B
    à%Q[®  ã               @   sn   d Z ddlZddlmZmZ yddlZW n ek
rD   edƒ‚Y nX ddlmZm	Z	 dZ
dZd	Zd
d„ ZdS )Ú
é    Né   )ÚLDAPPackageUnavailableErrorÚLDAPCommunicationErrorzpackage gssapi missingé   )Úsend_sasl_negotiationÚabort_sasl_negotiationé   é   c          	   C   s:  d}d}| j r¤t| j ƒdkr|| j d r|| j d dkrbt | j ¡ d ¡d }t d| tjj¡}nt d| j d  tjj¡}t| j ƒdkr¤| j d r¤| j d  	d¡}|dkrÄt d| j
j tjj¡}| jràtjt | j¡d	d
�nd}tj|tjj|d�}d}�yx\| |¡}|dk�rd}t| ||ƒ}	|	d }y|j�r:P W n tjjk
�rV   Y nX �qW | |¡}
t|
jƒdk�r€tdƒ‚|
jd }t|tƒ�sžt|ƒ}|dtfk�rÈ|
jdd… dk�rÈtdƒ‚|t@ �sÚtdƒ‚ttdddgƒ}| t|ƒ| d¡}t| ||jƒS  tjj tfk
�r4   t!| |ƒ ‚ Y nX dS )a  
    Performs a bind using the Kerberos v5 ("GSSAPI") SASL mechanism
    from RFC 4752. Does not support any security layers, only authentication!

    sasl_credentials can be empty or a tuple with one or two elements.
    The first element determines which service principal to request a ticket for and can be one of the following:
    
    - None or False, to use the hostname from the Server object
    - True to perform a reverse DNS lookup to retrieve the canonical hostname for the hosts IP address
    - A string containing the hostname
    
    The optional second element is what authorization ID to request.
    
    - If omitted or None, the authentication ID is used as the authorization ID
    - If a string, the authorization ID to use. Should start with "dn:" or "user:".
    Nó    r   r   Tzldap@r	   zutf-8Zinitiate)ÚnameÚusage)r   ZmechÚcredsÚ Z	saslCredsr
   zIncorrect response from serverz   z5Server max buffer size must be 0 if no security layerz=Server requires a security layer, but this is not implementedF)"Zsasl_credentialsÚlenÚsocketÚgethostbyaddrÚgetpeernameÚgssapiÚNameZNameTypeZhostbased_serviceÚencodeÚserverÚhostÚuserZCredentialsZSecurityContextZMechTypeZkerberosÚstepr   ZcompleteÚ
exceptionsZMissingContextErrorÚunwrapÚmessager   Ú
isinstanceÚintÚordÚNO_SECURITY_LAYERÚ	bytearrayÚwrapÚbytesZGSSErrorr   )Ú
connectionÚcontrolsZtarget_nameZauthz_idÚhostnamer   ÚctxZin_tokenZ	out_tokenÚresultZunwrapped_tokenZserver_security_layersZclient_security_layers© r*   ú_C:\Users\HIRONO~1\AppData\Local\Temp\pip-install-6i93dh7p\ldap3\ldap3\protocol\sasl\kerberos.pyÚsasl_gssapi-   sX     





r,   )Ú__doc__r   Zcore.exceptionsr   r   r   ÚImportErrorZsaslr   r   r!   ZINTEGRITY_PROTECTIONZCONFIDENTIALITY_PROTECTIONr,   r*   r*   r*   r+   Ú<module>   s   