3
K^;6                 @   s   d dl mZmZmZ d dlZd dlmZmZ d dlm	Z	 d dl
mZmZmZmZmZmZmZmZmZ d dlmZ d dlmZ d dlmZmZmZmZmZmZmZ d	d
 Z dd Z!dd Z"dd Z#dd Z$ej%eG dd de&Z'ej%eG dd de&Z(dS )    )absolute_importdivisionprint_functionN)utilsx509)UnsupportedAlgorithm)	_CRL_ENTRY_REASON_CODE_TO_ENUM_OCSP_BASICRESP_EXT_PARSER_OCSP_REQ_EXT_PARSER_OCSP_SINGLERESP_EXT_PARSER_asn1_integer_to_int_asn1_string_to_bytes_decode_x509_name_obj2txt_parse_asn1_generalized_time)_Certificate)serialization)OCSPCertStatusOCSPRequestOCSPResponseOCSPResponseStatus_CERT_STATUS_TO_ENUM_OIDS_TO_HASH_RESPONSE_STATUS_TO_ENUMc                s   t j  fdd}|S )Nc                s(   | j tjkrtdn | f| S d S )NzCOCSP response status is not successful so the property has no value)response_statusr   
SUCCESSFUL
ValueError)selfargs)func M/tmp/pip-unpacked-wheel-vvkwn1hz/cryptography/hazmat/backends/openssl/ocsp.pywrapper   s    z._requires_successful_response.<locals>.wrapper)	functoolswraps)r   r"   r    )r   r!   _requires_successful_response   s    
r%   c             C   s^   | j jd}| jj| j j| j j|| j j|}| j|dk | j|d | j jk t| |d S )NzASN1_OCTET_STRING **   r   )_ffinew_libOCSP_id_get0_infoNULLopenssl_assertr   )backendcert_idZkey_hashresr    r    r!   _issuer_key_hash(   s    r0   c             C   s^   | j jd}| jj|| j j| j j| j j|}| j|dk | j|d | j jk t| |d S )NzASN1_OCTET_STRING **r&   r   )r'   r(   r)   r*   r+   r,   r   )r-   r.   Z	name_hashr/   r    r    r!   _issuer_name_hash3   s    r1   c             C   s^   | j jd}| jj| j j| j j| j j||}| j|dk | j|d | j jk t| |d S )NzASN1_INTEGER **r&   r   )r'   r(   r)   r*   r+   r,   r   )r-   r.   numr/   r    r    r!   _serial_number>   s    r3   c             C   s   | j jd}| jj| j j|| j j| j j|}| j|dk | j|d | j jk t| |d }yt| S  tk
r   t	dj
|Y nX d S )NzASN1_OBJECT **r&   r   z*Signature algorithm OID: {} not recognized)r'   r(   r)   r*   r+   r,   r   r   KeyErrorr   format)r-   r.   Zasn1objr/   oidr    r    r!   _hash_algorithmI   s    r7   c               @   sb  e Zd Zdd ZejdZeedd Z	eedd Z
eedd	 Zeed
d Zeedd Zeedd Zeedd Zdd Zeedd Zeedd Zeedd Zeedd Zeedd Zeedd Zeed d! Zeed"d# Zeed$d% Zeed&d' Zejed(d) Zejed*d+ Zd,d- Zd.S )/_OCSPResponsec             C   s   || _ || _| j jj| j}| j j|tk t| | _| jtjkr| j jj	| j}| j j|| j j
jk | j j
j|| j jj| _| j j| j jj| jdk | j jj| jd| _| j j| j| j j
jk | j jj| j| _| j j| j| j j
jk d S )Nr&   r   )_backend_ocsp_responser)   ZOCSP_response_statusr,   r   _statusr   r   ZOCSP_response_get1_basicr'   r+   gcZOCSP_BASICRESP_free_basicZOCSP_resp_countZOCSP_resp_get0_singleZOCSP_SINGLERESP_get0_id_cert_id)r   r-   Zocsp_responsestatusbasicr    r    r!   __init__\   s(    

z_OCSPResponse.__init__r;   c             C   s>   | j jj| j}| j j|| j jjk t| j |j}t	j
|S )N)r9   r)   ZOCSP_resp_get0_tbs_sigalgr=   r,   r'   r+   r   	algorithmr   ZObjectIdentifier)r   Zalgr6   r    r    r!   signature_algorithm_oidz   s    z%_OCSPResponse.signature_algorithm_oidc             C   s8   | j }y
tj| S  tk
r2   tdj|Y nX d S )Nz)Signature algorithm OID:{} not recognized)rD   r   Z_SIG_OIDS_TO_HASHr4   r   r5   )r   r6   r    r    r!   signature_hash_algorithm   s    
z&_OCSPResponse.signature_hash_algorithmc             C   s2   | j jj| j}| j j|| j jjk t| j |S )N)r9   r)   ZOCSP_resp_get0_signaturer=   r,   r'   r+   r   )r   sigr    r    r!   	signature   s    z_OCSPResponse.signaturec                s    j jj j} j j| j jjk  j jjd} j jj||} j j|d  j jjk  j jj	| fdd} j j|dk  j jj
|d |d d  S )Nzunsigned char **r   c                s    j jj| d S )Nr   )r9   r)   ZOPENSSL_free)pointer)r   r    r!   <lambda>   s    z2_OCSPResponse.tbs_response_bytes.<locals>.<lambda>)r9   r)   ZOCSP_resp_get0_respdatar=   r,   r'   r+   r(   Zi2d_OCSP_RESPDATAr<   buffer)r   Zrespdatappr/   r    )r   r!   tbs_response_bytes   s    z _OCSPResponse.tbs_response_bytesc             C   sz   | j jj| j}| j jj|}g }xRt|D ]F}| j jj||}| j j|| j jj	k t
| j |}| |_|j| q,W |S )N)r9   r)   ZOCSP_resp_get0_certsr=   Zsk_X509_numrangeZsk_X509_valuer,   r'   r+   r   Z
_ocsp_respappend)r   Zsk_x509r2   certsir   certr    r    r!   certificates   s    z_OCSPResponse.certificatesc             C   s.   | j  \}}|| jjjkrd S t| j|S d S )N)_responder_key_namer9   r'   r+   r   )r   _asn1_stringr    r    r!   responder_key_hash   s    z _OCSPResponse.responder_key_hashc             C   s.   | j  \}}|| jjjkrd S t| j|S d S )N)rS   r9   r'   r+   r   )r   	x509_namerT   r    r    r!   responder_name   s    z_OCSPResponse.responder_namec             C   sP   | j jjd}| j jjd}| j jj| j||}| j j|dk |d |d fS )NzASN1_OCTET_STRING **zX509_NAME **r&   r   )r9   r'   r(   r)   ZOCSP_resp_get0_idr=   r,   )r   rU   rW   r/   r    r    r!   rS      s    z!_OCSPResponse._responder_key_namec             C   s   | j jj| j}t| j |S )N)r9   r)   ZOCSP_resp_get0_produced_atr=   r   )r   produced_atr    r    r!   rY      s    z_OCSPResponse.produced_atc             C   sH   | j jj| j| j jj| j jj| j jj| j jj}| j j|tk t| S )N)r9   r)   OCSP_single_get0_statusr>   r'   r+   r,   r   )r   r@   r    r    r!   certificate_status   s    z _OCSPResponse.certificate_statusc             C   sr   | j tjk	rd S | jjjd}| jjj| j| jjj	|| jjj	| jjj	 | jj
|d | jjj	k t| j|d S )NzASN1_GENERALIZEDTIME **r   )r[   r   REVOKEDr9   r'   r(   r)   rZ   r>   r+   r,   r   )r   	asn1_timer    r    r!   revocation_time   s    z_OCSPResponse.revocation_timec             C   s|   | j tjk	rd S | jjjd}| jjj| j|| jjj	| jjj	| jjj	 |d dkrXd S | jj
|d tk t|d  S d S )Nzint *r   r&   )r[   r   r\   r9   r'   r(   r)   rZ   r>   r+   r,   r   )r   Z
reason_ptrr    r    r!   revocation_reason   s    z_OCSPResponse.revocation_reasonc             C   sb   | j jjd}| j jj| j| j jj| j jj|| j jj | j j|d | j jjk t| j |d S )NzASN1_GENERALIZEDTIME **r   )	r9   r'   r(   r)   rZ   r>   r+   r,   r   )r   r]   r    r    r!   this_update  s    z_OCSPResponse.this_updatec             C   sb   | j jjd}| j jj| j| j jj| j jj| j jj| |d | j jjkrZt| j |d S d S d S )NzASN1_GENERALIZEDTIME **r   )r9   r'   r(   r)   rZ   r>   r+   r   )r   r]   r    r    r!   next_update  s    z_OCSPResponse.next_updatec             C   s   t | j| jS )N)r0   r9   r?   )r   r    r    r!   issuer_key_hash*  s    z_OCSPResponse.issuer_key_hashc             C   s   t | j| jS )N)r1   r9   r?   )r   r    r    r!   issuer_name_hash/  s    z_OCSPResponse.issuer_name_hashc             C   s   t | j| jS )N)r7   r9   r?   )r   r    r    r!   hash_algorithm4  s    z_OCSPResponse.hash_algorithmc             C   s   t | j| jS )N)r3   r9   r?   )r   r    r    r!   serial_number9  s    z_OCSPResponse.serial_numberc             C   s   t j| j| jS )N)r	   parser9   r=   )r   r    r    r!   
extensions>  s    z_OCSPResponse.extensionsc             C   s   t j| j| jS )N)r   rg   r9   r>   )r   r    r    r!   single_extensionsC  s    z_OCSPResponse.single_extensionsc             C   sL   |t jjk	rtd| jj }| jjj|| j}| jj	|dk | jj
|S )Nz/The only allowed encoding value is Encoding.DERr   )r   EncodingDERr   r9   _create_mem_bio_gcr)   Zi2d_OCSP_RESPONSE_bior:   r,   _read_mem_bio)r   encodingbior/   r    r    r!   public_bytesJ  s    

z_OCSPResponse.public_bytesN)__name__
__module____qualname__rB   r   Zread_only_propertyr   propertyr%   rD   rE   rG   rL   rR   rV   rX   rS   rY   r[   r^   r`   ra   rb   rc   rd   re   rf   cached_propertyrh   ri   rp   r    r    r    r!   r8   Z   sT   

	r8   c               @   sZ   e Zd Zdd Zedd Zedd Zedd Zed	d
 Ze	j
dd Zdd ZdS )_OCSPRequestc             C   s~   |j j|dkrtd|| _|| _| jj j| jd| _| jj| j| jjj	k | jj j
| j| _| jj| j| jjj	k d S )Nr&   z+OCSP request contains more than one requestr   )r)   ZOCSP_request_onereq_countNotImplementedErrorr9   _ocsp_requestZOCSP_request_onereq_get0_requestr,   r'   r+   ZOCSP_onereq_get0_idr?   )r   r-   Zocsp_requestr    r    r!   rB   Z  s    z_OCSPRequest.__init__c             C   s   t | j| jS )N)r0   r9   r?   )r   r    r    r!   rc   h  s    z_OCSPRequest.issuer_key_hashc             C   s   t | j| jS )N)r1   r9   r?   )r   r    r    r!   rd   l  s    z_OCSPRequest.issuer_name_hashc             C   s   t | j| jS )N)r3   r9   r?   )r   r    r    r!   rf   p  s    z_OCSPRequest.serial_numberc             C   s   t | j| jS )N)r7   r9   r?   )r   r    r    r!   re   t  s    z_OCSPRequest.hash_algorithmc             C   s   t j| j| jS )N)r
   rg   r9   rx   )r   r    r    r!   rh   x  s    z_OCSPRequest.extensionsc             C   sL   |t jjk	rtd| jj }| jjj|| j}| jj	|dk | jj
|S )Nz/The only allowed encoding value is Encoding.DERr   )r   rj   rk   r   r9   rl   r)   Zi2d_OCSP_REQUEST_biorx   r,   rm   )r   rn   ro   r/   r    r    r!   rp   |  s    
z_OCSPRequest.public_bytesN)rq   rr   rs   rB   rt   rc   rd   rf   re   r   ru   rh   rp   r    r    r    r!   rv   X  s   rv   ))
__future__r   r   r   r#   Zcryptographyr   r   Zcryptography.exceptionsr   Z0cryptography.hazmat.backends.openssl.decode_asn1r   r	   r
   r   r   r   r   r   r   Z)cryptography.hazmat.backends.openssl.x509r   Zcryptography.hazmat.primitivesr   Zcryptography.x509.ocspr   r   r   r   r   r   r   r%   r0   r1   r3   r7   Zregister_interfaceobjectr8   rv   r    r    r    r!   <module>   s"   ,$ ~