+
    šh©j×p  ã                   ó  € R t ^ RIt^ RIt^ RItRtRtRt ^ RIt]! ]R4      '       d"   ]P                  R8X  d   Rt]P                  3tM9Rt]P                  P                  ]P                  P                  P                  3t ^ R	IHt ^ R
IHt ^ RIHt RR lt ! R R4      t ! R R]4      t]R8  d   ]t ! R R]4      t  ! R R]4      t!R#   ]]3 d2     ^ RIt^ RIt^ RItRt]P*                  3t Lt  ] d	    RtRt  L‚i ; ii ; i)zÌ
This module provides GSS-API / SSPI  authentication as defined in :rfc:`4462`.

.. note:: Credential delegation is not supported in server mode.

.. seealso:: :doc:`/api/kex_gss`

.. versionadded:: 1.15
NTÚ	__title__zpython-gssapiÚMITúPYTHON-GSSAPI-NEWÚSSPIF)ÚMSG_USERAUTH_REQUEST)ÚSSHException)Ú__version_info__c                óÆ   € \         R8X  d   \        W4      # \         R8X  d   \        W4      # \         R8X  d!   \        P                  R8X  d   \        W4      # \        R4      h)a|  
Provide SSH2 GSS-API / SSPI authentication.

:param str auth_method: The name of the SSH authentication mechanism
                        (gssapi-with-mic or gss-keyex)
:param bool gss_deleg_creds: Delegate client credentials or not.
                             We delegate credentials by default.
:return: Either an `._SSH_GSSAPI_OLD` or `._SSH_GSSAPI_NEW` (Unix)
         object or an `_SSH_SSPI` (Windows) object
:rtype: object

:raises: ``ImportError`` -- If no GSS-API / SSPI module could be imported.

:see: `RFC 4462 <http://www.ietf.org/rfc/rfc4462.txt>`_
:note: Check for the available API and return either an `._SSH_GSSAPI_OLD`
       (MIT GSSAPI using python-gssapi package) object, an
       `._SSH_GSSAPI_NEW` (MIT GSSAPI using gssapi package) object
       or an `._SSH_SSPI` (MS SSPI) object.
       If there is no supported API available,
       ``None`` will be returned.
r   r   r   Úntz)Unable to import a GSS-API / SSPI module!)Ú_APIÚ_SSH_GSSAPI_OLDÚ_SSH_GSSAPI_NEWÚosÚnameÚ	_SSH_SSPIÚImportError)Úauth_methodÚgss_deleg_credss   &&ÚK/var/www/html/bestweb/venv/lib/python3.14/site-packages/paramiko/ssh_gss.pyÚGSSAuthr   N   sR   € ô, ˆu„}Ü˜{Ó<Ð<Ü	Ð$Ô	$Ü˜{Ó<Ð<Ü	�ŒœBŸG™G tœOÜ˜Ó6Ð6äÐEÓFÐFó    c                   óR   a € ] tR t^nt o RtR tR tR tRR ltR t	R t
R tR	tV tR
# )Ú_SSH_GSSAuthzg
Contains the shared variables and methods of `._SSH_GSSAPI_OLD`,
`._SSH_GSSAPI_NEW` and `._SSH_SSPI`.
c                ó¬   € Wn         W n        RV n        RV n        RV n        RV n         RV n        RV n        RV n        RV n	        RV n
        RV n        R# )ú½
:param str auth_method: The name of the SSH authentication mechanism
                        (gssapi-with-mic or gss-keyex)
:param bool gss_deleg_creds: Delegate client credentials or not
Nzssh-connectionz1.2.840.113554.1.2.2F)Ú_auth_methodÚ_gss_deleg_credsÚ	_gss_hostÚ	_usernameÚ_session_idÚ_serviceÚ
_krb5_mechÚ	_gss_ctxtÚ_gss_ctxt_statusÚ_gss_srv_ctxtÚ_gss_srv_ctxt_statusÚcc_file©Úselfr   r   s   &&&r   Ú__init__Ú_SSH_GSSAuth.__init__t   se   € ð (ÔØ /ÔØˆŒØˆŒØˆÔØ(ˆŒð	ð 1ˆŒð ˆŒØ %ˆÔð "ˆÔØ$)ˆÔ!ØˆŽr   c                óD   € VP                  R4      '       d	   Wn        R# R# )zÄ
This is just a setter to use a non default service.
I added this method, because RFC 4462 doesn't specify "ssh-connection"
as the only service value.

:param str service: The desired SSH service
zssh-N)Úfindr    )r(   Úservices   &&r   Úset_serviceÚ_SSH_GSSAuth.set_service�   s   € ð �<‰<˜×ÒØ#ŽMñ  r   c                ó   € Wn         R# )z´
Setter for C{username}. If GSS-API Key Exchange is performed, the
username is not set by C{ssh_init_sec_context}.

:param str username: The name of the user who attempts to login
N)r   )r(   Úusernames   &&r   Úset_usernameÚ_SSH_GSSAuth.set_usernameš   s	   € ð "Žr   c                óî   € ^ RI Hp ^ RIHp V P	                  ^4      pVP                  V! V P                  4      4      pV P	                  \        V4      4      pVR8X  d	   We,           # WF,           V,           # )a|  
This method returns a single OID, because we only support the
Kerberos V5 mechanism.

:param str mode: Client for client mode and server for server mode
:return: A byte sequence containing the number of supported
         OIDs, the length of the OID and the actual OID encoded with
         DER
:note: In server mode we just return the OID length and the DER encoded
       OID.
)ÚObjectIdentifier)ÚencoderÚserver)Úpyasn1.type.univr5   Úpyasn1.codec.derr6   Ú_make_uint32Úencoder!   Úlen)r(   Úmoder5   r6   ÚOIDsÚkrb5_OIDÚOID_lens   &&     r   Ússh_gss_oidsÚ_SSH_GSSAuth.ssh_gss_oids£   sd   € õ 	6Ý,à× Ñ  Ó#ˆØ—>‘>Ñ"2°4·?±?Ó"CÓDˆØ×#Ñ#¤C¨£MÓ2ˆØ�8ÔØÕ%Ð%Ø�~ Õ(Ð(r   c                óz   € ^ RI Hp VP                  V4      w  r4VP                  4       V P                  8w  d   R# R# )zÈ
Check if the given OID is the Kerberos V5 OID (server mode).

:param str desired_mech: The desired GSS-API mechanism of the client
:return: ``True`` if the given OID is supported, otherwise C{False}
©ÚdecoderFT)r9   rE   ÚdecodeÚ__str__r!   )r(   Údesired_mechrE   ÚmechÚ__s   &&   r   Ússh_check_mechÚ_SSH_GSSAuth.ssh_check_mech¹   s/   € õ 	-à—>‘> ,Ó/‰ˆØ�<‰<‹>˜TŸ_™_Ô,ÙÙr   c                ó0   € \         P                  ! RV4      # )z§
Create a 32 bit unsigned integer (The byte sequence of an integer).

:param int integer: The integer value to convert
:return: The byte sequence of an 32 bit integer
z!I)ÚstructÚpack)r(   Úintegers   &&r   r:   Ú_SSH_GSSAuth._make_uint32É   s   € ô �{Š{˜4 Ó)Ð)r   c                óÒ  € V P                  \        V4      4      pWQ,          pV\        P                  ! R\        4      ,          pWPP                  \        V4      4      ,          pWRP                  4       ,          pWPP                  \        V4      4      ,          pWSP                  4       ,          pWPP                  \        V4      4      ,          pWTP                  4       ,          pV# )a^  
Create the SSH2 MIC filed for gssapi-with-mic.

:param str session_id: The SSH session ID
:param str username: The name of the user who attempts to login
:param str service: The requested SSH service
:param str auth_method: The requested SSH authentication mechanism
:return: The MIC as defined in RFC 4462. The contents of the
         MIC field are:
         string    session_identifier,
         byte      SSH_MSG_USERAUTH_REQUEST,
         string    user-name,
         string    service (ssh-connection),
         string    authentication-method
                   (gssapi-with-mic or gssapi-keyex)
ÚB)r:   r<   rN   rO   r   r;   )r(   Ú
session_idr1   r-   r   Úmics   &&&&& r   Ú_ssh_build_micÚ_SSH_GSSAuth._ssh_build_micÒ   s°   € ð" ×Ñ¤ J£Ó0ˆØÕˆØŒv�{Š{˜3Ô 4Ó5Õ5ˆØ× Ñ ¤ X£Ó/Õ/ˆØ�‰Ó Õ ˆØ× Ñ ¤ W£Ó.Õ.ˆØ�~‰~ÓÕˆØ× Ñ ¤ [Ó!1Ó2Õ2ˆØ×!Ñ!Ó#Õ#ˆØˆ
r   )r   r"   r#   r   r   r$   r%   r!   r    r   r   r&   N)Úclient)Ú__name__Ú
__module__Ú__qualname__Ú__firstlineno__Ú__doc__r)   r.   r2   rA   rK   r:   rV   Ú__static_attributes__Ú__classdictcell__©Ú__classdict__s   @r   r   r   n   s2   ø‡ € ñò
ò6	$ò"ô)ò,ò *÷ð r   r   c                   óh   a € ] tR t^ït o RtR tRR ltRR ltRR ltRR lt	]
R 4       tR	 tR
tV tR# )r   z�
Implementation of the GSS-API MIT Kerberos Authentication for SSH2,
using the older (unmaintained) python-gssapi package.

:see: `.GSSAuth`
c                óH  € \         P                  WV4       V P                  '       dF   \        P                  \        P
                  \        P                  \        P                  3V n        R# \        P                  \        P
                  \        P                  3V n        R# ©r   N)	r   r)   r   ÚgssapiÚC_PROT_READY_FLAGÚC_INTEG_FLAGÚC_MUTUAL_FLAGÚC_DELEG_FLAGÚ
_gss_flagsr'   s   &&&r   r)   Ú_SSH_GSSAPI_OLD.__init__÷   ss   € ô 	×Ñ˜d°ÔAà× × Ð ä×(Ñ(Ü×#Ñ#Ü×$Ñ$Ü×#Ñ#ð	ˆDŽOô ×(Ñ(Ü×#Ñ#Ü×$Ñ$ðˆDŽOr   Nc                óØ  € ^ RI Hp W0n        Wn        \        P
                  ! RV P                  ,           \        P                  4      p\        P                  ! 4       pV P                  Vn	        Vf+   \        P                  P                  V P                  4      pMfVP                  V4      w  ršV	P                  4       V P                  8w  d   \        R4      h\        P                  P                  V P                  4      pRp VfE   \        P                   ! VVVP                  R7      V n        V P"                  P%                  V4      pMV P"                  P%                  V4      p V P"                  P.                  V n        V#   \        P&                   dN    RP)                  \*        P,                  ! 4       ^,          T P                  4      p\        P&                  ! T4      hi ; i)ac  
Initialize a GSS-API context.

:param str username: The name of the user who attempts to login
:param str target: The hostname of the target to connect to
:param str desired_mech: The negotiated GSS-API mechanism
                         ("pseudo negotiated" mechanism, because we
                         support just the krb5 mechanism :-))
:param str recv_token: The GSS-API token received from the Server
:raises:
    `.SSHException` -- Is raised if the desired mechanism of the client
    is not supported
:return: A ``String`` if the GSS-API has returned a token or
    ``None`` if no token was returned
rD   úhost@NúUnsupported mechanism OID.)Ú	peer_nameÚ	mech_typeÚ	req_flagsz{} Target: {})r9   rE   r   r   re   ÚNameÚC_NT_HOSTBASED_SERVICEÚContextrj   ÚflagsÚOIDÚmech_from_stringr!   rF   rG   r   ÚInitContextr"   ÚstepÚGSSExceptionÚformatÚsysÚexc_infoÚestablishedr#   )r(   ÚtargetrH   r1   Ú
recv_tokenrE   Ú	targ_nameÚctxÚ	krb5_mechrI   rJ   ÚtokenÚmessages   &&&&&        r   Ússh_init_sec_contextÚ$_SSH_GSSAPI_OLD.ssh_init_sec_context  sk  € õ$ 	-à!ŒØŒÜ—K’KØ�d—n‘nÕ$¤f×&CÑ&Có
ˆ	ô �nŠnÓˆØ—O‘OˆŒ	ØÒÜŸ
™
×3Ñ3°D·O±OÓD‰Ià—~‘~ lÓ3‰HˆDØ�|‰|‹~ §¡Ô0Ü"Ð#?Ó@Ð@ä"ŸJ™J×7Ñ7¸¿¹ÓH�	Øˆð	/ØÒ!Ü!'×!3Ò!3Ø'Ø'Ø!Ÿi™iô"�”ð
 Ÿ™×+Ñ+¨EÓ2‘àŸ™×+Ñ+¨JÓ7‘ð !%§¡× :Ñ :ˆÔØˆøô	 ×"Ñ"ô 	/Ø%×,Ñ,¬S¯\ª\«^¸AÕ->ÀÇÁÓOˆGÜ×%Ò% gÓ.Ð.ð	/ús   ÄAF ÅF ÆA"G)c                ó  € Wn         V'       gZ   V P                  V P                   V P                  V P                  V P                  4      pV P
                  P                  V4      pV# V P                  P                  V P                   4      pV# )aŽ  
Create the MIC token for a SSH2 message.

:param str session_id: The SSH session ID
:param bool gss_kex: Generate the MIC for GSS-API Key Exchange or not
:return: gssapi-with-mic:
         Returns the MIC token from GSS-API for the message we created
         with ``_ssh_build_mic``.
         gssapi-keyex:
         Returns the MIC token from GSS-API with the SSH session ID as
         message.
)r   rV   r   r    r   r"   Úget_micr$   ©r(   rT   Úgss_kexÚ	mic_fieldÚ	mic_tokens   &&&  r   Ússh_get_micÚ_SSH_GSSAPI_OLD.ssh_get_micA  s   € ð &ÔßØ×+Ñ+Ø× Ñ Ø—‘Ø—‘Ø×!Ñ!ó	ˆIð Ÿ™×.Ñ.¨yÓ9ˆIð Ðð ×*Ñ*×2Ñ2°4×3CÑ3CÓDˆIØÐr   c                óÚ   € Wn         W0n        V P                  f   \        P                  ! 4       V n        V P                  P                  V4      pV P                  P                  V n        V# )ás  
Accept a GSS-API context (server mode).

:param str hostname: The servers hostname
:param str username: The name of the user who attempts to login
:param str recv_token: The GSS-API Token received from the server,
                       if it's not the initial call.
:return: A ``String`` if the GSS-API has returned a token or ``None``
        if no token was returned
)r   r   r$   re   ÚAcceptContextry   r~   r%   ©r(   Úhostnamer€   r1   r„   s   &&&& r   Ússh_accept_sec_contextÚ&_SSH_GSSAPI_OLD.ssh_accept_sec_context\  sZ   € ð "ŒØ!ŒØ×ÑÒ%Ü!'×!5Ò!5Ó!7ˆDÔØ×"Ñ"×'Ñ'¨
Ó3ˆØ$(×$6Ñ$6×$BÑ$BˆÔ!Øˆr   c                ó8  € W n         W0n        V P                  eZ   V P                  V P                   V P                  V P                  V P                  4      pV P
                  P                  WA4       R# V P                  P                  V P                   V4       R# )a<  
Verify the MIC token for a SSH2 message.

:param str mic_token: The MIC token received from the client
:param str session_id: The SSH session ID
:param str username: The name of the user who attempts to login
:return: None if the MIC check was successful
:raises: ``gssapi.GSSException`` -- if the MIC check failed
N)r   r   rV   r    r   r$   Ú
verify_micr"   ©r(   r�   rT   r1   rŒ   s   &&&& r   Ússh_check_micÚ_SSH_GSSAPI_OLD.ssh_check_micp  s{   € ð &ÔØ!ŒØ�>‰>Ò%à×+Ñ+Ø× Ñ Ø—‘Ø—‘Ø×!Ñ!ó	ˆIð ×Ñ×)Ñ)¨)Ö?ð �N‰N×%Ñ% d×&6Ñ&6¸	ÖBr   c                ó:   € V P                   P                  e   R# R# )úy
Checks if credentials are delegated (server mode).

:return: ``True`` if credentials are delegated, otherwise ``False``
TF)r$   Údelegated_cred©r(   s   &r   Úcredentials_delegatedÚ%_SSH_GSSAPI_OLD.credentials_delegatedŠ  s   € ð ×Ñ×,Ñ,Ò8ÙÙr   c                ó   € \         h)a>  
Save the Client token in a file. This is used by the SSH server
to store the client credentials if credentials are delegated
(server mode).

:param str client_token: The GSS-API token received form the client
:raises:
    ``NotImplementedError`` -- Credential delegation is currently not
    supported in server mode
©ÚNotImplementedError©r(   Úclient_tokens   &&r   Úsave_client_credsÚ!_SSH_GSSAPI_OLD.save_client_creds•  ó
   € ô "Ð!r   ©r"   r#   rj   r   r$   r%   r   r   ©NNN©F©N©rY   rZ   r[   r\   r]   r)   r†   rŽ   r•   rš   Úpropertyr    r§   r^   r_   r`   s   @r   r   r   ï   sC   ø‡ € ñòô,2ôhô6ô(Cð4 ñó ð÷"ð "r   r   c                   óh   a € ] tR tRt o RtR tRR ltRR ltRR ltRR lt	]
R	 4       tR
 tRtV tR# )r   i¨  z�
Implementation of the GSS-API MIT Kerberos Authentication for SSH2,
using the newer, currently maintained gssapi package.

:see: `.GSSAuth`
c                óÔ  € \         P                  WV4       V P                  '       dn   \        P                  P
                  \        P                  P                  \        P                  P                  \        P                  P                  3V n	        R# \        P                  P
                  \        P                  P                  \        P                  P                  3V n	        R# rd   )
r   r)   r   re   ÚRequirementFlagÚprotection_readyÚ	integrityÚmutual_authenticationÚdelegate_to_peerrj   r'   s   &&&r   r)   Ú_SSH_GSSAPI_NEW.__init__°  s�   € ô 	×Ñ˜d°ÔAà× × Ð ä×&Ñ&×7Ñ7Ü×&Ñ&×0Ñ0Ü×&Ñ&×<Ñ<Ü×&Ñ&×7Ñ7ð	ˆDŽOô ×&Ñ&×7Ñ7Ü×&Ñ&×0Ñ0Ü×&Ñ&×<Ñ<ðˆDŽOr   Nc                ód  € ^ RI Hp W0n        Wn        \        P
                  ! RV P                  ,           \        P                  P                  R7      pVe>   VP                  V4      w  rxVP                  4       V P                  8w  d   \        R4      h\        P                  P                  p	Rp
VfF   \        P                  ! VV P                  V	RR7      V n        V P                   P#                  V
4      p
MV P                   P#                  V4      p
V P                   P$                  V n        V
# )aõ  
Initialize a GSS-API context.

:param str username: The name of the user who attempts to login
:param str target: The hostname of the target to connect to
:param str desired_mech: The negotiated GSS-API mechanism
                         ("pseudo negotiated" mechanism, because we
                         support just the krb5 mechanism :-))
:param str recv_token: The GSS-API token received from the Server
:raises: `.SSHException` -- Is raised if the desired mechanism of the
         client is not supported
:raises: ``gssapi.exceptions.GSSError`` if there is an error signaled
                                        by the GSS-API implementation
:return: A ``String`` if the GSS-API has returned a token or ``None``
         if no token was returned
rD   rm   )Ú	name_typeNrn   Úinitiate)r   ru   rI   Úusage)r9   rE   r   r   re   rr   ÚNameTypeÚhostbased_servicerF   rG   r!   r   ÚMechTypeÚkerberosÚSecurityContextrj   r"   ry   Úcompleter#   )r(   r   rH   r1   r€   rE   r�   rI   rJ   rƒ   r„   s   &&&&&      r   r†   Ú$_SSH_GSSAPI_NEW.ssh_init_sec_contextÆ  së   € õ& 	-à!ŒØŒÜ—K’KØ�d—n‘nÕ$Ü—o‘o×7Ñ7ô
ˆ	ð Ò#Ø—~‘~ lÓ3‰HˆDØ�|‰|‹~ §¡Ô0Ü"Ð#?Ó@Ð@Ü—O‘O×,Ñ,ˆ	ØˆØÒÜ#×3Ò3ØØ—o‘oØØ ô	ˆDŒNð —N‘N×'Ñ'¨Ó.‰Eà—N‘N×'Ñ'¨
Ó3ˆEØ $§¡× 7Ñ 7ˆÔØˆr   c                ó  € Wn         V'       gZ   V P                  V P                   V P                  V P                  V P                  4      pV P
                  P                  V4      pV# V P                  P                  V P                   4      pV# )aš  
Create the MIC token for a SSH2 message.

:param str session_id: The SSH session ID
:param bool gss_kex: Generate the MIC for GSS-API Key Exchange or not
:return: gssapi-with-mic:
         Returns the MIC token from GSS-API for the message we created
         with ``_ssh_build_mic``.
         gssapi-keyex:
         Returns the MIC token from GSS-API with the SSH session ID as
         message.
:rtype: str
)r   rV   r   r    r   r"   Úget_signaturer$   rŠ   s   &&&  r   rŽ   Ú_SSH_GSSAPI_NEW.ssh_get_micô  s   € ð &ÔßØ×+Ñ+Ø× Ñ Ø—‘Ø—‘Ø×!Ñ!ó	ˆIð Ÿ™×4Ñ4°YÓ?ˆIð Ðð ×*Ñ*×8Ñ8¸×9IÑ9IÓJˆIØÐr   c                óÞ   € Wn         W0n        V P                  f   \        P                  ! RR7      V n        V P                  P                  V4      pV P                  P                  V n        V# )r‘   Úaccept)r»   )r   r   r$   re   rÀ   ry   rÁ   r%   r“   s   &&&& r   r•   Ú&_SSH_GSSAPI_NEW.ssh_accept_sec_context  s\   € ð "ŒØ!ŒØ×ÑÒ%Ü!'×!7Ò!7¸hÔ!GˆDÔØ×"Ñ"×'Ñ'¨
Ó3ˆØ$(×$6Ñ$6×$?Ñ$?ˆÔ!Øˆr   c                ó8  € W n         W0n        V P                  eZ   V P                  V P                   V P                  V P                  V P                  4      pV P
                  P                  WA4       R# V P                  P                  V P                   V4       R# )aC  
Verify the MIC token for a SSH2 message.

:param str mic_token: The MIC token received from the client
:param str session_id: The SSH session ID
:param str username: The name of the user who attempts to login
:return: None if the MIC check was successful
:raises: ``gssapi.exceptions.GSSError`` -- if the MIC check failed
N)r   r   rV   r    r   r$   Úverify_signaturer"   r™   s   &&&& r   rš   Ú_SSH_GSSAPI_NEW.ssh_check_mic$  s{   € ð &ÔØ!ŒØ�>‰>Ò%à×+Ñ+Ø× Ñ Ø—‘Ø—‘Ø×!Ñ!ó	ˆIð ×Ñ×/Ñ/°	ÖEð �N‰N×+Ñ+¨D×,<Ñ,<¸iÖHr   c                ó:   € V P                   P                  e   R# R# )z†
Checks if credentials are delegated (server mode).

:return: ``True`` if credentials are delegated, otherwise ``False``
:rtype: bool
TF)r$   Údelegated_credsrŸ   s   &r   r    Ú%_SSH_GSSAPI_NEW.credentials_delegated>  s   € ð ×Ñ×-Ñ-Ò9ÙÙr   c                ó   € \         h)a?  
Save the Client token in a file. This is used by the SSH server
to store the client credentials if credentials are delegated
(server mode).

:param str client_token: The GSS-API token received form the client
:raises: ``NotImplementedError`` -- Credential delegation is currently
         not supported in server mode
r£   r¥   s   &&r   r§   Ú!_SSH_GSSAPI_NEW.save_client_credsJ  s
   € ô "Ð!r   rª   r«   r¬   r­   r®   r`   s   @r   r   r   ¨  sC   ø‡ € ñòô,,ô\ô8ô(Ið4 ñ	ó ð	÷
"ð 
"r   r   c                   ód   a € ] tR tRt o RtR tRR ltRR ltR tRR lt	]
R	 4       tR
 tRtV tR# )r   iW  zZ
Implementation of the Microsoft SSPI Kerberos Authentication for SSH2.

:see: `.GSSAuth`
c                ó,  € \         P                  WV4       V P                  '       dB   \        P                  \        P
                  ,          \        P                  ,          V n        R# \        P                  \        P
                  ,          V n        R# rd   )r   r)   r   ÚsspiconÚISC_REQ_INTEGRITYÚISC_REQ_MUTUAL_AUTHÚISC_REQ_DELEGATErj   r'   s   &&&r   r)   Ú_SSH_SSPI.__init__^  si   € ô 	×Ñ˜d°ÔAà× × Ð ä×)Ñ)Ü×-Ñ-õ.ä×*Ñ*õ+ð ŽOô ×)Ñ)¬G×,GÑ,GÕGð ŽOr   Nc                óT  € ^ RI Hp W0n        Wn        ^ pRV P                  ,           pVe>   VP	                  V4      w  r‰VP                  4       V P                  8w  d   \        R4      h Vf)   \        P                  ! RV P                  VR7      V n        V P                  P                  V4      w  rjV
^ ,          P                  p
T^ 8X  d    RT n        Rp
 T
#   \        P                   d9   pT;P                   RP#                  T P                  4      ,          un        h Rp?ii ; i)	aT  
Initialize a SSPI context.

:param str username: The name of the user who attempts to login
:param str target: The FQDN of the target to connect to
:param str desired_mech: The negotiated SSPI mechanism
                         ("pseudo negotiated" mechanism, because we
                         support just the krb5 mechanism :-))
:param recv_token: The SSPI token received from the Server
:raises:
    `.SSHException` -- Is raised if the desired mechanism of the client
    is not supported
:return: A ``String`` if the SSPI has returned a token or ``None`` if
         no token was returned
rD   úhost/Nrn   ÚKerberos)ÚscflagsÚ	targetspnz, Target: {}T)r9   rE   r   r   rF   rG   r!   r   ÚsspiÚ
ClientAuthrj   r"   Ú	authorizeÚBufferÚ
pywintypesÚerrorÚstrerrorr{   r#   )r(   r   rH   r1   r€   rE   râ   r�   rI   rJ   r„   Úes   &&&&&       r   r†   Ú_SSH_SSPI.ssh_init_sec_contextq  s  € õ$ 	-à!ŒØŒØˆØ˜dŸn™nÕ,ˆ	ØÒ#Ø—~‘~ lÓ3‰HˆDØ�|‰|‹~ §¡Ô0Ü"Ð#?Ó@Ð@ð		ØÒ!Ü!%§¢Ø¨¯©À9ô"�”ð  Ÿ>™>×3Ñ3°JÓ?‰LˆEØ˜!•H—O‘OˆEð
 �AŒ:ðð %)ˆDÔ!ØˆEðð ˆøô ×Ñô 	Ø�JŠJ˜.×/Ñ/°·±Ó?Õ?�JØûð	ús   Á*AC ÃD'Ã/3D"Ä"D'c                ó  € Wn         V'       gZ   V P                  V P                   V P                  V P                  V P                  4      pV P
                  P                  V4      pV# V P                  P                  V P                   4      pV# )aŠ  
Create the MIC token for a SSH2 message.

:param str session_id: The SSH session ID
:param bool gss_kex: Generate the MIC for Key Exchange with SSPI or not
:return: gssapi-with-mic:
         Returns the MIC token from SSPI for the message we created
         with ``_ssh_build_mic``.
         gssapi-keyex:
         Returns the MIC token from SSPI with the SSH session ID as
         message.
)r   rV   r   r    r   r"   Úsignr$   rŠ   s   &&&  r   rŽ   Ú_SSH_SSPI.ssh_get_mic¥  s   € ð &ÔßØ×+Ñ+Ø× Ñ Ø—‘Ø—‘Ø×!Ñ!ó	ˆIð Ÿ™×+Ñ+¨IÓ6ˆIð Ðð ×*Ñ*×/Ñ/°×0@Ñ0@ÓAˆIØÐr   c                óþ   € Wn         W n        RV P                   ,           p\        P                  ! RVR7      V n        V P                  P                  V4      w  rVV^ ,          P                  pV^ 8X  d
   RV n        RpV# )ag  
Accept a SSPI context (server mode).

:param str hostname: The servers FQDN
:param str username: The name of the user who attempts to login
:param str recv_token: The SSPI Token received from the server,
                       if it's not the initial call.
:return: A ``String`` if the SSPI has returned a token or ``None`` if
         no token was returned
rÙ   rÚ   )ÚspnTN)r   r   rÝ   Ú
ServerAuthr$   rß   rà   r%   )r(   r”   r1   r€   r�   râ   r„   s   &&&&   r   r•   Ú _SSH_SSPI.ssh_accept_sec_contextÀ  sm   € ð "ŒØ!ŒØ˜dŸn™nÕ,ˆ	Ü!Ÿ_š_¨Z¸YÔGˆÔØ×)Ñ)×3Ñ3°JÓ?‰ˆØ�a•—‘ˆØ�AŒ:Ø(,ˆDÔ%ØˆEØˆr   c                ó$  € W n         W0n        VeZ   V P                  V P                   V P                  V P                  V P                  4      pV P
                  P                  WA4       R# V P                  P                  V P                   V4       R# )a3  
Verify the MIC token for a SSH2 message.

:param str mic_token: The MIC token received from the client
:param str session_id: The SSH session ID
:param str username: The name of the user who attempts to login
:return: None if the MIC check was successful
:raises: ``sspi.error`` -- if the MIC check failed
N)r   r   rV   r    r   r$   Úverifyr"   r™   s   &&&& r   rš   Ú_SSH_SSPI.ssh_check_micÖ  sw   € ð &ÔØ!ŒØÒà×+Ñ+Ø× Ñ Ø—‘Ø—‘Ø×!Ñ!ó	ˆIð ×Ñ×%Ñ% iÖ;ð �N‰N×!Ñ! $×"2Ñ"2°IÖ>r   c                ó”   € V P                   \        P                  ,          ;'       d!    V P                  ;'       g    V P                   # )r�   )rj   rÓ   rÖ   r%   rŸ   s   &r   r    Ú_SSH_SSPI.credentials_delegatedô  s:   € ð �‰¤×!9Ñ!9Õ9÷ 
ð 
Ø×%Ñ%×8Ð8¨¯©ð	
r   c                ó   € \         h)a;  
Save the Client token in a file. This is used by the SSH server
to store the client credentails if credentials are delegated
(server mode).

:param str client_token: The SSPI token received form the client
:raises:
    ``NotImplementedError`` -- Credential delegation is currently not
    supported in server mode
r£   r¥   s   &&r   r§   Ú_SSH_SSPI.save_client_credsÿ  r©   r   rª   r«   r¬   r­   r®   r`   s   @r   r   r   W  sB   ø‡ € ñòô&2ôhò6ô,?ð< ñ
ó ð
÷"ð "r   r   © )T)é   é   )"r]   rN   r   r|   ÚGSS_AUTH_AVAILABLEÚGSS_EXCEPTIONSr   re   Úhasattrr   rz   Ú
exceptionsÚGeneralErrorÚrawÚmiscÚGSSErrorr   ÚOSErrorrá   rÓ   rÝ   râ   Úparamiko.commonr   Úparamiko.ssh_exceptionr   Úparamiko._versionr   r   r   r   Ú_SSH_GSSAPIr   r   rô   r   r   Ú<module>r     s8  ðñ,ó Û 	Û 
ð Ð ð €ð €ðÛáˆv�{×#Ò#¨×(8Ñ(8¸OÔ(KàˆØ ×-Ñ-Ð/‰à"ˆà×Ñ×*Ñ*Ø�J‰J�O‰O×$Ñ$ð
‰õ  1Ý /Ý .ôG÷@~ñ ~ôBq"�lô q"ðh �fÔà!€Kôl"�lô l"ô^s"�ö s"øðu 	�WÐô 
ð	ÛÛÛàˆØ$×*Ñ*Ð,ŠøØô Ø"ÐØ‹ðúð
ús4   –C © C Á
8C Ã	D
ÃC7Ã7DÄD
ÄDÄD
