§
    8·tcv<  ã                   óÌ   — d gZ ddlmZ ddlmZ ddlmZ ddlmZ ddl	m
Z
 ddlmZ  G d„ d	e¦  «        Z G d
„ de¦  «        Z G d„ de¦  «        Z G d„ de¦  «        Zdd„ZdS )Únewé    )ÚDerSequence)Úlong_to_bytes)ÚInteger)ÚHMAC)ÚEccKey)ÚDsaKeyc                   ó6   — e Zd ZdZd„ Zd„ Zd„ Zd„ Zd„ Zd„ Z	dS )	ÚDssSigSchemezoA (EC)DSA signature object.
    Do not instantiate directly.
    Use :func:`Cryptodome.Signature.DSS.new`.
    c                 ó–   — || _         || _        || _        | j                             ¦   «         | _        | j        dz
  dz  dz   | _        dS )z¤Create a new Digital Signature Standard (DSS) object.

        Do not instantiate this object directly,
        use `Cryptodome.Signature.DSS.new` instead.
        é   é   N)Ú_keyÚ	_encodingÚ_orderÚsize_in_bitsÚ_order_bitsÚ_order_bytes)ÚselfÚkeyÚencodingÚorders       ú:/usr/lib/python3/dist-packages/Cryptodome/Signature/DSS.pyÚ__init__zDssSigScheme.__init__4   sO   € ð ˆŒ	Ø!ˆŒØˆŒàœ;×3Ò3Ñ5Ô5ˆÔØ!Ô-°Ñ1°aÑ7¸!Ñ;ˆÔÐÐó    c                 ó4   — | j                              ¦   «         S )zRReturn ``True`` if this signature object can be used
        for signing messages.)r   Úhas_private)r   s    r   Úcan_signzDssSigScheme.can_signB   s   € ð Œy×$Ò$Ñ&Ô&Ð&r   c                 ó    — t          d¦  «        ‚©NzTo be provided by subclasses©ÚNotImplementedError©r   Úmsg_hashs     r   Ú_compute_noncezDssSigScheme._compute_nonceH   ó   € Ý!Ð"@ÑAÔAÐAr   c                 ó    — t          d¦  «        ‚r    r!   r#   s     r   Ú_valid_hashzDssSigScheme._valid_hashK   r&   r   c                 ó²  ‡ — ‰                       |¦  «        st          d¦  «        ‚‰                      |¦  «        }t          j        |                     ¦   «         d‰ j        …         ¦  «        }‰ j                             ||¦  «        }‰ j	        dk    r"d 
                    ˆ fd„|D ¦   «         ¦  «        }n!t          |¦  «                             ¦   «         }|S )aö  Produce the DSA/ECDSA signature of a message.

        :parameter msg_hash:
            The hash that was carried out over the message.
            The object belongs to the :mod:`Cryptodome.Hash` package.

            Under mode *'fips-186-3'*, the hash must be a FIPS
            approved secure hash (SHA-1 or a member of the SHA-2 family),
            of cryptographic strength appropriate for the DSA key.
            For instance, a 3072/256 DSA key can only be used
            in combination with SHA-512.
        :type msg_hash: hash object

        :return: The signature as a *byte string*
        :raise ValueError: if the hash algorithm is incompatible to the (EC)DSA key
        :raise TypeError: if the (EC)DSA key has no private half
        úHash is not sufficiently strongNÚbinaryr   c                 ó:   •— g | ]}t          |‰j        ¦  «        ‘ŒS © )r   r   )Ú.0Úxr   s     €r   ú
<listcomp>z%DssSigScheme.sign.<locals>.<listcomp>m   s6   ø€ ð 4ð 4ð 4Ø%&õ  -¨Q°Ô0AÑBÔBð 4ð 4ð 4r   )r(   Ú
ValueErrorr%   r   Ú
from_bytesÚdigestr   r   Ú_signr   Újoinr   Úencode)r   r$   ÚnonceÚzÚsig_pairÚoutputs   `     r   ÚsignzDssSigScheme.signN   sé   ø€ ð& ×Ò Ñ)Ô)ð 	@ÝÐ>Ñ?Ô?Ð?ð ×#Ò# HÑ-Ô-ˆõ Ô˜xŸšÑ0Ô0Ð1C°$Ô2CÐ1CÔDÑEÔEˆØ”9—?’? 1 eÑ,Ô,ˆð Œ>˜XÒ%Ð%Ø—X’Xð 4ð 4ð 4ð 4Ø*2ð4ñ 4ô 4ñ 5ô 5ˆFˆFõ ! Ñ*Ô*×1Ò1Ñ3Ô3ˆFàˆr   c                 ó”  — |                       |¦  «        st          d¦  «        ‚| j        dk    rVt          |¦  «        d| j        z  k    rt          d¦  «        ‚d„ |d| j        …         || j        d…         fD ¦   «         \  }}n©	 t          ¦   «                              |d¬¦  «        }n$# t          t          f$ r t          d	¦  «        ‚w xY wt          |¦  «        dk    s|                     ¦   «         st          d
¦  «        ‚t          |d         ¦  «        t          |d         ¦  «        }}d|cxk     r| j
        k     rn nd|cxk     r| j
        k     sn t          d¦  «        ‚t          j        |                     ¦   «         d| j        …         ¦  «        }| j                             |||f¦  «        }|st          d¦  «        ‚dS )aò  Check if a certain (EC)DSA signature is authentic.

        :parameter msg_hash:
            The hash that was carried out over the message.
            This is an object belonging to the :mod:`Cryptodome.Hash` module.

            Under mode *'fips-186-3'*, the hash must be a FIPS
            approved secure hash (SHA-1 or a member of the SHA-2 family),
            of cryptographic strength appropriate for the DSA key.
            For instance, a 3072/256 DSA key can only be used in
            combination with SHA-512.
        :type msg_hash: hash object

        :parameter signature:
            The signature that needs to be validated
        :type signature: byte string

        :raise ValueError: if the signature is not authentic
        r*   r+   é   z'The signature is not authentic (length)c                 ó6   — g | ]}t          j        |¦  «        ‘ŒS r-   )r   r2   )r.   r/   s     r   r0   z'DssSigScheme.verify.<locals>.<listcomp>—   s9   € ð  Jð  Jð  JØ$%õ !(Ô 2°1Ñ 5Ô 5ð  Jð  Jð  Jr   NT)Ústrictz$The signature is not authentic (DER)z,The signature is not authentic (DER content)r   r   z"The signature is not authentic (d)zThe signature is not authenticF)r(   r1   r   Úlenr   r   ÚdecodeÚ
IndexErrorÚhasOnlyIntsr   r   r2   r3   r   Ú_verify)r   r$   Ú	signatureÚr_primeÚs_primeÚder_seqr8   Úresults           r   ÚverifyzDssSigScheme.verify|   s
  € ð* ×Ò Ñ)Ô)ð 	@ÝÐ>Ñ?Ô?Ð?àŒ>˜XÒ%Ð%Ý�9‰~Œ~ ! dÔ&7Ñ"7Ò8Ð8Ý Ð!JÑKÔKÐKð Jð  JØ*3Ð4F°TÔ5FÐ4FÔ*GØ*3°DÔ4EÐ4FÐ4FÔ*Gð*Ið Jñ  Jô  JÑˆG�W�WðIÝ%™-œ-×.Ò.¨yÀÐ.ÑFÔF��øÝ¥
Ð+ð Ið Ið IÝ Ð!GÑHÔHÐHðIøøøå�7‰|Œ|˜qÒ Ð ¨×(;Ò(;Ñ(=Ô(=Ð Ý Ð!OÑPÔPÐPÝ& w¨q¤zÑ2Ô2µG¸GÀA¼JÑ4GÔ4G�WˆGà�GÐ)Ð)Ò)Ð)˜dœkÒ)Ð)Ð)Ð)Ð)°1°wÐ3LÐ3LÒ3LÐ3LÀÄÒ3LÐ3LÐ3LÐ3LÝÐAÑBÔBÐBåÔ˜xŸšÑ0Ô0Ð1C°$Ô2CÐ1CÔDÑEÔEˆØ”×"Ò" 1 w°Ð&8Ñ9Ô9ˆØð 	?ÝÐ=Ñ>Ô>Ð>àˆus   Â#B+ Â+!CN)
Ú__name__Ú
__module__Ú__qualname__Ú__doc__r   r   r%   r(   r;   rJ   r-   r   r   r   r   .   s   € € € € € ðð ð
<ð <ð <ð'ð 'ð 'ðBð Bð BðBð Bð Bð,ð ,ð ,ð\/ð /ð /ð /ð /r   r   c                   ó<   ‡ — e Zd Zˆ fd„Zd„ Zd„ Zd„ Zd„ Zd„ Zˆ xZ	S )ÚDeterministicDsaSigSchemec                 ój   •— t          t          | ¦  «                             |||¦  «         || _        d S ©N)ÚsuperrP   r   Ú_private_key)r   r   r   r   Úprivate_keyÚ	__class__s        €r   r   z"DeterministicDsaSigScheme.__init__±   s4   ø€ ÝÕ'¨Ñ.Ô.×7Ò7¸¸XÀuÑMÔMÐMØ'ˆÔÐÐr   c                 ó    — t          j        |¦  «        }| j                             ¦   «         }t	          |¦  «        dz  }||k    r|||z
  z  }|S )zSee 2.3.2 in RFC6979r   )r   r2   r   r   r@   )r   ÚbstrrI   Úq_lenÚb_lens        r   Ú	_bits2intz#DeterministicDsaSigScheme._bits2intµ   sR   € õ Ô# DÑ)Ô)ˆØ”×(Ò(Ñ*Ô*ˆÝ�D‘	”	˜A‘ˆØ�5Š=ˆ=à˜ ™Ñ&ˆFØˆr   c                 óX   — d|cxk     r| j         k     sn J ‚t          || j        ¦  «        S )zSee 2.3.3 in RFC6979r   )r   r   r   )r   Ú	int_mod_qs     r   Ú_int2octetsz%DeterministicDsaSigScheme._int2octetsÀ   s>   € ð �9Ð*Ð*Ò*Ð*˜tœ{Ò*Ð*Ð*Ð*Ð*Ð*Ý˜Y¨Ô(9Ñ:Ô:Ð:r   c                 ó†   — |                       |¦  «        }|| j        k     r|}n
|| j        z
  }|                      |¦  «        S )zSee 2.3.4 in RFC6979)r[   r   r^   )r   rX   Úz1Úz2s       r   Ú_bits2octetsz&DeterministicDsaSigScheme._bits2octetsÆ   sI   € ð �^Š^˜DÑ!Ô!ˆØ�”ÒÐØˆBˆBà�d”kÑ!ˆBØ×Ò Ñ#Ô#Ð#r   c                 óX  — |                      ¦   «         }d|j        z  }d|j        z  }dD ]†}t          j        |||z   |                      | j        ¦  «        z   |                      |¦  «        z   |¦  «                              ¦   «         }t          j        |||¦  «                              ¦   «         }Œ‡d}d|cxk     r| j        k     sän |dk    rSt          j        ||dz   |¦  «                              ¦   «         }t          j        |||¦  «                              ¦   «         }d}t          |¦  «        | j	        k     rEt          j        |||¦  «                              ¦   «         }||z  }t          |¦  «        | j	        k     °E|  
                    |¦  «        }d|cxk     r| j        k     ¯ßn Œâ|S )z!Generate k in a deterministic wayó   ó    )re   rd   éÿÿÿÿr   r   )r3   Údigest_sizer   r   r^   rT   rb   r   r@   r   r[   )r   ÚmhashÚh1Úmask_vÚnonce_kÚint_octr7   Úmask_ts           r   r%   z(DeterministicDsaSigScheme._compute_nonceÐ   sÍ  € ð
 �\Š\‰^Œ^ˆà˜5Ô,Ñ,ˆà˜EÔ-Ñ-ˆà)ð 	?ð 	?ˆGå”h˜wØ%¨Ñ/Ø#×/Ò/°Ô0AÑBÔBñ Cà#×0Ò0°Ñ4Ô4ñ 5à6;ñ=ô =÷ >DºV¹X¼Xð õ
 ”X˜g v¨uÑ5Ô5×<Ò<Ñ>Ô>ˆFˆFàˆØ�uÐ*Ð*Ò*Ð*˜tœ{Ò*Ð*Ð*Ð*à˜Š{ˆ{Ýœ( 7¨F°WÑ,<Ø#(ñ*ô *ß*0ª&©(¬(ð åœ '¨6°5Ñ9Ô9×@Ò@ÑBÔB�ð ˆFõ �f‘+”+ Ô 1Ò1Ð1Ýœ '¨6°5Ñ9Ô9×@Ò@ÑBÔB�Ø˜&Ñ �õ �f‘+”+ Ô 1Ò1Ð1ð
 —N’N 6Ñ*Ô*ˆEð! �uÐ*Ð*Ò*Ð*˜tœ{Ò*Ð*Ð*Ð*Ð*ð" ˆr   c                 ó   — dS )NTr-   r#   s     r   r(   z%DeterministicDsaSigScheme._valid_hashø   s   € Øˆtr   )
rK   rL   rM   r   r[   r^   rb   r%   r(   Ú__classcell__©rV   s   @r   rP   rP   ®   s„   ø€ € € € € ð(ð (ð (ð (ð (ð	ð 	ð 	ð;ð ;ð ;ð$ð $ð $ð&ð &ð &ðPð ð ð ð ð ð r   rP   c                   ó.   ‡ — e Zd ZdZˆ fd„Zd„ Zd„ Zˆ xZS )ÚFipsDsaSigScheme))i   é    )é   éà   )rt   é   )i   rv   c                 ó  •— t          t          | ¦  «                             |||¦  «         || _        t	          |j        ¦  «                             ¦   «         }|| j        f| j        vrd|| j        fz  }t          |¦  «        ‚d S )Nz+L/N (%d, %d) is not compliant to FIPS 186-3)
rS   rr   r   Ú	_randfuncr   Úpr   r   Ú_fips_186_3_L_Nr1   )r   r   r   r   ÚrandfuncÚLÚerrorrV   s          €r   r   zFipsDsaSigScheme.__init__  s‡   ø€ ÝÕ Ñ%Ô%×.Ò.¨s°H¸eÑDÔDÐDØ!ˆŒå�C”E‰NŒN×'Ò'Ñ)Ô)ˆØˆtÔÐ ¨Ô(<Ð<Ð<ØBØ˜4Ô+Ð,ñ-ˆEå˜UÑ#Ô#Ð#ð =Ð<r   c                 óD   — t          j        d| j        | j        ¬¦  «        S ©Nr   )Úmin_inclusiveÚmax_exclusiver{   )r   Úrandom_ranger   rx   r#   s     r   r%   zFipsDsaSigScheme._compute_nonce  s(   € åÔ#°!Ø26´+Ø-1¬^ð=ñ =ô =ð 	=r   c                 óL   — |j         dk    p|j                              d¦  «        S )z*Verify that SHA-1, SHA-2 or SHA-3 are usedz1.3.14.3.2.26z2.16.840.1.101.3.4.2.)ÚoidÚ
startswithr#   s     r   r(   zFipsDsaSigScheme._valid_hash  s,   € à” Ò/ð AØ”×'Ò'Ð(?Ñ@Ô@ð	Br   )rK   rL   rM   rz   r   r%   r(   ro   rp   s   @r   rr   rr   ü   sd   ø€ € € € € ð
€Oð$ð $ð $ð $ð $ð=ð =ð =ðBð Bð Bð Bð Bð Bð Br   rr   c                   ó*   ‡ — e Zd Zˆ fd„Zd„ Zd„ Zˆ xZS )ÚFipsEcDsaSigSchemec                 ój   •— t          t          | ¦  «                             |||¦  «         || _        d S rR   )rS   r‡   r   rx   )r   r   r   r   r{   rV   s        €r   r   zFipsEcDsaSigScheme.__init__   s1   ø€ ÝÕ  $Ñ'Ô'×0Ò0°°hÀÑFÔFÐFØ!ˆŒˆˆr   c                 óX   — t          j        d| j        j        j        | j        ¬¦  «        S r   )r   r‚   r   Ú_curver   rx   r#   s     r   r%   z!FipsEcDsaSigScheme._compute_nonce$  s.   € ÝÔ#°!Ø26´)Ô2BÔ2HØ-1¬^ð=ñ =ô =ð 	=r   c                 ó˜   — | j         j                             ¦   «         }d}d}d}|j        |v r|dk    S |j        |v r|dk    S |j        |v S )z�Verify that SHA-[23] (256|384|512) bits are used to
        match the security of P-256 (128 bits), P-384 (192 bits)
        or P-521 (256 bits))z2.16.840.1.101.3.4.2.1z2.16.840.1.101.3.4.2.8)z2.16.840.1.101.3.4.2.2z2.16.840.1.101.3.4.2.9)z2.16.840.1.101.3.4.2.3z2.16.840.1.101.3.4.2.10rv   i€  )r   ÚpointQr   r„   )r   r$   Úmodulus_bitsÚsha256Úsha384Úsha512s         r   r(   zFipsEcDsaSigScheme._valid_hash)  sf   € ð
 ”yÔ'×4Ò4Ñ6Ô6ˆàGˆØGˆØGˆàŒ<˜6Ð!Ð!Ø 3Ò&Ð&ØŒ\˜VÐ#Ð#Ø 3Ò&Ð&à”< 6Ð)Ð)r   )rK   rL   rM   r   r%   r(   ro   rp   s   @r   r‡   r‡     sV   ø€ € € € € ð"ð "ð "ð "ð "ð=ð =ð =ð
*ð *ð *ð *ð *ð *ð *r   r‡   r+   Nc                 óF  — |dvrt          d|z  ¦  «        ‚t          | t          ¦  «        r| j        j        }d}nXt          | t
          ¦  «        rt          | j        ¦  «        }d}n,t          dt          t          | ¦  «        ¦  «        z   ¦  «        ‚|  
                    ¦   «         rt          | |¦  «        }nd}|dk    rt          | |||¦  «        S |dk    r9t          | t          ¦  «        rt          | |||¦  «        S t          | |||¦  «        S t          d	|z  ¦  «        ‚)
aµ
  Create a signature object :class:`DSS_SigScheme` that
    can perform (EC)DSA signature or verification.

    .. note::
        Refer to `NIST SP 800 Part 1 Rev 4`_ (or newer release) for an
        overview of the recommended key lengths.

    :parameter key:
        The key to use for computing the signature (*private* keys only)
        or verifying one: it must be either
        :class:`Cryptodome.PublicKey.DSA` or :class:`Cryptodome.PublicKey.ECC`.

        For DSA keys, let ``L`` and ``N`` be the bit lengths of the modulus ``p``
        and of ``q``: the pair ``(L,N)`` must appear in the following list,
        in compliance to section 4.2 of `FIPS 186-4`_:

        - (1024, 160) *legacy only; do not create new signatures with this*
        - (2048, 224) *deprecated; do not create new signatures with this*
        - (2048, 256)
        - (3072, 256)

        For ECC, only keys over P-256, P384, and P-521 are accepted.
    :type key:
        a key object

    :parameter mode:
        The parameter can take these values:

        - *'fips-186-3'*. The signature generation is randomized and carried out
          according to `FIPS 186-3`_: the nonce ``k`` is taken from the RNG.
        - *'deterministic-rfc6979'*. The signature generation is not
          randomized. See RFC6979_.
    :type mode:
        string

    :parameter encoding:
        How the signature is encoded. This value determines the output of
        :meth:`sign` and the input to :meth:`verify`.

        The following values are accepted:

        - *'binary'* (default), the signature is the raw concatenation
          of ``r`` and ``s``. It is defined in the IEEE P.1363 standard.

          For DSA, the size in bytes of the signature is ``N/4`` bytes
          (e.g. 64 for ``N=256``).

          For ECDSA, the signature is always twice the length of a point
          coordinate (e.g. 64 bytes for P-256).

        - *'der'*, the signature is a ASN.1 DER SEQUENCE
          with two INTEGERs (``r`` and ``s``). It is defined in RFC3279_.
          The size of the signature is variable.
    :type encoding: string

    :parameter randfunc:
        A function that returns random *byte strings*, of a given length.
        If omitted, the internal RNG is used.
        Only applicable for the *'fips-186-3'* mode.
    :type randfunc: callable

    .. _FIPS 186-3: http://csrc.nist.gov/publications/fips/fips186-3/fips_186-3.pdf
    .. _FIPS 186-4: http://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.186-4.pdf
    .. _NIST SP 800 Part 1 Rev 4: http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-57pt1r4.pdf
    .. _RFC6979: http://tools.ietf.org/html/rfc6979
    .. _RFC3279: https://tools.ietf.org/html/rfc3279#section-2.2.2
    )r+   ÚderzUnknown encoding '%s'Údr/   zUnsupported key type Nzdeterministic-rfc6979z
fips-186-3zUnknown DSS mode '%s')r1   Ú
isinstancer   rŠ   r   r	   r   ÚqÚstrÚtyper   ÚgetattrrP   r‡   rr   )r   Úmoder   r{   r   Úprivate_key_attrrU   s          r   r   r   <  s7  € ðV Ð(Ð(Ð(ÝÐ0°8Ñ;Ñ<Ô<Ð<å�#•vÑÔð CØ”
Ô ˆØÐÐÝ	�C�Ñ	 Ô	 ð CÝ˜œ‘”ˆØÐÐåÐ0µ3µt¸C±y´y±>´>ÑAÑBÔBÐBà
‡‚ÑÔð Ý˜cÐ#3Ñ4Ô4ˆˆàˆàÐ&Ò&Ð&Ý(¨¨h¸¸{ÑKÔKÐKØ	�Ò	Ð	Ý�c�6Ñ"Ô"ð 	DÝ% c¨8°U¸HÑEÔEÐEå# C¨°5¸(ÑCÔCÐCåÐ0°4Ñ7Ñ8Ô8Ð8r   )r+   N)Ú__all__ÚCryptodome.Util.asn1r   ÚCryptodome.Util.numberr   ÚCryptodome.Math.Numbersr   ÚCryptodome.Hashr   ÚCryptodome.PublicKey.ECCr   ÚCryptodome.PublicKey.DSAr	   Úobjectr   rP   rr   r‡   r   r-   r   r   ú<module>r£      sd  ððD ˆ'€ð -Ð ,Ð ,Ð ,Ð ,Ð ,Ø 0Ð 0Ð 0Ð 0Ð 0Ð 0Ø +Ð +Ð +Ð +Ð +Ð +à  Ð  Ð  Ð  Ð  Ð  Ø +Ð +Ð +Ð +Ð +Ð +Ø +Ð +Ð +Ð +Ð +Ð +ð}ð }ð }ð }ð }�6ñ }ô }ð }ð@Kð Kð Kð Kð K ñ Kô Kð Kð\Bð Bð Bð Bð B�|ñ Bô Bð BðD*ð *ð *ð *ð *˜ñ *ô *ð *ð<d9ð d9ð d9ð d9ð d9ð d9r   