a ‚oe$ã@s¶ddlmZddlZddlmZddlmZmZmZm Z ddl m Z m Z m Z mZmZddlmZGdd„dejƒZGd d „d ejƒZGd d „d ƒZGd d„deƒZGdd„deƒZdS)é)Ú annotationsN)Úutils)ÚAlreadyFinalizedÚ InvalidKeyÚUnsupportedAlgorithmÚ_Reasons)ÚciphersÚcmacÚ constant_timeÚhashesÚhmac)ÚKeyDerivationFunctionc@seZdZdZdS)ÚModeZctrN)Ú__name__Ú __module__Ú __qualname__Z CounterMode©rrúIC:\Program Files\Certbot\pkgs\cryptography\hazmat\primitives\kdf\kbkdf.pyrsrc@seZdZdZdZdZdS)ÚCounterLocationZ before_fixedZ after_fixedZ middle_fixedN)rrrÚ BeforeFixedÚ AfterFixedÚ MiddleFixedrrrrrsrc @s`eZdZdddddddddddœ dd „Zedd d œd d „ƒZddddœdd„Zddœdd„ZdS)Ú _KBKDFDeriverztyping.CallablerÚintútyping.Optional[int]rútyping.Optional[bytes]) ÚprfÚmodeÚlengthÚrlenÚllenÚlocationÚbreak_locationÚlabelÚcontextÚfixedc Cspt|ƒs J‚t|tƒstdƒ‚t|tƒs0tdƒ‚|durJ|tjurJtdƒ‚|durd|tjkrdtdƒ‚|dur~t|tƒs~tdƒ‚|dur–|dkr–tdƒ‚|sž| rª| rªtdƒ‚|dus¼| |¡sÄtd ƒ‚|durÜ| durÜtd ƒ‚|duröt|tƒsötd ƒ‚|du�rd }| du�rd } t   d |¡t   d| ¡||_ ||_ ||_ ||_||_||_||_||_| |_d|_| |_dS)Nzmode must be of type Modez(location must be of type CounterLocationzPlease specify a break_locationzJbreak_location is ignored when location is not CounterLocation.MiddleFixedz!break_location must be an integerrz)break_location must be a positive integerz9When supplying fixed data, label and context are ignored.zrlen must be between 1 and 4zPlease specify an llenzllen must be an integerór#r$F)ÚcallableÚ isinstancerÚ TypeErrorrrÚ ValueErrorrÚ_valid_byte_lengthrZ _check_bytesÚ_prfÚ_modeÚ_lengthÚ_rlenÚ_llenÚ _locationÚ_break_locationÚ_labelÚ_contextÚ_usedÚ _fixed_data) Úselfrrrrr r!r"r#r$r%rrrÚ__init__%sZ   ÿþÿ ÿ    z_KBKDFDeriver.__init__Úbool)ÚvalueÚreturncCs@t|tƒstdƒ‚t d|¡}dt|ƒkr6dkst|jtƒr¶|jt|ƒkr¶t dƒ‚|d|j…}||jd…}td|dƒD]@} | |¡} t | |j¡} || |} |  | ¡| |  ¡¡qàd |¡d|j…S) NrATr&r<éézThere are too many iterations.z"break_location offset > len(fixed))r5rrZ_check_bytesliker.r>r/Úpowr?r*Ú_generate_fixed_inputr1rrrr(r2rÚranger,ÚupdateÚappendÚfinalizeÚjoin) r7rArBÚroundsÚoutputZr_binr%Zdata_before_ctrZdata_after_ctrÚiÚhZcounterZ input_datarrrÚderivexs>   ÿ þ   z_KBKDFDeriver.derive)r;cCsB|jrt|jtƒr|jSt |jd|j¡}d |jd|j |g¡S)NrDr&ó) r6r(r@rr>r.r0rKr3r4)r7Zl_valrrrrF¨sz#_KBKDFDeriver._generate_fixed_inputN)rrrr8Ú staticmethodr+rPrFrrrrr$s  I 0rc@sheZdZdddœdddddddddd dd œ d d „Zd ddœdd„Zd d dœdd„Zd d ddœdd„ZdS)Ú KBKDFHMACN©r"zhashes.HashAlgorithmrrrrrú typing.Any) Ú algorithmrrrr r!r#r$r%Úbackendr"c  Csbt|tjƒstdtjƒ‚ddlm} |  |¡s:tdtjƒ‚||_ t |j |||||| ||| ƒ |_ dS)Nz5Algorithm supplied is not a supported hash algorithm.r©rWz5Algorithm supplied is not a supported hmac algorithm.) r(r Z HashAlgorithmrrZUNSUPPORTED_HASHÚ,cryptography.hazmat.backends.openssl.backendrWZhmac_supportedÚ _algorithmrr,Ú_deriver) r7rVrrrr r!r#r$r%rWr"Úosslrrrr8²s0 þ  þözKBKDFHMAC.__init__r@z hmac.HMAC©rAr;cCst ||j¡S©N)r ZHMACrZ©r7rArrrr,àszKBKDFHMAC._prfcCs|j ||jj¡Sr^)r[rPrZZ digest_sizer_rrrrPãszKBKDFHMAC.deriveÚNone©rAÚ expected_keyr;cCst | |¡|¡st‚dSr^©r Zbytes_eqrPr©r7rArbrrrÚverifyæszKBKDFHMAC.verify)N©rrrr8r,rPrerrrrrS±s õ ó&.rSc @sfeZdZdddœddddddddddd œ d d „Zd d dœdd„Zd d dœdd„Zd d ddœdd„ZdS)Ú KBKDFCMACNrTrrrrrrU) rrrr r!r#r$r%rWr"c  CsRt|tjƒrt|tjƒs$tdtjƒ‚||_d|_t |j |||||| ||| ƒ |_ dS)Nú7Algorithm supplied is not a supported cipher algorithm.) Ú issubclassrZBlockCipherAlgorithmZCipherAlgorithmrrÚUNSUPPORTED_CIPHERrZÚ_cipherrr,r[) r7rVrrrr r!r#r$r%rWr"rrrr8ìs.ÿ þþözKBKDFCMAC.__init__r@z cmac.CMAC)Ú_r;cCs|jdusJ‚t |j¡Sr^)rkr ZCMAC)r7rlrrrr,szKBKDFCMAC._prfr]cCsT| |¡|_|jdusJ‚ddlm}| |j¡s>tdtjƒ‚|j  ||jj d¡S)NrrXrhrD) rZrkrYrWZcmac_algorithm_supportedrrrjr[rPZ block_size)r7rAr\rrrrPs   þzKBKDFCMAC.deriver`racCst | |¡|¡st‚dSr^rcrdrrrre)szKBKDFCMAC.verify)Nrfrrrrrgës õ ó$'rg)Z __future__rÚtypingZ cryptographyrZcryptography.exceptionsrrrrZcryptography.hazmat.primitivesrr r r r Z"cryptography.hazmat.primitives.kdfr ÚEnumrrrrSrgrrrrÚs   :