B
    à%Q[2  ã               @   sp   d Z ddlZddlmZmZmZ yddlmZmZ W n6 e	k
rj   G dd„ de
ƒZdd	d
„Zdd„ ZY nX dS )Ú
é    Né   )ÚlogÚlog_enabledÚNETWORK)Úmatch_hostnameÚCertificateErrorc               @   s   e Zd ZdS )r   N)Ú__name__Ú
__module__Ú__qualname__© r   r   ú[C:\Users\HIRONO~1\AppData\Local\Temp\pip-install-6i93dh7p\ldap3\ldap3\utils\tls_backport.pyr      s   r   é   c       
      C   s  t tƒrttd| |ƒ g }| s"dS |  d¡}|d }|dd… }| d¡}||krbtdt| ƒ ƒ‚|sv|  ¡ | ¡ kS |dkrŠ| d	¡ n>| 	d
¡sž| 	d
¡r°| t
 |¡¡ n| t
 |¡ dd¡¡ x|D ]}| t
 |¡¡ qÎW t
 dd |¡ d t
j¡}	|	 |¡S )z§Backported from Python 3.4.3 standard library

        Matching according to RFC 6125, section 6.4.3

        http://tools.ietf.org/html/rfc6125#section-6.4.3
        zmatching dn %s with hostname %sFÚ.r   r   NÚ*z,too many wildcards in certificate DNS name: z[^.]+zxn--z\*z[^.]*z\Az\.z\Z)r   r   r   ÚsplitÚcountr   ÚreprÚlowerÚappendÚ
startswithÚreÚescapeÚreplaceÚcompileÚjoinÚ
IGNORECASEÚmatch)
ÚdnÚhostnameZmax_wildcardsZpatsÚpiecesZleftmostÚ	remainderÚ	wildcardsÚfragÚpatr   r   r   Ú_dnsname_match#   s.    


r%   c             C   sò   | st dƒ‚g }|  dd¡}x0|D ](\}}|dkr"t||ƒr@dS | |¡ q"W |sšxF|  dd¡D ]6}x0|D ](\}}|dkrjt||ƒrˆdS | |¡ qjW q`W t|ƒdkrÄtd	|d
 tt|ƒ¡f ƒ‚n*t|ƒdkrætd||d f ƒ‚ntdƒ‚dS )au  Backported from Python 3.4.3 standard library.

        Verify that *cert* (in decoded format as returned by
        SSLSocket.getpeercert()) matches the *hostname*.  RFC 2818 and RFC 6125
        rules are followed, but IP addresses are not accepted for *hostname*.

        CertificateError is raised on failure. On success, the function
        returns nothing.
        ztempty or no certificate, match_hostname needs a SSL socket or SSL context with either CERT_OPTIONAL or CERT_REQUIREDÚsubjectAltNamer   ÚDNSNÚsubjectÚ
commonNamer   z&hostname %r doesn't match either of %sz, zhostname %r doesn't match %rr   z=no appropriate commonName or subjectAltName fields were found)	Ú
ValueErrorÚgetr%   r   Úlenr   r   Úmapr   )Úcertr   ÚdnsnamesÚsanÚkeyÚvalueÚsubr   r   r   r   Z   s.    

r   )r   )Ú__doc__r   Z	utils.logr   r   r   Zbackports.ssl_match_hostnamer   r   ÚImportErrorr*   r%   r   r   r   r   Ú<module>   s   
7