o
    wvXjk  ã                   @   s¼   d Z ddlmZmZ ddlZddlZddlZddlmZ ddl	m
Z
 ddlmZ ddlmZmZ ddlmZ dd	lmZ d
dlmZ dZG dd„ deƒZG dd„ deƒZG dd„ deƒZdS )zX.509 certificates.é    )Úabsolute_importÚunicode_literalsN)Údefault_backend)Úpadding)Úload_pem_x509_certificate)Úbytes_to_strÚensure_bytes)ÚSecurityError)Úvaluesé   )Úreraise_errors)ÚCertificateÚ	CertStoreÚFSCertStorec                   @   sH   e Zd ZdZdd„ Zdd„ Zdd„ Zdd	„ Zd
d„ Zdd„ Z	dd„ Z
dS )r   zX.509 certificate.c                 C   sH   t dtfd�� tt|ƒtƒ d�| _W d   ƒ d S 1 sw   Y  d S )NzInvalid certificate: {0!r})Úerrors)Úbackend)r   Ú
ValueErrorr   r   r   Ú_cert)ÚselfÚcert© r   úX/var/www/html/myproject/venv/lib/python3.10/site-packages/celery/security/certificate.pyÚ__init__   s   ÿ

ÿ"ýzCertificate.__init__c                 C   s   t j  ¡ | jjkS )z%Check if the certificate has expired.)ÚdatetimeÚnowr   Únot_valid_after©r   r   r   r   Úhas_expired    s   zCertificate.has_expiredc                 C   s
   | j  ¡ S )z Get public key from certificate.)r   Ú
public_keyr   r   r   r   Ú
get_pubkey$   s   
zCertificate.get_pubkeyc                 C   s   | j jS )z,Return the serial number in the certificate.)r   Úserial_numberr   r   r   r   Úget_serial_number(   s   zCertificate.get_serial_numberc                 C   s   d  dd„ | jjD ƒ¡S )zReturn issuer (CA) as a string.ú c                 s   s   � | ]}|j V  qd S ©N)Úvalue)Ú.0Úxr   r   r   Ú	<genexpr>.   s   € z)Certificate.get_issuer.<locals>.<genexpr>)Újoinr   Úissuerr   r   r   r   Ú
get_issuer,   s   zCertificate.get_issuerc                 C   s   d  |  ¡ |  ¡ ¡S )z<Serial number/issuer pair uniquely identifies a certificate.z{0} {1})Úformatr*   r!   r   r   r   r   Úget_id0   s   zCertificate.get_idc                 C   s^   t dƒ�! tjt |¡tjjd�}|  ¡  |t|ƒ||¡ W d  ƒ dS 1 s(w   Y  dS )z,Verify signature for string containing data.zBad signature: {0!r})ÚmgfÚsalt_lengthN)r   r   ÚPSSÚMGF1Ú
MAX_LENGTHr   Úverifyr   )r   ÚdataÚ	signatureÚdigestÚpaddr   r   r   r2   4   s   
þ

ÿ"úzCertificate.verifyN)Ú__name__Ú
__module__Ú__qualname__Ú__doc__r   r   r   r!   r*   r,   r2   r   r   r   r   r      s    r   c                   @   s0   e Zd ZdZdd„ Zdd„ Zdd„ Zdd	„ Zd
S )r   z"Base class for certificate stores.c                 C   s
   i | _ d S r#   )Ú_certsr   r   r   r   r   C   s   
zCertStore.__init__c                 c   s   � t | jƒD ]}|V  qdS )zReturn certificate iterator.N)r
   r;   )r   Úcr   r   r   Ú	itercertsF   s   €ÿzCertStore.itercertsc                 C   s.   z| j t|ƒ W S  ty   td |¡ƒ‚w )zGet certificate by id.zUnknown certificate: {0!r})r;   r   ÚKeyErrorr	   r+   )r   Úidr   r   r   Ú__getitem__K   s
   ÿzCertStore.__getitem__c                 C   s2   t | ¡ ƒ}|| jv rtd t¡ƒ‚|| j|< d S )NzDuplicate certificate: {0!r})r   r,   r;   r	   r+   r?   )r   r   Úcert_idr   r   r   Úadd_certR   s   
zCertStore.add_certN)r7   r8   r9   r:   r   r=   r@   rB   r   r   r   r   r   @   s    r   c                   @   s   e Zd ZdZdd„ ZdS )r   zFile system certificate store.c              	   C   s�   t  | ¡ tj |¡rtj |d¡}t |¡D ].}t|ƒ� }t| 	¡ ƒ}| 
¡ r1td | ¡ ¡ƒ‚|  |¡ W d   ƒ n1 s@w   Y  qd S )NÚ*zExpired certificate: {0!r})r   r   ÚosÚpathÚisdirr(   ÚglobÚopenr   Úreadr   r	   r+   r,   rB   )r   rE   ÚpÚfr   r   r   r   r   \   s   

ÿû€ÿzFSCertStore.__init__N)r7   r8   r9   r:   r   r   r   r   r   r   Y   s    r   )r:   Ú
__future__r   r   r   rG   rD   Úcryptography.hazmat.backendsr   Ú)cryptography.hazmat.primitives.asymmetricr   Úcryptography.x509r   Úkombu.utils.encodingr   r   Úcelery.exceptionsr	   Úcelery.fiver
   Úutilsr   Ú__all__Úobjectr   r   r   r   r   r   r   Ú<module>   s    *