§
    8·tc"  ã                   óV   — d dl T d dlmZmZmZmZ d dlmZmZm	Z	 ddgZ
	 	 d	d„Zd
d„ZdS )é    )Ú*)ÚDerNullÚDerSequenceÚDerObjectIdÚDerOctetString)ÚPBES1ÚPBES2Ú	PbesErrorÚwrapÚunwrapNc                 ó@  — |€t          ¦   «         }t          dt          t          |¦  «        |g¦  «        t          | ¦  «        g¦  «        }|                     ¦   «         }|€|S |st          d¦  «        ‚t          |¦  «        }|€d}t          j        |||||¦  «        S )aö
  Wrap a private key into a PKCS#8 blob (clear or encrypted).

    Args:

      private_key (byte string):
        The private key encoded in binary form. The actual encoding is
        algorithm specific. In most cases, it is DER.

      key_oid (string):
        The object identifier (OID) of the private key to wrap.
        It is a dotted string, like ``1.2.840.113549.1.1.1`` (for RSA keys).

      passphrase (bytes string or string):
        The secret passphrase from which the wrapping key is derived.
        Set it only if encryption is required.

      protection (string):
        The identifier of the algorithm to use for securely wrapping the key.
        The default value is ``PBKDF2WithHMAC-SHA1AndDES-EDE3-CBC``.

      prot_params (dictionary):
        Parameters for the protection algorithm.

        +------------------+-----------------------------------------------+
        | Key              | Description                                   |
        +==================+===============================================+
        | iteration_count  | The KDF algorithm is repeated several times to|
        |                  | slow down brute force attacks on passwords    |
        |                  | (called *N* or CPU/memory cost in scrypt).    |
        |                  | The default value for PBKDF2 is 1000.         |
        |                  | The default value for scrypt is 16384.        |
        +------------------+-----------------------------------------------+
        | salt_size        | Salt is used to thwart dictionary and rainbow |
        |                  | attacks on passwords. The default value is 8  |
        |                  | bytes.                                        |
        +------------------+-----------------------------------------------+
        | block_size       | *(scrypt only)* Memory-cost (r). The default  |
        |                  | value is 8.                                   |
        +------------------+-----------------------------------------------+
        | parallelization  | *(scrypt only)* CPU-cost (p). The default     |
        |                  | value is 1.                                   |
        +------------------+-----------------------------------------------+

      key_params (DER object):
        The algorithm parameters associated to the private key.
        It is required for algorithms like DSA, but not for others like RSA.

      randfunc (callable):
        Random number generation function; it should accept a single integer
        N and return a string of random data, N bytes long.
        If not specified, a new RNG will be instantiated
        from :mod:`Cryptodome.Random`.

    Return:
      The PKCS#8-wrapped private key (possibly encrypted), as a byte string.
    Nr   zEmpty passphrasez"PBKDF2WithHMAC-SHA1AndDES-EDE3-CBC)	r   r   r   r   ÚencodeÚ
ValueErrorÚtobytesr	   Úencrypt)	Úprivate_keyÚkey_oidÚ
passphraseÚ
protectionÚprot_paramsÚ
key_paramsÚrandfuncÚpk_infoÚpk_info_ders	            ú5/usr/lib/python3/dist-packages/Cryptodome/IO/PKCS8.pyr   r   2   sÇ   € ðv ÐÝ‘Y”Yˆ
õ ØÝÝ Ñ(Ô(Øðñ ô õ ˜{Ñ+Ô+ðñ ô €Gð —.’.Ñ"Ô"€KàÐØÐàð -ÝÐ+Ñ,Ô,Ð,õ ˜Ñ$Ô$€JØÐØ9ˆ
ÝŒ=˜ jØ# [°(ñ<ô <ð <ó    c                 ó  — |rËt          |¦  «        }d}	 t          j        | |¦  «        } d}n6# t          $ r}dt	          |¦  «        z  }Y d}~nd}~wt
          $ r d}Y nw xY w|sU	 t          j        | |¦  «        } d}n<# t          $ r}|dt	          |¦  «        z  z  }Y d}~nd}~wt
          $ r |dz  }Y nw xY w|st          d|z  ¦  «        ‚t          ¦   «                              | d	¬
¦  «        }t          |¦  «        dk    r|st          d¦  «        ‚|d         dk    rt          d¦  «        ‚t          ¦   «                              |d         d¬
¦  «        }t          ¦   «                              |d         ¦  «        j        }t          |¦  «        dk    rd}n:	 t          ¦   «                              |d         ¦  «         d}n#  |d         }Y nxY wt          ¦   «                              |d         ¦  «        j        }	||	|fS )aH  Unwrap a private key from a PKCS#8 blob (clear or encrypted).

    Args:
      p8_private_key (byte string):
        The private key wrapped into a PKCS#8 blob, DER encoded.
      passphrase (byte string or string):
        The passphrase to use to decrypt the blob (if it is encrypted).

    Return:
      A tuple containing

       #. the algorithm identifier of the wrapped key (OID, dotted string)
       #. the private key (byte string, DER encoded)
       #. the associated parameters (byte string, DER encoded) or ``None``

    Raises:
      ValueError : if decoding fails
    FTz	PBES1[%s]NzPBES1[Invalid]z
,PBES2[%s]z,PBES2[Invalid]zError decoding PKCS#8 (%s))é   é   é   )Únr_elementsr   z;Not a valid clear PKCS#8 structure (maybe it is encrypted?)r   z#Not a valid PrivateKeyInfo SEQUENCEé   )r"   r   )r   r   Údecryptr
   Ústrr   r	   r   ÚdecodeÚlenr   Úvaluer   r   Úpayload)
Úp8_private_keyr   ÚfoundÚeÚ	error_strr   ÚalgoÚalgo_oidÚalgo_paramsr   s
             r   r   r   �   s_  € ð( ð GÝ˜ZÑ(Ô(ˆ
àˆð	)Ý"œ]¨>¸:ÑFÔFˆNØˆEˆEøÝð 	-ð 	-ð 	-Ø#¥c¨!¡f¤fÑ,ˆIˆIˆIˆIˆIˆIøøøøÝð 	)ð 	)ð 	)Ø(ˆIˆIˆIð	)øøøð ð 	/ð/Ý!&¤¨~¸zÑ!JÔ!J�Ø��øÝð 3ð 3ð 3Ø˜\­C°©F¬FÑ2Ñ2�	�	�	�	�	�	øøøøÝð /ð /ð /ØÐ.Ñ.�	�	�	ð/øøøð ð 	GÝÐ9¸IÑEÑFÔFÐFå‰mŒm×"Ò" >¸yÐ"ÑIÔI€GÝ
ˆ7�|„|�qÒÐ ÐÝð 4ñ 5ô 5ð 	5ð ˆq„z�Q‚€ÝÐ>Ñ?Ô?Ð?õ ‰=Œ=×Ò ¨¤
¸ÐÑ?Ô?€DÝ‰}Œ}×#Ò# D¨¤GÑ,Ô,Ô2€HÝ
ˆ4�y„y�A‚~€~Øˆˆð	"Ý‰IŒI×Ò˜T !œWÑ%Ô%Ð%ØˆKˆKøð	"Ø˜qœ'ˆKˆKˆKøøøõ !Ñ"Ô"×)Ò)¨'°!¬*Ñ5Ô5Ô=€Kà�k ;Ð/Ð/sD   •- ­
A ·AÁA ÁA Á&A> Á>
B7ÂB"Â"B7Â6B7Æ)G Ç
G)NNNNN)N)ÚCryptodome.Util.py3compatÚCryptodome.Util.asn1r   r   r   r   ÚCryptodome.IO._PBESr   r	   r
   Ú__all__r   r   © r   r   ú<module>r5      sÂ   ððF (Ð 'Ð 'Ð 'ðð ð ð ð ð ð ð ð ð ð ð ð 8Ð 7Ð 7Ð 7Ð 7Ð 7Ð 7Ð 7Ð 7Ð 7ð �8Ð
€ð <@Ø59ð[<ð [<ð [<ð [<ð|W0ð W0ð W0ð W0ð W0ð W0r   