Framework/Listeners/FixControl/WriteFixControlFiles.ps1

Set-StrictMode -Version Latest 
class WriteFixControlFiles: FileOutputBase
{   
    hidden static [WriteFixControlFiles] $Instance = $null;
    hidden static [string] $FixFolderPath = "FixControlScripts";
    hidden static [string] $FixFilePath = (Join-Path "Core" "FixControl" | Join-Path -ChildPath "Services");
    
    hidden static [string] $RunScriptMessage = "# AzSK repair function uses files from the 'Services' sub-folder in this folder";
     hidden static [string] $RunAzureServicesSecurity = '
# Repair Azure resources
Repair-AzSKAzureServicesSecurity `
    -ParameterFilePath "$PSScriptRoot\FixControlConfig.json" #`
    #-ResourceGroupNames "" `
    #-ResourceTypeNames "" `
    #-ResourceNames "" `
    #-ControlIds ""'
;
    hidden static [string] $RunSubscriptionSecurity = '
# Repair Azure subscription
Repair-AzSKSubscriptionSecurity `
    -ParameterFilePath "$PSScriptRoot\FixControlConfig.json" #`
    #-ControlIds ""'
;

    static [WriteFixControlFiles] GetInstance()
    {
        if ( $null -eq [WriteFixControlFiles]::Instance)
        {
            [WriteFixControlFiles]::Instance = [WriteFixControlFiles]::new();
        }
    
        return [WriteFixControlFiles]::Instance
    }

    [void] RegisterEvents()
    {
        $this.UnregisterEvents();       

        $this.RegisterEvent([AzSKRootEvent]::GenerateRunIdentifier, {
            $currentInstance = [WriteFixControlFiles]::GetInstance();
            try 
            {
                $currentInstance.SetRunIdentifier([AzSKRootEventArgument] ($Event.SourceArgs | Select-Object -First 1));            
            }
            catch 
            {
                $currentInstance.PublishException($_);
            }
        });

        $this.RegisterEvent([SVTEvent]::CommandCompleted, {
            $currentInstance = [WriteFixControlFiles]::GetInstance();
            $currentInstance.PushAIEventsfromHandler("WriteFixControlFiles CommandCompleted"); 
            try 
            {
                $currentInstance.CommandCompletedAction($Event.SourceArgs);
                $currentInstance.FilePath = "";
            }
            catch 
            {
                $currentInstance.PublishException($_);
            }
        });
    }

    hidden [SVTEventContext[]] GetFixControlEventContext([SVTEventContext[]] $arguments, [ref]$fixFileNames)
    {
        $resultContext = @();
        $fixFileNames.Value = @();

        $arguments | Where-Object { $_.ControlItem.Enabled -and ($null -ne $_.ControlItem.FixControl) -and $_.ControlResults -and $_.ControlResults.Count -ne 0 } | 
        ForEach-Object {
            $eventContext = $_;

            if(($eventContext.ControlResults | Where-Object { $_.EnableFixControl } | Measure-Object).Count -ne 0)
            {
                $mapping = $null;
                if($eventContext.IsResource())
                {
                    $mapping = ([SVTMapping]::AzSKADOResourceMapping | 
                                Where-Object { $_.ResourceTypeName -eq $eventContext.ResourceContext.ResourceTypeName } | 
                                Select-Object -First 1);
                }
                else
                {
                    Write-Host -ForegroundColor Yellow "Unexpected resource type."
                }
                
                if($mapping -and (-not [string]::IsNullOrWhiteSpace($mapping.FixFileName)) -and (-not [string]::IsNullOrWhiteSpace($mapping.FixClassName)))
                {
                    $resultContext += $eventContext;
                    if($fixFileNames.Value -notcontains $mapping.FixFileName)
                    {
                        $fixFileNames.Value += $mapping.FixFileName;
                    }
                }
            }
        };

        return $resultContext;
    }

    hidden [void] InitializeFolder([SubscriptionContext] $subContext, [string[]] $fixControlFileNames, [string] $runScriptContent)
    {
        $this.SetFolderPath($subContext);
        Copy-Item (Join-Path $PSScriptRoot $([WriteFixControlFiles]::FixFolderPath)) $this.FolderPath -Recurse

        $this.SetFilePath($subContext, [WriteFixControlFiles]::FixFolderPath, "RunFixScript.ps1");
        Add-Content -Value $runScriptContent -Path $this.FilePath

        $this.SetFilePath($subContext, [WriteFixControlFiles]::FixFolderPath, "FixControlConfig.json");
                
        $parentFolderPath = (Get-Item -Path $PSScriptRoot).Parent.Parent.FullName;
        $parentFolderPath = (Join-Path $parentFolderPath $([WriteFixControlFiles]::FixFilePath))
        $fixControlFileNames | ForEach-Object {
            New-Item -ItemType Directory -Path (Join-Path $this.FolderPath "Services") | Out-Null
            Copy-Item (Join-Path $parentFolderPath $_) (Join-Path $this.FolderPath "Services" | Join-Path -ChildPath $_)
        };
    }

    [void] CommandCompletedAction([SVTEventContext[]] $arguments)
    {
        if($arguments -and $arguments.Count -ne 0)
        {
            $fixControlEventContext = @();
            [string[]] $fixControlFileNames = @();

            $fixControlEventContext += $this.GetFixControlEventContext($arguments, [ref]$fixControlFileNames);

            if($fixControlEventContext.Count -ne 0)
            {
                $output = @();
                $hasSubControls = $false;
                $hasResourceControls = $false;

                $fixControlEventContext | Group-Object { $_.SubscriptionContext.SubscriptionId } | 
                ForEach-Object {
                    $sub = $_.Group;
                    $subObject = [FixControlConfig]@{
                        SubscriptionContext = $sub[0].SubscriptionContext;
                    };
                    $output += $subObject;

                    $sub | Where-Object { -not $_.IsResource() } |
                    ForEach-Object {
                        $hasSubControls = $true;
                        $subObject.SubscriptionControls += $this.CreateControlParam($_);
                    };

                    $sub | Where-Object { $_.IsResource() } | Group-Object { $_.ResourceContext.ResourceGroupName } | 
                    ForEach-Object {
                        $rgObject = [ResourceGroupConfig]@{
                            ResourceGroupName = $_.Name;
                        };
                        $hasResourceControls = $true;
                        $subObject.ResourceGroups += $rgObject;
                        $_.Group | Group-Object { $_.ResourceContext.ResourceName } |
                        ForEach-Object {
                            $resource = $_.Group[0];
                            $resObject = [ResourceConfig]@{
                                ResourceName = $resource.ResourceContext.ResourceName;
                                ResourceType = $resource.ResourceContext.ResourceType;
                                ResourceTypeName = $resource.ResourceContext.ResourceTypeName;                                    
                            };

                            $rgObject.Resources += $resObject;

                            $resObject.Controls += $this.CreateControlParam($_.Group);
                        };
                    };
                };

                if($output.Count -ne 0)
                {
                    $runScriptContent = [WriteFixControlFiles]::RunScriptMessage;
                    if($hasSubControls)
                    {
                        $runScriptContent += [WriteFixControlFiles]::RunSubscriptionSecurity;
                    }

                    if($hasResourceControls)
                    {
                        $runScriptContent += [WriteFixControlFiles]::RunAzureServicesSecurity;
                    }

                    $this.InitializeFolder(($fixControlEventContext | Select-Object -First 1).SubscriptionContext, $fixControlFileNames, $runScriptContent);
                    [JsonHelper]::ConvertToJsonCustom($output, 15, 15) | Out-File $this.FilePath
                }                
            }            
        }
    }

    hidden [ControlParam[]] CreateControlParam([SVTEventContext[]] $resources)
    {
        $result = @();
        $resources | Group-Object { $_.ControlItem.Id } |
        ForEach-Object {
            $context = $_.Group[0];
            $controlObject = [ControlParam]@{
                ControlID = $context.ControlItem.ControlID;
                Id = $context.ControlItem.Id;
                ControlSeverity = $context.ControlItem.ControlSeverity;
                FixControlImpact = $context.ControlItem.FixControl.FixControlImpact;
                Description = $context.ControlItem.Description;
                Enabled = $context.ControlItem.Enabled;                        
            };

            $result += $controlObject;

            $_.Group | ForEach-Object {
                $_.ControlResults | Where-Object { $_.EnableFixControl } | ForEach-Object {
                    $controlObject.ChildResourceParams += [ChildResourceParam]@{
                        ChildResourceName = $_.ChildResourceName;
                        Parameters = $_.FixControlParameters;
                    };
                };
            };
        };
        return $result;
    }
}

# SIG # Begin signature block
# MIIjlAYJKoZIhvcNAQcCoIIjhTCCI4ECAQExDzANBglghkgBZQMEAgEFADB5Bgor
# BgEEAYI3AgEEoGswaTA0BgorBgEEAYI3AgEeMCYCAwEAAAQQH8w7YFlLCE63JNLG
# KX7zUQIBAAIBAAIBAAIBAAIBADAxMA0GCWCGSAFlAwQCAQUABCBFikoPzBdasEx7
# X0rg0OizMhY5YCumlJgFESdhWWQInKCCDYEwggX/MIID56ADAgECAhMzAAABh3IX
# chVZQMcJAAAAAAGHMA0GCSqGSIb3DQEBCwUAMH4xCzAJBgNVBAYTAlVTMRMwEQYD
# VQQIEwpXYXNoaW5ndG9uMRAwDgYDVQQHEwdSZWRtb25kMR4wHAYDVQQKExVNaWNy
# b3NvZnQgQ29ycG9yYXRpb24xKDAmBgNVBAMTH01pY3Jvc29mdCBDb2RlIFNpZ25p
# bmcgUENBIDIwMTEwHhcNMjAwMzA0MTgzOTQ3WhcNMjEwMzAzMTgzOTQ3WjB0MQsw
# CQYDVQQGEwJVUzETMBEGA1UECBMKV2FzaGluZ3RvbjEQMA4GA1UEBxMHUmVkbW9u
# ZDEeMBwGA1UEChMVTWljcm9zb2Z0IENvcnBvcmF0aW9uMR4wHAYDVQQDExVNaWNy
# b3NvZnQgQ29ycG9yYXRpb24wggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIB
# AQDOt8kLc7P3T7MKIhouYHewMFmnq8Ayu7FOhZCQabVwBp2VS4WyB2Qe4TQBT8aB
# znANDEPjHKNdPT8Xz5cNali6XHefS8i/WXtF0vSsP8NEv6mBHuA2p1fw2wB/F0dH
# sJ3GfZ5c0sPJjklsiYqPw59xJ54kM91IOgiO2OUzjNAljPibjCWfH7UzQ1TPHc4d
# weils8GEIrbBRb7IWwiObL12jWT4Yh71NQgvJ9Fn6+UhD9x2uk3dLj84vwt1NuFQ
# itKJxIV0fVsRNR3abQVOLqpDugbr0SzNL6o8xzOHL5OXiGGwg6ekiXA1/2XXY7yV
# Fc39tledDtZjSjNbex1zzwSXAgMBAAGjggF+MIIBejAfBgNVHSUEGDAWBgorBgEE
# AYI3TAgBBggrBgEFBQcDAzAdBgNVHQ4EFgQUhov4ZyO96axkJdMjpzu2zVXOJcsw
# UAYDVR0RBEkwR6RFMEMxKTAnBgNVBAsTIE1pY3Jvc29mdCBPcGVyYXRpb25zIFB1
# ZXJ0byBSaWNvMRYwFAYDVQQFEw0yMzAwMTIrNDU4Mzg1MB8GA1UdIwQYMBaAFEhu
# ZOVQBdOCqhc3NyK1bajKdQKVMFQGA1UdHwRNMEswSaBHoEWGQ2h0dHA6Ly93d3cu
# bWljcm9zb2Z0LmNvbS9wa2lvcHMvY3JsL01pY0NvZFNpZ1BDQTIwMTFfMjAxMS0w
# Ny0wOC5jcmwwYQYIKwYBBQUHAQEEVTBTMFEGCCsGAQUFBzAChkVodHRwOi8vd3d3
# Lm1pY3Jvc29mdC5jb20vcGtpb3BzL2NlcnRzL01pY0NvZFNpZ1BDQTIwMTFfMjAx
# MS0wNy0wOC5jcnQwDAYDVR0TAQH/BAIwADANBgkqhkiG9w0BAQsFAAOCAgEAixmy
# S6E6vprWD9KFNIB9G5zyMuIjZAOuUJ1EK/Vlg6Fb3ZHXjjUwATKIcXbFuFC6Wr4K
# NrU4DY/sBVqmab5AC/je3bpUpjtxpEyqUqtPc30wEg/rO9vmKmqKoLPT37svc2NV
# BmGNl+85qO4fV/w7Cx7J0Bbqk19KcRNdjt6eKoTnTPHBHlVHQIHZpMxacbFOAkJr
# qAVkYZdz7ikNXTxV+GRb36tC4ByMNxE2DF7vFdvaiZP0CVZ5ByJ2gAhXMdK9+usx
# zVk913qKde1OAuWdv+rndqkAIm8fUlRnr4saSCg7cIbUwCCf116wUJ7EuJDg0vHe
# yhnCeHnBbyH3RZkHEi2ofmfgnFISJZDdMAeVZGVOh20Jp50XBzqokpPzeZ6zc1/g
# yILNyiVgE+RPkjnUQshd1f1PMgn3tns2Cz7bJiVUaqEO3n9qRFgy5JuLae6UweGf
# AeOo3dgLZxikKzYs3hDMaEtJq8IP71cX7QXe6lnMmXU/Hdfz2p897Zd+kU+vZvKI
# 3cwLfuVQgK2RZ2z+Kc3K3dRPz2rXycK5XCuRZmvGab/WbrZiC7wJQapgBodltMI5
# GMdFrBg9IeF7/rP4EqVQXeKtevTlZXjpuNhhjuR+2DMt/dWufjXpiW91bo3aH6Ea
# jOALXmoxgltCp1K7hrS6gmsvj94cLRf50QQ4U8Qwggd6MIIFYqADAgECAgphDpDS
# AAAAAAADMA0GCSqGSIb3DQEBCwUAMIGIMQswCQYDVQQGEwJVUzETMBEGA1UECBMK
# V2FzaGluZ3RvbjEQMA4GA1UEBxMHUmVkbW9uZDEeMBwGA1UEChMVTWljcm9zb2Z0
# IENvcnBvcmF0aW9uMTIwMAYDVQQDEylNaWNyb3NvZnQgUm9vdCBDZXJ0aWZpY2F0
# ZSBBdXRob3JpdHkgMjAxMTAeFw0xMTA3MDgyMDU5MDlaFw0yNjA3MDgyMTA5MDla
# MH4xCzAJBgNVBAYTAlVTMRMwEQYDVQQIEwpXYXNoaW5ndG9uMRAwDgYDVQQHEwdS
# ZWRtb25kMR4wHAYDVQQKExVNaWNyb3NvZnQgQ29ycG9yYXRpb24xKDAmBgNVBAMT
# H01pY3Jvc29mdCBDb2RlIFNpZ25pbmcgUENBIDIwMTEwggIiMA0GCSqGSIb3DQEB
# AQUAA4ICDwAwggIKAoICAQCr8PpyEBwurdhuqoIQTTS68rZYIZ9CGypr6VpQqrgG
# OBoESbp/wwwe3TdrxhLYC/A4wpkGsMg51QEUMULTiQ15ZId+lGAkbK+eSZzpaF7S
# 35tTsgosw6/ZqSuuegmv15ZZymAaBelmdugyUiYSL+erCFDPs0S3XdjELgN1q2jz
# y23zOlyhFvRGuuA4ZKxuZDV4pqBjDy3TQJP4494HDdVceaVJKecNvqATd76UPe/7
# 4ytaEB9NViiienLgEjq3SV7Y7e1DkYPZe7J7hhvZPrGMXeiJT4Qa8qEvWeSQOy2u
# M1jFtz7+MtOzAz2xsq+SOH7SnYAs9U5WkSE1JcM5bmR/U7qcD60ZI4TL9LoDho33
# X/DQUr+MlIe8wCF0JV8YKLbMJyg4JZg5SjbPfLGSrhwjp6lm7GEfauEoSZ1fiOIl
# XdMhSz5SxLVXPyQD8NF6Wy/VI+NwXQ9RRnez+ADhvKwCgl/bwBWzvRvUVUvnOaEP
# 6SNJvBi4RHxF5MHDcnrgcuck379GmcXvwhxX24ON7E1JMKerjt/sW5+v/N2wZuLB
# l4F77dbtS+dJKacTKKanfWeA5opieF+yL4TXV5xcv3coKPHtbcMojyyPQDdPweGF
# RInECUzF1KVDL3SV9274eCBYLBNdYJWaPk8zhNqwiBfenk70lrC8RqBsmNLg1oiM
# CwIDAQABo4IB7TCCAekwEAYJKwYBBAGCNxUBBAMCAQAwHQYDVR0OBBYEFEhuZOVQ
# BdOCqhc3NyK1bajKdQKVMBkGCSsGAQQBgjcUAgQMHgoAUwB1AGIAQwBBMAsGA1Ud
# DwQEAwIBhjAPBgNVHRMBAf8EBTADAQH/MB8GA1UdIwQYMBaAFHItOgIxkEO5FAVO
# 4eqnxzHRI4k0MFoGA1UdHwRTMFEwT6BNoEuGSWh0dHA6Ly9jcmwubWljcm9zb2Z0
# LmNvbS9wa2kvY3JsL3Byb2R1Y3RzL01pY1Jvb0NlckF1dDIwMTFfMjAxMV8wM18y
# Mi5jcmwwXgYIKwYBBQUHAQEEUjBQME4GCCsGAQUFBzAChkJodHRwOi8vd3d3Lm1p
# Y3Jvc29mdC5jb20vcGtpL2NlcnRzL01pY1Jvb0NlckF1dDIwMTFfMjAxMV8wM18y
# Mi5jcnQwgZ8GA1UdIASBlzCBlDCBkQYJKwYBBAGCNy4DMIGDMD8GCCsGAQUFBwIB
# FjNodHRwOi8vd3d3Lm1pY3Jvc29mdC5jb20vcGtpb3BzL2RvY3MvcHJpbWFyeWNw
# cy5odG0wQAYIKwYBBQUHAgIwNB4yIB0ATABlAGcAYQBsAF8AcABvAGwAaQBjAHkA
# XwBzAHQAYQB0AGUAbQBlAG4AdAAuIB0wDQYJKoZIhvcNAQELBQADggIBAGfyhqWY
# 4FR5Gi7T2HRnIpsLlhHhY5KZQpZ90nkMkMFlXy4sPvjDctFtg/6+P+gKyju/R6mj
# 82nbY78iNaWXXWWEkH2LRlBV2AySfNIaSxzzPEKLUtCw/WvjPgcuKZvmPRul1LUd
# d5Q54ulkyUQ9eHoj8xN9ppB0g430yyYCRirCihC7pKkFDJvtaPpoLpWgKj8qa1hJ
# Yx8JaW5amJbkg/TAj/NGK978O9C9Ne9uJa7lryft0N3zDq+ZKJeYTQ49C/IIidYf
# wzIY4vDFLc5bnrRJOQrGCsLGra7lstnbFYhRRVg4MnEnGn+x9Cf43iw6IGmYslmJ
# aG5vp7d0w0AFBqYBKig+gj8TTWYLwLNN9eGPfxxvFX1Fp3blQCplo8NdUmKGwx1j
# NpeG39rz+PIWoZon4c2ll9DuXWNB41sHnIc+BncG0QaxdR8UvmFhtfDcxhsEvt9B
# xw4o7t5lL+yX9qFcltgA1qFGvVnzl6UJS0gQmYAf0AApxbGbpT9Fdx41xtKiop96
# eiL6SJUfq/tHI4D1nvi/a7dLl+LrdXga7Oo3mXkYS//WsyNodeav+vyL6wuA6mk7
# r/ww7QRMjt/fdW1jkT3RnVZOT7+AVyKheBEyIXrvQQqxP/uozKRdwaGIm1dxVk5I
# RcBCyZt2WwqASGv9eZ/BvW1taslScxMNelDNMYIVaTCCFWUCAQEwgZUwfjELMAkG
# A1UEBhMCVVMxEzARBgNVBAgTCldhc2hpbmd0b24xEDAOBgNVBAcTB1JlZG1vbmQx
# HjAcBgNVBAoTFU1pY3Jvc29mdCBDb3Jwb3JhdGlvbjEoMCYGA1UEAxMfTWljcm9z
# b2Z0IENvZGUgU2lnbmluZyBQQ0EgMjAxMQITMwAAAYdyF3IVWUDHCQAAAAABhzAN
# BglghkgBZQMEAgEFAKCBsDAZBgkqhkiG9w0BCQMxDAYKKwYBBAGCNwIBBDAcBgor
# BgEEAYI3AgELMQ4wDAYKKwYBBAGCNwIBFTAvBgkqhkiG9w0BCQQxIgQg547ey3Kt
# iRZViwceKarcQiWREEfE8le6G6UEm8My0XcwRAYKKwYBBAGCNwIBDDE2MDSgFIAS
# AE0AaQBjAHIAbwBzAG8AZgB0oRyAGmh0dHBzOi8vd3d3Lm1pY3Jvc29mdC5jb20g
# MA0GCSqGSIb3DQEBAQUABIIBAGe98qgNO2ehRHQyHQa6YAK3ojTGKGyJresYBVvA
# qHNpuMJEYYoEXdpumh5Tc47ixSPQr5uxHvn/bNt4fTNa3K10/jBb/j5PirOMYiqf
# kedjJFkbxYsnpRrYQtBNG2eKDl8452rGLc+lzWaqzLVXAaNi/oggc2EnA75mGCKb
# pd8Kr40cQhM3Oq53d5d+H8EDNAiyS8jhn4eKHwZC5M7F0TQ5cbz0EELmdHt7B0Ir
# hEiHzsNBxmPZCGpYYBiElOlV03EVXxbvAqJljcOra4mCJiLwBzbGUOjGUzqEO8MX
# eygHW9UCAfcUQ76vAjoIpS1remwTQjcGE26o87ZEvoqsCQmhghLxMIIS7QYKKwYB
# BAGCNwMDATGCEt0wghLZBgkqhkiG9w0BBwKgghLKMIISxgIBAzEPMA0GCWCGSAFl
# AwQCAQUAMIIBVQYLKoZIhvcNAQkQAQSgggFEBIIBQDCCATwCAQEGCisGAQQBhFkK
# AwEwMTANBglghkgBZQMEAgEFAAQgLaZKfkNBPVXb9bnvrtCJ8bWHRiT449gmUPH7
# fatNrsECBl/bmWJ0JBgTMjAyMTAxMTUxMzQzNTIuMzcyWjAEgAIB9KCB1KSB0TCB
# zjELMAkGA1UEBhMCVVMxEzARBgNVBAgTCldhc2hpbmd0b24xEDAOBgNVBAcTB1Jl
# ZG1vbmQxHjAcBgNVBAoTFU1pY3Jvc29mdCBDb3Jwb3JhdGlvbjEpMCcGA1UECxMg
# TWljcm9zb2Z0IE9wZXJhdGlvbnMgUHVlcnRvIFJpY28xJjAkBgNVBAsTHVRoYWxl
# cyBUU1MgRVNOOjMyQkQtRTNENS0zQjFEMSUwIwYDVQQDExxNaWNyb3NvZnQgVGlt
# ZS1TdGFtcCBTZXJ2aWNloIIORDCCBPUwggPdoAMCAQICEzMAAAEuqNIZB5P0a+gA
# AAAAAS4wDQYJKoZIhvcNAQELBQAwfDELMAkGA1UEBhMCVVMxEzARBgNVBAgTCldh
# c2hpbmd0b24xEDAOBgNVBAcTB1JlZG1vbmQxHjAcBgNVBAoTFU1pY3Jvc29mdCBD
# b3Jwb3JhdGlvbjEmMCQGA1UEAxMdTWljcm9zb2Z0IFRpbWUtU3RhbXAgUENBIDIw
# MTAwHhcNMTkxMjE5MDExNTA1WhcNMjEwMzE3MDExNTA1WjCBzjELMAkGA1UEBhMC
# VVMxEzARBgNVBAgTCldhc2hpbmd0b24xEDAOBgNVBAcTB1JlZG1vbmQxHjAcBgNV
# BAoTFU1pY3Jvc29mdCBDb3Jwb3JhdGlvbjEpMCcGA1UECxMgTWljcm9zb2Z0IE9w
# ZXJhdGlvbnMgUHVlcnRvIFJpY28xJjAkBgNVBAsTHVRoYWxlcyBUU1MgRVNOOjMy
# QkQtRTNENS0zQjFEMSUwIwYDVQQDExxNaWNyb3NvZnQgVGltZS1TdGFtcCBTZXJ2
# aWNlMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEArtNMolFTX3osUiMx
# D2r9SOk+HPjeblGceAcBWnZgaeLvj6W2xig7WdnnytNsmEJDwZgfLwHh16+Buqpg
# 9A1TeL52ukS0Rw0tuwyvgwSrdIz687drpAwV3WUNHLshAs8k0sq9wzr023uS7VjI
# zk2c80NxEmydRv/xjH/NxblxaOeiPyz19D3cE9/8nviozWqXYJ3NBXvg8GKww/+2
# mkCdK43Cjwjv65avq9+kHKdJYO8l4wOtyxrrZeybsNsHU2dKw8YAa3dHOUFX0pWJ
# yLN7hTd+jhyF2gHb5Au7Xs9oSaPTuqrvTQIblcmSkRg6N500WIHICkXthG9Cs5lD
# TtBiIwIDAQABo4IBGzCCARcwHQYDVR0OBBYEFIaaiSZOC4k3u6pJNDVSEvC3VE5s
# MB8GA1UdIwQYMBaAFNVjOlyKMZDzQ3t8RhvFM2hahW1VMFYGA1UdHwRPME0wS6BJ
# oEeGRWh0dHA6Ly9jcmwubWljcm9zb2Z0LmNvbS9wa2kvY3JsL3Byb2R1Y3RzL01p
# Y1RpbVN0YVBDQV8yMDEwLTA3LTAxLmNybDBaBggrBgEFBQcBAQROMEwwSgYIKwYB
# BQUHMAKGPmh0dHA6Ly93d3cubWljcm9zb2Z0LmNvbS9wa2kvY2VydHMvTWljVGlt
# U3RhUENBXzIwMTAtMDctMDEuY3J0MAwGA1UdEwEB/wQCMAAwEwYDVR0lBAwwCgYI
# KwYBBQUHAwgwDQYJKoZIhvcNAQELBQADggEBAI3gBGqnMK6602pjadYkMNePfmJq
# J2WC0n9uyliwBfxq0mXX0h9QojNO65JVTdxpdnr9i8wxgxxuw1r/gnby6zbcro9Z
# kCWMiPQbxC3AMyVAeOsqetyvgUEDPpmq8HpKs3f9ZtvRBIr86XGxTSZ8PvPztHYk
# ziDAom8foQgu4AS2PBQZIHU0qbdPCubnV8IPSPG9bHNpRLZ628w+uHwM2uscskFH
# dQe+D81dLYjN1CfbTGOOxbQFQCJN/40JGnFS+7+PzQ1vX76+d6OJt+lAnYiVeIl0
# iL4dv44vdc6vwxoMNJg5pEUAh9yirdU+LgGS9ILxAau+GMBlp+QTtHovkUkwggZx
# MIIEWaADAgECAgphCYEqAAAAAAACMA0GCSqGSIb3DQEBCwUAMIGIMQswCQYDVQQG
# EwJVUzETMBEGA1UECBMKV2FzaGluZ3RvbjEQMA4GA1UEBxMHUmVkbW9uZDEeMBwG
# A1UEChMVTWljcm9zb2Z0IENvcnBvcmF0aW9uMTIwMAYDVQQDEylNaWNyb3NvZnQg
# Um9vdCBDZXJ0aWZpY2F0ZSBBdXRob3JpdHkgMjAxMDAeFw0xMDA3MDEyMTM2NTVa
# Fw0yNTA3MDEyMTQ2NTVaMHwxCzAJBgNVBAYTAlVTMRMwEQYDVQQIEwpXYXNoaW5n
# dG9uMRAwDgYDVQQHEwdSZWRtb25kMR4wHAYDVQQKExVNaWNyb3NvZnQgQ29ycG9y
# YXRpb24xJjAkBgNVBAMTHU1pY3Jvc29mdCBUaW1lLVN0YW1wIFBDQSAyMDEwMIIB
# IjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAqR0NvHcRijog7PwTl/X6f2mU
# a3RUENWlCgCChfvtfGhLLF/Fw+Vhwna3PmYrW/AVUycEMR9BGxqVHc4JE458YTBZ
# sTBED/FgiIRUQwzXTbg4CLNC3ZOs1nMwVyaCo0UN0Or1R4HNvyRgMlhgRvJYR4Yy
# hB50YWeRX4FUsc+TTJLBxKZd0WETbijGGvmGgLvfYfxGwScdJGcSchohiq9LZIlQ
# YrFd/XcfPfBXday9ikJNQFHRD5wGPmd/9WbAA5ZEfu/QS/1u5ZrKsajyeioKMfDa
# TgaRtogINeh4HLDpmc085y9Euqf03GS9pAHBIAmTeM38vMDJRF1eFpwBBU8iTQID
# AQABo4IB5jCCAeIwEAYJKwYBBAGCNxUBBAMCAQAwHQYDVR0OBBYEFNVjOlyKMZDz
# Q3t8RhvFM2hahW1VMBkGCSsGAQQBgjcUAgQMHgoAUwB1AGIAQwBBMAsGA1UdDwQE
# AwIBhjAPBgNVHRMBAf8EBTADAQH/MB8GA1UdIwQYMBaAFNX2VsuP6KJcYmjRPZSQ
# W9fOmhjEMFYGA1UdHwRPME0wS6BJoEeGRWh0dHA6Ly9jcmwubWljcm9zb2Z0LmNv
# bS9wa2kvY3JsL3Byb2R1Y3RzL01pY1Jvb0NlckF1dF8yMDEwLTA2LTIzLmNybDBa
# BggrBgEFBQcBAQROMEwwSgYIKwYBBQUHMAKGPmh0dHA6Ly93d3cubWljcm9zb2Z0
# LmNvbS9wa2kvY2VydHMvTWljUm9vQ2VyQXV0XzIwMTAtMDYtMjMuY3J0MIGgBgNV
# HSABAf8EgZUwgZIwgY8GCSsGAQQBgjcuAzCBgTA9BggrBgEFBQcCARYxaHR0cDov
# L3d3dy5taWNyb3NvZnQuY29tL1BLSS9kb2NzL0NQUy9kZWZhdWx0Lmh0bTBABggr
# BgEFBQcCAjA0HjIgHQBMAGUAZwBhAGwAXwBQAG8AbABpAGMAeQBfAFMAdABhAHQA
# ZQBtAGUAbgB0AC4gHTANBgkqhkiG9w0BAQsFAAOCAgEAB+aIUQ3ixuCYP4FxAz2d
# o6Ehb7Prpsz1Mb7PBeKp/vpXbRkws8LFZslq3/Xn8Hi9x6ieJeP5vO1rVFcIK1GC
# RBL7uVOMzPRgEop2zEBAQZvcXBf/XPleFzWYJFZLdO9CEMivv3/Gf/I3fVo/HPKZ
# eUqRUgCvOA8X9S95gWXZqbVr5MfO9sp6AG9LMEQkIjzP7QOllo9ZKby2/QThcJ8y
# Sif9Va8v/rbljjO7Yl+a21dA6fHOmWaQjP9qYn/dxUoLkSbiOewZSnFjnXshbcOc
# o6I8+n99lmqQeKZt0uGc+R38ONiU9MalCpaGpL2eGq4EQoO4tYCbIjggtSXlZOz3
# 9L9+Y1klD3ouOVd2onGqBooPiRa6YacRy5rYDkeagMXQzafQ732D8OE7cQnfXXSY
# Ighh2rBQHm+98eEA3+cxB6STOvdlR3jo+KhIq/fecn5ha293qYHLpwmsObvsxsvY
# grRyzR30uIUBHoD7G4kqVDmyW9rIDVWZeodzOwjmmC3qjeAzLhIp9cAvVCch98is
# TtoouLGp25ayp0Kiyc8ZQU3ghvkqmqMRZjDTu3QyS99je/WZii8bxyGvWbWu3EQ8
# l1Bx16HSxVXjad5XwdHeMMD9zOZN+w2/XU/pnR4ZOC+8z1gFLu8NoFA12u8JJxzV
# s341Hgi62jbb01+P3nSISRKhggLSMIICOwIBATCB/KGB1KSB0TCBzjELMAkGA1UE
# BhMCVVMxEzARBgNVBAgTCldhc2hpbmd0b24xEDAOBgNVBAcTB1JlZG1vbmQxHjAc
# BgNVBAoTFU1pY3Jvc29mdCBDb3Jwb3JhdGlvbjEpMCcGA1UECxMgTWljcm9zb2Z0
# IE9wZXJhdGlvbnMgUHVlcnRvIFJpY28xJjAkBgNVBAsTHVRoYWxlcyBUU1MgRVNO
# OjMyQkQtRTNENS0zQjFEMSUwIwYDVQQDExxNaWNyb3NvZnQgVGltZS1TdGFtcCBT
# ZXJ2aWNloiMKAQEwBwYFKw4DAhoDFQD7X8I3oEgt5TXIMaj5vpaSkuhCm6CBgzCB
# gKR+MHwxCzAJBgNVBAYTAlVTMRMwEQYDVQQIEwpXYXNoaW5ndG9uMRAwDgYDVQQH
# EwdSZWRtb25kMR4wHAYDVQQKExVNaWNyb3NvZnQgQ29ycG9yYXRpb24xJjAkBgNV
# BAMTHU1pY3Jvc29mdCBUaW1lLVN0YW1wIFBDQSAyMDEwMA0GCSqGSIb3DQEBBQUA
# AgUA46uprzAiGA8yMDIxMDExNTA5NDIwN1oYDzIwMjEwMTE2MDk0MjA3WjB3MD0G
# CisGAQQBhFkKBAExLzAtMAoCBQDjq6mvAgEAMAoCAQACAiY0AgH/MAcCAQACAhGV
# MAoCBQDjrPsvAgEAMDYGCisGAQQBhFkKBAIxKDAmMAwGCisGAQQBhFkKAwKgCjAI
# AgEAAgMHoSChCjAIAgEAAgMBhqAwDQYJKoZIhvcNAQEFBQADgYEAFlqsdQvouxCm
# VCAK4nHyyWKZHJ3In7RdnR7kxSSzgFGxZT+tyaQe5pOvcWJLsQIKLceFoEitM7jr
# q1CpE5cud+zIui5klYYTEoeHa9iSMXh6hP78E/SJP0IjgJkrzumOgZUy2cbNxyQp
# 7OkGetHlLspTgI7UDorH241r4XCqAr8xggMNMIIDCQIBATCBkzB8MQswCQYDVQQG
# EwJVUzETMBEGA1UECBMKV2FzaGluZ3RvbjEQMA4GA1UEBxMHUmVkbW9uZDEeMBwG
# A1UEChMVTWljcm9zb2Z0IENvcnBvcmF0aW9uMSYwJAYDVQQDEx1NaWNyb3NvZnQg
# VGltZS1TdGFtcCBQQ0EgMjAxMAITMwAAAS6o0hkHk/Rr6AAAAAABLjANBglghkgB
# ZQMEAgEFAKCCAUowGgYJKoZIhvcNAQkDMQ0GCyqGSIb3DQEJEAEEMC8GCSqGSIb3
# DQEJBDEiBCDFsa/Wwa6sdYbyxGiqTwiqqdMCfcaM53PIklYPP5yJJjCB+gYLKoZI
# hvcNAQkQAi8xgeowgecwgeQwgb0EINr+zc7xiFaKqlU3SRN4r7HabRECHXsmlHoO
# IWhMgskpMIGYMIGApH4wfDELMAkGA1UEBhMCVVMxEzARBgNVBAgTCldhc2hpbmd0
# b24xEDAOBgNVBAcTB1JlZG1vbmQxHjAcBgNVBAoTFU1pY3Jvc29mdCBDb3Jwb3Jh
# dGlvbjEmMCQGA1UEAxMdTWljcm9zb2Z0IFRpbWUtU3RhbXAgUENBIDIwMTACEzMA
# AAEuqNIZB5P0a+gAAAAAAS4wIgQgIKxZCt/5epbKbGmYvL0HOD8SC6QJLLz6Ah0F
# ennTFDYwDQYJKoZIhvcNAQELBQAEggEAI9lcPxbH440Q1V4GqZbIiT/ePJCHBeUi
# +dcoWr8KVAIxJIfKVoyb4G8aAHthrDJ+Q2fDyCjDbT2VU0eps4f72WQtHY54VCu+
# cRlWVGfum7Wyqa7PJCZrmPwWbqUVcXdFIQ6liblAQXFNpkSdw4hD+8iB8bIge4XD
# MUIQTENfZmmdXEA4rHLOYQrQ1kSyObSlD5DVoJ9Lnv1dKKmDBH511689mEN57/BV
# bhphYOLCRbQh+dgmNRHhOhTLf0N6dH6Pszu0eO8OltJptfCdOZX8Xk3Rfyw6QpOn
# oyvSthghpkVz523zXSaAfqcAk2Q9D5PJAhwxTHF+Cv7dKqXx7Ad3Lw==
# SIG # End signature block