o
    q¨Êh€E  ã                   @   sà  d Z ddlmZmZmZmZ ddlmZmZ ddl	m
Z
mZmZmZmZmZmZmZmZmZmZmZmZ ddlmZmZ ddlmZ ddlmZmZmZm Z  G d	d
„ d
eƒZ!G dd„ deƒZ"G dd„ deƒZ#G dd„ deƒZ$G dd„ deƒZ%G dd„ deƒZ&G dd„ deƒZ'G dd„ deƒZ(G dd„ deƒZ)G dd„ deƒZ*G dd„ deƒZ+G dd „ d eƒZ,G d!d"„ d"eƒZ-G d#d$„ d$eƒZ.G d%d&„ d&eƒZ/G d'd(„ d(eƒZ0G d)d*„ d*eƒZ1G d+d,„ d,eƒZ2G d-d.„ d.eƒZ3G d/d0„ d0eƒZ4G d1d2„ d2eƒZ5G d3d4„ d4eƒZ6G d5d6„ d6eƒZ7G d7d8„ d8eƒZ8G d9d:„ d:eƒZ9G d;d<„ d<eƒZ:G d=d>„ d>eƒZ;G d?d@„ d@eƒZ<G dAdB„ dBeƒZ=G dCdD„ dDeƒZ>G dEdF„ dFeƒZ?G dGdH„ dHeƒZ@G dIdJ„ dJeƒZAG dKdL„ dLeƒZBG dMdN„ dNeƒZCG dOdP„ dPeƒZDdQS )RzÒ
ASN.1 type classes for the online certificate status protocol (OCSP). Exports
the following items:

 - OCSPRequest()
 - OCSPResponse()

Other type classes are defined that help compose the types listed above.
é    )Úunicode_literalsÚdivisionÚabsolute_importÚprint_functioné   )ÚDigestAlgorithmÚSignedDigestAlgorithm)ÚBooleanÚChoiceÚ
EnumeratedÚGeneralizedTimeÚ	IA5StringÚIntegerÚNullÚObjectIdentifierÚOctetBitStringÚOctetStringÚParsableOctetStringÚSequenceÚ
SequenceOf)ÚAuthorityInfoAccessSyntaxÚ	CRLReason)ÚPublicKeyAlgorithm)ÚCertificateÚGeneralNameÚGeneralNamesÚNamec                   @   ó   e Zd ZddiZdS )ÚVersionr   Úv1N©Ú__name__Ú
__module__Ú__qualname__Ú_map© r%   r%   úA/var/www/html/env/lib/python3.10/site-packages/asn1crypto/ocsp.pyr   '   ó    ÿr   c                   @   s(   e Zd ZdefdefdefdefgZdS )ÚCertIdÚhash_algorithmÚissuer_name_hashÚissuer_key_hashÚserial_numberN)r!   r"   r#   r   r   r   Ú_fieldsr%   r%   r%   r&   r(   -   s    ür(   c                   @   s   e Zd ZdefdefgZdS )ÚServiceLocatorÚissuerÚlocatorN)r!   r"   r#   r   r   r-   r%   r%   r%   r&   r.   6   s    þr.   c                   @   r   )ÚRequestExtensionIdz1.3.6.1.5.5.7.48.1.7Úservice_locatorNr    r%   r%   r%   r&   r1   =   r'   r1   c                   @   s4   e Zd ZdefdeddifdefgZdZdeiZ	dS )	ÚRequestExtensionÚextn_idÚcriticalÚdefaultFÚ
extn_value©r4   r7   r2   N)
r!   r"   r#   r1   r	   r   r-   Ú	_oid_pairr.   Ú
_oid_specsr%   r%   r%   r&   r3   C   s    ýÿr3   c                   @   ó   e Zd ZeZdS )ÚRequestExtensionsN)r!   r"   r#   r3   Ú_child_specr%   r%   r%   r&   r<   P   ó    r<   c                   @   sP   e Zd ZdefdedddœfgZdZdZdZdd	„ Z	e
d
d„ ƒZe
dd„ ƒZdS )ÚRequestÚreq_certÚsingle_request_extensionsr   T©ÚexplicitÚoptionalFNc                 C   ód   t ƒ | _| d D ]$}|d j}d| }t| |ƒr!t| ||d jƒ |d jr,| j |¡ qd| _dS )úv
        Sets common named extensions to private attributes and creates a list
        of critical extensions
        rA   r4   ú	_%s_valuer7   r5   TN©ÚsetÚ_critical_extensionsÚnativeÚhasattrÚsetattrÚparsedÚaddÚ_processed_extensions©ÚselfÚ	extensionÚnameÚattribute_namer%   r%   r&   Ú_set_extensions^   ó   


€
zRequest._set_extensionsc                 C   ó   | j s|  ¡  | jS ©z²
        Returns a set of the names (or OID if not a known extension) of the
        extensions marked as critical

        :return:
            A set of unicode strings
        ©rP   rV   rJ   ©rR   r%   r%   r&   Úcritical_extensionsp   ó   
zRequest.critical_extensionsc                 C   ó   | j du r	|  ¡  | jS )z¿
        This extension is used when communicating with an OCSP responder that
        acts as a proxy for OCSP requests

        :return:
            None or a ServiceLocator object
        F)rP   rV   Ú_service_locator_valuer[   r%   r%   r&   Úservice_locator_value~   ó   

zRequest.service_locator_value)r!   r"   r#   r(   r<   r-   rP   rJ   r_   rV   Úpropertyr\   r`   r%   r%   r%   r&   r?   T   s    þ
r?   c                   @   r;   )ÚRequestsN)r!   r"   r#   r?   r=   r%   r%   r%   r&   rc   �   r>   rc   c                   @   r   )ÚResponseTypez1.3.6.1.5.5.7.48.1.1Úbasic_ocsp_responseNr    r%   r%   r%   r&   rd   ‘   r'   rd   c                   @   r;   )ÚAcceptableResponsesN)r!   r"   r#   rd   r=   r%   r%   r%   r&   rf   —   r>   rf   c                   @   s"   e Zd ZdefdeddifgZdS )ÚPreferredSignatureAlgorithmÚsig_identifierÚcert_identifierrD   TN)r!   r"   r#   r   r   r-   r%   r%   r%   r&   rg   ›   s    þrg   c                   @   r;   )ÚPreferredSignatureAlgorithmsN)r!   r"   r#   rg   r=   r%   r%   r%   r&   rj   ¢   r>   rj   c                   @   s   e Zd ZddddœZdS )ÚTBSRequestExtensionIdÚnonceÚacceptable_responsesÚpreferred_signature_algorithms)ú1.3.6.1.5.5.7.48.1.2z1.3.6.1.5.5.7.48.1.4z1.3.6.1.5.5.7.48.1.8Nr    r%   r%   r%   r&   rk   ¦   s
    
ýrk   c                   @   s8   e Zd ZdefdeddifdefgZdZee	e
dœZdS )	ÚTBSRequestExtensionr4   r5   r6   Fr7   r8   )rl   rm   rn   N)r!   r"   r#   rk   r	   r   r-   r9   r   rf   rj   r:   r%   r%   r%   r&   rp   ®   s    ý
ýrp   c                   @   r;   )ÚTBSRequestExtensionsN)r!   r"   r#   rp   r=   r%   r%   r%   r&   rq   ½   r>   rq   c                   @   s@   e Zd Zdedddœfdedddœfd	efd
edddœfgZdS )Ú
TBSRequestÚversionr   r   ©rC   r6   Úrequestor_namer   TrB   Úrequest_listÚrequest_extensionsé   N)r!   r"   r#   r   r   rc   rq   r-   r%   r%   r%   r&   rr   Á   s    ürr   c                   @   r;   )ÚCertificatesN)r!   r"   r#   r   r=   r%   r%   r%   r&   ry   Ê   r>   ry   c                   @   s*   e Zd ZdefdefdedddœfgZdS )Ú	SignatureÚsignature_algorithmÚ	signatureÚcertsr   TrB   N)r!   r"   r#   r   r   ry   r-   r%   r%   r%   r&   rz   Î   s
    ýrz   c                   @   sp   e Zd ZdefdedddœfgZdZdZdZdZ	dZ
dd	„ Zed
d„ ƒZedd„ ƒZedd„ ƒZedd„ ƒZdS )ÚOCSPRequestÚtbs_requestÚoptional_signaturer   TrB   FNc                 C   sh   t ƒ | _| d d D ]$}|d j}d| }t| |ƒr#t| ||d jƒ |d jr.| j |¡ q
d| _dS )	rF   r   rw   r4   rG   r7   r5   TNrH   rQ   r%   r%   r&   rV   â   s   


€
zOCSPRequest._set_extensionsc                 C   rX   rY   rZ   r[   r%   r%   r&   r\   ô   r]   zOCSPRequest.critical_extensionsc                 C   r^   )zÊ
        This extension is used to prevent replay attacks by including a unique,
        random value with each request/response pair

        :return:
            None or an OctetString object
        F©rP   rV   Ú_nonce_valuer[   r%   r%   r&   Únonce_value  ra   zOCSPRequest.nonce_valuec                 C   r^   )a(  
        This extension is used to allow the client and server to communicate
        with alternative response formats other than just basic_ocsp_response,
        although no other formats are defined in the standard.

        :return:
            None or an AcceptableResponses object
        F)rP   rV   Ú_acceptable_responses_valuer[   r%   r%   r&   Úacceptable_responses_value  s   
z&OCSPRequest.acceptable_responses_valuec                 C   r^   )aj  
        This extension is used by the client to define what signature algorithms
        are preferred, including both the hash algorithm and the public key
        algorithm, with a level of detail down to even the public key algorithm
        parameters, such as curve name.

        :return:
            None or a PreferredSignatureAlgorithms object
        F)rP   rV   Ú%_preferred_signature_algorithms_valuer[   r%   r%   r&   Ú$preferred_signature_algorithms_value  ó   
z0OCSPRequest.preferred_signature_algorithms_value)r!   r"   r#   rr   rz   r-   rP   rJ   r‚   r„   r†   rV   rb   r\   rƒ   r…   r‡   r%   r%   r%   r&   r~   Ö   s$    þ


r~   c                   @   ó   e Zd ZdddddddœZdS )	ÚOCSPResponseStatusÚ
successfulÚmalformed_requestÚinternal_errorÚ	try_laterÚsign_requiredÚunauthorized)r   r   rx   é   é   é   Nr    r%   r%   r%   r&   rŠ   0  s    
úrŠ   c                   @   s(   e Zd ZdeddifdeddifgZdS )ÚResponderIdÚby_namerC   r   Úby_keyrx   N)r!   r"   r#   r   r   Ú_alternativesr%   r%   r%   r&   r”   ;  s    þr”   c                   @   s$   e Zd ZdefdedddœfgZdS )ÚRevokedInfoÚrevocation_timeÚrevocation_reasonr   TrB   N)r!   r"   r#   r   r   r-   r%   r%   r%   r&   r˜   B  s    þr˜   c                   @   s4   e Zd ZdeddifdeddifdeddifgZdS )	Ú
CertStatusÚgoodÚimplicitr   Úrevokedr   Úunknownrx   N)r!   r"   r#   r   r˜   r—   r%   r%   r%   r&   r›   I  s
    ýr›   c                   @   s:   e Zd ZdedddœfdedddœfdedddœfgZd	S )
ÚCrlIdÚcrl_urlr   TrB   Úcrl_numr   Úcrl_timerx   N)r!   r"   r#   r   r   r   r-   r%   r%   r%   r&   r    Q  s
    ýr    c                   @   r‰   )	ÚSingleResponseExtensionIdÚcrlÚarchive_cutoffÚ
crl_reasonÚinvalidity_dateÚcertificate_issuerÚ!signed_certificate_timestamp_list)z1.3.6.1.5.5.7.48.1.3z1.3.6.1.5.5.7.48.1.6z	2.5.29.21z	2.5.29.24z	2.5.29.29z1.3.6.1.4.1.11129.2.4.5Nr    r%   r%   r%   r&   r¤   Y  s    
÷r¤   c                   @   s>   e Zd ZdefdeddifdefgZdZee	e
e	eedœZdS )	ÚSingleResponseExtensionr4   r5   r6   Fr7   r8   )r¥   r¦   r§   r¨   r©   rª   N)r!   r"   r#   r¤   r	   r   r-   r9   r    r   r   r   r   r:   r%   r%   r%   r&   r«   g  s    ý
úr«   c                   @   r;   )ÚSingleResponseExtensionsN)r!   r"   r#   r«   r=   r%   r%   r%   r&   r¬   y  r>   r¬   c                	   @   sª   e Zd Zdefdefdefdedddœfded	ddœfgZd
ZdZ	dZ
dZdZdZdZdd„ Zedd„ ƒZedd„ ƒZedd„ ƒZedd„ ƒZedd„ ƒZedd„ ƒZdS )ÚSingleResponseÚcert_idÚcert_statusÚthis_updateÚnext_updater   TrB   Úsingle_extensionsr   FNc                 C   rE   )rF   r²   r4   rG   r7   r5   TNrH   rQ   r%   r%   r&   rV   Ž  rW   zSingleResponse._set_extensionsc                 C   rX   rY   rZ   r[   r%   r%   r&   r\      r]   z"SingleResponse.critical_extensionsc                 C   r^   )z¬
        This extension is used to locate the CRL that a certificate's revocation
        is contained within.

        :return:
            None or a CrlId object
        F)rP   rV   Ú
_crl_valuer[   r%   r%   r&   Ú	crl_value®  ra   zSingleResponse.crl_valuec                 C   r^   )zÜ
        This extension is used to indicate the date at which an archived
        (historical) certificate status entry will no longer be available.

        :return:
            None or a GeneralizedTime object
        F)rP   rV   Ú_archive_cutoff_valuer[   r%   r%   r&   Úarchive_cutoff_value¼  ra   z#SingleResponse.archive_cutoff_valuec                 C   r^   )zŽ
        This extension indicates the reason that a certificate was revoked.

        :return:
            None or a CRLReason object
        F)rP   rV   Ú_crl_reason_valuer[   r%   r%   r&   Úcrl_reason_valueÊ  ó   
	zSingleResponse.crl_reason_valuec                 C   r^   )a=  
        This extension indicates the suspected date/time the private key was
        compromised or the certificate became invalid. This would usually be
        before the revocation date, which is when the CA processed the
        revocation.

        :return:
            None or a GeneralizedTime object
        F)rP   rV   Ú_invalidity_date_valuer[   r%   r%   r&   Úinvalidity_date_value×  rˆ   z$SingleResponse.invalidity_date_valuec                 C   r^   )z—
        This extension indicates the issuer of the certificate in question.

        :return:
            None or an x509.GeneralNames object
        F)rP   rV   Ú_certificate_issuer_valuer[   r%   r%   r&   Úcertificate_issuer_valueç  r¹   z'SingleResponse.certificate_issuer_value)r!   r"   r#   r(   r›   r   r¬   r-   rP   rJ   r³   rµ   r·   rº   r¼   rV   rb   r\   r´   r¶   r¸   r»   r½   r%   r%   r%   r&   r­   }  s6    û




r­   c                   @   r;   )Ú	ResponsesN)r!   r"   r#   r­   r=   r%   r%   r%   r&   r¾   õ  r>   r¾   c                   @   s   e Zd ZdddœZdS )ÚResponseDataExtensionIdrl   Úextended_revoke)ro   z1.3.6.1.5.5.7.48.1.9Nr    r%   r%   r%   r&   r¿   ù  s    
þr¿   c                   @   s6   e Zd ZdefdeddifdefgZdZee	dœZ
dS )	ÚResponseDataExtensionr4   r5   r6   Fr7   r8   )rl   rÀ   N)r!   r"   r#   r¿   r	   r   r-   r9   r   r   r:   r%   r%   r%   r&   rÁ      s    ý
þrÁ   c                   @   r;   )ÚResponseDataExtensionsN)r!   r"   r#   rÁ   r=   r%   r%   r%   r&   rÂ     r>   rÂ   c                	   @   s>   e Zd Zdedddœfdefdefdefded	d
dœfgZdS )ÚResponseDatars   r   r   rt   Úresponder_idÚproduced_atÚ	responsesÚresponse_extensionsr   TrB   N)	r!   r"   r#   r   r”   r   r¾   rÂ   r-   r%   r%   r%   r&   rÃ     s    ûrÃ   c                   @   s0   e Zd ZdefdefdefdedddœfgZdS )	ÚBasicOCSPResponseÚtbs_response_datar{   r|   r}   r   TrB   N)r!   r"   r#   rÃ   r   r   ry   r-   r%   r%   r%   r&   rÈ     s    ürÈ   c                   @   s(   e Zd ZdefdefgZdZdeiZdS )ÚResponseBytesÚresponse_typeÚresponse)rË   rÌ   re   N)	r!   r"   r#   rd   r   r-   r9   rÈ   r:   r%   r%   r%   r&   rÊ   %  s    þÿrÊ   c                   @   sx   e Zd ZdefdedddœfgZdZdZdZdZ	dd	„ Z
ed
d„ ƒZedd„ ƒZedd„ ƒZedd„ ƒZedd„ ƒZdS )ÚOCSPResponseÚresponse_statusÚresponse_bytesr   TrB   FNc                 C   sr   t ƒ | _| d d jd d D ]$}|d j}d| }t| |ƒr(t| ||d jƒ |d jr3| j |¡ qd	| _d
S )rF   rÏ   rÌ   rÉ   rÇ   r4   rG   r7   r5   TN)rI   rJ   rN   rK   rL   rM   rO   rP   rQ   r%   r%   r&   rV   <  s   


€
zOCSPResponse._set_extensionsc                 C   rX   rY   rZ   r[   r%   r%   r&   r\   N  r]   z OCSPResponse.critical_extensionsc                 C   r^   )z§
        This extension is used to prevent replay attacks on the request/response
        exchange

        :return:
            None or an OctetString object
        Fr�   r[   r%   r%   r&   rƒ   \  ra   zOCSPResponse.nonce_valuec                 C   r^   )zÊ
        This extension is used to signal that the responder will return a
        "revoked" status for non-issued certificates.

        :return:
            None or a Null object (if present)
        F)rP   rV   Ú_extended_revoke_valuer[   r%   r%   r&   Úextended_revoke_valuej  ra   z"OCSPResponse.extended_revoke_valuec                 C   s   | d d j S )z’
        A shortcut into the BasicOCSPResponse sequence

        :return:
            None or an asn1crypto.ocsp.BasicOCSPResponse object
        rÏ   rÌ   ©rN   r[   r%   r%   r&   re   x  s   	z OCSPResponse.basic_ocsp_responsec                 C   s   | d d j d S )z�
        A shortcut into the parsed, ResponseData sequence

        :return:
            None or an asn1crypto.ocsp.ResponseData object
        rÏ   rÌ   rÉ   rÒ   r[   r%   r%   r&   Úresponse_dataƒ  s   	zOCSPResponse.response_data)r!   r"   r#   rŠ   rÊ   r-   rP   rJ   r‚   rÐ   rV   rb   r\   rƒ   rÑ   re   rÓ   r%   r%   r%   r&   rÍ   1  s&    þ




rÍ   N)EÚ__doc__Ú
__future__r   r   r   r   Úalgosr   r   Úcorer	   r
   r   r   r   r   r   r   r   r   r   r   r   r¥   r   r   Úkeysr   Úx509r   r   r   r   r   r(   r.   r1   r3   r<   r?   rc   rd   rf   rg   rj   rk   rp   rq   rr   ry   rz   r~   rŠ   r”   r˜   r›   r    r¤   r«   r¬   r­   r¾   r¿   rÁ   rÂ   rÃ   rÈ   rÊ   rÍ   r%   r%   r%   r&   Ú<module>   sV   
<	9	Zx
	