<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>pcuserinfo.com &#187; Active Directory</title>
	<atom:link href="http://pcuserinfo.com/category/windows/active-directory/feed/" rel="self" type="application/rss+xml" />
	<link>http://pcuserinfo.com</link>
	<description>For Geeks @nd the not so Geeky</description>
	<lastBuildDate>Sat, 13 Apr 2013 08:59:17 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.5.1</generator>
		<item>
		<title>Group Policy Management Structuring and Design</title>
		<link>http://pcuserinfo.com/group-policy-management/</link>
		<comments>http://pcuserinfo.com/group-policy-management/#comments</comments>
		<pubDate>Sun, 02 Sep 2012 08:58:11 +0000</pubDate>
		<dc:creator>Mick</dc:creator>
				<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[Windows]]></category>

		<guid isPermaLink="false">http://pcuserinfo.com/?p=2210</guid>
		<description><![CDATA[<p>Group Policy Management &#8211; Organizational Unit (OU) Design and Group Policy Objects (GPO) Implementation First thing to keep in mind when it comes to group policy management is that organizational units are not the same as security groups. The key... <a href="http://pcuserinfo.com/group-policy-management/" class="read-more">Read More &#8250;</a></p><p>The post <a href="http://pcuserinfo.com/group-policy-management/">Group Policy Management Structuring and Design</a> appeared first on <a href="http://pcuserinfo.com">pcuserinfo.com</a>.</p>]]></description>
				<content:encoded><![CDATA[<!-- Start Shareaholic LikeButtonSetTop Automatic --><!-- End Shareaholic LikeButtonSetTop Automatic --><h3>Group Policy Management &#8211; Organizational Unit (OU) Design and Group Policy Objects (GPO) Implementation</h3>
<p>First thing to keep in mind when it comes to group policy management is that organizational units are not the same as security groups. The key thing to remember is that a security group is used to assign permissions whereas a OU is just a container of objects.</p>
<p>Take care of properly designing your OU structure by considering the geographical or departmental location and needs of your users. <a href="http://pcuserinfo.com/wp-content/uploads/2012/09/Group-Policy-Management.jpg"><img class="alignright size-full wp-image-2228" title="group policy management console windows 7" alt="group policy management console windows 7" src="http://pcuserinfo.com/wp-content/uploads/2012/09/Group-Policy-Management.jpg" width="400" height="300" /></a></p>
<p>As you will probably know, OUs most likely contain one or more child OUs which by default inherit security stings from the parent OU.</p>
<p>As usual, no matter the size of your company, try to keep it simple. The concept is very similar to AD design where a single domain in a single forest is the easiest to administer.</p>
<h3>Windows 7 Group Policy Management</h3>
<p>The same goes for OU structure, try to minimize the amount of OUs  in order to avoid too much complexity. Avoid creating additional administrative overhead by creating multiple OUs that are subject  to the same GPO or security settings.</p>
<p>OUs are designed to make administration more easy. Of course, also do not oversimplify your OU structure as this might very easily override GPO settings required for specific users or computers.</p>
<p><span style="text-decoration: underline;"><strong>Group Policy Management Console</strong></span> &#8211; <a href="http://www.microsoft.com/en-us/download/details.aspx?id=21895http://" target="_blank">http://www.microsoft.com/en-us/download/details.aspx?id=21895</a></p>
<h3>What is Group Policy &#8211; Group Policy Management Editor</h3>
<p>The first thing to keep in mind is that GPOs are either applied to users or computers.</p>
<p><span style="text-decoration: underline;"><strong>Starter GPOs</strong></span></p>
<p>Multiple pre-configured GPO settings (3000 +) are available in Windows server 2008 R2. If you are not sure of the template you want just right click on a folder icon in the group policy management editor and choose Filter Options to enter your search criteria.</p>
<p><span style="text-decoration: underline;"><strong>Multiple local group policy objects (MLGPO)</strong></span></p>
<p>Whereas in the past, when you applied a local group policy restriction all users including administrators would be affected by the GPO. MLGPO enables you to enforce different GPOs based on the group the user is a member or any individual user account.</p>
<p><span style="text-decoration: underline;"><strong>Site GPO</strong> </span></p>
<ul>
<li>GPO must already exist to link it to a site</li>
<li>Not very common except to define network settings</li>
</ul>
<p><span style="text-decoration: underline;"><strong>Domain Linked GPO</strong></span></p>
<p>General advice is to leave the default domain policy alone as any changes made to this policy are Doman wide</p>
<p>It is better to create a separate policy and scope and not touch the default domain policy.<br />
Order of Inheritance (Screenshot)</p>
<h3>Group Policy Management Scopes</h3>
<p>As a rule child Ou settings will take precedence over domain or site settings GPOs There are ways to override this behavior, but they should only be used if all other options are not fit for your strategy.</p>
<p>One way would be to “Block Inheritance” Be very careful with this setting as it will block any other policies from being applied to the OU..<br />
Enoforce GPO Settings will do just the opposite and should also be used sparingly.</p>
<h3>Advanced Group Policy Management</h3>
<p><span style="text-decoration: underline;"><strong>Filtering</strong></span></p>
<p>Very similar to using NTFS permissions.  Go to the properties tab and check the Deny Group Policy Setting. (screenshor) As always DENY overrides any other settings.</p>
<p>You should design the scope of management or inheritance  of your OUs properly and only resort to enforce or block inheritance as a rare exception.</p>
<p><span style="text-decoration: underline;"><strong>WMI Filters allow you to filter GPOs based on</strong></span></p>
<ul>
<li>Hardware</li>
<li>Software Deployment</li>
</ul>
<p>If there is anyone out there using Group Policy to distribute software, read on. Suffice to say that it can be accomplished the MS way.</p>
<ul>
<li>Assigned – Software gets installed regardless of user consent</li>
<li>Published – user has the option to install</li>
<li>Has to be an msi file</li>
</ul>
<p><span style="text-decoration: underline;"><strong> Admx vs adm files</strong></span></p>
<p>In the old days –Win 2000 and earlier – we used to rely on Adm files, which were language dependent. They got replicated to all the SYSVOL folders in the domain so that every policy that is created also has every adm file connected to it stored in the SYSVOL. There often was an inconsistency between different language versions.</p>
<p><span style="text-decoration: underline;"><strong>Admx and Adml</strong></span></p>
<p>Admx files contain universal settings whereas the adml files contain language specific settings. These files can be stored in a central store making them a lot more efficient and less bulky than the adm files which had to be present in every SYSVOL volume in previous versions of Windows Server.</p>
<div class="shr-publisher-2210"></div><!-- Start Shareaholic LikeButtonSetBottom Automatic --><!-- End Shareaholic LikeButtonSetBottom Automatic --><p>The post <a href="http://pcuserinfo.com/group-policy-management/">Group Policy Management Structuring and Design</a> appeared first on <a href="http://pcuserinfo.com">pcuserinfo.com</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://pcuserinfo.com/group-policy-management/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Domain Name Resolution and New DNS Features in Windows Server 2008 R2</title>
		<link>http://pcuserinfo.com/domain-name-resolution/</link>
		<comments>http://pcuserinfo.com/domain-name-resolution/#comments</comments>
		<pubDate>Fri, 03 Aug 2012 18:49:44 +0000</pubDate>
		<dc:creator>Mick</dc:creator>
				<category><![CDATA[Active Directory]]></category>

		<guid isPermaLink="false">http://pcuserinfo.com/?p=2074</guid>
		<description><![CDATA[<p>Domain Name Resolution Domain name resolution or domain name to IP resolution in Windows can be achieved by using the NetBIOS Extended User Interface (NETBUI) in combination with WINS as well as DNS. While the former two methods are a... <a href="http://pcuserinfo.com/domain-name-resolution/" class="read-more">Read More &#8250;</a></p><p>The post <a href="http://pcuserinfo.com/domain-name-resolution/">Domain Name Resolution and New DNS Features in Windows Server 2008 R2</a> appeared first on <a href="http://pcuserinfo.com">pcuserinfo.com</a>.</p>]]></description>
				<content:encoded><![CDATA[<!-- Start Shareaholic LikeButtonSetTop Automatic --><!-- End Shareaholic LikeButtonSetTop Automatic --><h3>Domain Name Resolution</h3>
<p>Domain name resolution or domain name to IP resolution in Windows can be achieved by using the NetBIOS Extended User Interface (NETBUI) in combination with WINS as well as DNS.</p>
<p>While the former two methods are a bit outdated and are said to become obsolete, they might still be required for some older legacy applications in your company that require single namespace resolution. <a href="http://pcuserinfo.com/wp-content/uploads/2012/08/domain-name-resolution.jpg"><img class="alignright size-full wp-image-2126" title="domain name resolution" alt="domain name resolution" src="http://pcuserinfo.com/wp-content/uploads/2012/08/domain-name-resolution.jpg" width="326" height="368" /></a></p>
<p>DNS resolves hosts names to IP addresses and contains several new features and enhancements in Windows Server 2008 R2 such as:</p>
<p><span style="text-decoration: underline;"><strong>Stub Zone Support</strong></span> – A zone that only contains a copy of the authoritative servers for a zone like the SOA and NS records without including all the records for the hosts registered in that zone.</p>
<p>Stub zones in Active Directory are useful to hold records of child domains and therefore delegate authority to that child domain for any records it is responsible for.</p>
<p>These are called Delegation or Glue Records. Likewise, you can use stub zones in the child domain to hold records pointing to the parent domain.<br />
To create a stub zone you must have administrator privileges on the target DNS server.</p>
<h3>Domain Name Resolution &#8211; Conditional Forwarding</h3>
<p>Without a stub zone a DNS server will forward a domain name resolution request to an upstream DNS server if it holds no records for the request in its database. This is called a recursive query as the upstream DNS server will contact other DNS servers if it has no record.</p>
<p>Conditional forwarding in Windows Server 2008 R2 means that you can configure a DNS server to forward queries for a particular domain space to one or more specified DNS servers. If no conditional forwarders are configured or the forwarder is unable to resolve the name the DNS server will fall back on its root hints in its attempt to resolve the name.</p>
<p>For Security purposes it is generally recommended to remove the root hints from a domain controller. If the server would use root hints to perform iterative queries it would be vulnerable to attacks from the Internet. Preferred practice would be to use a caching-only forwarder to perform these queries on the public Internet.</p>
<h3>DNS Zone Transfers and Replication</h3>
<p>As long as the zone is Active Directory-integrated and the DNS service runs on a domain controller, it is automatically replicated to all DNS servers. These DNS servers must be specified to allow for zone transfer.</p>
<h3>Read Only Domain Controllers (RODCs)</h3>
<p>RODCs contain a primary read-only zone which can only be updated by pulling new DNS records from a writeable domain controller it has access to.</p>
<h3>DNS Security Extension (DNSSEC)</h3>
<p>Uses digital signatures and certificates to improve domain name resolution security</p>
<h3>DNS Cache Locking</h3>
<p>A popular method of malicious servers sending the DNS server a response to write or overwrite an entry in the cache.  Cache poisoning involves overwriting the entries in the cache with entries pointing to the attackers’ server. Windows Server 2008 R2 lets you lock down the cache.</p>
<h3>DNS Socket Pool</h3>
<p>Allows for a randomized pool of source ports as opposed to the known DNS ports and thus helps in reducing attack attempts.</p>
<h3>DNS Devolution</h3>
<p>Provides host name resolution for child domains. It will first append the domain namespace of the parent domain and subsequently append the namespace for each child domain to facilitate domain name resolution.</p>
<h3>Background Zone Loading</h3>
<p>While it could take a long time in large organizations to load the DNS data and start servicing clients Windows Server 2008 R2 remedies this situation through background zone loading. Background Zone Loading in Windows Server 2008 R2 allows the server to respond to domain name resolution queries much faster by using information stored in Active Directory.</p>
<h3>GlobalNames DNS Zone</h3>
<p>While similar to WINS to resolve hostnames to a single namespace the GlobalNames zone is not supported for peer-to-peer name resolution. Instead the zone holds a CNAME resource record mapping a single-label name to a FQDN, usually belonging to corporate servers or websites.</p>
<h3>WINS Push and Pull</h3>
<p>As soon as a specified number of updated records have been reached in the WINS database the WINS server will push the updates to its peers.</p>
<p>Pull replication lets an administrator specify to allow updates at specific intervals.</p>
<h3>Windows Server 2008 R2 &#8211; New DNS Features in Domain Name Resolution</h3>
<ul>
<li>Background zone loading</li>
<li>RODC support</li>
<li>GlobalNames DNS Zone</li>
<li>Full support for IPv6 forward and reverse lookup</li>
</ul>
<p>&nbsp;</p>
<p><span style="text-decoration: underline;"><strong>Windows Server 2008 R2 DNS Role</strong></span> &#8211; <a href="http://technet.microsoft.com/en-us/library/cc753635%28v=ws.10%29" target="_blank">http://technet.microsoft.com/en-us/library/cc753635%28v=ws.10%29</a></p>
<p>&nbsp;</p>
<div class="shr-publisher-2074"></div><!-- Start Shareaholic LikeButtonSetBottom Automatic --><!-- End Shareaholic LikeButtonSetBottom Automatic --><p>The post <a href="http://pcuserinfo.com/domain-name-resolution/">Domain Name Resolution and New DNS Features in Windows Server 2008 R2</a> appeared first on <a href="http://pcuserinfo.com">pcuserinfo.com</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://pcuserinfo.com/domain-name-resolution/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Deployment Services (WDS)</title>
		<link>http://pcuserinfo.com/windows-deployment-services-wds/</link>
		<comments>http://pcuserinfo.com/windows-deployment-services-wds/#comments</comments>
		<pubDate>Sat, 30 Jun 2012 12:16:44 +0000</pubDate>
		<dc:creator>Mick</dc:creator>
				<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[Windows]]></category>

		<guid isPermaLink="false">http://pcuserinfo.com/?p=1875</guid>
		<description><![CDATA[<p>Windows Deployment Services Infrastructure The arguably easiest way to deploy a standalone installation of Windows is through a setup DVD or CD. Recent versions of Windows – starting from Windows Vista – are now based on WIM files which are... <a href="http://pcuserinfo.com/windows-deployment-services-wds/" class="read-more">Read More &#8250;</a></p><p>The post <a href="http://pcuserinfo.com/windows-deployment-services-wds/">Windows Deployment Services (WDS)</a> appeared first on <a href="http://pcuserinfo.com">pcuserinfo.com</a>.</p>]]></description>
				<content:encoded><![CDATA[<!-- Start Shareaholic LikeButtonSetTop Automatic --><!-- End Shareaholic LikeButtonSetTop Automatic --><h3>Windows Deployment Services Infrastructure</h3>
<p>The arguably easiest way to deploy a standalone installation of Windows is through a setup DVD or CD. Recent versions of Windows – starting from Windows Vista – are now based on WIM files which are image based. Unlike Ghost or any other third party imaging software that use sector-based images,  WIM files contain disk images of that are file- based.</p>
<p>This means that there is a WIM file containing the basic OS setup which can then access other files to create the different Windows editions. This also explains why since Vista all Windows editions are available on a single DVD. <a href="http://pcuserinfo.com/wp-content/uploads/2012/06/Windows-Deployment-Services.jpg"><img class="alignright size-full wp-image-1886" title="windows deployment services windows 7" alt="windows deployment services windows 7" src="http://pcuserinfo.com/wp-content/uploads/2012/06/Windows-Deployment-Services.jpg" width="400" height="300" /></a></p>
<p>Another advantage of the WIM file architecture is that it can be modified before, during and after deployment using tools such as ImageX, Dism and Windows SIM.</p>
<p>Also don’t forget that the WIM image file format is hardware independent so it can be used to install on OS on different hardware platforms.</p>
<p>Microsoft Windows Deployment Services requires Windows Server 2008 with the WDS service installed as well as ADDS, DNS, DHCP and the NTFS file system.</p>
<p>For more information on using WIM installation methods visit this link <a href="http://pcuserinfo.com/windows-7-virtual-hard-disk-vhd-drive-image-virtual-machine-backup-restore">http://pcuserinfo.com/windows-7-virtual-hard-disk-vhd-drive-image-virtual-machine-backup-restore</a></p>
<h3>Windows Deployment Services Configuration</h3>
<p>WDS relies on the DHCP PXE boot service or boot disks for clients which do not support this technology  to make a connection to a bare-metal client.</p>
<p>In Windows Server 2008 R2 WDS provides a server based central management solution for installing any OS starting from Windows XP, Windows Server 2003 and later versions.</p>
<p>The easiest way to install WDS is through the Add Roles Wizard. Once the wizard start it will begin by creating the centrasl image store.</p>
<p>Next, it will check whether the server is a DHCP server. If there is another dedicated DHCP server on the network you should accept the default values of  Do not listen on port 67 and Configure DHCP option 60 to PXE client. That way the DHCP server will service all requests for the WDS server while at the same time disabling these services on the WDS server which prevents conflicts by 2 servers trying to listen on the same port.</p>
<p>Next you will be asked how to respond to client requests which can be No response, Respond only to known  (pre-staged) computers or respond to all which is obviously the most insecure.</p>
<p>At the completion of the wizard you are given the option to add boot and install images to the image store. These can be found on the installation DVD. Bear in mind that you do need different boot and install images for an x64 or x86 version of Windows.</p>
<p>After that you will need to create an image group which basically shares the files in the group across a single instance. For more information on fine-tuning WDS through the properties menu visit.</p>
<h3>WDS Image Types</h3>
<ul>
<li><strong><span style="text-decoration: underline;">Boot Image</span></strong> – Contain Windows PE and the WDS client and offer a boot menu so the client can select which OS to install</li>
</ul>
<ul>
<li><strong><span style="text-decoration: underline;">Install Image</span></strong> – Starts the installation via PXE boot</li>
</ul>
<ul>
<li><strong><span style="text-decoration: underline;">Capture Image</span></strong> – Used to make a copy or capture of a master computer</li>
</ul>
<ul>
<li><span style="text-decoration: underline;"><strong>Discover Imag</strong>e</span> – Used to boot clients that do not have a PXE compatible NIC and start the installation from an Install image</li>
</ul>
<p>Windows Deplyment Services &#8211; <a href="http://technet.microsoft.com/en-us/library/dd348502%28v=ws.10%29.aspx">http://technet.microsoft.com/en-us/library/dd348502%28v=ws.10%29.aspx</a></p>
<div class="shr-publisher-1875"></div><!-- Start Shareaholic LikeButtonSetBottom Automatic --><!-- End Shareaholic LikeButtonSetBottom Automatic --><p>The post <a href="http://pcuserinfo.com/windows-deployment-services-wds/">Windows Deployment Services (WDS)</a> appeared first on <a href="http://pcuserinfo.com">pcuserinfo.com</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://pcuserinfo.com/windows-deployment-services-wds/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Configuring Computer Networking</title>
		<link>http://pcuserinfo.com/computer-networking/</link>
		<comments>http://pcuserinfo.com/computer-networking/#comments</comments>
		<pubDate>Sat, 09 Jun 2012 16:19:10 +0000</pubDate>
		<dc:creator>Mick</dc:creator>
				<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[Windows]]></category>

		<guid isPermaLink="false">http://pcuserinfo.com/?p=1807</guid>
		<description><![CDATA[<p>Configuring Computer Networking  None – No Encryption or Authentication Some wireless access points require the user to accept a user agreement before being able to log on to the network. You can provide encryption through VPN, DirectAccess or IPsec to... <a href="http://pcuserinfo.com/computer-networking/" class="read-more">Read More &#8250;</a></p><p>The post <a href="http://pcuserinfo.com/computer-networking/">Configuring Computer Networking</a> appeared first on <a href="http://pcuserinfo.com">pcuserinfo.com</a>.</p>]]></description>
				<content:encoded><![CDATA[<!-- Start Shareaholic LikeButtonSetTop Automatic --><!-- End Shareaholic LikeButtonSetTop Automatic --><h3>Configuring Computer Networking</h3>
<p><strong> None – No Encryption or Authentication</strong></p>
<ul>
<li>Some wireless access points require the user to accept a user agreement before being able to log on to the network. You can provide encryption through VPN, DirectAccess or IPsec to enable some form of security.</li>
</ul>
<p><strong>Wired Equivalent Protection (WEP)</strong></p>
<ul>
<li>64 or 128 bit encryption</li>
<li>Sufficient to provide basic protection and almost universally supported</li>
<li>Wi-Fi Protected Access (WPA)</li>
<li>Offers significantly stronger encryption compared to WEP</li>
</ul>
<p><a href="http://pcuserinfo.com/wp-content/uploads/2012/06/Networks.jpg"><img class="aligncenter  wp-image-1826" title="Network Security" alt="Network Security" src="http://pcuserinfo.com/wp-content/uploads/2012/06/Networks.jpg" width="400" height="300" /></a></p>
<p><strong>WPA – Personal Shared Key (PSK)</strong></p>
<ul>
<li>Should be avoided if possible as WPA-PSK uses a static key which is difficult to manage in an enterprise environment.</li>
<li>WPA – Extensible Authentication Protocol (EAP) or WPA – Enterprise<br />
Requires a RADIUS server for authentication and allows multiple wireless access points to rely on one central server for authentication.</li>
<li>Network Policy Server (NPS) can pass authentication requests to a domain controller and allows for flexible authentication without the need for a static key.</li>
</ul>
<p>Windows Server 2008 R2 Enterprise and Datacenter support NPS without restriction whereas Windows Server 2008 R2 Standard supports a maximum of 50 clients and 2 remote RADIUS server groups.</p>
<p>Use a Public Key Infrastructure (PKI) to deploy certificates to both your RADIUS server and wireless client computers and enable autoenrollment. RADIUS Proxy Servers can be used to interconnect to forward requests to different RADIUS servers in the forest or for load-balance requests across multiple servers</p>
<p><strong>WPA2 (IEEE 802.11i)</strong></p>
<ul>
<li>Updated, even more secure version of the original WPA</li>
</ul>
<p><span style="text-decoration: underline;">Network Access Protection (NAP)</span> &#8211; <a href="http://technet.microsoft.com/en-us/network/bb545879.aspx" target="_blank">http://technet.microsoft.com/en-us/network/bb545879.aspx</a></p>
<h3>Windows Server 2008 R2 Wireless Network Authentication  Modes</h3>
<p><strong>Computer or User</strong></p>
<p>Windows uses computer credentials to authenticate prior to logon after which it checks the user credentials before the network can be accessed</p>
<p>Computer Only No user authentication is required as the computer authenticates to the network before displaying the logon screen</p>
<p><strong>Single Sign On (SSO)</strong></p>
<p>Supported by Windows Vista, Windows 7 and Windows Server 2008</p>
<h3>Remote Access – Dial-Up and VPN</h3>
<p>Dial-Up connections use an analog phone line to establish a connection to the network and are therefore very secure as you are not connected to the Internet.</p>
<p>Dial-Up access is very costly if you have many clients in your network as each is using a dedicated connection with very low bandwidth. Just like wireless networks, you can deploy a RADIUS server to handle authentication requests for Dial-Up clients.</p>
<p>VPNs on the other hand share a single internet connection thereby significantly reducing costs as your organization will already have an Internet connection and all that might be required is to purchase some extra bandwidth.</p>
<p>The drawback is that an Internet connection is mandatory and that you must allow incoming traffic through your firewall. You could use a Dial-Up connection and then create a VPN tunnel but the added overhead of VPN and the poor latency it provides would offer very poor performance.</p>
<p><strong>Point-to-Point Tunneling Protocol (PPTP)</strong></p>
<p>Originally a Microsoft technology that uses Point-to-Point (PPP) authentication for the user and Microsoft Point-to-Point Encryption</p>
<p>(MPPE) for data encryption.  No client certificate is required when using PEAP-MS, EAP_MS, EAP-MS-CHAP or MS-CHAP V2.</p>
<p><strong>Layer Two Tunneling Protocol (L2TP)</strong></p>
<p>An open standard VPN  protocol relying on PPP authentication  for user-level authentication and IPsec for computer-level authentication as well as data authentication, data integrity and data encryption. Requires computer certificates which in the Windows world is achieved by using Active Directory Certificate Services. L2TP is for now the only technology that can be used over the IPv6 Internet.</p>
<p><strong>Secure Socket Tunneling  Protocol (SSTP)</strong></p>
<p>Uses PPP authentication methods on the user-level authentication while relying on HTTP encapsulation over SSL for data authentication,</p>
<p>integrity and encryption. This enables it to travers many firewalls, NAT and proxy servers that would block traditional PPTP or L2TP traffic. SSTP is only supports on Windows Server 2008 and Windows Vista SP 1 and up and requires a CA.</p>
<p><strong>DirectAccess</strong></p>
<p>Only available in Windows 7 Enterprise, Windows 7 Ultimate and Windows Server 2008 R2 and requires the IPv6 protocol. Therefore transitional technologies such as 6to4, Teredo and ISATAP are mandatory in most networks. Also don’t forget to add firewall exeptions when using DirectAccess. For DirectAcces to work you need the following:</p>
<p>A multi-homed DirectAccess Server which is a member of a domain but NOT a domain controller with 2 consecutive IPv4 assigned to the public interface</p>
<p>DirectAccess clients must be joined to a domain and running Windows 7 Enterprise, Ultimate or Windows Server 2008 R2<br />
An AD domain which holds the Network Location Service Role (NLS) including IIS and the SSL certificate service</p>
<p>A PKI through a CA to support IPsec as well as a DNS server running at least Windows Server 2008 SP2.<br />
Application servers and a network infrastructure that support IPv6 or similar transition technologies</p>
<p><strong>End-to-Edge Protection</strong></p>
<p>Clients connect securely –encryption and authentication &#8211; to a DirectAccess server and can then communicate on the intranet with servers that do not support IPv6. Application servers however must support IPv6.</p>
<p><strong>End-to-End Protection</strong></p>
<p>Clients connect directly to application servers using IPv6 and IPsec over as well the Internet and the intranet. The DirectAccess server functions very much as a router forwarding traffic without accessing the content. This offers the highest level of security and requires the application servers to be running Windows Server 2008 or higher in combination with IPv6 and IPsec.</p>
<p>&nbsp;</p>
<div class="shr-publisher-1807"></div><!-- Start Shareaholic LikeButtonSetBottom Automatic --><!-- End Shareaholic LikeButtonSetBottom Automatic --><p>The post <a href="http://pcuserinfo.com/computer-networking/">Configuring Computer Networking</a> appeared first on <a href="http://pcuserinfo.com">pcuserinfo.com</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://pcuserinfo.com/computer-networking/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Active Directory DNS</title>
		<link>http://pcuserinfo.com/active-directory-dns/</link>
		<comments>http://pcuserinfo.com/active-directory-dns/#comments</comments>
		<pubDate>Sun, 13 May 2012 14:11:31 +0000</pubDate>
		<dc:creator>Mick</dc:creator>
				<category><![CDATA[Active Directory]]></category>

		<guid isPermaLink="false">http://pcuserinfo.com/?p=1717</guid>
		<description><![CDATA[<p>Active Directory DNS Records When a computer that is part of a domain using Active Directory integrated DNS boots up it queries the Service Record ( SRV) from a Domain Name System ( DNS) server to locate the nearest domain... <a href="http://pcuserinfo.com/active-directory-dns/" class="read-more">Read More &#8250;</a></p><p>The post <a href="http://pcuserinfo.com/active-directory-dns/">Active Directory DNS</a> appeared first on <a href="http://pcuserinfo.com">pcuserinfo.com</a>.</p>]]></description>
				<content:encoded><![CDATA[<!-- Start Shareaholic LikeButtonSetTop Automatic --><!-- End Shareaholic LikeButtonSetTop Automatic --><h3>Active Directory DNS Records</h3>
<p>When a computer that is part of a domain using Active Directory integrated DNS boots up it queries the Service Record ( SRV) from a Domain Name System ( DNS) server to locate the nearest domain controller. DNS basically enables the translation of IP addresses into Fully Qualified Domain Names (FQDNs).</p>
<p>So instead of contacting a host through its IP address you can just type in a name like somesite.com which is a lot easier to remember for humans than let’s say 158.56.23.45 which of course is an IP address. <a href="http://pcuserinfo.com/wp-content/uploads/2012/05/DNS-Active-Directory.jpg"><img class="alignright  wp-image-1740" title="DNS Active Directory" alt="DNS Active Directory" src="http://pcuserinfo.com/wp-content/uploads/2012/05/DNS-Active-Directory.jpg" width="400" height="300" /></a></p>
<p>DNS plays a major role in Active Directory and can be used to run independently on a perimeter network.</p>
<p>All DNS communication – whether it be on your internal network or the Internet – always uses UDP port 53.</p>
<p>The root of the DNS hierarchy is the dot (.) after which you have the .com, .biz, .net, .info and other suffixes.</p>
<h3>Active Directory Domain Name Resolution</h3>
<p>Active Directory heavily relies on DNS to match IP addresses to names. DNS therefore provides host records contained in zones specifying a given name resolution for a specific namespace.</p>
<h3>DNS and Active Directory &#8211; IPv6 Addresses</h3>
<p>IPv6 addresses are made up of 128 bits which gives us a lot more addresses than the 32-bit IP4 range that has almost been depleted or used up globally. IPv6 uses 8 16-bit pieces in a hexadecimal format. This should enable us to support addressing on the Internet for a long time.</p>
<p>•    Link-Local – FE80:: &#8211; Similar to IPv4 APIPA addresses that get allocated when no DHCP server can be contacted<br />
•    Site-Local – FEC0:: -  Equivalent to IPv4 internal addresses such as 10.0.0.0/8, 172.16.0.0/12 and 192.168.0.0/16<br />
•    Loopback &#8211; ::1 – Similar to 127.0.0.1 in IPv4<br />
•    Unspecified &#8211; :: &#8211; Comparable to 0.0.0.0 in IPv4 and thus indicating an absence of address<br />
•    Global Unicast – Unique addresses that are routable on the Internet</p>
<h3>Active Directory DNS Setup &#8211; Peer Name Resolution Protocol (PNRP)</h3>
<p>The Peer Name Resolution Protocol (PNRP) relies on peer systems to resolve computer names in Windows 7 and Server 2008 R2. This means, that unlike DNS there is no hierarchical structure as each server or computer holds a record for the name to be resolved. The computer just contacts all other computers or servers until it gets an authorative answer thereby greatly improving the security risk of a single-point DNS server failing.</p>
<h3>DNS in Active Directory &#8211; Global Names Zone (GNZ)</h3>
<p>Replaces WINS but must be configured manually and is only suitable when you have a small number of clients to handle. Useful for older applications that cannot work with the more complex FQDN structure. If a multitude of applications or users require single-name resolution then WINS will have to be implemented.</p>
<h3>Active Directory DNS Structures</h3>
<p>•    Dynamic DNS servers – Default mode when running DCpromo or when installing an AD integrated DNS server. DDNS enables computers and devices to self-register in Active Directory as long as these devices or computers belong to a known entity within AD <a href="http://pcuserinfo.com/wp-content/uploads/2012/05/www.jpg"><img class="alignright  wp-image-1738" title="Active Directory DNS best practices" alt="Active Directory DNS best practices" src="http://pcuserinfo.com/wp-content/uploads/2012/05/www.jpg" width="414" height="290" /></a></p>
<p>•    Read-Write DNS Servers – Usually a primary DNS server that is deployed in perimeter networks and will accept writes from trusted sources</p>
<p>•    Read-Only DNS Servers – Primarily secondary DNS servers that hold a read-only copy of the primary DNS server.</p>
<p>In Windows 2008 we also have the read-only domain controller (RODC) which runs primary read-only zones when integrated in AD DS.</p>
<p>Remember that RODCs provide a copy of the primary zone whereas traditionally  read-only zones are secondary  zones</p>
<p>•    Stub Zones – Contains pointers to other DNS servers</p>
<h3>Active Directory DNS Namespaces</h3>
<p>It is considered best practices to use different extensions for your internal and external network such as .com for external and maybe .local for you internal network. The segregation of your internal network from the Internet is commonly called Splt-Brain DNS.<br />
For more information on split-brain DNS setups, go to<br />
<a href="http://technet.microsoft.com/en-us/library/ee382323(WS.10).aspx" target="_blank">http://technet.microsoft.com/en-us/library/ee382323(WS.10).aspx</a></p>
<h3>Active Directory DNS Delegation</h3>
<p>When you create a domain tree in an existing forest you have to manually configure delegation before the root tree is created. This is because the name of the domain tree is different from the forest root domain. If however you create a child domain in the same forest this process is automated for the same reasons.</p>
<h3>Active Directory DNS – Windows Server 2008 R2</h3>
<p><span style="text-decoration: underline;"><strong>DNS Security Extensions</strong></span></p>
<p>DNS Security Extensions (DNSSEC) provides additional security to spoofing, man-in-the-middle and cache poisoning attacks It uses digitally signed signatures to send its records. To enable DNSSES you will need to edit the registry.<br />
<a href="http://www.microsoft.com/downloads/en/details.aspx?FamilyID=7a005a14-f740-4689-8c43-9952b5c3d36f&amp;displaylang=en">http://www.microsoft.com/downloads/en/details.aspx?FamilyID=7a005a14-f740-4689-8c43-9952b5c3d36f&amp;displaylang=en</a></p>
<p><span style="text-decoration: underline;"><strong>Active Directory DNS Cache Locking</strong></span></p>
<p>DNS Cache Locking prevents malicious users to poison the DNS cache in order to redirect queries to their servers. In Windows Server 2008 the cache cannot be overwritten until its TTL has expired. TTL  Settings can be changed by running the command dnscmd /Config /CacheLockingPercent percentvalue</p>
<p><strong><span style="text-decoration: underline;">Active Directory DNS Socket Pool</span></strong></p>
<p>When DNS Socket Pools are in use with Windows Server 2008 random ports get picked to perform DNS queries. This protects against attackers and randomizes the ports used. Socket Pools can be configured by editing the registry.</p>
<p><strong><span style="text-decoration: underline;">Active Directory DNS Devolution</span></strong></p>
<p>For more information on devolution behaviour in Windows Server 2008 R2 and Windows 7,<br />
go to <a href="http://technet.microsoft.com/en-us/library/ee683928%28WS.10%29.aspx">http://technet.microsoft.com/en-us/library/ee683928%28WS.10%29.aspx</a></p>
<h3>Active Directory Without DNS &#8211; Background Zone Loading</h3>
<p>Whenever an AD DS integrated DNS server holds a large number of zones and records, it needs to load all that data before servicing requests. Background loading enables the server to start processing requests while loading its zone data.</p>
<div class="shr-publisher-1717"></div><!-- Start Shareaholic LikeButtonSetBottom Automatic --><!-- End Shareaholic LikeButtonSetBottom Automatic --><p>The post <a href="http://pcuserinfo.com/active-directory-dns/">Active Directory DNS</a> appeared first on <a href="http://pcuserinfo.com">pcuserinfo.com</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://pcuserinfo.com/active-directory-dns/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Server 2008 Group Policy Management</title>
		<link>http://pcuserinfo.com/windows-server-2008-group-policy-management/</link>
		<comments>http://pcuserinfo.com/windows-server-2008-group-policy-management/#comments</comments>
		<pubDate>Sun, 06 May 2012 11:29:56 +0000</pubDate>
		<dc:creator>Mick</dc:creator>
				<category><![CDATA[Active Directory]]></category>

		<guid isPermaLink="false">http://pcuserinfo.com/?p=1680</guid>
		<description><![CDATA[<p>Group Policy Management in Windows Server 2008 R2 Windows Group Policy management consists of  a setting for defining the configuration, a scope to define the users or computers the policy applies to and finally an application which enforces these settings... <a href="http://pcuserinfo.com/windows-server-2008-group-policy-management/" class="read-more">Read More &#8250;</a></p><p>The post <a href="http://pcuserinfo.com/windows-server-2008-group-policy-management/">Windows Server 2008 Group Policy Management</a> appeared first on <a href="http://pcuserinfo.com">pcuserinfo.com</a>.</p>]]></description>
				<content:encoded><![CDATA[<!-- Start Shareaholic LikeButtonSetTop Automatic --><!-- End Shareaholic LikeButtonSetTop Automatic --><h3>Group Policy Management in Windows Server 2008 R2</h3>
<p>Windows Group Policy management consists of  a setting for defining the configuration, a scope to define the users or computers the policy applies to and finally an application which enforces these settings within the scope. Group Policy is a part of Active Directory and allows you to centrally manage clients and servers alike.</p>
<h3>AD Group Policy Management and Group Policy Objects (GPOs)</h3>
<p>A Group Policy Object contains one or more policy settings enabling it to apply these configuration settings to a user or computer. GPOs can be managed and created in Active Directory through the use of the Group Policy Management Console (GPMC). You can link a GPO to a site, domain or OU which thereby defines its scope. <a href="http://pcuserinfo.com/wp-content/uploads/2012/05/Group-Policy-Power-Management-400_400_cropped.jpg"><img class="alignright size-full wp-image-1701" title="Group Policy Power Management " alt="Group Policy Power Management" src="http://pcuserinfo.com/wp-content/uploads/2012/05/Group-Policy-Power-Management-400_400_cropped.jpg" width="329" height="361" /></a></p>
<p>Two types of filters for narrowing the scope are security filters which apply to specific global security groups as well as Windows Management Instrumentation (WMI) filters which are linked to the characteristics of the operating system (OS).</p>
<p>Windows Server 2008 comes with a third filter called Preferences.</p>
<h3>Install Group Policy Management &#8211; Group Policy Configuration</h3>
<p>Group Policy is applied to users and/or computers and has 3 states – Not configured, enabled or disabled. The standard setting for a new GPO is Not Configured which means that the policy has no effect on the existing configuration.  It is only by enabling or disabling that you make changes to the existing configuration of a computer or user.</p>
<p>Some policies only affect certain editions of Windows so be sure to read the policy settings explanatory text in the Group Policy Management Editor detail pane.</p>
<h3>Group Policy Client-Side Extensions (CSEs)</h3>
<p>Several dozen CSEs, such as security CSEs, CSEs that install software or others that process startup and logon scripts, are present in Windows now. They all are client driven and pull the GPO from the domain as opposed to a server driven, push technology triggering the CSE to apply theGPO settings on the client.</p>
<p>Standard CSE behavior is to only apply settings in a GPO if that GPO has changed to eliminate the need for redundant policy processing. Some settings could however be changed on the client computer especially if the user has local administrator rights. If this is the case, consider using CSEs that reapply policy settings at the next Group Policy refresh even when policy settings have not changed.</p>
<p>The only exception to this rule are Security CSEs which are reapplied every 16 hours by default even if a GPO has not changed. Group Policy Refresh happens every 90 minutes to 120 minutes thereafter and can be forced by running the command Gpupdate /force.<br />
Resultant Set of Policy (RSOP)</p>
<h3>Advanced Group Policy Management</h3>
<p>Computers and users are likely to be within the scope of multiple GPOs linked to the specific site or domain they belong to. RSOP allows you to view the effective policies of these combined GPOs much like effective permissions when dealing with folder rights.</p>
<p><strong>Local GPOs </strong></p>
<p>Starting from Windows 2000 all clients contain at least one local GPO where all policies – except the Security Settings – are set to Not Configured. Once the computer becomes part of a domain local GPOs get overridden by the domain or site GPO in AD.</p>
<p><img alt="" src="data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAl0AAAEgCAIAAAABtFH+AAAgAElEQVR4nOy9eXRUVb74e1zvr/fWG9bv/X7r3t97t2/bt7tt7cYBRdrOspX72qs0kxFDgjKJokFFRQZFAghIAkqCgYAiJIQhkgEIIVMlJKmkKvNcGWue53muOlMl9f7Y55w6NSYVwiCevT4r69TOOfucOknqk+937302xOVyb926deHChdzc3C+++OKPC55jYGBgYGD49fDRRx/t37//9OnTV65cqaqqgqqqqn766advv/32jwuee+KpZ89d/NmHTv1y8c4VH/mVZJr8GgUWBRq+nTzeO8YTDRIXd3xcAHjuOB9QphLhD8PhDyTCN3fsPvyO8N4hWDJQh4QuwAHwBxz+gJMOeSddMUjm9weZOwl+q+dMgj8iDxLrjy6K6L9TLzrtQaYSEiCAZwG5MxaYenfLB4H5LmfO/DC/DZ79bP4vcs5l/dJX8MDUuYs/P/HUs39c8Nznn3+el5dXXFwMFRUVffvtt//6b78tvHTV4sGFRpSngSmG1f4QGpggVmVoZw0BLwJ1XIbVPhL/jAypfPEYnDv+QZV/SE0HHtYgw1pkWIPwtAhPg/C0KE+LjuiwER0GtsFLHh0twTCNIRoRL4e02KAmFmpsgAAdUKP9ABXar8L6VVhfOL00egAKrFuBdZF0KrBOBdYhx9rlaLsM5cpQjgxtkxK0SlG2BGWL0RYx2iJGm8VosxhtEiNNIoJGYWwa6AiQBgHCik99PPgxYMWqjEGCZqOo48MJqJ3wAWrGvYBbo25A1Ygrmps8ZxjDjggqh+0JuDFkC2PQmoDrAxY61/rNs6GizxQL4+y51m+61m+iNq4PmG8MWiqHrJVD1iqe/daIo3rUWTPmqh1314676yY89ZNeFt/H4vsaBP4Ggb9RCANui5AENMVDHJvmmWihkBCw49AqBaCANhocWRhcknZ5GB0ABdqhQDtJugBKtEtJbivQbgXarSQ2uhRIlwLpksOdMn+X3N8pA/g6pd4Oibdd7OmQeNrF7naxmytycUUursgZQTuNDoDYaXajr6/dbHXDSrMnJqrksbjg774/7fZjKotXPR9Y3cgPH71rEQgU1TcV1TfVNTc1tTc1tTf1tTcNtTcNtZWW2kpLbaWtttJRW+move6qve6uve6Jjzvqpav2uqP2uqO20l5baauttNRWmmsrDbWVhtqbulridOqam4rqmybe8Nuv/qfNiwuMiNmNF166+q//9lugRghEioWXflbb8REtQpdiDDUCEdJeErtpYZ4WphQ4ovGPaP0jWng0nLH4jGr9o1r/qMY/GnVUBCOg/XAiHRxbwz4ApWHa/sSbHdESb2dEi4xokREdOqpDR3XImA4d1aFjegwwSm7Qa0ZpG4ARCh02oqO91GMj+nCh6rBhQIQ1ARpsIBo1NqDG+kn6SEKOVGLdSqxbSQoSeFGOcknapGibBG2VoK0StEUCpEh8uBAfQyLk9p0ZcQZdRamujmRWXrwLdqS8eIdqvO9evHM7RniRrsabwza6GoEdKTUCL1JqTOzFRIKMo8bZCDJ5O8YQZBJ2VMS3oyLMjsS2PKTGkB2lITUCL0aqUejkCuPaMeRFU2wvzkGNIS+aPSqzZ168eCZzs3lyUl5ZoaisUFRWqCorNDcrNDfL9DfLDDfLTDfLLFVllqoye1WZo6rMUVXmShIHib2qzFJVZq4qM90sM9ws090s09wsU1dWqMhTGwYGMv7xnzYvPqT2D6thlQ0rvPQziBqhDz/88ImnnrV4cMIEWiTajjG9SIR6Gj9PC48QkC7UwWM6eEwHj+vgcT3BhB4e18ET8RnX+kOAY+MzpvVTjCbPiCa6MsriOmRMj4zpkHE9Mq5Hx/XouAGbMGATBmzcgI3rsXEDwYQBJ2twijGAPhyyflQfgxEdABuhBaDDkeDDWnyIxiDJgIZEjfer8T413qfCe5V4L02Q4K+XS48aKS9KkBbaJ8ttEXJbSBDbiML5jBHpUkzOi8mocTZRY7QXY9rxofditB2vD5jjqTEiaoxQ4yztOL+xY8u9jx1nYUegxk450iVHOuVwJ6lGAqmvg1QjV+zmilwxokaaHelqNLkILypMHiXgjtVoccFHc09RXlRZvHcYOFrdSMF7643j4+KyEnFZibysRFFWoqooUVeUaCpK9BUlhmtXTNeuWK5dsVy7Yr9+xXH9iuP6ZVd8HNcvO8NfOq5fsV+/Yrt2xXLtivnaFcO1K4ZrV/QVJZqKEnVFiaqsRFFWIi8rkZSVGHp60v/z75QXh9Ww2Y0/8dSzq1evhp577rlzF38WGtEkvEjGiFSydFQHj+oIhYzpCAtO6OFJA8w3IACBEREYEb4BEcSHr4cJyKMSoYf5enhyZvyACQqdf1znH9cRLyepq9UjgAlyY9KA8imMKN+I8k1YCCOxITDhfIARVFIvQ0zGYgJgwCcImxKiHQPEDknDVarHR3Q4jwZhTQ0+pMEHNXg/cKQK71XhILnaKUc75Gi7nPBiqxRtlSCtktCHCPgwIj6t7n7WNFqKdy9kTCqbWj3mScKLd1OND1o2NVqNQIrAi3Q1JuXFRGq835nVCEHOmFmNUGMnLWrslCPRauyQAnwdUl+HJEyNFByhkytycoSkGoVhagReNDv9Ur2TxCXVu2SGuMgBxrgYHb7s4/l2D0zWuCnyTl9My8hMwInTFxVGdwQmh//UpnQ9j8e/XCi8XCi+XCi5Uii/Uqi4UqgqKdSUFGpKCg0lhYaSQnNJoaXkvK3kvL3kvKPkvKPk/Okvs6jGT3+ZFbPGUXLeVnLeUnLeUlJoKik0lBTqyWZVJYWKK4WyK4WSK4WSy4Wiy4Wajo60l1KAF4EaBQb03MWfn3vuOeiPC56z+6ZGQonEmbwIIkUtSDmClCkMjDihRyYNBECEQiMiNCIiEyIyIWITIjYTEC+jEBlJTDMjNM4CAwwQRMEPbRNWFhoJeQvJr0ITKjShIgozJjJjIjOeFEIaAhO5QUFJlE60Pg2xiRmhjuoIWQJHDmrwAQ2hxh4l3q3AOhQgoYpw5UibFGkFnwtUEpX0YiOAHi/OOWs6ax3ORY3zmEqd9EfY8ZeeTY2jxnnIplJqTNDRmKwX5xw7ziGzGk+QEZnVO4kdKTt2ysNMSamRsmOHzE/a0dcu8bZLPO1iD1fkpquRI3RyhE6O0AE2KDvSvWiweQVqG0BIoYmBSGMPQxsDvc17+NgJmxuO/lZaRmYwYUnLyBTrHBEY7N6Tb72hG+ifOH968vxp/vnT/POnJYWnJYWn5YWnFYWn1YWnNYWndYWnDYUFpsICc2GBpfAUgH7GtIzMgl17ImrIPQtMhQWGwgJ9YYGm8LSm8LSq8LSi8LSs8LSk8LT4/GnB+dOC86f550+r21pXpyymvDik9vPUsN039ccFz0F/XPCcH5umuzBx1MhT+3kaP5k4BflGeEwHTwAdGhGBkXIJIjYjEjMiNaNSCyq1oDISqQWR0V6G6s1ICAuaCDMqMSOJMAFgiQkWUxjDEBmpb5FuNqNiM0r424SIzajEgkktmMSMSS0Y2JZaMKkFl1pxqRWXWmhYAxILLrHgUksAIAlHHIWIAA8R4VHSnRRAnAJTQGAM8GlM0pgwBMaBIPWkHTX4oAbrV2N9KqxHhXUp0U4ioYpwZAiIF9liQo1NtI+nkBoFSOO8GnFGKd69bGpiO1JqnE1H451Ejb+UbGp0yJhUR+P8q/F+2DHZfseOmJlVeZgaQ8jgDpmfFjgSauSKPVyRm0NIMUKNjrDAUUh4UW1yDov1AJ7EQGckAinBaHyURsf+b74z2jxh9TLjqMw4Gy+OyYwRqEzO3DeWqro6B08cGz5xjHfi2MiJY+P5xybzjwryj4ryc6T5ObL8HOXJHNXJHO3JHN3JHN3JbMPJbMPJ7JOf7YgQIX375Gc7DCez9SezdSdztCdzVCdzVCdzFCdzZPk5kvwcUX6OIP/oZP7RiRPHRk8cGzlxjHfimKyR9fqip+leHFbDPjTci5QLoxOq/HE+f5w/PDDc3dHd3dHNbmUD6ln17Fb2uI5ImQqMCDCi2IxKzKjETLhQbkXlVlRhRRU2EmtCLCS0Sjkdy2whjYvIzDEgBUxsyGjypotcbsEIrJjcisltOEBBbkQRiEBmDSGNBKcAWqUQR0G5U2QOAIRRCEwBgSnAJ+wYAOEjT0eMfR0g1Ih2KYhsKlcWChlbqEE3lBdpYWLMSHHeY8QH2YvRdvw1eJFux8TZ1Bk7GpNV412KHWefXE1gxyQyq6QagSyBHSk1dsiRDhncIYO75EiHzN8u9bVLfNFq5AidHKGLI6TUGBk4Ai8qDPZ+vobOgCARg0JtAuQ6W9bhbw1W95BQG0KkHRJpKS1FZ1Cp+mGxLgK53p676hVlB7f/2OH+Y4cHjx0ePnZ45LvDY98dHP/uoOC7g6LjByXHD8pyDypyD6pzD2pyD2pyD+pI8j/ZHu3jtIzM/E+2gx3A/urcg4rcg4rcg5Lcg5LjB0XHDwq+Ozj+3cGx7w6OHjvMO3Z46NjhgWOHJfW1KxcumKMX+eP8IA5H4Qh6DPLx7uxvsiuLd4J+RCBFSofAiAorqrShShuqsmFgg8CKKK1ofBCKGSRqRSKxEMgpzHBMZBFYEDpyKwq+hrweAlPYYoIrbLjCShhUYcPl1hCySDAKaTQWIkIFiAFmOjgdKm0rNgeEpBonjUR+FQzqGdZig2qsX02MVu0k1IhwZcSnABh6Az5ZqBE39D7FhrsfIz4Q2dQHtaMxwo6zFOQdplIjokZqDE5ENpXqaIyIGiMSqnOz492IHZPvekTnZsdQ7CgP0alAO4AXZUiHDGzA7VI/pcZ2iZcr9gA4QI0i4EVXW5gaicDR5EJXZWyWaq3d40o6PROqMCZVPZOqXpK+SXVs+Oo+vlqite45eFRncfbz1RGkZWQ6nU6n05mWkRmvPlrDMp3tu2UvKzitPYf39Rze13d438DhfUNH9vGO7B05snfiyF5B9l5R9l5Jzl5Zzl5lzl5Vzl5Vzl4Nje8//pQ6BTjL9x9/Sn0X7K/M2SvL2SvL2SvK2SvK3ivI3jt5ZO/okb28I3uHD+8bPLyv//C+3sP7RDVVy596gu7FIbU/zIvRPYvgJX+cH4QdkUYkMBQV5FUW7yz6/m3Qm0hEioQR1RffgFaUq4ARVTZUZUM1DiwSO6ZOgA1V2dDGnEegnEGVHVPZwhisSINAyR4A7dMJd/DsiDjKhimBy7m5UKjkNtgwlR1X2XGVPaByhNGYA0E5w0q79lIqBKXWDdgDyigUNhJ7QEF/adMUp4ZO80jOsMwWCGHVXEiFlpdrpVZNUSoEvVHXEyP0DEisAbEZF5lwEdlzOWnEJwz4GOFFfEiDDaixfhXWq8K6lVinAgzAQdpkIS82iyJnaESo8a7GiPdMjbO04wM+beOe2THCi/HUSM+mxkuozjlwvL+xY4KBObPPrLbLw+zYQcSLSIeMCBzbpf52KaFGboQahYQa2wTOaDUCL/aOK67U9VypD1HC6i1h9X64/VDiYTIfbT9U2tAXRmNfB0/8/va9kzJdWWNfBGkZmUaj0Wg0pmVklt3uKyeh15c39VeE0zUi2f/7/z768+WKf750458vVS576dayl2qXvVS/7O+NK/7evOLFthUpnStTulal9K1KGVqVwluVMhrOsbQ3qVOAsxxLe5O+w8iqlKFVKQOrUvpWpXStSuGuTGlbkdKy4sXbK/7OWvb3mmUv3Vr20s1lL1X+86W+73Nf/B//+6y8SKkRbA8PDAMvFp2vpBPEDUFcnnc8L++b1WCUDRhfIzYjUgsqs4a8SElRbY/txQSo7ajaTngxXJnqy29AEJTbaMfUdqwxB4KgtMsCVG1D1VGCnBGlDVHaEEqHMfbh5oJzqezqy6kQlFo7aMdVdlwNcARUxEvCiyp7ICYhNcZGU5wKrajQKqLSsHJbQGbTXEiFVlRoSU0GZNaAjJsHPXKiLjw9KwGDfUwYGObDJ704qsN5WnxYi1EdjYQXZaFUKiXFpvDBqECNLGH8SHFeA8R7MzY1WS/So8Y5zPRPYMd748X5Gp46m47GmNnUefHiveh6FM+DHRMPWG2PVqMc6ZAh7TKYUKPER6hR7OUQ8aIbqLFN6GwTOtsETmDHNoGjTeDgCB3Ai92jsuLqruLqruKaruKaros1XZdquy/Vds+mO/BKXTeghIQ7JHrvkz3jUm1JfffP4aRlZGo0Go1GE61Yqv5qQ+/Vht5SGh3D4qzf/p8jl4tL//FCxT9euPbKC5WvvHDrlRdqXvkr69W/3n51MfvVRe2vLepYuqhn6aKBpYuGli7i0Tj6xhtU+1RJy8g8+sYb1D7DSxcNLF3Ut3RRz9JFHUsXtb22iP3qoqZXFze8+tfaV/5a9coLla+8cP2VF67944We3GMp/+1/na0X6dnU7o5uMl50BHFD0GMIwnISft7xvEli3CkKvCgxI1ILKrdiChs9XkTVdlQThXpGbKgaxIvZA2CbgJv3CJTbSKuZrQVp6dnwVG1EDS18tCJKbi4E5TaAl8CRVNhqB4DwEW/MgaCcIeql0oYrbbiS2rDhSpBojY26OBVaUaEJ66oMJV3VF1Kh5eUaen+klJsHPXKiljb2h+iYJNVIeXFcT0ulUgNwyFQqR4a2SYm/+TAvikKpVBbNi6x7aMS5dDTO2o7JPgQngRrvmRfnnE2Nb8ekOxpjDk+9G5P9H+Tk6h31O8rCU6wypEOOtMuQDhnSLqVCRn+7xMelqbFN5G6Lr0bgxa5RaXF1N0FNd3FN98Wa7os13WkZmfaEJS0js6SuJwKaF3tK6nt+ppGWkSlPWNIyMq829AGoGLRjWJz16P81euVi+Ssp115Juf5fKTdfTal+NaXm1b+xXvtb02t/ZS9d3PHPxZ3LFvcuWzywbPHQssU8kqOrV9NPGrF9dPVqsNvwssUDyxb3L1vcs2xxx7LFbf9czH5tcdNrf2147W+1r/7t1qspN19NufFfKddfSenNO5byf/9vibxIlyI9m9rd0Q075EGPITJe9AwHPd1F54sm9cRwG6EJEZsQsnMRo8WLqNoOQkO06egjVJ7w63bCjsPX1lApytt29HZO5D6NOY9AOQN0X0bXAFS2gQMQdCA7F4KgFRVqlaBmBdVWas2gjdyBi6hsiMrWD7aV1v4DEHQg+zi56/EGK0IGkQjlwnAvoir74IFQ1jOv0Y6rHSEvgg2lHVfaNZeo7GhO7aVUaEWFBtixv2INlFrbn9iL/JrlxMFrlqdCK8o1MitedwR6JHtIxs2jTr+iXCO1qItepyrSiyYCQhPWfnUNtCpvzyoIeuTEdXJs6qCGeJhcjxLrVmDtcpQrQznk0Jtm2ocLGHdDTVuMVOM9MeJdHYaT2It1fLgumbGpv4hpG3GixuTUGJFcjVZjhBfvZLL/AxI7JmvHmGqk7BhpShnSLkPaZXC7DG6nqZErobKppBqF7jahq41UY6uAtKPAYXShKzM2d43KLtZ0X6zpuVjTc6mm51ItQVpGpjZhScvI/Lm+j87V+j7ukPi9T/dOyPRX6/uussJIy8gUJyxpGZmljf0UZY39ZY39HTzJ3t//99HSkmsrllxbtaRy1ZKbq5bUvL6kPnVJY+qSptQlralL2lOXdKYu6Vm9ZGD1y0Nvvsx78yUA/YxpGZlH09dE1IDdht98eeDNl/tWL+lZvaQjdQk3dUlr6pLm1CUNqUvqU5fUvr6katWSm6uWXF+1pL8gN+V//B8zezE6m0p4kRYjBj3DQIpBB5vwooEahkp60YoprOpLb0ArKlRqOwYyqLzrayAot8mBauyopj3vESjtsgBIMfd2rGjyds4jUGr1ENjIGaB9S33lDWhlhUpjR9UgsUlKVG0f+BqCICKUHPgaglZUqNU2VG1TX04F3ZAxvKiy9h+gdAi2j/QrgRqtiCrciw3ZEJQ9QCRUswdBvNiYQyRXI7yosmsup1KCxJV2XMnNg6C8BhuutGkupUL7uYQU5aQXqe7F/VxcbhvaD0ErKjQyKw4sSPdiKF604lIrXnsEgt6o7bHiUmugu2wN9MiJajPecXUNBEH/LNWMh4beEBM2QP9iF3huqgzjyJBWKdHF2Ez70GmMVqMAYfEJ7o0O754XZxU1hqsxcTb1TtQY6cUHeLJ/ea8hwovXB8yJQ8a7FzXeI0HOnx3paqS9RNplCFcKt8tgrhTg54J4UeLliL1tIg+IF0NqFISpEXixZ0x5ua7/cl3/5bqBy3UDVwD1Ax/vOJy4f3Hbjm+uNgxG0MGTvv9Z1qRUX9owWNowWNpIUNY4+OXB/MQNfnkwv/z2UHnTMJ2uEdlXj/3r2PWyyowVN9euuLV2Rc3aFfVrV7DWLm9au5y9blnr+qXt65d2rV/av3HpwMalQxuX8kiOvv0W1fjRt9+KWcPbuHR449KBjUsHNi7tWb+0a/3S9vVL29YtZb+9rGnt8oa1y+vXrqhdu6J67YqqtSsGzp5+8V/+WxJeDI8X+UGYT0aKVwFBBzvoqI/vRTTKi+qS1dDKa6pwtw1QhgvRnhcKGON7MTxeHPia5sWvuSDXmksKktZHSHnRSuiQ8uIBLpFEHShPg1KrB6icasS4m9SaARuqFNSsgNIuC8lsqhC8xBuzgSxJLwprV0BrLgnpqdShAxB0gIsrBLXLoTxW2OyOqHiR6D4M5VGBF2tjeHFwH/TIPg41jXJ4L/RIVhvecXUNlFrLMeLjBnxUh49o43qRK0OBF5slSJM43IuisKE3RLwYpca7LcX76cVJP92LgCTUODs7xvDiTHac747G5CY1ziabmvip4vPrxTmr8X7ZMbQtC6kR2JErhbkSP1fiB3bkiEk1klJsFbpaBc5WgbNV4AAbRheatunDbp60tHHk54bhqwS8qw280gZeaSNB2e0ROuUUTQQVNLpGle9/vp8vN15rGgnRPHKteeR6BC2jsWGP0ekeU+3/879PVFdWb1lbs2Vt3Za1rC1rmz5Y25S5tjVzLWdrRvvWjK6tGb0fZwx8nM77OI23LW10W9p4fMaiXvK2pfG2pQ18nD7wcXrPRxldWzM6tma0bc1ozVzbnLm26YO1rC1r67esrd+6fujKhZf/57/MKo8aMZef3cqGHVSMOBz0dINIMdqLQhMqNtHnLEbkUdXhCoz0ItEBKaxZRaZPh6+tAV6MzpoOXVsDQbmNsbx4AIIOcOkiDB87Q3gRzAMJz6NyiTke/eVpUGp1P9npqKD1L1JTMJWCmuVQ2iUBRoxZFdSsgNIuCbAGkD61YQ05EJQ9pBTWroDWXBSE9SOysiEoewh8lcf3IhEjhntxeblGaiG9aMGlnDzokbxaCyaxDGaRXpRYcODFva1Y+9U10Ou1HNq4myENDqYwRsaLUpQIFsVhXrxNm9cfOYWRj7DuiQ7nrsb56mgMV+ODEzXeSUfj/VLjXQ0Zf1mxY2SKVYZyZQiX8qIU5kj8XImfE/IiocZWoatVAHC2CpxsvqNV4DC60Hc+/rJjkF/dLrzOnozmRuvkjdbJSkAbn85Nkqo2QRVHUMUR3OIIbnEEfRPaD3cdEqtst8gaAq7gFldQTac9NjXtQjr9fN3+p/8obKhv3LH19o6tTTu3Nu3c2rork7Mrs31XZucXH/Tu+aB/zwdDe7YM790ylrVlPGvL+L4t/PhMRr0c37dlPGsLb+8W3t4tQ3s+GNjzQd+eD7q++KBjV2bbrsy2XZnNO7c279zaum/XwPXrqY//flbxYjwvUpEiGS/WBy2VReeL6I98E8XyIjXuZvjaGghKuyRA1XZU3Z73CJR2SQAMR1YS9SDIU19+A4JSqwdjjbtR2Qa+foTqMqR6DekbxDZ0ZEBpRZVW9aVUsE1toA1HIAiC9nMRhbV/PwRBr1f3WxCFpX8/BC0vVwFHyi2IwooouMch6DgrbP6i+mIqBKXW9FtRhRVjZUNQak2/DWNlQ1D2oILYGFLYNBdTISi1to+azmjD5YLa5RAEQWuK+aG5jFIrLrWqi1KhFfSRNZM1yyBirE3tEQiCoOXlGgnpRYkFk3ByoUfyaiyY2ILVHIHAGByxGe8sXQM9cqLKhHFJL46Gz9PoU2HgYeJg/SnwoNQWmhdDaqSeGy6InMJ4LyPFexA1/hKnbdxfL1bEf6p4UtnUX60dOVKUIw23ozTkRY4EpgJHjthHebFV6G4VuluFLna4GhUW+NgPJQe/PTUgMDb0yWu6pNUdEoJOSXWntLpTWtMpremS1nRJa2NRB+iW1nfL6ntk9T2yYbHxky9zpFpnfY+MFYcGQK88Ho298sY+ghGJ6dDiP4vZza0Hvmj9+gvO17vaD+7qPLir+/CuvsO7+r/ZNXxk18iRnWM5OyeO7uQf28E/tkN8bLskGQTHtguO7Zg8umP86M6xIzt5R3byjuwa+GZX/+FdPQd3dRzc1fHNnu7vDo+VXin/qfCb9etm8GK0FEkvDgcdoRiRwFJJxIsGhJjUT8zTQMFT34AXaenH6kE7djts3A0xGYM20Cb3th2jDcMhjiLnaZAjVKmpGqn09muG7JjaPvg1BB3gEjNDIsbdDIQGzkAQBEFHcvdD0H4uqrAO7Ieg5ankbMgjA3IrorAicisityIKKyrn5kJQbj05u5+c6T+wP3T6XBYtFlTYAqxsCMoeVtgCoI+QKNnDcltAbtMWp0JQal0vfcaFNSADExOpAmYoUoNrUvOyUqHl5VqJNUB6EZdY1IWvU74ktiEIgqD0c2OYwIQDL7YSj7wJJVHBoBsQLHJlGEdGrMLYIkGp5900iULraUSoMTQe9T6pMQk7zrcX748a78IwnHn34pyzqXfPizPbca6CnOWkjrnYUYpwpQiHjBcBbWIfR+xrEwMvelqFbhAvsgUuNt/JFjjZfEe/3D0m0b6x7v2s7BPdQ5MSvVuocVKItAAXQEyhi4FE56b44utcuxuhXkrp6JNAZiD47vgWn7cAACAASURBVO/PGEViMatGyqqRsarlDdXyhmplQ7WqoVp9u1p9u1rfXKVvrjI2V5maq0zNVZbkMTdXmZqrDM1VhuYqfVOV5na1pqFa3VCtADQ3DNRWl5w6veqpPwuVBpEJSSJeHNbAw61Xu1lnImDX5LFvZtWXfswfZxedL5rQI5N6mAgZw4akhp4RQ5/CSA4cjTePIhGR8yjiQz3yJvLBNzEx9++HoP1t1PPhIp6DQ9bTHoVDPTcuFhgRBVowAhARWnDy2aqaC69Dy8o10oinvoEn19Af/Bb1LBvyweUxEJIITJjAiAnIGf3j5KR+KonarwaPSMU6FVi7HOOSq2oQXgz/1IhYaqohzjyNe+/Fu6TG2diRWaMxnheTnbZxb7x49+zYPF+xo5SAyK+SauRIYY7E3yb2t4l9wI5tYm8rqUa2wMUWOAk18p0tfEeXyCbWOr6/UPne9v0rMzZHs4pi7ebX45P61rsUq9/aPBvepHg7Me+++/hv3vgjwerHfrP6T/+e9qffpj3+6JonHk3/8+/SF/w+Y8Ef1j75h7VPPfbW04+te/pP6555fN0zj6975on1zzyxjmIhsfHWM0+8Hf7yrWeeWPvM4xlPP57+1J/WPPlY2oI/vLngD6v//Ps3nviP1x//3ao//XbVn377/nN/PrV5ndLkmtB6wpejn9GLHVeDsCPoMcAeOUXQY3Bo2HnH89isq8MDlUXni8Z1yKQ+tJIU+azw0PNFyUfBYbN5AA35LLcEj04lbRf1rRgPR431TFQZ/dHkZlhqgqWmvn0QtK8VbMMSEnEUUZXkc8ZNxPNgJWZUYsYA4liIzJi4LReCcqsjxGbCRCZMaMKEJkxkJjaiEcQitOiVEeMbsUkjBpbjANMWQ1LU4oMaYuHi7pAUQ8EiW4y2iNEWEdoUpcaIp96wflkh4/wOw2HWaJzrZP+YC1Hd7Y7G+5JcndGOsSc70gJHjhRpk8AcCdwm8bcRagReDKmRLXSzBa4WvhMA1DigcCstsNGJhnCFYYqD2R0BFoElAZ7ZYp0jeGy8YdiSRGREBlX+eF581odOhYWJGnhYA3ezzjg09YbxPMN4URi8vDMFZ4Z72HnH88BiGsRzw/UwXw8LDLDQCIN1oCRmFDyVWwbCsngPAZ+RyEeBI8RzwKOX47CgUnMEiHSGBTcQsbFvLwTtZYetswEQ0rbpLwVGWGiEydWsyFWojLTlqEzEclTCkO1woVlz/nUIgqCv2Bh9iQyBERcYwxZrjCbR8o3R6ziC9Rp12IgOG9ZiQxpskBhrg3YrySeGk+sSg5U0WkRIswhpFiJNwsj0aYMApmAB+HA9H64PTfIjqL231CXFjFMVI0bZxIE+9AaMvkkgwsphRxhD9gjijkEdsl0ftEYS60k3CVwYP1MaRnmv8Q6h2gEb1/rN4JJuDForh2w3h+1VPEf1qKtmzF077qkd99RNeOsnffWTPhbfz+L7qd8u+opmd5vbCUjeqc2ABLlWErYEYUtQtgRtpQEE2SpB2gBSpE0Ct0ngVrG/TexvFftaxf5Wka9V7GsVedlCIEVPC9/VTEqxhe9snnS0TDqaJ+0tNNgkrXwC8BCANoGDI3BwBI6YSxx3AMTOTrGrU+LqlLi6ouiWRuDuAchi0wuQe3rlnr4ZUYToJ/DGZACg9CVgUOWfPT506o8Lno30Il2NecfzEgBWm6LWmRrX+Sd0/kk9sa4htfKi2ER4iFptiiS0kEU05CEhe9E0RgqMvnAjfe3GMIDAwhAYw9di1IcgF0b288nVjEnC1jqeIL+C1YxD6xjrkUkDOmlAJw3YpBGbNNAgX47rsXE9sf4wsU1CW4UYH9Pj9OWIZ0BHWHBEh/F0GE+LDWuxYQ1GPA1VjfWq0B4l2k0+1J+QogRtFRNSbBEhzULCi4DwZRfD1Uh6MVqND64dZ+3FZNVYPeZJNENjJjsmUGMMOyajxvvoRaBGEMsCNd4acQI1AjsCNd5HL85sx+QFmaQdowVJrPgG7NhKqrGVUKOvVeRrFfnYIi9b6GkRuFsEbqDG5klH86QDqLF5wt48aW+esDdPRNkxphppSxxzo9TYKXYlUOOd2DEpNfbF92JIjfNkx5AXwXPgor1IAJYj1sDDGphcjMPP08AjGpin8Y9o/SNaeFRHBo46/4TOD5ad4oP1fqkwK+bywrFlhoiIVYVjEL68MCIwEFncmET7bEIXgX9CSzBO4BsjGdX4RrUU/nDgES2xLPOoFh7VIuRXZFSLjOrQSLToiBYd1WEjWpSnRUe02IgW45EMz5qhCDTYYBTAhX0qrE+FAiN20YzIlaEcCdomQcKkKApJkd6hOAc1PqBenFc71kRNZ0ygxkgvJqPGe+DFebFjAjVSISNQIxU4PiBqnHc7NiVvR0qNbDFCt2OrBG6lqZEt8rGj1NjMdzVPEmpsmnQQapywN0/Y6HaMUCNlx7B1HKMDR+BF0o5JqDGOF3vmGjXOSo0JvThLNdK9OAUWGSa96A+D8CKxMaT2Dal9YHVinsY/ovHzNL4R0hZjAJ1/XOcnwyngSOJrJPq4TEZGbGEAAY/r/ON6/7gujLFogOSA5zS+UY1vhI7aN6L28UiGKVTeYZV3SOUZUnmGVN5BlXdI7RtU+QZVvkG1b1DtG1B6B1S+QbVvgKwZVPsG1f5BtX9QDQ+pkSE1MqRBBtXwoBoeVCOAAQIU0B+fPlX4ywhUaG9MlGi3Eu1WIt1KpEuBdCmIpxK3yxCuDOGAvzcxzBbDLSK4RQQ3i+BmIdwshG+H0xhOgwCmOoRYAj9L4K/nE9QBJgkSB1vzTl1S8JOgdtIXj5oJb824p2bcUz3mBlSNOOnc5DkoYnQfDtno3BiyxuP6oCWMAXMC6EskUmtfzPoRNjExJEXEo3Bi9jWCMTjRa1HFfLz4PeZ2AkRxaYpDswhuFofREgndjrTlwSUhO1JqJKQoJqUodLOF7haBq0XgaiKkaG+asDdN2Jsn7U0TtuYJW/OkrXnC1jxha5kkYE/a2Hwbm28j1Wgn1ejgCB1coYMrcnBFjnYaHSJHh9jZCZA4OyXOLoIEanR1x/dij8zdKyeYWY2xc6qxGVB6Z4T4AI9PWLwYMe4mMmTUwMPqEGD9Rh5AAw9r/DyNn6f2j2j8Ixp4ROMnNQmPkR2QwE/jOv+4Dg4jFKWFGCMZpW1HMApitXB4sSB0rorGN6T0DSl9gwCFd5D8v4P6N6RP4e1TeHvlnl6Fl06Pwtuj8PUofD0Kf4+c3KDRq4B7FHCvEu5VwL1KBNBDgPYo0R4F0qNAuhVIjwLtUaDd4QCfdSkQ8mUMOmPRQa42TD2eGEwf5kiIrGlkjBirT/H2Ly1kvPfZ1JrwOf53taPxDqPGWQaOd55NjdfRGC+b+qBFjXcYPs5XvyNbjBAQmoTZYpgt9rNJNQJahN4WgadZ4G7mu5omXSBqJAQ5AQCaBGqMm1MFgWPEEseROVWxq4MWNc4ucHTPpEYPRZJqjBs19s8iZJwxakzkxTA7husQbFCrG/PUZKJV7eep/Ty1f1jto5xEmhLmafw8LfAlTDFCkdht6kiIM6r8w0BvKt+QKva7HVD6B5S+fgVBXwhvn9zbJ/f2Usg8gB6pp0fq6abRJfV0ST2dUk+n1N1JbHg6pJ4OqbdT6u2Uetul3g6pt0Pq65D6OqR+8LVT5u+UwZ0yuEuOgIW5O4kFSNFO6knBUqQdPAWKBMxeChH+RAyuNDSkm05bFOSgcAS4kK5DyohN8Y0Yz46/eDUm48XZ9zU+HB2N85hNBdsR2dTKIVt0NjWeGu+7HWcQ5By6HmeyI7E2ONgOAROI/JQdW4TeCDUCmiadTZOOpklH04Tj9gQZPkbZkVIje3Y5VeDFOeZU74IaZ86pzuDFRGqkvEjN00BHtGi8hTV4GnhYHSVLWkA5pA6vpDRGHOsPQRwSStVGjJSlM3NGmHrDKoJ+ZQx6FSRyXw+NboDM1wUgVdcp8XZIvB0Sb7vE0y7xcMWedomHK/FwxR6O2AOe5MuVeDkSL1fiaxN7ORJfCKmPI/VxJD6u1M+VwVwZ3C5DOFIYPOSJIw3RJkU4MoQjQ9qkkYBR3REvY8KOB/1PDszBEKMtIrRFhDaL0KZZE/FnH3JkzGkb929G44PwEBxmjcbZT9tIPKPxXs7cmPd5HXcyo4P4ow4fsEqmWOFWSWTsGG3HsMCR2LA3T9rJoaqOlkkHm+9g8x2tAIGDtsoxYcRoL4JIsVPi7pS4uyik7i6puzucHjoyD4BuQcKFZEIuAfHl50tEbBfSSezF0PzF0AiRES1qcAXMbhxgmh3GCFwktJcmAszkwkyhl1RNbIzh25E4CQwzoXfERkeA6uwE2nA0dlRjRzR2hHi4qy1qIUligUlMHbm0Mh7CgUe+dOAacnFj+rfUd4xqXlHGQUERZ0VJ+b0l/sKWd8QM57ViAPIxDuR8IWLWUIxR1tEzhcKBZ4PY6E8e3+wRGe4I0AK9QYnRLzH5JSZYaoaltKdkyMEUZxumsGHUPY/3K3cfmd+/qdBfq2OWBIiN0LH0ddrJJ3zZEJUVIb4SwNGoKWwIHY0NIT/oEG0sdABHBGg0egpnXAwxcWGJiaGAOYIbXbjOiQ+pYTphXhzVodQkAYM7UFxateHjvQwMDAwMDA8rF67e1LtweuKT8OJjC57zY9PkhDl8TI+bPYEN27Kmp4MMDAwMDAwPKxu2ZZnc+LAGpfCh048teA567Mnn/Nj0mAEfM+BjenzMgFu8gQ3bsqampwNTDAwMDAwMDyFT09OEF7UohQ+bfuzJ56DHnlzkx6bHDYFxQ2BMj48bAhbv1MZtWYHANIpNMTAwMDAwPHwEAtMbt2WZ3DhPi1L4sOnHnlxEetEYAGocNwYs3qmNn2Rh+JQfCTAwMDAwMDx8YPjUxk9m6UVDwOINbPwkC8ECbh/GwMDAwMDw8IFggaS9CCMBhxtlYGBgYGB4+IARwovDibxoDIwZAmMGIo/qg3GLA4lP9Sba2vKLj05ahvMWQ3/LHgbfAhvzRvlmCNpcPdv9Q1dytyjfDC0+OhmqubYF2lx9D85L3vmIsyS44fP/s2BgYGB4CPDBOOXF4dheNASAGqn+RY8PM1r98bm1EfrbN/3JfmtO9B9/fvF7GxcnbnO+T5qY8vegTbeol6WboI3l9+rUMd7pPfxZMDAwMDwUeHwY3YvD0V4EkeIYbdyN24vpzL74VG2A/naoL9lvzYWuI39bdGQMfJ3T9dwF+o4vgt4rCZ2a2r4HRL/Te/ezYGBgYHg4cHuxjbHnadDyqBFeNFr942JbfCrSocV7mmPW0L7VnLOQSLW+82Oi1hIwuOfZxXuabePNOQufzakPqyeaTi+qSKdSumsr4lwAlF5Eu85974DKhfsG53pVZINF70BrKyLvSfgb/3Ft+NmpfYgDkyLBnY++4eE/lCLiu3N91wwMDAwPCUarf+O2LON8ezFU0otssbxI+7wuemeOn8UhHZKCJLYjPtzptqBfACmk5pyFtErCZEXvzFnY9fsWgwuI5byoN065s+idhc8SB1ItJEnYnad6eOPc8LBbAYE7GboVDAwMDL9SKC8OaWbyIjXuZh7iRVqsBlEqShK6POr3LSYaac5ZGOmzWF4M340UWEyDJg8hbLqt479x0u4/rl28pyj6wKSIf+dj3PBYqg5zOQMDA8OvEaPVv4H0IiCGFyPGo86TF+ecPqXajCjv/Ch+MLwIxFZEz+4meOPAghXphBHf+TEyLZzUPUngxXi3hX4ULQnMwMDA8Ksk2otDmlheBGq0eKc2bJuX/sWK9Dvsyip6B4rqU0wvss01jxrR5RbzXSRB/b7F4X11id54/b7F9Axq+tq5JpZnuPPxbgvtW/Pw/woDAwPDL5vYXkRpXpwwBADjhoDFM19eDM/sJZ9H/XFtDLvQBrmEDaj5cW3icTcxXXhHXozqqEv4xuk731EP3yzH3cTIo6avXUy/YwwMDAy/WoAXY6ynEcOL+oDFE1j/8d6ZvMjwy+LO/gNgYGBgeLhI5EWwLvG4ITCuD4zp8TE9ZvYE1n30VWIvRg+IvBvXHWPc5V07151f2H089SwugPEiAwMDQ4iQF6PnaQAvjhnwUT02okV5WtTkwt/K3MPEiw8XjBcZGBgYQiTy4h/+8qwfmx7RYsNqdEiFDCphgxNL3/IF40UGBgYGhoeVRF78/RMLfejUkBIekPsHpL4+sUdvR958ZyfjRQYGBgaGhxXKizHWmfrdn57xIlN9Em+v2NsjdHdNOrUWOHX9dsaLDAwMDAwPK4m8+Ns/Pu3xBzomnB0TDu6ovZVnVRt9yzM+YbzIwMDAwPCwArxoduMjWmREi4xo0REt6gde/M3vn3T78NZhC3vI3Dxgut1nUOq9r63+qI4pTGEKU5jClIe3hHlRh4zoSC/+2+8WuLzY7V5jY7e+oUtX36GVaVyvrMz0wgEGBgYGBoaHlfB4ERnRIYQX/5/f/tnpQeva1bUcdS1HXdOqkqqdS5ZtYfKoDAwMDAwPK1QedVSLUhBe/J///menG61pU1WzFVVsRVWLXKJyvPTau78gL/5YWL5x84fLV6Yly8bNH/5YWH7fr5+BgYGB4R4DvGjx4GM6lILw4r/+5gmnG61mK2+1KG61yG82ySVKx99f3fxgenH3V98odW56zZlzpWvXvXvwSF5u/vlkOXgkL/XNt86cK43X+IPGg3+FDAwMDL8IZuNFxa0WeVWz/GaTTKJ0vPhfvxgvrt+U+U1O/pmffr50tSZZrpTVHzySt35TZrzGKW7Vtx/O/nY2XLvVHO/iOfFLG4ejMbjm8PbpPJPKnpGn0gfu+w+RgYGB4b5DeXFch1KQedTfPOF0ozVsZTVbUd2iqG6RS1WOv88ij/pzBevYd6fm5fqOfXfq5wrWbPaMFsPylWmnfrhUUs6qZnUnS11TfzWre/nKtHiNUxzO/tbp8tqdbqvdZbY5jRaH3mTTGqxqvUWpNcs1RpnKsPWrU+Mi5eHsb+NdPIfDmcbt07h9OmCfDtiDAUcw4JjGHdNTvv7+/qamJpHcmOzbp/PU5lFA1g+mr8+ZjxSaj16wfHfRlnfZ9n2J/USJI++y45n07vv+68jAwMBw3wl5UY9S0PoXPWgdR1XbBlDK1K6Xl76X2IvFV26u37Dx422fzcv1rd+wcdsn22ejxphePFtYVlnDbWwdTpbbbSO323iz9CJfJJ4NCbzY1tZGeDFcjcGAu6ury+/3NzU18yWGpN4+nSfXjwC+/sl0pMjcOuALBoPBYHBUhFyudR+/5Mgpci58o/W+/zoyMDAw3HfoXpwgCY1HdXmxxk5NQ4eG1aFmdagVWtd/Ln8/gReLLt9Yv2Eji8Xa+uG2ebm+9Rs2NjQ0zEaNMb14/uL1alY3u2Miv+BsUrA7JtgdE7P0ond2JYEX2Wz2FG6LpUZ7U1NTY2NjY2NjU1NTUm+fzjPp3YDsC5bSRlcwGOzj6ds6RoPBoM+PZf+kOPCjc2FqY4L2k72B9+sXmoGBgeEOIbzoxScM6IQBnTSgkwYUBl78fx/9i9uLtfTpm3v1zb265l6dSu95ZVWmyeqfkNiiKb5SuX7Dxrq6uqKioq0fbou5T7Ks37Dx4sWLbW1tQI0J9tz91TcqvZtes3xlWnHJTVZzf3uvKL/g7LhImQCQ6gRf8wvOtveK2ntFy1emxWucAnix4kYDRVP7UASUF+NdfEtLyxRmi1KjdRq3TONGr0Nh0kubmpqSevt0Fr7ZCjhabD1Vav+pXLbpw7ztX9c1caXBYPDoqVu7vjc++3p1gvaTvYHz8tNnYGBguPeYrP4N27KsXnySlCKf8uK//W6Bx4dzhkycISNnyMwZMmmMvtdWf2Sy+ick9ggullSt37Cptra2qKjo8uXLWz/ctu2T7dEUl9yMPnZCYi8uubl+w6aYXL16taKigsPhkGqMcfiExL77qyMqvYdes3xl2uXSmtttvK5BWX7B2U+/+n6W5Bec7RqUdQ3Klq9Mi9c4BeVFkJmsuNEALEjpMNyLsS++qalpCrMRasSAGq3TmHkaM06jumlUPY0oGxsb4x2e+AonJPaFqSzAtxdtx4pt2YXGA6ckh887pBo8GAxu+7Jo6zdjz6Y1JGg/2RuYoCkGBgaGBxnKi3wDSgFTz4Hz+vGuMVvnqLVrzNY1ZtVZ/MvSt5ls/kmpnc6FyzfWb9hUU1MDpHj16tXy8vKysrKrV69evny5sLCwoKDg6NGj1dXVn+/8IuJYwPoNm8rKyvLy8goKCs6ePXvx4sXS0tJr166VlpZeunTpwoULZ8+era6u3vbp9qvXWDFb+GLvEbXBQ69ZviqtpLyupX2sl6fMLzgrlGljMilWjwuVdPILzvbylL085fJVafEap4jwYlP7ED12pABejNnCpNTe2NgIvPjqa8unMBurpvn745cJci9PI3KZjVXMzot3eOIrnJTan02tBRy7YPu22H640L7/B3v/BBoMBmuaJlZvzs3MkT6/sjhB+8newARNMTAwMDzImGyEFwVGlE9CePHf//CUDw70CRx9Ake/wNEncBhs8Mq3PzPbYL7MQXHhCiHFwsJCIMWysrLy8vLS0tLi4mJgxKysrM8++6y0tHTHzi/ox1Ks37Dp3LlzOTk5eXl5p06dOnPmzA8//AC+/vDDD6dPnz558mRubm5ZWdknn24vvd4Q3cIXe4+oDV56zYpVaaXXWK2d4wNjmvyCs+cvX5sl+QVnB8Y0A2OaFavS4jVOEeHFmIXyYswW+DJHfX19ALURISNmmUJN06hhGtFOIappRD4Nizv0P7zV9mSLoDNeCwmukC9zPPt6NSC7yH7onD3rrIPV5Q8Gg209yjc2HV+3o37LUf1fV5yOdzhf5kj2BiZoioGBgeFBxmyDN2zLsnlxgREVGDEA4cVHH3vah0zxpG6e1D0sdfNkbpMDTd3wudkOC+ROig0bNlVXVxcWFl66dKm0tLSioqKsrOzixYtnzpz57rvvDh06tGfPnu3bt2dmZpaUlOzY+QX9WHojly5dOnbs2NGjR7/99tvc3NyTJ0/+8MMPP/744w8//FBQUJCXl5eTk3PgwAEul/vJp59Ht/BlVrbG6KPXrFi1pvR6Q1vXxOC4Nr/gLEIWiVL36VffI/FLfsHZwXHt4Lh2xao18RqnoHvxfxkMBoPBylvVdOhejNmCQO6sra0NoNYAap1CLVOoaQrVTyEam2towFDSpT83pC++Jt392fD/t4GzqEXQEbOFBFcokDufT60A7D9r//K0fWeB3QdP94+ZUjcdz/jk5rtHdJuOaF5YWRDvcIHcSb+BESX6fuYXnE3QFAMDA8ODjNlOeFFoRIVGVGjChCYMxsn1F/3o1LjaN6byjat84yqfxYW9uXmnxQ6LFE6Kn8trt32yvbu7u7S0tLS09PLly2fPns3Pz//2228PHz68d+/e7du3b9269Z133rl48eKOnV/Qj6XYsGHTuXPn9u/ff/jw4ePHj586dYouxRMnThw9evTrr79ms9nbPtl+vao5uoU9Wdlak49es/L1NeU3GrjdE8MT2vyCszAMv5/PXp7NBZ/jMFn0DtWahoUwreQXnB2e0A5PaFe+viZe4xRJxYsxWxApnNXV1QHUGkDMr762fArR11c3fH/88qGirI3tz77T9fyGzoUbuhYeMr+frftkXdtzrcLO2bx9OotXFgJ2n7J/ftL6aZ45GAzerB9Y81H5uzm6dftVa/fKU5Ydjne4SOEENxCU9OqFXboW6iV1P8HtBTcwQVMMDAwMDzIWO7xxW5bdh4tMqNCECk2oyEx68T8efwbGpia1/kmtn6/183V+qwdP37LL6kDEShed0mv12z7Z3tPTc+7cuTNnzrS1tbW0tDQ2NtbW1t68ebOiouLq1augm3DHzi8ijgVs2LDp2rVr1dXVLBarqamJTZbm5uZz584dO3bs0KFDra2t2z7ZfuNWS8wWvtqXrTP56DUrX19ztaKO3T7Sz1PkF5z1kQV8joNtlVWypmHhmoaFPlrJLzg7MKIcGFGufH1NvMYp6F4E0WGCeDFmC2Klq7KyMoCYA7ARR3QBWB3wK6b80m510ab253dIP9hr+OgSfjrH++l5OPeoNHMdZ+Fs3j6dF5bnAT7JNX183LL1W+OJUuv2fZfWfFrz1gHVmn3KtP2yF5fuiHe4WOmi38A36596veHJVlVt9P2kbmCCphgYGBgeZKwOhPIiQGzGEMKLTzwDY1NCg19g8AuNsMgI2714xge7rU5EonJHUFHZuGv3ntbW1lOnTt2+fXvnri9jcrWiLvpYicp9taJu1+49Mamrqzt06FBbW9uu3XsKi8tiHi5Rub/an6M3++k1K1PXlF1ncbsnhsY1+QVnvV4vPV4EY0TXNCzcI926pmEhfaJhfsHZwVHV4KhqZeqaeI1TJBUvxrv4Gzdu4LAhAOsCsBr3ywN+ScAn7Nde2Mh9dlP74k0dizd1LP7BlvWjc/9G7vOtou7ZvH06f1uWDfjwW+MHR7Xv5ejO3LBeZanX7B5M269I3S1ZsUP84tId8Q6XqNzgBtJv2luNL4CX1P0EtxfcwARNMTAwMDzIWJ2EFyVmlMAS8uLTMDYlNPpERr/I6BeZ/HYfnpG52+ZEpWpPNOU3Gnbt3nP79u26urqdu76MuU+y7Nq959atW62trbt276msZifYc+/+HIMFptesSk2/XtXU2SccExjzC856yAI+x8G2yioG8aKHVvILzg6OqQfH1KtS0+M1ThE9fzHBeNR4F3/hwgUc1uI+1auvLcd9kvqqmu+PX87N/+lQ0b4DF78YUJ8+OrB898jSDdzn2aLOWb59OinLDgO25Og2f6PbdEgNhL2voCd1t2TFTvHSzwV/X7otwe2l38B1DX99uymFrayNvp/UDZyXnz4DAwPDvcfmRDduy3L4AlILRkF48XdPPAVjod0FSAAAIABJREFUAZHJKzJ5RSaf2Oy3+7CMzJ12FyrXeGJSfoMFTLZz15fx9kmKXbv3cDicXbv3VNWwE++ZdSDHaIHpNatS029UNXX3CyeEhBfp8SL1Ia6xyaO9OMrXjfJ1q1LT4zVOEf28m1IjWmpEK02o3eGQyhUA4MV4F3/y5EnMp8J8MtwrDngFuGccd/Nw1yDu6sWdnQEn95rg87fYT7YJu2f/9ulQXtz0jWbdflVGluJEqbHwZ/Y/0o78cxv31c8Fr346+fLSDxLc3jAvsv7arr4d/X8GuL3gBs7LT5+BgYHh3mN3EV6UWTAKwouPPv4kjAWERpfQ6BYaPSKTx+7D0j/YYXehCq03Hjeqmnbt3rNz15cJ9pk9IJVaVds6455ZB46arDC95vU30itvNfcMiCZFpnjxYsySX3B2XGAYFxhefyM9XuMUwIset4fiX0aCALvDUctqAAAvxrv4o0ePYl4Z7hVjHj7uHseAFJ29uLMDd3BwBztgv3306NGk3j4dKo+6dp887SvFm3ulq3ZI/vkh+7/eq3r108l/fDLxnx9Pvrx0S4L26TcwosSMF+flp8/AwMBw7yG86A/IrJjMismtmNxKevG3jy+AsYDA4BSaXCKTW2z22H3omg+2O9yYUudLwK26toIzhYn3mSUFZwpv1bXNZs99Xx8z2RB6zbtbPr5Seqt3SMyXmJN9vOek2DQpNr275eN4jVNwu8dnuc5UDasj3sXvnV1J6u3TeXnpBy+/tnkGlm5J0H6yN3BefvoMDAwM9x6HG9u4LcvpD8hJKSqsGEp48U9/gbGA0OgQGp0ik0tsdtt96JtbPnO6MZXe96Cx/+tjZjtCrym+fOP9rZ+ymromxcZk6erjf/b5nuLLN+I1/qDx4F8hAwMDwy8CJ+lFhQ2jILz473/6C4wFREaHyOQUm1xSs9vhQ9/c8qnTjan0/l8ERZeub37vo9Q3MpJl83sfFV26ft+vn4GBgYHhHgO86PIHVDaMwI6hATJeRPCAxOyUml1Si0dm9Tj96JtbPmO1DDIwMDAwMDysbNyW5YIDajtOQXrx8QUIHpBbPAqrR2HzKm0+F4ylvb/dyRSmMIUpTGHKw1s2bstywwGtA6fAgBcffeJJFJ9S2rwqm1dl86nsPheMpX/w+f2+YKYwhSlMYQpT7mIhvYhREF78jyeeQgNTGodf4/BrHbDWAbthPP2DHff7gpnCFKYwhSlMuYtl47YsDxLQOTE9CeHF3//5GSwwrXciFB4Ez2C8yBSmMIUpTHmoy4ZtWR4koHdieheud+EGF5lH/f1fFmKBaaMLJUG8CJ7+PuNFpjCFKUxhysNcNmzL8iIBowunILz4h78sxAPTZjdmcqMmF2p0Il4EX/MeM+6GKUxhClOY8jCXDduyfEjA5MYp8JAXp6YtbsziRs0u1OREvAj25juffHPsJAPDfYT63b3EFKYwhSnzXYLBIPCixYNT4FNk/yI+NW3xAC/CJqffC2NvbPzom2MnE6ypxBSm3NUS4cWPmMIUpjBl/opGowkCL6IxvfjE03hg2upGLW7E7IJNDr8XRl9fl0l5MTA1zR6znWlQZd+QMTz4nGlQscdsganp++q1Oy3RXjxXN8rAwMAwL1Be9KMBqxe3kRBe/I/Hn8ID01Y3YnHDZqff7PB5YXTlW1soL9YNmuuHrVo77kaCDA8+WjteP2ytGzTfV6/daWG8yMDAcPegeXHK5g3YvAGbL2DzBQgv/u5PTwIvWl2wxek3O3w+GF2e8S7lxeO35DbflM0ftPqCJhcu15jGJvi8kdG+vr6Ojg4Oh8Nms5uamhobG1ksVkPj7Qk+z+oLMtwvbP6gzTd1/Jb8vnrtTgvjRQYGhrsH5UUYC9h9IQLAi48+tgAPTFndsNUFW1x+s8Prg9Fl6ZspL2bfkLmQoMUbtHiDMq11iDc6jXmCAV9wyh+c8ganPMGAcxq3TcN68Rj38OHDpYU7wM4M9wsXEsy+IbuvXrvTwniRgYHh7kHz4pTDhzt8AQDhxd/+8S94YMrmhm1u2OryW5y+aC864aDJEzR5gkO80QDsCE7BwSk4OOUPBtzTAcc0bp3GTNOY9tzp4xVF2wvz3wE7h8PaCKV8MxJdPwfiNSX5ZjFElMX5vfNworsBayNElcQ3hHybI/mLkrx1TpjxIgMDA0NcwrzoDzhJQl4MTE3bvYjdg9g8sM3l9yNYhBft/qDBHTS4g/0Dg5jfPh3wFp+/UXz+RvH568XnrxWfuzaFqKcRWX5+/vffZHR21ICdw2FtgFIO8aLr50Cspnj5iyBow43Qy0M35uVcyV/JrA/pOpYCLc7vms/GCex+xosMDAwMcaG8iOBTLjhEYCpIz6MiVnfs/sXsGzK7L6hzBXWuYGdnJ+IxTWHOKdQUQPVTsDIASwN+YcAvmfbx8/PzxyUKjWMK7BwOaz2Ucmg4un4ORDclObQYWn99Xhq/wytJ6pDEh8/9jtl9v1Iv/lQzXMke4vYMdvcOxOz/vlFVc67s5n3/m2RgYLi/hPcv4hRU/+KTfjQwoXaOqxyjChtPajbavSvfep/uRYs3qHYE1Y5gR2e3z6HAYS0IE4vPVRSfKy8+Vx5wDwacXWd/Oq+wBsCeUbDWQSkHh8Irh/KfI1OK665R9ZKDz4dVXn6H3OkdVuymhvKfgzIvxzxvjFOw1kEpB68R9euuBbk5KWCH53Ik0TuEVQ7R3wtrHRR+YaFzgYthrYNS1r2TAoVdW3Q7Ca9zKOIQ+s2RHHyedt+uZULP53MdQbUjaPH+Sr14sbavpb0ncf93YcG2+/43ycDAcH+hvGjz4gIjSgHjxHjUpzww3iWyd4ps7XwTZ9ygNrtT12+le9HkCSrsQYU9yOF2eG0S3CcLwJKAXxjwjQU8w7inH3d14Xb2jz+dl1kCYM8oWG9DKQcGI2qgtyuCCntQMZj/LPFdyYHnoWdzJAlbiGpqMP/Z5/PbYh8SfQrW2xAEgf0rMiGIPF1FJgRlFtvDdwg7ijppzCuhbVdkPpsjAe1EvZfQbm05KcRZ4l5nxEbUzanIhN5hge3id8gW7EGT51fqxZb2ngT93z/kH6so2v7TiY0ztXPmRWhB+vl5+fOL11Rt+mPk/0GP7T5yvz8j4l88VRLfEPJtnt/96LzdOgaGuwjlRZ0T61H4e5T+XqW/V+n3olNg/uLTHiTQLXV1S12dIns736K2eN/ctI3uRaMnKLMGZdZgG6fdZxPgPj4IE4vPlV04V3rhXCnuaMWtDT/+dF5sxMGeUbDeglL299Fq+vKfhTIvkC8vbILeKo+sJCjPpAaq7O+buakZThF2eMztsPYTHkWr7Mt/FqKVTawY10kcSxXy2ma4TnIjxttkvUXUsN56Pp9N1ht/rV7kdnQn6P8+ceL7E4fTC6+cm6mdu+zF87sfhaAXD4Veph+al3PN+5sKHXLk/QUJ/T2Pd4yB4V4Q8qID65b7u+X+boW/R0F68fdPPONFpnrl3l65t1vm7hQ7dTY4/b3tdC/qXEGxJSi2BJvZbT7beMDDC3gGA+4+3NURcHJwRzNub8SttT/+dF5gwMGeUbDWQilZfbSavvyFUGYh+bJwE7S2PLIyfDdJ1vOghaimLJKs56G15VEnjXmKsMNjbtMrqZZn2jP6ymNcZ5zKGa6T3IhximDTkZSFRyTgK1Wpc/1Kvdje3p6g//vEiROnyxt/quXN1M5d9WJt+mM0Kd477siLMx3OeJHhFwbdi11yH6FGOeXFPy/0olN9Sn+/0t+r8PXIPToHsvaDnXQvap1BgSkoMAVvN7P9ttGAq7f4p9ILP5Ve+OnqhZ9+vvDTz5itFjff+PGn8xN6HOwZBSsDSvmqN6IGyigNCkxBQW/+QijznCkoMEm+WgQt/EYS2q00E1qU30jsA1qIbiooKM2EqNZMQUFv/lel8U5BPzzmNisDIq8h/MKIpkozoRhXQjsq7ltOUJngOqmNqJsD9l+UmbEorE2t81fqxWY2J0H/9/enzpytHp5FO3GDPFBoVgulQ0Hlp6+RO712JnZT53c/Cq3+NOZ5Y5zizIvQgvRDRP2Lh0aPvL8A7PDo+7XRO4RVhvmMlhEFFxY6F7iYMy9CC158bQEUdm1xvBjvOs9HHEK/OeH/DRxa/QBnjxl+FUR4kVKjF5l67MlF0B9IL/Yp4D6Fv1fh1zuxtzK/oHtR4whOGoOTxmBjUwtsG8IdXNzRijuaMRsLs9Zi1luYpQo11fxw9vyYDgd7RsFKp2UZnz4smTQGJ3vynyYTpHt6YuyZXhqcNEr2LIIgCIIWZaYvArux0sP2Jwm1BkGL8lmRldQh9MNjbrPSoZT0jSm0awhOGoOTpWQ6d2MmddRZMBtxIyvyAjay4lznjBcf+3polVDEhZ3dSF4AicbxK/ViYxM7Qf/3HXjxzIuUA0JdaLXpj1EqitdCLC/+/+2deXCTZ57n1bU1+9/sHDtVWzvTk3QO0p1A+gBShdO9Vb3TW0lPqjMLvR0maZKBxUQJkPR0QkICmWQxNrKNbMvEhITDxAYM5vKFLWMbH2ADNviQLV86LB/Y2JatW7IuS8/+8Uqv3luvbB2v7N+nvkW9evW+rx4dfj88z/u8z8OsBMaXOP5LUfAC5KEtIfMd2kLwWXAD0l50n7FI7tCWJ3fdwI5Dey+M7ahs5aQs0D6cQ1uC/1fo/fCVhNSYIZBQ6F7E1Bjw4tPPY+2ojvZRLAuPzZ633iN5cdyIuobHW28VNcsLmmu+bpHn42msOlp/7UB1yYeDvY3HT5xUPkbJH/kfRCn77ya8GHxz4m3RHy6Q1owbV6kXa+tucVz/zjt2/NuqJXmRXMkLnNYZa36HtgT/38LuRcb6IuNLsLZkMnuXcy/mCl+wBsnYEErsdxMsW5hyEjvgUN7m8V/iLofKIiTRIXqxLejFu7gXn/rJT22uxbtqyz2t9d6I7d6Ine7FUSNqrC9yO2ZctkcLFh0el+2R8VGTTCZrkJ/vbr+clX+q9zFK/sj/IEr59G7Ci8Evd2U/3SC7QV45ulq9WC2v47j+HXMvhtbceGMNixfZri9GwYv4kfl4kS4tRi8yticvzYu96bvWPrnrBvZvwk+LkFUekhdHHLgabZgXf/Tci1an9/bg/O1hQ+uwqVVtmTK53hR/gnsx78bY8MyivCJ/fqxmQiGbVH5HzFhX1rFjxzruN0uyc85V3FZMoeSP/P+IUj5pS3gxwkbzyXqRiFZU5WM0PLOYd2MsoV5bLkvzYlV1Lcf177xjx7+t7OJxnLDtqLj8aE2FXE2ahM0Y+qMyvgQfLwbLQC5Y4FCHtjDVXOmtpry9GKac7O2o2PZrtvxyDfTQgSQ+VC8G1Rjw4pNr1lodnluKx419M039s80D85MG59bUUL+b2u65ioeG5oeqdMnRtIzMtIwsxhRerFDPuFluXoTELxq9r+KhoaZrNc4zVXlDznH9O5L6YgiCdYgNpNQtf3moN9TTJHT2Z+moSWzJxBsVGV6CV33xl6+sJZSh92Q1oTn3lS34XoE+QdR+N9ztqNyFD3sVU0Qp2Iev4D2SIJBEBvfipNHdinlxxNGGe/GJZ5432921D8dudo3X90zd6puZmHP84f+G7tNwe303HuqPVugSPuMuhE+OVuhuPNS7vb6Eem25ROrFsxW3bslPNVTJblXJmmtkjNe/c2QFCf9rjHaS7AYJ6HEDEUgoXsTVGPDiPz79E7PddeOe5kb7iPzhWF335Jje/vsdH+JeBID4E6kXy64fD3v9+89fZCb8rzHaSSovsvbFhUDiHboXW4le/OHTPzbZnJVtw5V31dXtOvnDsdFZ6+//7QPwIpBAIvXipfMZ3Ne//9/hI1/KziX8rzHaSRYvYi3MSVFUyKoI7sVHRvcdrf2O1s7gxfI7Q5Vtw1X3tTUPRkdnrFsI48BFizn9zGB/dzBdA8qu/r4Hyr4Hyt6Ovt72XsX93p57Q4P90X1RIEmJ1Is5RbUff/7/Pv7sS7bsSz/+TfnDhP81QiAQIYToxdsa+22NHasyhtpRTTZnZdtQZZvqxv2RmodjozPW32+Pfn1xsL+7uLgIy/lzxZculZSXX6usLK+prrx5s/pWg7y35+7N2hvRfVEgSYH5FyEQSOxC9+IdLdGLzzxvtruq7mpu3NdWPxit7Xw0NhuT64uYF0Wi66K/bBP9tXpPFmrqR1fuoYtt6PsWlFvuVXTframuZNlbI0sJdm5LkWmiW7Ios7yiysWBHTWylNi91ZgePBqAFyEQSOxC9GKLxo6rMXifxrMvmB1u+YNReef4za7JesX0+JzjD4Rxw6MF5sUf/FWp6L/WiZ5WbN3rGnuMhseQdgpNzKH2AZ+iu62qqpxhT40sRSQSy0MPZXKGraKNXLwEcyy3qHIxcfcos6R3lCDAixAIJHbBvThhdLdo7Lga8fv611kWPPWKx/WK6Ya+2cb+uYl559ZdH0fLiyMjI01NTVKpdLC/SyqVPr2u9C/+7qro7+88+z/11bf9jQ/QzQ7U0oOuNi/2dLeWl12jHUAjS4mdKjhYgkWWX9SYqgu8CIFAIL0nyV5sVttxNQa8+NSPf2p1epsH5psHDC1Dptsqy6SRNN4NH5qbm7OyshifwqQolUoH+ruxhb/6YbHor6//5Y97pKfMpdXOs2XuSzX+r0tcPd13rl27Qt2fwzWEBsvgFnKxKEUmD6wXy0ObBIVA2oC0UkM4gkaOT/kYOHTotbDHcrEoRSwmVQ6XUlSZmFC80IsGHwZLpcELLAuupJeZWqrQ4ciPgg+pB+csW7wBL0IgkNiF0YstuBeffv5nNtdiq9raqrG2auxtWseU2fPH9/fz92JjY+PatWufe+45xmerq6ulUmlHR8e+ffs6OjqkUukTz3//g785/5//vmXnJ2M5p4xpBRbpmYUPJfrurpaLJReo+2tkKcwnZkKTY+hqmVyMn8gJi4RtCWtJezE7hrYSIbkYdxi1XEsoaqhQId0ylYRoZ+4y0zXG/Y74ly2ugBchEEjsQvEirsaAF5954Rd2t+/u6MI9nfOeznVv1D1l9m7b/TlPL2JSfPPNN9m8WFpaWlD31f79n1oslv37P/3Xt4898cKZ//S3p3/wd1W/2ty1+4vxnfundn9peGXXYFdn84Xz56n7s1XCyOvlYuwBi8yY3cC9F3ONiqG+Fc2iMq0k6Tas5AilotQ/2Q4ewccYP8CLECEk3r97IF4QvdiktuNqtGJefHbtervb3z7uaR/ztI972se9jy2Lb+85wMeLuBTfeustDi+2trZu/ujSP+049dqe8yKRRPQXUpEoUyQq/C9P1zz38u1nUtrWvNzxw01NXZ0t584V0w7AYpsoeBE/BB8vUorAaIvlFzV6Xgy9KL4/eBEC4ZV4/9yBuIN58R3Miyo7rkaSFzsmFjseLXY8WuyY8D22+N7eezCsF4lS5PDipUuXMC+OOP2v7TmvVATu4lf0tHV3tXZ33enuut3V2dLV2dL1sKm4uIjhEIRWPYTwTp6UBkCOdkhENkdwLckcwUOFnqfsTpEDiy2WW1T+7ajhyowvhm8u5v8xxg/wIiRRifdvHUgERC82quxN6oAaA15cs26D3YMeTPo6HgUybfW9w8OLWVlZzxGQSCSMm5WWlj58+HDzR5f6TJ7fvl98+/atpsa6hvra6urKq1cvXy69dPFSyYWS8+fPFRcXF7W332d+MWJLJqm+R1nFq74oFqeQu5kQmhzFYnyvwDpqvxv2dtQoFJX1omZwZxl9JaHM1NqwSCQSpYjFKfR3xNhKHPZjjB/gRUhCEu8fOpAgAl784OC40d2osjWq7FitkerFB5O+jklfx6TvsdX3zgfhvciTy5cvt7e3b/7oUuuE9dX3AtVBl8tVVnZZKs0uKjo7NxfPGZESc5aPGom6aSXugBch8U+if/VA/Ah50eC+pbLhaqTVFyd9HZO+9kfR92JDQ8Pmjy6dbRl5/U8XEEIzMzPDw8MPOtpuNdRev365uLhIo4mbqZLbi4z9TVck4EVInJPonzwQV0heHLbharQ6CV7EpRh1L6pUqm+++eZgWv6r/5b/fUkNQqi5ua65ue7qlUuFhacKC08VF59lvqwYE5LRi9Q23NUAeBES5yT6Jw/EFaoXg2qkehGTYtS9CABLALwIiXMS/ZMH4grRiw2YF4dtt6heDErxPngREADgRUg8k+jfOxBvcC+OGdwNw7YGBi+6ES7F+498jy3gRSDBgBch8Uyif+9AvCF6sX7IhquR6kVMivcnfFPgRSDR0L2Y6BIBALByoHgRVyPJi7gU7wnYi/6ZBk3te8Soa8R+Q3uiywVEH/AiAACxg+jFuiEbrkYL1YsTvntC8qJ1urftym5idE2fWFRnsGcPXEevFHdbVGf66z9PbDmBWABeBAAgduBeHJ131w3ZcDVSvXhPYF5Utxx06rKRTY6nvnC7WZFOCZcXyTMthdksPrdv8CwSndBwbqsC8CIAALGD6MWbgzZcjWQvBqV4VzBeHO/IRDY5mjqGpo6hma/RbAGyycuPb60v3N52ZS8eVi8Sh4YJjFPKCHEipRjf3cirSIkfg00IgBcBAIgdBC+6bg7aMDVSvYhL8e54PLx49+5du93OvY3uvgRZb6CpfDSZj6by0WwBmi1A5jJK6gu3M+/P1ylx9BCvw4MXEQIvAgAQS4herB204mqkevHuhO/uhK8tLl68ePFiaWnp/Pw8xzaa1gxkKUcTeYFMytCjPDSRF/h3Ig+N5dhUWaxeZJs6mNSOSZyiUIYvi8Ty4IxLiDrENmW30JQW2HDkYjnpVeizU3EUSSwnHFgkFhPLQx1bXIaPJK6hHIcwtjhrOYQPeBEAgNgR8uIcuxfvBiuLcfOiXq8/ffr05OQk2zbDLYf95itoLAeN5qCxHDSWi8U/muPXSX06qU8ntXN5EeFiIBiOcW56liksgnMupaSk4J5hmW2KKDzSQRgnLxYxttwGNuY1VVZoPijaUmguKoLbkw7wIiBsKFPKYWtezl+VrTvJCMmL/RZcjSEv2jAvjvva4uhFhND8/Hx+fr5arWbcZqDxkN94wT+S7dce9WmP+jTZPu1Rn1bqVWd71VkedZZHleUYzuT0IkIoIAqxPMI5eIMOlItTZHJsmaBFYj2TYUJgAoxmIhWJsnFEUytzzl1MmK0x6eDlxZrU4AeXWsN8mJpU0cZc5t9XbFDnbozzK3KwzMIsffcofez8C5CAj10uFr388svEv2/wYjJB9KK831I7EFAj2YtBKbaN+ybj5UWE0PT0dFpamtFopG/TV/flov6sR5XpUWW6hzM9qiyvOntRle0elriGMl1Dma4hiWOIhxdxIUY2Nz2mGqwSp5GliOW4e0gTGjN6MXw1jbFItDIsz4v4C63IdlR17kZch+rcXGYxRnSCjq5Eo3W0uKs9CmWIT5nj98l4vYtOl4ecqlRRirQyd9Om3H7imgEPbUuIEIN7UYd5EVPjgJXkRVyKrXH0osFg4Kgv9si/8M6cXBg44hyQLPQfcQ5IXIOZrkGJo1/iUB5xKDMc/Rn2gSPs/W5kxBl6gw2LEcxNr5GlEFtQxeJgo6iceP2O0VUstTSWIrG0zbItszauUttRg9Caf5OA8F7kdVYEL0YF8CKLFwc8FamiTTmDxDVOl6ci1JBRFXqqMncTtq7S058TaCcK7utxDgSeFYl2VSTaGashRC/W9FtwNVqciwQvjvnaxnytY77WMd+k2ffO3ph7cW5ujvv6Ymf1Qc9Uga0v3daXbu1Ntysz7MojdmWGtTfD2pseSF86d78bamNmmLnpiTPak28ZJN0+iHdxEYvp9UVEbh2lXoHgKBK5LxB1mduLoWOH+t0s+V5JAcCjHbUmVUQ7L6pzN5JaVgmnTupTlFWhNllKoyytsbYmVbQxNzewlnZixl6RdjTGgtUEVqbWhJ4nH5DjOJRiEqvP+Ptmffs1qfjG5G1IB2V8LwyfI+Xj3Jiby/6x03enrKlJFW1MTd0oEqXWhMpG+rg25qppnwzjOyW/R9avLDwe7+KC001O5U7RpqP9jAuM24hEm3KUTvdCxS6RSLRJOrgQWN5V4STvW7Er8Cwklgl4ce9B3ZyrRmmRKy1ypaW2P+TF9Ta3v3Vs8U4wj8y+t2PvxbD9UR9UHXBPyCyKw1hwF2IPzYo0syLNrDhcc3Jb7MqZlPBryBU4/PrdBE6BDKf4mtTg2ZNwYiU9Rb8kxV3/IB6KYDeqHZhekblgIuLxAk9zHZD8NGPxCR8E7hjmt49vXJO6ceNG7Dl17kaWD4S0O8vF3FDZ1LkbRWFfNwDj2yC+GO0zCu3B+AkzfkTcX1l4OL3oXqjYJUqtpK4JQFcm03J/ziYRgdTKhGtjxQfz4tt7D47MuaqV5mqluUZprlGazQuLa9atF61Zu97m9reOLt4ZXbwzunhbFw8v8rl/sfH8u8TUF+2Un9le+d22awVbL+ZtKcr63en0V0989ZuvD/46duVMRtibcZOJCPqjqnM3UmsytGoE/Sly/QohxOrFUM2EU3jUgzDXYBjqN3wPyFAnpNVscdfhmmV/+wE/b8ytwZZpWmR/LwwfE2lv7o+dsHuYb4HxPxl061Nekf4RcX/C4QnjRefg0U2inRVEyWG1wMGjm/h7EdsFEqeEvKh33eg1V/eZq/vMNX1m88LimrXrRc+uXW9z+2+Pem+Pelt03had95F58e29BxI+3g0QCaxNt0lKRPdpBE6GHCdZ+lM8vRjaDD/xL82LfM7+3AcM68VAEQmGYn/7gW0xg6pzN6bW0LXIoiUU9B214sfsRYbKWWj3pXgR3yeOXvR4HQsucip3ijYdVQYfKrEK36ajSpejIlW0KacvsBLbhrgx43LlTpFo09EB2qtAYpWgFw+M6J1VvaaqXtONPtONPpN5YfHZgBdd/ts6z22dp2XE0zLieWRafHsPeBFIJDwMnvOGAAAgAElEQVT63eQST5R44yR7SyDlKX7tqPi6MM13jK9Iav9kfy3eXqQ2EtKUo87duDE1NXSRkOPtI3XuRmILampqKvubZ/hkmBpdGdtRmS0U3J37W2Aqf+iN82lH5d6SryDDe3HB1Xd0U8CLCwNHsVbRTak7N/H0Im5WkUgkEu2sTLg2VnwCXtxzYETvrFIYqxTGG73GG73GkBetLn/LiKdZG8iEaXEbeBFIKDz73VD6V5Aa7ti7YxB60JBWBB7TLoCJRCLRxtTUyOqL5KNxFCxcbYblOGy6EZHrS+xvn6gk5vv/mN4L9TNj+EJY+t2w7U5Zxeqw1NSNzHuyftHcn3AEXnR7vHaHE7KSgnlx254D2llnZY8RS5WC7MVmrRtLk9Y9YfJu2/M5eBFIIDDeDUBgKY2fUcTl9tjsC5CVlKAXP9fOLlQEvVjZw+TFJvAiIAzAiwAB8CIkyiF40VnRbcTVaHYQvNikcTdp3I0ad6PGPWH0btstRC/6Zxo0te8Ro64R+w3tiS4XEH3AiwCBRHvR5bHaHJCVFIZ2VAWpHfUXVpe/Ue1qVDlvqZwNKue40fvH3Z8l3IvW6d62K7uJ0TV9YlGdwZ49cB29UtxtUZ3hmpcYSFrAi4BwcLrcFqsdspKC97vRzDrLe4wVPcZKhalSEeyP+swLv7A4ffXDjrohR92Q7eaQbXTe/dZ7+xPuRXXLQacuG9nkeOoLt5sV6ZSweZE8mQR5PBrsOdIQNtzEYB7EJQ9GE0GxkxjwIiAcwIsrL/j9i9pZZ0WPqaLHVKUwVymC9y8+8/zPLQuLtUqTvM9U02eq6TXq9M433/0k4V4c78hENjmaOoamjqGZr9FsAbLJy49vrS/c3nZlLx7W+iJRjOQxQyMfLzTaXiQOSaORyZjFuKonKAYvAsJhAFhxhLyod1YoTBUKE15fXLNuvejpn/zU7PBWds5UdM6Ud86Ud85opu1vpH6U8PFudPclyHoDTeWjyXw0lY9mC9BsATKXUcI6PirBfhpZilgWmFJ4ScNoR1tLvI4HXgQvAoLAC6w48PFRtbPOSoUZj3lhcc26DaIfPbfOaHdfaRu93Dp6uXW0tG1MNWX5Pzv+lPDxUTWtGchSjibyApmUoUd5aCIv8O9EHhrLsXHNS0ycFypFpiFMNEydSUMuxkbbFolExDHU8OHB8ZG4EWlgGcrhqLNNkedXJLeWMg3WRtqWOMK4mDza+BKKzVYM4QJeBAAgdhC9WKEwVfaasQS8+OSzLxiszvO3BosbBs81DJ27NTQ4Ydj8zp5Ye1Gv13PPpzHccthvvoLGctBoDhrLQWO5WPyjOX6d1KeT+nRSO5cXCTMs4jMMk2axJ03SRJv3nnHmJspMVeQDysXEealSZBrKRU4yAVcxODVU0LATTvErNlcxBAp4EQCA2IHPMxVqR+01V/aaTZgX//Hpn8yZHWequ05Xd52p6S6sUfSPzv3LtvfjMP/i/Pw8x/yLA42H/MYL/pFsv/aoT3vUp8n2aY/6tFKvOturzvKoszyqLMcw57zEmA+CVsBcRWhFjXymX8aZjYNbysUpMjm2HFxFnwuRgkaWIhKRK5b0eiFLCSMrdpK1w4IXAYEzp58Z7O8OpmtA2dXf90DZ90DZ29HX296ruN/bc29osD/RxQSYCePFHz71Y73JfqLs/rdl7d9VPPiu8mHfyOzrb4nj4EWE0PT0dFpamtFopG/TV/flov6sR5XpUWW6hzM9qiyvOntRle0elriGMl1Dma4hiWOI04saWUqKTE68sCiWEbwRJS/i7bQBI4rl5CuYmPLYKmyBQzJMDhU9L/IohtAALwICZ7C/u7i4CMv5c8WXLpWUl1+rrCyvqa68ebP6VoO8t+fuzdobiS4mwAzdi5gaA178hx89pzfajl9pO3717onr978tf9Cnnfndm/HwosFg4Kgv9si/8M6cXBg44hyQLPQfcQ5IXIOZrkGJo1/iUB5xKDMc/Rn2gSNcXgy4gCgPohq4Z/rl045K6MlDaEEVi8WUyhm1q49cRpziGJ9EmLzXkrzIXGyWYggY8CIgcDAvikTXRX/ZJvpr9Z4s1NSPrtxDF9vQ9y0ot9yr6L5bU12Z6GICzODXFzUEL1YoTGQvXr37zbW7J8ravyt/2Dcy87vY1xfn5ua4ry92Vh/0TBXY+tJtfenW3nS7MsOuPGJXZlh7M/A5iq196ZxepN7sR9AaCieY0C2GLP1uKFVC4gbUI9DqaXJyVxrKkUXB66KMy5EXe8n3SiYO8CIgcDAv/uCvSkX/tU70tGLrXtfYYzQ8hrRTaGIOtQ/4FN1tVVXl5J0If+RC/y/q8oqKnXOwC1exe6vLODjRi+V0L2LtqN+Vd3xX8eBkVefpGz1Knf5f/hjz64th+6M+qDrgnpBZFIex4C7EHpoVaWZFmllxuObkttiVM7lhaJtNGsCLgDAZGRlpamqSSqWD/V1SqfTpdaV/8XdXRX9/59n/qa++7W98gG52oJYedLV5sae7tbzsWmhPvDNB8CHLjcvRZUm3eC23qOQKSJSJzk1rYbwY6HdT01NYrSiUK7+/OTAwZvjfb8e2Pyqf+xcbz79LTH3RTvmZ7ZXfbbtWsPVi3pairN+dTn/1xFe/+frgr2NXzqSG6V6QpAG8CAgTTIpSqXSgvxtb+KsfFov++vpf/rhHespcWu08W+a+VOP/usTV033n2rUrwf0S9b/UJVhk+UWN6f3WMfFiOcWLTzz7wrzVea5h6Nyt4fNN6gvN2qFHpt9v/zDh490AS4LWGpucgBcBYVJdXS2VSjs6Ovbt29fR0SGVSp94/vsf/M35//z3LTs/Gcs5ZUwrsEjPLHwo0Xd3tVwsuRDYjcM1tFuiA6d+eWB9oFseqUWTtAGtgz2+TLteQ72TWS4WpYjFpMrhUopKuos69KLU+80Ybq1m7TmBl4p8FUjOcjM3z7KFwMe70cwGvFhO9OKPnltntLlLW8dK28Yv3524fG9C9dj6h51/Bi8CCQS8CAiT0tLSgrqv9u//1GKx7N//6b++feyJF878p789/YO/q/rV5q7dX4zv3D+1+0vDK7sGuzqbL5w/H9iNtc8b0y3R2Nmftki5TZkwaEcYxzD2QmDp7rekojLcRc2/JyPzlrQi8O1vGK5sAUhe7DHhMTkW16zbIHrqxz812T3lD2fKH86Wd+oruvTaGce/7voYvAgkEPAiIExKS0tbW1s3f3Tpn3acem3PeZFIIvoLqUiUKRIV/pena557+fYzKW1rXu744aamrs6Wc+eKA7uxVcKYb/2KqC86917MNSqG+hZLkZZUVP63kIV/d9T6J9vBI/gYESJ7sazHiMfkwMZHff5n5oXF6l5TdR8Ws27O9ab4U/AikEDAi4AwuXTpEubFEaf/tT3nlYrAXfyKnrburtburjvdXbe7Olu6Olu6HjYVFxcF92OxTRS8iB+Cjxc5bpJmKdNSiho9L4ZeFN8/ul48oJl1lnUb8Zgc2HwaL/zc4vTVDtprB+y1A/baQfvovPuP7yd+nilgNQNeBIRJaWnpw4cPN390qc/k+e37xbdv32pqrGuor62urrx69fLl0ksXL5VcKDl//lxxcXFRe/v90J6EVj2E8E6ejLdE8/FicC3JHIQxLpnFw3GTNHn1sorKvx01XJnxxfDNxfw/RoRwL+45oJl1Xu8yXO8OxOTwPrt2vejZF35hcfrqhpxY6oecYwbvtt2fC9CL/pkGTe17xKhrxH5De6LLBUQf8CIgTC5fvtze3r75o0utE9ZX3wtUB10uV1nZZak0u6jo7NycnnVnYksmqb5HWcWrvigWp1D71+FNjmIxvpeccBs0rVsee9/OZRWV9aJmcGcZfSWhzNTasEgkEqWIxSn0d8TYShz2Y0SI6MWZhbIuQ1mX4XrX/PWu+aAX1663OP0NKjeWepV7zCgIL1qne9uu7CZG1/SJRXUGe/bAdfRKcbdFdYZ1/kUgmQEvAsLk8uXLDQ0Nmz+6dLZl5PU/XUAIzczMDA8PP+hou9VQe/365eLiIo0m1rdHsfssKRDArdWYF7ft+Vwz47zWabjeabjeabjWOW/EvWh1+W+p3Vga1O5xo3fbnsR7Ud1y0KnLRjY5nvrC7WZFOiVhvUjriER5kt/Pi3tgheiO6bCkoxH6L1P/1xQN4v13CF4EhIlKpfrmm28OpuW/+m/535fUIISam+uam+uuXrlUWHiqsPBUcfFZwmXFGJHcXmTsbxpnCF5cCHnxIdWLnltqT4Pa06D2jBsXt+05kHAvjndkIpscTR1DU8fQzNdotgDZ5OXHt9YXbm+7shdPGC9qZCmECjiNWP+8+B8/WiWJ0TviOGxMXhG8CADsJKMXhXVrddCLBzSzzmudhmvMXtR4GoIZNy6+HWMv8hnvRndfgqw30FQ+msxHU/lotgDNFiBzGSVhx0dNIc0tRQG8uPzDghcBAEgyiP1usJ6o17sMZV0GE9GLDVovnnHT4tt7Y+tFPuOjalozkKUcTeQFMilDj/LQRF7g34k8NJZj45yXONS1lyJGtmEXwg4wgW9JHUOB1Gsq+D8iQtNm8BJxJIM40Loe01+B4S3TLMU0wsVyhtLgLDn95cIUlw3wIgAAsSN0n4beVa4wl/WYynpM17uNJsfis2vXi9Zg9UXtIp5xk+/tvQdj7UW9Xs89n8Zwy2G/+Qoay0GjOWgsB43lYvGP5vh1Up9O6tNJ7dxeDOlQQ552kXkCKfoiYVtSh2DW8R2CN84E4e4kjai6pXSdIhyN4Y4cOXU2K9orMm7P551yD6XBo+T4y1E/EL6AFwEAiB34ff1avatCYalQWMp7zGXdpsD9i2vWrbe6/LdGFvHEx4sIofn5eY75FwcaD/mNF/wj2X7tUZ/2qE+T7dMe9WmlXnW2V53lUWd5VFmOYa55iYkyZLg9FKHwJ3eGDTifpc55yN5ROFTR4j5s0FXUyiJbFYz8KmFGuAjbx5rZx6wlp78cfRJIfoAXAQCIHSEvzrkqei0VvZZyhblcYQ6Md7Nm3QarCzWO+PBMmHzvxMWLCKHp6em0tDSj0Ujfpq/uy0X9WY8q06PKdA9nelRZXnX2oirbPSxxDWW6hjJdQxLHEIcX6T00xXIUYy8ihIJ24BpwgecgDvTro+H7N9O9yDHCRdj3QhtKg7vkHANlQDsqsEJ5PD1z6fLVjz85sHvvB7W1tT6fL9ElAsKDz6cxMueu6rNV9lqxWmNg3PCAF3U+PBNm3zsfxMOLBoOBo77YI//CO3NyYeCIc0Cy0H/EOSBxDWa6BiWOfolDecShzHD0Z9gHjrB6kdryRzzF8xy+Fi3NiygkDfb7W7kaKsmmSRGLU3CnhO3hTG9HpWzP552KaBomNO2GKTlz8di7PjEDXgSSAo/bXXbxe2naZ19+8sHvt2zZ9PKvhoaGEl0oIDwBL35wcGTOXaW0VfZZK/usFb2J9uLc3Bz39cXO6oOeqQJbX7qtL93am25XZtiVR+zKDGtvBj5HsbUvnc2L9AtipJN8oB2Qe7oTFLEXyZ1SQi9FbcDkPYgDdYbQsL2dOfrdRNCOShtKg9bth7nktJejfSA8AS8CSYHXaXvUfMp47/uhK18e3Pn6E2t+eqHkYqILBYSH6MUb/XZcjQn2Ytj+qA+qDrgnZBbFYSy4C7GHZkWaWZFmVhyuObktduVcldD/R5EAwItAUmA3TA9V5U41n+4p+fzkp1v+V8qL9bduMW3I3iFu6RD+E7qEg2H/Z8Wu08TuTz6mB18GuBd1857qAQeuxkR6kc/9i43n3yWmvmin/Mz2yu+2XSvYejFvS1HW706nv3riq998ffDXsSvnqgS8CABhkEql2L82o77++IfNJ//9Ru675z57be8bv5qaesy0R7S9SGlICgztzZ/Q5aQYIIhzCDcUL+JqTKQXAQEjiN80eBEQLFKpFPeiVCqVF+wr2v960edbjr33q4orF1h2iq4Xlz/AaEz/zAVxDuEG9+KowVszuIB58Ua/3bzgAy8CAgW8CAgWqVTa0dGxb9++jo4OqVSq7nvw1eZns3f+j6w//uxEThpLf1Q2L9IGvmAaiAMfDyQAhxYJbaukzgGkoUgo91ox3GoVru8FqVRyrrE+mO/jYi9bnCB6UT7kxNUIXgSEC3gRECzNzU37939qsVj27/+0ubnpkdHyxcef/sfrT/7Ha//9UM632Zc7epTDtJ1YvEgd+II2MgZjH2/W7t2E1lFSj3H2oUhIy/z76jP2PA/bOZFn2eIBoxerBxxBL2Lj3Yz4bsXx/kUA4Aa8CAiZzR9d+qcdp17bc37K8Oj7Huv3ZfdO/uk3x7/59ps7lnOdzi9LumobWsh7sHiRMvBFmIE4EGEzJoVEMG0908oI7u0ml4pjrA+GW5/Dli0ehLxo9NYOu3A1Brz47Nr1luD4qHEbBw4AuAEvAkJm80eXRpz+1/acv3q/9ZtbTnlL16LPV6RAFzsd1zsen2ie+XdZOXbmDUKu4pElERr4IsxAHIh5f5bVcfIiz1FKhOrFMePiTZUbV6PZGfDiLyxOf73K3aDGEvN5pmB4CCAs4EVAyGz+6FKfyfPb94vzqtqyKsfL6x/eU1mPNc1caJ+/cGdcWjW8v/Du2WLSjYzElkd6kyFhJBCOgTgoh6P3R6W0VXI3mfJsRyUILVQ6Unsvv1FK+JctHlDqi5gaQ1585oWfm52+2sGFm0NOLGMG77bdn8XIizA8BMAH8CIgZDZ/dKl1wvrqe0VfFDYdrRmrbX9c1PQot3b8ZNPUMbk6q0L1HyWKvK+/I+/EdLshfeALroE4WI9HHzJExOwbbi8yjnlCKKRYzDZapEjEY5QSvmWLB5T6Il5lDHjx6ed/Zl5YvNFnrlZaqpXWmn6rbs711nufxsiLkQ8PAffDrkbAi4CQ2fzRpbMtI6//6YLRZD50Wn7oeHlexcCxxplvW+Zz5GOHrij3HD7T8eBhoou5DJZ/J4iwoXixTu3B1Bjw4lM//qnR7inr1Jd3zZd3zVd0z2tnF/5118cx8iLv4SFw4H7Y1Qh4ERAyre3DW94/1do+jBDy+Xz6OeO5K5VH8k/9R/a3n2Qcz8o/M6vXJ7qMy4Kxv+lKguhFXIo3VW6L079m3QbRj55bZ7C5L7dNXL776Mr9ySv3J9WPbX/4v/8eXS9GPjwEDtwPuxoBLwJA3Akz+PJKguJFXI0BLz757Np5q+t8s+ZCy8iFlpGSlpGhR+bf/9sHEXmxubk5KyuL7dklDQ+BA/fDCut+2PgAXgQAIHbgXhw3+eo1XsyLofriE888P2dZOFs38H3dYFHDYFHD4MD4/P/e9j5/LzY2Nq5du/a5555j22BJw0PgwP2wwrofNj6AFwEAiB0UL+JqDHjxH595fs68cEbei0c5Ovcvb4l5ehGT4ptvvsnhxSUND4ED98MK676f+ABeBAAgdhC92KBdxNVI9KLjdLUimJ4+3ezrb77Lx4u4FN966y0OL6KlDA+BA/fDghfBiwAARBOKF3E1Wlx4O2qwvni6pvd0jUKp07/+VngvEqXIx4sRDg8RAu6HFdT9sPEBvAgAQOwgevHWSEiNQS8++8K8ZeFsXf/Zm/2FN5WFtcr+0bl/+eN7Yb2YlZX1HAGJRMKx8RKGhyAA98MK6H7Y+ABeBAAgdjB6sUG7GPDik2vWGqyu882a802ac03qc42qgXHj5nd2R/c+jSUND5GcrPT7YeMDeBEAgNgRxotP/fhFo819+e7E5bbx0rbx0rax4UnL73d8GHUvrvDhIYKs+Pth4wN4EQCA2EHxIq7GgBef/snPTA5vWae+rFNf9nD2+sNZzbT9jdSPouvFlT48xCq6HzY+gBcBAIgddC9iagx48Znnf25eWKzuNd8IxDSid74p/gTmmQISCHgRAIDYwejFWyM+qwutWbdB9OwLv7A4fbWDC8E4Ruc9f3x/P3gRSCDgRQAAYkc4L65db3H569XuerW7Tu2uU7nGjN5tuz8HLwIJBLwIAEDsCOPFNWvXW13+Bq0Xz7hp8e29MZyXGADCAl4EACB2hPPiug1WF2okPDFu8r2996AAveifadDUvkeMukbsN7QnulxA9AEvAgAQO/h5UefDM2H2vfNB4r1one5tu7KbGF3TJxbVGezZA9fRK8XdFtWZ/vrPE1tOIBaAFwEAiB3J6kV1y0GnLhvZ5HjqC7ebFemUcHmRPiYOx2bxuemQZ5HohMaKWxWAFwEAiB3J6sXxjkxkk6OpY2jqGJr5Gs0WIJu8/PjW+sLtbVf24mH1InHcmcAgqIwQh1yN8YBqvIq0wgd44wl4EQCA2CFEL969e9dut3Nvo7svQdYbaCofTeajqXw0W4BmC5C5jJL6wu3M+/N1Shw9xOvw4EWEwIsAAMQSIXrx4sWLpaWl8/PzHNtoWjOQpRxN5AUyKUOP8tBEXuDfiTw0lmNTZbF6kW1eYlI7JnH+Qxm+LBLLCdMek8fvpuwWmi8jRSxOCTwOvQp96iuOIonlhAOLxGJieagDl8vwYcqpM1ASBi5nLYfwAS8CABA7BOpFvV5/+vTpyclJtm2GWw77zVfQWA4azUFjOWgsF4t/NMevk/p0Up9OaufyIsLFQDAc48T3LPNjBCd0SklJwT3DMpUVZS6s0CLjzMgixpbbwMZs9UXSa4Umm6IthSa6Irg96QAvAgAQOwTqRYTQ/Px8fn6+Wq1m3Gag8ZDfeME/ku3XHvVpj/o02T7tUZ9W6lVne9VZHnWWR5XlGM7k9CJCKCAK+tzFYSb4Dc3rmCKTY8sELRLrmQyzDRNgNBOpSJSN+XiR38TIhKkgkw7wIgAAsUO4XkQITU9Pp6WlGY1G+jZ9dV8u6s96VJkeVaZ7ONOjyvKqsxdV2e5hiWso0zWU6RqSOIZ4eBEXYmQT32OqwSpxGlmKWI67J3QcfBXFi+GraYxFopVheV7EXwjaUQEAAAgI14sGg4Gjvtgj/8I7c3Jh4IhzQLLQf8Q5IHENZroGJY5+iUN5xKHMcPRn2AeOsPe7kRGn/w02LEYw8b1GlkJsQRWLg42icuL1O0ZXsdTSWIrE0jbLtszauEptRw1Ca/5NAsCLAADEDoF6cW5ujvv6Ymf1Qc9Uga0v3daXbu1Ntysz7MojdmWGtTfD2pseSF86d78bamNmmInvg/uEDEOsBRKrktgxxGJ6fRGRW0dJNTXuIpH7AlGXub0YOnao382S75UUAOBFAABih0C9GLY/6oOqA+4JmUVxGAvuQuyhWZFmVqSZFYdrTm6LXTmTEn4NuQIHvAgAQOwQohf53L/YeP5dYuqLdsrPbK/8btu1gq0X87YUZf3udPqrJ776zdcHfx27ciYj7M24yQR4EQCA2CFELwLRhrXpNkkBLwIAEDvAi0DyAV4EACB2gBeB5AO8CABA7OA7/yJ4ERAO4EUAAGIHby+OgBcBoQBeBAAgdqwcL/pnGjS17xGjrhH7De2JLhcQfcCLAADEjmT1onW6t+3KbmJ0TZ9YVGewZw9cR68Ud1tUZ7jmJQaSFvAiAACxIxIvjvgaR4TiRXXLQacuG9nkeOoLt5sV6ZSweZE8mQR5PBrsOdIQNtzEYB7EJQ9GE0GxkxjwIgAAsSNyL5oE4cXxjkxkk6OpY2jqGJr5Gs0WIJu8/PjW+sLtbVf24mGtLxLFSB4zNPLxQqPtReKQNBqZjFmMq3qCYvAiAACxQ4he5DPeje6+BFlvoKl8NJmPpvLRbAGaLUDmMkpYx0cl2E8jSxHLAlMKL2kY7WhridfxwIvgRQAAYoIQvchnfFRNawaylKOJvEAmZehRHprIC/w7kYfGcmxc8xIT54VKkWkIEw1TZ9KQi7HRtskDioeGB8dH4kakgWUoh6PONkWeX5HcWso0WBtpW+II42LyaONLKDZbMYQLeBEAgNghUC/q9Xru+TSGWw77zVfQWA4azUFjOWgsF4t/NMevk/p0Up9OaufyImGGRXyGYdIs9qRJmmjz3jPO3ESZqYp8QLmYOC9VikxDuchJJuAqBqeGChp2wil+xeYqhkABLwIAEDsE6kWE0Pz8PMf8iwONh/zGC/6RbL/2qE971KfJ9mmP+rRSrzrbq87yqLM8qizHMOe8xJgPglbAXEVoRY18pl/GmY2DW8rFKTI5thxcRZ8LkYJGliISkSuW9HohSwkjK3aStcOCFwHh4AJWHML1IkJoeno6LS3NaDTSt+mr+3JRf9ajyvSoMt3DmR5VlledvajKdg9LXEOZrqFM15DEMcTpRY0sJUUmJ15YFMsI3oiSF/F22oARxXLyFUxMeWwVtsAhGSaHip4XeRRDaIAXAeGg481IkPHx8dbW1pKSkuPHjx8/fvwbAvQ1q5bjZEpKSlpbW8eXzQQPhOtFg8HAUV/skX/hnTm5MHDEOSBZ6D/iHJC4BjNdgxJHv8ShPOJQZjj6M+wDR7i8GHABUR5ENXDP9MunHZXQk4fQgioWiymVM2pXH7mMOMUxPokwea8leZG52CzFEDDgRUA48DnPUpiamiopKZmcnLTb7TaAHxMTEyUlJVPL5jGZmZkZvV5vMBjMZrPVarXb7Xq9XqBenJub476+2Fl90DNVYOtLt/WlW3vT7coMu/KIXZlh7c3A5yi29qVzepF6sx9BayicYEK3GLL0u6FUCYkbUI9Aq6fJyV1pKEcWBa+LMi5HXuwl3yuZOMCLgHCY5g1+Ltbr9SdOnHA4HDab3WazWa2hWCxWi8VKXLNqg30UFovVbLYYjUaj0XTy5El95MwxMR/EYDAYjUZMijabjeTFvZxexFYJqj/qg6oD7gmZRXEYC+5C7KFZkWZWpJkVh2tObotdOZMbhrbZpAG8CAiHWTJ6vR5bMBqNFovFaDTO0jAYDN9++63d7rDZbBaLxZxorFab3e6w2x2MC4kundloNOn18/PzhtOnTxuWjdFoxOqFVqvVaDSaTCaz2b96Ry4AAA9sSURBVGzB/jMiZC/yuX+x8fy7xNQX7ZSf2V753bZrBVsv5m0pyvrd6fRXT3z1m68P/jp25UxqmO4FSRrAi4BwYPQiJsU33njDYrGwedFms5vNFqPRND9vSGysVtsvX35Z/O67lIXDaWlWqy3hxdPr56dnZrGbFKLiRbvd/vOf/xxTY9J4EYgZtNbY5AS8CAgHuhcxKT711FOfffYZpxdtRpN5ft6g188lNhaLNXXnzuKiIspCRXm5xWJNePFmZvVTj6ej68U1a9a88cYbmBqX5cVb4EVAGIAXAeFAcR4mxSeeeOKf//mfCwsLObxotdoMBqNePzczM5vYmM3mzz/7rLKykrLQ1NRkNpsTXrzHj6cnJ6dmZ2ej68Xt27d/+umnDkegNZvRixN8vHgLvAgIAPAiIBwozrNarS+++OJLL7104MCBsrIyDi/OzurHxsbVau3g4HBiMzk5hemQstDU1DQ5OZXw4vX3D/Yo+lRqdRS9+JOf/OTAgQOXL1++du2aw+Hg8GIjeBFICsCLgHBgrC9u27YtJyentraWw4szM7MjI6NDQ6q+voHEZnz8EaZDykJTU9P4+KOEF0+hUHZ2dg8NqaLoxV/96lclJSWdnZ1h64vgRSA5AC8CwoHt+qJEImlububw4vT0jFqtVSoHu7t7ExudbuxYfn5jYyNl4f79+zrdWMKL97Czp7394eDgUBS9KBaLm5ubw15f5OvFcaF60T/ToKl9jxh1jdhvaE90uYDoA14EhAPdi3itUS6Xc3jx8ePpoSF1T0/fgwddiY1Wq6soL3/w4AFlobe3V6vVJbx47e0P29ru9/cPRtGLOTk5fPqjYl7EkgRetE73tl3ZTYyu6ROL6gz27IHr6JXibovqDOv8i0AyA14EhAOjF2d53L848Wiyu7v37t2Otrb7iU1PT9/wsGZ4WMO4kPDi3blzr7m5tU/ZH//7F5PMi+qWg05dNrLJ8dQXbjcr0ikJ60XyGDf0J/nd4kcZOCeiZyNlSUcjjKBDH49n+cR7AkjwIiAc2LzIAeZFrVbX0tLW1HT7VmMLhDW3Whoamuvrm3p7+6LlRSIryovjHZnIJkdTx9DUMTTzNZotQDZ5+fGt9YXb267sxRPGixpZSopYzDosaKxP9/yPH62SxOgdcRw2Jq8IXgSEwzxv8EHITCbT1atXHzx4qFAou7oUnZ3dkLC5d6/93LlzpmhDlCK3FxsT60U+493o7kuQ9QaaykeT+WgqH80WoNkCZC6jJOz4qOS5pSiAF5d/WPAisMKh1z+M4TCbzT09PWVlZWcB3ly4cKGuro5zwDhmLOEgSlG4XuQzPqqmNQNZytFEXiCTMvQoD03kBf6dyENjOTbOeYlDE0hQxMgwo71cLEqRyQPrA/M+kVojyaN1y8Qsz4aGmxHLKYODy8WiFLE4BX9Afoo+8yJtUiv6KzC8ZZqlqNvze6dy/COivEHuktNfLkxx2QAvAsJhCSNZA8shbDM1vWU7UgTqRb1ezz2fxnDLYb/5ChrLQaM5aCwHjeVi8Y/m+HVSn07q00nt3F4M6VBDnnaReQIp+iJhW9JETqF1lGeDUzIGoUx5Qa9YcU6OQThacJE0bwZTNY3iRfr2fN6piOBgevF4lBx/OeoHwheKFx8BAABEFSRALyKE5ufnOeZfHGg85Dde8I9k+7VHfdqjPk22T3vUp5V61dledZZHneVRZTmGueYlJsowVPlinrmX/2SHnM9S5zxkOyyxosV92KCrqJVFtioY+VUYto9oWkdmH7OWnP5y9Ekg+UH0YqT7AgAA8EGIXkQITU9Pp6WlGY1G+jZ9dV8u6s96VJkeVaZ7ONOjyvKqsxdV2e5hiWso0zWU6RqSOIY4vEjvoSmWoxh7ESEUtANVJ1R/UCzNvCX1+mj4qaPoXqRP/cjfi/j+RPGzl5yleIQPhC9EL+7atSuCPZOHXQAAJBQhetFgMHDUF3vkX3hnTi4MHHEOSBb6jzgHJK7BTNegxNEvcSiPOJQZjv4M+8ARVi9SW/6Ip3jGdtSoeRGFpME+dTBXQyXZNClicQrulLCTR9HbUSnb83mnIpqGCU27YUrOXDz2rk/MrHgv7tq1awn9CxJOUVFRkpYcAOgIzotzc3Pc1xc7qw96pgpsfem2vnRrb7pdmWFXHrErM6y9Gfgcxda+dDYv0i+IkU7ygXZAGaftUMReJHdKCb0UtQET7/kTuoeEa0tiVSvMRFIc/W4iaEcVi1PIr0Dr9sNcctrL0T4QnhC9aF6JakxSu4AXgZWE4LwYtj/qg6oD7gmZRXEYC+5C7KFZkWZWpJkVh2tObotdOVcl9P9RJICV7cUkVQtIEVhhCMuLfO5fbDz/LjH1RTvlZ7ZXfrftWsHWi3lbirJ+dzr91RNf/ebrg7+OXTlXJUL0onllqTFJ7QJeBFYYwvIiIGCS1IukblZLujeEG54fS/jNWNVydUew+DuuRuFP/uoO0UuS7qjtAlIEVh7gRSCZoHvRHEaNYYW0TN/H2IvdkpdwHXZLJFfNSxIbEfAiAIQBvAgkE6vOiwxKAi8CQGwBLwLJBKMXzVxqpAiJMCmJXCxKSaF24mUcHo86vB/jkIFMY9sxbsYEdtcU0zu7ukNElFKoURWrRtIaWa/uEL0kkQTWhnbslrwUWCPBJce4744dLwUeM+1CAaQIrEjAi0AysSQvUtSHjdVDGDOIY7w6bHeG4f04b3Ul7EvbjBl2L5pxQQWbUxlrb/jKqzvwTa/uoC91S14SUXcn7Rt8jnuXAOBFYEUCXgSSiWXXF4PrGG7B5D08HuPQSIxj3TGMoMQAppYwgumWvBSqIjJWIHG34c8Gl7slL4X2IGzAsS/bLgRAisBKBbwIJBNsXjSzqjFSL/IYHo/Vi+R9I/SiOZwag11wyPYKVeoi9CL3vuBFYBUDXgSSiWh4kbsdlc/weGztqPR9ebWjcnnxqiQopG7JS5idyBU+bBF/ktGLjI2i4fcN044KXgRWKuBFIJng8KKZWY2k+xexCSQpI7lyjVfHMZItV78b0txc3P1uKGqhmYba0Sa0asdVQt+YHTs46ouEwxA60XDvy7hLCJAisIIBLwLJROReFDrhvChQwIvACga8CCQT3F40J5saGdUifN+AFIGVzTt7D06YwYtAkgBeFALgRWBlA14EkomwXjQnjxo51CJk64AUgRXPUrwIgSQwYX/TRUkCh10SXbQwgBeBlU3AizreXjwGAAAAACuXkBd1ATuG8WKiG58AAAAAIIYsxYsWgwECgUCWn6GhoYSXAYJnlX8d2NsHL0IgkERmlZ+IhZZV/nWwelEHXoRAIPHKKj8RCy2r/OsAL0IgkMRnlZ+IhZZV/nWAFyEQSOKzyk/EQssq/zrAixAIJPFZ5SdioWWVfx3gRQgEkvis8hOx0LLKvw7wIgQCSXxW+YlYaFnlXwd4EQKBJD6r/EQstKzyrwO8CIFAEp9VfiIWWlb51wFehEAgic8qPxELLav86wh58QPwIgQCSVBW+YlYaFnlXwd4EQKBJD6r/EQstKzyr4OXFy0uf4N2EbwIgUBilFV+IhZaVvnXAV6EQCCJzyo/EQstq/zrAC9CIJDEZ5WfiIWWVf51gBchEEjis8pPxELLKv86IvAiFvAiBAKJelb5iVhoWeVfB18v1mu84EUIBBKjrPITsdCyyr+OCLyIqxG8CIFAoptVfiIWWlb51xGZFzE14l4EAAAAgJUKpxed/jq1B/ei1uD75nzFOx8chEAgEAhkpebE+YoRo5+tvoiIXuyc8mkNvnFTXDPBHTNk6aF8ztQP37g4blwkrhkzLobNqNE7avRSHoZi4BUdJfMeUqgrvUzxsGVkjnU9KfOcmeMTN79QiuTF3+OoIfihBT7A4Ods8o3F9K8sDj8/xp8c9jMjxhjKaHwzxj+myML5uouB4H8L817dvJf3j5D009JyxUWMRh9JZp3LjHpmgWc0s04N9m8wWr0Ly8ica2TOrZtz6+Y9o/OeUYMH+0sZM3rHjIvjJizk3znv3+eI0d/9mORFC+bFDRs2nPq+5N64F1cjfqGRePNGHNLIHV0C0iSMLP+N3BpZJEVLTYPG20D43vFfApY6tQf7eWALWG6q3DdVbspDPLXDLizyIad8yEl5KB92YakZclJSPbiAhfIwsHLQSUz1wAJbbvQ7OJ4KZWCBO1X9Dl5R2hlT2WfDl/EXDZQk+DbxT0M+7KpVuWtV7ptqT53GW6fx1msXiX+Py/zDjNZfVmQ/V3IZGrBoffXB1GHRBHIzvqmLKNoIclOzyJZatbdW5alVeeTDbizVg0484X+BtN8YWyr6rMSU91q4ojATU9Zj4p/r3UZ6rnUZ+CewV5ehrNtY1m0s7zFVKMyVvZbKXktVn/WG0lbdb68ZcMgHF+RDC7XDzpsqV53aXa/xNGi9DVov8fy25PNkx6TvVFHJhg0bRKmpqc+/uH7cuIif+4hqjKcXQY1xU2PjiG8JXsR/HkQX0k3JqEZ8OaBGggnY1MgsS95eDJsoq5HdizzVWKtyE73IpsaAXZYkyCj+ZUX2W6WrUZu0auRtRw4v3tQsYl7E1Uj0Yng18vZixGqk2TEiQcZNjUQv0tW45JPkI7Pv+RfXv/baa6J9+/atWbfhTFGJcsZLPPclxItR/+sFO0bXi/RaI0WTjF6sHXbRa5AcXuSoNUbqRY5aY0RqDG9HFi8yhqjGmsHAW8aliC2QvEirKS6n4hiHKiP1tzqystQYDS/S1Ui0I69fYOzsGD0vRqRG3IuYGst7TJgaMTuyVRmjVWscnPOfKSpZs27Dm2++KcrNzd2zZ89/+4cnzxSVjBsX7wcbVJffaBOTWiN4MRpeZFRjwI6E751Payqx1kjxIkWN0WpNpahRQLVGdhESq4yMtUZiaypmR1yNmBcZW1Oj1qAagz8K6vZ0L5LVSPGioNUYpdZUjlrjErwYUYPqEiqO8VNj0ItENYZtTcXUuDQvdkz6Hpl9Z4pK/ts/PLlly5Z9+/aJTp8+nZmZuWfPnjXrNjz/4vpT35dYXH56rC4EWRHxc4Txqw8fp9/ipD2kxez0UR6anX5CfInJQjD8t4w8pgWfifEp6qsEPg3qR8qeRP+clh7LagmvvyBefwu8f2lMWVxuHEuP0eHln+BeXtJBFhbNgZD+cOh/KYQTGt+f4qnvS55/cf2adRu2bNny5z//+auvvhKVlpZ+++23mZmZ77///ltvvbVm3QYIBAKBQFZPfvvb327duvXjjz/+6quvjh49+v8B9vc0zV31bTwAAAAASUVORK5CYII=" /></p>
<p><strong>AD-Based GPOs</strong></p>
<p>When AD DS is installed these two GPOs are created by default</p>
<ul>
<li><span style="text-decoration: underline;">Default Domain Policy</span><br />
Contains no Security groups or WMI filters and affects all users and computers in the domain including servers.<br />
Takes care of password, account lockout and Kerberos policies</li>
<li><span style="text-decoration: underline;">Default Domain Controllers Policy</span><br />
Applied to the domain controllers OU only and should be used for auditing policies.</li>
</ul>
<h3>Group Policy Management Tools &#8211; GPO Components</h3>
<p>A GPO consists of two components – the Group Policy Container (GPC) linked to the Group Policy Template (GPT) which contains the settings for a particular GPO. The GPC defines the settings for a GPO whereas the GPT contains the specific settings you apply.<br />
Incremental version numbers keep track of the changes you make to any GPO and enable CSEs to discover that a policy has changed and needs updating during a policy refresh.</p>
<p>The GPC is replicated between domain controllers by the Directory Replication Agent (DRA) which in turn relies on the Knowledge Consistency Checker (KCC). The replication can be configured manually but usually happens within seconds between domains and between sites depending on your configuration.</p>
<p>The GPT on the other hand is located in the SYSVOL folder which is replicated by using either the File Replication Service (FRS) or Distributed File System Replication (DFS-R) if all your servers are running Windows Server 2008 or later.</p>
<p>The above also implies that both can be out of sync albeit for a short time. Clients will recognize this and will not process a new GPO until the GPT and GPC are in sync. To avoid conflicts and identify problems or version mismatch you can use gptool available from the Microsoft Download center.</p>
<h3>Group Policy Manager &#8211; Group Policy Settings Console</h3>
<ul>
<li><span style="text-decoration: underline;">Software Settings</span><br />
Provides a way to manage how to install and manage software. Allows for independent software vendors to add templates for configuration.</li>
<li><span style="text-decoration: underline;">Windows Settings</span><br />
Includes scripts – startup/shutdown (computer), logon/logoff (user) -, security settings and policy based Qos nodes.</li>
<li><span style="text-decoration: underline;">Administrative Templates</span><br />
Contains registry-based Group Policy settings</li>
<li><span style="text-decoration: underline;">Preferences</span><br />
Only available since Windows Vista and requires the download of the correct version of the Remote Server Administration Tools (RSAT)<br />
Contains more than 20 extra CSEs to configure loads of additional settings</li>
</ul>
<h3>Group Policy Management Tool &#8211; Group Policy Central Store</h3>
<p>Administrative templates used to have an .adm extension in versions prior to Windows Vista and used to be stored as part of a GPT in the SYSVOL folder. If used in multiple GPOs, multiple instances of the same template are stored causing for SYSVOL bloat.</p>
<p>Starting from Windows Vista and Server 2008 administrative templates are defined by two xml files , .admx to identify registry changes and .adml to provide language-specific settings. Any changes to be made can be applied to the .admx file and are automatically applied to all GPOs involved.</p>
<p><span style="text-decoration: underline;"><strong>Group Policy Management Editor</strong></span>- <a href="http://technet.microsoft.com/en-us/windowsserver/bb310732" target="_blank">http://technet.microsoft.com/en-us/windowsserver/bb310732</a></p>
<p>&nbsp;</p>
<div class="shr-publisher-1680"></div><!-- Start Shareaholic LikeButtonSetBottom Automatic --><!-- End Shareaholic LikeButtonSetBottom Automatic --><p>The post <a href="http://pcuserinfo.com/windows-server-2008-group-policy-management/">Windows Server 2008 Group Policy Management</a> appeared first on <a href="http://pcuserinfo.com">pcuserinfo.com</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://pcuserinfo.com/windows-server-2008-group-policy-management/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Active Directory Groups and Domain Services</title>
		<link>http://pcuserinfo.com/active-directory-groups/</link>
		<comments>http://pcuserinfo.com/active-directory-groups/#comments</comments>
		<pubDate>Tue, 01 May 2012 14:59:49 +0000</pubDate>
		<dc:creator>Mick</dc:creator>
				<category><![CDATA[Active Directory]]></category>

		<guid isPermaLink="false">http://pcuserinfo.com/?p=1644</guid>
		<description><![CDATA[<p>Active Directory Groups and Domain Services Administration Active Directory as a directory service provides information on enterprise resources such as  active directory users and groups as well as computers. To make it easier to manage objects these resources are divided... <a href="http://pcuserinfo.com/active-directory-groups/" class="read-more">Read More &#8250;</a></p><p>The post <a href="http://pcuserinfo.com/active-directory-groups/">Active Directory Groups and Domain Services</a> appeared first on <a href="http://pcuserinfo.com">pcuserinfo.com</a>.</p>]]></description>
				<content:encoded><![CDATA[<!-- Start Shareaholic LikeButtonSetTop Automatic --><!-- End Shareaholic LikeButtonSetTop Automatic --><h3>Active Directory Groups and Domain Services Administration</h3>
<p>Active Directory as a directory service provides information on enterprise resources such as  active directory users and groups as well as computers. To make it easier to manage objects these resources are divided into organizational Units (OUs) providing an Active Directory OU structure. Active  Directory groups on the other hand are meant for controlling access to AD objects.</p>
<p><strong>Active Directory Groups and Domain Services</strong> -<a href="http://technet.microsoft.com/en-us/library/cc268216.aspx" target="_blank"> http://technet.microsoft.com/en-us/library/cc268216.aspx</a></p>
<h3>Organizational Units (OUs) &#8211; Active Directory</h3>
<p>The best way to think of an Active Directory OU design is by comparing it to the folder hierarchy of a common disk drive. Just as you make folders to group similar documents or other data you would collect similar objects in the same OU for the purpose of easy administration. OUs should therefore reflect the administrative structure of you organization. <a href="http://pcuserinfo.com/wp-content/uploads/2012/05/Active-Directory-Domain-Services.jpg"><img class="alignright size-full wp-image-1651" title="Active Directory Groups" alt="Active Directory Groups" src="http://pcuserinfo.com/wp-content/uploads/2012/05/Active-Directory-Domain-Services.jpg" width="400" height="300" /></a></p>
<p>Keep in mind that OUs are not used to assign permission to resources as this is what Active Directory groups are for. Users belong to Active Directory security groups which are in turn given permission to resources.</p>
<p>An OU in Active Directory is simply an administrative container enabling you to manage users and groups contained within that OU.</p>
<p>In Windows Server 2008 OUs are automatically protected from accidental deletion. You will not be able to delete an OU unless you disable this protection in advanced features.</p>
<h3>Group Objects, Types and Scopes</h3>
<p>Groups are meant to create a single point of management for objects in Active Directory such as users, computers or even other groups.</p>
<p>They are commonly used to grant or deny permissions to a shared folder to a group rather than a single user. In order to effectively manage even a simple organization you need to create security groups in Active Directory for 2 distinctive purposes.</p>
<ul>
<li>Role Defining Groups – based on common business needs such as location and job type</li>
<li>Management Rule Defining Groups – based on how the resources need to be managed and accessed</li>
</ul>
<p>A Security Group can be given permission to resources and can also be configured as an email distribution list</p>
<p>A Distribution Group eliminates the requirement for access to resources and is therefore only used as an email distribution list. This Group does not contain a SID and should be used for email distribution lists to avoid overhead network traffic generating unnecessary access tokens.</p>
<p>A Global Group defines or identifies objects by job roles, location and so forth. Global groups are available t any trusted domains</p>
<p>A Domain Local Group is used to bundle users that need access to similar resources. It is replicated to all domain controllers in the same domain only</p>
<p>A Universal Group contains users and groups from multiple domains and are therefore useful in multi-domain forests.</p>
<h3>Group Nesting or IGDLA</h3>
<p>Identities (Users and Computers) are members of</p>
<p>Global Groups which represent business roles and are in turn member of</p>
<p>Domain Local Groups representing management roles such as read and write permissions to a folder</p>
<p>Access to Resources is granted by adding the domain local group to the ACL of the folder in question</p>
<h3>Shadow Groups</h3>
<p>The major difference between an OU and a group is that an object can only exist within the context of a single OU whereas a security principal can belong to many groups.</p>
<p>One of the challenges includes managing an OU where you want to grant all users permission to a folder while this is not possible on the OU level.</p>
<p>This is where shadow Active Directory groups bring relief. You create a group and then just copy all the users of the OU into that group granting them the required permissions. Bear in mind that when you add or remove a user from the OU, you must do the same manually in the shadow group and vice versa.</p>
<h3>Default Groups</h3>
<ul>
<li>Enterprise Admins &#8211; full control over any domain controllers in the forest</li>
<li>Schema Admins – full control over the AD schema</li>
<li>Administrators (Builtin) – full control over all domain controllers in a domain. Full control in the forest root domain which means they can manage Enterprise, Schema and domain admins</li>
<li>Domain Admins – Inherits all capabilities of the administrators group in a domain and is added to each client computer</li>
<li>Server Operators (Builtin) – Can logon locally to perform maintenance tasks on domain controllers. Account has no members by default</li>
<li>Account Operators &#8211; Can perform maintenance tasks on any OU except the Domain Controllers OU . Account has no members by default</li>
<li>Backup Operators (Builtin) &#8211; Account has no members by default</li>
<li>Print Operators – Can log on locally and shut down domain controllers</li>
</ul>
<h3>Special Identities</h3>
<ul>
<li>Anonymous Logon – member of the Everyone group in versions prior to Server 2003</li>
<li>Authenticated Users – Does not include Guest account</li>
<li>Everyone – Authenticated users and guest</li>
<li>Interactive – locally logged on users as well as remote desktop users</li>
<li>Network – users accessing resources over the network</li>
</ul>
<h3>Relative Distinguished Names (RDNs) Common Names (CNs) and Domain Components (DCs)</h3>
<p>Each object in Active Directory has a unique Distinguished Name (DN). The DN of an object is unique within the directory whereas the RDN of an object should be unique within its container or OU.</p>
<p>This is similar to not being able to create 2 documents or folders with the same name in the same folder.<br />
As an example – DN CN=Bob Baker OU=User Accounts, DC=baker,DC=com</p>
<h3>Name and Account Properties</h3>
<ul>
<li>Logon Name (Pre-Windows 2000) – the samid should be unique within the organization. The sAMAcountName should therefore be a unique, name-independent logon based on an employee number and soforth</li>
<li>User Logon Name – the userPrincipalName (UPN) consists of the logon name and the UPN suffix which is by default the DNS name of the domain where the object was created</li>
<li>Name – Should be unique in the OU and is the first part of the DN attribute which should be unique in the forest</li>
<li>Relative Distinguished Name (RDN) – Should be unique within an OU meaning the CN attribute must be unique in the OU. Easiest way to accomplish this is by including an employee number for example</li>
<li>Display Name – No requirement for unique names that appear in the Microsoft Exchange Global Address List (GAL)</li>
</ul>
<h3>DS Command Line Options</h3>
<ul>
<li><strong>DSQuery</strong> to find objects in the directory</li>
<li><strong>DSAdd</strong> to create objects</li>
<li><strong>DSGet</strong> to return specific attributes of an object</li>
<li><strong>DSMod</strong> to modify attributes of an object</li>
<li><strong>DSMove</strong> to move an object to a new container or OU</li>
<li><strong>DSRm</strong> to remove an object and/or all objects in the subtree</li>
</ul>
<p>Most commands are run by specifying the object type (e.g. user) as well as the object DN in quotes.</p>
<h3>Windows PowerShell</h3>
<p>Windows PowerShell is the recommended tool for performing and automating administrative tasks in Windows Server R2. System administration tasks can be performed by using command-lets (cmdlets) modules or snap-ins. A module or snap-in is a package of cmdlets and/or other items.</p>
<p>Windows Powershell is also backward compatible with cmd.exe making it easy to perform familiar tasks susch as ipconfig, ping or nslookup for example. Windows Poweshell return objects which can have properties – or attributes – that represent data maintained by the object such as a users first and last name.</p>
<p>Objects include methods which are actions you can perform on the object.</p>
<h3>Comma-Separated Values Data Exchange (CSVDE) and LDIFDE</h3>
<p><strong>CSVDE</strong> is a powerful tool that can assist administrators in importing existing user information – such as user accounts &#8211; from MS Excel or MS Access databases. It can import and export AD objects from or to comma-delimited (.csv) text files.</p>
<p>It cannot be used to import passwords so you will need to reset the user password on any account imported as well as enable the account.</p>
<p>The LDAP Data Interchange Format (LDIF) is file format which can be utilized to perform batch operations against directories that conform to LDAP standards. Unlike CSVDE <strong>LDIFDE</strong> can be used to modify or remove objects in the directory.</p>
<p>LDIFDE is also capable of importing user passwords. Remember that these accounts will be disabled until you reset the passwords and enable the accounts.</p>
<h3>Inheritable Permissions</h3>
<p>The Discretionary Access Control List (DACL) which is a part of the objects Access Control Entry (ACE) assigned to users and Active Directory groups controls the security principals. This simply means assigning permissions that manage access to objects and properties in Active Directory such as resetting passwords or changing files in a folder.</p>
<p>Note that not every permission is inheritable and inheritance can be scoped to specific object classes. Generally speaking, new objects inherit permissions from the parent OU or container.<br />
This can be manually modified by</p>
<ul>
<li>Disabling inheritance in the advanced settings of the new object</li>
<li>Allowing inheritance while overriding it with an explicit permission assigned to the child object. Explicit permissions always override inherited permissions to the extent that an explicit Allow permission will override an inherited Deny permission</li>
<li>Scoping the inheritance permission by changing the inheritance properties on the parent object. This is considered best practice as it defines the Access Control List (ACL) at its source rather than overriding permissions further down the line</li>
</ul>
<p>You can use Delegation of Control Wizard to assign specific administrative tasks to appropriate groups and individuals.</p>
<h3>User Account Templates</h3>
<p>User account templates are generic user accounts prepopulated with common properties. Take care to disable this account for security purposes. When you create a new user you can just simply copy this template saving you the time of having to fill out each property again. Not all attributes can be copied and following is a list summarizing the attributes that do get copied.</p>
<ol>
<li>General</li>
<li>Address</li>
<li>Account</li>
<li>Profile</li>
<li>Organization</li>
<li>Member Of</li>
</ol>
<h3>Modifying Properties of Multiple Users Simultaneously</h3>
<p>You can select multiple users objects by holding the CTRL key as you click each user. After that you can right-click on any user and select properties from the menu. Properties that can be changed for multiple users are:</p>
<ol>
<li>General</li>
<li>Account</li>
<li>Address</li>
<li>Profile</li>
<li>Organization</li>
</ol>
<div class="shr-publisher-1644"></div><!-- Start Shareaholic LikeButtonSetBottom Automatic --><!-- End Shareaholic LikeButtonSetBottom Automatic --><p>The post <a href="http://pcuserinfo.com/active-directory-groups/">Active Directory Groups and Domain Services</a> appeared first on <a href="http://pcuserinfo.com">pcuserinfo.com</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://pcuserinfo.com/active-directory-groups/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Active Directory Certificate Services</title>
		<link>http://pcuserinfo.com/active-directory-certificate-services/</link>
		<comments>http://pcuserinfo.com/active-directory-certificate-services/#comments</comments>
		<pubDate>Sat, 28 Apr 2012 17:12:58 +0000</pubDate>
		<dc:creator>Mick</dc:creator>
				<category><![CDATA[Active Directory]]></category>

		<guid isPermaLink="false">http://pcuserinfo.com/?p=1622</guid>
		<description><![CDATA[<p>Active Directory Certificate Services (AD CS) Explained Windows Server 2008 R2 uses Active Directory Certificate Services to build and control a Public Key Infrastructure (PKI) within an organization. AD CS in a Microsoft AD DS environment consists of the following... <a href="http://pcuserinfo.com/active-directory-certificate-services/" class="read-more">Read More &#8250;</a></p><p>The post <a href="http://pcuserinfo.com/active-directory-certificate-services/">Active Directory Certificate Services</a> appeared first on <a href="http://pcuserinfo.com">pcuserinfo.com</a>.</p>]]></description>
				<content:encoded><![CDATA[<!-- Start Shareaholic LikeButtonSetTop Automatic --><!-- End Shareaholic LikeButtonSetTop Automatic --><h3>Active Directory Certificate Services (AD CS) Explained</h3>
<p>Windows Server 2008 R2 uses Active Directory Certificate Services to build and control a Public Key Infrastructure (PKI) within an organization. AD CS in a Microsoft AD DS environment consists of the following components.</p>
<p>Certificate Authorities (CAs) such as root and child CAs which get their certificates from the root CA. Child CAs usually request a renewal of their certificate from the root CA as soon as their certificate expires. This is also the reason why root certificate durations are normally much longer than the subordinate CAs.</p>
<h3>Certificate Revocation Lists (CRLs)</h3>
<p>CA Web enrollment enables users to connect to a CA via a web browser and request certificates and Certificate Revocation Lists (CRLs) which is a list of certificates that have been revoked by your organization. A certificate on this list will consequently be refused. <a href="http://pcuserinfo.com/wp-content/uploads/2012/04/iStock_000016688127XSmall.jpg"><img class="alignright size-full wp-image-1637" title="Active Directory Certificate Services " alt="Active Directory Certificate Services " src="http://pcuserinfo.com/wp-content/uploads/2012/04/iStock_000016688127XSmall.jpg" width="400" height="300" /></a></p>
<h3>Online Responder (OR)</h3>
<p>The Online Responder service replaces the need to download a full CRL list as it responds to specific  certificate validation requests through the Online Certificate Status Protocol (ACSP).</p>
<p>ORs – which are a new feature in Windows Server R2 &#8211; are therefore much faster and more efficient than using CRLs.</p>
<h3>Network Device Enrollment Service (NDES)</h3>
<p>The Network Device Enrollment Service allows devices like routers and switches – that are typically not part of the AD DS system – to participate in the PKI system through the Network Device Enrollment Service (NDES) by using the Simple Certificate Enrollment Protocol (SCEP) developed by Cisco Systems. This protocol allows these low level network devices to be integrated and managed in the PKI hierarchy maintained by the AD CS.</p>
<h3>Microsoft Active Directory Certificate Services &#8211; Stand-Alone and Enterprise CAs</h3>
<p>A Stand-Alone CA can either be running as a member server or a stand-alone server in a workgroup. It is therefore also not necessary to be integrated in an AD DS. Stand-Alone CAs can run on Windows Server 2008 R2 Standard, Enterprise and Data Center editions.</p>
<p>They are used as internal root CAs in a multi-tier environment where the stand-alone CA generates certificates for the child CAs based on standard templates which cannot be modified. A Stand-Alone CA should be taken offline for security purposes after they have generated their certificates for the child CAs. Remember that AD DS directory membership is not a requirement for a Stand-Alone CA.</p>
<p>Enterprise CAs on the other hand must be integrated in an AD DS directory service as they automatically issue and approve certificates when requested by clients or endpoint devices. They are usually member servers in an AD DS domain that hold the role of child CAs. Their certificates are based on templates which can be edited to support specific requirements.</p>
<p><a href="http://social.technet.microsoft.com/wiki/contents/articles/4954.certificate-status-and-revocation-checking.aspx" target="_blank">http://social.technet.microsoft.com/wiki/contents/articles/4954.certificate-status-and-revocation-checking.aspx</a></p>
<h3>Install Active Directory Certificate Services &#8211; Final Configuration of an Issuing CA</h3>
<ul>
<li>Configure a certificate revocation policy. This should be completed before starting to issue certificates and includes specifying the Certificate Revocation Lists (CRLs) distribution points as well as the CRL and Delta CRL overlaps and the scheduling of CRL publication. A delta CRL contains only the changes made since the last base CRL update</li>
<li>Configure certificate templates for EFS, wireless networks, smart card certificates and web server certificates as needed</li>
<li>Configure enrollment and issuance options</li>
</ul>
<p>When using Online Responders you need to configure and install an Online Certificate Status Protocol (OCSP) Response Signing certificate and an Authority Information Access (AIA) extension to support it. The final step is to assign this template to a CA and enroll the system to obtain the certificate.</p>
<h3>Active Directory Certificate Services 2008 New Features</h3>
<ul>
<li>Certificate Enrollment Web Service and Certificate Enrollment Policy Web Service to enable certificate enrollment over HTTP</li>
<li>Certificate Enrollment across forests allowing for consolidation in multi-forest deployments</li>
<li>Better support for high-Volume CAs such as Network Access Protection (NAP) and other high-volume CAs.</li>
</ul>
<p><a href="http://technet.microsoft.com/en-us/library/dd448537%28WS.10%29.aspx" target="_blank">http://technet.microsoft.com/en-us/library/dd448537%28WS.10%29.aspx</a></p>
<p>AD DS Management Tools for controlling AD CS can be accessed through server manager in Windows Server 2008. To manage a CA, certificates, certificate templates or an Online Responder use the appropriate Microsoft Management Console (MMC) snap-ins. The AD DS tools to add to an MMC in order to manage Active Directory Certificate Services are Certification Authority, Certificates, Certificate Templates and Online Responder.</p>
<div class="shr-publisher-1622"></div><!-- Start Shareaholic LikeButtonSetBottom Automatic --><!-- End Shareaholic LikeButtonSetBottom Automatic --><p>The post <a href="http://pcuserinfo.com/active-directory-certificate-services/">Active Directory Certificate Services</a> appeared first on <a href="http://pcuserinfo.com">pcuserinfo.com</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://pcuserinfo.com/active-directory-certificate-services/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
