Ë
    zñ�j)p  ã                   óÞ  — d Z ddlZddlZddlZdZdZdZ	 ddlZ eed«      rej                  dk(  rdZej                  fZn8dZej                  j                  ej                  j                  j                  fZddlmZ ddlmZ dd„Z G d„ d«      Z G d„ de«      Z G d„ de«      Z G d„ de«      Zy# eef$ r/ 	 ddlZddlZddlZd	Zej*                  fZn# e$ r d
ZdZY nw xY wY Œqw xY w)zÌ
This module provides GSS-API / SSPI  authentication as defined in :rfc:`4462`.

.. note:: Credential delegation is not supported in server mode.

.. seealso:: :doc:`/api/kex_gss`

.. versionadded:: 1.15
é    NT© Ú	__title__zpython-gssapiÚMITúPYTHON-GSSAPI-NEWÚSSPIF)ÚMSG_USERAUTH_REQUEST)ÚSSHExceptionc                 ó¼   — t         dk(  rt        | |«      S t         dk(  rt        | |«      S t         dk(  rt        j                  dk(  rt        | |«      S t        d«      ‚)aÀ  
    Provide SSH2 GSS-API / SSPI authentication.

    :param str auth_method: The name of the SSH authentication mechanism
                            (gssapi-with-mic or gss-keyex)
    :param bool gss_deleg_creds: Delegate client credentials or not.
                                 We delegate credentials by default.
    :return: Either an `._SSH_GSSAPI_OLD` or `._SSH_GSSAPI_NEW` (Unix)
             object or an `_SSH_SSPI` (Windows) object
    :rtype: object

    :raises: ``ImportError`` -- If no GSS-API / SSPI module could be imported.

    :see: `RFC 4462 <http://www.ietf.org/rfc/rfc4462.txt>`_
    :note: Check for the available API and return either an `._SSH_GSSAPI_OLD`
           (MIT GSSAPI using python-gssapi package) object, an
           `._SSH_GSSAPI_NEW` (MIT GSSAPI using gssapi package) object
           or an `._SSH_SSPI` (MS SSPI) object.
           If there is no supported API available,
           ``None`` will be returned.
    r   r   r   Úntz)Unable to import a GSS-API / SSPI module!)Ú_APIÚ_SSH_GSSAPI_OLDÚ_SSH_GSSAPI_NEWÚosÚnameÚ	_SSH_SSPIÚImportError)Úauth_methodÚgss_deleg_credss     úQ/var/www/api.ozpay.ru/ozpay/venv/lib/python3.12/site-packages/paramiko/ssh_gss.pyÚGSSAuthr   M   sX   € ô, ˆu‚}Ü˜{¨OÓ<Ð<Ü	Ð$Ò	$Ü˜{¨OÓ<Ð<Ü	�ŠœBŸG™G tšOÜ˜ oÓ6Ð6äÐEÓFÐFó    c                   ó<   — e Zd ZdZd„ Zd„ Zd„ Zd
d„Zd„ Zd„ Z	d„ Z
y	)Ú_SSH_GSSAuthzs
    Contains the shared variables and methods of `._SSH_GSSAPI_OLD`,
    `._SSH_GSSAPI_NEW` and `._SSH_SSPI`.
    c                 ó®   — || _         || _        d| _        d| _        d| _        d| _        	 d| _        d| _        d| _        d| _	        d| _
        d| _        y)úÝ
        :param str auth_method: The name of the SSH authentication mechanism
                                (gssapi-with-mic or gss-keyex)
        :param bool gss_deleg_creds: Delegate client credentials or not
        Nzssh-connectionz1.2.840.113554.1.2.2F)Ú_auth_methodÚ_gss_deleg_credsÚ	_gss_hostÚ	_usernameÚ_session_idÚ_serviceÚ
_krb5_mechÚ	_gss_ctxtÚ_gss_ctxt_statusÚ_gss_srv_ctxtÚ_gss_srv_ctxt_statusÚcc_file©Úselfr   r   s      r   Ú__init__z_SSH_GSSAuth.__init__s   si   € ð (ˆÔØ /ˆÔØˆŒØˆŒØˆÔØ(ˆŒð	ð 1ˆŒð ˆŒØ %ˆÔð "ˆÔØ$)ˆÔ!Øˆ�r   c                 ó6   — |j                  d«      r|| _        yy)zì
        This is just a setter to use a non default service.
        I added this method, because RFC 4462 doesn't specify "ssh-connection"
        as the only service value.

        :param str service: The desired SSH service
        zssh-N)Úfindr!   )r)   Úservices     r   Úset_servicez_SSH_GSSAuth.set_serviceŽ   s   € ð �<‰<˜ÔØ#ˆD�Mð  r   c                 ó   — || _         y)zÔ
        Setter for C{username}. If GSS-API Key Exchange is performed, the
        username is not set by C{ssh_init_sec_context}.

        :param str username: The name of the user who attempts to login
        N)r   )r)   Úusernames     r   Úset_usernamez_SSH_GSSAuth.set_username™   s   € ð "ˆ�r   c                 óÖ   — ddl m} ddlm} | j	                  d«      }|j                   || j                  «      «      }| j	                  t        |«      «      }|dk(  r||z   S ||z   |z   S )aÄ  
        This method returns a single OID, because we only support the
        Kerberos V5 mechanism.

        :param str mode: Client for client mode and server for server mode
        :return: A byte sequence containing the number of supported
                 OIDs, the length of the OID and the actual OID encoded with
                 DER
        :note: In server mode we just return the OID length and the DER encoded
               OID.
        r   )ÚObjectIdentifier)Úencoderé   Úserver)Úpyasn1.type.univr3   Úpyasn1.codec.derr4   Ú_make_uint32Úencoder"   Úlen)r)   Úmoder3   r4   ÚOIDsÚkrb5_OIDÚOID_lens          r   Ússh_gss_oidsz_SSH_GSSAuth.ssh_gss_oids¢   sh   € õ 	6Ý,à× Ñ  Ó#ˆØ—>‘>Ñ"2°4·?±?Ó"CÓDˆØ×#Ñ#¤C¨£MÓ2ˆØ�8ÒØ˜XÑ%Ð%Ø�g‰~ Ñ(Ð(r   c                 ót   — ddl m} |j                  |«      \  }}|j                  «       | j                  k7  ryy)zè
        Check if the given OID is the Kerberos V5 OID (server mode).

        :param str desired_mech: The desired GSS-API mechanism of the client
        :return: ``True`` if the given OID is supported, otherwise C{False}
        r   ©ÚdecoderFT)r8   rC   ÚdecodeÚ__str__r"   )r)   Údesired_mechrC   ÚmechÚ__s        r   Ússh_check_mechz_SSH_GSSAuth.ssh_check_mech¸   s1   € õ 	-à—>‘> ,Ó/‰ˆˆbØ�<‰<‹>˜TŸ_™_Ò,ØØr   c                 ó.   — t        j                  d|«      S )zÇ
        Create a 32 bit unsigned integer (The byte sequence of an integer).

        :param int integer: The integer value to convert
        :return: The byte sequence of an 32 bit integer
        z!I)ÚstructÚpack)r)   Úintegers     r   r9   z_SSH_GSSAuth._make_uint32È   s   € ô �{‰{˜4 Ó)Ð)r   c                 óž  — | j                  t        |«      «      }||z  }|t        j                  dt        «      z  }|| j                  t        |«      «      z  }||j                  «       z  }|| j                  t        |«      «      z  }||j                  «       z  }|| j                  t        |«      «      z  }||j                  «       z  }|S )aÎ  
        Create the SSH2 MIC filed for gssapi-with-mic.

        :param str session_id: The SSH session ID
        :param str username: The name of the user who attempts to login
        :param str service: The requested SSH service
        :param str auth_method: The requested SSH authentication mechanism
        :return: The MIC as defined in RFC 4462. The contents of the
                 MIC field are:
                 string    session_identifier,
                 byte      SSH_MSG_USERAUTH_REQUEST,
                 string    user-name,
                 string    service (ssh-connection),
                 string    authentication-method
                           (gssapi-with-mic or gssapi-keyex)
        ÚB)r9   r;   rK   rL   r   r:   )r)   Ú
session_idr0   r-   r   Úmics         r   Ú_ssh_build_micz_SSH_GSSAuth._ssh_build_micÑ   s¾   € ð" ×Ñ¤ J£Ó0ˆØˆzÑˆØŒv�{‰{˜3Ô 4Ó5Ñ5ˆØˆt× Ñ ¤ X£Ó/Ñ/ˆØˆx�‰Ó Ñ ˆØˆt× Ñ ¤ W£Ó.Ñ.ˆØˆw�~‰~ÓÑˆØˆt× Ñ ¤ [Ó!1Ó2Ñ2ˆØˆ{×!Ñ!Ó#Ñ#ˆØˆ
r   N)Úclient)Ú__name__Ú
__module__Ú__qualname__Ú__doc__r*   r.   r1   r@   rI   r9   rR   r   r   r   r   r   m   s*   „ ñò
ò6	$ò"ó)ò,ò *ór   r   c                   óN   — e Zd ZdZd„ Z	 d
d„Zdd„Zdd„Zdd„Ze	d„ «       Z
d	„ Zy)r   z�
    Implementation of the GSS-API MIT Kerberos Authentication for SSH2,
    using the older (unmaintained) python-gssapi package.

    :see: `.GSSAuth`
    c                 ó:  — t         j                  | ||«       | j                  rDt        j                  t        j
                  t        j                  t        j                  f| _        yt        j                  t        j
                  t        j                  f| _        y©r   N)	r   r*   r   ÚgssapiÚC_PROT_READY_FLAGÚC_INTEG_FLAGÚC_MUTUAL_FLAGÚC_DELEG_FLAGÚ
_gss_flagsr(   s      r   r*   z_SSH_GSSAPI_OLD.__init__ö   sr   € ô 	×Ñ˜d K°ÔAà× Ò ä×(Ñ(Ü×#Ñ#Ü×$Ñ$Ü×#Ñ#ð	ˆD�Oô ×(Ñ(Ü×#Ñ#Ü×$Ñ$ðˆD�Or   Nc                 ó²  — ddl m} || _        || _        t	        j
                  d| j                  z   t        j                  «      }t	        j                  «       }| j                  |_	        |€*t        j                  j                  | j                  «      }ne|j                  |«      \  }	}
|	j                  «       | j                  k7  rt        d«      ‚t        j                  j                  | j                  «      }d}	 |€Ct	        j                   |||j                  ¬«      | _        | j"                  j%                  |«      }n| j"                  j%                  |«      }| j"                  j.                  | _        |S # t        j&                  $ rG dj)                  t+        j,                  «       d   | j                  «      }t	        j&                  |«      ‚w xY w)	aË  
        Initialize a GSS-API context.

        :param str username: The name of the user who attempts to login
        :param str target: The hostname of the target to connect to
        :param str desired_mech: The negotiated GSS-API mechanism
                                 ("pseudo negotiated" mechanism, because we
                                 support just the krb5 mechanism :-))
        :param str recv_token: The GSS-API token received from the Server
        :raises:
            `.SSHException` -- Is raised if the desired mechanism of the client
            is not supported
        :return: A ``String`` if the GSS-API has returned a token or
            ``None`` if no token was returned
        r   rB   úhost@NúUnsupported mechanism OID.)Ú	peer_nameÚ	mech_typeÚ	req_flagsz{} Target: {}r5   )r8   rC   r   r   r[   ÚNameÚC_NT_HOSTBASED_SERVICEÚContextr`   ÚflagsÚOIDÚmech_from_stringr"   rD   rE   r	   ÚInitContextr#   ÚstepÚGSSExceptionÚformatÚsysÚexc_infoÚestablishedr$   )r)   ÚtargetrF   r0   Ú
recv_tokenrC   Ú	targ_nameÚctxÚ	krb5_mechrG   rH   ÚtokenÚmessages                r   Ússh_init_sec_contextz$_SSH_GSSAPI_OLD.ssh_init_sec_context  sq  € õ$ 	-à!ˆŒØˆŒÜ—K‘KØ�d—n‘nÑ$¤f×&CÑ&Có
ˆ	ô �n‰nÓˆØ—O‘OˆŒ	ØÐÜŸ
™
×3Ñ3°D·O±OÓD‰Ià—~‘~ lÓ3‰HˆD�"Ø�|‰|‹~ §¡Ò0Ü"Ð#?Ó@Ð@ä"ŸJ™J×7Ñ7¸¿¹ÓH�	Øˆð	/ØÐ!Ü!'×!3Ñ!3Ø'Ø'Ø!Ÿi™iô"�”ð
 Ÿ™×+Ñ+¨EÓ2‘àŸ™×+Ñ+¨JÓ7�ð !%§¡× :Ñ :ˆÔØˆøô	 ×"Ñ"ò 	/Ø%×,Ñ,¬S¯\©\«^¸AÑ->ÀÇÁÓOˆGÜ×%Ñ% gÓ.Ð.ð	/ús   Ã?A E< Å<AGc                 ó  — || _         |sY| j                  | j                   | j                  | j                  | j                  «      }| j
                  j                  |«      }|S | j                  j                  | j                   «      }|S )aÞ  
        Create the MIC token for a SSH2 message.

        :param str session_id: The SSH session ID
        :param bool gss_kex: Generate the MIC for GSS-API Key Exchange or not
        :return: gssapi-with-mic:
                 Returns the MIC token from GSS-API for the message we created
                 with ``_ssh_build_mic``.
                 gssapi-keyex:
                 Returns the MIC token from GSS-API with the SSH session ID as
                 message.
        )r    rR   r   r!   r   r#   Úget_micr%   ©r)   rP   Úgss_kexÚ	mic_fieldÚ	mic_tokens        r   Ússh_get_micz_SSH_GSSAPI_OLD.ssh_get_mic@  s�   € ð &ˆÔÙØ×+Ñ+Ø× Ñ Ø—‘Ø—‘Ø×!Ñ!ó	ˆIð Ÿ™×.Ñ.¨yÓ9ˆIð Ðð ×*Ñ*×2Ñ2°4×3CÑ3CÓDˆIØÐr   c                 óØ   — || _         || _        | j                  €t        j                  «       | _        | j                  j                  |«      }| j                  j                  | _        |S )á³  
        Accept a GSS-API context (server mode).

        :param str hostname: The servers hostname
        :param str username: The name of the user who attempts to login
        :param str recv_token: The GSS-API Token received from the server,
                               if it's not the initial call.
        :return: A ``String`` if the GSS-API has returned a token or ``None``
                if no token was returned
        )r   r   r%   r[   ÚAcceptContextrn   rs   r&   ©r)   Úhostnameru   r0   ry   s        r   Ússh_accept_sec_contextz&_SSH_GSSAPI_OLD.ssh_accept_sec_context[  s^   € ð "ˆŒØ!ˆŒØ×ÑÐ%Ü!'×!5Ñ!5Ó!7ˆDÔØ×"Ñ"×'Ñ'¨
Ó3ˆØ$(×$6Ñ$6×$BÑ$BˆÔ!Øˆr   c                 ó6  — || _         || _        | j                  �Y| j                  | j                   | j                  | j                  | j                  «      }| j
                  j                  ||«       y| j                  j                  | j                   |«       y)at  
        Verify the MIC token for a SSH2 message.

        :param str mic_token: The MIC token received from the client
        :param str session_id: The SSH session ID
        :param str username: The name of the user who attempts to login
        :return: None if the MIC check was successful
        :raises: ``gssapi.GSSException`` -- if the MIC check failed
        N)r    r   rR   r!   r   r%   Ú
verify_micr#   ©r)   r�   rP   r0   r€   s        r   Ússh_check_micz_SSH_GSSAPI_OLD.ssh_check_mico  s�   € ð &ˆÔØ!ˆŒØ�>‰>Ð%à×+Ñ+Ø× Ñ Ø—‘Ø—‘Ø×!Ñ!ó	ˆIð ×Ñ×)Ñ)¨)°YÕ?ð �N‰N×%Ñ% d×&6Ñ&6¸	ÕBr   c                 ó2   — | j                   j                  �yy)ú‘
        Checks if credentials are delegated (server mode).

        :return: ``True`` if credentials are delegated, otherwise ``False``
        TF)r%   Údelegated_cred©r)   s    r   Úcredentials_delegatedz%_SSH_GSSAPI_OLD.credentials_delegated‰  s   € ð ×Ñ×,Ñ,Ð8ØØr   c                 ó   — t         ‚)a~  
        Save the Client token in a file. This is used by the SSH server
        to store the client credentials if credentials are delegated
        (server mode).

        :param str client_token: The GSS-API token received form the client
        :raises:
            ``NotImplementedError`` -- Credential delegation is currently not
            supported in server mode
        ©ÚNotImplementedError©r)   Úclient_tokens     r   Úsave_client_credsz!_SSH_GSSAPI_OLD.save_client_creds”  ó
   € ô "Ð!r   ©NNN©F©N©rT   rU   rV   rW   r*   r{   r‚   rˆ   rŒ   Úpropertyr‘   r—   r   r   r   r   r   î   sB   „ ñòð. DHó2óhó6ó(Cð4 ñó ðó"r   r   c                   óN   — e Zd ZdZd„ Z	 d
d„Zdd„Zdd„Zdd„Ze	d„ «       Z
d	„ Zy)r   z�
    Implementation of the GSS-API MIT Kerberos Authentication for SSH2,
    using the newer, currently maintained gssapi package.

    :see: `.GSSAuth`
    c                 óÆ  — t         j                  | ||«       | j                  rlt        j                  j
                  t        j                  j                  t        j                  j                  t        j                  j                  f| _	        yt        j                  j
                  t        j                  j                  t        j                  j                  f| _	        yrZ   )
r   r*   r   r[   ÚRequirementFlagÚprotection_readyÚ	integrityÚmutual_authenticationÚdelegate_to_peerr`   r(   s      r   r*   z_SSH_GSSAPI_NEW.__init__ª  sœ   € ô 	×Ñ˜d K°ÔAà× Ò ä×&Ñ&×7Ñ7Ü×&Ñ&×0Ñ0Ü×&Ñ&×<Ñ<Ü×&Ñ&×7Ñ7ð	ˆD�Oô ×&Ñ&×7Ñ7Ü×&Ñ&×0Ñ0Ü×&Ñ&×<Ñ<ðˆD�Or   Nc                 óR  — ddl m} || _        || _        t	        j
                  d| j                  z   t        j                  j                  ¬«      }|�<|j                  |«      \  }}|j                  «       | j                  k7  rt        d«      ‚t        j                  j                  }	d}
|€Dt	        j                  || j                  |	d¬«      | _        | j                   j#                  |
«      }
n| j                   j#                  |«      }
| j                   j$                  | _        |
S )	ae  
        Initialize a GSS-API context.

        :param str username: The name of the user who attempts to login
        :param str target: The hostname of the target to connect to
        :param str desired_mech: The negotiated GSS-API mechanism
                                 ("pseudo negotiated" mechanism, because we
                                 support just the krb5 mechanism :-))
        :param str recv_token: The GSS-API token received from the Server
        :raises: `.SSHException` -- Is raised if the desired mechanism of the
                 client is not supported
        :raises: ``gssapi.exceptions.GSSError`` if there is an error signaled
                                                by the GSS-API implementation
        :return: A ``String`` if the GSS-API has returned a token or ``None``
                 if no token was returned
        r   rB   rb   )Ú	name_typeNrc   Úinitiate)r   rj   rG   Úusage)r8   rC   r   r   r[   rg   ÚNameTypeÚhostbased_servicerD   rE   r"   r	   ÚMechTypeÚkerberosÚSecurityContextr`   r#   rn   Úcompleter$   )r)   rt   rF   r0   ru   rC   rv   rG   rH   rx   ry   s              r   r{   z$_SSH_GSSAPI_NEW.ssh_init_sec_contextÀ  sñ   € õ& 	-à!ˆŒØˆŒÜ—K‘KØ�d—n‘nÑ$Ü—o‘o×7Ñ7ô
ˆ	ð Ð#Ø—~‘~ lÓ3‰HˆD�"Ø�|‰|‹~ §¡Ò0Ü"Ð#?Ó@Ð@Ü—O‘O×,Ñ,ˆ	ØˆØÐÜ#×3Ñ3ØØ—o‘oØØ ô	ˆDŒNð —N‘N×'Ñ'¨Ó.‰Eà—N‘N×'Ñ'¨
Ó3ˆEØ $§¡× 7Ñ 7ˆÔØˆr   c                 ó  — || _         |sY| j                  | j                   | j                  | j                  | j                  «      }| j
                  j                  |«      }|S | j                  j                  | j                   «      }|S )aò  
        Create the MIC token for a SSH2 message.

        :param str session_id: The SSH session ID
        :param bool gss_kex: Generate the MIC for GSS-API Key Exchange or not
        :return: gssapi-with-mic:
                 Returns the MIC token from GSS-API for the message we created
                 with ``_ssh_build_mic``.
                 gssapi-keyex:
                 Returns the MIC token from GSS-API with the SSH session ID as
                 message.
        :rtype: str
        )r    rR   r   r!   r   r#   Úget_signaturer%   r~   s        r   r‚   z_SSH_GSSAPI_NEW.ssh_get_micî  s�   € ð &ˆÔÙØ×+Ñ+Ø× Ñ Ø—‘Ø—‘Ø×!Ñ!ó	ˆIð Ÿ™×4Ñ4°YÓ?ˆIð Ðð ×*Ñ*×8Ñ8¸×9IÑ9IÓJˆIØÐr   c                 óÜ   — || _         || _        | j                  €t        j                  d¬«      | _        | j                  j                  |«      }| j                  j                  | _        |S )r„   Úaccept)r¨   )r   r   r%   r[   r­   rn   r®   r&   r†   s        r   rˆ   z&_SSH_GSSAPI_NEW.ssh_accept_sec_context
  s`   € ð "ˆŒØ!ˆŒØ×ÑÐ%Ü!'×!7Ñ!7¸hÔ!GˆDÔØ×"Ñ"×'Ñ'¨
Ó3ˆØ$(×$6Ñ$6×$?Ñ$?ˆÔ!Øˆr   c                 ó6  — || _         || _        | j                  �Y| j                  | j                   | j                  | j                  | j                  «      }| j
                  j                  ||«       y| j                  j                  | j                   |«       y)a{  
        Verify the MIC token for a SSH2 message.

        :param str mic_token: The MIC token received from the client
        :param str session_id: The SSH session ID
        :param str username: The name of the user who attempts to login
        :return: None if the MIC check was successful
        :raises: ``gssapi.exceptions.GSSError`` -- if the MIC check failed
        N)r    r   rR   r!   r   r%   Úverify_signaturer#   r‹   s        r   rŒ   z_SSH_GSSAPI_NEW.ssh_check_mic  s�   € ð &ˆÔØ!ˆŒØ�>‰>Ð%à×+Ñ+Ø× Ñ Ø—‘Ø—‘Ø×!Ñ!ó	ˆIð ×Ñ×/Ñ/°	¸9ÕEð �N‰N×+Ñ+¨D×,<Ñ,<¸iÕHr   c                 ó2   — | j                   j                  �yy)z¦
        Checks if credentials are delegated (server mode).

        :return: ``True`` if credentials are delegated, otherwise ``False``
        :rtype: bool
        TF)r%   Údelegated_credsr�   s    r   r‘   z%_SSH_GSSAPI_NEW.credentials_delegated8  s   € ð ×Ñ×-Ñ-Ð9ØØr   c                 ó   — t         ‚)aw  
        Save the Client token in a file. This is used by the SSH server
        to store the client credentials if credentials are delegated
        (server mode).

        :param str client_token: The GSS-API token received form the client
        :raises: ``NotImplementedError`` -- Credential delegation is currently
                 not supported in server mode
        r“   r•   s     r   r—   z!_SSH_GSSAPI_NEW.save_client_credsD  s
   € ô "Ð!r   r™   rš   r›   rœ   r   r   r   r   r   ¢  sB   „ ñòð. DHó,ó\ó8ó(Ið4 ñ	ó ð	ó
"r   r   c                   óL   — e Zd ZdZd„ Z	 d
d„Zdd„Zd„ Zdd„Ze	d„ «       Z
d	„ Zy)r   zf
    Implementation of the Microsoft SSPI Kerberos Authentication for SSH2.

    :see: `.GSSAuth`
    c                 ó  — t         j                  | ||«       | j                  r8t        j                  t        j
                  z  t        j                  z  | _        yt        j                  t        j
                  z  | _        yrZ   )r   r*   r   ÚsspiconÚISC_REQ_INTEGRITYÚISC_REQ_MUTUAL_AUTHÚISC_REQ_DELEGATEr`   r(   s      r   r*   z_SSH_SSPI.__init__X  sh   € ô 	×Ñ˜d K°ÔAà× Ò ä×)Ñ)Ü×-Ñ-ñ.ä×*Ñ*ñ+ð �Oô ×)Ñ)¬G×,GÑ,GÑGð �Or   Nc                 ó.  — ddl m} || _        || _        d}d| j                  z   }|�<|j	                  |«      \  }}	|j                  «       | j                  k7  rt        d«      ‚	 |€'t        j                  d| j                  |¬«      | _        | j                  j                  |«      \  }}
|
d   j                  }
|dk(  r	 d	| _        d}
	 |
S # t        j                  $ r4}|xj                   dj#                  | j                  «      z  c_        ‚ d}~ww xY w)
a¼  
        Initialize a SSPI context.

        :param str username: The name of the user who attempts to login
        :param str target: The FQDN of the target to connect to
        :param str desired_mech: The negotiated SSPI mechanism
                                 ("pseudo negotiated" mechanism, because we
                                 support just the krb5 mechanism :-))
        :param recv_token: The SSPI token received from the Server
        :raises:
            `.SSHException` -- Is raised if the desired mechanism of the client
            is not supported
        :return: A ``String`` if the SSPI has returned a token or ``None`` if
                 no token was returned
        r   rB   úhost/Nrc   ÚKerberos)ÚscflagsÚ	targetspnz, Target: {}T)r8   rC   r   r   rD   rE   r"   r	   ÚsspiÚ
ClientAuthr`   r#   Ú	authorizeÚBufferÚ
pywintypesÚerrorÚstrerrorrp   r$   )r)   rt   rF   r0   ru   rC   rÈ   rv   rG   rH   ry   Úes               r   r{   z_SSH_SSPI.ssh_init_sec_contextk  s  € õ$ 	-à!ˆŒØˆŒØˆØ˜dŸn™nÑ,ˆ	ØÐ#Ø—~‘~ lÓ3‰HˆD�"Ø�|‰|‹~ §¡Ò0Ü"Ð#?Ó@Ð@ð		ØÐ!Ü!%§¡Ø¨¯©À9ô"�”ð  Ÿ>™>×3Ñ3°JÓ?‰LˆE�5Ø˜!‘H—O‘OˆEð
 �AŠ:ðð %)ˆDÔ!ØˆEðð ˆøô ×Ñò 	Ø�JŠJ˜.×/Ñ/°·±Ó?Ñ?�JØûð	ús   Á%AC ÃDÃ /DÄDc                 ó  — || _         |sY| j                  | j                   | j                  | j                  | j                  «      }| j
                  j                  |«      }|S | j                  j                  | j                   «      }|S )aÚ  
        Create the MIC token for a SSH2 message.

        :param str session_id: The SSH session ID
        :param bool gss_kex: Generate the MIC for Key Exchange with SSPI or not
        :return: gssapi-with-mic:
                 Returns the MIC token from SSPI for the message we created
                 with ``_ssh_build_mic``.
                 gssapi-keyex:
                 Returns the MIC token from SSPI with the SSH session ID as
                 message.
        )r    rR   r   r!   r   r#   Úsignr%   r~   s        r   r‚   z_SSH_SSPI.ssh_get_micŸ  s�   € ð &ˆÔÙØ×+Ñ+Ø× Ñ Ø—‘Ø—‘Ø×!Ñ!ó	ˆIð Ÿ™×+Ñ+¨IÓ6ˆIð Ðð ×*Ñ*×/Ñ/°×0@Ñ0@ÓAˆIØÐr   c                 óî   — || _         || _        d| j                   z   }t        j                  d|¬«      | _        | j                  j                  |«      \  }}|d   j                  }|dk(  r	d| _        d}|S )a§  
        Accept a SSPI context (server mode).

        :param str hostname: The servers FQDN
        :param str username: The name of the user who attempts to login
        :param str recv_token: The SSPI Token received from the server,
                               if it's not the initial call.
        :return: A ``String`` if the SSPI has returned a token or ``None`` if
                 no token was returned
        r¿   rÀ   )Úspnr   TN)r   r   rÃ   Ú
ServerAuthr%   rÅ   rÆ   r&   )r)   r‡   r0   ru   rv   rÈ   ry   s          r   rˆ   z _SSH_SSPI.ssh_accept_sec_contextº  ss   € ð "ˆŒØ!ˆŒØ˜dŸn™nÑ,ˆ	Ü!Ÿ_™_¨Z¸YÔGˆÔØ×)Ñ)×3Ñ3°JÓ?‰ˆˆuØ�a‘—‘ˆØ�AŠ:Ø(,ˆDÔ%ØˆEØˆr   c                 ó"  — || _         || _        |�Y| j                  | j                   | j                  | j                  | j                  «      }| j
                  j                  ||«       y| j                  j                  | j                   |«       y)ak  
        Verify the MIC token for a SSH2 message.

        :param str mic_token: The MIC token received from the client
        :param str session_id: The SSH session ID
        :param str username: The name of the user who attempts to login
        :return: None if the MIC check was successful
        :raises: ``sspi.error`` -- if the MIC check failed
        N)r    r   rR   r!   r   r%   Úverifyr#   r‹   s        r   rŒ   z_SSH_SSPI.ssh_check_micÐ  s}   € ð &ˆÔØ!ˆŒØÐà×+Ñ+Ø× Ñ Ø—‘Ø—‘Ø×!Ñ!ó	ˆIð ×Ñ×%Ñ% i°Õ;ð �N‰N×!Ñ! $×"2Ñ"2°IÕ>r   c                 ót   — | j                   t        j                  z  xr | j                  xs | j                   S )rŽ   )r`   rº   r½   r&   r�   s    r   r‘   z_SSH_SSPI.credentials_delegatedî  s2   € ð �‰¤×!9Ñ!9Ñ9ò 
Ø×%Ñ%Ò8¨¯©ð	
r   c                 ó   — t         ‚)a{  
        Save the Client token in a file. This is used by the SSH server
        to store the client credentials if credentials are delegated
        (server mode).

        :param str client_token: The SSPI token received form the client
        :raises:
            ``NotImplementedError`` -- Credential delegation is currently not
            supported in server mode
        r“   r•   s     r   r—   z_SSH_SSPI.save_client_credsù  r˜   r   r™   rš   r›   rœ   r   r   r   r   r   Q  sA   „ ñòð( DHó2óhò6ó,?ð< ñ
ó ð
ó"r   r   )T)rW   rK   r   rq   ÚGSS_AUTH_AVAILABLEÚGSS_EXCEPTIONSr   r[   Úhasattrr   ro   Ú
exceptionsÚGeneralErrorÚrawÚmiscÚGSSErrorr   ÚOSErrorrÇ   rº   rÃ   rÈ   Úparamiko.commonr   Úparamiko.ssh_exceptionr	   r   r   r   r   r   r   r   r   ú<module>rß      s#  ðñ,ó Û 	Û 
ð Ð ð €ð €ðÛáˆv�{Ô#¨×(8Ñ(8¸OÒ(KàˆØ ×-Ñ-Ð/‰à"ˆà×Ñ×*Ñ*Ø�J‰J�O‰O×$Ñ$ð
ˆõ  1Ý /óG÷@~ñ ~ôBq"�lô q"ôhl"�lô l"ô^s"�õ s"øði 	�WÐò 
ð	ÛÛÛàˆØ$×*Ñ*Ð,‰øØò Ø"ÐØŠðüð
ús6   –A$B6 Â6C,Â>CÃC,Ã	C&Ã#C,Ã%C&Ã&C,Ã+C,