Files
configpolicy/roles/dch-openvpn-server/files/vpn0.pyrocufflink.blue_ca.crt
Dustin C. Hatch a1ca06a3c5 Move VPN server to dedicated VM
The VPN capability of the UniFi Security Gateway is extremely limited.
It does not support road-warrior IPsec/IKEv2 configuration, and its
OpenVPN configuration is inflexible. As with DHCP, the best solution is
to simply move service to another machine.

To that end, I created a new VM, *vpn0.pyrocufflink.blue*, to host both
strongSwan and OpenVPN. For this to work, the necessary TCP/UDP ports
need to be forwarded, of course, and all of the remote subnets need
static routes on the gateway, specifying this machine as the next hop.
Additionally, ICMP redirects need to be disabled, to prevent confusing
the routing tables of devices on the same subnet as the VPN gateway.
2018-10-07 21:42:18 -05:00

253 lines
14 KiB
Plaintext

Certificate:
Data:
Version: 3 (0x2)
Serial Number:
12:ae:b5:db:96:be:43:b8:8d:31:11:f4:42:91:ef:ee
Signature Algorithm: sha256WithRSAEncryption
Issuer: C=US, O=Dustin C. Hatch, CN=DCH Root CA R1
Validity
Not Before: Feb 21 13:04:10 2018 GMT
Not After : Feb 20 13:04:10 2023 GMT
Subject: C=US, O=Dustin C. Hatch, CN=DCH CA R1
Subject Public Key Info:
Public Key Algorithm: rsaEncryption
Public-Key: (4096 bit)
Modulus:
00:c1:dd:56:e7:5c:9b:65:e0:50:24:39:ba:cd:26:
4e:6c:db:0a:41:ed:d1:10:46:31:b9:ea:e9:5d:04:
f5:8a:21:5a:8b:6e:5c:5c:23:e2:eb:ea:57:8c:fc:
ad:a0:c6:34:a1:2f:31:0a:4b:43:5a:b3:70:de:e9:
12:57:01:0b:c2:d2:df:c1:74:ea:c3:1d:10:95:a4:
86:9f:71:a5:9f:7a:b4:5e:68:58:dd:57:0f:b5:55:
b9:fb:89:6d:e7:3e:fd:92:c1:64:5b:7b:94:19:2e:
c7:d0:71:42:11:b8:d8:a5:9d:87:1f:d7:6b:8b:cb:
d9:76:32:5a:08:79:82:2b:36:ea:3c:79:ce:70:6d:
e3:40:e5:36:17:cf:1b:00:33:63:68:78:27:5a:be:
78:c2:01:92:08:00:2c:f6:08:bb:bf:5f:a4:77:60:
05:c2:1f:e3:21:db:96:d8:c0:b7:0a:72:a5:06:b4:
6e:d3:ee:d6:91:7e:47:fc:4a:1a:98:6a:3a:11:28:
9e:5e:61:02:2c:3d:c9:98:44:a0:9c:8b:19:69:46:
f5:22:32:09:f8:ab:b6:2d:a0:d7:59:61:13:65:2e:
5e:a3:64:7f:bf:4f:2c:94:e6:23:fc:f4:ef:3b:14:
8f:7c:7a:e0:44:53:67:ff:58:f9:1c:68:a4:36:ca:
62:52:46:38:12:a7:ce:64:9b:a1:32:cd:39:b9:f2:
55:47:2c:fa:c8:55:b8:2f:28:45:9a:fc:fc:cd:64:
54:fa:5f:19:fa:7e:dd:b1:e5:cf:65:18:a8:d2:8f:
34:16:83:f4:26:30:e1:a3:7f:b5:44:a0:d1:33:fe:
03:f2:3b:b2:4b:38:c0:e9:b2:03:e6:f4:18:1f:09:
63:e7:dd:26:dc:ec:9e:2b:a3:43:64:d8:fe:d1:76:
c0:c6:a9:92:1a:fa:01:07:15:73:4a:80:09:fa:02:
3e:83:7f:12:bc:00:1f:53:43:04:9e:7f:ac:2f:ff:
e9:cc:f2:06:fe:86:ce:8d:67:46:27:d0:48:de:75:
74:da:c2:18:0c:91:30:11:5c:cf:8e:1b:79:b2:94:
c8:5e:4b:76:1c:da:88:ef:e8:42:f7:4f:b5:9b:76:
fe:1c:b7:1d:ba:b2:0e:b0:db:29:4e:a1:48:03:c8:
0a:62:ab:a0:a5:19:86:ae:19:e8:72:35:0f:72:f0:
dd:1f:1d:29:6a:f2:8d:d4:1d:3e:fc:60:b0:cc:2c:
52:96:2a:f1:b4:5f:ac:d4:5a:e5:05:fc:86:61:e2:
5d:d7:4a:14:ff:f8:e8:60:64:fa:b1:5a:5e:70:d2:
5b:f9:e7:c4:e1:ae:12:d0:6a:48:90:4b:72:19:9d:
92:ef:85
Exponent: 65537 (0x10001)
X509v3 extensions:
X509v3 Basic Constraints: critical
CA:TRUE, pathlen:0
X509v3 Key Usage:
Digital Signature, Certificate Sign, CRL Sign
Authority Information Access:
CA Issuers - URI:http://dustin.hatch.name/dch-ca/dch-root-ca.cer
X509v3 Authority Key Identifier:
keyid:C7:BF:DF:C7:69:05:A9:E8:E3:3E:DB:CE:E6:47:CE:92:2D:27:11:6A
X509v3 CRL Distribution Points:
Full Name:
URI:http://dustin.hatch.name/dch-ca/dch-ca.crl
X509v3 Subject Key Identifier:
EC:79:C5:08:B7:1E:0A:67:C6:E0:34:31:3C:79:D9:D6:83:D9:49:DC
Signature Algorithm: sha256WithRSAEncryption
83:c2:82:7e:fe:a1:c3:c8:47:af:1e:f4:34:53:4f:cd:82:f1:
4b:2c:4b:a5:cb:94:a6:d3:5b:e0:77:f1:fd:1a:05:46:47:19:
43:72:91:b0:95:7e:ad:e0:65:34:47:23:26:09:12:c9:82:c0:
3a:2a:e2:92:e4:e6:c8:07:d0:a0:a9:11:d7:3c:ec:68:99:9c:
88:13:62:0e:0f:d4:78:7a:26:04:ec:80:65:18:ba:0d:a9:8c:
36:0c:af:5c:69:19:04:ac:ea:c0:3c:6e:06:f6:c7:65:ab:89:
fc:83:70:55:85:3e:86:db:77:59:dc:bd:87:7f:cd:e4:da:65:
ab:94:22:ce:a1:7f:a0:12:56:5a:04:8d:c4:86:cc:77:ee:14:
c5:89:bd:d5:9c:92:61:45:74:60:4c:d9:bd:a1:5a:05:8c:ca:
07:89:95:3f:56:ba:e0:ed:c2:b1:70:fe:ae:bd:a1:b3:db:2e:
9c:91:fa:69:de:1f:4f:bf:bc:1b:d2:35:9f:2b:80:53:be:6e:
44:3c:c6:1e:f2:15:42:ad:05:56:27:19:d0:d1:e0:b9:af:5a:
f3:ae:60:e8:bd:84:c0:49:bd:be:0b:d3:87:4e:af:4e:59:7c:
50:27:8b:85:ed:1f:1c:88:6d:34:d8:83:e3:13:56:20:f7:ba:
a1:72:4c:1a:21:3a:1f:dc:0c:b5:35:1a:e5:46:e6:66:7f:05:
90:79:ee:80:48:ea:7a:8c:12:ea:68:4c:c4:f7:6a:83:b2:4b:
ed:ca:16:98:33:4e:ce:5e:8b:a8:f3:05:b0:6c:67:ab:57:69:
24:02:7b:dd:48:4c:35:58:53:15:21:a1:bc:cd:b2:91:f0:cd:
11:44:96:0e:2e:5f:43:88:a1:fc:33:c7:27:46:6d:25:69:23:
d6:17:4c:ee:68:9f:d9:12:86:cb:d1:37:d9:42:bb:1f:35:65:
0c:c0:d1:58:d5:63:35:f0:1c:2d:3b:e1:a2:0f:a7:51:2a:5c:
53:d3:ba:b9:db:92:5a:59:e5:35:b7:c9:f9:b5:ff:bb:a2:e3:
b3:cb:ef:fd:94:36:00:c7:a5:f0:b5:f0:e7:05:b8:df:c0:e7:
61:dc:75:a7:d2:73:f3:15:75:7c:5e:d9:38:17:ad:f7:a8:de:
29:d3:f0:c4:5b:86:be:b9:9d:37:72:fc:65:c8:1f:95:b5:9b:
5d:d6:78:a1:33:09:bd:30:2d:aa:15:72:ee:16:5a:b4:aa:d9:
30:d4:6c:43:03:c3:ea:d0:d4:fc:cf:ce:a7:95:6d:dd:7d:20:
a1:60:4d:30:84:74:3b:3a:46:15:8c:78:e8:31:3b:e3:18:36:
bc:96:4f:f6:9f:48:e4:87
-----BEGIN CERTIFICATE-----
MIIF9DCCA9ygAwIBAgIQEq6125a+Q7iNMRH0QpHv7jANBgkqhkiG9w0BAQsFADBA
MQswCQYDVQQGEwJVUzEYMBYGA1UECgwPRHVzdGluIEMuIEhhdGNoMRcwFQYDVQQD
DA5EQ0ggUm9vdCBDQSBSMTAeFw0xODAyMjExMzA0MTBaFw0yMzAyMjAxMzA0MTBa
MDsxCzAJBgNVBAYTAlVTMRgwFgYDVQQKDA9EdXN0aW4gQy4gSGF0Y2gxEjAQBgNV
BAMMCURDSCBDQSBSMTCCAiIwDQYJKoZIhvcNAQEBBQADggIPADCCAgoCggIBAMHd
Vudcm2XgUCQ5us0mTmzbCkHt0RBGMbnq6V0E9YohWotuXFwj4uvqV4z8raDGNKEv
MQpLQ1qzcN7pElcBC8LS38F06sMdEJWkhp9xpZ96tF5oWN1XD7VVufuJbec+/ZLB
ZFt7lBkux9BxQhG42KWdhx/Xa4vL2XYyWgh5gis26jx5znBt40DlNhfPGwAzY2h4
J1q+eMIBkggALPYIu79fpHdgBcIf4yHbltjAtwpypQa0btPu1pF+R/xKGphqOhEo
nl5hAiw9yZhEoJyLGWlG9SIyCfirti2g11lhE2UuXqNkf79PLJTmI/z07zsUj3x6
4ERTZ/9Y+RxopDbKYlJGOBKnzmSboTLNObnyVUcs+shVuC8oRZr8/M1kVPpfGfp+
3bHlz2UYqNKPNBaD9CYw4aN/tUSg0TP+A/I7sks4wOmyA+b0GB8JY+fdJtzsniuj
Q2TY/tF2wMapkhr6AQcVc0qACfoCPoN/ErwAH1NDBJ5/rC//6czyBv6Gzo1nRifQ
SN51dNrCGAyRMBFcz44bebKUyF5LdhzaiO/oQvdPtZt2/hy3HbqyDrDbKU6hSAPI
CmKroKUZhq4Z6HI1D3Lw3R8dKWryjdQdPvxgsMwsUpYq8bRfrNRa5QX8hmHiXddK
FP/46GBk+rFaXnDSW/nnxOGuEtBqSJBLchmdku+FAgMBAAGjge4wgeswEgYDVR0T
AQH/BAgwBgEB/wIBADALBgNVHQ8EBAMCAYYwSwYIKwYBBQUHAQEEPzA9MDsGCCsG
AQUFBzAChi9odHRwOi8vZHVzdGluLmhhdGNoLm5hbWUvZGNoLWNhL2RjaC1yb290
LWNhLmNlcjAfBgNVHSMEGDAWgBTHv9/HaQWp6OM+287mR86SLScRajA7BgNVHR8E
NDAyMDCgLqAshipodHRwOi8vZHVzdGluLmhhdGNoLm5hbWUvZGNoLWNhL2RjaC1j
YS5jcmwwHQYDVR0OBBYEFOx5xQi3HgpnxuA0MTx52daD2UncMA0GCSqGSIb3DQEB
CwUAA4ICAQCDwoJ+/qHDyEevHvQ0U0/NgvFLLEuly5Sm01vgd/H9GgVGRxlDcpGw
lX6t4GU0RyMmCRLJgsA6KuKS5ObIB9CgqRHXPOxomZyIE2IOD9R4eiYE7IBlGLoN
qYw2DK9caRkErOrAPG4G9sdlq4n8g3BVhT6G23dZ3L2Hf83k2mWrlCLOoX+gElZa
BI3Ehsx37hTFib3VnJJhRXRgTNm9oVoFjMoHiZU/Vrrg7cKxcP6uvaGz2y6ckfpp
3h9Pv7wb0jWfK4BTvm5EPMYe8hVCrQVWJxnQ0eC5r1rzrmDovYTASb2+C9OHTq9O
WXxQJ4uF7R8ciG002IPjE1Yg97qhckwaITof3Ay1NRrlRuZmfwWQee6ASOp6jBLq
aEzE92qDskvtyhaYM07OXouo8wWwbGerV2kkAnvdSEw1WFMVIaG8zbKR8M0RRJYO
Ll9DiKH8M8cnRm0laSPWF0zuaJ/ZEobL0TfZQrsfNWUMwNFY1WM18BwtO+GiD6dR
KlxT07q525JaWeU1t8n5tf+7ouOzy+/9lDYAx6XwtfDnBbjfwOdh3HWn0nPzFXV8
Xtk4F633qN4p0/DEW4a+uZ03cvxlyB+VtZtd1nihMwm9MC2qFXLuFlq0qtkw1GxD
A8Pq0NT8z86nlW3dfSChYE0whHQ7OkYVjHjoMTvjGDa8lk/2n0jkhw==
-----END CERTIFICATE-----
Certificate:
Data:
Version: 3 (0x2)
Serial Number:
dd:bd:2c:48:e1:89:43:d8:8a:ae:6c:74:81:dd:39:64
Signature Algorithm: sha256WithRSAEncryption
Issuer: C=US, O=Dustin C. Hatch, CN=DCH Root CA R1
Validity
Not Before: Feb 21 12:05:04 2018 GMT
Not After : Feb 16 12:05:04 2038 GMT
Subject: C=US, O=Dustin C. Hatch, CN=DCH Root CA R1
Subject Public Key Info:
Public Key Algorithm: rsaEncryption
Public-Key: (4096 bit)
Modulus:
00:c6:1e:d9:7c:58:4c:92:fe:03:cf:4b:56:0c:6e:
a8:2a:53:7c:50:86:2a:c4:ff:20:36:15:60:ff:bc:
d6:af:b2:f5:b0:12:c3:d3:ae:92:7d:74:ba:cb:be:
84:5c:f8:97:7d:6f:9c:53:b5:8e:75:d0:96:66:53:
98:18:82:ce:61:83:a8:5d:69:4c:9d:17:54:f6:6b:
a7:ed:55:d7:1b:d6:7d:03:58:42:90:63:2e:a3:fa:
53:68:33:46:87:06:24:c2:26:8b:fd:18:eb:99:4e:
1c:b6:a4:c7:ab:75:0e:e3:57:e9:01:e0:2a:4d:de:
3d:cd:57:27:2a:d3:8a:91:04:0c:32:47:a6:1f:6c:
5d:08:ee:d4:62:3d:24:f0:13:26:9a:52:af:15:f6:
85:1a:d8:a9:99:4e:01:1b:33:83:6a:53:af:9d:90:
63:dd:02:7c:04:49:24:8f:22:7a:12:38:93:b9:9a:
54:7a:b6:9a:8a:e4:64:df:11:25:3a:d9:1f:ff:28:
3a:12:44:15:7e:4d:75:e6:a0:f0:94:d1:be:e2:b3:
54:a8:86:1c:a6:49:ff:1c:63:80:39:ea:17:5e:2f:
4a:73:8f:98:ce:ed:b0:fa:45:31:fb:db:05:10:0e:
95:79:8b:9c:a2:d5:d7:ac:4a:d7:36:49:f5:bd:27:
ad:04:86:76:7a:07:b3:04:bf:4e:36:c8:0c:b4:2b:
31:c4:c0:86:f6:14:cc:41:42:f5:1c:26:4e:45:6e:
62:b6:4f:74:ad:66:32:d3:be:d3:62:81:e3:a3:61:
3c:69:9a:ef:55:41:a6:5e:53:d8:56:c5:45:a6:84:
7b:0b:cd:fe:7c:ba:dc:69:bb:0a:20:94:c8:fd:7a:
e5:18:4b:50:60:cc:7c:d9:b5:5e:10:9c:f7:6e:5d:
f6:57:81:82:1f:53:6e:81:7c:c1:ba:79:ad:e4:d7:
da:47:16:9f:21:d1:3e:c2:9f:34:e3:ac:f4:c7:df:
a6:82:3b:69:fb:91:5b:26:63:8d:ed:92:58:3b:ae:
0f:a6:b0:5e:15:d6:4c:3f:0b:78:74:d0:72:4f:2b:
47:57:0e:4d:2b:d9:20:1a:3a:b6:bc:61:49:37:54:
93:61:90:1c:8b:91:d0:94:f4:4a:92:41:35:0a:b6:
11:85:4d:ab:44:c9:69:8d:c3:cb:b9:b2:4d:30:e6:
51:67:29:2b:3f:00:cf:ea:b4:86:7f:3e:44:51:cc:
ac:a6:99:d1:6d:25:47:61:c2:49:ea:4a:13:b0:f4:
5f:f5:b6:4f:17:0b:4a:a2:6c:3c:da:33:28:0f:ef:
bb:52:05:38:3b:41:36:b1:4a:3b:36:b8:a4:74:5e:
5d:b9:81
Exponent: 65537 (0x10001)
X509v3 extensions:
X509v3 Basic Constraints: critical
CA:TRUE
X509v3 Key Usage: critical
Certificate Sign, CRL Sign
X509v3 Subject Key Identifier:
C7:BF:DF:C7:69:05:A9:E8:E3:3E:DB:CE:E6:47:CE:92:2D:27:11:6A
Signature Algorithm: sha256WithRSAEncryption
53:15:96:21:e0:8a:fb:1d:1f:cf:ed:9b:df:cf:ea:7d:42:51:
bd:01:c5:08:86:83:0f:8f:66:39:55:c2:28:1e:bb:3a:ca:d1:
cf:91:cd:cd:cf:cb:3f:ad:6a:9a:ac:f9:7c:28:20:e8:8a:de:
55:51:12:cb:2e:41:e2:b4:88:c1:65:65:57:50:f7:0d:05:12:
78:5c:7f:1a:4f:26:5e:00:d8:af:f0:d6:d9:8c:27:56:dc:de:
c4:ba:ff:3a:8d:ef:19:21:c6:63:da:26:ac:f1:1d:ba:04:1e:
ac:41:6d:bb:9d:b7:c3:b5:9a:90:c1:60:2d:a8:b6:df:fe:f7:
e6:0b:41:62:e5:ee:8e:2c:0a:60:05:b5:9e:9f:9c:74:07:6e:
92:bc:bc:a5:86:23:58:d1:f9:b6:d4:be:15:1b:17:4a:48:89:
3a:07:7f:85:88:92:ab:4d:50:6a:ee:8a:a4:a7:41:06:83:c6:
87:f9:e9:fa:e0:ee:62:c4:30:77:5d:f6:0a:86:71:06:bf:97:
e9:e0:35:62:4d:1b:d9:91:e1:d9:f0:bb:99:38:a1:57:35:35:
89:63:08:b9:61:0c:28:3c:2f:48:b0:75:70:57:73:11:04:f7:
60:f2:b5:5f:4c:15:6a:ae:f3:6f:3b:7c:da:07:5b:db:6f:b0:
cd:38:52:8d:d3:f8:6a:09:2b:6d:f2:ba:62:cb:ad:55:54:a5:
d3:c4:ce:39:97:44:19:2b:67:17:6b:f2:16:84:4c:08:b8:09:
82:c9:6e:5d:de:28:db:51:a0:00:a3:f4:4f:d5:64:26:4b:96:
d7:9d:03:a7:60:3c:0b:d9:2b:ce:6e:b9:3f:02:b9:31:53:79:
70:e5:5e:89:a1:88:4c:32:ed:3a:84:1c:b7:0d:dc:56:04:ba:
b4:4d:11:8e:c3:5d:d8:08:09:78:9d:fe:b4:51:b5:1e:6d:c1:
89:fe:49:f9:a8:af:ec:da:fa:ea:4e:4d:e2:d8:40:35:75:39:
8f:f1:9f:cf:9a:d5:24:26:ec:2c:60:6d:10:d5:9b:ba:f8:22:
49:f8:b9:95:f8:80:82:af:1e:d2:2d:f4:b8:bb:62:58:a1:4b:
5d:4f:c8:9e:f5:d0:78:db:5a:fe:c7:dc:92:47:8e:40:7f:1c:
8d:f0:b1:68:8a:d9:6d:89:42:de:1a:b6:8c:04:94:3b:2e:4c:
fc:b8:b6:95:59:e6:d4:91:39:31:3e:f4:f2:74:b7:92:26:8c:
46:ba:98:ff:85:c1:70:64:e6:9c:91:4c:a9:0e:ce:07:ed:19:
86:c6:2d:7e:2c:e1:3b:9a:8a:9f:d0:83:48:05:9d:46:5b:90:
21:0d:fa:a0:38:15:9f:8a
-----BEGIN CERTIFICATE-----
MIIFTTCCAzWgAwIBAgIRAN29LEjhiUPYiq5sdIHdOWQwDQYJKoZIhvcNAQELBQAw
QDELMAkGA1UEBhMCVVMxGDAWBgNVBAoMD0R1c3RpbiBDLiBIYXRjaDEXMBUGA1UE
AwwORENIIFJvb3QgQ0EgUjEwHhcNMTgwMjIxMTIwNTA0WhcNMzgwMjE2MTIwNTA0
WjBAMQswCQYDVQQGEwJVUzEYMBYGA1UECgwPRHVzdGluIEMuIEhhdGNoMRcwFQYD
VQQDDA5EQ0ggUm9vdCBDQSBSMTCCAiIwDQYJKoZIhvcNAQEBBQADggIPADCCAgoC
ggIBAMYe2XxYTJL+A89LVgxuqCpTfFCGKsT/IDYVYP+81q+y9bASw9Oukn10usu+
hFz4l31vnFO1jnXQlmZTmBiCzmGDqF1pTJ0XVPZrp+1V1xvWfQNYQpBjLqP6U2gz
RocGJMImi/0Y65lOHLakx6t1DuNX6QHgKk3ePc1XJyrTipEEDDJHph9sXQju1GI9
JPATJppSrxX2hRrYqZlOARszg2pTr52QY90CfARJJI8iehI4k7maVHq2morkZN8R
JTrZH/8oOhJEFX5Ndeag8JTRvuKzVKiGHKZJ/xxjgDnqF14vSnOPmM7tsPpFMfvb
BRAOlXmLnKLV16xK1zZJ9b0nrQSGdnoHswS/TjbIDLQrMcTAhvYUzEFC9RwmTkVu
YrZPdK1mMtO+02KB46NhPGma71VBpl5T2FbFRaaEewvN/ny63Gm7CiCUyP165RhL
UGDMfNm1XhCc925d9leBgh9TboF8wbp5reTX2kcWnyHRPsKfNOOs9MffpoI7afuR
WyZjje2SWDuuD6awXhXWTD8LeHTQck8rR1cOTSvZIBo6trxhSTdUk2GQHIuR0JT0
SpJBNQq2EYVNq0TJaY3Dy7myTTDmUWcpKz8Az+q0hn8+RFHMrKaZ0W0lR2HCSepK
E7D0X/W2TxcLSqJsPNozKA/vu1IFODtBNrFKOza4pHReXbmBAgMBAAGjQjBAMA8G
A1UdEwEB/wQFMAMBAf8wDgYDVR0PAQH/BAQDAgEGMB0GA1UdDgQWBBTHv9/HaQWp
6OM+287mR86SLScRajANBgkqhkiG9w0BAQsFAAOCAgEAUxWWIeCK+x0fz+2b38/q
fUJRvQHFCIaDD49mOVXCKB67OsrRz5HNzc/LP61qmqz5fCgg6IreVVESyy5B4rSI
wWVlV1D3DQUSeFx/Gk8mXgDYr/DW2YwnVtzexLr/Oo3vGSHGY9omrPEdugQerEFt
u523w7WakMFgLai23/735gtBYuXujiwKYAW1np+cdAdukry8pYYjWNH5ttS+FRsX
SkiJOgd/hYiSq01Qau6KpKdBBoPGh/np+uDuYsQwd132CoZxBr+X6eA1Yk0b2ZHh
2fC7mTihVzU1iWMIuWEMKDwvSLB1cFdzEQT3YPK1X0wVaq7zbzt82gdb22+wzThS
jdP4agkrbfK6YsutVVSl08TOOZdEGStnF2vyFoRMCLgJgsluXd4o21GgAKP0T9Vk
JkuW150Dp2A8C9krzm65PwK5MVN5cOVeiaGITDLtOoQctw3cVgS6tE0RjsNd2AgJ
eJ3+tFG1Hm3Bif5J+aiv7Nr66k5N4thANXU5j/Gfz5rVJCbsLGBtENWbuvgiSfi5
lfiAgq8e0i30uLtiWKFLXU/InvXQeNta/sfckkeOQH8cjfCxaIrZbYlC3hq2jASU
Oy5M/Li2lVnm1JE5MT708nS3kiaMRrqY/4XBcGTmnJFMqQ7OB+0ZhsYtfizhO5qK
n9CDSAWdRluQIQ36oDgVn4o=
-----END CERTIFICATE-----