403Webshell
Server IP : 198.38.94.13  /  Your IP : 216.73.217.33
Web Server : Apache
System : Linux d4744.dxb1.stableserver.net 5.14.0-611.49.1.el9_7.x86_64 #1 SMP PREEMPT_DYNAMIC Tue Apr 21 16:39:08 EDT 2026 x86_64
User : revivere ( 1140)
PHP Version : 8.2.33
Disable Function : NONE
MySQL : OFF  |  cURL : ON  |  WGET : ON  |  Perl : ON  |  Python : OFF  |  Sudo : OFF  |  Pkexec : OFF
Directory :  /usr/lib/python3.9/site-packages/ipaclient/install/__pycache__/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Command :


[ Back ]     

Current File : /usr/lib/python3.9/site-packages/ipaclient/install/__pycache__/ipa_certupdate.cpython-39.pyc
a

�jix+�@sddlmZddlZddlZddlmZddlmZmZddl	m
Z
ddlmZm
Z
mZmZddlmZddlmZdd	lmZdd
lmZmZmZddlmZmZmZddlmZe� e!�Z"Gd
d�dej#�Z$ddd�Z%dd�Z&dd�Z'dd�Z(ddd�Z)dd�Z*dS)�)�absolute_importN)�urlsplit)�
certmonger�	certstore)�is_ipa_configured)�	admintool�certdb�ipaldap�ipautil)�services)�paths)�tasks)�api�errors�x509)�FQDN�IPA_CA_NICKNAME�RENEWAL_CA_NAME)�check_client_configurationcsDeZdZdZdZdZed�fdd�	�Zd
�fdd	�	Zd
d�Z	�Z
S)�
CertUpdatezipa-certupdatez%prog [options]zIUpdate local IPA certificate databases with certificates from the server.Fcs*tt|��|�|jddtdddd�dS)Nz--force-server�
forced_serverzipa.server.fqdnz6Force the use of the specified server for the update. )�dest�type�default�metavar�help)�superr�add_optionsZ
add_option�str)�cls�parserZdebug_option��	__class__��D/usr/lib/python3.9/site-packages/ipaclient/install/ipa_certupdate.pyr0s�zCertUpdate.add_optionsTcst��|�dS)N)r�validate_options)�selfZ
needs_rootr!r#r$r%<szCertUpdate.validate_optionsc
Cs�t�tj�d�}dtjd<dtjd<z�zddtjd�}|jjdurN|jj|d<tj	fi|��t�
�tjj�
�tt|j�tjj��Wn"tjy�t�dt��Yn0W|dur�tj�dd�q�|tjd<n$|dur�tj�dd�n
|tjd<0dS)	NZ
KRB5CCNAMEz/etc/krb5.keytabZKRB5_CLIENT_KTNAMEzMEMORY:Z
cli_installer)�contextZconfdirrz9Unable to obtain credentials for %s from /etc/krb5.keytab)r�os�environ�getrZETC_IPA�optionsrrZ	bootstrap�finalizeZBackendZ	rpcclientZconnect�
run_with_argsZ
disconnectrZCCacheError�logger�errorr�pop)r&Zold_krb5ccnameZbootstrap_kwr#r#r$�run?s6

��
�zCertUpdate.run)F)T)�__name__�
__module__�__qualname__Zcommand_name�usage�description�classmethodrr%r1�
__classcell__r#r#r!r$r(src	Cs�|dust|dd�dur(t|jj�j}n|j}t�d|�tj	�
|�}z|jjdd�}|d}Wn6t
jt
jfy�|jjddd	�}|dd
}Yn0|��t�||jj|jj|�}|r�|j��d}ng}t|�t��r�|jjddd
�}dd�|dD�}	t|�ddlm}
m}|
�����rVz|
�|�Wnt �yTt�!d�Yn0zt"|
||jj#|jj$|	�Wnt �y�t�!d�Yn0t%j&j'�(��r�t%j&j'�)�t%j&j*�(��r�t%j&j*�)�dS)z�
    Run the certupdate procedure with the given API object.

    :param api: API object with ldap2/rpcclient backend connected
                (such that Commands can be invoked)

    Nrz$Updating certificates from server %sz2.107)�version�resultTz2.0)�serverr9�	enable_raz	CA serverZenabled)Z
role_servrole�statuscSsg|]}|d�qS)Z
server_serverr#)�.0r;r#r#r$�
<listcomp>��z!run_with_args.<locals>.<listcomp>r)�
cainstance�custodiainstancez.Failed to add lightweight CA tracking requestszFailed to update RA config)+�getattrr�envZjsonrpc_uri�hostnamerr.�infor	Z
LDAPClientZfrom_hostname_secureZCommandZ
ca_is_enabledrZCommandErrorZNetworkErrorZgssapi_bindrZget_ca_certsZbasedn�realmZca_find�
update_clientrZserver_role_find�
update_serverZipaserver.installrArB�
CAInstanceZ
is_configuredZ$add_lightweight_ca_tracking_requests�	Exception�	exception�update_server_ra_configr<�ca_hostr�
knownservicesZhttpd�
is_running�restartZkrb5kdc)rr+r;Zldapr:Z
ca_enabled�certsZlwcasZresp�
ca_serversrArBr#r#r$r-csZ���
�r-cCs�ttj|�ttj|�ttj|�t�tjj	�}dD]d}|�
|�r6z|�|�Wq:tj
y�}z*t�d||j|�WYd}~q6WYd}~q:d}~00q:q6t|j|�t��t�|�dS)N)zIPA CAzExternal CA certzFailed to remove %s from %s: %s)�update_filerZ
IPA_CA_CRTZKDC_CA_BUNDLE_PEMZ
CA_BUNDLE_PEMr�NSSDatabaserrDZnss_dirZhas_nickname�delete_certr
�CalledProcessErrorr.r/Zsecdir�	update_dbr
Z(remove_ca_certs_from_systemwide_ca_storeZ(insert_ca_certs_into_systemwide_ca_store)rRZipa_db�nickname�er#r#r$rH�s"
�&rHcCsd�tjj�d��}ttj||�tj	j
��r>tj	j
�|�tj
ttd�}t�|�}|dur�tjjd}t�d|�tj|dd�zt�||�}Wn ty�t�d|��Yn0t�|d	�}|d
ks�|r�t�d|��t�d|�tj|d
d�ttj|�ttj|�dS)N�-�.)z
cert-databasez
cert-nicknamezca-name�<z$resubmitting certmonger request '%s'zdogtag-ipa-ca-renew-agent-reuse)�cazQResubmitting certmonger request '%s' timed out, please check the request manuallyzca-errorZ
MONITORINGzMError resubmitting certmonger request '%s', please check the request manuallyz!modifying certmonger request '%s'zdogtag-ipa-ca-renew-agent)�joinrrDrG�splitrXrZ"ETC_DIRSRV_SLAPD_INSTANCE_TEMPLATErrOZdirsrvrPrQZPKI_TOMCAT_ALIAS_DIRrrrZget_request_idZstartup_timeoutr.�debugZresubmit_requestZwait_for_request�RuntimeErrorrZScriptErrorZget_request_valueZmodifyrTZCA_CRTZ
CACERT_PEM)rR�instanceZcriteriaZ
request_id�timeout�stateZca_errorr#r#r$rI�sD�

���
��rIcCsjt|�dkrdS|d}|sT|j��|jtjjtjj|d�}|�|�|�	|�n||vrf|�	|�dS)z�
    After promoting a CA-less deployment to CA-ful, or after removal
    of a CA server from the topology, it may be necessary to update
    the default.conf ca_host setting on non-CA replicas.

    rN)Z	host_namerGZ
custodia_peer)
�lenrJZ$configure_certmonger_renewal_helpersZCustodiaInstancerrD�hostrGZ
import_ra_keyZupdate_ipa_conf)rArBr<rNrSZnew_ca_hostZcustodiar#r#r$rM�s

�
rM�c
CsZdd�|D�}ztj|||d�Wn2tyT}zt�d||�WYd}~n
d}~00dS)Ncss"|]}|ddur|dVqdS)�FrNr#)r>�cr#r#r$�	<genexpr>"r@zupdate_file.<locals>.<genexpr>)�modezfailed to update %s: %s)rZwrite_certificate_listrKr.r/)�filenamerRrlrZr#r#r$rT!s
rTcCs�t�|�}|��D]\}}|jr|�|�q|D]f\}}}}}	t�|d|�}
z|�|||
�Wq0tj	y�}zt
�d|||�WYd}~q0d}~00q0dS)z�Drop all CA certs from db then add certs from list provided

       This may result in some churn as existing certs are dropped
       and re-added but this also provides the ability to change
       the trust flags.
    Tzfailed to update %s in %s: %sN)rrUZ
list_certsr^rVrZkey_policy_to_trust_flagsZadd_certr
rWr.r/)�pathrRZdb�name�flagsZcertrYZtrustedZekuZ_serialZtrust_flagsrZr#r#r$rX)s
rX)N)rh)+Z
__future__rZloggingr(�urllib.parserZipalib.installrrZipalib.factsrZ	ipapythonrrr	r
ZipaplatformrZipaplatform.pathsrZipaplatform.tasksr
ZipalibrrrZipalib.constantsrrrZipalib.utilrZ	getLoggerr2r.Z	AdminToolrr-rHrIrMrTrXr#r#r#r$�<module>s(
;
Q0%


Youez - 2016 - github.com/yon3zu
LinuXploit