+
    :i3  c                  s   ^ RI Ht ^ RIt^ RIHtHt ^ RIHtHtH	t	 ^ RI
Ht ^ RIHt ^ RIHt ^ RIHt ^ R	IHtHtHt ^R
IHtHtHtHt ^RIHtHtHtHtH t H!t! ^RI"H#t#H$t$H%t%H&t&H't'H(t(H)t)H*t* ]PV                  ! ],4      t-^t.^t/^t0^t1^t2^t3^ft4Rt5Rt6Rt7] ! R R]4      4       t8Rt9] ! R R]4      4       t:R R lt;RR R llt< ! R R4      t=R# )    )annotationsN)IntEnumunique)MappingSequencecast)x509)default_backend)serialization)ec)Cipher
algorithmsmodes)BadResponseErrorTlvVersion	int2bytes)AIDSW	ApduErrorScpProcessorSmartCardConnectionSmartCardProtocol)INS_EXTERNAL_AUTHENTICATEINS_INITIALIZE_UPDATEINS_INTERNAL_AUTHENTICATEINS_PERFORM_SECURITY_OPERATIONKeyRefScpKeyParamsScpKid
StaticKeysi3  i4  i!  c                  s&    ] tR t^1t^t^t^t^tRtR# )KeyType N)	__name__
__module____qualname____firstlineno__AESECC_PUBLIC_KEYECC_PRIVATE_KEYECC_KEY_PARAMS__static_attributes__r!       ;/usr/lib/python3.14/site-packages/yubikit/securitydomain.pyr    r    1   s    
CNONr+   r    c                  sZ    ] tR t^<t^ t^t^t^t^t^t	]
R R l4       t]R R l4       tRtR# )Curvec                    V ^8  d   QhRRRR/# )   keyz6ec.EllipticCurvePrivateKey | ec.EllipticCurvePublicKeyreturnr-   r!   Zformat   "r,   __annotate__Curve.__annotate__F   s     4 4H4	4r+   c                	s    VP                   P                  P                  4       pV  F&  pVP                  P                  4       V8X  g   K$  Vu # 	  \        R 4      h)zUnsupported private key)curvenameZlower
ValueError)Zclsr0   r7   r6      &&  r,   	_from_keyZCurve._from_keyE   sL     yy~~##%Ezz!T)  233r+   c                   V ^8  d   QhRR/# )r/   r1   zec.EllipticCurver!   r2   r3   r,   r4   r5   P   s     ( (( (r+   c                	s@    \        \        V P                  4      ! 4       # N)Zgetattrr
   r7   self   &r,   _curveZCurve._curveO   s    r499%''r+   r!   N)r"   r#   r$   r%   	SECP256R1Z	SECP384R1Z	SECP521R1ZBrainpoolP256R1ZBrainpoolP384R1ZBrainpoolP512R1Zclassmethodr:   Zpropertyr@   r*   r!   r+   r,   r-   r-   <   sF    IIIOOO4 4 ( (r+   r-   c               r.   )r/   valueintr1   bytesr!   r2   r3   r,   r4   r4   T   s      S U r+   c                sn    \        V 4      pV^ ,          ^,          '       d
   RV,           p\        ^V4      # )r        )r   r   )rB   Zbs   & r,   	_int2asn1rG   T   s.    	5	B	!ut||r\tR=r+   c               s(    V ^8  d   QhRRRRRRRR/# )r/   r0   rD   dataivr1   r!   r2   r3   r,   r4   r4   [   s(     9 9e 95 9e 9U 9r+   c                s    \        \        P                  ! V 4      \        P                  ! V4      \        4       R 7      P                  4       pVP                  V4      VP                  4       ,           # ))Zbackend)	r   r   r&   r   ZCBCr   	encryptorZupdateZfinalize)r0   rH   rI   rJ      &&& r,   _encrypt_cbcrL   [   sV    s		"! ik	 
 D!I$6$6$888r+   c                  s    ] tR t^dtRtR R ltR R ltR"R R lltR R	 ltR
 R lt	R#R R llt
R R ltR R ltR R ltR R ltR R ltR R ltR$R R llt]P&                  ^ 3R R lltR%R R lltR tR!# )&SecurityDomainSessionzA session for managing SCP keysc               r;   )r/   
connectionr   r!   r2   r3   r,   r4   "SecurityDomainSession.__annotate__g   s     ; ;#6 ;r+   c                	s    \        V4      V n        V P                  P                  \        P                  4       V P                  P                  \        ^^^ 4      4       \        P                  R4       R# )i   z"SecurityDomain session initializedN)	r   protocolZselectr   ZSECURE_DOMAINZ	configurer   loggerdebug)r>   rN      &&r,   __init__ZSecurityDomainSession.__init__g   sN    )*5S../1a 019:r+   c               r.   )r/   
key_paramsr   r1   Noner!   r2   r3   r,   r4   rO   n   s     + +| + +r+   c                s<    V P                   P                  V4       R# )zInitialize SCP and authenticate the session.

SCP11b does not authenticate the OCE, and will not allow the usage of commands
which require authentication of the OCE.
N)rP   Zinit_scp)r>   rU   rS   r,   authenticateZ"SecurityDomainSession.authenticaten   s     	z*r+   c               s$    V ^8  d   QhRRRRRR/# )r/   tagrC   rH   rD   r1   r!   r2   r3   r,   r4   rO   v   s&     T TC Tu Tu Tr+   c                sd    V P                   P                  ^ \        V^,	          V^,          V4      # )z#Read data from the security domain.)rP   	send_apduINS_GET_DATA)r>   rX   rH      &&&r,   get_dataZSecurityDomainSession.get_datav   s'    }}&&q,q#*dSSr+   c               r;   )r/   r1   z"Mapping[KeyRef, Mapping[int, int]]r!   r2   r3   r,   r4   rO   z   s      %G r+   c                s   / p\         P                  ! V P                  \        4      4       FP  p\         P                  ! ^V4      p\        \        VR,          VR,          4      4      V\        VR,          4      &   KR  	  V# )z0Get information about the currently loaded keys.:r/   Nr/   :   Nr/   :Nr/   N)r   
parse_listr\   TAG_KEY_INFORMATIONunpackZdictZzipr   )r>   keysZdrH   s   &   r,   get_key_informationZ)SecurityDomainSession.get_key_informationz   se     .A BCA::dA&D%)#d4j$t**E%FDR!" D r+   c               r;   )r/   r1   rD   r!   r2   r3   r,   r4   rO      s     J J5 Jr+   c                sV    \         P                  ! ^sV P                  \        4      4      # )zGet information about the card.)r   r`   r\   TAG_CARD_RECOGNITION_DATAr=   r?   r,   get_card_recognition_dataZ/SecurityDomainSession.get_card_recognition_data   s     zz$.G HIIr+   c               s$    V ^8  d   QhRRRRRR/# )r/   klocboolklccr1   zMapping[KeyRef, bytes]r!   r2   r3   r,   r4   rO      s$     
 

(,
	
r+   c                s.   V'       g   V'       g   R;r\         P                  RV RV 24       RpV\        3V\        33 F'  w  rEV'       g   K   W0P	                  V4      ,          pK)  	  \        P                  ! V4      p\        ^ \        V4      ^4       Uu/ uF6  p\        Wx^,           ,          P                  4      Wx,          P                  bK8  	  up#   \
         d,   pTP                  \        P                  8w  d   h  Rp?K  Rp?ii ; iu upi )zGet a list of the CA issuer Subject Key Identifiers for keys.

Setting one of kloc or klcc to True will cause only those CAs to be returned.
By default, this will get both KLOC and KLCC CAs.

:param kloc: Get KLOC CAs.
:param klcc: Get KLCC CAs.
TzGetting CA identifiers KLOC=z, KLCC=r+   N)rQ   rR   TAG_CA_KLOC_IDENTIFIERSTAG_CA_KLCC_IDENTIFIERSr\   r   swr   REFERENCE_DATA_NOT_FOUNDr   r^   rangelenr   rB   )	r>   re   rg   rH   ZfetchrX   eZtlvsZis	   &&&      r,   get_supported_ca_identifiersZ2SecurityDomainSession.get_supported_ca_identifiers   s     DD3D6GH *+*+
JE uMM#..D
 ~~d#>CAs4yRS>T
>TF4A;$$%tw}}4>T
 	
	 ! ttr::: ;
s   C<DD$ D

Dc               r.   )r/   r0   r   r1   Sequence[x509.Certificate]r!   r2   r3   r,   r4   rO      s      & 5O r+   c                sv   \         P                  RV 24        \        P                  ! V P	                  \
        \        ^\        ^V4      4      4      4       Uu. uF  p\        P                  ! V4      NK  	  up# u upi   \         d-   pTP                  \        P                  8X  d   . u Rp?# h Rp?ii ; i)zhGet the certificates associated with the given SCP11 private key.

Certificates are returned leaf-last.
zGetting certificate bundle for N)rQ   rR   r   r^   r\   TAG_CERTIFICATE_STOREr   Zload_der_x509_certificater   rj   r   rk   )r>   r0   Zcertrn   r9   r,   get_certificate_bundleZ,SecurityDomainSession.get_certificate_bundle   s    
 	6se<=
	  NNMM"7T3tS>9RSD ..t4    	ttr222		s6   A B A<9B <B B8 B3,B82B33B8c               r;   )r/   r1   rV   r!   r2   r3   r,   r4   rO      s     $& $&t $&r+   c           	     s   \         P                  R4       RpV P                  4       P                  4        F  pVP                  ^8X  d   \        ^ ^ 4      p\        pMIVP                  R9   d   K:  VP                  R9   d   \        pMVP                  ^8X  d   \        pM\        p\        ^A4       F6  p V P                  P                  ^W2P                  VP                  V4       K8  	  K  	  \         P)                  R4       R#   \         dc   pTP                  \         P"                  \         P$                  39   d	    Rp? EK  TP                  \         P&                  8X  d    Rp?K  h Rp?ii ; i)zPerform a factory reset of the Security Domain.

This will remove all keys and associated data, as well as restore the default
SCP03 static keys, and generate a new (attestable) SCP11b key.
zResetting all SCP keysNzSCP keys resets           )r/   r]   )i   i   )rQ   rR   rb   ra   kidr   r   r   r   r   rl   rP   rY   kvnr   rj   r   ZAUTH_METHOD_BLOCKEDZ SECURITY_CONDITION_NOT_SATISFIEDZINCORRECT_PARAMETERSinfo)r>   rH   r0   ZinsZ_rn   s   &     r,   resetZSecurityDomainSession.reset   s    	-.++-224Cww$ Ql+L(L(/D/42Y
MM++D#wwN  56 	$% ! tt..;;   !8!88 s$   52DE3/E.E.-E..E3c               r.   )r/   rH   rD   r1   rV   r!   r2   r3   r,   r4   rO      s     B Bu B Br+   c                sL    V P                   P                  ^ \        ^^ V4       R# )z@Stores data in the security domain.

Requires OCE verification.
N)rP   rY   INS_STORE_DATA)r>   rH   rS   r,   
store_dataZ SecurityDomainSession.store_data   s    
 	>4DAr+   c               $    V ^8  d   QhRRRRRR/# )r/   r0   r   certificatesrp   r1   rV   r!   r2   r3   r,   r4   rO      s$     1 11)C1	1r+   c           
     s    \         P                  RV 24       V P                  \        ^\        ^V4      4      \        \        RP                  R V 4       4      4      ,           4       \         P                  R4       R# )zStore the certificate chain for the given key.

Requires OCE verification.

Certificates should be in order, with the leaf certificate last.
zStoring certificate bundle for r+   c              3  sr   "   T F-  qP                  \        P                  P                  4      x  K/  	  R # 5ir<   )public_bytesr	   EncodingZDER).0ZcrF   r,   	<genexpr>ZASecurityDomainSession.store_certificate_bundle.<locals>.<genexpr>   s)      HT1NN=#9#9#=#=>>s   57zCertificate bundle storedN)rQ   rR   rx   r   rq   joinru   )r>   r0   rz   r[   r,   store_certificate_bundleZ.SecurityDomainSession.store_certificate_bundle   sl     	6se<=c$n%% HT 	
 	/0r+   c               ry   )r/   r0   r   serialszSequence[int]r1   rV   r!   r2   r3   r,   r4   rO      s!     / /6 /M /d /r+   c           
     s    \         P                  RV 24       V P                  \        ^\        ^V4      4      \        ^pRP	                  R V 4       4      4      ,           4       \         P                  R4       R# )zStore which certificate serial numbers that can be used for a given key.

Requires OCE verification.

If no allowlist is stored, any certificate signed by the CA can be used.
zStoring serial allowlist for r+   c              3  s8   "   T F  p\        V4      x  K  	  R # 5ir<   )rG   )r}   srF   r,   r~   Z8SecurityDomainSession.store_allowlist.<locals>.<genexpr>  s      ?w!1ws   zSerial allowlist storedN)rQ   rR   rx   r   r   ru   )r>   r0   r   r[   r,   store_allowlistZ%SecurityDomainSession.store_allowlist   sb     	4SE:;c$n%$ ?w ??@A	
 	-.r+   c               ry   )r/   r0   r   skirD   r1   rV   r!   r2   r3   r,   r4   rO   	  s!     , ,6 , ,$ ,r+   c           
     s   \         P                  RV RVP                  4        24       VP                  \        P
                  \        P                  \        P                  39   pT P                  \        ^\        ^V'       d   RMR4      \        ^BV4      ,           \        ^V4      ,           4      4       \         P                  R4       R# )z^Store the SKI (Subject Key Identifier) for the CA of a given key.

Requires OCE verification.
zStoring CA issuer SKI for z: s   rE   zCA issuer SKI storedN)rQ   rR   Zhexrs   r   ZSCP11aZSCP11bZSCP11crx   r   ru   )r>   r0   r   rg   rK   r,   store_ca_issuerZ%SecurityDomainSession.store_ca_issuer	  s    
 	1#bDEww6==&--GGD4%U3c$nDs4QT~U	
 	*+r+   c               s(    V ^8  d   QhRRRRRRRR/# )r/   rs   rC   rt   delete_lastrf   r1   rV   r!   r2   r3   r,   r4   rO     s)     $ $c $C $$ $SW $r+   c                s   V'       g   V'       g   \        R4      hVR	9   d   V'       d   ^ pM\        R4      h\        P                  RT;'       g    R RT;'       g    R 24       RpV'       d   V\        ^\	        V.4      4      ,          pV'       d   V\        ^\	        V.4      4      ,          pV P
                  P                  ^\        ^ \        V4      V4       \        P                  R4       R# )
zDelete one (or more) keys.

Requires OCE verification.

All keys matching the given KID and/or KVN will be deleted.
To delete the final key you must set delete_last = True.
z&Must specify at least one of kid, kvn.z%SCP03 keys can only be deleted by KVNzDeleting keys with KID=ZANYz, KVN=r+   zKeys deletedN)i   r/   r]   )
r8   rQ   rR   r   rD   rP   rY   
INS_DELETErC   ru   )r>   rs   rt   r   rH   s   &&&& r,   
delete_keyZ SecurityDomainSession.delete_key  s     3EFF) !HII.s||enF3<<%.QRCeSEl++DCeSEl++Dj!S5EtLN#r+   c               (    V ^8  d   QhRRRRRRRR/# )	r/   r0   r   r6   r-   replace_kvnrC   r1   zec.EllipticCurvePublicKeyr!   r2   r3   r,   r4   rO   2  s2     Y YY"'YHKY	"Yr+   c                s   \         P                  RV 2V'       d   RV 2MR,           4       \        VP                  .4      \	        \
        P                  \        V.4      4      ,           pV P                  P                  ^\        W1P                  V4      p\        P                  ! \
        P                  V4      p\         P                  R4       \        P                  P!                  VP"                  V4      # )zcGenerate a new SCP11 key.

Requires OCE verification.

Use replace_kvn to replace an existing key.
zGenerating new key for z, replacing KVN=Z zNew key generated)rQ   rR   rD   rt   r   r    r)   rP   rY   INS_GENERATE_KEYrs   r`   r'   ru   r
   EllipticCurvePublicKeyZfrom_encoded_pointr@   )r>   r0   r6   r   rH   respZencoded_points   &&&&   r,   generate_ec_keyZ%SecurityDomainSession.generate_ec_key2  s     	%cU+3>!+/BH	
 cggY#g&<&<eUGn"MM}}&&"K$
 

7#9#94@'(((;;ELL-XXr+   c               r   )	r/   r0   r   skzCStaticKeys | ec.EllipticCurvePrivateKey | ec.EllipticCurvePublicKeyr   rC   r1   rV   r!   r2   r3   r,   r4   rO   G  s3     6$ 6$6$ P6$ 	6$
 
6$r+   c           	     sj   \         P                  RV R\        V4       24       V P                  P                  p\        V\        4      '       g   \        R4      h\        VP                  .4      pTpVP                  P                  P                  pVP                  p\        V\        4      '       d   V'       g   \        R4      hVP                  '       g   \        R4      hV^,          p\        \         \        ,          V4       Fm  p	\#        V	\$        4      R,          p
V\'        \(        P*                  \#        Wy4      4      \        \-        V
4      .4      ,           V
,           ,          pWj,          pKo  	  EMn\        V\.        P0                  4      '       d}   V'       g   \        R4      hVP2                  ^,           ^,          p\5        VP7                  4       P8                  V4      pV\'        \(        P:                  \#        W|4      4      ,          pM\        V\.        P<                  4      '       dc   V\'        \(        P>                  VPA                  \B        PD                  PF                  \B        PH                  PJ                  4      4      ,          pM\M        R4      hV\'        \(        PN                  \        \P        PS                  V4      .4      4      R,           ,          pV P                  PU                  ^\V        W8V4      pW8w  d   \Y        R	4      h\         P[                  R
4       R# )zImport an SCP key.

Requires OCE verification.

The value of the sk argument should match the SCP type as defined by the KID.
Use replace_kvn to replace an existing key.
zImporting key into z	 of type zMust be authenticated!zNo session DEK key availablez"New DEK must be set in static keys:Nr]   NzUnsupported key typerE   zIncorrect key check valuezKey importedN).rQ   rR   ZtyperP   Z
_processorZ
isinstancer   r8   rD   rt   ZstateZ_keysZkey_dekrs   r   r   r   rL   _DEFAULT_KCV_IVr   r    r&   rm   r
   ZEllipticCurvePrivateKeyZkey_sizer   Zprivate_numbersZprivate_valuer(   r   r'   r{   r	   r|   ZX962ZPublicFormatZUncompressedPointZ	TypeErrorr)   r-   r:   rY   INS_PUT_KEYr   ru   )r>   r0   r   r   Z	processorrH   ZexpectedZdekZp2ZkZkcvZnr   r   s   &&&&          r,   put_keyZSecurityDomainSession.put_keyG  sL    	*3%yb
CDMM,,	)\22566cggYoo##++WWb*%% !?@@::: !EFF$JB(5/2."1o6r:GKKc)=>CzARRUXXX /
 "b8899$%CDD[[1_*b002@@!DG33\#5IJJB 9 9::**OO%..33%22DD    677C..ur7J6K0LMPUUUD}}&&t[+4P"#>??N#r+   )rP   N)r+   )FF)r    r    F)r    )r"   r#   r$   r%   Z__doc__rT   rW   r\   rb   rd   ro   rr   rv   rx   r   r   r   r   r-   rA   r   r   r*   r!   r+   r,   rM   rM   d   se    );+TJ

>$$&LB1*/,$6 +0//aY*6$ 6$r+   rM   s   )s                   )>Z
__future__r   ZloggingZenumr   r   Ztypingr   r   r   Zcryptographyr   Zcryptography.hazmat.backendsr   Zcryptography.hazmat.primitivesr	   Z)cryptography.hazmat.primitives.asymmetricr
   Z&cryptography.hazmat.primitives.ciphersr   r   r   Zcorer   r   r   r   Zcore.smartcardr   r   r   r   r   r   Zcore.smartcard.scpr   r   r   r   r   r   r   r   Z	getLoggerr"   rQ   rZ   r   rw   r   r   r_   rc   rh   ri   rq   r    r   r-   rG   rL   rM   r!   r+   r,   <module>r      s    "    * *  8 8 8 L L ; ; 	 	 	 
		8	$ 
          g    (G ( (.9Y$ Y$r+   