
§|j   ã            "   @   sB  d  d l  Z  d  d l Z d  d l Z d  d l Z d  d l Z d  d l m Z m Z m Z m	 Z	 d  d l
 m Z m Z y d  d l Z Wn e k
 rž d Z Yn Xd d d d d g Z d	 j ƒ  j ƒ  Z y e j j Z e j Z Wn e k
 rý e Z Z Yn Xe d k	 oe e e f k Z y d  d
 l m Z m Z WnW e k
 r�y$ d  d l m Z d  d l m Z Wn e k
 rŠd Z d Z Yn XYn Xe s¬Gd d „  d e ƒ Z e sÍd d d „ Z d d „  Z Gd d „  d e ƒ Z Gd d „  d e ƒ Z d d d „ Z  d d „  Z! e! d d „  ƒ Z" d d „  Z# d d „  Z$ d S)é    N)ÚurllibÚhttp_clientÚmapÚfilter)ÚResolutionErrorÚExtractionErrorÚVerifyingHTTPSHandlerÚfind_ca_bundleÚis_availableÚ
cert_pathsÚ
opener_fora  
/etc/pki/tls/certs/ca-bundle.crt
/etc/ssl/certs/ca-certificates.crt
/usr/share/ssl/certs/ca-bundle.crt
/usr/local/share/certs/ca-root.crt
/etc/ssl/cert.pem
/System/Library/OpenSSL/certs/cert.pem
/usr/local/share/certs/ca-root-nss.crt
/etc/ssl/ca-bundle.pem
)ÚCertificateErrorÚmatch_hostname)r   )r   c               @   s   e  Z d  Z d S)r   N)Ú__name__Ú
__module__Ú__qualname__© r   r   ú</tmp/pip-build-5c7ija6t/setuptools/setuptools/ssl_support.pyr   5   s   r   é   c       
      C   sU  g  } |  s d S|  j  d ƒ } | d } | d d … } | j d ƒ } | | k rj t d t |  ƒ ƒ ‚ | s† |  j ƒ  | j ƒ  k S| d k r¢ | j d ƒ nY | j d	 ƒ sÀ | j d	 ƒ rÙ | j t j | ƒ ƒ n" | j t j | ƒ j	 d
 d ƒ ƒ x$ | D] } | j t j | ƒ ƒ qWt j
 d d j | ƒ d t j ƒ }	 |	 j | ƒ S)zpMatching according to RFC 6125, section 6.4.3

        http://tools.ietf.org/html/rfc6125#section-6.4.3
        FÚ.r   r   NÚ*z,too many wildcards in certificate DNS name: z[^.]+zxn--z\*z[^.]*z\Az\.z\Z)ÚsplitÚcountr   ÚreprÚlowerÚappendÚ
startswithÚreÚescapeÚreplaceÚcompileÚjoinÚ
IGNORECASEÚmatch)
ÚdnÚhostnameÚmax_wildcardsÚpatsÚpartsÚleftmostÚ	remainderÚ	wildcardsÚfragÚpatr   r   r   Ú_dnsname_match;   s*    
"&r.   c             C   sO  |  s t  d ƒ ‚ g  } |  j d f  ƒ } x@ | D]8 \ } } | d k r1 t | | ƒ r\ d S| j | ƒ q1 W| sÓ x] |  j d f  ƒ D]I } x@ | D]8 \ } } | d k r“ t | | ƒ r¾ d S| j | ƒ q“ Wq† Wt | ƒ d k rt d | d	 j t t | ƒ ƒ f ƒ ‚ n; t | ƒ d k r?t d
 | | d f ƒ ‚ n t d ƒ ‚ d S)a=  Verify that *cert* (in decoded format as returned by
        SSLSocket.getpeercert()) matches the *hostname*.  RFC 2818 and RFC 6125
        rules are followed, but IP addresses are not accepted for *hostname*.

        CertificateError is raised on failure. On success, the function
        returns nothing.
        zempty or no certificateÚsubjectAltNameÚDNSNÚsubjectÚ
commonNamer   z&hostname %r doesn't match either of %sz, zhostname %r doesn't match %rr   z=no appropriate commonName or subjectAltName fields were found)	Ú
ValueErrorÚgetr.   r   Úlenr   r!   r   r   )Úcertr%   ÚdnsnamesÚsanÚkeyÚvalueÚsubr   r   r   r   o   s.    %r   c               @   s.   e  Z d  Z d Z d d „  Z d d „  Z d S)r   z=Simple verifying handler: no auth, subclasses, timeouts, etc.c             C   s   | |  _  t j |  ƒ d  S)N)Ú	ca_bundleÚHTTPSHandlerÚ__init__)Úselfr<   r   r   r   r>   ›   s    	zVerifyingHTTPSHandler.__init__c                s   ˆ  j  ‡  f d d †  | ƒ S)Nc                s   t  |  ˆ  j | � S)N)ÚVerifyingHTTPSConnr<   )ÚhostÚkw)r?   r   r   Ú<lambda>¡   s    z2VerifyingHTTPSHandler.https_open.<locals>.<lambda>)Údo_open)r?   Úreqr   )r?   r   Ú
https_openŸ   s    z VerifyingHTTPSHandler.https_openN)r   r   r   Ú__doc__r>   rF   r   r   r   r   r   ˜   s   c               @   s.   e  Z d  Z d Z d d „  Z d d „  Z d S)r@   z@Simple verifying connection: no auth, subclasses, timeouts, etc.c             K   s    t  j |  | | � | |  _ d  S)N)ÚHTTPSConnectionr>   r<   )r?   rA   r<   rB   r   r   r   r>   ¨   s    zVerifyingHTTPSConn.__init__c             C   sí   t  j |  j |  j f t |  d d  ƒ ƒ } t |  d ƒ rj t |  d d  ƒ rj | |  _ |  j ƒ  |  j } n	 |  j } t	 j
 | d t	 j d |  j ƒ|  _ y t |  j j ƒ  | ƒ Wn5 t k
 rè |  j j t  j ƒ |  j j ƒ  ‚  Yn Xd  S)NÚsource_addressÚ_tunnelÚ_tunnel_hostÚ	cert_reqsÚca_certs)ÚsocketÚcreate_connectionrA   ÚportÚgetattrÚhasattrÚsockrJ   rK   ÚsslÚwrap_socketÚCERT_REQUIREDr<   r   Úgetpeercertr   ÚshutdownÚ	SHUT_RDWRÚclose)r?   rS   Úactual_hostr   r   r   Úconnect¬   s    $!	
	zVerifyingHTTPSConn.connectN)r   r   r   rG   r>   r\   r   r   r   r   r@   ¥   s   r@   c             C   s"   t  j j t |  p t ƒ  ƒ ƒ j S)z@Get a urlopen() replacement that uses ca_bundle for verification)r   ÚrequestÚbuild_openerr   r	   Úopen)r<   r   r   r   r   È   s    	c                s%   t  j ˆ  ƒ ‡  f d d †  ƒ } | S)Nc                 s(   t  ˆ  d ƒ s! ˆ  |  | Ž  ˆ  _ ˆ  j S)NÚalways_returns)rR   r`   )ÚargsÚkwargs)Úfuncr   r   ÚwrapperÑ   s    zonce.<locals>.wrapper)Ú	functoolsÚwraps)rc   rd   r   )rc   r   ÚonceÐ   s    !rg   c                 sr   y d d  l  }  Wn t k
 r( d  SYn XG‡  f d d †  d |  j ƒ ‰  ˆ  ƒ  } | j d ƒ | j d ƒ | j S)Nr   c                   s:   e  Z d  Z ‡ ‡  f d d †  Z ‡ ‡  f d d †  Z ‡  S)z"get_win_certfile.<locals>.CertFilec                s'   t  ˆ  |  ƒ j ƒ  t j |  j ƒ d  S)N)Úsuperr>   ÚatexitÚregisterrZ   )r?   )ÚCertFileÚ	__class__r   r   r>   á   s    z+get_win_certfile.<locals>.CertFile.__init__c                s0   y t  ˆ  |  ƒ j ƒ  Wn t k
 r+ Yn Xd  S)N)rh   rZ   ÚOSError)r?   )rk   rl   r   r   rZ   å   s    z(get_win_certfile.<locals>.CertFile.close)r   r   r   r>   rZ   r   )rk   )rl   r   rk   à   s   rk   ÚCAÚROOT)ÚwincertstoreÚImportErrorrk   ZaddstoreÚname)rp   Z	_wincertsr   )rk   r   Úget_win_certfileÙ   s    		rs   c              C   s4   t  t j j t ƒ }  t ƒ  p3 t |  d ƒ p3 t ƒ  S)z*Return an existing CA bundle path, or NoneN)r   ÚosÚpathÚisfiler   rs   ÚnextÚ_certifi_where)Zextant_cert_pathsr   r   r   r	   ñ   s    	c               C   s6   y t  d ƒ j ƒ  SWn t t t f k
 r1 Yn Xd  S)NZcertifi)Ú
__import__Úwhererq   r   r   r   r   r   r   rx   û   s    rx   )%rt   rN   ri   r   re   Zsetuptools.extern.six.movesr   r   r   r   Úpkg_resourcesr   r   rT   rq   Ú__all__Ústripr   r   r]   r=   rH   ÚAttributeErrorÚobjectr
   r   r   Zbackports.ssl_match_hostnamer3   r.   r   r@   r   rg   rs   r	   rx   r   r   r   r   Ú<module>   sP   "	4)#	
