Switch bits.d.o and lintian.d.o to letsencrypt
authorAurelien Jarno <aurelien@aurel32.net>
Wed, 29 Jun 2016 21:24:42 +0000 (23:24 +0200)
committerAurelien Jarno <aurelien@aurel32.net>
Wed, 29 Jun 2016 21:24:42 +0000 (23:24 +0200)
Signed-off-by: Aurelien Jarno <aurelien@aurel32.net>
modules/roles/manifests/static_mirror.pp
modules/ssl/files/chains/bits.debian.org.crt [deleted symlink]
modules/ssl/files/chains/lintian.debian.org.crt [deleted symlink]
modules/ssl/files/servicecerts/bits.debian.org.crt [deleted file]
modules/ssl/files/servicecerts/lintian.debian.org.crt [deleted file]

index b1c11ee..50e3dfc 100644 (file)
@@ -74,15 +74,15 @@ class roles::static_mirror {
 
        ssl::service { 'dsa.debian.org'      : ensure => "ifstatic", notify => Service['apache2'], }
        ssl::service { 'www.debian.org'      : ensure => "ifstatic", notify => Service['apache2'], }
-       ssl::service { 'bits.debian.org'     : ensure => "ifstatic", notify => Service['apache2'], tlsaport => [], }
-       ssl::service { 'lintian.debian.org'  : ensure => "ifstatic", notify => Service['apache2'], tlsaport => [], }
        ssl::service { 'rtc.debian.org'      : ensure => "ifstatic", notify => Service['apache2'], }
        ssl::service { 'd-i.debian.org'      : ensure => "ifstatic", notify => Service['apache2'], }
 
        # do
        ssl::service { 'appstream.debian.org'          : ensure => "ifstatic", notify => Service['apache2'], key => true, }
        ssl::service { 'backports.debian.org'          : ensure => "ifstatic", notify => Service['apache2'], key => true, }
+       ssl::service { 'bits.debian.org'               : ensure => "ifstatic", notify => Service['apache2'], key => true, }
        ssl::service { 'blends.debian.org'             : ensure => "ifstatic", notify => Service['apache2'], key => true, }
+       ssl::service { 'lintian.debian.org'            : ensure => "ifstatic", notify => Service['apache2'], key => true, }
        ssl::service { 'release.debian.org'            : ensure => "ifstatic", notify => Service['apache2'], key => true, }
        ssl::service { 'security-team.debian.org'      : ensure => "ifstatic", notify => Service['apache2'], key => true, }
        ssl::service { 'www.ports.debian.org'          : ensure => "ifstatic", notify => Service['apache2'], key => true, }
diff --git a/modules/ssl/files/chains/bits.debian.org.crt b/modules/ssl/files/chains/bits.debian.org.crt
deleted file mode 120000 (symlink)
index 50d224a..0000000
+++ /dev/null
@@ -1 +0,0 @@
-GANDI-2-CA
\ No newline at end of file
diff --git a/modules/ssl/files/chains/lintian.debian.org.crt b/modules/ssl/files/chains/lintian.debian.org.crt
deleted file mode 120000 (symlink)
index 50d224a..0000000
+++ /dev/null
@@ -1 +0,0 @@
-GANDI-2-CA
\ No newline at end of file
diff --git a/modules/ssl/files/servicecerts/bits.debian.org.crt b/modules/ssl/files/servicecerts/bits.debian.org.crt
deleted file mode 100644 (file)
index 104bbdc..0000000
+++ /dev/null
@@ -1,118 +0,0 @@
-Certificate:
-    Data:
-        Version: 3 (0x2)
-        Serial Number:
-            0e:51:c6:3b:9a:88:a6:46:e2:24:6c:44:f9:2f:bb:19
-    Signature Algorithm: sha256WithRSAEncryption
-        Issuer: C=FR, ST=Paris, L=Paris, O=Gandi, CN=Gandi Standard SSL CA 2
-        Validity
-            Not Before: Jul 13 00:00:00 2015 GMT
-            Not After : Jul 22 23:59:59 2016 GMT
-        Subject: OU=Domain Control Validated, OU=Gandi Standard SSL, CN=bits.debian.org
-        Subject Public Key Info:
-            Public Key Algorithm: rsaEncryption
-                Public-Key: (3072 bit)
-                Modulus:
-                    00:bd:4f:02:39:6b:83:f1:50:f5:a2:a6:23:12:dc:
-                    d9:4c:ef:ff:4b:35:f2:52:27:67:ea:8c:9a:c2:f9:
-                    e2:d3:5f:a9:bd:20:72:e0:f8:c8:8e:42:04:a3:99:
-                    8d:ba:31:1f:bb:85:5a:47:88:a4:61:57:32:d1:e3:
-                    74:cb:8a:64:4e:8e:b3:ab:ac:1b:16:7a:a3:d9:61:
-                    79:ee:c1:5f:97:4c:a4:ae:2a:d1:65:ac:0c:c0:50:
-                    80:15:af:52:fa:f0:6a:93:69:3d:2d:e1:88:9c:0a:
-                    18:18:b0:ae:17:ce:a2:af:d1:c6:84:af:4d:e9:a3:
-                    44:b4:fd:58:ff:5a:d9:eb:9d:ea:f7:9f:68:4b:80:
-                    74:9c:a2:b5:9f:bb:0c:06:1f:b3:6b:dd:eb:ac:3b:
-                    3f:b0:ac:42:ad:64:ac:1f:f9:58:26:e8:27:42:77:
-                    3b:ce:e9:2b:07:bc:52:22:da:94:52:61:8d:38:bd:
-                    49:ae:bc:94:12:34:20:d0:3f:7a:be:16:4a:18:3a:
-                    a2:96:8f:72:ca:2a:d6:5c:9c:35:e6:8b:ea:b6:eb:
-                    aa:2a:97:4c:08:ef:6d:43:f9:01:26:d7:09:47:0e:
-                    da:0b:7c:b8:48:e6:9d:d5:ea:6d:ac:06:5b:d4:af:
-                    c1:f6:73:b0:6a:ca:3e:b5:5a:29:84:05:d0:15:18:
-                    44:6b:fc:94:9e:f4:53:38:29:1d:03:59:dc:a0:21:
-                    03:3b:21:5d:db:86:66:48:3b:66:40:f0:88:e0:9c:
-                    58:b5:c3:82:9d:54:a2:5c:1b:40:f7:3e:c1:a3:ec:
-                    72:10:74:fc:b6:72:5c:ab:bc:7f:7a:d4:b3:1a:22:
-                    99:62:fb:de:6b:f0:f3:aa:39:f7:52:35:61:8f:2c:
-                    92:d6:33:70:1a:eb:4e:8c:5e:cc:19:32:81:1a:01:
-                    78:b9:c0:ec:5c:dc:4d:a9:d7:c9:ca:f5:5c:5a:49:
-                    ee:e9:fa:0b:4c:9c:a7:0c:e2:d2:9d:f2:0d:89:6c:
-                    56:00:ab:be:cc:c3:f5:cb:1c:0d
-                Exponent: 65537 (0x10001)
-        X509v3 extensions:
-            X509v3 Authority Key Identifier: 
-                keyid:B3:90:A7:D8:C9:AF:4E:CD:61:3C:9F:7C:AD:5D:7F:41:FD:69:30:EA
-
-            X509v3 Subject Key Identifier: 
-                E5:0F:04:C1:28:38:AF:C4:B4:68:E5:2B:6E:67:B8:CD:36:B7:CB:1B
-            X509v3 Key Usage: critical
-                Digital Signature, Key Encipherment
-            X509v3 Basic Constraints: critical
-                CA:FALSE
-            X509v3 Extended Key Usage: 
-                TLS Web Server Authentication, TLS Web Client Authentication
-            X509v3 Certificate Policies: 
-                Policy: 1.3.6.1.4.1.6449.1.2.2.26
-                  CPS: https://cps.usertrust.com
-                Policy: 2.23.140.1.2.1
-
-            X509v3 CRL Distribution Points: 
-
-                Full Name:
-                  URI:http://crl.usertrust.com/GandiStandardSSLCA2.crl
-
-            Authority Information Access: 
-                CA Issuers - URI:http://crt.usertrust.com/GandiStandardSSLCA2.crt
-                OCSP - URI:http://ocsp.usertrust.com
-
-            X509v3 Subject Alternative Name: 
-                DNS:bits.debian.org, DNS:www.bits.debian.org
-    Signature Algorithm: sha256WithRSAEncryption
-         6e:6d:ab:20:9e:e6:1e:a0:49:73:16:2f:52:c5:6b:e0:23:d8:
-         86:1f:df:d2:19:96:b5:b6:9c:6d:bd:1b:f6:7b:75:56:e4:f1:
-         83:e9:c8:80:17:6f:63:5c:8e:fb:b0:94:42:51:67:d0:5e:3c:
-         9c:db:49:bc:91:e5:40:14:1e:5c:be:53:4f:0b:04:87:ca:27:
-         8e:31:90:d6:03:fe:34:ff:93:8a:9a:06:be:bc:c8:a9:fc:56:
-         c0:ca:f1:6f:9b:ff:17:fa:a1:ce:85:fa:5f:76:69:53:ea:0c:
-         99:2c:97:cd:9e:c0:08:97:61:fe:41:68:f2:43:9d:b8:da:de:
-         18:b4:41:6f:73:a4:f5:c8:2c:3e:a7:2f:df:37:04:11:c3:5e:
-         c5:85:3c:82:30:1d:0f:fb:c4:e5:e4:1b:32:45:74:2b:cf:d1:
-         d4:eb:3b:3c:c7:49:33:6a:00:6f:1a:19:70:46:d5:42:d5:ce:
-         e6:f7:28:ae:3f:ac:b7:72:74:6c:94:a4:ac:ea:c4:19:43:02:
-         6d:ea:dc:0f:73:c4:9c:52:8e:87:a9:dc:4f:f0:1b:62:f6:1f:
-         61:ac:d9:06:05:8b:9f:3a:8c:e9:eb:68:29:d0:18:bf:87:be:
-         ed:5f:63:8c:49:27:9b:ed:2d:f0:fc:5f:3b:52:3c:94:83:ba:
-         d1:36:a1:fd
------BEGIN CERTIFICATE-----
-MIIFfDCCBGSgAwIBAgIQDlHGO5qIpkbiJGxE+S+7GTANBgkqhkiG9w0BAQsFADBf
-MQswCQYDVQQGEwJGUjEOMAwGA1UECBMFUGFyaXMxDjAMBgNVBAcTBVBhcmlzMQ4w
-DAYDVQQKEwVHYW5kaTEgMB4GA1UEAxMXR2FuZGkgU3RhbmRhcmQgU1NMIENBIDIw
-HhcNMTUwNzEzMDAwMDAwWhcNMTYwNzIyMjM1OTU5WjBaMSEwHwYDVQQLExhEb21h
-aW4gQ29udHJvbCBWYWxpZGF0ZWQxGzAZBgNVBAsTEkdhbmRpIFN0YW5kYXJkIFNT
-TDEYMBYGA1UEAxMPYml0cy5kZWJpYW4ub3JnMIIBojANBgkqhkiG9w0BAQEFAAOC
-AY8AMIIBigKCAYEAvU8COWuD8VD1oqYjEtzZTO//SzXyUidn6oyawvni01+pvSBy
-4PjIjkIEo5mNujEfu4VaR4ikYVcy0eN0y4pkTo6zq6wbFnqj2WF57sFfl0ykrirR
-ZawMwFCAFa9S+vBqk2k9LeGInAoYGLCuF86ir9HGhK9N6aNEtP1Y/1rZ653q959o
-S4B0nKK1n7sMBh+za93rrDs/sKxCrWSsH/lYJugnQnc7zukrB7xSItqUUmGNOL1J
-rryUEjQg0D96vhZKGDqilo9yyirWXJw15ovqtuuqKpdMCO9tQ/kBJtcJRw7aC3y4
-SOad1eptrAZb1K/B9nOwaso+tVophAXQFRhEa/yUnvRTOCkdA1ncoCEDOyFd24Zm
-SDtmQPCI4JxYtcOCnVSiXBtA9z7Bo+xyEHT8tnJcq7x/etSzGiKZYvvea/Dzqjn3
-UjVhjyyS1jNwGutOjF7MGTKBGgF4ucDsXNxNqdfJyvVcWknu6foLTJynDOLSnfIN
-iWxWAKu+zMP1yxwNAgMBAAGjggG3MIIBszAfBgNVHSMEGDAWgBSzkKfYya9OzWE8
-n3ytXX9B/Wkw6jAdBgNVHQ4EFgQU5Q8EwSg4r8S0aOUrbme4zTa3yxswDgYDVR0P
-AQH/BAQDAgWgMAwGA1UdEwEB/wQCMAAwHQYDVR0lBBYwFAYIKwYBBQUHAwEGCCsG
-AQUFBwMCMEsGA1UdIAREMEIwNgYLKwYBBAGyMQECAhowJzAlBggrBgEFBQcCARYZ
-aHR0cHM6Ly9jcHMudXNlcnRydXN0LmNvbTAIBgZngQwBAgEwQQYDVR0fBDowODA2
-oDSgMoYwaHR0cDovL2NybC51c2VydHJ1c3QuY29tL0dhbmRpU3RhbmRhcmRTU0xD
-QTIuY3JsMHMGCCsGAQUFBwEBBGcwZTA8BggrBgEFBQcwAoYwaHR0cDovL2NydC51
-c2VydHJ1c3QuY29tL0dhbmRpU3RhbmRhcmRTU0xDQTIuY3J0MCUGCCsGAQUFBzAB
-hhlodHRwOi8vb2NzcC51c2VydHJ1c3QuY29tMC8GA1UdEQQoMCaCD2JpdHMuZGVi
-aWFuLm9yZ4ITd3d3LmJpdHMuZGViaWFuLm9yZzANBgkqhkiG9w0BAQsFAAOCAQEA
-bm2rIJ7mHqBJcxYvUsVr4CPYhh/f0hmWtbacbb0b9nt1VuTxg+nIgBdvY1yO+7CU
-QlFn0F48nNtJvJHlQBQeXL5TTwsEh8onjjGQ1gP+NP+TipoGvrzIqfxWwMrxb5v/
-F/qhzoX6X3ZpU+oMmSyXzZ7ACJdh/kFo8kOduNreGLRBb3Ok9cgsPqcv3zcEEcNe
-xYU8gjAdD/vE5eQbMkV0K8/R1Os7PMdJM2oAbxoZcEbVQtXO5vcorj+st3J0bJSk
-rOrEGUMCbercD3PEnFKOh6ncT/AbYvYfYazZBgWLnzqM6etoKdAYv4e+7V9jjEkn
-m+0t8PxfO1I8lIO60Tah/Q==
------END CERTIFICATE-----
diff --git a/modules/ssl/files/servicecerts/lintian.debian.org.crt b/modules/ssl/files/servicecerts/lintian.debian.org.crt
deleted file mode 100644 (file)
index 5bb5f48..0000000
+++ /dev/null
@@ -1,118 +0,0 @@
-Certificate:
-    Data:
-        Version: 3 (0x2)
-        Serial Number:
-            eb:d3:cc:5f:03:06:2c:4a:a1:89:8c:db:1b:bd:e7:f5
-    Signature Algorithm: sha256WithRSAEncryption
-        Issuer: C=FR, ST=Paris, L=Paris, O=Gandi, CN=Gandi Standard SSL CA 2
-        Validity
-            Not Before: Jul 13 00:00:00 2015 GMT
-            Not After : Jul 22 23:59:59 2016 GMT
-        Subject: OU=Domain Control Validated, OU=Gandi Standard SSL, CN=lintian.debian.org
-        Subject Public Key Info:
-            Public Key Algorithm: rsaEncryption
-                Public-Key: (3072 bit)
-                Modulus:
-                    00:bc:78:46:64:be:a9:14:42:a8:05:60:19:72:33:
-                    5b:ab:80:0c:33:45:a7:14:e8:ad:88:57:e3:98:0e:
-                    86:55:36:0f:10:7e:6d:24:59:55:3e:44:d7:42:a2:
-                    c8:47:1d:45:a7:50:93:74:bd:11:52:0f:11:28:3b:
-                    5b:b4:07:a9:8d:55:86:23:a3:4c:d3:f1:d9:90:e4:
-                    47:22:b0:a8:40:5b:10:98:30:ae:02:d6:ca:c5:c3:
-                    98:c7:36:18:e4:3e:c1:6f:4d:6f:77:0d:7e:00:6a:
-                    93:40:e6:ed:b8:64:05:b9:2a:09:28:71:f7:19:2e:
-                    3a:fd:fa:92:66:b1:63:70:04:37:ab:9f:55:3f:04:
-                    0a:35:5a:20:0b:94:58:fd:1d:91:09:9b:2b:c8:9a:
-                    eb:17:2b:b0:db:93:d8:67:14:29:a0:fa:b1:b6:45:
-                    8e:24:1a:f0:72:ea:14:b2:16:43:df:d5:71:43:88:
-                    c3:9a:2e:01:ed:c4:f3:5e:bd:fd:dc:9e:d2:c0:40:
-                    f4:68:78:06:1f:76:e1:b4:b3:91:71:e1:db:74:fb:
-                    6b:49:97:5f:63:39:51:fb:00:3e:0d:31:2d:3f:0a:
-                    42:16:4d:e9:40:9c:26:19:a1:7b:4f:2a:64:9d:60:
-                    a7:53:76:8b:e6:0d:4d:23:f5:ab:cb:d9:63:7e:bc:
-                    46:0a:06:4b:da:2b:b1:0f:90:ef:75:db:a4:01:18:
-                    c6:2b:9d:17:e9:11:46:d4:31:06:2b:bf:2a:6f:66:
-                    28:b8:9f:c1:85:c5:6c:86:07:5f:b2:c4:66:bf:e3:
-                    6a:ab:24:48:59:3d:fc:2f:06:7a:8e:f1:51:de:36:
-                    1d:09:31:de:6b:e6:cb:9a:76:7b:db:fe:77:5a:c1:
-                    2b:96:74:57:7e:85:86:8f:cd:85:e5:03:f2:4f:1a:
-                    35:fc:70:02:4e:eb:ab:d9:44:15:18:a8:90:52:d7:
-                    f8:c2:32:6a:47:aa:dc:82:ee:ad:91:07:8c:c6:02:
-                    19:3d:a4:86:d6:c1:25:b1:e6:97
-                Exponent: 65537 (0x10001)
-        X509v3 extensions:
-            X509v3 Authority Key Identifier: 
-                keyid:B3:90:A7:D8:C9:AF:4E:CD:61:3C:9F:7C:AD:5D:7F:41:FD:69:30:EA
-
-            X509v3 Subject Key Identifier: 
-                A5:FF:CA:DA:D3:4E:6E:EF:84:05:29:D1:D2:BB:48:90:80:23:0E:03
-            X509v3 Key Usage: critical
-                Digital Signature, Key Encipherment
-            X509v3 Basic Constraints: critical
-                CA:FALSE
-            X509v3 Extended Key Usage: 
-                TLS Web Server Authentication, TLS Web Client Authentication
-            X509v3 Certificate Policies: 
-                Policy: 1.3.6.1.4.1.6449.1.2.2.26
-                  CPS: https://cps.usertrust.com
-                Policy: 2.23.140.1.2.1
-
-            X509v3 CRL Distribution Points: 
-
-                Full Name:
-                  URI:http://crl.usertrust.com/GandiStandardSSLCA2.crl
-
-            Authority Information Access: 
-                CA Issuers - URI:http://crt.usertrust.com/GandiStandardSSLCA2.crt
-                OCSP - URI:http://ocsp.usertrust.com
-
-            X509v3 Subject Alternative Name: 
-                DNS:lintian.debian.org, DNS:www.lintian.debian.org
-    Signature Algorithm: sha256WithRSAEncryption
-         5e:19:86:c5:6e:0b:7d:e9:b9:26:a8:a6:b0:fb:09:ef:31:29:
-         fd:90:13:51:df:01:d1:0e:32:b4:27:93:0e:9f:71:39:4c:99:
-         37:c0:de:99:31:93:52:fb:86:ff:c7:34:1c:36:6a:0c:36:20:
-         a8:0e:80:95:8a:79:01:f2:00:86:e5:a9:f8:75:c7:e7:c1:43:
-         40:71:10:62:59:53:13:9c:ab:93:a7:f9:64:b3:1c:87:5c:b2:
-         7d:8b:8d:39:ec:26:7e:c1:46:71:fa:7b:32:0b:04:51:2b:b0:
-         ea:c2:f3:99:7a:91:52:cf:5a:2c:6b:3f:d1:8a:49:4c:90:ad:
-         21:6a:75:fc:d9:d5:9d:32:6c:a1:c3:3e:33:96:1a:d3:ae:ba:
-         51:7e:39:83:36:63:13:30:cf:e5:3b:4c:b7:9b:9c:76:68:c9:
-         61:f7:a0:45:d7:b2:9b:2a:5e:dc:62:43:64:42:c4:19:d4:a1:
-         82:99:ab:a2:c6:14:ff:15:75:2c:fe:2c:32:80:73:a7:93:bd:
-         e7:d2:e6:06:23:71:ff:2a:9d:9f:ec:46:df:bb:91:f6:aa:07:
-         fe:06:7d:e4:d6:b3:60:83:22:ce:4d:72:24:ce:19:13:24:7e:
-         87:66:a2:05:06:bc:31:2e:81:a2:09:f2:bc:72:fd:66:fb:9a:
-         b7:5b:13:6f
------BEGIN CERTIFICATE-----
-MIIFhjCCBG6gAwIBAgIRAOvTzF8DBixKoYmM2xu95/UwDQYJKoZIhvcNAQELBQAw
-XzELMAkGA1UEBhMCRlIxDjAMBgNVBAgTBVBhcmlzMQ4wDAYDVQQHEwVQYXJpczEO
-MAwGA1UEChMFR2FuZGkxIDAeBgNVBAMTF0dhbmRpIFN0YW5kYXJkIFNTTCBDQSAy
-MB4XDTE1MDcxMzAwMDAwMFoXDTE2MDcyMjIzNTk1OVowXTEhMB8GA1UECxMYRG9t
-YWluIENvbnRyb2wgVmFsaWRhdGVkMRswGQYDVQQLExJHYW5kaSBTdGFuZGFyZCBT
-U0wxGzAZBgNVBAMTEmxpbnRpYW4uZGViaWFuLm9yZzCCAaIwDQYJKoZIhvcNAQEB
-BQADggGPADCCAYoCggGBALx4RmS+qRRCqAVgGXIzW6uADDNFpxTorYhX45gOhlU2
-DxB+bSRZVT5E10KiyEcdRadQk3S9EVIPESg7W7QHqY1VhiOjTNPx2ZDkRyKwqEBb
-EJgwrgLWysXDmMc2GOQ+wW9Nb3cNfgBqk0Dm7bhkBbkqCShx9xkuOv36kmaxY3AE
-N6ufVT8ECjVaIAuUWP0dkQmbK8ia6xcrsNuT2GcUKaD6sbZFjiQa8HLqFLIWQ9/V
-cUOIw5ouAe3E8169/dye0sBA9Gh4Bh924bSzkXHh23T7a0mXX2M5UfsAPg0xLT8K
-QhZN6UCcJhmhe08qZJ1gp1N2i+YNTSP1q8vZY368RgoGS9orsQ+Q73XbpAEYxiud
-F+kRRtQxBiu/Km9mKLifwYXFbIYHX7LEZr/jaqskSFk9/C8Geo7xUd42HQkx3mvm
-y5p2e9v+d1rBK5Z0V36Fho/NheUD8k8aNfxwAk7rq9lEFRiokFLX+MIyakeq3ILu
-rZEHjMYCGT2khtbBJbHmlwIDAQABo4IBvTCCAbkwHwYDVR0jBBgwFoAUs5Cn2Mmv
-Ts1hPJ98rV1/Qf1pMOowHQYDVR0OBBYEFKX/ytrTTm7vhAUp0dK7SJCAIw4DMA4G
-A1UdDwEB/wQEAwIFoDAMBgNVHRMBAf8EAjAAMB0GA1UdJQQWMBQGCCsGAQUFBwMB
-BggrBgEFBQcDAjBLBgNVHSAERDBCMDYGCysGAQQBsjEBAgIaMCcwJQYIKwYBBQUH
-AgEWGWh0dHBzOi8vY3BzLnVzZXJ0cnVzdC5jb20wCAYGZ4EMAQIBMEEGA1UdHwQ6
-MDgwNqA0oDKGMGh0dHA6Ly9jcmwudXNlcnRydXN0LmNvbS9HYW5kaVN0YW5kYXJk
-U1NMQ0EyLmNybDBzBggrBgEFBQcBAQRnMGUwPAYIKwYBBQUHMAKGMGh0dHA6Ly9j
-cnQudXNlcnRydXN0LmNvbS9HYW5kaVN0YW5kYXJkU1NMQ0EyLmNydDAlBggrBgEF
-BQcwAYYZaHR0cDovL29jc3AudXNlcnRydXN0LmNvbTA1BgNVHREELjAsghJsaW50
-aWFuLmRlYmlhbi5vcmeCFnd3dy5saW50aWFuLmRlYmlhbi5vcmcwDQYJKoZIhvcN
-AQELBQADggEBAF4ZhsVuC33puSaoprD7Ce8xKf2QE1HfAdEOMrQnkw6fcTlMmTfA
-3pkxk1L7hv/HNBw2agw2IKgOgJWKeQHyAIblqfh1x+fBQ0BxEGJZUxOcq5On+WSz
-HIdcsn2LjTnsJn7BRnH6ezILBFErsOrC85l6kVLPWixrP9GKSUyQrSFqdfzZ1Z0y
-bKHDPjOWGtOuulF+OYM2YxMwz+U7TLebnHZoyWH3oEXXspsqXtxiQ2RCxBnUoYKZ
-q6LGFP8VdSz+LDKAc6eTvefS5gYjcf8qnZ/sRt+7kfaqB/4GfeTWs2CDIs5NciTO
-GRMkfodmogUGvDEugaIJ8rxy/Wb7mrdbE28=
------END CERTIFICATE-----