/var/opt/nydus/ops/cryptography/x509/__pycache__
NameSizeModeActions
base.cpython-312.pyc474540644editdlrm
certificate_transparency.cpython-312.pyc41230644editdlrm
extensions.cpython-312.pyc1004660644editdlrm
general_name.cpython-312.pyc137870644editdlrm
name.cpython-312.pyc235830644editdlrm
ocsp.cpython-312.pyc264510644editdlrm
oid.cpython-312.pyc6280644editdlrm
__init__.cpython-312.pyc79690644editdlrm
Edit: /var/opt/nydus/ops/cryptography/x509/__pycache__/ocsp.cpython-312.pyc (26451B)
O jKH\ddlZddlZddlZddlmZmZddlmZddlm Z m Z ddl m Z ddl mZmZmZGddej"ZGd d ej"Ze j(e j*e j,e j.e j0fZd e j4d dfd ZGddej"ZGddZGddej<ZGddej<Z Gddej<Z!GddZ"GddZ#de$d efdZ%de$d e!fdZ&y) N)utilsx509)ocsp)hashes serialization)CERTIFICATE_PRIVATE_KEY_TYPES)_EARLIEST_UTC_TIME_convert_to_naive_utc_time_reject_duplicate_extensionceZdZdZdZy)OCSPResponderEncodingzBy HashzBy NameN)__name__ __module__ __qualname__HASHNAMEG/opt/nydus/tmp/pip-target-a90h98xg/lib/python/cryptography/x509/ocsp.pyr r s D Drr c$eZdZdZdZdZdZdZdZy)OCSPResponseStatusrN) rrr SUCCESSFULMALFORMED_REQUESTINTERNAL_ERROR TRY_LATER SIG_REQUIRED UNAUTHORIZEDrrrrrs!JNILLrr algorithmreturnc:t|ts tdy)Nz9Algorithm must be SHA1, SHA224, SHA256, SHA384, or SHA512) isinstance_ALLOWED_HASHES ValueError)r#s r_verify_algorithmr).s! i 1 G   2rceZdZdZdZdZy)OCSPCertStatusrrrN)rrrGOODREVOKEDUNKNOWNrrrr+r+5s DGGrr+ceZdZdejdejdej dedejde jejde jejde jejfd Z y ) _SingleResponsecertissuerr# cert_status this_update next_updaterevocation_timerevocation_reasonc t|tjrt|tjs tdt |t|t j s td|%t|t j s td||_||_||_||_ ||_ t|ts td|tjur| td|vtdt|t j s tdt|}|tkr td|%t|tj s td ||_||_||_y) N%cert and issuer must be a Certificatez%this_update must be a datetime objectz-next_update must be a datetime object or Nonez8cert_status must be an item from the OCSPCertStatus enumzBrevocation_time can only be provided if the certificate is revokedzDrevocation_reason can only be provided if the certificate is revokedz)revocation_time must be a datetime objectz7The revocation_time must be on or after 1950 January 1.zCrevocation_reason must be an item from the ReasonFlags enum or None)r&r Certificate TypeErrorr)datetime_cert_issuer _algorithm _this_update _next_updater+r-r(r r ReasonFlags _cert_status_revocation_time_revocation_reason) selfr1r2r#r3r4r5r6r7s r__init__z_SingleResponse.__init__<s$ 0 01 D$$: CD D)$+x'8'89CD D  ": **, KL L  #''+~6J  n44 4* !!, " ox/@/@A KLL8IO!33 ' !,Z!4#3#36 # ( /"3rN) rrrrr:r HashAlgorithmr+r<typingOptionalrBrGrrrr0r0;sB4B4  B4'' B4 $ B4 && B4__X%6%67B4 ):):;B4"??4+;+;<B4rr0czeZdZeej defdZeej defdZeej de jfdZ eej de fdZ ej dejdefdZeej dej$fdZy ) OCSPRequestr$cyz3 The hash of the issuer public key NrrFs rissuer_key_hashzOCSPRequest.issuer_key_hashrcyz- The hash of the issuer name NrrOs rissuer_name_hashzOCSPRequest.issuer_name_hashrQrcyzK The hash algorithm used in the issuer name and key hashes NrrOs rhash_algorithmzOCSPRequest.hash_algorithmrQrcyzM The serial number of the cert whose status is being checked NrrOs r serial_numberzOCSPRequest.serial_numberrQrencodingcy)z/ Serializes the request to DER NrrFr[s r public_byteszOCSPRequest.public_bytesrQrcy)zP The list of request extensions. Not single request extensions. NrrOs r extensionszOCSPRequest.extensionsrQrN)rrrpropertyabcabstractmethodbytesrPrTrrHrWintrZrEncodingr^r Extensionsr`rrrrLrLs     %    4 4   s    ]%;%;    DOO  rrL) metaclassceZdZeej defdZeej deje jfdZ eej deje jfdZeej de jfdZeej deje jfdZeej defdZeej defdZeej dej*fd Zeej defd Zy ) OCSPSingleResponser$cyzY The status of the certificate (an element from the OCSPCertStatus enum) NrrOs rcertificate_statusz%OCSPSingleResponse.certificate_statusrQrcyz^ The date of when the certificate was revoked or None if not revoked. NrrOs rr6z"OCSPSingleResponse.revocation_timerQrcyzi The reason the certificate was revoked or None if not specified or not revoked. NrrOs rr7z$OCSPSingleResponse.revocation_reasonrQrcyz The most recent time at which the status being indicated is known by the responder to have been correct NrrOs rr4zOCSPSingleResponse.this_updaterQrcyzC The time when newer information will be available NrrOs rr5zOCSPSingleResponse.next_updaterQrcyrNrrOs rrPz"OCSPSingleResponse.issuer_key_hashrQrcyrSrrOs rrTz#OCSPSingleResponse.issuer_name_hashrQrcyrVrrOs rrWz!OCSPSingleResponse.hash_algorithmrQrcyrYrrOs rrZz OCSPSingleResponse.serial_numberrQrN)rrrrarbrcr+rmrIrJr<r6rrBr7r4r5rdrPrTrrHrWrerZrrrrjrjs  N   1B1B!C   6??43C3C#D   X..   V__X->->?      %    4 4   s  rrjcReZdZeej dejefdZ eej de fdZ eej de jfdZeej dejej"fdZeej defdZeej defdZeej dej,e j.fdZeej dejefd Zeej deje j4fd Zeej dej8fd Zeej defd Zeej dejej8fd Z eej deje jBfdZ"eej dej8fdZ#eej dejej8fdZ$eej defdZ%eej defdZ&eej dej"fdZ'eej de(fdZ)eej de jTfdZ+eej de jTfdZ,ej de-j\defdZ/y) OCSPResponser$cy)z_ An iterator over the individual SINGLERESP structures in the response NrrOs r responseszOCSPResponse.responsesrQrcy)zm The status of the response. This is a value from the OCSPResponseStatus enumeration NrrOs rresponse_statuszOCSPResponse.response_statusrQrcy)zA The ObjectIdentifier of the signature algorithm NrrOs rsignature_algorithm_oidz$OCSPResponse.signature_algorithm_oidrQrcy)zX Returns a HashAlgorithm corresponding to the type of the digest signed NrrOs rsignature_hash_algorithmz%OCSPResponse.signature_hash_algorithmrQrcy)z% The signature bytes NrrOs r signaturezOCSPResponse.signaturerQrcy)z+ The tbsResponseData bytes NrrOs rtbs_response_byteszOCSPResponse.tbs_response_bytesrQrcy)z A list of certificates used to help build a chain to verify the OCSP response. This situation occurs when the OCSP responder uses a delegate certificate. NrrOs r certificateszOCSPResponse.certificatesrQrcy)z2 The responder's key hash or None NrrOs rresponder_key_hashzOCSPResponse.responder_key_hash(rQrcy)z. The responder's Name or None NrrOs rresponder_namezOCSPResponse.responder_name/rQrcy)z4 The time the response was produced NrrOs r produced_atzOCSPResponse.produced_at6rQrcyrlrrOs rrmzOCSPResponse.certificate_status=rQrcyrorrOs rr6zOCSPResponse.revocation_timeDrQrcyrqrrOs rr7zOCSPResponse.revocation_reasonLrQrcyrsrrOs rr4zOCSPResponse.this_updateTrQrcyrurrOs rr5zOCSPResponse.next_update\rQrcyrNrrOs rrPzOCSPResponse.issuer_key_hashcrQrcyrSrrOs rrTzOCSPResponse.issuer_name_hashjrQrcyrVrrOs rrWzOCSPResponse.hash_algorithmqrQrcyrYrrOs rrZzOCSPResponse.serial_numberxrQrcy)zR The list of response extensions. Not single response extensions. NrrOs rr`zOCSPResponse.extensionsrQrcy)zR The list of single response extensions. Not response extensions. NrrOs rsingle_extensionszOCSPResponse.single_extensionsrQrr[cy)z0 Serializes the response to DER Nrr]s rr^zOCSPResponse.public_bytesrQrN)0rrrrarbrcrIIteratorrjr}rrrObjectIdentifierrrJrrHrrdrrListr:rrNamerr<rr+rmr6rBr7r4r5rPrTrWrerZrgr`rrrfr^rrrr{r{s  6??+=>   !3   )>)>   -- .   5   E   fkk$*:*:;   FOOE$:    :   X..   N   1B1B!C   6??43C3C#D   X..   V__X->->?      %    4 4   s   DOO   4??    ]%;%;   rr{c eZdZddgfdejej ejejejfdejej e e e ejfdejejejddfdZdejdejd ejddfd Zd e d e d e d ejddf dZdejdeddfdZdefdZy)OCSPRequestBuilderNrequest request_hashr`r$c.||_||_||_yN)_request _request_hash _extensions)rFrrr`s rrGzOCSPRequestBuilder.__init__s  )%rr1r2r#c$|j |j tdt|t |t j rt |t j s tdt|||f|j|jS)N.Only one certificate can be added to a requestr9) rrr(r)r&rr:r;rr)rFr1r2r#s radd_certificatez"OCSPRequestBuilder.add_certificates == $(:(:(FMN N)$$ 0 01 D$$: CD D! 69 %t'9'94;K;K  rrTrPrZc|j |j tdt|ts t dt |tjd|tjd||jt|k7s|jt|k7r tdt|j||||f|jS)Nrz serial_number must be an integerrTrPz`issuer_name_hash and issuer_key_hash must be the same length as the digest size of the algorithm) rrr(r&rer;r)r _check_bytes digest_sizelenrr)rFrTrPrZr#s radd_certificate_by_hashz*OCSPRequestBuilder.add_certificate_by_hashs == $(:(:(FMN N-->? ?)$ -/?@ ,o>  C %   " "c/&: :6  " MM  y I     rextvalcriticalct|tjs tdtj|j ||}t ||jt|j|j|j|gzSNz"extension must be an ExtensionType) r&r ExtensionTyper; Extensionoidr rrrrrFrr extensions r add_extensionz OCSPRequestBuilder.add_extensionsq&$"4"45@A ANN6::x@ #It/?/?@! MM4--t/?/?9+/M  rcr|j|j tdtj|S)Nz*You must add a certificate before building)rrr(rcreate_ocsp_requestrOs rbuildzOCSPRequestBuilder.builds4 == T%7%7%?IJ J''--r)rrrrIrJTuplerr:rrHrdrerrrrGrrboolrrLrrrrrrsN  FH& LL  $"2"2F4H4HH  &oo LLsF,@,@@ A &KKt/A/A BC& &      ''    &     ''    <  ((  48    .{.rrceZdZdddgfdejedejej eje fdejejejdejejejfdZ dejdejd ejd ed ej"d ejej"d ejej"dejej$ddfdZde dejddfdZdej*ejddfdZdejdeddfdZded ejejdefdZededefdZy)OCSPResponseBuilderNresponse responder_idcertsr`c<||_||_||_||_yr) _response _responder_id_certsr)rFrrrr`s rrGzOCSPResponseBuilder.__init__s"") %rr1r2r#r3r4r5r6r7r$c |j tdt||||||||} t| |j|j |j S)Nz#Only one response per OCSPResponse.)rr(r0rrrr) rFr1r2r#r3r4r5r6r7 singleresps r add_responsez OCSPResponseBuilder.add_responsesg >> %BC C$          #     KK      rr[responder_certc |j tdt|tjs t dt|t s t dt|j||f|j|jS)Nz!responder_id can only be set oncez$responder_cert must be a Certificatez6encoding must be an element from OCSPResponderEncoding) rr(r&rr:r;r rrrr)rFr[rs rrz OCSPResponseBuilder.responder_ids    )@A A.$*:*:;BC C($9:H # NN X & KK      rc |j tdt|}t|dk(r tdt d|Ds t dt |j|j||jS)Nz!certificates may only be set oncerzcerts must not be an empty listc3PK|]}t|tj ywr)r&rr:).0xs r z3OCSPResponseBuilder.certificates..3sBEq:a!1!12Es$&z$certs must be a list of Certificates) rr(listrallr;rrrr)rFrs rrz OCSPResponseBuilder.certificates+s} ;; "@A AU  u:?>? ?BEBBBC C" NN          rrrc.t|tjs tdtj|j ||}t ||jt|j|j|j|j|gzSr) r&rrr;rrr rrrrrrs rrz!OCSPResponseBuilder.add_extension<sz&$"4"45@A ANN6::x@ #It/?/?@" NN    KK    { *   r private_keyc|j td|j tdtjt j |||S)Nz&You must add a response before signingz*You must add a responder_id before signing)rr(rrcreate_ocsp_responserr)rFrr#s rsignzOCSPResponseBuilder.signLsT >> !EF F    %IJ J((  ) )4i  rrct|ts td|tjur t dt j |dddS)Nz7response_status must be an item from OCSPResponseStatusz$response_status cannot be SUCCESSFUL)r&rr;rr(rr)clsrs rbuild_unsuccessfulz&OCSPResponseBuilder.build_unsuccessfulZsS/+=>I  0;; ;CD D(($dKKr)rrrrIrJr0rrr:r rrrrGrrHr+r<rBrrIterablerrrrr{r classmethodrrrrrrrs6: @DFH &///2 &oo LL))+@@ A  & v{{4+;+;<= &KKt/A/A BC &     ''  $  &&  __X%6%67  ):):; "??4+;+;<   > - ?C?O?O  & __T%5%56  " (( 48   2  ??6#7#78      L0 L  L Lrrdatac,tj|Sr)rload_der_ocsp_requestrs rrrhs  % %d ++rc,tj|Sr)rload_der_ocsp_responsers rrrls  & &t ,,r)'rbr<rI cryptographyrr"cryptography.hazmat.bindings._rustrcryptography.hazmat.primitivesrr/cryptography.hazmat.primitives.asymmetric.typesrcryptography.x509.baser r r Enumr rSHA1SHA224SHA256SHA384SHA512r'rHr)r+r0ABCMetarLrjr{rrrdrrrrrrs#   $3@EJJ  KK MM MM MM MM  !5!5 $ UZZ C4C4L( CKK( VA 3;;A Ha S[[a HS.S.l{L{L|,,+,--<-r