a „oeæ<ã@s2dZddlZddlZejZGdd„deƒZGdd„deƒZGdd„deƒZed k�r.d Z ej ej Bej Bej BejBZe de ejdd¡\ZZe ej¡Zed eƒee eed �Zee ed �ZedejdejdfƒdZdZdZejrüeedj ƒ�rbed7Ze !e¡\Z"Zedeƒej�r>eedj ƒdk�r>�qbed7Ze !e¡\Z"Zedeƒqæedej#ƒedej$ƒd %d¡Z&e 'e&¡Z(e )e&e(¡e *e&¡\Z+Z(e ,e+e(¡Z-e-e&k�sÂJ‚e .e&¡Z/e 0e/¡\Z1Z2ede2ƒe&e1k�sòJ‚ej.e&dd�Z/e 0e/¡\Z1Z2ede2ƒe&e1k�s&J‚edƒdS)a6 Helper classes for SSPI authentication via the win32security module. SSPI authentication involves a token-exchange "dance", the exact details of which depends on the authentication provider used. There are also a number of complex flags and constants that need to be used - in most cases, there are reasonable defaults. These classes attempt to hide these details from you until you really need to know. They are not designed to handle all cases, just the common ones. If you need finer control than offered here, just use the win32security functions directly. éNc@s^eZdZdd„Zdd„Zdd„Zdd„Zd d „Zd d „Zd d„Z dd„Z ddd„Z dd„Z dS)Ú _BaseAuthcCs | ¡dS)N)Úreset©Úself©rú/C:\Program Files\Certbot\pkgs\win32\lib\sspi.pyÚ__init__sz_BaseAuth.__init__cCs"d|_d|_d|_d|_d|_dS)z)Reset everything to an unauthorized stateNFr)ÚctxtÚ authenticatedÚinitiator_nameÚ service_nameÚ next_seq_numrrrrrs z_BaseAuth.resetcCs|j}|jd|_|S)zsGet the next sequence number for a transmission. Default implementation is to increment a counter é)r )rÚretrrrÚ_get_next_seq_num$s z_BaseAuth._get_next_seq_numcCs||j tj¡}|d}t ¡}| t t|ƒtj ¡¡| t |tj ¡¡||d_ |j  d||  ¡¡|dj |dj fS)z’Encrypt a string, returning a tuple of (encrypted_data, trailer). These can be passed to decrypt to get back the original string. ÚSecurityTrailerrr)r ÚQueryContextAttributesÚsspiconÚSECPKG_ATTR_SIZESÚ win32securityÚPySecBufferDescTypeÚappendÚPySecBufferTypeÚlenÚSECBUFFER_DATAÚSECBUFFER_TOKENÚBufferÚEncryptMessager)rÚdataÚ pkg_size_infoZ trailersizeÚencbufrrrÚencrypt,s ÿ z_BaseAuth.encryptcCsht ¡}| t t|ƒtj¡¡| t t|ƒtj¡¡||d_||d_|j   ||  ¡¡|djS)zADecrypt a previously encrypted string, returning the orignal datarr) rrrrrrrrrr ÚDecryptMessager)rrZtrailerr rrrÚdecrypt<sÿ  z_BaseAuth.decryptcCsr|j tj¡}|d}t ¡}| t t|ƒtj ¡¡| t |tj ¡¡||d_ |j  d||  ¡¡|dj S)z¬sign a string suitable for transmission, returning the signature. Passing the data and signature to verify will determine if the data is unchanged. Z MaxSignaturerr)r rrrrrrrrrrrZ MakeSignaturer)rrrZsigsizeÚsigbufrrrÚsignHs z_BaseAuth.signcCsbt ¡}| t t|ƒtj¡¡| t t|ƒtj¡¡||d_||d_|j   ||  ¡¡dS)zgVerifies data and its signature. If verification fails, an sspi.error will be raised. rrN) rrrrrrrrrr ZVerifySignaturer)rrÚsigr$rrrÚverifyWs   z_BaseAuth.verifycCsjt ¡}| t t|ƒtj¡¡||d_| t dtj¡¡|j   ||  ¡¡}|dj}||tj k fS)a; GSSAPI's unwrap with SSPI. https://docs.microsoft.com/en-us/windows/win32/secauthn/sspi-kerberos-interoperability-with-gssapi Usable mainly with Kerberos SSPI package, but this is not enforced. Return the clear text, and a boolean that is True if the token was encrypted. rr) rrrrrrZSECBUFFER_STREAMrrr r"rÚSECQOP_WRAP_NO_ENCRYPT)rÚtokenÚbufferZpfQOPÚrrrrÚunwrapcs ÿ  z_BaseAuth.unwrapFc Cs´|j tj¡}|d}|d}t ¡}| t t|ƒtj ¡¡||d_ | t |tj ¡¡| t |tj ¡¡|rxdntj }|j ||| ¡¡|dj |dj |dj }|S)a6 GSSAPI's wrap with SSPI. https://docs.microsoft.com/en-us/windows/win32/secauthn/sspi-kerberos-interoperability-with-gssapi Usable mainly with Kerberos SSPI package, but this is not enforced. Wrap a message to be sent to the other side. Encrypted if encrypt is True. rZ BlockSizerré)r rrrrrrrrrrrZSECBUFFER_PADDINGr(rr) rÚmsgr!Z size_infoZ trailer_sizeZ block_sizer*ZfQOPr+rrrÚwrap|s   ÿ ÿz_BaseAuth.wrapcCsD|jstdƒ‚z|j tj¡}Wnty2Yn0|\|_|_dS)zHAdds initiator and service names in the security context for ease of usez+Sec context is not completely authenticatedN) r Ú ValueErrorr rrZSECPKG_ATTR_NATIVE_NAMESÚerrorr r )rÚnamesrrrÚ_amend_ctx_name¡s z_BaseAuth._amend_ctx_nameN)F) Ú__name__Ú __module__Ú __qualname__rrrr!r#r%r'r,r/r3rrrrrs    %rc@s.eZdZdZddddejfdd„Zdd„ZdS)Ú ClientAuthz;Manages the client side of an SSPI authentication handshakeNcCsn|dur tjtjBtjBtjB}||_||_||_t  |¡|_ t  ||j dtj d|¡\|_ |_t |¡dS©NÚName)rÚISC_REQ_INTEGRITYÚISC_REQ_SEQUENCE_DETECTÚISC_REQ_REPLAY_DETECTÚISC_REQ_CONFIDENTIALITYÚscflagsÚdatarepÚ targetspnrÚQuerySecurityPackageInfoÚpkg_infoÚAcquireCredentialsHandleZSECPKG_CRED_OUTBOUNDÚ credentialsÚcredentials_expiryrr)rÚpkg_nameZ client_nameZ auth_infor@r>r?rrrr²s0 ÿþýÿ ûýzClientAuth.__init__c Csö|durFt|ƒtjkrFt ¡}t |jdtj¡}||_| |¡|}t ¡}t |jdtj¡}| |¡|j }|j dur†t  ¡|_ t  |j ||j |j|j||j |¡\}}}||_||_|tjtjfvrÖ|j  |¡|dk|_|jrî| ¡||fS)zVPerform *one* step of the client authentication process. Pass None for the first roundNÚMaxTokenr)ÚtyperrrrBrrrrr ÚPyCtxtHandleTypeZInitializeSecurityContextrDr@r>r?Ú ctxt_attrÚ ctxt_expiryÚSEC_I_COMPLETE_NEEDEDÚSEC_I_COMPLETE_AND_CONTINUEÚCompleteAuthTokenr r3© rZ sec_buffer_inZsec_buffer_newZtokenbufZsec_buffer_outZctxtinÚerrÚattrÚexprrrÚ authorizeÒsJÿ þ ÿ  ÿ   ø   zClientAuth.authorize©r4r5r6Ú__doc__rZSECURITY_NETWORK_DREPrrSrrrrr7¯sù r7c@s*eZdZdZddejfdd„Zdd„ZdS)Ú ServerAuthz;Manages the server side of an SSPI authentication handshakeNcCsn||_||_|dur,tjtjBtjBtjB}||_t  |¡|_ t  ||j dtj dd¡\|_ |_t |¡dSr8)Úspnr?rZASC_REQ_INTEGRITYZASC_REQ_SEQUENCE_DETECTZASC_REQ_REPLAY_DETECTZASC_REQ_CONFIDENTIALITYr>rrArBrCÚSECPKG_CRED_INBOUNDrDrErr)rrFrWr>r?rrrrs(ÿþýÿ ÿýzServerAuth.__init__c Csò|durFt|ƒtjkrFt ¡}t |jdtj¡}||_| |¡|}t ¡}t |jdtj¡}| |¡|j }|j dur†t  ¡|_ t  |j |||j |j|j |¡\}}}||_||_|tjtjfvrÒ|j  |¡|dk|_|jrê| ¡||fS)z8Perform *one* step of the server authentication process.NrGr)rHrrrrBrrrrr rIZAcceptSecurityContextrDr>r?rJrKrLrMrNr r3rOrrrrS sHÿ þ ÿ  ÿ   ù   zServerAuth.authorizerTrrrrrVsÿ rVÚ__main__ZKerberoszWe are:)r>r@)r>z SSP : %s (%s)r9ÚCommentrzClient step %szServer step %sz%Initiator name from the service side:z%Service name from the client side: ZhelloÚasciiz encrypted ?T)r!zcool!)3rUrrr1Úobjectrr7rVr4ZsspZISC_REQ_MUTUAL_AUTHr:r;r=r<ÚflagsrCrXZ cred_handlerRZQueryCredentialsAttributesZSECPKG_CRED_ATTR_NAMESZcredÚprintZ sspiclientZ sspiserverrBZ sec_bufferZ client_stepZ server_stepr rrrSrPr r Úencoderr%r&r'r!Z encryptedr#Z decryptedr/Úwrappedr,Z unwrappedZ was_encryptedrrrrÚstSO ÿþýüÿ  ÿ   ÿ