§
    ¢”jµE  ã                   óø   — d dl mZmZmZmZ d dlZd dlmZ ddlmZm	Z	m
Z
 ddlmZ ddlmZmZmZ g d¢Zd	„ Zd
„ Zd„ Zd„ Zd„ Zd„ Zd„ Zd„ Zd„ Zd„ Zd„ Zd„ Zd„ Zd„ Zd„ Z d„ Z!d„ Z"d„ Z#d„ Z$d„ Z%d„ Z&d„ Z'd„ Z(dS ) é    )Úunicode_literalsÚdivisionÚabsolute_importÚprint_functionN)Údatetimeé   )ÚCertificateÚint_from_bytesÚtimezone)ÚCIPHER_SUITE_MAP)ÚTLSVerificationErrorÚTLSDisconnectErrorÚTLSError)Údetect_client_auth_requestÚextract_chainÚget_dh_params_lengthÚparse_alertÚparse_handshake_messagesÚparse_session_infoÚparse_tls_recordsÚraise_client_authÚraise_dh_paramsÚraise_disconnectionÚraise_expired_not_yet_validÚraise_handshakeÚraise_hostnameÚraise_no_issuerÚraise_protocol_errorÚraise_revokedÚraise_self_signedÚraise_verificationÚraise_weak_signaturec                 ó�  — g }d}t          | ¦  «        D ]0\  }}}|dk    rŒt          |¦  «        D ]\  }}|dk    r|} nŒ|r nŒ1|rd}|t          |¦  «        k     rjt          |||dz   …         ¦  «        }	|dz   }
|
|	z   }|}||
|…         }|                     t          j        |¦  «        ¦  «         |t          |¦  «        k     °j|S )a  
    Extracts the X.509 certificates from the server handshake bytes for use
    when debugging

    :param server_handshake_bytes:
        A byte string of the handshake data received from the server

    :return:
        A list of asn1crypto.x509.Certificate objects
    Nó   ó   é   )r   r   Úlenr
   Úappendr	   Úload)Úserver_handshake_bytesÚoutputÚchain_bytesÚrecord_typeÚ_Úrecord_dataÚmessage_typeÚmessage_dataÚpointerÚcert_lengthÚ
cert_startÚcert_endÚ
cert_bytess                ú\/var/www/finuniver-perm.ru/html/portfolio/venv/lib/python3.11/site-packages/oscrypto/_tls.pyr   r   #   s"  € ð €Fà€Kå'8Ð9OÑ'PÔ'Pð ð Ñ#ˆ�Q˜Ø˜'Ò!Ð!ØÝ*BÀ;Ñ*OÔ*Oð 	ð 	Ñ&ˆL˜,Ø˜wÒ&Ð&Ø*�Ø�ð 'ð ð 	ØˆEð	ð ð 	8àˆØ�˜KÑ(Ô(Ò(Ð(Ý(¨°W¸WÀq¹[Ð5HÔ)IÑJÔJˆKØ  1™ˆJØ! KÑ/ˆHØˆGØ$ Z°Ð%8Ô9ˆJØ�MŠM�+Ô*¨:Ñ6Ô6Ñ7Ô7Ð7ð �˜KÑ(Ô(Ò(Ð(ð €Mó    c                 ó~   — t          | ¦  «        D ],\  }}}|dk    rŒt          |¦  «        D ]\  }}|dk    r  dS ŒŒ-dS )a)  
    Determines if a CertificateRequest message is sent from the server asking
    the client for a certificate

    :param server_handshake_bytes:
        A byte string of the handshake data received from the server

    :return:
        A boolean - if a client certificate request was found
    r$   ó   TF)r   r   )r*   r-   r.   r/   r0   r1   s         r7   r   r   K   sr   € õ (9Ð9OÑ'PÔ'Pð ð Ñ#ˆ�Q˜Ø˜'Ò!Ð!ØÝ*BÀ;Ñ*OÔ*Oð 	ð 	Ñ&ˆL˜,Ø˜wÒ&Ð&Ø�t�t�tð 'ð	ð ˆ5r8   c                 óÆ   — d}d}t          | ¦  «        D ]0\  }}}|dk    rŒt          |¦  «        D ]\  }}|dk    r|} nŒ|r nŒ1|rt          |dd…         ¦  «        dz  }|S )a  
    Determines the length of the DH params from the ServerKeyExchange

    :param server_handshake_bytes:
        A byte string of the handshake data received from the server

    :return:
        None or an integer of the bit size of the DH parameters
    Nr$   ó   r   é   é   )r   r   r
   )r*   r+   Údh_params_bytesr-   r.   r/   r0   r1   s           r7   r   r   `   s¯   € ð €Fà€Oå'8Ð9OÑ'PÔ'Pð ð Ñ#ˆ�Q˜Ø˜'Ò!Ð!ØÝ*BÀ;Ñ*OÔ*Oð 	ð 	Ñ&ˆL˜,Ø˜wÒ&Ð&Ø".�Ø�ð 'ð ð 	ØˆEð	ð ð :Ý °°!°Ô 4Ñ5Ô5¸Ñ9ˆà€Mr8   c                 óÊ   — t          | ¦  «        D ]R\  }}}|dk    rŒt          |¦  «        dk    r dS t          |dd…         ¦  «        t          |dd…         ¦  «        fc S dS )aV  
    Parses the handshake for protocol alerts

    :param server_handshake_bytes:
        A byte string of the handshake data received from the server

    :return:
        None or an 2-element tuple of integers:
         0: 1 (warning) or 2 (fatal)
         1: The alert description (see https://tools.ietf.org/html/rfc5246#section-7.2)
    ó   r=   Nr   r   )r   r'   r
   )r*   r-   r.   r/   s       r7   r   r      s…   € õ (9Ð9OÑ'PÔ'Pð Tð TÑ#ˆ�Q˜Ø˜'Ò!Ð!ØÝˆ{ÑÔ˜qÒ Ð Ø�4�4Ý˜{¨1¨Q¨3Ô/Ñ0Ô0µ.ÀÈQÈqÈSÔAQÑ2RÔ2RÐSÐSÐSÐSØˆ4r8   c                 ó¼  — d}d}d}d}d}d}d}t          | ¦  «        D ]Ì\  }	}
}|	dk    rŒt          |¦  «        D ]¯\  }}|dk    rŒddddd	d
œ|dd…                  }t          |dd…         ¦  «        }|dk    r|dd|z   …         }d|z   }|||dz   …         }t          |         }|dz   }|||dz   …         dk    }|dz   }||d…         }t	          |¦  «        D ]\  }}|dk    rd} nŒ ŒÍt          |¦  «        D ]É\  }	}
}|	dk    rŒt          |¦  «        D ]¬\  }}|dk    rŒt          |dd…         ¦  «        }|dk    r|dd|z   …         }d|z   }t          |||dz   …         ¦  «        }|dz   |z   }t          |||dz   …         ¦  «        }|€3|€1|dz   |z   }||d…         }t	          |¦  «        D ]\  }}|dk    rd} nŒ ŒÊ|�|€d}n||k    rd}nd}|||||dœS )a´  
    Parse the TLS handshake from the client to the server to extract information
    including the cipher suite selected, if compression is enabled, the
    session id and if a new or reused session ticket exists.

    :param server_handshake_bytes:
        A byte string of the handshake data received from the server

    :param client_handshake_bytes:
        A byte string of the handshake data sent to the server

    :return:
        A dict with the following keys:
         - "protocol": unicode string
         - "cipher_suite": unicode string
         - "compression": boolean
         - "session_id": "new", "reused" or None
         - "session_ticket: "new", "reused" or None
    NFr$   ó   ÚSSLv3ÚTLSv1zTLSv1.1zTLSv1.2zTLSv1.3)s    s   s   s   s   r   r=   é"   é#   r   ó    Únewó   Úreused)ÚprotocolÚcipher_suiteÚcompressionÚ
session_idÚsession_ticket)r   r   r
   r   Ú_parse_hello_extensions)r*   Úclient_handshake_bytesrL   rM   rN   rO   rP   Úserver_session_idÚclient_session_idr-   r.   r/   r0   r1   Úsession_id_lengthÚcipher_suite_startÚcipher_suite_bytesÚcompression_startÚextensions_length_startÚextensions_dataÚextension_typeÚextension_dataÚcipher_suite_lengthÚcompression_lengths                           r7   r   r   •   s8  € ð* €HØ€LØ€KØ€JØ€NàÐØÐå'8Ð9OÑ'PÔ'Pð  ð  Ñ#ˆ�Q˜Ø˜'Ò!Ð!ØÝ*BÀ;Ñ*OÔ*Oð 	ð 	Ñ&ˆL˜,à˜wÒ&Ð&Øà$Ø$Ø&Ø&Ø&ðð ð ˜1˜Q˜3Ôô!ˆHõ !/¨|¸B¸r¸EÔ/BÑ CÔ CÐØ  1Ò$Ð$Ø$0°°BÐ9JÑ4JÐ1JÔ$KÐ!à!#Ð&7Ñ!7ÐØ!-Ð.@ÐASÐVWÑAWÐ.WÔ!XÐÝ+Ð,>Ô?ˆLà 2°QÑ 6ÐØ&Ð'8Ð9JÈQÑ9NÐ'NÔOÐSZÒZˆKà&7¸!Ñ&;Ð#Ø*Ð+BÐ+CÐ+CÔDˆOÝ2IÈ/Ñ2ZÔ2Zð ð Ñ.� Ø! RÒ'Ð'Ø%*�NØ�Eð (ð øå'8Ð9OÑ'PÔ'Pð ð Ñ#ˆ�Q˜Ø˜'Ò!Ð!ØÝ*BÀ;Ñ*OÔ*Oð 	ð 	Ñ&ˆL˜,à˜wÒ&Ð&Øå .¨|¸B¸r¸EÔ/BÑ CÔ CÐØ  1Ò$Ð$Ø$0°°BÐ9JÑ4JÐ1JÔ$KÐ!à!#Ð&7Ñ!7ÐÝ"0°Ð>PÐQcÐfgÑQgÐ>gÔ1hÑ"iÔ"iÐà 2°QÑ 6Ð9LÑ LÐÝ!/°Ð=NÐO`ÐcdÑOdÐ=dÔ0eÑ!fÔ!fÐð !Ð(¨^Ð-CØ*;¸aÑ*?ÐBTÑ*TÐ'Ø".Ð/FÐ/GÐ/GÔ"H�Ý6MÈoÑ6^Ô6^ð ð Ñ2�N NØ%¨Ò+Ð+Ø)1˜Ø˜ð ,ð øàÐ$ØÐ$ØˆJˆJà Ð$5Ò5Ð5Ø"�
�
à%�
ð Ø$Ø"Ø Ø(ðð ð r8   c              #   ó  K  — d}t          | ¦  «        }||k     rq| ||dz   …         dk    rdS t          | |dz   |dz   …         ¦  «        }| ||dz   …         | |dz   |dz   …         | |dz   |dz   |z   …         fV — |d|z   z  }||k     °odS dS )aÜ  
    Creates a generator returning tuples of information about each record
    in a byte string of data from a TLS client or server. Stops as soon as it
    find a ChangeCipherSpec message since all data from then on is encrypted.

    :param data:
        A byte string of TLS records

    :return:
        A generator that yields 3-element tuples:
        [0] Byte string of record type
        [1] Byte string of protocol version
        [2] Byte string of record data
    r   r   ó   r&   é   N©r'   r
   ©Údatar2   Údata_lenÚlengths       r7   r   r     sÝ   è è € ð  €GÝ�4‰yŒy€HØ
�HÒ
Ð
à�˜ !™Ð#Ô$¨Ò/Ð/ØˆEÝ  W¨q¡[°¸1±Ð%<Ô =Ñ>Ô>ˆà�˜ 1™Ð$Ô%Ø�˜1‘˜W q™[Ð(Ô)Ø�˜1‘˜W q™[¨6Ñ1Ð1Ô2ð
ð 	
ð 	
ð 	
ð
 	�1�v‘:Ñˆð �HÒ
Ð
Ð
Ð
Ð
Ð
r8   c              #   óÖ   K  — d}t          | ¦  «        }||k     rOt          | |dz   |dz   …         ¦  «        }| ||dz   …         | |dz   |dz   |z   …         fV — |d|z   z  }||k     °MdS dS )a`  
    Creates a generator returning tuples of information about each message in
    a byte string of data from a TLS handshake record

    :param data:
        A byte string of a TLS handshake record data

    :return:
        A generator that yields 2-element tuples:
        [0] Byte string of message type
        [1] Byte string of message data
    r   r   é   Nrb   rc   s       r7   r   r   #  sª   è è € ð €GÝ�4‰yŒy€HØ
�HÒ
Ð
Ý  W¨q¡[°¸1±Ð%<Ô =Ñ>Ô>ˆà�˜ 1™Ð$Ô%Ø�˜1‘˜W q™[¨6Ñ1Ð1Ô2ð
ð 	
ð 	
ð 	
ð 	�1�v‘:Ñˆð �HÒ
Ð
Ð
Ð
Ð
Ð
r8   c              #   ó"  K  — | dk    rdS t          | dd…         ¦  «        }d}d|z   }|}||k     r^t          | ||dz   …         ¦  «        }t          | |dz   |dz   …         ¦  «        }|| |dz   |dz   |z   …         fV — |d|z   z  }||k     °\dS dS )a¹  
    Creates a generator returning tuples of information about each extension
    from a byte string of extension data contained in a ServerHello ores
    ClientHello message

    :param data:
        A byte string of a extension data from a TLS ServerHello or ClientHello
        message

    :return:
        A generator that yields 2-element tuples:
        [0] Byte string of extension type
        [1] Byte string of extension data
    r8   Nr   r=   rh   )r
   )rd   Úextentions_lengthÚextensions_startÚextensions_endr2   r[   Úextension_lengths          r7   rQ   rQ   <  så   è è € ð  ˆs‚{€{Øˆå& t¨A¨a¨C¤yÑ1Ô1ÐØÐØÐ*Ñ*€Nà€GØ
�NÒ
"Ð
"Ý'¨¨W°W¸q±[Ð-@Ô(AÑBÔBˆÝ)¨$¨w¸©{¸7ÀQ¹;Ð/FÔ*GÑHÔHÐàØ�˜1‘˜W q™[Ð+;Ñ;Ð;Ô<ð
ð 	
ð 	
ð 	
ð 	�1Ð'Ñ'Ñ'ˆð �NÒ
"Ð
"Ð
"Ð
"Ð
"Ð
"r8   c                 óD  — t          j        d|¦  «        p|                     d¦  «        dk    }|rd|z  }nd|z  }d|z  }d                     | j        ¦  «        }d                     | j        ¦  «        }|r|d|z  z  }|r|r|d	z  }|r|d
|z  z  }t          || ¦  «        ‚)z´
    Raises a TLSVerificationError due to a hostname mismatch

    :param certificate:
        An asn1crypto.x509.Certificate object

    :raises:
        TLSVerificationError
    z^\d+\.\d+\.\d+\.\d+$ú:éÿÿÿÿzIP address %szdomain name %sz:Server certificate verification failed - %s does not matchz, z valid domains: %sz orz valid IP addresses: %s)ÚreÚmatchÚfindÚjoinÚ	valid_ipsÚvalid_domainsr   )ÚcertificateÚhostnameÚis_ipÚhostname_typeÚmessageru   rv   s          r7   r   r   ^  sÖ   € õ ŒHÐ2°HÑ=Ô=ÐYÀÇÂÈsÑASÔASÐWYÒAY€EØð 4Ø'¨(Ñ2ˆˆà(¨8Ñ3ˆØJÈ]ÑZ€GØ—	’	˜+Ô/Ñ0Ô0€IØ—I’I˜kÔ7Ñ8Ô8€MØð 8ØÐ'¨-Ñ7Ñ7ˆØð ˜ð Ø�5ÑˆØð 9ØÐ,¨yÑ8Ñ8ˆÝ
˜w¨Ñ
4Ô
4Ð4r8   c                 ó&   — d}t          || ¦  «        ‚)z¡
    Raises a generic TLSVerificationError

    :param certificate:
        An asn1crypto.x509.Certificate object

    :raises:
        TLSVerificationError
    z&Server certificate verification failed©r   ©rw   r{   s     r7   r!   r!   z  s   € ð 7€GÝ
˜w¨Ñ
4Ô
4Ð4r8   c                 ó&   — d}t          || ¦  «        ‚)zÐ
    Raises a TLSVerificationError when a certificate uses a weak signature
    algorithm

    :param certificate:
        An asn1crypto.x509.Certificate object

    :raises:
        TLSVerificationError
    zMServer certificate verification failed - weak certificate signature algorithmr}   r~   s     r7   r"   r"   ‰  s   € ð ^€GÝ
˜w¨Ñ
4Ô
4Ð4r8   c                  ó$   — d} t          | ¦  «        ‚)zg
    Raises a TLSError indicating client authentication is required

    :raises:
        TLSError
    z5TLS handshake failed - client authentication required©r   )r{   s    r7   r   r   ™  s   € ð F€GÝ
�7Ñ
Ô
Ðr8   c                 ó&   — d}t          || ¦  «        ‚)z¾
    Raises a TLSVerificationError due to the certificate being revoked

    :param certificate:
        An asn1crypto.x509.Certificate object

    :raises:
        TLSVerificationError
    zEServer certificate verification failed - certificate has been revokedr}   r~   s     r7   r   r   ¥  s   € ð V€GÝ
˜w¨Ñ
4Ô
4Ð4r8   c                 ó&   — d}t          || ¦  «        ‚)zÏ
    Raises a TLSVerificationError due to no issuer certificate found in trust
    roots

    :param certificate:
        An asn1crypto.x509.Certificate object

    :raises:
        TLSVerificationError
    zgServer certificate verification failed - certificate issuer not found in trusted root certificate storer}   r~   s     r7   r   r   ´  s   € ð x€GÝ
˜w¨Ñ
4Ô
4Ð4r8   c                 ó&   — d}t          || ¦  «        ‚)zÄ
    Raises a TLSVerificationError due to a self-signed certificate
    roots

    :param certificate:
        An asn1crypto.x509.Certificate object

    :raises:
        TLSVerificationError
    zCServer certificate verification failed - certificate is self-signedr}   r~   s     r7   r    r    Ä  s   € ð T€GÝ
˜w¨Ñ
4Ô
4Ð4r8   c                 ó&   — d}t          || ¦  «        ‚)zî
    Raises a TLSVerificationError due to a certificate lifetime exceeding
    the CAB forum certificate lifetime limit

    :param certificate:
        An asn1crypto.x509.Certificate object

    :raises:
        TLSVerificationError
    zIServer certificate verification failed - certificate lifetime is too longr}   r~   s     r7   Úraise_lifetime_too_longr†   Ô  s   € ð Z€GÝ
˜w¨Ñ
4Ô
4Ð4r8   c                 ó0  — | d         d         }|d         j         }|d         j         }t          j        t          j        ¦  «        }||k    r|                     d¦  «        }d|z  }n ||k     r|                     d¦  «        }d|z  }t          || ¦  «        ‚)zÖ
    Raises a TLSVerificationError due to certificate being expired, or not yet
    being valid

    :param certificate:
        An asn1crypto.x509.Certificate object

    :raises:
        TLSVerificationError
    Útbs_certificateÚvalidityÚ	not_afterÚ
not_beforez%Y-%m-%d %H:%M:%SZzGServer certificate verification failed - certificate not valid until %sz?Server certificate verification failed - certificate expired %s)Únativer   Únowr   ÚutcÚstrftimer   )rw   r‰   rŠ   r‹   r�   Úformatted_beforer{   Úformatted_afters           r7   r   r   ä  s¤   € ð Ð,Ô-¨jÔ9€HØ˜Ô%Ô,€IØ˜,Ô'Ô.€Jå
Œ,•x”|Ñ
$Ô
$€Cà�CÒÐØ%×.Ò.Ð/CÑDÔDÐØ[Ð^nÑnˆˆØ	�SŠˆØ#×,Ò,Ð-AÑBÔBˆØSÐVeÑeˆå
˜w¨Ñ
4Ô
4Ð4r8   c                  ó    — t          d¦  «        ‚)ze
    Raises a TLSDisconnectError due to a disconnection

    :raises:
        TLSDisconnectError
    z$The remote end closed the connection)r   © r8   r7   r   r      s   € õ ÐCÑ
DÔ
DÐDr8   c                 óf   — t          | ¦  «        }|rt          d|z  ¦  «        ‚t          d¦  «        ‚)z»
    Raises a TLSError due to a protocol error

    :param server_handshake_bytes:
        A byte string of the handshake data received from the server

    :raises:
        TLSError
    z.TLS protocol error - server responded using %sz@TLS protocol error - server responded using a different protocol)Údetect_other_protocolr   )r*   Úother_protocols     r7   r   r     s>   € õ +Ð+AÑBÔB€Nàð ZÝÐGÈ.ÑXÑYÔYÐYå
ÐUÑ
VÔ
VÐVr8   c                  ó    — t          d¦  «        ‚)zS
    Raises a TLSError due to a handshake error

    :raises:
        TLSError
    zTLS handshake failedr�   r“   r8   r7   r   r     s   € õ Ð)Ñ
*Ô
*Ð*r8   c                  ó    — t          d¦  «        ‚)z_
    Raises a TLSError due to a TLS version incompatibility

    :raises:
        TLSError
    z-TLS handshake failed - protocol version errorr�   r“   r8   r7   Úraise_protocol_versionr™   )  s   € õ ÐBÑ
CÔ
CÐCr8   c                  ó    — t          d¦  «        ‚)zP
    Raises a TLSError due to weak DH params

    :raises:
        TLSError
    z)TLS handshake failed - weak DH parametersr�   r“   r8   r7   r   r   4  s   € õ Ð>Ñ
?Ô
?Ð?r8   c                 ó  — | dd…         dk    rdS | dd…         dk    r$t          j        d| t           j        ¦  «        rdS d	S | dd…         d
k    rdS | dd…         dk    rdS | dd…         dk    s| dd…         dk    rdS dS )a  
    Looks at the server handshake bytes to try and detect a different protocol

    :param server_handshake_bytes:
        A byte string of the handshake data received from the server

    :return:
        None, or a unicode string of "ftp", "http", "imap", "pop3", "smtp"
    r   ra   s   HTTP/ÚHTTPrh   s   220 s
   ^[^
]*ftpÚFTPÚSMTPs   220-s   +OK ÚPOP3s   * OKé	   s	   * PREAUTHÚIMAPN)rq   rr   ÚI)r*   s    r7   r•   r•   ?  s¹   € ð ˜a ˜cÔ" hÒ.Ð.Øˆvà˜a ˜cÔ" gÒ-Ð-ÝŒ8�OÐ%;½R¼TÑBÔBð 	Ø�5à�6à˜a ˜cÔ" gÒ-Ð-Øˆuà˜a ˜cÔ" gÒ-Ð-Øˆvà˜a ˜cÔ" gÒ-Ð-Ð1GÈÈ!ÈÔ1LÐP\Ò1\Ð1\Øˆvàˆ4r8   ))Ú
__future__r   r   r   r   rq   r   Ú_asn1r	   r
   r   Ú_cipher_suitesr   Úerrorsr   r   r   Ú__all__r   r   r   r   r   r   r   rQ   r   r!   r"   r   r   r   r    r†   r   r   r   r   r™   r   r•   r“   r8   r7   ú<module>r¨      s  ðà RÐ RÐ RÐ RÐ RÐ RÐ RÐ RÐ RÐ RÐ RÐ Rà 	€	€	€	Ø Ð Ð Ð Ð Ð à 8Ð 8Ð 8Ð 8Ð 8Ð 8Ð 8Ð 8Ð 8Ð 8Ø ,Ð ,Ð ,Ð ,Ð ,Ð ,Ø FÐ FÐ FÐ FÐ FÐ FÐ FÐ FÐ FÐ Fðð ð €ð.%ð %ð %ðPð ð ð*ð ð ð>ð ð ð,lð lð lð^ð ð ð>ð ð ð2(ð (ð (ðD5ð 5ð 5ð85ð 5ð 5ð5ð 5ð 5ð 	ð 	ð 	ð5ð 5ð 5ð5ð 5ð 5ð 5ð 5ð 5ð 5ð 5ð 5ð 5ð 5ð 5ð8Eð Eð EðWð Wð Wð&+ð +ð +ðDð Dð Dð@ð @ð @ðð ð ð ð r8   