o
    ›¨Êh¨  ã                   @  s  d Z ddlmZ ddlZddlZddlZddlmZmZ ddl	m
Z
 ddlmZmZ ddlmZ ddlmZmZ dd	lmZ d
dlmZ erpddlmZ ddlmZ ddlmZ ddlmZ ddlm Z  ddl!m"Z" ddl#m$Z$ dZ%G dd„ dƒZ&G dd„ dƒZ'G dd„ de'ƒZ(dS )zX.509 certificates.é    )ÚannotationsN)ÚTYPE_CHECKINGÚIterator)Údefault_backend)ÚpaddingÚrsa)Úload_pem_x509_certificate)Úbytes_to_strÚensure_bytes)ÚSecurityErroré   )Úreraise_errors)ÚDSAPublicKey)ÚEllipticCurvePublicKey)ÚEd448PublicKey)ÚEd25519PublicKey)ÚRSAPublicKey)Ú	Prehashed)ÚHashAlgorithm)ÚCertificateÚ	CertStoreÚFSCertStorec                   @  sV   e Zd ZdZddd„Zdd	d
„Zddd„Zd dd„Zd!dd„Zd!dd„Z	d"dd„Z
dS )#r   zX.509 certificate.ÚcertÚstrÚreturnÚNonec                 C  sb   t dtfd��  tt|ƒtƒ d�| _t| j ¡ tj	ƒstdƒ‚W d   ƒ d S 1 s*w   Y  d S )NzInvalid certificate: {0!r})Úerrors)Úbackendz'Non-RSA certificates are not supported.)
r   Ú
ValueErrorr   r
   r   Ú_certÚ
isinstanceÚ
public_keyr   r   )Úselfr   © r#   úM/var/www/html/env/lib/python3.10/site-packages/celery/security/certificate.pyÚ__init__"   s   ÿ
ÿÿ"úzCertificate.__init__Úboolc                 C  s   t j  ¡ | jjkS )z%Check if the certificate has expired.)ÚdatetimeÚutcnowr   Únot_valid_after©r"   r#   r#   r$   Úhas_expired,   s   zCertificate.has_expiredúXDSAPublicKey | EllipticCurvePublicKey | Ed448PublicKey | Ed25519PublicKey | RSAPublicKeyc                 C  s
   | j  ¡ S ©N)r   r!   r*   r#   r#   r$   Ú
get_pubkey0   s   
zCertificate.get_pubkeyÚintc                 C  s   | j jS )z,Return the serial number in the certificate.)r   Úserial_numberr*   r#   r#   r$   Úget_serial_number5   s   zCertificate.get_serial_numberc                 C  s   d  dd„ | jjD ƒ¡S )zReturn issuer (CA) as a string.ú c                 s  s   � | ]}|j V  qd S r-   )Úvalue)Ú.0Úxr#   r#   r$   Ú	<genexpr>;   s   € z)Certificate.get_issuer.<locals>.<genexpr>)Újoinr   Úissuerr*   r#   r#   r$   Ú
get_issuer9   s   zCertificate.get_issuerc                 C  s   |   ¡ › d|  ¡ › �S )z<Serial number/issuer pair uniquely identifies a certificate.r2   )r9   r1   r*   r#   r#   r$   Úget_id=   s   zCertificate.get_idÚdataÚbytesÚ	signatureÚdigestúHashAlgorithm | Prehashedc                 C  s^   t dƒ�! tjt |¡tjjd�}|  ¡  |t|ƒ||¡ W d  ƒ dS 1 s(w   Y  dS )z,Verify signature for string containing data.zBad signature: {0!r})ÚmgfÚsalt_lengthN)r   r   ÚPSSÚMGF1Ú
MAX_LENGTHr.   Úverifyr
   )r"   r;   r=   r>   Úpadr#   r#   r$   rE   A   s   
þ"úzCertificate.verifyN)r   r   r   r   )r   r&   )r   r,   )r   r/   )r   r   )r;   r<   r=   r<   r>   r?   r   r   )Ú__name__Ú
__module__Ú__qualname__Ú__doc__r%   r+   r.   r1   r9   r:   rE   r#   r#   r#   r$   r      s    






r   c                   @  s8   e Zd ZdZddd„Zddd„Zddd„Zddd„ZdS )r   z"Base class for certificate stores.r   r   c                 C  s
   i | _ d S r-   )Ú_certsr*   r#   r#   r$   r%   O   s   
zCertStore.__init__úIterator[Certificate]c                 c  s   � | j  ¡ E dH  dS )zReturn certificate iterator.N)rK   Úvaluesr*   r#   r#   r$   Ú	itercertsR   s   €zCertStore.itercertsÚidr   r   c                 C  s.   z| j t|ƒ W S  ty   td|›�ƒ‚w )zGet certificate by id.zUnknown certificate: )rK   r	   ÚKeyErrorr   )r"   rO   r#   r#   r$   Ú__getitem__V   s
   ÿzCertStore.__getitem__r   c                 C  s2   t | ¡ ƒ}|| jv rtdt›�ƒ‚|| j|< d S )NzDuplicate certificate: )r	   r:   rK   r   rO   )r"   r   Úcert_idr#   r#   r$   Úadd_cert]   s   
zCertStore.add_certN)r   r   )r   rL   )rO   r   r   r   )r   r   r   r   )rG   rH   rI   rJ   r%   rN   rQ   rS   r#   r#   r#   r$   r   L   s    


r   c                      s"   e Zd ZdZd‡ fdd„Z‡  ZS )	r   zFile system certificate store.Úpathr   r   r   c              	     s�   t ƒ  ¡  tj |¡rtj |d¡}t |¡D ].}t|ƒ� }t| 	¡ ƒ}| 
¡ r1td| ¡ ›�ƒ‚|  |¡ W d   ƒ n1 s@w   Y  qd S )NÚ*zExpired certificate: )Úsuperr%   ÚosrT   Úisdirr7   ÚglobÚopenr   Úreadr+   r   r:   rS   )r"   rT   ÚpÚfr   ©Ú	__class__r#   r$   r%   g   s   

ÿû€ÿzFSCertStore.__init__)rT   r   r   r   )rG   rH   rI   rJ   r%   Ú__classcell__r#   r#   r^   r$   r   d   s    r   ))rJ   Ú
__future__r   r'   rY   rW   Útypingr   r   Úcryptography.hazmat.backendsr   Ú)cryptography.hazmat.primitives.asymmetricr   r   Úcryptography.x509r   Úkombu.utils.encodingr	   r
   Úcelery.exceptionsr   Úutilsr   Ú-cryptography.hazmat.primitives.asymmetric.dsar   Ú,cryptography.hazmat.primitives.asymmetric.ecr   Ú/cryptography.hazmat.primitives.asymmetric.ed448r   Ú1cryptography.hazmat.primitives.asymmetric.ed25519r   Ú-cryptography.hazmat.primitives.asymmetric.rsar   Ú/cryptography.hazmat.primitives.asymmetric.utilsr   Ú%cryptography.hazmat.primitives.hashesr   Ú__all__r   r   r   r#   r#   r#   r$   Ú<module>   s0    -