o
    Œõ±jRn ã                   @   st  d Z ddlmZmZmZmZ ddlmZ ddlm	Z	 ddl
Z
ddlZddlZddlZddlZddlZddlmZ ddlmZmZ dd	lmZ dd
lmZmZmZ ddlmZmZmZmZ ddl m!Z!m"Z"m#Z#m$Z$m%Z%m&Z&m'Z'm(Z(m)Z)m*Z*m+Z+m,Z,m-Z-m.Z.m/Z/m0Z0m1Z1m2Z2m3Z3m4Z4m5Z5m6Z6m7Z7m8Z8m9Z9m:Z:m;Z;m<Z< ddl=m>Z> ddl?m@Z@mAZAmBZBmCZC G dd„ de*ƒZDG dd„ de*ƒZEG dd„ de*ƒZFG dd„ de0ƒZGG dd„ de3ƒZHG dd„ de4ƒZIG dd„ de"ƒZJG dd„ de3ƒZKG dd „ d e7ƒZLed!d"„ ƒZMG d#d$„ d$e%ƒZNG d%d&„ d&e.ƒZOG d'd(„ d(e3ƒZPG d)d*„ d*e6ƒZQG d+d,„ d,e4ƒZRG d-d.„ d.e%ƒZSG d/d0„ d0e3ƒZTG d1d2„ d2e%ƒZUG d3d4„ d4e%ƒZVG d5d6„ d6e%ƒZWG d7d8„ d8e5ƒZXG d9d:„ d:e5ƒZYG d;d<„ d<e4ƒZZG d=d>„ d>e4ƒZ[G d?d@„ d@e3ƒZ\G dAdB„ dBe3ƒZ]G dCdD„ dDe4ƒZ^G dEdF„ dFe3ƒZ_G dGdH„ dHe4ƒZ`G dIdJ„ dJe%ƒZaG dKdL„ dLe%ƒZbG dMdN„ dNe5ƒZcG dOdP„ dPe4ƒZdG dQdR„ dRe5ƒZeG dSdT„ dTe3ƒZfG dUdV„ dVe6ƒZgG dWdX„ dXe3ƒZhG dYdZ„ dZe%ƒZiG d[d\„ d\e+ƒZjG d]d^„ d^e+ƒZkG d_d`„ d`e3ƒZlG dadb„ dbe4ƒZmG dcdd„ dde3ƒZnG dedf„ dfe3ƒZoG dgdh„ dhe%ƒZpG didj„ dje4ƒZqG dkdl„ dle%ƒZrG dmdn„ dne3ƒZsG dodp„ dpe3ƒZtG dqdr„ dre3ƒZuG dsdt„ dte%ƒZvG dudv„ dve"ƒZwG dwdx„ dxe3ƒZxG dydz„ dze4ƒZyG d{d|„ d|e3ƒZzG d}d~„ d~e3ƒZ{G dd€„ d€e4ƒZ|G d�d‚„ d‚e%ƒZ}G dƒd„„ d„e4ƒZ~G d…d†„ d†e3ƒZG d‡dˆ„ dˆe3ƒZ€G d‰dŠ„ dŠe.ƒZ�G d‹dŒ„ dŒe3ƒZ‚G d�dŽ„ dŽe4ƒZƒG d�d�„ d�e.ƒZ„G d‘d’„ d’e3ƒZ…G d“d”„ d”e4ƒZ†G d•d–„ d–e3ƒZ‡G d—d˜„ d˜e4ƒZˆG d™dš„ dše3ƒZ‰G d›dœ„ dœe.ƒZŠG d�dž„ dže4ƒZ‹G dŸd „ d e.ƒZŒG d¡d¢„ d¢e3ƒZ�G d£d¤„ d¤e4ƒZŽG d¥d¦„ d¦e4ƒZ�G d§d¨„ d¨e4ƒZ�G d©dª„ dªe3ƒZ‘G d«d¬„ d¬e"ƒZ’G d­d®„ d®e+ƒZ“G d¯d°„ d°e3ƒZ”G d±d²„ d²e6ƒZ•G d³d´„ d´e3ƒZ–G dµd¶„ d¶e3ƒZ—G d·d¸„ d¸e6ƒZ˜G d¹dº„ dºe'ƒZ™G d»d¼„ d¼e'ƒZšG d½d¾„ d¾e'ƒZ›G d¿dÀ„ dÀe'ƒZœG dÁdÂ„ dÂe'ƒZ�G dÃdÄ„ dÄe'ƒZžG dÅdÆ„ dÆe3ƒZŸG dÇdÈ„ dÈe3ƒZ G dÉdÊ„ dÊe'ƒZ¡G dËdÌ„ dÌe3ƒZ¢G dÍdÎ„ dÎe3ƒZ£G dÏdÐ„ dÐe6ƒZ¤G dÑdÒ„ dÒe.ƒZ¥G dÓdÔ„ dÔe6ƒZ¦G dÕdÖ„ dÖe6ƒZ§G d×dØ„ dØe6ƒZ¨G dÙdÚ„ dÚe3ƒZ©G dÛdÜ„ dÜe6ƒZªG dÝdÞ„ dÞe3ƒZ«G dßdà„ dàe4ƒZ¬G dádâ„ dâe.ƒZ­G dãdä„ däe3ƒZ®G dådæ„ dæe4ƒZ¯G dçdè„ dèe3ƒZ°G dédê„ dêe3ƒZ±G dëdì„ dìe4ƒZ²G dídî„ dîe4ƒZ³G dïdð„ dðe3ƒZ´G dñdò„ dòe&ƒZµdS )ózò
ASN.1 type classes for X.509 certificates. Exports the following items:

 - Attributes()
 - Certificate()
 - Extensions()
 - GeneralName()
 - GeneralNames()
 - Name()

Other type classes are defined that help compose the types listed above.
é    )Úunicode_literalsÚdivisionÚabsolute_importÚprint_function)Úcontextmanager)ÚidnaNé   )Úunwrap)Ú
iri_to_uriÚ
uri_to_iri)ÚOrderedDict)Ú	type_nameÚstr_clsÚbytes_to_list)ÚAlgorithmIdentifierÚAnyAlgorithmIdentifierÚDigestAlgorithmÚSignedDigestAlgorithm)ÚAnyÚ	BitStringÚ	BMPStringÚBooleanÚChoiceÚConcatÚ
EnumeratedÚGeneralizedTimeÚGeneralStringÚ	IA5StringÚIntegerÚNullÚNumericStringÚObjectIdentifierÚOctetBitStringÚOctetStringÚParsableOctetStringÚPrintableStringÚSequenceÚ
SequenceOfÚSetÚSetOfÚTeletexStringÚUniversalStringÚUTCTimeÚ
UTF8StringÚVisibleStringÚVOID)ÚPublicKeyInfo)Úint_to_bytesÚint_from_bytesÚ	inet_ntopÚ	inet_ptonc                   @   s,   e Zd ZdZdZdd„ Zdd„ Zdd„ Zd	S )
ÚDNSNamer   ©é   é   c                 C   ó
   | |k S ©N© ©ÚselfÚotherr;   r;   ú‚/root/aizidognhua/tmp/workspace/projects/ec89d86c-575f-41c9-af57-ac45cbdbf775/venv/lib/python3.10/site-packages/asn1crypto/x509.pyÚ__ne__L   ó   
zDNSName.__ne__c                 C   s&   t |tƒsdS |  ¡  ¡ | ¡  ¡ kS )zº
        Equality as defined by https://tools.ietf.org/html/rfc5280#section-7.2

        :param other:
            Another DNSName object

        :return:
            A boolean
        F)Ú
isinstancer5   Ú__unicode__Úlowerr<   r;   r;   r?   Ú__eq__O   ó   
zDNSName.__eq__c                 C   s|   t |tƒsttdt| ƒt|ƒƒƒ‚| d¡r#d|dd…  | j¡ }n| | j¡}|| _|| _	d| _
| jdkr<d| _dS dS )zd
        Sets the value of the DNS name

        :param value:
            A unicode string
        úK
                %s value must be a unicode string, not %s
                Ú.ó   .r   Nó    )rB   r   Ú	TypeErrorr	   r   Ú
startswithÚencodeÚ	_encodingÚ_unicodeÚcontentsÚ_headerÚ_trailer)r=   ÚvalueÚencoded_valuer;   r;   r?   Úset_   s   
û


ÿzDNSName.setN)Ú__name__Ú
__module__Ú__qualname__rN   Ú_bad_tagr@   rE   rU   r;   r;   r;   r?   r5   G   s    r5   c                   @   s,   e Zd Zdd„ Zdd„ Zdd„ Zdd„ Zd	S )
ÚURIc                 C   sP   t |tƒsttdt| ƒt|ƒƒƒ‚|| _t|ƒ| _d| _| j	dkr&d| _	dS dS )úb
        Sets the value of the string

        :param value:
            A unicode string
        rG   NrJ   )
rB   r   rK   r	   r   rO   r
   rP   rQ   rR   ©r=   rS   r;   r;   r?   rU   ~   s   
û


ÿzURI.setc                 C   r9   r:   r;   r<   r;   r;   r?   r@   •   rA   z
URI.__ne__c                 C   s&   t |tƒsdS t| jdƒt|jdƒkS )z¶
        Equality as defined by https://tools.ietf.org/html/rfc5280#section-7.4

        :param other:
            Another URI object

        :return:
            A boolean
        FT)rB   rZ   r
   Únativer<   r;   r;   r?   rE   ˜   rF   z
URI.__eq__c                 C   s,   | j du rdS | jdu rt|  ¡ ƒ| _| jS ©ú7
        :return:
            A unicode string
        NÚ )rP   rO   r   Ú_merge_chunks©r=   r;   r;   r?   rC   ¨   s
   

zURI.__unicode__N)rV   rW   rX   rU   r@   rE   rC   r;   r;   r;   r?   rZ   |   s
    rZ   c                   @   sR   e Zd ZdZdZdZedd„ ƒZejdd„ ƒZdd„ Z	d	d
„ Z
dd„ Zdd„ ZdS )ÚEmailAddressNFr6   c                 C   s   | j S )z`
        :return:
            A byte string of the DER-encoded contents of the sequence
        )Ú	_contentsrb   r;   r;   r?   rP   ¿   s   zEmailAddress.contentsc                 C   s   d| _ || _dS )ze
        :param value:
            A byte string of the DER-encoded contents of the sequence
        FN)Ú_normalizedrd   r\   r;   r;   r?   rP   È   s   
c                 C   s”   t |tƒsttdt| ƒt|ƒƒƒ‚| d¡dkr-| dd¡\}}| d¡d | d¡ }n| d¡}d| _|| _	|| _
d	| _| jd
krHd
| _d	S d	S )r[   rG   ú@éÿÿÿÿr   Úasciió   @r   TNrJ   )rB   r   rK   r	   r   ÚfindÚrsplitrM   re   rO   rP   rQ   rR   )r=   rS   ÚmailboxÚhostnamerT   r;   r;   r?   rU   Ò   s"   
û


ÿzEmailAddress.setc                 C   sb   | j du r.|  ¡ }| d¡dkr| d¡| _ | j S | dd¡\}}| d¡d | d¡ | _ | j S )r_   Nri   rg   Úcp1252r   rf   r   )rO   ra   rj   Údecoderk   )r=   rP   rl   rm   r;   r;   r?   rC   ð   s   
þzEmailAddress.__unicode__c                 C   r9   r:   r;   r<   r;   r;   r?   r@     rA   zEmailAddress.__ne__c                 C   s¦   t |tƒsdS | js|  | j¡ |js| |j¡ | j d¡dks)|j d¡dkr/| j|jkS |j dd¡\}}| j dd¡\}}||krGdS | ¡ | ¡ krQdS dS )z¿
        Equality as defined by https://tools.ietf.org/html/rfc5280#section-7.5

        :param other:
            Another EmailAddress object

        :return:
            A boolean
        Fri   rg   r   T)	rB   rc   re   rU   r]   rd   rj   rk   rD   )r=   r>   Úother_mailboxÚother_hostnamerl   rm   r;   r;   r?   rE     s   
 zEmailAddress.__eq__)rV   rW   rX   rd   re   rY   ÚpropertyrP   ÚsetterrU   rC   r@   rE   r;   r;   r;   r?   rc   µ   s    

	rc   c                   @   s:   e Zd Zddd„Zdd„ Zedd„ ƒZdd	„ Zd
d„ ZdS )Ú	IPAddressNc                 C   s   t tdƒƒ‚)z?
        This method is not applicable to IP addresses
        z=
            IP address values can not be parsed
            )Ú
ValueErrorr	   )r=   ÚspecÚspec_paramsr;   r;   r?   Úparse'  s   ÿzIPAddress.parsec           
      C   sT  t |tƒsttdt| ƒt|ƒƒƒ‚|}| d¡dk}d}|r;| dd¡}|d }t|d ƒ}|dk r;ttdt| ƒƒƒ‚| d¡dkrUt	j
}|dkrRttd	t| ƒƒƒ‚d}nt	j}|d
krettdt| ƒƒƒ‚d
}d}|rŒd| }	|	d|t|	ƒ  7 }	tt|	dƒƒ}d|d t|ƒ  | }|| _t||ƒ| | _| j| _d| _| jdkr¨d| _dS dS )zÌ
        Sets the value of the object

        :param value:
            A unicode string containing an IPv4 address, IPv4 address with CIDR,
            an IPv6 address or IPv6 address with CIDR
        rG   ú/rg   r   r   zT
                    %s value contains a CIDR range less than 0
                    ú:é€   z“
                    %s value contains a CIDR range bigger than 128, the maximum
                    value for an IPv6 address
                    é    z’
                    %s value contains a CIDR range bigger than 32, the maximum
                    value for an IPv4 address
                    rJ   Ú1Ú0é   ó    é   N)rB   r   rK   r	   r   rj   ÚsplitÚintru   ÚsocketÚAF_INET6ÚAF_INETÚlenr1   Ú_nativer4   rP   Ú_bytesrQ   rR   )
r=   rS   Úoriginal_valueÚhas_cidrÚcidrÚpartsÚfamilyÚ	cidr_sizeÚ
cidr_bytesÚ	cidr_maskr;   r;   r?   rU   2  s\   
	ûüûû

ÿzIPAddress.setc                 C   sæ   | j du rdS | jdu rp|  ¡ }t|ƒ}d}d}|tddgƒv r7ttj|dd… ƒ}|dkr6t|dd… ƒ}n|tddgƒv rUttj	|dd… ƒ}|dkrUt|dd… ƒ}|durmd 
|¡}t| d¡ƒ}|d	 t|ƒ }|| _| jS )
z€
        The native Python datatype representation of this value

        :return:
            A unicode string or None
        Nr|   é   r   r�   é   z{0:b}r~   ry   )rP   rˆ   Ú	__bytes__r‡   rU   r3   r„   r…   r2   r†   ÚformatÚrstripr   )r=   Úbyte_stringÚbyte_lenrS   Úcidr_intÚ	cidr_bitsrŒ   r;   r;   r?   r]   y  s,   
	
€
zIPAddress.nativec                 C   r9   r:   r;   r<   r;   r;   r?   r@   ™  rA   zIPAddress.__ne__c                 C   s   t |tƒsdS |  ¡ | ¡ kS )zl
        :param other:
            Another IPAddress object

        :return:
            A boolean
        F)rB   rt   r”   r<   r;   r;   r?   rE   œ  s   
	zIPAddress.__eq__)NN)	rV   rW   rX   rx   rU   rr   r]   r@   rE   r;   r;   r;   r?   rt   &  s    
G
rt   c                   @   s"   e Zd ZdefdedeifgZdS )Ú	AttributeÚtypeÚvaluesrv   N)rV   rW   rX   r!   r)   r   Ú_fieldsr;   r;   r;   r?   r›   «  ó    þr›   c                   @   ó   e Zd ZeZdS )Ú
AttributesN)rV   rW   rX   r›   Ú_child_specr;   r;   r;   r?   r¡   ²  ó    r¡   c                
   @   ó$   e Zd Zddddddddd	d
œ	ZdS )ÚKeyUsageÚdigital_signatureÚnon_repudiationÚkey_enciphermentÚdata_enciphermentÚkey_agreementÚkey_cert_signÚcrl_signÚencipher_onlyÚdecipher_only©	r   r   r   é   r“   é   é   é   r�   N©rV   rW   rX   Ú_mapr;   r;   r;   r?   r¥   ¶  ó    
÷r¥   c                   @   ó,   e Zd ZdedddœfdedddœfgZdS )ÚPrivateKeyUsagePeriodÚ
not_beforer   T©ÚimplicitÚoptionalÚ	not_afterr   N)rV   rW   rX   r   rž   r;   r;   r;   r?   r¸   Ä  ó    þr¸   c                   @   s   e Zd ZdZdZdd„ ZdS )ÚNotReallyTeletexStringa6  
    OpenSSL (and probably some other libraries) puts ISO-8859-1
    into TeletexString instead of ITU T.61. We use Windows-1252 when
    decoding since it is a superset of ISO-8859-1, and less likely to
    cause encoding issues, but we stay strict with encoding to prevent
    us from creating bad data.
    rn   c                 C   s0   | j du rdS | jdu r|  ¡  | j¡| _| jS r^   )rP   rO   ra   ro   Ú_decoding_encodingrb   r;   r;   r?   rC   Ö  s
   

z"NotReallyTeletexString.__unicode__N)rV   rW   rX   Ú__doc__rÀ   rC   r;   r;   r;   r?   r¿   Ë  s    r¿   c                   c   s$   � zdt _d V  W dt _d S dt _w )NÚteletexrn   )r¿   rÀ   r;   r;   r;   r?   Ústrict_teletexã  s
   €rÃ   c                   @   s4   e Zd ZdefdefdefdefdefdefgZ	dS )ÚDirectoryStringÚteletex_stringÚprintable_stringÚuniversal_stringÚutf8_stringÚ
bmp_stringÚ
ia5_stringN)
rV   rW   rX   r¿   r%   r+   r-   r   r   Ú_alternativesr;   r;   r;   r?   rÄ   ì  s    ùrÄ   c                   @   s   e Zd Zi dd“dd“dd“dd“d	d
“dd“dd“dd“dd“dd“dd“dd“dd“dd“dd“dd “d!d"“i d#d$“d%d&“d'd(“d)d*“d+d,“d-d.“d/d0“d1d2“d3d4“d5d6“d7d8“d9d:“d;d<“d=d>“d?d@“dAdB“dCdD“¥Zg dE¢ZedFdG„ ƒZedHdI„ ƒZdJS )KÚNameTypez2.5.4.3Úcommon_namez2.5.4.4Úsurnamez2.5.4.5Úserial_numberz2.5.4.6Úcountry_namez2.5.4.7Úlocality_namez2.5.4.8Ústate_or_province_namez2.5.4.9Ústreet_addressz2.5.4.10Úorganization_namez2.5.4.11Úorganizational_unit_namez2.5.4.12Útitlez2.5.4.15Úbusiness_categoryz2.5.4.17Úpostal_codez2.5.4.20Útelephone_numberz2.5.4.41Únamez2.5.4.42Ú
given_namez2.5.4.43Úinitialsz2.5.4.44Úgeneration_qualifierz2.5.4.45Úunique_identifierz2.5.4.46Údn_qualifierz2.5.4.65Ú	pseudonymz2.5.4.97Úorganization_identifierz2.23.133.2.1Útpm_manufacturerz2.23.133.2.2Ú	tpm_modelz2.23.133.2.3Útpm_versionz2.23.133.2.4Úplatform_manufacturerz2.23.133.2.5Úplatform_modelz2.23.133.2.6Úplatform_versionz1.2.840.113549.1.9.1Úemail_addressz1.3.6.1.4.1.311.60.2.1.1Úincorporation_localityz1.3.6.1.4.1.311.60.2.1.2Úincorporation_state_or_provincez1.3.6.1.4.1.311.60.2.1.3Úincorporation_countryz0.9.2342.19200300.100.1.1Úuser_idz0.9.2342.19200300.100.1.25Údomain_componentz0.2.262.1.10.7.20Úname_distinguisher)!rë   rê   ré   r×   rÏ   rÐ   rØ   rÒ   rÑ   rÓ   rÔ   rÕ   rÖ   rÍ   rì   rÜ   rÝ   rÎ   rÛ   rÚ   rà   rß   rÙ   rè   rí   rî   rá   râ   rã   rä   rå   ræ   rç   c                 C   s:   |   |¡}|| jv r| j |¡}||fS t| jƒ}||fS )zÍ
        Returns an ordering value for a particular attribute key.

        Unrecognized attributes and OIDs will be sorted lexically at the end.

        :return:
            An orderable value.

        )ÚmapÚpreferred_orderÚindexr‡   )ÚclsÚ	attr_nameÚordinalr;   r;   r?   Úpreferred_ordinalK  s   


þzNameType.preferred_ordinalc                 C   sà   i dd“dd“dd“dd“d	d
“dd“dd“dd“dd“dd“dd“dd“dd“dd“dd“dd “d!d"“i d#d$“d%d&“d'd(“d)d*“d+d,“d-d.“d/d0“d1d2“d3d4“d5d6“d7d8“d9d:“d;d<“d=d>“d?d@“dAdB“dCdD“¥  | j| j¡S )EzZ
        :return:
            A human-friendly unicode string to display to users
        rÍ   zCommon NamerÎ   ÚSurnamerÏ   zSerial NumberrÐ   ÚCountryrÑ   ÚLocalityrÒ   zState/ProvincerÓ   zStreet AddressrÔ   ÚOrganizationrÕ   zOrganizational UnitrÖ   ÚTitler×   zBusiness CategoryrØ   zPostal CoderÙ   zTelephone NumberrÚ   ÚNamerÛ   z
Given NamerÜ   ÚInitialsrÝ   zGeneration QualifierrÞ   zUnique Identifierrß   zDN Qualifierrà   Ú	Pseudonymrè   zEmail Addressré   zIncorporation Localityrê   zIncorporation State/Provincerë   zIncorporation Countryrí   zDomain Componentrî   zName Distinguisherrá   zOrganization Identifierrâ   zTPM Manufacturerrã   z	TPM Modelrä   zTPM Versionrå   zPlatform Manufacturerræ   zPlatform Modelrç   zPlatform Versionrì   zUser ID)Úgetr]   rb   r;   r;   r?   Úhuman_friendly_  sŽ   ÿþýüûúùø	÷
öõôóòñðïîíìëêéèçæåäãâá à!ß"Þ#ÝzNameType.human_friendlyN)	rV   rW   rX   rµ   rð   Úclassmethodrõ   rr   rÿ   r;   r;   r;   r?   rÌ   ø  s–    ÿþýüûúùø	÷
öõôóòñðïîíìëéèçæåäâ à!ß"Þ$Ü&Ú(Ø.$
rÌ   c                   @   s  e Zd ZdefdefgZdZi de“de“de“de“de“d	e“d
e“de“de“de“de“de“de“de“de“de“de“i de	“de“de“de
“de“de“de“de“de“de“de“d e“d!e“d"e“d#e“d$e“d%e“¥Zd&Zed'd(„ ƒZd)d*„ Zd+d,„ Zd-d.„ Zd&S )/ÚNameTypeAndValuerœ   rS   ©rœ   rS   rÍ   rÎ   rÏ   rÐ   rÑ   rÒ   rÓ   rÔ   rÕ   rÖ   r×   rØ   rÙ   rÚ   rÛ   rÜ   rÝ   rÞ   rß   rà   rè   ré   rê   rë   rí   rî   rá   râ   rã   rä   rå   ræ   rç   rì   Nc                 C   s"   | j du r|  | d j¡| _ | j S )zµ
        Returns the value after being processed by the internationalized string
        preparation as specified by RFC 5280

        :return:
            A unicode string
        NrS   )Ú_preppedÚ_ldap_string_prepr]   rb   r;   r;   r?   Úprepped_value¼  s   

zNameTypeAndValue.prepped_valuec                 C   r9   r:   r;   r<   r;   r;   r?   r@   Ê  rA   zNameTypeAndValue.__ne__c                 C   s2   t |tƒsdS |d j| d jkrdS |j| jkS )zÃ
        Equality as defined by https://tools.ietf.org/html/rfc5280#section-7.1

        :param other:
            Another NameTypeAndValue object

        :return:
            A boolean
        Frœ   )rB   r  r]   r  r<   r;   r;   r?   rE   Í  s
   
zNameTypeAndValue.__eq__c                 C   sœ  t  dd|¡}t  dd|¡}tjdkrt  dd|¡}nt  dd|¡}t  dd|¡}| d	d¡}t  d
d|¡}d ttj|ƒ¡}t	 
d|¡}|D ]C}t |¡rTttdƒƒ‚t |¡r_ttdƒƒ‚t |¡rjttdƒƒ‚t |¡ruttdƒƒ‚t |¡r€ttdƒƒ‚|dkrŠttdƒƒ‚qGd}d}|D ]}t |¡r›d}q‘t |¡r¢d}q‘|r¿t |d ¡}t |d ¡}|s¹|r¹|s¿ttdƒƒ‚dt  dd|¡ ¡  d }|S )a"  
        Implements the internationalized string preparation algorithm from
        RFC 4518. https://tools.ietf.org/html/rfc4518#section-2

        :param string:
            A unicode string to prepare

        :return:
            A prepared unicode string, ready for comparison
        u   [Â­á †Í�á ‹-á �ï¸�-ï¼€ï¿¼]+r`   u	   [	
Â…]ú iÿÿ  u   í ´[íµ³-íµº]|í­€[í° -í±¿]|ó €�u   [ð�…³-ð�…ºó € -ó �¿ó €�]u?   [ ---Â„Â†-ÂŸÛ�Ü�á Žâ€Œ-â€�â€ª-â€®â� -â�£â�ª-â�¯ï»¿ï¿¹-ï¿»]+u   â€‹u   [Â áš€â€€-â€Šâ€¨-â€©â€¯â�Ÿã€€]ÚNFKCzc
                    X.509 Name objects may not contain unassigned code points
                    zŒ
                    X.509 Name objects may not contain change display or
                    zzzzdeprecated characters
                    zc
                    X.509 Name objects may not contain private use characters
                    zf
                    X.509 Name objects may not contain non-character code points
                    zb
                    X.509 Name objects may not contain surrogate code points
                    u   ï¿½zf
                    X.509 Name objects may not contain the replacement character
                    FTr   rg   z{
                    X.509 Name object contains a malformed bidirectional
                    sequence
                    z +z  )ÚreÚsubÚsysÚ
maxunicodeÚreplaceÚjoinrï   Ú
stringprepÚmap_table_b2ÚunicodedataÚ	normalizeÚin_table_a1ru   r	   Úin_table_c8Úin_table_c3Úin_table_c4Úin_table_c5Úin_table_d1Úin_table_d2Ústrip)r=   ÚstringÚcharÚhas_r_and_al_catÚ	has_l_catÚfirst_is_r_and_alÚlast_is_r_and_alr;   r;   r?   r  à  sr   
ü
ÿ
ÿ
ÿ
ÿ
ÿÿÿ	

€ÿz"NameTypeAndValue._ldap_string_prep)rV   rW   rX   rÌ   r   rž   Ú	_oid_pairrÄ   r%   r"   rc   r5   r-   Ú
_oid_specsr  rr   r  r@   rE   r  r;   r;   r;   r?   r  Œ  s     þÿþýüûúùø	÷
öõôóòñðïîíìêèçæåäãâá à!ß"Þ#Ý$Ü'
r  c                   @   s<   e Zd ZeZedd„ ƒZdd„ Zdd„ Zdd„ Z	d	d
„ Z
dS )ÚRelativeDistinguishedNamec                 C   s@   g }|   | ¡}t| ¡ ƒD ]}| d||| f ¡ qd |¡S )úb
        :return:
            A unicode string that can be used as a dict key or in a set
        ú%s: %sú)Ú_get_valuesÚsortedÚkeysÚappendr  )r=   Úoutputr�   Úkeyr;   r;   r?   ÚhashableP  s
   

z"RelativeDistinguishedName.hashablec                 C   r9   r:   r;   r<   r;   r;   r?   r@   `  rA   z RelativeDistinguishedName.__ne__c                 C   sz   t |tƒsdS t| ƒt|ƒkrdS |  | ¡}|  |¡}||kr!dS |  | ¡}|  |¡}|D ]}|| || kr: dS q-dS )zÌ
        Equality as defined by https://tools.ietf.org/html/rfc5280#section-7.1

        :param other:
            Another RelativeDistinguishedName object

        :return:
            A boolean
        FT)rB   r"  r‡   Ú
_get_typesr&  )r=   r>   Ú
self_typesÚother_typesÚself_valuesÚother_valuesÚ
type_name_r;   r;   r?   rE   c  s   




ÿz RelativeDistinguishedName.__eq__c                 C   s   t dd„ |D ƒƒS )zò
        Returns a set of types contained in an RDN

        :param rdn:
            A RelativeDistinguishedName object

        :return:
            A set object with unicode strings of NameTypeAndValue type field
            values
        c                 S   s   g | ]}|d  j ‘qS ©rœ   ©r]   ©Ú.0Úntvr;   r;   r?   Ú
<listcomp>�  ó    z8RelativeDistinguishedName._get_types.<locals>.<listcomp>)rU   ©r=   Úrdnr;   r;   r?   r-  ƒ  s   z$RelativeDistinguishedName._get_typesc                    s   i ‰ ‡ fdd„|D ƒ ˆ S )a$  
        Returns a dict of prepped values contained in an RDN

        :param rdn:
            A RelativeDistinguishedName object

        :return:
            A dict object with unicode strings of NameTypeAndValue value field
            values that have been prepped for comparison
        c                    s$   g | ]}ˆ   |d  j|jfg¡‘qS r3  )Úupdater]   r  r5  ©r*  r;   r?   r8  ž  s   $ z9RelativeDistinguishedName._get_values.<locals>.<listcomp>r;   r:  r;   r=  r?   r&  ‘  s   z%RelativeDistinguishedName._get_valuesN)rV   rW   rX   r  r¢   rr   r,  r@   rE   r-  r&  r;   r;   r;   r?   r"  M  s    
 r"  c                   @   s,   e Zd ZeZedd„ ƒZdd„ Zdd„ ZdS )ÚRDNSequencec                 C   s   d  dd„ | D ƒ¡S )r#  úc                 s   s   � | ]}|j V  qd S r:   )r,  )r6  r;  r;   r;   r?   Ú	<genexpr>¯  s   € z'RDNSequence.hashable.<locals>.<genexpr>)r  rb   r;   r;   r?   r,  ¥  s   
zRDNSequence.hashablec                 C   r9   r:   r;   r<   r;   r;   r?   r@   ±  rA   zRDNSequence.__ne__c                 C   sJ   t |tƒsdS t| ƒt|ƒkrdS t| ƒD ]\}}|| |kr" dS qdS )z¾
        Equality as defined by https://tools.ietf.org/html/rfc5280#section-7.1

        :param other:
            Another RDNSequence object

        :return:
            A boolean
        FT)rB   r>  r‡   Ú	enumerate)r=   r>   rñ   Úself_rdnr;   r;   r?   rE   ´  s   
ÿzRDNSequence.__eq__N)	rV   rW   rX   r"  r¢   rr   r,  r@   rE   r;   r;   r;   r?   r>  ¢  s    
r>  c                   @   sŒ   e Zd ZdefgZdZdZdZeddd„ƒZ	e
dd„ ƒZdd	„ Zd
d„ Zdd„ Ze
dd„ ƒZe
dd„ ƒZdd„ Ze
dd„ ƒZe
dd„ ƒZdS )rû   r`   NFc           	      C   sÎ   g }|s	d}t }nd}t}tt| ¡ dd„ d�ƒ}| ¡ D ]A\}}t |¡}|dkr/t|ƒ}n"|dkr8t|ƒ}n|t	g d¢ƒv rIt
dt|ƒd	�}nt
|||ƒd	�}| tt||d
œƒgƒ¡ q| dt|ƒd	�S )aY  
        Creates a Name object from a dict of unicode string keys and values.
        The keys should be from NameType._map, or a dotted-integer OID unicode
        string.

        :param name_dict:
            A dict of name information, e.g. {"common_name": "Will Bond",
            "country_name": "US", "organization_name": "Codex Non Sufficit LC"}

        :param use_printable:
            A bool - if PrintableString should be used for encoding instead of
            UTF8String. This is for backwards compatibility with old software.

        :return:
            An x509.Name object
        rÈ   rÆ   c                 S   s   t  | d ¡S )Nr   )rÌ   rõ   )Úitemr;   r;   r?   Ú<lambda>ô  s    zName.build.<locals>.<lambda>)r+  rè   rí   )rß   rÐ   rÏ   )rÚ   rS   r  r`   )r-   r%   r   r'  ÚitemsrÌ   rï   rc   r5   rU   rÄ   r)  r"  r  r>  )	rò   Ú	name_dictÚuse_printableÚrdnsÚencoding_nameÚencoding_classÚattribute_nameÚattribute_valuerS   r;   r;   r?   ÚbuildÕ  sD   þÿ


þþþ
ÿz
Name.buildc                 C   s   | j jS )r#  )Úchosenr,  rb   r;   r;   r?   r,    s   zName.hashablec                 C   s
   t | jƒS r:   )r‡   rN  rb   r;   r;   r?   Ú__len__  rA   zName.__len__c                 C   r9   r:   r;   r<   r;   r;   r?   r@     rA   zName.__ne__c                 C   s   t |tƒsdS | j|jkS )z·
        Equality as defined by https://tools.ietf.org/html/rfc5280#section-7.1

        :param other:
            Another Name object

        :return:
            A boolean
        F)rB   rû   rN  r<   r;   r;   r?   rE   !  s   
zName.__eq__c                 C   s„   | j d u r?tƒ | _ | jjD ]1}|D ],}|d }|| j v r6| j | }t|tƒs.|g }| j |< | |d ¡ q|d | j |< qq| j S )Nrœ   rS   )rˆ   r   rN  r]   rB   Úlistr)  )r=   r;  Útype_valÚ
field_nameÚexistingr;   r;   r?   r]   0  s   



ø	zName.nativec                 C   s  | j du r�tƒ }d}| jD ])}|D ]$}|d j}|}||v r/|| g||< ||  |d ¡ q|d ||< qqg }| ¡ }|dkrGtt|ƒƒ}|D ]}|| }	|  |	¡}
| d||
f ¡ qId}|D ]}| 	d¡dkrod	} nqb|std
nd}| 
|ddd… ¡| _ | j S )zg
        :return:
            A human-friendly unicode string containing the parts of the name
        Nrœ   rS   r÷   r$  Fú,rg   Tú, z; )Ú_human_friendlyr   rN  rÿ   r)  r(  ÚreversedrP  Ú_recursive_humanizerj   r  )r=   ÚdataÚ
last_fieldr;  rQ  rR  Úto_joinr(  r+  rS   Únative_valueÚ	has_commaÚelementÚ	separatorr;   r;   r?   rÿ   @  s:   


ù
þzName.human_friendlyc                    s,   t |tƒrd t‡ fdd„|D ƒƒ¡S |jS )zÑ
        Recursively serializes data compiled from the RDNSequence

        :param value:
            An Asn1Value object, or a list of Asn1Value objects

        :return:
            A unicode string
        rU  c                    s   g | ]}ˆ   |¡‘qS r;   )rX  )r6  Ú	sub_valuerb   r;   r?   r8  t  r9  z,Name._recursive_humanize.<locals>.<listcomp>)rB   rP  r  rW  r]   r\   r;   rb   r?   rX  g  s
   
ÿzName._recursive_humanizec                 C   ó$   | j du rt |  ¡ ¡ ¡ | _ | j S )zZ
        :return:
            The SHA1 hash of the DER-encoded bytes of this name
        N©Ú_sha1ÚhashlibÚsha1ÚdumpÚdigestrb   r;   r;   r?   re  x  ó   
z	Name.sha1c                 C   ra  )z]
        :return:
            The SHA-256 hash of the DER-encoded bytes of this name
        N©Ú_sha256rd  Úsha256rf  rg  rb   r;   r;   r?   rk  ƒ  rh  zName.sha256)F)rV   rW   rX   r>  rË   rV  rc  rj  r   rM  rr   r,  rO  r@   rE   r]   rÿ   rX  re  rk  r;   r;   r;   r?   rû   Ì  s,    ÿ<


&

rû   c                   @   ó"   e Zd ZdefdeddifgZdS )ÚAnotherNameÚtype_idrS   Úexplicitr   N)rV   rW   rX   r!   r   rž   r;   r;   r;   r?   rm  �  rŸ   rm  c                   @   s$   e Zd ZdZdZdefdefgZdS )ÚCountryNamer   Úx121_dcc_codeÚiso_3166_alpha2_codeN©rV   rW   rX   Úclass_Útagr    r%   rË   r;   r;   r;   r?   rp  –  ó    þrp  c                   @   s$   e Zd ZdZdZdefdefgZdS )ÚAdministrationDomainNamer   r   ÚnumericÚ	printableNrs  r;   r;   r;   r?   rw     rv  rw  c                   @   ó   e Zd ZdefdefgZdS )ÚPrivateDomainNamerx  ry  N©rV   rW   rX   r    r%   rË   r;   r;   r;   r?   r{  ª  ó    þr{  c                   @   óF   e Zd Zdeddifdedddœfded	ddœfd
edddœfgZdS )ÚPersonalNamerÎ   r»   r   rÛ   r   Trº   rÜ   r   rÝ   r°   N©rV   rW   rX   r%   rž   r;   r;   r;   r?   r  ±  ó    ür  c                   @   r~  )ÚTeletexPersonalNamerÎ   r»   r   rÛ   r   Trº   rÜ   r   rÝ   r°   N©rV   rW   rX   r*   rž   r;   r;   r;   r?   r‚  º  r�  r‚  c                   @   r    )ÚOrganizationalUnitNamesN©rV   rW   rX   r%   r¢   r;   r;   r;   r?   r„  Ã  r£   r„  c                   @   r    )ÚTeletexOrganizationalUnitNamesN)rV   rW   rX   r*   r¢   r;   r;   r;   r?   r†  Ç  r£   r†  c                   @   sŠ   e Zd Zdeddifdeddifdedddœfded	ddœfd
edddœfdedddœfdedddœfdedddœfde	dddœfg	Z
dS )ÚBuiltInStandardAttributesrÐ   r¼   TÚadministration_domain_nameÚnetwork_addressr   rº   Úterminal_identifierr   Úprivate_domain_namer   ©ro  r¼   rÔ   r°   Únumeric_user_identifierr“   Úpersonal_namer±   Úorganizational_unit_namesr²   N)rV   rW   rX   rp  rw  r    r%   r{  r  r„  rž   r;   r;   r;   r?   r‡  Ë  s    ÷r‡  c                   @   ó   e Zd ZdefdefgZdS )ÚBuiltInDomainDefinedAttributerœ   rS   Nr€  r;   r;   r;   r?   r‘  Ù  r}  r‘  c                   @   r    )ÚBuiltInDomainDefinedAttributesN)rV   rW   rX   r‘  r¢   r;   r;   r;   r?   r’  à  r£   r’  c                   @   r�  )ÚTeletexDomainDefinedAttributerœ   rS   Nrƒ  r;   r;   r;   r?   r“  ä  r}  r“  c                   @   r    )ÚTeletexDomainDefinedAttributesN)rV   rW   rX   r“  r¢   r;   r;   r;   r?   r”  ë  r£   r”  c                   @   rz  )ÚPhysicalDeliveryCountryNamerq  rr  Nr|  r;   r;   r;   r?   r•  ï  r}  r•  c                   @   rz  )Ú
PostalCodeÚnumeric_codeÚprintable_codeNr|  r;   r;   r;   r?   r–  ö  r}  r–  c                   @   ó(   e Zd ZdeddifdeddifgZdS )ÚPDSParameterrÆ   r¼   TrÅ   N)rV   rW   rX   r%   r*   rž   r;   r;   r;   r?   rš  ý  ó    þrš  c                   @   r    )ÚPrintableAddressNr…  r;   r;   r;   r?   rœ    r£   rœ  c                   @   r™  )ÚUnformattedPostalAddressÚprintable_addressr¼   TrÅ   N)rV   rW   rX   rœ  r*   rž   r;   r;   r;   r?   r�    r›  r�  c                   @   s*   e Zd ZdeddifdedddœfgZdS )	ÚE1634AddressÚnumberr»   r   Úsub_addressr   Trº   N)rV   rW   rX   r    rž   r;   r;   r;   r?   rŸ    s    þrŸ  c                   @   r    )Ú
NAddressesN)rV   rW   rX   r#   r¢   r;   r;   r;   r?   r¢    r£   r¢  c                   @   sF   e Zd Zdedddœfdedddœfdedddœfd	ed
difgZdS )ÚPresentationAddressÚ
p_selectorr   TrŒ  Ú
s_selectorr   Ú
t_selectorr   Ún_addressesro  r°   N)rV   rW   rX   r#   r¢  rž   r;   r;   r;   r?   r£    s    ür£  c                   @   rl  )ÚExtendedNetworkAddressÚe163_4_addressÚpsap_addressr»   r   N)rV   rW   rX   rŸ  r£  rË   r;   r;   r;   r?   r¨  #  rŸ   r¨  c                   @   s   e Zd ZdddddddœZdS )	ÚTerminalTypeÚtelexrÂ   Úg3_facsimileÚg4_facsimileÚia5_terminalÚvideotex)r°   r“   r±   r²   r³   r�   Nr´   r;   r;   r;   r?   r«  *  s    
úr«  c                   @   sˆ   e Zd Zi dd“dd“dd“dd“d	d
“dd“dd“dd“dd“dd“dd“dd“dd“dd“dd“dd “d!d"“d#d$d%d&d'd(d)œ¥Zd*S )+ÚExtensionAttributeTyper   rÍ   r   Úteletex_common_namer°   Úteletex_organization_namer“   Úteletex_personal_namer±   Úteletex_organization_unit_namesr²   Ú!teletex_domain_defined_attributesr³   Úpds_namer�   Úphysical_delivery_country_nameé	   rØ   é
   Úphysical_delivery_office_nameé   Úphysical_delivery_office_numberr7   Úextension_of_address_componentsé   Úphysical_delivery_personal_nameé   Ú#physical_delivery_organization_nameé   Ú.extension_physical_delivery_address_componentsr’   Úunformatted_postal_addressé   rÓ   Úpost_office_box_addressÚposte_restante_addressÚunique_postal_nameÚlocal_postal_attributesÚextended_network_addressÚterminal_type)é   r8   é   é   é   é   Nr´   r;   r;   r;   r?   r±  5  sV    ÿþýüûúùø	÷
öõôóòñðïér±  c                   @   s¨   e Zd ZdeddifdeddifgZdZi de“d	e“d
e“de	“de
“de“de“de“de“de“de“de“de“de“de“de“de“eeeeeedœ¥ZdS )ÚExtensionAttributeÚextension_attribute_typer»   r   Úextension_attribute_valuero  r   )rÓ  rÔ  rÍ   r²  r³  r´  rµ  r¶  r·  r¸  rØ   r»  r½  r¾  rÀ  rÂ  rÄ  rÅ  rÓ   )rÇ  rÈ  rÉ  rÊ  rË  rÌ  N)rV   rW   rX   r±  r   rž   r   r%   r*   r‚  r†  r”  r•  r–  rš  r�  r¨  r«  r!  r;   r;   r;   r?   rÒ  Q  s^    þÿþýüûúùø	÷
öõôóòñðïérÒ  c                   @   r    )ÚExtensionAttributesN)rV   rW   rX   rÒ  r¢   r;   r;   r;   r?   rÕ  s  r£   rÕ  c                   @   ó.   e Zd ZdefdeddifdeddifgZdS )Ú	ORAddressÚbuilt_in_standard_attributesÚ"built_in_domain_defined_attributesr¼   TÚextension_attributesN)rV   rW   rX   r‡  r’  rÕ  rž   r;   r;   r;   r?   r×  w  ó
    ýr×  c                   @   s*   e Zd ZdedddœfdeddifgZdS )	ÚEDIPartyNameÚname_assignerr   Trº   Ú
party_namer»   r   N)rV   rW   rX   rÄ   rž   r;   r;   r;   r?   rÜ    s    þrÜ  c                   @   sŒ   e Zd Zdeddifdeddifdeddifdedd	ifd
eddifdeddifde	ddifde
ddifdeddifg	Zdd„ Zdd„ ZdS )ÚGeneralNameÚ
other_namer»   r   Úrfc822_namer   Údns_namer   Úx400_addressr°   Údirectory_namero  r“   Úedi_party_namer±   Úuniform_resource_identifierr²   Ú
ip_addressr³   Úregistered_idr�   c                 C   r9   r:   r;   r<   r;   r;   r?   r@   “  rA   zGeneralName.__ne__c                 C   sP   | j dv rttd| j ƒƒ‚|j dv rttd|j ƒƒ‚| j |j kr"dS | j|jkS )z¼
        Does not support other_name, x400_address or edi_party_name

        :param other:
            The other GeneralName to compare to

        :return:
            A boolean
        )rà  rã  rå  zr
                Comparison is not supported for GeneralName objects of
                choice %s
                za
                Comparison is not supported for GeneralName objects of choice
                %sF)rÚ   ru   r	   rN  r<   r;   r;   r?   rE   –  s   
û
üzGeneralName.__eq__N)rV   rW   rX   rm  rc   r5   r×  rû   rÜ  rZ   rt   r!   rË   r@   rE   r;   r;   r;   r?   rß  †  s    ÷rß  c                   @   r    )ÚGeneralNamesN)rV   rW   rX   rß  r¢   r;   r;   r;   r?   ré  ¸  r£   ré  c                   @   rz  )ÚTimeÚutc_timeÚgeneral_timeN)rV   rW   rX   r,   r   rË   r;   r;   r;   r?   rê  ¼  r}  rê  c                   @   r�  )ÚValidityr¹   r½   N)rV   rW   rX   rê  rž   r;   r;   r;   r?   rí  Ã  r}  rí  c                   @   s(   e Zd ZdeddifdeddifgZdS )ÚBasicConstraintsÚcaÚdefaultFÚpath_len_constraintr¼   TN)rV   rW   rX   r   r   rž   r;   r;   r;   r?   rî  Ê  r›  rî  c                   @   s:   e Zd ZdedddœfdedddœfdedddœfgZd	S )
ÚAuthorityKeyIdentifierÚkey_identifierr   Trº   Úauthority_cert_issuerr   Úauthority_cert_serial_numberr   N)rV   rW   rX   r#   ré  r   rž   r;   r;   r;   r?   rò  Ñ  s
    ýrò  c                   @   s(   e Zd ZdeddifdeddifgZdS )ÚDistributionPointNameÚ	full_namer»   r   Úname_relative_to_crl_issuerr   N)rV   rW   rX   ré  r"  rË   r;   r;   r;   r?   rö  Ù  r›  rö  c                
   @   r¤   )ÚReasonFlagsÚunusedÚkey_compromiseÚca_compromiseÚaffiliation_changedÚ
supersededÚcessation_of_operationÚcertificate_holdÚprivilege_withdrawnÚaa_compromiser¯   Nr´   r;   r;   r;   r?   rù  à  r¶   rù  c                   @   s2   e Zd ZdefdedddœfdedddœfgZd	S )
ÚGeneralSubtreeÚbaseÚminimumr   ©r»   rð  Úmaximumr   Trº   N)rV   rW   rX   rß  r   rž   r;   r;   r;   r?   r  î  ó
    ýr  c                   @   r    )ÚGeneralSubtreesN)rV   rW   rX   r  r¢   r;   r;   r;   r?   r	  ö  r£   r	  c                   @   r·   )ÚNameConstraintsÚpermitted_subtreesr   Trº   Úexcluded_subtreesr   N)rV   rW   rX   r	  rž   r;   r;   r;   r?   r
  ú  r¾   r
  c                   @   sJ   e Zd Zdedddœfdedddœfded	ddœfgZd
Zedd„ ƒZ	dS )ÚDistributionPointÚdistribution_pointr   TrŒ  Úreasonsr   rº   Ú
crl_issuerr   Fc                 C   sl   | j du r3d| _ | d }|jdkrttdƒƒ‚|jD ]}|jdkr2|j}| ¡  d¡r2|| _  | j S q| j S )z_
        :return:
            None or a unicode string of the distribution point's URL
        FNr  r÷  z‡
                    CRL distribution points that are relative to the issuer are
                    not supported
                    ræ  ©zhttp://zhttps://zldap://zldaps://)Ú_urlrÚ   ru   r	   rN  r]   rD   rL   )r=   rÚ   Úgeneral_nameÚurlr;   r;   r?   r  
  s    

ÿ

€ zDistributionPoint.urlN)
rV   rW   rX   rö  rù  ré  rž   r  rr   r  r;   r;   r;   r?   r    s    ýr  c                   @   r    )ÚCRLDistributionPointsN)rV   rW   rX   r  r¢   r;   r;   r;   r?   r  &  r£   r  c                   @   s(   e Zd ZdefdefdefdefgZdS )ÚDisplayTextrÊ   Úvisible_stringrÉ   rÈ   N)rV   rW   rX   r   r.   r   r-   rË   r;   r;   r;   r?   r  *  s    ür  c                   @   r    )ÚNoticeNumbersN©rV   rW   rX   r   r¢   r;   r;   r;   r?   r  3  r£   r  c                   @   rz  )ÚNoticeReferenceÚorganizationÚnotice_numbersN)rV   rW   rX   r  r  rž   r;   r;   r;   r?   r  7  r}  r  c                   @   r™  )Ú
UserNoticeÚ
notice_refr¼   TÚexplicit_textN)rV   rW   rX   r  r  rž   r;   r;   r;   r?   r  >  r›  r  c                   @   s   e Zd ZdddœZdS )ÚPolicyQualifierIdÚ certification_practice_statementÚuser_notice)z1.3.6.1.5.5.7.2.1z1.3.6.1.5.5.7.2.2Nr´   r;   r;   r;   r?   r   E  s    
þr   c                   @   s*   e Zd ZdefdefgZdZeedœZ	dS )ÚPolicyQualifierInfoÚpolicy_qualifier_idÚ	qualifier)r$  r%  )r!  r"  N)
rV   rW   rX   r   r   rž   r   r   r  r!  r;   r;   r;   r?   r#  L  s    þ
þr#  c                   @   r    )ÚPolicyQualifierInfosN)rV   rW   rX   r#  r¢   r;   r;   r;   r?   r&  Y  r£   r&  c                   @   s   e Zd ZddiZdS )ÚPolicyIdentifierz2.5.29.32.0Ú
any_policyNr´   r;   r;   r;   r?   r'  ]  s    ÿr'  c                   @   rl  )ÚPolicyInformationÚpolicy_identifierÚpolicy_qualifiersr¼   TN)rV   rW   rX   r'  r&  rž   r;   r;   r;   r?   r)  c  rŸ   r)  c                   @   r    )ÚCertificatePoliciesN)rV   rW   rX   r)  r¢   r;   r;   r;   r?   r,  j  r£   r,  c                   @   r�  )ÚPolicyMappingÚissuer_domain_policyÚsubject_domain_policyN)rV   rW   rX   r'  rž   r;   r;   r;   r?   r-  n  r}  r-  c                   @   r    )ÚPolicyMappingsN)rV   rW   rX   r-  r¢   r;   r;   r;   r?   r0  u  r£   r0  c                   @   r·   )ÚPolicyConstraintsÚrequire_explicit_policyr   Trº   Úinhibit_policy_mappingr   N©rV   rW   rX   r   rž   r;   r;   r;   r?   r1  y  r¾   r1  c                   @   s  e Zd Zi dd“dd“dd“dd“d	d
“dd“dd“dd“dd“dd“dd“dd“dd“dd“dd“dd “d!d"“i d#d$“d%d&“d'd(“d)d*“d+d,“d-d.“d/d0“d1d2“d3d4“d5d6“d7d8“d9d:“d;d<“d=d>“d?d@“dAdB“dCdD“¥i dEdF“dGdH“dIdJ“dKdL“dMdN“dOdP“dQdR“dSdT“dUdV“dWdX“dYdZ“d[d\“d]d^“d_d`“dadb“dcdd“dedf“¥i dgdh“didj“dkdl“dmdn“dodp“dqdr“dsdt“dudv“dwdx“dydz“d{d|“d}d~“dd€“d�d‚“dƒd„“d…d†“d‡dˆ“¥i d‰dŠ“d‹dŒ“d�dŽ“d�d�“d‘d’“d“d”“d•d–“d—d˜“d™dš“d›dœ“d�dž“dŸd “d¡d¢“d£d¤“d¥d¦“d§d¨“d©dª“¥Zd«S )¬ÚKeyPurposeIdz2.5.29.37.0Úany_extended_key_usagez1.3.6.1.5.5.7.3.1Úserver_authz1.3.6.1.5.5.7.3.2Úclient_authz1.3.6.1.5.5.7.3.3Úcode_signingz1.3.6.1.5.5.7.3.4Úemail_protectionz1.3.6.1.5.5.7.3.5Úipsec_end_systemz1.3.6.1.5.5.7.3.6Úipsec_tunnelz1.3.6.1.5.5.7.3.7Ú
ipsec_userz1.3.6.1.5.5.7.3.8Útime_stampingz1.3.6.1.5.5.7.3.9Úocsp_signingz1.3.6.1.5.5.7.3.10Údvcsz1.3.6.1.5.5.7.3.13Úeap_over_pppz1.3.6.1.5.5.7.3.14Úeap_over_lanz1.3.6.1.5.5.7.3.15Úscvp_serverz1.3.6.1.5.5.7.3.16Úscvp_clientz1.3.6.1.5.5.7.3.17Ú	ipsec_ikez1.3.6.1.5.5.7.3.18Ú	capwap_acz1.3.6.1.5.5.7.3.19Ú
capwap_wtpz1.3.6.1.5.5.7.3.20Ú
sip_domainz1.3.6.1.5.5.7.3.21Úsecure_shell_clientz1.3.6.1.5.5.7.3.22Úsecure_shell_serverz1.3.6.1.5.5.7.3.23Úsend_routerz1.3.6.1.5.5.7.3.24Úsend_proxied_routerz1.3.6.1.5.5.7.3.25Ú
send_ownerz1.3.6.1.5.5.7.3.26Úsend_proxied_ownerz1.3.6.1.5.5.7.3.27Úcmc_caz1.3.6.1.5.5.7.3.28Úcmc_raz1.3.6.1.5.5.7.3.29Úcmc_archivez1.3.6.1.5.5.7.3.30Úbgpspec_routerz1.3.6.1.5.5.8.2.2Úike_intermediatez1.3.6.1.4.1.311.10.3.1Úmicrosoft_trust_list_signingz1.3.6.1.4.1.311.10.3.2Úmicrosoft_time_stamp_signingz1.3.6.1.4.1.311.10.3.3Úmicrosoft_server_gatedz1.3.6.1.4.1.311.10.3.3.1Úmicrosoft_serializedz1.3.6.1.4.1.311.10.3.4Úmicrosoft_efsz1.3.6.1.4.1.311.10.3.4.1Úmicrosoft_efs_recoveryz1.3.6.1.4.1.311.10.3.5Úmicrosoft_whqlz1.3.6.1.4.1.311.10.3.6Úmicrosoft_nt5z1.3.6.1.4.1.311.10.3.7Úmicrosoft_oem_whqlz1.3.6.1.4.1.311.10.3.8Úmicrosoft_embedded_ntz1.3.6.1.4.1.311.10.3.9Úmicrosoft_root_list_signerz1.3.6.1.4.1.311.10.3.10Ú!microsoft_qualified_subordinationz1.3.6.1.4.1.311.10.3.11Úmicrosoft_key_recoveryz1.3.6.1.4.1.311.10.3.12Úmicrosoft_document_signingz1.3.6.1.4.1.311.10.3.13Úmicrosoft_lifetime_signingz1.3.6.1.4.1.311.10.3.14Ú microsoft_mobile_device_softwarez1.3.6.1.4.1.311.20.2.2Úmicrosoft_smart_card_logonz1.2.840.113635.100.1.2Úapple_x509_basicz1.2.840.113635.100.1.3Ú	apple_sslz1.2.840.113635.100.1.4Úapple_local_cert_genz1.2.840.113635.100.1.5Úapple_csr_genz1.2.840.113635.100.1.6Úapple_revocation_crlz1.2.840.113635.100.1.7Úapple_revocation_ocspz1.2.840.113635.100.1.8Úapple_smimez1.2.840.113635.100.1.9Ú	apple_eapz1.2.840.113635.100.1.10Úapple_software_update_signingz1.2.840.113635.100.1.11Úapple_ipsecz1.2.840.113635.100.1.12Úapple_ichatz1.2.840.113635.100.1.13Úapple_resource_signingz1.2.840.113635.100.1.14Úapple_pkinit_clientz1.2.840.113635.100.1.15Úapple_pkinit_serverz1.2.840.113635.100.1.16Úapple_code_signingz1.2.840.113635.100.1.17Úapple_package_signingz1.2.840.113635.100.1.18Úapple_id_validationz1.2.840.113635.100.1.20Úapple_time_stampingz1.2.840.113635.100.1.21Úapple_revocationz1.2.840.113635.100.1.22Úapple_passbook_signingz1.2.840.113635.100.1.23Úapple_mobile_storez1.2.840.113635.100.1.24Úapple_escrow_servicez1.2.840.113635.100.1.25Úapple_profile_signerz1.2.840.113635.100.1.26Úapple_qa_profile_signerz1.2.840.113635.100.1.27Úapple_test_mobile_storez1.2.840.113635.100.1.28Úapple_otapki_signerz1.2.840.113635.100.1.29Úapple_test_otapki_signerz1.2.840.113625.100.1.30Ú)apple_id_validation_record_signing_policyz1.2.840.113625.100.1.31Úapple_smp_encryptionz1.2.840.113625.100.1.32Úapple_test_smp_encryptionz1.2.840.113635.100.1.33Úapple_server_authenticationz1.2.840.113635.100.1.34Úapple_pcs_escrow_servicez2.16.840.1.101.3.6.8Úpiv_card_authenticationz2.16.840.1.101.3.6.7Úpiv_content_signingz1.3.6.1.5.2.3.4Úpkinit_kpclientauthz1.3.6.1.5.2.3.5Úpkinit_kpkdcz1.2.840.113583.1.1.5Úadobe_authentic_documents_trustz2.16.840.1.101.3.8.7Úfpki_pivi_content_signingNr´   r;   r;   r;   r?   r5  €  sX   þýüûúùø	÷
öõóñðîíëéèæäãá à!ß"Þ$Ü%Û&Ú(Ø*Ö-Ó.Ò/Ñ0Ð1Ï2Î3Í4Ì5Ë6Ê7É8È9Ç:Æ;Å<Ä>ÂB¾C½D¼E»FºG¹H¸I·J¶KµL´M³N²O±P°Q¯R®S­T¬U«VªW©X¨Y§Z¦[¥\¤]£^¢_¡` aŸc�dœfšg™i—k
•r5  c                   @   r    )ÚExtKeyUsageSyntaxN©rV   rW   rX   r5  r¢   r;   r;   r;   r?   r‹  ð  r£   r‹  c                   @   ó   e Zd ZdddddœZdS )ÚAccessMethodÚocspÚ
ca_issuersr>  Úca_repository)z1.3.6.1.5.5.7.48.1z1.3.6.1.5.5.7.48.2z1.3.6.1.5.5.7.48.3z1.3.6.1.5.5.7.48.5Nr´   r;   r;   r;   r?   rŽ  ô  ó    
ürŽ  c                   @   rz  )ÚAccessDescriptionÚaccess_methodÚaccess_locationN)rV   rW   rX   rŽ  rß  rž   r;   r;   r;   r?   r“  ý  r}  r“  c                   @   r    )ÚAuthorityInfoAccessSyntaxN©rV   rW   rX   r“  r¢   r;   r;   r;   r?   r–    r£   r–  c                   @   r    )ÚSubjectInfoAccessSyntaxNr—  r;   r;   r;   r?   r˜    r£   r˜  c                   @   r    )ÚFeaturesNr  r;   r;   r;   r?   r™    r£   r™  c                   @   rz  )ÚEntrustVersionInfoÚentrust_versÚentrust_info_flagsN)rV   rW   rX   r   r   rž   r;   r;   r;   r?   rš    r}  rš  c                	   @   s"   e Zd Zddddddddd	œZd
S )ÚNetscapeCertificateTypeÚ
ssl_clientÚ
ssl_serverÚemailÚobject_signingÚreservedÚssl_caÚemail_caÚobject_signing_ca)r   r   r   r°   r“   r±   r²   r³   Nr´   r;   r;   r;   r?   r�    s    
ør�  c                   @   ó   e Zd ZddddœZdS )ÚVersionÚv1Úv2Úv3©r   r   r   Nr´   r;   r;   r;   r?   r§  %  ó
    
ýr§  c                   @   s"   e Zd ZdefdefdefgZdS )ÚTPMSpecificationrŽ   ÚlevelÚrevisionN)rV   rW   rX   r-   r   rž   r;   r;   r;   r?   r­  -  ó
    ýr­  c                   @   r    )ÚSetOfTPMSpecificationN)rV   rW   rX   r­  r¢   r;   r;   r;   r?   r±  5  r£   r±  c                   @   s"   e Zd ZdefdefdefgZdS )ÚTCGSpecificationVersionÚmajor_versionÚminor_versionr¯  Nr4  r;   r;   r;   r?   r²  9  r°  r²  c                   @   rz  )ÚTCGPlatformSpecificationÚversionÚplatform_classN)rV   rW   rX   r²  r#   rž   r;   r;   r;   r?   rµ  A  r}  rµ  c                   @   r    )ÚSetOfTCGPlatformSpecificationN)rV   rW   rX   rµ  r¢   r;   r;   r;   r?   r¸  H  r£   r¸  c                   @   r�  )ÚEKGenerationTypeÚinternalÚinjectedÚinternal_revocableÚinjected_revocable)r   r   r   r°   Nr´   r;   r;   r;   r?   r¹  L  r’  r¹  c                   @   r¦  )ÚEKGenerationLocationrâ   rå   Úek_cert_signerr«  Nr´   r;   r;   r;   r?   r¾  U  r¬  r¾  c                   @   r¦  )ÚEKCertificateGenerationLocationrâ   rå   r¿  r«  Nr´   r;   r;   r;   r?   rÀ  ]  r¬  rÀ  c                   @   s    e Zd ZddddddddœZd	S )
ÚEvaluationAssuranceLevelÚlevel1Úlevel2Úlevel3Úlevel4Úlevel5Úlevel6Úlevel7)r   r   r°   r“   r±   r²   r³   Nr´   r;   r;   r;   r?   rÁ  e  s    
ùrÁ  c                   @   r¦  )ÚEvaluationStatusÚdesigned_to_meetÚevaluation_in_progressÚevaluation_completedr«  Nr´   r;   r;   r;   r?   rÉ  q  r¬  rÉ  c                   @   r¦  )ÚStrengthOfFunctionÚbasicÚmediumÚhighr«  Nr´   r;   r;   r;   r?   rÍ  y  r¬  rÍ  c                   @   rÖ  )ÚURIReferenceræ  Úhash_algorithmr¼   TÚ
hash_valueN)rV   rW   rX   r   r   r   rž   r;   r;   r;   r?   rÑ  �  rÛ  rÑ  c                   @   st   e Zd Zdefdefdefdeddifdedd	d
œfdedd	d
œfde	dd	d
œfdedd	d
œfde	dd	d
œfg	Z
dS )ÚCommonCriteriaMeasuresr¶  Úassurance_levelÚevaluation_statusÚplusrð  FÚstrengh_of_functionr   Trº   Úprofile_oidr   Úprofile_urlr   Ú
target_oidr°   Ú
target_urir“   N)rV   rW   rX   r   rÁ  rÉ  r   rÍ  r!   rÑ  rž   r;   r;   r;   r?   rÔ  ‰  s    ÷rÔ  c                   @   r�  )ÚSecurityLevelrÂ  rÃ  rÄ  rÅ  )r   r   r°   r“   Nr´   r;   r;   r;   r?   rÝ  —  r’  rÝ  c                   @   s(   e Zd ZdefdefdeddifgZdS )Ú	FIPSLevelr¶  r®  r×  rð  FN)rV   rW   rX   r   rÝ  r   rž   r;   r;   r;   r?   rÞ     s
    ýrÞ  c                   @   sˆ   e Zd Zdeddifdeddifdeddd	œfd
eddd	œfdeddd	œfdeddd	œfde	ddd	œfdedddœfde
ddifg	ZdS )ÚTPMSecurityAssertionsr¶  rð  r¨  Úfield_upgradableFÚek_generation_typer   Trº   Úek_generation_locationr   Ú"ek_certificate_generation_locationr   Úcc_infor°   Ú
fips_levelr“   Úiso_9000_certifiedr±   r  Úiso_9000_urir¼   N)rV   rW   rX   r§  r   r¹  r¾  rÀ  rÔ  rÞ  r   rž   r;   r;   r;   r?   rß  ¨  s    ÷rß  c                   @   r    )ÚSetOfTPMSecurityAssertionsN)rV   rW   rX   rß  r¢   r;   r;   r;   r?   rè  ¶  r£   rè  c                   @   s&   e Zd Zddddddddd	d
dœ
ZdS )ÚSubjectDirectoryAttributeIdÚsupported_algorithmsÚtpm_specificationÚtcg_platform_specificationÚtpm_security_assertionsÚpda_date_of_birthÚpda_place_of_birthÚ
pda_genderÚpda_country_of_citizenshipÚpda_country_of_residenceÚentrust_user_role)
z2.5.4.52z2.23.133.2.16z2.23.133.2.17z2.23.133.2.18z1.3.6.1.5.5.7.9.1z1.3.6.1.5.5.7.9.2z1.3.6.1.5.5.7.9.3z1.3.6.1.5.5.7.9.4z1.3.6.1.5.5.7.9.5z1.2.840.113533.7.68.29Nr´   r;   r;   r;   r?   ré  º  s    
òré  c                   @   r    )ÚSetOfGeneralizedTimeN)rV   rW   rX   r   r¢   r;   r;   r;   r?   rô  Í  r£   rô  c                   @   r    )ÚSetOfDirectoryStringN)rV   rW   rX   rÄ   r¢   r;   r;   r;   r?   rõ  Ñ  r£   rõ  c                   @   r    )ÚSetOfPrintableStringNr…  r;   r;   r;   r?   rö  Õ  r£   rö  c                   @   s2   e Zd ZdefdedddœfdedddœfgZdS )	ÚSupportedAlgorithmÚalgorithm_identifierÚintended_usager   TrŒ  Úintended_certificate_policiesr   N)rV   rW   rX   r   r¥   r,  rž   r;   r;   r;   r?   r÷  Ù  r  r÷  c                   @   r    )ÚSetOfSupportedAlgorithmN)rV   rW   rX   r÷  r¢   r;   r;   r;   r?   rû  á  r£   rû  c                
   @   sH   e Zd ZdefdefgZdZeee	e
eeeeedœ	Zdd„ ZdeiZdS )ÚSubjectDirectoryAttributerœ   r�   )rœ   r�   )	rê  rë  rì  rí  rî  rï  rð  rñ  rò  c                 C   s"   | d j }|| jv r| j| S tS )Nrœ   )r]   r!  r)   )r=   Útype_r;   r;   r?   Ú_values_specø  s   


z&SubjectDirectoryAttribute._values_specN)rV   rW   rX   ré  r   rž   r   rû  r±  r¸  rè  rô  rõ  rö  r!  rþ  Ú_spec_callbacksr;   r;   r;   r?   rü  å  s$    þ÷ÿrü  c                   @   r    )ÚSubjectDirectoryAttributesN)rV   rW   rX   rü  r¢   r;   r;   r;   r?   r     r£   r   c                	   @   sŠ   e Zd Zi dd“dd“dd“dd“d	d
“dd“dd“dd“dd“dd“dd“dd“dd“dd“dd“dd “d!d"“d#d$d%d&d'd(d)d*œ¥Zd+S ),ÚExtensionIdz2.5.29.9Úsubject_directory_attributesz	2.5.29.14ró  z	2.5.29.15Ú	key_usagez	2.5.29.16Úprivate_key_usage_periodz	2.5.29.17Úsubject_alt_namez	2.5.29.18Úissuer_alt_namez	2.5.29.19Úbasic_constraintsz	2.5.29.30Úname_constraintsz	2.5.29.31Úcrl_distribution_pointsz	2.5.29.32Úcertificate_policiesz	2.5.29.33Úpolicy_mappingsz	2.5.29.35Úauthority_key_identifierz	2.5.29.36Úpolicy_constraintsz	2.5.29.37Úextended_key_usagez	2.5.29.46Úfreshest_crlz	2.5.29.54Úinhibit_any_policyz1.3.6.1.5.5.7.1.1Úauthority_information_accessÚsubject_information_accessÚtls_featureÚocsp_no_checkÚentrust_version_extensionÚnetscape_certificate_typeÚ!signed_certificate_timestamp_listÚmicrosoft_enroll_certtype)z1.3.6.1.5.5.7.1.11z1.3.6.1.5.5.7.1.24z1.3.6.1.5.5.7.48.1.5z1.2.840.113533.7.65.0z2.16.840.1.113730.1.1z1.3.6.1.4.1.11129.2.4.2z1.3.6.1.4.1.311.20.2Nr´   r;   r;   r;   r?   r    sX    ÿþýüûúùø	÷
öõôóòñðïår  c                	   @   sª   e Zd ZdefdeddifdefgZdZi de“de	“d	e
“d
e“de“de“de“de“de“de“de“de“de“de“de“de“de“eeeeee	edœ¥ZdS )Ú	ExtensionÚextn_idÚcriticalrð  FÚ
extn_value)r  r  r  ró  r  r  r  r  r  r  r	  r
  r  r  r  r  r  r  r  )r  r  r  r  r  r  r  N)rV   rW   rX   r  r   r$   rž   r   r   r#   r¥   r¸   ré  rî  r
  r  r,  r0  rò  r1  r‹  r   r–  r˜  r™  r   rš  r�  r   r!  r;   r;   r;   r?   r  '  sb    ýÿþýüûúùø	÷
öõôóòñðïær  c                   @   r    )Ú
ExtensionsN)rV   rW   rX   r  r¢   r;   r;   r;   r?   r  M  r£   r  c                   @   sl   e Zd Zdedddœfdefdefdefdefd	efd
efde	dddœfde	dddœfde
dddœfg
ZdS )ÚTbsCertificater¶  r   r¨  )ro  rð  rÏ   Ú	signatureÚissuerÚvalidityÚsubjectÚsubject_public_key_infoÚissuer_unique_idr   Trº   Úsubject_unique_idr   Ú
extensionsr°   rŒ  N)rV   rW   rX   r§  r   r   rû   rí  r0   r"   r  rž   r;   r;   r;   r?   r  Q  s    ör  c                   @   sþ  e Zd ZdefdefdefgZdZdZdZ	dZ
dZdZdZdZdZdZdZdZdZdZdZdZdZdZdZdZdZdZdZdZdZdZ dZ!dZ"dZ#dZ$dZ%dZ&dd„ Z'e(dd	„ ƒZ)e(d
d„ ƒZ*e(dd„ ƒZ+e(dd„ ƒZ,e(dd„ ƒZ-e(dd„ ƒZ.e(dd„ ƒZ/e(dd„ ƒZ0e(dd„ ƒZ1e(dd„ ƒZ2e(dd„ ƒZ3e(dd„ ƒZ4e(d d!„ ƒZ5e(d"d#„ ƒZ6e(d$d%„ ƒZ7e(d&d'„ ƒZ8e(d(d)„ ƒZ9e(d*d+„ ƒZ:e(d,d-„ ƒZ;e(d.d/„ ƒZ<e(d0d1„ ƒZ=e(d2d3„ ƒZ>e(d4d5„ ƒZ?e(d6d7„ ƒZ@e(d8d9„ ƒZAe(d:d;„ ƒZBe(d<d=„ ƒZCe(d>d?„ ƒZDe(d@dA„ ƒZEe(dBdC„ ƒZFe(dDdE„ ƒZGe(dFdG„ ƒZHe(dHdI„ ƒZIe(dJdK„ ƒZJe(dLdM„ ƒZKe(dNdO„ ƒZLdPdQ„ ZMe(dRdS„ ƒZNe(dTdU„ ƒZOe(dVdW„ ƒZPe(dXdY„ ƒZQe(dZd[„ ƒZRe(d\d]„ ƒZSe(d^d_„ ƒZTe(d`da„ ƒZUe(dbdc„ ƒZVe(ddde„ ƒZWe(dfdg„ ƒZXdhdi„ ZYdjdk„ ZZdldm„ Z[dS )nÚCertificateÚtbs_certificateÚsignature_algorithmÚsignature_valueFNc                 C   sh   t ƒ | _| d d D ]$}|d j}d| }t| |ƒr#t| ||d jƒ |d jr.| j |¡ q
d| _dS )	zv
        Sets common named extensions to private attributes and creates a list
        of critical extensions
        r(  r&  r  z	_%s_valuer  r  TN)rU   Ú_critical_extensionsr]   ÚhasattrÚsetattrÚparsedÚaddÚ_processed_extensions)r=   Ú	extensionrÚ   rK  r;   r;   r?   Ú_set_extensionsˆ  s   


€
zCertificate._set_extensionsc                 C   ó   | j s|  ¡  | jS )z²
        Returns a set of the names (or OID if not a known extension) of the
        extensions marked as critical

        :return:
            A set of unicode strings
        )r0  r2  r+  rb   r;   r;   r?   Úcritical_extensionsš  ó   
zCertificate.critical_extensionsc                 C   r3  )z¼
        This extension is used to constrain the period over which the subject
        private key may be used

        :return:
            None or a PrivateKeyUsagePeriod object
        )r0  r2  Ú_private_key_usage_period_valuerb   r;   r;   r?   Úprivate_key_usage_period_value¨  r5  z*Certificate.private_key_usage_period_valuec                 C   r3  )z½
        This extension is used to contain additional identification attributes
        about the subject.

        :return:
            None or a SubjectDirectoryAttributes object
        )r0  r2  Ú#_subject_directory_attributes_valuerb   r;   r;   r?   Ú"subject_directory_attributes_value¶  r5  z.Certificate.subject_directory_attributes_valuec                 C   r3  )zü
        This extension is used to help in creating certificate validation paths.
        It contains an identifier that should generally, but is not guaranteed
        to, be unique.

        :return:
            None or an OctetString object
        )r0  r2  Ú_key_identifier_valuerb   r;   r;   r?   Úkey_identifier_valueÄ  ó   z Certificate.key_identifier_valuec                 C   r3  )z«
        This extension is used to define the purpose of the public key
        contained within the certificate.

        :return:
            None or a KeyUsage
        )r0  r2  Ú_key_usage_valuerb   r;   r;   r?   Úkey_usage_valueÓ  r5  zCertificate.key_usage_valuec                 C   r3  )aT  
        This extension allows for additional names to be associate with the
        subject of the certificate. While it may contain a whole host of
        possible names, it is usually used to allow certificates to be used
        with multiple different domain names.

        :return:
            None or a GeneralNames object
        )r0  r2  Ú_subject_alt_name_valuerb   r;   r;   r?   Úsubject_alt_name_valueá  ó   z"Certificate.subject_alt_name_valuec                 C   r3  )z¿
        This extension allows associating one or more alternative names with
        the issuer of the certificate.

        :return:
            None or an x509.GeneralNames object
        )r0  r2  Ú_issuer_alt_name_valuerb   r;   r;   r?   Úissuer_alt_name_valueñ  r5  z!Certificate.issuer_alt_name_valuec                 C   r3  )a'  
        This extension is used to determine if the subject of the certificate
        is a CA, and if so, what the maximum number of intermediate CA certs
        after this are, before an end-entity certificate is found.

        :return:
            None or a BasicConstraints object
        )r0  r2  Ú_basic_constraints_valuerb   r;   r;   r?   Úbasic_constraints_valueÿ  r<  z#Certificate.basic_constraints_valuec                 C   r3  )zÃ
        This extension is used in CA certificates, and is used to limit the
        possible names of certificates issued.

        :return:
            None or a NameConstraints object
        )r0  r2  Ú_name_constraints_valuerb   r;   r;   r?   Úname_constraints_value	  r5  z"Certificate.name_constraints_valuec                 C   r3  )zµ
        This extension is used to help in locating the CRL for this certificate.

        :return:
            None or a CRLDistributionPoints object
            extension
        )r0  r2  Ú_crl_distribution_points_valuerb   r;   r;   r?   Úcrl_distribution_points_value	  r5  z)Certificate.crl_distribution_points_valuec                 C   r3  )a;  
        This extension defines policies in CA certificates under which
        certificates may be issued. In end-entity certificates, the inclusion
        of a policy indicates the issuance of the certificate follows the
        policy.

        :return:
            None or a CertificatePolicies object
        )r0  r2  Ú_certificate_policies_valuerb   r;   r;   r?   Úcertificate_policies_value*	  rA  z&Certificate.certificate_policies_valuec                 C   r3  )zû
        This extension allows mapping policy OIDs to other OIDs. This is used
        to allow different policies to be treated as equivalent in the process
        of validation.

        :return:
            None or a PolicyMappings object
        )r0  r2  Ú_policy_mappings_valuerb   r;   r;   r?   Úpolicy_mappings_value:	  r<  z!Certificate.policy_mappings_valuec                 C   r3  )zÏ
        This extension helps in identifying the public key with which to
        validate the authenticity of the certificate.

        :return:
            None or an AuthorityKeyIdentifier object
        )r0  r2  Ú_authority_key_identifier_valuerb   r;   r;   r?   Úauthority_key_identifier_valueI	  r5  z*Certificate.authority_key_identifier_valuec                 C   r3  )z¹
        This extension is used to control if policy mapping is allowed and
        when policies are required.

        :return:
            None or a PolicyConstraints object
        )r0  r2  Ú_policy_constraints_valuerb   r;   r;   r?   Úpolicy_constraints_valueW	  r5  z$Certificate.policy_constraints_valuec                 C   r3  )z–
        This extension is used to help locate any available delta CRLs

        :return:
            None or an CRLDistributionPoints object
        )r0  r2  Ú_freshest_crl_valuerb   r;   r;   r?   Úfreshest_crl_valuee	  s   	zCertificate.freshest_crl_valuec                 C   r3  )z¥
        This extension is used to prevent mapping of the any policy to
        specific requirements

        :return:
            None or a Integer object
        )r0  r2  Ú_inhibit_any_policy_valuerb   r;   r;   r?   Úinhibit_any_policy_valuer	  r5  z$Certificate.inhibit_any_policy_valuec                 C   r3  )zÖ
        This extension is used to define additional purposes for the public key
        beyond what is contained in the basic constraints.

        :return:
            None or an ExtKeyUsageSyntax object
        )r0  r2  Ú_extended_key_usage_valuerb   r;   r;   r?   Úextended_key_usage_value€	  r5  z$Certificate.extended_key_usage_valuec                 C   r3  )zâ
        This extension is used to locate the CA certificate used to sign this
        certificate, or the OCSP responder for this certificate.

        :return:
            None or an AuthorityInfoAccessSyntax object
        )r0  r2  Ú#_authority_information_access_valuerb   r;   r;   r?   Ú"authority_information_access_valueŽ	  r5  z.Certificate.authority_information_access_valuec                 C   r3  )z´
        This extension is used to access information about the subject of this
        certificate.

        :return:
            None or a SubjectInfoAccessSyntax object
        )r0  r2  Ú!_subject_information_access_valuerb   r;   r;   r?   Ú subject_information_access_valueœ	  r5  z,Certificate.subject_information_access_valuec                 C   r3  )zÍ
        This extension is used to list the TLS features a server must respond
        with if a client initiates a request supporting them.

        :return:
            None or a Features object
        )r0  r2  Ú_tls_feature_valuerb   r;   r;   r?   Útls_feature_valueª	  r5  zCertificate.tls_feature_valuec                 C   r3  )a-  
        This extension is used on certificates of OCSP responders, indicating
        that revocation information for the certificate should never need to
        be verified, thus preventing possible loops in path validation.

        :return:
            None or a Null object (if present)
        )r0  r2  Ú_ocsp_no_check_valuerb   r;   r;   r?   Úocsp_no_check_value¸	  r<  zCertificate.ocsp_no_check_valuec                 C   ó
   | d j S )zE
        :return:
            A byte string of the signature
        r*  r4  rb   r;   r;   r?   r  Ç	  ó   
zCertificate.signaturec                 C   r`  )zj
        :return:
            A unicode string of "rsassa_pkcs1v15", "rsassa_pss", "dsa", "ecdsa"
        r)  )Úsignature_algorb   r;   r;   r?   rb  Ð	  ra  zCertificate.signature_algoc                 C   r`  )zŸ
        :return:
            A unicode string of "md2", "md5", "sha1", "sha224", "sha256",
            "sha384", "sha512", "sha512_224", "sha512_256"
        r)  )Ú	hash_algorb   r;   r;   r?   rc  Ù	  s   
zCertificate.hash_algoc                 C   ó   | d d S )zT
        :return:
            The PublicKeyInfo object for this certificate
        r(  r#  r;   rb   r;   r;   r?   Ú
public_keyã	  ó   zCertificate.public_keyc                 C   rd  )zZ
        :return:
            The Name object for the subject of this certificate
        r(  r"  r;   rb   r;   r;   r?   r"  ì	  rf  zCertificate.subjectc                 C   rd  )zY
        :return:
            The Name object for the issuer of this certificate
        r(  r   r;   rb   r;   r;   r?   r   õ	  rf  zCertificate.issuerc                 C   s   | d d j S )zT
        :return:
            An integer of the certificate's serial number
        r(  rÏ   r4  rb   r;   r;   r?   rÏ   þ	  s   zCertificate.serial_numberc                 C   s   | j sdS | j jS )zŽ
        :return:
            None or a byte string of the certificate's key identifier from the
            key identifier extension
        N)r;  r]   rb   r;   r;   r?   ró  
  s   zCertificate.key_identifierc                 C   s.   | j du r| jjd t| jƒ d¡ | _ | j S )zÐ
        :return:
            A byte string of the SHA-256 hash of the issuer concatenated with
            the ascii character ":", concatenated with the serial number as
            an ascii string
        Nó   :rh   )Ú_issuer_serialr   rk  r   rÏ   rM   rb   r;   r;   r?   Úissuer_serial
  s   
	zCertificate.issuer_serialc                 C   ó   | d d d j S )zd
        :return:
            A datetime of latest time when the certificate is still valid
        r(  r!  r½   r4  rb   r;   r;   r?   Únot_valid_after!
  ó   zCertificate.not_valid_afterc                 C   rj  )zd
        :return:
            A datetime of the earliest time when the certificate is valid
        r(  r!  r¹   r4  rb   r;   r;   r?   Únot_valid_before)
  rl  zCertificate.not_valid_beforec                 C   s   | j sdS | j d jS )zŠ
        :return:
            None or a byte string of the key_identifier from the authority key
            identifier extension
        Nró  )rO  r]   rb   r;   r;   r?   r  1
  s   z$Certificate.authority_key_identifierc                 C   sn   | j du r4| j}|r1|d jr1| jd d j}| ¡ }| jd j}|jd t|ƒ d¡ | _ | j S d| _ | j S )a;  
        :return:
            None or a byte string of the SHA-256 hash of the isser from the
            authority key identifier extension concatenated with the ascii
            character ":", concatenated with the serial number from the
            authority key identifier extension as an ascii string
        Frô  r   rõ  rg  rh   N)Ú_authority_issuer_serialrO  r]   rN  Úuntagrk  r   rM   )r=   Úakivr   Úauthority_serialr;   r;   r?   Úauthority_issuer_serial>
  s   

ÿz#Certificate.authority_issuer_serialc                 C   ó   | j du r|  | j¡| _ | j S )z˜
        Returns complete CRL URLs - does not include delta CRLs

        :return:
            A list of zero or more DistributionPoint objects
        N)Ú_crl_distribution_pointsÚ!_get_http_crl_distribution_pointsrI  rb   r;   r;   r?   r	  T
  ó   
	z#Certificate.crl_distribution_pointsc                 C   rs  )z˜
        Returns delta CRL URLs - does not include complete CRLs

        :return:
            A list of zero or more DistributionPoint objects
        N)Ú_delta_crl_distribution_pointsru  rS  rb   r;   r;   r?   Údelta_crl_distribution_pointsa
  rv  z)Certificate.delta_crl_distribution_pointsc                 C   s\   g }|du rg S |D ]!}|d }|t u rq
|jdkrq
|jD ]}|jdkr*| |¡ qq
|S )a?  
        Fetches the DistributionPoint object for non-relative, HTTP CRLs
        referenced by the certificate

        :param crl_distribution_points:
            A CRLDistributionPoints object to grab the DistributionPoints from

        :return:
            A list of zero or more DistributionPoint objects
        Nr  rø  ræ  )r/   rÚ   rN  r)  )r=   r	  r*  r  Údistribution_point_namer  r;   r;   r?   ru  n
  s   



€þz-Certificate._get_http_crl_distribution_pointsc                 C   s^   | j sg S g }| j D ]"}|d jdkr,|d }|jdkrq
|j}| ¡  d¡r,| |¡ q
|S )zx
        :return:
            A list of zero or more unicode strings of the OCSP URLs for this
            cert
        r”  r�  r•  ræ  r  )rY  r]   rÚ   rD   rL   r)  )r=   r*  ÚentryÚlocationr  r;   r;   r?   Ú	ocsp_urls�
  s   


€zCertificate.ocsp_urlsc                 C   s¢   | j du rNg | _ | jr&| jD ]}|jdkr"|j| j vr"| j  |j¡ q| j S t d¡}| jjD ]}|D ]}|d jdkrL|d j}| 	|¡rL| j  |¡ q3q/| j S )z»
        :return:
            A list of unicode strings of valid domain names for the certificate.
            Wildcard certificates will have a domain in the form: *.example.com
        Nrâ  zE^(\*\.)?(?:[a-zA-Z0-9](?:[a-zA-Z0-9\-]*[a-zA-Z0-9])?\.)+[a-zA-Z]{2,}$rœ   rÍ   rS   )
Ú_valid_domainsr@  rÚ   r]   r)  r  Úcompiler"  rN  Úmatch)r=   r  Úpatternr;  Úname_type_valuerS   r;   r;   r?   Úvalid_domains£
  s$   

€
ø

€üzCertificate.valid_domainsc                 C   s@   | j du rg | _ | jr| jD ]}|jdkr| j  |j¡ q| j S )zj
        :return:
            A list of unicode strings of valid IP addresses for the certificate
        Nrç  )Ú
_valid_ipsr@  rÚ   r)  r]   )r=   r  r;   r;   r?   Ú	valid_ipsÆ
  s   


€zCertificate.valid_ipsc                 C   s   | j o| j d jS )zW
        :return;
            A boolean - if the certificate is marked as a CA
        rï  )rE  r]   rb   r;   r;   r?   rï  ×
  s   zCertificate.cac                 C   s   | j sdS | jd jS )zT
        :return;
            None or an integer of the maximum path length
        Nrñ  )rï  rE  r]   rb   r;   r;   r?   Úmax_path_lengthà
  s   zCertificate.max_path_lengthc                 C   s   | j du r| j| jk| _ | j S )zx
        :return:
            A boolean - if the certificate is self-issued, as defined by RFC
            5280
        N)Ú_self_issuedr"  r   rb   r;   r;   r?   Úself_issuedë
  s   
zCertificate.self_issuedc                 C   sR   | j du r&d| _ | jr&| jr#| jsd| _ | j S | j| jkr d| _ | j S d| _ | j S )aõ  
        :return:
            A unicode string of "no" or "maybe". The "maybe" result will
            be returned if the certificate issuer and subject are the same.
            If a key identifier and authority key identifier are present,
            they will need to match otherwise "no" will be returned.

            To verify is a certificate is truly self-signed, the signature
            will need to be verified. See the certvalidator package for
            one possible solution.
        NÚnoÚmaybe)Ú_self_signedr‡  ró  r  rb   r;   r;   r?   Úself_signed÷
  s   
üÿzCertificate.self_signedc                 C   ra  )zk
        :return:
            The SHA-1 hash of the DER-encoded bytes of this complete certificate
        Nrb  rb   r;   r;   r?   re    rh  zCertificate.sha1c                 C   ó   d  dd„ t| jƒD ƒ¡S )z¯
        :return:
            A unicode string of the SHA-1 hash, formatted using hex encoding
            with a space between each pair of characters, all uppercase
        r  c                 s   ó   � | ]}d | V  qdS ©z%02XNr;   ©r6  Úcr;   r;   r?   r@  $  ó   € z/Certificate.sha1_fingerprint.<locals>.<genexpr>)r  r   re  rb   r;   r;   r?   Úsha1_fingerprint  ó   zCertificate.sha1_fingerprintc                 C   ra  )zy
        :return:
            The SHA-256 hash of the DER-encoded bytes of this complete
            certificate
        Nri  rb   r;   r;   r?   rk  &  s   
zCertificate.sha256c                 C   rŒ  )z±
        :return:
            A unicode string of the SHA-256 hash, formatted using hex encoding
            with a space between each pair of characters, all uppercase
        r  c                 s   r�  rŽ  r;   r�  r;   r;   r?   r@  :  r‘  z1Certificate.sha256_fingerprint.<locals>.<genexpr>)r  r   rk  rb   r;   r;   r?   Úsha256_fingerprint2  r“  zCertificate.sha256_fingerprintc                 C   sH  t |tƒsttdt|ƒƒƒ‚| d¡ d¡ ¡ }| d¡dk}| o't	 
d|¡}| o-| }|rq| js5dS | d¡}| jD ]1}| d¡ d¡ ¡ }| d¡}	t|	ƒt|ƒkrWq=|	|kr^ d	S |  |¡}
|
rn|  ||	¡rn d	S q=dS | jsvdS |r{tjntj}t||ƒ}| jD ]}| d¡dkr’tjntj}t||ƒ}||kr¡ d	S q†dS )
a  
        Check if a domain name or IP address is valid according to the
        certificate

        :param domain_ip:
            A unicode string of a domain name or IP address

        :return:
            A boolean - if the domain or IP is valid for the certificate
        zL
                domain_ip must be a unicode string, not %s
                r   rh   rz   rg   z^\d+\.\d+\.\d+\.\d+$FrH   T)rB   r   rK   r	   r   rM   ro   rD   rj   r  r  r‚  r‚   r‡   Ú_is_wildcard_domainÚ_is_wildcard_matchr„  r„   r†   r…   r4   )r=   Ú	domain_ipÚencoded_domain_ipÚis_ipv6Úis_ipv4Ú	is_domainÚdomain_labelsÚvalid_domainÚencoded_valid_domainÚvalid_domain_labelsÚis_wildcardrŽ   Únormalized_ipÚvalid_ipÚvalid_familyÚnormalized_valid_ipr;   r;   r?   Úis_valid_domain_ip<  sH   
ü



€


ÿzCertificate.is_valid_domain_ipc                 C   sZ   |  d¡dkr	dS | ¡  d¡}|sdS |d  d¡dkrdS |d dd… dkr+dS d	S )
af  
        Checks if a domain is a valid wildcard according to
        https://tools.ietf.org/html/rfc6125#section-6.4.3

        :param domain:
            A unicode string of the domain name, where any U-labels from an IDN
            have been converted to A-labels

        :return:
            A boolean - if the domain is a valid wildcard domain
        Ú*r   FrH   r   rg   r“   zxn--T)ÚcountrD   r‚   rj   )r=   ÚdomainÚlabelsr;   r;   r?   r•  ~  s   zCertificate._is_wildcard_domainc                 C   sl   |d }|dd… }|d }|dd… }||krdS |dkr dS t  d| dd¡ d	 ¡}| |¡r4dS dS )
aÿ  
        Determines if the labels in a domain are a match for labels from a
        wildcard valid domain name

        :param domain_labels:
            A list of unicode strings, with A-label form for IDNs, of the labels
            in the domain name to check

        :param valid_domain_labels:
            A list of unicode strings, with A-label form for IDNs, of the labels
            in a wildcard domain pattern

        :return:
            A boolean - if the domain matches the valid domain
        r   r   NFr¦  Tú^z.*ú$)r  r~  r  r  )r=   rœ  rŸ  Úfirst_domain_labelÚother_domain_labelsÚwildcard_labelÚother_valid_domain_labelsÚwildcard_regexr;   r;   r?   r–  Ÿ  s   
zCertificate._is_wildcard_match)\rV   rW   rX   r  r   r"   rž   r0  r+  r8  r:  r=  r?  rB  rD  rF  rH  rJ  rL  rN  rP  rR  rT  rV  rX  rZ  r6  r\  r^  rh  rn  rt  rw  r}  rƒ  r†  rŠ  rc  rj  r2  rr   r4  r7  r9  r;  r>  r@  rC  rE  rG  rI  rK  rM  rO  rQ  rS  rU  rW  rY  r[  r]  r_  r  rb  rc  re  r"  r   rÏ   ró  ri  rk  rm  r  rr  r	  rx  ru  r|  r‚  r„  rï  r…  r‡  r‹  re  r’  rk  r”  r¥  r•  r–  r;   r;   r;   r?   r'  `  s   ý























	













"








	

	B!r'  c                   @   r    )ÚKeyPurposeIdentifiersNrŒ  r;   r;   r;   r?   r±  É  r£   r±  c                   @   r    )ÚSequenceOfAlgorithmIdentifiersN)rV   rW   rX   r   r¢   r;   r;   r;   r?   r²  Í  r£   r²  c                	   @   sP   e Zd Zdeddifdedddœfdeddifdeddifd	ed
ddœfgZdS )ÚCertificateAuxÚtrustr¼   TÚrejectr   rº   ÚaliasÚkeyidr>   r   N)rV   rW   rX   r±  r-   r#   r²  rž   r;   r;   r;   r?   r³  Ñ  s    ûr³  c                   @   s   e Zd ZeegZdS )ÚTrustedCertificateN)rV   rW   rX   r'  r³  Ú_child_specsr;   r;   r;   r?   r¸  Û  s    r¸  )¶rÁ   Ú
__future__r   r   r   r   Ú
contextlibr   Ú	encodingsr   rd  r  r„   r  r
  r  Ú_errorsr	   Ú_irir
   r   Ú_ordereddictr   Ú_typesr   r   r   Úalgosr   r   r   r   Úcorer   r   r   r   r   r   r   r   r   r   r   r   r    r!   r"   r#   r$   r%   r&   r'   r(   r)   r*   r+   r,   r-   r.   r/   r(  r0   Úutilr1   r2   r3   r4   r5   rZ   rc   rt   r›   r¡   r¥   r¸   r¿   rÃ   rÄ   rÌ   r  r"  r>  rû   rm  rp  rw  r{  r  r‚  r„  r†  r‡  r‘  r’  r“  r”  r•  r–  rš  rœ  r�  rŸ  r¢  r£  r¨  r«  r±  rÒ  rÕ  r×  rÜ  rß  ré  rê  rí  rî  rò  rö  rù  r  r	  r
  r  r  r  r  r  r  r   r#  r&  r'  r)  r,  r-  r0  r1  r5  r‹  rŽ  r“  r–  r˜  r™  rš  r�  r§  r­  r±  r²  rµ  r¸  r¹  r¾  rÀ  rÁ  rÉ  rÍ  rÑ  rÔ  rÝ  rÞ  rß  rè  ré  rô  rõ  rö  r÷  rû  rü  r   r  r  r  r  r'  r±  r²  r³  r¸  r;   r;   r;   r?   Ú<module>   s  x59q 
  BU* D

			"2%	p			 &      o
