rules/Azure.Common.Rule.ps1
# Copyright (c) Microsoft Corporation. # Licensed under the MIT License. # # Helper functions for rules # # Add a custom function to filter by resource type function global:ResourceType { [CmdletBinding()] [OutputType([System.Boolean])] param ( [Parameter(Mandatory = $True)] [String]$ResourceType ) process { return $PSRule.TargetType -eq $ResourceType; } } function global:ExtensionResourceType { [CmdletBinding()] [OutputType([System.Boolean])] param ( [Parameter(Mandatory = $True)] [String]$ResourceType ) process { return $TargetObject.ExtensionResourceType -eq $ResourceType; } } # Get sub resources of a specific resource type function global:GetSubResources { [CmdletBinding()] [OutputType([PSObject[]])] param ( [Parameter(Mandatory = $True)] [String[]]$ResourceType, [Parameter(Mandatory = $False)] [String[]]$Name ) process { $results = @(); $resources = @($TargetObject.resources); for ($i = 0; $i -lt $resources.Length; $i++) { $path = "resources[$i]"; if (($resources[$i].ResourceType -in $ResourceType -or $resources[$i].Type -in $ResourceType -or $resources[$i].ExtensionResourceType -in $ResourceType) -and ($Null -eq $Name -or $Name.Length -eq 0 -or [PSRule.Rules.Azure.Runtime.Helper]::GetSubResourceName($resources[$i].Name) -in $Name -or [PSRule.Rules.Azure.Runtime.Helper]::GetSubResourceName($resources[$i].ResourceName) -in $Name)) { $resource = $resources[$i]; if (!([bool]$resource.PSObject.Members['_PSRule'])) { $Null = Add-Member -InputObject $resource -MemberType NoteProperty -Name '_PSRule' -Value @{ path = $path; } } elseif (!([bool]$resource._PSRule.PSObject.Members['path'])) { $Null = Add-Member -InputObject $resource._PSRule -MemberType NoteProperty -Force -Name 'path' -Value $path; } $results += $resource; } } return $results; } } # Certain rules only apply if resource data has been exported function global:IsExport { [CmdletBinding()] [OutputType([System.Boolean])] param () process { return $Null -ne $TargetObject.SubscriptionId; } } function global:HasPeerNetwork { [CmdletBinding()] [OutputType([System.Boolean])] param () process { if ($PSRule.TargetType -ne 'Microsoft.Network/virtualNetworks') { return $False; } $peers = $TargetObject.Properties.virtualNetworkPeerings; if ($Null -eq $peers) { return $False; } $item = @($peers); return $item.Length -gt 0; } } function global:SupportsAcceleratedNetworking { [CmdletBinding()] param () process { if ($PSRule.TargetType -ne 'Microsoft.Compute/virtualMachines' -or !(IsExport)) { return $False; } if ($Null -eq ($TargetObject.Resources | Where-Object { $_.ResourceType -eq 'Microsoft.Network/networkInterfaces' })) { return $False; } $vmSize = $TargetObject.Properties.hardwareProfile.vmSize; if ($vmSize -notLike 'Standard_*_*') { if ($vmSize -match '^Standard_(F|B[1-2][0-9]ms)') { return $True; } else { return $False; } } $vmSizeParts = $vmSize.Split('_'); if ($Null -eq $vmSizeParts) { return $False; } $generation = $vmSizeParts[2]; $size = $vmSizeParts[1]; # Generation v2 if ($generation -eq 'v2') { if ($size -notMatch '^(A|NC|DS1$|D1$|F[1-2]s)') { return $True; } } # Generation v3 elseif ($generation -eq 'v3') { if ($size -notMatch '^(E2s?|E[2-8]-2|D2s?|NC)') { return $True; } } return $False; } } function global:IsWindowsOS { [CmdletBinding()] [OutputType([System.Boolean])] param () process { if ($PSRule.TargetType -notIn 'Microsoft.Compute/virtualMachines', 'Microsoft.Compute/virtualMachineScaleSets') { return $False; } return ($TargetObject.Properties.storageProfile.osDisk.osType -eq 'Windows') -or ($TargetObject.Properties.storageProfile.imageReference.publisher -in 'MicrosoftSQLServer', 'MicrosoftWindowsServer', 'MicrosoftVisualStudio', 'MicrosoftWindowsDesktop') -or ($TargetObject.Properties.virtualMachineProfile.storageProfile.osDisk.osType -eq 'Windows') -or ($TargetObject.Properties.virtualMachineProfile.storageProfile.imageReference.publisher -in 'MicrosoftSQLServer', 'MicrosoftWindowsServer', 'MicrosoftVisualStudio', 'MicrosoftWindowsDesktop') } } function global:IsWindowsClientOS { [CmdletBinding()] [OutputType([System.Boolean])] param () process { if ($PSRule.TargetType -notIn 'Microsoft.Compute/virtualMachines', 'Microsoft.Compute/virtualMachineScaleSets') { return $False; } return $TargetObject.Properties.storageProfile.imageReference.publisher -eq 'MicrosoftWindowsDesktop'; } } function global:SupportsHybridUse { [CmdletBinding()] [OutputType([System.Boolean])] param () process { if ($PSRule.TargetType -ne 'Microsoft.Compute/virtualMachines') { return $False; } return ( ($TargetObject.Properties.storageProfile.osDisk.osType -eq 'Windows') -or ($TargetObject.Properties.storageProfile.imageReference.publisher -in 'MicrosoftSQLServer', 'MicrosoftWindowsServer') ) -and !(IsWindowsClientOS); } } function global:IsLinuxOffering { [CmdletBinding()] [OutputType([System.Boolean])] param ($imageReference) process { $configLinuxOffers = $Configuration.GetStringValues('AZURE_LINUX_OS_OFFERS'); foreach ($configLinuxOffer in $configLinuxOffers) { if ($configLinuxOffer -ieq $imageReference.offer) { return $True } } $someLinuxOSNames = @('ubuntu', 'linux', 'rhel', 'centos', 'redhat', 'debian', 'suse') foreach ($linuxOSName in $someLinuxOSNames) { if ($imageReference.offer -match $linuxOSName) { return $True } } foreach ($publicLinuxOffering in $PublicLinuxOfferings) { if ($publicLinuxOffering[0] -ieq $imageReference.publisher -and $publicLinuxOffering[1] -ieq $imageReference.offer) { return $True } } return $False } } function global:VMHasLinuxOS { [CmdletBinding()] [OutputType([System.Boolean])] param () process { if ($PSRule.TargetType -ne 'Microsoft.Compute/virtualMachines') { return $False; } return $TargetObject.Properties.storageProfile.osDisk.osType -eq 'Linux' -or $Assert.HasField($TargetObject, 'properties.osProfile.linuxConfiguration').Result -or (IsLinuxOffering($TargetObject.Properties.storageProfile.imageReference)) } } function global:VMSSHasLinuxOS { [CmdletBinding()] [OutputType([System.Boolean])] param () process { if ($PSRule.TargetType -ne 'Microsoft.Compute/virtualMachineScaleSets') { return $False; } return $TargetObject.Properties.virtualMachineProfile.storageProfile.osDisk.osType -eq 'Linux' -or $Assert.HasField($TargetObject, 'properties.virtualMachineProfile.osProfile.linuxConfiguration').Result -or (IsLinuxOffering($TargetObject.Properties.virtualMachineProfile.storageProfile.imageReference)) } } $Global:FlagSupportsTagWarning = $True; # Determines if the object supports tags function global:SupportsTags { [CmdletBinding()] [OutputType([System.Boolean])] param ( [String]$TargetType = $PSRule.TargetType ) begin { if ($Global:FlagSupportsTagWarning) { Write-Warning -Message "The 'SupportsTags' PowerShell function has been replaced with the selector 'Azure.Resource.SupportsTags'. The 'SupportsTags' function is deprecated and will no longer work in the next major version. Please update your PowerShell rules to the selector instead. See https://aka.ms/ps-rule-azure/upgrade."; $Global:FlagSupportsTagWarning = $False; } } process { if ( ($TargetType -eq 'Microsoft.Subscription') -or ($TargetType -eq 'Microsoft.Resources/deployments') -or ($TargetType -eq 'Microsoft.AzureActiveDirectory/b2ctenants') -or ($TargetType -notLike 'Microsoft.*/*') -or ($TargetType -like 'Microsoft.Addons/*') -or ($TargetType -like 'Microsoft.Advisor/*') -or ($TargetType -like 'Microsoft.Authorization/*') -or ($TargetType -like 'Microsoft.Billing/*') -or ($TargetType -like 'Microsoft.Blueprint/*') -or ($TargetType -like 'Microsoft.Capacity/*') -or ($TargetType -like 'Microsoft.Classic*') -or ($TargetType -like 'Microsoft.Consumption/*') -or ($TargetType -like 'Microsoft.Gallery/*') -or ($TargetType -like 'Microsoft.Security/*') -or ($TargetType -like 'microsoft.support/*') -or ($TargetType -like 'Microsoft.WorkloadMonitor/*') -or ($TargetType -like '*/providers/roleAssignments') -or ($TargetType -like '*/providers/diagnosticSettings') -or # Exclude sub-resources by default ($TargetType -like 'Microsoft.*/*/*' -and !( $TargetType -eq 'Microsoft.Automation/automationAccounts/runbooks' -or $TargetType -eq 'Microsoft.Automation/automationAccounts/configurations' -or $TargetType -eq 'Microsoft.Automation/automationAccounts/compilationjobs' -or $TargetType -eq 'Microsoft.Automation/automationAccounts/modules' -or $TargetType -eq 'Microsoft.Automation/automationAccounts/nodeConfigurations' -or $TargetType -eq 'Microsoft.Automation/automationAccounts/python2Packages' -or $TargetType -eq 'Microsoft.Automation/automationAccounts/watchers' -or $TargetType -eq 'Microsoft.Resources/templateSpecs/versions' )) -or # Some exception to resources (https://docs.microsoft.com/azure/azure-resource-manager/management/tag-support#microsoftresources) ($TargetType -like 'Microsoft.Resources/*' -and !( $TargetType -eq 'Microsoft.Resources/deploymentScripts' -or $TargetType -eq 'Microsoft.Resources/resourceGroups' -or $TargetType -eq 'Microsoft.Resources/templateSpecs' -or $TargetType -eq 'Microsoft.Resources/templateSpecs/versions' )) -or # Some exception to resources (https://docs.microsoft.com/azure/azure-resource-manager/management/tag-support#microsoftinsights) ($TargetType -like 'Microsoft.Insights/*' -and !( $TargetType -eq 'Microsoft.Insights/actionGroups' -or $TargetType -eq 'Microsoft.Insights/activityLogAlerts' -or $TargetType -eq 'Microsoft.Insights/alertRules' -or $TargetType -eq 'Microsoft.Insights/autoscaleSettings' -or $TargetType -eq 'Microsoft.Insights/components' -or $TargetType -eq 'Microsoft.Insights/dataCollectionEndpoints' -or $TargetType -eq 'Microsoft.Insights/dataCollectionRules' -or $TargetType -eq 'Microsoft.Insights/guestDiagnosticSettings' -or $TargetType -eq 'Microsoft.Insights/metricAlerts' -or $TargetType -eq 'Microsoft.Insights/notificationGroups' -or $TargetType -eq 'Microsoft.Insights/privateLinkScopes' -or $TargetType -eq 'Microsoft.Insights/scheduledQueryRules' -or $TargetType -eq 'Microsoft.Insights/webTests' -or $TargetType -eq 'Microsoft.Insights/workbooks' -or $TargetType -eq 'Microsoft.Insights/workbookTemplates' )) -or # Some exceptions to resources (https://docs.microsoft.com/azure/azure-resource-manager/management/tag-support#microsoftcostmanagement) ($TargetType -like 'Microsoft.CostManagement/*' -and !( $TargetType -eq 'Microsoft.CostManagement/Connectors' )) ) { return $False; } return $True; } } # Determines if the object supports regions function global:SupportsRegions { [CmdletBinding()] [OutputType([System.Boolean])] param () process { if ( ($PSRule.TargetType -eq 'Microsoft.Subscription') -or ($PSRule.TargetType -eq 'Microsoft.AzureActiveDirectory/b2cDirectories') -or ($PSRule.TargetType -eq 'Microsoft.Network/trafficManagerProfiles') -or ($PSRule.TargetType -like 'Microsoft.Authorization/*') -or ($PSRule.TargetType -like 'Microsoft.Consumption/*') -or ($PSRule.TargetType -like '*/providers/roleAssignments') -or ($TargetObject.Location -eq 'global') ) { return $False; } return $True; } } function global:ConvertToUInt64 { param ( [Parameter(Mandatory = $True)] [System.Net.IPAddress]$IP ) process { $bytes = $IP.GetAddressBytes(); $size = $bytes.Length; [System.UInt64]$result = 0; for ($i = 0; $i -lt $size; $i++) { $result = ($result -shl 8) + $bytes[$i]; } return $result; } } function global:GetIPAddressCount { [CmdletBinding()] [OutputType([System.UInt64])] param ( [Parameter(Mandatory = $True)] [String]$Start, [Parameter(Mandatory = $True)] [String]$End ) process { $startIP = [System.Net.IPAddress]::Parse($Start); $endIP = [System.Net.IPAddress]::Parse($End); $startAddress = ConvertToUInt64 -IP $startIP; $endAddress = ConvertToUInt64 -IP $endIP; if ($endAddress -ge $startAddress) { return $endAddress - $startAddress + 1; } else { return $startAddress - $endAddress + 1; } } } function global:GetIPAddressSummary { [CmdletBinding()] [OutputType([PSObject])] param () process { $firewallRules = @($TargetObject.resources | Where-Object -FilterScript { $_.Type -like "*/firewallRules" } | ForEach-Object -Process { if (!($_.ResourceName -eq 'AllowAllWindowsAzureIps' -or ($_.properties.startIpAddress -eq '0.0.0.0' -and $_.properties.endIpAddress -eq '0.0.0.0'))) { $_; } }) $private = 0; $public = 0; foreach ($fwRule in $firewallRules) { if ($fwRule.Properties.startIpAddress -like "10.*" -or $fwRule.Properties.startIpAddress -like "172.*" -or $fwRule.Properties.startIpAddress -like "192.168.*") { $private += GetIPAddressCount -Start $fwRule.Properties.startIpAddress -End $fwRule.Properties.endIpAddress; } else { $public += GetIPAddressCount -Start $fwRule.Properties.startIpAddress -End $fwRule.Properties.endIpAddress; } } return [PSCustomObject]@{ Private = $private Public = $public } } } function global:GetCIDRMask { [CmdletBinding()] [OutputType([PSObject])] param ( [Parameter(Mandatory = $True)] [String]$CIDR ) process { $cidrParts = $CIDR.Split('/'); $ip = ConvertToUInt64 -IP ([System.Net.IPAddress]::Parse($cidrParts[0])); [System.UInt64]$mask = 4294967295; if ($cidrParts.Length -eq 2) { $mask = [System.UInt64](4294967295 -shl (32 - ([System.Byte]::Parse($cidrParts[1])))) -band 4294967295; } return [PSCustomObject]@{ Mask = $mask IP = $ip; } } } function global:WithinCIDR { [CmdletBinding()] [OutputType([System.Boolean])] param ( [Parameter(Mandatory = $True)] [String]$IP, [Parameter(Mandatory = $True)] [String[]]$CIDR ) process { [System.UInt64]$address = ConvertToUInt64 -IP ([System.Net.IPAddress]::Parse($IP)); $result = $False; for ($i = 0; (($i -lt $CIDR.Length) -and (!$result)); $i++) { $mask = GetCIDRMask -CIDR $CIDR[$i]; $result = ($mask.Mask -band $address) -eq $mask.IP; } return $result; } } # Determine if the VM is using a promo SKU. function global:IsVMPromoSku { process { if ($PSRule.TargetType -ne 'Microsoft.Compute/virtualMachines') { return $False; } return $TargetObject.Properties.hardwareProfile.vmSize -like '*_Promo'; } } # Normalizes the location for comparison. function global:GetNormalLocation { [CmdletBinding()] [OutputType([String])] param ( [Parameter(Mandatory = $True)] [AllowEmptyString()] [String]$Location ) process { return $Location.Replace(' ', '').ToLower(); } } function global:GetAvailabilityZone { [CmdletBinding()] [OutputType([String[]])] param ( [Parameter(Mandatory = $True)] [AllowEmptyString()] [string]$Location, [Parameter(Mandatory = $True)] [AllowEmptyCollection()] [PSObject[]]$Zone ) process { $normalizedLocation = GetNormalLocation -Location $Location; $availabilityZones = $Zone | Where-Object { (GetNormalLocation -Location $_.Location) -eq $normalizedLocation } | Select-Object -ExpandProperty Zones -First 1; return $availabilityZones | Sort-Object { [int]$_ }; } } function global:PrependConfigurationZoneWithProviderZone { [CmdletBinding()] [OutputType([PSObject[]])] param ( [Parameter(Mandatory = $True)] [AllowEmptyCollection()] [PSObject[]]$ConfigurationZone, [Parameter(Mandatory = $True)] [AllowEmptyCollection()] [PSObject[]]$ProviderZone ) process { if ($ConfigurationZone.Length -gt 0) { # Prepend configuration options and provider mappings together # We put configuration options at the beginning so they are processed first return @($ConfigurationZone) + @($ProviderZone); } return $ProviderZone; } } # SIG # Begin signature block # MIInngYJKoZIhvcNAQcCoIInjzCCJ4sCAQExDzANBglghkgBZQMEAgEFADB5Bgor # BgEEAYI3AgEEoGswaTA0BgorBgEEAYI3AgEeMCYCAwEAAAQQH8w7YFlLCE63JNLG # KX7zUQIBAAIBAAIBAAIBAAIBADAxMA0GCWCGSAFlAwQCAQUABCD3UJlNj+4jqJW+ # +3/QNPzamW3KeAOF4dXQ9t1CMfcRyaCCDYEwggX/MIID56ADAgECAhMzAAACzI61 # lqa90clOAAAAAALMMA0GCSqGSIb3DQEBCwUAMH4xCzAJBgNVBAYTAlVTMRMwEQYD # VQQIEwpXYXNoaW5ndG9uMRAwDgYDVQQHEwdSZWRtb25kMR4wHAYDVQQKExVNaWNy # b3NvZnQgQ29ycG9yYXRpb24xKDAmBgNVBAMTH01pY3Jvc29mdCBDb2RlIFNpZ25p # bmcgUENBIDIwMTEwHhcNMjIwNTEyMjA0NjAxWhcNMjMwNTExMjA0NjAxWjB0MQsw # CQYDVQQGEwJVUzETMBEGA1UECBMKV2FzaGluZ3RvbjEQMA4GA1UEBxMHUmVkbW9u # ZDEeMBwGA1UEChMVTWljcm9zb2Z0IENvcnBvcmF0aW9uMR4wHAYDVQQDExVNaWNy # b3NvZnQgQ29ycG9yYXRpb24wggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIB # AQCiTbHs68bADvNud97NzcdP0zh0mRr4VpDv68KobjQFybVAuVgiINf9aG2zQtWK # No6+2X2Ix65KGcBXuZyEi0oBUAAGnIe5O5q/Y0Ij0WwDyMWaVad2Te4r1Eic3HWH # UfiiNjF0ETHKg3qa7DCyUqwsR9q5SaXuHlYCwM+m59Nl3jKnYnKLLfzhl13wImV9 # DF8N76ANkRyK6BYoc9I6hHF2MCTQYWbQ4fXgzKhgzj4zeabWgfu+ZJCiFLkogvc0 # RVb0x3DtyxMbl/3e45Eu+sn/x6EVwbJZVvtQYcmdGF1yAYht+JnNmWwAxL8MgHMz # xEcoY1Q1JtstiY3+u3ulGMvhAgMBAAGjggF+MIIBejAfBgNVHSUEGDAWBgorBgEE # AYI3TAgBBggrBgEFBQcDAzAdBgNVHQ4EFgQUiLhHjTKWzIqVIp+sM2rOHH11rfQw # UAYDVR0RBEkwR6RFMEMxKTAnBgNVBAsTIE1pY3Jvc29mdCBPcGVyYXRpb25zIFB1 # ZXJ0byBSaWNvMRYwFAYDVQQFEw0yMzAwMTIrNDcwNTI5MB8GA1UdIwQYMBaAFEhu # ZOVQBdOCqhc3NyK1bajKdQKVMFQGA1UdHwRNMEswSaBHoEWGQ2h0dHA6Ly93d3cu # bWljcm9zb2Z0LmNvbS9wa2lvcHMvY3JsL01pY0NvZFNpZ1BDQTIwMTFfMjAxMS0w # Ny0wOC5jcmwwYQYIKwYBBQUHAQEEVTBTMFEGCCsGAQUFBzAChkVodHRwOi8vd3d3 # Lm1pY3Jvc29mdC5jb20vcGtpb3BzL2NlcnRzL01pY0NvZFNpZ1BDQTIwMTFfMjAx # MS0wNy0wOC5jcnQwDAYDVR0TAQH/BAIwADANBgkqhkiG9w0BAQsFAAOCAgEAeA8D # sOAHS53MTIHYu8bbXrO6yQtRD6JfyMWeXaLu3Nc8PDnFc1efYq/F3MGx/aiwNbcs # J2MU7BKNWTP5JQVBA2GNIeR3mScXqnOsv1XqXPvZeISDVWLaBQzceItdIwgo6B13 # vxlkkSYMvB0Dr3Yw7/W9U4Wk5K/RDOnIGvmKqKi3AwyxlV1mpefy729FKaWT7edB # d3I4+hldMY8sdfDPjWRtJzjMjXZs41OUOwtHccPazjjC7KndzvZHx/0VWL8n0NT/ # 404vftnXKifMZkS4p2sB3oK+6kCcsyWsgS/3eYGw1Fe4MOnin1RhgrW1rHPODJTG # AUOmW4wc3Q6KKr2zve7sMDZe9tfylonPwhk971rX8qGw6LkrGFv31IJeJSe/aUbG # dUDPkbrABbVvPElgoj5eP3REqx5jdfkQw7tOdWkhn0jDUh2uQen9Atj3RkJyHuR0 # GUsJVMWFJdkIO/gFwzoOGlHNsmxvpANV86/1qgb1oZXdrURpzJp53MsDaBY/pxOc # J0Cvg6uWs3kQWgKk5aBzvsX95BzdItHTpVMtVPW4q41XEvbFmUP1n6oL5rdNdrTM # j/HXMRk1KCksax1Vxo3qv+13cCsZAaQNaIAvt5LvkshZkDZIP//0Hnq7NnWeYR3z # 4oFiw9N2n3bb9baQWuWPswG0Dq9YT9kb+Cs4qIIwggd6MIIFYqADAgECAgphDpDS # AAAAAAADMA0GCSqGSIb3DQEBCwUAMIGIMQswCQYDVQQGEwJVUzETMBEGA1UECBMK # V2FzaGluZ3RvbjEQMA4GA1UEBxMHUmVkbW9uZDEeMBwGA1UEChMVTWljcm9zb2Z0 # IENvcnBvcmF0aW9uMTIwMAYDVQQDEylNaWNyb3NvZnQgUm9vdCBDZXJ0aWZpY2F0 # ZSBBdXRob3JpdHkgMjAxMTAeFw0xMTA3MDgyMDU5MDlaFw0yNjA3MDgyMTA5MDla # MH4xCzAJBgNVBAYTAlVTMRMwEQYDVQQIEwpXYXNoaW5ndG9uMRAwDgYDVQQHEwdS # ZWRtb25kMR4wHAYDVQQKExVNaWNyb3NvZnQgQ29ycG9yYXRpb24xKDAmBgNVBAMT # H01pY3Jvc29mdCBDb2RlIFNpZ25pbmcgUENBIDIwMTEwggIiMA0GCSqGSIb3DQEB # AQUAA4ICDwAwggIKAoICAQCr8PpyEBwurdhuqoIQTTS68rZYIZ9CGypr6VpQqrgG # OBoESbp/wwwe3TdrxhLYC/A4wpkGsMg51QEUMULTiQ15ZId+lGAkbK+eSZzpaF7S # 35tTsgosw6/ZqSuuegmv15ZZymAaBelmdugyUiYSL+erCFDPs0S3XdjELgN1q2jz # y23zOlyhFvRGuuA4ZKxuZDV4pqBjDy3TQJP4494HDdVceaVJKecNvqATd76UPe/7 # 4ytaEB9NViiienLgEjq3SV7Y7e1DkYPZe7J7hhvZPrGMXeiJT4Qa8qEvWeSQOy2u # M1jFtz7+MtOzAz2xsq+SOH7SnYAs9U5WkSE1JcM5bmR/U7qcD60ZI4TL9LoDho33 # X/DQUr+MlIe8wCF0JV8YKLbMJyg4JZg5SjbPfLGSrhwjp6lm7GEfauEoSZ1fiOIl # XdMhSz5SxLVXPyQD8NF6Wy/VI+NwXQ9RRnez+ADhvKwCgl/bwBWzvRvUVUvnOaEP # 6SNJvBi4RHxF5MHDcnrgcuck379GmcXvwhxX24ON7E1JMKerjt/sW5+v/N2wZuLB # l4F77dbtS+dJKacTKKanfWeA5opieF+yL4TXV5xcv3coKPHtbcMojyyPQDdPweGF # RInECUzF1KVDL3SV9274eCBYLBNdYJWaPk8zhNqwiBfenk70lrC8RqBsmNLg1oiM # CwIDAQABo4IB7TCCAekwEAYJKwYBBAGCNxUBBAMCAQAwHQYDVR0OBBYEFEhuZOVQ # BdOCqhc3NyK1bajKdQKVMBkGCSsGAQQBgjcUAgQMHgoAUwB1AGIAQwBBMAsGA1Ud # DwQEAwIBhjAPBgNVHRMBAf8EBTADAQH/MB8GA1UdIwQYMBaAFHItOgIxkEO5FAVO # 4eqnxzHRI4k0MFoGA1UdHwRTMFEwT6BNoEuGSWh0dHA6Ly9jcmwubWljcm9zb2Z0 # LmNvbS9wa2kvY3JsL3Byb2R1Y3RzL01pY1Jvb0NlckF1dDIwMTFfMjAxMV8wM18y # Mi5jcmwwXgYIKwYBBQUHAQEEUjBQME4GCCsGAQUFBzAChkJodHRwOi8vd3d3Lm1p # Y3Jvc29mdC5jb20vcGtpL2NlcnRzL01pY1Jvb0NlckF1dDIwMTFfMjAxMV8wM18y # Mi5jcnQwgZ8GA1UdIASBlzCBlDCBkQYJKwYBBAGCNy4DMIGDMD8GCCsGAQUFBwIB # FjNodHRwOi8vd3d3Lm1pY3Jvc29mdC5jb20vcGtpb3BzL2RvY3MvcHJpbWFyeWNw # cy5odG0wQAYIKwYBBQUHAgIwNB4yIB0ATABlAGcAYQBsAF8AcABvAGwAaQBjAHkA # XwBzAHQAYQB0AGUAbQBlAG4AdAAuIB0wDQYJKoZIhvcNAQELBQADggIBAGfyhqWY # 4FR5Gi7T2HRnIpsLlhHhY5KZQpZ90nkMkMFlXy4sPvjDctFtg/6+P+gKyju/R6mj # 82nbY78iNaWXXWWEkH2LRlBV2AySfNIaSxzzPEKLUtCw/WvjPgcuKZvmPRul1LUd # d5Q54ulkyUQ9eHoj8xN9ppB0g430yyYCRirCihC7pKkFDJvtaPpoLpWgKj8qa1hJ # Yx8JaW5amJbkg/TAj/NGK978O9C9Ne9uJa7lryft0N3zDq+ZKJeYTQ49C/IIidYf # wzIY4vDFLc5bnrRJOQrGCsLGra7lstnbFYhRRVg4MnEnGn+x9Cf43iw6IGmYslmJ # aG5vp7d0w0AFBqYBKig+gj8TTWYLwLNN9eGPfxxvFX1Fp3blQCplo8NdUmKGwx1j # NpeG39rz+PIWoZon4c2ll9DuXWNB41sHnIc+BncG0QaxdR8UvmFhtfDcxhsEvt9B # xw4o7t5lL+yX9qFcltgA1qFGvVnzl6UJS0gQmYAf0AApxbGbpT9Fdx41xtKiop96 # eiL6SJUfq/tHI4D1nvi/a7dLl+LrdXga7Oo3mXkYS//WsyNodeav+vyL6wuA6mk7 # r/ww7QRMjt/fdW1jkT3RnVZOT7+AVyKheBEyIXrvQQqxP/uozKRdwaGIm1dxVk5I # RcBCyZt2WwqASGv9eZ/BvW1taslScxMNelDNMYIZczCCGW8CAQEwgZUwfjELMAkG # A1UEBhMCVVMxEzARBgNVBAgTCldhc2hpbmd0b24xEDAOBgNVBAcTB1JlZG1vbmQx # HjAcBgNVBAoTFU1pY3Jvc29mdCBDb3Jwb3JhdGlvbjEoMCYGA1UEAxMfTWljcm9z # b2Z0IENvZGUgU2lnbmluZyBQQ0EgMjAxMQITMwAAAsyOtZamvdHJTgAAAAACzDAN # BglghkgBZQMEAgEFAKCBrjAZBgkqhkiG9w0BCQMxDAYKKwYBBAGCNwIBBDAcBgor # BgEEAYI3AgELMQ4wDAYKKwYBBAGCNwIBFTAvBgkqhkiG9w0BCQQxIgQgGjSf3ngX # /n/dvj5Sstg8/i+4ajYtQ3ASBZl1rEJyBJEwQgYKKwYBBAGCNwIBDDE0MDKgFIAS # AE0AaQBjAHIAbwBzAG8AZgB0oRqAGGh0dHA6Ly93d3cubWljcm9zb2Z0LmNvbTAN # BgkqhkiG9w0BAQEFAASCAQAIKwNHZBRZlOGAsmbtHfw9gnUc6/59kjc5Dh1x39g8 # gT/oswMCvEbZuKGFttaCoMfEmoGvg+snYh+6dyZ5zrixyx9iRyAW+t6TS/g7qJW3 # SM0OO7fTPp3GxxWVLgLghxyFvUjZUomYhbljetK2gt6feTJ3NDWmf+qh6bd3So4e # n6uLMj/rJo38W9QVgi4uJ89mRw6Z/pklj1QfCmoWWMx0yqRV5XalbO+vga3W0qoc # vvp3T9v8rlMQ1OVdZfu9RNwfkTiEZgOcZHbChCy6RajlhAQTUo56tuYIDAkVN8Pn # 5NTwRDup/u+UT7pErbKKp+Orxgx64yKdBVfJZxOv5gv4oYIW/TCCFvkGCisGAQQB # gjcDAwExghbpMIIW5QYJKoZIhvcNAQcCoIIW1jCCFtICAQMxDzANBglghkgBZQME # AgEFADCCAVEGCyqGSIb3DQEJEAEEoIIBQASCATwwggE4AgEBBgorBgEEAYRZCgMB # MDEwDQYJYIZIAWUDBAIBBQAEIF9diemk0dQoPu7oxEVLNabZPkc1c31qVm0eY1J6 # z06mAgZjR/dOoaQYEzIwMjIxMDE2MDkwNjI5Ljk5N1owBIACAfSggdCkgc0wgcox # CzAJBgNVBAYTAlVTMRMwEQYDVQQIEwpXYXNoaW5ndG9uMRAwDgYDVQQHEwdSZWRt # b25kMR4wHAYDVQQKExVNaWNyb3NvZnQgQ29ycG9yYXRpb24xJTAjBgNVBAsTHE1p # Y3Jvc29mdCBBbWVyaWNhIE9wZXJhdGlvbnMxJjAkBgNVBAsTHVRoYWxlcyBUU1Mg # RVNOOjNCQkQtRTMzOC1FOUExMSUwIwYDVQQDExxNaWNyb3NvZnQgVGltZS1TdGFt # cCBTZXJ2aWNloIIRVDCCBwwwggT0oAMCAQICEzMAAAGd/onl+Xu7TMAAAQAAAZ0w # DQYJKoZIhvcNAQELBQAwfDELMAkGA1UEBhMCVVMxEzARBgNVBAgTCldhc2hpbmd0 # b24xEDAOBgNVBAcTB1JlZG1vbmQxHjAcBgNVBAoTFU1pY3Jvc29mdCBDb3Jwb3Jh # dGlvbjEmMCQGA1UEAxMdTWljcm9zb2Z0IFRpbWUtU3RhbXAgUENBIDIwMTAwHhcN # MjExMjAyMTkwNTE5WhcNMjMwMjI4MTkwNTE5WjCByjELMAkGA1UEBhMCVVMxEzAR # BgNVBAgTCldhc2hpbmd0b24xEDAOBgNVBAcTB1JlZG1vbmQxHjAcBgNVBAoTFU1p # Y3Jvc29mdCBDb3Jwb3JhdGlvbjElMCMGA1UECxMcTWljcm9zb2Z0IEFtZXJpY2Eg # T3BlcmF0aW9uczEmMCQGA1UECxMdVGhhbGVzIFRTUyBFU046M0JCRC1FMzM4LUU5 # QTExJTAjBgNVBAMTHE1pY3Jvc29mdCBUaW1lLVN0YW1wIFNlcnZpY2UwggIiMA0G # CSqGSIb3DQEBAQUAA4ICDwAwggIKAoICAQDgEWh60BxJFuR+mlFuFCtG3mR2XHNC # fPMTXcp06YewAtS1bbGzK7hDC1JRMethcmiKM/ebdCcG6v6k4lQyLlSaHmHkIUC5 # pNEtlutzpsVN+jo+Nbdyu9w0BMh4KzfduLdxbda1VztKDSXjE3eEl5Of+5hY3pHo # JX9Nh/5r4tc4Nvqt9tvVcYeIxpchZ81AK3+UzpA+hcR6HS67XA8+cQUB1fGyRoVh # 1sCu0+ofdVDcWOG/tcSKtJch+eRAVDe7IRm84fPsPTFz2dIJRJA/PUaZR+3xW4Fd # 1ZbLNa/wMbq3vaYtKogaSZiiCyUxU7mwoA32iyTcGHC7hH8MgZWVOEBu7CfNvMyr # sR8Quvu3m91Dqsc5gZHMxvgeAO9LLiaaU+klYmFWQvLXpilS1iDXb/82+TjwGtxE # nc8x/EvLkk7Ukj4uKZ6J8ynlgPhPRqejcoKlHsKgxWmD3wzEXW1a09d1L2Io004w # 01i31QAMB/GLhgmmMIE5Z4VI2Jlh9sX2nkyh5QOnYOznECk4za9cIdMKP+sde2nh # vvcSdrGXQ8fWO/+N1mjT0SIkX41XZjm+QMGR03ta63pfsj3g3E5a1r0o9aHgcuph # W0lwrbBA/TGMo5zC8Z5WI+Rwpr0MAiDZGy5h2+uMx/2+/F4ZiyKauKXqd7rIl1se # AYQYxKQ4SemB0QIDAQABo4IBNjCCATIwHQYDVR0OBBYEFNbfEI3hKujMnF4Rgdva # y4rZG1XkMB8GA1UdIwQYMBaAFJ+nFV0AXmJdg/Tl0mWnG1M1GelyMF8GA1UdHwRY # MFYwVKBSoFCGTmh0dHA6Ly93d3cubWljcm9zb2Z0LmNvbS9wa2lvcHMvY3JsL01p # Y3Jvc29mdCUyMFRpbWUtU3RhbXAlMjBQQ0ElMjAyMDEwKDEpLmNybDBsBggrBgEF # BQcBAQRgMF4wXAYIKwYBBQUHMAKGUGh0dHA6Ly93d3cubWljcm9zb2Z0LmNvbS9w # a2lvcHMvY2VydHMvTWljcm9zb2Z0JTIwVGltZS1TdGFtcCUyMFBDQSUyMDIwMTAo # MSkuY3J0MAwGA1UdEwEB/wQCMAAwEwYDVR0lBAwwCgYIKwYBBQUHAwgwDQYJKoZI # hvcNAQELBQADggIBAIbHcpxLt2h0LNJ334iCNZYsta2Eant9JUeipwebFIwQMij7 # SIQ83iJ4Y4OL5YwlppwvF516AhcHevYMScY6NAXSAGhp5xYtkEckeV6gNbcp3C4I # 3yotWvDd9KQCh7LdIhpiYCde0SF4N5JRZUHXIMczvNhe8+dEuiCnS1sWiGPUFzNJ # fsAcNs1aBkHItaSxM0AVHgZfgK8R2ihVktirxwYG0T9o1h0BkRJ3PfuJF+nOjt1+ # eFYYgq+bOLQs/SdgY4DbUVfrtLdEg2TbS+siZw4dqzM+tLdye5XGyJlKBX7aIs4x # f1Hh1ymMX24YJlm8vyX+W4x8yytPmziNHtshxf7lKd1Pm7t+7UUzi8QBhby0vYrf # rnoW1Kws+z34uoc2+D2VFxrH39xq/8KbeeBpuL5++CipoZQsd5QO5Ni81nBlwi/7 # 1JsZDEomso/k4JioyvVAM2818CgnsNJnMZZSxM5kyeRdYh9IbjGdPddPVcv0kPKr # NalPtRO4ih0GVkL/a4BfEBtXDeEUIsM4A00QehD+ESV3I0UbW+b4NTmbRcjnVFk5 # t6nuK/FoFQc5N4XueYAOw2mMDhAoFE+2xtTHk2ewd9xGkbFDl2b6u/FbhsUb5+Xo # P0PdJ3FTNP6G/7Vr4sIOxar4PpY674aQCiMSywwtIWOoqRS/OP/rSjF9E/xfMIIH # cTCCBVmgAwIBAgITMwAAABXF52ueAptJmQAAAAAAFTANBgkqhkiG9w0BAQsFADCB # iDELMAkGA1UEBhMCVVMxEzARBgNVBAgTCldhc2hpbmd0b24xEDAOBgNVBAcTB1Jl # ZG1vbmQxHjAcBgNVBAoTFU1pY3Jvc29mdCBDb3Jwb3JhdGlvbjEyMDAGA1UEAxMp # TWljcm9zb2Z0IFJvb3QgQ2VydGlmaWNhdGUgQXV0aG9yaXR5IDIwMTAwHhcNMjEw # OTMwMTgyMjI1WhcNMzAwOTMwMTgzMjI1WjB8MQswCQYDVQQGEwJVUzETMBEGA1UE # CBMKV2FzaGluZ3RvbjEQMA4GA1UEBxMHUmVkbW9uZDEeMBwGA1UEChMVTWljcm9z # b2Z0IENvcnBvcmF0aW9uMSYwJAYDVQQDEx1NaWNyb3NvZnQgVGltZS1TdGFtcCBQ # Q0EgMjAxMDCCAiIwDQYJKoZIhvcNAQEBBQADggIPADCCAgoCggIBAOThpkzntHIh # C3miy9ckeb0O1YLT/e6cBwfSqWxOdcjKNVf2AX9sSuDivbk+F2Az/1xPx2b3lVNx # WuJ+Slr+uDZnhUYjDLWNE893MsAQGOhgfWpSg0S3po5GawcU88V29YZQ3MFEyHFc # UTE3oAo4bo3t1w/YJlN8OWECesSq/XJprx2rrPY2vjUmZNqYO7oaezOtgFt+jBAc # nVL+tuhiJdxqD89d9P6OU8/W7IVWTe/dvI2k45GPsjksUZzpcGkNyjYtcI4xyDUo # veO0hyTD4MmPfrVUj9z6BVWYbWg7mka97aSueik3rMvrg0XnRm7KMtXAhjBcTyzi # YrLNueKNiOSWrAFKu75xqRdbZ2De+JKRHh09/SDPc31BmkZ1zcRfNN0Sidb9pSB9 # fvzZnkXftnIv231fgLrbqn427DZM9ituqBJR6L8FA6PRc6ZNN3SUHDSCD/AQ8rdH # GO2n6Jl8P0zbr17C89XYcz1DTsEzOUyOArxCaC4Q6oRRRuLRvWoYWmEBc8pnol7X # KHYC4jMYctenIPDC+hIK12NvDMk2ZItboKaDIV1fMHSRlJTYuVD5C4lh8zYGNRiE # R9vcG9H9stQcxWv2XFJRXRLbJbqvUAV6bMURHXLvjflSxIUXk8A8FdsaN8cIFRg/ # eKtFtvUeh17aj54WcmnGrnu3tz5q4i6tAgMBAAGjggHdMIIB2TASBgkrBgEEAYI3 # FQEEBQIDAQABMCMGCSsGAQQBgjcVAgQWBBQqp1L+ZMSavoKRPEY1Kc8Q/y8E7jAd # BgNVHQ4EFgQUn6cVXQBeYl2D9OXSZacbUzUZ6XIwXAYDVR0gBFUwUzBRBgwrBgEE # AYI3TIN9AQEwQTA/BggrBgEFBQcCARYzaHR0cDovL3d3dy5taWNyb3NvZnQuY29t # L3BraW9wcy9Eb2NzL1JlcG9zaXRvcnkuaHRtMBMGA1UdJQQMMAoGCCsGAQUFBwMI # MBkGCSsGAQQBgjcUAgQMHgoAUwB1AGIAQwBBMAsGA1UdDwQEAwIBhjAPBgNVHRMB # Af8EBTADAQH/MB8GA1UdIwQYMBaAFNX2VsuP6KJcYmjRPZSQW9fOmhjEMFYGA1Ud # HwRPME0wS6BJoEeGRWh0dHA6Ly9jcmwubWljcm9zb2Z0LmNvbS9wa2kvY3JsL3By # b2R1Y3RzL01pY1Jvb0NlckF1dF8yMDEwLTA2LTIzLmNybDBaBggrBgEFBQcBAQRO # MEwwSgYIKwYBBQUHMAKGPmh0dHA6Ly93d3cubWljcm9zb2Z0LmNvbS9wa2kvY2Vy # dHMvTWljUm9vQ2VyQXV0XzIwMTAtMDYtMjMuY3J0MA0GCSqGSIb3DQEBCwUAA4IC # AQCdVX38Kq3hLB9nATEkW+Geckv8qW/qXBS2Pk5HZHixBpOXPTEztTnXwnE2P9pk # bHzQdTltuw8x5MKP+2zRoZQYIu7pZmc6U03dmLq2HnjYNi6cqYJWAAOwBb6J6Gng # ugnue99qb74py27YP0h1AdkY3m2CDPVtI1TkeFN1JFe53Z/zjj3G82jfZfakVqr3 # lbYoVSfQJL1AoL8ZthISEV09J+BAljis9/kpicO8F7BUhUKz/AyeixmJ5/ALaoHC # gRlCGVJ1ijbCHcNhcy4sa3tuPywJeBTpkbKpW99Jo3QMvOyRgNI95ko+ZjtPu4b6 # MhrZlvSP9pEB9s7GdP32THJvEKt1MMU0sHrYUP4KWN1APMdUbZ1jdEgssU5HLcEU # BHG/ZPkkvnNtyo4JvbMBV0lUZNlz138eW0QBjloZkWsNn6Qo3GcZKCS6OEuabvsh # VGtqRRFHqfG3rsjoiV5PndLQTHa1V1QJsWkBRH58oWFsc/4Ku+xBZj1p/cvBQUl+ # fpO+y/g75LcVv7TOPqUxUYS8vwLBgqJ7Fx0ViY1w/ue10CgaiQuPNtq6TPmb/wrp # NPgkNWcr4A245oyZ1uEi6vAnQj0llOZ0dFtq0Z4+7X6gMTN9vMvpe784cETRkPHI # qzqKOghif9lwY1NNje6CbaUFEMFxBmoQtB1VM1izoXBm8qGCAsswggI0AgEBMIH4 # oYHQpIHNMIHKMQswCQYDVQQGEwJVUzETMBEGA1UECBMKV2FzaGluZ3RvbjEQMA4G # A1UEBxMHUmVkbW9uZDEeMBwGA1UEChMVTWljcm9zb2Z0IENvcnBvcmF0aW9uMSUw # IwYDVQQLExxNaWNyb3NvZnQgQW1lcmljYSBPcGVyYXRpb25zMSYwJAYDVQQLEx1U # aGFsZXMgVFNTIEVTTjozQkJELUUzMzgtRTlBMTElMCMGA1UEAxMcTWljcm9zb2Z0 # IFRpbWUtU3RhbXAgU2VydmljZaIjCgEBMAcGBSsOAwIaAxUAt+lDSRX92KFyij71 # Jn20CoSyyuCggYMwgYCkfjB8MQswCQYDVQQGEwJVUzETMBEGA1UECBMKV2FzaGlu # Z3RvbjEQMA4GA1UEBxMHUmVkbW9uZDEeMBwGA1UEChMVTWljcm9zb2Z0IENvcnBv # cmF0aW9uMSYwJAYDVQQDEx1NaWNyb3NvZnQgVGltZS1TdGFtcCBQQ0EgMjAxMDAN # BgkqhkiG9w0BAQUFAAIFAOb1wTkwIhgPMjAyMjEwMTYwNzMxMDVaGA8yMDIyMTAx # NzA3MzEwNVowdDA6BgorBgEEAYRZCgQBMSwwKjAKAgUA5vXBOQIBADAHAgEAAgIF # NTAHAgEAAgIR2zAKAgUA5vcSuQIBADA2BgorBgEEAYRZCgQCMSgwJjAMBgorBgEE # AYRZCgMCoAowCAIBAAIDB6EgoQowCAIBAAIDAYagMA0GCSqGSIb3DQEBBQUAA4GB # AIZZ6P+IyF2Ti2T6z98eojYg3DHXMsjH4FX0+ah3UPLvu7cUWKNvejkSfVtSOZil # Q/yBudlALlDjoSCZfaPpf56tDem2l75s8dNMahR4T9Y3Rub8qnHZGXBCWZj2t9jT # ZdS7Gxy8fg5BeVULs1/dx/5zzXb7OMqHUDQh9K1ZKwrqMYIEDTCCBAkCAQEwgZMw # fDELMAkGA1UEBhMCVVMxEzARBgNVBAgTCldhc2hpbmd0b24xEDAOBgNVBAcTB1Jl # ZG1vbmQxHjAcBgNVBAoTFU1pY3Jvc29mdCBDb3Jwb3JhdGlvbjEmMCQGA1UEAxMd # TWljcm9zb2Z0IFRpbWUtU3RhbXAgUENBIDIwMTACEzMAAAGd/onl+Xu7TMAAAQAA # AZ0wDQYJYIZIAWUDBAIBBQCgggFKMBoGCSqGSIb3DQEJAzENBgsqhkiG9w0BCRAB # BDAvBgkqhkiG9w0BCQQxIgQg2at1cj+gjiekAcw6m1CEtZalf2bR2YX0VK2mRPQu # PNMwgfoGCyqGSIb3DQEJEAIvMYHqMIHnMIHkMIG9BCD1HmOt4IqgT4A0n4JblX/f # zFLyEu4OBDOb+mpMlYdFoTCBmDCBgKR+MHwxCzAJBgNVBAYTAlVTMRMwEQYDVQQI # EwpXYXNoaW5ndG9uMRAwDgYDVQQHEwdSZWRtb25kMR4wHAYDVQQKExVNaWNyb3Nv # ZnQgQ29ycG9yYXRpb24xJjAkBgNVBAMTHU1pY3Jvc29mdCBUaW1lLVN0YW1wIFBD # QSAyMDEwAhMzAAABnf6J5fl7u0zAAAEAAAGdMCIEIHqbZgpxgznamGeKKu2T8glF # oI/gcQ+QOyfbhnzPu6AOMA0GCSqGSIb3DQEBCwUABIICAFWnkYiPP+O6wTlgVthy # WnBOQjk2UFXBUF2+LjQxzbSToSmTw77fXCvmRROAMhuiUSVFz++/Ufo0l7kbkrE/ # GiRdhw+ED/mIHmDL+fd2t34jZVIWcLGfFb7x+gL5c1UCFxrBOLgkfrF7VZg3vQfb # gcdsAnDXWVUB9ip/w0iGzzjg0WcFyzyu1qDB7G+guvVBl1w6ueedaVWe32A0jiGJ # RBJ07kwotzzP90XIeL0YLaB3/8Toj+ywppKNNlrIgV9nSJbVJnUVKS7rsWj67hUS # xehTr/EHtCz66W+ujvQP74SoES127Zk5AovffcNIyKlmJKpnpI9Dl/7x8p7u0WEr # suK1hnR6XVk7Ij9KqnwGCOLs6aE7DY7u9Gm8MWAkzGja9lSO6PnLV5DLeW+fD6nY # 7edxTpnPhFieeiF/BUExjAJxtlE7exbd0jBntkgzTnqnSMRQMYmZWKqb2if5NzPn # tgSe8f4iqUPQhkKAt4SSI/h9VUG93eMXiPU6oY+MjZTZ60zdQkmdKYJUBTipRRIM # qiFv7n3uplijIBiFmzx3ZthSgQGeIUjJF7b5cZENUddbq6WLwvNQKR9AGs3SBUzE # 1bKOQadCizsldN2CpBK2iAKaOGPzz2X9v1ZOg9cjsL9ezbxcJpz5zJO2InGfBoUd # l0y4Scz7p2RbqntUfWf3J3B6 # SIG # End signature block |