From 5aa7ce19950fdb50dd0007e07ff24174db8af522 Mon Sep 17 00:00:00 2001 From: Mikael Andersson Date: Wed, 23 Apr 2025 15:49:52 +0200 Subject: [PATCH] zoomproxy conf to zoom-proxy-common --- .../overlay/etc/hiera/data/local.yaml | 189 ------------------ .../overlay/etc/satosa/backend.crt | 29 --- .../overlay/etc/satosa/frontend.crt | 29 --- .../overlay/etc/satosa/md-signer2.crt | 33 --- .../overlay/etc/satosa/metadata.crt | 29 --- 5 files changed, 309 deletions(-) delete mode 100644 zoomproxy-sto1-prod-1.sunet.se/overlay/etc/hiera/data/local.yaml delete mode 100644 zoomproxy-sto1-prod-1.sunet.se/overlay/etc/satosa/backend.crt delete mode 100644 zoomproxy-sto1-prod-1.sunet.se/overlay/etc/satosa/frontend.crt delete mode 100644 zoomproxy-sto1-prod-1.sunet.se/overlay/etc/satosa/md-signer2.crt delete mode 100644 zoomproxy-sto1-prod-1.sunet.se/overlay/etc/satosa/metadata.crt diff --git a/zoomproxy-sto1-prod-1.sunet.se/overlay/etc/hiera/data/local.yaml b/zoomproxy-sto1-prod-1.sunet.se/overlay/etc/hiera/data/local.yaml deleted file mode 100644 index 2968af7..0000000 --- a/zoomproxy-sto1-prod-1.sunet.se/overlay/etc/hiera/data/local.yaml +++ /dev/null @@ -1,189 +0,0 @@ ---- -satosa_config: - saml2_backend: "/etc/satosa/plugins/saml2_backend.yaml" - saml2_frontend: "/etc/satosa/plugins/saml2_frontend.yaml" - generated_attributes: "/etc/satosa/plugins/generated_attributes.yaml" - internal_attributes: "/etc/satosa/internal_attributes.yaml" - attribute_authorization: "/etc/satosa/plugins/attribute_authorization.yaml" - attribute_filter: "/etc/satosa/plugins/attribute_filter.yaml" - healthcheck: "/etc/satosa/plugins/healthcheck.yaml" -generated_attributes: - module: satosa.micro_services.attribute_generation.AddSyntheticAttributes - plugin: AddSyntheticAttributes - name: AddSyntheticAttributes - config: - synthetic_attributes: - default: - default: - schachomeorganization: "{{edupersonprincipalname.scope}}" -attribute_authorization: - module: satosa.micro_services.attribute_authorization.AttributeAuthorization - plugin: AttributeAuthorization - name: AttributeAuthorization - config: - force_attributes_presence_on_allow: true - attribute_allow: - default: - default: - edupersonscopedaffiliation: - - "^(member|employee)@sunet.se$" -attribute_filter: - module: satosa.micro_services.attribute_modifications.FilterAttributeValues - name: AttributeFilter - config: - attribute_filters: - default: - default: - edupersonscopedaffiliation: "^(member|employee|student)@" -internal_attributes: - attributes: - displayname: - saml: [displayName] - adfs: [displayName] - commonname: - saml: [cn] - adfs: [displayName] - givenname: - saml: [givenName] - adfs: [givenName] - surname: - saml: [sn] - adfs: [sn] - mail: - saml: [mail] - adfs: [mail] - edupersonprincipalname: - saml: [eduPersonPrincipalName] - adfs: [eduPersonPrincipalName] - edupersonscopedaffiliation: - saml: [eduPersonScopedAffiliation] - adfs: [eduPersonScopedAffiliation] - noredupersonnin: - saml: [norEduPersonNIN] - adfs: [norEduPersonNIN] - edupersonentitlement: - saml: [eduPersonEntitlement] - adfs: [eduPersonEntitlement] - schachomeorganization: - saml: [schacHomeOrganization] - schachomeorganizationtype: - saml: [schacHomeOrganizationType] - organizationname: - saml: [ou] - noreduorgacronym: - saml: [norEduOrgAcronym] - countryname: - saml: [c] - friendlycountryname: - saml: [co] - edupersontargetedid: - saml: [eduPersonTargetedID] - user_id_to_attr: edupersontargetedid -healthcheck: - module: swamid_plugins.healthcheck.HealthCheck - name: HealthCheck -satosa_proxy_conf: - BASE: https://zoom-saas-idp-proxy.sunet.se - INTERNAL_ATTRIBUTES: "internal_attributes.yaml" - BACKEND_MODULES: - - "plugins/saml2_backend.yaml" - FRONTEND_MODULES: - - "plugins/saml2_frontend.yaml" - MICRO_SERVICES: - - "plugins/generated_attributes.yaml" - - "plugins/attribute_authorization.yaml" - - "plugins/attribute_filter.yaml" - - "plugins/healthcheck.yaml" - LOGGING: - version: 1 - formatters: - default: - format: "%(asctime)s [%(process)d] [%(levelname)s] %(message)s" - handlers: - console: - class: logging.StreamHandler - level: DEBUG - formatter: default - stream: ext://sys.stdout - loggers: - satosa: - level: DEBUG - handlers: [console] - saml2: - level: DEBUG - handlers: [console] -saml2_backend: - config: - sp_config: - organization: {display_name: SUNET Zoom, name: SUNET Zoom, url: 'https://sunet.se'} - contact_person: - - {contact_type: technical, email_address: noc@sunet.se, given_name: Technical} - - {contact_type: support, email_address: noc@sunet.se, given_name: Support} - key_file: backend.key - cert_file: backend.crt - encryption_keypairs: - - { key_file: backend.key, cert_file: backend.crt } - allow_unknown_attributes: true - metadata: - mdq: - - url: https://mds.swamid.se - cert: "/etc/satosa/md-signer2.crt" - entityid: https://zoom-saas-idp-proxy.sunet.se/sp - service: - sp: - name_id_format: ['urn:oasis:names:tc:SAML:2.0:nameid-format:transient'] - allow_unsolicited: true - endpoints: - assertion_consumer_service: - - [//acs/post, 'urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST'] - - [//acs/redirect, 'urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect'] - discovery_response: - - [//disco, 'urn:oasis:names:tc:SAML:profiles:SSO:idp-discovery-protocol'] - want_response_signed: False - want_assertions_signed: False - want_assertions_or_response_signed: True - xmlsec_binary: /usr/bin/xmlsec1 - attribute_map_dir: attributemaps - disco_srv: https://service.seamlessaccess.org/ds - attribute_profile: saml - module: satosa.backends.saml2.SAMLBackend - name: Saml2SP - plugin: BackendModulePlugin -saml2_frontend: - config: - custom_attribute_release: - default: - default: - exclude: ["eduPersonTargetedID","eduPersonAffiliation"] - idp_config: - organization: {display_name: SWAMID, name: SWAMID, url: 'https://sunet.se'} - contact_person: - - {contact_type: technical, email_address: noc@sunet.se, given_name: Technical} - - {contact_type: support, email_address: noc@sunet.se, given_name: Support} - key_file: frontend.key - cert_file: frontend.crt - metadata: - local: [metadata/zoom.xml] - entityid: https://zoom-saas-idp-proxy.sunet.se/idp - accepted_time_diff: 300 - service: - idp: - endpoints: - single_sign_on_service: [] - name: SWAMID - name_id_format: ['urn:oasis:names:tc:SAML:2.0:nameid-format:transient'] - policy: - default: - attribute_restrictions: null - fail_on_missing_requested: false - lifetime: {minutes: 15} - name_form: urn:oasis:names:tc:SAML:2.0:attrname-format:uri - want_authn_requests_signed: false - xmlsec_binary: /usr/bin/xmlsec1 - endpoints: - single_sign_on_service: {'urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST': sso/post, - 'urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect': sso/redirect} - attribute_profile: saml - module: satosa.frontends.saml2.SAMLFrontend - plugin: FrontendModulePlugin - name: Saml2IDP diff --git a/zoomproxy-sto1-prod-1.sunet.se/overlay/etc/satosa/backend.crt b/zoomproxy-sto1-prod-1.sunet.se/overlay/etc/satosa/backend.crt deleted file mode 100644 index 2fef9c3..0000000 --- a/zoomproxy-sto1-prod-1.sunet.se/overlay/etc/satosa/backend.crt +++ /dev/null @@ -1,29 +0,0 @@ ------BEGIN CERTIFICATE----- -MIIFBTCCAu2gAwIBAgIJAPSHarYbYh/jMA0GCSqGSIb3DQEBCwUAMBkxFzAVBgNV -BAMMDnNhdG9zYV9iYWNrZW5kMB4XDTE3MDgyOTA4MTU0NFoXDTI3MDgyNzA4MTU0 -NFowGTEXMBUGA1UEAwwOc2F0b3NhX2JhY2tlbmQwggIiMA0GCSqGSIb3DQEBAQUA -A4ICDwAwggIKAoICAQCdP/NkGz/PXwB+vN9qgaEXkyKIKUXsesQFv0tx9ivrr9vW -jp5nIQG5OBPlKurw9lyYGKSF8npVdlx+6MBvizn50TxXt4s0DzoPOVyVQM21wA9D -p2Mbxq+Tx4zmHadyY+5upKxAtKwCpygHsgyyQ5okT09FVz6q+yp2xROjbtGx65FF -UwMiJWalfWlJ8E2Vbi4To6rURvSHik7fDMw2geBFntRs0NNniEU9PecJseI0vtzv -/L2JGFJKQzvZ538NtBF0cYWs11J0PfvT5XZyr4GVZSUdqmHsq4KxnGuAKkgnyefG -q8PFdHXEVcobnl3L1iPf1bTs2OiiBzzz0LgmdWHOAYo6gVdpkSdb1pzF1IUCUOhP -BC+8vHZjNnfVyP8wxChLNP559KrJJmHTsp9AetR14WsirNkH5lH/oj35VEioWMR4 -1Win3pT94RErVjKdCmJFNy14NCs3+M2VMmy3jsIL/VSY0ocZ0tdQhSkSm5YDRyOC -KrZcKjdwyie8Rrn3mpctllklkusZAkgf8iq/vhnj/x/jryt5/dUlqrCZ5Lwjp5gf -o8HC56Jw8N0AQldEwvoU1plm82ji/OO/ITZ+cpZ5pCMwIF6X4F6fKTCAtGis/sJy -XSoPt6taVOhJu79B2OE4b7mA8FZFB8xtSI97UaHIR4LYNo1bZGC+Oii98rL9OwID -AQABo1AwTjAdBgNVHQ4EFgQUbIky0J1V8GO64V4tVVaryNOXYK8wHwYDVR0jBBgw -FoAUbIky0J1V8GO64V4tVVaryNOXYK8wDAYDVR0TBAUwAwEB/zANBgkqhkiG9w0B -AQsFAAOCAgEAFh05O9tWYZpvmhI8Ru3mjDpOSkgWdfZIATJ6L35bQnW8J9/DL9yE -a58QQ4xCQm1U0yFr3ssDc5bD/Zvco0pq+RPiyR/ydY+4Ld9HtQjaYYYVTvfv6Vsc -X+UpHVsd0MhMUiFQo1Gq40vTMfenPg2lgzLdqiCorA/l9a3+G1dFIXw7Ro+4LTHZ -lCc+u+yQSkQsBHcVyYCW3UdNKSdGl3u99DY+BXO1aG/J11qvynjkC8o3PvMc39BQ -ryvonVkeIp+DPK2080HUjDpSiXKQElniDeZWkQin5/ra45rLS/23/jkqiOfUrSIu -WdYYGOgXOXU69PM71onMCNJK+MQQOuGky+y5LybunxiDdw0V9Ay1zRrjfUtV1EiD -EA5q2DuTAnkBTvwChA/DPRq7o3/Dw3JajVRN39lXjXcYczeBnTAXrNlCwJMtWQ1o -ZHmcDHEOnUQ6oSlXbWhAOOUQw+0z+RQLYbkK5AMFmUqLEYKIgx6asdxUtvwf4PxQ -6xHYyip9FvJ5GQcwNQpJ06xDeBi5D9wJ8/N2E6LV+7y5prqVvYWQCs5jCEJ+FSWH -5slPKSklNu3s4Ul4D6pqU32243+LNROyRaUuy3wXDfLiZLQa17QAhlim6RWpaplq -Mxe0+tX0hEXUAHD3qoocrc5Nn5gXeDpmZA4Ik8dtzyPj8AkGUtekHt8= ------END CERTIFICATE----- diff --git a/zoomproxy-sto1-prod-1.sunet.se/overlay/etc/satosa/frontend.crt b/zoomproxy-sto1-prod-1.sunet.se/overlay/etc/satosa/frontend.crt deleted file mode 100644 index b7f1c19..0000000 --- a/zoomproxy-sto1-prod-1.sunet.se/overlay/etc/satosa/frontend.crt +++ /dev/null @@ -1,29 +0,0 @@ ------BEGIN CERTIFICATE----- -MIIFBzCCAu+gAwIBAgIJAKGw1jEdxh7jMA0GCSqGSIb3DQEBCwUAMBoxGDAWBgNV -BAMMD3NhdG9zYV9mcm9udGVuZDAeFw0xNzA4MjkwODAwNDlaFw0yNzA4MjcwODAw -NDlaMBoxGDAWBgNVBAMMD3NhdG9zYV9mcm9udGVuZDCCAiIwDQYJKoZIhvcNAQEB -BQADggIPADCCAgoCggIBAMNmUZ4Fvt64HiJCgIytEN2AohTuNs6MWmOUyHj3Gq7J -TO3JmemKCg9MzR4s0dELfm5zd0/yq6EkeYitg2zrY2+87ue1H1wNDCBdq7msjCys -hW0h9bn/7MbwdfePJyyHxROZp+AB5r1mJCQHC8AAJDtVe7Th4A8K2ctC2XIuQn7A -im0giPP5EdKPKvNb+TuZ0yd6KfoX37ZMLSbacJPXs/3t/9e5Alv7wqpV7vUOxPu8 -uyC1yw7t8pMbU+MDskBt0Z+VZP/h8zZNmAtWjAc/1EddhFFyjIDUA9Xbh+yvIonR -CfrbdmxrkFjOXuhNgagJJBfDw4VUfokFa46DwlxgXqaZ8fsVj/n/p8bIdkITtaMw -/WIGs84JjZZd8BDsgFtUj4SJ8uO+4pdPl6yZKQ2CuLHvBdWvDleXUkIoMadkUqg/ -3hzdW8zNXNMFw9kmD3fSvYK89+JGc6Z74N6LnAAZqlQSYXYanKKHuHxTIY2HpiIk -nSzHx5uN3aKJCHA4uSNN7y0/Grlea6CN5OO6ZrWrSo2+MdNsQA2PDJOyoL9wvDav -B/NbOd12QtLSjbCwYqR9sCLm7u870w1UlKUMjJq9H01QpKqavsO3hSnx0av0JU8z -Ft5x6Ipgm0rsjVpgOjv5drxGTEViBRI6vsee5EAzZ0i3Bb/JXe/jswFpBimLeDLB -AgMBAAGjUDBOMB0GA1UdDgQWBBRZUcpJzK4O0vC9E5hylZX7C/2G3TAfBgNVHSME -GDAWgBRZUcpJzK4O0vC9E5hylZX7C/2G3TAMBgNVHRMEBTADAQH/MA0GCSqGSIb3 -DQEBCwUAA4ICAQAQkBpOJ24TuuRH84kuQBr5SMccn+NAHrAlW48NEWZ9UrRJpvo4 -Kf3zOyb9USd+bYlz5y6ThQtfYrDmCmtGWisRIrTLML17D5ffWe4fNmKhbpsL1MSJ -ozPbsCIjeqKLXTTfmnKr3NbW5x0GOowKhz+egVbYrrACupjuo4T7rM6oYV/O38b0 -h+U2vL4KlqZFmZ0Dnn0GibSWnejwZT4ZF7VuuO3YCbLoFLgOOh4Fg3pGmYPxJpVy -rTm7tpyMfhi1QAr0akuTVaV7A81frshPMw29JjUF3DARjaQL8FcPJf7sWGV1kIol -6cAA/iwmXwJ+ZdXNz2Tj7axp17wl03HOOczG2HbXblajwSrjTllXzoj9T+ZViGe2 -XtrnNXAg4IkC7SU14ba3lIlxP3VX5e2kvlTHlTqRcZCnAz5+FNKe4KRDNkSdN1RE -ljGL73m6LxFg0bA8wtwb/KkM3eS1YrxFccys3/GDLkU7wvfpuyprV7USHb9g02IE -i2Xovs/ly4/omWjdj9kN/iVqZB26Pv9bFxClTiJD2sbvmz0Z3O3qBg6VEyyen1Ql -agQ8QFJNklstQD+ZH354h1emKW3J/9DwGkxST+wqpPNjvJDU9nBWSbh/xFvspsBh -aiUovcRg/mWVPPDYc5Lj0ct472HsRavlTTa7p0egzN+FF4Je34IGiRTz0A== ------END CERTIFICATE----- diff --git a/zoomproxy-sto1-prod-1.sunet.se/overlay/etc/satosa/md-signer2.crt b/zoomproxy-sto1-prod-1.sunet.se/overlay/etc/satosa/md-signer2.crt deleted file mode 100644 index f182c7a..0000000 --- a/zoomproxy-sto1-prod-1.sunet.se/overlay/etc/satosa/md-signer2.crt +++ /dev/null @@ -1,33 +0,0 @@ ------BEGIN CERTIFICATE----- -MIIFyzCCA7OgAwIBAgIJAI9LJsUJXDMVMA0GCSqGSIb3DQEBCwUAMHwxCzAJBgNV -BAYTAlNFMRIwEAYDVQQIDAlTdG9ja2hvbG0xEjAQBgNVBAcMCVN0b2NraG9sbTEO -MAwGA1UECgwFU1VORVQxDzANBgNVBAsMBlNXQU1JRDEkMCIGA1UEAwwbU1dBTUlE -IG1ldGFkYXRhIHNpZ25lciB2Mi4wMB4XDTE2MTIwNjA5MjgyMFoXDTM2MTIwNjA5 -MjgyMFowfDELMAkGA1UEBhMCU0UxEjAQBgNVBAgMCVN0b2NraG9sbTESMBAGA1UE -BwwJU3RvY2tob2xtMQ4wDAYDVQQKDAVTVU5FVDEPMA0GA1UECwwGU1dBTUlEMSQw -IgYDVQQDDBtTV0FNSUQgbWV0YWRhdGEgc2lnbmVyIHYyLjAwggIiMA0GCSqGSIb3 -DQEBAQUAA4ICDwAwggIKAoICAQDQVw72PnIo9QIeV439kQnPcxZh/LddKw86eIU+ -nMfl4TpjSIyqTu4KJSnXbJyqXg+jQj3RzE9BUblpGrR7okmQwOh2nh+5A6SmyTOR -p7VEVT/Zw0GNnQi9gAW7J8Cy+Gnok4LeILI5u43hPylNKAnvs1+bo0ZlbHM6U5jm -6MlO+lrYA9dZzoPQqoCQbr3OweAaq5g8H54HuZacpYa3Q2GnUa4v+xywjntPdSQU -RTAbWWyJl3cHctX5+8UnX8nGCaxoBZqNp9PcEopyYJX8O1nrLumBMqu9Uh6GW1nx -OHfKDLvUoykG3Dm704ENVs88KaJXB1qQNsjdlm14UI9XCZbHfnFVnQ53ehsGFMha -Bf/Abd6v2wnhBLH/RxEUlw347qSeokw+SdDTSdW8jOEBiSqP/8BUzpCcbGlgAsVO -NKUS0K7IB2Bb79YYhyMvmJl24BGtkX+VM/mv47dxOtfzNFCMtUcJ2Dluv0xJG8xI -ot7umx/kbMBLuq7WdWELZJrgpt2bb9sXtYBpuxtGCW5g7+U7MNN1aKCiCSfq09YH -qu2DsU7HHAxEcGFXBiepBliCwZ24WLQh53bA3rihaln7SjdapT9VuSTpCvytb9RX -rq39mVuHMXvWYOG20XTV0+8U2vnsjAwsy28xPAcrLWRWoZbRJ+RoGp6L3GACq+t+ -HPIukwIDAQABo1AwTjAdBgNVHQ4EFgQUQ2iqKQV/mMZDeJDtLXvy0Bsn/BQwHwYD -VR0jBBgwFoAUQ2iqKQV/mMZDeJDtLXvy0Bsn/BQwDAYDVR0TBAUwAwEB/zANBgkq -hkiG9w0BAQsFAAOCAgEAHviIAfS8viUN8Qk//U1p6Z1VK5718NeS7uqabug/SwhL -Vxtg/0x9FPJYf05HXj4moAf2W1ZLnhr0pnEPGDbdHAgDC672fpaAV7DO95d7xubc -rofR7Of2fehYSUZbXBWFiQ+xB5QfRsUFgB/qgHUolgn+4RXniiBYlWe6QJVncHx+ -FtxD+vh1l5rLNkJgJLw2Lt3pbemSxUvv0CJtnK4jt2y95GsWGu1uSsVLrs0PR1Lj -kuxL6zZH4Pp9yjRDOUhbVYAnQ017mdcjvHYtp7c4GIWgyaBkDoMtU6fAt70QpeGj -XhecXk7Llx+oYNdZn14ZdFPRGMyAESLrT4Zf9M7QS3ypnWn/Ux0SwKWbnPUeRVbO -VZZ+M0jmdYK6o+UU5xH3peRWSJIjjRaKjbVlW5GgHwGFmQc/LN+va2jjThRsQWWt -zEwObijedInQ6wfL/VzFAwlWWoDAzKK9qnK4Rf3ORKkvhKrUa//2OYnZD0kHtHiC -OL+iFRLtJ/DQP5iZAF+M1Hta7acLmQ8v7Mn1ZR9lyDWzFx57VOKKtJ6RAmBvxOdP -8cIgBNvLAEdXh2knOLqYU/CeaGkxTD7Y0SEKx6OxEEdafba//MBkVLt4bRoLXts6 -6JY25FqFh3eJZjR6h4W1NW8KnBWuy+ITGfXxoJSsX78/pwAY+v32jRxMZGUi1J4= ------END CERTIFICATE----- diff --git a/zoomproxy-sto1-prod-1.sunet.se/overlay/etc/satosa/metadata.crt b/zoomproxy-sto1-prod-1.sunet.se/overlay/etc/satosa/metadata.crt deleted file mode 100644 index b0c82e0..0000000 --- a/zoomproxy-sto1-prod-1.sunet.se/overlay/etc/satosa/metadata.crt +++ /dev/null @@ -1,29 +0,0 @@ ------BEGIN CERTIFICATE----- -MIIFBzCCAu+gAwIBAgIJAO2iLzrmv26eMA0GCSqGSIb3DQEBCwUAMBoxGDAWBgNV -BAMMD3NhdG9zYV9tZXRhZGF0YTAeFw0xNzA4MjkwODAxMjlaFw0yNzA4MjcwODAx -MjlaMBoxGDAWBgNVBAMMD3NhdG9zYV9tZXRhZGF0YTCCAiIwDQYJKoZIhvcNAQEB -BQADggIPADCCAgoCggIBAK8z4ImxS6seGpMECgEuRjQxsEzCSahfvaKe6cfFvvof -1yPKzuBeBoDneQJWhH8L/DePZigNqit33PUJARrkgKbCGsdrElIg8zo2aSPohr3Q -3WXXBRUZyBExEXd/uC3nBWeE1XoccwEOwqRmaP5g9ubH3fmVozM9qWVP4vG+XFRL -b/XVh1k83V7UePHgIaaB2cbjjXwZBneUeTwf9GymTxpa0eJQjGqA0EvfWRTvGoop -nMX6WrMdX2RuxA2Eb1gBbzdXnsWchDcQD5Z2NyWFvzxPBuLnxgxKlBC+rPr/J10w -c9MO/jgq4VimmKWhTz1JwvcBSRmB47xWDmWzjBMOBFpEh9E2YgB2ugKyjvVRnRRF -qoEoNcQvnC/5rChnh8QxxYDMePB8NYL5iwqwYOFqxcjj+dX/ZF9CmBMIP4EFqXr8 -SCdnzz+QAAoLbV6MTQ/Fx1KBPGSO4E1b2/xtJDqyK/qcwWmmcIOWfW75GZeMFZNz -BauPaCfwmlCRqLel2EcPPhjJxgi45fEE7aEGA0HfDxqwVJwsNjD/SVp/cV2pYbvu -t9iip6jmIriw+KsSpCvRrDWCUeMi9YgvuvJaJd+ZG+Ej7d4WALQQDleBEGNybqDw -X7bJEv+BTxDioYb9onXBIZQYNqL69V29FMh8rUMTvKSC5xlFxmmG/XfyhRJItl/p -AgMBAAGjUDBOMB0GA1UdDgQWBBS0yk9TqlMkPqWQU/a+6MNZRaNm5DAfBgNVHSME -GDAWgBS0yk9TqlMkPqWQU/a+6MNZRaNm5DAMBgNVHRMEBTADAQH/MA0GCSqGSIb3 -DQEBCwUAA4ICAQA5H+B9bq7oQVMHvhyheNk46LKzgNgtktU026dyOGvUET1qdizk -HNFTzVfSXVYPLItFDHypGlS38PkmSXSkoAnDC1mNWP73NzNTyTcx6wamjrIPk7w8 -tzN4ZGL3G8irbiUqZg0SCdS/UdAZarsJTF/UpyF+jHsMYtXXJ6mKHftm75F480ip -gSuPXa/hFN5cj9EbQM9lm+Xfy+NjV4pM2JCWTGlzSrIxStk91oBn0T3EmCDmI+mG -mfV8j+AzRMdK/+rLbTPBA1qRnlEt5PXuqPh9zEd1Ipw+yY4SqaXBZCOOpaH0k3l1 -7bhmnhuQutTvEZlmrtYfrL2+MRqmvNfbXyZWPKCw4+H66NUcVD6jpX0/5qomGQt8 -sHHR4igdjyDbrBbiU0AS4spgATDfK05NG/bCIcUGfUlYDYFCViJVbvUUVp7cGlI3 -Ptjv1TXtKOLgehFrbwGHHvzpCrpMjfzttlShqKw/7V30EhgKzXymMvqEGVbTjehh -WoRodEqXKt34iVBEvKWdhSWHTkqTJDGb7ZEgOuQV7r7HPe2UHsYLxRXdArbTAcZg -Ffmq5eZTK7ZNOSTX3sCg/a8pZFN/z14DFiSsdxErgnJlVCsjQrI51iB4QhMWlDHW -3dmaODsyIoA5iaLPRPiFLyq1S1rclzj5dgW29vuLeHDNzZqLTtcdIfNUVg== ------END CERTIFICATE-----