classes/OSConfig.ps1
|
# Copyright (c) Microsoft Corporation. All rights reserved. function Get-ServerType() { try { $Value = Get-ItemPropertyValue -LiteralPath "HKLM:\SYSTEM\CurrentControlSet\Services\Netlogon\Parameters" -Name "SysvolReady" if (-not [String]::IsNullOrWhiteSpace($Value)) { return "Domain Controller" } } catch { # Ignored. } try { $Value = Get-ItemPropertyValue -LiteralPath "HKLM:\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters" -Name "Domain" if (-not [String]::IsNullOrWhiteSpace($Value)) { return "Member Server" } } catch { # Ignored. } return "Workgroup Member" } function Get-EnvironmentType { $Properties = Get-ItemProperty -Path "HKLM:\SOFTWARE\Microsoft\Windows NT\CurrentVersion" if ($Properties.InstallationType -match "Server") { if ($Properties.EditionId -eq "ServerAzureStackHCICor") { $InstallationType = "AzureLocal" if ($Properties.DisplayVersion -eq "24H2") { $Version = "24H2" } elseif ($Properties.DisplayVersion -eq "23H2") { $Version = "23H2" } else { return } } else { $InstallationType = "WindowsServer" # We need to have the necessary update for Windows Server 2022 and Windows Server 23H2 # but not for Windows Server 2025. We can use the UBR (Update Build Revision) to # determine the version. if ($Properties.DisplayVersion -eq "24H2") { $Version = "2025" } elseif (($Properties.DisplayVersion -eq "23H2") -and ($Properties.UBR -ge 1369)) { $Version = "2022" } elseif (($Properties.DisplayVersion -eq "21H2") -and ($Properties.UBR -ge 3091)) { $Version = "2022" } else { return } } } else { return } $Role = (Get-ServerType) -replace " ", "" "$InstallationType\$Version\$Role" } function ConvertFrom-Expression($Expression) { if ($Expression -isnot [String] -or [String]::IsNullOrWhiteSpace($Expression)) { throw [InvalidValueException]::new($Strings.ErrorInvalidExpression -f $Expression) } # JSON object format if ($Expression.TrimStart().StartsWith('{')) { $JsonObj = ConvertFrom-Json -InputObject $Expression -ErrorAction SilentlyContinue if ($null -ne $JsonObj) { $Result = @() foreach ($Property in $JsonObj.PSObject.Properties) { $Result += [PSCustomObject]@{ Name = $Property.Name; Value = $Property.Value } } if ($Result.Count -gt 0) { return , $Result } } } # Semicolon-delimited format $InQuotes = $False $ProcessedExpression = $Expression.Clone() for ($i = 0; $i -lt $Expression.Length; $i++) { if ($Expression[$i] -eq '"') { $InQuotes = -not $InQuotes continue } if ($InQuotes) { continue } if ($Expression[$i] -eq ";") { $ProcessedExpression = $ProcessedExpression.Remove($i, 1).Insert($i, "`n") } } try { $Result = @($ProcessedExpression | ConvertFrom-Csv -Header @("Name", "Value") -Delimiter ":") if (($Result.Count -eq 1) -and (-not $Result.Value)) { $Result[0].Value = $Result[0].Name $Result[0].Name = "*" } , $Result } catch { throw [InvalidValueException]::new($Strings.ErrorInvalidExpression -f $Expression) } } function Find-Rule($Name, $Rules) { # First pass: exact or wildcard match foreach ($Rule in $Rules) { $InclusionRule = -not $Rule.Name.StartsWith("!") $RuleName = if ($InclusionRule) { $Rule.Name } else { $Rule.Name.Substring(1) } if ($Name -like $RuleName) { return $(if ($InclusionRule) { $Rule } else { $null }) } } # Second pass: segment-boundary suffix match foreach ($Rule in $Rules) { $InclusionRule = -not $Rule.Name.StartsWith("!") $RuleName = if ($InclusionRule) { $Rule.Name } else { $Rule.Name.Substring(1) } if ($Name -like "*\$RuleName") { return $(if ($InclusionRule) { $Rule } else { $null }) } } } class OSConfigReason { [DscProperty()] [String] $Code [DscProperty()] [String] $Phrase OSConfigReason() { } OSConfigReason([String] $RuleId, [String] $Severity, [Bool] $IsCompliant, [String] $Reason) { $Status = if ($IsCompliant) { 'BaselineSettingCompliant' } else { 'BaselineSettingNotCompliant' } if ($RuleId) { $Status = "$Status`:$RuleId" } $this.Code = $Status if (-not [String]::IsNullOrWhiteSpace($Severity)) { $this.Phrase = "[$Severity] $Reason" } else { $this.Phrase = $Reason } } } [DscResource()] class OSConfig { [DscProperty()] [String] $RuleId [DscProperty()] [String] $Severity [DscProperty()] [String] $CorrelationGroup [DscProperty(Key)] [String] $Name [DscProperty(Key)] [String] $Type [DscProperty(Key)] [String] $Properties [DscProperty()] [String] $Value [DscProperty()] [String] $ValueType [DscProperty()] [String] $ValueName = 'value' [DscProperty()] [String] $Schema [DscProperty()] [Bool] $ExtendSchema [DscProperty()] [String] $Expression [DscProperty()] [String] $Template [DscProperty()] [Bool] $IsJsonValue = $False [DscProperty()] [String] $RoleFilter [DscProperty()] [String] $VersionFilter [DscProperty(NotConfigurable)] [OSConfigReason[]] $Reasons hidden [Bool] $IsCompliant = $True [OSConfig] Get() { $CurrentState = [OSConfig]::new() $CurrentState.RuleId = $this.RuleId $CurrentState.Severity = $this.Severity $CurrentState.Name = $this.Name $CurrentState.Type = $this.Type $CurrentState.Properties = $this.Properties $CurrentState.Value = $this.Value $CurrentState.Schema = $this.Schema $CurrentState.ExtendSchema = $this.ExtendSchema $CurrentState.ValueType = $this.ValueType $CurrentState.IsJsonValue = $this.IsJsonValue $CurrentState.RoleFilter = $this.RoleFilter $CurrentState.VersionFilter = $this.VersionFilter $CurrentState.Reasons = @() $env:OSCONFIG_LOG_DIR = "$PSScriptRoot\logs" $env:DMOSCONFIG_AUTHORITY = $Script:Constants.Authority.Cloud try { $ErrorActionPreference = 'Stop' if (-not $this.IsApplicable()) { $CurrentState.IsCompliant = $True $CurrentState.Reasons += [OSConfigReason]::new($this.RuleId, $null, $CurrentState.IsCompliant, 'Not applicable') return $CurrentState } $ActualValue = $this.GetActualValue() $ResourceProperties = @{ 'resource' = @{ 'name' = $this.Name 'type' = $this.Type 'properties' = $this.Properties | ConvertFrom-Json } 'template' = $this.GetTemplate($ActualValue) } $ResourceSchema = $this.GetSchema($ActualValue) $ResourceExpression = $this.Expression if ($ResourceExpression) { $ResourceProperties['expression'] = $ResourceExpression } elseif ($ResourceSchema) { $ResourceProperties['schema'] = $ResourceSchema } $Resource = @{ Name = $this.Name Type = 'Microsoft.OSConfig/Test' Properties = $ResourceProperties } $Output = Invoke-Native exec resource --correlation-id $(Get-CorrelationId) --correlation-group $this.CorrelationGroup --mode get --name $Resource.Name --type $Resource.Type --properties (ConvertTo-Json -InputObject $Resource.Properties -Compress -Depth 32) $CurrentState.IsCompliant = $Output.Properties.Compliance.Status -eq 'compliant' $CurrentState.Reasons += [OSConfigReason]::new($this.RuleId, $CurrentState.Severity, $CurrentState.IsCompliant, $Output.Properties.Compliance.Reason) } catch { $CurrentState.IsCompliant = $False $CurrentState.Reasons += [OSConfigReason]::new($this.RuleId, $CurrentState.Severity, $CurrentState.IsCompliant, "$_") Write-Verbose "Error: $_" } return $CurrentState } [Bool] Test() { try { return $this.Get().IsCompliant } catch { Write-Verbose "Error: $_" } return $False } [Void] Set() { try { $env:OSCONFIG_LOG_DIR = "$PSScriptRoot\logs" $env:DMOSCONFIG_AUTHORITY = $Script:Constants.Authority.Cloud if (-not $this.CorrelationGroup) { throw "No correlation group specified." } $ResourceProperties = $this.Properties | ConvertFrom-Json if ($this.ValueName) { $ResourceProperties | Add-Member -MemberType NoteProperty -Name $this.ValueName -Value $this.GetActualValue() } Invoke-Native exec resource --correlation-id $(Get-CorrelationId) --correlation-group $this.CorrelationGroup --mode set --name $this.Name --type $this.type --properties (ConvertTo-Json -InputObject $ResourceProperties -Compress -Depth 32) } catch { Write-Verbose "Error: $_" } } [Bool] IsApplicable() { if (-not [String]::IsNullOrWhiteSpace($this.RoleFilter)) { $CurrentRole = Get-ServerType $AllowedRoles = $this.RoleFilter -split ',' | ForEach-Object { $_.Trim() } if ($AllowedRoles -notcontains $CurrentRole) { return $False } } if (-not [String]::IsNullOrWhiteSpace($this.VersionFilter)) { $CurrentVersion = Get-WindowsServerVersion if (-not $CurrentVersion) { return $False } $AllowedVersions = $this.VersionFilter -split ',' | ForEach-Object { $_.Trim() } if ($AllowedVersions -notcontains $CurrentVersion) { return $False } } if ($this.IsJsonValue -and -not [String]::IsNullOrWhiteSpace($this.Value)) { $JsonObj = ConvertFrom-Json -InputObject $this.Value -ErrorAction SilentlyContinue if ($null -eq $JsonObj) { return $False } $JsonRules = @($JsonObj.PSObject.Properties | ForEach-Object { [PSCustomObject]@{ Name = $_.Name; Value = $_.Value } }) if ($JsonRules.Count -eq 0) { return $False } $Role = (Get-ServerType) -replace " ", "" if ($null -eq (Find-Rule -Name $Role -Rules $JsonRules)) { return $False } } # If there is no schema or expression, there must be a value to generate the compliance reasoning. # Omitting the schema and expression will provide a default compliance reasoning based on the value. if (-not $this.Schema -and -not $this.Expression -and -not $this.Value) { if ($this.ValueType -ne 'string[]') { throw "No value, schema, or expression specified to evaluate compliance." } } return $True } [PSCustomObject] GetDefaultSchema([PSCustomObject] $ActualValue) { if ($null -eq $ActualValue) { return @{ 'type' = 'null' } } switch ($this.ValueType) { 'string' { return @{ 'type' = 'string'; 'const' = $ActualValue } } 'string[]' { $ArraySchema = @{ 'type' = 'array' 'items' = @{ 'type' = 'string' 'enum' = $ActualValue } 'minItems' = $ActualValue.Count 'maxItems' = $ActualValue.Count 'uniqueItems' = $True } if ($ActualValue.Count -eq 0) { return @{ 'anyOf' = @( @{ 'type' = 'null' }, $ArraySchema ) } } return $ArraySchema } 'integer' { return @{ 'type' = 'integer'; 'const' = $ActualValue } } 'boolean' { return @{ 'type' = 'boolean'; 'const' = $ActualValue } } } return @{ 'const' = $ActualValue } } [PSCustomObject] GetSchema([PSCustomObject] $ActualValue) { $DefaultSchema = $this.GetDefaultSchema($ActualValue) $CustomSchema = if ($this.Schema) { ConvertFrom-Json -InputObject $this.Schema } if ($this.ExtendSchema -and $CustomSchema) { return @{ 'allOf' = @( $DefaultSchema, $CustomSchema ) } } elseif ($CustomSchema) { return $CustomSchema } else { return $DefaultSchema } } [String] GetTemplate([PSCustomObject] $ActualValue) { if ($this.Template) { return $this.Template } if ($null -eq $ActualValue) { return "The value {value} must be (null)" } return "The value {value} must be $(ConvertTo-Json -InputObject $ActualValue -Compress)." } [PSCustomObject] GetActualValue() { $Rules = if (-not [String]::IsNullOrWhiteSpace($this.Value)) { ConvertFrom-Expression -Expression $this.Value } if ($this.IsJsonValue) { $Role = (Get-ServerType) -replace " ", "" $Rule = Find-Rule -Name $Role -Rules $Rules } else { $EnvironmentType = Get-EnvironmentType $Rule = Find-Rule -Name $EnvironmentType -Rules $Rules } $StringValue = if ($null -ne $Rule) { $Rule.Value } elseif ($this.Value -or ($this.ValueType -eq 'string[]')) { $this.Value } else { (ConvertFrom-Json -InputObject $this.Properties).$($this.ValueName) } if ($null -eq $StringValue) { return $null } try { switch ($this.ValueType) { 'string' { return $StringValue } 'integer' { return [Int64]::Parse($StringValue) } 'boolean' { if ([Int32]::TryParse($StringValue, [ref]$null)) { return [Boolean]::Parse(([Int32]$StringValue -ne 0).ToString()) } else { return [Boolean]::Parse($StringValue) } } 'string[]' { if ([String]::IsNullOrWhiteSpace($StringValue)) { return @() } else { return @($StringValue -split ',' | ForEach-Object { $_.Trim() }) } } } } catch { throw "Unable to convert value '$StringValue' to type '$($this.ValueType)'" } return $StringValue } } # SIG # Begin signature block # MIInbgYJKoZIhvcNAQcCoIInXzCCJ1sCAQExDzANBglghkgBZQMEAgEFADB5Bgor # BgEEAYI3AgEEoGswaTA0BgorBgEEAYI3AgEeMCYCAwEAAAQQH8w7YFlLCE63JNLG # KX7zUQIBAAIBAAIBAAIBAAIBADAxMA0GCWCGSAFlAwQCAQUABCBZJyw3SqxWqEq5 # fZn0fZqx/xiWdIPxJRMPeUOgOqWXD6CCDMkwggYEMIID7KADAgECAhMzAAACHPrN # xZvoL37EAAAAAAIcMA0GCSqGSIb3DQEBCwUAMFcxCzAJBgNVBAYTAlVTMR4wHAYD # VQQKExVNaWNyb3NvZnQgQ29ycG9yYXRpb24xKDAmBgNVBAMTH01pY3Jvc29mdCBD # b2RlIFNpZ25pbmcgUENBIDIwMjQwHhcNMjYwNDE2MTg1OTQxWhcNMjcwNDE1MTg1 # OTQxWjB0MQswCQYDVQQGEwJVUzETMBEGA1UECBMKV2FzaGluZ3RvbjEQMA4GA1UE # BxMHUmVkbW9uZDEeMBwGA1UEChMVTWljcm9zb2Z0IENvcnBvcmF0aW9uMR4wHAYD # VQQDExVNaWNyb3NvZnQgQ29ycG9yYXRpb24wggEiMA0GCSqGSIb3DQEBAQUAA4IB # DwAwggEKAoIBAQDVsZfgOKmM31HPfoWOoNEiw0SlCiIxUMC0I9NMWbucKOw/e9lP # oAoehQVu6SG65V4EPzrYsnBnFPNoi4/HoOdjhz1qkrEt4I6tEcxXU6oOeY9zGveC # /3iBeuhLYxM3M/PkcUoebF+Nednm8OkdSPoDu8imViHPQq/8CQUu0WRR4rE+dMRf # rpVqfmNi2qWCX94T4MsepijGVkwE//tJg0ryAiYdHT34LSnlG/RSBZmQRGWZ5g8j # qnKjRParSqMft1gvjuUTVgtWNZfgcLFSK5Wa0myrq8OPcgTGGsRgun+tnSS+IxDT # xVsAPH1OzvPjwomguByhUe/OcvUN0D5Wmp7xAgMBAAGjggGqMIIBpjAOBgNVHQ8B # Af8EBAMCB4AwHwYDVR0lBBgwFgYKKwYBBAGCN0wIAQYIKwYBBQUHAwMwHQYDVR0O # BBYEFNoH7a2YDjOSwpkp6DHcmUS7J+0yMFQGA1UdEQRNMEukSTBHMS0wKwYDVQQL # EyRNaWNyb3NvZnQgSXJlbGFuZCBPcGVyYXRpb25zIExpbWl0ZWQxFjAUBgNVBAUT # DTIzMDAxMis1MDc1NjkwHwYDVR0jBBgwFoAUf1k/VCHarU/vBeXmo9ctBpQSCDEw # YAYDVR0fBFkwVzBVoFOgUYZPaHR0cDovL3d3dy5taWNyb3NvZnQuY29tL3BraW9w # cy9jcmwvTWljcm9zb2Z0JTIwQ29kZSUyMFNpZ25pbmclMjBQQ0ElMjAyMDI0LmNy # bDBtBggrBgEFBQcBAQRhMF8wXQYIKwYBBQUHMAKGUWh0dHA6Ly93d3cubWljcm9z # b2Z0LmNvbS9wa2lvcHMvY2VydHMvTWljcm9zb2Z0JTIwQ29kZSUyMFNpZ25pbmcl # MjBQQ0ElMjAyMDI0LmNydDAMBgNVHRMBAf8EAjAAMA0GCSqGSIb3DQEBCwUAA4IC # AQAUnEqhaRXe0T3hIJjvdQErEkrA/7bByjn6t5IArODkkRjzkYwtKMc2yYj2quaN # rLutWw2YZcngKPy1b71YyDJQTy4NDRwaSh9Tw5thrk3NmcPrAHia5vtcBJ1CgtKK # 7mQbIcQ22d/N3813ayCDDFewu1+jsZmX+r/aTEqaOM4TVxVtRSkuCy8nAXKuChOK # Li/zA4XuH8iEYqIsj2YoNaeSxVmeGiERXpKdo3dDmYi0kO5w2D8VS4c3+9h6gElY # BaAAg/dYErBg27qT3vv0zRDJhJufvCNylA8S7/+8H5E/PV5cng6na9VV/w9OV3qu # uND6zdGa2EX38Glp50F9AIQk3p2xXmcvorDeM4XJ7UlWYBi6g80J1SSOQnInCYFE # msfUNn3+1AaTJKSJL83quKArTac2pKhu0Yzzzrzo6HrsRiQKzpnRBb1/dMa6P3hz # 75XbMRBctNsFhZC07WCmjExdLg2eHW5uV0TY8D5+6wozJf7vF3+WHkYPO85Z+BC6 # U4FkNbYNycZ9cE4j1tXRdyDCfml6c0HWPHjNVDObrv9lKt3qUqFpX38VCqVCyNOO # 1UcXfQiVjJw32U2WUKZjt/neJKHEBsm9kFsLuWzkQ53+qcaSaytmsCnk2gOglrlD # 5d3kKyvvAw+rzm0lT8K38P6PLxfZQHhu4W8dV7Av8N2ZmDCCBr0wggSloAMCAQIC # EzMAAAA5O7Y3Gb8GHWcAAAAAADkwDQYJKoZIhvcNAQEMBQAwgYgxCzAJBgNVBAYT # AlVTMRMwEQYDVQQIEwpXYXNoaW5ndG9uMRAwDgYDVQQHEwdSZWRtb25kMR4wHAYD # VQQKExVNaWNyb3NvZnQgQ29ycG9yYXRpb24xMjAwBgNVBAMTKU1pY3Jvc29mdCBS # b290IENlcnRpZmljYXRlIEF1dGhvcml0eSAyMDExMB4XDTI0MDgwODIwNTQxOFoX # DTM2MDMyMjIyMTMwNFowVzELMAkGA1UEBhMCVVMxHjAcBgNVBAoTFU1pY3Jvc29m # dCBDb3Jwb3JhdGlvbjEoMCYGA1UEAxMfTWljcm9zb2Z0IENvZGUgU2lnbmluZyBQ # Q0EgMjAyNDCCAiIwDQYJKoZIhvcNAQEBBQADggIPADCCAgoCggIBANgBnB7jOMeq # lRYHNa265v4IY9fH8TKhemHfPINe1gpLaV3dhg324WwH06LcHbpnsBukCDNitryo # 0dtS/EW6I/yEL/bLSY8hKpbfQuWusBPr9qazYcDxCW/qnjb5JsI1s8bNOg3bVATv # QVL4tcf03aTycsz8QeCdM0l/yHRObJ9QqazM1r6VPEOJ7LL+uEEb73w6QCuhs89a # 1uv1zerOYMnsneRRwCbpyW11IcggU0cRKDDq1pjVJzIbIF6+oiXXbReOsgeI8zu1 # FyQfK0fVkaya8SmVHQ/tOf23mZ4W9k0Ri22QW9p3UgSC5OUDktKxxcCmGL6tXLfO # GSWHIIV4YrTJTT6PNty5REojHJuZHArkF9VnHTERWoTjAzfI3kP+5b4alUdhgAZ7 # ttOu1bVnXfHaqPYl2rPs20ji03LOVWsh/radgE17es5hL+t6lV0eVHrVhsssROWJ # uz2MXMCt7iw7lFPG9LXKGjsmonn2gotGdHIuEg5JnJMJVmixd5LRlkmgYRZKzhxS # CwyoGIq0PhaA7Y+VPct5pCHkijcIIDm0nlkK+0KyepolcqGm0T/GYQRMhHJlGOOm # VQop36wUVUYklUy++vDWeEgEo4s7hxN6mIbf2MSIQ/iIfMZgJxC69oukMUXCrOC3 # SkE/xIkgpfl22MM1itkZ35nNXkMolU1lAgMBAAGjggFOMIIBSjAOBgNVHQ8BAf8E # BAMCAYYwEAYJKwYBBAGCNxUBBAMCAQAwHQYDVR0OBBYEFH9ZP1Qh2q1P7wXl5qPX # LQaUEggxMBkGCSsGAQQBgjcUAgQMHgoAUwB1AGIAQwBBMA8GA1UdEwEB/wQFMAMB # Af8wHwYDVR0jBBgwFoAUci06AjGQQ7kUBU7h6qfHMdEjiTQwWgYDVR0fBFMwUTBP # oE2gS4ZJaHR0cDovL2NybC5taWNyb3NvZnQuY29tL3BraS9jcmwvcHJvZHVjdHMv # TWljUm9vQ2VyQXV0MjAxMV8yMDExXzAzXzIyLmNybDBeBggrBgEFBQcBAQRSMFAw # TgYIKwYBBQUHMAKGQmh0dHA6Ly93d3cubWljcm9zb2Z0LmNvbS9wa2kvY2VydHMv # TWljUm9vQ2VyQXV0MjAxMV8yMDExXzAzXzIyLmNydDANBgkqhkiG9w0BAQwFAAOC # AgEAFJQfOChP7onn6fLIMKrSlN1WYKwDFgAddymOUO3FrM8d7B/W/iQ6DxXsDn7D # 5W4wMwYeLystcEqfkjz4NURRgazyMu5yRzQh4LqjA4tStTcJh1opExo7nn5PuPBY # nbu0+THSuVHTe0VTTPVhily/piFrDo3axQ9P4C+Ol5yet+2gTfekICS5xS+cYfSI # vgn0JksVBVMYVI5QFu/qhnLhsEFEUzG8fvv0hjgkO+lkpV9ty6GkN4vdnd7ya6Q6 # aR9y34aiM1qmxaxBi6OUnyNl6fkuun/diTFnYDLTppOkr/mg5WSfCiDVMNCxtj4w # PKC5OmHm1DQIt/MNokbbH3UGsFP1QbzsLocuSqLCvH09Io3fDPTmscR9Y75G4qX7 # RTX8AdBPo0I6OEojf39zuFZt0qOHm65YWQE69cZM2ueE1MB05dNNgHK9gTE7zKvK # /fg8B2qjW88MT/WF5V5uvZGtqa9FSL2RazArA+rDPuf6JGYz4HpgMZHB4S6szWSK # YBv0VisCzfxgeU+dquXW9bd0auYlOB58DPcOYKdc3Se94g+xL4pcEhbB54JOgAkw # YTu/9dLeH2pDqeJZAABVDWRQCaXfO5LgyKwKCLYXpigrZYCjUSBcr+Ve8PFWMhVT # Ql0v4q8J/AUmQN5W4n101cY2L4A7GTQG1h32HHAvfQESWP0xghn7MIIZ9wIBATBu # MFcxCzAJBgNVBAYTAlVTMR4wHAYDVQQKExVNaWNyb3NvZnQgQ29ycG9yYXRpb24x # KDAmBgNVBAMTH01pY3Jvc29mdCBDb2RlIFNpZ25pbmcgUENBIDIwMjQCEzMAAAIc # +s3Fm+gvfsQAAAAAAhwwDQYJYIZIAWUDBAIBBQCgga4wGQYJKoZIhvcNAQkDMQwG # CisGAQQBgjcCAQQwHAYKKwYBBAGCNwIBCzEOMAwGCisGAQQBgjcCARUwLwYJKoZI # hvcNAQkEMSIEIKeIxvU0QSYkQ2YS2ihXREyJkIbEMphRlIA9zaLC7veUMEIGCisG # AQQBgjcCAQwxNDAyoBSAEgBNAGkAYwByAG8AcwBvAGYAdKEagBhodHRwOi8vd3d3 # Lm1pY3Jvc29mdC5jb20wDQYJKoZIhvcNAQEBBQAEggEAH0D9haovM6EPCXy29Wlq # kRCkTrCXz/0dyQdrcVtOIRoygmGGNYv1AGYS12mIkZyPS/RVswWIMIxrD+WnbsBM # rYg660ACB0Ah1DuhvRYf4rLRIlhAUZrDp5aRcLemLNbftvX/wnkHHmr+wf8ac8rF # RLLg/OU91JDytPOxW68qhQe4kPS8xxm4OfEogMoUCQ+DLQyasAJFfVx2ecc0Agot # OL9iw7K7l3zSUvFY+HrQbUdj17hfd5dEgiot8MIVZa48nuMJqg7zRNf32osWtd38 # pn9LbfIzucMaNSGyr3R8cPVHMOFl0iLTK/A7qqjxud65v8NXugZE2mMcJSM1qO4N # EqGCF60wghepBgorBgEEAYI3AwMBMYIXmTCCF5UGCSqGSIb3DQEHAqCCF4YwgheC # AgEDMQ8wDQYJYIZIAWUDBAIBBQAwggFaBgsqhkiG9w0BCRABBKCCAUkEggFFMIIB # QQIBAQYKKwYBBAGEWQoDATAxMA0GCWCGSAFlAwQCAQUABCBmEIfU6ibnC+TbPWmY # RDnUg2MdXt0QwE9SO3tesmG6rAIGaexu9ZnFGBMyMDI2MDUwMTE3MjExMS4xOTda # MASAAgH0oIHZpIHWMIHTMQswCQYDVQQGEwJVUzETMBEGA1UECBMKV2FzaGluZ3Rv # bjEQMA4GA1UEBxMHUmVkbW9uZDEeMBwGA1UEChMVTWljcm9zb2Z0IENvcnBvcmF0 # aW9uMS0wKwYDVQQLEyRNaWNyb3NvZnQgSXJlbGFuZCBPcGVyYXRpb25zIExpbWl0 # ZWQxJzAlBgNVBAsTHm5TaGllbGQgVFNTIEVTTjo2NTFBLTA1RTAtRDk0NzElMCMG # A1UEAxMcTWljcm9zb2Z0IFRpbWUtU3RhbXAgU2VydmljZaCCEfswggcoMIIFEKAD # AgECAhMzAAACFRgD04EHJnxTAAEAAAIVMA0GCSqGSIb3DQEBCwUAMHwxCzAJBgNV # BAYTAlVTMRMwEQYDVQQIEwpXYXNoaW5ndG9uMRAwDgYDVQQHEwdSZWRtb25kMR4w # HAYDVQQKExVNaWNyb3NvZnQgQ29ycG9yYXRpb24xJjAkBgNVBAMTHU1pY3Jvc29m # dCBUaW1lLVN0YW1wIFBDQSAyMDEwMB4XDTI1MDgxNDE4NDgyMFoXDTI2MTExMzE4 # NDgyMFowgdMxCzAJBgNVBAYTAlVTMRMwEQYDVQQIEwpXYXNoaW5ndG9uMRAwDgYD # VQQHEwdSZWRtb25kMR4wHAYDVQQKExVNaWNyb3NvZnQgQ29ycG9yYXRpb24xLTAr # BgNVBAsTJE1pY3Jvc29mdCBJcmVsYW5kIE9wZXJhdGlvbnMgTGltaXRlZDEnMCUG # A1UECxMeblNoaWVsZCBUU1MgRVNOOjY1MUEtMDVFMC1EOTQ3MSUwIwYDVQQDExxN # aWNyb3NvZnQgVGltZS1TdGFtcCBTZXJ2aWNlMIICIjANBgkqhkiG9w0BAQEFAAOC # Ag8AMIICCgKCAgEAw3HV3hVxL0lEYPV03XeNKZ517VIbgexhlDPdpXwDS0BYtxPw # i4XYpZR1ld0u6cr2Xjuugdg50DUx5WHL0QhY2d9vkJSk02rE/75hcKt91m2Ih287 # QRxRMmFu3BF6466k8qp5uXtfe6uciq49YaS8p+dzv3uTarD4hQ8UT7La95pOJiRq # xxd0qOGLECvHLEXPXioNSx9pyhzhm6lt7ezLxJeFVYtxShkavPoZN0dOCiYeh4Kg # oKoyagzMuSiLCiMUW4Ue4Qsm658FJNGTNh7V5qXYVA6k5xjw5WeWdKOz0i9A5jBc # bY9fVOo/cA8i1bytzcDTxb3nctcly8/OYeNstkab/Isq3Cxe1vq96fIHE1+ZGmJj # ka1sodwqPycVp/2tb+BjulPL5D6rgUXTPF84U82RLKHV57bB8fHRpgnjcWBQuXPg # VeSXpERWimt0NF2lCOLzqgrvS/vYqde5Ln9YlKKhAZ/xDE0TLIIr6+I/2JTtXP34 # nfjTENVqMBISWcakIxAwGb3RB5yHCxynIFNVLcfKAsEdC5U2em0fAvmVv0sonqnv # 17cuaYi2eCLWhoK1Ic85Dw7s/lhcXrBpY4n/Rl5l3wHzs4vOIhu87DIy5QUaEupE # syY0NWqgI4BWl6v1wgse+l8DWFeUXofhUuCgVTuTHN3K8idoMbn8Q3edUIECAwEA # AaOCAUkwggFFMB0GA1UdDgQWBBSJIXfxcqAwFqGj9jdwQtdSqadj1zAfBgNVHSME # GDAWgBSfpxVdAF5iXYP05dJlpxtTNRnpcjBfBgNVHR8EWDBWMFSgUqBQhk5odHRw # Oi8vd3d3Lm1pY3Jvc29mdC5jb20vcGtpb3BzL2NybC9NaWNyb3NvZnQlMjBUaW1l # LVN0YW1wJTIwUENBJTIwMjAxMCgxKS5jcmwwbAYIKwYBBQUHAQEEYDBeMFwGCCsG # AQUFBzAChlBodHRwOi8vd3d3Lm1pY3Jvc29mdC5jb20vcGtpb3BzL2NlcnRzL01p # Y3Jvc29mdCUyMFRpbWUtU3RhbXAlMjBQQ0ElMjAyMDEwKDEpLmNydDAMBgNVHRMB # Af8EAjAAMBYGA1UdJQEB/wQMMAoGCCsGAQUFBwMIMA4GA1UdDwEB/wQEAwIHgDAN # BgkqhkiG9w0BAQsFAAOCAgEAd42HtV+kGbvxzLBTC5O7vkCIBPy/BwpjCzeL53hA # iEOebp+VdNnwm9GVCfYq3KMfrj4UvKQTUAaS5Zkwe1gvZ3ljSSnCOyS5OwNu9dpg # 3ww+QW2eOcSLkyVAWFrLn6Iig3TC/zWMvVhqXtdFhG2KJ1lSbN222csY3E3/BrGl # uAlvET9gmxVyyxNy59/7JF5zIGcJibydxs94JL1BtPgXJOfZzQ+/3iTc6eDtmaWT # 6DKdnJocp8wkXKWPIsBEfkD6k1Qitwvt0mHrORah75SjecOKt4oWayVLkPTho12e # 0ongEg1cje5fxSZGthrMrWKvI4R7HEC7k8maH9ePA3ViH0CVSSOefaPTGMzIhHCo # 5p3jG5SMcyO3eA9uEaYQJITJlLG3BwwGmypY7C/8/nj1SOhgx1HgJ0ywOJL9xfP4 # AOcWmCfbsqgGbCaC7WH5sINdzfMar8V7YNFqkbCGUKhc8GpIyE+MKnyVn33jsuaG # AlNRg7dVRUSoYLJxvUsw9GOwyBpBwbE9sqOLm+HsO00oF23PMio7WFXcFTZAjp3u # jihBAfLrXICgGOHPdkZ042u1LZqOcnlr3XzvgMe+mPPyasW8f0rtzJj3V5E/EKiy # QlPxj9Mfq2x9himnlXWGZCVPeEBROrNbDYBfazTyLNCOTsRtksOSV3FBtPnpQtLN # 754wggdxMIIFWaADAgECAhMzAAAAFcXna54Cm0mZAAAAAAAVMA0GCSqGSIb3DQEB # CwUAMIGIMQswCQYDVQQGEwJVUzETMBEGA1UECBMKV2FzaGluZ3RvbjEQMA4GA1UE # BxMHUmVkbW9uZDEeMBwGA1UEChMVTWljcm9zb2Z0IENvcnBvcmF0aW9uMTIwMAYD # VQQDEylNaWNyb3NvZnQgUm9vdCBDZXJ0aWZpY2F0ZSBBdXRob3JpdHkgMjAxMDAe # Fw0yMTA5MzAxODIyMjVaFw0zMDA5MzAxODMyMjVaMHwxCzAJBgNVBAYTAlVTMRMw # EQYDVQQIEwpXYXNoaW5ndG9uMRAwDgYDVQQHEwdSZWRtb25kMR4wHAYDVQQKExVN # aWNyb3NvZnQgQ29ycG9yYXRpb24xJjAkBgNVBAMTHU1pY3Jvc29mdCBUaW1lLVN0 # YW1wIFBDQSAyMDEwMIICIjANBgkqhkiG9w0BAQEFAAOCAg8AMIICCgKCAgEA5OGm # TOe0ciELeaLL1yR5vQ7VgtP97pwHB9KpbE51yMo1V/YBf2xK4OK9uT4XYDP/XE/H # ZveVU3Fa4n5KWv64NmeFRiMMtY0Tz3cywBAY6GB9alKDRLemjkZrBxTzxXb1hlDc # wUTIcVxRMTegCjhuje3XD9gmU3w5YQJ6xKr9cmmvHaus9ja+NSZk2pg7uhp7M62A # W36MEBydUv626GIl3GoPz130/o5Tz9bshVZN7928jaTjkY+yOSxRnOlwaQ3KNi1w # jjHINSi947SHJMPgyY9+tVSP3PoFVZhtaDuaRr3tpK56KTesy+uDRedGbsoy1cCG # MFxPLOJiss254o2I5JasAUq7vnGpF1tnYN74kpEeHT39IM9zfUGaRnXNxF803RKJ # 1v2lIH1+/NmeRd+2ci/bfV+AutuqfjbsNkz2K26oElHovwUDo9Fzpk03dJQcNIIP # 8BDyt0cY7afomXw/TNuvXsLz1dhzPUNOwTM5TI4CvEJoLhDqhFFG4tG9ahhaYQFz # ymeiXtcodgLiMxhy16cg8ML6EgrXY28MyTZki1ugpoMhXV8wdJGUlNi5UPkLiWHz # NgY1GIRH29wb0f2y1BzFa/ZcUlFdEtsluq9QBXpsxREdcu+N+VLEhReTwDwV2xo3 # xwgVGD94q0W29R6HXtqPnhZyacaue7e3PmriLq0CAwEAAaOCAd0wggHZMBIGCSsG # AQQBgjcVAQQFAgMBAAEwIwYJKwYBBAGCNxUCBBYEFCqnUv5kxJq+gpE8RjUpzxD/ # LwTuMB0GA1UdDgQWBBSfpxVdAF5iXYP05dJlpxtTNRnpcjBcBgNVHSAEVTBTMFEG # DCsGAQQBgjdMg30BATBBMD8GCCsGAQUFBwIBFjNodHRwOi8vd3d3Lm1pY3Jvc29m # dC5jb20vcGtpb3BzL0RvY3MvUmVwb3NpdG9yeS5odG0wEwYDVR0lBAwwCgYIKwYB # BQUHAwgwGQYJKwYBBAGCNxQCBAweCgBTAHUAYgBDAEEwCwYDVR0PBAQDAgGGMA8G # A1UdEwEB/wQFMAMBAf8wHwYDVR0jBBgwFoAU1fZWy4/oolxiaNE9lJBb186aGMQw # VgYDVR0fBE8wTTBLoEmgR4ZFaHR0cDovL2NybC5taWNyb3NvZnQuY29tL3BraS9j # cmwvcHJvZHVjdHMvTWljUm9vQ2VyQXV0XzIwMTAtMDYtMjMuY3JsMFoGCCsGAQUF # BwEBBE4wTDBKBggrBgEFBQcwAoY+aHR0cDovL3d3dy5taWNyb3NvZnQuY29tL3Br # aS9jZXJ0cy9NaWNSb29DZXJBdXRfMjAxMC0wNi0yMy5jcnQwDQYJKoZIhvcNAQEL # BQADggIBAJ1VffwqreEsH2cBMSRb4Z5yS/ypb+pcFLY+TkdkeLEGk5c9MTO1OdfC # cTY/2mRsfNB1OW27DzHkwo/7bNGhlBgi7ulmZzpTTd2YurYeeNg2LpypglYAA7AF # vonoaeC6Ce5732pvvinLbtg/SHUB2RjebYIM9W0jVOR4U3UkV7ndn/OOPcbzaN9l # 9qRWqveVtihVJ9AkvUCgvxm2EhIRXT0n4ECWOKz3+SmJw7wXsFSFQrP8DJ6LGYnn # 8AtqgcKBGUIZUnWKNsIdw2FzLixre24/LAl4FOmRsqlb30mjdAy87JGA0j3mSj5m # O0+7hvoyGtmW9I/2kQH2zsZ0/fZMcm8Qq3UwxTSwethQ/gpY3UA8x1RtnWN0SCyx # TkctwRQEcb9k+SS+c23Kjgm9swFXSVRk2XPXfx5bRAGOWhmRaw2fpCjcZxkoJLo4 # S5pu+yFUa2pFEUep8beuyOiJXk+d0tBMdrVXVAmxaQFEfnyhYWxz/gq77EFmPWn9 # y8FBSX5+k77L+DvktxW/tM4+pTFRhLy/AsGConsXHRWJjXD+57XQKBqJC4822rpM # +Zv/Cuk0+CQ1ZyvgDbjmjJnW4SLq8CdCPSWU5nR0W2rRnj7tfqAxM328y+l7vzhw # RNGQ8cirOoo6CGJ/2XBjU02N7oJtpQUQwXEGahC0HVUzWLOhcGbyoYIDVjCCAj4C # AQEwggEBoYHZpIHWMIHTMQswCQYDVQQGEwJVUzETMBEGA1UECBMKV2FzaGluZ3Rv # bjEQMA4GA1UEBxMHUmVkbW9uZDEeMBwGA1UEChMVTWljcm9zb2Z0IENvcnBvcmF0 # aW9uMS0wKwYDVQQLEyRNaWNyb3NvZnQgSXJlbGFuZCBPcGVyYXRpb25zIExpbWl0 # ZWQxJzAlBgNVBAsTHm5TaGllbGQgVFNTIEVTTjo2NTFBLTA1RTAtRDk0NzElMCMG # A1UEAxMcTWljcm9zb2Z0IFRpbWUtU3RhbXAgU2VydmljZaIjCgEBMAcGBSsOAwIa # AxUAj6eTejbuYE1Ifjbfrt6tXevCUSCggYMwgYCkfjB8MQswCQYDVQQGEwJVUzET # MBEGA1UECBMKV2FzaGluZ3RvbjEQMA4GA1UEBxMHUmVkbW9uZDEeMBwGA1UEChMV # TWljcm9zb2Z0IENvcnBvcmF0aW9uMSYwJAYDVQQDEx1NaWNyb3NvZnQgVGltZS1T # dGFtcCBQQ0EgMjAxMDANBgkqhkiG9w0BAQsFAAIFAO2e1gUwIhgPMjAyNjA1MDEw # NzM0MjlaGA8yMDI2MDUwMjA3MzQyOVowdDA6BgorBgEEAYRZCgQBMSwwKjAKAgUA # 7Z7WBQIBADAHAgEAAgIMvDAHAgEAAgISqDAKAgUA7aAnhQIBADA2BgorBgEEAYRZ # CgQCMSgwJjAMBgorBgEEAYRZCgMCoAowCAIBAAIDB6EgoQowCAIBAAIDAYagMA0G # CSqGSIb3DQEBCwUAA4IBAQB/rWl9ys9H16QqS3CobWgDR5pZ26xGKVmcmNuCUw1K # M/3DOFZA3k+acoEBbuQ4q2xSh2ph+psyTvBV2y8tolGizBwWpkx12K80gVRRinZu # PuvmaH8rHz0kzIerdjkdlh/ooKseh7PmJdm1yX7Vvoq0XyVb3g+BwkvrZVg8kNaM # AEYj/XutO97ZToJOP7IBPDRtUw5NUojBmdr2Pxi4Rw7n7r+V2DWljUToU9zjHpFQ # AsrYJVEgt3rErryncbOW3utkBr5e/5YKHntDZK8cYBSBEOyeEwxhM+GWt60ZCt2T # 5ymTPHiTcSaK8c9RF3ZwZSIeCl50J2jlbHBAlk2FwIXyMYIEDTCCBAkCAQEwgZMw # fDELMAkGA1UEBhMCVVMxEzARBgNVBAgTCldhc2hpbmd0b24xEDAOBgNVBAcTB1Jl # ZG1vbmQxHjAcBgNVBAoTFU1pY3Jvc29mdCBDb3Jwb3JhdGlvbjEmMCQGA1UEAxMd # TWljcm9zb2Z0IFRpbWUtU3RhbXAgUENBIDIwMTACEzMAAAIVGAPTgQcmfFMAAQAA # AhUwDQYJYIZIAWUDBAIBBQCgggFKMBoGCSqGSIb3DQEJAzENBgsqhkiG9w0BCRAB # BDAvBgkqhkiG9w0BCQQxIgQgPKDpADt33obyQaGvZ5SaBhjBHR1VsznjYK44khec # aOowgfoGCyqGSIb3DQEJEAIvMYHqMIHnMIHkMIG9BCBwEPR2PDrTFLcrtQsKrUi7 # oz5JNRCF/KRHMihSNe7sijCBmDCBgKR+MHwxCzAJBgNVBAYTAlVTMRMwEQYDVQQI # EwpXYXNoaW5ndG9uMRAwDgYDVQQHEwdSZWRtb25kMR4wHAYDVQQKExVNaWNyb3Nv # ZnQgQ29ycG9yYXRpb24xJjAkBgNVBAMTHU1pY3Jvc29mdCBUaW1lLVN0YW1wIFBD # QSAyMDEwAhMzAAACFRgD04EHJnxTAAEAAAIVMCIEIISPzEP+kmNoy9x+683AMy8x # lyovwMFpIoVwEIdmyssJMA0GCSqGSIb3DQEBCwUABIICAJZnNRi4UhM6Jh2XK9Rs # HxAACDu9xbnAZEJs2wbDNRKHZXMduolWLwyRhu8ZuqehpGwmHwOOkhj8EHV8QMBU # +XNwe40rmTSgQryoNZcGzrJ815X1Wt9OeKhJaTFMHnCSWaCchJCZBsKcPjj5g4YR # lkDKtMyImXU593/L6Qq7ebyUbHuJjdkoslNnlDz4VOWu8XAAm3Kyjy9wwGdg+loe # WCpslWWURpaSKUUHkwXt29eTZ31n2THnUU+Z015uaxv/qZWyykuBl5I3RwWhxTl5 # VBtInqdeVz1InZxDJOIhBRkEY0iSHJDji/gquAePO83p1yMKy9S9NFKBERobhGvw # GoNVnWh/HsqPftttQZE/qsOGZ/xC063/+TTpsjITVd3yGbd0rfsKJZOwtW/DR1FE # xYD1wICli/fdhPAr1W/U9Li2eKSrdFx5dktCyxXpup2Y9uGp9an4UQ1pU4fdC06N # 7xfOcZbErPOziHv/yPGXjCsb3KWCNZCQLgDq74/95eENUQBHsalFXQ3HJ5RLt4v0 # vWpB660y54aKFLAA4YvyF15Pa1Y1nRHwzW6EOtylE127PCCq2PrTsee27aC7mC0R # 3R7ebPJ0Gg2hStgQ1QMNtRR6BxhKQgphc0vkHO7PEtJTfLdQR4yO0nPv4lmM6Edc # Q7LLCicbP9ZFnfiqgXPgLrIx # SIG # End signature block |