+
    :iuY  c                  s   ^ RI Ht ^ RIt^ RIt^ RIHt ^ RIHtHt ^ RI	H
t
 ^ RIHt ^ RIHt ^ RIHt ^ R	IHt ^ R
IHt ^RIHtHtHtHtHtHtHt ^RIHtHtH t H!t!H"t"H#t# ]PH                  ! ]%4      t&^qt'^rt(^st)^tt*^ut+^vt,^wt-^xt.^yt/^zt0^{t1^|t2^}t3^t4^t5^t6^t7^t8^t9^t:^t;^	t<^
t=^t>^t?^t@^tA^@tBRtC^tD] ! R R]4      4       tER R ltFR R ltGR tHR R ltIR tJ]
]! RRR7       ! R R4      4       4       tK ! R R]4      tL ! R R 4      tMR# )!    )annotationsN)	dataclass)IntEnumunique)total_ordering)
NamedTuple)default_backend)hashes)ec)
PBKDF2HMAC)InvalidPinErrorTlvVersion_override_version	bytes2int	int2bytesrequire_version)AIDSW	ApduErrorScpKeyParamsSmartCardConnectionSmartCardProtocols                   c                  sH    ] tR t^htRt^&t^'t]R R l4       t]R 4       t	Rt
R# )	ALGORITHMz(Algorithms for YubiHSM Auth credentials.c                   V ^8  d   QhRR/#    returnint Zformat   "4/usr/lib/python3.14/site-packages/yubikit/hsmauth.py__annotate__ZALGORITHM.__annotate__p   s     . . .    c                	s    V P                   P                  R 4      '       d   ^# V P                   P                  R4      '       d   ^ # \        R4      h)ZAES128EC_P256zUnknown algorithm)name
startswith
ValueErrorself   &r!   key_lenZALGORITHM.key_leno   s>    99))YY!!),,,--r#   c                	sL    V P                   P                  R 4      '       d   ^@# R# )r$   N)r%   r&   r(   r*   r!   
pubkey_lenZALGORITHM.pubkey_lenw   s    99	** +r#   r   N)__name__
__module____qualname____firstlineno____doc__AES128_YUBICO_AUTHENTICATIONEC_P256_YUBICO_AUTHENTICATIONpropertyr+   r,   __static_attributes__r   r#   r!   r   r   h   s7    2#% $&!. .  r#   r   c                    V ^8  d   QhRRRR/# )r   credential_passwordbytes | strr   bytesr   r   r    r!   r"   r"   }   s     
 
K 
E 
r#   c                s    \        V \        4      '       d&   V P                  4       P                  \        R 4      pM\        V 4      p\        V4      \        8w  d   \        R\        ,          4      hV# )s    z)Credential password must be %d bytes long)
isinstancestrencodeZljustCREDENTIAL_PASSWORD_LENr9   lenr'   )r7   Zpw   & r!   _parse_credential_passwordr@   }   sa    %s++ '')//0GO&'
2w))7:QQ
 	
 Ir#   c               r6   )r   labelr;   r   r9   r   r   r    r!   r"   r"      s        r#   c                s     V P                  4       p\        T4      \        8  g   \        T4      \
        8  d   \        R \        \
        3,          4      hT#   \         d    \        T 4      hi ; i)z*Label must be between %d and %d bytes long)r<   Z	Exceptionr'   r>   MIN_LABEL_LENMAX_LABEL_LEN)rA   Zparsed_labelr?   r!   _parse_labelrD      sn     ||~ <=(C,=,M8m,-
 	
     s   A A/c                sd    \         P                  ! \        V 4      p\        P                  ! V4      # N)r   unpackTAG_VERSIONr   Z
from_bytes)responsedatar?   r!   _parse_selectrJ      s#    ::k8,Dd##r#   c               r6   )r   passwordr;   r   ztuple[bytes, bytes]r   r   r    r!   r"   r"      s      s ': r#   c                s    V P                  4       p\        \        P                  ! 4       ^ RR\	        4       R7      P                  V4      pVR,          VR,          rCW43# )zmDerive encryption and MAC key from a password.

:return: A tuple containing the encryption key, and MAC key.
s   Yubicoi'  )	algorithmlengthZsaltZ
iterationsZbackendN   NrO   NN)r<   r
   r   ZSHA256r   Zderive)rK   Zpw_byteskeykey_enckey_macs   &    r!   _password_to_keyrT      s[    
  H
--/! fX  3xSWr#   c                sP    V R ,          \         P                  8X  d
   V R,          # R# )i  Ni )r   ZVERIFY_FAIL_NO_RETRY)swr*   r!   _retries_from_swrV      s!    	F{b---G|r#   FT)ZorderZfrozenc                  s\    ] tR t^t$ RtR]R&   R]R&   R]R&   R]R	&   R
 tR tR R ltRt	R# )
Credentialz!A YubiHSM Auth credential object.r;   rA   r   rL   r   counterzbool | Nonetouch_requiredc                	sr    V P                   P                  4       pVP                   P                  4       pW#8  # rE   )rA   Zlower)r)   otherZaZb   &&  r!   __lt__ZCredential.__lt__   s-    JJKKur#   c                	s4    V P                   VP                   8H  # rE   )rA   )r)   rZ   s   &&r!   __eq__ZCredential.__eq__   s    zzU[[((r#   c               r   r   r   r   r    r!   r"   ZCredential.__annotate__   s        #  r#   c                	s,    \        V P                  4      # rE   )ZhashrA   r(   r*   r!   __hash__ZCredential.__hash__   s    DJJr#   r   N)
r-   r.   r/   r0   r1   __annotations__r\   r]   r^   r5   r   r#   r!   rW   rW      s1     ,JL
)   r#   rW   c                  sP    ] tR t^t$ RtR]R&   R]R&   R]R&   ]R R l4       tRtR	# )
SessionKeyszYubiHSM Session Keys.r9   key_senckey_smac	key_srmacc               r6   )r   rH   r9   r   r`   r   r   r    r!   r"   ZSessionKeys.__annotate__   s     	
 	
U 	
{ 	
r#   c                	sN    VR ,          pVR,          pVR,          pV ! VVVR7      # )rN   :rO       N:rd   i0   N)ra   rb   rc   r   )ZclsrH   ra   rb   rc   s   &&   r!   parseZSessionKeys.parse   s3    C=E?UO	
 	
r#   r   N)	r-   r.   r/   r0   r1   r_   Zclassmethodre   r5   r   r#   r!   r`   r`      s'    OO	
 	
r#   r`   c                  s8   ] tR t^tRtR,R R llt]R R l4       tR R ltR	 R
 lt	R-R R llt
R-R R lltR-R R lltR-R R lltR-R R lltR R ltR R ltR R ltR R ltR R ltR R  ltR! R" ltR.R# R$ lltR,R% R& lltR' R( ltR,R) R* lltR+tR# )/HsmAuthSessionz,A session with the YubiHSM Auth application.Nc               $    V ^8  d   QhRRRRRR/# )r   
connectionr   scp_key_paramszScpKeyParams | Noner   Noner   r   r    r!   r"   HsmAuthSession.__annotate__   s(     3 3'3 ,3 
	3r#   c                	sP   \        V4      V n        \        P                  ! \	        V P                  P                  \        P                  4      4      4      V n        V P                  P                  V P                  4       V'       d   V P                  P                  V4       R # R # rE   )r   protocolr   ZpatchrJ   Zselectr   ZHSMAUTH_versionZ	configureZinit_scp)r)   rh   ri   s   &&&r!   __init__ZHsmAuthSession.__init__   so    
 **5)//$--..s{{;<
 	.MM"">2 r#   c               r   )r   r   r   r   r   r    r!   r"   rk      s       r#   c                s    V P                   # )z%The YubiHSM Auth application version.)rm   r(   r*   r!   versionZHsmAuthSession.version   s     }}r#   c               r   )r   r   rj   r   r   r    r!   r"   rk      s     E Et Er#   c                st    V P                   P                  ^ \        ^^4       \        P	                  R4       R# )z8Perform a factory reset on the YubiHSM Auth application.z-YubiHSM Auth application data reset performedN)rl   	send_apdu	INS_RESETloggerinfor(   r*   r!   resetZHsmAuthSession.reset   s'    9dD9CDr#   c               r   )r   r   zlist[Credential]r   r   r    r!   r"   rk      s      "2 r#   c           	     s   . p\         P                  ! V P                  P                  ^ \        ^ ^ 4      4       F  p\         P
                  ! \        V4      p\        V^ ,          4      p\        V^,          4      pVP                  ^,
          pV^^V,            P                  4       pVR,          pVP                  \        WtW4      4       K  	  V# )z(List YubiHSM Auth credentials on YubiKeyi)r   Z
parse_listrl   rp   INS_LISTrF   TAG_LABEL_LISTr   boolrM   ZdecodeZappendrW   )	r)   ZcredsZtlvrI   rL   rY   Zlabel_lengthrA   rX   s	   &        r!   list_credentialsZHsmAuthSession.list_credentials   s     >>$--"9"9!Xq!"LMC::nc2D!$q'*I!$q']N::>LQ-.557E2hGLLEgNO N r#   c               s4    V ^8  d   QhRRRRRRRRRR	R
RRR/# )r   management_keyr9   rA   r;   rQ   rL   r   r7   r8   rY   rw   r   rW   r   r   r    r!   r"   rk   	  sY     2S 2S2S 2S 	2S
 2S )2S 2S 
2Sr#   c           	     	s   \        V4      \        8w  d   \        R \        ,          4      h\        \        V4      \        \
        \        V4      4      ,           \        \        \        V4      4      ,           pV\        P                  8X  d<   V\        \        VR,          4      \        \        VR,          4      ,           ,          pM,V\        P                  8X  d   V\        \        V4      ,          pV\        \        \!        V4      4      ,          pV'       d"   V\        \"        \        ^4      4      ,          pM V\        \"        \        ^ 4      4      ,          p\$        P'                  RV RV RV R24        V P(                  P+                  ^ \,        ^ ^ V4       \$        P/                  R4       \9        Y$\:        T4      #   \0         d1   p\3        TP4                  4      p	T	f   h \7        T	R	T	 R
2R7      hRp?ii ; i)$Management key must be %d bytes longrN   rP   z)Importing YubiHSM Auth credential (label=z, algo=z, touch_required=Z)zCredential importedNInvalid management key,  attempts remainingZattempts_remainingZmessage)r>   MANAGEMENT_KEY_LENr'   r   TAG_MANAGEMENT_KEY	TAG_LABELrD   TAG_ALGORITHMr   r   r2   TAG_KEY_ENCTAG_KEY_MACr3   TAG_PRIVATE_KEYTAG_CREDENTIAL_PASSWORDr@   	TAG_TOUCHrr   Zdebugrl   rp   INS_PUTrs   r   rV   rU   r   rW   INITIAL_RETRY_COUNTER)
r)   ry   rA   rQ   rL   r7   rY   rI   eretriess
   &&&&&&&   r!   _put_credentialZHsmAuthSession._put_credential	  s    ~"4469KK 
 "N3)\%012-9!567 	 	>>>CSX.[#c(1KKKD)AAAC--D#%?@S%T
 	
 C	9Q<00DC	9Q<00D7wgi[ Q,-Q0	

	MM##Aw1d;KK-. %,A>RR  	&qtt,G!#*27);NO 		s   <8G H +G;;H c               s4    V ^8  d   QhRRRRRRRRRRR	R
RR/# )r   ry   r9   rA   r;   rR   rS   r7   r8   rY   rw   r   rW   r   r   r    r!   r"   rk   =  sP     !
 !
!
 !
 	!

 !
 )!
 !
 
!
r#   c                s    \         P                  P                  p\        V4      V8w  g   \        V4      V8w  d   \	        RV4      hV P                  VVW4,           \         P                  VV4      # )aS  Import a symmetric YubiHSM Auth credential.

:param management_key: The management key.
:param label: The label of the credential.
:param key_enc: The static K-ENC.
:param key_mac: The static K-MAC.
:param credential_password: The password used to protect
    access to the credential.
:param touch_required: The touch requirement policy.
z,Encryption and MAC key must be %d bytes long)r   r2   r+   r>   r'   r   )r)   ry   rA   rR   rS   r7   rY   Zaes128_key_lens   &&&&&&& r!   put_credential_symmetricZ'HsmAuthSession.put_credential_symmetric=  sn    ( #??GGw<>)S\^-K>  ##22
 	
r#   c               s0    V ^8  d   QhRRRRRRRRRR	R
R/# )r   ry   r9   rA   r;   derivation_passwordr7   r8   rY   rw   r   rW   r   r   r    r!   r"   rk   `  sF     
 

 
 !	

 )
 
 

r#   c                sB    \        V4      w  rgV P                  WWgWE4      # )al  Import a symmetric YubiHSM Auth credential derived from password.

:param management_key: The management key.
:param label: The label of the credential.
:param derivation_password: The password used to derive the keys from.
:param credential_password: The password used to protect
    access to the credential.
:param touch_required: The touch requirement policy.
)rT   r   )r)   ry   rA   r   r7   rY   rR   rS      &&&&&&  r!   put_credential_derivedZ%HsmAuthSession.put_credential_derived`  s-    $ ,,?@,,75H
 	
r#   c               s0    V ^8  d   QhRRRRRRRRR	R
RR/# )r   ry   r9   rA   r;   private_keyz+ec.EllipticCurvePrivateKeyWithSerializationr7   r8   rY   rw   r   rW   r   r   r    r!   r"   rk   x  sG     !
 !
!
 !
 A	!

 )!
 !
 
!
r#   c                s\   \        V P                  R4       \        VP                  \        P
                  4      '       g   \        R4      h\        P                  P                  pVP                  4       pV P                  VV\        VP                  V4      \        P                  VV4      # )a{  Import an asymmetric YubiHSM Auth credential.

:param management_key: The management key.
:param label: The label of the credential.
:param private_key: Private key corresponding to the public
    authentication key object on the YubiHSM.
:param credential_password: The password used to protect
    access to the credential.
:param touch_required: The touch requirement policy.
Unsupported curve   i   r    )r   ro   r:   curver	   	SECP256R1r'   r   r3   r+   Zprivate_numbersr   r   Zprivate_value)r)   ry   rA   r   r7   rY   Zlnnumbersr   r!   put_credential_asymmetricZ(HsmAuthSession.put_credential_asymmetricx  s    & 	i0+++R\\::01144<<--/##g++R033
 	
r#   c          
     ,    V ^8  d   QhRRRRRRRRR	R
/# )r   ry   r9   rA   r;   r7   r8   rY   rw   r   rW   r   r   r    r!   r"   rk     s<     
 

 
 )	

 
 

r#   c                sv    \        V P                  R4       V P                  VVR\        P                  VV4      # )a  Generate an asymmetric YubiHSM Auth credential.

Generates a private key on the YubiKey, whose corresponding
public key can be retrieved using `get_public_key`.

:param management_key: The management key.
:param label: The label of the credential.
:param credential_password: The password used to protect
    access to the credential.
:param touch_required: The touch requirement policy.
r#   r   )r   ro   r   r   r3   )r)   ry   rA   r7   rY      &&&&&r!   generate_credential_asymmetricZ-HsmAuthSession.generate_credential_asymmetric  s=    & 	i0##33
 	
r#   c               r6   )r   rA   r;   r   ec.EllipticCurvePublicKeyr   r   r    r!   r"   rk     s     Q QC Q,E Qr#   c                s   \        V P                  R4       \        \        \	        V4      4      pV P
                  P                  ^ \        ^ ^ V4      p\        P                  P                  \        P                  ! 4       V4      # )zGet the public key for an asymmetric credential.

This will return the long-term public key "PK-OCE" for an
asymmetric credential.

:param label: The label of the credential.
r   )r   ro   r   r   rD   rl   rp   INS_GET_PUBLIC_KEYr	   ZEllipticCurvePublicKeyZfrom_encoded_pointr   )r)   rA   rI   resr[   r!   get_public_keyZHsmAuthSession.get_public_key  s_     	i09l512mm%%a);Q4H((;;BLLNCPPr#   c               rg   )r   ry   r9   rA   r;   r   rj   r   r   r    r!   r"   rk     s!       c d r#   c                s   \        V4      \        8w  d   \        R\        ,          4      h\        \        V4      \        \
        \        V4      4      ,           p V P                  P                  ^ \        ^ ^ V4       \        P                  R4       R#   \         d1   p\        TP                  4      pTf   h \        TRT R2R7      hRp?ii ; i)zyDelete a YubiHSM Auth credential.

:param management_key: The management key.
:param label: The label of the credential.
rz   zCredential deletedNr{   r|   r}   )r>   r~   r'   r   r   r   rD   rl   rp   
INS_DELETErr   rs   r   rV   rU   r   )r)   ry   rA   rI   r   r      &&&   r!   delete_credentialZ HsmAuthSession.delete_credential  s     ~"4469KK  %~6|E*:
 

	MM##Az1a>KK,- 	&qtt,G!#*27);NO 		s   8B C+C

Cc               rg   )r   rI   r9   use_management_keyrw   r   rj   r   r   r    r!   r"   rk     s$      /3	r#   c                	s4   \        V P                  R4        V P                  P                  ^ \        V'       d   ^M^ ^ V4       \
        P                  R4       R#   \         d1   p\        TP                  4      pTf   h \        TRT R2R7      hRp?ii ; i)r   zCredential password changedNzInvalid auth, r|   r}   )r   i   r    )r   ro   rl   rp   INS_CHANGE_CREDENTIAL_PASSWORDrr   rs   r   rV   rU   r   )r)   rI   r   r   r   s   &&&  r!   _change_credential_passwordZ*HsmAuthSession._change_credential_password  s     	i0	MM##.'Q KK56 	&qtt,G!#*(	1DE 		s   AA B'+BBc               s(    V ^8  d   QhRRRRRRRR/# )r   rA   r;   r7   r8   new_credential_passwordr   rj   r   r   r    r!   r"   rk     s2     6 66 )6 "-	6
 
6r#   c                s    \        \        \        V4      4      \        \        \	        V4      4      ,           \        \        \	        V4      4      ,           pV P                  VR4       R# )zChange the password of a YubiHSM Auth credential.

:param label: The label of the credential.
:param credential_password: The current credential password.
:param new_credential_password: The new credential password.
FN)r   r   rD   r   r@   r   )r)   rA   r7   r   rI      &&&& r!   change_credential_passwordZ)HsmAuthSession.change_credential_password  s^     	<./')CDW)X '*+BC	 	 	((u5r#   c               s(    V ^8  d   QhRRRRRRRR/# )	r   rA   r;   ry   r9   r   r8   r   rj   r   r   r    r!   r"   rk     s2     5 55 5 "-	5
 
5r#   c                s   \        V4      \        8w  d   \        R\        ,          4      h\        \        \        V4      4      \        \        V4      ,           \        \        \        V4      4      ,           pV P                  VR4       R# )zChange the password of a YubiHSM Auth credential with management key.

:param label: The label of the credential.
:param management_key: The management key.
:param new_credential_password: The new credential password.
rz   TN)
r>   r~   r'   r   r   rD   r   r   r@   r   )r)   rA   ry   r   rI   r   r!    change_credential_password_adminZ/HsmAuthSession.change_credential_password_admin  sy     ~"4469KK 
 	<./$n56'*+BC 	 	((t4r#   c               s$    V ^8  d   QhRRRRRR/# )r   ry   r9   new_management_keyr   rj   r   r   r    r!   r"   rk   +  s(     ! !! "! 
	!r#   c                s   \        V4      \        8w  g   \        V4      \        8w  d   \        R\        ,          4      h\        \        V4      \        \        V4      ,           p V P
                  P                  ^ \        ^ ^ V4       \        P                  R4       R#   \         d1   p\        TP                  4      pTf   h \        TRT R2R7      hRp?ii ; i)zChange YubiHSM Auth management key

:param management_key: The current management key.
:param new_management_key: The new management key.
rz   zNew management key setNr{   r|   r}   )r>   r~   r'   r   r   rl   rp   INS_PUT_MANAGEMENT_KEYrr   rs   r   rV   rU   r   )r)   ry   r   rI   r   r   r   r!   put_management_keyZ!HsmAuthSession.put_management_key+  s     #55%&*<<69KK  %~6 2:
 

	MM##A'=q!TJKK01 	&qtt,G!#*27);NO 		s   %8B C*+CCc               r   r   r   r   r    r!   r"   rk   N  s      C r#   c                s\    V P                   P                  ^ \        ^ ^ 4      p\        V4      # )z(Get retries remaining for Management key)rl   rp   INS_GET_MANAGEMENT_KEY_RETRIESr   )r)   r   r?   r!   get_management_key_retriesZ)HsmAuthSession.get_management_key_retriesN  s)     mm%%a)GAN~r#   c               s0    V ^8  d   QhRRRRRRRRR	RR
R/# )r   rA   r;   contextr9   r7   r8   card_cryptobytes | None
public_keyr   r   r   r    r!   r"   rk   T  sF            )	 
 "  !  
 r#   c                	s   \        \        \        V4      4      \        \        V4      ,           pV'       d   V\        \        V4      ,          pV'       d   V\        \
        V4      ,          pV\        \        \        V4      4      ,          p V P                  P                  ^ \        ^ ^ V4      p\        P                  R4       V#   \         d1   p\        TP                  4      p	T	f   h \!        T	RT	 R2R7      hRp?ii ; i)r    zSession keys calculatedNzInvalid credential password, r|   r}   )r   r   rD   TAG_CONTEXTTAG_PUBLIC_KEYTAG_RESPONSEr   r@   rl   rp   INS_CALCULATErr   rs   r   rV   rU   r   )
r)   rA   r   r7   r   r   rI   r   r   r   s
   &&&&&&    r!   _calculate_session_keysZ&HsmAuthSession._calculate_session_keysT  s     9l512Sg5NNC
33DCk22D#%?@S%T
 	

	--))!]Aq$GCKK12 
  	&qtt,G!#*7y@ST 		s   8C D+C>>Dc          
     r   )r   rA   r;   r   r9   r7   r8   r   r   r   r`   r   r   r    r!   r"   rk   v  s<     
 

 
 )	

 "
 

r#   c           	     sR    \         P                  V P                  VVVVR7      4      # )a+  Calculate session keys from a symmetric YubiHSM Auth credential.

:param label: The label of the credential.
:param context: The context (host challenge + hsm challenge).
:param credential_password: The password used to protect
    access to the credential.
:param card_crypto: The card cryptogram.
)rA   r   r7   r   )r`   re   r   )r)   rA   r   r7   r   r   r!    calculate_session_keys_symmetricZ/HsmAuthSession.calculate_session_keys_symmetricv  s6        (($7'	 ) 
 	
r#   c               s0    V ^8  d   QhRRRRRRRRR	RR
R/# )r   rA   r;   r   r9   r   r   r7   r8   r   r   r`   r   r   r    r!   r"   rk     sF     &
 &
&
 &
 .	&

 )&
 &
 
&
r#   c           
     s   \        V P                  R4       \        VP                  \        P
                  4      '       g   \        R4      hVP                  4       p\        P                  ! R^4      \        P                  VP                  VP                  ^,          R4      ,           \        P                  VP                  VP                  ^,          R4      ,           p\        P!                  V P#                  VVVVVR7      4      # )aS  Calculate session keys from an asymmetric YubiHSM Auth credential.

:param label: The label of the credential.
:param context: The context (EPK.OCE + EPK.SD).
:param public_key: The YubiHSM device's public key.
:param credential_password: The password used to protect
    access to the credential.
:param card_crypto: The card cryptogram.
r   z!BZbig)rA   r   r7   r   r   r   )r   ro   r:   r   r	   r   r'   Zpublic_numbersstructZpackr   Zto_bytesZxZkey_sizeZyr`   re   r   )r)   rA   r   r   r7   r   r   Zpublic_key_datar   r!   !calculate_session_keys_asymmetricZ0HsmAuthSession.calculate_session_keys_asymmetric  s    $ 	i0***BLL99011++- KKa ll799j&9&9Q&>FGll799j&9&9Q&>FG 	   (($7'* ) 
 	
r#   c               rg   )r   rA   r;   r7   zbytes | str | Noner   r9   r   r   r    r!   r"   rk     s)     I II/AI	Ir#   c                s@   \        V P                  R4       \        \        \	        V4      4      pVeJ   V P                  R8  g   V P                  ^ ,          ^ 8X  d!   V\        \
        \        V4      4      ,          pV P                  P                  ^ \        ^ ^ V4      # )a4  Get the Host Challenge.

For symmetric credentials this is Host Challenge, a random 8 byte value.
For asymmetric credentials this is EPK-OCE.

:param label: The label of the credential.
:param credential_password: The password used to protect access to the
    credential, needed for asymmetric credentials.
r   )r   i   i   )
r   ro   r   r   rD   r   r@   rl   rp   INS_GET_CHALLENGE)r)   rA   r7   rI   s   &&& r!   get_challengeZHsmAuthSession.get_challenge  s     	i0)\%%89*LLI%aA)=C')CDW)X D }}&&q*;Q4HHr#   )rm   rl   rE   )F)NN)r-   r.   r/   r0   r1   rn   r4   ro   rt   rx   r   r   r   r   r   r   r   r   r   r   r   r   r   r   r   r   r5   r   r#   r!   rf   rf      s    63  E
2Sh!
F
0!
F
:Q8,6056!F D
2&
PI Ir#   rf   )NZ
__future__r   Zloggingr   Zdataclassesr   Zenumr   r   Z	functoolsr   Ztypingr   Zcryptography.hazmat.backendsr   Zcryptography.hazmat.primitivesr   Z)cryptography.hazmat.primitives.asymmetricr	   Z)cryptography.hazmat.primitives.kdf.pbkdf2r
   Zcorer   r   r   r   r   r   r   Zcore.smartcardr   r   r   r   r   r   Z	getLoggerr-   rr   r   rv   r   r   r   r   r   r   rG   r   r   r   r   r   r   r   r   ru   rq   ZINS_GET_VERSIONr   r   r   r   r~   r=   rB   rC   ZDEFAULT_MANAGEMENT_KEYr   r   r@   rD   rJ   rT   rV   rW   r`   rf   r   r#   r!   <module>r      sw  8 #   !   $  8 1 8 @    
		8	$ 	 	  
 	 !%  !%     H      (
$
$ 
t$    %  (
* 
(oI oIr#   