grthtrhthjhtyjytjytkergtrhtrjytjerhrfh3 «F\‡[ãR@sddlZddlZddlmZddlmZmZddlmZm Z ddl m Z ddl m Z ddlmZddlmZmZmZmZdd lmZmZmZmZmZ m!Z"m#Z$m%Z&m'Z(dd l)m*Z*m+Z+m,Z,m-Z-m.Z.m/Z/d d d ddddddddddddddddddd d!d"d#d$d%d&d'd(d)d*d+d,d-d.d/d0d1d2d3d4d5d6d7d8d9d:d;dd?d@dAdBdCdDdEdFdGdHdIdJdKdLdMdNdOdPdQdRdSdTdUdVdWdXdYdZd[d\gRZ0ye1Z2Wn&e3k �ršGd]d^„d^e4ƒZ2YnXej5Z5ej6Z6ej7Z7ej8Z8ej9Z9ej:Z:ej;Zd_Z?d`Z@daZAdbZBdcZCddZDejEZFejGZHejIZJejKZLejMZNejOZPejQZRejSZTejUZVejWZXejYZZej[Z\ej]Z^ej_Z`ejaZbejcZdejeZfejgZhejiZjejkZlejmZnejoZpejqZrejsZtejuZvejwZxejyZzej{Z|ej}Z~ejZ€ej�Z‚ejƒZ„ej…Z†ej‡Zˆej‰ZŠej‹ZŒej�ZŽej�Z�ej‘Z’ej“Z”ej•Z–ej—Z˜ej™Z™ejšZšej›Z›ejœ�r$ej�Z�ejžZžejŸZŸej Z e0j¡dedfdgdhgƒej¢Z¢ej£Z£ej¤Z¤ej¥Z¥ej¦Z¦ej§Z§ej¨Z¨ej©Z©ejªZªej«Z«ej¬Z¬ej­Z­ej®Z®didjdkdldmgZ¯dngZ°doZ±dpZ²GdqdS„dSe³ƒZ´eee´ƒZµe e´ƒZ¶GdrdT„dTe´ƒZ·GdsdU„dUe´ƒZ¸GdtdV„dVe´ƒZ¹GdudW„dWe´ƒZºGdvdX„dXe´ƒZ»Gdwdx„dxe4ƒZ¼Gdydz„dze¼ƒZ½Gd{d|„d|e¼ƒZ¾Gd}d~„d~e¼ƒZ¿Gdd€„d€e¼ƒZÀGd�d‚„d‚e¼ƒZÁGdƒd„„d„e¼ƒZÂd…d†„ZÃd‡dY„ZÄdˆd‰„ZÅeÅejÆdŠƒZÇeÅejÈd‹ƒZÉeÅejÊdŒƒZËGd�dZ„dZe4ƒZÌGdŽd[„d[e4ƒZÍeeÍeÎd�eσZÐGd�d\„d\e4ƒZÑeeÑeÎd‘eσZÒejÓƒdS)’éN)Úplatform)ÚwrapsÚpartial)ÚcountÚchain)ÚWeakValueDictionary)Ú errorcode)Ú deprecated)Ú binary_typeÚ integer_typesÚint2byteÚ indexbytes) Ú UNSPECIFIEDÚexception_from_error_queueÚffiÚlibÚ make_assertÚnativeÚ path_stringÚtext_to_bytes_and_warnÚno_zero_allocator)Ú FILETYPE_PEMÚ_PassphraseHelperÚPKeyÚX509NameÚX509Ú X509StoreÚOPENSSL_VERSION_NUMBERÚSSLEAY_VERSIONÚ SSLEAY_CFLAGSÚSSLEAY_PLATFORMÚ SSLEAY_DIRÚSSLEAY_BUILT_ONÚ SENT_SHUTDOWNÚRECEIVED_SHUTDOWNÚ SSLv2_METHODÚ SSLv3_METHODÚ SSLv23_METHODÚ TLSv1_METHODÚTLSv1_1_METHODÚTLSv1_2_METHODÚ OP_NO_SSLv2Ú OP_NO_SSLv3Ú OP_NO_TLSv1Ú OP_NO_TLSv1_1Ú OP_NO_TLSv1_2ÚMODE_RELEASE_BUFFERSÚOP_SINGLE_DH_USEÚOP_SINGLE_ECDH_USEÚOP_EPHEMERAL_RSAÚOP_MICROSOFT_SESS_ID_BUGÚOP_NETSCAPE_CHALLENGE_BUGÚ#OP_NETSCAPE_REUSE_CIPHER_CHANGE_BUGÚOP_SSLREF2_REUSE_CERT_TYPE_BUGÚOP_MICROSOFT_BIG_SSLV3_BUFFERÚOP_MSIE_SSLV2_RSA_PADDINGÚOP_SSLEAY_080_CLIENT_DH_BUGÚ OP_TLS_D5_BUGÚOP_TLS_BLOCK_PADDING_BUGÚOP_DONT_INSERT_EMPTY_FRAGMENTSÚOP_CIPHER_SERVER_PREFERENCEÚOP_TLS_ROLLBACK_BUGÚOP_PKCS1_CHECK_1ÚOP_PKCS1_CHECK_2ÚOP_NETSCAPE_CA_DN_BUGÚ"OP_NETSCAPE_DEMO_CIPHER_CHANGE_BUGÚOP_NO_COMPRESSIONÚOP_NO_QUERY_MTUÚOP_COOKIE_EXCHANGEÚ OP_NO_TICKETÚOP_ALLÚ VERIFY_PEERÚVERIFY_FAIL_IF_NO_PEER_CERTÚVERIFY_CLIENT_ONCEÚ VERIFY_NONEÚSESS_CACHE_OFFÚSESS_CACHE_CLIENTÚSESS_CACHE_SERVERÚSESS_CACHE_BOTHÚSESS_CACHE_NO_AUTO_CLEARÚSESS_CACHE_NO_INTERNAL_LOOKUPÚSESS_CACHE_NO_INTERNAL_STOREÚSESS_CACHE_NO_INTERNALÚSSL_ST_CONNECTÚ SSL_ST_ACCEPTÚ SSL_ST_MASKÚ SSL_CB_LOOPÚ SSL_CB_EXITÚ SSL_CB_READÚ SSL_CB_WRITEÚ SSL_CB_ALERTÚSSL_CB_READ_ALERTÚSSL_CB_WRITE_ALERTÚSSL_CB_ACCEPT_LOOPÚSSL_CB_ACCEPT_EXITÚSSL_CB_CONNECT_LOOPÚSSL_CB_CONNECT_EXITÚSSL_CB_HANDSHAKE_STARTÚSSL_CB_HANDSHAKE_DONEÚErrorÚ WantReadErrorÚWantWriteErrorÚWantX509LookupErrorÚZeroReturnErrorÚ SysCallErrorÚSSLeay_versionÚSessionÚContextÚ Connectionc@s eZdZdS)Ú_bufferN)Ú__name__Ú __module__Ú __qualname__©rsrsú/usr/lib/python3.6/SSL.pyrovsroééééééÚ SSL_ST_INITÚ SSL_ST_BEFOREÚ SSL_ST_OKÚSSL_ST_RENEGOTIATEz"/etc/ssl/certs/ca-certificates.crtz /etc/pki/tls/certs/ca-bundle.crtz/etc/ssl/ca-bundle.pemz/etc/pki/tls/cacert.pemz1/etc/pki/ca-trust/extracted/pem/tls-ca-bundle.pemz/etc/ssl/certss$/opt/pyca/cryptography/openssl/certss'/opt/pyca/cryptography/openssl/cert.pemc@seZdZdZdS)rez4 An error occurred in an `OpenSSL.SSL` API. N)rprqrrÚ__doc__rsrsrsrtreïsc@s eZdZdS)rfN)rprqrrrsrsrsrtrfùsc@s eZdZdS)rgN)rprqrrrsrsrsrtrgýsc@s eZdZdS)rhN)rprqrrrsrsrsrtrhsc@s eZdZdS)riN)rprqrrrsrsrsrtrisc@s eZdZdS)rjN)rprqrrrsrsrsrtrj sc@s eZdZdZdd„Zdd„ZdS)Ú_CallbackExceptionHelperaÅ A base class for wrapper classes that allow for intelligent exception handling in OpenSSL callbacks. :ivar list _problems: Any exceptions that occurred while executing in a context where they could not be raised in the normal way. Typically this is because OpenSSL has called into some Python code and requires a return value. The exceptions are saved to be raised later when it is possible to do so. cCs g|_dS)N)Ú _problems)ÚselfrsrsrtÚ__init__sz!_CallbackExceptionHelper.__init__c Cs6|jr2y tƒWntk r$YnX|jjdƒ‚dS)z� Raise an exception from the OpenSSL error queue or that was previously captured whe running a callback. rN)r�Ú_raise_current_errorreÚpop)r‚rsrsrtÚraise_if_problems  z)_CallbackExceptionHelper.raise_if_problemN)rprqrrrrƒr†rsrsrsrtr€ s r€c@seZdZdZdd„ZdS)Ú _VerifyHelperz^ Wrap a callback such that it can be used as a certificate verification callback. cs2tjˆƒtˆƒ‡‡fdd„ƒ}tjd|ƒˆ_dS)Nc s°tj|ƒ}tj|ƒtj|ƒ}tj|ƒ}tj|ƒ}tjƒ}tj||ƒ}t j |}yˆ|||||ƒ} Wn,t k r�} zˆj j | ƒdSd} ~ XnX| r¨tj|tjƒdSdSdS)Nrru)Ú_libZX509_STORE_CTX_get_current_certÚ X509_up_refrÚ_from_raw_x509_ptrZX509_STORE_CTX_get_errorZX509_STORE_CTX_get_error_depthZ"SSL_get_ex_data_X509_STORE_CTX_idxZX509_STORE_CTX_get_ex_datarnÚ_reverse_mappingÚ Exceptionr�ÚappendZX509_STORE_CTX_set_errorZ X509_V_OK) ÚokZ store_ctxZx509ÚcertZ error_numberZ error_depthÚindexÚsslZ connectionÚresultÚe)Úcallbackr‚rsrtÚwrapper2s$        z'_VerifyHelper.__init__..wrapperzint (*)(int, X509_STORE_CTX *))r€rƒrÚ_ffir”)r‚r”r•rs)r”r‚rtrƒ/s z_VerifyHelper.__init__N)rprqrrrrƒrsrsrsrtr‡)sr‡c@seZdZdZdd„ZdS)Ú_NpnAdvertiseHelperzT Wrap a callback such that it can be used as an NPN advertisement callback. cs2tjˆƒtˆƒ‡‡fdd„ƒ}tjd|ƒˆ_dS)Ncs yntj|}ˆ|ƒ}djtjdd„|Dƒƒƒ}tjdt|ƒƒtjd|ƒg|_|jdd|d<|jd|d<dSt k rš}zˆj j |ƒdSd}~XnXdS) Nócss|]}tt|ƒƒ|fVqdS)N)r Úlen)Ú.0Úprsrsrtú asz@_NpnAdvertiseHelper.__init__..wrapper..zunsigned int *zunsigned char[]rrurv) rnr‹ÚjoinrÚ from_iterabler–Únewr™Ú_npn_advertise_callback_argsrŒr�r�)r‘ÚoutÚoutlenÚargÚconnÚprotosÚprotostrr“)r”r‚rsrtr•Xs  z-_NpnAdvertiseHelper.__init__..wrapperz>int (*)(SSL *, const unsigned char **, unsigned int *, void *))r€rƒrr–r”)r‚r”r•rs)r”r‚rtrƒUs  z_NpnAdvertiseHelper.__init__N)rprqrrrrƒrsrsrsrtr—Psr—c@seZdZdZdd„ZdS)Ú_NpnSelectHelperzP Wrap a callback such that it can be used as an NPN selection callback. cs2tjˆƒtˆƒ‡‡fdd„ƒ}tjd|ƒˆ_dS)Nc sÞy¬tj|}tj||ƒdd…}g}x<|r`t|dƒ} |d| d…} |j| ƒ|| dd…}q&Wˆ||ƒ} tjdt| ƒƒtjd| ƒg|_|jdd|d<|jd|d<dSt k rØ} zˆj j| ƒdSd} ~ XnXdS)Nrruzunsigned char *zunsigned char[]rv) rnr‹r–Úbufferr r�rŸr™Ú_npn_select_callback_argsrŒr�) r‘r¡r¢Úin_Úinlenr£r¤ÚinstrÚ protolistÚlengthÚprotoÚoutstrr“)r”r‚rsrtr•�s$     z*_NpnSelectHelper.__init__..wrapperz^int (*)(SSL *, unsigned char **, unsigned char *, const unsigned char *, unsigned int, void *))r€rƒrr–r”)r‚r”r•rs)r”r‚rtrƒ~s  "z_NpnSelectHelper.__init__N)rprqrrrrƒrsrsrsrtr§ysr§c@seZdZdZdd„ZdS)Ú_ALPNSelectHelperzQ Wrap a callback such that it can be used as an ALPN selection callback. cs2tjˆƒtˆƒ‡‡fdd„ƒ}tjd|ƒˆ_dS)Nc sðy¾tj|}tj||ƒdd…}g}x<|r`t|dƒ} |d| d…} |j| ƒ|| dd…}q&Wˆ||ƒ} t| tƒs~tdƒ‚tj dt | ƒƒtj d| ƒg|_ |j dd|d<|j d|d<dSt k rê} zˆj j| ƒdSd} ~ XnXdS)Nrruz'ALPN callback must return a bytestring.zunsigned char *zunsigned char[]rv)rnr‹r–r¨r r�Ú isinstanceÚ _binary_typeÚ TypeErrorrŸr™Ú_alpn_select_callback_argsrŒr�) r‘r¡r¢rªr«r£r¤r¬r­Z encoded_lenr¯r°r“)r”r‚rsrtr•²s(      z+_ALPNSelectHelper.__init__..wrapperz^int (*)(SSL *, unsigned char **, unsigned char *, const unsigned char *, unsigned int, void *))r€rƒrr–r”)r‚r”r•rs)r”r‚rtrƒ¯s  $z_ALPNSelectHelper.__init__N)rprqrrrrƒrsrsrsrtr±ªsr±c@seZdZdZdd„ZdS)Ú_OCSPServerCallbackHelperað Wrap a callback such that it can be used as an OCSP callback for the server side. Annoyingly, OpenSSL defines one OCSP callback but uses it in two different ways. For servers, that callback is expected to retrieve some OCSP data and hand it to OpenSSL, and may return only SSL_TLSEXT_ERR_OK, SSL_TLSEXT_ERR_FATAL, and SSL_TLSEXT_ERR_NOACK. For clients, that callback is expected to check the OCSP data, and returns a negative value on error, 0 if the response is not acceptable, or positive if it is. These are mutually exclusive return code behaviours, and they mean that we need two helpers so that we always return an appropriate error code if the user's code throws an exception. Given that we have to have two helpers anyway, these helpers are a bit more helpery than most: specifically, they hide a few more of the OpenSSL functions so that the user has an easier time writing these callbacks. This helper implements the server side. cs2tjˆƒtˆƒ‡‡fdd„ƒ}tjd|ƒˆ_dS)Ncs²y€tj|}|tjkr"tj|ƒ}nd}ˆ||ƒ}t|tƒsBtdƒ‚|sJdSt|ƒ}t j |ƒ}|tj ||ƒdd…<t j |||ƒdSt k r¬}zˆjj|ƒdSd}~XnXdS)Nz'OCSP callback must return a bytestring.rwrrv)rnr‹r–ÚNULLÚ from_handler²r³r´r™rˆZOPENSSL_mallocr¨ZSSL_set_tlsext_status_ocsp_resprŒr�r�)r‘Úcdatar¤ÚdataÚ ocsp_dataZocsp_data_lengthZdata_ptrr“)r”r‚rsrtr•ös&        z3_OCSPServerCallbackHelper.__init__..wrapperzint (*)(SSL *, void *))r€rƒrr–r”)r‚r”r•rs)r”r‚rtrƒós 'z"_OCSPServerCallbackHelper.__init__N)rprqrrrrƒrsrsrsrtr¶Ýsr¶c@seZdZdZdd„ZdS)Ú_OCSPClientCallbackHelperað Wrap a callback such that it can be used as an OCSP callback for the client side. Annoyingly, OpenSSL defines one OCSP callback but uses it in two different ways. For servers, that callback is expected to retrieve some OCSP data and hand it to OpenSSL, and may return only SSL_TLSEXT_ERR_OK, SSL_TLSEXT_ERR_FATAL, and SSL_TLSEXT_ERR_NOACK. For clients, that callback is expected to check the OCSP data, and returns a negative value on error, 0 if the response is not acceptable, or positive if it is. These are mutually exclusive return code behaviours, and they mean that we need two helpers so that we always return an appropriate error code if the user's code throws an exception. Given that we have to have two helpers anyway, these helpers are a bit more helpery than most: specifically, they hide a few more of the OpenSSL functions so that the user has an easier time writing these callbacks. This helper implements the client side. cs2tjˆƒtˆƒ‡‡fdd„ƒ}tjd|ƒˆ_dS)Nc sªyxtj|}|tjkr"tj|ƒ}nd}tjdƒ}tj||ƒ}|dkrJd}ntj|d|ƒdd…}ˆ|||ƒ}t t |ƒƒSt k r¤}zˆj j |ƒdSd}~XnXdS)Nzunsigned char **rr˜ruéÿÿÿÿ)rnr‹r–r·r¸rŸrˆZSSL_get_tlsext_status_ocsp_respr¨ÚintÚboolrŒr�r�) r‘r¹r¤rºZocsp_ptrZocsp_lenr»Zvalidr“)r”r‚rsrtr•9s        z3_OCSPClientCallbackHelper.__init__..wrapperzint (*)(SSL *, void *))r€rƒrr–r”)r‚r”r•rs)r”r‚rtrƒ6s z"_OCSPClientCallbackHelper.__init__N)rprqrrrrƒrsrsrsrtr¼ sr¼cCsdd}t|tƒs(t|ddƒ}|dk r(|ƒ}t|tƒr6|}t|tƒsJtdƒ‚n|dkr`td|fƒ‚|S)NÚfilenoz3argument must be an int, or have a fileno() method.rz1file descriptor cannot be a negative integer (%i))r²r Úgetattrr´Ú ValueError)ÚobjÚfdÚmethrsrsrtÚ_asFileDescriptor[s      rÆcCstjtj|ƒƒS)z“ Return a string describing the version of OpenSSL in use. :param type: One of the :const:`SSLEAY_` constants defined in this module. )r–Ústringrˆrk)Útypersrsrtrknscs‡‡fdd„}|S)a” Builds a decorator that ensures that functions that rely on OpenSSL functions that are not present in this build raise NotImplementedError, rather than AttributeError coming out of cryptography. :param flag: A cryptography flag that guards the functions, e.g. ``Cryptography_HAS_NEXTPROTONEG``. :param error: The string to be used in the exception if the flag is false. cs$ˆst|ƒ‡fdd„ƒ}|S|SdS)Ncs tˆƒ‚dS)N)ÚNotImplementedError)ÚargsÚkwargs)ÚerrorrsrtÚexplodeƒsz<_make_requires.._requires_decorator..explode)r)ÚfuncrÍ)rÌÚflagrsrtÚ_requires_decorator�sz+_make_requires.._requires_decoratorrs)rÏrÌrÐrs)rÌrÏrtÚ_make_requiresws  rÑzNPN not availablezALPN not availablezSNI not availablec@seZdZdZdS)rlzÉ A class representing an SSL session. A session defines certain connection parameters which may be re-used to speed up the setup of subsequent connections. .. versionadded:: 0.14 N)rprqrrrrsrsrsrtrlœsc @sÎeZdZdZededededede diZ e dd „e j ƒDƒƒZ d d „Z ded d„Zdd„Zdfdd„Zdd„Zdd„Zdd„Zdd„Zefdd„Zdd„Zdd „Zd!d"„Zefd#d$„Zd%d&„Zd'd(„Zd)d*„Zd+d,„Zd-d.„Z d/d0„Z!d1d2„Z"d3d4„Z#d5d6„Z$d7d8„Z%d9d:„Z&d;d<„Z'd=d>„Z(d?d@„Z)dAdB„Z*dCdD„Z+dEdF„Z,dGdH„Z-dIdJ„Z.dKdL„Z/dMdN„Z0dOdP„Z1dQdR„Z2e3dSdT„ƒZ4dUdV„Z5e6dWdX„ƒZ7e6dYdZ„ƒZ8e9d[d\„ƒZ:e9d]d^„ƒZ;d_d`„Zd S)irmzÍ :class:`OpenSSL.SSL.Context` instances define the parameters for setting up new SSL connections. :param method: One of SSLv2_METHOD, SSLv3_METHOD, SSLv23_METHOD, or TLSv1_METHOD. Z SSLv2_methodZ SSLv3_methodZ SSLv23_methodZ TLSv1_methodZTLSv1_1_methodZTLSv1_2_methodccs0|](\}}tt|dƒdk r|tt|ƒfVqdS)N)rÁrˆ)ršZ identifierÚnamersrsrtrœ¸szContext.cCs&t|tƒstdƒ‚y|j|}Wntk r<tdƒ‚YnX|ƒ}t|tjkƒt j |ƒ}t|tjkƒtj |t j ƒ}yt j |dƒ}t|dkƒWntk r¨YnX||_d|_d|_d|_d|_d|_d|_d|_d|_d|_d|_d|_d|_d|_d|_d|_d|_d|_ |j!t j"ƒdS)Nzmethod must be an integerzNo such protocolru)#r²r r´Ú_methodsÚKeyErrorrÂÚ_openssl_assertr–r·rˆZ SSL_CTX_newÚgcZ SSL_CTX_freeZSSL_CTX_set_ecdh_autoÚAttributeErrorÚ_contextÚ_passphrase_helperÚ_passphrase_callbackÚ_passphrase_userdataÚ_verify_helperÚ_verify_callbackÚ_info_callbackÚ_tlsext_servername_callbackÚ _app_dataÚ_npn_advertise_helperÚ_npn_advertise_callbackÚ_npn_select_helperÚ_npn_select_callbackÚ_alpn_select_helperÚ_alpn_select_callbackÚ _ocsp_helperÚ_ocsp_callbackÚ _ocsp_dataÚset_modeZSSL_MODE_ENABLE_PARTIAL_WRITE)r‚ÚmethodZ method_funcZ method_objÚcontextÚresrsrsrtrƒ¼sF   zContext.__init__NcCsN|dkrtj}nt|ƒ}|dkr(tj}nt|ƒ}tj|j||ƒ}|sJtƒdS)aU Let SSL know where we can find trusted certificates for the certificate chain. Note that the certificates have to be in PEM format. If capath is passed, it must be a directory prepared using the ``c_rehash`` tool included with OpenSSL. Either, but not both, of *pemfile* or *capath* may be :data:`None`. :param cafile: In which file we can find the certificates (``bytes`` or ``unicode``). :param capath: In which directory we can find the certificates (``bytes`` or ``unicode``). :return: None N)r–r·Ú _path_stringrˆZSSL_CTX_load_verify_locationsrØr„)r‚ÚcafileÚcapathZ load_resultrsrsrtÚload_verify_locationsês zContext.load_verify_locationscs&tˆƒ‡‡fdd„ƒ}tt|ddd�S)Ncsˆ||ˆjƒS)N)rÛ)ÚsizeZverifyÚuserdata)r”r‚rsrtr• sz'Context._wrap_callback..wrapperT)Z more_argsÚtruncate)rrr)r‚r”r•rs)r”r‚rtÚ_wrap_callback szContext._wrap_callbackcCs@t|ƒstdƒ‚|j|ƒ|_|jj|_tj|j|jƒ||_ dS)aò Set the passphrase callback. This function will be called when a private key with a passphrase is loaded. :param callback: The Python callback to use. This must accept three positional arguments. First, an integer giving the maximum length of the passphrase it may return. If the returned passphrase is longer than this, it will be truncated. Second, a boolean value which will be true if the user should be prompted for the passphrase twice and the callback should verify that the two values supplied are equal. Third, the value given as the *userdata* parameter to :meth:`set_passwd_cb`. The *callback* must return a byte string. If an error occurs, *callback* should return a false value (e.g. an empty string). :param userdata: (optional) A Python object which will be given as argument to the callback :return: None zcallback must be callableN) Úcallabler´rõrÙr”rÚrˆZSSL_CTX_set_default_passwd_cbrØrÛ)r‚r”rórsrsrtÚ set_passwd_cbs   zContext.set_passwd_cbcCsˆtj|jƒ}t|dkƒtjtjƒƒjdƒ}tjtjƒƒjdƒ}|j ||ƒs„tjtj ƒƒ}tjtj ƒƒ}|t kr„|t kr„|jttƒdS)aÙ Specify that the platform provided CA certificates are to be used for verification purposes. This method has some caveats related to the binary wheels that cryptography (pyOpenSSL's primary dependency) ships: * macOS will only load certificates using this method if the user has the ``openssl@1.1`` `Homebrew `_ formula installed in the default location. * Windows will not work. * manylinux1 cryptography wheels will work on most common Linux distributions in pyOpenSSL 17.1.0 and above. pyOpenSSL detects the manylinux1 wheel and attempts to load roots via a fallback path. :return: None ruÚasciiN)rˆZ SSL_CTX_set_default_verify_pathsrØrÕr–rÇZX509_get_default_cert_dir_envÚdecodeZX509_get_default_cert_file_envÚ_check_env_vars_setZX509_get_default_cert_dirZX509_get_default_cert_fileÚ_CRYPTOGRAPHY_MANYLINUX1_CA_DIRÚ _CRYPTOGRAPHY_MANYLINUX1_CA_FILEÚ_fallback_default_verify_pathsÚ_CERTIFICATE_FILE_LOCATIONSÚ_CERTIFICATE_PATH_LOCATIONS)r‚Ú set_resultÚ dir_env_varÚ file_env_varZ default_dirZ default_filersrsrtÚset_default_verify_paths-s      z Context.set_default_verify_pathscCs tjj|ƒdk ptjj|ƒdk S)zp Check to see if the default cert dir/file environment vars are present. :return: bool N)ÚosÚenvironÚget)r‚rrrsrsrtrú^szContext._check_env_vars_setcCsRx$|D]}tjj|ƒr|j|ƒPqWx&|D]}tjj|ƒr,|jd|ƒPq,WdS)aW Default verify paths are based on the compiled version of OpenSSL. However, when pyca/cryptography is compiled as a manylinux1 wheel that compiled location can potentially be wrong. So, like Go, we will try a predefined set of paths and attempt to load roots from there. :return: None N)rÚpathÚisfilerñÚisdir)r‚Z file_pathZdir_pathrïrðrsrsrtrýis      z&Context._fallback_default_verify_pathscCs$t|ƒ}tj|j|ƒ}|s tƒdS)zÍ Load a certificate chain from a file. :param certfile: The name of the certificate chain file (``bytes`` or ``unicode``). Must be PEM encoded. :return: None N)rîrˆZ"SSL_CTX_use_certificate_chain_filerØr„)r‚Úcertfiler’rsrsrtÚuse_certificate_chain_file}s  z"Context.use_certificate_chain_filecCs8t|ƒ}t|tƒstdƒ‚tj|j||ƒ}|s4tƒdS)ah Load a certificate from a file :param certfile: The name of the certificate file (``bytes`` or ``unicode``). :param filetype: (optional) The encoding of the file, which is either :const:`FILETYPE_PEM` or :const:`FILETYPE_ASN1`. The default is :const:`FILETYPE_PEM`. :return: None zfiletype must be an integerN)rîr²r r´rˆZSSL_CTX_use_certificate_filerØr„)r‚r ÚfiletypeÚ use_resultrsrsrtÚuse_certificate_fileŽs   zContext.use_certificate_filecCs0t|tƒstdƒ‚tj|j|jƒ}|s,tƒdS)zs Load a certificate from a X509 object :param cert: The X509 object :return: None zcert must be an X509 instanceN)r²rr´rˆZSSL_CTX_use_certificaterØÚ_x509r„)r‚r�r rsrsrtÚuse_certificate¤s  zContext.use_certificatecCsDt|tƒstdƒ‚tj|jƒ}tj|j|ƒ}|s@tj|ƒt ƒdS)z‰ Add certificate to chain :param certobj: The X509 certificate object to add to the chain :return: None z certobj must be an X509 instanceN) r²rr´rˆÚX509_duprZSSL_CTX_add_extra_chain_certrØZ X509_freer„)r‚ZcertobjÚcopyÚ add_resultrsrsrtÚadd_extra_chain_cert²s   zContext.add_extra_chain_certcCs |jdk r|jjtƒtƒdS)N)rÙr†rer„)r‚rsrsrtÚ_raise_passphrase_exceptionÃs  z#Context._raise_passphrase_exceptioncCsHt|ƒ}|tkrt}nt|tƒs(tdƒ‚tj|j||ƒ}|sD|j ƒdS)aR Load a private key from a file :param keyfile: The name of the key file (``bytes`` or ``unicode``) :param filetype: (optional) The encoding of the file, which is either :const:`FILETYPE_PEM` or :const:`FILETYPE_ASN1`. The default is :const:`FILETYPE_PEM`. :return: None zfiletype must be an integerN) rîÚ _UNSPECIFIEDrr²r r´rˆZSSL_CTX_use_PrivateKey_filerØr)r‚Zkeyfiler r rsrsrtÚuse_privatekey_fileÉs   zContext.use_privatekey_filecCs2t|tƒstdƒ‚tj|j|jƒ}|s.|jƒdS)zs Load a private key from a PKey object :param pkey: The PKey object :return: None zpkey must be a PKey instanceN)r²rr´rˆZSSL_CTX_use_PrivateKeyrØZ_pkeyr)r‚Zpkeyr rsrsrtÚuse_privatekeyàs  zContext.use_privatekeycCstj|jƒstƒdS)zß Check if the private key (loaded with :meth:`use_privatekey`) matches the certificate (loaded with :meth:`use_certificate`) :return: :data:`None` (raises :exc:`Error` if something's wrong) N)rˆZSSL_CTX_check_private_keyrØr„)r‚rsrsrtÚcheck_privatekeyîs zContext.check_privatekeycCs0tjtd|ƒƒ}t|tjkƒtj|j|ƒdS)a% Load the trusted certificates that will be sent to the client. Does not actually imply any of the certificates are trusted; that must be configured separately. :param bytes cafile: The path to a certificates file in PEM format. :return: None rïN)rˆZSSL_load_client_CA_fileÚ_text_to_bytes_and_warnrÕr–r·ÚSSL_CTX_set_client_CA_listrØ)r‚rïZca_listrsrsrtÚload_client_caøs  zContext.load_client_cacCs*td|ƒ}ttj|j|t|ƒƒdkƒdS)aV Set the session id to *buf* within which a session can be reused for this Context object. This is needed when doing session resumption, because there is no way for a stored session to know which Context object it is associated with. :param bytes buf: The session id. :returns: None ÚbufruN)rrÕrˆZSSL_CTX_set_session_id_contextrØr™)r‚rrsrsrtÚset_session_ids zContext.set_session_idcCs t|tƒstdƒ‚tj|j|ƒS)aŽ Set the behavior of the session cache used by all connections using this Context. The previously set mode is returned. See :const:`SESS_CACHE_*` for details about particular modes. :param mode: One or more of the SESS_CACHE_* flags (combine using bitwise or) :returns: The previously set caching mode. .. versionadded:: 0.14 zmode must be an integer)r²r r´rˆZSSL_CTX_set_session_cache_moderØ)r‚ÚmodersrsrtÚset_session_cache_modes zContext.set_session_cache_modecCs tj|jƒS)z‡ Get the current session cache mode. :returns: The currently used cache mode. .. versionadded:: 0.14 )rˆZSSL_CTX_get_session_cache_moderØ)r‚rsrsrtÚget_session_cache_mode,szContext.get_session_cache_modecCsLt|tƒstdƒ‚t|ƒs"tdƒ‚t|ƒ|_|jj|_tj |j ||jƒdS)a„ et the verification flags for this Context object to *mode* and specify that *callback* should be used for verification callbacks. :param mode: The verify mode, this should be one of :const:`VERIFY_NONE` and :const:`VERIFY_PEER`. If :const:`VERIFY_PEER` is used, *mode* can be OR:ed with :const:`VERIFY_FAIL_IF_NO_PEER_CERT` and :const:`VERIFY_CLIENT_ONCE` to further control the behaviour. :param callback: The Python callback to use. This should take five arguments: A Connection object, an X509 object, and three integer variables, which are in turn potential error number, error depth and return code. *callback* should return True if verification passes and False otherwise. :return: None See SSL_CTX_set_verify(3SSL) for further details. zmode must be an integerzcallback must be callableN) r²r r´rör‡rÜr”rÝrˆZSSL_CTX_set_verifyrØ)r‚rr”rsrsrtÚ set_verify6s   zContext.set_verifycCs$t|tƒstdƒ‚tj|j|ƒdS)zÙ Set the maximum depth for the certificate chain verification that shall be allowed for this Context object. :param depth: An integer specifying the verify depth :return: None zdepth must be an integerN)r²r r´rˆZSSL_CTX_set_verify_depthrØ)r‚ÚdepthrsrsrtÚset_verify_depthSs zContext.set_verify_depthcCs tj|jƒS)z„ Retrieve the Context object's verify mode, as set by :meth:`set_verify`. :return: The verify mode )rˆZSSL_CTX_get_verify_moderØ)r‚rsrsrtÚget_verify_mode`szContext.get_verify_modecCs tj|jƒS)zŒ Retrieve the Context object's verify depth, as set by :meth:`set_verify_depth`. :return: The verify depth )rˆZSSL_CTX_get_verify_depthrØ)r‚rsrsrtÚget_verify_depthiszContext.get_verify_depthcCsht|ƒ}tj|dƒ}|tjkr$tƒtj|tjƒ}tj|tjtjtjƒ}tj|tj ƒ}tj |j |ƒdS)zº Load parameters for Ephemeral Diffie-Hellman :param dhfile: The file to load EDH parameters from (``bytes`` or ``unicode``). :return: None órN) rîrˆZ BIO_new_filer–r·r„rÖZBIO_freeZPEM_read_bio_DHparamsZDH_freeZSSL_CTX_set_tmp_dhrØ)r‚ZdhfileÚbioZdhrsrsrtÚ load_tmp_dhrs   zContext.load_tmp_dhcCstj|j|jƒƒdS)a  Select a curve to use for ECDHE key exchange. :param curve: A curve object to use as returned by either :meth:`OpenSSL.crypto.get_elliptic_curve` or :meth:`OpenSSL.crypto.get_elliptic_curves`. :return: None N)rˆZSSL_CTX_set_tmp_ecdhrØZ _to_EC_KEY)r‚ZcurversrsrtÚ set_tmp_ecdh†s zContext.set_tmp_ecdhcCsVtd|ƒ}t|tƒstdƒ‚ttj|j|ƒdkƒt|dƒ}t|j ƒdddgkƒdS)zó Set the list of ciphers to be used in this context. See the OpenSSL manual for more information (e.g. :manpage:`ciphers(1)`). :param bytes cipher_list: An OpenSSL cipher string. :return: None Ú cipher_listz"cipher_list must be a byte string.ruNZTLS_AES_256_GCM_SHA384ZTLS_CHACHA20_POLY1305_SHA256ZTLS_AES_128_GCM_SHA256) rr²Úbytesr´rÕrˆZSSL_CTX_set_cipher_listrØrnÚget_cipher_list)r‚r+ZtmpconnrsrsrtÚset_cipher_list’s   zContext.set_cipher_listc Cs´tjƒ}t|tjkƒyjxd|D]\}t|tƒs@tdt|ƒj fƒ‚tj |j ƒ}t|tjkƒtj ||ƒ}|stj |ƒtƒqWWn tk r tj|ƒ‚YnXtj|j|ƒdS)a_ Set the list of preferred client certificate signers for this server context. This list of certificate authorities will be sent to the client when the server requests a client certificate. :param certificate_authorities: a sequence of X509Names. :return: None .. versionadded:: 0.10 z3client CAs must be X509Name objects, not %s objectsN)rˆZsk_X509_NAME_new_nullrÕr–r·r²rr´rÈrpÚ X509_NAME_dupÚ_nameZsk_X509_NAME_pushÚX509_NAME_freer„rŒZsk_X509_NAME_freerrØ)r‚Zcertificate_authoritiesZ name_stackZca_namerZ push_resultrsrsrtÚset_client_ca_list²s$       zContext.set_client_ca_listcCs2t|tƒstdƒ‚tj|j|jƒ}t|dkƒdS)ai Add the CA certificate to the list of preferred signers for this context. The list of certificate authorities will be sent to the client when the server requests a client certificate. :param certificate_authority: certificate authority's X509 certificate. :return: None .. versionadded:: 0.10 z.certificate_authority must be an X509 instanceruN)r²rr´rˆZSSL_CTX_add_client_CArØrrÕ)r‚Zcertificate_authorityrrsrsrtÚ add_client_ca×s  zContext.add_client_cacCs t|tƒstdƒ‚tj|j|ƒS)aQ Set the timeout for newly created sessions for this Context object to *timeout*. The default value is 300 seconds. See the OpenSSL manual for more information (e.g. :manpage:`SSL_CTX_set_timeout(3)`). :param timeout: The timeout in (whole) seconds :return: The previous session timeout ztimeout must be an integer)r²r r´rˆZSSL_CTX_set_timeoutrØ)r‚ZtimeoutrsrsrtÚ set_timeoutës zContext.set_timeoutcCs tj|jƒS)z” Retrieve session timeout, as set by :meth:`set_timeout`. The default is 300 seconds. :return: The session timeout )rˆZSSL_CTX_get_timeoutrØ)r‚rsrsrtÚ get_timeoutùszContext.get_timeoutcs6tˆƒ‡fdd„ƒ}tjd|ƒ|_tj|j|jƒdS)að Set the information callback to *callback*. This function will be called from time to time during SSL handshakes. :param callback: The Python callback to use. This should take three arguments: a Connection object and two integers. The first integer specifies where in the SSL handshake the function was called, and the other the return code from a (possibly failed) internal function call. :return: None csˆtj|||ƒdS)N)rnr‹)r‘ÚwhereZ return_code)r”rsrtr•sz*Context.set_info_callback..wrapperzvoid (*)(const SSL *, int, int)N)rr–r”rÞrˆZSSL_CTX_set_info_callbackrØ)r‚r”r•rs)r”rtÚset_info_callbacks  zContext.set_info_callbackcCs|jS)zw Get the application data (supplied via :meth:`set_app_data()`) :return: The application data )rà)r‚rsrsrtÚ get_app_dataszContext.get_app_datacCs ||_dS)z� Set the application data (will be returned from get_app_data()) :param data: Any Python object :return: None N)rà)r‚rºrsrsrtÚ set_app_dataszContext.set_app_datacCs.tj|jƒ}|tjkrdStjtƒ}||_|S)zú Get the certificate store for the context. This can be used to add "trusted" certificates without using the :meth:`load_verify_locations` method. :return: A X509Store object or None if it does not have one. N)rˆZSSL_CTX_get_cert_storerØr–r·rÚ__new__Z_store)r‚ZstoreZpystorersrsrtÚget_cert_store&s    zContext.get_cert_storecCs t|tƒstdƒ‚tj|j|ƒS)zÝ Add options. Options set before are not cleared! This method should be used with the :const:`OP_*` constants. :param options: The options to add. :return: The new option bitmask. zoptions must be an integer)r²r r´rˆZSSL_CTX_set_optionsrØ)r‚ZoptionsrsrsrtÚ set_options7s zContext.set_optionscCs t|tƒstdƒ‚tj|j|ƒS)zà Add modes via bitmask. Modes set before are not cleared! This method should be used with the :const:`MODE_*` constants. :param mode: The mode to add. :return: The new mode bitmask. zmode must be an integer)r²r r´rˆZSSL_CTX_set_moderØ)r‚rrsrsrtrêDs zContext.set_modecs6tˆƒ‡fdd„ƒ}tjd|ƒ|_tj|j|jƒdS)a Specify a callback function to be called when clients specify a server name. :param callback: The callback function. It will be invoked with one argument, the Connection instance. .. versionadded:: 0.13 csˆtj|ƒdS)Nr)rnr‹)r‘Zalertr£)r”rsrtr•\sz7Context.set_tlsext_servername_callback..wrapperzint (*)(SSL *, int *, void *)N)rr–r”rßrˆZ&SSL_CTX_set_tlsext_servername_callbackrØ)r‚r”r•rs)r”rtÚset_tlsext_servername_callbackQs  z&Context.set_tlsext_servername_callbackcCs,t|tƒstdƒ‚ttj|j|ƒdkƒdS)z÷ Enable support for negotiating SRTP keying material. :param bytes profiles: A colon delimited list of protection profile names, like ``b'SRTP_AES128_CM_SHA1_80:SRTP_AES128_CM_SHA1_32'``. :return: None zprofiles must be a byte string.rN)r²r,r´rÕrˆZSSL_CTX_set_tlsext_use_srtprØ)r‚ZprofilesrsrsrtÚset_tlsext_use_srtpfs zContext.set_tlsext_use_srtpcCs,t|ƒ|_|jj|_tj|j|jtjƒdS)aò Specify a callback function that will be called when offering `Next Protocol Negotiation `_ as a server. :param callback: The callback function. It will be invoked with one argument, the :class:`Connection` instance. It should return a list of bytestrings representing the advertised protocols, like ``[b'http/1.1', b'spdy/2']``. .. versionadded:: 0.15 N) r—rár”rârˆZ%SSL_CTX_set_next_protos_advertised_cbrØr–r·)r‚r”rsrsrtÚset_npn_advertise_callbackus  z"Context.set_npn_advertise_callbackcCs,t|ƒ|_|jj|_tj|j|jtjƒdS)a Specify a callback function that will be called when a server offers Next Protocol Negotiation options. :param callback: The callback function. It will be invoked with two arguments: the Connection, and a list of offered protocols as bytestrings, e.g. ``[b'http/1.1', b'spdy/2']``. It should return one of those bytestrings, the chosen protocol. .. versionadded:: 0.15 N) r§rãr”rärˆZ SSL_CTX_set_next_proto_select_cbrØr–r·)r‚r”rsrsrtÚset_npn_select_callbackˆs  zContext.set_npn_select_callbackcCs>djtjdd„|Dƒƒƒ}tjd|ƒ}tj|j|t|ƒƒdS)a• Specify the protocols that the client is prepared to speak after the TLS connection has been negotiated using Application Layer Protocol Negotiation. :param protos: A list of the protocols to be offered to the server. This list should be a Python list of bytestrings representing the protocols to offer, e.g. ``[b'http/1.1', b'spdy/2']``. r˜css|]}tt|ƒƒ|fVqdS)N)r r™)ršr›rsrsrtrœ¨sz*Context.set_alpn_protos..zunsigned char[]N) r�rržr–rŸrˆZSSL_CTX_set_alpn_protosrØr™)r‚r¥r¦Ú input_strrsrsrtÚset_alpn_protosšs  zContext.set_alpn_protoscCs,t|ƒ|_|jj|_tj|j|jtjƒdS)a¢ Specify a callback function that will be called on the server when a client offers protocols using ALPN. :param callback: The callback function. It will be invoked with two arguments: the Connection, and a list of offered protocols as bytestrings, e.g ``[b'http/1.1', b'spdy/2']``. It should return one of those bytestrings, the chosen protocol. N) r±rår”rærˆZSSL_CTX_set_alpn_select_cbrØr–r·)r‚r”rsrsrtÚset_alpn_select_callback°s  z Context.set_alpn_select_callbackcCsh||_|j|_|dkr tj|_n tj|ƒ|_tj|j |jƒ}t |dkƒtj |j |jƒ}t |dkƒdS)z© This internal helper does the common work for ``set_ocsp_server_callback`` and ``set_ocsp_client_callback``, which is almost all of it. Nru) rçr”rèr–r·réZ new_handlerˆZSSL_CTX_set_tlsext_status_cbrØrÕZSSL_CTX_set_tlsext_status_arg)r‚ÚhelperrºÚrcrsrsrtÚ_set_ocsp_callbackÀs    zContext._set_ocsp_callbackcCst|ƒ}|j||ƒdS)aû Set a callback to provide OCSP data to be stapled to the TLS handshake on the server side. :param callback: The callback function. It will be invoked with two arguments: the Connection, and the optional arbitrary data you have provided. The callback must return a bytestring that contains the OCSP data to staple to the handshake. If no OCSP data is available for this connection, return the empty bytestring. :param data: Some opaque data that will be passed into the callback function when called. This can be used to avoid needing to do complex data lookups or to keep track of what context is being used. This parameter is optional. N)r¶rF)r‚r”rºrDrsrsrtÚset_ocsp_server_callbackÔsz Context.set_ocsp_server_callbackcCst|ƒ}|j||ƒdS)a� Set a callback to validate OCSP data stapled to the TLS handshake on the client side. :param callback: The callback function. It will be invoked with three arguments: the Connection, a bytestring containing the stapled OCSP assertion, and the optional arbitrary data you have provided. The callback must return a boolean that indicates the result of validating the OCSP data: ``True`` if the OCSP data is valid and the certificate can be trusted, or ``False`` if either the OCSP data is invalid or the certificate has been revoked. :param data: Some opaque data that will be passed into the callback function when called. This can be used to avoid needing to do complex data lookups or to keep track of what context is being used. This parameter is optional. N)r¼rF)r‚r”rºrDrsrsrtÚset_ocsp_client_callbackæsz Context.set_ocsp_client_callback)N)N)N)N)?rprqrrrr%r&r'r(r)r*rÓÚdictÚitemsrƒrñrõr÷rrúrýr rrrrrrrrrrrr r!r"r$r%r&r)r*r.r2r3r4r5r7r8r9r;r<rêÚ _requires_snir=r>Ú _requires_npnr?r@Ú_requires_alpnrBrCrFrGrHrsrsrsrtrm§sn.  1          %         z4ContextType has been deprecated, use Context insteadc@seZdZdZeƒZdxdd„Zdd„Zdd„Zd d „Z d d „Z e d d„ƒZ e dd„ƒZ dd„Zdydd„ZeZdzdd„Zd{dd„ZeZd|dd„Zdd„Zdd„Zd d!„Zd"d#„Zd$d%„Zd&d'„Zd(d)„Zd*d+„Zd,d-„Zd.d/„Zd0d1„Zd2d3„Z d4d5„Z!d6d7„Z"d8d9„Z#d:d;„Z$dd?„Z&d@dA„Z'dBdC„Z(dDdE„Z)dFdG„Z*dHdI„Z+d}dJdK„Z,dLdM„Z-dNdO„Z.dPdQ„Z/dRdS„Z0dTdU„Z1dVdW„Z2dXdY„Z3dZd[„Z4d\d]„Z5d^d_„Z6d`da„Z7dbdc„Z8ddde„Z9dfdg„Z:dhdi„Z;djdk„Ze?dpdq„ƒZ@eAdrds„ƒZBeAdtdu„ƒZCdvdw„ZDdS)~rnz NcCst|tƒstdƒ‚tj|jƒ}tj|tjƒ|_ tj |j tj ƒ||_d|_ d|_ d|_d|_||j|j <|dkrÌd|_tjtjƒƒ|_t|jtjkƒtjtjƒƒ|_t|jtjkƒtj|j |j|jƒn2d|_d|_||_tj|j t|jƒƒ}t|dkƒdS)zò Create a new Connection object, using the given OpenSSL.SSL.Context instance and socket. :param context: An SSL Context to use for this connection :param socket: The socket to use for transport layer z"context must be a Context instanceNru)r²rmr´rˆZSSL_newrØr–rÖZSSL_freeÚ_sslZ SSL_set_modeZSSL_MODE_AUTO_RETRYràr r©rµr‹Ú_socketZBIO_newZ BIO_s_memÚ _into_sslrÕr·Ú _from_sslZ SSL_set_bioZ SSL_set_fdrÆ)r‚rìÚsocketr‘rrsrsrtrƒs0   zConnection.__init__cCs0|jdkr td|jj|fƒ‚n t|j|ƒSdS)zy Look up attributes on the wrapped socket object if they are not found on the Connection object. Nz!'%s' object has no attribute '%s')rOr×Ú __class__rprÁ)r‚rÒrsrsrtÚ __getattr__<s zConnection.__getattr__cCsT|jjdk r|jjjƒ|jjdk r0|jjjƒ|jjdk rH|jjjƒ|jjdk r`|jjjƒ|jjdk rx|jjjƒtj||ƒ}|tj kr–t ƒ‚nº|tj kr¨t ƒ‚n¨|tj krºtƒ‚n–|tjkrÌtƒ‚n„|tjk�r Retrieve the protocol version of the current connection. :returns: The TLS version of the current connection, for example the value for TLS 1.2 would be ``TLSv1.2``or ``Unknown`` for connections that were not successfully established. :rtype: :class:`unicode` zutf-8)r–rÇrˆZSSL_get_versionrNrù)r‚r rsrsrtÚget_protocol_version_namef s z$Connection.get_protocol_version_namecCstj|jƒ}|S)a  Retrieve the SSL or TLS protocol version of the current connection. :returns: The TLS version of the current connection. For example, it will return ``0x769`` for connections made over TLS version 1. :rtype: :class:`int` )rˆZ SSL_versionrN)r‚r rsrsrtÚget_protocol_versionr s zConnection.get_protocol_versioncCs@tjdƒ}tjdƒ}tj|j||ƒtj|d|dƒdd…S)zâ Get the protocol that was negotiated by NPN. :returns: A bytestring of the protocol name. If no protocol has been negotiated yet, returns an empty string. .. versionadded:: 0.15 zunsigned char **zunsigned int *rN)r–rŸrˆZSSL_get0_next_proto_negotiatedrNr¨)r‚rºÚdata_lenrsrsrtÚget_next_proto_negotiated} s  z$Connection.get_next_proto_negotiatedcCs>djtjdd„|Dƒƒƒ}tjd|ƒ}tj|j|t|ƒƒdS)ah Specify the client's ALPN protocol list. These protocols are offered to the server during protocol negotiation. :param protos: A list of the protocols to be offered to the server. This list should be a Python list of bytestrings representing the protocols to offer, e.g. ``[b'http/1.1', b'spdy/2']``. r˜css|]}tt|ƒƒ|fVqdS)N)r r™)ršr›rsrsrtrœœ sz-Connection.set_alpn_protos..zunsigned char[]N) r�rržr–rŸrˆZSSL_set_alpn_protosrNr™)r‚r¥r¦rArsrsrtrBŽ s  zConnection.set_alpn_protoscCsHtjdƒ}tjdƒ}tj|j||ƒ|s,dStj|d|dƒdd…S)zà Get the protocol that was negotiated by ALPN. :returns: A bytestring of the protocol name. If no protocol has been negotiated yet, returns an empty string. zunsigned char **zunsigned int *r˜rN)r–rŸrˆZSSL_get0_alpn_selectedrNr¨)r‚rºr¤rsrsrtÚget_alpn_proto_negotiated¤ s   z$Connection.get_alpn_proto_negotiatedcCs tj|jtjƒ}t|dkƒdS)a Called to request that the server sends stapled OCSP data, if available. If this is not called on the client side then the server will not send OCSP data. Should be used in conjunction with :meth:`Context.set_ocsp_client_callback`. ruN)rˆZSSL_set_tlsext_status_typerNZTLSEXT_STATUSTYPE_ocsprÕ)r‚rErsrsrtÚ request_ocsp¶ s zConnection.request_ocsp)N)r)r)N)NN)N)Erprqrrrrr‹rƒrTrVrWrXrKrYr[r\rbÚwriterdrjÚreadrlrnrorprrrsrqrtrvrxrzr|r}r-r�r‚r8r9rƒr…r†rŠr‹rŒrŽr�r�r‘r’r“r”r{ryr–r—r™ršr›ržrŸr¡r¢r£rLr¥rMrBr¦r§rsrsrsrtrns| 6 )    $  %                   "      z:ConnectionType has been deprecated, use Connection instead)ÔrrRÚsysrÚ functoolsrrÚ itertoolsrrÚweakrefrrUrZcryptography.utilsr Zsixr r³r r r Z OpenSSL._utilrrrZ_exception_from_error_queuerr–rrˆrZ _make_assertrr~rrîrrrreZOpenSSL.cryptorrrrrrÚ__all__r¨roÚ NameErrorÚobjectrrrr r!r"ZSSL_SENT_SHUTDOWNr#ZSSL_RECEIVED_SHUTDOWNr$r%r&r'r(r)r*ZSSL_OP_NO_SSLv2r+ZSSL_OP_NO_SSLv3r,ZSSL_OP_NO_TLSv1r-ZSSL_OP_NO_TLSv1_1r.ZSSL_OP_NO_TLSv1_2r/ZSSL_MODE_RELEASE_BUFFERSr0ZSSL_OP_SINGLE_DH_USEr1ZSSL_OP_SINGLE_ECDH_USEr2ZSSL_OP_EPHEMERAL_RSAr3ZSSL_OP_MICROSOFT_SESS_ID_BUGr4ZSSL_OP_NETSCAPE_CHALLENGE_BUGr5Z'SSL_OP_NETSCAPE_REUSE_CIPHER_CHANGE_BUGr6Z"SSL_OP_SSLREF2_REUSE_CERT_TYPE_BUGr7Z!SSL_OP_MICROSOFT_BIG_SSLV3_BUFFERr8ZSSL_OP_MSIE_SSLV2_RSA_PADDINGr9ZSSL_OP_SSLEAY_080_CLIENT_DH_BUGr:ZSSL_OP_TLS_D5_BUGr;ZSSL_OP_TLS_BLOCK_PADDING_BUGr<Z"SSL_OP_DONT_INSERT_EMPTY_FRAGMENTSr=ZSSL_OP_CIPHER_SERVER_PREFERENCEr>ZSSL_OP_TLS_ROLLBACK_BUGr?ZSSL_OP_PKCS1_CHECK_1r@ZSSL_OP_PKCS1_CHECK_2rAZSSL_OP_NETSCAPE_CA_DN_BUGrBZ&SSL_OP_NETSCAPE_DEMO_CIPHER_CHANGE_BUGrCZSSL_OP_NO_COMPRESSIONrDZSSL_OP_NO_QUERY_MTUrEZSSL_OP_COOKIE_EXCHANGErFZSSL_OP_NO_TICKETrGZ SSL_OP_ALLrHZSSL_VERIFY_PEERrIZSSL_VERIFY_FAIL_IF_NO_PEER_CERTrJZSSL_VERIFY_CLIENT_ONCErKZSSL_VERIFY_NONErLZSSL_SESS_CACHE_OFFrMZSSL_SESS_CACHE_CLIENTrNZSSL_SESS_CACHE_SERVERrOZSSL_SESS_CACHE_BOTHrPZSSL_SESS_CACHE_NO_AUTO_CLEARrQZ!SSL_SESS_CACHE_NO_INTERNAL_LOOKUPrRZ SSL_SESS_CACHE_NO_INTERNAL_STORErSZSSL_SESS_CACHE_NO_INTERNALrTrUrVrWZCryptography_HAS_SSL_STr{r|r}r~ÚextendrXrYrZr[r\r]r^r_r`rarbrcrdrþrÿrûrürŒrer„rÕrfrgrhrirjr€r‡r—r§r±r¶r¼rÆrkrÑZCryptography_HAS_NEXTPROTONEGrLZCryptography_HAS_ALPNrMZ Cryptography_HAS_TLSEXT_HOSTNAMErKrlrmrpÚDeprecationWarningZ ContextTypernZConnectionTypeZSSL_library_initrsrsrsrtÚsÔ    ,  ')13C;     ZI