Private/Security/SystemTrust/Get-SecureBootSection.ps1
|
function Get-SecureBootSection { [CmdletBinding()] param( [Parameter(Mandatory)] [pscustomobject]$Templates ) Set-StrictMode -Version Latest $ErrorActionPreference = 'Stop' # ---------------------------- # Evidence container # ---------------------------- $evidence = [ordered]@{ Query = [ordered]@{ FirmwareTypeSource = $null SecureBootSource = $null ConfirmCmdletFound = $false } Firmware = [ordered]@{ FirmwareType = $null # UEFI | BIOS | Unknown PEFirmwareType = $null # 1=BIOS, 2=UEFI (if available) } SecureBoot = [ordered]@{ Enabled = $null # $true/$false/$null CimMsftSecureBootEnabled = $null ConfirmSecureBootUEFI = $null } Errors = New-Object System.Collections.Generic.List[string] } # ---------------------------- # Detect Firmware Type (UEFI vs BIOS) # Prefer registry: HKLM:\SYSTEM\CurrentControlSet\Control\PEFirmwareType # 1 = BIOS, 2 = UEFI # ---------------------------- try { $fw = Get-ItemProperty -LiteralPath 'HKLM:\SYSTEM\CurrentControlSet\Control' -Name 'PEFirmwareType' -ErrorAction Stop $pe = $fw.PEFirmwareType $evidence.Firmware.PEFirmwareType = $pe $evidence.Query.FirmwareTypeSource = 'Registry:HKLM\SYSTEM\CCS\Control\PEFirmwareType' $evidence.Firmware.FirmwareType = switch ($pe) { 2 { 'UEFI' } 1 { 'BIOS' } default { 'Unknown' } } } catch { $evidence.Errors.Add("Firmware type (PEFirmwareType) unavailable: $($_.Exception.Message)") } # Fallback: Get-ComputerInfo (not always present / can be slow) if (-not $evidence.Firmware.FirmwareType -or $evidence.Firmware.FirmwareType -eq 'Unknown') { try { $gci = Get-Command -Name Get-ComputerInfo -ErrorAction SilentlyContinue if ($gci) { $ci = Get-ComputerInfo -Property 'BiosFirmwareType' -ErrorAction Stop if ($ci.BiosFirmwareType) { $evidence.Query.FirmwareTypeSource = 'Get-ComputerInfo:BiosFirmwareType' # BiosFirmwareType is typically "Uefi" or "Legacy" $bft = [string]$ci.BiosFirmwareType if ($bft -match 'uefi') { $evidence.Firmware.FirmwareType = 'UEFI' } elseif ($bft -match 'legacy|bios') { $evidence.Firmware.FirmwareType = 'BIOS' } } } } catch { $evidence.Errors.Add("Get-ComputerInfo firmware type failed: $($_.Exception.Message)") } } $firmwareType = $evidence.Firmware.FirmwareType if (-not $firmwareType) { $firmwareType = 'Unknown' } # ---------------------------- # If not UEFI, Secure Boot is unsupported # ---------------------------- if ($firmwareType -ne 'UEFI') { $state = 'Unsupported' $condition = if ($firmwareType -eq 'BIOS') { 'Secure Boot is unsupported on legacy BIOS systems' } else { 'Secure Boot support cannot be determined (firmware type unknown)' } $context = "FirmwareType=$firmwareType" if ($evidence.Firmware.PEFirmwareType -ne $null) { $context += "; PEFirmwareType=$($evidence.Firmware.PEFirmwareType)" } return New-TrustSectionResult ` -Name 'SecureBoot' ` -State $state ` -Condition $condition ` -Context $context ` -Evidence ([pscustomobject]$evidence) ` -Templates $Templates } # ---------------------------- # Determine Secure Boot Status # Path 1: CIM/WMI MSFT_SecureBoot (often reliable when available) # Namespace: root\WMI, Class: MSFT_SecureBoot, Property: SecureBootEnabled # ---------------------------- $sbEnabled = $null try { $sb = Get-CimInstance -Namespace 'root\WMI' -ClassName 'MSFT_SecureBoot' -ErrorAction Stop if ($sb -and $sb.PSObject.Properties.Name -contains 'SecureBootEnabled') { $sbEnabled = [bool]$sb.SecureBootEnabled $evidence.SecureBoot.CimMsftSecureBootEnabled = $sbEnabled $evidence.Query.SecureBootSource = 'CIM:root\WMI:MSFT_SecureBoot.SecureBootEnabled' } } catch { $evidence.Errors.Add("MSFT_SecureBoot CIM unavailable: $($_.Exception.Message)") } # Path 2: Confirm-SecureBootUEFI (cmdlet) if ($sbEnabled -eq $null) { try { $cmd = Get-Command -Name Confirm-SecureBootUEFI -ErrorAction SilentlyContinue $evidence.Query.ConfirmCmdletFound = [bool]$cmd if ($cmd) { # This returns $true/$false; it may throw on unsupported access/config $confirm = Confirm-SecureBootUEFI -ErrorAction Stop $sbEnabled = [bool]$confirm $evidence.SecureBoot.ConfirmSecureBootUEFI = $sbEnabled $evidence.Query.SecureBootSource = 'Cmdlet:Confirm-SecureBootUEFI' } } catch { $evidence.Errors.Add("Confirm-SecureBootUEFI failed: $($_.Exception.Message)") } } $evidence.SecureBoot.Enabled = $sbEnabled # ---------------------------- # Evaluate health # ---------------------------- $warnings = New-Object System.Collections.Generic.List[string] $criticals = New-Object System.Collections.Generic.List[string] if ($sbEnabled -eq $true) { $state = 'Healthy' } elseif ($sbEnabled -eq $false) { $state = 'Critical' $criticals.Add('Secure Boot is disabled') } else { # UEFI system but we couldn't confirm the secure boot state $state = 'Warning' $warnings.Add('Secure Boot state is unknown') } # ---------------------------- # Build Condition/Context # ---------------------------- $condition = switch ($state) { 'Healthy' { 'Secure Boot is enabled' } 'Critical' { 'Secure Boot is disabled' } 'Warning' { 'Secure Boot state could not be confirmed' } default { 'Secure Boot information is unavailable or unsupported' } } $sbTxt = if ($sbEnabled -eq $true) { 'Enabled' } elseif ($sbEnabled -eq $false) { 'Disabled' } else { 'Unknown' } $src = if ($evidence.Query.SecureBootSource) { $evidence.Query.SecureBootSource } else { 'None' } $issues = @() if ($criticals.Count -gt 0) { $issues += $criticals } if ($warnings.Count -gt 0) { $issues += $warnings } $contextParts = @( "FirmwareType=$firmwareType" "SecureBoot=$sbTxt" "Source=$src" ) if ($evidence.Firmware.PEFirmwareType -ne $null) { $contextParts += "PEFirmwareType=$($evidence.Firmware.PEFirmwareType)" } if ($issues.Count -gt 0) { $contextParts += ("Findings=" + ($issues -join '; ')) } $context = $contextParts -join '; ' # ---------------------------- # Return standardized section result # ---------------------------- New-TrustSectionResult ` -Name 'SecureBoot' ` -State $state ` -Condition $condition ` -Context $context ` -Evidence ([pscustomobject]$evidence) ` -Templates $Templates } # SIG # Begin signature block # MIIfAgYJKoZIhvcNAQcCoIIe8zCCHu8CAQExDzANBglghkgBZQMEAgEFADB5Bgor # BgEEAYI3AgEEoGswaTA0BgorBgEEAYI3AgEeMCYCAwEAAAQQH8w7YFlLCE63JNLG # KX7zUQIBAAIBAAIBAAIBAAIBADAxMA0GCWCGSAFlAwQCAQUABCAYG+/RKqF03fkp # S70v/yBlZRBJ/bJ33i41ltlAXht8/aCCGEowggUMMIIC9KADAgECAhAR+U4xG7FH # qkyqS9NIt7l5MA0GCSqGSIb3DQEBCwUAMB4xHDAaBgNVBAMME1ZBRFRFSyBDb2Rl # IFNpZ25pbmcwHhcNMjUxMjE5MTk1NDIxWhcNMjYxMjE5MjAwNDIxWjAeMRwwGgYD # VQQDDBNWQURURUsgQ29kZSBTaWduaW5nMIICIjANBgkqhkiG9w0BAQEFAAOCAg8A # MIICCgKCAgEA3pzzZIUEY92GDldMWuzvbLeivHOuMupgpwbezoG5v90KeuN03S5d # nM/eom/PcIz08+fGZF04ueuCS6b48q1qFnylwg/C/TkcVRo0WFcKoFGT8yGxdfXi # caHtapZfbSRh73r7qR7w0CioVveNBVgfMsTgE0WKcuwxemvIe/ptmkfzwAiw/IAC # Ib0E0BjiX4PySbwWy/QKy/qMXYY19xpRItVTKNBtXzADUtzPzUcFqJU83vM2gZFs # Or0MhPvM7xEVkOWZFBAWAubbMCJ3rmwyVv9keVDJChhCeLSz2XR11VGDOEA2OO90 # Y30WfY9aOI2sCfQcKMeJ9ypkHl0xORdhUwZ3Wz48d3yJDXGkduPm2vl05RvnA4T6 # 29HVZTmMdvP2475/8nLxCte9IB7TobAOGl6P1NuwplAMKM8qyZh62Br23vcx1fXZ # TJlKCxBFx1nTa6VlIJk+UbM4ZPm954peB/fIqEacm8LkZ0cPwmLE5ckW7hfK4Trs # o+RaudU1sKeA+FvpOWgsPccVRWcEYyGkwbyTB3xrIBXA+YckbANZ0XL7fv7x29hn # gXbZipGu3DnTISiFB43V4MhNDKZYfbWdxze0SwLe8KzIaKnwlwRgvXDMwXgk99Mi # EbYa3DvA/5ZWikLW9PxBFD7Vdr8ZiG/tRC9I2Y6fnb+PVoZKc/2xsW0CAwEAAaNG # MEQwDgYDVR0PAQH/BAQDAgeAMBMGA1UdJQQMMAoGCCsGAQUFBwMDMB0GA1UdDgQW # BBRfYLVE8caSc990rnrIHUjoB7X/KjANBgkqhkiG9w0BAQsFAAOCAgEAiGB2Wmk3 # QBtd1LcynmxHzmu+X4Y5DIpMMNC2ahsqZtPUVcGqmb5IFbVuAdQphL6PSrDjaAR8 # 1S8uTfUnMa119LmIb7di7TlH2F5K3530h5x8JMj5EErl0xmZyJtSg7BTiBA/UrMz # 6WCf8wWIG2/4NbV6aAyFwIojfAcKoO8ng44Dal/oLGzLO3FDE5AWhcda/FbqVjSJ # 1zMfiW8odd4LgbmoyEI024KkwOkkPyJQ2Ugn6HMqlFLazAmBBpyS7wxdaAGrl18n # 6bS7QuAwCd9hitdMMitG8YyWL6tKeRSbuTP5E+ASbu0Ga8/fxRO5ZSQhO6/5ro1j # PGe1/Kr49Uyuf9VSCZdNIZAyjjeVAoxmV0IfxQLKz6VOG0kGDYkFGskvllIpQbQg # WLuPLJxoskJsoJllk7MjZJwrpr08+3FQnLkRuisjDOc3l4VxFUsUe4fnJhMUONXT # Sk7vdspgxirNbLmXU4yYWdsizz3nMUR0zebUW29A+HYme16hzrMPOeyoQjy4I5XX # 3wXAFdworfPEr/ozDFrdXKgbLwZopymKbBwv6wtT7+1zVhJXr+jGVQ1TWr6R+8ea # tIOFnY7HqGaxe5XB7HzOwJKdj+bpHAfXft1vUoiKr16VajLigcYCG8MdwC3sngO3 # JDyv2V+YMfsYBmItMGBwvizlQ6557NbK95EwggWNMIIEdaADAgECAhAOmxiO+dAt # 5+/bUOIIQBhaMA0GCSqGSIb3DQEBDAUAMGUxCzAJBgNVBAYTAlVTMRUwEwYDVQQK # EwxEaWdpQ2VydCBJbmMxGTAXBgNVBAsTEHd3dy5kaWdpY2VydC5jb20xJDAiBgNV # BAMTG0RpZ2lDZXJ0IEFzc3VyZWQgSUQgUm9vdCBDQTAeFw0yMjA4MDEwMDAwMDBa # Fw0zMTExMDkyMzU5NTlaMGIxCzAJBgNVBAYTAlVTMRUwEwYDVQQKEwxEaWdpQ2Vy # dCBJbmMxGTAXBgNVBAsTEHd3dy5kaWdpY2VydC5jb20xITAfBgNVBAMTGERpZ2lD # ZXJ0IFRydXN0ZWQgUm9vdCBHNDCCAiIwDQYJKoZIhvcNAQEBBQADggIPADCCAgoC # ggIBAL/mkHNo3rvkXUo8MCIwaTPswqclLskhPfKK2FnC4SmnPVirdprNrnsbhA3E # MB/zG6Q4FutWxpdtHauyefLKEdLkX9YFPFIPUh/GnhWlfr6fqVcWWVVyr2iTcMKy # unWZanMylNEQRBAu34LzB4TmdDttceItDBvuINXJIB1jKS3O7F5OyJP4IWGbNOsF # xl7sWxq868nPzaw0QF+xembud8hIqGZXV59UWI4MK7dPpzDZVu7Ke13jrclPXuU1 # 5zHL2pNe3I6PgNq2kZhAkHnDeMe2scS1ahg4AxCN2NQ3pC4FfYj1gj4QkXCrVYJB # MtfbBHMqbpEBfCFM1LyuGwN1XXhm2ToxRJozQL8I11pJpMLmqaBn3aQnvKFPObUR # WBf3JFxGj2T3wWmIdph2PVldQnaHiZdpekjw4KISG2aadMreSx7nDmOu5tTvkpI6 # nj3cAORFJYm2mkQZK37AlLTSYW3rM9nF30sEAMx9HJXDj/chsrIRt7t/8tWMcCxB # YKqxYxhElRp2Yn72gLD76GSmM9GJB+G9t+ZDpBi4pncB4Q+UDCEdslQpJYls5Q5S # UUd0viastkF13nqsX40/ybzTQRESW+UQUOsxxcpyFiIJ33xMdT9j7CFfxCBRa2+x # q4aLT8LWRV+dIPyhHsXAj6KxfgommfXkaS+YHS312amyHeUbAgMBAAGjggE6MIIB # NjAPBgNVHRMBAf8EBTADAQH/MB0GA1UdDgQWBBTs1+OC0nFdZEzfLmc/57qYrhwP # TzAfBgNVHSMEGDAWgBRF66Kv9JLLgjEtUYunpyGd823IDzAOBgNVHQ8BAf8EBAMC # AYYweQYIKwYBBQUHAQEEbTBrMCQGCCsGAQUFBzABhhhodHRwOi8vb2NzcC5kaWdp # Y2VydC5jb20wQwYIKwYBBQUHMAKGN2h0dHA6Ly9jYWNlcnRzLmRpZ2ljZXJ0LmNv # bS9EaWdpQ2VydEFzc3VyZWRJRFJvb3RDQS5jcnQwRQYDVR0fBD4wPDA6oDigNoY0 # aHR0cDovL2NybDMuZGlnaWNlcnQuY29tL0RpZ2lDZXJ0QXNzdXJlZElEUm9vdENB # LmNybDARBgNVHSAECjAIMAYGBFUdIAAwDQYJKoZIhvcNAQEMBQADggEBAHCgv0Nc # Vec4X6CjdBs9thbX979XB72arKGHLOyFXqkauyL4hxppVCLtpIh3bb0aFPQTSnov # Lbc47/T/gLn4offyct4kvFIDyE7QKt76LVbP+fT3rDB6mouyXtTP0UNEm0Mh65Zy # oUi0mcudT6cGAxN3J0TU53/oWajwvy8LpunyNDzs9wPHh6jSTEAZNUZqaVSwuKFW # juyk1T3osdz9HNj0d1pcVIxv76FQPfx2CWiEn2/K2yCNNWAcAgPLILCsWKAOQGPF # mCLBsln1VWvPJ6tsds5vIy30fnFqI2si/xK4VC0nftg62fC2h5b9W9FcrBjDTZ9z # twGpn1eqXijiuZQwgga0MIIEnKADAgECAhANx6xXBf8hmS5AQyIMOkmGMA0GCSqG # SIb3DQEBCwUAMGIxCzAJBgNVBAYTAlVTMRUwEwYDVQQKEwxEaWdpQ2VydCBJbmMx # GTAXBgNVBAsTEHd3dy5kaWdpY2VydC5jb20xITAfBgNVBAMTGERpZ2lDZXJ0IFRy # dXN0ZWQgUm9vdCBHNDAeFw0yNTA1MDcwMDAwMDBaFw0zODAxMTQyMzU5NTlaMGkx # CzAJBgNVBAYTAlVTMRcwFQYDVQQKEw5EaWdpQ2VydCwgSW5jLjFBMD8GA1UEAxM4 # RGlnaUNlcnQgVHJ1c3RlZCBHNCBUaW1lU3RhbXBpbmcgUlNBNDA5NiBTSEEyNTYg # MjAyNSBDQTEwggIiMA0GCSqGSIb3DQEBAQUAA4ICDwAwggIKAoICAQC0eDHTCphB # cr48RsAcrHXbo0ZodLRRF51NrY0NlLWZloMsVO1DahGPNRcybEKq+RuwOnPhof6p # vF4uGjwjqNjfEvUi6wuim5bap+0lgloM2zX4kftn5B1IpYzTqpyFQ/4Bt0mAxAHe # HYNnQxqXmRinvuNgxVBdJkf77S2uPoCj7GH8BLuxBG5AvftBdsOECS1UkxBvMgEd # gkFiDNYiOTx4OtiFcMSkqTtF2hfQz3zQSku2Ws3IfDReb6e3mmdglTcaarps0wjU # jsZvkgFkriK9tUKJm/s80FiocSk1VYLZlDwFt+cVFBURJg6zMUjZa/zbCclF83bR # VFLeGkuAhHiGPMvSGmhgaTzVyhYn4p0+8y9oHRaQT/aofEnS5xLrfxnGpTXiUOeS # LsJygoLPp66bkDX1ZlAeSpQl92QOMeRxykvq6gbylsXQskBBBnGy3tW/AMOMCZIV # NSaz7BX8VtYGqLt9MmeOreGPRdtBx3yGOP+rx3rKWDEJlIqLXvJWnY0v5ydPpOjL # 6s36czwzsucuoKs7Yk/ehb//Wx+5kMqIMRvUBDx6z1ev+7psNOdgJMoiwOrUG2Zd # SoQbU2rMkpLiQ6bGRinZbI4OLu9BMIFm1UUl9VnePs6BaaeEWvjJSjNm2qA+sdFU # eEY0qVjPKOWug/G6X5uAiynM7Bu2ayBjUwIDAQABo4IBXTCCAVkwEgYDVR0TAQH/ # BAgwBgEB/wIBADAdBgNVHQ4EFgQU729TSunkBnx6yuKQVvYv1Ensy04wHwYDVR0j # BBgwFoAU7NfjgtJxXWRM3y5nP+e6mK4cD08wDgYDVR0PAQH/BAQDAgGGMBMGA1Ud # JQQMMAoGCCsGAQUFBwMIMHcGCCsGAQUFBwEBBGswaTAkBggrBgEFBQcwAYYYaHR0 # cDovL29jc3AuZGlnaWNlcnQuY29tMEEGCCsGAQUFBzAChjVodHRwOi8vY2FjZXJ0 # cy5kaWdpY2VydC5jb20vRGlnaUNlcnRUcnVzdGVkUm9vdEc0LmNydDBDBgNVHR8E # PDA6MDigNqA0hjJodHRwOi8vY3JsMy5kaWdpY2VydC5jb20vRGlnaUNlcnRUcnVz # dGVkUm9vdEc0LmNybDAgBgNVHSAEGTAXMAgGBmeBDAEEAjALBglghkgBhv1sBwEw # DQYJKoZIhvcNAQELBQADggIBABfO+xaAHP4HPRF2cTC9vgvItTSmf83Qh8WIGjB/ # T8ObXAZz8OjuhUxjaaFdleMM0lBryPTQM2qEJPe36zwbSI/mS83afsl3YTj+IQhQ # E7jU/kXjjytJgnn0hvrV6hqWGd3rLAUt6vJy9lMDPjTLxLgXf9r5nWMQwr8Myb9r # EVKChHyfpzee5kH0F8HABBgr0UdqirZ7bowe9Vj2AIMD8liyrukZ2iA/wdG2th9y # 1IsA0QF8dTXqvcnTmpfeQh35k5zOCPmSNq1UH410ANVko43+Cdmu4y81hjajV/gx # dEkMx1NKU4uHQcKfZxAvBAKqMVuqte69M9J6A47OvgRaPs+2ykgcGV00TYr2Lr3t # y9qIijanrUR3anzEwlvzZiiyfTPjLbnFRsjsYg39OlV8cipDoq7+qNNjqFzeGxcy # tL5TTLL4ZaoBdqbhOhZ3ZRDUphPvSRmMThi0vw9vODRzW6AxnJll38F0cuJG7uEB # YTptMSbhdhGQDpOXgpIUsWTjd6xpR6oaQf/DJbg3s6KCLPAlZ66RzIg9sC+NJpud # /v4+7RWsWCiKi9EOLLHfMR2ZyJ/+xhCx9yHbxtl5TPau1j/1MIDpMPx0LckTetiS # uEtQvLsNz3Qbp7wGWqbIiOWCnb5WqxL3/BAPvIXKUjPSxyZsq8WhbaM2tszWkPZP # ubdcMIIG7TCCBNWgAwIBAgIQCoDvGEuN8QWC0cR2p5V0aDANBgkqhkiG9w0BAQsF # ADBpMQswCQYDVQQGEwJVUzEXMBUGA1UEChMORGlnaUNlcnQsIEluYy4xQTA/BgNV # BAMTOERpZ2lDZXJ0IFRydXN0ZWQgRzQgVGltZVN0YW1waW5nIFJTQTQwOTYgU0hB # MjU2IDIwMjUgQ0ExMB4XDTI1MDYwNDAwMDAwMFoXDTM2MDkwMzIzNTk1OVowYzEL # MAkGA1UEBhMCVVMxFzAVBgNVBAoTDkRpZ2lDZXJ0LCBJbmMuMTswOQYDVQQDEzJE # aWdpQ2VydCBTSEEyNTYgUlNBNDA5NiBUaW1lc3RhbXAgUmVzcG9uZGVyIDIwMjUg # MTCCAiIwDQYJKoZIhvcNAQEBBQADggIPADCCAgoCggIBANBGrC0Sxp7Q6q5gVrMr # V7pvUf+GcAoB38o3zBlCMGMyqJnfFNZx+wvA69HFTBdwbHwBSOeLpvPnZ8ZN+vo8 # dE2/pPvOx/Vj8TchTySA2R4QKpVD7dvNZh6wW2R6kSu9RJt/4QhguSssp3qome7M # rxVyfQO9sMx6ZAWjFDYOzDi8SOhPUWlLnh00Cll8pjrUcCV3K3E0zz09ldQ//nBZ # ZREr4h/GI6Dxb2UoyrN0ijtUDVHRXdmncOOMA3CoB/iUSROUINDT98oksouTMYFO # nHoRh6+86Ltc5zjPKHW5KqCvpSduSwhwUmotuQhcg9tw2YD3w6ySSSu+3qU8DD+n # igNJFmt6LAHvH3KSuNLoZLc1Hf2JNMVL4Q1OpbybpMe46YceNA0LfNsnqcnpJeIt # K/DhKbPxTTuGoX7wJNdoRORVbPR1VVnDuSeHVZlc4seAO+6d2sC26/PQPdP51ho1 # zBp+xUIZkpSFA8vWdoUoHLWnqWU3dCCyFG1roSrgHjSHlq8xymLnjCbSLZ49kPmk # 8iyyizNDIXj//cOgrY7rlRyTlaCCfw7aSUROwnu7zER6EaJ+AliL7ojTdS5PWPsW # eupWs7NpChUk555K096V1hE0yZIXe+giAwW00aHzrDchIc2bQhpp0IoKRR7YufAk # prxMiXAJQ1XCmnCfgPf8+3mnAgMBAAGjggGVMIIBkTAMBgNVHRMBAf8EAjAAMB0G # A1UdDgQWBBTkO/zyMe39/dfzkXFjGVBDz2GM6DAfBgNVHSMEGDAWgBTvb1NK6eQG # fHrK4pBW9i/USezLTjAOBgNVHQ8BAf8EBAMCB4AwFgYDVR0lAQH/BAwwCgYIKwYB # BQUHAwgwgZUGCCsGAQUFBwEBBIGIMIGFMCQGCCsGAQUFBzABhhhodHRwOi8vb2Nz # cC5kaWdpY2VydC5jb20wXQYIKwYBBQUHMAKGUWh0dHA6Ly9jYWNlcnRzLmRpZ2lj # ZXJ0LmNvbS9EaWdpQ2VydFRydXN0ZWRHNFRpbWVTdGFtcGluZ1JTQTQwOTZTSEEy # NTYyMDI1Q0ExLmNydDBfBgNVHR8EWDBWMFSgUqBQhk5odHRwOi8vY3JsMy5kaWdp # Y2VydC5jb20vRGlnaUNlcnRUcnVzdGVkRzRUaW1lU3RhbXBpbmdSU0E0MDk2U0hB # MjU2MjAyNUNBMS5jcmwwIAYDVR0gBBkwFzAIBgZngQwBBAIwCwYJYIZIAYb9bAcB # MA0GCSqGSIb3DQEBCwUAA4ICAQBlKq3xHCcEua5gQezRCESeY0ByIfjk9iJP2zWL # pQq1b4URGnwWBdEZD9gBq9fNaNmFj6Eh8/YmRDfxT7C0k8FUFqNh+tshgb4O6Lgj # g8K8elC4+oWCqnU/ML9lFfim8/9yJmZSe2F8AQ/UdKFOtj7YMTmqPO9mzskgiC3Q # YIUP2S3HQvHG1FDu+WUqW4daIqToXFE/JQ/EABgfZXLWU0ziTN6R3ygQBHMUBaB5 # bdrPbF6MRYs03h4obEMnxYOX8VBRKe1uNnzQVTeLni2nHkX/QqvXnNb+YkDFkxUG # tMTaiLR9wjxUxu2hECZpqyU1d0IbX6Wq8/gVutDojBIFeRlqAcuEVT0cKsb+zJNE # suEB7O7/cuvTQasnM9AWcIQfVjnzrvwiCZ85EE8LUkqRhoS3Y50OHgaY7T/lwd6U # Arb+BOVAkg2oOvol/DJgddJ35XTxfUlQ+8Hggt8l2Yv7roancJIFcbojBcxlRcGG # 0LIhp6GvReQGgMgYxQbV1S3CrWqZzBt1R9xJgKf47CdxVRd/ndUlQ05oxYy2zRWV # FjF7mcr4C34Mj3ocCVccAvlKV9jEnstrniLvUxxVZE/rptb7IRE2lskKPIJgbaP5 # t2nGj/ULLi49xTcBZU8atufk+EMF/cWuiC7POGT75qaL6vdCvHlshtjdNXOCIUjs # arfNZzGCBg4wggYKAgEBMDIwHjEcMBoGA1UEAwwTVkFEVEVLIENvZGUgU2lnbmlu # ZwIQEflOMRuxR6pMqkvTSLe5eTANBglghkgBZQMEAgEFAKCBhDAYBgorBgEEAYI3 # AgEMMQowCKACgAChAoAAMBkGCSqGSIb3DQEJAzEMBgorBgEEAYI3AgEEMBwGCisG # AQQBgjcCAQsxDjAMBgorBgEEAYI3AgEVMC8GCSqGSIb3DQEJBDEiBCB00JJtTY+9 # GlC2LYkcomvg/I4/3Wb+91F+nol9NFwQvzANBgkqhkiG9w0BAQEFAASCAgBz3z9b # XYL9HgCMrhqYyIoMnyEXvub0I4aOWUT2KWSQNcj9K97b148mKLk+UfvJbxrUgG+E # HL5mpG7kiBOSGMGuMX2bLQrzm+5Y64jTZTpXcjNbpw0s/O+AWapo+b0QsC4T8WIn # nTUK8NwkhfUtdNan9r7KJ5Ssjwl8O5a9HhtGgFNExQjteVikIHhU0W5BrIkXESn+ # 5B0B4aCGTmK87FYie5yCFDDk9zmbPr7E+9Z92QTg+xxot7rjBNm1riAhchdAauWi # VKzNN1bSboXqD4muAUUQwzKknN4KqPb3BwGy/aib3HeyeFU0UEt36KB0/YGhW95A # iawgmTApM4HhGeEmz2A0BgDfL7coWvad2B1iTI1d3L+CER1HK+J5E3ds02DpMzk4 # phX6mh+bYL6ee7ImqVsyLfa+IsJZgGPMvizaih8KxGp66a74ukh5LgyXs86vbvaq # qdoYFZ5fBN8XipSZ+SYf59SE1VpjBoZWTjBsQ11cTzsA4Xy1GOhWg3GYRj5NOkE7 # Up8qystfL70k5i4fxcZcKSKB5WhAQs/eVRVPAql7QE82NlJ4oQTOTXL5G01TDvFM # GDB2wdPnJPtbWTwoa/oxu2A8SvZthrntJQ5Da9aFrI5FisSc5JAJWzyDa+mykizt # tLnFDgW2j3URvUBGO2Mv6EI1/UbXUW80iKtFnqGCAyYwggMiBgkqhkiG9w0BCQYx # ggMTMIIDDwIBATB9MGkxCzAJBgNVBAYTAlVTMRcwFQYDVQQKEw5EaWdpQ2VydCwg # SW5jLjFBMD8GA1UEAxM4RGlnaUNlcnQgVHJ1c3RlZCBHNCBUaW1lU3RhbXBpbmcg # UlNBNDA5NiBTSEEyNTYgMjAyNSBDQTECEAqA7xhLjfEFgtHEdqeVdGgwDQYJYIZI # AWUDBAIBBQCgaTAYBgkqhkiG9w0BCQMxCwYJKoZIhvcNAQcBMBwGCSqGSIb3DQEJ # BTEPFw0yNjAzMDUyMTM5NTRaMC8GCSqGSIb3DQEJBDEiBCDUt6LrSDsltEUIRpw/ # cMBmVht/5Z2N1FyQV7EiXhUz7jANBgkqhkiG9w0BAQEFAASCAgC/jXS8cd9cfxub # v2Unm6bJY6M3Q16OhnHgPN9RjGEvBaLztrHWtUgu2J3y30fjWk0njfR6aaDpM9hW # NxHKYr6ComIWW7q4T7KFeuXZPlDJ+00uSrjQLR2pxdHcF+rfp3C66Al3r9RbZoLk # CJDh8b/4k6BZqdvv2aRtrT+2xGr41mzIR2uYz2k4gzlQPlzzmG0zFPuHOiiFxB14 # zTsesSHrvRsu9dRtB3VJL0dE4U3+tQP8w3crjNy52U4YqEJ3etXDh1QSwPkt7Lmr # oJ8qCMF0Qwochl2PfY8B6AzBcYoZHcgn+xfQ6zHqfCLab3OYa4KYZMe5iA+5qaou # 4s/vnLLIdICSdEG+zt3og9K1q4K5cKfX/qeBXQfik0QzNOY/J/qJ9qnlATF8Gfac # PdFqodMNOKnfyfp/JGqzZkQhcdEP3X+fVkNf7qTbhXE0esjMxIXDBYbmGBZwlOzu # QVJ63YcyFb/K+zNCCUJ2kkORvDcx4UpjWh5+kj7pgPAezglqfnzpEF1zgdrOC/uo # /of2Ka+NowJcAw5/2PdXjbvTE7uqwwO4np27/J8fpIZpqWV/FuiymazPWBG5Ea0s # vOwx5KVnDW43i1WHwDUcZC2dUBuPYvKdUvN4GvvM9Sl2rIcdq6xKb5Ybtpg7n+J0 # p88xbMjvzG2lRQzhWH1BFchqoUwwLg== # SIG # End signature block |