classes/OSConfig.ps1

# Copyright (c) Microsoft Corporation. All rights reserved.

function Get-ServerType() {
    try {
        $Value = Get-ItemPropertyValue -LiteralPath "HKLM:\SYSTEM\CurrentControlSet\Services\Netlogon\Parameters" -Name "SysvolReady"
        if (-not [String]::IsNullOrWhiteSpace($Value)) {
            return "Domain Controller"
        }
    } catch {
        # Ignored.
    }

    try {
        $Value = Get-ItemPropertyValue -LiteralPath "HKLM:\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters" -Name "Domain"
        if (-not [String]::IsNullOrWhiteSpace($Value)) {
            return "Member Server"
        }
    } catch {
        # Ignored.
    }

    return "Workgroup Member"
}

function Get-EnvironmentType {
    $Properties = Get-ItemProperty -Path "HKLM:\SOFTWARE\Microsoft\Windows NT\CurrentVersion"

    if ($Properties.InstallationType -match "Server") {
        if ($Properties.EditionId -eq "ServerAzureStackHCICor") {
            $InstallationType = "AzureLocal"

            if ($Properties.DisplayVersion -eq "24H2") {
                $Version = "24H2"
            } elseif ($Properties.DisplayVersion -eq "23H2") {
                $Version = "23H2"
            } else {
                return
            }
        } else {
            $InstallationType = "WindowsServer"

            # We need to have the necessary update for Windows Server 2022 and Windows Server 23H2
            # but not for Windows Server 2025. We can use the UBR (Update Build Revision) to
            # determine the version.

            if ($Properties.DisplayVersion -eq "24H2") {
                $Version = "2025"
            } elseif (($Properties.DisplayVersion -eq "23H2") -and ($Properties.UBR -ge 1369)) {
                $Version = "2022"
            } elseif (($Properties.DisplayVersion -eq "21H2") -and ($Properties.UBR -ge 3091)) {
                $Version = "2022"
            } else {
                return
            }
        }
    } else {
        return
    }

    $Role = (Get-ServerType) -replace " ", ""

    "$InstallationType\$Version\$Role"
}

function ConvertFrom-Expression($Expression) {
    if ($Expression -isnot [String] -or [String]::IsNullOrWhiteSpace($Expression)) {
        throw [InvalidValueException]::new($Strings.ErrorInvalidExpression -f $Expression)
    }

    # JSON object format
    if ($Expression.TrimStart().StartsWith('{')) {
        try {
            $JsonObj = ConvertFrom-Json -InputObject $Expression
            $Result = @()
            foreach ($Property in $JsonObj.PSObject.Properties) {
                $Result += [PSCustomObject]@{ Name = $Property.Name; Value = $Property.Value }
            }
            if ($Result.Count -gt 0) {
                return , $Result
            }
        } catch {
            # Not valid JSON, fall through to semicolon-delimited parsing
        }
    }

    # Semicolon-delimited format
    $InQuotes = $False
    $ProcessedExpression = $Expression.Clone()

    for ($i = 0; $i -lt $Expression.Length; $i++) {
        if ($Expression[$i] -eq '"') {
            $InQuotes = -not $InQuotes
            continue
        }

        if ($InQuotes) {
            continue
        }

        if ($Expression[$i] -eq ";") {
            $ProcessedExpression = $ProcessedExpression.Remove($i, 1).Insert($i, "`n")
        }
    }

    try {
        $Result = @($ProcessedExpression | ConvertFrom-Csv -Header @("Name", "Value") -Delimiter ":")

        if (($Result.Count -eq 1) -and (-not $Result.Value)) {
            $Result[0].Value = $Result[0].Name
            $Result[0].Name = "*"
        }

        , $Result
    } catch {
        throw [InvalidValueException]::new($Strings.ErrorInvalidExpression -f $Expression)
    }
}

function Find-Rule($Name, $Rules) {
    # First pass: exact or wildcard match
    foreach ($Rule in $Rules) {
        $InclusionRule = -not $Rule.Name.StartsWith("!")
        $RuleName = if ($InclusionRule) { $Rule.Name } else { $Rule.Name.Substring(1) }

        if ($Name -like $RuleName) {
            return $(if ($InclusionRule) { $Rule } else { $null })
        }
    }

    # Second pass: segment-boundary suffix match
    foreach ($Rule in $Rules) {
        $InclusionRule = -not $Rule.Name.StartsWith("!")
        $RuleName = if ($InclusionRule) { $Rule.Name } else { $Rule.Name.Substring(1) }

        if ($Name -like "*\$RuleName") {
            return $(if ($InclusionRule) { $Rule } else { $null })
        }
    }
}

class OSConfigReason {
    [DscProperty()]
    [String] $Code

    [DscProperty()]
    [String] $Phrase

    OSConfigReason() { }

    OSConfigReason([String] $RuleId, [String] $Severity, [Bool] $IsCompliant, [String] $Reason) {
        $Status = if ($IsCompliant) { 'BaselineSettingCompliant' } else { 'BaselineSettingNotCompliant' }

        if ($RuleId) {
            $Status = "$Status`:$RuleId"
        }

        $this.Code = $Status

        if (-not [String]::IsNullOrWhiteSpace($Severity)) {
            $this.Phrase = "[$Severity] $Reason"
        } else {
            $this.Phrase = $Reason
        }
    }
}

[DscResource()]
class OSConfig {
    [DscProperty()]
    [String] $RuleId

    [DscProperty()]
    [String] $Severity

    [DscProperty()]
    [String] $CorrelationGroup

    [DscProperty(Key)]
    [String] $Name

    [DscProperty(Key)]
    [String] $Type

    [DscProperty(Key)]
    [String] $Properties

    [DscProperty()]
    [String] $Value

    [DscProperty()]
    [String] $ValueType

    [DscProperty()]
    [String] $ValueName = 'value'

    [DscProperty()]
    [String] $Schema

    [DscProperty()]
    [Bool] $ExtendSchema

    [DscProperty()]
    [String] $Expression

    [DscProperty()]
    [String] $Template

    [DscProperty()]
    [String] $RoleFilter

    [DscProperty()]
    [String] $VersionFilter

    [DscProperty(NotConfigurable)]
    [OSConfigReason[]] $Reasons

    hidden [Bool] $IsCompliant = $True

    [OSConfig] Get() {
        $CurrentState = [OSConfig]::new()

        $CurrentState.RuleId = $this.RuleId
        $CurrentState.Severity = $this.Severity
        $CurrentState.Name = $this.Name
        $CurrentState.Type = $this.Type
        $CurrentState.Properties = $this.Properties
        $CurrentState.Value = $this.Value
        $CurrentState.Schema = $this.Schema
        $CurrentState.ExtendSchema = $this.ExtendSchema
        $CurrentState.ValueType = $this.ValueType
        $CurrentState.RoleFilter = $this.RoleFilter
        $CurrentState.VersionFilter = $this.VersionFilter
        $CurrentState.Reasons = @()

        $env:OSCONFIG_LOG_DIR = "$PSScriptRoot\logs"
        $env:DMOSCONFIG_AUTHORITY = $Script:Constants.Authority.Cloud

        try {
            $ErrorActionPreference = 'Stop'

            if (-not $this.IsApplicable()) {
                $CurrentState.IsCompliant = $True
                $CurrentState.Reasons += [OSConfigReason]::new($this.RuleId, $null, $CurrentState.IsCompliant, 'Not applicable')
                return $CurrentState
            }

            $ActualValue = $this.GetActualValue()

            $ResourceProperties = @{
                'resource' = @{
                    'name'       = $this.Name
                    'type'       = $this.Type
                    'properties' = $this.Properties | ConvertFrom-Json
                }
                'template' = $this.GetTemplate($ActualValue)
            }

            $ResourceSchema = $this.GetSchema($ActualValue)
            $ResourceExpression = $this.Expression

            if ($ResourceExpression) {
                $ResourceProperties['expression'] = $ResourceExpression
            } elseif ($ResourceSchema) {
                $ResourceProperties['schema'] = $ResourceSchema
            }

            $Resource = @{
                Name       = $this.Name
                Type       = 'Microsoft.OSConfig/Test'
                Properties = $ResourceProperties
            }

            $Output = Invoke-Native exec resource --correlation-id $(Get-CorrelationId) --correlation-group $this.CorrelationGroup --mode get --name $Resource.Name --type $Resource.Type --properties (ConvertTo-Json -InputObject $Resource.Properties -Compress -Depth 32)

            $CurrentState.IsCompliant = $Output.Properties.Compliance.Status -eq 'compliant'
            $CurrentState.Reasons += [OSConfigReason]::new($this.RuleId, $CurrentState.Severity, $CurrentState.IsCompliant, $Output.Properties.Compliance.Reason)
        } catch {
            $CurrentState.IsCompliant = $False
            $CurrentState.Reasons += [OSConfigReason]::new($this.RuleId, $CurrentState.Severity, $CurrentState.IsCompliant, "$_")
            Write-Verbose "Error: $_"
        }

        return $CurrentState
    }

    [Bool] Test() {
        try {
            return $this.Get().IsCompliant
        } catch {
            Write-Verbose "Error: $_"
        }

        return $False
    }

    [Void] Set() {
        try {
            $env:OSCONFIG_LOG_DIR = "$PSScriptRoot\logs"
            $env:DMOSCONFIG_AUTHORITY = $Script:Constants.Authority.Cloud

            if (-not $this.CorrelationGroup) {
                throw "No correlation group specified."
            }

            $ResourceProperties = $this.Properties | ConvertFrom-Json

            if ($this.ValueName) {
                $ResourceProperties | Add-Member -MemberType NoteProperty -Name $this.ValueName -Value $this.GetActualValue()
            }

            Invoke-Native exec resource --correlation-id $(Get-CorrelationId) --correlation-group $this.CorrelationGroup --mode set --name $this.Name --type $this.type --properties $ResourceProperties
        } catch {
            Write-Verbose "Error: $_"
        }
    }

    [Bool] IsApplicable() {
        if (-not [String]::IsNullOrWhiteSpace($this.RoleFilter)) {
            $CurrentRole = Get-ServerType
            $AllowedRoles = $this.RoleFilter -split ',' | ForEach-Object { $_.Trim() }

            if ($AllowedRoles -notcontains $CurrentRole) {
                return $False
            }
        }

        if (-not [String]::IsNullOrWhiteSpace($this.VersionFilter)) {
            $CurrentVersion = Get-WindowsServerVersion

            if (-not $CurrentVersion) {
                return $False
            }

            $AllowedVersions = $this.VersionFilter -split ',' | ForEach-Object { $_.Trim() }

            if ($AllowedVersions -notcontains $CurrentVersion) {
                return $False
            }
        }

        # If there is no schema or expression, there must be a value to generate the compliance reasoning.
        # Omitting the schema and expression will provide a default compliance reasoning based on the value.
        if (-not $this.Schema -and -not $this.Expression -and -not $this.Value) {
            if ($this.ValueType -ne 'string[]') {
                throw "No value, schema, or expression specified to evaluate compliance."
            }
        }

        return $True
    }

    [PSCustomObject] GetDefaultSchema([PSCustomObject] $ActualValue) {
        if ($null -eq $ActualValue) {
            return @{ 'type' = 'null' }
        }

        switch ($this.ValueType) {
            'string' {
                return @{ 'type' = 'string'; 'const' = $ActualValue }
            }
            'string[]' {
                $ArraySchema = @{
                    'type'        = 'array'
                    'items'       = @{
                        'type' = 'string'
                        'enum' = $ActualValue
                    }
                    'minItems'    = $ActualValue.Count
                    'maxItems'    = $ActualValue.Count
                    'uniqueItems' = $True
                }
                if ($ActualValue.Count -eq 0) {
                    return @{ 'anyOf' = @( @{ 'type' = 'null' }, $ArraySchema ) }
                }
                return $ArraySchema
            }
            'integer' {
                return @{ 'type' = 'integer'; 'const' = $ActualValue }
            }
            'boolean' {
                return @{ 'type' = 'boolean'; 'const' = $ActualValue }
            }
        }

        return @{ 'const' = $ActualValue }
    }

    [PSCustomObject] GetSchema([PSCustomObject] $ActualValue) {
        $DefaultSchema = $this.GetDefaultSchema($ActualValue)
        $CustomSchema = if ($this.Schema) { ConvertFrom-Json -InputObject $this.Schema }

        if ($this.ExtendSchema -and $CustomSchema) {
            return @{
                'allOf' = @(
                    $DefaultSchema,
                    $CustomSchema
                )
            }
        } elseif ($CustomSchema) {
            return $CustomSchema
        } else {
            return $DefaultSchema
        }
    }

    [String] GetTemplate([PSCustomObject] $ActualValue) {
        if ($this.Template) {
            return $this.Template
        }

        if ($null -eq $ActualValue) {
            return "The value {value} must be (null)"
        }

        return "The value {value} must be $(ConvertTo-Json -InputObject $ActualValue -Compress)."
    }

    [PSCustomObject] GetActualValue() {
        $Rules = if (-not [String]::IsNullOrWhiteSpace($this.Value)) {
            ConvertFrom-Expression -Expression $this.Value
        }

        $EnvironmentType = Get-EnvironmentType
        $Rule = Find-Rule -Name $EnvironmentType -Rules $Rules

        $StringValue = if ($null -ne $Rule) {
            $Rule.Value
        } elseif ($this.Value -or ($this.ValueType -eq 'string[]')) {
            $this.Value
        } else {
            (ConvertFrom-Json -InputObject $this.Properties).$($this.ValueName)
        }

        if ($null -eq $StringValue) {
            return $null
        }

        try {
            switch ($this.ValueType) {
                'string' {
                    return $StringValue
                }
                'integer' {
                    return [Int64]::Parse($StringValue)
                }
                'boolean' {
                    if ([Int32]::TryParse($StringValue, [ref]$null)) {
                        return [Boolean]::Parse(([Int32]$StringValue -ne 0).ToString())
                    } else {
                        return [Boolean]::Parse($StringValue)
                    }
                }
                'string[]' {
                    if ([String]::IsNullOrWhiteSpace($StringValue)) {
                        return @()
                    } else {
                        return @($StringValue -split ',' | ForEach-Object { $_.Trim() })
                    }
                }
            }
        } catch {
            throw "Unable to convert value '$StringValue' to type '$($this.ValueType)'"
        }

        return $StringValue
    }
}

# SIG # Begin signature block
# MIIoUQYJKoZIhvcNAQcCoIIoQjCCKD4CAQExDzANBglghkgBZQMEAgEFADB5Bgor
# BgEEAYI3AgEEoGswaTA0BgorBgEEAYI3AgEeMCYCAwEAAAQQH8w7YFlLCE63JNLG
# KX7zUQIBAAIBAAIBAAIBAAIBADAxMA0GCWCGSAFlAwQCAQUABCBdM82eNSu3U2yz
# fsgoCcFNLK4Hta1uNMEjnbDzo2MNK6CCDYUwggYDMIID66ADAgECAhMzAAAEhJji
# EuB4ozFdAAAAAASEMA0GCSqGSIb3DQEBCwUAMH4xCzAJBgNVBAYTAlVTMRMwEQYD
# VQQIEwpXYXNoaW5ndG9uMRAwDgYDVQQHEwdSZWRtb25kMR4wHAYDVQQKExVNaWNy
# b3NvZnQgQ29ycG9yYXRpb24xKDAmBgNVBAMTH01pY3Jvc29mdCBDb2RlIFNpZ25p
# bmcgUENBIDIwMTEwHhcNMjUwNjE5MTgyMTM1WhcNMjYwNjE3MTgyMTM1WjB0MQsw
# CQYDVQQGEwJVUzETMBEGA1UECBMKV2FzaGluZ3RvbjEQMA4GA1UEBxMHUmVkbW9u
# ZDEeMBwGA1UEChMVTWljcm9zb2Z0IENvcnBvcmF0aW9uMR4wHAYDVQQDExVNaWNy
# b3NvZnQgQ29ycG9yYXRpb24wggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIB
# AQDtekqMKDnzfsyc1T1QpHfFtr+rkir8ldzLPKmMXbRDouVXAsvBfd6E82tPj4Yz
# aSluGDQoX3NpMKooKeVFjjNRq37yyT/h1QTLMB8dpmsZ/70UM+U/sYxvt1PWWxLj
# MNIXqzB8PjG6i7H2YFgk4YOhfGSekvnzW13dLAtfjD0wiwREPvCNlilRz7XoFde5
# KO01eFiWeteh48qUOqUaAkIznC4XB3sFd1LWUmupXHK05QfJSmnei9qZJBYTt8Zh
# ArGDh7nQn+Y1jOA3oBiCUJ4n1CMaWdDhrgdMuu026oWAbfC3prqkUn8LWp28H+2S
# LetNG5KQZZwvy3Zcn7+PQGl5AgMBAAGjggGCMIIBfjAfBgNVHSUEGDAWBgorBgEE
# AYI3TAgBBggrBgEFBQcDAzAdBgNVHQ4EFgQUBN/0b6Fh6nMdE4FAxYG9kWCpbYUw
# VAYDVR0RBE0wS6RJMEcxLTArBgNVBAsTJE1pY3Jvc29mdCBJcmVsYW5kIE9wZXJh
# dGlvbnMgTGltaXRlZDEWMBQGA1UEBRMNMjMwMDEyKzUwNTM2MjAfBgNVHSMEGDAW
# gBRIbmTlUAXTgqoXNzcitW2oynUClTBUBgNVHR8ETTBLMEmgR6BFhkNodHRwOi8v
# d3d3Lm1pY3Jvc29mdC5jb20vcGtpb3BzL2NybC9NaWNDb2RTaWdQQ0EyMDExXzIw
# MTEtMDctMDguY3JsMGEGCCsGAQUFBwEBBFUwUzBRBggrBgEFBQcwAoZFaHR0cDov
# L3d3dy5taWNyb3NvZnQuY29tL3BraW9wcy9jZXJ0cy9NaWNDb2RTaWdQQ0EyMDEx
# XzIwMTEtMDctMDguY3J0MAwGA1UdEwEB/wQCMAAwDQYJKoZIhvcNAQELBQADggIB
# AGLQps1XU4RTcoDIDLP6QG3NnRE3p/WSMp61Cs8Z+JUv3xJWGtBzYmCINmHVFv6i
# 8pYF/e79FNK6P1oKjduxqHSicBdg8Mj0k8kDFA/0eU26bPBRQUIaiWrhsDOrXWdL
# m7Zmu516oQoUWcINs4jBfjDEVV4bmgQYfe+4/MUJwQJ9h6mfE+kcCP4HlP4ChIQB
# UHoSymakcTBvZw+Qst7sbdt5KnQKkSEN01CzPG1awClCI6zLKf/vKIwnqHw/+Wvc
# Ar7gwKlWNmLwTNi807r9rWsXQep1Q8YMkIuGmZ0a1qCd3GuOkSRznz2/0ojeZVYh
# ZyohCQi1Bs+xfRkv/fy0HfV3mNyO22dFUvHzBZgqE5FbGjmUnrSr1x8lCrK+s4A+
# bOGp2IejOphWoZEPGOco/HEznZ5Lk6w6W+E2Jy3PHoFE0Y8TtkSE4/80Y2lBJhLj
# 27d8ueJ8IdQhSpL/WzTjjnuYH7Dx5o9pWdIGSaFNYuSqOYxrVW7N4AEQVRDZeqDc
# fqPG3O6r5SNsxXbd71DCIQURtUKss53ON+vrlV0rjiKBIdwvMNLQ9zK0jy77owDy
# XXoYkQxakN2uFIBO1UNAvCYXjs4rw3SRmBX9qiZ5ENxcn/pLMkiyb68QdwHUXz+1
# fI6ea3/jjpNPz6Dlc/RMcXIWeMMkhup/XEbwu73U+uz/MIIHejCCBWKgAwIBAgIK
# YQ6Q0gAAAAAAAzANBgkqhkiG9w0BAQsFADCBiDELMAkGA1UEBhMCVVMxEzARBgNV
# BAgTCldhc2hpbmd0b24xEDAOBgNVBAcTB1JlZG1vbmQxHjAcBgNVBAoTFU1pY3Jv
# c29mdCBDb3Jwb3JhdGlvbjEyMDAGA1UEAxMpTWljcm9zb2Z0IFJvb3QgQ2VydGlm
# aWNhdGUgQXV0aG9yaXR5IDIwMTEwHhcNMTEwNzA4MjA1OTA5WhcNMjYwNzA4MjEw
# OTA5WjB+MQswCQYDVQQGEwJVUzETMBEGA1UECBMKV2FzaGluZ3RvbjEQMA4GA1UE
# BxMHUmVkbW9uZDEeMBwGA1UEChMVTWljcm9zb2Z0IENvcnBvcmF0aW9uMSgwJgYD
# VQQDEx9NaWNyb3NvZnQgQ29kZSBTaWduaW5nIFBDQSAyMDExMIICIjANBgkqhkiG
# 9w0BAQEFAAOCAg8AMIICCgKCAgEAq/D6chAcLq3YbqqCEE00uvK2WCGfQhsqa+la
# UKq4BjgaBEm6f8MMHt03a8YS2AvwOMKZBrDIOdUBFDFC04kNeWSHfpRgJGyvnkmc
# 6Whe0t+bU7IKLMOv2akrrnoJr9eWWcpgGgXpZnboMlImEi/nqwhQz7NEt13YxC4D
# dato88tt8zpcoRb0RrrgOGSsbmQ1eKagYw8t00CT+OPeBw3VXHmlSSnnDb6gE3e+
# lD3v++MrWhAfTVYoonpy4BI6t0le2O3tQ5GD2Xuye4Yb2T6xjF3oiU+EGvKhL1nk
# kDstrjNYxbc+/jLTswM9sbKvkjh+0p2ALPVOVpEhNSXDOW5kf1O6nA+tGSOEy/S6
# A4aN91/w0FK/jJSHvMAhdCVfGCi2zCcoOCWYOUo2z3yxkq4cI6epZuxhH2rhKEmd
# X4jiJV3TIUs+UsS1Vz8kA/DRelsv1SPjcF0PUUZ3s/gA4bysAoJf28AVs70b1FVL
# 5zmhD+kjSbwYuER8ReTBw3J64HLnJN+/RpnF78IcV9uDjexNSTCnq47f7Fufr/zd
# sGbiwZeBe+3W7UvnSSmnEyimp31ngOaKYnhfsi+E11ecXL93KCjx7W3DKI8sj0A3
# T8HhhUSJxAlMxdSlQy90lfdu+HggWCwTXWCVmj5PM4TasIgX3p5O9JawvEagbJjS
# 4NaIjAsCAwEAAaOCAe0wggHpMBAGCSsGAQQBgjcVAQQDAgEAMB0GA1UdDgQWBBRI
# bmTlUAXTgqoXNzcitW2oynUClTAZBgkrBgEEAYI3FAIEDB4KAFMAdQBiAEMAQTAL
# BgNVHQ8EBAMCAYYwDwYDVR0TAQH/BAUwAwEB/zAfBgNVHSMEGDAWgBRyLToCMZBD
# uRQFTuHqp8cx0SOJNDBaBgNVHR8EUzBRME+gTaBLhklodHRwOi8vY3JsLm1pY3Jv
# c29mdC5jb20vcGtpL2NybC9wcm9kdWN0cy9NaWNSb29DZXJBdXQyMDExXzIwMTFf
# MDNfMjIuY3JsMF4GCCsGAQUFBwEBBFIwUDBOBggrBgEFBQcwAoZCaHR0cDovL3d3
# dy5taWNyb3NvZnQuY29tL3BraS9jZXJ0cy9NaWNSb29DZXJBdXQyMDExXzIwMTFf
# MDNfMjIuY3J0MIGfBgNVHSAEgZcwgZQwgZEGCSsGAQQBgjcuAzCBgzA/BggrBgEF
# BQcCARYzaHR0cDovL3d3dy5taWNyb3NvZnQuY29tL3BraW9wcy9kb2NzL3ByaW1h
# cnljcHMuaHRtMEAGCCsGAQUFBwICMDQeMiAdAEwAZQBnAGEAbABfAHAAbwBsAGkA
# YwB5AF8AcwB0AGEAdABlAG0AZQBuAHQALiAdMA0GCSqGSIb3DQEBCwUAA4ICAQBn
# 8oalmOBUeRou09h0ZyKbC5YR4WOSmUKWfdJ5DJDBZV8uLD74w3LRbYP+vj/oCso7
# v0epo/Np22O/IjWll11lhJB9i0ZQVdgMknzSGksc8zxCi1LQsP1r4z4HLimb5j0b
# pdS1HXeUOeLpZMlEPXh6I/MTfaaQdION9MsmAkYqwooQu6SpBQyb7Wj6aC6VoCo/
# KmtYSWMfCWluWpiW5IP0wI/zRive/DvQvTXvbiWu5a8n7dDd8w6vmSiXmE0OPQvy
# CInWH8MyGOLwxS3OW560STkKxgrCxq2u5bLZ2xWIUUVYODJxJxp/sfQn+N4sOiBp
# mLJZiWhub6e3dMNABQamASooPoI/E01mC8CzTfXhj38cbxV9Rad25UAqZaPDXVJi
# hsMdYzaXht/a8/jyFqGaJ+HNpZfQ7l1jQeNbB5yHPgZ3BtEGsXUfFL5hYbXw3MYb
# BL7fQccOKO7eZS/sl/ahXJbYANahRr1Z85elCUtIEJmAH9AAKcWxm6U/RXceNcbS
# oqKfenoi+kiVH6v7RyOA9Z74v2u3S5fi63V4GuzqN5l5GEv/1rMjaHXmr/r8i+sL
# gOppO6/8MO0ETI7f33VtY5E90Z1WTk+/gFcioXgRMiF670EKsT/7qMykXcGhiJtX
# cVZOSEXAQsmbdlsKgEhr/Xmfwb1tbWrJUnMTDXpQzTGCGiIwghoeAgEBMIGVMH4x
# CzAJBgNVBAYTAlVTMRMwEQYDVQQIEwpXYXNoaW5ndG9uMRAwDgYDVQQHEwdSZWRt
# b25kMR4wHAYDVQQKExVNaWNyb3NvZnQgQ29ycG9yYXRpb24xKDAmBgNVBAMTH01p
# Y3Jvc29mdCBDb2RlIFNpZ25pbmcgUENBIDIwMTECEzMAAASEmOIS4HijMV0AAAAA
# BIQwDQYJYIZIAWUDBAIBBQCgga4wGQYJKoZIhvcNAQkDMQwGCisGAQQBgjcCAQQw
# HAYKKwYBBAGCNwIBCzEOMAwGCisGAQQBgjcCARUwLwYJKoZIhvcNAQkEMSIEIL7q
# +LaZPij7OykpRhMUgIwbwTXzjn5Jy2R7YMs3yBCmMEIGCisGAQQBgjcCAQwxNDAy
# oBSAEgBNAGkAYwByAG8AcwBvAGYAdKEagBhodHRwOi8vd3d3Lm1pY3Jvc29mdC5j
# b20wDQYJKoZIhvcNAQEBBQAEggEAP1A2DOnBzPQKxPZXthnIDtcHacx26gEzysXw
# NfM+fJSbI5RCziEOM+Ngz3rT5T1DYbvEMl7PCzzdxUVeJ+TqHf3FtlGCOg8QlScy
# JsngSUjPSkX7h3XyZcuW6+E0kB5Nl/tmBM3LAy1NSynersogAdMp0Rp8w7bSp1DI
# rGnKigdz2aD4V2BW7IRB4PB+0CCqAcIeT3f714at6xFZW/2r5JnhBToTQbeCPxj9
# 5/6pZv+e8MtrpKWF1e3KEIvcxjPf3btoXaj2a/Jgbz93b4Q0HJ9EeVQh8S2xRQHB
# dhN3XlLXTCR690T6Z4bzFy5mkITDF06e5jg108kzfzurpt0gG6GCF6wwgheoBgor
# BgEEAYI3AwMBMYIXmDCCF5QGCSqGSIb3DQEHAqCCF4UwgheBAgEDMQ8wDQYJYIZI
# AWUDBAIBBQAwggFZBgsqhkiG9w0BCRABBKCCAUgEggFEMIIBQAIBAQYKKwYBBAGE
# WQoDATAxMA0GCWCGSAFlAwQCAQUABCB73yRQe5NrsPwNG18j3WDgdG0N2vrE85kC
# Wn6uqarl2AIGaXPR7YSGGBIyMDI2MDMxMTE5MjcwMC4zOVowBIACAfSggdmkgdYw
# gdMxCzAJBgNVBAYTAlVTMRMwEQYDVQQIEwpXYXNoaW5ndG9uMRAwDgYDVQQHEwdS
# ZWRtb25kMR4wHAYDVQQKExVNaWNyb3NvZnQgQ29ycG9yYXRpb24xLTArBgNVBAsT
# JE1pY3Jvc29mdCBJcmVsYW5kIE9wZXJhdGlvbnMgTGltaXRlZDEnMCUGA1UECxMe
# blNoaWVsZCBUU1MgRVNOOjRDMUEtMDVFMC1EOTQ3MSUwIwYDVQQDExxNaWNyb3Nv
# ZnQgVGltZS1TdGFtcCBTZXJ2aWNloIIR+zCCBygwggUQoAMCAQICEzMAAAIYJdmS
# BeLn5eQAAQAAAhgwDQYJKoZIhvcNAQELBQAwfDELMAkGA1UEBhMCVVMxEzARBgNV
# BAgTCldhc2hpbmd0b24xEDAOBgNVBAcTB1JlZG1vbmQxHjAcBgNVBAoTFU1pY3Jv
# c29mdCBDb3Jwb3JhdGlvbjEmMCQGA1UEAxMdTWljcm9zb2Z0IFRpbWUtU3RhbXAg
# UENBIDIwMTAwHhcNMjUwODE0MTg0ODI1WhcNMjYxMTEzMTg0ODI1WjCB0zELMAkG
# A1UEBhMCVVMxEzARBgNVBAgTCldhc2hpbmd0b24xEDAOBgNVBAcTB1JlZG1vbmQx
# HjAcBgNVBAoTFU1pY3Jvc29mdCBDb3Jwb3JhdGlvbjEtMCsGA1UECxMkTWljcm9z
# b2Z0IElyZWxhbmQgT3BlcmF0aW9ucyBMaW1pdGVkMScwJQYDVQQLEx5uU2hpZWxk
# IFRTUyBFU046NEMxQS0wNUUwLUQ5NDcxJTAjBgNVBAMTHE1pY3Jvc29mdCBUaW1l
# LVN0YW1wIFNlcnZpY2UwggIiMA0GCSqGSIb3DQEBAQUAA4ICDwAwggIKAoICAQCx
# 3Ojq65AmoB/Eue8QF8i+PqScr6npucxcQVn9CM84XLCVyMN/MjwODWfMOXGbv+mp
# u+NaHK9rMqYXI7qps/AKV9GcjnuHk4KLGCk44IYklAhlJOIyC6LcHwM+IW0k9x/N
# G3cWyfGMtfAEiMaCeMZ+ZCXvN6MDVahgv+oGZCHD8UMVNZ5vF+jibREII7F/arCP
# fVo6NzZphR4+0sxcexco8UfS2nlIogX/20nFFKDQ1gS9CpWKWN7xpCQ93erMC7HY
# xzkcxIrg0xO1VUJgBYNRnin7qIMj23kE0IEix/migU1Ra3EKqekViItiQd8V/GFV
# QFnwsYbFiwDfqycPrmzYd/i3zqTR7xZ6Uf+6x+Fio4zfPbJojyuDTzrfUiTCpTPJ
# CgQ+oyweAF6bXGmY4ZIhSdW9OwC/6WYQIvZGqtw5mVlrHwrRqKKPyHpSRYE3YgD+
# KRpyRNIZVEFCZZZm4sVZX9PjG43OxwLRfvGjh962CmypoQDSNj9B6+RO8u/g6U03
# 144vws2HtWbRHrk/uhps5AOq1QUDAKCOA8nSJX+NAJowBw7dJikbnBIBiImSThcu
# M1KU3FTYh2OzWw5GGXuzssLqE5vttUAdXA43vgbF8U2IQgDoF+50A2OlAnSdRz+m
# kRelPimAMEexi1Xw7IpKMqwjE50VHt8gkiMNzwO9SQIDAQABo4IBSTCCAUUwHQYD
# VR0OBBYEFCQuocRcOhtjt0e6hAIFrixftovRMB8GA1UdIwQYMBaAFJ+nFV0AXmJd
# g/Tl0mWnG1M1GelyMF8GA1UdHwRYMFYwVKBSoFCGTmh0dHA6Ly93d3cubWljcm9z
# b2Z0LmNvbS9wa2lvcHMvY3JsL01pY3Jvc29mdCUyMFRpbWUtU3RhbXAlMjBQQ0El
# MjAyMDEwKDEpLmNybDBsBggrBgEFBQcBAQRgMF4wXAYIKwYBBQUHMAKGUGh0dHA6
# Ly93d3cubWljcm9zb2Z0LmNvbS9wa2lvcHMvY2VydHMvTWljcm9zb2Z0JTIwVGlt
# ZS1TdGFtcCUyMFBDQSUyMDIwMTAoMSkuY3J0MAwGA1UdEwEB/wQCMAAwFgYDVR0l
# AQH/BAwwCgYIKwYBBQUHAwgwDgYDVR0PAQH/BAQDAgeAMA0GCSqGSIb3DQEBCwUA
# A4ICAQCeSNGGPA+B2gim+3hiKhP+PQta4HEXcBEEpcMQ2CCtoq8LShE/BuMCaxec
# 8Sa26jkwPy4n1fD15ivGqqQrgMX2ydkyscx+ijEJr77WKsvPxiijMLi1yL5rg3ft
# JuR7Wm3XGz2pm2+Q+BkZafkFzBV+YDBJkseLYK5nTpjT9f63p80GetsxWi81oNfh
# Y93Ij0YTPF8iCAOxyTYimjhVcv8CtzPunYXtsRkZG7LGOAwL7CgKQMlof/KT/Bxm
# kCyLF7g8503QNbplvfk7cODf5rqmsA0xzdYh298oOXvk/RqpxBtABHtvR/iAfg0y
# RRy3RabgY3kqGwTVgrtX/ACoMqYriPHfMvPdrwezFr0cHcbKK2WYLmwOE6XhBMY3
# mRGLqgKhXiEr6QgWCeRaMeFJE2ibPfpCdsJIb8EcsSbYZFT27f8jjNR30TUAL3sg
# kQZ/Bv7Q1ZvdARyuTKl0Z1bCXQsQ5uGtBH0HVXv551zI2axfSnYFfSsWl3U+RclJ
# vF/whwSLD9uQ2BqBkT5WUO3Fd6u4t2jmTeUY6/us9i44RqhljEO9m2kc/0/frCZb
# gg2NHo0iefZQz6Ss//F4udFsMGSb1GyWegOFWtqWIoMfrYHGFyAv22JGA4eVwjTC
# q9VYt2/zJbyvGRrA6WEJGpPcQoQJbyS1QA/A1sFQuRP6hZy8FzCCB3EwggVZoAMC
# AQICEzMAAAAVxedrngKbSZkAAAAAABUwDQYJKoZIhvcNAQELBQAwgYgxCzAJBgNV
# BAYTAlVTMRMwEQYDVQQIEwpXYXNoaW5ndG9uMRAwDgYDVQQHEwdSZWRtb25kMR4w
# HAYDVQQKExVNaWNyb3NvZnQgQ29ycG9yYXRpb24xMjAwBgNVBAMTKU1pY3Jvc29m
# dCBSb290IENlcnRpZmljYXRlIEF1dGhvcml0eSAyMDEwMB4XDTIxMDkzMDE4MjIy
# NVoXDTMwMDkzMDE4MzIyNVowfDELMAkGA1UEBhMCVVMxEzARBgNVBAgTCldhc2hp
# bmd0b24xEDAOBgNVBAcTB1JlZG1vbmQxHjAcBgNVBAoTFU1pY3Jvc29mdCBDb3Jw
# b3JhdGlvbjEmMCQGA1UEAxMdTWljcm9zb2Z0IFRpbWUtU3RhbXAgUENBIDIwMTAw
# ggIiMA0GCSqGSIb3DQEBAQUAA4ICDwAwggIKAoICAQDk4aZM57RyIQt5osvXJHm9
# DtWC0/3unAcH0qlsTnXIyjVX9gF/bErg4r25PhdgM/9cT8dm95VTcVrifkpa/rg2
# Z4VGIwy1jRPPdzLAEBjoYH1qUoNEt6aORmsHFPPFdvWGUNzBRMhxXFExN6AKOG6N
# 7dcP2CZTfDlhAnrEqv1yaa8dq6z2Nr41JmTamDu6GnszrYBbfowQHJ1S/rboYiXc
# ag/PXfT+jlPP1uyFVk3v3byNpOORj7I5LFGc6XBpDco2LXCOMcg1KL3jtIckw+DJ
# j361VI/c+gVVmG1oO5pGve2krnopN6zL64NF50ZuyjLVwIYwXE8s4mKyzbnijYjk
# lqwBSru+cakXW2dg3viSkR4dPf0gz3N9QZpGdc3EXzTdEonW/aUgfX782Z5F37Zy
# L9t9X4C626p+Nuw2TPYrbqgSUei/BQOj0XOmTTd0lBw0gg/wEPK3Rxjtp+iZfD9M
# 269ewvPV2HM9Q07BMzlMjgK8QmguEOqEUUbi0b1qGFphAXPKZ6Je1yh2AuIzGHLX
# pyDwwvoSCtdjbwzJNmSLW6CmgyFdXzB0kZSU2LlQ+QuJYfM2BjUYhEfb3BvR/bLU
# HMVr9lxSUV0S2yW6r1AFemzFER1y7435UsSFF5PAPBXbGjfHCBUYP3irRbb1Hode
# 2o+eFnJpxq57t7c+auIurQIDAQABo4IB3TCCAdkwEgYJKwYBBAGCNxUBBAUCAwEA
# ATAjBgkrBgEEAYI3FQIEFgQUKqdS/mTEmr6CkTxGNSnPEP8vBO4wHQYDVR0OBBYE
# FJ+nFV0AXmJdg/Tl0mWnG1M1GelyMFwGA1UdIARVMFMwUQYMKwYBBAGCN0yDfQEB
# MEEwPwYIKwYBBQUHAgEWM2h0dHA6Ly93d3cubWljcm9zb2Z0LmNvbS9wa2lvcHMv
# RG9jcy9SZXBvc2l0b3J5Lmh0bTATBgNVHSUEDDAKBggrBgEFBQcDCDAZBgkrBgEE
# AYI3FAIEDB4KAFMAdQBiAEMAQTALBgNVHQ8EBAMCAYYwDwYDVR0TAQH/BAUwAwEB
# /zAfBgNVHSMEGDAWgBTV9lbLj+iiXGJo0T2UkFvXzpoYxDBWBgNVHR8ETzBNMEug
# SaBHhkVodHRwOi8vY3JsLm1pY3Jvc29mdC5jb20vcGtpL2NybC9wcm9kdWN0cy9N
# aWNSb29DZXJBdXRfMjAxMC0wNi0yMy5jcmwwWgYIKwYBBQUHAQEETjBMMEoGCCsG
# AQUFBzAChj5odHRwOi8vd3d3Lm1pY3Jvc29mdC5jb20vcGtpL2NlcnRzL01pY1Jv
# b0NlckF1dF8yMDEwLTA2LTIzLmNydDANBgkqhkiG9w0BAQsFAAOCAgEAnVV9/Cqt
# 4SwfZwExJFvhnnJL/Klv6lwUtj5OR2R4sQaTlz0xM7U518JxNj/aZGx80HU5bbsP
# MeTCj/ts0aGUGCLu6WZnOlNN3Zi6th542DYunKmCVgADsAW+iehp4LoJ7nvfam++
# Kctu2D9IdQHZGN5tggz1bSNU5HhTdSRXud2f8449xvNo32X2pFaq95W2KFUn0CS9
# QKC/GbYSEhFdPSfgQJY4rPf5KYnDvBewVIVCs/wMnosZiefwC2qBwoEZQhlSdYo2
# wh3DYXMuLGt7bj8sCXgU6ZGyqVvfSaN0DLzskYDSPeZKPmY7T7uG+jIa2Zb0j/aR
# AfbOxnT99kxybxCrdTDFNLB62FD+CljdQDzHVG2dY3RILLFORy3BFARxv2T5JL5z
# bcqOCb2zAVdJVGTZc9d/HltEAY5aGZFrDZ+kKNxnGSgkujhLmm77IVRrakURR6nx
# t67I6IleT53S0Ex2tVdUCbFpAUR+fKFhbHP+CrvsQWY9af3LwUFJfn6Tvsv4O+S3
# Fb+0zj6lMVGEvL8CwYKiexcdFYmNcP7ntdAoGokLjzbaukz5m/8K6TT4JDVnK+AN
# uOaMmdbhIurwJ0I9JZTmdHRbatGePu1+oDEzfbzL6Xu/OHBE0ZDxyKs6ijoIYn/Z
# cGNTTY3ugm2lBRDBcQZqELQdVTNYs6FwZvKhggNWMIICPgIBATCCAQGhgdmkgdYw
# gdMxCzAJBgNVBAYTAlVTMRMwEQYDVQQIEwpXYXNoaW5ndG9uMRAwDgYDVQQHEwdS
# ZWRtb25kMR4wHAYDVQQKExVNaWNyb3NvZnQgQ29ycG9yYXRpb24xLTArBgNVBAsT
# JE1pY3Jvc29mdCBJcmVsYW5kIE9wZXJhdGlvbnMgTGltaXRlZDEnMCUGA1UECxMe
# blNoaWVsZCBUU1MgRVNOOjRDMUEtMDVFMC1EOTQ3MSUwIwYDVQQDExxNaWNyb3Nv
# ZnQgVGltZS1TdGFtcCBTZXJ2aWNloiMKAQEwBwYFKw4DAhoDFQCda0atdaK40TxC
# sp+bgK0avnvP6aCBgzCBgKR+MHwxCzAJBgNVBAYTAlVTMRMwEQYDVQQIEwpXYXNo
# aW5ndG9uMRAwDgYDVQQHEwdSZWRtb25kMR4wHAYDVQQKExVNaWNyb3NvZnQgQ29y
# cG9yYXRpb24xJjAkBgNVBAMTHU1pY3Jvc29mdCBUaW1lLVN0YW1wIFBDQSAyMDEw
# MA0GCSqGSIb3DQEBCwUAAgUA7Vua9DAiGA8yMDI2MDMxMTA3NDAzNloYDzIwMjYw
# MzEyMDc0MDM2WjB0MDoGCisGAQQBhFkKBAExLDAqMAoCBQDtW5r0AgEAMAcCAQAC
# AgVnMAcCAQACAhOnMAoCBQDtXOx0AgEAMDYGCisGAQQBhFkKBAIxKDAmMAwGCisG
# AQQBhFkKAwKgCjAIAgEAAgMHoSChCjAIAgEAAgMBhqAwDQYJKoZIhvcNAQELBQAD
# ggEBADMyPxNxEZ5f5xha0u6MKl8f2wH1xIIZCp0FDAcO9NRWOUsMO77F1fsDWTiz
# n08ni9l4DWH/4rmfyzsWo4jc6QimHuNl8WN46RW2dCA2qfDJ3MdQYaCNYOZVy3sx
# b0hyeV2VUIvPK2Uc+liJcY+jbOtob8rG6QVTUPRSYEKMF94DBHJfNfM012hAGPc7
# BAjBBCFmokgcAbylnD3/iG3lKYlaaR2gKH1kM0C04MVJ3cpBbhM5z71pRaJIce1H
# QSWzigzdBkxjhxDH9n2hiKIqyf58/5/cdDEsdBNHvkux6PSklWQdJZVtHJZapXNf
# MfeJzSWTpOi0VhDTXbk8ck4dr7ExggQNMIIECQIBATCBkzB8MQswCQYDVQQGEwJV
# UzETMBEGA1UECBMKV2FzaGluZ3RvbjEQMA4GA1UEBxMHUmVkbW9uZDEeMBwGA1UE
# ChMVTWljcm9zb2Z0IENvcnBvcmF0aW9uMSYwJAYDVQQDEx1NaWNyb3NvZnQgVGlt
# ZS1TdGFtcCBQQ0EgMjAxMAITMwAAAhgl2ZIF4ufl5AABAAACGDANBglghkgBZQME
# AgEFAKCCAUowGgYJKoZIhvcNAQkDMQ0GCyqGSIb3DQEJEAEEMC8GCSqGSIb3DQEJ
# BDEiBCBNuYahQ98QMT3TV1fiZKFWmCeG5KqsDj6M6SKHBH4VBjCB+gYLKoZIhvcN
# AQkQAi8xgeowgecwgeQwgb0EIJkT3Im45Mi0jBZoRLqXMYorVdxKjPXKdHNo5XPH
# 14VqMIGYMIGApH4wfDELMAkGA1UEBhMCVVMxEzARBgNVBAgTCldhc2hpbmd0b24x
# EDAOBgNVBAcTB1JlZG1vbmQxHjAcBgNVBAoTFU1pY3Jvc29mdCBDb3Jwb3JhdGlv
# bjEmMCQGA1UEAxMdTWljcm9zb2Z0IFRpbWUtU3RhbXAgUENBIDIwMTACEzMAAAIY
# JdmSBeLn5eQAAQAAAhgwIgQgxpE9pquVaRCBN0U5ejp6Wk4zGcqI1NvVIGZtCDcJ
# 6aIwDQYJKoZIhvcNAQELBQAEggIANSo0R8iN5EQeMYQtqtqizJVk9kIHKZ1bY1JA
# xGCh4txaffcdJHnoJ09tHSr0vrS/JcCNt5KmsvJghhoHsbADSWKBIoq0G05r17fz
# vjTWzrmpn+1uOqkp+GDllKevvJJRNbxd6TZ9hE3SwydyCnZBnNIIuADJLc8PtbPX
# DQtSYe3L/MDNuoCrbT0C8gBea0c1mkxFHVhETa/8RRU+VWykR77G7ql8eW8zuZaJ
# Uho+oFWz6GnjjgdWTPrALXbkyajmXzabIhMvmkUw07u53E+vh6tw7PPKo8+qeuTJ
# 0ys5gXaIjzhJfgjAnI25JQFl29G/1d9a3DTiZc9T60QKKM0Ke9y+lBlrEd6W6qKp
# UFxpxcYC09Z4/4H1wIjMNZJH9kIDTw0j2eRv/g7tCwPGEd0/zLOYtzYEfNTZQfY1
# 7NcI34kOxZu4J11CoMmGltuCIjx4r/UHuSylcuO5ydNWbYVq5ZO4ZT9B2poNL0Bf
# bTBZpsSXvFTVzFHt85LrLdh2wsdQeXjp47A9xXSp6UAMWbDs+ZffaaQMGvxJSuda
# zi9oqwqGBYRHGjnn5OFcbFAmTVBQGA0pUm2tXM7k+jy4/jCU86DqSU5fJbp3lNvn
# iBl1j6859a4FEomXm7NwBpA0Ic2QW2d1hSGqLASF6bNfZwIIBiob76255/oFOrlt
# BRPfk70=
# SIG # End signature block