§
    8·tcçp  ã                   óä   — g d ¢Z ddlZddlZddlmZ ddlmZmZmZ ddl	m
Z
 ddlmZ ddlmZmZmZ ddlmZmZmZ  G d	„ d
e¦  «        Zdd„Zdd„Zd„ Zd„ Zd„ Zd„ Zd„ Zd„ Zd„ Zdd„Z e Z!dZ"dS ))ÚgenerateÚ	constructÚ
import_keyÚRsaKeyÚoidé    N)ÚRandom)ÚtobytesÚbordÚtostr)ÚDerSequence)ÚInteger)Útest_probable_primeÚgenerate_probable_primeÚ	COMPOSITE)Ú_expand_subject_public_key_infoÚ_create_subject_public_key_infoÚ _extract_subject_public_key_infoc                   ó(  — e Zd ZdZd„ Zed„ ¦   «         Zed„ ¦   «         Zed„ ¦   «         Zed„ ¦   «         Z	ed„ ¦   «         Z
ed„ ¦   «         Zd	„ Zd
„ Zd„ Zd„ Zd„ Zd„ Zd„ Zd„ Zd„ Zd„ Zd„ Zd„ Zd„ Z	 	 d!d„ZeZeZd„ Zd„ Zd„ Zd„ Zd„ Z d„ Z!d „ Z"dS )"r   aP  Class defining an actual RSA key.
    Do not instantiate directly.
    Use :func:`generate`, :func:`construct` or :func:`import_key` instead.

    :ivar n: RSA modulus
    :vartype n: integer

    :ivar e: RSA public exponent
    :vartype e: integer

    :ivar d: RSA private exponent
    :vartype d: integer

    :ivar p: First factor of the RSA modulus
    :vartype p: integer

    :ivar q: Second factor of the RSA modulus
    :vartype q: integer

    :ivar u: Chinese remainder component (:math:`p^{-1} \text{mod } q`)
    :vartype u: integer

    :undocumented: exportKey, publickey
    c                 ó|  — t          |                     ¦   «         ¦  «        }t          d¦  «        }|t          d¦  «        z  }|||fvrt          d¦  «        ‚|                     ¦   «         D ]\  }}t	          | d|z   |¦  «         Œ||k    r0| j        | j        dz
  z  | _        | j        | j        dz
  z  | _	        dS dS )a.  Build an RSA key.

        :Keywords:
          n : integer
            The modulus.
          e : integer
            The public exponent.
          d : integer
            The private exponent. Only required for private keys.
          p : integer
            The first factor of the modulus. Only required for private keys.
          q : integer
            The second factor of the modulus. Only required for private keys.
          u : integer
            The CRT coefficient (inverse of p modulo q). Only required for
            private keys.
        ©ÚnÚe)ÚpÚqÚdÚuzSome RSA components are missingÚ_é   N)
ÚsetÚkeysÚ
ValueErrorÚitemsÚsetattrÚ_dÚ_pÚ_dpÚ_qÚ_dq)ÚselfÚkwargsÚ	input_setÚ
public_setÚprivate_setÚ	componentÚvalues          ú:/usr/lib/python3/dist-packages/Cryptodome/PublicKey/RSA.pyÚ__init__zRsaKey.__init__M   sÊ   € õ& ˜Ÿš™œÑ&Ô&ˆ	Ý˜‘_”_ˆ
Ø ¥3Ð';Ñ#<Ô#<Ñ<ˆØ˜[¨*Ð5Ð5Ð5ÝÐ>Ñ?Ô?Ð?Ø &§¢¡¤ð 	2ð 	2ÑˆI�uÝ�D˜# 	™/¨5Ñ1Ô1Ð1Ð1Ø˜Ò#Ð#Ø”w $¤'¨A¡+Ñ.ˆDŒHØ”w $¤'¨A¡+Ñ.ˆDŒHˆHˆHð $Ð#ó    c                 ó*   — t          | j        ¦  «        S ©N)ÚintÚ_n©r)   s    r0   r   zRsaKey.nk   ó   € å�4”7‰|Œ|Ðr2   c                 ó*   — t          | j        ¦  «        S r4   )r5   Ú_er7   s    r0   r   zRsaKey.eo   r8   r2   c                 óp   — |                       ¦   «         st          d¦  «        ‚t          | j        ¦  «        S )Nz-No private exponent available for public keys)Úhas_privateÚAttributeErrorr5   r$   r7   s    r0   r   zRsaKey.ds   s4   € à×ÒÑ!Ô!ð 	RÝ Ð!PÑQÔQÐQÝ�4”7‰|Œ|Ðr2   c                 óp   — |                       ¦   «         st          d¦  «        ‚t          | j        ¦  «        S )Nz.No CRT component 'p' available for public keys)r<   r=   r5   r%   r7   s    r0   r   zRsaKey.py   ó4   € à×ÒÑ!Ô!ð 	SÝ Ð!QÑRÔRÐRÝ�4”7‰|Œ|Ðr2   c                 óp   — |                       ¦   «         st          d¦  «        ‚t          | j        ¦  «        S )Nz.No CRT component 'q' available for public keys)r<   r=   r5   r'   r7   s    r0   r   zRsaKey.q   r?   r2   c                 óp   — |                       ¦   «         st          d¦  «        ‚t          | j        ¦  «        S )Nz.No CRT component 'u' available for public keys)r<   r=   r5   Ú_ur7   s    r0   r   zRsaKey.u…   r?   r2   c                 ó4   — | j                              ¦   «         S )zSize of the RSA modulus in bits©r6   Úsize_in_bitsr7   s    r0   rE   zRsaKey.size_in_bits‹   s   € àŒw×#Ò#Ñ%Ô%Ð%r2   c                 óF   — | j                              ¦   «         dz
  dz  dz   S )z9The minimal amount of bytes that can hold the RSA modulusr   é   rD   r7   s    r0   Úsize_in_byteszRsaKey.size_in_bytes�   s%   € à”×$Ò$Ñ&Ô&¨Ñ*¨qÑ0°1Ñ4Ð4r2   c                 ó²   — d|cxk    r| j         k     sn t          d¦  «        ‚t          t          t	          |¦  «        | j        | j         ¦  «        ¦  «        S )Nr   zPlaintext too large)r6   r!   r5   Úpowr   r:   )r)   Ú	plaintexts     r0   Ú_encryptzRsaKey._encrypt“   sX   € Ø�IÐ'Ð'Ò'Ð' ¤Ò'Ð'Ð'Ð'ÝÐ2Ñ3Ô3Ð3Ý•3•w˜yÑ)Ô)¨4¬7°D´GÑ<Ô<Ñ=Ô=Ð=r2   c                 ó„  — d|cxk    r| j         k     sn t          d¦  «        ‚|                      ¦   «         st          d¦  «        ‚t	          j        d| j         ¬¦  «        }t	          |¦  «        t          || j        | j         ¦  «        z  | j         z  }t          || j        | j	        ¦  «        }t          || j
        | j        ¦  «        }||z
  | j        z  | j        z  }|| j	        z  |z   }|                     | j         ¦  «        |z  | j         z  }|t          || j        | j         ¦  «        k    rt          d¦  «        ‚|S )Nr   zCiphertext too largezThis is not a private keyr   )Úmin_inclusiveÚmax_exclusivez Fault detected in RSA decryption)r6   r!   r<   Ú	TypeErrorr   Úrandom_rangerJ   r:   r&   r%   r(   r'   rB   Úinverse)	r)   Ú
ciphertextÚrÚcpÚm1Úm2ÚhÚmpÚresults	            r0   Ú_decryptzRsaKey._decrypt˜   s6  € Ø�JÐ(Ð(Ò(Ð( ¤Ò(Ð(Ð(Ð(ÝÐ3Ñ4Ô4Ð4Ø×ÒÑ!Ô!ð 	9ÝÐ7Ñ8Ô8Ð8õ
 Ô ¨qÀÄÐHÑHÔHˆå�ZÑ Ô ¥3 q¨$¬'°4´7Ñ#;Ô#;Ñ;¸d¼gÑEˆå��T”X˜tœwÑ'Ô'ˆÝ��T”X˜tœwÑ'Ô'ˆØ�2‰g˜œÑ  D¤GÑ+ˆØ�”‰[˜2Ñˆà—)’)˜DœGÑ$Ô$ rÑ)¨T¬WÑ4ˆà�˜V T¤W¨d¬gÑ6Ô6Ò6Ð6ÝÐ?Ñ@Ô@Ð@Øˆr2   c                 ó"   — t          | d¦  «        S )z"Whether this is an RSA private keyr$   )Úhasattrr7   s    r0   r<   zRsaKey.has_private°   s   € õ �t˜TÑ"Ô"Ð"r2   c                 ó   — dS ©NT© r7   s    r0   Úcan_encryptzRsaKey.can_encryptµ   ó   € Øˆtr2   c                 ó   — dS r_   r`   r7   s    r0   Úcan_signzRsaKey.can_sign¸   rb   r2   c                 ó8   — t          | j        | j        ¬¦  «        S )z^A matching RSA public key.

        Returns:
            a new :class:`RsaKey` object
        r   )r   r6   r:   r7   s    r0   Ú
public_keyzRsaKey.public_key»   s   € õ ˜œ 4¤7Ð+Ñ+Ô+Ð+r2   c                 óê   — |                       ¦   «         |                      ¦   «         k    rdS | j        |j        k    s| j        |j        k    rdS |                       ¦   «         sdS | j        |j        k    S )NFT)r<   r   r   r   ©r)   Úothers     r0   Ú__eq__zRsaKey.__eq__Ã   st   € Ø×ÒÑÔ ×!2Ò!2Ñ!4Ô!4Ò4Ð4Ø�5ØŒ6�U”WÒÐ ¤¨%¬'Ò 1Ð 1Ø�5Ø×ÒÑ!Ô!ð 	Ø�4Ø”˜%œ'Ò!Ð"r2   c                 ó   — | |k     S r4   r`   rh   s     r0   Ú__ne__zRsaKey.__ne__Ì   s   € Ø˜E’MÐ"Ð"r2   c                 ó   — ddl m} |‚)Nr   )ÚPicklingError)Úpicklern   )r)   rn   s     r0   Ú__getstate__zRsaKey.__getstate__Ï   s   € à(Ð(Ð(Ð(Ð(Ð(ØÐr2   c                 ó*  — |                       ¦   «         rRdt          | j        ¦  «        t          | j        ¦  «        t          | j        ¦  «        t          | j        ¦  «        fz  }nd}dt          | j        ¦  «        t          | j        ¦  «        |fz  S )Nz, d=%d, p=%d, q=%d, u=%dÚ zRsaKey(n=%d, e=%d%s))r<   r5   r$   r%   r'   rB   r6   r:   )r)   Úextras     r0   Ú__repr__zRsaKey.__repr__Ô   s{   € Ø×ÒÑÔð 	Ø.µ#°d´g±,´,ÅÀDÄGÁÄÝ25°d´g±,´,ÅÀDÄGÁÄð2Nñ NˆEˆEð ˆEØ%­¨T¬W©¬µs¸4¼7±|´|ÀUÐ(KÑKÐKr2   c                 ó\   — |                       ¦   «         rd}nd}d|t          | ¦  «        fz  S )NÚPrivateÚPublicz%s RSA key at 0x%X)r<   Úid)r)   Úkey_types     r0   Ú__str__zRsaKey.__str__Ü   s8   € Ø×ÒÑÔð 	 Ø ˆHˆHàˆHØ# xµ°D±´Ð&:Ñ:Ð:r2   ÚPEMNr   c                 ó   — |�t          |¦  «        }|€t          j        }|dk    r˜d„ | j        | j        fD ¦   «         \  }}t          |d         ¦  «        dz  rd|z   }t          |d         ¦  «        dz  rd|z   }d||g}d                     d	„ |D ¦   «         ¦  «        }	d
t          j        |	¦  «        dd…         z   S |  	                    ¦   «         �r t          d| j        | j        | j        | j        | j        | j        | j        dz
  z  | j        | j        dz
  z  t!          | j        ¦  «                             | j        ¦  «        g	¦  «                             ¦   «         }
|dk    rd}|dk    r|rt'          d¦  «        ‚nƒddlm} |dk    r!|€d}|                     |
t.          d¦  «        }
nVd}|sd}|                     |
t.          ||¦  «        }
d}n0d}t1          t.          t          | j        | j        g¦  «        ¦  «        }
|dk    r|
S |dk    r-ddlm} |                     |
|||¦  «        }t          |¦  «        S t'          d|z  ¦  «        ‚)a5  Export this RSA key.

        Args:
          format (string):
            The format to use for wrapping the key:

            - *'PEM'*. (*Default*) Text encoding, done according to `RFC1421`_/`RFC1423`_.
            - *'DER'*. Binary encoding.
            - *'OpenSSH'*. Textual encoding, done according to OpenSSH specification.
              Only suitable for public keys (not private keys).

          passphrase (string):
            (*For private keys only*) The pass phrase used for protecting the output.

          pkcs (integer):
            (*For private keys only*) The ASN.1 structure to use for
            serializing the key. Note that even in case of PEM
            encoding, there is an inner ASN.1 DER structure.

            With ``pkcs=1`` (*default*), the private key is encoded in a
            simple `PKCS#1`_ structure (``RSAPrivateKey``).

            With ``pkcs=8``, the private key is encoded in a `PKCS#8`_ structure
            (``PrivateKeyInfo``).

            .. note::
                This parameter is ignored for a public key.
                For DER and PEM, an ASN.1 DER ``SubjectPublicKeyInfo``
                structure is always used.

          protection (string):
            (*For private keys only*)
            The encryption scheme to use for protecting the private key.

            If ``None`` (default), the behavior depends on :attr:`format`:

            - For *'DER'*, the *PBKDF2WithHMAC-SHA1AndDES-EDE3-CBC*
              scheme is used. The following operations are performed:

                1. A 16 byte Triple DES key is derived from the passphrase
                   using :func:`Cryptodome.Protocol.KDF.PBKDF2` with 8 bytes salt,
                   and 1 000 iterations of :mod:`Cryptodome.Hash.HMAC`.
                2. The private key is encrypted using CBC.
                3. The encrypted key is encoded according to PKCS#8.

            - For *'PEM'*, the obsolete PEM encryption scheme is used.
              It is based on MD5 for key derivation, and Triple DES for encryption.

            Specifying a value for :attr:`protection` is only meaningful for PKCS#8
            (that is, ``pkcs=8``) and only if a pass phrase is present too.

            The supported schemes for PKCS#8 are listed in the
            :mod:`Cryptodome.IO.PKCS8` module (see :attr:`wrap_algo` parameter).

          randfunc (callable):
            A function that provides random bytes. Only used for PEM encoding.
            The default is :func:`Cryptodome.Random.get_random_bytes`.

        Returns:
          byte string: the encoded key

        Raises:
          ValueError:when the format is unknown or when you try to encrypt a private
            key with *DER* format and PKCS#1.

        .. warning::
            If you don't provide a pass phrase, the private key will be
            exported in the clear!

        .. _RFC1421:    http://www.ietf.org/rfc/rfc1421.txt
        .. _RFC1423:    http://www.ietf.org/rfc/rfc1423.txt
        .. _`PKCS#1`:   http://www.ietf.org/rfc/rfc3447.txt
        .. _`PKCS#8`:   http://www.ietf.org/rfc/rfc5208.txt
        NÚOpenSSHc                 ó6   — g | ]}|                      ¦   «         ‘ŒS r`   )Úto_bytes©Ú.0Úxs     r0   ú
<listcomp>z%RsaKey.export_key.<locals>.<listcomp>7  s    € ÐIÐIÐI° §
¢
¡¤ÐIÐIÐIr2   r   é€   ó    s   ssh-rsar2   c                 óX   — g | ]'}t          j        d t          |¦  «        ¦  «        |z   ‘Œ(S )ú>I)ÚstructÚpackÚlen)r�   Úkps     r0   rƒ   z%RsaKey.export_key.<locals>.<listcomp>=  s/   € Ð!UÐ!UÐ!UÀb¥&¤+¨dµC¸±G´GÑ"<Ô"<¸rÑ"AÐ!UÐ!UÐ!Ur2   ó   ssh-rsa éÿÿÿÿr   zRSA PRIVATE KEYÚDERz&PKCS#1 private key cannot be encrypted©ÚPKCS8r{   zPRIVATE KEYzENCRYPTED PRIVATE KEYz"PBKDF2WithHMAC-SHA1AndDES-EDE3-CBCz
PUBLIC KEY©r{   z3Unknown key format '%s'. Cannot export the RSA key.)r	   r   Úget_random_bytesr:   r6   r
   ÚjoinÚbinasciiÚ
b2a_base64r<   r   r   r   r   r   r   r   rR   Úencoder!   ÚCryptodome.IOr�   Úwrapr   r   r{   )r)   ÚformatÚ
passphraseÚpkcsÚ
protectionÚrandfuncÚe_bytesÚn_bytesÚkeypartsÚ	keystringÚ
binary_keyry   r�   r{   Úpem_strs                  r0   Ú
export_keyzRsaKey.export_keyã   s­  € ðZ Ð!Ý  Ñ,Ô,ˆJàÐÝÔ.ˆHà�YÒÐØIÐI°t´wÀÄÐ6HÐIÑIÔIÑˆG�WÝ�G˜A”JÑÔ $Ñ&ð ,Ø! GÑ+�Ý�G˜A”JÑÔ $Ñ&ð ,Ø! GÑ+�Ø" G¨WÐ5ˆHØŸšÐ!UÐ!UÈHÐ!UÑ!UÔ!UÑVÔVˆIØ¥Ô!4°YÑ!?Ô!?ÀÀÀÔ!DÑDÐDð ×ÒÑÔñ !	;Ý$ aØ&*¤fØ&*¤fØ&*¤fØ&*¤fØ&*¤fØ&*¤f°´°q±Ñ&9Ø&*¤f°´°q±Ñ&9Ý&-¨d¬f¡o¤o×&=Ò&=¸d¼fÑ&EÔ&Eð	&(ñ 	)ô 	)÷ *0ª©¬ð ð �qŠyˆyØ,�Ø˜U’?�? z�?Ý$Ð%MÑNÔNÐNøà/Ð/Ð/Ð/Ð/Ð/à˜U’?�? zÐ'9Ø,�HØ!&§¢¨J½¸TÑ!BÔ!B�J�Jà6�HØ%ð JØ%I˜
Ø!&§¢¨J½Ø,6¸
ñ"Dô "D�Jà!%�J�Jà#ˆHÝ8½Ý9DÀdÄfØFJÄfðFNñ :Oô :Oñ;ô ;ˆJð
 �UŠ?ˆ?ØÐØ�UŠ?ˆ?Ø)Ð)Ð)Ð)Ð)Ð)à—j’j ¨X°zÀ8ÑLÔLˆGÝ˜7Ñ#Ô#Ð#åÐNÐQWÑWÑXÔXÐXr2   c                 ó    — t          d¦  «        ‚©Nz0Use module Cryptodome.Signature.pkcs1_15 instead©ÚNotImplementedError)r)   ÚMÚKs      r0   ÚsignzRsaKey.signt  ó   € Ý!Ð"TÑUÔUÐUr2   c                 ó    — t          d¦  «        ‚r¦   r§   )r)   r©   Ú	signatures      r0   ÚverifyzRsaKey.verifyw  r¬   r2   c                 ó    — t          d¦  «        ‚©Nz/Use module Cryptodome.Cipher.PKCS1_OAEP insteadr§   )r)   rK   rª   s      r0   ÚencryptzRsaKey.encryptz  ó   € Ý!Ð"SÑTÔTÐTr2   c                 ó    — t          d¦  «        ‚r±   r§   )r)   rS   s     r0   ÚdecryptzRsaKey.decrypt}  r³   r2   c                 ó   — t           ‚r4   r§   ©r)   r©   ÚBs      r0   ÚblindzRsaKey.blind€  ó   € Ý!Ð!r2   c                 ó   — t           ‚r4   r§   r·   s      r0   ÚunblindzRsaKey.unblindƒ  rº   r2   c                 ó   — t           ‚r4   r§   r7   s    r0   ÚsizezRsaKey.size†  rº   r2   )r{   Nr   NN)#Ú__name__Ú
__module__Ú__qualname__Ú__doc__r1   Úpropertyr   r   r   r   r   r   rE   rH   rL   r[   r<   ra   rd   rf   rj   rl   rp   rt   rz   r¤   Ú	exportKeyÚ	publickeyr«   r¯   r²   rµ   r¹   r¼   r¾   r`   r2   r0   r   r   3   s;  € € € € € ðð ð2/ð /ð /ð< ðð ñ „Xðð ðð ñ „Xðð ðð ñ „Xðð
 ðð ñ „Xðð
 ðð ñ „Xðð
 ðð ñ „Xðð
&ð &ð &ð5ð 5ð 5ð>ð >ð >ð
ð ð ð0#ð #ð #ð
ð ð ðð ð ð,ð ,ð ,ð#ð #ð #ð#ð #ð #ðð ð ð
Lð Lð Lð;ð ;ð ;ð >?Ø-1ðJYð JYð JYð JYðZ €IØ€IðVð Vð VðVð Vð VðUð Uð UðUð Uð Uð"ð "ð "ð"ð "ð "ð"ð "ð "ð "ð "r2   r   é  c                 ó˜  ‡‡‡‡‡— | dk     rt          d¦  «        ‚‰dz  dk    s‰dk     rt          d¦  «        ‚|€t          j        }t          d¦  «        x}}t          ‰¦  «        Š|                     ¦   «         | k    �r|d| dz  z  k     �r
| dz  }| |z
  }t          d¦  «        d|z  dz
  z                       ¦   «         xŠŠ||k    r*t          d¦  «        d|z  dz
  z                       ¦   «         Šˆˆfd	„}t          |||¬
¦  «        Št          d¦  «        | dz  dz
  z  Šˆˆˆˆfd„}t          |||¬
¦  «        }	‰|	z  }‰dz
                       |	dz
  ¦  «        }
‰                     |
¦  «        }|                     ¦   «         | k    r|d| dz  z  k     �°
‰|	k    r|	‰cŠ}	‰                     |	¦  «        }t          |‰|‰|	|¬¦  «        S )a4  Create a new RSA key pair.

    The algorithm closely follows NIST `FIPS 186-4`_ in its
    sections B.3.1 and B.3.3. The modulus is the product of
    two non-strong probable primes.
    Each prime passes a suitable number of Miller-Rabin tests
    with random bases and a single Lucas test.

    Args:
      bits (integer):
        Key length, or size (in bits) of the RSA modulus.
        It must be at least 1024, but **2048 is recommended.**
        The FIPS standard only defines 1024, 2048 and 3072.
      randfunc (callable):
        Function that returns random bytes.
        The default is :func:`Cryptodome.Random.get_random_bytes`.
      e (integer):
        Public RSA exponent. It must be an odd positive integer.
        It is typically a small number with very few ones in its
        binary representation.
        The FIPS standard requires the public exponent to be
        at least 65537 (the default).

    Returns: an RSA key object (:class:`RsaKey`, with private key).

    .. _FIPS 186-4: http://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.186-4.pdf
    i   z"RSA modulus length must be >= 1024é   r   é   zBRSA public exponent must be a positive, odd integer larger than 2.Nr   c                 óH   •— | ‰k    o| dz
                        ‰¦  «        dk    S ©Nr   )Úgcd)Ú	candidater   Úmin_ps    €€r0   Úfilter_pzgenerate.<locals>.filter_p½  s*   ø€ Ø˜uÒ$ÐD¨)°a©-×)<Ò)<¸QÑ)?Ô)?À1Ò)DÐDr2   )Ú
exact_bitsr�   Úprime_filteréd   c                 ót   •— | ‰k    o1| dz
                        ‰¦  «        dk    ot          | ‰z
  ¦  «        ‰k    S rË   )rÌ   Úabs)rÍ   r   Úmin_distanceÚmin_qr   s    €€€€r0   Úfilter_qzgenerate.<locals>.filter_qÆ  sH   ø€ Ø Ò%ð 6Ø ‘]×'Ò'¨Ñ*Ô*¨aÒ/ð6å˜	 A™Ñ&Ô&¨Ò5ð7r2   ©r   r   r   r   r   r   )
r!   r   r’   r   rE   Úsqrtr   ÚlcmrR   r   )Úbitsr�   r   r   r   Úsize_qÚsize_prÏ   r×   r   rÚ   r   rÕ   rÎ   rÖ   r   s     `         @@@@r0   r   r   Š  sB  øøøøø€ ð: ˆd‚{€{ÝÐ=Ñ>Ô>Ð>Øˆ1�u�‚z€z�Q˜’U�UÝÐ]Ñ^Ô^Ð^àÐÝÔ*ˆå�A‰JŒJÐ€AˆÝ�‰
Œ
€Aà
�.Š.Ñ
Ô
˜dÒ
"Ñ
" q¨A°$¸!±)Ñ,<Ò'=Ñ'=ð ˜‘ˆØ˜‘ˆå  ™œ¨¨F©
°Q©Ñ7×=Ò=Ñ?Ô?Ð?ˆ�Ø�VÒÐÝ˜Q‘Z”Z A¨¡J°¡NÑ3×9Ò9Ñ;Ô;ˆEð	Eð 	Eð 	Eð 	Eð 	Eð 	Eõ $¨vØ-5Ø19ð;ñ ;ô ;ˆõ ˜q‘z”z d¨a¡i°#¡oÑ6ˆð	7ð 	7ð 	7ð 	7ð 	7ð 	7ð 	7ð 	7õ
 $¨vØ-5Ø19ð;ñ ;ô ;ˆð �‰EˆØ�1‰u�kŠk˜!˜a™%Ñ Ô ˆØ�IŠI�c‰NŒNˆð? �.Š.Ñ
Ô
˜dÒ
"Ð
" q¨A°$¸!±)Ñ,<Ò'=Ñ'=ðB 	ˆ1‚u€uØ�!ˆˆˆ1à	�	Š	�!‰Œ€Aå�A˜˜a 1¨¨QÐ/Ñ/Ô/Ð/r2   Tc                 ó6  —  G d„ dt           ¦  «        } |¦   «         }t          d| ¦  «        D ]#\  }}t          ||t          |¦  «        ¦  «         Œ$|j        }|j        }t          |d¦  «        st          ||¬¦  «        }�nM|j        }	t          |d¦  «        r|j	        }
|j
        }nå|	|z  dz
  }|}|dz  d	k    r|dz  }|dz  d	k    °d
}t          d¦  «        }|s�|dk     rŠt          |¦  «        }||k     rht          |||¦  «        }|dk    rF||dz
  k    r=t          |d|¦  «        dk    r(t          |¦  «                             |dz   ¦  «        }
d}n|dz  }||k     °h|dz  }|s|dk     °Š|st          d¦  «        ‚||
z  d	k    sJ ‚||
z  }t          |d¦  «        r|j        }n|
                     |¦  «        }t          |||	|
||¬¦  «        }|�rÆ|dk    s||k    rt          d¦  «        ‚t          |¦  «                             |¦  «        dk    rt          d¦  «        ‚|dz  st          d¦  «        ‚|                     ¦   «         �rM|	dk    s|	|k    rt          d¦  «        ‚t          |¦  «                             |	¦  «        dk    rt          d¦  «        ‚|
|z  |k    rt          d¦  «        ‚t#          |
¦  «        t$          k    rt          d¦  «        ‚t#          |¦  «        t$          k    rt          d¦  «        ‚|
dz
  |dz
  z  }||
dz
                       |dz
  ¦  «        z  }||	z  t'          |¦  «        z  dk    rt          d¦  «        ‚t          |d¦  «        r6|dk    s||k    rt          d¦  «        ‚|
|z  |z  dk    rt          d¦  «        ‚|S )a!  Construct an RSA key from a tuple of valid RSA components.

    The modulus **n** must be the product of two primes.
    The public exponent **e** must be odd and larger than 1.

    In case of a private key, the following equations must apply:

    .. math::

        \begin{align}
        p*q &= n \\
        e*d &\equiv 1 ( \text{mod lcm} [(p-1)(q-1)]) \\
        p*u &\equiv 1 ( \text{mod } q)
        \end{align}

    Args:
        rsa_components (tuple):
            A tuple of integers, with at least 2 and no
            more than 6 items. The items come in the following order:

            1. RSA modulus *n*.
            2. Public exponent *e*.
            3. Private exponent *d*.
               Only required if the key is private.
            4. First factor of *n* (*p*).
               Optional, but the other factor *q* must also be present.
            5. Second factor of *n* (*q*). Optional.
            6. CRT coefficient *q*, that is :math:`p^{-1} \text{mod }q`. Optional.

        consistency_check (boolean):
            If ``True``, the library will verify that the provided components
            fulfil the main RSA properties.

    Raises:
        ValueError: when the key being imported fails the most basic RSA validity checks.

    Returns: An RSA key object (:class:`RsaKey`).
    c                   ó   — e Zd ZdS )úconstruct.<locals>.InputCompsN)r¿   rÀ   rÁ   r`   r2   r0   Ú
InputCompsrà     s   € € € € € Øˆr2   rá   rØ   r   r   r   r   rÈ   r   FrÒ   Tz2Unable to compute factors p and q from exponent d.r   zInvalid RSA public exponentz-RSA public exponent is not coprime to moduluszRSA modulus is not oddzInvalid RSA private exponentz.RSA private exponent is not coprime to modulusz RSA factors do not match moduluszRSA factor p is compositezRSA factor q is compositezInvalid RSA conditionzInvalid RSA component uzInvalid RSA component u with p)ÚobjectÚzipr#   r   r   r   r]   r   r   r   r   rJ   rÌ   r!   r   rR   r<   r   r   r5   )Úrsa_componentsÚconsistency_checkrá   Úinput_compsÚcompr/   r   r   Úkeyr   r   r   ÚktotÚtÚspottedÚaÚkÚcandr   ÚphirÚ   s                        r0   r   r   Û  s1  € ðPð ð ð ð •Vñ ô ð ð �*‘,”,€KÝÐ;¸^ÑLÔLð 3ð 3‰ˆˆuÝ�˜T¥7¨5¡>¤>Ñ2Ô2Ð2Ð2àŒ€AØŒ€AÝ�; Ñ$Ô$ð 33Ý�q˜AÐÑÔˆ‰àŒMˆÝ�; Ñ$Ô$ð '	Ø”ˆAØ”ˆAˆAð
 �q‘5˜1‘9ˆDð ˆAØ�a‘%˜1’*�*Ø�a‘�ð �a‘%˜1’*�*ð ˆGÝ˜‘
”
ˆAØð  ! c¢' 'Ý˜A‘J”J�à˜$’h�hÝ˜q ! Q™<œ<�Dà˜q’y�y T¨a°!©e¢_ _½¸TÀ1Àa¹¼ÈAÒ9MÐ9Mõ $ A™JœJŸNšN¨4°!©8Ñ4Ô4˜Ø"&˜ØØ˜‘F�Að ˜$’h�hð �Q‘�ð ð  ! c¢' 'ð ð WÝ Ð!UÑVÔVÐVà˜‘U˜q’L�L�L�LØ�Q‘ˆAå�; Ñ$Ô$ð 	Ø”ˆAˆAà—	’	˜!‘”ˆAõ �q˜A  a¨1°Ð2Ñ2Ô2ˆð ñ #Gð �Š6ˆ6�Q˜!’V�VÝÐ:Ñ;Ô;Ð;Ý�1‰:Œ:�>Š>˜!ÑÔ Ò!Ð!ÝÐLÑMÔMÐMð �1‰uð 	7ÝÐ5Ñ6Ô6Ð6à�?Š?ÑÔñ 	Gà�AŠvˆv˜˜aš˜Ý Ð!?Ñ@Ô@Ð@Ý�q‰zŒz�~Š~˜aÑ Ô  AÒ%Ð%Ý Ð!QÑRÔRÐRà�1‰u˜ŠzˆzÝ Ð!CÑDÔDÐDÝ" 1Ñ%Ô%­Ò2Ð2Ý Ð!<Ñ=Ô=Ð=Ý" 1Ñ%Ô%­Ò2Ð2Ý Ð!<Ñ=Ô=Ð=à�q‘5˜Q ™UÑ#ˆCØ˜!˜a™%Ÿš Q¨¡UÑ+Ô+Ñ+ˆCØ�A‘�˜C™œÑ  QÒ&Ð&Ý Ð!8Ñ9Ô9Ð9Ý�s˜CÑ Ô ð Gà˜’6�6˜Q !šV˜VÝ$Ð%>Ñ?Ô?Ð?Ø˜‘E˜A‘I !Ò#Ð#Ý$Ð%EÑFÔFÐFà€Jr2   c                 ó  — t          ¦   «                              | dd¬¦  «        }|d         dk    rt          d¦  «        ‚t          |dd…         t	          |d         ¦  «                             |d	         ¦  «        gz   ¦  «        S )
Né	   T©Únr_elementsÚonly_ints_expectedr   z(No PKCS#1 encoding of an RSA private keyr   é   é   é   )r   Údecoder!   r   r   rR   ©Úencodedr*   Úders      r0   Ú_import_pkcs1_privaterü   j  sx   € õ ‰-Œ-×
Ò
˜w°AÈ$Ð
Ñ
OÔ
O€CØ
ˆ1„v�‚{€{ÝÐCÑDÔDÐDÝ�S˜˜1˜”X¥¨¨Q¬¡¤×!8Ò!8¸¸Q¼Ñ!@Ô!@Ð AÑAÑBÔBÐBr2   c                 óh   — t          ¦   «                              | dd¬¦  «        }t          |¦  «        S )NrÈ   Trò   )r   rø   r   rù   s      r0   Ú_import_pkcs1_publicrþ   ~  s.   € õ
 ‰-Œ-×
Ò
˜w°AÈ$Ð
Ñ
OÔ
O€CÝ�S‰>Œ>Ðr2   c                 ó~   — t          | ¦  «        \  }}}|t          k    s|�t          d¦  «        ‚t          |¦  «        S )NzNo RSA subjectPublicKeyInfo)r   r   r!   rþ   )rú   r*   ÚalgoidÚencoded_keyÚparamss        r0   Ú_import_subjectPublicKeyInfor  ‡  sA   € å"AÀ'Ñ"JÔ"JÑ€FˆK˜Ø•‚}€}˜Ð*ÝÐ6Ñ7Ô7Ð7Ý Ñ,Ô,Ð,r2   c                 ó>   — t          | ¦  «        }t          |¦  «        S r4   )r   r  )rú   r*   Úsp_infos      r0   Ú_import_x509_certr  �  s   € å.¨wÑ7Ô7€GÝ'¨Ñ0Ô0Ð0r2   c                 ó¦   — ddl m} |                     | |¦  «        }|d         t          k    rt	          d¦  «        ‚t          |d         |¦  «        S )Nr   r�   zNo PKCS#8 encoded RSA keyr   )r—   r�   Úunwrapr   r!   Ú_import_keyDER)rú   rš   r�   rí   s       r0   Ú_import_pkcs8r
  •  sW   € Ø#Ð#Ð#Ð#Ð#Ð#à�Š�W˜jÑ)Ô)€AØˆ„t�s‚{€{ÝÐ4Ñ5Ô5Ð5Ý˜!˜Aœ$ 
Ñ+Ô+Ð+r2   c                 ó¦   — t           t          t          t          t          f}|D ] }	  || |¦  «        c S # t
          $ r Y Œw xY wt          d¦  «        ‚)z@Import an RSA key (public or private half), encoded in DER form.úRSA key format is not supported)rü   rþ   r  r  r
  r!   )Ú
extern_keyrš   Ú	decodingsÚdecodings       r0   r	  r	  ž  sy   € õ 'Ý%Ý-Ý"Ýð	 €Ið ð ð ˆð	Ø�8˜J¨
Ñ3Ô3Ð3Ð3Ð3øÝð 	ð 	ð 	ØˆDð	øøøõ Ð6Ñ
7Ô
7Ð7s   ¦4´
AÁ Ac                 ó~  — ddl m}m}m}m}  || |¦  «        \  }}|dk    rt          d¦  «        ‚ ||¦  «        \  }} ||¦  «        \  }	} ||¦  «        \  }
} ||¦  «        \  }} ||¦  «        \  }} ||¦  «        \  }} ||¦  «        \  }} ||¦  «         d„ ||	|
|||fD ¦   «         }t          |¦  «        S )Nr   )Úimport_openssh_private_genericÚ
read_bytesÚread_stringÚcheck_paddingzssh-rsazThis SSH key is not RSAc                 ó6   — g | ]}t          j        |¦  «        ‘ŒS r`   )r   Ú
from_bytesr€   s     r0   rƒ   z/_import_openssh_private_rsa.<locals>.<listcomp>Ä  s#   € ÐBÐBÐB q�WÔ Ñ"Ô"ÐBÐBÐBr2   )Ú_opensshr  r  r  r  r!   r   )ÚdataÚpasswordr  r  r  r  Ússh_nameÚ	decryptedr   r   r   Úiqmpr   r   r   ÚpaddedÚbuilds                    r0   Ú_import_openssh_private_rsar  °  s@  € ðCð Cð Cð Cð Cð Cð Cð Cð Cð Cð Cð Cð 9Ð8¸¸xÑHÔHÑ€Hˆià�9ÒÐÝÐ2Ñ3Ô3Ð3à�:˜iÑ(Ô(�L€A€yØ�:˜iÑ(Ô(�L€A€yØ�:˜iÑ(Ô(�L€A€yØ �j Ñ+Ô+�O€Dˆ)Ø�:˜iÑ(Ô(�L€A€yØ�:˜iÑ(Ô(�L€A€yà�˜IÑ&Ô&�I€A€vØ€M�&ÑÔÐàBÐB¨Q°°1°a¸¸DÐ,AÐBÑBÔB€EÝ�UÑÔÐr2   c                 ó"  — ddl m} t          | ¦  «        } |�t          |¦  «        }|                      d¦  «        r;t	          | ¦  «        }|                     ||¦  «        \  }}}t          ||¦  «        }|S |                      d¦  «        r;|                     t	          | ¦  «        |¦  «        \  }}}|rd}t          ||¦  «        S |                      d¦  «        rêt          j	        |  
                    d¦  «        d         ¦  «        }	g }
t          |	¦  «        d	k    rct          j        d
|	dd	…         ¦  «        d         }|
                     |	d	d	|z   …         ¦  «         |	d	|z   d…         }	t          |	¦  «        d	k    °ct          j        |
d         ¦  «        }t          j        |
d         ¦  «        }t#          ||g¦  «        S t          | ¦  «        dk    r)t%          | d         ¦  «        dk    rt          | |¦  «        S t'          d¦  «        ‚)aé  Import an RSA key (public or private).

    Args:
      extern_key (string or byte string):
        The RSA key to import.

        The following formats are supported for an RSA **public key**:

        - X.509 certificate (binary or PEM format)
        - X.509 ``subjectPublicKeyInfo`` DER SEQUENCE (binary or PEM
          encoding)
        - `PKCS#1`_ ``RSAPublicKey`` DER SEQUENCE (binary or PEM encoding)
        - An OpenSSH line (e.g. the content of ``~/.ssh/id_ecdsa``, ASCII)

        The following formats are supported for an RSA **private key**:

        - PKCS#1 ``RSAPrivateKey`` DER SEQUENCE (binary or PEM encoding)
        - `PKCS#8`_ ``PrivateKeyInfo`` or ``EncryptedPrivateKeyInfo``
          DER SEQUENCE (binary or PEM encoding)
        - OpenSSH (text format, introduced in `OpenSSH 6.5`_)

        For details about the PEM encoding, see `RFC1421`_/`RFC1423`_.

      passphrase (string or byte string):
        For private keys only, the pass phrase that encrypts the key.

    Returns: An RSA key object (:class:`RsaKey`).

    Raises:
      ValueError/IndexError/TypeError:
        When the given key cannot be parsed (possibly because the pass
        phrase is wrong).

    .. _RFC1421: http://www.ietf.org/rfc/rfc1421.txt
    .. _RFC1423: http://www.ietf.org/rfc/rfc1423.txt
    .. _`PKCS#1`: http://www.ietf.org/rfc/rfc3447.txt
    .. _`PKCS#8`: http://www.ietf.org/rfc/rfc5208.txt
    .. _`OpenSSH 6.5`: https://flak.tedunangst.com/post/new-openssh-key-format-and-bcrypt-pbkdf
    r   r‘   Ns   -----BEGIN OPENSSH PRIVATE KEYs   -----rŒ   ó    r   rö   r‡   rÈ   é0   r  )r—   r{   r	   Ú
startswithr   rø   r  r	  r”   Ú
a2b_base64ÚsplitrŠ   rˆ   ÚunpackÚappendr   r  r   r
   r!   )r  rš   r{   Útext_encodedÚopenssh_encodedÚmarkerÚenc_flagrZ   rû   r¡   r    Úlengthr   r   s                 r0   r   r   È  s  € ðR "Ð!Ð!Ð!Ð!Ð!å˜Ñ$Ô$€JØÐÝ˜ZÑ(Ô(ˆ
à×ÒÐ>Ñ?Ô?ð Ý˜ZÑ(Ô(ˆØ,/¯JªJ°|ÀZÑ,PÔ,PÑ)ˆ˜ Ý,¨_¸jÑIÔIˆØˆà×Ò˜XÑ&Ô&ð /à"%§*¢*­U°:Ñ->Ô->À
Ñ"KÔ"KÑˆˆf�hØð 	ØˆJÝ˜c :Ñ.Ô.Ð.à×Ò˜[Ñ)Ô)ð 
!åÔ'¨
×(8Ò(8¸Ñ(>Ô(>¸qÔ(AÑBÔBˆ	ØˆÝ�)‰nŒn˜qÒ Ð Ý”] 4¨°2°A°2¬Ñ7Ô7¸Ô:ˆFØ�OŠO˜I a¨¨F©
 lÔ3Ñ4Ô4Ð4Ø! ! f¡* + +Ô.ˆIõ �)‰nŒn˜qÒ Ð õ Ô˜x¨œ{Ñ+Ô+ˆÝÔ˜x¨œ{Ñ+Ô+ˆÝ˜!˜Q˜Ñ Ô Ð å
ˆ:�„˜ÒÐ�t J¨q¤MÑ2Ô2°dÒ:Ð:å˜j¨*Ñ5Ô5Ð5å
Ð6Ñ
7Ô
7Ð7r2   z1.2.840.113549.1.1.1)NrÆ   )Tr4   )#Ú__all__r”   rˆ   Ú
Cryptodomer   ÚCryptodome.Util.py3compatr	   r
   r   ÚCryptodome.Util.asn1r   ÚCryptodome.Math.Numbersr   ÚCryptodome.Math.Primalityr   r   r   ÚCryptodome.PublicKeyr   r   r   râ   r   r   r   rü   rþ   r  r  r
  r	  r  r   Ú	importKeyr   r`   r2   r0   ú<module>r5     só  ðð@ð ð €ð €€€Ø €€€à Ð Ð Ð Ð Ð Ø :Ð :Ð :Ð :Ð :Ð :Ð :Ð :Ð :Ð :Ø ,Ð ,Ð ,Ð ,Ð ,Ð ,à +Ð +Ð +Ð +Ð +Ð +ðGð Gð Gð Gð Gð Gð Gð Gð Gð Gð@ð @ð @ð @ð @ð @ð @ð @ð @ð @ð
T"ð T"ð T"ð T"ð T"ˆVñ T"ô T"ð T"ðn
N0ð N0ð N0ð N0ðbLð Lð Lð Lð^Cð Cð Cð(ð ð ð-ð -ð -ð1ð 1ð 1ð,ð ,ð ,ð8ð 8ð 8ð$ð ð ð0L8ð L8ð L8ð L8ð` €	ð €€€r2   