
Â�Â­Â�Â­Â�Â­Â�Â­Â�Â­Â�Â­Â�Â­Â�Â­Â�Â­Â�Â­Â�Â­Â�Â­Â�Â­Â�Â­Â�Â­Â�Â­Â�Â­Â�Â­
<!DOCTYPE html>
<html>
3
Šcjƒ$  ã               @   s†  U d Z ddlZddlZddlmZ ddlmZmZ ddlm	Z	 ddl
mZ ddlmZmZ ddlmZ ejeƒZdd	d
ddgdœZdddddgdœdddddgdœdddddgdœdœZxd:D ]Zed ee< q¾W xd;D ]Zed ee< qØW dZddd d!d"ddddddddd#gZd$d%d&eeeed'ƒgd(d)gd*œZeeeƒZ d+d,„ Zd-d.„ Zd/d0„ Zd1d2„ Zd3d4„ Zd5d6„ Ze ee	e!dd7œd8d9„Z"dS )<zCA Certs: Add ca certificates.é    N)Údedent)ÚsubpÚutil)ÚCloud)ÚConfig)Ú
MetaSchemaÚget_meta_doc)ÚPER_INSTANCEz!/usr/local/share/ca-certificates/z#cloud-init-ca-cert-{cert_index}.crtz/etc/ca-certificates.confzupdate-ca-certificates)Úca_cert_pathÚca_cert_local_pathÚca_cert_filenameÚca_cert_configÚca_cert_update_cmdz/etc/pki/ca-trust/z/usr/share/pki/ca-trust-source/z+anchors/cloud-init-ca-cert-{cert_index}.crtzupdate-ca-trustz/etc/pki/trust/z/usr/share/pki/trust/)ÚfedoraÚrhelÚopensuseúopensuse-microosúopensuse-tumbleweedúopensuse-leapÚsle_hpcú	sle-microÚslesr   Ú	almalinuxÚ
cloudlinuxr   a/  This module adds CA certificates to the system's CA store and updates any
related files using the appropriate OS-specific utility. The default CA
certificates can be disabled/deleted from use by the system with the
configuration option ``remove_defaults``.

.. note::
    certificates must be specified using valid yaml. in order to specify a
    multiline certificate, the yaml multiline list syntax must be used

.. note::
    Alpine Linux requires the ca-certificates package to be installed in
    order to provide the ``update-ca-certificates`` command.
ÚalpineÚdebianr   ÚubuntuZcc_ca_certszCA CertificateszAdd ca certificatesa              ca_certs:
              remove_defaults: true
              trusted:
                - single_line_cert
                - |
                  -----BEGIN CERTIFICATE-----
                  YOUR-ORGS-TRUSTED-CA-CERT-HERE
                  -----END CERTIFICATE-----
            Úca_certszca-certs)ÚidÚnameÚtitleÚdescriptionÚdistrosZ	frequencyZexamplesZactivate_by_schema_keysc             C   s*   t j| tƒ}tjj|d |d ƒ|d< |S )z²Return a distro-specific ca_certs config dictionary

    @param distro_name: String providing the distro class name.
    @returns: Dict of distro configurations for ca_cert.
    r   r   Úca_cert_full_path)ÚDISTRO_OVERRIDESÚgetÚDEFAULT_CONFIGÚosÚpathÚjoin)Údistro_nameÚcfg© r,   ú!/usr/lib/python3.6/cc_ca_certs.pyÚ_distro_ca_certs_configs|   s    r.   c             C   s   t j | d dd� dS )zŽ
    Updates the CA certificate cache on the current machine.

    @param distro_cfg: A hash providing _distro_ca_certs_configs function.
    r   F)ZcaptureN)r   )Ú
distro_cfgr,   r,   r-   Úupdate_ca_certs‰   s    r0   c             C   sL   |sdS x>t |dƒD ]0\}}t|ƒ}| d j|d�}tj||dd� qW dS )a-  
    Adds certificates to the system. To actually apply the new certificates
    you must also call the appropriate distro-specific utility such as
    L{update_ca_certs}.

    @param distro_cfg: A hash providing _distro_ca_certs_configs function.
    @param certs: A list of certificate strings.
    Né   r#   )Ú
cert_indexi¤  )Úmode)Ú	enumerateÚstrÚformatr   Ú
write_file)r/   Zcertsr2   ÚcZcert_file_contentsZcert_file_namer,   r,   r-   Úadd_ca_certs’   s    	r9   c             C   s@   | dkrt |ƒ n*| dkr<t|ƒ | dkr<d}tjd|d	� d
S )a.  
    Disables all default trusted CA certificates. For Alpine, Debian and
    Ubuntu to actually apply the changes you must also call
    L{update_ca_certs}.

    @param distro_name: String providing the distro class name.
    @param distro_cfg: A hash providing _distro_ca_certs_configs function.
    r   r   r   r   z/ca-certificates ca-certificates/trust_new_crts z	select noúdebconf-set-selectionsú-)ÚdataN)r   r   r   )r   r   z8ca-certificates ca-certificates/trust_new_crts select no)r:   r;   )Úremove_default_ca_certsÚdisable_system_ca_certsr   )r*   r/   Zdebconf_selr,   r,   r-   Údisable_default_ca_certs§   s    	
r?   c             C   sÊ   | d }| st jj|ƒ r dS d}d}t j|ƒjrÆtj|ƒ}g }xh|jƒ D ]\}||krhd}|j|ƒ qL|dks||d dkrˆ|j|ƒ qL|sš|j|ƒ d}|jd	| ƒ qLW tj	|d
j
|ƒd
 dd� dS )z¸
    For every entry in the CA_CERT_CONFIG file prefix the entry with a "!"
    in order to disable it.

    @param distro_cfg: A hash providing _distro_ca_certs_configs function.
    r   Nz;# Modified by cloud-init to deselect certs due to user-dataFTÚ r   ú#ú!Ú
Úwb)Zomode)rA   rB   )r'   r(   ÚexistsÚstatÚst_sizer   Z	load_fileÚ
splitlinesÚappendr7   r)   )r/   Zca_cert_cfg_fnZheader_commentZadded_headerZorigZ	out_linesÚliner,   r,   r-   r>   ¼   s(    

r>   c             C   s:   | d dkrdS t jdƒ tj| d ƒ tj| d ƒ dS )z’
    Removes all default trusted CA certificates from the system.

    @param distro_cfg: A hash providing _distro_ca_certs_configs function.
    r
   NzDeleting system CA certificatesr   )ÚLOGÚdebugr   Zdelete_dir_contents)r/   r,   r,   r-   r=   ã   s
    
r=   )r   r+   ÚcloudÚargsÚreturnc             C   sö   d|krt jdddd� nd|kr2tjd| ƒ dS d|krLd|krLtjd	ƒ |jd|jdƒƒ}t|jjƒ}d
|kr‚t jdddd� |jd|jd
dƒƒr®tjdƒ t	|jj|ƒ d|kràt j
|dƒ}|ràtjdt|ƒƒ t||ƒ tjdƒ t|ƒ dS )au  
    Call to handle ca_cert sections in cloud-config file.

    @param name: The module name "ca_cert" from cloud.cfg
    @param cfg: A nested dict containing the entire cloud config contents.
    @param cloud: The L{CloudInit} object in use.
    @param log: Pre-initialized Python logger object to use for logging.
    @param args: Any module arguments from cloud.cfg
    zca-certszKey 'ca-certs'z22.1zUse 'ca_certs' instead.)Z
deprecatedZdeprecated_versionZextra_messager   z<Skipping module named %s, no 'ca_certs' key in configurationNzMFound both ca-certs (deprecated) and ca_certs config keys. Ignoring ca-certs.zremove-defaultszKey 'remove-defaults'zUse 'remove_defaults' instead.Zremove_defaultsFz'Disabling/removing default certificatesZtrustedzAdding %d certificateszUpdating certificates)r   Z	deprecaterK   rL   Zwarningr%   r.   Údistror   r?   Zget_cfg_option_listÚlenr9   r0   )r   r+   rM   rN   Zca_cert_cfgr/   Ztrusted_certsr,   r,   r-   Úhandleñ   s>    




rR   )r   r   r   r   r   r   )r   r   )#Ú__doc__Zloggingr'   Útextwrapr   Z	cloudinitr   r   Zcloudinit.cloudr   Zcloudinit.configr   Zcloudinit.config.schemar   r   Zcloudinit.settingsr	   Z	getLoggerÚ__name__rK   r&   r$   rP   ZMODULE_DESCRIPTIONr"   Úmetar.   r0   r9   r?   r>   r=   r5   ÚlistrR   r,   r,   r,   r-   Ú<module>   s’   

      
	'