403Webshell
Server IP : 3.96.16.70  /  Your IP : 216.73.216.15
Web Server : Apache
System : Linux ip-172-31-26-103.ca-central-1.compute.internal 6.1.163-186.299.amzn2023.x86_64 #1 SMP PREEMPT_DYNAMIC Tue Feb 24 16:35:42 UTC 2026 x86_64
User : ec2-user ( 1000)
PHP Version : 8.4.18
Disable Function : NONE
MySQL : OFF  |  cURL : ON  |  WGET : ON  |  Perl : ON  |  Python : OFF  |  Sudo : ON  |  Pkexec : OFF
Directory :  /lib/python3.9/site-packages/acme/__pycache__/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Command :


[ Back ]     

Current File : /lib/python3.9/site-packages/acme/__pycache__/crypto_util.cpython-39.pyc
a

�]e�F�@svdZddlZddlZddlZddlZddlZddlZddlZddlm	Z	ddlm
Z
ddlmZddlmZddlm
Z
ddlmZdd	lmZdd
lmZddlmZddlZddlmZdd
lmZddlmZe�e�ZejZGdd�d�ZGdd�d�Zddeddfe e e!e!e!ee"e!fe
ee ej#d�dd�Z$d/e e
eee"ee"fe%e
eeej&ej'fe d�dd�Z(eej#ej)fee"d�dd�Z*eej#ej)fee"d �d!d"�Z+eej#ej)fee"d �d#d$�Z,eej#ej)fee"d �d%d&�Z-d0ej.e
ee"e
e!e!e%e
eej/e
eeej&ej'fej#d)�d*d+�Z0ej1feeej2eej#fe!e d,�d-d.�Z3dS)1zCrypto utilities.�N)�Any)�Callable)�List)�Mapping)�Optional)�Sequence)�Set)�Tuple)�Union)�crypto)�SSL)�errorsc@sPeZdZeeeejejffd�dd�Z	e
jeeejejfd�dd�Z
dS)�_DefaultCertSelection��certscCs
||_dS�Nr)�selfr�r�4/usr/lib/python3.9/site-packages/acme/crypto_util.py�__init__&sz_DefaultCertSelection.__init__��
connection�returncCs|��}|r|j�|d�SdSr)�get_servernamer�get)rrZserver_namerrr�__call__)sz_DefaultCertSelection.__call__N)�__name__�
__module__�__qualname__r�bytesr	r�PKey�X509rr�
Connectionrrrrrrr%s"rc@s�eZdZdZdeddfejeeee	e
je
jffe
eeejeegefeeejgee	e
je
jffdd�dd�Zeed�dd�Zejdd	�d
d�ZGdd
�d
�Ze	eefd�dd�ZdS)�	SSLSocketa�SSL wrapper for sockets.

    :ivar socket sock: Original wrapped socket.
    :ivar dict certs: Mapping from domain names (`bytes`) to
        `OpenSSL.crypto.X509`.
    :ivar method: See `OpenSSL.SSL.Context` for allowed values.
    :ivar alpn_selection: Hook to select negotiated ALPN protocol for
        connection.
    :ivar cert_selection: Hook to select certificate for connection. If given,
        `certs` parameter would be ignored, and therefore must be empty.

    N)�sockr�method�alpn_selection�cert_selectionrcCsX||_||_||_|s"|s"td��|r2|r2td��|}|durNt|rH|ni�}||_dS)Nz*Neither cert_selection or certs specified.z(Both cert_selection and certs specified.)r$r&r%�
ValueErrorrr')rr$rr%r&r'Zactual_cert_selectionrrrr=s�zSSLSocket.__init__��namercCst|j|�Sr)�getattrr$�rr*rrr�__getattr__TszSSLSocket.__getattr__rcCs�|�|�}|dur&t�d|���dS|\}}t�|j�}|�tj�|�tj	�|�
|�|�|�|jdur||�
|j�|�|�dS)a�SNI certificate callback.

        This method will set a new OpenSSL context object for this
        connection when an incoming connection provides an SNI name
        (in order to serve the appropriate certificate, if any).

        :param connection: The TLS connection object on which the SNI
            extension was received.
        :type connection: :class:`OpenSSL.Connection`

        Nz=Certificate selection for server name %s failed, dropping SSL)r'�logger�debugrr�Contextr%�set_options�OP_NO_SSLv2�OP_NO_SSLv3Zuse_privatekeyZuse_certificater&�set_alpn_select_callbackZset_context)rrZpair�key�certZnew_contextrrr�_pick_certificate_cbWs
�


zSSLSocket._pick_certificate_cbc@sBeZdZdZejdd�dd�Zeed�dd�Z	ee
d	�d
d�ZdS)zSSLSocket.FakeConnectionzFake OpenSSL.SSL.Connection.NrcCs
||_dSr)�_wrapped)rrrrrrwsz!SSLSocket.FakeConnection.__init__r)cCst|j|�Sr)r+r8r,rrrr-zsz$SSLSocket.FakeConnection.__getattr__)�unused_argsrc
GsBz|j��WStjy<}zt�|��WYd}~n
d}~00dSr)r8�shutdownr�Error�socket�error)rr9r=rrrr:}sz!SSLSocket.FakeConnection.shutdown)rrr�__doc__rr"r�strrr-�boolr:rrrr�FakeConnectionrsrA)rc
Cs�|j��\}}z�t�|j�}|�tj�|�tj�|�|j	�|j
durV|�|j
�|�t�
||��}|��t�d|�z|��Wn0tjy�}zt�|��WYd}~n
d}~00||fWS|���Yn0dS)NzPerforming handshake with %s)r$�acceptrr0r%r1r2r3Zset_tlsext_servername_callbackr7r&r4rAr"Zset_accept_stater.r/�do_handshaker;r<r=�close)rr$Zaddr�contextZssl_sockr=rrrrB�s&
 
zSSLSocket.accept)rrrr>�_DEFAULT_SSL_METHODr<rrrr	rr r!�intrrr"rrr?rr-r7rArBrrrrr#0s(
�
���r#i�i,)�r)r*�host�port�timeoutr%�source_address�alpn_protocolsrcCsRt�|�}|�|�d|i}zJt�d||t|�rDd�|d|d�nd�||f}	tj|	fi|��}
Wn0tj	y�}zt
�|��WYd}~n
d}~00t�
|
���}t�||�}
|
��|
�|�|dur�|
�|�z|
��|
��Wn2tj�y}zt
�|��WYd}~n
d}~00Wd�n1�s20Y|
��}|�sNJ�|S)a	Probe SNI server for SSL certificate.

    :param bytes name: Byte string to send as the server name in the
        client hello message.
    :param bytes host: Host to connect to.
    :param int port: Port to connect to.
    :param int timeout: Timeout in seconds.
    :param method: See `OpenSSL.SSL.Context` for allowed values.
    :param tuple source_address: Enables multi-path probing (selection
        of source interface). See `socket.creation_connection` for more
        info. Available only in Python 2.7+.
    :param alpn_protocols: Protocols to request using ALPN.
    :type alpn_protocols: `Sequence` of `bytes`

    :raises acme.errors.Error: In case of any problems.

    :returns: SSL certificate presented by the server.
    :rtype: OpenSSL.crypto.X509

    rLz!Attempting to connect to %s:%d%s.z
 from {0}:{1}r�rHN)rr0Zset_timeoutr.r/�any�formatr<Zcreate_connectionr=r
r;�
contextlib�closingr"Zset_connect_stateZset_tlsext_host_nameZset_alpn_protosrCr:Zget_peer_certificate)r*rIrJrKr%rLrMrEZ
socket_kwargsZsocket_tupler$r=ZclientZ
client_sslr6rrr�	probe_sni�s>

��� 

@
rSF)�private_key_pem�domains�must_staple�ipaddrsrcCs�t�tj|�}t��}g}|dur&g}|dur2g}t|�t|�dkrNtd��|D]}|�d|�qR|D]}|�d|j�qjd�|��	d�}	tj
dd	|	d
�g}
|r�|
�tj
dd	dd
��|�|
�|�|�|�
d�|�|d
�t�tj|�S)a�Generate a CSR containing domains or IPs as subjectAltNames.

    :param buffer private_key_pem: Private key, in PEM PKCS#8 format.
    :param list domains: List of DNS names to include in subjectAltNames of CSR.
    :param bool must_staple: Whether to include the TLS Feature extension (aka
        OCSP Must Staple: https://tools.ietf.org/html/rfc7633).
    :param list ipaddrs: List of IPaddress(type ipaddress.IPv4Address or ipaddress.IPv6Address)
    names to include in subbjectAltNames of CSR.
    params ordered this way for backward competablity when called by positional argument.
    :returns: buffer PEM-encoded Certificate Signing Request.
    NrzAAt least one of domains or ipaddrs parameter need to be not empty�DNS:�IP:�, �ascii�subjectAltNameF�Zcritical�values1.3.6.1.5.5.7.1.24sDER:30:03:02:01:05�sha256)rZload_privatekey�FILETYPE_PEM�X509Req�lenr(�append�exploded�join�encode�
X509Extension�add_extensions�
set_pubkey�set_version�sign�dump_certificate_request)rTrUrVrWZprivate_keyZcsr�sanlist�address�ips�
san_string�
extensionsrrr�make_csr�sF����


�rr)�loaded_cert_or_reqrcs6|��j�t|�}�dur|S�g�fdd�|D�S)Ncsg|]}|�kr|�qSrr)�.0�d�Zcommon_namerr�
<listcomp> �z4_pyopenssl_cert_or_req_all_names.<locals>.<listcomp>)�get_subject�CN�_pyopenssl_cert_or_req_san)rsZsansrrvr� _pyopenssl_cert_or_req_all_namess

r|)�cert_or_reqrcs(d�d��t|�}��fdd�|D�S)a�Get Subject Alternative Names from certificate or CSR using pyOpenSSL.

    .. todo:: Implement directly in PyOpenSSL!

    .. note:: Although this is `acme` internal API, it is used by
        `letsencrypt`.

    :param cert_or_req: Certificate or CSR.
    :type cert_or_req: `OpenSSL.crypto.X509` or `OpenSSL.crypto.X509Req`.

    :returns: A list of Subject Alternative Names that is DNS.
    :rtype: `list` of `str`

    �:ZDNScs$g|]}|���r|���d�qS)rN)�
startswith�split�rt�part��part_separator�prefixrrrw:s�z._pyopenssl_cert_or_req_san.<locals>.<listcomp>��_pyopenssl_extract_san_list_raw)r}�
sans_partsrr�rr{#s�r{cs&d}d|�t|�}�fdd�|D�S)aeGet Subject Alternative Names IPs from certificate or CSR using pyOpenSSL.

    :param cert_or_req: Certificate or CSR.
    :type cert_or_req: `OpenSSL.crypto.X509` or `OpenSSL.crypto.X509Req`.

    :returns: A list of Subject Alternative Names that are IP Addresses.
    :rtype: `list` of `str`. note that this returns as string, not IPaddress object

    r~z
IP Addresscs&g|]}|���r|t��d��qSr)rrbr��r�rrrwOrxz1_pyopenssl_cert_or_req_san_ip.<locals>.<listcomp>r�)r}r�r�rr�r�_pyopenssl_cert_or_req_san_ip>sr�cCsft|tj�r"t�tj|��d�}nt�tj|��d�}t�d|�}d}|durRgn|�	d��
|�}|S)aGet raw SAN string from cert or csr, parse it as UTF-8 and return.

    :param cert_or_req: Certificate or CSR.
    :type cert_or_req: `OpenSSL.crypto.X509` or `OpenSSL.crypto.X509Req`.

    :returns: raw san strings, parsed byte as utf-8
    :rtype: `list` of `str`

    zutf-8z5X509v3 Subject Alternative Name:(?: critical)?\s*(.*)rZNrN)�
isinstancerr!�dump_certificateZ
FILETYPE_TEXT�decoderl�re�search�groupr�)r}�textZraw_sanZparts_separatorr�rrrr�Rsr��:	T)r5rU�
not_before�validity�	force_sanrqrorcCsb|s|sJd��t��}|�tt�t�d��d��|�d�|durJg}|durVg}|durbg}|�	t�
ddd��t|�dkr�|d|��_
|�|���g}|D]}	|�	d	|	�q�|D]}
|�	d
|
j�q�d�|��d�}|�st|�d
k�st|�dk�r|�	tj
dd|d��|�|�|�|du�r8dn|�|�|�|�|�|�|d�|S)atGenerate new self-signed certificate.

    :type domains: `list` of `str`
    :param OpenSSL.crypto.PKey key:
    :param bool force_san:
    :param extensions: List of additional extensions to include in the cert.
    :type extensions: `list` of `OpenSSL.crypto.X509Extension`
    :type ips: `list` of (`ipaddress.IPv4Address` or `ipaddress.IPv6Address`)

    If more than one domain is provided, all of the domains are put into
    ``subjectAltName`` X.509 extension and first domain is set as the
    subject CN. If only one domain is provided no ``subjectAltName``
    extension is used, unless `force_san` is ``True``.

    z7Must provide one or more hostnames or IPs for the cert.��NsbasicConstraintsTsCA:TRUE, pathlen:0rrXrYrZr[rNr\Fr]r_)rr!Zset_serial_numberrG�binasciiZhexlify�os�urandomrjrcrgrbryrzZ
set_issuerrdrerfrhZgmtime_adj_notBeforeZgmtime_adj_notAfterrirk)r5rUr�r�r�rqror6rmrnZiprprrr�gen_ss_certqsH
��"�


r�)�chain�filetypercs8ttjtjftd��fdd��d��fdd�|D��S)z�Dump certificate chain into a bundle.

    :param list chain: List of `OpenSSL.crypto.X509` (or wrapped in
        :class:`josepy.util.ComparableX509`).

    :returns: certificate chain bundle
    :rtype: bytes

    )r6rcs6t|tj�r*t|jtj�r$t�d��|j}t��|�S)NzUnexpected CSR provided.)	r��jose�ComparableX509�wrappedrrar
r;r�)r6)r�rr�
_dump_cert�s

z(dump_pyopenssl_chain.<locals>._dump_certrxc3s|]}�|�VqdSrr)rtr6)r�rr�	<genexpr>�rxz'dump_pyopenssl_chain.<locals>.<genexpr>)r
r�r�rr!rre)r�r�r)r�r�r�dump_pyopenssl_chain�s 	r�)NFN)NNr�TNN)4r>r�rQZ	ipaddressZloggingr�r�r<�typingrrrrrrrr	r
Zjosepyr�ZOpenSSLrrZacmer
Z	getLoggerrr.Z
SSLv23_METHODrFrr#rrGr?r!rSr@ZIPv4AddressZIPv6Addressrrrar|r{r�r�r rgr�r`r�r�rrrr�<module>sz
	x�
�9��7�   ��C��

Youez - 2016 - github.com/yon3zu
LinuXploit