§
    ¥”j)(  ã                   ót  — d dl Z d dlZd dlmZ d dlmZ d dlmZ d dlmZm	Z	 ddl
mZ ddlmZ  G d	„ d
ej        ¦  «        Z ed¬¦  «         G d„ d¦  «        ¦   «         Z G d„ de j        ¦  «        Z G d„ d¦  «        Zde	j        defd„Z G d„ de¦  «        Z G d„ de¦  «        Z G d„ de¦  «        ZdS )é    N)Ú	dataclass)Údatetime)ÚOptional)ÚkeysÚx509é   )Úprocess_general_subtrees)ÚPKIXValidationParamsc                   ó$   — e Zd ZdZ	 dZ	 dZ	 dZdS )ÚTrustedServiceTyper   r   é   é   N)Ú__name__Ú
__module__Ú__qualname__ÚUNSPECIFIEDÚUNSUPPORTEDÚCERTIFICATE_AUTHORITYÚTIME_STAMPING_AUTHORITY© ó    ún/var/www/finuniver-perm.ru/html/portfolio/venv/lib/python3.11/site-packages/pyhanko_certvalidator/authority.pyr   r      s?   € € € € € Ø€Kðð €Kðð Ððð  Ððð r   r   T)Úfrozenc                   ó¸   — e Zd ZU dZdZed         ed<   	 dZee         ed<   	 dZ	ee         ed<   	 dZ
ee         ed<   	 dZee         ed<   	 ej        Zeed	<   dS )
ÚTrustQualifierszY
    .. versionadded 0.20.0

    Parameters that allow a trust root to be qualified.
    Nr
   Ústandard_parametersÚmax_path_lengthÚmax_aa_path_lengthÚ
valid_fromÚvalid_untilÚtrusted_service_type)r   r   r   Ú__doc__r   r   Ú__annotations__r   Úintr   r   r   r    r   r   r!   r   r   r   r   r   .   sÆ   € € € € € € ðð ð =AÐ˜Ð"8Ô9Ð@Ð@Ñ@ðð
 &*€O�X˜c”]Ð)Ð)Ñ)ðð
 )-Ð˜ œÐ,Ð,Ñ,ðð
 &*€J�˜Ô"Ð)Ð)Ñ)ðð '+€K�˜(Ô#Ð*Ð*Ñ*ðð 0BÔ/MÐÐ,ÐMÐMÑMðð r   r   c                   óÂ   — e Zd ZdZedej        fd„¦   «         Zedej	        fd„¦   «         Z
ed„ ¦   «         Zd„ Zd„ Zedee         fd„¦   «         Zd	ej        defd
„ZdS )Ú	AuthorityzM
    .. versionadded:: 0.20.0

    Abstract authority, i.e. a named key.
    Úreturnc                 ó   — t           ‚)z'
        The authority's name.
        ©ÚNotImplementedError©Úselfs    r   ÚnamezAuthority.name_   ó
   € õ
 "Ð!r   c                 ó   — t           ‚)z-
        The authority's public key.
        r)   r+   s    r   Ú
public_keyzAuthority.public_keyf   r.   r   c                 ó   — t           ‚)zm
        A hashable unique identifier of the authority, used in ``__eq__``
        and ``__hash__``.
        r)   r+   s    r   ÚhashablezAuthority.hashablem   s
   € õ "Ð!r   c                 ó*   — t          | j        ¦  «        S ©N)Úhashr2   r+   s    r   Ú__hash__zAuthority.__hash__u   s   € Ý�D”MÑ"Ô"Ð"r   c                 óP   — t          |t          ¦  «        sdS | j        |j        k    S ©NF)Ú
isinstancer&   r2   ©r,   Úothers     r   Ú__eq__zAuthority.__eq__x   s(   € Ý˜%¥Ñ+Ô+ð 	Ø�5àŒ} ¤Ò.Ð.r   c                 ó   — t           ‚)zá
        Key ID as (potentially) referenced in an authorityKeyIdentifier
        extension. Only used to eliminate non-matching trust anchors,
        never to retrieve keys or to definitively identify trust anchors.
        r)   r+   s    r   Úkey_idzAuthority.key_id~   s
   € õ "Ð!r   Úcertc                 ój   — |j         | j        k    rdS |j        r| j        r|j        | j        k    rdS dS )zñ
        Function to determine whether this trust root could potentially be an
        issuer of a given certificate.
        This function is used during path building.

        :param cert:
            The certificate to evaluate.
        FT)Úissuerr-   Úauthority_key_identifierr>   ©r,   r?   s     r   Úis_potential_issuer_ofz Authority.is_potential_issuer_of‡   sF   € ð Œ;˜$œ)Ò#Ð#Ø�5ØÔ(ð 	¨T¬[ð 	ØÔ,°´Ò;Ð;Ø�uØˆtr   N)r   r   r   r"   Úpropertyr   ÚNamer-   r   ÚPublicKeyInfor0   r2   r6   r<   r   Úbytesr>   ÚCertificateÚboolrD   r   r   r   r&   r&   X   sú   € € € € € ðð ð ð"�d”ið "ð "ð "ñ „Xð"ð ð"˜DÔ.ð "ð "ð "ñ „Xð"ð ð"ð "ñ „Xð"ð#ð #ð #ð/ð /ð /ð ð"˜ œð "ð "ð "ñ „Xð"ð¨4Ô+;ð Àð ð ð ð ð ð r   r&   c                   óv   — e Zd ZdZ	 ddedee         fd„Zedefd„¦   «         Z	edefd„¦   «         Z
d	„ Zd
„ ZdS )ÚTrustAnchorz’
    Abstract trust root. A trust root is an authority with trust qualifiers.
    Equality of trust roots reduces to equality of authorities.
    NÚ	authorityÚqualsc                 ó"   — || _         || _        d S r4   )Ú
_authorityÚ_quals)r,   rM   rN   s      r   Ú__init__zTrustAnchor.__init__ž   s   € ð $ˆŒØˆŒˆˆr   r'   c                 ó   — | j         S r4   )rP   r+   s    r   rM   zTrustAnchor.authority¤   s
   € àŒÐr   c                 ó,   — | j         pt          ¦   «         S )z0
        Qualifiers for the trust root.
        )rQ   r   r+   s    r   Útrust_qualifierszTrustAnchor.trust_qualifiers¨   s   € ð
 Œ{Ð/�oÑ/Ô/Ð/r   c                 óL   — t          |t          ¦  «        o|j        | j        k    S r4   )r9   rL   rP   r:   s     r   r<   zTrustAnchor.__eq__¯   s&   € å�u�kÑ*Ô*ð 4ØÔ  D¤OÒ3ð	
r   c                 ó*   — t          | j        ¦  «        S r4   )r5   rP   r+   s    r   r6   zTrustAnchor.__hash__µ   s   € Ý�D”OÑ$Ô$Ð$r   r4   )r   r   r   r"   r&   r   r   rR   rE   rM   rU   r<   r6   r   r   r   rL   rL   ˜   s¿   € € € € € ðð ð HLðð Ø"ðØ+3°OÔ+Dðð ð ð ð ð˜9ð ð ð ñ „Xðð ð0 /ð 0ð 0ð 0ñ „Xð0ð
ð 
ð 
ð%ð %ð %ð %ð %r   rL   r?   r'   c                 ó  — d}dx}}| j         �kd}| j         }|d         }t          |t          j        ¦  «        rt	          |¦  «        }|d         }t          |t          j        ¦  «        rt	          |¦  «        }d}| j        �"d}| j        }t          d„ |D ¦   «         ¦  «        }d}	|r%t          |pt          dg¦  «        |du||¬¦  «        }	t          | j	        |	| j
        | j        | j        rt          j        nt          j        ¬	¦  «        S )
a¨  
    Extract trust qualifiers from data and extensions of a certificate.

    .. note::
        Recall that any property of a trust root other than its name and public
        key are in principle irrelevant to the PKIX validation algorithm
        itself.
        This function is merely a helper function that allows the certificate's
        other data to be conveniently gathered to populate the default
        validation parameters for paths deriving from that trust root.

    :param cert:
        The certificate from which to extract qualifiers (usually a
        self-signed one)
    :return:
        A :class:`TrustQualifiers` object with the extracted qualifiers.
    FNTÚpermitted_subtreesÚexcluded_subtreesc                 óJ   — g | ] }|d          j         dk    ¯|d          j        ‘Œ!S )Úpolicy_identifierÚ
any_policy)ÚnativeÚdotted)Ú.0Úpol_infos     r   ú
<listcomp>z*derive_quals_from_cert.<locals>.<listcomp>Ý   s?   € ð ð ð àØÐ/Ô0Ô7¸<ÒGÐGð Ð,Ô-Ô4àGÐGÐGr   r]   )Úuser_initial_policy_setÚinitial_explicit_policyÚinitial_permitted_subtreesÚinitial_excluded_subtrees)r   r   r   r    r!   )Úname_constraints_valuer9   r   ÚGeneralSubtreesr	   Úcertificate_policies_valueÚ	frozensetr
   r   r   Únot_valid_beforeÚnot_valid_afterÚcar   r   r   )
r?   Ú	ext_foundrY   rZ   Únc_extÚpermitted_valÚexcluded_valÚacceptable_policiesÚpolicies_valÚparamss
             r   Úderive_quals_from_certru   ¹   s_  € ð& €IØ-1Ð1ÐÐ*ØÔ"Ð.Øˆ	Ø'+Ô'BˆØÐ3Ô4ˆÝ�m¥TÔ%9Ñ:Ô:ð 	IÝ!9¸-Ñ!HÔ!HÐØÐ1Ô2ˆÝ�l¥DÔ$8Ñ9Ô9ð 	GÝ 8¸Ñ FÔ FÐàÐØÔ&Ð2Øˆ	Ø15Ô1PˆÝ'ðð à ,ðñ ô ñ
ô 
Ðð €FØð 

Ý%à#Ð@¥y°,°Ñ'@Ô'@ð %8¸tÐ$CØ'9Ø&7ð	
ñ 	
ô 	
ˆõ ØÔ,Ø"ØÔ(ØÔ(ð Œwð0ÕÔ4Ð4å#Ô/ð
ñ 
ô 
ð 
r   c                   óè   ‡ — e Zd ZdZdej        fd„Zedej        fd„¦   «         Z	ed„ ¦   «         Z
ed„ ¦   «         Zedee         fd„¦   «         Zedej        fd	„¦   «         Zdej        fˆ fd
„Zˆ xZS )ÚAuthorityWithCertzz
    .. versionadded:: 0.20.0

    Authority provisioned as a certificate.

    :param cert:
        The certificate.
    r?   c                 ó   — || _         d S r4   ©Ú_certrC   s     r   rR   zAuthorityWithCert.__init__  s   € ØˆŒ
ˆ
ˆ
r   r'   c                 ó   — | j         j        S r4   )rz   Úsubjectr+   s    r   r-   zAuthorityWithCert.name  s   € àŒzÔ!Ð!r   c                 ó   — | j         j        S r4   )rz   r0   r+   s    r   r0   zAuthorityWithCert.public_key  s   € àŒzÔ$Ð$r   c                 óZ   — | j         }|j        j        |j                             ¦   «         fS r4   )rz   r|   r2   r0   ÚdumprC   s     r   r2   zAuthorityWithCert.hashable  s'   € àŒzˆØŒ|Ô$ d¤o×&:Ò&:Ñ&<Ô&<Ð<Ð<r   c                 ó   — | j         j        S r4   )rz   Úkey_identifierr+   s    r   r>   zAuthorityWithCert.key_id  s   € àŒzÔ(Ð(r   c                 ó   — | j         S r4   ry   r+   s    r   ÚcertificatezAuthorityWithCert.certificate  ó
   € àŒzÐr   c                 óŠ   •— t          ¦   «                              |¦  «        sdS |j        r|j        | j        j        k    rdS dS )NFT)ÚsuperrD   Úauthority_issuer_serialrz   Úissuer_serial)r,   r?   Ú	__class__s     €r   rD   z(AuthorityWithCert.is_potential_issuer_of   sJ   ø€ Ý‰wŒw×-Ò-¨dÑ3Ô3ð 	Ø�5ØÔ'ð 	ØÔ+¨t¬zÔ/GÒGÐGØ�uØˆtr   )r   r   r   r"   r   rI   rR   rE   rF   r-   r0   r2   r   rH   r>   rƒ   rD   Ú__classcell__©r‰   s   @r   rw   rw   þ   s#  ø€ € € € € ðð ð˜TÔ-ð ð ð ð ð ð"�d”ið "ð "ð "ñ „Xð"ð ð%ð %ñ „Xð%ð ð=ð =ñ „Xð=ð ð)˜ œð )ð )ð )ñ „Xð)ð ð˜TÔ-ð ð ð ñ „Xðð¨4Ô+;ð ð ð ð ð ð ð ð ð ð r   rw   c                   óŽ   ‡ — e Zd ZdZ	 	 ddej        dee         defˆ fd„Z	e
dej        fd	„¦   «         Ze
defd
„¦   «         Zˆ xZS )ÚCertTrustAnchoraŒ  
    .. versionadded:: 0.20.0

    Trust anchor provisioned as a certificate.

    :param cert:
        The certificate, usually self-signed.
    :param quals:
        Explicit trust qualifiers.
    :param derive_default_quals_from_cert:
        Flag indicating to derive default trust qualifiers from the certificate
        content if explicit ones are not provided. Defaults to ``False``.
    NFr?   rN   Úderive_default_quals_from_certc                 ó†   •— t          |¦  «        }|| _        t          ¦   «                              ||¦  «         || _        d S r4   )rw   rz   r†   rR   Ú_derive)r,   r?   rN   rŽ   rM   r‰   s        €r   rR   zCertTrustAnchor.__init__8  s>   ø€ õ & dÑ+Ô+ˆ	ØˆŒ
Ý‰Œ×Ò˜ EÑ*Ô*Ð*Ø5ˆŒˆˆr   r'   c                 ó   — | j         S r4   ry   r+   s    r   rƒ   zCertTrustAnchor.certificateC  r„   r   c                 ó‚   — | j         �| j         S | j        rt          | j        ¦  «        x| _         }|S t	          ¦   «         S r4   )rQ   r�   ru   rz   r   )r,   rN   s     r   rU   z CertTrustAnchor.trust_qualifiersG  sC   € àŒ;Ð"Ø”;ÐØŒ\ð 	%Ý"8¸¼Ñ"DÔ"DÐDˆDŒK˜%ØˆLå"Ñ$Ô$Ð$r   r8   )r   r   r   r"   r   rI   r   r   rJ   rR   rE   rƒ   rU   rŠ   r‹   s   @r   r�   r�   )  sÉ   ø€ € € € € ðð ð" ,0Ø/4ð		6ð 	6àÔð	6ð ˜Ô(ð	6ð )-ð		6ð 	6ð 	6ð 	6ð 	6ð 	6ð ð˜TÔ-ð ð ð ñ „Xðð ð% /ð %ð %ð %ñ „Xð%ð %ð %ð %ð %r   r�   c                   ó°   — e Zd ZdZdej        dej        fd„Ze	dej        fd„¦   «         Z
e	d„ ¦   «         Ze	dee         fd„¦   «         Ze	d	„ ¦   «         Zd
S )ÚNamedKeyAuthorityzÔ
    Authority provisioned as a named key.

    :param entity_name:
        The name of the entity that controls the private key of the trust root.
    :param public_key:
        The trust root's public key.
    Úentity_namer0   c                 ó"   — || _         || _        d S r4   )Ú_nameÚ_public_key)r,   r•   r0   s      r   rR   zNamedKeyAuthority.__init__\  s   € Ø ˆŒ
Ø%ˆÔÐÐr   r'   c                 ó   — | j         S r4   )r—   r+   s    r   r-   zNamedKeyAuthority.name`  r„   r   c                 ó   — | j         S r4   )r˜   r+   s    r   r0   zNamedKeyAuthority.public_keyd  s   € àÔÐr   c                 ó   — d S r4   r   r+   s    r   r>   zNamedKeyAuthority.key_idh  s   € àˆtr   c                 óL   — | j         j        | j                             ¦   «         fS r4   )r—   r2   r˜   r   r+   s    r   r2   zNamedKeyAuthority.hashablel  s!   € àŒzÔ" DÔ$4×$9Ò$9Ñ$;Ô$;Ð;Ð;r   N)r   r   r   r"   r   rF   r   rG   rR   rE   r-   r0   r   rH   r>   r2   r   r   r   r”   r”   R  sÏ   € € € € € ðð ð& D¤Ið &¸4Ô;Mð &ð &ð &ð &ð ð�d”ið ð ð ñ „Xðð ð ð  ñ „Xð ð ð˜ œð ð ð ñ „Xðð ð<ð <ñ „Xð<ð <ð <r   r”   )ÚabcÚenumÚdataclassesr   r   Útypingr   Ú
asn1cryptor   r   Ú
name_treesr	   Úpolicy_declr
   ÚEnumr   r   ÚABCr&   rL   rI   ru   rw   r�   r”   r   r   r   ú<module>r¦      s  ðØ 
€
€
€
Ø €€€Ø !Ð !Ð !Ð !Ð !Ð !Ø Ð Ð Ð Ð Ð Ø Ð Ð Ð Ð Ð à !Ð !Ð !Ð !Ð !Ð !Ð !Ð !à 0Ð 0Ð 0Ð 0Ð 0Ð 0Ø -Ð -Ð -Ð -Ð -Ð -ðð ð ð ð ˜œñ ô ð ðB €�$ÐÑÔð&ð &ð &ð &ð &ñ &ô &ñ Ôð&ðR=ð =ð =ð =ð =�”ñ =ô =ð =ð@%ð %ð %ð %ð %ñ %ô %ð %ðBB Ô!1ð B°oð Bð Bð Bð BðJ(ð (ð (ð (ð (˜	ñ (ô (ð (ðV&%ð &%ð &%ð &%ð &%�kñ &%ô &%ð &%ðR<ð <ð <ð <ð <˜	ñ <ô <ð <ð <ð <r   