+
      xi£  c                  s‚   € R t ^ RIHt ^ RIHt ]'       d   ^ RIHtHt ^ RIH	t	 RR R llt
RR R	 llt ! R
 R4      tR# )zŠModule for handling signed PSKC files.

This module defines a Signature class that handles the signature checking,
keys and certificates.
)Úannotations)ÚTYPE_CHECKING)Ú_ElementÚ_ElementTree©ÚPSKCNc               s4   € V ^8„  d   QhRRRRRRRRR	RR
RRR/# )é   Úxmlr   ÚkeyÚbytesÚcertificateZstrÚ	algorithmú
str | NoneÚdigest_algorithmÚcanonicalization_methodÚreturn© ©Zformató   "Ú3/usr/lib/python3.14/site-packages/pskc/signature.pyÚ__annotate__r   %   sN   € ÷ +ñ +Ø	ð+à	ð+ð ð+ð ð	+ð
 !ð+ð (ð+ð ñ+ó    c                sj  € ^ RI HpHpHp T;'       g    RpT;'       g    RpT;'       g    \	        VRR4      ;'       g    RpV! VP
                  VP                  R^4      R
,          P                  4       VP                  R^4      R
,          P                  4       VR7      P                  WVR	7      # )z—Sign PSKC data using X.509 certificate and private key.

xml: an XML document
key: the private key in binary format
certificate: the X.509 certificate
)Ú	XMLSignerÚXMLSignatureProcessorÚmethodsz
rsa-sha256Zsha256Zdefault_c14n_algorithmNz$http://www.w3.org/2006/12/xml-c14n11Z#)ZmethodZsignature_algorithmr   Zc14n_algorithm)r   Zcertiÿÿÿÿ)	Úsignxmlr   r   r   ZgetattrZ	envelopedZrsplitZlowerÚsign)	r   r   r
   r   r   r   r   r   r   s	   &&&&&&   r   Ú	sign_x509r   %   sº   € ÷ BÑAØ×)Ð)˜\€IØ'×3Ð3¨8Ðà÷ 	/ð 	/ÜÐ%Ð'?ÀÓF÷	/ð 	/à.ð ñ Ø× Ñ Ø%×,Ñ,¨S°!Ó4°RÕ8×>Ñ>Ó@Ø)×0Ñ0°°aÓ8¸Õ<×BÑBÓDØ.ô	÷
 dˆ3˜k€dÓ*ð+r   c               s(   € V ^8„  d   QhRRRRRRRR/# )r   Útreer   r
   r   Úca_pem_filer   r   r   r   r   r   r   B   s)   € ÷ ñ hð ¨Zð ÈZð Ðckñ r   c                sR   € ^ RI Hp V! 4       P                  WVR7      P                  # )a   Verify signature in PSKC data against a trusted X.509 certificate.

:param certificate: a PEM encoded certificate that is used for verification
:param ca_pem_file: the name of a file that contains a CA certificate

The signature can be verified in three ways:

* The signature has an embedded certificate that is signed by a CA that is
  configured in the system CA store. In this case neither `certificate` or
  `ca_pem_file` need to be specified
* The signature was made  and a certificate was transmitted out-of-band.
  In this case the `certificate` argument needs to be present.
* The signature has a certificate that is signed by a specific CA who's
  certificate was transmitted out-of-band. In this case the `ca_pem_file`
  is used to point to a CA certificate file (but a certificate needs to be
  embedded inside the PSKC file).

This function will raise an exception when the validation fails.

After calling this function a verified version of the PSKC file will
be present in the :attr:`signed_pskc` attribute.
)ÚXMLVerifier)Z	x509_certr   )r   r   ÚverifyÚ
signed_xml)r   r
   r   r   s   &&& r   Úverify_x509r!   B   s.   € õ. $Ù‹=×ÑØØð  ó ÷ jðr   c                  s¾   € ] tR t^`tRtR R lt]R R l4       t]R R l4       t]P                  R R	 l4       t]R
 R l4       t
RR R lltRR R lltR R ltRtR# )Ú	Signatureas  Class for handling signature checking of the PSKC file.

Instances of this class provide the following properties:

  is_signed: boolean to indicate whether a signature is present
  algorithm: identifier of the signing algorithm used
  canonicalization_method: identifier of the XML canonicalization used
  digest_algorithm: algorithm used for creating the hash
  issuer: issuer of the certificate
  serial: serial number of the certificate
  key: key that will be used when creating a signed PSKC file
  certificate: the certificate that is embedded in the signature
  signed_pskc: a PSKC instance with the signed information
c               ó    € V ^8„  d   QhRRRR/# )r   Úpskcr   r   ÚNoner   r   r   r   r   ÚSignature.__annotate__p   s   € ÷ ,ñ ,˜Tð , dñ ,r   c                	st   € Wn         R V n        R V n        R V n        R V n        R V n        R V n        R V n        R # ©N)r$   Ú
_algorithmr   r   ÚissuerÚserialr   r
   )Úselfr$   ó   &&r   Ú__init__ZSignature.__init__p   s;   € ØŒ	Ø&*ˆŒØ37ˆÔ$Ø,0ˆÔØ"&ˆŒØ"&ˆŒØ!%ˆŒØ'+ˆÖr   c               ó   € V ^8„  d   QhRR/# )r   r   Úboolr   r   r   r   r   r&   {   s   € ÷ Fñ F˜4ñ Fr   c                sÌ   € \        V P                  ;'       gI    V P                  ;'       g5    V P                  ;'       g!    V P                  ;'       g    V P
                  4      # )zšTest whether the PSKC file contains a signature.

This method does not check whether the signature is valid but only if
one was present in the PSKC file.
)r/   r   r   r   r)   r
   ©r+   ó   &r   Ú	is_signedZSignature.is_signedz   sk   € ô ØN‰N÷ Eð E˜d×:Ñ:÷ Eð EØ×!Ñ!÷Eð EØ%)§[¡[÷Eð EØ48×4DÑ4DóFð 	Fr   c               r.   )r   r   r   r   r   r   r   r   r&   †   s   € ÷ ñ ˜:ñ r   c                sB   € V P                   '       d   V P                   # R# )z#Provide the signing algorithm used.N)r(   r0   r1   r   r   ÚSignature.algorithm…   s   € ð ??ˆ?Ø—?‘?Ð"Ùr   c               r#   )r   Úvaluer   r   r%   r   r   r   r   r   r&      s   € ÷ 5ñ 5˜zð 5¨dñ 5r   c                	s,   € ^ RI Hp V! V4      V n        R# )i    )Únormalise_algorithmN)Zpskc.algorithmsr5   r(   )r+   r4   r5   s   && r   r   r3   Œ   s   € å7Ù-¨eÓ4ˆŽr   c               r.   )r   r   r   r   r   r   r   r   r&   ’   s   € ÷ !ñ !˜Tñ !r   c                s^   € \        V R4      '       g   V P                  4        V P                  # )z$Provide the signed PSKC information.Ú_signed_pskc)Zhasattrr   r6   r0   r1   r   Úsigned_pskcZSignature.signed_pskc‘   s&   € ô t˜^×,Ò,ØK‰KŒMØ× Ñ Ð r   Nc               s$   € V ^8„  d   QhRRRRRR/# )r   r
   r   r   r   r/   r   r   r   r   r   r&   ˜   s"   € ÷ ñ  *ð À*ð ÐX\ñ r   c                sŠ   € ^ RI Hp ^ RIHp V  \	        V P
                  W4      pV! 4       pVP                  We4       W`n        R# )aþ  Verify signature in PSKC data against a trusted X.509 certificate.

The signature can be verified in three ways:

* The signature has an embedded certificate that is signed by a CA that is
  configured in the system CA store. In this case neither `certificate` or
  `ca_pem_file` need to be specified
* The signature was made  and a certificate was transmitted out-of-band.
  In this case the `certificate` argument needs to be present.
* The signature has a certificate that is signed by a specific CA who's
  certificate was transmitted out-of-band. In this case the `ca_pem_file`
  is used to point to a CA certificate file (but a certificate needs to be
  embedded inside the PSKC file).

This function will raise an exception when the validation fails. The `certificate`
is expected to be passed as a PEM encoded string. The `ca_pem_file` should point to a CA
certificate store (PEM encoded file).

After calling this function a verified version of the PSKC file will
be present in the :attr:`signed_pskc` attribute.
r   )Ú
PSKCParserT)r$   r   Zpskc.parserr8   r!   r   Zparse_documentr6   )r+   r
   r   r   r8   r    r$   s   &&&    r   r   ZSignature.verify˜   s;   € õ, 	Ý*ÙÜ  §¡¨KÓEˆ
Ù‹vˆØ×!Ñ! $Ô3Ø ÔÙr   c               s$   € V ^8„  d   QhRRRRRR/# )r   r   r	   r
   r   r   r%   r   r   r   r   r   r&   ·   s!   € ÷ 
'ñ 
'˜ð 
'¨Jð 
'À$ñ 
'r   c                s   € Wn         W n        R# )a  Add an XML signature to the file.

Set up a key and optionally a certificate that will be used to create an
embedded XML signature when writing the file.

This is a utility function that is used to configure the properties
needed to create a signed PSKC file.
N)r   r
   )r+   r   r
   s   &&&r   r   ZSignature.sign·   s   € ð ŒØ&Ör   c               s    € V ^8„  d   QhRRRR/# )r   r   r   r   r   r   r   r   r   r&   Ã   s   € ÷ Añ A˜Hð A¨ñ Ar   c                sÔ   € V P                   '       g   Q hV P                  '       g   Q h\        WP                   V P                  V P                  V P                  V P
                  4      # )z=Sign an XML document with the configured key and certificate.)r   r
   r   r   r   r   )r+   r   r,   r   Úsign_xmlZSignature.sign_xmlÃ   sV   € àxxˆxˆˆxØ××ÐÐÐÜØ—‘˜4×+Ñ+¨T¯^©^Ø×!Ñ! 4×#?Ñ#?óAð 	Ar   )	r(   r6   r   r
   r   r)   r   r$   r*   ©NNr'   )Z__name__Z
__module__Z__qualname__Z__firstlineno__Ú__doc__r-   Zpropertyr2   r   Zsetterr7   r   r   r9   Z__static_attributes__r   r   r   r"   r"   `   sz   † ñõ,ð ôFó ðFð ôó ðð ×Ñô5ó ð5ð ô!ó ð!÷÷>
'÷Añ Ar   r"   )NNNr:   )r;   Z
__future__r    Ztypingr   Z
lxml.etreer   r   r$   r   r   r!   r"   r   r   r   Ú<module>r<      s3   ðñ*õ #å  çß1å÷+÷:÷<iAó iAr   