+
    i#                       a  R0 t0 t R t^ RIt^ RIt^ RIHtHtHt ^ RIH	t	 ^ RI
Ht ^ RIHt ^ RIHt ]P                   ! ]4      tRRRR	R
RRRRR./tRRRRRR
RRRRR./RRRRRR
RRRRR./RRRRRR
RRRRR./RRRRRR
RRRRR./RRRRRR
RRRRR .//tR1 F  t]R,          ]]&   K  	  R2 F  t]R,          ]]&   K  	  . R3OtR!R"R#]R$]R%R&R'./t] ^ k R( tR) tR* tR+ tR, tR- tR. R/ ltR# )4zCA Certs: Add ca certificates.N)	lifecyclesubputil)Cloud)Config)
MetaSchema)PER_INSTANCEca_cert_pathca_cert_local_pathz!/usr/local/share/ca-certificates/ca_cert_filenamez#cloud-init-ca-cert-{cert_index}.crtca_cert_configz/etc/ca-certificates.confca_cert_update_cmdzupdate-ca-certificatesaoscz/etc/ssl/certs/z#cloud-init-ca-cert-{cert_index}.pemz+/etc/ca-certificates/conf.d/cloud-init.confzupdate-ca-bundlefedoraz/etc/pki/ca-trust/z/usr/share/pki/ca-trust-source/z+anchors/cloud-init-ca-cert-{cert_index}.crtzupdate-ca-trustrhelopensusez/etc/pki/trust/z/usr/share/pki/trust/photonz/etc/pki/tls/certs/zrehash_ca_certificates.shidcc_ca_certsdistros	frequencyactivate_by_schema_keysca_certsca-certsc                    \         P                  V \        4      p\        P                  P                  VR,          VR,          4      VR&   V# )zReturn a distro-specific ca_certs config dictionary

@param distro_name: String providing the distro class name.
@returns: Dict of distro configurations for ca_cert.
r
   r   ca_cert_full_path)DISTRO_OVERRIDESgetDEFAULT_CONFIGospathjoin)distro_namecfgs   & >/usr/lib/python3/dist-packages/cloudinit/config/cc_ca_certs.py_distro_ca_certs_configsr%   o   sF     

{N
;C!ww|| !3'9#: C J    c                D    \         P                   ! V R,          RR7       R# )z
Updates the CA certificate cache on the current machine.

@param distro_cfg: A hash providing _distro_ca_certs_configs function.
r   F)captureN)r   
distro_cfgs   &r$   update_ca_certsr+   |   s     	IIj-.>r&   c                    V'       g   R# \        V^4       FA  w  r#\        V4      pV R,          P                  VR7      p\        P                  ! WTRR7       KC  	  R# )a  
Adds certificates to the system. To actually apply the new certificates
you must also call the appropriate distro-specific utility such as
L{update_ca_certs}.

@param distro_cfg: A hash providing _distro_ca_certs_configs function.
@param certs: A list of certificate strings.
Nr   )
cert_indexi  )mode)	enumeratestrformatr   
write_file)r*   certsr-   ccert_file_contentscert_file_names   &&    r$   add_ca_certsr7      sV     "5!,
 V#$78??! @ 
 	G -r&   c                    V R9   d   \        V4       R# V R9   d1   \        V4       V R9   d   Rp\        P                  ! RVR7       R# R# R# )a  
Disables all default trusted CA certificates. For Alpine, Debian and
Ubuntu to actually apply the changes you must also call
L{update_ca_certs}.

@param distro_name: String providing the distro class name.
@param distro_cfg: A hash providing _distro_ca_certs_configs function.
)dataN)r   r   )alpiner   debianraspberry-pi-osubuntu)r;   r<   r=   z8ca-certificates ca-certificates/trust_new_crts select no)zdebconf-set-selections-)remove_default_ca_certsdisable_system_ca_certsr   )r"   r*   debconf_sels   && r$   disable_default_ca_certsrB      sY     ((
+	  
 	 
+AAO  II5KH	 B
r&   c                v   V R,          pV'       d&   \         P                  P                  V4      '       g   R# RpRp\         P                  ! V4      P                  '       d   \
        P                  ! V4      p. pVP                  4        Fy  pWb8X  d   RpVP                  V4       K  VR8X  g   V^ ,          R9   d   VP                  V4       KF  V'       g   VP                  V4       RpVP                  RV,           4       K{  	  \
        P                  ! VRP                  V4      R,           R	R
7       R# R# )z
For every entry in the CA_CERT_CONFIG file prefix the entry with a "!"
in order to disable it.

@param distro_cfg: A hash providing _distro_ca_certs_configs function.
r   Nz;# Modified by cloud-init to deselect certs due to user-dataFT !
wb)omode)#rE   )r   r    existsstatst_sizer   load_text_file
splitlinesappendr2   r!   )r*   ca_cert_cfg_fnheader_commentadded_headerorig	out_lineslines   &      r$   r@   r@      s       01N!?!? 	F  L	ww~&&&"">2	OO%D%#  &tAw*4  &#$$^4#'L  t, & 	DIIi047t	
 'r&   c                    V R,          f   R# \         P                  R4       \        P                  ! V R,          4       \        P                  ! V R,          4       R# )z
Removes all default trusted CA certificates from the system.

@param distro_cfg: A hash providing _distro_ca_certs_configs function.
r	   NzDeleting system CA certificatesr
   )LOGdebugr   delete_dir_contentsr)   s   &r$   r?   r?      sF     .!)II/0Z78Z(<=>r&   c          
      L    V ^8  d   QhR\         R\        R\        R\        RR/# )   namer#   cloudargsreturnN)r0   r   r   list)r1   s   "r$   __annotate__ra      s/     8  8  8 6 8 % 8 t 8  8 r&   c                h   RV9   d   \         P                  ! RRRR7       MRV9  d   \        P                  RV 4       R# RV9   d   RV9   d   \        P	                  R	4       VP                  RVP                  R4      4      p\        V\        4      '       g   \        R
4      h\        VP                  P                  4      pRV9   d   \         P                  ! RRRR7       VP                  RVP                  RR4      4      '       d6   \        P                  R4       \        VP                  P                  V4       RV9   dJ   \        P                  ! VR4      pV'       d+   \        P                  R\        V4      4       \!        WV4       \        P                  R4       \#        V4       R# )aY  
Call to handle ca_cert sections in cloud-config file.

@param name: The module name "ca_cert" from cloud.cfg
@param cfg: A nested dict containing the entire cloud config contents.
@param cloud: The L{CloudInit} object in use.
@param log: Pre-initialized Python logger object to use for logging.
@param args: Any module arguments from cloud.cfg
r   zKey 'ca-certs'z22.1zUse 'ca_certs' instead.)
deprecateddeprecated_versionextra_messager   z<Skipping module named %s, no 'ca_certs' key in configurationNzMFound both ca-certs (deprecated) and ca_certs config keys. Ignoring ca-certs.zunexpected type: {ca_cert_cfg}zremove-defaultszKey 'remove-defaults'zUse 'remove_defaults' instead.remove_defaultsFz'Disabling/removing default certificatestrustedzAdding %d certificateszUpdating certificates)r   	deprecaterW   rX   warningr   
isinstancedict	TypeErrorr%   distror\   rB   r   get_cfg_option_listlenr7   r+   )r\   r#   r]   r^   ca_cert_cfgr*   trusted_certss   &&&&   r$   handlerr      sf    S'%3	

 
3			J	
 	SZ3."	
 ''*cggj&9:Kk4((899)%,,*;*;<J K'.%:	

 ;??+<eD  			;< !2!2J? K00iHII.M0BC3 II%&Jr&   c                @    V ^8  d   Qh/ ^ \         9   d
   \        ;R&   # )r[   meta)__conditional_annotations__r   )r1   s   "r$   ra   ra      s      $ $D j E %r&   )opensuse-microosopensuse-tumbleweedopensuse-leapsle_hpc	sle-microsles)	almalinuxcentos
cloudlinuxrocky)r|   r   r}   r~   r:   r;   r   r<   r   r   r   rv   rw   rx   ry   rz   r{   r=   r   ) ru   __doc__loggingr   	cloudinitr   r   r   cloudinit.cloudr   cloudinit.configr   cloudinit.config.schemar   cloudinit.settingsr   	getLogger__name__rW   r   r   rm   r   rt   r%   r+   r7   rB   r@   r?   rr   ra   )ru   s   @r$   <module>r      s  
 %  	 + + ! # . +! D==134 )/AG12 ,?I$01 ,?I$01 )5I$78 -/A$:;;$ LF  0
;VF  07V. 	-w
J7	 
?H*I6$
N?8 r&   