1# This file is dual licensed under the terms of the Apache License, Version
2# 2.0, and the BSD License. See the LICENSE file in the root of this repository
3# for complete details.
4
5from __future__ import annotations
6
7import abc
8import typing
9
10from cryptography import utils
11from cryptography.hazmat.bindings._rust import openssl as rust_openssl
12from cryptography.hazmat.primitives import _serialization, hashes
13from cryptography.hazmat.primitives.asymmetric import utils as asym_utils
14from cryptography.utils import Buffer
15
16_DSA_DEPRECATION_MSG = (
17 "DSA is deprecated and support will be removed in a future release. "
18 "Use a more modern signature algorithm."
19)
20
21
22class DSAParameters(metaclass=abc.ABCMeta):
23 @abc.abstractmethod
24 def generate_private_key(self) -> DSAPrivateKey:
25 """
26 Generates and returns a DSAPrivateKey.
27 """
28
29 @abc.abstractmethod
30 def parameter_numbers(self) -> DSAParameterNumbers:
31 """
32 Returns a DSAParameterNumbers.
33 """
34
35
36DSAParametersWithNumbers = DSAParameters
37DSAParameters.register(rust_openssl.dsa.DSAParameters)
38
39
40class DSAPrivateKey(metaclass=abc.ABCMeta):
41 @property
42 @abc.abstractmethod
43 def key_size(self) -> int:
44 """
45 The bit length of the prime modulus.
46 """
47
48 @abc.abstractmethod
49 def public_key(self) -> DSAPublicKey:
50 """
51 The DSAPublicKey associated with this private key.
52 """
53
54 @abc.abstractmethod
55 def parameters(self) -> DSAParameters:
56 """
57 The DSAParameters object associated with this private key.
58 """
59
60 @abc.abstractmethod
61 def sign(
62 self,
63 data: Buffer,
64 algorithm: asym_utils.Prehashed | hashes.HashAlgorithm,
65 ) -> bytes:
66 """
67 Signs the data
68 """
69
70 @abc.abstractmethod
71 def private_numbers(self) -> DSAPrivateNumbers:
72 """
73 Returns a DSAPrivateNumbers.
74 """
75
76 @abc.abstractmethod
77 def private_bytes(
78 self,
79 encoding: _serialization.Encoding,
80 format: _serialization.PrivateFormat,
81 encryption_algorithm: _serialization.KeySerializationEncryption,
82 ) -> bytes:
83 """
84 Returns the key serialized as bytes.
85 """
86
87 @abc.abstractmethod
88 def __copy__(self) -> DSAPrivateKey:
89 """
90 Returns a copy.
91 """
92
93 @abc.abstractmethod
94 def __deepcopy__(self, memo: dict) -> DSAPrivateKey:
95 """
96 Returns a deep copy.
97 """
98
99
100DSAPrivateKeyWithSerialization = DSAPrivateKey
101DSAPrivateKey.register(rust_openssl.dsa.DSAPrivateKey)
102
103
104class DSAPublicKey(metaclass=abc.ABCMeta):
105 @property
106 @abc.abstractmethod
107 def key_size(self) -> int:
108 """
109 The bit length of the prime modulus.
110 """
111
112 @abc.abstractmethod
113 def parameters(self) -> DSAParameters:
114 """
115 The DSAParameters object associated with this public key.
116 """
117
118 @abc.abstractmethod
119 def public_numbers(self) -> DSAPublicNumbers:
120 """
121 Returns a DSAPublicNumbers.
122 """
123
124 @abc.abstractmethod
125 def public_bytes(
126 self,
127 encoding: _serialization.Encoding,
128 format: _serialization.PublicFormat,
129 ) -> bytes:
130 """
131 Returns the key serialized as bytes.
132 """
133
134 @abc.abstractmethod
135 def verify(
136 self,
137 signature: Buffer,
138 data: Buffer,
139 algorithm: asym_utils.Prehashed | hashes.HashAlgorithm,
140 ) -> None:
141 """
142 Verifies the signature of the data.
143 """
144
145 @abc.abstractmethod
146 def __eq__(self, other: object) -> bool:
147 """
148 Checks equality.
149 """
150
151 @abc.abstractmethod
152 def __copy__(self) -> DSAPublicKey:
153 """
154 Returns a copy.
155 """
156
157 @abc.abstractmethod
158 def __deepcopy__(self, memo: dict) -> DSAPublicKey:
159 """
160 Returns a deep copy.
161 """
162
163
164DSAPublicKeyWithSerialization = DSAPublicKey
165DSAPublicKey.register(rust_openssl.dsa.DSAPublicKey)
166
167DSAPrivateNumbers = rust_openssl.dsa.DSAPrivateNumbers
168DSAPublicNumbers = rust_openssl.dsa.DSAPublicNumbers
169DSAParameterNumbers = rust_openssl.dsa.DSAParameterNumbers
170
171
172def generate_parameters(
173 key_size: int, backend: typing.Any = None
174) -> DSAParameters:
175 if key_size not in (1024, 2048, 3072, 4096):
176 raise ValueError("Key size must be 1024, 2048, 3072, or 4096 bits.")
177
178 return rust_openssl.dsa.generate_parameters(key_size)
179
180
181def generate_private_key(
182 key_size: int, backend: typing.Any = None
183) -> DSAPrivateKey:
184 parameters = _generate_parameters(key_size)
185 return parameters.generate_private_key()
186
187
188# Aliases that do not emit the deprecation warning on attribute access, for
189# internal use (e.g. the unions in
190# cryptography.hazmat.primitives.asymmetric.types, which are evaluated at
191# import time, and isinstance checks in the serialization and X.509 code).
192# `utils.deprecated` replaces the public names in this module's namespace, so
193# `generate_private_key` must go through the alias too.
194_generate_parameters = generate_parameters
195_DSAPublicKey = DSAPublicKey
196_DSAPrivateKey = DSAPrivateKey
197_DSAPrivateNumbers = DSAPrivateNumbers
198_DSAPublicNumbers = DSAPublicNumbers
199_DSAParameterNumbers = DSAParameterNumbers
200
201utils.deprecated(
202 generate_parameters,
203 __name__,
204 _DSA_DEPRECATION_MSG,
205 utils.DeprecatedIn51,
206 name="generate_parameters",
207)
208
209utils.deprecated(
210 generate_private_key,
211 __name__,
212 _DSA_DEPRECATION_MSG,
213 utils.DeprecatedIn51,
214 name="generate_private_key",
215)
216
217utils.deprecated(
218 DSAPrivateNumbers,
219 __name__,
220 _DSA_DEPRECATION_MSG,
221 utils.DeprecatedIn51,
222 name="DSAPrivateNumbers",
223)
224
225utils.deprecated(
226 DSAPublicNumbers,
227 __name__,
228 _DSA_DEPRECATION_MSG,
229 utils.DeprecatedIn51,
230 name="DSAPublicNumbers",
231)
232
233utils.deprecated(
234 DSAParameterNumbers,
235 __name__,
236 _DSA_DEPRECATION_MSG,
237 utils.DeprecatedIn51,
238 name="DSAParameterNumbers",
239)
240
241utils.deprecated(
242 DSAParameters,
243 __name__,
244 _DSA_DEPRECATION_MSG,
245 utils.DeprecatedIn51,
246 name="DSAParameters",
247)
248
249utils.deprecated(
250 DSAParameters,
251 __name__,
252 _DSA_DEPRECATION_MSG,
253 utils.DeprecatedIn51,
254 name="DSAParametersWithNumbers",
255)
256
257utils.deprecated(
258 DSAPrivateKey,
259 __name__,
260 _DSA_DEPRECATION_MSG,
261 utils.DeprecatedIn51,
262 name="DSAPrivateKey",
263)
264
265utils.deprecated(
266 DSAPrivateKey,
267 __name__,
268 _DSA_DEPRECATION_MSG,
269 utils.DeprecatedIn51,
270 name="DSAPrivateKeyWithSerialization",
271)
272
273utils.deprecated(
274 DSAPublicKey,
275 __name__,
276 _DSA_DEPRECATION_MSG,
277 utils.DeprecatedIn51,
278 name="DSAPublicKey",
279)
280
281utils.deprecated(
282 DSAPublicKey,
283 __name__,
284 _DSA_DEPRECATION_MSG,
285 utils.DeprecatedIn51,
286 name="DSAPublicKeyWithSerialization",
287)