diff --git a/content/rancher/v2.6/en/security/_index.md b/content/rancher/v2.6/en/security/_index.md index 1f121f11ed2..0cd5e3dcaf4 100644 --- a/content/rancher/v2.6/en/security/_index.md +++ b/content/rancher/v2.6/en/security/_index.md @@ -11,7 +11,7 @@ weight: 20

Reporting process

-

Please submit possible security issues by emailing security@rancher.com .

+

Please submit possible security issues by emailing security-rancher@suse.com .

Announcements

diff --git a/content/rancher/v2.6/en/security/hardening-guides/1.6-benchmark-2.6/Rancher_v2-6_CIS_v1-6_Benchmark_Assessment.pdf b/content/rancher/v2.6/en/security/hardening-guides/1.6-benchmark-2.6/Rancher_v2-6_CIS_v1-6_Benchmark_Assessment.pdf new file mode 100644 index 00000000000..cba5bceac24 --- /dev/null +++ b/content/rancher/v2.6/en/security/hardening-guides/1.6-benchmark-2.6/Rancher_v2-6_CIS_v1-6_Benchmark_Assessment.pdf @@ -0,0 +1,14756 @@ +%PDF-1.7 +%🖤 +1 0 obj +<< +/Type /Pages +/Kids [ 6 0 R 8 0 R 38 0 R 76 0 R 114 0 R 152 0 R 186 0 R 222 0 R 258 0 R 292 0 R 304 0 R 309 0 R 313 0 R 315 0 R 318 0 R 321 0 R 345 0 R 370 0 R 403 0 R 436 0 R 460 0 R 499 0 R 505 0 R 508 0 R 511 0 R 514 0 R 516 0 R 519 0 R 521 0 R 524 0 R 527 0 R 529 0 R 532 0 R 534 0 R 537 0 R 540 0 R 542 0 R 545 0 R 547 0 R 550 0 R 553 0 R 555 0 R 559 0 R 562 0 R 565 0 R 567 0 R 570 0 R 572 0 R 575 0 R 577 0 R 580 0 R 583 0 R 585 0 R 588 0 R 591 0 R 593 0 R 596 0 R 598 0 R 601 0 R 604 0 R 606 0 R 609 0 R 611 0 R 614 0 R 617 0 R 619 0 R 622 0 R 624 0 R 627 0 R 630 0 R 632 0 R 635 0 R 637 0 R 640 0 R 643 0 R 645 0 R 667 0 R 676 0 R 679 0 R 683 0 R 686 0 R 689 0 R 692 0 R 694 0 R 698 0 R 700 0 R 703 0 R 705 0 R 708 0 R 710 0 R 713 0 R 715 0 R 718 0 R 720 0 R 722 0 R 725 0 R 727 0 R 730 0 R 732 0 R 735 0 R 737 0 R 739 0 R 741 0 R 744 0 R 746 0 R 749 0 R 753 0 R 762 0 R 770 0 R 772 0 R 777 0 R 782 0 R 788 0 R 792 0 R 796 0 R 802 0 R 806 0 R 810 0 R 813 0 R 815 0 R 840 0 R 851 0 R 854 0 R 858 0 R 861 0 R 878 0 R 885 0 R 887 0 R 889 0 R 891 0 R ] +/Count 130 +>> +endobj +2 0 obj +<< +/Title (CIS v1.6 Benchmark - Self-Assessment Guide - Rancher v2.6) +/Creator (pandoc) +/Producer (WeasyPrint 54.1) +>> +endobj +3 0 obj +<< +/Type /Catalog +/Pages 1 0 R +/Outlines 1053 0 R +/Names << +/Dests << +/Names [ (TOC) [ 8 0 R /XYZ 77.509843 756.850394 0 ] (api-server) [ 508 0 R /XYZ 41.740157 784.430079 0 ] (apply-security-context-to-your-pods-and-containers-manual) [ 889 0 R /XYZ 84.259843 324.051496 0 ] (authentication-and-authorization) [ 739 0 R /XYZ 41.740157 784.430079 0 ] (cb1) [ 315 0 R /XYZ 84.259843 207.170079 0 ] (cb1-1) [ 315 0 R /XYZ 101.433071 205.473057 0 ] (cb101) [ 624 0 R /XYZ 84.259843 715.370079 0 ] (cb101-1) [ 624 0 R /XYZ 101.433071 713.673057 0 ] (cb104) [ 627 0 R /XYZ 84.259843 241.820079 0 ] (cb104-1) [ 627 0 R /XYZ 101.433071 240.123057 0 ] (cb107) [ 632 0 R /XYZ 84.259843 463.070079 0 ] (cb107-1) [ 632 0 R /XYZ 101.433071 461.373057 0 ] (cb11) [ 436 0 R /XYZ 84.259843 543.320079 0 ] (cb11-1) [ 436 0 R /XYZ 101.433071 541.623057 0 ] (cb11-10) [ 436 0 R /XYZ 99.933071 333.205821 0 ] (cb11-11) [ 436 0 R /XYZ 99.933071 314.258799 0 ] (cb11-12) [ 436 0 R /XYZ 99.933071 295.311778 0 ] (cb11-13) [ 436 0 R /XYZ 99.933071 276.364756 0 ] (cb11-14) [ 436 0 R /XYZ 99.933071 257.417735 0 ] (cb11-15) [ 436 0 R /XYZ 99.933071 238.470714 0 ] (cb11-16) [ 436 0 R /XYZ 99.933071 219.523692 0 ] (cb11-17) [ 436 0 R /XYZ 99.933071 200.576671 0 ] (cb11-18) [ 436 0 R /XYZ 99.933071 181.629649 0 ] (cb11-19) [ 436 0 R /XYZ 99.933071 162.682628 0 ] (cb11-2) [ 436 0 R /XYZ 99.933071 522.676036 0 ] (cb11-20) [ 436 0 R /XYZ 99.933071 143.735606 0 ] (cb11-21) [ 436 0 R /XYZ 99.933071 124.788585 0 ] (cb11-22) [ 436 0 R /XYZ 99.933071 105.841563 0 ] (cb11-23) [ 460 0 R /XYZ 99.933071 799.173057 0 ] (cb11-24) [ 460 0 R /XYZ 99.933071 780.226036 0 ] (cb11-25) [ 460 0 R /XYZ 99.933071 761.279014 0 ] (cb11-26) [ 460 0 R /XYZ 99.933071 742.331993 0 ] (cb11-27) [ 460 0 R /XYZ 99.933071 723.384971 0 ] (cb11-28) [ 460 0 R /XYZ 99.933071 704.437950 0 ] (cb11-29) [ 460 0 R /XYZ 99.933071 685.490928 0 ] (cb11-3) [ 436 0 R /XYZ 99.933071 503.729014 0 ] (cb11-30) [ 460 0 R /XYZ 99.933071 666.543907 0 ] (cb11-31) [ 460 0 R /XYZ 99.933071 647.596885 0 ] (cb11-32) [ 460 0 R /XYZ 99.933071 628.649864 0 ] (cb11-33) [ 460 0 R /XYZ 99.933071 609.702842 0 ] (cb11-34) [ 460 0 R /XYZ 99.933071 590.755821 0 ] (cb11-35) [ 460 0 R /XYZ 99.933071 571.808799 0 ] (cb11-36) [ 460 0 R /XYZ 99.933071 552.861778 0 ] (cb11-37) [ 460 0 R /XYZ 99.933071 533.914756 0 ] (cb11-38) [ 460 0 R /XYZ 99.933071 514.967735 0 ] (cb11-39) [ 460 0 R /XYZ 99.933071 496.020714 0 ] (cb11-4) [ 436 0 R /XYZ 99.933071 465.834971 0 ] (cb11-40) [ 460 0 R /XYZ 99.933071 477.073692 0 ] (cb11-41) [ 460 0 R /XYZ 99.933071 458.126671 0 ] (cb11-42) [ 460 0 R /XYZ 99.933071 439.179649 0 ] (cb11-43) [ 460 0 R /XYZ 99.933071 420.232628 0 ] (cb11-44) [ 460 0 R /XYZ 99.933071 401.285606 0 ] (cb11-45) [ 460 0 R /XYZ 99.933071 382.338585 0 ] (cb11-46) [ 460 0 R /XYZ 99.933071 363.391563 0 ] (cb11-47) [ 460 0 R /XYZ 99.933071 344.444542 0 ] (cb11-48) [ 460 0 R /XYZ 99.933071 325.497520 0 ] (cb11-49) [ 460 0 R /XYZ 99.933071 306.550499 0 ] (cb11-5) [ 436 0 R /XYZ 99.933071 427.940928 0 ] (cb11-50) [ 460 0 R /XYZ 99.933071 287.603477 0 ] (cb11-51) [ 460 0 R /XYZ 99.933071 268.656456 0 ] (cb11-52) [ 460 0 R /XYZ 99.933071 249.709434 0 ] (cb11-53) [ 460 0 R /XYZ 99.933071 211.815391 0 ] (cb11-54) [ 460 0 R /XYZ 99.933071 192.868370 0 ] (cb11-55) [ 460 0 R /XYZ 99.933071 173.921348 0 ] (cb11-56) [ 460 0 R /XYZ 99.933071 154.974327 0 ] (cb11-57) [ 460 0 R /XYZ 99.933071 136.027305 0 ] (cb11-58) [ 460 0 R /XYZ 99.933071 117.080284 0 ] (cb11-59) [ 460 0 R /XYZ 99.933071 98.133262 0 ] (cb11-6) [ 436 0 R /XYZ 99.933071 408.993907 0 ] (cb11-60) [ 499 0 R /XYZ 99.933071 799.173057 0 ] (cb11-61) [ 499 0 R /XYZ 99.933071 780.226036 0 ] (cb11-7) [ 436 0 R /XYZ 99.933071 390.046885 0 ] (cb11-8) [ 436 0 R /XYZ 99.933071 371.099864 0 ] (cb11-9) [ 436 0 R /XYZ 99.933071 352.152842 0 ] (cb110) [ 637 0 R /XYZ 84.259843 715.370079 0 ] (cb110-1) [ 637 0 R /XYZ 101.433071 713.673057 0 ] (cb113) [ 640 0 R /XYZ 84.259843 241.820079 0 ] (cb113-1) [ 640 0 R /XYZ 101.433071 240.123057 0 ] (cb116) [ 645 0 R /XYZ 84.259843 511.820079 0 ] (cb116-1) [ 645 0 R /XYZ 101.433071 510.123057 0 ] (cb116-10) [ 645 0 R /XYZ 99.933071 282.758799 0 ] (cb116-11) [ 645 0 R /XYZ 99.933071 263.811778 0 ] (cb116-12) [ 645 0 R /XYZ 99.933071 244.864756 0 ] (cb116-13) [ 645 0 R /XYZ 99.933071 225.917735 0 ] (cb116-14) [ 645 0 R /XYZ 99.933071 206.970714 0 ] (cb116-15) [ 645 0 R /XYZ 99.933071 188.023692 0 ] (cb116-16) [ 645 0 R /XYZ 99.933071 169.076671 0 ] (cb116-17) [ 645 0 R /XYZ 99.933071 150.129649 0 ] (cb116-18) [ 645 0 R /XYZ 99.933071 131.182628 0 ] (cb116-19) [ 645 0 R /XYZ 99.933071 112.235606 0 ] (cb116-2) [ 645 0 R /XYZ 99.933071 491.176036 0 ] (cb116-20) [ 645 0 R /XYZ 99.933071 93.288585 0 ] (cb116-21) [ 667 0 R /XYZ 99.933071 799.173057 0 ] (cb116-22) [ 667 0 R /XYZ 99.933071 780.226036 0 ] (cb116-23) [ 667 0 R /XYZ 99.933071 761.279014 0 ] (cb116-24) [ 667 0 R /XYZ 99.933071 742.331993 0 ] (cb116-25) [ 667 0 R /XYZ 99.933071 723.384971 0 ] (cb116-3) [ 645 0 R /XYZ 99.933071 472.229014 0 ] (cb116-4) [ 645 0 R /XYZ 99.933071 434.334971 0 ] (cb116-5) [ 645 0 R /XYZ 99.933071 415.387950 0 ] (cb116-6) [ 645 0 R /XYZ 99.933071 396.440928 0 ] (cb116-7) [ 645 0 R /XYZ 99.933071 377.493907 0 ] (cb116-8) [ 645 0 R /XYZ 99.933071 358.546885 0 ] (cb116-9) [ 645 0 R /XYZ 99.933071 320.652842 0 ] (cb117) [ 667 0 R /XYZ 84.259843 664.134971 0 ] (cb117-1) [ 667 0 R /XYZ 101.433071 662.437950 0 ] (cb12) [ 499 0 R /XYZ 84.259843 720.976036 0 ] (cb12-1) [ 499 0 R /XYZ 101.433071 719.279014 0 ] (cb120) [ 667 0 R /XYZ 84.259843 290.887950 0 ] (cb120-1) [ 667 0 R /XYZ 101.433071 289.190928 0 ] (cb121) [ 676 0 R /XYZ 84.259843 550.251496 0 ] (cb121-1) [ 676 0 R /XYZ 101.433071 548.554475 0 ] (cb124) [ 679 0 R /XYZ 84.259843 715.370079 0 ] (cb124-1) [ 679 0 R /XYZ 101.433071 713.673057 0 ] (cb127) [ 679 0 R /XYZ 84.259843 162.123057 0 ] (cb127-1) [ 679 0 R /XYZ 101.433071 160.426036 0 ] (cb130) [ 683 0 R /XYZ 84.259843 325.820079 0 ] (cb130-1) [ 683 0 R /XYZ 101.433071 324.123057 0 ] (cb133) [ 686 0 R /XYZ 84.259843 500.570079 0 ] (cb133-1) [ 686 0 R /XYZ 101.433071 498.873057 0 ] (cb136) [ 689 0 R /XYZ 84.259843 441.170079 0 ] (cb136-1) [ 689 0 R /XYZ 101.433071 439.473057 0 ] (cb139) [ 694 0 R /XYZ 84.259843 565.251496 0 ] (cb139-1) [ 694 0 R /XYZ 101.433071 563.554475 0 ] (cb142) [ 694 0 R /XYZ 84.259843 214.504475 0 ] (cb142-1) [ 694 0 R /XYZ 101.433071 212.807453 0 ] (cb145) [ 700 0 R /XYZ 84.259843 514.251496 0 ] (cb145-1) [ 700 0 R /XYZ 101.433071 512.554475 0 ] (cb148) [ 705 0 R /XYZ 84.259843 403.070079 0 ] (cb148-1) [ 705 0 R /XYZ 101.433071 401.373057 0 ] (cb15) [ 499 0 R /XYZ 84.259843 392.729014 0 ] (cb15-1) [ 499 0 R /XYZ 101.433071 391.031993 0 ] (cb151) [ 710 0 R /XYZ 84.259843 290.570079 0 ] (cb151-1) [ 710 0 R /XYZ 101.433071 288.873057 0 ] (cb154) [ 715 0 R /XYZ 84.259843 148.070079 0 ] (cb154-1) [ 715 0 R /XYZ 101.433071 146.373057 0 ] (cb157) [ 722 0 R /XYZ 84.259843 715.370079 0 ] (cb157-1) [ 722 0 R /XYZ 101.433071 713.673057 0 ] (cb160) [ 727 0 R /XYZ 84.259843 571.820079 0 ] (cb160-1) [ 727 0 R /XYZ 101.433071 570.123057 0 ] (cb163) [ 732 0 R /XYZ 84.259843 425.570079 0 ] (cb163-1) [ 732 0 R /XYZ 101.433071 423.873057 0 ] (cb166) [ 741 0 R /XYZ 84.259843 595.251496 0 ] (cb166-1) [ 741 0 R /XYZ 101.433071 593.554475 0 ] (cb169) [ 746 0 R /XYZ 84.259843 267.651496 0 ] (cb169-1) [ 746 0 R /XYZ 101.433071 265.954475 0 ] (cb172) [ 749 0 R /XYZ 84.259843 607.820079 0 ] (cb172-1) [ 749 0 R /XYZ 101.433071 606.123057 0 ] (cb174) [ 749 0 R /XYZ 84.259843 298.679014 0 ] (cb174-1) [ 749 0 R /XYZ 101.433071 296.981993 0 ] (cb176) [ 753 0 R /XYZ 84.259843 715.370079 0 ] (cb176-1) [ 753 0 R /XYZ 101.433071 713.673057 0 ] (cb179) [ 753 0 R /XYZ 84.259843 375.479014 0 ] (cb179-1) [ 753 0 R /XYZ 101.433071 373.781993 0 ] (cb179-2) [ 753 0 R /XYZ 99.933071 354.834971 0 ] (cb179-3) [ 753 0 R /XYZ 99.933071 335.887950 0 ] (cb179-4) [ 753 0 R /XYZ 99.933071 279.046885 0 ] (cb179-5) [ 753 0 R /XYZ 99.933071 260.099864 0 ] (cb18) [ 505 0 R /XYZ 84.259843 715.370079 0 ] (cb18-1) [ 505 0 R /XYZ 101.433071 713.673057 0 ] (cb180) [ 753 0 R /XYZ 84.259843 200.849864 0 ] (cb180-1) [ 753 0 R /XYZ 101.433071 199.152842 0 ] (cb182) [ 762 0 R /XYZ 84.259843 655.220079 0 ] (cb182-1) [ 762 0 R /XYZ 101.433071 653.523057 0 ] (cb182-2) [ 762 0 R /XYZ 99.933071 634.576036 0 ] (cb182-3) [ 762 0 R /XYZ 99.933071 615.629014 0 ] (cb182-4) [ 762 0 R /XYZ 99.933071 558.787950 0 ] (cb182-5) [ 762 0 R /XYZ 99.933071 539.840928 0 ] (cb183) [ 762 0 R /XYZ 84.259843 480.590928 0 ] (cb183-1) [ 762 0 R /XYZ 101.433071 478.893907 0 ] (cb185) [ 772 0 R /XYZ 84.259843 490.251496 0 ] (cb185-1) [ 772 0 R /XYZ 101.433071 488.554475 0 ] (cb186) [ 772 0 R /XYZ 84.259843 429.304475 0 ] (cb186-1) [ 772 0 R /XYZ 101.433071 427.607453 0 ] (cb188) [ 772 0 R /XYZ 84.259843 116.807453 0 ] (cb188-1) [ 772 0 R /XYZ 101.433071 115.110432 0 ] (cb189) [ 777 0 R /XYZ 84.259843 772.370079 0 ] (cb189-1) [ 777 0 R /XYZ 101.433071 770.673057 0 ] (cb191) [ 777 0 R /XYZ 84.259843 459.873057 0 ] (cb191-1) [ 777 0 R /XYZ 101.433071 458.176036 0 ] (cb192) [ 777 0 R /XYZ 84.259843 398.926036 0 ] (cb192-1) [ 777 0 R /XYZ 101.433071 397.229014 0 ] (cb194) [ 782 0 R /XYZ 84.259843 799.370079 0 ] (cb194-1) [ 782 0 R /XYZ 101.433071 797.673057 0 ] (cb195) [ 782 0 R /XYZ 84.259843 738.423057 0 ] (cb195-1) [ 782 0 R /XYZ 101.433071 736.726036 0 ] (cb197) [ 782 0 R /XYZ 84.259843 410.926036 0 ] (cb197-1) [ 782 0 R /XYZ 101.433071 409.229014 0 ] (cb198) [ 782 0 R /XYZ 84.259843 349.979014 0 ] (cb198-1) [ 782 0 R /XYZ 101.433071 348.281993 0 ] (cb2) [ 318 0 R /XYZ 84.259843 730.370079 0 ] (cb2-1) [ 318 0 R /XYZ 101.433071 728.673057 0 ] (cb201) [ 788 0 R /XYZ 84.259843 230.570079 0 ] (cb201-1) [ 788 0 R /XYZ 101.433071 228.873057 0 ] (cb202) [ 788 0 R /XYZ 84.259843 169.623057 0 ] (cb202-1) [ 788 0 R /XYZ 101.433071 167.926036 0 ] (cb204) [ 792 0 R /XYZ 84.259843 583.970079 0 ] (cb204-1) [ 792 0 R /XYZ 101.433071 582.273057 0 ] (cb205) [ 792 0 R /XYZ 84.259843 523.023057 0 ] (cb205-1) [ 792 0 R /XYZ 101.433071 521.326036 0 ] (cb207) [ 796 0 R /XYZ 84.259843 700.370079 0 ] (cb207-1) [ 796 0 R /XYZ 101.433071 698.673057 0 ] (cb208) [ 796 0 R /XYZ 84.259843 639.423057 0 ] (cb208-1) [ 796 0 R /XYZ 101.433071 637.726036 0 ] (cb21) [ 508 0 R /XYZ 84.259843 565.251496 0 ] (cb21-1) [ 508 0 R /XYZ 101.433071 563.554475 0 ] (cb210) [ 796 0 R /XYZ 84.259843 296.926036 0 ] (cb210-1) [ 796 0 R /XYZ 101.433071 295.229014 0 ] (cb211) [ 796 0 R /XYZ 84.259843 235.979014 0 ] (cb211-1) [ 796 0 R /XYZ 101.433071 234.281993 0 ] (cb213) [ 802 0 R /XYZ 84.259843 640.370079 0 ] (cb213-1) [ 802 0 R /XYZ 101.433071 638.673057 0 ] (cb214) [ 802 0 R /XYZ 84.259843 579.423057 0 ] (cb214-1) [ 802 0 R /XYZ 101.433071 577.726036 0 ] (cb217) [ 806 0 R /XYZ 84.259843 428.570079 0 ] (cb217-1) [ 806 0 R /XYZ 101.433071 426.873057 0 ] (cb218) [ 806 0 R /XYZ 84.259843 131.823057 0 ] (cb218-1) [ 806 0 R /XYZ 101.433071 130.126036 0 ] (cb219) [ 810 0 R /XYZ 84.259843 799.370079 0 ] (cb219-1) [ 810 0 R /XYZ 101.433071 797.673057 0 ] (cb221) [ 815 0 R /XYZ 84.259843 768.620079 0 ] (cb221-1) [ 815 0 R /XYZ 101.433071 766.923057 0 ] (cb221-10) [ 815 0 R /XYZ 99.933071 596.399864 0 ] (cb221-11) [ 815 0 R /XYZ 99.933071 577.452842 0 ] (cb221-12) [ 815 0 R /XYZ 99.933071 482.717735 0 ] (cb221-13) [ 815 0 R /XYZ 99.933071 463.770714 0 ] (cb221-14) [ 815 0 R /XYZ 99.933071 444.823692 0 ] (cb221-15) [ 815 0 R /XYZ 99.933071 425.876671 0 ] (cb221-16) [ 815 0 R /XYZ 99.933071 406.929649 0 ] (cb221-17) [ 815 0 R /XYZ 99.933071 387.982628 0 ] (cb221-18) [ 815 0 R /XYZ 99.933071 350.088585 0 ] (cb221-19) [ 815 0 R /XYZ 99.933071 331.141563 0 ] (cb221-2) [ 815 0 R /XYZ 99.933071 747.976036 0 ] (cb221-20) [ 815 0 R /XYZ 99.933071 198.512413 0 ] (cb221-21) [ 815 0 R /XYZ 99.933071 179.565391 0 ] (cb221-22) [ 815 0 R /XYZ 99.933071 160.618370 0 ] (cb221-23) [ 815 0 R /XYZ 99.933071 103.777305 0 ] (cb221-24) [ 840 0 R /XYZ 99.933071 799.173057 0 ] (cb221-25) [ 840 0 R /XYZ 99.933071 780.226036 0 ] (cb221-26) [ 840 0 R /XYZ 99.933071 761.279014 0 ] (cb221-27) [ 840 0 R /XYZ 99.933071 742.331993 0 ] (cb221-28) [ 840 0 R /XYZ 99.933071 723.384971 0 ] (cb221-29) [ 840 0 R /XYZ 99.933071 704.437950 0 ] (cb221-3) [ 815 0 R /XYZ 99.933071 729.029014 0 ] (cb221-30) [ 840 0 R /XYZ 99.933071 685.490928 0 ] (cb221-31) [ 840 0 R /XYZ 99.933071 666.543907 0 ] (cb221-4) [ 815 0 R /XYZ 99.933071 710.081993 0 ] (cb221-5) [ 815 0 R /XYZ 99.933071 691.134971 0 ] (cb221-6) [ 815 0 R /XYZ 99.933071 672.187950 0 ] (cb221-7) [ 815 0 R /XYZ 99.933071 653.240928 0 ] (cb221-8) [ 815 0 R /XYZ 99.933071 634.293907 0 ] (cb221-9) [ 815 0 R /XYZ 99.933071 615.346885 0 ] (cb222) [ 840 0 R /XYZ 84.259843 607.293907 0 ] (cb222-1) [ 840 0 R /XYZ 101.433071 605.596885 0 ] (cb225) [ 851 0 R /XYZ 84.259843 434.451496 0 ] (cb225-1) [ 851 0 R /XYZ 101.433071 432.754475 0 ] (cb228) [ 854 0 R /XYZ 84.259843 799.370079 0 ] (cb228-1) [ 854 0 R /XYZ 101.433071 797.673057 0 ] (cb231) [ 854 0 R /XYZ 84.259843 448.229014 0 ] (cb231-1) [ 854 0 R /XYZ 101.433071 446.531993 0 ] (cb234) [ 858 0 R /XYZ 84.259843 799.370079 0 ] (cb234-1) [ 858 0 R /XYZ 101.433071 797.673057 0 ] (cb237) [ 861 0 R /XYZ 84.259843 394.701496 0 ] (cb237-1) [ 861 0 R /XYZ 101.433071 393.004475 0 ] (cb237-10) [ 861 0 R /XYZ 99.933071 222.481281 0 ] (cb237-11) [ 861 0 R /XYZ 99.933071 203.534260 0 ] (cb237-12) [ 861 0 R /XYZ 99.933071 165.640217 0 ] (cb237-13) [ 861 0 R /XYZ 99.933071 127.746174 0 ] (cb237-14) [ 861 0 R /XYZ 99.933071 108.799152 0 ] (cb237-15) [ 861 0 R /XYZ 99.933071 89.852131 0 ] (cb237-16) [ 878 0 R /XYZ 99.933071 799.173057 0 ] (cb237-17) [ 878 0 R /XYZ 99.933071 780.226036 0 ] (cb237-18) [ 878 0 R /XYZ 99.933071 761.279014 0 ] (cb237-19) [ 878 0 R /XYZ 99.933071 742.331993 0 ] (cb237-2) [ 861 0 R /XYZ 99.933071 374.057453 0 ] (cb237-3) [ 861 0 R /XYZ 99.933071 355.110432 0 ] (cb237-4) [ 861 0 R /XYZ 99.933071 336.163410 0 ] (cb237-5) [ 861 0 R /XYZ 99.933071 317.216389 0 ] (cb237-6) [ 861 0 R /XYZ 99.933071 298.269367 0 ] (cb237-7) [ 861 0 R /XYZ 99.933071 279.322346 0 ] (cb237-8) [ 861 0 R /XYZ 99.933071 260.375324 0 ] (cb237-9) [ 861 0 R /XYZ 99.933071 241.428303 0 ] (cb238) [ 878 0 R /XYZ 84.259843 683.081993 0 ] (cb238-1) [ 878 0 R /XYZ 101.433071 681.384971 0 ] (cb24) [ 511 0 R /XYZ 84.259843 106.820079 0 ] (cb24-1) [ 511 0 R /XYZ 101.433071 105.123057 0 ] (cb241) [ 891 0 R /XYZ 84.259843 768.620079 0 ] (cb241-1) [ 891 0 R /XYZ 101.433071 766.923057 0 ] (cb241-10) [ 891 0 R /XYZ 99.933071 596.399864 0 ] (cb241-11) [ 891 0 R /XYZ 99.933071 577.452842 0 ] (cb241-12) [ 891 0 R /XYZ 99.933071 520.611778 0 ] (cb241-13) [ 891 0 R /XYZ 99.933071 501.664756 0 ] (cb241-14) [ 891 0 R /XYZ 99.933071 482.717735 0 ] (cb241-15) [ 891 0 R /XYZ 99.933071 463.770714 0 ] (cb241-16) [ 891 0 R /XYZ 99.933071 444.823692 0 ] (cb241-17) [ 891 0 R /XYZ 99.933071 425.876671 0 ] (cb241-18) [ 891 0 R /XYZ 99.933071 406.929649 0 ] (cb241-2) [ 891 0 R /XYZ 99.933071 747.976036 0 ] (cb241-3) [ 891 0 R /XYZ 99.933071 729.029014 0 ] (cb241-4) [ 891 0 R /XYZ 99.933071 710.081993 0 ] (cb241-5) [ 891 0 R /XYZ 99.933071 691.134971 0 ] (cb241-6) [ 891 0 R /XYZ 99.933071 672.187950 0 ] (cb241-7) [ 891 0 R /XYZ 99.933071 653.240928 0 ] (cb241-8) [ 891 0 R /XYZ 99.933071 634.293907 0 ] (cb241-9) [ 891 0 R /XYZ 99.933071 615.346885 0 ] (cb242) [ 891 0 R /XYZ 84.259843 347.679649 0 ] (cb242-1) [ 891 0 R /XYZ 101.433071 345.982628 0 ] (cb27) [ 516 0 R /XYZ 84.259843 388.070079 0 ] (cb27-1) [ 516 0 R /XYZ 101.433071 386.373057 0 ] (cb3) [ 321 0 R /XYZ 84.259843 509.420079 0 ] (cb3-1) [ 321 0 R /XYZ 101.433071 507.723057 0 ] (cb3-10) [ 321 0 R /XYZ 99.933071 318.252842 0 ] (cb3-11) [ 321 0 R /XYZ 99.933071 299.305821 0 ] (cb3-12) [ 321 0 R /XYZ 99.933071 280.358799 0 ] (cb3-13) [ 321 0 R /XYZ 99.933071 261.411778 0 ] (cb3-14) [ 321 0 R /XYZ 99.933071 242.464756 0 ] (cb3-15) [ 321 0 R /XYZ 99.933071 223.517735 0 ] (cb3-16) [ 321 0 R /XYZ 99.933071 204.570714 0 ] (cb3-17) [ 321 0 R /XYZ 99.933071 185.623692 0 ] (cb3-18) [ 321 0 R /XYZ 99.933071 166.676671 0 ] (cb3-19) [ 321 0 R /XYZ 99.933071 147.729649 0 ] (cb3-2) [ 321 0 R /XYZ 99.933071 488.776036 0 ] (cb3-20) [ 321 0 R /XYZ 99.933071 128.782628 0 ] (cb3-21) [ 321 0 R /XYZ 99.933071 109.835606 0 ] (cb3-22) [ 321 0 R /XYZ 99.933071 90.888585 0 ] (cb3-23) [ 345 0 R /XYZ 99.933071 799.173057 0 ] (cb3-24) [ 345 0 R /XYZ 99.933071 780.226036 0 ] (cb3-25) [ 345 0 R /XYZ 99.933071 761.279014 0 ] (cb3-26) [ 345 0 R /XYZ 99.933071 742.331993 0 ] (cb3-27) [ 345 0 R /XYZ 99.933071 723.384971 0 ] (cb3-28) [ 345 0 R /XYZ 99.933071 704.437950 0 ] (cb3-29) [ 345 0 R /XYZ 99.933071 685.490928 0 ] (cb3-3) [ 321 0 R /XYZ 99.933071 469.829014 0 ] (cb3-30) [ 345 0 R /XYZ 99.933071 666.543907 0 ] (cb3-31) [ 345 0 R /XYZ 99.933071 647.596885 0 ] (cb3-32) [ 345 0 R /XYZ 99.933071 628.649864 0 ] (cb3-33) [ 345 0 R /XYZ 99.933071 609.702842 0 ] (cb3-34) [ 345 0 R /XYZ 99.933071 590.755821 0 ] (cb3-35) [ 345 0 R /XYZ 99.933071 571.808799 0 ] (cb3-36) [ 345 0 R /XYZ 99.933071 552.861778 0 ] (cb3-37) [ 345 0 R /XYZ 99.933071 533.914756 0 ] (cb3-38) [ 345 0 R /XYZ 99.933071 514.967735 0 ] (cb3-39) [ 345 0 R /XYZ 99.933071 496.020714 0 ] (cb3-4) [ 321 0 R /XYZ 99.933071 431.934971 0 ] (cb3-40) [ 345 0 R /XYZ 99.933071 477.073692 0 ] (cb3-41) [ 345 0 R /XYZ 99.933071 458.126671 0 ] (cb3-42) [ 345 0 R /XYZ 99.933071 439.179649 0 ] (cb3-43) [ 345 0 R /XYZ 99.933071 420.232628 0 ] (cb3-44) [ 345 0 R /XYZ 99.933071 401.285606 0 ] (cb3-5) [ 321 0 R /XYZ 99.933071 412.987950 0 ] (cb3-6) [ 321 0 R /XYZ 99.933071 394.040928 0 ] (cb3-7) [ 321 0 R /XYZ 99.933071 375.093907 0 ] (cb3-8) [ 321 0 R /XYZ 99.933071 356.146885 0 ] (cb3-9) [ 321 0 R /XYZ 99.933071 337.199864 0 ] (cb30) [ 521 0 R /XYZ 84.259843 643.970079 0 ] (cb30-1) [ 521 0 R /XYZ 101.433071 642.273057 0 ] (cb33) [ 524 0 R /XYZ 84.259843 136.820079 0 ] (cb33-1) [ 524 0 R /XYZ 101.433071 135.123057 0 ] (cb36) [ 529 0 R /XYZ 84.259843 358.070079 0 ] (cb36-1) [ 529 0 R /XYZ 101.433071 356.373057 0 ] (cb39) [ 534 0 R /XYZ 84.259843 628.970079 0 ] (cb39-1) [ 534 0 R /XYZ 101.433071 627.273057 0 ] (cb4) [ 345 0 R /XYZ 84.259843 342.035606 0 ] (cb4-1) [ 345 0 R /XYZ 101.433071 340.338585 0 ] (cb42) [ 537 0 R /XYZ 84.259843 181.820079 0 ] (cb42-1) [ 537 0 R /XYZ 101.433071 180.123057 0 ] (cb45) [ 542 0 R /XYZ 84.259843 463.070079 0 ] (cb45-1) [ 542 0 R /XYZ 101.433071 461.373057 0 ] (cb48) [ 547 0 R /XYZ 84.259843 715.370079 0 ] (cb48-1) [ 547 0 R /XYZ 101.433071 713.673057 0 ] (cb51) [ 550 0 R /XYZ 84.259843 181.820079 0 ] (cb51-1) [ 550 0 R /XYZ 101.433071 180.123057 0 ] (cb54) [ 555 0 R /XYZ 84.259843 350.570079 0 ] (cb54-1) [ 555 0 R /XYZ 101.433071 348.873057 0 ] (cb55) [ 555 0 R /XYZ 84.259843 113.823057 0 ] (cb55-1) [ 555 0 R /XYZ 101.433071 112.126036 0 ] (cb56) [ 559 0 R /XYZ 84.259843 613.970079 0 ] (cb56-1) [ 559 0 R /XYZ 101.433071 612.273057 0 ] (cb59) [ 562 0 R /XYZ 84.259843 144.320079 0 ] (cb59-1) [ 562 0 R /XYZ 101.433071 142.623057 0 ] (cb62) [ 567 0 R /XYZ 84.259843 358.070079 0 ] (cb62-1) [ 567 0 R /XYZ 101.433071 356.373057 0 ] (cb65) [ 572 0 R /XYZ 84.259843 508.070079 0 ] (cb65-1) [ 572 0 R /XYZ 101.433071 506.373057 0 ] (cb68) [ 577 0 R /XYZ 84.259843 715.370079 0 ] (cb68-1) [ 577 0 R /XYZ 101.433071 713.673057 0 ] (cb7) [ 370 0 R /XYZ 84.259843 711.620079 0 ] (cb7-1) [ 370 0 R /XYZ 101.433071 709.923057 0 ] (cb7-10) [ 370 0 R /XYZ 99.933071 501.505821 0 ] (cb7-11) [ 370 0 R /XYZ 99.933071 482.558799 0 ] (cb7-12) [ 370 0 R /XYZ 99.933071 463.611778 0 ] (cb7-13) [ 370 0 R /XYZ 99.933071 444.664756 0 ] (cb7-14) [ 370 0 R /XYZ 99.933071 425.717735 0 ] (cb7-15) [ 370 0 R /XYZ 99.933071 406.770714 0 ] (cb7-16) [ 370 0 R /XYZ 99.933071 387.823692 0 ] (cb7-17) [ 370 0 R /XYZ 99.933071 368.876671 0 ] (cb7-18) [ 370 0 R /XYZ 99.933071 349.929649 0 ] (cb7-19) [ 370 0 R /XYZ 99.933071 330.982628 0 ] (cb7-2) [ 370 0 R /XYZ 99.933071 690.976036 0 ] (cb7-20) [ 370 0 R /XYZ 99.933071 312.035606 0 ] (cb7-21) [ 370 0 R /XYZ 99.933071 293.088585 0 ] (cb7-22) [ 370 0 R /XYZ 99.933071 274.141563 0 ] (cb7-23) [ 370 0 R /XYZ 99.933071 255.194542 0 ] (cb7-24) [ 370 0 R /XYZ 99.933071 236.247520 0 ] (cb7-25) [ 370 0 R /XYZ 99.933071 217.300499 0 ] (cb7-26) [ 370 0 R /XYZ 99.933071 198.353477 0 ] (cb7-27) [ 370 0 R /XYZ 99.933071 179.406456 0 ] (cb7-28) [ 370 0 R /XYZ 99.933071 160.459434 0 ] (cb7-29) [ 370 0 R /XYZ 99.933071 141.512413 0 ] (cb7-3) [ 370 0 R /XYZ 99.933071 672.029014 0 ] (cb7-30) [ 370 0 R /XYZ 99.933071 122.565391 0 ] (cb7-31) [ 370 0 R /XYZ 99.933071 103.618370 0 ] (cb7-32) [ 403 0 R /XYZ 99.933071 799.173057 0 ] (cb7-33) [ 403 0 R /XYZ 99.933071 780.226036 0 ] (cb7-34) [ 403 0 R /XYZ 99.933071 761.279014 0 ] (cb7-35) [ 403 0 R /XYZ 99.933071 742.331993 0 ] (cb7-36) [ 403 0 R /XYZ 99.933071 723.384971 0 ] (cb7-37) [ 403 0 R /XYZ 99.933071 704.437950 0 ] (cb7-38) [ 403 0 R /XYZ 99.933071 685.490928 0 ] (cb7-39) [ 403 0 R /XYZ 99.933071 666.543907 0 ] (cb7-4) [ 370 0 R /XYZ 99.933071 634.134971 0 ] (cb7-40) [ 403 0 R /XYZ 99.933071 647.596885 0 ] (cb7-41) [ 403 0 R /XYZ 99.933071 628.649864 0 ] (cb7-42) [ 403 0 R /XYZ 99.933071 609.702842 0 ] (cb7-43) [ 403 0 R /XYZ 99.933071 590.755821 0 ] (cb7-44) [ 403 0 R /XYZ 99.933071 571.808799 0 ] (cb7-45) [ 403 0 R /XYZ 99.933071 552.861778 0 ] (cb7-46) [ 403 0 R /XYZ 99.933071 533.914756 0 ] (cb7-47) [ 403 0 R /XYZ 99.933071 514.967735 0 ] (cb7-48) [ 403 0 R /XYZ 99.933071 496.020714 0 ] (cb7-49) [ 403 0 R /XYZ 99.933071 477.073692 0 ] (cb7-5) [ 370 0 R /XYZ 99.933071 596.240928 0 ] (cb7-50) [ 403 0 R /XYZ 99.933071 458.126671 0 ] (cb7-51) [ 403 0 R /XYZ 99.933071 439.179649 0 ] (cb7-52) [ 403 0 R /XYZ 99.933071 420.232628 0 ] (cb7-53) [ 403 0 R /XYZ 99.933071 382.338585 0 ] (cb7-54) [ 403 0 R /XYZ 99.933071 363.391563 0 ] (cb7-55) [ 403 0 R /XYZ 99.933071 344.444542 0 ] (cb7-56) [ 403 0 R /XYZ 99.933071 325.497520 0 ] (cb7-57) [ 403 0 R /XYZ 99.933071 306.550499 0 ] (cb7-58) [ 403 0 R /XYZ 99.933071 287.603477 0 ] (cb7-59) [ 403 0 R /XYZ 99.933071 268.656456 0 ] (cb7-6) [ 370 0 R /XYZ 99.933071 577.293907 0 ] (cb7-60) [ 403 0 R /XYZ 99.933071 249.709434 0 ] (cb7-61) [ 403 0 R /XYZ 99.933071 230.762413 0 ] (cb7-7) [ 370 0 R /XYZ 99.933071 558.346885 0 ] (cb7-8) [ 370 0 R /XYZ 99.933071 539.399864 0 ] (cb7-9) [ 370 0 R /XYZ 99.933071 520.452842 0 ] (cb71) [ 580 0 R /XYZ 84.259843 271.820079 0 ] (cb71-1) [ 580 0 R /XYZ 101.433071 270.123057 0 ] (cb74) [ 585 0 R /XYZ 84.259843 538.070079 0 ] (cb74-1) [ 585 0 R /XYZ 101.433071 536.373057 0 ] (cb77) [ 588 0 R /XYZ 84.259843 103.070079 0 ] (cb77-1) [ 588 0 R /XYZ 101.433071 101.373057 0 ] (cb8) [ 403 0 R /XYZ 84.259843 171.512413 0 ] (cb8-1) [ 403 0 R /XYZ 101.433071 169.815391 0 ] (cb80) [ 593 0 R /XYZ 84.259843 373.070079 0 ] (cb80-1) [ 593 0 R /XYZ 101.433071 371.373057 0 ] (cb83) [ 598 0 R /XYZ 84.259843 628.970079 0 ] (cb83-1) [ 598 0 R /XYZ 101.433071 627.273057 0 ] (cb86) [ 601 0 R /XYZ 84.259843 181.820079 0 ] (cb86-1) [ 601 0 R /XYZ 101.433071 180.123057 0 ] (cb89) [ 606 0 R /XYZ 84.259843 463.070079 0 ] (cb89-1) [ 606 0 R /XYZ 101.433071 461.373057 0 ] (cb92) [ 611 0 R /XYZ 84.259843 715.370079 0 ] (cb92-1) [ 611 0 R /XYZ 101.433071 713.673057 0 ] (cb95) [ 614 0 R /XYZ 84.259843 223.070079 0 ] (cb95-1) [ 614 0 R /XYZ 101.433071 221.373057 0 ] (cb98) [ 619 0 R /XYZ 84.259843 463.070079 0 ] (cb98-1) [ 619 0 R /XYZ 101.433071 461.373057 0 ] (cis-v1.6-kubernetes-benchmark---rancher-v2.6-with-kubernetes-v1.18-to-v1.21) [ 304 0 R /XYZ 84.259843 784.970079 0 ] (client-certificate-authentication-should-not-be-used-for-users-manual) [ 739 0 R /XYZ 84.259843 684.651496 0 ] (configure-image-provenance-using-imagepolicywebhook-admission-controller-manual) [ 887 0 R /XYZ 84.259843 684.651496 0 ] (consider-external-secret-storage-manual) [ 885 0 R /XYZ 84.259843 568.851496 0 ] (contentsbox) [ 8 0 R /XYZ 77.509843 756.850394 0 ] (controller-manager) [ 676 0 R /XYZ 41.740157 784.430079 0 ] (controls) [ 309 0 R /XYZ 84.259843 608.631496 0 ] (create-administrative-boundaries-between-resources-using-namespaces-manual) [ 889 0 R /XYZ 84.259843 720.651496 0 ] (ensure-that-a-minimal-audit-policy-is-created-automated) [ 741 0 R /XYZ 84.259843 720.651496 0 ] (ensure-that-a-unique-certificate-authority-is-used-for-etcd-automated) [ 732 0 R /XYZ 84.259843 595.970079 0 ] (ensure-that-all-namespaces-have-network-policies-defined-automated) [ 861 0 R /XYZ 84.259843 538.851496 0 ] (ensure-that-default-service-accounts-are-not-actively-used.-automated) [ 813 0 R /XYZ 84.259843 206.451496 0 ] (ensure-that-encryption-providers-are-appropriately-configured-automated) [ 645 0 R /XYZ 84.259843 670.970079 0 ] (ensure-that-service-account-tokens-are-only-mounted-where-necessary-manual) [ 840 0 R /XYZ 84.259843 449.446885 0 ] (ensure-that-the---anonymous-auth-argument-is-set-to-false-automated) [ 508 0 R /XYZ 84.259843 720.651496 0 ] (ensure-that-the---audit-log-maxage-argument-is-set-to-30-or-as-appropriate-automated) [ 598 0 R /XYZ 84.259843 799.370079 0 ] (ensure-that-the---audit-log-maxbackup-argument-is-set-to-10-or-as-appropriate-automated) [ 601 0 R /XYZ 84.259843 352.220079 0 ] (ensure-that-the---audit-log-maxsize-argument-is-set-to-100-or-as-appropriate-automated) [ 606 0 R /XYZ 84.259843 633.470079 0 ] (ensure-that-the---audit-log-path-argument-is-set-automated) [ 593 0 R /XYZ 84.259843 558.470079 0 ] (ensure-that-the---authorization-mode-argument-includes-node-automated) [ 537 0 R /XYZ 84.259843 352.220079 0 ] (ensure-that-the---authorization-mode-argument-includes-rbac-automated) [ 542 0 R /XYZ 84.259843 633.470079 0 ] (ensure-that-the---authorization-mode-argument-is-not-set-to-alwaysallow-automated) [ 534 0 R /XYZ 84.259843 799.370079 0 ] (ensure-that-the---authorization-mode-argument-is-not-set-to-alwaysallow-automated-1) [ 772 0 R /XYZ 84.259843 332.207453 0 ] (ensure-that-the---auto-tls-argument-is-not-set-to-true-automated) [ 710 0 R /XYZ 84.259843 445.970079 0 ] (ensure-that-the---basic-auth-file-argument-is-not-set-automated) [ 511 0 R /XYZ 84.259843 277.220079 0 ] (ensure-that-the---bind-address-argument-is-set-to-127.0.0.1-automated) [ 689 0 R /XYZ 84.259843 596.570079 0 ] (ensure-that-the---bind-address-argument-is-set-to-127.0.0.1-automated-1) [ 694 0 R /XYZ 84.259843 369.904475 0 ] (ensure-that-the---cert-file-and---key-file-arguments-are-set-as-appropriate-automated) [ 700 0 R /XYZ 84.259843 684.651496 0 ] (ensure-that-the---client-ca-file-argument-is-set-as-appropriate-automated) [ 632 0 R /XYZ 84.259843 633.470079 0 ] (ensure-that-the---client-ca-file-argument-is-set-as-appropriate-automated-1) [ 777 0 R /XYZ 84.259843 675.273057 0 ] (ensure-that-the---client-cert-auth-argument-is-set-to-true-automated) [ 705 0 R /XYZ 84.259843 558.470079 0 ] (ensure-that-the---encryption-provider-config-argument-is-set-as-appropriate-automated) [ 640 0 R /XYZ 84.259843 427.220079 0 ] (ensure-that-the---etcd-cafile-argument-is-set-as-appropriate-automated) [ 635 0 R /XYZ 84.259843 183.470079 0 ] (ensure-that-the---etcd-certfile-and---etcd-keyfile-arguments-are-set-as-appropriate-automated) [ 622 0 R /XYZ 84.259843 183.470079 0 ] (ensure-that-the---event-qps-argument-is-set-to-0-or-a-level-which-ensures-appropriate-event-capture-automated) [ 792 0 R /XYZ 84.259843 208.126036 0 ] (ensure-that-the---hostname-override-argument-is-not-set-manual) [ 792 0 R /XYZ 84.259843 425.926036 0 ] (ensure-that-the---insecure-bind-address-argument-is-not-set-automated) [ 575 0 R /XYZ 84.259843 145.970079 0 ] (ensure-that-the---insecure-port-argument-is-set-to-0-automated) [ 580 0 R /XYZ 84.259843 427.220079 0 ] (ensure-that-the---kubeconfig-kubelet.conf-file-ownership-is-set-to-rootroot-automated) [ 749 0 R /XYZ 84.259843 163.687950 0 ] (ensure-that-the---kubeconfig-kubelet.conf-file-permissions-are-set-to-644-or-more-restrictive-automated) [ 749 0 R /XYZ 84.259843 454.079014 0 ] (ensure-that-the---kubelet-certificate-authority-argument-is-set-as-appropriate-automated) [ 529 0 R /XYZ 84.259843 558.470079 0 ] (ensure-that-the---kubelet-client-certificate-and---kubelet-client-key-arguments-are-set-as-appropriate-automated) [ 524 0 R /XYZ 84.259843 352.220079 0 ] (ensure-that-the---kubelet-https-argument-is-set-to-true-automated) [ 521 0 R /XYZ 84.259843 799.370079 0 ] (ensure-that-the---make-iptables-util-chains-argument-is-set-to-true-automated) [ 792 0 R /XYZ 84.259843 799.370079 0 ] (ensure-that-the---peer-auto-tls-argument-is-not-set-to-true-automated) [ 727 0 R /XYZ 84.259843 727.220079 0 ] (ensure-that-the---peer-cert-file-and---peer-key-file-arguments-are-set-as-appropriate-automated) [ 715 0 R /XYZ 84.259843 333.470079 0 ] (ensure-that-the---peer-client-cert-auth-argument-is-set-to-true-automated) [ 720 0 R /XYZ 84.259843 183.470079 0 ] (ensure-that-the---profiling-argument-is-set-to-false-automated) [ 588 0 R /XYZ 84.259843 258.470079 0 ] (ensure-that-the---profiling-argument-is-set-to-false-automated-1) [ 676 0 R /XYZ 84.259843 167.404475 0 ] (ensure-that-the---profiling-argument-is-set-to-false-automated-2) [ 694 0 R /XYZ 84.259843 720.651496 0 ] (ensure-that-the---protect-kernel-defaults-argument-is-set-to-true-automated) [ 788 0 R /XYZ 84.259843 445.970079 0 ] (ensure-that-the---read-only-port-argument-is-set-to-0-automated) [ 777 0 R /XYZ 84.259843 301.829014 0 ] (ensure-that-the---request-timeout-argument-is-set-as-appropriate-automated) [ 609 0 R /XYZ 84.259843 183.470079 0 ] (ensure-that-the---root-ca-file-argument-is-set-as-appropriate-automated) [ 686 0 R /XYZ 84.259843 670.970079 0 ] (ensure-that-the---rotate-certificates-argument-is-not-set-to-false-automated) [ 796 0 R /XYZ 84.259843 138.881993 0 ] (ensure-that-the---secure-port-argument-is-not-set-to-0-automated) [ 585 0 R /XYZ 84.259843 708.470079 0 ] (ensure-that-the---service-account-key-file-argument-is-set-as-appropriate-automated) [ 619 0 R /XYZ 84.259843 633.470079 0 ] (ensure-that-the---service-account-lookup-argument-is-set-to-true-automated) [ 614 0 R /XYZ 84.259843 408.470079 0 ] (ensure-that-the---service-account-private-key-file-argument-is-set-as-appropriate-automated) [ 683 0 R /XYZ 84.259843 511.220079 0 ] (ensure-that-the---streaming-connection-idle-timeout-argument-is-not-set-to-0-automated) [ 782 0 R /XYZ 84.259843 641.326036 0 ] (ensure-that-the---terminated-pod-gc-threshold-argument-is-set-as-appropriate-automated) [ 676 0 R /XYZ 84.259843 720.651496 0 ] (ensure-that-the---tls-cert-file-and---tls-private-key-file-arguments-are-set-as-appropriate-automated) [ 627 0 R /XYZ 84.259843 427.220079 0 ] (ensure-that-the---tls-cert-file-and---tls-private-key-file-arguments-are-set-as-appropriate-automated-1) [ 796 0 R /XYZ 84.259843 542.326036 0 ] (ensure-that-the---token-auth-file-parameter-is-not-set-automated) [ 516 0 R /XYZ 84.259843 558.470079 0 ] (ensure-that-the---use-service-account-credentials-argument-is-set-to-true-automated) [ 679 0 R /XYZ 84.259843 332.523057 0 ] (ensure-that-the-admin.conf-file-ownership-is-set-to-rootroot-automated) [ 318 0 R /XYZ 84.259843 578.223057 0 ] (ensure-that-the-admin.conf-file-permissions-are-set-to-644-or-more-restrictive-automated) [ 318 0 R /XYZ 84.259843 694.023057 0 ] (ensure-that-the-admission-control-plugin-alwaysadmit-is-not-set-automated) [ 550 0 R /XYZ 84.259843 352.220079 0 ] (ensure-that-the-admission-control-plugin-alwayspullimages-is-set-manual) [ 555 0 R /XYZ 84.259843 520.970079 0 ] (ensure-that-the-admission-control-plugin-eventratelimit-is-set-automated) [ 545 0 R /XYZ 84.259843 183.470079 0 ] (ensure-that-the-admission-control-plugin-namespacelifecycle-is-set-automated) [ 562 0 R /XYZ 84.259843 314.720079 0 ] (ensure-that-the-admission-control-plugin-noderestriction-is-set-automated) [ 572 0 R /XYZ 84.259843 708.470079 0 ] (ensure-that-the-admission-control-plugin-podsecuritypolicy-is-set-automated) [ 567 0 R /XYZ 84.259843 558.470079 0 ] (ensure-that-the-admission-control-plugin-securitycontextdeny-is-set-if-podsecuritypolicy-is-not-used-manual) [ 555 0 R /XYZ 84.259843 314.223057 0 ] (ensure-that-the-admission-control-plugin-serviceaccount-is-set-automated) [ 559 0 R /XYZ 84.259843 799.370079 0 ] (ensure-that-the-anonymous-auth-argument-is-set-to-false-automated) [ 772 0 R /XYZ 84.259843 720.651496 0 ] (ensure-that-the-api-server-only-makes-use-of-strong-cryptographic-ciphers-automated) [ 667 0 R /XYZ 84.259843 506.287950 0 ] (ensure-that-the-api-server-pod-specification-file-ownership-is-set-to-rootroot-automated) [ 313 0 R /XYZ 84.259843 553.851496 0 ] (ensure-that-the-api-server-pod-specification-file-permissions-are-set-to-644-or-more-restrictive-automated) [ 313 0 R /XYZ 84.259843 684.651496 0 ] (ensure-that-the-audit-policy-covers-key-security-concerns-manual) [ 744 0 R /XYZ 84.259843 314.720079 0 ] (ensure-that-the-certificate-authorities-file-permissions-are-set-to-644-or-more-restrictive-automated) [ 753 0 R /XYZ 84.259843 519.629014 0 ] (ensure-that-the-client-certificate-authorities-file-ownership-is-set-to-rootroot-automated) [ 762 0 R /XYZ 84.259843 799.370079 0 ] (ensure-that-the-cluster-admin-role-is-only-used-where-required-manual) [ 813 0 R /XYZ 84.259843 684.651496 0 ] (ensure-that-the-cni-in-use-supports-network-policies-manual) [ 861 0 R /XYZ 84.259843 684.651496 0 ] (ensure-that-the-container-network-interface-file-ownership-is-set-to-rootroot-manual) [ 315 0 R /XYZ 84.259843 170.823057 0 ] (ensure-that-the-container-network-interface-file-permissions-are-set-to-644-or-more-restrictive-manual) [ 315 0 R /XYZ 84.259843 347.570079 0 ] (ensure-that-the-controller-manager-pod-specification-file-ownership-is-set-to-rootroot-automated) [ 313 0 R /XYZ 84.259843 277.251496 0 ] (ensure-that-the-controller-manager-pod-specification-file-permissions-are-set-to-644-or-more-restrictive-automated) [ 313 0 R /XYZ 84.259843 423.051496 0 ] (ensure-that-the-controller-manager.conf-file-ownership-is-set-to-rootroot-automated) [ 321 0 R /XYZ 84.259843 799.370079 0 ] (ensure-that-the-controller-manager.conf-file-permissions-are-set-to-644-or-more-restrictive-automated) [ 318 0 R /XYZ 84.259843 200.823057 0 ] (ensure-that-the-etcd-data-directory-ownership-is-set-to-etcdetcd-automated) [ 499 0 R /XYZ 84.259843 234.881993 0 ] (ensure-that-the-etcd-data-directory-permissions-are-set-to-700-or-more-restrictive-automated) [ 499 0 R /XYZ 84.259843 563.129014 0 ] (ensure-that-the-etcd-pod-specification-file-ownership-is-set-to-rootroot-automated) [ 315 0 R /XYZ 84.259843 478.370079 0 ] (ensure-that-the-etcd-pod-specification-file-permissions-are-set-to-644-or-more-restrictive-automated) [ 315 0 R /XYZ 84.259843 609.170079 0 ] (ensure-that-the-kubelet---config-configuration-file-has-permissions-set-to-644-or-more-restrictive-automated) [ 762 0 R /XYZ 84.259843 383.493907 0 ] (ensure-that-the-kubelet---config-configuration-file-ownership-is-set-to-rootroot-automated) [ 762 0 R /XYZ 84.259843 195.693907 0 ] (ensure-that-the-kubelet-only-makes-use-of-strong-cryptographic-ciphers-automated) [ 806 0 R /XYZ 84.259843 392.223057 0 ] (ensure-that-the-kubelet-service-file-ownership-is-set-to-rootroot-automated) [ 746 0 R /XYZ 84.259843 553.851496 0 ] (ensure-that-the-kubelet-service-file-permissions-are-set-to-644-or-more-restrictive-automated) [ 746 0 R /XYZ 84.259843 684.651496 0 ] (ensure-that-the-kubernetes-pki-certificate-file-permissions-are-set-to-644-or-more-restrictive-automated) [ 345 0 R /XYZ 84.259843 184.188585 0 ] (ensure-that-the-kubernetes-pki-directory-and-file-ownership-is-set-to-rootroot-automated) [ 321 0 R /XYZ 84.259843 668.570079 0 ] (ensure-that-the-kubernetes-pki-key-file-permissions-are-set-to-600-automated) [ 436 0 R /XYZ 84.259843 702.470079 0 ] (ensure-that-the-proxy-kubeconfig-file-ownership-is-set-to-rootroot-automated) [ 749 0 R /XYZ 84.259843 763.220079 0 ] (ensure-that-the-rotatekubeletservercertificate-argument-is-set-to-true-automated) [ 689 0 R /XYZ 84.259843 799.370079 0 ] (ensure-that-the-scheduler-pod-specification-file-ownership-is-set-to-rootroot-automated) [ 315 0 R /XYZ 84.259843 739.970079 0 ] (ensure-that-the-scheduler-pod-specification-file-permissions-are-set-to-644-or-more-restrictive-automated) [ 313 0 R /XYZ 84.259843 146.451496 0 ] (ensure-that-the-scheduler.conf-file-ownership-is-set-to-rootroot-automated) [ 318 0 R /XYZ 84.259843 331.623057 0 ] (ensure-that-the-scheduler.conf-file-permissions-are-set-to-644-or-more-restrictive-automated) [ 318 0 R /XYZ 84.259843 462.423057 0 ] (ensure-that-the-seccomp-profile-is-set-to-dockerdefault-in-your-pod-definitions-manual) [ 889 0 R /XYZ 84.259843 604.851496 0 ] (etcd-node-configuration-files) [ 700 0 R /XYZ 41.740157 784.430079 0 ] (extensible-admission-control) [ 887 0 R /XYZ 41.740157 784.430079 0 ] (general-policies) [ 889 0 R /XYZ 41.740157 784.430079 0 ] (header_bottom_text) [ 6 0 R /XYZ 85.009843 392.718898 0 ] (if-proxy-kubeconfig-file-exists-ensure-permissions-are-set-to-644-or-more-restrictive-automated) [ 746 0 R /XYZ 84.259843 423.051496 0 ] (kubelet) [ 772 0 R /XYZ 41.740157 784.430079 0 ] (logging) [ 741 0 R /XYZ 41.740157 784.430079 0 ] (master-node-configuration-files) [ 313 0 R /XYZ 41.740157 784.430079 0 ] (minimize-access-to-create-pods-manual) [ 813 0 R /XYZ 84.259843 307.251496 0 ] (minimize-access-to-secrets-manual) [ 813 0 R /XYZ 84.259843 523.851496 0 ] (minimize-the-admission-of-containers-wishing-to-share-the-host-ipc-namespace-automated) [ 851 0 R /XYZ 84.259843 238.710432 0 ] (minimize-the-admission-of-containers-wishing-to-share-the-host-network-namespace-automated) [ 854 0 R /XYZ 84.259843 603.629014 0 ] (minimize-the-admission-of-containers-wishing-to-share-the-host-process-id-namespace-automated) [ 851 0 R /XYZ 84.259843 589.851496 0 ] (minimize-the-admission-of-containers-with-added-capabilities-manual) [ 858 0 R /XYZ 84.259843 323.081993 0 ] (minimize-the-admission-of-containers-with-allowprivilegeescalation-automated) [ 854 0 R /XYZ 84.259843 252.487950 0 ] (minimize-the-admission-of-containers-with-capabilities-assigned-manual) [ 858 0 R /XYZ 84.259843 207.281993 0 ] (minimize-the-admission-of-containers-with-the-net_raw-capability-manual) [ 858 0 R /XYZ 84.259843 453.881993 0 ] (minimize-the-admission-of-privileged-containers-manual) [ 851 0 R /XYZ 84.259843 720.651496 0 ] (minimize-the-admission-of-root-containers-manual) [ 858 0 R /XYZ 84.259843 584.681993 0 ] (minimize-wildcard-use-in-roles-and-clusterroles-manual) [ 813 0 R /XYZ 84.259843 423.051496 0 ] (network-policies-and-cni) [ 861 0 R /XYZ 41.740157 784.430079 0 ] (overview) [ 304 0 R /XYZ 84.259843 704.822079 0 ] (pod-security-policies) [ 851 0 R /XYZ 41.740157 784.430079 0 ] (prefer-using-secrets-as-files-over-secrets-as-environment-variables-manual) [ 885 0 R /XYZ 84.259843 684.651496 0 ] (rbac-and-service-accounts) [ 813 0 R /XYZ 41.740157 784.430079 0 ] (scheduler) [ 694 0 R /XYZ 41.740157 784.430079 0 ] (secrets-management) [ 885 0 R /XYZ 41.740157 784.430079 0 ] (testing-controls-methodology) [ 304 0 R /XYZ 84.259843 166.076079 0 ] (the-default-namespace-should-not-be-used-automated) [ 889 0 R /XYZ 84.259843 193.251496 0 ] (title-block-header) [ 6 0 R /XYZ 84.259843 502.818898 0 ] (verify-that-the-rotatekubeletservercertificate-argument-is-set-to-true-automated) [ 806 0 R /XYZ 84.259843 670.970079 0 ] (worker-node-configuration-files) [ 746 0 R /XYZ 41.740157 784.430079 0 ] ] +>> +>> +>> +endobj +4 0 obj +<< +/ExtGState << +/a1.0 << +/ca 1 +>> +/A1.0 << +/CA 1 +>> +>> +/XObject << +>> +/Pattern << +>> +/Shading << +>> +/Font 1074 0 R +>> +endobj +5 0 obj +<< +/Filter /FlateDecode +/Length 2619 +>> +stream +x[ Wu+H @(^8A./f!vŮG>D=$ς?ZΗ7' 5 =jȱo\5ԞS-~xX3XP;lQa,@( +-!3g[d3 Ӆ.FƂ` AƂ"Ш%Lgufc,hV8&4AJ-cNjX&-fc,h $IM7+cA؂K &3Љ0Po&c,z1tԛ(ȹZެ`KFBuIS'LB :1]-cA/X4&2zz%мެdb:pia,@&2[V +3l^q6zc @oFlW"ZUzg Hfl B^|p}گ +ܡ"f/q, 9V7}G?O8nW/r71!6F?FSn4 _=?~xxݫ]/|PwD&Cݑ|aq5پ:Hf j=#){mz̗c}|-z#YPEٜ|#|oW(f;&@|~Nnwoo%oUlmYT#U'Ta~- $}grYw4I5}׀&̏B٦[dÞ\}ovOx9aZ}.}RECE1dէ4sCl]NDBІ͜m׼ +p$GDw-ϝW[˔ٱF7i_mgDt|߁H ߤ儼O\IX!y.m)neI?ߖ +GsWlB;tgbwm6y<Ԅǽ8NbGX](LyӝxٙQ2'+qs<]2w^fmLIf[me OxI'uO#%ͩ{F:e;|d?ǓLZ;#{!f&۰ıyxÌ)m,q4N.k 7qn+#<[ř|ެ}mx9L^_ͶtBy-B:Es/t'K۾sm-.0=d[l]O!F}\ pD>b.R=9c1Z9ngOgJ-쮱&m[OjCv7ɐ방rqTgN?+]])}}f3ʻ;vz\YٟR[=uG=oaː2SY凞ĿO9;‰_MHl2tﳤZۮF~3+yw%L؎`R7 a6+> +endobj +7 0 obj +<< +/Filter /FlateDecode +/Length 3648 +>> +stream +x\[ܶ~_C/@Q 4H[}v8Ӈ~Dr]ǖ>77R=}aOvJ)w3E63K '#)2磍v21Eoָ9JnMLJv/ 7Y&NCM:rBl7 Bۃ_:| +C)fKG8hy`$$2pGG7Qț:@.;htxm !D+ۃ+!GB^EKKB݄C Q83[Bxн-Do!dCc(fگ߄hJb6-n!RXx;!ྭ֣\~\CC +\q@YML=4`8ڡLS؆h`vu;ttCLJpiv ^hgjGͻ {9o-Do! E;#-Do!L!^ +[BO6av| EUT!|iqSLJ .w"M\!##kttt!qIS'B& + aK^ ߦklnk3ev![ @sM&L+2&.ɤ_6\sValA*Td ɐ"h9r!L|J"c6F0#Ľa +1Ud2t@fV8dx:l![LΓ!0,+2Ag ++2ex!|gpȾld(2؅!3MG>;q7k7h%jPR[-8,)PNJN'.a0ffL( +D3)$c9kU k>5K|^i>>ydk}D k}LLsOtմih~i/dCj͍oWq + 1JOWw\Ij2.  %u$67ѡc^:2]9̿1.an5,r,;^ GӇG}dNk߯0L&d7Ž?=zܿfرF5\4s[yWg~V|PY̱Nq~﫲o+ϫ޴)/OևXcMw9v0T=>R78Vk->_QӹNN-Xdݫ7.)BG'3|XV'm;κO4KgnǬclc6Y)t Ęs79UD6szRNe#Og$xz[}$׽95?ŞΞ, OcO$ӖD*k$r@ySt'>sqZ#|QVwz{c͢sNq _ld1uV}"8NO;WEp@NG^ BMNqGN]t?(oO3R;>v |?:/9œ]k-Z\s.Pm2GWv/00%>!"e\1u|٪j&9$xKԲc}V˓.a5Ny Ixny}>Mb#e#Oʗ3^~U5 ̬=^ukΖ'f? Xv0:sfΓ߁}mapC +6t(/+~%|_:qg[|0B g¡ 7loxu1,l.U0֝w(نQeLÜP*7d3ovځ$Mua5 +H*rkk,T|WKlhE&iyL& x:w +$D NKGYa +nh<ͥwRb#I-=]Vecl>+ȗۤc*(xUZaۼ%U~ZJsszr ղzέ;$mm<͟ͅSdZ +FfFkN6v؃l?2G)Qݼ]N??:ƼiقZn`YɈ\5U(7ɋa,WohuHko7=WI2mW%ȝCSs]N0 +x:cMdk^SWnnɦNpp5KQ4"K:z7D6Sa j4^•ĉFSׯ^feG!D7{;44(zWC;%}ͧa,=X;- +w0hj6m~\&`?DƲT䜼+^y\^ϛ^+ +endstream +endobj +8 0 obj +<< +/Type /Page +/Parent 1 0 R +/MediaBox [ 0 0 595.275591 841.889764 ] +/Contents 7 0 R +/Resources 4 0 R +/Annots [ 9 0 R 10 0 R 11 0 R 12 0 R 13 0 R 14 0 R 15 0 R 16 0 R 17 0 R 18 0 R 19 0 R 20 0 R 21 0 R 22 0 R 23 0 R 24 0 R 25 0 R 26 0 R 27 0 R 28 0 R 29 0 R 30 0 R 31 0 R 32 0 R 33 0 R 34 0 R 35 0 R 36 0 R ] +/TrimBox [ 0 0 595.275591 841.889764 ] +/BleedBox [ 0 0 595.275591 841.889764 ] +>> +endobj +9 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 76.423228 671.061024 504.679134 638.361024 ] +/BS << +/W 0 +>> +/Dest (cis-v1.6-kubernetes-benchmark---rancher-v2.6-with-kubernetes-v1.18-to-v1.21) +>> +endobj +10 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 488.750423 648.111024 496.429134 633.111024 ] +/BS << +/W 0 +>> +/Dest (cis-v1.6-kubernetes-benchmark---rancher-v2.6-with-kubernetes-v1.18-to-v1.21) +>> +endobj +11 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 76.423228 626.361024 504.679134 593.661024 ] +/BS << +/W 0 +>> +/Dest (controls) +>> +endobj +12 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 485.690364 618.411024 496.429134 603.411024 ] +/BS << +/W 0 +>> +/Dest (controls) +>> +endobj +13 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 76.423228 581.661024 504.679134 548.961024 ] +/BS << +/W 0 +>> +/Dest (master-node-configuration-files) +>> +endobj +14 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 485.521907 573.711024 496.429134 558.711024 ] +/BS << +/W 0 +>> +/Dest (master-node-configuration-files) +>> +endobj +15 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.673228 530.961024 498.679134 507.561024 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the-api-server-pod-specification-file-permissions-are-set-to-644-or-more-restrictive-automated) +>> +endobj +16 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 481.786556 510.561024 491.179134 495.561024 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the-api-server-pod-specification-file-permissions-are-set-to-644-or-more-restrictive-automated) +>> +endobj +17 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.673228 491.361024 498.679134 467.961024 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the-api-server-pod-specification-file-ownership-is-set-to-rootroot-automated) +>> +endobj +18 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 481.786556 470.961024 491.179134 455.961024 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the-api-server-pod-specification-file-ownership-is-set-to-rootroot-automated) +>> +endobj +19 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.673228 451.761024 498.679134 428.361024 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the-controller-manager-pod-specification-file-permissions-are-set-to-644-or-more-restrictive-automated) +>> +endobj +20 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 481.786556 431.361024 491.179134 416.361024 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the-controller-manager-pod-specification-file-permissions-are-set-to-644-or-more-restrictive-automated) +>> +endobj +21 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.673228 412.161024 498.679134 388.761024 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the-controller-manager-pod-specification-file-ownership-is-set-to-rootroot-automated) +>> +endobj +22 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 481.786556 391.761024 491.179134 376.761024 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the-controller-manager-pod-specification-file-ownership-is-set-to-rootroot-automated) +>> +endobj +23 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.673228 372.561024 498.679134 349.161024 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the-scheduler-pod-specification-file-permissions-are-set-to-644-or-more-restrictive-automated) +>> +endobj +24 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 481.786556 352.161024 491.179134 337.161024 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the-scheduler-pod-specification-file-permissions-are-set-to-644-or-more-restrictive-automated) +>> +endobj +25 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.673228 332.961024 498.679134 309.561024 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the-scheduler-pod-specification-file-ownership-is-set-to-rootroot-automated) +>> +endobj +26 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 481.786556 312.561024 491.179134 297.561024 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the-scheduler-pod-specification-file-ownership-is-set-to-rootroot-automated) +>> +endobj +27 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.673228 293.361024 498.679134 269.961024 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the-etcd-pod-specification-file-permissions-are-set-to-644-or-more-restrictive-automated) +>> +endobj +28 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 481.786556 272.961024 491.179134 257.961024 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the-etcd-pod-specification-file-permissions-are-set-to-644-or-more-restrictive-automated) +>> +endobj +29 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.673228 253.761024 498.679134 230.361024 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the-etcd-pod-specification-file-ownership-is-set-to-rootroot-automated) +>> +endobj +30 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 481.786556 233.361024 491.179134 218.361024 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the-etcd-pod-specification-file-ownership-is-set-to-rootroot-automated) +>> +endobj +31 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.673228 214.161024 498.679134 190.761024 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the-container-network-interface-file-permissions-are-set-to-644-or-more-restrictive-manual) +>> +endobj +32 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 481.786556 193.761024 491.179134 178.761024 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the-container-network-interface-file-permissions-are-set-to-644-or-more-restrictive-manual) +>> +endobj +33 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.673228 174.561024 498.679134 151.161024 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the-container-network-interface-file-ownership-is-set-to-rootroot-manual) +>> +endobj +34 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 481.786556 154.161024 491.179134 139.161024 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the-container-network-interface-file-ownership-is-set-to-rootroot-manual) +>> +endobj +35 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.673228 134.961024 498.679134 111.561024 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the-admin.conf-file-permissions-are-set-to-644-or-more-restrictive-automated) +>> +endobj +36 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 481.786556 114.561024 491.179134 99.561024 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the-admin.conf-file-permissions-are-set-to-644-or-more-restrictive-automated) +>> +endobj +37 0 obj +<< +/Filter /FlateDecode +/Length 3692 +>> +stream +x\[ܶ~_pf8C0Р@A@g$($}P/J86֖F|s!u׿rp?z.?b3F_ٔ~Kr2TnVN~SpFލ$N$y'1E@" + cx՗=PF5&2fQTg¨ދat=[8I01L> ߁($ՙ@RgU@.^u&3f11:#lj20T}l?HBt!0ɅdPTgNlb?U$ՙ"f4![Ug%Ws6쵐XP=df9G9G)r2|C2(9 &4;9 6Fuf19 !-D1D>&64l 12?ZՇ?ZH6F>b Z5:c4'hDF1s`j`cTg1"D13x Zc1A :^hNSbc8Z`cTg$A-(AQ){1A1C1nXGƨ^3?:i+2Y&ᒺea2ienvD>z^鋷~lZֈ=YuE*Ebmg%GO;Nژ"\;:Di+:F9 ֣PqP]zYˋqtp%I4tq%m5 F?8Xjޗ5ryW.\[bfy&&,2_aiKy 5ϳΆȱΩѠCAq> d'v–}v2POWPaN F8s/oNy~f*ZF_dsě/W_}Cy_Ao>6Ey-4Z?^:h>?H7}FA=o|L&?4h^nOhdyQ&5yD۷_~M6Ov`̊oYXˇ7,ygKZȒ+w{\'1}C:]N3sl&Ye'˒q>Ɗ /+ق)ǂ2U=uXtǡrY.zL헶h2˧sdvm^Y?le}mXF,v.K?8{=lW #݇>e7۝* $@dL]I9(t@3Nm~Hekg\/xw:މhmJ'>$M &흲`eU~RkUGvp6 [CގY.&r"kWKVi:GK:rnu|qƭm_nCfs;-z?ne8gyM4w+)w|k'^c9\i6M֦ݫf&Cq1U]΂Ex**oyKE[Ҝ+q(ha{wz(4y-{T)O/7ao0`?B.m37 `b1tZIaWdX[SM QyJM%XCa.W܎r-qc*6TjJwuJ;FTð Z,ʵOr*yJp⸃+34B~P}}]ë t'hс9ȓϱ/\_Kƞ^ o*<|i!=or@LWn,KEΩy,eoDN +endstream +endobj +38 0 obj +<< +/Type /Page +/Parent 1 0 R +/MediaBox [ 0 0 595.275591 841.889764 ] +/Contents 37 0 R +/Resources 4 0 R +/Annots [ 39 0 R 40 0 R 41 0 R 42 0 R 43 0 R 44 0 R 45 0 R 46 0 R 47 0 R 48 0 R 49 0 R 50 0 R 51 0 R 52 0 R 53 0 R 54 0 R 55 0 R 56 0 R 57 0 R 58 0 R 59 0 R 60 0 R 61 0 R 62 0 R 63 0 R 64 0 R 65 0 R 66 0 R 67 0 R 68 0 R 69 0 R 70 0 R 71 0 R 72 0 R 73 0 R 74 0 R ] +/TrimBox [ 0 0 595.275591 841.889764 ] +/BleedBox [ 0 0 595.275591 841.889764 ] +>> +endobj +39 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.673228 790.370079 498.679134 766.970079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the-admin.conf-file-ownership-is-set-to-rootroot-automated) +>> +endobj +40 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 481.786556 769.970079 491.179134 754.970079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the-admin.conf-file-ownership-is-set-to-rootroot-automated) +>> +endobj +41 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.673228 750.770079 498.679134 727.370079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the-scheduler.conf-file-permissions-are-set-to-644-or-more-restrictive-automated) +>> +endobj +42 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 481.786556 730.370079 491.179134 715.370079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the-scheduler.conf-file-permissions-are-set-to-644-or-more-restrictive-automated) +>> +endobj +43 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.673228 711.170079 498.679134 687.770079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the-scheduler.conf-file-ownership-is-set-to-rootroot-automated) +>> +endobj +44 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 481.786556 690.770079 491.179134 675.770079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the-scheduler.conf-file-ownership-is-set-to-rootroot-automated) +>> +endobj +45 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.673228 671.570079 498.679134 648.170079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the-controller-manager.conf-file-permissions-are-set-to-644-or-more-restrictive-automated) +>> +endobj +46 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 481.786556 651.170079 491.179134 636.170079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the-controller-manager.conf-file-permissions-are-set-to-644-or-more-restrictive-automated) +>> +endobj +47 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.673228 631.970079 498.679134 608.570079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the-controller-manager.conf-file-ownership-is-set-to-rootroot-automated) +>> +endobj +48 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 481.786556 611.570079 491.179134 596.570079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the-controller-manager.conf-file-ownership-is-set-to-rootroot-automated) +>> +endobj +49 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.673228 592.370079 498.679134 568.970079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the-kubernetes-pki-directory-and-file-ownership-is-set-to-rootroot-automated) +>> +endobj +50 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 481.786556 571.970079 491.179134 556.970079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the-kubernetes-pki-directory-and-file-ownership-is-set-to-rootroot-automated) +>> +endobj +51 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.673228 552.770079 498.679134 529.370079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the-kubernetes-pki-certificate-file-permissions-are-set-to-644-or-more-restrictive-automated) +>> +endobj +52 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 481.786556 532.370079 491.179134 517.370079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the-kubernetes-pki-certificate-file-permissions-are-set-to-644-or-more-restrictive-automated) +>> +endobj +53 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.673228 513.170079 498.679134 489.770079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the-kubernetes-pki-key-file-permissions-are-set-to-600-automated) +>> +endobj +54 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 481.786556 492.770079 491.179134 477.770079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the-kubernetes-pki-key-file-permissions-are-set-to-600-automated) +>> +endobj +55 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.673228 473.570079 498.679134 450.170079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the-etcd-data-directory-permissions-are-set-to-700-or-more-restrictive-automated) +>> +endobj +56 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 481.786556 453.170079 491.179134 438.170079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the-etcd-data-directory-permissions-are-set-to-700-or-more-restrictive-automated) +>> +endobj +57 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.673228 433.970079 498.679134 410.570079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the-etcd-data-directory-ownership-is-set-to-etcdetcd-automated) +>> +endobj +58 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 481.786556 413.570079 491.179134 398.570079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the-etcd-data-directory-ownership-is-set-to-etcdetcd-automated) +>> +endobj +59 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 76.423228 394.370079 504.679134 361.670079 ] +/BS << +/W 0 +>> +/Dest (api-server) +>> +endobj +60 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 481.982112 386.420079 496.429134 371.420079 ] +/BS << +/W 0 +>> +/Dest (api-server) +>> +endobj +61 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.673228 343.670079 498.679134 320.270079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the---anonymous-auth-argument-is-set-to-false-automated) +>> +endobj +62 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 481.786556 323.270079 491.179134 308.270079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the---anonymous-auth-argument-is-set-to-false-automated) +>> +endobj +63 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.673228 304.070079 498.679134 280.670079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the---basic-auth-file-argument-is-not-set-automated) +>> +endobj +64 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 481.786556 298.670079 491.179134 283.670079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the---basic-auth-file-argument-is-not-set-automated) +>> +endobj +65 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.673228 264.470079 498.679134 241.070079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the---token-auth-file-parameter-is-not-set-automated) +>> +endobj +66 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 481.786556 259.070079 491.179134 244.070079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the---token-auth-file-parameter-is-not-set-automated) +>> +endobj +67 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.673228 224.870079 498.679134 201.470079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the---kubelet-https-argument-is-set-to-true-automated) +>> +endobj +68 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 481.786556 219.470079 491.179134 204.470079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the---kubelet-https-argument-is-set-to-true-automated) +>> +endobj +69 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.673228 185.270079 498.679134 161.870079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the---kubelet-client-certificate-and---kubelet-client-key-arguments-are-set-as-appropriate-automated) +>> +endobj +70 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 481.786556 164.870079 491.179134 149.870079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the---kubelet-client-certificate-and---kubelet-client-key-arguments-are-set-as-appropriate-automated) +>> +endobj +71 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.673228 145.670079 498.679134 122.270079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the---kubelet-certificate-authority-argument-is-set-as-appropriate-automated) +>> +endobj +72 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 481.786556 125.270079 491.179134 110.270079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the---kubelet-certificate-authority-argument-is-set-as-appropriate-automated) +>> +endobj +73 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.673228 106.070079 498.679134 82.670079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the---authorization-mode-argument-is-not-set-to-alwaysallow-automated) +>> +endobj +74 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 481.786556 85.670079 491.179134 70.670079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the---authorization-mode-argument-is-not-set-to-alwaysallow-automated) +>> +endobj +75 0 obj +<< +/Filter /FlateDecode +/Length 3494 +>> +stream +x\M$d1r0p9̶=6YvyTݭM.fW*J{d#%M{<9aλ,]=>X\s$5jyg_c=95%!\w)\}~E)QKqpK슧 ޕ8\!-Q ]-P_ YYAC`S,#DN P10- sv>g Â- :|*"0zYa1 D)Ơa|40Q\Ȟϑ d10EdrW", Spx mV LB&oqv "=Y\hp#fyr:I ☥!9R̎Kb`HDiQ'XPN$8$If m֘ERBda%nqQKK0,٥0\ % +Z~ . 2 +!2!26`r$!y!GY!e =,2c r%s I3*:?OvHtI-.PAO +-.PU1 ٝbp!8 %(P=J哜B(ZZU,*.0eKxROB]lUIhbULS^E.tD,apҫ(.f CHFhuE-P{ҫ Z5#[z5ASB)0qna .: ^ESEVg*0"AC$$K&h- +qyҫ)''HT^EJuiU'TX*;b=2&'Hҫ9D0cJ^mV-C(U̧[z\eHCt ̨5[z3nL*& S7\B0L/C٨E|Xz5g̗E5Z\̗$,m֔, ҫuPQ-ZPU f,ZPQ +ҫZXz@cR-ZQҫSWAo@{dULP0BVǮjVT &_Z=8,vzZ=Jr{G#WZY^-9u$KB},ҫ +QA^ŜZW1%WZZ1,ꘇDK*:bUVWK*:&K*:tvBK 1a}Z3fH–S9`/[r4s 5荅kA-B+ Us1v޲}\_M{l]icmR[n9Ȣs Mjm=Gs+o9Ub\Lnl 9.}ӏ~;6JYgey6@6G`0'.?O18:Ge?Yϫ>s>1εK3͏GKG#g=鞖6>\w{gL&^;l>݇ziiaN1__MV׸4a0mS>*3.q=clfiׂ_ ݇ȥγŸ/v2*Iko~/'x~6^G7!Zy^pD^{m^:/V yn:F*?,vlF~95>>^kk]ծ^F[y0ЧGst`:^[-> Hx k>L?Oi=N}=O$!D'a/⨾1$y>y8:2}yyWͅo(h{E Y2F؎ԘK[hq̑n:Bl_xtOj99O-}pĨixX +k/"}vbq4 IaG}ZmTd[eH3CtȬ|?vK{Xǣ"zb+Y(jQyJzq^,\i%@&TzjcϜ~^}mGO?Pu(Zv`k>l },7 +endstream +endobj +76 0 obj +<< +/Type /Page +/Parent 1 0 R +/MediaBox [ 0 0 595.275591 841.889764 ] +/Contents 75 0 R +/Resources 4 0 R +/Annots [ 77 0 R 78 0 R 79 0 R 80 0 R 81 0 R 82 0 R 83 0 R 84 0 R 85 0 R 86 0 R 87 0 R 88 0 R 89 0 R 90 0 R 91 0 R 92 0 R 93 0 R 94 0 R 95 0 R 96 0 R 97 0 R 98 0 R 99 0 R 100 0 R 101 0 R 102 0 R 103 0 R 104 0 R 105 0 R 106 0 R 107 0 R 108 0 R 109 0 R 110 0 R 111 0 R 112 0 R ] +/TrimBox [ 0 0 595.275591 841.889764 ] +/BleedBox [ 0 0 595.275591 841.889764 ] +>> +endobj +77 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.673228 790.370079 498.679134 766.970079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the---authorization-mode-argument-includes-node-automated) +>> +endobj +78 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 481.786556 769.970079 491.179134 754.970079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the---authorization-mode-argument-includes-node-automated) +>> +endobj +79 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.673228 750.770079 498.679134 727.370079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the---authorization-mode-argument-includes-rbac-automated) +>> +endobj +80 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 481.786556 730.370079 491.179134 715.370079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the---authorization-mode-argument-includes-rbac-automated) +>> +endobj +81 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.673228 711.170079 498.679134 687.770079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the-admission-control-plugin-eventratelimit-is-set-automated) +>> +endobj +82 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 481.786556 690.770079 491.179134 675.770079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the-admission-control-plugin-eventratelimit-is-set-automated) +>> +endobj +83 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.673228 671.570079 498.679134 648.170079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the-admission-control-plugin-alwaysadmit-is-not-set-automated) +>> +endobj +84 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 481.786556 651.170079 491.179134 636.170079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the-admission-control-plugin-alwaysadmit-is-not-set-automated) +>> +endobj +85 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.673228 631.970079 498.679134 608.570079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the-admission-control-plugin-alwayspullimages-is-set-manual) +>> +endobj +86 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 481.786556 611.570079 491.179134 596.570079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the-admission-control-plugin-alwayspullimages-is-set-manual) +>> +endobj +87 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.673228 592.370079 498.679134 568.970079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the-admission-control-plugin-securitycontextdeny-is-set-if-podsecuritypolicy-is-not-used-manual) +>> +endobj +88 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 481.786556 571.970079 491.179134 556.970079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the-admission-control-plugin-securitycontextdeny-is-set-if-podsecuritypolicy-is-not-used-manual) +>> +endobj +89 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.673228 552.770079 498.679134 529.370079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the-admission-control-plugin-serviceaccount-is-set-automated) +>> +endobj +90 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 481.786556 532.370079 491.179134 517.370079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the-admission-control-plugin-serviceaccount-is-set-automated) +>> +endobj +91 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.673228 513.170079 498.679134 489.770079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the-admission-control-plugin-namespacelifecycle-is-set-automated) +>> +endobj +92 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 481.786556 492.770079 491.179134 477.770079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the-admission-control-plugin-namespacelifecycle-is-set-automated) +>> +endobj +93 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.673228 473.570079 498.679134 450.170079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the-admission-control-plugin-podsecuritypolicy-is-set-automated) +>> +endobj +94 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 481.786556 453.170079 491.179134 438.170079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the-admission-control-plugin-podsecuritypolicy-is-set-automated) +>> +endobj +95 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.673228 433.970079 498.679134 410.570079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the-admission-control-plugin-noderestriction-is-set-automated) +>> +endobj +96 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 481.786556 413.570079 491.179134 398.570079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the-admission-control-plugin-noderestriction-is-set-automated) +>> +endobj +97 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.673228 394.370079 498.679134 370.970079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the---insecure-bind-address-argument-is-not-set-automated) +>> +endobj +98 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 481.786556 373.970079 491.179134 358.970079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the---insecure-bind-address-argument-is-not-set-automated) +>> +endobj +99 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.673228 354.770079 498.679134 331.370079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the---insecure-port-argument-is-set-to-0-automated) +>> +endobj +100 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 481.786556 349.370079 491.179134 334.370079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the---insecure-port-argument-is-set-to-0-automated) +>> +endobj +101 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.673228 315.170079 498.679134 291.770079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the---secure-port-argument-is-not-set-to-0-automated) +>> +endobj +102 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 481.786556 309.770079 491.179134 294.770079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the---secure-port-argument-is-not-set-to-0-automated) +>> +endobj +103 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.673228 275.570079 498.679134 252.170079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the---profiling-argument-is-set-to-false-automated) +>> +endobj +104 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 481.786556 270.170079 491.179134 255.170079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the---profiling-argument-is-set-to-false-automated) +>> +endobj +105 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.673228 235.970079 498.679134 212.570079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the---audit-log-path-argument-is-set-automated) +>> +endobj +106 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 481.786556 230.570079 491.179134 215.570079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the---audit-log-path-argument-is-set-automated) +>> +endobj +107 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.673228 196.370079 498.679134 172.970079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the---audit-log-maxage-argument-is-set-to-30-or-as-appropriate-automated) +>> +endobj +108 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 481.786556 175.970079 491.179134 160.970079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the---audit-log-maxage-argument-is-set-to-30-or-as-appropriate-automated) +>> +endobj +109 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.673228 156.770079 498.679134 133.370079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the---audit-log-maxbackup-argument-is-set-to-10-or-as-appropriate-automated) +>> +endobj +110 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 481.786556 136.370079 491.179134 121.370079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the---audit-log-maxbackup-argument-is-set-to-10-or-as-appropriate-automated) +>> +endobj +111 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.673228 117.170079 498.679134 93.770079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the---audit-log-maxsize-argument-is-set-to-100-or-as-appropriate-automated) +>> +endobj +112 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 481.786556 96.770079 491.179134 81.770079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the---audit-log-maxsize-argument-is-set-to-100-or-as-appropriate-automated) +>> +endobj +113 0 obj +<< +/Filter /FlateDecode +/Length 3623 +>> +stream +x\K,X$c1rXxrif sOQɒZ*Lkf=#>$)l[? #dM d? rOeNH~dr! .|s}ə0o%$IPL!i 1@!"mX7XbFl0,'P1EvڤaXfFYfbe1Z0,b3!`I&$BChBޢ1Yw @$9$k2ULf',hqevT aVq^8&seY`FbL4L2sR1bVǑ5H?X搂,s̊2#zXf]VC1?efhoYf9+-lh`-Ĥg93!S I1c,&OGa'rINƇ :e&<̈9)z轍I֍d:e +I1e?\هA.Bj\Jc1`?uE?u9.A.81,3AA1,C]T:cXf6*\uY$92Fx C;? sA2X:ȥґ? @ǰ>[R'pYǰ\ IuO#)xt l9),`!4-%39[q2ǯ.`}3LkE6WEjS MNI 2щb3=7q荈q, ݼ3T$>pm=v.Ee::SBhT@k S?.tn`-B̑mF噡"sdE*2GVv$Q9:4 &&k4 u0a\d=&SRs +59!57;̑mB)9%k2g0>@̜LmM-9oc ; ;qbډ䢉;7q'v; I;ߝIN$Qv'vع݉9 +vb'qIN$Qn'vXwb's;9GNdQ;<݉\NE;Ŵp^݉ĝyu'v2q^݉\1;9GٝɜNdQ;sXNRn'x^7s,߇ b]#uy ͅ+ML{Y%Tm:߼?}7?3wͻӿ7ȥ<{tA5>T^A5> U^>s E#"Hre-_hGֽXwOJgᾸͤÝ:=n [#mс]_/VoK<`Z cix΋,O[mçp3ӈNwhL<9h.'qOښ LuZvv=Z.J~)\Uiw>SU'=L40 tỉ|;]خCiǃO6v+GO<v[mt`űcl8ݷXV] vvv6O{f6~}gQv~ygng*c5NlފΆ< qTc1P?(K~;MzۮGuNO1k.3a3Rg"q m\'7(Z8362,;ce^x)zj4N[FUo~Ac 阸*҉_VRqDޏfopedüFgZǫ'۱/B !vcN`bnn_Iz]S%9^ա #N[DZQj\8h:Mp3˛ijg^>瘕ߟ߆m-_A~KysW{hH>}xO3˸9뫶8I]RFHy>Fnuœn<ȴAO ݜUxkr([RGގ-Jhc~u{v3\7n%7)fvij&" {N 7qإT<إ4^6q݁YL^3@e +۾~"C5pȥ:]̦YLo7|8%!eҕ~Ѱt\ ƭ>4(o_o%N&7|#&w,ɏl\b>#c7qBmPv=/_X }[ 7 7Poc!TnP B*_K!~k+kdcjΤ#a[!]O[h j]ݧڠiQB[ T,PmmwCJ޹!?B\A+l'^mdtjLUUV֕cZ2pP@e z#%6y$IupMc R_ىQAM dXiFkh·o˄1VheqZRlcNMj:H4%iђo 9َlcɴB#ywbGJmmj{.sbguSj-afRs.ÝD9|2DLbm%K"uDI6Dx y`5}}lW4l~cm+ÊP;erA!ڍf!aj +endstream +endobj +114 0 obj +<< +/Type /Page +/Parent 1 0 R +/MediaBox [ 0 0 595.275591 841.889764 ] +/Contents 113 0 R +/Resources 4 0 R +/Annots [ 115 0 R 116 0 R 117 0 R 118 0 R 119 0 R 120 0 R 121 0 R 122 0 R 123 0 R 124 0 R 125 0 R 126 0 R 127 0 R 128 0 R 129 0 R 130 0 R 131 0 R 132 0 R 133 0 R 134 0 R 135 0 R 136 0 R 137 0 R 138 0 R 139 0 R 140 0 R 141 0 R 142 0 R 143 0 R 144 0 R 145 0 R 146 0 R 147 0 R 148 0 R 149 0 R 150 0 R ] +/TrimBox [ 0 0 595.275591 841.889764 ] +/BleedBox [ 0 0 595.275591 841.889764 ] +>> +endobj +115 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.673228 790.370079 498.679134 766.970079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the---request-timeout-argument-is-set-as-appropriate-automated) +>> +endobj +116 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 481.786556 769.970079 491.179134 754.970079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the---request-timeout-argument-is-set-as-appropriate-automated) +>> +endobj +117 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.673228 750.770079 498.679134 727.370079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the---service-account-lookup-argument-is-set-to-true-automated) +>> +endobj +118 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 481.786556 730.370079 491.179134 715.370079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the---service-account-lookup-argument-is-set-to-true-automated) +>> +endobj +119 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.673228 711.170079 498.679134 687.770079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the---service-account-key-file-argument-is-set-as-appropriate-automated) +>> +endobj +120 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 481.786556 690.770079 491.179134 675.770079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the---service-account-key-file-argument-is-set-as-appropriate-automated) +>> +endobj +121 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.673228 671.570079 498.679134 648.170079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the---etcd-certfile-and---etcd-keyfile-arguments-are-set-as-appropriate-automated) +>> +endobj +122 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 481.786556 651.170079 491.179134 636.170079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the---etcd-certfile-and---etcd-keyfile-arguments-are-set-as-appropriate-automated) +>> +endobj +123 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.673228 631.970079 498.679134 608.570079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the---tls-cert-file-and---tls-private-key-file-arguments-are-set-as-appropriate-automated) +>> +endobj +124 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 481.786556 611.570079 491.179134 596.570079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the---tls-cert-file-and---tls-private-key-file-arguments-are-set-as-appropriate-automated) +>> +endobj +125 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.673228 592.370079 498.679134 568.970079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the---client-ca-file-argument-is-set-as-appropriate-automated) +>> +endobj +126 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 481.786556 571.970079 491.179134 556.970079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the---client-ca-file-argument-is-set-as-appropriate-automated) +>> +endobj +127 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.673228 552.770079 498.679134 529.370079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the---etcd-cafile-argument-is-set-as-appropriate-automated) +>> +endobj +128 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 481.786556 532.370079 491.179134 517.370079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the---etcd-cafile-argument-is-set-as-appropriate-automated) +>> +endobj +129 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.673228 513.170079 498.679134 489.770079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the---encryption-provider-config-argument-is-set-as-appropriate-automated) +>> +endobj +130 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 481.786556 492.770079 491.179134 477.770079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the---encryption-provider-config-argument-is-set-as-appropriate-automated) +>> +endobj +131 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.673228 473.570079 498.679134 450.170079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-encryption-providers-are-appropriately-configured-automated) +>> +endobj +132 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 481.786556 453.170079 491.179134 438.170079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-encryption-providers-are-appropriately-configured-automated) +>> +endobj +133 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.673228 433.970079 498.679134 410.570079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the-api-server-only-makes-use-of-strong-cryptographic-ciphers-automated) +>> +endobj +134 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 481.786556 413.570079 491.179134 398.570079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the-api-server-only-makes-use-of-strong-cryptographic-ciphers-automated) +>> +endobj +135 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 76.423228 394.370079 504.679134 361.670079 ] +/BS << +/W 0 +>> +/Dest (controller-manager) +>> +endobj +136 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 482.305843 386.420079 496.429134 371.420079 ] +/BS << +/W 0 +>> +/Dest (controller-manager) +>> +endobj +137 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.673228 343.670079 498.679134 320.270079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the---terminated-pod-gc-threshold-argument-is-set-as-appropriate-automated) +>> +endobj +138 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 481.786556 323.270079 491.179134 308.270079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the---terminated-pod-gc-threshold-argument-is-set-as-appropriate-automated) +>> +endobj +139 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.673228 304.070079 498.679134 280.670079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the---profiling-argument-is-set-to-false-automated-1) +>> +endobj +140 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 481.786556 298.670079 491.179134 283.670079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the---profiling-argument-is-set-to-false-automated-1) +>> +endobj +141 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.673228 264.470079 498.679134 241.070079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the---use-service-account-credentials-argument-is-set-to-true-automated) +>> +endobj +142 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 481.786556 244.070079 491.179134 229.070079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the---use-service-account-credentials-argument-is-set-to-true-automated) +>> +endobj +143 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.673228 224.870079 498.679134 201.470079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the---service-account-private-key-file-argument-is-set-as-appropriate-automated) +>> +endobj +144 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 481.786556 204.470079 491.179134 189.470079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the---service-account-private-key-file-argument-is-set-as-appropriate-automated) +>> +endobj +145 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.673228 185.270079 498.679134 161.870079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the---root-ca-file-argument-is-set-as-appropriate-automated) +>> +endobj +146 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 481.786556 164.870079 491.179134 149.870079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the---root-ca-file-argument-is-set-as-appropriate-automated) +>> +endobj +147 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.673228 145.670079 498.679134 122.270079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the-rotatekubeletservercertificate-argument-is-set-to-true-automated) +>> +endobj +148 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 481.786556 125.270079 491.179134 110.270079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the-rotatekubeletservercertificate-argument-is-set-to-true-automated) +>> +endobj +149 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.673228 106.070079 498.679134 82.670079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the---bind-address-argument-is-set-to-127.0.0.1-automated) +>> +endobj +150 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 481.786556 85.670079 491.179134 70.670079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the---bind-address-argument-is-set-to-127.0.0.1-automated) +>> +endobj +151 0 obj +<< +/Filter /FlateDecode +/Length 3784 +>> +stream +x]K|T> f sOQYEvzz ,fXEVW(\5_1E~&`:?>X4WO6w}MZI~"88E'6 0LVf `z` Vʲb'VRc@or(^7ViؠA=Jذjsg_غ +)Blv4T/挱]ָ`aQM ס {줮ouן._5J_g1/ՑL>LЇȇȇ>v}1H:ט?M;!HiJϛ"e͛+YF|b3. +C 4Pƥ_b Hn&u)O-nY [$ vo&yBXlP-uۮX [dO[ioR&-ANͬc#v;q6, plA88w~FuxQDIѓ޹yPy3zIѓ'E?ET|Bw'EO}BW\z ;ޭkRpg"qmaum *'eQf$2Ωi$T@π*jL83R0739/ީwsF}\<G2TTIyKc  @&92ڑWW}c )A03X*i4 +cD?3R:ALx{uWA*pe$N=)蝛 E4=)zRQOŗ/t{RIW-t5muߢٔyg=My(_R;3}x;2APг F@#])uoe +Qx"|]5li5LEOKTn0E>1ڰUMw¢DMlgȞ22ز*`=nTTUNCTaa)-,JىeNb{@yTIѓ'E7s{h3f3'EO~"uO=)MhE =_0Bv{@4}.+}1$ň*1Ș"]֏_Lfʿ";!>arxЇ B߇-x-~k:b]T;gdi_+߾H᫿_|{>Пfi~%ZBN'7|[ +4a ̟l/-Z޾[:}uYv҃dK/3j[~9/l]Ҭ/)r7 E~8VF_ՙ]c( S",z';Ƈ|.sa/׋%JA!,)l2Ql뗎%ny(:wc]-L#g8P ]1Nm}eK۠ 6YY7NV<9f(~WF'JjGsŔ>uYߣ.g~ZYFOW}f3]>[JaL}?C{mkȷUo?F=2Ƙ7d1Qgo~#HAF$'Q&P#:Z;ofew |6]fML3I )E}?rc')!y?soIaƔxVa%l~`2E"Q bP;muEUsSX$k@Ʃ>6纨 +f=/fU\X \*rv-ڰF*TMSGz:~`H# +Zç- +GhUD͂T`Es>/7E> +endobj +153 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 76.423228 790.370079 504.679134 757.670079 ] +/BS << +/W 0 +>> +/Dest (scheduler) +>> +endobj +154 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 481.309749 782.420079 496.429134 767.420079 ] +/BS << +/W 0 +>> +/Dest (scheduler) +>> +endobj +155 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.673228 739.670079 498.679134 716.270079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the---profiling-argument-is-set-to-false-automated-2) +>> +endobj +156 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 481.786556 734.270079 491.179134 719.270079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the---profiling-argument-is-set-to-false-automated-2) +>> +endobj +157 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.673228 700.070079 498.679134 676.670079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the---bind-address-argument-is-set-to-127.0.0.1-automated-1) +>> +endobj +158 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 481.786556 679.670079 491.179134 664.670079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the---bind-address-argument-is-set-to-127.0.0.1-automated-1) +>> +endobj +159 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 76.423228 660.470079 504.679134 627.770079 ] +/BS << +/W 0 +>> +/Dest (etcd-node-configuration-files) +>> +endobj +160 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 481.237972 652.520079 496.429134 637.520079 ] +/BS << +/W 0 +>> +/Dest (etcd-node-configuration-files) +>> +endobj +161 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.673228 609.770079 498.679134 586.370079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the---cert-file-and---key-file-arguments-are-set-as-appropriate-automated) +>> +endobj +162 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 481.786556 589.370079 491.179134 574.370079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the---cert-file-and---key-file-arguments-are-set-as-appropriate-automated) +>> +endobj +163 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.673228 570.170079 498.679134 546.770079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the---client-cert-auth-argument-is-set-to-true-automated) +>> +endobj +164 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 481.786556 564.770079 491.179134 549.770079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the---client-cert-auth-argument-is-set-to-true-automated) +>> +endobj +165 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.673228 530.570079 498.679134 507.170079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the---auto-tls-argument-is-not-set-to-true-automated) +>> +endobj +166 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 481.786556 525.170079 491.179134 510.170079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the---auto-tls-argument-is-not-set-to-true-automated) +>> +endobj +167 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.673228 490.970079 498.679134 467.570079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the---peer-cert-file-and---peer-key-file-arguments-are-set-as-appropriate-automated) +>> +endobj +168 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 481.786556 470.570079 491.179134 455.570079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the---peer-cert-file-and---peer-key-file-arguments-are-set-as-appropriate-automated) +>> +endobj +169 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.673228 451.370079 498.679134 427.970079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the---peer-client-cert-auth-argument-is-set-to-true-automated) +>> +endobj +170 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 481.786556 430.970079 491.179134 415.970079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the---peer-client-cert-auth-argument-is-set-to-true-automated) +>> +endobj +171 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.673228 411.770079 498.679134 388.370079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the---peer-auto-tls-argument-is-not-set-to-true-automated) +>> +endobj +172 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 481.786556 406.370079 491.179134 391.370079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the---peer-auto-tls-argument-is-not-set-to-true-automated) +>> +endobj +173 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.673228 372.170079 498.679134 348.770079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-a-unique-certificate-authority-is-used-for-etcd-automated) +>> +endobj +174 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 481.786556 366.770079 491.179134 351.770079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-a-unique-certificate-authority-is-used-for-etcd-automated) +>> +endobj +175 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 76.423228 332.570079 504.679134 299.870079 ] +/BS << +/W 0 +>> +/Dest (authentication-and-authorization) +>> +endobj +176 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 478.154476 324.620079 496.429134 309.620079 ] +/BS << +/W 0 +>> +/Dest (authentication-and-authorization) +>> +endobj +177 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.673228 281.870079 498.679134 258.470079 ] +/BS << +/W 0 +>> +/Dest (client-certificate-authentication-should-not-be-used-for-users-manual) +>> +endobj +178 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 477.090267 261.470079 491.179134 246.470079 ] +/BS << +/W 0 +>> +/Dest (client-certificate-authentication-should-not-be-used-for-users-manual) +>> +endobj +179 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 76.423228 242.270079 504.679134 209.570079 ] +/BS << +/W 0 +>> +/Dest (logging) +>> +endobj +180 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 477.986019 234.320079 496.429134 219.320079 ] +/BS << +/W 0 +>> +/Dest (logging) +>> +endobj +181 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.673228 191.570079 498.679134 168.170079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-a-minimal-audit-policy-is-created-automated) +>> +endobj +182 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 477.090267 186.170079 491.179134 171.170079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-a-minimal-audit-policy-is-created-automated) +>> +endobj +183 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.673228 151.970079 498.679134 128.570079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the-audit-policy-covers-key-security-concerns-manual) +>> +endobj +184 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 477.090267 146.570079 491.179134 131.570079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the-audit-policy-covers-key-security-concerns-manual) +>> +endobj +185 0 obj +<< +/Filter /FlateDecode +/Length 3763 +>> +stream +x\ˮ#+66_"ËbY8,,9ntI|gu!|ZG[R`&&?3bs1/7!A'!8V1.k'R&1wI'6=G{;Kay:5<ޱISghMHOr(B^@\nkq#eٷYVmFyYW?mL,BsnvL&4uCm8tk~;6 }HC;ٗ?7|N>sc6$M;i?t|M?|:򇏗olFyMׄ|Mț$8[Kt|M?|:>fj-N.>tM. 9o?m0%J:&Mb(cfr[a8X`m13Y$pѪ .4 8; y1lMT0*a˞ i8n &JdU 3%cqd|2J90r?b8;?.%b28c Y8j29S&qOpN*9`g%~K?ރ3%R1ɆďW1Ξan جďQ1XP &%`6S'9DSRb A + ILSfU vI9FgV8p&̊JarR'xpTLgo8)8cP1Θc d*0 iMɪIgV'dRIPrQfV⇰uK䢊XSP1ypvK[Vpư?ٸb&Lh'D<?8'U ́X~))< K1Qg=#6j9|{R‰:X\n!bhL +&s 3(EcƙB4gh8##Lg9wɀ3 A 8;K#gQ8RK^ .S2ƹrNI301sRALlk'dGc#L,eCG.ilh(*.eCKt?¤R6}&qUx_<}]E~T֏" w?G*{>C͇*"-qU^ľ/)\BfEO{'sU_OW{t=ʋ6*Sy5͒"1^varx1'~g{yq/dNx>v "]ž[ue|^/cVpmsw=1O^n[#54ZxFU6FOS|8P%nCO.M<ˏ䪟lY{i:뇆ZLmbŊ_>]~9LI;b(s=ܜ7m70˃E5`+NgymnC-~T%e]*A(2Kq}B"IUlT(V{ëbBHB#u1r0Wkosw4R[ztZ.Jm2WLyA*7)UdsHh~M> +endobj +187 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 76.423228 790.370079 504.679134 757.670079 ] +/BS << +/W 0 +>> +/Dest (worker-node-configuration-files) +>> +endobj +188 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 477.518001 782.420079 496.429134 767.420079 ] +/BS << +/W 0 +>> +/Dest (worker-node-configuration-files) +>> +endobj +189 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.673228 739.670079 498.679134 716.270079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the-kubelet-service-file-permissions-are-set-to-644-or-more-restrictive-automated) +>> +endobj +190 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 477.090267 719.270079 491.179134 704.270079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the-kubelet-service-file-permissions-are-set-to-644-or-more-restrictive-automated) +>> +endobj +191 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.673228 700.070079 498.679134 676.670079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the-kubelet-service-file-ownership-is-set-to-rootroot-automated) +>> +endobj +192 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 477.090267 679.670079 491.179134 664.670079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the-kubelet-service-file-ownership-is-set-to-rootroot-automated) +>> +endobj +193 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.673228 660.470079 498.679134 637.070079 ] +/BS << +/W 0 +>> +/Dest (if-proxy-kubeconfig-file-exists-ensure-permissions-are-set-to-644-or-more-restrictive-automated) +>> +endobj +194 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 477.090267 640.070079 491.179134 625.070079 ] +/BS << +/W 0 +>> +/Dest (if-proxy-kubeconfig-file-exists-ensure-permissions-are-set-to-644-or-more-restrictive-automated) +>> +endobj +195 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.673228 620.870079 498.679134 597.470079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the-proxy-kubeconfig-file-ownership-is-set-to-rootroot-automated) +>> +endobj +196 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 477.090267 600.470079 491.179134 585.470079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the-proxy-kubeconfig-file-ownership-is-set-to-rootroot-automated) +>> +endobj +197 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.673228 581.270079 498.679134 557.870079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the---kubeconfig-kubelet.conf-file-permissions-are-set-to-644-or-more-restrictive-automated) +>> +endobj +198 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 477.090267 560.870079 491.179134 545.870079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the---kubeconfig-kubelet.conf-file-permissions-are-set-to-644-or-more-restrictive-automated) +>> +endobj +199 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.673228 541.670079 498.679134 518.270079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the---kubeconfig-kubelet.conf-file-ownership-is-set-to-rootroot-automated) +>> +endobj +200 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 477.090267 521.270079 491.179134 506.270079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the---kubeconfig-kubelet.conf-file-ownership-is-set-to-rootroot-automated) +>> +endobj +201 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.673228 502.070079 498.679134 478.670079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the-certificate-authorities-file-permissions-are-set-to-644-or-more-restrictive-automated) +>> +endobj +202 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 477.090267 481.670079 491.179134 466.670079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the-certificate-authorities-file-permissions-are-set-to-644-or-more-restrictive-automated) +>> +endobj +203 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.673228 462.470079 498.679134 439.070079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the-client-certificate-authorities-file-ownership-is-set-to-rootroot-automated) +>> +endobj +204 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 477.090267 442.070079 491.179134 427.070079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the-client-certificate-authorities-file-ownership-is-set-to-rootroot-automated) +>> +endobj +205 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.673228 422.870079 498.679134 399.470079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the-kubelet---config-configuration-file-has-permissions-set-to-644-or-more-restrictive-automated) +>> +endobj +206 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 477.090267 402.470079 491.179134 387.470079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the-kubelet---config-configuration-file-has-permissions-set-to-644-or-more-restrictive-automated) +>> +endobj +207 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.673228 383.270079 498.679134 359.870079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the-kubelet---config-configuration-file-ownership-is-set-to-rootroot-automated) +>> +endobj +208 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 477.090267 362.870079 491.179134 347.870079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the-kubelet---config-configuration-file-ownership-is-set-to-rootroot-automated) +>> +endobj +209 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 76.423228 343.670079 504.679134 310.970079 ] +/BS << +/W 0 +>> +/Dest (kubelet) +>> +endobj +210 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 481.214534 335.720079 496.429134 320.720079 ] +/BS << +/W 0 +>> +/Dest (kubelet) +>> +endobj +211 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.673228 292.970079 498.679134 269.570079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the-anonymous-auth-argument-is-set-to-false-automated) +>> +endobj +212 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 477.090267 272.570079 491.179134 257.570079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the-anonymous-auth-argument-is-set-to-false-automated) +>> +endobj +213 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.673228 253.370079 498.679134 229.970079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the---authorization-mode-argument-is-not-set-to-alwaysallow-automated-1) +>> +endobj +214 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 477.090267 232.970079 491.179134 217.970079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the---authorization-mode-argument-is-not-set-to-alwaysallow-automated-1) +>> +endobj +215 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.673228 213.770079 498.679134 190.370079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the---client-ca-file-argument-is-set-as-appropriate-automated-1) +>> +endobj +216 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 477.090267 193.370079 491.179134 178.370079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the---client-ca-file-argument-is-set-as-appropriate-automated-1) +>> +endobj +217 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.673228 174.170079 498.679134 150.770079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the---read-only-port-argument-is-set-to-0-automated) +>> +endobj +218 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 477.090267 168.770079 491.179134 153.770079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the---read-only-port-argument-is-set-to-0-automated) +>> +endobj +219 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.673228 134.570079 498.679134 111.170079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the---streaming-connection-idle-timeout-argument-is-not-set-to-0-automated) +>> +endobj +220 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 477.090267 114.170079 491.179134 99.170079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the---streaming-connection-idle-timeout-argument-is-not-set-to-0-automated) +>> +endobj +221 0 obj +<< +/Filter /FlateDecode +/Length 4004 +>> +stream +x\K sU$X @ E$@lE0䐿ZV3=^zT(GRΖ}ΤcɚHr!̐?L^ ^Oh@29xVhrne]XĘ8RPt)O rVug)8k$o/x4L3{E@JhLY+<Vl|*9` +QGdU0cLQ0PGM"C-`8⨈ + !T04Lc6ML8QrDt9$So='LR>fΘ@}S&`ʖ᜙r`!2-ԚgĢ4 .[MskN~O!rYbXme{ S[zйXdW0G?~lCȪ8܎Bܜ`&.rt<]In%'-ԋ l%uWWt?zqp85,ˎptP%rhLqp׷pi!QR8cǡJ˼y͗=EiE#D!]Wj<чɈ!G~ ݣ}#D!zW+oPG~u;h~.8zy&Lm{rX6Ü'LmTx_ٷ-9O^ҭsٺf&u6+:u(dE60@Vt.uʊ$̚ΜT4=3e41]jS*[} vΔ'qMIȅ>hOжĦ<LQ9oGLy8RN6h:g<D[bAPtcA9B#=>eϱcHKDȱ#⫑j;CC ;>*8QB%b,×4SIzMgQ9<)SMWBr`WbZPtN8ZpX.Ξc'tȱu&9m}u,&: e'i~ˆr$I儠Td)o+N;A_ق.*ٍ!xUggv(Q; +ztBwGeeы5]vRܙabvy1E\xxO&DSՇ<E'- .i< <{ēiy'[5}?8Amc"P L1ڤX1Sy*f %b?&B۽ i}ur7O +J>϶v3x?~9|e̮?xGZ3 ""2o+Wy>MҾVd-S/] ݋~v-o5[Z?T[.(^d^~Z~w=3FUGbK/tbPֱގY>/U B[t1 ;.YU|83\=}'tPm}E߿:_ipiY}_ZLv [;⁽V텿XX'v[AؼO'8n1&j> ]]җ5=vsEΗSX9{eiuR[[FmjZ}@^Ԁߊ?>}p%F~m;1gr5 je}%|O7ԬݾiظǺAظP]>q|7dՎqkŧ._qYѳZU0%&]vuvlѢKff *;ƓvxYeEfn2!!::P|(*lkK*.>n_Kf-j?H&m>[m'F$s}Pqx=>~pN'ˊ(-fVMɿm}n$ݰaVʿ,mﴙDJ$P"w^sٴ,kh|k窟ô|1LqRC#&0ڒlpB7 WyglC/gm8}yz{羿|S25<8U-ۓ|W2@z*L/H{c07^臹cĮ47^Nx9X>O: uvJNӄTpS.Pru&iW{T\i4CcbJ4,NpMuy_B0Bw/wv 7\a$zo'';ePcjlJ*SKY W:gCHN^IC:8@^QJ{q)3/IswdsS$~nם<u۳ܺ"˙ 7_$Na#"K7y@kH UIaCA2/+B^lƄ}=mp|qiϢK>+cJ!NTC!n?J(|%NDQNc]72 +N4FWL~sxݍ{U9(Ԟ;YR +'9/a}|Pˋ1J \H4UBVBDlc)f,ˈJ4ITIv6j;1:;8{-& [w*Nh{ٸf۳E¨LhF;7忷j+ĥa']Ϲ;Cg_>]Myu}d%6K$Fv3_/_]le; pYUo|}h꧱,)%{l.ڃ}w^?Q +endstream +endobj +222 0 obj +<< +/Type /Page +/Parent 1 0 R +/MediaBox [ 0 0 595.275591 841.889764 ] +/Contents 221 0 R +/Resources 4 0 R +/Annots [ 223 0 R 224 0 R 225 0 R 226 0 R 227 0 R 228 0 R 229 0 R 230 0 R 231 0 R 232 0 R 233 0 R 234 0 R 235 0 R 236 0 R 237 0 R 238 0 R 239 0 R 240 0 R 241 0 R 242 0 R 243 0 R 244 0 R 245 0 R 246 0 R 247 0 R 248 0 R 249 0 R 250 0 R 251 0 R 252 0 R 253 0 R 254 0 R 255 0 R 256 0 R ] +/TrimBox [ 0 0 595.275591 841.889764 ] +/BleedBox [ 0 0 595.275591 841.889764 ] +>> +endobj +223 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.673228 790.370079 498.679134 766.970079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the---protect-kernel-defaults-argument-is-set-to-true-automated) +>> +endobj +224 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 477.090267 769.970079 491.179134 754.970079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the---protect-kernel-defaults-argument-is-set-to-true-automated) +>> +endobj +225 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.673228 750.770079 498.679134 727.370079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the---make-iptables-util-chains-argument-is-set-to-true-automated) +>> +endobj +226 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 477.090267 730.370079 491.179134 715.370079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the---make-iptables-util-chains-argument-is-set-to-true-automated) +>> +endobj +227 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.673228 711.170079 498.679134 687.770079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the---hostname-override-argument-is-not-set-manual) +>> +endobj +228 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 477.090267 705.770079 491.179134 690.770079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the---hostname-override-argument-is-not-set-manual) +>> +endobj +229 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.673228 671.570079 498.679134 648.170079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the---event-qps-argument-is-set-to-0-or-a-level-which-ensures-appropriate-event-capture-automated) +>> +endobj +230 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 477.090267 651.170079 491.179134 636.170079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the---event-qps-argument-is-set-to-0-or-a-level-which-ensures-appropriate-event-capture-automated) +>> +endobj +231 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.673228 631.970079 498.679134 608.570079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the---tls-cert-file-and---tls-private-key-file-arguments-are-set-as-appropriate-automated-1) +>> +endobj +232 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 477.090267 611.570079 491.179134 596.570079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the---tls-cert-file-and---tls-private-key-file-arguments-are-set-as-appropriate-automated-1) +>> +endobj +233 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.673228 592.370079 498.679134 568.970079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the---rotate-certificates-argument-is-not-set-to-false-automated) +>> +endobj +234 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 477.090267 571.970079 491.179134 556.970079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the---rotate-certificates-argument-is-not-set-to-false-automated) +>> +endobj +235 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.673228 552.770079 498.679134 529.370079 ] +/BS << +/W 0 +>> +/Dest (verify-that-the-rotatekubeletservercertificate-argument-is-set-to-true-automated) +>> +endobj +236 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 477.090267 532.370079 491.179134 517.370079 ] +/BS << +/W 0 +>> +/Dest (verify-that-the-rotatekubeletservercertificate-argument-is-set-to-true-automated) +>> +endobj +237 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.673228 513.170079 498.679134 489.770079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the-kubelet-only-makes-use-of-strong-cryptographic-ciphers-automated) +>> +endobj +238 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 477.090267 492.770079 491.179134 477.770079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the-kubelet-only-makes-use-of-strong-cryptographic-ciphers-automated) +>> +endobj +239 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 76.423228 473.570079 504.679134 440.870079 ] +/BS << +/W 0 +>> +/Dest (rbac-and-service-accounts) +>> +endobj +240 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 481.191097 465.620079 496.429134 450.620079 ] +/BS << +/W 0 +>> +/Dest (rbac-and-service-accounts) +>> +endobj +241 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.673228 422.870079 498.679134 399.470079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the-cluster-admin-role-is-only-used-where-required-manual) +>> +endobj +242 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 477.090267 402.470079 491.179134 387.470079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the-cluster-admin-role-is-only-used-where-required-manual) +>> +endobj +243 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.673228 383.270079 498.679134 359.870079 ] +/BS << +/W 0 +>> +/Dest (minimize-access-to-secrets-manual) +>> +endobj +244 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 477.090267 377.870079 491.179134 362.870079 ] +/BS << +/W 0 +>> +/Dest (minimize-access-to-secrets-manual) +>> +endobj +245 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.673228 343.670079 498.679134 320.270079 ] +/BS << +/W 0 +>> +/Dest (minimize-wildcard-use-in-roles-and-clusterroles-manual) +>> +endobj +246 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 477.090267 338.270079 491.179134 323.270079 ] +/BS << +/W 0 +>> +/Dest (minimize-wildcard-use-in-roles-and-clusterroles-manual) +>> +endobj +247 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.673228 304.070079 498.679134 280.670079 ] +/BS << +/W 0 +>> +/Dest (minimize-access-to-create-pods-manual) +>> +endobj +248 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 477.090267 298.670079 491.179134 283.670079 ] +/BS << +/W 0 +>> +/Dest (minimize-access-to-create-pods-manual) +>> +endobj +249 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.673228 264.470079 498.679134 241.070079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-default-service-accounts-are-not-actively-used.-automated) +>> +endobj +250 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 477.090267 244.070079 491.179134 229.070079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-default-service-accounts-are-not-actively-used.-automated) +>> +endobj +251 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.673228 224.870079 498.679134 201.470079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-service-account-tokens-are-only-mounted-where-necessary-manual) +>> +endobj +252 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 477.090267 204.470079 491.179134 189.470079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-service-account-tokens-are-only-mounted-where-necessary-manual) +>> +endobj +253 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 76.423228 185.270079 504.679134 152.570079 ] +/BS << +/W 0 +>> +/Dest (pod-security-policies) +>> +endobj +254 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 478.790950 177.320079 496.429134 162.320079 ] +/BS << +/W 0 +>> +/Dest (pod-security-policies) +>> +endobj +255 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.673228 134.570079 498.679134 111.170079 ] +/BS << +/W 0 +>> +/Dest (minimize-the-admission-of-privileged-containers-manual) +>> +endobj +256 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 477.090267 129.170079 491.179134 114.170079 ] +/BS << +/W 0 +>> +/Dest (minimize-the-admission-of-privileged-containers-manual) +>> +endobj +257 0 obj +<< +/Filter /FlateDecode +/Length 3763 +>> +stream +x]K$ E> 0ٵX琿JZupU_HOI]ScΚ? +!zI+Od~*]m]T!{~ ʭ#\O똕9[%Iʛ' <,)OA͊㄄GIF(cf ~FT&4*ZG0R*F(Lh8fWlj; 7񧡨t f8R(ƉG7i7q)IpFX7i$X;QOYe qOhUى>`.:=))5 +zcBAO| +hzħQ:!RdْqVOٙ8Rq] +fScOdYB|MjD#WLr0) LpaS gu8k qSkFYH\32\3sf6tDO\3[hFfZhvO\3 `Bk&7iPkʌq ^O|f"$A3}f6k~Sk&j郠>)bLhfLfruSㆭOTk0=#5Y\<2#JjS~>}S9bN:Mj#W,]ڊ "J]ù6>_G&/&33s;!Tj.0 +NlW4.U"qB?^x|ōF]%Jxn*QXjlKBf\` DNp\(fFbC(,5yѦ .dγUw{?> pBbv~0;~x(,5+XhvRw?;+ +OSJnt)iލ FtO{S8?K{Sʻ, A5E=mJ-q̷<tKl=)~X'[,r[,>c;l>a(;a00vE8-[,!ݻ8<:L@h(IG9o?/(sF/c:R<껗̮/B/tKiEMh0cNhu_S&M恣i.iPm;f![n5`hje/"Jg- _8>_y^Vϵqj@^rϳg:,;*N(ˍl,0\Z,B]zK ԓSl}6fXkg]6l!)u]x_kUqMnƚ3DQwv'VU5/-_V~$G}d +fPd dn6y#4̉B&kEkf y.JS +t]ZrpBcY|: ӷjÉ &ahqy2L^v.@Y,k;.OPJx^-N2%ukP1h ?X>u]NƦ{16M&V C2t=욮PRЯ _5FnYave󙫪+:3m ۅZt j!B=tFЂ[q낮JŊRԅ53kPB6bQn]NC̍| +X,TinC5[lQ.h[{8qQ}/Tw5Z[[4ԇb*N͂Z*,.Sȳ&$f{#Iժ# 'қ+yG ө}*ZC{PXZVJP%X\c7=*{w|j|7 Zp" xYni006Ÿ(4.Z$utMY__>jm`lq! +XF7؄FK%jBij5S Rn 24/+։k}zjtPDOC̶|,,Ο" D2S!06:5S@J!II8ӈtjgڬd]eM;}J8^+Z+(:ւ7Frs0J6 U^V䞭mj݉QvY& ) - t*G_trbeah%_ EZWIz]&ْ ts0(mec/t۳6E\v]Q$wNx t'85$q ȳo\o)vxQ?Vˢyؽ9}|U6#TO}Z*R OI;^?l> +endstream +endobj +258 0 obj +<< +/Type /Page +/Parent 1 0 R +/MediaBox [ 0 0 595.275591 841.889764 ] +/Contents 257 0 R +/Resources 4 0 R +/Annots [ 259 0 R 260 0 R 261 0 R 262 0 R 263 0 R 264 0 R 265 0 R 266 0 R 267 0 R 268 0 R 269 0 R 270 0 R 271 0 R 272 0 R 273 0 R 274 0 R 275 0 R 276 0 R 277 0 R 278 0 R 279 0 R 280 0 R 281 0 R 282 0 R 283 0 R 284 0 R 285 0 R 286 0 R 287 0 R 288 0 R 289 0 R 290 0 R ] +/TrimBox [ 0 0 595.275591 841.889764 ] +/BleedBox [ 0 0 595.275591 841.889764 ] +>> +endobj +259 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.673228 790.370079 498.679134 766.970079 ] +/BS << +/W 0 +>> +/Dest (minimize-the-admission-of-containers-wishing-to-share-the-host-process-id-namespace-automated) +>> +endobj +260 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 477.090267 769.970079 491.179134 754.970079 ] +/BS << +/W 0 +>> +/Dest (minimize-the-admission-of-containers-wishing-to-share-the-host-process-id-namespace-automated) +>> +endobj +261 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.673228 750.770079 498.679134 727.370079 ] +/BS << +/W 0 +>> +/Dest (minimize-the-admission-of-containers-wishing-to-share-the-host-ipc-namespace-automated) +>> +endobj +262 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 477.090267 730.370079 491.179134 715.370079 ] +/BS << +/W 0 +>> +/Dest (minimize-the-admission-of-containers-wishing-to-share-the-host-ipc-namespace-automated) +>> +endobj +263 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.673228 711.170079 498.679134 687.770079 ] +/BS << +/W 0 +>> +/Dest (minimize-the-admission-of-containers-wishing-to-share-the-host-network-namespace-automated) +>> +endobj +264 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 477.090267 690.770079 491.179134 675.770079 ] +/BS << +/W 0 +>> +/Dest (minimize-the-admission-of-containers-wishing-to-share-the-host-network-namespace-automated) +>> +endobj +265 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.673228 671.570079 498.679134 648.170079 ] +/BS << +/W 0 +>> +/Dest (minimize-the-admission-of-containers-with-allowprivilegeescalation-automated) +>> +endobj +266 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 477.090267 651.170079 491.179134 636.170079 ] +/BS << +/W 0 +>> +/Dest (minimize-the-admission-of-containers-with-allowprivilegeescalation-automated) +>> +endobj +267 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.673228 631.970079 498.679134 608.570079 ] +/BS << +/W 0 +>> +/Dest (minimize-the-admission-of-root-containers-manual) +>> +endobj +268 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 477.090267 626.570079 491.179134 611.570079 ] +/BS << +/W 0 +>> +/Dest (minimize-the-admission-of-root-containers-manual) +>> +endobj +269 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.673228 592.370079 498.679134 568.970079 ] +/BS << +/W 0 +>> +/Dest (minimize-the-admission-of-containers-with-the-net_raw-capability-manual) +>> +endobj +270 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 477.090267 571.970079 491.179134 556.970079 ] +/BS << +/W 0 +>> +/Dest (minimize-the-admission-of-containers-with-the-net_raw-capability-manual) +>> +endobj +271 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.673228 552.770079 498.679134 529.370079 ] +/BS << +/W 0 +>> +/Dest (minimize-the-admission-of-containers-with-added-capabilities-manual) +>> +endobj +272 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 477.090267 532.370079 491.179134 517.370079 ] +/BS << +/W 0 +>> +/Dest (minimize-the-admission-of-containers-with-added-capabilities-manual) +>> +endobj +273 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.673228 513.170079 498.679134 489.770079 ] +/BS << +/W 0 +>> +/Dest (minimize-the-admission-of-containers-with-capabilities-assigned-manual) +>> +endobj +274 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 477.090267 492.770079 491.179134 477.770079 ] +/BS << +/W 0 +>> +/Dest (minimize-the-admission-of-containers-with-capabilities-assigned-manual) +>> +endobj +275 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 76.423228 473.570079 504.679134 440.870079 ] +/BS << +/W 0 +>> +/Dest (network-policies-and-cni) +>> +endobj +276 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 478.154476 465.620079 496.429134 450.620079 ] +/BS << +/W 0 +>> +/Dest (network-policies-and-cni) +>> +endobj +277 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.673228 422.870079 498.679134 399.470079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the-cni-in-use-supports-network-policies-manual) +>> +endobj +278 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 477.090267 417.470079 491.179134 402.470079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the-cni-in-use-supports-network-policies-manual) +>> +endobj +279 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.673228 383.270079 498.679134 359.870079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-all-namespaces-have-network-policies-defined-automated) +>> +endobj +280 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 477.090267 362.870079 491.179134 347.870079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-all-namespaces-have-network-policies-defined-automated) +>> +endobj +281 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 76.423228 343.670079 504.679134 310.970079 ] +/BS << +/W 0 +>> +/Dest (secrets-management) +>> +endobj +282 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 479.138851 335.720079 496.429134 320.720079 ] +/BS << +/W 0 +>> +/Dest (secrets-management) +>> +endobj +283 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.673228 292.970079 498.679134 269.570079 ] +/BS << +/W 0 +>> +/Dest (prefer-using-secrets-as-files-over-secrets-as-environment-variables-manual) +>> +endobj +284 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 477.090267 272.570079 491.179134 257.570079 ] +/BS << +/W 0 +>> +/Dest (prefer-using-secrets-as-files-over-secrets-as-environment-variables-manual) +>> +endobj +285 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.673228 253.370079 498.679134 229.970079 ] +/BS << +/W 0 +>> +/Dest (consider-external-secret-storage-manual) +>> +endobj +286 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 477.090267 247.970079 491.179134 232.970079 ] +/BS << +/W 0 +>> +/Dest (consider-external-secret-storage-manual) +>> +endobj +287 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 76.423228 213.770079 504.679134 181.070079 ] +/BS << +/W 0 +>> +/Dest (extensible-admission-control) +>> +endobj +288 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 478.118587 205.820079 496.429134 190.820079 ] +/BS << +/W 0 +>> +/Dest (extensible-admission-control) +>> +endobj +289 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.673228 163.070079 498.679134 139.670079 ] +/BS << +/W 0 +>> +/Dest (configure-image-provenance-using-imagepolicywebhook-admission-controller-manual) +>> +endobj +290 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 477.090267 142.670079 491.179134 127.670079 ] +/BS << +/W 0 +>> +/Dest (configure-image-provenance-using-imagepolicywebhook-admission-controller-manual) +>> +endobj +291 0 obj +<< +/Filter /FlateDecode +/Length 2228 +>> +stream +xZMDWDQv}K==P/*eIwv̨SO\_TfKL%E?/5)XiA>7&4ņ8lbn~7%e_ '73M) jʀS@؃{Pd.&`"n +]R^Ik, +AG0 "o1\*Dv;pc~a5֋8<4?0?nW$jtk~86eJ0ҡϼ`_Zbn$+yw7NO9?ytܬex|NG8ڭJt|N|:>]HaKNǁj'!3o64(hq Mѳs'4 &33}(ڼMPIx MLbyMH9b>q3]3}Pz*h.tS V ghbr9\r6M6Nc&݉yyYc&݉yQ<;1r;1OK2N;bw'uU@5ڔδvvK<s/&/%JlԅUM_|_ kӇ| _羚H‰($!@jP$W[ SEogE R/W駊-5:ӇR^S9k=a7w Bؿ+m\ufՃrS»d2'{PH]ؕȫ"!^Sܺ*єqcۜ57 i^РmʳT~M. 8OעS%mj6<Õ,~5zXe#3$Z-w}mm՞iMw]wRc^A[]˩]n2޼b6`{աt]*ye_ѱ9*w]-)~/3x.}__z+LQᖗ^(%#7xKק۬f]wbCWqبŽpOs\_v !]n0QkT3ڝ[CTLjMݛz㎦K-!lrR%6TZ]Yzhq GezJW+&-ޮx3sT_a͵ ޺>^]~ +>(ҦK0OjiR# i?&bF4|cj{'^kbzrPՠӯ=S#X+3`ksq +?` +L}zY9<ͭyT~|{ޭ09!d(*@X  Ļ087`´(RAQ]rL$]CA0d))!^tce֞)y ]ah: JB–PgfR!XǗ[8VmVq;pj)0j ztَxhl*JM׿k.Q"0=Bjn +5ƣTdi*sՇÉw +Xl*)<V))[$%#R qʗ < ,, + |v^4,bQ|ĴhZ w2D. %m^CAqDUnGagJ + +rWaP(KO2\(̧flHYrh=7YQ%[:&@3Xf5k@j!b׮pU6ݸ6Y3VH<6=heρ^r vA/UT +10n縹8yS1Z Uh:AB=cQH 2&46K[q>RbiK1b^;ʗw<閜4@AsRz|E=[P?(c{~+wY-ELvU>&wOЏ6G!F!9tsNj-}Vg#Os~X?-A&x…n7ƴb4|u0GP) ${펾^,L +endstream +endobj +292 0 obj +<< +/Type /Page +/Parent 1 0 R +/MediaBox [ 0 0 595.275591 841.889764 ] +/Contents 291 0 R +/Resources 4 0 R +/Annots [ 293 0 R 294 0 R 295 0 R 296 0 R 297 0 R 298 0 R 299 0 R 300 0 R 301 0 R 302 0 R ] +/TrimBox [ 0 0 595.275591 841.889764 ] +/BleedBox [ 0 0 595.275591 841.889764 ] +>> +endobj +293 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 76.423228 790.370079 504.679134 757.670079 ] +/BS << +/W 0 +>> +/Dest (general-policies) +>> +endobj +294 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 478.131038 782.420079 496.429134 767.420079 ] +/BS << +/W 0 +>> +/Dest (general-policies) +>> +endobj +295 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.673228 739.670079 498.679134 716.270079 ] +/BS << +/W 0 +>> +/Dest (create-administrative-boundaries-between-resources-using-namespaces-manual) +>> +endobj +296 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 477.090267 719.270079 491.179134 704.270079 ] +/BS << +/W 0 +>> +/Dest (create-administrative-boundaries-between-resources-using-namespaces-manual) +>> +endobj +297 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.673228 700.070079 498.679134 676.670079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the-seccomp-profile-is-set-to-dockerdefault-in-your-pod-definitions-manual) +>> +endobj +298 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 477.090267 679.670079 491.179134 664.670079 ] +/BS << +/W 0 +>> +/Dest (ensure-that-the-seccomp-profile-is-set-to-dockerdefault-in-your-pod-definitions-manual) +>> +endobj +299 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.673228 660.470079 498.679134 637.070079 ] +/BS << +/W 0 +>> +/Dest (apply-security-context-to-your-pods-and-containers-manual) +>> +endobj +300 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 477.090267 655.070079 491.179134 640.070079 ] +/BS << +/W 0 +>> +/Dest (apply-security-context-to-your-pods-and-containers-manual) +>> +endobj +301 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.673228 620.870079 498.679134 597.470079 ] +/BS << +/W 0 +>> +/Dest (the-default-namespace-should-not-be-used-automated) +>> +endobj +302 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 477.090267 615.470079 491.179134 600.470079 ] +/BS << +/W 0 +>> +/Dest (the-default-namespace-should-not-be-used-automated) +>> +endobj +303 0 obj +<< +/Filter /FlateDecode +/Length 4728 +>> +stream +x\ێȍ}ϯg 0; czS6j3'$EC:RfVۅJ!A2RAR]o/?]¿yp0oW\!Bqٛ9_/}5Shrv)F +%,)XPGgܞ3p$JPú힕1G +zhA5`xFO!e)/aStVƳƔj5eu[e5ybLt]|&@q LK.10)O.F`d?#4xF3 +xX ]V.Ak 0,gXC0,[fX`NpbX`6ǰrJaZ`' r ,P`Xu)0,]bXLʃ.`@d8*2,p],#ð^abe2))kr pDʋ֠eXc +,swWagQB`jxஶԌ&+3,@8LI+.Ix.`0,@TP^HaxRC.{fX[˰ wCCy&ðu xXdMXR0pWixJ̰ wKdXb!İ +N Âܔc BV䣼03, +ȢsF9;;FG~v\fv\{g'ⵔ츰\-D|\=x+Y.qaqޠX3;.$sK}=x9Yfqaqޠ#X3;.$K}<>xo~~\{\7hū{<̎ ;{&ؿ|<՞ tڤϗ~~?\O_+e~oJr +z>ïo^hG2y&+e:s?,3&-r܏x֯vvz[?{s0r:AOmyY{jWC׹_giQ +oVfr׻#67_~Y2V^i9eXm🿽|u 0Vc*mEC {S}qϪ*W[Qe&9Gitf~?2ߣ ?AhrWTz"qkFζ*bv1B|vnb#{zݝwV٧xC]1l)㋽jgrɆbTbYg~{N5ĝ_mr^'>VZd[ܛ}N:;QAڨד:?ё^ko<KWgVcݻZ;և3S.ɚknKq^hV-/νw>y|[<)Ë +pI]Ǐvm~wdd\g[Xw`zޝlVyjkM7Wh v{}ony`gV;˗:+rnNZdYM4Pp@yuS"Yi->v߅_QC m\YUD(D&iIb`WULLq;kTxѺ2?)®j/AkNOlgrקʭ-nk̈JʉNxrڽbkhӹƉIúmUy{ڤUb[ӛkmjwvsjlnEVyՐfFmO"ze1"kl*LyCNMP6hf]Ƕ*?6`[WNJ2k +^AoMn!w;T{Y^O"l7Wϟ43Gތ5_SjvP{vGC綟.a*_gS);oC'enҳa-q?QTyLyV9q_섚\*ӳd|M9ʗ„3ޓդWryQZz*>TAUD%.U}tyF3]Ħ4cM<#.R_)ESiV(ב!nBhg6ekrGH JSJ\-UnS3<ijQeǑUqcvۥ<#^|$} +kIr9/S5fWZg] ~/Rf#FP1 hXa.cYi/_@ndsUT[5rj\'ʯRE׋-7vJrl-M&W|%^jٮ_LbN0:jmTCY?E2˜ܑ VW*Kcow-%4l2Vؖ '`uc}Ǎx{ƕDm(ȦVXƟo+B潾 {9ur-oKZomp:|"qT3DH8]A"E']a˵ā(#ʡ<Ӭ]i,VHNˋA׻ +(*mbS "q9l9^A]BMk϶"/^Z@ƨ~:ˋJ.ZE T5ӪY'jjN^iF+a7ȭUK@^sS}d%yv>VnvͶW1  2U4&{ڡT6̝[* qݍ%y^ɾ#R{%JpUQWs^BT};?-+: p-kCƲU,춥MMQ4]\om?  +endstream +endobj +304 0 obj +<< +/Type /Page +/Parent 1 0 R +/MediaBox [ 0 0 595.275591 841.889764 ] +/Contents 303 0 R +/Resources 4 0 R +/Annots [ 305 0 R 306 0 R 307 0 R ] +/TrimBox [ 0 0 595.275591 841.889764 ] +/BleedBox [ 0 0 595.275591 841.889764 ] +>> +endobj +305 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 84.259843 740.570079 409.271317 725.570079 ] +/BS << +/W 0 +>> +/A << +/Type /Action +/S /URI +/URI (https://releases.rancher.com/documents/security/2.6/Rancher_v2-6_CIS_v1-6_Benchmark_Assessment.pdf) +>> +>> +endobj +306 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 351.653153 216.824079 461.230790 201.824079 ] +/BS << +/W 0 +>> +/A << +/Type /Action +/S /URI +/URI (https://www.cisecurity.org/benchmark/kubernetes/) +>> +>> +endobj +307 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 84.259843 201.824079 165.615800 186.824079 ] +/BS << +/W 0 +>> +/A << +/Type /Action +/S /URI +/URI (https://www.cisecurity.org/benchmark/kubernetes/) +>> +>> +endobj +308 0 obj +<< +/Filter /FlateDecode +/Length 3515 +>> +stream +x[K$ ׯ˒H@b NnzsǪbϬ2i*ȏT.ߟ\d\-JZ{++t K.@ŕbɗۂ_wM|3]k9t񭰘\dX>JɕS6X98,51RgVjXcB j# b +rɃ e(=[\-6W %Z<" ,^s9T-C|x -daeBɃ,xDh +Y`]A}x\j5|-̋>T %&!Kl!\Y! :XX@Y"eXe߂eRlaraJ݋ԥ%oawɃ,0` B% K  7`W0[X[qVoawclawcA0yƄ%X0p7rPǛpt`-,@/E%$nhO\-[XbL^s@B.,,H]* w`CD$n Dj y pyC \0]לoZXhaHb! # wޛiɃ,Tk>dx]}id஄M rB@@,8ZX+VJ 7R>‚AH,YH]V-,(PY2XX, Ŭ SHjcz Zx9Z&C(rNoaIda/AEFd/@$ / j,-,DhԒPc/ufrv*ZX7A 4y0aaGda(sLdܬ +Y6,4YYX|v&[X{ Z7#[XzZXȣDgm,f1dIHQLdA &:Y Ybc ZRoV fDFo T7y\M dLhDfk +3Y扁&V{yfR#e*|O># s("܂ݏcvݶ_>{{'IYuM 6)ߥ%(.r,U{3SvNFW3[ɧWEH:Hg1Nd8uNz5Ҕ qeMv#HeE^lois~)4@`0@L=|F2gSPty>le +)) ǻT%cnj)(XQi.+qI;zAQdq(eDG8xn?_?- +7oSOi3ҿFO;F_ ׽Oy; c6ZIh{˰.f?ls#抠Ss}헷dUNEɞ6uy}6OQPWSmhr纵X2|-"풱Ze(9Fl}aS9xCGxN-񨗾UN5#5iwzw}w汎]ϻ.,qϽۇg~?gG'g;_gwX>F>Zĺbקrar|w9RV:v}}. }-?tϷ{uw{k]~caLr!mnv>&UU?-A0B;vOS}U`|͛]c+{}wW;þO\L5lwxys9JnHa^yDŽ  xlrK=\=fB9}ͬ=yk8OB-h͹ly!w(nLU  w;>[qMO)WM)wgezkr 3*7y3q +F@QK@bqj"~i(i~,VM)۰`Ur}߃$&hR9B~]ɶ˰!z=e\ݵm~:շB@4L0 غ_zo Qޏd lʵ qVņ˃'׷ +ߏ^^={-Do .w]_ ++ޘ"/AfYG?0ܩӮKŶ%hT꫑SLُWoD<Ù,Gb]u%.3s@}Ɂ"3ѫ&9rGj=BUAiz3:OkR j=dž't] ⧾W&vCѯ~麘ة2zh뚟LS:oЮ*.ySXHβ}}UvOxx$ߖTibO4Ը\I- +ir$7H*ȳ~_ _H8@8@֑L^pH;q"FV?ɡξ[È1*{ap51M*rBi&=Ciq$2tofޚijH^uh-:C:ՃhAT)AL1H=Pz+HR FH&gCwں +)01hu@4u,Ll*|lCitc=ItZmTQ|liI{p1b2uR9Ť5 %&+WodK4͹sՠeIvsh{Q)HSϏ¿տדP[E +EZQל!,hg?YD虰| /70 5Tw@%<<|=˾bq fRQŋ$fzz 'j +endstream +endobj +309 0 obj +<< +/Type /Page +/Parent 1 0 R +/MediaBox [ 0 0 595.275591 841.889764 ] +/Contents 308 0 R +/Resources 4 0 R +/Annots [ 310 0 R 311 0 R ] +/TrimBox [ 0 0 595.275591 841.889764 ] +/BleedBox [ 0 0 595.275591 841.889764 ] +>> +endobj +310 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 84.259843 739.370079 128.273270 724.370079 ] +/BS << +/W 0 +>> +/A << +/Type /Action +/S /URI +/URI (https://kubernetes.io/docs/tasks/tools/) +>> +>> +endobj +311 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 345.193925 739.370079 356.281327 724.370079 ] +/BS << +/W 0 +>> +/A << +/Type /Action +/S /URI +/URI (https://stedolan.github.io/jq/) +>> +>> +endobj +312 0 obj +<< +/Filter /FlateDecode +/Length 3610 +>> +stream +x\M$ s% l drXwm9籺$88ǽ(|j*=~^S9Z[|?}8yWK" >%Rh{R,|=ݡn~=}ӿst"br!j@(%WJL0,H#EjpA  +5KAX["Z*(x xf,$albpLY,hɈ\.RdSd ]R%dЅK e ZȒaf*twUS]|5rUfS ԣ,R%,dQX\ Y.٧fʠK"-AƏ%O$*%Sd XؔA,1C_E 'dq@,ql@rX h 8bY . #rMtP.h`qtLؖ-} }jz K5ʅ+5 KN p/XRhf K %™ -.;: +,.`._,.`.(Z\Uulq|Z ލճ ލ)$ `ennL>Z\1[\GqoV]PHH3QX\!1 rlqA3eͅq +s w}V 5Z\-x7-.H]  (,.@~suMYsjqAW0)+,.;: EzodODdg= P ak4U#’w} +[2Y\6-.EX-.Up WvlqAn2|,;' @Y pa PXFZ\P"t-.(dkշ=.ps`2W%e`UKtm*dX\P +;`qR"-.;),.4PՈܒ"T`qAՠ5V2{Iڒ}frvR*Z\0NLiʠ hl`m).Zl7BMo .,.h>;)-.C-T7#[\f~[<#neo CŔAM͈[p`'KKllqAYo7/ Torx750%2MTރxSA}f 8yzry{y|ed^4Yl^5@Z0x'ܮ>KTP3kI6{ٌhv>/ +eG|#Iڱaߟ`lQf_WT;@ӽ-5^N +ƶc[j8ԵM5_O,`GSmpL +CMXB}LkT +Қ ~q"kY\^D qİ]k,,^"WeG=_eu /.Xl*" eЄ>qTM[pAC|NyiPP6}hssi˾U"WJu|b:c퀼36vS ̂/| +kCl<%^%|f=# _%>{xy͖jc˟E.i_?}͟w|}`|2>r.E` ?ϯcLSvjBkːv2dm߭۰ }A!ʎ8 1f;nڵГՓWKuOѥ7k}׶rߗMr3|ڦlZ[&ﭷ+>‚`bޯ#,-lцwVQ}qJr~𛛬ja6Vn%yeeh^M76mp0bN7U~2%y؏nEՓVi]9_#f9mBs{966NZquێ;ւnLkĉD*++g(sum.;[[z譎o~yo~"O';ˤlj0Sӷ߭=Uu#:n쨸߶e>زLi߾V]zNdZ /sβ,Ϻ?OɄ/+ƽGo~iZ=$G8j+~[ ̯ y|(ͱ;ߤKyjIto$$&?ozwٲd_9XYvz氷֧̓9V[E˒x>ȄnHa“F ܣuAfeӒ"e +~ +]e[|u ˷<`8uL&o3FaȊ'l7<kIe TiPqn ,/;+Bcf&!aGiV8a2)đ4)RDNqlSzazџRT!4e<Ӭc,Ttm}U9tP@tr#YzN H"g,-xs}Tu6HzPfО(]=S^OfYf\M+QSL'mWe1UɇoxZQ%eϖْ:vcl{VHC'Sb| j+!W Qs(iy+9CX^SK#>둰| ~O[+O)=w|h#,/x[X."[Ey#I[5TG\>Y~1g +endstream +endobj +313 0 obj +<< +/Type /Page +/Parent 1 0 R +/MediaBox [ 0 0 595.275591 841.889764 ] +/Contents 312 0 R +/Resources 4 0 R +/TrimBox [ 0 0 595.275591 841.889764 ] +/BleedBox [ 0 0 595.275591 841.889764 ] +>> +endobj +314 0 obj +<< +/Filter /FlateDecode +/Length 3665 +>> +stream +x\ێ}gY 0#@\B ȃ4VX\ !Y\Gqof]PH`Z\x]` И HK,.]ƚ[9*5Y\T0}:ʰnaeG)U "x-.]gQKHm w7D X\uM]ubqA0DGjqA"W xGf x S,\kò54Uҁw=a-x\-.H] P,.@,8X\s UR>S!,S,$֮r-,9 R JȾ] 2E dT rL؏.W2([\8b{)W-.;M,. H,.XT,.@(r% 3t,H-.@ % A J(e&oq"40bqA4U;M0ЄlG fS,Rn7K7 2> ONd @yoqAf .uY,.X7U%"E1u&%` U,.)~X\4Md@f6 ,xi7Z{{,,扁FV{yfAG2 ;˒SU(ɛ|Lp=}!#fX9F5|NB=gIY!8?Kҍr2_=v1(\H-n +ᶞBbLHfɦ_ls| G r=LɂXdl7zW~6_ޜ#x/{=SO8 ~{2b_=IGFzG7\Hk=^ߗ.]v`i}Ѻw෬|FZ_ֿ~\,}E&\jҟ1!i:Ty&_iuoTmkzk07Y7k[ŵNUƥ^ZS13~MV mZs?m/m8>VXþ x13ь) bY(_/3M>;"z}#[ݵ' ?.eVex^V{+_m{in#\zݲdD}feuz}][}v4[,}oftNcm_qI Y'ĶoE>9u-Ol `O$p[^=olixB3c~ՍYvD󔯿~~ qح۬k>n;I#Dc;uxumu|ˉ0{#ǽL[&#pQc5aoOgQ#Dc;)~x)m#E=~#Eѕ#yDHGFߎ~ڍQtvs7kۗ];~zcθR[I/v~ ީf z?dfW>B9հc{qz'Ǔcۍkku,~i㴙Yܼ}̿vƒ-iiϱUaV\^sɍWfGn}L1Ga%ĝ-BͶrGH0FY @*4Hi<.z}<u\>N]x9є4H;ޔ&_np}LDo8Sv%!n(׍w0އn erj'*+qjyj/gxWΦpq +Aag$,7;F* gr͕'˱1oR)O٬m-5'h3=-m9sWf}'G4(A 㹞VyOGjδ{eJ4,kf}hZxQĪq_gom/ e;7WVymo- "EoYՄgih0mNiyؒ}*F9czz}q*-+]\jk{y /ZaoObAU~-7MvA]D$AJ9\"J.ŷJ< wDG;Z*_qRS hP溣qbb? Q8HCw7]}6M׾L~)J_C|{٨W\on?eHsil2}URERe Iw)}}F'6xkY:ewf [z1VQ k[]Wc9>Y~k_ +endstream +endobj +315 0 obj +<< +/Type /Page +/Parent 1 0 R +/MediaBox [ 0 0 595.275591 841.889764 ] +/Contents 314 0 R +/Resources 4 0 R +/Annots [ 316 0 R ] +/TrimBox [ 0 0 595.275591 841.889764 ] +/BleedBox [ 0 0 595.275591 841.889764 ] +>> +endobj +316 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 101.433071 205.473057 101.433071 186.723057 ] +/BS << +/W 0 +>> +/Dest (cb1-1) +>> +endobj +317 0 obj +<< +/Filter /FlateDecode +/Length 3689 +>> +stream +x[oϧ8p8A"EE$JP>?˞Ieq] p͐=>'W\)5'9_^^Rbw%H5x~.r:ߝ\gsp@ˏv죡PybC9d9tVK3b GURKT0CB( L|TU2Tc6TaM " EdTj.CG9X:fP$KW]J)K'%VO.–H"-]-؛:JfKaKw+:'KWZDL]Η\࣋[:"17aEaR6t$-}t [_K1Vk͞EBS[0B->' XANd1   +;)R, +RBNRt,-QE&"Xp` +X,`-Abb[,0x+paX .$ T ebXbSX.KI e!o@]fi` &1X . 2 + 00Y,\qo@PX,p7dS [,p7Dtn>X,p7HH 0QlBb=t-2X,.U?cMVJM "Kgꪣ ^vRX]*X]X,"jX]bDjKRbAw7DX,@|s1uM]ub RX(|IL]vHd0vył"W bAw 1uKX:,[cM#Yu>tZ,HஆM) 0!  RWsN R!3u:Z,d:"Y, vkXl,[2X,@F*!6lAh$sX,1a?Z\+QX8bX+X xł\a "W2sKGIdY,( XPB.3yKՖN3ł"ih;M`bG7b6?lbc` GXPJfXP +l >X,fXP=lAg4MXCłJ  .uY,TobgIbA:؂L~tt * jJ, f`<(q+d]db.Dfk=33[YtYFVV<3CeI*c"ӧ*a:d̒B=([~ n?[Naec󫆊R`d;hR aܣF:$`q;tS#nɰXm&$3Kd. +d[n͋mA,Z`xu~:_ܞ#x/{=SП4^.ȶ;ˈqŷs;z<5uߎVn>v^|6ײ5/[37h>sm۝ g|'q-0omZZ]/{-A_kaY-͞Ѵ-Ȗix(Jrj9r~[Dm3c j+{suO/'VDGR.>^W>6ǣS8pxy()gxӦk|JTǩX)@i[fKi_gkό[dmd>z}>Ǻ?4oLr5#6e{^Wȃkvtvߩywu, f49ͣE>])5b$88oD&/=Lt=vg^FocRՇ1 2L׾udɎC8<"W'Gcݟv(tG7~H"Dq¢}˝~~vIkk3~R͙9ˢQ[|$?8|El݉Ho7Mؗ$ 2a͆Cx-v?JR'(u,Ç8O.+/Dc3zɭsh5f. |ĕ!Z Ӎ+` 97]<mMSLG#o}g%vV2p3fM>jɾzKo{ߣZ8mB2VQk[Odo=5,_; +endstream +endobj +318 0 obj +<< +/Type /Page +/Parent 1 0 R +/MediaBox [ 0 0 595.275591 841.889764 ] +/Contents 317 0 R +/Resources 4 0 R +/Annots [ 319 0 R ] +/TrimBox [ 0 0 595.275591 841.889764 ] +/BleedBox [ 0 0 595.275591 841.889764 ] +>> +endobj +319 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 101.433071 728.673057 101.433071 709.923057 ] +/BS << +/W 0 +>> +/Dest (cb2-1) +>> +endobj +320 0 obj +<< +/Filter /FlateDecode +/Length 4631 +>> +stream +x\[$m~_V+ 0!FEfڳ6yGUR:g9.R"?R*Uwev&"_o?_~XſZbsQٿ'Lp%pYL*x}\_]s[])%z*,&rJ6(uB0)VtC,EcA=+A .9h,g!qrt*' brr8oʃ sD(=j'x xh( Y`]YAxL(YlNm0!Y MRy(LRL +ChCQy% O'odiYO &_C!MQx\0dx@g29k(s1i0K0Kp; BQCr*Pa Cаx& h˰ p˶8 xE  1ĥY”%`Ѕ' K!z K%vVʃ,0` \& K&  7`V 0jX[1>gaw}aw}BPyI!h0p׳P Ǫpt`5,@ϓhx%+O%jX.cT^1.ABX4,]*Ұ wY`AD#DjuX pyCа` ߌ0]W-9kX%aH!9 "հ wދkkiʃ,k*>dXx]0km*D஄M b@@,kX3R԰  R> ɂY*pb XB%kX]y-JD@t>_?|7ç.?(s nqn`-,fZ +w,#Pk;-5:~BxVvCjnß2No/6ڭ򵲟wu6ۘP?~S3P5{y&XӿQ1O/D&lj+3-}Թ<1~,Dess DyQ"};XM#ݥvDV@dWi -['=I|*oLc̵ݦ*S bi_qAIdױ,Oi- U?S( +&/{I[廥\F~uy7kfn-0)ZoͲD-Ro7O\2Ma E%7v2F|dߙn.S/./bȓ)uEyÄzchQEuhKV=r0@{EA^Ͷk 9M璝.;+a ] 1tN&N/K-uvv،z9]mknc~Nmw2[{it:. -μ'k棱Yl|UF!.\,3yR&eu5qzTl=/?ӹ:GQw?Ьl=mY^<}mv-/='QeenwLB1B$ ˙Xİ,uc6d~x2\#ϼhvY`[F) +e9}su>:9SuOZֶYeUC'(6LkC.%w:N8S*B^)bA[D:NU8)tho~%:FI&>#]ua R9&וcSxGP{-`SpX9na'#xIv[A@zAP^ ktW$G#~Z&:˱ \3] c +Ku>DAC9k9 E_n>l^95?o>aXRPkE64V[n;}}F{У/e+8Ao15]# 8%OmgfQ+q\TZq_O%#Uq}I)Z9Jr؟p8Bsu>L OіBx=3=fc] +wh-ex2ŖX6%{C,ajp"<<I+'A|n|g=86gX̪K^=\|tKзT+ѲqFR}A˻Ǧgr[Uf+6N)O0w,f;]RI0` ^@xȁ]Wdh!W@a]|&Ǣ)2W_S1NRq, 񻖔 ]Qi{G)IV31_.>,i~򀾑&Mx[S_T5մm$TJ >O +vQ4c2;5yB͐+B]rkkTZ()w+KM>bܒ屈>6Ov ^#\BRJ64ӛ4{T9"k6> +endobj +322 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 101.433071 507.723057 101.433071 488.973057 ] +/BS << +/W 0 +>> +/Dest (cb3-1) +>> +endobj +323 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 488.776036 99.933071 470.026036 ] +/BS << +/W 0 +>> +/Dest (cb3-2) +>> +endobj +324 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 469.829014 99.933071 451.079014 ] +/BS << +/W 0 +>> +/Dest (cb3-3) +>> +endobj +325 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 431.934971 99.933071 413.184971 ] +/BS << +/W 0 +>> +/Dest (cb3-4) +>> +endobj +326 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 412.987950 99.933071 394.237950 ] +/BS << +/W 0 +>> +/Dest (cb3-5) +>> +endobj +327 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 394.040928 99.933071 375.290928 ] +/BS << +/W 0 +>> +/Dest (cb3-6) +>> +endobj +328 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 375.093907 99.933071 356.343907 ] +/BS << +/W 0 +>> +/Dest (cb3-7) +>> +endobj +329 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 356.146885 99.933071 337.396885 ] +/BS << +/W 0 +>> +/Dest (cb3-8) +>> +endobj +330 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 337.199864 99.933071 318.449864 ] +/BS << +/W 0 +>> +/Dest (cb3-9) +>> +endobj +331 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 318.252842 99.933071 299.502842 ] +/BS << +/W 0 +>> +/Dest (cb3-10) +>> +endobj +332 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 299.305821 99.933071 280.555821 ] +/BS << +/W 0 +>> +/Dest (cb3-11) +>> +endobj +333 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 280.358799 99.933071 261.608799 ] +/BS << +/W 0 +>> +/Dest (cb3-12) +>> +endobj +334 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 261.411778 99.933071 242.661778 ] +/BS << +/W 0 +>> +/Dest (cb3-13) +>> +endobj +335 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 242.464756 99.933071 223.714756 ] +/BS << +/W 0 +>> +/Dest (cb3-14) +>> +endobj +336 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 223.517735 99.933071 204.767735 ] +/BS << +/W 0 +>> +/Dest (cb3-15) +>> +endobj +337 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 204.570714 99.933071 185.820714 ] +/BS << +/W 0 +>> +/Dest (cb3-16) +>> +endobj +338 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 185.623692 99.933071 166.873692 ] +/BS << +/W 0 +>> +/Dest (cb3-17) +>> +endobj +339 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 166.676671 99.933071 147.926671 ] +/BS << +/W 0 +>> +/Dest (cb3-18) +>> +endobj +340 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 147.729649 99.933071 128.979649 ] +/BS << +/W 0 +>> +/Dest (cb3-19) +>> +endobj +341 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 128.782628 99.933071 110.032628 ] +/BS << +/W 0 +>> +/Dest (cb3-20) +>> +endobj +342 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 109.835606 99.933071 91.085606 ] +/BS << +/W 0 +>> +/Dest (cb3-21) +>> +endobj +343 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 90.888585 99.933071 72.138585 ] +/BS << +/W 0 +>> +/Dest (cb3-22) +>> +endobj +344 0 obj +<< +/Filter /FlateDecode +/Length 4927 +>> +stream +x][$m~_ `>y؝ݱ p|T.g%JK"?*ڝ-~~p/39闓5-J~dؕdRa.o??6M);>(S +HlRRtXFӖ  bY!e(%#1\ᤐ[ % +^965w&JK5Z&&r4Z11F 4CvDVA +9iYB VASh xNQh@J,6ZJ0\2J+ٜ-!XafPi(LRL +Ch4z G'8kbxHAL>B #aOP񤁀PPJA_P,IÁ`hi@,daY K(aA4,x +-A[4,[iXd]԰ p!հ qCaAB.=iXװ vaArV* @5,:rа٤awaF^̪F +l5, ϖ4, Op*-`аq z^zQ(X5BX V{|а̌GXaw]Slhe\.QSiŸWl\EQ   <װ.Sk4jX] a8g*[rְ%aHҒ"9 "հ wދk9 "pYB  f4Uc=Bw k4வhX65,I +|ְD^ÂɔXhp$d4B4,@`mJ(YÂ!K^Â! B }dADL.D$0-zZe\Ұ %2pNR&5, 4,9Ұ SѰd\9Ȃ [D9aAѠgdjX\CJ5,Li)UdLhXd5,@diJ,IÂYÂ!^IÂb! "> Fd YaAq' `of J7)v[B|3iXP0BY4nI7N-B_HÂY7ѫKYͤ.w4pi԰7jrB|dY]1^oU ,*k+9h1Y樮謺l`h էy*B|fNrfA{1w]ӯ?_Օ$,& pe*;B@^0F>FHeˢ W w[[ Ef`"SpuYn$Y!E !膯Ǯ6O׹1Hwy 9FB&k_UȽʻw~:BU~ϠPIc55ý̆3[:!ˎǚ+>Dy]Y=N%_HPr V|JLjΨ{ 'ֆ]mg|X=vv i-G}ivӮ ,E3nWxZ"$L)(Ÿ#6o%{ĩg@]5X U~82ȓw>YoR>2W#yFI8X;=/yKѩ>X{(h rl,b>bcSFJU a͕iI1$zܽ'kk59*{-gd}ٯ&נ~{L?ÎD0r}Km%)xP( e2AbrYG>w&q)3pEZ}*\(O#sF.Hd,k->>81puuc)i9KI[,%)x#W=+jQd-Dv_B"P$fOvf]d~VkU 6e.{㢅L&g<;?5]mϸ2|~x58Ͳ% JybҚ +4EȲQ? {I'3-{-D FݏDKi}gH#ohip04VҶ\SpOhr6m |P"+Yy7{D=k <  X$^}dXއv)ڐGlǚ| `:SC58jl#y%n=Ї|W8×>%4^;0ȭ#YBbvla-㓾w7wNZ.߱Gxڽa +!tJﰏg?um%voPu/+1{/ͪ t}9AθqªoAƱ&ϐ!p"Xh9CǪcۚq* +ql 9cM>'VΒݚw ot,ťxhlrږGd:H}^zZV_p}ѧMր7 )əO^4z{ˋ9. y)jō}.ZX=6kwC׫W|gmiw0uwW=R[XK( _Qzd>WWeWwzI%9Jޗ I-a2|^+Ӣ*eG*!5םV{͔B=lk~7^Vbex,WC'ݡ㫀H?׺l-f%ErcqpHsrW89UfўcM>eʷ|3N}yq;${P< ]cwEEw.\ʗɋą»G{Y2|ş'y{via!ic{g,@MﴬGsk(rVqXR'瓼>ԓum-ξ]ⷓLJ1b)\>΋\ǬV'L d/]>znw#5d%]_:V +2mܽ5n)ө,W±,YwgHsp4-vN-SwXޝou}X>Em.}SK%nz$Tj >OJI)6քidKanD^iZo}RGF~2T=>J?و 8 F;o +_NLGۉRVXn7o/v(.`Le/PT~pUJVW^pPFjq֎Nr8L/,9rCOtvŏ{wl]ϞL% ,o hlBObG]n^hn#ԹNžwaQr5=ֹr͡ GT6p1.K\IA%?5SeHSrOTk Fά[Y +B0_̌͝<7"rl {\oLJ;饡^e96#yBriЂVNy4[*)UQt@mecj2ťYzYcQyy>ΥժVԕѼrPKmK6u}ii6J+"md a(|o.e0jߩ7-7RЀ9Y _RP7^')HЛu~Z-ԟyҀ +endstream +endobj +345 0 obj +<< +/Type /Page +/Parent 1 0 R +/MediaBox [ 0 0 595.275591 841.889764 ] +/Contents 344 0 R +/Resources 4 0 R +/Annots [ 346 0 R 347 0 R 348 0 R 349 0 R 350 0 R 351 0 R 352 0 R 353 0 R 354 0 R 355 0 R 356 0 R 357 0 R 358 0 R 359 0 R 360 0 R 361 0 R 362 0 R 363 0 R 364 0 R 365 0 R 366 0 R 367 0 R 368 0 R ] +/TrimBox [ 0 0 595.275591 841.889764 ] +/BleedBox [ 0 0 595.275591 841.889764 ] +>> +endobj +346 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 799.173057 99.933071 780.423057 ] +/BS << +/W 0 +>> +/Dest (cb3-23) +>> +endobj +347 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 780.226036 99.933071 761.476036 ] +/BS << +/W 0 +>> +/Dest (cb3-24) +>> +endobj +348 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 761.279014 99.933071 742.529014 ] +/BS << +/W 0 +>> +/Dest (cb3-25) +>> +endobj +349 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 742.331993 99.933071 723.581993 ] +/BS << +/W 0 +>> +/Dest (cb3-26) +>> +endobj +350 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 723.384971 99.933071 704.634971 ] +/BS << +/W 0 +>> +/Dest (cb3-27) +>> +endobj +351 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 704.437950 99.933071 685.687950 ] +/BS << +/W 0 +>> +/Dest (cb3-28) +>> +endobj +352 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 685.490928 99.933071 666.740928 ] +/BS << +/W 0 +>> +/Dest (cb3-29) +>> +endobj +353 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 666.543907 99.933071 647.793907 ] +/BS << +/W 0 +>> +/Dest (cb3-30) +>> +endobj +354 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 647.596885 99.933071 628.846885 ] +/BS << +/W 0 +>> +/Dest (cb3-31) +>> +endobj +355 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 628.649864 99.933071 609.899864 ] +/BS << +/W 0 +>> +/Dest (cb3-32) +>> +endobj +356 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 609.702842 99.933071 590.952842 ] +/BS << +/W 0 +>> +/Dest (cb3-33) +>> +endobj +357 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 590.755821 99.933071 572.005821 ] +/BS << +/W 0 +>> +/Dest (cb3-34) +>> +endobj +358 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 571.808799 99.933071 553.058799 ] +/BS << +/W 0 +>> +/Dest (cb3-35) +>> +endobj +359 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 552.861778 99.933071 534.111778 ] +/BS << +/W 0 +>> +/Dest (cb3-36) +>> +endobj +360 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 533.914756 99.933071 515.164756 ] +/BS << +/W 0 +>> +/Dest (cb3-37) +>> +endobj +361 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 514.967735 99.933071 496.217735 ] +/BS << +/W 0 +>> +/Dest (cb3-38) +>> +endobj +362 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 496.020714 99.933071 477.270714 ] +/BS << +/W 0 +>> +/Dest (cb3-39) +>> +endobj +363 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 477.073692 99.933071 458.323692 ] +/BS << +/W 0 +>> +/Dest (cb3-40) +>> +endobj +364 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 458.126671 99.933071 439.376671 ] +/BS << +/W 0 +>> +/Dest (cb3-41) +>> +endobj +365 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 439.179649 99.933071 420.429649 ] +/BS << +/W 0 +>> +/Dest (cb3-42) +>> +endobj +366 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 420.232628 99.933071 401.482628 ] +/BS << +/W 0 +>> +/Dest (cb3-43) +>> +endobj +367 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 401.285606 99.933071 382.535606 ] +/BS << +/W 0 +>> +/Dest (cb3-44) +>> +endobj +368 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 101.433071 340.338585 101.433071 321.588585 ] +/BS << +/W 0 +>> +/Dest (cb4-1) +>> +endobj +369 0 obj +<< +/Filter /FlateDecode +/Length 4731 +>> +stream +x]K$ȳH" l,>Í=ttX,0="U]cg*ԃA)EH?9L%EtbM +jEer2'!P2vs??:M)ѻpga1SAa#Iɇ3R4=߲Ƃ}VXb'G1|r +!),g!֪<b+<Lң\|Qy <#21 Nc Y1d : KpVA4^,ɪ)ñ$ :Ӏ,d 5$ Y ְtwǟ/~-k rV/ > =`v0~d9&Zmʶi)^m>䥺\&?-]5󗵛+=v6DگmT%_ϋ9utqy"?.[MFꥇ}#eokm{8ڬuL4/h--.m""YVEƂX *>{:oBX02^ܛ%A D ڄ뢆~1ln˟>Z޸myuXʟE`Fg=TٯP!5GSo(=.n\ suk[ߊO57R_u(5ՓudcVMyy9^Oh]"Z˥u]` vy֗{ vݻN;dp08?-_6ÙId%]s^rۊ|N9ِnb~g萆j.zvdI6r=:h#͈4~yiX >nkAߘlg3sU(˝Ŧ(<ѹ0<֖-IrAX᧪zM* d +g&ʑi2͌FhLf4eh-&3*r;ًe˶=ue+AKܵjD~BĐ<{5fhi89!k]fc +0j_%dE힛R?wa";sw;,r`cUV5\{[ѤGZ>^wmkⲼ&; +Ǿm8\7u@z]mZۖ~fCݶnlܴNl6zmnKg4zN8/]#1 - g)jzϽ!ISqX\Deo"ױBfn B\h/@M_ʺnnC& +m_:V-Ye'i6^.JMfG< dGv"[dM'tAϪs>MrA~UrXkiXh4 U:5}@Bz(lk1?޲s3$J+^.jG*RyT-MCaꔻZJMr#-Ycmd7r =q^BRJ64ӛ4{Ԕ&g_*B +/I5jt"[%Q5 8N.d$fg}lt؆:l%nu,ӱr&&M< UE7{ru&>N#v'oėxOϭAT3DyJnIXm_iK s>,]e~_o0%{wlݐH&'d<݈m& Q64kq yT[IuL CwӕfN=ֱ{vs&.e<!:5+):B:짊am;y +)K<avn]LE|17,OF[e#"}96jN:S Nz=U. h=IpZbщG@;FtE lS)՚ZgUKYa0J)+׳% P9d%BsNQoݢu đQ-ܔ|wsR> +endobj +371 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 101.433071 709.923057 101.433071 691.173057 ] +/BS << +/W 0 +>> +/Dest (cb7-1) +>> +endobj +372 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 690.976036 99.933071 672.226036 ] +/BS << +/W 0 +>> +/Dest (cb7-2) +>> +endobj +373 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 672.029014 99.933071 653.279014 ] +/BS << +/W 0 +>> +/Dest (cb7-3) +>> +endobj +374 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 634.134971 99.933071 615.384971 ] +/BS << +/W 0 +>> +/Dest (cb7-4) +>> +endobj +375 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 596.240928 99.933071 577.490928 ] +/BS << +/W 0 +>> +/Dest (cb7-5) +>> +endobj +376 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 577.293907 99.933071 558.543907 ] +/BS << +/W 0 +>> +/Dest (cb7-6) +>> +endobj +377 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 558.346885 99.933071 539.596885 ] +/BS << +/W 0 +>> +/Dest (cb7-7) +>> +endobj +378 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 539.399864 99.933071 520.649864 ] +/BS << +/W 0 +>> +/Dest (cb7-8) +>> +endobj +379 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 520.452842 99.933071 501.702842 ] +/BS << +/W 0 +>> +/Dest (cb7-9) +>> +endobj +380 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 501.505821 99.933071 482.755821 ] +/BS << +/W 0 +>> +/Dest (cb7-10) +>> +endobj +381 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 482.558799 99.933071 463.808799 ] +/BS << +/W 0 +>> +/Dest (cb7-11) +>> +endobj +382 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 463.611778 99.933071 444.861778 ] +/BS << +/W 0 +>> +/Dest (cb7-12) +>> +endobj +383 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 444.664756 99.933071 425.914756 ] +/BS << +/W 0 +>> +/Dest (cb7-13) +>> +endobj +384 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 425.717735 99.933071 406.967735 ] +/BS << +/W 0 +>> +/Dest (cb7-14) +>> +endobj +385 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 406.770714 99.933071 388.020714 ] +/BS << +/W 0 +>> +/Dest (cb7-15) +>> +endobj +386 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 387.823692 99.933071 369.073692 ] +/BS << +/W 0 +>> +/Dest (cb7-16) +>> +endobj +387 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 368.876671 99.933071 350.126671 ] +/BS << +/W 0 +>> +/Dest (cb7-17) +>> +endobj +388 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 349.929649 99.933071 331.179649 ] +/BS << +/W 0 +>> +/Dest (cb7-18) +>> +endobj +389 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 330.982628 99.933071 312.232628 ] +/BS << +/W 0 +>> +/Dest (cb7-19) +>> +endobj +390 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 312.035606 99.933071 293.285606 ] +/BS << +/W 0 +>> +/Dest (cb7-20) +>> +endobj +391 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 293.088585 99.933071 274.338585 ] +/BS << +/W 0 +>> +/Dest (cb7-21) +>> +endobj +392 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 274.141563 99.933071 255.391563 ] +/BS << +/W 0 +>> +/Dest (cb7-22) +>> +endobj +393 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 255.194542 99.933071 236.444542 ] +/BS << +/W 0 +>> +/Dest (cb7-23) +>> +endobj +394 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 236.247520 99.933071 217.497520 ] +/BS << +/W 0 +>> +/Dest (cb7-24) +>> +endobj +395 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 217.300499 99.933071 198.550499 ] +/BS << +/W 0 +>> +/Dest (cb7-25) +>> +endobj +396 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 198.353477 99.933071 179.603477 ] +/BS << +/W 0 +>> +/Dest (cb7-26) +>> +endobj +397 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 179.406456 99.933071 160.656456 ] +/BS << +/W 0 +>> +/Dest (cb7-27) +>> +endobj +398 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 160.459434 99.933071 141.709434 ] +/BS << +/W 0 +>> +/Dest (cb7-28) +>> +endobj +399 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 141.512413 99.933071 122.762413 ] +/BS << +/W 0 +>> +/Dest (cb7-29) +>> +endobj +400 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 122.565391 99.933071 103.815391 ] +/BS << +/W 0 +>> +/Dest (cb7-30) +>> +endobj +401 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 103.618370 99.933071 84.868370 ] +/BS << +/W 0 +>> +/Dest (cb7-31) +>> +endobj +402 0 obj +<< +/Filter /FlateDecode +/Length 4923 +>> +stream +x]K$m赁+K". pAb|[ְ>a +PyI[fnkX]>jXC1F]@Hհ=x4,@c#,Ѱ w]4ʸ\2O4-l\EÂDE.3kX7Q3:_!hXs0ߌ0]W-9kX%afac3D%CrEaAbz/D DDe=*P n4Uc=Bwk<வhX2mjX|ְD^ÂٔXhp4,HRykX*YÂ! yaA!Lq\! "E d&f RǠU p2x.iXLNR&5, 4,9ְ WѰSsAtsNÂ! A 2հ34rIZ㱕<3kX9 5, R<а#vаM9*P` rnf r,z `o& ,4,(6 5,ge䛞5,_J5,(do"SP|3iXP(* h*o4^,%F73o"WI].dx]DQ\ Dd3%ꊁ̭ꒁbJꚁJ.@Ld9VtV]6_cÄӸDa sfNrn[ы'.c_1_ԕGI/n1A#H#B҅teMT鶜L3E0TuY$Y2C81J +b:OoW&u%+֐!(>dN4ـ)S }5!'+/3`Mr8-_ֽ 6b$f=_ ~y?Gk9'_q_j3BQ#KuDTCCv1$6 GpiM 4fL㳬.to:z'y߁ kLAV*C DK~K)wRˡN<Sm hӖNVϛ6Wel RPĝNwOD+:ĂZnul{As>d=&$\VyڂĦX]uխ8qq*rn/sÃD<\Oy򒺡[|-SZ7 };pI?͈@_22ZT[dO uCwN/?-`Jm1vu>ƇGX^f+Q|mZFZ)p'mNYQHUq 搝̸p ˴Y:HQ۶|먻,?q\y'k.øvg5>'YGB :t:ȓ +P:tUݿ/{rpT'GPh)_!gmtRoWn /[f?oU&pkV}X&pn8\qK$;\L&{)+z`GF } %`l8B:=;9嶹ؾcx(`jTj߱zCT`|@J: +ԗ?CdJT3u-. *\R}+SY}-Ju۪,ğ:/q@TYBs Ob!3BʼnfJ;*N/?"AO{y{sjϮ.k3?=L!Cޗ?e5%躚?As#} w_D7 "d?2tfA'染dۼ'Tj%mـtck[@M! +ST1x)!k$G# Bae UmAE$G9\y)S[fCmO|+z(:5ݲtcu1y[lPov\Qo2T4|=!R\}w={Ծ3kRs& >eܱ [h FeH4a]dA,wZ o)V#9qY _%>FE^.'g"_!It*h*Z*̀/tx69Z{g_+2AC^t=CGlpG]D̀ gu^G]$o 1ޝmNoL_>F!uә\1 /H%iob$c&sU^g`0j[̈́g Ҋ)q(:YX烽ecc26X(:*wk3wnlحz.p_۽0'(x'F<z==~vސH!G[mnsev,͢ tzL @ȱ:p3$}.dzɡ*d<R^Pji|wGdƀ8W87Uy #q4t &˓_~1"22Hej +/^ʄEO [)RqvnA~{B;xճVc ezsG_ߗ?ے5+]vm+}+V*w+{isu15YwکoW>ks*˵6;8a쟆Yۀ᯻b?_cȦ6nUL;CݥK(83e{ƕTLO0n@w )`W3 wT^턏ʻNw_׃8/ -| yW4$Y~Uc%6d{ٰZCǽ{uہ}-p fѠpv| rI͡#\Wp1.sQC}JPc:,]bc'M"?C!k{F%uivlzջ bliȣ{}/"ڠQ?Fj16өT/9TyZ[4 F-xs1@ͽR JtN .@+VRmUKj)S2j:ҔQ:hZFsNl/bɬXQ}y ^-J>ΥժVj[WB\GWcfS52ctL)y<,]Z~Ed]+{p&"|QCSodcrK)@Y +0gw+AgYjIRE17ϟ$ԥ Y>PuO +endstream +endobj +403 0 obj +<< +/Type /Page +/Parent 1 0 R +/MediaBox [ 0 0 595.275591 841.889764 ] +/Contents 402 0 R +/Resources 4 0 R +/Annots [ 404 0 R 405 0 R 406 0 R 407 0 R 408 0 R 409 0 R 410 0 R 411 0 R 412 0 R 413 0 R 414 0 R 415 0 R 416 0 R 417 0 R 418 0 R 419 0 R 420 0 R 421 0 R 422 0 R 423 0 R 424 0 R 425 0 R 426 0 R 427 0 R 428 0 R 429 0 R 430 0 R 431 0 R 432 0 R 433 0 R 434 0 R ] +/TrimBox [ 0 0 595.275591 841.889764 ] +/BleedBox [ 0 0 595.275591 841.889764 ] +>> +endobj +404 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 799.173057 99.933071 780.423057 ] +/BS << +/W 0 +>> +/Dest (cb7-32) +>> +endobj +405 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 780.226036 99.933071 761.476036 ] +/BS << +/W 0 +>> +/Dest (cb7-33) +>> +endobj +406 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 761.279014 99.933071 742.529014 ] +/BS << +/W 0 +>> +/Dest (cb7-34) +>> +endobj +407 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 742.331993 99.933071 723.581993 ] +/BS << +/W 0 +>> +/Dest (cb7-35) +>> +endobj +408 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 723.384971 99.933071 704.634971 ] +/BS << +/W 0 +>> +/Dest (cb7-36) +>> +endobj +409 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 704.437950 99.933071 685.687950 ] +/BS << +/W 0 +>> +/Dest (cb7-37) +>> +endobj +410 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 685.490928 99.933071 666.740928 ] +/BS << +/W 0 +>> +/Dest (cb7-38) +>> +endobj +411 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 666.543907 99.933071 647.793907 ] +/BS << +/W 0 +>> +/Dest (cb7-39) +>> +endobj +412 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 647.596885 99.933071 628.846885 ] +/BS << +/W 0 +>> +/Dest (cb7-40) +>> +endobj +413 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 628.649864 99.933071 609.899864 ] +/BS << +/W 0 +>> +/Dest (cb7-41) +>> +endobj +414 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 609.702842 99.933071 590.952842 ] +/BS << +/W 0 +>> +/Dest (cb7-42) +>> +endobj +415 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 590.755821 99.933071 572.005821 ] +/BS << +/W 0 +>> +/Dest (cb7-43) +>> +endobj +416 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 571.808799 99.933071 553.058799 ] +/BS << +/W 0 +>> +/Dest (cb7-44) +>> +endobj +417 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 552.861778 99.933071 534.111778 ] +/BS << +/W 0 +>> +/Dest (cb7-45) +>> +endobj +418 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 533.914756 99.933071 515.164756 ] +/BS << +/W 0 +>> +/Dest (cb7-46) +>> +endobj +419 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 514.967735 99.933071 496.217735 ] +/BS << +/W 0 +>> +/Dest (cb7-47) +>> +endobj +420 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 496.020714 99.933071 477.270714 ] +/BS << +/W 0 +>> +/Dest (cb7-48) +>> +endobj +421 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 477.073692 99.933071 458.323692 ] +/BS << +/W 0 +>> +/Dest (cb7-49) +>> +endobj +422 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 458.126671 99.933071 439.376671 ] +/BS << +/W 0 +>> +/Dest (cb7-50) +>> +endobj +423 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 439.179649 99.933071 420.429649 ] +/BS << +/W 0 +>> +/Dest (cb7-51) +>> +endobj +424 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 420.232628 99.933071 401.482628 ] +/BS << +/W 0 +>> +/Dest (cb7-52) +>> +endobj +425 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 382.338585 99.933071 363.588585 ] +/BS << +/W 0 +>> +/Dest (cb7-53) +>> +endobj +426 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 363.391563 99.933071 344.641563 ] +/BS << +/W 0 +>> +/Dest (cb7-54) +>> +endobj +427 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 344.444542 99.933071 325.694542 ] +/BS << +/W 0 +>> +/Dest (cb7-55) +>> +endobj +428 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 325.497520 99.933071 306.747520 ] +/BS << +/W 0 +>> +/Dest (cb7-56) +>> +endobj +429 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 306.550499 99.933071 287.800499 ] +/BS << +/W 0 +>> +/Dest (cb7-57) +>> +endobj +430 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 287.603477 99.933071 268.853477 ] +/BS << +/W 0 +>> +/Dest (cb7-58) +>> +endobj +431 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 268.656456 99.933071 249.906456 ] +/BS << +/W 0 +>> +/Dest (cb7-59) +>> +endobj +432 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 249.709434 99.933071 230.959434 ] +/BS << +/W 0 +>> +/Dest (cb7-60) +>> +endobj +433 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 230.762413 99.933071 212.012413 ] +/BS << +/W 0 +>> +/Dest (cb7-61) +>> +endobj +434 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 101.433071 169.815391 101.433071 151.065391 ] +/BS << +/W 0 +>> +/Dest (cb8-1) +>> +endobj +435 0 obj +<< +/Filter /FlateDecode +/Length 4512 +>> +stream +x\K$ s+H Y ]8C~>JfwNb =_N_mw]8AXL&lPX,Ha`R!* XƂ!kV\rX ++C U O5p%$,pZA,3y炉Pzxޙ/*/xD&&vibb!k<,Xd j<”Ƌ"YY|NdNQxʃ,6Z +P2+ٜ5`B&9`Q,ц K 5A?rVՋw%d>ʃ,| |,6E AFpIYp次pJ/p,I<4 YG AjXC1f]@Hհ 2.aASyŸ+~ -cѰ wHÂ|f kX5pb5,] AqH4,@|3tU^1aAf K4,kX `aAlJJQÂX,xHT^4x$ Bd<‰5,@bm +aA򐅼װ yȂAd8d\CdL.V5^&'๤aAJlXK װo$]ҰbXÂT \E"=2s l 眆CddʌVDh%jV֙YÂHa+M ʃ, 0?`&9*P` r Y6e4,( Ӱh$Mְ0aR֛YÂBM,-e4,( YRY4oIXo4^,%FYof f`^ȲLvp7 "3MdxCB~38c`U2^DXMe*Ϊ|0a}"!!f$,p Fv(|gusHjiF~7}; "U2i*C(\7D(;|FRն[1Q Bea/౶ȶ`iBIWz(tBRHsCKVR)$J^VD5\`FzQp`!aySWN@Ueӻ?: +M|QHw_}<("0 CX7 ry˗W:2z8>?wdqqఀT_/cX]S>DEٗ2?urmwcD&ڑaլ9v07Ծcow[bӼ#דm:H1Coy9͆־laŎ7Η+Zl/~-ߓOZ_VibF\4o~Ҽ>.6D~VV;;ɖizB^U\y,W׼vn',Zdcq^ۊw(vh_IcQڮVsukiX/4볝:Ժgl)>q6~zCm'8y]s֮[ǰui3(Y۱4]|~+&7O}Dy+?~A=2-,v--2; +ٻrȞ >o?hAqɰ馿z+X}KST +V{Pdgv4kQ;:: -BG˻U@nfW]9S]NhVljR$/"6$QVtF!VQ;^=,򏖧t[n?Ci{D5 >\2a o{ lf3 E6_Kv[,(@1ʘ@w@ +[XRa}wRKdOkgg͸x-6Fx<tS L!W[~oZl-A'&[É9s#;rLJa|cRtVA' (F c:cx2wR[[i?<ꔣPeg:Ov{=ewz +v;%ڕ b(d(4{^fp7L3D㣗DdHNאVٙP$*%S L:=y$_Or<aݾ],la-<+Ň6.7AǑQ8TyWyDHtA>Uyȭ$pI[4[g\Y9L3r4{D9<:/ӳlM&S6?| p[$W+r 0"&$;VdE[~ߑ>l*uS=(^-b7 D=^Yכo7au\/>A6y\H7v;~fGr4\ܮvEN='8-'->b}+|*6 `ç"l՟O5<]IÍ d :^o/o즿s7-m4gm{0qO~ + Ξa*..Lס*OQr!ED%z}KA.\6>];fc]BԖ7NPtFboMY! 3ʄAQLTyBl;y%AhՌ(/|^r]!9r[˥u]7`d^yI,^UvA]߷i{v;]nI =J*Ii}\me:²osNQ[ϓ +W_gc8sm?Z_rl=wi9ٜ,2iFW[x9Ҹ"/cȌru\U;ߨYc/~DwNa-cNN;Ő~JrBf'i{[FSٗ`8NahUxl[!Wі"jFwM[V|4>.JMfG< ɎD D;u7ȞMyx9[S_TdjM5zi4 U:5}BϓB5͘ΟfM.> +endobj +437 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 101.433071 541.623057 101.433071 522.873057 ] +/BS << +/W 0 +>> +/Dest (cb11-1) +>> +endobj +438 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 522.676036 99.933071 503.926036 ] +/BS << +/W 0 +>> +/Dest (cb11-2) +>> +endobj +439 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 503.729014 99.933071 484.979014 ] +/BS << +/W 0 +>> +/Dest (cb11-3) +>> +endobj +440 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 465.834971 99.933071 447.084971 ] +/BS << +/W 0 +>> +/Dest (cb11-4) +>> +endobj +441 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 427.940928 99.933071 409.190928 ] +/BS << +/W 0 +>> +/Dest (cb11-5) +>> +endobj +442 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 408.993907 99.933071 390.243907 ] +/BS << +/W 0 +>> +/Dest (cb11-6) +>> +endobj +443 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 390.046885 99.933071 371.296885 ] +/BS << +/W 0 +>> +/Dest (cb11-7) +>> +endobj +444 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 371.099864 99.933071 352.349864 ] +/BS << +/W 0 +>> +/Dest (cb11-8) +>> +endobj +445 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 352.152842 99.933071 333.402842 ] +/BS << +/W 0 +>> +/Dest (cb11-9) +>> +endobj +446 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 333.205821 99.933071 314.455821 ] +/BS << +/W 0 +>> +/Dest (cb11-10) +>> +endobj +447 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 314.258799 99.933071 295.508799 ] +/BS << +/W 0 +>> +/Dest (cb11-11) +>> +endobj +448 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 295.311778 99.933071 276.561778 ] +/BS << +/W 0 +>> +/Dest (cb11-12) +>> +endobj +449 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 276.364756 99.933071 257.614756 ] +/BS << +/W 0 +>> +/Dest (cb11-13) +>> +endobj +450 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 257.417735 99.933071 238.667735 ] +/BS << +/W 0 +>> +/Dest (cb11-14) +>> +endobj +451 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 238.470714 99.933071 219.720714 ] +/BS << +/W 0 +>> +/Dest (cb11-15) +>> +endobj +452 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 219.523692 99.933071 200.773692 ] +/BS << +/W 0 +>> +/Dest (cb11-16) +>> +endobj +453 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 200.576671 99.933071 181.826671 ] +/BS << +/W 0 +>> +/Dest (cb11-17) +>> +endobj +454 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 181.629649 99.933071 162.879649 ] +/BS << +/W 0 +>> +/Dest (cb11-18) +>> +endobj +455 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 162.682628 99.933071 143.932628 ] +/BS << +/W 0 +>> +/Dest (cb11-19) +>> +endobj +456 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 143.735606 99.933071 124.985606 ] +/BS << +/W 0 +>> +/Dest (cb11-20) +>> +endobj +457 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 124.788585 99.933071 106.038585 ] +/BS << +/W 0 +>> +/Dest (cb11-21) +>> +endobj +458 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 105.841563 99.933071 87.091563 ] +/BS << +/W 0 +>> +/Dest (cb11-22) +>> +endobj +459 0 obj +<< +/Filter /FlateDecode +/Length 4906 +>> +stream +x]]不}_q">AX$42 s3 $eKr,V/jzL-G,܋şoKk[7X]L?ِ 3$J&)]e_/.q/ޔ(@&,+uMJŠKXPSaJP# jPBre  jIa9 =VAyDtzxޙ/*/xD&ibb5^.\x ]؅`5t ƋЅ"Y]|Nt蝢2tue]lN2\r*gs[l8Ya&a  w!a{_~}il`$,. peڙ& Q",΋n$bL~qkLwv)8 E]2ҕv~Hb c%Ҁd0C4+H}W1Gh%/GE4¿t{_We7- _>t_ݟhӗZ^G_>N2!.n]ThiOX:Ϛ0 cEE}΢~毷_q߉rvQY0B(QL_Y筰٫`z$9:bD>H[wd6%"Z+Jdjl*q?FpNNO~gwD iK)2}AS5 rJtSBma6liU݄7s':AAc[F 5i_F_f3X45^}cie:-d9{V1$$<) 9ݤwOȽ Gލ@wZe *tã@/)L->̴=Dy8cY_%\W4J; bK,g4{ XJxEuΣqQΔ l[ÑG$ń +7$wN hLi0ԙcIp] 93br[d?+-OoMCQ/,bXQȏ*dMdaZN#aM~O1 VjC7yv8{|<5[ ҂@=(4>9|f*ʺ"}`ZFw]oɉĽ#!-Ss0aOSíiʳ|øT<)Y#y(A[W2-AW>$r[Ww׎61SkDg8dgqM ~kX=•Rd>yfۚ0hjweز#>2f???J]}VH Fmr r\tKȣmeg^~M$jHiRtg_u<9ݮ/02yEF7A'tXy{y HsXE +U3 : o׏JԁjZ]wH̸U6/xݭo ;j:`dE^:p1 ==MfK(ow`[ɝ l<)p=΄!v!n˸i=4SFp?xܑd?sS״~)A'<[AjU2 qqI0:wE= j7;Edd(7gPy(`cP;5[{HX=Sy09x_Y#.f:!j&}#*\Rm-cF;pd.F_L;wNwuud'JUBZ<}QBb7՞65DW-6Jx>H9^B?AKܽBȬIϰ%rޚXyz#lN?{9o[W'U=h oS!+cbGx!Ade}ɣo[1I#I",Eq"ޝ"DH56UǷӧ LӒ c"3,!Ufюo!ʺa)ʾC9dfDlUrJ#Ruu6;N"0%yl"BA{bTDUt+gowF" Bf ?h +WuO^1cЫE] gyZ}bT0r=}*Xr𧬂"NY9UРUD9 (2b(@ R=Oo8_+ydsdf>&wCHtK$c}4[WL[L_`LLy$[Rҽ0U3>*6x @PI2u~q}tcLy:hڻsNȺŗxAb샺v3 Uc6Bn=A>N"=?z=Fcvn"z_EO)t1IZ`GvVv3zȋM>ΣF%Ӟ$Gb??ۦdQ1мDfyƀ8NJV"5;u״n×y;رT}gg$'-8tN{ ϗ8m&_ɩc0]Nr ,arSǺw$_IArt.XCǽ:4qۀ})*#jQ3|zӋ5ش zI͡p.sQ_*q%E۔n .Jq5Xf+5 Fj׋ +y_ta\R6U/."+oQ>^YxP+W[O7& +x:˸sMg:.zEQ rk".zo4,UDQ4ji)bKLw^J5h=N~T⦬Իx5ZqoΩݝm%k,Z+5жmulFh&ƛ\enVRۯ$`./mɢ3Rr4rXZvEdY+[p@d0Ux37X喎u`nV߰PL*OVY~i+Y. MK(a|2?i +endstream +endobj +460 0 obj +<< +/Type /Page +/Parent 1 0 R +/MediaBox [ 0 0 595.275591 841.889764 ] +/Contents 459 0 R +/Resources 4 0 R +/Annots [ 461 0 R 462 0 R 463 0 R 464 0 R 465 0 R 466 0 R 467 0 R 468 0 R 469 0 R 470 0 R 471 0 R 472 0 R 473 0 R 474 0 R 475 0 R 476 0 R 477 0 R 478 0 R 479 0 R 480 0 R 481 0 R 482 0 R 483 0 R 484 0 R 485 0 R 486 0 R 487 0 R 488 0 R 489 0 R 490 0 R 491 0 R 492 0 R 493 0 R 494 0 R 495 0 R 496 0 R 497 0 R ] +/TrimBox [ 0 0 595.275591 841.889764 ] +/BleedBox [ 0 0 595.275591 841.889764 ] +>> +endobj +461 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 799.173057 99.933071 780.423057 ] +/BS << +/W 0 +>> +/Dest (cb11-23) +>> +endobj +462 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 780.226036 99.933071 761.476036 ] +/BS << +/W 0 +>> +/Dest (cb11-24) +>> +endobj +463 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 761.279014 99.933071 742.529014 ] +/BS << +/W 0 +>> +/Dest (cb11-25) +>> +endobj +464 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 742.331993 99.933071 723.581993 ] +/BS << +/W 0 +>> +/Dest (cb11-26) +>> +endobj +465 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 723.384971 99.933071 704.634971 ] +/BS << +/W 0 +>> +/Dest (cb11-27) +>> +endobj +466 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 704.437950 99.933071 685.687950 ] +/BS << +/W 0 +>> +/Dest (cb11-28) +>> +endobj +467 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 685.490928 99.933071 666.740928 ] +/BS << +/W 0 +>> +/Dest (cb11-29) +>> +endobj +468 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 666.543907 99.933071 647.793907 ] +/BS << +/W 0 +>> +/Dest (cb11-30) +>> +endobj +469 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 647.596885 99.933071 628.846885 ] +/BS << +/W 0 +>> +/Dest (cb11-31) +>> +endobj +470 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 628.649864 99.933071 609.899864 ] +/BS << +/W 0 +>> +/Dest (cb11-32) +>> +endobj +471 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 609.702842 99.933071 590.952842 ] +/BS << +/W 0 +>> +/Dest (cb11-33) +>> +endobj +472 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 590.755821 99.933071 572.005821 ] +/BS << +/W 0 +>> +/Dest (cb11-34) +>> +endobj +473 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 571.808799 99.933071 553.058799 ] +/BS << +/W 0 +>> +/Dest (cb11-35) +>> +endobj +474 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 552.861778 99.933071 534.111778 ] +/BS << +/W 0 +>> +/Dest (cb11-36) +>> +endobj +475 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 533.914756 99.933071 515.164756 ] +/BS << +/W 0 +>> +/Dest (cb11-37) +>> +endobj +476 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 514.967735 99.933071 496.217735 ] +/BS << +/W 0 +>> +/Dest (cb11-38) +>> +endobj +477 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 496.020714 99.933071 477.270714 ] +/BS << +/W 0 +>> +/Dest (cb11-39) +>> +endobj +478 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 477.073692 99.933071 458.323692 ] +/BS << +/W 0 +>> +/Dest (cb11-40) +>> +endobj +479 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 458.126671 99.933071 439.376671 ] +/BS << +/W 0 +>> +/Dest (cb11-41) +>> +endobj +480 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 439.179649 99.933071 420.429649 ] +/BS << +/W 0 +>> +/Dest (cb11-42) +>> +endobj +481 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 420.232628 99.933071 401.482628 ] +/BS << +/W 0 +>> +/Dest (cb11-43) +>> +endobj +482 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 401.285606 99.933071 382.535606 ] +/BS << +/W 0 +>> +/Dest (cb11-44) +>> +endobj +483 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 382.338585 99.933071 363.588585 ] +/BS << +/W 0 +>> +/Dest (cb11-45) +>> +endobj +484 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 363.391563 99.933071 344.641563 ] +/BS << +/W 0 +>> +/Dest (cb11-46) +>> +endobj +485 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 344.444542 99.933071 325.694542 ] +/BS << +/W 0 +>> +/Dest (cb11-47) +>> +endobj +486 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 325.497520 99.933071 306.747520 ] +/BS << +/W 0 +>> +/Dest (cb11-48) +>> +endobj +487 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 306.550499 99.933071 287.800499 ] +/BS << +/W 0 +>> +/Dest (cb11-49) +>> +endobj +488 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 287.603477 99.933071 268.853477 ] +/BS << +/W 0 +>> +/Dest (cb11-50) +>> +endobj +489 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 268.656456 99.933071 249.906456 ] +/BS << +/W 0 +>> +/Dest (cb11-51) +>> +endobj +490 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 249.709434 99.933071 230.959434 ] +/BS << +/W 0 +>> +/Dest (cb11-52) +>> +endobj +491 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 211.815391 99.933071 193.065391 ] +/BS << +/W 0 +>> +/Dest (cb11-53) +>> +endobj +492 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 192.868370 99.933071 174.118370 ] +/BS << +/W 0 +>> +/Dest (cb11-54) +>> +endobj +493 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 173.921348 99.933071 155.171348 ] +/BS << +/W 0 +>> +/Dest (cb11-55) +>> +endobj +494 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 154.974327 99.933071 136.224327 ] +/BS << +/W 0 +>> +/Dest (cb11-56) +>> +endobj +495 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 136.027305 99.933071 117.277305 ] +/BS << +/W 0 +>> +/Dest (cb11-57) +>> +endobj +496 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 117.080284 99.933071 98.330284 ] +/BS << +/W 0 +>> +/Dest (cb11-58) +>> +endobj +497 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 98.133262 99.933071 79.383262 ] +/BS << +/W 0 +>> +/Dest (cb11-59) +>> +endobj +498 0 obj +<< +/Filter /FlateDecode +/Length 3936 +>> +stream +x\Y$ ~_,Sub0ymf󐿟Q]cfg bgAQGRUH\RL +jEe8`KN>TKx?gscΔ _ +I9% + +E+LJ.DKX#$vg%%1ع2߳ +pɲƂ,AT!f &BQ9kb.MNyobb+&c +Y K̤ 4^,>zRy5^,) +/CXWVy"YW %35,` X.Ӱ]԰b?f]@Hհ<5,`!-Ѱ wmAS|hel.QÂܵۧ WZ66ƢaA"Py p5,DTaAZHҰ w7 `"аX骼baA†2D%C !հ wދK{ "piʃ,>; ׀U|ɪ!x]a%JEÂܕaALBpYh; bfSRB!Sy:hXRykX_AA  #0"VsQ,5,\5,H!V5^t&'٤aAJlLkX7.iX1aA*aBƳItV A ˨2#iXZxLRgf 2G#pT@JY`A2GAXÂYÂ!#alSͤaA!ȂOÂBHa`<" ͨ7kXz3kXP> I:d/.+j5ÙJ)yU!o5)7//+’kwyyBFd2ͿcY(*]9$/(~嘺iHSRIҧx78Ȧj3 I%GZd ad\RX&`ԨkRk[zWgmɂ&Ww2`~Nm'tq'k= _ữ1c d]6* /GgB "p_ݵ;a H굍v,95߮懭mӶ_m;xM Rޅ\KJX4Pgh+L[dړv*` 8gkaiGZӤsӓ\X)[*Iw傟.WaKC]GcR'7ʊIMZm]u;|H될\^z}GzȹUZޤ] }suy׬[TZA>4_NPWkUű)%d&fq^5~_O| i~;99MogYw܂Գ1wņkXm|$zn~㰭x'iӐGrjE9)gkCwiV[nF8^Ӗ%"J;MBV[FzҼO&7?{^#Gcy<&cūrdwIkzaf(F ]Qp;ee" zuc{yMpMuݛmhٞy5{S׿{N[uT5eJZhn5DSKc)lX |br; +t͚^pNx͒R*<\:ˮ0|jv$O6]Qd ElTL JF{'s-i;mr["uLYQ>%)tE],7&{^QiE]qtI.cuu[QG7:y(nߊ;}Eݪnws=DoRR1Hw=/FV= qgl; )|tH7JGKRKsX_]FTSm\sKZn>,&!tw=)n bKLlY m m{h[_u1(2yOڪX{гmZ_@&y'IG_N.C&,H]ǃ, +y$7B\?Rmc:ri+G#хZ7yaɵ+ebɲzJnU좄d'C<7H'bin7yU>Nں4m5i9Q6T.FPSCk7>)A!~NmhfvkB͐+B:vhTZ(}Wh H od_^S툧CxIiVPh74n'g2)7U5M5*S?X&%ovVI3=vaMh;˦mv֗<Ʋo/[wm&z*M<[VaM?+g"5!0 nʏ3tW 'v2رq&Vq'oS l|NmAvԣݘl" +<`vt3hitPÜxV^e,{|up[79;Ef":`mmC剡tF4Am0t8]7]gpx:bOd>toF^.}[M +rpϏ|ĕ4!+SG\̃r 6bAΓtՋ> +endobj +500 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 799.173057 99.933071 780.423057 ] +/BS << +/W 0 +>> +/Dest (cb11-60) +>> +endobj +501 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 780.226036 99.933071 761.476036 ] +/BS << +/W 0 +>> +/Dest (cb11-61) +>> +endobj +502 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 101.433071 719.279014 101.433071 700.529014 ] +/BS << +/W 0 +>> +/Dest (cb12-1) +>> +endobj +503 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 101.433071 391.031993 101.433071 372.281993 ] +/BS << +/W 0 +>> +/Dest (cb15-1) +>> +endobj +504 0 obj +<< +/Filter /FlateDecode +/Length 3121 +>> +stream +x͛[ Ss+H݀ +b4->88Aq\C~]vb;svDj$EDi|&bʡV/ONJ"j\6-̤%$n{H X?7ŵ/N1#/?J%Z +%Gՠ"GR(%2z, 0M)]l&<`|l<`&9HRFnV–HcbcA#؂cA,MXCG䱠q~3KoVMMly$~x,h +[RW[45gނIoN.ÖcAc 7ѻG=.wS<4{,@MdޞTj;ЛGb*Gr `&v5XVdr E>wLO#p(X3kl~9f5y~>O/b=ӻ/~ѼmbxWakODm2 acF6d`8t3#cmq&blOWb+ɮ}ϯn+, uU~:gF>WW4>R"p]L7O_~_0:oޝ_jJj'MV aEPCfz<^{OVv6V:ҽަ;d뷣taS^ꔽt|,-{+memp܏:̯~~#>mO͍һlɭ{m};]x>|fozo {=}ˣNopƻeWl>SkGijfOk #E'!OolZ G٦5v[nܴ-hEIP='nEdc_NzE4ErVO)~YOե;Nl,}ڵ(ӣ}+E ~#|z ݖnؖ\u/窫7ϖ{@ >q}Zʦ{"1!]`G;nvsөXǔz@re eZeCc{ա#IcpoʼΡlPpq;:1v7>c/`V apSս'Ήe;KʴlqO7D=>M.h^Fj.VnG j+7~.=x ɲ 8-$ٲ +o+{^zk&1dP2 ?ap۹o=YlL8Xr`gV܇7;W:>Z[d_ء +R8,mb̽t+~87ꈱQ/іr8d@v[S6y_ԟO6K5z% +!|/jARmp6kY1 -t/)a;S8L_],rBr+}p]jo{7ҐbTk1Nrr7̡_FNwa큤^;ZKcʨU筭{~2C]p#|tH~y-6}.qS1ᔊS;MVP꡷ +eiw+xR054Fu_;iA k7I:i"^ו./ێ ǴYQO1Y7hx uN&Ю4}Ȳx&=!xq$2;6sދ݈}ѭBa}\K(YչCqQ۴L ȵz_סk),iet.k]=R)avec'OgIڇa3/c͑dOі,sOF3L-"BZ;./QK)ulO\]/SLϫ:*Éi|W+Ȗd$@i 2f͑KVG׻TgMڞiH)]Oߧ[,VNBίtP+O5g0DEu9{>+?g%kO"ToyTmG8<ݸvb_/V{-vOD +endstream +endobj +505 0 obj +<< +/Type /Page +/Parent 1 0 R +/MediaBox [ 0 0 595.275591 841.889764 ] +/Contents 504 0 R +/Resources 4 0 R +/Annots [ 506 0 R ] +/TrimBox [ 0 0 595.275591 841.889764 ] +/BleedBox [ 0 0 595.275591 841.889764 ] +>> +endobj +506 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 101.433071 713.673057 101.433071 694.923057 ] +/BS << +/W 0 +>> +/Dest (cb18-1) +>> +endobj +507 0 obj +<< +/Filter /FlateDecode +/Length 4866 +>> +stream +x]ێ$q}gK~`! 2 ?tNK0z f̌iJޙFMUF$O7sʹϗO'RWS,p6'L9?%J)_Oouȓ~y٪R5׏N@T!l*&"`FH* _rT0[U'㶪3l2^R SBTFcu0D{ﬠ3AEtzt֨-.AgtΩ Fc Yy6.`גxEEl99I`EAa ЕElQIW +%{/ +t:YTiIg +uQ-Q"`KpJ:[<$x"0[-ntX-|l-:E06% >K,`sQ>%'р-AXN謑i|1sElqK\,lA -; -8ЭH\^(qL-q ( 8ׁ;%.p ]L$q|8FK\!-`GLvx3:I\FV9k k~}2W}702Uo?מ'Y0wDwǥ: #Wy'rZv[]Bݞu1MpzgY=ul2:@ =̥'r%a]oޒsKjܵ@el[UZgJ`z=M;KVG׉>WBOWRy >}<h%yt6뽀v:s븙QE+!\A+ ݩm\Lv<oǢw^CwC߳k<\筢ޫWXnޢmeiWtؒyCQ֬wOenUwô>Mui^nmi;aڹ]S;d|ݴ:w"18NgkceDZr輖m%W|D~Cs0!vS=adL?3|WPv/v/8P 杻GFJ>VWP5"%)}yU;jq?ТvǑpg[?wl0y4$q={l ݾ +)?Mh}_͚0PgT:Wiwv +艳hT<Hﳰ#=-jn̩x +zpf`CUqz-aHϹsn#K}<Нr-R_Ev7 zƬmX}ȼo}%Ͷ+y4Ґ VヤЛFn&ݓІ5W%kCR3Xf8MM-2@+{)=*~|m!sZWO~oInz-5Y"mZO}){FfV2j6ZM}fYK/8Gh+)3=#6kM&S;֜䬯BSoGtzXv0\MmCz7YxA{GLeyo Jq#9P1uZ6z¨-؜*VLbzHVn>% Gb4PfGCM]g6%P[K_E)z.s̨ҥ8 "zFnE{ f׳Q'9O܀{ IL7H*0e@Flh~.>:3؍r +!٦+thB^4UMF']JS!EϲG]$.uƧuIcZHOS[HY1y*<"NKb?+P7#PׅxT W {qũw{{ Mxͯ*b10 0ăF_NsL2^N9U7g]tt޳,s;>@M~sB=)[O&<҆ǭe|Gv=4AMra}ĶCz&^V/ᰧCG/G7p 3r +endstream +endobj +508 0 obj +<< +/Type /Page +/Parent 1 0 R +/MediaBox [ 0 0 595.275591 841.889764 ] +/Contents 507 0 R +/Resources 4 0 R +/Annots [ 509 0 R ] +/TrimBox [ 0 0 595.275591 841.889764 ] +/BleedBox [ 0 0 595.275591 841.889764 ] +>> +endobj +509 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 101.433071 563.554475 101.433071 544.804475 ] +/BS << +/W 0 +>> +/Dest (cb21-1) +>> +endobj +510 0 obj +<< +/Filter /FlateDecode +/Length 4963 +>> +stream +x]I$qׯIq_c X6 kI0/XI2TSF X2_*NR]o?_~)z?⢰_rq:?)fob_pɛ_/諙rF_~"SL1*/2XJ[A`=a9K,3n͊%p$ uQ5+C XCgVCDQY#$SHdH V%^0SkQ‚W%,@.5%z K@ 𴓰 fȂ"a\є "s! l 邧@D$e%a<4rIZ9Eyf 0Q(a 2M ȃ, ?l{ D# N‚ I‚ QF&Q‚ "> +SJ‚M$,|3IXBO87AEAMY8$@' N‚I7ы%Df]L4HX 䛈l^x}D|&3eI(@oK + oŚR$ &2Ī*ZeEU9Di!o9Gof7cן|ۯJJk +dlG|cqR$!| sR G !8ȋ2\b|f>"GD>hY֮*>oו$}>JV۶5S2-@k:iw|!($blq+h?\rd#t?|~ +=vϿSQw>?'zEz̛8^ k6^\V̅)zq~ΰr圴*/.Uk_7fTwA?Ʊ]Yk6Zgz{`* Z|I4':JQjGi%r+X--`I_lږQ 8i,ȤJоrz;^Y)6hFgݙaodXP| !搏\P1|Qvw0>oWgSNmYX5ѓ}^cφT-Ө1i;c"ycޕai+D/>Qo+똭X(3coP"sN[oPb|YZhC|M`T5?SY6X(*_fxŭpeQa!C26 ԛlV='%2K[e-/CuK-?Wcsa!*eNcӮ.Fi8:r6}|zkd㌊{]Bq}ފWgg˝מQ7ɦ[PA_G?^786+B#NصDI-Vxl:ԙVԯ"#x.*)[m3[{Y6=~/dƓ5׷aRR YF-lC7zZ\[ꞈeOy5Ku=Gj,Ox۲}nXV"ѳwfOy9+ޏ^[GFުKrQ*Ejw_Gz]᳙Pu9x~Ddă:W~s^O"f?m"V'f{O2n`;? 'lC`\BFC x,es%kCX0nd7 Ϸuf2bQv8V۪6r^e`{xf1ĭVOy5 YVP5]u2G=l3c |"=,bɇ<-H&5OM=m==]:,-ZӹqU}oz'bӓ}^BXÞhZd*Xo >,8ǯ[93'*=]wf-xlk`͓}^~NJ]]f9WrxPۻzCx[|e=R늄'tx`C= O<"ӧ^cCke31z>fVǭ{f#Nݳ6KhY" < S5.;"Z[4oߙ')VI#a3DڼMm/H+ufi;ПjLԷ=n,u )^vW;iZѝaEm65F396i?ɳ7y'<=kqѫUWm=9T]iܽ ;(gB.οc},"mgtk +25K>عZPw7{2m: \yog{֋l i{2(C)=]sj("?W[+{tJ7aӪ\ڪFWVsr/k_g1v "zVeWkWofaaiwT{3,;woܒ]Q_BOBzVDzϳֻ3tzD̲PlrSXm.>/I:Ny|N<%arKf$<9&lNä2zn5,ӕƾ<(ߎzT(QogRo(Ã1׫8솆VipΖ7[_< Q^Qo75y NYr]m21׶:(.ֆM@t^O5&H/ =RclcV~Dx&U%>}e N7-fe72[ +&7Ҝq~l]$A4iCߢt n*+;)t&]=wOZ ) +z;yF~1lH[jR:F2֏ }ulLjc9ݒJ)-ZgXoԌu5nJgj#[^j|X gk2^Mz&/WB݈}@{Ctl\GB'6ѹ4Y9E]0"UkTY&TnT_[ qm"Suhl|k;1UCr]"Gmbkz\5EnSS@*Dcgɔ\VٍYoIBk߱BjzhٸTN5p4+^IS=VX]0.mfЕVV 44/~x}"zڠQ9- d-ay|E=]Cm,ΞmAN?=p nz瓺J[LZE Tc)ݪZʊbN3״ҔU[z-ynαN-L-ލzK[irml zdz7j=sv}Ԫ-wQ;U +K4pZɺ"Rk%|&lUQC"lr%=aN*AAs .#ED_o@S %-' +endstream +endobj +511 0 obj +<< +/Type /Page +/Parent 1 0 R +/MediaBox [ 0 0 595.275591 841.889764 ] +/Contents 510 0 R +/Resources 4 0 R +/Annots [ 512 0 R ] +/TrimBox [ 0 0 595.275591 841.889764 ] +/BleedBox [ 0 0 595.275591 841.889764 ] +>> +endobj +512 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 101.433071 105.123057 101.433071 86.373057 ] +/BS << +/W 0 +>> +/Dest (cb24-1) +>> +endobj +513 0 obj +<< +/Filter /FlateDecode +/Length 4732 +>> +stream +x]Y~_,(^@ /Af;6q;J-J-u`,;VctP>/bLǓS7 ; ra'RFOXEv1UJi+B0 *bJ +f@3(E'`UKU&hT0C'VCD QD:Fd `$ti޻(si"%` $-[%`J[ Z' [(`JKd"KЩRg\VI:lZQNAK8'Άjxt[esŘ@%0% +$0! I$`(RX4PV@>-UőjBDX[@ka!+q"qݒJZ % 3k' ,(PJXpwJ\`AA ֵ ,hRX%$. )` ,qq:Z k +xH\^C/q25Q5S Ơk2xא(Gxdw`%.|-wu'iՠc8>Q¸E+$qb8.3J\0 xW[ԒMR8.'q0h8`~tE]TQ- 0 *ID]$-qxPC%.]LIUZ Q; Dl@MQ``5F`` \  Ip[)J\&b" 8ZUy3u:$.LZA/q~`wI& B-*`*g.4l-q<]贖 oPh"V^I\kI4#(qA$?(q V`JQ[@x$.M,sDl$.r3J\#l1H\lz3H\l'qAR~`7Y8tJI\tzӐތ$Oz^o E8MI$7NH=7p3ބG/"7.ft]x^` VZ+ deg# +0!lĘI L,VJ (/1Zp5Ԇ<0g'0,}Ysdv%5>wϞ01R415&oӷ 2vOZ4j NA66 +;/,_ͫz#? +IuoW4zw\cs8̀-w?>_O@r~ L&߁=&5\Xi>ݗmىy\Ʀ  -O[MkߙczjbI#gh+6E9C4ݸo_k7'~}t|1mN0y?SyrܽYaCfger;ܼbc>S8jaйk-38Z)Ferp +oT"9)X&ӝySr 6hvu;eob׈[[Lzj~ :|Ɗv9lg2R})m eg w 5ӱFZY{;mf{P4ϛ#wdD(.[!kcr2ihg{RsNٶݍ7=WR`/|23 h^ Rsg +^d?tV\`gmxW]qW +x~$ywp 6F!7?f][\{w97o$ו#r3M?l\Q5W +Bs8V 6h[ٯSXA՝yڍ%7hQv9Z>MxKtueY{3{ccZ)%yڍ~χW)qwm|2 +=ݙpr$Ipݭ:Pcy}nf׆Kk/1fDeœ#j6n4g=ws8y>,HT޲H/k.z2Ex4,mm!l5 +jv-<]!P+o{^ytG Cl=qa.R :tW畈6I/8iygL#cv97T0c)/S91S}|WghN/了{hzr9am?wR&i`g;3:ҹذs\ǒjoQLu3`J?t۟Y7*~9x$ N1 E:', 7 Oiݠ/`4. w9Y@*'[ Bz)Wļ`t)g!RX3nU- e{4GSWa1m:tNkBӝEfܺFmJEr!TI]NS&tf7{\1J IL7JO*֬)|5BllIxf}1Z}b^NH◓ BjWB Vhr8*{.04wTኔg@wǩGEo}=PMU8hOlM8uJLm8l*Lղ ȶl?]aq#Vi-:ƳhA[04G0>`i"}iXZO˜c]-TʲسɩC4;h1Hc6%pmeJDQ2eĐmS,GB)]+]+~3^lq\ PNՔŗ̷jJe˺i^wmiP5WTln!{d;sI ѱntƞ;{p񖧁b;X2"c%mM莁UAo+&@MQ/ӾtrSPP>jcls KE޲yޠ<|2N| +endstream +endobj +514 0 obj +<< +/Type /Page +/Parent 1 0 R +/MediaBox [ 0 0 595.275591 841.889764 ] +/Contents 513 0 R +/Resources 4 0 R +/TrimBox [ 0 0 595.275591 841.889764 ] +/BleedBox [ 0 0 595.275591 841.889764 ] +>> +endobj +515 0 obj +<< +/Filter /FlateDecode +/Length 4869 +>> +stream +x][,~_Qφu2k1ЧffY_(uKeTfvMP=M%$}"TfW +ED)x{}"EprEV]A8|tI`o7].ZB$C H(,E2)r\4l1Zs\4lAq"ovy[v}`a "E d"&k9.c=^t^@׬.B!XW8.ZJDLz @% `tr\lTHDȜ)؂ D)qA԰ QG2kIt5֙hPL4&8.bq\X:b FMqAEKqIqAIzAa2q `^z3r\zK}?Oק5h-,? +Çg'_eP\AOCo`Qy>5Loqs۩myݥJMWOy6 cd3xa8~D,hJ!myi 9LNʚl"Rv]1;e>]gieZ,p?BcX|JAwy=<cӶrc}[ˋ:B+9ͶO;g1;={ָiwv?؋6D1egD%RˈJ' el)ݖ9zPmK^e{}ևu+c#\w闆p[VƤ$;z~ ӊV6,#g"a-Q_pZ6͝~Yc5+}ݽ*XlRҶ;\ =\fcH|?r'1Z]f76UoYr];s n75돌?}DZ: ƢiYku:΅gs#sPX^ʃhd.~`暽X`Ds~Klwr ܭ0y!=3UX:Cf~wK& qQn("9;;yc{HϭN}m[<= oQn76j̲hǦ+'똃|w@xdza}ۊ*4mPFO'zvo4{ 0z=)Oz<q_n&сR9Y]EN"ΌCqi`u N\G6w˒AMa4#9ZwFY%~b]-t֕xd7=I1*lfj;~Ӻǵ{M Zg܎6b d~t\8:J/Vbl.cיCݥCkc*LݲȱdP]FХ:XtV Ib,تҴ1ǽ i&}a$mKMsL>VY'oViAN=4l%+U:F*k%j/jGB)cOqTZ'qT&-[=^L ['{KFFMj{JSeۺmC3l7Tln!{d,y].U;!*iQ[6o=8ҟ6[#γW{%cMaA_Mx"+_%6}lugcjW K^4Ym6 +endstream +endobj +516 0 obj +<< +/Type /Page +/Parent 1 0 R +/MediaBox [ 0 0 595.275591 841.889764 ] +/Contents 515 0 R +/Resources 4 0 R +/Annots [ 517 0 R ] +/TrimBox [ 0 0 595.275591 841.889764 ] +/BleedBox [ 0 0 595.275591 841.889764 ] +>> +endobj +517 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 101.433071 386.373057 101.433071 367.623057 ] +/BS << +/W 0 +>> +/Dest (cb27-1) +>> +endobj +518 0 obj +<< +/Filter /FlateDecode +/Length 4697 +>> +stream +x]ێ}gIV~ p.E nc#ϡZ*=l`vZU$UbKTK~>/B釓U7/Y+{> >Zö髏Ng3茶I*T*IPY;xoTN%̰ /Ufp VR 6&3* 5K*J+ءR(f2Nӝ3zp!(Q[ Dla " q7؂ADCԈl\DɆ%.a=^t E]N{ Sk!`K\R$q̀N>  0 2t Ȗ.tZK\ lA4(qA0L$. $ZұJ qA`7PQ 4&$.bJ\X:B%.f bLM/qATQ!ơSJ₨֛%.L qA$&x¸zK\X( h¸'a vtDz3H\0MDbJ ]LI\7Jk{ iČZ̭b@{1[y1g@i$& `&VYLPj% /8}jSTp3O1,}YsbR'11S44#005.Is"d! |N2j-NId$01#fӄVI +XY VXau(C$vW*:Yq́|̗X wߟ>ǟ=;|_zr_o>ToU Z62 ڮ@Vǘܕz4o;+c&[ұ۞ݼΎxjg,^=W}~û9H>\\p2$q+s <ÝlːJDiFu*HE:w{fQ鯺Ԇ -~{ӱV+B;R(-Ts8TM4~$Iz>6\vI18{!1le?TD-ʽGy۾-W+} _~i[W2ƨnnxg6Z?GKA}N[#&às[Wp׾4^gdˍW;T92w҃YY QSv}Owk-Fa&W69h;.跐ᐸ7}$ٮض7Fu[o\sGam :CkxXAK3OwiV}W)Ȩr; q%YS^Ak3ݍ}u}O2xctueY{v6qlj9j7ą?^-*9oe>-;+{ v;,|3IR\w=t)y>vvmy@?OejFTsOwG:9iYw42y'F+ ̻ 8#3ꆯK7;;ŷz-.eл;JFkDvz.Xf#omGV +Uj7`k Oᐸ}+}&b(fKD," od\v4dmwo6 +yk9ud2đheûres~ZwIHo5<76_s8tn;=}9~k<9}NOZo+| YpȤlE*eY VS#ƣW;_#^{o5CMw9BF~W5zo3VEJ|;~-efnJz |~n}WU|{v96j.n=x-حtǵM~HSSk~nCY^n`7}Bzg!r;F_[(H=dYħݮs~u3;.좹3/XcC"3Ԧʇs8nCJo}Y $}/?߫/\_z׌[ 'rIS02( uuuKar˕ܤ;5} 7H6 ڷӹ{6ls 6_m?=J0h^iyv<]>R"MzX}^9Rjz7J K890:\./?ľ$KdGcդ6WK` !j:W]aS6CXlmVkR.9]u +m;o /'z(MoM5Ȩ1*%CI]Ncf8]!K I,7f|)j՘{RNt hrf(b<}B^NHBi[B VHMETKOYR-<RMN$"wR+wuX;mK{_0J(H.=66]}%*1낺"Npe+TmL\edN7p*v;[/\n,ORFٮV@ +U\iyZicdҌ{9}w9CD|p[&(K2'>%:Unۙ,8wga6pCUC-k3> +endobj +520 0 obj +<< +/Filter /FlateDecode +/Length 4726 +>> +stream +x]ێ#}W9i/^ <;6q;b7/.u`vUT?(1ǓI%Y~;+ip*?_Oo싿_:EJ^+w=! JPIes"ZB$C H(,E2)r\4l1Zs\4lAq"ov{[v`a "E d"&k9.c?Qt^@׬.B!XW8.^JD,z @% `tr\lRHDȜ)؂ D)qA԰ QG2{I 5hP,4&8.fq\6:b FMqAEKqIqAIzAa2q `]~3r\~[79SV~oFLi7J,v59 S@sҍ+MB-MdB0.VAagmΛjAH3ru/v /,uvɹ 沗eWu+}yhS?4j;Cβ .sg~զܾD`v8MΟ7^ڲÇkvv/4h"4MkQ& %h ɞmLuWdžV6?gVʼt` `T7_u6)D Wx.ͳƐXN2RFx9.s-Y;yz(fTu-#C`CNg杛gFc\%vo;+j+L^^`CNt5W}_?s<6E:ĸݒX<'?n =ͧݛVs;n%z6uP!*ɖUrO6Pv'# M=zá`Fj\LFf_^r}OM'<zw7d;U{Muԣ(wdy8ėCvR_Ek6TX_͇t-iTg5k3=~~W(I4˧ciG}I(|,Jzَ_sd='sէTwKmٳ8"&|i*+=o8{+gsHcU&Vߩc-EC$e:u3Oc11O'GA#eG].DG[Flm;OjGLmYU* 544Ne;Ê>;Ԯ wUhe)da}Snj5ZPV +3_j +gRAۗm bed'tkkbm=C盰ꦿա-n(}etyi.QΨTb<1ˉ~"KYݬё0 Z.rrbͭ:Sj*#LiP7<#tnHS^.t~Yk;rr&~=v++녦klxiRWXEFjU*%/CqUf/:eC+ +b/%SH#vCC*IUXUE]\ e15P~].U'kg^upw&;_{q3jom|^cK'MevN )4q,.}kKyq/Oi4U换(K2_'{S9!vZVЕ[ޓ׻ăb"˦j~ʺǵڶ{)*텮a'Znd܆2b d>tnÞ.M9:{.Vᢿ\Ʀ3%&qEEK".Fque 3 }'u~O.Ktپ"wAlaN軗l/+ګ#i%<^j_^Vceemn䴥B 1Ic6p}GQ2YdPls2,#;JM}?Ү:*KW%S 9d%##}*)uvw6l3ķTjnU.gFsO΄T*m=87us%Hɕ=a:5FE_xț +EWtM/C%mͭx9!T/m 'HM)"} J"} +endstream +endobj +521 0 obj +<< +/Type /Page +/Parent 1 0 R +/MediaBox [ 0 0 595.275591 841.889764 ] +/Contents 520 0 R +/Resources 4 0 R +/Annots [ 522 0 R ] +/TrimBox [ 0 0 595.275591 841.889764 ] +/BleedBox [ 0 0 595.275591 841.889764 ] +>> +endobj +522 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 101.433071 642.273057 101.433071 623.523057 ] +/BS << +/W 0 +>> +/Dest (cb30-1) +>> +endobj +523 0 obj +<< +/Filter /FlateDecode +/Length 4922 +>> +stream +x][q~_Lx?^<ٱ p}DDZɢsiUR,HWibLˏ5X]/V6LN'L0L׷ .y˟~vu}5SJhw̲ۗ4r+4 , KLIbA [V6E' 5& +1M[V&h+ N., 6J<%#<%ѓ$H<xi޻(,dqIi *Y, &qB˓>IXpT$a> HX%pW$,p] NäHX6iyiR)F pd$,T0I!wޓ,Y( ׀c+i2@ +U;,J$af)a`pBl$,N)/aO +<|"Ovd3Ȅcaݷ7fs}o3/T_p Lv;D'_'U !{d!BBjRtB?퇕<ȋ| C6$*[$L]!keY]W(YmkM˴.8;Xƒ]>ND1m(8ʈו]5O"\[nL|!nǯzzQ8Naӹ:.~9үƱtfcc+1]ƴm<2eY ʹSx_^}\ltUe:3V_]K?":mvu0ٔzm^m;Ƭ-ۆ0`Y6|Q[=ٌY]k=<}md^mvv\Z|D|:s}j}}@ 'Tq9F/sr[!ňIG; wZjzLl6ȬX &s!+Roa<<^iTNn;3bG+ Kk;wFocbնk89y,;~ۑ}\SZep}ۇ*߱`Rs}΂ǡ zձ7YR#ڥүRGy +xŭpcQa!p0r`+16am>TYeK6q,>,܏QY&ky=,c XJ,D͡DaNl qE:3*uG};B[mr+ud<5j-jvj f/wj|ѫyk3,˞lJc{7U/8sGzޱb;{YUةI`vrS*Ej껯C~],}dYRI[#OӞtxP}N6XЬ.o-b|f>Ÿ kE0c%PC x5[MSy:K>ҰCX0v631(;zUJ³rd`/=Bq\}+VcPdgN{ٝ5`>j[3:])3{IL߳}^=0ޱwĢ'-ݹqU}zwĦ'<WbU{[Y;+VŢ&ʿ~\g`w?~mr̙=Q麇~` |(}iт6=t8ntVw?6wG7gYq@!7v7+"xs:~apwUץ;8 &j,\Get4KwU߼;YgZ?8_3ݱwĕ'<5fVǽ{f#Nٳ6KhҞ5,L`d4idY?f(j5/c6k& qI;CYs[|+78Fڬ"!N!:a#]=oyK}gƞ#7Fv):?Ny׫|>0pM^`F.c,WhM؝0IBaBnB\Kk#Jˆދv~J{&.!ӡLy1uv4n4RyGb~_;4 w7*Ӽ,Zr1"&`>/f΢U@{6ίNlwi*/{aahپ쪇7U!DPŪB~?mXkF*^E4n0u닾=hi1jI>/t[GEm10yVU5lNj//IWot/!Efau&];=wmZ-_X6e@l&WBYs#풿* +dk{}@jcYRJY)-KjrWWXZUQy<@DOz5酜n"N\&J8mw<$kRDŦdc<:wbNmM`yx`Zo"5U8҈ ՖmCl'tTb3Z~ULՐlkj;t\۩Z5UwQSlh7V sQT?ɹZEf7fC]m'..] +q"q9n/?hVZ~j +רymI%>I>V:VҀe!4Q 3Mc+*ST cM9CXOJNTULɮۊt:&󚙻kvoɡonqW86;:I'ռ]`N0V6t*Y>C&y寗 9I=_@__7iغ"sO'$vlXco54?n kۻ쵥n]!#fFӌC ZlMw%8sJ \ΣlH\ݥk >(.لK3$>oVP]0"_RfЕVV &~OVBx}/"z2A{qj[X6T.*e=]Cm,bgZӏF-(miVVG4UimPeK(j)S54%:+~6[=^@sSe%@wޒ*m;]]-vA|LU6-߅9;s K%D}8j*_'J#_+VDjτ, +:,_)wKJ\c +JAԦT > +endobj +525 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 101.433071 135.123057 101.433071 116.373057 ] +/BS << +/W 0 +>> +/Dest (cb33-1) +>> +endobj +526 0 obj +<< +/Filter /FlateDecode +/Length 4734 +>> +stream +x]ɎWYC^AˆCwiZc@IdȪ)84zK0 g% F!DI +K%fI ~=Ka`et?@G;_w=}?:{R=཰*B%fT+N1FN37,Uf,FKTE4 +fh=vH%!à;NBTyWNy#tqp lQHNgaN[9آ5Eat"  +'$z1"t")aNaEagt +8a#-V 4l1t }jUВYآ7`9P8 + +8P&*Ñ +z0T^s4-$tJrDlqL%l1Xh8. +Ze4lk 4ֈ(9.[#@pa@qup "h.@uu &8 4xW)8.0]Qes\`XF: A 8.0]w `u~8swUF9 #h +|8[@C4hlPK8.]5 d ޕ =FYA:9.]8*q>Uq\`RSs:TQp\`, p\6H貺8 ZR "IX$qxC9.p]q +5+ V[tP ˖YV+$fӁw%q$P8 +V`EB>V[ Xl1p\z: -Z) -8.@D0D؂H01xèr:A׬.@'=ޛXr\9..q\3a +pECP9-9.@ [ r\T. ࡱPs:#h8. *r\e&l[ fV[5h8.(8.6i9. +7Pqh:!8.2` X D-YQ;oz -! +-"nIo8-* s  ~=lk#Ӂw: p&"[no/@#>㕁vPoeS oٜML,cpPJ Yp˜}jSTpIF, 9j1Rl̏'8=|2eG"@H +,1ѷk@.Yn)KX)FFѿRͼ[l~$m[F?,%qf^Zm{lL !$p(" +ź@+̬ߝ&+Dm9fAرe>ǟ߽;}׊׼s _ce~l7u]KWVz;oԏ\te6\'v*O2~{;;r(̸}Ox7© p-TVan`t_Y;͛1_<[ + +o%Ţ~:d_C+>~u+5o֛泝' |m,1.eC<۱:AJ1[ )eM3;kxigv/*:0_⎌ۥvxG!+Աk9瑙oJW2@QEhYphWy3(sWF]gu +!.+t*(L;R:;?);T>E hgBW*j oCPksl Սzsv> MOR]eoʧɃ?g<ņKc_C) ksegEq=:CMȒӿlsX;m6u]wę; z,J*koh5f4V 8BUs8nę-M"~5ty9t: +9 +ǍйLѹ@rOms 3{O^v{ObΩ>gTe='%;! ƕn-s8_Eo⽌gk}u6f#EeTWX<%oqni3+ƫBy옹]<s8D]rҵ;f4~qhiEV䱳Py}߈z5Wb6L11e[yu*]uyE~ G_*pޘݾ#6٦HYpHݒ]'n"^|ޔڱ/ѵKGܕVQ]a;u;3R}f227|z9%jz"[_9e+;wu&&]D=͹c}ޑYhueԫ#ӟyպ+ (]},\ rƣ;G; z7|.6(ĜC.}[^]W+#_>5oVj77k[(Wp(ވk\]]pߥA>>枫69Pw[_wYhw}d&RyZƬtSvgWٟ7?EaW&^uč vܶ_a:zu+ +hcwXw9BXˌw;J|L~6ޭmٯ*RXA՝uڍ% B +Z6:GCkɷ1G]}Y^}^}fHjC.n=4d_áv#zG\xk]Jؚ]mX—eb;;a\2I\\v9鵧4\c/wmhŧ2t^[ 5 +߰.;| 9TuG4ߟٿrgpߟ/AteARG%/wޞkߌnQ^1K[u}M+@=[u3ۻ+ew ѐǨAbr5.mu\sqE% }tze5>iXL;=02 8#3\xĎmsL6ܕy^2 {O`7ӥx(a/֣ܞ7Yp2{S$ {-I畚ݗ?R0!ގ2+9&IF3kI g{^]hA SL(m ؠ/ 4N_?*φ\^)aD.KƎ!j:ًANbzct)e! lmVK-] +E]+2t +fsY&Э^:ʣDƨX6,b<1ˉ~.rYͬѫ{Fa@2\ĖZe|)j՘GRCxFhzzmFbG3Z7j!)+_O3m +a3Zn- *^?aif)1O@OvBk]aÍ4mKz_0ێ )O[JI!k>f +yŲl"(N[*;s-V+ڊ}qIo*vg%96Ӌ !wRJoW;k0BW}MZ ;uǺ8{9xJnNi">8-Ŋm%C9%gJP[g֓kxN17 ˲i4_2Բ6q6ĞK h[c؈U{ExF2;7a:la:]]iGTtIOn*mMZ63vR7Th9h:UgmβtM=h64a{y}O&HZH_[i91:a9Ly*mfԥQC 3;h1HC6m&ffGQ2eEmrS<,;JUc;Ҷ2(KfW%] ׳d%#sm"5βefw4L5TjvQ.guW*L wpFz9Rz#7I\zdɹ'L`^o+&BMSkjQt0Jsb Jo&O͔*6NJ^/J1I?# +endstream +endobj +527 0 obj +<< +/Type /Page +/Parent 1 0 R +/MediaBox [ 0 0 595.275591 841.889764 ] +/Contents 526 0 R +/Resources 4 0 R +/TrimBox [ 0 0 595.275591 841.889764 ] +/BleedBox [ 0 0 595.275591 841.889764 ] +>> +endobj +528 0 obj +<< +/Filter /FlateDecode +/Length 4793 +>> +stream +x]ێ$q}gK~=X0`ȖAKm F:-^ ?(1퇛I)VY{wWTݿ' "$t9&^Qw-RZ߿#5"cT * rNgT^ 41%N3\nUfVȨ"06(U% +fRv(-%!Zri%|L: +#|)NENgaKRq:[Vr:bM duE`8]-I.+:"T.R%d q N)M0I>0: [tgtXp:3!FfjFl:XV[h[d` %t&m9mX@$l>TiY1Qb:bh؂[5Z8.0[+oT…5[ (PJpwr\`@5k h9.0]cwANV[` ¨h8.]dw14Uz cXr\`:` +`uA`  ,xW;4Iqj=H6B,ӆ&4 xW%L̘[ wUD$TǙq / }w1Q x9. ̨U35*$q\8oBI@%!S8.hIs\YX&auAHC9.]Lޕ @Ŋe]#S?o~zWfQq\>nJC쥤ܜLUEkmTr* õ>'ѢfhڪKcK#S'~O5h-vkY~  +twN:GաF=B.¡yfj0ll ⁍gͶstwc>Ջy X"L=^{d-"%5G_hMWI{j[^EZC8&BGt&`WNfUtFK%\y-ӡ2o~нBI<{ +Awq\3rsό1,[j>wxbCq zK̉z;Wt\㑡䪩 ~0E04ϼ= 1y:ǰ?K-[f/B^lDZ)<|z:jv<ĢC <6[kf:<uu4|{P0hݤ6{o^t;Mʃrc,/NpcM/ 7 1o囟l_˯e}84M]sCHGtTڝ!ZCqE<٭{pؽ>kmumϔGyG\y1ϳќyiHLo3(ZŨF˼j9H|OMes4S~Ei߼y džЍ~#=;dooHmPVĔ/#w&Wf}Mm}J/%-cÂ*}fjfpa9}ږ,ls-KM˘|gv/U\6N4]Vcp\8=yu9}hkI3_wޮ1GN`GߡˬɎO\;9\)s5жw8_T<>Kγݶ,6|bi[۽SWߡ6\~w7~f>ĄvRguW IM>I% yZ]g?pފn!`WG +Nح0y!=p6UXÆo-Q$E`Jt/g|=gɡϸ9C::ov:[Lluz=ѳSyd^00 +;!ydq_>Ǯ?F,˲%pf?}?¿ES >M \ j+7qv<φ7?i9q,+p0eѷW"כ`Mouif[ ZzI+9_< RN]AJఉ>0Tc=wဣۿ-nNGEQӓhym늺ᱩ}o:HEml|y<φZuȱ'd_y~lrH\f^9ݾ6|}Cs4\mܩqgymDZW嫏@739?w>3Ou;|Gy1ӡ8臝\c- Yhzgoºð^~<φBa۩0.YayQ7N-y9>9y{<-|!BCo;e{^p{uv^ѳE"thLx~ϛ[.&r]ᄐ[nivJ!^na3l6TH n;T~Q(M/F{+\MHwz^ƪM*;VwrR7Kz,ppypQ;ram2]z[Flm?w"&a([YVU Y>ca|Ԯ򻚍feMd{ʖ!rzSPELoT”+LM c^`x*VFBʡ.ֶڣ u 5Cw 7Tkf++8עwl23ՔCl'F1od-ڢ3~5z"HK5#zt4z*TgMݔuc8j+"1"Mi2l]zsI:W} 6q/]JY>ahVK_5)1Ol_Jhl6I7ֱ =.B/%Hn[I yDRniND7U>FYH[W_Z6Ѝ[Wq&oMU؆ v.Vu mzk۳N5j vAt2g܁1y2?o\8:FUVbl.cי>%߇"qEICF\r0uVf J~;v!KuOcU[1$AlƋ`Jwd_GI7(m #i#<^j__9]uv0L r衅]]g+ XUuhtVb6%8^ +-ҿvc4'W&-[g-ΡN-̏ʶuuuͰ#SٳMw{ΒguR՟b4&j&CރC,}Cqys㽒H+kBwk 7tgKmlue?y_3o@KEn/CAo$ ROM[ͫtvH +endstream +endobj +529 0 obj +<< +/Type /Page +/Parent 1 0 R +/MediaBox [ 0 0 595.275591 841.889764 ] +/Contents 528 0 R +/Resources 4 0 R +/Annots [ 530 0 R ] +/TrimBox [ 0 0 595.275591 841.889764 ] +/BleedBox [ 0 0 595.275591 841.889764 ] +>> +endobj +530 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 101.433071 356.373057 101.433071 337.623057 ] +/BS << +/W 0 +>> +/Dest (cb36-1) +>> +endobj +531 0 obj +<< +/Filter /FlateDecode +/Length 4774 +>> +stream +x][,9~_QH؎MB<,Z ҈ڇsjAa|J_yNOWFitU+!_o_~[cŨ^b?X]5]_/l^9ݎ5<ܻ7ӈz1w>A:`͵Qb2cyNjrL;%#koSFӆy#2Fw]΋nFO؉{֡`ik!z6s҆5~Wr{q%`vbw_I4m_6_*> Уm?W>{WV@}4wn~[~Fj6&Qf3Y}}{Ԥ{S/@>a$vq%71h;.wx0ِ;q@m[N`QXus(Ś' + ocOX9BXKw+J%Z?n6-3꣏<>[=ty(GV^Ak3=cyNc?e>˲l^XŽ v'_hUJ]%m_—ebaOC9¶}9$EuW4ghCl]an|"SCͿ@DŽ\c~œw=C5OOG}7Y/+>}|,`ӡ`0oq)PҶXY[oݟ׵'|كyNԝ}Ϥڷzy^vs YFo<ѣOf9潝=_Eץzv_hNR>>V[?đկBM}j#ؙqڃyNĝ8G.^,5CAwkD“ܠ}k' +!h[{;l(Ľ7P<{;-O9VV7,8~-W&=ey[oUoOGzF=?o`ӡsgў}zso2fz7 {M}{KE92N$d+w-J#Gz=:tމ{5WH `!t'ێƏBLo {>t_lٯg9#H+k#Oƛ8l;X5OGcAND^fzZ~yCihC?.?d,K<;1͞Ցs8k ++9wbvw㒺W/ݷ_׌[ 'rI32vQljץ-[d&u߱XNȄ7՗ O4]?+Nu7elEpqCz+[F*ʯ3qӖ +ʜnnKU +wb_z\Yx'6 !WRFٮVa *4:h-4~2iƽ]r9CD|pӹG.|]>>Unۙ,2өYXM#4~Pڌ25{N ma#6FS2vCxZ82o:a/)t] +2T)Nвi2-MZ6334}ۮTWsѸ钪4e]4IS{̺4~zx']IZH_[i$-'Kit25][[EأԡQ] ]mfضRβYy(tʲR6)[nJUm+m+n6g-Qql g_NՔŗ ̵kJʲe<;϶6gj6H=3vy*ўY{2t ΁C894lJ+ikBw LVLx"+^SQlQXJsj *>-mV!bhhʹYd0e +endstream +endobj +532 0 obj +<< +/Type /Page +/Parent 1 0 R +/MediaBox [ 0 0 595.275591 841.889764 ] +/Contents 531 0 R +/Resources 4 0 R +/TrimBox [ 0 0 595.275591 841.889764 ] +/BleedBox [ 0 0 595.275591 841.889764 ] +>> +endobj +533 0 obj +<< +/Filter /FlateDecode +/Length 4801 +>> +stream +x]َ,9}g1^›$5Ai3dfTeVߦە^q]2g KdTJ9:_=}w*z%⡨FST[b6 䯧es*`?3ȩb^Peq{APĜ%,mUfPN^R 6 3E㶪 3l4$`> +*aZ:tƫNRYEL9"o$]V!$txC%l! El):IaEdA` ЕDlAI9 N1muV{sZ:❶OxSf3k#:؂آc(3H1/I`cT-I$`S(I,`SVhf((:k$"px +8[3WIga H\l$.p`[Z$.p[H\Mpaq] +$qJYuN H=J\+q:JAudu9El%.;*g(qw1U eSx&MxF,.*A'qwGkxג ( +Eo +;[@`: PpK$.] slLA5 '2=.[2!d l{  D#`$qAJ$qAJj+qf kO€b7Y8tZK\MBiIK7iěy]x3J\ x(i¼'!;I[l& ro& f ބG/n $7]$Lx@ V5Gg2qę X[- j= I4,Sw Bimh ӸE53Endƴ x-ܕd?r_yzA)?w8]0+U#Dp-/@l! |K6"n-Λnl$b,^ɰm6pfJhQ/BrA~ 14fu4 抇X&{dr_1:zjv>XC) mnz/,b=''OVi"^V*8m$׏$V% mS:OiL}Z_m|4rњ&8[v[Sd.}1`Ӗg.cJT1%җ] +8 \yrO?wu';{Q+bc. .̽yۂ*-G9tN6n Zijу^_p> ]0ɽiVPLgާ\UXyye%Z! +%}y[?ў>1fR![wKU$G,NRzre7<B۹ z^nul<:@ -'r#1r39¹tƭCV},GX!y$lp_[ܧ1nP\~9S*8K%xe2iy2m˳e>RJ㼬pC]J*gYUx |[X^\A

9z+~%e|!=p[®z}9ՂRð*9BY>rNfeee=ց-w1;+h~`CmC=ezJa9%kgԍoXչ_Ãy{*Fme0TFk>#y FMhh ;~=hrz/Ҕ%oXCm]t^o[ ys GUqhI/9u}HxWJo7.Dcy}ѻxY@5ΈocywVp+,^6o6Vy^iWX=ot. =MoqsޖzS짝i=Za|i=rݴ:w<0VwqpQNkce o)]Ӓ+kD|s0!궗SΞ0|}f/ +-ǣHy<vv˼s~=¼)Qaay8TxW}@)Ǒpg[?ǓݦH<ѐna,ɟu+|3蛧ћ5s9~%>PgT:٤Uڝ4]|eVՃyuwYؑYq +sor8oVONS+}<ޝwŭv{v^e#7{K}<r-R_Evj| zƬ"auؐy% 7df}}0ϣ7 =ЛD͆玨M' k|ۏkľa`C?P}[?j|ISDy87NW7wq5=WW:Ƥ#\By8  !.Nٟ'm]>kD=`W2 f Fl~ޮ|2z3pׇ +7ac4qjǠ0w~u{7٬Z~5e^/@[|0Ջ?=͟ӱ]r0 UXww|YJl#|i̯-K]Rs45\rʯ ,.)~ifؾ;r )Ww)>WO&a2cJ ߵT.h,8>+dRrrA.dC|D1 痺E]XUe0kTyyV+k6ObAlz,/HOZ4a/ƴqWl~+Cu]lcRu cיakZ%P[K_E)_m^kuܤlBm$ҵh`60j|A$LHN]Nb4F*Tg͵).dߚ2˥okcӀ^NLדBj߹B +Qr8鎗.e~zYe|&?QoRfP_۟z%<7xI<4! Şv.c_&i!=nKzl!l\cj&f +Ӹrjbߠw;}^ʂ[]wF}V*b~tm nH;q;\>ɤr,sy˷Ug2!Uq[ƭ 񗽤b*lfZhMi}EC[ǭzv݉4AMӎBp]k3|{ztq|4\E≓%ZCF> +endobj +535 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 101.433071 627.273057 101.433071 608.523057 ] +/BS << +/W 0 +>> +/Dest (cb39-1) +>> +endobj +536 0 obj +<< +/Filter /FlateDecode +/Length 4898 +>> +stream +x]K$ȳ 9}]>ttXa~T$Y]ngE}"**|OrzJ)ஷ/?]ŸRbPؿZ8yC`71\.gx.:j/rv)FVKi+b4>' 1g1|tmYbĂΘ$İ.jeeav b +rhȃ 9kS҃3z +),"x:g^K<|xkă,Φ(d*YLVEb,du%YTPZe;y ,`׺$,]봒wEMY`'wVQ22`V'a2kr8உD^k< ]㕑w3AQ7x,X ߃ghl2pK$,] kh5锃OIGh\XCx.6*+a> ;wN-d%ao& @oV0]'SwKF“J@'`<).,aA*oYl2VXpV'e4fXwY‚ܥmS‚`pl$,M9 aA +<|"/LxDd<⢓mNDY1DY2HX`޷@8OQ ٔsDA/)EK(aAnV%,@,5%,z K@ 𴓰 fȂ"a)xOC8Ok ,%,H&! JЈ%jřI‚DX&4"&$,P%,@`aȃ,; R2n& R,F `oF ,$,*L&KXO) N7$aA +&Ba?`݉n.X>߶ɈGXmo/PNʭ{tsN_᷺&m] :Oy6tά+~Pۜx8`f7oѓ0{g7={C{2ዞtyI}CN< ~ DS^t|K9ZcH}MOy: =ȯ̲Fv[Y;3VN~e(>:fv1ffDuAQӌe>`{yY}ߔݬ]f98,o\ԗ߆'DXM d*k 鷬MY:Og}͏-t4Kge<;Y3\83ݱw'<5LcΤŕ{!Sv> }-]<] +Յ(6pšӼK,9 Cpê -UȜcg3DgNt贬+3`۬Bȓu$lؗeا>ů|^셅?g9J+6w̪L\f76I)g{lwˍoѣ׶@auõckI`DQ\aƇ{xS[o`Rt3ݴ-B}:yڧlWɳ)O_ǰ.*Ikp +dWIutQ,_S+|kJ2a)S~_r߽*do'QGr%*$SKfg +{CP}_=jS"j%դ2}gD(4bo^񐬭bD%*]'WtpS]&:Wf_˚ȦvAvT6UkTY&TnT_K qm"Sil|6ktLLՐ\+k9t|J^5WwQ/n,KpAmE&_.e3JPq} /VqZ+2{I2}O%eÈ1dzY_0v^Kꆠq9w2ikewA͑ڹh(BGWyoW$huUo%[I;i' +JFУ<׷YtQ"p- ;;+y߽zC]DmިoFx2Ֆǰ~l{-xZ[=ۜ4kVF5jK;un .@SZUTj)#Nb):/\ӞJS6eݺ5o6ss}tldhnTKJ}ʆ {W¿ΐuJ՟ ѩ_h-߁RG_c]bϕl3"5W{tLZ5},t)WJc +RA&Tά$KB=[mC^hMKQiMI?P +endstream +endobj +537 0 obj +<< +/Type /Page +/Parent 1 0 R +/MediaBox [ 0 0 595.275591 841.889764 ] +/Contents 536 0 R +/Resources 4 0 R +/Annots [ 538 0 R ] +/TrimBox [ 0 0 595.275591 841.889764 ] +/BleedBox [ 0 0 595.275591 841.889764 ] +>> +endobj +538 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 101.433071 180.123057 101.433071 161.373057 ] +/BS << +/W 0 +>> +/Dest (cb42-1) +>> +endobj +539 0 obj +<< +/Filter /FlateDecode +/Length 4786 +>> +stream +x]Ms+$@CY f{wbNyTd*=l{ўVIbj¿/4bL'5ߘbv1'V6 N',0L]/o~q<>!%o;sVYB A9ARsCyAGLIR KU6E'`5& +3MKU&h+`N.*`6J:%#<*K:I.@tDV;-wQYҒUXAyB-&tNt]Q啖t.AbKQnpHI:lCB# l%Q[)#Xt G!FܻIt-h|-*xЃKHDlQb`C Lr)H<@JCgD`^bҰŢ:BJ\@ DXh@V%-qo^L%qq)z+qr$qs )qt݃%%%Kґ$.]*H\`FFz Ĩ$.]wM €>HXqxik(Gxdw`%.x! P`H\:a4j1y xWG4Kqߢ}w1P FՄZҁwIJޅ$. @oVKJ1J\%#qFAE0 %. +~=I\I\u~ tB:(t]’THxn6%.! L>!%.IAON₠ p,Q[l(qA0 AxCl\-%. 1Y+qAp1Ԫft-"t:H\0k 0": !K 贕 $؂"q!xN8ӅNk -%.&b1DUK:<3J\(q f`JQ[@}dI\&:BJ\(qA(#qA₤` <> Cv%.CIG727曘 6 qAEuNS-8 M$+qA>7p30߄G/bo1\u $L|4W ^ʘgQ(P* Uc +Hbfbf5 +Vb@'\OWJ9:5p MQqk35 jzc&}e5<dZ) Mti3lGϗ8Ƈ05`one_ aRI?&`~lV6m>VL>r^lW{jt9P/2w|x(+$;mugádZ{m~*+K筐,uȪ(B9Rsy7us/P]ztm 2v~F髨ʗ6990P/Pnsl :97oMOR=c˧1i~:ҺՆ 쥳WoGϭq/˝Χ==rm͛=s8ޕY_V=ߌ6z:# +*p3w9*m?h6i~j#2ZM3>#&Zw9Z7{zV,v}y~\Lѥ@2;sL ԜS{}`76gW꼒YM0[ޗp{}4qF|39ZF^%]cJߚq܏,m8ƙkڧ=HrdK|k:{Ch^|s8|mxF1k_q15UyΎz|b;ɶ [+Y#/gg!궗3<=в~:WP"Z[&ys8TmD~`޹uߌoT[߽0WP<%.4V\`gnxW]q(WY<|}?|;cx2-6Eۙhueݖԫ| _Fu+ }wH;:3t+ m2zν3л| TLB-ëЕ 鞄gQ˫k +b=s8nh^ +@Ѹ-s8o7VWwaX|߷sP qЄBXFg62.&P3z :)⧣͡}߿?}g!x_,tAyeERGjlϭ79 +Ӱx!lk XV绂s4$>*1-f-n{XRVǥυa=tw+m轓~/8ޓygL#os8LoxžbQ7ں#Zffv)oh5zm'I} \UzFtMiXKQs~,m_w#6+wV7ȏDT8 +M;Lmok}^8f}4e}}es845.&6wjs&}U>s4}7֤ڷy^6sYFqbޕٝyv|]"݊,r7{ZYy[?ĞBM}j#qڝyč8{.^,։PyXe͝+{uxF!}s3H3ᐼˌ2a5;zGxyӥ_m{.cY)~kz`e)]2~?/mpr=zt㛼'e7L +5j|N믟XN,Mþ!GQեXs +bkSWU˲$ 5 OInPT \W&w%[>;Ǫc7R^ zsn@ӕ8_lhyV`˸)֤-ݮ-|.Z:߄t^u5Ikk[ ^"J隥RFU1R6$.'A*E[4fճVg]tDn*Ֆ +5UlYSfJ:ZlIݬ(*_b[ 7f!=_N.] + +XUUKf/ ] OWpUgmT>]YJr_YJ5mhiYu*fy}騄tkZc3)2&I\+8SXʕ\] +嗙jWͼfpw&;_8Ƚjo-a/f{q~,7ibhnƄ0B7}ťVvLjI#i 9œ'r/K4_=YvǍla*|$ǝ|xnÄ2ob[ZWPqc_ۖ]5b/)ueP]\Z25X͸KWՑym۴zIpʇp gV$r6Ck ˈ ^(. Slff$IlMA^삹ζa]dS$p_7M3{^nd_z@Vj.d)~~Y:y[ ղ=NN͵ Q&-۔"ݴ . SEVK &?e+2>qk)TI5xJtU"m.x[9ОN՗Uj[J*e=ǰ> +endobj +541 0 obj +<< +/Filter /FlateDecode +/Length 4763 +>> +stream +x]ێ$q}gK~ =X0`ȖAKm F:-YiKiTe/aVWVSzE$ ~*ip*?_.o]~)y/ߓb1TQ9'B3*.XmUfVȨ"06(sJ0Ce9PF$PZJVCF3:儇=Jtbu:43F`S. kt8etŚ8-`p[4]-@WduEz8]2¥h-KNK'\4Fr:6 ÈB'4l%V[b΄ѪitisE`YlAs =ls$8!H@G#lc!tr80RAGFg=F`Ia p\` lp\`hnLRy fJ Do9.0\@)q\`qb X89.0]cwU 59Yl9.; +w 0Wp9.VQr\`:Jq)1h8.]nj'5(#h +q|8[@`N PK8.p]01cl%TLUPg-,De8.p]g/0j xWԜt8.q  0 %]VL1r\%qfa!# ) @B"w1' p*1F$Rx_/=郍6Y:!w(ml":&ZK,z1I +ZGUt+}v9Naro~>]\>+ڕkYvi_.T6.iLݦfҽL'R\߁M9jkKOQY|3u˿|Z22(-a| MPy5MGϥ<͛<[4}[ˋvcM 7灻ic7k am{]})ײ>\2=0ÃCHۼ:*y.!r?"iqB)e@Z|{3p94+Vl;q:znûQQ#<Шك+M{A*F})=e^cZέĕiᓻTP9G3WdLmLG8O14>27cCch34x珐{.!w?|dk2\FhC̓;<̬ m<hl98*ȃ??DT:Um C\: ~[qP֐fk2^۵x{-ꒋ+,=NFwf zIFܔ|g52\hCR}1կlttйbq؈rԗrtܣի>kώ쐽-u.3 c@j2 ?Sĭ ʩ&W򽶕챡폥ou+L;2 +kaRWX.&`ҕ>[߭}0+B-6JMiӆ5\GS~h6m}5պ/_oOzHl& 6YF~L[Ò1}ᒙe k˪s;qqOOΩc[}X}]4unn;\C_5'Qۍt6/Dsyu-B!:*Z[w 6+L^D% ++g huCaDmp)ѽl=Gɡϸ9옗1C:?c7V뇭&3toQn7y5FY1R:`$:xdzyRU hHty4- p&ɣ

    B,7eXK\6_H!$x-EVbPS{(u yEI[3 Dgd7>O[61-%Mo['>NZF9IS)u)̓ݭCi nFmÿLmϝRMGh qQ$5Eup?"ⷞGOǘ>xPTC~͟,ڨQ.ᯆauQ +PLY8 +{,Ұv_'<"W_p6|Tid|cr辖.݆%sDzGs2!j?Q}=Kw@հuayU`ϼp~~7w @ꑒ&tѾ<φ*%«G1y#O<7qo5(o(8ڈ$p__rU+pcP$hīRws|e>(t=ASҮ]r9}we>MS(烱ivp^3[^$vWGr`{8Xʯ{VSa܆n;T~Q(M/z+C{4VnRٱ&g~]-Uy r7%(zTE.#y۲E]mۖ[8|,S Uv YGE(Uj6z 5[*fսZ/*bzcy\f +Lm^{C2r{bm=p\绰>N _0tvAfRzOr-zW&3QI]M:Ķ~bD #N֢-:^M.Xd[T1ۅMWJsBK{T=MP79݆ǩ aHSOk;l]vqI:WHW7 +PnGҥ!VWahV_5)1Olo_Jhl6I7ֱ =.B/Lz"ݖyl%\6CI5XUC]U45(N׆2VnƝo8Wfo+w|fg1A?JX6a7 ŝF߲Nkd܌{9mNQ.1RC_/eײnܺ3xRLI +۰*Z|m{vىTAUӎB}8uVf&/@kO˥h赥*\e:ӧP$(iҡzȈP\nLXIs=oǮ0Tp1tiiv,r+$x1lXiZ^LuQ{06&_esL~VƞiAN=4l%+UN. UJ &_UGK]nD7KKEK@ns譓=e%##c&=:^fn]w{ΒguR՟b]3&j&.X# +ak<{%;"ud !12([j oPcPT;k|$&=f+Ӝ L'O vhH;PO~7dj$7dZ +endstream +endobj +542 0 obj +<< +/Type /Page +/Parent 1 0 R +/MediaBox [ 0 0 595.275591 841.889764 ] +/Contents 541 0 R +/Resources 4 0 R +/Annots [ 543 0 R ] +/TrimBox [ 0 0 595.275591 841.889764 ] +/BleedBox [ 0 0 595.275591 841.889764 ] +>> +endobj +543 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 101.433071 461.373057 101.433071 442.623057 ] +/BS << +/W 0 +>> +/Dest (cb45-1) +>> +endobj +544 0 obj +<< +/Filter /FlateDecode +/Length 4834 +>> +stream +x]ێ$9}gM|HhX!!nҊ Bδ錼Tu;3lG+U#wz|r^0~2`@G>_?uU 1:%_eT*!5v^YǨ9̰(Tyab +f +0C/Rap*!J +!cbt8 QEV硓^q:獴9g3F!9-V#8l1:xN`vZ:آלщ.+:".` ЉRlZp:) ljVIr)ℍX-ӰӁ'!0Uխau1rExQVАx`2 LX@85G*9BB$GZkZ`` +p\5lQFs\h@n 5B: 4f + 4Wg8.Р\@)r\qb{ 4XW[8.Р]m@w5Yl9.;Zqj)<e8.XTUA xWyVAq*.pP2q\ F]P:9.@cBXqǬi CtX >V1̺(ҹqQi ,x8. ޕӁw E`9.A +@A8.]В^xL I @ƃ@q½G xWX9.p]a:آq tX̚F:t]!1Ü+8nr8*p\Dw(C܀kqXP- XQqWE+qW!(}[)r\&B4ocUN<{3K = !K G؂q\"sN'a l B'%ADtxh%1ԜΈ *r\e&ٶ`&9hk8.Af آLMqAQ!ơ(p\uエ16jh`E` Ȭ[p`'N`\o f`M lk#Ӂw: p&"[no/@#>!81^ ʦ ʳ9M{$6i3 B)6_cf c3OX}sbzؘ׏rHA|e""v Es"d! |N2f-NId$_0o#xq@h=`[|gW4X`soPFG C\)̬/]Ɋ1Z/ e>_~0zt/o$5aȦؗ +~_5>AY5k6oKɩ{K4)mٮӽsݵ=&ϥʆW@D7mbX`9lU7 W )5 +~:˴d$4KrM+ry:~̦K9y\=$=M+}Ps{Kn "Ucv{!,#~Bэ &9~>Buʴ~!Ea=Vt5ZrwR=?/SWB[7r΍T^`<0f+W +z[iuBj/68XtH_U7m9fH^}C%A(C.}[^]W+ :CN<{*~yWa]#h}} zz,Zgi,PJTl;oZ=ϑ~uZ@n`VoǠ/ʒwB +ZI0Z9ZţgټƱ$=s:W >K {+-*|Z:O,V@>`!l;|Q2I\\v9~GSgFyHD+Қ1^|*#PQmZ?rnWriw;_QxSE:gC9 ]F)3Df\92<4K^,zhZ^(dν^[5TP@< 1&H[ZN=]ƅK5?!N:>ZzYw4<|02gzugFݙرSߚ絈z$IHkQpe>㡌nXB7ܟ78Xt2s$v͑D< +M;LmL]t?J ?lSi =˲gY `0q.P]J.A7\R﵊bكuNԝsϤ:zyY m;2㼂b}2{Plgku.=eW2Zm%:1Vg5Չ?ؕBMsj5"i9wo}x%_xND"OkD"yOоuqj(cuNz~Lr>i}W*o>=u;cE..Ayn'iԧOC"nY^Wo :Cveș~I~};}}9ӕP{ ;SoQC8ROiw.sbΡfǙS4|w_An VCJmڽ|:CN>ƞǵ+{ъ'7xn KU!)#X/1obXC~gRUy;Vܪ ]lRQѱM''?^ T6M:F'o[=-dG[}y#Sm[8#>5fږՁ b_Ri[>*[zR-}%_ +?ޘKq$N \5źb3AC˶[]ԂR(XbL;C皰NN/e'ӹ%]p[KYiziViUQJm)Y'ybD #F &ɬWPdjX1ۅ-7fLZ*|3A]:F"AIֈ\:p 7j!]+/3m +a Pv8&M_OXE^ܐ?R<4R+$*:i|+KKz_1KKO[KIɐżDRSiXV:_e9.m#Td䴥B 3%ЪM,)Mt(ڢ/6Z1ERYqjkd)}h%k,ԴȖ6{o{%0"SѪEɇ3\3!2wwQu"81鍚vd)z'L`^o+&mӋu +zCzOf_`( +endstream +endobj +545 0 obj +<< +/Type /Page +/Parent 1 0 R +/MediaBox [ 0 0 595.275591 841.889764 ] +/Contents 544 0 R +/Resources 4 0 R +/TrimBox [ 0 0 595.275591 841.889764 ] +/BleedBox [ 0 0 595.275591 841.889764 ] +>> +endobj +546 0 obj +<< +/Filter /FlateDecode +/Length 4884 +>> +stream +x]Y$9~_QHk|VHKBX⡻vzEZx3}3fUS>/vUJ}_JĘw/R'/X\d + ©䣻~GDHN}Oz',)yIe1UJ*è!hWMLS kU6Eǩ`:23 ʬU f,*JK`hFt>&X]N>XK{"%8-NY+9l&NaF:آc0.I.+:"T.R%d q N)M00H>0: [tgtXq:3!FfjFl:XV[0h[d` %t&m9mX@$l>TiY1Qb:bh؂[5Z8.0[+oT…5[ (PJpwr\`@5k h9.0]cwANV[` ¨h8.]dw14Uz cXr\`: 0 ynvRs\`jq"?LJq=tp\„FXqiP1y xWE KB83oBy8.p]8*q>#x9.p]e9xW$9.p] A( %]VL1r\%qL c!r\pޕ d @IqARMm9.f &x̼Mz3p\,lqQXlAДy Nz3jd´뚣%3ɦ~{]^~wʟya I'7J,V59 %R3RM726]4 +Ln]ԋXzwwb譯,kaC ? g*Oqg3kH=kNc~ӯ~'ׇ_~&%F,x᳽wЇaE])/h >~k*:7QJK{F>1)(S|fwu#mN+'s[J˿^?jSߏJ3ܜ<&wӜT:SpsS箦7UҨ)O.e|.p~9lJ5>3Ԇ,5d_yIӱn5ǔ6m/s90]շT& 7]Bi PdO}Z7STEM +iB<`PܛM= Z+L;" _R5RWEjAZfo~'`g]{F3_{OY!%ha(q'IpQn…J۳Ʋ29J-=uPf>ͲΛJ/ uL1?3`);l=9P,,s}*Gi/pW[,8>`ӥyvT_C#g}|&祟/lge3cDCyfovò.)!CqX5uYr{?̸9fJU+o]e쮻Նr}7a8QLp۰}lSY/iraնlg߷ϵ2׊ ]@px +<!"_iBh<!G +QS|mᠮyT3 kkw4?>vv}Y鶴ea;e#X>Ѱw(50]ݍ}\C9 a{`󽹘4+<y7tXmb'<./hj7r]n(1X#Sg"[9o !A/ϯ0{뻺v ڭc;ȶ)P_7ΘzOyֵur 85qͯ,{-Re^Y_^Eosm xUB+=Bʹ<fvpgR{b`aw/ue@2o)+L)y;A\6!]i/M~nh0"ɨ~<Z^y\5bVHo;#@1 H +|]\TPu2 "-7cgMNL=P9Űt=ύ{KgFly9)?i9=ԸpY[^=?y 8G?ж}Vzd~_9ls5 ̨c_?y7P8dC~yOӎ:tйmu%>"!9䳧7,4@UE_-I6dC.;wlc\Zd=Cv/p2á WݷFq~ w=s $vMx.ϣ!1a,ɟ5ty7RВ_/rѸzj.ͼDgS^}ůƓ͍Jm.vq +G^dCq*6orq޾ڭ:MddC↝k7!u>s﹩܃zOEC w'<BawۥDv?%[1Əg xm5P|!bsw6큆(Yvz.!~_t>YQyʿ%cf>a!Wv{g2ϣ!amGM?Lܶuwm6G +pB/h:e Yqyg-^p/_Q$=īRIJ5q|&bdml4>غ;Nv_\ـҖ޸/Ghs}R=u6҆հ}*^zx+MOz+x3+P9JcU&;V]7r}_SIzY:c1>w'F!8rįze +}RLeYUV DS'1GG]|J6;%7*fZLBbztNf\m2Э-(z:߄T7%p oTkF++vJjYe3*U+):Nva_R`V}7jtI lMJ:Ft\PSŖ5o4X;>iǥÍ^ ogLl׋ Lj׸B^hr8ʆ&~Ydth +W<Rtv*YN徲z@vݥBKEɤ'ҭk-]uyDRIyo|tWo=H+~ߖO~\rB{2zY<)Ea6PێXŖ4T?u׶eKJUTUm/t;t=vk ctiJ讵tb.26i.+J\:Vwqˮ,[I+]O~( ]ta]EYnE!/+M {<>yg}$^6xɗ~yY}7|-P-ts MZEN[9+E8J"%bn-l/S4vNtUZ*x-ΡN5Զue^ffol*-s}0sCਭ +F(XXzW;^zG5)e3FEMx"+lIMFsX:}˼!T/-!HϞ Em}y +endstream +endobj +547 0 obj +<< +/Type /Page +/Parent 1 0 R +/MediaBox [ 0 0 595.275591 841.889764 ] +/Contents 546 0 R +/Resources 4 0 R +/Annots [ 548 0 R ] +/TrimBox [ 0 0 595.275591 841.889764 ] +/BleedBox [ 0 0 595.275591 841.889764 ] +>> +endobj +548 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 101.433071 713.673057 101.433071 694.923057 ] +/BS << +/W 0 +>> +/Dest (cb48-1) +>> +endobj +549 0 obj +<< +/Filter /FlateDecode +/Length 4945 +>> +stream +x][q~_0Cs /bFv8C~DDZsLbU;_)~tQS +JEaju_$Sp}pɋ]~諙rF_)X,~ 0Ĝ%eEr b8cJú햕!I,K+ȡR"(xOJ)lȋh$SN{-BI9CS8 Dd1)Z!vK֕DdQAisrNeTi3O>Y$֓mZI +Q"xijG') j!1щ<ȂɗȢb +h"\08l&%$0)O.F+~r!G -UŻ !Րa'qaB˓!KXب L'F;j KXs4 MZtE^TNI, O*ID^`HZJX޳rp{DdHX<,[aMYRH<ҘaU*f pM B$I@ ^ $7!+0KX% N8S9IX dHX d a<)kxbxY`.b| ]Ys:]2:iA_?xOz@4/iW\IXJ-uRWj6|X^wYu"aU9v +«]M;Q_U3}i_?ֆXs{_dskyP_njvlFSLz\.y3gTΣzγ+z7 g-˖MYW_6ZmXmpYjy:u17P +ƙxF3Cf_:o#&Qyfwp/:VUVmY߱0LR-GoaW,ǬgYq%U8Y,,uaW +72YbZVlL _X/UVْzOy6K6}T,m<ֶ,xDaN<Kv[w4Mdv؏iO/zֹQ`?6 %7{f팲pv'W}o7ɦ[PA_)ۯEkcC~~Ŵ\Ɠ9aZRQN.C7ZL.=KeOy6K}{7U/C;sGzޱb扞;{Y}eI`v*s*Ajg_GzX]Y?ĕ5FJ&mv~<:OgyZ;+pksy :"6gf]0j8Yd8V2 +y1π^r\6zYA3>NtvLF=Ǫm{{نRvpPnݛ{(`v +u4ibyγY;xN̚z͙g殃=$^$ٍ{^>ޱw'ȥ-ݱqU}MOy: =ȯ̲FD㷲wf`{yY}ߔݬ]f98,w\ԗOkU^A7wMY:Og}͏-Ǟh6 ^y>w̳pz|tWtxyCz[re̩{* O6]#?L|Z-w26q;k-|`ʳ0U}E= jD_~`;NOQBsFLÄ/ik9K|/etM%oWraKIV~yu{-e>3 M^{,95JL魜sI0Ie:pB7ҕ¾ߢyQhѿv(Qm1gRmZЛĞ=Ԑ)'k;쎆UpΖCwhzByT ߚӼK,9闇1:"&eU;At[9+9t[Lt8iY;WzS3>$!hþ\>o_9Wy|K; (xݓuĂٙ93}ɏ~oǼ{mˑA90غYm̻~&+6Rq7 ˍ +dZTSwx_>\v%)W馥$X{a>/mvkYԧc~.*Iz5NW:!utQ,oZ^f|{:۸L#XT&Njn"Vy*d8>~$]#N ;ad".UkW 8Ny,Z-{mu4Tjt ,S"j%դ2%Mv +Mr7x`xHV1뮓h:컩.tbNeMdyx[;RD*26UkTY&TnT_K qm"Sil|6ktLLՐ\+k9t|J^5WwQ/n,AmTl([?ɔ;ms!.޵oҾc<%Zn#'Safѱ{ +ߨ+MJؔv׼% 9ѩ^I^Q]/i+m۷[]w+낄^oJ ޳v:CA*UJ&D +lNGklyJ!CO*R#׹+fDj阜*jz,e%1sj *,ΒjЈ׈Zrz,*-?WO?~K# +endstream +endobj +550 0 obj +<< +/Type /Page +/Parent 1 0 R +/MediaBox [ 0 0 595.275591 841.889764 ] +/Contents 549 0 R +/Resources 4 0 R +/Annots [ 551 0 R ] +/TrimBox [ 0 0 595.275591 841.889764 ] +/BleedBox [ 0 0 595.275591 841.889764 ] +>> +endobj +551 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 101.433071 180.123057 101.433071 161.373057 ] +/BS << +/W 0 +>> +/Dest (cb51-1) +>> +endobj +552 0 obj +<< +/Filter /FlateDecode +/Length 4742 +>> +stream +x][F~_1H1}I( $.R!L RW3lڳ㪾g4St|{)fKw֊tѝe CH~9MrgRF>b VP97`T^Ŕ$p -UfPNR 2& +3,m3L$`N.*`6J:t %у$QH:kH;-wQlqIiI`DJ1H:[JtNt]Q啖t.E"QS1ĥ(7htZش# +䃠3+DlqVIga Gҁ' 1 +jI`1DlAK `D `/H\# )/qO +:|ve:B$.c=$k #-.` "SL6D$qAp1ft-"t:H\ XK ^0:M[0T$.T4D\i'[xi-qA4ޠD234֒hjIGיQH~`WQ 4&$.@bI\X:bI\f Fbf )O₤nq蔒 ! 0.y%.HVa%0n $-.-p0nIXo$-&{^oF f` ^ D^o1\u $LzW ^+(F anC +܋*154XYF/F 0B6P_ck Qy!`Όo2aXJk|_? >=l aLM0 LBw;xo9>fxbfb a#y؈8HL09ހG8£DfzcmiZ=ҠBXĚo; ++:il2L'p k-䱂'=/ꏿ_(E?]z@5IXCqһ&>]g<>sYInIL5uЕ#/sJ=B;ueޒ.SPӯ?9:!z_ do<7VG5;Nԁt1@zZF;56?wW|lsN3IVtIuve}3}g zn҉歊 @~; X.$c_ېD|N+Xq{L%~ROHLإ֩v8}cIɚxoٔFeB~k8nm_án2&TϽXNE.'r_-4: +֏6ScyHn_揿ӟk+]9K;c &En <>[֌7Pr1BC-c(,GnXݙ XuloÞa0lean}ڪ7f߬Nمu[XaD+琖jTq FS$Bʾ<AJ5۹=H)-,֜qi:V{2^.CwZ}("N*IF0 ~77jI9g> v7JsdS+5?'f;}ѻx/; 3v9\o:ox'+I8=qrW{uגI4T&m]c]#%ӵ*ɖp5{W߇&__ѣ}]}쯸wުGgG=ޏmʙaG.n񀗳3n{9=;?dy2\Ѳ܋̖3Py}3Qu7W|\AU3貭3ᐸ7}$V} u[oXs6V@ug!4Q 5YO?65 6>[ݙpoM=fWQv9ZmDQG_ݓ٫N ٙp݈>|xzWq^?F=ڱXAНy{Ϧ=vJC)59.m3ZS8Nv{+1T@t9t>빳Ϥ>}g!x_,t3zyZ>5e{n}3ZEO6vOԤO55=";5}ˉzS}yYn==|nw}}OA~!ҙ/1MzlX}^9FjzmVl.ߍI'y_߂Fq4_NDb)fQHEv!)o)Щǁ^?󻜍N+bA^/|'1I2vM[ 7ڪFBTWņ=E~Ӷk{4k{/ry+ޒ-kݩQ6wRMilY7γ Ꙫ-R>k. ?c$D=LԤ5݉ރC_n(6܎,#"9VքZ4b i[2PΖxK5 +4%cr KEWѪUA/OYd/ +endstream +endobj +553 0 obj +<< +/Type /Page +/Parent 1 0 R +/MediaBox [ 0 0 595.275591 841.889764 ] +/Contents 552 0 R +/Resources 4 0 R +/TrimBox [ 0 0 595.275591 841.889764 ] +/BleedBox [ 0 0 595.275591 841.889764 ] +>> +endobj +554 0 obj +<< +/Filter /FlateDecode +/Length 4495 +>> +stream +x]Y ~_\ubȁ m`C~>T$[YL `v$Hִ4J)@NZEXhʛ?Up~=_cVa9S 6N`yb>`Ă>-+B K,A& hܖ!$0Ge40VkA4x Q!eE^D+S!FeBIdY!7DZAr)JY\pZAxXh' Y]IAx)ӖgW>9%17ÎBxȃ,i+d!|IиoeeBx.wI`BDxqklx./aA$ )"/+SwKVDaDEG2F*aA"g pW{$,]MH{DdqJXO(3{^y^y`g>ܔI(PQ Q# h PDiWNY锾#3֟}o˟~Ԛ2vfz~Po͉Q_~F/ U`ei"G ʳHMlwk;˝<ĝuYrvZJG}Ot>o:>ꁴⅥ5G [V(!]h͞Ic޾&lwC"[\-]qi0-0=)=9O6ڕEk1.I^3Fr}lѡ{R뿎x-"_㗶+gd \-6؝1?"i5= 4p;ysy=o=lY/0}= a5z,[Ek[e\/Ş7ιeϴ5ϴsѷV4KW\Ty=B5| >o΃?I~]iXOoMyszp'vj,drQro+->yEul̴V;qs]Ϯ=VgIu kM̓}ޚ׹i;]{w{Y :8\saطױ> \z{깮A7/Wƙ߷ND-X[E:e}8~xOḺ3v'| ]=7t?uzϛwDMH+'Oͣ8y<}5U L`>EDXA7"qM;imM>bNm=<>UNܖYSY塰,G߯nn|?N)1JdY}?uXtmΗz^I}YeyQÜfi җcLx͟vL<<ּ6qCqg|.ɡKOLFN lؓ/1mc{Mves4_Wby(>3 (m^y>s>~ fn_bs;ʺ2CK[=Ak;4°w>tێpGOq2zX,zĤ i܆f:W#VUQ,j(iw?rY?iT`ISԼ3br4#+b9^TKhkG e\{-UݕizPrp>s~(yH>َs_ȡv쟋wŎkˆz{<˱3\YVSaDelmwy/EfRWc4,m3l~M_luga\-+)PJ"`7SGML&|"o93y<Njm/d "Ei~(}p=co\yNk!jlr$j9}lV3tĐW<*LAPu +csMOXU"ƿLO5[Naz~d}Ym ,5|6PctHX~9 #Sdbygy 񋒊Ǜߣ#jUb ^Ŕ2Qn8_6VVa/nТ^-r3vp_eZw=ْyZoE7߅& +cw#ilooz-Uy 9.tb}T_8r´nM}:TծՍrڲ$?uh1k"HN ]Nby4,[Ի.Jwu>2D~GK24[4/'ʹ!|ZWnҩtYi$ +ߨSU*'!&`"PκMt +BrHi8H=+g99Q# +FF uӛG +ˁP\*$q&~zFA,<O +endstream +endobj +555 0 obj +<< +/Type /Page +/Parent 1 0 R +/MediaBox [ 0 0 595.275591 841.889764 ] +/Contents 554 0 R +/Resources 4 0 R +/Annots [ 556 0 R 557 0 R ] +/TrimBox [ 0 0 595.275591 841.889764 ] +/BleedBox [ 0 0 595.275591 841.889764 ] +>> +endobj +556 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 101.433071 348.873057 101.433071 330.123057 ] +/BS << +/W 0 +>> +/Dest (cb54-1) +>> +endobj +557 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 101.433071 112.126036 101.433071 93.376036 ] +/BS << +/W 0 +>> +/Dest (cb55-1) +>> +endobj +558 0 obj +<< +/Filter /FlateDecode +/Length 4774 +>> +stream +x]ێ$q}g%x}`/%CO}`򖙑Y=Q4%<< 2Xc +/?]¿bqտ+V&# lBr&.o?D `(H\#M)/qO +:|Ove:B$.@`=%k  "F-.` " RL6D$qAp1xUy3u:$.&LZA/q~pI& B-*`*Ad.4lA-q"]贖 ؂hPh"V^I\kIZґuf 8T+M0- ?v`&9XGhx%.e$.6y$.H + ⓸ )?q,qh:$.H:biHK^oF UXob'd=7`C"` $[p֛`'IaI$qAכQXo""7]u $LzW ^+((P*n(p/f (/MeU( m8a}<0gL辭9z2l˟.|{\^w-y^X#x ry&m[ߓAeӍT6]4Ln-RAm}8ۊB"Docp`$%-Ksx%س>-ب]; mӏ_#?~'0v;eRONw_ޫ)EqN,F^ҲDxψnC=̲o\>QZj+r9^??v)4˦Pe2Pb?X~h-#6>cuM;Bur|+7خteq6`G[k)O\Sjܮ~3vվѵoSbT1Zie*~uSҎc:xoTǭ- me۪߲,TY(}t|-1w_|hy[rC1C[-17Q;NIj pj}&w-MG5R[5Kca#?u2רNU͝[!*:}S#IJhlA(ѽƢohx/s)9A=O +vCeѪ|+{Jޙ֓͛v+Gq|)HR酻u@JǟI6owf2LnA"{A6h%c-J#*9^W};kGqzE?*kNein+2,X<{ڶ{S>=% K6h_3^fFe^R~dt4ˆ]t$ftӨ:ϦķJٴ1ea]56݄ՒA*Ǥ&˻< V¥ z0Ӽ/J\y?e=ŲU4|oSUFR'$) d'AJ7ۺ3Hi&׬Q3/WJ{g1.*_ykY-%V|38ͷ]ў9!thwyyoC' _E=yO.wޜ-Bj^ůuI&]թ:@m1X]ԆƗ2a\Cmϱ/#Ϲef4Y_ sj6n}N=-w1:_Ό8~.ϳߏ)_}tO_9ջj߂F`FU3J8dC8xh1˭Q;[ٿY|33u<ZGH6]"~=twQ(x{-t5426HnL^2ֳ~Ez&oԵE{W9BAp+5F[y6CW]Y@g8gt?[Eͫ;,7o6Z )\}%1ul}%oG=XW)vNsK2ZRw>ܼs͑;?!5증׹Zތ.K|oB#R&H!C(4t;#07(7U;]<φtTj)?[KzYrS'ѿπݻyjw[ڥE;vYf鉎ֆdž̝|'Ao_st=T}JB> ?WDmҽmX|~[^ݛvǓySm6Von1jG(>PA`{n$v?NЫᔫ$0_ڞtի㜖J|Tn Ж&~3֗z@R\SPN@vHGx@>!|D@=!#Hr}f  =+RٓmtOY O4}4򱅖t&;9?Tg򹏹Nj?^t1ʇr,^tۅe'ALB:|T,h*XÔ)Qc?64󻚍#U|\\ DNbntq7S(&Ҙ3Umj U{4\绰>N_Ӛ0t=jZ&J8ZTQMfRu~D Nբ C񡤳0V QKj:AtJiThbϚ)66 pFY_ƈRgaVqoGm$v!\\(CMUKX]Ye|#?SkRfASگz%<6xQMܥCh3c AR5IRꚘ)q(TTŮAm!v6Tjy=ݵr7|šS/Ux X+bl+0Bw}:Z;ԏ}I3Ku Vc4.tzF<4n]Ǚ`$Ta6@]cO*2VƞmAN=ňA{R-*E TCɗl-QRh1Ey{9э7i:hɶȍpuldd~ݤS*M˺l{A#SճMw{ƎxpޘIkl6F8l<^vG5;&V?'E:V E՟㓳%%61[AL\yC]^*OYz#2LPZ>h:Iv}W +endstream +endobj +559 0 obj +<< +/Type /Page +/Parent 1 0 R +/MediaBox [ 0 0 595.275591 841.889764 ] +/Contents 558 0 R +/Resources 4 0 R +/Annots [ 560 0 R ] +/TrimBox [ 0 0 595.275591 841.889764 ] +/BleedBox [ 0 0 595.275591 841.889764 ] +>> +endobj +560 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 101.433071 612.273057 101.433071 593.523057 ] +/BS << +/W 0 +>> +/Dest (cb56-1) +>> +endobj +561 0 obj +<< +/Filter /FlateDecode +/Length 4908 +>> +stream +x]Y丑~_F} ? 0crl,j /( Q*;ۍJE_R)U7%r zEM+)-V;9$6N1{Kǟ\f9L,gbT^`e)F +zsXGgܖ!K,I+A 뢶[V&j' > +, 6J<Fi?(=H<"/xN!:S' JK<YvNI<2B8mLI8NUVK<YNAl&@8Aᒄ&e$0N.$Iyr1Z L 9J8`h , ,'WA@4ZbmE u*k ,)$,\$,@\raJY ̵N ,@=JX`#aZkV8வ) Xdu8*JX8FF; V&wMRN5.@ gJXc k P&. dJX` ,wu4j)  HXSK<6YIX0I#m ++rJx.`HX/<$yq!i ƓB*aA½g pWyk%,]J`"/1 XKX\jJ8' +$,i'aA̐GE)DOC Ok ,%,H&! JxhPs$aAraPQd@JY`( A4GA띄)J7)AM7YAD|d& +%,Y'IXsIf [|)pn oF ,!ȃ,pnI7N/@973o"K( >$pi7JLf&8X1P^* *5I,@Ld)UU0 +xm0a>U9Di!o9Gofwo|'RVjC|c`2#XЦ8f)>҇ Kэ?퇕DGoEjt2?#?03s(rD탖ev]IGj۶fjJ:t1` 򁆠t" hc!QFܪ~)rd#t㯟Ͽ[/o4LOg;i,`~ZX~ƅy-?gpkoi-ciqL2G&Ykoڛru]쿯~yOk*l\H9x˗| aI>N~_ۼlڗQy7Y{Iw:ct0)wdg3PdwrJٺnV̰; x=tݵu6;j-~EVƫr.5йq4 :F}U̵kAG[UOy:uwquc_Y󼵞tz.?C۵zu~u~Wi/}6o;a;VP@g1|d<ޏ] Au g3_" m-vMYTydfXIEJlfǞ /^|iTY^ѴvnQʼ+ڎ +/QXX(3cvdTeuepݺ}ۇ*ر`Ss}΂ǡ zձ7YR#Rd`<|EiLV`Vp\eݱdt|?F6YS=aakRMzJDd{i}WH#tzy:>`L>52[qFEԃn$dr>Eԛ3[O7ɦ[PA_Gת Ny6Y~WzqŮ%Hj]'cĶR~ pqsQI(p<8|W?SK=kReOy:K޻'Z)4qYہ>wtp+f;'<ߏ^[ +tj|N`c1>ܱ]Uw*ZŲHmHOik;|6K>y{COg'H>id_ԣ{΂ 6=,#}_BXy:;Ytd<ߏ_sfvOTz]s0Vv>4hcX.np\߱bwG7gYq@!7v7 "xs:~apwU׵8XH/{0I`'U?؋6q͞YB{i0OYvލAE=bFZk15 ؤ#ӓ/u%gI7!ql򸰥$G?˼v͑_)%Z4^֧*Yf\o 邭{O#<6[jM1N![zGn]k9K/nizwXI=9T_Ka]_jr&daٞkAzy?-ZI{۲e}Qlav1tVL&-{Xk;zn ͖:v~]5;u{3t0C)Uw)s5aط}⎞f;^=uƵ-[űvu5Zߛ7#S\;cWcl,$她%T1>)ER20 +Cs0L/D&t vG4>" +#ף. sۇ){ԛ`b~*Lz_7ECu!l~~eu/ +} +qe6rR^:?hVf7*!O]3)zUvl䵒8=4q-S,חNJhOZ7Les@ǚ52AXOJNTULɾۊz& ovrhɱ7y۸+VdNF5o'c.@;r= Ivۥ9cd2 h?wM}oǍjhaܓї>dJldžc:ZC0v^[ꆠq9w2ikewA-ҽ{uqǫTe<] +j]:ΰMd+1 $M$[ai.v纛CWZYk >|ҼG jF}Զ06\e9v ,;{9h­.2jݖO*m5iu .@SFUtj)+Nb):o\ӞJS6miZd[9Ǿ:[X2 {7-mmv빫e.H葩Cٙ UU[*!:oZv:Zc˗g0EXi}JZ+3a;&gUgv_*wJ\ :̩M%|^yeTRЛۺmm*U7>5 +endstream +endobj +562 0 obj +<< +/Type /Page +/Parent 1 0 R +/MediaBox [ 0 0 595.275591 841.889764 ] +/Contents 561 0 R +/Resources 4 0 R +/Annots [ 563 0 R ] +/TrimBox [ 0 0 595.275591 841.889764 ] +/BleedBox [ 0 0 595.275591 841.889764 ] +>> +endobj +563 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 101.433071 142.623057 101.433071 123.873057 ] +/BS << +/W 0 +>> +/Dest (cb59-1) +>> +endobj +564 0 obj +<< +/Filter /FlateDecode +/Length 4733 +>> +stream +x]Y~_,>1^ <̴wlyWx*=vnU(?KY C;s|8}<[) ۳VF |ʻ um9{GSҞ~O*QEԌ{err)ȩ`F T0(Ux3S gTR`u0Dvpht\*:i=8o.98-6 +,l`s:[ӂt(Ndt]tQ6cX]N:%`ւI9X`S:(tN'lduj8-GADe8PA& +q0kTqsV[ Xl1p\z: -Z) -p8.G0D ]]O01xCr:A׬.@'=ޛSk!`s\]f@' >  0 A3t.tRr\l7qAPL'8. $AqA0n W 4&8.@br\X:آ EqAE qIMqAQd @ qAMe8.f j&x̸zs\ lpQXlq NzlQp\fnِ֛@g]L q\7rk{ l@z-V6d <3 _Z#Aepl*Ra?f0F<$#w_5^I6~&9=&E򟄃RW*-o\ ݒ*%AStG3Kajc p uoW6Z`( pÁ5v +`6&ߘ X%pH" +Ÿ+,ޝ`d-Rl>+v݇ӗ/?~Z1~ Mf7ʰ/jc9VS#k9d?|E=$KrOuX;?b[hii +W[Vj|1.2s\ͯOsw9ZU^+斈1|B]^+76UP r:Ry ?i]I١:)ztm 2?G*jMK-D[ݗp96Z9;Մe'1ʇiz9w ƾ~.xEϵy-˝·=#rmՏ=s8]ޔ^Y_OVo_#0}]W挿;̝yJ}ϼr=j4f)V]}FcՀ#d]ESuH#%X]*ɖcsq:ݔ3]M]%+sٙpkOw,]iehiEՖ3Py}5jnׯu)G7u˶; Uvû∋@U#s1}GmM{3x%0NجÈyWe>WoJN؉ԥCsK|i)]2Nmͪ;u;#R}d"27|z1%jz"Z_9e+;wu&&5w]97;RtwDv9B݆E(*:^frǂ̕| mވ;b;bǻ ^wkFYy ++#3Pq%QU^AOs4}<>˲swgG?TzuVt/ ٗp݈{zWqgawCw9=4 1rkoi(e<>5kå}FY|JCwPPuYn;fߍ>y}==I;X5x{=ݢbꗶ67FznMo +$q/dI0HE;BLd&VWr}4?T֚vۢV}7)N2ڟXcO$1&8ۋO aN1 edNXd/|>~R8~yl>os6ڞˆH Ɗ!r:ًANbJ2 z:rMX3n.Hz4bztV; /'T{3+ rQu(2攥CL'Ft91/D.ڠ35h $SŜ]Nl4[zʗTf):gd&q1"t9;"4Q dMU|Im+W +uSnQRt C3h +[<^ڣZ "7R+wu i.}l^2&=nI]Zl&m#*1˂"& +Slb[<W;m{[Ůps+%jU-6KL/&\I+QfZY#sZ؉v? fS收*Ӓ6il,y/|ϿN+8+QBnۙ ;ŴoaiheimFCǕj{N) ʢma#VJekȼo=|rF~R*PuNHQ:Kz[wm8l*ղȶdiBS]AFС:Sٶ,Kg$ ۃ`#J軇׋}2@BEJˉ/˜tomRnƞ.NNյ04lSVjlVi( +]@&Mnʖ%q`[Jj[ڶRѶi<oIȶpDMY|\HMMlYםgssg*j6Hy3v<]ԁKR$D&j#V ΁C nMhB#7+YFDr 1ۊ PmES!- +nk&TiN,"AiLrihcڋV@{1{oV^f? +endstream +endobj +565 0 obj +<< +/Type /Page +/Parent 1 0 R +/MediaBox [ 0 0 595.275591 841.889764 ] +/Contents 564 0 R +/Resources 4 0 R +/TrimBox [ 0 0 595.275591 841.889764 ] +/BleedBox [ 0 0 595.275591 841.889764 ] +>> +endobj +566 0 obj +<< +/Filter /FlateDecode +/Length 4988 +>> +stream +x]Y$~_&yXc{ksl,j a~T`(Q5Ft2HE}H}UFR]o?\~%z械ZxC`71\_/o_/:jS V`yh|XA/b b۳"p9y11I`%a]vD$GF)As<gR6YEt4%Dxy !$dYi!)YMQbU"ċ@;Y%J"v99'2x*ŴUO6Ê$( d gYUFY#Ɣjhu[eŘDdK`dQ1H.I`b\\6NK +`dVi*]jrEdIX` dA ,Y ,Z$,[oA J ĵ)8 , %,\ 씰tܣk}0Xu)HX`i%aZ"%,:.V'+aZed$,. ale1)) p$$,p]D^\k< ynHXƙ a e(1B@+a[  U9Di!{Q)/?^?_LYJi +dLG1| Y)A7ncbiaMXpxP?Cv );l#0%oP䈘 _-:tJd}s lb~nR>,?:ΈQ `ҞB۾V2MCRJm">&K o+lِ0bܦ|Nk_2iG㯟~O?\+8Z7.ݭ2T^jV}-ukZ;Wy ϣ!y1F8GZ/R:5lv}1quY<$G)O:}^ָʾh5.& #wh{gaGfns/l10Mxo, + v1|eֽ3;)yi|N=5kcGOy:<DY@%-hyD:iHerF+s +"3Xֱt|,-ŲmY=oljcSqc{ڃ|-YUsǂY,b)Y:OgkYtۿ~v;Jb?{`20滸߁<Ǧ=r.s >X|Ns[ î)6[/ [;M%udy-Q -X&F7Z.kF^d61B2fǧߜ?X [1GГurC:6ͷ#AFh'pn1`^D`d'6lv4G扨u{k{tLⒾHkYq_%%Ҫq\kȅ='9Zsϵ]WyFNs(^X0V㺹UnSWؘݦKE_#2}" չCb،y=KkeUt};aFz`fN׿mC9R'c)j+A6zp*(gB.ve^j[2[lIiLם-:.>O[mcޖ6u6tgf]~ +{q3g\2ZKYo2}ݽڼodښ2"&oNGaSt+2]st|h<]ru=Xqh5rs8#I֥bXZu74W]F>.[޻Q1~`wjOoLkut*H۸KHӸm{l_dl!h]iGR%=~ G>bΦ] n>b&tFGk|#Dj 複KzE=K󮃵]=`QN8zZ20Eez m갅r͋BQm1=(ϣ>,cΤڴviiPC`hk4z8zg3J;4OOBu!|T ii%U️y *bRT ⦳'YPٴ{}OOgzt괬;n:wld'Ita\v텾5 `2V#Se۰-=e.*-R $;E]e?s^LP;L Uk<{d'!vTG-i~J$kXReww~aN d8B1YRgw^_unkhz#!9ݒ) + +dm9:Ogf^3&$<9i3[(}馹(|$bsfpgn-'v\>Yl9C\\C~շ Jyny5r 7.7{BnL9lZ:P1[}퍇6<"]z6z={h< GmX<NyKb{}RYlw/6[ܓ(dvpku;@FqH1F/na-5;S\Ĺ\Ͳa7m?^By.`U!aOI/iP*&+/)t&]wjWKշ+z.p}>,EAJԪiz7;8bLQ'KKb?q6 GhoqNB3mX f{2^-i*tQs'/;UDźd<UU&<".WJnM5i ;շ}B\'toTka2;s%fH˭@]r5g*RiTMCa6u ;*Q}ܒTikݘvA~(+hY԰A4kHP;|Юt\NhmvVI:8IQKmK'%'6T2FG cK: c%'&dMuCrTv9t|g\Ӌf]fx+d2:d1 0F_ ֎N Xdǽ]v)nXoXޛΣ,}_-~^Թq:Z2d-$uaDNo1 ݨ#\NClmf6i2?un^/mW6p4xv+kWTttpaq%06bANI~ǧR_삅ti 7˛n2 +V!ayy# O*rh+;SOrr-ޡޖek g,ZQFMZ-y66G4hd +ZSKq{L1|V=+K6ף% 9ѩQǒI^S(im߷ݼ AˆLըw%߅Y;k) j?%x5[L!p"R#os+gDZX*j9YW0ck}'\-+qHoS +0vC%YB2VgRЛQq>)?gq +endstream +endobj +567 0 obj +<< +/Type /Page +/Parent 1 0 R +/MediaBox [ 0 0 595.275591 841.889764 ] +/Contents 566 0 R +/Resources 4 0 R +/Annots [ 568 0 R ] +/TrimBox [ 0 0 595.275591 841.889764 ] +/BleedBox [ 0 0 595.275591 841.889764 ] +>> +endobj +568 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 101.433071 356.373057 101.433071 337.623057 ] +/BS << +/W 0 +>> +/Dest (cb62-1) +>> +endobj +569 0 obj +<< +/Filter /FlateDecode +/Length 4714 +>> +stream +x]ێ}gI@^ <̶wlZ6NQg-btZʐ{iUJ*bT +u)[S 6s&˩`:03xEsU+é`3*%aR:"!8V…#)9p(8]98-6J,l`9-H:آ'NaFDF` XlN*NIau:|봴"$VNri⤍Xl1t K>f4Ith -|-;0D%Dm8Ё &p,C{h@G+ +:8" [q-#Ұ 8. -5@ 52* |krfJ K  (E KN 9. .Y9. .8. .%9.0]"du(HwIIqbi Ы8t+B 9.0]w$ xW[7swF; 7X- X 0C&4 ,xWEL̘[ wU@(G3,s DEX.3p\Q535*% r\8oBI@E!cX.hIs\YX&au^HC9.p]Lޕޕn-4kðe4U!5ӁwBs:>r\i$Ё(k \0"z8.pQB9kqXP- XH1p\5l!9.e +7<- >0"`21xCr:EkVST8.ZJ z @"K G؂q"4dİ0˚&d?x{ߧφHYQpn [ɡfɓ@c-/;?L, S>bV +Kh9`:@%GmPԉ9L @@ec>K,wO_}?FO×+xmkҸ˟_\u%}*u_K]Z|Jƌ.IbG?7_z.N_I]\J~O{7}އmY^$:-|rW6]5M9Cwj t5O>uCe-\H<'QbKՍyVVZN#r z~_@!UKWu6g>@R}]n:܀1 M~.TeܔO>qj϶}`n\Q\݃WR`"9o;w^FwF{nv[h39\l +V]`u½g8t/uҽ^sG5 cP_r7L֥pMtdSm.t,tr6kcKxF{髻]qd-_CM9Lz2b:پ0G^1OY*TIܤߧV5os8_lٯg9#H 5{#O{nx oAVp͑jIV5?#qN?=t܈As)Py3 *_ۯ + .GĩyOzДRnNSw^g(ҺPy('dbK)Ivg(6`=̺IRYya٪aggDڑ9$I 9#*Se:0Ru=4tǓFOzA*~9d #6F$?RQ9a]^>%Y!ǏN66Most9 g\+f\^ +5)Ax)e!6m-f\+΅tj[i:WT9Mw^Nz +MgrjYd攥CL'Ft91e.ڠ3tU2LIs:Ft9l)_R5斯TS( Ȇ6>+ތITR侖 /'kH◓Lj[B VHMEdKfWEgLT:C^J,i#rWXp-iR̶d'-KMM5ry +yLŪ)\ +e6U-P~ U=WTw[ʭbW*X-60^r%UejeRJ/8N7 f0i:#ηm,u|O@lY;l+STmK۶WJ#ڶW,m*7x[ξޝ)/ks))uiy=7a!zfoع\3DBTGb6ʓsLNpbބ&4rw۱yD$JښI^늦V>[-L(ҜEHBҧ12t {ƞ&翄 +endstream +endobj +570 0 obj +<< +/Type /Page +/Parent 1 0 R +/MediaBox [ 0 0 595.275591 841.889764 ] +/Contents 569 0 R +/Resources 4 0 R +/TrimBox [ 0 0 595.275591 841.889764 ] +/BleedBox [ 0 0 595.275591 841.889764 ] +>> +endobj +571 0 obj +<< +/Filter /FlateDecode +/Length 4976 +>> +stream +x]Y$m~_Q6z`@’a衧w[k`}i 4z`|d\Y%t~ju_"Kp}'W׿H,gbT^`e%F +zAsXGgܞ!K,I+A 뢶{V&j' > +, 6J<Fi(=H<"/x.!:K' JK<YvNI<2B6$VC*%,D' :_B ApIqd\P&Ņ%JgVAVC+ Nk HX`-d1JX`"a:xX.TX MIX`0,aZ`%,@]냑vKA ܵN+ pZy,aq:Y pj%,p] ##azu `+IIIX&)'a 1h%,p]swWF5 `( Gpp`%,X PbHX: ch蔃OEGh\Cx.wI`j$,]m%pW$,] ^âHXhyyQ9% $pio" +#3hƙ⒁[Eq@|i$.@L,SW VJ\6P_cn _ +0"52cX8D}18R~4!00}k4!L EB!!bBjb]t#!ua#9'ё@k4P~ Q)aR!9D~8]#"|,PwJ<.c +sӯ&Fp/v8"Wl15cBlOvmeҥpLȔpQ`O*AfC0rZX#14O_?/.+i_~vנDC|=4Ϲ{":QoW䧼f+Wj[>Q +Tkn+i N{/C^~bSt~kdeTQp0;vy.s>2*<ܶ&3-3LP|Mix{:o'ώvaiCB6E9z#Oy6c閨q y=e^}ۖ6Y61B2& LV=6$5>2oXh-p{{.Y;GWǦm.[8n }ED#hCWT4oQWWg1!3徴;zMK|LNcWVn281žNczK-}Q\39֬mU#hy2ǃ6UӡYYjLuj¦MV,FhmSUo(G/'XZ}9]ﮖHjqF0o.ԾF*QcEWc-ɿRY6J7ڑ>SWvvzdC1X->]Y璷W[`}Mֱ&M:3Ίn<'=˖mKIPOUmL7-_YO'/ŰPon쁵dX2߰~qDx</ o.u*o#Mf>W챥0k~C?JT/W/HNG19Wŭz[-t d;q<ZĀwy[$yჺhvizxvTaszQ7K46/>! +%{t"(Q{}XGI'L9j|744O9fd;Zhw[lh~Au! ei%QB۶s:鞈It+{N'x}E4k:CTi7@[;OJVĹ bPa\NDW/ I-_4-iwZam|RݡRFf믷l9qdg`q{{}O;U&('9l3lnL9lZ:muҗONln8-tQ{"Ny:>yO#ɦD.;-7`x0E|!9_E7s)£^u +=nPlc'ƩѬn/ۼZup򐟞VnLZ;>P͗{:Fz.Yk<ĵqNkV׃Y~1]7-ksv.gԲ0%Oha>[fc+̿a|g<&uӁuszӴɏm~ݯ:ǜ6Ã6G#;Oy:k;)^}e~c2ǯ;#X}T]*?gtVyg>ml<5:bF͂@ :syZęX#Wܖۭ߰^[?٬0ǍX\K"iwػE[ u-]"kU{3!G\7چxz$wLm_qKW(^tmBrwC'CmzRcܲi; + +jK֫?ȱ6׫4t&]7rׅS7+z(Pn}8{.ӥ\U(^ +90z۳΍ wDU/~?^qsJۘ%Z*_?ZC}For%=Tk9ޓjѕLoNOBW,:qxQxbD'*V Ů0]t:ͺ5ujL}VTӮQfPS}K;~HjE;tf^ tH1]-=UYseM]]4l(>ntJn̎zA~(+ǞhY԰A +C]q +S yIӨf'o顣4]itfI t{ꮱ cnHuؒuN&kXɉ wS~ߐUzeA3sA;99.o/|#f2~j QۍqPFkG'Bq 2^r)nXodEͣ,}o-~^~q:Z2d$ɠaDN#o1 Ȯ#\NClmfubdo^mkf64xv++Ottpa #06bAJI~ǻR]쁅h 7ˋn +!`yy# W{9@ΩaD'Smy slJP/˲g{3-(&RhJpj^bl28Z=ԿpM{+]JإrђGHc$ݩnmnʚ aDjd¿5ϴ j?e%D`8j5|J!C?ĖFsV_ik%&tUQwy"3XQ{lYMzLRЀ9[ *_R˂P4Un&ʉ0:e|R~]K +endstream +endobj +572 0 obj +<< +/Type /Page +/Parent 1 0 R +/MediaBox [ 0 0 595.275591 841.889764 ] +/Contents 571 0 R +/Resources 4 0 R +/Annots [ 573 0 R ] +/TrimBox [ 0 0 595.275591 841.889764 ] +/BleedBox [ 0 0 595.275591 841.889764 ] +>> +endobj +573 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 101.433071 506.373057 101.433071 487.623057 ] +/BS << +/W 0 +>> +/Dest (cb65-1) +>> +endobj +574 0 obj +<< +/Filter /FlateDecode +/Length 4803 +>> +stream +x]ێ}VxAbr,FvzwN9DD.3fUK<<,آ +|!_0r!zg._bv_۫VF$~*/]/v  0 A3t.tRr\l7qAPL'8. $֙`ܐ\E 0LS:ۖ,~2m ! [Pi9. +7$78tBp\ezS 0.z3p\zKK,]~}0|B/$J߀d#~1ۀLZ=Lp-qZgW=j9a,G)o ٩̩*OuߦHY]uMg,BGPf=o9k2ll$߮~{9Pb\a~[Dz[ Ha))暺<ϛѸI=]I;uJ]uRF}˰ӵL9嚖wwޫlkboǕ{6;0LQ{qx0ـ& +"#s q橵z;|ђGtUt*dT4TH 'o +vݏNvg#1]ڰ:]̦1)7s:ԙMSCH鉞S7?8|#x]3ipK=*iӕ{Ps{LaQ Xӡw!QZㄢA97՞;ZtU)TB;m#X!tǿV\Pn^iHQuzWι=^ z|񌣍G9zնO&zo{>5D-}dGy۾/W+wWVJB> RB9Bl 4&Qg3Y8>k=MQ.1z,k]{\I 49NdrXn}[I0m\5rXA1փyNc1JcRDg=ͦu_[}1b;_%'as:G+wFYG_ѧ϶yc C1;磋;=l5;{R^ +>nK|: +==t=+_HݪC{_Ԟt}2mct@?Oi< 5զG~SCUO;~`(9BQJO,+Jw

    s:kx&u׾#cжӞ+m<D>=l(vv|]"Y~%[/ck}VS8yk;UIOz;3{ N{0鐸}+s"1Tt~^%"G+NGCl[{;lĽ7P<w9wݷ{?1s^YݐY0-W&=ey[ߪ^?m^=A +=o`ӡsgўlh2fzoN߻fm%7}n_`!DRO"y2s0ѫyNXWZyw6|ӃyNН,jf; FM}zE~4!BO|_/e=Nfz~C`!r|2dOGEZ߃$zud=>_z_t;1O;]󣭷(:CysWL|O]wsS~u7:좹#}i VC +mڽxee)q:<鷤_ד]v쩶qJ_5 m75/kebٻoEk>)mDtI"ӛ]]&U;(?- r:-ϯZwS0soQ:>y)z$;|zy5nE ub`OoH~mܪo9A3mJPMڼQ}nOmcۧ 3UmF?$#4~>rvؓ˰lE}q +O+. R @v56t ++9!Tӹ" $Ssq1UFZ>MdqP墉_. ?È8 edEvاԶcP売nR~[(t>]`"Kq{1IA \5źb3@CӶ[]ԂR(HuMLGssjӹ&ӦKZIwn oT{ +MJ*QeԖCL'Ft0/D)ڠ3Z:f$SŒ.l4[{Te) :Ԇgd72t+#BsK=PZ.ԑ/ԶqzTIUDK' "K'GU'B*ӮZ%ilV񼑨U1\ H[Z\Y^2&}"ݚLJ},%1ˊ*NVڧr%bkb[27;m{Iw[mbW}qdr '6ӋC]a &n4eVv>A͸/ySڪNt ?H[b(Gڌ-T֙d;s@^T1*BH {!i +f_U; +endstream +endobj +575 0 obj +<< +/Type /Page +/Parent 1 0 R +/MediaBox [ 0 0 595.275591 841.889764 ] +/Contents 574 0 R +/Resources 4 0 R +/TrimBox [ 0 0 595.275591 841.889764 ] +/BleedBox [ 0 0 595.275591 841.889764 ] +>> +endobj +576 0 obj +<< +/Filter /FlateDecode +/Length 4718 +>> +stream +x][q~_V&Y>8A L`6:/J-uX݃nUR$?~,Ԕ*N!~xQCp +-jet]`!$g_e_\{G_͐7]UCPNP%&Aq^Py=)I*5v +0æ$̰DAa٠iJ0m%AF)QCdvG{Igc2It0hj%].J: [\RZ9ⴵJK1H:[ȓu@.I.+:آҒ.RV%T q3 .)IMuQ$-^$`#e$<((VóiI`1:؂xآ(3h`^80dD&` I4`OAR:%" [-3WJV2 $. -ƒ@*i |kf* K[  (% KN $. .9o$. .%. .Y$.]"u8$qVA 42`TK\ &F%qkQAwCk2XK\ %z]P=t$.@a["qO`A%.p]1|. :Džy^IBE8.3J\ xWVjI&) x~p4 Z. *(qX$. d<(x.$q*G$q* GF5a +s BҁwK:R!I\lJ\ L>!%.IAON₠ p,Q[l(qA0 AxCl\-%. 1Y+qAp1ft-"t:H\k "& % `tJ\lTK !*81p#w_-m$c/X|/r?Y7iLx\ζ-a#BjFjtc#cMEMl3[fgb1VE[Kk# a3Dcf@׀/05/嗿v_qF)h b:*{ßlgwQO7}= +;4LW$Dz\X]N?oO&&ZZedz> WӼ5;8~ +c|\l]8ڠͪk!HˮɽmSQ\ۨ^|45iA(]jV]n/e(:$zRW.6A{]_}۫[y\lq-U+:W >H2eTzm81p;y4S> Z;P2LCP R5R—F2 ?wo2;h73.d_NS7fҗw+]!2NiR9 RAJAۍΒ +sv̸dH̘mYQ`ێ53wD(.g!+۴`ڎq66Zc(T4cyΆV^A_# +RoQ`䌑1 pYZ(gԼZŦ#uIxRZky:{?c9ӷPkuK2a`ӡf=Ϲf4,U9J^e>=TOp+#{[ثwxGϽu˝Η#3rm͏;s:>>Y_ovdo73z/]7Py0Py|rKiVOO7|F̀gdG4a,<̭IO/$4lו#n4״/crdK|1r͞zviu,wjca:rluwK6s0uYSfoU]Dxm2{k.@ʟF7u_7ߛ-Py$>\Q*ٴ;]|.VՃyN}"2 Nan(רhΩxdO=ty*niOj5beMuN+O'w;"-E7D>\|Y>"=Q۰Xo$fz{yΆ޸T}NBm> ߣDҽmX|~.nW2bǃyNTS[?k@q >%s;~흻+u|ߏyj] 4Az;O})R~==P.ܼg5.zYyΆĴ7$E9"mo0۶5J!#4=c=t=c}wyhl}Zv+OaOV9jwK3V7įQ9ZkDYg_wOforl燒-S>.j9j ۔7Jvpo?Eo(h8M`-+v>'7O]AW 陲r&Or.K}z뾶gF!mAnжNs;_|zgGrVSu>i^8hïz;u!]d2L:wn/C>9c113j7TGS._b=(fUղ. b CZ$7k3WQ|J6>˪ɰcł9^jГa|5`VӶ[]& Zb3k&]/iMvAR~sF)QUFQJ]IYqD N-QGa,@5]*"JsuBM[TzҠNv }4I#׹ccb.֙Ԯqrzr8& SfHJym+v*YN徲z@vݥCKG%gҭkͤ]uyLRN[0_٥K%MlT]ZeRhFY\fke'~EX&.eU=i~;Le"o_{rUTn%"Ӧ~ҺmU#RWU ]Nl*tgmыՑֱi xIq|Z,d_E\Ʀ$_"qIے5]F\ⲫ05ff2 Jj׳ +⺺΍Kj:ۖپ"˭/4G0> `i*}掠a,'K)_e]s(Z&oZusӦFs-h'-۔"UZJ"%bn-b/S4_vNtUZ.x[ΡN՗ԶTd^ffoj*SQ *r$D,V2ɪ˯ +6v܏#"%Vפ9JF&C]Qͻr&=B(9B2VߦJF~ \P&Oi>js +endstream +endobj +577 0 obj +<< +/Type /Page +/Parent 1 0 R +/MediaBox [ 0 0 595.275591 841.889764 ] +/Contents 576 0 R +/Resources 4 0 R +/Annots [ 578 0 R ] +/TrimBox [ 0 0 595.275591 841.889764 ] +/BleedBox [ 0 0 595.275591 841.889764 ] +>> +endobj +578 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 101.433071 713.673057 101.433071 694.923057 ] +/BS << +/W 0 +>> +/Dest (cb68-1) +>> +endobj +579 0 obj +<< +/Filter /FlateDecode +/Length 4921 +>> +stream +x][亍~_QAlv䡧f:O}ؿeKe j4zLBQ'U)~tQS +JEa_rq:?)fob]pɋ]uL9_S V`y?h|XAOb b۲"p9y11I`%a]vD$GF)As<gR6YEt4)Dxy +!$dYi!)YMQbU"ċ@;Y%J"v99'2x*Ŵ'UO6Ê$( d gYUFY#Ɣjhu[eŘDdK`dQ1H4.I`b\6NK +'`d?Vi*]jrEdIX` dA ,Y ,Z$,[oA J ĵ)8 , %,\ 씰tܣk}0Xu)HX`i%aZ"%,:NV'+aZed$,N ale2)) p$$,p]8a Z px Aڹ+#ag0 Do ;Y`X dHX:c4j) H&p5*(B80͆S$"!VкH1g%Viӏ_׿O?J!nקPal(JKrԭe[K9kNy]UMz392*mٰeTe6k=E&sdLg?OQ}v|ʷ?|skqPLM ̌CS{:LM7ns"Ӎ[YwS}-L7.A'L3+S*1ݣzl] Қ33#ֶ 1CǡI8=Xۺ+mھOy:vwy܌iC/zֹQ`36 %7ϛ\#AkS8v<'_Ly:k뎡иVղ<\YhUa߸~kz~ +0VӟxBڳT/{γY]q\;cy_vn?7k;c.7[:Ogj~V8z{guo+r!U,ԶϾt_]Y?ĕ5FJ&mv~@dă$@re}n5wsN&m] :Oy63k> +M/j3Ճ殃=? qg;/zYA&"6vmw=}O$=WM=l=:Y, scH^ MOy: =ȯ̲FeBX9:;Yz4X:fv1ffDWqx\ktMb?jjZ7e>`{qd);Yrm".qY>:>!w?<׶>3L2^1Id9k|/S)spJ+ _\UN2a&r-Ho7ʹ=eN. m3ܓN1P},6>ҽ +A6:((gBڞn[gͭ"_F7RĤDxNǖbʁ{Nvӧ24tZVA& y:tT?YI}){ا^楺դCSfAh==iYݠf=yޖդ2)g:g9es혓ur2o9fU(i-y떐˒^@j|>gOfo꬟~d'.vg,Eđ?3_i%=p[ٽ#҇Fa#k=W5ŵwVp0w=`dg[}=x([6m)l/pT]qY:͢xmIAҚ90oxX& lBЏh(bWͲ_?Sk=e5kŒ]_O&^g5ݴ0Kiseojkg ̋Y1lK(Vrr +i҆D'5|2NiES|!O#C4Oe&U!#D#B[d".Uk νh7dXZ>&Vsl9ipX f[2^Mz!w".WBF :^7+UDźdE&_/e3 o^/}qQ -Ld4$۲aDwNqc^^]u`%uCPݸ452;۠| {uptWFRlߒI\QѾ (.YK wTO;>b̍KyoJ+`E[~vwWB?yC]DmިoFx2Ֆ˰l{-7jmYlsr讅[]peԫ-+MJؔv׼% 9ѩ^I^Q]/i+m۷[]w+낄^oJ>ΐuJ՟ ѩh-RG_]bw׹+fDj阜*jFY7015UQ8)@HuSLP, v)To&R,'=VوP +endstream +endobj +580 0 obj +<< +/Type /Page +/Parent 1 0 R +/MediaBox [ 0 0 595.275591 841.889764 ] +/Contents 579 0 R +/Resources 4 0 R +/Annots [ 581 0 R ] +/TrimBox [ 0 0 595.275591 841.889764 ] +/BleedBox [ 0 0 595.275591 841.889764 ] +>> +endobj +581 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 101.433071 270.123057 101.433071 251.373057 ] +/BS << +/W 0 +>> +/Dest (cb71-1) +>> +endobj +582 0 obj +<< +/Filter /FlateDecode +/Length 4714 +>> +stream +x]ێ}gI@^ KMt7sz$6p*~l{XE9=X@pu.U +)r^!x[!#zetgf;8c[õm?vpiOX'ܛ~_`ڌJZ'ݻ5Kyt[0e,]m] +7,~۴oulu-c9CpuӃŗ^f|ms4|ho7}uW+.Ғa}>:;~)I]FL'٘p$TY6T5a-Jh^<69VB`g޹w7߽0PU=%҃tZ\`cájŻꂈ@.\oGzgwuuDjM[1ѐH{bVUe Rh~sӡ+Qzj,ǎS+G=8GlAhw/k)7fՍy~c"2$nbs5J{T2O.߃;}jOG79zo4XဢKSn*=w>BwD69BW.Eѹ#ҟguO3yh/^ozXo2q55U_I_6J3f2Уm_W=ns8ĮOm6jG5i89WOWgwis&Pdskݖp]BizCE(3xp`c.LmTr'O]'7صƕF+찠_!-ѐhW⦯$ەr[۶lU#k(̼ns8nV36xI~{wkFYy + ɧ[+_%Wxecáu?*oc&:}^Xns4ԺUJX]m_§yybЍy۾gI"[uiO+34M!Nɮ0M7<g1Mڡ柡cD̀jS}[x.;bzGtwߟٿos8ony?(,H-Ȯ^rk.z-E!m6WG~RӮ]A{69o mj9tv:.yCuw^ kC{YoơN0 iyi2{Ȍ2sL9{F?/yK;HBL`;l3KЀծOt`cw%6w7D8A70ŷǦ}?nJe"c.XJ4f۷^֞ey{yƍ1ק´Ź@Iۮjb zi~cO&^"Rw+Zo/BX5' ⽝=_/E׹zv_h NRf嚺z#oi`GV +r7`e;+q]/='jᆍLjgv1ᐼ򵌴ife29vmut?W˻VuKtisB/[Î}+ֳ=(1~#ޜ~7qyzw q%zɫWkf5ژp^~޽^_io} f7ݘp]~fQ~!tg*6!Aԇmyk-5sL]w;}if{ip o~7-:*>r9@m5 +xc0駇1LAQа꼐s8cI5J,A鐪ŘN*? r/N57p(KYFEvWzd?R8Q|7)>FD4ms"Ssq{)(NA+XmhڴqUH6B;ʦ*&ۣҩm\ۦSM7yKx9ZϬ4ʭeQcT,RS1h, jWa@2%]ĦK|Ij֘[RN4<#htx3F$SK=Z7z&)#O3m +i3Z!5q/U|OYΟJ_ib2R zU+Ic]aõ2mKy_0۶ +IH.-66M}%*1"Nۧpe+TWŶ@y"v2T\S m)]VKt ``> /fzq~ȕTe5jH+>> +endobj +584 0 obj +<< +/Filter /FlateDecode +/Length 4834 +>> +stream +x]َ$q}g7%$0$ۀ%ACOm F_Wz3$+r֨dO+#D`2K_~/bLNjSS.7 䣻 ve\{G_͔7]=N!JP)msSyA[LIR н* JI*ADAa* 4I* J+ءR("kvG{Igc2It0NK4y]t[\RZ94tl u`%]-]-@WuEy%]KH%T ^g\VI:'lZQNAK8#Άjxt[esŘ@%0% +$0!L I$`(RX4QVD>-UőjBDX[@ka!+q"qݒJZ % 3k' ,(PJXpwJ\`AA ֵ ,hRX%$. )` ,qq:Z k +xH\^C/q25Q5S Ơk2xא(Gxdw`%.|-wu'iդc8>Q&¸E+O$qb8.3J\0 xW[ԒMR8.'q0i8`~tE]TQ- 0 O*ID]$-qxRC%.]LIUZ Q'\; Dl@MQ``5F`` \ LIp[)J\&b" 8ZUy3u:$.&LZA/q~bwI& B-*`*g.4l-q<]贖 oPh"V^I\kI4#(qA$?(q V`JQ[@x$.M,sDl$.r3J\#l1H\lz3H\l'qAR~b7Y8tJI\tzӐތ$Oz^o E8MI$7NH=7p3ބG/"7.ft]x^\` VZ+ deg# +0!lĘI L,VJ (/19ԇ<0g70,}]sdv#/?}{.?ɑ  +$tqc'f&)'R3R]?,l:rc]9n\?(NXc}`xl&?!]-ښdy>VLXB݁< Am6{.mk$w/& ptbC3? J-z +ĺH*/>]@s ^vӘ8~?w?^3i{ï?S\d~kPankhѽ.SQWfmWԺ|,YtTliJ2k͞ZΗV?Tt˿|Z,2xTQ\)#R7p7їZAPFC~n'C> Ns?$d(.ңy2ϳ+]rt۽SPD=B^CˮyˏQdBn@aiAY&#_1 3zm$qȨ@h-X|#tȥ]}d2L[LY)"zՊݪD']mbn_of".Ųg۰k*7 IKܪsZ~}.w:_֌ír_nNcps|jW-iol^^?}qC* PgsPr /UU]M6XK۹ܞԹ<o9۽{/s C?3ma]*=cZ3;lf\_mO_/GZI4Lq|?Iw>fݭۦbHw6_$*#7,oƣmsynpl|{T #u8Ȗ,%xe/zcȿEOgg`KS4a7NyTgR[ PbƁQiQW/kvᶽ]~'[!k(cZ~{E2a\C/UѴu-rн,3˺{Ωi=]ѳ7@hk~dC۾M#[>bQ'+k3*gl ~#jQۧ63TFkh>#93a-Yh=zg>G.%7P|@ǧb'iQx.ӡpo>x[yDFuzYEH|i2i֯^ 3OcG+!l bj O<}чxﳀ-HsyAjr͑e7Xj~D>fϝcigu23zow}Py} v~lWβ+mu%'#gyQ^N{zGN?3|"Zg9t:y0Qm7wy!6OWoF/帅xo6y$>\Q*ln<wJѬz2ӡdDj9cv|1{|@;vFOy:<7DCsS'ѿOwDNy6ju`m)L w [ w/ ;=8gyVGu^uR=Lr@_zxm/=j=aHgq|4x9_acf$Fj>2}W~»{'U프W]U|Wݺふr̮gu.-gnt~ǩq҆_~4f8ro~7 bv(@壪eg SSZW^ƕd7*l~'\ DN|jҋߞ'\j +V i[-X[ ݽPu5bm֦MXMNw_ҚuvAvR~gs)QUf;Rv~D N Y]/ga,@.tv-S-k*-LiP6 u/ uQ|\{k;ܘ;⨎&~ v++녶+jxiKSah7U)3OBٮZ%<6xHW!4k.Bl^:*!=nM][l%횬:&Jkb>+{*F&vo+qաTľr[/5ȵ[0_<(fRIUgVY'l[Zى|lLqo\4g3|[%,}~B//œq*[ʭ+q?XēbV"æhuli]ACǍZvՈԕAuBڰ +]m2nGxZ:2_7mž/m9>ίP-Vᢿ\ƦmJvE⊓)Z2]F\ⲫ05Vf2 Jjӳw庺΍KtԦپ"w% l`}ie`Wb/#ګci%> +endobj +586 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 101.433071 536.373057 101.433071 517.623057 ] +/BS << +/W 0 +>> +/Dest (cb74-1) +>> +endobj +587 0 obj +<< +/Filter /FlateDecode +/Length 4924 +>> +stream +x]ێ$q}g`!_AKᇝm F>JKմ42HD02+S_~R1/5EX?V.N^g8M ~ 粎)`'R9;*CTO1UN1gI3|tƭUfΘ$̰.jVeav +f죠 +vh!9kSIgR6YEt4)Dty +!$lYiIa)I[MQbU`tKJv99'2t*Ŵ'UNVaEaBt峨-*#,lqt ocJj5ZybLt`%0$ + +$01N.'Ivr%LʓJ4`\Q4tFKD`l.HL`5lqX$.l ,֩%.[tpaqm +N kX.{uF ڵ. ,x:$.p]kQSXdu8*J\XFF ɤ$.p]wM uq88swWF5 h +r8[@Cghl2K$.]5 tA '#F\XI%.]8*+q> H\SK:6YI\äH\6i芺< Z2 O*ID]$-qxRC%.],qA*oQ[l2 VXV'e4fXҁwY%)qA$0I8! +6c dB>Q&{ DlqI\z6' - -$.@D0e[E8؂HQ0ٔsDèJ`Aע.A1 XK\Ԕ%.O.I\3Nₘa pES2%-%.@ $[ J\L.3( ࡱPK:h$.H.L*J\e&RЄl{ fQ[wdh$.H e$.6i%. + ⓸ 0Q,qh:$.:aiXLdOXoF -!-nIo$]-&; rL ~Hߌb3Iҁw p&"[io@>">vI(PoS + oŜILL,SpPj% [q=STp)If, 9z1Q˟.dFPJ;WX&c=oӷ8Vۦ5S- ܑi  V@ P'bl+(. ي{n2hO?_~?c>]oVioqXmr3Ųz|vr+-]}x;n234Bs6^nW;4c}L970Fg~~>-AX"1H%*_ۿ\sޅ+U(l~ZNSvNvx;˭ wYtj\2 HG j u Qo$1DTr"D2VL;Jd28!!\C/Zkw -’ ]|,+@&Zsm +ќ+{ǦJ;#\C~5vDn[I_a6mۺ^n"t[%su^186cR6hFF3a0Ӄ7mkQ;&"Ǔ^Pj51 +_!z=\]d72Z8ImH`vl:y]RxZ<yړu^yگ}kF`uE ?mH;7ʓŶcC z{A3>ĉyޙ{;zmeJP)瞫o0m~AꟸodC}gg| +u:g:ޟu0;avr{12EOy9ddR_lG!w<+@M=^r>ȥ~~z}*w>[?<j o,kaw4~-> +,uvLtsu^k㞙]{;ciGyݻGe>7ygr;:Z 9}>:!W?|_ۯm}f,\_u7Oy9Dǚ9[ѐ6 ^|g_XTFc|"p#6??7cCkH1|:/܃|LZW2EGṻgmHhS`;dO͊5v4_<NwQb/ I[G4\~1pocy FK#KJ~^l-sҶw}PC (+j#f="Yu{ s7aѾZzܾg}in'Xz($=x|N:¡)m١GaB@3! mߑ\"ƙ"js3>e\ϕq-O GCLElE(|?1 +Ɏv̬ƌ3I=Uqqc*pwIem ݹb^h,zAeuz<?'=0,琉sJ萘> =0LO{osou746O> JM.ӵkɢ>Lc CG78(};[\K0z!nQu< +=F%}|~]nPFnaAg68,r@5p]?'-tD6)&#=YenOگbճG<{:׆ehܴycӲ)kWYxJs~_.<8\G&mRWSWzXyR:M n,)zs=L#?R&gpf5$.QE Q~W*9A\$?֖-L`XNF{,OG ZφZS-{w,Q3赘^MzkdL!oޠe{X[ń~-T.6ڣ5mB6i6l: ]pjSutj2ˌMk6!͓ ]w60Mf^)p +$ZN.b5f*RWu)6d7ߍ=FbƵVƬwm%vG\|Zn'ҥtOf*|5HKQf/Cc'veåcl㥓mR6dLs5HRꚘ(OJ.TtžA}!vTj[]wsql3 .|ފcsj']lTv3&솁{ةLltld6b dtnþzrwSTpOlwW$hw:*7Ca-$@NГO #vn7]e,X=O//PWI7;#i#ҞJDg%Rhɶs8~vlddnRK*[}Wo{e!GWO3k^g:HOɄGtƖ,8ћK,5p\:#Rs%'LUQ eޡ +T}\-+!iN2A卩jsIH[EzA2R:F˜t#.'45F +endstream +endobj +588 0 obj +<< +/Type /Page +/Parent 1 0 R +/MediaBox [ 0 0 595.275591 841.889764 ] +/Contents 587 0 R +/Resources 4 0 R +/Annots [ 589 0 R ] +/TrimBox [ 0 0 595.275591 841.889764 ] +/BleedBox [ 0 0 595.275591 841.889764 ] +>> +endobj +589 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 101.433071 101.373057 101.433071 82.623057 ] +/BS << +/W 0 +>> +/Dest (cb77-1) +>> +endobj +590 0 obj +<< +/Filter /FlateDecode +/Length 4725 +>> +stream +x]Y~_,>1^ <f󐿟(Uj{cnU(?KY C;s|<}:[) ۳VF# |ʻ um;gGSҞ@*QEԌ{err)ȩ`F T0(Ux3S gTR`u0Dvpht\*:i=8o.98-6 +,l`s:[ӂt(Ndt]tQ6cX]N:%`ւI9X`S:(tN'lduj8-GADe8PA& +q0kTqsV[ Xl1p\z: -Z) -p8.G0D ]]O01xCr:A׬.@'=ޛSk!`s\]f@' >  0 A3t.tRr\l7qAPL'8. $AqA0n W 4&8.@br\X:آ EqAE qIMqAQd @ qAMe8.f j&x̸zs\ lpQXlq NzlQp\fnِ֛@g]L q\7rk{ l@z-V6d <3 _Z#Aepl*Ra?f0F<$#w_5^I6~&==.E򟄃R@Et-qa,aJ}FId#0ѿRݼZ`7IhX[fzEw'tT6vd +lx?~\{:+>a6.0=yLk-HDiݷmّyT|?&ûttZNDi4m5}c8818?,>F2NE\Pj[0 teS7O?|nhVL|xn:7.1>ɦ4P7M(nLl W'+?zɦ r!ٱYp +N[?;log!\As4o_!ywd'oC>>ꕚm'4Hs$(VO rq)KHQB^ߕ4 sTa<-cp{?2*ysY7qGF"MKσT!x pG愺3jZi6DLeŦ@ȡk& + +$SNT*!{OչNѣku&*~4bB}yZwc3_[^MhzY63|fy{pi={ע},dܬ9{ݽ>6WCXAp+%ݝ!j }ћx/;A +gq;gs7.)xsSO4±"x(ckkZ]r|oJb;FKڇQu-9a5y΃WMۍ}y >n>v#.Ն=M9t]KM]%+sٙpkOw,]iehiEՖ3Py}5jnׯuɣVO8s]ؙhUG\l 71x+HlM/x%0Nج~DK\P]4]ڍm.z'f՝y~>2S>5oq}ꯜWMV{ǕѝyލH +. Tz3K};w; nÿ\zwDl^| +C?b;B;:9tW 2WwoWݾޙp݈ ^}%!Ë٠gD-=0УmߖW{ܙpg/lV +'7^Q-s8oW. bu_+xRBw9B/W)ZxO7n(wvq?>!7?j][\{w97o$ەr3MtXꪑ5W +Bs8V 6xI~ޭmٯSXA՝yڍ/B4p(; a?&Oc%:ݙƱC#EP/P_/5y*%l㶍/\FӲ׹b;;aT.$..U[J}1ϠOpi{bzm:&$Tu-+ۯes84 bIݯsygKݮk < N4/L+>lIpV@dn|unzr]4Q{4STwnLO0&h(u㧼ZMEԶm{4m{-Ry+ޒ.mى6wRgٲn3;϶4L5UTlv.g{mq_PKDmJ#;9pML Mh> +endobj +592 0 obj +<< +/Filter /FlateDecode +/Length 4753 +>> +stream +x]َ%9}_qGKx $4, T4 gzIgR5E2tnFx Ng^}WRHz1Ooo¿buտopw(LN'[0L.Ϸ?~q:)%o N!JP)msSyA&$` dh +0Rt +f1QPEa)hU%a&I3trAPi;QJEdnptFO>&D]N#鬝| KEIG%%-N)I[ %OEMf;,um^Um]a;r:?}u5h/vkY~0L : +GݠFC.¡¢jbW7(toʣiC\1]dP2gz1ϣ+C$ۡKtŤ$&>?W oGAږWVӏݵ&&eU'Si#uR&a:y8t!^Y(X`kNzvUCRs暡}$=#l+A+ыyǁj/i#'^qGkTF*c2^ 9GaAKr{yElz1ϣ!Ǧ EgCAp,3_p>_l9uOW;gGVRf>@#u ڼ˛y-á86+Oc< < 9a[濶/嗲>t\8=eS`7qgykeo1lvv?~Z8r/3h_W^hh'{nw*V1reS`|OM 2h+6xAn Ћy'/*7#Ϣ#O"9D™{b݂.]áhOK }&ޟ_lSϫlceQI^80CqE5c>:k>Ѥ6[D`K4Ejy9.$W Nح0I%~ iLg`(-49Ptc^,Sr3)w̞zyud3*|^'5:v~Yvh0"!Ǧ[NX1.BdNxqQJk۽ wDω-*#{օZ:AЕ@Gܧ޿5/#vM3u,XqfAzd l4bC8LNp?Y'so odo-tsoN,zESmF:ޮV{!gn\ Hif[})Ճ k*x\{t|DQ)h)œ#.y8C^;?OgG.j}ˇ!/y8c=y "{ʳ^eoesꭶbC{nP[ףhx5Goc<qY-[L:u}:Og|q<8L)u~T3gOwbFgdZCI$ +rW.!~-<?vSߕL)nuQQ֣aL.HZ9$?y[\yp~1ϣ!^;$ +~Mo_sͫCϧINZ6ŷ/S6}sɯ nZ^/Crɔ5嗣=iY6loI~mdҝB%]IgNj_ʯ_],M>5#|~WhE?]$ڡ1 odO 01uZ>t|`h\i w%ÌTId[!rzsդ1oՑ7ԮqrzvVqT /M/?ah+gpU̓?heV *^;:$y@Shi;w*f{騄L5uJڹTc늺*f ++\ U15P~^Uje^wpw&;{q=էZn"|b~,4QukufH>gqmI3< gV(K4_7:rǍla*L/{ Nh&ֱu u7kjU#RWU ]a'6F3@4x2?oڄ=_8>/-Vo.c6%߻"qI۔-.#.BqUe+3}%l?]a #6i/r+$mL4~`i*}a,'Km:| ZƞAN-EN[%+"[UZ&J"%b_GKMӮDߤrˌW%[ 9֩ƒQ>wRKil[7.k5C|LU6)_;saAJU~Ne˘Ikl,Bm8^vG5;&V߄& E:WtEoI%%6eͩNP*7e"7vg +f$W +endstream +endobj +593 0 obj +<< +/Type /Page +/Parent 1 0 R +/MediaBox [ 0 0 595.275591 841.889764 ] +/Contents 592 0 R +/Resources 4 0 R +/Annots [ 594 0 R ] +/TrimBox [ 0 0 595.275591 841.889764 ] +/BleedBox [ 0 0 595.275591 841.889764 ] +>> +endobj +594 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 101.433071 371.373057 101.433071 352.623057 ] +/BS << +/W 0 +>> +/Dest (cb80-1) +>> +endobj +595 0 obj +<< +/Filter /FlateDecode +/Length 4727 +>> +stream +x]ێ}VHVy 0ym{¿1bT_oZ.I@~/']_N_y}6Ch{I4ི*B4 *kuֳ J*A`״TEafI3t^Pi;QJLFi;84tF.DEN{#Y[-A1lQiIgaJ%-H:b'IaADA` DlQNiIi10 +>,uF"%,I# +传3)El#t K>a4ItYtDAC%G @ $0좗xhHNbҰ1rEl-H ql1Lؖ t*j |J;  3ƥXJQSb{ K K%J!-`ǁt KZy ad$.@XLJX)@c$.`𮱸i 5lQ7X- X 0CgH6%X𮎘1 tN '=Z\hA;%.]LT$q>3w5at]mw7X A۠+bX.hH\YxPL" i @ƃ*qbz8D8b=P0VpVe4zXҁwQMӦ' ^NtpDpm%. + u=K\z2Fo` \  Qp [)J\&Bd[ZU93u:%.LZA/q~H0:[0T$.T4\i'[xi-qA0ޠ234֒hjI*3ݐ\E 0LS:V,~2G,qA&-7!fZoz -$. M4RD4,qeZo ")7m$֛^ȰEuNS-8 MsD :֛AXo£C!7.ft]xN\` VZ+deH+ F bnC +܋ʋ1Mk$1h3 N`ZR+1lx Srǜ|Ɉa˚&dؿ; 6F򏆃0fW&-o's"d! |$O2j-NAd$05VOYZ}*wfyCGmP49gNV\c1%lw_>< : ׿|t=s:|.ܣy_Dl&y/M}^KT'.S|\uaބLj6ӵL,\723AYԭ>~ӯ?!3l_נ.,Jon:vWPs|sx?Ԕd&.KN).~/v96Gz쏛z^g +ԋsUU~(޹wߌo/sdGs ZAUuإoj_ájõŦ^yKrv.SFӆv2Fݷ]΅ܼH^u\P|3D3o!T/x˽@Bdk!+Z+ + +:te>*2z*NӗGLN^ѳp6Fi-7f՝y:sWNJ=$n!8,s?k<gN乛Ge['w|fn82784h[ݗp-4 iM:݇@y [qB}wR=?OSFBK׻z΍܃Ao68V_ss8nUoh޿le?VD-= УmߗW+@qg!6Cˏm6jGx4v ~ JKuO-m@]_YEha޹-s8k_3W;T12wɲ|ޣ&OO{- #k+h[HܗpH܈lWmor;#º7WR6d1֝yPc-=ޭ4(mhٴk>Fy ++} 3P5QR^Ak3ݍ}y}e>˲l^u:磋[ݗp݈>|xzWq.yY<fs4۾gI"[uyO+34O!Nٮ0O7>g)Mڡ_cB͈j1Wɻ⧣;}ߝ3/؍{Dz )|#W]sAg^nE/m67Fyn] 'yɏ `o mj9tv:.\xԡ;DN7FX'-ΘFs8Loxž`32nuGS.^kN)p?Ϋ5曹?4bk/qFiSįS v9~FlVיִo=q+oajo{덏]t界+nE؏v]&i̶ol=rtyƝ1算¼ť@IۮjVb fm~cM,uU>s8nkL}{'5жў+m+(n<ѽOfw9o{Zt]wOlgֈ^(Oﳎck>)OCY*TYܤߧV w4y'o>6,<ݟuic7}Czg!2n|7{: +lW{b+h|ܙph܈yYΐ{q+&>YݮsP~u3:.좹#X}C"3Ц݊s8nCJo}Y xODS. ڤ#Sώs:'(bI +9ǃf?Tٳ*G"L\L?IGRw='R`E9,SGUbا$бN646Most~ L Btz)Nw=YaS6CX 6m-fkR. g{t:4bzt;o /'TKEsQu*2jEjs!\I]N ftf7ɺ +Ct1Dn*͖%UYcnjJ:llIQ?.@kܘr\FbRfBj-*^4=Ľ~̲tPJH4HU$"7R+wuXj;mK{_0۶JHH.-66M}%*1낺"Nۧpe+TTWŶ@e&v2T\ m)]ΗVKt[`> /ƽ8A?Jب2a5 PŕF_FqoM>A&͸?N4gȚt:ŴH[?cQ-L֙ҙa8e4B W5h(1 _sͮ*町0.Vhk6bSk45-co/]+G}S'%C5\Vᢽ\:%"q)Z6MF\ⲩ0Vff&@Osj.7"]Rqfۢl& \`j/ڂYƙ=Wd# I K+-7d)n~Y:> +endobj +597 0 obj +<< +/Filter /FlateDecode +/Length 4741 +>> +stream +x][q~_Vx} p.836<+7IfdkAnUR$?~,l}UNHz1Oۏ.j +N_NU+ +Gw6L!9Vc~qe}5SJhwWVB A9AR +* MLIR V`$ c0RvJ0M +f䂠 +vh!A^=Lu:vӒ.M{%t8M$l!zDl11XI`A$Aa ElQ^iIR$u :Cr*IM+00H>:[rIgt$x0[ ntH DA&!LE & +J4`ȧ U:%" +8X [3WHk` H\`-l1d%.`[Z$.[RIK\`paqm$qJI εN ,H=H\`y#qZ^ ޵޵9El%.;NVG+qwVAb 0p%.V&&*&` uax84AZ)#qw /q2 wA!Nv` V+q +  xW',œ[M:&/qui=.[O8.*+q> +wJ-$%qop qַI+@WԥI%.p]В"Dԅ @'?T$.]嬕wuF#q0m9 guRL!Jc%xW$.]^6%.&J\'xFiJ!x |Ru~µ ((K +$q)%.Xc$.e4oq{[q@`)&" ؏W%7S kQAhR%.^j'v$.i $؂"q)xN8ӅNk -%.&bXDWK:RόD`` u4!qƇ7Nl~6GH o71&7Ix|$'v%.CIG7 I\y(qA +Mlyf lqpQDlӔy N~$ɰmpfrhQ/ +ceh|V-%{;(i1=rUKZT_9])8mNu/liy~gy-3,kY/6zJ[yS=cvkFk[^nH_ڹ +amhVs'[i/-cshɖAQGx~SmQ]ssÞe<[c^xO({-*pMBbK46a ^rctE{r;?%1rgϤX]a|;=D_^'P8b~eO;Rvz9dw<8A (78[y[m?eǦKei~?ZOrV<@<>G{FǕ칼SA3T'uho|uh2"Ryt:C/=o9v8kEiŃQdl]x,.jmU^;huqqJ*Up'<Zk*1MVQYBr}d5hR/eզ3uI5riWu5~[}s3}%%7LG=PK9ws#Ϲf4=UdOeZ9ut :F[|:3#w+<ߧG K~ؽqm8 u03Fׯ<\wP?dC}?-b[vL󷶲*wh=̷-WXwv1\C}C ܫo[ѥAOwc:PoEWu s7>s{}ÝfvJ͏kQdC}_MW],y3;8\xn9x#e^$kú苠<έO/mʑb7G[ڧŖps=wAhY|h +{x7q6|iʎunZv^<^N;?g6wP5D,"%syp:yͣa|ܵ_Dڄ!; p:VqM|z_.#m}c >8D"dGCb%O<]!-|޽]qmtg[ ҝ͝vQ7]| uT<}"2+Nan(hΩxd3z2á੸U)?{#7{[}GdCnKQ]t#_W櫭0g鉎ֆdž̝|'AoM{y 6+lxڤ{ڰFʷ\^[v<続z|Qy8wn6 bw~3W;b!Ng<BFS2|#o{vHrwٟ7m]?kD9aW2 a ZN?LnUHo;_kk}[nph ]9v+86pWa/n{qU&> +AhK{˝8wM;A|oanTkMrI>%>^J~jdhCD{wm OVx]^>i!]8Ǩ,:L:w̿ZSKU~@|e)hχ0CUGS/‡Γ &'9YX>Vv0TaJM|G|p~WaؘzŘ+V̭W.b>?N\f +Vф@{CjP uj^[.l]iMvAv-}|\x-QMfR qD Nբ è񡫳0V QKj:AtJiThbϚjwS:ml/n kd#֏K1Z7f#]ůԮsrz6qT/]ʞ SJ +פ<)>v_Jxn6FoCRh +=]:ٱtTBz&ݖB:t $c) uMVq(TTŮAu!v6Ujy=ݵr7|š3Ux  X+bj+0Bw}:[;ԏ}I+K^uOV4.tz뼎4n]Ǖ@%Ta6@]cO*:nԳN5n vއ4mqwU/6G[Ǧ/󥭍㓵j.2vKu(W/В2b,C[09VҺq(,5\ n_ڮ̎EWYnŐ./ƂI=^> +endobj +599 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 101.433071 627.273057 101.433071 608.523057 ] +/BS << +/W 0 +>> +/Dest (cb83-1) +>> +endobj +600 0 obj +<< +/Filter /FlateDecode +/Length 4916 +>> +stream +x]M丑ȳ, ƎS9]65 HPJY]ng)I!S_~'9=cpۏ.j^O(oW\!T`71\.g.6j$rv)FQHi+b4>' 1gI5|tmEj$Θ$԰.jeavj +zh("9kSу$3z +),"d:If^K<|d$k$.Φ(t*Q]LVEb`,t(.*(-ɲ|NΉ J1meF'k$zeXQ.A,ʠH2 ]~$xۘZ nd(.|L.*&%LI$`\rIbb 'rx* X] X ]V(.6; . q8+q:E u*k ,)$. \$.`\r,qZp%.`]냑vKA ޵N+ xZe8Yk8.:A`e2)) x$$.p]8a Z xx Aڹ+#qgQ7x. X Cfl2pK$.] kl5锃OIGX\XCx.6*+q> ;wN-d%qo qI+@WI$.]ВD @'?T%.]孕 w#ʠMF5a +k Bw K2R1K\mJ\"$q BrS1H\ .( QDtqI\z6' . .p$.G0e [  "SL6c$ fJt-d:J\k KM ^DP2$.`H\hJ$Nt!Zd A I2;4bIZ9Eqf 0(q "M0(. 0?l{  D#ʠNₔ IₔQF`(qAVYd @)%qA q`]R$.V!D'lśQ젋"ʠ ,[pM$ d'qA$q ěŔ@x3`&Iޅg$.MxRl@>?"$f coS +܋*9IL@MD)Ylj% pœ})8D) 3wb^Tcc.( ɘn[c6I?EC(6D]I Z\n$?s~XiIuF\(n|0Q!(F|`h*?P!_-Mm%p5S=}E%*S`/xm(c!Mp}* +c |BUtK-Z vԇ~d~z(ʷh?~NuXopkp7CKWoK[䵣OMX^w,vEWz.EVu.~QNgշ~>XB:vɹk%G@6绐_զCsm`4P =.,C<Փm po g-~W^zm6tX,|sm>>``ig43aenc5ե9t4{xy?4ʶ:o˜3IٶJ>εy:w<_=^;Vgv] 2aP_6mGqLU>(:a5u6U`RF6O~h:6&0$U>Ÿ cʓE!0cC x9smZ;'; 629(:zeJPM=suo0;}~bu1tllt Y(~Pۜrn:H٣oErݸ3}d=yI}Cޖy$+@ލ^lt>ȥ8*o>;|ӓm՟YhZ}g3_ү '8mcfLTz_83H;?j6y7}7Oy:Me158fyڞ|A{4t|Cx_}0N2~$m"ϵy:D5?r{!mA:|gjlWlthdgCn8ȇ>o\^Fwц'ܼ6$߻' 橼 S-./:P[,l'-blxaM:"u=9RG9_ohmni\d٥Mћ{z~ntuhYt,[2n]? ]{vwosrm_Ijj[EiLf>\f 7qF:3[:r]ӛi'KI~2ye/e=T4fޛDɠ Y{dgɗ/)-sf/uӂvr-`yetQ9̏g:iVoÚޱ{m0[mɶRwe6تu{ü3&e;%5i=^;iZ6Io|'ԩ>ρ1eitGDk;G.$?[).K\8]|#曾!Xr@k[}kݽatpJKW^ ~\DGzڥrg>G}ǜIC28B|;Z;[Cay: QQk75gy VYrpctENڃw踷d#sVsҶN@ee^9m&0: +ہd_}8I}}l{W^DKmz򼵯RvGVؙ@+.--7?7Sn9_.zږsAb5V9X9[]KcQE:Q\aCX|!S<~s*[/k \nZ\Ũ 0Qw|m'YtO_ǰ.!9*Ikpe+$::]IN?Z7v(:ěp-/? !%/R cۅ] A1.Uhe7fX=A<ڌNzEo,ebRLP&\ +;wxaoxXb~[zqUM'7Ӆ^Tlk]t+]p[;t.~ZרVfRZMk$.B7v0MfN Skr'.b7f*Z7]uᅲEF:@mUb1Ż{G\|/VTK/OXfg𭔘|ЮAWW&6[H<4q.3aK'%'mVd<T#unkDa>+yJv7(-U͂fp^wf\aM/|-͍Toҋj]+슁zqѷR\Wkcr0/2iǽ]r)ۜP2# hCOok6)?eD +endstream +endobj +601 0 obj +<< +/Type /Page +/Parent 1 0 R +/MediaBox [ 0 0 595.275591 841.889764 ] +/Contents 600 0 R +/Resources 4 0 R +/Annots [ 602 0 R ] +/TrimBox [ 0 0 595.275591 841.889764 ] +/BleedBox [ 0 0 595.275591 841.889764 ] +>> +endobj +602 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 101.433071 180.123057 101.433071 161.373057 ] +/BS << +/W 0 +>> +/Dest (cb86-1) +>> +endobj +603 0 obj +<< +/Filter /FlateDecode +/Length 4786 +>> +stream +x]ێ}VH@Y <I\H}F fT#qjL-$%qop qA+@WԥA%.p]В"Dԅ@?T$.]$.]e:BH\: [aLYSH:aIU*$ 'R3R[6_2=VOzx@i>/&(2&b:wfyCGm=P29 @@&Wb1l;˿?Oчs_~_ ׿p` +>a;e6S#>7fҗO[]ϓNvŨФL~cZF{T|N0|x S;LFh^ey ^&jo vǦ+}e7?oi#yõUWX| 3vW&kuג.1elMzTG϶1NqZ)Vl)w[g]=}"Mۋy >f}uW+.g o{X9Nfž􀗳3u<=г~:WP"Z{&ys8TmD~`޹wߌoT{+{[ayJ]>貭P`H^n?ǓhYi/w9oaf?5tKR>]2~ͧ՛S9nlҡ`'>\Q*=ٴ]ڍe~W~# 7f՝y~~"2dn(yhUT|js8n"M9V84s_C w;860?l-jw9j7?^ĭUrܖu>/'+{ 3MI"[uyOJC-5ͮK>,>;x:&Ԍ^yúx.;bhsFc?빳egOߙp ~PcYTZ㑇z)容(shBiXJ<6Fyn%֮ z^A{v9mCl=qa)Rb㰬y% we1:iw4oM=<+ ,+ֹQu?effr6܍~^vHl86oj:o:ͺ5u-j|f)QUF̨Tbk? I~JYeWa,@5]*$JsBM[TZҠN6 h|p7#׹(}"ÍY/'gHl◓ Bj׸B=.$VnGҤً~,|S*\fh[!OikW<6xH\+X --k.B,o/>nM][l&eM!2IUuE]g ++S U15P~UT56šGU{k Ex'6ۋ3c] a &n42h씏/_ f8r&'O^>i_'{c9:UTnL;"Æ e:0-j^Rʠjе6dbSk4q7#ھi͡ʇpoMgV$r6Ck ˈ ^(.YY633WR>oyWP]07"_R6l .0 ^ռ4G0~Ledi*}zcYZ OxuΡs(P-أ䴡\ ;eزM ٬2QTLY-14xQlP}&R^񋴹2Uo8C;RV_2 +2sWm)Ȗuye=۰> +endobj +605 0 obj +<< +/Filter /FlateDecode +/Length 4778 +>> +stream +x]Y$9~_QH}HVHKZ1bAiEZxWfF;N*#|ß?luBh1oo/]N_N1UISGw&r1囟]5ϣZr$5"cT * rNgT^ 41%N3\ڮUfVȨ"06(V% +fRv(-%!Zri%|L: +#|)NENgaKRq:[Vr:bM duE`8]-I.+:"T.R%d q N)M0I>0: [tgtXp:3!FfjFl:XV[h[d` %t&m9mX@$l>TiY1Qb:bh؂[5Z8.0[+oT…5[ (PJpwr\`@5k h9.0]cwANV[` ¨h8.]dw14Uz cXr\`:` +`uA`  ,xW;4Iqj=H6B,ӆ&4 xW%L̘[ wUD$TǙq / }w1Q x9. ̨U35*$q\8oBI@%!S8.hIs\YX&auAHC9.]Lޕ ˵+N HOy}Pظ1Ew[+eJ-ʨz9}b)T_=]ҪE ,YW̫ J/i)h,){`]Ӵzt|_z#*Ó6U4ϞhŊiL f%zCkxsyvcT=N kdTYtK.G=%Z4oMtsyui-ë; G<#B39~.?GژM-f6F=>DkYN|X=0ÃCHۼ:*y.!r?|"iq y9SÀ.5f:s.8?[=[m ^|<+ʓy z?\zpƁfP4QJOE.cZέĕiU|Zm*(˜+2m,Pm/is_lOȘi+jnL7ؤt1w+iR6x_ڏ `&?]uXB+)7~mٶXmhm'igs>p6[/(F~c 2ݮ?e\۔Y1nӲqYsmߛg +m?ִk| omO:؛ʍqAgg9H}!r9e=Cyϵzk9>8K=O:v~7vQcEd.^حch`9`'2mmA,p4[:آB^TG;aSyd۸K})m9 +\0Fetm=Me|嗯,{Hl( P!1MtF`mXЊ\ jQ +zF;w#dC!mopuUѕ{B YͲZe.A_E}{]4hs٧P{I+C5'<R0 -M׼e7xkvyP΍@Zn~IFMwz2áٍ*Ybq8m#}郋'<j>.nV5<Ѵq+d[mTfynUƛi(Í]ѳ7!Sqgymg嫷@W3#1:g T"2ncQ#=3cG+!l Ǖ-GGOy8Ǣw^EwE{[^<~"^ƤA3>yWtGIZ{>b(cS98_|;nini:6J+[·v)rco_iM;y_kx諻Owުϴca: }-]l wK6(dC~z4@հuyU`g޹wߌod_@Cꑒ)tѾ<*%«{y=ON;7qo5(~]ޛzamDrx Sa/\U>1(^nUU);sZ\ʏub+icwe>MSivP_3_^Wv W/tx8\ʯ{fSa܆U}wx*U(_D!]}|Qj73v^ińNj^=r#?5Zfq_.pˈ폗IXVUi*@H˔ YGZ(Uj6z53*fZLB1y= +S|36a/Ўi{=X9Z(Xj7u6.lSC״: ݹ']PYJ_X)UeԤlb[?1ۅ~!kC[3'a@-]¦+S=ktnc_0F_bznJx8Fb\\`RUB3QvtiUUF'pMJ̓( E WM0[Aj'(Q?7e" 0CAo?]f'/ +endstream +endobj +606 0 obj +<< +/Type /Page +/Parent 1 0 R +/MediaBox [ 0 0 595.275591 841.889764 ] +/Contents 605 0 R +/Resources 4 0 R +/Annots [ 607 0 R ] +/TrimBox [ 0 0 595.275591 841.889764 ] +/BleedBox [ 0 0 595.275591 841.889764 ] +>> +endobj +607 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 101.433071 461.373057 101.433071 442.623057 ] +/BS << +/W 0 +>> +/Dest (cb89-1) +>> +endobj +608 0 obj +<< +/Filter /FlateDecode +/Length 4675 +>> +stream +x]Ms$@C^ v{=6q; C%.CIG727֛X 6 qA!DuAS-8 M$+qA>73DD/b^o1]u $L8zW ^ʘWQ(PoS + oĜ54XYF/f VJL(/1k<3c0-,hh5?wOwchci +$ CqA&;LRBHlDHH ZnH09xz3z*h֣ % C\ޝɊk2/Ɲp 0ztJ9'munTRe?8LG r@͙|a~^[y[FOL}KW]SҖ~q:XwRveci}q9 +5en}U^rXހ\n8FH0T8]ːꇳ ˨ۀDf-SY{s.O5tZa^ϩ9oNӕk0s{iY ݜ/@Dkn`wg]Yz C91ՑLr>r9}Rʼz!GajokR{較y:zT]snz 'lf?l[Ao 2edbu髠¢ 5G +oYX>dr У lߖW +b|_~ibbTq(Yh(6qm"J C">H"Ũ6!k~ ڗƫGvj +L#x}ZyX;i7pOny|L4;JMnp~ I7@m9'1(zs(%k*BȰs8˱V 2$U?ΛVsHAF-=[Yh1苲oS^A+˙F:Cx_1:zvkP|B:CF~ë5J۲X§esbaCw9nǞ/J&Iʀnա#ݯhм\4O̻2.ȋŧ2i^ 5#m!+9T@t9t_Qǡe[SE:GCݗ ]F)#Fx<4JA-zhZ^(a\ 08!PO+H~`/:CCl=qaiRb";6IfxNZ֝1i;s8LoDž_:3 +nuGܵS5kN)p \UF}<#a8Fv%z~2~yuߍܬY?*:]%"{[;Wφ“mxF!}s #2 s4$|-u#ʼn#ye29vkut?W-[6e;owGzƨ瞋o0+m n[Yp'wd+G9~k|mޝ0k+fs Xtg!s#zɫ얹g%3@XM=^s8oR~xw\^k?<s4,kj; +fE- |;~޲_3{sgV>Gp_y7x:Cwe19حtǵMnhCԿڿ_8Y? dqoHs8Dގ5_s,Q֏ ^YϿy>ϳv{ޗ3]yq:GCcyYzjrǮW|O]w#nfv\Eswgwؐ 9;;?'ʭ]T5>O\M.6(赬;'?/6S7x 4mT&}Usuבh:+{i,`O';4:ftl/J|ίS6zD4?'MS~d~ϻSsOS_\)?;eَOc_~9=7844i=>f nZ>l<zi׆&(&m +Tɛp}X8eT)]]a U}۠^7^>,7xaqNmMfm8v \b~]YAlm,>ږՕoԗ$WF͈\h\\ߕj)VB4>zbA^/ՠ'q~cXh:-/l7ŚP50Q7a5wf_ʚri>T]QJ])YqD D-٨=\rDXnjՑ +TlUSfJ:œiȯ@dsDQ8<eUd1 lM|rA(W(WDžڭ^4o9~,*\f?h[!wюIܬy'qc6ttTBLtuT$Uc.uU)OJ.T]Ltud^3nʝ\joma/c8C?4Q۵1a3 čFGqƧSN$dbSk4q7k ұizHpʯ )V_cQsg$rҡUo섩Y633v}|.vˆ|HMgMxB`aI臧׋}2ٗګKei%> +endobj +610 0 obj +<< +/Filter /FlateDecode +/Length 4740 +>> +stream +x][q~_Vx} p.A9glyWoRZɸ{sUKXRSc +ΗO?¿bqտopg(LN'G0L[]N鿗yL)y/XEv +1UJi+B0 *'41%I3\ Cת3(E'`Uת3L$`N.*`6J:tM%ѓ$QH:k'H;-wQlqIiI`DJ1H:[JtNt]Q啖tN.E"QS1kQnrZ%鴞iEfAg`W.:2O8bfmՒc:؂xآ(3hb^80Q2$vHQbD!XLr$JCgDVG^ba a:bI\` lA -lK@tK*i ,X.TX0$.\@)I\`)qb ,X:o$.]KK\`"-`h%. *H\@]L##qFudbTxDEx,.LV&H+7x8e$. !%.P&.(lJ\:c%.@a["qO`I%.p]1|.M:Džy^IBe%.p]g?aE58X%xW$.p] Nap$.6i芺4 Z2`T0HZJ\Xޓx"=h$._0Nʀ)$xWi*˦>D `/H\#M)/qO +:|Ove:B$.c=%k #-n` "SL6D$qAp1ft-"t:H\MXKM^0:M[0U$.R4E\i'[xi-qA4ޠD2+4jIGQH~bWQL4&$.fI\6:bI\f Fbf )O₤nq蔒 ! 0/y%.HVa-0o $-.-p0oIo$-&{oF f` ^ Do1\u $L~W ^;(F amC +܋*1=4YF/F B6P_ct si Qy!`͌0-}sdv#˟N~{^#eG|X}2 ry&m [FԍԠtc#cMA/Ml3[FzU+E[ཌྷb6JF%޵#y|]/^pƱ=9稱?؄< ӯͿ(*_|vس;(y۱rycZEqVf(cY.\]N,/&&笳9zZe}1=^nki^u9ok. 6!]mk!HɽMjr)uϖ&mt \E5737V]14^ΟC. u]˾˿[>/6vj.us^koSngHCʿB vo̜1NYuS6Nڂ_o8q#tvoֈB`h6_hdagJ|\Ziںf/|eI$;3ehk lVL%[*lg,d~Dc2\Dqᰵ={Mc&xiIiQ23rn}+e^Z1P8b~eO;Rzlx'{:vq/Q=OIb7BX +-ޮ܋MbK[a +kh/dƋLv1H<7H%+,0xsy}nqz՘0ra$ڌLTkfDlRKy fz(˓[N? 9mk6,fN_4bЫ +oߜr&`'E/M\|09l߸,ZRq(.xSi\ +T.@JmRڱY Cʱ>YZ_9ջj߂vf`FU+*3y6T~=b[vL󷶲*uh=кgރ{, v1nXCmCtnշЭ̸BOwco:P9X땼^ԒSj7ifaݯ\>G9|*+ +hgl=wy+o-?\`KW|/ڰky&IqSVۗ$[|uH#-\ߘjbK|9r͞;?h!hQ|tac?"m1>Ҏ;Sf.ݒ5?tƟ3 T -=q0ӡj' +W杻GFk~w; TuO<gC8PvU*>PzǑpg[ǓhQ$tHX':_B3Z﫺yzft)^{S +vн1ćJ;J +ˠQ~oU=Pw0"_̊S~~1k|hΩxd=лT*ҔR==^t?Bl;*-E7@W[aXϘ! OWñ IvY>W3.@LdO剟2I~Zc#l!SOOێcݷ>dr]>f-}OW>2ÕxO9: ʯG ,NL~nհt,aϓWX/9{|~qTt&;V7rR)>̟r8^?M[6TGS/oY!AL bE&l 6LiҺI=l,R5 BZ̭W.b~SMl> {4bm tB5Tņ=O6o]绰>v5a[ ڵM1jQwj2;Քm@ wM̦FOZT ILWJsmBK{T{ҡncxAHzk#֏K1Z7Jx99j3N.] +*Fm:^#~'L*3*\2~+N徱I=)CwfQ t[c eF50[q%7Ńb>& +۴b{ZWqc]ub)ucPݴ>ĦAh;!z92`ϗ6lUu/H\qҾCKfȈP\nLXIzơ\p1|i2;]eCv &=VF?<=d_gK7(m ci#?˾m +endstream +endobj +611 0 obj +<< +/Type /Page +/Parent 1 0 R +/MediaBox [ 0 0 595.275591 841.889764 ] +/Contents 610 0 R +/Resources 4 0 R +/Annots [ 612 0 R ] +/TrimBox [ 0 0 595.275591 841.889764 ] +/BleedBox [ 0 0 595.275591 841.889764 ] +>> +endobj +612 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 101.433071 713.673057 101.433071 694.923057 ] +/BS << +/W 0 +>> +/Dest (cb92-1) +>> +endobj +613 0 obj +<< +/Filter /FlateDecode +/Length 4918 +>> +stream +x]Y$q~_Q6}`@aavZk`}Lȣ{ZN3#xY,}WNR?~)zꦰZ8yC`71_oo_ouL9o_S V`y?h|XAOb b۲"p9y11I`%a]vD$GF)As<gR6YEt4)Dxy +!$dYi!)YMQbU"ċ@;Y%J"v99'2x*Ŵ'UO6Ê$( d gYUFY#Ɣjhu[eŘDdK`dQ1H4.I`b\6NK +'`d?Vi*]jrEdIX` dA ,Y ,Z$,[oA J ĵ)8 , %,\ 씰tܣk}0Xu)HX`i%aZ"%,:NV'+aZed$,N ale2)) p$$,p]8a Z px Aڹ+#ag0 Do ;Y`X dHX:c4j) 2j&UgNU\EMKŮ˹.g^z,Ӻ:yui,&SLqq ˆڲAXNlldTeLRdRtmA6_z VX A7YR"-uV +72YbOZV`L Ŀ2U_;lߎ<%C,Қ=33;{XX:Vft7C.( x~Kv[w4Mw:Og'Ӟ^s?"\7mKH94{f팲pv'K}dӭk/qG헹MFܙ^t{Kw-DZHVo:vZ Jkc?\JJ89zq^OК>C0ouO։5^lh}1wتq)f'`Z>lwo}ZoO}wB;R{Oz__bc_v%:Yۉ>wtp+f(tyZ{l<{ +dV8z{gu+r!U,ԶϾ,uzPVy6AG;;<%ikSoQЬ,o-b|f>>xcE!0c%>.x^r\6gzγY=a?`݉n.XdسXmo/PNʭ{}76ou1Mں™u^ty^YVP9S=Xn:H٘H?|ƩϽcE/y:<ɤ>YDfڮSܷD? +w[pG/g.y: >ɥ-ݱyU^y|:f$ }lΌcә_t|쿶r3Q:7ǛMivWG |wqӿ7y:;Meckqqĵ=M Vw|Rmat׵8F,I3V,r읎fi ՕxgyVq\ϙW^lOr~v6oyϏVo6q Y9գRj^do1B{q- Uc7>c?ˇ^t{}&q{EE8ys,}4.L`e= >iND[T-Ů?Z1 ߤ#\ӛ_( =6s[.Cڙi,MQXgDIv|~"GksUU=GWG4Sl#LW䅿yյMX$a% [:j.Ii"im;ҧm;e UHP},Hfm$ Yh{:I䕓w>`u+b/[Ɵm,852/ln+Twά,L[f|ek4Lj2ǾD]Vkd +llU뽖oav湎aF Etf6:(RǕֲou={dݖ/sAr^HŎ-׵nay7e(F=9ٜs +歮ҿˬ]l}oEUvYwaccV]=խ/7_eY:˚҇sI1O7c#)l6Uwu9kutQ}ܭF9'ҝ܂yv;aRNq:Օ?n<(_jcӡg!as&.S rhz$q:zg>t;4OAu!GƤa= 4- k@cnI:&2ӁlCee^ֺG})tΓ Gا>I)%W|w5סF ᡂpX-u;o7yt [냅C|9jpسw?Uy;Rsv:~Hi2jWu UqrS>E=t8 GEm9I/(vS"']5=W箇cCtM6ÑN/?,OK.kvLU^/G~VUTXĒgi y==*BmȃɳnO_ǰnɫ +A6t4=>NK:]INrOrƽco|vL7MyF5/ +} +qe6rR^:> 0_aiVfHP\hLN$wZV:NҀve16I t[馱cH5XuF&iXɉ +:7S~]-UZgA3sN ;_99tllecs#L?N:٨ P\WkCr r>nmXo(ҹ2_>nTC ӰuE;}FHڨĶl8S/5}׮WWkIT7.'CF6tL3oaϷytk +7|8Mg|gM⎊-\gXEFq:]dz񩠔ans}MWZ+ްӼӼG}9@ʩm`Dm'Sm ۶ؒ keڳKnumQSSWiNF4UiXe +K2$j)6S54%z>+aSڭ;^ls<7GzK&xFumnwml gz5).{ڙ YT)بe* q5%ys\6#Rs%'LUQӷ"Mtr!MB*Üd `IH"}%7їDכ(W +endstream +endobj +614 0 obj +<< +/Type /Page +/Parent 1 0 R +/MediaBox [ 0 0 595.275591 841.889764 ] +/Contents 613 0 R +/Resources 4 0 R +/Annots [ 615 0 R ] +/TrimBox [ 0 0 595.275591 841.889764 ] +/BleedBox [ 0 0 595.275591 841.889764 ] +>> +endobj +615 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 101.433071 221.373057 101.433071 202.623057 ] +/BS << +/W 0 +>> +/Dest (cb95-1) +>> +endobj +616 0 obj +<< +/Filter /FlateDecode +/Length 4786 +>> +stream +x]ێ}VH@Y <I\H}F fT#qjL-$%qop qA+@WԥA%.p]В"Dԅ@?T$.]$.]e:BH\: [aLYSH:aIU*$ 'R3R[6_2=VOzx@i>/&(2&b:wfyCGm=P29 @@&Wb1l;˿?Oчs_~_ ׿p` +>a;e6S#>7fҗO[]ϓNvŨФL~cZF{T|N0|x S;LFh^ey ^&jo vǦ+}e7?oi#yõUWX| 3vW&kuג.1elMzTG϶1NqZ)Vl)w[g]=}"Mۋy >f}uW+.g o{X9Nfž􀗳3u<=г~:WP"Z{&ys8TmD~`޹wߌoT{+{[ayJ]>貭P`H^n?ǓhYi/w9oaf?5tKR>]2~ͧ՛S9nlҡ`'>\Q*=ٴ]ڍe~W~# 7f՝y~~"2dn(yhUT|js8n"M9V84s_C w;860?l-jw9j7?^ĭUrܖu>/'+{ 3MI"[uyOJC-5ͮK>,>;x:&Ԍ^yúx.;bhsFc?빳egOߙp ~PcYTZ㑇z)容(shBiXJ<6Fyn%֮ z^A{v9mCl=qa)Rb㰬y% we1:iw4oM=<+ ,+ֹQu?effr6܍~^vHl86oj:o:ͺ5u-j|f)QUF̨Tbk? I~JYeWa,@5]*$JsBM[TZҠN6 h|p7#׹(}"ÍY/'gHl◓ Bj׸B=.$VnGҤً~,|S*\fh[!OikW<6xH\+X --k.B,o/>nM][l&eM!2IUuE]g ++S U15P~UT56šGU{k Ex'6ۋ3c] a &n42h씏/_ f8r&'O^>i_'{c9:UTnL;"Æ e:0-j^Rʠjе6dbSk4q7#ھi͡ʇpoMgV$r6Ck ˈ ^(.YY633WR>oyWP]07"_R6l .0 ^ռ4G0~Ledi*}zcYZ OxuΡs(P-أ䴡\ ;eزM ٬2QTLY-14xQlP}&R^񋴹2Uo8C;RV_2 +2sWm)Ȗuye=۰> +endobj +618 0 obj +<< +/Filter /FlateDecode +/Length 4751 +>> +stream +x]ێ$q}gK~ =H0 ȖAˆm F:-QYj=UK0xxd2UU"޾|"89"J J>w$0At׷ .o?uu"%[RY#B A:F0*DyF@ST0V`Mq*a* c2[U:(˩`J.0*%aR:"5)'<9VǤ Щ91tIx]t$s)k%-I:/p8.buqkL [ [2p\@$]]X؂H0Z XkET +0+ p[0T8.T$FdlAq"] j؂hエ#V^r\kIYIqA^Pq V`JV[@h8.M,sXl1r\f Fآؤf I؂$08tRr\TzS[ 0.i9.HFb%3n $ [BV[4%f܂;q:[t$i9.@&"zvK z3]Ls\ 7rk{ u쎁:̭얁b +잁4XYF`ZRIv@ ',O "okIO`.?;eG!@ȩ-+ ѷBbf`CڐY +DX,Lxȍ?DzT ɥ[,"4Kv[shr@Lm|4;8<o+&T,b}GL09jwo?"(||ZW>˵+N 0'<ӾvQ]l\ҘMvL'R\߁M9jkKNQY|3~_?AWS_RаsY~ O;Py5MGϥ<lw9MnqB\"꧛;!0{jGM3Z4滼<[47cw@yEF1W|sޛ]~1oZ +5̈́6FĽҾDkYN|[F!lm^vG<k~do4Ը !v]2KwtbΜSgl;q:znͨѨWlhq&D͠h2S1X-Vʴ&>6eLB[=6gl~ ;1G=鐻O>25nzf.ă?,=-3kCB'&A)GÅ +~_ 3sUՍ%=smr{3R2Ӑ+s3JїζZ9k-?jFWg|z˲V!M6 --׹ū%vhEuzKJ|i_}SCfK;L]Gln*m9kisn1޳CALFX'5jS򽶕챡ɷoGeuץlRC҇u+o`sCen믣6vW:\)s?4жwj8c;~?eWKu\_AX`}g~zvf? 6޲]{2?~cm5T8!ɷ/n^ʣ&oًGt/i2[ƥV_NVZ];l %jL(7pMgg9H}Ρʼ,2! 뼹㡯]zky<8K=O:v~qQcE>6]*[Dgx6o[C + ͽ`oLQO}B`*;84q*ϓ,]yOۯr#ٛ1:%6TMxa5}xS ^ AII.5Ue:^'c;L[Z?ðEz|IV~sekKPfCڳVOV2GGlNy#bJAJiY7>|;2b\xYofo#o8BkЍЏ"ɨT.ZOy:]^wfu۾*~jt=ttqͲ}Ï/Oct#"΍oӦK_ֽ>rNH 㭵pqF'oOlqdC~U#zLzawo"u03OuwP8dgCe܏3>yofynji'd?xp.ӡ |_a]n?2ψ{OtgcωܲsM;vJnY|t:C_=~EQ}|unʡZvܙ#;yQQN􎞥;쿃aG#'<vμp~~7wxCꑒ*tѾ<φ*%«Gy#Q<7qo5(E)8ڈ~R$p_/>1(^nUU)^\y3g+eԎV|Gd"8'Ǽ혵[p<_55N nT~[Q(MSz+C4VnRٱ&g~ -Uy/Wk +s7%(zG.#yE][89|,+Uv Y\(Uj6z5o7[*fVLB1= +S|36a/Ўi{=X9V(Xjv6.lSC״: ݹ']Po\ղ`TjRWShl0V ٖ.tvaӕ\RŞ5UwS:MlgdA@Xb#ԯk1=wZ7z#]m#..0] +*Fm(;^4* *7 U&%_m^ &^;i:󀲡ܥBhIOR7yH<"FkjkbƕPV#P]巕PuUwb߸m^ m[,&ZIkf^ 솁[)g|탌qo?_47p>FYH^[_Z6Ѝ[Wq&OcTa6PہXŞU4y\끯m.;ה1jQn q;оrijYzk +csp):+Jڧth2b,C[29V\O۱+ 5\ a]}܊! B`3^[5VV0F{x~/&:HڨIFikIR/9&?SoP+ cϴ ZňA{*[UZ'F*k%j/٪[r#b.i7Js{oRukђizdObImOil[]]g =2=ۤ|g,y].U;!*Pc*m{p? lFγW{%cMaA_Mx"+_%610[Af'(?7e"E0CAo?d6'oK[ +endstream +endobj +619 0 obj +<< +/Type /Page +/Parent 1 0 R +/MediaBox [ 0 0 595.275591 841.889764 ] +/Contents 618 0 R +/Resources 4 0 R +/Annots [ 620 0 R ] +/TrimBox [ 0 0 595.275591 841.889764 ] +/BleedBox [ 0 0 595.275591 841.889764 ] +>> +endobj +620 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 101.433071 461.373057 101.433071 442.623057 ] +/BS << +/W 0 +>> +/Dest (cb98-1) +>> +endobj +621 0 obj +<< +/Filter /FlateDecode +/Length 4848 +>> +stream +x]M丑ȳI?Ç50 c]65{ؿL Q2\OS$$_C>+|hc +ޞ/?~<)8JEQZ09|t3NpɋߖuL)y_b $B0 *'t1%I3\ƮUf֘(" 4U f: (%`nt/錞|L&FM>XKEIgaKJK:[VI:b)Ia yRHb0:IEtEQ[WZ%\֊!uFE"%鴞I+ +䃠3+Dlq#b#Bj5yu"-l1&XQ[0[T`M$0!L6+4h&Ɇ@ &SxhHgau lA `$qm-"qnJZZ…JRVJISb K K6z KV+ ,x5El%.;N#I\`Uw 8+QI\`&*+q „5HXq)#qkQb489- X 3$q  xW'?aM&wu4-Fy' x$.p]g? xW<jI\8LoVKJ1J\%#q"Dԅ @'8Tޅ{OxrDx{Dlh$.@\Nʀ)$xWḭ*ݦ>d QG;>):?I\%` VS%.1[2H\`Jѷ=-?`)&k%.c?QtL1E]N B\{)bK\r$q̀N[ B-X*M 2t Ȗ.tZK\ lA4(qA4L$.^C-(qA~ʡX&i)ElMH\ɛm'q6?lb#` 9+qA&o71fo -$.HO9L4R$4V˼ߌ$Rob'D>7EMIX$7Nߌ ~ytx%0"2MD^x]@|&+cqF1c@UL(p/Us +Hbfbg5[R+1m'Cό!w2aYXDmыFk~9=dFPJ[WX&ao)3Ie a#u!u#5hqNe#0r{jOg"hU`GJ& REtPg+9v̇fw?0zrik_ b_g\Y^e9f}Psf_XVeٖs;.-~_{ɁU_uSrCۯC{[K{lbk;_Ni ]^S榛;V[7 ׆m) +~Rti)HiB;W?z^ }z vOu!i]Y[e[2tsfA6Z݃u ":/3. Q/Kbj3w|r))J*VF:OP{_WV:P@f/,˴02̮^r#>/ =Bzyնd:h<zo 6 $o̾eb n}Z{0|l?Wb|{!v'}*~yW2MQmN`gCىk- Q]"67_[OX]\Mlx!q'iHrC;"-Fm[oD|DփurmƇ + ߒ_M}9ҟ] ȭl17e?»S!z,gz<ZţYW_GnycY +0zO{=VP_} .7.%ͮ,nu<@Ѓuac5$e˙w4mfhYnCW]\EsBnjjQ5x ~ȡ0|EjlYLy<\4J!63$ՑxY +jsD**G4m%;Wyn%6 z@gy:$ߎQ!mky-.m \J,\ECц1:j,uȘv:OV8X5082\x].1x[Qo2 y Q-o43[/x`u/ѣ~ y:f.yiH"ecǦĶRs_E%eG9[eke9uu `uq)]F.lo=ɥkIJ<Rwεx&u׹#ж3c?(f'<oG|s캔A.2ltRS}.Uil:i]RxNE{<:Oĝ=<vƊ=]]sYȋ>O\P? Owk[' Oy],n<<"oǚ9[hHge?<;Y3\ߗޗ3 +ʃu q'gguCx~t[s NԼbU|:+csq=6ߝ?7cC"3Ԧˇtɇj~g/= zֆyTl7Lo,_Z̓!o~'ʭST->!d/ I[GyDe]>9zaϧCYf]<ڽ~ifÁ6ut g|8\{Rw#5>2uJͿ|]z3xmW52Kb#+_F2/wUS~WwxܞnS"u;j׵ϥ߷qK'ҵ~A Gvsuj=ccs6q3w^-S"پ|ټݑX篵^D1r6v$]7Ƚec׏FUpvO2׽zXR@{ݒ0 {!?upE+ qӮJ}?&( ׿K w-;5+^a>c\2+V&.S1_Y;*7m3k2O]w Mc}pik tyuq&Q9*!*N.5lޠΈ\2? TS^襊8zoB7+kGGڲ9* SK_<&Ѹڛ\j|Ƃ5^sդgq~)^h-/wŚPu_҆wa3f_˚rmi*T]QI]-&ĶyD Nզ-&٬\ɶrDXnn͵ +TUSnJ:6¢ʐֈq)Ik^Nζo'Үsrz\H&K',*˯Rk<僶 R.$&^:VmC/ˆK0KG%ϤJ[Hِ1yHռLR.X/lw*+`E [oF?yg}]YڨI߸u,KR*~y|E]}Z[ /Z(^m.Mm-nZE TC갔GqB)|6ϊ_Vע%jpwlddnRKRm̺a!GWs#kZg:HOɄGmu C%*z=F\:#Rs%N ޠH +25ZRb!iN2A}yMIː씃ޘ*4"}R~ƞ8C +endstream +endobj +622 0 obj +<< +/Type /Page +/Parent 1 0 R +/MediaBox [ 0 0 595.275591 841.889764 ] +/Contents 621 0 R +/Resources 4 0 R +/TrimBox [ 0 0 595.275591 841.889764 ] +/BleedBox [ 0 0 595.275591 841.889764 ] +>> +endobj +623 0 obj +<< +/Filter /FlateDecode +/Length 4701 +>> +stream +x]Y~_>1 8A`6|Eѽ`vZU<ǏŒW/$ F!DE +K)fIz{肽~"Vyw}MzgȫbtJ>eT*!5v^YǨ9̰(Tyab +f +0C/Rap*!J +!cbt8 QEV硓^q:獴9g3F!9-V#8l1:xN`vZ:آלމ.+:".` ЉRlZp:) ljVAr)ℍX-ӰӁ'!0UBKNgaRް:؂@9"(3h ^8@y? G*8P!{рv0.z)1`:آ@+؂h [hZ8.Р[#@o …  4(Phpwr\A ) 4hW8.]mwFNV[` As\`Z +qb) 0p8.VwUUKwEP2q\ z]P=tJs\ ޕ3V q\`2`X]G3.?{ߗHY6.m._ <&mE YCFX)FFb)r僜 f g&VAbcm;ϛ + >65r/u]v eL +a{4/>\c]lxçϿӟ1Z^.Ra/䘆;ٍ28k)ceK2 +MqMeIg2J0@i)꓍ڕ2eΧ';]SW1Pަ嫿]?zcۏ'ӟkӋitvyN_ C[s6o Jԍ)ҭ]mӽai?R,ەd}:)eN^ض[_jɼ.e&h)Cu|;Ft!flN4B1(8bm u zOLa:***]‚~Lur)-©5 I%7񷿯lf %u @OAX._*l$jD#'\xDpaw={c6O41L-J=Sfe+=d>Ne^913w.m=vUL=OWt|;rӸ7a`\(l)~?N8vWDt5?t^t^Df/fAn`D +vBzL`VYld +tlvޱ-[?Ι-*QOu?/ +֮8vagNs9nޚSeNo[I1/? lM鯡>~u+5o֛}5Ͻ8YTkR9 RAJAӌN/̙vD t|mY1qGFRlصyd*2kmDk(qh=lh` wuk(!gQmdHi?lӑI١:)zt 6o{[gj,|il"s:Ԫm|^oyG5CkV{V'{2]gí/쭳W^u-˝Χ#3rmՏ;s:m~Wo,Y/V}+v Lk}_չ⯠?`ӡrϼ:OiVwOWZ}FcՀ#dmX-I"G>BHdm`ӡpo|>kt $7tۦX?|_3ĜS{}&%;! T5-Mh<9v`?0=o7߽0WPU=% 3W+mb> R񛰛=ty3wJ&?o?E:`.W61Уs6$Ɲ; vܶa:ۺkb#4>c=t=c-#4(m9H?idW +js:o({?)Dos:Gξ,k>wOfrljCjt&j9j6acxomJ^ngL×eosˢ@1b4b'S5 v(<*#秮HzWDOGƲg陲[Dy0jt粤gP*ctFt\:.NCLiM!wi ]+8~s^)?3;,0Nώ6,KGtܽpaއsufG|Ah#0Ա3EHл4Ŕ4.2g8Ǘ$*_T^c{PL(e اvX +fƏ|lt"9Nӎ3Btr)֋ANbzNt)t[MX3.H:xtbzuVf8 ս;rQw(2e@L'Ft0/D.`05:} $SŜ.l4[FʗTf):gd&75sDq.v4yEhpŚ2b=V6C"J)<~2:B)1O M_j%47xI1\Hkڦm D%u鱙Fc6H\, ꊘ(,OV(mL\eZQ*s-V+ڊ}qIg{K 6Ӌ !WRJծVa *4yvuq+KZ+:iIi,y:Da Uu&nW2zY8(!LFLCU,CMk3:TצfsJYTm+*UR7=c7#cSRIt~ +mspN%+JZthj2-MZ63VR7PhhUg2eMh 64a~xz}O&<HZH_[iiI R.9:'oRn.NNյ04lSVjlVi^( +]@&Mnʖ%8OQo{ڶR:ѶiܼoIȶpu,d`d]YΫiꙊ.R>E \"!2Է`6kӋaEpb^ބ&4rwX2"c%mMdZ / P}EST~/- +Iu +4|Ezc;PUWjrz 5PY$S +endstream +endobj +624 0 obj +<< +/Type /Page +/Parent 1 0 R +/MediaBox [ 0 0 595.275591 841.889764 ] +/Contents 623 0 R +/Resources 4 0 R +/Annots [ 625 0 R ] +/TrimBox [ 0 0 595.275591 841.889764 ] +/BleedBox [ 0 0 595.275591 841.889764 ] +>> +endobj +625 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 101.433071 713.673057 101.433071 694.923057 ] +/BS << +/W 0 +>> +/Dest (cb101-1) +>> +endobj +626 0 obj +<< +/Filter /FlateDecode +/Length 4862 +>> +stream +x]Y$ɑ~_ς }Ê=@YI=ttI,5><-<,颻307H/}WNR?~)z?ꢰߵrq:?)fobpɛ?}L9_S V`y?h|XAOŜ%eEr b8cJú햕!I,K+ȡR"(xOJ)lȋh$SN{-BI9CS8 Dd1)Z!vK֕DdQAisrNeTi3O>Y$֓mZE +Q"xijG') j!1щ<ȂŗȢb ;h"\08l&%$0)O.F+~r!G -UŻ !Րa">2$V ÷%셷b@|)Ge +bnLIJ"sLOD`>3EɌmݷ7;?vg8R)?Bi_a5n1H=}HHH?s~XIItF^2?#?03os*rD탖ev]Iˊ)4N>/D.>%evRh \VȌjِk Pn_>݀Rs]2,ix~?b1?+i^}Z?c|? +-|\/}k6΅u;pk;`}^}˺^]NWl}f򍲏Te6k=E&sdli}M?FYҔ.bA~09&03jߵD?(Ot3&1'2ݸAt7x2btxt"=~am>VYe3=o}͐rYe֬^\dG5uϱ90Ƒd2]!l|ٴ;DC/zyQd[01 %?Zh3=zmy +p~g>-3 (^ϵg>f8-8VG v<~nvyNJY$J)][>OgkBm&^$Yzc-a(gMjW_GzDŮ,}zqgYRIAGg߼V{YI"j%D :"6gf6E0JF}C] x,es<%kCX0d7 Ϗmf2bYvvڎWm(m ' ֽs fgo[mA]L.pb2 }gʱXkĂ/y6 vkc̞gG n5}(ゥ>n|=ᦳo͋}cSttwD\pLwq>Og'5O:"m=9|EMcn[(sJu<Ei9XeKjN\=[.vcxէj8t-V6c!4{~5}zuf(2EӏE;aQKtQtТ܃waӲ2o KlQ}\H:HC{Y,L +ʙns/X.:7_]TES׵_Atqw_ !}wVSƲ|y_qPd\dSh|ՎKֺZlhYec+ sU+mGZ7r˨6pd-ZqfK%bY3yތ8.{JͲu)0y̨ D7߁))z7L|]fc< f.<ƤTH* cvg& Yf_Ɔ/3*?[ LI":6>ھɋ&ym/,h[ eUF!ȼ0Lg r%ZL<(_zT +A笷SX3w ֞jȔ3+vGC?գӻwCGiCtT|gi݀|]2e!۷Mz<ǘv15kd\pToV:0ӱ_äeg^ +5 +dE=L8S~GGm9-(vhP[&'k\5=宇fÐtM-N=,Om)Y[ň~KTlN6ʣ\ɦЉMt:͖5-qôvT:UkTY&TnT_[qm&Suhl|jtLLՐ\kk;|[Z5WwQ/R=l&SAJn̆yvb'|ZWDm䤺t*}aYitB;CoTBAfRtel䵒8=4q-S,חNJhOZ7Les@ǚ52AXOJNTULɾmz& ovrhɱ#Km\f(͍d2T'd1b F_ ֆN帀cd}~+nXoy6#g?nTC ӰuE枌~_CHPm0q ;YWkh~׮wWkKT7.'CF6tL3o]K[owtXh +vp:v|gC⊚v3#.d.JL2H>IS=RP_0.mfЕV5Ali>i^#뾈 jF}vcDm'Sm sl{5ƲlC 6ʨw[x>դQ4MUZ1Vҭq[Lѩ|U=_iKVע% 9Se%@ wVvnz;  =2Uߴ|g}ԪJNd8j5+B8%VysZɶ"Rk%|&,UQo0Ex#3Pݲom +JAԦT~M) +P*o&EQi,*> +endobj +628 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 101.433071 240.123057 101.433071 221.373057 ] +/BS << +/W 0 +>> +/Dest (cb104-1) +>> +endobj +629 0 obj +<< +/Filter /FlateDecode +/Length 4787 +>> +stream +x]ێ}VH@Y <I\H}F fT#qjL-$%qop qA+@WԥA%.p]В"Dԅ@?T$.]$.]e:BH\: [aLYSH:aIU*$ 'R3R[6_2=VOzx@i>/&(2&b:wfyCGm=P29 @@&Wb1l;˿?Oчs_~_ ׿p` +>a;e6S#>7fҗO[]ϓNvŨФL~cZF{T|N0|x S;LFh^ey ^&jo vǦ+}e7?oi#yõUWX| 3vW&kuג.1elMzTG϶1NqZ)Vl)w[g]=}"Mۋy >f}uW+.g o{X9Nfž􀗳3u<=г~:WP"Z{&ys8TmD~`޹wߌoT{+{[ayJ]>貭P`H^n?ǓhYi/w9oaf?5tKR>]2~ͧ՛S9nlҡ`'>\Q*=ٴ]ڍe~W~# 7f՝y~~"2dn(yhUT|js8n"M9V84s_C w;860?l-jw9j7?^ĭUrܖu>/'+{ 3MI"[uyOJC-5ͮK>,>;x:&Ԍ^yúx.;bhsFc?빳egOߙp ~PcYTZ㑇z)容(shBiXJ<6Fyn%֮ z^A{v9mCl=qa)Rb㰬y% we1:iw4oM=<+ ,+ֹQu?effr6܍~^vHl86oj:o:ͺ5u-j|f)QUF̨Tbk? I~JYeWa,@5]*$JsBM[TZҠN6 h|p7#׹(}"ÍY/'gHl◓ Bj׸B=.$VnGҤً~,|S*\fh[!OikW<6xH\+X --k.B,o/>nM][l&eM!2IUuE]g ++S U15P~UT56šGU{k Ex'6ۋ3c] a &n42h씏/_ f8r&'O^>i_'{c9:UTnL;"Æ e:0-j^Rʠjе6dbSk4q7#ھi͡ʇpoMgV$r6Ck ˈ ^(.YY633WR>oyWP]07"_R6l .0 ^ռ4G0~Ledi*}zcYZ OxuΡs(P-أ䴡\ ;eزM ٬2QTLY-14xQlP}&R^񋴹2Uo8C;RV_2 +2sWm)Ȗuye=۰> +endobj +631 0 obj +<< +/Filter /FlateDecode +/Length 4776 +>> +stream +x][q~_Vx?؉^FX!?_QIԳ tb"EiU")<]o_~)89"ZQN>,a +əo]yL)y_XEv +1UJi+B0 *'41%I3\ C[UT0* KAۭ* 4I* J+ءR("kvӽ3z1$t:Igi%].J:-.)-lqHI:B6IaV:bb.$Aa ElQ^iIR$u :Cr*IM+0I>:[rIgt~$x0Z ntHtDA&!LE & +J4`ȧ U:%" +8X [#WHk` H\`-l1d%.`[Z$.[RIK\`paqm$qJI εN ,H=H\`y#qZ^ ޵޵9El%.;NVG+qwVAb Ыp%.V&&*&` +uax84A)#qw /q2 wA!N` V+q +  xW'L˜[M:&/qui-WQ1P^U2P^VA3P _^#0+]LPj%n(/1p¼4nQy!`Ό0,}[sdNy,!&W&o[8̦s!u4lYuea+Lec+!ϫUܓK',"0LۦJqF\"[#v< +l墳5uhݤ6M`Gݖ_7cm(P@ aȧm͈о69ikɖ~r}}ݶo0=ܖJf?e_=;ToGfKWd|xMsRˈs[1V +7r i2"r?l=|jCvG|)Hwcӥ u"'I;^\, a]^ ِħW}B`snٜ$ }^=S/tgf[MOl֢z˧初ñVJ3 a,I~<9g l4bЫ +pDJ y~[3 ^g\o}.T +ޘUOwgMfBuheל$Hô>acskn}"Q2xux`Zi~sdC{hhgY { y AwQK/O`Aə k\CAZ²~X{Oǘ?xTC~՟Sߙ7R$ l !;tfrQh8J3GwJևyCW]Y@=Hsy`?o Ich+dpm|%1ul})KޖzSer}|y#w>!ݴ:uz|L;Vvs{P2Ŷptڏrw,iGfgT ;Zg8Pu ;wsq;lH=R"B l z䙙'\?Cm}pF^oC9w^ cj;Lrzez^gy>Em*~טxR˗_#Ur^4y%=1`}̧i|5rPԗWt[N^nhmtߑ{R6"I0+/*KvΎ9h_Pq(E7jۣUGS/o'AL:9|U,*@Ô)Tt@Wjk8nj"k6W,뭘[&]8r)| {4bm t[bCol]L]iMsOxZR~s-zר&QI]M:Z? E~jфl홳0V QKj:AtJiThbϚ)66 0X?)1eץWj}.Hⷋ Bj׹B +Qhr8. +C݃LIyM R~+K'rX$h +=.B/Bz&ݖyl!\6C1I5XuC]3U45(-N׆S2VnƝo82fo+w|Fk1C?Jب6a7 ŝF߲N kdҌ{咧9cVn1E_/t2y7iܺ3%xR +۰b{ZWqc]ub)ucPݴubӠk͎EWYnŐ!/ƂI=^?ߋɾ6joҷQFxKls͏=ʲس-C1:HcVREuhtVb6%8^ +-ҿvc4'W&-[g-ΡN-̏zJ[eۺiYwmC3{dz6I.{ؙvT'_?t(? +([#+Խ&tD֪o&ACQْNsj8PޟB2R70 Joû>?s. +endstream +endobj +632 0 obj +<< +/Type /Page +/Parent 1 0 R +/MediaBox [ 0 0 595.275591 841.889764 ] +/Contents 631 0 R +/Resources 4 0 R +/Annots [ 633 0 R ] +/TrimBox [ 0 0 595.275591 841.889764 ] +/BleedBox [ 0 0 595.275591 841.889764 ] +>> +endobj +633 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 101.433071 461.373057 101.433071 442.623057 ] +/BS << +/W 0 +>> +/Dest (cb107-1) +>> +endobj +634 0 obj +<< +/Filter /FlateDecode +/Length 4832 +>> +stream +x]ێ}yb `x'00ӻc# C~?HRK3NJb-ɳ#w|xtrAV_oR?X]IUޝO;şOyyVCNI{CR=཰*B%fT+.1FN37,Uf,FKTE4 +fh=vH%!C;NBTyWNy#tqp lQHNgaN[9آ5Ew"  +'$z1"t")aNaFagt +8a#-V 4l1t }lUivk%E)oXls lq4$^8@y? G*8P!{рv0.z)1`:آ@+؂h [hZ8.Р[#@o …  4(Phpwr\A ) 4hW8.]mwFMV[` As\`Z +qb) 0p8.VwUU.sPs\`8 UV( xW8.P`.(lr\A!,wec4j!: ,xW qfޢ\w4 xTqJ OREq"nDq  bX.hIq\/<&au~$ A w#+80{XlAq\:L[fN#XSp:aNG x7M O8.`q f; \!cun ,( c+آ+؂DCl\-9. !q1*sjtts\%XK % `tp\#lTh +9A6t゠` A +Xe:q<4֒jNgDZg qC +9.4JL` hOZl[ bV[5r3p\lQBq\l +؂(ܐd @ qAMe8.LqAM,yKMqA4"DauASd-8 MsEEqAt.73DDϦBZoz6]޵L8z- ^ʐVPoeS oٜ54XYf VM/11DSTp}]sbzؘӗp{z]Δ!60 Tp[DHQ%ǜH*Y禎)AS- fou=}ϧ7.(,_{o ,m;r+û:Y1@!1aӗoѻºkoddSYKyı寞'5yM_m)9c͇Nivm?u8;]~?D1]P_wߜn]O K\S⦫W%% n#CJ͇¡@2/A2,Y:̒i:]kڥüS)NӕkPs{Sn "Uc6.,=0B0':rING#_#Pݨ2-e^HQus8Z +:o:z~^΄Unt^剠7YGm+mA -&`gáz@**(hC0C(. cCԢs =ʻmyu_ 6_(V-F5)A <*ub9Z*8D.;o ɕU0 dm!t_!z\x֐QPAsՃwrG/Ǭ4)wC4.j]\I6/跐ᐸ4}$ٮؖr#Lu[Ds|]E֝u}9:JcRg#yV}x;r; z ,[xWJrѺк/Woξ"mgǒ8`tGPP_#.5y*%l$iܱXAНug勒I2[uH+:2z^C'] \S4@DŽjӮ#_WA;ڭJUݑ?6n6v+8`CbʽYh6r(eȈ+GTz㑻Fɋ]M+WSU84+p&Zy +$߱`g!z Cl=qaiRMEa9dw.*am裓ϯ|N;cvWpވ`=_=:3 +nuGfbv)_絈zm'IHsy>0]˼C]^'p{`gw#7w=O5GA+460'27}/*+nEG.X+SDO9u/ˊes44ڝ9קn¼ǹ@-KW5+vjss&}Us8nkrO}{5жџ+}+(&;;ףz-eл;JF+#)u}_*Ǻ:q>;UIOF[<:CFw HPamXD2v2p; 'mpF&}u #2p s4$|F3 e29vkut;W-[67]#M9jJ/[Vw9:7 Y +((ދeδߟ_u'JYo+ȼ#YpȤlE*enY `VSw#ţW;wWZyw:GCȯ~fYWV3cI,j9ǯ[kfrO]ww Ww3˼5Yp;92uֻ/O;DHNKGY^W_A7:CX5Gː=i՞stg!w#zcw\ZFhEtϓWxn ”7 Ko,I-Abz?}AIvmNq:o[k 乏tjS(ת_K8q:0Gd~R>(n2lI:IhIOb0ajO_tzvz˲1]Oš]ˬ?0W8aLq14@q\}d'Z_iןSS5Me+4fzl-ycԾYLwD6r2\Pqf}ʆ*'>sز]dilq. 8AЌ &u:wfOoN{^R8A_]f |uyf9ޯ ,Lo8Dquڍ׋>K9{l폄KC<SG[?aOiB׾%pd-[a1lN.T@қ E>Ӌ Facyf~_ߧZjzHoIotG{_%8rϧ5Èi^eCGQ2:" CKj[N<売jR}[Q + Č5\ՋANʺ0US+6C4lkUK-.)u $RVy2ׄN{3+M/*MU41*V-%뀘:Nrb_Ҵ`V=Q +L-K9Ft9l)_KV5o4P;]H;8|S@RnF-5u&6zm\!ljnҤi S#U*M̓?HS!^ҎIܬy'QcƷdLDttXK$Uc.uU(OJ*mLudNnʝTjom`/ٱ^IXɈRhFY\fkexcdǽ~:e7Uep4ʒ7ɜZ>2q%*[ʭ31dաa8J!Be7 -h~\)צUKIYTV-ևD*tԤgȼtlu8Fp@/tsg$Rҡ5Tm䄱Y633v}С\䀄P7in6]d*HІ'3{^/dWf@Vjg*x·n~X}>2y[ն4{9mj(F4jSKOjlv(*]@&MnV%_q`{טI=mNtTܢljx-Y +g߮N5 UjZI]ds=0"SѪEɻ3\3!2uQ"81-\2#Rr%Lh-VLx"n+HSӫjQt[0Fsb oSwSrBTL/O) 靯^H>S4}+#$) +endstream +endobj +635 0 obj +<< +/Type /Page +/Parent 1 0 R +/MediaBox [ 0 0 595.275591 841.889764 ] +/Contents 634 0 R +/Resources 4 0 R +/TrimBox [ 0 0 595.275591 841.889764 ] +/BleedBox [ 0 0 595.275591 841.889764 ] +>> +endobj +636 0 obj +<< +/Filter /FlateDecode +/Length 4660 +>> +stream +x]Y$9~_QHk|jX!!. 1bAEiၿG4j2G9YTW/VSzt"EprEVJ J>' Br:.䯗o~v4j]TֈCQ%29vQy%Ĕ8pjTaSt +fX#0ؠR`r* JIءHkft NN+c҉TМUNq$.r: [\9┵kbto$-:l"l"-K.EkY]N:-p43 +ӰKXlqFjNg`O8bdfmQeu1EQf ^8@ lҖ#FtL†`8 SxHV [[,f.-&Y -Hq1E[qZ2) J9.0 \)9.0`\rqp'8.0`]v5VI ,xdu( 5J ,xHs\QX:Fq(-VwCXs\d.(lr\:m8.@aB-wUiP1y xWE KB83oBy8.p],T}F +wJJ'qopBPeuI# Z`2IX]d,$P ZB$ H(,pE2)r\4l1Zs\4lq<ov{[v`a |5ːd9?v etqR)ק:;F=u+eόv>ci)W~J?suϦ?W},7T6%\}/IXqˌ ++2x@xPOz3,V=DZ*tY^{K{:\ jVuNکs6ܡpWYCÈ8ML6y|ס4֣v{@eޭ ū2NۂP) Fg;O0UG`/3T>M Bv Y٦v< LZ0QGdFuZ`/ Yh=lhu;~=h +r+z~QW1m`ӡpo|>kMt=:73HO}M_8_nIN9u/}dݝfVJE_DUcyNm_.+.{fм8t=ϛyõWWX<o6wA>+qI<\s:ʣq.mr iȮ\?R"n\._ި/yfw3f +9l[Ao}0wbo7Io{QtOL(˫k@`!vǟ=VZVPr0ɿC[=tݹ9QXR^AF9th=揾˯1g}E}}3{c;?X: +2sV6Q{,PK] {oSJ>p9u,[bn GzٝYqdFH噁W5;pz +gx@K +t){ޏS6j(<:˹,s؆'2IKSZ/rz [^ChJ)W/uLKwGryU>](g\պt$pƪ2L*wO!t>>E%f +Q&~ЃK,#XbI8~,J*H 9~Lp:`f=o]FfYY|P1#DNbjj_0㕯iU +}V`˸+VFvBʮ&ֶأu }שnKZ.̥9Q*eΨTb81ۅ~!KYݨ݃0 ٚ.tvaӍ:R-k*=LiP7v<#}4J=ͪ#ҔS(c-c.֙įԮqtztVq /MJ1fѱ@Jye+v*YN徲z@vݥBKEɤ'ҭkM]uyDR> +endobj +638 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 101.433071 713.673057 101.433071 694.923057 ] +/BS << +/W 0 +>> +/Dest (cb110-1) +>> +endobj +639 0 obj +<< +/Filter /FlateDecode +/Length 4930 +>> +stream +x][$m~_NY !FFv{wls!?U%b]fvN EQ)VZ~~/9=cpOoj^_)(7V.N^'"8M .yuu}7ShWb9;+XO1VĂ>:㶬1\N^bA gLX bXݲ20Q;1tQ`i9QJA5O)@A=My<ijv +i%^B>I<Y|VZysJAgSx`ȃ,&E+"d1Nx ȃ,*(-|NΉ J1myF'kzM+0I! +<YYAox8H<1%aZVY-3EdƲp۞;_|'8)?B)_a5o HB:$D]H X\n$$o?$$:jc_(?)"ΩBZu%:/+.:kucq+4zت2cv@ZoiF$}6W5ZU7zo}Z=O}wB;R{Hz_{j^ljcقs;8+NavkW,fm'wE߱_tV|V+{vZa E}g1tVl R>:]5vmf+o+k܅*ʛ::ڋuOw$)W7V(!bhuod>1k,t|5T, yq+JdSd9.SLV,$_kĂavgwü`LF=eJBuov`{y7ĭǠ.I[C8΋u:qzyfXAEmszuvfcbvr{1e#X,$d;6vme'=Wzxrb\/т߽>iK[d:Og'_X,Y;3VŢN4M'|γY;_jhuwMb?{o`20=tyYqln.X〈>,w\P au;׶>3LYH/瘤?ku"c͏-Ǟh6 ^]|gjl5#X$ggphd^˘S=z* O6]#?e?؋6qf,ESyj]w<%4ۿo_')Z4@')eK-cl{*2l ^ cge\˸䠓d9TJjf$FLB\WHm}un. J׵_VK,e-eljqW$pHiYd_3_/zez5lֈt]tjWEDZVe :QP3QB͊]u^nlSz wd]u)q*8Mz]Gz2= dޱ8׵8]7LgIòE6zշˇrZnݗ]u8Gq2 yP)n.EUkuɋ#y-\j#Da< 0L V8LjRgEc.Т9R9+Q>LcΤ1[I{!St> }[wN.ۦ_=c0VqҺ,Xv/0taÆN*YTr&F{vb'7yO}%°xաoxjLxXsH0$:;}dfj6sQ9]y>MSv-ыuΦ> h\RNCrSf%,7j߱{{4}Φ=/yKapT +Ygy1d{>gCsrZVYm90(vV"'&Y!{]G6cmB$rb[Kªފ)i%2o,b]MŇ,13ݴ$JKboBW 9g!3cLϷPNDT\Ҥ nUw:1)t&];5˗ J-?Hb:rrvLO7D/rV*d~$x'i2_n  +} +qe6rR^:^?aiV4IP|Юۯz'6y$N ub/ԥcl6Z(OJ7Les@ǚ52AXOJNTUtɾmz: ovrhɱ͸]f(͍d2T;d1b F_ ֆN c_d}r+nXo(y2ѩ7iغ"sOF{.{P*-F4~'j ͏{-DuȦіi[ s|i(MVpy;kWTtpaq%0wVbANI~ǧti;u7˛2 +V!ayy% 7"r+ SOr֗ؒkeڳ-KnumQSSWiNhpb2ZUKq[Lѩ|V=)KVע% 9ѩ^ŒI^Q]/i+m۷[] uABLU7%߅Y;s! ?%S?lh-RG_]b79Εl3"5W{tLZ5},+(WJ :̩M&|TaPUo~&š |I +endstream +endobj +640 0 obj +<< +/Type /Page +/Parent 1 0 R +/MediaBox [ 0 0 595.275591 841.889764 ] +/Contents 639 0 R +/Resources 4 0 R +/Annots [ 641 0 R ] +/TrimBox [ 0 0 595.275591 841.889764 ] +/BleedBox [ 0 0 595.275591 841.889764 ] +>> +endobj +641 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 101.433071 240.123057 101.433071 221.373057 ] +/BS << +/W 0 +>> +/Dest (cb113-1) +>> +endobj +642 0 obj +<< +/Filter /FlateDecode +/Length 4725 +>> +stream +x]Ɏ$Wـ(0|`@ zJK2#nS4j2K$dU3Q"蝹޾|[CŠ +/oJ/.wI@^hwח ./iu"F) QE"Fe^[Ǩ9̰h3Wyab +f +0W4WE2 +fh=Rv(-%!ҌNYi%\:: 獲EᜳbT +9B$-:xthNdt]tVNK+l N)aMbuQ$-N`%9?NC`FN$)Ngaް:؂@;"(#H$^8@{/LԆ#H`:Da't¸9 ӊ#1)b0rYlh8. ["آ q\@`[p\@[#⸀F*qpa一Ḁ@R一一@u Q%BNV[` T x.*Cq"tA xW{L Aw-p37xW[9.0]m@z]P=t8.@aB-wUnjiP!: ,xWtBy83nB99.]LTq>xUs\`0Ss:Qr\`,Pp8.&tY]2q4 `V8. ?9.p]i8.p]i:BAs\: [fLYR)8xW*0J#M O8.^#%tpXx e:b^Қa \ }[)r\&!q1*sZfu:9.LŊD/q̀N |-*`*A3t +.tJq\4l7qAL'9. $֙`H"&Xi)YlMp\Imq?Xlb` YqA:-7!-5fZoz -8.҉&s\NJ +XojqeZo "I7cm$֛h`` Ȍ[p֛`'N`\Zo f` lk#Ӂw: p&<[nm/A?!81^ Hp/f+ $7ؠ286jiJ%ٰ33NG9t #y>V#hq %#10z*G1 `,_`cY`f[4ub'@~4ĿpPG+1r٘aw><_K)Mg +ߍk3>5LѽrݧQ71vZbMys~6?<)ps|UmoLfW~S D8$^,X@6wKn d,wpu,x!KWڵņ[c_[gm.faۖ;O{#Ϥ'wv9ذZ%$@ 崮5+v7!8.?\W?^"@r_ӡҬrS| M=j4?i=m:e3<{q4XHK, Ѻ/кd>G/?-gVЦ_Cj~\o˽'#&!Զ>υ3,S{}cw l.3G~J<973}чx/;#7-8=;,yåUXm5 uٙtZr*,7~UD(zؙl(w7qDq~^W qa8l+.3P]uqY| {_s#{}0oMi79GbVUe ߩCw g/Qzj,ǎM:l1ć JǚKJ_MYu_ӡngDL)~|19ja,Z?9e5s6uv+Ptk4s'_S @ng!tÿ\z"y6/Z1nGGcAB~'FzkyNލ[Wr< ҳY'zw|ǝyN TckQljWeGmvFs6 vn "?m\- B9B7v_gdk^P$ y&䧹Zxt;y?=njDîMlb{ws:$nMI+޷m9FaU#k(̼s:V36xM~GwkFxԺ՝yΆZ5QV^@os:G,k>w;9CF|tq ~ëջ6pCw9}SDVj Mqȴmk#L OY|LvgQ3zeœw=C⧃;}^>?}g!~PcY[C|\YftBJmo5JMowuOؙtH^QAlr%.eu\J98LSֆ;ơN0 ڙt`=yw}zgdF{9}n<꥝\$!~&W6 ?4`k/vFioxzs RZw erB?]?)ߎu7 elY}qÙHj8O:_:{uF'k>^9LAQа꺐s8njnI]Zl"mK$Uc*VuE(,OV(mD\e2Rn/ؗWbo)|ކ+b-lW+k0BW}yv~5~X7.^iNtmeKy1?󸖅-t։a8e4BmگbjZPq65ĞS h[m؈uVԴ]޺V,kNK7j(E{; UGuJ6E*%S:F7q˦X-VR>oڮTWsѸ钪i-:ˆh-ب81zu&<P{rcIZp馗eΡkȃP)GɩCfrbmL`JMM*E d}ɍr wVŧoۖmFmYTnD-};YS_202.RSSR6Ӻl{mnTC\Lefg)ߑsEToPDm'Mטܝ8ĤC Mh<뱒yD$JښI^ۊV>[-=L(ҜEHBҧÑ2td A& +endstream +endobj +643 0 obj +<< +/Type /Page +/Parent 1 0 R +/MediaBox [ 0 0 595.275591 841.889764 ] +/Contents 642 0 R +/Resources 4 0 R +/TrimBox [ 0 0 595.275591 841.889764 ] +/BleedBox [ 0 0 595.275591 841.889764 ] +>> +endobj +644 0 obj +<< +/Filter /FlateDecode +/Length 5011 +>> +stream +x]K$9nDs€~mxm,|ޅc`}T̈g2ԃOBR2;sI/?]~XſbPo +Wg9J(TO?9˟~smw]티L)٠ +X֑ +CTX41BbϷ1䠱 {V-@ k,JH +Yἵ*Xf +31_T^%LLxCx YBNx)'! E*H%⡝2dueYlN2dfW9[Ld5s&6IaDbRxDʃ,xY?8(嬌V/,9 UdAk#d)jd4 ).5 g +\ D  ǒ4 N%pԐda\Y! hX@Y<eXe[e뢆VRaraJESb' K!z K%vV!ʃ,0` \& K& a5,@a԰b|VlY)@%1H0p4A>Xaw=a  w!Aw VyҰDÂuӟ2V5,]}*qeBX4,]LTaA>xkX0Sk`OQ ɅYÂ"1hUEor\ KSӰK@ kX +dPѰSsNtsNÂ! A ψ2հ34bIZ㱕83kX9q5,0A Ty0aGasTd% Y6%L YiXPl4&kXZ ˈ7=kXq)fְEOěI%EQyNSQ-0 &IE kXPbx3kX7&KT0g$, #I/~{\fWo,;*${Ub6!l"&`܇뇟.__/;/?3/歬{V~\>+[pؖrT^>LgB5 ]y{-Mi{:~~ZNƮl(He;%̷G+j sKfh3ug~uG-M~f7G1՛4fguwΓyo>[2od9e *("$5}[+n-mfga}u qV~+ȭϻFAB4 pdv*`΢Vh~\{vwZ9/SY #)E A4ߧHJSnHZ4;&>DKڀ8ϭupxՐmxi*kطݯ] ߩٞ.r -*e.D2i/[ӅQZNkkﯰ4}6'E+{$ >>[] Q>ɣ+R9ʙ항wS@\#`.^Mïv+wh֭ w#2eU3;M)R@E1(.'t}/tyj="+XeUW7n:wYuC @{ICZJ4pJ)Cړy9CeL%`no,-L32unÄel6مs92=M {ٻܻ%oN@΂܆G-TXv[{ؐT,ww͈w[0M̑VWdc<ʏCL;v42|SYG1YP?ˡGynvಧwR(!u.d.Ө6-frrVjauVyq UĜ{8{'I\rݓy=%Ę₅n3ªmqu-mŴb}<*)LSJrm_=u ݕW*L|+S߄{B_i=7hM^S =yPQN8HDz,OEd=K[]z'l|*?sygo ZJҺ?AЦU# )D㔦} AlWEgX#7.HypOr/DΎydCE%;^ l| Cz<$9{#+,>$;> +endobj +646 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 101.433071 510.123057 101.433071 491.373057 ] +/BS << +/W 0 +>> +/Dest (cb116-1) +>> +endobj +647 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 491.176036 99.933071 472.426036 ] +/BS << +/W 0 +>> +/Dest (cb116-2) +>> +endobj +648 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 472.229014 99.933071 453.479014 ] +/BS << +/W 0 +>> +/Dest (cb116-3) +>> +endobj +649 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 434.334971 99.933071 415.584971 ] +/BS << +/W 0 +>> +/Dest (cb116-4) +>> +endobj +650 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 415.387950 99.933071 396.637950 ] +/BS << +/W 0 +>> +/Dest (cb116-5) +>> +endobj +651 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 396.440928 99.933071 377.690928 ] +/BS << +/W 0 +>> +/Dest (cb116-6) +>> +endobj +652 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 377.493907 99.933071 358.743907 ] +/BS << +/W 0 +>> +/Dest (cb116-7) +>> +endobj +653 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 358.546885 99.933071 339.796885 ] +/BS << +/W 0 +>> +/Dest (cb116-8) +>> +endobj +654 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 320.652842 99.933071 301.902842 ] +/BS << +/W 0 +>> +/Dest (cb116-9) +>> +endobj +655 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 282.758799 99.933071 264.008799 ] +/BS << +/W 0 +>> +/Dest (cb116-10) +>> +endobj +656 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 263.811778 99.933071 245.061778 ] +/BS << +/W 0 +>> +/Dest (cb116-11) +>> +endobj +657 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 244.864756 99.933071 226.114756 ] +/BS << +/W 0 +>> +/Dest (cb116-12) +>> +endobj +658 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 225.917735 99.933071 207.167735 ] +/BS << +/W 0 +>> +/Dest (cb116-13) +>> +endobj +659 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 206.970714 99.933071 188.220714 ] +/BS << +/W 0 +>> +/Dest (cb116-14) +>> +endobj +660 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 188.023692 99.933071 169.273692 ] +/BS << +/W 0 +>> +/Dest (cb116-15) +>> +endobj +661 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 169.076671 99.933071 150.326671 ] +/BS << +/W 0 +>> +/Dest (cb116-16) +>> +endobj +662 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 150.129649 99.933071 131.379649 ] +/BS << +/W 0 +>> +/Dest (cb116-17) +>> +endobj +663 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 131.182628 99.933071 112.432628 ] +/BS << +/W 0 +>> +/Dest (cb116-18) +>> +endobj +664 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 112.235606 99.933071 93.485606 ] +/BS << +/W 0 +>> +/Dest (cb116-19) +>> +endobj +665 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 93.288585 99.933071 74.538585 ] +/BS << +/W 0 +>> +/Dest (cb116-20) +>> +endobj +666 0 obj +<< +/Filter /FlateDecode +/Length 3977 +>> +stream +x\[\ ~_1H"u?4(P Ѵ(zNQG3Ý^g EIfk2;sIwkRW[*pt @ɤ|ǧ;{\?~}w]8VXL&lPX,Ha`R!* XƂ!KV\rX ++C U O5p%$,pZA,3y炉Pzxޙ/*/xD&&vibb!k<,Xd j<”Ƌ"YY|NdNQxʃ,6Z +P2+ٜ%`B&9`Qؤ,ц K 5AƏNJ9+ŻɒxxXAl>B #aOp񬁀d8sPb8%``8Yw, sUd,hadLЖa-mq𖭋bZ K9ȅ) KN  wOPB`8G K쬆 %BOY` L0pM0pn5,a԰b|VlY K"7p5,`g5,U. $djXx' 0HK4,]WZK԰ w]b\hXTaA>x5,]G|.a8$ ga*[rְ wK^Dac3D%CrEaA" "p" "p2Y({ ׀U|ɪHa5pT4,] $5,Yװ f6%aA,<|*/< !Td 6Jְ yBkX`ȂLQ ɅYÂ"1hUEor\ KiXZd8x#钆<Y* 쑙k<YdkXL<4, ԰ *3Z QKBԙYÂHa&RA)(~PlQykXr3kX3dkX۔z3iXP,dAƧaAHa`'3qY_{le޶c{}Ӷ砾.ɛwlwJs6I،K$nnkj@>߼jb- oxHe&5tQJ-ι~3x osUxqkzme&|ؕo:}(-I8͒϶Wѷ=pkB{b.FwOg;~ǼLk^f"3j~E>\$cqtWh&h17=Xb[TjVxmH>\giDS2=‡MHj+TZ^ iΒi5RfuâRГj m֖Ǧ;1ҟf=XGB*tYCkxm?yf,IVP=EXOdf9{K.Ok#obw +譭 $fqrTKn}I[=߇Ob:<.U526iu.C"5u"HVl5Y\VklYM_2t*\p@^q"ɧ6r3rMWW99\KW_dXcLe잼'?og6y:W-YB=Qѥyr 'ױ=mҮWu3l-2w{H}]GmMJ(}:-upC%zwS?3Pm]xr>gX֕6y{lF6_kDw!KQtgti+~ tz|Zږ}qDc6Wo'#x| /'Uҹ~_j e>>7~|7{۞?'ߟqr~P"1u'Ϩ +n 9A$W+j !u}Œ',"&iM %yM|ox*&D<$ex7z6FU[C4%`ϴ[|VjM -P?N["?;?@8? +=/kP]L:o}CB42#~6C+Ʈ!IG_˕7 ,C;f!cKValj=Q¨̛B|],yoĭ98}ϑ{ޏ|XGysE]]ZLkxumt8/_&;F6R9l]&W_{?ZoY/4-Pֳߠ 䧃|2< Ab{kXB)-Zl{;O $؆}5?n D$6M3K-l=!` ym;oY-pItP]!:loӲ׈sJ>T׮FPePCo96>)A!~mЌeFݐx+B:vm0v*Vyv-]Siꔇi9KG,{ +yA<$]!) +DZlL**fK0I7y갦i]R6 %^@wQ-TxRO+u,Lt*Ǹ1uSCc,Z|F3]c{Xmt٭5iI{p1b2֭8ZJ#_VMuWú+񢭌#Ȗh$@a54WggˑKfރʳ%uܼG ę-\(:hO= qy~]"O(h\?+<g%LD698O`یesnŪK0<]K?PoTBfwN!v'q*S +endstream +endobj +667 0 obj +<< +/Type /Page +/Parent 1 0 R +/MediaBox [ 0 0 595.275591 841.889764 ] +/Contents 666 0 R +/Resources 4 0 R +/Annots [ 668 0 R 669 0 R 670 0 R 671 0 R 672 0 R 673 0 R 674 0 R ] +/TrimBox [ 0 0 595.275591 841.889764 ] +/BleedBox [ 0 0 595.275591 841.889764 ] +>> +endobj +668 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 799.173057 99.933071 780.423057 ] +/BS << +/W 0 +>> +/Dest (cb116-21) +>> +endobj +669 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 780.226036 99.933071 761.476036 ] +/BS << +/W 0 +>> +/Dest (cb116-22) +>> +endobj +670 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 761.279014 99.933071 742.529014 ] +/BS << +/W 0 +>> +/Dest (cb116-23) +>> +endobj +671 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 742.331993 99.933071 723.581993 ] +/BS << +/W 0 +>> +/Dest (cb116-24) +>> +endobj +672 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 723.384971 99.933071 704.634971 ] +/BS << +/W 0 +>> +/Dest (cb116-25) +>> +endobj +673 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 101.433071 662.437950 101.433071 643.687950 ] +/BS << +/W 0 +>> +/Dest (cb117-1) +>> +endobj +674 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 101.433071 289.190928 101.433071 270.440928 ] +/BS << +/W 0 +>> +/Dest (cb120-1) +>> +endobj +675 0 obj +<< +/Filter /FlateDecode +/Length 4752 +>> +stream +x][$7~_1Hi|)ߤ + " .:ၿW]]=Ndv|)>Wy=l?sIΗ'3`_-JS%pTK|?KYONXױg7 1rJ&(^a0BTXNb) bD1䠱 9V{V.YXÖ5:cT1D)<GsqE%lr)&j2CxYB1V,x|N/BQy5^,) +/CXWVyDc5^S(HLNys&L!{o4Smz$Ťd&Y7NyBxSΊ:nox8HAL.BqIDő.2e \.5p%LKp xYE ,UyҰ;ȂxYy <Ж`-x-b5,[26jXhX>GҰraJEN <@4,@]Ӱv=azFz*5,:Nfaw5I v5,L.gaw]6aw]p A[.awa e5B@Xs^469%-XZM6aAڌSye WZlEÂB5,]gְ?aEuX5p׺b4,] AdhXmdJ.`iXUx2HC'8TÂ^4,]װ w !QygaඊO#XRh<றa5& "pM bb@ QӰ fJJQÂX xT^p4,HRyiXz*d ,9 ,4,@D0[M E R԰H6BaA +r\ MDbar)5,O.iX1aA*a);DB Z ,5,.#ˌF%jG̬aA8qa&RANH~l"QyҰ gfְ gӰfҰȂOÂbaqѰ،|ӑK7H->r4,(YBY4oI7N/BWHÂ#Y7ѫ[ͤnwC2i<."Өa.o"r{ ̜qfuzVu{Z%u|9GR7 &2],`Zn/1a¼$"!ảY?(6}OԝǶIӘmW0NPCĵQAΈL7dneqKx9 2;q9R +J1|ɤޤ?;g9_y E-}vNXyI)>0TF:2xCy*_Rz&[.P9z^jN yq>>\JPQWB*|S~/ٶ_ ҟPߜ0 MD~cIﺟ|8/'ϛ|i @Rcy ^xM5_^yqYo0ZNVd/ƥ oʜ,VNdg_/=.޹,KNogz0),[F諵|\s U D۵lMNoY֪ak,6-Z#[$ZC# k]sRK8bHȓD=ת,У3 wr=;>o,\}M0c,+}\O)Qhp=[hsmCןo.jW\gc+{Ymy/ ;lAC:/-@YNj@eKL#MPM`YFM֣Ҭq[)1ܪ Uik4SC:M3î[ 6y]nyX׹9/5>%!.B g-DdG=֑]>>=aUMj*GA>hօO6n:p|@v? du-#54OrY={e]:W' ޼EۢR1T:sϮ'ny]g v0l +kxJާ2_gYY}q" lfZd-Nf}R&l,rvs5ܲ[qG,X}a3)Ybwvo5 ޼kXٵ,Vְl%}g\=7kv<ymy`X]p5Yz2,zl6ZLE|ٯewjygW77⸧JΖGi> = +wCޖ>d[|mpHGWGl?_QH{#"k)E=܊z~lLrhzވP}>,nDطst#gR8A?_x~MEn`i7ΨQ$?iĔgRah2'uE8uk*寝o6 #ǙhLw]bz4aiY3/XcMS&"Ets<3?,OM烚y{ކOt-.'Jή] L +h8 2Es]}>Lf8b]hU`i|}ܱBDhdBGV/Wg;q4HhpTIbn5y,?Ⱛ.b]Ίoe]yx9[>T~PnkiI_y!TJ >O +o0idv5~L͐+BrKkTZ(}Wh0&~5o8)zQ= e':=`^ǝh:r%w :?6YC_ǝxMJڎs%1  + W{ }f,oM*\2KY4+.:tpɉRtXd+1 e'],?ɩܗa_ʦBAl촬Q~{}y_DڡS%tq}_Oj;4|rkЂVF5jK ;F[uF-&S\5gUKtҕ]Ynx=Z= +Ҝ%{,Z;FIhiw[mb4#25Zؕ|wh_ y< 5䝯?dr'bk:J+{tLILKr!j?W+Fc +P?c믩!/I̿h׷oClS +endstream +endobj +676 0 obj +<< +/Type /Page +/Parent 1 0 R +/MediaBox [ 0 0 595.275591 841.889764 ] +/Contents 675 0 R +/Resources 4 0 R +/Annots [ 677 0 R ] +/TrimBox [ 0 0 595.275591 841.889764 ] +/BleedBox [ 0 0 595.275591 841.889764 ] +>> +endobj +677 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 101.433071 548.554475 101.433071 529.804475 ] +/BS << +/W 0 +>> +/Dest (cb121-1) +>> +endobj +678 0 obj +<< +/Filter /FlateDecode +/Length 4591 +>> +stream +x]K$qׯM ae4l,t詝م+`}L>23*+g4=ꪌ#bs̕fJ)O/4EOWJ +xE5q&? )foc>_k87똫r/n)F ++E), ++ CYcA !5`kJq4nF b29%RyUxOJϚ)lʋh5sSlxy +!LFy 3i<.E Td):!vKޕTd@Fe7U^RL{%?iX `q +8cC0p9Tyaqr&9  E id5,U'aа2ٔHDawm94,`rw'aw-۠ae w!^ VYa, 2Id iXMBiYK7Mxʼ.H5, YȐXd6fx/R[:]VXؓu>h#>ᱏ +F]l_`f]0O~?}xw=GĉHXL|ËA[>{|_@ 5V}?wWʄޅ𼟟J3M:ZD3;?-uk_aehyy0^+)85vqvmPU]2dŕn8*/*Zm:?PhKn)[{a?R|\ȽdZQ!2y{0Q˸iёt8m m[ZxY;7B-/Kq k 8E +d5M"zziWAJiwrJ2RquVM{47y0pRß/ց+#S6s9}6jS}MʔJK?Yh_h섢Ң1UG}@iQ}2mCwGCaiji JK-ٯyqfZx۫g[y9xNl8#sʪ +٬UmJ!ϛFNѯ}^,xw+K`VP Z\Az EB,vӂ +wz_ϺR6dOX7.UY, [CI07zft_>ggٳЫy߸|'u}f9WOL=uޚAGw&nhZ|H0=^ױvu_5 e4/WyqhJkۍig< +|=Wyfx߽+s +w7+l_r7ӻ[31Ɓ'9>Ǹl;*jec~5Oy՘I@*= COxF ";cSHd7lŭþmW=q'Cz-<='6BS>YVOld>'cX33Qˡ:>cجs;{nm93-/AUEj.k=:GäUgͨ=)h|ڇV{ qOCiSz_>^ۤ¹_X 'nbSKH'b`p(c>#{r`ߵ }>'Փv~ݦ_}X]ꛊz8al]*vp+M_/9ç\TuldLL&|?}/9s58y+6Նj~?&;=:F*l) =;Y獤 p 4x _erkJMy`k7]gT nKEEyHa9j0Kx~y]fS!V趥(L CfzHgYx[ Ҁ<~rÊ)lQHr 3͉UnuIT3XsS\^s+%A"L)f?'ɇ݃TևN~ݓ{R,#شn8mIxZ>D^`PFZMa\cX!f0{&4)4Q$i e{Cq4HCwlc侧ЉMQuf0-k`#nݖRTծFsPQ}- N +vQ_Qma&w/T[\)E-曥b+z\5ERSB ]Q.$qMfkJvfb'?_|TJD7ȉt|>Ԭ4F~PU|0\JnOVH uXӀ216e)t[馱uP@ki^aU? +G"U!]'+rӷuɡaHFkv[YxKONV@:s!IG$VKYV3r3e̷xW1븥a:PSc\iNB4b2ZUKqR[Lѩ?Uh++EK@~tGGd%B cF^Uھo^]W0 Rw%_;]ZSvBLbfu0Jiyq㽒H+{2r9Fg]g0cT_Gj!LVPjjW6cTQ' 'Ao #93y[m׃` +endstream +endobj +679 0 obj +<< +/Type /Page +/Parent 1 0 R +/MediaBox [ 0 0 595.275591 841.889764 ] +/Contents 678 0 R +/Resources 4 0 R +/Annots [ 680 0 R 681 0 R ] +/TrimBox [ 0 0 595.275591 841.889764 ] +/BleedBox [ 0 0 595.275591 841.889764 ] +>> +endobj +680 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 101.433071 713.673057 101.433071 694.923057 ] +/BS << +/W 0 +>> +/Dest (cb124-1) +>> +endobj +681 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 101.433071 160.426036 101.433071 141.676036 ] +/BS << +/W 0 +>> +/Dest (cb127-1) +>> +endobj +682 0 obj +<< +/Filter /FlateDecode +/Length 4592 +>> +stream +x][ܶ~_2E( hZ}8 I %^$jǮ)J3 g5g KdTJ9:_ޝ~:iƿbqS_hʛ?c*foc8?vL|7-U9k7"bQ{ ,UBsXGeEA9y1$p۲2İѐĂ&(j- &rV$5*lȋh%s*D2HB>I<,>k#3eKoГb*kvMdLf.sY7s]xlAiO3ꄞk,; .zBMC46M -[y40 Oe)ـ3ٗ78m[&MZ,~[Np_ږvMm.ޓlн- }Ɇ,=^ҫmu=xeSսi/6m*:qsܶ,>g]]ǵ>lke/0Gc;_bO.sBc\'-e+/ mzk=MfIC6K}~-GG{reA}o.vvuy9ӊ.Jׂmϣ/g]M]q3wm%r&U~5гy^U2q! dtWVah;irnP{+7Fjߴ]U=_}o<2︙n'i"q&sC(s-'SX%/"lQ?{ÿp)?~G`G)>%ISc>:Ai>/idq覹yKO/i im̹GP[SE*F\ڵ TnT_S6P@gM0fV3'bD-]$KRJ=ktWw)^]x`#%wt5[4/'O'vG!Xx(on(ҩtYi|"?AoTFrajz%7yꐤ>l(;泣1t[ꦱuP@ cI6!aHUTɾz* fpwаy$fqG6y[W l&ZI'[F^@:s!Љv^N&ӏ2Y- ceAGlq_?W;O +endstream +endobj +683 0 obj +<< +/Type /Page +/Parent 1 0 R +/MediaBox [ 0 0 595.275591 841.889764 ] +/Contents 682 0 R +/Resources 4 0 R +/Annots [ 684 0 R ] +/TrimBox [ 0 0 595.275591 841.889764 ] +/BleedBox [ 0 0 595.275591 841.889764 ] +>> +endobj +684 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 101.433071 324.123057 101.433071 305.373057 ] +/BS << +/W 0 +>> +/Dest (cb130-1) +>> +endobj +685 0 obj +<< +/Filter /FlateDecode +/Length 4506 +>> +stream +x]K$ȳ15 , 76=t0ja?*BP0#cQ]I}LjJ)௷._<ojL1E33=_/uժ5tGfybQ`iRX( 1g1(z1|N$ 6 1YbhĂ&SXFCcyD{3$5*lȋh%s*DoHB$,xYx%d.E NHH d"%,pA띄h-8HX^ aBL-a W8`vJXQu| +8FKXΡȃ,p` ʙ$,]gtw1 +ʦ%,]wm tx% AZwA8h1BH VY'aSa5˟0Vʤ$, I0Dh\в2!d IX@]gZ kVj56k $,;(@ohJ$, .`JXUX$yQcJXX޳9 pW{="d%,@\0*m ,,Z,aA)aALI[ B*$,YOg j% ^*$,8k%, dѷ=,pq! "E d*e%,V%^*EK(aA^a)6`/&xᒄ<%,`HXH%\Ȃ [D#aAѠ&2+4PI‚PQL4"&$,}xM`&9"8dy$,H Xm%,o~3JX5dA'aAAq,a`<%,&aiLdOoF ,EAMY$7N/@9o& f`^<Hߌqp2Iw &"[io;$h@/am 4U 4H2*Fx0a9}!bL1-<ܝb| g夬5Ji +f}  ٛ +s1w p=fcFV¢6vBwc`OicU:E }0]Gc]Ioe%61PH5dV;bŎ"Iˋ |A5ʸlyb}>W)8(`9t? >Oڇ2;vi" e|}^۴x{?屙)Zh[ח_}1!7^-m}aMWd*GilZ~\d2G5ÅV])iV*W93z lg-+zy?Wa{4jPGo0[&`hOqUnS:=#Xd pg5jzsqU{^a([f5OF8x2l\٬S[_YR_E"w9z tz6\d7q?T͊;=qg{[$oV%mÙ *Ʀ_~˳{mV־5cٖy1.;z:i:^k묷Qe6yo2p*{)tyZҋO)6S[Ʊe n84a q=z[ÄU04;ΠZer(pݷ^};zע#9ݑCl6˜dT Yh{yY(z[DKYWuojŦv[uֱulo\?'U_K]zm ØPOqS{W֮#Nrll9a4Xh#}%]-Oyw5_;yHV3sMy~35_FS' QDrnNP@- bt洙 +Ŵ5l=ۢuPnCZOjTByTIK`1oQC ْ);t-j~0=VY"q6#V`5)y"~Myas.s0ClMvsz3gMTPu% 8;WI 77?h_(-v3_ C/ܧAL)# pՏ8W6hS}dg‘=KyZ8g !y_ZǮe;Xv{[?88< u˺XێKMƣwO'Tw<;l_=v zxKc5Uك<ڸt^p^ o5_6+5_=憏 t[y6oSV;/4yEgXs0o7*V\=/g:wsyqs_?,pf5s׿AwR}oMZsr4tx/{Ϫ;8dsqG]qv^R%Gq闺Әr 3v7}[otxSJ 6"utX)ɵI©|^wm73$g5;8t*:8N'tV~MO=~;yqSvNOzy4\K6)>& +6boЏe{Cqz Ҟ:*ƚB'6Gՙ9 u3U򥕵] BFZ7; E ~klj|BLՑ|+k9t֨Y*RWU]% asDqK/4[4om&v녢P:Vh7n#'SpcYi|q@5*#O`|s)?Nxn6VI#=4.cQ_&i5Ǖq5rs-S~0@MZN}m: E tc)ժZʈbN˨iҔHU®,[W-αN-L-}mu]#SݫѮ=sg3:HrbR; 7YW;Bx:4YD=;F14UZަ(Üޝ٠y7Qz 6 + +endstream +endobj +686 0 obj +<< +/Type /Page +/Parent 1 0 R +/MediaBox [ 0 0 595.275591 841.889764 ] +/Contents 685 0 R +/Resources 4 0 R +/Annots [ 687 0 R ] +/TrimBox [ 0 0 595.275591 841.889764 ] +/BleedBox [ 0 0 595.275591 841.889764 ] +>> +endobj +687 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 101.433071 498.873057 101.433071 480.123057 ] +/BS << +/W 0 +>> +/Dest (cb133-1) +>> +endobj +688 0 obj +<< +/Filter /FlateDecode +/Length 4514 +>> +stream +x\K$ȳ^b6 `CuM x"$1"Y3wP]I}J7r]p&G桱R6T{&lr>ev붎zSk.^YL.9ۨ*XǤ3b bL 1 y_V GV>;X՘ykUD+<MғΤR}Uy< L.:WMJ)G%V4^,YY(d )XY|Ae⡝ +dwYlN`b-D*gK.GxΙ *3 +FJYyȒl*` 1RyvƋL*YlN`% |Ά' | + |r  5ցBHIC a<*iXFLXvU;d̒yӂݏ5,n[ϟ|NYqp@+#0l{@,!|O"),n,$B1mn+2$f62􋥂BRe}s]ք5WٛQ^w=~#d/oV>:/>]{;vSxG|~_w?v^.'`?q XVF:oѭӣT>/t=kY,'mkyg2ۧ}zYrf[O=㷮~CRsc"ڱr]iMRxV >EֿP"q :$~%:o +cQ:;DmN3camiF~FMvKMi%`ͭ3O>:qI[7vaCXǖNY\/2w縮.{}З'┹ 8ݯ,oŧe>bԵa-G{I)۽6]_5]zven?m>oq[);뿏ehv|`uD_MqH˞~ڴl̔aN&c-,Cz\Ie\f=6}y~3GȸlP?5Ɂ 9::;u3彞ɤ<{nGfk3}CvNg VmZ6/yocwĻŰ S:BZ7w3 ^5bAE5х8dDL˿]v5$s "-FaMV~_so;+ߞ˽T!TyՎi[@A1Րo(pCCeЮ2~Z*ly[Il^p[ZTc5>1KT'|?brƻ~"INyssWdzQr?o& +cG*nuP`&o;E~m8` )p3xI#~RϨ{2/ˋ%5)dz ~W~ȱHݻA 'ԹC>T:3|Ǥl& IpH,<6XuxG|6cXvT xɝ5l7ZߗmW S}GVE7<U{cu>MSz ԉ22b<-۳mjLho{y<5-ʥ^^; ';`|8[V/t'_$V ~)7q9ox ߇6<g%wV"ZcV+}Gu>qO#yd۞@^roHZΐ*%[#[f~+mGF(;;^X9߽G"nĺ/{;7<3_pثB}xX!frG2nb(|ng$gŻd,01Vt7ɞ<K8Dsœg {JzS]ZBA0 ;)B |a5b!H4^N!=_rkkqX*ReV]S +g̗=9bC%ak[iI~Ĭ+l'A;NT^,05;o>8.7{̧ A*I@4(ϲB].R_X<(=4 + z]<[^7 a]?+%v!$ʯ3,9q;i`$aq״ yG;6ړKdnv&S0$O}m>[:ՓdZ}œ:&,wo ~rk.8@ ?uC,NF= ؟dWfؽaq^Ӭn'n \ISzf yő|mf^C /HRAe W$  ţN6bCNY~ܗxi?ɣfeӝF! A6LNvZ7(B{z}WSL>:x:5Ǵ}1'S}N {a$9sjԂ6Gjk(;Ntŀ ls)պZڈ> +endobj +690 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 101.433071 439.473057 101.433071 420.723057 ] +/BS << +/W 0 +>> +/Dest (cb136-1) +>> +endobj +691 0 obj +<< +/Filter /FlateDecode +/Length 2788 +>> +stream +x[$S̳a咪t1\xBփ& 󐯟zZ$g3*T-~R^/<󮔚]ow{SaWw/]5xy]1ty﮸V~j |SS\rHT*JT1CLD-T0#f 0jL3,BTfe +3BT0ט A`i :] ' ޥRC ρT]gRJ0X3]-ћ Ӓ.M*T[BtN%[]`$LWZ̨B'%G]bQERV&)e %IT[J`:-ӁQs)dU3]-!d:؂g HN XAq1 cE+Tg9+@Yq@C< +l ʥ:آ 4T`,P-@A[0(pkR=c&>1( 3@A\- ȅ+Usd,P@=3(1vJb,PpW c` tt2^2cXFB)X`n(b-TwC- QcBb,8Gh4!e,~]P4Ƃ포iRcAw}Q]u>cɺ(;Re,.6*e,.Y x50Dp+vjw}X] <o \ꪓZ +cAwX]II.;8g, e,H.X] CCuEK`,@\-YV]awEre,Hn6 RnP `C R1WsN +t.9#cA"EuŲ1 vUka,h9 \iz[.4?0؂H$s1䘐aT.W2pMu: r63 rw-\b,yc,`0`+r% 2g:[d3 ҅{Ƃ` AƂ +$ءKbΤ噅Xr-Td,2A RRl& 0?-َH~l"͡:آ J -, XP c,\  qD /71`]|0THȺZ ` J-|tb[B5ƂR7 c 䛈@ifn ӁLc +7ٲ^ޘqeig'F@^Vr$zh3YDO Bxp;}Z!c,dŲ0D#=nc}ooO#@k+,P1ѷkBp[>n4iCfwyr~wۊ]-|Y-HWOhpkB.8RT68as?"/n_?|?m^_rC~=p 5vQQQ'<5iq;H&a,MuEomuoζ׋-e簫_xvy;ƸY?.~{;XhُK|Hi?}Z㽋edcte#׍N\c{eU=ϺJw]9ɂVy7K{u:&9!Tq "8:zZ&_:'FIb nm 7Ym 䵁OsVoo7yhuu|)}^o&?{6ri{=y vD (6cmi{c'[Zs{ ~ym۪B.FO[{ +aD$| 22+lˮZGݴcEHB/5uL2Gq{q'9QJ8ug֝ {Et7=ecס!/!uCz/}v~ܛ꣋t1i5DŽؘ'"nDBzӆeZ~H6^wLQKkitu-clCۣegqj3) nALj +V.q/S*,.k9LCEFRbf'mmyVy16 y:^ߠ;j;I![v> +endobj +693 0 obj +<< +/Filter /FlateDecode +/Length 4368 +>> +stream +x\Y$G~_HN$+ B<^EZxEVefTU1㱽qowE_8SșRjNt|<}:Y梱Wgg)j* !\t?KONqgojMeK6* +uAahr1) XƂ1#+C %j,AU F‘U!ώ4p5f,pZA,Q +E3T_U^eB0)NUREd:!KtDVA +%kYB +VA_rxxh*Y`]EAx5X ʫْˑm4`5s&6É&d^dű D#•fK}?=9}I?ȇ0 =D\ tGVhI[Ӗ4!\[ "V"O'$ HwG9$9$ϕ< \jjG6cjָ+]؞6Ѓ2׹e-]ۡn5vZdm'F\tIn+ur%sӁ1Iޚ#2s6 YaB䘦$QPRMhPTS;~/oG9dv>!z;|o%/qrB[~;|o=y!v{NȉJEyk\ִξ<׬%}ng\Zy|Ri +^CRe}vWW^=G!cpʼY^rZ[ى뼏Z}^}式Z}^]9ۜH?wmὒ!*J(.wO?ů? ןY h!u4Zx@a˿z;nb^ +sili՗/pG2;B}m)+eW~벮2K6n\ v@q_mr)ef^IH+fl{j/li&a >~Xw i<8N +-Iuik8ߒ#krع}}wIK؋%15dYֵEXb02oqv*Grݺye؏2w[}=+F.kzː3ps/z&?SK_~gQleuri QLe'[ #\dBmΘtxԀJy_]|/֋<wmMXIG}E5҅8-oaqW+p_Z1'l k2]L ;f"i=2p{a|_J%/>oa}}w7#`7Z[\NϏe}òEV . L턷,/"^(dBtYz:ŒĦi?z}]v4X +sJ7 'v9>h64dWñfoA{XĺEWw[۹rܩw wsXr:9_]usJ:Aʸʳ[=K|!{ȿ9e~{/&aGio吝upny=VFv)ׅQٔQKDc*n'|2qQ5y/{2ϱ͋2 4/ʨyQFnXF-?`u;bVE&X_Q$>^.%4U]€mckb9DEЯ?!muLqJ YoqLBp ^qHX#zF~ɝ]9dvV} + l9%Q8nwm !.IwE#YH]~d(zVf$߯{tfcm y6J]ڏ]{@M8Op;'ž1@bM)֝lϽ4Z³t~2T׮PuPco96>)$@ 9b tCѮv +rRۭűSy*k횟LSe(^]D]2,W}$Kgcmv)8~4ql'VMOw2tUhv?]"*#Oh?d^IlVIꐦGyr9r*tG롱 ULs1H ؒݰAfX) &9S~ڐqhd scIN;$9w!W|'^c=MI&d8(LѧFu?YL?N=RpP5exD_,~ہ~`,=?> +endobj +695 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 101.433071 563.554475 101.433071 544.804475 ] +/BS << +/W 0 +>> +/Dest (cb139-1) +>> +endobj +696 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 101.433071 212.807453 101.433071 194.057453 ] +/BS << +/W 0 +>> +/Dest (cb142-1) +>> +endobj +697 0 obj +<< +/Filter /FlateDecode +/Length 2895 +>> +stream +x͚Id )l`dR6 !FYÃAø琯?{Z^{CQS%R DDrׇ7 +%m5NM-^%]-t}c)K>^Mqx˿mCk9rTBPrT *bqT)Rbʎ*s#`F*^U`<0Cܫ̈S n8*&R8IϞ.rȵ +t\ ('t-St +[R#t $V%O[TjtHru%"ixWuu2kRAG{]R!O|S\v)GaK\lIB lQy:p"I٭vK%Ƣ`= [dA1 E Z= +ڂ"bKAs+`K@(v-cD؂ + D`KTX [<pcJ= 3cRz, <+`t݋u%@]њ=+@]tut U<(+LcFcV5Jwc%Xn,8\] ؃@ݘ DcQcXG  $?-EXBDX p9{ +\[X]X>W̸o1ˁsn J<$p 5z,H. NjOrl C` p&kZ  ,E8UՕGbq ġ 2y,.%%E`q tضΞF(% +{:p4ܵccA.&c ǂ\5Rǂ:|.ǂB$ -uhҪǂa豠D؂c"ѷ(lA$ z,()#ìzC-qXPT `ǂ` EFD枎a ltcXP#lA4豠Ɗ,3%1՞N걠j*z,6A R:Lx,X< A4I걠hfXP+l=7-, D| `a`:"+ͨ /-߬ Mxξm-, –Mٷ`Mez,h9[Y= @޽oM dt."䛈lܞTjguo M8[+{qZ΀_ˑK̲f*L zEgf- BݏcVwT~+_syvSV[_aĆN/.h>P4LgNvoѥx> 4ܸ"y5|F ڌ:Ң T//pÊtYR7DE*1]_|?}ݟ +'z x^wt0Í^ri1z'sχuN=YJ^M7{hQ=uۖ^_~s˳ 8FuX򌏽_OZjp)w}_cznS*|Rn< >VO/y㵽]/xθذxcw÷ʹ-G;*!OGżO:{$[%r=D<<Խos(?LNtns[۹ݟ~{@X/ w}3yjˈ}o!:u ݾw_n0"X>Pdw\ޗ3mSnk.1ޭ/w1yym}~S?X_{XlwtسgH%o)"oׄԜ}2CZZU/owܾ}};j_ȒZ~[o~satyy612t+~ؗgSH/^qmMDcGxmtn!14>f od>2؞b9Jy P׺Y1ӽ8jjL]a:u,˲O .VnԾ]EZeՆ4cAt#z8ԻV,/fGvGQz;zKcʨUgg~2]]xG!-egqkL~M>\8ŏTiRwU(KC\i˔ڧ +[,wT!5lXK,AloyVyQoXˬL2|v/7cNe Rg1bCXUH 7iI҇M;ƺWM۸:sbV, B^ m߇?+k= +endstream +endobj +698 0 obj +<< +/Type /Page +/Parent 1 0 R +/MediaBox [ 0 0 595.275591 841.889764 ] +/Contents 697 0 R +/Resources 4 0 R +/TrimBox [ 0 0 595.275591 841.889764 ] +/BleedBox [ 0 0 595.275591 841.889764 ] +>> +endobj +699 0 obj +<< +/Filter /FlateDecode +/Length 4817 +>> +stream +x][$m~_NY!F9<ٱX!?U%Uٵ;>"u(VUٳeS%E:_>̔ZbuQٿo +gk(M3|R . m.eO:=l8O)d*`VSJ.D! FHhJJ bsYae)Yg%1l IaY93FAC³aPzxN1WT^&b"+S1dG%c5^,Y"dY\N^%⠝2dueYL4V?T^xc[ sTdk"d1)j4 p)MTi ಟ(SP2QJ^WD$ 97%PԐ[B\Y|! ,(aőװm ֢aܒ)V%c 1s$ < T4,\԰tI!: <`Sx'k4, Xmp[4, .iXY`Qr6peCp%,*/MAaw]qpבP&Q. $djX<5,@cCXaAڂOids͘>W&qoX4,],T^Â|f VTaAZZw+FÂE4,9LX&k`*LaAX'$*/M0$ax2C5,],EÂ5{ "pY|v n48 x]cRѰ wy԰ &&a; b5,ŀO AÂd@,Y(Kְ 9Ӱ 9ȂADS\ "E dS.DA/)'٤aAJ4a) 2^ᒆ70[OwzM3 i)}p.Uag +~/k]BqswQ>sǹ[ 4R8sO86hRL v枹li7w,QrJی{6.wꇦEvkcKc|:ZV[Fj۞˚pDuMeD Cb4I3Uceq?Cn>4퐵Yg};7|@hߎY5Yب*wfel|P,V+m7n(-WXAZp(ꤥEꖶlKo뙶h2~M+:*Q5ѣZ{q5)χGeb;2Vn}n1n} +^V(d^Zt{m ӅD6þ~UU[gl]r×PC߃DBC4|eI.^^o+-m$`ΈeI2!tn, o:{ |I=j^W"> ]Ӫ+ ;`A&Pd@ r'X|u\6s6YBn"-踹mvWCZ?%qui_oE4u(sR!IY[>̢wS8X|")>qe˼b1qW|࿕3~ڷ[gekfumXl]nZث]"WEYѱ:bECl7yѬ@5}µ̆g|iGe%Xr8]i4[Ld)i; #W_q*ɎOT޶cu*ml&€ya=K]#,ZVY!uSo#->fŦ "P#7-`Gt'~Jfiƃk+^MV]gdk~w3\bů9&>$~z?A\v\5]aIv[֌7u}[Y/7n՛LwϥFrCcqKܸo7 yV7u ir٥> r_pq +rfɶiU|f}-ȗ^jySᇇc׈:O 53O7]Ձ2ѸG"ln )dg>$>tVIys +5ݓyf ߌ'\. +pՉAeG]FÞhDwcI]uqRuVL+뒘[ -E[SMtBN d";5MO5rSHZni-JTUKe] +"U?GodCϵn܎x9!E>Rf_: 0$zn'g3ePSnk6?"t*#O`?y\N7;y$IuHӀ4 +uٔJ}aW3]c+P# 2cM:!c$&MeEr΢z;vHr3n!]ޮFԅd6:dgj7:!@aTr֎Nq8^N:en-sBFY([׉Ҟ4tp[WdA2#l(5u94쭤j;WС nzpxh2`ϗ c7p!> +endobj +701 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 101.433071 512.554475 101.433071 493.804475 ] +/BS << +/W 0 +>> +/Dest (cb145-1) +>> +endobj +702 0 obj +<< +/Filter /FlateDecode +/Length 4755 +>> +stream +x]ێ}I@Y ;1q;EDZDwۭ*^Jat>+}_z1oϗoOߝ¿1`TOpglN>Y@aə/'/?y}6CJhwsVYB A9ARsCyASLIR KU6E'`5& +3MKU&h+`N.*`6J:%#<K:I.@tDV;-wQYҒUXAyB-&tNt]Q啖t.AbKQnpHI:lÈB' l%Q[)#XI:0ZMݤHK:[ VtDAC%LMJ$`" 6(i!D&$ 3Z"RY/1ib1rEld%. [@"b,I\@`[ H\@[Vi/qpa@R@AF풍^J %BNQ[` HX.i$.] ##qzu`bTXJ\`&` +ua$ ,x84swSF 5x Do +q;[@`ΐ(l0pK$.p]0 cl5蘼#OԥA0nʃ>I\H}F fT#qjL-$%qop qA+@WԥA%.p]В"Dԅ@?T$.]$.]e:BH\: [aLYSH:aIU*$ Ʉaa5GKF+ɮq >=l? aLm_av5N<:ZЎGd#BjFjtFb3acTOm@&B|c; +#̶i(NJegNV\ca ?|{o?Lc|INƎ~)z~k_hۺ{:€) MtiݔץlG]?YV$ty4[?s H>Oа}Y^rXހ J'ҕ.dewptu5ժ/P=\@.rᗣLy9jy@pn!p YZh'*t{i׺CuS Dx 92x#ZLar7HsxE  fXngá97MO8l-"^)n ҳ7qܚ"w=6Fk/tI{Wz d~1?osX;{iD]:wun+l.~Ts8Tf\ZU~gwOe흍w9Z͆wZ¼܊$WP;/38op_áO&|p:42Hft}n0II~Ac?׵sj/}f:|VJ/jl!x_!x#`xt}мؗp-/ڪ+,>Fnqnƕd뱤yL[:2-?k +Ot+OGz~Eٍy/cWwbV}<:;|d&.RAx9;QGz܏}^g +XDr/dpetgáOHS(0D=͹Agע} z3_vm)J"e6Zw1!+;A7d:u{gmUoPտd 鞄sQ˫k +b=s8nl^ +y:<A_{. 6\ @C4B9B7{.<-}{Q*k|e?Z0ҳhrHܙhHqw@m噦(zs(Ś+ + ocXw9BXkw+J^wk[&VP@lugávzk1Fٙph現"W;860?!ڝyڰ_}/7*%nyY\XAНyix\w=鵷4ԲXcAʸgŧ4= 5#W+r1T@t9t?빳?}g!x_,tAˊ*1-V-{XRVǥυaYJDz錄heȯrz顝y ++ֹQu?effr4܍~^" y 3[QHi>]{3 +?Ot`gw#6+w7=qvzc}y%㊲[㑯 Ҕy"Yֵ3и3ڿj0[\&vq?Xv]H}ݙpH~ou{ жў+m2D^ݙh(NWZt]wWlg[ υRvzLo3I6#_*5U`cOiw97}wJ`qy zy&oɸ|4,ގ7l7P;EQեذs܎jڡWMM{=diQM9hSM +bkSOU˲$ 4 OInPT 'W~W&w%[ƪ}^ Bz)g=qWS/6C +mEx, \``yif`>JU¥IJ,C|PokZGiCvv1ʤe8^-Yet*Zb(6)[iJM oi{6iseƫUq8vvddRRR-l{fa!yes#c皧:H ѱmlj@);{p͛dYh> +endobj +704 0 obj +<< +/Filter /FlateDecode +/Length 4886 +>> +stream +x][q~_Vx?8"N`aώ`6:/Jj9vc33*^ǯW4Stx颦~jEar:?)$g_p'ZW3v׿*S!('TJ[Aq^Py=)I*ڪ̠dLTfX +nU fIR \TZmu0DY#贛<:K:'I.@tN>vZҥ{#Ғ-dctXo-&+l1$"l-+-钝\D.Ab[QnrZ%鴞iEfAg`W.:2O8bfmՒc:؂xآ(3hb^80Q2$vHQbD!XLr$JCgDVG^ba a:bI\` lA -lK@tK*i ,X.TX0$.\@)I\`)qb ,X:o$.]KK\`"-`h%. *H\@]L##qFudbTxDExQ&A+qwC$ 5N kx h +qr8[@Cg(l2K$.p]9 tL^'Ҥz\I{$.p]8*+q> H\SK:6II\äH\6i芺4 Z2 O*ID]$-qxRC%.]$q*ga-6 @i+i2` +IU#,J$q۔(q  |)%.IAO N₠ p,Q[(dS b ؂ADS҈l\Dɦ$.c=^tL1E]N B XK\1%.O.I\3$qAHSE)DN ҅Nk -%.&bXK%)^gF "CE 0MS:Ëm'q?Xlb#`u$qAQaQF`כA₤` "> ơSJ₤#֛$.f Y&x¼Mz3H\8( hJ¼'a vtD$y%.@&"zqK z3]LK\ 7Jk{u񙬌⎁:Vq@{ᭂg@F7 `&VыpPj%n(/1p¼oQy!gL辮9Z2l˟.|/o;eG#@ȩ In[(Me%jCjfifV"7VBW.r5W ɥXև59 &HA˶v}:Ig3}ѶhA-| + xDil2AAX(Z%bżO_/;i8Gx~O~v)E?;.-k\;y|.Յ*KnCy]i+z(K\WM9bkM? ZfڧkPT%a ` 8>kp-9@X4}]$j%Ó6Ҵ JϞlŊفLO/j;kvl]"f|.!9J78#.lQd; 0Fg}5MOh.o*7 7#O\lfc68%ܾgX\MFڹd4jr6B]8půqvbEw6qm\wel붍Xn֟ߋ]]k5NKd/\go\۠a9 43~/qx1K=| D`?:t*8C>1p wʕg 7)WۍRnO*c!C^w7 FnƦ K*%{)槨)9Dz{,? ;-jMˣKz%h&E,@C$},e[븎1D9-/fiW 2N3MDPiArƝ;y2ϓ,EwueIsލB`f:=%얇e lʨ13rrtflutx 5֋uˋ.qFggT-a !Ψ4y&PBM4bCG)p`ѧnl h6DO 2˦mt|f_R2=;( +M'< Ih8P}!4euLr.;/m6FӗyZdVm]K9jsTvuH]8*p,ĚydC,!JNVb[,x0=|n,6|ڄ|cn75F}Y[ԲבH]kڗ^v\PoaʺxkGNy:ǠFF[ae]??K, fz6jufmp ip?[wFiSU +»I@ܚݾꪇWpޢH[' /w#lyԨG!PQѵZ7{|l9o1KNVxcU\|t;vW/:{VG܆Ͱt:X8i_|p43 ьʒ.äsNu?T7H(~4P4c)ǘ<緽,\4Oܽ#fQղ80 SSZ7c;,7JJ6~ # Bz+֫I/bƄ8WSXO +lUm {4avojzu+OsJxZ;JE)Uzר*QJ]IY8 E~Jфnm0 QMJ:At\PSŖ5o4X;^ݺ#ʖk1cb.Ll Bj׸B^hr8& tfB*\2*}Usם}ez@Shi!T\HϤ[S[I.!*yźJT셪U(NWS2;Znʝ8jo-|޲cQЏ&6zVY'l{Z)e&qo?_3> ",}-~B./Q-L֕d5񤘿ɦ鄆:ob[ZWP1_Sˮ2^ZvbSkzoC/@kǦ9Җv~mr +}sp6|'m.Z2]F\ⲫ05Vf2 Jj׳庺.Ktl_tVtI/t_iZ#㾘 `i*}掠a,'Kmsl>&^&oZ枭AN-EN[%+"[UZE TC/JGB)}O~Tj'~T&-[<^l \ZZKFAUJ--mݴxk jmR~>2w<îIkl@Km> +endobj +706 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 101.433071 401.373057 101.433071 382.623057 ] +/BS << +/W 0 +>> +/Dest (cb148-1) +>> +endobj +707 0 obj +<< +/Filter /FlateDecode +/Length 4737 +>> +stream +x]ێ}g+~?8"Nac# C~?HR3vv0;*^JbIjɳ;C;s|<}:[cޞ0~2`@G;?_sH?eyVCNI{2z{aUJHͨW1*'b +fXoY<01XN3RQz0Cyi8̐zF%JVC1Z1:iAwN"I8փFZb+V1̺(ҹqQi ,x8. ޕӁw E`9.A +@A8.]В^xL I @ƃ@q½G xWX9.p]a:آq tX̚F:t]!1Ü+8nr8*p\Dw(C܀cqXP- XQqWE+qW!(}[)r\&B4ocUN<{3K = !K G؂q\"sN'a l B'%ADtxh%1ԜΈ *r\e&ٶ`&9hk8.Af آLMqAQ!ơ(p\uエ16jh`E` Ȭ[p`'N`\o f`M lk#Ӂw: p&"[no/@#>!81^ ʦ ʳ9M{$6i3 B)6_cf S3O', F)?|٘)?X 2Pm}Kvh9B3Z禎)As- u>‹OcG +ؾAbU^`CUb'@q0¿}Pg+h9$_b3l=xo?0zto0}Nak/5`@o2랖e/)WY樂nnemdǤ965φ2iǪ.5Y>xȹn,lщ/Bo?:|cD:ADwW%x_k0m@3TY2| 7Z,aS8A<aff6E~6sUծ-{ 6%LrW1Yh V')1#!ܮif4}%&Ĕ_".+$Yq Q.KS쿐;w9M|gr"IvW[z\K5±h˴+4P=`PA*ؾ:CN qTT0x5)˜ξ:CNh?z p̌ڦa>y~9&T/Aԇ)L(*c -Ŭ~;_JΗuHu=Lqs8UzC>۩LG% +] m˹fcYy]k+mPVMFC6PWcDRSPWpWjwC9鍐5"J7,?w}yOQ(e$KC`_!/xk%2ٟ+{"TϑԟUم]s8]C2c#̺9Fz㛇 N!ٔ2C2{WsqWx皗tvp?_sYa1s4$qڛk K+Oavr?;7PIr}ݨs8Tޖ|!̛ŧh%[7s8v{zK*;ru¾tn]{nqOws)I2׊ڸ̣ݭ>\c2$݇휡qL7z֧}b;KهtcBiͶ̇)rOt<-us8|DF1M6GcG{<&VmrdGt9G9㕹;fV۟7~UdtE^Yh;YwnWQuqF쾗w\s8TDWMqAoJGzcw*I}uq-9ݻSPvܒ.(lnS:w/nI]WpH4痣\-US ^wǕ:GCyZ4\Q/E!zG_v< ;25Wѱz:{9j@}Yp ^}'!VK|IeɓkmZ7ꖿ@:CN<{(~yW<Oft9}S]"6u@(Ɂ0Hms{s8xMyXǬ4)wCSte=5Pa.Wۿ1ᐸ7}${ܶLO0mk ޑcs8iv+$[{֦6jg6\oI- +hi:Ck_<&Oc%^}nXv\_áv'zG\xk]J؛]mI,|^ȇv9vB(<@3uLo}KCi5fD+Rzʋez +3jFTo,x'p{ޠ𻓛e+ȏD< +MLĶמOC_T2(a`Liҧ^kY_sgy=Dnĭ_&_pN?-܌% dH/rD} /LKq"34qqi5M[ruiY'M!Oe;5 zscX~/ڷsĞ KsXMۧ# ҋ] }<~I+5~*7Ҽ¤`.i'͐?-mbfjup(J[FEv!%1Ƶg\-eƈ\HY:fZ^ r7†AGb]ڠekXjAv-*V&#й*,ӡdsYt^^NVgVCʣDibT,RK 1e߉ܴd=6I2L)s9Ft9l)_JZ5摯TPc4K}z5Y#BKK3Z^N֔X'ҶrzTIEDKOXYޅib4R}fvf/]aÍ4%%/%`'-ˈ-dȈl^"BK,+Day| +WRF* qӖ +Μ$p*v;ؗt.|^FfZq~ȝTΈRJϣ8N7"x4Y{9ui,(F4jsK;5Y4;B,+-la8KLQ?БtV Z:+nU6=^t ,g'jKFh"5βufwgrjd*j5*yݳv:Mց+L upFz9p'81%\:#s%'L`^o&> +endobj +709 0 obj +<< +/Filter /FlateDecode +/Length 4922 +>> +stream +x]Y丑~_;Xw nᇮ15~ؿ_H!*Re r Օ"_J)@.ZEo*oW)*orH=\T1{˾Ͽs]\9X,r*X,m^h}X(b bH1('/ YVq[V6XdѐXED +X `Q +8#%, s) Xr&9 댎pJXYU atEٔܵIܵ&@E5$, rwVZA(hB@Y'aSnk2̟Vʤ$,]0}"/+1º(+Bwa L,wx]cw7x M yY霒 X ++$"/*(`4P p=KX;'aAj# KV5a +kΪH!`%pW%,]6$, +^ $R9 aA<|"/(\{ DdHV$aAY+aA.T6@] $pi7JLf&81Ѐ^* 4*9 IL@LD)YU0 60gU:D&31G+v}wGw|Ŕ)+?T_a، n8v 0ws4+Y!* ڈGX5p掁=S0e+d}sC#||,k6HoC sݯ(Q_7N'+Ю̓J`l;Xqٲ,"Ѵ*.E9O_/;G_.~_.B_ 燲0t[.kY,7ÿ_ʇm6U~Y8<ܫ뮽cz/^Zi "ੱ|j=5)(61кajjyhsSqUwBf6SyWOy6%FO=`,2]z&9fP}MfDͺk7|K^y{C\Y<,Tƨhzi"G5^XfHӴq}nU܅fy7cV`{ +NNa;mǝq'ӜRXs(CL=W4[g3㒤5>ߚ5hthT돖ڶW-mTvp^k[LUmi+V\PIBcGyi}wЂ +ӧ_;^i̎8襰lִGa\/ٞQOܲf|ѓuM3}_":nw=}K$S!zX?z:ui}gǑYz' ޳dЃ,k^i+t<_cf915Dg٤{YMuSy7~;nlZ5rn988֦/yK]C[GKK;Sn]7/Gyi}_=gqfg^|g-8rYo˙h~:O9O?;U0ۂ|ee̩n|έO6iiѲ s~ьavo^;mkRS}t{}4H;wUGsŲ|Ǯ/\e WXZoj:ϦitN|ZG[b$2bL%/teV{Ɋs#'Nhv"#kL쥟tv"K3h5KffF>bf6̴YkO3/3Tn י)3Ve,t<xG-Ցq }@)Bmf%ii 4mMZS4Eo6tOx(GW:piem?̣;suNc}}6;JKAEus?|ҳ.o:Mx;q֮Yir?Sӟt;m߰Xj7㾷UX=f7W3uoU9b a(M3t8`r%,K{99mQ%4sf>[Bs)\Dzo&n9]jӠ_<$|{L0La!)cyW~gҎL&3 ԜZj /N_,&ɤxz"'[.N@m/|Ե- v݀Q$oض49 ?Z_RIr{"j%ke2CRn +UNBWbkVl~K]wlcuB#V3n)nH}^T]+uBJd$n.M&YTj\ E,LZ*|:6nݶ䯬ֈv̻u9mLA[xx+_/> +} +D׵[I7}iT~ Kݦ RyJUf%:$veb:ۏEiJDJؔvūޒ9ӭd%@ }JVڶoZ] jVoJ>ΐuJ)bR{= 5講P!_:)u7׹+fDJ ӡ9 ,+5URxKo!`No2AӗM)!T/#]_O|gpZ +endstream +endobj +710 0 obj +<< +/Type /Page +/Parent 1 0 R +/MediaBox [ 0 0 595.275591 841.889764 ] +/Contents 709 0 R +/Resources 4 0 R +/Annots [ 711 0 R ] +/TrimBox [ 0 0 595.275591 841.889764 ] +/BleedBox [ 0 0 595.275591 841.889764 ] +>> +endobj +711 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 101.433071 288.873057 101.433071 270.123057 ] +/BS << +/W 0 +>> +/Dest (cb151-1) +>> +endobj +712 0 obj +<< +/Filter /FlateDecode +/Length 4504 +>> +stream +x]ێ}gy)ހ10yi{lyP/J-vxޖx)ŒԔgO%$t?}8cɨ +gR ֛(np(g'לɟO|r2t)N`I#9]s:-& l1Hp:B;NgaZ:آӜ ˳:".Ot;)aNaDct +Xa-F 4l!q:{f8Вآ#V[( [` 8P q$ȓX@0s@68)Ő@KB@h[a"qqݒ %!- 3% 4(P +hpwr\A * 4hWh&)8. ` qqk pxHq\^Cq2(U^USsƠ渀PxW(Gxbxw`9.|A-wenji }>V̸E+qb.s\0* xWjԜ+U.q0H8`~tY]D-) 0 ƒIX$qxC9.]L Fk ,xWV[WÖpV+$zӁwp ލ&E^zstpXpn8.pbuq\z:x -Z) -p8.G0 ]]lqlg,chUNgy90K <= !K $q\lPS!* 88̙ŋ >9J2lL{zd? aLM0 T@wx-:ZF a=y.#%hqE#1rXSqľX#̶itP9VL1|ZaR雯W響C?87:vw:'1]ʌmSF[JҤ\)_>Un#n9_~->jwrGU~`z3Шv|Gͧ|{r#Z {Hs8^oᷖk4-:'oR |pk[ӖIgPjceߣ`̶Q֗p(#ZO4(R^KRKu +`iFV̈ty<2^\^k@ l|, ]Pחp۹]OWYuqADn]v]&ԽKH Mv9/x%O5\CeE)w稊5hwO1vv;fh_)R[Xg!%.{}y;7x6}(FgxFk pmҡ2jb~^HDzd"kqz1Ywfl6d3@ӖK]ԢPTd;y妳EMNVݟ*Wu5ju+}fq?TTj]%LWF,5)eĈ.'FHE:3^jMBD9]HĦK3\NK֐ZR}nxF6,uqjb{ nJx9#O1M +ajb/ +^4# ${'0Yg,q/N4QV˸ieK|}_&[uqh¸>nmdCCr|ok>{K +endstream +endobj +713 0 obj +<< +/Type /Page +/Parent 1 0 R +/MediaBox [ 0 0 595.275591 841.889764 ] +/Contents 712 0 R +/Resources 4 0 R +/TrimBox [ 0 0 595.275591 841.889764 ] +/BleedBox [ 0 0 595.275591 841.889764 ] +>> +endobj +714 0 obj +<< +/Filter /FlateDecode +/Length 5038 +>> +stream +x][$9~_QHk|HÑ]3 BH K35ͪ_,J|_JĘw/R'X\UISGw.L!9KZǟ\Zr},kD!HǰXRA;ϰbJ b`]İ):1֑aEalPfJCe9P$PZJAF3<儇=Jtby<43F`S/ kBx8exŚ8, pY4^, RqdKZ15OK'\4Fr,X ӆ4&4 pW%?fMsX*bX^*@̺>qXpT|F UsXSs3<Ȅeac3c^ONYQJi +@'LC0|wY !#u! !`ne!BrEGmE>Du>s:"D?(^֡*'|OkEs@-Dw+vvüW3~[N5T\E-OK,Y,_G,㲜:yeiT)&m8ʸe2YNdddnGLRdR}7|{γ0] '3= D0-u)V +WY$+@/LǗ&%#:Ogv nEL=N&,5 KPSSH0&ҧY] ot>Wl |qE:3uGܽ͌RV8Z;,Tn +p6|^CV'}_J+#=Ww?>wIZ"XHVhl:ԙvZMJocE%%y=Ҽ`Ly6?!+u`'<5XwΆf4m4H[{+^~_֓Lcu) As{H|_@,{Y~,[pnT 3͎dp}ڹج@:8H4?)Uo<G +-0q"IGޖWb2cUɵ>Z'-Wޖ`W֜J7ttإ=Y,`Q |`ra}nub"n_fymH[b-3 jh8Ydq,ddws{rlGzγY9د5ӌOqb0/X>֙ɌGjnC);YxPjݫ eD(=7ߠ7ՌԆ(#tydIiHesߓ +ɦ޽:Y,`/hǙVyq:f`GkQY;VĢG|Y~ڽ3{ܣuvʏW_we-x.cMntVһK,Gߖ8┇zǵM}n;ߩܿz!_$qcJ#q-ǭݢgY%ys3WU^[ +n=#iK;W,^yy?Z˜ʉgSJ^&+ e{~ۭ-M)͚7?FpOy:K;N"K.3\뤳gf3ƝyZO3U܊Kh#v +)$SZ$ulO>nYnYgB2=9bܒC,w #0C?=\OLe%{b-oˬsX,j<jU~j[8*m.5yJ}}>^UߥsfG^el49\k|~h cjsؾkDC]Y]:N}-;`kFػS7tp^jَAtRRWeɻ3imuy,<5t:\e-_Z۸R9pUdsn-]{s{}$i>eFq9U@Kz*">Y#>0v]^kEtH#%A͓ .> &/dqN6wUn[-jL6m>{V΋0g\=6P{& +oix`D&a܈ir2ڴXDmM5VUmՍ>椆Ǡ`-Ϧ1>ql0SE~_ 2(Q8#a kY~vUӹhK. +V1od5FkwJVvӛjw1"˘n?|;>d*:-){'yqAUVŗcGU9zZ*MqV0k>4JcU&U5=K>d>;z/Pٖxe!cv/d Q$gb({[VdnpA$T֏#c>QV|o]ʴ2{ 5ZP_jWK'--;HBtk$ MAESd[YtotkfKG鷦v4CJZ>!C]75m1Of-H|'fHKC]r5g*RqTMMCa&v3U +-=dH>.yC5ra7zE]+q..0 +Q!vr^5c Kq;TNS>(M**o[qlv&gӏAֲ{! +<`jT"> +endobj +716 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 101.433071 146.373057 101.433071 127.623057 ] +/BS << +/W 0 +>> +/Dest (cb154-1) +>> +endobj +717 0 obj +<< +/Filter /FlateDecode +/Length 4571 +>> +stream +x]ێ}gy)ހ10yifϡ$^DZ잙fUK<<,բ< |.'9xI S,.F7u,`9rteg,ȳBJOos0Q38eTV80UfPS R3*349ת3ĩ` 1*)`TB:"bt n9AV砓Nq:H`5l1AHNg`Dq: [Ղt(N`t]atA&x"VN 3tRԬ# +dS +Xl1Z(Na Ӂ'v3Uѭ:؂@Y"(#hqrn#@<ʇ `q Ct9.C'Az7q\qכ゠֛X16hכ@EauNS`-8 ME XכXo£gC>7.ft]x\` ϖ[ qx+NF `neC܋ʱ1k$6h3`ZR +6l h SQYa.d xyQdS|N_<`=ӻHYp +@t-qb9ZnI+u%As-.;?,,,u>NQH^hۃ4VC90k1Y|c4X`"*R(_AĿshRjcNʜ߼?}?} +yw\+_\BF~טoLCWeNn>_6\^SNYM*7o_7_Eb;41¼‹o/2J75S-QFsxWhJk +`DO0!2ٻ.2i8Zby3^chŠ󕱕wj;veu;X yidpG/I(z<5g*iiǁ*7c`L})X=> a XK%/APT̆} EMV,tˎ`RGFddj\s9 j B:-e+3VMTSdWyʾlFoZuecmKo+N}8]']vǴi  =VeQ)civizd˵ +SU{ 7PV1mbVJy>hWVtS&5"8tC]_q_yfI YuqADn]v]&Խ3||g3y/Kd,?WfňPM;ʣU[lܙph -U"~w;ߕyF}sy:ޖm$ʸY+jgn6f*o`wnc2rMjs8}l wpF_߉}gkݧ2{,s8|xFK5c}jwN] ޱ3ڙpDių淣8?݇@ѻYդcqwgG=k|0.rw,k<t"3q=&|3]C;=tnp1rx4[**Y+B2w~bD#\ Un&O@.trbͥS.%kH-_L)P>7<#hxk5FNb{ nJx9#N1M +ajb/ +^TIOTa42! _RIYlZn3\I[5t.cn/>nN[l!̋$c)uY),OZ(MB\4y2++\n̝Olo.|^ƉZqOy+UbH >4Z3;3h2ȸr4NsJj,y|t4+Ben],V;$æ*h/iMBCǕJvQ=AeBSڰ ]%u2Ҵbvd7ež.u9TII*\ԷK_tLH\ŤeJ UF\ԅⲪ0fF@֕䦏S:U]TnDEGeN.$pu}QL4,a{x=gmQ=Kji(̈́Kxiyxoi\ƞNNŵEJK9+$[T&L$%dfسOQ?-m^ɍh^4eoIgpvDI}Il;KIu\ClLEfV){Δ:p JCtw:Uh2Vܰv>1 +endstream +endobj +718 0 obj +<< +/Type /Page +/Parent 1 0 R +/MediaBox [ 0 0 595.275591 841.889764 ] +/Contents 717 0 R +/Resources 4 0 R +/TrimBox [ 0 0 595.275591 841.889764 ] +/BleedBox [ 0 0 595.275591 841.889764 ] +>> +endobj +719 0 obj +<< +/Filter /FlateDecode +/Length 4797 +>> +stream +x]]q}_L ~ ^6<ݱ pED>g;VIS[W4V1始SWJ{wʆ䣻 v!/v.;fHUCPNP%&Aq^Py=ST0kR`MI*a* AR` J* J+ءR(k:Nd `$NK4x]tsik-bt'%`$]-]-@WuEy%]hKЩRg\$RN$00H>:[rIGH:-?<((Vg7)Ғcu/1E/QfАyI` H6J,`bl$рIn>Hi茖lqKL@X\Q[(Y K-֪%. UK\@ \$. 0.Eo%. P.$. p.;%. .{休@ddwPSX@:KZ ,xH\QC/q2kX p. $qK<7x8e$.]c@?J'+q=t$.@cAX"q'iՠc8>Q¼E/$qQ xT#qjt]mw78 A#m +uiP)F xd$.T0HZJ\pIUHUa-kô4A0*t]Bw۔,0Q8 +6h'B>Q; DlJ\zH2F`` B  I#p RL6dyЫΛ!е qAv+`-5DLz @C$.i+qAHSE!DN ҅Nk -%.&bXK%Uy%.9T+M0- 0>y$.M,sDl!g%.f Fb qARI!ơSJ₤#֛J\yכQD +M,yf Y:؂) &Iyb yכQXo"S17.ft]D^`VZ+ de+(f ) +b@|ILL,pPj% ]p=STp1L}[sLh=??]~OdFPJ[W&ao'R41ggd#BԠ1閍3aNDŽSkoU>|x[2Lf'@q¿tPG+9v̇bw~ }z_to㱟mr3|?ߦZ; _29ې8˸Q7ֱ94Bk6ܮv+i2zl]ũF;-O9Kd:0=V=[-xw_|H[r-p*s= צXnA:ͩө~6〣q;>Xl +k Q$1DTr "D2fLgk&uURLp=s:m}_cg٨vhhya K#xwm{#VvMyf˽>嵶 3k+&_ۼF:Cv5vDn[I_am}p/pakGW|]vF:CNLڏxX!@1QcM7:#ݍtM_[zɾHAFIP(rW9jv @ټ?W:Ŗzz,ۯ 2:E-f [A-CFCi;'GOR*9ib6 _Hby aOdC9¶c5$uW4mdh^CW]\Mc:@Ljj;]G~ŃvȯJ3$՞xQ +l!g^f|Q@f\l%;gn%֯_Xz]A2=1*1-V-.zXVǥEa9tw.*m裓Ϸfc9'-ΘFƴ{9w"[wlXqFeԝn񈻷]b[Qm2 yuQ7 ӭylGB+bQK=s:oǯ[kfvOT]w ޛ{e>Wygs:|NJ]]sȋ:܌w\ԗwwC"n d,K<ƣߐ>Xt܎5?r,ѐ֏ ^Y|ngp/},g*1<Ws64[.lgGxϩnJy'uW8wPw.Gl~8x֯ Ms:C`k5}\myrgUlgϓ=Wnܯo!3,r{i;툔ƌX?˟sCk4CKVfn|q"FXYz's:Kw{^jQ5okR&YrzʚIc\u:bţ=ոqquOYnPcIx鐸s-7zoKA~棴صw^ӎ߾G `Ql!1 $!^6ү߳ةO^a ߊ+.9!#rx!<,{0(L?o2 0v3^]֧eJywq +פym*$yn6񼓸7ֱRht tTBLt뱙uT$c. uM)OJ.Tn巙xӵ +דyZ7|F\W4{[ Ux+ XO2jn:N&DoE\gkcl4${Rܜ!g>xMZ> +endobj +721 0 obj +<< +/Filter /FlateDecode +/Length 4758 +>> +stream +x]Yȍ~_FqLa +ə௯7_/uL)yEv +1VKi+B0 ,'\bJ b@1(E' V[V&hXC'VCDQD<&{gc2It0NK4y]xY\RZ94xl Cy`%^,I/BXWyEy%^KH%T q3M.Z$֓mZAAK"8ij'Άjxv[esŘ@"`%0% $ 0!L I `(RP4QVD> -UőjB"DXYP@k!!+aE %xKJ{ ,b* ,FOX@.L)IX`)ab ,P:o$,]KKX`֢ȃ,0` JX@]UFF;V&&*&0aZ k.A]㔑2 w!N V{Maܟ0VKX:bD^tƅy -O$aQY p%,OFZwIJE$,9LoV0]&bwKFxIE  IKX0P ZȦ͢[+[bM~%ƾhVjaef!QVFm#VpV~߻OyjzYAc/޲;4GPͲoXpsu΂cj1q +iL\XF}\kYx沆b@{^صE;#uwe~v"Cʒ;/_BVœ[EUrR:YѬǠFF[a;/G+[ųVxY~߳r޻:Hha]xvsY|:wLcĿHy]K=W, ¹;wQx.&ERG7{͜#+;WѬ,Lj bX2dW٢.1˘KOb񪗦fufHkOeh>C"[bxC.dă{oxr(kL%3}+G<{b,3.YE#OK,)ܲՓmu'owa]vpz27xZºj= +ߐk yOu ti⇍CQYetVި_UC-xC{8c!hboPM9i i2!d?Ifrj[KJ{P)%rj㼑|xܷT`IB6:w,Q-^Mz!Zd3_E*5H}`xHVuD%F6TѼwUo*z: )kB7{ #U;"JSEFUJJ: TI =_74MFwڞrHҚ#jت&J3uZB n([dyݘ F~ v ++mn%GQC,,4ާU*#O>TMogVROuHҀv!T3Uc+jRAǚU2CXOʞ讑]5TuvugȾbkOu5o_v6_ٱHfӏF6zYGlk&Zщ_U$>mHmmn䴩B Z6Qcp}ThNp*b(2ZQK(j)ԘQkRQnx5Z5r9vudh]JBM뾋vAM"SժM7[掸TLUpԤ56}TE!/ +us%یHɕ=iY"]SrKOB* E9B4Rj9w):'#:" +endstream +endobj +722 0 obj +<< +/Type /Page +/Parent 1 0 R +/MediaBox [ 0 0 595.275591 841.889764 ] +/Contents 721 0 R +/Resources 4 0 R +/Annots [ 723 0 R ] +/TrimBox [ 0 0 595.275591 841.889764 ] +/BleedBox [ 0 0 595.275591 841.889764 ] +>> +endobj +723 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 101.433071 713.673057 101.433071 694.923057 ] +/BS << +/W 0 +>> +/Dest (cb157-1) +>> +endobj +724 0 obj +<< +/Filter /FlateDecode +/Length 4812 +>> +stream +x]]q}_V&Y?8q wf󐿟CHG̝VISW4V1始S7U+cPBr&uϼ!%o4r*A4 *.Xc3lNR kLTf 3LVR \TZmu0DYKFi7xttF>&D]N#vZҥ{%%-N[$l<)Q[L $l1$"l-+- .EkE]N:"tZ$QAAK8RFlt G!FadQG;>):?I\%` VC%.1[2H\`Hѷ<->`!&k%.c=^t 1E]N B\k!bK\r$q̀N[ B-* 2t Ȗ.tZK\ lA4(qA4L$.Z]-(qA~ȡ&Xi)ElMH\ɋm'q?Xlb#` 9+qA&/71f^o -$.H9L4R$4V˼ތ$RXob'D>7EMI$7Nތ zytx%0"2MD^x]@|&+c^qF1c@UL(p/Us +Hbfbe5[R+1m'Cό!_d´뚣b؟xW81SV~4E|i`!ָ|h=B;ZAS- ]fS=}>;/0daUU;M=6}-mtllaWiZñ0ocЍBi.;Uj^oȕk{Hl!q$s:$naeTHHzKR2UQСQEԖS;n%u(Aw?c8:wRve6 \ uf;VKCHS2758.? ijsG%?tqfpa񝲃6ZcuN혰Fn Q_TG>Bs:ėaދ  t>Ku¼L =n97ry]+CPo6q7>>Xt ~>|%>dr/ Qr_kQŶ˫kJF,={$P{P_}".|4*%,uܱȇs6سE$Ipݭ:|My'lF^|*w tLQmuկx.rhsfc?뵳eߧws:˅.vb#XV$xQ +jk.,ˌ8 +;ai+C94p+~uZ'OuNƃ9nǥ@-W5+vs?gK?*Re9Rwnܓzh { ~Yhϕ>HكuN{;{^ˮK,s 6yyrLg3I?ęկBM}j5"<:gCb~|>*:X%"W+gCѶ~vܰQ{oD9wS}8rn?ߖ+cVGsղ{']#Mcs76's:t8:>[/XM-sxrѝ0k+'ޏWD,z鐹I=يCv< Epl:gCpɥ{5}׼|"6=Xtɯ²Fd*X@{_9-53'*{虃>n}U|{9vbwGs!'uֻ/;DXNKY^y0 i;F?p,Q֏ ^Yz>ϳv{K˙`ӡq'GgC9{#83,n9Fhۇv<:Cνv;!~1S/o\К⺧/pwӹ=c]+װ.~||/z;!]󻤢"0cuj-*X1Tev0i/:!7QM9hK~uPGU۲1 /InPT'W>W&wZ~U⹟XKqz5I|5b3A˶[]&ńn)TtMllGծMXM]&.8-7QUZ*kT3*U+%:NvߩҴ`V=Ʒ0 Z.rvM:Rj*=LiPX;^}4IC~ :#ǹ(c"ÍYogLlⷋ Bi׸B=.$nGҤy;feT43A +λvNf;}e+eݥC8R(I=6.cy*yź3\Ʌ5P~NUkwWmb_Cq_`X2mtlgr&6zv2&l(.6${29C$|xy2__ ~ܨrL=Y~{{<(os/:mXFMc+ +7mU#RRWU˅! +]޺^{Ǧ9!i(:X~98MG%_Y8EKVQf H~~ˇ #!5mn7]dU"'M3{^d_f@Vj7.d)~~X}]Aj[ MZ(Vm*ImNZE TCOJW^ +5h?v|Tj':>*~Q6[<^@9Sd% vVlyn;?wWv[dZ5(=3wuT+Sᨭdr"`#K<\g;Ẅ\ ?cD*hmń7(Ҿ56mVxIu +j4 hJ? zRѥ*b'SC-C]d +endstream +endobj +725 0 obj +<< +/Type /Page +/Parent 1 0 R +/MediaBox [ 0 0 595.275591 841.889764 ] +/Contents 724 0 R +/Resources 4 0 R +/TrimBox [ 0 0 595.275591 841.889764 ] +/BleedBox [ 0 0 595.275591 841.889764 ] +>> +endobj +726 0 obj +<< +/Filter /FlateDecode +/Length 4821 +>> +stream +x]Yq~_Q#}`%^ k%V~Id>fU5.F"2Wo4Stp ~jEar:?0)$g\p|諙RF럿g)X ,rn +8/p)I,ڲĠĂdLXbX +nY bIbA \XZAmyDY#<%ѓ$H -UőjB"DXYP@k!!+aE %xKJ{ ,b* ,FOX@.\)IX`)ab ,P:o$,]KKX`֢ȃ,p` JX@]UFFXuz +QIX@]IX@]D^05 EnqHX@]CKXG?J'+a=xJX&D O@I%,p]a>&qaB˓>IXTV|F "wEx]mw78 F aۤ\WI%,p]QxRH"G'0D ,HX#M)/aO +<|"Ovd;@i?Q5~_Z%Zm5ZV mڞnD`s\oSNRni7_닆{zЭ zv_^iv:@gRp窼O{t=lTlH[S L]봔 +Xӗnv*^ uhβTy!QdGsDmXV[l1̺ږ+@{^wlw0,Cm5=f+YTgzeyJ~׬]}SNs|7 7 }54Zsyny[<̥Meo뺕oJFw\)^(:/Yf羝j̺byn`?w~ 3cү]},:D;˶oy7d={r>,j613n `$=kksMŦ].k_dL_/˛.e;_7>gCч+[vGT_ѝyWf]ۨڗdve\5}VBCSi$ːF䞞iwf}* +o~#or;:z_"77myG?m쩼d7-|`㪼!MpĄ' tR/BlT w% ,<.Т{>M1O{/sT)9L}Oc9=Ԟ_d~O{Gi 2iiٺWߠMR4u?6)b^"![}A8d{ZUdmRO$+:͚9"_+M qNy]:֩}xZۼھL-rڙaUR%rۜC0L兾5!q.^28*M|?ǰEg’u|Ţ>bf,M)=rTLq9s:Z?WAvgh,7y[O2)vKʮ39 +VH \EnZݘ~޻iƋB(WtNy/v]/z4v(r66"~=uQb\,K_fkumݖK;f]O2OSX6>ZҫS7rNy4>YݶjE-3X6_Vufgo ;x^YxwrwtcqdXqG[.ꝘW<~ym /˘7/Yw ?:屚ǫ\CgnK{O][kn_]P^א˺| htyu;+ʺ% +Nr][yz:~m7ώhm!z+/;偧_8Wz:gN;y[ⷛOGzy:燯,];x<` +k3Icf!Me-ߣ=vyqayuqz\X2ددKObj s5> k=1a-dGtwS%bL>=ˌ#jVs:|3Op{K~Oy8K SEk/Փm7bnj|bdsP&Be%:owb5hI"6 h~6GiV9W'^L[crWp6ט+LjU;,rfuQHW=?~cM6^ Xk_vKi$ 坒<\"[v5|}3M~dya8xbs;AM>> +endobj +728 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 101.433071 570.123057 101.433071 551.373057 ] +/BS << +/W 0 +>> +/Dest (cb160-1) +>> +endobj +729 0 obj +<< +/Filter /FlateDecode +/Length 4717 +>> +stream +x]ێ}gI@^ <fϡ$^D.LfUK<<, +|)ײ>8O9#O1יuFc\05u_\5# *i?*M èTB2sN˨p!p*aVzr0Co8JyFai'i +0C99̐8F%JVC֤4E[Ndg}P9SNK#9]謵s: [LbւMq: [Ȓ`uEyG ˳:".Pgךw~St N'egMbuQ$-V`!8N0gFINg`RN:؂@Y"(#qrAiN{9P>t9h@i$$tJrD@m9& [4F.-4` p\@[& l tEV i9. .(P +8Hq\@`]2Vq\@]r\@]Rp\D` qر# %)a8.@vX U^h 4xW9Luq*[fn2Bq\J+qҁ wA!w` )u +n +?fL:wGIg-Z xq\`Oq8Ì8.0]I9xW 8.0] p8.I貺Љ= ZR`:Hq'r\`+ +4V[+ @aˌi8P` +N=Bqi@y ``/Xq\`stpXpm8.pbuE;q.P8[H) -p8.G ]]hO0Y8cCr::@׬C'Skcs\q̀Nj \-*`*꼂g$lq<]+oYtz-GD#\(FJtFbaw}u++,V+ ,0Z";r+$ :Z1@ee>K,2w/_?|?F._J5~w6㵑5i7FW?V]BO29桦N1狿vP:;3ޛQ1&Rq}w8H!ckk ai\K{(=&VHj~e]Zs.uJti5tZ؛9lruaO <|xŨ +SIgz(2nOhlgd_3vdXE)!Vů$w9պ/z%t'=rB3Z|27[u# RVQ8\sG5)ncU>]uI=_C$rhK +{<~+׾<׆gt퀋*{>su?TϤFn#xcrv9ֽ#=Kfϣ^Amy; U?ݽj|3(ί_ݷBT<%mitV\`gӡjûj∳@n\Gzg wsu*ڴ~=1׏NA-X}])9cF^Ϧn +6ݎ{cMݤ݈HQwŗ(pSvsVݗtj#i8%r-ϢUS ^}BDv9B7&Ey ҟf5Ovt{h>fd.kwo-ܿޙt݈ ^}%!fóY+>O{`Ey۾-.W ={ܙtgO/lVbS|T_[ڥ/Pl6ڕ3UX\zs*|'I;k/j;#]j:&g3aw'?}{TS!|2kj]\Y@LBn[y>' ;ݙtx =yf!=ݮhr4];&64]D4q^5=ް+:?mvhlg=5/t; n_,tAqeFRjG]sgS7ۨkv<^ +j$ 3鐼R٪=xK\j*sqx% we]}4;aڙt`=iw}zg$F쏘Sކ[%zi'Ic LUF?a:y?z6(} v9~7b ~'G$ jԾi=+fE؎z]&qol=gY; ~g%?mq.pw7ʞM,uEew9R7It!cD n,r9/YCjbJ:oQq>N6@k+ܨv1:"~Ǥ6+IЫT^i\04,didRrU*c3Tmf͵ԮK:1[II7-6VMV]HE1ˌ,'se-TW&Cy".v oĦ[qOy+UbH >4Z3;?~,qo.4Ȩd<^6(Ԟϵ4Xf_es/--ˢjQvr(\dRdJD2dDlc,{\)M+M+v6f-QvL gWNֹٗTd4^[ ɆI/{ۍ +endstream +endobj +730 0 obj +<< +/Type /Page +/Parent 1 0 R +/MediaBox [ 0 0 595.275591 841.889764 ] +/Contents 729 0 R +/Resources 4 0 R +/TrimBox [ 0 0 595.275591 841.889764 ] +/BleedBox [ 0 0 595.275591 841.889764 ] +>> +endobj +731 0 obj +<< +/Filter /FlateDecode +/Length 4936 +>> +stream +x][q~_#@\Ë8yWHZ={8fUKc)~tQS +JEQ_rq:?)fob_pɓ_諙rF_)T*~ Ĝ%UEr +f8cJ0úVaI*J+ءR(tON)lh$SN{-BI9ҒS8 Dl1)ZIawKJv99'2t*Ŵ'UNVaDBt峨-*#,lqt ocJh54ZybLt%0$ +$01N.'Ivr%LʓJ4`\Q4tFKD`l.HL`5lq$. l ,֩%.[tpaqm +N kX.{uF ڵ. ,x:$.p]kSXdu8*J\FF ɤ$.p]wM 1h%.p]ik (Gxp`%.| ,wu'iդSxN>Q'qa˓!K\ L'̨F3jK\8L&]Q'SwAKF“J`Q'IK\2P x{ wVUa-6 @a+i2` +IU=,J,qAҴ)qA$0I8! +6c dB>Q&\{ DlqI\z6' - -$.@D0e[\E\8؂HQ0ٔsDW%]0SkQQ݄XK\Ԕ0%.O.I\3Nₘa dK: [dK\H:%.H  UfP`ZtN:3I\\(T+M0- ?`&9X$.Hr3I\l1H\lz3J\lA'qAVa0Y8tJI\uz8 0.i$.Va%0n ތd[p>WX#dS_!FGۚ,˂Z~-r-0e}ԶSmAsy~"iBܺ)ttqNuҬ8,zڡm/K?6nF?[th<*G86 Uzu j9%3ljӂ9F("c@hg@8r;6c=GO3/3BI7~֙BY͔U2t#<BlBVoV|ǻ{ȭ=m܀[m Δu'/_9씸̊I. :mE֠#bX{H2,݂2?`vO}st䷼kfS`V,S8kY+mCX|2{TϺϨ#y>3˸X8FNrԃf8U70^:1S&D5d| +sTCuJ)]n͓B^ns!Ô=L}P=KOM`wNlCMkEwiw]9o:hK*97Xfq@䠠= R"g<ȁ6p'2=c2TZdGKPZ1OFfD\s)l% .j6.;٧ +0:tX<φh&O݀˭, +o, vawo8vcnjH[IØX7_vPbE[u'< AhUbJmK#ovkIX7>Ͻ]~͸-ݶo벌^ʩUاMY&'<*1Nn{21tZ8 +ʧ;sy I! |yyǂ2t?ǶR^?pHx̢;vqc݃y+#?ֱw<0RZ'`:G=s2ӡ8>m  C8+^4xyWOy:ǫ?_!z>Cmlwb_ʾw̻м9WJȖy~~=x4 +y:ǘ]hx^zcQ_]48dgCV6&z`:^>e"E6] P#N<d\s.A!,QXM͇ t73 r@pyŴԪ jsG'~(?2d$[`#guy/mtOPީ{uUH6kp}1_=IYk7X}Y৖jE/5ZnKJxMrm\q2/y'I|T,)*`ǔOjGkk(-NDoX"g[1^MzdLÁM tC ˈ ^(.Y[2+i' +Ku FХ:קY^tV$-;++{?<C$mޤ\FFxԖ˰ls-=ʲlC eԳ- > +endobj +733 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 101.433071 423.873057 101.433071 405.123057 ] +/BS << +/W 0 +>> +/Dest (cb163-1) +>> +endobj +734 0 obj +<< +/Filter /FlateDecode +/Length 4749 +>> +stream +x][q~_V~ p. sf󐿟HR3kgЧ[Uȏ U;S;sx"&ooR?Y]@G]_wH]ȫbtJ_~H*'QEԌ{err)ȩ`F T0(Ux3S gTR`u0Dvrht锜\*:i=9o.N98-6 +,l`s:[ӂt(Ndt]tQO6cX]N:%dւI9Y`S:(tN'lduj8-V'̸E+OҹqbX.3p\0* ,xWjԜ+UX.q0I8`~tY]D  -) 0 O"IX$qxC9.p]LVk xW=8._-3NB)8xWH0 +#M O8.`q f; \cun± ,( pc+آ+xSl\-9.M!q1*sj +tts\ཙ0K = )K G؂q)(xN8ӅNJ -9.*`DSs:#:3p\q V`JV[@br\X:آ ``37=Qx|D&s\N Xo*qeZo Xobnjۨ]Zoz -. +-p"3nIXo8-* si8.&'c3R[2_wXYÿZ},7 L @`$? XauHJf\Ŋ9Z/6^x~ +}y aou-aol.4Yda3_1&E;yúL\klgshuDz2sXǪf]8ٛmiX`bXށئD!%u!փBYuY)t]d-)[p]oѕt5$vhPfun7R{[_l݃a/p\^p0ـ#dW),h5?lRC@;ۢOӏFYbulK#Ď9b]n#m㟬N)CMGU %G|]\iˈK{Ze>14 !s,yMonjarQ|e>U$S/<w_Џͣa8z'FzknK|{/+;{":t;x +Y{n!=Zvk,3+] 6&ݡGoб&z )w=CUOO;Y;}yNXAˊ[5i +x`0ِ mj9uv:.x!;N{Y\]1 's:Lx=ugF=عSœ=zN.p?Ϋ7 XڋQy Yvs|$X (Voajķ}ƼVx낽4eHc>rt-+>> +endobj +736 0 obj +<< +/Filter /FlateDecode +/Length 3800 +>> +stream +x\ˮ#+6`d_@E AFp'8~NJR;׆jTh\R,-%6'pt D@ɤ|ǧNO>;g[)%z? *&rJ6(uB0)UtX!KU\rT0ϊ* RU`O5p%$E,pZUC,3yE炉31_T]%LLtCt [BNt)'Ma EH%1:EeteU[lN2dfUW9KLd5s&갢0I1):[ E@k:-OJ9+&KN}bU[0[l`%|Jg|&Ù>)Fñ$:ӈ,l 5& [+W*qy؂ϤqmhѸ@lӸl]Ը@0j\@`\ʑ5. P.T4. p.;5. .{Ҹ׸@9j\@]bg5.`.j:k\v42i\]r6i\],#qfQ` ٲ .@%5H0x\>Xqw=qb?Vq=t4.@c#,Ѹ w]S4ʸ\2OF\Yeb,.i\Ϭq8z x<:_!h\8@7,ꊱ%g x5.66IT]2Ӹdl,P "xh\6i\:Bk\:,[eM#X5փ)4x:̰Z+nS゘D0 +̦5.BOEqAP-X֦P$[{ -4.@D`Cn`  RԸLfraָ FUEor] Ki\XK k\ +lRѸd\9؂ [D9qAѠg2ո{I c+̬qAh$TԸ;M0- 0?`&9P` r [L [i\Pl4&k\Z ozָRYBMlu[(~3i\P( h*ʺ'a vte5.@&"z5%etx70"2MDނxCB|+81ߪ ,*9 =4Yf VtVMX/1siLQE!g$Y,}sbt9?/=ϖLY8KiF|e ; v|/gnSf9f`c+LfZ~ܯ8NƆu>+l(C d$-o +\8g=`><$͇wΛ΂ΝmYT_m.e~9ɧU~Ҷ[ kS\E;|hjӞo1?_lħg`JqM,)X% W)~XTd0.a{NbG~5QzDsZl]]kN[{ĎO?QO˩;<WI/E O͆HѸADZ&;%"2=hlAj$ؖq7l<;O. +# r{!orjU?0[KjF+@tHjg7%\u^sǧmK ݭɦ%dj_isWq=el=tpY +(X0u@qwfvMSҸ_5{f4 :۱mGL7#9}6\V= ɒҺu v D7wZ+!/Mwy8ގMk)B2z}u-=ۄiXwgWIky<@+\U/}uucӖ]9)kw@?my@i.uHy圗;pהVہk;&Sti6wΣ!nǚ9[3٪y՞ϝ'^y9+h|A\áN3\D̶M2T/bΩO.jӊs~EF?ggw+~l=:;gxM/FFhC̓7xzVb,_U]e.걇xp7y8W:~,evgsJN(lē䇉#ʢFùhH;"no%w}ff>so%i=ϲVD K7OpYa2<~Λb1o#t_CҬ2yJH?SEhRaq/oܺLYw6Uؖ <~ˆǽ{uۉtA]ӎp]hpCxF2:7aO^!y`ZrpK>MLv-"NFq:tXe3c'm~d#䔺*"i<f7vZ6(Fxy}&ǺDڨIFi06ӥi9txhX{Ԃ4zh4jk0vU:F*k-jS\aY8ZLѥ?#YiYeZD- +#S:KX2+8nR%.mnH쑩EKιΔuJϒ q?(G.6ay}K> +endobj +738 0 obj +<< +/Filter /FlateDecode +/Length 3198 +>> +stream +x[M$ 賁) b drXwm=9籺$9ClQ%QD4LyI Z|y:?Qoq(lS9Ԑc/-jϩ_wE[zӿs +׷*Ju(#9ԚrqD% wO5r$ +5쉠Q,5CTx"{(ȕAbF/,PZOݕUbM9*1GOC)%7O&%w,CEȓAV=Y.\\tI'%:ݑ5j P:ܛ+QQ(ܘɓ2|]" +T#KХP d~<x"sm͉֤ѓeRW]0]AAyTk#8H@j=H@9HY0A,cE p 8AT$a l+ t+ԣ BM܊x\\R Aqu9qvYZ,<..3teq1plqw9R@qf5Z# MK+1x7e [)S@IR?f]PH=d=.@c!!- wc4*֋ϕ+,-b) Bd.y\XQ+' Eސ=.;o!\ו@5 2x<.*I\Y pq8P +x{w)3{\P$H{\t<.@^։i$“w)b=xv +xWM JU 5 `@<.(MBx\P:Aϕr reEx\:t゚ qAM)BȾt.=.E<.`?zBkW Z%`)`/|tY j. {]d{\L=.h ]f! Bc/ S{2!g6 4 &<.f;{\62Y<.h-vy\tI<.o~z\ S &{\I<.@\~y\ЙωE.%#EqeISw&ɓ蒺x\Kfi#ws3y2.2q +o"/llz3VȀX{f@ _#P;VS,Fr |L8vd +ܡblU~9V5~|ןO_{?w_m'eG}#k1۩cN0k2;Aӣ.ȵ܃۩^NƶcG;䵣͠3_O,`Gz,(\ Z{9~oXT,kt#/xD5~v8טjl;EfƎv\֌>TmCUyŷC >ő5 oE]Wj5C \Vׇٝ&Z{yKjΏ_=Xgg`7c{ YWϏ_>#f~ { >7>/|& _%~g)~OlTзU4ϯN_~ca>cyr{OYnr}v]<}GUrk2uwk>v8¼j_,E/T]n6z> \n6o_on=o+;1cfV}۾Qw^Oe~ogtu1ԭ,:l k˽^6 52Qbo eפ*CO_>\nm%O֣o^f7n'zNZVf #G7fSHRN#dئ}]У!>ۊnouyo/m\vvuӥFc^v=fԔWm`ٷg9s yaޟ/n=^={_l4Ͱ̓5~h]5mH([p-‚'), +_i%qG"kuWsZ8)y9[s֣}X~\4]LbWjkN2皚b$3mkYMne؂BhLߡU*l_L{:؜H/uij@sZZ{FN}%Y{Z$#MX)lgri(+_3PJ4g .;sƣ^jv-lrɂnufHaFac$۪7u<%ײEf Ԃyinl,?^8:7ky ݰ^'Z`b[2^K4V]K:̃(FQ4AMuH4/v*X2FhL2k6 +S)0ۂmXq\F(:}W΁): Gy+cq9|eX +G c{l;: Ť `4b:am͵R9BvVPW+̖x&@ٺs]Us}zjcc=aR̔cߗĎ{?IHljoIp*|3_zL5߸*\!߿uryx>"n䴽fVQ5my@zG(m" +endstream +endobj +739 0 obj +<< +/Type /Page +/Parent 1 0 R +/MediaBox [ 0 0 595.275591 841.889764 ] +/Contents 738 0 R +/Resources 4 0 R +/TrimBox [ 0 0 595.275591 841.889764 ] +/BleedBox [ 0 0 595.275591 841.889764 ] +>> +endobj +740 0 obj +<< +/Filter /FlateDecode +/Length 4786 +>> +stream +x]ێ$q}gK>X0`ȒA ݵ#?udVdeVOk;^ 3i?Ȩr t|:}>iƿbqQog)*orH.z1_wǜ9X*r*T*m^h}T(41gI3|$Kת3('/`YUqת 3l4$`> +*aZ:tƫNRYEL9"o$]V!$txC%l! El):IaEdA` ЕDlAI9 N1]'紤3Fy`Ӊ:x)DAgaK>:❶OxSղw;팤H`%$ +)%l%lr%lʊbt %p@gDNOAbg` sElq$.p KN%E%|K fj ץ@8P.%.p\tQu>X hQ +8#%. s)` ,qQ9uFG  7`Tp$.VMIK\@]4I\@]1NZ&H37xzm%. %$.PGxp`%.|u0eH\&c|lLA5 '2=.-zYI\$q8^aFxq%xج%.] ^A`~SF.+SwAKVJ'0 +@2F*qAbzI\:⒕q tp[*m FXҁwYiSY`0P! +D*$.YCOk/qAxP-I*$.8k%. dѷ<-> ؂HQ0JHcUIJt-t&J\#)LFTK\W.I\33$qA̰"q","sIg` l BgD$ ZXK%i^g& šp4&$.bK\X:[Tp3SFf!okm$ӯ0_줠iO'tk ~8!2]hZ4 #u)Ǫ.PA9l%V+-mn^n^U/0П2zoT"5Ίp3`9x(cCm0[H84ˡHX#4 TЍcsNC 8b^=״t%\@~*XZuMBZ z-U7 +GBMݫ#$ˑ:;_HvކOCn:ocso s7ѥXܮƎoZ"{Ҽ뭝iLUSF燌Q5vr0σ @Jq9bz"2Zj$m B2/iDh.Bւ^<0wXìZqg,?t<ZM^kWdu7PFNYl[t;j(0B9+QXʪMGgF[թA*,h1K\7P_RC<tcWQ_rTMR0* yZ9-¬6\֑nވ[@.wOGhh cW,_/FWx`AU38`C8xh1˭Q;6t=f$ou<Zw{zO6"z~$](["it^@+3y[=%նC4,{\i۴ƅh|,ϣ!8ގE⽊gq0~*^߅|A7g{M|߲ytVߚq!c]eO;-TCa|i#wN5ױ<c<]c&\ 5Gڱc}]rm wK6(`C({zƟ3|v"eyhJ;`?1=7]O(ȨJ=R'-`y8TDWO^=r} $Mx,!vv>󰆮 +)?Nh)/ݿG՛5s9~%7uY`kgTI;;RiTP4*ͪ<HYؑYq +so5_~nΩxdo3z0ϣ7<i*O==~7p݉/W.&:߰_g0=fDDGkcCF m<zwUメЛOÏ{QW鞄6Qm.nW}<؝x6j77}=h(6z'q{.$6¿}j|eMo\98̆$;0>Tpu\(_hm9 üW=? M/f*}i't,{rWҗ/zIns|0|u2z~!6\ S(gr~I/9Rek|#Sɔ5獜@[MA_GO.:LrPꡋ8zů'~ b~TŽG"N^ YG ŵ5l|.ȕf!rs-kef1')7_f +A {4b B=TŖ=ORo]>vq[ պUBU{&sQI}M8 ">_JEQS'a@.trͥ6RJ=k=MPwu GD~#ՏK1Z7Jx9yjLԾsz 6q/]S*fDIyC R|{ꕰo6FyhCR=]&ƆٱLBz&ݖB:t $c)6 uMVq(TžAu!v^ʂ[]wF!V*b~tm nH;qN;4^N9i:o sfoH;ωMՍ-lօx e領XVmؤW4yځgםkJ4(mе =o/^l̗MKWǧ*\e:קP$8iҡ%;dX(. +sla&ru=OP8kt]G}Ҋ! B`7^+ {^_<ɡzK7(m ci#> +endobj +742 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 101.433071 593.554475 101.433071 574.804475 ] +/BS << +/W 0 +>> +/Dest (cb166-1) +>> +endobj +743 0 obj +<< +/Filter /FlateDecode +/Length 4530 +>> +stream +x]ێ丑}ϯg# ^60`ڋrl,j a) Q*;Bu"x '!K_/Z=Řۏ.j +N_)(U+&cPBr& 叿m]G_͔7]%,M!JP)Mʹ)㼠z-$` ح* T0Ud* T0C'VCD Q֒tM%ѓ$QH:ti޻(,lqIiI`*I[, 3J\r(q v`JQ[@`~fI\6:BJ\(qA(#qA₤` "> S%.CIG727 6 qA!DuAS-8 M$+qA>73DD/bo1]u $L~W ^ʘwQ(PoS + oĜ=4YF/f VJL(/19STp1LX}sbSlΏ/_~/( In[ M3Ie a#u!u#5hqIe#r}Z ^toHl͂bؾ9(CdvW**Oub΁Kf>%6ָ/OR˯ghM/iЩ'<Ԕo2A旟at0Y}ڙg\Xʽjɷ2ǎms\ޜկ|?}ZD3ALwxؾށ᷀@Bvo+_-. o3gdN-ӻak|%a0mRnĞ5nVe[f0Ȝ$Z"dgC{6x3Q=:zMZW]r9aKAǂj׸A;wcxOq΢bsV]oP;f1it61kc3nKbv>W0}82aQ#nn33Ĕcy/ެnwz7DHne~XCxߧ_Rlܬ8˞tH{&\) /v0;cp<;(f''<G-c~ NHz5'A ϠOlWVA6nRS}ۄ욆f+o+k܅*ʛ'<AQ>\os"14t~ٛ-"6g)MjQ>uYqN6xGc1픑6;=;2LWt7lǣzeOBZ}̋j.NQuCboe^ڪ3cQ嵷1s?^xzu>.Zژ{Yj匝pFa=s_{c&m +<*L3ˆnym2T8$,C,L\埴LAU.4oۮQj륱jUt6ŗst9KS8iF9Cۢ"42SQS+ZAHsvL`o;aUԋ.~ 8 eu!UvC<4$WOb\h\\j/j!*g_ Bz+w&)q7S6CloW<kRLBźbc=:؆wa3f_˚vA4JDi>6UGר&#fTjRWK m"Silz6kY+l+j9At\J^5ՑtSl/n, 5~\sZE.ζoҮsrz\H&KK)',*gpM|жA*1ٯz'ym6z7ֱhzY6\:Y>^:*|&VJʆCej놺&Vǧq%jbנw;][{kwb߸Cq mvVvF5o;cnH;q]ʉǾ${Rܜ!g>xke_{zǍjlaܓ忖O_O¶lXF]c/*7U'ZR7M˅!]# K7n(Y\ƮI\ݥCk (.Y[23w҆>oTP]0"_RfyUVAL7l54~xy}/&Q{qi,m'K\e9tujm[{Ԃ4zhaWL{*[uZE TC/갔;(St_H;>+m)ۭEK ݩ^ŒQy^Im/IUۮnvC|LU6%G\g:HWɄ؏(:WTb6Ȼϕl3"5W{tLH~l%>쾂5U\-)7g=o9TLyQB2b{QޘEPZγaB)_ t;D +endstream +endobj +744 0 obj +<< +/Type /Page +/Parent 1 0 R +/MediaBox [ 0 0 595.275591 841.889764 ] +/Contents 743 0 R +/Resources 4 0 R +/TrimBox [ 0 0 595.275591 841.889764 ] +/BleedBox [ 0 0 595.275591 841.889764 ] +>> +endobj +745 0 obj +<< +/Filter /FlateDecode +/Length 4213 +>> +stream +x\Y~_1D(^\!NAhJIVwJcǫJUZaw=aZ w!Q/ V{|аDÂuOiq& "pOU24-l\JUÂE +D.hX7Ȩ^ÂuZwVÂE5,;@7,\WUck)D.`kX,lllHNC5,H]aA k eʃ,x P׀UbŪHkm$.M Rf/@@*kX +sҰ U J> قY*P& PXjѰ {װ {ȂAT:T]ATLD䘰V5^d+๬aAdKװo\ҰbHÂ\! BE"S<*s l P眆CT_LVdh%jGEÂBpa;M ʃ, `lG fYB$ J,Y7y5,ӰdLְ0TWaEÂ,)q[Cfְd(QTdAT&a tx JԔxY4,@&*zH~3XL4iX 7Qj{{ ,,ꉁFV{zf`GR &v%H`:X/1:`r$!#g̋ Bu?Yl9׷/ goDR4+`{6 #ӽ-5Ԣ/'AƶctKPB6A Hwg1$wJu.zN5r ǘd5:ԃlsta[:m]ֳK`Gt[[lli"aemGG^uIn.+֘ur%ŧqC!IGԽeL8(>Tt*‡ +Z1Ͷc:I>TԹ9ԎKO"Kus>~PPvz@^ ބ_%~bO>?<#bR~ { gd+9KO,SrbSh%<'w7[6n)ŖwN}z} δ +և>]R3 ͼO5~Rl߄< iwTJO_|?|?aNZa uko,--,JzBkeqe{YW%ڀALUx<8))|qRݺhzkڹ6sdɧdNN6j6Gힺw",댗U?qBP }/M}'2N[\/rS״}$iδ ar YsZȕ@&Zvmt)ͱbuV۴5mӸ鄾/sGD/(o8G:>(Ho杹6:{/g6p*!n2"'g? ^/S3H 3HѸd_Mo#eE3lDێjW=,covyVhu' ׽oN&۟!9M9M~9s!.% +ktqo"ŹnSis盺->ĩe!{Y/-ơQMQhw\blz-d{lEɉj>9?찙ZT/_C0N:*V +Zy>u:7bP5zҚhk?tg]T3.]C 3??LM;w_b[t5[ti'Fm7SΑsO%E*߮{B!΄e^!no;tw[Q{2;~pzKʮ'\>?PQn$ oxUj~.f1"}[BH^8 S~ܵeI[RT[DwTp;|EP]QW7ۭ^_l? t̂_ـLvGH sz|Cwz}}~ ^6&wpT=1Ϟ+moΛMl³?Ogn$ʑ<]؟ć7>5"wYi3ОBMV<5&OxQ~k0$(OEFZmC?\wB_=gf=tO~w?O|x;gO<35bvg~J@5źePFP_ //kOac.I~<|H!ͳ'L\?1.Igp]?l>pػ3d{О2\&Vܑ̫ƭd~R1aJČc@m瀳d #ъ&SCuiRuNE"^N6쩏*҇vЂj-AhI!M+ۇ&sYX#hW{;t9TZ(CWhOܒak[r4"qۍqb$1q/KWBI`w8<탣R4plVIꐦGyr9r*tG롱 ULs1H ؒAfX) &9W~ܐqjc䄻1$a;>߉hOf/}Ivd9 N +63a//}R..rpY&/̔|C⊛Δ.yrP\ l#&;d'is QFe> +endobj +747 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 101.433071 265.954475 101.433071 247.204475 ] +/BS << +/W 0 +>> +/Dest (cb169-1) +>> +endobj +748 0 obj +<< +/Filter /FlateDecode +/Length 3991 +>> +stream +x\Yo$~_1L~ p"N`A;Y<+vH +WjGXGge&"O?Ȥ@W[l.*kp[bBɤ\LJ]m{tl8NXM)QPX,^a`Rr!*h XƂ!sV\rX ++C sV.YXÖ%aʃ ³D(=j; ׀ciBwb5p( "pWܦ1 e A4,MI)jX OEaA" KANakS|$Ys$Y2hX[M E R԰Hfraְ | Zxљ*/g)+ 2^pIe R,8*k< YdkXHŒ21ECc=8~zAW|[t<]׵cqOWPV{j!s=2jФuu[`W]kKNֳ$msA[Rtef* 'bwkZdl|届rdde?}cg=3WY#5օ1ydcZ "c'ō&[OmC ߠ L>b8bŊB-mۻ齝 X{b4 }^^>_>b1k)l%bPUM)~Ys]dL W/7PSF=?v"_d&G\YTχß-,J㙥_m- ~-Q vYtŅV_ b#,~XsY00˷cD#Qk{3~$9/^s*oJ_6sIf ښ5) -eZLo36\iɓeyY(riW:;icrXJgc",S;KlAS^g?{LD~'Scn.S'h+fCTtyl;݇ǔ~-}Py, 9BnM~L8<6Ƽ۲OYkwqv9M12GL4 +[u1"7尖B>^]ff,6̶R-ˣH<$78^4"F r +,> E;sDo*ZǯyVw%]>C{~!wWt8籢lvHbW\{}Gq0Gg &@:ɭ;uE9|M1׷ލTGBY讫qڞH&:ݺuno5IMM@ m g!GFl}l@'8F6^1Lm&[kocZ_@̦V#C&9\_&V9YVOƮdy!A6~]yn;Ή4M7ȎY> ǎ39ld;|#c=YL?IQvc8( чJn}LNJ[yh~u۳ewulݐgO&/7E1؏Dt< <چf ݏ;754Am0t8]7]gpxi27a/-NTb +rp|ĕ4.\vSG\̃r 6bAΓtՋbj2ŵ[SK]qVzL1?̚t%yWY[y-ٜX= +-ν;GKhsvm2xGdJ[8k,{YZS+!6&|}!,HIȓ\WDZd a{JV^FΘjQԻR4> +endobj +750 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 101.433071 606.123057 101.433071 587.373057 ] +/BS << +/W 0 +>> +/Dest (cb172-1) +>> +endobj +751 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 101.433071 296.981993 101.433071 278.231993 ] +/BS << +/W 0 +>> +/Dest (cb174-1) +>> +endobj +752 0 obj +<< +/Filter /FlateDecode +/Length 4874 +>> +stream +x][$9~_QHk| $ $#!FЊiEZx8/efTeUM0%t昳WJ)@wOZEX]hʛ?Up~;cs9;g똳U9k_EN+Xޫ+!, diϊr bI`%(gea!1LQ` 9ZAM3^(=H V%^*EK(aA KE/a^$aϐ1C, dK<YdKXO d i-aA6 % .9Ldo"mv(aA&ᢈ<) x$d$,!p$,xHoF1]$L@ V5Gg23qęČzb@{[E1g#I21kmLŴ&,٧9E`{f<ȌeA{1+Ŗؿv 6}zYɔwJ` f7Jdcᰄ:,DCHXI7[1|_ZdH283ed\ pw^~m<*|(#!/ArX +sCKWz'i5s#bSRu]se}λˊe/xa~Dž~h4ph}_揿?c^OSZ 4=/5MhdlqЄ9XM#-Tǥ+=n^*=k]E c0D/}:׉V>a6wßԜ ̈́Jy}CWX˼:O֗êڮͣNkCguI=c:6E]F_iv|q9couWdK|zlR0S݆e R263Mҝ _RV + #X1M;G9!ϣu +8hT(.[z댨{Bz]T/]^_~?P*ʰ)\V:WC@3g65l*_[50ExIjeɦ,zF6ӫu7mu;mW^-u];9g]wWkn1ʒYQNF] }u~%嵆(M0UwO8MyC&Ƶ ?/m,p8CqFd@oܝu4s +hr? +?S^|j/}k|#t2DV7kr֚P7b~;og rW}3#IX7M:~Han7,.2E5,od8[M@ܰnqU֛k(Z7 K*ggMMYaJp-mBꗓm>Tc a뺰}au2Ba +ZbEsOkpnƏ𩴑6kYtu.SUqìonfYg3\g2Ƹ˵袵׺(ȣgPF߽m[!X&+wH1-| nNÚoAz׾2\5Rlrr~9ݓZgi,y3^7u;덯[jĿk9X=KPeiTh<ߥL]KCM߯c|Ynfʼ:' sU^hSr֥D]˭ 򄝭K,~&J# )99%b&GLԿ-UuWwH焨Lt9wc2@ʥ"o3U~ +ǯd+.{mU!8g}E?C^bTƗ/{gAI2迆[!r@s`$pye+̛Mfp]mǦݷM.ёd[(Nе:jYPв/2w!g &u^7}h)C$8wy&1(c){$O*5MTV<ڝa2lmA_GcP[^5bh2$m<'(QBe\PtEG9gTf*?ou~{ȋ uJ/f:Xʫ4Ѧ|H&@[}Y$j͏DL{_/ϗ:O@)0 +Y4fb($#BqlxfLNXi|V/.܁Hd-a|\q #G/E">LJF}^rCI_|>ni3DT;s3/WLcLʜHD!9DZq&3ɬvo8:B $Uu"goR=kZ6صk_Qď<#ǤTPj_߽gg Xh4ኟ]~`N'{xd:_\-OVM> WWTk@־]A㺟!' k/ϭ]Nu[n6юlr"뛼f +!C6Q5%8`xʔk@y~ ?( Q|[b`T?N_ PjPFG:̩Y浅rLS(:d7#`C,F9296luD6#[wzR7S#~ pdw94R0[gs 7..3)o\y{Vȕח"j'2KիEv;q4HsxH6NOD'ꩻA1^0]YufVi:o/'t7ojM5§l47 ;շ}Bϓ@W5MΟfߑS3$r+'.'\mTUseK]2i63Ou +S_vQ(VhLo&NNzˠN7,F7LSyCݤq5:k%Q$ M t{鮱uRD cM6:!cLMt7Ⱦۊ<}z; f2wбm&>_N6߈і̦Z'luFgqPoVkG'~T}Lq/6gg ve2?Nt}{eʲ[vl]睌w$O/hiA6i>n4쭤j:w&Élf e|܌ {tmp-lIy8LƖ|[:dad;gi +}MnhlsӍVF1 拹a2sy% 罊 +`jN}}`L'S] ˾縒3hwh妵纓3p-hu1DMZ-NVhzj2$j)vbP>kϳҕY ngsctzdhaݩ4JFMn{AC0> +endobj +754 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 101.433071 713.673057 101.433071 694.923057 ] +/BS << +/W 0 +>> +/Dest (cb176-1) +>> +endobj +755 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 101.433071 373.781993 101.433071 355.031993 ] +/BS << +/W 0 +>> +/Dest (cb179-1) +>> +endobj +756 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 354.834971 99.933071 336.084971 ] +/BS << +/W 0 +>> +/Dest (cb179-2) +>> +endobj +757 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 335.887950 99.933071 317.137950 ] +/BS << +/W 0 +>> +/Dest (cb179-3) +>> +endobj +758 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 279.046885 99.933071 260.296885 ] +/BS << +/W 0 +>> +/Dest (cb179-4) +>> +endobj +759 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 260.099864 99.933071 241.349864 ] +/BS << +/W 0 +>> +/Dest (cb179-5) +>> +endobj +760 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 101.433071 199.152842 101.433071 180.402842 ] +/BS << +/W 0 +>> +/Dest (cb180-1) +>> +endobj +761 0 obj +<< +/Filter /FlateDecode +/Length 4697 +>> +stream +x\Y%m~?< %Q`̃qAzܶ 0C~>JKU3۷BQGJ*{&|e_fkr.)jMe)-q2!dR . n?:L)p˛؛S +Xd +BTX 1BbGV\rX ++C #@ ,k,aKH +䰎HAbN`"5&K4&&jbb!k<,xLIE'Y\N^%⠝2dueY(xśP2+QNsLޓƳئWyXQ,BQy%xrCƏNrVV[ sUdk"d5 +2K  g +\ 5p%%i8ɂ K!rUd5,C^eXpTxd 1I9 S*x`vjXXI!: <`sxgK0p{Tyax  2r`V 0jX[1.gҰ.kX]T^2X^!h9 E `(Cj4=,X s^4f p?eM%jX6cT^16AʺhXpT^Â|f iXSkhXRykX_AA  "0"V R԰Hfraְ 39U^& RbWl5,^d,z F% x5,H`hXWdCd,dAa"]հ ;ȂhPÂ2v4,^xLdFBE LR<а#a6?lb aANYÂ!#alSIÂB0Y8xDta֥7)(ͤaAa<Ȃ(&IE +kXPbfְa#,ͤwC2i<."ӨanDd 3eǙVȀVI=3 Ce*c"&,OU9$̜d˂=([|ӧ_ՓcalK]0+SۃY +,+UD/U1RbZz&bs[!HmԱcl,fG]+}!idM0IMoĹk}P&u6B+|W:/Nju'Wv !+_EA4 H[~W8r7=q^ž׺M?ײ?ziZ_ʕoxi/IVc["S~fˬo?nv"BUV^6oa })Y\VUqVFxdcQ"ױ%ǍvǪ[rtMc':w2Olr7J"Rdei֧kWM״9-poն e&۫핛qqsx^o>}}A#k S`1,k`貭9 COWב"JMQp &@KK%v:/'xdӃH +6o]ލ6i\\ ٛYhMx-^ö=J,k[ +laF:U|Gz]To]ޘo@V<@sa+<K5oe],oۻ: `=Hg(} 7֖R0#Lݔ:_"D"2l`4?[rX[ă&׉ڝ@gU'3ӎg}:xIr\O}WBGZ}纗+%h /2WCᲈ !~?L-ļ3&8"hB |Hp:.A&@5&: q*24宆CO(9e0lXƋrB ߔ4TM4C-6E$ʓ\Oocu{B +#-n:Xʛ)ncu~9%G%"Glh-6CdSNy9ǙǞ/WL$BY2XxD1",)4,+6&3ɬۤ~+"9Tk#u[J6jOxC g}]>^5% y`E!eJZG¯n{+s y4R)]S:$G:Î\h/նgX&|RZBulzAd<yfa[Xm@P{yy#3"W-sldldȼ0'k@t0 RVS୼G=JS|Q%d.9g+vz VI_>9f ( mSnVݗq + (bݼV3Oߛ)SRyHӪ+kfE\uso$-ϱZP5SgV)m.8R@&Mt˱ǒ. 캻݆=6Gկ[9ߡכe6 :d6ka}j .y?&&1q_վZ>&qm}a52\szΘj&HYklݿ}+xhMŃήEMivH5rnIvݚ{ldMj=o4|f>:kDGy^:kva]]ӗFz˖C|lzT}Lɻ__mkqLkdxe-2:L}vmn#YwiL9ly6gxqlxC$9=ݲfe@sl秉{m+~vslvS~+➗rxȒ=(ɀ[߯/ݥei\3E񵩳enϛФ|msMQLzC^|z<ךn°9mx楬;8]o f޴<$ƿ%ea~Z/UF#C&3B tQ3#YFOƮdl.vQBl28hpTK&b8in7y|桫.b}Vui[ =]ǂZSM:OBN d.'Ӭ'bnĽ\i外[[ }R/G4?DsWBLmNk|ܒ%sMyw ^NŃ~ +I)VPh7n'g2ꬪl4ya]_"t OMJ>:1F'6;y;갦ѳ*N/ySX^@P'MTxR{Wc[Bީ3Ltq{}mi䌥1B 6:QshNp5Zo15Z8ZJ=?Ϛt%yV⡬<^|liFKfڝʣoc߼y4 Ҩ%_¿W֎T'!6oQK3Ԕc|I0qFsx"J0d`qZ!uH)@9 +0w:Ml͡B6VQ> %DWR?ꃋ]D +endstream +endobj +762 0 obj +<< +/Type /Page +/Parent 1 0 R +/MediaBox [ 0 0 595.275591 841.889764 ] +/Contents 761 0 R +/Resources 4 0 R +/Annots [ 763 0 R 764 0 R 765 0 R 766 0 R 767 0 R 768 0 R ] +/TrimBox [ 0 0 595.275591 841.889764 ] +/BleedBox [ 0 0 595.275591 841.889764 ] +>> +endobj +763 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 101.433071 653.523057 101.433071 634.773057 ] +/BS << +/W 0 +>> +/Dest (cb182-1) +>> +endobj +764 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 634.576036 99.933071 615.826036 ] +/BS << +/W 0 +>> +/Dest (cb182-2) +>> +endobj +765 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 615.629014 99.933071 596.879014 ] +/BS << +/W 0 +>> +/Dest (cb182-3) +>> +endobj +766 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 558.787950 99.933071 540.037950 ] +/BS << +/W 0 +>> +/Dest (cb182-4) +>> +endobj +767 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 539.840928 99.933071 521.090928 ] +/BS << +/W 0 +>> +/Dest (cb182-5) +>> +endobj +768 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 101.433071 478.893907 101.433071 460.143907 ] +/BS << +/W 0 +>> +/Dest (cb183-1) +>> +endobj +769 0 obj +<< +/Filter /FlateDecode +/Length 2687 +>> +stream +x]dϯk咪!1`EȐ/6͎5sW}t;z9JJ="W1J9aQ׸+'Nj.J|h.r6z(o?~o/՚_7%gDUD9DT; V1[gUVKd*a!*0C-{}VU7LT^`"TCL&=1].*e|LR6=UR *"lLt hR:JV˰%`v*؂UHtU]Ō*tRry.Ua:]TGaR&[Ju%Sbf:p"j.xkhޭ"l !,>#@HErb%ƀA uV0 +R Fgf] *%Zb$P[ KuE1h-X +[)cXI +ޚX.q$c,P [2(`'cpX U+@]5/%l`ѩ/X`zɌcVa&JwCc,0p7dT|P C`'7wX D=tA 20DpWħA+KMGu'~Yv>X]TX]0'j`,WLP "c p9/غTWR " ,N +HBua#y PƂx ܕX]1=T[5mO#Xu@ +wcɕ d,H Ba,Qp`,H\91*!䣺PY @XU آ!0[20 "p#lvD +Ռ DŽ| t)k+X9Ş+pz޵pf@獱 WWa,QJ@dt f,@ %D%dI pB#T3I3 cAZX7A RRl& >-َH~l"͡:آ J -, {囙 +lAXP%&3Љ0T_oc,_|0THVM-̌`KDBuAS%~ &!.PX0&"zz%PZu+t."XMD,7fg\YZY荁g+2Uw^Ld%[Pz"'&OUv83Knp Ct?rYMߨv܏;~ߔ?lZڍ1ܗ7_u8Ă<xb9eQ226?`b^g㧜|^Gripg|uiRoZl=`qǣ~_^{cN:m+_Mvgn{szVϟ;_:~9z\uٟҗ~W/j-cz\¾ֈe7y% p8 =Ix^Z8gTicuGdp;s?={oxpQݑq+oyh0/_;"$hٶY}^-WyxqMo[(6">S܄磌w!occMdr>rgcopĨڞ?:&BLYF/Οv^4LAFRpֺᯊ"BY`ߒ1ui +e{ݐ[}ި]WEeU4cAl]7"Z 9˪Dlԫ]7Z|[+G2>Ӕյ'}Nin.>"ũ@_kDs߄'uCPoO3'+$ +uyeJܟSf*6ȸ{*O*O:f[u9=Η/B7c˔-\y Rb?v7\ҍ@wSV݉q*6{,e)NUNJ{{=߅`Gqw2Ai7;[0@a'Fo{S,?N'c'uqۏ1T<$$HW(_:.yqw$kzAp" `}uc a2kAP?09\alu aG {fGQЍ[:Bg)bJ\g:2&1oDK:n> +endobj +771 0 obj +<< +/Filter /FlateDecode +/Length 4233 +>> +stream +x\K$9ׯ3&a;V{`xI Bzkw@i gڎE;?Lw&|_aRs㉖ ZEc9q^!}NO_}wKɻx3EU" VK>&܂%j Fk b`8pdUc1\`9<B<'ݒJe\/%evYbx Yb%g"d,dPK%@&ːC;*&P"gjXb-&G%#S\b ,sKoR6x$A[Y?8C.ňV/(8!Md- PN % | W.\,.s`׸p@<, Y"' ,5y%T xȂY< Ж--Su-K.$ 7@.\ZXiaA"ܳbn,,,,`ni \ 0p780pa-,UaRBlaw}` 0pG,ڹ>}hka{|-i*?#V+5YX|&..CFBˋKZXب ,‚u;:_‚E-,;, Gp]WXX%oav +,,/<‚^-,H]!XXH{Ld [X<HV@ +% [<.Q$l,_,, `oaA*ԜxHL^Zp-,Bd<™-,@bPCཅC  #XCmb Y)ZX$[Je DŽz Zx/%M^e r[RI,,9 WȂP[R<2s l 眅Cd_Pe&;4jI1IY,,(I-,@R<b;ZX&YBd JRn J,M7 2> *Ed YXP]Aĥԛ‚&J<#nkHRof *CA$MՈ[`MKW$fiMd@z3XL4YX ԛlڞ1#?E*b7bo5 ؋*g<4,K2O <6 /1>`z!c,YY~Yxz>Ͽ~(A +}?k"?\^`kb;hIx㞎4!Z+Vȏ' H1s:MLsI+yTԹ9Ԏ+cjIW=G7CL4]ۛ[k )#[?*5*krXlPe=Yĝ Mޅ4Ow1mp!] &4eLڅB:=ڱ{L]_ ڙk`Au)>ߏ,XX)bٟS} +d/K9O)~dE8Y]*n|uˁVUJT}z_ +^!:u#ߓnWwysYoU!'vW4|SGˁiwysy5}Bޝ@|V^KӥQ/wN?Ęޟ9\K 9a54nl^*9@5B"Sg3JnLgoH[+:oֶj ~I~nt5[zPmhӔ}ZɚZ&::%s5|vl.&BsëaQL_sIA"&w]iMm)9hE?'b#S6.#X^V=791 7nG.MY.j~]iwѶnx'wzl=xS6v8߯_зpRk}KWa=ЦҰ)? !me*m7ݭ#{ ^_k&;[v=<_oM\25˜7kzS_/&V|ZP܍e6|&XiMǧ|8߅#c:/]xQsi_+zlG/橓Mikӷw8QnonuǴEƭvW%?[z#Nnj]"(3/Rvp9_CrKU>jrw!W|'^dq'dOc) 0FG@'y[:q/6C>:r/o6_qO-Ydr'Y׉#lѳIve>ki{o8u~wAi& ^8ja/y@ +z9,|VCJ-\#.T)NLqH=PAR*0yPC%*Kz|k/l/qTwIz/p^ +endstream +endobj +772 0 obj +<< +/Type /Page +/Parent 1 0 R +/MediaBox [ 0 0 595.275591 841.889764 ] +/Contents 771 0 R +/Resources 4 0 R +/Annots [ 773 0 R 774 0 R 775 0 R ] +/TrimBox [ 0 0 595.275591 841.889764 ] +/BleedBox [ 0 0 595.275591 841.889764 ] +>> +endobj +773 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 101.433071 488.554475 101.433071 469.804475 ] +/BS << +/W 0 +>> +/Dest (cb185-1) +>> +endobj +774 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 101.433071 427.607453 101.433071 408.857453 ] +/BS << +/W 0 +>> +/Dest (cb186-1) +>> +endobj +775 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 101.433071 115.110432 101.433071 96.360432 ] +/BS << +/W 0 +>> +/Dest (cb188-1) +>> +endobj +776 0 obj +<< +/Filter /FlateDecode +/Length 3943 +>> +stream +x\Y$ ~_,K"u ?8`x;0n{lyGU.1:At:(D-~?uٙK|<=;XOmJ,'\9 +I%9?mw]8򣰘L)٠ +X֑ +CTX,1Bb{V\rX ++C h*' brr8oʃ sD(=j'x xh( Y`]YAxL(YlNy6s&[ְ>PyI%h'7p5,`g5,U. $djXkX `aAlJJQÂX,xT^4$ Bd<‰5,@`m +aA򐅼װ yȂAD8DjzY`.j~@2 )DcЪƋVy<4,H bar)K@ kX +dhXd\9Ȃ [D9aAѠgdjX$TJ5,Mi)UdLhXd;hX&Y(9{I79CoM7BD|VÂ2M/%7)~[(J4,( YBY4oI7N/B_XÂY7ѫ%,fRPL4jX 䛈lxCB|3dYX@o٪ ,URk+9Z4,sT8VtV-X/1aR}KTpf$,p Ftsь.4[ct O9<|R+e$El7 &bm/EDHekMDAöL]"Op(O /DnyUo5)qFrbqޝϋ+t޽ :` O}}^^Ӽw>/.kL-jx}@T|6hpx~{?}߿_?{ ZOx$7bx,<~y|Ꮿک^…ؽbSeDY[* G*^5HaD6~(tȄJmU?P|2O+Q_WqJO_xqb !!lbK6H esgޏkq~^WY_mXbk1NlvO7ዖj`Q7]m/iE|y5g:ݏIԅT`&;{]*̀XWm>!۷oMڊNͤN[6Ϯ3I~9Y' dW%$vWyW 2lekV  }m)KVlI 8u^Zl_␩ᕾ= rkk_xxkoѐջO;/eƋu$=II~kS9H +gve8xhA2vb'UuuLHULͮ-\*VL,?٬b~7lr\m8_?<߂|yǡ< G1$HswIOx<-pٹF6-5q79+MŬV' ;֘{N(WUvK 3]^87pڲU]}`'.7ktMOvzrOg <~-Z=d&ܴK|=jc{Wp|lt.eRIG.#wDԝ}>A=Ma "M+,Sx),maSIӝ}>ž-e9#?b'(Wu^eQj"7%ozV0XpTov 7j쎛m!\G$$mUMr|\!YL{ 2esi{B=8:z g2ghkmۻC[ȍ8/#ATrwĮmu =zf+;ɽ˓]෈wm%g. %:V#xA\Nw)-LH$\Jh ̶5z2BDdY5n%üz(HXJ'yn;oqMİ'iAq@W].:7mkӴ׈sJGPMvMBN eNmC36]1bnĽ]i頶[G }RoG4?DN+^:ɷL>bݒ%W{md7~G<wOCHJ0†fz3q;9a/rS\6v@ETAq7)ye\I7;y;갦iR6;e6Ie=&T-ud36!0 nʏ3tW Od;ȱcLN}ǝNCJ#\SG\̃r 6bAΓtՋjx5DS#04>k%H3a; kt(P+nŪKz.>?Tg~\ B2I(_+Ef6dǙj6%? +endstream +endobj +777 0 obj +<< +/Type /Page +/Parent 1 0 R +/MediaBox [ 0 0 595.275591 841.889764 ] +/Contents 776 0 R +/Resources 4 0 R +/Annots [ 778 0 R 779 0 R 780 0 R ] +/TrimBox [ 0 0 595.275591 841.889764 ] +/BleedBox [ 0 0 595.275591 841.889764 ] +>> +endobj +778 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 101.433071 770.673057 101.433071 751.923057 ] +/BS << +/W 0 +>> +/Dest (cb189-1) +>> +endobj +779 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 101.433071 458.176036 101.433071 439.426036 ] +/BS << +/W 0 +>> +/Dest (cb191-1) +>> +endobj +780 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 101.433071 397.229014 101.433071 378.479014 ] +/BS << +/W 0 +>> +/Dest (cb192-1) +>> +endobj +781 0 obj +<< +/Filter /FlateDecode +/Length 4519 +>> +stream +x\[,9~_QHc| ߤ,+!v@>5 ԃ4/efTVvO^ir/pp3U+R/?\^_*hʛ~Up}MqrgۘU9k1)FVK'W1ZV0 +SYbA Ҟ!% kJQ4nFC b2rȃ Yg +Pzx֨"/gxΩx# +!$"- %^,.8- MIY,^,$ HωHetiϳ+aNH! +< YYAﴕx~$p»ୖig$,Fy/! E A^‚A,Y(Uv9IX-dqJX-dA a" oxY`. "E d*e" 8A/X"Z%L FR؊8K8\bgH‚! \ElE*YD@  ,%,H6ءq%i>g& šp4"&$,aKX8<$pi7Jg{ L|Lb@z=V1eح3_>#Ie +b*Fi E5(:2_?I[{IsT,XZmIN炷kЌNy_Eq~Pt.݁-1fnH[G69v~1O:Mx}]&ֹ6V~ 7c;F)r,zʄX=;$P|Ɓ7$J_(H?i0-ym>Nʾtn= \4/%3pA2pj^/%FG K\-YnsSP%]a7f'9ɗG%^m6c>K Yq=Oswb" _QdbyCl~4ryoيH!Xg~>iHˇ(G*g xrRG,Kjvr)#[+'r-w¼~2-d멊i6:G)ض`itDkkTJݰJ&ɺݱ*ۓq!v_%~쇆wߖ_ػގ%W'65zkEC|rǢJU} K,sefo3~uy nښ[Ow񝠇w+<^cn_4͋)8sm>ymd!oAzlVJ='X<|cuSͽ=OqcklZ6:cCz{zANsDf_2( +]Gޮ?bJC߉c򱥞k,+:L˻FlC\Cjo\y6陰U{Y~57t-1#?(CLߐؚ-F-3To+zz!y~J\yл(ez;6o'yV7 r=9K(2t 85NڑidbNzZ,o৤wfMZ_L&/+lt!' +roBI LuLzhKyl[yq?S\Gm?ZJUre`<{L%kr(>4A\wt8>$'4 [j~m@W].:3-k㴜Gú-EgZWMVwʝ[; I .+ݺ&,fOƏ/ z EW{}bF4?DRW@Mwx#n5i#.'GX}3~;9a/SS^i4@TFP7)~(A7;y:ꐤj̎c6;$-gVIe=&T5td3Q7!0 n/+wWd;ȡcL} loec-M?Aۍ& 0F_ +ykG'~^8Lqo]6g|#8/X,s ~~>o;NƯK'zFn3-M?&YCǭFs=4AMD?t8m7]kܤ@m6c^M8~D +y:(scKN]Uǖ.٩! +s(N!JL6yzp> +endobj +783 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 101.433071 797.673057 101.433071 778.923057 ] +/BS << +/W 0 +>> +/Dest (cb194-1) +>> +endobj +784 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 101.433071 736.726036 101.433071 717.976036 ] +/BS << +/W 0 +>> +/Dest (cb195-1) +>> +endobj +785 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 101.433071 409.229014 101.433071 390.479014 ] +/BS << +/W 0 +>> +/Dest (cb197-1) +>> +endobj +786 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 101.433071 348.281993 101.433071 329.531993 ] +/BS << +/W 0 +>> +/Dest (cb198-1) +>> +endobj +787 0 obj +<< +/Filter /FlateDecode +/Length 4757 +>> +stream +x]ێ$;}gIh? B< i}i;@1%2b9r7ES)x޾pQSp +JEQZQN>Y`3_.o.u}5SJhw";r*ATM!n1%I3\ C[UT0* KAۭ* 4I* J+ءR("kvӽ3z1$t:Igi%].J:-.)-lqHI:B6IaV:bb.$Aa ElQ^iIR$u :Cr*IM+Q$-^$`H: [?):?I\%` l[1[2H\`Jٷ<-> ؂LQ0yUIZEt 0k "^% `t$. T$.T4E\i؂$[di-qA4٠D234֒p#יQH~ʩ4&$.Ŷ,6u: FQaQF`37Id|$姜&K\N) XoqכQd֛X q qA"␢:؂) q Nz$,b>su>ޯ~=WmE +VѺ_{?6} `.獘3 ڜ0SգM&O`n,+^.ŊvGک1wǿw`~z'J97:o-a^䵜Kܣyo$tdy &>ג.1 dϬ/Xx˾} ?ŖRmid@nox?Sea\ڿb)Aah eY;xobm_?WJGtγ #4}\>Lg4Ѥ"wPeguUtQ'|tuB\u 8_sva~[{s5gV߯Gi6j~GdYz+Y"EY_}ba] +;Q6y:O^ONy:4SkI@G1hu*5Q{/?7桛6D+-֭Ξ' wyӡ81٬_F<1p_ˉ1$EAEan9"z'CU:φ({kVDxFk1_3zWQ3Bl7^ M<hvΌg,T4Mzy:?(Ol6]"[-Y cg{HMRy:+_t߻SPݝm{C qYT|rdCqHmvc +gN(:޸7"`X>#yrhWOm6"f'!3Նac|z~:φV:QW; G8bfls/E%,Vq`̍gwxF\@ܴw=Խڸ{(=WPzgtxڎvѰٯE=Jkst=Jmϖ\CqA;V R7 婏y+=~iG}t=Jc'|<:k999gTU8Cw"w0'T>lzGy&OJ!qs$yoH 9'1_oqE6z2!?sYVX^o96x,[⸍Ҿ6!nSiov|<>'}\=}byf$mv;}xOضS֗{>=;Tvy=|:Wd|.y[gT\__1>vu"-v6R'?+V1zSdyuƖYU_'Ky F~ՏaY/8nݮmC66na|Gc;gʋMLuVc~;Zۨu<h{tG4Y۸)~[xbEq90cf'是J?/pf|)O9l~2-O(.π^~N-tόChr8g3y]sżJPcȟc~:G7l>|̨M| +ٹ:.\ۥyǥp]0QA0I|aM&Ǜ4⇩2HE nJcŅ;I0NSL[ȲSu@II@@2TBN?ގCݘm})J#)#w=\͞3W֖WxT>//哩N> +|%Щ3\'ىOeyY}܇}yi!qrFp0i[Jќ_oO_ᬂ5d>iƫKSȇӈ0XZ!|xYH qY٥&=` 6߲,2{Vܧ8l?\|9TI6ݫ)!]ANQYutq,J-G|a>j>ߘ],(EIͰUEpuD}K8 EU 4Dhm߆:ij| ZȖp!jzW^87S6C$^7+kmuņ=:\绰]ײ&<.֎7Q +MU"î2ˌJMj6 I.U& fӳQǭXD\"[ZsmB+{T=MPϫ}ٍmU|9e۵8Vl]vqA(:W(WDžQutiU*ˇUgpM WMv:$y@Set _:*|&Vyl%e.cyyź3U4BU@w]VnkTkwb߸CqOlvV&6vFٮwƄ0Bw}+w=Ȥv˥Ls:u|.ϲQxB_yܨqJg|tz<)GWa &4hue]ECǍa|M^KƠiu2i52ϸmbKdvl=_zssUසuOW$r>CKUo-[;i +b,ȗO*+w 7LwVF;z},mޤo\n,KR[.9kv,=ے=(^m)xTeND2UePmKrQRh9E{QiNt|Tlnx-[-rΡߝ%[.絛zI[e۾iwm6{fz5).{Ou]T);!:J1Q'hTB@m<\xd#RJxOUA?&$E`M?4$WKJ luS$\j!/9\-/B)?C_Q +endstream +endobj +788 0 obj +<< +/Type /Page +/Parent 1 0 R +/MediaBox [ 0 0 595.275591 841.889764 ] +/Contents 787 0 R +/Resources 4 0 R +/Annots [ 789 0 R 790 0 R ] +/TrimBox [ 0 0 595.275591 841.889764 ] +/BleedBox [ 0 0 595.275591 841.889764 ] +>> +endobj +789 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 101.433071 228.873057 101.433071 210.123057 ] +/BS << +/W 0 +>> +/Dest (cb201-1) +>> +endobj +790 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 101.433071 167.926036 101.433071 149.176036 ] +/BS << +/W 0 +>> +/Dest (cb202-1) +>> +endobj +791 0 obj +<< +/Filter /FlateDecode +/Length 4070 +>> +stream +x\K$mׯ 1"/` , fkw$V>cd2U]3#<$`̲W7e&"_o?]~I]T7%N&s$L*x}_]k^)%:QXM)QPX,^a`Rr!*h XƂ!3+A .9h,e!dU K5İ%$e rXG 1{l0JYsqE%lr{`5^11Ɛ5CPjYe&Y"dѓʃ,.'dqNQxʃ,jM(Y(|9 +&dIYklӫWMив1 pkXϬa0 : pzDjܵ!hXs0 oLWC%g p4,@6$*/հ`ly^4,] +kXH{TdiX'LN#sH9" ܂ݏc6wmc|˧_ՓcaRkɱ xex +ɶ$B!RBZb;t!nu|{!lԕn^ +{*|!YR"do>_\>_\LgԲyU!_kt^]B}>\;eӓ޺|׿?_ jݷO b#7$Ƽтmc遈DFnb+GZҖxB轟dO_vGq/Go?~ʪDDSYb[ +VI}.[%~]U h27"c[]\%H$aں|96Ux8KVO5&Ok~$GL䠹<98ѵ*Gb2v5g49z7MMa}EƬr1uC}Y=^;vx|\Dy@{r9\jkg8nsew].P]ן>y,Ioy..^+7VߴEz̯c=2Z;@ICN6fϞ}] ӆCh<8c`Kk{!k}ͧ5 + aƫ`MG'.m|I|vPO'l{u;j`I[F;N1b;aF{Uw?ZJ燺:xFe~q岶[_qμmbo~&~Vsr'VrC&ljb@k>TZob'GQdXpuS͸> y)+jE??/lw+v);aܔ8Lӱ +ueK-6sWC~iPd&Ht7bZiFRNwπXJu \OГ}~1roSĽ&ޝ*CKYmoT[vQ h}DzMx[de7o3tmQ!iAzw䱉"7(֝crgb}>k~>}~b9]l&-taspm$-ͭ'*r;%+E}?Q>tOsΞwѶ,Jc{ώAϨ*nsF9a5[?,EW0t,ǩުyûpW=<7{@,`0˟F(cbO*QWN"܋: ފBӃq|S&/࡮ vS,OAm=ӻjsWm̢?|;qKczoۭ ut_bT7ivJ9j^vj.h=Knq ZG-?-o8ݤT +فvv|_s̡D1f:VPe_t{^pI~{׿m̮ﱖeb{k$R<7~xX~Tһo0̿w#QW#ؑ'yޫM^9;?GȺãZ"%y9ȱWd4gjVe pS{ c Fwg5:fXc,Q35KklwzY\ ߶}lUY߄yj/G/%ooN/uBc{p/2R%g/&"X!3 +Y#؎iŖcK 3*Qnwz#_&V,'cY^Ʒ8D ׶sUÙHtc呡8CUuv֥e;oL* v _*z˱!Bܓ%!{Myw".'N%$uXAJ˸iˤU4y ^ߠ" O`y2$⛃WJuXӀ4.) ]e3)tG롱uQBO' 5cOY g`J.0LeGr᪁d.Ƹv4v{IC1bxd1'dG# 0F_*{@'q:qo?_js>8yN z+ٮYy?:8hغ#L!?I/i6 ll58܂<Bvtfő|̀]8L占..2O! +i:C:얎X2a\'y +/s-K!~xuNX :0uҲGD:}P_VXPT_/r_;54Lט.V]yvk :)wn(\F6FL]غugUKiUaݕİJUeRQKқ4Yq#niwR* +endstream +endobj +792 0 obj +<< +/Type /Page +/Parent 1 0 R +/MediaBox [ 0 0 595.275591 841.889764 ] +/Contents 791 0 R +/Resources 4 0 R +/Annots [ 793 0 R 794 0 R ] +/TrimBox [ 0 0 595.275591 841.889764 ] +/BleedBox [ 0 0 595.275591 841.889764 ] +>> +endobj +793 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 101.433071 582.273057 101.433071 563.523057 ] +/BS << +/W 0 +>> +/Dest (cb204-1) +>> +endobj +794 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 101.433071 521.326036 101.433071 502.576036 ] +/BS << +/W 0 +>> +/Dest (cb205-1) +>> +endobj +795 0 obj +<< +/Filter /FlateDecode +/Length 4094 +>> +stream +x\Y#~ׯsExb0yXl;F3;,hQ,:-{$}b_fkr.)L +梲+%N&s8O&R<>oGgJΆ/?I9% + +E+LJ.DKX#$vg%%1ع2߳ +pɲƂ,AT!f &BQ9kb.MNyobb+&c +Y K̤ 4^,>zRy5^,) +/CXWVy"YW %3 @,Y8M%kXdiXdAȠa"S,o5=,05?`ȂHQ ɅYÂ"1hUEgr\ MjX\dz F% x5,HhXWdCd,dAa"]հ ;ȂhPÂ2HC#5YÂHa 2M ʃ, ?l D aANͬaAΐőӰ)fҰdAħaAh$Lְ0f䛎5,|3kXP$Gݯ;^y}^]V/9"rYO5~R:/Olp{{UF"3CugW:zˊ>_xP=ޑۢx1yw_y8|@2^p~E c? *^&|v/ /H1N* H;#|o[pTy̓9^6~jm\WN9/讬ZTyۆSNsUTQ__2xt ͱLrESSkl,]-T$: +oݢqщ|aMdoW lk.Ӥم=z:_?ԕS[k1\Z?Fq^_~o3umfW ߟݛ +~Hj|7);وD+>ϋCC\L_dHdxK>Y50Dh 'ᨢDeATbDNjb]G7H!H}bB:Zc[]m.C~^e&t94QEԃz/n@.åa%\ \'7 >!H6em@/7Ď5X.&亯ic|[9x>ۮ#y>b"Nl}J͓ۼĜI|\他I^1z_7`Ki o}'nzm{pqkOnkŵ|HIh\.6+EZmsb{x=euCu?c~/cjb>?; +w7==nqiWD$ܣfF[פ g{nZ5GdJ?W;,pYם"[d\WMnEeXj> x41f'zCُɀb] 9p~As-}ªV)~zZN4Ͷޞ۹?=+Y\&=KzXڋf(y Ù.Nیus/6s^3M/_ɧe$O\j|$Z&?L[9n6h{o[=G=+dKfr~nx4YyݣzM;^;}-Rs>?X}A-=ŝxbkÎIϩ/סU تWY]GGv2!_1!1RlE[=/ҼKR(uYnWVgULoTVXϮޗ|ԕDBTV9hwWVG| _YN_B熳HYWἻzgƀ19+ۉ*9fk2_VeUn,F6|lBj;5\폾+RUx{ CWwc}:Z}:r͞]`N[Ҫo7;H}d3^Πl^VzUV{~nmM#ay$!r쀮'u1 >ɗg۷V㕞~ڏԱ0ө^9Vc̣1C \6PuRͤQ :mLuj+Ϊ҈)&UaݕİJܵqђPX9l9bɬ{Pyswo{\S8#S®%gG}Jkj%d05䝯?F9F`u$Ki}nJ^+YgvEx> +endobj +797 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 101.433071 698.673057 101.433071 679.923057 ] +/BS << +/W 0 +>> +/Dest (cb207-1) +>> +endobj +798 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 101.433071 637.726036 101.433071 618.976036 ] +/BS << +/W 0 +>> +/Dest (cb208-1) +>> +endobj +799 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 101.433071 295.229014 101.433071 276.479014 ] +/BS << +/W 0 +>> +/Dest (cb210-1) +>> +endobj +800 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 101.433071 234.281993 101.433071 215.531993 ] +/BS << +/W 0 +>> +/Dest (cb211-1) +>> +endobj +801 0 obj +<< +/Filter /FlateDecode +/Length 4831 +>> +stream +x]ێ$q}g%xz`/eCOʹ}`Ȭ작\;%H#3c +.?_¿buտopW(,N''ذL׷ .o?ҒB'k'qAP8P-H8K)J\ lH\ l q<%ix.` R-3>oqb\þF)QdʃQw|<EKH*aݵRwumu;ãy~]wlSCKp9)#zTWv#7~_ߦ*#z-ʑ@2Ϸlbu}2F_wrœV|XXFѫMr[u,k;2۵^8m}8+z ='H1yu;B/1Y,.}B4/%%*VdC뱟WGNwy4HC%=\OD]rfL8}~~mejA~e4P2y.ӡwuo?nGݽ'Zcin=U?wեf?tSƄ:r>.:Gw\COLwj}gp󣻾pv?w<}FMx|H)_Eʹ x'LG:y;-=~hD{.ϳtHXpQyyU{ר&QI]M8 Ejфlaû0V QKj:AtJiThbϚjwS:ml/ri9lEmUpc6Q]vqAH:W(W7 +PnGҥ!֮WTᚔ' G=^ &^w(uH~No(;ٱtTBz&ݖJ:t $c- uMVq(TTŮAm%v6Ujy=ݵr7|šs;Ux b~tQm nH;eqoԯ}I+K^uOV1ԣ4]:nTc Ӹu%W2Ai3 : |M=^SƠiG}8Mvw Mo`/mm|bf +csp%:+Nڗth q1ˡ-[ɀ+i]8.7/mQ_fǢ,bH؎cJOob3ڛm,ү/ۚcaujea] Z]g+ X)U٪ҺP4LUY+1T|V%8Oѥ{ڍ:э7iܺ5o6ȍpuldd~ݤS*Mj{A=SճMGxhH`,Ԥ56'(w9l#"5V2քXZ4/ل7(cPT_r&PPe[EMm"(M%|G +endstream +endobj +802 0 obj +<< +/Type /Page +/Parent 1 0 R +/MediaBox [ 0 0 595.275591 841.889764 ] +/Contents 801 0 R +/Resources 4 0 R +/Annots [ 803 0 R 804 0 R ] +/TrimBox [ 0 0 595.275591 841.889764 ] +/BleedBox [ 0 0 595.275591 841.889764 ] +>> +endobj +803 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 101.433071 638.673057 101.433071 619.923057 ] +/BS << +/W 0 +>> +/Dest (cb213-1) +>> +endobj +804 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 101.433071 577.726036 101.433071 558.976036 ] +/BS << +/W 0 +>> +/Dest (cb214-1) +>> +endobj +805 0 obj +<< +/Filter /FlateDecode +/Length 4539 +>> +stream +x\Y$m~_Q6 =X0` h`S`X#`f{zwN*8$#ٙjsI/?\̒bsQٿo +Wk(-{&\ח ]/?>R/" +eWX!,)V XƂ!#+A *9h,Ae!dU K4İ%$e A w +φ%BQ9\\Qy <~l,1Ɛ5APxKd4d!ƋGoTdq9y vːޕUd1XWJ&Ry Kg^aGH1)<Y EAx~4p"[nox8HA_C!IQ젅qIBő.2e \. 5p%,Kp xYE , /aw 4,8x-[4,[2jXdl԰p!Ѱq}a•끝x.{Ұu}N =z<ְx$ m4,Ua԰uِu !@{kX@]-rw]0N:rQ81j6=,X s^ 8%-ʞZ-6aA 󩼲+Z^lEÂE.3kX_Qk="ZW!hXwX, k*,aA‹@8հ`D.{Ѱ wM^Â5GAköU48  k<1hX65, .kXdNÂi))E b1!Syquа  KAJa5,Hx4,H eаR,o<,p> ȂLQ ْ )DcЪƋn p2x6iX-VRKƦװpaϒ@l 쐙k< YdkXL\l PD aAΎͬaAΐa|ͤaA1ąd aA# /oPoSmͤaA!<Ȃ(z"dq4,(1r5,@zz$Lqp7 "3&2[7ސgVO 7 G؋h3I=4,sTO VF=60_ctIQECB̉Y-9f3z>\~{\UOEP[+lW`b\ 1O1/Y!* ި"W|^式>%,ܔI(Pp9 Q7A|0/'@Mt6)Sq)GFg]~?z|~'gҗay;쫿[\m;/<<7oy}sz?ݗ:v8icy]j]BgSx꓏u1\SW$8͍4!7 h뮽m5mgygBi޽ݶ}6Ye+6cOn&Sm]s ۵yNU[}>ߚ?ha hi{݂W1v,z==^ʹ3Zx~׎1xOR?`ek^XoKSirhZa~`mgItoOV(^W1ؽ=2] e@^Lv\~{c}9`8,bc)#\{Ayz/GotowI_Yvv ;gj_bzw<Wtc"7qsՎm~Q6αX drQӔ~F9ϪŇW + _i3۹*^) ڐ um J7Vc*c[^O=W[oX?ljooǩY\cۯ՚"*>ߓ5qiZ?#e 'WѐE,z }iRvb}T몣'&w*%gjr멾A_BOU6^3O3瓲Vjda=~ +uXi}]iqc[{Zۺ'F&Wro&*So:癝U9iQlzv&V#(Nkn(t瓡c;{<^O]ch f?ymR~nc5td3ϊ :`rcߩ(V}n#euǏE/bMgbuYqu {H~r ߄}-i^BecܰqȝO͝-n.fVICك}u{K0ME]?l/n8j5Խ%SbM3۷F3rp%y n+^9y$7!c6..m\lyWP̽Vs; +JriW.zE?J/j]5-yL/" +875ȑ'WnDZo3z6=͂`z}'=[Ox)o@9խ?6'[>o""[lp6o->r+JY%[tͷOs=o?c֩c6Wo AY|>|rIob>۷~}'Йë:n9}\??Pg?~}vcicxň;{;y 罰KÜq58n닏ƭS=swy|U6vpӋo5XF7Nuuk>Pm9ig9>sToL׽KKKL?C7lsCNݰ9q# nqy w˯?9M7o8?؇)&nG&~#[26Y;o@c'N%$uXaBw=IbAfˤUi=BETFp)~mƼ䭒$=!Ml+eS>+DiϠ;ZmBeJAjǖl 2CXJI4]L7aˆ< c3&V{Nr"iX;Pc\xdv'dgF  0F_*ցNQun2-.0|pGo^2˲E.t5;3 lݐe$@BNF ؟dgнaq^n&v \I S:f Hd63`/x~H +r9̓gH!qMgH 9(.ńeJRN2T4ąH#O0+ +)r`rҲGD}0u@HXST_/r勾yX^=?5fjA 飂g I6@14ice[WK]qVFN1*CAZ%=lɏ(HwNsufdVhQT-}=^2h +gfjfph.{YNV<ߺ@M6y담MB.DYYDș`7+u^(3Puzb%Mw__udIP}'n}ĥ"sқ͝X/O>mP; & +endstream +endobj +806 0 obj +<< +/Type /Page +/Parent 1 0 R +/MediaBox [ 0 0 595.275591 841.889764 ] +/Contents 805 0 R +/Resources 4 0 R +/Annots [ 807 0 R 808 0 R ] +/TrimBox [ 0 0 595.275591 841.889764 ] +/BleedBox [ 0 0 595.275591 841.889764 ] +>> +endobj +807 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 101.433071 426.873057 101.433071 408.123057 ] +/BS << +/W 0 +>> +/Dest (cb217-1) +>> +endobj +808 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 101.433071 130.126036 101.433071 111.376036 ] +/BS << +/W 0 +>> +/Dest (cb218-1) +>> +endobj +809 0 obj +<< +/Filter /FlateDecode +/Length 2863 +>> +stream +x[ Ss+H݀ +b4)>8ۜqsvt/{Cj$DDj/ Ɵjm%f{Q(ooq]҅IKHrM7&JK?O._l>×ZˑןLJ-jPJ)SvT5O3RѨ3`XU^`F, +fpKQ1DDG)dLztC-6WW=HE9k!眪SؒK%*y:آR˰E-tDNst-=]ZUuu :"y:QX\]-Rsu% EO'EtDRѢ[H%cQW[b-TDP0.y mQ=*AVR܊!.!ؒ4{$-uuEz,[cl* Uxn{,Vpa&y,WjV•sX .½x,PWR cL =Awx,Ppa=`U0{,X+y,Pp7VR +Ƃ-Օ +ƄGvnp7& ܍8J] $l`=`.t" ωi*pmcAwb\] \0Nb<$px,H.Y=;jX]ԞcAw7$pH<` Lp]WZ=$pX  + @C=dp{X]J" 2KcNL#Y A +Oc=KTǂ ڶ dcAZ)cAnR>WǂB$ -uhҪǂa豠D؂c2ٷ[[(lA$ z,()ìzC-qXPlTz|tc̀cAi[Qc؂$c2]=[ z,;4jILS:z, &4AJW[ X+?(6Q:"I=ܬ j-՛cA#؂cA,MXCG䱠qEc걠 DmlfX$( ijN܂I7A'OaKl걠lfX4&2zHZYp75ӁL\DfWV8{b@@o؋ݪgZLT5Vdr E>wL>GTPgb~|ן/_c/N"aw(0kG@ MPt6Z&]l,0yaN8J?-fYgmPyt&؟6shH' ϗcw~l'pRusvZק[?|d'g"Oy ÷6. ]mLM=3Osvdti?!ER6׍"& v|ss5' 0<  +t}>&zA^B">xpB1bGZ!gxtny/5x?n"xCQ# b.VޠQw/λ}\ fc6CxŨ4Sf_¨#Fn?Pl#{!n%Bmtnzh?,9Fm`G;3ߋ)!/j*S1!vv8o|VB0 inv{>)S,>uðTJwgEbT[ѱN9ԻV,/f7a펤]usReg~2]]xG!-#$YmZ"~ މTiRwU(KC\i˔p> +eV*Ґyåf^A,6WrtG1c'2enAj,uCl3X +8 W~i"Nf?((tEusmSǸZ4[ (*LsqYI^Hd>wm}pF4[qpYN|Yĕ5[:qve6-;i2u)Z.4.etnk]?)kdc'gar`ҁ!}\L:Ke˱^34%d$934fjGi :viоQ \@F]6z,ݦ|֧eR9ŔtZWeLbZW%ߵ~7% PZݹ̧rՑ!R~l=w: 33y[kIعk_IyZHTsCԾ[/Zg%'"d T +Ol}h+oqίCvj?eR~R)V%H!vc {x:B_ +endstream +endobj +810 0 obj +<< +/Type /Page +/Parent 1 0 R +/MediaBox [ 0 0 595.275591 841.889764 ] +/Contents 809 0 R +/Resources 4 0 R +/Annots [ 811 0 R ] +/TrimBox [ 0 0 595.275591 841.889764 ] +/BleedBox [ 0 0 595.275591 841.889764 ] +>> +endobj +811 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 101.433071 797.673057 101.433071 778.923057 ] +/BS << +/W 0 +>> +/Dest (cb219-1) +>> +endobj +812 0 obj +<< +/Filter /FlateDecode +/Length 3997 +>> +stream +x\K$ 賁^Ⴭ,6Q]XUYAT,ȏßBΔRs-~ꤱOGg)j* !\xͩZaw=aZ w!Q/ V{|аDÂuOiq& "pLʫeX\[XٸD4,]gѰoQ2:_!jXw0oYʫR4,]װY$QyccQjXHUÂܵ1 p]Ba4Uc=Bw k<வjX65,H hX `aA*djIÂT-x(T^28d Bdy1Vv _||Ra1bigkߝ}%煀| %~4k7%CT-}-Oo~?~|u<m}:2 EŊ>/Ƿ?]ЃMzpE )n"ܔqϛy5 F_C-_x-yp,˚л3!+EhFk w]6_(>_{Zx>qa ڴvX{8{[[Y#EV# )0(ه5Ч{o'(-~W^qX<ğ}\эoI|JsOK"NZu~a+o<{4#|m|fFtϗ^?pN[0Lu=f԰mJ[}[jɖMuf>o]`fk#p-֖^ݺ0.ck=5t-<ɹHxNv> +=>_ڦo},]c; on"n:4]y<V`{a{_}]Q,K5M5Ȭhz+sDk9\Ix_^_2Y~,o,]Y~K 5T~#3 Yo+/>mQmv#ng6TrGe*=yҽF9l_ 4PV2Jed +nú FS_1܇}ucCEGћ:d.lQY:RڰlyOnlQ삜V߶>D^[iU>·#Pg'FQkÛW7kxo羈/6\oW|փWmvZ91V7ĎXԅ^f ]­~ht9?U [x—,.V8bLi󹫸Q7pcNOzrIgƾ^]mg}v/pu]ݓdlnVg,6[;p=3nA +|=qCp3^nq/#:G{M0y_aPGcr[DrGHć55;:d!"#! E/v+ٜtX+r'i{ qd]M7\Ugy}oQ$/ ē{M; kd|7rʂm.(>t?~ǥ)ҿF=^>bn>R{4ĵm*y~1aȏ$ק5ú+[>E roi'6PIhMF.L'L4+'L\h(L:tpHhr8}4|} dPh;V2=Go[br*1uA $`1Vt7ɞ>TK8Tsbb:OtGʏ;u M&sŬCcgbDCv9t:rKkqTRe^Z*CWh'Qg~,U}It̵-ox:D8펝tXacw=I A.vˤP\L4~"*#O;p4\gA^I@,(OYa.Yi/W"Ϡ;VTa2Aϵ 5cMv!g`$ڮ8\qEzpYrhwGIc?9 +SKl%${;LbI0=Z:{] 2-Z!tǏ* ׁx-Yf2~L/6I$2ecǽxMr;Knp%1N +]WG!ܹ |MV8i0SQ43)\BFq*:S쐲az֟TK2OLNk"(< ֕>_^ϞE#QR:Ov֧##m{a934fiA飂Ze@R:bhF딖˺Yڈj> +endobj +814 0 obj +<< +/Filter /FlateDecode +/Length 5430 +>> +stream +x]K$qׯ0t`%C-5_2̨JVM ltd$"tg??8əKt~ɚ[$>;Kɰ+1G!dRaㄿ6}q5;{SJ}$ +&,+II%٤9*Ib)ZDI bPɬ%A >+IbJ. +ɑ1\$9 9VM (x%ͱhygb.i i.y--9vZZ11FZA.ii YY- PIK%`4s +ZZ,S Y]YM,6Z`d"5 i޲Ҝ3 jF:)&%ChiZZ,?ZpCY^Fwii YOAt>BAFpIILYCX:yA)jHd!\5 BYA aAEÂ%[xKE bZ 7H@.ThXةaAb' P7pn5,@jX@A(@G\p784, .װjQ9[ % L `а +z^zQ(XBXw V{a +3n uO@+r0petVKhqeܢhX]awY`E0pXj- |0p~kXu0oYV-9kX]װV $QӒ"9 հ waދk9 "p5 5,_4 [eLY5)4ua- km*D஘M b@@/kX3R԰ 4|jZ4xf YjdD6%aA%xaA.Lq@] l)2v~3"00F9q J}q'. MY@i1nѢs=Rߘ_I~v#\_"O[Me-iq"sGӘP`ľ}pk^t]hژ#̆0X>jYUѸW?zi^Ji/2+hIŵkou2`jw7f m魜T%wͲu>6oonAK6e>LdG"ۃvi-yk"=Ua ko{Æl,[Km(uk6]xm2Tk^S QmAgYϹ.WV1Q3ǗU#*Nm^bC˰(fh$Dv9+܇֔eg&nvl&{Ț2TQڡ +h +e)]vӑ7e㲜9R1Qw05˥ ow(ު1o-6& +Svug],˼gG%' +,C,ϣ$;񛾃aX+̄ lLrnC, f=n&Ho_}.9YKѢ\M̃<Ϸ "'(ujaxͺ{w칫rw&]m;do᯦hV)mh9eq%) +⬺QTDvvN2Fnۥ+1_Lv{ə&{>f U5cAH0K 734V݊]#p +~Mq$y c&Vn2[7|yVF-FvJvŘxX{cPVFyn/pt=vV2Ϩ29Wz`9ʛR@Kr8ޭr{Ko@Gwϩ4 7-!ynn(wUD޸hcyUIrM"O[;6Os4!'ZFwq˸ȤXȿJ~;ݲHvގmwisC,@PVK>͡-(R>&7e(ɍ_KeF&l#tM׉)zn&mYo}[]`<ݖ['tqԲk9yS}j-y;nM~M,md0?,ޟ- M6;_咿A)ST;Ǔ8͗oLJ~~X')d.C_m+ ^aڒ)ۜ~m@?lr?+9S=6Uݞ,oo6)6Q}#.Rw)pa<$`;"n!{q]tq!6s]y}jÖRPsQszh4*9[P'zR?عh8Lw&ظH9Bz=ҸTjZ_DYT= +DMnȽs?d^͝+J;lj<^O ]/ UBo3MP _U⨩j/OK%26yH==6!%o\.}{l-wkk.7Cc55kd}VD; 27UX9 UYuέ܅v~z'cNgk5l%繒,¬>PX ~TPlŪt_(SA GU?! $T/,^d:5Tx֛PN +endstream +endobj +815 0 obj +<< +/Type /Page +/Parent 1 0 R +/MediaBox [ 0 0 595.275591 841.889764 ] +/Contents 814 0 R +/Resources 4 0 R +/Annots [ 816 0 R 817 0 R 818 0 R 819 0 R 820 0 R 821 0 R 822 0 R 823 0 R 824 0 R 825 0 R 826 0 R 827 0 R 828 0 R 829 0 R 830 0 R 831 0 R 832 0 R 833 0 R 834 0 R 835 0 R 836 0 R 837 0 R 838 0 R ] +/TrimBox [ 0 0 595.275591 841.889764 ] +/BleedBox [ 0 0 595.275591 841.889764 ] +>> +endobj +816 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 101.433071 766.923057 101.433071 748.173057 ] +/BS << +/W 0 +>> +/Dest (cb221-1) +>> +endobj +817 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 747.976036 99.933071 729.226036 ] +/BS << +/W 0 +>> +/Dest (cb221-2) +>> +endobj +818 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 729.029014 99.933071 710.279014 ] +/BS << +/W 0 +>> +/Dest (cb221-3) +>> +endobj +819 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 710.081993 99.933071 691.331993 ] +/BS << +/W 0 +>> +/Dest (cb221-4) +>> +endobj +820 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 691.134971 99.933071 672.384971 ] +/BS << +/W 0 +>> +/Dest (cb221-5) +>> +endobj +821 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 672.187950 99.933071 653.437950 ] +/BS << +/W 0 +>> +/Dest (cb221-6) +>> +endobj +822 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 653.240928 99.933071 634.490928 ] +/BS << +/W 0 +>> +/Dest (cb221-7) +>> +endobj +823 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 634.293907 99.933071 615.543907 ] +/BS << +/W 0 +>> +/Dest (cb221-8) +>> +endobj +824 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 615.346885 99.933071 596.596885 ] +/BS << +/W 0 +>> +/Dest (cb221-9) +>> +endobj +825 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 596.399864 99.933071 577.649864 ] +/BS << +/W 0 +>> +/Dest (cb221-10) +>> +endobj +826 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 577.452842 99.933071 558.702842 ] +/BS << +/W 0 +>> +/Dest (cb221-11) +>> +endobj +827 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 482.717735 99.933071 463.967735 ] +/BS << +/W 0 +>> +/Dest (cb221-12) +>> +endobj +828 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 463.770714 99.933071 445.020714 ] +/BS << +/W 0 +>> +/Dest (cb221-13) +>> +endobj +829 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 444.823692 99.933071 426.073692 ] +/BS << +/W 0 +>> +/Dest (cb221-14) +>> +endobj +830 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 425.876671 99.933071 407.126671 ] +/BS << +/W 0 +>> +/Dest (cb221-15) +>> +endobj +831 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 406.929649 99.933071 388.179649 ] +/BS << +/W 0 +>> +/Dest (cb221-16) +>> +endobj +832 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 387.982628 99.933071 369.232628 ] +/BS << +/W 0 +>> +/Dest (cb221-17) +>> +endobj +833 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 350.088585 99.933071 331.338585 ] +/BS << +/W 0 +>> +/Dest (cb221-18) +>> +endobj +834 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 331.141563 99.933071 312.391563 ] +/BS << +/W 0 +>> +/Dest (cb221-19) +>> +endobj +835 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 198.512413 99.933071 179.762413 ] +/BS << +/W 0 +>> +/Dest (cb221-20) +>> +endobj +836 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 179.565391 99.933071 160.815391 ] +/BS << +/W 0 +>> +/Dest (cb221-21) +>> +endobj +837 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 160.618370 99.933071 141.868370 ] +/BS << +/W 0 +>> +/Dest (cb221-22) +>> +endobj +838 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 103.777305 99.933071 85.027305 ] +/BS << +/W 0 +>> +/Dest (cb221-23) +>> +endobj +839 0 obj +<< +/Filter /FlateDecode +/Length 3623 +>> +stream +x[K# WleVb`x;rUvl9cwף%';u`ȏdu _z+])5'9>>HYz ;x$E_SJr!Κs_՚_+K3EU"+Fs`%pZ,de!D1$b +`ɞ/YbbA _c6X D&KPzxTj&/sx.e[RJX<,xD/Bldd K(-^,ک@XW1yyWZDL^J.@L{alQؤ ^,b5y%2ǐEks)n&/B<Ȃͷ $B9YrK N BNrf BNR0y DI,5yXX̐%[X@[XX[-,`୐O0b ” e` Ѕg 1 R edaw1A@GǾeOU;LV\(,,n($p7d|-,n+rwC`awda hka=x-,d. - w}E3|h|‚g7Zv>jaA"P ,"j w=#R[<,,] H,,@|s`&:XX`a$1ycGC-,H]jaARd wI<%XX{+:tĸ̈بYI(Rn1yII" *!گk yMX7n!ou~e!Ac !="$3ƞc!Vzq ٨Hvߖ_!$7Mn|8|?e<-@ߏo}zzFޯ IKi|GoL̜唷)P2 yX?co͡D'n0SEDtߐYЯa8agS٭:Nipηj 7Tc#Ұ˭} lTS=[fوmx +U4,7Q||q89j濛vQtެg}+STW^_ ٭WȻ)n4/innImw O_&ewe/^O?(To@_M"]([dV^Z'aP @n'q UsbWMbJM~*}d6 {}n]<Yn7)ww0)}|b&N|vǵ7ӒEqƢ +;M2?6|JkXxf0yHO7Xh-EiY]Y^R~Չ ?muݢVe -Y[Y临85~k5p/UoggoU6w@Ӛ9̢PPI }Z渷&Wlf7fSu jmѥ&>_͗Gy ߓ3~ņOf<*_vm;mt7tmIqHMc3Owk|]>dxZK[d)Y3DyBnI.Yt11fboY?}?rS{ j:Z;;LN~L /olx^N[OwLC9t '+ә{"{3vs\_kR1ex4%Zutp%Lј'EsZvbA΋tի2oZScJ#Ƀ'#S7rS<7ϋ֝> +endobj +841 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 799.173057 99.933071 780.423057 ] +/BS << +/W 0 +>> +/Dest (cb221-24) +>> +endobj +842 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 780.226036 99.933071 761.476036 ] +/BS << +/W 0 +>> +/Dest (cb221-25) +>> +endobj +843 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 761.279014 99.933071 742.529014 ] +/BS << +/W 0 +>> +/Dest (cb221-26) +>> +endobj +844 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 742.331993 99.933071 723.581993 ] +/BS << +/W 0 +>> +/Dest (cb221-27) +>> +endobj +845 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 723.384971 99.933071 704.634971 ] +/BS << +/W 0 +>> +/Dest (cb221-28) +>> +endobj +846 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 704.437950 99.933071 685.687950 ] +/BS << +/W 0 +>> +/Dest (cb221-29) +>> +endobj +847 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 685.490928 99.933071 666.740928 ] +/BS << +/W 0 +>> +/Dest (cb221-30) +>> +endobj +848 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 666.543907 99.933071 647.793907 ] +/BS << +/W 0 +>> +/Dest (cb221-31) +>> +endobj +849 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 101.433071 605.596885 101.433071 586.846885 ] +/BS << +/W 0 +>> +/Dest (cb222-1) +>> +endobj +850 0 obj +<< +/Filter /FlateDecode +/Length 4345 +>> +stream +x\K$ s+HÇY v^lu*=v`'.R"?*U'2;sIϗ'kRWKl.*M,'\9?I%O']şN_mw]8L)٠ +X֑ +CTX 1BbGV\rX ++C *' brr8oʃ sD(=j'x xh( Y`]YAxL(YlN6s&[ְ>a PyI!h+7p5,`g5,U. $djXkX `aAlJJQÂX,xT^4$ Bd<‰5,@`m +aA򐅼װ yȂAD8DjzY`.j~@2 )DcЪƋVy<4,H bar)K@ kX +dhXd\9Ȃ [D9aAѠgdjX$TJ5,Mi)UdLhXd;hX&Y(9{I79CoM7BD|VÂ2M/%7)~[(J4,( YBY4oI7N/B_XÂY7ѫ[YͤnwC2i<."Өa.o"r{ ̒qfuzVu{Z%u|%GR7 &2],`:nX/1>`²4oQECš -}9F1zز?7_{_;eGl#1۾`?kD~9#2ݑ 0\Xw-*rȈN,iKGV+}!\KOM4tBtG81:={9}81 PIX֤*]؞6PC21˺ubn;՘iyIֺ8wRL; 1&憒ܖ,s+oƄykB3O3ޝeS1!L(ⰖLM(&ԩcУMWQW"uw>~Q@v!uYo_~f_:&OZ:߫T'{YC:ޫ%!'BCF92>,&kjtH6ǖU>Rz&*[>p9/z^șS~Ck=EUe0*KE__T!o)]sR6VPԯޜ0> \W1${7N7yֺۧ_z( (|.:R>~/NWIO5~My""gOw^{ JvjBʊn-0ou|\J[ۯm4.5M)߯{~ܵYe8VmWYaоSyDV{Yg*ǹ]X2\kB2 N$!kT]e Ukr$vW^ NMYE>mund?SE/{z8..VG?Ua ~_[ُڽ<{՟q?~ۣ[}3m\Ae*% nN>Z_0Ħk$gXeZHHr>$ ~*hu$jS5YYk]nUm}qt^v]Z#󭞛$:mCY#Yޯ<44lW997yq^>Rv z\g>m9icaó?M*hgrI`9ף5Ts&:tkb~x /E dquQMtӒ_wI + YC =d~\] 0ca;ϙ#j*D}v]:93;HߪGI}(g7:֮#[-ȩ(tݺnuL-Y)(NΡ<7Nl8njg?5ߥ7\4|Z3ǔZkoP)O^sū$А6{{`;|ػ:?6 ys3IЀ;[%Fq*~O{Fad\ȭl{s[k1y[LFsC훐 3C}؎{Cb2yIQn6 =qR (wÌ-gOY9蟉BXWM3p1~S .tr\Rv9F=[ϵ-rb V7Mem0tK*Ol#.#$ "ѸV;EmnaT<]ѐo&P(-;7,XD~@,@Sj]Ya6hr~dxۡUsXOj nkpC}cq Uyiiݖ{&i6甝(,߀;|H-šfUci۫z>/PyK>콗_TqŊѶcَق8%-m,(㵋5 :t_$hX;} Sn.}=YtԄWh/m7퇵I} 0mO>,jMȆdYΖصirU}W{%XVދ!Di/j|_5}=$A=+d qj{[hr2rWR@l:^Ė>HЪɃX}_:Vݑ,ƭdyS6^.JMf9 hpTIvd'b8 {n8yI@W].:7M+4׈=IʫfZSMb&JVOyRHrt@ĶӬ 17C^r +rR˭>Sʣji S.Sp-vXj_d\<ٍ?/>+lh7ij2)7U5Mw TN_wWщf'o4cG48\Jfg}lt؆:lKDݛj?u',y/19F`{iku<•'La"Z r15^UW+Vl ;> +endobj +852 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 101.433071 432.754475 101.433071 414.004475 ] +/BS << +/W 0 +>> +/Dest (cb225-1) +>> +endobj +853 0 obj +<< +/Filter /FlateDecode +/Length 4380 +>> +stream +x\K sWXU` @< 8l{'A0`琿!ӭnAv0;-,ɖdτ,lM%E>_=}w"bu1Ζ8`K|26cW8{Ǟ)%:{rJVWX!\ ++Z% FHxJK bsYae9Yge1l IaY<B)<Lңs\\Qy <6XWL1dǐ%/@`IA9iY| kYS^, ExJfVy<)y {x֚*MI9)Y' @,Y8M%kXdiXdAȠa"S,o5=,05?`ȂHQ ɅYÂ"1hUEgr\ MGհpz F% x5,HU4,QdCd,dAa"]հ ;ȂhPÂ2HF. Uk<&3PQ 2M ʃ, ?l D aANͬaAΐőӰ)fҰdAħaAh$Lְ0f䛎5,_J5,(o"S(fҰ0d QTdAT&!:iY\a Jof f DDI-wC2i<."Өa.o"r{Lgf8Z1 @o٪ ؋*5J &2ժU0-e"&էDa gfN`D-+8 9=b %"`Wfbw""Eť&" a[] yEbPfZ"O(UI³S)eU[oJyᆐa!o5~[!Sey0a=e8r8XuM9NHҐB98<}Q1zgs2NbV8p!%^5Շevi}h*[Gߞ~}~x>}93!9,u\i~߿?|yenT$q^-!O%~aBSQIkfhЃ4_\N$ oudnuR&b:O[He.-~',EtĈlp3RȩY@ciĮB[I a`O]w}m ۯmY|X#T,L))c]7IJ&. Y +f 6vl.vyͿ鲴ㆎ@mc222^l[cdߧ[Vcp1ny#6c}` em᡹l[C81^Q`gҺ -cuW7)DBkŎzqVf몾i6fC8 ZtY*oϝabip8^*84)惩-oqш8}'pF`Cz>Ȳ7-0lW4*@#GBJ na1 r-ޯ?KIqi^d pBtԠUs"A<S"l|׿.{0"̹|N0_ yk^}TlBͤ2V-z 79ǾO}ccׇ9Wن0nן{}s42HjIh?)ҢT`9m.;L[&'SNJqSGo?\ZӚ.&M9"ܫ{"f܏MK9FUoJ~LSױD@+-w>踮uƿ7ޮmb4o*]Zվ?z| Yc qᡏS*Yx4VP+#y̫:[H3Tܥěg6=, ;/7s'rù#Rד^{ +ڎW-)jm(?ކ+z#z +!sDs l]^҅B!wW ۍC,}A=j=o[ڇl16rH`E}jfzۑއF搋2+}ݍ3܈/7ݪ6~ܸ9,?}=^k-c{SV澣$x +藅P=oyD5{"6}ylDN%_݅}Ɉr~ RjSWʲ lL~}a=5 J5-'t~DPr?"- +[]qx,/Ou%7D,%Ae)׶e-!>/4uy8*%,O~J䠾JJnK+~_u?:^KMSb+Yn< OύFgj&7z?]0CʋO KgP7.7YoYtMGr2v1 XZ\9&QԥAyq2|O/WeAm amߝ􌩝3@1ED><ך#E\NWzNoA"yɃ<;mxnoq2,޾BqXؒ_N޳Bf bJ @D^mlB]ܙTybɲz2v!UlXec>`xl= İ'0]';Xy⽩.vb}Tuik -E{SPUBF en.'աî31WC֮v +rR-SʽktS)^]@7+!_?C<؍/֕-:tPMo$aFSSkV<+PUg`<߯$⛍VH uXӀ)5e3)t[릱uP@O' cMY aH*LeEr檁dڸvvm+2l%:I'|d P/zkC'yA\؝L;q/c譼hh%~u9kغ"'I.$˛*@t<~'ۆj wnkݩ{mip fA3 +b d~{uqƠJq9̝|ĕ4G܅놎0a钭'iy +/s C!Е6bh؏lIJE"r 2R„O2/ۙv {95zhFjݖa+m5i=(\FFLUtjVU-St?GMqWø+qVƭ'^| hΩzKfލʽܼa=2-Z>gSuZ՟bs} j;?r%Ci>k%H3a; {Oʻu^(PzBSR +0GJr ..]y3gy`"cK%J(C` +endstream +endobj +854 0 obj +<< +/Type /Page +/Parent 1 0 R +/MediaBox [ 0 0 595.275591 841.889764 ] +/Contents 853 0 R +/Resources 4 0 R +/Annots [ 855 0 R 856 0 R ] +/TrimBox [ 0 0 595.275591 841.889764 ] +/BleedBox [ 0 0 595.275591 841.889764 ] +>> +endobj +855 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 101.433071 797.673057 101.433071 778.923057 ] +/BS << +/W 0 +>> +/Dest (cb228-1) +>> +endobj +856 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 101.433071 446.531993 101.433071 427.781993 ] +/BS << +/W 0 +>> +/Dest (cb231-1) +>> +endobj +857 0 obj +<< +/Filter /FlateDecode +/Length 4385 +>> +stream +x\K$ ˒H^ 8C~>Jt̎"(#jw\RO'kRW[l.*M,'\9%J)Now97:}_>M)ѻpL)٠ +X֑ +CTX,1BbGV\rX ++C *' brr8oʃ sD(=j'x xh( Y`]YAxL(YlN6s&[ְ>!daw} z G `(cl  z:Y ރI f< p?ŧV5,]}*qoeb,.iXϬa0 z p":_!hXs0 oY+Ɩ5,]װQ $QyccjXEÂܵHÂܵGA^5mFjRhʌVDhԒPc+ufְ s4*jX7A Ty0aGa(sTd Y6L YiXPl4&kXZ ˨7=kXz3kXPȢDm(fҰ0d HQTdAT&:iY|a JRof fDF d7z\ ȤL@V-7$g:3Kř ꑁ"Z%|FR &*SU0U ,0a9}"!!f$,p Fvkьi>=~ROڏG)/n*$쪄5}DT?ȐXdvHfxVQe}q7;9#ľBj|S:[B +-o,$ydC}D5W$ Ş[Ȫ"ZQ-,o NuKGɍЭw?>´OOmqq~ՕHi[C%`a ߆z֦57[Aׅc (I]…[C[٭Q"$1u9|kȬ`^[۲k/!91%0Bu2xdɺ5 W, <3`r@2Pld]~ ߯o07 gP"+ҵ")UX˫` Ѭ$ i;lq 'e|>lلU>O[.;9bw.;emluoP%aAvg$#CmN5W{p9GjFp/8|\bF}MJ"x|}"*} ޛ>@Ob.gvV'0CRI))}Jķ\>K#L>͌oFY6Ce.. ޷9$9t809qr0lA"ŒpK*qrt_끫eIn"is;pnkXd+vo8|rCZ 8>p+(JcK_v rxZþ`HxC?O<CR7_7kXmH("̹~NPXXZV?&{A4+bIexW0p^/7>rKTYt&mj/)ozOۯIXGxŊB8[QMtVUޣ)%v^ ݬ!z_~kB4q155m(CtТZ-Qo>Zvvb96 _c*ܓ74^VwZn* n>y0}<σ&^`/,O[n<@8V<vaz59䩞gE'uX"<!Ţ]ˣUncN{_mH~E/sz6}l߯:rWk6W&->voKtجS+7V]R:Nle辷旵5ԶLVtgW9<4_u,Xt{/nؓNsD4}SL~_Y-xG mlq!v.[2@aIMjdT؜=L_\mia0\2ބ{xse&h}F7DZ=&~m{s˴idžz}QUƽ79\Cgڏ[jcܖ>ܞ׎MS^Q='qI{pm5۝f_ee#{tsÊj}oƎS~٢IhsM(v \CrvcPy?><|+RudkUDCau%ֳ f?Zd#BֻT꣎R|mgCUcG^ӛn'gIEnB!HRJqiěJ}1BևpW+ȣ"T_vzjƭv;ޱ=0JIjz3.p]o] +|ɍ-۽~Vv7*z'Ә2}%^{>;W}t1CY)W\}-J{#Α5l*֝YmJ;>VbmS- /JF䧓e<2d!m]OrrزoIȞчZ7ymkD5ebɲzkJ/Ȇ֫Eǀ<7ɎD GdM'/(vAϪs>Myx9aZSTކjEh4 U:5}CB⧶ ΟvM^\vSHn-JU]Ke:xv*$ߠ3qK͓r +=qN!) +Dl jMUpFW*B +IjL"[%Q5 8N.RY_.[no5N*4:xlɮ[]' 5t 9tS~ڐj}&s}A;fr;.owF{~n =ڍ& 0F*ykG'>q8q/N5y +^,˝6_'>;qo;Zd"Fn3=O?.YCOxͣZsgb:Ⱦn}k&\!^vŻ%i +rpFH>OCJ.#.Aq9MXd1 IE~dbJ#Gn R`/͓<ЯvU<@;i Nz=P}9P&ߣ o.fyt[yRnͤ-PtLqRWU-S ü+]aޕxh+㶈׳% P9ѲYŹwhIvsh{C82S;CWk|g;uZzxZ^=T@!,߁8OG#/sx"J晰lrUO`یi5zb%LQЀ9{8 ߅VŭB2I(_}HfƦd*(isR  +endstream +endobj +858 0 obj +<< +/Type /Page +/Parent 1 0 R +/MediaBox [ 0 0 595.275591 841.889764 ] +/Contents 857 0 R +/Resources 4 0 R +/Annots [ 859 0 R ] +/TrimBox [ 0 0 595.275591 841.889764 ] +/BleedBox [ 0 0 595.275591 841.889764 ] +>> +endobj +859 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 101.433071 797.673057 101.433071 778.923057 ] +/BS << +/W 0 +>> +/Dest (cb234-1) +>> +endobj +860 0 obj +<< +/Filter /FlateDecode +/Length 4887 +>> +stream +x][\~_QD !$ bvE{'Qut9.ng:.E~tT;ZyWfgr.)`M +#~R8:WbOBdR >mOuuw]8QXL&lPX,Ha`R!* XƂ!=+A .9h,g!qrgc1\ Ia9 9VAL^`"5w&K5]pc!K(iYc0"dHVAiY[ְ>!daw} z G `(cl  z:Y ރI4f< p?ŧV5,]1}*qoeb,.iXϬa0 z p":_!hXs0 oY+Ɩ5,]װQ $QyccjXEÂܵHÂܵGA^5mFjRh`ȂLQ ɅYÂ"cЪƋVy<4,H BӰk)K@ kX +dhXPdGfdAa2]Ӱ {ȂlPÂ3VjX$T:3kX9I5,` Ty0aGA,~2GA +aA^YÂ!^ئ7Bd|VÂ2֛5,_z3kXPb%ⷅ7!K@ -0 MƋְ(ͬa 7ѫ[Y֛I.dx]dQ<`V[[oHtfgVw ,7 [؋h= 5i1Q5@XYuλOU9$̜dnc c_qSmqR4f!8@L7dL׸%]J<&2@'c5+}ym+=6QOH&H7FL `|V@T\;De%z12M4q\Mvcm( %A5Yϭ,>+ tdMZzwNbCYOC^t&soo|QKg8,4Y+|ߜ=T'{^y!977s礜X(oCƇɚh#טB]/t}-*>p9ԑ3uWui_5]K]0EN@$.>t7/hO[2~l8+ m~<~h 4~[䐓 +]ZAK}jퟖ?G[ ZMO;wygAcklƥjn|ֹ yN$y NT>,*9KroҪ+hǢ]mF*M]'lkzkYz-=/z7쮕* ǫzn~khm뿍CtXi4dɯҦs ugЯt\Ǿ#;/e}Ҽ~mpUq2ɜ7m5kY Oإ2֛}9-ϋE^'-wEa36#чD:9K'=6t㊉BPڷt.ﱮ)gXd9?'+!yAZu^ZV@!Prš`K]FuyW~JꁯAI :౷Wʿ,|BK,18%f + 75U5DGGⵉoo.XjrCͪR}2(N7y(qK +"/ۣ; p]kL;zr=-ttbANY7>C1R vvHM7L.pۘ}-cS%/Y@A%ٝuޞ9%062`@*,ek3c1ϒaP)`čw/q1sJcV//0 CNc0h4G'!ܘ8R* ޷y{ڑRqfj,|xm[ԴyBfVrqlb!S׍o4laKiD{A-rϽ,WgK&P"}YA8q!5v8ۙu'erj_1<ˆYuxR%ys.@/]TRi׋#TbDz\T_:oX5g);]7w_36F'7ܒPtÌ9֯K4ہ3ckksnk7oɛ>fbK,ڞTN֥&h5lVڇ%3QK'p_7dQة` +V]TxvVv߅/*,X16fCݘ]o,ڵcݓv6y{;WfVdRgbUKꌻ[7^6ӵ9?2Gmk bF?yΛ␆3ܷ kmin=v Lyq3~W{/׈'nF }Ft vxLɞeF!/%_'vEI 7]D|檷9 &dcl;]:oǕY-'"F}D}F5Nn[ZD1z`m|#:>%bJxB#ʉS vA.$:mO3.g$y[ lлoVj7TJ&RČ(hls՞_t%9MYVN^}-H1!vxN} Y. fr 'hX7wy;_ŨǿY7:om>R ߈˕ ; p4Ӆ6Z56[d+DԌnO#_rm6<.JMfG< 7ɎD {dM'uAϪs>Myx:[RTܲٚj.6MBN dK;;ۚfLfO&wrSHZni-JTUKe:xv'{K,\<ٍOyù#/KDl jMUpF3TNwD|J鱣kpFI].n\Jy^klET6Si HuX]NkX9m r"9Cw`{gMz;v>g{]dxd1:dI& 0F*ykG'9>'"C s6bhvo>W9{wl]H&;ry#v'dGЬq'Q`o%]GP׹31 NdMẄ́+F=ҹHmpһ&ᐜq<!85'):B:짊xa;y +91?Li<sӍVG1A +L0ӲGC{>>0vөT:CsޡMG=1R ^=6:QshN[pmbj2ťZSKqVzN15YJ ]YiE-QOliΎ= +-ε;GIj}߼E4 đQ-J^;Z<.Dsgbs+iku\jr a&'.6cj+=zb!=OVЀ S ^!,_^!Iz\+AxFɫ- +endstream +endobj +861 0 obj +<< +/Type /Page +/Parent 1 0 R +/MediaBox [ 0 0 595.275591 841.889764 ] +/Contents 860 0 R +/Resources 4 0 R +/Annots [ 862 0 R 863 0 R 864 0 R 865 0 R 866 0 R 867 0 R 868 0 R 869 0 R 870 0 R 871 0 R 872 0 R 873 0 R 874 0 R 875 0 R 876 0 R ] +/TrimBox [ 0 0 595.275591 841.889764 ] +/BleedBox [ 0 0 595.275591 841.889764 ] +>> +endobj +862 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 101.433071 393.004475 101.433071 374.254475 ] +/BS << +/W 0 +>> +/Dest (cb237-1) +>> +endobj +863 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 374.057453 99.933071 355.307453 ] +/BS << +/W 0 +>> +/Dest (cb237-2) +>> +endobj +864 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 355.110432 99.933071 336.360432 ] +/BS << +/W 0 +>> +/Dest (cb237-3) +>> +endobj +865 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 336.163410 99.933071 317.413410 ] +/BS << +/W 0 +>> +/Dest (cb237-4) +>> +endobj +866 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 317.216389 99.933071 298.466389 ] +/BS << +/W 0 +>> +/Dest (cb237-5) +>> +endobj +867 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 298.269367 99.933071 279.519367 ] +/BS << +/W 0 +>> +/Dest (cb237-6) +>> +endobj +868 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 279.322346 99.933071 260.572346 ] +/BS << +/W 0 +>> +/Dest (cb237-7) +>> +endobj +869 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 260.375324 99.933071 241.625324 ] +/BS << +/W 0 +>> +/Dest (cb237-8) +>> +endobj +870 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 241.428303 99.933071 222.678303 ] +/BS << +/W 0 +>> +/Dest (cb237-9) +>> +endobj +871 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 222.481281 99.933071 203.731281 ] +/BS << +/W 0 +>> +/Dest (cb237-10) +>> +endobj +872 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 203.534260 99.933071 184.784260 ] +/BS << +/W 0 +>> +/Dest (cb237-11) +>> +endobj +873 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 165.640217 99.933071 146.890217 ] +/BS << +/W 0 +>> +/Dest (cb237-12) +>> +endobj +874 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 127.746174 99.933071 108.996174 ] +/BS << +/W 0 +>> +/Dest (cb237-13) +>> +endobj +875 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 108.799152 99.933071 90.049152 ] +/BS << +/W 0 +>> +/Dest (cb237-14) +>> +endobj +876 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 89.852131 99.933071 71.102131 ] +/BS << +/W 0 +>> +/Dest (cb237-15) +>> +endobj +877 0 obj +<< +/Filter /FlateDecode +/Length 3166 +>> +stream +x͛K$ )l2%zb`x;rXO6guݜ5bgԃEQ?Qx$|Ojm%BQ[M ~#I [z|g.4M%r-xÿc +ˏBTQRfGc-`Ir*0CZUO3$*`)U fSش8H#&"WCH2=]!ז+Œ<sEFOBYآSآQ<le™T {[]-` eqVE\]j׺D21(b]f)G`K&m(St [?P.:5fT Ga !3(<R$R UGT[R@j$q)B&آ=p-` 7X fؒ=0h+ +豀[=0 3c\x,` <0`t1݋uYsX.K e@]ftut +{,p#b%Հ8 +!J Mc` pu%`wMJcIRX@  c{{,@c!!-XnlX9 ZX[Xn>WB,3osn B >0>`EM ܍Ӂ15X.Xp o!Bյ@V +KcV@$qu% 8P<dpcAwI:5y,@^3J w)b=KTǂ ڲ dcAZ)cAnR>WcA!ruEx,@b걠$)y,( eX ?؂LcHjXP4c?zB-Ⱡ XBŤXK< x,( `x,RjBf"lA.t1z, XPS.3K՞NcA,UXi&H` 0cmX6:* jMݬ j-Ħ7ǂFǂF9XcA$ 0/mY=4&7smlⱠ lQ( ijμ<]-ǂ7o"w7{\j<4{,l=Zj;ЫX[#{Z̀_#0;˚S,PFr E>&WL8>GTPfb70-sbD/?xo?NODdXM0Uؚ퀇f! :fDi,nf$b,8salw&k)D gDNY &ዓtc1;|rN'yΧrFF(|:_nHp6VOl$~@`Ҏے],ƧqcjF)nv2¿{}OOb6+lw/_뷇i}믟i rfYkր Wǭ߿>Y {|W܆'uOTRB*o8^ll l|˰&ExN@J?Ƽ.bQ:8ͼ[j^m=tVzqY}v*Hn~X6ݭ;di9^&B>$ Dcco؝u߀a/m4T8q qIbTsݠ̗K *Å=硦ߏ{yA&|QZCMy Ñt{(6;MAEۘ<гqz_Ir~e 3QKoϛӈHzRO#%+wcnDT}-Qg9V7;#NZEE=aۣҧ?oώw7(l`f>`1^$+a& IZ0uW +yvT'W}O(r:x*iҼamUϧ߁ͼ=V7{p?Y@h_{d0ëa{9nܞ2ec6hgǕXƱEO^z?JoM=HC+U^6I0[pM\Sǃ"X$;&ܿhKb/8d%˒NmqcIX},7x;{;uQ3k=-xfg Ί7ői교8I'S-_J]% DCƋQmH"c~Ni`2j$=dk#z8tTں)3Թ;Gk!_F5%nҕ2f?8u*!4eJK2;O!5l_g\jvbssϝxRf]b%Aw;..[Hh42F<ahw.|6['lN)}}:Kdފp-s5ٖ=so,+2__9?9-`x]mz1maS,=:kiqhWN.4B7E^<.8`.q]:u<$\ҡT(.۴L ȵz_֡`kX䩓̮MwvK^ K\;mg8FqM}t}HW1R.Xsx;wzh̩1S 9XctYm/kegb2b6ZwvR9ŔzZQNuTUYkx#[e͒#,TfIېiH)jzU!sT+X+X%N ՜=aÖH]F^\~VL%/&> +endobj +879 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 799.173057 99.933071 780.423057 ] +/BS << +/W 0 +>> +/Dest (cb237-16) +>> +endobj +880 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 780.226036 99.933071 761.476036 ] +/BS << +/W 0 +>> +/Dest (cb237-17) +>> +endobj +881 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 761.279014 99.933071 742.529014 ] +/BS << +/W 0 +>> +/Dest (cb237-18) +>> +endobj +882 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 742.331993 99.933071 723.581993 ] +/BS << +/W 0 +>> +/Dest (cb237-19) +>> +endobj +883 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 101.433071 681.384971 101.433071 662.634971 ] +/BS << +/W 0 +>> +/Dest (cb238-1) +>> +endobj +884 0 obj +<< +/Filter /FlateDecode +/Length 3336 +>> +stream +x[K$ 賁%z1r9v<6QUXݜݙ]9xvvKE~Tpyrp|yp$ơoI๸Z^T\i)|禨_O?|uױM8GZ!QXLR|2X ,`J)ؚłp{VjXcB  F,--<{A<3EPzx1\[l&JxD.)XrΩZ<,`dI[`*kZ=/R%/`dQX\ ^,٧f K"-AƏN$*ŻSx XA,1C_ 'da@,ql@rP ` 8b^ , sMdP,`adLЖa-} }bz K5ȅ)5 KN  w/PR`f K %BKY`J0p/0pn-,:abƂ` ܍ S"7p7&-,`n-,87. $dZXx^$ ЙHK,,H ZP[ wCB ]ȹYXTdaA>x-,H@b$.da$ a&9j wKDa+C +GjaA"7 2p'" 2p3YF ׀5|ɪHa>`-p,,] "X-,Yp WvlaAn<|&/;ŃY&pa XFZXP"d-,( ekٷ=,0s@2W%eǠUpm*xXXP +;`aR-,;I,,4WՈȂ$d`aA٠5V2{Iⱗ}frv*ZX7NHi `l`mɃ,‚Zl7B装Mo ,,,h>;I-,罅-T7#[Xf~[D~2Ɂ\a}D)9v]qY:Is9fSyJq7dzXkeʆzfs̽~ʬv6$,lNtQ^D׽Dmކ砱a;mtv@`Re4B1PqD~{ћ?hYqCſ2OrwOE@Yq}Dmn2lJ> {#j?тt7:۽\0iӁȏ.nd߿_ ٫IۆgT > +jХ\fEV] +T˖dC$cZKNVx?nt7zdl]RćݜOjYXd4plNՅ(ϙ+8e +]D~}ìߨrN.XlUa/{D!vyĝ~wrד~f̼'BÌv9]MMJ+`R1H4[i$q淁 "ZpO{v R`&quȺp5$9WtOjE< rh./].ucQ1;1ET:E0)&nβ?=~yaǣh':7y3͞An/rn0x +y5 G04L&CEtc F3ҵY{+Ҙ!F6BAOźxBYuT]!\! +SՀmIvS R2U/^ +TARfu׃g &]sЃ<П^_yxP'OUSĄ:ϦR/cq:Ka8싔LrkԂmZWB҃bh~feȔfC-}R9Ţ5L%&*;"̖h&@IsY%A˺Iv?6K2S;+0'! +E߈5g`˗Z +Wu46{ySpLK"\hff͛Szl ˍMg?"[E.3I[+X?cJ/a +endstream +endobj +885 0 obj +<< +/Type /Page +/Parent 1 0 R +/MediaBox [ 0 0 595.275591 841.889764 ] +/Contents 884 0 R +/Resources 4 0 R +/TrimBox [ 0 0 595.275591 841.889764 ] +/BleedBox [ 0 0 595.275591 841.889764 ] +>> +endobj +886 0 obj +<< +/Filter /FlateDecode +/Length 3182 +>> +stream +x[Mϯ$>!|&`@!?8͏y+[!.v,lN8{ +W5Z[z?}8yWO/qs_I൸Z)K>?v/tӿo Z1?HŕZOD A(%WJLrpbkL5RѨ5DPCcDTh (jP#L5BK!zOePīJ$\3rmQY,d". )0Ys9TLKj>0Y.)z&.*0Y.StaFd*A}`&.Je 2_K}E\"Bp )T BddA$>2@/'ZIFn,ARt3 X@je,ksZ0-9ͭ0 x43&]KeE2.]Pqt* lUߪqpg\ `\Y(8W p/ +)GqwEg\]*k.X-B΍qAb 3jd\A0S3x7$.ĸ\p]*kηZ$.h)2.,|PYqpd*qA(ʠe\5iqAEbd\P"tAk7]@ ](tAȸLjSe\PRz Ve]-k*¸u\E3.;K@ Ȃ2.( T`*r5"3g]d3.@ Y j.X̞qfh%aj&Soʸjv*2.@` 2`\vb\XPt jܬ j.GM[oCd| dqȼg\Bz3*ĥ7+&M,H6ɶ, Bʠ F&؉2tMmY z=,tL3`̖=7g\XmY鎁&̭t{1[gAFP+˚U|L8oQeCYu!,\sbL?|N;e|#Y1ڱaߟ`, ~\eA6RC0}űߚC^;Jome?XNizz򴡫ӫef; 􇽎eMJfA|0΁Gl,K[c0{(anCm6ʬ͎{7pw٭P+*p-GY\=7>[qdM[fsCP|=*;݇2Nu}//\KxAX:y@>d7vl|/; l?x +x7čgK' OK9 ȗ{ Yq'h೩Su/y~77;֏ߝ/\?xkOkR  oiޚxrƪUxm7׽5^] ?ZX;lb6Jv{W<맶oϘ6:t9z2Zϴaģ^ݮzne+zgv- p^$|ʛp=4Us}[ғ;טo;,haj0WBYrnz |'mQzh9tK]!??ƠGHn1Ct#9k̍=:vp"1vuYYz G,3:ˡC^z(=ܣrkh7ǖZ?k)H{"#G[}ϨN"#<{XHΨ@2v"lp, +dwRF뺾wޛý.׻𼽥އ40lN# Յh)Y~l cB7l8?d?~a:Nz;b/(U>~zwq৓T.Ϻ4yd`SRJJr\q=cVǝaawfur +r6UeW_ Lߚ[pԡO7tyStaQ6m8?^.vkT5Yb`)&F9 :lj@>Z1S=u8rm#D9Re6,TY.u`-!+v|/yK ty,W4\oew/Y(.wJi<"t);?V#5Ҏ:,B)gw{aaCb7f rϪ$[8LQذC 44]^zpXYΧ.săz7OlzȂjlb /}Nv}\ c3өOsQRl%6YV8e߿NzO[o}&Wv2~3l60F uM<׺G04Le uc2#Ί3c&뭌ΡcC+m]2YSywVtMj^)nFMsȽiz_kk%5Ub+Xb {FgoC<"I}1C'qTmsfЬKؓX>u=vH{:FD1ج 0KqV*3XO>*ӈiP3̖d&@iwzWəKV*){l[oy.ELz,=,ء[Ȭ;!g5ҿQkCE5|᧽% S_}7AeV(yڥO3_o +м-T%վP3/Fy{` +endstream +endobj +887 0 obj +<< +/Type /Page +/Parent 1 0 R +/MediaBox [ 0 0 595.275591 841.889764 ] +/Contents 886 0 R +/Resources 4 0 R +/TrimBox [ 0 0 595.275591 841.889764 ] +/BleedBox [ 0 0 595.275591 841.889764 ] +>> +endobj +888 0 obj +<< +/Filter /FlateDecode +/Length 4325 +>> +stream +x\K$ 賁- l d|fsG(=ݳcHDQGRUhRJ)Of_j4_њhk*>/F6MWGԚ~&VK.9*Xz㒳Ia%`j,spa#5U =B mX֘5:cT1!xl\4K*Ui<V% %Vc5^,ц`4d d Oި&aP5SA@5,]oMְ wFN;LVWѰ w]1AÂu!@>5,]-rw]4NÂu% `( Ǩpt`5,@y 0␖hX")> ZlIÂܵۧb34-ؔ@5,]gѰ : "pzDjܵ "pyC԰X$ -tU^]L-EÂ,9 S$*//0$ax1C5,H]aA轆 kY|q n48 x]crհ w)ljX2\Ѱ.Ȃ4,HՀOaA6 D@ʃ,! X/עaAv;aAv)j}dA,5,-aA [J\baj5,/.iX1AÂ\! \E8dB$ Z ,5,(LFDhԒP ̢aA iTQ *M ʃ, ?TlG PD AÂREÂR 3N&՛YÂj 2> I 3FÂj M4,_RY4,ޠDmͬaA %"EQyISUzdq5hXPSzhX4&2zHPn@&Ef4,@&2[7ޘBgQO 7"G؋h3I=4,KRO VF=60_ca 'yD`1dZd[dn~9|{?ǯImDrR4vUym' 2 /5mԢOAFtdOk:b:\ ID(Pn1s:ILsI+yԹ9ԎGlg9&@%#ѭHwa{4έ.=zӴr&k? 5 +KrXĬPe5gqeB6!IG262 aB䘦$QPRMhPTS;~Ooq\q\'!/:ԛ9'+X[9ߛ|ݗr^p7{s?ݞr YN ְPڧ!}O߾?P?<cl7m7'o:`+vh|gl]|H}hg|!Β|~3iC*uIYkҡMƓ$ўi|My%^U1FU]1NJm4SX?d6[]1h;)5k>q]cX˩[C')7eutj?IqAkrdwIee;!ldKUr=?̽o'*2O4ν}Z hxUuc!uqOSkzhrx^ci?Xk9g([( (PdӲBI Of1g͵~G;ڬQX@RcZjGNzOZxUaeⷱ*Ә:7lg^K{>Ʈs5Y9Ű{3uI_@>?w٢Эz[[BR2cu:kF՝ȫ C>y_r'ю˧qb6{yϯk/K^g{={DZ-+vfO5eN jK6G˾qoɻ1d<}snx]\?u2eC 3ģKܨenjuVn3.e1.iR]n6ݰ?7^=5kEζ* ȏ5r8mF:GŶylR68rF5wsGrxFG9 Z"qF`?cqxP9ǛX'>p+se>Yk͙?]>I1O:V│c9P4wRg뜚 +&q;5)^{OMc{nDW=uV;>eN׳kT:b=2s g"{Py=yRum} [J3Mֶҹj߰.'NZ dɕw!N2G;NK矟}wr2=ŝ-GYݦ[aya۵TVKNVƮ_}_OAONO8Sޞb? i§ 8qOkݮU +(z]!- W' "nk]mFLLJknuPwl,WN"m31ȭFǠasַ +Ϲ nrQ 婘>! F KҾ?}\շvc*ldze^os6_?o[$|f'BU9#am=|h&:zC j`Gz,om w|~ =OO~$’8(rF.tײŒlϐ/r tb匦>򥋼?m\0ɷ+DܙL7dzMY|o!JL,3}m d9YFhtcQ衺4Ct:+ +u7OL'J/X BAslH ;;Cl]ǒ†FűSy*ʚLSe(^Dƙ]]G5צq;In_ ++LdӓD/bLj.*&N qP yڅ äٚoZIM6W7=/xzBC.2y~-:C:ѐ)&Sdrz?ȭ4h4~ rhU.Hlȁ֕C y۪Qt. E}ʶ.gځhҧ^)-nl.> +endobj +890 0 obj +<< +/Filter /FlateDecode +/Length 4317 +>> +stream +x\K$ȳ%Xa~65 }GeHdeDu횚 `PG(2=~ ppԜ|ɻ, >Ysvj*rA ]s:'5 >+咳U 9J2X)8b bH 1Xc,@ U!F́-U +rɃ ,^ .-KW]JIc"'Exd %&Ēej +duY|UrR ɫ=/zqR lLv)e!KRMddaX‚A@Ƀ,֮R-Y(F r,,,@Dj@mb Y)ZX$s2[X%!V-^d+laAȥ\4\b‚\! pEDD/@ / J,-,( LxhPcyfpr*ZXmLHi `&ba$HsLd!a Jn J,G `of ,,,>9 -,罅5䛑-,|XXP#DgJIlaAe"QLdAT} LB tx Ԕ4, @, 7Y.J2Y<."da.o"r{f8Y1^o5K o͚jd &2˒̪*eE%s%MVl Ft?rZO?}=o/?i`IkƊ\6#ՠkBRtS!ny"Cb9 iw-h\tרczϻuwU%'!{w#|ǎIa!N{:O!Xfx\w8#a|D:]yO繢ׄPsTժgKӺe1hY؜oOvtѩWըq 2Hw>U2"\ݪ~׫Ua2eYʕ}\B!yҷVB$ GucÅc~sz $Cܐ)kN.[BOkJEH +!Sæߠ,1`&_$ +;=]{;eZteYʌWzupѺ+w3cFC~zJ+Ɣ[YF=1=l^Oǒ[o"ޓ`gNȡ[6\P!(,/ekfoNn~ǸcZPCPbaF}Elc{S kϿajօik͟;gd1Cʜc/;'.L-=ؚ-jzy<`uARFq1G,Hz9] 8rh'*}>m +ABsڏ ݽXduK VsyÈUE0ɼ/U(~l'r`2?nn/JAJ)qcɎ_I1o̢&7CK[5g*3Nfz0'aZS䧛o\Z< [|#}|͡pD%K.ʗA\lgw?EXM#Aw4^]nr}߆}ٓ>vK"ٲ]Cs-99=Pއ>z};-z:=%?j|* fmuqL~;lq}^- 𹹾qfL e`G vx|"5 3Hއ bnV u1s4X 쓣O%Iaw ^kهCM r-c fv)Sx Z80yI\ylk|ccD}.kx=xƷLK~;kXpG +_!nftsdIdJ$Q+#ps{ǨFH=F.?O"0k=szxzbyv)ޏ˯\9y$1Ik蹤q1 +B5ͰqTT38} |c]>E_ޓ8a]d[`Z=n^@jb=b]ةc]>^1P26xDaFvVr_k1#k{߲:8)`i]3BFzO?u +E^Q;-PUjїG©Y2Zv'_|x?JT~']~/TWi1=7L#z-i>RvOU_}jzރ RY:qOKrZD~71iı`uGV7,*/@%9YrY[ir[R*% Y\[6#wVܱ.ګC@cw}akɎ~<&$ښ/h f}Ƅ:W\+4lX*6fԭUqyDw7i2b?NnƗeI^6̸xJc88oug}@VwˤW?@8uC=~T9H֓8D1coݭzަSx +B2k߅I +YjeYJ(]c +endstream +endobj +891 0 obj +<< +/Type /Page +/Parent 1 0 R +/MediaBox [ 0 0 595.275591 841.889764 ] +/Contents 890 0 R +/Resources 4 0 R +/Annots [ 892 0 R 893 0 R 894 0 R 895 0 R 896 0 R 897 0 R 898 0 R 899 0 R 900 0 R 901 0 R 902 0 R 903 0 R 904 0 R 905 0 R 906 0 R 907 0 R 908 0 R 909 0 R 910 0 R ] +/TrimBox [ 0 0 595.275591 841.889764 ] +/BleedBox [ 0 0 595.275591 841.889764 ] +>> +endobj +892 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 101.433071 766.923057 101.433071 748.173057 ] +/BS << +/W 0 +>> +/Dest (cb241-1) +>> +endobj +893 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 747.976036 99.933071 729.226036 ] +/BS << +/W 0 +>> +/Dest (cb241-2) +>> +endobj +894 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 729.029014 99.933071 710.279014 ] +/BS << +/W 0 +>> +/Dest (cb241-3) +>> +endobj +895 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 710.081993 99.933071 691.331993 ] +/BS << +/W 0 +>> +/Dest (cb241-4) +>> +endobj +896 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 691.134971 99.933071 672.384971 ] +/BS << +/W 0 +>> +/Dest (cb241-5) +>> +endobj +897 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 672.187950 99.933071 653.437950 ] +/BS << +/W 0 +>> +/Dest (cb241-6) +>> +endobj +898 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 653.240928 99.933071 634.490928 ] +/BS << +/W 0 +>> +/Dest (cb241-7) +>> +endobj +899 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 634.293907 99.933071 615.543907 ] +/BS << +/W 0 +>> +/Dest (cb241-8) +>> +endobj +900 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 615.346885 99.933071 596.596885 ] +/BS << +/W 0 +>> +/Dest (cb241-9) +>> +endobj +901 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 596.399864 99.933071 577.649864 ] +/BS << +/W 0 +>> +/Dest (cb241-10) +>> +endobj +902 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 577.452842 99.933071 558.702842 ] +/BS << +/W 0 +>> +/Dest (cb241-11) +>> +endobj +903 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 520.611778 99.933071 501.861778 ] +/BS << +/W 0 +>> +/Dest (cb241-12) +>> +endobj +904 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 501.664756 99.933071 482.914756 ] +/BS << +/W 0 +>> +/Dest (cb241-13) +>> +endobj +905 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 482.717735 99.933071 463.967735 ] +/BS << +/W 0 +>> +/Dest (cb241-14) +>> +endobj +906 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 463.770714 99.933071 445.020714 ] +/BS << +/W 0 +>> +/Dest (cb241-15) +>> +endobj +907 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 444.823692 99.933071 426.073692 ] +/BS << +/W 0 +>> +/Dest (cb241-16) +>> +endobj +908 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 425.876671 99.933071 407.126671 ] +/BS << +/W 0 +>> +/Dest (cb241-17) +>> +endobj +909 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 406.929649 99.933071 388.179649 ] +/BS << +/W 0 +>> +/Dest (cb241-18) +>> +endobj +910 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 101.433071 345.982628 101.433071 327.232628 ] +/BS << +/W 0 +>> +/Dest (cb242-1) +>> +endobj +911 0 obj +<< +/Title (CIS v1.6 Benchmark - Self-Assessment Guide - Rancher v2.6) +/Dest [ 6 0 R /XYZ 85.009843 502.818898 0 ] +/Count 141 +/First 912 0 R +/Last 1048 0 R +/Parent 1053 0 R +>> +endobj +912 0 obj +<< +/Title (CIS v1.6 Kubernetes Benchmark - Rancher v2.6 with Kubernetes v1.18 to v1.21) +/Dest [ 304 0 R /XYZ 84.259843 784.970079 0 ] +/Count 2 +/First 913 0 R +/Last 914 0 R +/Parent 911 0 R +/Next 915 0 R +>> +endobj +913 0 obj +<< +/Title (Overview) +/Dest [ 304 0 R /XYZ 84.259843 704.822079 0 ] +/Count 0 +/Parent 912 0 R +/Next 914 0 R +>> +endobj +914 0 obj +<< +/Title (Testing controls methodology) +/Dest [ 304 0 R /XYZ 84.259843 166.076079 0 ] +/Count 0 +/Prev 913 0 R +/Parent 912 0 R +>> +endobj +915 0 obj +<< +/Title (Controls) +/Dest [ 309 0 R /XYZ 84.259843 608.631496 0 ] +/Count 0 +/Prev 912 0 R +/Parent 911 0 R +/Next 916 0 R +>> +endobj +916 0 obj +<< +/Title (1.1 Master Node Configuration Files) +/Dest [ 313 0 R /XYZ 41.740157 784.430079 0 ] +/Count 21 +/Prev 915 0 R +/First 917 0 R +/Last 937 0 R +/Parent 911 0 R +/Next 938 0 R +>> +endobj +917 0 obj +<< +/Title (1.1.1 Ensure that the API server pod specification file permissions are set to 644 or more restrictive \(Automated\)) +/Dest [ 313 0 R /XYZ 84.259843 684.651496 0 ] +/Count 0 +/Parent 916 0 R +/Next 918 0 R +>> +endobj +918 0 obj +<< +/Title (1.1.2 Ensure that the API server pod specification file ownership is set to root:root \(Automated\)) +/Dest [ 313 0 R /XYZ 84.259843 553.851496 0 ] +/Count 0 +/Prev 917 0 R +/Parent 916 0 R +/Next 919 0 R +>> +endobj +919 0 obj +<< +/Title (1.1.3 Ensure that the controller manager pod specification file permissions are set to 644 or more restrictive \(Automated\)) +/Dest [ 313 0 R /XYZ 84.259843 423.051496 0 ] +/Count 0 +/Prev 918 0 R +/Parent 916 0 R +/Next 920 0 R +>> +endobj +920 0 obj +<< +/Title (1.1.4 Ensure that the controller manager pod specification file ownership is set to root:root \(Automated\)) +/Dest [ 313 0 R /XYZ 84.259843 277.251496 0 ] +/Count 0 +/Prev 919 0 R +/Parent 916 0 R +/Next 921 0 R +>> +endobj +921 0 obj +<< +/Title (1.1.5 Ensure that the scheduler pod specification file permissions are set to 644 or more restrictive \(Automated\)) +/Dest [ 313 0 R /XYZ 84.259843 146.451496 0 ] +/Count 0 +/Prev 920 0 R +/Parent 916 0 R +/Next 922 0 R +>> +endobj +922 0 obj +<< +/Title (1.1.6 Ensure that the scheduler pod specification file ownership is set to root:root \(Automated\)) +/Dest [ 315 0 R /XYZ 84.259843 739.970079 0 ] +/Count 0 +/Prev 921 0 R +/Parent 916 0 R +/Next 923 0 R +>> +endobj +923 0 obj +<< +/Title (1.1.7 Ensure that the etcd pod specification file permissions are set to 644 or more restrictive \(Automated\)) +/Dest [ 315 0 R /XYZ 84.259843 609.170079 0 ] +/Count 0 +/Prev 922 0 R +/Parent 916 0 R +/Next 924 0 R +>> +endobj +924 0 obj +<< +/Title (1.1.8 Ensure that the etcd pod specification file ownership is set to root:root \(Automated\)) +/Dest [ 315 0 R /XYZ 84.259843 478.370079 0 ] +/Count 0 +/Prev 923 0 R +/Parent 916 0 R +/Next 925 0 R +>> +endobj +925 0 obj +<< +/Title (1.1.9 Ensure that the Container Network Interface file permissions are set to 644 or more restrictive \(Manual\)) +/Dest [ 315 0 R /XYZ 84.259843 347.570079 0 ] +/Count 0 +/Prev 924 0 R +/Parent 916 0 R +/Next 926 0 R +>> +endobj +926 0 obj +<< +/Title (1.1.10 Ensure that the Container Network Interface file ownership is set to root:root \(Manual\)) +/Dest [ 315 0 R /XYZ 84.259843 170.823057 0 ] +/Count 0 +/Prev 925 0 R +/Parent 916 0 R +/Next 927 0 R +>> +endobj +927 0 obj +<< +/Title (1.1.13 Ensure that the admin.conf file permissions are set to 644 or more restrictive \(Automated\)) +/Dest [ 318 0 R /XYZ 84.259843 694.023057 0 ] +/Count 0 +/Prev 926 0 R +/Parent 916 0 R +/Next 928 0 R +>> +endobj +928 0 obj +<< +/Title (1.1.14 Ensure that the admin.conf file ownership is set to root:root \(Automated\)) +/Dest [ 318 0 R /XYZ 84.259843 578.223057 0 ] +/Count 0 +/Prev 927 0 R +/Parent 916 0 R +/Next 929 0 R +>> +endobj +929 0 obj +<< +/Title (1.1.15 Ensure that the scheduler.conf file permissions are set to 644 or more restrictive \(Automated\)) +/Dest [ 318 0 R /XYZ 84.259843 462.423057 0 ] +/Count 0 +/Prev 928 0 R +/Parent 916 0 R +/Next 930 0 R +>> +endobj +930 0 obj +<< +/Title (1.1.16 Ensure that the scheduler.conf file ownership is set to root:root \(Automated\)) +/Dest [ 318 0 R /XYZ 84.259843 331.623057 0 ] +/Count 0 +/Prev 929 0 R +/Parent 916 0 R +/Next 931 0 R +>> +endobj +931 0 obj +<< +/Title (1.1.17 Ensure that the controller-manager.conf file permissions are set to 644 or more restrictive \(Automated\)) +/Dest [ 318 0 R /XYZ 84.259843 200.823057 0 ] +/Count 0 +/Prev 930 0 R +/Parent 916 0 R +/Next 932 0 R +>> +endobj +932 0 obj +<< +/Title (1.1.18 Ensure that the controller-manager.conf file ownership is set to root:root \(Automated\)) +/Dest [ 321 0 R /XYZ 84.259843 799.370079 0 ] +/Count 0 +/Prev 931 0 R +/Parent 916 0 R +/Next 933 0 R +>> +endobj +933 0 obj +<< +/Title (1.1.19 Ensure that the Kubernetes PKI directory and file ownership is set to root:root \(Automated\)) +/Dest [ 321 0 R /XYZ 84.259843 668.570079 0 ] +/Count 0 +/Prev 932 0 R +/Parent 916 0 R +/Next 934 0 R +>> +endobj +934 0 obj +<< +/Title (1.1.20 Ensure that the Kubernetes PKI certificate file permissions are set to 644 or more restrictive \(Automated\)) +/Dest [ 345 0 R /XYZ 84.259843 184.188585 0 ] +/Count 0 +/Prev 933 0 R +/Parent 916 0 R +/Next 935 0 R +>> +endobj +935 0 obj +<< +/Title (1.1.21 Ensure that the Kubernetes PKI key file permissions are set to 600 \(Automated\)) +/Dest [ 436 0 R /XYZ 84.259843 702.470079 0 ] +/Count 0 +/Prev 934 0 R +/Parent 916 0 R +/Next 936 0 R +>> +endobj +936 0 obj +<< +/Title (1.1.11 Ensure that the etcd data directory permissions are set to 700 or more restrictive \(Automated\)) +/Dest [ 499 0 R /XYZ 84.259843 563.129014 0 ] +/Count 0 +/Prev 935 0 R +/Parent 916 0 R +/Next 937 0 R +>> +endobj +937 0 obj +<< +/Title (1.1.12 Ensure that the etcd data directory ownership is set to etcd:etcd \(Automated\)) +/Dest [ 499 0 R /XYZ 84.259843 234.881993 0 ] +/Count 0 +/Prev 936 0 R +/Parent 916 0 R +>> +endobj +938 0 obj +<< +/Title (1.2 API Server) +/Dest [ 508 0 R /XYZ 41.740157 784.430079 0 ] +/Count 35 +/Prev 916 0 R +/First 939 0 R +/Last 973 0 R +/Parent 911 0 R +/Next 974 0 R +>> +endobj +939 0 obj +<< +/Title (1.2.1 Ensure that the --anonymous-auth argument is set to false \(Automated\)) +/Dest [ 508 0 R /XYZ 84.259843 720.651496 0 ] +/Count 0 +/Parent 938 0 R +/Next 940 0 R +>> +endobj +940 0 obj +<< +/Title (1.2.2 Ensure that the --basic-auth-file argument is not set \(Automated\)) +/Dest [ 511 0 R /XYZ 84.259843 277.220079 0 ] +/Count 0 +/Prev 939 0 R +/Parent 938 0 R +/Next 941 0 R +>> +endobj +941 0 obj +<< +/Title (1.2.3 Ensure that the --token-auth-file parameter is not set \(Automated\)) +/Dest [ 516 0 R /XYZ 84.259843 558.470079 0 ] +/Count 0 +/Prev 940 0 R +/Parent 938 0 R +/Next 942 0 R +>> +endobj +942 0 obj +<< +/Title (1.2.4 Ensure that the --kubelet-https argument is set to true \(Automated\)) +/Dest [ 521 0 R /XYZ 84.259843 799.370079 0 ] +/Count 0 +/Prev 941 0 R +/Parent 938 0 R +/Next 943 0 R +>> +endobj +943 0 obj +<< +/Title (1.2.5 Ensure that the --kubelet-client-certificate and --kubelet-client-key arguments are set as appropriate \(Automated\)) +/Dest [ 524 0 R /XYZ 84.259843 352.220079 0 ] +/Count 0 +/Prev 942 0 R +/Parent 938 0 R +/Next 944 0 R +>> +endobj +944 0 obj +<< +/Title (1.2.6 Ensure that the --kubelet-certificate-authority argument is set as appropriate \(Automated\)) +/Dest [ 529 0 R /XYZ 84.259843 558.470079 0 ] +/Count 0 +/Prev 943 0 R +/Parent 938 0 R +/Next 945 0 R +>> +endobj +945 0 obj +<< +/Title (1.2.7 Ensure that the --authorization-mode argument is not set to AlwaysAllow \(Automated\)) +/Dest [ 534 0 R /XYZ 84.259843 799.370079 0 ] +/Count 0 +/Prev 944 0 R +/Parent 938 0 R +/Next 946 0 R +>> +endobj +946 0 obj +<< +/Title (1.2.8 Ensure that the --authorization-mode argument includes Node \(Automated\)) +/Dest [ 537 0 R /XYZ 84.259843 352.220079 0 ] +/Count 0 +/Prev 945 0 R +/Parent 938 0 R +/Next 947 0 R +>> +endobj +947 0 obj +<< +/Title (1.2.9 Ensure that the --authorization-mode argument includes RBAC \(Automated\)) +/Dest [ 542 0 R /XYZ 84.259843 633.470079 0 ] +/Count 0 +/Prev 946 0 R +/Parent 938 0 R +/Next 948 0 R +>> +endobj +948 0 obj +<< +/Title (1.2.10 Ensure that the admission control plugin EventRateLimit is set \(Automated\)) +/Dest [ 545 0 R /XYZ 84.259843 183.470079 0 ] +/Count 0 +/Prev 947 0 R +/Parent 938 0 R +/Next 949 0 R +>> +endobj +949 0 obj +<< +/Title (1.2.11 Ensure that the admission control plugin AlwaysAdmit is not set \(Automated\)) +/Dest [ 550 0 R /XYZ 84.259843 352.220079 0 ] +/Count 0 +/Prev 948 0 R +/Parent 938 0 R +/Next 950 0 R +>> +endobj +950 0 obj +<< +/Title (1.2.12 Ensure that the admission control plugin AlwaysPullImages is set \(Manual\)) +/Dest [ 555 0 R /XYZ 84.259843 520.970079 0 ] +/Count 0 +/Prev 949 0 R +/Parent 938 0 R +/Next 951 0 R +>> +endobj +951 0 obj +<< +/Title (1.2.13 Ensure that the admission control plugin SecurityContextDeny is set if PodSecurityPolicy is not used \(Manual\)) +/Dest [ 555 0 R /XYZ 84.259843 314.223057 0 ] +/Count 0 +/Prev 950 0 R +/Parent 938 0 R +/Next 952 0 R +>> +endobj +952 0 obj +<< +/Title (1.2.14 Ensure that the admission control plugin ServiceAccount is set \(Automated\)) +/Dest [ 559 0 R /XYZ 84.259843 799.370079 0 ] +/Count 0 +/Prev 951 0 R +/Parent 938 0 R +/Next 953 0 R +>> +endobj +953 0 obj +<< +/Title (1.2.15 Ensure that the admission control plugin NamespaceLifecycle is set \(Automated\)) +/Dest [ 562 0 R /XYZ 84.259843 314.720079 0 ] +/Count 0 +/Prev 952 0 R +/Parent 938 0 R +/Next 954 0 R +>> +endobj +954 0 obj +<< +/Title (1.2.16 Ensure that the admission control plugin PodSecurityPolicy is set \(Automated\)) +/Dest [ 567 0 R /XYZ 84.259843 558.470079 0 ] +/Count 0 +/Prev 953 0 R +/Parent 938 0 R +/Next 955 0 R +>> +endobj +955 0 obj +<< +/Title (1.2.17 Ensure that the admission control plugin NodeRestriction is set \(Automated\)) +/Dest [ 572 0 R /XYZ 84.259843 708.470079 0 ] +/Count 0 +/Prev 954 0 R +/Parent 938 0 R +/Next 956 0 R +>> +endobj +956 0 obj +<< +/Title (1.2.18 Ensure that the --insecure-bind-address argument is not set \(Automated\)) +/Dest [ 575 0 R /XYZ 84.259843 145.970079 0 ] +/Count 0 +/Prev 955 0 R +/Parent 938 0 R +/Next 957 0 R +>> +endobj +957 0 obj +<< +/Title (1.2.19 Ensure that the --insecure-port argument is set to 0 \(Automated\)) +/Dest [ 580 0 R /XYZ 84.259843 427.220079 0 ] +/Count 0 +/Prev 956 0 R +/Parent 938 0 R +/Next 958 0 R +>> +endobj +958 0 obj +<< +/Title (1.2.20 Ensure that the --secure-port argument is not set to 0 \(Automated\)) +/Dest [ 585 0 R /XYZ 84.259843 708.470079 0 ] +/Count 0 +/Prev 957 0 R +/Parent 938 0 R +/Next 959 0 R +>> +endobj +959 0 obj +<< +/Title (1.2.21 Ensure that the --profiling argument is set to false \(Automated\)) +/Dest [ 588 0 R /XYZ 84.259843 258.470079 0 ] +/Count 0 +/Prev 958 0 R +/Parent 938 0 R +/Next 960 0 R +>> +endobj +960 0 obj +<< +/Title (1.2.22 Ensure that the --audit-log-path argument is set \(Automated\)) +/Dest [ 593 0 R /XYZ 84.259843 558.470079 0 ] +/Count 0 +/Prev 959 0 R +/Parent 938 0 R +/Next 961 0 R +>> +endobj +961 0 obj +<< +/Title (1.2.23 Ensure that the --audit-log-maxage argument is set to 30 or as appropriate \(Automated\)) +/Dest [ 598 0 R /XYZ 84.259843 799.370079 0 ] +/Count 0 +/Prev 960 0 R +/Parent 938 0 R +/Next 962 0 R +>> +endobj +962 0 obj +<< +/Title (1.2.24 Ensure that the --audit-log-maxbackup argument is set to 10 or as appropriate \(Automated\)) +/Dest [ 601 0 R /XYZ 84.259843 352.220079 0 ] +/Count 0 +/Prev 961 0 R +/Parent 938 0 R +/Next 963 0 R +>> +endobj +963 0 obj +<< +/Title (1.2.25 Ensure that the --audit-log-maxsize argument is set to 100 or as appropriate \(Automated\)) +/Dest [ 606 0 R /XYZ 84.259843 633.470079 0 ] +/Count 0 +/Prev 962 0 R +/Parent 938 0 R +/Next 964 0 R +>> +endobj +964 0 obj +<< +/Title (1.2.26 Ensure that the --request-timeout argument is set as appropriate \(Automated\)) +/Dest [ 609 0 R /XYZ 84.259843 183.470079 0 ] +/Count 0 +/Prev 963 0 R +/Parent 938 0 R +/Next 965 0 R +>> +endobj +965 0 obj +<< +/Title (1.2.27 Ensure that the --service-account-lookup argument is set to true \(Automated\)) +/Dest [ 614 0 R /XYZ 84.259843 408.470079 0 ] +/Count 0 +/Prev 964 0 R +/Parent 938 0 R +/Next 966 0 R +>> +endobj +966 0 obj +<< +/Title (1.2.28 Ensure that the --service-account-key-file argument is set as appropriate \(Automated\)) +/Dest [ 619 0 R /XYZ 84.259843 633.470079 0 ] +/Count 0 +/Prev 965 0 R +/Parent 938 0 R +/Next 967 0 R +>> +endobj +967 0 obj +<< +/Title (1.2.29 Ensure that the --etcd-certfile and --etcd-keyfile arguments are set as appropriate \(Automated\)) +/Dest [ 622 0 R /XYZ 84.259843 183.470079 0 ] +/Count 0 +/Prev 966 0 R +/Parent 938 0 R +/Next 968 0 R +>> +endobj +968 0 obj +<< +/Title (1.2.30 Ensure that the --tls-cert-file and --tls-private-key-file arguments are set as appropriate \(Automated\)) +/Dest [ 627 0 R /XYZ 84.259843 427.220079 0 ] +/Count 0 +/Prev 967 0 R +/Parent 938 0 R +/Next 969 0 R +>> +endobj +969 0 obj +<< +/Title (1.2.31 Ensure that the --client-ca-file argument is set as appropriate \(Automated\)) +/Dest [ 632 0 R /XYZ 84.259843 633.470079 0 ] +/Count 0 +/Prev 968 0 R +/Parent 938 0 R +/Next 970 0 R +>> +endobj +970 0 obj +<< +/Title (1.2.32 Ensure that the --etcd-cafile argument is set as appropriate \(Automated\)) +/Dest [ 635 0 R /XYZ 84.259843 183.470079 0 ] +/Count 0 +/Prev 969 0 R +/Parent 938 0 R +/Next 971 0 R +>> +endobj +971 0 obj +<< +/Title (1.2.33 Ensure that the --encryption-provider-config argument is set as appropriate \(Automated\)) +/Dest [ 640 0 R /XYZ 84.259843 427.220079 0 ] +/Count 0 +/Prev 970 0 R +/Parent 938 0 R +/Next 972 0 R +>> +endobj +972 0 obj +<< +/Title (1.2.34 Ensure that encryption providers are appropriately configured \(Automated\)) +/Dest [ 645 0 R /XYZ 84.259843 670.970079 0 ] +/Count 0 +/Prev 971 0 R +/Parent 938 0 R +/Next 973 0 R +>> +endobj +973 0 obj +<< +/Title (1.2.35 Ensure that the API Server only makes use of Strong Cryptographic Ciphers \(Automated\)) +/Dest [ 667 0 R /XYZ 84.259843 506.287950 0 ] +/Count 0 +/Prev 972 0 R +/Parent 938 0 R +>> +endobj +974 0 obj +<< +/Title (1.3 Controller Manager) +/Dest [ 676 0 R /XYZ 41.740157 784.430079 0 ] +/Count 7 +/Prev 938 0 R +/First 975 0 R +/Last 981 0 R +/Parent 911 0 R +/Next 982 0 R +>> +endobj +975 0 obj +<< +/Title (1.3.1 Ensure that the --terminated-pod-gc-threshold argument is set as appropriate \(Automated\)) +/Dest [ 676 0 R /XYZ 84.259843 720.651496 0 ] +/Count 0 +/Parent 974 0 R +/Next 976 0 R +>> +endobj +976 0 obj +<< +/Title (1.3.2 Ensure that the --profiling argument is set to false \(Automated\)) +/Dest [ 676 0 R /XYZ 84.259843 167.404475 0 ] +/Count 0 +/Prev 975 0 R +/Parent 974 0 R +/Next 977 0 R +>> +endobj +977 0 obj +<< +/Title (1.3.3 Ensure that the --use-service-account-credentials argument is set to true \(Automated\)) +/Dest [ 679 0 R /XYZ 84.259843 332.523057 0 ] +/Count 0 +/Prev 976 0 R +/Parent 974 0 R +/Next 978 0 R +>> +endobj +978 0 obj +<< +/Title (1.3.4 Ensure that the --service-account-private-key-file argument is set as appropriate \(Automated\)) +/Dest [ 683 0 R /XYZ 84.259843 511.220079 0 ] +/Count 0 +/Prev 977 0 R +/Parent 974 0 R +/Next 979 0 R +>> +endobj +979 0 obj +<< +/Title (1.3.5 Ensure that the --root-ca-file argument is set as appropriate \(Automated\)) +/Dest [ 686 0 R /XYZ 84.259843 670.970079 0 ] +/Count 0 +/Prev 978 0 R +/Parent 974 0 R +/Next 980 0 R +>> +endobj +980 0 obj +<< +/Title (1.3.6 Ensure that the RotateKubeletServerCertificate argument is set to true \(Automated\)) +/Dest [ 689 0 R /XYZ 84.259843 799.370079 0 ] +/Count 0 +/Prev 979 0 R +/Parent 974 0 R +/Next 981 0 R +>> +endobj +981 0 obj +<< +/Title (1.3.7 Ensure that the --bind-address argument is set to 127.0.0.1 \(Automated\)) +/Dest [ 689 0 R /XYZ 84.259843 596.570079 0 ] +/Count 0 +/Prev 980 0 R +/Parent 974 0 R +>> +endobj +982 0 obj +<< +/Title (1.4 Scheduler) +/Dest [ 694 0 R /XYZ 41.740157 784.430079 0 ] +/Count 2 +/Prev 974 0 R +/First 983 0 R +/Last 984 0 R +/Parent 911 0 R +/Next 985 0 R +>> +endobj +983 0 obj +<< +/Title (1.4.1 Ensure that the --profiling argument is set to false \(Automated\)) +/Dest [ 694 0 R /XYZ 84.259843 720.651496 0 ] +/Count 0 +/Parent 982 0 R +/Next 984 0 R +>> +endobj +984 0 obj +<< +/Title (1.4.2 Ensure that the --bind-address argument is set to 127.0.0.1 \(Automated\)) +/Dest [ 694 0 R /XYZ 84.259843 369.904475 0 ] +/Count 0 +/Prev 983 0 R +/Parent 982 0 R +>> +endobj +985 0 obj +<< +/Title (2 Etcd Node Configuration Files) +/Dest [ 700 0 R /XYZ 41.740157 784.430079 0 ] +/Count 7 +/Prev 982 0 R +/First 986 0 R +/Last 992 0 R +/Parent 911 0 R +/Next 993 0 R +>> +endobj +986 0 obj +<< +/Title (2.1 Ensure that the --cert-file and --key-file arguments are set as appropriate \(Automated\)) +/Dest [ 700 0 R /XYZ 84.259843 684.651496 0 ] +/Count 0 +/Parent 985 0 R +/Next 987 0 R +>> +endobj +987 0 obj +<< +/Title (2.2 Ensure that the --client-cert-auth argument is set to true \(Automated\)) +/Dest [ 705 0 R /XYZ 84.259843 558.470079 0 ] +/Count 0 +/Prev 986 0 R +/Parent 985 0 R +/Next 988 0 R +>> +endobj +988 0 obj +<< +/Title (2.3 Ensure that the --auto-tls argument is not set to true \(Automated\)) +/Dest [ 710 0 R /XYZ 84.259843 445.970079 0 ] +/Count 0 +/Prev 987 0 R +/Parent 985 0 R +/Next 989 0 R +>> +endobj +989 0 obj +<< +/Title (2.4 Ensure that the --peer-cert-file and --peer-key-file arguments are set as appropriate \(Automated\)) +/Dest [ 715 0 R /XYZ 84.259843 333.470079 0 ] +/Count 0 +/Prev 988 0 R +/Parent 985 0 R +/Next 990 0 R +>> +endobj +990 0 obj +<< +/Title (2.5 Ensure that the --peer-client-cert-auth argument is set to true \(Automated\)) +/Dest [ 720 0 R /XYZ 84.259843 183.470079 0 ] +/Count 0 +/Prev 989 0 R +/Parent 985 0 R +/Next 991 0 R +>> +endobj +991 0 obj +<< +/Title (2.6 Ensure that the --peer-auto-tls argument is not set to true \(Automated\)) +/Dest [ 727 0 R /XYZ 84.259843 727.220079 0 ] +/Count 0 +/Prev 990 0 R +/Parent 985 0 R +/Next 992 0 R +>> +endobj +992 0 obj +<< +/Title (2.7 Ensure that a unique Certificate Authority is used for etcd \(Automated\)) +/Dest [ 732 0 R /XYZ 84.259843 595.970079 0 ] +/Count 0 +/Prev 991 0 R +/Parent 985 0 R +>> +endobj +993 0 obj +<< +/Title (3.1 Authentication and Authorization) +/Dest [ 739 0 R /XYZ 41.740157 784.430079 0 ] +/Count 1 +/Prev 985 0 R +/First 994 0 R +/Last 994 0 R +/Parent 911 0 R +/Next 995 0 R +>> +endobj +994 0 obj +<< +/Title (3.1.1 Client certificate authentication should not be used for users \(Manual\)) +/Dest [ 739 0 R /XYZ 84.259843 684.651496 0 ] +/Count 0 +/Parent 993 0 R +>> +endobj +995 0 obj +<< +/Title (3.2 Logging) +/Dest [ 741 0 R /XYZ 41.740157 784.430079 0 ] +/Count 2 +/Prev 993 0 R +/First 996 0 R +/Last 997 0 R +/Parent 911 0 R +/Next 998 0 R +>> +endobj +996 0 obj +<< +/Title (3.2.1 Ensure that a minimal audit policy is created \(Automated\)) +/Dest [ 741 0 R /XYZ 84.259843 720.651496 0 ] +/Count 0 +/Parent 995 0 R +/Next 997 0 R +>> +endobj +997 0 obj +<< +/Title (3.2.2 Ensure that the audit policy covers key security concerns \(Manual\)) +/Dest [ 744 0 R /XYZ 84.259843 314.720079 0 ] +/Count 0 +/Prev 996 0 R +/Parent 995 0 R +>> +endobj +998 0 obj +<< +/Title (4.1 Worker Node Configuration Files) +/Dest [ 746 0 R /XYZ 41.740157 784.430079 0 ] +/Count 10 +/Prev 995 0 R +/First 999 0 R +/Last 1008 0 R +/Parent 911 0 R +/Next 1009 0 R +>> +endobj +999 0 obj +<< +/Title (4.1.1 Ensure that the kubelet service file permissions are set to 644 or more restrictive \(Automated\)) +/Dest [ 746 0 R /XYZ 84.259843 684.651496 0 ] +/Count 0 +/Parent 998 0 R +/Next 1000 0 R +>> +endobj +1000 0 obj +<< +/Title (4.1.2 Ensure that the kubelet service file ownership is set to root:root \(Automated\)) +/Dest [ 746 0 R /XYZ 84.259843 553.851496 0 ] +/Count 0 +/Prev 999 0 R +/Parent 998 0 R +/Next 1001 0 R +>> +endobj +1001 0 obj +<< +/Title (4.1.3 If proxy kubeconfig file exists ensure permissions are set to 644 or more restrictive \(Automated\)) +/Dest [ 746 0 R /XYZ 84.259843 423.051496 0 ] +/Count 0 +/Prev 1000 0 R +/Parent 998 0 R +/Next 1002 0 R +>> +endobj +1002 0 obj +<< +/Title (4.1.4 Ensure that the proxy kubeconfig file ownership is set to root:root \(Automated\)) +/Dest [ 749 0 R /XYZ 84.259843 763.220079 0 ] +/Count 0 +/Prev 1001 0 R +/Parent 998 0 R +/Next 1003 0 R +>> +endobj +1003 0 obj +<< +/Title (4.1.5 Ensure that the --kubeconfig kubelet.conf file permissions are set to 644 or more restrictive \(Automated\)) +/Dest [ 749 0 R /XYZ 84.259843 454.079014 0 ] +/Count 0 +/Prev 1002 0 R +/Parent 998 0 R +/Next 1004 0 R +>> +endobj +1004 0 obj +<< +/Title (4.1.6 Ensure that the --kubeconfig kubelet.conf file ownership is set to root:root \(Automated\)) +/Dest [ 749 0 R /XYZ 84.259843 163.687950 0 ] +/Count 0 +/Prev 1003 0 R +/Parent 998 0 R +/Next 1005 0 R +>> +endobj +1005 0 obj +<< +/Title (4.1.7 Ensure that the certificate authorities file permissions are set to 644 or more restrictive \(Automated\)) +/Dest [ 753 0 R /XYZ 84.259843 519.629014 0 ] +/Count 0 +/Prev 1004 0 R +/Parent 998 0 R +/Next 1006 0 R +>> +endobj +1006 0 obj +<< +/Title (4.1.8 Ensure that the client certificate authorities file ownership is set to root:root \(Automated\)) +/Dest [ 762 0 R /XYZ 84.259843 799.370079 0 ] +/Count 0 +/Prev 1005 0 R +/Parent 998 0 R +/Next 1007 0 R +>> +endobj +1007 0 obj +<< +/Title (4.1.9 Ensure that the kubelet --config configuration file has permissions set to 644 or more restrictive \(Automated\)) +/Dest [ 762 0 R /XYZ 84.259843 383.493907 0 ] +/Count 0 +/Prev 1006 0 R +/Parent 998 0 R +/Next 1008 0 R +>> +endobj +1008 0 obj +<< +/Title (4.1.10 Ensure that the kubelet --config configuration file ownership is set to root:root \(Automated\)) +/Dest [ 762 0 R /XYZ 84.259843 195.693907 0 ] +/Count 0 +/Prev 1007 0 R +/Parent 998 0 R +>> +endobj +1009 0 obj +<< +/Title (4.2 Kubelet) +/Dest [ 772 0 R /XYZ 41.740157 784.430079 0 ] +/Count 13 +/Prev 998 0 R +/First 1010 0 R +/Last 1022 0 R +/Parent 911 0 R +/Next 1023 0 R +>> +endobj +1010 0 obj +<< +/Title (4.2.1 Ensure that the anonymous-auth argument is set to false \(Automated\)) +/Dest [ 772 0 R /XYZ 84.259843 720.651496 0 ] +/Count 0 +/Parent 1009 0 R +/Next 1011 0 R +>> +endobj +1011 0 obj +<< +/Title (4.2.2 Ensure that the --authorization-mode argument is not set to AlwaysAllow \(Automated\)) +/Dest [ 772 0 R /XYZ 84.259843 332.207453 0 ] +/Count 0 +/Prev 1010 0 R +/Parent 1009 0 R +/Next 1012 0 R +>> +endobj +1012 0 obj +<< +/Title (4.2.3 Ensure that the --client-ca-file argument is set as appropriate \(Automated\)) +/Dest [ 777 0 R /XYZ 84.259843 675.273057 0 ] +/Count 0 +/Prev 1011 0 R +/Parent 1009 0 R +/Next 1013 0 R +>> +endobj +1013 0 obj +<< +/Title (4.2.4 Ensure that the --read-only-port argument is set to 0 \(Automated\)) +/Dest [ 777 0 R /XYZ 84.259843 301.829014 0 ] +/Count 0 +/Prev 1012 0 R +/Parent 1009 0 R +/Next 1014 0 R +>> +endobj +1014 0 obj +<< +/Title (4.2.5 Ensure that the --streaming-connection-idle-timeout argument is not set to 0 \(Automated\)) +/Dest [ 782 0 R /XYZ 84.259843 641.326036 0 ] +/Count 0 +/Prev 1013 0 R +/Parent 1009 0 R +/Next 1015 0 R +>> +endobj +1015 0 obj +<< +/Title (4.2.6 Ensure that the --protect-kernel-defaults argument is set to true \(Automated\)) +/Dest [ 788 0 R /XYZ 84.259843 445.970079 0 ] +/Count 0 +/Prev 1014 0 R +/Parent 1009 0 R +/Next 1016 0 R +>> +endobj +1016 0 obj +<< +/Title (4.2.7 Ensure that the --make-iptables-util-chains argument is set to true \(Automated\)) +/Dest [ 792 0 R /XYZ 84.259843 799.370079 0 ] +/Count 0 +/Prev 1015 0 R +/Parent 1009 0 R +/Next 1017 0 R +>> +endobj +1017 0 obj +<< +/Title (4.2.8 Ensure that the --hostname-override argument is not set \(Manual\)) +/Dest [ 792 0 R /XYZ 84.259843 425.926036 0 ] +/Count 0 +/Prev 1016 0 R +/Parent 1009 0 R +/Next 1018 0 R +>> +endobj +1018 0 obj +<< +/Title (4.2.9 Ensure that the --event-qps argument is set to 0 or a level which ensures appropriate event capture \(Automated\)) +/Dest [ 792 0 R /XYZ 84.259843 208.126036 0 ] +/Count 0 +/Prev 1017 0 R +/Parent 1009 0 R +/Next 1019 0 R +>> +endobj +1019 0 obj +<< +/Title (4.2.10 Ensure that the --tls-cert-file and --tls-private-key-file arguments are set as appropriate \(Automated\)) +/Dest [ 796 0 R /XYZ 84.259843 542.326036 0 ] +/Count 0 +/Prev 1018 0 R +/Parent 1009 0 R +/Next 1020 0 R +>> +endobj +1020 0 obj +<< +/Title (4.2.11 Ensure that the --rotate-certificates argument is not set to false \(Automated\)) +/Dest [ 796 0 R /XYZ 84.259843 138.881993 0 ] +/Count 0 +/Prev 1019 0 R +/Parent 1009 0 R +/Next 1021 0 R +>> +endobj +1021 0 obj +<< +/Title (4.2.12 Verify that the RotateKubeletServerCertificate argument is set to true \(Automated\)) +/Dest [ 806 0 R /XYZ 84.259843 670.970079 0 ] +/Count 0 +/Prev 1020 0 R +/Parent 1009 0 R +/Next 1022 0 R +>> +endobj +1022 0 obj +<< +/Title (4.2.13 Ensure that the Kubelet only makes use of Strong Cryptographic Ciphers \(Automated\)) +/Dest [ 806 0 R /XYZ 84.259843 392.223057 0 ] +/Count 0 +/Prev 1021 0 R +/Parent 1009 0 R +>> +endobj +1023 0 obj +<< +/Title (5.1 RBAC and Service Accounts) +/Dest [ 813 0 R /XYZ 41.740157 784.430079 0 ] +/Count 6 +/Prev 1009 0 R +/First 1024 0 R +/Last 1029 0 R +/Parent 911 0 R +/Next 1030 0 R +>> +endobj +1024 0 obj +<< +/Title (5.1.1 Ensure that the cluster-admin role is only used where required \(Manual\)) +/Dest [ 813 0 R /XYZ 84.259843 684.651496 0 ] +/Count 0 +/Parent 1023 0 R +/Next 1025 0 R +>> +endobj +1025 0 obj +<< +/Title (5.1.2 Minimize access to secrets \(Manual\)) +/Dest [ 813 0 R /XYZ 84.259843 523.851496 0 ] +/Count 0 +/Prev 1024 0 R +/Parent 1023 0 R +/Next 1026 0 R +>> +endobj +1026 0 obj +<< +/Title (5.1.3 Minimize wildcard use in Roles and ClusterRoles \(Manual\)) +/Dest [ 813 0 R /XYZ 84.259843 423.051496 0 ] +/Count 0 +/Prev 1025 0 R +/Parent 1023 0 R +/Next 1027 0 R +>> +endobj +1027 0 obj +<< +/Title (5.1.4 Minimize access to create pods \(Manual\)) +/Dest [ 813 0 R /XYZ 84.259843 307.251496 0 ] +/Count 0 +/Prev 1026 0 R +/Parent 1023 0 R +/Next 1028 0 R +>> +endobj +1028 0 obj +<< +/Title (5.1.5 Ensure that default service accounts are not actively used. \(Automated\)) +/Dest [ 813 0 R /XYZ 84.259843 206.451496 0 ] +/Count 0 +/Prev 1027 0 R +/Parent 1023 0 R +/Next 1029 0 R +>> +endobj +1029 0 obj +<< +/Title (5.1.6 Ensure that Service Account Tokens are only mounted where necessary \(Manual\)) +/Dest [ 840 0 R /XYZ 84.259843 449.446885 0 ] +/Count 0 +/Prev 1028 0 R +/Parent 1023 0 R +>> +endobj +1030 0 obj +<< +/Title (5.2 Pod Security Policies) +/Dest [ 851 0 R /XYZ 41.740157 784.430079 0 ] +/Count 9 +/Prev 1023 0 R +/First 1031 0 R +/Last 1039 0 R +/Parent 911 0 R +/Next 1040 0 R +>> +endobj +1031 0 obj +<< +/Title (5.2.1 Minimize the admission of privileged containers \(Manual\)) +/Dest [ 851 0 R /XYZ 84.259843 720.651496 0 ] +/Count 0 +/Parent 1030 0 R +/Next 1032 0 R +>> +endobj +1032 0 obj +<< +/Title (5.2.2 Minimize the admission of containers wishing to share the host process ID namespace \(Automated\)) +/Dest [ 851 0 R /XYZ 84.259843 589.851496 0 ] +/Count 0 +/Prev 1031 0 R +/Parent 1030 0 R +/Next 1033 0 R +>> +endobj +1033 0 obj +<< +/Title (5.2.3 Minimize the admission of containers wishing to share the host IPC namespace \(Automated\)) +/Dest [ 851 0 R /XYZ 84.259843 238.710432 0 ] +/Count 0 +/Prev 1032 0 R +/Parent 1030 0 R +/Next 1034 0 R +>> +endobj +1034 0 obj +<< +/Title (5.2.4 Minimize the admission of containers wishing to share the host network namespace \(Automated\)) +/Dest [ 854 0 R /XYZ 84.259843 603.629014 0 ] +/Count 0 +/Prev 1033 0 R +/Parent 1030 0 R +/Next 1035 0 R +>> +endobj +1035 0 obj +<< +/Title (5.2.5 Minimize the admission of containers with allowPrivilegeEscalation \(Automated\)) +/Dest [ 854 0 R /XYZ 84.259843 252.487950 0 ] +/Count 0 +/Prev 1034 0 R +/Parent 1030 0 R +/Next 1036 0 R +>> +endobj +1036 0 obj +<< +/Title (5.2.6 Minimize the admission of root containers \(Manual\)) +/Dest [ 858 0 R /XYZ 84.259843 584.681993 0 ] +/Count 0 +/Prev 1035 0 R +/Parent 1030 0 R +/Next 1037 0 R +>> +endobj +1037 0 obj +<< +/Title (5.2.7 Minimize the admission of containers with the NET_RAW capability \(Manual\)) +/Dest [ 858 0 R /XYZ 84.259843 453.881993 0 ] +/Count 0 +/Prev 1036 0 R +/Parent 1030 0 R +/Next 1038 0 R +>> +endobj +1038 0 obj +<< +/Title (5.2.8 Minimize the admission of containers with added capabilities \(Manual\)) +/Dest [ 858 0 R /XYZ 84.259843 323.081993 0 ] +/Count 0 +/Prev 1037 0 R +/Parent 1030 0 R +/Next 1039 0 R +>> +endobj +1039 0 obj +<< +/Title (5.2.9 Minimize the admission of containers with capabilities assigned \(Manual\)) +/Dest [ 858 0 R /XYZ 84.259843 207.281993 0 ] +/Count 0 +/Prev 1038 0 R +/Parent 1030 0 R +>> +endobj +1040 0 obj +<< +/Title (5.3 Network Policies and CNI) +/Dest [ 861 0 R /XYZ 41.740157 784.430079 0 ] +/Count 2 +/Prev 1030 0 R +/First 1041 0 R +/Last 1042 0 R +/Parent 911 0 R +/Next 1043 0 R +>> +endobj +1041 0 obj +<< +/Title (5.3.1 Ensure that the CNI in use supports Network Policies \(Manual\)) +/Dest [ 861 0 R /XYZ 84.259843 684.651496 0 ] +/Count 0 +/Parent 1040 0 R +/Next 1042 0 R +>> +endobj +1042 0 obj +<< +/Title (5.3.2 Ensure that all Namespaces have Network Policies defined \(Automated\)) +/Dest [ 861 0 R /XYZ 84.259843 538.851496 0 ] +/Count 0 +/Prev 1041 0 R +/Parent 1040 0 R +>> +endobj +1043 0 obj +<< +/Title (5.4 Secrets Management) +/Dest [ 885 0 R /XYZ 41.740157 784.430079 0 ] +/Count 2 +/Prev 1040 0 R +/First 1044 0 R +/Last 1045 0 R +/Parent 911 0 R +/Next 1046 0 R +>> +endobj +1044 0 obj +<< +/Title (5.4.1 Prefer using secrets as files over secrets as environment variables \(Manual\)) +/Dest [ 885 0 R /XYZ 84.259843 684.651496 0 ] +/Count 0 +/Parent 1043 0 R +/Next 1045 0 R +>> +endobj +1045 0 obj +<< +/Title (5.4.2 Consider external secret storage \(Manual\)) +/Dest [ 885 0 R /XYZ 84.259843 568.851496 0 ] +/Count 0 +/Prev 1044 0 R +/Parent 1043 0 R +>> +endobj +1046 0 obj +<< +/Title (5.5 Extensible Admission Control) +/Dest [ 887 0 R /XYZ 41.740157 784.430079 0 ] +/Count 1 +/Prev 1043 0 R +/First 1047 0 R +/Last 1047 0 R +/Parent 911 0 R +/Next 1048 0 R +>> +endobj +1047 0 obj +<< +/Title (5.5.1 Configure Image Provenance using ImagePolicyWebhook admission controller \(Manual\)) +/Dest [ 887 0 R /XYZ 84.259843 684.651496 0 ] +/Count 0 +/Parent 1046 0 R +>> +endobj +1048 0 obj +<< +/Title (5.7 General Policies) +/Dest [ 889 0 R /XYZ 41.740157 784.430079 0 ] +/Count 4 +/Prev 1046 0 R +/First 1049 0 R +/Last 1052 0 R +/Parent 911 0 R +>> +endobj +1049 0 obj +<< +/Title (5.7.1 Create administrative boundaries between resources using namespaces \(Manual\)) +/Dest [ 889 0 R /XYZ 84.259843 720.651496 0 ] +/Count 0 +/Parent 1048 0 R +/Next 1050 0 R +>> +endobj +1050 0 obj +<< +/Title (5.7.2 Ensure that the seccomp profile is set to docker/default in your pod definitions \(Manual\)) +/Dest [ 889 0 R /XYZ 84.259843 604.851496 0 ] +/Count 0 +/Prev 1049 0 R +/Parent 1048 0 R +/Next 1051 0 R +>> +endobj +1051 0 obj +<< +/Title (5.7.3 Apply Security Context to Your Pods and Containers \(Manual\)) +/Dest [ 889 0 R /XYZ 84.259843 324.051496 0 ] +/Count 0 +/Prev 1050 0 R +/Parent 1048 0 R +/Next 1052 0 R +>> +endobj +1052 0 obj +<< +/Title (5.7.4 The default namespace should not be used \(Automated\)) +/Dest [ 889 0 R /XYZ 84.259843 193.251496 0 ] +/Count 0 +/Prev 1051 0 R +/Parent 1048 0 R +>> +endobj +1053 0 obj +<< +/Count 142 +/First 911 0 R +/Last 911 0 R +>> +endobj +1054 0 obj +<< +/Length1 41004 +/Filter /FlateDecode +/Length 7588 +>> +stream +x| xUut;YH',-11QZM`D!Ȓ@XAM @aDp\*qЙhԘp{F6K5;Sc')A k*<Ex©3g9Q}Ss +@S2u¼7OOɍZ?͠Ta}.lR9.ǶOl#>Q09qx/a̜ +C +Fj3sJ·w@򳋅Es[> 4zy)} D)T ׼y#C*>vkz޽r!;~P?LA9z!B~Z6D#cVV&mbC^[Ka5@.,tUvlC嵿tݠFXkc?Rx{oVk%^wO#}Z%~[ F3o*?W*֏+_&KWd/9J'x ~t?5` ^8H/ K8q|8J|\sv* +_;8_X8cv]j9=.pwXq{.VQJqsi+,0iK.>&=mɄ9n 6p +TQ럱J+>݈ʏK8(xqOfuwi I{lY*s*3REi.$M +;evi9ev|R%}-/Y"=q\ţ]Rq\1+.|8qN#nBgq9>j/=: +q_Sq +\9Na N+8g78>&=c9.lҨPIp2GgFpφ9'8bᐈi  8pW&ۈ=DZǻrHw;@.f 2|-7pͱWOԫ{I=#,aĴL,rÌ)f)%ؽQnnF욊]:{.9!ubR=xYD8r h3ځ\jH!2#Mts oN1 +aCs141:cG5pph[h` 8Z%M64rTD9Ez(jײIB7d6xuf5p-lΦ*yT:;ʄnT jY +pl(Q-G7h8LcfN #xzEy1[,biC+7!8,DA Ep 4Vq/|E_=ka'/NV%B0jHa3Q=?϶ 1.F]"G %t y< E"H Ѕ{kF`7Fסf ;iYTb O +1V-~ `67}/,ME좈e\(*Ί'̢$&*D{?m#4:oD3vV}ХyCHms, +bHL`]bN!CD/xW9==X!e ++\&]ç 7_+]|zV_A2,,DFE*F`"̑Qks}h]^2H9*1an0gL M 5>S3`ۛ +fVZo$RΑoߚ 6\tL|Bzp7MHO3.-5X\#/`ע/?WniqÜJ76 ~7zX:򔨰.wfz|n'YB1M,&::!F+ kvʨc `hQ1GOņTo4>xS=ԓaVJDJdJT'%:%_/y|ѾȬ,OVtVLVBaŠҨROi򄪄 m]:uȎ̎dGFFz +F.ZYz˙N~!4#-,M55V?^ܐ}dWO/vL!]^=GUBrB8hW*$&ZZGe;%(. nZ<*jI" +#"ލ!~/\jHV]MP +WAqlU|0EMGLt~aIM_2Cª͵V 'y]Y/f"|/Lt}n,\g `0JJ@ySu&-U<ڪՐ1tSm1lJvrUTZ?roi |KVWxUvnʟ)[;>E_wher^c`b#ԝT} h ;viG~][ieNsk/_[yv6?$lݶRټuJw",տ6@U>!:Ab)A5g2f dd7S51* ʱ3/JR,,-Hbl0e2;4r]n>tޕΕP܌}F+Vru؇qk@%gMnҝxWsWK_c_S_s_'$͝ɮQI踄敖W AM-V Da' GaLHNHRIҤ򤪤IBξ=Rۃ,Uwz ee;?7sϷo;,;8zoH-GbcO`X70b$G7i+Y9VI =~Z̤c:mj!K:i@E.TV꫗vJ[6Wؼ}!{-[i }};l9k,2][T}j6+pTY ~nuTSsyb`DŽ]9۶)T?ouܭJ1dɗǙ 7d@/ FΞ^% =wG~t =Ci#Wn`QX(V +KuNAQ'2+ ;ϒ0I(`1EɄL6`٧l<Bo+>h`:^HPP\NM #18KԪX[Fm<}Ye5Nk屧/0$EQl:VVB)g> f>hi>ͥ,jC}PQ7Q >9hS9Def;y͞=}Q(EtUg-Ҿ(4K;-[>Ek}c҂ۭwZ_>Q @$]qdLuJi:io(ͤud0 S:4` t04:da@`3wI~9-dӧ̙EfL$P4UZjaT mZO7?_jV-no?ZDͭ ZCޡ)oZ}CMkmZ ,Dju\8bٖaxFVj5OFC!@=v^"ZSH `CH#<@;j$FC;xuJΙ2sfQ)fzά(SQS#37gMWk +̄9fQ˹yR3F[ӦoDy8f!ϐra><A(tR2-Ue&meX:Ϧj5meߚ J8V;/Ƹ~ByO54Q`1> +endstream +endobj +1055 0 obj +<< +/Length1 7648 +/Filter /FlateDecode +/Length 4714 +>> +stream +x9yxSU眛&-Pڴ P&鞦M=ݒ%;m)tR"oTe(::q ysޟ}{9wo9#fQ e\Xм`tUQ3O+qj{a z|}L|E[p߮J5k;@ն@ahٿgc!{E/Ee>;Yvn^LY,BsޅGV T@_GqW0 #?EO2+))A Y \B)~y~m +!/-:nXݦ +ZpvdB9s&LZ>=*E{eǏew2|i a=J$%NNV0f%k& Bd5вmQdkANFi$9wПȉJ*aym1;"P9{ 1g_gA0;y^^~cԁ1lT'$ҍIQ}D -!5*hT܍aB Ff?HB&Z# T,xcoDh.gR`Ky`ȃjn@Ь& ;lۗO Ǘ^=ނr}bfq!iB += _. Lg A$@+p :N +Ňyz ;* .6w +_^%,{ED}>#|vxIx_s򈦈E<nWfCY~IF\HdOϟ1Tf\nqPhS"\d⤚Qk34:r'B$FQJ-zO2gi+}aBW-;S$/7cGe,x.XЗu +].QCX(,+*LIDI#pI醙 9c2XHfH%s]}]m^p(NEtp.wFJ j15Qjظ,"Jkj8щwʎ#'u<܎O:RT3D ed7+ߝ8mVn߾h]CL-2T=P1;Pk.ЏD# Fd_u;D`؂+oY:V#qp*N2K(/U(g峅xVXCNb,x?U 3O]?">E/ >A(f|D"1Q9+.Ui]݇HY*5 f)G~+mʚ56ۚ>!հb8E/u!aĢp2| + +9QL"6](Idgk7L`miWq ޼^a[33T(<hhjH7E#װZ8>h5g8ΟW&EzHsp{[ sdy+Zsl{4z"g4 'Rbl1inc_/sn3 +yOyF,hɾ^JXFs5jW{vEyǦՑn}Iii$f9>N\\'2P]/.`]@š#)/Ӏͤ"4h +w&8>UXUضVhLo#*uwQCxEgكr3먯WSdNަ'6FsxnHň._\к9 gZm7׻]덆ρV x'r1\]?/:2B*"cvlvmi/Lr\.<k>w_#6H%/Rhk;)1yu1l/U195Y0fki֭xJc26P0oc#WXjqaJMNBQvTn;Z|ƿhw6Ky;b 9Dw&ʘ'cZo7[y:#FH8lx8&D% Nj*d)dTztf6ؗfr;ÛlyY"p͝QzeV]Q8 hfG.r5@A(5_;yl?Ya:c*&jv0P!OYcن@͵55xTegU`8=C(~{GN0cI5Ԛ1 oZi9uut`c8am,spţsQ .Mr{bJWAA#U%`7ܳdI$XNa Ɉ&U_9d4z&!& '褃Btzn7(5#J}Td /odqjzte*e+T}IКoyu4YEN5L.㚜8Qł[p]d[m9;V֙6],rۛ^*a9Į`r3r[6Kg74F5mi*6RV+U]Mݙjwit.NeiuCVNNmK +;D!wjHZ,9%@cZqmi +RJҊ|"\#y2RJL+*FCv]YULĵ3y4k Xc6w䦯9%>oWz+Z%;^wTéL̓5E4xuWW?T}_dMT]>("83DB*lRULӃL&K+u2df #Y5fK3>h: 5˹A,M ީ {Q6t>[2Y?~Q_ p[#K +~tX Rޣ5Pmf/蜯 g5ׁ̓As7@j\;}f^pqR^p?(~grS<; a0 kʊnduK; &˳{g%]nM@J0!q$+yS}ⳁ^oX5jwʥJ/Ovo,*h*Mzo2ox:o@B:iU~r1[zx j7nY?+]nv5?#EjL5~:ϕD+;qRW!Nw)%R*L(S793TOkҳ<9INu\!G +4KMKI s:Ue "䩉XOɅO Y K 2۶Z9ui뉯Է怪YDP4Tpod*@4WXBOukt㳼A0Ƴx|n˖#?sŀsN #AOCJ3X&wmZ_Xۦu;sGYo OǑEF/|b{㖣Oōq8`)y8ێq~ݎwl؉^fP xd}J&䞖=~Չn׏tuj/io 7gB EB4] }iз ȀV>4PjCh" +u!rH 0e~cY-Uh>}f*,< bG" +endstream +endobj +1056 0 obj +<< +/Length1 47128 +/Filter /FlateDecode +/Length 11769 +>> +stream +x} xEhUw2353IH0<W $0 s1bVA +nD֋.rO$XoΡNwUPBH + 3e㫞$Xҷw_}p?+< B{~0!/oCΌYЭx?|Œ H'dxvmsyF݄affrD|^5xv9 myyOr7%'\y}"﷜g异M}jfwj~i\KT)>$ӼA>ReֆmWFߓ|u$]H2Y$~e+9 1A b 1A b 1A b 1A b 1A b 1A b 1A b 1A b 1A b o*v#S$?<<+D~/A$t%I2 !-d$G;.R[xAҊ#|(n>/&/ k~WË+(itUpՑGj۠&CPjR aZ khvݴUn{`M#Ra5.0Qy/N|`z]%]]{[D3 @čeKBqڒ]:a٢N^ e,D,Sͧ)ďe2JhY7DL0KYzĩ׼@8tRYϝ杼j60:;OjV7J u `:YT7Blf)Pw<֞_OUs^,3bf 5KiX !b[^'b[p/~ 8'48+'ƀo ր77j ޜpZK>pJgpD~r"|'֧ᓏZ8 y?R }.V~,Xϵ>~>jGȟWm[bN290f-[emaf-̨0MTSL`s`(h Q&77ˋWBu"/3`Bc~ѣhnT20n0# ,`X䁡7Z!7Zan>  A^8z`@W }xx_/@Z( pz]jZ0Dz:yD@8xO'=ytCU@%rx^r;{xnW:v)rl:Et; +@vmvmBz"d h7L Ӡe:2M4HwC b-j!PD z `@ZyjR<)g<$!?'-?|:o<! qxN;_qH{-rSH1`D]&"@WpxDQj&b@rs&{9uM'޻m!Rډ䯄d#f@bfC ?Eld O"-lGc05q9Md4gjێh2r/yk!Y9;f[msTWyqVj+@=d !E@+Ֆ#~nd4î[]֑-֋޶glg +ϱqYsMstŝc01a c01a c01a c01a c01 }^[=AZG$q͖M U4bu+.`N\~~G⪫ɦ 9KHe^O(տ_f-ZT)~} zD'EWf`&bUױ95Mvf!_,!ЬUZpy$}E'uѽKv{=C)(u +CelN8)[O˧wckd++8hG!}:Yw/gz~ƿ +d?M;t'gF%+I x U޵UgKP}qDI:}u62[nSNuPOY`һ~XI3h3g77DD̠l:.3&+HAZE]a ٮkjDNț眯9fN8ww&6t&vF?+~ž7%"Y$UJ%ry"q,sZ*9ġ4~קFDa5#q/woaq9s'[\-h$%N ؂HhKrr{OBDg!)nYTG.B,wPͺMgh2םS]?kӮ;>xg@×Ya+2(҆x*52|JU|uZuU/!./僀'Ӳ\ujQ8}tJXxu6?|^jIQKRs/ {{BT=uI7=iG~|:M!y`g_4+ S..>uM +_ScP:0"AaVvNaNmIR5A>`M)ǺנyG|( ;]* F-Zux~~)l**Q\|GbI]TeqtTYvsd}U 4g+)lU|%&N#5!Wr1R[ۑM'?ϿD6<|8.?81v灊i'KgJ[.@v6n됪^kF~ NF`vm^۱89q>@YLS$p?X#;+X\NBDgʏ7o(-X-3 /yiPJXf}G~㋊}BOI7*іYEԪ4R-z cF?j3+*fUTfm|7UnjʲϾeЛG9H~*́O2JBB]r +-I Eݔщl2.Q=좪-Hn&yȠMDuh~wQg4ZhK=SʒRTAyP'-mb`gۻF ك"m%;*L!UH' "R$-Ȱ5ǂW"!**7R5\,U + +(6]S5 W% +Bv4i::g35RtpԨ$RW 2\qZz_j0RoQ'ORls|zRks}je%__^%o7ػ״ɇC &ҧ~8ewYXX>L]?^ۆP7{ћ>ӈɐH8ܧD)Q%K9d4B9&[hTR:_I W-PhaΤ.J2F;ͩS_߂Sa]BJa(?Xc-1~|oA[n$K'>cZXF6I.qF]%3ZFUorj >fW CbE+~5uӆvn%nxBAF䩚o4x~} Ә =͔09h\!~tc!('!!-/|W#]IN)-rF쨻S}CӋ甈 O=-Q2XJHa%_%~rIf&eQM^Y?M_6_<m|`=-VĈ5# (}#|UJ]lGkajt@G?%ՌP͆OuٺC7 h #x &I R'[lpRnWOfId9֋ Ԇ|6N+b|VnGCKgBsh?ϤwH.?B=βAsUrX> Ynr]+#,RKlONg,,2MN CDCfXP;*FGz^5(G帨]Lf|,ՙSs5ڰ 2na#-#ɬRf`˴eӬRm$)TGraJspm>1Nm^W{PLKD/y'tߢVm'NDR-y/T?qZXGł6ou~\N1j0Pկ^Cp:RbD'E=gI߰N8f6RʦX੔Iv3/LBbRgU^4H<ٶ[=nbPa=QdBdR9t|J(]h{Y%MwQk}b܌7zbzr$'9S} LIH>#BvےJ;{K5#$ wTu$eq͓*|LLzHNL'%%''y|}ý}CJ%4%gM>s#eM2odpyt #:zT:B%~GKˇF,G={&y*ҚO۰/}]񾞸ݭlujfXwx,\DH#ݡ Fh˥/3"TIF_jY ]Cʭy0tW, ,laÍ*]fbbB쒇0]i\o/{_a08swq6] w=y'#1bX6F5bg:]VcWI$[&kJ+)#cGólKwt>J?[`(6 +nVnCա(fk26&+-%d}1:Vf s۬[ n6\tz[q:Fg@](ו@ZvXC j)ӓRiDLRE}Eo]iҨqƅQ,†">2(I!vl̐l6nˌ5S!V!T7U gSo(W qb>#TPUֺJ+su;x8nʺCU6vn[\渣a$DOg٠==B=3^* fۺ3xg<á'O >z%Jț.-)mH`BZQ޴EivU\ҋ]Zݡ\4V+6s[GX\uq~7͛g3vvzaЀu][J ohߞSR}4\IV7؎:*MG+.hI.3d圏R]7Ľي LL/z5 ͛={vUHŮb -z[^iv||xQ#X8~#2EYqDclH@%Yzىەkg]?"Y+zr$kwՅ +zj"ÞE/ana3JiNsO<\NGq"ՏK@csEyu7*! < +HR/k7+-N?]:}WffcS)͙En QqDD#svn5oe#~8a Oa;{57WHxB1F?J\wȶ*%40[If'sgJ,g$]Ŵ QFJUGst mA5C,[4.֩;+5i.MqxmyŠR]<'7FR\ڴ *]G69ԝN'7ҽt~`t{:uV F""!Ւh4Mwu%oNsğĚ;z֥`p[E ~9Sw(PHF]\*~Ⱦ3}C'(d؈{ݲny |ǻj/ g$P%|.+gl1H={?y\"t-]_ @F=OG~ Eȕ&&ɾ3!d/|odsmF݅&S"Y8]jItMCi;St)q[$r9XE?c"fi]O_j—X$OgcXK567 EH3i1_HDqw&\jf E&ښ y,J?b{0BZ] +Q +6E6a_t?ԨIPscs;tB`Q!}PDsIF?(4=9ѫ(j:vxpV Z>Sv,.ǝx7|maK qբ\1ptl1cʺ+盒yH[rkefp1;UuЭVծ;yz-ɞHt`Mftvulsms{=cum=P3k\.,͖?16BǕNXܓDmw }1g3z~|݄O0:)M{өsZ?J|MFynOb0#6Nm14t4WcFj,̬af /g kwNO:Ğg8]N6xXD'*g'7N1W&n։*fnޱwO@?FOb7Hz"Rd'c"Am'|2RΘNf/4 nޥXUh]&gTfYo4%r?ң?+N]??X 2Wtr57El[k(G<`m!@AZ64lC1b+Et1+JV++u+@_#zN}\ԋaLoڏݏ,#:οq#Feh Qȿ7|̃+8R]M1| ڒYjkup\ڙu]ծ.5,Wg Õh}um)yZd)&E +Vj\c[Q=}ևlKjۖ9a4ź͆Q_^I!8>R>g_Y6o!P?:f+ cb+{<\( +Xh^g"}T+꩚N@jJMEYɓ"|:NIXG) +=eX+-jkM \^asAATl,EI⍀Z(hȶ@(GRmY(5J)I:v|ξWQ>7~&?]/Lѷt:7t>{~,]좃OœC9i^:g*qsrb+47ga0': ;]NUפGB/jZ3yg:(Otq0Xj6_vXraztZ9cN+Q:pfᚏzWZZjKk Oͳ;Io:(you+QcŎJ\\vle`i^حTƫ֗/9fuaz|xtk!Td}#oJ@؅y/[ׁB>u<I Hx6pMQ tթ{?s+~F +F)2fDzܢk.\p5|u6;IyxEC%P/FBP_ *EkH-+ rO ēdsd%z*ST{w }X+`ÇH"ĔgnZB;pUi0Z oȝ]:.(HKkJK?q楹Q JfV% -#̋A-#Pڠed,b'v+t^&tۑxIS&ec;w-\jL%'%G5j +4⸼L4XuҖrb3k܅1H͉fV)_#u5iݠ+&Lb/\泷S{kYϻ/HAZZdxg|m+I.$<޲wa M +oh%B{kԅ;SCru+TW+b`jjL31WG/kw!g(E$$m\JUޡgWS'bCz*y֦KNWJib7LK9`! 4޼ćwkF4ڧHnV]sHg6^$G#e#2L&s̯O@IFWE6sl^f#Ee~< ^z>ܤj6Ufu"]xvފ A-e@`4WO/[j{Kgv y(qT,[(ʵ-IG,;!RTROb"u, L + 6yUa +3hqL/3$JJfDڣTS|3>-EY35lc%d/67T4lnM^W>۰aٿC1=Si޸apyUSYUC8+Vb, GD%ʣOj qyMqA̫s y`_䗸beF,El9U4]sËDɳ 7ɡ(!_RӞ޹\6?o^4k]4E[v ne%}ӷtG"HtcL/W觔+`Cnt\r^r]x#D~pnD1)h^#yHAD RtEM(DF!KB:n@tb|}ߌF?G_9ıG!zqc/}TK(U<,+5c&Y6~VlBXN.YɲI%ex=iV4lrLl3d> +stream +x|yxTŶo {s;ݝN$B&4<a<*C &P"ǃA<!=9\q@#z= +݉N]VZހ0B;̔=/ ӫw~ ;:dx.FAc 8h_Cf4nh:oB|qS,j "DҦ/1o,s ̘h!aCm1wi&Ews ˞ ' ~ p9'̂]0urvlDüO.?_õM s-\;03G-r(#@HD\VdBϞ?Q]~"!-bhd<'cYބ=Fzkg&.HYPQC8WL +~%UBxN](-̎tRwrꄳDA@⅒ -p8h +ޏ7A)rMM([ +/ +ʊYTxW%qJk}*D+ edš{Rl +ү=ch?i=t\F2؎ke?:Q5uóQZ-uA~"ET< +{&M$Fh"Z~1 &߹s߷5MYJ0kG|*}w7}X g\[wB!ROG}>.^N0`halv^prx!Ty N޽k|}M;ufӖZ(I7t"Z +B+ѧtk-atjVb)kp'?/W0te&'}ŏf#1}쨰FG}х.?\\PAK\Fdٌʠ3otF1Z)q*SE⡓DF'ыLt|. v:FOA t#}8->AG0:a>etftN1:0Dsshmb?%eh]C̷u =b~L{Dp1 :1@_$`;h$څ\pn!v@sNٌf "Nh&2̀3M4-B-E;ŎiJ01NS*v8B>1|="g4DF/zvfh,1Mil +@=0hF@QF¬DinF]:g waj0/NmQ+pnͧb&h6SsPv&* dgTdw@0訁VgTNTFuTPQ s8t)Y(E~5?ux83%d֭E#}uÇ ` +Uz@-pmמ,ߠ-t0gPRxC^| z[(p :e<_ +G2 z~_CF6sVT-*CpM1p =Րd:wzۊU \9C& M.86?:.\n[8 FehGB ltFl\GtDm8 aAW)Wh{ ` vm_K>rH+V4~YpȢG}ulG>cj+?l{jr9u?u"/>z<O墑TONtR\95=)َ͛賮dIIuj1j|sr]|3ܪqygfp$SvfFSc.>.'b/Y͙;p𬒺5E;f*Y[ !4hNI]qJJ5%u8o9͝=`ZVzGL;'}5d\3{0\HIYs:eR8X-fvh4t AfdvsN¢lN7P2+mq^_V%Q%5(BNוi +aJ-mΖϛ w"⺡ ԃK+7}O37 Fbm^::cP\[ qU  $ &k:!:1io&L!msپEl_.ζ⡋PұSY ^8x +i7g ++ӿp4@ke :a+ +>EGVYkQ50 kG#^]/dKpUX<_tRv 8ۉW΀r4=z( 6m>pB#tD>Q Pt0Q(M'*u|?x<kk:hbJ}v9(!^_Z~CioɵCs:H)v}p6iI=Şk +f&x9%R ZUxCa^0 m3$V1˗ib]kxixFX<r@0Q!{%厠H$J{* g`G&^2&љ1:#geV m$X| +6}wጓ?EjjjN=VY!3cz7Z&>@oXC-2VJ1*+*+= b@fěA5rrHK7f MM7f|4c;Sv߿e׌.`qIe^:W_-TBY~#P +"ȓ 8@iR7.^Fǁ$a`o)9dM#oy}Hdfs ? 2QT&2{h1<81{c`ҚYhUu%_+k1L],굛cWn?o\Y+W؝,-^lI19QUe붌X+x8}Sէ''亿8*8j$T7԰R'UFUU$ctCOͭ6í7T=,@2cm|XiLee>'RL ,.m&ز{hVֱVA*$j1YHv=NIR4m $,-G>=*P4c+i; +IvB^X"<zD7&*cDpi#%ۗ/}e;w|V +$a  TK)"2ؐ p&ڪR(xy7/_s?5J^ïI[s5aYuBѷkل]l›;PrVÃ2"SY4H>w +w~tHmF1RzCeXE׉KfKc?<`C5>ZtZBs~ +=G鑺jS&y +{'hlNY7lt{z+72DT3D(-l*ӓE8ɠD:u{ v{YF)ɀd;0v4ؽɆY@º5m8O545h 4X,b{Cx%n`gUh"Tf8Jlas9sV3ߪa/;5m.ؖ=77-oYOngomV>mvA^zydovGۅ?ex '/f~UZDA"DQ@>Gk5J"iY AF4,Vh6WUS)*2rDA'K(xL0x2 "o1"n%lݻGXܨRUJ1V;&L!"2yŌtҼ|ц+5S!L[+>]fŏ?~쪕Y|_W2~cTe]G ?R7ֽ`?ScRܨ?:^I[*u*",ÀҥNpwEA웝#9]fqsP'N/}{\}3ygd_X!U֢J:fe%dx]_FՒiZ;OAH܋j]q_<'T~8jz.q4*U,eBmJ&r>2lhy T3ĉ#<8xp%^'.+̠~ L)wqD$ qRI.:.ӂr\e+PI ;Kǯk$[>V29ْ˥x +z^kysGF9:B;GF`vg'qn8e'AW+QSZ~)>tPφJw-G'4Kf4.:1A&a2J)eD"oJ;Hr҅}>X:J, +Q>);̀p,5nigߠtIh)JPǍlHl +|#%wPʔ#2HaMUIRU KU m0T0&iKUۉsbu*.]nOlK:YMFy!}#!V%͇*v_o%hحOC@[aQz02}&*V wEO҉ &8KnO(RDfˋRYuI@TI AT(1 !C +RxCg{z^{ d%nw]:DbhLlʓ1dw'< &):>E,U6@#RHG #űXy2JWo4, KtA1aaSܞ4>6 |.JO\5dP@z~hE (#=X Iz`{C\ \އ!,K)ܟClKLI/?IOMY1+vx!NJV|,B4XS )ҧYn}ْJV,NqF;ϫΫ,* +XFB7у:m"rɂs>e^lMS-S 3gdZMRLD@KIotxXd/-P~;"{㣶%q#֑i-~S#/ (8՛6VO/%}%; zcT8{;:22F\fպ24HtYz[ˈ]ۤJ^:77e@C>kn(NIMUj\Mjjg]ar9Y2x#_ҹ[^v}o/xͦ GN?\Xz{B,|dᴅزrWķw>fIva26qNNan(pt̬+sT#eh,##CV+cb%!O=XzOYۦjcQUǺ:хϚ~<9BĨ'(z| y7JGJG-}4Zt<TZZxQ~ ϰ moW3iKda@{vg.w I\Dd(3˔*S=FD }6}_.>ʅPQݯ阺UEW;=m+3]t,yG؁8gtM]hzz jn^2#~]Vo$ʢ P(%D[Cc.+\-ׯiA'|H>VA% +_yYDz_ꄍkWﱐ c7&/a/N|ev>`AnaH͂ J6tL%a2҉Ѭ%7tD7 }$kCh,W4kw֙Iǔ,PvEIݵo>v2V֑3|̧ DEvs|8X]FوBdҙ(¼Zoџ:Ԗaf jIܚy"~dei]]E{Զ'doyi\ja^0QG[Eu:&ZcI &Js[e( LG<[yxcIrO)ztqHgZZji0mǔ6Bt,H&|RYm: >*dʾKN*]v_ri6w5vEqqp )C,:%NDp &m,KR/nhW'eIDQ‰Kt)Yd1y\(n.-E.%&IrWŗpş13<Y?e3EGJPK#-2A` (נF g1 s@@pvr]{NO&IirKSyykv!OШs8`n=)qGzS>NEyû6Wk2 O<]7ߞ^* ⅒-$|(QF2pֱaBX6Ro<>>\zn_5xy0'Vĵz"5h߯ɏ ⣂qUf|֪` +bHd'KIAyO +npH4DkR径tw!ۦ|ٸ7[3t g/K=бC7El_p||}Viŋ{*"+02 +DȊ)PJt/hޭA 1zV2d&,>sL  XyKlH&!|)LoWU~2) +.6hpn§>x0Gƻ狞,s|.y$$i7 sc>a0D.~F0oxH GH[X_tGأ?'AܮnM-lփTu*LU K4INp`ryWr%'qr"hMR:Abp4Q[ECJI^j/+ $[̕rLOWoFGYt0K,T{TbV݄'?b&d!vSd8S]FV% +a'u20e~~Zvk -tj2e+Ձ I=z0,d~`$ -ԩ*V櫲fj"qh+ YЎ<ϒKdI@P1HUuDUp"L` p]cp[nI-߶YK\l~s:JԆN qY6{Nb4Nɘo 3"L>n5 ZFѴ)~a<~'{ҺrF5X٦A,[bUlnۘ`J0w6> +endobj +1059 0 obj +<< +/Type /Font +/Subtype /CIDFontType2 +/BaseFont /EREYAA+DejaVuSans +/CIDSystemInfo << +/Registry (Adobe) +/Ordering (Identity) +/Supplement 0 +>> +/W [ 3 [ 317 ] 16 [ 360 317 ] 20 [ 636 636 ] 25 [ 636 ] 36 [ 684 686 698 ] 42 [ 774 ] 44 [ 294 ] 53 [ 694 634 ] 68 [ 612 ] 70 [ 549 634 615 352 ] 75 [ 633 277 ] 78 [ 579 277 974 633 611 ] 85 [ 411 520 392 633 591 ] ] +/FontDescriptor 1058 0 R +>> +endobj +1060 0 obj +<< +/Length 744 +>> +stream +/CIDInit /ProcSet findresource begin +12 dict begin +begincmap +/CIDSystemInfo +<< /Registry (Adobe) +/Ordering (UCS) +/Supplement 0 +>> def +/CMapName /Adobe-Identity-UCS def +/CMapType 2 def +1 begincodespacerange +<0000> +endcodespacerange +30 beginbfchar +<0026> <0043> +<002c> <0049> +<0036> <0053> +<0003> <0020> +<0059> <0076> +<0014> <0031> +<0011> <002e> +<0019> <0036> +<0025> <0042> +<0048> <0065> +<0051> <006e> +<0046> <0063> +<004b> <0068> +<0050> <006d> +<0044> <0061> +<0055> <0072> +<004e> <006b> +<0010> <002d> +<004f> <006c> +<0049> <0066> +<0024> <0041> +<0056> <0073> +<0057> <0074> +<002a> <0047> +<0058> <0075> +<004c> <0069> +<0047> <0064> +<0035> <0052> +<0015> <0032> +<0052> <006f> +endbfchar +endcmap +CMapName currentdict /CMap defineresource pop +end +end +endstream +endobj +1061 0 obj +<< +/Type /Font +/Subtype /Type0 +/BaseFont /EREYAA+DejaVuSans +/Encoding /Identity-H +/DescendantFonts [ 1059 0 R ] +/ToUnicode 1060 0 R +>> +endobj +1062 0 obj +<< +/Type /FontDescriptor +/FontName /CHSCVX+Poppins +/FontFamily (Poppins) +/Flags 4 +/FontBBox [ -27 -132 753 704 ] +/ItalicAngle 0 +/Ascent 1049 +/Descent -349 +/CapHeight 704 +/StemV 80 +/StemH 80 +/FontFile2 1055 0 R +>> +endobj +1063 0 obj +<< +/Type /Font +/Subtype /CIDFontType2 +/BaseFont /CHSCVX+Poppins +/CIDSystemInfo << +/Registry (Adobe) +/Ordering (Identity) +/Supplement 0 +>> +/W [ 3 [ 266 ] 5 [ 291 ] 7 [ 621 ] 10 [ 158 453 453 485 ] 15 [ 197 550 209 475 627 319 574 588 628 627 634 545 630 629 212 ] 32 [ 722 ] 36 [ 673 612 771 706 512 503 777 691 245 ] 46 [ 598 431 860 702 785 578 787 607 586 540 674 675 975 ] 60 [ 583 540 422 ] 64 [ 422 ] 66 [ 732 256 675 675 606 675 619 328 675 639 245 247 514 245 1029 639 639 675 675 372 521 363 639 560 819 478 562 454 ] 95 [ 290 ] 204 [ 218 ] ] +/FontDescriptor 1062 0 R +>> +endobj +1064 0 obj +<< +/Length 1430 +>> +stream +/CIDInit /ProcSet findresource begin +12 dict begin +begincmap +/CIDSystemInfo +<< /Registry (Adobe) +/Ordering (UCS) +/Supplement 0 +>> def +/CMapName /Adobe-Identity-UCS def +/CMapType 2 def +1 begincodespacerange +<0000> +endcodespacerange +79 beginbfchar +<0026> <0043> +<002c> <0049> +<0036> <0053> +<0003> <0020> +<0059> <0076> +<0014> <0031> +<0011> <002e> +<0019> <0036> +<0025> <0042> +<0048> <0065> +<0051> <006e> +<0046> <0063> +<004b> <0068> +<0050> <006d> +<0044> <0061> +<0055> <0072> +<004e> <006b> +<0010> <002d> +<004f> <006c> +<0049> <0066> +<0024> <0041> +<0056> <0073> +<0057> <0074> +<002a> <0047> +<0058> <0075> +<004c> <0069> +<0047> <0064> +<0035> <0052> +<0015> <0032> +<0016> <0033> +<002e> <004b> +<0045> <0062> +<005a> <0077> +<001b> <0038> +<0052> <006f> +<0030> <004d> +<0031> <004e> +<004a> <0067> +<0029> <0046> +<0017> <0034> +<0033> <0050> +<001a> <0037> +<0018> <0035> +<0013> <0030> +<0028> <0045> +<005d> <007a> +<002f> <004c> +<003a> <0057> +<001c> <0039> +<005c> <0079> +<005b> <0078> +<0027> <0044> +<0032> <004f> +<0037> <0054> +<0053> <0070> +<000f> <002c> +<001d> <003a> +<002b> <0048> +<0039> <0056> +<003c> <0059> +<000b> <0028> +<000c> <0029> +<004d> <006a> +<0054> <0071> +<000a> <0027> +<0012> <002f> +<000d> <002a> +<005f> <007c> +<0020> <003d> +<0042> <005f> +<0043> <0060> +<0005> <0022> +<003e> <005b> +<0040> <005d> +<00cc> <2019> +<0007> <0024> +<0038> <0055> +<003d> <005a> +<0034> <0051> +endbfchar +endcmap +CMapName currentdict /CMap defineresource pop +end +end +endstream +endobj +1065 0 obj +<< +/Type /Font +/Subtype /Type0 +/BaseFont /CHSCVX+Poppins +/Encoding /Identity-H +/DescendantFonts [ 1063 0 R ] +/ToUnicode 1064 0 R +>> +endobj +1066 0 obj +<< +/Type /FontDescriptor +/FontName /QVTIIS+DejaVuSans +/FontFamily (DejaVu Sans) +/Flags 4 +/FontBBox [ -9 -92 733 729 ] +/ItalicAngle 0 +/Ascent 928 +/Descent -235 +/CapHeight 729 +/StemV 80 +/StemH 80 +/FontFile2 1056 0 R +>> +endobj +1067 0 obj +<< +/Type /Font +/Subtype /CIDFontType2 +/BaseFont /QVTIIS+DejaVuSans +/CIDSystemInfo << +/Registry (Adobe) +/Ordering (Identity) +/Supplement 0 +>> +/W [ 3 [ 348 ] 11 [ 457 457 ] 16 [ 415 379 365 695 695 695 695 695 695 695 695 695 695 399 ] 36 [ 773 762 733 830 683 ] 44 [ 372 ] 46 [ 774 637 995 836 ] 51 [ 732 ] 53 [ 770 720 682 ] 57 [ 773 1103 ] 60 [ 724 ] 66 [ 500 ] 68 [ 674 715 592 715 678 435 715 711 342 ] 78 [ 665 342 1041 711 687 715 715 493 595 478 711 651 923 645 651 582 ] 5038 [ 741 ] ] +/FontDescriptor 1066 0 R +>> +endobj +1068 0 obj +<< +/Length 1182 +>> +stream +/CIDInit /ProcSet findresource begin +12 dict begin +begincmap +/CIDSystemInfo +<< /Registry (Adobe) +/Ordering (UCS) +/Supplement 0 +>> def +/CMapName /Adobe-Identity-UCS def +/CMapType 2 def +1 begincodespacerange +<0000> +endcodespacerange +61 beginbfchar +<0014> <0031> +<0016> <0033> +<0017> <0034> +<0018> <0035> +<0011> <002e> +<0003> <0020> +<0028> <0045> +<0051> <006e> +<0056> <0073> +<0058> <0075> +<0055> <0072> +<0048> <0065> +<0057> <0074> +<004b> <0068> +<0044> <0061> +<0024> <0041> +<0033> <0050> +<002c> <0049> +<0059> <0076> +<0053> <0070> +<0052> <006f> +<0047> <0064> +<0046> <0063> +<004c> <0069> +<13ae> <00660069> +<004f> <006c> +<0050> <006d> +<0019> <0036> +<000b> <0028> +<000c> <0029> +<0015> <0032> +<005a> <0077> +<001d> <003a> +<004a> <0067> +<001a> <0037> +<001b> <0038> +<001c> <0039> +<0026> <0043> +<0031> <004e> +<004e> <006b> +<0049> <0066> +<0030> <004d> +<0013> <0030> +<0010> <002d> +<002e> <004b> +<0045> <0062> +<005c> <0079> +<005d> <007a> +<0035> <0052> +<0025> <0042> +<002f> <004c> +<0036> <0053> +<005b> <0078> +<0027> <0044> +<0054> <0071> +<0039> <0056> +<0037> <0054> +<0042> <005f> +<003a> <0057> +<0012> <002f> +<003c> <0059> +endbfchar +endcmap +CMapName currentdict /CMap defineresource pop +end +end +endstream +endobj +1069 0 obj +<< +/Type /Font +/Subtype /Type0 +/BaseFont /QVTIIS+DejaVuSans +/Encoding /Identity-H +/DescendantFonts [ 1067 0 R ] +/ToUnicode 1068 0 R +>> +endobj +1070 0 obj +<< +/Type /FontDescriptor +/FontName /YKWSLN+DejaVuSansMono +/FontFamily (DejaVu Sans Mono) +/Flags 4 +/FontBBox [ 0 -155 598 728 ] +/ItalicAngle 0 +/Ascent 928 +/Descent -235 +/CapHeight 728 +/StemV 80 +/StemH 80 +/FontFile2 1057 0 R +>> +endobj +1071 0 obj +<< +/Type /Font +/Subtype /CIDFontType2 +/BaseFont /YKWSLN+DejaVuSansMono +/CIDSystemInfo << +/Registry (Adobe) +/Ordering (Identity) +/Supplement 0 +>> +/W [ 3 [ 602 602 602 602 602 602 602 602 602 602 602 ] 15 [ 602 602 601 602 602 602 602 602 602 602 602 602 602 602 602 602 602 602 602 602 602 601 602 602 602 602 602 602 602 602 ] 46 [ 602 602 602 601 602 602 602 602 602 602 602 602 602 602 602 ] 62 [ 602 602 602 ] 66 [ 601 ] 68 [ 601 601 601 601 601 602 602 602 601 602 601 601 601 602 601 601 602 601 601 601 601 602 601 602 602 602 602 602 602 ] ] +/FontDescriptor 1070 0 R +>> +endobj +1072 0 obj +<< +/Length 1570 +>> +stream +/CIDInit /ProcSet findresource begin +12 dict begin +begincmap +/CIDSystemInfo +<< /Registry (Adobe) +/Ordering (UCS) +/Supplement 0 +>> def +/CMapName /Adobe-Identity-UCS def +/CMapType 2 def +1 begincodespacerange +<0000> +endcodespacerange +89 beginbfchar +<0031> <004e> +<0052> <006f> +<0057> <0074> +<0024> <0041> +<0053> <0070> +<004f> <006c> +<004c> <0069> +<0046> <0063> +<0044> <0061> +<0045> <0062> +<0048> <0065> +<0058> <0075> +<0050> <006d> +<0047> <0064> +<0056> <0073> +<0055> <0072> +<0003> <0020> +<0010> <002d> +<0051> <006e> +<0020> <003d> +<0008> <0025> +<001f> <003c> +<004b> <0068> +<0012> <002f> +<0049> <0066> +<0021> <003e> +<0038> <0055> +<001d> <003a> +<002a> <0047> +<004e> <006b> +<0042> <005f> +<005a> <0077> +<0011> <002e> +<0006> <0023> +<0004> <0021> +<0059> <0076> +<0037> <0054> +<004a> <0067> +<005c> <0079> +<0007> <0024> +<0014> <0031> +<002c> <0049> +<0033> <0050> +<0027> <0044> +<0035> <0052> +<003e> <005b> +<0005> <0022> +<005e> <007b> +<0060> <007d> +<0040> <005d> +<001e> <003b> +<005b> <0078> +<000b> <0028> +<000c> <0029> +<002f> <004c> +<000d> <002a> +<005f> <007c> +<000a> <0027> +<0015> <0032> +<0009> <0026> +<0054> <0071> +<0019> <0036> +<0017> <0034> +<0013> <0030> +<002b> <0048> +<0036> <0053> +<0028> <0045> +<0030> <004d> +<0032> <004f> +<0029> <0046> +<003f> <005c> +<001a> <0037> +<0018> <0035> +<001b> <0038> +<0016> <0033> +<0022> <003f> +<0026> <0043> +<003a> <0057> +<000f> <002c> +<003c> <0059> +<001c> <0039> +<003b> <0058> +<0039> <0056> +<0034> <0051> +<0025> <0042> +<005d> <007a> +<004d> <006a> +<0023> <0040> +<002e> <004b> +endbfchar +endcmap +CMapName currentdict /CMap defineresource pop +end +end +endstream +endobj +1073 0 obj +<< +/Type /Font +/Subtype /Type0 +/BaseFont /YKWSLN+DejaVuSansMono +/Encoding /Identity-H +/DescendantFonts [ 1071 0 R ] +/ToUnicode 1072 0 R +>> +endobj +1074 0 obj +<< +/EREYAA 1061 0 R +/CHSCVX 1065 0 R +/QVTIIS 1069 0 R +/YKWSLN 1073 0 R +>> +endobj +xref +0 1075 +0000000000 65535 f +0000000015 00000 n +0000001104 00000 n +0000001238 00000 n +0000040577 00000 n +0000040711 00000 n +0000043403 00000 n +0000043602 00000 n +0000047323 00000 n +0000047729 00000 n +0000047930 00000 n +0000048133 00000 n +0000048268 00000 n +0000048404 00000 n +0000048562 00000 n +0000048721 00000 n +0000048954 00000 n +0000049188 00000 n +0000049403 00000 n +0000049619 00000 n +0000049860 00000 n +0000050102 00000 n +0000050325 00000 n +0000050549 00000 n +0000050781 00000 n +0000051014 00000 n +0000051228 00000 n +0000051443 00000 n +0000051670 00000 n +0000051898 00000 n +0000052107 00000 n +0000052317 00000 n +0000052546 00000 n +0000052776 00000 n +0000052987 00000 n +0000053199 00000 n +0000053414 00000 n +0000053629 00000 n +0000057395 00000 n +0000057860 00000 n +0000058057 00000 n +0000058255 00000 n +0000058474 00000 n +0000058694 00000 n +0000058895 00000 n +0000059097 00000 n +0000059325 00000 n +0000059554 00000 n +0000059764 00000 n +0000059975 00000 n +0000060190 00000 n +0000060406 00000 n +0000060637 00000 n +0000060869 00000 n +0000061072 00000 n +0000061276 00000 n +0000061495 00000 n +0000061715 00000 n +0000061916 00000 n +0000062118 00000 n +0000062255 00000 n +0000062393 00000 n +0000062587 00000 n +0000062782 00000 n +0000062972 00000 n +0000063163 00000 n +0000063354 00000 n +0000063546 00000 n +0000063738 00000 n +0000063931 00000 n +0000064170 00000 n +0000064410 00000 n +0000064625 00000 n +0000064841 00000 n +0000065048 00000 n +0000065255 00000 n +0000068823 00000 n +0000069301 00000 n +0000069497 00000 n +0000069694 00000 n +0000069890 00000 n +0000070087 00000 n +0000070286 00000 n +0000070486 00000 n +0000070686 00000 n +0000070887 00000 n +0000071085 00000 n +0000071284 00000 n +0000071518 00000 n +0000071753 00000 n +0000071952 00000 n +0000072152 00000 n +0000072355 00000 n +0000072559 00000 n +0000072761 00000 n +0000072964 00000 n +0000073164 00000 n +0000073365 00000 n +0000073561 00000 n +0000073758 00000 n +0000073947 00000 n +0000074138 00000 n +0000074330 00000 n +0000074523 00000 n +0000074713 00000 n +0000074904 00000 n +0000075090 00000 n +0000075277 00000 n +0000075489 00000 n +0000075702 00000 n +0000075917 00000 n +0000076133 00000 n +0000076346 00000 n +0000076559 00000 n +0000080257 00000 n +0000080760 00000 n +0000080962 00000 n +0000081165 00000 n +0000081367 00000 n +0000081570 00000 n +0000081781 00000 n +0000081993 00000 n +0000082214 00000 n +0000082436 00000 n +0000082665 00000 n +0000082895 00000 n +0000083096 00000 n +0000083298 00000 n +0000083496 00000 n +0000083695 00000 n +0000083908 00000 n +0000084122 00000 n +0000084321 00000 n +0000084521 00000 n +0000084732 00000 n +0000084944 00000 n +0000085090 00000 n +0000085237 00000 n +0000085451 00000 n +0000085666 00000 n +0000085858 00000 n +0000086051 00000 n +0000086262 00000 n +0000086474 00000 n +0000086693 00000 n +0000086913 00000 n +0000087112 00000 n +0000087312 00000 n +0000087520 00000 n +0000087729 00000 n +0000087925 00000 n +0000088121 00000 n +0000091980 00000 n +0000092451 00000 n +0000092588 00000 n +0000092726 00000 n +0000092918 00000 n +0000093111 00000 n +0000093310 00000 n +0000093510 00000 n +0000093667 00000 n +0000093825 00000 n +0000094038 00000 n +0000094252 00000 n +0000094448 00000 n +0000094645 00000 n +0000094837 00000 n +0000095030 00000 n +0000095253 00000 n +0000095477 00000 n +0000095678 00000 n +0000095880 00000 n +0000096077 00000 n +0000096275 00000 n +0000096472 00000 n +0000096670 00000 n +0000096830 00000 n +0000096991 00000 n +0000097188 00000 n +0000097386 00000 n +0000097521 00000 n +0000097657 00000 n +0000097840 00000 n +0000098024 00000 n +0000098216 00000 n +0000098409 00000 n +0000102247 00000 n +0000102734 00000 n +0000102893 00000 n +0000103053 00000 n +0000103274 00000 n +0000103496 00000 n +0000103699 00000 n +0000103903 00000 n +0000104126 00000 n +0000104350 00000 n +0000104554 00000 n +0000104759 00000 n +0000104990 00000 n +0000105222 00000 n +0000105435 00000 n +0000105649 00000 n +0000105878 00000 n +0000106108 00000 n +0000106326 00000 n +0000106545 00000 n +0000106781 00000 n +0000107018 00000 n +0000107236 00000 n +0000107455 00000 n +0000107590 00000 n +0000107726 00000 n +0000107919 00000 n +0000108113 00000 n +0000108324 00000 n +0000108536 00000 n +0000108739 00000 n +0000108943 00000 n +0000109134 00000 n +0000109326 00000 n +0000109540 00000 n +0000109754 00000 n +0000113833 00000 n +0000114320 00000 n +0000114523 00000 n +0000114727 00000 n +0000114932 00000 n +0000115138 00000 n +0000115328 00000 n +0000115519 00000 n +0000115756 00000 n +0000115994 00000 n +0000116225 00000 n +0000116457 00000 n +0000116661 00000 n +0000116866 00000 n +0000117074 00000 n +0000117283 00000 n +0000117491 00000 n +0000117700 00000 n +0000117853 00000 n +0000118007 00000 n +0000118204 00000 n +0000118402 00000 n +0000118563 00000 n +0000118725 00000 n +0000118907 00000 n +0000119090 00000 n +0000119255 00000 n +0000119421 00000 n +0000119618 00000 n +0000119816 00000 n +0000120018 00000 n +0000120221 00000 n +0000120370 00000 n +0000120520 00000 n +0000120702 00000 n +0000120885 00000 n +0000124723 00000 n +0000125194 00000 n +0000125415 00000 n +0000125637 00000 n +0000125851 00000 n +0000126066 00000 n +0000126284 00000 n +0000126503 00000 n +0000126707 00000 n +0000126912 00000 n +0000127088 00000 n +0000127265 00000 n +0000127464 00000 n +0000127664 00000 n +0000127859 00000 n +0000128055 00000 n +0000128253 00000 n +0000128452 00000 n +0000128604 00000 n +0000128757 00000 n +0000128944 00000 n +0000129132 00000 n +0000129326 00000 n +0000129521 00000 n +0000129667 00000 n +0000129814 00000 n +0000130016 00000 n +0000130219 00000 n +0000130386 00000 n +0000130554 00000 n +0000130710 00000 n +0000130867 00000 n +0000131074 00000 n +0000131282 00000 n +0000133585 00000 n +0000133880 00000 n +0000134024 00000 n +0000134169 00000 n +0000134371 00000 n +0000134574 00000 n +0000134788 00000 n +0000135003 00000 n +0000135188 00000 n +0000135374 00000 n +0000135552 00000 n +0000135731 00000 n +0000140534 00000 n +0000140773 00000 n +0000141029 00000 n +0000141236 00000 n +0000141442 00000 n +0000145032 00000 n +0000145263 00000 n +0000145460 00000 n +0000145649 00000 n +0000149334 00000 n +0000149537 00000 n +0000153277 00000 n +0000153500 00000 n +0000153634 00000 n +0000157398 00000 n +0000157621 00000 n +0000157755 00000 n +0000162461 00000 n +0000162852 00000 n +0000162986 00000 n +0000163118 00000 n +0000163250 00000 n +0000163382 00000 n +0000163514 00000 n +0000163646 00000 n +0000163778 00000 n +0000163910 00000 n +0000164042 00000 n +0000164175 00000 n +0000164308 00000 n +0000164441 00000 n +0000164574 00000 n +0000164707 00000 n +0000164840 00000 n +0000164973 00000 n +0000165106 00000 n +0000165239 00000 n +0000165372 00000 n +0000165505 00000 n +0000165637 00000 n +0000165768 00000 n +0000170770 00000 n +0000171169 00000 n +0000171302 00000 n +0000171435 00000 n +0000171568 00000 n +0000171701 00000 n +0000171834 00000 n +0000171967 00000 n +0000172100 00000 n +0000172233 00000 n +0000172366 00000 n +0000172499 00000 n +0000172632 00000 n +0000172765 00000 n +0000172898 00000 n +0000173031 00000 n +0000173164 00000 n +0000173297 00000 n +0000173430 00000 n +0000173563 00000 n +0000173696 00000 n +0000173829 00000 n +0000173962 00000 n +0000174095 00000 n +0000174229 00000 n +0000179035 00000 n +0000179498 00000 n +0000179632 00000 n +0000179764 00000 n +0000179896 00000 n +0000180028 00000 n +0000180160 00000 n +0000180292 00000 n +0000180424 00000 n +0000180556 00000 n +0000180688 00000 n +0000180821 00000 n +0000180954 00000 n +0000181087 00000 n +0000181220 00000 n +0000181353 00000 n +0000181486 00000 n +0000181619 00000 n +0000181752 00000 n +0000181885 00000 n +0000182018 00000 n +0000182151 00000 n +0000182284 00000 n +0000182417 00000 n +0000182550 00000 n +0000182683 00000 n +0000182816 00000 n +0000182949 00000 n +0000183082 00000 n +0000183215 00000 n +0000183348 00000 n +0000183481 00000 n +0000183613 00000 n +0000188611 00000 n +0000189074 00000 n +0000189207 00000 n +0000189340 00000 n +0000189473 00000 n +0000189606 00000 n +0000189739 00000 n +0000189872 00000 n +0000190005 00000 n +0000190138 00000 n +0000190271 00000 n +0000190404 00000 n +0000190537 00000 n +0000190670 00000 n +0000190803 00000 n +0000190936 00000 n +0000191069 00000 n +0000191202 00000 n +0000191335 00000 n +0000191468 00000 n +0000191601 00000 n +0000191734 00000 n +0000191867 00000 n +0000192000 00000 n +0000192133 00000 n +0000192266 00000 n +0000192399 00000 n +0000192532 00000 n +0000192665 00000 n +0000192798 00000 n +0000192931 00000 n +0000193064 00000 n +0000193198 00000 n +0000197785 00000 n +0000198176 00000 n +0000198311 00000 n +0000198444 00000 n +0000198577 00000 n +0000198710 00000 n +0000198843 00000 n +0000198976 00000 n +0000199109 00000 n +0000199242 00000 n +0000199375 00000 n +0000199509 00000 n +0000199643 00000 n +0000199777 00000 n +0000199911 00000 n +0000200045 00000 n +0000200179 00000 n +0000200313 00000 n +0000200447 00000 n +0000200581 00000 n +0000200715 00000 n +0000200849 00000 n +0000200983 00000 n +0000201116 00000 n +0000206097 00000 n +0000206608 00000 n +0000206742 00000 n +0000206876 00000 n +0000207010 00000 n +0000207144 00000 n +0000207278 00000 n +0000207412 00000 n +0000207546 00000 n +0000207680 00000 n +0000207814 00000 n +0000207948 00000 n +0000208082 00000 n +0000208216 00000 n +0000208350 00000 n +0000208484 00000 n +0000208618 00000 n +0000208752 00000 n +0000208886 00000 n +0000209020 00000 n +0000209154 00000 n +0000209288 00000 n +0000209422 00000 n +0000209556 00000 n +0000209690 00000 n +0000209824 00000 n +0000209958 00000 n +0000210092 00000 n +0000210226 00000 n +0000210360 00000 n +0000210494 00000 n +0000210628 00000 n +0000210762 00000 n +0000210896 00000 n +0000211030 00000 n +0000211164 00000 n +0000211298 00000 n +0000211431 00000 n +0000211563 00000 n +0000215574 00000 n +0000215821 00000 n +0000215955 00000 n +0000216089 00000 n +0000216224 00000 n +0000216359 00000 n +0000219555 00000 n +0000219778 00000 n +0000219913 00000 n +0000224854 00000 n +0000225077 00000 n +0000225212 00000 n +0000230250 00000 n +0000230473 00000 n +0000230607 00000 n +0000235414 00000 n +0000235617 00000 n +0000240561 00000 n +0000240784 00000 n +0000240919 00000 n +0000245691 00000 n +0000245894 00000 n +0000250695 00000 n +0000250918 00000 n +0000251053 00000 n +0000256050 00000 n +0000256273 00000 n +0000256408 00000 n +0000261217 00000 n +0000261420 00000 n +0000266288 00000 n +0000266511 00000 n +0000266646 00000 n +0000271495 00000 n +0000271698 00000 n +0000276574 00000 n +0000276797 00000 n +0000276932 00000 n +0000281905 00000 n +0000282128 00000 n +0000282263 00000 n +0000287124 00000 n +0000287327 00000 n +0000292165 00000 n +0000292388 00000 n +0000292523 00000 n +0000297432 00000 n +0000297635 00000 n +0000302594 00000 n +0000302817 00000 n +0000302952 00000 n +0000307972 00000 n +0000308195 00000 n +0000308330 00000 n +0000313147 00000 n +0000313350 00000 n +0000317920 00000 n +0000318151 00000 n +0000318286 00000 n +0000318420 00000 n +0000323269 00000 n +0000323492 00000 n +0000323627 00000 n +0000328610 00000 n +0000328833 00000 n +0000328968 00000 n +0000333776 00000 n +0000333979 00000 n +0000339042 00000 n +0000339265 00000 n +0000339400 00000 n +0000344189 00000 n +0000344392 00000 n +0000349443 00000 n +0000349666 00000 n +0000349801 00000 n +0000354679 00000 n +0000354882 00000 n +0000359675 00000 n +0000359898 00000 n +0000360033 00000 n +0000365029 00000 n +0000365252 00000 n +0000365387 00000 n +0000370176 00000 n +0000370379 00000 n +0000375288 00000 n +0000375511 00000 n +0000375646 00000 n +0000380645 00000 n +0000380868 00000 n +0000381002 00000 n +0000385802 00000 n +0000386005 00000 n +0000390833 00000 n +0000391056 00000 n +0000391191 00000 n +0000395993 00000 n +0000396196 00000 n +0000401012 00000 n +0000401235 00000 n +0000401370 00000 n +0000406361 00000 n +0000406584 00000 n +0000406719 00000 n +0000411580 00000 n +0000411783 00000 n +0000416636 00000 n +0000416859 00000 n +0000416994 00000 n +0000421744 00000 n +0000421947 00000 n +0000426762 00000 n +0000426985 00000 n +0000427120 00000 n +0000432113 00000 n +0000432336 00000 n +0000432471 00000 n +0000437332 00000 n +0000437535 00000 n +0000442361 00000 n +0000442584 00000 n +0000442719 00000 n +0000447642 00000 n +0000447845 00000 n +0000452621 00000 n +0000452844 00000 n +0000452980 00000 n +0000457917 00000 n +0000458140 00000 n +0000458276 00000 n +0000463138 00000 n +0000463341 00000 n +0000468192 00000 n +0000468415 00000 n +0000468551 00000 n +0000473458 00000 n +0000473661 00000 n +0000478396 00000 n +0000478619 00000 n +0000478755 00000 n +0000483760 00000 n +0000483983 00000 n +0000484119 00000 n +0000488919 00000 n +0000489122 00000 n +0000494208 00000 n +0000494583 00000 n +0000494719 00000 n +0000494853 00000 n +0000494987 00000 n +0000495121 00000 n +0000495255 00000 n +0000495389 00000 n +0000495523 00000 n +0000495657 00000 n +0000495791 00000 n +0000495926 00000 n +0000496061 00000 n +0000496196 00000 n +0000496331 00000 n +0000496466 00000 n +0000496601 00000 n +0000496736 00000 n +0000496871 00000 n +0000497006 00000 n +0000497140 00000 n +0000497273 00000 n +0000501325 00000 n +0000501596 00000 n +0000501731 00000 n +0000501866 00000 n +0000502001 00000 n +0000502136 00000 n +0000502271 00000 n +0000502407 00000 n +0000502543 00000 n +0000507370 00000 n +0000507593 00000 n +0000507729 00000 n +0000512395 00000 n +0000512626 00000 n +0000512762 00000 n +0000512898 00000 n +0000517565 00000 n +0000517788 00000 n +0000517924 00000 n +0000522505 00000 n +0000522728 00000 n +0000522864 00000 n +0000527453 00000 n +0000527676 00000 n +0000527812 00000 n +0000530675 00000 n +0000530878 00000 n +0000535321 00000 n +0000535552 00000 n +0000535688 00000 n +0000535824 00000 n +0000538794 00000 n +0000538997 00000 n +0000543889 00000 n +0000544112 00000 n +0000544248 00000 n +0000549078 00000 n +0000549281 00000 n +0000554242 00000 n +0000554465 00000 n +0000554601 00000 n +0000559413 00000 n +0000559616 00000 n +0000564613 00000 n +0000564836 00000 n +0000564972 00000 n +0000569551 00000 n +0000569754 00000 n +0000574867 00000 n +0000575090 00000 n +0000575226 00000 n +0000579872 00000 n +0000580075 00000 n +0000584947 00000 n +0000585150 00000 n +0000589983 00000 n +0000590206 00000 n +0000590342 00000 n +0000595229 00000 n +0000595432 00000 n +0000600328 00000 n +0000600551 00000 n +0000600687 00000 n +0000605479 00000 n +0000605682 00000 n +0000610693 00000 n +0000610916 00000 n +0000611052 00000 n +0000615876 00000 n +0000616079 00000 n +0000619954 00000 n +0000620157 00000 n +0000623430 00000 n +0000623633 00000 n +0000628494 00000 n +0000628717 00000 n +0000628853 00000 n +0000633458 00000 n +0000633661 00000 n +0000637949 00000 n +0000638172 00000 n +0000638308 00000 n +0000642374 00000 n +0000642605 00000 n +0000642741 00000 n +0000642877 00000 n +0000647826 00000 n +0000648097 00000 n +0000648233 00000 n +0000648369 00000 n +0000648503 00000 n +0000648637 00000 n +0000648771 00000 n +0000648905 00000 n +0000649041 00000 n +0000653813 00000 n +0000654076 00000 n +0000654212 00000 n +0000654346 00000 n +0000654480 00000 n +0000654614 00000 n +0000654748 00000 n +0000654884 00000 n +0000657646 00000 n +0000657849 00000 n +0000662157 00000 n +0000662396 00000 n +0000662532 00000 n +0000662668 00000 n +0000662803 00000 n +0000666821 00000 n +0000667060 00000 n +0000667196 00000 n +0000667332 00000 n +0000667468 00000 n +0000672062 00000 n +0000672309 00000 n +0000672445 00000 n +0000672581 00000 n +0000672717 00000 n +0000672853 00000 n +0000677685 00000 n +0000677916 00000 n +0000678052 00000 n +0000678188 00000 n +0000682333 00000 n +0000682564 00000 n +0000682700 00000 n +0000682836 00000 n +0000687005 00000 n +0000687252 00000 n +0000687388 00000 n +0000687524 00000 n +0000687660 00000 n +0000687796 00000 n +0000692702 00000 n +0000692933 00000 n +0000693069 00000 n +0000693205 00000 n +0000697819 00000 n +0000698050 00000 n +0000698186 00000 n +0000698322 00000 n +0000701260 00000 n +0000701483 00000 n +0000701619 00000 n +0000705691 00000 n +0000705894 00000 n +0000711399 00000 n +0000711798 00000 n +0000711934 00000 n +0000712068 00000 n +0000712202 00000 n +0000712336 00000 n +0000712470 00000 n +0000712604 00000 n +0000712738 00000 n +0000712872 00000 n +0000713006 00000 n +0000713141 00000 n +0000713276 00000 n +0000713411 00000 n +0000713546 00000 n +0000713681 00000 n +0000713816 00000 n +0000713951 00000 n +0000714086 00000 n +0000714221 00000 n +0000714356 00000 n +0000714491 00000 n +0000714626 00000 n +0000714761 00000 n +0000714895 00000 n +0000718593 00000 n +0000718880 00000 n +0000719015 00000 n +0000719150 00000 n +0000719285 00000 n +0000719420 00000 n +0000719555 00000 n +0000719690 00000 n +0000719825 00000 n +0000719960 00000 n +0000720096 00000 n +0000724516 00000 n +0000724739 00000 n +0000724875 00000 n +0000729330 00000 n +0000729561 00000 n +0000729697 00000 n +0000729833 00000 n +0000734293 00000 n +0000734516 00000 n +0000734652 00000 n +0000739614 00000 n +0000739949 00000 n +0000740085 00000 n +0000740219 00000 n +0000740353 00000 n +0000740487 00000 n +0000740621 00000 n +0000740755 00000 n +0000740889 00000 n +0000741023 00000 n +0000741157 00000 n +0000741292 00000 n +0000741427 00000 n +0000741562 00000 n +0000741697 00000 n +0000741831 00000 n +0000741964 00000 n +0000745205 00000 n +0000745460 00000 n +0000745595 00000 n +0000745730 00000 n +0000745865 00000 n +0000746000 00000 n +0000746136 00000 n +0000749547 00000 n +0000749750 00000 n +0000753007 00000 n +0000753210 00000 n +0000757610 00000 n +0000757813 00000 n +0000762205 00000 n +0000762572 00000 n +0000762708 00000 n +0000762842 00000 n +0000762976 00000 n +0000763110 00000 n +0000763244 00000 n +0000763378 00000 n +0000763512 00000 n +0000763646 00000 n +0000763780 00000 n +0000763915 00000 n +0000764050 00000 n +0000764185 00000 n +0000764320 00000 n +0000764455 00000 n +0000764590 00000 n +0000764725 00000 n +0000764860 00000 n +0000764995 00000 n +0000765131 00000 n +0000765323 00000 n +0000765545 00000 n +0000765671 00000 n +0000765817 00000 n +0000765957 00000 n +0000766154 00000 n +0000766388 00000 n +0000766619 00000 n +0000766875 00000 n +0000767114 00000 n +0000767361 00000 n +0000767591 00000 n +0000767833 00000 n +0000768058 00000 n +0000768302 00000 n +0000768530 00000 n +0000768761 00000 n +0000768975 00000 n +0000769210 00000 n +0000769428 00000 n +0000769672 00000 n +0000769899 00000 n +0000770131 00000 n +0000770378 00000 n +0000770597 00000 n +0000770832 00000 n +0000771036 00000 n +0000771212 00000 n +0000771407 00000 n +0000771612 00000 n +0000771818 00000 n +0000772025 00000 n +0000772279 00000 n +0000772509 00000 n +0000772732 00000 n +0000772943 00000 n +0000773154 00000 n +0000773369 00000 n +0000773585 00000 n +0000773799 00000 n +0000774049 00000 n +0000774264 00000 n +0000774483 00000 n +0000774701 00000 n +0000774917 00000 n +0000775129 00000 n +0000775334 00000 n +0000775541 00000 n +0000775746 00000 n +0000775947 00000 n +0000776174 00000 n +0000776404 00000 n +0000776633 00000 n +0000776850 00000 n +0000777067 00000 n +0000777293 00000 n +0000777529 00000 n +0000777773 00000 n +0000777989 00000 n +0000778202 00000 n +0000778430 00000 n +0000778644 00000 n +0000778856 00000 n +0000779039 00000 n +0000779253 00000 n +0000779457 00000 n +0000779682 00000 n +0000779915 00000 n +0000780128 00000 n +0000780350 00000 n +0000780547 00000 n +0000780721 00000 n +0000780911 00000 n +0000781108 00000 n +0000781300 00000 n +0000781511 00000 n +0000781719 00000 n +0000781923 00000 n +0000782158 00000 n +0000782371 00000 n +0000782580 00000 n +0000782775 00000 n +0000782972 00000 n +0000783155 00000 n +0000783327 00000 n +0000783510 00000 n +0000783702 00000 n +0000783901 00000 n +0000784123 00000 n +0000784343 00000 n +0000784583 00000 n +0000784805 00000 n +0000785053 00000 n +0000785284 00000 n +0000785530 00000 n +0000785766 00000 n +0000786019 00000 n +0000786241 00000 n +0000786418 00000 n +0000786614 00000 n +0000786841 00000 n +0000787060 00000 n +0000787269 00000 n +0000787501 00000 n +0000787722 00000 n +0000787945 00000 n +0000788153 00000 n +0000788408 00000 n +0000788656 00000 n +0000788879 00000 n +0000789106 00000 n +0000789318 00000 n +0000789513 00000 n +0000789713 00000 n +0000789892 00000 n +0000790092 00000 n +0000790275 00000 n +0000790490 00000 n +0000790695 00000 n +0000790886 00000 n +0000791071 00000 n +0000791310 00000 n +0000791542 00000 n +0000791778 00000 n +0000792000 00000 n +0000792194 00000 n +0000792411 00000 n +0000792624 00000 n +0000792825 00000 n +0000793019 00000 n +0000793209 00000 n +0000793406 00000 n +0000793594 00000 n +0000793799 00000 n +0000793969 00000 n +0000794167 00000 n +0000794362 00000 n +0000794533 00000 n +0000794738 00000 n +0000794971 00000 n +0000795174 00000 n +0000795355 00000 n +0000795419 00000 n +0000803098 00000 n +0000807902 00000 n +0000819763 00000 n +0000832159 00000 n +0000832393 00000 n +0000832797 00000 n +0000833595 00000 n +0000833748 00000 n +0000833979 00000 n +0000834576 00000 n +0000836061 00000 n +0000836211 00000 n +0000836446 00000 n +0000836985 00000 n +0000838222 00000 n +0000838375 00000 n +0000838619 00000 n +0000839214 00000 n +0000840839 00000 n +0000840996 00000 n +trailer +<< +/Size 1075 +/Root 3 0 R +/Info 2 0 R +>> +startxref +841088 +%%EOF diff --git a/content/rancher/v2.6/en/security/hardening-guides/1.6-benchmark-2.6/_index.md b/content/rancher/v2.6/en/security/hardening-guides/1.6-benchmark-2.6/_index.md new file mode 100644 index 00000000000..913d6594f3c --- /dev/null +++ b/content/rancher/v2.6/en/security/hardening-guides/1.6-benchmark-2.6/_index.md @@ -0,0 +1,3098 @@ +--- +title: CIS v1.6 Benchmark - Self-Assessment Guide - Rancher v2.6 +weight: 101 +--- + +### CIS v1.6 Kubernetes Benchmark - Rancher v2.6 with Kubernetes v1.18 to v1.21 + +[Click here to download a PDF version of this document](https://releases.rancher.com/documents/security/2.6/Rancher_v2-6_CIS_v1-6_Benchmark_Assessment.pdf). + +#### Overview + +This document is a companion to the Rancher v2.6 security hardening guide. The hardening guide provides prescriptive guidance for hardening a production installation of Rancher, and this benchmark guide is meant to help you evaluate the level of security of the hardened cluster against each control in the benchmark. + +This guide corresponds to specific versions of the hardening guide, Rancher, CIS Benchmark and Kubernetes: + +| Hardening Guide Version | Rancher Version | CIS Benchmark Version | Kubernetes Version | +| ----------------------- | --------------- | --------------------- | ------------------- | +| Hardening Guide CIS v1.6 Benchmark | Rancher v2.6.3 | CIS v1.6 | Kubernetes v1.18, v1.19, v1.20 and v1.21 | + +Because Rancher and RKE install Kubernetes services as Docker containers, many of the control verification checks in the CIS Kubernetes Benchmark do not apply and will have a result of `Not Applicable`. This guide will walk through the various controls and provide updated example commands to audit compliance in Rancher created clusters. + +This document is to be used by Rancher operators, security teams, auditors and decision makers. + +For more detail about each audit, including rationales and remediations for failing tests, you can refer to the corresponding section of the CIS Kubernetes Benchmark v1.6. You can download the benchmark, after creating a free account, in [Center for Internet Security (CIS)](https://www.cisecurity.org/benchmark/kubernetes/). + +#### Testing controls methodology + +Rancher and RKE install Kubernetes services via Docker containers. Configuration is defined by arguments passed to the container at the time of initialization, not via configuration files. + +Where control audits differ from the original CIS benchmark, the audit commands specific to Rancher are provided for testing. When performing the tests, you will need access to the Docker command line on the hosts of all three RKE roles. The commands also make use of the [kubectl](https://kubernetes.io/docs/tasks/tools/) (with a valid configuration file) and [jq](https://stedolan.github.io/jq/) tools, which are required in the testing and evaluation of test results. + +> NOTE: For the moment only `automated` tests (previously called `scored`) are covered in this guide. + +### Controls +## 1.1 Master Node Configuration Files +### 1.1.1 Ensure that the API server pod specification file permissions are set to 644 or more restrictive (Automated) + + +**Result:** Not Applicable + +**Remediation:** +Cluster provisioned by RKE doesn't require or maintain a configuration file for kube-apiserver. +All configuration is passed in as arguments at container run time. + +### 1.1.2 Ensure that the API server pod specification file ownership is set to root:root (Automated) + + +**Result:** Not Applicable + +**Remediation:** +Cluster provisioned by RKE doesn't require or maintain a configuration file for kube-apiserver. +All configuration is passed in as arguments at container run time. + +### 1.1.3 Ensure that the controller manager pod specification file permissions are set to 644 or more restrictive (Automated) + + +**Result:** Not Applicable + +**Remediation:** +Cluster provisioned by RKE doesn't require or maintain a configuration file for controller-manager. +All configuration is passed in as arguments at container run time. + +### 1.1.4 Ensure that the controller manager pod specification file ownership is set to root:root (Automated) + + +**Result:** Not Applicable + +**Remediation:** +Cluster provisioned by RKE doesn't require or maintain a configuration file for controller-manager. +All configuration is passed in as arguments at container run time. + +### 1.1.5 Ensure that the scheduler pod specification file permissions are set to 644 or more restrictive (Automated) + + +**Result:** Not Applicable + +**Remediation:** +Cluster provisioned by RKE doesn't require or maintain a configuration file for scheduler. +All configuration is passed in as arguments at container run time. + +### 1.1.6 Ensure that the scheduler pod specification file ownership is set to root:root (Automated) + + +**Result:** Not Applicable + +**Remediation:** +Cluster provisioned by RKE doesn't require or maintain a configuration file for scheduler. +All configuration is passed in as arguments at container run time. + +### 1.1.7 Ensure that the etcd pod specification file permissions are set to 644 or more restrictive (Automated) + + +**Result:** Not Applicable + +**Remediation:** +Cluster provisioned by RKE doesn't require or maintain a configuration file for etcd. +All configuration is passed in as arguments at container run time. + +### 1.1.8 Ensure that the etcd pod specification file ownership is set to root:root (Automated) + + +**Result:** Not Applicable + +**Remediation:** +Cluster provisioned by RKE doesn't require or maintain a configuration file for etcd. +All configuration is passed in as arguments at container run time. + +### 1.1.9 Ensure that the Container Network Interface file permissions are set to 644 or more restrictive (Manual) + + +**Result:** warn + +**Remediation:** +Run the below command (based on the file location on your system) on the master node. +For example, +chmod 644 + +**Audit:** + +```bash +stat -c permissions=%a +``` + +### 1.1.10 Ensure that the Container Network Interface file ownership is set to root:root (Manual) + + +**Result:** warn + +**Remediation:** +Run the below command (based on the file location on your system) on the master node. +For example, +chown root:root + +**Audit:** + +```bash +stat -c %U:%G +``` + +### 1.1.13 Ensure that the admin.conf file permissions are set to 644 or more restrictive (Automated) + + +**Result:** Not Applicable + +**Remediation:** +Cluster provisioned by RKE does not store the Kubernetes default kubeconfig credentials file on the nodes. + +### 1.1.14 Ensure that the admin.conf file ownership is set to root:root (Automated) + + +**Result:** Not Applicable + +**Remediation:** +Cluster provisioned by RKE does not store the Kubernetes default kubeconfig credentials file on the nodes. + +### 1.1.15 Ensure that the scheduler.conf file permissions are set to 644 or more restrictive (Automated) + + +**Result:** Not Applicable + +**Remediation:** +Cluster provisioned by RKE doesn't require or maintain a configuration file for scheduler. +All configuration is passed in as arguments at container run time. + +### 1.1.16 Ensure that the scheduler.conf file ownership is set to root:root (Automated) + + +**Result:** Not Applicable + +**Remediation:** +Cluster provisioned by RKE doesn't require or maintain a configuration file for scheduler. +All configuration is passed in as arguments at container run time. + +### 1.1.17 Ensure that the controller-manager.conf file permissions are set to 644 or more restrictive (Automated) + + +**Result:** Not Applicable + +**Remediation:** +Cluster provisioned by RKE doesn't require or maintain a configuration file for controller-manager. +All configuration is passed in as arguments at container run time. + +### 1.1.18 Ensure that the controller-manager.conf file ownership is set to root:root (Automated) + + +**Result:** Not Applicable + +**Remediation:** +Cluster provisioned by RKE doesn't require or maintain a configuration file for controller-manager. +All configuration is passed in as arguments at container run time. + +### 1.1.19 Ensure that the Kubernetes PKI directory and file ownership is set to root:root (Automated) + + +**Result:** pass + +**Remediation:** +Run the below command (based on the file location on your system) on the master node. +For example, +chown -R root:root /etc/kubernetes/pki/ + +**Audit Script:** `check_files_owner_in_dir.sh` + +```bash +#!/usr/bin/env bash + +# This script is used to ensure the owner is set to root:root for +# the given directory and all the files in it +# +# inputs: +# $1 = /full/path/to/directory +# +# outputs: +# true/false + +INPUT_DIR=$1 + +if [[ "${INPUT_DIR}" == "" ]]; then + echo "false" + exit +fi + +if [[ $(stat -c %U:%G ${INPUT_DIR}) != "root:root" ]]; then + echo "false" + exit +fi + +statInfoLines=$(stat -c "%n %U:%G" ${INPUT_DIR}/*) +while read -r statInfoLine; do + f=$(echo ${statInfoLine} | cut -d' ' -f1) + p=$(echo ${statInfoLine} | cut -d' ' -f2) + + if [[ $(basename "$f" .pem) == "kube-etcd-"* ]]; then + if [[ "$p" != "root:root" && "$p" != "etcd:etcd" ]]; then + echo "false" + exit + fi + else + if [[ "$p" != "root:root" ]]; then + echo "false" + exit + fi + fi +done <<< "${statInfoLines}" + + +echo "true" +exit + +``` + +**Audit Execution:** + +```bash +./check_files_owner_in_dir.sh /node/etc/kubernetes/ssl +``` + +**Expected Result**: + +```console +'true' is equal to 'true' +``` + +**Returned Value**: + +```console +true +``` + +### 1.1.20 Ensure that the Kubernetes PKI certificate file permissions are set to 644 or more restrictive (Automated) + + +**Result:** pass + +**Remediation:** +Run the below command (based on the file location on your system) on the master node. +For example, +chmod -R 644 /etc/kubernetes/pki/*.crt + +**Audit Script:** `check_files_permissions.sh` + +```bash +#!/usr/bin/env bash + +# This script is used to ensure the file permissions are set to 644 or +# more restrictive for all files in a given directory or a wildcard +# selection of files +# +# inputs: +# $1 = /full/path/to/directory or /path/to/fileswithpattern +# ex: !(*key).pem +# +# $2 (optional) = permission (ex: 600) +# +# outputs: +# true/false + +# Turn on "extended glob" for use of '!' in wildcard +shopt -s extglob + +# Turn off history to avoid surprises when using '!' +set -H + +USER_INPUT=$1 + +if [[ "${USER_INPUT}" == "" ]]; then + echo "false" + exit +fi + + +if [[ -d ${USER_INPUT} ]]; then + PATTERN="${USER_INPUT}/*" +else + PATTERN="${USER_INPUT}" +fi + +PERMISSION="" +if [[ "$2" != "" ]]; then + PERMISSION=$2 +fi + +FILES_PERMISSIONS=$(stat -c %n\ %a ${PATTERN}) + +while read -r fileInfo; do + p=$(echo ${fileInfo} | cut -d' ' -f2) + + if [[ "${PERMISSION}" != "" ]]; then + if [[ "$p" != "${PERMISSION}" ]]; then + echo "false" + exit + fi + else + if [[ "$p" != "644" && "$p" != "640" && "$p" != "600" ]]; then + echo "false" + exit + fi + fi +done <<< "${FILES_PERMISSIONS}" + + +echo "true" +exit + +``` + +**Audit Execution:** + +```bash +./check_files_permissions.sh /node/etc/kubernetes/ssl/!(*key).pem +``` + +**Expected Result**: + +```console +'true' is equal to 'true' +``` + +**Returned Value**: + +```console +true +``` + +### 1.1.21 Ensure that the Kubernetes PKI key file permissions are set to 600 (Automated) + + +**Result:** pass + +**Remediation:** +Run the below command (based on the file location on your system) on the master node. +For example, +chmod -R 600 /etc/kubernetes/ssl/*key.pem + +**Audit Script:** `check_files_permissions.sh` + +```bash +#!/usr/bin/env bash + +# This script is used to ensure the file permissions are set to 644 or +# more restrictive for all files in a given directory or a wildcard +# selection of files +# +# inputs: +# $1 = /full/path/to/directory or /path/to/fileswithpattern +# ex: !(*key).pem +# +# $2 (optional) = permission (ex: 600) +# +# outputs: +# true/false + +# Turn on "extended glob" for use of '!' in wildcard +shopt -s extglob + +# Turn off history to avoid surprises when using '!' +set -H + +USER_INPUT=$1 + +if [[ "${USER_INPUT}" == "" ]]; then + echo "false" + exit +fi + + +if [[ -d ${USER_INPUT} ]]; then + PATTERN="${USER_INPUT}/*" +else + PATTERN="${USER_INPUT}" +fi + +PERMISSION="" +if [[ "$2" != "" ]]; then + PERMISSION=$2 +fi + +FILES_PERMISSIONS=$(stat -c %n\ %a ${PATTERN}) + +while read -r fileInfo; do + p=$(echo ${fileInfo} | cut -d' ' -f2) + + if [[ "${PERMISSION}" != "" ]]; then + if [[ "$p" != "${PERMISSION}" ]]; then + echo "false" + exit + fi + else + if [[ "$p" != "644" && "$p" != "640" && "$p" != "600" ]]; then + echo "false" + exit + fi + fi +done <<< "${FILES_PERMISSIONS}" + + +echo "true" +exit + +``` + +**Audit Execution:** + +```bash +./check_files_permissions.sh /node/etc/kubernetes/ssl/*key.pem +``` + +**Expected Result**: + +```console +'true' is equal to 'true' +``` + +**Returned Value**: + +```console +true +``` + +### 1.1.11 Ensure that the etcd data directory permissions are set to 700 or more restrictive (Automated) + + +**Result:** pass + +**Remediation:** +On the etcd server node, get the etcd data directory, passed as an argument --data-dir, +from the below command: +ps -ef | grep etcd Run the below command (based on the etcd data directory found above). For example, +chmod 700 /var/lib/etcd + +**Audit:** + +```bash +stat -c %a /node/var/lib/etcd +``` + +**Expected Result**: + +```console +'700' is equal to '700' +``` + +**Returned Value**: + +```console +700 +``` + +### 1.1.12 Ensure that the etcd data directory ownership is set to etcd:etcd (Automated) + + +**Result:** pass + +**Remediation:** +On the etcd server node, get the etcd data directory, passed as an argument --data-dir, +from the below command: +ps -ef | grep etcd +Run the below command (based on the etcd data directory found above). +For example, chown etcd:etcd /var/lib/etcd + +A system service account is required for etcd data directory ownership. +Refer to Rancher's hardening guide for more details on how to configure this ownership. + +**Audit:** + +```bash +stat -c %U:%G /node/var/lib/etcd +``` + +**Expected Result**: + +```console +'etcd:etcd' is present +``` + +**Returned Value**: + +```console +etcd:etcd +``` + +## 1.2 API Server +### 1.2.1 Ensure that the --anonymous-auth argument is set to false (Automated) + + +**Result:** pass + +**Remediation:** +Edit the API server pod specification file /etc/kubernetes/manifests/kube-apiserver.yaml +on the master node and set the below parameter. +--anonymous-auth=false + +**Audit:** + +```bash +/bin/ps -ef | grep kube-apiserver | grep -v grep +``` + +**Expected Result**: + +```console +'false' is equal to 'false' +``` + +**Returned Value**: + +```console +root 6465 6444 8 13:04 ? 00:01:02 kube-apiserver --requestheader-allowed-names=kube-apiserver-proxy-client --etcd-cafile=/etc/kubernetes/ssl/kube-ca.pem --service-node-port-range=30000-32767 --encryption-provider-config=/etc/kubernetes/ssl/encryption.yaml --secure-port=6443 --proxy-client-cert-file=/etc/kubernetes/ssl/kube-apiserver-proxy-client.pem --tls-cert-file=/etc/kubernetes/ssl/kube-apiserver.pem --api-audiences=unknown --storage-backend=etcd3 --tls-cipher-suites=TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384,TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305,TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384,TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305 --audit-policy-file=/etc/kubernetes/audit-policy.yaml --etcd-servers=https://:2379 --kubelet-certificate-authority=/etc/kubernetes/ssl/kube-ca.pem --service-account-signing-key-file=/etc/kubernetes/ssl/kube-service-account-token-key.pem --admission-control-config-file=/etc/kubernetes/admission.yaml --etcd-prefix=/registry --service-account-key-file=/etc/kubernetes/ssl/kube-service-account-token-key.pem --tls-private-key-file=/etc/kubernetes/ssl/kube-apiserver-key.pem --requestheader-group-headers=X-Remote-Group --requestheader-username-headers=X-Remote-User --advertise-address= --client-ca-file=/etc/kubernetes/ssl/kube-ca.pem --requestheader-client-ca-file=/etc/kubernetes/ssl/kube-apiserver-requestheader-ca.pem --requestheader-extra-headers-prefix=X-Remote-Extra- --enable-admission-plugins=NamespaceLifecycle,LimitRanger,ServiceAccount,DefaultStorageClass,DefaultTolerationSeconds,MutatingAdmissionWebhook,ValidatingAdmissionWebhook,ResourceQuota,NodeRestriction,Priority,TaintNodesByCondition,PersistentVolumeClaimResize,PodSecurityPolicy,EventRateLimit --authorization-mode=Node,RBAC --cloud-provider= --etcd-certfile=/etc/kubernetes/ssl/kube-node.pem --etcd-keyfile=/etc/kubernetes/ssl/kube-node-key.pem --service-cluster-ip-range=10.43.0.0/16 --profiling=false --service-account-issuer=rke --allow-privileged=true --insecure-port=0 --anonymous-auth=false --audit-log-path=/var/log/kube-audit/audit-log.json --kubelet-client-certificate=/etc/kubernetes/ssl/kube-apiserver.pem --kubelet-client-key=/etc/kubernetes/ssl/kube-apiserver-key.pem --proxy-client-key-file=/etc/kubernetes/ssl/kube-apiserver-proxy-client-key.pem --bind-address=0.0.0.0 --kubelet-preferred-address-types=InternalIP,ExternalIP,Hostname --audit-log-maxsize=100 --audit-log-format=json --service-account-lookup=true --runtime-config=policy/v1beta1/podsecuritypolicy=true --audit-log-maxage=30 --audit-log-maxbackup=10 +``` + +### 1.2.2 Ensure that the --basic-auth-file argument is not set (Automated) + + +**Result:** pass + +**Remediation:** +Follow the documentation and configure alternate mechanisms for authentication. Then, +edit the API server pod specification file /etc/kubernetes/manifests/kube-apiserver.yaml +on the master node and remove the --basic-auth-file= parameter. + +**Audit:** + +```bash +/bin/ps -ef | grep kube-apiserver | grep -v grep +``` + +**Expected Result**: + +```console +'--basic-auth-file' is not present +``` + +**Returned Value**: + +```console +root 6465 6444 8 13:04 ? 00:01:02 kube-apiserver --requestheader-allowed-names=kube-apiserver-proxy-client --etcd-cafile=/etc/kubernetes/ssl/kube-ca.pem --service-node-port-range=30000-32767 --encryption-provider-config=/etc/kubernetes/ssl/encryption.yaml --secure-port=6443 --proxy-client-cert-file=/etc/kubernetes/ssl/kube-apiserver-proxy-client.pem --tls-cert-file=/etc/kubernetes/ssl/kube-apiserver.pem --api-audiences=unknown --storage-backend=etcd3 --tls-cipher-suites=TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384,TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305,TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384,TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305 --audit-policy-file=/etc/kubernetes/audit-policy.yaml --etcd-servers=https://:2379 --kubelet-certificate-authority=/etc/kubernetes/ssl/kube-ca.pem --service-account-signing-key-file=/etc/kubernetes/ssl/kube-service-account-token-key.pem --admission-control-config-file=/etc/kubernetes/admission.yaml --etcd-prefix=/registry --service-account-key-file=/etc/kubernetes/ssl/kube-service-account-token-key.pem --tls-private-key-file=/etc/kubernetes/ssl/kube-apiserver-key.pem --requestheader-group-headers=X-Remote-Group --requestheader-username-headers=X-Remote-User --advertise-address= --client-ca-file=/etc/kubernetes/ssl/kube-ca.pem --requestheader-client-ca-file=/etc/kubernetes/ssl/kube-apiserver-requestheader-ca.pem --requestheader-extra-headers-prefix=X-Remote-Extra- --enable-admission-plugins=NamespaceLifecycle,LimitRanger,ServiceAccount,DefaultStorageClass,DefaultTolerationSeconds,MutatingAdmissionWebhook,ValidatingAdmissionWebhook,ResourceQuota,NodeRestriction,Priority,TaintNodesByCondition,PersistentVolumeClaimResize,PodSecurityPolicy,EventRateLimit --authorization-mode=Node,RBAC --cloud-provider= --etcd-certfile=/etc/kubernetes/ssl/kube-node.pem --etcd-keyfile=/etc/kubernetes/ssl/kube-node-key.pem --service-cluster-ip-range=10.43.0.0/16 --profiling=false --service-account-issuer=rke --allow-privileged=true --insecure-port=0 --anonymous-auth=false --audit-log-path=/var/log/kube-audit/audit-log.json --kubelet-client-certificate=/etc/kubernetes/ssl/kube-apiserver.pem --kubelet-client-key=/etc/kubernetes/ssl/kube-apiserver-key.pem --proxy-client-key-file=/etc/kubernetes/ssl/kube-apiserver-proxy-client-key.pem --bind-address=0.0.0.0 --kubelet-preferred-address-types=InternalIP,ExternalIP,Hostname --audit-log-maxsize=100 --audit-log-format=json --service-account-lookup=true --runtime-config=policy/v1beta1/podsecuritypolicy=true --audit-log-maxage=30 --audit-log-maxbackup=10 +``` + +### 1.2.3 Ensure that the --token-auth-file parameter is not set (Automated) + + +**Result:** pass + +**Remediation:** +Follow the documentation and configure alternate mechanisms for authentication. Then, +edit the API server pod specification file /etc/kubernetes/manifests/kube-apiserver.yaml +on the master node and remove the --token-auth-file= parameter. + +**Audit:** + +```bash +/bin/ps -ef | grep kube-apiserver | grep -v grep +``` + +**Expected Result**: + +```console +'--token-auth-file' is not present +``` + +**Returned Value**: + +```console +root 6465 6444 8 13:04 ? 00:01:02 kube-apiserver --requestheader-allowed-names=kube-apiserver-proxy-client --etcd-cafile=/etc/kubernetes/ssl/kube-ca.pem --service-node-port-range=30000-32767 --encryption-provider-config=/etc/kubernetes/ssl/encryption.yaml --secure-port=6443 --proxy-client-cert-file=/etc/kubernetes/ssl/kube-apiserver-proxy-client.pem --tls-cert-file=/etc/kubernetes/ssl/kube-apiserver.pem --api-audiences=unknown --storage-backend=etcd3 --tls-cipher-suites=TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384,TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305,TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384,TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305 --audit-policy-file=/etc/kubernetes/audit-policy.yaml --etcd-servers=https://:2379 --kubelet-certificate-authority=/etc/kubernetes/ssl/kube-ca.pem --service-account-signing-key-file=/etc/kubernetes/ssl/kube-service-account-token-key.pem --admission-control-config-file=/etc/kubernetes/admission.yaml --etcd-prefix=/registry --service-account-key-file=/etc/kubernetes/ssl/kube-service-account-token-key.pem --tls-private-key-file=/etc/kubernetes/ssl/kube-apiserver-key.pem --requestheader-group-headers=X-Remote-Group --requestheader-username-headers=X-Remote-User --advertise-address= --client-ca-file=/etc/kubernetes/ssl/kube-ca.pem --requestheader-client-ca-file=/etc/kubernetes/ssl/kube-apiserver-requestheader-ca.pem --requestheader-extra-headers-prefix=X-Remote-Extra- --enable-admission-plugins=NamespaceLifecycle,LimitRanger,ServiceAccount,DefaultStorageClass,DefaultTolerationSeconds,MutatingAdmissionWebhook,ValidatingAdmissionWebhook,ResourceQuota,NodeRestriction,Priority,TaintNodesByCondition,PersistentVolumeClaimResize,PodSecurityPolicy,EventRateLimit --authorization-mode=Node,RBAC --cloud-provider= --etcd-certfile=/etc/kubernetes/ssl/kube-node.pem --etcd-keyfile=/etc/kubernetes/ssl/kube-node-key.pem --service-cluster-ip-range=10.43.0.0/16 --profiling=false --service-account-issuer=rke --allow-privileged=true --insecure-port=0 --anonymous-auth=false --audit-log-path=/var/log/kube-audit/audit-log.json --kubelet-client-certificate=/etc/kubernetes/ssl/kube-apiserver.pem --kubelet-client-key=/etc/kubernetes/ssl/kube-apiserver-key.pem --proxy-client-key-file=/etc/kubernetes/ssl/kube-apiserver-proxy-client-key.pem --bind-address=0.0.0.0 --kubelet-preferred-address-types=InternalIP,ExternalIP,Hostname --audit-log-maxsize=100 --audit-log-format=json --service-account-lookup=true --runtime-config=policy/v1beta1/podsecuritypolicy=true --audit-log-maxage=30 --audit-log-maxbackup=10 +``` + +### 1.2.4 Ensure that the --kubelet-https argument is set to true (Automated) + + +**Result:** pass + +**Remediation:** +Edit the API server pod specification file /etc/kubernetes/manifests/kube-apiserver.yaml +on the master node and remove the --kubelet-https parameter. + +**Audit:** + +```bash +/bin/ps -ef | grep kube-apiserver | grep -v grep +``` + +**Expected Result**: + +```console +'--kubelet-https' is not present OR '--kubelet-https' is not present +``` + +**Returned Value**: + +```console +root 6465 6444 8 13:04 ? 00:01:02 kube-apiserver --requestheader-allowed-names=kube-apiserver-proxy-client --etcd-cafile=/etc/kubernetes/ssl/kube-ca.pem --service-node-port-range=30000-32767 --encryption-provider-config=/etc/kubernetes/ssl/encryption.yaml --secure-port=6443 --proxy-client-cert-file=/etc/kubernetes/ssl/kube-apiserver-proxy-client.pem --tls-cert-file=/etc/kubernetes/ssl/kube-apiserver.pem --api-audiences=unknown --storage-backend=etcd3 --tls-cipher-suites=TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384,TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305,TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384,TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305 --audit-policy-file=/etc/kubernetes/audit-policy.yaml --etcd-servers=https://:2379 --kubelet-certificate-authority=/etc/kubernetes/ssl/kube-ca.pem --service-account-signing-key-file=/etc/kubernetes/ssl/kube-service-account-token-key.pem --admission-control-config-file=/etc/kubernetes/admission.yaml --etcd-prefix=/registry --service-account-key-file=/etc/kubernetes/ssl/kube-service-account-token-key.pem --tls-private-key-file=/etc/kubernetes/ssl/kube-apiserver-key.pem --requestheader-group-headers=X-Remote-Group --requestheader-username-headers=X-Remote-User --advertise-address= --client-ca-file=/etc/kubernetes/ssl/kube-ca.pem --requestheader-client-ca-file=/etc/kubernetes/ssl/kube-apiserver-requestheader-ca.pem --requestheader-extra-headers-prefix=X-Remote-Extra- --enable-admission-plugins=NamespaceLifecycle,LimitRanger,ServiceAccount,DefaultStorageClass,DefaultTolerationSeconds,MutatingAdmissionWebhook,ValidatingAdmissionWebhook,ResourceQuota,NodeRestriction,Priority,TaintNodesByCondition,PersistentVolumeClaimResize,PodSecurityPolicy,EventRateLimit --authorization-mode=Node,RBAC --cloud-provider= --etcd-certfile=/etc/kubernetes/ssl/kube-node.pem --etcd-keyfile=/etc/kubernetes/ssl/kube-node-key.pem --service-cluster-ip-range=10.43.0.0/16 --profiling=false --service-account-issuer=rke --allow-privileged=true --insecure-port=0 --anonymous-auth=false --audit-log-path=/var/log/kube-audit/audit-log.json --kubelet-client-certificate=/etc/kubernetes/ssl/kube-apiserver.pem --kubelet-client-key=/etc/kubernetes/ssl/kube-apiserver-key.pem --proxy-client-key-file=/etc/kubernetes/ssl/kube-apiserver-proxy-client-key.pem --bind-address=0.0.0.0 --kubelet-preferred-address-types=InternalIP,ExternalIP,Hostname --audit-log-maxsize=100 --audit-log-format=json --service-account-lookup=true --runtime-config=policy/v1beta1/podsecuritypolicy=true --audit-log-maxage=30 --audit-log-maxbackup=10 +``` + +### 1.2.5 Ensure that the --kubelet-client-certificate and --kubelet-client-key arguments are set as appropriate (Automated) + + +**Result:** pass + +**Remediation:** +Follow the Kubernetes documentation and set up the TLS connection between the +apiserver and kubelets. Then, edit API server pod specification file +/etc/kubernetes/manifests/kube-apiserver.yaml on the master node and set the +kubelet client certificate and key parameters as below. +--kubelet-client-certificate= +--kubelet-client-key= + +**Audit:** + +```bash +/bin/ps -ef | grep kube-apiserver | grep -v grep +``` + +**Expected Result**: + +```console +'--kubelet-client-certificate' is present AND '--kubelet-client-key' is present +``` + +**Returned Value**: + +```console +root 6465 6444 8 13:04 ? 00:01:02 kube-apiserver --requestheader-allowed-names=kube-apiserver-proxy-client --etcd-cafile=/etc/kubernetes/ssl/kube-ca.pem --service-node-port-range=30000-32767 --encryption-provider-config=/etc/kubernetes/ssl/encryption.yaml --secure-port=6443 --proxy-client-cert-file=/etc/kubernetes/ssl/kube-apiserver-proxy-client.pem --tls-cert-file=/etc/kubernetes/ssl/kube-apiserver.pem --api-audiences=unknown --storage-backend=etcd3 --tls-cipher-suites=TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384,TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305,TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384,TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305 --audit-policy-file=/etc/kubernetes/audit-policy.yaml --etcd-servers=https://:2379 --kubelet-certificate-authority=/etc/kubernetes/ssl/kube-ca.pem --service-account-signing-key-file=/etc/kubernetes/ssl/kube-service-account-token-key.pem --admission-control-config-file=/etc/kubernetes/admission.yaml --etcd-prefix=/registry --service-account-key-file=/etc/kubernetes/ssl/kube-service-account-token-key.pem --tls-private-key-file=/etc/kubernetes/ssl/kube-apiserver-key.pem --requestheader-group-headers=X-Remote-Group --requestheader-username-headers=X-Remote-User --advertise-address= --client-ca-file=/etc/kubernetes/ssl/kube-ca.pem --requestheader-client-ca-file=/etc/kubernetes/ssl/kube-apiserver-requestheader-ca.pem --requestheader-extra-headers-prefix=X-Remote-Extra- --enable-admission-plugins=NamespaceLifecycle,LimitRanger,ServiceAccount,DefaultStorageClass,DefaultTolerationSeconds,MutatingAdmissionWebhook,ValidatingAdmissionWebhook,ResourceQuota,NodeRestriction,Priority,TaintNodesByCondition,PersistentVolumeClaimResize,PodSecurityPolicy,EventRateLimit --authorization-mode=Node,RBAC --cloud-provider= --etcd-certfile=/etc/kubernetes/ssl/kube-node.pem --etcd-keyfile=/etc/kubernetes/ssl/kube-node-key.pem --service-cluster-ip-range=10.43.0.0/16 --profiling=false --service-account-issuer=rke --allow-privileged=true --insecure-port=0 --anonymous-auth=false --audit-log-path=/var/log/kube-audit/audit-log.json --kubelet-client-certificate=/etc/kubernetes/ssl/kube-apiserver.pem --kubelet-client-key=/etc/kubernetes/ssl/kube-apiserver-key.pem --proxy-client-key-file=/etc/kubernetes/ssl/kube-apiserver-proxy-client-key.pem --bind-address=0.0.0.0 --kubelet-preferred-address-types=InternalIP,ExternalIP,Hostname --audit-log-maxsize=100 --audit-log-format=json --service-account-lookup=true --runtime-config=policy/v1beta1/podsecuritypolicy=true --audit-log-maxage=30 --audit-log-maxbackup=10 +``` + +### 1.2.6 Ensure that the --kubelet-certificate-authority argument is set as appropriate (Automated) + + +**Result:** pass + +**Remediation:** +Follow the Kubernetes documentation and setup the TLS connection between +the apiserver and kubelets. Then, edit the API server pod specification file +/etc/kubernetes/manifests/kube-apiserver.yaml on the master node and set the +--kubelet-certificate-authority parameter to the path to the cert file for the certificate authority. +--kubelet-certificate-authority= + +**Audit:** + +```bash +/bin/ps -ef | grep kube-apiserver | grep -v grep +``` + +**Expected Result**: + +```console +'--kubelet-certificate-authority' is present +``` + +**Returned Value**: + +```console +root 6465 6444 8 13:04 ? 00:01:02 kube-apiserver --requestheader-allowed-names=kube-apiserver-proxy-client --etcd-cafile=/etc/kubernetes/ssl/kube-ca.pem --service-node-port-range=30000-32767 --encryption-provider-config=/etc/kubernetes/ssl/encryption.yaml --secure-port=6443 --proxy-client-cert-file=/etc/kubernetes/ssl/kube-apiserver-proxy-client.pem --tls-cert-file=/etc/kubernetes/ssl/kube-apiserver.pem --api-audiences=unknown --storage-backend=etcd3 --tls-cipher-suites=TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384,TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305,TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384,TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305 --audit-policy-file=/etc/kubernetes/audit-policy.yaml --etcd-servers=https://:2379 --kubelet-certificate-authority=/etc/kubernetes/ssl/kube-ca.pem --service-account-signing-key-file=/etc/kubernetes/ssl/kube-service-account-token-key.pem --admission-control-config-file=/etc/kubernetes/admission.yaml --etcd-prefix=/registry --service-account-key-file=/etc/kubernetes/ssl/kube-service-account-token-key.pem --tls-private-key-file=/etc/kubernetes/ssl/kube-apiserver-key.pem --requestheader-group-headers=X-Remote-Group --requestheader-username-headers=X-Remote-User --advertise-address= --client-ca-file=/etc/kubernetes/ssl/kube-ca.pem --requestheader-client-ca-file=/etc/kubernetes/ssl/kube-apiserver-requestheader-ca.pem --requestheader-extra-headers-prefix=X-Remote-Extra- --enable-admission-plugins=NamespaceLifecycle,LimitRanger,ServiceAccount,DefaultStorageClass,DefaultTolerationSeconds,MutatingAdmissionWebhook,ValidatingAdmissionWebhook,ResourceQuota,NodeRestriction,Priority,TaintNodesByCondition,PersistentVolumeClaimResize,PodSecurityPolicy,EventRateLimit --authorization-mode=Node,RBAC --cloud-provider= --etcd-certfile=/etc/kubernetes/ssl/kube-node.pem --etcd-keyfile=/etc/kubernetes/ssl/kube-node-key.pem --service-cluster-ip-range=10.43.0.0/16 --profiling=false --service-account-issuer=rke --allow-privileged=true --insecure-port=0 --anonymous-auth=false --audit-log-path=/var/log/kube-audit/audit-log.json --kubelet-client-certificate=/etc/kubernetes/ssl/kube-apiserver.pem --kubelet-client-key=/etc/kubernetes/ssl/kube-apiserver-key.pem --proxy-client-key-file=/etc/kubernetes/ssl/kube-apiserver-proxy-client-key.pem --bind-address=0.0.0.0 --kubelet-preferred-address-types=InternalIP,ExternalIP,Hostname --audit-log-maxsize=100 --audit-log-format=json --service-account-lookup=true --runtime-config=policy/v1beta1/podsecuritypolicy=true --audit-log-maxage=30 --audit-log-maxbackup=10 +``` + +### 1.2.7 Ensure that the --authorization-mode argument is not set to AlwaysAllow (Automated) + + +**Result:** pass + +**Remediation:** +Edit the API server pod specification file /etc/kubernetes/manifests/kube-apiserver.yaml +on the master node and set the --authorization-mode parameter to values other than AlwaysAllow. +One such example could be as below. +--authorization-mode=RBAC + +**Audit:** + +```bash +/bin/ps -ef | grep kube-apiserver | grep -v grep +``` + +**Expected Result**: + +```console +'Node,RBAC' not have 'AlwaysAllow' +``` + +**Returned Value**: + +```console +root 6465 6444 8 13:04 ? 00:01:02 kube-apiserver --requestheader-allowed-names=kube-apiserver-proxy-client --etcd-cafile=/etc/kubernetes/ssl/kube-ca.pem --service-node-port-range=30000-32767 --encryption-provider-config=/etc/kubernetes/ssl/encryption.yaml --secure-port=6443 --proxy-client-cert-file=/etc/kubernetes/ssl/kube-apiserver-proxy-client.pem --tls-cert-file=/etc/kubernetes/ssl/kube-apiserver.pem --api-audiences=unknown --storage-backend=etcd3 --tls-cipher-suites=TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384,TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305,TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384,TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305 --audit-policy-file=/etc/kubernetes/audit-policy.yaml --etcd-servers=https://:2379 --kubelet-certificate-authority=/etc/kubernetes/ssl/kube-ca.pem --service-account-signing-key-file=/etc/kubernetes/ssl/kube-service-account-token-key.pem --admission-control-config-file=/etc/kubernetes/admission.yaml --etcd-prefix=/registry --service-account-key-file=/etc/kubernetes/ssl/kube-service-account-token-key.pem --tls-private-key-file=/etc/kubernetes/ssl/kube-apiserver-key.pem --requestheader-group-headers=X-Remote-Group --requestheader-username-headers=X-Remote-User --advertise-address= --client-ca-file=/etc/kubernetes/ssl/kube-ca.pem --requestheader-client-ca-file=/etc/kubernetes/ssl/kube-apiserver-requestheader-ca.pem --requestheader-extra-headers-prefix=X-Remote-Extra- --enable-admission-plugins=NamespaceLifecycle,LimitRanger,ServiceAccount,DefaultStorageClass,DefaultTolerationSeconds,MutatingAdmissionWebhook,ValidatingAdmissionWebhook,ResourceQuota,NodeRestriction,Priority,TaintNodesByCondition,PersistentVolumeClaimResize,PodSecurityPolicy,EventRateLimit --authorization-mode=Node,RBAC --cloud-provider= --etcd-certfile=/etc/kubernetes/ssl/kube-node.pem --etcd-keyfile=/etc/kubernetes/ssl/kube-node-key.pem --service-cluster-ip-range=10.43.0.0/16 --profiling=false --service-account-issuer=rke --allow-privileged=true --insecure-port=0 --anonymous-auth=false --audit-log-path=/var/log/kube-audit/audit-log.json --kubelet-client-certificate=/etc/kubernetes/ssl/kube-apiserver.pem --kubelet-client-key=/etc/kubernetes/ssl/kube-apiserver-key.pem --proxy-client-key-file=/etc/kubernetes/ssl/kube-apiserver-proxy-client-key.pem --bind-address=0.0.0.0 --kubelet-preferred-address-types=InternalIP,ExternalIP,Hostname --audit-log-maxsize=100 --audit-log-format=json --service-account-lookup=true --runtime-config=policy/v1beta1/podsecuritypolicy=true --audit-log-maxage=30 --audit-log-maxbackup=10 +``` + +### 1.2.8 Ensure that the --authorization-mode argument includes Node (Automated) + + +**Result:** pass + +**Remediation:** +Edit the API server pod specification file /etc/kubernetes/manifests/kube-apiserver.yaml +on the master node and set the --authorization-mode parameter to a value that includes Node. +--authorization-mode=Node,RBAC + +**Audit:** + +```bash +/bin/ps -ef | grep kube-apiserver | grep -v grep +``` + +**Expected Result**: + +```console +'Node,RBAC' has 'Node' +``` + +**Returned Value**: + +```console +root 6465 6444 8 13:04 ? 00:01:02 kube-apiserver --requestheader-allowed-names=kube-apiserver-proxy-client --etcd-cafile=/etc/kubernetes/ssl/kube-ca.pem --service-node-port-range=30000-32767 --encryption-provider-config=/etc/kubernetes/ssl/encryption.yaml --secure-port=6443 --proxy-client-cert-file=/etc/kubernetes/ssl/kube-apiserver-proxy-client.pem --tls-cert-file=/etc/kubernetes/ssl/kube-apiserver.pem --api-audiences=unknown --storage-backend=etcd3 --tls-cipher-suites=TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384,TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305,TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384,TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305 --audit-policy-file=/etc/kubernetes/audit-policy.yaml --etcd-servers=https://:2379 --kubelet-certificate-authority=/etc/kubernetes/ssl/kube-ca.pem --service-account-signing-key-file=/etc/kubernetes/ssl/kube-service-account-token-key.pem --admission-control-config-file=/etc/kubernetes/admission.yaml --etcd-prefix=/registry --service-account-key-file=/etc/kubernetes/ssl/kube-service-account-token-key.pem --tls-private-key-file=/etc/kubernetes/ssl/kube-apiserver-key.pem --requestheader-group-headers=X-Remote-Group --requestheader-username-headers=X-Remote-User --advertise-address= --client-ca-file=/etc/kubernetes/ssl/kube-ca.pem --requestheader-client-ca-file=/etc/kubernetes/ssl/kube-apiserver-requestheader-ca.pem --requestheader-extra-headers-prefix=X-Remote-Extra- --enable-admission-plugins=NamespaceLifecycle,LimitRanger,ServiceAccount,DefaultStorageClass,DefaultTolerationSeconds,MutatingAdmissionWebhook,ValidatingAdmissionWebhook,ResourceQuota,NodeRestriction,Priority,TaintNodesByCondition,PersistentVolumeClaimResize,PodSecurityPolicy,EventRateLimit --authorization-mode=Node,RBAC --cloud-provider= --etcd-certfile=/etc/kubernetes/ssl/kube-node.pem --etcd-keyfile=/etc/kubernetes/ssl/kube-node-key.pem --service-cluster-ip-range=10.43.0.0/16 --profiling=false --service-account-issuer=rke --allow-privileged=true --insecure-port=0 --anonymous-auth=false --audit-log-path=/var/log/kube-audit/audit-log.json --kubelet-client-certificate=/etc/kubernetes/ssl/kube-apiserver.pem --kubelet-client-key=/etc/kubernetes/ssl/kube-apiserver-key.pem --proxy-client-key-file=/etc/kubernetes/ssl/kube-apiserver-proxy-client-key.pem --bind-address=0.0.0.0 --kubelet-preferred-address-types=InternalIP,ExternalIP,Hostname --audit-log-maxsize=100 --audit-log-format=json --service-account-lookup=true --runtime-config=policy/v1beta1/podsecuritypolicy=true --audit-log-maxage=30 --audit-log-maxbackup=10 +``` + +### 1.2.9 Ensure that the --authorization-mode argument includes RBAC (Automated) + + +**Result:** pass + +**Remediation:** +Edit the API server pod specification file /etc/kubernetes/manifests/kube-apiserver.yaml +on the master node and set the --authorization-mode parameter to a value that includes RBAC, +for example: +--authorization-mode=Node,RBAC + +**Audit:** + +```bash +/bin/ps -ef | grep kube-apiserver | grep -v grep +``` + +**Expected Result**: + +```console +'Node,RBAC' has 'RBAC' +``` + +**Returned Value**: + +```console +root 6465 6444 8 13:04 ? 00:01:02 kube-apiserver --requestheader-allowed-names=kube-apiserver-proxy-client --etcd-cafile=/etc/kubernetes/ssl/kube-ca.pem --service-node-port-range=30000-32767 --encryption-provider-config=/etc/kubernetes/ssl/encryption.yaml --secure-port=6443 --proxy-client-cert-file=/etc/kubernetes/ssl/kube-apiserver-proxy-client.pem --tls-cert-file=/etc/kubernetes/ssl/kube-apiserver.pem --api-audiences=unknown --storage-backend=etcd3 --tls-cipher-suites=TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384,TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305,TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384,TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305 --audit-policy-file=/etc/kubernetes/audit-policy.yaml --etcd-servers=https://:2379 --kubelet-certificate-authority=/etc/kubernetes/ssl/kube-ca.pem --service-account-signing-key-file=/etc/kubernetes/ssl/kube-service-account-token-key.pem --admission-control-config-file=/etc/kubernetes/admission.yaml --etcd-prefix=/registry --service-account-key-file=/etc/kubernetes/ssl/kube-service-account-token-key.pem --tls-private-key-file=/etc/kubernetes/ssl/kube-apiserver-key.pem --requestheader-group-headers=X-Remote-Group --requestheader-username-headers=X-Remote-User --advertise-address= --client-ca-file=/etc/kubernetes/ssl/kube-ca.pem --requestheader-client-ca-file=/etc/kubernetes/ssl/kube-apiserver-requestheader-ca.pem --requestheader-extra-headers-prefix=X-Remote-Extra- --enable-admission-plugins=NamespaceLifecycle,LimitRanger,ServiceAccount,DefaultStorageClass,DefaultTolerationSeconds,MutatingAdmissionWebhook,ValidatingAdmissionWebhook,ResourceQuota,NodeRestriction,Priority,TaintNodesByCondition,PersistentVolumeClaimResize,PodSecurityPolicy,EventRateLimit --authorization-mode=Node,RBAC --cloud-provider= --etcd-certfile=/etc/kubernetes/ssl/kube-node.pem --etcd-keyfile=/etc/kubernetes/ssl/kube-node-key.pem --service-cluster-ip-range=10.43.0.0/16 --profiling=false --service-account-issuer=rke --allow-privileged=true --insecure-port=0 --anonymous-auth=false --audit-log-path=/var/log/kube-audit/audit-log.json --kubelet-client-certificate=/etc/kubernetes/ssl/kube-apiserver.pem --kubelet-client-key=/etc/kubernetes/ssl/kube-apiserver-key.pem --proxy-client-key-file=/etc/kubernetes/ssl/kube-apiserver-proxy-client-key.pem --bind-address=0.0.0.0 --kubelet-preferred-address-types=InternalIP,ExternalIP,Hostname --audit-log-maxsize=100 --audit-log-format=json --service-account-lookup=true --runtime-config=policy/v1beta1/podsecuritypolicy=true --audit-log-maxage=30 --audit-log-maxbackup=10 +``` + +### 1.2.10 Ensure that the admission control plugin EventRateLimit is set (Automated) + + +**Result:** pass + +**Remediation:** +Follow the Kubernetes documentation and set the desired limits in a configuration file. +Then, edit the API server pod specification file /etc/kubernetes/manifests/kube-apiserver.yaml +and set the below parameters. +--enable-admission-plugins=...,EventRateLimit,... +--admission-control-config-file= + +**Audit:** + +```bash +/bin/ps -ef | grep kube-apiserver | grep -v grep +``` + +**Expected Result**: + +```console +'NamespaceLifecycle,LimitRanger,ServiceAccount,DefaultStorageClass,DefaultTolerationSeconds,MutatingAdmissionWebhook,ValidatingAdmissionWebhook,ResourceQuota,NodeRestriction,Priority,TaintNodesByCondition,PersistentVolumeClaimResize,PodSecurityPolicy,EventRateLimit' has 'EventRateLimit' +``` + +**Returned Value**: + +```console +root 6465 6444 8 13:04 ? 00:01:02 kube-apiserver --requestheader-allowed-names=kube-apiserver-proxy-client --etcd-cafile=/etc/kubernetes/ssl/kube-ca.pem --service-node-port-range=30000-32767 --encryption-provider-config=/etc/kubernetes/ssl/encryption.yaml --secure-port=6443 --proxy-client-cert-file=/etc/kubernetes/ssl/kube-apiserver-proxy-client.pem --tls-cert-file=/etc/kubernetes/ssl/kube-apiserver.pem --api-audiences=unknown --storage-backend=etcd3 --tls-cipher-suites=TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384,TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305,TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384,TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305 --audit-policy-file=/etc/kubernetes/audit-policy.yaml --etcd-servers=https://:2379 --kubelet-certificate-authority=/etc/kubernetes/ssl/kube-ca.pem --service-account-signing-key-file=/etc/kubernetes/ssl/kube-service-account-token-key.pem --admission-control-config-file=/etc/kubernetes/admission.yaml --etcd-prefix=/registry --service-account-key-file=/etc/kubernetes/ssl/kube-service-account-token-key.pem --tls-private-key-file=/etc/kubernetes/ssl/kube-apiserver-key.pem --requestheader-group-headers=X-Remote-Group --requestheader-username-headers=X-Remote-User --advertise-address= --client-ca-file=/etc/kubernetes/ssl/kube-ca.pem --requestheader-client-ca-file=/etc/kubernetes/ssl/kube-apiserver-requestheader-ca.pem --requestheader-extra-headers-prefix=X-Remote-Extra- --enable-admission-plugins=NamespaceLifecycle,LimitRanger,ServiceAccount,DefaultStorageClass,DefaultTolerationSeconds,MutatingAdmissionWebhook,ValidatingAdmissionWebhook,ResourceQuota,NodeRestriction,Priority,TaintNodesByCondition,PersistentVolumeClaimResize,PodSecurityPolicy,EventRateLimit --authorization-mode=Node,RBAC --cloud-provider= --etcd-certfile=/etc/kubernetes/ssl/kube-node.pem --etcd-keyfile=/etc/kubernetes/ssl/kube-node-key.pem --service-cluster-ip-range=10.43.0.0/16 --profiling=false --service-account-issuer=rke --allow-privileged=true --insecure-port=0 --anonymous-auth=false --audit-log-path=/var/log/kube-audit/audit-log.json --kubelet-client-certificate=/etc/kubernetes/ssl/kube-apiserver.pem --kubelet-client-key=/etc/kubernetes/ssl/kube-apiserver-key.pem --proxy-client-key-file=/etc/kubernetes/ssl/kube-apiserver-proxy-client-key.pem --bind-address=0.0.0.0 --kubelet-preferred-address-types=InternalIP,ExternalIP,Hostname --audit-log-maxsize=100 --audit-log-format=json --service-account-lookup=true --runtime-config=policy/v1beta1/podsecuritypolicy=true --audit-log-maxage=30 --audit-log-maxbackup=10 +``` + +### 1.2.11 Ensure that the admission control plugin AlwaysAdmit is not set (Automated) + + +**Result:** pass + +**Remediation:** +Edit the API server pod specification file /etc/kubernetes/manifests/kube-apiserver.yaml +on the master node and either remove the --enable-admission-plugins parameter, or set it to a +value that does not include AlwaysAdmit. + +**Audit:** + +```bash +/bin/ps -ef | grep kube-apiserver | grep -v grep +``` + +**Expected Result**: + +```console +'NamespaceLifecycle,LimitRanger,ServiceAccount,DefaultStorageClass,DefaultTolerationSeconds,MutatingAdmissionWebhook,ValidatingAdmissionWebhook,ResourceQuota,NodeRestriction,Priority,TaintNodesByCondition,PersistentVolumeClaimResize,PodSecurityPolicy,EventRateLimit' not have 'AlwaysAdmit' OR '--enable-admission-plugins' is not present +``` + +**Returned Value**: + +```console +root 6465 6444 8 13:04 ? 00:01:02 kube-apiserver --requestheader-allowed-names=kube-apiserver-proxy-client --etcd-cafile=/etc/kubernetes/ssl/kube-ca.pem --service-node-port-range=30000-32767 --encryption-provider-config=/etc/kubernetes/ssl/encryption.yaml --secure-port=6443 --proxy-client-cert-file=/etc/kubernetes/ssl/kube-apiserver-proxy-client.pem --tls-cert-file=/etc/kubernetes/ssl/kube-apiserver.pem --api-audiences=unknown --storage-backend=etcd3 --tls-cipher-suites=TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384,TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305,TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384,TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305 --audit-policy-file=/etc/kubernetes/audit-policy.yaml --etcd-servers=https://:2379 --kubelet-certificate-authority=/etc/kubernetes/ssl/kube-ca.pem --service-account-signing-key-file=/etc/kubernetes/ssl/kube-service-account-token-key.pem --admission-control-config-file=/etc/kubernetes/admission.yaml --etcd-prefix=/registry --service-account-key-file=/etc/kubernetes/ssl/kube-service-account-token-key.pem --tls-private-key-file=/etc/kubernetes/ssl/kube-apiserver-key.pem --requestheader-group-headers=X-Remote-Group --requestheader-username-headers=X-Remote-User --advertise-address= --client-ca-file=/etc/kubernetes/ssl/kube-ca.pem --requestheader-client-ca-file=/etc/kubernetes/ssl/kube-apiserver-requestheader-ca.pem --requestheader-extra-headers-prefix=X-Remote-Extra- --enable-admission-plugins=NamespaceLifecycle,LimitRanger,ServiceAccount,DefaultStorageClass,DefaultTolerationSeconds,MutatingAdmissionWebhook,ValidatingAdmissionWebhook,ResourceQuota,NodeRestriction,Priority,TaintNodesByCondition,PersistentVolumeClaimResize,PodSecurityPolicy,EventRateLimit --authorization-mode=Node,RBAC --cloud-provider= --etcd-certfile=/etc/kubernetes/ssl/kube-node.pem --etcd-keyfile=/etc/kubernetes/ssl/kube-node-key.pem --service-cluster-ip-range=10.43.0.0/16 --profiling=false --service-account-issuer=rke --allow-privileged=true --insecure-port=0 --anonymous-auth=false --audit-log-path=/var/log/kube-audit/audit-log.json --kubelet-client-certificate=/etc/kubernetes/ssl/kube-apiserver.pem --kubelet-client-key=/etc/kubernetes/ssl/kube-apiserver-key.pem --proxy-client-key-file=/etc/kubernetes/ssl/kube-apiserver-proxy-client-key.pem --bind-address=0.0.0.0 --kubelet-preferred-address-types=InternalIP,ExternalIP,Hostname --audit-log-maxsize=100 --audit-log-format=json --service-account-lookup=true --runtime-config=policy/v1beta1/podsecuritypolicy=true --audit-log-maxage=30 --audit-log-maxbackup=10 +``` + +### 1.2.12 Ensure that the admission control plugin AlwaysPullImages is set (Manual) + + +**Result:** warn + +**Remediation:** +Edit the API server pod specification file /etc/kubernetes/manifests/kube-apiserver.yaml +on the master node and set the --enable-admission-plugins parameter to include +AlwaysPullImages. +--enable-admission-plugins=...,AlwaysPullImages,... + +**Audit:** + +```bash +/bin/ps -ef | grep kube-apiserver | grep -v grep +``` + +### 1.2.13 Ensure that the admission control plugin SecurityContextDeny is set if PodSecurityPolicy is not used (Manual) + + +**Result:** warn + +**Remediation:** +Edit the API server pod specification file /etc/kubernetes/manifests/kube-apiserver.yaml +on the master node and set the --enable-admission-plugins parameter to include +SecurityContextDeny, unless PodSecurityPolicy is already in place. +--enable-admission-plugins=...,SecurityContextDeny,... + +**Audit:** + +```bash +/bin/ps -ef | grep kube-apiserver | grep -v grep +``` + +### 1.2.14 Ensure that the admission control plugin ServiceAccount is set (Automated) + + +**Result:** pass + +**Remediation:** +Follow the documentation and create ServiceAccount objects as per your environment. +Then, edit the API server pod specification file /etc/kubernetes/manifests/kube-apiserver.yaml +on the master node and ensure that the --disable-admission-plugins parameter is set to a +value that does not include ServiceAccount. + +**Audit:** + +```bash +/bin/ps -ef | grep kube-apiserver | grep -v grep +``` + +**Expected Result**: + +```console +'--disable-admission-plugins' is not present OR '--disable-admission-plugins' is not present +``` + +**Returned Value**: + +```console +root 6465 6444 8 13:04 ? 00:01:02 kube-apiserver --requestheader-allowed-names=kube-apiserver-proxy-client --etcd-cafile=/etc/kubernetes/ssl/kube-ca.pem --service-node-port-range=30000-32767 --encryption-provider-config=/etc/kubernetes/ssl/encryption.yaml --secure-port=6443 --proxy-client-cert-file=/etc/kubernetes/ssl/kube-apiserver-proxy-client.pem --tls-cert-file=/etc/kubernetes/ssl/kube-apiserver.pem --api-audiences=unknown --storage-backend=etcd3 --tls-cipher-suites=TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384,TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305,TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384,TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305 --audit-policy-file=/etc/kubernetes/audit-policy.yaml --etcd-servers=https://:2379 --kubelet-certificate-authority=/etc/kubernetes/ssl/kube-ca.pem --service-account-signing-key-file=/etc/kubernetes/ssl/kube-service-account-token-key.pem --admission-control-config-file=/etc/kubernetes/admission.yaml --etcd-prefix=/registry --service-account-key-file=/etc/kubernetes/ssl/kube-service-account-token-key.pem --tls-private-key-file=/etc/kubernetes/ssl/kube-apiserver-key.pem --requestheader-group-headers=X-Remote-Group --requestheader-username-headers=X-Remote-User --advertise-address= --client-ca-file=/etc/kubernetes/ssl/kube-ca.pem --requestheader-client-ca-file=/etc/kubernetes/ssl/kube-apiserver-requestheader-ca.pem --requestheader-extra-headers-prefix=X-Remote-Extra- --enable-admission-plugins=NamespaceLifecycle,LimitRanger,ServiceAccount,DefaultStorageClass,DefaultTolerationSeconds,MutatingAdmissionWebhook,ValidatingAdmissionWebhook,ResourceQuota,NodeRestriction,Priority,TaintNodesByCondition,PersistentVolumeClaimResize,PodSecurityPolicy,EventRateLimit --authorization-mode=Node,RBAC --cloud-provider= --etcd-certfile=/etc/kubernetes/ssl/kube-node.pem --etcd-keyfile=/etc/kubernetes/ssl/kube-node-key.pem --service-cluster-ip-range=10.43.0.0/16 --profiling=false --service-account-issuer=rke --allow-privileged=true --insecure-port=0 --anonymous-auth=false --audit-log-path=/var/log/kube-audit/audit-log.json --kubelet-client-certificate=/etc/kubernetes/ssl/kube-apiserver.pem --kubelet-client-key=/etc/kubernetes/ssl/kube-apiserver-key.pem --proxy-client-key-file=/etc/kubernetes/ssl/kube-apiserver-proxy-client-key.pem --bind-address=0.0.0.0 --kubelet-preferred-address-types=InternalIP,ExternalIP,Hostname --audit-log-maxsize=100 --audit-log-format=json --service-account-lookup=true --runtime-config=policy/v1beta1/podsecuritypolicy=true --audit-log-maxage=30 --audit-log-maxbackup=10 +``` + +### 1.2.15 Ensure that the admission control plugin NamespaceLifecycle is set (Automated) + + +**Result:** pass + +**Remediation:** +Edit the API server pod specification file /etc/kubernetes/manifests/kube-apiserver.yaml +on the master node and set the --disable-admission-plugins parameter to +ensure it does not include NamespaceLifecycle. + +**Audit:** + +```bash +/bin/ps -ef | grep kube-apiserver | grep -v grep +``` + +**Expected Result**: + +```console +'--disable-admission-plugins' is not present OR '--disable-admission-plugins' is not present +``` + +**Returned Value**: + +```console +root 6465 6444 8 13:04 ? 00:01:02 kube-apiserver --requestheader-allowed-names=kube-apiserver-proxy-client --etcd-cafile=/etc/kubernetes/ssl/kube-ca.pem --service-node-port-range=30000-32767 --encryption-provider-config=/etc/kubernetes/ssl/encryption.yaml --secure-port=6443 --proxy-client-cert-file=/etc/kubernetes/ssl/kube-apiserver-proxy-client.pem --tls-cert-file=/etc/kubernetes/ssl/kube-apiserver.pem --api-audiences=unknown --storage-backend=etcd3 --tls-cipher-suites=TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384,TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305,TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384,TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305 --audit-policy-file=/etc/kubernetes/audit-policy.yaml --etcd-servers=https://:2379 --kubelet-certificate-authority=/etc/kubernetes/ssl/kube-ca.pem --service-account-signing-key-file=/etc/kubernetes/ssl/kube-service-account-token-key.pem --admission-control-config-file=/etc/kubernetes/admission.yaml --etcd-prefix=/registry --service-account-key-file=/etc/kubernetes/ssl/kube-service-account-token-key.pem --tls-private-key-file=/etc/kubernetes/ssl/kube-apiserver-key.pem --requestheader-group-headers=X-Remote-Group --requestheader-username-headers=X-Remote-User --advertise-address= --client-ca-file=/etc/kubernetes/ssl/kube-ca.pem --requestheader-client-ca-file=/etc/kubernetes/ssl/kube-apiserver-requestheader-ca.pem --requestheader-extra-headers-prefix=X-Remote-Extra- --enable-admission-plugins=NamespaceLifecycle,LimitRanger,ServiceAccount,DefaultStorageClass,DefaultTolerationSeconds,MutatingAdmissionWebhook,ValidatingAdmissionWebhook,ResourceQuota,NodeRestriction,Priority,TaintNodesByCondition,PersistentVolumeClaimResize,PodSecurityPolicy,EventRateLimit --authorization-mode=Node,RBAC --cloud-provider= --etcd-certfile=/etc/kubernetes/ssl/kube-node.pem --etcd-keyfile=/etc/kubernetes/ssl/kube-node-key.pem --service-cluster-ip-range=10.43.0.0/16 --profiling=false --service-account-issuer=rke --allow-privileged=true --insecure-port=0 --anonymous-auth=false --audit-log-path=/var/log/kube-audit/audit-log.json --kubelet-client-certificate=/etc/kubernetes/ssl/kube-apiserver.pem --kubelet-client-key=/etc/kubernetes/ssl/kube-apiserver-key.pem --proxy-client-key-file=/etc/kubernetes/ssl/kube-apiserver-proxy-client-key.pem --bind-address=0.0.0.0 --kubelet-preferred-address-types=InternalIP,ExternalIP,Hostname --audit-log-maxsize=100 --audit-log-format=json --service-account-lookup=true --runtime-config=policy/v1beta1/podsecuritypolicy=true --audit-log-maxage=30 --audit-log-maxbackup=10 +``` + +### 1.2.16 Ensure that the admission control plugin PodSecurityPolicy is set (Automated) + + +**Result:** pass + +**Remediation:** +Follow the documentation and create Pod Security Policy objects as per your environment. +Then, edit the API server pod specification file /etc/kubernetes/manifests/kube-apiserver.yaml +on the master node and set the --enable-admission-plugins parameter to a +value that includes PodSecurityPolicy: +--enable-admission-plugins=...,PodSecurityPolicy,... +Then restart the API Server. + +**Audit:** + +```bash +/bin/ps -ef | grep kube-apiserver | grep -v grep +``` + +**Expected Result**: + +```console +'NamespaceLifecycle,LimitRanger,ServiceAccount,DefaultStorageClass,DefaultTolerationSeconds,MutatingAdmissionWebhook,ValidatingAdmissionWebhook,ResourceQuota,NodeRestriction,Priority,TaintNodesByCondition,PersistentVolumeClaimResize,PodSecurityPolicy,EventRateLimit' has 'PodSecurityPolicy' +``` + +**Returned Value**: + +```console +root 6465 6444 8 13:04 ? 00:01:02 kube-apiserver --requestheader-allowed-names=kube-apiserver-proxy-client --etcd-cafile=/etc/kubernetes/ssl/kube-ca.pem --service-node-port-range=30000-32767 --encryption-provider-config=/etc/kubernetes/ssl/encryption.yaml --secure-port=6443 --proxy-client-cert-file=/etc/kubernetes/ssl/kube-apiserver-proxy-client.pem --tls-cert-file=/etc/kubernetes/ssl/kube-apiserver.pem --api-audiences=unknown --storage-backend=etcd3 --tls-cipher-suites=TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384,TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305,TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384,TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305 --audit-policy-file=/etc/kubernetes/audit-policy.yaml --etcd-servers=https://:2379 --kubelet-certificate-authority=/etc/kubernetes/ssl/kube-ca.pem --service-account-signing-key-file=/etc/kubernetes/ssl/kube-service-account-token-key.pem --admission-control-config-file=/etc/kubernetes/admission.yaml --etcd-prefix=/registry --service-account-key-file=/etc/kubernetes/ssl/kube-service-account-token-key.pem --tls-private-key-file=/etc/kubernetes/ssl/kube-apiserver-key.pem --requestheader-group-headers=X-Remote-Group --requestheader-username-headers=X-Remote-User --advertise-address= --client-ca-file=/etc/kubernetes/ssl/kube-ca.pem --requestheader-client-ca-file=/etc/kubernetes/ssl/kube-apiserver-requestheader-ca.pem --requestheader-extra-headers-prefix=X-Remote-Extra- --enable-admission-plugins=NamespaceLifecycle,LimitRanger,ServiceAccount,DefaultStorageClass,DefaultTolerationSeconds,MutatingAdmissionWebhook,ValidatingAdmissionWebhook,ResourceQuota,NodeRestriction,Priority,TaintNodesByCondition,PersistentVolumeClaimResize,PodSecurityPolicy,EventRateLimit --authorization-mode=Node,RBAC --cloud-provider= --etcd-certfile=/etc/kubernetes/ssl/kube-node.pem --etcd-keyfile=/etc/kubernetes/ssl/kube-node-key.pem --service-cluster-ip-range=10.43.0.0/16 --profiling=false --service-account-issuer=rke --allow-privileged=true --insecure-port=0 --anonymous-auth=false --audit-log-path=/var/log/kube-audit/audit-log.json --kubelet-client-certificate=/etc/kubernetes/ssl/kube-apiserver.pem --kubelet-client-key=/etc/kubernetes/ssl/kube-apiserver-key.pem --proxy-client-key-file=/etc/kubernetes/ssl/kube-apiserver-proxy-client-key.pem --bind-address=0.0.0.0 --kubelet-preferred-address-types=InternalIP,ExternalIP,Hostname --audit-log-maxsize=100 --audit-log-format=json --service-account-lookup=true --runtime-config=policy/v1beta1/podsecuritypolicy=true --audit-log-maxage=30 --audit-log-maxbackup=10 +``` + +### 1.2.17 Ensure that the admission control plugin NodeRestriction is set (Automated) + + +**Result:** pass + +**Remediation:** +Follow the Kubernetes documentation and configure NodeRestriction plug-in on kubelets. +Then, edit the API server pod specification file /etc/kubernetes/manifests/kube-apiserver.yaml +on the master node and set the --enable-admission-plugins parameter to a +value that includes NodeRestriction. +--enable-admission-plugins=...,NodeRestriction,... + +**Audit:** + +```bash +/bin/ps -ef | grep kube-apiserver | grep -v grep +``` + +**Expected Result**: + +```console +'NamespaceLifecycle,LimitRanger,ServiceAccount,DefaultStorageClass,DefaultTolerationSeconds,MutatingAdmissionWebhook,ValidatingAdmissionWebhook,ResourceQuota,NodeRestriction,Priority,TaintNodesByCondition,PersistentVolumeClaimResize,PodSecurityPolicy,EventRateLimit' has 'NodeRestriction' +``` + +**Returned Value**: + +```console +root 6465 6444 8 13:04 ? 00:01:02 kube-apiserver --requestheader-allowed-names=kube-apiserver-proxy-client --etcd-cafile=/etc/kubernetes/ssl/kube-ca.pem --service-node-port-range=30000-32767 --encryption-provider-config=/etc/kubernetes/ssl/encryption.yaml --secure-port=6443 --proxy-client-cert-file=/etc/kubernetes/ssl/kube-apiserver-proxy-client.pem --tls-cert-file=/etc/kubernetes/ssl/kube-apiserver.pem --api-audiences=unknown --storage-backend=etcd3 --tls-cipher-suites=TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384,TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305,TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384,TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305 --audit-policy-file=/etc/kubernetes/audit-policy.yaml --etcd-servers=https://:2379 --kubelet-certificate-authority=/etc/kubernetes/ssl/kube-ca.pem --service-account-signing-key-file=/etc/kubernetes/ssl/kube-service-account-token-key.pem --admission-control-config-file=/etc/kubernetes/admission.yaml --etcd-prefix=/registry --service-account-key-file=/etc/kubernetes/ssl/kube-service-account-token-key.pem --tls-private-key-file=/etc/kubernetes/ssl/kube-apiserver-key.pem --requestheader-group-headers=X-Remote-Group --requestheader-username-headers=X-Remote-User --advertise-address= --client-ca-file=/etc/kubernetes/ssl/kube-ca.pem --requestheader-client-ca-file=/etc/kubernetes/ssl/kube-apiserver-requestheader-ca.pem --requestheader-extra-headers-prefix=X-Remote-Extra- --enable-admission-plugins=NamespaceLifecycle,LimitRanger,ServiceAccount,DefaultStorageClass,DefaultTolerationSeconds,MutatingAdmissionWebhook,ValidatingAdmissionWebhook,ResourceQuota,NodeRestriction,Priority,TaintNodesByCondition,PersistentVolumeClaimResize,PodSecurityPolicy,EventRateLimit --authorization-mode=Node,RBAC --cloud-provider= --etcd-certfile=/etc/kubernetes/ssl/kube-node.pem --etcd-keyfile=/etc/kubernetes/ssl/kube-node-key.pem --service-cluster-ip-range=10.43.0.0/16 --profiling=false --service-account-issuer=rke --allow-privileged=true --insecure-port=0 --anonymous-auth=false --audit-log-path=/var/log/kube-audit/audit-log.json --kubelet-client-certificate=/etc/kubernetes/ssl/kube-apiserver.pem --kubelet-client-key=/etc/kubernetes/ssl/kube-apiserver-key.pem --proxy-client-key-file=/etc/kubernetes/ssl/kube-apiserver-proxy-client-key.pem --bind-address=0.0.0.0 --kubelet-preferred-address-types=InternalIP,ExternalIP,Hostname --audit-log-maxsize=100 --audit-log-format=json --service-account-lookup=true --runtime-config=policy/v1beta1/podsecuritypolicy=true --audit-log-maxage=30 --audit-log-maxbackup=10 +``` + +### 1.2.18 Ensure that the --insecure-bind-address argument is not set (Automated) + + +**Result:** pass + +**Remediation:** +Edit the API server pod specification file /etc/kubernetes/manifests/kube-apiserver.yaml +on the master node and remove the --insecure-bind-address parameter. + +**Audit:** + +```bash +/bin/ps -ef | grep kube-apiserver | grep -v grep +``` + +**Expected Result**: + +```console +'--insecure-bind-address' is not present +``` + +**Returned Value**: + +```console +root 6465 6444 8 13:04 ? 00:01:02 kube-apiserver --requestheader-allowed-names=kube-apiserver-proxy-client --etcd-cafile=/etc/kubernetes/ssl/kube-ca.pem --service-node-port-range=30000-32767 --encryption-provider-config=/etc/kubernetes/ssl/encryption.yaml --secure-port=6443 --proxy-client-cert-file=/etc/kubernetes/ssl/kube-apiserver-proxy-client.pem --tls-cert-file=/etc/kubernetes/ssl/kube-apiserver.pem --api-audiences=unknown --storage-backend=etcd3 --tls-cipher-suites=TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384,TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305,TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384,TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305 --audit-policy-file=/etc/kubernetes/audit-policy.yaml --etcd-servers=https://:2379 --kubelet-certificate-authority=/etc/kubernetes/ssl/kube-ca.pem --service-account-signing-key-file=/etc/kubernetes/ssl/kube-service-account-token-key.pem --admission-control-config-file=/etc/kubernetes/admission.yaml --etcd-prefix=/registry --service-account-key-file=/etc/kubernetes/ssl/kube-service-account-token-key.pem --tls-private-key-file=/etc/kubernetes/ssl/kube-apiserver-key.pem --requestheader-group-headers=X-Remote-Group --requestheader-username-headers=X-Remote-User --advertise-address= --client-ca-file=/etc/kubernetes/ssl/kube-ca.pem --requestheader-client-ca-file=/etc/kubernetes/ssl/kube-apiserver-requestheader-ca.pem --requestheader-extra-headers-prefix=X-Remote-Extra- --enable-admission-plugins=NamespaceLifecycle,LimitRanger,ServiceAccount,DefaultStorageClass,DefaultTolerationSeconds,MutatingAdmissionWebhook,ValidatingAdmissionWebhook,ResourceQuota,NodeRestriction,Priority,TaintNodesByCondition,PersistentVolumeClaimResize,PodSecurityPolicy,EventRateLimit --authorization-mode=Node,RBAC --cloud-provider= --etcd-certfile=/etc/kubernetes/ssl/kube-node.pem --etcd-keyfile=/etc/kubernetes/ssl/kube-node-key.pem --service-cluster-ip-range=10.43.0.0/16 --profiling=false --service-account-issuer=rke --allow-privileged=true --insecure-port=0 --anonymous-auth=false --audit-log-path=/var/log/kube-audit/audit-log.json --kubelet-client-certificate=/etc/kubernetes/ssl/kube-apiserver.pem --kubelet-client-key=/etc/kubernetes/ssl/kube-apiserver-key.pem --proxy-client-key-file=/etc/kubernetes/ssl/kube-apiserver-proxy-client-key.pem --bind-address=0.0.0.0 --kubelet-preferred-address-types=InternalIP,ExternalIP,Hostname --audit-log-maxsize=100 --audit-log-format=json --service-account-lookup=true --runtime-config=policy/v1beta1/podsecuritypolicy=true --audit-log-maxage=30 --audit-log-maxbackup=10 +``` + +### 1.2.19 Ensure that the --insecure-port argument is set to 0 (Automated) + + +**Result:** pass + +**Remediation:** +Edit the API server pod specification file /etc/kubernetes/manifests/kube-apiserver.yaml +on the master node and set the below parameter. +--insecure-port=0 + +**Audit:** + +```bash +/bin/ps -ef | grep kube-apiserver | grep -v grep +``` + +**Expected Result**: + +```console +'0' is equal to '0' +``` + +**Returned Value**: + +```console +root 6465 6444 8 13:04 ? 00:01:02 kube-apiserver --requestheader-allowed-names=kube-apiserver-proxy-client --etcd-cafile=/etc/kubernetes/ssl/kube-ca.pem --service-node-port-range=30000-32767 --encryption-provider-config=/etc/kubernetes/ssl/encryption.yaml --secure-port=6443 --proxy-client-cert-file=/etc/kubernetes/ssl/kube-apiserver-proxy-client.pem --tls-cert-file=/etc/kubernetes/ssl/kube-apiserver.pem --api-audiences=unknown --storage-backend=etcd3 --tls-cipher-suites=TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384,TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305,TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384,TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305 --audit-policy-file=/etc/kubernetes/audit-policy.yaml --etcd-servers=https://:2379 --kubelet-certificate-authority=/etc/kubernetes/ssl/kube-ca.pem --service-account-signing-key-file=/etc/kubernetes/ssl/kube-service-account-token-key.pem --admission-control-config-file=/etc/kubernetes/admission.yaml --etcd-prefix=/registry --service-account-key-file=/etc/kubernetes/ssl/kube-service-account-token-key.pem --tls-private-key-file=/etc/kubernetes/ssl/kube-apiserver-key.pem --requestheader-group-headers=X-Remote-Group --requestheader-username-headers=X-Remote-User --advertise-address= --client-ca-file=/etc/kubernetes/ssl/kube-ca.pem --requestheader-client-ca-file=/etc/kubernetes/ssl/kube-apiserver-requestheader-ca.pem --requestheader-extra-headers-prefix=X-Remote-Extra- --enable-admission-plugins=NamespaceLifecycle,LimitRanger,ServiceAccount,DefaultStorageClass,DefaultTolerationSeconds,MutatingAdmissionWebhook,ValidatingAdmissionWebhook,ResourceQuota,NodeRestriction,Priority,TaintNodesByCondition,PersistentVolumeClaimResize,PodSecurityPolicy,EventRateLimit --authorization-mode=Node,RBAC --cloud-provider= --etcd-certfile=/etc/kubernetes/ssl/kube-node.pem --etcd-keyfile=/etc/kubernetes/ssl/kube-node-key.pem --service-cluster-ip-range=10.43.0.0/16 --profiling=false --service-account-issuer=rke --allow-privileged=true --insecure-port=0 --anonymous-auth=false --audit-log-path=/var/log/kube-audit/audit-log.json --kubelet-client-certificate=/etc/kubernetes/ssl/kube-apiserver.pem --kubelet-client-key=/etc/kubernetes/ssl/kube-apiserver-key.pem --proxy-client-key-file=/etc/kubernetes/ssl/kube-apiserver-proxy-client-key.pem --bind-address=0.0.0.0 --kubelet-preferred-address-types=InternalIP,ExternalIP,Hostname --audit-log-maxsize=100 --audit-log-format=json --service-account-lookup=true --runtime-config=policy/v1beta1/podsecuritypolicy=true --audit-log-maxage=30 --audit-log-maxbackup=10 +``` + +### 1.2.20 Ensure that the --secure-port argument is not set to 0 (Automated) + + +**Result:** pass + +**Remediation:** +Edit the API server pod specification file /etc/kubernetes/manifests/kube-apiserver.yaml +on the master node and either remove the --secure-port parameter or +set it to a different (non-zero) desired port. + +**Audit:** + +```bash +/bin/ps -ef | grep kube-apiserver | grep -v grep +``` + +**Expected Result**: + +```console +6443 is greater than 0 OR '--secure-port' is not present +``` + +**Returned Value**: + +```console +root 6465 6444 8 13:04 ? 00:01:02 kube-apiserver --requestheader-allowed-names=kube-apiserver-proxy-client --etcd-cafile=/etc/kubernetes/ssl/kube-ca.pem --service-node-port-range=30000-32767 --encryption-provider-config=/etc/kubernetes/ssl/encryption.yaml --secure-port=6443 --proxy-client-cert-file=/etc/kubernetes/ssl/kube-apiserver-proxy-client.pem --tls-cert-file=/etc/kubernetes/ssl/kube-apiserver.pem --api-audiences=unknown --storage-backend=etcd3 --tls-cipher-suites=TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384,TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305,TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384,TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305 --audit-policy-file=/etc/kubernetes/audit-policy.yaml --etcd-servers=https://:2379 --kubelet-certificate-authority=/etc/kubernetes/ssl/kube-ca.pem --service-account-signing-key-file=/etc/kubernetes/ssl/kube-service-account-token-key.pem --admission-control-config-file=/etc/kubernetes/admission.yaml --etcd-prefix=/registry --service-account-key-file=/etc/kubernetes/ssl/kube-service-account-token-key.pem --tls-private-key-file=/etc/kubernetes/ssl/kube-apiserver-key.pem --requestheader-group-headers=X-Remote-Group --requestheader-username-headers=X-Remote-User --advertise-address= --client-ca-file=/etc/kubernetes/ssl/kube-ca.pem --requestheader-client-ca-file=/etc/kubernetes/ssl/kube-apiserver-requestheader-ca.pem --requestheader-extra-headers-prefix=X-Remote-Extra- --enable-admission-plugins=NamespaceLifecycle,LimitRanger,ServiceAccount,DefaultStorageClass,DefaultTolerationSeconds,MutatingAdmissionWebhook,ValidatingAdmissionWebhook,ResourceQuota,NodeRestriction,Priority,TaintNodesByCondition,PersistentVolumeClaimResize,PodSecurityPolicy,EventRateLimit --authorization-mode=Node,RBAC --cloud-provider= --etcd-certfile=/etc/kubernetes/ssl/kube-node.pem --etcd-keyfile=/etc/kubernetes/ssl/kube-node-key.pem --service-cluster-ip-range=10.43.0.0/16 --profiling=false --service-account-issuer=rke --allow-privileged=true --insecure-port=0 --anonymous-auth=false --audit-log-path=/var/log/kube-audit/audit-log.json --kubelet-client-certificate=/etc/kubernetes/ssl/kube-apiserver.pem --kubelet-client-key=/etc/kubernetes/ssl/kube-apiserver-key.pem --proxy-client-key-file=/etc/kubernetes/ssl/kube-apiserver-proxy-client-key.pem --bind-address=0.0.0.0 --kubelet-preferred-address-types=InternalIP,ExternalIP,Hostname --audit-log-maxsize=100 --audit-log-format=json --service-account-lookup=true --runtime-config=policy/v1beta1/podsecuritypolicy=true --audit-log-maxage=30 --audit-log-maxbackup=10 +``` + +### 1.2.21 Ensure that the --profiling argument is set to false (Automated) + + +**Result:** pass + +**Remediation:** +Edit the API server pod specification file /etc/kubernetes/manifests/kube-apiserver.yaml +on the master node and set the below parameter. +--profiling=false + +**Audit:** + +```bash +/bin/ps -ef | grep kube-apiserver | grep -v grep +``` + +**Expected Result**: + +```console +'false' is equal to 'false' +``` + +**Returned Value**: + +```console +root 6465 6444 8 13:04 ? 00:01:02 kube-apiserver --requestheader-allowed-names=kube-apiserver-proxy-client --etcd-cafile=/etc/kubernetes/ssl/kube-ca.pem --service-node-port-range=30000-32767 --encryption-provider-config=/etc/kubernetes/ssl/encryption.yaml --secure-port=6443 --proxy-client-cert-file=/etc/kubernetes/ssl/kube-apiserver-proxy-client.pem --tls-cert-file=/etc/kubernetes/ssl/kube-apiserver.pem --api-audiences=unknown --storage-backend=etcd3 --tls-cipher-suites=TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384,TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305,TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384,TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305 --audit-policy-file=/etc/kubernetes/audit-policy.yaml --etcd-servers=https://:2379 --kubelet-certificate-authority=/etc/kubernetes/ssl/kube-ca.pem --service-account-signing-key-file=/etc/kubernetes/ssl/kube-service-account-token-key.pem --admission-control-config-file=/etc/kubernetes/admission.yaml --etcd-prefix=/registry --service-account-key-file=/etc/kubernetes/ssl/kube-service-account-token-key.pem --tls-private-key-file=/etc/kubernetes/ssl/kube-apiserver-key.pem --requestheader-group-headers=X-Remote-Group --requestheader-username-headers=X-Remote-User --advertise-address= --client-ca-file=/etc/kubernetes/ssl/kube-ca.pem --requestheader-client-ca-file=/etc/kubernetes/ssl/kube-apiserver-requestheader-ca.pem --requestheader-extra-headers-prefix=X-Remote-Extra- --enable-admission-plugins=NamespaceLifecycle,LimitRanger,ServiceAccount,DefaultStorageClass,DefaultTolerationSeconds,MutatingAdmissionWebhook,ValidatingAdmissionWebhook,ResourceQuota,NodeRestriction,Priority,TaintNodesByCondition,PersistentVolumeClaimResize,PodSecurityPolicy,EventRateLimit --authorization-mode=Node,RBAC --cloud-provider= --etcd-certfile=/etc/kubernetes/ssl/kube-node.pem --etcd-keyfile=/etc/kubernetes/ssl/kube-node-key.pem --service-cluster-ip-range=10.43.0.0/16 --profiling=false --service-account-issuer=rke --allow-privileged=true --insecure-port=0 --anonymous-auth=false --audit-log-path=/var/log/kube-audit/audit-log.json --kubelet-client-certificate=/etc/kubernetes/ssl/kube-apiserver.pem --kubelet-client-key=/etc/kubernetes/ssl/kube-apiserver-key.pem --proxy-client-key-file=/etc/kubernetes/ssl/kube-apiserver-proxy-client-key.pem --bind-address=0.0.0.0 --kubelet-preferred-address-types=InternalIP,ExternalIP,Hostname --audit-log-maxsize=100 --audit-log-format=json --service-account-lookup=true --runtime-config=policy/v1beta1/podsecuritypolicy=true --audit-log-maxage=30 --audit-log-maxbackup=10 +``` + +### 1.2.22 Ensure that the --audit-log-path argument is set (Automated) + + +**Result:** pass + +**Remediation:** +Edit the API server pod specification file /etc/kubernetes/manifests/kube-apiserver.yaml +on the master node and set the --audit-log-path parameter to a suitable path and +file where you would like audit logs to be written, for example: +--audit-log-path=/var/log/apiserver/audit.log + +**Audit:** + +```bash +/bin/ps -ef | grep kube-apiserver | grep -v grep +``` + +**Expected Result**: + +```console +'--audit-log-path' is present +``` + +**Returned Value**: + +```console +root 6465 6444 8 13:04 ? 00:01:02 kube-apiserver --requestheader-allowed-names=kube-apiserver-proxy-client --etcd-cafile=/etc/kubernetes/ssl/kube-ca.pem --service-node-port-range=30000-32767 --encryption-provider-config=/etc/kubernetes/ssl/encryption.yaml --secure-port=6443 --proxy-client-cert-file=/etc/kubernetes/ssl/kube-apiserver-proxy-client.pem --tls-cert-file=/etc/kubernetes/ssl/kube-apiserver.pem --api-audiences=unknown --storage-backend=etcd3 --tls-cipher-suites=TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384,TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305,TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384,TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305 --audit-policy-file=/etc/kubernetes/audit-policy.yaml --etcd-servers=https://:2379 --kubelet-certificate-authority=/etc/kubernetes/ssl/kube-ca.pem --service-account-signing-key-file=/etc/kubernetes/ssl/kube-service-account-token-key.pem --admission-control-config-file=/etc/kubernetes/admission.yaml --etcd-prefix=/registry --service-account-key-file=/etc/kubernetes/ssl/kube-service-account-token-key.pem --tls-private-key-file=/etc/kubernetes/ssl/kube-apiserver-key.pem --requestheader-group-headers=X-Remote-Group --requestheader-username-headers=X-Remote-User --advertise-address= --client-ca-file=/etc/kubernetes/ssl/kube-ca.pem --requestheader-client-ca-file=/etc/kubernetes/ssl/kube-apiserver-requestheader-ca.pem --requestheader-extra-headers-prefix=X-Remote-Extra- --enable-admission-plugins=NamespaceLifecycle,LimitRanger,ServiceAccount,DefaultStorageClass,DefaultTolerationSeconds,MutatingAdmissionWebhook,ValidatingAdmissionWebhook,ResourceQuota,NodeRestriction,Priority,TaintNodesByCondition,PersistentVolumeClaimResize,PodSecurityPolicy,EventRateLimit --authorization-mode=Node,RBAC --cloud-provider= --etcd-certfile=/etc/kubernetes/ssl/kube-node.pem --etcd-keyfile=/etc/kubernetes/ssl/kube-node-key.pem --service-cluster-ip-range=10.43.0.0/16 --profiling=false --service-account-issuer=rke --allow-privileged=true --insecure-port=0 --anonymous-auth=false --audit-log-path=/var/log/kube-audit/audit-log.json --kubelet-client-certificate=/etc/kubernetes/ssl/kube-apiserver.pem --kubelet-client-key=/etc/kubernetes/ssl/kube-apiserver-key.pem --proxy-client-key-file=/etc/kubernetes/ssl/kube-apiserver-proxy-client-key.pem --bind-address=0.0.0.0 --kubelet-preferred-address-types=InternalIP,ExternalIP,Hostname --audit-log-maxsize=100 --audit-log-format=json --service-account-lookup=true --runtime-config=policy/v1beta1/podsecuritypolicy=true --audit-log-maxage=30 --audit-log-maxbackup=10 +``` + +### 1.2.23 Ensure that the --audit-log-maxage argument is set to 30 or as appropriate (Automated) + + +**Result:** pass + +**Remediation:** +Edit the API server pod specification file /etc/kubernetes/manifests/kube-apiserver.yaml +on the master node and set the --audit-log-maxage parameter to 30 or as an appropriate number of days: +--audit-log-maxage=30 + +**Audit:** + +```bash +/bin/ps -ef | grep kube-apiserver | grep -v grep +``` + +**Expected Result**: + +```console +30 is greater or equal to 30 +``` + +**Returned Value**: + +```console +root 6465 6444 8 13:04 ? 00:01:02 kube-apiserver --requestheader-allowed-names=kube-apiserver-proxy-client --etcd-cafile=/etc/kubernetes/ssl/kube-ca.pem --service-node-port-range=30000-32767 --encryption-provider-config=/etc/kubernetes/ssl/encryption.yaml --secure-port=6443 --proxy-client-cert-file=/etc/kubernetes/ssl/kube-apiserver-proxy-client.pem --tls-cert-file=/etc/kubernetes/ssl/kube-apiserver.pem --api-audiences=unknown --storage-backend=etcd3 --tls-cipher-suites=TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384,TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305,TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384,TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305 --audit-policy-file=/etc/kubernetes/audit-policy.yaml --etcd-servers=https://:2379 --kubelet-certificate-authority=/etc/kubernetes/ssl/kube-ca.pem --service-account-signing-key-file=/etc/kubernetes/ssl/kube-service-account-token-key.pem --admission-control-config-file=/etc/kubernetes/admission.yaml --etcd-prefix=/registry --service-account-key-file=/etc/kubernetes/ssl/kube-service-account-token-key.pem --tls-private-key-file=/etc/kubernetes/ssl/kube-apiserver-key.pem --requestheader-group-headers=X-Remote-Group --requestheader-username-headers=X-Remote-User --advertise-address= --client-ca-file=/etc/kubernetes/ssl/kube-ca.pem --requestheader-client-ca-file=/etc/kubernetes/ssl/kube-apiserver-requestheader-ca.pem --requestheader-extra-headers-prefix=X-Remote-Extra- --enable-admission-plugins=NamespaceLifecycle,LimitRanger,ServiceAccount,DefaultStorageClass,DefaultTolerationSeconds,MutatingAdmissionWebhook,ValidatingAdmissionWebhook,ResourceQuota,NodeRestriction,Priority,TaintNodesByCondition,PersistentVolumeClaimResize,PodSecurityPolicy,EventRateLimit --authorization-mode=Node,RBAC --cloud-provider= --etcd-certfile=/etc/kubernetes/ssl/kube-node.pem --etcd-keyfile=/etc/kubernetes/ssl/kube-node-key.pem --service-cluster-ip-range=10.43.0.0/16 --profiling=false --service-account-issuer=rke --allow-privileged=true --insecure-port=0 --anonymous-auth=false --audit-log-path=/var/log/kube-audit/audit-log.json --kubelet-client-certificate=/etc/kubernetes/ssl/kube-apiserver.pem --kubelet-client-key=/etc/kubernetes/ssl/kube-apiserver-key.pem --proxy-client-key-file=/etc/kubernetes/ssl/kube-apiserver-proxy-client-key.pem --bind-address=0.0.0.0 --kubelet-preferred-address-types=InternalIP,ExternalIP,Hostname --audit-log-maxsize=100 --audit-log-format=json --service-account-lookup=true --runtime-config=policy/v1beta1/podsecuritypolicy=true --audit-log-maxage=30 --audit-log-maxbackup=10 +``` + +### 1.2.24 Ensure that the --audit-log-maxbackup argument is set to 10 or as appropriate (Automated) + + +**Result:** pass + +**Remediation:** +Edit the API server pod specification file /etc/kubernetes/manifests/kube-apiserver.yaml +on the master node and set the --audit-log-maxbackup parameter to 10 or to an appropriate +value. +--audit-log-maxbackup=10 + +**Audit:** + +```bash +/bin/ps -ef | grep kube-apiserver | grep -v grep +``` + +**Expected Result**: + +```console +10 is greater or equal to 10 +``` + +**Returned Value**: + +```console +root 6465 6444 8 13:04 ? 00:01:02 kube-apiserver --requestheader-allowed-names=kube-apiserver-proxy-client --etcd-cafile=/etc/kubernetes/ssl/kube-ca.pem --service-node-port-range=30000-32767 --encryption-provider-config=/etc/kubernetes/ssl/encryption.yaml --secure-port=6443 --proxy-client-cert-file=/etc/kubernetes/ssl/kube-apiserver-proxy-client.pem --tls-cert-file=/etc/kubernetes/ssl/kube-apiserver.pem --api-audiences=unknown --storage-backend=etcd3 --tls-cipher-suites=TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384,TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305,TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384,TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305 --audit-policy-file=/etc/kubernetes/audit-policy.yaml --etcd-servers=https://:2379 --kubelet-certificate-authority=/etc/kubernetes/ssl/kube-ca.pem --service-account-signing-key-file=/etc/kubernetes/ssl/kube-service-account-token-key.pem --admission-control-config-file=/etc/kubernetes/admission.yaml --etcd-prefix=/registry --service-account-key-file=/etc/kubernetes/ssl/kube-service-account-token-key.pem --tls-private-key-file=/etc/kubernetes/ssl/kube-apiserver-key.pem --requestheader-group-headers=X-Remote-Group --requestheader-username-headers=X-Remote-User --advertise-address= --client-ca-file=/etc/kubernetes/ssl/kube-ca.pem --requestheader-client-ca-file=/etc/kubernetes/ssl/kube-apiserver-requestheader-ca.pem --requestheader-extra-headers-prefix=X-Remote-Extra- --enable-admission-plugins=NamespaceLifecycle,LimitRanger,ServiceAccount,DefaultStorageClass,DefaultTolerationSeconds,MutatingAdmissionWebhook,ValidatingAdmissionWebhook,ResourceQuota,NodeRestriction,Priority,TaintNodesByCondition,PersistentVolumeClaimResize,PodSecurityPolicy,EventRateLimit --authorization-mode=Node,RBAC --cloud-provider= --etcd-certfile=/etc/kubernetes/ssl/kube-node.pem --etcd-keyfile=/etc/kubernetes/ssl/kube-node-key.pem --service-cluster-ip-range=10.43.0.0/16 --profiling=false --service-account-issuer=rke --allow-privileged=true --insecure-port=0 --anonymous-auth=false --audit-log-path=/var/log/kube-audit/audit-log.json --kubelet-client-certificate=/etc/kubernetes/ssl/kube-apiserver.pem --kubelet-client-key=/etc/kubernetes/ssl/kube-apiserver-key.pem --proxy-client-key-file=/etc/kubernetes/ssl/kube-apiserver-proxy-client-key.pem --bind-address=0.0.0.0 --kubelet-preferred-address-types=InternalIP,ExternalIP,Hostname --audit-log-maxsize=100 --audit-log-format=json --service-account-lookup=true --runtime-config=policy/v1beta1/podsecuritypolicy=true --audit-log-maxage=30 --audit-log-maxbackup=10 +``` + +### 1.2.25 Ensure that the --audit-log-maxsize argument is set to 100 or as appropriate (Automated) + + +**Result:** pass + +**Remediation:** +Edit the API server pod specification file /etc/kubernetes/manifests/kube-apiserver.yaml +on the master node and set the --audit-log-maxsize parameter to an appropriate size in MB. +For example, to set it as 100 MB: +--audit-log-maxsize=100 + +**Audit:** + +```bash +/bin/ps -ef | grep kube-apiserver | grep -v grep +``` + +**Expected Result**: + +```console +100 is greater or equal to 100 +``` + +**Returned Value**: + +```console +root 6465 6444 8 13:04 ? 00:01:02 kube-apiserver --requestheader-allowed-names=kube-apiserver-proxy-client --etcd-cafile=/etc/kubernetes/ssl/kube-ca.pem --service-node-port-range=30000-32767 --encryption-provider-config=/etc/kubernetes/ssl/encryption.yaml --secure-port=6443 --proxy-client-cert-file=/etc/kubernetes/ssl/kube-apiserver-proxy-client.pem --tls-cert-file=/etc/kubernetes/ssl/kube-apiserver.pem --api-audiences=unknown --storage-backend=etcd3 --tls-cipher-suites=TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384,TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305,TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384,TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305 --audit-policy-file=/etc/kubernetes/audit-policy.yaml --etcd-servers=https://:2379 --kubelet-certificate-authority=/etc/kubernetes/ssl/kube-ca.pem --service-account-signing-key-file=/etc/kubernetes/ssl/kube-service-account-token-key.pem --admission-control-config-file=/etc/kubernetes/admission.yaml --etcd-prefix=/registry --service-account-key-file=/etc/kubernetes/ssl/kube-service-account-token-key.pem --tls-private-key-file=/etc/kubernetes/ssl/kube-apiserver-key.pem --requestheader-group-headers=X-Remote-Group --requestheader-username-headers=X-Remote-User --advertise-address= --client-ca-file=/etc/kubernetes/ssl/kube-ca.pem --requestheader-client-ca-file=/etc/kubernetes/ssl/kube-apiserver-requestheader-ca.pem --requestheader-extra-headers-prefix=X-Remote-Extra- --enable-admission-plugins=NamespaceLifecycle,LimitRanger,ServiceAccount,DefaultStorageClass,DefaultTolerationSeconds,MutatingAdmissionWebhook,ValidatingAdmissionWebhook,ResourceQuota,NodeRestriction,Priority,TaintNodesByCondition,PersistentVolumeClaimResize,PodSecurityPolicy,EventRateLimit --authorization-mode=Node,RBAC --cloud-provider= --etcd-certfile=/etc/kubernetes/ssl/kube-node.pem --etcd-keyfile=/etc/kubernetes/ssl/kube-node-key.pem --service-cluster-ip-range=10.43.0.0/16 --profiling=false --service-account-issuer=rke --allow-privileged=true --insecure-port=0 --anonymous-auth=false --audit-log-path=/var/log/kube-audit/audit-log.json --kubelet-client-certificate=/etc/kubernetes/ssl/kube-apiserver.pem --kubelet-client-key=/etc/kubernetes/ssl/kube-apiserver-key.pem --proxy-client-key-file=/etc/kubernetes/ssl/kube-apiserver-proxy-client-key.pem --bind-address=0.0.0.0 --kubelet-preferred-address-types=InternalIP,ExternalIP,Hostname --audit-log-maxsize=100 --audit-log-format=json --service-account-lookup=true --runtime-config=policy/v1beta1/podsecuritypolicy=true --audit-log-maxage=30 --audit-log-maxbackup=10 +``` + +### 1.2.26 Ensure that the --request-timeout argument is set as appropriate (Automated) + + +**Result:** pass + +**Remediation:** +Edit the API server pod specification file /etc/kubernetes/manifests/kube-apiserver.yaml +and set the below parameter as appropriate and if needed. +For example, +--request-timeout=300s + +**Audit:** + +```bash +/bin/ps -ef | grep kube-apiserver | grep -v grep +``` + +**Expected Result**: + +```console +'--request-timeout' is not present OR '--request-timeout' is not present +``` + +**Returned Value**: + +```console +root 6465 6444 8 13:04 ? 00:01:02 kube-apiserver --requestheader-allowed-names=kube-apiserver-proxy-client --etcd-cafile=/etc/kubernetes/ssl/kube-ca.pem --service-node-port-range=30000-32767 --encryption-provider-config=/etc/kubernetes/ssl/encryption.yaml --secure-port=6443 --proxy-client-cert-file=/etc/kubernetes/ssl/kube-apiserver-proxy-client.pem --tls-cert-file=/etc/kubernetes/ssl/kube-apiserver.pem --api-audiences=unknown --storage-backend=etcd3 --tls-cipher-suites=TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384,TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305,TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384,TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305 --audit-policy-file=/etc/kubernetes/audit-policy.yaml --etcd-servers=https://:2379 --kubelet-certificate-authority=/etc/kubernetes/ssl/kube-ca.pem --service-account-signing-key-file=/etc/kubernetes/ssl/kube-service-account-token-key.pem --admission-control-config-file=/etc/kubernetes/admission.yaml --etcd-prefix=/registry --service-account-key-file=/etc/kubernetes/ssl/kube-service-account-token-key.pem --tls-private-key-file=/etc/kubernetes/ssl/kube-apiserver-key.pem --requestheader-group-headers=X-Remote-Group --requestheader-username-headers=X-Remote-User --advertise-address= --client-ca-file=/etc/kubernetes/ssl/kube-ca.pem --requestheader-client-ca-file=/etc/kubernetes/ssl/kube-apiserver-requestheader-ca.pem --requestheader-extra-headers-prefix=X-Remote-Extra- --enable-admission-plugins=NamespaceLifecycle,LimitRanger,ServiceAccount,DefaultStorageClass,DefaultTolerationSeconds,MutatingAdmissionWebhook,ValidatingAdmissionWebhook,ResourceQuota,NodeRestriction,Priority,TaintNodesByCondition,PersistentVolumeClaimResize,PodSecurityPolicy,EventRateLimit --authorization-mode=Node,RBAC --cloud-provider= --etcd-certfile=/etc/kubernetes/ssl/kube-node.pem --etcd-keyfile=/etc/kubernetes/ssl/kube-node-key.pem --service-cluster-ip-range=10.43.0.0/16 --profiling=false --service-account-issuer=rke --allow-privileged=true --insecure-port=0 --anonymous-auth=false --audit-log-path=/var/log/kube-audit/audit-log.json --kubelet-client-certificate=/etc/kubernetes/ssl/kube-apiserver.pem --kubelet-client-key=/etc/kubernetes/ssl/kube-apiserver-key.pem --proxy-client-key-file=/etc/kubernetes/ssl/kube-apiserver-proxy-client-key.pem --bind-address=0.0.0.0 --kubelet-preferred-address-types=InternalIP,ExternalIP,Hostname --audit-log-maxsize=100 --audit-log-format=json --service-account-lookup=true --runtime-config=policy/v1beta1/podsecuritypolicy=true --audit-log-maxage=30 --audit-log-maxbackup=10 +``` + +### 1.2.27 Ensure that the --service-account-lookup argument is set to true (Automated) + + +**Result:** pass + +**Remediation:** +Edit the API server pod specification file /etc/kubernetes/manifests/kube-apiserver.yaml +on the master node and set the below parameter. +--service-account-lookup=true +Alternatively, you can delete the --service-account-lookup parameter from this file so +that the default takes effect. + +**Audit:** + +```bash +/bin/ps -ef | grep kube-apiserver | grep -v grep +``` + +**Expected Result**: + +```console +'--service-account-lookup' is not present OR 'true' is equal to 'true' +``` + +**Returned Value**: + +```console +root 6465 6444 8 13:04 ? 00:01:02 kube-apiserver --requestheader-allowed-names=kube-apiserver-proxy-client --etcd-cafile=/etc/kubernetes/ssl/kube-ca.pem --service-node-port-range=30000-32767 --encryption-provider-config=/etc/kubernetes/ssl/encryption.yaml --secure-port=6443 --proxy-client-cert-file=/etc/kubernetes/ssl/kube-apiserver-proxy-client.pem --tls-cert-file=/etc/kubernetes/ssl/kube-apiserver.pem --api-audiences=unknown --storage-backend=etcd3 --tls-cipher-suites=TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384,TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305,TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384,TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305 --audit-policy-file=/etc/kubernetes/audit-policy.yaml --etcd-servers=https://:2379 --kubelet-certificate-authority=/etc/kubernetes/ssl/kube-ca.pem --service-account-signing-key-file=/etc/kubernetes/ssl/kube-service-account-token-key.pem --admission-control-config-file=/etc/kubernetes/admission.yaml --etcd-prefix=/registry --service-account-key-file=/etc/kubernetes/ssl/kube-service-account-token-key.pem --tls-private-key-file=/etc/kubernetes/ssl/kube-apiserver-key.pem --requestheader-group-headers=X-Remote-Group --requestheader-username-headers=X-Remote-User --advertise-address= --client-ca-file=/etc/kubernetes/ssl/kube-ca.pem --requestheader-client-ca-file=/etc/kubernetes/ssl/kube-apiserver-requestheader-ca.pem --requestheader-extra-headers-prefix=X-Remote-Extra- --enable-admission-plugins=NamespaceLifecycle,LimitRanger,ServiceAccount,DefaultStorageClass,DefaultTolerationSeconds,MutatingAdmissionWebhook,ValidatingAdmissionWebhook,ResourceQuota,NodeRestriction,Priority,TaintNodesByCondition,PersistentVolumeClaimResize,PodSecurityPolicy,EventRateLimit --authorization-mode=Node,RBAC --cloud-provider= --etcd-certfile=/etc/kubernetes/ssl/kube-node.pem --etcd-keyfile=/etc/kubernetes/ssl/kube-node-key.pem --service-cluster-ip-range=10.43.0.0/16 --profiling=false --service-account-issuer=rke --allow-privileged=true --insecure-port=0 --anonymous-auth=false --audit-log-path=/var/log/kube-audit/audit-log.json --kubelet-client-certificate=/etc/kubernetes/ssl/kube-apiserver.pem --kubelet-client-key=/etc/kubernetes/ssl/kube-apiserver-key.pem --proxy-client-key-file=/etc/kubernetes/ssl/kube-apiserver-proxy-client-key.pem --bind-address=0.0.0.0 --kubelet-preferred-address-types=InternalIP,ExternalIP,Hostname --audit-log-maxsize=100 --audit-log-format=json --service-account-lookup=true --runtime-config=policy/v1beta1/podsecuritypolicy=true --audit-log-maxage=30 --audit-log-maxbackup=10 +``` + +### 1.2.28 Ensure that the --service-account-key-file argument is set as appropriate (Automated) + + +**Result:** pass + +**Remediation:** +Edit the API server pod specification file /etc/kubernetes/manifests/kube-apiserver.yaml +on the master node and set the --service-account-key-file parameter +to the public key file for service accounts: +--service-account-key-file= + +**Audit:** + +```bash +/bin/ps -ef | grep kube-apiserver | grep -v grep +``` + +**Expected Result**: + +```console +'--service-account-key-file' is present +``` + +**Returned Value**: + +```console +root 6465 6444 8 13:04 ? 00:01:02 kube-apiserver --requestheader-allowed-names=kube-apiserver-proxy-client --etcd-cafile=/etc/kubernetes/ssl/kube-ca.pem --service-node-port-range=30000-32767 --encryption-provider-config=/etc/kubernetes/ssl/encryption.yaml --secure-port=6443 --proxy-client-cert-file=/etc/kubernetes/ssl/kube-apiserver-proxy-client.pem --tls-cert-file=/etc/kubernetes/ssl/kube-apiserver.pem --api-audiences=unknown --storage-backend=etcd3 --tls-cipher-suites=TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384,TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305,TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384,TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305 --audit-policy-file=/etc/kubernetes/audit-policy.yaml --etcd-servers=https://:2379 --kubelet-certificate-authority=/etc/kubernetes/ssl/kube-ca.pem --service-account-signing-key-file=/etc/kubernetes/ssl/kube-service-account-token-key.pem --admission-control-config-file=/etc/kubernetes/admission.yaml --etcd-prefix=/registry --service-account-key-file=/etc/kubernetes/ssl/kube-service-account-token-key.pem --tls-private-key-file=/etc/kubernetes/ssl/kube-apiserver-key.pem --requestheader-group-headers=X-Remote-Group --requestheader-username-headers=X-Remote-User --advertise-address= --client-ca-file=/etc/kubernetes/ssl/kube-ca.pem --requestheader-client-ca-file=/etc/kubernetes/ssl/kube-apiserver-requestheader-ca.pem --requestheader-extra-headers-prefix=X-Remote-Extra- --enable-admission-plugins=NamespaceLifecycle,LimitRanger,ServiceAccount,DefaultStorageClass,DefaultTolerationSeconds,MutatingAdmissionWebhook,ValidatingAdmissionWebhook,ResourceQuota,NodeRestriction,Priority,TaintNodesByCondition,PersistentVolumeClaimResize,PodSecurityPolicy,EventRateLimit --authorization-mode=Node,RBAC --cloud-provider= --etcd-certfile=/etc/kubernetes/ssl/kube-node.pem --etcd-keyfile=/etc/kubernetes/ssl/kube-node-key.pem --service-cluster-ip-range=10.43.0.0/16 --profiling=false --service-account-issuer=rke --allow-privileged=true --insecure-port=0 --anonymous-auth=false --audit-log-path=/var/log/kube-audit/audit-log.json --kubelet-client-certificate=/etc/kubernetes/ssl/kube-apiserver.pem --kubelet-client-key=/etc/kubernetes/ssl/kube-apiserver-key.pem --proxy-client-key-file=/etc/kubernetes/ssl/kube-apiserver-proxy-client-key.pem --bind-address=0.0.0.0 --kubelet-preferred-address-types=InternalIP,ExternalIP,Hostname --audit-log-maxsize=100 --audit-log-format=json --service-account-lookup=true --runtime-config=policy/v1beta1/podsecuritypolicy=true --audit-log-maxage=30 --audit-log-maxbackup=10 +``` + +### 1.2.29 Ensure that the --etcd-certfile and --etcd-keyfile arguments are set as appropriate (Automated) + + +**Result:** pass + +**Remediation:** +Follow the Kubernetes documentation and set up the TLS connection between the apiserver and etcd. +Then, edit the API server pod specification file /etc/kubernetes/manifests/kube-apiserver.yaml +on the master node and set the etcd certificate and key file parameters. +--etcd-certfile= +--etcd-keyfile= + +**Audit:** + +```bash +/bin/ps -ef | grep kube-apiserver | grep -v grep +``` + +**Expected Result**: + +```console +'--etcd-certfile' is present AND '--etcd-keyfile' is present +``` + +**Returned Value**: + +```console +root 6465 6444 8 13:04 ? 00:01:02 kube-apiserver --requestheader-allowed-names=kube-apiserver-proxy-client --etcd-cafile=/etc/kubernetes/ssl/kube-ca.pem --service-node-port-range=30000-32767 --encryption-provider-config=/etc/kubernetes/ssl/encryption.yaml --secure-port=6443 --proxy-client-cert-file=/etc/kubernetes/ssl/kube-apiserver-proxy-client.pem --tls-cert-file=/etc/kubernetes/ssl/kube-apiserver.pem --api-audiences=unknown --storage-backend=etcd3 --tls-cipher-suites=TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384,TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305,TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384,TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305 --audit-policy-file=/etc/kubernetes/audit-policy.yaml --etcd-servers=https://:2379 --kubelet-certificate-authority=/etc/kubernetes/ssl/kube-ca.pem --service-account-signing-key-file=/etc/kubernetes/ssl/kube-service-account-token-key.pem --admission-control-config-file=/etc/kubernetes/admission.yaml --etcd-prefix=/registry --service-account-key-file=/etc/kubernetes/ssl/kube-service-account-token-key.pem --tls-private-key-file=/etc/kubernetes/ssl/kube-apiserver-key.pem --requestheader-group-headers=X-Remote-Group --requestheader-username-headers=X-Remote-User --advertise-address= --client-ca-file=/etc/kubernetes/ssl/kube-ca.pem --requestheader-client-ca-file=/etc/kubernetes/ssl/kube-apiserver-requestheader-ca.pem --requestheader-extra-headers-prefix=X-Remote-Extra- --enable-admission-plugins=NamespaceLifecycle,LimitRanger,ServiceAccount,DefaultStorageClass,DefaultTolerationSeconds,MutatingAdmissionWebhook,ValidatingAdmissionWebhook,ResourceQuota,NodeRestriction,Priority,TaintNodesByCondition,PersistentVolumeClaimResize,PodSecurityPolicy,EventRateLimit --authorization-mode=Node,RBAC --cloud-provider= --etcd-certfile=/etc/kubernetes/ssl/kube-node.pem --etcd-keyfile=/etc/kubernetes/ssl/kube-node-key.pem --service-cluster-ip-range=10.43.0.0/16 --profiling=false --service-account-issuer=rke --allow-privileged=true --insecure-port=0 --anonymous-auth=false --audit-log-path=/var/log/kube-audit/audit-log.json --kubelet-client-certificate=/etc/kubernetes/ssl/kube-apiserver.pem --kubelet-client-key=/etc/kubernetes/ssl/kube-apiserver-key.pem --proxy-client-key-file=/etc/kubernetes/ssl/kube-apiserver-proxy-client-key.pem --bind-address=0.0.0.0 --kubelet-preferred-address-types=InternalIP,ExternalIP,Hostname --audit-log-maxsize=100 --audit-log-format=json --service-account-lookup=true --runtime-config=policy/v1beta1/podsecuritypolicy=true --audit-log-maxage=30 --audit-log-maxbackup=10 +``` + +### 1.2.30 Ensure that the --tls-cert-file and --tls-private-key-file arguments are set as appropriate (Automated) + + +**Result:** pass + +**Remediation:** +Follow the Kubernetes documentation and set up the TLS connection on the apiserver. +Then, edit the API server pod specification file /etc/kubernetes/manifests/kube-apiserver.yaml +on the master node and set the TLS certificate and private key file parameters. +--tls-cert-file= +--tls-private-key-file= + +**Audit:** + +```bash +/bin/ps -ef | grep kube-apiserver | grep -v grep +``` + +**Expected Result**: + +```console +'--tls-cert-file' is present AND '--tls-private-key-file' is present +``` + +**Returned Value**: + +```console +root 6465 6444 8 13:04 ? 00:01:02 kube-apiserver --requestheader-allowed-names=kube-apiserver-proxy-client --etcd-cafile=/etc/kubernetes/ssl/kube-ca.pem --service-node-port-range=30000-32767 --encryption-provider-config=/etc/kubernetes/ssl/encryption.yaml --secure-port=6443 --proxy-client-cert-file=/etc/kubernetes/ssl/kube-apiserver-proxy-client.pem --tls-cert-file=/etc/kubernetes/ssl/kube-apiserver.pem --api-audiences=unknown --storage-backend=etcd3 --tls-cipher-suites=TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384,TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305,TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384,TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305 --audit-policy-file=/etc/kubernetes/audit-policy.yaml --etcd-servers=https://:2379 --kubelet-certificate-authority=/etc/kubernetes/ssl/kube-ca.pem --service-account-signing-key-file=/etc/kubernetes/ssl/kube-service-account-token-key.pem --admission-control-config-file=/etc/kubernetes/admission.yaml --etcd-prefix=/registry --service-account-key-file=/etc/kubernetes/ssl/kube-service-account-token-key.pem --tls-private-key-file=/etc/kubernetes/ssl/kube-apiserver-key.pem --requestheader-group-headers=X-Remote-Group --requestheader-username-headers=X-Remote-User --advertise-address= --client-ca-file=/etc/kubernetes/ssl/kube-ca.pem --requestheader-client-ca-file=/etc/kubernetes/ssl/kube-apiserver-requestheader-ca.pem --requestheader-extra-headers-prefix=X-Remote-Extra- --enable-admission-plugins=NamespaceLifecycle,LimitRanger,ServiceAccount,DefaultStorageClass,DefaultTolerationSeconds,MutatingAdmissionWebhook,ValidatingAdmissionWebhook,ResourceQuota,NodeRestriction,Priority,TaintNodesByCondition,PersistentVolumeClaimResize,PodSecurityPolicy,EventRateLimit --authorization-mode=Node,RBAC --cloud-provider= --etcd-certfile=/etc/kubernetes/ssl/kube-node.pem --etcd-keyfile=/etc/kubernetes/ssl/kube-node-key.pem --service-cluster-ip-range=10.43.0.0/16 --profiling=false --service-account-issuer=rke --allow-privileged=true --insecure-port=0 --anonymous-auth=false --audit-log-path=/var/log/kube-audit/audit-log.json --kubelet-client-certificate=/etc/kubernetes/ssl/kube-apiserver.pem --kubelet-client-key=/etc/kubernetes/ssl/kube-apiserver-key.pem --proxy-client-key-file=/etc/kubernetes/ssl/kube-apiserver-proxy-client-key.pem --bind-address=0.0.0.0 --kubelet-preferred-address-types=InternalIP,ExternalIP,Hostname --audit-log-maxsize=100 --audit-log-format=json --service-account-lookup=true --runtime-config=policy/v1beta1/podsecuritypolicy=true --audit-log-maxage=30 --audit-log-maxbackup=10 +``` + +### 1.2.31 Ensure that the --client-ca-file argument is set as appropriate (Automated) + + +**Result:** pass + +**Remediation:** +Follow the Kubernetes documentation and set up the TLS connection on the apiserver. +Then, edit the API server pod specification file /etc/kubernetes/manifests/kube-apiserver.yaml +on the master node and set the client certificate authority file. +--client-ca-file= + +**Audit:** + +```bash +/bin/ps -ef | grep kube-apiserver | grep -v grep +``` + +**Expected Result**: + +```console +'--client-ca-file' is present +``` + +**Returned Value**: + +```console +root 6465 6444 8 13:04 ? 00:01:02 kube-apiserver --requestheader-allowed-names=kube-apiserver-proxy-client --etcd-cafile=/etc/kubernetes/ssl/kube-ca.pem --service-node-port-range=30000-32767 --encryption-provider-config=/etc/kubernetes/ssl/encryption.yaml --secure-port=6443 --proxy-client-cert-file=/etc/kubernetes/ssl/kube-apiserver-proxy-client.pem --tls-cert-file=/etc/kubernetes/ssl/kube-apiserver.pem --api-audiences=unknown --storage-backend=etcd3 --tls-cipher-suites=TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384,TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305,TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384,TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305 --audit-policy-file=/etc/kubernetes/audit-policy.yaml --etcd-servers=https://:2379 --kubelet-certificate-authority=/etc/kubernetes/ssl/kube-ca.pem --service-account-signing-key-file=/etc/kubernetes/ssl/kube-service-account-token-key.pem --admission-control-config-file=/etc/kubernetes/admission.yaml --etcd-prefix=/registry --service-account-key-file=/etc/kubernetes/ssl/kube-service-account-token-key.pem --tls-private-key-file=/etc/kubernetes/ssl/kube-apiserver-key.pem --requestheader-group-headers=X-Remote-Group --requestheader-username-headers=X-Remote-User --advertise-address= --client-ca-file=/etc/kubernetes/ssl/kube-ca.pem --requestheader-client-ca-file=/etc/kubernetes/ssl/kube-apiserver-requestheader-ca.pem --requestheader-extra-headers-prefix=X-Remote-Extra- --enable-admission-plugins=NamespaceLifecycle,LimitRanger,ServiceAccount,DefaultStorageClass,DefaultTolerationSeconds,MutatingAdmissionWebhook,ValidatingAdmissionWebhook,ResourceQuota,NodeRestriction,Priority,TaintNodesByCondition,PersistentVolumeClaimResize,PodSecurityPolicy,EventRateLimit --authorization-mode=Node,RBAC --cloud-provider= --etcd-certfile=/etc/kubernetes/ssl/kube-node.pem --etcd-keyfile=/etc/kubernetes/ssl/kube-node-key.pem --service-cluster-ip-range=10.43.0.0/16 --profiling=false --service-account-issuer=rke --allow-privileged=true --insecure-port=0 --anonymous-auth=false --audit-log-path=/var/log/kube-audit/audit-log.json --kubelet-client-certificate=/etc/kubernetes/ssl/kube-apiserver.pem --kubelet-client-key=/etc/kubernetes/ssl/kube-apiserver-key.pem --proxy-client-key-file=/etc/kubernetes/ssl/kube-apiserver-proxy-client-key.pem --bind-address=0.0.0.0 --kubelet-preferred-address-types=InternalIP,ExternalIP,Hostname --audit-log-maxsize=100 --audit-log-format=json --service-account-lookup=true --runtime-config=policy/v1beta1/podsecuritypolicy=true --audit-log-maxage=30 --audit-log-maxbackup=10 +``` + +### 1.2.32 Ensure that the --etcd-cafile argument is set as appropriate (Automated) + + +**Result:** pass + +**Remediation:** +Follow the Kubernetes documentation and set up the TLS connection between the apiserver and etcd. +Then, edit the API server pod specification file /etc/kubernetes/manifests/kube-apiserver.yaml +on the master node and set the etcd certificate authority file parameter. +--etcd-cafile= + +**Audit:** + +```bash +/bin/ps -ef | grep kube-apiserver | grep -v grep +``` + +**Expected Result**: + +```console +'--etcd-cafile' is present +``` + +**Returned Value**: + +```console +root 6465 6444 8 13:04 ? 00:01:02 kube-apiserver --requestheader-allowed-names=kube-apiserver-proxy-client --etcd-cafile=/etc/kubernetes/ssl/kube-ca.pem --service-node-port-range=30000-32767 --encryption-provider-config=/etc/kubernetes/ssl/encryption.yaml --secure-port=6443 --proxy-client-cert-file=/etc/kubernetes/ssl/kube-apiserver-proxy-client.pem --tls-cert-file=/etc/kubernetes/ssl/kube-apiserver.pem --api-audiences=unknown --storage-backend=etcd3 --tls-cipher-suites=TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384,TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305,TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384,TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305 --audit-policy-file=/etc/kubernetes/audit-policy.yaml --etcd-servers=https://:2379 --kubelet-certificate-authority=/etc/kubernetes/ssl/kube-ca.pem --service-account-signing-key-file=/etc/kubernetes/ssl/kube-service-account-token-key.pem --admission-control-config-file=/etc/kubernetes/admission.yaml --etcd-prefix=/registry --service-account-key-file=/etc/kubernetes/ssl/kube-service-account-token-key.pem --tls-private-key-file=/etc/kubernetes/ssl/kube-apiserver-key.pem --requestheader-group-headers=X-Remote-Group --requestheader-username-headers=X-Remote-User --advertise-address= --client-ca-file=/etc/kubernetes/ssl/kube-ca.pem --requestheader-client-ca-file=/etc/kubernetes/ssl/kube-apiserver-requestheader-ca.pem --requestheader-extra-headers-prefix=X-Remote-Extra- --enable-admission-plugins=NamespaceLifecycle,LimitRanger,ServiceAccount,DefaultStorageClass,DefaultTolerationSeconds,MutatingAdmissionWebhook,ValidatingAdmissionWebhook,ResourceQuota,NodeRestriction,Priority,TaintNodesByCondition,PersistentVolumeClaimResize,PodSecurityPolicy,EventRateLimit --authorization-mode=Node,RBAC --cloud-provider= --etcd-certfile=/etc/kubernetes/ssl/kube-node.pem --etcd-keyfile=/etc/kubernetes/ssl/kube-node-key.pem --service-cluster-ip-range=10.43.0.0/16 --profiling=false --service-account-issuer=rke --allow-privileged=true --insecure-port=0 --anonymous-auth=false --audit-log-path=/var/log/kube-audit/audit-log.json --kubelet-client-certificate=/etc/kubernetes/ssl/kube-apiserver.pem --kubelet-client-key=/etc/kubernetes/ssl/kube-apiserver-key.pem --proxy-client-key-file=/etc/kubernetes/ssl/kube-apiserver-proxy-client-key.pem --bind-address=0.0.0.0 --kubelet-preferred-address-types=InternalIP,ExternalIP,Hostname --audit-log-maxsize=100 --audit-log-format=json --service-account-lookup=true --runtime-config=policy/v1beta1/podsecuritypolicy=true --audit-log-maxage=30 --audit-log-maxbackup=10 +``` + +### 1.2.33 Ensure that the --encryption-provider-config argument is set as appropriate (Automated) + + +**Result:** pass + +**Remediation:** +Follow the Kubernetes documentation and configure a EncryptionConfig file. +Then, edit the API server pod specification file /etc/kubernetes/manifests/kube-apiserver.yaml +on the master node and set the --encryption-provider-config parameter to the path of that file: --encryption-provider-config= + +**Audit:** + +```bash +/bin/ps -ef | grep kube-apiserver | grep -v grep +``` + +**Expected Result**: + +```console +'--encryption-provider-config' is present +``` + +**Returned Value**: + +```console +root 6465 6444 8 13:04 ? 00:01:02 kube-apiserver --requestheader-allowed-names=kube-apiserver-proxy-client --etcd-cafile=/etc/kubernetes/ssl/kube-ca.pem --service-node-port-range=30000-32767 --encryption-provider-config=/etc/kubernetes/ssl/encryption.yaml --secure-port=6443 --proxy-client-cert-file=/etc/kubernetes/ssl/kube-apiserver-proxy-client.pem --tls-cert-file=/etc/kubernetes/ssl/kube-apiserver.pem --api-audiences=unknown --storage-backend=etcd3 --tls-cipher-suites=TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384,TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305,TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384,TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305 --audit-policy-file=/etc/kubernetes/audit-policy.yaml --etcd-servers=https://:2379 --kubelet-certificate-authority=/etc/kubernetes/ssl/kube-ca.pem --service-account-signing-key-file=/etc/kubernetes/ssl/kube-service-account-token-key.pem --admission-control-config-file=/etc/kubernetes/admission.yaml --etcd-prefix=/registry --service-account-key-file=/etc/kubernetes/ssl/kube-service-account-token-key.pem --tls-private-key-file=/etc/kubernetes/ssl/kube-apiserver-key.pem --requestheader-group-headers=X-Remote-Group --requestheader-username-headers=X-Remote-User --advertise-address= --client-ca-file=/etc/kubernetes/ssl/kube-ca.pem --requestheader-client-ca-file=/etc/kubernetes/ssl/kube-apiserver-requestheader-ca.pem --requestheader-extra-headers-prefix=X-Remote-Extra- --enable-admission-plugins=NamespaceLifecycle,LimitRanger,ServiceAccount,DefaultStorageClass,DefaultTolerationSeconds,MutatingAdmissionWebhook,ValidatingAdmissionWebhook,ResourceQuota,NodeRestriction,Priority,TaintNodesByCondition,PersistentVolumeClaimResize,PodSecurityPolicy,EventRateLimit --authorization-mode=Node,RBAC --cloud-provider= --etcd-certfile=/etc/kubernetes/ssl/kube-node.pem --etcd-keyfile=/etc/kubernetes/ssl/kube-node-key.pem --service-cluster-ip-range=10.43.0.0/16 --profiling=false --service-account-issuer=rke --allow-privileged=true --insecure-port=0 --anonymous-auth=false --audit-log-path=/var/log/kube-audit/audit-log.json --kubelet-client-certificate=/etc/kubernetes/ssl/kube-apiserver.pem --kubelet-client-key=/etc/kubernetes/ssl/kube-apiserver-key.pem --proxy-client-key-file=/etc/kubernetes/ssl/kube-apiserver-proxy-client-key.pem --bind-address=0.0.0.0 --kubelet-preferred-address-types=InternalIP,ExternalIP,Hostname --audit-log-maxsize=100 --audit-log-format=json --service-account-lookup=true --runtime-config=policy/v1beta1/podsecuritypolicy=true --audit-log-maxage=30 --audit-log-maxbackup=10 +``` + +### 1.2.34 Ensure that encryption providers are appropriately configured (Automated) + + +**Result:** pass + +**Remediation:** +Follow the Kubernetes documentation and configure a EncryptionConfig file. +In this file, choose aescbc, kms or secretbox as the encryption provider. + +**Audit Script:** `check_encryption_provider_config.sh` + +```bash +#!/usr/bin/env bash + +# This script is used to check the encrption provider config is set to aesbc +# +# outputs: +# true/false + +# TODO: Figure out the file location from the kube-apiserver commandline args +ENCRYPTION_CONFIG_FILE="/node/etc/kubernetes/ssl/encryption.yaml" + +if [[ ! -f "${ENCRYPTION_CONFIG_FILE}" ]]; then + echo "false" + exit +fi + +for provider in "$@" +do + if grep "$provider" "${ENCRYPTION_CONFIG_FILE}"; then + echo "true" + exit + fi +done + +echo "false" +exit + +``` + +**Audit Execution:** + +```bash +./check_encryption_provider_config.sh aescbc +``` + +**Expected Result**: + +```console +'true' is equal to 'true' +``` + +**Returned Value**: + +```console +- aescbc: true +``` + +### 1.2.35 Ensure that the API Server only makes use of Strong Cryptographic Ciphers (Automated) + + +**Result:** warn + +**Remediation:** +Edit the API server pod specification file /etc/kubernetes/manifests/kube-apiserver.yaml +on the master node and set the below parameter. +--tls-cipher-suites=TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_RSA_WITH_AES_128_GCM +_SHA256,TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305,TLS_ECDHE_RSA_WITH_AES_256_GCM +_SHA384,TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305,TLS_ECDHE_ECDSA_WITH_AES_256_GCM +_SHA384 + +**Audit:** + +```bash +/bin/ps -ef | grep kube-apiserver | grep -v grep +``` + +## 1.3 Controller Manager +### 1.3.1 Ensure that the --terminated-pod-gc-threshold argument is set as appropriate (Automated) + + +**Result:** pass + +**Remediation:** +Edit the Controller Manager pod specification file /etc/kubernetes/manifests/kube-controller-manager.yaml +on the master node and set the --terminated-pod-gc-threshold to an appropriate threshold, +for example: +--terminated-pod-gc-threshold=10 + +**Audit:** + +```bash +/bin/ps -ef | grep kube-controller-manager | grep -v grep +``` + +**Expected Result**: + +```console +'--terminated-pod-gc-threshold' is present +``` + +**Returned Value**: + +```console +root 6684 6662 1 13:04 ? 00:00:12 kube-controller-manager --profiling=false --cluster-cidr=10.42.0.0/16 --service-account-private-key-file=/etc/kubernetes/ssl/kube-service-account-token-key.pem --service-cluster-ip-range=10.43.0.0/16 --address=0.0.0.0 --leader-elect=true --node-monitor-grace-period=40s --v=2 --allocate-node-cidrs=true --enable-hostpath-provisioner=false --pod-eviction-timeout=5m0s --configure-cloud-routes=false --feature-gates=RotateKubeletServerCertificate=true --cloud-provider= --kubeconfig=/etc/kubernetes/ssl/kubecfg-kube-controller-manager.yaml --root-ca-file=/etc/kubernetes/ssl/kube-ca.pem --terminated-pod-gc-threshold=1000 --allow-untagged-cloud=true --use-service-account-credentials=true +``` + +### 1.3.2 Ensure that the --profiling argument is set to false (Automated) + + +**Result:** pass + +**Remediation:** +Edit the Controller Manager pod specification file /etc/kubernetes/manifests/kube-controller-manager.yaml +on the master node and set the below parameter. +--profiling=false + +**Audit:** + +```bash +/bin/ps -ef | grep kube-controller-manager | grep -v grep +``` + +**Expected Result**: + +```console +'false' is equal to 'false' +``` + +**Returned Value**: + +```console +root 6684 6662 1 13:04 ? 00:00:12 kube-controller-manager --profiling=false --cluster-cidr=10.42.0.0/16 --service-account-private-key-file=/etc/kubernetes/ssl/kube-service-account-token-key.pem --service-cluster-ip-range=10.43.0.0/16 --address=0.0.0.0 --leader-elect=true --node-monitor-grace-period=40s --v=2 --allocate-node-cidrs=true --enable-hostpath-provisioner=false --pod-eviction-timeout=5m0s --configure-cloud-routes=false --feature-gates=RotateKubeletServerCertificate=true --cloud-provider= --kubeconfig=/etc/kubernetes/ssl/kubecfg-kube-controller-manager.yaml --root-ca-file=/etc/kubernetes/ssl/kube-ca.pem --terminated-pod-gc-threshold=1000 --allow-untagged-cloud=true --use-service-account-credentials=true +``` + +### 1.3.3 Ensure that the --use-service-account-credentials argument is set to true (Automated) + + +**Result:** pass + +**Remediation:** +Edit the Controller Manager pod specification file /etc/kubernetes/manifests/kube-controller-manager.yaml +on the master node to set the below parameter. +--use-service-account-credentials=true + +**Audit:** + +```bash +/bin/ps -ef | grep kube-controller-manager | grep -v grep +``` + +**Expected Result**: + +```console +'true' is not equal to 'false' +``` + +**Returned Value**: + +```console +root 6684 6662 1 13:04 ? 00:00:12 kube-controller-manager --profiling=false --cluster-cidr=10.42.0.0/16 --service-account-private-key-file=/etc/kubernetes/ssl/kube-service-account-token-key.pem --service-cluster-ip-range=10.43.0.0/16 --address=0.0.0.0 --leader-elect=true --node-monitor-grace-period=40s --v=2 --allocate-node-cidrs=true --enable-hostpath-provisioner=false --pod-eviction-timeout=5m0s --configure-cloud-routes=false --feature-gates=RotateKubeletServerCertificate=true --cloud-provider= --kubeconfig=/etc/kubernetes/ssl/kubecfg-kube-controller-manager.yaml --root-ca-file=/etc/kubernetes/ssl/kube-ca.pem --terminated-pod-gc-threshold=1000 --allow-untagged-cloud=true --use-service-account-credentials=true +``` + +### 1.3.4 Ensure that the --service-account-private-key-file argument is set as appropriate (Automated) + + +**Result:** pass + +**Remediation:** +Edit the Controller Manager pod specification file /etc/kubernetes/manifests/kube-controller-manager.yaml +on the master node and set the --service-account-private-key-file parameter +to the private key file for service accounts. +--service-account-private-key-file= + +**Audit:** + +```bash +/bin/ps -ef | grep kube-controller-manager | grep -v grep +``` + +**Expected Result**: + +```console +'--service-account-private-key-file' is present +``` + +**Returned Value**: + +```console +root 6684 6662 1 13:04 ? 00:00:12 kube-controller-manager --profiling=false --cluster-cidr=10.42.0.0/16 --service-account-private-key-file=/etc/kubernetes/ssl/kube-service-account-token-key.pem --service-cluster-ip-range=10.43.0.0/16 --address=0.0.0.0 --leader-elect=true --node-monitor-grace-period=40s --v=2 --allocate-node-cidrs=true --enable-hostpath-provisioner=false --pod-eviction-timeout=5m0s --configure-cloud-routes=false --feature-gates=RotateKubeletServerCertificate=true --cloud-provider= --kubeconfig=/etc/kubernetes/ssl/kubecfg-kube-controller-manager.yaml --root-ca-file=/etc/kubernetes/ssl/kube-ca.pem --terminated-pod-gc-threshold=1000 --allow-untagged-cloud=true --use-service-account-credentials=true +``` + +### 1.3.5 Ensure that the --root-ca-file argument is set as appropriate (Automated) + + +**Result:** pass + +**Remediation:** +Edit the Controller Manager pod specification file /etc/kubernetes/manifests/kube-controller-manager.yaml +on the master node and set the --root-ca-file parameter to the certificate bundle file`. +--root-ca-file= + +**Audit:** + +```bash +/bin/ps -ef | grep kube-controller-manager | grep -v grep +``` + +**Expected Result**: + +```console +'--root-ca-file' is present +``` + +**Returned Value**: + +```console +root 6684 6662 1 13:04 ? 00:00:12 kube-controller-manager --profiling=false --cluster-cidr=10.42.0.0/16 --service-account-private-key-file=/etc/kubernetes/ssl/kube-service-account-token-key.pem --service-cluster-ip-range=10.43.0.0/16 --address=0.0.0.0 --leader-elect=true --node-monitor-grace-period=40s --v=2 --allocate-node-cidrs=true --enable-hostpath-provisioner=false --pod-eviction-timeout=5m0s --configure-cloud-routes=false --feature-gates=RotateKubeletServerCertificate=true --cloud-provider= --kubeconfig=/etc/kubernetes/ssl/kubecfg-kube-controller-manager.yaml --root-ca-file=/etc/kubernetes/ssl/kube-ca.pem --terminated-pod-gc-threshold=1000 --allow-untagged-cloud=true --use-service-account-credentials=true +``` + +### 1.3.6 Ensure that the RotateKubeletServerCertificate argument is set to true (Automated) + + +**Result:** Not Applicable + +**Remediation:** +Edit the Controller Manager pod specification file /etc/kubernetes/manifests/kube-controller-manager.yaml +on the master node and set the --feature-gates parameter to include RotateKubeletServerCertificate=true. +--feature-gates=RotateKubeletServerCertificate=true + +Cluster provisioned by RKE handles certificate rotation directly through RKE. + +### 1.3.7 Ensure that the --bind-address argument is set to 127.0.0.1 (Automated) + + +**Result:** pass + +**Remediation:** +Edit the Controller Manager pod specification file /etc/kubernetes/manifests/kube-controller-manager.yaml +on the master node and ensure the correct value for the --bind-address parameter + +**Audit:** + +```bash +/bin/ps -ef | grep kube-controller-manager | grep -v grep +``` + +**Expected Result**: + +```console +'--bind-address' is not present OR '--bind-address' is not present +``` + +**Returned Value**: + +```console +root 6684 6662 1 13:04 ? 00:00:12 kube-controller-manager --profiling=false --cluster-cidr=10.42.0.0/16 --service-account-private-key-file=/etc/kubernetes/ssl/kube-service-account-token-key.pem --service-cluster-ip-range=10.43.0.0/16 --address=0.0.0.0 --leader-elect=true --node-monitor-grace-period=40s --v=2 --allocate-node-cidrs=true --enable-hostpath-provisioner=false --pod-eviction-timeout=5m0s --configure-cloud-routes=false --feature-gates=RotateKubeletServerCertificate=true --cloud-provider= --kubeconfig=/etc/kubernetes/ssl/kubecfg-kube-controller-manager.yaml --root-ca-file=/etc/kubernetes/ssl/kube-ca.pem --terminated-pod-gc-threshold=1000 --allow-untagged-cloud=true --use-service-account-credentials=true +``` + +## 1.4 Scheduler +### 1.4.1 Ensure that the --profiling argument is set to false (Automated) + + +**Result:** pass + +**Remediation:** +Edit the Scheduler pod specification file /etc/kubernetes/manifests/kube-scheduler.yaml file +on the master node and set the below parameter. +--profiling=false + +**Audit:** + +```bash +/bin/ps -ef | grep kube-scheduler | grep -v grep +``` + +**Expected Result**: + +```console +'false' is equal to 'false' +``` + +**Returned Value**: + +```console +root 6889 6870 0 13:04 ? 00:00:02 kube-scheduler --leader-elect=true --profiling=false --v=2 --kubeconfig=/etc/kubernetes/ssl/kubecfg-kube-scheduler.yaml --address=0.0.0.0 +``` + +### 1.4.2 Ensure that the --bind-address argument is set to 127.0.0.1 (Automated) + + +**Result:** pass + +**Remediation:** +Edit the Scheduler pod specification file /etc/kubernetes/manifests/kube-scheduler.yaml +on the master node and ensure the correct value for the --bind-address parameter + +**Audit:** + +```bash +/bin/ps -ef | grep kube-scheduler | grep -v grep +``` + +**Expected Result**: + +```console +'--bind-address' is not present OR '--bind-address' is not present +``` + +**Returned Value**: + +```console +root 6889 6870 0 13:04 ? 00:00:02 kube-scheduler --leader-elect=true --profiling=false --v=2 --kubeconfig=/etc/kubernetes/ssl/kubecfg-kube-scheduler.yaml --address=0.0.0.0 +``` + +## 2 Etcd Node Configuration Files +### 2.1 Ensure that the --cert-file and --key-file arguments are set as appropriate (Automated) + + +**Result:** pass + +**Remediation:** +Follow the etcd service documentation and configure TLS encryption. +Then, edit the etcd pod specification file /etc/kubernetes/manifests/etcd.yaml +on the master node and set the below parameters. +--cert-file= +--key-file= + +**Audit:** + +```bash +/bin/ps -ef | /bin/grep etcd | /bin/grep -v grep +``` + +**Expected Result**: + +```console +'--cert-file' is present AND '--key-file' is present +``` + +**Returned Value**: + +```console +etcd 6259 6237 1 13:03 ? 00:00:13 /usr/local/bin/etcd --listen-peer-urls=https://:2380 --peer-trusted-ca-file=/etc/kubernetes/ssl/kube-ca.pem --peer-cert-file=/etc/kubernetes/ssl/kube-etcd-.pem --peer-client-cert-auth=true --heartbeat-interval=500 --name=etcd- --initial-cluster=etcd-=https://:2380 --trusted-ca-file=/etc/kubernetes/ssl/kube-ca.pem --peer-key-file=/etc/kubernetes/ssl/kube-etcd--key.pem --cipher-suites=TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 --listen-client-urls=https://:2379 --initial-advertise-peer-urls=https://:2380 --key-file=/etc/kubernetes/ssl/kube-etcd--key.pem --client-cert-auth=true --enable-v2=true --election-timeout=5000 --data-dir=/var/lib/rancher/etcd/ --initial-cluster-token=etcd-cluster-1 --initial-cluster-state=new --cert-file=/etc/kubernetes/ssl/kube-etcd-.pem --advertise-client-urls=https://:2379 root 6465 6444 8 13:04 ? 00:01:02 kube-apiserver --requestheader-allowed-names=kube-apiserver-proxy-client --etcd-cafile=/etc/kubernetes/ssl/kube-ca.pem --service-node-port-range=30000-32767 --encryption-provider-config=/etc/kubernetes/ssl/encryption.yaml --secure-port=6443 --proxy-client-cert-file=/etc/kubernetes/ssl/kube-apiserver-proxy-client.pem --tls-cert-file=/etc/kubernetes/ssl/kube-apiserver.pem --api-audiences=unknown --storage-backend=etcd3 --tls-cipher-suites=TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384,TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305,TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384,TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305 --audit-policy-file=/etc/kubernetes/audit-policy.yaml --etcd-servers=https://:2379 --kubelet-certificate-authority=/etc/kubernetes/ssl/kube-ca.pem --service-account-signing-key-file=/etc/kubernetes/ssl/kube-service-account-token-key.pem --admission-control-config-file=/etc/kubernetes/admission.yaml --etcd-prefix=/registry --service-account-key-file=/etc/kubernetes/ssl/kube-service-account-token-key.pem --tls-private-key-file=/etc/kubernetes/ssl/kube-apiserver-key.pem --requestheader-group-headers=X-Remote-Group --requestheader-username-headers=X-Remote-User --advertise-address= --client-ca-file=/etc/kubernetes/ssl/kube-ca.pem --requestheader-client-ca-file=/etc/kubernetes/ssl/kube-apiserver-requestheader-ca.pem --requestheader-extra-headers-prefix=X-Remote-Extra- --enable-admission-plugins=NamespaceLifecycle,LimitRanger,ServiceAccount,DefaultStorageClass,DefaultTolerationSeconds,MutatingAdmissionWebhook,ValidatingAdmissionWebhook,ResourceQuota,NodeRestriction,Priority,TaintNodesByCondition,PersistentVolumeClaimResize,PodSecurityPolicy,EventRateLimit --authorization-mode=Node,RBAC --cloud-provider= --etcd-certfile=/etc/kubernetes/ssl/kube-node.pem --etcd-keyfile=/etc/kubernetes/ssl/kube-node-key.pem --service-cluster-ip-range=10.43.0.0/16 --profiling=false --service-account-issuer=rke --allow-privileged=true --insecure-port=0 --anonymous-auth=false --audit-log-path=/var/log/kube-audit/audit-log.json --kubelet-client-certificate=/etc/kubernetes/ssl/kube-apiserver.pem --kubelet-client-key=/etc/kubernetes/ssl/kube-apiserver-key.pem --proxy-client-key-file=/etc/kubernetes/ssl/kube-apiserver-proxy-client-key.pem --bind-address=0.0.0.0 --kubelet-preferred-address-types=InternalIP,ExternalIP,Hostname --audit-log-maxsize=100 --audit-log-format=json --service-account-lookup=true --runtime-config=policy/v1beta1/podsecuritypolicy=true --audit-log-maxage=30 --audit-log-maxbackup=10 root 24183 24165 1 13:16 ? 00:00:00 kube-bench run --targets etcd --scored --nosummary --noremediations --v=5 --config-dir=/etc/kube-bench/cfg --benchmark rke-cis-1.6-hardened --json --log_dir /tmp/results/logs --outputfile /tmp/results/etcd.json +``` + +### 2.2 Ensure that the --client-cert-auth argument is set to true (Automated) + + +**Result:** pass + +**Remediation:** +Edit the etcd pod specification file /etc/kubernetes/manifests/etcd.yaml on the master +node and set the below parameter. +--client-cert-auth="true" + +**Audit:** + +```bash +/bin/ps -ef | /bin/grep etcd | /bin/grep -v grep +``` + +**Expected Result**: + +```console +'--client-cert-auth' is present OR 'true' is equal to 'true' +``` + +**Returned Value**: + +```console +etcd 6259 6237 1 13:03 ? 00:00:13 /usr/local/bin/etcd --listen-peer-urls=https://:2380 --peer-trusted-ca-file=/etc/kubernetes/ssl/kube-ca.pem --peer-cert-file=/etc/kubernetes/ssl/kube-etcd-.pem --peer-client-cert-auth=true --heartbeat-interval=500 --name=etcd- --initial-cluster=etcd-=https://:2380 --trusted-ca-file=/etc/kubernetes/ssl/kube-ca.pem --peer-key-file=/etc/kubernetes/ssl/kube-etcd--key.pem --cipher-suites=TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 --listen-client-urls=https://:2379 --initial-advertise-peer-urls=https://:2380 --key-file=/etc/kubernetes/ssl/kube-etcd--key.pem --client-cert-auth=true --enable-v2=true --election-timeout=5000 --data-dir=/var/lib/rancher/etcd/ --initial-cluster-token=etcd-cluster-1 --initial-cluster-state=new --cert-file=/etc/kubernetes/ssl/kube-etcd-.pem --advertise-client-urls=https://:2379 root 6465 6444 8 13:04 ? 00:01:02 kube-apiserver --requestheader-allowed-names=kube-apiserver-proxy-client --etcd-cafile=/etc/kubernetes/ssl/kube-ca.pem --service-node-port-range=30000-32767 --encryption-provider-config=/etc/kubernetes/ssl/encryption.yaml --secure-port=6443 --proxy-client-cert-file=/etc/kubernetes/ssl/kube-apiserver-proxy-client.pem --tls-cert-file=/etc/kubernetes/ssl/kube-apiserver.pem --api-audiences=unknown --storage-backend=etcd3 --tls-cipher-suites=TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384,TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305,TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384,TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305 --audit-policy-file=/etc/kubernetes/audit-policy.yaml --etcd-servers=https://:2379 --kubelet-certificate-authority=/etc/kubernetes/ssl/kube-ca.pem --service-account-signing-key-file=/etc/kubernetes/ssl/kube-service-account-token-key.pem --admission-control-config-file=/etc/kubernetes/admission.yaml --etcd-prefix=/registry --service-account-key-file=/etc/kubernetes/ssl/kube-service-account-token-key.pem --tls-private-key-file=/etc/kubernetes/ssl/kube-apiserver-key.pem --requestheader-group-headers=X-Remote-Group --requestheader-username-headers=X-Remote-User --advertise-address= --client-ca-file=/etc/kubernetes/ssl/kube-ca.pem --requestheader-client-ca-file=/etc/kubernetes/ssl/kube-apiserver-requestheader-ca.pem --requestheader-extra-headers-prefix=X-Remote-Extra- --enable-admission-plugins=NamespaceLifecycle,LimitRanger,ServiceAccount,DefaultStorageClass,DefaultTolerationSeconds,MutatingAdmissionWebhook,ValidatingAdmissionWebhook,ResourceQuota,NodeRestriction,Priority,TaintNodesByCondition,PersistentVolumeClaimResize,PodSecurityPolicy,EventRateLimit --authorization-mode=Node,RBAC --cloud-provider= --etcd-certfile=/etc/kubernetes/ssl/kube-node.pem --etcd-keyfile=/etc/kubernetes/ssl/kube-node-key.pem --service-cluster-ip-range=10.43.0.0/16 --profiling=false --service-account-issuer=rke --allow-privileged=true --insecure-port=0 --anonymous-auth=false --audit-log-path=/var/log/kube-audit/audit-log.json --kubelet-client-certificate=/etc/kubernetes/ssl/kube-apiserver.pem --kubelet-client-key=/etc/kubernetes/ssl/kube-apiserver-key.pem --proxy-client-key-file=/etc/kubernetes/ssl/kube-apiserver-proxy-client-key.pem --bind-address=0.0.0.0 --kubelet-preferred-address-types=InternalIP,ExternalIP,Hostname --audit-log-maxsize=100 --audit-log-format=json --service-account-lookup=true --runtime-config=policy/v1beta1/podsecuritypolicy=true --audit-log-maxage=30 --audit-log-maxbackup=10 root 24183 24165 1 13:16 ? 00:00:00 kube-bench run --targets etcd --scored --nosummary --noremediations --v=5 --config-dir=/etc/kube-bench/cfg --benchmark rke-cis-1.6-hardened --json --log_dir /tmp/results/logs --outputfile /tmp/results/etcd.json +``` + +### 2.3 Ensure that the --auto-tls argument is not set to true (Automated) + + +**Result:** pass + +**Remediation:** +Edit the etcd pod specification file /etc/kubernetes/manifests/etcd.yaml on the master +node and either remove the --auto-tls parameter or set it to false. + --auto-tls=false + +**Audit:** + +```bash +/bin/ps -ef | /bin/grep etcd | /bin/grep -v grep +``` + +**Expected Result**: + +```console +'--auto-tls' is not present OR '--auto-tls' is not present +``` + +**Returned Value**: + +```console +etcd 6259 6237 1 13:03 ? 00:00:13 /usr/local/bin/etcd --listen-peer-urls=https://:2380 --peer-trusted-ca-file=/etc/kubernetes/ssl/kube-ca.pem --peer-cert-file=/etc/kubernetes/ssl/kube-etcd-.pem --peer-client-cert-auth=true --heartbeat-interval=500 --name=etcd- --initial-cluster=etcd-=https://:2380 --trusted-ca-file=/etc/kubernetes/ssl/kube-ca.pem --peer-key-file=/etc/kubernetes/ssl/kube-etcd--key.pem --cipher-suites=TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 --listen-client-urls=https://:2379 --initial-advertise-peer-urls=https://:2380 --key-file=/etc/kubernetes/ssl/kube-etcd--key.pem --client-cert-auth=true --enable-v2=true --election-timeout=5000 --data-dir=/var/lib/rancher/etcd/ --initial-cluster-token=etcd-cluster-1 --initial-cluster-state=new --cert-file=/etc/kubernetes/ssl/kube-etcd-.pem --advertise-client-urls=https://:2379 root 6465 6444 8 13:04 ? 00:01:02 kube-apiserver --requestheader-allowed-names=kube-apiserver-proxy-client --etcd-cafile=/etc/kubernetes/ssl/kube-ca.pem --service-node-port-range=30000-32767 --encryption-provider-config=/etc/kubernetes/ssl/encryption.yaml --secure-port=6443 --proxy-client-cert-file=/etc/kubernetes/ssl/kube-apiserver-proxy-client.pem --tls-cert-file=/etc/kubernetes/ssl/kube-apiserver.pem --api-audiences=unknown --storage-backend=etcd3 --tls-cipher-suites=TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384,TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305,TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384,TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305 --audit-policy-file=/etc/kubernetes/audit-policy.yaml --etcd-servers=https://:2379 --kubelet-certificate-authority=/etc/kubernetes/ssl/kube-ca.pem --service-account-signing-key-file=/etc/kubernetes/ssl/kube-service-account-token-key.pem --admission-control-config-file=/etc/kubernetes/admission.yaml --etcd-prefix=/registry --service-account-key-file=/etc/kubernetes/ssl/kube-service-account-token-key.pem --tls-private-key-file=/etc/kubernetes/ssl/kube-apiserver-key.pem --requestheader-group-headers=X-Remote-Group --requestheader-username-headers=X-Remote-User --advertise-address= --client-ca-file=/etc/kubernetes/ssl/kube-ca.pem --requestheader-client-ca-file=/etc/kubernetes/ssl/kube-apiserver-requestheader-ca.pem --requestheader-extra-headers-prefix=X-Remote-Extra- --enable-admission-plugins=NamespaceLifecycle,LimitRanger,ServiceAccount,DefaultStorageClass,DefaultTolerationSeconds,MutatingAdmissionWebhook,ValidatingAdmissionWebhook,ResourceQuota,NodeRestriction,Priority,TaintNodesByCondition,PersistentVolumeClaimResize,PodSecurityPolicy,EventRateLimit --authorization-mode=Node,RBAC --cloud-provider= --etcd-certfile=/etc/kubernetes/ssl/kube-node.pem --etcd-keyfile=/etc/kubernetes/ssl/kube-node-key.pem --service-cluster-ip-range=10.43.0.0/16 --profiling=false --service-account-issuer=rke --allow-privileged=true --insecure-port=0 --anonymous-auth=false --audit-log-path=/var/log/kube-audit/audit-log.json --kubelet-client-certificate=/etc/kubernetes/ssl/kube-apiserver.pem --kubelet-client-key=/etc/kubernetes/ssl/kube-apiserver-key.pem --proxy-client-key-file=/etc/kubernetes/ssl/kube-apiserver-proxy-client-key.pem --bind-address=0.0.0.0 --kubelet-preferred-address-types=InternalIP,ExternalIP,Hostname --audit-log-maxsize=100 --audit-log-format=json --service-account-lookup=true --runtime-config=policy/v1beta1/podsecuritypolicy=true --audit-log-maxage=30 --audit-log-maxbackup=10 root 24183 24165 1 13:16 ? 00:00:00 kube-bench run --targets etcd --scored --nosummary --noremediations --v=5 --config-dir=/etc/kube-bench/cfg --benchmark rke-cis-1.6-hardened --json --log_dir /tmp/results/logs --outputfile /tmp/results/etcd.json +``` + +### 2.4 Ensure that the --peer-cert-file and --peer-key-file arguments are set as appropriate (Automated) + + +**Result:** pass + +**Remediation:** +Follow the etcd service documentation and configure peer TLS encryption as appropriate +for your etcd cluster. +Then, edit the etcd pod specification file /etc/kubernetes/manifests/etcd.yaml on the +master node and set the below parameters. +--peer-client-file= +--peer-key-file= + +**Audit:** + +```bash +/bin/ps -ef | /bin/grep etcd | /bin/grep -v grep +``` + +**Expected Result**: + +```console +'--peer-cert-file' is present AND '--peer-key-file' is present +``` + +**Returned Value**: + +```console +etcd 6259 6237 1 13:03 ? 00:00:13 /usr/local/bin/etcd --listen-peer-urls=https://:2380 --peer-trusted-ca-file=/etc/kubernetes/ssl/kube-ca.pem --peer-cert-file=/etc/kubernetes/ssl/kube-etcd-.pem --peer-client-cert-auth=true --heartbeat-interval=500 --name=etcd- --initial-cluster=etcd-=https://:2380 --trusted-ca-file=/etc/kubernetes/ssl/kube-ca.pem --peer-key-file=/etc/kubernetes/ssl/kube-etcd--key.pem --cipher-suites=TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 --listen-client-urls=https://:2379 --initial-advertise-peer-urls=https://:2380 --key-file=/etc/kubernetes/ssl/kube-etcd--key.pem --client-cert-auth=true --enable-v2=true --election-timeout=5000 --data-dir=/var/lib/rancher/etcd/ --initial-cluster-token=etcd-cluster-1 --initial-cluster-state=new --cert-file=/etc/kubernetes/ssl/kube-etcd-.pem --advertise-client-urls=https://:2379 root 6465 6444 8 13:04 ? 00:01:02 kube-apiserver --requestheader-allowed-names=kube-apiserver-proxy-client --etcd-cafile=/etc/kubernetes/ssl/kube-ca.pem --service-node-port-range=30000-32767 --encryption-provider-config=/etc/kubernetes/ssl/encryption.yaml --secure-port=6443 --proxy-client-cert-file=/etc/kubernetes/ssl/kube-apiserver-proxy-client.pem --tls-cert-file=/etc/kubernetes/ssl/kube-apiserver.pem --api-audiences=unknown --storage-backend=etcd3 --tls-cipher-suites=TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384,TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305,TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384,TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305 --audit-policy-file=/etc/kubernetes/audit-policy.yaml --etcd-servers=https://:2379 --kubelet-certificate-authority=/etc/kubernetes/ssl/kube-ca.pem --service-account-signing-key-file=/etc/kubernetes/ssl/kube-service-account-token-key.pem --admission-control-config-file=/etc/kubernetes/admission.yaml --etcd-prefix=/registry --service-account-key-file=/etc/kubernetes/ssl/kube-service-account-token-key.pem --tls-private-key-file=/etc/kubernetes/ssl/kube-apiserver-key.pem --requestheader-group-headers=X-Remote-Group --requestheader-username-headers=X-Remote-User --advertise-address= --client-ca-file=/etc/kubernetes/ssl/kube-ca.pem --requestheader-client-ca-file=/etc/kubernetes/ssl/kube-apiserver-requestheader-ca.pem --requestheader-extra-headers-prefix=X-Remote-Extra- --enable-admission-plugins=NamespaceLifecycle,LimitRanger,ServiceAccount,DefaultStorageClass,DefaultTolerationSeconds,MutatingAdmissionWebhook,ValidatingAdmissionWebhook,ResourceQuota,NodeRestriction,Priority,TaintNodesByCondition,PersistentVolumeClaimResize,PodSecurityPolicy,EventRateLimit --authorization-mode=Node,RBAC --cloud-provider= --etcd-certfile=/etc/kubernetes/ssl/kube-node.pem --etcd-keyfile=/etc/kubernetes/ssl/kube-node-key.pem --service-cluster-ip-range=10.43.0.0/16 --profiling=false --service-account-issuer=rke --allow-privileged=true --insecure-port=0 --anonymous-auth=false --audit-log-path=/var/log/kube-audit/audit-log.json --kubelet-client-certificate=/etc/kubernetes/ssl/kube-apiserver.pem --kubelet-client-key=/etc/kubernetes/ssl/kube-apiserver-key.pem --proxy-client-key-file=/etc/kubernetes/ssl/kube-apiserver-proxy-client-key.pem --bind-address=0.0.0.0 --kubelet-preferred-address-types=InternalIP,ExternalIP,Hostname --audit-log-maxsize=100 --audit-log-format=json --service-account-lookup=true --runtime-config=policy/v1beta1/podsecuritypolicy=true --audit-log-maxage=30 --audit-log-maxbackup=10 root 24183 24165 1 13:16 ? 00:00:00 kube-bench run --targets etcd --scored --nosummary --noremediations --v=5 --config-dir=/etc/kube-bench/cfg --benchmark rke-cis-1.6-hardened --json --log_dir /tmp/results/logs --outputfile /tmp/results/etcd.json +``` + +### 2.5 Ensure that the --peer-client-cert-auth argument is set to true (Automated) + + +**Result:** pass + +**Remediation:** +Edit the etcd pod specification file /etc/kubernetes/manifests/etcd.yaml on the master +node and set the below parameter. +--peer-client-cert-auth=true + +**Audit:** + +```bash +/bin/ps -ef | /bin/grep etcd | /bin/grep -v grep +``` + +**Expected Result**: + +```console +'--peer-client-cert-auth' is present OR 'true' is equal to 'true' +``` + +**Returned Value**: + +```console +etcd 6259 6237 1 13:03 ? 00:00:13 /usr/local/bin/etcd --listen-peer-urls=https://:2380 --peer-trusted-ca-file=/etc/kubernetes/ssl/kube-ca.pem --peer-cert-file=/etc/kubernetes/ssl/kube-etcd-.pem --peer-client-cert-auth=true --heartbeat-interval=500 --name=etcd- --initial-cluster=etcd-=https://:2380 --trusted-ca-file=/etc/kubernetes/ssl/kube-ca.pem --peer-key-file=/etc/kubernetes/ssl/kube-etcd--key.pem --cipher-suites=TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 --listen-client-urls=https://:2379 --initial-advertise-peer-urls=https://:2380 --key-file=/etc/kubernetes/ssl/kube-etcd--key.pem --client-cert-auth=true --enable-v2=true --election-timeout=5000 --data-dir=/var/lib/rancher/etcd/ --initial-cluster-token=etcd-cluster-1 --initial-cluster-state=new --cert-file=/etc/kubernetes/ssl/kube-etcd-.pem --advertise-client-urls=https://:2379 root 6465 6444 8 13:04 ? 00:01:02 kube-apiserver --requestheader-allowed-names=kube-apiserver-proxy-client --etcd-cafile=/etc/kubernetes/ssl/kube-ca.pem --service-node-port-range=30000-32767 --encryption-provider-config=/etc/kubernetes/ssl/encryption.yaml --secure-port=6443 --proxy-client-cert-file=/etc/kubernetes/ssl/kube-apiserver-proxy-client.pem --tls-cert-file=/etc/kubernetes/ssl/kube-apiserver.pem --api-audiences=unknown --storage-backend=etcd3 --tls-cipher-suites=TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384,TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305,TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384,TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305 --audit-policy-file=/etc/kubernetes/audit-policy.yaml --etcd-servers=https://:2379 --kubelet-certificate-authority=/etc/kubernetes/ssl/kube-ca.pem --service-account-signing-key-file=/etc/kubernetes/ssl/kube-service-account-token-key.pem --admission-control-config-file=/etc/kubernetes/admission.yaml --etcd-prefix=/registry --service-account-key-file=/etc/kubernetes/ssl/kube-service-account-token-key.pem --tls-private-key-file=/etc/kubernetes/ssl/kube-apiserver-key.pem --requestheader-group-headers=X-Remote-Group --requestheader-username-headers=X-Remote-User --advertise-address= --client-ca-file=/etc/kubernetes/ssl/kube-ca.pem --requestheader-client-ca-file=/etc/kubernetes/ssl/kube-apiserver-requestheader-ca.pem --requestheader-extra-headers-prefix=X-Remote-Extra- --enable-admission-plugins=NamespaceLifecycle,LimitRanger,ServiceAccount,DefaultStorageClass,DefaultTolerationSeconds,MutatingAdmissionWebhook,ValidatingAdmissionWebhook,ResourceQuota,NodeRestriction,Priority,TaintNodesByCondition,PersistentVolumeClaimResize,PodSecurityPolicy,EventRateLimit --authorization-mode=Node,RBAC --cloud-provider= --etcd-certfile=/etc/kubernetes/ssl/kube-node.pem --etcd-keyfile=/etc/kubernetes/ssl/kube-node-key.pem --service-cluster-ip-range=10.43.0.0/16 --profiling=false --service-account-issuer=rke --allow-privileged=true --insecure-port=0 --anonymous-auth=false --audit-log-path=/var/log/kube-audit/audit-log.json --kubelet-client-certificate=/etc/kubernetes/ssl/kube-apiserver.pem --kubelet-client-key=/etc/kubernetes/ssl/kube-apiserver-key.pem --proxy-client-key-file=/etc/kubernetes/ssl/kube-apiserver-proxy-client-key.pem --bind-address=0.0.0.0 --kubelet-preferred-address-types=InternalIP,ExternalIP,Hostname --audit-log-maxsize=100 --audit-log-format=json --service-account-lookup=true --runtime-config=policy/v1beta1/podsecuritypolicy=true --audit-log-maxage=30 --audit-log-maxbackup=10 root 24183 24165 1 13:16 ? 00:00:00 kube-bench run --targets etcd --scored --nosummary --noremediations --v=5 --config-dir=/etc/kube-bench/cfg --benchmark rke-cis-1.6-hardened --json --log_dir /tmp/results/logs --outputfile /tmp/results/etcd.json +``` + +### 2.6 Ensure that the --peer-auto-tls argument is not set to true (Automated) + + +**Result:** pass + +**Remediation:** +Edit the etcd pod specification file /etc/kubernetes/manifests/etcd.yaml on the master +node and either remove the --peer-auto-tls parameter or set it to false. +--peer-auto-tls=false + +**Audit:** + +```bash +/bin/ps -ef | /bin/grep etcd | /bin/grep -v grep +``` + +**Expected Result**: + +```console +'--peer-auto-tls' is not present OR '--peer-auto-tls' is present +``` + +**Returned Value**: + +```console +etcd 6259 6237 1 13:03 ? 00:00:13 /usr/local/bin/etcd --listen-peer-urls=https://:2380 --peer-trusted-ca-file=/etc/kubernetes/ssl/kube-ca.pem --peer-cert-file=/etc/kubernetes/ssl/kube-etcd-.pem --peer-client-cert-auth=true --heartbeat-interval=500 --name=etcd- --initial-cluster=etcd-=https://:2380 --trusted-ca-file=/etc/kubernetes/ssl/kube-ca.pem --peer-key-file=/etc/kubernetes/ssl/kube-etcd--key.pem --cipher-suites=TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 --listen-client-urls=https://:2379 --initial-advertise-peer-urls=https://:2380 --key-file=/etc/kubernetes/ssl/kube-etcd--key.pem --client-cert-auth=true --enable-v2=true --election-timeout=5000 --data-dir=/var/lib/rancher/etcd/ --initial-cluster-token=etcd-cluster-1 --initial-cluster-state=new --cert-file=/etc/kubernetes/ssl/kube-etcd-.pem --advertise-client-urls=https://:2379 root 6465 6444 8 13:04 ? 00:01:02 kube-apiserver --requestheader-allowed-names=kube-apiserver-proxy-client --etcd-cafile=/etc/kubernetes/ssl/kube-ca.pem --service-node-port-range=30000-32767 --encryption-provider-config=/etc/kubernetes/ssl/encryption.yaml --secure-port=6443 --proxy-client-cert-file=/etc/kubernetes/ssl/kube-apiserver-proxy-client.pem --tls-cert-file=/etc/kubernetes/ssl/kube-apiserver.pem --api-audiences=unknown --storage-backend=etcd3 --tls-cipher-suites=TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384,TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305,TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384,TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305 --audit-policy-file=/etc/kubernetes/audit-policy.yaml --etcd-servers=https://:2379 --kubelet-certificate-authority=/etc/kubernetes/ssl/kube-ca.pem --service-account-signing-key-file=/etc/kubernetes/ssl/kube-service-account-token-key.pem --admission-control-config-file=/etc/kubernetes/admission.yaml --etcd-prefix=/registry --service-account-key-file=/etc/kubernetes/ssl/kube-service-account-token-key.pem --tls-private-key-file=/etc/kubernetes/ssl/kube-apiserver-key.pem --requestheader-group-headers=X-Remote-Group --requestheader-username-headers=X-Remote-User --advertise-address= --client-ca-file=/etc/kubernetes/ssl/kube-ca.pem --requestheader-client-ca-file=/etc/kubernetes/ssl/kube-apiserver-requestheader-ca.pem --requestheader-extra-headers-prefix=X-Remote-Extra- --enable-admission-plugins=NamespaceLifecycle,LimitRanger,ServiceAccount,DefaultStorageClass,DefaultTolerationSeconds,MutatingAdmissionWebhook,ValidatingAdmissionWebhook,ResourceQuota,NodeRestriction,Priority,TaintNodesByCondition,PersistentVolumeClaimResize,PodSecurityPolicy,EventRateLimit --authorization-mode=Node,RBAC --cloud-provider= --etcd-certfile=/etc/kubernetes/ssl/kube-node.pem --etcd-keyfile=/etc/kubernetes/ssl/kube-node-key.pem --service-cluster-ip-range=10.43.0.0/16 --profiling=false --service-account-issuer=rke --allow-privileged=true --insecure-port=0 --anonymous-auth=false --audit-log-path=/var/log/kube-audit/audit-log.json --kubelet-client-certificate=/etc/kubernetes/ssl/kube-apiserver.pem --kubelet-client-key=/etc/kubernetes/ssl/kube-apiserver-key.pem --proxy-client-key-file=/etc/kubernetes/ssl/kube-apiserver-proxy-client-key.pem --bind-address=0.0.0.0 --kubelet-preferred-address-types=InternalIP,ExternalIP,Hostname --audit-log-maxsize=100 --audit-log-format=json --service-account-lookup=true --runtime-config=policy/v1beta1/podsecuritypolicy=true --audit-log-maxage=30 --audit-log-maxbackup=10 root 24183 24165 2 13:16 ? 00:00:00 kube-bench run --targets etcd --scored --nosummary --noremediations --v=5 --config-dir=/etc/kube-bench/cfg --benchmark rke-cis-1.6-hardened --json --log_dir /tmp/results/logs --outputfile /tmp/results/etcd.json +``` + +### 2.7 Ensure that a unique Certificate Authority is used for etcd (Automated) + + +**Result:** pass + +**Remediation:** +[Manual test] +Follow the etcd documentation and create a dedicated certificate authority setup for the +etcd service. +Then, edit the etcd pod specification file /etc/kubernetes/manifests/etcd.yaml on the +master node and set the below parameter. +--trusted-ca-file= + +**Audit:** + +```bash +/bin/ps -ef | /bin/grep etcd | /bin/grep -v grep +``` + +**Expected Result**: + +```console +'--trusted-ca-file' is present +``` + +**Returned Value**: + +```console +etcd 6259 6237 1 13:03 ? 00:00:13 /usr/local/bin/etcd --listen-peer-urls=https://:2380 --peer-trusted-ca-file=/etc/kubernetes/ssl/kube-ca.pem --peer-cert-file=/etc/kubernetes/ssl/kube-etcd-.pem --peer-client-cert-auth=true --heartbeat-interval=500 --name=etcd- --initial-cluster=etcd-=https://:2380 --trusted-ca-file=/etc/kubernetes/ssl/kube-ca.pem --peer-key-file=/etc/kubernetes/ssl/kube-etcd--key.pem --cipher-suites=TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 --listen-client-urls=https://:2379 --initial-advertise-peer-urls=https://:2380 --key-file=/etc/kubernetes/ssl/kube-etcd--key.pem --client-cert-auth=true --enable-v2=true --election-timeout=5000 --data-dir=/var/lib/rancher/etcd/ --initial-cluster-token=etcd-cluster-1 --initial-cluster-state=new --cert-file=/etc/kubernetes/ssl/kube-etcd-.pem --advertise-client-urls=https://:2379 root 6465 6444 8 13:04 ? 00:01:02 kube-apiserver --requestheader-allowed-names=kube-apiserver-proxy-client --etcd-cafile=/etc/kubernetes/ssl/kube-ca.pem --service-node-port-range=30000-32767 --encryption-provider-config=/etc/kubernetes/ssl/encryption.yaml --secure-port=6443 --proxy-client-cert-file=/etc/kubernetes/ssl/kube-apiserver-proxy-client.pem --tls-cert-file=/etc/kubernetes/ssl/kube-apiserver.pem --api-audiences=unknown --storage-backend=etcd3 --tls-cipher-suites=TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384,TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305,TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384,TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305 --audit-policy-file=/etc/kubernetes/audit-policy.yaml --etcd-servers=https://:2379 --kubelet-certificate-authority=/etc/kubernetes/ssl/kube-ca.pem --service-account-signing-key-file=/etc/kubernetes/ssl/kube-service-account-token-key.pem --admission-control-config-file=/etc/kubernetes/admission.yaml --etcd-prefix=/registry --service-account-key-file=/etc/kubernetes/ssl/kube-service-account-token-key.pem --tls-private-key-file=/etc/kubernetes/ssl/kube-apiserver-key.pem --requestheader-group-headers=X-Remote-Group --requestheader-username-headers=X-Remote-User --advertise-address= --client-ca-file=/etc/kubernetes/ssl/kube-ca.pem --requestheader-client-ca-file=/etc/kubernetes/ssl/kube-apiserver-requestheader-ca.pem --requestheader-extra-headers-prefix=X-Remote-Extra- --enable-admission-plugins=NamespaceLifecycle,LimitRanger,ServiceAccount,DefaultStorageClass,DefaultTolerationSeconds,MutatingAdmissionWebhook,ValidatingAdmissionWebhook,ResourceQuota,NodeRestriction,Priority,TaintNodesByCondition,PersistentVolumeClaimResize,PodSecurityPolicy,EventRateLimit --authorization-mode=Node,RBAC --cloud-provider= --etcd-certfile=/etc/kubernetes/ssl/kube-node.pem --etcd-keyfile=/etc/kubernetes/ssl/kube-node-key.pem --service-cluster-ip-range=10.43.0.0/16 --profiling=false --service-account-issuer=rke --allow-privileged=true --insecure-port=0 --anonymous-auth=false --audit-log-path=/var/log/kube-audit/audit-log.json --kubelet-client-certificate=/etc/kubernetes/ssl/kube-apiserver.pem --kubelet-client-key=/etc/kubernetes/ssl/kube-apiserver-key.pem --proxy-client-key-file=/etc/kubernetes/ssl/kube-apiserver-proxy-client-key.pem --bind-address=0.0.0.0 --kubelet-preferred-address-types=InternalIP,ExternalIP,Hostname --audit-log-maxsize=100 --audit-log-format=json --service-account-lookup=true --runtime-config=policy/v1beta1/podsecuritypolicy=true --audit-log-maxage=30 --audit-log-maxbackup=10 root 24183 24165 2 13:16 ? 00:00:00 kube-bench run --targets etcd --scored --nosummary --noremediations --v=5 --config-dir=/etc/kube-bench/cfg --benchmark rke-cis-1.6-hardened --json --log_dir /tmp/results/logs --outputfile /tmp/results/etcd.json +``` + +## 3.1 Authentication and Authorization +### 3.1.1 Client certificate authentication should not be used for users (Manual) + + +**Result:** warn + +**Remediation:** +Alternative mechanisms provided by Kubernetes such as the use of OIDC should be +implemented in place of client certificates. + +## 3.2 Logging +### 3.2.1 Ensure that a minimal audit policy is created (Automated) + + +**Result:** pass + +**Remediation:** +Create an audit policy file for your cluster. + +**Audit:** + +```bash +/bin/ps -ef | grep kube-apiserver | grep -v grep +``` + +**Expected Result**: + +```console +'--audit-policy-file' is present +``` + +**Returned Value**: + +```console +root 6465 6444 8 13:04 ? 00:01:03 kube-apiserver --requestheader-allowed-names=kube-apiserver-proxy-client --etcd-cafile=/etc/kubernetes/ssl/kube-ca.pem --service-node-port-range=30000-32767 --encryption-provider-config=/etc/kubernetes/ssl/encryption.yaml --secure-port=6443 --proxy-client-cert-file=/etc/kubernetes/ssl/kube-apiserver-proxy-client.pem --tls-cert-file=/etc/kubernetes/ssl/kube-apiserver.pem --api-audiences=unknown --storage-backend=etcd3 --tls-cipher-suites=TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384,TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305,TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384,TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305 --audit-policy-file=/etc/kubernetes/audit-policy.yaml --etcd-servers=https://:2379 --kubelet-certificate-authority=/etc/kubernetes/ssl/kube-ca.pem --service-account-signing-key-file=/etc/kubernetes/ssl/kube-service-account-token-key.pem --admission-control-config-file=/etc/kubernetes/admission.yaml --etcd-prefix=/registry --service-account-key-file=/etc/kubernetes/ssl/kube-service-account-token-key.pem --tls-private-key-file=/etc/kubernetes/ssl/kube-apiserver-key.pem --requestheader-group-headers=X-Remote-Group --requestheader-username-headers=X-Remote-User --advertise-address= --client-ca-file=/etc/kubernetes/ssl/kube-ca.pem --requestheader-client-ca-file=/etc/kubernetes/ssl/kube-apiserver-requestheader-ca.pem --requestheader-extra-headers-prefix=X-Remote-Extra- --enable-admission-plugins=NamespaceLifecycle,LimitRanger,ServiceAccount,DefaultStorageClass,DefaultTolerationSeconds,MutatingAdmissionWebhook,ValidatingAdmissionWebhook,ResourceQuota,NodeRestriction,Priority,TaintNodesByCondition,PersistentVolumeClaimResize,PodSecurityPolicy,EventRateLimit --authorization-mode=Node,RBAC --cloud-provider= --etcd-certfile=/etc/kubernetes/ssl/kube-node.pem --etcd-keyfile=/etc/kubernetes/ssl/kube-node-key.pem --service-cluster-ip-range=10.43.0.0/16 --profiling=false --service-account-issuer=rke --allow-privileged=true --insecure-port=0 --anonymous-auth=false --audit-log-path=/var/log/kube-audit/audit-log.json --kubelet-client-certificate=/etc/kubernetes/ssl/kube-apiserver.pem --kubelet-client-key=/etc/kubernetes/ssl/kube-apiserver-key.pem --proxy-client-key-file=/etc/kubernetes/ssl/kube-apiserver-proxy-client-key.pem --bind-address=0.0.0.0 --kubelet-preferred-address-types=InternalIP,ExternalIP,Hostname --audit-log-maxsize=100 --audit-log-format=json --service-account-lookup=true --runtime-config=policy/v1beta1/podsecuritypolicy=true --audit-log-maxage=30 --audit-log-maxbackup=10 +``` + +### 3.2.2 Ensure that the audit policy covers key security concerns (Manual) + + +**Result:** warn + +**Remediation:** +Consider modification of the audit policy in use on the cluster to include these items, at a +minimum. + +## 4.1 Worker Node Configuration Files +### 4.1.1 Ensure that the kubelet service file permissions are set to 644 or more restrictive (Automated) + + +**Result:** Not Applicable + +**Remediation:** +Cluster provisioned by RKE doesn’t require or maintain a configuration file for the kubelet service. +All configuration is passed in as arguments at container run time. + +### 4.1.2 Ensure that the kubelet service file ownership is set to root:root (Automated) + + +**Result:** Not Applicable + +**Remediation:** +Cluster provisioned by RKE doesn’t require or maintain a configuration file for the kubelet service. +All configuration is passed in as arguments at container run time. + +### 4.1.3 If proxy kubeconfig file exists ensure permissions are set to 644 or more restrictive (Automated) + + +**Result:** pass + +**Remediation:** +Run the below command (based on the file location on your system) on the each worker node. +For example, +chmod 644 $proykubeconfig + +**Audit:** + +```bash +/bin/sh -c 'if test -e /node/etc/kubernetes/ssl/kubecfg-kube-proxy.yaml; then stat -c %a /node/etc/kubernetes/ssl/kubecfg-kube-proxy.yaml; fi' +``` + +**Expected Result**: + +```console +'644' is present OR '640' is present OR '600' is equal to '600' OR '444' is present OR '440' is present OR '400' is present OR '000' is present +``` + +**Returned Value**: + +```console +600 +``` + +### 4.1.4 Ensure that the proxy kubeconfig file ownership is set to root:root (Automated) + + +**Result:** pass + +**Remediation:** +Run the below command (based on the file location on your system) on the each worker node. +For example, chown root:root /etc/kubernetes/ssl/kubecfg-kube-proxy.yaml + +**Audit:** + +```bash +/bin/sh -c 'if test -e /etc/kubernetes/ssl/kubecfg-kube-proxy.yaml; then stat -c %U:%G /etc/kubernetes/ssl/kubecfg-kube-proxy.yaml; fi' +``` + +**Expected Result**: + +```console +'root:root' is not present OR '/etc/kubernetes/ssl/kubecfg-kube-proxy.yaml' is not present +``` + +### 4.1.5 Ensure that the --kubeconfig kubelet.conf file permissions are set to 644 or more restrictive (Automated) + + +**Result:** pass + +**Remediation:** +Run the below command (based on the file location on your system) on the each worker node. +For example, +chmod 644 /etc/kubernetes/ssl/kubecfg-kube-node.yaml + +**Audit:** + +```bash +/bin/sh -c 'if test -e /etc/kubernetes/ssl/kubecfg-kube-node.yaml; then stat -c permissions=%a /etc/kubernetes/ssl/kubecfg-kube-node.yaml; fi' +``` + +**Expected Result**: + +```console +'permissions' is not present +``` + +### 4.1.6 Ensure that the --kubeconfig kubelet.conf file ownership is set to root:root (Automated) + + +**Result:** pass + +**Remediation:** +Run the below command (based on the file location on your system) on the each worker node. +For example, +chown root:root /etc/kubernetes/ssl/kubecfg-kube-node.yaml + +**Audit:** + +```bash +/bin/sh -c 'if test -e /node/etc/kubernetes/ssl/kubecfg-kube-node.yaml; then stat -c %U:%G /node/etc/kubernetes/ssl/kubecfg-kube-node.yaml; fi' +``` + +**Expected Result**: + +```console +'root:root' is equal to 'root:root' +``` + +**Returned Value**: + +```console +root:root +``` + +### 4.1.7 Ensure that the certificate authorities file permissions are set to 644 or more restrictive (Automated) + + +**Result:** pass + +**Remediation:** +Run the following command to modify the file permissions of the +--client-ca-file chmod 644 + +**Audit Script:** `check_cafile_permissions.sh` + +```bash +#!/usr/bin/env bash + +CAFILE=$(ps -ef | grep kubelet | grep -v apiserver | grep -- --client-ca-file= | awk -F '--client-ca-file=' '{print $2}' | awk '{print $1}') +if test -z $CAFILE; then CAFILE=$kubeletcafile; fi +if test -e $CAFILE; then stat -c permissions=%a $CAFILE; fi + +``` + +**Audit Execution:** + +```bash +./check_cafile_permissions.sh +``` + +**Expected Result**: + +```console +'permissions' is not present +``` + +### 4.1.8 Ensure that the client certificate authorities file ownership is set to root:root (Automated) + + +**Result:** pass + +**Remediation:** +Run the following command to modify the ownership of the --client-ca-file. +chown root:root + +**Audit Script:** `check_cafile_ownership.sh` + +```bash +#!/usr/bin/env bash + +CAFILE=$(ps -ef | grep kubelet | grep -v apiserver | grep -- --client-ca-file= | awk -F '--client-ca-file=' '{print $2}' | awk '{print $1}') +if test -z $CAFILE; then CAFILE=$kubeletcafile; fi +if test -e $CAFILE; then stat -c %U:%G $CAFILE; fi + +``` + +**Audit Execution:** + +```bash +./check_cafile_ownership.sh +``` + +**Expected Result**: + +```console +'root:root' is not present +``` + +### 4.1.9 Ensure that the kubelet --config configuration file has permissions set to 644 or more restrictive (Automated) + + +**Result:** Not Applicable + +**Remediation:** +Run the following command (using the config file location identified in the Audit step) +chmod 644 /var/lib/kubelet/config.yaml + +Clusters provisioned by RKE doesn’t require or maintain a configuration file for the kubelet. +All configuration is passed in as arguments at container run time. + +### 4.1.10 Ensure that the kubelet --config configuration file ownership is set to root:root (Automated) + + +**Result:** Not Applicable + +**Remediation:** +Run the following command (using the config file location identified in the Audit step) +chown root:root /var/lib/kubelet/config.yaml + +Clusters provisioned by RKE doesn’t require or maintain a configuration file for the kubelet. +All configuration is passed in as arguments at container run time. + +## 4.2 Kubelet +### 4.2.1 Ensure that the anonymous-auth argument is set to false (Automated) + + +**Result:** pass + +**Remediation:** +If using a Kubelet config file, edit the file to set authentication: anonymous: enabled to +false. +If using executable arguments, edit the kubelet service file +/etc/systemd/system/kubelet.service.d/10-kubeadm.conf on each worker node and +set the below parameter in KUBELET_SYSTEM_PODS_ARGS variable. +--anonymous-auth=false +Based on your system, restart the kubelet service. For example: +systemctl daemon-reload +systemctl restart kubelet.service + +**Audit:** + +```bash +/bin/ps -fC kubelet +``` + +**Audit Config:** + +```bash +/bin/cat /var/lib/kubelet/config.yaml +``` + +**Expected Result**: + +```console +'' is not present +``` + +### 4.2.2 Ensure that the --authorization-mode argument is not set to AlwaysAllow (Automated) + + +**Result:** pass + +**Remediation:** +If using a Kubelet config file, edit the file to set authorization: mode to Webhook. If +using executable arguments, edit the kubelet service file +/etc/systemd/system/kubelet.service.d/10-kubeadm.conf on each worker node and +set the below parameter in KUBELET_AUTHZ_ARGS variable. +--authorization-mode=Webhook +Based on your system, restart the kubelet service. For example: +systemctl daemon-reload +systemctl restart kubelet.service + +**Audit:** + +```bash +/bin/ps -fC kubelet +``` + +**Audit Config:** + +```bash +/bin/cat /var/lib/kubelet/config.yaml +``` + +**Expected Result**: + +```console +'' is not present +``` + +### 4.2.3 Ensure that the --client-ca-file argument is set as appropriate (Automated) + + +**Result:** pass + +**Remediation:** +If using a Kubelet config file, edit the file to set authentication: x509: clientCAFile to +the location of the client CA file. +If using command line arguments, edit the kubelet service file +/etc/systemd/system/kubelet.service.d/10-kubeadm.conf on each worker node and +set the below parameter in KUBELET_AUTHZ_ARGS variable. +--client-ca-file= +Based on your system, restart the kubelet service. For example: +systemctl daemon-reload +systemctl restart kubelet.service + +**Audit:** + +```bash +/bin/ps -fC kubelet +``` + +**Audit Config:** + +```bash +/bin/cat /var/lib/kubelet/config.yaml +``` + +**Expected Result**: + +```console +'' is not present +``` + +### 4.2.4 Ensure that the --read-only-port argument is set to 0 (Automated) + + +**Result:** pass + +**Remediation:** +If using a Kubelet config file, edit the file to set readOnlyPort to 0. +If using command line arguments, edit the kubelet service file +/etc/systemd/system/kubelet.service.d/10-kubeadm.conf on each worker node and +set the below parameter in KUBELET_SYSTEM_PODS_ARGS variable. +--read-only-port=0 +Based on your system, restart the kubelet service. For example: +systemctl daemon-reload +systemctl restart kubelet.service + +**Audit:** + +```bash +/bin/ps -fC kubelet +``` + +**Audit Config:** + +```bash +/bin/cat /var/lib/kubelet/config.yaml +``` + +**Expected Result**: + +```console +'' is not present OR '' is not present +``` + +### 4.2.5 Ensure that the --streaming-connection-idle-timeout argument is not set to 0 (Automated) + + +**Result:** pass + +**Remediation:** +If using a Kubelet config file, edit the file to set streamingConnectionIdleTimeout to a +value other than 0. +If using command line arguments, edit the kubelet service file +/etc/systemd/system/kubelet.service.d/10-kubeadm.conf on each worker node and +set the below parameter in KUBELET_SYSTEM_PODS_ARGS variable. +--streaming-connection-idle-timeout=5m +Based on your system, restart the kubelet service. For example: +systemctl daemon-reload +systemctl restart kubelet.service + +**Audit:** + +```bash +/bin/ps -fC kubelet +``` + +**Audit Config:** + +```bash +/bin/cat /var/lib/kubelet/config.yaml +``` + +**Expected Result**: + +```console +'30m' is not equal to '0' OR '--streaming-connection-idle-timeout' is not present +``` + +**Returned Value**: + +```console +UID PID PPID C STIME TTY TIME CMD root 7101 7078 3 13:04 ? 00:00:23 kubelet --streaming-connection-idle-timeout=30m --cluster-dns=10.43.0.10 --pod-infra-container-image=rancher/mirrored-pause:3.4.1 --node-ip= --network-plugin=cni --event-qps=0 --kubeconfig=/etc/kubernetes/ssl/kubecfg-kube-node.yaml --root-dir=/var/lib/kubelet --cni-bin-dir=/opt/cni/bin --tls-cipher-suites=TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305,TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384,TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305,TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384,TLS_RSA_WITH_AES_256_GCM_SHA384,TLS_RSA_WITH_AES_128_GCM_SHA256 --v=2 --feature-gates=RotateKubeletServerCertificate=true --cloud-provider= --hostname-override= --tls-cert-file=/etc/kubernetes/ssl/kube-kubelet-.pem --authorization-mode=Webhook --resolv-conf=/etc/resolv.conf --volume-plugin-dir=/var/lib/kubelet/volumeplugins --cluster-domain=cluster.local --tls-private-key-file=/etc/kubernetes/ssl/kube-kubelet--key.pem --authentication-token-webhook=true --cni-conf-dir=/etc/cni/net.d --cgroups-per-qos=True --make-iptables-util-chains=true --read-only-port=0 --fail-swap-on=false --anonymous-auth=false --protect-kernel-defaults=true --client-ca-file=/etc/kubernetes/ssl/kube-ca.pem --address=0.0.0.0 --cgroup-driver=cgroupfs --resolv-conf=/run/systemd/resolve/resolv.conf +``` + +### 4.2.6 Ensure that the --protect-kernel-defaults argument is set to true (Automated) + + +**Result:** pass + +**Remediation:** +If using a Kubelet config file, edit the file to set protectKernelDefaults: true. +If using command line arguments, edit the kubelet service file +/etc/systemd/system/kubelet.service.d/10-kubeadm.conf on each worker node and +set the below parameter in KUBELET_SYSTEM_PODS_ARGS variable. +--protect-kernel-defaults=true +Based on your system, restart the kubelet service. For example: +systemctl daemon-reload +systemctl restart kubelet.service + +**Audit:** + +```bash +/bin/ps -fC kubelet +``` + +**Audit Config:** + +```bash +/bin/cat /var/lib/kubelet/config.yaml +``` + +**Expected Result**: + +```console +'' is not present +``` + +### 4.2.7 Ensure that the --make-iptables-util-chains argument is set to true (Automated) + + +**Result:** pass + +**Remediation:** +If using a Kubelet config file, edit the file to set makeIPTablesUtilChains: true. +If using command line arguments, edit the kubelet service file +/etc/systemd/system/kubelet.service.d/10-kubeadm.conf on each worker node and +remove the --make-iptables-util-chains argument from the +KUBELET_SYSTEM_PODS_ARGS variable. +Based on your system, restart the kubelet service. For example: +systemctl daemon-reload +systemctl restart kubelet.service + +**Audit:** + +```bash +/bin/ps -fC kubelet +``` + +**Audit Config:** + +```bash +/bin/cat /var/lib/kubelet/config.yaml +``` + +**Expected Result**: + +```console +'' is not present OR '' is not present +``` + +### 4.2.8 Ensure that the --hostname-override argument is not set (Manual) + + +**Result:** Not Applicable + +**Remediation:** +Edit the kubelet service file /etc/systemd/system/kubelet.service.d/10-kubeadm.conf +on each worker node and remove the --hostname-override argument from the +KUBELET_SYSTEM_PODS_ARGS variable. +Based on your system, restart the kubelet service. For example: +systemctl daemon-reload +systemctl restart kubelet.service + +Clusters provisioned by RKE set the --hostname-override to avoid any hostname configuration errors + +### 4.2.9 Ensure that the --event-qps argument is set to 0 or a level which ensures appropriate event capture (Automated) + + +**Result:** pass + +**Remediation:** +If using a Kubelet config file, edit the file to set eventRecordQPS: to an appropriate level. +If using command line arguments, edit the kubelet service file +/etc/systemd/system/kubelet.service.d/10-kubeadm.conf on each worker node and +set the below parameter in KUBELET_SYSTEM_PODS_ARGS variable. +Based on your system, restart the kubelet service. For example: +systemctl daemon-reload +systemctl restart kubelet.service + +**Audit:** + +```bash +/bin/ps -fC kubelet +``` + +**Audit Config:** + +```bash +/bin/cat /var/lib/kubelet/config.yaml +``` + +**Expected Result**: + +```console +'' is not present +``` + +### 4.2.10 Ensure that the --tls-cert-file and --tls-private-key-file arguments are set as appropriate (Automated) + + +**Result:** pass + +**Remediation:** +If using a Kubelet config file, edit the file to set tlsCertFile to the location +of the certificate file to use to identify this Kubelet, and tlsPrivateKeyFile +to the location of the corresponding private key file. +If using command line arguments, edit the kubelet service file +/etc/systemd/system/kubelet.service.d/10-kubeadm.conf on each worker node and +set the below parameters in KUBELET_CERTIFICATE_ARGS variable. +--tls-cert-file= +--tls-private-key-file= +Based on your system, restart the kubelet service. For example: +systemctl daemon-reload +systemctl restart kubelet.service + +**Audit:** + +```bash +/bin/ps -fC kubelet +``` + +**Audit Config:** + +```bash +/bin/cat /var/lib/kubelet/config.yaml +``` + +**Expected Result**: + +```console +'' is not present AND '' is not present +``` + +### 4.2.11 Ensure that the --rotate-certificates argument is not set to false (Automated) + + +**Result:** pass + +**Remediation:** +If using a Kubelet config file, edit the file to add the line rotateCertificates: true or +remove it altogether to use the default value. +If using command line arguments, edit the kubelet service file +/etc/systemd/system/kubelet.service.d/10-kubeadm.conf on each worker node and +remove --rotate-certificates=false argument from the KUBELET_CERTIFICATE_ARGS +variable. +Based on your system, restart the kubelet service. For example: +systemctl daemon-reload +systemctl restart kubelet.service + +**Audit:** + +```bash +/bin/ps -fC kubelet +``` + +**Audit Config:** + +```bash +/bin/cat /var/lib/kubelet/config.yaml +``` + +**Expected Result**: + +```console +'--rotate-certificates' is not present OR '--rotate-certificates' is not present +``` + +**Returned Value**: + +```console +UID PID PPID C STIME TTY TIME CMD root 7101 7078 3 13:04 ? 00:00:23 kubelet --streaming-connection-idle-timeout=30m --cluster-dns=10.43.0.10 --pod-infra-container-image=rancher/mirrored-pause:3.4.1 --node-ip= --network-plugin=cni --event-qps=0 --kubeconfig=/etc/kubernetes/ssl/kubecfg-kube-node.yaml --root-dir=/var/lib/kubelet --cni-bin-dir=/opt/cni/bin --tls-cipher-suites=TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305,TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384,TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305,TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384,TLS_RSA_WITH_AES_256_GCM_SHA384,TLS_RSA_WITH_AES_128_GCM_SHA256 --v=2 --feature-gates=RotateKubeletServerCertificate=true --cloud-provider= --hostname-override= --tls-cert-file=/etc/kubernetes/ssl/kube-kubelet-.pem --authorization-mode=Webhook --resolv-conf=/etc/resolv.conf --volume-plugin-dir=/var/lib/kubelet/volumeplugins --cluster-domain=cluster.local --tls-private-key-file=/etc/kubernetes/ssl/kube-kubelet--key.pem --authentication-token-webhook=true --cni-conf-dir=/etc/cni/net.d --cgroups-per-qos=True --make-iptables-util-chains=true --read-only-port=0 --fail-swap-on=false --anonymous-auth=false --protect-kernel-defaults=true --client-ca-file=/etc/kubernetes/ssl/kube-ca.pem --address=0.0.0.0 --cgroup-driver=cgroupfs --resolv-conf=/run/systemd/resolve/resolv.conf +``` + +### 4.2.12 Verify that the RotateKubeletServerCertificate argument is set to true (Automated) + + +**Result:** Not Applicable + +**Remediation:** +Edit the kubelet service file /etc/systemd/system/kubelet.service.d/10-kubeadm.conf +on each worker node and set the below parameter in KUBELET_CERTIFICATE_ARGS variable. +--feature-gates=RotateKubeletServerCertificate=true +Based on your system, restart the kubelet service. For example: +systemctl daemon-reload +systemctl restart kubelet.service + +Clusters provisioned by RKE handles certificate rotation directly through RKE. + +**Audit Config:** + +```bash +/bin/cat /var/lib/kubelet/config.yaml +``` + +### 4.2.13 Ensure that the Kubelet only makes use of Strong Cryptographic Ciphers (Automated) + + +**Result:** pass + +**Remediation:** +If using a Kubelet config file, edit the file to set TLSCipherSuites: to +TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305,TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384,TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305,TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384,TLS_RSA_WITH_AES_256_GCM_SHA384,TLS_RSA_WITH_AES_128_GCM_SHA256 +or to a subset of these values. +If using executable arguments, edit the kubelet service file +/etc/systemd/system/kubelet.service.d/10-kubeadm.conf on each worker node and +set the --tls-cipher-suites parameter as follows, or to a subset of these values. +--tls-cipher-suites=TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305,TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384,TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305,TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384,TLS_RSA_WITH_AES_256_GCM_SHA384,TLS_RSA_WITH_AES_128_GCM_SHA256 +Based on your system, restart the kubelet service. For example: +systemctl daemon-reload +systemctl restart kubelet.service + +**Audit:** + +```bash +/bin/ps -fC kubelet +``` + +**Audit Config:** + +```bash +/bin/cat /var/lib/kubelet/config.yaml +``` + +**Expected Result**: + +```console +'' is not present +``` + +## 5.1 RBAC and Service Accounts +### 5.1.1 Ensure that the cluster-admin role is only used where required (Manual) + + +**Result:** warn + +**Remediation:** +Identify all clusterrolebindings to the cluster-admin role. Check if they are used and +if they need this role or if they could use a role with fewer privileges. +Where possible, first bind users to a lower privileged role and then remove the +clusterrolebinding to the cluster-admin role : +kubectl delete clusterrolebinding [name] + +### 5.1.2 Minimize access to secrets (Manual) + + +**Result:** warn + +**Remediation:** +Where possible, remove get, list and watch access to secret objects in the cluster. + +### 5.1.3 Minimize wildcard use in Roles and ClusterRoles (Manual) + + +**Result:** warn + +**Remediation:** +Where possible replace any use of wildcards in clusterroles and roles with specific +objects or actions. + +### 5.1.4 Minimize access to create pods (Manual) + + +**Result:** warn + +**Remediation:** +Where possible, remove create access to pod objects in the cluster. + +### 5.1.5 Ensure that default service accounts are not actively used. (Automated) + + +**Result:** pass + +**Remediation:** +Create explicit service accounts wherever a Kubernetes workload requires specific access +to the Kubernetes API server. +Modify the configuration of each default service account to include this value +automountServiceAccountToken: false + +**Audit Script:** `check_for_default_sa.sh` + +```bash +#!/bin/bash + +set -eE + +handle_error() { + echo "false" +} + +trap 'handle_error' ERR + +count_sa=$(kubectl get serviceaccounts --all-namespaces -o json | jq -r '.items[] | select(.metadata.name=="default") | select((.automountServiceAccountToken == null) or (.automountServiceAccountToken == true))' | jq .metadata.namespace | wc -l) +if [[ ${count_sa} -gt 0 ]]; then + echo "false" + exit +fi + +for ns in $(kubectl get ns --no-headers -o custom-columns=":metadata.name") +do + for result in $(kubectl get clusterrolebinding,rolebinding -n $ns -o json | jq -r '.items[] | select((.subjects[].kind=="ServiceAccount" and .subjects[].name=="default") or (.subjects[].kind=="Group" and .subjects[].name=="system:serviceaccounts"))' | jq -r '"\(.roleRef.kind),\(.roleRef.name)"') + do + read kind name <<<$(IFS=","; echo $result) + resource_count=$(kubectl get $kind $name -n $ns -o json | jq -r '.rules[] | select(.resources[] != "podsecuritypolicies")' | wc -l) + if [[ ${resource_count} -gt 0 ]]; then + echo "false" + exit + fi + done +done + + +echo "true" +``` + +**Audit Execution:** + +```bash +./check_for_default_sa.sh +``` + +**Expected Result**: + +```console +'true' is equal to 'true' +``` + +**Returned Value**: + +```console +true +``` + +### 5.1.6 Ensure that Service Account Tokens are only mounted where necessary (Manual) + + +**Result:** warn + +**Remediation:** +Modify the definition of pods and service accounts which do not need to mount service +account tokens to disable it. + +## 5.2 Pod Security Policies +### 5.2.1 Minimize the admission of privileged containers (Manual) + + +**Result:** warn + +**Remediation:** +Create a PSP as described in the Kubernetes documentation, ensuring that +the .spec.privileged field is omitted or set to false. + +### 5.2.2 Minimize the admission of containers wishing to share the host process ID namespace (Automated) + + +**Result:** pass + +**Remediation:** +Create a PSP as described in the Kubernetes documentation, ensuring that the +.spec.hostPID field is omitted or set to false. + +**Audit:** + +```bash +kubectl get psp -o json | jq .items[] | jq -r 'select((.spec.hostPID == null) or (.spec.hostPID == false))' | jq .metadata.name | wc -l | xargs -I {} echo '--count={}' +``` + +**Expected Result**: + +```console +1 is greater than 0 +``` + +**Returned Value**: + +```console +--count=1 +``` + +### 5.2.3 Minimize the admission of containers wishing to share the host IPC namespace (Automated) + + +**Result:** pass + +**Remediation:** +Create a PSP as described in the Kubernetes documentation, ensuring that the +.spec.hostIPC field is omitted or set to false. + +**Audit:** + +```bash +kubectl get psp -o json | jq .items[] | jq -r 'select((.spec.hostIPC == null) or (.spec.hostIPC == false))' | jq .metadata.name | wc -l | xargs -I {} echo '--count={}' +``` + +**Expected Result**: + +```console +1 is greater than 0 +``` + +**Returned Value**: + +```console +--count=1 +``` + +### 5.2.4 Minimize the admission of containers wishing to share the host network namespace (Automated) + + +**Result:** pass + +**Remediation:** +Create a PSP as described in the Kubernetes documentation, ensuring that the +.spec.hostNetwork field is omitted or set to false. + +**Audit:** + +```bash +kubectl get psp -o json | jq .items[] | jq -r 'select((.spec.hostNetwork == null) or (.spec.hostNetwork == false))' | jq .metadata.name | wc -l | xargs -I {} echo '--count={}' +``` + +**Expected Result**: + +```console +1 is greater than 0 +``` + +**Returned Value**: + +```console +--count=1 +``` + +### 5.2.5 Minimize the admission of containers with allowPrivilegeEscalation (Automated) + + +**Result:** pass + +**Remediation:** +Create a PSP as described in the Kubernetes documentation, ensuring that the +.spec.allowPrivilegeEscalation field is omitted or set to false. + +**Audit:** + +```bash +kubectl get psp -o json | jq .items[] | jq -r 'select((.spec.allowPrivilegeEscalation == null) or (.spec.allowPrivilegeEscalation == false))' | jq .metadata.name | wc -l | xargs -I {} echo '--count={}' +``` + +**Expected Result**: + +```console +1 is greater than 0 +``` + +**Returned Value**: + +```console +--count=1 +``` + +### 5.2.6 Minimize the admission of root containers (Manual) + + +**Result:** warn + +**Remediation:** +Create a PSP as described in the Kubernetes documentation, ensuring that the +.spec.runAsUser.rule is set to either MustRunAsNonRoot or MustRunAs with the range of +UIDs not including 0. + +### 5.2.7 Minimize the admission of containers with the NET_RAW capability (Manual) + + +**Result:** warn + +**Remediation:** +Create a PSP as described in the Kubernetes documentation, ensuring that the +.spec.requiredDropCapabilities is set to include either NET_RAW or ALL. + +### 5.2.8 Minimize the admission of containers with added capabilities (Manual) + + +**Result:** warn + +**Remediation:** +Ensure that allowedCapabilities is not present in PSPs for the cluster unless +it is set to an empty array. + +### 5.2.9 Minimize the admission of containers with capabilities assigned (Manual) + + +**Result:** warn + +**Remediation:** +Review the use of capabilites in applications runnning on your cluster. Where a namespace +contains applicaions which do not require any Linux capabities to operate consider adding +a PSP which forbids the admission of containers which do not drop all capabilities. + +## 5.3 Network Policies and CNI +### 5.3.1 Ensure that the CNI in use supports Network Policies (Manual) + + +**Result:** warn + +**Remediation:** +If the CNI plugin in use does not support network policies, consideration should be given to +making use of a different plugin, or finding an alternate mechanism for restricting traffic +in the Kubernetes cluster. + +### 5.3.2 Ensure that all Namespaces have Network Policies defined (Automated) + + +**Result:** pass + +**Remediation:** +Follow the documentation and create NetworkPolicy objects as you need them. + +**Audit Script:** `check_for_network_policies.sh` + +```bash +#!/bin/bash + +set -eE + +handle_error() { + echo "false" +} + +trap 'handle_error' ERR + +for namespace in $(kubectl get namespaces --all-namespaces -o json | jq -r '.items[].metadata.name'); do + policy_count=$(kubectl get networkpolicy -n ${namespace} -o json | jq '.items | length') + if [[ ${policy_count} -eq 0 ]]; then + echo "false" + exit + fi +done + +echo "true" + +``` + +**Audit Execution:** + +```bash +./check_for_network_policies.sh +``` + +**Expected Result**: + +```console +'true' is equal to 'true' +``` + +**Returned Value**: + +```console +true +``` + +## 5.4 Secrets Management +### 5.4.1 Prefer using secrets as files over secrets as environment variables (Manual) + + +**Result:** warn + +**Remediation:** +if possible, rewrite application code to read secrets from mounted secret files, rather than +from environment variables. + +### 5.4.2 Consider external secret storage (Manual) + + +**Result:** warn + +**Remediation:** +Refer to the secrets management options offered by your cloud provider or a third-party +secrets management solution. + +## 5.5 Extensible Admission Control +### 5.5.1 Configure Image Provenance using ImagePolicyWebhook admission controller (Manual) + + +**Result:** warn + +**Remediation:** +Follow the Kubernetes documentation and setup image provenance. + +## 5.7 General Policies +### 5.7.1 Create administrative boundaries between resources using namespaces (Manual) + + +**Result:** warn + +**Remediation:** +Follow the documentation and create namespaces for objects in your deployment as you need +them. + +### 5.7.2 Ensure that the seccomp profile is set to docker/default in your pod definitions (Manual) + + +**Result:** warn + +**Remediation:** +Seccomp is an alpha feature currently. By default, all alpha features are disabled. So, you +would need to enable alpha features in the apiserver by passing "--feature- +gates=AllAlpha=true" argument. +Edit the /etc/kubernetes/apiserver file on the master node and set the KUBE_API_ARGS +parameter to "--feature-gates=AllAlpha=true" +KUBE_API_ARGS="--feature-gates=AllAlpha=true" +Based on your system, restart the kube-apiserver service. For example: +systemctl restart kube-apiserver.service +Use annotations to enable the docker/default seccomp profile in your pod definitions. An +example is as below: +apiVersion: v1 +kind: Pod +metadata: + name: trustworthy-pod + annotations: + seccomp.security.alpha.kubernetes.io/pod: docker/default +spec: + containers: + - name: trustworthy-container + image: sotrustworthy:latest + +### 5.7.3 Apply Security Context to Your Pods and Containers (Manual) + + +**Result:** warn + +**Remediation:** +Follow the Kubernetes documentation and apply security contexts to your pods. For a +suggested list of security contexts, you may refer to the CIS Security Benchmark for Docker +Containers. + +### 5.7.4 The default namespace should not be used (Automated) + + +**Result:** pass + +**Remediation:** +Ensure that namespaces are created to allow for appropriate segregation of Kubernetes +resources and that all new resources are created in a specific namespace. + +**Audit Script:** `check_for_default_ns.sh` + +```bash +#!/bin/bash + +set -eE + +handle_error() { + echo "false" +} + +trap 'handle_error' ERR + +count=$(kubectl get all -n default -o json | jq .items[] | jq -r 'select((.metadata.name!="kubernetes"))' | jq .metadata.name | wc -l) +if [[ ${count} -gt 0 ]]; then + echo "false" + exit +fi + +echo "true" + + +``` + +**Audit Execution:** + +```bash +./check_for_default_ns.sh +``` + +**Expected Result**: + +```console +'true' is equal to 'true' +``` + +**Returned Value**: + +```console +true +``` + diff --git a/content/rancher/v2.6/en/security/hardening-guides/1.6-hardening-2.6/Rancher_v2-6_CIS_v1-6_Hardening_Guide.pdf b/content/rancher/v2.6/en/security/hardening-guides/1.6-hardening-2.6/Rancher_v2-6_CIS_v1-6_Hardening_Guide.pdf new file mode 100644 index 00000000000..2df9a1dae27 --- /dev/null +++ b/content/rancher/v2.6/en/security/hardening-guides/1.6-hardening-2.6/Rancher_v2-6_CIS_v1-6_Hardening_Guide.pdf @@ -0,0 +1,8129 @@ +%PDF-1.7 +%🖤 +1 0 obj +<< +/Type /Pages +/Kids [ 6 0 R 8 0 R 30 0 R 45 0 R 53 0 R 67 0 R 77 0 R 99 0 R 129 0 R 169 0 R 204 0 R 241 0 R 280 0 R 320 0 R 360 0 R 400 0 R 435 0 R 475 0 R 515 0 R 538 0 R 572 0 R ] +/Count 21 +>> +endobj +2 0 obj +<< +/Title (Hardening Guide with CIS v1.6 Benchmark) +/Creator (pandoc) +/Producer (WeasyPrint 54.1) +>> +endobj +3 0 obj +<< +/Type /Catalog +/Pages 1 0 R +/Outlines 600 0 R +/Names << +/Dests << +/Names [ (TOC) [ 8 0 R /XYZ 77.509843 756.850394 0 ] (cb1) [ 45 0 R /XYZ 84.259843 441.572079 0 ] (cb1-1) [ 45 0 R /XYZ 101.433071 439.875057 0 ] (cb1-2) [ 45 0 R /XYZ 99.933071 420.928036 0 ] (cb1-3) [ 45 0 R /XYZ 99.933071 401.981014 0 ] (cb1-4) [ 45 0 R /XYZ 99.933071 383.033993 0 ] (cb1-5) [ 45 0 R /XYZ 99.933071 364.086971 0 ] (cb10) [ 400 0 R /XYZ 84.259843 697.970079 0 ] (cb10-1) [ 400 0 R /XYZ 101.433071 696.273057 0 ] (cb10-10) [ 400 0 R /XYZ 99.933071 525.749864 0 ] (cb10-100) [ 475 0 R /XYZ 99.933071 249.709434 0 ] (cb10-101) [ 475 0 R /XYZ 99.933071 230.762413 0 ] (cb10-102) [ 475 0 R /XYZ 99.933071 211.815391 0 ] (cb10-103) [ 475 0 R /XYZ 99.933071 192.868370 0 ] (cb10-104) [ 475 0 R /XYZ 99.933071 173.921348 0 ] (cb10-105) [ 475 0 R /XYZ 99.933071 154.974327 0 ] (cb10-106) [ 475 0 R /XYZ 99.933071 136.027305 0 ] (cb10-107) [ 475 0 R /XYZ 99.933071 117.080284 0 ] (cb10-108) [ 475 0 R /XYZ 99.933071 98.133262 0 ] (cb10-109) [ 515 0 R /XYZ 99.933071 799.173057 0 ] (cb10-11) [ 400 0 R /XYZ 99.933071 506.802842 0 ] (cb10-110) [ 515 0 R /XYZ 99.933071 780.226036 0 ] (cb10-111) [ 515 0 R /XYZ 99.933071 761.279014 0 ] (cb10-112) [ 515 0 R /XYZ 99.933071 742.331993 0 ] (cb10-113) [ 515 0 R /XYZ 99.933071 723.384971 0 ] (cb10-114) [ 515 0 R /XYZ 99.933071 704.437950 0 ] (cb10-115) [ 515 0 R /XYZ 99.933071 685.490928 0 ] (cb10-116) [ 515 0 R /XYZ 99.933071 666.543907 0 ] (cb10-117) [ 515 0 R /XYZ 99.933071 647.596885 0 ] (cb10-118) [ 515 0 R /XYZ 99.933071 533.914756 0 ] (cb10-119) [ 515 0 R /XYZ 99.933071 514.967735 0 ] (cb10-12) [ 400 0 R /XYZ 99.933071 487.855821 0 ] (cb10-120) [ 515 0 R /XYZ 99.933071 496.020714 0 ] (cb10-121) [ 515 0 R /XYZ 99.933071 477.073692 0 ] (cb10-122) [ 515 0 R /XYZ 99.933071 458.126671 0 ] (cb10-123) [ 515 0 R /XYZ 99.933071 439.179649 0 ] (cb10-124) [ 515 0 R /XYZ 99.933071 420.232628 0 ] (cb10-13) [ 400 0 R /XYZ 99.933071 468.908799 0 ] (cb10-14) [ 400 0 R /XYZ 99.933071 449.961778 0 ] (cb10-15) [ 400 0 R /XYZ 99.933071 431.014756 0 ] (cb10-16) [ 400 0 R /XYZ 99.933071 412.067735 0 ] (cb10-17) [ 400 0 R /XYZ 99.933071 393.120714 0 ] (cb10-18) [ 400 0 R /XYZ 99.933071 374.173692 0 ] (cb10-19) [ 400 0 R /XYZ 99.933071 355.226671 0 ] (cb10-2) [ 400 0 R /XYZ 99.933071 677.326036 0 ] (cb10-20) [ 400 0 R /XYZ 99.933071 336.279649 0 ] (cb10-21) [ 400 0 R /XYZ 99.933071 317.332628 0 ] (cb10-22) [ 400 0 R /XYZ 99.933071 298.385606 0 ] (cb10-23) [ 400 0 R /XYZ 99.933071 279.438585 0 ] (cb10-24) [ 400 0 R /XYZ 99.933071 260.491563 0 ] (cb10-25) [ 400 0 R /XYZ 99.933071 241.544542 0 ] (cb10-26) [ 400 0 R /XYZ 99.933071 222.597520 0 ] (cb10-27) [ 400 0 R /XYZ 99.933071 203.650499 0 ] (cb10-28) [ 400 0 R /XYZ 99.933071 184.703477 0 ] (cb10-29) [ 400 0 R /XYZ 99.933071 165.756456 0 ] (cb10-3) [ 400 0 R /XYZ 99.933071 658.379014 0 ] (cb10-30) [ 400 0 R /XYZ 99.933071 127.862413 0 ] (cb10-31) [ 400 0 R /XYZ 99.933071 108.915391 0 ] (cb10-32) [ 400 0 R /XYZ 99.933071 89.968370 0 ] (cb10-33) [ 435 0 R /XYZ 99.933071 799.173057 0 ] (cb10-34) [ 435 0 R /XYZ 99.933071 780.226036 0 ] (cb10-35) [ 435 0 R /XYZ 99.933071 761.279014 0 ] (cb10-36) [ 435 0 R /XYZ 99.933071 742.331993 0 ] (cb10-37) [ 435 0 R /XYZ 99.933071 723.384971 0 ] (cb10-38) [ 435 0 R /XYZ 99.933071 704.437950 0 ] (cb10-39) [ 435 0 R /XYZ 99.933071 685.490928 0 ] (cb10-4) [ 400 0 R /XYZ 99.933071 639.431993 0 ] (cb10-40) [ 435 0 R /XYZ 99.933071 666.543907 0 ] (cb10-41) [ 435 0 R /XYZ 99.933071 647.596885 0 ] (cb10-42) [ 435 0 R /XYZ 99.933071 628.649864 0 ] (cb10-43) [ 435 0 R /XYZ 99.933071 609.702842 0 ] (cb10-44) [ 435 0 R /XYZ 99.933071 590.755821 0 ] (cb10-45) [ 435 0 R /XYZ 99.933071 571.808799 0 ] (cb10-46) [ 435 0 R /XYZ 99.933071 552.861778 0 ] (cb10-47) [ 435 0 R /XYZ 99.933071 533.914756 0 ] (cb10-48) [ 435 0 R /XYZ 99.933071 514.967735 0 ] (cb10-49) [ 435 0 R /XYZ 99.933071 496.020714 0 ] (cb10-5) [ 400 0 R /XYZ 99.933071 620.484971 0 ] (cb10-50) [ 435 0 R /XYZ 99.933071 477.073692 0 ] (cb10-51) [ 435 0 R /XYZ 99.933071 458.126671 0 ] (cb10-52) [ 435 0 R /XYZ 99.933071 439.179649 0 ] (cb10-53) [ 435 0 R /XYZ 99.933071 420.232628 0 ] (cb10-54) [ 435 0 R /XYZ 99.933071 401.285606 0 ] (cb10-55) [ 435 0 R /XYZ 99.933071 382.338585 0 ] (cb10-56) [ 435 0 R /XYZ 99.933071 363.391563 0 ] (cb10-57) [ 435 0 R /XYZ 99.933071 344.444542 0 ] (cb10-58) [ 435 0 R /XYZ 99.933071 325.497520 0 ] (cb10-59) [ 435 0 R /XYZ 99.933071 306.550499 0 ] (cb10-6) [ 400 0 R /XYZ 99.933071 601.537950 0 ] (cb10-60) [ 435 0 R /XYZ 99.933071 287.603477 0 ] (cb10-61) [ 435 0 R /XYZ 99.933071 268.656456 0 ] (cb10-62) [ 435 0 R /XYZ 99.933071 249.709434 0 ] (cb10-63) [ 435 0 R /XYZ 99.933071 230.762413 0 ] (cb10-64) [ 435 0 R /XYZ 99.933071 211.815391 0 ] (cb10-65) [ 435 0 R /XYZ 99.933071 192.868370 0 ] (cb10-66) [ 435 0 R /XYZ 99.933071 173.921348 0 ] (cb10-67) [ 435 0 R /XYZ 99.933071 154.974327 0 ] (cb10-68) [ 435 0 R /XYZ 99.933071 136.027305 0 ] (cb10-69) [ 435 0 R /XYZ 99.933071 117.080284 0 ] (cb10-7) [ 400 0 R /XYZ 99.933071 582.590928 0 ] (cb10-70) [ 435 0 R /XYZ 99.933071 98.133262 0 ] (cb10-71) [ 475 0 R /XYZ 99.933071 799.173057 0 ] (cb10-72) [ 475 0 R /XYZ 99.933071 780.226036 0 ] (cb10-73) [ 475 0 R /XYZ 99.933071 761.279014 0 ] (cb10-74) [ 475 0 R /XYZ 99.933071 742.331993 0 ] (cb10-75) [ 475 0 R /XYZ 99.933071 723.384971 0 ] (cb10-76) [ 475 0 R /XYZ 99.933071 704.437950 0 ] (cb10-77) [ 475 0 R /XYZ 99.933071 685.490928 0 ] (cb10-78) [ 475 0 R /XYZ 99.933071 666.543907 0 ] (cb10-79) [ 475 0 R /XYZ 99.933071 647.596885 0 ] (cb10-8) [ 400 0 R /XYZ 99.933071 563.643907 0 ] (cb10-80) [ 475 0 R /XYZ 99.933071 628.649864 0 ] (cb10-81) [ 475 0 R /XYZ 99.933071 609.702842 0 ] (cb10-82) [ 475 0 R /XYZ 99.933071 590.755821 0 ] (cb10-83) [ 475 0 R /XYZ 99.933071 571.808799 0 ] (cb10-84) [ 475 0 R /XYZ 99.933071 552.861778 0 ] (cb10-85) [ 475 0 R /XYZ 99.933071 533.914756 0 ] (cb10-86) [ 475 0 R /XYZ 99.933071 514.967735 0 ] (cb10-87) [ 475 0 R /XYZ 99.933071 496.020714 0 ] (cb10-88) [ 475 0 R /XYZ 99.933071 477.073692 0 ] (cb10-89) [ 475 0 R /XYZ 99.933071 458.126671 0 ] (cb10-9) [ 400 0 R /XYZ 99.933071 544.696885 0 ] (cb10-90) [ 475 0 R /XYZ 99.933071 439.179649 0 ] (cb10-91) [ 475 0 R /XYZ 99.933071 420.232628 0 ] (cb10-92) [ 475 0 R /XYZ 99.933071 401.285606 0 ] (cb10-93) [ 475 0 R /XYZ 99.933071 382.338585 0 ] (cb10-94) [ 475 0 R /XYZ 99.933071 363.391563 0 ] (cb10-95) [ 475 0 R /XYZ 99.933071 344.444542 0 ] (cb10-96) [ 475 0 R /XYZ 99.933071 325.497520 0 ] (cb10-97) [ 475 0 R /XYZ 99.933071 306.550499 0 ] (cb10-98) [ 475 0 R /XYZ 99.933071 287.603477 0 ] (cb10-99) [ 475 0 R /XYZ 99.933071 268.656456 0 ] (cb11) [ 515 0 R /XYZ 84.259843 179.686628 0 ] (cb11-1) [ 515 0 R /XYZ 101.433071 177.989606 0 ] (cb11-10) [ 538 0 R /XYZ 99.933071 723.384971 0 ] (cb11-11) [ 538 0 R /XYZ 99.933071 704.437950 0 ] (cb11-12) [ 538 0 R /XYZ 99.933071 685.490928 0 ] (cb11-13) [ 538 0 R /XYZ 99.933071 666.543907 0 ] (cb11-14) [ 538 0 R /XYZ 99.933071 647.596885 0 ] (cb11-15) [ 538 0 R /XYZ 99.933071 628.649864 0 ] (cb11-16) [ 538 0 R /XYZ 99.933071 609.702842 0 ] (cb11-17) [ 538 0 R /XYZ 99.933071 590.755821 0 ] (cb11-18) [ 538 0 R /XYZ 99.933071 571.808799 0 ] (cb11-19) [ 538 0 R /XYZ 99.933071 552.861778 0 ] (cb11-2) [ 515 0 R /XYZ 99.933071 159.042585 0 ] (cb11-20) [ 538 0 R /XYZ 99.933071 533.914756 0 ] (cb11-21) [ 538 0 R /XYZ 99.933071 514.967735 0 ] (cb11-22) [ 538 0 R /XYZ 99.933071 496.020714 0 ] (cb11-23) [ 538 0 R /XYZ 99.933071 477.073692 0 ] (cb11-24) [ 538 0 R /XYZ 99.933071 458.126671 0 ] (cb11-25) [ 538 0 R /XYZ 99.933071 439.179649 0 ] (cb11-26) [ 538 0 R /XYZ 99.933071 420.232628 0 ] (cb11-3) [ 515 0 R /XYZ 99.933071 140.095563 0 ] (cb11-4) [ 515 0 R /XYZ 99.933071 121.148542 0 ] (cb11-5) [ 515 0 R /XYZ 99.933071 102.201520 0 ] (cb11-6) [ 538 0 R /XYZ 99.933071 799.173057 0 ] (cb11-7) [ 538 0 R /XYZ 99.933071 780.226036 0 ] (cb11-8) [ 538 0 R /XYZ 99.933071 761.279014 0 ] (cb11-9) [ 538 0 R /XYZ 99.933071 742.331993 0 ] (cb12) [ 538 0 R /XYZ 84.259843 294.539606 0 ] (cb12-1) [ 538 0 R /XYZ 101.433071 292.842585 0 ] (cb12-10) [ 538 0 R /XYZ 99.933071 122.319391 0 ] (cb12-11) [ 538 0 R /XYZ 99.933071 103.372370 0 ] (cb12-12) [ 572 0 R /XYZ 99.933071 799.173057 0 ] (cb12-13) [ 572 0 R /XYZ 99.933071 780.226036 0 ] (cb12-14) [ 572 0 R /XYZ 99.933071 761.279014 0 ] (cb12-15) [ 572 0 R /XYZ 99.933071 742.331993 0 ] (cb12-16) [ 572 0 R /XYZ 99.933071 723.384971 0 ] (cb12-17) [ 572 0 R /XYZ 99.933071 704.437950 0 ] (cb12-18) [ 572 0 R /XYZ 99.933071 685.490928 0 ] (cb12-19) [ 572 0 R /XYZ 99.933071 666.543907 0 ] (cb12-2) [ 538 0 R /XYZ 99.933071 273.895563 0 ] (cb12-20) [ 572 0 R /XYZ 99.933071 628.649864 0 ] (cb12-21) [ 572 0 R /XYZ 99.933071 590.755821 0 ] (cb12-22) [ 572 0 R /XYZ 99.933071 571.808799 0 ] (cb12-23) [ 572 0 R /XYZ 99.933071 552.861778 0 ] (cb12-3) [ 538 0 R /XYZ 99.933071 254.948542 0 ] (cb12-4) [ 538 0 R /XYZ 99.933071 236.001520 0 ] (cb12-5) [ 538 0 R /XYZ 99.933071 217.054499 0 ] (cb12-6) [ 538 0 R /XYZ 99.933071 198.107477 0 ] (cb12-7) [ 538 0 R /XYZ 99.933071 179.160456 0 ] (cb12-8) [ 538 0 R /XYZ 99.933071 160.213434 0 ] (cb12-9) [ 538 0 R /XYZ 99.933071 141.266413 0 ] (cb2) [ 53 0 R /XYZ 84.259843 753.620079 0 ] (cb2-1) [ 53 0 R /XYZ 101.433071 751.923057 0 ] (cb2-2) [ 53 0 R /XYZ 99.933071 732.976036 0 ] (cb3) [ 53 0 R /XYZ 84.259843 654.779014 0 ] (cb3-1) [ 53 0 R /XYZ 101.433071 653.081993 0 ] (cb3-2) [ 53 0 R /XYZ 99.933071 634.134971 0 ] (cb3-3) [ 53 0 R /XYZ 99.933071 615.187950 0 ] (cb3-4) [ 53 0 R /XYZ 99.933071 596.240928 0 ] (cb4) [ 53 0 R /XYZ 84.259843 282.344928 0 ] (cb4-1) [ 53 0 R /XYZ 101.433071 280.647907 0 ] (cb5) [ 53 0 R /XYZ 84.259843 217.647907 0 ] (cb5-1) [ 53 0 R /XYZ 101.433071 215.950885 0 ] (cb5-2) [ 53 0 R /XYZ 99.933071 197.003864 0 ] (cb5-3) [ 53 0 R /XYZ 99.933071 178.056842 0 ] (cb5-4) [ 53 0 R /XYZ 99.933071 159.109821 0 ] (cb5-5) [ 53 0 R /XYZ 99.933071 140.162799 0 ] (cb6) [ 67 0 R /XYZ 84.259843 749.870079 0 ] (cb6-1) [ 67 0 R /XYZ 101.433071 748.173057 0 ] (cb6-2) [ 67 0 R /XYZ 99.933071 729.226036 0 ] (cb6-3) [ 67 0 R /XYZ 99.933071 710.279014 0 ] (cb6-4) [ 67 0 R /XYZ 99.933071 672.384971 0 ] (cb6-5) [ 67 0 R /XYZ 99.933071 634.490928 0 ] (cb7) [ 77 0 R /XYZ 84.259843 716.781496 0 ] (cb7-1) [ 77 0 R /XYZ 101.433071 715.084475 0 ] (cb7-10) [ 77 0 R /XYZ 99.933071 544.561281 0 ] (cb7-11) [ 77 0 R /XYZ 99.933071 525.614260 0 ] (cb7-12) [ 77 0 R /XYZ 99.933071 506.667238 0 ] (cb7-13) [ 77 0 R /XYZ 99.933071 487.720217 0 ] (cb7-14) [ 77 0 R /XYZ 99.933071 468.773195 0 ] (cb7-2) [ 77 0 R /XYZ 99.933071 696.137453 0 ] (cb7-3) [ 77 0 R /XYZ 99.933071 677.190432 0 ] (cb7-4) [ 77 0 R /XYZ 99.933071 658.243410 0 ] (cb7-5) [ 77 0 R /XYZ 99.933071 639.296389 0 ] (cb7-6) [ 77 0 R /XYZ 99.933071 620.349367 0 ] (cb7-7) [ 77 0 R /XYZ 99.933071 601.402346 0 ] (cb7-8) [ 77 0 R /XYZ 99.933071 582.455324 0 ] (cb7-9) [ 77 0 R /XYZ 99.933071 563.508303 0 ] (cb8) [ 77 0 R /XYZ 84.259843 372.023195 0 ] (cb8-1) [ 77 0 R /XYZ 101.433071 370.326174 0 ] (cb8-2) [ 77 0 R /XYZ 99.933071 351.379152 0 ] (cb8-3) [ 77 0 R /XYZ 99.933071 332.432131 0 ] (cb8-4) [ 77 0 R /XYZ 99.933071 294.538088 0 ] (cb8-5) [ 77 0 R /XYZ 99.933071 275.591066 0 ] (cb9) [ 99 0 R /XYZ 84.259843 652.281496 0 ] (cb9-1) [ 99 0 R /XYZ 101.433071 650.584475 0 ] (cb9-10) [ 99 0 R /XYZ 99.933071 423.220217 0 ] (cb9-100) [ 204 0 R /XYZ 99.933071 780.226036 0 ] (cb9-101) [ 204 0 R /XYZ 99.933071 761.279014 0 ] (cb9-102) [ 204 0 R /XYZ 99.933071 742.331993 0 ] (cb9-103) [ 204 0 R /XYZ 99.933071 723.384971 0 ] (cb9-104) [ 204 0 R /XYZ 99.933071 704.437950 0 ] (cb9-105) [ 204 0 R /XYZ 99.933071 685.490928 0 ] (cb9-106) [ 204 0 R /XYZ 99.933071 666.543907 0 ] (cb9-107) [ 204 0 R /XYZ 99.933071 609.702842 0 ] (cb9-108) [ 204 0 R /XYZ 99.933071 590.755821 0 ] (cb9-109) [ 204 0 R /XYZ 99.933071 571.808799 0 ] (cb9-11) [ 99 0 R /XYZ 99.933071 404.273195 0 ] (cb9-110) [ 204 0 R /XYZ 99.933071 552.861778 0 ] (cb9-111) [ 204 0 R /XYZ 99.933071 533.914756 0 ] (cb9-112) [ 204 0 R /XYZ 99.933071 514.967735 0 ] (cb9-113) [ 204 0 R /XYZ 99.933071 496.020714 0 ] (cb9-114) [ 204 0 R /XYZ 99.933071 477.073692 0 ] (cb9-115) [ 204 0 R /XYZ 99.933071 458.126671 0 ] (cb9-116) [ 204 0 R /XYZ 99.933071 439.179649 0 ] (cb9-117) [ 204 0 R /XYZ 99.933071 420.232628 0 ] (cb9-118) [ 204 0 R /XYZ 99.933071 401.285606 0 ] (cb9-119) [ 204 0 R /XYZ 99.933071 382.338585 0 ] (cb9-12) [ 99 0 R /XYZ 99.933071 385.326174 0 ] (cb9-120) [ 204 0 R /XYZ 99.933071 363.391563 0 ] (cb9-121) [ 204 0 R /XYZ 99.933071 344.444542 0 ] (cb9-122) [ 204 0 R /XYZ 99.933071 325.497520 0 ] (cb9-123) [ 204 0 R /XYZ 99.933071 306.550499 0 ] (cb9-124) [ 204 0 R /XYZ 99.933071 287.603477 0 ] (cb9-125) [ 204 0 R /XYZ 99.933071 249.709434 0 ] (cb9-126) [ 204 0 R /XYZ 99.933071 230.762413 0 ] (cb9-127) [ 204 0 R /XYZ 99.933071 211.815391 0 ] (cb9-128) [ 204 0 R /XYZ 99.933071 192.868370 0 ] (cb9-129) [ 204 0 R /XYZ 99.933071 173.921348 0 ] (cb9-13) [ 99 0 R /XYZ 99.933071 366.379152 0 ] (cb9-130) [ 204 0 R /XYZ 99.933071 154.974327 0 ] (cb9-131) [ 204 0 R /XYZ 99.933071 136.027305 0 ] (cb9-132) [ 204 0 R /XYZ 99.933071 117.080284 0 ] (cb9-133) [ 204 0 R /XYZ 99.933071 98.133262 0 ] (cb9-134) [ 241 0 R /XYZ 99.933071 799.173057 0 ] (cb9-135) [ 241 0 R /XYZ 99.933071 780.226036 0 ] (cb9-136) [ 241 0 R /XYZ 99.933071 742.331993 0 ] (cb9-137) [ 241 0 R /XYZ 99.933071 723.384971 0 ] (cb9-138) [ 241 0 R /XYZ 99.933071 704.437950 0 ] (cb9-139) [ 241 0 R /XYZ 99.933071 685.490928 0 ] (cb9-14) [ 99 0 R /XYZ 99.933071 347.432131 0 ] (cb9-140) [ 241 0 R /XYZ 99.933071 666.543907 0 ] (cb9-141) [ 241 0 R /XYZ 99.933071 647.596885 0 ] (cb9-142) [ 241 0 R /XYZ 99.933071 628.649864 0 ] (cb9-143) [ 241 0 R /XYZ 99.933071 609.702842 0 ] (cb9-144) [ 241 0 R /XYZ 99.933071 590.755821 0 ] (cb9-145) [ 241 0 R /XYZ 99.933071 571.808799 0 ] (cb9-146) [ 241 0 R /XYZ 99.933071 552.861778 0 ] (cb9-147) [ 241 0 R /XYZ 99.933071 533.914756 0 ] (cb9-148) [ 241 0 R /XYZ 99.933071 514.967735 0 ] (cb9-149) [ 241 0 R /XYZ 99.933071 496.020714 0 ] (cb9-15) [ 99 0 R /XYZ 99.933071 328.485109 0 ] (cb9-150) [ 241 0 R /XYZ 99.933071 477.073692 0 ] (cb9-151) [ 241 0 R /XYZ 99.933071 458.126671 0 ] (cb9-152) [ 241 0 R /XYZ 99.933071 439.179649 0 ] (cb9-153) [ 241 0 R /XYZ 99.933071 420.232628 0 ] (cb9-154) [ 241 0 R /XYZ 99.933071 401.285606 0 ] (cb9-155) [ 241 0 R /XYZ 99.933071 382.338585 0 ] (cb9-156) [ 241 0 R /XYZ 99.933071 363.391563 0 ] (cb9-157) [ 241 0 R /XYZ 99.933071 344.444542 0 ] (cb9-158) [ 241 0 R /XYZ 99.933071 325.497520 0 ] (cb9-159) [ 241 0 R /XYZ 99.933071 306.550499 0 ] (cb9-16) [ 99 0 R /XYZ 99.933071 309.538088 0 ] (cb9-160) [ 241 0 R /XYZ 99.933071 287.603477 0 ] (cb9-161) [ 241 0 R /XYZ 99.933071 268.656456 0 ] (cb9-162) [ 241 0 R /XYZ 99.933071 249.709434 0 ] (cb9-163) [ 241 0 R /XYZ 99.933071 230.762413 0 ] (cb9-164) [ 241 0 R /XYZ 99.933071 211.815391 0 ] (cb9-165) [ 241 0 R /XYZ 99.933071 192.868370 0 ] (cb9-166) [ 241 0 R /XYZ 99.933071 173.921348 0 ] (cb9-167) [ 241 0 R /XYZ 99.933071 154.974327 0 ] (cb9-168) [ 241 0 R /XYZ 99.933071 136.027305 0 ] (cb9-169) [ 241 0 R /XYZ 99.933071 117.080284 0 ] (cb9-17) [ 99 0 R /XYZ 99.933071 290.591066 0 ] (cb9-170) [ 241 0 R /XYZ 99.933071 98.133262 0 ] (cb9-171) [ 280 0 R /XYZ 99.933071 799.173057 0 ] (cb9-172) [ 280 0 R /XYZ 99.933071 780.226036 0 ] (cb9-173) [ 280 0 R /XYZ 99.933071 761.279014 0 ] (cb9-174) [ 280 0 R /XYZ 99.933071 742.331993 0 ] (cb9-175) [ 280 0 R /XYZ 99.933071 723.384971 0 ] (cb9-176) [ 280 0 R /XYZ 99.933071 704.437950 0 ] (cb9-177) [ 280 0 R /XYZ 99.933071 685.490928 0 ] (cb9-178) [ 280 0 R /XYZ 99.933071 666.543907 0 ] (cb9-179) [ 280 0 R /XYZ 99.933071 647.596885 0 ] (cb9-18) [ 99 0 R /XYZ 99.933071 271.644045 0 ] (cb9-180) [ 280 0 R /XYZ 99.933071 628.649864 0 ] (cb9-181) [ 280 0 R /XYZ 99.933071 609.702842 0 ] (cb9-182) [ 280 0 R /XYZ 99.933071 590.755821 0 ] (cb9-183) [ 280 0 R /XYZ 99.933071 571.808799 0 ] (cb9-184) [ 280 0 R /XYZ 99.933071 552.861778 0 ] (cb9-185) [ 280 0 R /XYZ 99.933071 533.914756 0 ] (cb9-186) [ 280 0 R /XYZ 99.933071 514.967735 0 ] (cb9-187) [ 280 0 R /XYZ 99.933071 496.020714 0 ] (cb9-188) [ 280 0 R /XYZ 99.933071 477.073692 0 ] (cb9-189) [ 280 0 R /XYZ 99.933071 458.126671 0 ] (cb9-19) [ 99 0 R /XYZ 99.933071 252.697023 0 ] (cb9-190) [ 280 0 R /XYZ 99.933071 439.179649 0 ] (cb9-191) [ 280 0 R /XYZ 99.933071 420.232628 0 ] (cb9-192) [ 280 0 R /XYZ 99.933071 401.285606 0 ] (cb9-193) [ 280 0 R /XYZ 99.933071 382.338585 0 ] (cb9-194) [ 280 0 R /XYZ 99.933071 363.391563 0 ] (cb9-195) [ 280 0 R /XYZ 99.933071 344.444542 0 ] (cb9-196) [ 280 0 R /XYZ 99.933071 325.497520 0 ] (cb9-197) [ 280 0 R /XYZ 99.933071 306.550499 0 ] (cb9-198) [ 280 0 R /XYZ 99.933071 287.603477 0 ] (cb9-199) [ 280 0 R /XYZ 99.933071 268.656456 0 ] (cb9-2) [ 99 0 R /XYZ 99.933071 612.690432 0 ] (cb9-20) [ 99 0 R /XYZ 99.933071 233.750002 0 ] (cb9-200) [ 280 0 R /XYZ 99.933071 249.709434 0 ] (cb9-201) [ 280 0 R /XYZ 99.933071 230.762413 0 ] (cb9-202) [ 280 0 R /XYZ 99.933071 211.815391 0 ] (cb9-203) [ 280 0 R /XYZ 99.933071 192.868370 0 ] (cb9-204) [ 280 0 R /XYZ 99.933071 173.921348 0 ] (cb9-205) [ 280 0 R /XYZ 99.933071 154.974327 0 ] (cb9-206) [ 280 0 R /XYZ 99.933071 136.027305 0 ] (cb9-207) [ 280 0 R /XYZ 99.933071 117.080284 0 ] (cb9-208) [ 280 0 R /XYZ 99.933071 98.133262 0 ] (cb9-209) [ 320 0 R /XYZ 99.933071 799.173057 0 ] (cb9-21) [ 99 0 R /XYZ 99.933071 214.802980 0 ] (cb9-210) [ 320 0 R /XYZ 99.933071 780.226036 0 ] (cb9-211) [ 320 0 R /XYZ 99.933071 761.279014 0 ] (cb9-212) [ 320 0 R /XYZ 99.933071 742.331993 0 ] (cb9-213) [ 320 0 R /XYZ 99.933071 723.384971 0 ] (cb9-214) [ 320 0 R /XYZ 99.933071 704.437950 0 ] (cb9-215) [ 320 0 R /XYZ 99.933071 685.490928 0 ] (cb9-216) [ 320 0 R /XYZ 99.933071 666.543907 0 ] (cb9-217) [ 320 0 R /XYZ 99.933071 647.596885 0 ] (cb9-218) [ 320 0 R /XYZ 99.933071 628.649864 0 ] (cb9-219) [ 320 0 R /XYZ 99.933071 609.702842 0 ] (cb9-22) [ 99 0 R /XYZ 99.933071 195.855959 0 ] (cb9-220) [ 320 0 R /XYZ 99.933071 590.755821 0 ] (cb9-221) [ 320 0 R /XYZ 99.933071 571.808799 0 ] (cb9-222) [ 320 0 R /XYZ 99.933071 552.861778 0 ] (cb9-223) [ 320 0 R /XYZ 99.933071 533.914756 0 ] (cb9-224) [ 320 0 R /XYZ 99.933071 514.967735 0 ] (cb9-225) [ 320 0 R /XYZ 99.933071 496.020714 0 ] (cb9-226) [ 320 0 R /XYZ 99.933071 477.073692 0 ] (cb9-227) [ 320 0 R /XYZ 99.933071 458.126671 0 ] (cb9-228) [ 320 0 R /XYZ 99.933071 439.179649 0 ] (cb9-229) [ 320 0 R /XYZ 99.933071 420.232628 0 ] (cb9-23) [ 99 0 R /XYZ 99.933071 176.908937 0 ] (cb9-230) [ 320 0 R /XYZ 99.933071 401.285606 0 ] (cb9-231) [ 320 0 R /XYZ 99.933071 382.338585 0 ] (cb9-232) [ 320 0 R /XYZ 99.933071 363.391563 0 ] (cb9-233) [ 320 0 R /XYZ 99.933071 344.444542 0 ] (cb9-234) [ 320 0 R /XYZ 99.933071 325.497520 0 ] (cb9-235) [ 320 0 R /XYZ 99.933071 306.550499 0 ] (cb9-236) [ 320 0 R /XYZ 99.933071 287.603477 0 ] (cb9-237) [ 320 0 R /XYZ 99.933071 268.656456 0 ] (cb9-238) [ 320 0 R /XYZ 99.933071 249.709434 0 ] (cb9-239) [ 320 0 R /XYZ 99.933071 230.762413 0 ] (cb9-24) [ 99 0 R /XYZ 99.933071 157.961916 0 ] (cb9-240) [ 320 0 R /XYZ 99.933071 211.815391 0 ] (cb9-241) [ 320 0 R /XYZ 99.933071 192.868370 0 ] (cb9-242) [ 320 0 R /XYZ 99.933071 173.921348 0 ] (cb9-243) [ 320 0 R /XYZ 99.933071 154.974327 0 ] (cb9-244) [ 320 0 R /XYZ 99.933071 136.027305 0 ] (cb9-245) [ 320 0 R /XYZ 99.933071 117.080284 0 ] (cb9-246) [ 320 0 R /XYZ 99.933071 98.133262 0 ] (cb9-247) [ 360 0 R /XYZ 99.933071 799.173057 0 ] (cb9-248) [ 360 0 R /XYZ 99.933071 780.226036 0 ] (cb9-249) [ 360 0 R /XYZ 99.933071 761.279014 0 ] (cb9-25) [ 99 0 R /XYZ 99.933071 139.014895 0 ] (cb9-250) [ 360 0 R /XYZ 99.933071 742.331993 0 ] (cb9-251) [ 360 0 R /XYZ 99.933071 723.384971 0 ] (cb9-252) [ 360 0 R /XYZ 99.933071 704.437950 0 ] (cb9-253) [ 360 0 R /XYZ 99.933071 685.490928 0 ] (cb9-254) [ 360 0 R /XYZ 99.933071 666.543907 0 ] (cb9-255) [ 360 0 R /XYZ 99.933071 647.596885 0 ] (cb9-256) [ 360 0 R /XYZ 99.933071 628.649864 0 ] (cb9-257) [ 360 0 R /XYZ 99.933071 609.702842 0 ] (cb9-258) [ 360 0 R /XYZ 99.933071 590.755821 0 ] (cb9-259) [ 360 0 R /XYZ 99.933071 571.808799 0 ] (cb9-26) [ 99 0 R /XYZ 99.933071 120.067873 0 ] (cb9-260) [ 360 0 R /XYZ 99.933071 552.861778 0 ] (cb9-261) [ 360 0 R /XYZ 99.933071 533.914756 0 ] (cb9-262) [ 360 0 R /XYZ 99.933071 514.967735 0 ] (cb9-263) [ 360 0 R /XYZ 99.933071 496.020714 0 ] (cb9-264) [ 360 0 R /XYZ 99.933071 477.073692 0 ] (cb9-265) [ 360 0 R /XYZ 99.933071 458.126671 0 ] (cb9-266) [ 360 0 R /XYZ 99.933071 439.179649 0 ] (cb9-267) [ 360 0 R /XYZ 99.933071 420.232628 0 ] (cb9-268) [ 360 0 R /XYZ 99.933071 401.285606 0 ] (cb9-269) [ 360 0 R /XYZ 99.933071 382.338585 0 ] (cb9-27) [ 99 0 R /XYZ 99.933071 101.120852 0 ] (cb9-270) [ 360 0 R /XYZ 99.933071 363.391563 0 ] (cb9-271) [ 360 0 R /XYZ 99.933071 344.444542 0 ] (cb9-272) [ 360 0 R /XYZ 99.933071 325.497520 0 ] (cb9-273) [ 360 0 R /XYZ 99.933071 306.550499 0 ] (cb9-274) [ 360 0 R /XYZ 99.933071 287.603477 0 ] (cb9-275) [ 360 0 R /XYZ 99.933071 268.656456 0 ] (cb9-276) [ 360 0 R /XYZ 99.933071 249.709434 0 ] (cb9-277) [ 360 0 R /XYZ 99.933071 230.762413 0 ] (cb9-278) [ 360 0 R /XYZ 99.933071 211.815391 0 ] (cb9-279) [ 360 0 R /XYZ 99.933071 192.868370 0 ] (cb9-28) [ 129 0 R /XYZ 99.933071 799.173057 0 ] (cb9-280) [ 360 0 R /XYZ 99.933071 173.921348 0 ] (cb9-281) [ 360 0 R /XYZ 99.933071 154.974327 0 ] (cb9-282) [ 360 0 R /XYZ 99.933071 136.027305 0 ] (cb9-283) [ 360 0 R /XYZ 99.933071 117.080284 0 ] (cb9-284) [ 360 0 R /XYZ 99.933071 98.133262 0 ] (cb9-29) [ 129 0 R /XYZ 99.933071 780.226036 0 ] (cb9-3) [ 99 0 R /XYZ 99.933071 574.796389 0 ] (cb9-30) [ 129 0 R /XYZ 99.933071 761.279014 0 ] (cb9-31) [ 129 0 R /XYZ 99.933071 742.331993 0 ] (cb9-32) [ 129 0 R /XYZ 99.933071 723.384971 0 ] (cb9-33) [ 129 0 R /XYZ 99.933071 704.437950 0 ] (cb9-34) [ 129 0 R /XYZ 99.933071 685.490928 0 ] (cb9-35) [ 129 0 R /XYZ 99.933071 666.543907 0 ] (cb9-36) [ 129 0 R /XYZ 99.933071 647.596885 0 ] (cb9-37) [ 129 0 R /XYZ 99.933071 628.649864 0 ] (cb9-38) [ 129 0 R /XYZ 99.933071 609.702842 0 ] (cb9-39) [ 129 0 R /XYZ 99.933071 590.755821 0 ] (cb9-4) [ 99 0 R /XYZ 99.933071 555.849367 0 ] (cb9-40) [ 129 0 R /XYZ 99.933071 571.808799 0 ] (cb9-41) [ 129 0 R /XYZ 99.933071 552.861778 0 ] (cb9-42) [ 129 0 R /XYZ 99.933071 533.914756 0 ] (cb9-43) [ 129 0 R /XYZ 99.933071 514.967735 0 ] (cb9-44) [ 129 0 R /XYZ 99.933071 496.020714 0 ] (cb9-45) [ 129 0 R /XYZ 99.933071 477.073692 0 ] (cb9-46) [ 129 0 R /XYZ 99.933071 458.126671 0 ] (cb9-47) [ 129 0 R /XYZ 99.933071 439.179649 0 ] (cb9-48) [ 129 0 R /XYZ 99.933071 420.232628 0 ] (cb9-49) [ 129 0 R /XYZ 99.933071 401.285606 0 ] (cb9-5) [ 99 0 R /XYZ 99.933071 536.902346 0 ] (cb9-50) [ 129 0 R /XYZ 99.933071 382.338585 0 ] (cb9-51) [ 129 0 R /XYZ 99.933071 363.391563 0 ] (cb9-52) [ 129 0 R /XYZ 99.933071 344.444542 0 ] (cb9-53) [ 129 0 R /XYZ 99.933071 325.497520 0 ] (cb9-54) [ 129 0 R /XYZ 99.933071 306.550499 0 ] (cb9-55) [ 129 0 R /XYZ 99.933071 287.603477 0 ] (cb9-56) [ 129 0 R /XYZ 99.933071 268.656456 0 ] (cb9-57) [ 129 0 R /XYZ 99.933071 249.709434 0 ] (cb9-58) [ 129 0 R /XYZ 99.933071 230.762413 0 ] (cb9-59) [ 129 0 R /XYZ 99.933071 211.815391 0 ] (cb9-6) [ 99 0 R /XYZ 99.933071 499.008303 0 ] (cb9-60) [ 129 0 R /XYZ 99.933071 192.868370 0 ] (cb9-61) [ 129 0 R /XYZ 99.933071 173.921348 0 ] (cb9-62) [ 129 0 R /XYZ 99.933071 154.974327 0 ] (cb9-63) [ 129 0 R /XYZ 99.933071 136.027305 0 ] (cb9-64) [ 129 0 R /XYZ 99.933071 117.080284 0 ] (cb9-65) [ 129 0 R /XYZ 99.933071 98.133262 0 ] (cb9-66) [ 169 0 R /XYZ 99.933071 799.173057 0 ] (cb9-67) [ 169 0 R /XYZ 99.933071 780.226036 0 ] (cb9-68) [ 169 0 R /XYZ 99.933071 761.279014 0 ] (cb9-69) [ 169 0 R /XYZ 99.933071 742.331993 0 ] (cb9-7) [ 99 0 R /XYZ 99.933071 480.061281 0 ] (cb9-70) [ 169 0 R /XYZ 99.933071 723.384971 0 ] (cb9-71) [ 169 0 R /XYZ 99.933071 704.437950 0 ] (cb9-72) [ 169 0 R /XYZ 99.933071 685.490928 0 ] (cb9-73) [ 169 0 R /XYZ 99.933071 666.543907 0 ] (cb9-74) [ 169 0 R /XYZ 99.933071 647.596885 0 ] (cb9-75) [ 169 0 R /XYZ 99.933071 628.649864 0 ] (cb9-76) [ 169 0 R /XYZ 99.933071 514.967735 0 ] (cb9-77) [ 169 0 R /XYZ 99.933071 496.020714 0 ] (cb9-78) [ 169 0 R /XYZ 99.933071 477.073692 0 ] (cb9-79) [ 169 0 R /XYZ 99.933071 458.126671 0 ] (cb9-8) [ 99 0 R /XYZ 99.933071 461.114260 0 ] (cb9-80) [ 169 0 R /XYZ 99.933071 439.179649 0 ] (cb9-81) [ 169 0 R /XYZ 99.933071 420.232628 0 ] (cb9-82) [ 169 0 R /XYZ 99.933071 401.285606 0 ] (cb9-83) [ 169 0 R /XYZ 99.933071 382.338585 0 ] (cb9-84) [ 169 0 R /XYZ 99.933071 363.391563 0 ] (cb9-85) [ 169 0 R /XYZ 99.933071 344.444542 0 ] (cb9-86) [ 169 0 R /XYZ 99.933071 325.497520 0 ] (cb9-87) [ 169 0 R /XYZ 99.933071 306.550499 0 ] (cb9-88) [ 169 0 R /XYZ 99.933071 287.603477 0 ] (cb9-89) [ 169 0 R /XYZ 99.933071 268.656456 0 ] (cb9-9) [ 99 0 R /XYZ 99.933071 442.167238 0 ] (cb9-90) [ 169 0 R /XYZ 99.933071 249.709434 0 ] (cb9-91) [ 169 0 R /XYZ 99.933071 230.762413 0 ] (cb9-92) [ 169 0 R /XYZ 99.933071 211.815391 0 ] (cb9-93) [ 169 0 R /XYZ 99.933071 192.868370 0 ] (cb9-94) [ 169 0 R /XYZ 99.933071 173.921348 0 ] (cb9-95) [ 169 0 R /XYZ 99.933071 154.974327 0 ] (cb9-96) [ 169 0 R /XYZ 99.933071 136.027305 0 ] (cb9-97) [ 169 0 R /XYZ 99.933071 117.080284 0 ] (cb9-98) [ 169 0 R /XYZ 99.933071 98.133262 0 ] (cb9-99) [ 204 0 R /XYZ 99.933071 799.173057 0 ] (configure-default-service-account) [ 53 0 R /XYZ 84.259843 561.590928 0 ] (configure-etcd-user-and-group) [ 45 0 R /XYZ 84.259843 283.686971 0 ] (configure-kernel-runtime-parameters) [ 45 0 R /XYZ 84.259843 539.222079 0 ] (configure-network-policy) [ 67 0 R /XYZ 84.259843 599.840928 0 ] (contentsbox) [ 8 0 R /XYZ 77.509843 756.850394 0 ] (create-etcd-user-and-group) [ 45 0 R /XYZ 84.259843 169.788971 0 ] (ensure-that-all-namespaces-have-network-policies-defined) [ 67 0 R /XYZ 84.259843 564.092928 0 ] (header_bottom_text) [ 6 0 R /XYZ 85.009843 422.718898 0 ] (known-issues) [ 45 0 R /XYZ 84.259843 799.370079 0 ] (overview) [ 30 0 R /XYZ 84.259843 272.631496 0 ] (reference-hardened-cloud-config-configuration) [ 515 0 R /XYZ 84.259843 385.582628 0 ] (reference-hardened-cloud-config-for-red-hat-enterprise-linux-8-rhel-8-and-ubuntu-20.04-lts) [ 538 0 R /XYZ 84.259843 360.287606 0 ] (reference-hardened-cloud-config-for-suse-linux-enterprise-server-15-sles-15-and-opensuse-leap-15) [ 515 0 R /XYZ 84.259843 245.434628 0 ] (reference-hardened-rke-cluster.yml-configuration) [ 77 0 R /XYZ 84.259843 191.441066 0 ] (reference-hardened-rke-template-configuration) [ 400 0 R /XYZ 84.259843 799.370079 0 ] (set-automountserviceaccounttoken-to-false-for-default-service-accounts) [ 53 0 R /XYZ 84.259843 522.092928 0 ] (title-block-header) [ 6 0 R /XYZ 84.259843 502.818898 0 ] ] +>> +>> +>> +endobj +4 0 obj +<< +/ExtGState << +/a1.0 << +/ca 1 +>> +/A1.0 << +/CA 1 +>> +>> +/XObject << +>> +/Pattern << +>> +/Shading << +>> +/Font 621 0 R +>> +endobj +5 0 obj +<< +/Filter /FlateDecode +/Length 2579 +>> +stream +xˎd 602%R^I N"b\AOqy:UT?.tw9⑨Yz-V/oONj=|b5؊.j˩ ^4ϧ}q5Bk%|2 kLT *JT9ZS.DUb#T0#WK0Úg Q`Fј +fĖ+QE1P 3MDs(t)-5ŚN5j1Gk &2lLze[PlI^*lIFt[]NuEDkrs3kЉW%!0]!7갣H]-Er:ؒU)l1ZnM}whd [RFu +lZBc@5XK \9@VeH-+2DRd P- +#FbعT[c&؂%2(hknMZd,P$pa0(^@\Rc,P0WNt+cKb,P`W cjQ UŕT[cX`Fb%jJHX`nr1wSEݔ,r)Kb,0p7Y*p] $t%e,BBZXȞBV 2Gu-Ċ'b) TX]  2ݘ0dpyCf,;-DR]  2 ,%D P] pXAXP]XP]ɪCCuE=1 ۖi$AHtD0Ӂ"1pMƂR 9c ȂcAq XP@J@;3T YT[cд9cAMESb, e`,@FZDMwd YfXPsA=YeWX jP PKǦg,CO `t j-*E2sI6c2]bd,[ 2xrTE QKbΤיXVBO MPiT[ O/3c(sh6Mg,p-Ic|כ lAXФ&3Љ071`_z +Mxd6-ެ`KFBuIS#LB :1]-cA+כX4&2zz$ެ db:pia,@&2[V +3^q:=17##{*=3HfBO VB E>fL>GTP3l~|O_A=_'ej֥\ow~~\?&s;Qeц2=cb7 }᧞<<|dW髾Z;uRpޞ_=po R$bE)hcr4ٯѯ[.!A~qx6= DzTcӉu?aj^T3`9YwP'tֶ\2"ގXKF;)\Pz"\ЏO@^`}i}[Dzoݩ;UIMX[:hvYRcz1!+w|\zӥָw, 6>"lƞ\ϲ#`bl`@\DqʼJBv9ExZ{޶ys-IYqY1Hhu_LGqzAx`zki +6놶]7\~TU6a~6'^?̩+K8Mߧ.n?-燄՗g*PVcvL7ڔs.u"ˉ_ɸa1~[_>f6DJץm2ex";&mW`57Ax9!)W;/VH u,YR䟷 WT)9ޠ(jf }oN$2clwX} ߡ;{nSkuHMx܋)3Y e8OW~/;ܪY`%n}Lv>:W҈ԥf[[7[mw?{{u\҉)}ޥtKh9zy {t&9kknR_:}PAGLlޱ1-;:s%i鼯ʜļJy;"̖t&@yw纞NVϙK:)Sql{D )+3uY~YClX:N00D7XoGq> +endobj +7 0 obj +<< +/Filter /FlateDecode +/Length 3520 +>> +stream +xMo$+l`$@8}r6)n)4YoMj$!ZwUdU=$5-EwIN)r~8}:5zE`{;¿ƻ՛}^tԫ):j6艭GzzaQ"uPkжX芭GT?޲ߘl(%C=Q樊tF4ND>НND'ud(Euw5NEMI DAʝHX ꜯW@#^JTQ DAP=6ΣG~e1"AatQ2iMD`y0|@yr< DAǒfByЃ<m#ՏK< (21NDx-*ŞчΈ&щ!GщD6!e]H]EQ? Jt4XpԹ n4^] +:жu="ʑ[4&[!;Bw":F׹*ʺD*5yv"N?zars KD>a?K.Msc< +բm pȑ[-d*0G`y=t)uyH2ָ٣PE p|"ՏK< (ND'DoEDECgDщD݉Dt"w[{aa ެ.bv=^?o:xo\s{2i( aym>wN>Q*)k@GQ;\ۚ2غӐDHcDnzUn5i:k˖ԑʽNUӎއ5bZ\un[bk\#]Rm1U&\PC@͵JP7 Oe9';=Cт&'jL5Tf5x2Ug{]+6,zhE@m!\:V/T}t[1B@vLRmnU2EU;AX U*,h(wyrlA:x6w-O FՎIeF7f's{ɐVӶM.˰TF^KmmqzYǍjisq%3>)ذ8Y։Z m7kǧ+kKfPEs A6txbȼ47`_mziUp8t=K&4%ޥ Z>\݂Q:{&Y +З;L-{Y4]mi8iaitE:}rMMG mv; 9v)^Pe=69o-85i{N]ՄӺP4Uf1>mĩDY n]nɶ r<:-^2ug7qK[o'}va8HM-t/k%nan=(Z%N +]54}792MD頋vztO N˪;sjonwra,>'g˦ /9 +endstream +endobj +8 0 obj +<< +/Type /Page +/Parent 1 0 R +/MediaBox [ 0 0 595.275591 841.889764 ] +/Contents 7 0 R +/Resources 4 0 R +/Annots [ 9 0 R 10 0 R 11 0 R 12 0 R 13 0 R 14 0 R 15 0 R 16 0 R 17 0 R 18 0 R 19 0 R 20 0 R 21 0 R 22 0 R 23 0 R 24 0 R 25 0 R 26 0 R 27 0 R 28 0 R ] +/TrimBox [ 0 0 595.275591 841.889764 ] +/BleedBox [ 0 0 595.275591 841.889764 ] +>> +endobj +9 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 76.423228 671.061024 504.679134 638.361024 ] +/BS << +/W 0 +>> +/Dest (overview) +>> +endobj +10 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 489.361263 663.111024 496.429134 648.111024 ] +/BS << +/W 0 +>> +/Dest (overview) +>> +endobj +11 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 76.423228 626.361024 504.679134 593.661024 ] +/BS << +/W 0 +>> +/Dest (configure-kernel-runtime-parameters) +>> +endobj +12 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 488.881526 618.411024 496.429134 603.411024 ] +/BS << +/W 0 +>> +/Dest (configure-kernel-runtime-parameters) +>> +endobj +13 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 76.423228 581.661024 504.679134 548.961024 ] +/BS << +/W 0 +>> +/Dest (configure-etcd-user-and-group) +>> +endobj +14 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 146.805601 573.711024 177.256773 554.961024 ] +/BS << +/W 0 +>> +/Dest (configure-etcd-user-and-group) +>> +endobj +15 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 488.881526 573.711024 496.429134 558.711024 ] +/BS << +/W 0 +>> +/Dest (configure-etcd-user-and-group) +>> +endobj +16 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 76.423228 536.961024 504.679134 504.261024 ] +/BS << +/W 0 +>> +/Dest (configure-default-service-account) +>> +endobj +17 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 146.805601 529.011024 197.845152 510.261024 ] +/BS << +/W 0 +>> +/Dest (configure-default-service-account) +>> +endobj +18 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 488.893245 529.011024 496.429134 514.011024 ] +/BS << +/W 0 +>> +/Dest (configure-default-service-account) +>> +endobj +19 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 76.423228 492.261024 504.679134 459.561024 ] +/BS << +/W 0 +>> +/Dest (configure-network-policy) +>> +endobj +20 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 488.809749 484.311024 496.429134 469.311024 ] +/BS << +/W 0 +>> +/Dest (configure-network-policy) +>> +endobj +21 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 76.423228 447.561024 504.679134 414.861024 ] +/BS << +/W 0 +>> +/Dest (reference-hardened-rke-cluster.yml-configuration) +>> +endobj +22 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 234.738707 439.611024 313.229430 420.861024 ] +/BS << +/W 0 +>> +/Dest (reference-hardened-rke-cluster.yml-configuration) +>> +endobj +23 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 489.877620 439.611024 496.429134 424.611024 ] +/BS << +/W 0 +>> +/Dest (reference-hardened-rke-cluster.yml-configuration) +>> +endobj +24 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 76.423228 402.861024 504.679134 370.161024 ] +/BS << +/W 0 +>> +/Dest (reference-hardened-rke-template-configuration) +>> +endobj +25 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 484.970394 394.911024 496.429134 379.911024 ] +/BS << +/W 0 +>> +/Dest (reference-hardened-rke-template-configuration) +>> +endobj +26 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 76.423228 358.161024 504.679134 325.461024 ] +/BS << +/W 0 +>> +/Dest (reference-hardened-cloud-config-configuration) +>> +endobj +27 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 210.896178 350.211024 288.867613 335.211024 ] +/BS << +/W 0 +>> +/Dest (reference-hardened-cloud-config-configuration) +>> +endobj +28 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 485.030452 350.211024 496.429134 335.211024 ] +/BS << +/W 0 +>> +/Dest (reference-hardened-cloud-config-configuration) +>> +endobj +29 0 obj +<< +/Filter /FlateDecode +/Length 4946 +>> +stream +x]K$qׯ# 2 F3m F"+I3#{V ;f0{62)"/O_NfJyp1?'5`K >MzVr_gǞTJt6#O)d*`VSJ.DKXP#$re%A%5ȹ2߲ +pɒƂ!N0E8=j'\ !TtD/YÂ䠋wN Z LŢVS԰H6BaA +1xUE7Vy<4,H&,V쥦װ?qaϒ@XЙk< ]dkXN%v);lMg=hDc/'Aw葁בGt1#  E#W M皎n3T/e7:қbF)ߗӟ/%K󙚵ќ0JŊgr'B3 2$rØ e'ʘ ƬX{ԹR\; |raBɅ8b[F ~'Y/f}Ԥ +_N|KI6窪|>Ab:]ʑyЅYGIE|孋7ȵ׿eE hs,>s]/l҅Yt-w3K-F=bzCWsv_Cا ^6]D.iхô4ges:j"a̍=" {Q+ˁGVEQ#םxޱGvBēO$foӅx"_A/=_أ ;Ca밆x ?>]X.0j =|"~}?=s + }g4[{ta +=B}N<أ ;w!}~}i9з|{=bwх໌׻vO5C|c.߅7v?l\gQآb ̏+|/c|2>bL<~-82?6&O v?7Je.5^nc?l6/Ɣeް\Z]dۛy?vOHGoObCϲBCzY~Hg[n=s?o2Bs=,dž::O+I~G[oYޡ_Ưn/-q.wTmɕt|5/bҚ?iɽ4|o8|ǡfU_m\~|޹j==.8 d]TЛnC5+6Uk_xɼo1>Z#Vy(n=n+]ȂD/ּRQgkyfܮ G84?;7Ǚ*+ͶShݝ={Vjk!4nDNcY[^}>{x|8U쟷~`J}YrFn6r\}6Coѓ|6OsJs~kE훩u㍽xgû'PǍ/׵w¾W~q˴5"5}gYk?>쭸@s>b.YV?_-ΖS/`+lN?њoZ$7|>êu-mr] ]If!8K^^Z^_sazG1xI!d.s6q0 342SS~ebD0AWr٨\rnX(*n|qpP&NHg^%T -ZȨ 3y #$c*/HƓs+=-} 8_5_^,od Mo4539zі2Q?mCfiȶÛJ,2G"k?PC4DڹMqg[2[o&yUlXu $9 7%[o1lFLɎ>"\;.]gEXD8kUH]RQCB-N +rRߘ*Q7݈&qSH:nZRzSxv_s.jHk"^x9jSHб„zFΦK\]Ҭ4$Ш8h;zەݑ6Μ>u:LC װu ˕Ξ$+ :6fC[ǝxMvӁ AmJb>dRY/<[#vqߡմ* mp;%,D⊇%\rF\H٠&'' +s F<ˬ]ibZ`//`r2(zsc6hoԫ6ØO2mg=dyQ{594zkAÅQAe@R օhҚTum-YRj=EUz:Ȩ4'r׺% 9uLzɬТQƹj{fPW$f5Qj +Q#ac> +endobj +31 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 84.259843 445.281496 409.271317 430.281496 ] +/BS << +/W 0 +>> +/A << +/Type /Action +/S /URI +/URI (https://releases.rancher.com/documents/security/2.6/Rancher_v2-6_CIS_v1-6_Hardening_Guide.pdf) +>> +>> +endobj +32 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 107.173228 418.281496 162.214732 403.281496 ] +/BS << +/W 0 +>> +/Dest (overview) +>> +endobj +33 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 107.173228 403.281496 332.953990 388.281496 ] +/BS << +/W 0 +>> +/Dest (configure-kernel-runtime-parameters) +>> +endobj +34 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 107.173228 386.659914 295.486949 371.659914 ] +/BS << +/W 0 +>> +/Dest (configure-etcd-user-and-group) +>> +endobj +35 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 169.605601 388.281496 200.056773 369.531496 ] +/BS << +/W 0 +>> +/Dest (configure-etcd-user-and-group) +>> +endobj +36 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 107.173228 367.909914 319.724254 352.909914 ] +/BS << +/W 0 +>> +/Dest (configure-default-service-account) +>> +endobj +37 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 169.605601 369.531496 220.645152 350.781496 ] +/BS << +/W 0 +>> +/Dest (configure-default-service-account) +>> +endobj +38 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 107.173228 350.781496 255.796275 335.781496 ] +/BS << +/W 0 +>> +/Dest (configure-network-policy) +>> +endobj +39 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 107.173228 317.031496 400.593883 302.031496 ] +/BS << +/W 0 +>> +/Dest (reference-hardened-rke-template-configuration) +>> +endobj +40 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 107.173228 302.031496 397.449596 287.031496 ] +/BS << +/W 0 +>> +/Dest (reference-hardened-cloud-config-configuration) +>> +endobj +41 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 233.696178 302.031496 311.667613 287.031496 ] +/BS << +/W 0 +>> +/Dest (reference-hardened-cloud-config-configuration) +>> +endobj +42 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 293.575760 126.231496 442.798661 111.231496 ] +/BS << +/W 0 +>> +/A << +/Type /Action +/S /URI +/URI (file:///doc_tools/%7B%7B%3Cbaseurl%3E%7D%7D/rancher/v2.6/en/security/hardening-guides/1.6-benchmark-2.6/) +>> +>> +endobj +43 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 84.259843 111.231496 285.368241 96.231496 ] +/BS << +/W 0 +>> +/A << +/Type /Action +/S /URI +/URI (file:///doc_tools/%7B%7B%3Cbaseurl%3E%7D%7D/rancher/v2.6/en/security/hardening-guides/1.6-benchmark-2.6/) +>> +>> +endobj +44 0 obj +<< +/Filter /FlateDecode +/Length 5107 +>> +stream +x\I$9ׯ3R7 !"`ئġH^"3#L+i;bIgşw+L)5':_>u&G;6K7dzMt5x̄Mt~9KyO?8sǝ5y(\rQih.(M1}LJSrKUk1cSTKԚy_6eMlHkƬ49 >Vm#(xE ygRmm.{-2贶jRJhm^bNk%:" +%km ^|AkC:Ui+U6buZ[ &BUْ˱hb jmΙ jvKm%뵶^6D ezE}& @^lN`% |Ά' | + |r  5֡; /UKaA7hXx4,@[hXdӰ oɺaAMaA→HÂȅ)U 07;5,]laAꆘ$ p7p7T X  pkXaҰb|)VbI e=4, ஏX湁>Zaw=a  w!Q V{a3a*ܟVƕ4,]W>!qeBƥT5,]8aA>x5,]ੵ6jX0hXfmZ X [$j[60$aXġ$.{հ wm AÂܵGm/x נ VV@ + k4wUÂeaALE0h{ R!SsNjцOmKQÂlA, P& XjѰ {װ {AD:Djz^`.j~@@2S*9&c֖)paAdȥLװo8\Ұl͑l L̵6^dkXHmiXP[ +'pZoe7,_s+_˴%vC|Z/t=7_3ۘ9l! (+ ߡ? +[l<5.B<^luZx>7ekzgƾ8N-|ƇErQQ/,xy4aR~=8w[}]M9ڮQ(k&שŊp]WyΣ+z8Cd ޹ %u,"!P0g%oVWar/z<72U+Lx~~zf r`! | +HaBfI=}}-_föX=|z0B*ch)%'2C^ ;W;.N:}J_(bxٜS潷nM&џuj0+f=tiMT-JpLunب Ǡ埄֘ibHE>U}^&ncj7r|襝޾?OoR~> ++ľ_n5}/&IdL)kۦc^tKs#?Rf2;`Z +?4YssOy6@/sm޹E[jm}v}`kcW9N>K|r+J#sY*p,c/gL1*qB_5X!; 3>?Lj1l5t_%i;zo=9vtu.1L~s`5j{;U3>l@;o ׀><; +=(";4;3CK7'*ư ظ8ʼnn (BNXE?f@QY.jth+|; kIY Vj9a9χ,E>o ~bzfvӹ:o6/o{e^ ;Ovܪb)Q0urdFHg {.GNݴ&i ƥ>ϊEn9:);._פasJ-[ <_>WkNukvlnj5Q<UgpWn\: ^JQ{Ψ>#5o,#Ⱦ\{{ #>췔CJ{i㉚-oTH+80uܱ!\Eg+[}^[|Ӧ蠻]9YچzǺVwY)G#Cxyv2ף*%u7ǁ*t"+7 W +]|;nhǠo+RO ~ы5nr)g]MN.9v@Uۙg}܌;|u}gݳo[* Yj-BA _|r))s܁/!*}_/NgsΏ>ݒs3έu=Y;SѶ[G-ױg#,}i5 ۳]y-V3(~lq^7^Fs#(dNJ⟘)ц{#߈Ǎ%,9ȕoz^;rE{K4θcى^sKDǶ{˝mtXxAv/Cn!P㵷v8?JscjõqvrLG1W?f/tҽ[>bYv#,z x\ʴ#ˋvj_uI=Y>Gerb_N)dA2O;"7@.'K;C40ľ{7~MWl +=;yָFOUyqH9x&1VL7ɞ:??2D&q.E> u"^N6/*?$ՇETiA0U5;BhI!]N +C9څ|tCq_)I̮K~2M=!xvշߨ{ĆsKWr4v$bV+l'A;N{T3MTؚ3Pg.՜r䭐$= !M|;aR^tCbc4cKv!g`$8LeC|ƱU%'=q'9 |<421N,d6'do d 0F_r߭dǽ~Zܜsʑ㏥ȝ{~8uՏ{;lݐ'A2jǶDO'ٕyo0ivn  ]<1$o/;)@Ku3zץs \K>!qŷNV#.䠸نM6H9=OR"0hY9t- B59V0zo,:}P_$u,tjX.r/wJh #ș[c6*evk7D9)uf(\f;m;OubYV\T)SLߥbZI{;OZz9:;dQhITwN;M۹=ed$np5{G}WkSpe~ +\>,(%%`)2QxDZkr&r6;ؼ 1TޭZuI @)L; VSEx࠷7Q+V9?j\K +endstream +endobj +45 0 obj +<< +/Type /Page +/Parent 1 0 R +/MediaBox [ 0 0 595.275591 841.889764 ] +/Contents 44 0 R +/Resources 4 0 R +/Annots [ 46 0 R 47 0 R 48 0 R 49 0 R 50 0 R 51 0 R ] +/TrimBox [ 0 0 595.275591 841.889764 ] +/BleedBox [ 0 0 595.275591 841.889764 ] +>> +endobj +46 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 191.048717 658.622079 244.661998 643.622079 ] +/BS << +/W 0 +>> +/A << +/Type /Action +/S /URI +/URI (file:///doc_tools/%7B%7B%3Cbaseurl%3E%7D%7D/rancher/v2.6/en/admin-settings/pod-security-policies/) +>> +>> +endobj +47 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 101.433071 439.875057 101.433071 421.125057 ] +/BS << +/W 0 +>> +/Dest (cb1-1) +>> +endobj +48 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 420.928036 99.933071 402.178036 ] +/BS << +/W 0 +>> +/Dest (cb1-2) +>> +endobj +49 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 401.981014 99.933071 383.231014 ] +/BS << +/W 0 +>> +/Dest (cb1-3) +>> +endobj +50 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 383.033993 99.933071 364.283993 ] +/BS << +/W 0 +>> +/Dest (cb1-4) +>> +endobj +51 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 364.086971 99.933071 345.336971 ] +/BS << +/W 0 +>> +/Dest (cb1-5) +>> +endobj +52 0 obj +<< +/Filter /FlateDecode +/Length 4933 +>> +stream +x]K$qׯ和 0 @ {- ; fY+3̨^FwUF ~A2s?ɹח/\I_-?7Lp%pYL*xx\smw]L)٠ +X֑ +CTXb) bĞ1䠱 {VёU O5p%$,pZA,3y炉Pzxޙ/*/xD&&vibb!k<,Xd j<”Ƌ"YY|NdNQxʃ,6Z +P2+ٜm0!Y MRyQ,ц K 5AƏNJ9+&KN}bY0Yl`% |Jg |&Ù>)ñ$ :Ӏ,d 5$ Y3WA*ayȂAϤam֢anaoٺap!հ#kX@\RѰ԰IR^awհD X!IIby 0v5,հ>[ְ>d0I[<7p5,`g5,U. $djX' ИK4,]W9 2.aASyŸ+Z6.ƢaAQ  <װ wSk#ˌVxhPc+yfְ s4*jXiLH `B$A$?H6]d:f[JuQ;Ug+f率TiMw.&5!IS:oٹߡ$M֧뼹^3 8%Ug+f'Ӥ}[H{߾ X:uNo<w?_G^/?d6O'"G$_:zLX{Ƶ>q^zeiBkq;<[d-tA_Fg.jm0HၡLj:~ewFoo)|w9`'e:lsԩ)O-9kATltjL 5> p+h_i p2t~~g1 CuڔW/@9MAZjX w?7!;1]@-Y5K-uC䭉Tc۬26>Y`mۼ}Y g tYxMn6r)M?bzcAx{e异"C^GU y-9Z/$E@G*_z8ea7"'_-{:$v\ sbQ(nSU q4ѫW(]?oaˀ"[Gr =/M܃;Y:9:ݓCANv DD~l ݝی=>;'GkGIJ[s&ucR BNN&dN?m=eVOձ3fGv_Ni87עSo1)$wGG ,xky/?˟~a^aN[_ͥeTഷd=#n37),>R0u]7FoτRږ̮GuT^6aHlΡuި[x鞦տ^vӸ׬I'c%lc*4wXa{?Mi; +@;ձqTVW4YQ~euk[}m07rgy_:;s>>Ҏ(&=ޝ/7p}ڳSc|ogx.:΍~}| <EmQb3Qv ɱGbZU>Wc6hryxo}OVa]1sjhRv4Q'ƌ<}KAmM0MLxN`ul?ǜNVn&y|3vdH%ңmݓu"\IȀeiE=&Sc9`IO8Ik=%{S $aȢN-QN>G%hW8VvT;ٜ r̤o6ǣ{܇-lT{s'Bξl!uN3zJOC9npN_F)!9$/Gd]JBU>_-⚼զ-v5hgzTL<+onn}n\w_Sy:_k<( H{b{J8k{=?O ҅B"L'n6"F?9#/IWOT0V9j +KJWgrJCv[mz.Շm'Y>|W/X[z(kXe*Wy+DYW7j֗K_"I^Q?_EP1.Y[]f+9v1/:V ׯŮgjrgʾ$R~ogv\5VM)TұBDd{kJ!Zb%&3AˎGŇd1vn=7y/.b}V/tK{G*okM5zi4 U:5}@Bz(olk1?\!q/WZ9rQ˵%}R/G4?DN+^Lt#-Yc- ;/}&KHJ0†fz3v;9a/eUfɛ/Syݤ$WULuXӀ4N%0:vJy^klCT6Si Huؒ]NkX9m rqCr>UE7{rq&>sdRbu2Ȓ 6M!@a~6[;:IuL2\vnSGrf9:rE?.|ev[7ٓ{XI<ӈ}LDˣlhM쭤:w&ÉzGfN=ܱ{vs@(/jRb\ᒯSå~Q\N!FL1ȹz硐b +#nzS4_ ;-y?yz}"6ڡS?~cB퀧S^e9T`lwhEܣ䌩1B \6:QshNpmbj2ŵZSKj)bP6k:̣ҕQnx=ZٜӸ;;JX2+8T%ю}mm$ԎjPST+.+C\"O}6 ay%i<-i<]q%q=a8 &EFy̘jk^XS3`^jj[reTQDOfyn{\,ԟR +endstream +endobj +53 0 obj +<< +/Type /Page +/Parent 1 0 R +/MediaBox [ 0 0 595.275591 841.889764 ] +/Contents 52 0 R +/Resources 4 0 R +/Annots [ 54 0 R 55 0 R 56 0 R 57 0 R 58 0 R 59 0 R 60 0 R 61 0 R 62 0 R 63 0 R 64 0 R 65 0 R ] +/TrimBox [ 0 0 595.275591 841.889764 ] +/BleedBox [ 0 0 595.275591 841.889764 ] +>> +endobj +54 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 101.433071 751.923057 101.433071 733.173057 ] +/BS << +/W 0 +>> +/Dest (cb2-1) +>> +endobj +55 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 732.976036 99.933071 714.226036 ] +/BS << +/W 0 +>> +/Dest (cb2-2) +>> +endobj +56 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 101.433071 653.081993 101.433071 634.331993 ] +/BS << +/W 0 +>> +/Dest (cb3-1) +>> +endobj +57 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 634.134971 99.933071 615.384971 ] +/BS << +/W 0 +>> +/Dest (cb3-2) +>> +endobj +58 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 615.187950 99.933071 596.437950 ] +/BS << +/W 0 +>> +/Dest (cb3-3) +>> +endobj +59 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 596.240928 99.933071 577.490928 ] +/BS << +/W 0 +>> +/Dest (cb3-4) +>> +endobj +60 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 101.433071 280.647907 101.433071 261.897907 ] +/BS << +/W 0 +>> +/Dest (cb4-1) +>> +endobj +61 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 101.433071 215.950885 101.433071 197.200885 ] +/BS << +/W 0 +>> +/Dest (cb5-1) +>> +endobj +62 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 197.003864 99.933071 178.253864 ] +/BS << +/W 0 +>> +/Dest (cb5-2) +>> +endobj +63 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 178.056842 99.933071 159.306842 ] +/BS << +/W 0 +>> +/Dest (cb5-3) +>> +endobj +64 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 159.109821 99.933071 140.359821 ] +/BS << +/W 0 +>> +/Dest (cb5-4) +>> +endobj +65 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 140.162799 99.933071 121.412799 ] +/BS << +/W 0 +>> +/Dest (cb5-5) +>> +endobj +66 0 obj +<< +/Filter /FlateDecode +/Length 4925 +>> +stream +x\[$m~_V u  lǃ!Ù<$X}ά"K*q3ԜzŚ-kg?ǫMt5x !\v_Cy?qw] (\rQaU ++FIa%gZ5ĈiXG1V]@Hհ<4,dƣ,Ѱ w]ESbhe\IÂuSyո +q -Rհ w , 2װ w]@x]հ wQ7D ơа8 UyZ X [$*/8Ӱ`l,P pjX6aAZB٣ K(^5!lFjRhU;d̒yaAǞcN˷/H?S886֞Wxe|p FP8RYDHA,FSLXL$c$z?ZhR;3mm06  +I~ iO`̽BHy~|7~ GZ*;>k߸p.}>}l;i*J9mS;W}˯?AbT"ϘǯSm١wc'Zs*@|DWd2k׿ݿ۴KU1G+>8u(\𕵋`V쾰ϰ\d8ɗh"HZ2i&SY؇j E;5hrKKpDYhIkow/.A=Փ3=/ @ -bm`8q'~r_bHwc?'ݥ͗kU,KtN7z2*WB|';$a1 ԥ{#QTЅ8EsIn rW8*t;^3yr]h +X}SB뫠ΰeEf ;vE<7G`~ Wc[ +n;{OMm ǧbˑũ~9/:<ܚNHލ?ݪ}\ElBwmVk˙^ƳG-#[u߯xJqX@y %|j:vyeHnTs=]|NC鲟EϘsnX6V.<J֓2?B&F P +θ0} oCmhRjne@^Rth—gdv +~$=36\Nt# b~[H\<7#KσؚK?! WEB.e˅?2mOŞxi?̕"GǃR*WidBe*szjǵ*Q3*BGV-Uow?{^gjeib}9C.IoҹZ[SPJW=ZWۭzo߮n_O\$MaNvyeESԉ^UE/]wj{SuuavCe/wY)N9Z.GVsLkwUWڦif^hv[cq}׽b.%֛-LQ;Ot~&zUC7/"r\2+|zގx4 ;)簕&ik>dgt\6>qq[h/52ǷkhƗ^mA:Y,>uHȼx tU)C_/}~rJ,֯W^_RciQ9|NMkr'{dM_]wOd6'~UV?'*]@/|2 l|:r?8Փi(5mc~TH^Sz+.KeYky,mTLz$m?e ,ēďo| 8c_BOazM[?aX#ɺ޴3:8?D`GVjzϸ[NYçxm{) 9 +3GH&k{Yv{ƳR}?󙺋N{vz6{ULmz^vWvoWVMO+ +>U*Oe?a\u$ts{]jW~ك7ȪN7{6Ϳ]{.<uO)l^R۾zڢ=Okw!CGO?7~6]-֡=Lno592\3|o<]-Q/qs悽)uZUmnoLY]MsR,;>?JACx ﹭% X^oIb|x8b)B}gmU_Sړ>jl;u%ҝ]Wg){8xyhe.ڇ=,+󗿮 xW~>@5Y7Ho7˃{boXɤsGv]BFA$3qi\wiu{f7?Ca?s|" +#ۓyָ̟ vx9JC\͘s9!+qOrCuiRuN0veÖRCE}]o-~0 ;)E!~ccz#88̡k~2]=xv6eN"Fl?趶EoH#'rvXBA;N\/w~kO E86y$IOuHӀ<r93莳VT2Aϵ 5cMv!g`$..7qۊ<#TKN{Nr&yXKc^xkdv/2ގl7/&S0$O}k 2-.4C-JǸduP$_.tǽh2˓d~G'<7voy{4 L7 $ƩCAu B3xhq2_k/ ݐ.rpX&/̔|SO)b 8S"C,?IS8eɣfԝV!NA 䁜h]ɣj/"L>o:x:5ô>9'\И+ ș1K ZH2-'DyQE{p1c2eXWK[qQGM1*CQZ%y{RP;jH;i W%r'mI BLE4=DZda(\ !:ׇU.} +PZ85[4ra":p[:YW +endstream +endobj +67 0 obj +<< +/Type /Page +/Parent 1 0 R +/MediaBox [ 0 0 595.275591 841.889764 ] +/Contents 66 0 R +/Resources 4 0 R +/Annots [ 68 0 R 69 0 R 70 0 R 71 0 R 72 0 R 73 0 R 74 0 R 75 0 R ] +/TrimBox [ 0 0 595.275591 841.889764 ] +/BleedBox [ 0 0 595.275591 841.889764 ] +>> +endobj +68 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 101.433071 748.173057 101.433071 729.423057 ] +/BS << +/W 0 +>> +/Dest (cb6-1) +>> +endobj +69 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 729.226036 99.933071 710.476036 ] +/BS << +/W 0 +>> +/Dest (cb6-2) +>> +endobj +70 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 710.279014 99.933071 691.529014 ] +/BS << +/W 0 +>> +/Dest (cb6-3) +>> +endobj +71 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 672.384971 99.933071 653.634971 ] +/BS << +/W 0 +>> +/Dest (cb6-4) +>> +endobj +72 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 634.490928 99.933071 615.740928 ] +/BS << +/W 0 +>> +/Dest (cb6-5) +>> +endobj +73 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 287.395585 321.344928 323.513505 306.344928 ] +/BS << +/W 0 +>> +/A << +/Type /Action +/S /URI +/URI (https://github.com/projectcalico/canal) +>> +>> +endobj +74 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 84.259843 291.344928 111.294999 276.344928 ] +/BS << +/W 0 +>> +/A << +/Type /Action +/S /URI +/URI (https://www.suse.com/c/rancher_blog/comparing-kubernetes-cni-providers-flannel-calico-canal-and-weave/) +>> +>> +endobj +75 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 308.171464 172.723346 401.561844 157.723346 ] +/BS << +/W 0 +>> +/A << +/Type /Action +/S /URI +/URI (https://kubernetes.io/docs/concepts/services-networking/network-policies/) +>> +>> +endobj +76 0 obj +<< +/Filter /FlateDecode +/Length 5585 +>> +stream +x]K$qׯ% , Z zaCO}L>23jg0U$ɶgXN)|L)O/5'osH(N1{6__N?uM9gi)F㕢"cI)~;a9kE`Gv/`sZ`Rq/`EZذGa1j12)ZQfʈz)Vgc2^e6ZxaJQ+  I+A:Y)K֕2bZYĬeӾ?Dd2k'$ %9jxdVFW+Nx))Ļɐ,O6BBʓ !kXH|& fTaZLwFE5,9L&k`jYLNI,9 0 O&IԲ8 հ w1g px" p0 Pr AViq@ + k,4wYÂܕiSÂ`pB4,cа d2|jYkX a)SND^9 /4,@D0e[M E R԰H6̬aA7Vl԰ F0[ KM Na~pI2 ^*`*CdY [D(V A K2Ѱ34rIZ+c#yfҰ q$T԰nLHЏ$^$?H6e$f4-}Y^;+B 8:#+{+jn>܇>ׅr34몙VpS#^(5tifY#ǟxXY ǕDِ1g!I`@(C3;Qb6N A݆n[+H7FCBR|{[Si;(z$#"-.ES0s`or#' +:W"&7(N)!Qfx*{+]Lc]L*Wz n%Y 켑^1ـ  Ʋӷ?Ⱦ¿1^/< !~$Cvr;Nao$5ȓ3eG*GҠмLNR EI*3N@v>˩}Eb\^A\8AT`? Fy'CT֔#܎hШ%|])4g|O $O ki,}B/C3eɦL +cEZ~W)}./͟<>^Ws}|uҞwQ8I f XU0Wo_-nBf|E1Xd|F>${G[ +;|vsX +<{*3^>V66e us,Jce?RrGwgcPyݠ4qCc'.gMV]heGNj`/&dd!DG|d wUy?0sQ5y\[s!qSFuTecp[y?JC10'~5I׍~AHywՙʲԮj˴jj52(yƭQ곺!AN:GYݿmmwUy7FHUS +\ +4$<n6")C|YsW&H:G$AfCF?.js%>o,=ϝG Ρ\A88j!'9yMgbj'!Dew궥UD֡kڪяJ>gϋ"pbrY*^D^6[xWĔdW c׿aBտ9#nS 38BWxi_Rvx9IRY˯U{c^K\MrLZ8 D#l|_r.=j^5 ݮ-O,=hՏ>Ls=BtỪ'9}|U?^5~_p^[uz9uN"uz9չnqu7u;7ۥ}$o ]8].^v/ea[-UaKOî]^Pjܝ u]aHE6=D˲V~:7FymkkUsmntza؞R/.enMQUXOqlMnf^DCbM ND ql.ˋibJ #ۓߕxjٯv}|~5/qlǪ#Ă`&G[& e2)%&;gY3~YN_"^}Y&zMY$Gwyi|^5c#=~+asSRZ  +{Idb/. Bthy3[KB_9ː\uӏvv{vvڐ]wc,'+pVM>-gXiRm+U6FLtK +OG43oVmо[q<0Áj|`O&L4Z;zNiXFvw4Y@,A>cbCПQ$lUxyg1;Nf,M .fJڞ0PU]wt fm3Qrˡ}m6RxZ;s}}wMu3G#yOxl:LYZr/뭷_} Wz-vplVZx6}yds;/eH8KE۞tWH˱oh _$LO FQ_$  +Er.>\ mw,jA1FJLYux˪eG3r_2GS~G[~s[:#WKTקۋq;Vo6h'+mLE؍u)99_Hy[vrJ$:QmV7hTݢ8' $im;Ѿ„ؓR;Bu&wÛ_1aLZW"}w-J`w›njWDYNQ$g(O?}?@oLMNx39) WmxՌm'VuWC]KD:U# `Dځ(KhAS\nQP:o".5~WԷ<*:7=6dy++|@-}{wW; juaϭ4{N=_YQnS(+{eC hyt$n i睸fD[n5"T'0AWnxҳEĞ,tZ" r8Curg)d9%xV9B\>Dv9;}d=1l:k5ˏM[++D vOћ.dw?M| 2Vbog{!ْ~O4Cw,^g]Al.E-m/*UnMUb4ʍM!.'M3ɝ31UC\)I}ni7MTUs|g:&xvR냏`rU#9M툗扝rQyw0HFNKU.'fɍ Qyͤdu띈o6ZH#=4aMQvfGydtMb+ ܴC56kd*#T&F͔_VΧoM,}kCΗƭ\m6_2,j',/Ui @;rֆNkMdڌ{9T9GIX.ZEGI9Jln36g}6˭:qC{}6t$.Á:Kd e#|n=:8tCrnJ˨OI|GRvCE|ס9[)9vD/ +/C!_qfǦ+bx!0_ƆeW(L{}C6hoԗ&x:װ*-Ujm{Ԃ=՗FjՖ)Wڪ:Q4TZk1VR8R-ԿV{Vڭ3^@~4Gg-L +-Tiywm03zdjz5{K|G]P֞ +MqLr\Q=r& aU Ӱpk1uLLd|\04U[^-uH @Y0_v/jYi_H$&oZ:)q +endstream +endobj +77 0 obj +<< +/Type /Page +/Parent 1 0 R +/MediaBox [ 0 0 595.275591 841.889764 ] +/Contents 76 0 R +/Resources 4 0 R +/Annots [ 78 0 R 79 0 R 80 0 R 81 0 R 82 0 R 83 0 R 84 0 R 85 0 R 86 0 R 87 0 R 88 0 R 89 0 R 90 0 R 91 0 R 92 0 R 93 0 R 94 0 R 95 0 R 96 0 R 97 0 R ] +/TrimBox [ 0 0 595.275591 841.889764 ] +/BleedBox [ 0 0 595.275591 841.889764 ] +>> +endobj +78 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 101.433071 715.084475 101.433071 696.334475 ] +/BS << +/W 0 +>> +/Dest (cb7-1) +>> +endobj +79 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 696.137453 99.933071 677.387453 ] +/BS << +/W 0 +>> +/Dest (cb7-2) +>> +endobj +80 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 677.190432 99.933071 658.440432 ] +/BS << +/W 0 +>> +/Dest (cb7-3) +>> +endobj +81 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 658.243410 99.933071 639.493410 ] +/BS << +/W 0 +>> +/Dest (cb7-4) +>> +endobj +82 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 639.296389 99.933071 620.546389 ] +/BS << +/W 0 +>> +/Dest (cb7-5) +>> +endobj +83 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 620.349367 99.933071 601.599367 ] +/BS << +/W 0 +>> +/Dest (cb7-6) +>> +endobj +84 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 601.402346 99.933071 582.652346 ] +/BS << +/W 0 +>> +/Dest (cb7-7) +>> +endobj +85 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 582.455324 99.933071 563.705324 ] +/BS << +/W 0 +>> +/Dest (cb7-8) +>> +endobj +86 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 563.508303 99.933071 544.758303 ] +/BS << +/W 0 +>> +/Dest (cb7-9) +>> +endobj +87 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 544.561281 99.933071 525.811281 ] +/BS << +/W 0 +>> +/Dest (cb7-10) +>> +endobj +88 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 525.614260 99.933071 506.864260 ] +/BS << +/W 0 +>> +/Dest (cb7-11) +>> +endobj +89 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 506.667238 99.933071 487.917238 ] +/BS << +/W 0 +>> +/Dest (cb7-12) +>> +endobj +90 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 487.720217 99.933071 468.970217 ] +/BS << +/W 0 +>> +/Dest (cb7-13) +>> +endobj +91 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 468.773195 99.933071 450.023195 ] +/BS << +/W 0 +>> +/Dest (cb7-14) +>> +endobj +92 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 101.433071 370.326174 101.433071 351.576174 ] +/BS << +/W 0 +>> +/Dest (cb8-1) +>> +endobj +93 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 351.379152 99.933071 332.629152 ] +/BS << +/W 0 +>> +/Dest (cb8-2) +>> +endobj +94 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 332.432131 99.933071 313.682131 ] +/BS << +/W 0 +>> +/Dest (cb8-3) +>> +endobj +95 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 294.538088 99.933071 275.788088 ] +/BS << +/W 0 +>> +/Dest (cb8-4) +>> +endobj +96 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 275.591066 99.933071 256.841066 ] +/BS << +/W 0 +>> +/Dest (cb8-5) +>> +endobj +97 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 298.350419 124.541066 391.740800 109.541066 ] +/BS << +/W 0 +>> +/A << +/Type /Action +/S /URI +/URI (file:///doc_tools/%7B%7B%3Cbaseurl%3E%7D%7D/rke/latest/en/installation/) +>> +>> +endobj +98 0 obj +<< +/Filter /FlateDecode +/Length 5342 +>> +stream +x]]q}_./?_@` n/Ewmy)JTjwg~vUd%aDFcE53G5&_XࢊZ]_/:jU'N"bQ{!)#I'$yb>I(bR,m"̠3$$%(M0FCR0G!hab D +iƫFR5*lfҜS!FJ*Fgm4[!Rl!` NiŦ褴[,Z' i ]IL-:h#e|NDbZFN1mӬ'純fQ4 [YL-i+9BŔoN;#ybm$1 %$ +)%l%lr%lʊbt %p -ieY؂ 8[,9 ؖ t68-i$.p \%.p`\I\@RsS҅G X`%.p]G)H\ASL-`GLrx%. .J\^UaXQ6%-qwm$qwm Etxz܂4rwVZAE wA!^` VHN, `Ui ڠ41K\6udԇ_hQ4\|\雌\ζ$(\CHb[a[?`%̲l6_s~?ɪϳ:l3c㔇\*u{[rK~[uc[hM[k­vg?¬WMd^$gP5||}E??Ϙq" E^$LBį0?X]ӌyV7doRYvJ6m]ga O\hao y֍:ͻn#a"( jY +:6>SG0aaqnٟۈ6@>v]?#Z!it>4yJy"]yxy" xOK #Z8썼 + ̈ҥ~ᔧUhM7-ӧ.,T9UqYf+kԙ 2lH;6i2eua,{@/19LxQ9]a79<xa Dn?˾4?ʼ ǃVN<5'u;c_}ᔺ?~^upIZ6ʼgݕ}i/'yj-*wIX\к) xq9.Đ;)4aEoU.>虢_Tonszޞƕi5<< 1lX+8F\ qZEe4;{Y:?-yQ9nk:+i1YN;u +dVrٴzǻYs) P(`9&o2O(v.w6AkJƮ4 :VC0 Őg0X.l˖R<;kcj[Q(g"9&D!,;tD,{`;o[So}L/ N;`a@|+s'u#dG,x'<ums]bs?'_7a1A;s*OcoZ:5%ygpz[5> ͏5Y/ihe_?ҙ_AfegJWtq6ż(wվG3N;VŬҲN~a]w=c8<1Yu9tjp:*tB\n)TiztFD}uveH]U|zDw{fC +V+/%AX[^~3 (3=~ +GSΓ:"-{hQɂд$}͡JN'=Z1uO @>hs1Ѻ90cKi5 7&G;<weE%VT<M } 03KIjI^PPW|zUfa$ʻ!Cl`č ߅X*o4i}ykɼ<-+)CɋYT^ilm8^F}Mb L#Z7)p:r.3txJ x9PtH3@4^qNFпǀ|#2y%G@<<@l$ƇoE%ćam8A7gQ[Pv9^D`7ޢNܬJ +z< 7pZ*tV('o'uIsА{O[Vq\2&/a:b#3AZ\B,e}Rye#ݷ֢R-H}Ix}jQ- + 2BgݞSyy~cV0ZTR`zr_v+~8-B7g 4@pBTss:D]hQI j/`SC,~ x?-P_QtRi 5o|AhYIа5A۲ᠭc$ί?ǼjwU6^"vV'uV_@X'oy#X-*)7AjSCh?mC0%@ٞFyRy E~=!d4.2﷝l[1l}vV"He;QcDMVyESfJ>ըת;[]iS#-ڏ=DdQ ܸr.N< e2h[2.1,^UoXg:GNP(y>4K}d|~ha$;o}'U7#+4aN|1VSA=sU )ytzs?U҃-6̦ЯQ-q~/+#Sה1G_[. oGKst/ [-E] m bv̑G"ӎ8-ɧA;p=;AUM'zX* f+~-Y_B3Ňj3@⡘Bt +P][>*5]ftfơ; oTWQ_8RkuܤlB"еhBgI*5 ]|siTlRW͵).dfi2|Dq)upc7c mįܾs&NKcM׬2>OTᛔ|0 ^ f/i:$Gf#E16̎Gm3ܭҡ9bJ݊$_"qYT".Bq9Te 3c%~CQfǢŐ!/ƂɌ=^ɡzK7(m7Fxԕ˰lc+꼽ZYn=ׂ=ňAڜR-*E tc)jY'b)cKWZ#W&/[G-αߝ9[,YzNWeۺiYwmmP7$Tw5M-#-?eä'ٔlu +BmdҰ5JF]kBw(rNG_J,|0UXVZ@X4=QݵmBN ˖qЛ9aI? +endstream +endobj +99 0 obj +<< +/Type /Page +/Parent 1 0 R +/MediaBox [ 0 0 595.275591 841.889764 ] +/Contents 98 0 R +/Resources 4 0 R +/Annots [ 100 0 R 101 0 R 102 0 R 103 0 R 104 0 R 105 0 R 106 0 R 107 0 R 108 0 R 109 0 R 110 0 R 111 0 R 112 0 R 113 0 R 114 0 R 115 0 R 116 0 R 117 0 R 118 0 R 119 0 R 120 0 R 121 0 R 122 0 R 123 0 R 124 0 R 125 0 R 126 0 R 127 0 R ] +/TrimBox [ 0 0 595.275591 841.889764 ] +/BleedBox [ 0 0 595.275591 841.889764 ] +>> +endobj +100 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 289.074296 784.370079 316.109452 769.370079 ] +/BS << +/W 0 +>> +/A << +/Type /Action +/S /URI +/URI (file:///doc_tools/%7B%7B%3Cbaseurl%3E%7D%7D/rke/latest/en/config-options/nodes/) +>> +>> +endobj +101 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 101.433071 650.584475 101.433071 631.834475 ] +/BS << +/W 0 +>> +/Dest (cb9-1) +>> +endobj +102 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 612.690432 99.933071 593.940432 ] +/BS << +/W 0 +>> +/Dest (cb9-2) +>> +endobj +103 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 574.796389 99.933071 556.046389 ] +/BS << +/W 0 +>> +/Dest (cb9-3) +>> +endobj +104 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 555.849367 99.933071 537.099367 ] +/BS << +/W 0 +>> +/Dest (cb9-4) +>> +endobj +105 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 536.902346 99.933071 518.152346 ] +/BS << +/W 0 +>> +/Dest (cb9-5) +>> +endobj +106 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 499.008303 99.933071 480.258303 ] +/BS << +/W 0 +>> +/Dest (cb9-6) +>> +endobj +107 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 480.061281 99.933071 461.311281 ] +/BS << +/W 0 +>> +/Dest (cb9-7) +>> +endobj +108 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 461.114260 99.933071 442.364260 ] +/BS << +/W 0 +>> +/Dest (cb9-8) +>> +endobj +109 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 442.167238 99.933071 423.417238 ] +/BS << +/W 0 +>> +/Dest (cb9-9) +>> +endobj +110 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 423.220217 99.933071 404.470217 ] +/BS << +/W 0 +>> +/Dest (cb9-10) +>> +endobj +111 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 404.273195 99.933071 385.523195 ] +/BS << +/W 0 +>> +/Dest (cb9-11) +>> +endobj +112 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 385.326174 99.933071 366.576174 ] +/BS << +/W 0 +>> +/Dest (cb9-12) +>> +endobj +113 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 366.379152 99.933071 347.629152 ] +/BS << +/W 0 +>> +/Dest (cb9-13) +>> +endobj +114 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 347.432131 99.933071 328.682131 ] +/BS << +/W 0 +>> +/Dest (cb9-14) +>> +endobj +115 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 328.485109 99.933071 309.735109 ] +/BS << +/W 0 +>> +/Dest (cb9-15) +>> +endobj +116 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 309.538088 99.933071 290.788088 ] +/BS << +/W 0 +>> +/Dest (cb9-16) +>> +endobj +117 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 290.591066 99.933071 271.841066 ] +/BS << +/W 0 +>> +/Dest (cb9-17) +>> +endobj +118 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 271.644045 99.933071 252.894045 ] +/BS << +/W 0 +>> +/Dest (cb9-18) +>> +endobj +119 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 252.697023 99.933071 233.947023 ] +/BS << +/W 0 +>> +/Dest (cb9-19) +>> +endobj +120 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 233.750002 99.933071 215.000002 ] +/BS << +/W 0 +>> +/Dest (cb9-20) +>> +endobj +121 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 214.802980 99.933071 196.052980 ] +/BS << +/W 0 +>> +/Dest (cb9-21) +>> +endobj +122 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 195.855959 99.933071 177.105959 ] +/BS << +/W 0 +>> +/Dest (cb9-22) +>> +endobj +123 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 176.908937 99.933071 158.158937 ] +/BS << +/W 0 +>> +/Dest (cb9-23) +>> +endobj +124 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 157.961916 99.933071 139.211916 ] +/BS << +/W 0 +>> +/Dest (cb9-24) +>> +endobj +125 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 139.014895 99.933071 120.264895 ] +/BS << +/W 0 +>> +/Dest (cb9-25) +>> +endobj +126 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 120.067873 99.933071 101.317873 ] +/BS << +/W 0 +>> +/Dest (cb9-26) +>> +endobj +127 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 101.120852 99.933071 82.370852 ] +/BS << +/W 0 +>> +/Dest (cb9-27) +>> +endobj +128 0 obj +<< +/Filter /FlateDecode +/Length 4974 +>> +stream +x]ɎW\`aJfKIKHF/[9kDFcO'X],?_g)*orH#'b6 ]_N_ks*`?#ȩb^eq{A9K"#YEfPN^ 6 3EFQ6D0dѰXE D +2U@If +),"d&ZI +7,O`H2[!Ғ KQӢ $Ţv KJ 蠍$NDYLF^䜖d(l:QF +QYϢ x$sW') rvIaDlAK `l1H$1*ʖ$)J$)+I4`Wrxi58 [< -+`$q$.pXr8--8-l$.p[&H\@0SK\.r,q:p%.p`]烕v q:2Z:MQ[` ʙ$. 3:J\@]t#+qZUA`Eٔ޵I޵.@E>$. xswVZAE wA!^` V{Ȭ7Sak2ܟЧVʤ$.]|,+QBE-+Bw᨜ L d @i-qA6 MK_x3I\xC0XUy0nR8a.dq%βߙ!h6ڈlԞ^7h$gjy&¤qp U!Ot6iОw2C w7l첿tĈ3*䓀kbϤ֨oVkyבlL$9@q%>?zB<0M2X^˔k]lpte&3Ij^L,/pېe2d6;sZ"x&xW'inwr `?hi]7_;sz^D U! pB;.dlz邁 ܺ&u%TP1 y2jգ%cQßS] ]uН9t# U!˄uοĭԠX!\ )-S`BZsD9KD X +6nC=c V+&dS@ ._cyǐ9 dIA^u!RPw#|W^BsmGq +0wkv%fR89MN7w&MDwc6M>g|7M>s|6Ġ]Zy-ɏ!8sz٣B$WŻ1y9IIѢ=QN)HYOGԨv[NxR8`M>Yz_;U!%n= jT1Xr(UӘoۙvs:id-~{&73Һ:ű=NqG}Nei)N|0aT-XoЕS|XAP?G[Q{;CO  Gz 9sjpMׅi +v'?9L_G7@ޛ_`*q љ_DH +Y9,LK(K?q]v``kq T[kvlS9 ˛t^8p,kO8jG}q`0x[t8s:>F$Wqh˞8p&,6'F&uSgޢ1[Oo+p]jz?l5o?}mR8`HXB> x=gF}g{KB6 (5:sEgL.gƲ^DJPē 7wR8H( okօv,X|Ga6mFR+soBZuW:Û ˻p-vCHV90Nxbܲ.shrwhr> o?49s%ީeOܪgK31jB]wD9 G/~օ<&Gj(C:c#goU1M69G}i#\MpM: EB~C{MMEfY}NAͤŤqq*_K}[دܷ9I%k |d3:_|ڍtx[օcϙQ{ߙ]Axʄ4]rx'u^B 7]n0t&ۜ/`Mq=;rTfZ X,`G w6g'u'{Ѫ.`ey=050;~zaDtgT+ˮz⨾oM@ݠ7cT{}&ejY6)Gl[ +BX4Gr;W0? 0"3_i+ehDvUb|?k w..y#(~&p-~pP?|I%<ͼ#_>CvdJB?\?4F7M,_4̏'gs^y>7$!Lۯދݥ]qQ+}5כ;_~< ƄGcZ`d~zd~nRv)p&Rݰ)n&Dג%%HUg/ymQb}ꋘ_+*Ψ\S}Yj; I.ʻV\S|.'1nTRSͥ) .ՊҖ:FmG+yCqmknx9a!䣐7о@Ot}kr /-'k4: + +_Sy_ UHU+fM^WR*T.nT;ƊپLB~&ݚ*.=bT%uLa~*WZP~Y%7;}^‚}[r'?WU0_/cd~*dku0BKn4$Zى˯IriqsyQxpGG_yws?W?nue [u{2VoLomDKdZ^_P_SS׍KNSTi[vɶBՌx|j4}tPEp?.S-qYKl +Ͳ ȾZl?M%EFk2jnuI[˂yM+~svJJ5OƩT\e9ny)t鼭\\ rZh.zv2P*iBt4]c)J,OZ5hkR+|jj{8t嬱dB]St%m,eo{!E!-}s7[ * Dg9sB6R4v<g2G_Cs:^ ۂV/o j|rUx} L4 rMCE#QqJ\VS':* +endstream +endobj +129 0 obj +<< +/Type /Page +/Parent 1 0 R +/MediaBox [ 0 0 595.275591 841.889764 ] +/Contents 128 0 R +/Resources 4 0 R +/Annots [ 130 0 R 131 0 R 132 0 R 133 0 R 134 0 R 135 0 R 136 0 R 137 0 R 138 0 R 139 0 R 140 0 R 141 0 R 142 0 R 143 0 R 144 0 R 145 0 R 146 0 R 147 0 R 148 0 R 149 0 R 150 0 R 151 0 R 152 0 R 153 0 R 154 0 R 155 0 R 156 0 R 157 0 R 158 0 R 159 0 R 160 0 R 161 0 R 162 0 R 163 0 R 164 0 R 165 0 R 166 0 R 167 0 R ] +/TrimBox [ 0 0 595.275591 841.889764 ] +/BleedBox [ 0 0 595.275591 841.889764 ] +>> +endobj +130 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 799.173057 99.933071 780.423057 ] +/BS << +/W 0 +>> +/Dest (cb9-28) +>> +endobj +131 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 780.226036 99.933071 761.476036 ] +/BS << +/W 0 +>> +/Dest (cb9-29) +>> +endobj +132 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 761.279014 99.933071 742.529014 ] +/BS << +/W 0 +>> +/Dest (cb9-30) +>> +endobj +133 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 742.331993 99.933071 723.581993 ] +/BS << +/W 0 +>> +/Dest (cb9-31) +>> +endobj +134 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 723.384971 99.933071 704.634971 ] +/BS << +/W 0 +>> +/Dest (cb9-32) +>> +endobj +135 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 704.437950 99.933071 685.687950 ] +/BS << +/W 0 +>> +/Dest (cb9-33) +>> +endobj +136 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 685.490928 99.933071 666.740928 ] +/BS << +/W 0 +>> +/Dest (cb9-34) +>> +endobj +137 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 666.543907 99.933071 647.793907 ] +/BS << +/W 0 +>> +/Dest (cb9-35) +>> +endobj +138 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 647.596885 99.933071 628.846885 ] +/BS << +/W 0 +>> +/Dest (cb9-36) +>> +endobj +139 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 628.649864 99.933071 609.899864 ] +/BS << +/W 0 +>> +/Dest (cb9-37) +>> +endobj +140 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 609.702842 99.933071 590.952842 ] +/BS << +/W 0 +>> +/Dest (cb9-38) +>> +endobj +141 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 590.755821 99.933071 572.005821 ] +/BS << +/W 0 +>> +/Dest (cb9-39) +>> +endobj +142 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 571.808799 99.933071 553.058799 ] +/BS << +/W 0 +>> +/Dest (cb9-40) +>> +endobj +143 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 552.861778 99.933071 534.111778 ] +/BS << +/W 0 +>> +/Dest (cb9-41) +>> +endobj +144 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 533.914756 99.933071 515.164756 ] +/BS << +/W 0 +>> +/Dest (cb9-42) +>> +endobj +145 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 514.967735 99.933071 496.217735 ] +/BS << +/W 0 +>> +/Dest (cb9-43) +>> +endobj +146 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 496.020714 99.933071 477.270714 ] +/BS << +/W 0 +>> +/Dest (cb9-44) +>> +endobj +147 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 477.073692 99.933071 458.323692 ] +/BS << +/W 0 +>> +/Dest (cb9-45) +>> +endobj +148 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 458.126671 99.933071 439.376671 ] +/BS << +/W 0 +>> +/Dest (cb9-46) +>> +endobj +149 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 439.179649 99.933071 420.429649 ] +/BS << +/W 0 +>> +/Dest (cb9-47) +>> +endobj +150 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 420.232628 99.933071 401.482628 ] +/BS << +/W 0 +>> +/Dest (cb9-48) +>> +endobj +151 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 401.285606 99.933071 382.535606 ] +/BS << +/W 0 +>> +/Dest (cb9-49) +>> +endobj +152 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 382.338585 99.933071 363.588585 ] +/BS << +/W 0 +>> +/Dest (cb9-50) +>> +endobj +153 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 363.391563 99.933071 344.641563 ] +/BS << +/W 0 +>> +/Dest (cb9-51) +>> +endobj +154 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 344.444542 99.933071 325.694542 ] +/BS << +/W 0 +>> +/Dest (cb9-52) +>> +endobj +155 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 325.497520 99.933071 306.747520 ] +/BS << +/W 0 +>> +/Dest (cb9-53) +>> +endobj +156 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 306.550499 99.933071 287.800499 ] +/BS << +/W 0 +>> +/Dest (cb9-54) +>> +endobj +157 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 287.603477 99.933071 268.853477 ] +/BS << +/W 0 +>> +/Dest (cb9-55) +>> +endobj +158 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 268.656456 99.933071 249.906456 ] +/BS << +/W 0 +>> +/Dest (cb9-56) +>> +endobj +159 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 249.709434 99.933071 230.959434 ] +/BS << +/W 0 +>> +/Dest (cb9-57) +>> +endobj +160 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 230.762413 99.933071 212.012413 ] +/BS << +/W 0 +>> +/Dest (cb9-58) +>> +endobj +161 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 211.815391 99.933071 193.065391 ] +/BS << +/W 0 +>> +/Dest (cb9-59) +>> +endobj +162 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 192.868370 99.933071 174.118370 ] +/BS << +/W 0 +>> +/Dest (cb9-60) +>> +endobj +163 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 173.921348 99.933071 155.171348 ] +/BS << +/W 0 +>> +/Dest (cb9-61) +>> +endobj +164 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 154.974327 99.933071 136.224327 ] +/BS << +/W 0 +>> +/Dest (cb9-62) +>> +endobj +165 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 136.027305 99.933071 117.277305 ] +/BS << +/W 0 +>> +/Dest (cb9-63) +>> +endobj +166 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 117.080284 99.933071 98.330284 ] +/BS << +/W 0 +>> +/Dest (cb9-64) +>> +endobj +167 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 98.133262 99.933071 79.383262 ] +/BS << +/W 0 +>> +/Dest (cb9-65) +>> +endobj +168 0 obj +<< +/Filter /FlateDecode +/Length 5056 +>> +stream +x]MܸseH?$X,@``OlMy)JiQXUd%H%s_R]~|*z)O?.*orH (|_6寿{cV|$G*2!!{AH +Fs`κ>) `6 I f 3l4NJ&($ ;ZL!9B*уf +),Eh4"3HiY|lY)oRlq` bl)aEd!-+iEmL䜘SL}^D4c6ILÈB'(Ybl񤭔FᏔSFMaщi/1 E QFb^8ƨ\N"H6eb$lʅ% mfDawAb2ai,lA `u$qm"qnF:m…ZR +NJYSbG K>X K. Kh xbl%.;*2$.p]2:J\FV)i x&$.p]1iQa k=nAk+qZghBfI, `=V҂U)Ŵ4%.)LFT ]f 8 b-*`*R3 l-q<]#qAޠ&234֒hj)i^g& ]E 0LSi4!q^,~2GL-)Y^n& R-V[ M^oF -$.:(v%.#Mk IXoZ'q%74֛X 6Sf ;ᢈiNS-8 M`N7p3ބG/n $^oFq3IJ3 Mx^x}&'&^q&q@z=Vq@{1[Eq@|y$nL,Sw 0"hq@ᏹnOU"&3w_K6z!m?&?{i1? kCft7JM9tQM1/FFb*tY fgf3֋AWQm=VR8oWeƞ60S}\-s'^Va4Wۡݘ뻟.oD>_wߘwMU\KbGr:ۤoMXj+(ܨC\:}[}FLD {Œ1WŠN$bkU?܊qO ~Vz sn~}ބ}u^T|vx;@C҉B' 8N5B}R]&^e5a`PvGtNӥIPmu% #>]9܅}y$h-aϷeɰ#fѠy@dDy^U%Ck~Xz#,?7pu 9OW~`we(ΛMSw4nOMϿ}X筰9q{*m&oek"דv^|jZ;v6VFLkKs%nݿ?dt3d"B_rȬ*\v;e Ia-CPq7:۲s_f7A!Xh],yI߁w\?8"c:oLKJ߷ma`qנ/^W'6e2ZuS gR[Q)X~t9 ] n.UD 3Mϲz+v$ .}8uLkÐ)neU2\W] Yqd!'MØy$,Cpjۺim7ن^ +l}[_G E%ǘy9@> G .*݆k3O(o H ޷.ǘiN_]ɫGN6[L.ΐCЊI;9<,&C'=_2ɽеđAs_(uyc"72ו md~%{nT;&b1@߿3[U}Q{("cs]y^gXCdiy͝ѱܜ&4e5Zetއi`4ޤ8+Q`saGd)c Qfю1{qޜ$hL!',fvb,V{uRPH*y.5V4 )X1t=A^ REc^3U%踙kLXꑺ9nux'Ϭ^j=Xzkk'\ ~c:cbWگ㪒C>n!bH'Dcvv(q'αrέ^>s^XeȠlOó Cqc:zXwxʺБ)]%m9aR9DA@SQ9Oot|UɗQ;rD>vDEпaqk;[m D혲F ZU#*}]k^'ilz{O;be~xy8"W YU%l@_Ё^X@okyz뗧o 9 @W;?pJ:v$t>:} +aLp!xʘy F<~yH*: GVB3¿T x'#â֕#tH@},t׿ˀ_Ahn`Cu Ň2઒:[q$t>:߅1xc-kS;t?re'rTZ0=yj|L67{&+-Atɦy-u4w! eeתwV}PxΠyyƒAZ~EN x# zlb61gN)aL=󕿾4a <7\_М>2sCSD|jb1?]ylݾ'1/ # bBvPeq`FƋ*osWzkOݰ/jQ>*P!4|(f1g/)B5Ňb3Kͻ({BT%?ssmәK^'|ZJE)ݫUZ[QcTR_rqE~K)7a*@r5_.E7kOŚ+-buJF4C1\@kNtc⣐/\}^+*Nz"4f&U*e~W!_YJxlVZyt+f2I tkb+idMۊTyעV@ +xI\Fke'~Q~.Lq.LӜ%o'd vwdC.cdmܺ34 EXM#ElҒ4yچݢb/9MePSS[_ڰ +]kiGi|i,͡p.ӒF˔|mg]t:(-Myle&6=ڮEF%-infۢl& \`j/ڂRV^#>`i*}nXZ Ot֗uΡe.-TˢfQurnubEmJ]*-E tc)jY;Nb+S,-^^ ]^.x[q;䬾ddծR"vl{mn-3Ջr^3vn:)W3`|d 33!?]j4w2G[C9" H MQd5>)ұp h7oKE;ݥڈ[:V O?b +endstream +endobj +169 0 obj +<< +/Type /Page +/Parent 1 0 R +/MediaBox [ 0 0 595.275591 841.889764 ] +/Contents 168 0 R +/Resources 4 0 R +/Annots [ 170 0 R 171 0 R 172 0 R 173 0 R 174 0 R 175 0 R 176 0 R 177 0 R 178 0 R 179 0 R 180 0 R 181 0 R 182 0 R 183 0 R 184 0 R 185 0 R 186 0 R 187 0 R 188 0 R 189 0 R 190 0 R 191 0 R 192 0 R 193 0 R 194 0 R 195 0 R 196 0 R 197 0 R 198 0 R 199 0 R 200 0 R 201 0 R 202 0 R ] +/TrimBox [ 0 0 595.275591 841.889764 ] +/BleedBox [ 0 0 595.275591 841.889764 ] +>> +endobj +170 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 799.173057 99.933071 780.423057 ] +/BS << +/W 0 +>> +/Dest (cb9-66) +>> +endobj +171 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 780.226036 99.933071 761.476036 ] +/BS << +/W 0 +>> +/Dest (cb9-67) +>> +endobj +172 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 761.279014 99.933071 742.529014 ] +/BS << +/W 0 +>> +/Dest (cb9-68) +>> +endobj +173 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 742.331993 99.933071 723.581993 ] +/BS << +/W 0 +>> +/Dest (cb9-69) +>> +endobj +174 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 723.384971 99.933071 704.634971 ] +/BS << +/W 0 +>> +/Dest (cb9-70) +>> +endobj +175 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 704.437950 99.933071 685.687950 ] +/BS << +/W 0 +>> +/Dest (cb9-71) +>> +endobj +176 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 685.490928 99.933071 666.740928 ] +/BS << +/W 0 +>> +/Dest (cb9-72) +>> +endobj +177 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 666.543907 99.933071 647.793907 ] +/BS << +/W 0 +>> +/Dest (cb9-73) +>> +endobj +178 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 647.596885 99.933071 628.846885 ] +/BS << +/W 0 +>> +/Dest (cb9-74) +>> +endobj +179 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 628.649864 99.933071 609.899864 ] +/BS << +/W 0 +>> +/Dest (cb9-75) +>> +endobj +180 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 514.967735 99.933071 496.217735 ] +/BS << +/W 0 +>> +/Dest (cb9-76) +>> +endobj +181 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 496.020714 99.933071 477.270714 ] +/BS << +/W 0 +>> +/Dest (cb9-77) +>> +endobj +182 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 477.073692 99.933071 458.323692 ] +/BS << +/W 0 +>> +/Dest (cb9-78) +>> +endobj +183 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 458.126671 99.933071 439.376671 ] +/BS << +/W 0 +>> +/Dest (cb9-79) +>> +endobj +184 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 439.179649 99.933071 420.429649 ] +/BS << +/W 0 +>> +/Dest (cb9-80) +>> +endobj +185 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 420.232628 99.933071 401.482628 ] +/BS << +/W 0 +>> +/Dest (cb9-81) +>> +endobj +186 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 401.285606 99.933071 382.535606 ] +/BS << +/W 0 +>> +/Dest (cb9-82) +>> +endobj +187 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 382.338585 99.933071 363.588585 ] +/BS << +/W 0 +>> +/Dest (cb9-83) +>> +endobj +188 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 363.391563 99.933071 344.641563 ] +/BS << +/W 0 +>> +/Dest (cb9-84) +>> +endobj +189 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 344.444542 99.933071 325.694542 ] +/BS << +/W 0 +>> +/Dest (cb9-85) +>> +endobj +190 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 325.497520 99.933071 306.747520 ] +/BS << +/W 0 +>> +/Dest (cb9-86) +>> +endobj +191 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 306.550499 99.933071 287.800499 ] +/BS << +/W 0 +>> +/Dest (cb9-87) +>> +endobj +192 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 287.603477 99.933071 268.853477 ] +/BS << +/W 0 +>> +/Dest (cb9-88) +>> +endobj +193 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 268.656456 99.933071 249.906456 ] +/BS << +/W 0 +>> +/Dest (cb9-89) +>> +endobj +194 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 249.709434 99.933071 230.959434 ] +/BS << +/W 0 +>> +/Dest (cb9-90) +>> +endobj +195 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 230.762413 99.933071 212.012413 ] +/BS << +/W 0 +>> +/Dest (cb9-91) +>> +endobj +196 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 211.815391 99.933071 193.065391 ] +/BS << +/W 0 +>> +/Dest (cb9-92) +>> +endobj +197 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 192.868370 99.933071 174.118370 ] +/BS << +/W 0 +>> +/Dest (cb9-93) +>> +endobj +198 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 173.921348 99.933071 155.171348 ] +/BS << +/W 0 +>> +/Dest (cb9-94) +>> +endobj +199 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 154.974327 99.933071 136.224327 ] +/BS << +/W 0 +>> +/Dest (cb9-95) +>> +endobj +200 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 136.027305 99.933071 117.277305 ] +/BS << +/W 0 +>> +/Dest (cb9-96) +>> +endobj +201 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 117.080284 99.933071 98.330284 ] +/BS << +/W 0 +>> +/Dest (cb9-97) +>> +endobj +202 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 98.133262 99.933071 79.383262 ] +/BS << +/W 0 +>> +/Dest (cb9-98) +>> +endobj +203 0 obj +<< +/Filter /FlateDecode +/Length 4851 +>> +stream +x]K$9ׯ3~I!-1̀P/әU]ӋrZ=]a;#/"l]-~q/39凋5)X%pu  I%o]˿u՛Rwb2)d*`YG ++QaEgh,{޲Ƃ}VXb'G[V>9XÕykU &ӣ\|Qy <#21 Nc Y1d : KpVA4^,ɪgaw}aw} Py`  ynkX]>jXC1F]@Hհ^xћ*/璆)+v 2^pIc R,*k<YdkXH<4, ԰ ,3Z ࡑK5[3PQ d@JY@?l D ְ g/fְ gװ)fҰXȂOÂb0Y8xjXP\FYK7,Mxʸ-%L,!ʃ,2nI7N/B_XÂY7ѫSYͤNwC2i<."Өa.o"r{ ̒qfuz|:e`VI3_ɑI2GunLgi E<L>ST3s,s1S6?_~{._~RgڏGI _n1L%r>SGHeI7\L}2LAUuY]dv_ ?l "9vD}g7X /؉/>]0fh 79s~_׿qO_.w?Ƶ~̓6 )P֢Mi&[3%>K>O|FTvp hb!6@X Yx+*בDy[@x.h]ke[姥`(Un(Uy( [AЉLjyilGQ16Ѓ(~q)h@kURJO9 CDeu|0 zpaf^xk^*<;.V_fB*ίHlԓjH؞U99<ҜTMFoSIMf"sHJ#fH:[bQg#%*6,]t:T4Fe-nhڴ4PfyÛQ+m/:N5f'M]9 +}@97Ο)R5ɃCsyAaR#< x/U!FiqC?cDbN2eQvψ9" +wQuid|_ jk2;kr͐ء+H +lms=zݶira(YY .~9%c&wZu82u 5ד!"u+=LmoWҰwsV(s]ySZw/s}ƩtEW $՗G7̜d +]Gx/:X4)ۓ+t;:FIsCvϦA,BK/[04szqitS #WEE Ǝ0(HDu +9 + `*TyP[AM- Js\S`oܴ0"ʲLv-6@{:fFhVKVA])ˍ[c ʴW8vy;ݕ\lJtE}Đ acձ:1`, cw _g_(AvFw9퀌RDV#=h KeoZxldHc'ǪGAѻۢ;4/{c0^%Jwy݃uʭ-z],;h1_٦=JU=F},I{ٛF^}iVR_A~ +*d1DHŨD뜧eݓjނ/wT"R9`hX$.䜾!*FCMV$!B "ʎ{FDZ:QEDOlLpO5Sͱ:QM8xnoUC::]uyT!/dICޤ%}sOiω}&2Μn}y|S.ǖ1RӃ2I)W-,, +V[; +ek;wz=FH}CA`m{:1,£n[XxƗN qe}k{JCa*xX]k8V؝a]d};PWItGqw+:1\ 9GOrtl2zʹ1_},aꜧIIF/`äw}bt<9:X<*VrLO.'O}OpO%QwLNoKz5+YNnD'G0^l YԽvީYOXAr,/?T|3 eTH\'V䷋ +?HduE{$S%);},q +i~h2ԮVo7Vݖ,Oorx64]. +҉s<+吆D;n&#K9]ܠV֧Aܖ7*GZzi4U:5]!^/ +ۚx7bnĽ\iE-7R/窥,l{+G5ɷ& cR$G@5Rnzk%$t†fz#v;9^fjʭ04MדoP:U~pMJWMdlvFzZ8Ns١\Jfr*t{c e=&T%ud?+GmBv39tS~[g9CE7{رm$q'vy{7kul&v,i47`<[%IlAy?.y +^HN#w/v^͏{wl]GO&_y\64k~yng`o%]GP׹#1}8}7]h|nf}prT4ڤ83f|ĕ]:쇊p2KS rIzGUkdznC4^ oZ(B?=ZȱvhԷLt*˸>+m=ۢaQr1mtT 7F[ܴ9F-&SnO^J={:ZFMYiy-Qhi~:;dVhqݩ> +endobj +205 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 799.173057 99.933071 780.423057 ] +/BS << +/W 0 +>> +/Dest (cb9-99) +>> +endobj +206 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 780.226036 99.933071 761.476036 ] +/BS << +/W 0 +>> +/Dest (cb9-100) +>> +endobj +207 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 761.279014 99.933071 742.529014 ] +/BS << +/W 0 +>> +/Dest (cb9-101) +>> +endobj +208 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 742.331993 99.933071 723.581993 ] +/BS << +/W 0 +>> +/Dest (cb9-102) +>> +endobj +209 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 723.384971 99.933071 704.634971 ] +/BS << +/W 0 +>> +/Dest (cb9-103) +>> +endobj +210 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 704.437950 99.933071 685.687950 ] +/BS << +/W 0 +>> +/Dest (cb9-104) +>> +endobj +211 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 685.490928 99.933071 666.740928 ] +/BS << +/W 0 +>> +/Dest (cb9-105) +>> +endobj +212 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 666.543907 99.933071 647.793907 ] +/BS << +/W 0 +>> +/Dest (cb9-106) +>> +endobj +213 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 609.702842 99.933071 590.952842 ] +/BS << +/W 0 +>> +/Dest (cb9-107) +>> +endobj +214 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 590.755821 99.933071 572.005821 ] +/BS << +/W 0 +>> +/Dest (cb9-108) +>> +endobj +215 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 571.808799 99.933071 553.058799 ] +/BS << +/W 0 +>> +/Dest (cb9-109) +>> +endobj +216 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 552.861778 99.933071 534.111778 ] +/BS << +/W 0 +>> +/Dest (cb9-110) +>> +endobj +217 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 533.914756 99.933071 515.164756 ] +/BS << +/W 0 +>> +/Dest (cb9-111) +>> +endobj +218 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 514.967735 99.933071 496.217735 ] +/BS << +/W 0 +>> +/Dest (cb9-112) +>> +endobj +219 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 496.020714 99.933071 477.270714 ] +/BS << +/W 0 +>> +/Dest (cb9-113) +>> +endobj +220 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 477.073692 99.933071 458.323692 ] +/BS << +/W 0 +>> +/Dest (cb9-114) +>> +endobj +221 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 458.126671 99.933071 439.376671 ] +/BS << +/W 0 +>> +/Dest (cb9-115) +>> +endobj +222 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 439.179649 99.933071 420.429649 ] +/BS << +/W 0 +>> +/Dest (cb9-116) +>> +endobj +223 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 420.232628 99.933071 401.482628 ] +/BS << +/W 0 +>> +/Dest (cb9-117) +>> +endobj +224 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 401.285606 99.933071 382.535606 ] +/BS << +/W 0 +>> +/Dest (cb9-118) +>> +endobj +225 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 382.338585 99.933071 363.588585 ] +/BS << +/W 0 +>> +/Dest (cb9-119) +>> +endobj +226 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 363.391563 99.933071 344.641563 ] +/BS << +/W 0 +>> +/Dest (cb9-120) +>> +endobj +227 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 344.444542 99.933071 325.694542 ] +/BS << +/W 0 +>> +/Dest (cb9-121) +>> +endobj +228 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 325.497520 99.933071 306.747520 ] +/BS << +/W 0 +>> +/Dest (cb9-122) +>> +endobj +229 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 306.550499 99.933071 287.800499 ] +/BS << +/W 0 +>> +/Dest (cb9-123) +>> +endobj +230 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 287.603477 99.933071 268.853477 ] +/BS << +/W 0 +>> +/Dest (cb9-124) +>> +endobj +231 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 249.709434 99.933071 230.959434 ] +/BS << +/W 0 +>> +/Dest (cb9-125) +>> +endobj +232 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 230.762413 99.933071 212.012413 ] +/BS << +/W 0 +>> +/Dest (cb9-126) +>> +endobj +233 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 211.815391 99.933071 193.065391 ] +/BS << +/W 0 +>> +/Dest (cb9-127) +>> +endobj +234 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 192.868370 99.933071 174.118370 ] +/BS << +/W 0 +>> +/Dest (cb9-128) +>> +endobj +235 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 173.921348 99.933071 155.171348 ] +/BS << +/W 0 +>> +/Dest (cb9-129) +>> +endobj +236 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 154.974327 99.933071 136.224327 ] +/BS << +/W 0 +>> +/Dest (cb9-130) +>> +endobj +237 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 136.027305 99.933071 117.277305 ] +/BS << +/W 0 +>> +/Dest (cb9-131) +>> +endobj +238 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 117.080284 99.933071 98.330284 ] +/BS << +/W 0 +>> +/Dest (cb9-132) +>> +endobj +239 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 98.133262 99.933071 79.383262 ] +/BS << +/W 0 +>> +/Dest (cb9-133) +>> +endobj +240 0 obj +<< +/Filter /FlateDecode +/Length 4260 +>> +stream +x]A$m賁%( CMbdfX琿%ݭ5j̫"?QJ?#H-o?~>yWǟfa K:ťPOJJM \ݎOst?()'U VJkX#|*$18F1X1K[VX#T V#DM ^H.CXM^/h\.Rx圓X<,`dI[<$eBɃ,Q +YY"S @.1yg,^%0 +"KB-^.oɃGHYOAD>Z<,HTD o)XYb,l o!@̐ŗlA<).YKq\#[  QRȂX\x1X@@$P, 5y*[X@D%2YX@@[FokC[X@@\ ]ZX@\vZX@]{rĒ-, .q0p5MdA(YX] +XX]QVuE ܍Ƃ!$ ^1haw#la:x3B@da" p7T O\-,H 0ɫ.h[hم ,,H]XXwQ #X !YX 0uM^uXXhaFaHbCG +GjaAbxdODdg=&D ׀5|Ha>}d䢄(@@(8ZX]-%[X!‚AH,Y]*Y(F J,,,@Dj@mN 9?`ȂH laAI1hMP,,\ p^` J,p 09-^,-,@ ^H,-,(efoaFh%j^bapv*ZX7LHi `G'L~04AJlaHXX Yo|XXP=dAgaAila`<-,A0ߌlaRbaA%&xV:,T, !Ƀ,$7N/CX‚7o"7Sb ,pi7o" +3):3c c2^VxΑ̤R5 +ff &\Oc*;R%+܂9Vo?b=N?fɔOubEbWny-D^$Q!J݄ 5Bb(p["E*s@0b`*ʶ]kJ]y +节9D*_CR4@F)Q?~8/~;ȍќ~:_O}Mx;o#@+O?~a9̵ag@RVh{*/)1ftyӪ|e)qrKo*w{F7ߴS2Ac[{z.SZ˚=p׊PQn0+N9L_/(/qQ>Fʻ6:o4@w xK^PA"D 1W8-2 +KO+o_C u3XC6z ]K ̦c~j:1UT}A|k3@6\oxnn&c.b*暫ssEUYFoǪfg^wtN)9+Ϣ:1m1<28*ipr9¬:sX =W8ֵMn׉HD{}q"rlHa9cܗm=I̘GOJ:\tO9 "#+cGH |GhjEuc k+d~2Ye۠Sl׸g&uc,\УXE$. +l 7Y8jNĀZ_pɑhw>sV8_3#,1dèzwsb83UBl 7Y8#)JJtY(Zl 7Y8fHG51i҈Yw\v-<6\E“D~;n0-}JLu|Bu02 GsslË~09SUcW=6UtXfEˎpI>d(O +bҹ +^_Sݯ!/#.m2 OW՚n{! B_pa1Y<5q!F:IhΧzwa5}tݙ]jچfÍ\&zf*1~Q~3cӸ4\{.x+)Аc@-fF{oXȻ$Aǵ'4;=e NL#0OWaYtQSUcb\a{$e*X0 GO+&0۝r %ϥܿVn2|nwqT!ksU:1Ģ;yܙq@}\M ڙߑ6Y0]>d_f68Z/>BXcoEoGt?-ҷ/Krh^M18=Y3z΅߾_cS_*~۷OVZ)=}lSy-g˾Lʫ ^S^U Z>/1O= +Gӥ,iUoXwj.GKz=LSҋǛϋa~:xAkIOd5N^,]:s%)9^pJ26Z?jznahwW/ Dᖬo]Xzj8Zr%&3y,=ptKCsYnec vGՅl,9Nh&U +ljڍhvjj%A 7=q`jz҅(#q/W[9v2˭OKRjmDٺ:IWA[tRCm M0F`}!7o褋rs2k}; sRԨ8S0(euw8}GرuGG2==Y&zr#vA>85od:w$M9 IoWZ̗f/^͐դ:Gې|;- r*f|(n&NLc#]*? mk0;>і f|0Ѻeb"Jީ#R;TZn9МwP G=\c -xw3с*[@F5FO,MVkjYXL-SlԿNUh|SVF-Q؝v~+cI1hyݩFmm<o-2[tS%{w.uVd0lGbP(PxzpaR]q6rcK0c"_"`Q.f>OF +g9Yǟ5oN zE.>)%Ւv  +endstream +endobj +241 0 obj +<< +/Type /Page +/Parent 1 0 R +/MediaBox [ 0 0 595.275591 841.889764 ] +/Contents 240 0 R +/Resources 4 0 R +/Annots [ 242 0 R 243 0 R 244 0 R 245 0 R 246 0 R 247 0 R 248 0 R 249 0 R 250 0 R 251 0 R 252 0 R 253 0 R 254 0 R 255 0 R 256 0 R 257 0 R 258 0 R 259 0 R 260 0 R 261 0 R 262 0 R 263 0 R 264 0 R 265 0 R 266 0 R 267 0 R 268 0 R 269 0 R 270 0 R 271 0 R 272 0 R 273 0 R 274 0 R 275 0 R 276 0 R 277 0 R 278 0 R ] +/TrimBox [ 0 0 595.275591 841.889764 ] +/BleedBox [ 0 0 595.275591 841.889764 ] +>> +endobj +242 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 799.173057 99.933071 780.423057 ] +/BS << +/W 0 +>> +/Dest (cb9-134) +>> +endobj +243 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 780.226036 99.933071 761.476036 ] +/BS << +/W 0 +>> +/Dest (cb9-135) +>> +endobj +244 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 742.331993 99.933071 723.581993 ] +/BS << +/W 0 +>> +/Dest (cb9-136) +>> +endobj +245 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 723.384971 99.933071 704.634971 ] +/BS << +/W 0 +>> +/Dest (cb9-137) +>> +endobj +246 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 704.437950 99.933071 685.687950 ] +/BS << +/W 0 +>> +/Dest (cb9-138) +>> +endobj +247 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 685.490928 99.933071 666.740928 ] +/BS << +/W 0 +>> +/Dest (cb9-139) +>> +endobj +248 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 666.543907 99.933071 647.793907 ] +/BS << +/W 0 +>> +/Dest (cb9-140) +>> +endobj +249 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 647.596885 99.933071 628.846885 ] +/BS << +/W 0 +>> +/Dest (cb9-141) +>> +endobj +250 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 628.649864 99.933071 609.899864 ] +/BS << +/W 0 +>> +/Dest (cb9-142) +>> +endobj +251 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 609.702842 99.933071 590.952842 ] +/BS << +/W 0 +>> +/Dest (cb9-143) +>> +endobj +252 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 590.755821 99.933071 572.005821 ] +/BS << +/W 0 +>> +/Dest (cb9-144) +>> +endobj +253 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 571.808799 99.933071 553.058799 ] +/BS << +/W 0 +>> +/Dest (cb9-145) +>> +endobj +254 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 552.861778 99.933071 534.111778 ] +/BS << +/W 0 +>> +/Dest (cb9-146) +>> +endobj +255 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 533.914756 99.933071 515.164756 ] +/BS << +/W 0 +>> +/Dest (cb9-147) +>> +endobj +256 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 514.967735 99.933071 496.217735 ] +/BS << +/W 0 +>> +/Dest (cb9-148) +>> +endobj +257 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 496.020714 99.933071 477.270714 ] +/BS << +/W 0 +>> +/Dest (cb9-149) +>> +endobj +258 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 477.073692 99.933071 458.323692 ] +/BS << +/W 0 +>> +/Dest (cb9-150) +>> +endobj +259 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 458.126671 99.933071 439.376671 ] +/BS << +/W 0 +>> +/Dest (cb9-151) +>> +endobj +260 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 439.179649 99.933071 420.429649 ] +/BS << +/W 0 +>> +/Dest (cb9-152) +>> +endobj +261 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 420.232628 99.933071 401.482628 ] +/BS << +/W 0 +>> +/Dest (cb9-153) +>> +endobj +262 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 401.285606 99.933071 382.535606 ] +/BS << +/W 0 +>> +/Dest (cb9-154) +>> +endobj +263 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 382.338585 99.933071 363.588585 ] +/BS << +/W 0 +>> +/Dest (cb9-155) +>> +endobj +264 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 363.391563 99.933071 344.641563 ] +/BS << +/W 0 +>> +/Dest (cb9-156) +>> +endobj +265 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 344.444542 99.933071 325.694542 ] +/BS << +/W 0 +>> +/Dest (cb9-157) +>> +endobj +266 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 325.497520 99.933071 306.747520 ] +/BS << +/W 0 +>> +/Dest (cb9-158) +>> +endobj +267 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 306.550499 99.933071 287.800499 ] +/BS << +/W 0 +>> +/Dest (cb9-159) +>> +endobj +268 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 287.603477 99.933071 268.853477 ] +/BS << +/W 0 +>> +/Dest (cb9-160) +>> +endobj +269 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 268.656456 99.933071 249.906456 ] +/BS << +/W 0 +>> +/Dest (cb9-161) +>> +endobj +270 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 249.709434 99.933071 230.959434 ] +/BS << +/W 0 +>> +/Dest (cb9-162) +>> +endobj +271 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 230.762413 99.933071 212.012413 ] +/BS << +/W 0 +>> +/Dest (cb9-163) +>> +endobj +272 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 211.815391 99.933071 193.065391 ] +/BS << +/W 0 +>> +/Dest (cb9-164) +>> +endobj +273 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 192.868370 99.933071 174.118370 ] +/BS << +/W 0 +>> +/Dest (cb9-165) +>> +endobj +274 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 173.921348 99.933071 155.171348 ] +/BS << +/W 0 +>> +/Dest (cb9-166) +>> +endobj +275 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 154.974327 99.933071 136.224327 ] +/BS << +/W 0 +>> +/Dest (cb9-167) +>> +endobj +276 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 136.027305 99.933071 117.277305 ] +/BS << +/W 0 +>> +/Dest (cb9-168) +>> +endobj +277 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 117.080284 99.933071 98.330284 ] +/BS << +/W 0 +>> +/Dest (cb9-169) +>> +endobj +278 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 98.133262 99.933071 79.383262 ] +/BS << +/W 0 +>> +/Dest (cb9-170) +>> +endobj +279 0 obj +<< +/Filter /FlateDecode +/Length 4524 +>> +stream +x]A$m賁%( ! &1fX琿-ݭQ"%>*&=~ G88Z2_~>r$?K3tKfI矕@ŕb]_O鿷}9Zs 䊔`@+%WJL`kX#|*$18F1X1K[VX#T V#DM ^H.CXM^/h\.Rx圓X<,`dI[<$eBɃ,Q +YY"S @x<KUM^K[^%!/d0`\ ^,٧j K"-AƏN$*"l:Sx XAB!/ق da@,ql@r,, +DK! bMs-`yȒ8[H@0fɃ,T ,, ,2ܲ޲BLoaqI2[X@\R촰RK[X]"4ylaQ|FXE ܍Ƃ`$ 1haw#la w!N {"YX\DZbaAgi R 3yՅZv!jaA"P  5ZX-p7-,H]  H,,@|suM^uXXha$1yc瑇ZX‚ ‚ Aha0m9dx]`aT 2pWæ(!! daWKCgux A.lakW%B‚! R }dCdɜTf JʨǠU6y^(8XXZ &x钅 +Y0U,,@(r[Yd[XL,,Y ZX QPefoa"4jI:S,,NSE 0MPi)MdLXXh,,@beɃ,XX Y7,TYYXP}v&[X{ jԛ-,zS,,Qo3mf2dIHQLdATy LB txԜ fDFo. ֛\. +dx]d\Dfk +3)Zqb \2^DbxHDe)\5@X3xs &\V% w(RKVL FvkivY_O{fY)k?ON:EbWna"/BQ!J] 뢛 +Pp[C؊ Udff<B(۲GJ~(/a59.!)n@F+QYMite_r#3O7O ~O/0~\.Ïk_/\k{n1??GHԠ+2\s]eoa%ԞHǐJ2WG Y-BZXk|NJ Vf4X.,DZ7] u9Q,”9 &쿳,G +FKXs}fTK)Լ_fz~bΞn4WqVn}Δ_mm^6a7×avQ2UUw30s'(8 Umл whZQ&Qg9ԮI~>Q}ԊE"Y'yF|76ѭC0;[7 $h\>18*2OA ?NkY$fwq@ b +pcFULHQԣ~US9 DY0{o1ߎwˆ(E׵tRJ\:~a̫;$T*s3淩:@u)_w,&]~>Q^JN)oETw C^}&Fḩϻd"݁o9Jkc9PH1^.yM9."h9sOFzI5ܝ$Ou9n+fzt\W@H3 R,GZ#ǚsղ^+~&}5xNMΨmMr Wqͤ(=-Ǥ@LQRz!ݮޛ+,ɰn)$QiqqԘ573hWSTu7+˳Cؤ ?yd|:>t~f>1>Nyλo.{2j<~}c=E +?T(9y ^ħϖmlҍUul28홂}:@[Čf[GIୈ\?\H(ӳE>Q䫾߽BFaֈ֯sWb Z7Ysd;_>£l3CƸ0*/^DF˦G It=8f=[-b}`&$f.VyL9jd:YIx&}!:mUf0ղV%ϊDStg尝B$JTM82C sD", Nq}W{3cݡ 14x{) ,轸Ɠeٞ!W'|;Y,>y|qT9P}q>'f⼼NInL6 Β]NBS]cIrX~`WPwm4f}y>8`tvʨejѕ+D;E918#& ~l᥅څ0f!=t{ƁwA_0#az>Ot͠06V0-E#nCl>3GBŦ*pq +'(hܐ1F*=4rXc7s7L!fOCq{jw ,xS~/Ɗ˸K_N +>uiҜ3n{OZ!JVG.՘ 'ǥE7)JқAg\#븼09Nym/Iz=tg=Ij~G'3HB֔~O~=lI}Kh/@%%kRS6?nz6.kW꫗DᖬSJs|*wQRn2cuSc-[zCkmb}T]2ҞjR6T.hvjj-A w !t`5=BH vRTdZWQVW'7hԢsS%g@o {oȯTi +Dd񫿬T=V S+SyK)tzUHuҀ.*.쨯 h[wmzM<[r^ +aM?+GoBv+9uW~ݐW9S0{ܱu$nG +vy7xOVחv}*@a%0lǤ$"o%̡Č_g +zB͟N|vw[71y2IOydm78׼v+#hܑV]74_vZ̯/ԾnCz_ +> +endobj +281 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 799.173057 99.933071 780.423057 ] +/BS << +/W 0 +>> +/Dest (cb9-171) +>> +endobj +282 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 780.226036 99.933071 761.476036 ] +/BS << +/W 0 +>> +/Dest (cb9-172) +>> +endobj +283 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 761.279014 99.933071 742.529014 ] +/BS << +/W 0 +>> +/Dest (cb9-173) +>> +endobj +284 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 742.331993 99.933071 723.581993 ] +/BS << +/W 0 +>> +/Dest (cb9-174) +>> +endobj +285 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 723.384971 99.933071 704.634971 ] +/BS << +/W 0 +>> +/Dest (cb9-175) +>> +endobj +286 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 704.437950 99.933071 685.687950 ] +/BS << +/W 0 +>> +/Dest (cb9-176) +>> +endobj +287 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 685.490928 99.933071 666.740928 ] +/BS << +/W 0 +>> +/Dest (cb9-177) +>> +endobj +288 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 666.543907 99.933071 647.793907 ] +/BS << +/W 0 +>> +/Dest (cb9-178) +>> +endobj +289 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 647.596885 99.933071 628.846885 ] +/BS << +/W 0 +>> +/Dest (cb9-179) +>> +endobj +290 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 628.649864 99.933071 609.899864 ] +/BS << +/W 0 +>> +/Dest (cb9-180) +>> +endobj +291 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 609.702842 99.933071 590.952842 ] +/BS << +/W 0 +>> +/Dest (cb9-181) +>> +endobj +292 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 590.755821 99.933071 572.005821 ] +/BS << +/W 0 +>> +/Dest (cb9-182) +>> +endobj +293 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 571.808799 99.933071 553.058799 ] +/BS << +/W 0 +>> +/Dest (cb9-183) +>> +endobj +294 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 552.861778 99.933071 534.111778 ] +/BS << +/W 0 +>> +/Dest (cb9-184) +>> +endobj +295 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 533.914756 99.933071 515.164756 ] +/BS << +/W 0 +>> +/Dest (cb9-185) +>> +endobj +296 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 514.967735 99.933071 496.217735 ] +/BS << +/W 0 +>> +/Dest (cb9-186) +>> +endobj +297 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 496.020714 99.933071 477.270714 ] +/BS << +/W 0 +>> +/Dest (cb9-187) +>> +endobj +298 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 477.073692 99.933071 458.323692 ] +/BS << +/W 0 +>> +/Dest (cb9-188) +>> +endobj +299 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 458.126671 99.933071 439.376671 ] +/BS << +/W 0 +>> +/Dest (cb9-189) +>> +endobj +300 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 439.179649 99.933071 420.429649 ] +/BS << +/W 0 +>> +/Dest (cb9-190) +>> +endobj +301 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 420.232628 99.933071 401.482628 ] +/BS << +/W 0 +>> +/Dest (cb9-191) +>> +endobj +302 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 401.285606 99.933071 382.535606 ] +/BS << +/W 0 +>> +/Dest (cb9-192) +>> +endobj +303 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 382.338585 99.933071 363.588585 ] +/BS << +/W 0 +>> +/Dest (cb9-193) +>> +endobj +304 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 363.391563 99.933071 344.641563 ] +/BS << +/W 0 +>> +/Dest (cb9-194) +>> +endobj +305 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 344.444542 99.933071 325.694542 ] +/BS << +/W 0 +>> +/Dest (cb9-195) +>> +endobj +306 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 325.497520 99.933071 306.747520 ] +/BS << +/W 0 +>> +/Dest (cb9-196) +>> +endobj +307 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 306.550499 99.933071 287.800499 ] +/BS << +/W 0 +>> +/Dest (cb9-197) +>> +endobj +308 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 287.603477 99.933071 268.853477 ] +/BS << +/W 0 +>> +/Dest (cb9-198) +>> +endobj +309 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 268.656456 99.933071 249.906456 ] +/BS << +/W 0 +>> +/Dest (cb9-199) +>> +endobj +310 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 249.709434 99.933071 230.959434 ] +/BS << +/W 0 +>> +/Dest (cb9-200) +>> +endobj +311 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 230.762413 99.933071 212.012413 ] +/BS << +/W 0 +>> +/Dest (cb9-201) +>> +endobj +312 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 211.815391 99.933071 193.065391 ] +/BS << +/W 0 +>> +/Dest (cb9-202) +>> +endobj +313 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 192.868370 99.933071 174.118370 ] +/BS << +/W 0 +>> +/Dest (cb9-203) +>> +endobj +314 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 173.921348 99.933071 155.171348 ] +/BS << +/W 0 +>> +/Dest (cb9-204) +>> +endobj +315 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 154.974327 99.933071 136.224327 ] +/BS << +/W 0 +>> +/Dest (cb9-205) +>> +endobj +316 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 136.027305 99.933071 117.277305 ] +/BS << +/W 0 +>> +/Dest (cb9-206) +>> +endobj +317 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 117.080284 99.933071 98.330284 ] +/BS << +/W 0 +>> +/Dest (cb9-207) +>> +endobj +318 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 98.133262 99.933071 79.383262 ] +/BS << +/W 0 +>> +/Dest (cb9-208) +>> +endobj +319 0 obj +<< +/Filter /FlateDecode +/Length 4985 +>> +stream +x]MׯI ~005VX4c`~U*Fg1[9TCRg$#H&S_~'ZĘח/\Ÿ5Gw&jet]f%$g^e\YRF뿾p%&!ɹ%㼐GLIJ.XcǤ3lNJ֘($EA6h0A[) f䂐F)1 (ki-4IbZ@FJ#Z|i)--{4 [\RZJsik[, yB[L $bP;IHblQ^i)-RVLKHS11(H4lFAH3+4H)`ŏpbzM`1i/1E/Qz¼$q aXLF%01-6h$X4ҌlqKL@X\1 P- ql1$. Z$. ЭUIK\@[@0SI\@`\J\@\@)I\@\wJ\@ ]t quy#qvF/qwj%qASL-`Džt$ ,x +X.^`e11* ,xDe%.]0iaA$ ,x8<4rwSF 5x Do +q;[@`G! PbH\:a4j1y xWG4PBE-/$qb" x%./Q #&) x~pX4 0-ZbZZTQ- 0 +/*IĴHZJ\ޓ,1 P4AЧ.ʀ)4ha) THx.%. `#qvI!x |RH'N₠ p,1 `%.c$JQ`` #qA0.}l\xɖ 8x *y"t `( Z": % `Ҵ $؂"q%xR-p%.4%. (+ 0B#DUKiVq%./*J\nHL)Єh~l"` 9+qA(qA(#qf )O₤nq)%qA_r%.Ho"m"f Y࢈iNS-8 &IJ$+qA(q ě)f .4.ýs"(.=}֯ K[&o*!U6smS8`}3sa}r=1V6<Zʨ=47ƾA{m:kdhguV{F}^(^ +| J 9x]⑀ +}`PkgОﲲF'oA͛9@-`PwG:j]m9/cξmyl@lA{'F-k!:׬76s>a呜hy``>L߀%zK:灗 F#nxfe5>σfcy4ǨoC&E۾Yޛ90/LG+ o.w2ߨ0yЂim`7t#`Efϊgz{a}|%Բ:j. +[3<-8ls:UO[(/xSkA!Ce{ml%ᚷVͮL`C=ܑ +Powܳ.0j[`E+ލoT6 9aO + _?Dh>j1jτ5Q1NQ4cFQ{F#AH^{ &w5s Bf>Bw)sk+˿;~~6tȃ=܈څ /\j\N{).70jO1T9I I}5S*:rP6qJfah|Poh3l>Ǟ9{'DF}"<.;7wRWw݉-HP .Gc-]L- Xz=O 87^>![ ů-k_S# q++!*B~^V~𗒋Hxxa~3}E/yQz/YA GLYxUxσܢR8qiXe5>i+Ƃ^b~z w1/.tmXyzQU1'k*ma1:4kBӜ[— nKWQE`e圥Ali'Arߩ\4%i5M3lɗr>ArKsBj5_MPX*^utgG_{mx — oįܮrrzr8* 1Wf U"eYѶ@RMoq_IֱR ^ +=HQvm}騄L%wNTY#)$Uȣ낺"f +SlnWŮ@W;]Nyݕr|mš{K e죘M2|a5 PŕF_Wq]kd҈re 9>'ߛk#}?#b?q +[­qR_+m W5h(1 _۪*眺0.:lĦ@hjjm_j826u]R~8Odp>.cM:$_"qY됎TkE\ⲹauf2 ۛgmj.7/:̶EgM>˫h eZV~wvs`i"}mXZOz2:ɕ;oR5}SFu-lwbƪvڛ,nB,+%ljY8OQokڵR*ѵ⇼\nDr-C}:Us_2 +2j9){y6a!z!=}0[ ? `K;D!?ll4vlq3ycD*h ^'4E޿&[#a +Ҝfp6}"\Y _ +endstream +endobj +320 0 obj +<< +/Type /Page +/Parent 1 0 R +/MediaBox [ 0 0 595.275591 841.889764 ] +/Contents 319 0 R +/Resources 4 0 R +/Annots [ 321 0 R 322 0 R 323 0 R 324 0 R 325 0 R 326 0 R 327 0 R 328 0 R 329 0 R 330 0 R 331 0 R 332 0 R 333 0 R 334 0 R 335 0 R 336 0 R 337 0 R 338 0 R 339 0 R 340 0 R 341 0 R 342 0 R 343 0 R 344 0 R 345 0 R 346 0 R 347 0 R 348 0 R 349 0 R 350 0 R 351 0 R 352 0 R 353 0 R 354 0 R 355 0 R 356 0 R 357 0 R 358 0 R ] +/TrimBox [ 0 0 595.275591 841.889764 ] +/BleedBox [ 0 0 595.275591 841.889764 ] +>> +endobj +321 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 799.173057 99.933071 780.423057 ] +/BS << +/W 0 +>> +/Dest (cb9-209) +>> +endobj +322 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 780.226036 99.933071 761.476036 ] +/BS << +/W 0 +>> +/Dest (cb9-210) +>> +endobj +323 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 761.279014 99.933071 742.529014 ] +/BS << +/W 0 +>> +/Dest (cb9-211) +>> +endobj +324 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 742.331993 99.933071 723.581993 ] +/BS << +/W 0 +>> +/Dest (cb9-212) +>> +endobj +325 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 723.384971 99.933071 704.634971 ] +/BS << +/W 0 +>> +/Dest (cb9-213) +>> +endobj +326 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 704.437950 99.933071 685.687950 ] +/BS << +/W 0 +>> +/Dest (cb9-214) +>> +endobj +327 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 685.490928 99.933071 666.740928 ] +/BS << +/W 0 +>> +/Dest (cb9-215) +>> +endobj +328 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 666.543907 99.933071 647.793907 ] +/BS << +/W 0 +>> +/Dest (cb9-216) +>> +endobj +329 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 647.596885 99.933071 628.846885 ] +/BS << +/W 0 +>> +/Dest (cb9-217) +>> +endobj +330 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 628.649864 99.933071 609.899864 ] +/BS << +/W 0 +>> +/Dest (cb9-218) +>> +endobj +331 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 609.702842 99.933071 590.952842 ] +/BS << +/W 0 +>> +/Dest (cb9-219) +>> +endobj +332 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 590.755821 99.933071 572.005821 ] +/BS << +/W 0 +>> +/Dest (cb9-220) +>> +endobj +333 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 571.808799 99.933071 553.058799 ] +/BS << +/W 0 +>> +/Dest (cb9-221) +>> +endobj +334 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 552.861778 99.933071 534.111778 ] +/BS << +/W 0 +>> +/Dest (cb9-222) +>> +endobj +335 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 533.914756 99.933071 515.164756 ] +/BS << +/W 0 +>> +/Dest (cb9-223) +>> +endobj +336 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 514.967735 99.933071 496.217735 ] +/BS << +/W 0 +>> +/Dest (cb9-224) +>> +endobj +337 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 496.020714 99.933071 477.270714 ] +/BS << +/W 0 +>> +/Dest (cb9-225) +>> +endobj +338 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 477.073692 99.933071 458.323692 ] +/BS << +/W 0 +>> +/Dest (cb9-226) +>> +endobj +339 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 458.126671 99.933071 439.376671 ] +/BS << +/W 0 +>> +/Dest (cb9-227) +>> +endobj +340 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 439.179649 99.933071 420.429649 ] +/BS << +/W 0 +>> +/Dest (cb9-228) +>> +endobj +341 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 420.232628 99.933071 401.482628 ] +/BS << +/W 0 +>> +/Dest (cb9-229) +>> +endobj +342 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 401.285606 99.933071 382.535606 ] +/BS << +/W 0 +>> +/Dest (cb9-230) +>> +endobj +343 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 382.338585 99.933071 363.588585 ] +/BS << +/W 0 +>> +/Dest (cb9-231) +>> +endobj +344 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 363.391563 99.933071 344.641563 ] +/BS << +/W 0 +>> +/Dest (cb9-232) +>> +endobj +345 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 344.444542 99.933071 325.694542 ] +/BS << +/W 0 +>> +/Dest (cb9-233) +>> +endobj +346 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 325.497520 99.933071 306.747520 ] +/BS << +/W 0 +>> +/Dest (cb9-234) +>> +endobj +347 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 306.550499 99.933071 287.800499 ] +/BS << +/W 0 +>> +/Dest (cb9-235) +>> +endobj +348 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 287.603477 99.933071 268.853477 ] +/BS << +/W 0 +>> +/Dest (cb9-236) +>> +endobj +349 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 268.656456 99.933071 249.906456 ] +/BS << +/W 0 +>> +/Dest (cb9-237) +>> +endobj +350 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 249.709434 99.933071 230.959434 ] +/BS << +/W 0 +>> +/Dest (cb9-238) +>> +endobj +351 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 230.762413 99.933071 212.012413 ] +/BS << +/W 0 +>> +/Dest (cb9-239) +>> +endobj +352 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 211.815391 99.933071 193.065391 ] +/BS << +/W 0 +>> +/Dest (cb9-240) +>> +endobj +353 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 192.868370 99.933071 174.118370 ] +/BS << +/W 0 +>> +/Dest (cb9-241) +>> +endobj +354 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 173.921348 99.933071 155.171348 ] +/BS << +/W 0 +>> +/Dest (cb9-242) +>> +endobj +355 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 154.974327 99.933071 136.224327 ] +/BS << +/W 0 +>> +/Dest (cb9-243) +>> +endobj +356 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 136.027305 99.933071 117.277305 ] +/BS << +/W 0 +>> +/Dest (cb9-244) +>> +endobj +357 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 117.080284 99.933071 98.330284 ] +/BS << +/W 0 +>> +/Dest (cb9-245) +>> +endobj +358 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 98.133262 99.933071 79.383262 ] +/BS << +/W 0 +>> +/Dest (cb9-246) +>> +endobj +359 0 obj +<< +/Filter /FlateDecode +/Length 4962 +>> +stream +x]Ms$@CF'1H㵃`!?5k$jYd||(\5~a_rFcpח/\^ϒcu$_vQyCןY@Qm {쳿^˿:jUgNrbQ{!)#IW1Z`n1g) f"p9y) f8k`hhL0F$aBѰX4#+=Hi֨bZDVJ#R!:㍔U') d @HZlM$.x3I\I#D'L(qAvE` ,[pM`NǛI7ыK(.w}3Ii]xA\ ބg+#391qę [% l5 I\4,SW 0"hq@ᏹnOU"&3w_cv[O/?aˏYV_ X{"6AWj) e2e a{t؈x_tc#1cY fgf3׋H(ȶyTCmYp=z>!^0;SW$:iRs*I2µz"Ve.H*1Q0L{{yd UA֠| Y:PzYE8:l5sl!b.tQ<QF}e7(#Y^Ajt,:.tX Oc9"ĉ- s 6xu6zyEDj6tȏ`[L-yu/NWh`.( O90A d5hA9sPZ^A9>B?-n]x#9qh>#%:AFz[ŬVu[,>B'"[ہy ia<.tɞcχXᷤt]́N}5qԞYM8ViN˞'lه[ >FCX)?tN8LF+\KMU ;P +\Osڨ$]I`óSͤybjL\=DVuwy}5sƽ1Fڼ΢]vi D3R9OWy~$'&?ׅ{~t^ۥ`ҙ7, 3Yg( L~J|9h"oڎ.㻌Wcʸ^W?W +A )uӫǓ:ӼJ7#?&Zutw>+oʸm)0G`2s`{+pݬ<6Σbyf׍+.ǖʄ 6yǺAYR<(k;yHPFm3wE@霧xOuoE7ԮxTh D6 v1b35֔4ٳɜi5&8ߞa]huWFvXޑd>(#g!3r+A 372 ]=++=pRg>Q 8dCz~9t?@inzL\KbZ~a":e3D0 += ߾7n+GǞ[0|Ԇ -:Yr`.tf7E2XoUg"7APb.07s@y&o }]}F+,ǖ-9>E mU ҦT4ϯuDxVk^~]Ӽ׳6ak&̨mSɤy:$gnZ?sj94 'QkdgPo|FR:R[օ~9Wy-FcpouQ:=LLlBܠ.tY+VnS.׏,5/e숗2jRvقC6@L~񘲼[zF<=Z{1fF> l-I@2^C)>B?>>M#-Knbz&ȡ#ڨ}W8O1½|F16r/XLz*e{u[XBЊ9OUBuc 3ǧffmڹ9J )YF BmiyC[҉&{b׵.|Y:O +3CNǽ>-'PtR4Ț_p:ț3V1Чlϊڸ_d !|ڳRޤÿ́ĺвܿt_ #ҍ'm|\r]is-?#[I{y$oL)١ Οc0{2sxzaSOZg]0|\Xm8^݁G[n9s] ϒ'Zq@ݶ dD|6s '~&W,h:LwۮQ{Ʃn=BDxogR4pZS5}>6yt%^#/g}dgA}fr|B4cqT[ĉ(A[e♯Wp*,)\'@3 V{1n7o\-{ܿ\rY:g&qAO|Z9Ҽfis}Cs/5O~{_$c-\G녿18;)fW]]D0aT1'yZ8nX5>#7+bA`F1߽V.I*TS|(6C +t}V`S+MGkb>t\jztƮ;/TKWQ_)Eֵʨ3*W/9kO"Хhw" Sr'^.b{iTRSͥ) j ƈZJ_— oįܾqzr8醗&4fI*|2,W!_chWUn^*8x! Rcl^&i!?n][l%횬\c*f ++Sbkb_7;}^ʂkM*wX{5ELlQO&XV a &n4h{MʯmI3eCkWdKQwdE??/m4mܺ3W0M;EXM'&6 uku#T55ֆVZC] C+VGMoTn G-UoQ]mJG".BqUe+3}%~w?/:7/6Er]_;WWF{x~`i*}XZ Or֗uΡeJjYԍ=NN͵p45{WlUi(*]@MVe$R>EoiJmDJreƫUptY}$B]"vl{n5CBLuSCw{Ma@U.+&`'38'Kݒa5q%q5;#e^We5~Pc ,4 +U/ȡ"Y׽RBFm%e%O{ +endstream +endobj +360 0 obj +<< +/Type /Page +/Parent 1 0 R +/MediaBox [ 0 0 595.275591 841.889764 ] +/Contents 359 0 R +/Resources 4 0 R +/Annots [ 361 0 R 362 0 R 363 0 R 364 0 R 365 0 R 366 0 R 367 0 R 368 0 R 369 0 R 370 0 R 371 0 R 372 0 R 373 0 R 374 0 R 375 0 R 376 0 R 377 0 R 378 0 R 379 0 R 380 0 R 381 0 R 382 0 R 383 0 R 384 0 R 385 0 R 386 0 R 387 0 R 388 0 R 389 0 R 390 0 R 391 0 R 392 0 R 393 0 R 394 0 R 395 0 R 396 0 R 397 0 R 398 0 R ] +/TrimBox [ 0 0 595.275591 841.889764 ] +/BleedBox [ 0 0 595.275591 841.889764 ] +>> +endobj +361 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 799.173057 99.933071 780.423057 ] +/BS << +/W 0 +>> +/Dest (cb9-247) +>> +endobj +362 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 780.226036 99.933071 761.476036 ] +/BS << +/W 0 +>> +/Dest (cb9-248) +>> +endobj +363 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 761.279014 99.933071 742.529014 ] +/BS << +/W 0 +>> +/Dest (cb9-249) +>> +endobj +364 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 742.331993 99.933071 723.581993 ] +/BS << +/W 0 +>> +/Dest (cb9-250) +>> +endobj +365 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 723.384971 99.933071 704.634971 ] +/BS << +/W 0 +>> +/Dest (cb9-251) +>> +endobj +366 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 704.437950 99.933071 685.687950 ] +/BS << +/W 0 +>> +/Dest (cb9-252) +>> +endobj +367 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 685.490928 99.933071 666.740928 ] +/BS << +/W 0 +>> +/Dest (cb9-253) +>> +endobj +368 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 666.543907 99.933071 647.793907 ] +/BS << +/W 0 +>> +/Dest (cb9-254) +>> +endobj +369 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 647.596885 99.933071 628.846885 ] +/BS << +/W 0 +>> +/Dest (cb9-255) +>> +endobj +370 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 628.649864 99.933071 609.899864 ] +/BS << +/W 0 +>> +/Dest (cb9-256) +>> +endobj +371 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 609.702842 99.933071 590.952842 ] +/BS << +/W 0 +>> +/Dest (cb9-257) +>> +endobj +372 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 590.755821 99.933071 572.005821 ] +/BS << +/W 0 +>> +/Dest (cb9-258) +>> +endobj +373 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 571.808799 99.933071 553.058799 ] +/BS << +/W 0 +>> +/Dest (cb9-259) +>> +endobj +374 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 552.861778 99.933071 534.111778 ] +/BS << +/W 0 +>> +/Dest (cb9-260) +>> +endobj +375 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 533.914756 99.933071 515.164756 ] +/BS << +/W 0 +>> +/Dest (cb9-261) +>> +endobj +376 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 514.967735 99.933071 496.217735 ] +/BS << +/W 0 +>> +/Dest (cb9-262) +>> +endobj +377 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 496.020714 99.933071 477.270714 ] +/BS << +/W 0 +>> +/Dest (cb9-263) +>> +endobj +378 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 477.073692 99.933071 458.323692 ] +/BS << +/W 0 +>> +/Dest (cb9-264) +>> +endobj +379 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 458.126671 99.933071 439.376671 ] +/BS << +/W 0 +>> +/Dest (cb9-265) +>> +endobj +380 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 439.179649 99.933071 420.429649 ] +/BS << +/W 0 +>> +/Dest (cb9-266) +>> +endobj +381 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 420.232628 99.933071 401.482628 ] +/BS << +/W 0 +>> +/Dest (cb9-267) +>> +endobj +382 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 401.285606 99.933071 382.535606 ] +/BS << +/W 0 +>> +/Dest (cb9-268) +>> +endobj +383 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 382.338585 99.933071 363.588585 ] +/BS << +/W 0 +>> +/Dest (cb9-269) +>> +endobj +384 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 363.391563 99.933071 344.641563 ] +/BS << +/W 0 +>> +/Dest (cb9-270) +>> +endobj +385 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 344.444542 99.933071 325.694542 ] +/BS << +/W 0 +>> +/Dest (cb9-271) +>> +endobj +386 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 325.497520 99.933071 306.747520 ] +/BS << +/W 0 +>> +/Dest (cb9-272) +>> +endobj +387 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 306.550499 99.933071 287.800499 ] +/BS << +/W 0 +>> +/Dest (cb9-273) +>> +endobj +388 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 287.603477 99.933071 268.853477 ] +/BS << +/W 0 +>> +/Dest (cb9-274) +>> +endobj +389 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 268.656456 99.933071 249.906456 ] +/BS << +/W 0 +>> +/Dest (cb9-275) +>> +endobj +390 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 249.709434 99.933071 230.959434 ] +/BS << +/W 0 +>> +/Dest (cb9-276) +>> +endobj +391 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 230.762413 99.933071 212.012413 ] +/BS << +/W 0 +>> +/Dest (cb9-277) +>> +endobj +392 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 211.815391 99.933071 193.065391 ] +/BS << +/W 0 +>> +/Dest (cb9-278) +>> +endobj +393 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 192.868370 99.933071 174.118370 ] +/BS << +/W 0 +>> +/Dest (cb9-279) +>> +endobj +394 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 173.921348 99.933071 155.171348 ] +/BS << +/W 0 +>> +/Dest (cb9-280) +>> +endobj +395 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 154.974327 99.933071 136.224327 ] +/BS << +/W 0 +>> +/Dest (cb9-281) +>> +endobj +396 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 136.027305 99.933071 117.277305 ] +/BS << +/W 0 +>> +/Dest (cb9-282) +>> +endobj +397 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 117.080284 99.933071 98.330284 ] +/BS << +/W 0 +>> +/Dest (cb9-283) +>> +endobj +398 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 98.133262 99.933071 79.383262 ] +/BS << +/W 0 +>> +/Dest (cb9-284) +>> +endobj +399 0 obj +<< +/Filter /FlateDecode +/Length 5083 +>> +stream +x]Ɏ$WY@7`Ѐ-FCcUUYZs3sqwpFVu+*Fh\a?Ȩr t}|UJEI3~MQyC,pQm \_/:jUGN"bQ{!)#I'$yb>I( ؂HQ0JHcJt-%(qA 0R ^pI4C [T$.@WEd.؂ [DH3Fda A Me-qzh%j)43PQ44blMH\ 61`$qAJIₔ`V`ǛQ€a "> d @HZlƛ$.@f ;&xB.x3J\ x(blAДv Nx$b3I\Cfaƛ)(Nw}3Ii]DA\`Vk#$hPG*Nhp/z(h/Ie +U$-Nh/1qmi +CD"?dF Dmѳl{t׿ӯLY1P |Jy&B+f!aᛔ،ĸLk`Ff )Fc`P[.>5ݻ]Y-闃K1Dhl|/-)7ڛ1HpF|%OK72G[ZDHRVǽrٮl)ܿltp!a:UQ鹄荵'.zO=קza(g’l=!yᖯcHv8?5_?_6`G+/tC +*f|z[|Z뢴um'gmy 6]`e=/N2*rȁ~ cvGIcʛzե3U:qFUӮzV8_ՋRٿ*;Ȏ +ᦼaXtIkh1=pM{sOak#Qo5,Ky~ +c5rJy\2 Q 3ǤDt9qMZF%mD 5]z4æA\i@un[Ic٥b#6Oz@(dA[ &%:q\иP 2ЛxؘАxY3yfA!pem6 +{2&{fX@Do̜TB{ +6Sm}`"3eNUbhM<w7fJ6ZbIqPa6=ڗW`:BTgqAoo +l?#.kH{GL:Jc|4:2ypt6q:D^Xm:vC'(Xu>K/ 3 DY#(#Hyd}Zåq؉~ag7-V|/M< N+=$g٤'LFx,O ,D3|ɸMyu$%p$hOMSox r=ѪzQAye;Ttb4"M1ҕO`~{Ri\!ETN|MNxU*yahxX2j~!4ΑZl9qM8y%RZ>N HSb~3F3?@㖝[Ņ]ACD $s:Σb\.%NB嫹;=Ȯ91D(&f+y>z"A8 hό^Y{]H2 Rtt5R޲p:OɒZo +Hq\axxV5MG<x6Q" j'>ܗw^0,G>y*(8MNΎiQu{`!eonS&yꎆ?\VYKayxJ[P[ЛyN t`yI{fz24|phZc"^9吏_xNSl;OQHgo##c#;~>sh= OY@;< Pg$hW7aLRPlz=fg#K{ǖ| FWA<aRyyz4F^H~[.K6紝æéM= (P6O"m <ˋw:4pMhu5,&l<^}y3^?640G/۾l=٬lgױ4oSX`+ysl'ޙ(.QL6%~mt/-Hw T3?A]mto@Wd˚sW f ++b:Ovgv~16ո!(0eL4FnlMZqlN!i]yw|m|?|ֺƩ9gt@!ϡO֮[Yr khLi.@;Z^NzmD>yRYe9Le!sp$>TnҘz@&MaՖm%S M9VS-} 8P:Ts=,_SCyhsŒvD32vo}"N^t{'A̽G"46J/c|#}UsHLDw f0{1?VfI*4S|6Il@⩘_Bv]lcЅufơ: _.J_E)]qVMkV!I\7M̖>wz +$jr'^.b4j*\nJKe8/ mDq-5V: ;Sk]zQ;W{m;^hn47MS>j_U &^;i:$ye0;$-gmVe0_/cM nH;qmx}\v)ݜurt\<^}=֏[6n]Ǟ$ML5Ahi.6 F{i: +} ָ3e|ivV]>8Zqpz]u(WwFq1ᆹ[29ޤ*kt=z7;]e),^x1Lfi^#j `i&}XOr֗qe'xmC,7=ׂ4zhA4u%oJUi(]@MaQn)OD/StFOVX+a˭=^\ ؟N-L,MJ=i}^ǠnH葩j~M#s*?eä~`8:j2YWN!_) Sܟd9NEhd^7jY)NsCi92.yoos&ҙ3jTK^M~ +endstream +endobj +400 0 obj +<< +/Type /Page +/Parent 1 0 R +/MediaBox [ 0 0 595.275591 841.889764 ] +/Contents 399 0 R +/Resources 4 0 R +/Annots [ 401 0 R 402 0 R 403 0 R 404 0 R 405 0 R 406 0 R 407 0 R 408 0 R 409 0 R 410 0 R 411 0 R 412 0 R 413 0 R 414 0 R 415 0 R 416 0 R 417 0 R 418 0 R 419 0 R 420 0 R 421 0 R 422 0 R 423 0 R 424 0 R 425 0 R 426 0 R 427 0 R 428 0 R 429 0 R 430 0 R 431 0 R 432 0 R 433 0 R ] +/TrimBox [ 0 0 595.275591 841.889764 ] +/BleedBox [ 0 0 595.275591 841.889764 ] +>> +endobj +401 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 84.259843 724.970079 177.650223 709.970079 ] +/BS << +/W 0 +>> +/A << +/Type /Action +/S /URI +/URI (file:///doc_tools/%7B%7B%3Cbaseurl%3E%7D%7D/rancher/v2.6/en/installation) +>> +>> +endobj +402 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 101.433071 696.273057 101.433071 677.523057 ] +/BS << +/W 0 +>> +/Dest (cb10-1) +>> +endobj +403 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 677.326036 99.933071 658.576036 ] +/BS << +/W 0 +>> +/Dest (cb10-2) +>> +endobj +404 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 658.379014 99.933071 639.629014 ] +/BS << +/W 0 +>> +/Dest (cb10-3) +>> +endobj +405 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 639.431993 99.933071 620.681993 ] +/BS << +/W 0 +>> +/Dest (cb10-4) +>> +endobj +406 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 620.484971 99.933071 601.734971 ] +/BS << +/W 0 +>> +/Dest (cb10-5) +>> +endobj +407 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 601.537950 99.933071 582.787950 ] +/BS << +/W 0 +>> +/Dest (cb10-6) +>> +endobj +408 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 582.590928 99.933071 563.840928 ] +/BS << +/W 0 +>> +/Dest (cb10-7) +>> +endobj +409 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 563.643907 99.933071 544.893907 ] +/BS << +/W 0 +>> +/Dest (cb10-8) +>> +endobj +410 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 544.696885 99.933071 525.946885 ] +/BS << +/W 0 +>> +/Dest (cb10-9) +>> +endobj +411 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 525.749864 99.933071 506.999864 ] +/BS << +/W 0 +>> +/Dest (cb10-10) +>> +endobj +412 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 506.802842 99.933071 488.052842 ] +/BS << +/W 0 +>> +/Dest (cb10-11) +>> +endobj +413 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 487.855821 99.933071 469.105821 ] +/BS << +/W 0 +>> +/Dest (cb10-12) +>> +endobj +414 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 468.908799 99.933071 450.158799 ] +/BS << +/W 0 +>> +/Dest (cb10-13) +>> +endobj +415 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 449.961778 99.933071 431.211778 ] +/BS << +/W 0 +>> +/Dest (cb10-14) +>> +endobj +416 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 431.014756 99.933071 412.264756 ] +/BS << +/W 0 +>> +/Dest (cb10-15) +>> +endobj +417 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 412.067735 99.933071 393.317735 ] +/BS << +/W 0 +>> +/Dest (cb10-16) +>> +endobj +418 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 393.120714 99.933071 374.370714 ] +/BS << +/W 0 +>> +/Dest (cb10-17) +>> +endobj +419 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 374.173692 99.933071 355.423692 ] +/BS << +/W 0 +>> +/Dest (cb10-18) +>> +endobj +420 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 355.226671 99.933071 336.476671 ] +/BS << +/W 0 +>> +/Dest (cb10-19) +>> +endobj +421 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 336.279649 99.933071 317.529649 ] +/BS << +/W 0 +>> +/Dest (cb10-20) +>> +endobj +422 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 317.332628 99.933071 298.582628 ] +/BS << +/W 0 +>> +/Dest (cb10-21) +>> +endobj +423 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 298.385606 99.933071 279.635606 ] +/BS << +/W 0 +>> +/Dest (cb10-22) +>> +endobj +424 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 279.438585 99.933071 260.688585 ] +/BS << +/W 0 +>> +/Dest (cb10-23) +>> +endobj +425 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 260.491563 99.933071 241.741563 ] +/BS << +/W 0 +>> +/Dest (cb10-24) +>> +endobj +426 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 241.544542 99.933071 222.794542 ] +/BS << +/W 0 +>> +/Dest (cb10-25) +>> +endobj +427 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 222.597520 99.933071 203.847520 ] +/BS << +/W 0 +>> +/Dest (cb10-26) +>> +endobj +428 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 203.650499 99.933071 184.900499 ] +/BS << +/W 0 +>> +/Dest (cb10-27) +>> +endobj +429 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 184.703477 99.933071 165.953477 ] +/BS << +/W 0 +>> +/Dest (cb10-28) +>> +endobj +430 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 165.756456 99.933071 147.006456 ] +/BS << +/W 0 +>> +/Dest (cb10-29) +>> +endobj +431 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 127.862413 99.933071 109.112413 ] +/BS << +/W 0 +>> +/Dest (cb10-30) +>> +endobj +432 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 108.915391 99.933071 90.165391 ] +/BS << +/W 0 +>> +/Dest (cb10-31) +>> +endobj +433 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 89.968370 99.933071 71.218370 ] +/BS << +/W 0 +>> +/Dest (cb10-32) +>> +endobj +434 0 obj +<< +/Filter /FlateDecode +/Length 4531 +>> +stream +x]M$ ˒H}l"9,r{mXRSN\vK,z"Uڝ-~>wٙK|~xdM +=pv @ɤ|~.ϧvRƝ)%zο(,&rJ6(uB0)VtXƂ!-+A .9h,gqrec5\ Ia9 =VAL^`"=j'x xNQxʃ.6Z +P2+ٜm0!Y MRyQ0RL +ChCQy% G'w%t>ʃ.0>BAFpIYp次pJ/p,I<4 ]G AFUyЅ +kX@D3iX@@[hX@[iX@[.jX@\i5, . T4, `.;5, .{Ұװ9jX@]bg5,`.$UtkXt42iX]r6iX]t#ajQ9[ e  iX] z G (ch  z8]`ϓK4,]W0)}he\.QÂuSyŸW-Zٸ4,]gְo0z pFjuX pqCа` 0g*[rְ wK^f K4,8TÂ^4,]4,]{Tt5,@\ҧk,֦aAʰaALBY(h{ bfSRbCȧuа Y KANakSd .但C  "0!VwQ.5,\5,H!"CjMNksIÂ`(v 2^pIc R.*`(2#2x ְ.xiX=tA4aAYf`F.xl%dFBE Mi)UtLhXH4,@diʃ.XÂYÂ^IÂb "> Fd YaAqg /%7)P|3iXP(* h*J&!:i]|a Jof f DDN d7:] Ȥ񀻈L@V-7$g:3Kƙ [) h9 I4,sTg 0:m`x ٧~*̜! #o9\n̏w|?i88?q:H\v C;3y +>"#J2+I7QC1rnReh,:;3ӓq_/2SQu[SJ^t?3Hp;#Þ/;EZ"JQ x-/ + ]Zev]vZc$g47O_|7/͇?h7ߞz|VƌUbDwZgHyVA!*=E܆,ƽ˭>͗/W!z×m~F*l)yA"޳alIZN"4.LVMW^->\[zs9Z\ޫyK +Tcu2шٛ"=Bh 6NkEZKIu%90A\vL8. vwwE%eG{M:Hgl*3t(fzSɔHE*nrDt#;s1r-Xdr1_ 3"1v]-l +kOu$3N7+KTq2q//Wte%/Wr(:lv%$2e73; 7fD79IKN5-*y[]*tnT.za5H^");֌~[}὞zJ61ˌ 1n3&s qyӷ]z"v$q|y.wL8Λ +3}J]t8rhuXeqmj5!soye +!vL0E!q@e%5mkg0J7\[ȫK\?IuhjrӋR=ބƠq\cckܢdp&ƝnS]N @ EWCq / Y$mZ)+nÌi,(Nn4>承O8/SZ[&Ez}WB][p`#1"qupwd^S[qu)Z~ZTidY&ߘp? ," ON XA֞&O>w,BcT]<&sSgnHx񈩟^}rYhHKd㘱1D>@Ke4![uRx\BӅz쎘73~7$q +)[n(/@yP8M彯X(O;^%q\[@7(s&yc0}wӹ1}s`Mc21 ɪ$ ^eX;,'o21kHnj(l$c,kwZBbY΄k9$r)VVtoǷ]nA$9G9&rc)e%m5i5h޿WackU&[bQGVuu憋¸N#@J" gL8ҡk\VԍUU51(9\Ȑ3rļl16!9~ij9lacpJ{v\+*=.mW>&yVD+-h]2qͯpUK]#?X0EIM7fRʣSCqQVOi~[d-Pq9)bx}1YŐ$wO_5IFו('[sG/%J[2m#k/n麹917#i,6N,ǖeKjAt:/bjZ0Oa3_׵Y0'9\2?Hm7+ +.InN~>ȇ*&YV+K +mWP ]bS%Ī3 /;p%>DU7TZַĦzt3-SgΗO'TKkJcqj&+:JZI!~n%njr#q+Wj9tR]R+gR[~VevuʭFWj>b~\X 7~C|:R R:XaCuH}9_f_|B׬49M~_"4 qs)9^q+F鱡k- QPqU ҭԮ:z*U=Kk^a}VD[@u394W~^g=Cʢ=ذ'fq'ge6}};ħi`5Y\?JfLTiuY1Lay"INOO0)x #99?(-Yqۆa܏dEy,_PtDd粡zCǽgq;{-anÎzG]˄OVlo<`_.>[S*Vy<$[JC:;A\7eWa5[)WҚ^$uu]!4xf[W]_7fWZ(J?ܽ~ݯ*ڠQ{j{06ө4]esh[;B^=jA5Ђv<] REuhpvTuW,gR)f}K*Co)+#^@w4?KX2+K7*%Ҷu:ڞY8Gv #}"-J՟it^ yp!,g'ݔ2/qlg2G_a&'_ Fgt_yke +g9;92I(_Dfd:3M[LL? +endstream +endobj +435 0 obj +<< +/Type /Page +/Parent 1 0 R +/MediaBox [ 0 0 595.275591 841.889764 ] +/Contents 434 0 R +/Resources 4 0 R +/Annots [ 436 0 R 437 0 R 438 0 R 439 0 R 440 0 R 441 0 R 442 0 R 443 0 R 444 0 R 445 0 R 446 0 R 447 0 R 448 0 R 449 0 R 450 0 R 451 0 R 452 0 R 453 0 R 454 0 R 455 0 R 456 0 R 457 0 R 458 0 R 459 0 R 460 0 R 461 0 R 462 0 R 463 0 R 464 0 R 465 0 R 466 0 R 467 0 R 468 0 R 469 0 R 470 0 R 471 0 R 472 0 R 473 0 R ] +/TrimBox [ 0 0 595.275591 841.889764 ] +/BleedBox [ 0 0 595.275591 841.889764 ] +>> +endobj +436 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 799.173057 99.933071 780.423057 ] +/BS << +/W 0 +>> +/Dest (cb10-33) +>> +endobj +437 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 780.226036 99.933071 761.476036 ] +/BS << +/W 0 +>> +/Dest (cb10-34) +>> +endobj +438 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 761.279014 99.933071 742.529014 ] +/BS << +/W 0 +>> +/Dest (cb10-35) +>> +endobj +439 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 742.331993 99.933071 723.581993 ] +/BS << +/W 0 +>> +/Dest (cb10-36) +>> +endobj +440 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 723.384971 99.933071 704.634971 ] +/BS << +/W 0 +>> +/Dest (cb10-37) +>> +endobj +441 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 704.437950 99.933071 685.687950 ] +/BS << +/W 0 +>> +/Dest (cb10-38) +>> +endobj +442 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 685.490928 99.933071 666.740928 ] +/BS << +/W 0 +>> +/Dest (cb10-39) +>> +endobj +443 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 666.543907 99.933071 647.793907 ] +/BS << +/W 0 +>> +/Dest (cb10-40) +>> +endobj +444 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 647.596885 99.933071 628.846885 ] +/BS << +/W 0 +>> +/Dest (cb10-41) +>> +endobj +445 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 628.649864 99.933071 609.899864 ] +/BS << +/W 0 +>> +/Dest (cb10-42) +>> +endobj +446 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 609.702842 99.933071 590.952842 ] +/BS << +/W 0 +>> +/Dest (cb10-43) +>> +endobj +447 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 590.755821 99.933071 572.005821 ] +/BS << +/W 0 +>> +/Dest (cb10-44) +>> +endobj +448 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 571.808799 99.933071 553.058799 ] +/BS << +/W 0 +>> +/Dest (cb10-45) +>> +endobj +449 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 552.861778 99.933071 534.111778 ] +/BS << +/W 0 +>> +/Dest (cb10-46) +>> +endobj +450 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 533.914756 99.933071 515.164756 ] +/BS << +/W 0 +>> +/Dest (cb10-47) +>> +endobj +451 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 514.967735 99.933071 496.217735 ] +/BS << +/W 0 +>> +/Dest (cb10-48) +>> +endobj +452 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 496.020714 99.933071 477.270714 ] +/BS << +/W 0 +>> +/Dest (cb10-49) +>> +endobj +453 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 477.073692 99.933071 458.323692 ] +/BS << +/W 0 +>> +/Dest (cb10-50) +>> +endobj +454 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 458.126671 99.933071 439.376671 ] +/BS << +/W 0 +>> +/Dest (cb10-51) +>> +endobj +455 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 439.179649 99.933071 420.429649 ] +/BS << +/W 0 +>> +/Dest (cb10-52) +>> +endobj +456 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 420.232628 99.933071 401.482628 ] +/BS << +/W 0 +>> +/Dest (cb10-53) +>> +endobj +457 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 401.285606 99.933071 382.535606 ] +/BS << +/W 0 +>> +/Dest (cb10-54) +>> +endobj +458 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 382.338585 99.933071 363.588585 ] +/BS << +/W 0 +>> +/Dest (cb10-55) +>> +endobj +459 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 363.391563 99.933071 344.641563 ] +/BS << +/W 0 +>> +/Dest (cb10-56) +>> +endobj +460 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 344.444542 99.933071 325.694542 ] +/BS << +/W 0 +>> +/Dest (cb10-57) +>> +endobj +461 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 325.497520 99.933071 306.747520 ] +/BS << +/W 0 +>> +/Dest (cb10-58) +>> +endobj +462 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 306.550499 99.933071 287.800499 ] +/BS << +/W 0 +>> +/Dest (cb10-59) +>> +endobj +463 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 287.603477 99.933071 268.853477 ] +/BS << +/W 0 +>> +/Dest (cb10-60) +>> +endobj +464 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 268.656456 99.933071 249.906456 ] +/BS << +/W 0 +>> +/Dest (cb10-61) +>> +endobj +465 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 249.709434 99.933071 230.959434 ] +/BS << +/W 0 +>> +/Dest (cb10-62) +>> +endobj +466 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 230.762413 99.933071 212.012413 ] +/BS << +/W 0 +>> +/Dest (cb10-63) +>> +endobj +467 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 211.815391 99.933071 193.065391 ] +/BS << +/W 0 +>> +/Dest (cb10-64) +>> +endobj +468 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 192.868370 99.933071 174.118370 ] +/BS << +/W 0 +>> +/Dest (cb10-65) +>> +endobj +469 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 173.921348 99.933071 155.171348 ] +/BS << +/W 0 +>> +/Dest (cb10-66) +>> +endobj +470 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 154.974327 99.933071 136.224327 ] +/BS << +/W 0 +>> +/Dest (cb10-67) +>> +endobj +471 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 136.027305 99.933071 117.277305 ] +/BS << +/W 0 +>> +/Dest (cb10-68) +>> +endobj +472 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 117.080284 99.933071 98.330284 ] +/BS << +/W 0 +>> +/Dest (cb10-69) +>> +endobj +473 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 98.133262 99.933071 79.383262 ] +/BS << +/W 0 +>> +/Dest (cb10-70) +>> +endobj +474 0 obj +<< +/Filter /FlateDecode +/Length 4945 +>> +stream +x]Ϗq ,M{`0I :Jz-G`gXd,~UEQZ/0/kro*9^ DWBlr>.ϗKw]Ga2sQa#Ǥ3R4Ԉ9ee +G5jPȎ5|vAcA WbVXBUyPĆ@^h:=iAAFpI  < XCńI_ d :Ӏ,t!iH@\] Cа@6Z4, miX@`]ҰPjX@@\4, @.LhX@\vjX@]Lau)&av)pҰհ w X!ǤaAYÂ4`T 0iX[1jXmа w} Py`#nA]װ w}IX5B@yҰDÂuO@+$ "p1O2z\eR*D.iXOְoQZw/VÂE5,9@7,LWc  X @ iX06q ^4,H]4,H] xzd6ȱNՃ"o)X /؉ ׆Et47[mϗ;$;W?P'$ŌZ)ĈoX;;-ݯod]WϏ˺'ٗo9R5$3v{ /OkA|Fx-V._[+VhnwQ !@9Q qrɜg,H CYY{?o{Bپt&Y7^K+\]]) S31Ә"\McTSjVΌ!<d'~ +?o|7(sC- ^= Fkp&Ƿ^֑sHD y@G.CxG7Da dM'4&sSp`1%sPC9 +0M_90voFzV0~޳y5d: IJܴz ʜ@<\{x[ YtoUV7blvphH<e8WQ"C,+"R/C",sHfΫ~>0Me_n{kl`Gm +| sH4 g+;Rw&6H~g%Tib Gky *;ee3Jc<>VVᎢ[5NC7&(0C _v!qxRyh$⒕ M!Ęy "¯q@9Pb1]g(hV^G'q>O%uw >$/V⸻3$jE@e)_{fP<&)K"z\(wKʧ{:a OOa.'[鑧gudy_81hp<]*Q7Elb>0`vH1"=r׳VZem +5q6OA_4Alg!.XdeҺeŎ+XVnaVu[mbގy7 +5}S](c\CQ綝#QVXԩ^W7ń1 7xoG1nzCD[]#yVz$"LY:ދ OQfpaפdcQ6jglG^(1ו7tn};`3nP=9eI+sѤG9b,ì6g݌l&3izPv9!;_Hh_M維#Vz:ȿn.T؏Ab7 ly;S\4K.m]G\VTZ?:sr쀐#b{V1(s3clkDld{^y3cp-LgDʙ3A .Og8qlܿt.i֋&❈GV#[cJoXs)$w21aAr4EՄc3osdmn%e3Q(oh~۶u$J{?cF_9I#((-]`ٚcEAjՕ> en^ +cW0I䄫a9i+vV۶VZm叡Uq8$e21IגRNogNC]4ԣտMEW5Qh hP~@"H"0?vRz)K r9f˗LyL<%Po㦼hT{Mg옳xF^M_;|‹|$'&AbrJt %مo:7]F y0Mqw;E9INDž8|UG_["UPRމ/tɎ[࢜\}@ӑ[T۟kWf"8r6K-cǡ^Q1tȗL_Ñ_0ۣmf2d2um-FGnԘ|s*?he}ouT&vmQ㦻0n7})(,Cr7!ȿw:]HN߹A5 E1uq/40?_OQ&35v"\/򙢠A?mKǭhOP,rnD>V19>ZކWb"$ےqw| ݯRS%3s/;W8 D57Zַ9M\7pD|YZSU|`VU{FNҨl8)B֪FMRhJ-.j{mTnx-gUfS'nЦ>S|#%9Աٍ.Ȇ|Y)g^OFf;L| SsQy.4竹줞*t[c je=T%5kd? +{J)?/ȳMh[cu[395|ɹN4}[Wš,ϵ,P5XG(F'r B9O2>]v2d/A~"'Q#w_%\ -|d=$'*MC3\6Vkh~,ng`%]CP׸=1}ؑ}3]iՋ-c3;%՛$򽇪.%<]WRtv ⢯]eldHz?CAVwхrI3/nҦ 8ѲGQW]TgP7sOm7&x:˴l> Ju=nQ r1aqhGY^ J[4ZE ls)jLwj/SԿ=QiQIRox-Zޜ|wv.bIVhn0J۶mWo{n#̊92Xܔ|fdVZgZp<:LO[N s9pqX5JF][p@dP* +endstream +endobj +475 0 obj +<< +/Type /Page +/Parent 1 0 R +/MediaBox [ 0 0 595.275591 841.889764 ] +/Contents 474 0 R +/Resources 4 0 R +/Annots [ 476 0 R 477 0 R 478 0 R 479 0 R 480 0 R 481 0 R 482 0 R 483 0 R 484 0 R 485 0 R 486 0 R 487 0 R 488 0 R 489 0 R 490 0 R 491 0 R 492 0 R 493 0 R 494 0 R 495 0 R 496 0 R 497 0 R 498 0 R 499 0 R 500 0 R 501 0 R 502 0 R 503 0 R 504 0 R 505 0 R 506 0 R 507 0 R 508 0 R 509 0 R 510 0 R 511 0 R 512 0 R 513 0 R ] +/TrimBox [ 0 0 595.275591 841.889764 ] +/BleedBox [ 0 0 595.275591 841.889764 ] +>> +endobj +476 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 799.173057 99.933071 780.423057 ] +/BS << +/W 0 +>> +/Dest (cb10-71) +>> +endobj +477 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 780.226036 99.933071 761.476036 ] +/BS << +/W 0 +>> +/Dest (cb10-72) +>> +endobj +478 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 761.279014 99.933071 742.529014 ] +/BS << +/W 0 +>> +/Dest (cb10-73) +>> +endobj +479 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 742.331993 99.933071 723.581993 ] +/BS << +/W 0 +>> +/Dest (cb10-74) +>> +endobj +480 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 723.384971 99.933071 704.634971 ] +/BS << +/W 0 +>> +/Dest (cb10-75) +>> +endobj +481 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 704.437950 99.933071 685.687950 ] +/BS << +/W 0 +>> +/Dest (cb10-76) +>> +endobj +482 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 685.490928 99.933071 666.740928 ] +/BS << +/W 0 +>> +/Dest (cb10-77) +>> +endobj +483 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 666.543907 99.933071 647.793907 ] +/BS << +/W 0 +>> +/Dest (cb10-78) +>> +endobj +484 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 647.596885 99.933071 628.846885 ] +/BS << +/W 0 +>> +/Dest (cb10-79) +>> +endobj +485 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 628.649864 99.933071 609.899864 ] +/BS << +/W 0 +>> +/Dest (cb10-80) +>> +endobj +486 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 609.702842 99.933071 590.952842 ] +/BS << +/W 0 +>> +/Dest (cb10-81) +>> +endobj +487 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 590.755821 99.933071 572.005821 ] +/BS << +/W 0 +>> +/Dest (cb10-82) +>> +endobj +488 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 571.808799 99.933071 553.058799 ] +/BS << +/W 0 +>> +/Dest (cb10-83) +>> +endobj +489 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 552.861778 99.933071 534.111778 ] +/BS << +/W 0 +>> +/Dest (cb10-84) +>> +endobj +490 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 533.914756 99.933071 515.164756 ] +/BS << +/W 0 +>> +/Dest (cb10-85) +>> +endobj +491 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 514.967735 99.933071 496.217735 ] +/BS << +/W 0 +>> +/Dest (cb10-86) +>> +endobj +492 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 496.020714 99.933071 477.270714 ] +/BS << +/W 0 +>> +/Dest (cb10-87) +>> +endobj +493 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 477.073692 99.933071 458.323692 ] +/BS << +/W 0 +>> +/Dest (cb10-88) +>> +endobj +494 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 458.126671 99.933071 439.376671 ] +/BS << +/W 0 +>> +/Dest (cb10-89) +>> +endobj +495 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 439.179649 99.933071 420.429649 ] +/BS << +/W 0 +>> +/Dest (cb10-90) +>> +endobj +496 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 420.232628 99.933071 401.482628 ] +/BS << +/W 0 +>> +/Dest (cb10-91) +>> +endobj +497 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 401.285606 99.933071 382.535606 ] +/BS << +/W 0 +>> +/Dest (cb10-92) +>> +endobj +498 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 382.338585 99.933071 363.588585 ] +/BS << +/W 0 +>> +/Dest (cb10-93) +>> +endobj +499 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 363.391563 99.933071 344.641563 ] +/BS << +/W 0 +>> +/Dest (cb10-94) +>> +endobj +500 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 344.444542 99.933071 325.694542 ] +/BS << +/W 0 +>> +/Dest (cb10-95) +>> +endobj +501 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 325.497520 99.933071 306.747520 ] +/BS << +/W 0 +>> +/Dest (cb10-96) +>> +endobj +502 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 306.550499 99.933071 287.800499 ] +/BS << +/W 0 +>> +/Dest (cb10-97) +>> +endobj +503 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 287.603477 99.933071 268.853477 ] +/BS << +/W 0 +>> +/Dest (cb10-98) +>> +endobj +504 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 268.656456 99.933071 249.906456 ] +/BS << +/W 0 +>> +/Dest (cb10-99) +>> +endobj +505 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 249.709434 99.933071 230.959434 ] +/BS << +/W 0 +>> +/Dest (cb10-100) +>> +endobj +506 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 230.762413 99.933071 212.012413 ] +/BS << +/W 0 +>> +/Dest (cb10-101) +>> +endobj +507 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 211.815391 99.933071 193.065391 ] +/BS << +/W 0 +>> +/Dest (cb10-102) +>> +endobj +508 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 192.868370 99.933071 174.118370 ] +/BS << +/W 0 +>> +/Dest (cb10-103) +>> +endobj +509 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 173.921348 99.933071 155.171348 ] +/BS << +/W 0 +>> +/Dest (cb10-104) +>> +endobj +510 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 154.974327 99.933071 136.224327 ] +/BS << +/W 0 +>> +/Dest (cb10-105) +>> +endobj +511 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 136.027305 99.933071 117.277305 ] +/BS << +/W 0 +>> +/Dest (cb10-106) +>> +endobj +512 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 117.080284 99.933071 98.330284 ] +/BS << +/W 0 +>> +/Dest (cb10-107) +>> +endobj +513 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 98.133262 99.933071 79.383262 ] +/BS << +/W 0 +>> +/Dest (cb10-108) +>> +endobj +514 0 obj +<< +/Filter /FlateDecode +/Length 5015 +>> +stream +x]K$qׯCkI> |.MK0z t#3*jzv +4G ~ e??JdTJ9:_~:|*z%⡐џ!Oࢊ'Z=O.˘U9k_DN)Hޫ).,diK`r lI %(%ea!6LQ  >ZM@3^ zh֨"-fhΩx#Ѳ +!$D"- %Z/.8-MI^,F' ^ ]Ih)HˠӖfW>9%1C6HÊ$(,x g^V9Bh bJjvFybm$^0^t `)% l% lr% lʊbt %pڀfNOABg a42IX,xA /hK t68-i$,p\%,p@\IX,a:`%,p@]烕v a:2Z:" @%,:*g(awU9 @VMIKX@]4IX@]DZTXNZ.Hkpג @PGpes`%,: P0K$,]5 R& aiY-FY E$,]gQk4D KXqPohHJ$,]ZX$iQAcaJXPY‚9 pW^\ VX0V@ +3,рZ,aAڔ DNI0`[ B"c A'҂³ j$x@H/I*$,8k%,dַx(aLL$aAFUR\H +HX_J%,z % h$,`HXUe. x-a,]Ќ YkP‚d̠%,/hL$ +ME Li)ExLHXagKX&^' Rn& R/V[ oF /$,:(6%,$$,d3IX OX7" ,[`MD f ffMXbH ppg D2 &,[ɷ^ag#[ŐB[E1f#A 21j +b@a +"w2cYslJ)>~{?Oo*c ;֞͘n* @tC0Hf"ΤݘIb|n̒ep<3g4 O`\yLj.qJ)hٱ>L"(n]m pK"lPYY#8EClgrٲ^дO'@n߰kO_wßf?>ο\O3m"OӢ L4%?Ü7}oy~sI Í L;eu*O˙N^Ln&rcEo!Xo" eNlCO.]7{ˍPNgb8[oѱl^<ςY>~A6(."ץ0|\cz棏IǼ$DO@1'kfe +Ų1ќazdmy:Ty)¤!$Mi!NcxpJe+4gݒ0Av`оV&rNv6^z^4u<^2Յ%<j>`v/¡T +2#*'YhQ~Ky3/Ut6Wkl9Qs\P|咒 +^J~RDZ2O#֥O(9yj8L+'oN23/=^6z ܾ!Ffڸ{I嘐Nh761oKq566ٽޯ:~Ġ]:;ިay󈧇"΀<.F Uhnrluv5c2J* K|7nsި Q*}$DK66-yлC"zs|f=c\дߥum\^gvx/It-?P>чx XF֪|qh^m%au8 . ?/bmjs+}fGh * \< D!UВ ȡQu'I7esj\aN PBB8a!f=X{;U"v 2Jy֎ խ:\ dWkf|!Zv-+~lˎ?Hb~ElЭn7x]tH n23=-0eP/,_н O*nNx ̅TEPȀ&}à沑Ixe9Ǻ$}u2SN˭XXNV:*y/.[\N|ڶ:f4f/=џ9c @mjwdmo]9-'> +endobj +516 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 799.173057 99.933071 780.423057 ] +/BS << +/W 0 +>> +/Dest (cb10-109) +>> +endobj +517 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 780.226036 99.933071 761.476036 ] +/BS << +/W 0 +>> +/Dest (cb10-110) +>> +endobj +518 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 761.279014 99.933071 742.529014 ] +/BS << +/W 0 +>> +/Dest (cb10-111) +>> +endobj +519 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 742.331993 99.933071 723.581993 ] +/BS << +/W 0 +>> +/Dest (cb10-112) +>> +endobj +520 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 723.384971 99.933071 704.634971 ] +/BS << +/W 0 +>> +/Dest (cb10-113) +>> +endobj +521 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 704.437950 99.933071 685.687950 ] +/BS << +/W 0 +>> +/Dest (cb10-114) +>> +endobj +522 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 685.490928 99.933071 666.740928 ] +/BS << +/W 0 +>> +/Dest (cb10-115) +>> +endobj +523 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 666.543907 99.933071 647.793907 ] +/BS << +/W 0 +>> +/Dest (cb10-116) +>> +endobj +524 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 647.596885 99.933071 628.846885 ] +/BS << +/W 0 +>> +/Dest (cb10-117) +>> +endobj +525 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 533.914756 99.933071 515.164756 ] +/BS << +/W 0 +>> +/Dest (cb10-118) +>> +endobj +526 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 514.967735 99.933071 496.217735 ] +/BS << +/W 0 +>> +/Dest (cb10-119) +>> +endobj +527 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 496.020714 99.933071 477.270714 ] +/BS << +/W 0 +>> +/Dest (cb10-120) +>> +endobj +528 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 477.073692 99.933071 458.323692 ] +/BS << +/W 0 +>> +/Dest (cb10-121) +>> +endobj +529 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 458.126671 99.933071 439.376671 ] +/BS << +/W 0 +>> +/Dest (cb10-122) +>> +endobj +530 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 439.179649 99.933071 420.429649 ] +/BS << +/W 0 +>> +/Dest (cb10-123) +>> +endobj +531 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 420.232628 99.933071 401.482628 ] +/BS << +/W 0 +>> +/Dest (cb10-124) +>> +endobj +532 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 101.433071 177.989606 101.433071 159.239606 ] +/BS << +/W 0 +>> +/Dest (cb11-1) +>> +endobj +533 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 159.042585 99.933071 140.292585 ] +/BS << +/W 0 +>> +/Dest (cb11-2) +>> +endobj +534 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 140.095563 99.933071 121.345563 ] +/BS << +/W 0 +>> +/Dest (cb11-3) +>> +endobj +535 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 121.148542 99.933071 102.398542 ] +/BS << +/W 0 +>> +/Dest (cb11-4) +>> +endobj +536 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 102.201520 99.933071 83.451520 ] +/BS << +/W 0 +>> +/Dest (cb11-5) +>> +endobj +537 0 obj +<< +/Filter /FlateDecode +/Length 4885 +>> +stream +x][$9 ~_H8GZ!-1gz:suRUgw[t\N%iwa.9w'kr3X\L?_ggC6ѕ(\z˱?;s)ޔUXLmTX,Hahr1) 5b>lYjQcA=+,-@ ]XPÕykU!Wx.FO;2x.{GdR.:WLJ) %4^.х`5t Y%Bʃ.3i ]>iXG1F]@Hհ=x4,@e#,Ѱ w]iq\SyŸW-Zٸ4,]'kX7Q#:_!jXw0ߌp]W-D.`kXQXlHNC5,H] EÂܵHÂܵaʃ.^5*}Hkm.$ ,@A(kX8sҰ  B> قY*4,@`m +ְ {BkX=tAȠa"So5=.p5?@2% rLЪ/yp<5,9 NR5, 4,๠aA.]E E="s l 眆 A 3d5,\M<5, R<аd;jX&]( a3tkXߔ|3kXP,tAħaAHa`QrR@z{>>~im| 'pg^?=;>rۺx?qY"w|5 ò9OL!ikc"oa$mfqvYh$2NPEnK3c( W4tPi:rYh&;n/+T㮾} (@+W_w2&<R/yy}CgQiUd7m?2"씔{o!ˀ0Ww? J9Qǣ2|Y^ +baۂc:"RGCm ŲžyU@a8ec&|͎8@c>8qJL:,;De+}$>sX7&m\8]vvobN7@:4 I=sw{[4y1'VdEVlz؞o彝HqwBJ9(33^ޛb6)_ *ow4} +q5H}" =:DJψz:7lz_Vh# YϾot4B>e,Gf֎@lٿ2hV 1[ee9o0Sou&W;s,wn:i%OѴ<y4Ns& d266\sINYgy]w<Ȣ> j,*`aZ 5oABE]Vs"7_M*ǞyC7cγrm( I*z4Y%h+Vw~:G=YNgxPyQ0X#9]s"h Kgt 0O%|چp!w̰VߎdluM>8E6O,*[j~<^tkzlqAwѹ﵎t!pCHw"dxYM(k yyOVvM'Br0׎TlXqZrA:Ƶ hWoe~k~9l@H\(H_v#{utv#ސ2|FLTINH!=Y4˝>˓K^ktJhnPΝBJW/0+wgZA^=k޹e}'?P̽eɯlBwtR4z|_ +s;OADqo#$ ,3{FO/Myo>(SQ3wcX@ea(ಷT|tMˮ?qw|Aɻ{E+~?/fнQah +t$d311@B ~zM~WTE'7c㋬ %'wExJew97MoXBcɯny]mmƤ4m=eǜresq,,O~0q3L|LyL1RuOR)؜UzLiL,þEeoX^;K7=-2-stct|sAR>yr0J{sG6nͥEpğwy瑃`A=gQ鏻t{G6n\ȿqsiIrDNvieRKʼms鶎[K g,M^yN[9$ va>T +gEh~FU3ncnu EFN咰Brj+y]&IåӆڤBSYYb|ˋ+Me֯P>پ1*Nẹ;?7jQ +N@5i?)ڼnjw!9]+%d]7ۓ/[(l;e__OrzP!,mu!+XXheRC^}ULU"J|zcdyzkL|*K# +XWw2܉qK:Y+e}ZAlMײ>Gp[ZS_Ub]mѠTiXK6f't9)/l:?Xͷ7\)rSHZn-6KVh-UN^Mm4S>G,կKr T[[o6ڐ_O1+c +Dmd_:5sm*tJ+TF䙾\JCW&7yH#=5 Z Ȟ@ώ*t[b d=T%5kd> +GJv+.]غjf [v,dۦowJL[Xޤ%n6bN0:kom$QNO0)za99}?()'^qoZ 8zA9[> Ɏ{Xx^KqGbm8}s]hhxxYb dm}pbUΔZb|\rQC}H7AcnXf 5!Ǜh +y+4^ a\R>̎UWC4^7޴,Q~svUNA{`BmSiL6д#vB. wZ\ 7 i(\f+՘Ni2=1[Lѩ[:ViGMYx-Zѝs:KXZ5Ti{h{#tERLmo¿j@+UN3Yiy4)CE> +endobj +539 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 799.173057 99.933071 780.423057 ] +/BS << +/W 0 +>> +/Dest (cb11-6) +>> +endobj +540 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 780.226036 99.933071 761.476036 ] +/BS << +/W 0 +>> +/Dest (cb11-7) +>> +endobj +541 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 761.279014 99.933071 742.529014 ] +/BS << +/W 0 +>> +/Dest (cb11-8) +>> +endobj +542 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 742.331993 99.933071 723.581993 ] +/BS << +/W 0 +>> +/Dest (cb11-9) +>> +endobj +543 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 723.384971 99.933071 704.634971 ] +/BS << +/W 0 +>> +/Dest (cb11-10) +>> +endobj +544 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 704.437950 99.933071 685.687950 ] +/BS << +/W 0 +>> +/Dest (cb11-11) +>> +endobj +545 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 685.490928 99.933071 666.740928 ] +/BS << +/W 0 +>> +/Dest (cb11-12) +>> +endobj +546 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 666.543907 99.933071 647.793907 ] +/BS << +/W 0 +>> +/Dest (cb11-13) +>> +endobj +547 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 647.596885 99.933071 628.846885 ] +/BS << +/W 0 +>> +/Dest (cb11-14) +>> +endobj +548 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 628.649864 99.933071 609.899864 ] +/BS << +/W 0 +>> +/Dest (cb11-15) +>> +endobj +549 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 609.702842 99.933071 590.952842 ] +/BS << +/W 0 +>> +/Dest (cb11-16) +>> +endobj +550 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 590.755821 99.933071 572.005821 ] +/BS << +/W 0 +>> +/Dest (cb11-17) +>> +endobj +551 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 571.808799 99.933071 553.058799 ] +/BS << +/W 0 +>> +/Dest (cb11-18) +>> +endobj +552 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 552.861778 99.933071 534.111778 ] +/BS << +/W 0 +>> +/Dest (cb11-19) +>> +endobj +553 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 533.914756 99.933071 515.164756 ] +/BS << +/W 0 +>> +/Dest (cb11-20) +>> +endobj +554 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 514.967735 99.933071 496.217735 ] +/BS << +/W 0 +>> +/Dest (cb11-21) +>> +endobj +555 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 496.020714 99.933071 477.270714 ] +/BS << +/W 0 +>> +/Dest (cb11-22) +>> +endobj +556 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 477.073692 99.933071 458.323692 ] +/BS << +/W 0 +>> +/Dest (cb11-23) +>> +endobj +557 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 458.126671 99.933071 439.376671 ] +/BS << +/W 0 +>> +/Dest (cb11-24) +>> +endobj +558 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 439.179649 99.933071 420.429649 ] +/BS << +/W 0 +>> +/Dest (cb11-25) +>> +endobj +559 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 420.232628 99.933071 401.482628 ] +/BS << +/W 0 +>> +/Dest (cb11-26) +>> +endobj +560 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 101.433071 292.842585 101.433071 274.092585 ] +/BS << +/W 0 +>> +/Dest (cb12-1) +>> +endobj +561 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 273.895563 99.933071 255.145563 ] +/BS << +/W 0 +>> +/Dest (cb12-2) +>> +endobj +562 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 254.948542 99.933071 236.198542 ] +/BS << +/W 0 +>> +/Dest (cb12-3) +>> +endobj +563 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 236.001520 99.933071 217.251520 ] +/BS << +/W 0 +>> +/Dest (cb12-4) +>> +endobj +564 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 217.054499 99.933071 198.304499 ] +/BS << +/W 0 +>> +/Dest (cb12-5) +>> +endobj +565 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 198.107477 99.933071 179.357477 ] +/BS << +/W 0 +>> +/Dest (cb12-6) +>> +endobj +566 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 179.160456 99.933071 160.410456 ] +/BS << +/W 0 +>> +/Dest (cb12-7) +>> +endobj +567 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 160.213434 99.933071 141.463434 ] +/BS << +/W 0 +>> +/Dest (cb12-8) +>> +endobj +568 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 141.266413 99.933071 122.516413 ] +/BS << +/W 0 +>> +/Dest (cb12-9) +>> +endobj +569 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 122.319391 99.933071 103.569391 ] +/BS << +/W 0 +>> +/Dest (cb12-10) +>> +endobj +570 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 103.372370 99.933071 84.622370 ] +/BS << +/W 0 +>> +/Dest (cb12-11) +>> +endobj +571 0 obj +<< +/Filter /FlateDecode +/Length 3690 +>> +stream +x\K ϯE 0t`0$F` -*C~>t=XIV L`ɏduK¯"J9]s<"T8\ct]sto1ZSxe \r`U<b2X.V1b 1h P V,U!F$ bP`7yċp0x]¦'ȥRC5y<1"YRJX<,zxDldAP2[ YvY`]AX#r&%ldI>VY"`~,p"r.֠͞EBY| B,>' ANq€PIb@(Il@I^ C(B&"\Y :XX Y X _ފdap!\XX\R 촰plau9`avYJ,-,.3F< +[X ]&-,.(XX:aB)` `Enn>XX !YXCqof]@H`2XXT Z9*5YXT>WeeG)U "p-,]gQKHm w7D `XXtM^ubaA DGjaA"W pGf p Y ׀5|ɪHa񀻞a>W pWæ)+! C,,HE\9YX)KhaA D@Ƀ,$֮r-Y8 r,H,,@F*!6s1,-,RE,,1îZ\ɀkWlaAR-,;M,,XX+dXXPJ@fn ɶ.xDY ZXPBAШ%O֙‚"iha&AЏ?(6Q&p>}!#fY_v>Wo|夬%iaEBWnNP 8W R !njQ!rB`q=tS!nȐXe&$3˕ɼ.*8ٲ>{璕ۺp?Hގ5r9!CR,@B/A˦^FޜF4ln_}wXO_kzKzxBWtir:Ωk7{\I dNQcC>J=VPk"BQZ_ϲhv|ɻ#[!4DkGdŨ52QɃc^NpыP9FlꀵnaBv1/Gp?sZ?NP]WSxϸ+֘ՍTVO@rI\Qf$ 1/@(@T 4>ؔ7š2tL6Z6`VW7!SYWwF -)(&s4beES4-^EwciIncc^e,j`t7j& +o&(;~{OͨHNnj$,'=Н1#asF6Kި,ُ&%r{q!/T4a妩L>K3m滰/fx=]΂ ~zYrv{r^Rn34}8ޛ/-}qyD@1e=F. d͐ey5o2!ubʠk.y +%;Om`(ty=amy9cJM].xwh(L +yZJSf˄*YO*qzl̋Q>R"2Ulr*ä=-攷 JyƔvPo.R =doǩZ&M-CFjYYnݴdžH#J@&q3yn),9&'!gwEQhρ +fT^;쐢yC\1f񴓩y>0^CUizcQ{s{=ȐE.occ^Af}5K}lR\Eld75SWv݌sjJq)bFؘc)O?l'۠.WﳌzWn<>1A7oθCŽdׯ#'Cd0q5Nr ? }Pb s eD#)v A{C}qJizRn~3kBJNش=ӣv'ڝ#ӪtĔ-@5s>ԿPjxV&Y7^/]yikՀ}VZ2?˫v82Z-A_>:&qW,[,Զ 㕑+[z-.vC}WâՍo\OKO}F ~}.C}Oί_kcb0}J|˳@ "F&${G+YZ*Vꢠf8&p K&1^ 7.u4E5"X'Ji< U;5]!dNoS 34Cޯ~t0Ů{1 S7ޠ-{R9uKNk_& !JA~:l+|l7y2k6>P;UgBMJf'o7i:b + *ι_C +w߱ uڲkOAǖL:Y!OʙXnc7 yFK4{r4s8]>dxZj-2h7C0 }Z[;:Kp2+08M4gGt/|:9"tlݐHo6i#vA&d*olx^:w&Ʊ9t n{"vqz^]nR1_ex4%Zutp%Lј'EsZ6bA΋WeVZScJ#Ƀ'#S7rS<7扅EFCvO*rj4S)M奙sxy9ء>O=1R 4fe [;yQi͢-Pt7Z17:mrܥsAm8kob.-l{gssbwcvV`Pl P e_RHLGs$q+AN}&{*O`iVa՛ %COpo=ͬ ֤kٓyd/ +endstream +endobj +572 0 obj +<< +/Type /Page +/Parent 1 0 R +/MediaBox [ 0 0 595.275591 841.889764 ] +/Contents 571 0 R +/Resources 4 0 R +/Annots [ 573 0 R 574 0 R 575 0 R 576 0 R 577 0 R 578 0 R 579 0 R 580 0 R 581 0 R 582 0 R 583 0 R 584 0 R ] +/TrimBox [ 0 0 595.275591 841.889764 ] +/BleedBox [ 0 0 595.275591 841.889764 ] +>> +endobj +573 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 799.173057 99.933071 780.423057 ] +/BS << +/W 0 +>> +/Dest (cb12-12) +>> +endobj +574 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 780.226036 99.933071 761.476036 ] +/BS << +/W 0 +>> +/Dest (cb12-13) +>> +endobj +575 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 761.279014 99.933071 742.529014 ] +/BS << +/W 0 +>> +/Dest (cb12-14) +>> +endobj +576 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 742.331993 99.933071 723.581993 ] +/BS << +/W 0 +>> +/Dest (cb12-15) +>> +endobj +577 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 723.384971 99.933071 704.634971 ] +/BS << +/W 0 +>> +/Dest (cb12-16) +>> +endobj +578 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 704.437950 99.933071 685.687950 ] +/BS << +/W 0 +>> +/Dest (cb12-17) +>> +endobj +579 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 685.490928 99.933071 666.740928 ] +/BS << +/W 0 +>> +/Dest (cb12-18) +>> +endobj +580 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 666.543907 99.933071 647.793907 ] +/BS << +/W 0 +>> +/Dest (cb12-19) +>> +endobj +581 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 628.649864 99.933071 609.899864 ] +/BS << +/W 0 +>> +/Dest (cb12-20) +>> +endobj +582 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 590.755821 99.933071 572.005821 ] +/BS << +/W 0 +>> +/Dest (cb12-21) +>> +endobj +583 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 571.808799 99.933071 553.058799 ] +/BS << +/W 0 +>> +/Dest (cb12-22) +>> +endobj +584 0 obj +<< +/Type /Annot +/Subtype /Link +/Rect [ 99.933071 552.861778 99.933071 534.111778 ] +/BS << +/W 0 +>> +/Dest (cb12-23) +>> +endobj +585 0 obj +<< +/Title (Hardening Guide with CIS v1.6 Benchmark) +/Dest [ 6 0 R /XYZ 85.009843 502.818898 0 ] +/Count 14 +/First 586 0 R +/Last 597 0 R +/Parent 600 0 R +>> +endobj +586 0 obj +<< +/Title (Overview) +/Dest [ 30 0 R /XYZ 84.259843 272.631496 0 ] +/Count 1 +/First 587 0 R +/Last 587 0 R +/Parent 585 0 R +/Next 588 0 R +>> +endobj +587 0 obj +<< +/Title (Known Issues) +/Dest [ 45 0 R /XYZ 84.259843 799.370079 0 ] +/Count 0 +/Parent 586 0 R +>> +endobj +588 0 obj +<< +/Title (Configure Kernel Runtime Parameters) +/Dest [ 45 0 R /XYZ 84.259843 539.222079 0 ] +/Count 0 +/Prev 586 0 R +/Parent 585 0 R +/Next 589 0 R +>> +endobj +589 0 obj +<< +/Title (Configure etcd user and group) +/Dest [ 45 0 R /XYZ 84.259843 283.686971 0 ] +/Count 1 +/Prev 588 0 R +/First 590 0 R +/Last 590 0 R +/Parent 585 0 R +/Next 591 0 R +>> +endobj +590 0 obj +<< +/Title (Create etcd user and group) +/Dest [ 45 0 R /XYZ 84.259843 169.788971 0 ] +/Count 0 +/Parent 589 0 R +>> +endobj +591 0 obj +<< +/Title (Configure default Service Account) +/Dest [ 53 0 R /XYZ 84.259843 561.590928 0 ] +/Count 1 +/Prev 589 0 R +/First 592 0 R +/Last 592 0 R +/Parent 585 0 R +/Next 593 0 R +>> +endobj +592 0 obj +<< +/Title (Set automountServiceAccountToken to false for default service accounts) +/Dest [ 53 0 R /XYZ 84.259843 522.092928 0 ] +/Count 0 +/Parent 591 0 R +>> +endobj +593 0 obj +<< +/Title (Configure Network Policy) +/Dest [ 67 0 R /XYZ 84.259843 599.840928 0 ] +/Count 1 +/Prev 591 0 R +/First 594 0 R +/Last 594 0 R +/Parent 585 0 R +/Next 595 0 R +>> +endobj +594 0 obj +<< +/Title (Ensure that all Namespaces have Network Policies defined) +/Dest [ 67 0 R /XYZ 84.259843 564.092928 0 ] +/Count 0 +/Parent 593 0 R +>> +endobj +595 0 obj +<< +/Title (Reference Hardened RKE cluster.yml Configuration) +/Dest [ 77 0 R /XYZ 84.259843 191.441066 0 ] +/Count 0 +/Prev 593 0 R +/Parent 585 0 R +/Next 596 0 R +>> +endobj +596 0 obj +<< +/Title (Reference Hardened RKE Template Configuration) +/Dest [ 400 0 R /XYZ 84.259843 799.370079 0 ] +/Count 0 +/Prev 595 0 R +/Parent 585 0 R +/Next 597 0 R +>> +endobj +597 0 obj +<< +/Title (Reference Hardened cloud-config Configuration) +/Dest [ 515 0 R /XYZ 84.259843 385.582628 0 ] +/Count 2 +/Prev 596 0 R +/First 598 0 R +/Last 599 0 R +/Parent 585 0 R +>> +endobj +598 0 obj +<< +/Title (Reference Hardened cloud-config for SUSE Linux Enterprise Server 15 \(SLES 15\) and openSUSE Leap 15) +/Dest [ 515 0 R /XYZ 84.259843 245.434628 0 ] +/Count 0 +/Parent 597 0 R +/Next 599 0 R +>> +endobj +599 0 obj +<< +/Title (Reference Hardened cloud-config for Red Hat Enterprise Linux 8 \(RHEL 8\) and Ubuntu 20.04 LTS) +/Dest [ 538 0 R /XYZ 84.259843 360.287606 0 ] +/Count 0 +/Prev 598 0 R +/Parent 597 0 R +>> +endobj +600 0 obj +<< +/Count 15 +/First 585 0 R +/Last 585 0 R +>> +endobj +601 0 obj +<< +/Length1 9900 +/Filter /FlateDecode +/Length 6558 +>> +stream +x:{\UU^py? 8Tt|:)HZj +>2%S35#sd9ff͌:33^Lfn3ݽkǷ׷Q%CBzzCksoCCӆK/J{Sfll) ;npԓ`yaԤ?Do6wz1ispܓ.i ̐S4sY8%E`YԷL8Cj~xjF^vnZ;ΠI%=cGǷ@"|lΜioθ~HZz6Q? {n^{bQa`拊BMMvT{Y ]_V=xC⤮ +_0WP}Qc󚬏L8@/ 6];':fꆶ?/9hYATeI ES8\v% Xmڬ|;!U/]6O~8Ock||)5Pr瘒% g_ٟ ̞|Jg>#&ׁowQ)N;$ GP? +1 +{U0@MNo i}c!`&̆BXԦisv0 gt mmmW^[:bP:=<3zB[#zA7f:޶ rXǃЭO'={̘^:$됬4;Zi|H>mZ7<.|ڌ'lOD x–7'xrO-No7W"~WZ7jſ 7~kkZ 65W_ ƫ?OjO{+ioD~rG5R| (xP~i)^~/]Vo']ksBD<+ +;?o)'Z o|]q lxLQ;Wy@c+)1ʟOV|.k  o>ȷ3[l@b&$pc(iQu nXoz+>݌]3=k5O)#?'^Ջ>Al>q?V4*'4c% TbI+\qre=m\Rҥ$K3]ԍ +\,+.B.8K5cBDl8S8: +&0G`jƩ"pI'N08??Oc 28q?>Z`&pC6>JC6|PH)ppC|pkpH |@h*{>';ȗA} O/S__ľf׆fI>x' +nj <{WO#eÞF쑈<>9xw79[wc6_t1Z`H_ >#aJ,b5cH@]r1$ ПKS@8ډW`-E\ +sYɆF* NTrQI,4K=2/]$pxd9*'`/lehV:+`dXԓv @pF@\dpp0'K1.cd|2~r|^ΒKXnSMgBxǔ/1 4 +y .ZstZ{ +L*~P)l@e%؄4 K9L$)?C-P"L x#i^n@ ;4D.vIYpB`M0 -%-&޵RaYl/|)grG!i r)6i [UD6 #޴0@yG2̢V)k` aUoiVy {Rceu-ߢ'&JN]xaV6g3EzQ/v* We>A~]IBېcة&RCy(;r)x\bE4%>pAU/ <`Zjj̶#|3'ĦSHo6]lJeb$;䋾4_'F,m6e^dwX󥽔i"א͘!&x@RVk\m4cDXnxo64ڮkHI83yE|?ؓl1aB,pd2FsH )읋MvO5l!{:{g +BB""Sc=!PO'ψȈ̈-]RZV^"rmlmΥ:dfegEEGt+%G%E&Eh R1$k_: +7{ +kŤ6f;>?oHI9%=;^{QW-kWIV +RV4>09@cgm\O}lAAkj8CI #QfzώzhהV{֓)v㯜?%>~ot4FE$Il =]jmTiaB:I*Ӽ&۩ BCkCQ IB6 uD&z\[۹%yy4f4RIsW:*#i9!ekz4u3}ރg&pNm&`}kHL >$rS/.iwI`;UL vm9{P%ﶴ`W?|̇~%>_ڣkO0d23mfG%>@4ZRi{-MLRaN-,&u0˥Qvd=K.YR~ NvBڶ}񝭕u[^ךN+{qh8SeHWm-3Nf3Y"#׏uKuVq~Vgڹ vEh,9\BlF3Y!3tSΨ,_3x-_leɤKRWKtDZėIU)uT7K#7*Mn+wJcY*\!W'5-Ѱ_ o~oow yǒ%h4Fz2]iٺ_j_C_$L(c_PB .KeH8zmaW}3]ӣIރ5t)QW/!:#(zmt-ף?n6vu}v+;n^>^_`EOO[>ZO5?USm3?Z)g~Gey ?nyw(Kۣ5kF t SPo:Vw1:|G5|:6R(U ejTf.Y|leRGm@yslg#Ta?z/:Vh(PqD(MW̤I3VZIQAMwhDт ~Lb~ 6]+9玷$qOv+  W;:dgvƹ;cTAuFQu|"7ڡ;Lw Vs`sƁs8h_ogoWwn"c+L +K;&II1}Њ]1clԸ݈2PAb%?L4Q{&UUlH=?N:9'ty<6Crn23=#7Wm=u<9ynejVޏ_6r:\JdLgaլ|)KliK:cNEa2:)H,bbȒ^o^Z[5jIYk}Z=@v>A/' aM鵐9ͣ][Tcm7+tvþİ>ʂoQiwkwJjO{4%/@[؎X$=PR@ave:l1n#뜙#\7O<(âvܜb5<5L%JeRT.vJd.10NW! rl80ţl"N3|g3qNFQg28$clRIzjg!he4gV-fQmC§]#왓G9ObFYG}/wĀg{Sw%iJ6 t4YǙ2LR7-&],eR,mL RW:.Qܤ@ 54,np()#d7T" n5m0GYRWM$Xӥa.{ܣx 5͘fJ3{R"/%) eRBRKnlM&fӻƲݺvN'/*/;-/[%ǸtߑuXbx]3_zlgiZiJfIڗ>HN ޖ@emc\͡ V("X 0 N8z&B$jD8 &PBw1A6̅4: +9Tam\%z/yf!չi k&~, hlZFYn<, icWd&$pZ_Hgs?3VRB;̦Qm-1%ItܹsMyh?zIڗ6R~e6c‡/v*Le;j n;錑tRFA: z> +stream +xYyxSו>Y2/l%,xӓ]-YWxȖWy_pb2LiI&MB)k !K҄44̌L &:m:th$'ۄ|_{='#Ftba} 59W>h)Ŏde@B NOOynBC{gKpso B"BM0v:Be/sG? +bݍ3yx_Mt6,BK艹H =GE缿[?a~ =cxed4op7s I +\0OA^2f^H8-y +$>/0 +R }@kGi~ӗi,F?CqAI,B@Lj5?Ϙ>}u^ߛ~(P&Zǯ:XI.bI!J%h5Y&(qHJP6ـ,.rP!#@ <*$/=/Bt +xzgCd9#Gc(@on1X̯ҁIQ}A,!Ў%0 sQ2@1o&h>BQa_x3Z %r|;0PZz^AO(%Iu @ñc~DϨNK +C6Tʐ'v_O}Ϳ+ Ef^j܇)tG܀S6aIXE&#g&/ b J*yԅ2OÈW4r5Pub:rUlq8F3bZJ^XBڸɆMOk~UoGk`"e3 >{Iq8meZlr׸]Ul 8N:gxEYJKVZ 1l Ym-kN9!7YYZcW+cF 2*SJWdS,\UVqIA#fLos +<(=@I%V2eO(Y֩T:Y\[ɫ)wj[[Z-x Sfe1=7xQ``&R`E+)ϵƭNv6\>ph)܀2@5&fyOpQqÂ쒅 ; T +e#]l2Yh;ZV]r@dzZY)8nrYK + _c"l?u̓Mc$!ME@C&aSICyI)aK]iIōm!ɦ,p#w0fFd1`1l]dkNǗ9lS&o;+Q2#nfXF q놊; ^Xo @}a&H$Ԅm0RS[ޟ[Wg3Qz!{ߛQ]f2\KHXSVQ{ ڤ@^&_A\X̛)if\dT_5yL~ϔ̞  ϿW&h5WXgrPBNw@Q'#F\wBxen }tl>#6]\m~9G2Lȏiz3K LNH +c$y3r~5UyqB6;S@R :|v5@67~y>r'>E{,|2RT4bWJ2,uطs[Ahy6cI;?ߝ׻y y: ڤѷkY9q5[|ɷ0YswmI}EbyVbY\U? rV.9-_@.Hfo + +Є7u4;#p1L:9˪JW֜BUL. _$S5q$-*k a#t/2Rq!"RBfx6nn7\{㼲ZZh,z۞=44.O{]Xt]sIWK&ԆZP+XD)|ENi.ϷyhVW+ ~ +n)QJYݨzi_3º^; }y]<[yQ1z)) +84lA?B.`DHg~ ?mڠD+9i_me +endstream +endobj +603 0 obj +<< +/Length1 7204 +/Filter /FlateDecode +/Length 4874 +>> +stream +x9kXUוku}.y\^ jA#H-QV1iK'!CmjhjR4k&~Ik-vZ˜~68:1t:c컟k^{`BKKVV>QD +,@ˊ*.ܱ>꟣gYEY[>br~KcE fl-;=g6qWR۸=;o+|4 چΚ߇~ `JSG~wv[_.kohRc4Cg+vaToh=/ K +-mӗZ?^V\d 8@pkl)3hA}R*/@/H݄UP>iK%OeH$ +/g,u5 5BM0ht( +YRHN!;QM#{3?XW9GN7ޙzPOySԧfk)?Kr_fƚ)P.m<*(RvPZtHJ`3T@ ltNOF +)V![ Z{^H\DA:$xW ֔z~!6-3]U!SgxzTxzC7nGRWz-)ƊKhƗ0e!!ϖ:σV'g2|awy?~ +Sv6e <:h~݋}n$#2Sm=]؅G#|Ȋka?>hCC20:SWTVa TVq2VtaV{|8p7 .,uqXRl%V,65.YY.WpUqw.;p0&pi.)%]Xh;ܸȌ | 0obq9ns9nvnr?UIL7f(Di(=Rm<-ӆ@@'Xx S^l3O`0;Gْ6a'p,t#=Gmh%Տs)tzR4S4 nF4ւ5C5uu\ң4EC> &}c4ȈFA6̪a)??\;e8v_8[ `^&H"0ZPFo$ :0;9%\߭k6HMIv[uI+ +g%Y'G&ǮB裣vcƘuq[NͯSs%$dg]Y + u1vVBNHd~&W#Z>}Ru;44,Z);_߱t}т5=9,d wTG){[sU5CZ*zXfLЩgh0)#(YV"V%_&ݲ|ʒ:9cs ˯TK& >a1fdPCQddm![k~#E"M:!=]c~?IIѕk3l@ZvtFL';>:A}5l@7?8pBܮ2Wh#IqHsbH${MΜ9YpWaqU߿$3Ok-vE0ԬS]w䅑3˖O$%J +vACM:!l +ckH ++zSxlmѣ=뾺8/%edyS^<#1"aN +܁ufG|c.osE؊ap3#`(*'f !-e$0˿}ŷGoؼi|U(؉J,eɖc(+|m"H/+qFq=&[ta*H fWKJ$^5fϛΛ;G[ޝ\TW\!N~E_}Jǎ>V=#z!wl2,- ѱcv:Oz]rCv  V 0k]zLv\Z :2Y0'+\ zrbIײĎ+uf-?ݣhI xD`vik{Wzm"^cVTTmO ;-DPꔯaR`(a^X>=:*  \j zIKPI\R:sP.bǮFV&K?-rE.eUe1yuN-rMK67Az]ۣtKjTajTe}f96굕G.яi +Dy/i,j bP"$XCaV ,m4ߒo^$UbPry) 񟑢).~[r<֣=ܾ0_/Y][_hXh\h[обQ]6[MGYN(<[s#š + [#*Yk*S8k}ITX޾xw02Tg;d3q(grL7Ɣ=&#>ʒw#_aq1}[<&=,bOjRt%fZKuNruttݪ `x'8;/fPWsg֝;zY,LO?c˯Pzͧbع@v=QdP,{k!6@ebƧ͘:VyO KJ 5e[Q n%fY1I:Fc[t!3WNp̛|GA[6.Z45)*TN!VLMFl>:&ګӋzCtȜ:#$y'E 1X2j\Y9c c T,3<ˠ,ɺd}!٘lJ6}3ՕIOtn.FP!$*"ʪ5 |k+^v#kOCvN"?:o1/ț[0+$ccH6tnFfN Ŋ[C̟c7 +|fs(1jn{'C~S+>  6YQt%8'nS$Ir [x]Ko;S%u/xDYEZMkJPJ4EΨȨSЌ#2y!}Z?4>P<іJ\qAQ4Ja7HZ%Vm].?ΒX>J,̓KG' t zH-rlhl"`{M 1zfQђiY Yo +,sW{$%"%^=OKR\z +T, Edަ|MxEf^-~5FM/`[ͬ3m XA +P uN` $S JYԪ$ ,&vzv5T@#\=?Z|MZmjj*C!pal! +Rbz&*[7Ӻ*tU* +UDy1<0׫fuu?psifc? 7u唄iS{Y? 1ޚa b(J )1C<1Zw1,`#uMjzK +,!>DuI'TVTBƖȨm lo"l/ | +endstream +endobj +604 0 obj +<< +/Length1 16252 +/Filter /FlateDecode +/Length 11592 +>> +stream +x{y|TEo-w۝ҝI !IH -"  $L@ac' A#A#s:;uo||^ԽUw9uS|OBV (phg&y{lt= B=h5hO[P~8z y`PƤ[킁CRg~A*Bx7M=a9LEӓ\w'W DR̛:{y7=S'̟dPחm:kWύqB6yBILgM/Mv L)=uІ&=k ȸD O?59fObs ͝h'~}<[ꖎ3@ +xəIpDslt&1z];3"QkdF@ñ%@C8W ~+T(sǡSx(Â.Uϥ@> G;P)zCKa;} jF5h6ע@MhٝA@P(v4ن.)P;uEEhFAvP Eݽ{oɒ(PQ8^)*}8iƙ帽hސqw*{ԣlrKHXrhQ*c*!|>9='' \7 ɒawE3bSlRZ +x[F1Zh!H7ׁٜb*.ܫ@l:؀P,MvEiUXgLtTd#,j1!Uxd3;tff K+P7WK+M3Ȟi7Lξz]V3톲8eVn l&leD/xV$n` #J$RP7Gi-Ş6bV:mp4 RRT6s:LTN5w5;yfk0n^3_;qŚcɱXPr@YY-d3̎Yٙh%,nd󾚶p<Ē3= DXMC 1$'IgtӲlN¢lJ GI4^NY]Z-XˠIQ&sTFD@D641yp靸rK{8rR!mz TGc *11[Ý(7%͠0@`mfs 쬬l5 ԧomӀ!g|ʾYWzoVv^s¼ܬѣQn3-o9V5-PN|_.C[]Iu^ wտʳE;09B&fZK4b} 5 +w)C! AWƵgPL&mGی!2V Fx*­̽D6Ý@2;ZUJk|7$Y7^č@w4Ml+s2+(\ꁮ9>݌0Fdw5#55@]6X^W fT `$zmE_D +(ZT%wvCv]0lpa6;뾛oCգWj&vS`~{hD$Z77ǷN)gJK_*#w#q ѵBV^:@դhAÍ8qN[ dkZ~;qR~=]fG^vXlu6Y +s)=r 7V/:iW9؝Q Eś60cir篥z?NA)8!ELR%EQ>'4_|9_h H88 g[Ȟkr4w{!hNE ^ 'O%'A~MA Edp3F^ŃN,~}n7rTݠhIQI ̖C|*2NG1#G^͑>"=gfhg$_xgnZ1ySONGtj=;t]lCAү}5Z EP]- +Iq}*JPDmt_`|s3&7N!$yF.wvilξ1SNLܵoߖ[˷o\=a}ŵ46s>ͩ̎UXkK۶=śK_ a.萀*( )@T/DLAENEL6FH5=S SRn`ZR-:9XGX'Wqcp&_ J5q =,6Yr1ixa3ˢF^~t+n-h6k5OOۻfh0 pc#|jϬUd` 2W{(!$^qh;怟6k8kh rI\a8>-Qz1C#'Rk| 3vc[͛W^FГ.oKf_3@Ѕx#^Ƕ:K_۫{AMK%=D@yRbǣX8mԂRIˈx$t*{Z(-bӰ+$ +$2@nݽp%J>g +^7pCG6NiN+6֬iˢy+$ܝSdIub0HANf{ 'Sx#UdB @ Nx-QƠ14Hy'Թ9-7f-}v.eKyƣ (TϺc-P ӣtiMuNm7kD[+?~쪕Y|[VmzdBrϮ%SXy/u͵/֜(R̥!o}*Zn@iRj$g +Qtde iwb1cFߧvůek<<Wkw/ A%n $d4ݐ&;ͩV`~@<0][}x.W\fE,ku፻8$ RF`b҂Ԁ5'w*&{̙OvRr;lR<T%*;UӎM2x ʁc=1B:E8 簓 ;kk()R<:R_*3n>p%P4bP%pXWB:#-H"2)Ql/% J.-^(:\,L>%;̀p@@5,vElF_O_j|{ a'MC%Rdmw}rMA> [ PC`!@ E +Cn|JJ(5$0[xoB<@rIh:%\. ,haS)$@.`0j{d@Yna+$1 Y1j3l7Z P,&[P2<{Υs &8H܎$ȝᤄ̐%.R!.xC v ;w9Fֱ)Ħ;d'[utk Lg2UtCn טj#5@-Z]VV_ZZn$*.‘g\Ė٭ex[sP(}fHXͪB$t .EjI~ A.+x~zᅪ {bJͥv](=B7 1U%Z NO  ZtUE.XlӐp%K%Yk1O=cp+,̡Eˬ 0g_:3&^l g;41-kŦ>|h+a]"KgSY: T3V7l/, TY:U}lri69'>-G+|SB\΄pSTe$R`893LL oz}􁱕f?7#ߟV]p!5;Wilgr'E=.d\DJCͻcO==(k$U{n"ggXxM64pVvHূk!na)Ƿh,qp +x# !G̨f~`ѭ6C{o間;aliN~pR\.K+dED +B66m!*e{sp?,5H؃%g~wzVfZSZZ^^Z#m^?d8 gg?|S r?= `\^ +RE~'"!:h.LBEVsKD.+ׯiI ̛|쭒#Z|dc9_ꅍkJؑ[vy C{Www;xD[(R3cR' +(UItb {tn咳s/$dYNz VIzr@tXogTZCtΰ +4k{$zIV7LƠW4&|9PT̠#Vm\ڷv X5nYU)$'=삟:߹WY6v42VpQPvQ{uFʿ4Av!>!:I_hPy +X4 D +kC|kKdkyiK\jПmDO%FP֕{7"{"ΰgS*+iA6dA1"j먹ѸUY + U[kl Y`NK>x/}Q̎o}7~]yGۗIʥ ۧy\V N ٙ@&EۂYKRnNoڮ8' -9,E #bI:YJ!B'Ep#\"p-Mʝig![̑>H!gti>%.ѿm^]b6H6R|l)$+Y>ƮJ ȢU i I~:^`)HK @iQ#>7g"z>tgw'0џVNQL$ q!hYF_`o?]]t#4Ÿ.Լ+׵,=+UHST9UIե|G~x~D~d~T~t~Ls]!WH+ + +u2Q^QYU]St1ZH +<8=v?Oݙ:SˮI&k{c[?_ury(_xo,~;[z?Va +wJwn5eRU8YM=5\s34<*Lx晊8;q>w0a(`7^l0Vch ^Z4|! +=FaEPNO?BSZ9d8;xpj8 l+, pt4EJ/@.]9z09JK׮---#ՓO]i-$uCFla8w_o +ddAA3" tGeU>Q[kο =1#36[PTaNxw7{- <ԩ^G(VHz^yJˑL;ر ^:[ˡ;ZRMΐkF c3U|g|ڬ3T4L8V?s8{v|IOٹ{B%la<⓽ n@$$aB "SiNʷ/F#_0Q""\]rą?@$Jܩiсx{!l:|U`KML4+aVT0p#. +xa2#~C!&R` AF]|b<j1BʞU{;6rZ|x:Y7I3Q,5`L0uY#BT^(Ʉi2p}^;y{p?0;`ֱf: ,L,]썦|&(Qe: +KHEHr\h:)Q{}XLg( E?U.edY0q˪Z..}:`6h73dK]\tНׅ1TMXQPbCq]T.kGOP@v ^J~!UԼu@x=]ʯŠF͙;򱊆g6_ѷ򉪟.l"6lU9 abe1A ~_: ~GCqfz &%Jo0 bEuQ}"ꤩ':"n#n"c]H/h#O{ 5 ?0,Uߓ}a#5l}]?s]ھ!*bWnS |?^ݬFtPo1VN`_uou C\4-FOh*m$șP:26Cp4h2ȿ=-BsPfߣ5_kMdxIؗ*@aZwL{'ڝqPσ{&p_KpS4qw;럗ͭԎ֎*msFԴ1K#8(>6".¾=B ]OĄ(u'fԩOLRgM n~Z/?S +endstream +endobj +605 0 obj +<< +/Type /FontDescriptor +/FontName /PDIVRQ+DejaVuSans +/FontFamily (DejaVu Sans) +/Flags 4 +/FontBBox [ 0 -14 472 560 ] +/ItalicAngle 0 +/Ascent 928 +/Descent -235 +/CapHeight 560 +/StemV 80 +/StemH 80 +/FontFile2 601 0 R +>> +endobj +606 0 obj +<< +/Type /Font +/Subtype /CIDFontType2 +/BaseFont /PDIVRQ+DejaVuSans +/CIDSystemInfo << +/Registry (Adobe) +/Ordering (Identity) +/Supplement 0 +>> +/W [ 3 [ 317 ] 17 [ 317 ] 20 [ 636 ] 25 [ 636 ] 37 [ 686 698 ] 42 [ 774 751 294 ] 54 [ 634 ] 68 [ 612 ] 70 [ 549 634 615 ] 74 [ 634 633 277 ] 78 [ 579 ] 80 [ 974 633 611 ] 85 [ 411 520 392 633 591 817 ] ] +/FontDescriptor 605 0 R +>> +endobj +607 0 obj +<< +/Length 702 +>> +stream +/CIDInit /ProcSet findresource begin +12 dict begin +begincmap +/CIDSystemInfo +<< /Registry (Adobe) +/Ordering (UCS) +/Supplement 0 +>> def +/CMapName /Adobe-Identity-UCS def +/CMapType 2 def +1 begincodespacerange +<0000> +endcodespacerange +27 beginbfchar +<002b> <0048> +<0044> <0061> +<0055> <0072> +<0047> <0064> +<0048> <0065> +<0051> <006e> +<004c> <0069> +<004a> <0067> +<0003> <0020> +<002a> <0047> +<0058> <0075> +<005a> <0077> +<0057> <0074> +<004b> <0068> +<0026> <0043> +<002c> <0049> +<0036> <0053> +<0059> <0076> +<0014> <0031> +<0011> <002e> +<0019> <0036> +<0025> <0042> +<0046> <0063> +<0050> <006d> +<004e> <006b> +<0052> <006f> +<0056> <0073> +endbfchar +endcmap +CMapName currentdict /CMap defineresource pop +end +end +endstream +endobj +608 0 obj +<< +/Type /Font +/Subtype /Type0 +/BaseFont /PDIVRQ+DejaVuSans +/Encoding /Identity-H +/DescendantFonts [ 606 0 R ] +/ToUnicode 607 0 R +>> +endobj +609 0 obj +<< +/Type /FontDescriptor +/FontName /VMMSNF+Poppins +/FontFamily (Poppins) +/Flags 4 +/FontBBox [ -27 -260 122 795 ] +/ItalicAngle 0 +/Ascent 1049 +/Descent -349 +/CapHeight 795 +/StemV 80 +/StemH 80 +/FontFile2 602 0 R +>> +endobj +610 0 obj +<< +/Type /Font +/Subtype /CIDFontType2 +/BaseFont /VMMSNF+Poppins +/CIDSystemInfo << +/Registry (Adobe) +/Ordering (Identity) +/Supplement 0 +>> +/W [ 3 [ 266 ] 10 [ 158 453 453 ] 15 [ 197 550 209 ] 19 [ 627 319 574 588 628 627 634 545 630 629 212 ] 36 [ 673 612 771 706 512 503 777 691 245 ] 46 [ 598 431 ] 49 [ 702 785 578 ] 53 [ 607 586 540 674 675 975 ] 68 [ 675 675 606 675 619 328 675 639 245 247 514 245 1029 639 639 675 675 372 521 363 639 560 819 478 562 ] 206 [ 379 379 ] 209 [ 411 ] ] +/FontDescriptor 609 0 R +>> +endobj +611 0 obj +<< +/Length 1248 +>> +stream +/CIDInit /ProcSet findresource begin +12 dict begin +begincmap +/CIDSystemInfo +<< /Registry (Adobe) +/Ordering (UCS) +/Supplement 0 +>> def +/CMapName /Adobe-Identity-UCS def +/CMapType 2 def +1 begincodespacerange +<0000> +endcodespacerange +66 beginbfchar +<002b> <0048> +<0044> <0061> +<0055> <0072> +<0047> <0064> +<0048> <0065> +<0051> <006e> +<004c> <0069> +<004a> <0067> +<0003> <0020> +<002a> <0047> +<0058> <0075> +<005a> <0077> +<0057> <0074> +<004b> <0068> +<0026> <0043> +<002c> <0049> +<0036> <0053> +<0059> <0076> +<0014> <0031> +<0011> <002e> +<0019> <0036> +<0025> <0042> +<0046> <0063> +<0050> <006d> +<004e> <006b> +<0016> <0033> +<0017> <0034> +<0018> <0035> +<001a> <0037> +<001c> <0039> +<0032> <004f> +<0052> <006f> +<0049> <0066> +<002e> <004b> +<004f> <006c> +<0035> <0052> +<0033> <0050> +<0056> <0073> +<0053> <0070> +<0024> <0041> +<0031> <004e> +<005c> <0079> +<0028> <0045> +<0037> <0054> +<0010> <002d> +<0015> <0032> +<0045> <0062> +<0054> <0071> +<000b> <0028> +<000c> <0029> +<000f> <002c> +<001d> <003a> +<0039> <0056> +<001b> <0038> +<0013> <0030> +<0027> <0044> +<0029> <0046> +<00d1> <2022> +<005b> <0078> +<003a> <0057> +<0038> <0055> +<00ce> <201c> +<00cf> <201d> +<004d> <006a> +<002f> <004c> +<000a> <0027> +endbfchar +endcmap +CMapName currentdict /CMap defineresource pop +end +end +endstream +endobj +612 0 obj +<< +/Type /Font +/Subtype /Type0 +/BaseFont /VMMSNF+Poppins +/Encoding /Identity-H +/DescendantFonts [ 610 0 R ] +/ToUnicode 611 0 R +>> +endobj +613 0 obj +<< +/Type /FontDescriptor +/FontName /KLOSSF+DejaVuSansMono +/FontFamily (DejaVu Sans Mono) +/Flags 5 +/FontBBox [ 0 -14 584 759 ] +/ItalicAngle 0 +/Ascent 928 +/Descent -235 +/CapHeight 759 +/StemV 80 +/StemH 80 +/FontFile2 603 0 R +>> +endobj +614 0 obj +<< +/Type /Font +/Subtype /CIDFontType2 +/BaseFont /KLOSSF+DejaVuSansMono +/CIDSystemInfo << +/Registry (Adobe) +/Ordering (Identity) +/Supplement 0 +>> +/W [ 16 [ 601 601 ] 29 [ 601 ] 36 [ 601 ] 54 [ 601 601 ] 66 [ 601 ] 68 [ 601 ] 70 [ 601 601 601 601 ] 76 [ 601 ] 78 [ 601 601 601 601 601 601 ] 85 [ 601 601 601 601 601 ] 92 [ 601 ] ] +/FontDescriptor 613 0 R +>> +endobj +615 0 obj +<< +/Length 674 +>> +stream +/CIDInit /ProcSet findresource begin +12 dict begin +begincmap +/CIDSystemInfo +<< /Registry (Adobe) +/Ordering (UCS) +/Supplement 0 +>> def +/CMapName /Adobe-Identity-UCS def +/CMapType 2 def +1 begincodespacerange +<0000> +endcodespacerange +25 beginbfchar +<0048> <0065> +<0057> <0074> +<0046> <0063> +<0047> <0064> +<0049> <0066> +<0044> <0061> +<0058> <0075> +<004f> <006c> +<0056> <0073> +<0055> <0072> +<0011> <002e> +<005c> <0079> +<0050> <006d> +<0042> <005f> +<0053> <0070> +<0052> <006f> +<004c> <0069> +<001d> <003a> +<0010> <002d> +<0051> <006e> +<0036> <0053> +<0059> <0076> +<0024> <0041> +<0037> <0054> +<004e> <006b> +endbfchar +endcmap +CMapName currentdict /CMap defineresource pop +end +end +endstream +endobj +616 0 obj +<< +/Type /Font +/Subtype /Type0 +/BaseFont /KLOSSF+DejaVuSansMono +/Encoding /Identity-H +/DescendantFonts [ 614 0 R ] +/ToUnicode 615 0 R +>> +endobj +617 0 obj +<< +/Type /FontDescriptor +/FontName /FEHHOP+DejaVuSansMono +/FontFamily (DejaVu Sans Mono) +/Flags 4 +/FontBBox [ 0 -14 585 699 ] +/ItalicAngle 0 +/Ascent 928 +/Descent -235 +/CapHeight 699 +/StemV 80 +/StemH 80 +/FontFile2 604 0 R +>> +endobj +618 0 obj +<< +/Type /Font +/Subtype /CIDFontType2 +/BaseFont /FEHHOP+DejaVuSansMono +/CIDSystemInfo << +/Registry (Adobe) +/Ordering (Identity) +/Supplement 0 +>> +/W [ 3 [ 601 602 602 602 602 602 602 602 602 602 ] 14 [ 601 602 601 601 601 601 602 602 601 601 602 602 602 602 601 602 602 ] 32 [ 602 602 ] 36 [ 602 602 602 602 602 602 602 602 602 ] 46 [ 602 602 602 601 602 601 ] 53 [ 602 602 602 602 602 602 ] 60 [ 602 ] 62 [ 602 ] 64 [ 602 ] 66 [ 602 602 602 601 601 601 601 601 602 602 602 602 601 601 602 601 601 602 602 602 601 601 601 602 601 602 601 602 602 602 602 ] ] +/FontDescriptor 617 0 R +>> +endobj +619 0 obj +<< +/Length 1500 +>> +stream +/CIDInit /ProcSet findresource begin +12 dict begin +begincmap +/CIDSystemInfo +<< /Registry (Adobe) +/Ordering (UCS) +/Supplement 0 +>> def +/CMapName /Adobe-Identity-UCS def +/CMapType 2 def +1 begincodespacerange +<0000> +endcodespacerange +84 beginbfchar +<0056> <0073> +<005c> <0079> +<0046> <0063> +<0057> <0074> +<004f> <006c> +<0012> <002f> +<0048> <0065> +<0011> <002e> +<0047> <0064> +<001c> <0039> +<0013> <0030> +<0010> <002d> +<004e> <006b> +<0058> <0075> +<0045> <0062> +<0052> <006f> +<0051> <006e> +<0049> <0066> +<0059> <0076> +<0050> <006d> +<0055> <0072> +<004c> <0069> +<0042> <005f> +<0020> <003d> +<0014> <0031> +<0053> <0070> +<0044> <0061> +<005b> <0078> +<0015> <0032> +<0018> <0035> +<0003> <0020> +<0016> <0033> +<0017> <0034> +<004a> <0067> +<0005> <0022> +<004b> <0068> +<001d> <003a> +<0036> <0053> +<0024> <0041> +<0037> <0054> +<0039> <0056> +<000e> <002b> +<0006> <0023> +<0004> <0021> +<0007> <0024> +<000b> <0028> +<004d> <006a> +<005f> <007c> +<0054> <0071> +<000a> <0027> +<003e> <005b> +<0040> <005d> +<000c> <0029> +<001e> <003b> +<005e> <007b> +<0060> <007d> +<005a> <0077> +<0031> <004e> +<0033> <0050> +<001b> <0038> +<002c> <0049> +<0028> <0045> +<002e> <004b> +<000f> <002c> +<0035> <0052> +<0027> <0044> +<0026> <0043> +<002f> <004c> +<002b> <0048> +<003a> <0057> +<002a> <0047> +<0030> <004d> +<0019> <0036> +<0032> <004f> +<003c> <0059> +<0038> <0055> +<001a> <0037> +<0009> <0026> +<0029> <0046> +<005d> <007a> +<0025> <0042> +<0043> <0060> +<0021> <003e> +<0008> <0025> +endbfchar +endcmap +CMapName currentdict /CMap defineresource pop +end +end +endstream +endobj +620 0 obj +<< +/Type /Font +/Subtype /Type0 +/BaseFont /FEHHOP+DejaVuSansMono +/Encoding /Identity-H +/DescendantFonts [ 618 0 R ] +/ToUnicode 619 0 R +>> +endobj +621 0 obj +<< +/PDIVRQ 608 0 R +/VMMSNF 612 0 R +/KLOSSF 616 0 R +/FEHHOP 620 0 R +>> +endobj +xref +0 622 +0000000000 65535 f +0000000015 00000 n +0000000227 00000 n +0000000343 00000 n +0000027063 00000 n +0000027196 00000 n +0000029848 00000 n +0000030047 00000 n +0000033640 00000 n +0000033990 00000 n +0000034124 00000 n +0000034260 00000 n +0000034422 00000 n +0000034585 00000 n +0000034741 00000 n +0000034898 00000 n +0000035055 00000 n +0000035215 00000 n +0000035376 00000 n +0000035537 00000 n +0000035688 00000 n +0000035840 00000 n +0000036015 00000 n +0000036191 00000 n +0000036367 00000 n +0000036539 00000 n +0000036712 00000 n +0000036884 00000 n +0000037057 00000 n +0000037230 00000 n +0000042250 00000 n +0000042554 00000 n +0000042804 00000 n +0000042940 00000 n +0000043103 00000 n +0000043260 00000 n +0000043417 00000 n +0000043578 00000 n +0000043739 00000 n +0000043891 00000 n +0000044064 00000 n +0000044237 00000 n +0000044410 00000 n +0000044672 00000 n +0000044932 00000 n +0000050113 00000 n +0000050368 00000 n +0000050623 00000 n +0000050756 00000 n +0000050887 00000 n +0000051018 00000 n +0000051149 00000 n +0000051280 00000 n +0000056287 00000 n +0000056584 00000 n +0000056717 00000 n +0000056848 00000 n +0000056981 00000 n +0000057112 00000 n +0000057243 00000 n +0000057374 00000 n +0000057507 00000 n +0000057640 00000 n +0000057771 00000 n +0000057902 00000 n +0000058033 00000 n +0000058164 00000 n +0000063163 00000 n +0000063432 00000 n +0000063565 00000 n +0000063696 00000 n +0000063827 00000 n +0000063958 00000 n +0000064089 00000 n +0000064285 00000 n +0000064544 00000 n +0000064775 00000 n +0000070434 00000 n +0000070787 00000 n +0000070920 00000 n +0000071051 00000 n +0000071182 00000 n +0000071313 00000 n +0000071444 00000 n +0000071575 00000 n +0000071706 00000 n +0000071837 00000 n +0000071968 00000 n +0000072100 00000 n +0000072232 00000 n +0000072364 00000 n +0000072496 00000 n +0000072628 00000 n +0000072761 00000 n +0000072892 00000 n +0000073023 00000 n +0000073154 00000 n +0000073285 00000 n +0000073514 00000 n +0000078930 00000 n +0000079367 00000 n +0000079605 00000 n +0000079739 00000 n +0000079871 00000 n +0000080003 00000 n +0000080135 00000 n +0000080267 00000 n +0000080399 00000 n +0000080531 00000 n +0000080663 00000 n +0000080795 00000 n +0000080928 00000 n +0000081061 00000 n +0000081194 00000 n +0000081327 00000 n +0000081460 00000 n +0000081593 00000 n +0000081726 00000 n +0000081859 00000 n +0000081992 00000 n +0000082125 00000 n +0000082258 00000 n +0000082391 00000 n +0000082524 00000 n +0000082657 00000 n +0000082790 00000 n +0000082923 00000 n +0000083056 00000 n +0000083188 00000 n +0000088237 00000 n +0000088756 00000 n +0000088889 00000 n +0000089022 00000 n +0000089155 00000 n +0000089288 00000 n +0000089421 00000 n +0000089554 00000 n +0000089687 00000 n +0000089820 00000 n +0000089953 00000 n +0000090086 00000 n +0000090219 00000 n +0000090352 00000 n +0000090485 00000 n +0000090618 00000 n +0000090751 00000 n +0000090884 00000 n +0000091017 00000 n +0000091150 00000 n +0000091283 00000 n +0000091416 00000 n +0000091549 00000 n +0000091682 00000 n +0000091815 00000 n +0000091948 00000 n +0000092081 00000 n +0000092214 00000 n +0000092347 00000 n +0000092480 00000 n +0000092613 00000 n +0000092746 00000 n +0000092879 00000 n +0000093012 00000 n +0000093145 00000 n +0000093278 00000 n +0000093411 00000 n +0000093544 00000 n +0000093676 00000 n +0000093807 00000 n +0000098938 00000 n +0000099417 00000 n +0000099550 00000 n +0000099683 00000 n +0000099816 00000 n +0000099949 00000 n +0000100082 00000 n +0000100215 00000 n +0000100348 00000 n +0000100481 00000 n +0000100614 00000 n +0000100747 00000 n +0000100880 00000 n +0000101013 00000 n +0000101146 00000 n +0000101279 00000 n +0000101412 00000 n +0000101545 00000 n +0000101678 00000 n +0000101811 00000 n +0000101944 00000 n +0000102077 00000 n +0000102210 00000 n +0000102343 00000 n +0000102476 00000 n +0000102609 00000 n +0000102742 00000 n +0000102875 00000 n +0000103008 00000 n +0000103141 00000 n +0000103274 00000 n +0000103407 00000 n +0000103540 00000 n +0000103672 00000 n +0000103803 00000 n +0000108729 00000 n +0000109224 00000 n +0000109357 00000 n +0000109491 00000 n +0000109625 00000 n +0000109759 00000 n +0000109893 00000 n +0000110027 00000 n +0000110161 00000 n +0000110295 00000 n +0000110429 00000 n +0000110563 00000 n +0000110697 00000 n +0000110831 00000 n +0000110965 00000 n +0000111099 00000 n +0000111233 00000 n +0000111367 00000 n +0000111501 00000 n +0000111635 00000 n +0000111769 00000 n +0000111903 00000 n +0000112037 00000 n +0000112171 00000 n +0000112305 00000 n +0000112439 00000 n +0000112573 00000 n +0000112707 00000 n +0000112841 00000 n +0000112975 00000 n +0000113109 00000 n +0000113243 00000 n +0000113377 00000 n +0000113511 00000 n +0000113645 00000 n +0000113778 00000 n +0000113910 00000 n +0000118245 00000 n +0000118756 00000 n +0000118890 00000 n +0000119024 00000 n +0000119158 00000 n +0000119292 00000 n +0000119426 00000 n +0000119560 00000 n +0000119694 00000 n +0000119828 00000 n +0000119962 00000 n +0000120096 00000 n +0000120230 00000 n +0000120364 00000 n +0000120498 00000 n +0000120632 00000 n +0000120766 00000 n +0000120900 00000 n +0000121034 00000 n +0000121168 00000 n +0000121302 00000 n +0000121436 00000 n +0000121570 00000 n +0000121704 00000 n +0000121838 00000 n +0000121972 00000 n +0000122106 00000 n +0000122240 00000 n +0000122374 00000 n +0000122508 00000 n +0000122642 00000 n +0000122776 00000 n +0000122910 00000 n +0000123044 00000 n +0000123178 00000 n +0000123312 00000 n +0000123446 00000 n +0000123579 00000 n +0000123711 00000 n +0000128310 00000 n +0000128829 00000 n +0000128963 00000 n +0000129097 00000 n +0000129231 00000 n +0000129365 00000 n +0000129499 00000 n +0000129633 00000 n +0000129767 00000 n +0000129901 00000 n +0000130035 00000 n +0000130169 00000 n +0000130303 00000 n +0000130437 00000 n +0000130571 00000 n +0000130705 00000 n +0000130839 00000 n +0000130973 00000 n +0000131107 00000 n +0000131241 00000 n +0000131375 00000 n +0000131509 00000 n +0000131643 00000 n +0000131777 00000 n +0000131911 00000 n +0000132045 00000 n +0000132179 00000 n +0000132313 00000 n +0000132447 00000 n +0000132581 00000 n +0000132715 00000 n +0000132849 00000 n +0000132983 00000 n +0000133117 00000 n +0000133251 00000 n +0000133385 00000 n +0000133519 00000 n +0000133653 00000 n +0000133786 00000 n +0000133918 00000 n +0000138978 00000 n +0000139497 00000 n +0000139631 00000 n +0000139765 00000 n +0000139899 00000 n +0000140033 00000 n +0000140167 00000 n +0000140301 00000 n +0000140435 00000 n +0000140569 00000 n +0000140703 00000 n +0000140837 00000 n +0000140971 00000 n +0000141105 00000 n +0000141239 00000 n +0000141373 00000 n +0000141507 00000 n +0000141641 00000 n +0000141775 00000 n +0000141909 00000 n +0000142043 00000 n +0000142177 00000 n +0000142311 00000 n +0000142445 00000 n +0000142579 00000 n +0000142713 00000 n +0000142847 00000 n +0000142981 00000 n +0000143115 00000 n +0000143249 00000 n +0000143383 00000 n +0000143517 00000 n +0000143651 00000 n +0000143785 00000 n +0000143919 00000 n +0000144053 00000 n +0000144187 00000 n +0000144321 00000 n +0000144454 00000 n +0000144586 00000 n +0000149623 00000 n +0000150142 00000 n +0000150276 00000 n +0000150410 00000 n +0000150544 00000 n +0000150678 00000 n +0000150812 00000 n +0000150946 00000 n +0000151080 00000 n +0000151214 00000 n +0000151348 00000 n +0000151482 00000 n +0000151616 00000 n +0000151750 00000 n +0000151884 00000 n +0000152018 00000 n +0000152152 00000 n +0000152286 00000 n +0000152420 00000 n +0000152554 00000 n +0000152688 00000 n +0000152822 00000 n +0000152956 00000 n +0000153090 00000 n +0000153224 00000 n +0000153358 00000 n +0000153492 00000 n +0000153626 00000 n +0000153760 00000 n +0000153894 00000 n +0000154028 00000 n +0000154162 00000 n +0000154296 00000 n +0000154430 00000 n +0000154564 00000 n +0000154698 00000 n +0000154832 00000 n +0000154966 00000 n +0000155099 00000 n +0000155231 00000 n +0000160389 00000 n +0000160868 00000 n +0000161098 00000 n +0000161233 00000 n +0000161366 00000 n +0000161499 00000 n +0000161632 00000 n +0000161765 00000 n +0000161898 00000 n +0000162031 00000 n +0000162164 00000 n +0000162297 00000 n +0000162431 00000 n +0000162565 00000 n +0000162699 00000 n +0000162833 00000 n +0000162967 00000 n +0000163101 00000 n +0000163235 00000 n +0000163369 00000 n +0000163503 00000 n +0000163637 00000 n +0000163771 00000 n +0000163905 00000 n +0000164039 00000 n +0000164173 00000 n +0000164307 00000 n +0000164441 00000 n +0000164575 00000 n +0000164709 00000 n +0000164843 00000 n +0000164977 00000 n +0000165111 00000 n +0000165244 00000 n +0000165376 00000 n +0000169982 00000 n +0000170501 00000 n +0000170635 00000 n +0000170769 00000 n +0000170903 00000 n +0000171037 00000 n +0000171171 00000 n +0000171305 00000 n +0000171439 00000 n +0000171573 00000 n +0000171707 00000 n +0000171841 00000 n +0000171975 00000 n +0000172109 00000 n +0000172243 00000 n +0000172377 00000 n +0000172511 00000 n +0000172645 00000 n +0000172779 00000 n +0000172913 00000 n +0000173047 00000 n +0000173181 00000 n +0000173315 00000 n +0000173449 00000 n +0000173583 00000 n +0000173717 00000 n +0000173851 00000 n +0000173985 00000 n +0000174119 00000 n +0000174253 00000 n +0000174387 00000 n +0000174521 00000 n +0000174655 00000 n +0000174789 00000 n +0000174923 00000 n +0000175057 00000 n +0000175191 00000 n +0000175325 00000 n +0000175458 00000 n +0000175590 00000 n +0000180610 00000 n +0000181129 00000 n +0000181263 00000 n +0000181397 00000 n +0000181531 00000 n +0000181665 00000 n +0000181799 00000 n +0000181933 00000 n +0000182067 00000 n +0000182201 00000 n +0000182335 00000 n +0000182469 00000 n +0000182603 00000 n +0000182737 00000 n +0000182871 00000 n +0000183005 00000 n +0000183139 00000 n +0000183273 00000 n +0000183407 00000 n +0000183541 00000 n +0000183675 00000 n +0000183809 00000 n +0000183943 00000 n +0000184077 00000 n +0000184211 00000 n +0000184345 00000 n +0000184479 00000 n +0000184613 00000 n +0000184747 00000 n +0000184881 00000 n +0000185015 00000 n +0000185150 00000 n +0000185285 00000 n +0000185420 00000 n +0000185555 00000 n +0000185690 00000 n +0000185825 00000 n +0000185960 00000 n +0000186094 00000 n +0000186227 00000 n +0000191317 00000 n +0000191700 00000 n +0000191835 00000 n +0000191970 00000 n +0000192105 00000 n +0000192240 00000 n +0000192375 00000 n +0000192510 00000 n +0000192645 00000 n +0000192780 00000 n +0000192915 00000 n +0000193050 00000 n +0000193185 00000 n +0000193320 00000 n +0000193455 00000 n +0000193590 00000 n +0000193725 00000 n +0000193860 00000 n +0000193995 00000 n +0000194128 00000 n +0000194261 00000 n +0000194394 00000 n +0000194526 00000 n +0000199486 00000 n +0000199957 00000 n +0000200090 00000 n +0000200223 00000 n +0000200356 00000 n +0000200489 00000 n +0000200623 00000 n +0000200757 00000 n +0000200891 00000 n +0000201025 00000 n +0000201159 00000 n +0000201293 00000 n +0000201427 00000 n +0000201561 00000 n +0000201695 00000 n +0000201829 00000 n +0000201963 00000 n +0000202097 00000 n +0000202231 00000 n +0000202365 00000 n +0000202499 00000 n +0000202633 00000 n +0000202767 00000 n +0000202902 00000 n +0000203035 00000 n +0000203168 00000 n +0000203301 00000 n +0000203434 00000 n +0000203567 00000 n +0000203700 00000 n +0000203833 00000 n +0000203966 00000 n +0000204100 00000 n +0000204233 00000 n +0000207998 00000 n +0000208309 00000 n +0000208443 00000 n +0000208577 00000 n +0000208711 00000 n +0000208845 00000 n +0000208979 00000 n +0000209113 00000 n +0000209247 00000 n +0000209381 00000 n +0000209515 00000 n +0000209649 00000 n +0000209783 00000 n +0000209917 00000 n +0000210088 00000 n +0000210242 00000 n +0000210357 00000 n +0000210523 00000 n +0000210712 00000 n +0000210841 00000 n +0000211034 00000 n +0000211207 00000 n +0000211391 00000 n +0000211550 00000 n +0000211729 00000 n +0000211906 00000 n +0000212098 00000 n +0000212316 00000 n +0000212528 00000 n +0000212590 00000 n +0000219237 00000 n +0000223479 00000 n +0000228442 00000 n +0000240125 00000 n +0000240357 00000 n +0000240747 00000 n +0000241502 00000 n +0000241652 00000 n +0000241881 00000 n +0000242413 00000 n +0000243715 00000 n +0000243862 00000 n +0000244103 00000 n +0000244476 00000 n +0000245203 00000 n +0000245357 00000 n +0000245598 00000 n +0000246199 00000 n +0000247753 00000 n +0000247907 00000 n +trailer +<< +/Size 622 +/Root 3 0 R +/Info 2 0 R +>> +startxref +247994 +%%EOF diff --git a/content/rancher/v2.6/en/security/hardening-guides/1.6-hardening-2.6/_index.md b/content/rancher/v2.6/en/security/hardening-guides/1.6-hardening-2.6/_index.md new file mode 100644 index 00000000000..9ec9b5338dd --- /dev/null +++ b/content/rancher/v2.6/en/security/hardening-guides/1.6-hardening-2.6/_index.md @@ -0,0 +1,637 @@ +--- +title: Hardening Guide with CIS v1.6 Benchmark +weight: 100 +--- + +This document provides prescriptive guidance for hardening a production installation of a RKE cluster to be used with Rancher v2.6.3. It outlines the configurations and controls required to address Kubernetes benchmark controls from the Center for Information Security (CIS). + +> This hardening guide describes how to secure the nodes in your cluster, and it is recommended to follow this guide before installing Kubernetes. + +This hardening guide is intended to be used for RKE clusters and associated with specific versions of the CIS Kubernetes Benchmark, Kubernetes, and Rancher: + +| Rancher Version | CIS Benchmark Version | Kubernetes Version | +| --- | --- | --- | +| Rancher v2.6.3 | Benchmark v1.6 | Kubernetes v1.18, v1.19, v1.20 and v1.21 | + +[Click here to download a PDF version of this document](https://releases.rancher.com/documents/security/2.6/Rancher_v2-6_CIS_v1-6_Hardening_Guide.pdf). + +- [Overview](#overview) +- [Configure Kernel Runtime Parameters](#configure-kernel-runtime-parameters) +- [Configure `etcd` user and group](#configure-etcd-user-and-group) +- [Configure `default` service account](#configure-default-service-account) +- [Configure Network Policy](#configure-network-policy) +- [Reference Hardened RKE `cluster.yml` Configuration](#reference-hardened-rke-cluster-yml-configuration) +- [Reference Hardened RKE Template Configuration](#reference-hardened-rke-template-configuration) +- [Reference Hardened **cloud-config** Configuration](#reference-hardened-cloud-config-configuration) + +### Overview + +This document provides prescriptive guidance for hardening a RKE cluster to be used for installing Rancher v2.6.3 with Kubernetes v1.18 up to v1.21 or provisioning a RKE cluster with Kubernetes v1.18 up to v.21 to be used within Rancher v2.6.3. It outlines the configurations required to address Kubernetes benchmark controls from the Center for Information Security (CIS). + +For more details about evaluating a hardened cluster against the official CIS benchmark, refer to the [CIS 1.6 Benchmark - Self-Assessment Guide - Rancher v2.6]({{}}/rancher/v2.6/en/security/hardening-guides/1.6-benchmark-2.6/). + +#### Known Issues + +- Rancher **exec shell** and **view logs** for pods are **not** functional in a CIS v1.6 hardened setup when only public IP is provided when registering custom nodes. This functionality requires a private IP to be provided when registering the custom nodes. +- When setting the `default_pod_security_policy_template_id:` to `restricted` or `restricted-noroot`, based on the pod security policies (PSP) [provided]({{}}/rancher/v2.6/en/admin-settings/pod-security-policies/) by Rancher, Rancher creates **RoleBindings** and **ClusterRoleBindings** on the default service accounts. The CIS v1.6 check 5.1.5 requires that the default service accounts have no roles or cluster roles bound to it apart from the defaults. In addition the default service accounts should be configured such that it does not provide a service account token and does not have any explicit rights assignments. + +### Configure Kernel Runtime Parameters + +The following `sysctl` configuration is recommended for all nodes type in the cluster. Set the following parameters in `/etc/sysctl.d/90-kubelet.conf`: + +```ini +vm.overcommit_memory=1 +vm.panic_on_oom=0 +kernel.panic=10 +kernel.panic_on_oops=1 +kernel.keys.root_maxbytes=25000000 +``` + +Run `sysctl -p /etc/sysctl.d/90-kubelet.conf` to enable the settings. + +### Configure `etcd` user and group + +A user account and group for the **etcd** service is required to be setup before installing RKE. The **uid** and **gid** for the **etcd** user will be used in the RKE **config.yml** to set the proper permissions for files and directories during installation time. + +#### Create `etcd` user and group + +To create the **etcd** user and group run the following console commands. The commands below use `52034` for **uid** and **gid** are for example purposes. Any valid unused **uid** or **gid** could also be used in lieu of `52034`. + +```bash +groupadd --gid 52034 etcd +useradd --comment "etcd service account" --uid 52034 --gid 52034 etcd --shell /usr/sbin/nologin +``` + +Update the RKE **config.yml** with the **uid** and **gid** of the **etcd** user: + +```yaml +services: + etcd: + gid: 52034 + uid: 52034 +``` + +### Configure `default` Service Account + +#### Set `automountServiceAccountToken` to `false` for `default` service accounts + +Kubernetes provides a default service account which is used by cluster workloads where no specific service account is assigned to the pod. Where access to the Kubernetes API from a pod is required, a specific service account should be created for that pod, and rights granted to that service account. The default service account should be configured such that it does not provide a service account token and does not have any explicit rights assignments. + +For each namespace including **default** and **kube-system** on a standard RKE install, the **default** service account must include this value: + +```yaml +automountServiceAccountToken: false +``` + +Save the following configuration to a file called `account_update.yaml`. + +```yaml +apiVersion: v1 +kind: ServiceAccount +metadata: + name: default +automountServiceAccountToken: false +``` + +Create a bash script file called `account_update.sh`. Be sure to `chmod +x account_update.sh` so the script has execute permissions. + +```bash +#!/bin/bash -e + +for namespace in $(kubectl get namespaces -A -o=jsonpath="{.items[*]['metadata.name']}"); do + kubectl patch serviceaccount default -n ${namespace} -p "$(cat account_update.yaml)" +done +``` + +### Configure Network Policy + +#### Ensure that all Namespaces have Network Policies defined + +Running different applications on the same Kubernetes cluster creates a risk of one compromised application attacking a neighboring application. Network segmentation is important to ensure that containers can communicate only with those they are supposed to. A network policy is a specification of how selections of pods are allowed to communicate with each other and other network endpoints. + +Network Policies are namespace scoped. When a network policy is introduced to a given namespace, all traffic not allowed by the policy is denied. However, if there are no network policies in a namespace all traffic will be allowed into and out of the pods in that namespace. To enforce network policies, a CNI (container network interface) plugin must be enabled. This guide uses [Canal](https://github.com/projectcalico/canal) to provide the policy enforcement. Additional information about CNI providers can be found [here](https://www.suse.com/c/rancher_blog/comparing-kubernetes-cni-providers-flannel-calico-canal-and-weave/). + +Once a CNI provider is enabled on a cluster a default network policy can be applied. For reference purposes a **permissive** example is provided below. If you want to allow all traffic to all pods in a namespace (even if policies are added that cause some pods to be treated as “isolated”), you can create a policy that explicitly allows all traffic in that namespace. Save the following configuration as `default-allow-all.yaml`. Additional [documentation](https://kubernetes.io/docs/concepts/services-networking/network-policies/) about network policies can be found on the Kubernetes site. + +> This `NetworkPolicy` is just an example and is not recommended for production use. + +```yaml +--- +apiVersion: networking.k8s.io/v1 +kind: NetworkPolicy +metadata: + name: default-allow-all +spec: + podSelector: {} + ingress: + - {} + egress: + - {} + policyTypes: + - Ingress + - Egress +``` + +Create a bash script file called `apply_networkPolicy_to_all_ns.sh`. Be sure to `chmod +x apply_networkPolicy_to_all_ns.sh` so the script has execute permissions. + +```bash +#!/bin/bash -e + +for namespace in $(kubectl get namespaces -A -o=jsonpath="{.items[*]['metadata.name']}"); do + kubectl apply -f default-allow-all.yaml -n ${namespace} +done +``` + +Execute this script to apply the `default-allow-all.yaml` configuration with the **permissive** `NetworkPolicy` to all namespaces. + +### Reference Hardened RKE `cluster.yml` Configuration + +The reference `cluster.yml` is used by the RKE CLI that provides the configuration needed to achieve a hardened install of Rancher Kubernetes Engine (RKE). RKE install [documentation]({{}}/rke/latest/en/installation/) is provided with additional details about the configuration items. This reference `cluster.yml` does not include the required **nodes** directive which will vary depending on your environment. Documentation for node configuration in RKE can be found [here]({{}}/rke/latest/en/config-options/nodes/). + +> For a Kubernetes v1.18 cluster, the configuration `spec.volumes: 'ephemeral'` should be removed from the `PodSecurityPolicy`, since it's not supported in this Kubernetes release. + +```yaml +# If you intend to deploy Kubernetes in an air-gapped environment, +# please consult the documentation on how to configure custom RKE images. +# https://rancher.com/docs/rke/latest/en/installation/ . + +# The nodes directive is required and will vary depending on your environment. +# Documentation for node configuration can be found here: +# https://rancher.com/docs/rke/latest/en/config-options/nodes/ +nodes: [] +services: + etcd: + image: "" + extra_args: {} + extra_binds: [] + extra_env: [] + win_extra_args: {} + win_extra_binds: [] + win_extra_env: [] + external_urls: [] + ca_cert: "" + cert: "" + key: "" + path: "" + uid: 52034 + gid: 52034 + snapshot: false + retention: "" + creation: "" + backup_config: null + kube-api: + image: "" + extra_args: {} + extra_binds: [] + extra_env: [] + win_extra_args: {} + win_extra_binds: [] + win_extra_env: [] + service_cluster_ip_range: "" + service_node_port_range: "" + pod_security_policy: true + always_pull_images: false + secrets_encryption_config: + enabled: true + custom_config: null + audit_log: + enabled: true + configuration: null + admission_configuration: null + event_rate_limit: + enabled: true + configuration: null + kube-controller: + image: "" + extra_args: + feature-gates: RotateKubeletServerCertificate=true + tls-cipher-suites: TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305,TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384,TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305,TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384,TLS_RSA_WITH_AES_256_GCM_SHA384,TLS_RSA_WITH_AES_128_GCM_SHA256 + extra_binds: [] + extra_env: [] + win_extra_args: {} + win_extra_binds: [] + win_extra_env: [] + cluster_cidr: "" + service_cluster_ip_range: "" + scheduler: + image: "" + extra_args: + tls-cipher-suites: TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305,TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384,TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305,TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384,TLS_RSA_WITH_AES_256_GCM_SHA384,TLS_RSA_WITH_AES_128_GCM_SHA256 + extra_binds: [] + extra_env: [] + win_extra_args: {} + win_extra_binds: [] + win_extra_env: [] + kubelet: + image: "" + extra_args: + feature-gates: RotateKubeletServerCertificate=true + protect-kernel-defaults: true + tls-cipher-suites: TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305,TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384,TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305,TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384,TLS_RSA_WITH_AES_256_GCM_SHA384,TLS_RSA_WITH_AES_128_GCM_SHA256 + extra_binds: [] + extra_env: [] + win_extra_args: {} + win_extra_binds: [] + win_extra_env: [] + cluster_domain: cluster.local + infra_container_image: "" + cluster_dns_server: "" + fail_swap_on: false + generate_serving_certificate: true + kubeproxy: + image: "" + extra_args: {} + extra_binds: [] + extra_env: [] + win_extra_args: {} + win_extra_binds: [] + win_extra_env: [] +network: + plugin: "" + options: {} + mtu: 0 + node_selector: {} + update_strategy: null +authentication: + strategy: "" + sans: [] + webhook: null +addons: | + # Upstream Kubernetes restricted PSP policy + # https://github.com/kubernetes/website/blob/564baf15c102412522e9c8fc6ef2b5ff5b6e766c/content/en/examples/policy/restricted-psp.yaml + apiVersion: policy/v1beta1 + kind: PodSecurityPolicy + metadata: + name: restricted-noroot + spec: + privileged: false + # Required to prevent escalations to root. + allowPrivilegeEscalation: false + requiredDropCapabilities: + - ALL + # Allow core volume types. + volumes: + - 'configMap' + - 'emptyDir' + - 'projected' + - 'secret' + - 'downwardAPI' + # Assume that ephemeral CSI drivers & persistentVolumes set up by the cluster admin are safe to use. + - 'csi' + - 'persistentVolumeClaim' + - 'ephemeral' + hostNetwork: false + hostIPC: false + hostPID: false + runAsUser: + # Require the container to run without root privileges. + rule: 'MustRunAsNonRoot' + seLinux: + # This policy assumes the nodes are using AppArmor rather than SELinux. + rule: 'RunAsAny' + supplementalGroups: + rule: 'MustRunAs' + ranges: + # Forbid adding the root group. + - min: 1 + max: 65535 + fsGroup: + rule: 'MustRunAs' + ranges: + # Forbid adding the root group. + - min: 1 + max: 65535 + readOnlyRootFilesystem: false + --- + apiVersion: rbac.authorization.k8s.io/v1 + kind: ClusterRole + metadata: + name: psp:restricted-noroot + rules: + - apiGroups: + - extensions + resourceNames: + - restricted-noroot + resources: + - podsecuritypolicies + verbs: + - use + --- + apiVersion: rbac.authorization.k8s.io/v1 + kind: ClusterRoleBinding + metadata: + name: psp:restricted-noroot + roleRef: + apiGroup: rbac.authorization.k8s.io + kind: ClusterRole + name: psp:restricted-noroot + subjects: + - apiGroup: rbac.authorization.k8s.io + kind: Group + name: system:serviceaccounts + - apiGroup: rbac.authorization.k8s.io + kind: Group + name: system:authenticated + --- + apiVersion: networking.k8s.io/v1 + kind: NetworkPolicy + metadata: + name: default-allow-all + spec: + podSelector: {} + ingress: + - {} + egress: + - {} + policyTypes: + - Ingress + - Egress + --- + apiVersion: v1 + kind: ServiceAccount + metadata: + name: default + automountServiceAccountToken: false +addons_include: [] +system_images: + etcd: "" + alpine: "" + nginx_proxy: "" + cert_downloader: "" + kubernetes_services_sidecar: "" + kubedns: "" + dnsmasq: "" + kubedns_sidecar: "" + kubedns_autoscaler: "" + coredns: "" + coredns_autoscaler: "" + nodelocal: "" + kubernetes: "" + flannel: "" + flannel_cni: "" + calico_node: "" + calico_cni: "" + calico_controllers: "" + calico_ctl: "" + calico_flexvol: "" + canal_node: "" + canal_cni: "" + canal_controllers: "" + canal_flannel: "" + canal_flexvol: "" + weave_node: "" + weave_cni: "" + pod_infra_container: "" + ingress: "" + ingress_backend: "" + metrics_server: "" + windows_pod_infra_container: "" +ssh_key_path: "" +ssh_cert_path: "" +ssh_agent_auth: false +authorization: + mode: "" + options: {} +ignore_docker_version: false +kubernetes_version: v1.18.12-rancher1-1 +private_registries: [] +ingress: + provider: "" + options: {} + node_selector: {} + extra_args: {} + dns_policy: "" + extra_envs: [] + extra_volumes: [] + extra_volume_mounts: [] + update_strategy: null + http_port: 0 + https_port: 0 + network_mode: "" +cluster_name: +cloud_provider: + name: "" +prefix_path: "" +win_prefix_path: "" +addon_job_timeout: 0 +bastion_host: + address: "" + port: "" + user: "" + ssh_key: "" + ssh_key_path: "" + ssh_cert: "" + ssh_cert_path: "" +monitoring: + provider: "" + options: {} + node_selector: {} + update_strategy: null + replicas: null +restore: + restore: false + snapshot_name: "" +dns: null +upgrade_strategy: + max_unavailable_worker: "" + max_unavailable_controlplane: "" + drain: null + node_drain_input: null +``` + +### Reference Hardened RKE Template Configuration + +The reference RKE template provides the configuration needed to achieve a hardened install of Kubernetes. RKE templates are used to provision Kubernetes and define Rancher settings. Follow the Rancher [documentation]({{}}/rancher/v2.6/en/installation) for additional installation and RKE template details. + +```yaml +# +# Cluster Config +# +default_pod_security_policy_template_id: restricted-noroot +docker_root_dir: /var/lib/docker +enable_cluster_alerting: false +enable_cluster_monitoring: false +enable_network_policy: true +local_cluster_auth_endpoint: + enabled: true +name: '' +# +# Rancher Config +# +rancher_kubernetes_engine_config: + addon_job_timeout: 45 + authentication: + strategy: x509 + dns: + nodelocal: + ip_address: '' + node_selector: null + update_strategy: {} + enable_cri_dockerd: false + ignore_docker_version: true +# +# # Currently only nginx ingress provider is supported. +# # To disable ingress controller, set `provider: none` +# # To enable ingress on specific nodes, use the node_selector, eg: +# provider: nginx +# node_selector: +# app: ingress +# + ingress: + default_backend: false + default_ingress_class: true + http_port: 0 + https_port: 0 + provider: nginx + kubernetes_version: v1.21.8-rancher1-1 + monitoring: + provider: metrics-server + replicas: 1 +# +# If you are using calico on AWS +# +# network: +# plugin: calico +# calico_network_provider: +# cloud_provider: aws +# +# # To specify flannel interface +# +# network: +# plugin: flannel +# flannel_network_provider: +# iface: eth1 +# +# # To specify flannel interface for canal plugin +# +# network: +# plugin: canal +# canal_network_provider: +# iface: eth1 +# + network: + mtu: 0 + options: + flannel_backend_type: vxlan + plugin: canal + rotate_encryption_key: false +# +# services: +# kube-api: +# service_cluster_ip_range: 10.43.0.0/16 +# kube-controller: +# cluster_cidr: 10.42.0.0/16 +# service_cluster_ip_range: 10.43.0.0/16 +# kubelet: +# cluster_domain: cluster.local +# cluster_dns_server: 10.43.0.10 +# + services: + scheduler: + extra_args: + tls-cipher-suites: TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305,TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384,TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305,TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384,TLS_RSA_WITH_AES_256_GCM_SHA384,TLS_RSA_WITH_AES_128_GCM_SHA256 + etcd: + backup_config: + enabled: true + interval_hours: 12 + retention: 6 + safe_timestamp: false + timeout: 300 + creation: 12h + extra_args: + election-timeout: 5000 + heartbeat-interval: 500 + gid: 52034 + retention: 72h + snapshot: false + uid: 52034 + kube_api: + always_pull_images: false + audit_log: + enabled: true + event_rate_limit: + enabled: true + pod_security_policy: true + secrets_encryption_config: + enabled: true + service_node_port_range: 30000-32767 + kube-controller: + extra_args: + feature-gates: RotateKubeletServerCertificate=true + tls-cipher-suites: TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305,TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384,TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305,TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384,TLS_RSA_WITH_AES_256_GCM_SHA384,TLS_RSA_WITH_AES_128_GCM_SHA256 + kubelet: + extra_args: + feature-gates: RotateKubeletServerCertificate=true + protect-kernel-defaults: true + tls-cipher-suites: TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305,TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384,TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305,TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384,TLS_RSA_WITH_AES_256_GCM_SHA384,TLS_RSA_WITH_AES_128_GCM_SHA256 + fail_swap_on: false + generate_serving_certificate: true + ssh_agent_auth: false + upgrade_strategy: + max_unavailable_controlplane: '1' + max_unavailable_worker: 10% +windows_prefered_cluster: false +``` + +### Reference Hardened **cloud-config** Configuration + +A **cloud-config** configuration file is generally used in cloud infrastructure environments to allow for configuration management of compute instances. The reference config configures SUSE Linux Enterprise Server (SLES), openSUSE Leap, Red Hat Enterprise Linux (RHEL) and Ubuntu operating system level settings needed before installing Kubernetes. + +#### Reference Hardened **cloud-config** for SUSE Linux Enterprise Server 15 (SLES 15) and openSUSE Leap 15 + +```yaml +#cloud-config +system_info: + default_user: + groups: + - docker +write_files: +- path: "/etc/sysctl.d/90-kubelet.conf" + owner: root:root + permissions: '0644' + content: | + vm.overcommit_memory=1 + vm.panic_on_oom=0 + kernel.panic=10 + kernel.panic_on_oops=1 + kernel.keys.root_maxbytes=25000000 +package_update: true +ssh_pwauth: false +runcmd: +# Docker should already be installed in SLES 15 SP3 +- zypper install docker containerd +- systemctl daemon-reload +- systemctl enable docker.service +- systemctl start --no-block docker.service +- sysctl -p /etc/sysctl.d/90-kubelet.conf +- groupadd --gid 52034 etcd +- useradd --comment "etcd service account" --uid 52034 --gid 52034 etcd --shell /usr/sbin/nologin +``` + +#### Reference Hardened **cloud-config** for Red Hat Enterprise Linux 8 (RHEL 8) and Ubuntu 20.04 LTS + +```yaml +#cloud-config +system_info: + default_user: + groups: + - docker +write_files: +- path: "/etc/sysctl.d/90-kubelet.conf" + owner: root:root + permissions: '0644' + content: | + vm.overcommit_memory=1 + vm.panic_on_oom=0 + kernel.panic=10 + kernel.panic_on_oops=1 + kernel.keys.root_maxbytes=25000000 +package_update: true +ssh_pwauth: false +runcmd: +# Install Docker from Rancher's Docker installation scripts - github.com/rancher/install-docker +- curl https://releases.rancher.com/install-docker/20.10.sh | sh +- sysctl -p /etc/sysctl.d/90-kubelet.conf +- groupadd --gid 52034 etcd +- useradd --comment "etcd service account" --uid 52034 --gid 52034 etcd --shell /usr/sbin/nologin +``` diff --git a/content/rancher/v2.6/en/security/hardening-guides/_index.md b/content/rancher/v2.6/en/security/hardening-guides/_index.md index a3635419be5..ea4e969f058 100644 --- a/content/rancher/v2.6/en/security/hardening-guides/_index.md +++ b/content/rancher/v2.6/en/security/hardening-guides/_index.md @@ -1,6 +1,6 @@ --- title: Self-Assessment and Hardening Guides for Rancher v2.6 -shortTitle: Rancher v2.6 Guides +shortTitle: Rancher v2.6 Hardening Guides weight: 1 aliases: - /rancher/v2.6/en/security/rancher-2.5/ @@ -10,4 +10,56 @@ aliases: - /rancher/v2.6/en/security/rancher-2.5/1.6-benchmark-2.5/ --- -Rancher v2.6 hardening guides are currently being updated. For the time being, please consult [Rancher v2.5 self-assessment and hardening guides]({{}}/rancher/v2.5/en/security/rancher-2.5) for more information. +Rancher provides specific security hardening guides for each supported Rancher's Kubernetes distributions. + +- [Rancher Kubernetes Distributions](#rancher-kubernetes-distributions) +- [Hardening Guides and Benchmark Versions](#hardening-guides-and-benchmark-versions) + - [RKE Guides](#rke-guides) + - [RKE2 Guides](#rke2-guides) + - [K3s Guides](#k3s) +- [Rancher with SELinux](#rancher-with-selinux) + +# Rancher Kubernetes Distributions + +Rancher uses the following Kubernetes distributions: + +- [**RKE**]({{}}/rke/latest/en/), Rancher Kubernetes Engine, is a CNCF-certified Kubernetes distribution that runs entirely within Docker containers. +- [**RKE2**](https://docs.rke2.io/) is a fully conformant Kubernetes distribution that focuses on security and compliance within the U.S. Federal Government sector. +- [**K3s**]({{}}/k3s/latest/en/) is a fully conformant, lightweight Kubernetes distribution. It is easy to install, with half the memory of upstream Kubernetes, all in a binary of less than 100 MB. + +To harden a Kubernetes cluster outside of Rancher's distributions, refer to your Kubernetes provider docs. + +# Hardening Guides and Benchmark Versions + +These guides have been tested along with the Rancher v2.6 release. Each self-assessment guide is accompanied with a hardening guide and tested on a specific Kubernetes version and CIS benchmark version. If a CIS benchmark has not been validated for your Kubernetes version, you can choose to use the existing guides until a newer version is added. + +### RKE Guides + +| Kubernetes Version | CIS Benchmark Version | Self Assessment Guide | Hardening Guides | +| --- | --- | --- | --- | +| Kubernetes v1.18, v1.19, v1.20 and v1.21 | CIS v1.6 | [Link](./1.6-benchmark-2.6) | [Link](./1.6-hardening-2.6) | + +> **Notes** +> +> - Kubernetes v1.22 is currently in experimental mode in Rancher v2.6.3. +> - CIS v1.20 benchmark version for Kubernetes v1.19 and v1.20 is not yet released as a profile in Rancher's CIS Benchmark chart. + +### RKE2 Guides + +| Kubernetes Version | CIS Benchmark Version | Self Assessment Guide | Hardening Guides | +| --- | --- | --- | --- | +| Kubernetes v1.18 | CIS v1.5 | [Link](https://docs.rke2.io/security/cis_self_assessment15/) | [Link](https://docs.rke2.io/security/hardening_guide/) | +| Kubernetes v1.20 | CIS v1.6 | [Link](https://docs.rke2.io/security/cis_self_assessment16/) | [Link](https://docs.rke2.io/security/hardening_guide/) | + +### K3s Guides + +| Kubernetes Version | CIS Benchmark Version | Self Assessment Guide | Hardening Guide | +| --- | --- | --- | --- | +| Kubernetes v1.17, v1.18, & v1.19 | CIS v1.5 | [Link]({{}}/k3s/latest/en/security/self_assessment/) | [Link]({{}}/k3s/latest/en/security/hardening_guide/) | + + +# Rancher with SELinux + +[Security-Enhanced Linux (SELinux)](https://en.wikipedia.org/wiki/Security-Enhanced_Linux) is a security enhancement to Linux. After being historically used by government agencies, SELinux is now industry standard and is enabled by default on RHEL and CentOS. + +To use Rancher with SELinux, we recommend installing the `rancher-selinux` RPM according to the instructions on [this page.]({{}}/rancher/v2.6/en/security/selinux/#installing-the-rancher-selinux-rpm) diff --git a/scripts/converters/css/style-portrait.css b/scripts/converters/css/style-portrait.css index e6bcd2303ef..ab19e788e28 100644 --- a/scripts/converters/css/style-portrait.css +++ b/scripts/converters/css/style-portrait.css @@ -238,7 +238,7 @@ h2 { font-size:1.5em; } -h3 {font-size:1.4em;} +h3 {font-size:1.2em;} h4 {font-size:1.3em; line-height:30px; } @@ -283,7 +283,7 @@ nav ul li a { nav ul li a::after {content: target-counter(attr(href url), page, decimal); float:right;margin-right:10px;} nav ul li ul {list-style-type: none; border-left-style: dashed; border-left-width: 1px; border-color: #000; margin-top:1.5em;} nav ul li ul li {margin-left:-.5em;color:#ff0000;} -nav ul li ul li a {border:none;font-family:PoppinsExtraLight;margin-top:-1.5em;} +nav ul li ul li a {border:none;font-family:PoppinsExtraLight;font-size:.75em;margin-bottom:1.8em;} nav ul li ul li a::after {font-size:.75em;} nav code {background:none;} nav a{text-decoration:none;outline:none;color:#000;} diff --git a/scripts/converters/run_results_to_md.sh b/scripts/converters/run_results_to_md.sh index acca856e0b1..58521f9670a 100755 --- a/scripts/converters/run_results_to_md.sh +++ b/scripts/converters/run_results_to_md.sh @@ -6,4 +6,4 @@ test_helpers=${2:?path to kube-bench test_helpers scripts is a required argument [ -f ${results} ] || (echo "file:'${results}' does not exist"; exit 1) [ -d ${test_helpers} ] || (echo "dir: '${test_helpers}' not a valid directory"; exit 1) -docker run -v${results}:/source/results.json -v ${test_helpers}:/test_helpers -it --rm doc_converters:latest results_to_md +docker run -v ${results}:/source/results.json -v ${test_helpers}:/test_helpers -it --rm doc_converters:latest results_to_md diff --git a/scripts/converters/scripts/results_to_md.sh b/scripts/converters/scripts/results_to_md.sh index 453dcbde069..388054cd449 100755 --- a/scripts/converters/scripts/results_to_md.sh +++ b/scripts/converters/scripts/results_to_md.sh @@ -1,45 +1,42 @@ #!/bin/bash -#results_file="${1:-/source/results.json}" -results_file="${1:-/home/paraglade/brain/projects/cis_benchmark/clusters/cis/csr.json}" -#test_helpers="${2:-/test_helpers}" -test_helpers="${2:-/home/paraglade/brain/repos/rancher-security-scan/package/helper_scripts}" +results_file="${1:-/source/results.json}" +test_helpers="${2:-/test_helpers}" header() { cat < NOTE: only scored tests are covered in this guide. +> NOTE: Only \`automated\` tests (previously called \`scored\`) are covered in this guide. ### Controls EOF @@ -90,12 +87,11 @@ for id in $(get_ids); do test_desc=$(echo ${result} | jq -r '.description') audit=$(echo ${result} | jq -r '.audit') audit_config=$(echo ${result} | jq -r '.audit_config') - actual_value=$(echo ${result} | jq -r '.actual_value_per_node."cis-aio-0"') + actual_value=$(echo ${result} | jq -r '.actual_value_per_node[]') type=$(echo ${result} | jq -r '.test_type') status=$(echo ${result} | jq -r '.state') remediation=$(echo ${result} | jq -r '.remediation') expected_result=$(echo ${result} | jq -r '.expected_result') -# echo "#### ${test} ${test_desc}" echo if [ "${type}" = "skip" ]; then echo "**Result:** Not Applicable" @@ -113,7 +109,7 @@ for id in $(get_ids); do if [[ ${audit} =~ ".sh" ]]; then audit_script=$(basename $(echo ${audit} | cut -d ' ' -f1)) test_helper="${test_helpers}/${audit_script}" - echo "**Audit Script:** ${audit_script}" + echo "**Audit Script:** \`${audit_script}\`" echo echo '```bash' cat ${test_helper} @@ -143,6 +139,14 @@ for id in $(get_ids); do echo '```' echo fi + if [ ! -z "${expected_result}" ]; then + echo "**Expected Result**:" + echo + echo '```console' + echo ${expected_result} + echo '```' + echo + fi if [ ! -z "${actual_value}" ] && [ "${status}" != "PASS" ] && [ "${type}" != "skip" ] && [ "${type}" != "manual" ]; then echo "**Returned Value**:" echo @@ -151,14 +155,6 @@ for id in $(get_ids); do echo '```' echo fi - if [ ! -z "${expected_result}" ]; then - echo "**Expected result**:" - echo - echo '```console' - echo ${expected_result} - echo '```' - echo - fi done done done