Viewing File: /usr/lib/python2.7/site-packages/backports/ssl_match_hostname/__init__.pyc

ó
„ÚuVc@sdZddlZddlZyddlZWnek
rGdZnXdZdefd„ƒYZdd„Z	d„Z
d	„Zd
„ZdS(sJThe match_hostname() function from Python 3.3.3, essential when using SSL.iÿÿÿÿNs3.5.0.1tCertificateErrorcBseZRS((t__name__t
__module__(((sI/usr/lib/python2.7/site-packages/backports/ssl_match_hostname/__init__.pyRsic
CsRg}|stS|jdƒ}|d}|d}|jdƒ}||krgtdt|ƒƒ‚n|sƒ|jƒ|jƒkS|dkrŸ|jdƒnY|jdƒs½|jdƒrÖ|jtj	|ƒƒn"|jtj	|ƒj
dd	ƒƒx$|D]}|jtj	|ƒƒqÿWtjd
dj|ƒdtj
ƒ}	|	j|ƒS(
shMatching according to RFC 6125, section 6.4.3

    http://tools.ietf.org/html/rfc6125#section-6.4.3
    t.iit*s,too many wildcards in certificate DNS name: s[^.]+sxn--s\*s[^.]*s\As\.s\Z(tFalsetsplittcountRtreprtlowertappendt
startswithtretescapetreplacetcompiletjoint
IGNORECASEtmatch(
tdnthostnamet
max_wildcardstpatstpartstleftmostt	remaindert	wildcardstfragtpat((sI/usr/lib/python2.7/site-packages/backports/ssl_match_hostname/__init__.pyt_dnsname_matchs*

"
&cCs=t|tƒr9tjdkr9t|ddddƒ}n|S(Nitencodingtasciiterrorststrict(i(t
isinstancetstrtsystversion_infotunicode(tobj((sI/usr/lib/python2.7/site-packages/backports/ssl_match_hostname/__init__.pyt_to_unicodeLscCs%tjt|ƒjƒƒ}||kS(sˆExact matching of IP addresses.

    RFC 6125 explicitly doesn't define an algorithm for this
    (section 1.7.2 - "Out of Scope").
    (t	ipaddresst
ip_addressR(trstrip(tipnamethost_iptip((sI/usr/lib/python2.7/site-packages/backports/ssl_match_hostname/__init__.pyt_ipaddress_matchQscCs|stdƒ‚nytjt|ƒƒ}WnUtk
rGd}n?tk
r]d}n)tk
r…tdkrd}q†‚nXg}|jddƒ}xŠ|D]‚\}}|dkrì|dkrÜt||ƒrÜdS|j	|ƒq¥|dkr¥|dk	rt
||ƒrdS|j	|ƒq¥q¥W|s—xc|jddƒD]L}xC|D];\}}|dkrQt||ƒr|dS|j	|ƒqQqQWqDWnt|ƒdkrÔtd	|d
j
tt|ƒƒfƒ‚n;t|ƒdkrtd||dfƒ‚ntd
ƒ‚dS(s)Verify that *cert* (in decoded format as returned by
    SSLSocket.getpeercert()) matches the *hostname*.  RFC 2818 and RFC 6125
    rules are followed, but IP addresses are not accepted for *hostname*.

    CertificateError is raised on failure. On success, the function
    returns nothing.
    stempty or no certificate, match_hostname needs a SSL socket or SSL context with either CERT_OPTIONAL or CERT_REQUIREDtsubjectAltNametDNSNs
IP Addresstsubjectt
commonNameis&hostname %r doesn't match either of %ss, shostname %r doesn't match %ris=no appropriate commonName or subjectAltName fields were found(((t
ValueErrorR)R*R(tNonetUnicodeErrortAttributeErrortgetRR
R/tlenRRtmapR(tcertRR-tdnsnamestsantkeytvaluetsub((sI/usr/lib/python2.7/site-packages/backports/ssl_match_hostname/__init__.pytmatch_hostname]sJ
	
	
	%(
t__doc__RR$R)tImportErrorR5t__version__R4RRR(R/RA(((sI/usr/lib/python2.7/site-packages/backports/ssl_match_hostname/__init__.pyt<module>s

5		
Back to Directory File Manager