From c3a3d9378ee8a101dbdff6f823cfe50582401359 Mon Sep 17 00:00:00 2001 From: Jorrit Folmer Date: Sun, 24 Jan 2016 21:23:33 +0100 Subject: [PATCH] Added SAML authentication support through ADFS --- README.md | 81 +++++++++++++++++++- adfs_claim_descriptions.png | Bin 0 -> 22120 bytes adfs_claim_rule_group_membership_admins.png | Bin 0 -> 9042 bytes adfs_claim_rule_group_membership_users.png | Bin 0 -> 8988 bytes adfs_claim_rules.png | Bin 0 -> 9075 bytes adfs_claim_rules_get_attrs.png | Bin 0 -> 10969 bytes adfs_rp_endpoints.png | Bin 0 -> 8999 bytes manifests/authentication.pp | 59 ++++++++++++++ manifests/init.pp | 4 + manifests/inputs.pp | 4 +- manifests/params.pp | 3 + 11 files changed, 148 insertions(+), 3 deletions(-) create mode 100644 adfs_claim_descriptions.png create mode 100644 adfs_claim_rule_group_membership_admins.png create mode 100644 adfs_claim_rule_group_membership_users.png create mode 100644 adfs_claim_rules.png create mode 100644 adfs_claim_rules_get_attrs.png create mode 100644 adfs_rp_endpoints.png create mode 100644 manifests/authentication.pp diff --git a/README.md b/README.md index b4c51d4..2ab0710 100644 --- a/README.md +++ b/README.md @@ -1,4 +1,4 @@ -# Deploy Splunk into any imaginable topology. +# Puppet module to Deploy Splunk into any imaginable topology. This Puppet module can be used to create and arrange Splunk instances into simple, distributed or clustered topologies. It does so with the following principles in mind: @@ -250,6 +250,65 @@ node 'splunk-cidx1.internal.corp.tld', } ``` +### Example 5 + +Enabling Single Sign-On through Active Directory Federation Services (ADFS) as an Identity provider, on a search head: + +``` +node 'splunk-sh.internal.corp.tld' { + class { 'splunk': + ... + authtype => 'SAML', + idptype => 'ADFS', + idpurl => 'https://sso.internal.corp.tld/adfs/ls', + ... + } +} +``` + +And then on the ADFS side: + +1. Add a new Relying Party Trust, by importing the XML from `https://splunk-sh.internal.corp.tld/saml/spmetadata`. Since this metadata is kept behind a Splunk login, you'll have to: + + - first browse to https://splunk-sh.internal.corp.tld/account/login?loginType=Splunk + - then browse to https://splunk-sh.internal.corp.tld/saml/spmetadata, and copy/paste the SAML metadata XML to the Windows server. + - import the SAML metadata XML from the relying party (Splunk) from a file + +1. Add 3 new claim descriptions for: + + - role + - realName + - mail + + ![ADFS claim descriptions for Splunk](adfs_claim_descriptions.png) + +1. Add new claim rules, using the new claim descriptions created above: + + ![ADFS get attributes claim rule for Splunk](adfs_claim_rules_get_attrs.png) + + ![ADFS map admins claim rule for Splunk](adfs_claim_rule_group_membership_admins.png) + + ![ADFS map users claim rule for Splunk](adfs_claim_rule_group_membership_users.png) + + The rules overview should look something like this: + + ![ADFS show all claim rules for Splunk](adfs_claim_rules.png) + +1. import the Splunk Root CA (/opt/splunk/etc/auth/cacert.pem) in the Trusted Root Certificates store of the Windows server, +1. `Set-ADFSRelyingPartyTrust -TargetIdentifier host10.testlab.local -EncryptionCertificateRevocationCheck none` +1. `Set-ADFSRelyingPartyTrust -TargetIdentifier host10.testlab.local -SigningCertificateRevocationCheck none` +1. `Set-ADFSRelyingPartyTrust -TargetIdentifier host10.testlab.local -EncryptClaims $False` +1. `Set-ADFSRelyingPartyTrust -TargetIdentifier host10.testlab.local -SignedSamlRequestsRequired $False`, otherwise you'll find messages like these in the Windows Eventlog: `System.NotSupportedException: ID6027: Enveloped Signature Transform cannot be the last transform in the chain.` + +For some reason the ADFS side doesn't like the AuthnRequests that Splunk sends, so `signAuthnRequest = false` is set in Splunk if you use `idptype => 'ADFS'`. +And on the ADFS server: + +Logout doesn't work by the way, throws this error: + +``` +Malformed SAML document(Assertion) received from IDP Please provide a diag for analysis. +``` + ## Parameters ### Main splunk class @@ -354,6 +413,21 @@ node 'splunk-cidx1.internal.corp.tld', Optional. Specify the SPlunk version to use. For example to install the 6.2.2 version: `verion => '6.2.2-255606'`. +#### `authtype` + + Optional. Specify the authentication to use. + Currently supports 'Splunk' (default) and 'SAML'. + +#### `idptype` + + Optional. Specifies the SAML identity provider type to use. + Currently only supports 'ADFS'. + +#### `idpurl` + + Optional. Specifies the base url for the identity provider. + For ADFS IdP's this will be something like https://sso.corp.tld/adfs/ls + ## Compatibility Requires Splunk and Splunkforwarders >= 6.2.0. @@ -363,6 +437,10 @@ If you have version >= 6.2.0 servers but with stock settings from a previous Spl ## Changelog +### 1.0.6 + +- Add SAML authentication support through ADFS as IdP + ### 1.0.5 - Specify IP to bind to @@ -416,4 +494,5 @@ Initial release: - Search head load-balancing - Search head pooling +- Managing apps or inputs on Splunkforwarders, see principle 1. diff --git a/adfs_claim_descriptions.png b/adfs_claim_descriptions.png new file mode 100644 index 0000000000000000000000000000000000000000..646f740c15c0e1a000c8f69243782c3acc4094ce GIT binary patch literal 22120 zcmb5V1z4NivNlYC0u>}ci)+x*;_fYJfMUg=xI?kxZiPaC;O-?@Deev}1b2#SaSQJL zg}(dU=Y0Qn_CEX1mFvo*^URuOt-0r(nFPO=m&ATd`WOWT1zTDQq=bTkW`Kh7;3F0) z@(4L^`)3psH8yF`YZccAh%`(qvI!Dj+?2_ZtJ0q~&QAsm^l}58HB$+<`8~&E$UfD z)qON4)VkazM7iv_FCoMm0zrOU>jAd6hql!*_d7z)2;xI8@8gkB^&=`uj1$?yI{Nwh z6A*6Nu=^h=;K=>Y|FG-2XV_HRz-k0QexksRw41iT3dgIrt4N1UPV(r0;+RGv(AFr6i;q0^xLuHRW%%JHS!0mY`b=vT{L{m zsA;_qM$Uu=uBe($5$h#Q>!|Bi^Y(*8{RQy^0%pKH@64H_I`yT&=SUqA3xfS^;N!jD z&mE_WR*1acKUOPWbm!2Pdsq(;)9DwU>7ueWp|t%zBmZ59^n=K6mz7coq(t;G{!DNG z`TA!Wy(+Q;#CMO?x$w1Rf;lq9$0PECVIGOKlAMmQNWCrKb!KLxpsBQCvkdEM^^UfM z__mC=&mRP9G}80Aw_C7<#S(?a#{H9QtH-ST7ovhgAkOo0E7|J^FmyoFl2Oe)c~@2( zB)d`JuWeb~FCx6ByH=-Mv}TyAV^^hbY&UdDtM$WQR*w-8OTR~XUhit7HI&MGmTU{VNvdI^H=Wp#764v|&=fkfc1u zG1XPX?l1KuF0VSH(DTQJ@Zs;KI=)m{nLt`=!e1(mBM&VueR2UOmH&@EdF4^|4utR~j$X6`c2v8>K z>wOGc$6UhZX{l|?_&J+jP1)yJQDjOM%ma%4oz}yA9L0b9ZgD{+bfuI-@DsN@v~sgEF~-mE<`VPE{fPl z#GGTKE=hC~Rb*H1HUh(>;Sd78l*t*wcta5EX_qJ88G^MoLTF+#Hy^Hg9xL zGIlW0^2Z9q^tEx`cc^z$bPC<5%Q2x=txANzd*lCbuE# zHl#dO!+y7GQ&#q3s?1{W2u&wI5br21_a)Up+97g!j1||0nI~vppD<1tEQOiV+A#~( z6~bb_lygm3t_HhG#v65Y;+weKSizh7r;?@NnZPyMYBUs-$>}iS1NQDgAnEACCj&Q{ zdC?>dSz8x=#cfavIM+n-iH2MTbQr=}${UjO9RKmUN0DaW%}3DGY9IlW-)_ov`Ps~y zOzP!x$@sP;f-oz%oUUcO0o6MBO~YGo6k8Mo1%=%>Y$H`76)bz(Y#Q44D`xAvz4O^- zL0=MA&!NH5VCFg|-{`gXTm>yQLCs5q)?4%#@2IoFE-o)?P=g9kVb;njVwq}+Zr+qs zF%WQ8m}mxDpS|-?tJkv}*ZHW6oad7mVdfmryB5=*P2W>XxcdcRFR7kqSbs}XHg9K3C&Gh0E@}hf(GQan<0e59CMDMM09+7o6>^3iKm5teYxp)Q+*Eck56BZFM zWnA}Md@@+f_U_H|9uRcqQxcJz;&%**Qm2g7Ic%Xden=;+VMHz=hI1iEzlZ> zO*T6>C(R&O3UGQA7Q|Zns_Aw&C}ff`4{%q4${^1Nrkbnk9UP; z>uMBc-diob9^9921N7VQZrZjE?@cs8PlT`s^3P`DHVTYHWM?P$qS;L8lm=hntj$6(B z^#XogWiM8=K1j}09(j^rg)`k<;A!H`Z9+D)tav|F2qqx$;+_&Vo-%Jy?es&O&0ko6 z`hQ!#`=w{nu>j_~ky5#F(v1p*4afrngMyA+g`3u;T_TM_hgrtoV%IGeRql3g-CAh2@j=)M zFm7El*Au8ny_u{p2M&@;4ni5-=IrYOH1ge4>AUc9)F?3lqQT86n5GobR!IH z&!&)m?e5{hr6*Wn4G&?_u0NvHp_*2I*40qys(#igSME}*+AxjTAr84jfXbu-s$IG1MmscfA@BI^-S|xf?y(q-?QQe7wUp~<>3M;e z)45MkaWgHF$A^c9M@LVdJ|zqW<@HHX2L=R0Iv*b#C>D$r7Z;O|kXVtGasRr*p$F11 z$!V1_+|6xfTp!H_rO4*A3i14O`R;EMQE2uwY;t0v=BC!2l`k~EShRw{Xzs9*=(4cX z8m_)B$u30ASsUb3i(WI#?L~8PwCaIhv+roxw5>)_0)&jWdQ|r>J&26x9>rEZE zcU^NOM3E&&dU0CCk#CGiU2M%aK{Ea=^1Ej}B>UI1j_2SBzn5*zy+y_E(n1@@SFLhn z-sGo&W4n#*>$LM#a`W;E`lWE*Rd-pc57zEJM#r{wJutZ(e8+`SPt`RkXFSHvXO=h4N*9-Wo4&c{d>W`vV4 zWn<8bxv0hYkuo;Vku%qZE4Myz!ii$FPsFeWX*H>4Nz>}EyctBv%!Zai#6JE4 zF%H~owPIFgKD{cTy#LbG@|Uhw%x-qE>a5QP4AO)9SQx1ceHaBDfevRF(zEyV$;wcN zHvn2{R|LMrIIcT%)gSVUJe*BOrF28|0GB=MJO?yLhc7A1W(r^H?R*2zZY-3JH`wHu z$w_(2z$Lfxd-*HQO#45vB`qo)?-o)RS%X$Br%p0v^(y-ohanO7I7k}xjr?N7t&D#L z$v}a4Q#?y%%#xT}5iV<&TosNqNAW!;WJx~X9VxawKx7>^I!7-`woD{H##0t)|5oJi zsBym>56#BO6C{%N&fs3E=HP`r+yzjHAtiIuX60&Te5(3vkDjm6gT5re3%hKi7?+8d z`wpF@6RX%wH8%0wh}KxV#u_M8?#vAqVH7LA)8ncGdb+HcUID`(cX~(4NI@uJ=jR+@ z{050&@&yf^Kj8`~;6A)ZQQ+dHB|TU?D`mWoUBrQ?_gDXkNRT1I{kHEPx`kBbe&_4G ziILJa*s$74*F9r35fw-wzPXzR+_X33Xtj9&7cmFq1;|^?@1rKWs4}%t?!8XAt}mD-L{4S5*IE#;ECIzu!Q)lskO*=(w*|YsK2&5^yQ-;4c}5ZnjQg-~kZNCh4BQM{X%&xxkD|Crtz@0bfGVp;&D zCD2~Azf!Xzq(MkWVY9Hw)0 zEm^^CS1rg-W6zr;awu8b49CwbA9K{bfWsFf?VA8ctl6xzvKW?*BG>>cL;2c11C^pQ+(G%+9& zJGjU=@-yOV*Uk#JufB9NU3Vn0-J!ONk@uvZzP(9lUE?LJrX%iW2O_gS{uLP%3xbu| z2u>Y57vos2AN80YxU(7wQ6S{F`Ox@cK=`v;_+OEmVZ7+Er*bc$#7M8+%dn<*M zp4JUnfGb$f@;f`gTufl@4vlr%O_Me5Wgn5z>9&L$_hdmlV6<48n^)Yub-Yg$CoX4)M$Fr% zmcH~HY78D~lxVT)eo~t%AAZb1>rW{`E2;;ln_4K`SO?_%fMR*V7kJRpbHp`pfVs04 z&jvhR?+Oq{Nrw2LV1Erje-3O-r|5wo^)`gFiSgGu?{u|F)zrj3x!JnzI(oG&>V*&= zSwva@8mxOgIwW~}wATfpp8QBS!0gsIV+taz24f!jRJ_4_n=h#RM@j`Fu#$_BGAu&u z@U{SRo@DxNd@)G=`0my+4pYzV^fpW9jJ`o8I@?X{*eRG!TFD?7Afy*f2cB(5-i~|_ za+47F?p_oKIo$h=Xkx`b$C1+z981RmLmr_E2JlJV+OI8l4(BR}tV_nJ2>VT-deat(Ie7Y1EL>F#bV!1kjy zpJ-AJ+Wx8awyIimA3ABH{(EhYZ_XAlP2p361>H+Q-P*6}bS+safPyJL5l}|=wasLD zW_DnGVmL>VEJI9pbueJB=}gz5^sFM?cu~cEXFpy?EZTG7@p(=~fxnFM4IF|JEFQes z_LkV|l$zu%tIdMw-6-G!pCjgM1!9F9ZZ_~w37-{S=(af2F;g$48ccNxINnx@l#qUqQlO$stn8G1szd^}R)O3KMGn*^uxGrRy!t zmK!H%L#Ae_AWU~hQ(Axy+(<7S*z7PpPf449IL5j~mVR+)nL<2_X2=T+_de_^qSDjL z*m9`m-Hg8p$FY^eE|gPKXFI7X{Ltda2$m&@c#q4(F1Mz3&Dm`V3Xej*b`|YbLe=K` z*}+L|%C*FIpiIUWK9{}d7Eaj)!nyI~k`&dH9s~mzaqreWZjTnFHLQ!J>nW5Nr$%f= zUyevWJ{D9J9ra3zyIZs!xn^IuR%*~M&^QTtWzrdNmRakO*!+u_qow)!_wVT{;1l57 zyb|ki!4Ytx46WNH4r#p3g_6a}1VirOaeV9OxvGF$Z8?@zPwhpz==c(w272m$CB-05toOBz? z0n>t=q62NhuUGpzBeLW&y!+lVC^0@*^0{Ff(AFp7q)j~)jTG4mYWqSVgh~$%z{s7L zFUlM|-CcB1DPcJ|18_7y1v_rDuWi7qEY)j?qgr-9efIkx$b5~T;)^!3j+S1PnCS&u z6qSFTZ7;sSQ_(T+eSW=9U|x}NyVE*q*K+c^p&QNCb4RUnP&i2{4IR>QR+467VCahU z*m5VCJ$#XhR2dfOan{H<;!=B}2O(Zgn76iOm_(Hy$pJh>e|3@fKJ(%O=UW2wcR8rE zhD$hR_wN7up6x2YnSjOgagw0TO`*a6`@Sxv+_vIq@%ObvV7`g zoKS%Sp5rkuQ{NR+%$ILVM(=4oXmNCQ`egB4ECnEtyB75IrrNP_vfK7(xG1(PVm($@ zQ8wq(S`o1nwopSA44*m>sV>rkPAg7_4gwelo%q&*D6kmRF;aR9*xW6V&bW_q+G@)F zIS@7Lg7~R@mxT6XPf;ve@?2)-5lm>`jT#jpSv(2^iFrsV|49tgdqNH{Vn>({cD|-V z_ubWgr{IQXfoP2aeQl?|H^RL;C$>9|F|)Zjzr0k*sHl>zLAW@&T7J~GF0XgbFEJUr z%+X5*=!9?*bM(s?^|w5s4gt{LKOTB6cRkt>X2i$nuFmkCuQR20EYz!jsNm$_qgP># z=(sY~o@V;SO&akqx#cO1xP(-2lp8Ss{r!h;q{LzgFXWP0DTL z*QvMt$-oOO-VbFYQLNu~h=U$oq{J~zOD23cM+6*|ak|iCJk;s!jX~iM1{#I}+YThm z>K(+fIDfzsKdURIIfO>ncE8(}dML6<2Zk@ViretFuGEr#!$GUme{>UaH}~q6jC#=v z4;VO>Kt-E-vW7`9{cLY54pcxYy$TJ1z6Zmcn}j zbhp={=C&VawkJ02ltHZMOPmNeNaBEaa|Z9qSrEIE>waf{gnkiK9dU-+oRz$=#8;Vf zc6)K2j6q+cz#Xn%^EJVi!n}crbu>yl-kZW>oN`Mp)FzU+icGpq&WxHpec!+436bK#@Q~P6)R{WLeXxu#-hT6v1=HsBeu&^( z((-V~mA2cPJ$9F?NX4H>+rLvDhoXV;`zCJ_PZ9m)7Kk0cmDa1ZfY815N=o?}>V zg-B$zZS60c*XB6aV`EDc(rKN?8K{saZVMndX~h&yn_Ds^TI45;Pzg=RfZoDmVhbw3 zs#<*Qp`s1iW!vLre`4f%e}rcZu6#6ntNzQKT;DVBw-FQmE`4l3u^kqXAsiV1J3pyj zD8BwU9G*Q8lLDZTyX6CvbsTaUI{*6RffgAU!V(79p+#kCr?DwaYM3A}{TFx*C;cK;w|B?JbNTUKigVSX*T#(5}&4>MhNNne6W zsYY+p(2f!t_h;2>yPMu{0qsjNmkv1$4L!!@YqbOBE?19|h6OGnE1u0_BBR}#-iYo) z`_2bQGZ`1k*zSIk2~tlFy)LBCZeVu1dJ@uMh8d|1CB9C1*6`5F^N7M7A?j`9ha5=T ze6HAj0)}=Y!C2u;h*=p?$=ZeKmv?;I8EBCLxvNW@Ok6ruO-tkgtu|iYuyF|2xr)hI z#r|54nf*~MsTb#Vm7BjJ>bgMF@@dx@-FN4EzQL~_C>|9`MORLEKT<*l2S&DHp5Et= zDyJ0goDH^W7u@&fR{Z#yoeP%D(q*%EMuE6O(`d4@;JAP+>uQP1!8lxp=lz(a+vtCbj)P{o| z!{Xn+I!4sQQ~Z?I6xX`iYDyop&0`!OOmt0hMcso*V+BgKWiZ{_@ZaB7Z*cocvNL=a zFMRx)4d?$49-NT_mR~DEkKyo{Y6@SbKWK+E{s!aV?B&79 zNxrC=WsJ?#-p2m;=#Ob*rxPW;-tQ+eUIGh}m02apmuKFA>2`#d0@3?%)HS^h9qF;QY);GkFV^1>8ZfkrVPo(46LTas2WL#z z+9B3Jdp)3&HCKl^_cGfP!zxkTqKFeD5#CxB=_P1_Lq-!W8cfMGSqC7F8Qj(T;fd*N zzy^=6Nr+5L0A4#JwJ*HP?P-a@>%Cq6x|AlOj!;1F9_4C*(ab>M*tPd`%;A@!5WJj( zvv5LDKIU65Ggm4&Cy0D9gX}ZM0c;<^X8@`!=+9Hn3MBl23hNm{A*ed`dPz;88RI4#P*d zfPAbI>6oE6w+QyD(oiIII`sFqoCtpjb@Y&_8!8!y5MC(X{nd#>H^NqAc`9CUlXEn0 z2!Cb&W`8ghW#WmU{u~QI%f>>?@h?v*DLxbWa2S?e)XAo7!X!)m#35^BiqB>DQGGpj z5+>@M*~R{@YW`eX;x_@G1oN}(tQj1f=Yj(DTT9^AQx+v1H~T;`D!Sytl33s z<_wfH1rm>Vu8!YR{iY!Dd-REOA74*vYMuF2SeKZ({k>^uoKB4coY&x42M3b#J|{nf zB(4?&uZMzf7kr8if3pnE`&4c>gC2_wky8@1anb6UAIv!2wS13&FNX2MECtZ5!2#r+ zOgB{g*y6N8b{MBgtOiiAM#pC(By|^BPj?N^F`jLxyVSiyP$pvF&&eg|D+o63{MPTk zv;G!xC<@AcZe^Rmub`?dGi64O%&rxZ7tZ77b@qmtQv$%TGv7BT)@-QCi%LZy0Q&yn z#v=}nm%u|7cdmUE-)Ii)&xpa-{3Fdf9B#zkhQqbppMoj&Ba{oXAis=nUu?%C>A;Ze zsoxKyG@X*@222$z3murl%)sfdVpyXst^E`GhLxg^ZB(+d6c{EH0M?3MGhQR#nnvJn z_f0UbX?E0*=848gww9gMf=cNrn7kGzG&9kO1cWVpLho^PH?BtyHb@MO_#AUF^YN8^ z0SZ}l%{8%6O+n?Z-@&SL@PJhVDimum)s|N2$w=`l*_BV<^wBglI9-}Yz ztNS!rf8r}xx(h2Nhh{fg{~`wmH;|NyUc8W?NyVnod&8tjBV0gek%5K7$}jq$X7FVK zHD<2HY11(YSImrZZci;0$FY4t9qt9nYiDnW4Q=^EZIk>KkD zDxSf2ZX*gEQd{`nX_0a7XY2n?VM6wM%s`aptRaCo9B48~5cd_7`Eyx#)6M?HBIA&$ z*v-tB{AJOppDr<&^XJn=;Tdj90qUZ_X|#Tt;rD-Mgf<;?SSrxEl~R*aluW#{-ypdo zm%`nZNA>ZZWd^U&lHOd!-X@!E!g=p>%c|Ven!}aPWsL||J9AMYV`8}{c*SpR-~68* z)J5-@XZX`@PVO9k@-_R4nnF|KLe$d5qL_5QK4?(k?0Tz4y8iOmHVPoa(ba#nRAMA# zH}%D)%>g+SoUp*ZL;L}6UAgCCvTGl^Pd+$o5)V&Zdl=)86fr_5@rJ!gz@Qglw`DQJ zQJBdRS($(1;J-@YGJ=h@D;{i9`FKUBA1zYZ9QrNPlPBAMy|5S*rIgE^C6;YM(;dJj zKRJEG-(hxApton4%O`9Rw`(|Loq_)jPJ2C`j+M4(=A!{()wI*R^?v+Te;k%4i z#;Zn86=nfZ8L9aDgtR(!8^RujT(GvE6hZ$q!vCJ@Ww|6DHi{uCC&K6}?T6TmCE(c0 zt{Ez!8=v)krv6RkiSPS{n5$1dINg}ba5bMC`I=UkMYH&?BV4}9yl&()EuXf@IQD<3 zwsK8-jiSt21tszt&K;Nlqj4CXr(yzdP@e?IHo^)8npTd%A6h?^;Kg{ zSo!UR6Fs;xMH;FBzL`X#6EeEaS-#NH7T%;7pvXWj1uPbh|15c>54uYnx-Oow{=zYf zPYeKiSo}`p7;Yys>et3w@h40)E1Z(=PKN+wOh8wpr0IaR1^enUZ#YDW1gddOL;F0_ zrh7?XHFTYHK1lrECyqmYLYQA^wnS_&^><3PT&AT1b3efss<5)Gz$^G(^JTqJ>(XB!IxmX1wEMAl9&WpQl(fm+A0zuP z#8^fq2~Z>C!Q&0P!Q)u>?Dqt}uhPPfT_#;JS<@e!=$pW^oVOM2G!l+2$LjBo>yPnW z&tMT~#9jQ?aO}8y%qW|)swEBmb_O6BC!SbhddN)lTNNae>LNz*#4q3n7Axw5wolz= zo67CSwpwvbFIvmx<#|D)F0`Ao)&KlVdbgt{ zzpW7$u=z5uDKpL!s=4EgmNbEPI?_Y)DynJ85-R`-T$)!+9}?=D6E#+Gr9yoNb^YHl z7)dZ)!J`f!H1fp^cX26=hmQ8WDswIBIxIB9YA+fL8 zus;$hKUH_yUE_U0BPrzUc=Ei&v*67)oTKJoh?(7~g}J(i)p?8;_Uk0Mr~f2M(Y08+ zF&nrnjkpH%;Mib*3nQ>KMr1Z5v7_L&LpfCY9d(craa7sZblTy%1Xe3VaW*P3x}Yu- z|8b?!&#h;`H~fPs5ZC8N%@?Gjhm2=D*&y)B-%JT9bn!2tG{B{OobbhZyr*Z>Je6V$ z<(=-XztV^Sn00n2Ar7Z9+j!-j$uh?9nTA@eF>i9W?H8=r}*W z*iD7#9p85me?UbE4c7%RM_JQHu`hKHYZA+j$E!Vy65uaqG_i2VYuR`ydUn`BxZx=u z%g*(0iBz24Ryp~OD+p6|4Ab=bXgb%*V9;-az}=6D5_QlG0vEUxle$y!nltR(ew^{|}~lZ~r$;&2fPTSglMLu-x_IHDQI35Pv-${Jjm{ zSE*EZnyHfS&Pw)zxZC?`lpmgnemM(6xh`7%cdnTAgk1$oRdlaY0tZ22!m%RE3zP+S zNZxWC#uSqX3}Lw^_89OOMg>#$CHT}jsaVrgt?XADLmBeqo!pPG-tC zC*94dP)GrIav{vK%M>IFB@i3(ilgLnpMpZ_9$>DyM7NUvu;RdEz7}R7#unoCcpV8@5)vcGx0UaJ?qL57DQ@jg@dutIv>$@2ELve&>k z!(92o@M2NEUsdUKhpF=#~u#Lc3Rj><c5&Jey2)wq=ay?iq_!cckW(*pc!h*sch2Jer{9c3v5O)LasDa-wRifisRNMIxXD=0wpBsXV;yrf&79o`F#gBmW2h zld%4bQhIxl{NtDJmNj2UfuMqegXF=s!1Qo1*CV~|2M@jQ8|(-TeAWcvxg1oqYsn=^ zgIFKm3upaOAGiq=(vxWHBQIaGT(iXT2&y4N@LSXhznQ6tNOy}xvK$m-7=KpH%<*qI z;9C+7KX0^2xh&6&8q5blRBTK6D)D3GvEP}IqeC4!%^6sNDnX|qB{X=* z92u+1>Z2zA*)RzVCn)aaPRhTk%+hWq*g4;5a4C~sD@R}j7r2(#==}7;vSm7@V7=4e zqL!Z7WsOI=ZC|<6k?^`@2hegR(QMIIm~&C>_r33RZa99PJCLM+l9kB%Ba%_wp!<}X zd++X%vwugmnC1jtq!XyNPZl@o6rgBh5*+e--sY??{NVL}f?v%be4sN1@Que$wN`HJ z6Tb8hD@v#Wv2BomqVe5WF{(F7P^^NTXH^ebUG+Lbw$Np}7iI%qUd)uCy%0b_g34YB zd5s)1`=PXJt^ z=ED)U8}PQEcyp@ZAP)wu&&V9m=u?0HHpf)FMW^SWwG%rRzLSJrvXV9k(GI#0HCuCU znES>WH?NBa;`P^#z`=>X1(V>8oG#qM{`Ty{d(#{Wq#YdrZi3_)Xy3i}F40OA@mN3ZcqqC)Pjc0f*GH9ePS!(1TUzkzV-^&iwJANPX%4 zFFM5#T`BoDllZr3J35O9_J35_^9G%Y`f%uE>^|DC#$QA|PHKl-57XUkk>$reBC|Wp zHq<0Z_g#Oe{W>UnuK(V1BcFP`8`{i3I?yy)NhTRX6*#+lSfIp;q{M;cDLCV^)PB^I}CTxtP5N98S!h7o0K(W$Lz{N9U zjnt4`E`8gk4_63J7Mb8nP}e&iujQOf6seplH%S3ptQecZh#$|ky+(-lp&;ve^7Rij z#UJ$-E^8P733B<$Ud@-+G%{XB^at=kDVJ4ec5N00O%Bz(6zjAr-BX=4F#z%1}s46V?4l--rGC%KfPN zh8HNg|GJnM@VK-i`8Cpsnojings4~rL%V_k4=S0J4MFP4-YQgg2I9>M87Q{hdu?2T zZSHFhpn;G)l2z5a0MfKhoWQAU%xJ-loOMXuTM-)dRiUYvopD--#h&`k9Gb^6r4i^G z>&8zFGSBb!KGjsTBh2wFW%`Uvb1jRNRWzL>JAcsxGj0#exB93V5x5DG<~GGv=_SH< z+TDLDKEM8x?g1i_s6EX!m;Pf^T>uz9qpb^GDKjO4$IOW= zJCNrTlfs`Q8Rv`pVw3OXR#x#zU1rX3NJaaTxYe@s)iT{0?Z)4Q& z#*TNIAoi*0!uKMNK-|Swef4?IDJ%m+CLN$%BAMc=dF8)WLZ*6+`jNGBv{g@nsDb>{ zu(#_@R#!1jVE;m3c|)WZct#Rb7f1i%Gn@M#hG7UVz5G}C(r7|o0Jd?j&pL*29{1W^ zAur5M?OHfZ?WU;sd0p&}7wsfbFjuzahoMcu%+9N!00~ao0Ed=ftaTM#FnrFswbu)r z&<#-mp@3KFSMRC7YbdeGf6@&>$4m@Fz4-B1+tR#{1RS)H;!J6|cC+^blKL#1X&8l| zsnRz=%)>E%?oLSUbF-#Jei8kVYBSIK4VQ|}C!B7^We_&#}T$(hzs+p>s zKIOgxarcHtrr=xzvy^?xNjPR$2BLt7f(PRmnD#yAR3oe{kozRyeeaapTvWF8<|8=! z$UMI)Qk8pLk%pT48+@mjU;l$~|J7mj=ky;cpg&E1(VG-OC7B|6lNc)d-|(UH-}V8F zP#S>l$po^Xow5BPi9#xVX>>OB#S!osr$1o1>((HwFG*THjrqTOCBbC=?Bsy}j+bDBHaH-dOYnCPZ)3(e`g}>ndOOnf&4_+Q_?(y*(8b-h zNt|YTrri|?u4Y&QOz@3B-hXD2?7xDWK~vDvB^}J%@*gBY)L!)|xTCbhGwp@f)!fs@ zpv$T&M`gk~D{;jg=YdG}=SOx|RYY<@JG8^t#Q0%t?WQ1&9bZe5sL5PL@x*>(afN8=!rO8I)2`40MSO*!_4P1KD= z52sY7^83m9?9fa$xpYT9C@)*0f!IDaM8=lG>R`ufd+5^=kXlKj#%)g3w)y zc<*FvM@fizyT^m9&rsxOm6~&688| zM)s!$v(QBrxPcgYtg!;91VSY5AjP7)JC_;^zP<+ z*Y?0NrX;oRUA1N0S$R`G{pn*gJUv*pP};kp$KZlwTtFRH-1t%eJ7qev0e4};x?r`s&SZgsy~sE&p_mLn zUCZ*KVMgb1rSyv*5I863tRpR0{~@{p!qr8Wr>SfHiy_Ep&Su6|w$+n<F6(r)CxY+h_m7Iv&%9gre%rj zE_t~^FXLHW=9~plEhO*b!b9amDa>-C$r*%1)*Aw-UC&+rW8LPRtrykZ-&G;Zm#9Jr ze8WObP6c{Ijr{C4%Hcm5u}f3>_3nAf-!>BMIk(0xc~&L-$ifdBsRkK2lXo7AcYWEt zstCd?phfyKWPdDf-F-srProiQnEwapAYlTTuev{u#EZXR=?`$k!~XA1 zg!@$4Kbo5mJ3)iEVt%|=n+vS66lYqv%_+kB9TPTA*L^X;_o=c!?YsYPzd;2Fz>KB) zl~HkHdA6IJH{;(AJ)a};lH*SG$hY7NXApZ@H>S+C=aTK}eXgLyMG|EyQoU}++x{pd zFM9#ybnydJ=v_k;Ak&~oFaOocKJG4`XV*fLh``DtAFH=whe{nZGckudO^+k8>{(F( z#!AO_@_)*&JpV&80?84N7MCoB2}qtEjEJl|cOBUyJ#K8}vxUOP4&!!wMbzU|WVuWn zBTzkp0sXqxEFMbD$h=PD@ec?1(wFRWFZTOTP(S&ikWrIAPFtwaWFmrYp$64^6S4Js zM5W~?i_qRTrR zavTWVFv@%~tm~YOJC8#}{J=nxN}>I=b1avkKOqDlSKr#8IP2YGPLGUIV>+VBFGUJ$#q0!F7MG9_Akyqxdp7P^~fJB_ZawS{PB^a|0|M-h63D{ z4w zhcr8S%@eCW;SjQH&(8!ixN?Nsl=~${w>J9P*Qep-FJdg8y#IPPAQ$T&f!Axu6{b_SOtp8}L>O02! ztEq~;4be+@pXP@DxcpBNh@3#$Mvmxb`k-4(0*TT&;%bI=o{eD9Fp+VDzkvOGCXr85 z#74r9-X}|4Fdcit%|7C|^R5r!= z736$?ALb*3evW<`L(}MLXY&ZmZyhJj(MZ$;3B!rKyMic@$Bl@5Qg-H}CVscv4zVyX zEE0UJ)7oO}ofM*W}-~}$dbgENXJ3e9O`N_M}6(eWFaB48!zQ~Yo1rB&u?PEBdj#1>= zbA6$Y>3eP+nN3+P@vQkxHpTmH-)9f`C7>G7|E7_+58}B6R#d~~T-Ro$p5{YId?U*H z+wL7RIq(h3zOioRBkG+0)5w*8L%F^2sT7mKrwu8Yp-36SSi)Fp8Y5&$T4ZTxh(WR> zW^9ouW39+msLWNCtQE>$7c-W0WhsTEXl%)tZ1;>?_ul_~{@vR=^UO2n`M&d>Gw;0L zd(L@(@9(_=yE1)XSX#@nPXV{uuE9^)eSl>NCOTh{yesfJ^SAhslK0QinMGXAug=}4 zTvyFu!N#Ju8YD3@N0T$)Rs1f2@j0-UL_@42L!J^&=u;4vo7g1fz7E+NF!q?V`3HH( zZ|rd&v=;IW&E4S+dp^D!)UX{jJC~togC8zW^#;H;cWk*f+MO6X8hLu^1&J4L)2KfcHyK`@NM?TM&UajP8p zs+p1b9&F~+yNZ|xP4SaPSedK7#BhR@Z0(19VK)xVE1>5*eWTL@&03+XMh1TS zdenoO!_et1(ry!^J6DThwqY%p^|aVx81lK8qFaM5@V_g?&?-{3rUTPu`DZxZ6yBuP2q*wY^6(;W3l0^QFe zMRcDX^+kz}dNJm>XQ^LCp>{`+cE?CU= zx=@~Vp1T(ok=y@Swk}$=u}NTKH_~oM9sS~(7kSK`S{`A{0h3a zYSgNCe43JcTX=iULKvQxc2qk4aKlu;yMXCKwsA}yP4;7xuuz_jR-w{!_U^&Gm72Pf zl%_IMDXmz-^HE3KKqk^~Sei#1b4$aDXQb_!aHh<~aqO_;&8-U$gmk?#7ddwKv}YQN zI8y8~)Dqwd++DT`z^}i7uirPVOVqSR)OUFG&oIefd^L21+TYn}>p%d6w`Y}>!LLdG zS9)6f`UI%&rO&O0GahO7jnQ9sZ!pB-baiDi?D6-_SWsJom_wbSL*12g`8F-I_MtK> z5`X+14OR6`O>=~BrhT2pPMtfNqfItXZ>+5!oiDu{V5|M+tk)(a(KH=?8wZQ`r|m{( zF1Yr0C0%HV|5#fd524;fX@)@m0ueK5FM3x7ubnPgERd@-+Q4}Q;v)~vpF?L-eby}_ z3`-Mn4S9>nH&#h{a05y?e^)=~z&!orA7uKtR$;EajZ9sTNM8GiZzG*45+VWXY`N=0FbU)Jx z+fbAJuDfq{d7upU$%b(wrz8A{SzpIOp+}2clLgWKBWUcZTq;$HGZL%wn#Jz|O(`)O zJ&bOdv`__B8?@;2LNcAIwW_VQm@U4;E3K{rzz<2|dlKXb1?L;lLlhljFSeBI4yxi` zbD;0eR#C#;*ewf^>e1u6Qtnx9Ql9Q(!oB)E(rBXGkNqOCjtN2!|WTgcUPc6YGJ@dF?9O&W}TNaA6ZWaL!LfBku_7qJISkr+>C|E z#+-bul;M2SX#hy4^RtB8R!z(hZt6UHq8M8vRqL$fb2283(Blg7vxBKv0@R-ub2 z;BgN6^F8XfDSRUJo!rTFuu+-tM1O)G`@?DoS)(ATbrHJNiCg^&7;^4^fYf9>?kYM( z_X5tj)c+L0FM%z3vH68l$JPhD4!gg=#;7w!jC9^*##WVee=+>0se7`m8%S7_ddvP^j958kiOPJ|XUCPZ0HsvwGe zpA?Wr%cq}IQTK?oF`5@h_2XLMx{BB@m(v=WXx_d!5U7Yb^>7!O*s$PUjr^W7`#fdx#cqsrNli@xZqX6->u25GtNqBY!zEkQ^L}p#fE}y&X58n{KF>w`|tNP$0uFgxpd6W zy_a%B6gXu6Xt}P#HlN$EeA(yIaejA?-Cc?YfK7{WlF8@K$zEd}2(j?nryZ%+i+tJ& z6fm!Q4>Tr)1<8S>IILsz7ZL2kdKjij?VEGB!+N=k=dTfVcoF#AV)ik>U&Xr0duv`L+7lOlj#0#vhT%J^deuUILx2VUhB zVUxPvc3Apk@ht@$T_B(ENeoXX4pgvo=XNixDD!TTIPSK!)_Mn0;7WEWuuo*4T0vm? zZ~w>i(~?-SzG-QVv~$@200o9pGdnguA9BbwO%XM&Q+#OSvKfKO%Kfm^+?R`|hIFD4 z@K7asvhkJ)hDlZMWH2&$ozUBAnoMRZBEZsT!gfvprEs=hovF8Dv9HgR!0*4fwvEh)!WWWGHwfc@0q60kiZu zWrAFu4jIYc%c92M=U(y(Kh%xCR#)xs%Yax+W}y}ZS*l33n>eB3j8jo*r|n*6z0C#J zN+Xf7pnZZkAghhZ#AI?@S4H`CCnY7}`Jy`e>{f#c5}?+^-^MF+Nydk*zz|s}u(!g) zyIRgmKtf<<^h7*`FIdW?9Wxdr&YM_pn=_CO3RUPMU2tHQ&UK;~1cecXssyMCP1YHA z)CHOFmJOtz9P=>PrH`zclqle9QN4fXLvz8_&%DDd?Yf{M8rsG{Lp5=CIcu95Jb$AeP(8_wH(W;cbqIQaqQt6*O>hZ^e(qKw(Rfr#>u+pNokHS%vNR zlrY=f<|JfK271-*@!1e>uFttlYNsmO=WJmo2Td3R#d{0;=hrU%vE!h zil;egV`LFJEVaFv+U2~+e=TJAr9lUFC0=swaZZ}n3j@tdALW%sV?R<%jobT`)>2nS2}zyxOr!2DCw&87#s)t~ z+O?41e&2^E#xj{7TSDpENM|lTcUU-+8#@26o@-pi=|r!i|LP9%TO3Twq|XalVR@Fx zKB)Q5k@?G6Gs-HAs|Bp1zrAt?83!99@uiP&SI{5uMLdUH+*~1oHa`+f6u-A4prSDS zoqs(yufXi?o4{n1Af~`;<`dQOedc;Kkc?*0-TPNpT8mHAe2=`Ys2q>FNgzir7C924@<1*cKp@l{PHC23+OkkXxP2 zb|sx{s3?uTq(1ju(d2bPFHeU zQ9sW5(i;o;@JMDb;kkv`#g%w#8Y&Hx&y_3-ih07<)&ZcXH?QSJ*Q&+LcP--Xbz_&6 zQNwy8up71Bnkyq{HT@bkF#Q#QA$u(c7BFT1HyZplo8@c^`MQ8m_qN7!{(?l9;pHS7 zpW)VcWy$zA7W$3L#8+GtHz zoH<_GBaS#F&5sAe4nCSn@x)rZCmqV?eGMBliQ0Vq#zN&(FMp?KuI4L=uXh{ub}YCipD2w#5j6ZubVLD>v*8vV~0=-EN(w3ZT&1wIc~oi z*e${0SjFR6JCUr)E^Nwig1?Vgsl;}DjAdP~d$e@ZDuotr4yGt81_t#K0wYKeFG#SS z?9Ul+4g?IbL85=pT8e6zAY{#QLOEz}KU%WITBq!DD+!FKl#*6rER;vpYS1}?!-WX= zvgIjVq&>#9B*K%8YVYRBH)7@D*pqcwrXW}(b0nuaFwCtI1>TEH($UzlBJQ7%bVCJ7 zTdPU-?Shr!x5RssVrS}&Ty{KcrTQMF&*aTu-87n$x{PaTr_zj)fR{fXVe=?i7&8+lXIYeXAj`BJ9@ z<@7TZ?F7(Duqclvw`Lh}+{ z$($mQMW{pz)fxNhzVa>VCyz98$;M<|-o1mvP4C{eAgwK8iXhiNQH zURt1NA6KJ9PejDb^GL&FTONY8RU(x&skjf$qoj#3L=^bR$^#Fs4vAfD2pi}EUTfvu zBD+<7AOZ7Ni5~F5ns4T7JuoPKK#lUj5-)N8Yw2A{SBcBK!8W=qb8A6R3RX9!?|VYz z(QEz`>1_+cE<#QeI-TOrOkM=l+jI!p#Q5K`&T=ex@4YM=G#{p>l_(&?(W;^sdv^;a zkN*C`o#QisuB6}%Ckb9_RkJ*?>=3)SOS3I?F9J$E*|fu3G3gp|NZmWvmcpU5@rQ*Xl;-@5&EZ1&E`=`w}_My7F42QG}JV&S|4)x4d{ceaHj z?n0ffuzU#)5U6<}lT_x=k@vP|N;w0TR&{l}v}`P4F}{;%@uSYv?Lgq!zE-XQ=s#%6 z;+9mM8{%N+*Y5`zRQ$RQCzJCz!qb^OQz|uw%9*C%D=$$gWc;)LncYmfKpkbIfwv-6 zcTpa7huv|=iErl9f;-+%I1@Z208Q6lzkiL2^3zIY;9)f&0(c59D>xAB8TU|anGPAr zIA~IlA8V)b$sy4|-$<88=fIe#?J*ZsaqfjL%4qMSmx9359h!Jarl&c0w!Iptc)44_ z;)||s+9KIxS?>#H^+@<7o`oF1R+W^thj-@;V&=TnI1gc2a|fue$|xre;7Km2d;ZcuwO6xsYy zb%OxKZsu@?#?jqqE(#g5_Pte4kh>nRb>V@BrYz+e+-lT)wVQrW^V08Ky20@}F$#` zh+h44S0bRqTm+nwW-kJq;b$ zu4)|5WdY&Hu7IdCQPT2NVRY_dYf|>cyRG$=6g+^UaoHnhyeS4SV0sM$ij#i>*S%&ZHo;TRo#j1DxP+ z^s1Slqtm9q5i~H^`&E9WAemcZObNE~twECudPp{^=rM}!lS%NdlW#-wkpUUn-a*F+t@K&~$6N8VKHMNQgzstQ+6KY*ur zIM|7_?0ZdRrd|~n$Qd~zxnCA>1umm^8YcO+UfQE7Q_UWJyU z*`c@IuCu6K;XxKxM#ByQ>!ZXjJxrQ#V9fMZV<%UQ3oEQzb$Hy@&B8xe?uSX`7 zPNJE&$Y{2};$?jchK7uB?EzV{LtI}#69EI+vDi`R_hg-v+OMj7&3}+z_Nqjn%j9J2 zLJR$E49brvN%M%^CuqqcVpv6QPlieRHE}Wyi(o!!=%WnFJl?d?w`v^Q^j=)6Bu{|! zRX5M)CFRKm3{dUul9-X}G*26mHMjB`+MT52O*;qD&!s?gR#JS%X8KY_WcX2){MV=t zerWbZX|$Z|y0DV1@GnibDv4$Y+h4?ZJ&pdT!oPK=E#Y=j+%Cli|Kupe;N+-*OSdTu z{?hvFp?`0tRiMKYBuqm{HtKe}--R)Jv#@fUaXdz|z|Ly;WTuO#@>B-CQ=o6V5H@4q z==sYi4E>y=W5{a_nQ(SOdLS9iI`v^w`H#1@;U{u1v{0$S@oz^`2s3 zH38>PJRI38tZbH7z4}QI6cTTK`EQnQ!AD*sugXFjP;=_!!mFs>9PhM-#7fr3uRk z_b)EG77C#mkF@JQ-@U^i3SP|fVBea%McP!x4S&*WLG{)7;15nHdN(VoryO;v6&NLi zXV(bRi}9mGew=jBdr3!Sc1D9hBS0cgP<2nys;FxZKIBo!PKR0g?Kl{N0XF%QyNFe5%{C9(5$2U z3l|t}A)H3m*5?`xr*uth8Wblel8}lf#`5f_FxUrPwe`3Pr;gE5VV+0#p^#-}CFFKlS7JDtO2Iqi8enYP797n3p>4@%EtR48?` z)5EGuBA~UwZfNRP1N2->6^r` zoNi%wcp0{CJ+{00#_N4xD2&Rqj&&rpm)YR@U$4Kvb}F87&Xhs*H}JD zKN`~)-L}lB!xO1G_|>^rOxW?t$f98uEG-hc{Nwf@i*P#Tb#i=?TKW-k#giF4@x~lC zz#!v^+ye&|A=NKr;DxuT-{}uNs>r8EciwNsKpM4uO^50UeaMLL}d=3fD zf%%!%^$i82n22>}%3K>Lc>r7O<7^d?G*1z&`-}*GR<^T3f1+eSD}J(xupv99On{tV zH%g$>s5M*jXl9Lg&!k5sJ>;rLO|}fi9l=&%xUZ<=$G#tDLs_00Ry}4v_EaEX^aq$% zCS+FP^O0SlHS=TDo+ck&?WHx#yT~zsa|IF+a)4>GVYQ(ggMM#eb1B4UmF{AW=$1nW z*e(cgzc1e24x_LBK~a9f)}Mj=*X%!WE#xQ1bGzlSV`y04AWjWn*`5LwY^*)})vps44-S&LdHG(Td>XcI+dA_kMZ#jeK3&PRn!J_$2o41!j8 zKSc{6R@{fUQKKnd4k@LW=*TBZ6z`dILT~jmbh<4HP?`Bj6_Bo~PA+qWU0&f1!mgx1 z&_goA27*==Ik9T`+vT*5)Gj`TxFK0H|GKd!acn_?ewpijXdwnoqke7(ygs-2dXly{ z8}?dLO@K%-zPqT&?sT19)7M(>bQYu@$}4tpYD|N>GC!y+Shg=AlUVGdJRNE13_H_; zX(LQk1}|1nMgh4O#AO55jadMheb>(n0u*r2I(|y%nzX}BaM|fig7v7tDhU^##J95= zOqZlL+KufOW!7i>O{4#`Mk85T6>Y{J2%oEITnKq2um*vj5XSye6G2-*g4(HXx+^6w?wVmt{vmW}FB zk}v)cF)*;NWYp_Y9Lt#3Ud;mXSl;uv$GL9hK;8+nEu<{5wrZVXQnMRzVoyqhWWkWA z4NZgSaRkkKtqWZM2M7&BK6JzZmkqoofm1EaOjmAbM{ZVfR!+Xj3luG$7O>N^fN+4( zT8X!pS8qh4ByDaa{s{Uy@E-B;i*VxJ;Q)C0iBSJe-G6EQ{FGcKVD;i+QNyuvCFkPD1qMM+ zEfcUqbTNaw<#K)kO32I1mY^N2sf~hX%o?13vC={5Cy!XZ*dW@S|Cn%!4}hIjzm%-w zg4QG-{2~jAm-7MUz5LpCuSJ6QVvfk2rJ$b2!%@w?5H%Zc(ayL8-kOr^nXB&7wOx47 zmUm%9`_aC|(zZ1cig;nG<9&9_ABay*FXx&o+?WwT-vflCb7?Quy(p&pOvr|6&{j=K zRPDH0uyop8vRb-#-O`*p65}e*)5{5$=~de5>O5bO5A-YvxCAOf?rBZ_4ubfwZ7V7U zi4YEL^j2@RC8w*ANnn<1E+a|M5wbT6wwSe)sM&aZd~|t75Fp$anzEFj%$|HXHG(%& zJzbEk4kTiOPJz2TwXpR#vnSPAw76{ccIZhK=m!>d9Q*wJ;>M3bnRE@gmS!X5M9n#L zcud?AyC=MKfAzu}MK|Irz9oO5x!8UaNu-HNT!wg_*8oMKEX3RW)5+Anb2}*@Dg_A0 zaeuEWgP`Z*#^;4V4b^*$39)*BoWWmJ0g@!(*0gB1G8#GLNGKE!T`rTbz9V~*7=y!E zQjm{6JQYi+NEHn{p5DPNr=|-3%zlq8ZK&KJ&EyLB`+ri zvoWt5?%brr=r5WPb3=H^!L}rJG3dRu;^Un3WLq=()GV0nai_+KZ9*6WBIWtu%=3J_ z$C0%+2dk4G^-b9yis5z~M@P%V3uH@HAcHF$gSq~>uzd);h1uo?HNOCp{!J8FMb*l7 zVxFvkXG~RJPcj_1WoCzGGj%;0XGs-BWEDf z*k9V&aiQ?UraT64(qqPtO7z;a7w2R8}>IIJQo&n0kYa&y*` z_?%5=?_0bJ4zpq?AzK?;;q$}O;ny1FuFblww+v}JD{5q-Hx@QDX`{AU4~)5wL=*W$ zj2}7(zbE~~fUv>#zkz7X>Xqr=wzXM5Pk7>JQHzOOGQH&rCYWGBeg$9cSvGbPOo>a~ zNPuX!GJ{qDfCm`M$12O-4kMPyuB2}cbx%0zyWK>E!%?XC9O9-^n3Wdl^In*6S(jG+ z!USelZTaMy2x#^Dcpb@*kja!H&V|v|G9jb4o;eTo(>G@ zi}3&#uFtD4?VZ`8JhsbGdQXeo&HSu(1lTQmrhqk$3o6@@S+KV-Y%#Kw1TX@%n0Tp9 z^kFz8qX9RC2rnPuB0xOH)~1eT)UE>XT%S712jBM4{#D=~{Vwo>pkHeI@!wfDZvyy? zVeD4mUb?)J2;nV*zS=qR+8^&4qJwgPe@HR~wf+KB;)Gw@Z{=#D1_=Pl^cOk+ZLB{j z{=XVpf5AtPJLIq4*Po#Mi#WyqtoQ$eLj7LwiS6&rvA^yGLOl9ADE-+z`?X*M$cO)I zwEg+8|IXJ^{_zUGI&r@rru?&m@lOQ&*TZxHsev2+Zv+Qk^S{)4wt&?CK+}H<{_h6h ze=aal`!DzUA8G$DX$kM~U^Irca;|TwMGS2(|OXCa{XOfA2-#_0J#ku4g_kAz- zzK=LrqSRy)ful4k*LI=e5Xeu`2JC)D0H6&Zl0U#A05(L3cH>05)l5EV2yd6gO(dDM z`Uyx2Po{+UuiMJ@3ZDz02@QA$^Sh=ccNzU~tFkh;GX3-sXxI5YxXndN^)z(3t2;C) zDZ<#>ftQgJ%mHUtO)5rREODtHX9kjaOCZomrAs$C;0?WgpI~Lrbdq)*?;$BT;Act< z?2$kEWHoj*a$#NSM(Cl2e%*qd1OB2?mb3P3>#UGUT3b;ubLw~xc*RAvL=m2GZKQC? zmx18g=q)#^3L+E$P9zKU!Cs=KC&j{iA{ko96t8Zn;Ne`u!L*1FfogV2P?wcc z-BbYMoscI^->$(!uQPmM6Fu9wU!h}s`mHvbQP#(iAO8)(N$r}QP1`|#x3FNThQTg&>Dilvn;Xi`xzb7R&^uDd^apvq9X0!oURWFf+2O`7=4K-GXIK}ud($de- y2l@ASvw>bA*gzBAgdj`&CK$+s4FpWRxzXW$yJ-AxEx>NcDAT9I`3L+8#4G2g_LZnNPF2w?f0s^6g7O@1RDoF2w zlmLkmI?@azbcE1b-bT+k_niCg{l53}eS5K4du3(SImaAh?L5=h)jE3U^dS%kbX5DA z#w`#CED8J>9s~m=Z_~(~AkcZTwuZWa55sJCF*{ftq*kAIa82l1Owv{6sVDsRy$P&# zBNt}ISiA2O$$_j)as4*Fj3C_O`2Zz&H|2SXUOY1h30A|P|MBm$+xG%N2uL11#jlA) zX=6afMXsW~kqzQ(4^Fw98!^8pFqprO`u2P@FIZUFJ&|cuB+J-N!R`y-&JqEiSFO&?kDl??{&2Fv6rK6)FeHw6jQv z2e017f_c?Pr2WHRSoa6yoTq=Uc1_>U!m>lz@q9(yY`4XG>+r`NZE3BXDtwg8j(ede znD{(~S@W3GbW}KkvXs*5sp7mL^YzEMC_Rm#B|F%Tq8+Rs&M)}2NEx%lPG2~W7%2`2 z2Nkv2(p-l9+HF7I?%R4_S(dRLQ4Q0?XC!hcCZ-X+*2Mfq(8r>I43Nl`EpF2UZiRGEt828(^IR}sJu%>eQ8~pb<4%DyDdr@ z`5S8tu8&MXtlwFhxAG)(VKK{^0($&`*Fs72xqme4@Vz7*a_rq95KkRk8bc}cg?$TS z7jf0(5&)y!AHgq=#jwd43G;=rVP4^oi?-kHMeM7WqamNP3+wUg#yDmzAZheZ#d-NC zn~B$hjLMK{^H8{^m)E|huRJPktuGS=(2}+`)hG9TQrL$pi08awPDCFxR!cnmIgumw zSx#dmwbh`e%`n#SAh+%(U}Ftqo_%?J9CJ2_53+qGNtE6iNvqiz6MX-!h$Id6Q^Mk zBLQ{E@SnBc^V8wy4FYs2AjJ8qM1E|CZQ)Lsz}Y(X8@N^vzn$i*BQM~j<@GCD%9xlb zO&{3L*SL6^>!g8|bnf+#mtXPnu$z$Q1xS*u5Lvw{86JN0=%lAlh8X$f2}cgDE{&8{ z+pXr-M&WHfEDPuJp{h}wUZj@ZEQ@*4+u;$nP%wFlA8Mw?60a$m3^$e)>dI7uF;6gI zJPYs0X!FCx_-ZRs4%}aQDcd}8dfNY+weMEF1$P_+(^CdEXUCvQ_=#=BYd?jOG|qxS zsk9*$BfARsx?%%3?3h`6m!UVWWW{ zTv1?yhlXMHH3mh=!y4FxJ0&*iu5FzPBR=&9?qd%u2b%T{?sUV`o{uq^XIrXbFX{{S z!qO6F_;@S5TY1aXp`CT&iwT{psWY&Z(i9i)${WO|(nhQ)$!6dTUYv z<=ZPP4D{W>feL#~PwbN{*5J}CGPRbgalP=X>#=MEQ+o4gV$Z=OdG)4D&kOgn&gRrA zEe{G|o(cP{O-h}7e^Nsrq{xb8T!~#Xs_b*DG{rZ!dTUqI%|GfBh%RpM6Mu>$wQNyd02lJZtRwkiJWVEXmjT}6BN&P<#tSZ1e?am@>iP>W zU9D&}jj|9J<40L0%>|ycX7^WjvcryOeu?m_JAMXXaFLjz0iJLoP<4EVQ1N2oHGqNo zU*3NT9^(XMvpZyBXLj4-W$u-4+*!7o%vLHsB=8robjn$iBw$$XPYI3j%=~sbcU;mA zO|vCkstySnW@{8}T61iR0#*VvAQtn7H3OPK`Y{ChPcY`0%&-UFMLu8K{tZ z<4WDEHnW>-%!wsQ2#4*#r`Mw%Nb%p4zYNhqCUZTzhkoMr?c&Ol>EInc0U-rx_LFG! zgs)qk{5+zT*^(bav)f?JvpvzmJ!yp_&0=}+f_&--g;%%c;WpFHCJ9HXg0IW{cm@?? zDS2}3&d`Y$_nE9#2s63koJ^~^ zL`IuEzVFQ8GdsFKQUXQc&ziZ2`!frwEbC;(+Ye8k>H*2|$Wui>_Df@FgvK&^hm&bv zU^xkILV9nWyVVuy8L5&&ndnh2c!}Terd2KFkgCciMOs>(miNG{0s>z>A@FIR_8!vT z@Hu-f7{eC%NiDKyG=-zuEL+lAR3Xs4WK;I+`CO9H&FGpnW{fn0IOmW?h{k*@=x9Hr zRxf8XUy}%=q#Fu$UfgG<;a#oBbsV5iLdmxA;`Z!K(-Razd5ftoDV)oZM_u zNH*GKoC;n2cw^7BT!&ZK}p zDxq8a$d|7ZMM<+yi$5@}TW589m#MP^3MAAdDV^Oi?C`8)V0>L4r+br4L{M^LXUE0Z z^}b_G8JEJ%5rsvu8O@taZ>cZ8!{9K^oR_u{uLUDsUqG;F-bCAir(0GJUil(0yos15 z;-reZWmvq#Dy(5{0TADOo48XkR}-&BLRV0TC6>rQ%-aW5b1&xq|c7UhJOJaT-9K9E|r%xYz}60xc3IJFO!!|fnnsX?x| z5azn^$~oTl4#>KT_g39SD$oX@;#}q<3qsoXTlM4PbM7Thd@>jBH}sExe>YQCHqE|B zf6&=EBV6N^l~(qIZ*VO>W|ZlL0dlyCz4)rF1QP6Zc8;Dda1c>`vbv27+n=?LXUq51LtBHv=o)cwLA z+CrVKm$(wsJGLIMBtCKzE@%nG6fc7@B8pwuEseV(t#`BZRql1EVklQQ7>xDnlP!as z_C_F3#(0^(_JyK$7S25iP9fTVfEnn>TjAm zFn=vk&iIJs^ane-?Euqfj&@GVH|G6lg{KLm#QIyo-)_X&Lk`|$`oxgZIYbW}EVp(jw0`~x9Z#CHWfPP!)mLr`34Yf6zAK85# znKZ&lR33-S4dC_YQkw!_=T8Pl#zR$4#~`y&DUl|qDtpsxZ3*XbDfi1kr68v%Dm=_S zvGnXhDV#KxLE@B)O#KdgU)Kl))S646=7PWoVZX4A`0`IG<%K|ZckqhQg zyux~7xAQI%Bv{y4jf5e=urJc3*KZwdnOX30Y7!_l+F0bKK+}hHkzhF@tT=Isy{!u? z4pZf=K!N+LFh4|X%e$z?<^FcQKfQQF#i)yI3nE0~ph?u5wDF570;P_LLo!hOwdLNP z#Tp}Gcg4iZwyuG(8Px)^(|-IXuA`?=l<;0 zIo*LyDaX5|=MtL9^8?=j{PpZtpUc4X3zJ|RVNNwS*QDDqc&S7BIEspOxz?cv2Rbc& z6xpQB1ZHX9b+mjstW08bRQ2Z5d#l`Ig-PJnH1;3KB4ZW|fX*VG?+#&iWR4_4y<&AQ zAqZSTq(v>ICOq4f4Z-0UuFb0=lJWLjui(B9%=5=2Zl~ZUaWT=JvNaFje zcMUz-DQDQX?Cpd|a%z~L3&DVqBf*om_(A$Ow_nCQUYfVHG|`qQR_n|S+We>S_bKhE zu{}2cT;osg2#(y#O~vKx%(r+>!UruMx>pvGqGKx^EWW)*xhHw8E%mSYd?uaa>Ak5d zM_uX3|Jm8**%B9m(!neVy<{D<7d9WzRrHGp?Rr!(dn1fQ92eJ={c%tL&qr{;J{X9; zgX1z$)S-p^s0@(aRb}jxLPiMBd-_Zx@f(>~Z54}+z(t2UQSM2rq)#Ku$_W3_U5?Ro zdrl{jB5%!Srg?;C+VJ^7dYiojp*SEh^tckuvgsO1pQi z6&1r4`p33opdJ)<;m2(!tR;~Lb*4| zf-f^bmDi&3`Il=?!zG@ z_*WG8(L4X;O056`2&upf!lQ-V89jnkyWeTqa705(8Dwr?mT*v44D4(SZa`^X zL$Y?w#i9}SP*zOWcDTKP;uL%XfukS}Et21IWZiC5+kbBxa?Awhb%QW8^1gK|6|$(r z00LIyjryX|I}qBwcX8L?M5tZQw`+!cEJbdMPkc^_J78`~ z?G*~t7lf3d6l&IG?4OOKqibdDoqTnZg_O(V%wTlX(J%SQ`!ZX&g-9C+{z-k@?&$hb zgzk5C&3iVi@)<*hDqPfbZA{>5yx8pg!!co11iy?rCi{ZCQkBwYG_iOMF8`4;nz4JJ zQ0coKsb=`3lGz+>r=Bd!NcNt!xFMmUk0V?9azs-@l)|QjQ0a$}6=mfkQ8LPDun^eX z=OqIVHy#nhGJm>L5W(O_3Dk~CrWlooeQS?2OVUZ??&3+t48f3Wv@m<$ThdEC?X(Q| z1jT0fHh1n%d|Kk-_E^c z4Nk+JI%U~6H{X=Fwn>>2GIDM=T|49LNO`vrYNZ?%(ku)SM6~l75Br9R;@KYi4x$_6 z9joA&uctYM5J$eeS(hRMK0~l5lg}{^R%S6DlLD$jg|~{@qmQ0%pLQmay4H zYcus*@$9*T!|FqU&(O@OC_FFsM3K((>uHUOf53wUjQh9cB7KA;^%@k#C8oxWcjy)$7w&4g>%VW4QX zeI}=TQObl%fq2W{&OC*14CZuea<|ost{#+*S2f0W@|q3X`1DIivSfJ>SwhApP$`$Y zStn;>5uW?v28ghc4#jsp%;x08^xNCUC1_UCy!aBE=k#{8UNk=+x@ZrUYrsmT>0v04 zh%?FFLWt_D26X9d34x`65>S9l0k|0M6Xs2`Y1Lk!tPpHJz!%R`i``QDoWck!!2nuf znadDQ!&&7%VS~fNc3{#B4;j-=FoMR9Rvs$N6y`+BgeS#4Da&?aK0{}P0hWa?Iy^Q9` zX&hA1&3EJc@Nka1t*XuVrh6&8qbb0Z$AUt2p+2KYr0g_rMSOIBY?X|g4+r|tk$Qa~ zCfm<{Ap>S;I-K3R#9|#W)MJsdqt#>M@z}~QkEV~&#~G-%3K=MDA|14TSO{x64H$lu zagwuWZsww-H zGq6#z13hkoI}o#=dc<^x9m~ViZ3K_ zAP}R#%3BTxLZCN`eC(+n->qiVeA&;#fu^~f@2k6)dV_Xp(X?k?bFVRG@t33vQ?*5Q zhyyq0_`FOR8Ikydy%|f}H0!_v3Ig{7vWsidpEE`RB(%)9c}1a_PZE2z!^StV(PK?V zWxm~sbx7BRNZajb>Pu?&PO$R@hy`*xXr|Se8vjbhsMX@~B~YP9}a|=>;PG&fD>!`e{c}Gj}Pd40Rm@kdA*- zkklaB8X%t(s0F4zp-8_6`N2iMeL;{k=MXG{W(F>8z!ZbFCrec}n~_R9`DdftP?O?f z^v%JM-I>Hv$33ISZtpr*s4$bbSAD9nPY`h#uojE8(E`=YyjyxBk=+gDY_uoQDw|$P zypj(1!qUFhp(l!KjD~4m)-M|Syk5ao=^I3Uz8xSAc1%rH?K6U8bF|gL#1bzNyIdA1 zbn?uipA2s0WKV@i0y8qXm~{*2HNsd!Y&WzHLWJi3Ld6L%1Y4rO`gLpKs zr>nAy;W69BLsXow>r3}4OWf|~IpFINau-!m*98&7QX;G>s!HGDg3R1cEKsDcGyq_9 zN;GWfAR4+-2zUW$k$SX{(*(B)Ip*!IJwc_@nKVpsUe-Lb1RUV_?^gC{0Y=XNFcRPjRE3PLN$x#9fo&{J%%s-3jP1Qn`j@WxSMG1R#$M-7g)=2SH{1tE z8h=rh@&W2pD*YTt_boi;-PHY{clmN@_m4-n3fuBE$r|rzI!BKu4hqWxfH<}K0_(of z>3L6UDOTB4kEAj@mqJC`yto+QkQF?T= z4)cc#WbTCmW?&0YFbmx2=ceg|{DDO!&Umm~TrH6e3o7%VPlZf<-P$w%gsC(Yh8W@f zc=YSyBB0)>GXiADF_19YUfDO#!e0c0@6x+I?4A0_%doO(4)^P@1i|}fsQryuwTDwn ze;NF~)EwL|-2c5*&ie%+f~2;YQ}mc_yH3%&_c00e za<(FEaoI7Yc8_57CJ9qC#h5`dAk7B0Vu(Y1A`W(hU-Yib`cU_Pj|-zL0N8@0I%R}1 zml&z4xvYp2icmyHPjlr&-7K)X(;l!7&!k5lswz23#&$T4bj&0|Srz}}W7iPQO&NFX zoP%NY8$saL&JF8(2Q)I*%H66S12LweY6>6XquCZyA*qfT&BZeTT|w^et;es(@H;we zmprI*HP!mNTnFBj{!O?8b%FFt``q3;(D_#s`F*bQn-f9*b>j1n3Z&%!(iTwsA5IB= zb#~{!v;`Eu{p&RCcej6y#_@ljIQ%*A|LD4aZ`bQUTo4)ufG}{&0K6L5++X@oK%ajvE;S%<&xhuJ@bl1T zg)Lh`tUoFhZ{5M|$++hs^IXUQ8T1szX6@=WBbL5SWTgmTuVI$n(qKM?+XSZy_#%up z_C=E=ZP~mn3~05>?tT8?N_4;%D1DI#)q4kDycKF00$Z`9PKj0Y*LP@c%f5y)qoKR! zq7Pr)CSw!V1q^U;q84~IF)5iDq92EM|MA_*ysgOOf%)8_vAT07=klkme7(&eHSWjx zJ~s4Ic@)-2Cf%t?usk5rVY$ckAPGTtXm(`n`1jA6``9m`y03YN31xG)N1@!IuV$-_0gGTY*CGo}27SuE{^H--?#i$9)qv zz91xK{c&0z{l1)w>Mhct*G+eD5v}|qNm#2+`2m%K?lind=rbaKG)TZe}r;_4`6y$4Eu=&Jk8h{C0remO4gx=AhEH#~&b zWQAVau-?)am<&Pi^8j*A^G*6X5z|y)<(yqg_rL}2vs>{?*~0f#m1il2`{=liLXNGV zhBH=KzYQ6p1Xydudh;E$+zrj0gOyuwI7#Hkc-_yLqq>AgY{t{5%ujPFM4- zHs-=LoYx`8h}s6^Cx*ivjC7Xpj+?l++0%Ee?Nv+ePYVIaroan?@(`FZ7|@EqFGI9} zXufxQ*6d!%EJ(Utn?8o5nE`r^{2$Tb4=2O@!=<(@{U7Kvoju3|5?^{ahYWVKdUW^- zqXp=-ViET$tE6Vn167c?p6!a=9afNv5(H!i21znl@q@&HtRE}rp5@W}HDduK8Q@nh OAZ<-ujr_}2kNyV;D$@}F literal 0 HcmV?d00001 diff --git a/adfs_claim_rules.png b/adfs_claim_rules.png new file mode 100644 index 0000000000000000000000000000000000000000..4d62c3c215b6410b6459f375f5dc2789bea95520 GIT binary patch literal 9075 zcma)hc_5T)`~QeYk|JcCO66opO36A@_G}3urYPBkY+)WEC1lG|mQf5LdzNfdgb
    c3t;<-S_8nUDxwWgpq+3=U&0R2n2#t zNBhb(1cHfTzy%kXg{DH_o-Yc-ta{uQn6- z*0S52?{0%KYNTr=Pf_NrwO8loOFZlRLVmJVg!3nI7Tu~hPNU3zTd%(xIk$e9L5avQ zfAR`YC9OA29`sGVbEB%-=dpfF(bsmPpz*=LbpE6a&&+Ps*FasY_VJnNVOQ+3amj$v zm=}gv>?M|NqVjdwEnqn}RSf;kaOIA1V^xQVyk$9#(Dcw>vnsC=eAEOvTrnNmEn&2) zT-v@SF;#!<&1A1z#WT7uP41c0akr{uA=^McXw2w~zs*cyB8@%6YOGE~nVj0G=fTNK zZFQust~6MG13c4A3T`_ld@bPi_xZWHrl4x=wBkSPUYwlkQf=F?@g>ysUWS)Y;Md;3 za=kg`)B5YLEZzC@6@z0bWTN!@r13ud-bmiCTMp7Bqq(EbDH*St%B^`*RsvoF9*ocT zeK10iOdA@*W9xgt-H?wa&~Y?9EmGf*=%d$vP+asKVPj=6%8+Ddb6Up=1HQ=cidm}O za2o7PhAyCtBvqcPcvAe0-U_0+xh|&^&qrV$wCtZLHtp?t!nX7w6WuKx?xNc$Ub6OU z_Twa+1hBp-M+jJrA4$cIBSRrf>f&7yps&{}*QhV9JI0Z%n68m0^eCL5XO!7_X19?> zNzcjrM?qg_%T2Y7jXRyP4pb9-DnZ6Sb$%7?~n6VcWulIB~lD4EQ>xMXT_f_)M^-l-gCV6`!waF{#1R0uu`7 z#8%}pJA&HQIsl4<@WV|ll8)}&*>)cW)_r>2y(+M+^Pa>EBql>j0iHdARE69EqAxBI zr%R0bLb5P-gnh~tz?DsPsvV#vF@Xr?e!e$rMtr(7cK5UNyrLM)cc!$V`{C)pz$NDv z9@V5)RuzEdO~EfPoAG0#watw&jCpxo$_uNP(*oaYyJwvVrZWLg(BLz=O({FF!p#Y< z^LEx@Mr-Cq1ZISk_*CMn)SxI-Eu1xztEqatb$_K6$|XzWn;~*H>=z7Zi>B5dryMr@ zaxss2%wNSxf^Xb6{g+B2NA0?dN`URQ+P*3q654a5^yM$c_(XQ3DhC&zRKf(TB}Yl> zi5Tdy74`8*C`PU^H07Xu)qRb+>G|0kRFi;2A8laA0co9*&^KWYG*x{){q_wjtxyx` z*u7jb6h>0=aT6Y zbrj#Z8pkT`4`DI=(G40Q2U+LtTXnCqBdK8zxp~+l=O+#PjNge|AF!PfVc*|<8MPU1 zZoU#O>2mR5*E<6wRB{J4fPsGTPK{+ZO@f-fSB9?osX_brrG~64OdbtyKSqm{ae@gy z_Cg#`*Q9yi?WL{=1k0^o_Bt8FAd2{eetC+J`n;R_TkJDu^1E;pWqg3GhfwR+w<`zP z!xcwr%#BXj7tecVO9P<>GT5wkQ}Bw2Sj?~bT)_6q>FseMWAGl4ojN6X{3GkPn^$8oY9JG(czb1ReSIuO=-a0WdQKT?zo2l*?TLg? zL1c>#kxLs@GDps)*4ozAbX6tDjYPf{sKsO>V=+FEQ2e}ylISST7s78+rm+kvKQOp2 z##dfmA(JzF;poUkdEc0cxO)`e+(i$)rsns8^WZ{D%QXp&ik0<9mLZh`eW>|D%}bQ? z_U4!}Y6l5}e=x8lv?yhdvJ=1lVsN*JvaiDFXx$r*q@_e$j?FERfwDRBdur;H?;|6R zpGpm320pB$tb8AdoJH=Tpo?^Gn< z@O$ljl5NcfpR2wqWE-39uL2XO1+iJ+(FIWD)xCv>`;N(;zRY}$xa8)!anTeMYLo+R zq?q|YCwnT-NjFyzdG(`&#-y_BRkiV3v(CL27Z|mgU70Xf5uwHA?b}yra#wW}y$+_3p{jBc0Az+nL># zH+7yh>XjuB$p>?sl$9z3`#8Du(#&!a10bTct4n>gnc~8DVa_S&tf)2-IWnnN{gf(M z<8Th0$>kD2a*tmLGyWUl2A9y3BU%8M}JC|(#a#N(RI_-i&(jL;Q5>A=ucP;w^ zh}iFwdfM`Vn%U^MY(F!82jiEor;5<*ZjR2)-fxP1BmGsTOmGPI{vxxA^V@qLoxqzwS3ke*49AJQJMwH&ufx%O%-hr03o zaZJu!bCeGLbNznp`XAe}?f}WX{dG_@KPjTfx~@+SM~-?jyvu%k#l$&GEB5s5n_^eP z?9y)k;LV(fDa~l*(Y{1e=RoL(kgA#86N}Fn z!TKw{_O)`SRVPl|3AK*CPiyONg7>*?3(s(#_(TE23ArLkmY?3+gizgiW`M6&krII0 zf<`QTt+md^Bq_wT|7t77ayy>}Mr-e>De{l0ws|B(V5JG(9-mGAHS`=^)*Z9~WHZu> zG$#}GbM#o&mClj(&VwQ7RnUiTs<8-}6HFC@G?toj7qbxLxoL9rb|l(#;fm1-)XD}PQW$XCSzOpn&aS80J9+9)DWETo=qEnzywzsIThYi<@} z<|Y@!eEJB1R;4|$1?gZflZ!#n{VKUq%i=1%U$V?KGY^`2ylxrA$K5go144yQzO8)! zB2xWfwC>_V2Ok${;cK@t_SISkj7*N@uiCl>;`)w%->;1))P%K$+148q;~rAJn42qD zc{fT>i(7x?^W1l~z8&Xalq}UGE_20xPCepyFU>nIwrN>l<)MWQ*R8{ED!y76Viy&I zp*+Jy;*{d^3~NXE{I1lFv|Bo0r?KddGwMEy*=ZltQpQHSv>u!X8xStx5LpFM57oj#ddvie}34r6ov$46y>mTbJNi~_s-KH?I^?#X5O zz#rFNzFAA)>5`^qlifAK($;-HKM6dlPjTN}BB;aFp9!6_a`>b@F{hr+lF9m90x%v6!mYWS!4(^T1b{hNJn_W`ebOsOwBj#k|WSDF3*%q?+)*Qxg+&0ozaBn=et5I&Zdhnp51FvHU}StLuYInCh(A!I z2gYIGXDl3=PX<$&i7`}EeeFRso?)Hwl3dSF%y56FSS98=K4Q{p?O-QcRf8Y`FRy!~ z+T8PR2sxwyOZNmh7E4m@;>ZhrE5Z~K2OklCG!}z4Y#@%xmx)lY2;!1J?snjYoGCbR zmz-YVUrc|8Eexhw`6qD4z?(tqU64MHbxvXl+He~*#tV}NIFDA8mYr9HeK;JxtIs*< z@k0CiJ(>8%Y{wmC#jW}_y+f$O+cLOo?-T^eN>9hW`>CK|ism`ba$!Hbe=DCM(VI)x zQ4NP?u38*WygpIBw1!VHB;tMe`Qk^k&+CR^Vx!TV+IVg)N1JCE+^250?{d@w3fUtB z$LoZ(QMDMdmbrj;(n!QTuYkS}cqynaJ>aK};ZplLIpCd)xDftiEaq--+Xr4+8<}xn z?!mL1D{CK5?;#TE={-a=TADQ*|L{HQC+oAgjrO5q{;oF0Zrgj+L20(N#hys$2V-;t zbbfY{!sTJZnvHeeywP}Sa3R}i)++2%jQ?7(giAq#C;wGPYpLct?L+q_NC=|)H8=K^ zJI#|+iMW1t6MpSEA=RTAhD*kEQB?Gv1`>Mxtm4+1udjI>lu4xtdTKeDeLrE+K>T{W zVJsn<8M)eTdzD_J_KG~mb?OyQVvK(r2Ghx*#_fiLLBY0@$!UR1+LzS8Eyfx%92fZG zVZWb2d`#VGXfuX)!+~H2UhuRSS}GJ*7b-ax!&N0;#Ra^7lgN6;`R7j&nw>+M(2oID z%k_mY<4YhJzTR0^Ezmi9@w6ucX&> z^G_r{*Rwp8r%Sw$O*XS=Sh*w0dx^boUN2e2vZC92W}tIu)?&HeS?PD3ElsY2S8iM* zNiE4(qOa5>ZSEKRc>Qa0(FLPx7CyM_1#Nu0qvVh0^ZUQCQ_wGbD}LEN8GpZA;iuER zz!&fVkp0ewK3?ba2zeTxj=808x5%`~I!Me*wRf7*AFid>v2lDlnB{)}fa%{@ z_-mCOK?J_j+;vYHi5kjI(C*X4N-=)tw3>HSM6#1E?)wU8wuet0f+5tzMU?5-oH*q< zv4V`L$S9F*_~MmGtFMseI}pdN1B3mtxO!shpUC%4NuaiE5TDx*G=foJV zE(#tu99)}jH3`eDkjprKn^5*v(*-aW4CwCcKkvwQiM$;4Yc zf@baAH>DzWSJ^#|&VB@HICRp8_Y|rS*D@_*tf&Z4_eq8~td-T*C)=Tw_7KXn3H^Q= zTMOCS15m`TvcuDP=es`N%Z{3sCZd?Kft*F59EUAOY18K zQG*0+%J0@75m&Q*r45xo^ry5wr1!svni6^4O8s-9{ zq;@NOuW{}L zj62FkJt53@=*0BG$j0hRcMem)w-$%-{pMe9LgLQXY~++)vih2H{uFOl5I^uFKqT-? zvXexp3}e(vPK1(dXi-F(Ss^DUeKWXZSn|p|X`iF0X|aV+msK{fOB>I=RHtvxD@Pit z8J)ehM*2l0uT)59czvi!Ld|t)@;iyEF3UHO$>Oba7PX-4X1-O@+z|JW&P>9L1vid7 z-95CapS@D20g5+rVh3NnZXQP#IB|){_3pRfHM<Nt;$5eiMI0C6K*R@{=@H$D}C5lI}Ob!hvM^&x5vlV12tTrYB$C z$SERoLq}#og;MpsoFdRR4C7cEe_}LS_<=lkoA)6La6)LhA`U}_UBor=5$I=wun&%0 zyOl%MZw)C+vKIt(stvFgQ`J9@Ec(Ha>G?GP@?vRH9-_a$@_O8|VO4y$GwgQ@m)52m zCNmE^=;6T+k+bDCS;KkKud!jT;$-9=IbKNS(*c9{t{?8Sg70OTRL8itRFouqO6cN# z^sdFl#V&TYaxdmI+uV!qYHI`Tup&FEuiSs){e5fme#R}BG(b< z|14OT06647C@7|2svhbe6yVtJ#{RF-|KBJ5@DXU^gbwI@=m>;8dHLU`0-uoco+FUZ z!zy76foE{sfRapK4xzS=08|{(0LU)SrxTIK)WC_w7=Y3$q|{(l>g;O@;ZPTY;Yrx# zpN8_@7{F`E(0eOxa%rLVmJ@Ijpm4z|JvPuHb$N47tUy-x4lWXZhxvo#T(@B%5*lP? z(gwam5yl&}KphU4scduz$_un>2sCi}5jFKG&plCcEt!4xsdVG-k<0!#)B4k*NX-(BeWR{dNdgUtkPBp+01+!N0VQVP8(6a7@)Vc zeJUu?TDE?v%bTEwQrkl*_UYd&@*pgVCL`%veP%VkUzVY}S7$=%MXs-9Z` zCeIkjzt69bCa2fY6Pl750%o=scxd=P^x!zr!lidepS&tXFD^u{SYv$`2EA1@Kq^t!b?E)6bc3DQcE3PzS5KZhb7qGjQ4!SK9?DzV zpoP!uI z_|VL(ZPJs-b>I?M@A$$(*O3};>24&Swyp`Ht&hmU;xdp2q=zHYN0KqY z_j`~efUyX(7w-f|ynnf)zcMozz|zA`LWqhK`q0KXCGRuvXO)j?U&s#+RNYh0#vs-T zkZRB@n-Lyl>Mh3ns`u~u--iC$r0@Sj;;-F**S9lj#7Ou}_dl2ku;9`^nzds-_8-qw`hPd{zvuTi9cqx_zmE2ALw{?kLFxbKkgCAe(fX0f=r9jq zQ~lX+>ue^K4|`ChA@yjq>1DwIXUQB`aMQG`{v+`XN%~Zc03WM^rMMUl{ z9QH`+CP|oB4BViw{kiePE*G#i$X%VZY$;Cm3TG3`HBVa0J;s%m85+tgDm*PRMf-Lt zhHH~)O69T|XhOeh@v~0o2}U_Sbu|Ysssp*uzpAvZrprPT%$Q&u!hu-2@-(dA`~rhO zA`2;{^Ao<$=Met)O}UNO{H`- zA_}Dntp(4q=w&P_kXv){qW4uwuGEqJ*YMc-wA})EJ!!N1m?+36x9=;g8}bD@?VX+7 z%G>a8cvL|D)NQ~0d^IQ#oMR#}TMdtRGR7Em>{*qRsi=Eh>U#a7P2D@wG)WKEr_gX)W25FLT3`A%EYivqV7Z4+Q-QOmJvq`A=Zl!4-q)zmCZM*OA-*bp+N1 z2*T@a!%qzS#i1Pb$BtD>xo|_9A@Y|!{R``V>gBCdI&Jb?22Wdgn@U|p>M#todSR<| z7*E9FVR*yt6o$9_UHJJ;or0Hv8*ooDCYJ845aii#699j}sOtBzqy4}Tv7z)k7C=qv zcE{BW`UX}-MFkBomJK0HP}c~KQ5{Qv09f!;^rAxMmddcydlKHPPYi+foj-VKj?R54RFj127LugT`CFtbv0*l4yAst|a<|I;hv&e}b~a;TKFL zNp2)7oOYHk3z|VQ52f44JnF>KU!WEkn`0*?T<=5%h&cMX%3E#?cM0jDs%Ht83^{&1 zN+jbmyiJkzDqL+%{ewMZTT!dA@{|N3S=h0Sz(#o@|Dhkt9|9GxO>4Xh$E4Bkj*u*2 zxOm~j4K=h1|K5DapE)^gZz-XXjerSSo!*v3Kox^q56T{F?!s@D5KQMGl#8JsV)VCGB zn2nw~%qw{d88OqOt&Q~GE{~r3CI^3dU7IlxLe*oaYop*)98M8Jsi|dDJs_Ce8E_pV zUrc4bPug*Te}cu|t0>kZ5b)lFO#=~p1o83MYDF@W!>wJ710Snq7L#trou6{z4F00n u$B;twl99n6lMxCr%ccgwKfg)}9Spp2V$Z;x`bTkaE6kWRY=zjnWYOs<3 literal 0 HcmV?d00001 diff --git a/adfs_claim_rules_get_attrs.png b/adfs_claim_rules_get_attrs.png new file mode 100644 index 0000000000000000000000000000000000000000..936f0952124f3fe38ad09f7cf68a5a6816ae865d GIT binary patch literal 10969 zcmcI~cRZX=*Y_$BgpeRg5+r2xwkvv15UjdFbb{4u^xhMq_tgn2O7s%Fmt8d$A&BVF zqWAVJzx#fk-+jN&{eIqmUS_Yk=FD8@TxYKDoH;XdLRFMxi3w>40RRB8+^d&r001@^ z^LvetjiKbGFN^>HtXXm|CDq-qHl}K09?Fs9{X)KlW{vNH{G{i$8TT>5A2amnmgVgOT5l*#E4ni4QEw>A5x z<#cZ+`}C4RxLF;9MGpr=Lt+U4NL)XYSP0-15WtA$*6R|Mjl&cWPt$hokhu2N8_UE~ zTn+AN_gd_JQrGCY`b@Egi0ak0P%5{O=y0y3@UWL`p@k9F);{LGfhKD)<&1Cv29V<+ z$XfTVre+Hz4;gfvG6a$ymke5hAEK4ebx?HBm#&U@J&U>-y zv^1H}`;OjEj)-bC9(Fj!BpAz=_q_RSp3SabOLiov$KeTs!YIVfU7Wvi`)s-XxO$Yd z7uiaH|63l>gl@VH#%_b=k@CS4k-eVl2UF$AtMC%a5xT*`` zCHg`AcSvQ`2cvYPI-}&GyfUcznUcQhlQoED(eO7ZJ&_-)uXZj?>bYUKFa~;fmN>k7 z$=(l1e(NlbrTb{rE}K)owz63zSJf3H-EuDv)53GWiL}98Rq&`91P3wYIR2E#9DJ}g zFD*=+x$|k01HRmX_X;TRi;NV`_8QdHn|RwjfPV0c^wOcL`sMZ%nkfA4rcT&{!ud(1 zn0K37#gCx7OClJd!R7Mo(U53l)kRqTN-56pn63W9aR*D0Pj3lx6XgyHc0^vpY`L=O zFo#iYE|QFaSSV$9Ob&E>5$s=z{{7kMlCb`{(@L`uP-qwMe+mX8X0R4#l9CWPtr?W-DsS-8^t*NVvW5|JN}(>vj5W`GMYY%C#VEM) z;5YjRu-*xMuB~U~S`N?j2!hHL5+cc-|G2m!@)oPv+!47q>hW;GSKf@;iaB77?wkAo zX#*CySoZf7-q4K%4-ct9yN7Y-Q25g!d19Zz6ll0{LD3%jFn(W#d;bdr;p^?g(S*?Q zNCcLY((RWlo34apmSSuZrSwTZKN^P850sdSa`fE(_(Fs6Bp;N`SM4je^@UGtJ!wPP zR6A-lp#b_>{-Q8=td}y_sD4lnepf>5wW*Y_f$99VvZ<8Kj~b24?NbqyqAkD`*`4HD%E5W%)%&=IXB9$m$%`*KC^s+Jx9&@ zit8Cmp9Cq^yX?8q9vSq9q3vx=4--LyJ70qT44n}s)mrBsOKkx%M)Ta3TUzk# z>CRM_XJEmgo!qFgx^iJ&5sRUYaxft&erw1D)r|QOZ_UA7jar?4xx0^4QY==4`rN2G z{Qb*5q*|J_4vPpW+{d?q$p0Bo2M%jn!f2!)D#qH-*~TiTf_v#H%sJsqs+-$^b)=LX ziDhCV3FS&HcKiaDQs#r z?4M}W%FDXt0oG0@p+22aVgU;dzbG?tWIo*+f-v?)d5CzrOWrZ2xW|=7Slfx_I&$-) z2OeLd3X&pX^NKX0Z~~;e*o_o4XnW>@tCUS+U2~a=A;ht(q>}P3{LK7Kj`D89H&LzC=W7iJ}PrA zwzvu8V@n(|GpKJ!p6ngvJ^Wa`S{4p?$46UUA`?Ht%Ai=E6j|INNJwUW(e2teg%|nm zWJNt#ZEK3iADLb6*rI-Uv63mpoA! z0l&hYr}Q)n)L|mUnbTPknFhXhcU?_5osFE2lu4A1W|{p>Y0cGf9GrFk#Vjeh5sZ7tY;^?WTy~BDkVTB zg`d5GZ+1f+IC(m?uS;a^XO}^ee$E&&cO`Y$|C{eKLQBHfd*$~waxh*{-6*!NulO^Q zu>_9SyTpE=fh|G3z4RrRVZkG923vo=&Ks0*4prc``XagV3o;^OhK*Cd0E9JwIaTmK6UO|UUMtiY}Ms-i0myRz`_r#DB;8oc^ z{UYfgx`B9K9RILKBH?xPR_zlT7o*FL5W??CuhvG35ndNfe1kTb$ebqyx3L4ic4tHu zj~UMPy9X|gyx$MGeB>Ib6tC$iZWjCc%E$a*WPxqgi!Yl@EVbJWl^tdbB%qRAEvFh* zfq9MqU7+RiP#y%ZVd!Wony-QV%IHO~B6%XsX(P!v&5BEF`3A|Ka1lDKBKz6?8aBt( zcOH8}L#t_xKce6xyTe2$9B>JwCFl@9_<8jP8WK8Ev z0gc18w0twRz@2rk*+S_@yRFA|mNLvMcHvBsW*C;VByRoLAM8H9b8hjIv6i@bZ^J@g zKTyqywnAg?1mZw^+_Fu)h>zKTuY%XVlnV7jc~LA5`~7@Ni2G5 zka>z#jOQv0r18Jv^j5O_J>g)&RjYHi z+uV_V`j$nJ_%Yfe+R&){jW&ejJARY*F(u&#z>HNkeoYf zi2)Kgx*y&PF-&V^9XqB~4vI(cNztFUZ>YG-w!m4icjJ zxkC(ZU*3%HqlFC1gC|vr_-3r(?V6GgXaX!-{VYLdB(y?;t_b{3M5GgsK9WkA?>!{N z`(<9|ALeca56ju}9;1>ez*=U?eUoL6?`^y_7`dRH10W)c&TJx$&`{g4jk~=SG>01> z^mO~j{d^X>s{U};Me|yHlBD9t+7`cZfG-ZVU(o;Q6XgEgJHWkh8ouBIOtCRZ0zUu6 zqid3sYkI2jy(S)}xb%Ch$av_dtT^8&g((OA!BIoSvRYrP~ z?WNm=kDCGC+Vi(k=k$>rp7VI~ybOpY@gg4!ADR;alfJuVrf>#~XOjH~<#fiyx4ehG zI3U~!+@Da3T|)ON)9W4f0+^u}V;`8I=T6P4jAxZKWAncjqw~<8nb^5JApj9Gn!%K{ z`z9TxLJw)h(r+G06x9Yar&21LU)q+aAo3_|KRqe0(?xj2cXT2=9IIw%mIBU03YKm3YB;f z1=SbH2?ZI6Nd?xOqq_ut6wFY5PEoV4RQE~e*ZK$ngu?)C8Mf=*Tjk0AzR?Ku@(WYe zkH;>!ttc;?oKc{dGMz#g>~>di^1BuuUtJ0^I&44CGfF9da4^Vu&nj~UO9Bp%fM;Oc zeC$S>8E&GE?V1A$z`r|=PUip>;C1?k??@>Av&9xR7&5z&@;+u!1^*>Q!u*qmw_b2k z_LrI}ewaQsCjQHH~>8hv<{86rwZl zI}a+PiI8C<(>$rI)7`zta)j?2N)SR&ZhY7 zvXTqCF@EX^=J(35=h6H4N}h*t(UfR&-cvy`*GCB~`qjs7zg_|N=_Z`HHV)E@ zz5)W)d5h!&a{nN@Hb0?)?j_Sf6o4KvcS_;BqT@rWP48?+zMb2e4HPGYCZ00+v)m|8 zm$-;}NuA2bu4132kmw18chGynR3$EY3qG?JtyF%86yI;Uopnd&^7sA-n;zpUVDBAS zkdOPI_u8TIRpA^ zVtRVJ@R!lC;rNI;o#bI`zBw<=%N8u2%kJm5|G1hSxkRQp)y4`CI2;NH{AlA3Q&I0~ zaF5%ablsC`3!uQ)?GMNvL!S*#k3NZ$m3#}kw51IkMa5rp`2rdKU}~s$By7r_b>3Dd zD0rZCMI%Nu{{qe{kXS$;+qhe(GSR$#?vo1Z_@bK-M5 zRLmoMYw=lpr|(cM-VO(uvIHQWCD^T<3NV5J_BCv;S3ej`OIQz;Ok|7TU?^9&%bPr{ zWQjjhi?h2JW=dMB0s;1x>R_0?UhVkc`^sPHC=A#o3OnyE2`0%a#VvN!xjDiPi6r1D zbbb?aFP@XhewBJ4aD`#EX+%D zHg$+G|)=cLAF_}AGFHq{zE@@`1cnFh{VHmnNH-a-_mZ!AH$%+N%NP$w@V z1&?zsZ9n$cV)jXcYFl@^6ev@P04PSI3iiH%h#=VqPI3E(CTj`jEC4N!MX~fe{Y`}j z1N_uj@p37Krh@KjlCigfL3xBKDk>+79YPACQwjYSeI`UIK!UiH0A@!y**-_gX`4{Z z#~O)YVL}r#_ZDrum%T5cU#3o(0L#PIq~@dZbB$B;) z3T5#RvrE>zbC_?RD~4_djPV;3wKLE?CzI*4bK=Z~yuzTaRm`QTL{_IDa_jxO4rI`6 z%!Yw{rEg;xd(%l60R;wvy;o)17oXiO<;Ykuqo_p8x?#{b(APGd`>R>b$H*w`qX3^%9bTE@j8ZaXK zF$#>SDd6M<&~QPK0d@64Z410UZX2yWm{FQVpo&1{)5-xA?&p`kczbq8gAuP72wGbC ze)kVtH*WEh%f7@PLH`>f1((5TCTB7tlH+ReV&Z2LUKT_VI}1X=C6+$AnP;@L)u>

    i=zq>99+$CdW$6Xoqd-T7kR0HmEVKcKmsT) z&6ve5qHBifPTObnGw3(L3Z7L5zkN37PW^NL0N$@=UGJ31OLbv{gha!;D8`oE^f&!6 zyw4r(kFHuipF!ciNlY;R=nF^9dgPVUW5(ghG0w9)E6A4WTiP%TpdBd~C{;lxheIZ5 zm1r%e7Sw1ayMZ7|v}7lzKeYanJ~cPZCaZYQ(h+Eyr>Qa!G`K|U=t%Vhr?_w5(hoEi zPM47-*CeDq(Y1gj1O)1uKC0$GkEw z>p7iK_RlNbL6OtxgyIlCR4gkr7Gs8#2}ViYAAQ4dzyCx?Rynr$Ieew1| zc={o(ko10qOW1dP%&xB_And@-3ODNK1&&VW``&}8+i$qYn4z%dWEG5Q_MKSFhGaqf zKo0RBEEMiv|BuED|8j5!p?~*tuD#%20{?J^F`m+m7lhaY{N6~7a9EJQ4}P7nmYvEG zqOaSR5dAy+%TNG!_?2r&l6Ytt{?9eH2P^$0ko` zhm1{KlGuqmwh=O)5-h^4NHn#i#ioH1`Gu&(V0kAtpgIGqfgaqiAl@Rt4A|0m%{QG> z)a$HZ9H=gEDdZVe+|Z_T{E7$Hie!(sl&7Ket)3$MGe0@dZE*-vo1kA&mk6Wi%4bg7 znG46>e1yku-+8|W=h4_zDrEgHU+&)YtPu>o~eeH^Jt1qzGkiXZo-?FG2&j z&dz$~u-Ktbe>$Y~tM0>Fj(nT&s62ef9x&OUVse^=Q4&X4+kpm4!H0K;l284s#^p4A zQ`yh|W;GC+{=j5SO<`g#bjawLyYnl&6~TFlR}?pi;j4*w2iBC#f5!zMh#V)^PBXKX z#17qiJOoMP2j^GHs#&`eN>SZVof6u%0ewj}^Eub!C)t&+*m%!7H9IB~o%{WhgbMIq8C@t(sBzCF>I$qab ziH~*0G0WhN!acn9{xvY`ynjL)56VH)%C9Fp%z$@UvGGvp8FV zL~E7$3h4@EEz8*ZOe)ypkQESw1=2|`$+YR`8&0+Ony~vxA0O?uJ0ZK=y7Ov2F)QJQ zx^UbyL-sO$>?O;4yvpEY5Ufg}s}8hCI=mP5*)X0)%30-oH?lK!L4P438IouUN{@ng z6=XN#TI3Rhy`+pL@Sug0ll1v=z#+gs5atrGl@l(%_zqZaZDpzOvgvb;Cl@jywS5Yd zu8#vr)$vS?lmfD`XD76JJp6)WlP5EakkGfXt`SQ3Xnxi=F&r`<{~g|Iq6LgY=6+8A zaqIEL5IeP{$&HdW@}^xiKRq|8>v%;&{=3f{s)MXc7=7H` zDnF5f#4tdwE<>_NW!=I!15i7`gyzGFy}4_lG9kdPx~p%-pOqgq8-E}*-47Y3+prs9 zX|w>P+^A=tDTk)hTKyTunU@K9oaoftI^20npb$2ZDGv-*!M3A+8w~-XDj>kj0b#rc zGw-^k&(k4iGfxybUBI+sA4d$M|7=)g8Gng8Y#VDl*W<{RW1`7jRnXk45lydHl11fRe6*2iM2kLnG9PFe&+nn|>3olm4Uk_2L@YxE^> zMXKlab29;m1Y&j41e7jyS~bMvP2PNU#)Zt)FYg&qXc)pXPqljWaLAq;zD&mi0mfPU zED+M%y;KIx^)<6M5df-QS{!YUPt0W5ffA8#=x%A8kiXHZf1PljX$c1j7_?XUy80%RyYwK_;?a;V>@LpgZct8a?_A$PfHz8$X1Wlk<{e$ixE! zF0qHkO)iM z;DVL@YW3^hG&v&gJw%RGk$v)zKiSUwJv-m1DS31LNr~df+84k1Uj&y zvRKX)s`jHqzv52g}{u< zB;f%9A%6tyj{5+7kBGKe<0h$sG!R#{#zKY*dw3N@h8=BhLqYHe$v2oS3(Nzg>Tm$_ zO(P%xWx|IinLywNdK~NxysjQwP>Ky#GJPt?iq>~?k#h`)gokbJY{V||CLl}Q8Ii?( zqqG1n6;a~w$Wnk(k&cft%E_&GUIb63h}pLid*%{xxFXF`*R z~wr~W-PcC$?Yxk zK<^0erfU`js!a*Y%V(-$KT~4ZyTztg{3)aaG5$hfg`#POEI7P-w;AaY9QO@D2sD~I zL@~6Go6TS53+!TT~Mjc$htqzjhF29^3eS*=GC(@ zz+1|hZ06znTh@zDc?-N3jnrj|ocW%N6dzEqqbjw`;*ZllxXK%eveh}dXho3XiU&bgG@bE#=MMKH1r@m;MpOC$^fGw~d$##K* z4^9Al!lnbR5|v{x)# z0~Y}B$%0dX%XwgLjg9*|MaZ~^Z~=QOm?r@+%!f=SxV~wJ0RCdydVK?4GO)@xU3aOc zDoF&`nE`FI^G*-J*?GjM?8hY}n8p^t59QL{0=35d*xH3tSG^*QZ|V!GpYAr9+Ix#=swQ6~j^7ajSdPy|LBxKELYBYeX^xJ1oDg_&ZFL z>RM7l`Jesv>;l!U2tLw!Gri?_C_&N$A9**`T1D4@cl9OrfU#l8;az#2{8aRB^}Cz) zs=s9?A<1%4R*bZXBNXG+nu#g9%UzS7f*uX)+dr#1icS9zPgHTIa#H!!+YZsly&HG9 zFfjVZh8NK=gv4{QVMur(tV?QuaxAE`FQy&2~6m3^O~e{luQxU(PT);oi=w3y4)t}-VW z?%}S(^_7nPM&-5hcy@fX3-;pMniG_ZpnP5eXHjHB zdijClI&<%DP)Kr#>pmV&ZXbY+puP!Rn4j&Gj5tC+qU;Ri5sx{EE_zc#x4@Ii64s7s z?TgP6;`yN_kY^KY0RmC7%y0NV!q|B)8gh0l#XXae!1>pfOHLuYZPF?u>EF}LnAh;A8v+4Z0=1-!BP}K z=r91FHR?H;F_5ntVr?A`Pd39|h6DWE{~MUegnt1G0LJSDOBKjmm< zaB%vrohQaaF%b=qW2JgZJHy#J_nPBV>F%A zis&&3en*tL_TyR|G4%6tqeUYagO*7iqh12@34MuaB0SXl`_Q_a{KfzZt4+1kHars9UJtsQW`EJVLrWiy`&`SclIj3f>2h)h7J0F z5H(7TS*?->l5;Ub>8?3LRL}E42P?i#i8ahn9Dyi2cIXGRWsv6Huch?kJdkAIo_Q}Q z{m=RvpxcRTV=-iSUSv0opvI$a$s1^HPwSpZ;36^)y}muMrrmJ6qY2Myb6-4yAL5u| z``!)$U9XdG*2n+Q%>PCw%#;pgj^m+oJ=fiQWZcb)W;*Qn4EU{!ptHk7oJjvO*yOK+ zB}}K>gr59MhS`mU-<(9L{B?w4aviaP+p2MsNg!^HRYqBEVpg30PGiIr|6A?9wEJ6wQCbX(f8}yh`yXXoJ2wA8O!a>V!TC=z zFo8S&%VFFQ!Ie<>Usd_PimAf90jBT%Ctm3PlbBEck7Cf2`+F-3 zfkVw#C!hC%`j#b3J@Vdn#1oi$h~{{}+2v8{`PUe|!6!NyL&r9y3BJMYV`j9IkfOrz zDJZieWV3zXQ&p*B^`4iz;;wW2>VyiyRH%uC$xHB}qrx$Rt`OqDFPJKLFSZS!k?-j>|@{G zVo19*3iZteZE7{fv(TDv9hs)*!7;?E{Tm-%=RYXo_bAg z{xDtRdSj+n(Rl<58ERC*ZHvA!Rb_CzVp&8R?kK`nY`COtq@evVQXi4#=lJB3?ZLW> zMP{OX-`CP}KImY_OauOI;-kh|;SaM$6OQ>1>E^K+V@(8}3c|^e1FFS4|J3mV=pu=t zSmckg)wj5K7OtM1mLG+S9v1~#h`q-Cm0E?QHLE}t!}X;zS5-FX#mR6t$Jm8>%RjI~Q>DOWPZ&K&qSMR!u^KBZaamRI#aQ~_=&PKN16xEZ?}yL298 z>2!`|m8SKFUS}#E+Og7Tfz7#ewdAUL!K;YG%a|wPM5+knKZ`kRZ`=RfGNi88wi`=z z-+574LL@;Y;-YrflJ;1bzB>ofloqRKBuA$+;mdXn9lsmsG%=H5tX}RltZuM1lLdK{ z3z1DX)8Uh4f#UtUdH9b80851#z0z{AGgjJC`_MR?XZc5p2mCaO=i1a?TYn^#akwfF pQ*mwgyD=uUJGtYANNskB{p&Se{Xk796ce%vkdsz=St4Z^@L%hacOw7* literal 0 HcmV?d00001 diff --git a/adfs_rp_endpoints.png b/adfs_rp_endpoints.png new file mode 100644 index 0000000000000000000000000000000000000000..ed3beaed7c002c21c9a43ae5d31f615284e89a45 GIT binary patch literal 8999 zcmc(FcT`i`w{DO_P$7tblpsX}6a*;-P&$$XX;KeD=+d@yMT&F~kQR_GK?D-%Qj`GF zL8J+Yn<}A+H0c7;+YQHa&i##d-+1Hx_r^$e=K9v&YpuQ4H@~%K){M};s{%UeR`V<*K?kkT&AUrFoNF{wQiX~h}T)!ecYNq9V zJC(6#XRc6Nt$Uv zAz$1*jyYAv+&}!xk&zki5+2GBs?TsJUOgOJY3(=B*nV%m+`ejevBDIJb}-N9$N&|Y z2+Zuvou0-LIR1c2uUd|LO)Jl#fOCPM#hj6_)*~B75b*Y!GGWCQCloWzvZo8ScIz6b zK5XZ>-ka)@M<2!2HrZt|Q-+AOCEk>w(?mx#>N>&l%Z}I$^##Zis8(->}zDUt_jP`uCMogx?FHq8XMOX z-k76=c~yWp&+PPhuK*H&=$Lh=)UZpI9i2YoXO_WJVnTS$s`Uyk z+{s-=DdSjq4w(3Le7lRUcibJPw_txK`JTgsd!zv(>w3xh`hh-j_o3DLbQL&gmp4I) z9+A&nsPZPLCQfdc6@Uy0&en*YZ|bHE5K+?BBr0gjSuk!C@YZxDvJN@1Eu%L=u%@{R z%hC;?>{H7zF$nA=y8QV1+{z{nO_(=HW7p(*Tct91Z$-yt$uCs( zi`u6f8df3df{lQ2Fe>$;2Yb)q*khj%o2zeyO>?6Qy(J}Z%j4nC-#qGE)p;e0?j2)K zR@&2KJMUj++=gbN&|yV8jGIt!4}_hqfCxLXsL@A4e#*|J=`~`HstggYB(6twK5+$| ze^y3?p(vwlL6aC1Whnq*hJCxj0&B!m7$O?+p)cN5Q0{16%5hS_92ctgj>g)8yhaGs zcR;)~$lHPc*BE=n8)eWBYm|d}d_MT>bTRCMv!Ks=)}whflg7lRvpLj5&l!4^=~{Yy zxB5P02GHm!Q;j;_SC)kY?`iCL$%St@dCo|CvbE<5re+HHT)`BV@nWFyNOk-SEa9OI zw<__Z_?OYS+d1iab#rAmWy9vHJNhC6RdTMnFg1UE05|nnXWCcXXNvlpA`CihE3wxd zO(n9`(#IH`1m|dOOlG5VdeemLV-ykg>zT>Q`Lbj1?zgC?%g|uVthHIQ8%x2C5ZnqgLm_tV?(cEGtHETJNK&U z?r(}dyH&?*e{~HQd@ybOCLe@1IDXBgVQ|zNzx@6FmC0PkWe8~hDLnYbAH(_a?;EFX zsMNSi(?(TA8svkYX0ZesbhNa~qJZ>4{jrVVs~BZs?9_$Wk}E+~pW0|s3W^MskH`M7 zH+fBsZembJ?9C-Mi!LO6w2_tY-f^1r{ZtCB5|Zq-EN9SFpZDgB0J?B~d#>TOl5w<~^6uYz zu~Z@%JftbkUx9s5fOpqq&V41ds)q9|qD{Yn2 zs+K0?cwBZjT`C12kBW!%6jrdY&{kPaj8G@O%Aob#{eZWV#V%gwxi;Z(PMo4-M;^|F zj#A&+j`ey_fB5EU*dGqlayTH6Ic1EIkFNdAXil`cdh3JY2pZKdvgMKX#|aefvr6`Z zNj8>J0bDSj&V09aEojB{N9*k+uN$0gFMYWBaB`=f@pV31DKBVPR;{d#M={@hIl?IH zugVL?12xo5D|~tJ{cLv_mV0tw}sc2+(czIOf|1j2^ort<2=R zHO3=5Pdthbtgq)d=Q;ChWk8|cPZRI=={L%)@9Jm2x5bNL5U%D0?av(SX)$1XGk}zh z6pM0WV-=~R!aomNg4P%^sGqkkF9=&uFT;~78J}s(y*w&V7`T-l zqo4KpeyY#lc(PhwCb2Q}D!$`fSas1na@19V3 zdW$jP+n6;@cr`Z_pb4FI*k~~1#{GgSPiXaBz_l`BP5kfUb@muxe4V;JjKYd=sR-Mo za2g0%z@+o`}Lb4UYkgfu&iqM?s<7zqFYu(-^;-Xd_hacQL z=0#Ti{ntD9J5P@&B*zS<#iPFR^E&J^U&lIh{cLOBusYuQ^@lt5ZP+E;PJvo(1u3?K zqOe+wBx)d6t^hhlnY#^daeUYY)(P$If=@z5o${}hj~o*SQD!lDlX>Tk7c5NiIoY}$$l;1I=A!EILN5_5YX>bv!D-}fXK<6OyYy>< zh&#_-e?*H0AI87HV}w+cA#Wb}8K9w^l2Q^sb0#l@k;A z!c30x5o4xY|9FuwOLWsMckhcjylo8F#xcFzk5;=|-VaRBgZKE3w-9&J>(MLi6DkQt zh7C9Rh(!a*BvFif!v;jx6z;eo;xS zNo=zWNrxk4DD8XiZb3jO6H~eRQSl8#+mt%%tP6Dgp7vTWUX|DsZu|0Pz&kfCB;=GB zv^pC?b?`lvo0h@5Ts>=hY?7r@~KNUV`LK*bQr(m`Vvd0{zS-)m}xPCRl8 zbxNBE3B*%eg$LrPAWSet5W*zf+w&^*>wCIp#m9w@dkhxc%Kh|C$lE0sNI1&AEu(-F{qEk|N zdwB}ktc3|?}gCi&{H|KUwm3DY+ew!)tC&PY;nN1lCU0)`|A34<@nN*yU<;&|DmhUOZ zcb1fP(w5Sv9M^Z7zNX)}!uv68XYc7C^641~lB;Im zv=Cv>5Wtr{jO@IJuFbywBd#!Vur4)`g{f%l+U1(IqZ+5U=o!SLoQj`MMVP3TdA&p> zeAA|$z7?An5`fFPwW&fLq#;<&kThHhfjg5O7c{e{#`MZAzB_jR#1S%fhJp|sCQw$Z z;m8ADqfHhO?H`+aBL3&d3YPxLfy1YjDZZeVv>-N=G7sZsE@N$T+_~>poM^dN$6Q-q zH=7u`B|G@HF^>5^VVC1=?~hpKKXwl$Y83*$^Vj@cyt3jZ8)&uR?HWaqyeN7UR?lR7 zyxEZ|ETX+tA%Xhto10qJ-w$KCL1qDm?6#%t^D}cz238a^&C+j&lY7Qq}`83_r{Pdd&JHY_|Q0%LZOh!Za-dobCJGl59xi8E7N#qggv z^NB~J^bmiW;uMhvT$#W|_aLiPuwEu`B`{DNKE6J)~P zkg+QnxfzeLtOJj3+IOejlrmR#`J%nh_2e0pRRE;9ImSf^fBe2-{`E-zj~m6?-z;c^ ziu2y~C}lNO7gX0)w(seqK5>Ks>erAy{$FKf9X5N+8ypLOU(H7|iy1D!0fAm~wafWl znpC-r=|R7{?LuuitgAf)uwlycXTYN_k(%Ayqc*PDTzdH8!3e+RC8VAYliykV!?}{@ zp#}q-cpEHpx6UANu)o>lawetw_N!BGY5a>XX=jgslIBa_M$8BQIYkF8i zPa!>4a1AKi=z6U@2v8a5cBBPeMNWC8OTZtxa<3&u7=7bU?m;4qDsVKdioML5ImWt7 zc(IO|%sCayFrX-R@us_xZo8Y@@t4?z6b6qzk+17glsbtGZ0!@YA%G4OJ`}iwVG0GV zBBStE_qdN0Fia?&r?-h$BX1Mwg(LCw!Y37fRfZsCI3+z}=N_>}JsFjA_Q<_|6Xt0c zX_is%v{Jv^kil+3hy3nl=@&5kXrXFv`{-y*oNimB#Lz{U!Hk>siOuj(2Jo%B$l`)kQD5x%v+GI+BX+ zU6D5`P-8r!TBn)J5}|}q!#&oS%gu_eovshY(`y>(t=`Gh6V+c`f2h)_UdD`P%V?vF z9Uw+3W5m;6L^5CGtG!?ACC>>7ff@{~s5N^8t%a<31=6)dXbsA%5C~z&pRzytS=-xl zI)WZvzo-3cVq~2G-PeEJK5=x&AW;H-3gLc1F@K^<=v_=#DnI^K#!HqL zg9YzwpWuh*faPM|rCsDk$8{~lyA>YXbbSTBmdz`_a_5(g@%ROclnBh0rY5pX-iAtL zz_I2gYO0u#SzY~%*0{T5O}tP$U5_TR&srv&zvk{ODz;RFaRh%=N#Rvw0(D(qC89E? zcx*xHV0Umx1(mq)ara;~z`E3CKfed_R0lhFEA0Lti z)Ya8JA?JS-u13oL=Ih_2UEYeQ7+W#FWu{-Uzbsl`=qyR|(&3_Hv!Ni1Wg6F;*4gDf zow<3|OjTd}u!Pa$gZ<{_k@E8C&9Pcl7jCraNZ*UF@7Xi`H&fo$odRzo(6ydF+JeUQ zpJfeX{h=IcobNBVoL9bYo(k}`ji&Mk+74NRYpbWVYE6xBrVWMOvO4yxp)w}Hk4(E* z>}538Snx$!#3L&B02^I4O=aS(17SuOO%>oF%*=6o^wR*7xw}*?{(+5OF5N7B7}-4X z%K08QCR`FG6~#5E)E6AtvU6@kKRd!XZdz^elvBZ@2Q6_MvJ725=H4!@U6<U{lb3ka7%CrBjnz=DPFb23d4La^zK{1<-dHZjvI@wH}stsH^Z}7^+`H#D#(%&yi*w#G zX^SW#!g|fC=$-iR54)1BSdEzhVWeJ9dJp)EQ{re|cg382k{17@^3GV7UrcMD!#jRj zEkvz^-6gx)?m57|*DbF+16W#DCJsbESr!;HAK0+~9)sU|yg6YYX2M8vnTy;B&(@eS&?E@pNTZgiHkV7R$wa`l4;;a6CZuw;Yo-8FdLm_6M?0;8A3m zo;fbnR8>9mf8qXbM<9#zS+Ka|U)f&v`Z_B2s?$^)+$w2m2Os|Inre9Zc?JUSBr);%aP*e*o)BYIfI#aPp_9&4}5a`_YF; z;~`7(I^i7TalEcpR9su3b$qlrAuarjBe`;=rkS41A#m?3XlPB5FLme>U>2o$O~R{< zC<}Wt4|w2Ih#ghVP%-BWvmbcjsAf2;lXaO!r~Q-arSc9_EzQo$TcqAr!siKUNf>5+ zq=bAgA?CqJH0_GUsl=(6X-%EP;zN_j8fqqFZ=X*CV|G@d|EU@-X)~rp6z?B)M|WOB%G4*a$rN#X zstJ}(uvz?7@x{<~XuiTfhfn9ch7>rOud4Ty$w~%XxP3D+SudQwrzjUieM57|*}dt5 zG?kA#)#`J9{fv?+X4zCJ${aos<6Rg>#E#yz$6fhP>aLZDAUKr~FpYpi7F69?(Aiul zU@yts6sZ$lfj8_g-GzbVRruPcWB$bW_~6^b#Kc7UB0;432_=4)gnt*vi}=-QPBQi{ z6HXRz@+v;!yj^lpq+saKgLUFhsWht35_D;nLP=4j-RBIf^lFatHXhS{;gyeDA_++! z9Zt^A)c8Hvx$}=2E@V&kx7@Pw5hhP_^i67x=`5)MOW<){llG)RL57-){qoU0et3tN zXU-Y!VF}EMqV{zTmAnEMr8(MI)L;bHXX@I;QMOyHYgILo3kEICW}97 zFvVM5V(BOb@lz9AoGGiy^w_L|9Q&=e-Iw6wTaRnV5=?yX-sqr|4p$#%6n$K(la6a= z&Nq2r#N98LVsPmB#cid7`@d7{0v`2gI<(_BmE^g7K zHW5kai~%!kHbbQnN|xq{ShE6e&!Td))f!)?_1IMpdQFieu2y=dOZY#N-)D*3yy`%? z0HZ;`8x&X$i|p^n3c zfll*&wlJ_oL)^Mm&{zEwxLH{FZcW4#D6S$vySP`G1w!W-uoU;ud!j$y_^-`s4ZF+xwRIa!ylT2sR?fllR+A%1Fl)u!9)*_AX_`(qc?LPebJg}ZkY1{4JwnK zZqFnAd-CZE-j6f3i}j$j{EN+{$ii`Nk96tMLdNcfMc&z#A;7oF#C?bjpH7`#@~bkm zt3v+IpDxf*7ThJ=O$JIa;t?lSR22Lp;B$adh@-B0d8>uqm-iowYT2I4y9s$IGr$L0 zO>@oU6I?bIMXtdrR$a;l!ucCi^vcj*l@RvM;kJTE;~&o9JY}dF^4sUK!qVuFQL`ch z+LS!N7@Ehhtw=Tf^VFJ?drq4g6!#skU0N+$3RLIsJ0X8w)+9lKDRAd3GT&*1R?fzY2^3cY%Qois&` zd43~*{BN88-66&QX#Ot*1NlFj|Bd|bNB{q+d8PkxKU60OX_F$df^+2(&0zESYov`! z@{tuZ!9xnBD#p)_IpmC1>+v&LM$N*1L@oEfu5vCnCM@Vh{SC_ ziHFt8kz+~JqRas|zcEqiGr8tF({dnQcS2S(IW%f?%uK|J*#hYNU?>=bh~j995_z)U zNaBiPv~L#ZYZW@!;W^XANVX6QM1FQZSK(+G31Bw5TllI(zrjUdCLENcgb+Gp<0Eag zls*da;5FZ-^rF{v9&S|Ce*n@b0zvCn))$01$}@k3&plse?k#wnKZF-YQ+|a+^Rt~X zLSs2~hT~Rci;7`G1L86a1PaG9=stb5>Vie=Y)GDvlSx8PTNMWxrb4?ZsXoZ!le@$& z%+sGd2P8`tL@vOip{18ti)0tC2(xXz3q>Klmf~EEP4766bdkGB=sr0S3j`#3P{H|R zYm}OjK!Kn_Tg5=hd!z&k2)Y@7uwwn7U+o|ea*=!{B-%s$zwHXSfA&xzE?+;amUhie z_)c`Mt;NKdE1mK83-AI$S7{}z#Z`SdMb4|D&LS2k{s&aPX(=V?GZXy#G z5X%7v1y@5r_)Ef!`>>zf_h#3aJtikmZ1ZA{x&%hQ!Vw17qy*dgpC9U3Ay{yu_#{hQ zz>|;ZuVuxCqB4!ulpM}vn56z3ZdmafO|{oG?_|#Y^;64F6vN&FTJw#q34YQPL>^>u z4&@Itp=0trR&^H5bGSw1dE};paFatBg*h`lAOff!1gd3!*W*umX%`U9T+k_QH$aJm+DO57)BJ zXPsMDQd+KX@z0Ob)W$-OIoM!3-HOx}#O7y>z+w}SOSLCSDhi7RAp|iMtC%oQ6mCI; zHUfcU18tQ-vBUAz&Vu}Opb*H{F}lBqd&23H>fdbsodiIp=U<5dl~jZx>XVcJMQZfa zw{PFxAHEF*F;u^=qx>g#z(NcCk1hXX!@Z8!6J{c&QGTNYX^26G|4(mm8jyas5{b(roD@!DCZ_4&Z zK+Z#gX7l`G&Q*i$2KJtX7|`MwI^nb0KplL%*U!Op>plY3g8tF~@)9jsr}JX4P}c6% z&%Ez--J<$SuMvcea{~w+TFt+dN8w4HDA)*t%a|HjUC188b^_(h))N z7@H+kx**PICgXaVUFGFOrG${J4_`RoW>g=t!aOVy4YwTPz+UXwQ?RzVnN?jgZZ~m& zIsH}f#}O%92!Hli#)rG-;)ablBZ_s-WTCRC2^4OKBFU-xm1aP-&&a^}S`DwMfw2_k z=7RYLy)2P4jsiRhE%`SH6g}W{#h8LhLfSz6Ai#gvip^oe**@sg3#gjX|(vOx_}`8Fpic$z3_;(gTDc}Nm ZaSvnJnjj=WASb{;R8e=4#kVbj{|l)V3DW=o literal 0 HcmV?d00001 diff --git a/manifests/authentication.pp b/manifests/authentication.pp new file mode 100644 index 0000000..a7c9fe9 --- /dev/null +++ b/manifests/authentication.pp @@ -0,0 +1,59 @@ +# vim: ts=2 sw=2 et +class splunk::authentication +( + $splunk_home = $splunk::splunk_home, + $authType = $splunk::authtype, + $idptype = $splunk::idptype, + $idpurl = $splunk::idpurl, +){ + case $authType { + 'Splunk': { + augeas { "${splunk_home}/etc/system/local/authentication.conf SAML": + require => Class['splunk::installed'], + lens => 'Puppet.lns', + incl => "${splunk_home}/etc/system/local/authentication.conf", + changes => [ + 'rm authentication/authType', + 'rm authentication/authSettings', + ], + } + } + 'SAML': { + case $idptype { + 'ADFS': { + $attributeQuerySoapPassword = 'unimportant' + $attributeQuerySoapUsername = 'unimportant' + $entityId = $::fqdn + $idpAttributeQueryUrl = $idpurl + $idpSLOUrl = "${idpurl}?wa=wsignout1.0" + $idpSSOUrl = $idpurl + $idpCertPath = "${splunk_home}/etc/auth/idpcert.crt" + $signAuthnRequest = false + $signedAssertion = true + $redirectPort = $splunk::httpport } + default: { + fail 'Unsupported Identity Provider' } + } + augeas { "${splunk_home}/etc/system/local/authentication.conf SAML": + require => Class['splunk::installed'], + lens => 'Puppet.lns', + incl => "${splunk_home}/etc/system/local/authentication.conf", + changes => [ + 'set authentication/authType SAML', + 'set authentication/authSettings saml_settings', + "set saml_settings/attributeQuerySoapPassword ${attributeQuerySoapPassword}", + "set saml_settings/attributeQuerySoapUsername ${attributeQuerySoapUsername}", + "set saml_settings/entityId ${entityId}", + "set saml_settings/idpAttributeQueryUrl ${idpAttributeQueryUrl}", + "set saml_settings/idpSLOUrl ${idpSLOUrl}", + "set saml_settings/idpSSOUrl ${idpSSOUrl}", + "set saml_settings/idpCertPath ${idpCertPath}", + "set saml_settings/redirectPort ${redirectPort}", + "set saml_settings/signAuthnRequest ${signAuthnRequest}", + "set saml_settings/signedAssertion ${signedAssertion}", + ], + } + } + } +} + diff --git a/manifests/init.pp b/manifests/init.pp index a448db4..3f40c8b 100644 --- a/manifests/init.pp +++ b/manifests/init.pp @@ -84,6 +84,9 @@ $useACK = $splunk::params::useACK, $ds_intermediate = $splunk::params::ds_intemediate, $version = $splunk::params::version, + $authtype = $splunk::params::authtype, + $idptype = $splunk::params::idptype, + $idpurl = $splunk::params::idpurl, ) inherits splunk::params { if $type == 'uf' { @@ -126,6 +129,7 @@ include splunk::deploymentclient include splunk::passwd include splunk::service + include splunk::authentication } # ISSUES diff --git a/manifests/inputs.pp b/manifests/inputs.pp index 4f603c6..f5721fc 100644 --- a/manifests/inputs.pp +++ b/manifests/inputs.pp @@ -29,7 +29,7 @@ "set SSL/serverCert '${splunk_home}/etc/auth/certs/s2s.pem'", "set SSL/rootCA '${splunk_home}/etc/auth/certs/ca.crt'", "set SSL/dhfile '${splunk_home}/etc/auth/certs/dhparam.pem'", - "set SSL/ecdhCurveName ${ecdhcurvename}", + 'rm SSL/ecdhCurveName', ]; } } else { @@ -45,7 +45,7 @@ "set SSL/serverCert '${splunk_home}/etc/auth/certs/s2s.pem'", "set SSL/rootCA '${splunk_home}/etc/auth/certs/ca.crt'", "set SSL/dhfile '${splunk_home}/etc/auth/certs/dhparam.pem'", - 'rm SSL/ecdhCurveName', + "set SSL/ecdhCurveName ${ecdhcurvename}", ]; } } diff --git a/manifests/params.pp b/manifests/params.pp index c85e679..a5753c5 100644 --- a/manifests/params.pp +++ b/manifests/params.pp @@ -30,5 +30,8 @@ $useACK = false $ds_intermediate = undef $version = undef + $authtype = 'Splunk' + $idptype = undef + $idpurl = undef }