a ‚oe]‹ã @sàddlmZddlZddlZddlZddlZddlmZddlm Z ddl m Z m Z ddlmZmZmZmZmZmZmZmZddlmZmZmZddlmZmZmZmZdd l m!Z!m"Z"dd l#m$Z$e d d d ¡Z%ej&e j'e j(e j)e j*e j+e j,e j-e j.fZ/Gd d„de0ƒZ1ddddœdd„Z2ddddœdd„Z3dddœdd„Z4Gdd„dƒZ5Gd d!„d!ƒZ6Gd"d#„d#ej7ƒZ8Gd$d%„d%e0ƒZ9Gd&d'„d'ej:d(�Z;e; Gd-d.„d.ej:d(�Z?e? d?„ZEdTd1d2d.d3œd@dA„ZFdUd1d2d.d3œdBdC„ZGGdDdE„dEƒZHGdFdG„dGƒZIGdHdI„dIƒZJGdJdK„dKƒZKdLdMœdNdO„ZLdS)Vé)Ú annotationsN)Úutils)Úx509)ÚhashesÚ serialization)ÚdsaÚecÚed448Úed25519ÚpaddingÚrsaÚx448Úx25519)Ú CertificateIssuerPrivateKeyTypesÚCertificateIssuerPublicKeyTypesÚCertificatePublicKeyTypes)Ú ExtensionÚ ExtensionsÚ ExtensionTypeÚ_make_sequence_methods)ÚNameÚ _ASN1Type)ÚObjectIdentifierižécs&eZdZddddœ‡fdd„ Z‡ZS)ÚAttributeNotFoundÚstrrÚNone)ÚmsgÚoidÚreturncstƒ |¡||_dS©N)ÚsuperÚ__init__r)Úselfrr©Ú __class__©ú7C:\Program Files\Certbot\pkgs\cryptography\x509\base.pyr"8s zAttributeNotFound.__init__©Ú__name__Ú __module__Ú __qualname__r"Ú __classcell__r&r&r$r'r7srzExtension[ExtensionType]ú%typing.List[Extension[ExtensionType]]r)Ú extensionÚ extensionsrcCs"|D]}|j|jkrtdƒ‚qdS)Nz$This extension has already been set.)rÚ ValueError)r.r/Úer&r&r'Ú_reject_duplicate_extension=s r2rúHtyping.List[typing.Tuple[ObjectIdentifier, bytes, typing.Optional[int]]])rÚ attributesrcCs$|D]\}}}||krtdƒ‚qdS)Nz$This attribute has already been set.)r0)rr4Zattr_oidÚ_r&r&r'Ú_reject_duplicate_attributeGsr6údatetime.datetime©ÚtimercCs:|jdur2| ¡}|r|nt ¡}|jdd�|S|SdS)z’Normalizes a datetime to a naive datetime in UTC. time -- datetime to normalize. Assumed to be in UTC if not timezone aware. N)Útzinfo)r:Z utcoffsetÚdatetimeZ timedeltaÚreplace)r9Úoffsetr&r&r'Ú_convert_to_naive_utc_timeSs  r>c@sxeZdZejjfdddddœdd„Zeddœd d „ƒZeddœd d „ƒZd dœdd„Z dddœdd„Z ddœdd„Z dS)Ú AttributerÚbytesÚintr)rÚvalueÚ_typercCs||_||_||_dSr )Ú_oidÚ_valuerC)r#rrBrCr&r&r'r"bszAttribute.__init__©rcCs|jSr )rD©r#r&r&r'rlsz Attribute.oidcCs|jSr )rErGr&r&r'rBpszAttribute.valuercCsd|j›d|j›d�S)Nz)rrBrGr&r&r'Ú__repr__tszAttribute.__repr__ÚobjectÚbool©ÚotherrcCs2t|tƒstS|j|jko0|j|jko0|j|jkSr )Ú isinstancer?ÚNotImplementedrrBrC©r#rMr&r&r'Ú__eq__ws   ÿ ýzAttribute.__eq__cCst|j|j|jfƒSr )ÚhashrrBrCrGr&r&r'Ú__hash__�szAttribute.__hash__N) r)r*r+rZ UTF8StringrBr"ÚpropertyrrIrQrSr&r&r&r'r?asü  r?c@sHeZdZdddœdd„Zedƒ\ZZZddœd d „Zd d d œdd„Z dS)Ú Attributesztyping.Iterable[Attribute]r)r4rcCst|ƒ|_dSr )ÚlistÚ _attributes)r#r4r&r&r'r"†szAttributes.__init__rWrrFcCsd|j›d�S)Nz Not after time (represented as UTC datetime) Nr&rGr&r&r'Únot_valid_afterÆszCertificate.not_valid_afterrcCsdS)z1 Returns the issuer name object. Nr&rGr&r&r'ÚissuerÍszCertificate.issuercCsdS©z2 Returns the subject name object. Nr&rGr&r&r'ÚsubjectÔszCertificate.subjectú%typing.Optional[hashes.HashAlgorithm]cCsdS©zt Returns a HashAlgorithm corresponding to the type of the digest signed in the certificate. Nr&rGr&r&r'Úsignature_hash_algorithmÛsz$Certificate.signature_hash_algorithmrcCsdS©zJ Returns the ObjectIdentifier of the signature algorithm. Nr&rGr&r&r'Úsignature_algorithm_oidåsz#Certificate.signature_algorithm_oidz;typing.Union[None, padding.PSS, padding.PKCS1v15, ec.ECDSA]cCsdS)z= Returns the signature algorithm parameters. Nr&rGr&r&r'Úsignature_algorithm_parametersìsz*Certificate.signature_algorithm_parametersrcCsdS)z/ Returns an Extensions object. Nr&rGr&r&r'r/õszCertificate.extensionscCsdS©z. Returns the signature bytes. Nr&rGr&r&r'Ú signatureüszCertificate.signaturecCsdS)zR Returns the tbsCertificate payload bytes as defined in RFC 5280. Nr&rGr&r&r'Útbs_certificate_bytessz!Certificate.tbs_certificate_bytescCsdS)zh Returns the tbsCertificate payload bytes with the SCT list extension stripped. Nr&rGr&r&r'Útbs_precertificate_bytes sz$Certificate.tbs_precertificate_bytesrJrKrLcCsdS©z" Checks equality. Nr&rPr&r&r'rQszCertificate.__eq__cCsdS©z" Computes a hash. Nr&rGr&r&r'rSszCertificate.__hash__úserialization.Encoding©ÚencodingrcCsdS)zB Serializes the certificate to PEM or DER format. Nr&©r#r�r&r&r'Ú public_bytesszCertificate.public_bytesr)rprcCsdS)zÕ This method verifies that certificate issuer name matches the issuer subject name and that the certificate is signed by the issuer's private key. No other validation is performed. Nr&)r#rpr&r&r'Úverify_directly_issued_by$sz%Certificate.verify_directly_issued_byN)r)r*r+ÚabcÚabstractmethodrirTrjrkrmrnrorprrrurwrxr/rzr{r|rQrSrƒr„r&r&r&r'rc¤sfrc)Ú metaclassc@sTeZdZeejddœdd„ƒƒZeejddœdd„ƒƒZeejddœd d „ƒƒZd S) ÚRevokedCertificaterArFcCsdS)zG Returns the serial number of the revoked certificate. Nr&rGr&r&r'rj2sz RevokedCertificate.serial_numberr7cCsdS)zH Returns the date of when this certificate was revoked. Nr&rGr&r&r'Úrevocation_date9sz"RevokedCertificate.revocation_datercCsdS)zW Returns an Extensions object containing a list of Revoked extensions. Nr&rGr&r&r'r/@szRevokedCertificate.extensionsN) r)r*r+rTr…r†rjr‰r/r&r&r&r'rˆ1srˆc@sTeZdZddddœdd„Zeddœdd „ƒZeddœd d „ƒZeddœd d „ƒZdS)Ú_RawRevokedCertificaterAr7r©rjr‰r/cCs||_||_||_dSr ©Ú_serial_numberÚ_revocation_dateÚ _extensions©r#rjr‰r/r&r&r'r"Msz_RawRevokedCertificate.__init__rFcCs|jSr )r�rGr&r&r'rjWsz$_RawRevokedCertificate.serial_numbercCs|jSr )rŽrGr&r&r'r‰[sz&_RawRevokedCertificate.revocation_datecCs|jSr )r�rGr&r&r'r/_sz!_RawRevokedCertificate.extensionsN)r)r*r+r"rTrjr‰r/r&r&r&r'rŠLs rŠc@s¤eZdZejdddœdd„ƒZejdddœdd „ƒZejd d d œd d„ƒZeejddœdd„ƒƒZ eejddœdd„ƒƒZ eejddœdd„ƒƒZ eejddœdd„ƒƒZ eejddœdd„ƒƒZ eejddœd d!„ƒƒZeejddœd"d#„ƒƒZeejddœd$d%„ƒƒZejd&d'd(œd)d*„ƒZejd dœd+d,„ƒZejd d-d.œd/d0„ƒZejd1d2d.œd3d0„ƒZejd4d5d.œd6d0„ƒZejd7dœd8d9„ƒZejd:d'd;œdS)?ÚCertificateRevocationListrr@r€cCsdS)z: Serializes the CRL to PEM or DER format. Nr&r‚r&r&r'rƒesz&CertificateRevocationList.public_bytesrdrecCsdSrgr&rhr&r&r'riksz%CertificateRevocationList.fingerprintrAz#typing.Optional[RevokedCertificate])rjrcCsdS)zs Returns an instance of RevokedCertificate or None if the serial_number is not in the CRL. Nr&)r#rjr&r&r'Ú(get_revoked_certificate_by_serial_numberqszBCertificateRevocationList.get_revoked_certificate_by_serial_numberrsrFcCsdSrtr&rGr&r&r'ruzsz2CertificateRevocationList.signature_hash_algorithmrcCsdSrvr&rGr&r&r'rw„sz1CertificateRevocationList.signature_algorithm_oidrcCsdS)zC Returns the X509Name with the issuer of this CRL. Nr&rGr&r&r'rp‹sz CertificateRevocationList.issuerú"typing.Optional[datetime.datetime]cCsdS)z? Returns the date of next update for this CRL. Nr&rGr&r&r'Ú next_update’sz%CertificateRevocationList.next_updater7cCsdS)z? Returns the date of last update for this CRL. Nr&rGr&r&r'Ú last_update™sz%CertificateRevocationList.last_updatercCsdS)zS Returns an Extensions object containing a list of CRL extensions. Nr&rGr&r&r'r/ sz$CertificateRevocationList.extensionscCsdSryr&rGr&r&r'rz§sz#CertificateRevocationList.signaturecCsdS)zO Returns the tbsCertList payload bytes as defined in RFC 5280. Nr&rGr&r&r'Útbs_certlist_bytes®sz,CertificateRevocationList.tbs_certlist_bytesrJrKrLcCsdSr}r&rPr&r&r'rQµsz CertificateRevocationList.__eq__cCsdS)z< Number of revoked certificates in the CRL. Nr&rGr&r&r'r[»sz!CertificateRevocationList.__len__rˆ)ÚidxrcCsdSr r&©r#r—r&r&r'r]Ász%CertificateRevocationList.__getitem__Úsliceútyping.List[RevokedCertificate]cCsdSr r&r˜r&r&r'r]Åsztyping.Union[int, slice]zAtyping.Union[RevokedCertificate, typing.List[RevokedCertificate]]cCsdS)zS Returns a revoked certificate (or slice of revoked certificates). Nr&r˜r&r&r'r]Ész#typing.Iterator[RevokedCertificate]cCsdS)z8 Iterator over the revoked certificates Nr&rGr&r&r'r\Ñsz"CertificateRevocationList.__iter__r)rmrcCsdS)zQ Verifies signature of revocation list against given public key. Nr&)r#rmr&r&r'Úis_signature_valid×sz,CertificateRevocationList.is_signature_validN)r)r*r+r…r†rƒrir’rTrurwrpr”r•r/rzr–rQr[ÚtypingÚoverloadr]r\r›r&r&r&r'r‘dsXr‘c@s6eZdZejdddœdd„ƒZejddœdd „ƒZejd dœd d „ƒZeejd dœdd„ƒƒZ eejddœdd„ƒƒZ eejddœdd„ƒƒZ eejddœdd„ƒƒZ eejddœdd„ƒƒZ ejdddœdd „ƒZeejddœd!d"„ƒƒZeejddœd#d$„ƒƒZeejddœd%d&„ƒƒZejddd'œd(d)„ƒZd*S)+ÚCertificateSigningRequestrJrKrLcCsdSr}r&rPr&r&r'rQäsz CertificateSigningRequest.__eq__rArFcCsdSr~r&rGr&r&r'rSêsz"CertificateSigningRequest.__hash__rcCsdSrlr&rGr&r&r'rmðsz$CertificateSigningRequest.public_keyrcCsdSrqr&rGr&r&r'rrösz!CertificateSigningRequest.subjectrscCsdSrtr&rGr&r&r'ruýsz2CertificateSigningRequest.signature_hash_algorithmrcCsdSrvr&rGr&r&r'rwsz1CertificateSigningRequest.signature_algorithm_oidrcCsdS)z@ Returns the extensions in the signing request. Nr&rGr&r&r'r/sz$CertificateSigningRequest.extensionsrUcCsdS)z/ Returns an Attributes object. Nr&rGr&r&r'r4sz$CertificateSigningRequest.attributesrr@r€cCsdS)z; Encodes the request to PEM or DER format. Nr&r‚r&r&r'rƒsz&CertificateSigningRequest.public_bytescCsdSryr&rGr&r&r'rz"sz#CertificateSigningRequest.signaturecCsdS)zd Returns the PKCS#10 CertificationRequestInfo bytes as defined in RFC 2986. Nr&rGr&r&r'Útbs_certrequest_bytes)sz/CertificateSigningRequest.tbs_certrequest_bytescCsdS)z8 Verifies signature of signing request. Nr&rGr&r&r'r›1sz,CertificateSigningRequest.is_signature_validrXcCsdS)z: Get the attribute value for a given OID. Nr&)r#rr&r&r'rZ8sz/CertificateSigningRequest.get_attribute_for_oidN)r)r*r+r…r†rQrSrmrTrrrurwr/r4rƒrzrŸr›rZr&r&r&r'ržãsDržr@ú typing.Any)ÚdataÚbackendrcCs t |¡Sr )Ú rust_x509Úload_pem_x509_certificate©r¡r¢r&r&r'r¤Dsr¤ztyping.List[Certificate])r¡rcCs t |¡Sr )r£Úload_pem_x509_certificates)r¡r&r&r'r¦Jsr¦cCs t |¡Sr )r£Úload_der_x509_certificater¥r&r&r'r§Osr§cCs t |¡Sr )r£Úload_pem_x509_csrr¥r&r&r'r¨Vsr¨cCs t |¡Sr )r£Úload_der_x509_csrr¥r&r&r'r©]sr©cCs t |¡Sr )r£Úload_pem_x509_crlr¥r&r&r'rªdsrªcCs t |¡Sr )r£Úload_der_x509_crlr¥r&r&r'r«ksr«c@sxeZdZdggfddddœdd„Zddd œd d „Zd d ddœdd„Zddœdddddœdd„Zddddddœdd„ZdS) Ú CertificateSigningRequestBuilderNútyping.Optional[Name]r-r3)Ú subject_namer/r4cCs||_||_||_dS)zB Creates an empty X.509 certificate request (v1). N)Ú _subject_namer�rW)r#r®r/r4r&r&r'r"rs z)CertificateSigningRequestBuilder.__init__r©ÚnamercCs4t|tƒstdƒ‚|jdur$tdƒ‚t||j|jƒS)zF Sets the certificate requestor's distinguished name. úExpecting x509.Name object.Nú&The subject name may only be set once.)rNrÚ TypeErrorr¯r0r¬r�rW©r#r±r&r&r'r®�s   ÿz-CertificateSigningRequestBuilder.subject_namerrK©ÚextvalÚcriticalrcCsDt|tƒstdƒ‚t|j||ƒ}t||jƒt|j|j|g|j ƒS)zE Adds an X.509 extension to the certificate request. ú"extension must be an ExtensionType) rNrr´rrr2r�r¬r¯rW©r#r·r¸r.r&r&r'Ú add_extension�s   ýz.CertificateSigningRequestBuilder.add_extension)Ú_tagrr@ztyping.Optional[_ASN1Type])rrBr¼rcCs|t|tƒstdƒ‚t|tƒs$tdƒ‚|dur>t|tƒs>tdƒ‚t||jƒ|durZ|j}nd}t|j |j |j|||fgƒS)zK Adds an X.509 attribute with an OID and associated value. zoid must be an ObjectIdentifierzvalue must be bytesNztag must be _ASN1Type) rNrr´r@rr6rWrBr¬r¯r�)r#rrBr¼Útagr&r&r'Ú add_attributeŸs   ýz.CertificateSigningRequestBuilder.add_attributerú"typing.Optional[_AllowedHashTypes]r rž©Ú private_keyrfr¢rcCs |jdurtdƒ‚t |||¡S)zF Signs the request using the requestor's private key. Nz/A CertificateSigningRequest must have a subject)r¯r0r£Zcreate_x509_csr©r#rÁrfr¢r&r&r'Úsign¿s z%CertificateSigningRequestBuilder.sign)N)r)r*r+r"r®r»r¾rÃr&r&r&r'r¬qsú û$ür¬c @sÒeZdZUded<ddddddgfddddddddd œd d „Zd dd œdd„Zd dd œdd„Zdddœdd„Zdddœdd„Zdddœdd„Z dddœdd„Z d d!dd"œd#d$„Z d.dd%œd&d'd(d)d*d+œd,d-„Z dS)/ÚCertificateBuilderr-r�Nr­z*typing.Optional[CertificatePublicKeyTypes]útyping.Optional[int]r“r)Ú issuer_namer®rmrjrnror/rcCs6tj|_||_||_||_||_||_||_||_ dSr ) r^r`Z_versionÚ _issuer_namer¯Ú _public_keyr�Ú_not_valid_beforeÚ_not_valid_afterr�)r#rÆr®rmrjrnror/r&r&r'r"Ðs zCertificateBuilder.__init__rr°cCsDt|tƒstdƒ‚|jdur$tdƒ‚t||j|j|j|j |j |j ƒS)z3 Sets the CA's distinguished name. r²Nú%The issuer name may only be set once.) rNrr´rÇr0rÄr¯rÈr�rÉrÊr�rµr&r&r'rÆãs  ùzCertificateBuilder.issuer_namecCsDt|tƒstdƒ‚|jdur$tdƒ‚t|j||j|j|j |j |j ƒS)z: Sets the requestor's distinguished name. r²Nr³) rNrr´r¯r0rÄrÇrÈr�rÉrÊr�rµr&r&r'r®õs  ùzCertificateBuilder.subject_namer)Úkeyrc Cs`t|tjtjtjtjt j t j t jfƒs.tdƒ‚|jdur@tdƒ‚t|j|j||j|j|j|jƒS)zT Sets the requestor's public key (as found in the signing request). z‰Expecting one of DSAPublicKey, RSAPublicKey, EllipticCurvePublicKey, Ed25519PublicKey, Ed448PublicKey, X25519PublicKey, or X448PublicKey.Nz$The public key may only be set once.)rNrZ DSAPublicKeyr Z RSAPublicKeyrZEllipticCurvePublicKeyr ZEd25519PublicKeyr ZEd448PublicKeyrZX25519PublicKeyr Z X448PublicKeyr´rÈr0rÄrÇr¯r�rÉrÊr�)r#rÌr&r&r'rms2ùþ ÿ ùzCertificateBuilder.public_keyrA©ÚnumberrcCsht|tƒstdƒ‚|jdur$tdƒ‚|dkr4tdƒ‚| ¡dkrHtdƒ‚t|j|j|j ||j |j |j ƒS)z5 Sets the certificate serial number. ú'Serial number must be of integral type.Nú'The serial number may only be set once.rz%The serial number should be positive.é ú3The serial number should not be more than 159 bits.) rNrAr´r�r0Ú bit_lengthrÄrÇr¯rÈrÉrÊr�©r#rÎr&r&r'rj,s&   ÿùz CertificateBuilder.serial_numberr7r8cCszt|tjƒstdƒ‚|jdur&tdƒ‚t|ƒ}|tkr>tdƒ‚|jdurZ||jkrZtdƒ‚t|j |j |j |j ||j|j ƒS)z7 Sets the certificate activation time. úExpecting datetime object.Nz*The not valid before may only be set once.z>The not valid before date must be on or after 1950 January 1).zBThe not valid before date must be before the not valid after date.)rNr;r´rÉr0r>Ú_EARLIEST_UTC_TIMErÊrÄrÇr¯rÈr�r�©r#r9r&r&r'rnGs,  ÿÿùz#CertificateBuilder.not_valid_beforecCszt|tjƒstdƒ‚|jdur&tdƒ‚t|ƒ}|tkr>tdƒ‚|jdurZ||jkrZtdƒ‚t|j |j |j |j |j||j ƒS)z7 Sets the certificate expiration time. rÕNz)The not valid after may only be set once.zrÖrÉrÄrÇr¯rÈr�r�r×r&r&r'rods2  ÿÿþÿùz"CertificateBuilder.not_valid_afterrrKr¶c CsTt|tƒstdƒ‚t|j||ƒ}t||jƒt|j|j |j |j |j |j |j|gƒS)z= Adds an X.509 extension to the certificate. r¹)rNrr´rrr2r�rÄrÇr¯rÈr�rÉrÊrºr&r&r'r»„s   ùz CertificateBuilder.add_extension)Ú rsa_paddingrr¿r ztdƒ‚|jdurZ||jkrZtdƒ‚t|j ||j|j |j ƒS)NrÕú!Last update may only be set once.ú8The last update date must be on or after 1950 January 1.z9The last update date must be before the next update date.) rNr;r´rÝr0r>rÖrÞrÚrÇr�rÛ)r#r•r&r&r'r•ås(  ÿÿûz,CertificateRevocationListBuilder.last_update)r”rcCsrt|tjƒstdƒ‚|jdur&tdƒ‚t|ƒ}|tkr>tdƒ‚|jdurZ||jkrZtdƒ‚t|j |j||j |j ƒS)NrÕrßràz8The next update date must be after the last update date.) rNr;r´rÞr0r>rÖrÝrÚrÇr�rÛ)r#r”r&r&r'r”ýs(  ÿÿûz,CertificateRevocationListBuilder.next_updaterrKr¶cCsLt|tƒstdƒ‚t|j||ƒ}t||jƒt|j|j |j |j|g|j ƒS)zM Adds an X.509 extension to the certificate revocation list. r¹) rNrr´rrr2r�rÚrÇrÝrÞrÛrºr&r&r'r»s   ûz.CertificateRevocationListBuilder.add_extensionrˆ)Úrevoked_certificatercCs2t|tƒstdƒ‚t|j|j|j|j|j|gƒS)z8 Adds a revoked certificate to the CRL. z)Must be an instance of RevokedCertificate) rNrˆr´rÚrÇrÝrÞr�rÛ)r#rár&r&r'Úadd_revoked_certificate(s  ûz8CertificateRevocationListBuilder.add_revoked_certificaterr¿r r‘rÀcCsD|jdurtdƒ‚|jdur$tdƒ‚|jdur6tdƒ‚t |||¡S)NzA CRL must have an issuer namez"A CRL must have a last update timez"A CRL must have a next update time)rÇr0rÝrÞr£Zcreate_x509_crlrÂr&r&r'rÃ9s   z%CertificateRevocationListBuilder.sign)N) r)r*r+rÙr"rÆr•r”r»rârÃr&r&r&r'rÚÄs úürÚc@sjeZdZddgfddddœdd„Zddd œd d „Zd dd œdd„Zddddœdd„Zddddœdd„ZdS)ÚRevokedCertificateBuilderNrÅr“r-r‹cCs||_||_||_dSr rŒr�r&r&r'r"Lsz"RevokedCertificateBuilder.__init__rArÍcCsXt|tƒstdƒ‚|jdur$tdƒ‚|dkr4tdƒ‚| ¡dkrHtdƒ‚t||j|jƒS)NrÏrÐrz$The serial number should be positiverÑrÒ) rNrAr´r�r0rÓrãrŽr�rÔr&r&r'rjVs   ÿ ÿz'RevokedCertificateBuilder.serial_numberr7r8cCsNt|tjƒstdƒ‚|jdur&tdƒ‚t|ƒ}|tkr>tdƒ‚t|j||j ƒS)NrÕz)The revocation date may only be set once.z7The revocation date must be on or after 1950 January 1.) rNr;r´rŽr0r>rÖrãr�r�r×r&r&r'r‰hs  ÿ ÿz)RevokedCertificateBuilder.revocation_daterrKr¶cCsDt|tƒstdƒ‚t|j||ƒ}t||jƒt|j|j |j|gƒS)Nr¹) rNrr´rrr2r�rãr�rŽrºr&r&r'r»xs   ýz'RevokedCertificateBuilder.add_extensionr rˆ)r¢rcCs:|jdurtdƒ‚|jdur$tdƒ‚t|j|jt|jƒƒS)Nz/A revoked certificate must have a serial numberz1A revoked certificate must have a revocation date)r�r0rŽrŠrr�)r#r¢r&r&r'Úbuild†s  ÿýzRevokedCertificateBuilder.build)N)r)r*r+r"rjr‰r»rär&r&r&r'rãKsü rãrArFcCst t d¡d¡d?S)NéZbigr)rAÚ from_bytesÚosÚurandomr&r&r&r'Úrandom_serial_number”sré)N)N)N)N)N)N)MZ __future__rr…r;rçrœZ cryptographyrZ"cryptography.hazmat.bindings._rustrr£Zcryptography.hazmat.primitivesrrZ)cryptography.hazmat.primitives.asymmetricrrr r r r r rZ/cryptography.hazmat.primitives.asymmetric.typesrrrZcryptography.x509.extensionsrrrrZcryptography.x509.namerrZcryptography.x509.oidrrÖÚUnionZSHA224ZSHA256ZSHA384ZSHA512ZSHA3_224ZSHA3_256ZSHA3_384ZSHA3_512Z_AllowedHashTypesÚ Exceptionrr2r6r>r?rUÚEnumr^raÚABCMetarcÚregisterrˆrŠr‘ržr¤r¦r§r¨r©rªr«r¬rÄrÚrãrér&r&r&r'Ús|   (  ùÿ   $  | ] ÿÿÿÿÿÿ\xI