ShieldingDataAnswerFile/ShieldingDataAnswerFile.psm1
# Copyright (c) Microsoft Corporation. All rights reserved. # Licensed under the MIT License. function New-ShieldingDataAnswerFile { <# .SYNOPSIS Creates an OS specialization answer file for use with shielded virtual machines. .DESCRIPTION Shielded VMs require unattended OS installations due to the security features that prevent you from seeing the VM console while the VM is running. These unattended installations require answer files to configure the operating system. For example, the administrator password must be set on your VM before you can use it. This function creates simple answer files for use with Windows and Linux shielded VMs that are compatible with System Center Virtual Machine Manager. SCVMM is not required to deploy VMs using these answer files, however they are designed to be compatible with it. Any text included in the answer file is encrypted in the shielding data file and cannot be changed by a malicious user. Such information includes your administrator password and domain join credentials. There are several substitution strings available for fields that must change when the VM is deployed, such as its computer name and static IP configuration, if required. These substitution strings are printed at the end of the command execution and should be supplied to New-ShieldedVMSpecializationDataFile with the actual, intended values. All answer files will include a command to turn off the VM after provisioning completes. This is required for most virtualization fabric managers to know when a shielded VM guest OS has finished specializing. .PARAMETER Path Location to save the answer file (.xml extension). .PARAMETER AdminCredentials The desired username and password for a new user account (with administrator privileges) to be created on the VM. .PARAMETER RootPassword The password for the root user account. .PARAMETER RootSshKey SSH public key blob to associate with the root user account. Either the path to a public key file (.pub) or the raw public key data can be provided. .PARAMETER DomainName Name of the Active Directory domain to which the VM should join. .PARAMETER DomainJoinCredentials User credentials privileged to join the VM to the specified Active Directory domain. .PARAMETER ProductKeyRequired Indicates that the VM OS requires a product key during installation. The product key will be provided at deployment time by Virtual Machine Manager or your fabric specialization keyfile. By default, the answer file will not include a field for the product key and assumes you have evaluation or volume licensed media. .PARAMETER RDPCertificatePath Path to a PFX file containing a certificate and private key that should be used to secure inbound Remote Desktop connections. .PARAMETER RDPCertificatePassword Password for the Remote Desktop certificate file. .PARAMETER StaticIPPool Indicates the VM should use a static IP address provided by a System Center Virtual Machine Manager IP pool. 'All' will provision a static IPv4 address, IPv6 address, primary DNS server, and gateway. 'IPv4Address' only provisions a static IPv4 address, primary DNS server, and gateway. 'IPv6Address' only provisions a static IPv6 address, primary DNS server, and gateway. 'DnsServerOnly' sets the primary DNS server but uses DHCP for IPv4 and IPv6 addresses. Omit this parameter if your VM should use DHCP to obtain its IPv4, IPv6 and DNS server addresses. .PARAMETER ConfigurationScript Path to any configuration scripts that should run during installation. Only .ps1 and .bat scripts are supported. .PARAMETER Locale Configures Windows to use a specific locale for language and UI elements. Defaults to en-US. .PARAMETER Force Skips all safety checks when creating the answer file. This switch will allow the use of default administrator account and overwrite existing files. .EXAMPLE $admin = Get-Credential 'administrator' -Message 'Local administrator account credentials' New-ShieldingDataAnswerFile -Path .\unattend.xml -AdminCredentials $admin Create a basic Windows answer file and sets the built-in administrator account password .EXAMPLE $admin = Get-Credential -Message "Local administrator account credentials" $djcred = Get-Credential -Message "Domain join credentials" New-ShieldingDataAnswerFile -Path .\unattend.xml -AdminCredentials $admin -DomainName 'contoso.com' -DomainJoinCredentials $djcred -ConfigurationScript .\mycustomconfig.ps1 Create a Windows answer file that joins the VM to a domain and runs a configuration script .EXAMPLE $password = Read-Host -Prompt "Root Password" -AsSecureString New-ShieldingDataAnswerFile -Path ./linuxanswer.xml -RootPassword $password -RootSshKey ~/.ssh/id_rsa.pub Create a Linux answer file and associate your public SSH key with the root user account. #> [CmdletBinding(DefaultParameterSetName='WindowsAnswerFile')] param( [Parameter(Mandatory = $true, Position = 0)] [string] $Path, [Parameter(ParameterSetName='WindowsAnswerFile', Mandatory=$true)] [pscredential] $AdminCredentials, [Parameter(ParameterSetName='LinuxAnswerFile', Mandatory=$true)] [securestring] $RootPassword, [Parameter(ParameterSetName='LinuxAnswerFile')] [string] $RootSshKey, [Parameter(ParameterSetName='WindowsAnswerFile')] [string] $DomainName, [Parameter(ParameterSetName='WindowsAnswerFile')] [pscredential] $DomainJoinCredentials, [Parameter(ParameterSetName='WindowsAnswerFile')] [switch] $ProductKeyRequired, [Parameter(ParameterSetName='WindowsAnswerFile')] [string] $RDPCertificatePath, [Parameter(ParameterSetName='WindowsAnswerFile')] [securestring] $RDPCertificatePassword, [ValidateSet('All', 'IPv4Address', 'IPv6Address', 'DnsServerOnly')] [string] $StaticIPPool, [Parameter(ParameterSetName='WindowsAnswerFile')] [string[]] $ConfigurationScript, [Parameter(ParameterSetName='WindowsAnswerFile')] [ValidateSet("ar-SA", "bg-BG", "zh-HK", "zh-CN", "zh-TW", "hr-HR", "cs-CZ", "da-DK", "nl-NL", "en-US", "en-GB", "et-EE", "fi-FI", "fr-FR", "de-DE", "el-GR", "he-IL", "hu-HU", "it-IT", "ja-JP", "ko-KR", "lv-LV", "lt-LT", "nb-NO", "pl-PL", "pt-BR", "pt-PT", "ro-RO", "ru-RU", "sr-Latn-CS", "sr-Latn-RS", "sk-SK", "sl-SI", "es-ES", "sv-SE", "th-TH", "tr-TR", "uk-UA")] [string] $Locale = 'en-US', [switch] $Force = $false ) $Windows = $PSCmdlet.ParameterSetName -eq 'WindowsAnswerFile' ## Parameter Validation # Ensure path has an XML extension if ($Path -notlike '*.xml') { throw [System.ArgumentException] "Answer file path must have a .xml extension" } # Validate path location $ParentPath = Split-Path $Path -Parent if ($ParentPath) { $ParentPath = Resolve-Path $ParentPath -ErrorAction SilentlyContinue if (-not (Test-Path $ParentPath -PathType Container)) { throw [System.IO.DirectoryNotFoundException] ("Answer file path is invalid: directory could not be found.") } } else { $ParentPath = Get-Location -PSProvider FileSystem } $Path = Join-Path $ParentPath (Split-Path $Path -Leaf) # Parse credentials if ($Windows) { $AdminUsername = $AdminCredentials.UserName $AdminPassword = $AdminCredentials.GetNetworkCredential().Password } else { $AdminUsername = 'root' $tempAdminCredential = New-Object -TypeName System.Management.Automation.PSCredential -ArgumentList 'root', $RootPassword $AdminPassword = $tempAdminCredential.GetNetworkCredential().Password $tempAdminCredential = $null } # Validate username if ([string]::IsNullOrEmpty($AdminUsername)) { throw [System.ArgumentException] 'Administrator username cannot be empty' } elseif ($Windows -and $AdminUsername -eq 'Administrator') { if ($Force) { Write-Warning "The built-in 'Administrator' account will be enabled by this answer file." } else { throw [System.ArgumentException] "It is not recommended to enable the built-in 'Administrator' account in the VM. Select a different username or use -Force if you are sure you want to use this account." } } elseif ($AdminUsername -and $Windows -and $AdminUsername -match '["/\\\[\]:;\|=,\+\*\?<>]+') { throw [System.ArgumentException] 'Administrator username cannot contain any of the following characters: " / \ [ ] : ; | = , + * ? < >' } # Validate password if ([string]::IsNullOrEmpty($AdminPassword)) { throw [System.ArgumentException] 'Administrator password cannot be empty' } # Ensure domain credentials are provided if a domain name is provided if ($DomainName -and -not $DomainJoinCredentials) { throw [System.ArgumentNullException] "Domain join credentials are required when a domain name is specified." } # Ensure the RDP certificate exists if ($RDPCertificatePath -and -not (Test-Path $RDPCertificatePath -PathType Leaf)) { throw [System.IO.FileNotFoundException] ("Could not find the RDP certificate at '{0}'. Please provide a path to a valid PFX file." -f $RDPCertificatePath) } # Ensure the RDP certificate is a PFX file if ($RDPCertificatePath -and $RDPCertificatePath -notlike '*.pfx') { throw [System.ArgumentException] "The RDP certificate must be in the Personal Information Exchange (.pfx) file format, containing both the certificate and its private key." } # Ensure an RDP certificate password is provided if an RDP certificate path is provided if ($RDPCertificatePath -and -not $RDPCertificatePassword) { throw [System.ArgumentNullException] "The RDP certificate password is required when an RDP certificate path is specified." } # Check if the RDP certificate password is valid for the specified file if ($RDPCertificatePath) { try { $null = Get-PfxData -FilePath $RDPCertificatePath -Password $RDPCertificatePassword } catch { throw [System.ArgumentException] "The RDP certificate password is invalid for the specified RDP certificate file." } } # Prevent users from passing more than one value to StaticIPPool if 'All' is included if ($StaticIPPool -and $StaticIPPool.Count -gt 1 -and ($StaticIPPool -contains 'All' -or $StaticIPPool -contains 'DnsServerOnly')) { throw [System.ArgumentException] "The Static IP Pool configuration specified is invalid. Valid combinations are: empty, 'All', 'DnsServerOnly', 'IPv4Address', 'IPv6Address', or both 'IPv4Address' and 'IPv6Address'." } # Validate configuration script extension for Windows if ($ConfigurationScript) { foreach ($script in $ConfigurationScript) { if ($script -notlike '*.ps1' -and $script -notlike '*.bat') { throw [System.ArgumentException] ("The configuration script '{0}' is invalid. Only PowerShell (.ps1) and batch scripts (.bat) are supported.") } } } ## Load the sample answer file $ScriptModulePath = Split-Path $PSCommandPath -Parent -Resolve | Convert-Path if ($Windows) { $AnswerFilePath = Join-Path $ScriptModulePath 'WindowsUnattend.xml' } else { $AnswerFilePath = Join-Path $ScriptModulePath 'LinuxUnattend.xml' } if (-not (Test-Path $AnswerFilePath -PathType Leaf)) { throw [System.IO.FileNotFoundException] ("Unable to load the template unattend file from '{0}'." -f $AnswerFilePath) } [xml]$AnswerFile = Get-Content -Path $AnswerFilePath -ErrorAction Stop $FilesToIncludeInPDK = @() $FSKSubstitutionStrings = @( [pscustomobject] @{ Key = '@ComputerName@'; Purpose = 'Network name for the VM' } ) $FSK_IPv4Sub = $FSK_IPv6Sub = $FSK_DNSSub = $true if ($Windows) { $nsmgr = New-Object System.Xml.XmlNamespaceManager $AnswerFile.NameTable $nsmgr.AddNamespace('ns', 'urn:schemas-microsoft-com:unattend') $nsmgr.AddNamespace('xsi', 'http://www.w3.org/2001/XMLSchema-instance') $nsmgr.AddNamespace('wcm', 'http://schemas.microsoft.com/WMIConfig/2002/State') # Configure the local administrator account if ($AdminUsername -eq 'Administrator') { $AdminAccount = $AnswerFile.SelectSingleNode("//ns:AdministratorPassword", $nsmgr) $AdminAccount.Value = $AdminPassword $LocalAccounts = $AnswerFile.SelectSingleNode("//ns:LocalAccounts", $nsmgr) $null = $LocalAccounts.ParentNode.RemoveChild($LocalAccounts) } else { $LocalAccount = $AnswerFile.SelectSingleNode("//ns:LocalAccount", $nsmgr) $LocalAccount.Name = $AdminUsername $LocalAccount.Password.Value = $AdminPassword $AdminAccount = $AnswerFile.SelectSingleNode("//ns:AdministratorPassword", $nsmgr) $null = $AdminAccount.ParentNode.RemoveChild($AdminAccount) } # Remove product key if not required if (-not $ProductKeyRequired) { $pk = $AnswerFile.SelectSingleNode("//ns:ProductKey", $nsmgr) $null = $pk.ParentNode.RemoveChild($pk) } else { $FSKSubstitutionStrings += [pscustomobject] @{ Key = '@ProductKey@'; Purpose = 'Windows product key for activation' } } # Replace domain join information if ($DomainName) { $djinfo = $AnswerFile.SelectSingleNode("//ns:component[contains(@name, 'Microsoft-Windows-UnattendedJoin')]/ns:Identification", $nsmgr) $djinfo.JoinDomain = $DomainName $usercreds = $DomainJoinCredentials.GetNetworkCredential() if ($usercreds.Domain) { $userdomain = $usercreds.Domain } else { $userdomain = $DomainName } $djinfo.Credentials.Domain = $userdomain $djinfo.Credentials.Username = $usercreds.UserName $djinfo.Credentials.Password = $usercreds.Password } else { $djinfo = $AnswerFile.SelectSingleNode("//ns:component[contains(@name, 'Microsoft-Windows-UnattendedJoin')]", $nsmgr) $null = $djinfo.ParentNode.RemoveChild($djinfo) } # Add RDP certificate installation steps if ($RDPCertificatePath) { $flatname = Convert-Path $RDPCertificatePath | Split-Path -Leaf $password = (New-Object System.Management.Automation.PSCredential -ArgumentList 'anyuser', $RDPCertificatePassword).GetNetworkCredential().Password $passwordbytes = [System.Text.Encoding]::Unicode.GetBytes($password) $base64password = [System.Convert]::ToBase64String($passwordbytes) $RDPConfigPath = Join-Path $ParentPath 'RDPCertificateConfig.ps1' if ((Test-Path $RDPConfigPath) -and -not $Force) { throw [System.IO.IOException] ("RDP configuration file already exists at '{0}'. Use -Force to overwrite." -f $RDPConfigPath) } else { $command = @' $Password = [System.Text.Encoding]::Unicode.GetString([System.Convert]::FromBase64String("{0}")) $SecurePassword = ConvertTo-SecureString -AsPlainText -String $Password -Force $Certificate = Import-PfxCertificate -FilePath "$env:SystemDrive\temp\{1}" -Password $SecurePassword -CertStoreLocation Cert:\LocalMachine\My Get-CimInstance -Namespace root/CIMV2/TerminalServices -ClassName Win32_TSGeneralSetting | Set-CimInstance -Property @{{ SSLCertificateSHA1Hash = $Certificate.Thumbprint }} Remove-Item "$env:SystemDrive\temp\{1}" -Force Remove-Item "$env:SystemDrive\temp\RDPCertificateConfig.ps1" -Force '@ -f $base64password, $flatname Set-Content -Path $RDPConfigPath -Value $command -Force $firstCommand = $AnswerFile.SelectSingleNode("//ns:RunSynchronousCommand", $nsmgr) $clone = $firstCommand.CloneNode($true) $clone.Description = "Configures the RDP certificate" $clone.Path = 'cmd.exe /c "echo powershell.exe -File %SYSTEMDRIVE%\temp\RDPCertificateConfig.ps1" >> %WINDIR%\Setup\Scripts\SetupComplete.cmd' $null = $firstCommand.ParentNode.InsertBefore($clone, $firstCommand) $FilesToIncludeInPDK += [pscustomobject] @{ LocalPath = $RDPCertificatePath; VMPath = "%SYSTEMDRIVE%\temp\$flatname" } $FilesToIncludeInPDK += [pscustomobject] @{ LocalPath = $RDPConfigPath; VMPath = "%SYSTEMDRIVE%\temp\RDPCertificateConfig.ps1" } } } # Remove unnecessary networking nodes if ($StaticIPPool -ne 'All' -and $StaticIPPool -ne 'IPv4Address') { $IPNode = $AnswerFile.SelectSingleNode("//ns:Ipv4Settings", $nsmgr) $null = $IPNode.ParentNode.RemoveChild($IPNode) $IPv4Address = $AnswerFile.SelectSingleNode("//ns:component[contains(@name, 'Microsoft-Windows-TCPIP')]//ns:IpAddress[. = '@IP4Addr-1@']", $nsmgr) $IPv6Address = $AnswerFile.SelectSingleNode("//ns:component[contains(@name, 'Microsoft-Windows-TCPIP')]//ns:IpAddress[. = '@IP6Addr-1@']", $nsmgr) $null = $IPv4Address.ParentNode.RemoveChild($IPv4Address) $IPv6Address.keyValue = '1' $FSK_IPv4Sub = $false } if ($StaticIPPool -ne 'All' -and $StaticIPPool -ne 'IPv6Address') { $IPNode = $AnswerFile.SelectSingleNode("//ns:Ipv6Settings", $nsmgr) $null = $IPNode.ParentNode.RemoveChild($IPNode) $IPv6Address = $AnswerFile.SelectSingleNode("//ns:component[contains(@name, 'Microsoft-Windows-TCPIP')]//ns:IpAddress[. = '@IP6Addr-1@']", $nsmgr) $null = $IPv6Address.ParentNode.RemoveChild($IPv6Address) $FSK_IPv6Sub = $false } if (-not $StaticIPPool) { $IPNode = $AnswerFile.SelectSingleNode("//ns:component[contains(@name, 'Microsoft-Windows-TCPIP')]", $nsmgr) $null = $IPNode.ParentNode.RemoveChild($IPNode) $DnsNode = $AnswerFile.SelectSingleNode("//ns:component[contains(@name, 'Microsoft-Windows-DNS-Client')]", $nsmgr) $null = $DnsNode.ParentNode.RemoveChild($DnsNode) $FSK_IPv4Sub = $FSK_IPv6Sub = $FSK_DNSSub = $false } # Add configuration scripts if ($ConfigurationScript) { $originalnode = $AnswerFile.SelectSingleNode("//ns:RunSynchronousCommand", $nsmgr) $parentnode = $originalnode.ParentNode $templatenode = $originalnode.CloneNode($true) $null = $templatenode.RemoveChild($newnode.ChildNodes.Where({ $_.Name -eq 'Description'})) foreach ($script in $ConfigurationScript) { $newnode = $templatenode.CloneNode($true) $flatname = Split-Path -Path $script -Leaf if ($script -like '*.bat') { $newnode.Path = 'cmd.exe /c "echo cmd.exe /c "%SYSTEMDRIVE%\temp\{0}"" >> %WINDIR%\Setup\Scripts\SetupComplete.cmd' -f $flatname } else { $newnode.Path = 'cmd.exe /c "echo powershell.exe -File "%SYSTEMDRIVE%\temp\{0}"" >> %WINDIR%\Setup\Scripts\SetupComplete.cmd' -f $flatname } $null = $parentnode.InsertBefore($newnode, $originalnode) $FilesToIncludeInPDK += [pscustomobject] @{ LocalPath = $script; VMPath = ("%SYSTEMDRIVE%\temp\{0}" -f $flatname) } } } # Add command to delete existing setupcomplete.cmd if it exists $firstCommand = $AnswerFile.SelectSingleNode("//ns:RunSynchronousCommand", $nsmgr) $synchronousCommandsNode = $firstCommand.ParentNode $setupCompleteNode = $firstCommand.CloneNode($true) $setupCompleteNode.Description = "Delete existing setupcomplete.cmd file" $setupCompleteNode.Path = 'cmd.exe /c "IF EXIST %WINDIR%\Setup\Scripts\setupcomplete.cmd ( del /F %WINDIR%\Setup\Scripts\setupcomplete.cmd )"' $null = $synchronousCommandsNode.InsertBefore($setupCompleteNode, $firstCommand) # Add command to create script folder if it does not exist $scriptNode = $firstCommand.CloneNode($true) $scriptNode.Description = "Creates the scripts directory if required" $scriptNode.Path = 'cmd.exe /c "IF NOT EXIST %WINDIR%\Setup\Scripts ( md %WINDIR%\Setup\Scripts )"' $null = $synchronousCommandsNode.InsertBefore($scriptNode, $setupCompleteNode) # Ensure synchronous commands are ordered correctly $current = 1 foreach ($commandnode in $AnswerFile.SelectSingleNode("//ns:RunSynchronous", $nsmgr).ChildNodes) { $commandnode.Order = $current.ToString() $current += 1 } # Update locale placeholders $AnswerFile.SelectSingleNode("//ns:InputLocale", $nsmgr).'#text' = $Locale $AnswerFile.SelectSingleNode("//ns:UserLocale", $nsmgr).'#text' = $Locale $AnswerFile.SelectSingleNode("//ns:SystemLocale", $nsmgr).'#text' = $Locale $AnswerFile.SelectSingleNode("//ns:UILanguage", $nsmgr).'#text' = $Locale } # End Windows Configuration # Start Linux Configuration else { $nsmgr = New-Object System.Xml.XmlNamespaceManager $AnswerFile.NameTable $nsmgr.AddNamespace('ns', 'http://www.microsoft.com/schema/linuxvmmst') $nsmgr.AddNamespace('xsi', 'http://www.w3.org/2001/XMLSchema-instance') $nsmgr.AddNamespace('xsd', 'http://www.w3.org/2001/XMLSchema') $nsmgr.AddNamespace('d4p1', 'http://www.microsoft.com/schema/linuxvmmst') # Configure the administrator account $User = $AnswerFile.SelectSingleNode("//ns:User", $nsmgr) $User.Password = [System.Convert]::ToBase64String([System.Text.Encoding]::UTF8.GetBytes($AdminPassword)) # Configure the SSH key if ($RootSshKey) { # Check if a file path was provided if ((Test-Path -Path $RootSshKey -PathType Leaf -ErrorAction Continue)) { $RootSshKey = Get-Content -Path $RootSshKey -ErrorAction Stop } $User.SSHKey = $RootSshKey } else { $SSHKey = $User.SelectSingleNode("//ns:SSHKey", $nsmgr) $null = $User.RemoveChild($SSHKey) } # Configure networking if ($StaticIPPool -ne 'All' -and $StaticIPPool -ne 'IPv4Address') { $IPv4Node = $AnswerFile.SelectSingleNode("//ns:IPV4Property", $nsmgr) $null = $IPV4Node.ParentNode.RemoveChild($IPv4Node) $FSK_IPv4Sub = $false } if ($StaticIPPool -ne 'All' -and $StaticIPPool -ne 'IPv6Address') { $IPv6Node = $AnswerFile.SelectSingleNode("//ns:IPV6Property", $nsmgr) $null = $IPV6Node.ParentNode.RemoveChild($IPv6Node) $FSK_IPv6Sub = $false } if (-not $StaticIPPool) { $NetNode = $AnswerFile.SelectSingleNode("//ns:VNetAdapters", $nsmgr) $null = $NetNode.ParentNode.RemoveChild($NetNode) $FSK_IPv4Sub = $FSK_IPv6Sub = $FSK_DNSSub = $false } } # End Linux Configuration ## Finish collecting FSK substitution string messages if ($FSK_DNSSub) { $FSKSubstitutionStrings += [pscustomobject] @{ Key = '@MACAddr-1@'; Purpose = 'MAC address for vNIC' } $FSKSubstitutionStrings += [pscustomobject] @{ Key = '@DnsAddr-1-1@'; Purpose = 'Static DNS server address' } } if ($FSK_IPv4Sub -or $FSK_IPv6Sub) { $FSKSubstitutionStrings += [pscustomobject] @{ Key = '@NextHop-1-1@'; Purpose = 'Static gateway address' } } if ($FSK_IPv4Sub) { $FSKSubstitutionStrings += [pscustomobject] @{ Key = '@IP4Addr-1@'; Purpose = 'Static IPv4 Address (CIDR notation)' } } if ($FSK_IPv6Sub) { $FSKSubstitutionStrings += [pscustomobject] @{ Key = '@IP6Addr-1@'; Purpose = 'Static IPv6 Address (CIDR notation)' } } ## Write answer file to disk if ((Test-Path $Path) -and -not $Force) { throw [System.IO.IOException] ("Answer file already exists at '{0}'. Use -Force to overwrite." -f $Path) } try { $AnswerFile.Save($Path) } catch { $e = [System.IO.IOException] "Unable to create the answer file." $e.InnerException = $_ throw $e } ## Write required files and substitution strings to the console Write-Output ("Shielding data answer file was created successfully and saved to '{0}'" -f $Path) if ($FilesToIncludeInPDK.Count -gt 0) { Write-Output "" Write-Output "When creating your Shielding Data File, be sure to include the following items in the 'Other Files' section." Format-Table -AutoSize -InputObject $FilesToIncludeInPDK } Write-Output "", "The following substitution strings are included in the answer file and should be supplied when creating your shielded VM fabric specialization keyfile for a VM instance." Format-Table -AutoSize -InputObject $FSKSubstitutionStrings } # SIG # Begin signature block # MIIkGgYJKoZIhvcNAQcCoIIkCzCCJAcCAQExDzANBglghkgBZQMEAgEFADB5Bgor # BgEEAYI3AgEEoGswaTA0BgorBgEEAYI3AgEeMCYCAwEAAAQQH8w7YFlLCE63JNLG # KX7zUQIBAAIBAAIBAAIBAAIBADAxMA0GCWCGSAFlAwQCAQUABCBOcdNBpmwYoWiX # qj2UGeGepPr9efp+XT/q4f37cU33LqCCDYMwggYBMIID6aADAgECAhMzAAAAxOmJ # +HqBUOn/AAAAAADEMA0GCSqGSIb3DQEBCwUAMH4xCzAJBgNVBAYTAlVTMRMwEQYD # VQQIEwpXYXNoaW5ndG9uMRAwDgYDVQQHEwdSZWRtb25kMR4wHAYDVQQKExVNaWNy # b3NvZnQgQ29ycG9yYXRpb24xKDAmBgNVBAMTH01pY3Jvc29mdCBDb2RlIFNpZ25p # bmcgUENBIDIwMTEwHhcNMTcwODExMjAyMDI0WhcNMTgwODExMjAyMDI0WjB0MQsw # CQYDVQQGEwJVUzETMBEGA1UECBMKV2FzaGluZ3RvbjEQMA4GA1UEBxMHUmVkbW9u # ZDEeMBwGA1UEChMVTWljcm9zb2Z0IENvcnBvcmF0aW9uMR4wHAYDVQQDExVNaWNy # b3NvZnQgQ29ycG9yYXRpb24wggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIB # AQCIirgkwwePmoB5FfwmYPxyiCz69KOXiJZGt6PLX4kvOjMuHpF4+nypH4IBtXrL # GrwDykbrxZn3+wQd8oUK/yJuofJnPcUnGOUoH/UElEFj7OO6FYztE5o13jhwVG87 # 7K1FCTBJwb6PMJkMy3bJ93OVFnfRi7uUxwiFIO0eqDXxccLgdABLitLckevWeP6N # +q1giD29uR+uYpe/xYSxkK7WryvTVPs12s1xkuYe/+xxa8t/CHZ04BBRSNTxAMhI # TKMHNeVZDf18nMjmWuOF9daaDx+OpuSEF8HWyp8dAcf9SKcTkjOXIUgy+MIkogCy # vlPKg24pW4HvOG6A87vsEwvrAgMBAAGjggGAMIIBfDAfBgNVHSUEGDAWBgorBgEE # AYI3TAgBBggrBgEFBQcDAzAdBgNVHQ4EFgQUy9ZihM9gOer/Z8Jc0si7q7fDE5gw # UgYDVR0RBEswSaRHMEUxDTALBgNVBAsTBE1PUFIxNDAyBgNVBAUTKzIzMDAxMitj # ODA0YjVlYS00OWI0LTQyMzgtODM2Mi1kODUxZmEyMjU0ZmMwHwYDVR0jBBgwFoAU # SG5k5VAF04KqFzc3IrVtqMp1ApUwVAYDVR0fBE0wSzBJoEegRYZDaHR0cDovL3d3 # dy5taWNyb3NvZnQuY29tL3BraW9wcy9jcmwvTWljQ29kU2lnUENBMjAxMV8yMDEx # LTA3LTA4LmNybDBhBggrBgEFBQcBAQRVMFMwUQYIKwYBBQUHMAKGRWh0dHA6Ly93 # d3cubWljcm9zb2Z0LmNvbS9wa2lvcHMvY2VydHMvTWljQ29kU2lnUENBMjAxMV8y # MDExLTA3LTA4LmNydDAMBgNVHRMBAf8EAjAAMA0GCSqGSIb3DQEBCwUAA4ICAQAG # Fh/bV8JQyCNPolF41+34/c291cDx+RtW7VPIaUcF1cTL7OL8mVuVXxE4KMAFRRPg # mnmIvGar27vrAlUjtz0jeEFtrvjxAFqUmYoczAmV0JocRDCppRbHukdb9Ss0i5+P # WDfDThyvIsoQzdiCEKk18K4iyI8kpoGL3ycc5GYdiT4u/1cDTcFug6Ay67SzL1BW # XQaxFYzIHWO3cwzj1nomDyqWRacygz6WPldJdyOJ/rEQx4rlCBVRxStaMVs5apao # pIhrlihv8cSu6r1FF8xiToG1VBpHjpilbcBuJ8b4Jx/I7SCpC7HxzgualOJqnWmD # oTbXbSD+hdX/w7iXNgn+PRTBmBSpwIbM74LBq1UkQxi1SIV4htD50p0/GdkUieeN # n2gkiGg7qceATibnCCFMY/2ckxVNM7VWYE/XSrk4jv8u3bFfpENryXjPsbtrj4Ns # h3Kq6qX7n90a1jn8ZMltPgjlfIOxrbyjunvPllakeljLEkdi0iHv/DzEMQv3Lz5k # pTdvYFA/t0SQT6ALi75+WPbHZ4dh256YxMiMy29H4cAulO2x9rAwbexqSajplnbI # vQjE/jv1rnM3BrJWzxnUu/WUyocc8oBqAU+2G4Fzs9NbIj86WBjfiO5nxEmnL9wl # iz1e0Ow0RJEdvJEMdoI+78TYLaEEAo5I+e/dAs8DojCCB3owggVioAMCAQICCmEO # kNIAAAAAAAMwDQYJKoZIhvcNAQELBQAwgYgxCzAJBgNVBAYTAlVTMRMwEQYDVQQI # EwpXYXNoaW5ndG9uMRAwDgYDVQQHEwdSZWRtb25kMR4wHAYDVQQKExVNaWNyb3Nv # ZnQgQ29ycG9yYXRpb24xMjAwBgNVBAMTKU1pY3Jvc29mdCBSb290IENlcnRpZmlj # YXRlIEF1dGhvcml0eSAyMDExMB4XDTExMDcwODIwNTkwOVoXDTI2MDcwODIxMDkw # OVowfjELMAkGA1UEBhMCVVMxEzARBgNVBAgTCldhc2hpbmd0b24xEDAOBgNVBAcT # B1JlZG1vbmQxHjAcBgNVBAoTFU1pY3Jvc29mdCBDb3Jwb3JhdGlvbjEoMCYGA1UE # AxMfTWljcm9zb2Z0IENvZGUgU2lnbmluZyBQQ0EgMjAxMTCCAiIwDQYJKoZIhvcN # AQEBBQADggIPADCCAgoCggIBAKvw+nIQHC6t2G6qghBNNLrytlghn0IbKmvpWlCq # uAY4GgRJun/DDB7dN2vGEtgL8DjCmQawyDnVARQxQtOJDXlkh36UYCRsr55JnOlo # XtLfm1OyCizDr9mpK656Ca/XllnKYBoF6WZ26DJSJhIv56sIUM+zRLdd2MQuA3Wr # aPPLbfM6XKEW9Ea64DhkrG5kNXimoGMPLdNAk/jj3gcN1Vx5pUkp5w2+oBN3vpQ9 # 7/vjK1oQH01WKKJ6cuASOrdJXtjt7UORg9l7snuGG9k+sYxd6IlPhBryoS9Z5JA7 # La4zWMW3Pv4y07MDPbGyr5I4ftKdgCz1TlaRITUlwzluZH9TupwPrRkjhMv0ugOG # jfdf8NBSv4yUh7zAIXQlXxgotswnKDglmDlKNs98sZKuHCOnqWbsYR9q4ShJnV+I # 4iVd0yFLPlLEtVc/JAPw0XpbL9Uj43BdD1FGd7P4AOG8rAKCX9vAFbO9G9RVS+c5 # oQ/pI0m8GLhEfEXkwcNyeuBy5yTfv0aZxe/CHFfbg43sTUkwp6uO3+xbn6/83bBm # 4sGXgXvt1u1L50kppxMopqd9Z4DmimJ4X7IvhNdXnFy/dygo8e1twyiPLI9AN0/B # 4YVEicQJTMXUpUMvdJX3bvh4IFgsE11glZo+TzOE2rCIF96eTvSWsLxGoGyY0uDW # iIwLAgMBAAGjggHtMIIB6TAQBgkrBgEEAYI3FQEEAwIBADAdBgNVHQ4EFgQUSG5k # 5VAF04KqFzc3IrVtqMp1ApUwGQYJKwYBBAGCNxQCBAweCgBTAHUAYgBDAEEwCwYD # VR0PBAQDAgGGMA8GA1UdEwEB/wQFMAMBAf8wHwYDVR0jBBgwFoAUci06AjGQQ7kU # BU7h6qfHMdEjiTQwWgYDVR0fBFMwUTBPoE2gS4ZJaHR0cDovL2NybC5taWNyb3Nv # ZnQuY29tL3BraS9jcmwvcHJvZHVjdHMvTWljUm9vQ2VyQXV0MjAxMV8yMDExXzAz # XzIyLmNybDBeBggrBgEFBQcBAQRSMFAwTgYIKwYBBQUHMAKGQmh0dHA6Ly93d3cu # bWljcm9zb2Z0LmNvbS9wa2kvY2VydHMvTWljUm9vQ2VyQXV0MjAxMV8yMDExXzAz # XzIyLmNydDCBnwYDVR0gBIGXMIGUMIGRBgkrBgEEAYI3LgMwgYMwPwYIKwYBBQUH # AgEWM2h0dHA6Ly93d3cubWljcm9zb2Z0LmNvbS9wa2lvcHMvZG9jcy9wcmltYXJ5 # Y3BzLmh0bTBABggrBgEFBQcCAjA0HjIgHQBMAGUAZwBhAGwAXwBwAG8AbABpAGMA # eQBfAHMAdABhAHQAZQBtAGUAbgB0AC4gHTANBgkqhkiG9w0BAQsFAAOCAgEAZ/KG # pZjgVHkaLtPYdGcimwuWEeFjkplCln3SeQyQwWVfLiw++MNy0W2D/r4/6ArKO79H # qaPzadtjvyI1pZddZYSQfYtGUFXYDJJ80hpLHPM8QotS0LD9a+M+By4pm+Y9G6XU # tR13lDni6WTJRD14eiPzE32mkHSDjfTLJgJGKsKKELukqQUMm+1o+mgulaAqPypr # WEljHwlpblqYluSD9MCP80Yr3vw70L01724lruWvJ+3Q3fMOr5kol5hNDj0L8giJ # 1h/DMhji8MUtzluetEk5CsYKwsatruWy2dsViFFFWDgycScaf7H0J/jeLDogaZiy # WYlobm+nt3TDQAUGpgEqKD6CPxNNZgvAs0314Y9/HG8VfUWnduVAKmWjw11SYobD # HWM2l4bf2vP48hahmifhzaWX0O5dY0HjWwechz4GdwbRBrF1HxS+YWG18NzGGwS+ # 30HHDiju3mUv7Jf2oVyW2ADWoUa9WfOXpQlLSBCZgB/QACnFsZulP0V3HjXG0qKi # n3p6IvpIlR+r+0cjgPWe+L9rt0uX4ut1eBrs6jeZeRhL/9azI2h15q/6/IvrC4Dq # aTuv/DDtBEyO3991bWORPdGdVk5Pv4BXIqF4ETIheu9BCrE/+6jMpF3BoYibV3FW # TkhFwELJm3ZbCoBIa/15n8G9bW1qyVJzEw16UM0xghXtMIIV6QIBATCBlTB+MQsw # CQYDVQQGEwJVUzETMBEGA1UECBMKV2FzaGluZ3RvbjEQMA4GA1UEBxMHUmVkbW9u # ZDEeMBwGA1UEChMVTWljcm9zb2Z0IENvcnBvcmF0aW9uMSgwJgYDVQQDEx9NaWNy # b3NvZnQgQ29kZSBTaWduaW5nIFBDQSAyMDExAhMzAAAAxOmJ+HqBUOn/AAAAAADE # MA0GCWCGSAFlAwQCAQUAoIHcMBkGCSqGSIb3DQEJAzEMBgorBgEEAYI3AgEEMBwG # CisGAQQBgjcCAQsxDjAMBgorBgEEAYI3AgEVMC8GCSqGSIb3DQEJBDEiBCAx/ASS # jE0H5mNlOsVULQZruC8qTlLdhAEO1Ee2hGLtpjBwBgorBgEEAYI3AgEMMWIwYKAq # gCgARwB1AGEAcgBkAGUAZAAgAEYAYQBiAHIAaQBjACAAVABvAG8AbABzoTKAMGh0 # dHBzOi8vZ2l0aHViLmNvbS9NaWNyb3NvZnQvR3VhcmRlZEZhYnJpY1Rvb2xzLzAN # BgkqhkiG9w0BAQEFAASCAQAlGWLrZ4c7nzokycjmlM2aKkUf+FecZy5rpQ6OwGtN # MuodL5A7K7vjh7xuxW8JsYb3ZBG3ncTRCgMrX5517XVWOZFr475QLF7zR4apxGMJ # lqxxDvkTyk/J9gLaCtxIGB2rmcY0SGL14pOA8w53QDPETk/vS4zEpAx7xUF0//HJ # SNH9883qEvmOWkIX1jtZuYBrZvKO8AxsGqHivDqNHD/xI7CzSMWbzl1hH3MjQqYI # xIgahWNJfz/ylu/Y3RZpQ/UI12UrJjOJkB7+9/v2BrFv08Q/2r3mc1uEz5txOred # /FQP2F2r05Q51dLntdMfsM+phjqd09NgQX5Ui5ZG58LloYITSTCCE0UGCisGAQQB # gjcDAwExghM1MIITMQYJKoZIhvcNAQcCoIITIjCCEx4CAQMxDzANBglghkgBZQME # AgEFADCCATwGCyqGSIb3DQEJEAEEoIIBKwSCAScwggEjAgEBBgorBgEEAYRZCgMB # MDEwDQYJYIZIAWUDBAIBBQAEIMktj531eRZG+WtkQelqzZoRZFzjKKPavmUAxtD4 # LCFmAgZaTs9zxwUYEzIwMTgwMTI1MTcyMTI0LjgzMlowBwIBAYACAfSggbikgbUw # gbIxCzAJBgNVBAYTAlVTMRMwEQYDVQQIEwpXYXNoaW5ndG9uMRAwDgYDVQQHEwdS # ZWRtb25kMR4wHAYDVQQKExVNaWNyb3NvZnQgQ29ycG9yYXRpb24xDDAKBgNVBAsT # A0FPQzEnMCUGA1UECxMebkNpcGhlciBEU0UgRVNOOjEyRTctMzA2NC02MTEyMSUw # IwYDVQQDExxNaWNyb3NvZnQgVGltZS1TdGFtcCBTZXJ2aWNloIIOzTCCBnEwggRZ # oAMCAQICCmEJgSoAAAAAAAIwDQYJKoZIhvcNAQELBQAwgYgxCzAJBgNVBAYTAlVT # MRMwEQYDVQQIEwpXYXNoaW5ndG9uMRAwDgYDVQQHEwdSZWRtb25kMR4wHAYDVQQK # ExVNaWNyb3NvZnQgQ29ycG9yYXRpb24xMjAwBgNVBAMTKU1pY3Jvc29mdCBSb290 # IENlcnRpZmljYXRlIEF1dGhvcml0eSAyMDEwMB4XDTEwMDcwMTIxMzY1NVoXDTI1 # MDcwMTIxNDY1NVowfDELMAkGA1UEBhMCVVMxEzARBgNVBAgTCldhc2hpbmd0b24x # EDAOBgNVBAcTB1JlZG1vbmQxHjAcBgNVBAoTFU1pY3Jvc29mdCBDb3Jwb3JhdGlv # bjEmMCQGA1UEAxMdTWljcm9zb2Z0IFRpbWUtU3RhbXAgUENBIDIwMTAwggEiMA0G # CSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCpHQ28dxGKOiDs/BOX9fp/aZRrdFQQ # 1aUKAIKF++18aEssX8XD5WHCdrc+Zitb8BVTJwQxH0EbGpUdzgkTjnxhMFmxMEQP # 8WCIhFRDDNdNuDgIs0Ldk6zWczBXJoKjRQ3Q6vVHgc2/JGAyWGBG8lhHhjKEHnRh # Z5FfgVSxz5NMksHEpl3RYRNuKMYa+YaAu99h/EbBJx0kZxJyGiGKr0tkiVBisV39 # dx898Fd1rL2KQk1AUdEPnAY+Z3/1ZsADlkR+79BL/W7lmsqxqPJ6Kgox8NpOBpG2 # iAg16HgcsOmZzTznL0S6p/TcZL2kAcEgCZN4zfy8wMlEXV4WnAEFTyJNAgMBAAGj # ggHmMIIB4jAQBgkrBgEEAYI3FQEEAwIBADAdBgNVHQ4EFgQU1WM6XIoxkPNDe3xG # G8UzaFqFbVUwGQYJKwYBBAGCNxQCBAweCgBTAHUAYgBDAEEwCwYDVR0PBAQDAgGG # MA8GA1UdEwEB/wQFMAMBAf8wHwYDVR0jBBgwFoAU1fZWy4/oolxiaNE9lJBb186a # GMQwVgYDVR0fBE8wTTBLoEmgR4ZFaHR0cDovL2NybC5taWNyb3NvZnQuY29tL3Br # aS9jcmwvcHJvZHVjdHMvTWljUm9vQ2VyQXV0XzIwMTAtMDYtMjMuY3JsMFoGCCsG # AQUFBwEBBE4wTDBKBggrBgEFBQcwAoY+aHR0cDovL3d3dy5taWNyb3NvZnQuY29t # L3BraS9jZXJ0cy9NaWNSb29DZXJBdXRfMjAxMC0wNi0yMy5jcnQwgaAGA1UdIAEB # /wSBlTCBkjCBjwYJKwYBBAGCNy4DMIGBMD0GCCsGAQUFBwIBFjFodHRwOi8vd3d3 # Lm1pY3Jvc29mdC5jb20vUEtJL2RvY3MvQ1BTL2RlZmF1bHQuaHRtMEAGCCsGAQUF # BwICMDQeMiAdAEwAZQBnAGEAbABfAFAAbwBsAGkAYwB5AF8AUwB0AGEAdABlAG0A # ZQBuAHQALiAdMA0GCSqGSIb3DQEBCwUAA4ICAQAH5ohRDeLG4Jg/gXEDPZ2joSFv # s+umzPUxvs8F4qn++ldtGTCzwsVmyWrf9efweL3HqJ4l4/m87WtUVwgrUYJEEvu5 # U4zM9GASinbMQEBBm9xcF/9c+V4XNZgkVkt070IQyK+/f8Z/8jd9Wj8c8pl5SpFS # AK84Dxf1L3mBZdmptWvkx872ynoAb0swRCQiPM/tA6WWj1kpvLb9BOFwnzJKJ/1V # ry/+tuWOM7tiX5rbV0Dp8c6ZZpCM/2pif93FSguRJuI57BlKcWOdeyFtw5yjojz6 # f32WapB4pm3S4Zz5Hfw42JT0xqUKloakvZ4argRCg7i1gJsiOCC1JeVk7Pf0v35j # WSUPei45V3aicaoGig+JFrphpxHLmtgOR5qAxdDNp9DvfYPw4TtxCd9ddJgiCGHa # sFAeb73x4QDf5zEHpJM692VHeOj4qEir995yfmFrb3epgcunCaw5u+zGy9iCtHLN # HfS4hQEegPsbiSpUObJb2sgNVZl6h3M7COaYLeqN4DMuEin1wC9UJyH3yKxO2ii4 # sanblrKnQqLJzxlBTeCG+SqaoxFmMNO7dDJL32N79ZmKLxvHIa9Zta7cRDyXUHHX # odLFVeNp3lfB0d4wwP3M5k37Db9dT+mdHhk4L7zPWAUu7w2gUDXa7wknHNWzfjUe # CLraNtvTX4/edIhJEjCCBNkwggPBoAMCAQICEzMAAACsiiG8etKbcvQAAAAAAKww # DQYJKoZIhvcNAQELBQAwfDELMAkGA1UEBhMCVVMxEzARBgNVBAgTCldhc2hpbmd0 # b24xEDAOBgNVBAcTB1JlZG1vbmQxHjAcBgNVBAoTFU1pY3Jvc29mdCBDb3Jwb3Jh # dGlvbjEmMCQGA1UEAxMdTWljcm9zb2Z0IFRpbWUtU3RhbXAgUENBIDIwMTAwHhcN # MTYwOTA3MTc1NjU0WhcNMTgwOTA3MTc1NjU0WjCBsjELMAkGA1UEBhMCVVMxEzAR # BgNVBAgTCldhc2hpbmd0b24xEDAOBgNVBAcTB1JlZG1vbmQxHjAcBgNVBAoTFU1p # Y3Jvc29mdCBDb3Jwb3JhdGlvbjEMMAoGA1UECxMDQU9DMScwJQYDVQQLEx5uQ2lw # aGVyIERTRSBFU046MTJFNy0zMDY0LTYxMTIxJTAjBgNVBAMTHE1pY3Jvc29mdCBU # aW1lLVN0YW1wIFNlcnZpY2UwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIB # AQChxPQ8pY5zMaEXQVyrdwi3qdFDqrvf3HT5ujVWaoQJ2Km7+1T3GNnGpbND6Pom # Acw9NfV+C+RMmCrThpUlBVzeuzsNL2Lsj9mMdK83ixebazenSrA0rXLIifWBzKHV # P6jzsQWo96cHukHZqI8xRp3tYivgapt5LLrn9Rm2Jn+E0h2lKDOw5sIteZiriOMP # H2Z7mtgYXmyB8ThgdB46p6frNGpcXr11pa1Vkldl0iY6oBAKQQSxJ5Bn4N7ui5Wj # 5wDkDZzGAg6n1ptMPTPJhL2uosW84YjnSp/2suNap3qOjKEYXmpGzvasq5qyqPyv # fqfksOfNBaJntfpC8dIDJKrnAgMBAAGjggEbMIIBFzAdBgNVHQ4EFgQU2EdwqIU1 # ixNhr4eQ6EUXJOCYpw0wHwYDVR0jBBgwFoAU1WM6XIoxkPNDe3xGG8UzaFqFbVUw # VgYDVR0fBE8wTTBLoEmgR4ZFaHR0cDovL2NybC5taWNyb3NvZnQuY29tL3BraS9j # cmwvcHJvZHVjdHMvTWljVGltU3RhUENBXzIwMTAtMDctMDEuY3JsMFoGCCsGAQUF # BwEBBE4wTDBKBggrBgEFBQcwAoY+aHR0cDovL3d3dy5taWNyb3NvZnQuY29tL3Br # aS9jZXJ0cy9NaWNUaW1TdGFQQ0FfMjAxMC0wNy0wMS5jcnQwDAYDVR0TAQH/BAIw # ADATBgNVHSUEDDAKBggrBgEFBQcDCDANBgkqhkiG9w0BAQsFAAOCAQEASOzoXifD # GxicXbTOdm43DB9dYxwNXaQj0hW0ztBACeWbX6zxee1w7TJeXQx1IfTz1BWJAfVl # a7HA1oxa0LiF/Uf6rfRvEEmGmHr9wWEbr3xiErllTFE2V/mdYBSEwdj74m8QLBeF # Y37Cjx4TFe+AB/FQly3kvfrJKDaYYTTXTAFYAKpi0AcDTcESXZcshJ/O8UZs9fr0 # BgrOm5h7qeQ1CJNmDMVEqElQt/cFO3dxqrAKv3Fu/nsT5GkABu+vIibgxX6tNmqc # cIIXKALgv7zDIaRAAWtXV9LwnmstDUbIp8dH/oSVm3tPnCPlrB3+C28vPnvJdbtJ # i/yOuETd+rLn+qGCA3cwggJfAgEBMIHioYG4pIG1MIGyMQswCQYDVQQGEwJVUzET # MBEGA1UECBMKV2FzaGluZ3RvbjEQMA4GA1UEBxMHUmVkbW9uZDEeMBwGA1UEChMV # TWljcm9zb2Z0IENvcnBvcmF0aW9uMQwwCgYDVQQLEwNBT0MxJzAlBgNVBAsTHm5D # aXBoZXIgRFNFIEVTTjoxMkU3LTMwNjQtNjExMjElMCMGA1UEAxMcTWljcm9zb2Z0 # IFRpbWUtU3RhbXAgU2VydmljZaIlCgEBMAkGBSsOAwIaBQADFQA5cCWLFMh53V8M # XemLnLOUmfcct6CBwTCBvqSBuzCBuDELMAkGA1UEBhMCVVMxEzARBgNVBAgTCldh # c2hpbmd0b24xEDAOBgNVBAcTB1JlZG1vbmQxHjAcBgNVBAoTFU1pY3Jvc29mdCBD # b3Jwb3JhdGlvbjEMMAoGA1UECxMDQU9DMScwJQYDVQQLEx5uQ2lwaGVyIE5UUyBF # U046MjY2NS00QzNGLUM1REUxKzApBgNVBAMTIk1pY3Jvc29mdCBUaW1lIFNvdXJj # ZSBNYXN0ZXIgQ2xvY2swDQYJKoZIhvcNAQEFBQACBQDeFCMPMCIYDzIwMTgwMTI1 # MDkzNDA3WhgPMjAxODAxMjYwOTM0MDdaMHcwPQYKKwYBBAGEWQoEATEvMC0wCgIF # AN4UIw8CAQAwCgIBAAICCF8CAf8wBwIBAAICGOAwCgIFAN4VdI8CAQAwNgYKKwYB # BAGEWQoEAjEoMCYwDAYKKwYBBAGEWQoDAaAKMAgCAQACAxbjYKEKMAgCAQACAweh # IDANBgkqhkiG9w0BAQUFAAOCAQEAdORxn881g9wwAIucByMSwDXernzL8nQPzbBZ # 179YegNIkKQ/nrN5HYT6SJNfacUf9/ZBubGFsDJdWW1WZNp1URGd7S7miELwfAlY # BgDD4NFU7rTlfxc4V4UKblZFJY3eU/euVB0tR/89nKQK1oqmWUGU4jzCS+vHhvNT # mOwTSL31GaTdAiMmzcQby8/6xZLOogXPRlnMRTQRbroZStA8TuHdToXphKiztxSV # MS7xj7j+r1hXtbTV+WkDgIg54nfcuP/69J/Q+ahP5tn4AUB8OH8UT0UK6UwVauTw # X2tOHJ9FY5sgWjjfmJsyOF3bTUKIHIOLHEXJTBiiVMB48jY8RDGCAvUwggLxAgEB # MIGTMHwxCzAJBgNVBAYTAlVTMRMwEQYDVQQIEwpXYXNoaW5ndG9uMRAwDgYDVQQH # EwdSZWRtb25kMR4wHAYDVQQKExVNaWNyb3NvZnQgQ29ycG9yYXRpb24xJjAkBgNV # BAMTHU1pY3Jvc29mdCBUaW1lLVN0YW1wIFBDQSAyMDEwAhMzAAAArIohvHrSm3L0 # AAAAAACsMA0GCWCGSAFlAwQCAQUAoIIBMjAaBgkqhkiG9w0BCQMxDQYLKoZIhvcN # AQkQAQQwLwYJKoZIhvcNAQkEMSIEIPMsECHY/NRgD741a+nYUGZR8qWqQodqad7G # NCf7KMkzMIHiBgsqhkiG9w0BCRACDDGB0jCBzzCBzDCBsQQUOXAlixTIed1fDF3p # i5yzlJn3HLcwgZgwgYCkfjB8MQswCQYDVQQGEwJVUzETMBEGA1UECBMKV2FzaGlu # Z3RvbjEQMA4GA1UEBxMHUmVkbW9uZDEeMBwGA1UEChMVTWljcm9zb2Z0IENvcnBv # cmF0aW9uMSYwJAYDVQQDEx1NaWNyb3NvZnQgVGltZS1TdGFtcCBQQ0EgMjAxMAIT # MwAAAKyKIbx60pty9AAAAAAArDAWBBQlbVpdqIBXfVfzIGx0LjbupvKxbzANBgkq # hkiG9w0BAQsFAASCAQBorEy4pU196rydDDupkq3raho1E2dWj3DHcQ0nLGOo7vA4 # i0AjESN1vkuuYYYecqDjj7xBwm2pFlfKvLGC1jV9Szr1DZBeRyinged2dwQMkoVY # GSO3t6SAMlvQwQArKSBFslMjFHmpm/ZhAdjLj7tXZ0Uok+QCtMStFACx8mHIwawZ # yqDsC2xqUhSLnEW/kggAVqPamSg3u0LCl/O8p1r9KiM+UAEmit4Rim10ndhRX+zp # SVimgkDXPmU2oFuFpvBYXCZy4X6WSQHyxwn8xyQqEwTjfXR9TJ1107Y4smxzTpwr # 8px9dQaJhhfiAFCguenqEGxl1CJfXLIgMnH7mq3v # SIG # End signature block |