3
]ð]V  ã               @   s:   d Z yddlZW n ek
r$   Y nX G dd„ deƒZdS )z!A fake SSLContext implementation.é    Nc               @   s`   e Zd ZdZdZdd„ Zed	d
„ ƒZdd„ Zdd„ Z	eee	ƒZ
ddd„Zddd„Zddd„ZdS )Ú
SSLContexta‰  A fake SSLContext.

    This implements an API similar to ssl.SSLContext from python 3.2
    but does not implement methods or properties that would be
    incompatible with ssl.wrap_socket from python 2.7 < 2.7.9.

    You must pass protocol which must be one of the PROTOCOL_* constants
    defined in the ssl module. ssl.PROTOCOL_SSLv23 is recommended for maximum
    interoperability.
    Ú_cafileÚ	_certfileÚ_keyfileÚ	_protocolÚ_verify_modec             C   s$   d | _ d | _d | _|| _tj| _d S )N)r   r   r   r   ÚsslÚ	CERT_NONEr   )ÚselfÚprotocol© r   ú6/tmp/pip-build-20mum3z4/pymongo/pymongo/ssl_context.pyÚ__init__&   s
    zSSLContext.__init__c             C   s   | j S )zhThe protocol version chosen when constructing the context.
        This attribute is read-only.
        )r   )r
   r   r   r   r   -   s    zSSLContext.protocolc             C   s   | j S )zÉWhether to try to verify other peers' certificates and how to
        behave if verification fails. This attribute must be one of
        ssl.CERT_NONE, ssl.CERT_OPTIONAL or ssl.CERT_REQUIRED.
        )r   )r
   r   r   r   Z__get_verify_mode4   s    zSSLContext.__get_verify_modec             C   s
   || _ dS )zSetter for verify_mode.N)r   )r
   Úvaluer   r   r   Z__set_verify_mode;   s    zSSLContext.__set_verify_modeNc             C   s   || _ || _dS )a²  Load a private key and the corresponding certificate. The certfile
        string must be the path to a single file in PEM format containing the
        certificate as well as any number of CA certificates needed to
        establish the certificate's authenticity. The keyfile string, if
        present, must point to a file containing the private key. Otherwise
        the private key will be taken from certfile as well.
        N)r   r   )r
   ÚcertfileÚkeyfiler   r   r   Úload_cert_chainA   s    zSSLContext.load_cert_chainc             C   s
   || _ dS )z­Load a set of "certification authority"(CA) certificates used to
        validate other peers' certificates when `~verify_mode` is other than
        ssl.CERT_NONE.
        N)r   )r
   ÚcafileÚdummyr   r   r   Úload_verify_locationsL   s    z SSLContext.load_verify_locationsFTc             C   s&   t j|| j| j|| j| j| j||d�	S )zXWrap an existing Python socket sock and return an ssl.SSLSocket
        object.
        )r   r   Úserver_sideÚ	cert_reqsÚssl_versionÚca_certsÚdo_handshake_on_connectÚsuppress_ragged_eofs)r   Úwrap_socketr   r   r   r   r   )r
   Úsockr   r   r   r   r   r   r   r   S   s    
zSSLContext.wrap_socket)r   r   r   r   r   )N)NN)FTTN)Ú__name__Ú
__module__Ú__qualname__Ú__doc__Ú	__slots__r   Úpropertyr   Z_SSLContext__get_verify_modeZ_SSLContext__set_verify_modeÚverify_moder   r   r   r   r   r   r   r      s   
 


  r   )r!   r   ÚImportErrorÚobjectr   r   r   r   r   Ú<module>   s
   