403Webshell
Server IP : 127.0.1.1  /  Your IP : 216.73.216.17
Web Server : Apache/2.4.58 (Ubuntu)
System : Linux dalsi.io 6.8.0-117-generic #117-Ubuntu SMP PREEMPT_DYNAMIC Tue May 5 19:26:24 UTC 2026 x86_64
User : www-data ( 33)
PHP Version : 8.3.6
Disable Function : NONE
MySQL : OFF  |  cURL : ON  |  WGET : ON  |  Perl : ON  |  Python : OFF  |  Sudo : ON  |  Pkexec : OFF
Directory :  /usr/lib/python3/dist-packages/redis/__pycache__/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Command :


[ Back ]     

Current File : /usr/lib/python3/dist-packages/redis/__pycache__/ocsp.cpython-312.pyc
�

���b�,��
�ddlZddlZddlZddlmZmZddlZddlZddlm	Z	m
Z
ddlmZddl
mZddlmZddlmZmZddlmZdd	lmZdd
lmZmZddlmZmZddlmZdd
lm Z m!Z!d�Z"dd�Z#d�Z$d�Z%dd�Z&Gd�d�Z'y)�N)�urljoin�urlparse)�hazmat�x509)�InvalidSignature)�backends)�DSAPublicKey)�ECDSA�EllipticCurvePublicKey)�PKCS1v15)�RSAPublicKey)�SHA1�Hash)�Encoding�PublicFormat)�ocsp)�AuthorizationError�ConnectionErrorc�R�|j�}	t|t�r;|j|j|j
t
�|j�yt|t�r2|j|j|j
|j�yt|t�r;|j|j|j
t|j��y|j|j|j
�y#t$rtd��wxYw)Nzfailed to valid ocsp response)
�
public_key�
isinstancer
�verify�	signature�tbs_response_bytesr�signature_hash_algorithmr	rr
rr)�issuer_cert�
ocsp_response�pubkeys   �,/usr/lib/python3/dist-packages/redis/ocsp.py�_verify_responser s���
�
#�
#�
%�F�?��f�l�+��M�M��'�'��0�0��
��6�6�	
����
-��M�M��'�'��0�0��6�6�
�
�� 6�
7��M�M��'�'��0�0��m�<�<�=�
�
�M�M�-�1�1�=�3S�3S�T���?��=�>�>�?�s �A
D�AD�A
D�*&D�D&c�v�tj|�}|jtjjk(rtd��|jtjjk(r[|jtjjk7r?tdt|j�jd�d�d���td��|jtjj�k\rtd��|j r6|j tjj�krtd��|j"}|j$}|j&}|}|�||j(k(s||k(r|}n�|j*}t-||||�}		|	d	}
|
j0j3t4j6�}|�0t4j8j:j<|j>vrtd��|
}|rtA||�y#t.$rtd
��wxYw)
z=A wrapper the return the validity of a known ocsp certificatez4you are not authorized to view this ocsp certificatezReceived an �.�z ocsp certificate statusz?failed to retrieve a sucessful response from the ocsp responderz)ocsp certificate was issued in the futurez1ocsp certificate has invalid update - in the pastrz'no certificates found for the responderz'delegate not autorized for ocsp signingT)!r�load_der_ocsp_response�response_status�OCSPResponseStatus�UNAUTHORIZEDr�
SUCCESSFUL�certificate_status�OCSPCertStatus�GOODr�str�split�this_update�datetime�now�next_update�responder_name�issuer_key_hash�responder_key_hash�subject�certificates�_get_certificates�
IndexError�
extensions�get_extension_for_classr�ExtendedKeyUsage�oid�ExtendedKeyUsageOID�OCSP_SIGNING�valuer )r�
ocsp_bytes�validaterr2�issuer_hash�responder_hash�cert_to_validate�certs�responder_certs�responder_cert�exts            r�_check_certificaterI2s���/�/�
�;�M��$�$��(?�(?�(L�(L�L� �!W�X�X��$�$��(?�(?�(J�(J�J��+�+�t�/B�/B�/G�/G�G�!��s�=�#C�#C�D�J�J�3�O�PQ�R�S�T*�*��
�
�M�
�	
�� � �H�$5�$5�$9�$9�$;�;��I�J�J�	�!�!��%�%��(9�(9�(=�(=�(?�?��Q�R�R�"�1�1�N��/�/�K�"�5�5�N�"���"��k�1�1�1��[�(�&���*�*��+��;���
��	M�,�Q�/�N��'�'�?�?��@U�@U�V���;�$�(�(�6�6�C�C�3�9�9�T�!�"K�L�L�)����)�=�9����	M�!�"K�L�L�	M�s�'H#�#H8c��|�8|D�cgc]+}t|�|k(r|j|jk(r|��-}}|S|D�cgc],}|j|k(r|j|jk(r|��.}}|Scc}wcc}w�N)�_get_pubkey_hash�issuerr5)rErr2rC�cr6s      rr7r7ms������
����"�n�4����[�EX�EX�9X�
�
��
���	�
���y�y�N�*�q�x�x�;�;N�;N�/N�
�
��
����
��
s
�0A4�1A9c�
�|j�}t|t�r/|jtj
tj�}nmt|t�r/|jtjtj�}n.|jtj
tj�}tt�tj���}|j!|�|j#�S)N)�backend)rrr
�public_bytesr�DERr�PKCS1r�X962�UncompressedPoint�SubjectPublicKeyInforrr�default_backend�update�finalize)�certificater�h�sha1s    rrLrL~s���
�
#�
#�
%�F��&�,�'�������l�.@�.@�A��	�F�2�	3�����
�
�|�/M�/M�N��������l�.O�.O�P������ 8� 8� :�;�D��K�K��N��=�=�?��c�d�|dvrtd��d}|j�j�}|j�D]/}|j�}|j|j
k(s�-|}n|�td��|�%t
j|�}||k7rtd��t||�S)z�An implemention of a function for set_ocsp_client_callback in PyOpenSSL.

    This function validates that the provide ocsp_bytes response is valid,
    and matches the expected, stapled responses.
    )r]Nzno ocsp response presentNz2no matching issuer cert found in certificate chainz/received and expected certificates do not match)	r�get_peer_certificate�to_cryptography�get_peer_cert_chainr5rMr�load_pem_x509_certificaterI)�conr@�expectedr�	peer_certrN�cert�es        r�ocsp_staple_verifierrh�s����[� ��8�9�9��K��(�(�*�:�:�<�I�
�
$�
$�
&���� � �"���<�<�9�+�+�+��K��	����R�S�S����*�*�8�4����>�!�"S�T�T��k�:�6�6r]c�B�eZdZdZdd�Zd�Zd�Zd�Zd�Zd�Z	d	�Z
d
�Zy)�OCSPVerifieraA class to verify ssl sockets for RFC6960/RFC6961. This can be used
    when using direct validation of OCSP responses and certificate revocations.

    @see https://datatracker.ietf.org/doc/html/rfc6960
    @see https://datatracker.ietf.org/doc/html/rfc6961
    Nc�<�||_||_||_||_yrK)�SOCK�HOST�PORT�CA_CERTS)�self�sock�host�port�ca_certss     r�__init__zOCSPVerifier.__init__�s����	���	���	� ��
r]c��tj|�}tj|j	�tj��}|S)z?Convert SSL certificates in a binary (DER) format to ASCII PEM.)�ssl�DER_cert_to_PEM_certrrb�encoderrW)rp�der�pemrfs    r�
_bin2asciizOCSPVerifier._bin2ascii�s:���&�&�s�+���-�-�c�j�j�l�H�<T�<T�<V�W���r]c��|jjd�}|durtd��|j|�}|j	|�S)z�This function returns the certificate, primary issuer, and primary ocsp server
        in the chain for a socket already wrapped with ssl.
        TFz!no certificate found for ssl peer)rl�getpeercertrr|�_certificate_components)rprzrfs   r�components_from_socketz#OCSPVerifier.components_from_socket�sJ���i�i�#�#�D�)���%�<�!�"E�F�F����s�#���+�+�D�1�1r]c���	|jjtjjj
�j}|D�cgc]5}|jtjjjk(r|��7}}	|djj}|D�cgc]5}|jtjjjk(r|��7}}	|djj}|||fS#tjjj$rtd��wxYwcc}w#t$rd}Y��wxYwcc}w#t$rtd��wxYw)z�Given an SSL certificate, retract the useful components for
        validating the certificate status with an OCSP server.

        Args:
            cert ([bytes]): A PEM encoded ssl certificate
        z-No AIA information present in ssl certificaterNzno ocsp servers in certificate)r9�get_extension_for_oidrr<�ExtensionOID�AUTHORITY_INFORMATION_ACCESSr?�cryptography�ExtensionNotFoundr�
access_method�AuthorityInformationAccessOID�
CA_ISSUERS�access_locationr8�OCSP)rprf�aia�i�issuersrM�ocspsrs        rrz$OCSPVerifier._certificate_components�s_��	S��/�/�7�7����%�%�B�B���e�
��
�����$�(�(�"H�"H�"S�"S�S�
�
��
�
	��Q�Z�/�/�5�5�F��
�����$�(�(�"H�"H�"M�"M�M�
�
��
�	D���8�+�+�1�1�D��V�T�!�!��5� � �+�+�=�=�	S�!�"Q�R�R�	S��
���	��F�	��
���	D�!�"B�C�C�	D�s6�AD�
:D8�
D=�':E�$E�3D5�=E�
E�E(c��tj|j|jf|j��}tj|j�tj��}|j|�S)z�Return the certificate, primary issuer, and primary ocsp server
        from the host defined by the socket. This is useful in cases where
        different certificates are occasionally presented.
        )rt)rw�get_server_certificatermrnrorrbryrrWr)rpr{rfs   r�!components_from_direct_connectionz.OCSPVerifier.components_from_direct_connection�sY���(�(�$�)�)�T�Y�Y�)?�$�-�-�X���-�-�c�j�j�l�H�<T�<T�<V�W���+�+�D�1�1r]c��tj�}|j||tjj
jj��}|j�}tj|jtj
jjj��}t||j!d��}|S)z#Return the complete url to the ocsp�ascii)r�OCSPRequestBuilder�add_certificater�r�
primitives�hashes�SHA256�build�base64�	b64encoderQ�
serializationrrRr�decode)rp�serverrfr�orb�request�path�urls        r�build_certificate_urlz"OCSPVerifier.build_certificate_url�s����%�%�'���!�!��+�|�2�2�=�=�D�D�K�K�M�
���)�)�+������ � ��!2�!2�!@�!@�!I�!I�!M�!M�N�
���f�d�k�k�'�2�3���
r]c�t�tj|�}|jstd��|j}|j|�}|j
|||�}t|�jdd�}tj||��}|jstd��t||jd�S)z5Checks the validitity of an ocsp server for an issuerz"failed to fetch issuer certificatezapplication/ocsp-request)�HostzContent-Type)�headersz failed to fetch ocsp certificateT)
�requests�get�okr�contentr|r�r�netlocrI)	rpr�rf�
issuer_url�rrzr�ocsp_url�headers	         r�check_certificatezOCSPVerifier.check_certificate
s���
�L�L��$���t�t�!�"F�G�G��i�i���o�o�c�*���-�-�f�d�K�H���X�&�-�-�6�
��
�L�L��6�2���t�t�!�"D�E�E�!�+�q�y�y�$�?�?r]c���	|j�\}}}|�td��|j|||�S#t$r7|j	�\}}}|�td��|j|||�cYSwxYw)aDReturns the validity of the certificate wrapping our socket.
        This first retrieves for validate the certificate, issuer_url,
        and ocsp_server for certificate validate. Then retrieves the
        issuer certificate from the issuer_url, and finally checks
        the valididy of OCSP revocation status.
        z%no issuers found in certificate chain)r�rr�rr�)rprfr��ocsp_servers    r�is_validzOCSPVerifier.is_valid"s���		I�,0�,G�,G�,I�)�D�*�k��!�%�&M�N�N��)�)�+�t�Z�H�H��!�	I�,0�,R�,R�,T�)�D�*�k��!�%�&M�N�N��)�)�+�t�Z�H�H�		I�s�36�=A6�5A6rK)�__name__�
__module__�__qualname__�__doc__rur|r�rr�r�r�r��r]rrjrj�s2���!��
2�&"�P2�� @�*Ir]rj)TrK)(r�r/rw�urllib.parserr�%cryptography.hazmat.primitives.hashesr�r�rr�cryptography.exceptionsr�cryptography.hazmatr�-cryptography.hazmat.primitives.asymmetric.dsar	�,cryptography.hazmat.primitives.asymmetric.ecr
r�1cryptography.hazmat.primitives.asymmetric.paddingr�-cryptography.hazmat.primitives.asymmetric.rsar
rr�,cryptography.hazmat.primitives.serializationrr�cryptography.x509r�redis.exceptionsrrr rIr7rLrhrjr�r]r�<module>r�s`��
��
�*�,��%�4�(�F�V�F�F�<�O�"�@�?�88�v�"
� 7�8JI�JIr]

Youez - 2016 - github.com/yon3zu
LinuXploit