o
    Œõ±jËÝ ã                   @   sÎ  d dl mZmZmZmZ d dlZd dlZd dlZd dlZddl	m
ZmZmZmZmZmZmZmZmZmZmZmZmZmZmZ ddlmZmZmZmZmZm Z m!Z!m"Z"m#Z# ddl$m%Z% ddl&m'Z'm(Z(m)Z)m*Z*m+Z+m,Z,m-Z-m.Z.m/Z/m0Z0m1Z1m2Z2m3Z3m4Z4m5Z5m6Z6 ddl7m8Z8 dd	l9m:Z: dd
l;m<Z<m=Z=m>Z> ddl?m@Z@mAZAmBZBmCZC ddlDmEZEmFZFmGZGmHZHmIZImJZJ ddlKmLZL e M¡ ZNeNd  eNd fZOe8ƒ ZPePdkræddlQmRZRmSZSmTZTmUZUmVZV ddlWmXZYmZZ[m\Z\m]Z^m_Z` nddlambZbmcZcmTZTmdZdmeZe g d¢Zfg d¢ZgG dd„ dƒZhG dd„ deheƒZiG dd„ deheƒZjG dd„ deheƒZ
dydd„Zkdd „ Zldzd!d"„Zmd#d$„ Zndyd%d&„Zod'd(„ Zpd)d*„ Zqd+d,„ Zrd-d.„ Zsd/d0„ Ztd1d2„ Zud3d4„ Zvd5d6„ Zwd7d8„ Zxd9d:„ Zyd{d<d=„Zzd>d?„ Z{dzd@dA„Z|dBdC„ Z}dzdDdE„Z~dzdFdG„ZdHdI„ Z€dJdK„ Z�dLdM„ Z‚dNdO„ Z_d|dQdR„Zƒd|dSdT„Z„d|dUdV„Z…dWdX„ Z†dYdZ„ Z‡d[d\„ Zˆd]d^„ Z]d|d_d`„Z‰d|dadb„ZŠd|dcdd„Z‹d|dedf„ZŒd|dgdh„Z�d|didj„ZŽd|dkdl„Z�d|dmdn„Z�d|dodp„Z‘dqdr„ Z’dsdt„ Z“dudv„ Z”dwdx„ Z•dS )}é    )Úunicode_literalsÚdivisionÚabsolute_importÚprint_functionNé   )ÚCertificateÚDHParametersÚ	DSAParamsÚDSASignatureÚECDomainParametersÚECPrivateKeyÚIntegerÚint_from_bytesÚint_to_bytesÚPrivateKeyAlgorithmÚPrivateKeyInfoÚPublicKeyAlgorithmÚPublicKeyInfoÚRSAPrivateKeyÚRSAPublicKey)	Ú_CertificateBaseÚ_fingerprintÚ_parse_pkcs12Ú_PrivateKeyBaseÚ_PublicKeyBaseÚ_unwrap_private_key_infoÚparse_certificateÚparse_privateÚparse_public)Úpretty_message)Úbuffer_from_bytesÚbuffer_from_unicodeÚ
byte_arrayÚbytes_from_bufferÚcastÚderefÚnativeÚnewÚnullÚpointer_setÚsizeofÚstructÚstruct_bytesÚstruct_from_bufferÚunwrapÚwrite_to_buffer)Úbackend)Ú
fill_width)ÚAsymmetricKeyErrorÚIncompleteAsymmetricKeyErrorÚSignatureError)Ú	type_nameÚstr_clsÚbyte_clsÚ	int_types)Úadd_pkcs1v15_signature_paddingÚadd_pss_paddingÚraw_rsa_private_cryptÚraw_rsa_public_cryptÚ!remove_pkcs1v15_signature_paddingÚverify_pss_padding)Úconstant_compareé   Ú	winlegacy)Úadvapi32ÚAdvapi32ConstÚhandle_errorÚopen_context_handleÚclose_context_handle)Úec_generate_pairÚec_compute_public_key_pointÚec_public_key_infoÚ
ecdsa_signÚecdsa_verify)ÚbcryptÚBcryptConstrD   Úopen_alg_handleÚclose_alg_handle)r   Údsa_signÚ
dsa_verifyrJ   rK   Úgenerate_pairÚload_certificateÚload_pkcs12Úload_private_keyÚload_public_keyÚparse_pkcs12Ú
PrivateKeyÚ	PublicKeyÚrsa_oaep_decryptÚrsa_oaep_encryptÚrsa_pkcs1v15_decryptÚrsa_pkcs1v15_encryptÚrsa_pkcs1v15_signÚrsa_pkcs1v15_verifyÚrsa_pss_signÚrsa_pss_verify(   r   é   é   é   é   é   é   é   é   é   é   é%   é)   é+   é/   é5   é;   é=   éC   éG   éI   éO   éS   éY   éa   ée   ég   ék   ém   éq   é   éƒ   é‰   é‹   é•   é—   é�   é£   é§   é­   é³   éµ   é¿   éÁ   éÅ   éÇ   éÓ   éß   éã   éå   éé   éï   éñ   éû   i  i  i  i  i  i  i  i%  i3  i7  i9  i=  iK  iQ  i[  i]  ia  ig  io  iu  i{  i  i…  i�  i‘  i™  i£  i¥  i¯  i±  i·  i»  iÁ  iÉ  iÍ  iÏ  iÓ  iß  iç  ië  ió  i÷  iý  é	  i  i  i#  i-  i3  i9  i;  iA  iK  iQ  iW  iY  i_  ie  ii  ik  iw  i�  iƒ  i‡  i�  i“  i•  i¡  i¥  i«  i³  i½  iÅ  iÏ  i×  iÝ  iã  iç  iï  iõ  iù  i  i  i  i  i)  i+  i5  i7  i;  i=  iG  iU  iY  i[  i_  im  iq  is  iw  i‹  i�  i—  i¡  i©  i­  i³  i¹  iÇ  iË  iÑ  i×  iß  iå  iñ  iõ  iû  iý  i  i	  i  i  i  i%  i'  i-  i?  iC  iE  iI  iO  iU  i]  ic  ii  i  i�  i‹  i“  i�  i£  i©  i±  i½  iÁ  iÇ  iÍ  iÏ  iÕ  iá  ië  iý  iÿ  i  i	  i  i  i  i  i  i'  i)  i/  iQ  iW  i]  ie  iw  i�  i�  i“  i•  i™  iŸ  i§  i«  i­  i³  i¿  iÉ  iË  iÏ  iÑ  iÕ  iÛ  iç  ió  iû  i  i  i  i  i  i#  i+  i/  i=  iA  iG  iI  iM  iS  iU  i[  ie  iy  i  iƒ  i…  i�  i¡  i£  i­  i¹  i»  iÅ  iÍ  iÓ  iÙ  iß  iñ  i÷  iû  iý  i	  i  i  i'  i7  iE  iK  iO  iQ  iU  iW  ia  im  is  iy  i‹  i�  i�  iŸ  iµ  i»  iÃ  iÉ  iÍ  iÏ  iÓ  iÛ  iá  ië  ií  i÷  i  i  i  i!  i#  i'  i)  i3  i?  iA  iQ  iS  iY  i]  i_  ii  iq  iƒ  i›  iŸ  i¥  i­  i½  i¿  iÃ  iË  iÛ  iÝ  iá  ié  iï  iõ  iù  i	  i	  i	  i#	  i%	  i+	  i/	  i5	  iC	  iI	  iM	  iO	  iU	  iY	  i_	  ik	  iq	  iw	  i…	  i‰	  i�	  i›	  i£	  i©	  i­	  iÇ	  iÙ	  iã	  ië	  iï	  iõ	  i÷	  iý	  i
  i
  i!
  i1
  i9
  i=
  iI
  iW
  ia
  ic
  ig
  io
  iu
  i{
  i
  i�
  i…
  i‹
  i“
  i—
  i™
  iŸ
  i©
  i«
  iµ
  i½
  iÁ
  iÏ
  iÙ
  iå
  iç
  ií
  iñ
  ió
  i  i  i  i  i#  i)  i-  i?  iG  iQ  iW  i]  ie  io  i{  i‰  i�  i“  i™  i›  i·  i¹  iÃ  iË  iÏ  iÝ  iá  ié  iõ  iû  i  i  i  i%  i/  i1  iA  i[  i_  ia  im  is  iw  iƒ  i‰  i‘  i•  i�  i³  iµ  i¹  i»  iÇ  iã  iå  ië  iñ  i÷  iû  i  i  i  i  i  i!  i+  i-  i=  i?  iO  iU  ii  iy  i�  i…  i‡  i‹  i�  i£  i«  i·  i½  iÇ  iÉ  iÍ  iÓ  iÕ  iÛ  iå  iç  ió  iý  iÿ  i	  i  i  i!  i'  i/  i5  i;  iK  iW  iY  i]  ik  iq  iu  i}  i‡  i�  i•  i›  i±  i·  i¹  iÃ  iÑ  iÕ  iÛ  ií  iï  iù  i  i  i  i  i%  i)  i1  iC  iG  iM  iO  iS  iY  i[  ig  ik  i  i•  i¡  i£  i§  i­  i³  iµ  i»  iÑ  iÓ  iÙ  ié  iï  iû  iý  i  i  i  i!  i%  i+  i9  i=  i?  iQ  ii  is  iy  i{  i…  i‡  i‘  i“  i�  i£  i¥  i¯  i±  i»  iÁ  iÉ  iç  iñ  ió  iý  i  i  i  i'  i-  i9  iE  iG  iY  i_  ic  ii  io  i�  iƒ  i�  i›  i¡  i¥  i§  i«  iÃ  iÅ  iÑ  i×  iç  iï  iõ  iû  i  i  i  i#  i)  i+  i1  i7  iA  iG  iS  i_  iq  is  iy  i}  i�  i—  i¯  i³  iµ  i¹  i¿  iÁ  iÍ  iÑ  iß  iý  i  i  i  i'  i-  i7  iC  iE  iI  iO  iW  i]  ig  ii  im  i{  i�  i‡  i‹  i‘  i“  i�  iŸ  i¯  i»  iÃ  iÕ  iÙ  iß  ië  ií  ió  iù  iÿ  i  i!  i/  i3  i;  iE  iM  iY  ik  io  iq  iu  i�  i™  iŸ  i¡  i±  i·  i½  iË  iÕ  iã  iç  i  i  i  i  i  i%  i)  i+  i7  i=  iA  iC  iI  i_  ie  ig  ik  i}  i  iƒ  i�  i‘  i—  i›  iµ  i»  iÁ  iÅ  iÍ  i×  i÷  i  i	  i  i  i  i  i  i%  i3  i9  i=  iE  iO  iU  ii  im  io  iu  i“  i—  iŸ  i©  i¯  iµ  i½  iÃ  iÏ  iÓ  iÙ  iÛ  iá  iå  ië  ií  i÷  iù  i	  i  i#  i'  i3  iA  i]  ic  iw  i{  i�  i•  i›  iŸ  i¥  i³  i¹  i¿  iÉ  iË  iÕ  iá  ié  ió  iõ  iÿ  i  i  i  i5  i7  i;  iC  iI  iM  iU  ig  iq  iw  i}  i  i…  i�  i›  i�  i§  i­  i³  i¹  iÁ  iÇ  iÑ  i×  iÙ  iß  iå  ië  iõ  iý  i  i  i1  i3  iE  iI  iQ  i[  iy  i�  i“  i—  i™  i£  i©  i«  i±  iµ  iÇ  iÏ  iÛ  ií  iý  i  i  i  i  i!  i#  i-  i/  i5  i?  iM  iQ  ii  ik  i{  i}  i‡  i‰  i“  i§  i«  i­  i±  i¹  iÉ  iÏ  iÕ  i×  iã  ió  iû  iÿ  i  i#  i%  i/  i1  i7  i;  iA  iG  iO  iU  iY  ie  ik  is  i  iƒ  i‘  i�  i§  i¿  iÅ  iÑ  i×  iÙ  iï  i÷  i	  i  i  i'  i+  i-  i3  i=  iE  iK  iO  iU  is  i�  i‹  i�  i™  i£  i¥  iµ  i·  iÉ  iá  ió  iù  i	  i  i!  i#  i5  i9  i?  iA  iK  iS  i]  ic  ii  iq  iu  i{  i}  i‡  i‰  i•  i™  iŸ  i¥  i§  i³  i·  iÅ  i×  iÛ  iá  iõ  iù  i  i  i  i  i  i%  i+  i/  i=  iI  iM  iO  im  iq  i‰  i�  i•  i¡  i­  i»  iÁ  iÅ  iÇ  iË  iÝ  iã  iï  i÷  iý  i  i  i  i  i9  iI  iK  iQ  ig  iu  i{  i…  i‘  i—  i™  i�  i¥  i¯  iµ  i»  iÓ  iá  iç  ië  ió  iÿ  i   i   i   i'   i)   i-   i3   iG   iM   iQ   i_   ic   ie   ii   iw   i}   i‰   i¡   i«   i±   i¹   iÃ   iÅ   iã   iç   ií   iï   iû   iÿ   i!  i!  i5!  iA!  iI!  iO!  iY!  i[!  i_!  is!  i}!  i…!  i•!  i—!  i¡!  i¯!  i³!  iµ!  iÁ!  iÇ!  i×!  iÝ!  iå!  ié!  iñ!  iõ!  iû!  i"  i	"  i"  i"  i!"  i%"  i+"  i1"  i9"  iK"  iO"  ic"  ig"  is"  iu"  i"  i…"  i‡"  i‘"  i�"  iŸ"  i£"  i·"  i½"  iÛ"  iá"  iå"  ií"  i÷"  i#  i	#  i#  i'#  i)#  i/#  i3#  i5#  iE#  iQ#  iS#  iY#  ic#  ik#  iƒ#  i�#  i•#  i§#  i­#  i±#  i¿#  iÅ#  iÉ#  iÕ#  iÝ#  iã#  iï#  ió#  iù#  i$  i$  i$  i$  i)$  i=$  iA$  iC$  iM$  i_$  ig$  ik$  iy$  i}$  i$  i…$  i›$  i¡$  i¯$  iµ$  i»$  iÅ$  iË$  iÍ$  i×$  iÙ$  iÝ$  iß$  iõ$  i÷$  iû$  i%  i%  i%  i%  i'%  i1%  i=%  iC%  iK%  iO%  is%  i�%  i�%  i“%  i—%  i�%  iŸ%  i«%  i±%  i½%  iÍ%  iÏ%  iÙ%  iá%  i÷%  iù%  i&  i&  i&  i&  i'&  i)&  i5&  i;&  i?&  iK&  iS&  iY&  ie&  ii&  io&  i{&  i�&  iƒ&  i�&  i›&  iŸ&  i­&  i³&  iÃ&  iÉ&  iË&  iÕ&  iÝ&  iï&  iõ&  i'  i'  i5'  i7'  iM'  iS'  iU'  i_'  ik'  im'  is'  iw'  i'  i•'  i›'  i�'  i§'  i¯'  i³'  i¹'  iÁ'  iÅ'  iÑ'  iã'  iï'  i(  i(  i(  i(  i(  i(  i!(  i1(  i=(  i?(  iI(  iQ(  i[(  i](  ia(  ig(  iu(  i�(  i—(  iŸ(  i»(  i½(  iÁ(  iÕ(  iÙ(  iÛ(  iß(  ií(  i÷(  i)  i)  i)  i!)  i#)  i?)  iG)  i])  ie)  ii)  io)  iu)  iƒ)  i‡)  i�)  i›)  i¡)  i§)  i«)  i¿)  iÃ)  iÕ)  i×)  iã)  ié)  ií)  ió)  i*  i*  i*  i%*  i/*  iO*  iU*  i_*  ie*  ik*  im*  is*  iƒ*  i‰*  i‹*  i—*  i�*  i¹*  i»*  iÅ*  iÍ*  iÝ*  iã*  ië*  iñ*  iû*  i+  i'+  i1+  i3+  i=+  i?+  iK+  iO+  iU+  ii+  im+  io+  i{+  i�+  i—+  i™+  i£+  i¥+  i©+  i½+  iÍ+  iç+  ië+  ió+  iù+  iý+  i	,  i,  i,  i#,  i/,  i5,  i9,  iA,  iW,  iY,  ii,  iw,  i�,  i‡,  i“,  iŸ,  i­,  i³,  i·,  iË,  iÏ,  iÛ,  iá,  iã,  ié,  iï,  iÿ,  i-  i-  i-  i;-  iC-  iI-  iM-  ia-  ie-  iq-  i‰-  i�-  i¡-  i©-  i³-  iµ-  iÅ-  iÇ-  iÓ-  iß-  i.  i.  i.  i.  i.  i.  i%.  i-.  i3.  i7.  i9.  i?.  iW.  i[.  io.  iy.  i.  i….  i“.  i—.  i�.  i£.  i¥.  i±.  i·.  iÁ.  iÃ.  iÍ.  iÓ.  iç.  ië.  i/  i	/  i/  i/  i'/  i)/  iA/  iE/  iK/  iM/  iQ/  iW/  io/  iu/  i}/  i�/  iƒ/  i¥/  i«/  i³/  iÃ/  iÏ/  iÑ/  iÛ/  iÝ/  iç/  ií/  iõ/  iù/  i0  i0  i#0  i)0  i70  i;0  iU0  iY0  i[0  ig0  iq0  iy0  i}0  i…0  i‘0  i•0  i£0  i©0  i¹0  i¿0  iÇ0  iË0  iÑ0  i×0  iß0  iå0  iï0  iû0  iý0  i1  i	1  i1  i!1  i'1  i-1  i91  iC1  iE1  iK1  i]1  ia1  ig1  im1  is1  i1  i‘1  i™1  iŸ1  i©1  i±1  iÃ1  iÇ1  iÕ1  iÛ1  ií1  i÷1  iÿ1  i	2  i2  i2  i2  i)2  i52  iY2  i]2  ic2  ik2  io2  iu2  iw2  i{2  i�2  i™2  iŸ2  i§2  i­2  i³2  i·2  iÉ2  iË2  iÏ2  iÑ2  ié2  ií2  ió2  iù2  i3  i%3  i+3  i/3  i53  iA3  iG3  i[3  i_3  ig3  ik3  is3  iy3  i3  iƒ3  i¡3  i£3  i­3  i¹3  iÁ3  iË3  iÓ3  ië3  iñ3  iý3  i4  i4  i4  i4  i4  i74  iE4  iU4  iW4  ic4  ii4  im4  i�4  i‹4  i‘4  i—4  i�4  i¥4  i¯4  i»4  iÉ4  iÓ4  iá4  iñ4  iÿ4  i	5  i5  i5  i-5  i35  i;5  iA5  iQ5  ie5  io5  iq5  iw5  i{5  i}5  i�5  i�5  i�5  i™5  i›5  i¡5  i·5  i½5  i¿5  iÃ5  iÕ5  iÝ5  iç5  iï5  i6  i6  i6  i#6  i16  i56  i76  i;6  iM6  iO6  iS6  iY6  ia6  ik6  im6  i‹6  i�6  i­6  i¯6  i¹6  i»6  iÍ6  iÑ6  iã6  ié6  i÷6  i7  i7  i7  i7  i?7  iE7  iI7  iO7  i]7  ia7  iu7  i7  i�7  i£7  i©7  i«7  iÉ7  iÕ7  iß7  iñ7  ió7  i÷7  i8  i8  i!8  i38  i58  iA8  iG8  iK8  iS8  iW8  i_8  ie8  io8  iq8  i}8  i�8  i™8  i§8  i·8  iÅ8  iÉ8  iÏ8  iÕ8  i×8  iÝ8  iá8  iã8  iÿ8  i9  i9  i#9  i%9  i)9  i/9  i=9  iA9  iM9  i[9  ik9  iy9  i}9  iƒ9  i‹9  i‘9  i•9  i›9  i¡9  i§9  i¯9  i³9  i»9  i¿9  iÍ9  iÝ9  iå9  ië9  iï9  iû9  i:  i:  i:  i:  i':  i+:  i1:  iK:  iQ:  i[:  ic:  ig:  im:  iy:  i‡:  i¥:  i©:  i·:  iÍ:  iÕ:  iá:  iå:  ië:  ió:  iý:  i;  i;  i;  i!;  i#;  i-;  i9;  iE;  iS;  iY;  i_;  iq;  i{;  i�;  i‰;  i›;  iŸ;  i¥;  i§;  i­;  i·;  i¹;  iÃ;  iË;  iÑ;  i×;  iá;  iã;  iõ;  iÿ;  i<  i<  i<  i<  i<  i)<  i5<  iC<  iO<  iS<  i[<  ie<  ik<  iq<  i…<  i‰<  i—<  i§<  iµ<  i¿<  iÇ<  iÑ<  iÝ<  iß<  iñ<  i÷<  i=  i=  i=  i=  i=  i!=  i-=  i3=  i7=  i?=  iC=  io=  is=  iu=  iy=  i{=  i…=  i‘=  i—=  i�=  i«=  i¯=  iµ=  i»=  iÁ=  iÉ=  iÏ=  ió=  i>  i	>  i>  i>  i>  i#>  i)>  i/>  i3>  iA>  iW>  ic>  ie>  iw>  i�>  i‡>  i¡>  i¹>  i½>  i¿>  iÃ>  iÅ>  iÉ>  i×>  iÛ>  iá>  iç>  iï>  iÿ>  i?  i?  i7?  i;?  i=?  iA?  iY?  i_?  ie?  ig?  iy?  i}?  i‹?  i‘?  i­?  i¿?  iÍ?  iÓ?  iÝ?  ié?  ië?  iñ?  iý?  i@  i!@  i%@  i+@  i1@  i?@  iC@  iE@  i]@  ia@  ig@  im@  i‡@  i‘@  i£@  i©@  i±@  i·@  i½@  iÛ@  iß@  ië@  i÷@  iù@  i	A  iA  iA  iA  i!A  i3A  i5A  i;A  i?A  iYA  ieA  ikA  iwA  i{A  i“A  i«A  i·A  i½A  i¿A  iËA  içA  iïA  ióA  iùA  iB  iB  iB  iB  i#B  i)B  i/B  iCB  iSB  iUB  i[B  iaB  isB  i}B  iƒB  i…B  i‰B  i‘B  i—B  i�B  iµB  iÅB  iËB  iÓB  iÝB  iãB  iñB  iC  iC  iC  i%C  i'C  i3C  i7C  i9C  iOC  iWC  iiC  i‹C  i�C  i“C  i¥C  i©C  i¯C  iµC  i½C  iÇC  iÏC  iáC  içC  iëC  iíC  iñC  iùC  i	D  iD  iD  i#D  i)D  i;D  i?D  iED  iKD  iQD  iSD  iYD  ieD  ioD  iƒD  i�D  i¡D  i¥D  i«D  i­D  i½D  i¿D  iÉD  i×D  iÛD  iùD  iûD  iE  iE  iE  i+E  i1E  iAE  iIE  iSE  iUE  iaE  iwE  i}E  iE  i�E  i£E  i­E  i¯E  i»E  iÇE  c                   @   s,   e Zd ZdZdZdZdZdd„ Zdd„ ZdS )Ú_WinKeyNc                 C   s(   || _ || _tdkrt| _dS t| _dS )zö
        :param key_handle:
            A CNG BCRYPT_KEY_HANDLE value (Vista and newer) or an HCRYPTKEY
            (XP and 2003) from loading/importing the key

        :param asn1:
            An asn1crypto object for the concrete type
        rA   N)Ú
key_handleÚasn1Ú_backendrB   Ú_librL   ©Úselfr™   rš   © rŸ   ú‹/root/aizidognhua/tmp/workspace/projects/ec89d86c-575f-41c9-af57-ac45cbdbf775/venv/lib/python3.10/site-packages/oscrypto/_win/asymmetric.pyÚ__init__‚  s
   


z_WinKey.__init__c                 C   sb   | j rtdkr| j | j ¡}n| j | j ¡}t|ƒ d | _ | jr,tdkr,t| jƒ d | _d | _d S )NrA   )r™   r›   rœ   ÚCryptDestroyKeyÚBCryptDestroyKeyrD   Úcontext_handlerF   )rž   ÚresrŸ   rŸ   r    Ú__del__”  s   

z_WinKey.__del__)	Ú__name__Ú
__module__Ú__qualname__r™   r¤   Úex_key_handlerœ   r¡   r¦   rŸ   rŸ   rŸ   r    r˜   v  s    r˜   c                   @   s4   e Zd ZdZdZdd„ Zedd„ ƒZedd„ ƒZdS )	rX   zM
    Container for the OS crypto library representation of a private key
    Nc                 C   ó   t  | ||¡ dS )zô
        :param key_handle:
            A CNG BCRYPT_KEY_HANDLE value (Vista and newer) or an HCRYPTKEY
            (XP and 2003) from loading/importing the key

        :param asn1:
            An asn1crypto.keys.PrivateKeyInfo object
        N©r˜   r¡   r�   rŸ   rŸ   r    r¡   ©  ó   
zPrivateKey.__init__c                 C   s  t dkrn| jdkrt| jƒ}tdt|| jƒƒ| _| jS | jdkrL| jd d }tt	d|dœƒt
t|d j| jd	 jj|d
 jƒƒdœƒ}t|ƒ| _| jS | jd	 j}tt	ddiƒt|d |d dœƒdœƒ}t|ƒ| _| jS t| j| j| jƒ\}}t|ƒ| _| jS )z\
        :return:
            A PublicKey object corresponding to this private key.
        rA   ÚecNÚdsaÚprivate_key_algorithmÚ
parameters©Ú	algorithmr±   ÚgÚprivate_keyÚp©r³   Ú
public_keyr³   ÚrsaÚmodulusÚpublic_exponent©rº   r»   )r›   r³   Ú(_pure_python_ec_compute_public_key_pointrš   rY   rI   ÚcurveÚ_public_keyr   r   r   Úpowr&   ÚparsedrV   r   Ú_bcrypt_key_handle_to_asn1Úbit_sizer™   )rž   Ú	pub_pointÚparamsÚpub_asn1rÁ   Ú_rŸ   rŸ   r    r¸   µ  sF   

%
Üþýû
òÿþü
	þ
zPrivateKey.public_keyc                 C   s   | j du rt | jtƒ| _ | j S )aY  
        Creates a fingerprint that can be compared with a public key to see if
        the two form a pair.

        This fingerprint is not compatible with fingerprints generated by any
        other software.

        :return:
            A byte string that is a sha256 hash of selected components (based
            on the key type)
        N)r   rš   rU   ©rž   rŸ   rŸ   r    Úfingerprintæ  s   
zPrivateKey.fingerprint)	r§   r¨   r©   Ú__doc__r¿   r¡   Úpropertyr¸   rÉ   rŸ   rŸ   rŸ   r    rX   ¢  s    
0rX   c                   @   s   e Zd ZdZdd„ ZdS )rY   zL
    Container for the OS crypto library representation of a public key
    c                 C   r«   )zó
        :param key_handle:
            A CNG BCRYPT_KEY_HANDLE value (Vista and newer) or an HCRYPTKEY
            (XP and 2003) from loading/importing the key

        :param asn1:
            An asn1crypto.keys.PublicKeyInfo object
        Nr¬   r�   rŸ   rŸ   r    r¡   þ  r­   zPublicKey.__init__N)r§   r¨   r©   rÊ   r¡   rŸ   rŸ   rŸ   r    rY   ù  s    rY   c                   @   s8   e Zd ZdZdZdZdd„ Zedd„ ƒZedd„ ƒZ	dS )	r   zM
    Container for the OS crypto library representation of a certificate
    Nc                 C   r«   )zù
        :param key_handle:
            A CNG BCRYPT_KEY_HANDLE value (Vista and newer) or an HCRYPTKEY
            (XP and 2003) from loading/importing the certificate

        :param asn1:
            An asn1crypto.x509.Certificate object
        Nr¬   r�   rŸ   rŸ   r    r¡     r­   zCertificate.__init__c                 C   s$   | j du rt| jd d ƒ| _ | j S )zh
        :return:
            The PublicKey object for the public key this certificate contains
        NÚtbs_certificateÚsubject_public_key_info)r¿   rV   rš   rÈ   rŸ   rŸ   r    r¸     s   
zCertificate.public_keyc                 C   sÎ   | j du rdd| _ | jjtddgƒv rd| jd j}| jd j}|dkr%t}n|dkr,t}n|dkr3t}n|d	kr:t	}nt
td
|ƒƒ‚z|| | jd j| jd  ¡ |ƒ d| _ W | j S  tyc   Y | j S w | j S )zT
        :return:
            A boolean - if the certificate is self-signed
        NFÚyesÚmaybeÚsignature_algorithmÚrsassa_pkcs1v15Ú
rsassa_pssr¯   Úecdsaz¦
                        Unable to verify the signature of the certificate since
                        it uses the unsupported algorithm %s
                        Úsignature_valuerÌ   T)Ú_self_signedrš   Úself_signedÚsetÚsignature_algoÚ	hash_algor_   ra   rQ   rK   ÚOSErrorr   r&   Údumpr4   )rž   rØ   rÙ   Úverify_funcrŸ   rŸ   r    rÖ   *  s>   
û
üýýzCertificate.self_signed)
r§   r¨   r©   rÊ   r¿   rÕ   r¡   rË   r¸   rÖ   rŸ   rŸ   rŸ   r    r     s    

r   c                 C   s  | t g d¢ƒvrttdt| ƒƒƒ‚| dkr'|t g d¢ƒvr&ttdt|ƒƒƒ‚nA| dkrStdk s3tdkrA|d	kr@ttd
t|ƒƒƒ‚n'|t g d¢ƒvrRttdt|ƒƒƒ‚n| dkrh|t g d¢ƒvrhttdt|ƒƒƒ‚tdkr…| dkr€t|ƒ\}}td|ƒtd|ƒfS t	| |ƒS t
| ||ƒS )aB  
    Generates a public/private key pair

    :param algorithm:
        The key algorithm - "rsa", "dsa" or "ec"

    :param bit_size:
        An integer - used for "rsa" and "dsa". For "rsa" the value maye be 1024,
        2048, 3072 or 4096. For "dsa" the value may be 1024, plus 2048 or 3072
        if on Windows 8 or newer.

    :param curve:
        A unicode string - used for "ec" keys. Valid values include "secp256r1",
        "secp384r1" and "secp521r1".

    :raises:
        ValueError - when any of the parameters contain an invalid value
        TypeError - when any of the parameters are of the wrong type
        OSError - when an error is returned by the OS crypto library

    :return:
        A 2-element tuple of (PublicKey, PrivateKey). The contents of each key
        may be saved by calling .asn1.dump().
    )r¹   r¯   r®   zM
            algorithm must be one of "rsa", "dsa", "ec", not %s
            r¹   )é   é   é   é   zX
                bit_size must be one of 1024, 2048, 3072, 4096, not %s
                r¯   ©é   r   rA   rÝ   zG
                    bit_size must be 1024, not %s
                    )rÝ   rÞ   rß   zZ
                    bit_size must be one of 1024, 2048, 3072, not %s
                    r®   ©Ú	secp256r1Ú	secp384r1Ú	secp521r1zd
                curve must be one of "secp256r1", "secp384r1", "secp521r1", not %s
                N)r×   Ú
ValueErrorr   ÚreprÚ_win_version_infor›   Ú_pure_python_ec_generate_pairrY   rX   Ú_advapi32_generate_pairÚ_bcrypt_generate_pair)r³   rÃ   r¾   Úpub_infoÚ	priv_inforŸ   rŸ   r    rR   W  sL   üüÿüÿüÿü
rR   c                 C   sD  | dkrd}nd}t tdƒ}t |tƒ tjdtƒ |¡}t|ƒ t|ƒ}t|ƒ}t |tƒ tjd||¡}t|ƒ t	t||ƒ}t
|ƒ}	tt|	ƒ}
t||ƒ|
d… }| dkr_t||	|ƒ\}}||fS t tdƒ}t |tƒ tjdtƒ |¡}t|ƒ t|ƒ}t|ƒ}t |tƒ tjd||¡}t|ƒ t||ƒ|
d… }t|||ƒ\}}||fS )ao  
    Accepts an key handle and exports it to ASN.1

    :param algorithm:
        The key algorithm - "rsa" or "dsa"

    :param bit_size:
        An integer - only used when algorithm is "rsa"

    :param key_handle:
        The handle to export

    :return:
        A 2-element tuple of asn1crypto.keys.PrivateKeyInfo and
        asn1crypto.keys.PublicKeyInfo
    r¹   ÚRSABLOBHEADERÚDSSBLOBHEADERúDWORD *r   N)r'   rB   ÚCryptExportKeyr(   rC   ÚPRIVATEKEYBLOBrD   r%   r    r-   r.   r*   r#   Ú _advapi32_interpret_rsa_key_blobÚPUBLICKEYBLOBÚ _advapi32_interpret_dsa_key_blob)r³   rÃ   r™   Ústruct_typeÚout_lenr¥   Úbuffer_lengthÚbuffer_Úblob_struct_pointerÚblob_structÚstruct_sizeÚprivate_blobÚpublic_infoÚprivate_infoÚpublic_out_lenÚpublic_buffer_lengthÚpublic_bufferÚpublic_blobrŸ   rŸ   r    Ú_advapi32_key_handle_to_asn1§  sn   
úú
 
åúúr  c              	   C   sÌ   | dkrt j}t j}nt j}t j}d}d}zAt|dd�}ttdƒ}|d> t jB }t 	||||¡}t
|ƒ t|ƒ}t| ||ƒ\}	}
t|	ƒt|
ƒfW |rNt|ƒ |rVt |¡ S S |r]t|ƒ |ret |¡ w w )a�  
    Generates a public/private key pair using CryptoAPI

    :param algorithm:
        The key algorithm - "rsa" or "dsa"

    :param bit_size:
        An integer - used for "rsa" and "dsa". For "rsa" the value maye be 1024,
        2048, 3072 or 4096. For "dsa" the value may be 1024.

    :raises:
        ValueError - when any of the parameters contain an invalid value
        TypeError - when any of the parameters are of the wrong type
        OSError - when an error is returned by the OS crypto library

    :return:
        A 2-element tuple of (PublicKey, PrivateKey). The contents of each key
        may be saved by calling .asn1.dump().
    r¹   NF©Úverify_onlyúHCRYPTKEY *é   )rC   ÚMS_ENH_RSA_AES_PROVÚCALG_RSA_SIGNÚMS_ENH_DSS_DH_PROVÚCALG_DSS_SIGNrE   r'   rB   ÚCRYPT_EXPORTABLEÚCryptGenKeyrD   r.   r  rV   rU   rF   r¢   )r³   rÃ   ÚproviderÚalgorithm_idr¤   r™   Úkey_handle_pointerÚflagsr¥   rÿ   r   rŸ   rŸ   r    rë   ÿ  s4   
ÿþÿrë   c              	   C   s,  | dkrd}t j}t j}n| dkr!|dkrd}nd}t j}t j}nd}t j}t j}ttdƒ}t 	|t
ƒ |t
ƒ d	|d	¡}t|ƒ t|ƒ}t|ƒ}	t 	|t
ƒ ||	||d	¡}t|ƒ tt||	ƒ}
t|
ƒ}tt|ƒ}t|	|ƒ|d
… }| dkrztd||ƒ}n| dkr’|dkrŠtdd||ƒ}ntdd||ƒ}ntd||ƒ}ttdƒ}t 	|t
ƒ |t
ƒ d	|d	¡}t|ƒ t|ƒ}t|ƒ}t 	|t
ƒ ||||d	¡}t|ƒ tt||ƒ}t|ƒ}tt|ƒ}t||ƒ|d
… }| dkrìtd||ƒ}||fS | dk�r|dk�rtdd||ƒ}||fS tdd||ƒ}||fS td||ƒ}||fS )au  
    Accepts an key handle and exports it to ASN.1

    :param algorithm:
        The key algorithm - "rsa", "dsa" or "ec"

    :param bit_size:
        An integer - only used when algorithm is "dsa"

    :param key_handle:
        The handle to export

    :return:
        A 2-element tuple of asn1crypto.keys.PrivateKeyInfo and
        asn1crypto.keys.PublicKeyInfo
    r¹   ÚBCRYPT_RSAKEY_BLOBr¯   rÝ   ÚBCRYPT_DSA_KEY_BLOB_V2ÚBCRYPT_DSA_KEY_BLOBÚBCRYPT_ECCKEY_BLOBúULONG *r   NÚprivater   r@   Úpublic)rM   ÚBCRYPT_RSAFULLPRIVATE_BLOBÚBCRYPT_RSAPUBLIC_BLOBÚBCRYPT_DSA_PRIVATE_BLOBÚBCRYPT_DSA_PUBLIC_BLOBÚBCRYPT_ECCPRIVATE_BLOBÚBCRYPT_ECCPUBLIC_BLOBr'   rL   ÚBCryptExportKeyr(   rD   r%   r    r-   r.   r*   r#   Ú_bcrypt_interpret_rsa_key_blobÚ_bcrypt_interpret_dsa_key_blobÚ_bcrypt_interpret_ec_key_blob)r³   rÃ   r™   r÷   Úprivate_blob_typeÚpublic_blob_typeÚprivate_out_lenr¥   Úprivate_buffer_lengthÚprivate_bufferÚprivate_blob_struct_pointerÚprivate_blob_structrý   rþ   rµ   r  r  r  Úpublic_blob_struct_pointerÚpublic_blob_structr  r¸   rŸ   rŸ   r    rÂ   3  sŠ   
ù	

ù	
	
ø
üþrÂ   c           
   	   C   sÖ   | dkrt j}n| dkrt j}nt jt jt jdœ| }ddddœ| }d}z4t|ƒ}ttdƒ}t 	|||d	¡}t
|ƒ t|ƒ}t |d	¡}t
|ƒ t| ||ƒ\}}	W |rYt |¡ n	|rbt |¡ w w t|ƒt|	ƒfS )
aL  
    Generates a public/private key pair using CNG

    :param algorithm:
        The key algorithm - "rsa", "dsa" or "ec"

    :param bit_size:
        An integer - used for "rsa" and "dsa". For "rsa" the value maye be 1024,
        2048, 3072 or 4096. For "dsa" the value may be 1024, plus 2048 or 3072
        if on Windows 8 or newer.

    :param curve:
        A unicode string - used for "ec" keys. Valid values include "secp256r1",
        "secp384r1" and "secp521r1".

    :raises:
        ValueError - when any of the parameters contain an invalid value
        TypeError - when any of the parameters are of the wrong type
        OSError - when an error is returned by the OS crypto library

    :return:
        A 2-element tuple of (PublicKey, PrivateKey). The contents of each key
        may be saved by calling .asn1.dump().
    r¹   r¯   rã   é   i€  r—   NúBCRYPT_KEY_HANDLE *r   )rM   ÚBCRYPT_RSA_ALGORITHMÚBCRYPT_DSA_ALGORITHMÚBCRYPT_ECDSA_P256_ALGORITHMÚBCRYPT_ECDSA_P384_ALGORITHMÚBCRYPT_ECDSA_P521_ALGORITHMrN   r'   rL   ÚBCryptGenerateKeyPairrD   r.   ÚBCryptFinalizeKeyPairrÂ   r£   rV   rU   )
r³   rÃ   r¾   Úalg_constantr™   Ú
alg_handler  r¥   r¸   rµ   rŸ   rŸ   r    rì   ˜  sB   ýüýü

€ÿÿrì   c                 C   st  t | tƒsttdt| ƒƒƒ‚| dk rtdƒ‚| dkrtdƒ‚| d dkr(tdƒ‚d	}d
}z…| d }tdkr>ttj	ƒ}t
|ƒ}	 tdkrIt |¡}nt |||d¡}t|ƒ t|ƒ}t|ƒ}|d
 dkrdq>|d
krp|d dkroq>n|dkr�|d }|dkr�|dkr�q>d}	tD ]}
||
 dkr‘d}	 nq…|	s±t| |ƒr±|d
 }t| |ƒr±t||dœƒW |r°t|ƒ S S q?|r¹t|ƒ w w )a`  
    Generates DH parameters for use with Diffie-Hellman key exchange. Returns
    a structure in the format of DHParameter defined in PKCS#3, which is also
    used by the OpenSSL dhparam tool.

    THIS CAN BE VERY TIME CONSUMING!

    :param bit_size:
        The integer bit size of the parameters to generate. Must be between 512
        and 4096, and divisible by 64. Recommended secure value as of early 2016
        is 2048, with an absolute minimum of 1024.

    :raises:
        ValueError - when any of the parameters contain an invalid value
        TypeError - when any of the parameters are of the wrong type
        OSError - when an error is returned by the OS crypto library

    :return:
        An asn1crypto.algos.DHParameters object. Use
        oscrypto.asymmetric.dump_dh_parameters() to save to disk for usage with
        web servers.
    z=
            bit_size must be an integer, not %s
            i   z-bit_size must be greater than or equal to 512rà   z+bit_size must be less than or equal to 4096é@   r   z!bit_size must be a multiple of 64Nr   é   ÚwinTrA   é   re   rc   é
   rb   rd   F)r¶   r´   )Ú
isinstancer8   Ú	TypeErrorr   r5   rç   r›   rN   rM   ÚBCRYPT_RNG_ALGORITHMr    ÚosÚurandomrL   ÚBCryptGenRandomrD   r#   r   Ú_SMALL_PRIMESÚ	_is_primer   rO   )rÃ   r8  r´   Ú	byte_sizeÚbufferÚrbr¥   r¶   ÚremÚ	divisibleÚprimeÚqrŸ   rŸ   r    Úgenerate_dh_parametersØ  sh   
ü	
ÿþ

ÿÚ&
ÿrM  c                 C   sð   d}|d }|d dkr|d7 }|d }|d dks| dkr!d}n| dkr(d}n| dkr/d}n| d	kr6d
}n| dkr<d}t |ƒD ]5}t d|d ¡}t|||ƒ}|dksZ||d kr[q@t |d ƒD ]}t|d|ƒ}||d krq nqa dS q@dS )u÷   
    An implementation of Millerâ€“Rabin for checking if a number is prime.

    :param bit_size:
        An integer of the number of bits in the prime number

    :param n:
        An integer, the prime number

    :return:
        A boolean
    r   r@   r   i  iR  rb   iŠ  é   i&  rc   iÂ  râ   FT)ÚrangeÚrandomÚ	randrangerÀ   )rÃ   ÚnÚrÚsÚkrÇ   ÚaÚxrŸ   rŸ   r    rE  <  s:   þÿþrE  c                 C   sZ  | d }| d }|}|| }|| }|| }|| }	|	| }
|j j}t|d|… ddd… ƒ}t|||… ddd… ƒ}t|||… ddd… ƒ}t|||… ddd… ƒ}t|||	… ddd… ƒ}t||	|
… ddd… ƒ}t||
|
| … ddd… ƒ}ttddiƒt||dœƒd	œƒ}td
||||||||dœ	ƒ}tdtddiƒ|dœƒ}||fS )aÉ  
    Takes a CryptoAPI RSA private key blob and converts it into the ASN.1
    structures for the public and private keys

    :param bit_size:
        The integer bit size of the key

    :param blob_struct:
        An instance of the advapi32.RSAPUBKEY struct

    :param blob:
        A byte string of the binary data after the header

    :return:
        A 2-element tuple of (asn1crypto.keys.PublicKeyInfo,
        asn1crypto.keys.PrivateKeyInfo)
    r:  r	  r   Néÿÿÿÿr³   r¹   r¼   r·   ú	two-prime©	Úversionrº   r»   Úprivate_exponentÚprime1Úprime2Ú	exponent1Ú	exponent2Úcoefficient©r[  r°   rµ   )	Ú	rsapubkeyÚpubexpr   r   r   r   r   r   r   )rÃ   rü   ÚblobÚlen1Úlen2Úprime1_offsetÚprime2_offsetÚexponent1_offsetÚexponent2_offsetÚcoefficient_offsetÚprivate_exponent_offsetr»   rº   r]  r^  r_  r`  ra  r\  Úpublic_key_infoÚrsa_private_keyÚprivate_key_inforŸ   rŸ   r    rô   j  sX   ÿþü
÷ÿûrô   c              	   C   s  d}| d }|}|| }|| }|}t |d|… ddd… ƒ}	t |||… ddd… ƒ}
t |||… ddd… ƒ}t |||| … ddd… ƒ}t |||| … ddd… ƒ}ttdt|	|
|dœƒdœƒt|ƒd	œƒ}tdtdt|	|
|dœƒdœƒt|ƒd
œƒ}||fS )aí  
    Takes a CryptoAPI DSS private key blob and converts it into the ASN.1
    structures for the public and private keys

    :param bit_size:
        The integer bit size of the key

    :param public_blob:
        A byte string of the binary data after the public key header

    :param private_blob:
        A byte string of the binary data after the private key header

    :return:
        A 2-element tuple of (asn1crypto.keys.PublicKeyInfo,
        asn1crypto.keys.PrivateKeyInfo)
    é   r:  r   NrX  r¯   ©r¶   rL  r´   r²   r·   rb  )r   r   r   r	   r   r   r   )rÃ   r  rþ   rf  rg  Úq_offsetÚg_offsetÚx_offsetÚy_offsetr¶   rL  r´   rW  Úyrn  rp  rŸ   rŸ   r    rö   ±  sF   ýþ÷ýþörö   c                 C   sb  t t|jƒ}t t|jƒ}|}t|d|… ƒ}t|||| … ƒ}| dkr4ttddiƒt||dœƒdœƒS | dkr¨t t|jƒ}t t|j	ƒ}	|| }
|
| }||	 }||	 }||	 }|| }t||
|… ƒ}t|||… ƒ}t|||… ƒ}t|||… ƒ}t|||… ƒ}t|||| … ƒ}t
d||||||||d	œ	ƒ}tdtddiƒ|d
œƒS ttdt| ƒƒƒ‚)aÁ  
    Take a CNG BCRYPT_RSAFULLPRIVATE_BLOB and converts it into an ASN.1
    structure

    :param key_type:
        A unicode string of "private" or "public"

    :param blob_struct:
        An instance of BCRYPT_RSAKEY_BLOB

    :param blob:
        A byte string of the binary data contained after the struct

    :return:
        An asn1crypto.keys.PrivateKeyInfo or asn1crypto.keys.PublicKeyInfo
        object, based on the key_type param
    r   r  r³   r¹   r¼   r·   r  rY  rZ  rb  úM
            key_type must be one of "public", "private", not %s
            )r&   ÚintÚcbPublicExpÚ	cbModulusr   r   r   r   ÚcbPrime1ÚcbPrime2r   r   r   rç   r   rè   )Úkey_typerü   re  Úpublic_exponent_byte_lengthÚmodulus_byte_lengthÚmodulus_offsetr»   rº   Úprime1_byte_lengthÚprime2_byte_lengthrh  ri  rj  rk  rl  rm  r]  r^  r_  r`  ra  r\  ro  rŸ   rŸ   r    r"  î  sh   ÿþü
÷ÿû	ür"  c              	   C   sx  t t|jƒ}|dkr-tt t|jƒƒ}|}|| }|| }t|d|… ƒ}	t|||… ƒ}
nC|dkrht t|jƒ}t t|jƒ}|}|| }|| }|| }|| }t|||… ƒ}t|||… ƒ}	t|||… ƒ}
ntdt	|ƒ ƒ‚| dkr�t|||… ƒ}t
tdt|	||
dœƒdœƒt|ƒd	œƒS | d
kr³t|||| … ƒ}tdtdt|	||
dœƒdœƒt|ƒdœƒS ttdt	| ƒƒƒ‚)an  
    Take a CNG BCRYPT_DSA_KEY_BLOB or BCRYPT_DSA_KEY_BLOB_V2 and converts it
    into an ASN.1 structure

    :param key_type:
        A unicode string of "private" or "public"

    :param version:
        An integer - 1 or 2, indicating the blob is BCRYPT_DSA_KEY_BLOB or
        BCRYPT_DSA_KEY_BLOB_V2

    :param blob_struct:
        An instance of BCRYPT_DSA_KEY_BLOB or BCRYPT_DSA_KEY_BLOB_V2

    :param blob:
        A byte string of the binary data contained after the struct

    :return:
        An asn1crypto.keys.PrivateKeyInfo or asn1crypto.keys.PublicKeyInfo
        object, based on the key_type param
    r@   r   r   zversion must be 1 or 2, not %sr  r¯   rr  r²   r·   r  rb  rx  )r&   ry  ÚcbKeyr   r7   rL  ÚcbSeedLengthÚcbGroupSizerç   rè   r   r   r	   r   r   r   r   )r~  r[  rü   re  Úkey_byte_lengthrL  rt  Úpublic_offsetÚprivate_offsetr¶   r´   Úseed_byte_lengthÚgroup_byte_lengthrs  Úp_offsetr  r  rŸ   rŸ   r    r#  C  sf   ýþ÷ýþöür#  c                 C   sà   t t|jƒ}t t|jƒ}tjdtjdtjdtjdtj	dtj
di| }d|d|d …  }| dkr@ttdtd	|d
�dœƒ|dœƒS | dkrgt||d |d … ƒ}tdtdtd	|d
�dœƒtd||dœƒdœƒS ttdt| ƒƒƒ‚)aµ  
    Take a CNG BCRYPT_ECCKEY_BLOB and converts it into an ASN.1 structure

    :param key_type:
        A unicode string of "private" or "public"

    :param blob_struct:
        An instance of BCRYPT_ECCKEY_BLOB

    :param blob:
        A byte string of the binary data contained after the struct

    :return:
        An asn1crypto.keys.PrivateKeyInfo or asn1crypto.keys.PublicKeyInfo
        object, based on the key_type param
    rä   rå   ræ   ó   r   r   r  r®   Únamed)ÚnameÚvaluer²   r·   r  rb   ÚecPrivkeyVer1)r[  rµ   r¸   rb  rx  )r&   ry  ÚdwMagicr„  rM   ÚBCRYPT_ECDSA_PRIVATE_P256_MAGICÚBCRYPT_ECDSA_PRIVATE_P384_MAGICÚBCRYPT_ECDSA_PRIVATE_P521_MAGICÚBCRYPT_ECDSA_PUBLIC_P256_MAGICÚBCRYPT_ECDSA_PUBLIC_P384_MAGICÚBCRYPT_ECDSA_PUBLIC_P521_MAGICr   r   r   r   r   r   r   rç   r   rè   )r~  rü   re  Úmagicr‡  r¾   r  r  rŸ   rŸ   r    r$  ž  sX   úù	þþøþþý÷ür$  c                 C   s‚   t | tƒr| }n4t | tƒrt| ƒ}n*t | tƒr3t| dƒ�}t| ¡ ƒ}W d  ƒ n1 s-w   Y  n	ttdt	| ƒƒƒ‚t
|tƒS )a¡  
    Loads an x509 certificate into a Certificate object

    :param source:
        A byte string of file contents or a unicode string filename

    :raises:
        ValueError - when any of the parameters contain an invalid value
        TypeError - when any of the parameters are of the wrong type
        OSError - when an error is returned by the OS crypto library

    :return:
        A Certificate object
    rH  Nz€
            source must be a byte string, unicode string or
            asn1crypto.x509.Certificate object, not %s
            )r>  ÚAsn1Certificater7   r   r6   ÚopenÚreadr?  r   r5   Ú	_load_keyr   )ÚsourceÚcertificateÚfrŸ   rŸ   r    rS   å  s   



ÿ€û
rS   c                 C   s  | }t | tƒr| d d }|j}d}|dkr4|j\}}|dkr%ttdƒƒ‚|tg d¢ƒvr3ttdƒƒ‚n8|d	krl|jdu rCttd
ƒƒ‚|j	dkr\t
dk sPtdkr\ttd|j ¡ |j	ƒƒ‚|j	dkrl|jdkrlttdƒƒ‚tdkr|dkry|d| ƒS t| ||ƒS t| |||ƒS )aê  
    Loads a certificate, public key or private key into a Certificate,
    PublicKey or PrivateKey object

    :param key_object:
        An asn1crypto.x509.Certificate, asn1crypto.keys.PublicKeyInfo or
        asn1crypto.keys.PrivateKeyInfo object

    :param container:
        The class of the object to hold the key_handle

    :raises:
        ValueError - when any of the parameters contain an invalid value
        TypeError - when any of the parameters are of the wrong type
        oscrypto.errors.AsymmetricKeyError - when the key is incompatible with the OS crypto library
        OSError - when an error is returned by the OS crypto library

    :return:
        A PrivateKey, PublicKey or Certificate object, based on container
    rÌ   rÍ   Nr®   rŽ  zR
                Windows only supports EC keys using named curves
                rã   z‰
                Windows only supports EC keys using the named curves
                secp256r1, secp384r1 and secp521r1
                r¯   z†
                The DSA key does not contain the necessary p, q and g
                parameters and can not be used
                rÝ   rá   rA   zÍ
                Windows XP, 2003, Vista, 7 and Server 2008 only support DSA
                keys based on SHA1 (1024 bits or less) - this key is based
                on %s and is %s bits
                rÞ   Úsha1a  
                Windows only supports 2048 bit DSA keys based on SHA2 - this
                key is 2048 bits and based on SHA1, a non-standard
                combination that is usually generated by old versions
                of OpenSSL
                )r>  rš  r³   r¾   r2   r   r×   rÙ   r3   rÃ   ré   r›   ÚupperÚ_advapi32_load_keyÚ_bcrypt_load_key)Ú
key_objectÚ	containerÚkey_infoÚalgoÚ
curve_nameÚ
curve_typerŸ   rŸ   r    r�    sH   

ÿÿÿ
ÿù	ÿ	
r�  c                 C   s:  t |tƒrdnd}|j}|dkrd}|dks|dkrtj}ntj}d}d}zbt||dkd�}t|||ƒ}t|ƒ}	t	t
dƒ}
t
 ||	t|ƒtƒ d|
¡}t|ƒ t|
ƒ}||| ƒ}||_|dkr…t|||d	d
�}t|ƒ}t	t
dƒ}t
 ||t|ƒtƒ d|¡}t|ƒ t|ƒ|_|W S  tyœ   |r•t
 |¡ |r›t|ƒ ‚ w )ah  
    Loads a certificate, public key or private key into a Certificate,
    PublicKey or PrivateKey object via CryptoAPI

    :param key_object:
        An asn1crypto.x509.Certificate, asn1crypto.keys.PublicKeyInfo or
        asn1crypto.keys.PrivateKeyInfo object

    :param key_info:
        An asn1crypto.keys.PublicKeyInfo or asn1crypto.keys.PrivateKeyInfo
        object

    :param container:
        The class of the object to hold the key_handle

    :raises:
        ValueError - when any of the parameters contain an invalid value
        TypeError - when any of the parameters are of the wrong type
        oscrypto.errors.AsymmetricKeyError - when the key is incompatible with the OS crypto library
        OSError - when an error is returned by the OS crypto library

    :return:
        A PrivateKey, PublicKey or Certificate object, based on container
    r  r  rÒ   r¹   Nr  r  r   F)Úsigning)r>  r   r³   rC   r
  r  rE   Ú_advapi32_create_blobr    r'   rB   ÚCryptImportKeyÚlenr(   rD   r.   r¤   rª   Ú	Exceptionr¢   rF   )r¥  r§  r¦  r~  r¨  r  r¤   r™   re  rú   r  r¥   ÚoutputÚex_blobÚ	ex_bufferÚex_key_handle_pointerrŸ   rŸ   r    r£  [  s`   
ú

ú

ûr£  Tc                 C   s<  |dkrt j}nt j}|dkrd}|rt j}n	t j}nd}t j}ttdƒ}t|ƒ}||_	t j
|_d|_||_tt|ƒ}	t|	ƒ}
||
_| j}|d }|d }|dk�r	ttd	ƒ}t|ƒ}||_|dkr�| d
 j}t j|_|d j|_t|d jd|d�ddd… }n„| d j}t j|_|d j|_t|d jd|d�ddd… }|t|d jd|d�ddd… 7 }|t|d jd|d�ddd… 7 }|t|d jd|d�ddd… 7 }|t|d jd|d�ddd… 7 }|t|d jd|d�ddd… 7 }|t|d jd|d�ddd… 7 }||
_n�ttdƒ}t|ƒ}||_|dk�r6t j|_| d d j}t| d
 jjd|d�ddd… }nt j|_| d d j}t| d jjddd�ddd… }||
_t|d d|d�ddd… }|t|d ddd�ddd… 7 }|t|d d|d�ddd… 7 }||7 }ttd ƒ}t|ƒ}d!|_|t|ƒ7 }t|	ƒ| S )"aâ  
    Generates a blob for importing a key to CryptoAPI

    :param key_info:
        An asn1crypto.keys.PublicKeyInfo or asn1crypto.keys.PrivateKeyInfo
        object

    :param key_type:
        A unicode string of "public" or "private"

    :param algo:
        A unicode string of "rsa" or "dsa"

    :param signing:
        If the key handle is for signing - may only be False for rsa keys

    :return:
        A byte string of a blob to pass to advapi32.CryptImportKey()
    r  r¹   rï   rð   Ú
BLOBHEADERr   r:  r	  Ú	RSAPUBKEYr¸   r»   rº   F)ÚsignedÚwidthNrX  rµ   r]  r^  r_  r`  ra  r\  Ú	DSSPUBKEYr³   r±   r°   rq  r¶   rL  r´   ÚDSSSEEDl   ÿÿ )rC   rõ   ró   r  ÚCALG_RSA_KEYXr  r+   rB   r.   ÚbTypeÚCUR_BLOB_VERSIONÚbVersionÚreservedÚaiKeyAlgÚpublickeystrucrÃ   ÚbitlenrÁ   ÚRSA1r™  r&   rd  r   ÚRSA2rc  ÚDSS1ÚDSS2Ú	dsspubkeyÚcounterr,   )r§  r~  r¨  r«  Ú	blob_typer÷   r  Úblob_header_pointerÚblob_headerrû   rü   rÃ   rf  rg  Úpubkey_pointerÚpubkeyÚparsed_key_infoÚ	blob_datarÅ   Úkey_dataÚdssseed_pointerÚdssseedrŸ   rŸ   r    r¬  ²  s|   




 
""""""

"   
r¬  c           +   	   C   sl  d}d}t |tƒrdnd}|j}|dkrd}�z•|dkr!|jd n|}tjtjtjtjtj	dœ| }	t
|	ƒ}|dkrë|dkrNtj}
tj}|d	 j}d
}d
}n=tj}
tj}|d j}t|d jƒ}t|d jƒ}t|d jƒ}t|d jƒ}t|d jƒ}t|d jƒ}t|ƒ}t|ƒ}t|d jƒ}t|d jƒ}ttdƒ}t|ƒ}||_|j|_t|ƒ|_t|ƒ|_||_||_t|ƒ| | }|dkré||| 7 }|t||ƒ7 }|t||ƒ7 }|t||ƒ7 }|t|t|ƒƒ7 }�n˜|dk�rû|dk�rtj}
|d	 jj}|d d }ntj }
t!|ƒd	 j}t|d jjƒ}|d d }t|ƒ}t|d jƒ}t|d jƒ}t|d jƒ} |jdk�rAt| ƒ}!nd}!t"t|ƒt|ƒt|ƒƒ}"t||"ƒ}t||"ƒ}t||"ƒ}t| |!ƒ} d}#d|! }$|jdk�rº|dk�rxtj#}ntj$}ttd ƒ}t|ƒ}||_%|"|_&tj'|_(tj)|_*|!|_+|!|_,t-|#ƒ|_.t|ƒ}||$|  | | | 7 }|dk�r¹|t||!ƒ7 }nÉ|dk�rÃtj/}ntj0}ttd!ƒ}t|ƒ}||_%|"|_&t-|#ƒ|_.t-|$ƒ|_1t-| ƒ|_2t|ƒ| | | }|dk�rú|t||!ƒ7 }nˆ|dk�rƒ|dk�rtj3}
|d	  4¡ \}%}&n"tj5}
|d jd	 }|�r%| 4¡ \}%}&nd
}%d
}&t|d jd jƒ}ttd"ƒ}t|ƒ}tj6tj7tj8tj9tj:tj;d#œ||f }d$d%d&d'œ| }"t|%ƒ}'t|&ƒ}(t|'|"ƒ}'t|(|"ƒ}(||_%|"|_&t|ƒ|' |( }|dk�rƒ|t||"ƒ7 }t<td(ƒ})t =|t>ƒ |
|)|t|ƒtj?¡}*t@|*ƒ t|)ƒ}||| ƒW |�r¬tA|ƒ S S |�rµtA|ƒ w w ))a»  
    Loads a certificate, public key or private key into a Certificate,
    PublicKey or PrivateKey object via CNG

    :param key_object:
        An asn1crypto.x509.Certificate, asn1crypto.keys.PublicKeyInfo or
        asn1crypto.keys.PrivateKeyInfo object

    :param key_info:
        An asn1crypto.keys.PublicKeyInfo or asn1crypto.keys.PrivateKeyInfo
        object

    :param container:
        The class of the object to hold the key_handle

    :param curve_name:
        None or a unicode string of the curve name for an EC key

    :raises:
        ValueError - when any of the parameters contain an invalid value
        TypeError - when any of the parameters are of the wrong type
        oscrypto.errors.AsymmetricKeyError - when the key is incompatible with the OS crypto library
        OSError - when an error is returned by the OS crypto library

    :return:
        A PrivateKey, PublicKey or Certificate object, based on container
    Nr  r  rÒ   r¹   r®   r@   )r¹   r¯   rä   rå   ræ   r¸   r   rµ   r]  r^  r_  r`  ra  r\  r»   rº   r  r¯   r³   r±   r°   r¶   r´   rL  rÝ   rq  s   ÿÿÿÿó   ÿr  r  r  ))r  rä   )r  rå   )r  ræ   )r  rä   )r  rå   )r  ræ   é    é0   éB   rã   r/  )Br>  r   r³   r¾   rM   r0  r1  r2  r3  r4  rN   r  ÚBCRYPT_RSAPUBLIC_MAGICrÁ   r  ÚBCRYPT_RSAFULLPRIVATE_MAGICr   r&   r®  r+   rL   r.   ÚMagicrÃ   Ú	BitLengthrz  r{  r|  r}  r,   r1   r  r  r   ÚmaxÚBCRYPT_DSA_PUBLIC_MAGIC_V2ÚBCRYPT_DSA_PRIVATE_MAGIC_V2r’  r„  ÚDSA_HASH_ALGORITHM_SHA256ÚhashAlgorithmÚDSA_FIPS186_3ÚstandardVersionr…  r†  r"   ÚCountÚBCRYPT_DSA_PUBLIC_MAGICÚBCRYPT_DSA_PRIVATE_MAGICÚSeedrL  r   Ú	to_coordsr  r–  r—  r˜  r“  r”  r•  r'   ÚBCryptImportKeyPairr(   ÚBCRYPT_NO_KEY_VALIDATIONrD   rO   )+r¥  r§  r¦  r©  r8  r™   r~  r¨  Úalg_selectorr7  rÈ  r™  Ú
parsed_keyÚprime1_sizeÚprime2_sizer]  r^  r_  r`  ra  r\  r»   rº   rû   rü   re  r¸   rÅ   Úprivate_bytesÚpublic_bytesr¶   r´   rL  Úq_lenÚ	key_widthÚcountÚseedrW  rw  Úx_bytesÚy_bytesr  r¥   rŸ   rŸ   r    r¤    sF  ûú




€










€





€


úù
ýü



ù	

ÿ
ÿr¤  c                 C   s¶   t | tƒr| }nN|dur$t |tƒr| d¡}t |tƒs$ttdt|ƒƒƒ‚t | tƒrCt| dƒ�}| 	¡ } W d  ƒ n1 s=w   Y  nt | tƒsQttdt| ƒƒƒ‚t
| |ƒ}t|tƒS )a   
    Loads a private key into a PrivateKey object

    :param source:
        A byte string of file contents, a unicode string filename or an
        asn1crypto.keys.PrivateKeyInfo object

    :param password:
        A byte or unicode string to decrypt the private key file. Unicode
        strings will be encoded using UTF-8. Not used is the source is a
        PrivateKeyInfo object.

    :raises:
        ValueError - when any of the parameters contain an invalid value
        TypeError - when any of the parameters are of the wrong type
        oscrypto.errors.AsymmetricKeyError - when the private key is incompatible with the OS crypto library
        OSError - when an error is returned by the OS crypto library

    :return:
        A PrivateKey object
    Núutf-8zP
                    password must be a byte string, not %s
                    rH  z�
                source must be a byte string, unicode string or
                asn1crypto.keys.PrivateKeyInfo object, not %s
                )r>  r   r6   Úencoder7   r?  r   r5   r›  rœ  r   r�  rX   )rž  ÚpasswordÚprivate_objectr   rŸ   rŸ   r    rU     s,   



ü

ÿ€
û

rU   c                 C   s‚   t | tƒr| }n4t | tƒrt| ƒ}n*t | tƒr3t| dƒ�}t| ¡ ƒ}W d  ƒ n1 s-w   Y  n	ttdt	|ƒƒƒ‚t
|tƒS )a3  
    Loads a public key into a PublicKey object

    :param source:
        A byte string of file contents, a unicode string filename or an
        asn1crypto.keys.PublicKeyInfo object

    :raises:
        ValueError - when any of the parameters contain an invalid value
        TypeError - when any of the parameters are of the wrong type
        oscrypto.errors.AsymmetricKeyError - when the public key is incompatible with the OS crypto library
        OSError - when an error is returned by the OS crypto library

    :return:
        A PublicKey object
    rH  Nz‚
            source must be a byte string, unicode string or
            asn1crypto.keys.PublicKeyInfo object, not %s
            )r>  r   r7   r   r6   r›  rœ  r?  r   r5   r�  rY   )rž  r¸   r   rŸ   rŸ   r    rV   9  s   



ÿ€û
rV   c                 C   s   t | |tƒS )aÍ  
    Parses a PKCS#12 ANS.1 DER-encoded structure and extracts certs and keys

    :param data:
        A byte string of a DER-encoded PKCS#12 file

    :param password:
        A byte string of the password to any encrypted data

    :raises:
        ValueError - when any of the parameters are of the wrong type or value
        OSError - when an error is returned by one of the OS decryption functions

    :return:
        A three-element tuple of:
         1. An asn1crypto.keys.PrivateKeyInfo object
         2. An asn1crypto.x509.Certificate object
         3. A list of zero or more asn1crypto.x509.Certificate objects that are
            "extra" certificates, possibly intermediates from the cert chain
    )r   rU   )Údatarö  rŸ   rŸ   r    rW   a  s   rW   c           	      C   sà   |durt |tƒr| d¡}t |tƒsttdt|ƒƒƒ‚t | tƒr;t| dƒ�}| ¡ } W d  ƒ n1 s5w   Y  nt | tƒsIttdt| ƒƒƒ‚t	| |ƒ\}}}d}d}|r\t
|tƒ}|rdt
|jtƒ}dd„ |D ƒ}|||fS )aø  
    Loads a .p12 or .pfx file into a PrivateKey object and one or more
    Certificates objects

    :param source:
        A byte string of file contents or a unicode string filename

    :param password:
        A byte or unicode string to decrypt the PKCS12 file. Unicode strings
        will be encoded using UTF-8.

    :raises:
        ValueError - when any of the parameters contain an invalid value
        TypeError - when any of the parameters are of the wrong type
        oscrypto.errors.AsymmetricKeyError - when a contained key is incompatible with the OS crypto library
        OSError - when an error is returned by the OS crypto library

    :return:
        A three-element tuple containing (PrivateKey, Certificate, [Certificate, ...])
    Nrô  zH
                password must be a byte string, not %s
                rH  zR
            source must be a byte string or a unicode string, not %s
            c                 S   s   g | ]}t |jtƒ‘qS rŸ   )r�  r¸   r   )Ú.0ÚinforŸ   rŸ   r    Ú
<listcomp>²  s    zload_pkcs12.<locals>.<listcomp>)r>  r6   rõ  r7   r?  r   r5   r›  rœ  rW   r�  rX   r¸   r   )	rž  rö  r   r§  Ú	cert_infoÚextra_certs_infoÚkeyÚcertÚextra_certsrŸ   rŸ   r    rT   z  s6   


ü

ÿ€
ü

rT   c                 C   ó    | j dkr	tdƒ‚t| |||ƒS )aÖ  
    Verifies an RSASSA-PKCS-v1.5 signature.

    When the hash_algorithm is "raw", the operation is identical to RSA
    public key decryption. That is: the data is not hashed and no ASN.1
    structure with an algorithm identifier of the hash algorithm is placed in
    the encrypted byte string.

    :param certificate_or_public_key:
        A Certificate or PublicKey instance to verify the signature with

    :param signature:
        A byte string of the signature to verify

    :param data:
        A byte string of the data the signature is for

    :param hash_algorithm:
        A unicode string of "md5", "sha1", "sha256", "sha384", "sha512" or "raw"

    :raises:
        oscrypto.errors.SignatureError - when the signature is determined to be invalid
        ValueError - when any of the parameters contain an invalid value
        TypeError - when any of the parameters are of the wrong type
        OSError - when an error is returned by the OS crypto library
    r¹   ú*The key specified is not an RSA public key©r³   rç   Ú_verify©Úcertificate_or_public_keyÚ	signaturerø  Úhash_algorithmrŸ   rŸ   r    r_   ·  s   
r_   c                 C   s0   | j }|dkr|dkrtdƒ‚t| |||dd�S )a¯  
    Verifies an RSASSA-PSS signature. For the PSS padding the mask gen algorithm
    will be mgf1 using the same hash algorithm as the signature. The salt length
    with be the length of the hash algorithm, and the trailer field with be the
    standard 0xBC byte.

    :param certificate_or_public_key:
        A Certificate or PublicKey instance to verify the signature with

    :param signature:
        A byte string of the signature to verify

    :param data:
        A byte string of the data the signature is for

    :param hash_algorithm:
        A unicode string of "md5", "sha1", "sha256", "sha384" or "sha512"

    :raises:
        oscrypto.errors.SignatureError - when the signature is determined to be invalid
        ValueError - when any of the parameters contain an invalid value
        TypeError - when any of the parameters are of the wrong type
        OSError - when an error is returned by the OS crypto library
    r¹   rÒ   r  T©Úrsa_pss_paddingr  )r  r  rø  r  Úcp_algrŸ   rŸ   r    ra   Ù  s   ra   c                 C   r  )aÂ  
    Verifies a DSA signature

    :param certificate_or_public_key:
        A Certificate or PublicKey instance to verify the signature with

    :param signature:
        A byte string of the signature to verify

    :param data:
        A byte string of the data the signature is for

    :param hash_algorithm:
        A unicode string of "md5", "sha1", "sha256", "sha384" or "sha512"

    :raises:
        oscrypto.errors.SignatureError - when the signature is determined to be invalid
        ValueError - when any of the parameters contain an invalid value
        TypeError - when any of the parameters are of the wrong type
        OSError - when an error is returned by the OS crypto library
    r¯   z)The key specified is not a DSA public keyr  r  rŸ   rŸ   r    rQ   û  ó   
rQ   c                 C   r  )aÅ  
    Verifies an ECDSA signature

    :param certificate_or_public_key:
        A Certificate or PublicKey instance to verify the signature with

    :param signature:
        A byte string of the signature to verify

    :param data:
        A byte string of the data the signature is for

    :param hash_algorithm:
        A unicode string of "md5", "sha1", "sha256", "sha384" or "sha512"

    :raises:
        oscrypto.errors.SignatureError - when the signature is determined to be invalid
        ValueError - when any of the parameters contain an invalid value
        TypeError - when any of the parameters are of the wrong type
        OSError - when an error is returned by the OS crypto library
    r®   z)The key specified is not an EC public keyr  r  rŸ   rŸ   r    rK   	  r  rK   Fc           	      C   sN  t | ttfƒsttdt| ƒƒƒ‚t |tƒsttdt|ƒƒƒ‚t |tƒs,ttdt|ƒƒƒ‚| j}|dkp6|dk}tg d¢ƒ}|rH|sH|tdgƒO }||vr`d}|rV|sV|d	7 }t	td
|t
|ƒƒƒ‚|so|durot	td| ¡ ƒƒ‚|dkr‡t|ƒ| jd kr‡t	td| jt|ƒƒƒ‚tdkrŸ| jdkr—t| |||ƒS t| ||||ƒS t| ||||ƒS )a(  
    Verifies an RSA, DSA or ECDSA signature

    :param certificate_or_public_key:
        A Certificate or PublicKey instance to verify the signature with

    :param signature:
        A byte string of the signature to verify

    :param data:
        A byte string of the data the signature is for

    :param hash_algorithm:
        A unicode string of "md5", "sha1", "sha256", "sha384", "sha512" or "raw"

    :param rsa_pss_padding:
        If PSS padding should be used for RSA keys

    :raises:
        oscrypto.errors.SignatureError - when the signature is determined to be invalid
        ValueError - when any of the parameters contain an invalid value
        TypeError - when any of the parameters are of the wrong type
        OSError - when an error is returned by the OS crypto library
    ú�
            certificate_or_public_key must be an instance of the Certificate or
            PublicKey class, not %s
            zA
            signature must be a byte string, not %s
            ú<
            data must be a byte string, not %s
            r¹   rÒ   ©Úmd5r¡  Úsha256Úsha384Úsha512Úrawú+"md5", "sha1", "sha256", "sha384", "sha512"ú, "raw"úB
            hash_algorithm must be one of %s, not %s
            Fúu
            PSS padding may only be used with RSA keys - signing via a %s key
            was requested
            re   zÀ
                data must be 11 bytes shorter than the key size when
                hash_algorithm is "raw" - key size is %s bytes, but
                data is %s bytes long
                rA   r®   )r>  r   rY   r?  r   r5   r7   r³   r×   rç   rè   r¢  r®  rF  r›   Ú_pure_python_ecdsa_verifyÚ_advapi32_verifyÚ_bcrypt_verify)	r  r  rø  r  r
  r  Ú	cp_is_rsaÚvalid_hash_algorithmsÚvalid_hash_algorithms_errorrŸ   rŸ   r    r  5	  s\   û
ü
üûûù

r  c              
   C   sÚ  | j }|dkp
|dk}|r1|r1ddddddœ |d	¡}t| |ƒ}| j}	t|||	||ƒs/td
ƒ‚dS |rY|dkrYt| |ƒ}
zt| j|
ƒ}t||ƒsKt	ƒ ‚W dS  t	yX   td
ƒ‚w d}zˆt
jt
jt
jt
jt
jdœ| }ttdƒ}t | j|tƒ d	|¡}t|ƒ t|ƒ}t ||t|ƒd	¡}t|ƒ |dkr¿zt |¡ ¡ }t|ƒd }||d… |d|…  }W n t	ttfy¾   td
ƒ‚w |ddd… }t ||t|ƒ| jtƒ d	¡}t|ƒ W |rât  |¡ dS dS |rìt  |¡ w w )a6  
    Verifies an RSA, DSA or ECDSA signature via CryptoAPI

    :param certificate_or_public_key:
        A Certificate or PublicKey instance to verify the signature with

    :param signature:
        A byte string of the signature to verify

    :param data:
        A byte string of the data the signature is for

    :param hash_algorithm:
        A unicode string of "md5", "sha1", "sha256", "sha384", "sha512" or "raw"

    :param rsa_pss_padding:
        If PSS padding should be used for RSA keys

    :raises:
        oscrypto.errors.SignatureError - when the signature is determined to be invalid
        ValueError - when any of the parameters contain an invalid value
        TypeError - when any of the parameters are of the wrong type
        OSError - when an error is returned by the OS crypto library
    r¹   rÒ   rq  é   rÓ  rÔ  r9  ©r¡  Úsha224r  r  r  r   úSignature is invalidNr  r  úHCRYPTHASH *r¯   r   rX  )!r³   Úgetr<   rÃ   r>   r4   r=   rF  r?   rç   rC   ÚCALG_MD5Ú	CALG_SHA1ÚCALG_SHA_256ÚCALG_SHA_384ÚCALG_SHA_512r'   rB   ÚCryptCreateHashr¤   r(   rD   r.   ÚCryptHashDatar®  r
   ÚloadÚto_p1363ÚOverflowErrorr?  ÚCryptVerifySignatureWr™   ÚCryptDestroyHash)r  r  rø  r  r
  r¨  Úalgo_is_rsaÚhash_lengthÚdecrypted_signatureÚkey_sizeÚpadded_plaintextÚ	plaintextÚhash_handleÚalg_idÚhash_handle_pointerr¥   Úhalf_lenÚreversed_signaturerŸ   rŸ   r    r  —	  s�   ûú


ÿþÿûú
ûÿú
ÿÿr  c              
   C   sn  |dkr|}nt jt jt jt jt jdœ| }tt|ƒ|ƒ ¡ }t	ƒ }d}| j
}	|	dkp.|	dk}
|
rw|rPt j}ttdƒ}t|ƒ}t|ƒ}ttd|ƒ|_t|ƒ|_n t j}ttdƒ}t|ƒ}|dkret	ƒ |_nt|ƒ}ttd|ƒ|_ttd	|ƒ}nz	t |¡ ¡ }W n tttfyŽ   td
ƒ‚w t | j||t|ƒ|t|ƒ|¡}|t jk}|pª|t jk}|r±td
ƒ‚t |ƒ dS )a0  
    Verifies an RSA, DSA or ECDSA signature via CNG

    :param certificate_or_public_key:
        A Certificate or PublicKey instance to verify the signature with

    :param signature:
        A byte string of the signature to verify

    :param data:
        A byte string of the data the signature is for

    :param hash_algorithm:
        A unicode string of "md5", "sha1", "sha256", "sha384", "sha512" or "raw"

    :param rsa_pss_padding:
        If PSS padding should be used for RSA keys

    :raises:
        oscrypto.errors.SignatureError - when the signature is determined to be invalid
        ValueError - when any of the parameters contain an invalid value
        TypeError - when any of the parameters are of the wrong type
        OSError - when an error is returned by the OS crypto library
    r  r  r   r¹   rÒ   ÚBCRYPT_PSS_PADDING_INFOú	wchar_t *ÚBCRYPT_PKCS1_PADDING_INFOúvoid *r"  N)!rM   ÚBCRYPT_MD5_ALGORITHMÚBCRYPT_SHA1_ALGORITHMÚBCRYPT_SHA256_ALGORITHMÚBCRYPT_SHA384_ALGORITHMÚBCRYPT_SHA512_ALGORITHMÚgetattrÚhashlibÚdigestr(   r³   ÚBCRYPT_PAD_PSSr+   rL   r.   r!   r$   ÚpszAlgIdr®  ÚcbSaltÚBCRYPT_PAD_PKCS1r
   r,  r-  rç   r.  r?  r4   ÚBCryptVerifySignaturer™   ÚSTATUS_INVALID_SIGNATUREÚSTATUS_INVALID_PARAMETERrD   )r  r  rø  r  r
  rG  Úhash_constantÚpadding_infor  r  r  Úpadding_info_struct_pointerÚpadding_info_structÚhash_bufferr¥   ÚfailurerŸ   rŸ   r    r  
  sd   ûú


ÿù
	r  c                 C   ó   | j dkr	tdƒ‚t| ||ƒS )aL  
    Generates an RSASSA-PKCS-v1.5 signature.

    When the hash_algorithm is "raw", the operation is identical to RSA
    private key encryption. That is: the data is not hashed and no ASN.1
    structure with an algorithm identifier of the hash algorithm is placed in
    the encrypted byte string.

    :param private_key:
        The PrivateKey to generate the signature with

    :param data:
        A byte string of the data the signature is for

    :param hash_algorithm:
        A unicode string of "md5", "sha1", "sha256", "sha384", "sha512" or "raw"

    :raises:
        ValueError - when any of the parameters contain an invalid value
        TypeError - when any of the parameters are of the wrong type
        OSError - when an error is returned by the OS crypto library

    :return:
        A byte string of the signature
    r¹   ú+The key specified is not an RSA private key©r³   rç   Ú_sign©rµ   rø  r  rŸ   rŸ   r    r^   ^
  s   
r^   c                 C   s.   | j }|dkr|dkrtdƒ‚t| ||dd�S )a$  
    Generates an RSASSA-PSS signature. For the PSS padding the mask gen
    algorithm will be mgf1 using the same hash algorithm as the signature. The
    salt length with be the length of the hash algorithm, and the trailer field
    with be the standard 0xBC byte.

    :param private_key:
        The PrivateKey to generate the signature with

    :param data:
        A byte string of the data the signature is for

    :param hash_algorithm:
        A unicode string of "md5", "sha1", "sha256", "sha384" or "sha512"

    :raises:
        ValueError - when any of the parameters contain an invalid value
        TypeError - when any of the parameters are of the wrong type
        OSError - when an error is returned by the OS crypto library

    :return:
        A byte string of the signature
    r¹   rÒ   rV  Tr	  rW  )rµ   rø  r  Úpkey_algrŸ   rŸ   r    r`   
  s   r`   c                 C   rU  )a7  
    Generates a DSA signature

    :param private_key:
        The PrivateKey to generate the signature with

    :param data:
        A byte string of the data the signature is for

    :param hash_algorithm:
        A unicode string of "md5", "sha1", "sha256", "sha384" or "sha512"

    :raises:
        ValueError - when any of the parameters contain an invalid value
        TypeError - when any of the parameters are of the wrong type
        OSError - when an error is returned by the OS crypto library

    :return:
        A byte string of the signature
    r¯   z*The key specified is not a DSA private keyrW  rY  rŸ   rŸ   r    rP    
  ó   
rP   c                 C   rU  )a:  
    Generates an ECDSA signature

    :param private_key:
        The PrivateKey to generate the signature with

    :param data:
        A byte string of the data the signature is for

    :param hash_algorithm:
        A unicode string of "md5", "sha1", "sha256", "sha384" or "sha512"

    :raises:
        ValueError - when any of the parameters contain an invalid value
        TypeError - when any of the parameters are of the wrong type
        OSError - when an error is returned by the OS crypto library

    :return:
        A byte string of the signature
    r®   z*The key specified is not an EC private keyrW  rY  rŸ   rŸ   r    rJ   ¼
  r[  rJ   c                 C   s.  t | tƒsttdt| ƒƒƒ‚t |tƒsttdt|ƒƒƒ‚| j}|dkp&|dk}tg d¢ƒ}| jdkr;|s;|tdgƒO }||vrSd}|rI|sI|d7 }ttd	|t	|ƒƒƒ‚|sb|d
urbttd| 
¡ ƒƒ‚|dkrzt|ƒ| jd krzttd| jt|ƒƒƒ‚tdkr�| jdkr‰t| ||ƒS t| |||ƒS t| |||ƒS )a�  
    Generates an RSA, DSA or ECDSA signature

    :param private_key:
        The PrivateKey to generate the signature with

    :param data:
        A byte string of the data the signature is for

    :param hash_algorithm:
        A unicode string of "md5", "sha1", "sha256", "sha384", "sha512" or "raw"

    :param rsa_pss_padding:
        If PSS padding should be used for RSA keys

    :raises:
        ValueError - when any of the parameters contain an invalid value
        TypeError - when any of the parameters are of the wrong type
        OSError - when an error is returned by the OS crypto library

    :return:
        A byte string of the signature
    zO
            private_key must be an instance of PrivateKey, not %s
            r  r¹   rÒ   r  r  r  r  r  Fr  re   zÀ
                data must be 11 bytes shorter than the key size when
                hash_algorithm is "raw" - key size is %s bytes, but data
                is %s bytes long
                rA   r®   )r>  rX   r?  r   r5   r7   r³   r×   rç   rè   r¢  r®  rF  r›   Ú_pure_python_ecdsa_signÚ_advapi32_signÚ_bcrypt_sign)rµ   rø  r  r
  rZ  Úpkey_is_rsar  r  rŸ   rŸ   r    rX  Ø
  sR   
ü
üûûù

rX  c              	   C   sÚ  | j }|dkp
|dk}|r|dkrt| j|ƒ}t| |ƒS |r9|r9dddddd	œ |d
¡}t||| j|ƒ}t| |ƒS | j dkrH|dkrHttdƒƒ‚d}z™t	j
t	jt	jt	jt	jdœ| }	ttdƒ}
t | j|	tƒ d
|
¡}t|ƒ t|
ƒ}t ||t|ƒd
¡}t|ƒ ttdƒ}t |t	jtƒ d
tƒ |¡}t|ƒ t|ƒ}t|ƒ}t |t	jtƒ d
||¡}t|ƒ t|t|ƒƒ}|ddd… }|dkrÙt|ƒd }||d… |d|…  }t |¡ ¡ }|W |rãt  |¡ S S |rìt  |¡ w w )a«  
    Generates an RSA, DSA or ECDSA signature via CryptoAPI

    :param private_key:
        The PrivateKey to generate the signature with

    :param data:
        A byte string of the data the signature is for

    :param hash_algorithm:
        A unicode string of "md5", "sha1", "sha256", "sha384", "sha512" or "raw"

    :param rsa_pss_padding:
        If PSS padding should be used for RSA keys

    :raises:
        ValueError - when any of the parameters contain an invalid value
        TypeError - when any of the parameters are of the wrong type
        OSError - when an error is returned by the OS crypto library

    :return:
        A byte string of the signature
    r¹   rÒ   r  rq  r  rÓ  rÔ  r9  r   r   r¯   r  zO
            Windows does not support md5 signatures with DSA keys
            Nr  r#  rñ   rX  r   )!r³   r9   rF  r;   r$  r:   rÃ   rç   r   rC   r%  r&  r'  r(  r)  r'   rB   r*  r¤   r(   rD   r.   r+  r®  ÚCryptSignHashWÚAT_SIGNATUREr%   r    r#   r
   Ú
from_p1363rÛ   r0  )rµ   rø  r  r
  r¨  r1  Úpadded_datar2  r7  r8  r9  r¥   rø   rù   rú   r°  r:  rŸ   rŸ   r    r]  0  s–   
ûú
ÿûú
û
úúÿÿr]  c              
   C   sÆ  |dkr|}nt jt jt jt jt jdœ| }tt|ƒ|ƒ ¡ }t	ƒ }d}| j
}|dkp.|dk}	|	r~|rXdddd	d
dœ| }
t j}ttdƒ}t|ƒ}t|ƒ}ttd|ƒ|_|
|_n t j}ttdƒ}t|ƒ}|dkrmt	ƒ |_nt|ƒ}ttd|ƒ|_ttd|ƒ}|dkr•| jdkr•|tddgƒv r•ttdƒƒ‚ttdƒ}t | j||t|ƒt	ƒ d||¡}t|ƒ t|ƒ}t|ƒ}|	r¾ttd|ƒ}t | j||t|ƒ||||¡}t|ƒ t|t|ƒƒ}|	sát  !|¡ "¡ }|S )a¥  
    Generates an RSA, DSA or ECDSA signature via CNG

    :param private_key:
        The PrivateKey to generate the signature with

    :param data:
        A byte string of the data the signature is for

    :param hash_algorithm:
        A unicode string of "md5", "sha1", "sha256", "sha384", "sha512" or "raw"

    :param rsa_pss_padding:
        If PSS padding should be used for RSA keys

    :raises:
        ValueError - when any of the parameters contain an invalid value
        TypeError - when any of the parameters are of the wrong type
        OSError - when an error is returned by the OS crypto library

    :return:
        A byte string of the signature
    r  r  r   r¹   rÒ   r	  rq  rÓ  rÔ  r9  r<  r=  r>  r?  r¯   rÝ   r  r¡  z~
            Windows does not support sha1 signatures with DSA keys based on
            sha224, sha256 or sha512
            rñ   )#rM   r@  rA  rB  rC  rD  rE  rF  rG  r(   r³   rH  r+   rL   r.   r!   r$   rI  rJ  rK  rÃ   r×   rç   r   r'   ÚBCryptSignHashr™   r®  rD   r%   r    r#   r
   rb  rÛ   )rµ   rø  r  r
  rG  rO  rP  r  rZ  r_  r2  rQ  rR  rS  rø   r¥   Ú
buffer_lenrG  r  rŸ   rŸ   r    r^  ª  s”   ûúûú


"ÿ
ø
ø
r^  c                 C   sx   t | ttfƒsttdt| ƒƒƒ‚t |tƒsttdt|ƒƒƒ‚t |tƒs,ttdt|ƒƒƒ‚tdkr6t	| ||ƒS t
| ||ƒS )aG  
    Encrypts a value using an RSA public key

    :param certificate_or_public_key:
        A Certificate or PublicKey instance to encrypt with

    :param data:
        A byte string of the data to encrypt

    :param rsa_oaep_padding:
        If OAEP padding should be used instead of PKCS#1 v1.5

    :raises:
        ValueError - when any of the parameters contain an invalid value
        TypeError - when any of the parameters are of the wrong type
        OSError - when an error is returned by the OS crypto library

    :return:
        A byte string of the ciphertext
    r  r  úA
            rsa_oaep_padding must be a bool, not %s
            rA   )r>  r   rY   r?  r   r5   r7   Úboolr›   Ú_advapi32_encryptÚ_bcrypt_encrypt)r  rø  Úrsa_oaep_paddingrŸ   rŸ   r    Ú_encrypt#  s$   û
ü
ürk  c              	   C   s¤   d}|rt j}ttdt|ƒƒ}t | jtƒ d|tƒ |d¡}t|ƒ t	|ƒ}t
|ƒ}t||ƒ t|t|ƒƒ t | jtƒ d||||¡}t|ƒ t|t	|ƒƒddd… S )aU  
    Encrypts a value using an RSA public key via CryptoAPI

    :param certificate_or_public_key:
        A Certificate or PublicKey instance to encrypt with

    :param data:
        A byte string of the data to encrypt

    :param rsa_oaep_padding:
        If OAEP padding should be used instead of PKCS#1 v1.5

    :raises:
        ValueError - when any of the parameters contain an invalid value
        TypeError - when any of the parameters are of the wrong type
        OSError - when an error is returned by the OS crypto library

    :return:
        A byte string of the ciphertext
    r   rñ   TNrX  )rC   Ú
CRYPT_OAEPr'   rB   r®  ÚCryptEncryptrª   r(   rD   r%   r    r/   r)   r#   )r  rø  rj  r  rø   r¥   re  rG  rŸ   rŸ   r    rh  W  s:   ù	
ù	rh  c                 C   óâ   t j}|du r-t j}ttdƒ}t|ƒ}tt jƒ}ttd|ƒ|_	t
ƒ |_d|_ttd|ƒ}nt
ƒ }ttdƒ}t | j|t|ƒ|t
ƒ dt
ƒ d||¡
}	t|	ƒ t|ƒ}
t|
ƒ}t | j|t|ƒ|t
ƒ d||
||¡
}	t|	ƒ t|t|ƒƒS )aO  
    Encrypts a value using an RSA public key via CNG

    :param certificate_or_public_key:
        A Certificate or PublicKey instance to encrypt with

    :param data:
        A byte string of the data to encrypt

    :param rsa_oaep_padding:
        If OAEP padding should be used instead of PKCS#1 v1.5

    :raises:
        ValueError - when any of the parameters contain an invalid value
        TypeError - when any of the parameters are of the wrong type
        OSError - when an error is returned by the OS crypto library

    :return:
        A byte string of the ciphertext
    TÚBCRYPT_OAEP_PADDING_INFOr=  r   r?  r  )rM   rK  ÚBCRYPT_PAD_OAEPr+   rL   r.   r!   rA  r$   rI  r(   ÚpbLabelÚcbLabelr'   ÚBCryptEncryptr™   r®  rD   r%   r    r#   )r  rø  rj  r  rQ  rR  rS  rP  rø   r¥   re  rG  rŸ   rŸ   r    ri  �  óR   


ööri  c                 C   st   t | tƒsttdt| ƒƒƒ‚t |tƒsttdt|ƒƒƒ‚t |tƒs*ttdt|ƒƒƒ‚tdkr4t| ||ƒS t	| ||ƒS )a1  
    Encrypts a value using an RSA private key

    :param private_key:
        A PrivateKey instance to decrypt with

    :param ciphertext:
        A byte string of the data to decrypt

    :param rsa_oaep_padding:
        If OAEP padding should be used instead of PKCS#1 v1.5

    :raises:
        ValueError - when any of the parameters contain an invalid value
        TypeError - when any of the parameters are of the wrong type
        OSError - when an error is returned by the OS crypto library

    :return:
        A byte string of the plaintext
    zY
            private_key must be an instance of the PrivateKey class, not %s
            zB
            ciphertext must be a byte string, not %s
            rf  rA   )
r>  rX   r?  r   r5   r7   rg  r›   Ú_advapi32_decryptÚ_bcrypt_decrypt)rµ   Ú
ciphertextrj  rŸ   rŸ   r    Ú_decryptØ  s$   
ü
ü
ürx  c                 C   sb   d}|rt j}|ddd… }t|ƒ}ttdt|ƒƒ}t | jtƒ d|||¡}t	|ƒ t
|t|ƒƒS )a?  
    Encrypts a value using an RSA private key via CryptoAPI

    :param private_key:
        A PrivateKey instance to decrypt with

    :param ciphertext:
        A byte string of the data to decrypt

    :param rsa_oaep_padding:
        If OAEP padding should be used instead of PKCS#1 v1.5

    :raises:
        ValueError - when any of the parameters contain an invalid value
        TypeError - when any of the parameters are of the wrong type
        OSError - when an error is returned by the OS crypto library

    :return:
        A byte string of the plaintext
    r   NrX  rñ   T)rC   rl  r    r'   rB   r®  ÚCryptDecryptrª   r(   rD   r#   r%   )rµ   rw  rj  r  rG  rø   r¥   rŸ   rŸ   r    ru    s    úru  c                 C   rn  )a9  
    Encrypts a value using an RSA private key via CNG

    :param private_key:
        A PrivateKey instance to decrypt with

    :param ciphertext:
        A byte string of the data to decrypt

    :param rsa_oaep_padding:
        If OAEP padding should be used instead of PKCS#1 v1.5

    :raises:
        ValueError - when any of the parameters contain an invalid value
        TypeError - when any of the parameters are of the wrong type
        OSError - when an error is returned by the OS crypto library

    :return:
        A byte string of the plaintext
    Tro  r=  r   r?  r  )rM   rK  rp  r+   rL   r.   r!   rA  r$   rI  r(   rq  rr  r'   ÚBCryptDecryptr™   r®  rD   r%   r    r#   )rµ   rw  rj  r  rQ  rR  rS  rP  rø   r¥   re  rG  rŸ   rŸ   r    rv  6  rt  rv  c                 C   ó
   t | |ƒS )aF  
    Encrypts a byte string using an RSA public key or certificate. Uses PKCS#1
    v1.5 padding.

    :param certificate_or_public_key:
        A PublicKey or Certificate object

    :param data:
        A byte string, with a maximum length 11 bytes less than the key length
        (in bytes)

    :raises:
        ValueError - when any of the parameters contain an invalid value
        TypeError - when any of the parameters are of the wrong type
        OSError - when an error is returned by the OS crypto library

    :return:
        A byte string of the encrypted data
    ©rk  ©r  rø  rŸ   rŸ   r    r]   ~  s   
r]   c                 C   r{  )aì  
    Decrypts a byte string using an RSA private key. Uses PKCS#1 v1.5 padding.

    :param private_key:
        A PrivateKey object

    :param ciphertext:
        A byte string of the encrypted data

    :raises:
        ValueError - when any of the parameters contain an invalid value
        TypeError - when any of the parameters are of the wrong type
        OSError - when an error is returned by the OS crypto library

    :return:
        A byte string of the original plaintext
    ©rx  ©rµ   rw  rŸ   rŸ   r    r\   –  s   
r\   c                 C   ó   t | |dd�S )aZ  
    Encrypts a byte string using an RSA public key or certificate. Uses PKCS#1
    OAEP padding with SHA1.

    :param certificate_or_public_key:
        A PublicKey or Certificate object

    :param data:
        A byte string, with a maximum length 41 bytes (or more) less than the
        key length (in bytes)

    :raises:
        ValueError - when any of the parameters contain an invalid value
        TypeError - when any of the parameters are of the wrong type
        OSError - when an error is returned by the OS crypto library

    :return:
        A byte string of the encrypted data
    T©rj  r|  r}  rŸ   rŸ   r    r[   ¬  s   r[   c                 C   r€  )aú  
    Decrypts a byte string using an RSA private key. Uses PKCS#1 OAEP padding
    with SHA1.

    :param private_key:
        A PrivateKey object

    :param ciphertext:
        A byte string of the encrypted data

    :raises:
        ValueError - when any of the parameters contain an invalid value
        TypeError - when any of the parameters are of the wrong type
        OSError - when an error is returned by the OS crypto library

    :return:
        A byte string of the original plaintext
    Tr�  r~  r  rŸ   rŸ   r    rZ   Ä  s   rZ   )NN)N)T)F)–Ú
__future__r   r   r   r   rA  ÚsysrF  rP  Ú_asn1r   rš  r   r	   r
   r   r   r   r   r   r   r   r   r   r   r   Ú_asymmetricr   r   r   r   r   r   r   r   r   Ú_errorsr   Ú_ffir    r!   r"   r#   r$   r%   r&   r'   r(   r)   r*   r+   r,   r-   r.   r/   Ú r0   Ú_intr1   Úerrorsr2   r3   r4   Ú_typesr5   r6   r7   r8   Ú_pkcs1r9   r:   r;   r<   r=   r>   Úutilr?   ÚgetwindowsversionÚ_gwvré   r›   Ú	_advapi32rB   rC   rD   rE   rF   Ú_ecdsarG   rê   rH   r½   rI   rJ   r\  rK   r  Ú_cngrL   rM   rN   rO   Ú__all__rD  r˜   rX   rY   rR   r  rë   rÂ   rì   rM  rE  rô   rö   r"  r#  r$  rS   r�  r£  r¬  r¤  rU   rV   rW   rT   r_   ra   rQ   r  r  r  r^   r`   rP   rX  r]  r^  rk  rh  ri  rx  ru  rv  r]   r\   r[   rZ   rŸ   rŸ   rŸ   r    Ú<module>   s˜   D,H   ,W
LP
X4
e@d.G=U[G&P
Wg 
i8
(
=""

b
nY!!

X
z
y
4
9
H
3
+H