+
    Dfj"                      a  0 t $ R t^ RIHt ^ RIHtHtHtHt ^ RI	H
t
Ht ^ RIHtHtHt ^ RIHt ]
'       d   ^ RIHt  ! R R]4      t ! R	 R
]4      t ! R R]4      t ! R R]4      t ! R R]4      t]! ]4       ! R R4      4       t]! ]4       ! R R4      4       t]! ]4       ! R R4      4       t]! ]4       ! R R4      4       t]! ]4       ! R R4      4       t]! ]4       ! R R4      4       t]! ]4       ! R R4      4       t]! ]4       ! R R 4      4       tR!]! 4       R"]! 4       R#]! 4       R$]! 4       R%]! 4       R&]! 4       R']! 4       R(]! 4       /t R)]!R*&   R+ R, lt"R- R. lt#R/ R0 lt$R1 R2 lt%R3 R4 lt&R5 R6 lt'R7# )8z
SSH key exchange handling.
)annotations)sha1sha256sha384sha512)TYPE_CHECKINGProtocol)	Attribute	Interfaceimplementer)error)_Hashc                  &    ] tR t^tRR R lltRtR# )_HashFactoryc                    V ^8  d   QhRRRR/# )   databytesreturnr    )formats   "8/usr/lib/python3/dist-packages/twisted/conch/ssh/_kex.py__annotate___HashFactory.__annotate__   s      U U     c                	    R # Nr   )selfr   s   &&r   __call___HashFactory.__call__   s    r   r   N).)__name__
__module____qualname____firstlineno__r   __static_attributes__r   r   r   r   r      s     r   r   c                  P    ] tR t^t$ Rt]! R4      tR]R&   ]! R4      tR]R&   Rt	R	# )
_IKexAlgorithmz:
An L{_IKexAlgorithm} describes a key exchange algorithm.
zAn L{int} giving the preference of the algorithm when negotiating key exchange. Algorithms with lower precedence values are more preferred.int
preferencezqA callable hash algorithm constructor (e.g. C{hashlib.sha256}) suitable for use with this key exchange algorithm.r   hashProcessorr   N)
r    r!   r"   r#   __doc__r	   r(   __annotations__r)   r$   r   r   r   r&   r&      s7      	J  #,	=#M< r   r&   c                  :    ] tR t^-tRt]! R4      t]! R4      tRtR# )_IFixedGroupKexAlgorithmzi
An L{_IFixedGroupKexAlgorithm} describes a key exchange algorithm with a
fixed prime / generator group.
zdAn L{int} giving the prime number used in Diffie-Hellman key exchange, or L{None} if not applicable.zAn L{int} giving the generator number used in Diffie-Hellman key exchange, or L{None} if not applicable. (This is not related to Python generator functions.)r   N)	r    r!   r"   r#   r*   r	   prime	generatorr$   r   r   r   r-   r-   -   s)    
 	2E
 	'Ir   r-   c                      ] tR t^?tRtRtR# )#_IEllipticCurveExchangeKexAlgorithmz
An L{_IEllipticCurveExchangeKexAlgorithm} describes a key exchange algorithm
that uses an elliptic curve exchange between the client and server.
r   Nr    r!   r"   r#   r*   r$   r   r   r   r1   r1   ?   s    r   r1   c                      ] tR t^FtRtRtR# )_IGroupExchangeKexAlgorithmz
An L{_IGroupExchangeKexAlgorithm} describes a key exchange algorithm
that uses group exchange between the client and server.

A prime / generator group should be chosen at run time based on the
requested size. See RFC 4419.
r   Nr2   r   r   r   r4   r4   F   s    r   r4   c                  "    ] tR t^PtRt^t]tRtR# )_Curve25519SHA256z
Elliptic Curve Key Exchange using Curve25519 and SHA256. Defined in
U{https://datatracker.ietf.org/doc/draft-ietf-curdle-ssh-curves/}.
r   N	r    r!   r"   r#   r*   r(   r   r)   r$   r   r   r   r6   r6   P       
 JMr   r6   c                  "    ] tR t^[tRt^t]tRtR# )_Curve25519SHA256LibSSHzF
As L{_Curve25519SHA256}, but with a pre-standardized algorithm name.
r   Nr7   r   r   r   r:   r:   [   s     JMr   r:   c                  "    ] tR t^etRt^t]tRtR# )_ECDH256a<  
Elliptic Curve Key Exchange with SHA-256 as HASH. Defined in
RFC 5656.

Note that C{ecdh-sha2-nistp256} takes priority over nistp384 or nistp512.
This is the same priority from OpenSSH.

C{ecdh-sha2-nistp256} is considered preety good cryptography.
If you need something better consider using C{curve25519-sha256}.
r   Nr7   r   r   r   r<   r<   e   s    	 JMr   r<   c                  "    ] tR t^vtRt^t]tRtR# )_ECDH384zH
Elliptic Curve Key Exchange with SHA-384 as HASH. Defined in
RFC 5656.
r   N)	r    r!   r"   r#   r*   r(   r   r)   r$   r   r   r   r>   r>   v   r8   r   r>   c                  "    ] tR t^tRt^t]tRtR# )_ECDH512zH
Elliptic Curve Key Exchange with SHA-512 as HASH. Defined in
RFC 5656.
r   N)	r    r!   r"   r#   r*   r(   r   r)   r$   r   r   r   r@   r@      r8   r   r@   c                  "    ] tR t^tRt^t]tRtR# )_DHGroupExchangeSHA256zW
Diffie-Hellman Group and Key Exchange with SHA-256 as HASH. Defined in
RFC 4419, 4.2.
r   Nr7   r   r   r   rB   rB      r8   r   rB   c                  "    ] tR t^tRt^t]tRtR# )_DHGroupExchangeSHA1zU
Diffie-Hellman Group and Key Exchange with SHA-1 as HASH. Defined in
RFC 4419, 4.1.
r   N)	r    r!   r"   r#   r*   r(   r   r)   r$   r   r   r   rD   rD      s    
 JMr   rD   c                  6    ] tR t^tRt^t]t]! R4      t	^t
RtR# )_DHGroup14SHA1zu
Diffie-Hellman key exchange with SHA-1 as HASH and Oakley Group 14
(2048-bit MODP Group). Defined in RFC 4253, 8.2.
i  32317006071311007300338913926423828248817941241140239112842009751400741706634354222619689417363569347117901737909704191754605873209195028853758986185622153212175412514901774520270235796078236248884246189477587641105928646099411723245426622522193230540919037680524235519125679715870117001058055877651038861847280257976054903569732561526167081339361799541336476559160368317896729073178384589680639671900977202194168647225871031411336429319536193471636533209717077448227988588565369208645296636077250268955505928362751121174096972998068410554359584866583291642136218231078990999448652468262416972035911852507045361090559r   N)r    r!   r"   r#   r*   r(   r   r)   r'   r.   r/   r$   r   r   r   rF   rF      s)    
 JM
	E Ir   rF      curve25519-sha256s   curve25519-sha256@libssh.orgs$   diffie-hellman-group-exchange-sha256s"   diffie-hellman-group-exchange-sha1s   diffie-hellman-group14-sha1s   ecdh-sha2-nistp256s   ecdh-sha2-nistp384s   ecdh-sha2-nistp521zdict[bytes, _IKexAlgorithm]_kexAlgorithmsc                    V ^8  d   QhRRRR/# )r   kexAlgorithmr   r   r&   r   )r   s   "r   r   r      s     ( ( (> (r   c                f    V \         9  d   \        P                  ! RV : 24      h\         V ,          # )a9  
Get a description of a named key exchange algorithm.

@param kexAlgorithm: The key exchange algorithm name.
@type kexAlgorithm: L{bytes}

@return: A description of the key exchange algorithm named by
    C{kexAlgorithm}.
@rtype: L{_IKexAlgorithm}

@raises ConchError: if the key exchange algorithm is not found.
z$Unsupported key exchange algorithm: )rI   r   
ConchErrorrK   s   &r   getKexrO      s1     >)!ElEUVWW,''r   c                    V ^8  d   QhRRRR/# r   rK   r   r   boolr   )r   s   "r   r   r      s     	P 	P% 	PD 	Pr   c                >    \         P                  \        V 4      4      # )z
Returns C{True} if C{kexAlgorithm} is an elliptic curve.

@param kexAlgorithm: The key exchange algorithm name.

@return: C{True} if C{kexAlgorithm} is an elliptic curve, otherwise
    C{False}.
)r1   
providedByrO   rN   s   &r   isEllipticCurverU      s     /99&:NOOr   c                    V ^8  d   QhRRRR/# rQ   r   )r   s   "r   r   r      s     	E 	Eu 	E 	Er   c                >    \         P                  \        V 4      4      # )z
Returns C{True} if C{kexAlgorithm} has a fixed prime / generator group.

@param kexAlgorithm: The key exchange algorithm name.

@return: C{True} if C{kexAlgorithm} has a fixed prime / generator group,
    otherwise C{False}.
)r-   rT   rO   rN   s   &r   isFixedGrouprX      s     $..vl/CDDr   c                    V ^8  d   QhRRRR/# )r   rK   r   r   r   r   )r   s   "r   r   r      s     	 	5 	\ 	r   c                0    \        V 4      pVP                  # )z
Get the hash algorithm callable to use in key exchange.

@param kexAlgorithm: The key exchange algorithm name.

@return: A callable hash algorithm constructor (e.g. C{hashlib.sha256}).
)rO   r)   rK   kexs   & r   getHashProcessorr]      s     
Cr   c                    V ^8  d   QhRRRR/# )r   rK   r   r   ztuple[int, int]r   )r   s   "r   r   r      s     $ $ $? $r   c                Z    \        \        V 4      4      pVP                  VP                  3# )z
Get the generator and the prime to use in key exchange.

@param kexAlgorithm: The key exchange algorithm name.
@type kexAlgorithm: L{bytes}

@return: A L{tuple} containing L{int} generator and L{int} prime.
@rtype: L{tuple}
)r-   rO   r/   r.   r[   s   & r   getDHGeneratorAndPrimer`      s&     #6,#7
8C==#))##r   c                   V ^8  d   QhRR/# )r   r   zlist[bytes]r   )r   s   "r   r   r     s      + r   c                   a ^ RI Hp  ^ RIHp ^ RIHp V ! 4       p\        P                  4       o\        S4       F  pVP                  R4      '       d:   VP                  RR4      pVP                  VP                  4       W%,          4      pM*VP                  R4      '       d   VP                  4       pMRpV'       d   K  SP                  V4       K  	  \        SV3R lR	7      # )
z
Get a list of supported key exchange algorithm names in order of
preference.

@return: A C{list} of supported key exchange algorithm names.
)default_backend)ec)_curveTables   ecdhs   ecdsarH   Tc                *   < SV ,          P                   # r   )r(   )rK   kexAlgorithmss   &r   <lambda>*getSupportedKeyExchanges.<locals>.<lambda>(  s    l0K0V0Vr   )key)cryptography.hazmat.backendsrc   )cryptography.hazmat.primitives.asymmetricrd   twisted.conch.ssh.keysre   rI   copylist
startswithreplace+elliptic_curve_exchange_algorithm_supportedECDHx25519_supportedpopsorted)rc   rd   re   backendkeyAlgorithmkeyAlgorithmDsa	supportedrg   s          @r   getSupportedKeyExchangesr{     s     =<2G"'')M]+""7++*227HEOKK	;7I $$%9::002IIyl+ , V r   N)(__conditional_annotations__r*   
__future__r   hashlibr   r   r   r   typingr   r   zope.interfacer	   r
   r   twisted.conchr   r   r   r&   r-   r1   r4   r6   r:   r<   r>   r@   rB   rD   rF   rI   r+   rO   rU   rX   r]   r`   r{   )r|   s   @r   <module>r      s  
 # 0 0 * < < 8 
Y "~ $. .  01  2 01  2 01  2  01  2 01  2 ()  * ()  * %&  '6 +-#%<%>+-C-E)+?+A"N$48:8:8:	/+ 	($	P	E	$r   