classes/OSConfig.ps1

# Copyright (c) Microsoft Corporation. All rights reserved.

function Get-ServerType() {
    try {
        $Value = Get-ItemPropertyValue -LiteralPath "HKLM:\SYSTEM\CurrentControlSet\Services\Netlogon\Parameters" -Name "SysvolReady"
        if (-not [String]::IsNullOrWhiteSpace($Value)) {
            return "Domain Controller"
        }
    } catch {
        # Ignored.
    }

    try {
        $Value = Get-ItemPropertyValue -LiteralPath "HKLM:\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters" -Name "Domain"
        if (-not [String]::IsNullOrWhiteSpace($Value)) {
            return "Member Server"
        }
    } catch {
        # Ignored.
    }

    return "Workgroup Member"
}

function Get-EnvironmentType {
    $Properties = Get-ItemProperty -Path "HKLM:\SOFTWARE\Microsoft\Windows NT\CurrentVersion"

    if ($Properties.InstallationType -match "Server") {
        if ($Properties.EditionId -eq "ServerAzureStackHCICor") {
            $InstallationType = "AzureLocal"

            if ($Properties.DisplayVersion -eq "24H2") {
                $Version = "24H2"
            } elseif ($Properties.DisplayVersion -eq "23H2") {
                $Version = "23H2"
            } else {
                return
            }
        } else {
            $InstallationType = "WindowsServer"

            # We need to have the necessary update for Windows Server 2022 and Windows Server 23H2
            # but not for Windows Server 2025. We can use the UBR (Update Build Revision) to
            # determine the version.

            if ($Properties.DisplayVersion -eq "24H2") {
                $Version = "2025"
            } elseif (($Properties.DisplayVersion -eq "23H2") -and ($Properties.UBR -ge 1369)) {
                $Version = "2022"
            } elseif (($Properties.DisplayVersion -eq "21H2") -and ($Properties.UBR -ge 3091)) {
                $Version = "2022"
            } else {
                return
            }
        }
    } else {
        return
    }

    $Role = (Get-ServerType) -replace " ", ""

    "$InstallationType\$Version\$Role"
}

function ConvertFrom-Expression($Expression) {
    if ($Expression -isnot [String] -or [String]::IsNullOrWhiteSpace($Expression)) {
        throw [InvalidValueException]::new($Strings.ErrorInvalidExpression -f $Expression)
    }

    # JSON object format
    if ($Expression.TrimStart().StartsWith('{')) {
        $JsonObj = ConvertFrom-Json -InputObject $Expression -ErrorAction SilentlyContinue
        if ($null -ne $JsonObj) {
            $Result = @()
            foreach ($Property in $JsonObj.PSObject.Properties) {
                $Result += [PSCustomObject]@{ Name = $Property.Name; Value = $Property.Value }
            }
            if ($Result.Count -gt 0) {
                return , $Result
            }
        }
    }

    # Semicolon-delimited format
    $InQuotes = $False
    $ProcessedExpression = $Expression.Clone()

    for ($i = 0; $i -lt $Expression.Length; $i++) {
        if ($Expression[$i] -eq '"') {
            $InQuotes = -not $InQuotes
            continue
        }

        if ($InQuotes) {
            continue
        }

        if ($Expression[$i] -eq ";") {
            $ProcessedExpression = $ProcessedExpression.Remove($i, 1).Insert($i, "`n")
        }
    }

    try {
        $Result = @($ProcessedExpression | ConvertFrom-Csv -Header @("Name", "Value") -Delimiter ":")

        if (($Result.Count -eq 1) -and (-not $Result.Value)) {
            $Result[0].Value = $Result[0].Name
            $Result[0].Name = "*"
        }

        , $Result
    } catch {
        throw [InvalidValueException]::new($Strings.ErrorInvalidExpression -f $Expression)
    }
}

function Find-Rule($Name, $Rules) {
    # First pass: exact or wildcard match
    foreach ($Rule in $Rules) {
        $InclusionRule = -not $Rule.Name.StartsWith("!")
        $RuleName = if ($InclusionRule) { $Rule.Name } else { $Rule.Name.Substring(1) }

        if ($Name -like $RuleName) {
            return $(if ($InclusionRule) { $Rule } else { $null })
        }
    }

    # Second pass: segment-boundary suffix match
    foreach ($Rule in $Rules) {
        $InclusionRule = -not $Rule.Name.StartsWith("!")
        $RuleName = if ($InclusionRule) { $Rule.Name } else { $Rule.Name.Substring(1) }

        if ($Name -like "*\$RuleName") {
            return $(if ($InclusionRule) { $Rule } else { $null })
        }
    }
}

class OSConfigReason {
    [DscProperty()]
    [String] $Code

    [DscProperty()]
    [String] $Phrase

    OSConfigReason() { }

    OSConfigReason([String] $RuleId, [String] $Severity, [Bool] $IsCompliant, [String] $Reason) {
        $Status = if ($IsCompliant) { 'BaselineSettingCompliant' } else { 'BaselineSettingNotCompliant' }

        if ($RuleId) {
            $Status = "$Status`:$RuleId"
        }

        $this.Code = $Status

        if (-not [String]::IsNullOrWhiteSpace($Severity)) {
            $this.Phrase = "[$Severity] $Reason"
        } else {
            $this.Phrase = $Reason
        }
    }
}

[DscResource()]
class OSConfig {
    [DscProperty()]
    [String] $RuleId

    [DscProperty()]
    [String] $Severity

    [DscProperty()]
    [String] $CorrelationGroup

    [DscProperty(Key)]
    [String] $Name

    [DscProperty(Key)]
    [String] $Type

    [DscProperty(Key)]
    [String] $Properties

    [DscProperty()]
    [String] $Value

    [DscProperty()]
    [String] $ValueType

    [DscProperty()]
    [String] $ValueName = 'value'

    [DscProperty()]
    [String] $Schema

    [DscProperty()]
    [Bool] $ExtendSchema

    [DscProperty()]
    [String] $Expression

    [DscProperty()]
    [String] $Template

    [DscProperty()]
    [Bool] $IsJsonValue = $False

    [DscProperty()]
    [String] $RoleFilter

    [DscProperty()]
    [String] $VersionFilter

    [DscProperty(NotConfigurable)]
    [OSConfigReason[]] $Reasons

    hidden [Bool] $IsCompliant = $True

    [OSConfig] Get() {
        $CurrentState = [OSConfig]::new()

        $CurrentState.RuleId = $this.RuleId
        $CurrentState.Severity = $this.Severity
        $CurrentState.Name = $this.Name
        $CurrentState.Type = $this.Type
        $CurrentState.Properties = $this.Properties
        $CurrentState.Value = $this.Value
        $CurrentState.Schema = $this.Schema
        $CurrentState.ExtendSchema = $this.ExtendSchema
        $CurrentState.ValueType = $this.ValueType
        $CurrentState.IsJsonValue = $this.IsJsonValue
        $CurrentState.RoleFilter = $this.RoleFilter
        $CurrentState.VersionFilter = $this.VersionFilter
        $CurrentState.Reasons = @()

        $env:OSCONFIG_LOG_DIR = "$PSScriptRoot\logs"
        $env:DMOSCONFIG_AUTHORITY = $Script:Constants.Authority.Cloud

        try {
            $ErrorActionPreference = 'Stop'

            if (-not $this.IsApplicable()) {
                $CurrentState.IsCompliant = $True
                $CurrentState.Reasons += [OSConfigReason]::new($this.RuleId, $null, $CurrentState.IsCompliant, 'Not applicable')
                return $CurrentState
            }

            $ActualValue = $this.GetActualValue()

            $ResourceProperties = @{
                'resource' = @{
                    'name'       = $this.Name
                    'type'       = $this.Type
                    'properties' = $this.Properties | ConvertFrom-Json
                }
                'template' = $this.GetTemplate($ActualValue)
            }

            $ResourceSchema = $this.GetSchema($ActualValue)
            $ResourceExpression = $this.Expression

            if ($ResourceExpression) {
                $ResourceProperties['expression'] = $ResourceExpression
            } elseif ($ResourceSchema) {
                $ResourceProperties['schema'] = $ResourceSchema
            }

            $Resource = @{
                Name       = $this.Name
                Type       = 'Microsoft.OSConfig/Test'
                Properties = $ResourceProperties
            }

            $Output = Invoke-Native exec resource --correlation-id $(Get-CorrelationId) --correlation-group $this.CorrelationGroup --mode get --name $Resource.Name --type $Resource.Type --properties (ConvertTo-Json -InputObject $Resource.Properties -Compress -Depth 32)

            $CurrentState.IsCompliant = $Output.Properties.Compliance.Status -eq 'compliant'
            $CurrentState.Reasons += [OSConfigReason]::new($this.RuleId, $CurrentState.Severity, $CurrentState.IsCompliant, $Output.Properties.Compliance.Reason)
        } catch {
            $CurrentState.IsCompliant = $False
            $CurrentState.Reasons += [OSConfigReason]::new($this.RuleId, $CurrentState.Severity, $CurrentState.IsCompliant, "$_")
            Write-Verbose "Error: $_"
        }

        return $CurrentState
    }

    [Bool] Test() {
        try {
            return $this.Get().IsCompliant
        } catch {
            Write-Verbose "Error: $_"
        }

        return $False
    }

    [Void] Set() {
        try {
            $env:OSCONFIG_LOG_DIR = "$PSScriptRoot\logs"
            $env:DMOSCONFIG_AUTHORITY = $Script:Constants.Authority.Cloud

            if (-not $this.CorrelationGroup) {
                throw "No correlation group specified."
            }

            $ResourceProperties = $this.Properties | ConvertFrom-Json

            if ($this.ValueName) {
                $ResourceProperties | Add-Member -MemberType NoteProperty -Name $this.ValueName -Value $this.GetActualValue()
            }

            Invoke-Native exec resource --correlation-id $(Get-CorrelationId) --correlation-group $this.CorrelationGroup --mode set --name $this.Name --type $this.type --properties $ResourceProperties
        } catch {
            Write-Verbose "Error: $_"
        }
    }

    [Bool] IsApplicable() {
        if (-not [String]::IsNullOrWhiteSpace($this.RoleFilter)) {
            $CurrentRole = Get-ServerType
            $AllowedRoles = $this.RoleFilter -split ',' | ForEach-Object { $_.Trim() }

            if ($AllowedRoles -notcontains $CurrentRole) {
                return $False
            }
        }

        if (-not [String]::IsNullOrWhiteSpace($this.VersionFilter)) {
            $CurrentVersion = Get-WindowsServerVersion

            if (-not $CurrentVersion) {
                return $False
            }

            $AllowedVersions = $this.VersionFilter -split ',' | ForEach-Object { $_.Trim() }

            if ($AllowedVersions -notcontains $CurrentVersion) {
                return $False
            }
        }

        if ($this.IsJsonValue -and -not [String]::IsNullOrWhiteSpace($this.Value)) {
            $JsonObj = ConvertFrom-Json -InputObject $this.Value -ErrorAction SilentlyContinue
            if ($null -eq $JsonObj) {
                return $False
            }

            $JsonRules = @($JsonObj.PSObject.Properties | ForEach-Object {
                [PSCustomObject]@{ Name = $_.Name; Value = $_.Value }
            })

            if ($JsonRules.Count -eq 0) {
                return $False
            }

            $Role = (Get-ServerType) -replace " ", ""
            if ($null -eq (Find-Rule -Name $Role -Rules $JsonRules)) {
                return $False
            }
        }

        # If there is no schema or expression, there must be a value to generate the compliance reasoning.
        # Omitting the schema and expression will provide a default compliance reasoning based on the value.
        if (-not $this.Schema -and -not $this.Expression -and -not $this.Value) {
            if ($this.ValueType -ne 'string[]') {
                throw "No value, schema, or expression specified to evaluate compliance."
            }
        }

        return $True
    }

    [PSCustomObject] GetDefaultSchema([PSCustomObject] $ActualValue) {
        if ($null -eq $ActualValue) {
            return @{ 'type' = 'null' }
        }

        switch ($this.ValueType) {
            'string' {
                return @{ 'type' = 'string'; 'const' = $ActualValue }
            }
            'string[]' {
                $ArraySchema = @{
                    'type'        = 'array'
                    'items'       = @{
                        'type' = 'string'
                        'enum' = $ActualValue
                    }
                    'minItems'    = $ActualValue.Count
                    'maxItems'    = $ActualValue.Count
                    'uniqueItems' = $True
                }
                if ($ActualValue.Count -eq 0) {
                    return @{ 'anyOf' = @( @{ 'type' = 'null' }, $ArraySchema ) }
                }
                return $ArraySchema
            }
            'integer' {
                return @{ 'type' = 'integer'; 'const' = $ActualValue }
            }
            'boolean' {
                return @{ 'type' = 'boolean'; 'const' = $ActualValue }
            }
        }

        return @{ 'const' = $ActualValue }
    }

    [PSCustomObject] GetSchema([PSCustomObject] $ActualValue) {
        $DefaultSchema = $this.GetDefaultSchema($ActualValue)
        $CustomSchema = if ($this.Schema) { ConvertFrom-Json -InputObject $this.Schema }

        if ($this.ExtendSchema -and $CustomSchema) {
            return @{
                'allOf' = @(
                    $DefaultSchema,
                    $CustomSchema
                )
            }
        } elseif ($CustomSchema) {
            return $CustomSchema
        } else {
            return $DefaultSchema
        }
    }

    [String] GetTemplate([PSCustomObject] $ActualValue) {
        if ($this.Template) {
            return $this.Template
        }

        if ($null -eq $ActualValue) {
            return "The value {value} must be (null)"
        }

        return "The value {value} must be $(ConvertTo-Json -InputObject $ActualValue -Compress)."
    }

    [PSCustomObject] GetActualValue() {
        $Rules = if (-not [String]::IsNullOrWhiteSpace($this.Value)) {
            ConvertFrom-Expression -Expression $this.Value
        }

        if ($this.IsJsonValue) {
            $Role = (Get-ServerType) -replace " ", ""
            $Rule = Find-Rule -Name $Role -Rules $Rules
        } else {
            $EnvironmentType = Get-EnvironmentType
            $Rule = Find-Rule -Name $EnvironmentType -Rules $Rules
        }

        $StringValue = if ($null -ne $Rule) {
            $Rule.Value
        } elseif ($this.Value -or ($this.ValueType -eq 'string[]')) {
            $this.Value
        } else {
            (ConvertFrom-Json -InputObject $this.Properties).$($this.ValueName)
        }

        if ($null -eq $StringValue) {
            return $null
        }

        try {
            switch ($this.ValueType) {
                'string' {
                    return $StringValue
                }
                'integer' {
                    return [Int64]::Parse($StringValue)
                }
                'boolean' {
                    if ([Int32]::TryParse($StringValue, [ref]$null)) {
                        return [Boolean]::Parse(([Int32]$StringValue -ne 0).ToString())
                    } else {
                        return [Boolean]::Parse($StringValue)
                    }
                }
                'string[]' {
                    if ([String]::IsNullOrWhiteSpace($StringValue)) {
                        return @()
                    } else {
                        return @($StringValue -split ',' | ForEach-Object { $_.Trim() })
                    }
                }
            }
        } catch {
            throw "Unable to convert value '$StringValue' to type '$($this.ValueType)'"
        }

        return $StringValue
    }
}

# SIG # Begin signature block
# MIIoVQYJKoZIhvcNAQcCoIIoRjCCKEICAQExDzANBglghkgBZQMEAgEFADB5Bgor
# BgEEAYI3AgEEoGswaTA0BgorBgEEAYI3AgEeMCYCAwEAAAQQH8w7YFlLCE63JNLG
# KX7zUQIBAAIBAAIBAAIBAAIBADAxMA0GCWCGSAFlAwQCAQUABCAeybLhzj91H4cg
# pjL/s2g399rizsJ1v8TBXCLyRydlTaCCDYUwggYDMIID66ADAgECAhMzAAAEhJji
# EuB4ozFdAAAAAASEMA0GCSqGSIb3DQEBCwUAMH4xCzAJBgNVBAYTAlVTMRMwEQYD
# VQQIEwpXYXNoaW5ndG9uMRAwDgYDVQQHEwdSZWRtb25kMR4wHAYDVQQKExVNaWNy
# b3NvZnQgQ29ycG9yYXRpb24xKDAmBgNVBAMTH01pY3Jvc29mdCBDb2RlIFNpZ25p
# bmcgUENBIDIwMTEwHhcNMjUwNjE5MTgyMTM1WhcNMjYwNjE3MTgyMTM1WjB0MQsw
# CQYDVQQGEwJVUzETMBEGA1UECBMKV2FzaGluZ3RvbjEQMA4GA1UEBxMHUmVkbW9u
# ZDEeMBwGA1UEChMVTWljcm9zb2Z0IENvcnBvcmF0aW9uMR4wHAYDVQQDExVNaWNy
# b3NvZnQgQ29ycG9yYXRpb24wggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIB
# AQDtekqMKDnzfsyc1T1QpHfFtr+rkir8ldzLPKmMXbRDouVXAsvBfd6E82tPj4Yz
# aSluGDQoX3NpMKooKeVFjjNRq37yyT/h1QTLMB8dpmsZ/70UM+U/sYxvt1PWWxLj
# MNIXqzB8PjG6i7H2YFgk4YOhfGSekvnzW13dLAtfjD0wiwREPvCNlilRz7XoFde5
# KO01eFiWeteh48qUOqUaAkIznC4XB3sFd1LWUmupXHK05QfJSmnei9qZJBYTt8Zh
# ArGDh7nQn+Y1jOA3oBiCUJ4n1CMaWdDhrgdMuu026oWAbfC3prqkUn8LWp28H+2S
# LetNG5KQZZwvy3Zcn7+PQGl5AgMBAAGjggGCMIIBfjAfBgNVHSUEGDAWBgorBgEE
# AYI3TAgBBggrBgEFBQcDAzAdBgNVHQ4EFgQUBN/0b6Fh6nMdE4FAxYG9kWCpbYUw
# VAYDVR0RBE0wS6RJMEcxLTArBgNVBAsTJE1pY3Jvc29mdCBJcmVsYW5kIE9wZXJh
# dGlvbnMgTGltaXRlZDEWMBQGA1UEBRMNMjMwMDEyKzUwNTM2MjAfBgNVHSMEGDAW
# gBRIbmTlUAXTgqoXNzcitW2oynUClTBUBgNVHR8ETTBLMEmgR6BFhkNodHRwOi8v
# d3d3Lm1pY3Jvc29mdC5jb20vcGtpb3BzL2NybC9NaWNDb2RTaWdQQ0EyMDExXzIw
# MTEtMDctMDguY3JsMGEGCCsGAQUFBwEBBFUwUzBRBggrBgEFBQcwAoZFaHR0cDov
# L3d3dy5taWNyb3NvZnQuY29tL3BraW9wcy9jZXJ0cy9NaWNDb2RTaWdQQ0EyMDEx
# XzIwMTEtMDctMDguY3J0MAwGA1UdEwEB/wQCMAAwDQYJKoZIhvcNAQELBQADggIB
# AGLQps1XU4RTcoDIDLP6QG3NnRE3p/WSMp61Cs8Z+JUv3xJWGtBzYmCINmHVFv6i
# 8pYF/e79FNK6P1oKjduxqHSicBdg8Mj0k8kDFA/0eU26bPBRQUIaiWrhsDOrXWdL
# m7Zmu516oQoUWcINs4jBfjDEVV4bmgQYfe+4/MUJwQJ9h6mfE+kcCP4HlP4ChIQB
# UHoSymakcTBvZw+Qst7sbdt5KnQKkSEN01CzPG1awClCI6zLKf/vKIwnqHw/+Wvc
# Ar7gwKlWNmLwTNi807r9rWsXQep1Q8YMkIuGmZ0a1qCd3GuOkSRznz2/0ojeZVYh
# ZyohCQi1Bs+xfRkv/fy0HfV3mNyO22dFUvHzBZgqE5FbGjmUnrSr1x8lCrK+s4A+
# bOGp2IejOphWoZEPGOco/HEznZ5Lk6w6W+E2Jy3PHoFE0Y8TtkSE4/80Y2lBJhLj
# 27d8ueJ8IdQhSpL/WzTjjnuYH7Dx5o9pWdIGSaFNYuSqOYxrVW7N4AEQVRDZeqDc
# fqPG3O6r5SNsxXbd71DCIQURtUKss53ON+vrlV0rjiKBIdwvMNLQ9zK0jy77owDy
# XXoYkQxakN2uFIBO1UNAvCYXjs4rw3SRmBX9qiZ5ENxcn/pLMkiyb68QdwHUXz+1
# fI6ea3/jjpNPz6Dlc/RMcXIWeMMkhup/XEbwu73U+uz/MIIHejCCBWKgAwIBAgIK
# YQ6Q0gAAAAAAAzANBgkqhkiG9w0BAQsFADCBiDELMAkGA1UEBhMCVVMxEzARBgNV
# BAgTCldhc2hpbmd0b24xEDAOBgNVBAcTB1JlZG1vbmQxHjAcBgNVBAoTFU1pY3Jv
# c29mdCBDb3Jwb3JhdGlvbjEyMDAGA1UEAxMpTWljcm9zb2Z0IFJvb3QgQ2VydGlm
# aWNhdGUgQXV0aG9yaXR5IDIwMTEwHhcNMTEwNzA4MjA1OTA5WhcNMjYwNzA4MjEw
# OTA5WjB+MQswCQYDVQQGEwJVUzETMBEGA1UECBMKV2FzaGluZ3RvbjEQMA4GA1UE
# BxMHUmVkbW9uZDEeMBwGA1UEChMVTWljcm9zb2Z0IENvcnBvcmF0aW9uMSgwJgYD
# VQQDEx9NaWNyb3NvZnQgQ29kZSBTaWduaW5nIFBDQSAyMDExMIICIjANBgkqhkiG
# 9w0BAQEFAAOCAg8AMIICCgKCAgEAq/D6chAcLq3YbqqCEE00uvK2WCGfQhsqa+la
# UKq4BjgaBEm6f8MMHt03a8YS2AvwOMKZBrDIOdUBFDFC04kNeWSHfpRgJGyvnkmc
# 6Whe0t+bU7IKLMOv2akrrnoJr9eWWcpgGgXpZnboMlImEi/nqwhQz7NEt13YxC4D
# dato88tt8zpcoRb0RrrgOGSsbmQ1eKagYw8t00CT+OPeBw3VXHmlSSnnDb6gE3e+
# lD3v++MrWhAfTVYoonpy4BI6t0le2O3tQ5GD2Xuye4Yb2T6xjF3oiU+EGvKhL1nk
# kDstrjNYxbc+/jLTswM9sbKvkjh+0p2ALPVOVpEhNSXDOW5kf1O6nA+tGSOEy/S6
# A4aN91/w0FK/jJSHvMAhdCVfGCi2zCcoOCWYOUo2z3yxkq4cI6epZuxhH2rhKEmd
# X4jiJV3TIUs+UsS1Vz8kA/DRelsv1SPjcF0PUUZ3s/gA4bysAoJf28AVs70b1FVL
# 5zmhD+kjSbwYuER8ReTBw3J64HLnJN+/RpnF78IcV9uDjexNSTCnq47f7Fufr/zd
# sGbiwZeBe+3W7UvnSSmnEyimp31ngOaKYnhfsi+E11ecXL93KCjx7W3DKI8sj0A3
# T8HhhUSJxAlMxdSlQy90lfdu+HggWCwTXWCVmj5PM4TasIgX3p5O9JawvEagbJjS
# 4NaIjAsCAwEAAaOCAe0wggHpMBAGCSsGAQQBgjcVAQQDAgEAMB0GA1UdDgQWBBRI
# bmTlUAXTgqoXNzcitW2oynUClTAZBgkrBgEEAYI3FAIEDB4KAFMAdQBiAEMAQTAL
# BgNVHQ8EBAMCAYYwDwYDVR0TAQH/BAUwAwEB/zAfBgNVHSMEGDAWgBRyLToCMZBD
# uRQFTuHqp8cx0SOJNDBaBgNVHR8EUzBRME+gTaBLhklodHRwOi8vY3JsLm1pY3Jv
# c29mdC5jb20vcGtpL2NybC9wcm9kdWN0cy9NaWNSb29DZXJBdXQyMDExXzIwMTFf
# MDNfMjIuY3JsMF4GCCsGAQUFBwEBBFIwUDBOBggrBgEFBQcwAoZCaHR0cDovL3d3
# dy5taWNyb3NvZnQuY29tL3BraS9jZXJ0cy9NaWNSb29DZXJBdXQyMDExXzIwMTFf
# MDNfMjIuY3J0MIGfBgNVHSAEgZcwgZQwgZEGCSsGAQQBgjcuAzCBgzA/BggrBgEF
# BQcCARYzaHR0cDovL3d3dy5taWNyb3NvZnQuY29tL3BraW9wcy9kb2NzL3ByaW1h
# cnljcHMuaHRtMEAGCCsGAQUFBwICMDQeMiAdAEwAZQBnAGEAbABfAHAAbwBsAGkA
# YwB5AF8AcwB0AGEAdABlAG0AZQBuAHQALiAdMA0GCSqGSIb3DQEBCwUAA4ICAQBn
# 8oalmOBUeRou09h0ZyKbC5YR4WOSmUKWfdJ5DJDBZV8uLD74w3LRbYP+vj/oCso7
# v0epo/Np22O/IjWll11lhJB9i0ZQVdgMknzSGksc8zxCi1LQsP1r4z4HLimb5j0b
# pdS1HXeUOeLpZMlEPXh6I/MTfaaQdION9MsmAkYqwooQu6SpBQyb7Wj6aC6VoCo/
# KmtYSWMfCWluWpiW5IP0wI/zRive/DvQvTXvbiWu5a8n7dDd8w6vmSiXmE0OPQvy
# CInWH8MyGOLwxS3OW560STkKxgrCxq2u5bLZ2xWIUUVYODJxJxp/sfQn+N4sOiBp
# mLJZiWhub6e3dMNABQamASooPoI/E01mC8CzTfXhj38cbxV9Rad25UAqZaPDXVJi
# hsMdYzaXht/a8/jyFqGaJ+HNpZfQ7l1jQeNbB5yHPgZ3BtEGsXUfFL5hYbXw3MYb
# BL7fQccOKO7eZS/sl/ahXJbYANahRr1Z85elCUtIEJmAH9AAKcWxm6U/RXceNcbS
# oqKfenoi+kiVH6v7RyOA9Z74v2u3S5fi63V4GuzqN5l5GEv/1rMjaHXmr/r8i+sL
# gOppO6/8MO0ETI7f33VtY5E90Z1WTk+/gFcioXgRMiF670EKsT/7qMykXcGhiJtX
# cVZOSEXAQsmbdlsKgEhr/Xmfwb1tbWrJUnMTDXpQzTGCGiYwghoiAgEBMIGVMH4x
# CzAJBgNVBAYTAlVTMRMwEQYDVQQIEwpXYXNoaW5ndG9uMRAwDgYDVQQHEwdSZWRt
# b25kMR4wHAYDVQQKExVNaWNyb3NvZnQgQ29ycG9yYXRpb24xKDAmBgNVBAMTH01p
# Y3Jvc29mdCBDb2RlIFNpZ25pbmcgUENBIDIwMTECEzMAAASEmOIS4HijMV0AAAAA
# BIQwDQYJYIZIAWUDBAIBBQCgga4wGQYJKoZIhvcNAQkDMQwGCisGAQQBgjcCAQQw
# HAYKKwYBBAGCNwIBCzEOMAwGCisGAQQBgjcCARUwLwYJKoZIhvcNAQkEMSIEIMci
# QcC9tFYLlSaYoPIDqmqX3pSR/5pjV9Lx84pm9DcHMEIGCisGAQQBgjcCAQwxNDAy
# oBSAEgBNAGkAYwByAG8AcwBvAGYAdKEagBhodHRwOi8vd3d3Lm1pY3Jvc29mdC5j
# b20wDQYJKoZIhvcNAQEBBQAEggEAI/XwYon23BtHTlcbKXHS19M+2Vpf+x9PCuSv
# GROC2LETyePApGhv9DolaynT8WQyfSVDz9OE5WOBjq5fG8ddyJUBGAcbVBqO0y0D
# cewaMAKvtNCkbewJtYzaodkIma9MdAWTUr0ZImrrr1q6HWWBST24MB3gednkEhVE
# JdkUECZHGPeQK/2oR7o/SYvsRUn8CwPYJa3PliKaGiBDjR8V3MsGvs2D5r+yUsFq
# UslhyBf8Zy9YCqAzANuNo5aVSV+05b1Osb5Z43tFuLCvFEitUObgEKMadr5k94R1
# pc5ua8mB6exQmFHwnBec0EEtDViolbJrERmXAVpp65rhE5hN66GCF7AwghesBgor
# BgEEAYI3AwMBMYIXnDCCF5gGCSqGSIb3DQEHAqCCF4kwgheFAgEDMQ8wDQYJYIZI
# AWUDBAIBBQAwggFaBgsqhkiG9w0BCRABBKCCAUkEggFFMIIBQQIBAQYKKwYBBAGE
# WQoDATAxMA0GCWCGSAFlAwQCAQUABCCChqWtOmUxN7QdcWTpto/1y5M4kmW+jBhb
# lueTzrbdVwIGabxUxxJbGBMyMDI2MDQyMTA1MTUzMC4xMjFaMASAAgH0oIHZpIHW
# MIHTMQswCQYDVQQGEwJVUzETMBEGA1UECBMKV2FzaGluZ3RvbjEQMA4GA1UEBxMH
# UmVkbW9uZDEeMBwGA1UEChMVTWljcm9zb2Z0IENvcnBvcmF0aW9uMS0wKwYDVQQL
# EyRNaWNyb3NvZnQgSXJlbGFuZCBPcGVyYXRpb25zIExpbWl0ZWQxJzAlBgNVBAsT
# Hm5TaGllbGQgVFNTIEVTTjoyRDFBLTA1RTAtRDk0NzElMCMGA1UEAxMcTWljcm9z
# b2Z0IFRpbWUtU3RhbXAgU2VydmljZaCCEf4wggcoMIIFEKADAgECAhMzAAACEtEI
# BjzKGE+qAAEAAAISMA0GCSqGSIb3DQEBCwUAMHwxCzAJBgNVBAYTAlVTMRMwEQYD
# VQQIEwpXYXNoaW5ndG9uMRAwDgYDVQQHEwdSZWRtb25kMR4wHAYDVQQKExVNaWNy
# b3NvZnQgQ29ycG9yYXRpb24xJjAkBgNVBAMTHU1pY3Jvc29mdCBUaW1lLVN0YW1w
# IFBDQSAyMDEwMB4XDTI1MDgxNDE4NDgxNVoXDTI2MTExMzE4NDgxNVowgdMxCzAJ
# BgNVBAYTAlVTMRMwEQYDVQQIEwpXYXNoaW5ndG9uMRAwDgYDVQQHEwdSZWRtb25k
# MR4wHAYDVQQKExVNaWNyb3NvZnQgQ29ycG9yYXRpb24xLTArBgNVBAsTJE1pY3Jv
# c29mdCBJcmVsYW5kIE9wZXJhdGlvbnMgTGltaXRlZDEnMCUGA1UECxMeblNoaWVs
# ZCBUU1MgRVNOOjJEMUEtMDVFMC1EOTQ3MSUwIwYDVQQDExxNaWNyb3NvZnQgVGlt
# ZS1TdGFtcCBTZXJ2aWNlMIICIjANBgkqhkiG9w0BAQEFAAOCAg8AMIICCgKCAgEA
# r0zToDkpWQtsZekS0cV0quDdKSTGkovvBaZH0OAIEi0O3CcO77JiX8c4Epq9uibH
# VZZ1W/LoufE172vkRXO+QYNtWWorECJ2AcZQ10bpAltkhZNiXlVJ8L3QzhKgrXrm
# Mkm2J+/g81U23JPcO4wXHEftonT3wpd//936rjmwxMm7NkbsygbJf+4AVBMNr4aM
# PQhBd76od0KMB6WrvyEGOOU0893OFufS5EDey4n44WgaxJE0Vnv3/OOvuOw5Kp1K
# PqjjYJ+L9ywLuBMtcDfLpNQO/h1eFEoMrbiEM67TOfNlXfxbDz4MlsYvLioxgd2X
# zey1QxrV1+i+JyVDJMiSe9gKOuzpiQQFE19DUPgsidyjLTzXEhSVLBlRor0eCVf7
# gC6Rfk8NY3rO2sggOL79vU5FuDKTh/sIOtcUHeHC42jBGB+tfdKC1KOBR+UlN9aO
# zg8mpUNI2FgqQvirVP9ppbeMUfvp2wA9voyTiRWvDgzCxo8xlJ1nscYTHIQrmkF9
# j/Ca0IDmt8fvOn64nnlJOGUYZYHMC1l0xtgkYTE1ESUqqkawKk7iqbxdnLyycS+d
# R+zaxPudMDLrQFz8lgfy9obk0D8HC2dzhWpYNn5hdkoPEzgCqQUOp8v3Qj/sd4an
# yupe5KoCkjABOP3yhSQ4W9Z+DrJnhM/rbsXC7oTv26cCAwEAAaOCAUkwggFFMB0G
# A1UdDgQWBBRSBblSxb5cYKYOwvd/VfoXOfu33jAfBgNVHSMEGDAWgBSfpxVdAF5i
# XYP05dJlpxtTNRnpcjBfBgNVHR8EWDBWMFSgUqBQhk5odHRwOi8vd3d3Lm1pY3Jv
# c29mdC5jb20vcGtpb3BzL2NybC9NaWNyb3NvZnQlMjBUaW1lLVN0YW1wJTIwUENB
# JTIwMjAxMCgxKS5jcmwwbAYIKwYBBQUHAQEEYDBeMFwGCCsGAQUFBzAChlBodHRw
# Oi8vd3d3Lm1pY3Jvc29mdC5jb20vcGtpb3BzL2NlcnRzL01pY3Jvc29mdCUyMFRp
# bWUtU3RhbXAlMjBQQ0ElMjAyMDEwKDEpLmNydDAMBgNVHRMBAf8EAjAAMBYGA1Ud
# JQEB/wQMMAoGCCsGAQUFBwMIMA4GA1UdDwEB/wQEAwIHgDANBgkqhkiG9w0BAQsF
# AAOCAgEAXnSAkmX79Rc7lxS1wOozXJ7V0ou5DntVcOJplIkDjvEN8BIQph4U+gSO
# LZuVReP/z9YdUiUkcPwL1PM245/kEX1EegpxNc8HDA6hKCHg0ALNEcuxnGOlgKLo
# kXfUer1D5hiW8PABM9R+neiteTgPaaRlJFvGTYvotc0uqGiES5hMQhL8RNFhpS9R
# cIWHtnQGEnrdOUvCAhs4FeViawcmLTKv+1870c/MeTHi0QDdeR+7/Wg4qhkJ2k1i
# EHJdmYf8rIV0NRBZcdRTTdHee35SXP5neNCfAkjDIuZycRud6jzPLCNLiNYzGXBs
# wzJygj4EeSORT7wMvaFuKeRAXoXC3wwYvgIsI1zn3DGY625Y+yZSi8UNSNHuri36
# Zv9a+Q4vJwDpYK36S0TB2pf7xLiiH32nk7YK73Rg98W6fZ2INuzYzZ7Ghgvfffkj
# 4EUXg1E0EffY1pEqkbpDTP7h/DBqtzoPXsyw2MUh+7yvWcq2BGZSuca6CY6X4ioM
# uc5PWpsmvOOli7ARNA7Ab8kKdCc2gNDLacglsweZEc9/VQB6hls/b6Kk32nkwuHE
# xKlaeoSVrKB5U9xlp1+c8J/7GJj4Rw7AiQ8tcp+WmfyD8KxX2QlKbDi4SUjnglv4
# 617R8+a/cDWJyaMt8279Wn7f2yMedN7kfGIQ5SZj66RdhdlZOq8wggdxMIIFWaAD
# AgECAhMzAAAAFcXna54Cm0mZAAAAAAAVMA0GCSqGSIb3DQEBCwUAMIGIMQswCQYD
# VQQGEwJVUzETMBEGA1UECBMKV2FzaGluZ3RvbjEQMA4GA1UEBxMHUmVkbW9uZDEe
# MBwGA1UEChMVTWljcm9zb2Z0IENvcnBvcmF0aW9uMTIwMAYDVQQDEylNaWNyb3Nv
# ZnQgUm9vdCBDZXJ0aWZpY2F0ZSBBdXRob3JpdHkgMjAxMDAeFw0yMTA5MzAxODIy
# MjVaFw0zMDA5MzAxODMyMjVaMHwxCzAJBgNVBAYTAlVTMRMwEQYDVQQIEwpXYXNo
# aW5ndG9uMRAwDgYDVQQHEwdSZWRtb25kMR4wHAYDVQQKExVNaWNyb3NvZnQgQ29y
# cG9yYXRpb24xJjAkBgNVBAMTHU1pY3Jvc29mdCBUaW1lLVN0YW1wIFBDQSAyMDEw
# MIICIjANBgkqhkiG9w0BAQEFAAOCAg8AMIICCgKCAgEA5OGmTOe0ciELeaLL1yR5
# vQ7VgtP97pwHB9KpbE51yMo1V/YBf2xK4OK9uT4XYDP/XE/HZveVU3Fa4n5KWv64
# NmeFRiMMtY0Tz3cywBAY6GB9alKDRLemjkZrBxTzxXb1hlDcwUTIcVxRMTegCjhu
# je3XD9gmU3w5YQJ6xKr9cmmvHaus9ja+NSZk2pg7uhp7M62AW36MEBydUv626GIl
# 3GoPz130/o5Tz9bshVZN7928jaTjkY+yOSxRnOlwaQ3KNi1wjjHINSi947SHJMPg
# yY9+tVSP3PoFVZhtaDuaRr3tpK56KTesy+uDRedGbsoy1cCGMFxPLOJiss254o2I
# 5JasAUq7vnGpF1tnYN74kpEeHT39IM9zfUGaRnXNxF803RKJ1v2lIH1+/NmeRd+2
# ci/bfV+AutuqfjbsNkz2K26oElHovwUDo9Fzpk03dJQcNIIP8BDyt0cY7afomXw/
# TNuvXsLz1dhzPUNOwTM5TI4CvEJoLhDqhFFG4tG9ahhaYQFzymeiXtcodgLiMxhy
# 16cg8ML6EgrXY28MyTZki1ugpoMhXV8wdJGUlNi5UPkLiWHzNgY1GIRH29wb0f2y
# 1BzFa/ZcUlFdEtsluq9QBXpsxREdcu+N+VLEhReTwDwV2xo3xwgVGD94q0W29R6H
# XtqPnhZyacaue7e3PmriLq0CAwEAAaOCAd0wggHZMBIGCSsGAQQBgjcVAQQFAgMB
# AAEwIwYJKwYBBAGCNxUCBBYEFCqnUv5kxJq+gpE8RjUpzxD/LwTuMB0GA1UdDgQW
# BBSfpxVdAF5iXYP05dJlpxtTNRnpcjBcBgNVHSAEVTBTMFEGDCsGAQQBgjdMg30B
# ATBBMD8GCCsGAQUFBwIBFjNodHRwOi8vd3d3Lm1pY3Jvc29mdC5jb20vcGtpb3Bz
# L0RvY3MvUmVwb3NpdG9yeS5odG0wEwYDVR0lBAwwCgYIKwYBBQUHAwgwGQYJKwYB
# BAGCNxQCBAweCgBTAHUAYgBDAEEwCwYDVR0PBAQDAgGGMA8GA1UdEwEB/wQFMAMB
# Af8wHwYDVR0jBBgwFoAU1fZWy4/oolxiaNE9lJBb186aGMQwVgYDVR0fBE8wTTBL
# oEmgR4ZFaHR0cDovL2NybC5taWNyb3NvZnQuY29tL3BraS9jcmwvcHJvZHVjdHMv
# TWljUm9vQ2VyQXV0XzIwMTAtMDYtMjMuY3JsMFoGCCsGAQUFBwEBBE4wTDBKBggr
# BgEFBQcwAoY+aHR0cDovL3d3dy5taWNyb3NvZnQuY29tL3BraS9jZXJ0cy9NaWNS
# b29DZXJBdXRfMjAxMC0wNi0yMy5jcnQwDQYJKoZIhvcNAQELBQADggIBAJ1Vffwq
# reEsH2cBMSRb4Z5yS/ypb+pcFLY+TkdkeLEGk5c9MTO1OdfCcTY/2mRsfNB1OW27
# DzHkwo/7bNGhlBgi7ulmZzpTTd2YurYeeNg2LpypglYAA7AFvonoaeC6Ce5732pv
# vinLbtg/SHUB2RjebYIM9W0jVOR4U3UkV7ndn/OOPcbzaN9l9qRWqveVtihVJ9Ak
# vUCgvxm2EhIRXT0n4ECWOKz3+SmJw7wXsFSFQrP8DJ6LGYnn8AtqgcKBGUIZUnWK
# NsIdw2FzLixre24/LAl4FOmRsqlb30mjdAy87JGA0j3mSj5mO0+7hvoyGtmW9I/2
# kQH2zsZ0/fZMcm8Qq3UwxTSwethQ/gpY3UA8x1RtnWN0SCyxTkctwRQEcb9k+SS+
# c23Kjgm9swFXSVRk2XPXfx5bRAGOWhmRaw2fpCjcZxkoJLo4S5pu+yFUa2pFEUep
# 8beuyOiJXk+d0tBMdrVXVAmxaQFEfnyhYWxz/gq77EFmPWn9y8FBSX5+k77L+Dvk
# txW/tM4+pTFRhLy/AsGConsXHRWJjXD+57XQKBqJC4822rpM+Zv/Cuk0+CQ1Zyvg
# DbjmjJnW4SLq8CdCPSWU5nR0W2rRnj7tfqAxM328y+l7vzhwRNGQ8cirOoo6CGJ/
# 2XBjU02N7oJtpQUQwXEGahC0HVUzWLOhcGbyoYIDWTCCAkECAQEwggEBoYHZpIHW
# MIHTMQswCQYDVQQGEwJVUzETMBEGA1UECBMKV2FzaGluZ3RvbjEQMA4GA1UEBxMH
# UmVkbW9uZDEeMBwGA1UEChMVTWljcm9zb2Z0IENvcnBvcmF0aW9uMS0wKwYDVQQL
# EyRNaWNyb3NvZnQgSXJlbGFuZCBPcGVyYXRpb25zIExpbWl0ZWQxJzAlBgNVBAsT
# Hm5TaGllbGQgVFNTIEVTTjoyRDFBLTA1RTAtRDk0NzElMCMGA1UEAxMcTWljcm9z
# b2Z0IFRpbWUtU3RhbXAgU2VydmljZaIjCgEBMAcGBSsOAwIaAxUA5VHBr4h00EN7
# jUdQ33SE+qbk/8CggYMwgYCkfjB8MQswCQYDVQQGEwJVUzETMBEGA1UECBMKV2Fz
# aGluZ3RvbjEQMA4GA1UEBxMHUmVkbW9uZDEeMBwGA1UEChMVTWljcm9zb2Z0IENv
# cnBvcmF0aW9uMSYwJAYDVQQDEx1NaWNyb3NvZnQgVGltZS1TdGFtcCBQQ0EgMjAx
# MDANBgkqhkiG9w0BAQsFAAIFAO2RAMMwIhgPMjAyNjA0MjAxOTQ1MDdaGA8yMDI2
# MDQyMTE5NDUwN1owdzA9BgorBgEEAYRZCgQBMS8wLTAKAgUA7ZEAwwIBADAKAgEA
# AgIDVwIB/zAHAgEAAgISXTAKAgUA7ZJSQwIBADA2BgorBgEEAYRZCgQCMSgwJjAM
# BgorBgEEAYRZCgMCoAowCAIBAAIDB6EgoQowCAIBAAIDAYagMA0GCSqGSIb3DQEB
# CwUAA4IBAQAOMvR3hhn7qc38PIc6Vxto4+nBHE7rBZZXfYzLeHkhSXwbrOHnZy+i
# DHFZv8zv7Poyrxdph5/KwKgph5rEYR5a/XD+akmpShyVekokKF8EqxCXo/Z5YnnE
# 70AXfdyQo1AWTE1owXXi6OmfILk0hZ4trf2KHS0OnBEHfaU5+dxH391GLJYP+LMi
# qsHiASm/ohgaTiVCc0j7IjOpnf9vm+9JQEQCcm7Bk2F2ORTAo6Nu0QWaXdfrEOY3
# TgSK5Pr6zepd1itAGwcnaTGdJ4e/9MidxviFNa8gNPaHgeA3A87qYKshKYRE8d64
# 46DiZ/oCrbriSWkXcifDHPMc/SoygwbmMYIEDTCCBAkCAQEwgZMwfDELMAkGA1UE
# BhMCVVMxEzARBgNVBAgTCldhc2hpbmd0b24xEDAOBgNVBAcTB1JlZG1vbmQxHjAc
# BgNVBAoTFU1pY3Jvc29mdCBDb3Jwb3JhdGlvbjEmMCQGA1UEAxMdTWljcm9zb2Z0
# IFRpbWUtU3RhbXAgUENBIDIwMTACEzMAAAIS0QgGPMoYT6oAAQAAAhIwDQYJYIZI
# AWUDBAIBBQCgggFKMBoGCSqGSIb3DQEJAzENBgsqhkiG9w0BCRABBDAvBgkqhkiG
# 9w0BCQQxIgQgK5C/hR9R1dxTcv3+z9b0zfESENKwuk+fZs5I+1CtIp0wgfoGCyqG
# SIb3DQEJEAIvMYHqMIHnMIHkMIG9BCBz+X5GvO7WngknH4BZeYU+BzBL1Jy5oJ8w
# VlTNIxfYgzCBmDCBgKR+MHwxCzAJBgNVBAYTAlVTMRMwEQYDVQQIEwpXYXNoaW5n
# dG9uMRAwDgYDVQQHEwdSZWRtb25kMR4wHAYDVQQKExVNaWNyb3NvZnQgQ29ycG9y
# YXRpb24xJjAkBgNVBAMTHU1pY3Jvc29mdCBUaW1lLVN0YW1wIFBDQSAyMDEwAhMz
# AAACEtEIBjzKGE+qAAEAAAISMCIEIAMFyT7e5VBW8pRGcfA2oX7rw6aV/ZJ4fwNp
# xDIBorg4MA0GCSqGSIb3DQEBCwUABIICAENThV860L9Phy1VXtApBeAfjeOSI0dQ
# AKrqKEWhVuKJltnz4zJgKdsbfyxA91xNJVRLSpWjmGIxDuNvahGt7RjWT56rC0Y6
# ISabiK0ql5PuBHRAzkxrHLuc9jx75M4neAkLQXE1sYOVqKuNwEQlB1JY7LesnHX+
# bOR+2/qIkf4MwJwJUSv/e37MlqqSpbdfN5RFLscOfPq6uAmcbYWbEAF4/A0ETe0O
# RzoPJ2pSLW36SQcKCi89BdjFXXifvxsSfl2vM7WhhHm0bLeDmi/UbqCggmGAdfh5
# uRXxE6lRBwRbF8zxjWOKz+pACV1W9d1qrJK54PDBCZQTUKbHjmzLj195pDhYhJcV
# irRxXiUQriuPzyz2HYT+kV3KxJUVDI202x/z+0pSW/GHrhbLel4J5/Hu6wtUqBU0
# RhH8+knS+vE1Rac5PE9HCuCIs35ZKWuLh9vMr04uWvLvSz0F9nC08GEVbRRyTMj6
# CdvGX4QuXR3LGSl9lu9ORW6QiJUNOYITTbhzzHDzMCKdxuRY8mERmG7C3ntiKMhR
# BElK0JpBDzs60kET0MlAXlc6Z8sV2/k4tJm40lv+3h2OtdDE7mcWPWJffa7+uW5K
# RZ6qC4iHCQ3vKj8BlYOr5kTSSaB4MTqoQ1YWdnZmj06u1PRuOrpLnxQ5mtEuEeye
# Fi1jrDrrdLeg
# SIG # End signature block