a ‚oe0fã@sndZddlZddlZddlZddlZddlZddlZddlZddlm Z ddlm Z ddlm Z ddlm Z ddlm Z ddlmZdd lmZdd lmZdd lmZdd lmZdd lmZddlmZddlmZddlmZddlmZddlmZddlmZddlmZddlm Z ddlm!Z!ddlm"Z"ddlm#Z#ddl$m%Z&ddl'm(Z)ddl*m+Z+ddl,mZ-e .e/¡Z0gd¢Z1ddgZ2gd¢Z3e4e 5e3e2e1d ¡ƒZ6ej7e8ee"j9d!œd"d#„Z:ej7e e8e fdd$œd%d&„Z;ej7e e8e fdd$œd'd(„Ze8ee e8e8fe e8d.œd/d0„Z?e8e8e@d1œd2d3„ZAe8e8eBd1œd4d5„ZCe8e8ee8d1œd6d7„ZDej7e"j9e@d8œd9d:„ZEej7e"j9e8dd;œdd?„ZGej7ee e8ejHe"j9dd@œdAdB„ZIe e8e8e8dCœdDdE„ZJej7e e8e e8e e8e e8ddFœdGdH„ZKej7eeLeLfdIœdJdK„ZMe8ej7ddLœdMdN„ZNdS)OzGFunctionality for autorenewal and associated juggling of configurationséN)ÚAny)ÚDict)ÚIterable)ÚList)ÚMapping)ÚOptional)ÚTuple)ÚUnion)Údefault_backend)Úec)Úrsa)Úload_pem_private_key)Ú configuration)Ú crypto_util)Úerrors)Úutil)Úcli)Úclient)Ú constants)Úhooks)Ústorage)Úupdater)Úobj)Údisco)Úos)Z config_dirZlogs_dirZwork_dirZ user_agentÚserverZaccountÚ authenticatorÚ installerÚ renew_hookÚpre_hookÚ post_hookZhttp01_addressZpreferred_chainÚkey_typeÚelliptic_curveÚ rsa_key_sizeÚ http01_port)Z must_stapleZallow_subset_of_namesÚ reuse_keyZ autorenew)Ú pref_challs)ÚconfigÚ full_pathÚreturnc Cs~zt ||¡}WnXtjtfyh}z:t d|¡t dt|ƒ¡t dt   ¡¡WYd}~dSd}~00d|j vr„t d|¡dS|j d}d|vr¦t d|¡dS|  d d ¡|d <t |ƒ}zt||ƒt||ƒWnPttjf�y&}z0t d |t|ƒ¡t dt   ¡¡WYd}~dSd}~00zd d „| ¡Dƒ|_Wn8tj�yx}zt d||¡WYd}~dSd}~00|S)a•Try to instantiate a RenewableCert, updating config with relevant items. This is specifically for use in renewal and enforces several checks and policies to ensure that we can try to proceed with the renewal request. The config argument is modified by including relevant options read from the renewal configuration file. :param configuration.NamespaceConfig config: configuration for the current lineage :param str full_path: Absolute path to the configuration file that defines this lineage :returns: the RenewableCert object or None if a fatal error occurred :rtype: `storage.RenewableCert` or NoneType z(Renewal configuration file %s is broken.zThe error was: %s Skipping.úTraceback was: %sNÚ renewalparamszqsÿz reconstitute..z{Renewal configuration file %s references a certificate that contains an invalid domain name. The problem was: %s. Skipping.)rÚ RenewableCertrZCertStorageErrorÚIOErrorÚloggerÚerrorÚstrÚdebugÚ tracebackÚ format_excrÚgetÚ"_remove_deprecated_config_elementsÚ restore_required_config_elementsÚ_restore_plugin_configsÚ ValueErrorÚErrorÚnamesÚdomainsZConfigurationError)r'r(Úrenewal_candidater4r+r,r,r/Ú reconstitute9sP  ÿ ÿ þÿ þrB)r'r+r)cCsPd|vr| d¡s|d|_d|vrL| d¡sL|d}t|tƒrF|g}||_dS)z¥ webroot_map is, uniquely, a dict, and the general-purpose configuration restoring logic is not able to correctly parse it from the serialized form. Ú webroot_mapÚ webroot_pathN)Ú set_by_userrCÚ isinstancer5rD)r'r+Zwpr,r,r/Ú_restore_webroot_config|s  rGcCsÂg}|ddkrt||ƒn| |d¡| d¡durF| |d¡t|ƒD]n}| dd¡}| ¡D]T\}}| |d¡rf| |¡sf|dvr t||t |ƒƒqft   |¡}t||||ƒƒqfqNdS)aSets plugin specific values in config from renewalparams :param configuration.NamespaceConfig config: configuration for the current lineage :param configobj.Section renewalparams: Parameters from the renewal configuration file that defines this lineage rZwebrootrNú-Ú_)ÚNoneÚTrueÚFalse) rGÚappendr9ÚsetÚreplaceÚitemsÚ startswithrEÚsetattrÚevalrZ argparse_type)r'r+Zplugin_prefixesZ plugin_prefixZ config_itemZ config_valueÚcastr,r,r/r<Žs     r<c Cs–i}t dtffttt t¡ƒttt t¡ƒtt t t ¡ƒ¡}|D]0\}}||vrB|  |¡sB||||ƒ}|||<qB|  ¡D]\}}t |||ƒq|dS)aSets non-plugin specific values in config from renewalparams :param configuration.NamespaceConfig config: configuration for the current lineage :param configobj.Section renewalparams: parameters from the renewal configuration file that defines this lineage r&N)Ú itertoolsÚchainÚ_restore_pref_challsÚzipÚBOOL_CONFIG_ITEMSÚrepeatÚ _restore_boolÚINT_CONFIG_ITEMSÚ _restore_intÚSTR_CONFIG_ITEMSÚ _restore_strrErPrR)r'r+Zupdated_valuesZrequired_itemsZ item_nameZ restore_funcÚvalueÚkeyr,r,r/r;ºs ü  r;)r+r)cCsdd„| ¡DƒS)zàRemoves deprecated config options from the parsed renewalparams. :param dict renewalparams: list of parsed renewalparams :returns: list of renewalparams with deprecated config options removed :rtype: dict cSs i|]\}}|tjvr||“qSr,)rZDEPRECATED_OPTIONS)r-Z option_nameÚvr,r,r/Ú Üs  ÿz6_remove_deprecated_config_elements..)rP)r+r,r,r/r:Ós r:)Ú unused_namer`r)cCst|tƒr|gn|}t |¡S)a—Restores preferred challenges from a renewal config file. If value is a `str`, it should be a single challenge type. :param str unused_name: option name :param value: option value :type value: `list` of `str` or `str` :returns: converted option value to be stored in the runtime config :rtype: `list` of `str` :raises errors.Error: if value can't be converted to a bool )rFr5rZparse_preferred_challenges)rdr`r,r,r/rWàsrW)Únamer`r)cCs.| ¡}|dvr&t d|›d|›�¡‚|dkS)a#Restores a boolean key-value pair from a renewal config file. :param str name: option name :param str value: option value :returns: converted option value to be stored in the runtime config :rtype: bool :raises errors.Error: if value can't be converted to a bool )ÚtrueZfalsezExpected True or False for z but found rf)Úlowerrr>)rer`Zlowercase_valuer,r,r/r[ös r[cCsV|dkr$|dkr$t d¡t d¡Sz t|ƒWStyPt d|›�¡‚Yn0dS)a#Restores an integer key-value pair from a renewal config file. :param str name: option name :param str value: option value :returns: converted option value to be stored in the runtime config :rtype: int :raises errors.Error: if value can't be converted to an int r$rJz!updating legacy http01_port valuezExpected a numeric value for N)r3ÚinforÚ flag_defaultÚintr=rr>©rer`r,r,r/r]s     r]cCs@|dkr0|tjkr0t dtjd|¡tjdS|dkrt d¡dSt d¡dS)zDReturn true if any of the circumstances for automatic renewal apply.z+Auto-renewal forced with --force-renewal...Tz0Certificate is due for renewal, auto-renewing...zCCertificate not due for renewal, but simulating renewal for dry runz#Certificate not yet due for renewalF)Zrenew_by_defaultr3r6Zshould_autorenewrhÚdry_runÚ display_utilÚnotify)r'rlr,r,r/Ú should_renew7s    rp)r'rlÚoriginal_serverr)cCs@t |j¡r)r'rlrqr?r,r,r/Ú_avoid_invalidating_lineageFs  ÿÿrscsžˆ d¡rˆjsdSˆjs$ˆjs$dSˆjr.dSˆj ¡‰d‡‡fdd„fd‡‡‡fdd„fd‡‡‡fd d„fg}|D]$}|d ƒrtt d |d ›d �¡‚qtdS)z®Don't allow combining --reuse-key with any flags that would conflict with key reuse (--key-type, --rsa-key-size, --elliptic-curve), unless --new-key is also set. r%Nz --key-typecsˆˆj ¡kS©N)Zprivate_key_typergr,)Úktrlr,r/Únóz,_avoid_reuse_key_conflicts..z--rsa-key-sizecsˆdkoˆjˆjkS)Nr )r#r,©r'rurlr,r/rvprwz--elliptic-curvecs"ˆdko ˆjo ˆj ¡ˆj ¡kS)NÚecdsa)r"rgr,rxr,r/rvrsézUnable to change the rz½ of this certificate because --reuse-key is set. To stop reusing the private key, specify --no-reuse-key. To change the private key this one time and then reuse it in future, add --new-key.)rEr%Únew_keyr!rgrr>)r'rlZpotential_conflictsZconflictr,rxr/Ú_avoid_reuse_key_conflictsSs,   ÿÿÿû  ÿr|)r'r@Ú le_clientrlr)c Csà|jd}| dt d¡¡}t|||ƒt||ƒ|s>| ¡}|jrd|jsdt j   |j ¡}t ||ƒnd}| ||¡\}}}} |jršt dt j  |j¡¡n2| ¡} | | ||j||¡| | ¡¡| ¡t |||j¡dS)zRenew a certificate lineage.r+rNz(Dry run: skipping updating lineage at %s)rr9rrirsr|r?r%r{rÚpathÚnormpathZprivkeyÚ_update_renewal_params_from_keyZobtain_certificatermr3r6ÚdirnameÚcertÚlatest_common_versionZsave_successorZpemZupdate_all_links_toÚtruncaterrZlive_dir) r'r@r}rlZrenewal_paramsrqr{Znew_certZ new_chainrIZ prior_versionr,r,r/Ú renew_certs$     r…)ÚmsgsÚcategoryr)cs ‡fdd„|Dƒ}dd |¡S)z:Format a results report for a category of renewal outcomesc3s|]}d|ˆfVqdS)z%s (%s)Nr,)r-Úm©r‡r,r/Ú žrwzreport..z z )rr)r†r‡Úlinesr,r‰r/ÚreportœsrŒ)r'Úrenew_successesÚrenew_failuresÚ renew_skippedÚparse_failuresr)cCs>tj}tj}|dtj›�ƒ|jr&dnd}|rD|dƒ|t|dƒƒ|s„|s„|d|›d�ƒ|jdusz|j dusz|j dur‚|d ƒn�|r¬|s¬|d |›d �ƒ|t|d ƒƒnh|rÎ|sÎ|d |ƒ|t|dƒƒnF|�r|�r|d|›d�ƒ|t|d ƒdƒ|d|ƒ|t|dƒƒ|�r0|dƒ|t|dƒƒ|tjƒdS)aÝ Print a report to the terminal about the results of the renewal process. :param configuration.NamespaceConfiguration config: Configuration :param list renew_successes: list of fullchain paths which were renewed :param list renew_failures: list of fullchain paths which failed to be renewed :param list renew_skipped: list of messages to print about skipped certificates :param list parse_failures: list of renewal parameter paths which had errors Ú zsimulated renewalZrenewalz7The following certificates are not due for renewal yet:ZskippedzNo zs were attempted.NzNo hooks were run.zCongratulations, all z s succeeded: Úsuccessz@All %ss failed. The following certificates could not be renewed:ZfailurezThe following z s succeeded:zThe following %ss failed:zB Additionally, the following renewal configurations were invalid: Z parsefail) rnror3r4Ú display_objZ SIDE_FRAMErmrŒrrr )r'r�rŽr�r�roZ notify_errorZ renewal_nounr,r,r/Ú_renew_describe_results¢s@  ÿÿ ÿ  r”)r'r)c s’t‡fdd„ˆjDƒƒr"t d¡‚ˆjr:t ˆˆj¡g}n t ˆ¡}g}g}g}g}g}g}tj   ¡ olˆj }|D�]Ð} t j d| dd�t ˆ¡} t | ¡} zt| | ƒ} Wn\t�y} zBt d| | | ¡t dt ¡¡| | ¡WYd } ~ qrWYd } ~ n d } ~ 00zÔ| �s| | ¡n¾|  ¡d d lm}tj ¡}t| | ƒ�rž|�rtt  !d d ¡}t "d|¡t# $|¡d}| %| || ¡| | j&¡| '|  (¡¡n0t) *|  +d|  ,¡¡¡}| d| j&| -d¡f¡t. /| | |¡Wqrt�yB} zJt d| | ¡t dt ¡¡| �r.| | j&¡| '|  (¡¡WYd } ~ qrd } ~ 00qrt0ˆ||||ƒ|�sb|�r€t t1|ƒ›dt1|ƒ›d�¡‚t d¡||fS)z5Examine each lineage; renew if due and report resultsc3s|]}|ˆjvVqdSrt)rC)r-Údomain©r'r,r/rŠÖrwz)handle_renewal_request..afCurrently, the renew verb is capable of either renewing all installed certificates that are due to be renewed or renewing a single certificate specified by its name. If you would like to renew specific certificates by their domains, use the certonly command instead. The renew verb may provide other options for selecting certificates to renew in the future.z Processing F)ZpausezTRenewal configuration file %s (cert: %s) produced an unexpected error: %s. Skipping.r*Nr)Úmainrziàz3Non-interactive renewal: random delay of %s secondsr‚z%s expires on %sz%Y-%m-%dz-Failed to renew certificate %s with error: %sz renew failure(s), z parse failure(s)zno renewal failures)2Úanyr@rr>ZcertnamerZrenewal_file_for_certnameZrenewal_conf_filesÚsysÚstdinÚisattyZrandom_sleep_on_renewrnZ notificationÚcopyÚdeepcopyZlineagename_for_filenamerBÚ Exceptionr3r4r6r7r8rMZensure_deployedÚcertbot._internalr—Ú plugins_discoZPluginsRegistryZfind_allrpÚrandomZuniformrhÚtimeÚsleepr…Z fullchainÚextendr?rZnotAfterÚversionrƒÚstrftimerZrun_generic_updatersr”Úlen)r'Z conf_filesr�rŽr�r�Zrenewed_domainsZfailed_domainsZapply_random_sleepZ renewal_fileZlineage_configZ lineagenamerAÚer—ZpluginsZ sleep_timeZexpiryr,r–r/Úhandle_renewal_requestÒsŠ     þ "     ÿ  ÿ ÿÿþ &ÿ ÿ r©)Úkey_pathr'r)cCs˜t|dƒ�$}t| ¡dtƒd�}Wdƒn1s40Yt|tjƒrZd|_|j|_ n:t|t j ƒrxd|_|j j |_nt d|›dt|ƒ›d�¡‚dS)NÚrb)ÚpasswordZbackendr ryzKey at z is of an unsupported type: Ú.)Úopenr Úreadr rFr Z RSAPrivateKeyr!Zkey_sizer#r ZEllipticCurvePrivateKeyZcurverer"rr>Útype)rªr'Zfile_hrar,r,r/r€Bs 2    r€)OÚ__doc__rœrUZloggingr¡r™r¢r7Útypingrrrrrrrr Zcryptography.hazmat.backendsr Z)cryptography.hazmat.primitives.asymmetricr r Z,cryptography.hazmat.primitives.serializationr ZcertbotrrrrrŸrrrrrrZcertbot._internal.displayrr“Zcertbot._internal.pluginsrr Zcertbot.compatrZcertbot.displayrnZ getLoggerÚ__name__r3r^r\rYrNrVZ CONFIG_ITEMSZNamespaceConfigr5r1rBrGr<r;r:rWÚboolr[rjr]r_rprsr|ZClientr…rŒr”Úlistr©r€r,r,r,r/Ús”                           ÿ ÿ C ÿ  ÿ , ÿ  "ÿ ÿ , ÿ   þ 0p