xjn ddlmZddlZddlZddlZddlmZddlmZddl m Z ddl m Z ddlmZmZmZmZmZmZmZmZmZmZddlmZmZdd lmZmZmZdd l m!Z!m"Z"dd l#m$Z$ejd d d Z%ejLe jNe jPe jRe jTe jVe jXe jZe j\fZ/Gdde0Z1 d$dZ2 d%dZ3d&dZ4GddZ5GddZ6GddejnZ8Gdde0Z9e jtZ:e jvZ;e jxZe j~Z?e jZ@e jZAe jZBe jZCe jZDGddZEGddZFGdd ZGGd!d"ZHd'd#ZIy)() annotationsN)Iterable)utils)x509)hashes) dsaeced448ed25519mldsamlkempaddingrsax448x25519) CertificateIssuerPrivateKeyTypesCertificatePublicKeyTypes) Extension ExtensionType_make_sequence_methods)Name _ASN1Type)ObjectIdentifieric eZdZdfd ZxZS)AttributeNotFoundc2t||||_yN)super__init__oid)selfmsgr! __class__s j/mnt/ssd/data/Dropbox/adrian/sandbox/mcp-query/venv/lib/python3.12/site-packages/cryptography/x509/base.pyr zAttributeNotFound.__init__8s )r#strr!rreturnNone__name__ __module__ __qualname__r __classcell__r$s@r%rr7s r&rcZ|D]&}|j|jk(stdy)Nz$This extension has already been set.)r! ValueError) extension extensionses r%_reject_duplicate_extensionr5=s1 E 55IMM !CD DEr&c:|D]\}}}||k(s tdy)Nz$This attribute has already been set.)r1)r! attributesattr_oid_s r%_reject_duplicate_attributer:Gs. %E!Q s?CD DEr&c|j=|j}|r|ntj}|j d|z S|S)zNormalizes a datetime to a naive datetime in UTC. time -- datetime to normalize. Assumed to be in UTC if not timezone aware. N)tzinfo)r< utcoffsetdatetime timedeltareplace)timeoffsets r%_convert_to_naive_utc_timerCQsG  {{!!x'9'9';||4|(611 r&ceZdZejj f ddZed dZed dZd dZ d dZ d dZ y) Attributec.||_||_||_yr)_oid_value_type)r"r!valuerIs r%r zAttribute.__init__`s    r&c|jSr)rGr"s r%r!z Attribute.oidjs yyr&c|jSr)rHrLs r%rJzAttribute.valuens {{r&c<d|jd|jdS)Nz)r!rJrLs r%__repr__zAttribute.__repr__rs  (4::.CCr&ct|tstS|j|jk(xr4|j|jk(xr|j |j k(Sr) isinstancerENotImplementedr!rJrI)r"others r%__eq__zAttribute.__eq__usS%+! ! HH ! * ekk) * ekk) r&cZt|j|j|jfSr)hashr!rJrIrLs r%__hash__zAttribute.__hash__s TXXtzz4::677r&N)r!rrJbytesrIintr(r))r(r)r(rYr(r')rTobjectr(boolr(rZ) r+r,r-r UTF8StringrJr propertyr!rPrUrXr&r%rErE_sv ))//     D 8r&rEcDeZdZ ddZed\ZZZddZddZ y) Attributesc$t||_yr)list _attributes)r"r7s r%r zAttributes.__init__s +r&rfc"d|jdS)Nz ?EEr&N)r7zIterable[Attribute]r(r)r[)r!rr(rE) r+r,r-r r__len____iter__ __getitem__rPrjrar&r%rcrcs7,', , & >%'12 2  JtY$?34 4#C)9)9:  **CC/       2d 2eS 1 2  r& rsa_paddingecdsa_deterministicch|j td|Zt|tjtj fs t dt|tjs t d|%t|tjs t dtj|||||S)zF Signs the request using the requestor's private key. z/A CertificateSigningRequest must have a subjectPadding must be PSS or PKCS1v15&Padding is only supported for RSA keys1Deterministic ECDSA is only supported for EC keys) rzr1rRrPSSPKCS1v15rr RSAPrivateKeyr EllipticCurvePrivateKey rust_x509create_x509_csrr" private_key algorithmbackendrrs r%signz%CertificateSigningRequestBuilder.signs    %NO O  "kGKK9I9I+JK ABBk3+<+<= HII  *k2+E+EFG((        r&)r| Name | Noner3list[Extension[ExtensionType]]r70list[tuple[ObjectIdentifier, bytes, int | None]])rrr(rx)rrrr]r(rx)r!rrJrYrz_ASN1Type | Noner(rxr) rrr_AllowedHashTypes | Noner typing.Anyr%padding.PSS | padding.PKCS1v15 | Noner bool | Noner(CertificateSigningRequest)r+r,r-r r|rrrrar&r%rxrxs%)57GI &! &3 &E &   # /3 ) ."&      *  H# ! >B+/! 5! ,!  ! ; ! )!  #! r&rxceZdZUded<ddddddgdf ddZddZddZdd ddZdd Zdd Z dd Z dd Z dddd  ddZ ddZ y)CertificateBuilderrr{Nc tj|_||_||_||_||_||_||_||_ ||_ yr) rorr_version _issuer_namerz _public_key_serial_number_not_valid_before_not_valid_afterr{_public_key_rsa_padding) r" issuer_namer| public_key serial_numbernot_valid_beforenot_valid_afterr3public_key_rsa_paddings r%r zCertificateBuilder.__init__)sO  ')%+!1 /%'=$r&c t|ts td|j t dt ||j |j|j|j|j|j|jS)z3 Sets the CA's distinguished name. r~%The issuer name may only be set once.) rRrrrr1rrzrrrrr{rrs r%rzCertificateBuilder.issuer_name>s$%9: :    (DE E!            " "  ! !     ( (  r&c t|ts td|j t dt |j ||j|j|j|j|j|jS)z: Sets the requestor's distinguished name. r~r) rRrrrzr1rrrrrrr{rrs r%r|zCertificateBuilder.subject_nameQs$%9: :    )EF F!            " "  ! !     ( (  r&)rct|tjtjt j tjtjtjtjtjtj tj"t$j&t(j*f s t-d|B|t.j0ur t-dt|tjs t-d|j2 t5dt7|j8|j:||j<|j>|j@|jB|S)zT Sets the requestor's public key (as found in the signing request). zExpecting one of DSAPublicKey, RSAPublicKey, EllipticCurvePublicKey, Ed25519PublicKey, Ed448PublicKey, MLDSA44PublicKey, MLDSA65PublicKey, MLDSA87PublicKey, MLKEM768PublicKey, MLKEM1024PublicKey, X25519PublicKey or X448PublicKey.z2rsa_padding must be the PSS class, not an instancez2rsa_padding is only supported with RSA public keysz$The public key may only be set once.)"rRr DSAPublicKeyr RSAPublicKeyr EllipticCurvePublicKeyr Ed25519PublicKeyr Ed448PublicKeyr MLDSA44PublicKeyMLDSA65PublicKeyMLDSA87PublicKeyr MLKEM768PublicKeyMLKEM1024PublicKeyrX25519PublicKeyr X448PublicKeyrrrrr1rrrzrrrr{)r"keyrs r%rzCertificateBuilder.public_keyds=     ))(($$&&&&&&''((&&""  "5   "'++-Hc3#3#34H    'CD D!            " "  ! !      r&c rt|ts td|j t d|dkr t d|j dk\r t dt |j|j|j||j|j|j|jS)z5 Sets the certificate serial number. 'Serial number must be of integral type.'The serial number may only be set once.rz%The serial number should be positive.3The serial number should not be more than 159 bits.)rRrZrrr1 bit_lengthrrrzrrrr{rr"numbers r%rz CertificateBuilder.serial_numbers&#&EF F    *FG G Q;DE E    # %E "            " "  ! !     ( (  r&c t|tjs td|j t dt |}|t kr t d|j||jkDr t dt|j|j|j|j||j|j|jS)z7 Sets the certificate activation time. Expecting datetime object.z*The not valid before may only be set once.z>The not valid before date must be on or after 1950 January 1).zBThe not valid before date must be before the not valid after date.)rRr>rrr1rC_EARLIEST_UTC_TIMErrrrzrrr{rr"rAs r%rz#CertificateBuilder.not_valid_befores$ 1 1289 9  ! ! -IJ J)$/ $ $$   ,8M8M1M "               ! !     ( (  r&c t|tjs td|j t dt |}|t kr t d|j||jkr t dt|j|j|j|j|j||j|jS)z7 Sets the certificate expiration time. rz)The not valid after may only be set once.zrrr1rCrrrrrzrrr{rrs r%rz"CertificateBuilder.not_valid_afters$ 1 1289 9  ,HI I)$/ $ $N   " " .t--- "              " "      ( (  r&c ^t|ts tdt|j||}t ||j t|j|j|j|j|j|jg|j ||jS)z= Adds an X.509 extension to the certificate. r)rRrrrr!r5r{rrrzrrrrrrs r%rz CertificateBuilder.add_extensions &-0@A Afjj(F; #It/?/?@!              " "  ! ! *d * *  ( (  r&rch|j td|j td|j td|j td|j td|j td| td|Zt|tjtjfs tdt|tjs td |%t|tjs td t!j"|||||S) zC Signs the certificate using the CA's private key. &A certificate must have a subject name&A certificate must have an issuer name'A certificate must have a serial number/A certificate must have a not valid before time.A certificate must have a not valid after time$A certificate must have a public keyz$Need private key to sign certificaterrr)rzr1rrrrrrrRrrrrrr rrcreate_x509_certificaters r%rzCertificateBuilder.sign s7    %EF F    $EF F    &FG G  ! ! )NO O  (MN N    #CD D  BC C  "kGKK9I9I+JK ABBk3+<+<= HII  *k2+E+EFG00        r&cJ|j td|j td|j td|j td|j td|j tdtj|ddddS) z@ Creates an unsigned certificate, per RFC 9925. Nrrrrrr)rhash_algorithmrr) rzr1rrrrrrrrLs r%create_unsignedz"CertificateBuilder.create_unsignedAs    %EF F    $EF F    &FG G  ! ! )NO O  (MN N    #CD D00  $   r&)rrr|rrz CertificatePublicKeyTypes | Noner int | Nonerdatetime.datetime | Nonerrr3rrtype[padding.PSS] | Noner(r))rrr(r)rrrrr(r)rrZr(r)rAdatetime.datetimer(r)rrrr]r(rr) rrrrrrrrrrr( Certificate)r(r)r+r,r-__annotations__r rr|rrrrrrrrar&r%rr&s5//$($(7;$(594857;?> >">5 > " > 3 >2>3>!9> >* & .15 5 &5 . 5  5 n 8 < @ # /3  6# 3 >B+/3 53 ,3  3 ; 3 )3  3 j r&rceZdZUded<ded<dddggf ddZ ddZ ddZ dd Z dd Z dd Z dddd  dd Z y) CertificateRevocationListBuilderrr{list[RevokedCertificate]_revoked_certificatesNcJ||_||_||_||_||_yr)r _last_update _next_updater{r)r"r last_update next_updater3revoked_certificatess r%r z)CertificateRevocationListBuilder.__init__ds,(''%%9"r&ct|ts td|j t dt ||j |j|j|jS)Nr~r) rRrrrr1rrrr{r)r"rs r%rz,CertificateRevocationListBuilder.issuer_namersf+t,9: :    (DE E/            & &   r&crt|tjs td|j t dt |}|t kr t d|j||jkDr t dt|j||j|j|jS)Nr!Last update may only be set once.8The last update date must be on or after 1950 January 1.z9The last update date must be before the next update date.) rRr>rrr1rCrrrrr{r)r"rs r%rz,CertificateRevocationListBuilder.last_updates+x'8'8989 9    (@A A0= + +J     ([4;L;L-LK 0            & &   r&crt|tjs td|j t dt |}|t kr t d|j||jkr t dt|j|j||j|jS)Nrrrz8The next update date must be after the last update date.) rRr>rrr1rCrrrrr{r)r"rs r%rz,CertificateRevocationListBuilder.next_updates+x'8'8989 9    (@A A0= + +J     ([4;L;L-LJ 0            & &   r&ct|ts tdt|j||}t ||j t|j|j|jg|j ||jS)zM Adds an X.509 extension to the certificate revocation list. r) rRrrrr!r5r{rrrrrrs r%rz.CertificateRevocationListBuilder.add_extensions &-0@A Afjj(F; #It/?/?@/          *d * *  & &   r&ct|ts tdt|j|j |j |jg|j|S)z8 Adds a revoked certificate to the CRL. z)Must be an instance of RevokedCertificate) rRRevokedCertificaterrrrrr{r)r"revoked_certificates r%add_revoked_certificatez8CertificateRevocationListBuilder.add_revoked_certificatesa -/ABGH H/             >d(( >*= >   r&rc|j td|j td|j td|Zt |t j t jfs tdt |tjs td|%t |tjs tdtj|||||S)NzA CRL must have an issuer namez"A CRL must have a last update timez"A CRL must have a next update timerrr)rr1rrrRrrrrrrr rrcreate_x509_crlrs r%rz%CertificateRevocationListBuilder.signs    $=> >    $AB B    $AB B  "kGKK9I9I+JK ABBk3+<+<= HII  *k2+E+EFG((        r&) rrrrrrr3rrr)rrr(r)rrr(r)rrr(r)rrrr]r(r)rrr(rr) rrrrrrrrrrr(CertificateRevocationList) r+r,r-rr rrrrrrrar&r%rr`s//33$(0404579; :  :. :. : 3 : 7 :    )   , ) 0 , ) 0 # /3 ) & #5 ) *# $ >B+/$ 5$ ,$  $ ; $ )$  #$ r&rc\eZdZddgf ddZddZ d dZ d dZd d dZy) RevokedCertificateBuilderNc.||_||_||_yr)r_revocation_dater{)r"rrevocation_dater3s r%r z"RevokedCertificateBuilder.__init__s , /%r&ct|ts td|j t d|dkr t d|j dk\r t dt ||j|jS)Nrrrz$The serial number should be positiverr) rRrZrrr1rrrr{rs r%rz'RevokedCertificateBuilder.serial_numbers&#&EF F    *FG G Q;CD D    # %E ) D))4+;+;  r&ct|tjs td|j t dt |}|t kr t dt|j||jS)Nrz)The revocation date may only be set once.z7The revocation date must be on or after 1950 January 1.) rRr>rrr1rCrrrr{rs r%rz)RevokedCertificateBuilder.revocation_dates}$ 1 1289 9  ,HI I)$/ $ $I )   t'7'7  r&ct|ts tdt|j||}t ||j t|j|jg|j |S)Nr) rRrrrr!r5r{rrrrs r%rz'RevokedCertificateBuilder.add_extension)sn&-0@A Afjj(F; #It/?/?@(     ! ! *d * *  r&c|j td|j tdtj|S)Nz/A revoked certificate must have a serial numberz1A revoked certificate must have a revocation date)rr1rrcreate_revoked_certificate)r"rs r%buildzRevokedCertificateBuilder.build7sI    &NO O  (C 33D99r&)rrrrr3r)rrZr(r)rArr(r)rrrr]r(rr)rrr(r)r+r,r-r rrrrrar&r%rrsj%)4857 &!&2&3 & $ % "  #  /3  "  :r&rcZtjtjdddz S)Nbigr)rZ from_bytesosurandomrar&r%random_serial_numberrAs >>"**R.% 0A 55r&)r2zExtension[ExtensionType]r3rr(r))r!rr7rr(r))rArr(rr^)J __future__rr>r typingcollections.abcr cryptographyr"cryptography.hazmat.bindings._rustrrcryptography.hazmat.primitivesr)cryptography.hazmat.primitives.asymmetricrr r r r r rrrr/cryptography.hazmat.primitives.asymmetric.typesrrcryptography.x509.extensionsrrrcryptography.x509.namerrcryptography.x509.oidrrUnionSHA224SHA256SHA384SHA512SHA3_224SHA3_256SHA3_384SHA3_512_AllowedHashTypes Exceptionrr5r:rCrErcEnumrortrrrrload_pem_x509_certificateload_der_x509_certificateload_pem_x509_certificatesload_pem_x509_csrload_der_x509_csrload_pem_x509_crlload_der_x509_crlrxrrrrrar&r%r.s # $@1    32&X&&tQ2LL MM MM MM MM OO OO OO OO   E'E.E EE E@E E !8!8HFF( ejj -Y- ## 11&??%??&??%??&AA////////m m `w w t Y Y xB:B:J6r&