o
     `6                     @   s   d dl mZmZmZ d dlZd dlmZmZ d dlm	Z	 d dl
mZmZmZmZmZmZ d dlmZ d dlmZ d dlmZmZmZmZmZmZmZ d	d
 Zdd Zdd Zdd Z dd Z!e"eG dd de#Z$e"eG dd de#Z%dS )    )absolute_importdivisionprint_functionN)utilsx509)UnsupportedAlgorithm)_CRL_ENTRY_REASON_CODE_TO_ENUM_asn1_integer_to_int_asn1_string_to_bytes_decode_x509_name_obj2txt_parse_asn1_generalized_time)_Certificate)serialization)OCSPCertStatusOCSPRequestOCSPResponseOCSPResponseStatus_CERT_STATUS_TO_ENUM_OIDS_TO_HASH_RESPONSE_STATUS_TO_ENUMc                    s   t   fdd}|S )Nc                    s$   | j tjkr
td | g|R  S )NzCOCSP response status is not successful so the property has no value)response_statusr   
SUCCESSFUL
ValueError)selfargsfunc home/ych/rk3568/buildroot/output/rockchip_rk3568/host/lib/python3.10/site-packages/cryptography/hazmat/backends/openssl/ocsp.pywrapper!   s
   z._requires_successful_response.<locals>.wrapper)	functoolswraps)r   r    r   r   r   _requires_successful_response    s   	r#   c                 C   s^   | j d}| j| j j| j j|| j j|}| |dk | |d | j jk t| |d S NASN1_OCTET_STRING **   r   _ffinew_libOCSP_id_get0_infoNULLopenssl_assertr
   )backendcert_idZkey_hashresr   r   r   _issuer_key_hash.   s   r1   c                 C   s^   | j d}| j|| j j| j j| j j|}| |dk | |d | j jk t| |d S r$   r'   )r.   r/   Z	name_hashr0   r   r   r   _issuer_name_hash<   s   r2   c                 C   s^   | j d}| j| j j| j j| j j||}| |dk | |d | j jk t| |d S )NzASN1_INTEGER **r&   r   )r(   r)   r*   r+   r,   r-   r	   )r.   r/   numr0   r   r   r   _serial_numberJ   s   r4   c                 C   s   | j d}| j| j j|| j j| j j|}| |dk | |d | j jk t| |d }zt| W S  tyB   t	d
|w )NzASN1_OBJECT **r&   r   z*Signature algorithm OID: {} not recognized)r(   r)   r*   r+   r,   r-   r   r   KeyErrorr   format)r.   r/   Zasn1objr0   oidr   r   r   _hash_algorithmT   s$   
r8   c                   @   sb  e Zd Zdd ZedZeedd Z	eedd Z
eedd	 Zeed
d Zeedd Zeedd Zeedd Zdd Zeedd Zeedd Zeedd Zeedd Zeedd Zeedd Zeed d! Zeed"d# Zeed$d% Zeed&d' Zejed(d) Zejed*d+ Zd,d- Zd.S )/_OCSPResponsec                 C   s  || _ || _| j j| j}| j |tv  t| | _| jtju r| j j	| j}| j || j j
jk | j j
|| j jj| _| j j| j}|dkrStd|| j j| jd| _| j | j| j j
jk | j j| j| _| j | j| j j
jk d S d S )Nr&   zhOCSP response contains more than one SINGLERESP structure, which this library does not support. {} foundr   )_backend_ocsp_responser*   ZOCSP_response_statusr-   r   _statusr   r   ZOCSP_response_get1_basicr(   r,   gcZOCSP_BASICRESP_free_basicZOCSP_resp_countr   r6   ZOCSP_resp_get0_singleZOCSP_SINGLERESP_get0_id_cert_id)r   r.   Zocsp_responsestatusZbasicZnum_respr   r   r   __init__j   s<   

z_OCSPResponse.__init__r<   c                 C   s>   | j j| j}| j || j jjk t| j |j}t	
|S N)r:   r*   ZOCSP_resp_get0_tbs_sigalgr>   r-   r(   r,   r   	algorithmr   ZObjectIdentifier)r   Zalgr7   r   r   r   signature_algorithm_oid   s   
z%_OCSPResponse.signature_algorithm_oidc                 C   s0   | j }ztj| W S  ty   td|w )Nz)Signature algorithm OID:{} not recognized)rE   r   Z_SIG_OIDS_TO_HASHr5   r   r6   )r   r7   r   r   r   signature_hash_algorithm   s   z&_OCSPResponse.signature_hash_algorithmc                 C   s2   | j j| j}| j || j jjk t| j |S rC   )r:   r*   ZOCSP_resp_get0_signaturer>   r-   r(   r,   r
   )r   sigr   r   r   	signature   s   z_OCSPResponse.signaturec                    s    j j j} j | j jjk  j jd} j j||} j |d  j jjk  j j	| fdd} j |dk  j j
|d |d d  S )Nzunsigned char **r   c                    s    j j| d S )Nr   )r:   r*   ZOPENSSL_free)pointerr   r   r   <lambda>   s    z2_OCSPResponse.tbs_response_bytes.<locals>.<lambda>)r:   r*   ZOCSP_resp_get0_respdatar>   r-   r(   r,   r)   Zi2d_OCSP_RESPDATAr=   buffer)r   Zrespdatappr0   r   rJ   r   tbs_response_bytes   s   z _OCSPResponse.tbs_response_bytesc                 C   sv   | j j| j}| j j|}g }t|D ]#}| j j||}| j || j jj	k t
| j |}| |_|| q|S rC   )r:   r*   ZOCSP_resp_get0_certsr>   Zsk_X509_numrangeZsk_X509_valuer-   r(   r,   r   Z
_ocsp_respappend)r   Zsk_x509r3   Zcertsir   Zcertr   r   r   certificates   s   z_OCSPResponse.certificatesc                 C   s*   |   \}}|| jjjkrd S t| j|S rC   )_responder_key_namer:   r(   r,   r
   )r   _asn1_stringr   r   r   responder_key_hash      z _OCSPResponse.responder_key_hashc                 C   s*   |   \}}|| jjjkrd S t| j|S rC   )rS   r:   r(   r,   r   )r   	x509_namerT   r   r   r   responder_name   rW   z_OCSPResponse.responder_namec                 C   sP   | j jd}| j jd}| j j| j||}| j |dk |d |d fS )Nr%   zX509_NAME **r&   r   )r:   r(   r)   r*   ZOCSP_resp_get0_idr>   r-   )r   rU   rX   r0   r   r   r   rS      s   z!_OCSPResponse._responder_key_namec                 C   s   | j j| j}t| j |S rC   )r:   r*   ZOCSP_resp_get0_produced_atr>   r   )r   produced_atr   r   r   rZ      s   z_OCSPResponse.produced_atc                 C   sH   | j j| j| j jj| j jj| j jj| j jj}| j |tv  t| S rC   )r:   r*   OCSP_single_get0_statusr?   r(   r,   r-   r   )r   rA   r   r   r   certificate_status   s   z _OCSPResponse.certificate_statusc                 C   sr   | j tjurd S | jjd}| jj| j| jjj	|| jjj	| jjj	 | j
|d | jjj	k t| j|d S NzASN1_GENERALIZEDTIME **r   )r\   r   REVOKEDr:   r(   r)   r*   r[   r?   r,   r-   r   r   Z	asn1_timer   r   r   revocation_time   s   z_OCSPResponse.revocation_timec                 C   sx   | j tjurd S | jjd}| jj| j|| jjj	| jjj	| jjj	 |d dkr,d S | j
|d tv  t|d  S )Nzint *r   )r\   r   r^   r:   r(   r)   r*   r[   r?   r,   r-   r   )r   Z
reason_ptrr   r   r   revocation_reason  s    
z_OCSPResponse.revocation_reasonc                 C   sb   | j jd}| j j| j| j jj| j jj|| j jj | j |d | j jjk t| j |d S r]   )	r:   r(   r)   r*   r[   r?   r,   r-   r   r_   r   r   r   this_update  s   z_OCSPResponse.this_updatec                 C   s^   | j jd}| j j| j| j jj| j jj| j jj| |d | j jjkr-t| j |d S d S r]   )r:   r(   r)   r*   r[   r?   r,   r   r_   r   r   r   next_update,  s   z_OCSPResponse.next_updatec                 C      t | j| jS rC   r1   r:   r@   rJ   r   r   r   issuer_key_hash<     z_OCSPResponse.issuer_key_hashc                 C   re   rC   r2   r:   r@   rJ   r   r   r   issuer_name_hashA  rh   z_OCSPResponse.issuer_name_hashc                 C   re   rC   r8   r:   r@   rJ   r   r   r   hash_algorithmF  rh   z_OCSPResponse.hash_algorithmc                 C   re   rC   r4   r:   r@   rJ   r   r   r   serial_numberK  rh   z_OCSPResponse.serial_numberc                 C      | j j| jS rC   )r:   Z_ocsp_basicresp_ext_parserparser>   rJ   r   r   r   
extensionsP     z_OCSPResponse.extensionsc                 C   ro   rC   )r:   Z_ocsp_singleresp_ext_parserrp   r?   rJ   r   r   r   single_extensionsU  rr   z_OCSPResponse.single_extensionsc                 C   L   |t jjur
td| j }| jj|| j}| j	|dk | j
|S Nz/The only allowed encoding value is Encoding.DERr   )r   EncodingDERr   r:   _create_mem_bio_gcr*   Zi2d_OCSP_RESPONSE_bior;   r-   _read_mem_bior   encodingbior0   r   r   r   public_bytesZ  s   
z_OCSPResponse.public_bytesN)__name__
__module____qualname__rB   r   Zread_only_propertyr   propertyr#   rE   rF   rH   rN   rR   rV   rY   rS   rZ   r\   r`   rb   rc   rd   rg   rj   rl   rn   cached_propertyrq   rs   r}   r   r   r   r   r9   h   s|    
 		r9   c                   @   sZ   e Zd Zdd Zedd Zedd Zedd Zed	d
 Ze	j
dd Zdd ZdS )_OCSPRequestc                 C   s~   |j |dkrtd|| _|| _| jj | jd| _| j| j| jjj	k | jj 
| j| _| j| j| jjj	k d S )Nr&   z+OCSP request contains more than one requestr   )r*   ZOCSP_request_onereq_countNotImplementedErrorr:   _ocsp_requestZOCSP_request_onereq_get0Z_requestr-   r(   r,   ZOCSP_onereq_get0_idr@   )r   r.   Zocsp_requestr   r   r   rB   h  s   z_OCSPRequest.__init__c                 C   re   rC   rf   rJ   r   r   r   rg   v     z_OCSPRequest.issuer_key_hashc                 C   re   rC   ri   rJ   r   r   r   rj   z  r   z_OCSPRequest.issuer_name_hashc                 C   re   rC   rm   rJ   r   r   r   rn   ~  r   z_OCSPRequest.serial_numberc                 C   re   rC   rk   rJ   r   r   r   rl     r   z_OCSPRequest.hash_algorithmc                 C   ro   rC   )r:   Z_ocsp_req_ext_parserrp   r   rJ   r   r   r   rq     s   z_OCSPRequest.extensionsc                 C   rt   ru   )r   rv   rw   r   r:   rx   r*   Zi2d_OCSP_REQUEST_bior   r-   ry   rz   r   r   r   r}     s   
z_OCSPRequest.public_bytesN)r~   r   r   rB   r   rg   rj   rn   rl   r   r   rq   r}   r   r   r   r   r   f  s    




r   )&
__future__r   r   r   r!   cryptographyr   r   Zcryptography.exceptionsr   Z0cryptography.hazmat.backends.openssl.decode_asn1r   r	   r
   r   r   r   Z)cryptography.hazmat.backends.openssl.x509r   Zcryptography.hazmat.primitivesr   Zcryptography.x509.ocspr   r   r   r   r   r   r   r#   r1   r2   r4   r8   Zregister_interfaceobjectr9   r   r   r   r   r   <module>   s$    $
 ~