+
    :iv  c                   s   ^ RI t ^ RIt^ RIHt ^ RIt^ RIHt ^ RIHtH	t	 ^ RI
HtHt ^ RIHtHtHt ^ RIHt ^ RIHtHtHtHtHtHtHtHtHtHt ^R	IHtH t H!t!H"t"H#t#H$t$H%t%H&t&H't'H(t(H)t)H*t*H+t+ ^R
I,H-t-H.t.H/t/H0t0 ^RI,H1t1H2t2H3t3H4t4H5t5H6t6H7t7H8t8H9t9H:t:H;t;H<t< ]Pz                  ! ]>4      t?]3! 4       R 4       t@]3! 4       R 4       tA]3! 4       R 4       tB]3! 4       R 4       tC]P                  ! R]@R7      tE]P                  ! R]ARR7      tF]P                  ! RRR]BR7      tH]P                  ! RRRR7      tI]P                  ! R]2! ]4      ]P                  P                  RR7      tL]P                  ! R ]2! ]4      ]P                  P                  R!R7      tM]P                  ! R"R#]P                  ! . ROR%R&7      R$R'R(]CR)7      tO]P                  ! R*R'R'R'R+R,7      tPR- tQ]6! ].R.7      ]P                  ]7R/ 4       4       4       t]P                  4       ]P                  R0 4       4       tT]P                  4       ]P                  ]4R1 4       4       4       tU]P                  4       R2 4       tW]WP                  R34      ]P                  ]P                  ! R4]P                  ! ^^4      R5R67      ]P                  ! R7]P                  ! ^ ^4      R8R67      ]H]I]4R9 4       4       4       4       4       4       4       tYR: tZR; t[]WP                  R<4      ]P                  ]P                  ! RRR=R7      ]P                  ! R>R?R@R7      RA 4       4       4       4       t\]WP                  RB4      ]P                  ]P                  ! RCRDRER7      ]P                  ! R>RFRGR7      RH 4       4       4       4       t]]WP                  RI4      ]P                  ]I]P                  ! RJRKR'RLRM7      ]P                  ! R>RNRO]BR7      ]P                  ! RRRP]BR7      ]P                  ! R"RQRR]2! ]4      RS7      ]P                  ! RCRTR'RURM7      ]P                  ! RVRWR'RXRM7      ]4RY 4       4       4       4       4       4       4       4       4       4       t^]WP                  RZ4      ]P                  ]P                  ! RCRDR%R[7      ]P                  ! R>R?R%R\R]7      R^ 4       4       4       4       t_]P                  4       R_ 4       t`]`P                  R`4      ]P                  ]H]I]P                  ! R"RQRa]2! ]4      ]P                  P                  R'Rb7      ]5]L]M]E]P                  ! Rc]P                  ! Rd4      ReR67      Rf 4       4       4       4       4       4       4       4       4       4       tc]`P                  Rg4      ]P                  ]I]H]L]M]E]P                  ! Rh]P                  ! Ri4      RjR67      ]P                  ! RCRkRlR7      Rm 4       4       4       4       4       4       4       4       4       td]`P                  4       ]P                  ]5]E]P                  ! Rn]P                  ! Rd4      RoR67      Rp 4       4       4       4       4       te]`P                  Rq4      ]P                  ]ERr 4       4       4       tf]`P                  4       ]P                  ]5]E]P                  ! RsRtR'RuRM7      ]P                  ! RRRvR7      ]P                  ! Rc]P                  ! Rd4      ReR67      Rw 4       4       4       4       4       4       4       tg]`P                  Rx4      ]P                  ]H]I]P                  ! Ry]@R7      ]P                  ! Rz]@R7      R{ 4       4       4       4       4       4       th]`P                  R|4      ]P                  ]H]I]ER} 4       4       4       4       4       ti]P                  R~4      R 4       tjR tk]jP                  Rg4      ]P                  ]H]I]P                  ! RCRkRR7      ]P                  ! RsRtR'RRM7      ]P                  ! RRR'RRM7      ]P]E]P                  ! R]P                  ! Ri4      RoR67      R 4       4       4       4       4       4       4       4       4       4       tl]jP                  R4      ]P                  ]5]E]P                  ! Rn]P                  ! Rd4      RoR67      R 4       4       4       4       4       tm]jP                  R`4      ]P                  ]H]I]E]P                  ! R]P                  ! Ri4      ReR%R7      ]P                  ! RRRR'R7      ]P                  ! RRR]P                  RR'Rb7      ]O]PR 4       4       4       4       4       4       4       4       4       4       to]jP                  R4      ]P                  ]I]E]P                  ! R]P                  ! Ri4      ReR67      ]P                  ! R]P                  ! Rd4      RR67      ]P                  ! RRRR'R7      ]OR 4       4       4       4       4       4       4       4       tp]jP                  R|4      ]P                  ]H]I]E]PR 4       4       4       4       4       4       tq]P                  R4      R 4       tr]rP                  R4      ]I]P                  ]F]P                  ! R]P                  ! Rd4      RR67      R 4       4       4       4       4       ts]rP                  Rg4      ]I]H]P                  ]F]P                  ! R]P                  ! Ri4      RR67      R 4       4       4       4       4       4       tt]rP                  R`4      ]I]H]P                  ]FR 4       4       4       4       4       tuRR ltvRR ltwRR ltxRR ltyRR ltzRR lt{R t|R# )    N)uuid4)default_backend)hashesserialization)	TRANSPORTNotSupportedError)SW	ApduErrorSmartCardConnection)
CAPABILITY)
DEFAULT_MANAGEMENT_KEYKEY_TYPEMANAGEMENT_KEY_TYPE	OBJECT_ID
PIN_POLICYSLOTTOUCH_POLICYChuidInvalidPinError
PivSession)	check_keyderive_management_keygenerate_cccgenerate_chuidgenerate_csrgenerate_random_management_key generate_self_signed_certificateget_piv_infoget_pivman_dataget_pivman_protected_datapivman_change_pinpivman_set_mgm_keypivman_set_pin_attempts)InvalidPasswordErrorget_leaf_certificatesparse_certificatesparse_private_key)CliFail
EnumChoiceclick_callbackclick_force_optionclick_format_optionclick_groupclick_postpone_executionclick_promptget_scp_paramslog_or_echopretty_printprompt_timeoutc                 s     \         VP                  4       P                  R R4      ,          #   \         d4     \        \	        T^4      4      u #   \
         d    \        T4      hi ; ii ; i)-_)r   upperreplaceKeyErrorint	Exception
ValueErrorctxparamval   &&&3/usr/lib/python3.14/site-packages/ykman/_cli/piv.pyclick_parse_piv_slotr@   [   sc    "CIIK''S122 "	"C%% 	"S/!	""s    *- A+AA+A''A+c                 s   VP                  4       R 8X  d   \        P                  #  \        VP                  4       P                  RR4      ,          #   \         d+     \        T^4      u #   \         d    \        T4      hi ; ii ; i)ZCCCr2   r3   )r4   r   r
   r5   r6   r7   r8   r9   r:   r>   r?   click_parse_piv_objectrA   f   sx    
yy{e###",,S#677 "	"sB< 	"S/!	""s#   *A BA,)B,BBc                 s     \         P                  V4      pV'       d   \        V4      R9  d   \        R4      hV#   \         d    \        T4      hi ; i)   z[Management key must be exactly 16, 24, or 32 bytes (32, 48, or 64 hexadecimal digits) long.)rB   i   i    )bytesfromhexlenr9   r8   )r;   r<   r=   key   &&& r?   click_parse_management_keyrH   s   sU    	mmC 3s8</;  
 os   < < Ac                 sX     \        \        V4      #   \         d    \        T4      hi ; iN)getattrr   ZAttributeErrorr9   r:   r>   r?   click_parse_hashrK      s-    vs## os    )slot)callback	object_idZOBJECT)rM   metavarz-mz--management-keyzthe management key)helprM   z-Pz--pinzPIN code)rP   z--pin-policyzPIN policy for slot)typedefaultrP   z--touch-policyztouch policy for slotz-az--hash-algorithmSHA256F)Zcase_sensitiveTzhash algorithm)rQ   rR   show_defaultrP   rM   z --update-chuid/--no-update-chuidz+update the CHUID GUID to a new random value)is_flagrR   rT   rP   c                 s    \        V R V 4      # )name)rJ   )Zfobj   &r?   _fnamerX      s    4&&    )Zconnectionsc                s   V P                   R,          pVP                  \        4      pV P                  VP                  4       \        V \        P                  V4      p \        W#4      pT P                   R,          pY@P                   R&   \#        T4      T P                   R&   \        P                  TP$                  9   ;'       d    \        P                  TP&                  9  T P                   R&   R#   \         dX   pTP                  \        P                  8X  d3   T'       g+   TP                  \        P                  8X  d   \!        R4      hh Rp?ii ; i)a  
Manage the PIV application.

Examples:


  Generate an ECC P-256 private key and a self-signed certificate in
  slot 9a:
  $ ykman piv keys generate --algorithm ECCP256 9a pubkey.pem
  $ ykman piv certificates generate --subject "CN=yubico" 9a pubkey.pem


  Change the PIN from 123456 to 654321:
  $ ykman piv access change-pin --pin 123456 --new-pin 654321


  Reset all PIV data and restore default settings:
  $ ykman piv reset
Zdevicez)Unable to manage PIV over NFC without SCPNinfosessionpivman_datafips_unready)objZopen_connectionr	   Zcall_on_closeZcloser.   r
   PIVr   r   swr   CONDITIONS_NOT_SATISFIEDZ	transportr   ZNFCr&   r   fips_capablefips_approved)r;   ZdevZconnZ
scp_paramsr[   erZ   s   &      r?   pivre      s   0 ''(
C23Ddjj!Z^^T:J	T. 776?D GGI,W5CGGM$+++XX
dFXFX0X GGN  DDB///.EFFs    C5 5E &E'+EEc                sL   V P                   R,          p\        V P                   R,          4      p\        P                  VP                  9   d(   \        P                  VP
                  9   V^ ,          R&   \        P                  ! RP                  \        V4      4      4       R# )z0
Display general status of the PIV application.
rZ   r[   zFIPS approved
N)
r^   r   r
   r_   rb   rc   clickechojoinr0   )r;   rZ   datas   &  r?   rZ   rZ      sm     776?D	*+D~~***#->>T5G5G#GQ 	JJtyyd+,-rY   c                s   V P                   R,          p\        P                  VP                  9   d   \	        R4      hV'       g   \
        P                  ! RRRR7       \
        P                  ! R4       V P                   R,          pVP                  4         VP                  4       P                  ^ 8  p\
        P                  ! R4       V'       dD   \
        P                  ! R	4       \
        P                  ! R
4       \
        P                  ! R4       M,\
        P                  ! R4       \
        P                  ! R
4       \
        P                  ! R4       R#   \         d    Rp Li ; i)zz
Reset all PIV data.

This action will wipe all data and restore factory settings for
the PIV application on the YubiKey.
rZ   zbCannot perform PIV reset when FIDO is configured, use 'ykman config reset' for full factory reset.zTWARNING! This will delete all stored PIV data and restore factory settings. Proceed?TZabortZerrzResetting PIV data...r[   z?Reset complete. All PIV data has been cleared from the YubiKey.z=Your YubiKey now has the default PIN, PUK and Management Key:	PIN:	123456	PUK:	12345678z8Your YubiKey now has the default PIN and Management Key:zA	Management Key:	010203040506070801020304050607080102030405060708N)r^   r
   r_   Zreset_blockedr&   rg   confirmrh   resetget_puk_metadataattempts_remainingr   )r;   forcerZ   r[   Zhas_puks   &&   r?   ro   ro      s    776?D~~+++?
 	

 !		
 
JJ&'ggi GMMO**,??!C 
JJPQ

RS

#$

%&

MN

#$	JJTU  s   E E+*E+c                     R# )z$Manage PIN, PUK, and Management Key.N rt   rY   r?   accessru   !      rY   zset-retrieszpin-retrieszPIN-RETRIES)rQ   rO   zpuk-retrieszPUK-RETRIESc                s   V P                   R,          pV P                   R,          p\        P                  VP                  9   dL   VP	                  4       P
                  '       d!   VP                  4       P
                  '       g   \        R4      h VP                  4        \        R4      h  \         d     Mi ; i\        YTRTR7       \        P                  ! R4       T'       g!   \        P                  ! RT R	T R
2RRR7        \        YcT4       \        P                  ! R4       \        P                  ! R4       \        P                  ! R4       \        P                  ! R4       R#   \         d    \        R4      hi ; i)zq
Set the number of PIN and PUK retry attempts.

NOTE: This will reset the PIN and PUK to their factory defaults.
r[   rZ   z<Retry attempts must be set before PIN/PUK have been changed.z2PIN/PUK retries cannot be changed on this YubiKey.T)require_pin_and_key	no_promptzAWARNING: This will reset the PIN and PUK to the factory defaults!z1Set the number of PIN and PUK retry attempts to: Z Z?rk   zNumber of PIN/PUK retries set.z Default PINs have been restored:rl   rm   zSetting PIN retries failed.N)r^   r
   r_   rb   Zget_pin_metadataZdefault_valuerp   r&   Zget_bio_metadatar   _ensure_authenticatedrg   rh   rn   r!   r8   )r;   management_keypinZpin_retriesZpuk_retriesrr   r[   rZ      &&&&&&  r?   set_pin_retriesr}   &  sD    ggi G776?D~~***$$&444((*888N   "JKK  .de 
JJRS?}Am1		
5kB

34

56

#$

%& 53445s   B- -B;:B;A$E2 2F	c                 s    V'       d   R MRpV'       d   \        V 4      M\        V P                  4       4      pY5u;8:  d   ^8:  g/   M V^8X  d   \        V RV R24      h\        V RV RV R24      hR# )Z
charactersrC   z must be exactly 8 z long.z must be between z and 8 N)rE   encoder&   )r{   rV   pin_complexitymin_lenZunitZpin_len   &&&&  r?   _validate_pin_lengthr   Y  sr    )<wD(c#hc#**,.?G""a<TF"5dV6BCCTF"3G9GD6PQQ	 #rY   c                 s   V P                   p\        P                  V P                  9   d   ^M^p\	        VRV 2V^4       \	        VRV 2WV4        V! 4        \
        P                  ! RV R24       R#   \         dM   pTP                  pT'       d&   T^8w  d   \        T4      MRp	\        T RT	 R24      h\        T R24      hRp?i\         d4   pTP                  \        P                  8X  d   \        T R	24      hh Rp?ii ; i)
i   zCurrent zNew z set.
15 or morez change failed -  tries left.z is blocked.Nz& does not meet complexity requirement.)r   r
   r_   rb   r   rg   rh   r   rq   strr&   r   r`   r   ra   )
rZ   rV   ZcurrentZnewZfnr   r   rd   attempts
f_attemptss
   &&&&&     r?   _do_change_pin_pukr   c  s    ((N>>T%6%66aAGHTF"3^QGTFm^E


T$u%& 1''*2b.XlJTF"3J<|LMMTF,/00 442...TF"HIJJs+   !A5 5D ACDD.DDz
change-pinzcurrent PIN codez-nz	--new-pinza new PIN to setc           	     s  aaa V P                   R,          pV P                   R,          oSP                  4       '       g   \        R4      hS'       g   \        R4      oS'       g   \	        RRRRRR	7      o\        VR
SSVVV3R l4       R# )z
Change the PIN code.

The PIN must be between 6 and 8 bytes long, and supports any type of
alphanumeric characters. For cross-platform compatibility, numeric PINs are
recommended.
rZ   r[   PIN is blocked.zEnter the current PINzEnter the new PIN TFrR   
hide_inputrT   confirmation_promptZPINc                  s   < \        SSS 4      # rI   )r   )new_pinr{   r[      r?   <lambda>Zchange_pin.<locals>.<lambda>  s    !'38rY   N)r^   Zget_pin_attemptsr&   _prompt_pinr-   r   )r;   r{   r   rZ   r[      &ff @r?   
change_pinr   y  s~     776?Dggi G##%%'((12 $
 8rY   z
change-pukz-pz--pukzcurrent PUK codez	--new-pukza new PUK code to setc           	     sT  aaa V P                   R,          pV P                   R,          o SP                  4       P                  '       g   \        R4      h S'       g   \        R4      oS'       g   \        RRRRRR	7      o\        VR
SSVVV3R l4       R#   \         d     LOi ; i)z
Change the PUK code.

If the PIN is lost or blocked it can be reset using a PUK.
The PUK must be between 6 and 8 bytes long, and supports any type of
alphanumeric characters.
rZ   r[   PUK is blocked.zEnter the current PUKzEnter the new PUKr   TFr   ZPUKc                  s(   < SP                  SS 4      # rI   )
change_puk)new_pukpukr[   r   r?   r   Zchange_puk.<locals>.<lambda>  s    ""30rY   N)r^   rp   rq   r&   r   r   r-   r   )r;   r   r   rZ   r[   r   r?   r   r     s     776?Dggi G'')<<<+,, =
 12 $
 0  s   B B B'&B'zchange-management-keyz-tz--touchz9require touch on YubiKey when prompted for management key)rU   rP   z--new-management-keyza new management key to setzcurrent management keyz--algorithmzmanagement key algorithm)rP   rQ   z	--protectzkstore new management key on the YubiKey, protected by PIN (a random key will be used if no key is provided)z-gz
--generatezgenerate a random management key (implied by --protect unless --new-management-key is also given, can't be used with --new-management-key)c	           	     sf   V P                   R,          p	V P                   R,          '       d   V'       d   \        R4      hV'       g    V	P                  4       P                  pV P                   R,          p
\        P                  V
P                  9   d/   V\
        P                  39   d   \        VP                   R24      h\        V VVVRVR7      pV'       d   V'       d   \        R4      hV'       d   V	P                  R8  d   \        R	4      hV P                   R
,          pV'       gK   VP                  '       d9   V'       d   \        W	WVR7       M!V'       g   \        P                   ! RRRR7       V'       g   V'       g	   V'       d<   \#        V4      pV'       g(   \        P$                  ! RVP'                  4        24       M5V'       d   \        R4      h \(        P+                  \-        RRRR7      4      p\1        V4      VP2                  8w  d   \        RVP2                  ,          4      h \5        WW%VR7       \        P$                  ! R4       R#   \         d    \
        P                  p ELi ; i  \.         d    \        R4      hi ; i  \6         d    \        R4      hi ; i)z
Change the management key.

Management functionality is guarded by a management key.
This key is required for administrative tasks, such as generating key pairs.
A random key may be generated and stored on the YubiKey, protected by PIN.
r[   r]   zDYubiKey FIPS must be in FIPS approved mode prior to using --protect.rZ    not supported on YubiKey FIPS.z;Enter the current management key [blank to use default key])rw   mgm_key_promptrx   z@Invalid options: --new-management-key conflicts with --generate.z,Require touch not supported on this YubiKey.r\   rx   zlThe current management key is stored on the YubiKey and will not be cleared if no PIN is provided. Continue?Trk   zGenerated management key: zuNew management key not given. Remove the --force flag, or set the --generate flag or the --new-management-key option.zEnter the new management key)r   r   z(New management key has the wrong format.z8Management key has the wrong length (expected %d bytes).)touchZstore_on_devicezNew management key set.z#Changing the management key failed.N)   r    r    )r^   r&   Zget_management_key_metadatakey_typer   r   ZTDESr
   r_   rb   rV   ry   versionhas_stored_key_verify_pinrg   rn   r   rh   ZhexrC   rD   r-   r8   rE   Zkey_lenr    r   )r;   rz   	algorithmr{   Znew_management_keyr   Zprotectgeneraterr   r[   rZ   Zpin_verifiedpivmans   &&&&&&&&&    r?   change_management_keyr     sV   z ggi G
ww~7R
 	
 	1;;=FFI 776?D~~***y=P=U=U<W/W((GHII(#TL hN
 	

 9,DEE WW]#FF111fUCMML	 h!?	!J

78J8N8N8P7QRS/ 	J%*]] 6#',0&" )"3"33F 
 	

=QX	
 	

,-Q ! 	1+00I	1v  JHIIJ  =;<<=s*   	I !I? 7$J I<;I<?JJ0zunblock-pin)requiredzNEW-PIN)r   rO   c                s   V P                   R,          pV'       g   \        RRRRR7      pV'       g   \        RRRRRR7      pV P                   R	,          p\        TR
VP                  \        P
                  VP                  9   d   ^M^4        VP                  W4       \        P                  ! R4       R#   \         dH   pTP                  pT'       d$   T^8w  d   \        T4      MRp\        RT R24      h\        R4      hRp?i\         d1   pTP                  \         P"                  8X  d   \        R4      hh Rp?ii ; i)z
Unblock the PIN (using PUK).
r[   z	Enter PUKr   FT)rR   rT   r   zEnter a new PIN)rR   rT   r   r   rZ   zNew PINzNew PIN set.r   zPIN unblock failed - r   r   Nz)PIN does not meet complexity requirement.)r^   r-   r   r   r
   r_   rb   unblock_pinrg   rh   r   rq   r   r&   r   r`   r   ra   )r;   r   r   r[   rZ   rd   r   r   s   &&&     r?   r   r   \  s    ggi G;SWX $
 776?D^^t000a	C)

>" -''*2b.XlJ1*\JKK+,, 442...EFFs+   'B9 9EADEE+D??Ec                 rs   )z
Manage private keys.
Nrt   rt   rY   r?   keysr     rv   rY   r   z"algorithm to use in key generation)rP   rQ   rR   rT   zpublic-key-outputZwbz
PUBLIC-KEYc	                s   V P                   R,          '       d   \        R4      h\        WV4       V P                   R,          p	\        WV4       V	P	                  WWx4      p
TpVP                  V
P                  V\        P                  P                  R7      4       \        RV R\        V4       2\        V4       R# )z
Generate an asymmetric key pair.

The private key is generated on the YubiKey, and written to one of the slots.


SLOT        PIV slot of the private key
PUBLIC-KEY  file containing the generated public key (use '-' to use stdout)
r]   zCYubiKey FIPS must be in FIPS approved mode prior to key generation.r[   encodingformatzPrivate key generated in slot z, public key written to N)r^   r&   _check_key_support_fipsry   generate_keywritepublic_bytesr   PublicFormatSubjectPublicKeyInfor/   rX   logger)r;   rL   public_key_outputrz   r{   r   r   
pin_policytouch_policyr[   
public_keykey_encodings   &&&&&&&&&   r?   r   r     s    L ww~Q
 	
 CJ7ggi G#N3%%dzPJL! --BB 	  	
 
(.F#$
%	'	rY   Zimportzprivate-keyZrbzPRIVATE-KEYz
--passwordz(password used to decrypt the private keyc                sh   V P                   R,          '       d   \        R4      hV P                   R,          pVP                  4       p	 Ve   VP                  4       p \	        W4      p \        T \        P                  ! TP                  4       4      T4       \        YT4       TP!                  Y4YV4       \        P                  ! RTP"                   R24       R#   \
         dJ    \        P                  RRR7       Tf   \        RR	RR
R7      p K  Rp\        P                  ! R4        K  i ; i)z
Import a private key from file.

Write a private key to one of the PIV slots on the YubiKey.


SLOT         PIV slot of the private key
PRIVATE-KEY  file containing the private key (use '-' to use stdin)
r]   z?YubiKey FIPS must be in FIPS approved mode prior to key import.r[   TNzError parsing keyZexc_infozEnter password to decrypt keyr   FrR   r   rT   Wrong password.zPrivate key imported into slot .)r^   r&   readr~   r%   r"   r   debugr-   rg   rh   r   r   Zfrom_public_keyr   ry   Zput_keyrV   )
r;   rz   r{   rL   Zprivate_keyr   r   passwordr[   rj   s
   &&&&&&&&  r?   
import_keyr     s   , ww~WXXggi GD
(H	+D;K 	X%%k&<&<&>? #N3OODz@	JJ01=>- $ 	LL,tL<'3#!&	 

,-	s   C 5D1D10D1certificateZCERTIFICATEc                s   V P                   R,          p VP                  V4      pTP	                  TP                  TR7      4       \        RT R\        T4       2\        T4       R#   \         d    \        R4      hi ; i)a0  
Generate an attestation certificate for a key pair.

Attestation is used to show that an asymmetric key was generated on the
YubiKey and therefore doesn't exist outside the device.


SLOT         PIV slot of the private key
CERTIFICATE  file to write attestation certificate to (use '-' to use stdout)
r[   zAttestation failed.r   z!Attestation certificate for slot  written to N)	r^   
attest_keyr   r&   r   r   r/   rX   r   )r;   rL   r   r   r[   certr   r?   attestr   
  s      ggi G-!!$' d'''89
+D6f[>Q=RS  -+,,-s   A) )B rZ   c           
     s   V P                   R,          p VP                  V4      pRTRVP                  P                  RVP                  '       d   RMRRVP
                  P                  RVP                  P                  /p\        P                  ! R	P                  \        V4      4      4       R#   \         d5   pTP                  \        P                  8X  d   \        R
T R24      hh Rp?ii ; i)a	  
Show metadata about a private key.

This will show what type of key is stored in a specific slot,
whether it was imported into the YubiKey, or generated on-chip,
and what the PIN and Touch policies are for using the key.


SLOT        PIV slot of the private key
r[   zKey slotZ	AlgorithmZOriginZ	GENERATEDZIMPORTEDzPIN required for usezTouch required for userf   No key stored in slot r   N)r^   get_slot_metadatar   rV   Z	generatedr   r   rg   rh   ri   r0   r   r`   r   REFERENCE_DATA_NOT_FOUNDr&   )r;   rL   r[   metadatarZ   rd   s   &&    r?   r   r   '  s     ggi G,,T2**//X%7%7%7kZ"H$7$7$<$<$h&;&;&@&@
 	

499\$/01 442...24&:;;s   ;B2 AB2 2C1=/C,,C1z-vz--verifyz>verify that the public key matches the private key in the slotzPIN code (used for --verify)c                s  aa	a
 V P                   R,          o
 S
P                  S4      P                  o	\        P	                  R4       TpTP                  S	P                  T\         P"                  P$                  R
7      4       \'        RS R\)        T4       2\        T4       R#   \
         dC   pTP                  \        P                  8X  d   \        RS R24      h\        RS R24      hRp?i\         d     S
P                  S4      P                  4       o	\        P	                  R4        L  \        \
        3 dv     S
P                  S4      P                  4       o	\        P	                  R4       T'       d   T	T
T3R	 lp\        T S
Yu4         ELR  \
         d    \        RS R24      hi ; ii ; ii ; i)a  
Export a public key corresponding to a stored private key.

This command uses several different mechanisms for exporting the public key
corresponding to a stored private key, which may fail.
If a certificate is stored in the slot it is assumed to contain the correct public
key. If this is not the case, the wrong public key will be returned.

The --verify flag can be used to verify that the public key being returned matches
the private key, by using the slot to create and verify a signature. This may
require the PIN to be provided.


SLOT        PIV slot of the private key
PUBLIC-KEY  file to write the public key to (use '-' to use stdout)
r[   zPublic key read from YubiKeyr   r   z&Unable to export public key from slot Nz!Public key read using attestationz'Public key read from stored certificatec                  s   < \        R R7      ;_uu_ 4        \        SSS 4      '       g   \        RS R24      h RRR4       R#   + '       g   i     R# ; i)      ?timeoutz7This public key is not tied to the private key in slot r   Nr1   r   r&   )r   r[   rL   r   r?   	do_verifyZexport.<locals>.do_verifyv  sP    +C88#,WdJ#G#G&-%,,06%4'" !" $H 9888   #AA	r   zPublic key for slot r   )r^   r   r   r   r   r   r`   r   r   r&   r   r   get_certificate_verify_pin_if_neededr   r   r   r   r   r/   rX   )r;   rL   r   r   verifyr{   rd   r   r   r   r[   s   &f&&&&   @@r?   exportr   G  s   : ggi GP..t4??
346 L! --BB 	  	
 
tfL8I1J0KLC  H442...24&:;;>tfAFGG P	P ++D1<<>JLL<=!9- 	PP$44T:EEG
FG" *#w	G P FtfANOOP	P	PsM   0B& &F=1=C..F=;F==4D33F9;FFF=F55F99F=Zmovesourcedestc                s   W48X  d   \        R4      hV P                  R,          p\        WV4        VP                  W44       \        P
                  ! RVP                   RVP                   R24       R#   \         d[   pTP                  \        P                  8X  d   \        R4      hTP                  \        P                  8X  d   \        R4      hh Rp?ii ; i)	z
Moves a key.

Moves a key from one PIV slot into another.


SOURCE            PIV slot of the key to move
DEST              PIV slot to move the key into
z#SOURCE must be different from DEST.r[   zKey moved from slot z	 to slot r   zDEST slot is not empty.zNo key in SOURCE slot.N)r&   r^   ry   move_keyrg   rh   rV   r   r`   r   INCORRECT_PARAMETERSr   )r;   rz   r{   r   r   r[   rd      &&&&&  r?   r   r     s      ~;<<ggi G#N3&

)&++i		{!LM 442***344442...233s   AA6 6CACCZdeletec                s4   V P                   R,          p\        WV4        VP                  V4       \        P                  ! RVP
                   R24       R#   \         d5   pTP                  \        P                  8X  d   \        RT R24      hh Rp?ii ; i)zd
Delete a key.

Delete a key from a PIV slot on the YubiKey.


SLOT            PIV slot of the key
r[   zKey in slot 	 deleted.r   r   N)r^   ry   
delete_keyrg   rh   rV   r   r`   r   r   r&   )r;   rz   r{   rL   r[   rd   r   r?   r   r     s     ggi G#N34 

\$))I67 442...24&:;;s   5A B#/BBZcertificatesc                 rs   )z
Manage certificates.

By default, modifying the certificate in a slot will also update the
CHUID with a new random GUID. To prevent this, use the --no-update-chuid
option.
Nrt   rt   rY   r?   r   r     rv   rY   c                 st    V P                  \        P                  4      p \        P                  ! V4      pTP                  '       d   \        P                  R4       R# \        4       P                  Tn        \        T4      p\        P                  R4       T P#                  \        P                  T4       R#   \
         d    \        P                  R 4        R# i ; i  \         dJ   pTP                  \        P                  8X  d%   \        P                  R4       \!        4       p Rp?Lh Rp?ii ; i)zLeaving unparsable CHUID as-isNzLeaving signed CHUID as-iszUpdating CHUID GUIDzGenerating new CHUID)
get_objectr   CHUIDr   Z
from_bytesr9   r   r   Zasymmetric_signaturer   rC   Zguidr   r`   r   FILE_NOT_FOUNDr   
put_object)r[   Z
chuid_dataZchuidrd   s   &   r?   _update_chuidr     s    ''	8
	$$Z0E %%%LL56W]]
5\
*+ y
3!  	LL9:	  442$$$LL/0')JsK   C# B< C# 
C# !9C# < C C# C  C# #D7.>D21D22D7z,a password may be needed to decrypt the dataz?verify that the certificate matches the private key in the slotz-cz
--compressz)compresses the certificate before storingr   c	                sz  aaaa V P                   R,          oVP                  4       p	 Ve   VP                  4       p \        W4      p
 \        T
4      ^8  d   \        T
4      pT^ ,          pM	T
^ ,          p\        YT4       T'       d   TP                  4       o SP                  S4      pTP                  \         P"                  \         P$                  39   d!   T P                   R,          p\'        T SY4       TP(                  \*        P"                  \*        P,                  39   d   RoMRo TTTT3R lp\;        T STT4       SP=                  SY4       T'       d   \?        S4       \        P                  ! RSP@                   24       R#   \         dL    \
        P                  RRR7       Tf   \        RRRRR	7      p EK  Rp\        P                  ! R
4        EK  i ; i  \.         d5   pTP0                  \2        P4                  8X  d   \7        RS R24      hh Rp?i\8         d    Ro ELi ; i)z
Import an X.509 certificate.

Write a certificate to one of the PIV slots on the YubiKey.


SLOT            PIV slot of the certificate
CERTIFICATE     file containing the certificate (use '-' to use stdin)
r[   TNzError parsing certificater   z%Enter password to decrypt certificater   Fr   r   r\                 >@No private key in slot r   r   c                  s   < \        SR 7      ;_uu_ 4        \        SSS 4      '       g   \        RS R24      h RRR4       R#   + '       g   i     R# ; i)r   zIThe public key of the certificate does not match the private key in slot r   Nr   )r   r[   rL   r   s   r?   r   Z%import_certificate.<locals>.do_verify?  sO    00 $
;;!//3fA7  < 1000r   zCertificate imported into slot )!r^   r   r~   r$   r"   r   r   r-   rg   rh   rE   r#   ry   r   r   r   r   ALWAYSZONCEr   r   r   CACHEDr   r`   r   r   r&   r   r   put_certificater   rV   )r;   rz   r{   rL   r   r   r   Zcompressupdate_chuidrj   ZcertsZleafsZcert_to_importr   r   rd   r   r   r[   r   s   &&&f&&&&&        @@@r?   import_certificater     s   : ggi G99;D
(H	&t6E 	
5zA~ &e,qq#N3#..0
	006H""z'8'8*//&JJ/C&6$$)<)<l>Q>Q(RR	 	 	c7Is;D.;g	JJ0<=w $ 	LL4tLD';#!&	 

,-	N  	ttr222 7vQ?@@  	G	sB   F BG, /G, 5G)G)(G),H:7/H&&H:3H:9H:r   c                sb   V P                   R,          p VP                  V4      pVP                  VP                  VR7      4       \	        RV R\        V4       2\        V4       R#   \         d;   pTP                  \        P                  8X  d   \        R4      h\        R4      hRp?ii ; i)z
Export an X.509 certificate.

Reads a certificate from one of the PIV slots on the YubiKey.


SLOT            PIV slot of the certificate
CERTIFICATE     file to write certificate to (use '-' to use stdout)
r[   r   zCertificate from slot z exported to zNo certificate found.zFailed reading certificate.N)r^   r   r   r   r/   rX   r   r   r`   r   r   r&   )r;   r   rL   r   r[   r   rd   s   &&&&   r?   export_certificater   O  s     ggi G9&&t,$++V+<=$TF-{8K7LM	

  9442$$$122788	9s   AA) )B.45B))B.z
public-key)rQ   rO   r   z-sz	--subjectz2subject for the certificate, as an RFC 4514 string)rP   r   z-dz--valid-daysz,number of days until the certificate expiresim  c	                sd   V P                   R,          p	 V	P                  V4      p
V
P                  \        P                  \        P
                  39   d   RpMRp V'       d1   VP                  4       p\        P                  ! V\        4       4      pM7V	P                   R8  d   \        R4      hV	P                  V4      P"                  p\$        P$                  P'                  \$        P(                  P*                  4      pV\$        P,                  ! VR	7      ,           pR
V9  d
   RV,           p\/        WVRR7        \1        VR7      ;_uu_ 4        \3        WWEWV4      pRRR4       V	P5                  VX4       V'       d   \7        V	4       \8        P:                  ! RVP<                   R24       R#   \         d5   pTP                  \        P                  8X  d   \        RT R24      hh Rp?i\         d    Rp ELi ; i  + '       g   i     L; i  \         d    \        R4      hi ; i)a;  
Generate a self-signed X.509 certificate.

A self-signed certificate is generated and written to one of the slots on
the YubiKey. A private key must already be present in the corresponding key slot.


SLOT            PIV slot of the certificate
PUBLIC-KEY      file containing a public key (use '-' to use stdin)
r[   r   r   r   r   Nr   z-PUBLIC-KEY required for YubiKey prior to 5.4.)Zdays=CN=T)rw   r   zCertificate generated in slot zCertificate generation failed.)i   r   r    )r^   r   r   r   r   r   r   r`   r   r   r&   r   r   r   load_pem_public_keyr   r   r   datetimenowZtimezoneZutcZ	timedeltary   r1   r   r   r   rg   rh   rV   )r;   rz   r{   rL   r   subjectZ
valid_dayshash_algorithmr   r[   r   r   rd   rj   r   Zvalid_tor   s   &&&&&&&&&        r?   generate_certificater   n  s   Z ggi G,,T2  \%8%8,:M:M$NNGG  "66t_=NO
	9	$EFF..t4??





 1 1 5 5
6CX''Z88H
''/ #NM
8G,,3zC>D - 	d+'"

3DII;a@AC  442...3D6;<< , -,  86778sT   AF4 F4 >H H!!H /H 4H?/G..H;HHH	H H/Zrequestz
csr-outputZCSRz<subject for the requested certificate, as an RFC 4514 stringc           	     sx   V P                   R,          pV P                   R,          pVP                  4       p	\        P                  ! V	\	        4       4      pRV9  d
   RV,           p VP                  V4      p
V
P                  \        P                  \        P                  39   d   RpMRp \!        WW4        \#        VR7      ;_uu_ 4        \%        WrW5V4      pR	R	R	4       TP'                  XP)                  \        P*                  P,                  R7      4       \/        RT R\1        T4       2\2        T4       R	#   \         d5   pTP                  \        P                  8X  d   \        RT R24      hh R	p?i\         d    R
p Li ; i  + '       g   i     L; i  \         d    \        R4      hi ; i)a  
Generate a Certificate Signing Request (CSR).

A private key must already be present in the corresponding key slot.


SLOT        PIV slot of the certificate
PUBLIC-KEY  file containing a public key (use '-' to use stdin)
CSR         file to write CSR to (use '-' to use stdout)
r[   r\   r   r   r   r   r   r   Nr   r   z.Certificate Signing Request generation failed.r   zCSR for slot r   )r^   r   r   r   r   r   r   r   r   r   r   r`   r   r   r&   r   r   r1   r   r   r   ZEncodingZPEMr/   rX   r   )r;   r{   rL   r   Z
csr_outputr   r   r[   r   rj   r   r   rd   Zcsrs   &&&&&&&       r?   $generate_certificate_signing_requestr     sz   4 ggi GWW]#F??D2249JKJ
''/,,T2  \%8%8,:M:M$NNGG f*HG,,wj>RC -
 S%%}/E/E/I/I%JK
v\&*<)=>
#  442...3D6;<<  -, HFGGHsU   'AD? *D? :F" FF" ?F
/E99FFFF	F" F" "F9c                s    V P                   R,          p\        WV4       VP                  V4       V'       d   \        V4       \        P
                  ! RVP                   R24       R# )z|
Delete a certificate.

Delete a certificate from a PIV slot on the YubiKey.


SLOT            PIV slot of the certificate
r[   zCertificate in slot r   N)r^   ry   delete_certificater   rg   rh   rV   )r;   rz   r{   rL   r   r[   s   &&&&& r?   r   r   	  sO     ggi G#N3t$g	JJ%dii[	:;rY   objectsc                 rs   )aY  
Manage PIV data objects.

Examples:


  Write the contents of a file to data object with ID: abc123:
  $ ykman piv objects import abc123 myfile.txt


  Read the contents of the data object with ID: abc123 into a file:
  $ ykman piv objects export abc123 myfile.txt


  Generate a random value for CHUID:
  $ ykman piv objects generate chuid
Nrt   rt   rY   r?   r   r      rv   rY   outputZOUTPUTc                sX  a aaaaaa S P                   R,          oS P                   R,          oS P                   R,          '       dO   S\        P                  \        P                  \        P                  \        P
                  39   d   \        R4      hRV VVVVVV3R lloS! 4        R# )z
Export an arbitrary PIV data object.


OBJECT          name of PIV data object, or ID in HEX
OUTPUT          file to write object to (use '-' to use stdout)
r[   r\   r]   zAYubiKey FIPS must be in FIPS approved mode to export this object.c                 s  <  SP                  SP                  S4      4       \        R S R\        S4       2\        S4       R#   \
         du   pTP                  \        P                  8X  d   \        R4      hTP                  \        P                  8X  d&   T '       d   \        SSSS4       S! RR7        Rp?R# h Rp?ii ; i)zExported object z to zNo data found.F)retryN)r   r   r/   rX   r   r   r`   r   r   r&    SECURITY_CONDITION_NOT_SATISFIEDr   )	r   rd   r;   do_read_objectrN   r   r{   r   r[   s	   & r?   r   Z#read_object.<locals>.do_read_objectO  s    	LL++I67"9+T&.1ABFF  	ttr(((.//<<<C&#6U++	s%   A A CAB?!B?>B??CN)T)r^   r   PRINTEDZFINGERPRINTSZFACIALZIRISr&   )r;   r{   rN   r   r   r   r[   s   ffff@@@r?   read_objectr   5  s     ggi GWW]#F
ww~9	1 $ O
 	
  rY   rj   ZDATAc                s   V P                   R,          p\        P                  V8X  d1   V P                   R,          pVP                  '       d   \	        R4      h\        WV4        VP                  W4P                  4       4       \        P                  ! R4       R#   \         d;   pTP                  \        P                  8X  d   \	        R4      h\	        R4      hRp?ii ; i)a  
Write an arbitrary PIV object.

Write a PIV object by providing the object id.
Yubico writable PIV objects are available in
the range 5f0000 - 5fffff.


OBJECT         name of PIV data object, or ID in HEX
DATA           file containing the data to be written (use '-' to use stdin)
r[   r\   zFCan't write to slot 0x5fc109 while management key is protected by PIN.zObject imported.z-Something went wrong, is the object id valid?zError writing object.N)r^   r   r   has_protected_keyr&   ry   r   r   rg   rh   r   r`   r   r   )r;   r{   rz   rN   rj   r[   r   rd   s   &&&&&   r?   write_objectr   a  s    & ggi GI%'###X  #N3/9iik2

%& /442***IJJ-../s   &5B C"(5CC"c                s~   V P                   R,          p\        WV4       \        P                  V8X  d*   VP	                  \        P                  \        4       4       MI\        P                  V8X  d*   VP	                  \        P                  \        4       4       M\        R4      h\        P                  ! R4       R# )z
Generate and write data for a supported data object.


Supported data objects:
  "CHUID" (Card Holder Unique ID)
  "CCC"   (Card Capability Container)


OBJECT         name of PIV data object, or ID in HEX
r[   z#Unsupported object ID for generate.zObject generated.N)r^   ry   r   r   r   r   r
   r   r&   rg   rh   )r;   r{   rz   rN   r[   s   &&&& r?   generate_objectr     s~    $ ggi G#N3)#9??N,<=				*9//@;<<	JJ"#rY   c                 s    \        V R RRR7      pVR 8X  d   \        #  \        P                  V4      #   \         d    \        R4      hi ; i)r   TFr   z$Management key has the wrong format.)r-   r   rC   rD   r8   r&   )promptrz   s   & r?   _prompt_management_keyr     sT    !t%N %%>}}^,, ><==>s	   3 A
c                 s     \        V R RRR7      # )r   TFr   )r-   )r   rW   r?   r   r     s    t%PPrY   c                 s   V P                   R ,          pV P                   R,          pVP                  '       d*   V'       g"   \        WWqVR7      '       g   \        R4      hR# \	        WW$VR7       V'       d   \        WWqVR7       R# R# )r[   r\   r   z5Failed to authenticate with protected management key.TN)r^   r   r   r&   _authenticate)r;   r{   rz   rw   r   rx   r[   r   r|   r?   ry   ry     so     ggi GWW]#F3	JJQRR#)TC&C rY   c                 sX   V'       g   V'       d   \        R 4      h\        4       pRp VP                  V4       VP                  '       dU   \	        4       ;_uu_ 4        VP                  \        W2P                  4      4       RRR4       RpVP                  V4       V# VP                  '       dV    \        V4      p\	        4       ;_uu_ 4        VP                  VP                  4       RRR4       RpVP                  V4       V#   + '       g   i     L; i  + '       g   i     L8; i  \         d    \        P                  RRR7        L]i ; i  \         d3   pTP                  pT^ 8  d   \        RT R24      h\        R4      hRp?i\         d    \        R	4      hi ; i)
zPIN required.FNTz$Failed to read stored management keyr   zPIN verification failed, r   r   zPIN verification failed.)r&   r   Z
verify_pinZhas_derived_keyr1   authenticater   Zsaltr   r   rF   r8   r   Zwarningr   rq   )	r;   r[   r   r{   rx   ZauthenticatedZpivman_protrd   r   s	   &&&&&    r?   r   r     sh   /**-CM23!!!!!$$%:3%LM " Ms#& % """V7@#%%((9 & $ s# - "! &%  VEPTUV  -''a<5hZ|LMM+,, 20112s}   "E E %D	E  E 3D/ D,
D/ 6E 	D	E D,	'D/ /"EE EE F)"-FF)F)c                 s     V! 4       #   \          df   pTP                  \        P                  8X  dA   \        P                  R 4       T P                  R,          p\        YYcT4        Rp?T! 4       # h Rp?ii ; i)z:Command failed due to PIN required, verifying and retryingr\   N)r   r`   r   r   r   r   r^   r   )r;   r[   Zfuncr{   rx   rd   r   r   r?   r   r     sh    v 442666LLUVWW]+Ff9== 6M s   	 A9AA43A44A9c                 s&   V'       g.   V'       d   \        R 4      hVf   \        4       pM\        V4      p \        4       ;_uu_ 4        VP                  V4       RRR4       R#   + '       g   i     R# ; i  \         d    \        R4      hi ; i)zManagement key required.Nz*Authentication with management key failed.)r&   r   r1   r   r8   )r;   r[   rz   r   rx   s   &&&&&r?   r   r     st    455%!7!9!7!GD  0  DBCCDs)   A9 	A%A9 %A6	0A9 6A9 9Bc                 sH   V P                   R ,          p\        P                  VP                  9   dp   V\        P
                  \        P                  39   d   \        RVP                   R24      hV\        P                  39   d   \        RVP                   R24      hR# R# )rZ   z	Key type r   zPIN policy N)r^   r
   r_   rb   r   ZRSA1024ZX25519r&   rV   r   ZNEVER)r;   r   r   rZ   rG   r?   r   r     s    776?D~~***(((//::Ihmm_4STUU***,,joo..MN  - +rY   )rS   ZSHA384ZSHA512)z1Enter a management key [blank to use default key])z	Enter PIN)NNFNF)F)NF)}r   ZloggingZuuidr   rg   Zcryptography.hazmat.backendsr   Zcryptography.hazmat.primitivesr   r   Zyubikit.corer   r   Zyubikit.core.smartcardr   r   r	   Zyubikit.managementr
   Zyubikit.pivr   r   r   r   r   r   r   r   r   r   re   r   r   r   r   r   r   r   r   r   r   r   r    r!   Zutilr"   r#   r$   r%   r&   r'   r(   r)   r*   r+   r,   r-   r.   r/   r0   r1   Z	getLoggerZ__name__r   r@   rA   rH   rK   ZargumentZclick_slot_argumentZclick_object_argumentZoptionZclick_management_key_optionZclick_pin_optionZDEFAULTrV   Zclick_pin_policy_optionZclick_touch_policy_optionZChoiceZclick_hash_optionZclick_update_chuid_optionrX   Zpass_contextZcommandrZ   ro   Zgroupru   ZIntRanger}   r   r   r   r   r   r   r   ZRSA2048ZFiler   r   r   r   r   r   r   r   r   r   r   ZINTr   r   r   r   r   r   r   r   r   ry   r   r   r   r   rt   rY   r?   <module>r      sl  8     8 @ 5 E E )          
		8	$ " " 	" 	" 
 
   nnV6JK 0(  $ll	'	  <<gJ? ,,	J	##		  "LL	L	!  %%	 	  LL	4U	K	  "LL&	6 ' -./*   0*Z 	.  	. 'V   'VT / / ENN1c$:MRENN1c$:MR)5    S S  )5XR, dG"45dK&89 : 6  D dG"45dK&=>" ? 6  "J '(	D	 	&'	 	!'	 	#	'	(	 
8	 
/	 f=    )Vf=R dGe,dK%C% D -  %P   j	-	H	!! #%**T*:LQ, R        ",^ hEJJt$4mLdL'QR/? S M       /?d EJJt$4mL M    
0 f   : 	I	 dG"@A#%**T*:LQ: R B    :z f#78!56 7 9    2 h     
( > 40 hdL'UV	J	 ,+V UZZ-}EP> F   W    "P>f hEJJt$4mL9 M    
94 juzz$' 	=	 	7	 @8       0@8F i5::d#3\J5::d#3UC	G	 0  D K    0f h<      <" 9 ( 	uzz$/B$ C    
$N 	UZZ-v>/ ?     /B 	$     
$0	>Q0"J
D rY   