a ‚oe|$ã@sfdZddlZddlZddlZddlZddlmZddlmZddlmZddlm Z ddlm Z ddlm Z dd lm Z dd lm Z dd lmZdd lmZdd lmZddlmZddlmZddlmZddlmZddlmZddlmZddlmZddlmZe  e!¡Z"e�r,eej#e ej$fZ%Gdd„dƒZ&Gdd„dej'ej(ƒZ(ej)ddœdd„Z*dS)zStandalone Authenticator.éN)ÚAny)ÚCallable)Ú DefaultDict)ÚDict)ÚIterable)ÚList)ÚMapping)ÚSet)ÚTuple)ÚType)Ú TYPE_CHECKING)Úcrypto)Ú challenges)Ú standalone)Ú achallenges)Úerrors)Ú interfaces)Úutil)Úcommonc@s„eZdZdZeeeejej ffe e j j ddœdd„Zdeeejee jdœdd „Zedd œd d „Zeee jfd œdd„ZdS)Ú ServerManagera§Standalone servers manager. Manager for `ACMEServer` and `ACMETLSServer` instances. `certs` and `http_01_resources` correspond to `acme.crypto_util.SSLSocket.certs` and `acme.crypto_util.SSLSocket.http_01_resources` respectively. All created servers share the same certificates and resources, so if you're running both TLS and non-TLS instances, HTTP01 handlers will serve the same URLs! N)ÚcertsÚhttp_01_resourcesÚreturncCsi|_||_||_dS©N)Ú _instancesrr)Úselfrr©rúEC:\Program Files\Certbot\pkgs\certbot\_internal\plugins\standalone.pyÚ__init__2szServerManager.__init__Ú)ÚportÚchallenge_typeÚ listenaddrrc Cs–|tjksJ‚||jvr"|j|S||f}zt ||j¡}Wn2tjyn}zt  ||¡‚WYd}~n d}~00|  ¡|  ¡dd}||j|<|S)aRun ACME server on specified ``port``. This method is idempotent, i.e. all calls with the same pair of ``(port, challenge_type)`` will reuse the same server. :param int port: Port to run the server on. :param challenge_type: Subclass of `acme.challenges.Challenge`, currently only `acme.challenge.HTTP01`. :param str listenaddr: (optional) The address to listen on. Defaults to all addrs. :returns: DualNetworkedServers instance. :rtype: ACMEServerMixin Nré) rÚHTTP01rÚacme_standaloneÚHTTP01DualNetworkedServersrÚsocketÚerrorrÚStandaloneBindErrorZ serve_foreverÚ getsocknames)rr r!r"ZaddressÚserversr(Z real_portrrrÚrun9s  ÿ" zServerManager.run)r rcCsF|j|}| ¡D]}tjdg|dd…¢RŽq| ¡|j|=dS)zWStop ACME server running on the specified ``port``. :param int port: zStopping server at %s:%d...Né)rr*ÚloggerÚdebugZshutdown_and_server_close)rr ÚinstanceZsocknamerrrÚstop\s   ÿ zServerManager.stop©rcCs |j ¡S)zÉReturn all running instances. Once the server is stopped using `stop`, it will not be returned. :returns: Mapping from ``port`` to ``servers``. :rtype: tuple )rÚcopy©rrrrÚrunningis zServerManager.running)r)Ú__name__Ú __module__Ú __qualname__Ú__doc__rÚbytesr r ZPKeyZX509r r%ÚHTTP01RequestHandlerÚHTTP01ResourcerÚintr rÚ ChallengeÚstrr&r,r1rr5rrrrr%s  þ ÿ ÿ # rcs eZdZdZdZeeddœ‡fdd„ Zeedddœd d „ƒZ e d œd d „Z dd œdd„Z e e eejdœdd„Ze ejeejdœdd„Zejejdœdd„Zejejdœdd„Zejeejejfdœdd„Ze ejddœdd„Zeeje dœd d!„Z‡ZS)"Ú AuthenticatoraStandalone Authenticator. This authenticator creates its own ephemeral TCP listener on the necessary port in order to respond to incoming http-01 challenges from the certificate authority. Therefore, it does not rely on any existing server program. zàRuns an HTTP server locally which serves the necessary validation files under the /.well-known/acme-challenge/ request path. Suitable if there is no HTTP server already running. HTTP challenge only (wildcards not supported).N)ÚargsÚkwargsrcs@tƒj|i|¤Žt t¡|_i|_tƒ|_t|j|jƒ|_ dSr) ÚsuperrÚ collectionsÚ defaultdictÚsetÚservedrrrr+)rrArB©Ú __class__rrrƒs  zAuthenticator.__init__).N)ÚaddrcCsdSrr)ÚclsrJrrrÚadd_parser_arguments‘sz"Authenticator.add_parser_argumentsr2cCsdS)NzÞThis authenticator creates its own ephemeral TCP listener on the necessary port in order to respond to incoming http-01 challenges from the certificate authority. Therefore, it does not rely on any existing server program.rr4rrrÚ more_info•szAuthenticator.more_infocCsdSrrr4rrrÚprepare›szAuthenticator.prepare)ÚdomainrcCstjgSr)rr$)rrOrrrÚget_chall_prefžszAuthenticator.get_chall_pref)Úachallsrcs‡fdd„|DƒS)Ncsg|]}ˆ |¡‘qSr)Ú_try_perform_single)Ú.0Úachallr4rrÚ ¤óz)Authenticator.perform..r)rrQrr4rÚperform¢szAuthenticator.perform)rTrc CsBz | |¡WStjy:}zt|ƒWYd}~qd}~00qdSr)Ú_perform_singlerr)Ú_handle_perform_error)rrTr(rrrrR¦s z!Authenticator._try_perform_singlecCs"| |¡\}}|j| |¡|Sr)Ú_perform_http_01rGrJ)rrTr+ÚresponserrrrX®szAuthenticator._perform_singlecCsX|jj}|jj}|jj|tj|d�}| ¡\}}tj j |j ||d�}|j   |¡||fS)N)r")Úchallr[Ú validation)ÚconfigÚ http01_portÚhttp01_addressr+r,rr$Zresponse_and_validationr%r;r<r\rrJ)rrTr Úaddrr+r[r]ÚresourcerrrrZ´s ÿ zAuthenticator._perform_http_01cCsb|j ¡D]$\}}|D]}||vr| |¡qq |j ¡ ¡D]\}}|j|s>|j |¡q>dSr)rGÚitemsÚremover+r5r1)rrQZunused_serversZserver_achallsrTr r+rrrÚcleanupÀs zAuthenticator.cleanup)Úfailed_achallsrcCs:|jj|jj}}|r$|›d|›�nd|›�}d|›d�S)Nú:zport zThe Certificate Authority failed to download the challenge files from the temporary standalone webserver started by Certbot on zt. Ensure that the listed domains point to this machine and that it can accept inbound connections from the internet.)r^r_r`)rrfr raZ neat_addrrrrÚ auth_hintÊs ÿzAuthenticator.auth_hint) r6r7r8r9Ú descriptionrrÚ classmethodrrLr?rMrNrr rr>rPrÚAnnotatedChallengerZChallengeResponserWrRrXr r%r&rZrerhÚ __classcell__rrrHrr@vs,ÿ ÿ ÿ ÿÿ  r@)r(rcCsd|jjtjkr t d |j¡¡‚|jjtjkr\d |j¡}tj |dddd�}|s`t |¡‚n|‚dS)Nz†Could not bind TCP port {0} because you don't have the appropriate permissions (for example, you aren't running this program as root).zªCould not bind TCP port {0} because it is already in use by another process on this system (such as a web server). Please stop the program in question and then try again.ZRetryZCancelF)Údefault) Z socket_errorÚerrnoZEACCESrZ PluginErrorÚformatr Z EADDRINUSEÚ display_utilZyesno)r(ÚmsgZ should_retryrrrrYÓsýÿýÿ rY)+r9rDrnZloggingr'Útypingrrrrrrrr r r r ZOpenSSLr Zacmerrr%ZcertbotrrrZcertbot.displayrrpZcertbot.pluginsrZ getLoggerr6r.ZBaseDualNetworkedServersrkZ ServedTyperZPluginr@r)rYrrrrÚsB                    ÿÿQ]