HEX
Server: nginx/1.30.4
System: Linux d-twindigital-web-1.host-ed.eu 4.18.0-553.141.2.el8_10.x86_64 #1 SMP Wed Jul 8 10:28:18 EDT 2026 x86_64
User: u_twindigital_html (1009)
PHP: 8.3.30
Disabled: NONE
Upload Files
File: //lib/python3.6/site-packages/certbot/__pycache__/ocsp.cpython-36.opt-1.pyc
3

ߦ)_�:�@srdZddlmZddlmZddlZddlZddlmZddlmZddlm	Z	ddl
mZdd	l
mZdd
l
mZddlmZddlmZddlZddlZdd
lmZddlmZddlmZddlmZddlmZddlmZddlmZyddlm Z e!e j"d�Wne#e$fk
�r*dZ YnXej%e&�Z'Gdd�de(�Z)dd�Z*dd�Z+dd�Z,dd�Z-d d!�Z.dS)"z*Tools for checking certificate revocation.�)�datetime)�	timedeltaN)�PIPE)�Popen)�x509)�InvalidSignature)�UnsupportedAlgorithm)�default_backend)�hashes)�
serialization)�Optional)�Tuple)�crypto_util)�errors)�util)�getenv)�
RenewableCert)�ocsp�signature_hash_algorithmc@s4eZdZdZd
dd�Zdd�Zddd	�Zd
d�ZdS)�RevocationCheckerzEThis class figures out OCSP checking on this system, and performs it.FcCs�d|_|pt|_|jr�tjd�s6tjd�d|_dStdddddgttdtj	�d	�}|j
�\}}d
|krvdd�|_n
d
d�|_dS)NF�opensslz-openssl not installed, can't check revocationTrz-header�var�val)�stdout�stderrZuniversal_newlines�envz	Missing =cSs
d|gS)NzHost=�)�hostrr�/usr/lib/python3.6/ocsp.py�<lambda>:sz,RevocationChecker.__init__.<locals>.<lambda>cSsd|gS)NZHostr)rrrrr<s)�brokenr�use_openssl_binaryrZ
exe_exists�logger�inforrZenv_no_snap_for_external_callsZcommunicate�	host_args)�selfZenforce_openssl_binary_usageZtest_host_formatZ_out�errrrr�__init__*s

zRevocationChecker.__init__cCs|j|j|j�S)a Get revoked status for a particular cert version.

        .. todo:: Make this a non-blocking call

        :param `.interfaces.RenewableCert` cert: Certificate object
        :returns: True if revoked; False if valid or the check failed or cert is expired.
        :rtype: bool

        )�ocsp_revoked_by_paths�	cert_path�
chain_path)r%�certrrr�ocsp_revoked>szRevocationChecker.ocsp_revoked�
cCsn|jr
dStjjtj��}tj|�|kr,dSt|�\}}|sD|rHdS|j	r`|j
|||||�St||||�S)aEPerforms the OCSP revocation check

        :param str cert_path: Certificate filepath
        :param str chain_path: Certificate chain
        :param int timeout: Timeout (in seconds) for the OCSP query

        :returns: True if revoked; False if valid or the check failed or cert is expired.
        :rtype: bool

        F)r �pytzZUTCZfromutcr�utcnowrZnotAfter�_determine_ocsp_serverr!�_check_ocsp_openssl_bin�_check_ocsp_cryptography)r%r)r*�timeout�now�urlrrrrr(Ksz'RevocationChecker.ocsp_revoked_by_pathsc
Cstd�}td�}d}|dk	s$|dk	r4|dk	r0|n|}|dkrFd|g}	n&|jd�r`|td�d�}d|d|g}	ddd	d
|d|d|d
|ddt|�dg|j|�|	}
tjd|�tjdj|
��ytj	|
tjd�\}}Wn"t
jk
r�tjd|�dSXt
|||�S)NZ
http_proxyZ
HTTP_PROXYz-urlzhttp://z-hostz-pathrrz	-no_noncez-issuerz-certz-CAfilez
-verify_otherz-trust_otherz-timeoutz-headerzQuerying OCSP for %s� )�logz*OCSP check failed for %s (are we offline?)F)r�
startswith�len�strr$r"�debug�joinrZ
run_scriptrZSubprocessErrorr#�_translate_ocsp_query)
r%r)r*rr5r3Zenv_http_proxyZenv_HTTP_PROXYZ
proxy_hostZurl_opts�cmd�outputr&rrrr1is&


4z)RevocationChecker._check_ocsp_openssl_binN)F)r-)�__name__�
__module__�__qualname__�__doc__r'r,r(r1rrrrr's


rcs�t|d��}tj|j�t��}WdQRXy:|jjtj�}tjj	��fdd�|j
D�}|djj
}Wn&tjt
fk
r�tjd|�dSX|j�}|jd�djd	�}|r�||fStjd
||�dS)
z�Extract the OCSP server host from a certificate.

    :param str cert_path: Path to the cert we're checking OCSP for
    :rtype tuple:
    :returns: (OCSP server URL or None, OCSP server host or None)

    �rbNcsg|]}|j�kr|�qSr)Z
access_method)�.0�description)�ocsp_oidrr�
<listcomp>�sz*_determine_ocsp_server.<locals>.<listcomp>rzCannot extract OCSP URI from %sz://��/z4Cannot process OCSP host from URL (%s) in cert at %s)NN)NN)�openr�load_pem_x509_certificate�readr	�
extensions�get_extension_for_classZAuthorityInformationAccessZAuthorityInformationAccessOIDZOCSP�valueZaccess_location�ExtensionNotFound�
IndexErrorr"r#�rstrip�	partition)r)�file_handlerr+�	extensionZdescriptionsr5rr)rGrr0�s 	r0c'Cst|d��}tj|j�t��}WdQRXt|d��}tj|j�t��}WdQRXtj�}|j||tj	��}|j
�}|jtj
j�}	ytj||	ddi|d�}
Wn(tjjk
r�tjd|dd�dSX|
jd	kr�tjd
||
j�dStj|
j�}|jtjjk�rtjd||j�dSyt||||�Wn�tk
�rV}ztjt|��WYdd}~Xn�tj k
�r�}ztjt|��WYdd}~Xntt!k
�r�tjd|�YnTt"k
�r�}
ztjd
|t|
��WYdd}
~
Xn Xtj#d||j$�|j$tj%j&kSdS)NrDzContent-Typezapplication/ocsp-request)�dataZheadersr3z*OCSP check failed for %s (are we offline?)T)�exc_infoF��z*OCSP check failed for %s (HTTP status: %d)z'Invalid OCSP response status for %s: %sz)Invalid signature on OCSP response for %sz!Invalid OCSP response for %s: %s.z%OCSP certificate status for %s is: %s)'rKrrLrMr	rZOCSPRequestBuilderZadd_certificater
ZSHA1ZbuildZpublic_bytesrZEncodingZDER�requestsZpost�
exceptionsZRequestExceptionr"r#Zstatus_codeZload_der_ocsp_responseZcontentZresponse_statusZOCSPResponseStatusZ
SUCCESSFUL�error�_check_ocsp_responserr:r�Errorr�AssertionErrorr;Zcertificate_statusZOCSPCertStatusZREVOKED)r)r*r5r3rU�issuerr+ZbuilderZrequestZrequest_binaryZresponse�
response_ocsp�er\rrrr2�sJ

$
r2cCs�|j|jkrtd��t|||�t|jt|j��sL|j|jksL|j|jkrTtd��tj	�}|j
sjtd��|j
|tdd�kr�td��|jr�|j|tdd�kr�td��dS)	z3Verify that the OCSP is valid for serveral criteriazMthe certificate in response does not correspond to the certificate in requestz<the issuer does not correspond to issuer of the certificate.zparam thisUpdate is not set.�)Zminutesz"param thisUpdate is in the future.z param nextUpdate is in the past.N)
Z
serial_numberr_�_check_ocsp_response_signature�
isinstanceZhash_algorithm�typeZissuer_key_hashZissuer_name_hashrr/Zthis_updaterZnext_update)raZrequest_ocsp�issuer_certr)r4rrrr]�sr]c
sdd���j|jks"�j�|�kr4tjd|�|}n�tjd|���fdd��jD�}|sbtd��|d}|j|jkr~td	��y"|jj	t
j�}t
jj
j|jk}Wnt
jtfk
r�d
}YnX|s�td��|j}tj|j�|j|j|��j}tj|j��j�j|�dS)
zIVerify an OCSP response signature against certificate issuer or respondercSstjj|j��jS)N)rZSubjectKeyIdentifierZfrom_public_key�
public_keyZdigest)r+rrr�	_key_hashsz1_check_ocsp_response_signature.<locals>._key_hashzGOCSP response for certificate %s is signed by the certificate's issuer.zGOCSP response for certificate %s is delegated to an external responder.cs*g|]"}�j|jks"�j�|�kr|�qSr)�responder_name�subject�responder_key_hash)rEr+)rirarrrHsz2_check_ocsp_response_signature.<locals>.<listcomp>z0no matching responder certificate could be foundrz?responder certificate is not signed by the certificate's issuerFz<responder is not authorized by issuer to sign OCSP responsesN)rjrkrlr"r;Zcertificatesr_r`rNrOrZExtendedKeyUsageZoidZExtendedKeyUsageOIDZOCSP_SIGNINGrPrQrRrrZverify_signed_payloadrhZ	signatureZtbs_certificate_bytesZtbs_response_bytes)rargr)Zresponder_certZresponder_certsrVZdelegate_authorizedZchosen_hashr)rirarrds6

rdc	s�d}�fdd�|D�}�fdd�|D�\}}}|r<|jd�nd	}d
|ksT|rP|sT|rrtjd��tjd�|�d
S|r�|r�d
S|r�|jd�}|r�tjd|�dStjd�|�d
Sd	S)z7Parse openssl's weird output to work out what it means.�good�revoked�unknowncsg|]}dj�|��qS)z{0}: (WARNING.*)?{1})�format)rE�s)r)rrrH<sz)_translate_ocsp_query.<locals>.<listcomp>c3s |]}tj|�tjd�VqdS))�flagsN)�re�search�DOTALL)rE�p)�ocsp_outputrr�	<genexpr>=sz(_translate_ocsp_query.<locals>.<genexpr>�NzResponse verify OKz#Revocation status for %s is unknownzUncertain output:
%s
stderr:
%sFzOCSP revocation warning: %sTz2Unable to properly parse OCSP output: %s
stderr:%s)rmrnro)�groupr"r#r;�warning)	r)rwZocsp_errorsZstatesZpatternsrmrnror{r)r)rwrr=8s$

r=)/rCrrZloggingrs�
subprocessrrZcryptographyrZcryptography.exceptionsrrZcryptography.hazmat.backendsr	Zcryptography.hazmat.primitivesr
rr.rZZacme.magic_typingrr
ZcertbotrrrZcertbot.compat.osrZcertbot.interfacesrZcryptography.x509r�getattrZOCSPResponse�ImportError�AttributeErrorZ	getLoggerr@r"�objectrr0r2r]rdr=rrrr�<module>sB

h2"6