�0M�01#�1#rc�2a�]tRtRtRtRV3RlltRtV;t#)r9iZz�
An exception raised when an error occurred while verifying a certificate
using `OpenSSL.X509StoreContext.verify_certificate`.

:ivar certificate: The certificate which caused verificate failure.
:type certificate: :class:`X509`
c�(�V^8�dQhRRRRRRRR/#)	r�messager�errorsz	list[Any]�certificater1rrkr)rs"rr�"X509StoreContextError.__annotate__cs,��'�'��'�$-�'�<@�'�	
�'rc	�><�\SV`V4W nW0nR#r)r	r�rjrk)r�rirjrkrs&&&&�rr��X509StoreContextError.__init__cs���	����!���&�r)rkrj)rArBrCrDrEr�rFr>r?s@rr9r9Zs����'�'rc��]tRtRtRtRRRllt]RRl4t]RR	l4tR
Rlt	RR
lt
RRltRRltRt
R#)r8ika

An X.509 store context.

An X.509 store context is used to carry out the actual verification process
of a certificate in a described context. For describing such a context, see
:class:`X509Store`.

:param X509Store store: The certificates which will be trusted for the
    purposes of any verifications.
:param X509 certificate: The certificate to be verified.
:param chain: List of untrusted certificates that may be used for building
    the certificate chain. May be ``None``.
:type chain: :class:`list` of :class:`X509`
Nc�(�V^8�dQhRRRRRRRR/#)	rr9r7rkr1�chain�Sequence[X509] | Nonerrkr)rs"rr�X509StoreContext.__annotate__{s2��;�;��;��;�%�	;�

�;rc	�J�WnW nVPV4VnR#r)r7�_cert�_build_certificate_stack�_chain)r�r9rkrqs&&&&rr��X509StoreContext.__init__{s ���� �
��3�3�E�:��rc� �V^8�dQhRRRR/#)r�certificatesrrrrkr)rs"rrrs�s����+��	
�rc	�6�RRlpVe\V4^8Xd\P#\P!4p\V\P8g4\P!W!4pVF�p\V\4'g\R4h\\P!VP4^8�4\P!W#P4^8:gKw\P!VP4\4K�	V#)c� �V^8�dQhRRRR/#)r�srrrkr)rs"rr�?X509StoreContext._build_certificate_stack.<locals>.__annotate__�s��	!�	!�s�	!�t�	!rc���\\P!V44F/p\P!W4p\P!V4K1	\P
!V4R#r)r\rQ�sk_X509_num�
sk_X509_valuer]�sk_X509_free)r}rfr<s&  r�cleanup�:X509StoreContext._build_certificate_stack.<locals>.cleanup�sJ���4�+�+�A�.�/���&�&�q�,�����q�!�0�
���a� rz+One of the elements is not an X509 instance)rZrWr\rQ�sk_X509_new_nullr[r]rmr1rn�X509_up_refr��sk_X509_pushr]r�)rzr�r2rcs&   rrv�)X509StoreContext._build_certificate_stack�s���	!���3�|�#4��#9��9�9���%�%�'�������*�+�����'�� �D��d�D�)�)�� M�N�N��D�,�,�T�Z�Z�8�1�<�=�� � ��
�
�3�q�8����t�z�z�*�$�&�!��rc� �V^8�dQhRRRR/#)r�	store_ctxrrr9r)rs"rrrs�s��>�>�3�>�3H�>rc
��\P!\P!\P!V444PR4p\P!V4\P!V4V.p\P!V4p\P!V4p\PV4p\WV4#)z�
Convert an OpenSSL native context error failure into a Python
exception.

When a call to native OpenSSL X509_verify_cert fails, additional
information about the failure can be obtained from the store context.
rT)rWr�rQ�X509_verify_cert_error_string�X509_STORE_CTX_get_errorr(�X509_STORE_CTX_get_error_depth�X509_STORE_CTX_get_current_cert�X509_dupr1rdr9)r�rirjr�ru�pycerts&     r�_exception_from_context�(X509StoreContext._exception_from_context�s����+�+��.�.��-�-�i�8�
�
��&��/�		�
�)�)�)�4��/�/�	�:��
���4�4�Y�?���
�
�e�$���(�(��/��$�W�f�=�=rc��V^8�dQhRR/#r7r)rs"rrrs�s����S�rc
��\P!4p\V\P8g4\P
!V\P4p\P!WPPVPPVP4p\V^8H4\P!V4pV^8:dVPV4hV#)a
Verifies the certificate and runs an X509_STORE_CTX containing the
results.

:raises X509StoreContextError: If an error occurred when validating a
  certificate in the context. Sets ``certificate`` attribute to
  indicate which certificate caused the error.
)rQ�X509_STORE_CTX_newr[rWr\r]�X509_STORE_CTX_free�X509_STORE_CTX_initr7rur�rw�X509_verify_certr�)r�r�rws&  r�_verify_certificate�$X509StoreContext._verify_certificate�s����+�+�-�	��	�T�Y�Y�.�/��G�G�I�t�'?�'?�@�	��&�&��{�{�)�)�4�:�:�+;�+;�T�[�[�
��	��q��!��#�#�I�.���!�8��.�.�y�9�9��rc� �V^8�dQhRRRR/#)rr9r7rrkr)rs"rrrs�s��	�	�y�	�T�	rc
��WnR#)z�
Set the context's X.509 store.

.. versionadded:: 0.15

:param X509Store store: The store description which will be used for
    the purposes of any *future* verifications.
Nrfr8s&&r�	set_store�X509StoreContext.set_store�s	���rc��V^8�dQhRR/#r�r)rs"rrrs�s��
#�
#�D�
#rc
�&�VP4R#)z�
Verify a certificate in a context.

.. versionadded:: 0.15

:raises X509StoreContextError: If an error occurred when validating a
  certificate in the context. Sets ``certificate`` attribute to
  indicate which certificate caused the error.
N)r�r�s&r�verify_certificate�#X509StoreContext.verify_certificate�s��	
� � �"rc��V^8�dQhRR/#)rrz
list[X509]r)rs"rrrs�s����J�rc
��VP4p\P!V4p\V\P
8g4.p\
\P!V44F[p\P!W$4p\V\P
8g4\PV4pVPV4K]	\P!V4V#)a
Verify a certificate in a context and return the complete validated
chain.

:raises X509StoreContextError: If an error occurred when validating a
  certificate in the context. Sets ``certificate`` attribute to
  indicate which certificate caused the error.

.. versionadded:: 20.0
)
r�rQ�X509_STORE_CTX_get1_chainr[rWr\r\r�r�r1rdr�r�)r�r��
cert_stackr�rfrcr�s&      r�get_verified_chain�#X509StoreContext.get_verified_chain�s����,�,�.�	��3�3�I�>�
��
�d�i�i�/�0����t�'�'�
�3�4�A��%�%�j�4�D��D�D�I�I�-�.��,�,�T�2�F��M�M�&�!�	5�	
���*�%��
r)rurwr7r)rArBrCrDrEr��staticmethodrvr�r�r�r�r�rFrrrr8r8ksM��
�;�����:�>��>�2�0	�
#��rc�$�V^8�dQhRRRRRR/#)rr�r=rHrarr1r)rs"rrr	s!��)�)�3�)��)�$�)rc���\V\4'dVPR4p\V4pV\8XdE\
P!V\P\P\P4pM<V\8Xd'\
P!V\P4pM\R4hV\P8Xd\4\PV4#)z�
Load a certificate (X509) from the string *buffer* encoded with the
type *type*.

:param type: The file type (one of FILETYPE_PEM, FILETYPE_ASN1)

:param bytes buffer: The buffer the certificate is stored in

:return: The X509 object
r&�3type argument must be FILETYPE_PEM or FILETYPE_ASN1)rmrrcr_r.rQ�PEM_read_bio_X509rWr\r-�d2i_X509_biorpr�r1rd)r�rHrMr s&&  rrprp	s����&�#������w�'��
�v�
�C��|���%�%�c�4�9�9�d�i�i����K��	
��	�� � ��d�i�i�0���N�O�O��t�y�y�����"�"�4�(�(rc�$�V^8�dQhRRRRRR/#)rr�r=rcr1rrar)rs"rrr&s!����3��d��u�rc�j�\4pV\8Xd"\P!W!P4pMeV\
8Xd"\P!W!P4pM9V\8Xd$\P!W!P^^4pM\R4h\V^8H4\V4#)z�
Dump the certificate *cert* into a buffer string encoded with the type
*type*.

:param type: The file type (one of FILETYPE_PEM, FILETYPE_ASN1, or
    FILETYPE_TEXT)
:param cert: The certificate to dump
:return: The buffer with the dumped certificate in
�Ctype argument must be FILETYPE_PEM, FILETYPE_ASN1, or FILETYPE_TEXT)r_r.rQ�PEM_write_bio_X509r�r-�i2d_X509_bio�
FILETYPE_TEXT�
X509_print_exrpr[rg)r�rcrM�result_codes&&  rrjrj&s����.�C��|���-�-�c�:�:�>��	
��	��'�'��Z�Z�8��	
��	��(�(��j�j�!�Q�?���
�
�	
�
�K�1�$�%��#��rc�$�V^8�dQhRRRRRR/#)rr�r=r�r3rrar)rs"rrrBs!������D��U�rc��\4pV\8Xd\PpM'V\8Xd\P
pM\
R4hV!W!P4pV^8wd\4\V4#)z�
Dump a public key to a buffer.

:param type: The file type (one of :data:`FILETYPE_PEM` or
    :data:`FILETYPE_ASN1`).
:param PKey pkey: The public key to dump
:return: The buffer with the dumped key in it.
:rtype: bytes
r�)
r_r.rQ�PEM_write_bio_PUBKEYr-�i2d_PUBKEY_biorpr�r�rg)r�r�rM�	write_bior�s&&   rr�r�Bsd���.�C��|���-�-�	�	
��	��'�'�	��N�O�O��C���,�K��a�����#��rc
�,�V^8�dQhRRRRRRRRR	R
/#)rr�r=r�r3�cipherrm�
passphrase�PassphraseCallableT | Nonerrar)rs"rrr[sA��B�B�

�B�
�B�
�B�+�	B�
�Brc	���\4p\V\4'g\R4hVePVf\R4h\P
!\
V44pV\P8Xd\R4hM\Pp\W4pV\8XdZ\P!VVPV\P^VPVP4pVP!4M�V\"8Xd"\P$!WAP4pM�V\&8Xd�\P(!VP4\P*8wd\R4h\P,!\P.!VP4\P04p\P2!WH^4pM\R4h\5V^8g4\7V4#)aU
Dump the private key *pkey* into a buffer string encoded with the type
*type*.  Optionally (if *type* is :const:`FILETYPE_PEM`) encrypting it
using *cipher* and *passphrase*.

:param type: The file type (one of :const:`FILETYPE_PEM`,
    :const:`FILETYPE_ASN1`, or :const:`FILETYPE_TEXT`)
:param PKey pkey: The PKey to dump
:param cipher: (optional) if encrypted PEM format, the cipher to use
:param passphrase: (optional) if encrypted PEM format, this can be either
    the passphrase to use, or a callback for providing the passphrase.

:return: The buffer with the dumped key in
:rtype: bytes
zpkey must be a PKeyzDif a value is given for cipher one must also be given for passphrasezInvalid cipher namez-Only RSA keys are supported for FILETYPE_TEXTr�)r_rmr3rnrQ�EVP_get_cipherbynamerYrWr\rp�_PassphraseHelperr.�PEM_write_bio_PrivateKeyr��callback�
callback_args�raise_if_problemr-�i2d_PrivateKey_bior�r�r�r]r�r��	RSA_printr[rg)	r�r�r�r�rM�
cipher_obj�helperr�r%s	&&&&     rr�r�[s���*�.�C��d�D�!�!��-�.�.�
�����8��
��.�.�|�F�/C�D�
�����"��2�3�3�#��Y�Y�
�
�t�
0�F��|���3�3���J�J���I�I�
��O�O�� � �
��	���!�	
��	��-�-�c�:�:�>��	
��	����D�J�J�'�4�+<�+<�<��K�L�L��g�g�d�,�,�T�Z�Z�8�$�-�-�H���n�n�S�q�1���
�
�	
�
�K�1�$�%��#��rc�p�]tRtRtRRRllt]RRl4t]RRl4t]3RR	llt	R
Rlt
RtR
#)r�i�c
�,�V^8�dQhRRRRRRRRRR	/#)
rr�r=r�r��	more_argsr��truncaterrkr)rs"rr�_PassphraseHelper.__annotate__�s<��-�-��-�/�-��	-�
�-�
�
-rc	�l�V\8wdVe\R4hW nW0nW@n.VnR#)Nz0only FILETYPE_PEM key format supports encryption)r.rp�_passphrase�
_more_args�	_truncate�	_problems)r�r�r�r�r�s&&&&&rr��_PassphraseHelper.__init__�s:���<��J�$:��B��
�&��#��!��*,��rc��V^8�dQhRR/#r7r)rs"rrr��s����#�rc	��VPf\P#\VP\4'g\VP4'd"\P!RVP4#\R4h)N�pem_password_cb�2Last argument must be a byte string or a callable.)	r�rWr\rmra�callabler��_read_passphrasernr�s&rr��_PassphraseHelper.callback�sc�����#��9�9��
��(�(�%�
0�
0�H�T�=M�=M�4N�4N��=�=�!2�D�4I�4I�J�J��D��
rc��V^8�dQhRR/#r7r)rs"rrr��s����s�rc	���VPf\P#\VP\4'g\VP4'd\P#\
R4h)Nr�)r�rWr\rmrar�rnr�s&rr��_PassphraseHelper.callback_args�sU�����#��9�9��
��(�(�%�
0�
0�H�T�=M�=M�4N�4N��9�9���D��
rc� �V^8�dQhRRRR/#)r�
exceptionTypeztype[Exception]rrkr)rs"rrr��s��(�(�o�(�$�(rc	��VP'd(\V4VPP^4hR# TdL&i;ir�)r��_exception_from_error_queue�pop)r�r�s&&rr��"_PassphraseHelper.raise_if_problem�sH���>�>�>�
�+�M�:��.�.�$�$�Q�'�'���!�
��
�s�<�A�Ac
�,�V^8�dQhRRRRRRRRRR/#)rr�r�sizer=�rwflag�userdatarr)rs"rrr��s4������!��+.��:=��	�rc	�V�\VP4'd8VP'dVPW#V4pM.VPV4pMVPfQhVPp\V\4'g\R4h\
V4V8�d$VP'dVRVpM\R4h\\
V44FpWVV^,W&K	\
V4# \d'pTPPT4Rp?^#Rp?ii;i)NzBytes expectedz+passphrase returned by callback is too long)r�r�r�rmrarprZr�r\�	Exceptionr�r�)r�r�r�r�r�r�rf�es&&&&&   rr��"_PassphraseHelper._read_passphrase�s���	���(�(�)�)��?�?�?�!�-�-�d�H�E�F�!�-�-�f�5�F��'�'�3�3�3��)�)���f�e�,�,� �!1�2�2��6�{�T�!��>�>�>�#�E�T�]�F�$�E����3�v�;�'���A��E�*���(��v�;����	��N�N�!�!�!�$���	�s$�,C7�BC7�3AC7�7D(�D#�#D()r�r�r�r�N)FF)rArBrCrDr�r�r�r�r2r�r�rFrrrr�r��sE��-� ��������AF�(��rr�c�$�V^8�dQhRRRRRR/#)rr�r=rH�str | bytesrr3r)rs"rrr�s!������k��d�rc�R�\V\4'dVPR4p\V4pV\8XdE\
P!V\P\P\P4pM<V\8Xd'\
P!V\P4pM\R4hV\P8Xd\4\P\4p\P!V\
P 4VnRVnV#)a
Load a public key from a buffer.

:param type: The file type (one of :data:`FILETYPE_PEM`,
    :data:`FILETYPE_ASN1`).
:param buffer: The buffer the key is stored in.
:type buffer: A Python string object, either unicode or bytestring.
:return: The PKey object.
:rtype: :class:`PKey`
r&r�T)rmrrcr_r.rQ�PEM_read_bio_PUBKEYrWr\r-�d2i_PUBKEY_biorpr�r3r
r]r�r�r�)r�rHrM�evp_pkeyr�s&&   rr�r��s����&�#������w�'��
�v�
�C��|���+�+�����D�I�I�t�y�y�
��
��	��&�&�s�D�I�I�6���N�O�O��4�9�9�����<�<���D�����4�#5�#5�6�D�J��D���Krc�(�V^8�dQhRRRRRRRR/#)	rr�r=rHr�r�r�rr3r)rs"rrr	s0��&�&�

�&��&�+�&�
�	&rc�j�\V\4'dVPR4p\V4p\	W4pV\
8XdM\P!V\PVPVP4pVP4M<V\8Xd'\P!V\P4pM\R4hV\P8Xd\!4\"P%\"4p\P&!V\P(4VnV#)a�
Load a private key (PKey) from the string *buffer* encoded with the type
*type*.

:param type: The file type (one of FILETYPE_PEM, FILETYPE_ASN1)
:param buffer: The buffer the key is stored in
:param passphrase: (optional) if encrypted PEM format, this can be
                   either the passphrase to use, or a callback for
                   providing the passphrase.

:return: The PKey object
r&r�)rmrrcr_r�r.rQ�PEM_read_bio_PrivateKeyrWr\r�r�r�r-�d2i_PrivateKey_biorpr�r3r
r]r�r�)r�rHr�rMr�r�r�s&&&    rr�r�	s���"�&�#������w�'��
�v�
�C�
�t�
0�F��|���/�/�����F�O�O�V�-A�-A�
��	���!�	
��	��*�*�3��	�	�:���N�O�O��4�9�9�����<�<���D�����4�#5�#5�6�D�J��Krc�$�V^8�dQhRRRRRR/#)rr�r=r�r6rrar)rs"rrr9	s!����3��W���rc�j�\4pV\8Xd"\P!W!P4pMeV\
8Xd"\P!W!P4pM9V\8Xd$\P!W!P^^4pM\R4h\V^8g4\V4#)aV
Dump the certificate request *req* into a buffer string encoded with the
type *type*.

:param type: The file type (one of FILETYPE_PEM, FILETYPE_ASN1)
:param req: The certificate request to dump
:return: The buffer with the dumped certificate request in


.. deprecated:: 24.2.0
   Use `cryptography.x509.CertificateSigningRequest` instead.
r�)r_r.rQ�PEM_write_bio_X509_REQr�r-�i2d_X509_REQ_bior��X509_REQ_print_exrpr[rg)r�r�rMr�s&&  rr;r;9	s����.�C��|���1�1�#�x�x�@��	
��	��+�+�C���:��	
��	��,�,�S�(�(�A�q�A���
�
�	
�
�K�1�$�%��#��rr3c�$�V^8�dQhRRRRRR/#)rr�r=rHrarr6r)rs"rrrg	s!����3����'�rc�>�\V\4'dVPR4p\V4pV\8XdE\
P!V\P\P\P4pM<V\8Xd'\
P!V\P4pM\R4h\V\P8g4\P\4p\P!V\
P 4VnV#)as
Load a certificate request (X509Req) from the string *buffer* encoded with
the type *type*.

:param type: The file type (one of FILETYPE_PEM, FILETYPE_ASN1)
:param buffer: The buffer the certificate request is stored in
:return: The X509Req object

.. deprecated:: 24.2.0
   Use `cryptography.x509.load_der_x509_csr` or
   `cryptography.x509.load_pem_x509_csr` instead.
r&r�)rmrrcr_r.rQ�PEM_read_bio_X509_REQrWr\r-�d2i_X509_REQ_biorpr[r6r
r]r�r�)r�rHrMr��x509reqs&&   rr<r<g	s����&�#������w�'��
�v�
�C��|���(�(��d�i�i����D�I�I�N��	
��	��#�#�C����3���N�O�O��C�4�9�9�$�%��o�o�g�&�G��7�7�3�� 2� 2�3�G�L��Nr)��
)r�)r-r.r�r/r0r1r2r3r4r5r6r7r8r9r:rjr;r�r�rFrBrpr<r�r�i��rr�)p�__conditional_annotations__�
__future__rrVr��	functools�sysr�r+�base64r�collections.abcrrrrr	r
�version_infor�TypeVar�_T�typing_extensions�cryptographyrr �)cryptography.hazmat.primitives.asymmetricr!r"r#r$r%�
OpenSSL._utilr&r'rYr(r�r)rWr*rQr+�_make_assertr,ra�__all__r�r�r�r�r��_PrivateKeyr�r�r�r�r��
_PublicKeyr�ra�PassphraseCallableT�SSL_FILETYPE_PEMr.r��SSL_FILETYPE_ASN1r-r�r�r0�EVP_PKEY_DSAr/�EVP_PKEY_DHr>�EVP_PKEY_ECr?r�r2r�r[r_rgrrrxr�r�r3rrBrF�total_orderingr5r4r6r1r:r7r9r8rprjr�r�r�r�r�r;r�rAr-r<r)rs@r�<module>rs����"�"����
�
���.�������w��#������	����	�B��-�$���)���������:����������	������	�������������	������	��
�
�[�*�
$�%���E�8�C��J�#7�7�8���)�)��c�)��+�+�
�s�+��
��!�!��#�!��!�!��#�!��������������I���:�E�B���u�%���4;�+�2�&�:
�
�~.�~.�Bd.�d.�N���5�	�5����1�	�1�$�������D���g:�g:�	�g:�T���o�o�	�o�dg�g�T8�8�.g#�g#�T'�I�'�"[�[�|)�:�8�2B�JK�K�\�D&�R�@&>�"������	��	#�	��@&>�"������	��	#�	r

Youez - 2016 - github.com/yon3zu
LinuXploit