§
    pïg–„  ã            	       óþ  — d dl Z d dlZd dlZd dlZd dlmZ d dlmZ d dl	m
Z
mZ d dlmZmZmZmZmZmZmZ d dlmZmZmZ d dlmZmZmZmZ d dlmZmZ d d	l m!Z!  ej        d
dd¦  «        Z" G d„ de#¦  «        Z$dee         dej%        ee                  ddfd„Z&de!dej%        ej'        e!e(ej)        e*         f                  ddfd„Z+dej        dej        fd„Z, G d„ d¦  «        Z- G d„ d¦  «        Z. G d„ dej/        ¦  «        Z0 G d„ de#¦  «        Z1 G d„ d e j2        ¬!¦  «        Z3e3 4                    ej3        ¦  «          G d"„ d#e j2        ¬!¦  «        Z5e5 4                    ej5        ¦  «          G d$„ d%e5¦  «        Z6 G d&„ d'e j2        ¬!¦  «        Z7e7 4                    ej7        ¦  «          G d(„ d)e j2        ¬!¦  «        Z8e8 4                    ej8        ¦  «         	 d;d*e(d+ej9        de3fd,„Z:	 d;d*e(d+ej9        de3fd-„Z;	 d;d*e(d+ej9        de8fd.„Z<	 d;d*e(d+ej9        de8fd/„Z=	 d;d*e(d+ej9        de7fd0„Z>	 d;d*e(d+ej9        de7fd1„Z? G d2„ d3¦  «        Z@ G d4„ d5¦  «        ZA G d6„ d7¦  «        ZB G d8„ d9¦  «        ZCde*fd:„ZDdS )<é    N)Úutils)Úx509)ÚhashesÚserialization)ÚdsaÚecÚed25519Úed448ÚrsaÚx25519Úx448)Ú#CERTIFICATE_ISSUER_PUBLIC_KEY_TYPESÚCERTIFICATE_PRIVATE_KEY_TYPESÚCERTIFICATE_PUBLIC_KEY_TYPES)Ú	ExtensionÚExtensionTypeÚ
ExtensionsÚ_make_sequence_methods)ÚNameÚ	_ASN1Type)ÚObjectIdentifieriž  é   c                   ó,   ‡ — e Zd Zdededdfˆ fd„Zˆ xZS )ÚAttributeNotFoundÚmsgÚoidÚreturnNc                 óf   •— t          t          | ¦  «                             |¦  «         || _        d S ©N)Úsuperr   Ú__init__r   )Úselfr   r   Ú	__class__s      €ú8/usr/lib/python3/dist-packages/cryptography/x509/base.pyr!   zAttributeNotFound.__init__*   s-   ø€ ÝÕ Ñ&Ô&×/Ò/°Ñ4Ô4Ð4ØˆŒˆˆó    )Ú__name__Ú
__module__Ú__qualname__Ústrr   r!   Ú__classcell__©r#   s   @r$   r   r   )   sS   ø€ € € € € ð˜Cð Ð&6ð ¸4ð ð ð ð ð ð ð ð ð ð r%   r   Ú	extensionÚ
extensionsr   c                 óN   — |D ]!}|j         | j         k    rt          d¦  «        ‚Œ"d S )Nz$This extension has already been set.)r   Ú
ValueError)r,   r-   Úes      r$   Ú_reject_duplicate_extensionr1   /   sD   € ð
 ð Eð EˆØŒ5�I”MÒ!Ð!ÝÐCÑDÔDÐDð "ðEð Er%   r   Ú
attributesc                 óB   — |D ]\  }}}|| k    rt          d¦  «        ‚Œd S )Nz$This attribute has already been set.)r/   )r   r2   Úattr_oidÚ_s       r$   Ú_reject_duplicate_attributer6   9   sD   € ð %ð Eð E‰ˆ�!�QØ�sŠ?ˆ?ÝÐCÑDÔDÐDð ðEð Er%   Útimec                 óœ   — | j         �D|                      ¦   «         }|r|nt          j        ¦   «         }|                      d¬¦  «        |z
  S | S )z’Normalizes a datetime to a naive datetime in UTC.

    time -- datetime to normalize. Assumed to be in UTC if not timezone
            aware.
    N)Útzinfo)r9   Ú	utcoffsetÚdatetimeÚ	timedeltaÚreplace)r7   Úoffsets     r$   Ú_convert_to_naive_utc_timer?   E   sP   € ð „{ÐØ—’Ñ!Ô!ˆØ!Ð;��¥xÔ'9Ñ';Ô';ˆØ�|Š| 4ˆ|Ñ(Ô(¨6Ñ1Ð1àˆr%   c            	       óž   — e Zd Zej        j        fdedededdfd„Z	e
defd„¦   «         Ze
defd„¦   «         Zdefd	„Zd
edefd„Zdefd„ZdS )Ú	Attributer   ÚvalueÚ_typer   Nc                 ó0   — || _         || _        || _        d S r   )Ú_oidÚ_valuerC   )r"   r   rB   rC   s       r$   r!   zAttribute.__init__T   s   € ð ˆŒ	ØˆŒØˆŒ
ˆ
ˆ
r%   c                 ó   — | j         S r   )rE   ©r"   s    r$   r   zAttribute.oid^   s
   € àŒyÐr%   c                 ó   — | j         S r   )rF   rH   s    r$   rB   zAttribute.valueb   s
   € àŒ{Ðr%   c                 óB   — d                      | j        | j        ¦  «        S )Nz<Attribute(oid={}, value={!r})>)Úformatr   rB   rH   s    r$   Ú__repr__zAttribute.__repr__f   s   € Ø0×7Ò7¸¼À$Ä*ÑMÔMÐMr%   Úotherc                 óš   — t          |t          ¦  «        st          S | j        |j        k    o| j        |j        k    o| j        |j        k    S r   )Ú
isinstancerA   ÚNotImplementedr   rB   rC   ©r"   rM   s     r$   Ú__eq__zAttribute.__eq__i   sO   € Ý˜%¥Ñ+Ô+ð 	"Ý!Ð!ð ŒH˜œ	Ò!ð *Ø”
˜eœkÒ)ð*à”
˜eœkÒ)ð	
r%   c                 óD   — t          | j        | j        | j        f¦  «        S r   )Úhashr   rB   rC   rH   s    r$   Ú__hash__zAttribute.__hash__s   s   € Ý�T”X˜tœz¨4¬:Ð6Ñ7Ô7Ð7r%   )r&   r'   r(   r   Ú
UTF8StringrB   r   ÚbytesÚintr!   Úpropertyr   r)   rL   ÚobjectÚboolrR   rU   © r%   r$   rA   rA   S   s
  € € € € € ð
 Ô)Ô/ð	ð àðð ðð ð	ð
 
ðð ð ð ð ðÐ%ð ð ð ñ „Xðð ð�uð ð ð ñ „XððN˜#ð Nð Nð Nð Nð
˜Fð 
 tð 
ð 
ð 
ð 
ð8˜#ð 8ð 8ð 8ð 8ð 8ð 8r%   rA   c                   ón   — e Zd Zdej        e         ddfd„Z ed¦  «        \  ZZ	Z
defd„Zdedefd„ZdS )	Ú
Attributesr2   r   Nc                 ó.   — t          |¦  «        | _        d S r   )ÚlistÚ_attributes)r"   r2   s     r$   r!   zAttributes.__init__x   s   € õ   
Ñ+Ô+ˆÔÐÐr%   ra   c                 ó6   — d                      | j        ¦  «        S )Nz<Attributes({})>)rK   ra   rH   s    r$   rL   zAttributes.__repr__€   s   € Ø!×(Ò(¨Ô)9Ñ:Ô:Ð:r%   r   c                 óp   — | D ]}|j         |k    r|c S Œt          d                     |¦  «        |¦  «        ‚)NzNo {} attribute was found)r   r   rK   )r"   r   Úattrs      r$   Úget_attribute_for_oidz Attributes.get_attribute_for_oidƒ   sK   € Øð 	ð 	ˆDØŒx˜3ŠˆØ���ð õ  Ð ;× BÒ BÀ3Ñ GÔ GÈÑMÔMÐMr%   )r&   r'   r(   ÚtypingÚIterablerA   r!   r   Ú__len__Ú__iter__Ú__getitem__r)   rL   r   re   r\   r%   r$   r^   r^   w   s    € € € € € ð,à”O IÔ.ð,ð 
ð,ð ,ð ,ð ,ð &<Ð%;¸MÑ%JÔ%JÑ"€GˆX�{ð;˜#ð ;ð ;ð ;ð ;ðNÐ)9ð N¸ið Nð Nð Nð Nð Nð Nr%   r^   c                   ó   — e Zd ZdZdZdS )ÚVersionr   é   N)r&   r'   r(   Úv1Úv3r\   r%   r$   rl   rl   ‹   s   € € € € € Ø	
€BØ	
€B€B€Br%   rl   c                   ó,   ‡ — e Zd Zdededdfˆ fd„Zˆ xZS )ÚInvalidVersionr   Úparsed_versionr   Nc                 óf   •— t          t          | ¦  «                             |¦  «         || _        d S r   )r    rq   r!   rr   )r"   r   rr   r#   s      €r$   r!   zInvalidVersion.__init__‘   s/   ø€ Ý�n˜dÑ#Ô#×,Ò,¨SÑ1Ô1Ð1Ø,ˆÔÐÐr%   )r&   r'   r(   r)   rX   r!   r*   r+   s   @r$   rq   rq   �   sR   ø€ € € € € ð-˜Cð -°ð -¸ð -ð -ð -ð -ð -ð -ð -ð -ð -ð -r%   rq   c                   óè  — e Zd Zej        dej        defd„¦   «         Zej	        de
fd„¦   «         Zej	        defd„¦   «         Zej        defd„¦   «         Zej	        dej        fd„¦   «         Zej	        dej        fd„¦   «         Zej	        defd	„¦   «         Zej	        defd
„¦   «         Zej	        dej        ej                 fd„¦   «         Zej	        defd„¦   «         Zej	        defd„¦   «         Zej	        defd„¦   «         Zej	        defd„¦   «         Zej	        defd„¦   «         Zej        de de!fd„¦   «         Z"ej        de
fd„¦   «         Z#ej        de$j%        defd„¦   «         Z&dS )ÚCertificateÚ	algorithmr   c                 ó   — dS ©z4
        Returns bytes using digest passed.
        Nr\   ©r"   rv   s     r$   ÚfingerprintzCertificate.fingerprint—   ó   € € € r%   c                 ó   — dS )z3
        Returns certificate serial number
        Nr\   rH   s    r$   Úserial_numberzCertificate.serial_number�   r{   r%   c                 ó   — dS )z1
        Returns the certificate version
        Nr\   rH   s    r$   ÚversionzCertificate.version£   r{   r%   c                 ó   — dS ©z(
        Returns the public key
        Nr\   rH   s    r$   Ú
public_keyzCertificate.public_key©   r{   r%   c                 ó   — dS )z?
        Not before time (represented as UTC datetime)
        Nr\   rH   s    r$   Únot_valid_beforezCertificate.not_valid_before¯   r{   r%   c                 ó   — dS )z>
        Not after time (represented as UTC datetime)
        Nr\   rH   s    r$   Únot_valid_afterzCertificate.not_valid_afterµ   r{   r%   c                 ó   — dS )z1
        Returns the issuer name object.
        Nr\   rH   s    r$   ÚissuerzCertificate.issuer»   r{   r%   c                 ó   — dS ©z2
        Returns the subject name object.
        Nr\   rH   s    r$   ÚsubjectzCertificate.subjectÁ   r{   r%   c                 ó   — dS ©zt
        Returns a HashAlgorithm corresponding to the type of the digest signed
        in the certificate.
        Nr\   rH   s    r$   Úsignature_hash_algorithmz$Certificate.signature_hash_algorithmÇ   r{   r%   c                 ó   — dS ©zJ
        Returns the ObjectIdentifier of the signature algorithm.
        Nr\   rH   s    r$   Úsignature_algorithm_oidz#Certificate.signature_algorithm_oidÐ   r{   r%   c                 ó   — dS )z/
        Returns an Extensions object.
        Nr\   rH   s    r$   r-   zCertificate.extensionsÖ   r{   r%   c                 ó   — dS ©z.
        Returns the signature bytes.
        Nr\   rH   s    r$   Ú	signaturezCertificate.signatureÜ   r{   r%   c                 ó   — dS )zR
        Returns the tbsCertificate payload bytes as defined in RFC 5280.
        Nr\   rH   s    r$   Útbs_certificate_bytesz!Certificate.tbs_certificate_bytesâ   r{   r%   c                 ó   — dS )zh
        Returns the tbsCertificate payload bytes with the SCT list extension
        stripped.
        Nr\   rH   s    r$   Útbs_precertificate_bytesz$Certificate.tbs_precertificate_bytesè   r{   r%   rM   c                 ó   — dS ©z"
        Checks equality.
        Nr\   rQ   s     r$   rR   zCertificate.__eq__ï   r{   r%   c                 ó   — dS ©z"
        Computes a hash.
        Nr\   rH   s    r$   rU   zCertificate.__hash__õ   r{   r%   Úencodingc                 ó   — dS )zB
        Serializes the certificate to PEM or DER format.
        Nr\   ©r"   rž   s     r$   Úpublic_byteszCertificate.public_bytesû   r{   r%   N)'r&   r'   r(   ÚabcÚabstractmethodr   ÚHashAlgorithmrW   rz   ÚabstractpropertyrX   r}   rl   r   r   r‚   r;   r„   r†   r   rˆ   r‹   rf   ÚOptionalrŽ   r   r‘   r   r-   r•   r—   r™   rZ   r[   rR   rU   r   ÚEncodingr¡   r\   r%   r$   ru   ru   –   s  € € € € € ØÔð VÔ%9ð ¸eð ð ð ñ Ôðð
 	Ôð˜sð ð ð ñ Ôðð
 	Ôð˜ð ð ð ñ Ôðð
 	ÔðÐ8ð ð ð ñ Ôðð
 	Ôð (Ô"3ð ð ð ñ Ôðð
 	Ôð Ô!2ð ð ð ñ Ôðð
 	Ôð˜ð ð ð ñ Ôðð
 	Ôð˜ð ð ð ñ Ôðð
 	Ôðà	Œ˜Ô-Ô	.ðð ð ñ Ôðð 	ÔðÐ)9ð ð ð ñ Ôðð
 	Ôð˜Jð ð ð ñ Ôðð
 	Ôð˜5ð ð ð ñ Ôðð
 	Ôð uð ð ð ñ Ôðð
 	Ôð¨%ð ð ð ñ Ôðð 	Ôð˜Fð  tð ð ð ñ Ôðð
 	Ôð˜#ð ð ð ñ Ôðð
 	Ôð ]Ô%;ð Àð ð ð ñ Ôðð ð r%   ru   )Ú	metaclassc                   óŠ   — e Zd Zej        defd„¦   «         Zej        dej        fd„¦   «         Zej        de	fd„¦   «         Z
dS )ÚRevokedCertificater   c                 ó   — dS )zG
        Returns the serial number of the revoked certificate.
        Nr\   rH   s    r$   r}   z RevokedCertificate.serial_number  r{   r%   c                 ó   — dS )zH
        Returns the date of when this certificate was revoked.
        Nr\   rH   s    r$   Úrevocation_datez"RevokedCertificate.revocation_date  r{   r%   c                 ó   — dS )zW
        Returns an Extensions object containing a list of Revoked extensions.
        Nr\   rH   s    r$   r-   zRevokedCertificate.extensions  r{   r%   N)r&   r'   r(   r¢   r¥   rX   r}   r;   r­   r   r-   r\   r%   r$   rª   rª     s–   € € € € € ØÔð˜sð ð ð ñ Ôðð
 	Ôð Ô!2ð ð ð ñ Ôðð
 	Ôð˜Jð ð ð ñ Ôðð ð r%   rª   c                   óŠ   — e Zd Zdedej        defd„Zedefd„¦   «         Zedej        fd„¦   «         Z	edefd„¦   «         Z
d	S )
Ú_RawRevokedCertificater}   r­   r-   c                 ó0   — || _         || _        || _        d S r   ©Ú_serial_numberÚ_revocation_dateÚ_extensions©r"   r}   r­   r-   s       r$   r!   z_RawRevokedCertificate.__init__  ó"   € ð ,ˆÔØ /ˆÔØ%ˆÔÐÐr%   r   c                 ó   — | j         S r   )r³   rH   s    r$   r}   z$_RawRevokedCertificate.serial_number)  s   € àÔ"Ð"r%   c                 ó   — | j         S r   )r´   rH   s    r$   r­   z&_RawRevokedCertificate.revocation_date-  s   € àÔ$Ð$r%   c                 ó   — | j         S r   )rµ   rH   s    r$   r-   z!_RawRevokedCertificate.extensions1  s   € àÔÐr%   N)r&   r'   r(   rX   r;   r   r!   rY   r}   r­   r-   r\   r%   r$   r°   r°     s¿   € € € € € ð&àð&ð "Ô*ð&ð ð	&ð &ð &ð &ð ð#˜sð #ð #ð #ñ „Xð#ð ð% Ô!2ð %ð %ð %ñ „Xð%ð ð ˜Jð  ð  ð  ñ „Xð ð  ð  r%   r°   c                   óÄ  — e Zd Zej        dej        defd„¦   «         Zej        de	j
        defd„¦   «         Zej        dedej        e         fd„¦   «         Zej        dej        e	j
                 fd„¦   «         Zej        defd	„¦   «         Zej        defd
„¦   «         Zej        dej        ej                 fd„¦   «         Zej        dej        fd„¦   «         Zej        defd„¦   «         Zej        defd„¦   «         Zej        defd„¦   «         Zej        dedefd„¦   «         Z ej        defd„¦   «         Z!ej"        dedefd„¦   «         Z#ej"        de$dej%        e         fd„¦   «         Z#ej        dej&        ee$f         dej&        eej%        e         f         fd„¦   «         Z#ej        dej'        e         fd„¦   «         Z(ej        de)defd„¦   «         Z*dS )ÚCertificateRevocationListrž   r   c                 ó   — dS )z:
        Serializes the CRL to PEM or DER format.
        Nr\   r    s     r$   r¡   z&CertificateRevocationList.public_bytes7  r{   r%   rv   c                 ó   — dS rx   r\   ry   s     r$   rz   z%CertificateRevocationList.fingerprint=  r{   r%   r}   c                 ó   — dS )zs
        Returns an instance of RevokedCertificate or None if the serial_number
        is not in the CRL.
        Nr\   )r"   r}   s     r$   Ú(get_revoked_certificate_by_serial_numberzBCertificateRevocationList.get_revoked_certificate_by_serial_numberC  r{   r%   c                 ó   — dS r�   r\   rH   s    r$   rŽ   z2CertificateRevocationList.signature_hash_algorithmL  r{   r%   c                 ó   — dS r�   r\   rH   s    r$   r‘   z1CertificateRevocationList.signature_algorithm_oidU  r{   r%   c                 ó   — dS )zC
        Returns the X509Name with the issuer of this CRL.
        Nr\   rH   s    r$   rˆ   z CertificateRevocationList.issuer[  r{   r%   c                 ó   — dS )z?
        Returns the date of next update for this CRL.
        Nr\   rH   s    r$   Únext_updatez%CertificateRevocationList.next_updatea  r{   r%   c                 ó   — dS )z?
        Returns the date of last update for this CRL.
        Nr\   rH   s    r$   Úlast_updatez%CertificateRevocationList.last_updateg  r{   r%   c                 ó   — dS )zS
        Returns an Extensions object containing a list of CRL extensions.
        Nr\   rH   s    r$   r-   z$CertificateRevocationList.extensionsm  r{   r%   c                 ó   — dS r”   r\   rH   s    r$   r•   z#CertificateRevocationList.signatures  r{   r%   c                 ó   — dS )zO
        Returns the tbsCertList payload bytes as defined in RFC 5280.
        Nr\   rH   s    r$   Útbs_certlist_bytesz,CertificateRevocationList.tbs_certlist_bytesy  r{   r%   rM   c                 ó   — dS r›   r\   rQ   s     r$   rR   z CertificateRevocationList.__eq__  r{   r%   c                 ó   — dS )z<
        Number of revoked certificates in the CRL.
        Nr\   rH   s    r$   rh   z!CertificateRevocationList.__len__…  r{   r%   Úidxc                 ó   — d S r   r\   ©r"   rÎ   s     r$   rj   z%CertificateRevocationList.__getitem__‹  ó   € àˆr%   c                 ó   — d S r   r\   rÐ   s     r$   rj   z%CertificateRevocationList.__getitem__�  rÑ   r%   c                 ó   — dS )zS
        Returns a revoked certificate (or slice of revoked certificates).
        Nr\   rÐ   s     r$   rj   z%CertificateRevocationList.__getitem__“  r{   r%   c                 ó   — dS )z8
        Iterator over the revoked certificates
        Nr\   rH   s    r$   ri   z"CertificateRevocationList.__iter__›  r{   r%   r‚   c                 ó   — dS )zQ
        Verifies signature of revocation list against given public key.
        Nr\   )r"   r‚   s     r$   Úis_signature_validz,CertificateRevocationList.is_signature_valid¡  r{   r%   N)+r&   r'   r(   r¢   r£   r   r§   rW   r¡   r   r¤   rz   rX   rf   r¦   rª   rÀ   r¥   rŽ   r   r‘   r   rˆ   r;   rÅ   rÇ   r   r-   r•   rË   rZ   r[   rR   rh   Úoverloadrj   ÚsliceÚListÚUnionÚIteratorri   r   rÖ   r\   r%   r$   r¼   r¼   6  sª  € € € € € ØÔð ]Ô%;ð Àð ð ð ñ Ôðð
 	Ôð VÔ%9ð ¸eð ð ð ñ Ôðð
 	ÔðØ ðà	ŒÐ+Ô	,ðð ð ñ Ôðð 	Ôðà	Œ˜Ô-Ô	.ðð ð ñ Ôðð 	ÔðÐ)9ð ð ð ñ Ôðð
 	Ôð˜ð ð ð ñ Ôðð
 	Ôð˜Vœ_¨XÔ->Ô?ð ð ð ñ Ôðð
 	Ôð˜XÔ.ð ð ð ñ Ôðð
 	Ôð˜Jð ð ð ñ Ôðð
 	Ôð˜5ð ð ð ñ Ôðð
 	Ôð Eð ð ð ñ Ôðð
 	Ôð˜Fð  tð ð ð ñ Ôðð
 	Ôð˜ð ð ð ñ Ôðð
 „_ð˜sð Ð'9ð ð ð ñ „_ðð „_ð˜uð ¨¬Ð5GÔ)Hð ð ð ñ „_ðð 	ÔðØ”<  U 
Ô+ðà	ŒÐ(¨&¬+Ð6HÔ*IÐIÔ	Jðð ð ñ Ôðð 	Ôð˜&œ/Ð*<Ô=ð ð ð ñ Ôðð
 	ÔðØ=ðà	ðð ð ñ Ôðð ð r%   r¼   c                   ó2  — e Zd Zej        dedefd„¦   «         Zej        defd„¦   «         Z	ej        de
fd„¦   «         Zej        defd„¦   «         Zej        dej        ej                 fd„¦   «         Zej        defd„¦   «         Zej        defd	„¦   «         Zej        defd
„¦   «         Zej        dej        defd„¦   «         Zej        defd„¦   «         Zej        defd„¦   «         Zej        defd„¦   «         Z ej        dedefd„¦   «         Z!dS )ÚCertificateSigningRequestrM   r   c                 ó   — dS r›   r\   rQ   s     r$   rR   z CertificateSigningRequest.__eq__®  r{   r%   c                 ó   — dS r�   r\   rH   s    r$   rU   z"CertificateSigningRequest.__hash__´  r{   r%   c                 ó   — dS r�   r\   rH   s    r$   r‚   z$CertificateSigningRequest.public_keyº  r{   r%   c                 ó   — dS rŠ   r\   rH   s    r$   r‹   z!CertificateSigningRequest.subjectÀ  r{   r%   c                 ó   — dS r�   r\   rH   s    r$   rŽ   z2CertificateSigningRequest.signature_hash_algorithmÆ  r{   r%   c                 ó   — dS r�   r\   rH   s    r$   r‘   z1CertificateSigningRequest.signature_algorithm_oidÏ  r{   r%   c                 ó   — dS )z@
        Returns the extensions in the signing request.
        Nr\   rH   s    r$   r-   z$CertificateSigningRequest.extensionsÕ  r{   r%   c                 ó   — dS )z/
        Returns an Attributes object.
        Nr\   rH   s    r$   r2   z$CertificateSigningRequest.attributesÛ  r{   r%   rž   c                 ó   — dS )z;
        Encodes the request to PEM or DER format.
        Nr\   r    s     r$   r¡   z&CertificateSigningRequest.public_bytesá  r{   r%   c                 ó   — dS r”   r\   rH   s    r$   r•   z#CertificateSigningRequest.signatureç  r{   r%   c                 ó   — dS )zd
        Returns the PKCS#10 CertificationRequestInfo bytes as defined in RFC
        2986.
        Nr\   rH   s    r$   Útbs_certrequest_bytesz/CertificateSigningRequest.tbs_certrequest_bytesí  r{   r%   c                 ó   — dS )z8
        Verifies signature of signing request.
        Nr\   rH   s    r$   rÖ   z,CertificateSigningRequest.is_signature_validô  r{   r%   r   c                 ó   — dS )z:
        Get the attribute value for a given OID.
        Nr\   )r"   r   s     r$   re   z/CertificateSigningRequest.get_attribute_for_oidú  r{   r%   N)"r&   r'   r(   r¢   r£   rZ   r[   rR   rX   rU   r   r‚   r¥   r   r‹   rf   r¦   r   r¤   rŽ   r   r‘   r   r-   r^   r2   r   r§   rW   r¡   r•   ré   rÖ   re   r\   r%   r$   rÝ   rÝ   ­  sg  € € € € € ØÔð˜Fð  tð ð ð ñ Ôðð
 	Ôð˜#ð ð ð ñ Ôðð
 	ÔðÐ8ð ð ð ñ Ôðð
 	Ôð˜ð ð ð ñ Ôðð
 	Ôðà	Œ˜Ô-Ô	.ðð ð ñ Ôðð 	ÔðÐ)9ð ð ð ñ Ôðð
 	Ôð˜Jð ð ð ñ Ôðð
 	Ôð˜Jð ð ð ñ Ôðð
 	Ôð ]Ô%;ð Àð ð ð ñ Ôðð
 	Ôð˜5ð ð ð ñ Ôðð
 	Ôð uð ð ð ñ Ôðð 	Ôð Dð ð ð ñ Ôðð
 	ÔðÐ)9ð ¸eð ð ð ñ Ôðð ð r%   rÝ   ÚdataÚbackendc                 ó*   — t          j        | ¦  «        S r   )Ú	rust_x509Úload_pem_x509_certificate©rì   rí   s     r$   rð   rð     ó   € õ Ô.¨tÑ4Ô4Ð4r%   c                 ó*   — t          j        | ¦  «        S r   )rï   Úload_der_x509_certificaterñ   s     r$   rô   rô     rò   r%   c                 ó*   — t          j        | ¦  «        S r   )rï   Úload_pem_x509_csrrñ   s     r$   rö   rö     ó   € õ Ô& tÑ,Ô,Ð,r%   c                 ó*   — t          j        | ¦  «        S r   )rï   Úload_der_x509_csrrñ   s     r$   rù   rù     r÷   r%   c                 ó*   — t          j        | ¦  «        S r   )rï   Úload_pem_x509_crlrñ   s     r$   rû   rû   "  r÷   r%   c                 ó*   — t          j        | ¦  «        S r   )rï   Úload_der_x509_crlrñ   s     r$   rý   rý   )  r÷   r%   c                   óH  — e Zd Zdg g fdej        e         dej        ee                  dej        ej	        e
eej        e         f                  fd„Zdedd fd„Zd	ed
edd fd„Zddœde
dedej        e         dd fd„Z	 ddedej        ej                 dej        defd„ZdS )Ú CertificateSigningRequestBuilderNÚsubject_namer-   r2   c                 ó0   — || _         || _        || _        dS )zB
        Creates an empty X.509 certificate request (v1).
        N)Ú_subject_namerµ   ra   )r"   r   r-   r2   s       r$   r!   z)CertificateSigningRequestBuilder.__init__0  s"   € ð *ˆÔØ%ˆÔØ%ˆÔÐÐr%   Únamer   c                 ó¬   — t          |t          ¦  «        st          d¦  «        ‚| j        �t	          d¦  «        ‚t          || j        | j        ¦  «        S )zF
        Sets the certificate requestor's distinguished name.
        úExpecting x509.Name object.Nú&The subject name may only be set once.)rO   r   Ú	TypeErrorr  r/   rÿ   rµ   ra   ©r"   r  s     r$   r   z-CertificateSigningRequestBuilder.subject_name?  s\   € õ ˜$¥Ñ%Ô%ð 	;ÝÐ9Ñ:Ô:Ð:ØÔÐ)ÝÐEÑFÔFÐFÝ/Ø�$Ô" DÔ$4ñ
ô 
ð 	
r%   ÚextvalÚcriticalc                 óè   — t          |t          ¦  «        st          d¦  «        ‚t          |j        ||¦  «        }t          || j        ¦  «         t          | j        | j        |gz   | j	        ¦  «        S )zE
        Adds an X.509 extension to the certificate request.
        ú"extension must be an ExtensionType)
rO   r   r  r   r   r1   rµ   rÿ   r  ra   ©r"   r	  r
  r,   s       r$   Úadd_extensionz.CertificateSigningRequestBuilder.add_extensionK  sw   € õ ˜&¥-Ñ0Ô0ð 	BÝÐ@ÑAÔAÐAå˜fœj¨(°FÑ;Ô;ˆ	Ý# I¨tÔ/?Ñ@Ô@Ð@å/ØÔØÔ 	˜{Ñ*ØÔñ
ô 
ð 	
r%   )Ú_tagr   rB   r  c                ón  — t          |t          ¦  «        st          d¦  «        ‚t          |t          ¦  «        st          d¦  «        ‚|�$t          |t          ¦  «        st          d¦  «        ‚t          || j        ¦  «         |�|j        }nd}t          | j	        | j
        | j        |||fgz   ¦  «        S )zK
        Adds an X.509 attribute with an OID and associated value.
        zoid must be an ObjectIdentifierzvalue must be bytesNztag must be _ASN1Type)rO   r   r  rW   r   r6   ra   rB   rÿ   r  rµ   )r"   r   rB   r  Útags        r$   Úadd_attributez.CertificateSigningRequestBuilder.add_attribute]  sÅ   € õ ˜#Õ/Ñ0Ô0ð 	?ÝÐ=Ñ>Ô>Ð>å˜%¥Ñ'Ô'ð 	3ÝÐ1Ñ2Ô2Ð2àÐ¥J¨tµYÑ$?Ô$?ÐÝÐ3Ñ4Ô4Ð4å# C¨Ô)9Ñ:Ô:Ð:àÐØ”*ˆCˆCàˆCå/ØÔØÔØÔ  e¨SÐ 1Ð2Ñ2ñ
ô 
ð 	
r%   Úprivate_keyrv   rí   c                 óZ   — | j         €t          d¦  «        ‚t          j        | ||¦  «        S )zF
        Signs the request using the requestor's private key.
        Nz/A CertificateSigningRequest must have a subject)r  r/   rï   Úcreate_x509_csr©r"   r  rv   rí   s       r$   Úsignz%CertificateSigningRequestBuilder.sign}  s1   € ð ÔÐ%ÝÐNÑOÔOÐOÝÔ(¨¨{¸IÑFÔFÐFr%   r   )r&   r'   r(   rf   r¦   r   rÙ   r   r   ÚTupler   rW   rX   r!   r   r[   r  r   r  r   r   r¤   ÚAnyrÝ   r  r\   r%   r$   rÿ   rÿ   /  s„  € € € € € ð /3Ø<>ð ð&ð &à”o dÔ+ð&ð ”K 	¨-Ô 8Ô9ð&ð ”KØŒLÐ)¨5°&´/À#Ô2FÐFÔGô
ð	&ð &ð &ð &ð

 ð 

Ð*Lð 

ð 

ð 

ð 

ð
Ø#ð
Ø/3ð
à	+ð
ð 
ð 
ð 
ð. ,0ð
ð 
ð 
àð
ð ð
ð
 Œo˜iÔ(ð
ð 
,ð
ð 
ð 
ð 
ðH #ð	Gð Gà2ðGð ”? 6Ô#7Ô8ðGð ”ð	Gð
 
#ðGð Gð Gð Gð Gð Gr%   rÿ   c                   óü  — e Zd ZU ej        ee                  ed<   ddddddg fdej        e	         dej        e	         dej        e
         dej        e         dej        ej                 dej        ej                 d	ej        ee                  d
dfd„Zde	d
d fd„Zde	d
d fd„Zde
d
d fd„Zded
d fd„Zdej        d
d fd„Zdej        d
d fd„Zdeded
d fd„Z	 ddedej        ej                 dej        d
efd„ZdS )ÚCertificateBuilderrµ   NÚissuer_namer   r‚   r}   r„   r†   r-   r   c                 óŠ   — t           j        | _        || _        || _        || _        || _        || _        || _        || _	        d S r   )
rl   ro   Ú_versionÚ_issuer_namer  Ú_public_keyr³   Ú_not_valid_beforeÚ_not_valid_afterrµ   )r"   r  r   r‚   r}   r„   r†   r-   s           r$   r!   zCertificateBuilder.__init__Ž  sK   € õ  œ
ˆŒØ'ˆÔØ)ˆÔØ%ˆÔØ+ˆÔØ!1ˆÔØ /ˆÔØ%ˆÔÐÐr%   r  c           	      óÜ   — t          |t          ¦  «        st          d¦  «        ‚| j        �t	          d¦  «        ‚t          || j        | j        | j        | j	        | j
        | j        ¦  «        S )z3
        Sets the CA's distinguished name.
        r  Nú%The issuer name may only be set once.)rO   r   r  r  r/   r  r  r   r³   r!  r"  rµ   r  s     r$   r  zCertificateBuilder.issuer_name¡  sv   € õ ˜$¥Ñ%Ô%ð 	;ÝÐ9Ñ:Ô:Ð:ØÔÐ(ÝÐDÑEÔEÐEÝ!ØØÔØÔØÔØÔ"ØÔ!ØÔñ
ô 
ð 	
r%   c           	      óÜ   — t          |t          ¦  «        st          d¦  «        ‚| j        �t	          d¦  «        ‚t          | j        || j        | j        | j	        | j
        | j        ¦  «        S )z:
        Sets the requestor's distinguished name.
        r  Nr  )rO   r   r  r  r/   r  r  r   r³   r!  r"  rµ   r  s     r$   r   zCertificateBuilder.subject_name³  sv   € õ ˜$¥Ñ%Ô%ð 	;ÝÐ9Ñ:Ô:Ð:ØÔÐ)ÝÐEÑFÔFÐFÝ!ØÔØØÔØÔØÔ"ØÔ!ØÔñ
ô 
ð 	
r%   Úkeyc           
      ól  — t          |t          j        t          j        t
          j        t          j        t          j
        t          j        t          j        f¦  «        st          d¦  «        ‚| j        �t#          d¦  «        ‚t%          | j        | j        || j        | j        | j        | j        ¦  «        S )zT
        Sets the requestor's public key (as found in the signing request).
        z‰Expecting one of DSAPublicKey, RSAPublicKey, EllipticCurvePublicKey, Ed25519PublicKey, Ed448PublicKey, X25519PublicKey, or X448PublicKey.Nz$The public key may only be set once.)rO   r   ÚDSAPublicKeyr   ÚRSAPublicKeyr   ÚEllipticCurvePublicKeyr	   ÚEd25519PublicKeyr
   ÚEd448PublicKeyr   ÚX25519PublicKeyr   ÚX448PublicKeyr  r   r/   r  r  r  r³   r!  r"  rµ   )r"   r&  s     r$   r‚   zCertificateBuilder.public_keyÅ  s´   € õ ØåÔ ÝÔ ÝÔ)ÝÔ(ÝÔ$ÝÔ&ÝÔ"ðñ
ô 
ð 	õ ð!ñô ð ð ÔÐ'ÝÐCÑDÔDÐDÝ!ØÔØÔØØÔØÔ"ØÔ!ØÔñ
ô 
ð 	
r%   Únumberc           	      óT  — t          |t          ¦  «        st          d¦  «        ‚| j        �t	          d¦  «        ‚|dk    rt	          d¦  «        ‚|                     ¦   «         dk    rt	          d¦  «        ‚t          | j        | j        | j	        || j
        | j        | j        ¦  «        S )z5
        Sets the certificate serial number.
        ú'Serial number must be of integral type.Nú'The serial number may only be set once.r   z%The serial number should be positive.é    ú3The serial number should not be more than 159 bits.)rO   rX   r  r³   r/   Ú
bit_lengthr  r  r  r   r!  r"  rµ   ©r"   r/  s     r$   r}   z CertificateBuilder.serial_numberê  s¿   € õ ˜&¥#Ñ&Ô&ð 	GÝÐEÑFÔFÐFØÔÐ*ÝÐFÑGÔGÐGØ�QŠ;ˆ;ÝÐDÑEÔEÐEð ×ÒÑÔ #Ò%Ð%ÝØHñô ð õ "ØÔØÔØÔØØÔ"ØÔ!ØÔñ
ô 
ð 	
r%   r7   c           	      óz  — t          |t          j        ¦  «        st          d¦  «        ‚| j        �t	          d¦  «        ‚t          |¦  «        }|t          k     rt	          d¦  «        ‚| j        �|| j        k    rt	          d¦  «        ‚t          | j	        | j
        | j        | j        || j        | j        ¦  «        S )z7
        Sets the certificate activation time.
        úExpecting datetime object.Nz*The not valid before may only be set once.z>The not valid before date must be on or after 1950 January 1).zBThe not valid before date must be before the not valid after date.)rO   r;   r  r!  r/   r?   Ú_EARLIEST_UTC_TIMEr"  r  r  r  r   r³   rµ   ©r"   r7   s     r$   r„   z#CertificateBuilder.not_valid_before  sÚ   € õ ˜$¥Ô 1Ñ2Ô2ð 	:ÝÐ8Ñ9Ô9Ð9ØÔ!Ð-ÝÐIÑJÔJÐJÝ)¨$Ñ/Ô/ˆØÕ$Ò$Ð$Ýð$ñô ð ð Ô Ð,°¸Ô8MÒ1MÐ1MÝðñô ð õ "ØÔØÔØÔØÔØØÔ!ØÔñ
ô 
ð 	
r%   c           	      óz  — t          |t          j        ¦  «        st          d¦  «        ‚| j        �t	          d¦  «        ‚t          |¦  «        }|t          k     rt	          d¦  «        ‚| j        �|| j        k     rt	          d¦  «        ‚t          | j	        | j
        | j        | j        | j        || j        ¦  «        S )z7
        Sets the certificate expiration time.
        r8  Nz)The not valid after may only be set once.z<The not valid after date must be on or after 1950 January 1.zAThe not valid after date must be after the not valid before date.)rO   r;   r  r"  r/   r?   r9  r!  r  r  r  r   r³   rµ   r:  s     r$   r†   z"CertificateBuilder.not_valid_after$  sÛ   € õ ˜$¥Ô 1Ñ2Ô2ð 	:ÝÐ8Ñ9Ô9Ð9ØÔ Ð,ÝÐHÑIÔIÐIÝ)¨$Ñ/Ô/ˆØÕ$Ò$Ð$Ýð#ñô ð ð
 Ô"Ð.Ø�tÔ-Ò-Ð-åðñô ð õ "ØÔØÔØÔØÔØÔ"ØØÔñ
ô 
ð 	
r%   r	  r
  c           
      ó  — t          |t          ¦  «        st          d¦  «        ‚t          |j        ||¦  «        }t          || j        ¦  «         t          | j        | j	        | j
        | j        | j        | j        | j        |gz   ¦  «        S )z=
        Adds an X.509 extension to the certificate.
        r  )rO   r   r  r   r   r1   rµ   r  r  r  r   r³   r!  r"  r  s       r$   r  z CertificateBuilder.add_extensionD  s�   € õ ˜&¥-Ñ0Ô0ð 	BÝÐ@ÑAÔAÐAå˜fœj¨(°FÑ;Ô;ˆ	Ý# I¨tÔ/?Ñ@Ô@Ð@å!ØÔØÔØÔØÔØÔ"ØÔ!ØÔ 	˜{Ñ*ñ
ô 
ð 	
r%   r  rv   rí   c                 ó6  — | j         €t          d¦  «        ‚| j        €t          d¦  «        ‚| j        €t          d¦  «        ‚| j        €t          d¦  «        ‚| j        €t          d¦  «        ‚| j        €t          d¦  «        ‚t          j        | ||¦  «        S )zC
        Signs the certificate using the CA's private key.
        Nz&A certificate must have a subject namez&A certificate must have an issuer namez'A certificate must have a serial numberz/A certificate must have a not valid before timez.A certificate must have a not valid after timez$A certificate must have a public key)	r  r/   r  r³   r!  r"  r   rï   Úcreate_x509_certificater  s       r$   r  zCertificateBuilder.signZ  s©   € ð ÔÐ%ÝÐEÑFÔFÐFàÔÐ$ÝÐEÑFÔFÐFàÔÐ&ÝÐFÑGÔGÐGàÔ!Ð)ÝÐNÑOÔOÐOàÔ Ð(ÝÐMÑNÔNÐNàÔÐ#ÝÐCÑDÔDÐDåÔ0°°{ÀIÑNÔNÐNr%   r   )r&   r'   r(   rf   rÙ   r   r   Ú__annotations__r¦   r   r   rX   r;   r!   r  r   r‚   r}   r„   r†   r[   r  r   r   r¤   r  ru   r  r\   r%   r$   r  r  ‹  sN  € € € € € € Ø”˜Y }Ô5Ô6Ð6Ð6Ñ6ð .2Ø.2ØDHØ.2Ø?CØ>BØ<>ð&ð &à”_ TÔ*ð&ð ”o dÔ+ð&ð ”OÐ$@ÔAð	&ð
 ” sÔ+ð&ð !œ/¨(Ô*;Ô<ð&ð  œ¨Ô):Ô;ð&ð ”K 	¨-Ô 8Ô9ð&ð 
ð&ð &ð &ð &ð&
 ð 
Ð)=ð 
ð 
ð 
ð 
ð$
 ð 
Ð*>ð 
ð 
ð 
ð 
ð$#
à)ð#
ð 
ð#
ð #
ð #
ð #
ðJ
 Cð 
Ð,@ð 
ð 
ð 
ð 
ð6
ØÔ%ð
à	ð
ð 
ð 
ð 
ð>
 HÔ$5ð 
Ð:Nð 
ð 
ð 
ð 
ð@
Ø#ð
Ø/3ð
à	ð
ð 
ð 
ð 
ð4 #ð	Oð Oà2ðOð ”? 6Ô#7Ô8ðOð ”ð	Oð
 
ðOð Oð Oð Oð Oð Or%   r  c                   óÀ  — e Zd ZU ej        ee                  ed<   ej        e         ed<   dddg g fdej	        e
         dej	        ej                 dej	        ej                 dej        ee                  dej        e         f
d	„Zde
d
d fd„Zdej        d
d fd„Zdej        d
d fd„Zdeded
d fd„Zded
d fd„Z	 ddedej	        ej                 dej        d
efd„ZdS )Ú CertificateRevocationListBuilderrµ   Ú_revoked_certificatesNr  rÇ   rÅ   r-   Úrevoked_certificatesc                 óL   — || _         || _        || _        || _        || _        d S r   )r  Ú_last_updateÚ_next_updaterµ   rB  )r"   r  rÇ   rÅ   r-   rC  s         r$   r!   z)CertificateRevocationListBuilder.__init__|  s2   € ð (ˆÔØ'ˆÔØ'ˆÔØ%ˆÔØ%9ˆÔ"Ð"Ð"r%   r   c                 óÄ   — t          |t          ¦  «        st          d¦  «        ‚| j        �t	          d¦  «        ‚t          || j        | j        | j        | j	        ¦  «        S )Nr  r$  )
rO   r   r  r  r/   rA  rE  rF  rµ   rB  )r"   r  s     r$   r  z,CertificateRevocationListBuilder.issuer_nameŠ  sj   € õ ˜+¥tÑ,Ô,ð 	;ÝÐ9Ñ:Ô:Ð:ØÔÐ(ÝÐDÑEÔEÐEÝ/ØØÔØÔØÔØÔ&ñ
ô 
ð 	
r%   c                 ób  — t          |t          j        ¦  «        st          d¦  «        ‚| j        �t	          d¦  «        ‚t          |¦  «        }|t          k     rt	          d¦  «        ‚| j        �|| j        k    rt	          d¦  «        ‚t          | j	        || j        | j
        | j        ¦  «        S )Nr8  ú!Last update may only be set once.ú8The last update date must be on or after 1950 January 1.z9The last update date must be before the next update date.)rO   r;   r  rE  r/   r?   r9  rF  rA  r  rµ   rB  )r"   rÇ   s     r$   rÇ   z,CertificateRevocationListBuilder.last_update™  sÊ   € õ ˜+¥xÔ'8Ñ9Ô9ð 	:ÝÐ8Ñ9Ô9Ð9ØÔÐ(ÝÐ@ÑAÔAÐAÝ0°Ñ=Ô=ˆØÕ+Ò+Ð+ÝØMñô ð ð ÔÐ(¨[¸4Ô;LÒ-LÐ-LÝØKñô ð õ 0ØÔØØÔØÔØÔ&ñ
ô 
ð 	
r%   c                 ób  — t          |t          j        ¦  «        st          d¦  «        ‚| j        �t	          d¦  «        ‚t          |¦  «        }|t          k     rt	          d¦  «        ‚| j        �|| j        k     rt	          d¦  «        ‚t          | j	        | j        || j
        | j        ¦  «        S )Nr8  rI  rJ  z8The next update date must be after the last update date.)rO   r;   r  rF  r/   r?   r9  rE  rA  r  rµ   rB  )r"   rÅ   s     r$   rÅ   z,CertificateRevocationListBuilder.next_update±  sÊ   € õ ˜+¥xÔ'8Ñ9Ô9ð 	:ÝÐ8Ñ9Ô9Ð9ØÔÐ(ÝÐ@ÑAÔAÐAÝ0°Ñ=Ô=ˆØÕ+Ò+Ð+ÝØMñô ð ð ÔÐ(¨[¸4Ô;LÒ-LÐ-LÝØJñô ð õ 0ØÔØÔØØÔØÔ&ñ
ô 
ð 	
r%   r	  r
  c                 ó   — t          |t          ¦  «        st          d¦  «        ‚t          |j        ||¦  «        }t          || j        ¦  «         t          | j        | j	        | j
        | j        |gz   | j        ¦  «        S )zM
        Adds an X.509 extension to the certificate revocation list.
        r  )rO   r   r  r   r   r1   rµ   rA  r  rE  rF  rB  r  s       r$   r  z.CertificateRevocationListBuilder.add_extensionÉ  sƒ   € õ ˜&¥-Ñ0Ô0ð 	BÝÐ@ÑAÔAÐAå˜fœj¨(°FÑ;Ô;ˆ	Ý# I¨tÔ/?Ñ@Ô@Ð@Ý/ØÔØÔØÔØÔ 	˜{Ñ*ØÔ&ñ
ô 
ð 	
r%   Úrevoked_certificatec                 óª   — t          |t          ¦  «        st          d¦  «        ‚t          | j        | j        | j        | j        | j        |gz   ¦  «        S )z8
        Adds a revoked certificate to the CRL.
        z)Must be an instance of RevokedCertificate)	rO   rª   r  rA  r  rE  rF  rµ   rB  )r"   rM  s     r$   Úadd_revoked_certificatez8CertificateRevocationListBuilder.add_revoked_certificateÜ  sa   € õ Ð-Õ/AÑBÔBð 	IÝÐGÑHÔHÐHå/ØÔØÔØÔØÔØÔ&Ð*=Ð)>Ñ>ñ
ô 
ð 	
r%   r  rv   rí   c                 ó²   — | j         €t          d¦  «        ‚| j        €t          d¦  «        ‚| j        €t          d¦  «        ‚t	          j        | ||¦  «        S )NzA CRL must have an issuer namez"A CRL must have a last update timez"A CRL must have a next update time)r  r/   rE  rF  rï   Úcreate_x509_crlr  s       r$   r  z%CertificateRevocationListBuilder.signí  sa   € ð ÔÐ$ÝÐ=Ñ>Ô>Ð>àÔÐ$ÝÐAÑBÔBÐBàÔÐ$ÝÐAÑBÔBÐBåÔ(¨¨{¸IÑFÔFÐFr%   r   )r&   r'   r(   rf   rÙ   r   r   r?  rª   r¦   r   r;   r!   r  rÇ   rÅ   r[   r  rO  r   r   r¤   r  r¼   r  r\   r%   r$   rA  rA  x  sè  € € € € € € Ø”˜Y }Ô5Ô6Ð6Ð6Ñ6Ø!œ;Ð'9Ô:Ð:Ð:Ñ:ð .2Ø:>Ø:>Ø<>Ø@Bð:ð :à”_ TÔ*ð:ð ”_ XÔ%6Ô7ð:ð ”_ XÔ%6Ô7ð	:ð
 ”K 	¨-Ô 8Ô9ð:ð %œkÐ*<Ô=ð:ð :ð :ð :ð
Øð
à	+ð
ð 
ð 
ð 
ð
Ø#Ô,ð
à	+ð
ð 
ð 
ð 
ð0
Ø#Ô,ð
à	+ð
ð 
ð 
ð 
ð0
Ø#ð
Ø/3ð
à	+ð
ð 
ð 
ð 
ð&
Ø#5ð
à	+ð
ð 
ð 
ð 
ð* #ð	Gð Gà2ðGð ”? 6Ô#7Ô8ðGð ”ð	Gð
 
#ðGð Gð Gð Gð Gð Gr%   rA  c            	       óÜ   — e Zd Zddg fdej        e         dej        ej                 dej        ee	                  fd„Z
dedd fd„Zd	ej        dd fd
„Zde	dedd fd„Zddej        defd„ZdS )ÚRevokedCertificateBuilderNr}   r­   r-   c                 ó0   — || _         || _        || _        d S r   r²   r¶   s       r$   r!   z"RevokedCertificateBuilder.__init__   r·   r%   r/  r   c                 ó$  — t          |t          ¦  «        st          d¦  «        ‚| j        �t	          d¦  «        ‚|dk    rt	          d¦  «        ‚|                     ¦   «         dk    rt	          d¦  «        ‚t          || j        | j        ¦  «        S )Nr1  r2  r   z$The serial number should be positiver3  r4  )	rO   rX   r  r³   r/   r5  rS  r´   rµ   r6  s     r$   r}   z'RevokedCertificateBuilder.serial_number
  s£   € Ý˜&¥#Ñ&Ô&ð 	GÝÐEÑFÔFÐFØÔÐ*ÝÐFÑGÔGÐGØ�QŠ;ˆ;ÝÐCÑDÔDÐDð ×ÒÑÔ #Ò%Ð%ÝØHñô ð õ )Ø�DÔ)¨4Ô+;ñ
ô 
ð 	
r%   r7   c                 ó  — t          |t          j        ¦  «        st          d¦  «        ‚| j        �t	          d¦  «        ‚t          |¦  «        }|t          k     rt	          d¦  «        ‚t          | j        || j	        ¦  «        S )Nr8  z)The revocation date may only be set once.z7The revocation date must be on or after 1950 January 1.)
rO   r;   r  r´   r/   r?   r9  rS  r³   rµ   r:  s     r$   r­   z)RevokedCertificateBuilder.revocation_date  s�   € õ ˜$¥Ô 1Ñ2Ô2ð 	:ÝÐ8Ñ9Ô9Ð9ØÔ Ð,ÝÐHÑIÔIÐIÝ)¨$Ñ/Ô/ˆØÕ$Ò$Ð$ÝØLñô ð õ )ØÔ  tÔ'7ñ
ô 
ð 	
r%   r	  r
  c                 óè   — t          |t          ¦  «        st          d¦  «        ‚t          |j        ||¦  «        }t          || j        ¦  «         t          | j        | j	        | j        |gz   ¦  «        S )Nr  )
rO   r   r  r   r   r1   rµ   rS  r³   r´   r  s       r$   r  z'RevokedCertificateBuilder.add_extension,  sw   € õ ˜&¥-Ñ0Ô0ð 	BÝÐ@ÑAÔAÐAå˜fœj¨(°FÑ;Ô;ˆ	Ý# I¨tÔ/?Ñ@Ô@Ð@Ý(ØÔØÔ!ØÔ 	˜{Ñ*ñ
ô 
ð 	
r%   rí   c                 ó´   — | j         €t          d¦  «        ‚| j        €t          d¦  «        ‚t          | j         | j        t	          | j        ¦  «        ¦  «        S )Nz/A revoked certificate must have a serial numberz1A revoked certificate must have a revocation date)r³   r/   r´   r°   r   rµ   )r"   rí   s     r$   ÚbuildzRevokedCertificateBuilder.build:  sf   € ØÔÐ&ÝÐNÑOÔOÐOØÔ Ð(ÝØCñô ð õ &ØÔØÔ!Ý�tÔ'Ñ(Ô(ñ
ô 
ð 	
r%   r   )r&   r'   r(   rf   r¦   rX   r;   rÙ   r   r   r!   r}   r­   r[   r  r  rª   rY  r\   r%   r$   rS  rS  ÿ  s  € € € € € ð /3Ø>BØ<>ð	&ð &à” sÔ+ð&ð  œ¨Ô):Ô;ð&ð ”K 	¨-Ô 8Ô9ð	&ð &ð &ð &ð
 Cð 
Ð,Gð 
ð 
ð 
ð 
ð$
ØÔ%ð
à	$ð
ð 
ð 
ð 
ð 
Ø#ð
Ø/3ð
à	$ð
ð 
ð 
ð 
ð
ð 
˜VœZð 
Ð3Eð 
ð 
ð 
ð 
ð 
ð 
r%   rS  c                  ób   — t                                t          j        d¦  «        d¦  «        dz	  S )Né   Úbigr   )rX   Ú
from_bytesÚosÚurandomr\   r%   r$   Úrandom_serial_numberr`  H  s#   € Ý�>Š>�"œ* R™.œ.¨%Ñ0Ô0°AÑ5Ð5r%   r   )Er¢   r;   r^  rf   Úcryptographyr   Ú"cryptography.hazmat.bindings._rustr   rï   Úcryptography.hazmat.primitivesr   r   Ú)cryptography.hazmat.primitives.asymmetricr   r   r	   r
   r   r   r   Ú/cryptography.hazmat.primitives.asymmetric.typesr   r   r   Úcryptography.x509.extensionsr   r   r   r   Úcryptography.x509.namer   r   Úcryptography.x509.oidr   r9  Ú	Exceptionr   rÙ   r1   r  rW   r¦   rX   r6   r?   rA   r^   ÚEnumrl   rq   ÚABCMetaru   Úregisterrª   r°   r¼   rÝ   r  rð   rô   rö   rù   rû   rý   rÿ   r  rA  rS  r`  r\   r%   r$   ú<module>rm     sÒ  ðð €
€
€
Ø €€€Ø 	€	€	€	Ø €€€à Ð Ð Ð Ð Ð Ø @Ð @Ð @Ð @Ð @Ð @Ø @Ð @Ð @Ð @Ð @Ð @Ð @Ð @ðð ð ð ð ð ð ð ð ð ð ð ð ð ð ð ð ð ðð ð ð ð ð ð ð ð ð ð
ð ð ð ð ð ð ð ð ð ð ð ð 3Ð 2Ð 2Ð 2Ð 2Ð 2Ð 2Ð 2Ø 2Ð 2Ð 2Ð 2Ð 2Ð 2ð '�XÔ& t¨Q°Ñ2Ô2Ð ðð ð ð ð ˜	ñ ô ð ðEØ˜Ô'ðEà”˜I mÔ4Ô5ðEð 
ðEð Eð Eð Eð	EØ	ð	Eà”ØŒÐ% u¨f¬o¸cÔ.BÐBÔCôð	Eð
 
ð	Eð 	Eð 	Eð 	Eð XÔ%6ð ¸8Ô;Lð ð ð ð ð!8ð !8ð !8ð !8ð !8ñ !8ô !8ð !8ðHNð Nð Nð Nð Nñ Nô Nð Nð(ð ð ð ð ˆeŒjñ ô ð ð
-ð -ð -ð -ð -�Yñ -ô -ð -ðið ið ið ið i˜CœKð iñ iô ið iðZ × Ò �YÔ*Ñ +Ô +Ð +ðð ð ð ð  3¤;ð ñ ô ð ð* × Ò ˜IÔ8Ñ 9Ô 9Ð 9ð ð  ð  ð  ð  Ð/ñ  ô  ð  ð0qð qð qð qð q¨#¬+ð qñ qô qð qðh × "Ò " 9Ô#FÑ GÔ GÐ GðQð Qð Qð Qð Q¨#¬+ð Qñ Qô Qð Qðj × "Ò " 9Ô#FÑ GÔ GÐ Gð
 (,ð5ð 5Ø
ð5Ø œ*ð5àð5ð 5ð 5ð 5ð (,ð5ð 5Ø
ð5Ø œ*ð5àð5ð 5ð 5ð 5ð (,ð-ð -Ø
ð-Ø œ*ð-àð-ð -ð -ð -ð (,ð-ð -Ø
ð-Ø œ*ð-àð-ð -ð -ð -ð (,ð-ð -Ø
ð-Ø œ*ð-àð-ð -ð -ð -ð (,ð-ð -Ø
ð-Ø œ*ð-àð-ð -ð -ð -ðYGð YGð YGð YGð YGñ YGô YGð YGðxjOð jOð jOð jOð jOñ jOô jOð jOðZDGð DGð DGð DGð DGñ DGô DGð DGðNF
ð F
ð F
ð F
ð F
ñ F
ô F
ð F
ðR6˜cð 6ð 6ð 6ð 6ð 6ð 6r%   