+
    :iQ  c                   s   ^ RI t ^ RIHt ^ RIt^ RIHt ^ RIHtHtH	t	 ^ RI
Ht ^ RIHt ^ RIHtHtHtHt ^RIHtHtHt ^R	IHtHt ^R
IHtHtHtHtHtHtH t H!t!H"t"H#t# ] PH                  ! ]%4      t& ! R R]4      tR t']! ]	.R7      ]PP                  ]R 4       4       4       t]PS                  4       ]PP                  R 4       4       t*]PS                  4       ]]PP                  R 4       4       4       t+R t,]P[                  R4      R 4       t.].PS                  R4      ]P^                  ! R]P`                  ! ^^c4      RR7      ]P^                  ! R]P`                  ! ^^c4      RR7      ]P^                  ! R]P`                  ! ^^c4      RR7      ]Pb                  ! RRRR 7      ]]PP                  R! 4       4       4       4       4       4       4       t2].PS                  R"4      ]Pb                  ! R#R$R%R 7      ]Pb                  ! R&R'R(R 7      ]PP                  R) 4       4       4       4       t3].PS                  R*4      ]Pb                  ! RRR+R 7      ]Pb                  ! R,R-R.R 7      ]PP                  R/ 4       4       4       4       t4].PS                  R04      ]Pb                  ! RRR1R 7      ]Pb                  ! R&R2R3R 7      ]PP                  R4 4       4       4       4       t5].PS                  R54      ]Pb                  ! RRR6R 7      ]Pb                  ! R,R-R7R 7      ]Pb                  ! R&R'R(R 7      ]PP                  R8 4       4       4       4       4       t6].PS                  R94      ]P^                  ! R:R;]! ]4      R<7      ]Pb                  ! RRR=R 7      ]PP                  R> 4       4       4       4       t7]P[                  R?4      R@ 4       t8]8PS                  RA4      ]PP                  ]P^                  ! RBRC]! ]4      R<7      RD 4       4       4       t9]8PS                  RE4      ]P^                  ! RBRC]! ]4      R<7      ]P^                  ! R:R;]! ]4      R<7      ]Pb                  ! RRR=R 7      ]]PP                  RF 4       4       4       4       4       4       t:]8PS                  RG4      ]Pb                  ! RRR=R 7      ]PP                  ]P^                  ! RBRC]! ]4      R<7      ]P^                  ! RH]Pv                  ! RI4      RJR7      RK 4       4       4       4       4       t<]8PS                  4       ]PP                  ]Pb                  ! R#R$RLR 7      ]]P^                  ! RBRC]! ]]Pz                  .RM7      R<7      ]P^                  ! RN]Pv                  ! RO4      RPR7      RQ 4       4       4       4       4       4       t>]P[                  RR4      RS 4       t?]?PS                  RT4      ]PP                  ]P^                  ! RBRC]! ]4      R<7      ]]P^                  ! RN]Pv                  ! RO4      RPR7      RU 4       4       4       4       4       t@]?PS                  RV4      ]Pb                  ! RRR=R 7      ]PP                  ]P^                  ! RBRC]! ]4      R<7      RW 4       4       4       4       tA]?PS                  RG4      ]Pb                  ! RRR=R 7      ]PP                  ]P^                  ! RBRC]! ]4      R<7      ]P^                  ! RX]Pv                  ! RI4      RPR7      RY 4       4       4       4       4       tBR# )Z    N)IntEnum)	TRANSPORT)SW	ApduErrorSmartCardConnection)
CAPABILITY)KEY_REF)
KEY_STATUS
PIN_POLICYUIFOpenPgpSession)get_key_infoget_openpgp_info
safe_reset)parse_certificatesparse_private_key)
CliFail
EnumChoiceclick_force_optionclick_format_optionclick_groupclick_postpone_executionclick_promptget_scp_paramslog_or_echopretty_printc                   sF   a  ] tR t^@t o ^t^t^t^t^tV 3R lR lt	Rt
V tR# )r   c                s    < V ^8  d   QhRS[ /# )i   name)Zstr)format__classdict__s   "7/usr/lib/python3.14/site-packages/ykman/_cli/openpgp.pyZ__annotate__ZKEY_REF.__annotate__G   s     5 5S 5    c                s6    \        V 4      P                  V4      # )N)_KEY_REF__getattribute__)Zselfr      &&r   r!   ZKEY_REF.__getattribute__G   s    ~..t44r    N)__name__Z
__module__Z__qualname__Z__firstlineno__ZSIGZDECZAUTATTZENCr!   Z__static_attributes__Z__classdictcell__)r   s   @r   r   r   @   s(     
C
C
C
C
C5 5r   r   c                 s    \        V R V 4      # )r   )Zgetattr)Zfobjs   &r   _fnamer&   K   s    4&&r   )Zconnectionsc                s\   V P                   R,          pVP                  \        4      pV P                  VP                  4       \        V \        P                  V4      p \        W#4      V P                   R&   R#   \         d   pTP                  \        P                  8X  d3   T'       g+   TP                  \        P                  8X  d   \!        R4      hTP                  \        P"                  8X  d1   T P$                  R8X  d   Y P                   R&    Rp?R# \!        R4      hh Rp?ii ; i)z
Manage the OpenPGP application.

Examples:


  Set the retries for PIN, Reset Code and Admin PIN to 10:
  $ ykman openpgp access set-retries 10 10 10


  Require touch to use the authentication key:
  $ ykman openpgp keys set-touch aut on
Zdevicesessionz-Unable to manage OpenPGP over NFC without SCPresetconnzQMemory corruption detected, OpenPGP needs to be reset using 'ykman openpgp reset'N)objZopen_connectionr   Zcall_on_closeZcloser   r   OPENPGPr   r   swr   CONDITIONS_NOT_SATISFIEDZ	transportr   ZNFCr   ZMEMORY_FAILUREZinvoked_subcommand)ctxZdevr)   Z
scp_paramses   &    r   openpgpr0   O   s    " ''(
C23Ddjj!Z%7%7>J+D=	 DDB///.IJJTTR&&&%%0"&, 
 !s%    A: :D+&D&,A(D&D&&D+c                s>   V P                   R,          p\        V P                   R,          4      p\        P                  VP                  9   d!   \        P                  VP
                  9   VR&   \        P                  ! RP                  \        V4      4      4       R# )z4
Display general status of the OpenPGP application.
infor'   zFIPS approved
N)
r*   r   r   r+   Zfips_capableZfips_approvedclickechojoinr   )r.   r1   Zdatas   &  r   r1   r1   {   sm     776?DCGGI./DT... * 2 2d6H6H H_	JJtyyd+,-r   c                s|   V'       g   \         P                  ! RRRR7       \         P                  ! R4       RV P                  9   d#   V P                  R,          P	                  4        M\        V P                  R,          4       \        P                  R4       \         P                  ! R4       \        4        R	# )
z
Reset all OpenPGP data.

This action will wipe all OpenPGP data, and set all PINs to their default
values.

The attestation key and certificate will NOT be reset.
zaWARNING! This will delete all stored OpenPGP keys and data and restore factory settings. Proceed?TZabortZerrz3Resetting OpenPGP data, don't remove the YubiKey...r'   r)   zOpenPGP application data resetzGReset complete. OpenPGP data has been cleared and default PINs are set.N)	r3   confirmr4   r*   r(   r   loggerr1   echo_default_pins)r.   forcer"   r   r(   r(      s     )		
 
JJDECGG	  "3776?#
KK01	JJQ r   c                  s    \         P                  ! R 4       \         P                  ! R4       \         P                  ! R4       R# )zPIN:         123456zReset code:  NOT SETzAdmin PIN:   12345678N)r3   r4   r#   r   r   r9   r9      s)    	JJ$%	JJ%&	JJ&'r   accessc                     R# )z&Manage PIN, Reset Code, and Admin PIN.Nr#   r#   r   r   r;   r;          r   zset-retrieszuser-pin-retrieszPIN-RETRIES)typemetavarzreset-code-retrieszRESET-CODE-RETRIESzadmin-pin-retrieszADMIN-PIN-RETRIESz-az--admin-pinzadmin PIN for OpenPGP)Zhelpc           	     s   V P                   R,          pVf   \        RRR7      pVP                  R8  pV'       d   \        P                  ! R4       V'       g*   \        P
                  ! RV RV RV R	2RRR
7      '       df   VP                  V4       VP                  W#V4       \        P                  ! R4       V'       d#   \        P                  ! R4       \        4        R# R# R# )zO
Set the number of retry attempts for the User PIN, Reset Code, and Admin PIN.
r'   NEnter Admin PINT
hide_inputzBWARNING: Setting PIN retries will reset the values for all 3 PINs!zSet PIN retry counters to: Z ?r6   z/Number of PIN/Reset Code/Admin PIN retries set.z"Default values have been restored:)i   r    r    )	r*   r   Zversionr3   r4   r7   verify_adminZset_pin_attemptsr9   )r.   	admin_pinZuser_pin_retriesZreset_code_retriesZadmin_pin_retriesr:   r'   Zresets_pinss   &&&&&&  r   set_pin_retriesrF      s    " ggi G !2tD	//I-K

WX
%&6%7q9K8LA
Q	 	  	Y'  2C	
 	

DEJJ;< r   z
change-pinz-Pz--pinzcurrent PIN codez-nz	--new-pinz	a new PINc                >   V P                   R,          pVf   \        RRR7      pVf   \        RRRR7      p VP                  W4       \        P                  ! R4       R#   \
         d1   pTP                  \        P                  8X  d   \        R	4      hh Rp?ii ; i)
z
Change the User PIN.

The PIN has a minimum length of 6 (or 8, for YubiKey 5.7+ FIPS when not using KDF),
and supports any type of alphanumeric characters.
r'   N	Enter PINTrA   New PINrB   Zconfirmation_promptUser PIN has been changed.z)PIN does not meet complexity requirement.)
r*   r   
change_pinr3   r4   r   r,   r   r-   r   )r.   pinnew_pinr'   r/      &&&  r   rL   rL      s     ggi G
{;48 $
3(

/0 442...EFF   'A! !B,+BBzchange-reset-codez	Admin PINz-rz--reset-codeza new Reset Codec                s`   V P                   R,          pVf   \        RRR7      pVf   \        RRRR7      pVP                  V4        VP                  V4       \        P
                  ! R4       R#   \         d1   pTP                  \        P                  8X  d   \        R	4      hh Rp?ii ; i)
zu
Change the Reset Code.

The Reset Code has a minimum length of 6, and supports any type of
alphanumeric characters.
r'   Nr@   TrA   zNew Reset CoderJ   zReset Code has been changed.z0Reset Code does not meet complexity requirement.)r*   r   rD   Zset_reset_coder3   r4   r   r,   r   r-   r   )r.   rE   
reset_coder'   r/   rO   r   change_reset_coderR      s     ggi G !2tD	! $

 #z*

12 442...LMMs   	'A2 2B-=+B((B-zchange-admin-pinzcurrent Admin PINz--new-admin-pinznew Admin PINc                rG   )
zs
Change the Admin PIN.

The Admin PIN has a minimum length of 8, and supports any type of
alphanumeric characters.
r'   Nr@   TrA   zNew Admin PINrJ   zAdmin PIN has been changed.z/Admin PIN does not meet complexity requirement.)
r*   r   change_adminr3   r4   r   r,   r   r-   r   )r.   rE   Znew_admin_pinr'   r/   rO   r   rS   rS   !  s     ggi G !2tD	$ $
Y6

01 442...KLLrP   zunblock-pinz2Admin PIN (use "-" as a value to prompt for input)z
Reset Codec                s   V P                   R,          pVe   Ve   \        R4      hVR8X  d   \        RRR7      pVf   Vf   \        RRR7      pVf   \        R	RRR
7      pV'       d   VP                  V4        VP	                  W24       \
        P                  ! R4       R#   \         d1   pTP                  \        P                  8X  d   \        R4      hh Rp?ii ; i)aJ  
Unblock the PIN (using Reset Code or Admin PIN).

If the PIN is lost or blocked you can reset it to a new value using the Reset Code.
Alternatively, the Admin PIN can be used (using the "-a, --admin-pin" option)
instead of the Reset Code.

The new PIN has a minimum length of 6, and supports any type of
alphanumeric characters.
r'   NzFInvalid options: Only one of --reset-code and --admin-pin may be used.-r@   TrA   zEnter Reset CoderI   rJ   rK   z-New PIN does not meet complexity requirement.)r*   r   r   rD   Z	reset_pinr3   r4   r   r,   r   r-   )r.   rE   rQ   rN   r'   r/      &&&&  r   unblock_pinrV   B  s    & ggi G)"7T
 	
 C !2tD	i/!"4F
 $
 Y''.

/0 442...IJJs   <'B% %C 0+CC zset-signature-policypolicyZPOLICY)r?   r>   zAdmin PIN for OpenPGPc                s    V P                   R,          pVf   \        RRR7      p VP                  V4       VP                  V4       \        P
                  ! R4       R#   \         d    \        R4      hi ; i)z
Set the Signature PIN policy.

The Signature PIN policy is used to control whether the PIN is
always required when using the Signature key, or if it is required
only once per session.


POLICY  signature PIN policy to set (always, once)
r'   Nr@   TrA   z"Signature PIN policy has been set.z'Failed to set new Signature PIN policy.)r*   r   rD   Zset_signature_pin_policyr3   r4   	Exceptionr   )r.   rW   rE   r'      &&& r   set_signature_policyrZ   u  sq     ggi G !2tD	AY'((0

78 A?@@As   8A   A7keysc                 r<   )zManage private keys.Nr#   r#   r   r   r[   r[     r=   r   r1   keyZKEYc                sf   V P                   R,          pVP                  4       P                  pVP                  P	                  V4      pV\
        P                  8X  d   \        RVP                   R24      h\        W1V4      p\        P                  ! RP                  \        V4      4      4       R# )a  
Show metadata about a private key.

This will show what type of key is stored in a specific slot,
whether it was imported into the YubiKey, or generated on-chip,
and what the Touch policy is for using the key.


KEY            key slot to set (sig, dec, aut or att)
r'   zNo key stored in slot .r2   N)r*   Zget_application_related_datadiscretionaryZkey_informationZgetr   ZNONEr   r   r   r3   r4   r5   r   )r.   r\   r'   r^   Zstatusr1   s   &&    r   metadatar_     s     ggi G88:HHM**..s3F .sxxj:;;F3D	JJtyyd+,-r   z	set-touchc                sn   V P                   R,          pVP                  P                  4       P                  RR4      pVf   \	        RRR7      pRVP                   R	V R
2pVP
                  '       d
   RV,           pV'       g    \        P                  ! VRRR7      '       dJ    VP                  V4       VP                  W4       \        P                  ! RVP                   R24       R# R#   \         d;   pTP                  \        P                  8X  d   \        R4      h\        R4      hRp?ii ; i)au  
Set the touch policy for OpenPGP keys.

The touch policy is used to require user interaction for all operations using the
private key on the YubiKey. The touch policy is set individually for each key slot.
To see the current touch policy, run the "openpgp info" subcommand.

WARNING: Setting the touch policy of the attestation key to "fixed" cannot be undone
without replacing the attestation private key.

Touch policies:


Off (default)  no touch required
On             touch required
Fixed          touch required, can't be disabled without deleting the private key
Cached         touch required, cached for 15s after use
Cached-Fixed   touch required, cached for 15s after use, can't be disabled
               without deleting the private key


KEY            key slot to set (sig, dec, aut or att)
POLICY         touch policy to set (on, off, fixed, cached or cached-fixed)
r'   Z_rT   Nr@   TrA   zSet touch policy of z key to rC   r6   zTouch policy for slot z set.zTouch policy not allowed.zFailed to set touch policy.zZWARNING: This touch policy cannot be changed without deleting the corresponding key slot!
)r*   r   ZlowerZreplacer   Zis_fixedr3   r7   rD   Zset_uifr4   r   r,   r   Z SECURITY_CONDITION_NOT_SATISFIEDr   )	r.   r\   rW   rE   r:   r'   Zpolicy_nameZpromptr/   s	   &&&&&    r   	set_touchr`     s   > ggi G++##%--c37K !2tD	#CHH:Xk]!DF* 	 fDd;;	9  +OOC(JJ/z?@	 <
  	9ttr:::9::788	9s   %AC/ /D4:5D//D4Zimportzprivate-keyZrbzPRIVATE-KEYc                s   V P                   R,          pV\        P                  8w  d   V P                  R4       Vf   \	        RRR7      p \        VP                  4       RR7      p TP                  T4       TP                  Y4       \        P                  ! R	TP                   R
24       R#   \         d    \        R4      hi ; i  \         d    \        R4      hi ; i)a^  
Import a private key for OpenPGP attestation.

The attestation key is by default pre-generated during production with a
Yubico-issued key and certificate.

WARNING: This private key cannot be recovered once overwritten!


KEY          key slot to import to (only 'att' supported)
PRIVATE-KEY  file containing the private key (use '-' to use stdin)
r'   z:Importing keys is only supported for the Attestation slot.Nr@   TrA   ZpasswordzFailed to parse private key.zPrivate key imported for slot r]   z!Failed to import attestation key.)r*   r   r%   Zfailr   r   readrX   r   rD   Zput_keyr3   r4   r   )r.   r\   Zprivate_keyrE   r'   s   &&&& r   
import_keyrc     s    $ ggi G
gkkMN !2tD	6'(8(8(:TJ;Y')

3CHH:Q?@  64556  ;9::;s   B0 (AC
 0C
C!zPIN code)ZhiddencertificateZwbZCERTIFICATEc                s   V P                   R,          pV'       g   \        RRR7      p VP                  V4      pV'       d+   \        P
                  ! RVP                   R24      '       d   VP                  \        P                  4      pV\        P                  \        P                  39   d   \        P                  ! R4        VP                  V4       VP                  V4      pVP!                  VP#                  VR	7      4       \%        R
VP&                   R\)        V4       2\*        V4       R# R#   \         d    Rp ELi ; i  \,         d    \/        R4      hi ; i)a2  
Generate an attestation certificate for a key.

Attestation is used to show that an asymmetric key was generated on the
YubiKey and therefore doesn't exist outside the device.


KEY          key slot to attest (sig, dec, aut)
CERTIFICATE  file to write attestation certificate to (use '-' to use stdout)
r'   rH   TrA   Nz9There is already data stored in the certificate slot for z, do you want to overwrite it?zTouch the YubiKey sensor...Zencodingz!Attestation certificate for slot z written to zAttestation failed.)r*   r   get_certificate
ValueErrorr3   r7   ZvalueZget_uifr   r%   r
   ZONZFIXEDr4   Z
verify_pinZ
attest_keywritepublic_bytesr   r   r&   r8   rX   r   )r.   r\   rd   rM   r   r'   certZtouch_policys   &&&&&   r   attestrk     s8   $ ggi G;48&&s+ 5==
CCII; O' 	'  w{{3CFFCII..JJ45	1s#%%c*Dd///@A3CHH:\+&')	  (  	1/00	1s   D9 A-E 9E
	E
E$certificatesc                 r<   )z
Manage certificates.
Nr#   r#   r   r   rl   rl   <  r=   r   Zexportc                s6   V P                   R,          p VP                  V4      pTP                  TP                  TR7      4       \        RTP                   R\        T4       2\        T4       R#   \         d    \        RTP                   R24      hi ; i)z
Export an OpenPGP certificate.


KEY          key slot to read from (sig, dec, aut, or att)
CERTIFICATE  file to write certificate to (use '-' to use stdout)
r'   z%Failed to read certificate from slot r]   re   Certificate for slot z exported to N)
r*   rf   rg   r   r   rh   ri   r   r&   r8   )r.   r\   r   rd   r'   rj   rU   r   export_certificatern   C  s     ggi GK&&s+ d'''89
zvk7J6KL  K=chhZqIJJKs   A3 3%BZdeletec                s   V P                   R,          pVf   \        RRR7      p VP                  V4       VP                  V4       \        P
                  ! RVP                   R24       R#   \         d    \        R4      hi ; i)	zd
Delete an OpenPGP certificate.


KEY  key slot to delete certificate from (sig, dec, aut, or att)
r'   Nr@   TrA   rm   z	 deleted.zFailed to delete certificate.)	r*   r   rD   delete_certificater3   r4   r   rX   r   )r.   r\   rE   r'   rY   r   ro   ro   ^  s{     ggi G !2tD	7Y'""3'

*388*I>? 75667s   AA. .Brj   c                s   V P                   R,          pVf   \        RRR7      p \        VP                  4       RR7      p\        T4      ^8w  d   \        R4      h TP                  T4       TP                  Y^ ,          4       \        P                  ! R	TP                   24       R#   \         d    \        R4      hi ; i  \         d    \        R
4      hi ; i)z
Import an OpenPGP certificate.


KEY          key slot to import certificate to (sig, dec, aut, or att)
CERTIFICATE  file containing the certificate (use '-' to use stdin)
r'   Nr@   TrA   ra   zFailed to parse certificate.z Can only import one certificate.zCertificate imported into slot zFailed to import certificate.)r*   r   r   rb   rX   r   ZlenrD   Zput_certificater3   r4   r   )r.   r\   rj   rE   r'   ZcertsrU   r   import_certificaterp   u  s     ggi G !2tD	6"499;> 5zQ8997Y'1X.

4SXXJ?@  64556  75667s   B+ AC +CC)CZloggingZenumr   r3   Zyubikit.corer   Zyubikit.core.smartcardr   r   r   Zyubikit.managementr   Zyubikit.openpgpr   r    r   r	   r
   r   r0   r   r   r   Zutilr   r   r   r   r   r   r   r   r   r   r   r   Z	getLoggerr$   r8   r&   Zpass_contextZcommandr1   r(   r9   Zgroupr;   ZargumentZIntRangeZoptionrF   rL   rR   rS   rV   rZ   r[   r_   r`   ZFilerc   r%   rk   rl   rn   ro   rp   r#   r   r   <module>rq      s  8    " E E )  A @ 8   
		8	$5g 5' -./&   0&R 		.  	. 	   :( 	x1 1 "2)>Vu~~a4>R ennQ3=P dM(?@    A W  > dG"45dKk2  3 6 : #$dM4dN);<  = 5 %< "#dM(;<d%O<  = = $: -R dN6dKk2)  3 7 )X &'(J1GHdM(?@A  A I (A0 	v  fu:g+>?. @  .* ku:g+>?(CAdM(?@/9   A B @ /9d hdM(?@u:g+>?EJJt$4mL; M @  A 
;@ dG*-u:gw{{m+TUEJJt$4mL(1 M V  .  (1V 	~  hu:g+>?EJJt$4mL M  @   
, hdM(?@u:g+>?7 @  A  7& hdM(?@u:g+>?UZZ-}E7 F @  A  
7r   