o
    ™¨ÊhÌ\  ã                   @   s¦  d dl mZmZmZ d dlZd dlZd dlZd dlmZ d dl	Z	d dl
mZ d dlmZmZmZ d dlmZmZ d dlmZ e dd	d	¡Zd
d„ Zdd„ ZG dd„ deƒZdd„ Zdd„ Zdd„ Zdd„ Zdd„ Zdd„ ZG dd„ deƒZ e	 !ej"¡G dd„ de#ƒƒZ$e	 !ej"¡G d d!„ d!e#ƒƒZ%e	 !ej"¡G d"d#„ d#e#ƒƒZ&e	 !ej"¡G d$d%„ d%e#ƒƒZ'G d&d'„ d'e#ƒZ(G d(d)„ d)e#ƒZ)G d*d+„ d+e#ƒZ*G d,d-„ d-e#ƒZ+d.d/„ Z,dS )0é    )Úabsolute_importÚdivisionÚprint_functionN)ÚEnum)Úutils)ÚdsaÚecÚrsa)Ú	ExtensionÚExtensionType)ÚNamei²  é   c                 C   s"   |D ]}|j | j krtdƒ‚qd S )Nz$This extension has already been set.)ÚoidÚ
ValueError)Ú	extensionÚ
extensionsÚe© r   úH/var/www/html/env/lib/python3.10/site-packages/cryptography/x509/base.pyÚ_reject_duplicate_extension   s
   ÿÿr   c                 C   s6   | j dur|  ¡ }|r|nt ¡ }| jdd�| S | S )z’Normalizes a datetime to a naive datetime in UTC.

    time -- datetime to normalize. Assumed to be in UTC if not timezone
            aware.
    N)Útzinfo)r   Ú	utcoffsetÚdatetimeÚ	timedeltaÚreplace)ÚtimeÚoffsetr   r   r   Ú_convert_to_naive_utc_time   s
   
r   c                   @   s   e Zd ZdZdZdS )ÚVersionr   é   N)Ú__name__Ú
__module__Ú__qualname__Úv1Úv3r   r   r   r   r   ,   s    r   c                 C   ó
   |  | ¡S ©N)Úload_pem_x509_certificate©ÚdataÚbackendr   r   r   r'   1   ó   
r'   c                 C   r%   r&   )Úload_der_x509_certificater(   r   r   r   r,   5   r+   r,   c                 C   r%   r&   )Úload_pem_x509_csrr(   r   r   r   r-   9   r+   r-   c                 C   r%   r&   )Úload_der_x509_csrr(   r   r   r   r.   =   r+   r.   c                 C   r%   r&   )Úload_pem_x509_crlr(   r   r   r   r/   A   r+   r/   c                 C   r%   r&   )Úload_der_x509_crlr(   r   r   r   r0   E   r+   r0   c                       s   e Zd Z‡ fdd„Z‡  ZS )ÚInvalidVersionc                    s   t t| ƒ |¡ || _d S r&   )Úsuperr1   Ú__init__Úparsed_version)ÚselfÚmsgr4   ©Ú	__class__r   r   r3   J   s   
zInvalidVersion.__init__)r    r!   r"   r3   Ú__classcell__r   r   r7   r   r1   I   s    r1   c                   @   sú   e Zd Zejdd„ ƒZejdd„ ƒZejdd„ ƒZejdd„ ƒZ	ejd	d
„ ƒZ
ejdd„ ƒZejdd„ ƒZejdd„ ƒZejdd„ ƒZejdd„ ƒZejdd„ ƒZejdd„ ƒZejdd„ ƒZejdd„ ƒZejdd„ ƒZejdd „ ƒZejd!d"„ ƒZd#S )$ÚCertificatec                 C   ó   dS ©z4
        Returns bytes using digest passed.
        Nr   ©r5   Ú	algorithmr   r   r   ÚfingerprintQ   ó    zCertificate.fingerprintc                 C   r;   )z3
        Returns certificate serial number
        Nr   ©r5   r   r   r   Úserial_numberW   r@   zCertificate.serial_numberc                 C   r;   )z1
        Returns the certificate version
        Nr   rA   r   r   r   Úversion]   r@   zCertificate.versionc                 C   r;   ©z(
        Returns the public key
        Nr   rA   r   r   r   Ú
public_keyc   r@   zCertificate.public_keyc                 C   r;   )z?
        Not before time (represented as UTC datetime)
        Nr   rA   r   r   r   Únot_valid_beforei   r@   zCertificate.not_valid_beforec                 C   r;   )z>
        Not after time (represented as UTC datetime)
        Nr   rA   r   r   r   Únot_valid_aftero   r@   zCertificate.not_valid_afterc                 C   r;   )z1
        Returns the issuer name object.
        Nr   rA   r   r   r   Úissueru   r@   zCertificate.issuerc                 C   r;   ©z2
        Returns the subject name object.
        Nr   rA   r   r   r   Úsubject{   r@   zCertificate.subjectc                 C   r;   ©zt
        Returns a HashAlgorithm corresponding to the type of the digest signed
        in the certificate.
        Nr   rA   r   r   r   Úsignature_hash_algorithm�   r@   z$Certificate.signature_hash_algorithmc                 C   r;   ©zJ
        Returns the ObjectIdentifier of the signature algorithm.
        Nr   rA   r   r   r   Úsignature_algorithm_oidˆ   r@   z#Certificate.signature_algorithm_oidc                 C   r;   )z/
        Returns an Extensions object.
        Nr   rA   r   r   r   r   Ž   r@   zCertificate.extensionsc                 C   r;   ©z.
        Returns the signature bytes.
        Nr   rA   r   r   r   Ú	signature”   r@   zCertificate.signaturec                 C   r;   )zR
        Returns the tbsCertificate payload bytes as defined in RFC 5280.
        Nr   rA   r   r   r   Útbs_certificate_bytesš   r@   z!Certificate.tbs_certificate_bytesc                 C   r;   ©z"
        Checks equality.
        Nr   ©r5   Úotherr   r   r   Ú__eq__    r@   zCertificate.__eq__c                 C   r;   ©z#
        Checks not equal.
        Nr   rS   r   r   r   Ú__ne__¦   r@   zCertificate.__ne__c                 C   r;   ©z"
        Computes a hash.
        Nr   rA   r   r   r   Ú__hash__¬   r@   zCertificate.__hash__c                 C   r;   )zB
        Serializes the certificate to PEM or DER format.
        Nr   ©r5   Úencodingr   r   r   Úpublic_bytes²   r@   zCertificate.public_bytesN)r    r!   r"   ÚabcÚabstractmethodr?   ÚabstractpropertyrB   rC   rE   rF   rG   rH   rJ   rL   rN   r   rP   rQ   rU   rW   rY   r\   r   r   r   r   r:   O   sF    















r:   c                   @   sú   e Zd Zejdd„ ƒZejdd„ ƒZejdd„ ƒZejdd„ ƒZ	ejd	d
„ ƒZ
ejdd„ ƒZejdd„ ƒZejdd„ ƒZejdd„ ƒZejdd„ ƒZejdd„ ƒZejdd„ ƒZejdd„ ƒZejdd„ ƒZejdd„ ƒZejdd „ ƒZejd!d"„ ƒZd#S )$ÚCertificateRevocationListc                 C   r;   )z:
        Serializes the CRL to PEM or DER format.
        Nr   rZ   r   r   r   r\   »   r@   z&CertificateRevocationList.public_bytesc                 C   r;   r<   r   r=   r   r   r   r?   Á   r@   z%CertificateRevocationList.fingerprintc                 C   r;   )zs
        Returns an instance of RevokedCertificate or None if the serial_number
        is not in the CRL.
        Nr   )r5   rB   r   r   r   Ú(get_revoked_certificate_by_serial_numberÇ   r@   zBCertificateRevocationList.get_revoked_certificate_by_serial_numberc                 C   r;   rK   r   rA   r   r   r   rL   Î   r@   z2CertificateRevocationList.signature_hash_algorithmc                 C   r;   rM   r   rA   r   r   r   rN   Õ   r@   z1CertificateRevocationList.signature_algorithm_oidc                 C   r;   )zC
        Returns the X509Name with the issuer of this CRL.
        Nr   rA   r   r   r   rH   Û   r@   z CertificateRevocationList.issuerc                 C   r;   )z?
        Returns the date of next update for this CRL.
        Nr   rA   r   r   r   Únext_updateá   r@   z%CertificateRevocationList.next_updatec                 C   r;   )z?
        Returns the date of last update for this CRL.
        Nr   rA   r   r   r   Úlast_updateç   r@   z%CertificateRevocationList.last_updatec                 C   r;   )zS
        Returns an Extensions object containing a list of CRL extensions.
        Nr   rA   r   r   r   r   í   r@   z$CertificateRevocationList.extensionsc                 C   r;   rO   r   rA   r   r   r   rP   ó   r@   z#CertificateRevocationList.signaturec                 C   r;   )zO
        Returns the tbsCertList payload bytes as defined in RFC 5280.
        Nr   rA   r   r   r   Útbs_certlist_bytesù   r@   z,CertificateRevocationList.tbs_certlist_bytesc                 C   r;   rR   r   rS   r   r   r   rU   ÿ   r@   z CertificateRevocationList.__eq__c                 C   r;   rV   r   rS   r   r   r   rW     r@   z CertificateRevocationList.__ne__c                 C   r;   )z<
        Number of revoked certificates in the CRL.
        Nr   rA   r   r   r   Ú__len__  r@   z!CertificateRevocationList.__len__c                 C   r;   )zS
        Returns a revoked certificate (or slice of revoked certificates).
        Nr   )r5   Úidxr   r   r   Ú__getitem__  r@   z%CertificateRevocationList.__getitem__c                 C   r;   )z8
        Iterator over the revoked certificates
        Nr   rA   r   r   r   Ú__iter__  r@   z"CertificateRevocationList.__iter__c                 C   r;   )zQ
        Verifies signature of revocation list against given public key.
        Nr   )r5   rE   r   r   r   Úis_signature_valid  r@   z,CertificateRevocationList.is_signature_validN)r    r!   r"   r]   r^   r\   r?   ra   r_   rL   rN   rH   rb   rc   r   rP   rd   rU   rW   re   rg   rh   ri   r   r   r   r   r`   ¹   sF    















r`   c                   @   s´   e Zd Zejdd„ ƒZejdd„ ƒZejdd„ ƒZejdd„ ƒZej	d	d
„ ƒZ
ej	dd„ ƒZej	dd„ ƒZej	dd„ ƒZejdd„ ƒZej	dd„ ƒZej	dd„ ƒZej	dd„ ƒZdS )ÚCertificateSigningRequestc                 C   r;   rR   r   rS   r   r   r   rU   &  r@   z CertificateSigningRequest.__eq__c                 C   r;   rV   r   rS   r   r   r   rW   ,  r@   z CertificateSigningRequest.__ne__c                 C   r;   rX   r   rA   r   r   r   rY   2  r@   z"CertificateSigningRequest.__hash__c                 C   r;   rD   r   rA   r   r   r   rE   8  r@   z$CertificateSigningRequest.public_keyc                 C   r;   rI   r   rA   r   r   r   rJ   >  r@   z!CertificateSigningRequest.subjectc                 C   r;   rK   r   rA   r   r   r   rL   D  r@   z2CertificateSigningRequest.signature_hash_algorithmc                 C   r;   rM   r   rA   r   r   r   rN   K  r@   z1CertificateSigningRequest.signature_algorithm_oidc                 C   r;   )z@
        Returns the extensions in the signing request.
        Nr   rA   r   r   r   r   Q  r@   z$CertificateSigningRequest.extensionsc                 C   r;   )z;
        Encodes the request to PEM or DER format.
        Nr   rZ   r   r   r   r\   W  r@   z&CertificateSigningRequest.public_bytesc                 C   r;   rO   r   rA   r   r   r   rP   ]  r@   z#CertificateSigningRequest.signaturec                 C   r;   )zd
        Returns the PKCS#10 CertificationRequestInfo bytes as defined in RFC
        2986.
        Nr   rA   r   r   r   Útbs_certrequest_bytesc  r@   z/CertificateSigningRequest.tbs_certrequest_bytesc                 C   r;   )z8
        Verifies signature of signing request.
        Nr   rA   r   r   r   ri   j  r@   z,CertificateSigningRequest.is_signature_validN)r    r!   r"   r]   r^   rU   rW   rY   rE   r_   rJ   rL   rN   r   r\   rP   rk   ri   r   r   r   r   rj   $  s2    










rj   c                   @   s6   e Zd Zejdd„ ƒZejdd„ ƒZejdd„ ƒZdS )ÚRevokedCertificatec                 C   r;   )zG
        Returns the serial number of the revoked certificate.
        Nr   rA   r   r   r   rB   s  r@   z RevokedCertificate.serial_numberc                 C   r;   )zH
        Returns the date of when this certificate was revoked.
        Nr   rA   r   r   r   Úrevocation_datey  r@   z"RevokedCertificate.revocation_datec                 C   r;   )zW
        Returns an Extensions object containing a list of Revoked extensions.
        Nr   rA   r   r   r   r     r@   zRevokedCertificate.extensionsN)r    r!   r"   r]   r_   rB   rm   r   r   r   r   r   rl   q  s    

rl   c                   @   s2   e Zd Zdg fdd„Zdd„ Zdd„ Zdd	„ ZdS )
Ú CertificateSigningRequestBuilderNc                 C   s   || _ || _dS )zB
        Creates an empty X.509 certificate request (v1).
        N)Ú_subject_nameÚ_extensions)r5   Úsubject_namer   r   r   r   r3   ‡  s   
z)CertificateSigningRequestBuilder.__init__c                 C   s0   t |tƒs	tdƒ‚| jdurtdƒ‚t|| jƒS )zF
        Sets the certificate requestor's distinguished name.
        úExpecting x509.Name object.Nú&The subject name may only be set once.)Ú
isinstancer   Ú	TypeErrorro   r   rn   rp   ©r5   Únamer   r   r   rq   Ž  s
   

z-CertificateSigningRequestBuilder.subject_namec                 C   s@   t |tƒs	tdƒ‚t|j||ƒ}t|| jƒ t| j| j|g ƒS )zE
        Adds an X.509 extension to the certificate request.
        ú"extension must be an ExtensionType)	rt   r   ru   r
   r   r   rp   rn   ro   ©r5   r   Úcriticalr   r   r   Úadd_extension˜  s   
ÿz.CertificateSigningRequestBuilder.add_extensionc                 C   s    | j du r	tdƒ‚| | ||¡S )zF
        Signs the request using the requestor's private key.
        Nz/A CertificateSigningRequest must have a subject)ro   r   Úcreate_x509_csr©r5   Úprivate_keyr>   r*   r   r   r   Úsign¦  s   
z%CertificateSigningRequestBuilder.sign)r    r!   r"   r3   rq   r{   r   r   r   r   r   rn   †  s
    
rn   c                   @   sd   e Zd Zddddddg fdd„Zdd„ Zdd„ Zdd	„ Zd
d„ Zdd„ Zdd„ Z	dd„ Z
dd„ ZdS )ÚCertificateBuilderNc                 C   s6   t j| _|| _|| _|| _|| _|| _|| _|| _	d S r&   )
r   r$   Ú_versionÚ_issuer_namero   Ú_public_keyÚ_serial_numberÚ_not_valid_beforeÚ_not_valid_afterrp   )r5   Úissuer_namerq   rE   rB   rF   rG   r   r   r   r   r3   °  s   
zCertificateBuilder.__init__c                 C   sD   t |tƒs	tdƒ‚| jdurtdƒ‚t|| j| j| j| j	| j
| jƒS )z3
        Sets the CA's distinguished name.
        rr   Nú%The issuer name may only be set once.)rt   r   ru   r‚   r   r€   ro   rƒ   r„   r…   r†   rp   rv   r   r   r   r‡   ¼  ó   


ýzCertificateBuilder.issuer_namec                 C   sD   t |tƒs	tdƒ‚| jdurtdƒ‚t| j|| j| j| j	| j
| jƒS )z:
        Sets the requestor's distinguished name.
        rr   Nrs   )rt   r   ru   ro   r   r€   r‚   rƒ   r„   r…   r†   rp   rv   r   r   r   rq   Ê  r‰   zCertificateBuilder.subject_namec                 C   sP   t |tjtjtjfƒstdƒ‚| jdurt	dƒ‚t
| j| j|| j| j| j| jƒS )zT
        Sets the requestor's public key (as found in the signing request).
        zGExpecting one of DSAPublicKey, RSAPublicKey, or EllipticCurvePublicKey.Nz$The public key may only be set once.)rt   r   ÚDSAPublicKeyr	   ÚRSAPublicKeyr   ÚEllipticCurvePublicKeyru   rƒ   r   r€   r‚   ro   r„   r…   r†   rp   )r5   Úkeyr   r   r   rE   Ø  s   ÿ

ýzCertificateBuilder.public_keyc                 C   sj   t |tjƒs
tdƒ‚| jdurtdƒ‚|dkrtdƒ‚| ¡ dkr%tdƒ‚t| j| j	| j
|| j| j| jƒS )z5
        Sets the certificate serial number.
        ú'Serial number must be of integral type.Nú'The serial number may only be set once.r   z%The serial number should be positive.é    ú3The serial number should not be more than 159 bits.)rt   ÚsixÚinteger_typesru   r„   r   Ú
bit_lengthr€   r‚   ro   rƒ   r…   r†   rp   ©r5   Únumberr   r   r   rB   è  s   

ýz CertificateBuilder.serial_numberc                 C   sz   t |tjƒs
tdƒ‚| jdurtdƒ‚t|ƒ}|tkrtdƒ‚| jdur-|| jkr-tdƒ‚t| j	| j
| j| j|| j| jƒS )z7
        Sets the certificate activation time.
        úExpecting datetime object.Nz*The not valid before may only be set once.zHThe not valid before date must be after the unix epoch (1970 January 1).zBThe not valid before date must be before the not valid after date.)rt   r   ru   r…   r   r   Ú_UNIX_EPOCHr†   r€   r‚   ro   rƒ   r„   rp   ©r5   r   r   r   r   rF   þ  s    
ÿ
ýz#CertificateBuilder.not_valid_beforec                 C   sz   t |tjƒs
tdƒ‚| jdurtdƒ‚t|ƒ}|tkrtdƒ‚| jdur-|| jk r-tdƒ‚t| j	| j
| j| j| j|| jƒS )z7
        Sets the certificate expiration time.
        r—   Nz)The not valid after may only be set once.zGThe not valid after date must be after the unix epoch (1970 January 1).zAThe not valid after date must be after the not valid before date.)rt   r   ru   r†   r   r   r˜   r…   r€   r‚   ro   rƒ   r„   rp   r™   r   r   r   rG     s"   


ÿýz"CertificateBuilder.not_valid_afterc              	   C   sT   t |tƒs	tdƒ‚t|j||ƒ}t|| jƒ t| j| j	| j
| j| j| j| j|g ƒS )z=
        Adds an X.509 extension to the certificate.
        rx   )rt   r   ru   r
   r   r   rp   r€   r‚   ro   rƒ   r„   r…   r†   ry   r   r   r   r{   -  s   
ýz CertificateBuilder.add_extensionc                 C   sz   | j du r	tdƒ‚| jdu rtdƒ‚| jdu rtdƒ‚| jdu r$tdƒ‚| jdu r-tdƒ‚| jdu r6tdƒ‚| | ||¡S )zC
        Signs the certificate using the CA's private key.
        Nz&A certificate must have a subject namez&A certificate must have an issuer namez'A certificate must have a serial numberz/A certificate must have a not valid before timez.A certificate must have a not valid after timez$A certificate must have a public key)ro   r   r‚   r„   r…   r†   rƒ   Úcreate_x509_certificater}   r   r   r   r   =  s   





zCertificateBuilder.sign)r    r!   r"   r3   r‡   rq   rE   rB   rF   rG   r{   r   r   r   r   r   r€   ¯  s    
þr€   c                   @   sP   e Zd Zdddg g fdd„Zdd„ Zdd„ Zdd	„ Zd
d„ Zdd„ Zdd„ Z	dS )Ú CertificateRevocationListBuilderNc                 C   s"   || _ || _|| _|| _|| _d S r&   )r‚   Ú_last_updateÚ_next_updaterp   Ú_revoked_certificates)r5   r‡   rc   rb   r   Úrevoked_certificatesr   r   r   r3   W  s
   
z)CertificateRevocationListBuilder.__init__c                 C   s<   t |tƒs	tdƒ‚| jd urtdƒ‚t|| j| j| j| j	ƒS )Nrr   rˆ   )
rt   r   ru   r‚   r   r›   rœ   r�   rp   rž   )r5   r‡   r   r   r   r‡   _  s   


þz,CertificateRevocationListBuilder.issuer_namec                 C   sr   t |tjƒs
tdƒ‚| jd urtdƒ‚t|ƒ}|tkrtdƒ‚| jd ur-|| jkr-tdƒ‚t| j	|| j| j
| jƒS )Nr—   ú!Last update may only be set once.úCThe last update date must be after the unix epoch (1970 January 1).z9The last update date must be before the next update date.)rt   r   ru   rœ   r   r   r˜   r�   r›   r‚   rp   rž   )r5   rc   r   r   r   rc   i  ó   
ÿ
þz,CertificateRevocationListBuilder.last_updatec                 C   sr   t |tjƒs
tdƒ‚| jd urtdƒ‚t|ƒ}|tkrtdƒ‚| jd ur-|| jk r-tdƒ‚t| j	| j|| j
| jƒS )Nr—   r    r¡   z8The next update date must be after the last update date.)rt   r   ru   r�   r   r   r˜   rœ   r›   r‚   rp   rž   )r5   rb   r   r   r   rb   {  r¢   z,CertificateRevocationListBuilder.next_updatec                 C   sL   t |tƒs	tdƒ‚t|j||ƒ}t|| jƒ t| j| j	| j
| j|g | jƒS )zM
        Adds an X.509 extension to the certificate revocation list.
        rx   )rt   r   ru   r
   r   r   rp   r›   r‚   rœ   r�   rž   ry   r   r   r   r{   �  s   
þz.CertificateRevocationListBuilder.add_extensionc                 C   s2   t |tƒs	tdƒ‚t| j| j| j| j| j|g ƒS )z8
        Adds a revoked certificate to the CRL.
        z)Must be an instance of RevokedCertificate)	rt   rl   ru   r›   r‚   rœ   r�   rp   rž   )r5   Úrevoked_certificater   r   r   Úadd_revoked_certificate›  s   

ýz8CertificateRevocationListBuilder.add_revoked_certificatec                 C   sD   | j d u r	tdƒ‚| jd u rtdƒ‚| jd u rtdƒ‚| | ||¡S )NzA CRL must have an issuer namez"A CRL must have a last update timez"A CRL must have a next update time)r‚   r   rœ   r�   Úcreate_x509_crlr}   r   r   r   r   ¨  s   


z%CertificateRevocationListBuilder.sign)
r    r!   r"   r3   r‡   rc   rb   r{   r¤   r   r   r   r   r   r›   V  s    
ÿ
r›   c                   @   s<   e Zd Zddg fdd„Zdd„ Zdd„ Zdd	„ Zd
d„ ZdS )ÚRevokedCertificateBuilderNc                 C   s   || _ || _|| _d S r&   )r„   Ú_revocation_daterp   )r5   rB   rm   r   r   r   r   r3   ¶  s   
z"RevokedCertificateBuilder.__init__c                 C   sZ   t |tjƒs
tdƒ‚| jd urtdƒ‚|dkrtdƒ‚| ¡ dkr%tdƒ‚t|| j| j	ƒS )NrŽ   r�   r   z$The serial number should be positiver�   r‘   )
rt   r’   r“   ru   r„   r   r”   r¦   r§   rp   r•   r   r   r   rB   ¼  s   

ÿz'RevokedCertificateBuilder.serial_numberc                 C   sN   t |tjƒs
tdƒ‚| jd urtdƒ‚t|ƒ}|tkrtdƒ‚t| j|| j	ƒS )Nr—   z)The revocation date may only be set once.zBThe revocation date must be after the unix epoch (1970 January 1).)
rt   r   ru   r§   r   r   r˜   r¦   r„   rp   r™   r   r   r   rm   Í  s   

ÿz)RevokedCertificateBuilder.revocation_datec                 C   sD   t |tƒs	tdƒ‚t|j||ƒ}t|| jƒ t| j| j	| j|g ƒS )Nrx   )
rt   r   ru   r
   r   r   rp   r¦   r„   r§   ry   r   r   r   r{   Ú  s   

þz'RevokedCertificateBuilder.add_extensionc                 C   s.   | j d u r	tdƒ‚| jd u rtdƒ‚| | ¡S )Nz/A revoked certificate must have a serial numberz1A revoked certificate must have a revocation date)r„   r   r§   Úcreate_x509_revoked_certificate)r5   r*   r   r   r   Úbuildå  s   

ÿ
zRevokedCertificateBuilder.build)r    r!   r"   r3   rB   rm   r{   r©   r   r   r   r   r¦   µ  s    
ÿr¦   c                   C   s   t  t d¡d¡d? S )Né   Úbigr   )r   Úint_from_bytesÚosÚurandomr   r   r   r   Úrandom_serial_numberð  s   r¯   )-Ú
__future__r   r   r   r]   r   r­   Úenumr   r’   Úcryptographyr   Ú)cryptography.hazmat.primitives.asymmetricr   r   r	   Úcryptography.x509.extensionsr
   r   Úcryptography.x509.namer   r˜   r   r   r   r'   r,   r-   r.   r/   r0   Ú	Exceptionr1   Úadd_metaclassÚABCMetaÚobjectr:   r`   rj   rl   rn   r€   r›   r¦   r¯   r   r   r   r   Ú<module>   sF   

i
j
L) (_;