Viewing File: /opt/imunify360/venv/lib/python3.11/site-packages/Crypto/Signature/__pycache__/DSS.cpython-311.pyc



]j;ddlmZddlmZddlmZddlmZddlm	Z	ddl
mZddgZGd	de
ZGd
deZGdd
eZGddeZddZdS))DerSequence)
long_to_bytes)Integer)HMAC)EccKey)DsaKeyDssSigSchemenewc6eZdZdZdZdZdZdZdZdZ	dS)	r	zkA (EC)DSA signature object.
    Do not instantiate directly.
    Use :func:`Crypto.Signature.DSS.new`.
    c||_||_||_|j|_|jdz
dzdz|_dS)zCreate a new Digital Signature Standard (DSS) object.

        Do not instantiate this object directly,
        use `Crypto.Signature.DSS.new` instead.
        N)_key	_encoding_ordersize_in_bits_order_bits_order_bytes)selfkeyencodingorders    v/builddir/build/BUILD/imunify360-venv-2.6.3/opt/imunify360/venv/lib64/python3.11/site-packages/Crypto/Signature/DSS.py__init__zDssSigScheme.__init__3sO	!;3355!-1a7!;c4|jS)zRReturn ``True`` if this signature object can be used
        for signing messages.)rhas_private)rs rcan_signzDssSigScheme.can_signAsy$$&&&rc tdNzTo be provided by subclassesNotImplementedErrorrmsg_hashs  r_compute_noncezDssSigScheme._compute_nonceG!"@AAArc tdr r!r#s  r_valid_hashzDssSigScheme._valid_hashJr&rcjstd|st	d|}t
j|dj	}j
||}jdkr"dfd|D}n!t|}|S)aCompute the DSA/ECDSA signature of a message.

        Args:
          msg_hash (hash object):
            The hash that was carried out over the message.
            The object belongs to the :mod:`Crypto.Hash` package.
            Under mode ``'fips-186-3'``, the hash must be a FIPS
            approved secure hash (SHA-2 or SHA-3).

        :return: The signature as ``bytes``
        :raise ValueError: if the hash algorithm is incompatible to the (EC)DSA key
        :raise TypeError: if the (EC)DSA key has no private half
        zPrivate key is needed to signHash is not sufficiently strongNbinaryrc:g|]}t|jS)rr).0xrs  r
<listcomp>z%DssSigScheme.sign.<locals>.<listcomp>ks6222#$ -Q0ABB222r)rr	TypeErrorr(
ValueErrorr%r
from_bytesdigestr_signrjoinrencode)rr$noncezsig_pairoutputs`     rsignzDssSigScheme.signMsy$$&&	=;<<<))	@>???##H--
x001C$2C1CDEE9??1e,,>X%%XX2222(022233FF!**1133F
rc||std|jdkrVt|d|jzkrtdd|d|j||jdfD\}}n	t|d}n$#ttf$rtd	wxYwt|dks|std
t|dt|d}}d|cxkr|j
krnnd|cxkr|j
ksntd
tj|d|j}|j
|||f}|stddS)aCheck if a certain (EC)DSA signature is authentic.

        Args:
          msg_hash (hash object):
            The hash that was carried out over the message.
            This is an object belonging to the :mod:`Crypto.Hash` module.
            Under mode ``'fips-186-3'``, the hash must be a FIPS
            approved secure hash (SHA-2 or SHA-3).

          signature (``bytes``):
            The signature that needs to be validated.

        :raise ValueError: if the signature is not authentic
        r*r+z'The signature is not authentic (length)c6g|]}tj|Sr-)rr3)r.r/s  rr0z'DssSigScheme.verify.<locals>.<listcomp>s9 J J J$%!( 21 5 5 J J JrNT)strictz$The signature is not authentic (DER)z,The signature is not authentic (DER content)rr
z"The signature is not authentic (d)zThe signature is not authenticF)r(r2rlenrrdecode
IndexErrorhasOnlyIntsrrr3r4r_verify)rr$	signaturer_primes_primeder_seqr9results        rverifyzDssSigScheme.verifyzs
 ))	@>???>X%%9~~!d&7"788 !JKKK J J*34FT5F4F*G*3D4E4F4F*G*I J J JGWW
I%--..y.FF
+
I
I
I !GHHH
I7||q  (;(;(=(=  !OPPP&wqz22GGAJ4G4GWGG))))dk)))))1w3L3L3L3L3L3L3L3LABBBx001C$2C1CDEE""1w&899	?=>>>us#B++!CN)
__name__
__module____qualname____doc__rrr%r(r<rKr-rrr	r	-s
<<<'''BBBBBB+++Z*****rc<eZdZfdZdZdZdZdZdZxZ	S)DeterministicDsaSigSchemecjtt||||||_dSN)superrQr_private_key)rrrrprivate_key	__class__s     rrz"DeterministicDsaSigScheme.__init__s4
'..77XuMMM'rctj|}|j}t	|dz}||kr|||z
z}|S)zSee 2.3.2 in RFC6979r)rr3rrrA)rbstrrJq_lenb_lens     r	_bits2intz#DeterministicDsaSigScheme._bits2intsR#D))((**D		A
5==
&F
rcXd|cxkr|jksnJt||jS)zSee 2.3.3 in RFC6979r)rrr)r	int_mod_qs  r_int2octetsz%DeterministicDsaSigScheme._int2octetss>9****t{******Y(9:::rc||}||jkr|}n
||jz
}||S)zSee 2.3.4 in RFC6979)r\rr_)rrYz1z2s    r_bits2octetsz&DeterministicDsaSigScheme._bits2octetssI^^D
!
!
BBdk!B###rcX|}d|jz}d|jz}dD]}tj|||z||jz||z|}tj|||}d}d|cxkr|jksn|dkrStj||dz|}tj|||}d}t||j	krEtj|||}||z
}t||j	kE|
|}d|cxkr|jkn|S)z!Generate k in a deterministic way)rfrerr)r4digest_sizerr
r_rUrcrrArr\)rmhashh1mask_vnonce_kint_octr8mask_ts        rr%z(DeterministicDsaSigScheme._compute_nonces
\\^^5,,E--)	?	?Ghw%/#//0ABB C#0044 56;==>DVXX

Xgvu55<<>>FFu****t{****{{(7FW,<#(***0&(('6599@@BBFf++ 111'6599@@BB& f++ 111
NN6**E!u****t{*****"rcdS)NTr-r#s  rr(z%DeterministicDsaSigScheme._valid_hashstr)
rLrMrNrr\r_rcr%r(
__classcell__rWs@rrQrQs(((((			;;;$$$&&&PrrQc.eZdZdZfdZdZdZxZS)FipsDsaSigScheme))i))ru)irwctt||||||_t	|j}||jf|jvrd||jfz}t|dS)Nz+L/N (%d, %d) is not compliant to FIPS 186-3)
rTrsr	_randfuncrprr_fips_186_3_L_Nr2)rrrrrandfuncLerrorrWs       rrzFipsDsaSigScheme.__init__s
%%..sHeDDD!CENN''))
t (<<<B4+,-EU###=<rcDtjd|j|jSNr
)
min_inclusive
max_exclusiver|)rrandom_rangerryr#s  rr%zFipsDsaSigScheme._compute_nonces(#!26+-1^===	=rcL|jdkp|jdS)z*Verify that SHA-1, SHA-2 or SHA-3 are usedz
1.3.14.3.2.26z2.16.840.1.101.3.4.2.)oid
startswithr#s  rr(zFipsDsaSigScheme._valid_hashs,/A''(?@@	Br)rLrMrNr{rr%r(rprqs@rrsrssd
O$$$$$===BBBBBBBrrsc*eZdZfdZdZdZxZS)FipsEcDsaSigSchemecjtt||||||_dSrS)rTrrry)rrrrr|rWs     rrzFipsEcDsaSigScheme.__init__s1
 $''00hFFF!rcXtjd|jjj|jSr)rrr_curverryr#s  rr%z!FipsEcDsaSigScheme._compute_nonces.#!26)2B2H-1^===	=rc|jj}d}d}d}d}||z|z|z}	|j|v}n#t$rd}YnwxYw|S)zxVerify that the strength of the hash matches or exceeds
        the strength of the EC. We fail if the hash is too weak.)z2.16.840.1.101.3.4.2.4z2.16.840.1.101.3.4.2.7z2.16.840.1.101.3.4.2.5)z2.16.840.1.101.3.4.2.1z2.16.840.1.101.3.4.2.8z2.16.840.1.101.3.4.2.6)z2.16.840.1.101.3.4.2.2z2.16.840.1.101.3.4.2.9)z2.16.840.1.101.3.4.2.3z2.16.840.1.101.3.4.2.10F)rpointQrrAttributeError)	rr$modulus_bitssha224sha256sha384sha512shsrJs	         rr(zFipsEcDsaSigScheme._valid_hash"sy'4466`_EFvo&/	\S(FF			FFF	
s	=AA)rLrMrNrr%r(rprqs@rrrsV"""""===
rrr+Nc|dvrtd|zt|tr.|jj}d}|jjdkrtdnXt|trt|j}d}n,tdtt|z|rt||}nd}|d	krt||||S|d
kr9t|trt||||St||||Std|z)a
Create a signature object :class:`DssSigScheme` that
    can perform (EC)DSA signature or verification.

    .. note::
        Refer to `NIST SP 800 Part 1 Rev 4`_ (or newer release) for an
        overview of the recommended key lengths.

    Args:
        key (:class:`Crypto.PublicKey.DSA` or :class:`Crypto.PublicKey.ECC`):
            The key to use for computing the signature (*private* keys only)
            or for verifying one.
            For DSA keys, let ``L`` and ``N`` be the bit lengths of the modulus ``p``
            and of ``q``: the pair ``(L,N)`` must appear in the following list,
            in compliance to section 4.2 of `FIPS 186-4`_:

            - (1024, 160) *legacy only; do not create new signatures with this*
            - (2048, 224) *deprecated; do not create new signatures with this*
            - (2048, 256)
            - (3072, 256)

            For ECC, only keys over P-224, P-256, P-384, and P-521 are accepted.

        mode (string):
            The parameter can take these values:

            - ``'fips-186-3'``. The signature generation is randomized and carried out
              according to `FIPS 186-3`_: the nonce ``k`` is taken from the RNG.
            - ``'deterministic-rfc6979'``. The signature generation is not
              randomized. See RFC6979_.

        encoding (string):
            How the signature is encoded. This value determines the output of
            :meth:`sign` and the input to :meth:`verify`.

            The following values are accepted:

            - ``'binary'`` (default), the signature is the raw concatenation
              of ``r`` and ``s``. It is defined in the IEEE P.1363 standard.
              For DSA, the size in bytes of the signature is ``N/4`` bytes
              (e.g. 64 for ``N=256``).
              For ECDSA, the signature is always twice the length of a point
              coordinate (e.g. 64 bytes for P-256).

            - ``'der'``, the signature is a ASN.1 DER SEQUENCE
              with two INTEGERs (``r`` and ``s``). It is defined in RFC3279_.
              The size of the signature is variable.

        randfunc (callable):
            A function that returns random ``bytes``, of a given length.
            If omitted, the internal RNG is used.
            Only applicable for the *'fips-186-3'* mode.

    .. _FIPS 186-3: http://csrc.nist.gov/publications/fips/fips186-3/fips_186-3.pdf
    .. _FIPS 186-4: http://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.186-4.pdf
    .. _NIST SP 800 Part 1 Rev 4: http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-57pt1r4.pdf
    .. _RFC6979: http://tools.ietf.org/html/rfc6979
    .. _RFC3279: https://tools.ietf.org/html/rfc3279#section-2.2.2
    )r+derzUnknown encoding '%s'ded25519z ECC key is not on a NIST P curver/zUnsupported key type Nzdeterministic-rfc6979z
fips-186-3zUnknown DSS mode '%s')r2
isinstancerrrnamerrqstrtypergetattrrQrrs)rmoderr|rprivate_key_attrrVs       rr
r
6sWD(((08;<<<#v	C
 :?i''?@@@(	C	 	 C03tCyy>>ABBB
c#344&&&(h{KKK	
		c6""	D%c8UHEEE#C5(CCC047888r)r+N)Crypto.Util.asn1rCrypto.Util.numberrCrypto.Math.NumbersrCrypto.HashrCrypto.PublicKey.ECCrCrypto.PublicKey.DSAr__all__objectr	rQrsrr
r-rr<module>rseD)(((((,,,,,,''''''''''''''''''5
!wwwww6wwwtKKKKKKKK\BBBBB|BBBD>]9]9]9]9]9]9r
Back to Directory File Manager