o
    Bd\R½!  ã                   @   sb   d Z dZddgZddlZddlmZ ddlmZmZm	Z	 ddl
T G d	d„ dƒZd
d„ Zdd„ ZdS )ar  
RSA digital signature protocol according to PKCS#1 v1.5

See RFC3447__ or the `original RSA Labs specification`__.

This scheme is more properly called ``RSASSA-PKCS1-v1_5``.

For example, a sender may authenticate a message using SHA-1 like
this:

        >>> from Crypto.Signature import PKCS1_v1_5
        >>> from Crypto.Hash import SHA
        >>> from Crypto.PublicKey import RSA
        >>>
        >>> message = 'To be signed'
        >>> key = RSA.importKey(open('privkey.der').read())
        >>> h = SHA.new(message)
        >>> signer = PKCS1_v1_5.new(key)
        >>> signature = signer.sign(h)

At the receiver side, verification can be done using the public part of
the RSA key:

        >>> key = RSA.importKey(open('pubkey.der').read())
        >>> h = SHA.new(message)
        >>> verifier = PKCS1_v1_5.new(key)
        >>> if verifier.verify(h, signature):
        >>>    print "The signature is authentic."
        >>> else:
        >>>    print "The signature is not authentic."

:undocumented: __revision__, __package__

.. __: http://www.ietf.org/rfc/rfc3447.txt
.. __: http://www.rsa.com/rsalabs/node.asp?id=2125
z$Id$ÚnewÚPKCS115_SigSchemeé    N)Úceil_div)ÚDerSequenceÚDerNullÚDerOctetString)Ú*c                   @   s0   e Zd ZdZdd„ Zdd„ Zdd„ Zdd	„ Zd
S )r   zLThis signature scheme can perform PKCS#1 v1.5 RSA signature or verification.c                 C   s
   || _ dS )a  Initialize this PKCS#1 v1.5 signature scheme object.
        
        :Parameters:
         key : an RSA key object
          If a private half is given, both signature and verification are possible.
          If a public half is given, only verification is possible.
        N)Ú_key)ÚselfÚkey© r   úM/var/www/html/env/lib/python3.10/site-packages/Crypto/Signature/PKCS1_v1_5.pyÚ__init__G   s   
zPKCS115_SigScheme.__init__c                 C   s
   | j  ¡ S )zCReturn True if this cipher object can be used for signing messages.)r	   Úhas_private)r
   r   r   r   Úcan_signQ   s   
zPKCS115_SigScheme.can_signc                 C   sN   t jj | jj¡}t|dƒ}t||ƒ}| j |¡}t	dƒ|t
|ƒ  | }|S )az  Produce the PKCS#1 v1.5 signature of a message.
    
        This function is named ``RSASSA-PKCS1-V1_5-SIGN``, and is specified in
        section 8.2.1 of RFC3447.
    
        :Parameters:
         mhash : hash object
                The hash that was carried out over the message. This is an object
                belonging to the `Crypto.Hash` module.
    
        :Return: The signature encoded as a string.
        :Raise ValueError:
            If the RSA key length is not sufficiently long to deal with the given
            hash algorithm.
        :Raise TypeError:
            If the RSA key has no private half.
        é   r   )ÚCryptoÚUtilÚnumberÚsizer	   Únr   ÚEMSA_PKCS1_V1_5_ENCODEÚdecryptÚbchrÚlen)r
   ÚmhashÚmodBitsÚkÚemÚmÚSr   r   r   ÚsignU   s   

zPKCS115_SigScheme.signc                 C   s€   t jj | jj¡}t|dƒ}t|ƒ|krdS | j |d¡d }t	dƒ|t|ƒ  | }z
t
||ƒ}W ||kS  ty?   Y dS w )a†  Verify that a certain PKCS#1 v1.5 signature is authentic.
    
        This function checks if the party holding the private half of the key
        really signed the message.
    
        This function is named ``RSASSA-PKCS1-V1_5-VERIFY``, and is specified in
        section 8.2.2 of RFC3447.
    
        :Parameters:
         mhash : hash object
                The hash that was carried out over the message. This is an object
                belonging to the `Crypto.Hash` module.
         S : string
                The signature that needs to be validated.
    
        :Return: True if verification is correct. False otherwise.
        r   r   )r   r   r   r   r	   r   r   r   Úencryptr   r   Ú
ValueError)r
   r   r    r   r   r   Úem1Úem2r   r   r   Úverifyu   s   
ùÿzPKCS115_SigScheme.verifyN)Ú__name__Ú
__module__Ú__qualname__Ú__doc__r   r   r!   r&   r   r   r   r   r   D   s    
 c                 C   sˆ   t | jtƒ  ¡ gƒ}t|  ¡ ƒ}t | ¡ | ¡ gƒ ¡ }|t|ƒd k r,tdt|ƒ ƒ‚tdƒ|t|ƒ d  }t	dƒ| tdƒ | S )a@  
    Implement the ``EMSA-PKCS1-V1_5-ENCODE`` function, as defined
    in PKCS#1 v2.1 (RFC3447, 9.2).

    ``EMSA-PKCS1-V1_5-ENCODE`` actually accepts the message ``M`` as input,
    and hash it internally. Here, we expect that the message has already
    been hashed instead.

    :Parameters:
     hash : hash object
            The hash object that holds the digest of the message being signed.
     emLen : int
            The length the final encoding must have, in bytes.

    :attention: the early standard (RFC2313) stated that ``DigestInfo``
        had to be BER-encoded. This means that old signatures
        might have length tags in indefinite form, which
        is not supported in DER. Such encoding cannot be
        reproduced by this function.

    :attention: the same standard defined ``DigestAlgorithm`` to be
        of ``AlgorithmIdentifier`` type, where the PARAMETERS
        item is optional. Encodings for ``MD2/4/5`` without
        ``PARAMETERS`` cannot be reproduced by this function.

    :Return: An ``emLen`` byte long string that encodes the hash.
    é   z8Selected hash algorith has a too long digest (%d bytes).éÿ   é   z r   )
r   Úoidr   Úencoder   Údigestr   r#   r   Úb)ÚhashÚemLenÚ
digestAlgor0   Ú
digestInfoÚPSr   r   r   r   £   s   0þýr   c                 C   s   t | ƒS )aH  Return a signature scheme object `PKCS115_SigScheme` that
    can be used to perform PKCS#1 v1.5 signature or verification.

    :Parameters:
     key : RSA key object
      The key to use to sign or verify the message. This is a `Crypto.PublicKey.RSA` object.
      Signing is only possible if *key* is a private RSA key.

    )r   )r   r   r   r   r   á   s   
)r*   Ú__revision__Ú__all__ÚCrypto.Util.numberr   r   ÚCrypto.Util.asn1r   r   r   ÚCrypto.Util.py3compatr   r   r   r   r   r   r   Ú<module>   s   %_>