From 4b24d829e31b6173ca644527b062681c1d0cedde Mon Sep 17 00:00:00 2001 From: Patrick Date: Mon, 25 Sep 2023 23:39:10 +0200 Subject: [PATCH] feat: secureboot on laptop --- hosts/patricknix/default.nix | 1 + hosts/patricknix/secrets/secureboot.tar.age | Bin 0 -> 31168 bytes modules/impermanence/default.nix | 5 +++- modules/optional/secureboot.nix | 24 ++++++++++++++++++++ 4 files changed, 29 insertions(+), 1 deletion(-) create mode 100644 hosts/patricknix/secrets/secureboot.tar.age diff --git a/hosts/patricknix/default.nix b/hosts/patricknix/default.nix index 2354537..962b44d 100644 --- a/hosts/patricknix/default.nix +++ b/hosts/patricknix/default.nix @@ -11,6 +11,7 @@ ../../modules/optional/xserver.nix ../../modules/optional/wayland.nix + ../../modules/optional/secureboot.nix ../../modules/hardware/bluetooth.nix ../../modules/hardware/laptop.nix diff --git a/hosts/patricknix/secrets/secureboot.tar.age b/hosts/patricknix/secrets/secureboot.tar.age new file mode 100644 index 0000000000000000000000000000000000000000..f0b9ac0d561dd58b2823c3807333496592a84daf GIT binary patch literal 31168 zcmV()K;OS%XJsvAZewzJaCB*JZZ2G>>Rdq*AD`+=!W^6)u zN@ZtPQF&)XXk~6qXhL~TSwS~+S9mZ;FIfsLJ|J*ub}eu+H8vnxMrUbBcOXG9GI?(@ zLrpg`Lqk`Q&Vj)Nijk}Xm?X=L^d&aGebo~Gj?lXH8*xI zZ$eZ|aWo3*2sPYKO>qy?eM1GM+JHVuQd1~8?5XXdODSZ7$aoxO>SMbJ9uBO z=GgZPccx`M(ZWE`5c0Xsl77VBj{w_=9*dF>TndrtHJlB0jzi+;5@m7O} z@x;!&5p|$}_mnqF%c-v*zOsqa%tDujvx9xY{i5yI*qMp9D$u8QF`MYSeTWe+!v`YYzm90xMUn*jYXRP}W*UMo_>O@CKGbH-JV2y>*A;0m-=`KVfphL7(J;D)ik6ke48M$Z$ zjR86aely1WYsh&gLktC)qFJ~g(sQ6a ztJ2P|i=@Rl1TU#E;ZuhLpvtdOtd8Jb`Y+_W?6gQd7Y}q+PFk* z+R{#fd)uS(J+R#3Vx+1d8{MXH4@o$0F=eGh_SFpY=$>78EyNRlpjOOery^i9iGF~U zFm(0CdTw!u?W8bvCP6rHH;M74=U=fAfVbIBOM{8Si+TnwrLa!tX|~Q#8Ba)yLV0^W zKm${#LSliu3pLuCGNGB1C&?bC)THV=`NM#0UZQ*-R(S{i-d zykZ0-g@Tgi`MId%S|qBro$D{X0Z#LcW(MrJwDBOjQ+R0ceYhU}TceoY2n(Ya%ryT$vpkh#S9bEffj$4tu&U;6?M!wp<{f zJF5K7cZc!X2p=nyi40Lr!OF5gMte@=-A7l>wHgE~{juxf{QR2W-Sw`VI~ScjRrnIH z!8&?tL&cdpJH)(nXE`Msnt&cH!ck@$pK>}noo)MO7@}i7?Q8}$dr)b#C+eJUltN@3 zd(1lc<-e`BMFP;bv_rUTPYs1WJIFZYn3(t3{4<8kR4=R<*X_J>p+ z0J|uZroGTG^$JWJ&9`-zQJZou*CXz6Q;&~euNX7gd}RPbP^v*zTmL>m*JeXjT>%{4 zY~Lr~P5gp(H^0-F!Ete=jMCEOg?Oz3neHKp=!MXI;jnHQ9f>n;?PJ=6c+f`g1;`0D z<_6OWqF+3ZT3GFTgx&ToQT3?f=bMaaj;lW#%jIyT0UQXqS|yQsCXIm{i2^rd*vF1K*ey+6%=k^)se(-&;97|sn6$s!srL$ zz&(Xu=H)oJXs_b)lHI6{H=w&NEqnPooLoKO!1HBKnxIdMR1F}=LGJ5{y5;VZ(ks3Y|PL;-!`R20rx`8#hh-`@t zClrz5oiNyzeg&9)j(aI~%Gso7j;=y~M+dF{H8i1mIeF!Mrx@Ggu zx3~$$ieVqZPR{L2x{KS=1w}k2Dg-wpe4&b1l_~t9D7$$p%!2q0i1J~z42Jx5qp9d( z2$t(1P!kz_duUu8&*epU7n1z1=(ZXh}94Nfg zfcDYek@7D_dhX-nE?G#H!)pnFTm>cGyj)nFK>>&f?w#6qWW$4*x)>lu2Tf2@#iGzE z^$7#`;0lkm9D&-l5SF7~R&a~!7(-#{Y_8y#oouzDW+kUpcS=vV&|~e=KZ>Y+VKks* zzUS7nb*Q_Q`=3Z@uHVC*OsGF@8Q;ZLucO*j;R|PFFx(cFY6Lo=MUIPuPoKaqdj;I6 z8Oq~1ZZLhXO^jzUgItQ}X(>KIX1utO6V)GZ)79<|G`_mJv(LjS6n*JfT<&|4gQDMz zW{+vVUal-t6xZOiYn+fqQOu17Z0Rh{0339!%RzicJ1MeYO!;Xor{UiByX;YCGTtXX z?8I-bujp!lc)~L4wCpBXkoa~#qGZWO#5Esb9+EzUI0wVvodlqZv8ycVXL>IsZB{`F z{X9nBUcs9;yB&XuaKfDksguBiu#$EV>yq{aapYYTkrUSH1n`XjneC;Y+lD{M&;UZ4 zI*r&{DdB7mn(oES9=TgGk0@I^kh|cF3uF=s!CGQ=#SF73UM|F&dkBCfui#2IaYNe& z4I#cNq%*hLR!>fYZ~4mf@;w~JQI?Vg5m6NH@GfUk#@)e=PZWvYs<9?p8<0Ske@1BK z4DIxc(N-w>Q1^O?j%wAxOZ(|3{xjsOl^US8wBSzDqZIt5@1ydY2F5Qrq%g*Ol_yyc zXzD2y#WyCp9Aui&;|wYY)z;xy#PW;8>*MY-*{X7pH(Go1A$j@s$^wN%y`~?^Q>*v6B;3&aMQ0XtsXO zQvF-3W!7tMfGY+{-G?TwzZW#1cFpZ?9P<7M zWXv-IGqJ$(PW2(-%3~PjS2eww;t`fuRzncy!8_S?T}S0RC06u3^@!EiRcHbiO@u@b z`l;yB!T%ATTaPAcTvYx|O-WftrSW33k z;P31blQE5^`250{U!XhK(Nm5`pV!DJyWfOcqEBGl|DOxlx#@pokGSCBvJy8;>BToP z=eUiV9$Mltc-F#;X^ld1!6H7Lq&f3XnwtkR>mwk7Xefgnlp^{>xrC=@Jlcr&)+qUl zYb+mwR-Ne#gY-ZkIJoi;YEw@^XZ)NUZ_5iD_+!a(rS`fXN@-ZGi?i~0Fi8#a13N_L zfmSkmZ-s$!pb{mqz<(0)n`UVq3fou%8HMN5=dCS6GQmPaUwJ_#fg24Fz&Y$~l;wWo z6TiW`*|$yudM%t%FrE__3ialq7F>Fz$h$2-mur7tCy(0q+ zx`p3IKc5cje)9Daxp;>UCG5`<0J~!!1`*2_6i$_mLU|Uqy(iE;c8iB_6wv;81cn8Y z36ddW1 z3hKOg?uwp8>IKGdczqWZ9VKMi((;hFn-+=y7zsoyj0w&W(MVx%ZH~#38?5CZ{2{RbqolmG3?oP?^N5NPmt}0{4lWkfijq7pq99lu-zedcq6YpSuA@!^ z+e#?wG^5_{=vz2*o`Tn=k9UocbFu7YE!NIx5D*dren@H2zdbG*AcHszQV!yN;;QrB zR_R1EGx}<0`GTqK-VsTKDW$jZU_)1vuf3!;ofm^MM@)wGu(8Mh1k(=LBaQ=-`v{r4 z$9)Q`l_Mstp;`jH2LY}aia?GW&XSMABOAgD7%KFQs4*;LGtlEEr(vssr1esoihVLxP`AifCPuWHaJ7%WiVDw8+qlq% z1*1Ex@v0U-X%A|u1rfMqkxAWp1F@0n8Ad;{pVYoOz7>bJ((nr&u_s?weim)sT2c+? zk3?+=1hrtr-`(=+jbV=C(bQgk$IttG*}{Fw)ji)zc4Z?~W zvd+oHbI@bqmF0<*KV?W8I*urGh`z1eQfSKUDJQPV z8wU0;o8~&reXl;C6~De6pQ`x^tqdQGEv>Z_n-r!5;$RL*dmp^m>{JU`6g} zv6vMTYIo{jidr-lvC{YnkDA*!{sg|&q21h{2X+jg)kPP9Mqad*>>8Ue8x^G<&5O;~ zjrh-nxq+a1TCGVt<8*48#hn9onc>c!vsF=%o$oQM+0#>V>^y-Tw1(hdWK(2qknehE4~dPrni zHvEkj#&vQ?&@=g9eSjTE}u}6o)v~1b}V{YUA#8ui8 zqe%r&<&t>B;#Li|*Lfs`izOHf?Nxn^AU_8=rkfws3b!!aRbiH({))HHH?ei*C~uN} z#jQ&QTLSD*UsSFTRXd1`ezpSs5T+<|#eQ(O&$Z+f3!O9|!Z49pYZc zirODS!Bu46vniCw#e~P}`;g45e-QGSnHl`E?TX9@&5RAPvpt)Jm?Yg)9I2_qgl_3) zU2gc@ip0V#Vok6sh0eA&(}>x$NPvaHhIDRXdrSz&$rOoYf)?uU z=M|I*mdZze0UDHk#H{{jBHCI3vf5-~KL?$W?i`%Ko;1hsmltZ6^qL@} zshH$ZHqdRY)27XKS|TW`?UtM__;rD&`~V!wIp5kcnPA-d&M%m}S4W1A0RTzHxw~ju ztk4G!{FnhQ9WW~S2_|I9W1yjU>H>f)64=3ihegvBjTlDcfno zU`#_-jPAblIg)$*-$qd<(;mw~B2o8afOCw#kY+&@e&oTg*5w-~T;=X#eiO<{Q+ z;9lbA^2!MK)s*h`ne-7bd2VDi{3*72B`!SnuEa*2ZIV?%Fu^|y{ik@kfz5liss{+;M^he+(@0_e!LR_g2sqQ?{ z#DNFeSF`yt(V-iUhh+T%$Cue_k@S5V!azj4$}x&S zPi?AJWF?%XL8^iV8A(m1>{~Km304Y|o$io<{5s1-8+y2Lm}*0ui=tes-^hfvfQ2XvVMQP4f&^vxV%><(Sw zB(%nknnO%H3^Z$cb5*u9ZYXKC8F#TgnNaHkRI5@+ZaSQQvZb$kWEpi|KP#dB3fI;l5*Glc$xP%H>^0JaV6bR$+$j> zt!A7WI3quleu83pc5nsoMjDmqx(5!^fEH3Q9+P{2S zRM>1;F*hKOv2&n>h<@H&t&=*#KvIfZw?k&3j}l4oudveworeoK{@FX1B|keNmNm*$ z@f&ebSW5%z>br^ZF1yGk2WhtD9@q6Tv7GTElRd8i=4)39u4jS|#N93sAr1__5rS4U zRlhqB=yu8+)y1P2qMBu2hyQ>zQ=tg#W$(^V6?|HkVuGw+(!I;H>w_$e8h{Vd&xT_< zdqUo$u~uU`fN~?Yb@EH)?P51A41g7@x2IHU1o^P$-rzLkjGiq!gYAJ8t~*;l6Tl|4 zq-HU$9nEtco?nWa?(XQgw2CUj%|U7lEOWMLMT$o%jd-oD8h1-hbT)1VI`-=IorA=g z*uAio)%$APWL4tH4;CkDTD#iZixOHXlnh1F$r-`l`V?Mr2PaQ{D3J1^0mEFCKb=N7#rWRJrD`o?Dn z(&^?|`2aD~jh+mp>|rP1+cdI%*FN&wHEHu{=r@F?N+tZ%uo|b4#VYceV=C*>kfgb# z;I!9kDGf=d7KYkbP!vW_ail$aX+928@|4oQM(v~9yW2o|1M6f@u7xd;kk&}YfWeBs zi^A$${`?jMn8qsSV{7C=kx45W=W1`M6W1Ts6}rqJQ}eByZR{Bu>ZMCvyegwa047{j zBgt`deCnzBT*&c;%+aRnGi^VzE5Nlo3|xK∋XNn=2f|iA&`yRizT<4WAcAkNUwgY7rp`gn>dv@|bOHP02kzD2%GKj-i7wQ#Gl zu(0SIz~ZdAq50WQK|Xj2ERj>?)J+%NXVXYFR;4yaLW)+y8Hz~Ya#z(1xDfZ3^g=d4o|jI#RITDcy7 zZHxyAb_B8Wlb^m#%kBO21msUCd-xV+;D%~7Bu5ef&Rnjez3^X0!tKooiUWzdIMA<6 z+`yiWnn0hf3bu#?BwMlx28e2YDig5=Rx*id(fS2sm_nM5EnVDBCz&;7jJlKDDFwiX zqqvY*QKE8Bm9A6^`GUHJ;nH|c{r=i;egrKzR#(bJBHoCGn|sSPhdRLhKP1UBy+S3z z9<|bBiKUx7vs;{h?Czpci#y7&0z=O1GVcAtEWb&=0T9tZk6E z3m$`+i3;A`7m#~1S3)3DT}whDrTv|_HpcH(X|TNepl1pp*}^V5IApqrCr6xE$=h$d z>6#dkb5Od5+Np&Xfi>EoqLO1_#68{EIRJ^xfSW7aQ%Nm=?tLIJ4#5%z(v8P5*~~E3 zqVO(1FOR+yI*F6~5a#GcdTAhnISW&{%)PepHB_=cfRSwKKOs(50OvawgAh}W`}tuY z4$g@r{=VOEHDsFcS>Z@+z`ewzmm0!7M$3{3GY@DUX7S>%=(Ud@4lVrE8VYI|l6DF> zdvdD)%|E&z%aKdCU8Qe0QR}FgA6mX`h}OwIZFTcSBA1HZqQA-SF0}M75%9g3hOy70E7aRGP8@A<4d9K@s8{ zGIyfqitp^sX-#&hEX}1YzR~2Jc#UfpU;{I^f5do;bHrcI<&6+g;aF>_bx1>l08;Rl zPYh@<8Tn}EIuc0)re~6xEUtBq|1e@+!CQlBZkQ9!|2T!`iBhvPAR*`{a3VZmDLqx^ z!~9<3Gld;9r>yM9df^N6dN^P>4VKJn1i3xhs?%E->ym(Q3c#Z;$$qe7GPo9yNov!h zZK>E0ewWYTWq4O7f^iX$G2v3DsmPAH0FD%ymT^vQyO%0WDf+#4mN zqQA!{wUeqC=Gqe6;&_s&k25%BLs;W=-H3z2SUb^@`ip-%by5btC&ar=bxPxjU%LS) zLO&sI*y`a@KT$tN@FeU;?CZ01eJ~z(pZdk|Q2Nnq5ONCA3I9IoSKwZdr!m9hXIcVV z%+$8FX#5g_xEgWOT0}M>epeCc7N|vxF#fb4#&`57yw9AUD6-b?{PN@d)kd|--}hu# zhxe!F7fJdj=M= zhpQAmK_d0Ie-P}7%V~<-W2cJ|AF2X z^09Q~kKo}(?%rv5#so|vvlgMqoC`#ZT9Q_ z!Ay`f!3qg}?UCExwdf4R>LVjF$zFsfN*V6D*z)FjSW#2^UX+=8^ph+vC>!-1uF_-) zpT|FEN>vf}g}0b*&gznu_Zt+ztBkTBjh5lD7FynuhYzrau&BB{>H~f@6KK{*pn%u4 z*BU0OM{RaQ@?C>BQwux38hQjDA^eer1+VRba|NUxI#guDdoUFQLG3s` z$`dE}C%pEgntX{=I~?a~-SB~Cw^&oU?^RBBHeH|lkP;&@R9h6uoCMhQKyDm1w=l?~X&w;gAv%4kK6091leJMJO(TnKX z)yY2l5N3z!ryA`@DoX|b6UA5%th~crE=X9CA{~sYdF67A@BFLMf(`fuo6&B22!P!j z>U+IiK;AYt%Wk0;rvIYDlfCFb-~~qJGiNKt#@ZGdr6+N)dnaT~##XJ!UgriA*vUhM2DFbt&P07`%zqrF>(E>ihWuMO3%a*h;h2Zi%??C6`JGygRz>NsrMk zEWOy|6`tF$EsrqKjuL^yjo%u!CvAl&DMyKM-<%^DmOsQW(N27ciU}qnZ0RM7yaIwU zMa4rMN!1n&4|6VjDCodBl-zQU!7eBDsvWR~IKWoKMkmJwi)^iw;*NNeH9%}T*lWbY z(KsIO4p^O}ct`XqsGDdfN;_%SKw{OrJv)cEGRO0mZ&EqY9{Me|D~)qF$5B4q9E~ zo+dK;k>E9f1g}D;b4>gFzkQ5}_GAb@=4NTFdsd5FxiB^tB$b1184?angXT0Jfj0FE z^PT)gn^AV~2AW%1kqsk zBc(Y27N3ERs766!=~zrxdj?rrN!jm7No(ym!UK||jdf?7@zfB_@`O@8J-C0UdAdrB zmE4=YLjFh3fioyICfUwBUN!|Hy>BLdAY zn;(S?d>3!~Hm&Il|1`T^4*C}Qtm=dB$R+xuO7Bz?n&2H^T;RMZPN;m3uc6FEr7X04 zh`ga6_94(u{G0EU9iPqu=Fn!@~Z4v;}Z#KM+UH4?2At9(9OOI zyEHOv2}gP4KJ8jko5)ky`S2afCr*nnDiVX>Dm!z>5<792`V~LWf>8Db zwJe~7gUvcmE!c?dp|a)eUYShehhAYUBZD1rq_>^XUh)H9Cr+aV)%c{H2qq^~;&k!n zYj;9FQ8K?4GQH%q^MfP}ICD;o=3+Ea?_6bvY~^~x_HdhOqRQov6N2(wu)kDyrE_++ zrP3;d7=U!Ch4jbzlN)?@y01gqk%_$11JKI>tsW76R)=p{Nz&)qY_Fep<8wwmKNMKL zKH8<#(V%_%Y^`i_%JDm}H-WnP#dx#41CIJkW@6E~SJumb zS%>-ka6$U!v6-;Z4;rXq^gS18Z;rwTNf9{~>;5el&D?lcEbczR*i44i{qd53CY~b} z8CVb+!DV@(G40N<0rtPT9^&H6jE#lzA7ovX!_Z`Yq8@rWN5{}w$?`1gaHl`&R-mIz zrzYROWpbbQndgf+mqK4Ac(|H2b3*3YQ0dLs2x3%ADSxz=?@H8ntU7c31mKj&e;gcE zXLA+9yCsXv44am9T|^$XP@@M;1Nnp$>CQB z=#Y=jSIbt2p%kDA$%nh{F<3EntpQj7kPRf4>6Z=Ra_P5hJxBf_Qn(wP(%?}teL}<~ z3eW2Zm?NaAU$c!W!T*p#aJtE8u5u)u`YBJlzbUAN#++py3Bo0mhj~e>wR&7%4YO>i zxg$1$#M>}PV}&2T@B6{-5j%^m>iO29KEnC!c;Rpfb%SGsQv~&X(I1@K1bKlUXD?E! zuDDa6JhBC8J?LJ`($w;-JOmBYNWHWYLPQf1FT7ACAZbG+j;38YOy~Ugj|WPYj%E_3 zds%vr+cbLTa}i)w*98Af#4vZi=A;Ndy;;hYRpNmA;MmoW+f(QAbP9M(o!3&-8xHTO=YtI88g zA(vSr>75T7q7`&UVA-3%5+I*4=r~rDS)(J~$Pn#q4p#d^tyjP6i4mV_PYa@DzhNa; zMP5!NB$-mJE-EL(bfeE~X|S@1QFMp8a~Y3N0e-|oA#aD07zk(IT&Kb~hU`3vcWnl{vxyp!qJae)>0MEj$se6tJOf3fa z(C;8c;P>KyS7>chXY}C0&Y;-s^}C)$-@y+Tks-fn`u++#A?mK>Rx#w=?onD|vAU|6 z`k^1mkc!CLkNA_%yZVG*&2#cUI#1F?Q5AXRusf9PV-h0L{sFZk3CTG~OWV+pg>`f} z)_U8cG~%o9UjTIh2L6tgbUYBO3==C@rv)U#G~Y_qVY!KwJNBW40?yD;lAQgaBd4iJ z0V}~1zZULqa;V z0A=8BPp2pe4+54y4ST+<%>g?!XX8$XZ9;#RH{C}4Oq(hmD^hGcr&hcF#8NF-nfS1p z4na+8#ajW}h{FQE4e=J9*&0m{gHvJ}P!4&q>)9ibCqi7dgod4g}!*J*ZS%r3JQf?{HAp$Z~~zs+EM-E|Q0_04&z+ zg-66%uCOQHs(SCwrIZeC@fdA<&O2rHUiC{9eH`ky-y;`S zQRWBb!fj*Uzv*3oXg^Jf{U-7367Y_w4*zSnQeZkzXU8);Y{n1#s}k>sfZn9<$68ZV zqoHMYWrpm38I4^gpvb$Jg+2{S5DwSo7=(+@_PYZ#AaFI{Yq@qcW(+_OoGBHE?NpJS zPBrwS;K48OV5Mm-$-4;-kpZDW8m(@Y^uj>a_M*5?)IEnE9ASPDxbPe+df~mBsUupS zkC}DxZ~oa*r>k}b_07)he+4~sQQJ*&&LwtwmaM=;Fjk3?X#efFJ{w#p?F*p3MG&Ks zuzNp}q;aGZwU1fcULXpd@c)7lYEIrPk(sl;)s%m{arav|pdC~~+dLcRyd%35TWTC9}#U zG80O(!1-fy%%C-!R12W(Rio6?&+Z?3B&-mSwxx+3HUlw3z3#INZ{&pbAO+KH$-qE; zYb{GFy2(Bhd0Dl3@)jqL*=2{tqdfUYWdo8Kia)(E(92(P#k&#*16WS0P*F+ZO~F1Y zBkG^*?llNYM-hn@mOlH=Rtbm&T}tYSL{Pi>AS<9z2|E;EIlXsbWj@;KmO0_d^^&|^ z3*ostoK6cq@pdPC{sEL!TOCyh|9+|6z*iMD^I7qLlrqmG|9EEYm07b;SCPs)qG)lw z8CW)xJ=}za72dNP9kWWVmXb{BT2XOe01*<@JM7By`WV5Q42p%_3TVSkaJ@xH2Vpl{ zvNAwA|NX|we{oZtb};zpvF?{z9@-bWvdN+uO{tuw1gQoHBLdCq};(B)rSNYq*I7`h_K}wO&B_C z#5p48JYeHy@-AVN>5f15gaJ~jQ8GP|;XJ+tg6`AE>md2%{MR8JqRI{d%pF&Ku5gPe zm17knk;4ChTr#G=(t`P@p4!F@A7m#FQEM#0AVr(!WHRfmqI)IwmpW-at{6;tGCinOWO;&UTrWDqD-C zHzEHt2ojhF@p_78-n@74$#wL_Yq8Fd8x_z!Qv`Tw>d9wTp0FM0JN7OC5@^l};WxE$ zv{vj1oPpF#&kkPnx>cj>7*^=}COspTI(7<<@&RD>KshM*Y3{Z{x9Do%h;&xvx|-@F zA2#09Td~ghW&-!iS6-x=(wcLt-6VS{BPBTsHd>83JcpznAH$hyw0~727@j-$3z<43 zitV}H4f$rky*jjUoE9cf+oU^%Xo^u4W4aZ7d*H6Bj z_&?rcg2Dtl7{moKc|0ni;1}YM2j-bUL8jcdW{(GWZ(4(K#lUr1Yme)=gw>a+yL^hd z-+uUBAPwumqQ=$;KbQL=@(pMlzqD*|A{<^jSkBY5C-sb7JQm=GzBL@nQSwZ#n0^VM zWMFtVZ}SyhwY5*-qV;6i31H}&RXbt&gX@deMDW;p0;RQ9Q>@>PR418}U*7`rQ3@q>D79I*g_*!lsT7pKRuonP;GaiB zCy5jKVqEydR5GKA!wTJBrFmm#4$WYl1K}Qv5lp5WZQ0%((wX#$)meJhU25!Ai$)VP zK|*}ws)c1OhJ7e3bXo7>E6%!Tprf*@(l~%%h8j4K`n59QmC|Z2gj|HnB8I&y7rYYy z9a`oluLbpD^htpSvp-rYVWPZ+fH@&0503>5rWQG7X>mm327v)3(s0yrwfqLu_%c;y z-)Z=$*({&WMNDR&2Jtd;UET=)R2__rp|PqmbMu*kXhHQ(R8{HG`&sYsvC2jMNbXNx z={v8NWN?458>9fB&P{2fh8uXCf@9hK$A!5nhu!+4E&j{{g>{-kUia@&BZx*n*k)-& zq*rqnyzn32Q+h5JqH{eNF{{4^|6!DWoPs0*J7d{S&65BK5NW%6LCYuxA>JMYJ z^q*Pv%^1vhCOE@yk?jmi#=ymahFE3Po|ahuH3O(*xG@ei0Djzkhi8$cPyR>>ol%Ab zq&nnJ6P_U3Mv9p%w6J=z!;q|BGnqR!z}@%X+@d4UH~qI-z-97eMbtJ#ag;B&;R#OW z_t_^C9@-biVzry%l;!L&Th&6Rhqr8DyUoH54D{*}*UVF)UX{2GZw7Gmu{N6NsFPMD z<=RC*noy|v{emM_Cu-8Q$-Ol+P~ zy&W}~YiwHd5GBF;!LPmU6{p3qX1QUyZ!A4+qSuj*wF%6wmhSX$2ZH)RtSS!8ha~;@BPvR(4NVo`6l`$YO^1Z&{_cF#z__69iKJrzN$4h zI?!*&&u3{zb6Q^Bt?By{pmuPc^Y0bDJzzuzE7ZC&qgFQ`@1*NSk=r#Q3Y5(WvNZrD zXrCEsiKLCm$8TuK>ol3A{M)b;O2RCc1=bYMoCw)wO6-C4HIN(jWF_SgmdX>N+i>@n zr;K0!mcf8-48B5NV%qB?fJp6nPEUAW_Ubd3f>Qho zYt*JTSu7z!CE5IYh7#M113I{Q{hrsukbt)Py?|FY!zaGo1FSv^*M|@a@5g5R&otTE zel0-di5y2UB;(d`=5MUzT5JxMuh;V(-Pf!_)*Y|s|E#iG{(6`@@GTEHi1>P~*QYH^ zEjpuPzqZ%CRLUQ1G;U3g`9{L!O+0Pfftnbc-2SI~2pPcQ%yl@(U8M`fz)vAPMb6 zBqXAHsE}A5@VFa+IL0Dm#D6^+&yyEvj@~O_k?WI}C8tt$TrrI(9@0RjxoJ%J8VL^a z$=u6-kPC_L_ok@TWb?Zf~%E!2)XJ-J*2SYMACGvm1C@2lXKxGQ>{&+!x! z3%T{12JWz-NHsXg3RK18}b>;I|&Y)Z&j(f+Y(@ zH~;!NtSoHwe_Ndanf|SBA$Yn?YL-NEkfM3L;h)(TiB(77FC~gZSU%?5Rw=SKZI8r* zn3|IPnKsEwn!!c%c@}ZEMro$jD}t{7>j^uT9ku&ZUtIhjn}$$ZvfMWU zCrN-w4G!W=%`KYLNL6n`NLlIT-1NPF?rVgp2{rMhVfcN+K8#e-YWjdDYo6Dgu9DrO z7<%kkP?AxL+AL#33t=0^l**3o-}5#&A7a88Q>aN*h`-9+{6h$3W5=KDnUM2u}D}=9n9T{ z=4;W~M>Z5mvsE4ZZr^q8CRsAyq?BVu;aoO!f9JRZKfr$ec1g{iEzEj~Yq+&w_zCag zd+iY~c(DDoL_sD*z)OfBsf1Vm-IHH;jPb(eky7D#hBaSFy>fjxitsx1WldEY90ED- z^oH~1@)T!tR2G%TyHp4UF^^kml_pO&Zsy;RKR3d*A3eOP(4r+ho zdSH%aqtARyl1(egKNL0lH*&rL*X{Tq;`u5G`PviyvIDcX*NMgj0=L6oP0QYd3FKdz zMAy&<%esxGvy4@>umXOrPoA^SE-yLh>aLF4ESmP3n7Oo*DB>`~PF%hFS!+8q-v;_W zb?UAU?A(H~;BQeRR5hlA_!gJw~Wd)HJaiXkP=(`A`gkF9sgSV30woycJ7DUFlDTbtG@^V z{foH>?-_$oRGS`W-;c`kz)slO-?)}$klxPluumhZ4)&Dx#tN6 zyk_eXj~FQYP^cFGE!g`HP7HIrl;b-L=m%Te%=K2F{|)s$e`IU&wXLRq4~wI{ttoy8 z>;e#3vlu3d?}cI93U+)ZdHsq~9GU1QvjqFR!BqK`f8g-7{B{V40&5ZAJtUh*Olm}?Ji%|v;#N^$wKFPTA| zuNcCxAw-d#{k2BEKxjVeI~Og1Lr(?@{R0aQ)p&v@W`MNJ}Z!k z4{8}AdlB^+4)Dw#_8!)wpNywt@cHQ809}> zPy?0$GeJGP0cp-Oyb^gIxJjC{lW0QHG}V@sY1t107sR275CF&H+4E>pJdByKulEP4 zOyM(GJ_b9@Ww38YRj19sW9%?MK~g6X=!DOWJoIM^=NylrVx%!nrO ztN@^fAKsznG=_5aHWAN+1R$AGG39fJL=h=jfwn0AfxZ^~#GT8bVICv`O!B>*dI*pK4HMh*S9(b1J)VY5i46@^ocx*E!j8-IMA$Ux||B1eg z^E_!<_%rg;itxaR^@R_-(geFa3>J0>NfLzufD8n`qF`Mieoe+xp^tYIJzJ`wtZ^9G zs*wSW{Pq@$bMQI6&Ih&qa^H=sS`1#{E!DUey zFF(?_v+*aBaHd0KH7SZU;O>qY2R!Nw!ggarMPXe1B}~&^Q*A zy|$M_i`VN*8x`tO6A;zkJ9xB(;io>zRMqb_f5q_HNTH9V_OMTVm5|v4li$)dI;Luh zZcX|fNL*LW+U_@ik`0AO$gkMBT)m&uFdZ(W^b2i)el14uX-U|Yk7=UkE z{;&eGZ7u@&&>J@!r}ul9cx}1%RFXTHZ$Ey5%&u?|&x9~LaX-uDL1EI^Hc6ZOIby2w^16sn`xQnRZ6B^vN~k2xlgdF`5(0`yI&3k0PqL&#LkqZ}gVK7}0;~0bF7eq&0C1u~OnZSxz)+ zf54pMz-*eM(7gc%0y3I{79yWC^`tsF|Ff3Rfb0Zfsz8Bwz(u<;qt*!n9UyJdfHZLb zWNCer@0gu|y(0_DQc3Nxj&HOiOPm?y7mK1Q4Aoa^X0mPE2S^4V5&~iCvV{%p;}c6r zq;U!7DZ$4q7!44_E_ix!O@kt6_euN27~^IiV|vIy$w4EL#+{c+#*%}lg!{xUYLSB# z{W$g6Q-Dz-;^W4Jn|Np@`(%T3Rn)Ts>SAh9YoKYX*YF^4-(n_p2%B1Y_LfD>I7tE= zUBgJ*mTB9%qg#3a3k2RY^D)J#QDYSXHw5sX=xJM`UE>Hy=Y zuZd1(kG~K`T8)~C@XB*oE6NS9=>{nl`6_9#S&dMhcfseKRK4t5ieV(0;$gq-+2)w$ z)@c8z*6dk}(g~lu1APy7IF@)ZJKDlKgn(_0S(ymu2KSux6i$>- zK~8Ll{czdAl>1Cf4-B^F9V47DFequVfQ4p(&E@?RTV`)^)1+~xAHp9av%bT^Iq`*I zz5fFc%FAF)Tn*b`mJw1`grp$24j&}@1*LD&svAmD?~79HoQ680D%BmgZ~J41RWO#d ze-DNO8K)mynqg>ygZV&VP>8k|*i|aS0!B3$uq`5Ck2naWNwDkjGB}n?>Uy!DrWDDp6;M zHuq&wLV+q)9eGx?6{pLR&W!)p71kijcb7_EVSwdXp+>kEff%|4vJ$uFoOCd5A;5aC z!L%ZoS$x%sNre7!gfI1zs4HX0JzXp6oe{9v$0<)7fnC<@4xsEEVm7AR-&|3?l5S?- z!wkqQnyQY-Xtja@Jo-f%sh?pIGythE8}}Ox8Rc_tx7S3iEgHxn9PXMV#fPI~S=5+M zxt71)Icgg*GB;KykSdp~{(zvzn{`9D5G9}kn~TV%g4R5lI;tFG+ttt-JwNO=;s1}{ z#+Ln6p-v4i@!1e(to<0ck(ZG`;VVlpGEJTtfPccNCRIlECq^R;h?+`Xd%}s$@2nV< zm$#v6P8@5GR!bC9TP(izS2Ud?NcV0SDFtW^4J)aw>e%6cOvl|u>$iVS$^b$`W=#N~ zOTfw_Vd7skO<)1#^sh9DL8~{<;x0L4z6@Y_yDRSAfCLoG@>B; z3d;B*X(t=qiA>L09S5#Q=)0EolnjYo-2r_}(!BT7V+knxCc+xKvyA--iCEmFldv;Q z)mNrDharV3j)l{*$IDU<{ZY$@z2H|mpO~fx?ELr9Kqz#QbzeRx{zr z16%$2>jN!6g&_k@@ygQpt6_dsv1Rm|<+zLB<^kg4yp zW14{+lQq(H2LSvDxV|~t$-b?QaDwbU4?`{_W#68OmM6$Co93HYXvM2@HkN*pxOO0) zQi-eoi8?LtvB?fSyTj&b*bP7}R&a*Qn;_q|fp-gM++`xr2?t`{I7~@DI78EgQiQbNgTLAyMnsQ^`r80qu1Jjt zl6j82^x|gapH6p4vSJE=ly3+lvy`Ec>ZW?O^{Syr&Mmzku&C=TQ4L$Z3t#EazZ!Z! zI$=1sIjstXdV_7uhpKitt+J6D7;>SUC%|I=E0Q=+AP(K^D#s0TCDE@?JWA!@V zw^!qFIqxh})ljR8=>||No#|Vc!Hq_jP(H4=vdA%VYkzzA$V{g@JoUj;24UM9e&jZo zsE~W-@*5i>m~IrW%ROyZUbl)s6b#O4rStV^eDENWSLOXz7Ei~(YQJAS$n-kI!DQ~f z`8X}aj;S$it}^FTp}XM#O?V3-2DtqrEv98qzO}`}xfDcrU5ay#C@{FMV@jZ`>o6@B6Ne@$))WYLS3ON-{XVrC3B$ zCP3oPc2)o0yNkl?5?OQ=XSYM+#fbq`aPVZ+^kK!!>r$x)GqgkRQ$UkCL+<7$YZeQ@d;A~gQhHbB& zsPQhYXTkt*7+}Hmuon^r<>4$w)(OG2vAl$RZHmwkQ=r7livoG=o~UAOYUNnQ8j!dC z94@V%IcMU|I+PK|#}JB*1XVmj)Fb2nQO|T-LNU&WrWtCOTxbEYC%O(y08bdb`l1AQ zYuxMYupXmCEl78^^nyiW741{oY7oHL%slAYHGDpAyrTEe4qMnal`{FZB}f5dcEJj8 z^TJPf$Ee1U0DdB6Xz++aw6h?KGblOO(R|1R8|7>gFY0AN>KA>J*+qBON5FNUTXP{{ zs1jl`CnbNHIN`IS0+3ZY=X$I_P{GaR0cH_~5@UtHMw^QVL-5j&tN3HXI=pm&5hZv(EOwLFTuRbp}~ zUN~Pm9%HoQP(Ng_Kf%s|jAbt)>$OUJ?HN1X*DK%%*G!4#;{9;I;GrISHYN$<)R@%4 zQ8?+-whW|&I$mK~HM~n z?$6WlVuvO~0xUK#G3%&DRDaGVPd94%GVGx?EDt1WK~hk+RKEir<4A~90&#jfMIsxR z2VB0!xL6u;qvO#HVGSA*w*-ggE}hxhu{8MRV(mH`oB zRmq&Vk((cHQ3*IE{#lMfIa&s*NVyqhS^sGxH)OYZ%$+trJSOldKJ%3vF5KQrZ<1mU z8)dkYa2B^&g%{sB6;JJTyJ3XBK@>-&|JF-Hh^c4czWcDZJQ}Qn^HW|KjM{D0y?&l? zqUbK{^9_?Gyhj#eUQ-vveIBvsUBi@~3XWYY2={n=3_%clyvhUovSeSbXVPro!FGNj zT*p9xpA;*Sdq{we5|IZkp#^h(&kbsa>Av~UEW}qS$%mB+Dr6T|$v$>yQgx(g1I>Ul zj;VkXNjmXD$+y-tFY@KQ&w&We{r*YF3`xh>r!@bX&aM58F&orad`-L;Rl47mG4M4ET`)r_VL$jVv3iDI%2j0em_aA7Y5I4uyKys;|W>D(1SBj2AD!`l}X z>agIEceFE99V4zbj)UrieVl##s&s1BQQ2Z>Jc>IXeF)g)ZMpY9>m^hxgD-d^c?(9R zb*-3OaD2KsQONDrA)&)%Qwkeyc!A^;6(0pPr79FvU$5Z&D6-_tQkA3K?`Mvp5F_#t zLUGE&Wm?H7-D)B*Kd~mEnafZkJe6oYDWn3YK@&%evtA_D0VhM(;~r>DwH&FX>X?DJ zAK8#HV0F13`8DP9cF;O_LFL@A0P|!}|8J&JDgBccaec%_Sxvgf;-f4U)Oa6H++UI$ z&tA#zW7-J8%k#ae`+oBTnGssQHGji&@z1Y{fI$vsX6|0f$GuaLl+)yIIfX_z!szt3 z-q{I7cdiJ9@zssF>HS)%B@V37EFTB~b_~WQyyUOWJ1$hn9NEl@V-A=w-n$$ZO$`pW z)X3#y?F4TW`6=u4L?5vNb1lyWm{P_?rEbmTU__{m^)kR!AvhX|>UM$9>1tTGAe!h) zA|2$!mBT^RtQ}ns2>0yjUtOE-TbPNm=@8(9cfWk3kjO8|7YD0}7qgOT$pynfq&qri z%w!{aI_39}_tHGw$tsp`Nk&IS14lEC!7BiZd8CL#yX(-q8Y$V9fK&XMk6kKl2bU3h zu@?iKczO4;)?<^4f{KGD(b7R-LDDR}>vwt8J`Wx{GpWl=TWWXjFKxua&U`Ij=D6W$Lp$0c?iLNxNP~15(`erZ*kJzy7UY*^*R-NlL`+5LY%M$s{N{V-XDzEc7rO zx>JNorz7Jcuy<*=CnxUkW4BTYS41{dr?@Vtg=`>Pq#yDw{A+o_-5YcP^}<65eh}1x zePdLxDM^5^LkweV&3+S0%kg))pE)Dh9qvA2Xc=qA!NGhA50zuNszNVgp%O&S_giiV zYhf*WaO)4S$B%)0W8gDyrRn9b8$c+Xm^+EnhCa;~h1ID$2=GrLSC6mV_V&8Kf(LDGhX`lYU$bzDS4-Y?IOs5?BdzbT# zwG^Q~Wx?03ca8-k0(DD%SFL?x^)b1b81tiuE>0{%J;jjjh>9B9Bv9RZl=h&3Y%TU3 zD|pY!#rUCy{;Da;o3yNch^SbA0*%DP0_;3aFJ%Hgqha-?v6kraR|a?4Lt#-tCZZA; z-3hlr$YZKR?=@C)zl0X6pv9D|!FP!G^IsVQK(nXRA11Ob1HJpJyU_&!&mL~&{O!GJ zz7Var3E^?g21QH z2b4Kv^ulXIGGxQ6tT=Et1T`qMO4s?I`mpzIX;NI04!18-R_J`8vE(5n*Qj8i?N5MqhUy=q13?_@HFGQU-sFR*4 zwJJc3+bS2PYHlMnRd;uB%O8Yq!RGdeU;EwUWVIH!TkafDn7FtQD%z?&s9-Dd)7>DZ z2wyDJ&;YI164!|{mAyMZ#xEkv^N&u>B0RX!hNUqQmFE*JXUM+jVR_Q)e5cb3;KbV4 z?+x-lf{678L$`xP)P*`>ctCz$?Yfz*$o(|W6`tc1-TLLEC&7PTp=-7dGNrTOjrTB( zvlXppTr1U9gAy_H zRgGAmVtdY@aZ_I}&=iDqqoIZW3Qc;J5IqnTkv6iGrD1HHiZfB}(ry<-@Kx2MbxUn} zP+##3PIP7ve0(ML*J?|fsy4UnHnNbb%mH*ydiN1eDg01E&9om$%L9-uCx~XHb}rNB z>Uxl z{7dMBn(3to=Hya!U()O0Y*!E|f;fd;S3>?k>Bye2dXm)52W%U8ja5>;MPkhWaL^HI zgM4I4A>fiE&0!qD_q-&4dmgmDj_Cg|61>}pbwaOf`q{zW4;YYS<0$7TLQefPd zDeZ0QQuiK;OYNPSB-hla#nqk~$wo%cZ;qOm>=|M|et?#{sFWn)lD;Y{fD?y)hPJnt z_@b_|jw=n-zsk*Bhw&&q{@^x~##1;IH!0=Hy_(vgl!!?N5|R3*Gj zkJ48$sDXW85P2gIU7>(_Rldv$*9rP3Fmh9q$S{t07z5c>PP%{CcLlKdo=U?W+)tLf*hE)){^#xmZW}_x${mr7I9DGN~$IAF1ncmIAx%oEPDy^K#{zwN!L=*kxj*Vmw z?H1;{kLuJQ@|lkd&NLC5+60v$+sL3LZe!H>Q5+(1sJzYF_{3hRfC1*!@bOh0FxS+4S%42U7!gfnOq_Xc)+5~(QNPJwS#Mtk_dRnc>25~ z5CL*Wuq%od5R4uUoQ2~sKl;~7F zNI&dh(l@hc1D2LU*a+iLho(Pi{L|Gls$v5f&GFalWZqw&SYB}W&kz8na3&G|E8s4l z)VVNtER0urS`r!o&OP`o`z=Rv4J_QTH6_j{fW-`mA}=hCMQ*DaqaiV{cLwewe&&|g z5u|Pa2pVjX-cDL?ugMcK%=HCiXsrKtIwxr# z;0)l~XqbJ8&~JDS6;UJyD0#>lZsDM9$hHBVeJ1T8vocw=cy;x*TL1#CMk|EGu%a>& zKaPrGj+KfRD^5C#o&D{*cNnyN7HVvlQE4)uXPqsmlo+j$!`RwwHKp9pJpWk}L7d4_W#R#IPQKrYm0W*pe<256Nh%@GJsNB|yv=?KI_rNpc z`ygVQ>PZ6N;4cYTFLTIk(g55|G1n^OCw*?yfi6n4ZVH&lsL*CzrAJMQno79vPeB+O zgC+7|VkRy!6!c1E*~;Fr+~OMIVaXkyJI@>Y22g{3bt~|N{@!$q01ygCx#%3B3uh#x zX_!cPJ?#DIqxULVh#(^#Y0iey50ezSP3d9XH-g}`kDc+t24b(ciCo$k9N%^Fh}p0_ z-gxuke7{yeru+L@96(wxE8}os6&Z&n&FBm8ZZ%#x@z;?&a(N$iuVdDrd>+Szs1!uB zFjWG?qZtjkZP=Y9@8wlX%B56%@3nKD!X2gtbfG!ubc(Zw6U4F^;^rP+ziK_{ zNnb)WW24|Bln5{>^`YC@B82z>RSn$;`N;SCnw9lx(2p&6u zL2F+taQ<=PC-g7Hjz4a^Mpj0kd(~OK+x+njya=u+QoV7+lAc^K=7jhZuT)TuY@zZX zw7z{Eln?T;3UVl9fzk}hwu0&{l~QBr_R0L;rB7A;RCqo+IOUzhjBhipi6tx&DZpc@ zt#I{nMsH-}Y^jR9@H5+&sw(;r6#`Hh{ES)G!d-6p0Ta%uMY(Hd4`?QclSTsk=yn6+ za!*#W8#!Z|s_ytUj~W!(xbd#m(}bx@HLkRT;!%@PEjLSqm?JT7efiDfK5~Ik(fJ(D zJCS@}i7|CuuSH}%4>K7sSH|hEkExZ-N~T-q*n{%`6aozX0uIf&C_gvRAQC5T($A^) z|ClvzcbV|b)lCfdg}{+e*VYIy04W)>3Fg`gY`?lG`1LT@0PXwGYCI_yMc(% zZSI<4R%jJ+qyNc#hnQt>{R?<)A*CyWa>n)^FB3|G=cH^|+h(5;T0%7rX)MxmYgdxB zXv99H!nC)f4K?WOV?b#-uB}^Re9}W#o^WTn?zLpB`oxY>F;S@j=b}6b@4J1oMv7>U7QV6qbxRW=+$ySmb8p#xMsAUm;$hYg(ZV|_+en<4 z(?Yi5!Sjlvo9e6-SVD7z`StDCk&{pI|H!slB!j3ayzSJ2gyIQg68;1B zcpYt6aHlB9!F3JT#h(_PWC1+A#3*j5eiXJ@$uuD;kiRwdjbJeQy$iD94sp}CEHGMP zRx51*@fZlui)x)$K%r&HA6SQYc-3wz!wlZZcfj*~8&(9$(&8%rXD*n1blQArG{blr zzeSk+Lr0){&rM1yb+ut)_9aI2*QU=)YGaw?LF9>ZNW*0bB(5Z16esmw*DXm#$5Ht% zFh4H85BUHU(K#wGism{c>xrTU0Qt^DxfY~8X`mwe+G>?!piU{Bs?B`I0-hZvZPyZS z=K99txv<>{TCQ{gMH$=%^hP2fbTK+55vo6SaobGSUc;g$Z3K~U~95CIx%}y zvl2wS)TfiZC$;ep38($ta8Cni~CV;Tgsl#W)A~C%_dbbMo~~1MoZHm zl+p13*sMqb7C({Zse2hX`x7fKIBTw*kw_dWu9iimgNl*Scr#i@?@eexaRi-2eU%v2MAM7l1<^c-d>+G5`jv#*v3!?!)gX;dVrChBVZ?MIF$kQMXtvk1bw=2=rF# zMsUD(>TIz?%y5QY?qJ_o;}-g{D2&Tywd=vs>-=~uHU*-0vqtIcdhuhdHkDlE2*Sb? zmq``MIcvyp=mG}}x-{-1rE}eB?M6Yz3z;sJ%tx=&JmqRNNHMgpw|U_4k41@Ut^k9j zu~Q4Wji{T(c6UC)BWAlN2Gxa+4E8dKG+e+!VjqmOT?OdfS0=daY?sj*4wE6v22- z5<<6~PbyVbEQybTMJ_z#na!W&eZQ%ao&`)_UUDNDPLvsdd-sRhfDYg}^-DD5k)0?P zC~inmo?%;s(*fdUDC7!T%%LjZI&@fAkYhF4r(e}8S}eR$eKhI1s3PU60ByH+wd`Bv zUenE}`kzf^_oC;CJ(VHr}d$%+H)9TU!dNlwd5WHb6YVI-@U<1Vg|#+7}h&jt+wXFs$K4CZ<-%`1R|Gp`b5``Un>P zb+6Mf3llKbDKrV95uu_M(R(0`=*}yUemYfGl0t_G@xbmBMv$8YNPiF@5cG=^N#5%# zh5E>x%RrgNYk98*LR+*R4CJN1D-i-l?^1754%xRa zl4^!Rv+aGANbo~xA^vXcPo4 zq{CJAtpg@JmlFjm4V|b38dhpd3Lo@dWN9R);<}MoDAMi_&hM`Rx`ABY`b8(o=iL zqe4ERC9<mWVN1>?bGL$zvS-*pBo61^coT@gIASFKS%mmyf4dqA^%q zkX8ct8l$M!3|~}>U5I!6Gb<$qK{SWNY|WzN%!=6DV^5b*!QAwD#YR%v&8AYu9^iJD=Zih*4?>o40~~s*Wur z40A_9LpN~sZlxCF@QnPpCs#Lj)QO74-9v%!jHsF;8j3%j+3Vpy7q$Wfj+0;=u&!-43R>6~aMB1?Q z3fWaH%QUT#RXC=+@wyj|$ZKMf`EnS}=?U@TE*h3{mY@L^}G3n6HBUF~=-*#eWG z)k)EFd$(%2544*IQDoJsv|UJry=Ydc?Zmk3j9A-I*gcU^VA{_B4~~#AO50&tqXBz6UV_=!#h*OxJ4<#`XV#{^(rn9;_J+VFf5pdLfN|>84dvw!T`F0HA z%AuaFFU)F(?Jiq>o=kKEe&3%HaAtM6QUn`H-%&PL?(fVU-Di@)%|;U}3EV&~`BB)q z^dp{?-9Fe9MIf+t!pwXC5M}6qgbWz>Wd`W9Lz^z ztG6J#^~uh?uF@e%9$5CEBS){W^|veY0{>iOaZPxRxFSyFy=y7)OXlI|(K@H5OyQvwX3&}}eSTD8eYM5uG#IHCn!8)PqIk_3^Xy|02D zk|+DQbV=c9q2Dz73&14VUHR*Mc@(m?k#-rl3PLI})dNZ1hDgbhdmwtEDYy9+o2QCF zbq5ra!TltgoWn(bBc?*|(zQoV%l7Bhz3aY^;%9wZlZ07i9qq2Knv@b~KHKn(0FC09D;+{VBHmp*$ArV1sMb7fXQmOB#!yO0NWRS9K69L)iAGO>>T(vj@EE8`) z0SFiKnt-J7X-`IL4IR38BNOC#7_2BjEIfj`!k*i8UC9XhhU=i);P|f2 zk%lEe-H#_F7nFQ!#;5*6<*^`>PY$Xzmp2k)#7^RCs`-O{sSGm1EDkF;i3c!+QT_ezj7WS;*7)QL4 zCH>`uicwTzdiu5dTa%nvKbDg z-1=mz$3>HhjIOG(Y->2O;WjjtUiW1?Qgh2&Xm!;GWQH%9tgCrbzxK*bPe=QKuJxlx z(ft7|L;vD3>iPhnw;hYi&axt7j%}bjsg8~W;~G~iN%y9t0Eami$|z9gNgc+&NwW6y z=6Sxam5kl8881>zahJtJiE{bMy%9LcRd)UF@gRj{=T2Piw;f<8W=aZCqomJ>&qFC{ z)SNov0~XoGZ7o6uFzf%y=8%evW;RbJFhFrp44ck^o|_5@MJ?xzw$2tF=(e6ERh*}A zl{SlDG_M%~{dXNk#iGuG>t|E&{mK&xH-Y^XK~b z{=aOKBLx9W&6ET&ohB12c(H+W*Vn@>Y&Rl5c{RY$CY$xS);2-4Bm_xkoJ&wUsCf4R zGuv4EZk!>22`#W961Avwe|N9vp|;rK+DuSgb%zS;DYt3VNzK*ckiCw-AdTFeIkSW#LjdwuL}{e7JHEpoFqf!*%J)dB`Q_EFH-yUKoGkrKoA zXlepD+Dz_Ce^(Ww^6&SU{Cvg=ifjGjrrl%vI^N2y;30nKB;;e(+- z<4-*1s+*cHaVtQd8ti^1HLMIT3h4Fl$$Il4;RYNA#$U0@Lw^Cy-R+D0Oz4uU8`BM4 zY9V-am($>noNWGIC*5RD&LM8%(=5db;0a5I3~r)K{_5d!c19 zf2WE9{GS?zzrK6n&NG4xSOHYtP`Crfb~$--fnT2u>`^F(9X^r1uFnz;tkBL2b!S$r z#*&5m>Qt!7_K0<45p5jpW)Fww7cPAmqA6Ksd22Fl#6kQwPrUDbe-%|K#JEia<}y|Y z?HDb)-Nawdod}wg-!9c2>1yT1UxSA*S+xuU$qup~^f<+*I^!%a4;;*hI9!z`*+vU> zvyUJLyRB~q8@7q1#YXmTQjpd7e!UbCUQl!P<{521NrjaHWt<4yI>Y!9ZN9P#`04%` zpUVeGe?;e#{Llp-V8r>us+`nxB%;_BOn_L z(UD*w*g|+Nnc_pZ@kb60;wYZj4cFH=j%LHHSY1#{qx||RUWm8QMc5nQgAJbW6ICC& zww*K>LER9^rH`R8Tot(amxDZp`JED(AKId%_Na!4Sh_Q%Lth-Vve?N*adLfU_+3~l zT4<+VS|V%FB~UN4V~1P?zRoiJh4>f7@_uO1hZ@qqc&lBNi$s|^#B3+_<(X*l&{Ln0 z0t{*e)i;X;r`B^}Sany07$sk=21rnlj3ZU!PB?racx zugC>%?Nh-CQw9yWj-K_LlKH&|dA(llc!7fNF>|go&2EI!N4j~&OLSjv!{;Gc(oMPB zTJQ&B(;942nl#mLF-ifK{Jfq7E%p4S@V2Ne$8E2GqeDnfl4=K;6FMlYo??N$X=7w{B8NQtqDBtS551C(LZIVkauV*3>Y|+|)6(@eI|COq@%nr(+lK~_T6~KkkOd^P)uQm4Qc*xZkOC&Y@`n7BX!K2Vx*w^vh zQ30v$)dA)MCG1n~ZaX)p;tBX^d@)>?4=4)Gz-};yBDedC{>cHE=vF+HjM&dwX2eC?+$xb~A jFg7xtwQB^(8Xm}8?I6=iq0l&bd08+=EpMz^1R|AoiDzW? literal 0 HcmV?d00001 diff --git a/modules/impermanence/default.nix b/modules/impermanence/default.nix index 600e2ad..89274db 100644 --- a/modules/impermanence/default.nix +++ b/modules/impermanence/default.nix @@ -18,10 +18,13 @@ ]; directories = [ - "/var/tmp/agenix-rekey" "/var/log" "/var/lib/systemd" "/var/lib/nixos" + { + directory = "/var/tmp/agenix-rekey"; + mode = "0777"; + } ] ++ lib.lists.optionals config.hardware.bluetooth.enable [ "/var/lib/bluetooth" diff --git a/modules/optional/secureboot.nix b/modules/optional/secureboot.nix index 6136158..b60f42d 100644 --- a/modules/optional/secureboot.nix +++ b/modules/optional/secureboot.nix @@ -4,6 +4,30 @@ config, ... }: { + # HOW TO: Add secureboot to new systems + # generate keys with `sbct create-keys' + # tar the resulting folder using + # `tar cvf secureboot.tar -C /etc/secureboot . + # Copy the tar to local using scp + # and encrypt it using rage + # safe the encrypted archive to hosts//secrets/secureboot.tar.age + # DO NOT forget to delete the unecrypted archives + # link /run/secureboot to /etc/secureboot + # This is necesarry since for the first + # apply the rekeyed keys are not yet available but needed for + # signing the boot files + # ensure the boot files are signed using + # `sbctl verify' + # Now reboot the computer into BIOS and + # enable secureboot, this may include + # removing old keys + # bootctl should now read + # `Secure Boot: disabled (setup)' + # you can now enroll your secureboot keys using + # `sbctl enroll-keys` + # If you want to be able to boot microsoft signed images append + # `--microsoft` + # Time to reboot and pray environment.systemPackages = [ # For debugging and troubleshooting Secure Boot. (pkgs.sbctl.override