+
    :i=5  c                   s   ^ RI t ^ RIt^ RIHt ^ RIt^ RIHt ^ RIHt ^ RI	H
t
HtHt ^ RIHtHtHtHtHt ^ RIHt ^ RIHt ^R	IHtHtHt ^R
IHtHtHtHtHtH t H!t!H"t"H#t#H$t$H%t% ] PL                  ! ]'4      t(]! R].R]PR                  9  R7      ]PT                  ] R 4       4       4       t+]+PY                  4       ]PT                  R 4       4       t-]+PY                  4       ]PT                  ]R 4       4       4       t.]+P_                  4       R 4       t0R t1R t2]! 4       R 4       t3 ! R R]4      t4]Pj                  ! RR]4! 4       ]! 4       3]3R7      t6]0PY                  R4      ]PT                  ]6]Pj                  ! R]Pn                  ! R4      RR7      ]Pp                  ! RR ]! 4       ^ R!R"7      R# 4       4       4       4       4       t9]0PY                  R$4      ]PT                  ]6]Pj                  ! R%R&R'7      ]Pp                  ! R(R)R*R+7      ]Pp                  ! RR ]! 4       ^ R!R"7      R, 4       4       4       4       4       4       t:]0PY                  4       ]PT                  ]6]Pj                  ! R-]Pn                  ! R4      R.R7      R/ 4       4       4       4       t;]0PY                  R04      ]PT                  ]6]R1 4       4       4       4       t<]0PY                  R24      ]PT                  ]6]Pj                  ! R3R6]! 4       R47      R5 4       4       4       4       t=R# )7i    N)Any)x509)serialization)SW	ApduErrorSmartCardConnection)KeyRefScp03KeyParamsScp11KeyParamsScpKid
StaticKeys)
CAPABILITY)SecurityDomainSession)InvalidPasswordErrorparse_certificatesparse_private_key)CliFailHexIntParamTypeclick_callbackclick_force_optionclick_groupclick_postpone_executionclick_promptget_scp_paramslog_or_echoorganize_scp11_certificatespretty_printsdz--full-help)ZconnectionsZhiddenc                s   V P                   R,          pVP                  \        4      pV P                  VP                  4       \        V4      p\        V \        R4      V4      pV'       d   VP                  V4       \        V\        4      ;'       g@    \        V\        4      ;'       d(    VP                  P                  \        P                  8H  V P                   R&   W0P                   R&   R# )zC
Manage the Security Domain application, which holds keys for SCP.
ZdeviceauthenticatedsessionN)objZopen_connectionr   Zcall_on_closeZcloser   r   r   Zauthenticate
isinstancer   r   refkidr	   SCP11a)ctxZdevZconnr   Z
scp_paramss   &    >/usr/lib/python3.14/site-packages/ykman/_cli/securitydomain.pysecuritydomainr&   E   s     ''(
C23Ddjj!#D)GZ^T:JZ( 	:~. 	0 	0j.1 0 0NN&--/ GGO !GGI    c           	     sv   V P                   R,          p. pVP                  4       pVP                  4       P                  4        EF  pVP                  ^8X  d9   TP                  RVP                  R R2VP                  ^8X  d   RMR./4       KM  VP                  R9   d   K`  / pWC9   d"   RP                  R W4,           4       4      VR	&    VP                  V4       Uu. uF  qfP                  P                  4       NK  	  upVR
&    \        VP                  4      P                  pVP                  V RVP                  R RVP                  R R2V/4       EK  	  \        P                   ! RP                  \#        RV/4      4      4       R# u upi   \         d     Li ; i  \         d    Rp Li ; i)z2
List keys in the Security Domain of the YubiKey.
r   zSCP03 (KID=0x01-0x03, KVN=0x02X)zDefault key setzImported key set:c              3   s(   "   T F  qR  x  K
  	  R# 5i)r(   N ).0Zb   & r%   	<genexpr>Zinfo.<locals>.<genexpr>y   s     5S(Q3j(s   zCA Key IdentifierzCertificate chainzSCP11 OCE CAz (KID=0xz, KVN=0xZ
zSCP keysN)   i   )r   Zget_supported_ca_identifiersZget_key_informationkeysr"   Zappendkvnjoinget_certificate_bundleZsubjectZrfc4514_stringr   r	   name
ValueErrorclickechor   )r$   r   dataZcasr!   ZinnerZcr4   s   &       r%   infor9   b   s    
	BD

)
)
+C%%',,.77a<KK23773-qA-0WW_)BTD WW$&Ez-0XX5S#(5S-S)*8:8Q8QRU8V.8V1II,,.8V.)*
&cgg++ KKD6#''#hswwsm1MuUV3 /6 
JJtyyz4&89:;.    &%&s6   F!"FF
F(FF%$F%(F87F8c                sF   RV P                   9   d   \        R4      hV'       g   \        P                  ! RRRR7       \        P                  ! R4       V P                   R,          P                  4        \        P                  ! R4       \        P                  ! R	4       R
# )z
Reset all Security Domain data.

This action will wipe all keys and restore factory settings for
the Security Domain on the YubiKey.
Zscpz6Reset must be performed without an active SCP session.z`WARNING! This will delete all stored Security Domain data and restore factory settings. Proceed?TZabortZerrz!Resetting Security Domain data...r   zGReset complete. Security Domain data has been cleared from the YubiKey.z,Your YubiKey now has the default SCP key setN)r   r   r6   confirmr7   reset)r$   forces   &&r%   r<   r<      sx     NOO)		
 
JJ23GGI	JJQ 
JJ=>r'   c                 s    R# )zManage SCP keys.Nr+   r+   r'   r%   r0   r0      s    r'   c                 sN    V P                   R ,          '       g   \        R4      hR# )r   z>This command requires authentication, invoke ykman with --scp.N)r   r   )r$      &r%   _require_authr?      s"    77?##VWW $r'   c                 s    \        V R V 4      # r4   )Zgetattr)Zfobjr>   r%   _fnamerA      s    4&&r'   c                 sJ     \        V!  #   \         d    \        T4      hi ; i)N)r   ZAttributeErrorr5   )r$   paramZvals   &&&r%   click_parse_scp_refrC      s*    s| os    "c                   s*   a  ] tR t^t o RtR tRtV tR# )ScpKidParamTyper"   c                s   \        V\        4      '       d   V#  VP                  4       R R VR,          P                  4       ,           p\        V,          #   \
         d     TP                  4       P                  R4      '       d   \        TR,          ^4      u # RT9   d   \        TP                  RR4      ^4      u # \        T4      u #   \         d    T P                  T: R2Y#4         R # i ; ii ; i)N0x:r/   NNr*    z is not a valid integerr   )
r    ZintZupperZlowerr	   ZKeyErrorZ
startswithZreplacer5   Zfail)ZselfvaluerB   r$   r4   s   &&&& r%   convertZScpKidParamType.convert   s    eS!!L	K;;="%b	(99D$< 	KK;;=++D11uRy"--%<u}}S"5r::5z! K		UI%<=uJJK	KsM   ;A C8"$CCC8"C>C8
CC8!C4/C83C44C8r+   N)__name__Z
__module__Z__qualname__Z__firstlineno__r4   rH   Z__static_attributes__Z__classdictcell__)Z__classdict__s   @r%   rD   rD      s     DK Kr'   rD   keyzKID KVN)metavartypeZcallbackZgeneratezpublic-key-outputZwbz
PUBLIC-KEY)rL   rK   z-rz--replace-kvnz3replace an existing key of the same type (same KID))rL   defaulthelpc                s   \        V 4       \        P                  \        P                  \        P                  3pVP
                  V9  d(   RP                  R V 4       4      p\        RV R24      hV P                  R,          p VP                  WR7      p\        P                  P                   p	TP#                  TP%                  T	\        P&                  P(                  R	7      4       \+        R
T R\-        T4       2\.        T4       R#   \         d1   pTP                  \        P                  8X  d   \        R4      hh Rp?ii ; i)z
Generate an asymmetric key pair.

The private key is generated on the YubiKey, and written to one of the slots.


KID KVN     key reference for the new key
PUBLIC-KEY  file containing the generated public key (use '-' to use stdout)
z, c              3   sJ   "   T F  pR VR RVP                    R2x  K  	  R# 5i)rE   xz (r)   Nr@   )r,   Zvr-   r%   r.   Zgenerate_key.<locals>.<genexpr>   s%     DeAa5166(!4es   !#zKID must be one of .r   )replace_kvnNo space left for SCP keys.N)encodingZformatzPrivate key generated for z, public key written to )r?   r	   r#   SCP11bSCP11cr"   r2   r   r   Zgenerate_ec_keyr   swr   NO_SPACEr   EncodingPEMwritepublic_bytesZPublicFormatZSubjectPublicKeyInfor   rA   logger)
r$   rJ   Zpublic_key_outputrQ   ZvalidZ
values_strr   
public_keyeZkey_encodings
   &&&&      r%   generate_keyr_      s!   , #]]FMM6==9E
wweYYDeDD
+J<q9::ggi G,,S,J
 !))--L! --BB 	  	
 
$SE)A#$
%	'	  442;;788s   D E
+EE
ZimportinputZINPUT)rK   z-pz
--passwordz-password used to decrypt the file (if needed))rN   c                sh   \        V 4       V P                  R,          pVP                  \        P                  8X  dN   TP                  T\        VP                  R4       Uu. uF  p\        P                  V4      NK  	  up!  4       R# \        P                  ! R4      P                  VRV 4      pVP                  4       pVP                  \        P                  \        P                  \        P                   39   dV    Ve   VP#                  4       p \%        W4      p	 \1        \3        Y4      4      w  rpT'       d   \5        T4      T.,           pMwVP                  ^.\7        ^ ^04      O59   d?   \1        \3        VR4      4      w  rpV
'       g   \9        R4      hV
P;                  4       p	RpM\9        RVP                  R R24      h VP                  WV4       \        P.                  ! RV	 R24       T'       d(   TPE                  Y4       \        P.                  ! R4       T
'       dg   T
PF                  PI                  \J        PL                  4      pTPO                  YPP                  PR                  4       \        P.                  ! R4       R# R# u upi   \&         dL    \(        P+                  RRR7       Tf   \-        RR	RR
R7      p EK  Rp\        P.                  ! R4        EK  i ; i  \<         d1   pTP>                  \@        PB                  8X  d   \9        R4      hh Rp?ii ; i)a  
Import a key or certificate.

KID 0x01 expects the input to be a ":"-separated triple of K-ENC:K-MAC:K-DEK.

KID 0x11, 0x13, and 0x15 expect the input to be a file containing a private key and
(optionally) a certificate chain.

KID 0x10, 0x20-0x2F expect the file to contain a CA-KLOC certificate.


KID KVN     key reference for the new key
INPUT       SCP03 keyset, or input file (use '-' to use stdin)
r   r*   NZrbTzError parsing file)Zexc_infozEnter password to decrypt filerF   F)rM   Z
hide_inputZshow_defaultzWrong password.z3Input does not contain a valid CA-KLOC certificate.zInvalid value for KID=rO   rP   zKey stored for rR   zCertificate bundle stored.zCA key identifier stored.)*r?   r   r"   r	   ZSCP03Zput_keyr
   ZsplitZbytesZfromhexr6   FilerH   Zreadr#   rT   rU   Zencoder   r   r\   Zdebugr   r7   r   r   ZlistZranger   r]   r   rV   r   rW   Zstore_certificate_bundleZ
extensionsZget_extension_for_classr   ZSubjectKeyIdentifierZstore_ca_issuerrG   Zdigest)r$   rJ   r`   ZpasswordrQ   r   ZkZfiler8   ZtargetZcaZbundleZleafZinterr^   Zskis   &&&&&           r%   
import_keyrb     s   8 #ggi G
ww&,,ZEKKPSDT)UDTq%--*:DT)UVW::d##E45D99;D
ww6==&--??##??,2*4: 7t.
D &\TF*F	T.E$-.	.56Ht6TU4OPP .swwqk;<<[1

_VHA./ ((5

/0 
mm33D4M4MNYY%5%56

./ 
q *V ( 21DA#+8 "#'%*	 H  $HJJ0112@  442;;788s6   "JJ ,K6 5K3K32K36L1+L,,L1zcertificates-outputZOUTPUTc                s   V P                   R,          p\        VP                  V4      4       Uu. uF-  pVP                  \        P
                  P                  R7      NK/  	  ppV'       dC   VP                  RP                  V4      4       \        RV R\        V4       2\        V4       R# \        RV R24      hu upi )	z
Export certificate chain for a key.


KID KVN     key reference to output certificate chain for
OUTPUT      file to write the certificate chain to (use '-' to use stdout)
r   )rS   r'   zCertificate chain for z written to z No certificate chain stored for rP   N)r   Zreversedr3   r[   r   rX   rY   rZ   r2   r   rA   r\   r   )r$   rJ   Zcertificates_outputr   ZcertZpemss   &&&   r%   exportrc   k  s     ggi G W;;C@AAD 	=#9#9#=#=>A 	  !!#((4.1$SEf=P6Q5RS	
 8Q?@@s   3B>Zdeletec                s   \        V 4       V P                  R,          pV'       g   \        P                  ! RRRR7        VP	                  VP
                  VP                  4       \        P                  ! R4       R	#   \         d_   pTP                  \        P                  8X  d   \        RT R24      hTP                  \        P                  8X  d   \        R4      hh R	p?ii ; i)
z
Delete a key or keyset.

Deletes the key or keyset with the given KID and KVN. Set either KID or KVN to 0 to
use it as a wildcard and delete all keys matching the specific KID or KVN


KID KVN     key reference for the key to delete
r   z9WARNING! This will delete all matching SCP keys. Proceed?Tr:   zSCP key deleted.zNo key stored in rP   z>This would delete ALL SCP keys, use the reset command instead.N)r?   r   r6   r;   
delete_keyr"   r1   r7   r   rV   r   ZREFERENCE_DATA_NOT_FOUNDr   ZCONDITIONS_NOT_SATISFIED)r$   rJ   r=   r   r^   s   &&&  r%   rd   rd     s     #ggi GG	

377CGG,

%& 442...-cU!455442...P  	s   <A? ?C(
AC##C(zset-allowlistserials)ZnargsrL   c                s    \        V 4       V P                  R,          pVP                  W4       \        P                  ! RV R24       R# )aQ  
Set an allowlist of certificate serial numbers for a key.

Each certificate in the chain used when authenticating an SCP11a/c session will be
checked and rejected if their serial number is not in this allowlist.


KID KVN     key reference to set the allowlist for
SERIALS     serial numbers of certificates to allow (space separated)
r   z$SCP serial number allowlist set for rP   N)r?   r   Zstore_allowlistr6   r7   )r$   rJ   re   r   s   &&& r%   set_allowlistrf     s>     #ggi GC)	JJ5cU!<=r'   r   )>ZloggingZsysZtypingr    r6   Zcryptographyr   Zcryptography.hazmat.primitivesr   Zyubikit.core.smartcardr   r   r   Zyubikit.core.smartcard.scpr   r   r   r	   r
   Zyubikit.managementr   Zyubikit.securitydomainr   Zutilr   r   r   r   r   r   r   r   r   r   r   r   r   r   Z	getLoggerrI   r\   ZargvZpass_contextr&   Zcommandr9   r<   Zgroupr0   r?   rA   rC   rD   ZargumentZclick_key_argumentra   Zoptionr_   rb   rc   rd   rf   r+   r'   r%   <module>rg      sM  8  
    8 E E  * 8 
    
		8	$ *+M4Q !  
!0 "<  "<J ?   ?6  X
'  Ko K( ^^	

_.	/ 	  j#%**T*:LQ			>& R   &R h)dL'VW			>O0 X *   O0d %EJJt,<hOA P   A0 h    B o	/*;<> =   >r'   