+
    Hߺi)7                   p  a  0 t $ ^ RIHt ^ RIt^ RIt^ RIt^ RIt^ RIt^ RIt^ RI	H
t
 ^ RIHtHt ^ RIHt ^ RIHtHtHt ]P$                  R[8  d   ^ RIHt M0]P$                  R\8  d   ]P(                  ! R4      tR	 R
 ltM^ RIHt ^ RIHtHt ^ RIHtHtHtHtHt ^ RI H!t! ^ RI H"t# ^ RI H$t% ^ RI H&t' ^ RI H(t) ^ RI H*t+ ^ RI H,t- . R]Ot.]]P^                  ]P`                  ]Pb                  ]Pd                  ]Pf                  3,          t4]]Pj                  ]Pl                  ]Pn                  ]Pp                  ]Pr                  3,          t:]]4]:3,          t;]]<]R$]<3,          3,          t=])P|                  t?R%]@R&   ])P                  tBR%]@R&   R^tC])P                  tER%]@R&   ])P                  tGR%]@R&   ])P                  tIR%]@R&&   ])P                  tKR%]@R'&    ! R( R]L4      tM]! ]%]M4      tN]+! ]M4      tOR_R) R* lltPR+ R, ltQR- R. ltRR/ R0 ltSR1 R2 ltT ! R3 R44      tU ! R5 R4      tV ! R6 R74      tW]! R84      R9 R: l4       tX]! R;4      R< R= l4       tY]P                   ! R> R4      4       t[]! R?4       ! R@ R4      4       t\]! RA4       ! RB R4      4       t] ! RC R4      t^ ! RD R!4      t_ ! RE R4      t` ! RF R ]L4      ta ! RG R4      tbRH RI ltcRJ RK ltdRL RM lteR`RN RO lltf ! RP RQ4      tgRR RS lthR_RT RU lltiRV RW ltj]jtk]P&                  ! ]j]lRA]mR"RX7       RY RZ ltn]nto]P&                  ! ]n]lRA]mR#RX7       R# )a    )annotationsN)	b16encode)IterableSequence)partial)AnyCallableUnion)
deprecatedTc               $    V ^8  d   QhRRRRRR/# )   msgstrkwargsobjectreturnzCallable[[_T], _T] )formats   "0/usr/lib/python3/dist-packages/OpenSSL/crypto.py__annotate__r      s"       v 2D     c                    R  # )c                    V # Nr   )fs   &r   <lambda>deprecated.<locals>.<lambda>   s    r   r   )r   r   s   &,r   r   r      s    r   )utilsx509)dsaeced448ed25519rsa)StrOrBytesPath)byte_string)exception_from_error_queue)ffi)lib)make_assert)
path_bytesFILETYPE_ASN1FILETYPE_PEMTYPE_DSATYPE_RSAX509ErrorPKeyX509ExtensionX509NameX509Req	X509StoreX509StoreContextX509StoreContextErrorX509StoreFlagsdump_certificate_requestload_certificate_request.intTYPE_DHTYPE_ECc                      ] tR t^ttRtRtR# )r2   z/
An error occurred in an `OpenSSL.crypto` API.
r   N)__name__
__module____qualname____firstlineno____doc____static_attributes__r   r   r   r2   r2   t   s    r   c                    V ^8  d   QhRRRR/# )r   bufferbytes | Noner   r   r   )r   s   "r   r   r   ~   s        r   c                f   V f;   \         P                  ! \         P                  ! 4       4      p\         P                  pM@\        P
                  ! RV 4      p\         P                  ! V\        V 4      4      pV3R R llp\        V\        P                  8g  4       \        P                  ! W4      pV# )z
Allocate a new OpenSSL memory BIO.

Arrange for the garbage collector to clean it up automatically.

:param buffer: None or some bytes to use to put into the BIO so that they
    can be read out.
char[]c               $    V ^8  d   QhRRRRRR/# )r   bior   refr   r   )r   s   "r   r   "_new_mem_buf.<locals>.__annotate__   s!     	& 	&c 	& 	&s 	&r   c                .    \         P                  ! V 4      # r   )_libBIO_free)rM   rN   s   &&r   free_new_mem_buf.<locals>.free   s    ==%%r   )rQ   BIO_new	BIO_s_memrR   _ffinewBIO_new_mem_buflen_openssl_assertNULLgc)rH   rM   rS   datas   &   r   _new_mem_bufr_   ~   s}     ~ll4>>+,}}xx&)""4V5 '+ 	& C499$%
''#
CJr   c                    V ^8  d   QhRRRR/# )r   rM   r   r   bytesr   )r   s   "r   r   r      s     ; ; ; ;r   c                    \         P                  ! R4      p\        P                  ! W4      p\         P                  ! V^ ,          V4      R,          # )zG
Copy the contents of an OpenSSL BIO object into a Python byte string.
zchar**NNN)rW   rX   rQ   BIO_get_mem_datarH   )rM   result_bufferbuffer_lengths   &  r   _bio_to_stringrg      s=     HHX&M))#=M;;}Q'7::r   c               $    V ^8  d   QhRRRRRR/# )r   boundaryr   whenra   r   Noner   )r   s   "r   r   r      s!     + +S + +$ +r   c                    \        V\        4      '       g   \        R4      h\        V \        P
                  8g  4       \        P                  ! W4      pV^ 8X  d   \        R4      hR# )a  
The the time value of an ASN1 time object.

@param boundary: An ASN1_TIME pointer (or an object safely
    castable to that type) which will have its value set.
@param when: A string representation of the desired time value.

@raise TypeError: If C{when} is not a L{bytes} string.
@raise ValueError: If C{when} does not represent a time in the required
    format.
@raise RuntimeError: If the time value cannot be set for some other
    (unspecified) reason.
zwhen must be a byte stringzInvalid stringN)	
isinstancera   	TypeErrorr[   rW   r\   rQ   ASN1_TIME_set_string
ValueError)ri   rj   
set_results   && r   _set_asn1_timerr      sX     dE""455 H		)***8:JQ)** r   c                    V ^8  d   QhRRRR/# )r   rj   ra   r   r   r   )r   s   "r   r   r      s       3 r   c                    \         P                  ! 4       p\        V\        P                  8g  4       \        P
                  ! V\         P                  4      p\        W4       V# )al  
Behaves like _set_asn1_time but returns a new ASN1_TIME object.

@param when: A string representation of the desired time value.

@raise TypeError: If C{when} is not a L{bytes} string.
@raise ValueError: If C{when} does not represent a time in the required
    format.
@raise RuntimeError: If the time value cannot be set for some other
    (unspecified) reason.
)rQ   ASN1_TIME_newr[   rW   r\   r]   ASN1_TIME_freerr   )rj   rets   & r   _new_asn1_timerx      sF     


CC499$%
''#t**
+C3Jr   c                    V ^8  d   QhRRRR/# )r   	timestampr   r   rI   r   )r   s   "r   r   r      s      c l r   c                   \         P                  ! RV 4      p\        P                  ! V4      ^ 8X  d   R# \        P                  ! V4      \        P
                  8X  d+   \         P                  ! \        P                  ! V4      4      # \         P                  ! R4      p\        P                  ! W4       \        V^ ,          \         P                  8g  4       \         P                  ! RV^ ,          4      p\        P                  ! V4      p\         P                  ! V4      p\        P                  ! V^ ,          4       V# )aE  
Retrieve the time value of an ASN1 time object.

@param timestamp: An ASN1_GENERALIZEDTIME* (or an object safely castable to
    that type) from which the time value will be retrieved.

@return: The time value from C{timestamp} as a L{bytes} string in a certain
    format.  Or C{None} if the object contains no time value.
ASN1_STRING*NzASN1_GENERALIZEDTIME**)rW   castrQ   ASN1_STRING_lengthASN1_STRING_typeV_ASN1_GENERALIZEDTIMEstringASN1_STRING_get0_datarX   ASN1_TIME_to_generalizedtimer[   r\   ASN1_GENERALIZEDTIME_free)rz   string_timestampgeneralized_timestampstring_datastring_results   &    r   _get_asn1_timer      s     yy;/0A5./43N3NN{{4556FGHH $)A B)))K-a0DII=>99^5J15MN001ABK0&&'<Q'?@r   c                  :    ] tR t^tR R ltR R ltR R ltRtR# )	_X509NameInvalidatorc                   V ^8  d   QhRR/# r   r   rk   r   )r   s   "r   r   !_X509NameInvalidator.__annotate__   s     ) )$ )r   c                	    . V n         R # r   _namesselfs   &r   __init___X509NameInvalidator.__init__   s	    &(r   c                    V ^8  d   QhRRRR/# r   namer5   r   rk   r   )r   s   "r   r   r      s     ! ! !T !r   c                	<    V P                   P                  V4       R # r   )r   appendr   r   s   &&r   add_X509NameInvalidator.add   s    4 r   c                   V ^8  d   QhRR/# r   r   )r   s   "r   r   r      s      t r   c                	0    V P                    F  pV=K  	  R # r   )r   _namer   s   & r   clear_X509NameInvalidator.clear   s    KKD
  r   r   N)rA   rB   rC   rD   r   r   r   rF   r   r   r   r   r      s    )! r   r   c                      ] tR t^tRtRtRtR R ltR R lt]	R R	 l4       t
R
 R ltR R ltR R ltR R ltRtR# )r3   z<
A class representing an DSA or RSA public key or key pair.
FTc                   V ^8  d   QhRR/# r   r   )r   s   "r   r   PKey.__annotate__   s     " "$ "r   c                	    \         P                  ! 4       p\        P                  ! V\         P                  4      V n        R V n        R# )FN)rQ   EVP_PKEY_newrW   r]   EVP_PKEY_free_pkey_initializedr   pkeys   & r   r   PKey.__init__   s0      "WWT4#5#56
!r   c                   V ^8  d   QhRR/# )r   r   _Keyr   )r   s   "r   r   r     s     O OT Or   c                    ^ RI HpHp V P                  '       d2   \	        \
        V 4      p\        P                  ! \        V! V4      4      # \        \
        V 4      p\        P                  ! \        V! VRR7      4      # )z
Export as a ``cryptography`` key.

:rtype: One of ``cryptography``'s `key interfaces`_.

.. _key interfaces: https://cryptography.io/en/latest/hazmat/            primitives/asymmetric/rsa/#key-interfaces

.. versionadded:: 16.1.0
)load_der_private_keyload_der_public_keyN)password)
,cryptography.hazmat.primitives.serializationr   r   _only_publicdump_publickeyr-   typingr}   r   dump_privatekey)r   r   r   ders   &   r   to_cryptography_keyPKey.to_cryptography_key  s]    	

  5C;;t%8%=>>!-6C;;t%9#%MNNr   c                    V ^8  d   QhRRRR/# )r   
crypto_keyr   r   r3   r   )r   s   "r   r   r     s     77 77t 77 77r   c                   \        V\        P                  \        P                  \        P
                  \        P                  \        P                  \        P                  \        P                  \        P                  \        P                  \        P                  3
4      '       g   \!        R4      h^ RIHpHpHpHp \        V\        P                  \        P                  \        P                  \        P                  \        P                  34      '       d5   \-        \.        VP1                  VP2                  VP4                  4      4      # VP7                  VP2                  VP8                  V! 4       4      p\;        \.        V4      # )z
Construct based on a ``cryptography`` *crypto_key*.

:param crypto_key: A ``cryptography`` key.
:type crypto_key: One of ``cryptography``'s `key interfaces`_.

:rtype: PKey

.. versionadded:: 16.1.0
zUnsupported key type)EncodingNoEncryptionPrivateFormatPublicFormat)rm   r!   DSAPrivateKeyDSAPublicKeyr"   EllipticCurvePrivateKeyEllipticCurvePublicKeyr$   Ed25519PrivateKeyEd25519PublicKeyr#   Ed448PrivateKeyEd448PublicKeyr%   RSAPrivateKeyRSAPublicKeyrn   r   r   r   r   r   load_publickeyr-   public_bytesDERSubjectPublicKeyInfoprivate_bytesPKCS8load_privatekey)clsr   r   r   r   r   r   s   &&     r   from_cryptography_keyPKey.from_cryptography_key  s2    !!  **))))((%%$$!!  
 
 233	
 	
   ))(($$  	
 	
 "''LL,"C"C  **m11<>C #=#66r   c               $    V ^8  d   QhRRRRRR/# )r   typer=   bitsr   rk   r   )r   s   "r   r   r   U  s!     6! 6! 6!C 6!D 6!r   c           	        \        V\        4      '       g   \        R4      h\        V\        4      '       g   \        R4      hV\        8X  d   V^ 8:  d   \	        R4      h\
        P                  ! 4       p\        P                  ! V\
        P                  4      p\
        P                  ! V\
        P                  4       \
        P                  ! 4       p\
        P                  ! WBV\        P                  4      p\        V^8H  4       \
        P                   ! V P"                  V4      p\        V^8H  4       EMV\$        8X  Ed   \
        P&                  ! 4       p\        V\        P                  8g  4       \        P                  ! V\
        P(                  4      p\
        P*                  ! Wb\        P                  ^ \        P                  \        P                  \        P                  4      p\        V^8H  4       \        \
        P,                  ! V4      ^8H  4       \        \
        P.                  ! V P"                  V4      ^8H  4       M\1        R4      hRV n        R# )a  
Generate a key pair of the given type, with the given number of bits.

This generates a key "into" the this object.

:param type: The key type.
:type type: :py:data:`TYPE_RSA` or :py:data:`TYPE_DSA`
:param bits: The number of bits.
:type bits: :py:data:`int` ``>= 0``
:raises TypeError: If :py:data:`type` or :py:data:`bits` isn't
    of the appropriate type.
:raises ValueError: If the number of bits isn't an integer of
    the appropriate size.
:return: ``None``
ztype must be an integerzbits must be an integerzInvalid number of bitszNo such key typeTN)rm   r=   rn   r0   rp   rQ   BN_newrW   r]   BN_freeBN_set_wordRSA_F4RSA_newRSA_generate_key_exr\   r[   EVP_PKEY_assign_RSAr   r/   DSA_newDSA_freeDSA_generate_parameters_exDSA_generate_keyEVP_PKEY_set1_DSAr2   r   )r   r   r   exponentr%   resultr!   ress   &&&     r   generate_keyPKey.generate_keyU  s     $$$566$$$5668qy !9:: {{}Hwwx6HXt{{3,,.C--c499MFFaK(--djj#>FFaK(X,,.CC499,-''#t}}-C11499aDIItyyC C1H%D11#6!;<D224::sCqHI*++ r   c                   V ^8  d   QhRR/# r   r   boolr   )r   s   "r   r   r     s      t r   c                   V P                   '       d   \        R4      h\        P                  ! V P	                  4       4      \        P
                  8w  d   \        R4      h\        P                  ! V P                  4      p\        P                  ! V\        P                  4      p\        P                  ! V4      pV^8X  d   R# \        4        R# )a@  
Check the consistency of an RSA private key.

This is the Python equivalent of OpenSSL's ``RSA_check_key``.

:return: ``True`` if key is consistent.

:raise OpenSSL.crypto.Error: if the key is inconsistent.

:raise TypeError: if the key is of a type which cannot be checked.
    Only RSA keys can currently be checked.
zpublic key onlyz'Only RSA keys can currently be checked.TN)r   rn   rQ   EVP_PKEY_typer   EVP_PKEY_RSAEVP_PKEY_get1_RSAr   rW   r]   RSA_freeRSA_check_key_raise_current_error)r   r%   r   s   &  r   check
PKey.check  s     -..diik*d.?.??EFF$$TZZ0ggc4==)##C(Q;r   c                   V ^8  d   QhRR/# r   r   r=   r   )r   s   "r   r   r     s     , ,c ,r   c                B    \         P                  ! V P                  4      # )z<
Returns the type of the key

:return: The type of the key.
)rQ   EVP_PKEY_idr   r   s   &r   r   	PKey.type  s     

++r   c                   V ^8  d   QhRR/# r   r   )r   s   "r   r   r     s     . .c .r   c                B    \         P                  ! V P                  4      # )zP
Returns the number of bits of the key

:return: The number of bits of the key.
)rQ   EVP_PKEY_bitsr   r   s   &r   r   	PKey.bits  s     !!$**--r   )r   r   N)rA   rB   rC   rD   rE   r   r   r   r   classmethodr   r   r   r   r   rF   r   r   r   r3   r3      sM     LL"
O. 77 77r6!p4,. .r   c                     a  ] tR tRtRtRtR V 3R llt]R R l4       t]R R	 l4       t	]R
 R l4       t
R R ltR R ltR R ltRtV ;t# )_EllipticCurvei  aB  
A representation of a supported elliptic curve.

@cvar _curves: :py:obj:`None` until an attempt is made to load the curves.
    Thereafter, a :py:type:`set` containing :py:type:`_EllipticCurve`
    instances each of which represents one curve supported by the system.
@type _curves: :py:type:`NoneType` or :py:type:`set`
Nc                    V ^8  d   QhRRRR/# r   otherr   r   r   r   )r   s   "r   r   _EllipticCurve.__annotate__  s     	 	C 	D 	r   c                Z   < \        V\        4      '       d   \        SV `  V4      # \        # )z
Implement cooperation with the right-hand side argument of ``!=``.

Python 3 seems to have dropped this cooperation in this very narrow
circumstance.
)rm   r  super__ne__NotImplemented)r   r  	__class__s   &&r   r
  _EllipticCurve.__ne__  s'     e^,,7>%((r   c                    V ^8  d   QhRRRR/# r   r*   r   r   set[_EllipticCurve]r   )r   s   "r   r   r    s     E E E0C Er   c                   a a SP                  \        P                  ^ 4      p\        P                  ! RV4      pSP                  W24       \	        V V3R lV 4       4      # )z
Get the curves supported by OpenSSL.

:param lib: The OpenSSL library binding object.

:return: A :py:type:`set` of ``cls`` instances giving the names of the
    elliptic curves the underlying library supports.
zEC_builtin_curve[]c              3  \   <"   T F!  pSP                  SVP                  4      x  K#  	  R # 5ir   )from_nidnid).0cr   r*   s   & r   	<genexpr>7_EllipticCurve._load_elliptic_curves.<locals>.<genexpr>  s#     D^3<<QUU++^s   ),)EC_get_builtin_curvesrW   r\   rX   set)r   r*   
num_curvesbuiltin_curvess   ff  r   _load_elliptic_curves$_EllipticCurve._load_elliptic_curves  sM     ..tyy!<
"6
C 	!!.=D^DDDr   c                    V ^8  d   QhRRRR/# r  r   )r   s   "r   r   r    s      s /B r   c                b    V P                   f   V P                  V4      V n         V P                   # )z
Get, cache, and return the curves supported by OpenSSL.

:param lib: The OpenSSL library binding object.

:return: A :py:type:`set` of ``cls`` instances giving the names of the
    elliptic curves the underlying library supports.
)_curvesr  )r   r*   s   &&r   _get_elliptic_curves#_EllipticCurve._get_elliptic_curves  s*     ;;33C8CK{{r   c               $    V ^8  d   QhRRRRRR/# )r   r*   r   r  r=   r   r  r   )r   s   "r   r   r    s&     O O3 OS O^ Or   c           	     x    V ! W\         P                  ! VP                  V4      4      P                  R4      4      # )a  
Instantiate a new :py:class:`_EllipticCurve` associated with the given
OpenSSL NID.

:param lib: The OpenSSL library binding object.

:param nid: The OpenSSL NID the resulting curve object will represent.
    This must be a curve NID (and not, for example, a hash NID) or
    subsequent operations will fail in unpredictable ways.
:type nid: :py:class:`int`

:return: The curve object.
ascii)rW   r   
OBJ_nid2sndecode)r   r*   r  s   &&&r   r  _EllipticCurve.from_nid  s.     3T[[)<=DDWMNNr   c               (    V ^8  d   QhRRRRRRRR/# )	r   r*   r   r  r=   r   r   r   rk   r   )r   s   "r   r   r     s(      C c   r   c                *    Wn         W n        W0n        R# )aA  
:param _lib: The :py:mod:`cryptography` binding instance used to
    interface with OpenSSL.

:param _nid: The OpenSSL NID identifying the curve this object
    represents.
:type _nid: :py:class:`int`

:param name: The OpenSSL short name identifying the curve this object
    represents.
:type name: :py:class:`unicode`
NrQ   _nidr   )r   r*   r  r   s   &&&&r   r   _EllipticCurve.__init__   s     			r   c                   V ^8  d   QhRR/# r   r   r   r   )r   s   "r   r   r    s     ( (# (r   c                	$    R V P                   : R2# )z<Curve >r   r   s   &r   __repr___EllipticCurve.__repr__  s    Q''r   c                   V ^8  d   QhRR/# r   r   r   r   )r   s   "r   r   r    s     . .C .r   c                    V P                   P                  V P                  4      p\        P                  ! V\         P
                  4      # )z
Create a new OpenSSL EC_KEY structure initialized to use this curve.

The structure is automatically garbage collected when the Python object
is garbage collected.
)rQ   EC_KEY_new_by_curve_namer-  rW   r]   EC_KEY_free)r   keys   & r   
_to_EC_KEY_EllipticCurve._to_EC_KEY  s3     ii00;wwsD,,--r   r,  )rA   rB   rC   rD   rE   r!  r
  r  r  r"  r  r   r4  r<  rF   __classcell__r  s   @r   r  r    sm     G	 	 E E"   O O "(. .r   r  zSget_elliptic_curves is deprecated. You should use the APIs in cryptography instead.c                   V ^8  d   QhRR/# )r   r   r  r   )r   s   "r   r   r   #  s     5 50 5r   c                 4    \         P                  \        4      # )as  
Return a set of objects representing the elliptic curves supported in the
OpenSSL build in use.

The curve objects have a :py:class:`unicode` ``name`` attribute by which
they identify themselves.

The curve objects are useful as values for the argument accepted by
:py:meth:`Context.set_tmp_ecdh` to specify which elliptical curve should be
used for ECDHE key exchange.
)r  r"  rQ   r   r   r   get_elliptic_curvesrB    s      ..t44r   zRget_elliptic_curve is deprecated. You should use the APIs in cryptography instead.c                    V ^8  d   QhRRRR/# )r   r   r   r   r  r   )r   s   "r   r   r   6  s     1 1S 1^ 1r   c                f    \        4        F  pVP                  V 8X  g   K  Vu # 	  \        RV 4      h)a8  
Return a single curve object selected by name.

See :py:func:`get_elliptic_curves` for information about curve objects.

:param name: The OpenSSL short name identifying the curve object to
    retrieve.
:type name: :py:class:`unicode`

If the named curve is not supported then :py:class:`ValueError` is raised.
zunknown curve name)rB  r   rp   )r   curves   & r   get_elliptic_curverF  2  s2      %&::L ' )4
00r   c                     a  ] tR tRtRtR R ltR V 3R lltR R ltR	 R
 ltR R lt	R R lt
R R ltR R ltR R ltRtV ;t# )r5   iH  a  
An X.509 Distinguished Name.

:ivar countryName: The country of the entity.
:ivar C: Alias for  :py:attr:`countryName`.

:ivar stateOrProvinceName: The state or province of the entity.
:ivar ST: Alias for :py:attr:`stateOrProvinceName`.

:ivar localityName: The locality of the entity.
:ivar L: Alias for :py:attr:`localityName`.

:ivar organizationName: The organization name of the entity.
:ivar O: Alias for :py:attr:`organizationName`.

:ivar organizationalUnitName: The organizational unit of the entity.
:ivar OU: Alias for :py:attr:`organizationalUnitName`

:ivar commonName: The common name of the entity.
:ivar CN: Alias for :py:attr:`commonName`.

:ivar emailAddress: The e-mail address of the entity.
c                    V ^8  d   QhRRRR/# r   r   )r   s   "r   r   X509Name.__annotate__b  s     = =X =$ =r   c                    \         P                  ! VP                  4      p\        P                  ! V\         P
                  4      V n        R# )z~
Create a new X509Name, copying the given X509Name instance.

:param name: The name to copy.
:type name: :py:class:`X509Name`
N)rQ   X509_NAME_dupr   rW   r]   X509_NAME_freer   s   &&r   r   X509Name.__init__b  s0     !!$**-''$(;(;<
r   c               $    V ^8  d   QhRRRRRR/# )r   r   r   valuer   r   rk   r   )r   s   "r   r   rI  l  s!     %# %# %#C %#D %#r   c           	     	  < VP                  R 4      '       d   \        S	V `	  W4      # \        V4      \        Jd$   \        R\        V4      P                  R R24      h\        P                  ! \        V4      4      pV\        P                  8X  d    \        4        \        R4      h\        \        P                  ! V P                   4      4       F  p\        P"                  ! V P                   V4      p\        P$                  ! V4      p\        P&                  ! V4      pW78X  g   KX  \        P(                  ! V P                   V4      p\        P*                  ! V4        M	  \-        V\        4      '       d   VP/                  R4      p\        P0                  ! V P                   V\        P2                  VRR^ 4      pV'       g   \        4        R# R#   \         d     ELFi ; i)_z$attribute name must be string, not 'z.200'No such attributeutf-8N)
startswithr	  __setattr__r   r   rn   rA   rQ   OBJ_txt2nid_byte_string	NID_undefr   r2   AttributeErrorrangeX509_NAME_entry_countr   X509_NAME_get_entryX509_NAME_ENTRY_get_objectOBJ_obj2nidX509_NAME_delete_entryX509_NAME_ENTRY_freerm   encodeX509_NAME_add_entry_by_NIDMBSTRING_UTF8)
r   r   rO  r  ientent_objent_nid
add_resultr  s
   &&&      r   rW  X509Name.__setattr__l  s   ??37&t33 :S K((.a1 
 |D12$.. $& !!455 t11$**=>A**4::q9C55c:G&&w/G~11$**a@))#. ? eS!!LL)E44JJT//B

  " )  s   
G G$#G$c                    V ^8  d   QhRRRR/# )r   r   r   r   
str | Noner   )r   s   "r   r   rI    s     & & &
 &r   c                   \         P                  ! \        V4      4      pV\         P                  8X  d    \	        4        \        R4      h\         P                  ! V P                  VR4      pVR8X  d   R# \         P                  ! V P                  V4      p\         P                  ! V4      p\        P                  ! R4      p\         P                  ! We4      p\        V^ 8  4        \        P                  ! V^ ,          V4      R,          P!                  R4      p\         P"                  ! V^ ,          4       V#   \
         d     EL	i ; i  \         P"                  ! T^ ,          4       i ; i)z
Find attribute. An X509Name object has the following attributes:
countryName (alias C), stateOrProvince (alias ST), locality (alias L),
organization (alias O), organizationalUnit (alias OU), commonName
(alias CN) and more...
rS  Nunsigned char**rc   rT  rU  )rQ   rX  rY  rZ  r   r2   r[  X509_NAME_get_index_by_NIDr   r^  X509_NAME_ENTRY_get_datarW   rX   ASN1_STRING_to_UTF8r[   rH   r(  OPENSSL_free)	r   r   r  entry_indexentryr^   re   data_lengthr   s	   &&       r   __getattr__X509Name.__getattr__  s$    |D12$.. $& !!45555djj#rJ"(([A,,U3!23..}Cq()	0[[q!1;?BIIF
 mA./-  * mA./s   
D; (4E ;E
	E
E,c                    V ^8  d   QhRRRR/# r  r   )r   s   "r   r   rI    s     @ @C @D @r   c                	    \        V\        4      '       g   \        # \        P                  ! V P
                  VP
                  4      ^ 8H  # r   rm   r5   r  rQ   X509_NAME_cmpr   r   r  s   &&r   __eq__X509Name.__eq__  s5    %**!!!!$**ekk:a??r   c                    V ^8  d   QhRRRR/# r  r   )r   s   "r   r   rI    s     ? ?C ?D ?r   c                	    \        V\        4      '       g   \        # \        P                  ! V P
                  VP
                  4      ^ 8  # r{  r|  r~  s   &&r   __lt__X509Name.__lt__  s5    %**!!!!$**ekk:Q>>r   c                   V ^8  d   QhRR/# r0  r   )r   s   "r   r   rI    s     
 
# 
r   c                &   \         P                  ! RR4      p\        P                  ! V P                  V\        V4      4      p\        V\         P                  8g  4       RP                  \         P                  ! V4      P                  R4      4      # )z&
String representation of an X509Name
rK   i   z<X509Name object '{}'>rT  )rW   rX   rQ   X509_NAME_oneliner   rZ   r[   r\   r   r   r(  )r   re   format_results   &  r   r4  X509Name.__repr__  sq     3/..JJs='9
 	23'..KK&--g6
 	
r   c                   V ^8  d   QhRR/# r   r   )r   s   "r   r   rI    s     
/ 
/c 
/r   c                B    \         P                  ! V P                  4      # )z
Return an integer representation of the first four bytes of the
MD5 digest of the DER representation of the name.

This is the Python equivalent of OpenSSL's ``X509_NAME_hash``.

:return: The (integer) hash of this name.
:rtype: :py:class:`int`
)rQ   X509_NAME_hashr   r   s   &r   hashX509Name.hash  s     ""4::..r   c                   V ^8  d   QhRR/# r   r   ra   r   )r   s   "r   r   rI    s      U r   c                   \         P                  ! R4      p\        P                  ! V P                  V4      p\        V^ 8  4       \         P                  ! V^ ,          V4      R,          p\        P                  ! V^ ,          4       V# )zn
Return the DER encoding of this name.

:return: The DER encoded form of this name.
:rtype: :py:class:`bytes`
ro  rc   )rW   rX   rQ   i2d_X509_NAMEr   r[   rH   rs  )r   re   encode_resultr   s   &   r   r   X509Name.der  si     !23**4::}E*+M!$4mDQG-*+r   c                   V ^8  d   QhRR/# )r   r   zlist[tuple[bytes, bytes]]r   )r   s   "r   r   rI    s       9 r   c                6   . p\        \        P                  ! V P                  4      4       F  p\        P                  ! V P                  V4      p\        P
                  ! V4      p\        P                  ! V4      p\        P                  ! V4      p\        P                  ! V4      p\        P                  ! \        P                  ! V4      \        P                  ! V4      4      R,          pVP                  \        P                  ! V4      V34       K  	  V# )z
Returns the components of this name, as a sequence of 2-tuples.

:return: The components of this name.
:rtype: :py:class:`list` of ``name, value`` tuples.
rc   )r\  rQ   r]  r   r^  r_  rq  r`  r'  rW   rH   r   r~   r   r   )	r   r   rf  rg  fnamefvalr  r   rO  s	   &        r   get_componentsX509Name.get_components  s     t11$**=>A**4::q9C33C8E005D""5)C??3'D KK**40$2I2I$2OE MM4;;t,e45 ?  r   )r   )rA   rB   rC   rD   rE   r   rW  rw  r  r  r4  r  r   r  rF   r>  r?  s   @r   r5   r5   H  sB    0=%# %#N&P@?

/ r   zZX509Extension support in pyOpenSSL is deprecated. You should use the APIs in cryptography.c                      ] tR tRt$ RtRR R llt]R R l4       t]P                  R]P                  R	]P                  R
/tR]R&   R R ltR R ltR R ltR R ltR R ltRtR# )r4   i  ze
An X.509 v3 certificate extension.

.. deprecated:: 23.3.0
   Use cryptography's X509 APIs instead.
Nc               0    V ^8  d   QhRRRRRRRRRRR	R
/# )r   	type_namera   criticalr   rO  subjectzX509 | Noneissuerr   rk   r   )r   s   "r   r   X509Extension.__annotate__  sV     CG CGCG CG 	CG
 CG CG 
CGr   c                   \         P                  ! R4      p\        P                  ! V\         P                  \         P                  \         P                  \         P                  ^ 4       \        P
                  ! V4       Ve3   \        V\        4      '       g   \        R4      hVP                  Vn
        Ve3   \        V\        4      '       g   \        R4      hVP                  Vn        V'       d
   RV,           p\        P                  ! \         P                  WaV4      pV\         P                  8X  d   \        4        \         P                  ! V\        P                  4      V n        R# )ae  
Initializes an X509 extension.

:param type_name: The name of the type of extension_ to create.
:type type_name: :py:data:`bytes`

:param bool critical: A flag indicating whether this is a critical
    extension.

:param value: The OpenSSL textual representation of the extension's
    value.
:type value: :py:data:`bytes`

:param subject: Optional X509 certificate to use as subject.
:type subject: :py:class:`X509`

:param issuer: Optional X509 certificate to use as issuer.
:type issuer: :py:class:`X509`

.. _extension: https://www.openssl.org/docs/manmaster/man5/
    x509v3_config.html#STANDARD-EXTENSIONS
zX509V3_CTX*Nzissuer must be an X509 instancez subject must be an X509 instances	   critical,)rW   rX   rQ   X509V3_set_ctxr\   X509V3_set_ctx_nodbrm   r1   rn   _x509issuer_certsubject_certX509V3_EXT_nconfr   r]   X509_EXTENSION_free
_extension)r   r  r  rO  r  r  ctx	extensions   &&&&&&  r   r   X509Extension.__init__  s    < hh}%
 	CDIItyy$))QO 	  % fd++ ABB$llCOgt,, BCC&}}C !5(E))$))SUK			! "'')T-E-EFr   c                   V ^8  d   QhRR/# r7  r   )r   s   "r   r   r  ]  s     
 
c 
r   c                	j    \         P                  ! \         P                  ! V P                  4      4      # r   )rQ   r`  X509_EXTENSION_get_objectr  r   s   &r   r-  X509Extension._nid\  s'    **4??;
 	
r   emailDNSURIztyping.ClassVar[dict[int, str]]	_prefixesc                   V ^8  d   QhRR/# r0  r   )r   s   "r   r   r  h  s        s  r   c                	X   \         P                  ! R \        P                  ! V P                  4      4      p\         P
                  ! V\        P                  4      p. p\        \        P                  ! V4      4       F  p\        P                  ! W4      p V P                  VP                  ,          p\         P                  ! VP                  P                  P                  VP                  P                  P                   4      R,          P#                  R4      pVP%                  VR,           V,           4       K  	  RP/                  V4      #   \&         dO    \)        4       p\        P*                  ! Yt4       TP%                  \-        T4      P#                  R4      4        EK,  i ; i)zGENERAL_NAMES*rc   rT  :z, )rW   r}   rQ   X509V3_EXT_d2ir  r]   GENERAL_NAMES_freer\  sk_GENERAL_NAME_numsk_GENERAL_NAME_valuer  r   rH   dia5r^   lengthr(  r   KeyErrorr_   GENERAL_NAME_printrg   join)r   namespartsrf  r   labelrO  rM   s   &       r   _subjectAltNameString#X509Extension._subjectAltNameStringh  s1   		d11$//B
 t667t//67A--e7D
2tyy1 DFFJJOOTVVZZ5F5FG&/  US[501 8 yy  B"n''2^C077@AABs   EAF)(F)c                   V ^8  d   QhRR/# r0  r   )r   s   "r   r   r  ~  s     3 3 3r   c                   \         P                  V P                  8X  d   V P                  4       # \	        4       p\         P
                  ! WP                  ^ ^ 4      p\        V^ 8g  4       \        V4      P                  R4      # )z6
:return: a nice text representation of the extension
rT  )
rQ   NID_subject_alt_namer-  r  r_   X509V3_EXT_printr  r[   rg   r(  )r   rM   print_results   &  r   __str__X509Extension.__str__~  sg     $$		1--//n,,S//1aH)*c"))'22r   c                   V ^8  d   QhRR/# r   r   )r   s   "r   r   r    s     A Ad Ar   c                B    \         P                  ! V P                  4      # )zS
Returns the critical field of this X.509 extension.

:return: The critical field.
)rQ   X509_EXTENSION_get_criticalr  r   s   &r   get_criticalX509Extension.get_critical  s     //@@r   c                   V ^8  d   QhRR/# r  r   )r   s   "r   r   r    s       r   c                    \         P                  ! V P                  4      p\         P                  ! V4      p\         P                  ! V4      pV\
        P                  8w  d   \
        P                  ! V4      # R# )z
Returns the short type name of this X.509 extension.

The result is a byte string such as :py:const:`b"basicConstraints"`.

:return: The short type name.
:rtype: :py:data:`bytes`

.. versionadded:: 0.12
s   UNDEF)rQ   r  r  r`  r'  rW   r\   r   )r   objr  bufs   &   r   get_short_nameX509Extension.get_short_name  sV     ,,T__=s# ooc"$));;s##r   c                   V ^8  d   QhRR/# r  r   )r   s   "r   r   r    s     : :% :r   c                   \         P                  ! V P                  4      p\        P                  ! RV4      p\         P
                  ! V4      p\         P                  ! V4      p\        P                  ! W44      R,          # )z
Returns the data of the X509 extension, encoded as ASN.1.

:return: The ASN.1 encoded data of this X509 extension.
:rtype: :py:data:`bytes`

.. versionadded:: 0.12
r|   rc   )rQ   X509_EXTENSION_get_datar  rW   r}   r   r~   rH   )r   octet_resultr   char_resultresult_lengths   &    r   get_dataX509Extension.get_data  s\     33DOOD		.,?00?//>{{;6q99r   )r  NN)rA   rB   rC   rD   rE   r   propertyr-  rQ   	GEN_EMAILGEN_DNSGEN_URIr  __annotations__r  r  r  r  r  rF   r   r   r   r4   r4     sn    
CGJ 
 
 	ee2I.  ,3A,: :r   zPCSR support in pyOpenSSL is deprecated. You should use the APIs in cryptography.c                      ] tR tRtRtR R ltR R lt]R R l4       tR	 R
 lt	R R lt
R R ltR R ltR R ltR R ltR R ltR R ltR R ltRtR# )r6   i  z~
An X.509 certificate signing requests.

.. deprecated:: 24.2.0
   Use `cryptography.x509.CertificateSigningRequest` instead.
c                   V ^8  d   QhRR/# r   r   )r   s   "r   r   X509Req.__annotate__  s      $ r   c                	    \         P                  ! 4       p\        P                  ! V\         P                  4      V n        V P                  ^ 4       R# r   N)rQ   X509_REQ_newrW   r]   X509_REQ_free_reqset_version)r   reqs   & r   r   X509Req.__init__  s6    !GGC!3!34	r   c                   V ^8  d   QhRR/# )r   r   x509.CertificateSigningRequestr   )r   s   "r   r   r    s     & &!? &r   c                >    ^ RI Hp \        \        V 4      pV! V4      # )z
Export as a ``cryptography`` certificate signing request.

:rtype: ``cryptography.x509.CertificateSigningRequest``

.. versionadded:: 17.1.0
)load_der_x509_csr)cryptography.x509r  "_dump_certificate_request_internalr-   )r   r  r   s   &  r   to_cryptographyX509Req.to_cryptography  s     	80E %%r   c                    V ^8  d   QhRRRR/# )r   
crypto_reqr  r   r6   r   )r   s   "r   r   r    s      F F7F	Fr   c                    \        V\        P                  4      '       g   \        R4      h^ RIHp VP                  VP                  4      p\        \        V4      # )z
Construct based on a ``cryptography`` *crypto_req*.

:param crypto_req: A ``cryptography`` X.509 certificate signing request
:type crypto_req: ``cryptography.x509.CertificateSigningRequest``

:rtype: X509Req

.. versionadded:: 17.1.0
z%Must be a certificate signing requestr   )
rm   r    CertificateSigningRequestrn   r   r   r   r   "_load_certificate_request_internalr-   )r   r  r   r   s   &&  r   from_cryptographyX509Req.from_cryptography  sG     *d&D&DEECDDI%%hll31-EEr   c                    V ^8  d   QhRRRR/# r   r   r3   r   rk   r   )r   s   "r   r   r    s     
) 
)t 
) 
)r   c                x    \         P                  ! V P                  VP                  4      p\	        V^8H  4       R# )z
Set the public key of the certificate signing request.

:param pkey: The public key to use.
:type pkey: :py:class:`PKey`

:return: ``None``
N)rQ   X509_REQ_set_pubkeyr  r   r[   r   r   rq   s   && r   
set_pubkeyX509Req.set_pubkey  s*     --diiD

a(r   c                   V ^8  d   QhRR/# r   r   r3   r   )r   s   "r   r   r    s      D r   c                D   \         P                  \         4      p\        P                  ! V P                  4      Vn        \        VP
                  \        P                  8g  4       \        P                  ! VP
                  \        P                  4      Vn        RVn        V# )zk
Get the public key of the certificate signing request.

:return: The public key.
:rtype: :py:class:`PKey`
T)r3   __new__rQ   X509_REQ_get_pubkeyr  r   r[   rW   r\   r]   r   r   r   s   & r   
get_pubkeyX509Req.get_pubkey  sf     ||D!--dii8


dii/0WWTZZ););<
 r   c                    V ^8  d   QhRRRR/# r   versionr=   r   rk   r   )r   s   "r   r   r  	  s     ) )3 )4 )r   c                    \        V\        4      '       g   \        R4      hV^ 8w  d   \        R4      h\        P
                  ! V P                  V4      p\        V^8H  4       R# )z
Set the version subfield (RFC 2986, section 4.1) of the certificate
request.

:param int version: The version number.
:return: ``None``
zversion must be an intz9Invalid version. The only valid version for X509Req is 0.N)rm   r=   rn   rp   rQ   X509_REQ_set_versionr  r[   )r   r  rq   s   && r   r  X509Req.set_version	  sX     '3''455a<K  ..tyy'B

a(r   c                   V ^8  d   QhRR/# r   r   )r   s   "r   r   r    s     4 4S 4r   c                B    \         P                  ! V P                  4      # )z
Get the version subfield (RFC 2459, section 4.1.2.1) of the certificate
request.

:return: The value of the version subfield.
:rtype: :py:class:`int`
)rQ   X509_REQ_get_versionr  r   s   &r   get_versionX509Req.get_version  s     ((33r   c                   V ^8  d   QhRR/# r   r   r5   r   )r   s   "r   r   r  $  s      X r   c                    \         P                  \         4      p\        P                  ! V P                  4      Vn        \        VP
                  \        P                  8g  4       Wn	        V# )a  
Return the subject of this certificate signing request.

This creates a new :class:`X509Name` that wraps the underlying subject
name field on the certificate signing request. Modifying it will modify
the underlying signing request, and will have the effect of modifying
any other :class:`X509Name` that refers to this subject.

:return: The subject of this certificate signing request.
:rtype: :class:`X509Name`
)
r5   r  rQ   X509_REQ_get_subject_namer  r   r[   rW   r\   _ownerr   s   & r   get_subjectX509Req.get_subject$  sK     )33DII>


dii/0 r   c                    V ^8  d   QhRRRR/# r   
extensionszIterable[X509Extension]r   rk   r   )r   s   "r   r   r  :  s     ) ))@ )T )r   c                   \         P                  ! R\        ^R7       \        P                  ! 4       p\        V\        P                  8g  4       \        P                  ! V\        P                  4      pV FD  p\        V\        4      '       g   \        R4      h\        P                  ! W#P                  4       KF  	  \        P                  ! V P                   V4      p\        V^8H  4       R# )z
Add extensions to the certificate signing request.

:param extensions: The X.509 extensions to add.
:type extensions: iterable of :py:class:`X509Extension`
:return: ``None``
This API is deprecated and will be removed in a future version of pyOpenSSL. You should use pyca/cryptography's X.509 APIs instead.
stacklevel+One of the elements is not an X509ExtensionN)warningswarnDeprecationWarningrQ   sk_X509_EXTENSION_new_nullr[   rW   r\   r]   sk_X509_EXTENSION_freerm   r4   rp   sk_X509_EXTENSION_pushr  X509_REQ_add_extensionsr  )r   r%  stackextrj  s   &&   r   add_extensionsX509Req.add_extensions:  s     	& 	
 //1*+t::;Cc=11 !NOO ''~~>  11$))UC

a(r   c                   V ^8  d   QhRR/# )r   r   zlist[X509Extension]r   )r   s   "r   r   r  [  s     $ $ 3 $r   c                   \         P                  ! R\        ^R7       . p\        P                  ! V P
                  4      p\        P                  ! VR 4      p\        \        P                  ! V4      4       F  p\        P                  \        4      p\        P                  ! \        P                  ! W#4      4      p\        P                  ! V\        P                  4      Vn        VP!                  V4       K  	  V# )z
Get X.509 extensions in the certificate signing request.

:return: The X.509 extensions in this request.
:rtype: :py:class:`list` of :py:class:`X509Extension` objects.

.. versionadded:: 0.15
r'  r(  c                v    \         P                  ! V \        P                  ! \         P                  R 4      4      # )r  )rQ   sk_X509_EXTENSION_pop_freerW   	addressof_original_lib)xs   &r   r   (X509Req.get_extensions.<locals>.<lambda>r  s'    d55t113HIr   )r+  r,  r-  rQ   X509_REQ_get_extensionsr  rW   r]   r\  sk_X509_EXTENSION_numr4   r  X509_EXTENSION_dupsk_X509_EXTENSION_valuer  r  r   )r   extsnative_exts_objrf  r3  r  s   &     r   get_extensionsX509Req.get_extensions[  s     	& 	
 66tyyA''
 t11/BCA''6C//,,_@I "WWY0H0HICNKK D r   c               $    V ^8  d   QhRRRRRR/# r   r   r3   digestr   r   rk   r   )r   s   "r   r   r    s!     ) ) )s )t )r   c                l   VP                   '       d   \        R4      hVP                  '       g   \        R4      h\        P                  ! \        V4      4      pV\        P                  8X  d   \        R4      h\        P                  ! V P                  VP                  V4      p\        V^ 8  4       R# )a!  
Sign the certificate signing request with this key and digest type.

:param pkey: The key pair to sign with.
:type pkey: :py:class:`PKey`
:param digest: The name of the message digest to use for the signature,
    e.g. :py:data:`"sha256"`.
:type digest: :py:class:`str`
:return: ``None``
zKey has only public partKey is uninitializedNo such digest methodN)r   rp   r   rQ   EVP_get_digestbynamerY  rW   r\   X509_REQ_signr  r   r[   )r   r   rH  
digest_objsign_results   &&&  r   signX509Req.sign  s     788   344..|F/CD
"455((DJJ
Ka(r   c                    V ^8  d   QhRRRR/# )r   r   r3   r   r   r   )r   s   "r   r   r    s      4 D r   c                    \        V\        4      '       g   \        R4      h\        P                  ! V P
                  VP                  4      pV^ 8:  d   \        4        V# )a  
Verifies the signature on this certificate signing request.

:param PKey key: A public key.

:return: ``True`` if the signature is correct.
:rtype: bool

:raises OpenSSL.crypto.Error: If the signature is invalid or there is a
    problem verifying the signature.
pkey must be a PKey instance)rm   r3   rn   rQ   X509_REQ_verifyr  r   r   )r   r   r   s   && r   verifyX509Req.verify  sI     $%%:;;%%dii<Q; "r   )r  N)rA   rB   rC   rD   rE   r   r  r  r  r  r  r  r  r!  r4  rD  rP  rV  rF   r   r   r   r6   r6     s[    
& F F*
))"4,)B$L)0 r   c                     ] tR tRtRtR R lt]R R l4       tR R lt]R	 R
 l4       t	R R lt
R R ltR R ltR R ltR R ltR R ltR R ltR R ltR R ltR R ltR R  ltR! R" ltR# R$ ltR% R& ltR' R( ltR) R* ltR+ R, ltR- R. ltR/ R0 ltR1 R2 ltR3 R4 ltR5 R6 ltR7 R8 lt R9 R: lt!R; R< lt"R= R> lt#R? R@ lt$RA RB lt%RCt&RD# )Er1   i  z
An X.509 certificate.
c                   V ^8  d   QhRR/# r   r   )r   s   "r   r   X509.__annotate__  s     ; ;$ ;r   c                	    \         P                  ! 4       p\        V\        P                  8g  4       \        P
                  ! V\         P                  4      V n        \        4       V n	        \        4       V n
        R # r   )rQ   X509_newr[   rW   r\   r]   	X509_freer  r   _issuer_invalidator_subject_invalidator)r   r    s   & r   r   X509.__init__  sJ    }}		)*WWT4>>2
#7#9 $8$:!r   c                    V ^8  d   QhRRRR/# )r   r    r   r   r1   r   )r   s   "r   r   rZ    s      c d r   c                	    V P                  V 4      p\        P                  ! V\        P                  4      Vn        \        4       Vn        \        4       Vn        V# r   )	r  rW   r]   rQ   r]  r  r   r^  r_  )r   r    certs   && r   _from_raw_x509_ptrX509._from_raw_x509_ptr  sA    {{3WWT4>>2
#7#9 $8$:!r   c                   V ^8  d   QhRR/# )r   r   x509.Certificater   )r   s   "r   r   rZ    s     . .!1 .r   c                >    ^ RI Hp \        \        V 4      pV! V4      # )zp
Export as a ``cryptography`` certificate.

:rtype: ``cryptography.x509.Certificate``

.. versionadded:: 17.1.0
)load_der_x509_certificate)r  ri  dump_certificater-   )r   ri  r   s   &  r   r  X509.to_cryptography  s     	@}d3(--r   c                    V ^8  d   QhRRRR/# )r   crypto_certrg  r   r1   r   )r   s   "r   r   rZ    s     4 4,< 4 4r   c                    \        V\        P                  4      '       g   \        R4      h^ RIHp VP                  VP                  4      p\        \        V4      # )z
Construct based on a ``cryptography`` *crypto_cert*.

:param crypto_key: A ``cryptography`` X.509 certificate.
:type crypto_key: ``cryptography.x509.Certificate``

:rtype: X509

.. versionadded:: 17.1.0
zMust be a certificater  )
rm   r    Certificatern   r   r   r   r   load_certificater-   )r   rm  r   r   s   &&  r   r  X509.from_cryptography  sG     +t'7'788344I&&x||4s33r   c                    V ^8  d   QhRRRR/# r  r   )r   s   "r   r   rZ    s     I I3 I4 Ir   c                    \        V\        4      '       g   \        R4      h\        \        P
                  ! V P                  V4      ^8H  4       R# )z
Set the version number of the certificate. Note that the
version value is zero-based, eg. a value of 0 is V1.

:param version: The version number of the certificate.
:type version: :py:class:`int`

:return: ``None``
zversion must be an integerN)rm   r=   rn   r[   rQ   X509_set_versionr  )r   r  s   &&r   r  X509.set_version  s;     '3''899--djj'BaGHr   c                   V ^8  d   QhRR/# r   r   )r   s   "r   r   rZ    s     1 1S 1r   c                B    \         P                  ! V P                  4      # )zx
Return the version number of the certificate.

:return: The version number of the certificate.
:rtype: :py:class:`int`
)rQ   X509_get_versionr  r   s   &r   r  X509.get_version  s     $$TZZ00r   c                   V ^8  d   QhRR/# r  r   )r   s   "r   r   rZ    s      D r   c                J   \         P                  \         4      p\        P                  ! V P                  4      Vn        VP
                  \        P                  8X  d   \        4        \        P                  ! VP
                  \        P                  4      Vn        RVn        V# )z[
Get the public key of the certificate.

:return: The public key.
:rtype: :py:class:`PKey`
T)r3   r  rQ   X509_get_pubkeyr  r   rW   r\   r   r]   r   r   r   s   & r   r  X509.get_pubkey  sg     ||D!))$**5
::" "WWTZZ););<
 r   c                    V ^8  d   QhRRRR/# r  r   )r   s   "r   r   rZ    s     ) )t ) )r   c                    \        V\        4      '       g   \        R4      h\        P                  ! V P
                  VP                  4      p\        V^8H  4       R# )z}
Set the public key of the certificate.

:param pkey: The public key.
:type pkey: :py:class:`PKey`

:return: :py:data:`None`
rT  N)rm   r3   rn   rQ   X509_set_pubkeyr  r   r[   r  s   && r   r  X509.set_pubkey  sC     $%%:;;))$**djjA

a(r   c               $    V ^8  d   QhRRRRRR/# rG  r   )r   s   "r   r   rZ    s!     ) ) )s )t )r   c                   \        V\        4      '       g   \        R4      hVP                  '       d   \	        R4      hVP
                  '       g   \	        R4      h\        P                  ! \        V4      4      pV\        P                  8X  d   \	        R4      h\        P                  ! V P                  VP                  V4      p\        V^ 8  4       R# )z
Sign the certificate with this key and digest type.

:param pkey: The key to sign with.
:type pkey: :py:class:`PKey`

:param digest: The name of the message digest to use.
:type digest: :py:class:`str`

:return: :py:data:`None`
rT  zKey only has public partrJ  rK  N)rm   r3   rn   r   rp   r   rQ   rL  rY  rW   r\   	X509_signr  r   r[   )r   r   rH  evp_mdrO  s   &&&  r   rP  	X509.sign  s     $%%:;;788   344**<+?@TYY455nnTZZVDa(r   c                   V ^8  d   QhRR/# r  r   )r   s   "r   r   rZ  7  s     1 1 1r   c                   \         P                  ! V P                  4      p\        P                  ! R4      p\         P
                  ! V\        P                  \        P                  V4       \         P                  ! V^ ,          4      pV\         P                  8X  d   \        R4      h\        P                  ! \         P                  ! V4      4      # )z
Return the signature algorithm used in the certificate.

:return: The name of the algorithm.
:rtype: :py:class:`bytes`

:raises ValueError: If the signature algorithm is undefined.

.. versionadded:: 0.13
zASN1_OBJECT **zUndefined signature algorithm)rQ   X509_get0_tbs_sigalgr  rW   rX   X509_ALGOR_get0r\   r`  rZ  rp   r   
OBJ_nid2ln)r   sig_algalgr  s   &   r   get_signature_algorithmX509.get_signature_algorithm7  s     ++DJJ7hh'(S$))TYY@s1v&$.. <=={{4??3/00r   c                    V ^8  d   QhRRRR/# )r   digest_namer   r   ra   r   )r   s   "r   r   rZ  J  s     
 
# 
% 
r   c                $   \         P                  ! \        V4      4      pV\        P                  8X  d   \        R4      h\        P                  ! R\         P                  4      p\        P                  ! R^4      p\        V4      V^ &   \         P                  ! V P                  W#V4      p\        V^8H  4       RP                  \        P                  ! W4^ ,          4       Uu. uF  p\        V4      P                  4       NK  	  up4      # u upi )z
Return the digest of the X509 object.

:param digest_name: The name of the digest algorithm to use.
:type digest_name: :py:class:`str`

:return: The digest of the object, formatted as
    :py:const:`b":"`-delimited hex pairs.
:rtype: :py:class:`bytes`
rK  zunsigned char[]zunsigned int[]   :)rQ   rL  rY  rW   r\   rp   rX   EVP_MAX_MD_SIZErZ   X509_digestr  r[   r  rH   r   upper)r   r  rH  re   r  digest_resultchs   &&     r   rH  X509.digestJ  s     **<+DETYY455!2D4H4HI!115}-a((JJ}
 	*+yy ++m15EFFB "##%F
 	
s   $"Dc                   V ^8  d   QhRR/# r   r   )r   s   "r   r   rZ  i  s     7 73 7r   c                B    \         P                  ! V P                  4      # )za
Return the hash of the X509 subject.

:return: The hash of the subject.
:rtype: :py:class:`int`
)rQ   X509_subject_name_hashr  r   s   &r   subject_name_hashX509.subject_name_hashi  s     **4::66r   c                    V ^8  d   QhRRRR/# )r   serialr=   r   rk   r   )r   s   "r   r   rZ  r  s     ) ) ) )r   c                   \        V\        4      '       g   \        R4      h\        V4      R,          pVP	                  R4      p\
        P                  ! R4      p\        P                  ! WC4      p\        V\
        P                  8g  4       \        P                  ! V^ ,          \
        P                  4      p\        P                  ! V^ ,          4       \        V\
        P                  8g  4       \
        P                  ! V\        P                  4      p\        P                  ! V P                   V4      p\        V^8H  4       R# )z
Set the serial number of the certificate.

:param serial: The new serial number.
:type serial: :py:class:`int`

:return: :py:data`None`
zserial must be an integer:r   NNr&  zBIGNUM**N)rm   r=   rn   hexrc  rW   rX   rQ   	BN_hex2bnr[   r\   BN_to_ASN1_INTEGERr   r]   ASN1_INTEGER_freeX509_set_serialNumberr  )r   r  
hex_serialhex_serial_bytesbignum_serialr   asn1_serialrq   s   &&      r   set_serial_numberX509.set_serial_numberr  s     &#&&788[_
%,,W5, @$))+,--mA.>		J]1%&tyy01ggk4+A+AB//

KH

a(r   c                   V ^8  d   QhRR/# r   r   )r   s   "r   r   rZ    s     ( (3 (r   c                   \         P                  ! V P                  4      p\         P                  ! V\        P
                  4      p \         P                  ! V4      p \        P                  ! V4      p\        V^4      pV\         P                  ! V4       \         P                  ! V4       #   \         P                  ! T4       i ; i  \         P                  ! T4       i ; i)zX
Return the serial number of this certificate.

:return: The serial number.
:rtype: int
)rQ   X509_get_serialNumberr  ASN1_INTEGER_to_BNrW   r\   	BN_bn2hexr   r=   rs  r   )r   r  r  r  hexstring_serialr  s   &     r   get_serial_numberX509.get_serial_number  s     00<//TYYG		(6J.#';;z#: -r2!!*-LL' !!*-LL's$   C	 #B. C	 .CC	 	C!c                    V ^8  d   QhRRRR/# r   amountr=   r   rk   r   )r   s   "r   r   rZ    s     / /# /$ /r   c                    \        V\        4      '       g   \        R4      h\        P                  ! V P
                  4      p\        P                  ! W!4       R# )z
Adjust the time stamp on which the certificate stops being valid.

:param int amount: The number of seconds by which to adjust the
    timestamp.
:return: ``None``
amount must be an integerN)rm   r=   rn   rQ   X509_getm_notAfterr  X509_gmtime_adj)r   r  notAfters   && r   gmtime_adj_notAfterX509.gmtime_adj_notAfter  s?     &#&&788**4::6X.r   c                    V ^8  d   QhRRRR/# r  r   )r   s   "r   r   rZ    s     0 03 04 0r   c                    \        V\        4      '       g   \        R4      h\        P                  ! V P
                  4      p\        P                  ! W!4       R# )z
Adjust the timestamp on which the certificate starts being valid.

:param amount: The number of seconds by which to adjust the timestamp.
:return: ``None``
r  N)rm   r=   rn   rQ   X509_getm_notBeforer  r  )r   r  	notBefores   && r   gmtime_adj_notBeforeX509.gmtime_adj_notBefore  s?     &#&&788,,TZZ8	Y/r   c                   V ^8  d   QhRR/# r   r   )r   s   "r   r   rZ    s     " "T "r   c                <   V P                  4       pVf   \        R4      hVP                  R4      p\        P                  P	                  VR4      p\        P
                  P                  p\        P                  P                  V4      P                  RR7      pW58  # )z
Check whether the certificate has expired.

:return: ``True`` if the certificate has expired, ``False`` otherwise.
:rtype: bool
NzUnable to determine notAfterrT  z%Y%m%d%H%M%SZ)tzinfo)	get_notAfterrp   r(  datetimestrptimetimezoneutcnowreplace)r   
time_bytestime_string	not_afterUTCutcnows   &     r   has_expiredX509.has_expired  s     &&(
;<< ''0%%..{OL	##""&&s+3343@!!r   c                    V ^8  d   QhRRRR/# )r   whichr   r   rI   r   )r   s   "r   r   rZ    s     1 1 1 1r   c                	8    \        V! V P                  4      4      # r   )r   r  )r   r  s   &&r   _get_boundary_timeX509._get_boundary_time  s    eDJJ/00r   c                   V ^8  d   QhRR/# r   r   rI   r   )r   s   "r   r   rZ    s     A A| Ar   c                @    V P                  \        P                  4      # )z
Get the timestamp at which the certificate starts being valid.

The timestamp is formatted as an ASN.1 TIME::

    YYYYMMDDhhmmssZ

:return: A timestamp string, or ``None`` if there is none.
:rtype: bytes or NoneType
)r  rQ   r  r   s   &r   get_notBeforeX509.get_notBefore  s     &&t'?'?@@r   c               $    V ^8  d   QhRRRRRR/# )r   r  zCallable[..., Any]rj   ra   r   rk   r   )r   s   "r   r   rZ    s$     7 7'7/47	7r   c                	:    \        V! V P                  4      V4      # r   )rr   r  )r   r  rj   s   &&&r   _set_boundary_timeX509._set_boundary_time  s     eDJJ/66r   c                    V ^8  d   QhRRRR/# r   rj   ra   r   rk   r   )r   s   "r   r   rZ    s     G G% GD Gr   c                B    V P                  \        P                  V4      # )z
Set the timestamp at which the certificate starts being valid.

The timestamp is formatted as an ASN.1 TIME::

    YYYYMMDDhhmmssZ

:param bytes when: A timestamp string.
:return: ``None``
)r  rQ   r  r   rj   s   &&r   set_notBeforeX509.set_notBefore  s     &&t'?'?FFr   c                   V ^8  d   QhRR/# r  r   )r   s   "r   r   rZ    s     @ @l @r   c                @    V P                  \        P                  4      # )z
Get the timestamp at which the certificate stops being valid.

The timestamp is formatted as an ASN.1 TIME::

    YYYYMMDDhhmmssZ

:return: A timestamp string, or ``None`` if there is none.
:rtype: bytes or NoneType
)r  rQ   r  r   s   &r   r  X509.get_notAfter  s     &&t'>'>??r   c                    V ^8  d   QhRRRR/# r  r   )r   s   "r   r   rZ    s     F F F4 Fr   c                B    V P                  \        P                  V4      # )z
Set the timestamp at which the certificate stops being valid.

The timestamp is formatted as an ASN.1 TIME::

    YYYYMMDDhhmmssZ

:param bytes when: A timestamp string.
:return: ``None``
)r  rQ   r  r  s   &&r   set_notAfterX509.set_notAfter  s     &&t'>'>EEr   c                    V ^8  d   QhRRRR/# )r   r  r   r   r5   r   )r   s   "r   r   rZ  
  s     	 	s 	x 	r   c                	    \         P                  \         4      pV! V P                  4      Vn        \	        VP                  \
        P                  8g  4       Wn        V# r   )r5   r  r  r   r[   rW   r\   r   )r   r  r   s   && r   	_get_nameX509._get_name
  sC    )4::&


dii/0 r   c               $    V ^8  d   QhRRRRRR/# )r   r  r   r   r5   r   rk   r   )r   s   "r   r   rZ    s!     ) )s )( )t )r   c                	    \        V\        4      '       g   \        R 4      hV! V P                  VP                  4      p\        V^8H  4       R# )zname must be an X509NameN)rm   r5   rn   r  r   r[   )r   r  r   rq   s   &&& r   	_set_nameX509._set_name  s;    $))6774::tzz2

a(r   c                   V ^8  d   QhRR/# r  r   )r   s   "r   r   rZ    s      H r   c                z    V P                  \        P                  4      pV P                  P	                  V4       V# )ae  
Return the issuer of this certificate.

This creates a new :class:`X509Name` that wraps the underlying issuer
name field on the certificate. Modifying it will modify the underlying
certificate, and will have the effect of modifying any other
:class:`X509Name` that refers to this issuer.

:return: The issuer of this certificate.
:rtype: :class:`X509Name`
)r  rQ   X509_get_issuer_namer^  r   r   s   & r   
get_issuerX509.get_issuer  s1     ~~d778  $$T*r   c                    V ^8  d   QhRRRR/# )r   r  r5   r   rk   r   )r   s   "r   r   rZ  +  s     
) 
) 
)d 
)r   c                z    V P                  \        P                  V4       V P                  P	                  4        R# )zw
Set the issuer of this certificate.

:param issuer: The issuer.
:type issuer: :py:class:`X509Name`

:return: ``None``
N)r  rQ   X509_set_issuer_namer^  r   )r   r  s   &&r   
set_issuerX509.set_issuer+  s*     	t00&9  &&(r   c                   V ^8  d   QhRR/# r  r   )r   s   "r   r   rZ  7  s      X r   c                z    V P                  \        P                  4      pV P                  P	                  V4       V# )ai  
Return the subject of this certificate.

This creates a new :class:`X509Name` that wraps the underlying subject
name field on the certificate. Modifying it will modify the underlying
certificate, and will have the effect of modifying any other
:class:`X509Name` that refers to this subject.

:return: The subject of this certificate.
:rtype: :class:`X509Name`
)r  rQ   X509_get_subject_namer_  r   r   s   & r   r!  X509.get_subject7  s1     ~~d889!!%%d+r   c                    V ^8  d   QhRRRR/# )r   r  r5   r   rk   r   )r   s   "r   r   rZ  G  s     
* 
*8 
* 
*r   c                z    V P                  \        P                  V4       V P                  P	                  4        R# )z{
Set the subject of this certificate.

:param subject: The subject.
:type subject: :py:class:`X509Name`

:return: ``None``
N)r  rQ   X509_set_subject_namer_  r   )r   r  s   &&r   set_subjectX509.set_subjectG  s*     	t117;!!'')r   c                   V ^8  d   QhRR/# r   r   )r   s   "r   r   rZ  S  s     	3 	3S 	3r   c                B    \         P                  ! V P                  4      # )z
Get the number of extensions on this certificate.

:return: The number of extensions.
:rtype: :py:class:`int`

.. versionadded:: 0.12
)rQ   X509_get_ext_countr  r   s   &r   get_extension_countX509.get_extension_countS  s     &&tzz22r   c                    V ^8  d   QhRRRR/# r$  r   )r   s   "r   r   rZ  ^  s     - -)@ -T -r   c                   \         P                  ! R\        ^R7       V F^  p\        V\        4      '       g   \        R4      h\        P                  ! V P                  VP                  R4      p\        V^8H  4       K`  	  R# )z
Add extensions to the certificate.

:param extensions: The extensions to add.
:type extensions: An iterable of :py:class:`X509Extension` objects.
:return: ``None``
r'  r(  r*  NrU  )r+  r,  r-  rm   r4   rp   rQ   X509_add_extr  r  r[   )r   r%  r3  rj  s   &&  r   r4  X509.add_extensions^  sj     	& 	
 Cc=11 !NOO**4::s~~rJJJ!O, r   c                    V ^8  d   QhRRRR/# )r   indexr=   r   r4   r   )r   s   "r   r   rZ  w  s      3 = r   c                   \         P                  ! R\        ^R7       \        P	                  \        4      p\
        P                  ! V P                  V4      Vn        VP                  \        P                  8X  d   \        R4      h\
        P                  ! VP                  4      p\        P                  ! V\
        P                  4      Vn        V# )a  
Get a specific extension of the certificate by index.

Extensions on a certificate are kept in order. The index
parameter selects which extension will be returned.

:param int index: The index of the extension to retrieve.
:return: The extension at the specified index.
:rtype: :py:class:`X509Extension`
:raises IndexError: If the extension index was out of bounds.

.. versionadded:: 0.12
r'  r(  zextension index out of bounds)r+  r,  r-  r4   r  rQ   X509_get_extr  r  rW   r\   
IndexErrorr@  r]   r  )r   r  r3  r  s   &&  r   get_extensionX509.get_extensionw  s     	& 	
 ##M2**4::u=>>TYY&<==++CNN;	D,D,DE
r   )r^  r_  r  N)'rA   rB   rC   rD   rE   r   r  rd  r  r  r  r  r  r  rP  r  rH  r  r  r  r  r  r  r  r  r  r  r  r  r  r  r  r  r!  r
  r  r4  r  rF   r   r   r   r1   r1     s    ;  . 4 4&I1))81&
>7)8((/0""1A7
G@F	) 
) 
*	3-2 r   c                  p   ] tR tRt$ Rt]P                  tR]R&   ]P                  t
R]R&   ]P                  tR]R&   ]P                  tR]R&   ]P                  tR]R&   ]P"                  tR]R	&   ]P&                  tR]R
&   ]P*                  tR]R&   ]P.                  tR]R&   ]P2                  tR]R&   RtR# )r:   i  z
Flags for X509 verification, used to change the behavior of
:class:`X509Store`.

See `OpenSSL Verification Flags`_ for details.

.. _OpenSSL Verification Flags:
    https://www.openssl.org/docs/manmaster/man3/X509_VERIFY_PARAM_set_flags.html
r=   	CRL_CHECKCRL_CHECK_ALLIGNORE_CRITICALX509_STRICTALLOW_PROXY_CERTSPOLICY_CHECKEXPLICIT_POLICYINHIBIT_MAPCHECK_SS_SIGNATUREPARTIAL_CHAINr   N)rA   rB   rC   rD   rE   rQ   X509_V_FLAG_CRL_CHECKr  r  X509_V_FLAG_CRL_CHECK_ALLr  X509_V_FLAG_IGNORE_CRITICALr  X509_V_FLAG_X509_STRICTr   X509_V_FLAG_ALLOW_PROXY_CERTSr!  X509_V_FLAG_POLICY_CHECKr"  X509_V_FLAG_EXPLICIT_POLICYr#  X509_V_FLAG_INHIBIT_MAPr$  X509_V_FLAG_CHECK_SS_SIGNATUREr%  X509_V_FLAG_PARTIAL_CHAINr&  rF   r   r   r   r:   r:     s     //Is/77M37;;OS;33K3!??s?55L#5;;OS;33K3"AAA77M37r   c                  f    ] tR tRtRtR R ltR R ltR R ltR	 R
 ltR R lt	RR R llt
RtR# )r7   i  a  
An X.509 store.

An X.509 store is used to describe a context in which to verify a
certificate. A description of a context may include a set of certificates
to trust, a set of certificate revocation lists, verification flags and
more.

An X.509 store, being only a description, cannot be used by itself to
verify a certificate. To carry out the actual verification process, see
:class:`X509StoreContext`.
c                   V ^8  d   QhRR/# r   r   )r   s   "r   r   X509Store.__annotate__  s     ; ;$ ;r   c                	    \         P                  ! 4       p\        P                  ! V\         P                  4      V n        R # r   )rQ   X509_STORE_newrW   r]   X509_STORE_free_storer   stores   & r   r   X509Store.__init__  s(    ##%ggeT%9%9:r   c                    V ^8  d   QhRRRR/# )r   rc  r1   r   rk   r   )r   s   "r   r   r3    s     " "T "d "r   c                    \        V\        4      '       g   \        4       h\        P                  ! V P
                  VP                  4      p\        V^8H  4       R# )a  
Adds a trusted certificate to this store.

Adding a certificate with this method adds this certificate as a
*trusted* certificate.

:param X509 cert: The certificate to add to this store.

:raises TypeError: If the certificate is not an :class:`X509`.

:raises OpenSSL.crypto.Error: If OpenSSL was unhappy with your
    certificate.

:return: ``None`` if the certificate was added successfully.
N)rm   r1   rn   rQ   X509_STORE_add_certr7  r  r[   )r   rc  r   s   && r   add_certX509Store.add_cert  s?      $%%+&&t{{DJJ?q!r   c                    V ^8  d   QhRRRR/# )r   crlzx509.CertificateRevocationListr   rk   r   )r   s   "r   r   r3    s     H H9 Hd Hr   c                   \        V\        P                  4      '       d   ^ RIHp \        VP                  VP                  4      4      p\        P                  ! V\        P                  4      p\        V\        P                  8g  4       \        P                  ! V\        P                  4      pM\        R4      h\        \        P                   ! V P"                  V4      ^ 8g  4       R# )a  
Add a certificate revocation list to this store.

The certificate revocation lists added to a store will only be used if
the associated flags are configured to check certificate revocation
lists.

.. versionadded:: 16.1.0

:param crl: The certificate revocation list to add to this store.
:type crl: ``cryptography.x509.CertificateRevocationList``
:return: ``None`` if the certificate revocation list was added
    successfully.
r  z?CRL must be of type cryptography.x509.CertificateRevocationListN)rm   r    CertificateRevocationListr   r   r_   r   r   rQ   d2i_X509_CRL_biorW   r\   r[   r]   X509_CRL_freern   X509_STORE_add_crlr7  )r   rA  r   rM   openssl_crls   &&   r   add_crlX509Store.add_crl  s     c499::Ms//=>C//TYY?KK49945''+t'9'9:C> 
 	//SAQFGr   c                    V ^8  d   QhRRRR/# )r   flagsr=   r   rk   r   )r   s   "r   r   r3    s     L Ls Lt Lr   c                `    \        \        P                  ! V P                  V4      ^ 8g  4       R# )ab  
Set verification flags to this store.

Verification flags can be combined by oring them together.

.. note::

  Setting a verification flag sometimes requires clients to add
  additional information to the store, otherwise a suitable error will
  be raised.

  For example, in setting flags to enable CRL checking a
  suitable CRL must be added to the store otherwise an error will be
  raised.

.. versionadded:: 16.1.0

:param int flags: The verification flags to set on this store.
    See :class:`X509StoreFlags` for available constants.
:return: ``None`` if the verification flags were successfully set.
N)r[   rQ   X509_STORE_set_flagsr7  )r   rK  s   &&r   	set_flagsX509Store.set_flags  s"    , 	11$++uEJKr   c                    V ^8  d   QhRRRR/# )r   vfy_timezdatetime.datetimer   rk   r   )r   s   "r   r   r3    s     M M!2 Mt Mr   c                F   \         P                  ! 4       p\        P                  ! V\         P                  4      p\         P
                  ! V\        P                  ! VP                  4       4      4       \        \         P                  ! V P                  V4      ^ 8g  4       R# )a\  
Set the time against which the certificates are verified.

Normally the current time is used.

.. note::

  For example, you can determine if a certificate was valid at a given
  time.

.. versionadded:: 17.0.0

:param datetime vfy_time: The verification time to set on this store.
:return: ``None`` if the verification time was successfully set.
N)rQ   X509_VERIFY_PARAM_newrW   r]   X509_VERIFY_PARAM_freeX509_VERIFY_PARAM_set_timecalendartimegm	timetupler[   X509_STORE_set1_paramr7  )r   rQ  params   && r   set_timeX509Store.set_time  sm      **,t::;''8??8#5#5#78	
 	224;;F!KLr   Nc               $    V ^8  d   QhRRRRRR/# )r   cafilezStrOrBytesPath | Nonecapathr   rk   r   )r   s   "r   r   r3  &  s(     1# 1#%1# &1# 
	1#r   c                    Vf   \         P                  pM\        V4      pVf   \         P                  pM\        V4      p\        P                  ! V P
                  W4      pV'       g   \        4        R# R# )a  
Let X509Store know where we can find trusted certificates for the
certificate chain.  Note that the certificates have to be in PEM
format.

If *capath* is passed, it must be a directory prepared using the
``c_rehash`` tool included with OpenSSL.  Either, but not both, of
*cafile* or *capath* may be ``None``.

.. note::

  Both *cafile* and *capath* may be set simultaneously.

  Call this method multiple times to add more than one location.
  For example, CA certificates, and certificate revocation list bundles
  may be passed in *cafile* in subsequent calls to this method.

.. versionadded:: 20.0

:param cafile: In which file we can find the certificates (``bytes`` or
               ``unicode``).
:param capath: In which directory we can find the certificates
               (``bytes`` or ``unicode``).

:return: ``None`` if the locations were set successfully.

:raises OpenSSL.crypto.Error: If both *cafile* and *capath* is ``None``
    or the locations could not be set for any reason.

N)rW   r\   _path_bytesrQ   X509_STORE_load_locationsr7  r   )r   r^  r_  load_results   &&& r   load_locationsX509Store.load_locations&  s^    F >YYF (F>YYF (F44KK
  " r   r7  r   )rA   rB   rC   rD   rE   r   r>  rH  rN  r[  rd  rF   r   r   r   r7   r7     s-    ;",H<L0M01# 1#r   c                  2   a  ] tR tRtRtR V 3R lltRtV ;t# )r9   iZ  z
An exception raised when an error occurred while verifying a certificate
using `OpenSSL.X509StoreContext.verify_certificate`.

:ivar certificate: The certificate which caused verificate failure.
:type certificate: :class:`X509`
c               (    V ^8  d   QhRRRRRRRR/# )	r   messager   errorsz	list[Any]certificater1   r   rk   r   )r   s   "r   r   "X509StoreContextError.__annotate__c  s,     ' ''$-'<@'	'r   c                	>   < \         SV `  V4       W n        W0n        R # r   )r	  r   rj  rk  )r   ri  rj  rk  r  s   &&&&r   r   X509StoreContextError.__init__c  s     	!&r   )rk  rj  )rA   rB   rC   rD   rE   r   rF   r>  r?  s   @r   r9   r9   Z  s    ' 'r   c                      ] tR tRtRtRR R llt]R R l4       t]R R	 l4       tR
 R lt	R R lt
R R ltR R ltRtR# )r8   ik  a  
An X.509 store context.

An X.509 store context is used to carry out the actual verification process
of a certificate in a described context. For describing such a context, see
:class:`X509Store`.

:param X509Store store: The certificates which will be trusted for the
    purposes of any verifications.
:param X509 certificate: The certificate to be verified.
:param chain: List of untrusted certificates that may be used for building
    the certificate chain. May be ``None``.
:type chain: :class:`list` of :class:`X509`
Nc               (    V ^8  d   QhRRRRRRRR/# )	r   r9  r7   rk  r1   chainSequence[X509] | Noner   rk   r   )r   s   "r   r   X509StoreContext.__annotate__{  s2     ; ;; ; %	;
 
;r   c                	J    Wn         W n        V P                  V4      V n        R # r   )r7  _cert_build_certificate_stack_chain)r   r9  rk  rq  s   &&&&r   r   X509StoreContext.__init__{  s       
33E:r   c                    V ^8  d   QhRRRR/# )r   certificatesrr  r   rk   r   )r   s   "r   r   rs    s      +	r   c                	6   R  R lpV e   \        V 4      ^ 8X  d   \        P                  # \        P                  ! 4       p\        V\        P                  8g  4       \        P                  ! W!4      pV  F  p\        V\        4      '       g   \        R4      h\        \        P                  ! VP                  4      ^ 8  4       \        P                  ! W#P                  4      ^ 8:  g   Kw  \        P                  ! VP                  4       \        4        K  	  V# )c                    V ^8  d   QhRRRR/# )r   sr   r   rk   r   )r   s   "r   r   ?X509StoreContext._build_certificate_stack.<locals>.__annotate__  s     	! 	!s 	!t 	!r   c                    \        \        P                  ! V 4      4       F/  p\        P                  ! W4      p\        P                  ! V4       K1  	  \        P
                  ! V 4       R # r   )r\  rQ   sk_X509_numsk_X509_valuer]  sk_X509_free)r}  rf  r<  s   &  r   cleanup:X509StoreContext._build_certificate_stack.<locals>.cleanup  sJ     4++A./&&q,q! 0 a r   z+One of the elements is not an X509 instance)rZ   rW   r\   rQ   sk_X509_new_nullr[   r]   rm   r1   rn   X509_up_refr  sk_X509_pushr]  r   )rz  r  r2  rc  s   &   r   rv  )X509StoreContext._build_certificate_stack  s    	! 3|#4#999%%'*+' DdD)) MNND,,TZZ81<=  

3q8tzz*$& ! r   c                    V ^8  d   QhRRRR/# )r   	store_ctxr   r   r9   r   )r   s   "r   r   rs    s     > >3 >3H >r   c                   \         P                  ! \        P                  ! \        P                  ! V 4      4      4      P                  R4      p\        P                  ! V 4      \        P                  ! V 4      V.p\        P                  ! V 4      p\        P                  ! V4      p\        P                  V4      p\        WV4      # )z
Convert an OpenSSL native context error failure into a Python
exception.

When a call to native OpenSSL X509_verify_cert fails, additional
information about the failure can be obtained from the store context.
rT  )rW   r   rQ   X509_verify_cert_error_stringX509_STORE_CTX_get_errorr(  X509_STORE_CTX_get_error_depthX509_STORE_CTX_get_current_certX509_dupr1   rd  r9   )r  ri  rj  r  ru  pycerts   &     r   _exception_from_context(X509StoreContext._exception_from_context  s     ++..--i8
 &/	 	 )))4//	:
 44Y?e$((/$Wf==r   c                   V ^8  d   QhRR/# r7  r   )r   s   "r   r   rs    s      S r   c                   \         P                  ! 4       p\        V\        P                  8g  4       \        P
                  ! V\         P                  4      p\         P                  ! WP                  P                  V P                  P                  V P                  4      p\        V^8H  4       \         P                  ! V4      pV^ 8:  d   V P                  V4      hV# )a  
Verifies the certificate and runs an X509_STORE_CTX containing the
results.

:raises X509StoreContextError: If an error occurred when validating a
  certificate in the context. Sets ``certificate`` attribute to
  indicate which certificate caused the error.
)rQ   X509_STORE_CTX_newr[   rW   r\   r]   X509_STORE_CTX_freeX509_STORE_CTX_initr7  ru  r  rw  X509_verify_certr  )r   r  rw   s   &  r   _verify_certificate$X509StoreContext._verify_certificate  s     ++-		TYY./GGIt'?'?@	&&{{))4::+;+;T[[
 	q!##I.!8..y99r   c                    V ^8  d   QhRRRR/# )r   r9  r7   r   rk   r   )r   s   "r   r   rs    s     	 	y 	T 	r   c                    Wn         R# )z
Set the context's X.509 store.

.. versionadded:: 0.15

:param X509Store store: The store description which will be used for
    the purposes of any *future* verifications.
Nrf  r8  s   &&r   	set_storeX509StoreContext.set_store  s	     r   c                   V ^8  d   QhRR/# r   r   )r   s   "r   r   rs    s     
# 
#D 
#r   c                &    V P                  4        R# )z
Verify a certificate in a context.

.. versionadded:: 0.15

:raises X509StoreContextError: If an error occurred when validating a
  certificate in the context. Sets ``certificate`` attribute to
  indicate which certificate caused the error.
N)r  r   s   &r   verify_certificate#X509StoreContext.verify_certificate  s     	  "r   c                   V ^8  d   QhRR/# )r   r   z
list[X509]r   )r   s   "r   r   rs    s      J r   c                   V P                  4       p\        P                  ! V4      p\        V\        P
                  8g  4       . p\        \        P                  ! V4      4       F[  p\        P                  ! W$4      p\        V\        P
                  8g  4       \        P                  V4      pVP                  V4       K]  	  \        P                  ! V4       V# )a  
Verify a certificate in a context and return the complete validated
chain.

:raises X509StoreContextError: If an error occurred when validating a
  certificate in the context. Sets ``certificate`` attribute to
  indicate which certificate caused the error.

.. versionadded:: 20.0
)r  rQ   X509_STORE_CTX_get1_chainr[   rW   r\   r\  r  r  r1   rd  r   r  )r   r  
cert_stackr   rf  rc  r  s   &      r   get_verified_chain#X509StoreContext.get_verified_chain  s     ,,.	 33I>

dii/0t''
34A%%j4DDDII-.,,T2FMM&!	 5 	*%r   )ru  rw  r7  r   )rA   rB   rC   rD   rE   r   staticmethodrv  r  r  r  r  r  rF   r   r   r   r8   r8   k  sM    ;  : > >20	
# r   c               $    V ^8  d   QhRRRRRR/# )r   r   r=   rH   ra   r   r1   r   )r   s   "r   r   r   	  s!     ) )3 ) )$ )r   c                   \        V\        4      '       d   VP                  R4      p\        V4      pV \        8X  dE   \
        P                  ! V\        P                  \        P                  \        P                  4      pM<V \        8X  d'   \
        P                  ! V\        P                  4      pM\        R4      hV\        P                  8X  d   \        4        \        P                  V4      # )z
Load a certificate (X509) from the string *buffer* encoded with the
type *type*.

:param type: The file type (one of FILETYPE_PEM, FILETYPE_ASN1)

:param bytes buffer: The buffer the certificate is stored in

:return: The X509 object
r&  3type argument must be FILETYPE_PEM or FILETYPE_ASN1)rm   r   rc  r_   r.   rQ   PEM_read_bio_X509rW   r\   r-   d2i_X509_biorp   r   r1   rd  )r   rH   rM   r    s   &&  r   rp  rp  	  s     &#w'
v
C|%%c499diiK		  dii0NOOtyy""4((r   c               $    V ^8  d   QhRRRRRR/# )r   r   r=   rc  r1   r   ra   r   )r   s   "r   r   r   &  s!      3 d u r   c                j   \        4       pV \        8X  d"   \        P                  ! W!P                  4      pMeV \
        8X  d"   \        P                  ! W!P                  4      pM9V \        8X  d$   \        P                  ! W!P                  ^ ^ 4      pM\        R4      h\        V^8H  4       \        V4      # )z
Dump the certificate *cert* into a buffer string encoded with the type
*type*.

:param type: The file type (one of FILETYPE_PEM, FILETYPE_ASN1, or
    FILETYPE_TEXT)
:param cert: The certificate to dump
:return: The buffer with the dumped certificate in
Ctype argument must be FILETYPE_PEM, FILETYPE_ASN1, or FILETYPE_TEXT)r_   r.   rQ   PEM_write_bio_X509r  r-   i2d_X509_bioFILETYPE_TEXTX509_print_exrp   r[   rg   )r   rc  rM   result_codes   &&  r   rj  rj  &  s     .C|--c::>		''ZZ8		((jj!Q?
 	

 K1$%#r   c               $    V ^8  d   QhRRRRRR/# )r   r   r=   r   r3   r   ra   r   )r   s   "r   r   r   B  s!       D U r   c                    \        4       pV \        8X  d   \        P                  pM'V \        8X  d   \        P
                  pM\        R4      hV! W!P                  4      pV^8w  d   \        4        \        V4      # )z
Dump a public key to a buffer.

:param type: The file type (one of :data:`FILETYPE_PEM` or
    :data:`FILETYPE_ASN1`).
:param PKey pkey: The public key to dump
:return: The buffer with the dumped key in it.
:rtype: bytes
r  )
r_   r.   rQ   PEM_write_bio_PUBKEYr-   i2d_PUBKEY_biorp   r   r   rg   )r   r   rM   	write_bior  s   &&   r   r   r   B  sd     .C|--			''	NOOC,Ka#r   c          
     ,    V ^8  d   QhRRRRRRRRR	R
/# )r   r   r=   r   r3   cipherrm  
passphrasePassphraseCallableT | Noner   ra   r   )r   s   "r   r   r   [  sA     B B
B
B B +	B
 Br   c           	        \        4       p\        V\        4      '       g   \        R4      hVeP   Vf   \        R4      h\        P
                  ! \        V4      4      pV\        P                  8X  d   \        R4      hM\        P                  p\        W4      pV \        8X  dZ   \        P                  ! VVP                  V\        P                  ^ VP                  VP                  4      pVP!                  4        MV \"        8X  d"   \        P$                  ! WAP                  4      pMV \&        8X  d   \        P(                  ! VP                  4      \        P*                  8w  d   \        R4      h\        P,                  ! \        P.                  ! VP                  4      \        P0                  4      p\        P2                  ! WH^ 4      pM\        R4      h\5        V^ 8g  4       \7        V4      # )aU  
Dump the private key *pkey* into a buffer string encoded with the type
*type*.  Optionally (if *type* is :const:`FILETYPE_PEM`) encrypting it
using *cipher* and *passphrase*.

:param type: The file type (one of :const:`FILETYPE_PEM`,
    :const:`FILETYPE_ASN1`, or :const:`FILETYPE_TEXT`)
:param PKey pkey: The PKey to dump
:param cipher: (optional) if encrypted PEM format, the cipher to use
:param passphrase: (optional) if encrypted PEM format, this can be either
    the passphrase to use, or a callback for providing the passphrase.

:return: The buffer with the dumped key in
:rtype: bytes
zpkey must be a PKeyzDif a value is given for cipher one must also be given for passphrasezInvalid cipher namez-Only RSA keys are supported for FILETYPE_TEXTr  )r_   rm   r3   rn   rQ   EVP_get_cipherbynamerY  rW   r\   rp   _PassphraseHelperr.   PEM_write_bio_PrivateKeyr   callbackcallback_argsraise_if_problemr-   i2d_PrivateKey_bior  r   r   r]   r   r   	RSA_printr[   rg   )	r   r   r  r  rM   
cipher_objhelperr  r%   s	   &&&&     r   r   r   [  s   * .CdD!!-..8  ..|F/CD
"233 # YY
t0F|33JJIIOO  
 	!		--c::>		DJJ'4+<+<<KLLggd,,TZZ8$--HnnSq1
 	

 K1$%#r   c                  p    ] tR tRtRR R llt]R R l4       t]R R l4       t]3R R	 llt	R
 R lt
RtR# )r  i  c          
     ,    V ^8  d   QhRRRRRRRRRR	/# )
r   r   r=   r  r  	more_argsr   truncater   rk   r   )r   s   "r   r   _PassphraseHelper.__annotate__  s<     - -- /- 	-
 - 
-r   c                	l    V\         8w  d   Ve   \        R4      hW n        W0n        W@n        . V n        R # )Nz0only FILETYPE_PEM key format supports encryption)r.   rp   _passphrase
_more_args	_truncate	_problems)r   r   r  r  r  s   &&&&&r   r   _PassphraseHelper.__init__  s:     <J$:B  &#!*,r   c                   V ^8  d   QhRR/# r7  r   )r   s   "r   r   r    s      # r   c                	   V P                   f   \        P                  # \        V P                   \        4      '       g   \        V P                   4      '       d"   \        P                  ! RV P                  4      # \        R4      h)Npem_password_cb2Last argument must be a byte string or a callable.)	r  rW   r\   rm   ra   callabler  _read_passphrasern   r   s   &r   r  _PassphraseHelper.callback  sc    #99((%00HT=M=M4N4N==!2D4I4IJJD r   c                   V ^8  d   QhRR/# r7  r   )r   s   "r   r   r    s      s r   c                	    V P                   f   \        P                  # \        V P                   \        4      '       g   \        V P                   4      '       d   \        P                  # \        R4      h)Nr  )r  rW   r\   rm   ra   r  rn   r   s   &r   r  _PassphraseHelper.callback_args  sU    #99((%00HT=M=M4N4N99D r   c                    V ^8  d   QhRRRR/# )r   exceptionTypeztype[Exception]r   rk   r   )r   s   "r   r   r    s     ( (o ($ (r   c                	    V P                   '       d(    \        V4       V P                   P                  ^ 4      hR#   T d     L&i ; ir  )r  _exception_from_error_queuepop)r   r  s   &&r   r  "_PassphraseHelper.raise_if_problem  sH    >>>+M: ..$$Q''  ! s   < AAc          
     ,    V ^8  d   QhRRRRRRRRRR/# )r   r  r   sizer=   rwflaguserdatar   r   )r   s   "r   r   r    s4      !+.:=	r   c                	V    \        V P                  4      '       d8   V P                  '       d   V P                  W#V4      pM.V P                  V4      pMV P                  f   Q hV P                  p\        V\        4      '       g   \        R4      h\        V4      V8  d$   V P                  '       d   VR V pM\        R4      h\        \        V4      4       F  pWVV^,            W&   K  	  \        V4      #   \         d'   pT P                  P                  T4        R p?^ # R p?ii ; i)NzBytes expectedz+passphrase returned by callback is too long)r  r  r  rm   ra   rp   rZ   r  r\  	Exceptionr  r   )r   r  r  r  r  r   rf  es   &&&&&   r   r  "_PassphraseHelper._read_passphrase  s    	(())???!--dHEF!--f5F''333))fe,, !1226{T!>>>#ET]F$E  3v;'AE* (v; 	NN!!!$	s$   ,C7 BC7 3AC7 7D(D##D()r  r  r  r  N)FF)rA   rB   rC   rD   r   r  r  r  r2   r  r  rF   r   r   r   r  r    sE    -      AF ( r   r  c               $    V ^8  d   QhRRRRRR/# )r   r   r=   rH   str | bytesr   r3   r   )r   s   "r   r   r     s!       k d r   c                R   \        V\        4      '       d   VP                  R4      p\        V4      pV \        8X  dE   \
        P                  ! V\        P                  \        P                  \        P                  4      pM<V \        8X  d'   \
        P                  ! V\        P                  4      pM\        R4      hV\        P                  8X  d   \        4        \        P                  \        4      p\        P                  ! V\
        P                   4      Vn        RVn        V# )a  
Load a public key from a buffer.

:param type: The file type (one of :data:`FILETYPE_PEM`,
    :data:`FILETYPE_ASN1`).
:param buffer: The buffer the key is stored in.
:type buffer: A Python string object, either unicode or bytestring.
:return: The PKey object.
:rtype: :class:`PKey`
r&  r  T)rm   r   rc  r_   r.   rQ   PEM_read_bio_PUBKEYrW   r\   r-   d2i_PUBKEY_biorp   r   r3   r  r]   r   r   r   )r   rH   rM   evp_pkeyr   s   &&   r   r   r     s     &#w'
v
C|++DIItyy
 
	&&sDII6NOO499<<D4#5#56DJDKr   c               (    V ^8  d   QhRRRRRRRR/# )	r   r   r=   rH   r  r  r  r   r3   r   )r   s   "r   r   r   	  s0     & &
&& +& 
	&r   c                j   \        V\        4      '       d   VP                  R4      p\        V4      p\	        W4      pV \
        8X  dM   \        P                  ! V\        P                  VP                  VP                  4      pVP                  4        M<V \        8X  d'   \        P                  ! V\        P                  4      pM\        R4      hV\        P                  8X  d   \!        4        \"        P%                  \"        4      p\        P&                  ! V\        P(                  4      Vn        V# )a  
Load a private key (PKey) from the string *buffer* encoded with the type
*type*.

:param type: The file type (one of FILETYPE_PEM, FILETYPE_ASN1)
:param buffer: The buffer the key is stored in
:param passphrase: (optional) if encrypted PEM format, this can be
                   either the passphrase to use, or a callback for
                   providing the passphrase.

:return: The PKey object
r&  r  )rm   r   rc  r_   r  r.   rQ   PEM_read_bio_PrivateKeyrW   r\   r  r  r  r-   d2i_PrivateKey_biorp   r   r3   r  r]   r   r   )r   rH   r  rM   r  r  r   s   &&&    r   r   r   	  s    " &#w'
v
Ct0F|//FOOV-A-A
 	!		**3		:NOO499<<D4#5#56DJKr   c               $    V ^8  d   QhRRRRRR/# )r   r   r=   r  r6   r   ra   r   )r   s   "r   r   r   9	  s!      3 W  r   c                j   \        4       pV \        8X  d"   \        P                  ! W!P                  4      pMeV \
        8X  d"   \        P                  ! W!P                  4      pM9V \        8X  d$   \        P                  ! W!P                  ^ ^ 4      pM\        R4      h\        V^ 8g  4       \        V4      # )aV  
Dump the certificate request *req* into a buffer string encoded with the
type *type*.

:param type: The file type (one of FILETYPE_PEM, FILETYPE_ASN1)
:param req: The certificate request to dump
:return: The buffer with the dumped certificate request in


.. deprecated:: 24.2.0
   Use `cryptography.x509.CertificateSigningRequest` instead.
r  )r_   r.   rQ   PEM_write_bio_X509_REQr  r-   i2d_X509_REQ_bior  X509_REQ_print_exrp   r[   rg   )r   r  rM   r  s   &&  r   r;   r;   9	  s     .C|11#xx@		++C:		,,S((AqA
 	

 K1$%#r   r3  c               $    V ^8  d   QhRRRRRR/# )r   r   r=   rH   ra   r   r6   r   )r   s   "r   r   r   g	  s!      3  ' r   c                >   \        V\        4      '       d   VP                  R4      p\        V4      pV \        8X  dE   \
        P                  ! V\        P                  \        P                  \        P                  4      pM<V \        8X  d'   \
        P                  ! V\        P                  4      pM\        R4      h\        V\        P                  8g  4       \        P                  \        4      p\        P                  ! V\
        P                   4      Vn        V# )as  
Load a certificate request (X509Req) from the string *buffer* encoded with
the type *type*.

:param type: The file type (one of FILETYPE_PEM, FILETYPE_ASN1)
:param buffer: The buffer the certificate request is stored in
:return: The X509Req object

.. deprecated:: 24.2.0
   Use `cryptography.x509.load_der_x509_csr` or
   `cryptography.x509.load_pem_x509_csr` instead.
r&  r  )rm   r   rc  r_   r.   rQ   PEM_read_bio_X509_REQrW   r\   r-   d2i_X509_REQ_biorp   r[   r6   r  r]   r  r  )r   rH   rM   r  x509reqs   &&   r   r<   r<   g	  s     &#w'
v
C|((diiDIIN		##C3NOOC499$%oog&G773 2 23GLNr   )      )r     )r-   r.   r  r/   r0   r1   r2   r3   r4   r5   r6   r7   r8   r9   r:   rj  r;   r   r   rF  rB  rp  r<   r   r   i  r   r  )p__conditional_annotations__
__future__r   rV  r  	functoolssysr   r+  base64r   collections.abcr   r   r   r   r	   r
   version_infor   TypeVar_Ttyping_extensionscryptographyr   r    )cryptography.hazmat.primitives.asymmetricr!   r"   r#   r$   r%   OpenSSL._utilr&   r'   rY  r(   r  r)   rW   r*   rQ   r+   _make_assertr,   ra  __all__r   r   r   r   r   _PrivateKeyr   r   r   r   r   
_PublicKeyr   ra   PassphraseCallableTSSL_FILETYPE_PEMr.   r  SSL_FILETYPE_ASN1r-   r  r   r0   EVP_PKEY_DSAr/   EVP_PKEY_DHr>   EVP_PKEY_ECr?   r  r2   r   r[   r_   rg   rr   rx   r   r   r3   r  rB  rF  total_orderingr5   r4   r6   r1   r:   r7   r9   r8   rp  rj  r   r   r  r   r   r;   r  rA   r-  r<   r   )r  s   @r   <module>r     s   " "    
    .   w#		B - $  ): 		 		
 [*$%E8CJ#778  ))c )++s + !!# !!!# !  I  :EB u%4;+2&:
 
~. ~.Bd. d.N 5	5 1	1$   D g: g:	g:T o o	odg gT8 8.g# g#T'I '"[ [|):82BJK K\D&R@ &> "   	 	#	@ &> "   	 	#	r   