+
     h,  c                   s   ^ RI t ^ RIt^ RIt^ RIHtHt ^ RIt^ RIt^ RIH	t	H
t
 ^ RIHt ^ RIHt ^ RIHt ^ RIHtHt ^ RIHt ^ R	IHt ^ R
IHtHt ^ RIHtHt ^ RIHt ^ RIH t H!t! R t"RR lt#R t$R t%RR lt& ! R R4      t'R# )i    N)urljoinurlparse)hazmatx509)InvalidSignature)backends)DSAPublicKey)ECDSAEllipticCurvePublicKey)PKCS1v15)RSAPublicKey)SHA1Hash)EncodingPublicFormat)ocsp)AuthorizationErrorConnectionErrorc                 s   V P                  4       p \        V\        4      '       d=   VP                  VP                  VP
                  \        4       VP                  4       R# \        V\        4      '       d4   VP                  VP                  VP
                  VP                  4       R# \        V\        4      '       d=   VP                  VP                  VP
                  \        VP                  4      4       R# VP                  VP                  VP
                  4       R#   \         d    \        R 4      hi ; i)zfailed to valid ocsp responseN)
public_key
isinstancer
   ZverifyZ	signatureZtbs_response_bytesr	   Zsignature_hash_algorithmr   r   r   r   r   )issuer_certocsp_responsepubkeys   && //usr/lib/python3.14/site-packages/redis/ocsp.py_verify_responser      s    ##%F?fl++MM''00
66	 --MM''0066
  677MM''00m<<= MM-11=3S3ST ?=>>?s    AD' $AD' -AD' ?&D' 'D>c                s   \         P                  ! V4      pVP                  \         P                  P                  8X  d   \        R4      hVP                  \         P                  P                  8X  dc   VP                  \         P                  P                  8w  d9   \        R\        VP                  4      P                  R4      ^,           R24      hM\        R4      hVP                  \        P                  P                  4       8  d   \        R4      hVP                   '       d9   VP                   \        P                  P                  4       8  d   \        R4      hVP"                  pVP$                  pVP&                  pT pVe   W@P(                  8X  g   We8X  d   T pMVP*                  p\-        WWF4      p	 V	^ ,          p
T
P0                  P3                  \4        P6                  4      pTe4   \4        P8                  P:                  P<                  TP>                  9  d   \        R	4      hT
pV'       d   \A        Ws4       R
#   \.         d    \        R4      hi ; i)z=A wrapper the return the validity of a known ocsp certificatez4you are not authorized to view this ocsp certificatezReceived an Z.z ocsp certificate statusz@failed to retrieve a successful response from the ocsp responderz)ocsp certificate was issued in the futurez1ocsp certificate has invalid update - in the pastz'no certificates found for the responderz'delegate not autorized for ocsp signingT)!r   Zload_der_ocsp_responseZresponse_statusZOCSPResponseStatusZUNAUTHORIZEDr   Z
SUCCESSFULZcertificate_statusZOCSPCertStatusZGOODr   ZstrZsplitZthis_updatedatetimeZnowZnext_updateresponder_nameZissuer_key_hashZresponder_key_hashsubjectcertificates_get_certificates
IndexError
extensionsZget_extension_for_classr   ZExtendedKeyUsageoidZExtendedKeyUsageOIDZOCSP_SIGNINGvaluer   )r   
ocsp_bytesZvalidater   r   Zissuer_hashresponder_hashZcert_to_validatecertsZresponder_certsZresponder_certZexts   &&&         r   _check_certificater%   1   s    //
;M$$(?(?(L(LL !WXX$$(?(?(J(JJ++t/B/B/G/GG!s=#C#CDJJ3OPQRS T* *  H N
 	
   H$5$5$9$9$;;IJJ 	!!!%%(9(9(=(=(??QRR"11N//K"55N""111(&**+
	M,Q/N ''??@U@UV;$((66CC399T!"KLL))9  	M!"KLL	Ms   ?	I
 
I!c                 s(   VfC   V  Uu. uF4  p\        V4      V8X  g   K  VP                  VP                  8X  g   K2  VNK6  	  ppV# V  Uu. uF5  pVP                  V8X  g   K  VP                  VP                  8X  g   K3  VNK7  	  ppV# u upi u upi N)_get_pubkey_hashissuerr   )r$   r   r   r#   cr   s   &&&&  r   r   r   l   s     
"n4 9:[EXEX9X A 	 
 	 
yyN* /0xx;;N;N/N A 	 
 

s!   B
B
B
B#B Bc                 s$   V P                  4       p\        V\        4      '       d0   VP                  \        P
                  \        P                  4      pMs\        V\        4      '       d0   VP                  \        P                  \        P                  4      pM.VP                  \        P
                  \        P                  4      p\        \        4       \        P                  ! 4       R 7      pVP!                  V4       VP#                  4       # ))Zbackend)r   r   r
   public_bytesr   DERr   ZPKCS1r   ZX962ZUncompressedPointZSubjectPublicKeyInfor   r   r   default_backendZupdateZfinalize)Zcertificater   ZhZsha1   &   r   r'   r'   }   s    ##%F &,''l.@.@A	F2	3	3|/M/MNl.O.OP 8 8 :;DKKN==?    c                s|   VR9   d   \        R4      hRpV P                  4       P                  4       pV P                  4        F2  pVP                  4       pVP                  VP
                  8X  g   K0  Tp M	  Vf   \        R4      hVe(   \        P                  ! V4      pWG8w  d   \        R4      h\        W14      # )zAn implementation of a function for set_ocsp_client_callback in PyOpenSSL.

This function validates that the provide ocsp_bytes response is valid,
and matches the expected, stapled responses.
Nzno ocsp response presentz2no matching issuer cert found in certificate chainz/received and expected certificates do not match)r.   N)	r   Zget_peer_certificateZto_cryptographyZget_peer_cert_chainr   r(   r   load_pem_x509_certificater%   )Zconr"   Zexpectedr   Z	peer_certr)   certZes   &&&     r   ocsp_staple_verifierr1      s     [ 899K((*::<I$$&  "<<9+++K	 ' RSS**84>!"STTk66r.   c                   sX   a  ] tR t^t o RtRR ltR tR tR tR t	R t
R	 tR
 tRtV tR# )OCSPVerifierzA class to verify ssl sockets for RFC6960/RFC6961. This can be used
when using direct validation of OCSP responses and certificate revocations.

@see https://datatracker.ietf.org/doc/html/rfc6960
@see https://datatracker.ietf.org/doc/html/rfc6961
Nc                s6    Wn         W n        W0n        W@n        R # r&   )SOCKHOSTPORTCA_CERTS)selfZsockZhostZportca_certss   &&&&&r   __init__ZOCSPVerifier.__init__   s    			 r.   c                s    \         P                  ! V4      p\        P                  ! VP	                  4       \
        P                  ! 4       4      pV# )z?Convert SSL certificates in a binary (DER) format to ASCII PEM.)sslZDER_cert_to_PEM_certr   r/   encoder   r,   )r7   derpemr0   s   &&  r   
_bin2asciiZOCSPVerifier._bin2ascii   s:     &&s+--cjjlH<T<T<VWr.   c                s    V P                   P                  R4      pVRJ d   \        R4      hV P                  V4      pV P	                  V4      # )zThis function returns the certificate, primary issuer, and primary ocsp
server in the chain for a socket already wrapped with ssl.
TFz!no certificate found for ssl peer)r3   Zgetpeercertr   r>   _certificate_components)r7   r<   r0      &  r   components_from_socketZ#OCSPVerifier.components_from_socket   sJ     ii##D)%<!"EFFs#++D11r.   c                s    VP                   P                  \        P                  P                  P
                  4      P                  pT Uu. uF:  pTP                  \        P                  P                  P                  8X  g   K8  TNK<  	  pp T^ ,          P                  P                  pT Uu. uF:  pTP                  \        P                  P                  P                  8X  g   K8  TNK<  	  pp T^ ,          P                  P                  pYT3#   \        P                  P                   P                   d    \        R4      hi ; iu upi   \         d    Rp Li ; iu upi   \         d    \        R4      hi ; i)zGiven an SSL certificate, retract the useful components for
validating the certificate status with an OCSP server.

Args:
    cert ([bytes]): A PEM encoded ssl certificate
z-No AIA information present in ssl certificateNzno ocsp servers in certificate)r   Zget_extension_for_oidr   r    ZExtensionOIDZAUTHORITY_INFORMATION_ACCESSr!   cryptographyZExtensionNotFoundr   Zaccess_methodZAuthorityInformationAccessOIDZ
CA_ISSUERSZaccess_locationr   ZOCSP)r7   r0   ZaiaZiZissuersr(   Zocspsr   s   &&      r   r?   Z$OCSPVerifier._certificate_components   sg   	S//77%%BBe  
$(("H"H"S"SS A 	 

	QZ//55F 
$(("H"H"M"MM A 	 
	D8++11D T!!5   ++== 	S!"QRR	S
  	F	
  	D!"BCC	DsB   AD 5EEE 15E%+E%4E* 5E
E"!E"*Fc                s   \         P                  ! V P                  V P                  3V P                  R7      p\
        P                  ! VP                  4       \        P                  ! 4       4      pV P                  V4      # )zReturn the certificate, primary issuer, and primary ocsp server
from the host defined by the socket. This is useful in cases where
different certificates are occasionally presented.
)r8   )r:   Zget_server_certificater4   r5   r6   r   r/   r;   r   r,   r?   )r7   r=   r0   r@   r   !components_from_direct_connectionZ.OCSPVerifier.components_from_direct_connection   sY     (($))TYY)?$--X--cjjlH<T<T<VW++D11r.   c                s   \         P                  ! 4       pVP                  W#\        P                  P
                  P                  P                  4       4      pVP                  4       p\        P                  ! VP                  \        P
                  P                  P                  P                  4      4      p\        WP!                  R4      4      pV# )z#Return the complete url to the ocspZascii)r   ZOCSPRequestBuilderZadd_certificaterB   r   Z
primitivesZhashesZSHA256Zbuildbase64Z	b64encoder*   Zserializationr   r+   r    Zdecode)r7   serverr0   r   ZorbZrequestZpathZurls   &&&&    r   build_certificate_urlZ"OCSPVerifier.build_certificate_url   s    %%' !!|22==DDKKM
 ))+  !2!2!@!@!I!I!M!MN
 fkk'23
r.   c                s   \         P                  ! V4      pVP                  '       g   \        R4      hVP                  pV P                  V4      pV P                  WV4      pR\        V4      P                  RR/p\         P                  ! WxR7      pVP                  '       g   \        R4      h\        WdP                  R4      # )z3Checks the validity of an ocsp server for an issuerz"failed to fetch issuer certificateZHostzContent-Typezapplication/ocsp-request)Zheadersz failed to fetch ocsp certificateT)
requestsZgetZokr   Zcontentr>   rF   r   Znetlocr%   )	r7   rE   r0   
issuer_urlZrr<   r   Zocsp_urlZheaders	   &&&&     r   check_certificateZOCSPVerifier.check_certificate  s     LL$ttt!"FGGiiooc*--fKH HX&--6
 LL2ttt!"DEE!+yy$??r.   c                s     V P                  4       w  rpVf   \        R4      hV P                  W1V4      #   \         d8    T P	                  4       w  rpTf   \        R4      hT P                  Y1T4      u # i ; i)a  Returns the validity of the certificate wrapping our socket.
This first retrieves for validate the certificate, issuer_url,
and ocsp_server for certificate validate. Then retrieves the
issuer certificate from the issuer_url, and finally checks
the validity of OCSP revocation status.
z%no issuers found in certificate chain)rA   r   rI   r   rC   )r7   r0   rH   Zocsp_serverr-   r   is_validZOCSPVerifier.is_valid!  s    		I,0,G,G,I)Dk!%&MNN))+ZHH! 	I,0,R,R,T)Dk!%&MNN))+ZHH		Is   36 ?A87A8)r6   r4   r5   r3   r&   )Z__name__Z
__module__Z__qualname__Z__firstlineno__Z__doc__r9   r>   rA   r?   rC   rF   rI   rJ   Z__static_attributes__Z__classdictcell__)Z__classdict__s   @r   r2   r2      s;     !
2&"P2 @*I Ir.   r2   )Tr&   )(rD   r   r:   Zurllib.parser    r   Z%cryptography.hazmat.primitives.hashesrB   rG   r   r   Zcryptography.exceptionsr   Zcryptography.hazmatr   Z-cryptography.hazmat.primitives.asymmetric.dsar   Z,cryptography.hazmat.primitives.asymmetric.ecr   r   Z1cryptography.hazmat.primitives.asymmetric.paddingr	   Z-cryptography.hazmat.primitives.asymmetric.rsar
   r   r   Z,cryptography.hazmat.primitives.serializationr   r   Zcryptography.x509r   Zredis.exceptionsr   r   r   r%   r   r'   r1   r2   ) r.   r   <module>rK      s`      
 * ,  % 4 ( F V F F < O " @?88v" 78JI JIr.   