a ‚oe¥Hã @s"dZddlZddlZddlZddlZddlmZddlmZddlmZddlm Z ddlm Z ddlm Z dd lm Z dd lm Z ddlZdd lmZdd lmZdd lmZddlmZddlmZddlmZddlmZddlmZe e¡Zejddœdd„Zejddœdd„Z ejddœdd„Z!ejddœdd„Z"eje#e ej$dœdd„Z%eje#e e e#dœdd „Z&eje e#e e ej$e ej$fd!œd"d#„Z'ej$e#e e e#d$œd%d&„Z(e e eej$ge#feej$ge e e#ffd'œd(d)„Z)eje#d*œd+d,„Z*ejee eej$ge#feej$ge e e#ffeej$ge#feej$ge#fe e#d-œd.d/„Z+dEejej$e,e e#d1œd2d3„Z-dFeje#e,e e#e e#d4œd5d6„Z.ee#e#d7œd8d9„Z/ejeej$e#d:œd;d<„Z0ejeej$ee#dd=œd>d?„Z1e d@ƒZ2ejedAe2fe2ee2dBœdCdD„Z3dS)Gz Tools for managing certificates.éN)ÚAny)ÚCallable)ÚIterable)ÚList)ÚOptional)ÚTuple)ÚTypeVar)ÚUnion)Ú configuration)Ú crypto_util)Úerrors)Úocsp)Úutil)Ústorage)Úos)ÚconfigÚreturncCs$t |¡D]}tj||dd�q dS)ajUpdate the certificate file family symlinks to use archive_dir. Use the information in the config file to make symlinks point to the correct archive directory. .. note:: This assumes that the installation is using a Reverter object. :param config: Configuration. :type config: :class:`certbot._internal.configuration.NamespaceConfig` T)Zupdate_symlinksN)rÚrenewal_conf_filesÚ RenewableCert)rÚ renewal_file©rú?C:\Program Files\Certbot\pkgs\certbot\_internal\cert_manager.pyÚupdate_live_symlinks!s rcCsŽt|dƒd}|j}|sHtjd |¡dd�\}}|tjks>|sHt d¡‚t||ƒ}|sft  d |¡¡‚t   |||¡tj d ||¡d d �d S) z¡Rename the specified lineage to the new name. :param config: Configuration. :type config: :class:`certbot._internal.configuration.NamespaceConfig` Úrenamerz&Enter the new name for certificate {0}T)Úforce_interactiveúUser ended interaction.z,No existing certificate with name {0} found.z Successfully renamed {0} to {1}.F)ÚpauseN) Ú get_certnamesÚ new_certnameÚ display_utilZ input_textÚformatÚOKr ÚErrorÚlineage_for_certnameZConfigurationErrorrZrename_renewal_configÚ notification)rÚcertnamerÚcodeÚlineagerrrÚrename_lineage1s(þ   ÿÿÿr(c Csšg}g}t |¡D]v}z$t ||¡}t |¡| |¡Wqty†}z4t d||¡t  dt   ¡¡| |¡WYd}~qd}~00qt |||ƒdS)zªDisplay information about certs configured with Certbot :param config: Configuration. :type config: :class:`certbot._internal.configuration.NamespaceConfig` zIRenewal configuration file %s produced an unexpected error: %s. Skipping.úTraceback was: %sN) rrrr Zverify_renewable_certÚappendÚ ExceptionÚloggerZwarningÚdebugÚ tracebackÚ format_excÚ_describe_certs)rÚ parsed_certsÚparse_failuresrZrenewal_candidateÚerrrÚ certificatesKs  ÿ"r4cCsŒt|ddd�}dg}|D]}| d|¡q| d¡| d¡tjd |¡dd �sbt d ¡d S|D] }t ||¡t  d   |¡¡qfd S) z;Delete Certbot files associated with a certificate lineage.ÚdeleteT)Úallow_multiplez8The following certificate(s) are selected for deletion: z * aP WARNING: Before continuing, ensure that the listed certificates are not being used by any installed server software (e.g. Apache, nginx, mail servers). Deleting a certificate that is still being used will cause the server software to stop working. See https://certbot.org/deleting-certs for information on deleting certificates safely.z: Are you sure you want to delete the above certificate(s)?Ú )Údefaultz$Deletion of certificate(s) canceled.Nz.Deleted all files relating to certificate {0}.) rr*rZyesnoÚjoinr,ÚinforZ delete_filesÚnotifyr )rÚ certnamesÚmsgr%rrrr5bs ÿ   ÿr5)Ú cli_configr%rc Cs†|j}tj|dd�zt ||¡}Wntjy:YdS0zt ||¡WStjtfy€t   d|¡t   dt   ¡¡YdS0dS)z)Find a lineage object with name certname.éí©ÚmodeNzRenewal conf file %s is broken.r)) Úrenewal_configs_dirrÚmake_or_verify_dirrZrenewal_file_for_certnamer ÚCertStorageErrorrÚIOErrorr,r-r.r/)r>r%Ú configs_dirrrrrr#|s r#)rr%rcCst||ƒ}|r| ¡SdS)z0Find the domains in the cert with name certname.N)r#Únames)rr%r'rrrÚdomains_for_certnameŽs rH)rÚdomainsrcsPtjtttjttjftttjttjfdœ‡fdd„ }d}t|||ƒS)aˆFind existing certs that match the given domain names. This function searches for certificates whose domains are equal to the `domains` parameter and certificates whose domains are a subset of the domains in the `domains` parameter. If multiple certificates are found whose names are a subset of `domains`, the one whose names are the largest subset of `domains` is returned. If multiple certificates' domains are an exact match or equally sized subsets, which matching certificates are returned is undefined. :param config: Configuration. :type config: :class:`certbot._internal.configuration.NamespaceConfig` :param domains: List of domain names :type domains: `list` of `str` :returns: lineages representing the identically matching cert and the largest subset if they exist :rtype: `tuple` of `storage.RenewableCert` or `None` )Úcandidate_lineageÚrvrcsb|\}}t| ¡ƒ}|tˆƒkr&|}n4| tˆƒ¡rZ|durB|}nt|ƒt| ¡ƒkrZ|}||fS)zsReturn cert as identical_names_cert if it matches, or subset_names_cert if it matches as subset N)ÚsetrGÚissubsetÚlen)rJrKZidentical_names_certZsubset_names_certZcandidate_names©rIrrÚupdate_certs_for_domain_matches®s   z?find_duplicative_certs..update_certs_for_domain_matches)NN)rrrrÚ_search_lineages)rrIrPÚinitrrOrÚfind_duplicative_certs•s ÿ ÿýrS)rJÚfiletypercs,|j‰‡‡fdd„t ˆ¡Dƒ}|r(|SdS)aJ In order to match things like: /etc/letsencrypt/archive/example.com/chain1.pem. Anonymous functions which call this function are eventually passed (in a list) to `match_and_check_overlaps` to help specify the acceptable_matches. :param `.storage.RenewableCert` candidate_lineage: Lineage whose archive dir is to be searched. :param str filetype: main file name prefix e.g. "fullchain" or "chain". :returns: Files in candidate_lineage's archive dir that match the provided filetype. :rtype: list of str or None cs,g|]$}t d ˆ¡|¡rtj ˆ|¡‘qS)z {0}[0-9]*.pem)ÚreÚmatchr rÚpathr9)Ú.0Úf©Ú archive_dirrTrrÚ Ùsÿz"_archive_files..N)r[rÚlistdir)rJrTÚpatternrrZrÚ_archive_filesÊs r_)rcCsdd„dd„dd„dd„gS)zª Generates the list that's passed to match_and_check_overlaps. Is its own function to make unit testing easier. :returns: list of functions :rtype: list cSs|jS©N)Zfullchain_path©ÚxrrrÚèóz%_acceptable_matches..cSs|jSr`©Ú cert_pathrarrrrcèrdcSs t|dƒS)NÚcert©r_rarrrrcérdcSs t|dƒS)NÚ fullchainrhrarrrrcérdrrrrrÚ_acceptable_matchesàs  ÿrj)r>rcs(tƒ}tˆ|‡fdd„dd„ƒ}|dS)a“ If config.cert_path is defined, try to find an appropriate value for config.certname. :param `configuration.NamespaceConfig` cli_config: parsed command line arguments :returns: a lineage name :rtype: str :raises `errors.Error`: If the specified cert path can't be matched to a lineage name. :raises `errors.OverlappingMatchFound`: If the matched lineage's archive is shared. csˆjSr`rera©r>rrrcùrdz&cert_path_to_lineage..cSs|jSr`)Ú lineagenamerarrrrcùrdr)rjÚmatch_and_check_overlaps)r>Úacceptable_matchesrVrrkrÚcert_path_to_lineageìs ÿro)r>rnÚ match_funcÚrv_funcrc s�tjttttttjgtfttjgtttffttdœ‡‡fdd„ }t||g|ƒ}|sxt   d|j ›d�¡‚nt |ƒdkrŒt   ¡‚|S)a Searches through all lineages for a match, and checks for duplicates. If a duplicate is found, an error is raised, as performing operations on lineages that have their properties incorrectly duplicated elsewhere is probably a bad idea. :param `configuration.NamespaceConfig` cli_config: parsed command line arguments :param list acceptable_matches: a list of functions that specify acceptable matches :param function match_func: specifies what to match :param function rv_func: specifies what to return )rJÚ return_valuernrcsd‡fdd„|Dƒ}g}|D]&}t|tƒr2||7}q|r| |¡qˆˆƒ}||vr`| ˆˆƒ¡|S)z1Returns a list of matches using _search_lineages.csg|] }|ˆƒ‘qSrr)rXÚfunc©rJrrr\rdzBmatch_and_check_overlaps..find_matches..)Ú isinstanceÚlistr*)rJrrrnZacceptable_matches_resolvedZacceptable_matches_rvÚitemrV©rprqrtrÚ find_matches s   z.match_and_check_overlaps..find_matcheszNo match found for cert-path ú!é)rrrÚstrrr rrrQr r"rfrNZOverlappingMatchFound)r>rnrprqryZmatchedrrxrrmýs ÿÿý rmF)rrgÚskip_filter_checksrc CsZg}t ¡}|jr&|j|jkr&|s&dS|jrDt|jƒ | ¡¡sDdStj  t j ¡}g}|j rf|  d¡|j|kr||  d¡n| |¡r�|  d¡|r¤dd |¡}nF|j|}|jdkr¾d}n,|jdkrÜd |jd ›d �}nd |j›d �}d  |j|¡} tt |j¡dƒ} |  d|j›d| ›d|j›dd | ¡¡›d| ›d|j›d|j›�¡d |¡S)zJ Returns a human readable description of info about a RenewableCert objectNZ TEST_CERTZEXPIREDZREVOKEDz INVALID: z, r{z VALID: 1 dayzVALID: iz hour(s)z daysz {0} ({1})rbz Certificate Name: z Serial Number: z Key Type: z Domains: ú z Expiry Date: z Certificate Path: z Private Key Path: Ú)r ZRevocationCheckerr%rlrIrLrMrGÚdatetimeÚnowÚpytzZUTCZ is_test_certr*Z target_expiryZ ocsp_revokedr9ZdaysZsecondsr r Zget_serial_from_certrfZprivate_key_typeriZprivkey) rrgr}ÚcertinfoZcheckerr�ZreasonsÚstatusÚdiffZ valid_stringÚserialrrrÚhuman_readable_cert_info&sL        ÿþ ýüûúr‡)rÚverbr6Ú custom_promptrc CsÚ|j}|r|g}nÄt |¡}dd„|Dƒ}|s8t d¡‚|r||sLd |¡}n|}tj||ddd�\} }| tjkrÖt d¡‚nZ|sŒd  |¡}n|}tj ||ddd�\} } | tjksÂ| t d t |ƒƒvrÌt d¡‚|| g}|S) z4Get certname from flag, interactively, or error out.cSsg|]}t |¡‘qSr)rZlineagename_for_filename)rXÚnamerrrr\Yrdz!get_certnames..zNo existing certificates found.z+Which certificate(s) would you like to {0}?z --cert-nameT)Zcli_flagrrz(Which certificate would you like to {0}?r) r%rrr r"r rZ checklistr!ZmenuÚrangerN) rrˆr6r‰r%r<Ú filenamesÚchoicesÚpromptr&ÚindexrrrrQs4   ÿ    ÿ   r)ÚmsgsrcCsdd dd„|Dƒ¡S)zFFormat a results report for a category of single-line renewal outcomesz z css|]}t|ƒVqdSr`)r|)rXr=rrrÚ zrdz _report_lines..)r9)r�rrrÚ _report_linesxsr’)rr1rcCs4g}|D] }t||ƒ}|dur| |¡qd |¡S)z)Format a results report for a parsed certNr7)r‡r*r9)rr1rƒrgZ cert_inforrrÚ_report_human_readable}s   r“)rr1r2rcCs‚g}|j}|s|s|dƒnL|rP|js,|jr0dnd}|d |¡ƒ|t||ƒƒ|rh|dƒ|t|ƒƒtjd |¡ddd�d S) z/Print information about the certs we know aboutzNo certificates found.z matching rzFound the following {0}certs:z3 The following renewal configurations were invalid:r7F)rÚwrapN) r*r%rIr r“r’rr$r9)rr1r2Úoutr;rVrrrr0ˆs  r0ÚT.)r>rsÚ initial_rvÚargsrc Gsˆ|j}tj|dd�|}t |¡D]`}zt ||¡}Wn8tjtfynt   d|¡t   dt   ¡¡Yq"Yn0|||g|¢RŽ}q"|S)aâIterate func over unbroken lineages, allowing custom return conditions. Allows flexible customization of return values, including multiple return values and complex checks. :param `configuration.NamespaceConfig` cli_config: parsed command line arguments :param function func: function used while searching over lineages :param initial_rv: initial return value of the function (any type) :returns: Whatever was specified by `func` if a match is found. r?r@z)Renewal conf file %s is broken. Skipping.r)) rBrrCrrrr rDrEr,r-r.r/)r>rsr—r˜rFrKrrJrrrrQ¡s   rQ)F)FN)4Ú__doc__r€ZloggingrUr.Útypingrrrrrrrr r‚Zcertbotr r r r rZcertbot._internalrZcertbot.compatrZcertbot.displayrZ getLoggerÚ__name__r,ZNamespaceConfigrr(r4r5r|rr#rHrSr_rjrormÚboolr‡rr’r“r0r–rQrrrrÚs�                  ÿ  ÿ ÿÿ 5ÿ ÿÿû *ÿ ÿ +ÿ  ÿ ' ÿ þ ÿ