+
    :i  c                   sN   ^ RI t ^ RIt^ RIHt ^ RIHt ^ RIHt ^ RIH	t	 ^ RI
HtHt ^ RIHtHtHtHt ]P$                  ! ]4      tRt ! R	 R
]4      tR tR tR tR tR tR tR R lt ! R R] P>                  4      t R R lt!]"PG                  R4      R,           t$R R lt%R# )    N)x509)default_backend)serialization)pkcs12)Tlv	int2bytes)	ApduErrorApplicationNotAvailableErrorSmartCardConnectionSmartCardProtocols
   -----BEGINc                   s    ] tR t^2tRtRtR# )InvalidPasswordErrorzLRaised when parsing key/certificate and the password might be wrong/missing. N)__name__
__module____qualname____firstlineno__Z__doc____static_attributes__r       //usr/lib/python3.14/site-packages/ykman/util.pyr   r   2   s    Vr   r   c                 s     \         P                  ! W\        4       4      w  r#pV'       d   VP                  ^ V4       W$3#   \         d   p\        T4      hRp?ii ; i)r    N)r   Zload_key_and_certificatesr   Zinsert
ValueErrorr   )datapasswordkeycertZcases   &&    r   _parse_pkcs12r   6   sX    &99O-
3 JJq$x &"1%%&s   >A AAAc                s   \        V 4      '       d>   RV 9   pV'       d   Vf   \        R4      h \        P                  ! W\	        4       R7      # \        V 4      '       d(   \        W4      ^ ,          pV'       g   \        R4      hV#  \        P                  ! W\	        4       R7      #   \
         d5   pT'       d   \        T4      h\        P                  RRR7        Rp?LRp?i\         d    \        P                  RRR7        Li ; i  \         d    \        P                  R	RR7        Mi ; i\        R
4      h)zIdentify, decrypt and return a cryptography private key object.

:param data: The private key in bytes.
:param password: The password to decrypt the private key
    (if it is encrypted).
s	   ENCRYPTEDNz'No password provided for encrypted key.)Zbackendz Failed to parse PEM private key TZexc_infoz+PKCS12 file does not contain a private key.z"Failed to parse private key as DERzCould not parse private key.)is_pemr   r   Zload_pem_private_keyr   r   loggerdebug	Exception	is_pkcs12r   Zload_der_private_key)r   r   Z	encryptedr   r   s   &&   r   parse_private_keyr!   B   s    d|| D(	)&'PQQ
	L 55(9  D+A.JKK
J11O$5
 	
#  	L*1--LL;dLKK 	LLL;dLK	L  J9DIJ 3
44s5   B( D (D
3*C""D
/D
	D
"D21D2c                s|   \         P                  R4       \        V 4      '       dx   . pV P                  \        4       FG  pV'       g   K   VP                  \        P                  ! \        V,           \        4       4      4       KI  	  V'       g   \        R4      hV# \        V 4      '       d   \        W4      ^,          #  \        P                  ! V \        4       4      .#   \         d    \         P                  RRR7        K  i ; i  \         d    \         P                  RRR7        Mi ; i\        R4      h)zIdentify, decrypt and return a list of cryptography x509 certificates.

:param data: The certificate(s) in bytes.
:param password: The password to decrypt the certificate(s).
z9Attempting to parse certificate using PEM, PKCS12 and DERzFailed to parse PEM certificateTr   z,PEM file does not contain any certificate(s)z"Failed to parse certificate as DERzCould not parse certificate.)r   r   r   ZsplitPEM_IDENTIFIERZappendr   Zload_pem_x509_certificater   r   r   r    r   Zload_der_x509_certificate)r   r   certsr   s   &&  r   parse_certificatesr$   m   s    LLLM d||JJ~.DtSLL66*T1?3D / KLL T,Q//J..t_5FGHH ! SLL!BTLRS  J9DIJ 3
44s$   9C"D ""DD"D0/D0c                s    V  Uu. uF  qP                   NK  	  ppV  Uu. uF  qP                  V9  g   K  VNK  	  ppV# u upi u upi )zExtract the leaf certificates from a list of certificates.

Leaf certificates are ones whose subject does not appear as
issuer among the others.

:param certs: The list of cryptography x509 certificate objects.
)ZissuerZsubject)r#   r   ZissuersZleafss   &   r   get_leaf_certificatesr%      sF     (--ut{{uG-#Ced||7'BTTeECL .Cs   A AAc                 s(    T ;'       d
    \         V 9   # )N)r"   )r      &r   r   r      s    **Nd**r   c                s    \         P                  ! \         P                  ! ^0V 4      4      ^ ,          pVP                  ^8H  ;'       d    VP                  R8H  #   \
         d    \        P                  RRR7        R# i ; i)zz
Tries to identify a PKCS12 container.
The PFX PDU version is assumed to be v3.
See: https://tools.ietf.org/html/rfc7292.
s   zUnable to parse TLVTr   F)r   Z
parse_fromZunpackZtagZvaluer   r   r   )r   Zheader   & r   r    r       sh    ;

4 67:zzT!==fllg&== ;*T:;s   AA 
A "B ?B c                0    V ^8  d   QhR\         R\        /# )   serialreturn)intZstrZformat   "r   __annotate__r/      s     ' '3 '3 'r   c                sv    V R8  d#   RP                  R \        V ^4       4       4      # V  R\        V 4       R2# )z@Displays an x509 certificate serial number in a readable format.l            Z:c              3   s(   "   T F  qR  x  K
  	  R# 5i)Z02xNr   )Z.0Zbr'   r   Z	<genexpr>Z!display_serial.<locals>.<genexpr>   s     B,AqS'
,As   z (Z))Zjoinr   Zhex)r*   r&   r   display_serialr0      s>    $$xxBIfb,ABBBXRF}A&&r   c                   s    ] tR t^tR]P
                  3R]P
                  3R]P
                  3R]P
                  3R]P
                  3R]P                  ^,          3.tRtR# )	OSVERSIONINFOWdwOSVersionInfoSizedwMajorVersiondwMinorVersiondwBuildNumberZdwPlatformIdZszCSDVersionr   N)	r   r   r   r   ctypesZc_ulongZc_wcharZ_fields_r   r   r   r   r1   r1      sV    	/	6>>*	6>>*	&..)	(	#-.Hr   r1   c                sP    V ^8  d   QhR\         \        \        \        3,          /# )r)   r+   )Ztupler,   r-   r.   r   r/   r/      s!     H HU3S=1 Hr   c                 s   \        4       p \        P                  ! V 4      V n        \        P                  P
                  P                  \        P                  ! V 4      4       V P                  V P                  V P                  3# )z?Get the true Windows version, since sys.getwindowsversion lies.)r1   r6   Zsizeofr2   ZwindllZNtdllZRtlGetVersionZbyrefr3   r4   r5   )Zosvis    r   get_windows_versionr7      s[    D%}}T2D
MM%%fll4&89 3 3T5G5GGGr   Z001FD1011B5504s   yubico.com/getting-startedc                r(   )r)   
connectionr+   )r	   Zboolr-   r.   r   r/   r/      s     
$ 
$"5 
$$ 
$r   c           
     s    \        V 4      pVP                  \        P                  R4      4       VP	                  ^ ^^ ^\        ^^.4      4       VP	                  ^ ^^ ^ 4      pV\        8H  #   \
        \        3 d    Rp T\        8H  # i ; i)zJCheck if the given SmartCardConnection over NFC is in restricted NFC mode.ZD2760000850101N)r
   ZselectbytesfromhexZ	send_apdur   r   _RESTRICTED_NDEF)r8   ZpZndefs   &  r   is_nfc_restrictedr<      s    j)	/01	D$dE4,,?@{{4tT2 ### 34 ###s   A#A. .BB)&r6   ZloggingZcryptographyr   Zcryptography.hazmat.backendsr   Zcryptography.hazmat.primitivesr   Z,cryptography.hazmat.primitives.serializationr   Zyubikit.corer   r   Zyubikit.core.smartcardr   r   r	   r
   Z	getLoggerr   r   r"   r   r   r   r!   r$   r%   r   r    r0   Z	Structurer1   r7   r9   r:   r;   r<   r   r   r   <module>r=      s   8    8 8 ? '  
		8	$ W9 W	&(5V$5N
+'V%% H ==!125RR 
$r   