Return-Path: <mohit.m.sethi@ericsson.com>
X-Original-To: lwip@ietfa.amsl.com
Delivered-To: lwip@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1])
 by ietfa.amsl.com (Postfix) with ESMTP id 3F78412711B
 for <lwip@ietfa.amsl.com>; Mon, 26 Feb 2018 11:42:12 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.32
X-Spam-Level: 
X-Spam-Status: No, score=-4.32 tagged_above=-999 required=5
 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1,
 DKIM_VALID_AU=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_MED=-2.3,
 RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, SPF_PASS=-0.001]
 autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key)
 header.d=ericsson.com
Received: from mail.ietf.org ([4.31.198.44])
 by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024)
 with ESMTP id 4bvkY4AdTO0w for <lwip@ietfa.amsl.com>;
 Mon, 26 Feb 2018 11:42:09 -0800 (PST)
Received: from sesbmg23.ericsson.net (sesbmg23.ericsson.net [193.180.251.37])
 (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256
 bits)) (No client certificate requested)
 by ietfa.amsl.com (Postfix) with ESMTPS id 065DC12D7F7
 for <lwip@ietf.org>; Mon, 26 Feb 2018 11:42:08 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; d=ericsson.com; s=mailgw201801;
 c=relaxed/simple; q=dns/txt; i=@ericsson.com; t=1519674127;
 h=From:Sender:Reply-To:Subject:Date:Message-ID:To:Cc:MIME-Version:Content-Type:
 Content-Transfer-Encoding:Content-ID:Content-Description:Resent-Date:Resent-From:
 Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID:In-Reply-To:References:List-Id:
 List-Help:List-Unsubscribe:List-Subscribe:List-Post:List-Owner:List-Archive;
 bh=3IALXgUY81BA2zXSkA2SBj4O0ZjJN2TwNa3fIxXPCec=;
 b=UbAFmt0uunAdO/Z6NbVahMhtV4FIiFzygtQx3kgnaCkQWGxP/LV9uofcccW+4tpw
 ViJjt20oyYENcJu95zJzM/cpxIBFvgFic0clz2/lozZg5vL623AAYwDFoK64Et3Q
 Jhfuyy+Mv/z1T9pcNKuOLHp7JWaTv2rDg+smKbshP90=;
X-AuditID: c1b4fb25-083ff70000002d5f-6e-5a94630f71ee
Received: from ESESSHC012.ericsson.se (Unknown_Domain [153.88.183.54])
 by sesbmg23.ericsson.net (Symantec Mail Security) with SMTP id
 74.1F.11615.F03649A5; Mon, 26 Feb 2018 20:42:07 +0100 (CET)
Received: from nomadiclab.fi.eu.ericsson.se (153.88.183.153) by
 smtp.internal.ericsson.com (153.88.183.56) with Microsoft SMTP Server id
 14.3.352.0; Mon, 26 Feb 2018 20:42:06 +0100
Received: from nomadiclab.fi.eu.ericsson.se (localhost [127.0.0.1])	by
 nomadiclab.fi.eu.ericsson.se (Postfix) with ESMTP id 2452948178F; Mon, 26 Feb
 2018 21:42:06 +0200 (EET)
Received: from [127.0.0.1] (localhost [IPv6:::1])	by
 nomadiclab.fi.eu.ericsson.se (Postfix) with ESMTP id CF5D44813A5; Mon, 26 Feb
 2018 21:42:05 +0200 (EET)
References: <151967388722.21803.2650061959603617056@ietfa.amsl.com>
To: "lwip@ietf.org" <lwip@ietf.org>, Zhen Cao <zhencao.ietf@gmail.com>, Suresh
 Krishnan <Suresh@kaloom.com>
From: Mohit Sethi <mohit.m.sethi@ericsson.com>
X-Forwarded-Message-Id: <151967388722.21803.2650061959603617056@ietfa.amsl.com>
Message-ID: <b673d380-7bec-a333-a9c7-f52fc082e2f1@ericsson.com>
Date: Mon, 26 Feb 2018 21:42:05 +0200
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:52.0) Gecko/20100101
 Thunderbird/52.6.0
MIME-Version: 1.0
In-Reply-To: <151967388722.21803.2650061959603617056@ietfa.amsl.com>
Content-Type: multipart/signed; protocol="application/pkcs7-signature";
 micalg=sha-256; boundary="------------ms070204030708090905040601"
X-AV-Checked: ClamAV using ClamSMTP
X-Brightmail-Tracker: H4sIAAAAAAAAA+NgFrrAIsWRmVeSWpSXmKPExsUyM2K7mS5/8pQog50vBSzm7RO22NZ1isVi
 +t4/jA7MHjtn3WX3WLLkJ5PH+Ssz2AOYo7hsUlJzMstSi/TtErgyHq3dyl7QvZCxYuX/O4wN
 jNPaGbsYOTgkBEwkNpxM72Lk4hASOMwoMePqMlYIZwejxOk5G9ggnE2MEmc3nmaCcBYwShy5
 soUdpF1YwE1i1bSELkZOoLizxPfprxhBbBGBXInOpW+YQWw2AT2JznPHwWwJAX+JC1vWgdm8
 AvYS63esZgGxWQRUJS7ffgxmiwpESHSunM8CUSMocXLmEzCbU8BFou3bGbD5zALdjBKPL/tA
 zFSWWNCyiBHiBnWJrR0HGCcwCs1C0j4LSQuEHSZx80UrVFxc4taT+UwQtq3Enbm7mSFsbYll
 C19D2boSi7atYMcUt5aY8esgG4StKDGl+yFUjanE66MfGSFsY4ll6/6yLWDkWcUoWpxanJSb
 bmSsl1qUmVxcnJ+nl5dasokRGLcHt/xW3cF4+Y3jIUYBDkYlHl4ZrylRQqyJZcWVuYcYVYDm
 PNqw+gKjFEtefl6qkgjvysWTo4R4UxIrq1KL8uOLSnNSiw8xSnOwKInzzhFujxISSE8sSc1O
 TS1ILYLJMnFwSjUwFm9UD494tfT/G5vncaaL21ISLD51sN61XpVxx81JQ9Mh5tq5xTvks8zL
 hW4cX2Hz78zTLXduz5lWdmJnZI768qA5h2oNY2dqvZwqIbrmgE9ll92cN12r98yVPd6xSLa0
 zyv+xONlBe+m/Tp8+jKv9qRWWbdNfr93JGZO7PT1ObZH5Ly59fNLT5RYijMSDbWYi4oTAfv0
 dNjjAgAA
Archived-At: <https://mailarchive.ietf.org/arch/msg/lwip/Dcld7wHXulSwykY7SQOr4BWKTXA>
Subject: [Lwip] Fwd:  I-D Action: draft-ietf-lwig-crypto-sensors-06.txt
X-BeenThere: lwip@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: Lightweight IP stack <lwip.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/lwip>,
 <mailto:lwip-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/lwip/>
List-Post: <mailto:lwip@ietf.org>
List-Help: <mailto:lwip-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/lwip>,
 <mailto:lwip-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 26 Feb 2018 19:42:12 -0000

--------------ms070204030708090905040601
Content-Type: multipart/alternative;
 boundary="------------0A31E2BBD452409BF2C16389"
Content-Language: en-US

This is a multi-part message in MIME format.
--------------0A31E2BBD452409BF2C16389
Content-Type: text/plain; charset=windows-1252; format=flowed
Content-Transfer-Encoding: quoted-printable

Dear all,

Thanks to all the feedback from the directorates as well as the IESG. We =

have now updated the draft based on the feedback received. There were no =

major changes and a list of all the issues fixed can be found below.=20
This feedback has greatly helped us to improve the final version of the=20
document. Hopefully, it has also made the job of the RFC editor easy.

--Mohit, Jari, Ari and Heidi

- Update acknowledgments section with all the reviewers.
- Added a bullet in section 9 (Summary) stating that developers should=20
provide mechanisms for devices to generate new identities. (Christian=20
Huitema)
- Expanded first use of ECDSA. (Dan Romascanu)
- Uniformly use "resource-constrained" instead of small devices. (Dan=20
Romascanu)
- Add a sentence on how a real implementation would find the resource=20
directory. (Dan Romascanu)
- "physically different" replaced with "physically distinct" in section=20
7. (Spencer Dawkins)
- Fixed typo in Section 6 "results for for all the 128". (Emmanuel Baccel=
li)
- Rephrased the bullet on cryptographic-quality randomness on Arduino=20
(Emmanuel Baccelli)
- Explicit mention of what is n and m in section 4.1. (Emmanuel Baccelli)=

- Separate OS from cryptographic libraries and cite survey on OS for=20
resource-constrained devices. (Emmanuel Baccelli)
- Fixed typo in Section 7 "enough power to be stay on". (Kathleen=20
Moriarty and Emmanuel Baccelli)
- Fix missing article before "CoAP base specification". (Ben Campbell)
- Rephrased "Once both peers..." in section 4.1. (Ben Campbell)
- Added missing article before Igrp. (Ben Campbell)
- Fixed repeating either in section 4.2. (Ben Campbell)
- Added article "It is written in nesC programming language..." before=20
"nesC". (Ben Campbell)
- Rephrased "The workshop recommended that additional work should be=20
undertaken in" in section 2. (Warren Kumari)
- Rephrased ".. to be fed in (not both an identity and certificate or=20
shared secrets that must be kept confidential)". (Warren Kumari)
- Split long sentence to remove ambiguity "For example, leap-of-faith or =

trust-on-first-use based pairing methods assume that the attacker....".=20
(Warren Kumari)
- Split long sentence to remove ambiguity "We decided to use the Arduino =

Mega which has the same 8-bit architecture like the Arduino Uno...".=20
(Warren Kumari)
- Join sentences "For instance, a sensor that wakes up every now and=20
then can likely spend a fraction ...". (Warren Kumari)
- Added reference to nesC. (Eric Rescorla)
- Removed reference to outdated symmetric crypto algorithms. (Eric Rescor=
la)
- Change "For example, leap-of-faith or trust-on-first-use based pairing =

methods assume that the" to "For example, *many* leap-of-faith or=20
trust-on-first-use based pairing methods assume that the". (Eric Rescorla=
)
- Remove "intuitive" from "intuitive API for developer". (Eric Rescorla)
- Remove extra 0 in measurements for ed25519. (Eric Rescorla)
- Add that relic now also support x25519 and ed25519. (Eric Rescorla)
- Add citation to SEC 2 recommended domain parameters for comparable RSA =

key lengths. (Eric Rescorla)
- Remove hyphen in wrap-around. (Eric Rescorla)
- Use the secp and sect notation uniformly. (Eric Rescorla)
- Authors have decided against adding commas in the measurements=20
reported. We had commas in the earlier versions but the working group=20
decided that it can cause confusion even though it provides better=20
readability.





-------- Forwarded Message --------
Subject: 	[Lwip] I-D Action: draft-ietf-lwig-crypto-sensors-06.txt
Date: 	Mon, 26 Feb 2018 11:38:07 -0800
From: 	internet-drafts@ietf.org
To: 	i-d-announce@ietf.org
CC: 	lwip@ietf.org



A New Internet-Draft is available from the on-line Internet-Drafts direct=
ories.
This draft is a work item of the Light-Weight Implementation Guidance WG =
of the IETF.

         Title           : Practical Considerations and Implementation Ex=
periences in Securing Smart Object Networks
         Authors         : Mohit Sethi
                           Jari Arkko
                           Ari Keranen
                           Heidi-Maria Back
	Filename        : draft-ietf-lwig-crypto-sensors-06.txt
	Pages           : 34
	Date            : 2018-02-26

Abstract:
    This memo describes challenges associated with securing resource-
    constrained smart object devices.  The memo describes a possible
    deployment model where resource-constrained devices sign message
    objects, discusses the availability of cryptographic libraries for
    resource-constrained devices and presents some preliminary
    experiences with those libraries for message signing on resource-
    constrained devices.  Lastly, the memo discusses trade-offs involving=

    different types of security approaches.


The IETF datatracker status page for this draft is:
https://datatracker.ietf.org/doc/draft-ietf-lwig-crypto-sensors/

There are also htmlized versions available at:
https://tools.ietf.org/html/draft-ietf-lwig-crypto-sensors-06
https://datatracker.ietf.org/doc/html/draft-ietf-lwig-crypto-sensors-06

A diff from the previous version is available at:
https://www.ietf.org/rfcdiff?url2=3Ddraft-ietf-lwig-crypto-sensors-06


Please note that it may take a couple of minutes from the time of submiss=
ion
until the htmlized version and diff are available at tools.ietf.org.

Internet-Drafts are also available by anonymous FTP at:
ftp://ftp.ietf.org/internet-drafts/

_______________________________________________
Lwip mailing list
Lwip@ietf.org
https://www.ietf.org/mailman/listinfo/lwip


--------------0A31E2BBD452409BF2C16389
Content-Type: text/html; charset=windows-1252
Content-Transfer-Encoding: quoted-printable

<html>
  <head>

    <meta http-equiv=3D"content-type" content=3D"text/html; charset=3Dwin=
dows-1252">
  </head>
  <body bgcolor=3D"#FFFFFF" text=3D"#000000">
    <p>Dear all,<br>
      <br>
      Thanks to all the feedback from the directorates as well as the
      IESG. We have now updated the draft based on the feedback
      received. There were no major changes and a list of all the issues
      fixed can be found below. This feedback has greatly helped us to
      improve the final version of the document. Hopefully, it has also
      made the job of the RFC editor easy.<br>
      <br>
      --Mohit, Jari, Ari and Heidi<br>
      <br>
      - Update acknowledgments section with all the reviewers. <br>
      - Added a bullet in section 9 (Summary) stating that developers
      should provide mechanisms for devices to generate new identities.
      (Christian Huitema)<br>
      - Expanded first use of ECDSA. (Dan Romascanu)<br>
      - Uniformly use "resource-constrained" instead of small devices.
      (Dan Romascanu)<br>
      - Add a sentence on how a real implementation would find the
      resource directory. (Dan Romascanu) <br>
      - "physically different" replaced with "physically distinct" in
      section 7. (Spencer Dawkins)<br>
      - Fixed typo in Section 6 "results for for all the 128". (Emmanuel
      Baccelli)<br>
      - Rephrased the bullet on cryptographic-quality randomness on
      Arduino (Emmanuel Baccelli)<br>
      - Explicit mention of what is n and m in section 4.1. (Emmanuel
      Baccelli)<br>
      - Separate OS from cryptographic libraries and cite survey on OS
      for resource-constrained devices. (Emmanuel Baccelli)<br>
      - Fixed typo in Section 7 "enough power to be stay on". (Kathleen
      Moriarty and Emmanuel Baccelli)<br>
      - Fix missing article before "CoAP base specification". (Ben
      Campbell)<br>
      - Rephrased "Once both peers..." in section 4.1. (Ben Campbell)<br>=

      - Added missing article before Igrp. (Ben Campbell)<br>
      - Fixed repeating either in section 4.2. (Ben Campbell)<br>
      - Added article "It is written in nesC programming language..."
      before "nesC". (Ben Campbell)<br>
      - Rephrased "The workshop recommended that additional work should
      be undertaken in" in section 2. (Warren Kumari)<br>
      - Rephrased ".. to be fed in (not both an identity and certificate
      or shared secrets that must be kept confidential)". (Warren
      Kumari)<br>
      - Split long sentence to remove ambiguity "For example,
      leap-of-faith or trust-on-first-use based pairing methods assume
      that the attacker....". (Warren Kumari)<br>
      - Split long sentence to remove ambiguity "We decided to use the
      Arduino Mega which has the same 8-bit architecture like the
      Arduino Uno...". (Warren Kumari)<br>
      - Join sentences "For instance, a sensor that wakes up every now
      and then can likely spend a fraction ...". (Warren Kumari)<br>
      - Added reference to nesC. (Eric Rescorla)<br>
      - Removed reference to outdated symmetric crypto algorithms. (Eric
      Rescorla)<br>
      - Change "For example, leap-of-faith or trust-on-first-use based
      pairing methods assume that the" to "For example, *many*
      leap-of-faith or trust-on-first-use based pairing methods assume
      that the". (Eric Rescorla)<br>
      - Remove "intuitive" from "intuitive API for developer". (Eric
      Rescorla)<br>
      - Remove extra 0 in measurements for ed25519. (Eric Rescorla)<br>
      - Add that relic now also support x25519 and ed25519. (Eric
      Rescorla)<br>
      - Add citation to SEC 2 recommended domain parameters for
      comparable RSA key lengths. (Eric Rescorla)<br>
      - Remove hyphen in wrap-around. (Eric Rescorla)<br>
      - Use the secp and sect notation uniformly. (Eric Rescorla)<br>
      - Authors have decided against adding commas in the measurements
      reported. We had commas in the earlier versions but the working
      group decided that it can cause confusion even though it provides
      better readability.<br>
      =A0<br>
      <br>
      <br>
    </p>
    <div class=3D"moz-forward-container"><br>
      <br>
      -------- Forwarded Message --------
      <table class=3D"moz-email-headers-table" border=3D"0" cellspacing=3D=
"0"
        cellpadding=3D"0">
        <tbody>
          <tr>
            <th nowrap=3D"nowrap" valign=3D"BASELINE" align=3D"RIGHT">Sub=
ject:
            </th>
            <td>[Lwip] I-D Action: draft-ietf-lwig-crypto-sensors-06.txt<=
/td>
          </tr>
          <tr>
            <th nowrap=3D"nowrap" valign=3D"BASELINE" align=3D"RIGHT">Dat=
e: </th>
            <td>Mon, 26 Feb 2018 11:38:07 -0800</td>
          </tr>
          <tr>
            <th nowrap=3D"nowrap" valign=3D"BASELINE" align=3D"RIGHT">Fro=
m: </th>
            <td><a class=3D"moz-txt-link-abbreviated" href=3D"mailto:inte=
rnet-drafts@ietf.org">internet-drafts@ietf.org</a></td>
          </tr>
          <tr>
            <th nowrap=3D"nowrap" valign=3D"BASELINE" align=3D"RIGHT">To:=
 </th>
            <td><a class=3D"moz-txt-link-abbreviated" href=3D"mailto:i-d-=
announce@ietf.org">i-d-announce@ietf.org</a></td>
          </tr>
          <tr>
            <th nowrap=3D"nowrap" valign=3D"BASELINE" align=3D"RIGHT">CC:=
 </th>
            <td><a class=3D"moz-txt-link-abbreviated" href=3D"mailto:lwip=
@ietf.org">lwip@ietf.org</a></td>
          </tr>
        </tbody>
      </table>
      <br>
      <br>
      <pre>A New Internet-Draft is available from the on-line Internet-Dr=
afts directories.
This draft is a work item of the Light-Weight Implementation Guidance WG =
of the IETF.

        Title           : Practical Considerations and Implementation Exp=
eriences in Securing Smart Object Networks
        Authors         : Mohit Sethi
                          Jari Arkko
                          Ari Keranen
                          Heidi-Maria Back
	Filename        : draft-ietf-lwig-crypto-sensors-06.txt
	Pages           : 34
	Date            : 2018-02-26

Abstract:
   This memo describes challenges associated with securing resource-
   constrained smart object devices.  The memo describes a possible
   deployment model where resource-constrained devices sign message
   objects, discusses the availability of cryptographic libraries for
   resource-constrained devices and presents some preliminary
   experiences with those libraries for message signing on resource-
   constrained devices.  Lastly, the memo discusses trade-offs involving
   different types of security approaches.


The IETF datatracker status page for this draft is:
<a class=3D"moz-txt-link-freetext" href=3D"https://datatracker.ietf.org/d=
oc/draft-ietf-lwig-crypto-sensors/">https://datatracker.ietf.org/doc/draf=
t-ietf-lwig-crypto-sensors/</a>

There are also htmlized versions available at:
<a class=3D"moz-txt-link-freetext" href=3D"https://tools.ietf.org/html/dr=
aft-ietf-lwig-crypto-sensors-06">https://tools.ietf.org/html/draft-ietf-l=
wig-crypto-sensors-06</a>
<a class=3D"moz-txt-link-freetext" href=3D"https://datatracker.ietf.org/d=
oc/html/draft-ietf-lwig-crypto-sensors-06">https://datatracker.ietf.org/d=
oc/html/draft-ietf-lwig-crypto-sensors-06</a>

A diff from the previous version is available at:
<a class=3D"moz-txt-link-freetext" href=3D"https://www.ietf.org/rfcdiff?u=
rl2=3Ddraft-ietf-lwig-crypto-sensors-06">https://www.ietf.org/rfcdiff?url=
2=3Ddraft-ietf-lwig-crypto-sensors-06</a>


Please note that it may take a couple of minutes from the time of submiss=
ion
until the htmlized version and diff are available at tools.ietf.org.

Internet-Drafts are also available by anonymous FTP at:
<a class=3D"moz-txt-link-freetext" href=3D"ftp://ftp.ietf.org/internet-dr=
afts/">ftp://ftp.ietf.org/internet-drafts/</a>

_______________________________________________
Lwip mailing list
<a class=3D"moz-txt-link-abbreviated" href=3D"mailto:Lwip@ietf.org">Lwip@=
ietf.org</a>
<a class=3D"moz-txt-link-freetext" href=3D"https://www.ietf.org/mailman/l=
istinfo/lwip">https://www.ietf.org/mailman/listinfo/lwip</a>
</pre>
    </div>
  </body>
</html>

--------------0A31E2BBD452409BF2C16389--

--------------ms070204030708090905040601
Content-Type: application/pkcs7-signature; name="smime.p7s"
Content-Transfer-Encoding: base64
Content-Disposition: attachment; filename="smime.p7s"
Content-Description: S/MIME Cryptographic Signature

MIAGCSqGSIb3DQEHAqCAMIACAQExDzANBglghkgBZQMEAgEFADCABgkqhkiG9w0BBwEAAKCC
DMUwggX7MIID46ADAgECAhBcf8Ki080s7KKjg2APnSBWMA0GCSqGSIb3DQEBCwUAMEcxCzAJ
BgNVBAYTAlNFMREwDwYDVQQKDAhFcmljc3NvbjElMCMGA1UEAwwcRXJpY3Nzb24gTkwgSW5k
aXZpZHVhbCBDQSB2MzAeFw0xNzEwMDgxMDAzMjJaFw0yMDEwMDgxMDAzMjFaMGgxETAPBgNV
BAoMCEVyaWNzc29uMRYwFAYDVQQDDA1Nb2hpdCBTZXRoaSBNMSkwJwYJKoZIhvcNAQkBFhpt
b2hpdC5tLnNldGhpQGVyaWNzc29uLmNvbTEQMA4GA1UEBRMHZXNldG1vaDCCASIwDQYJKoZI
hvcNAQEBBQADggEPADCCAQoCggEBAN23/VIr1UI1NLeaFL45vzBE0NglNKyyUQknMqT5zRxm
ocJ74fYRJmfHmaQxEYdxp6cCYFxbM2OJOiMN5LRxEQG282Dsjnff6mHXt5wNsMrHZ88poT3X
yZCzFBkQF/kswJKu6OD9v1J6WWl9fV2h0QRP0ju+B/H2O3OzioHDP9Qazzr5TMTvmRmXoMfh
WXyH/joBaGVyn8SCeRaI0wVGRCKDp93UzdL5o+qGqCUPJQP/2SR/4UoCUTqEtSgh4iCBNAs/
OwhHwbWdU73/EJtsaaOG2fhwMTgWR3KJOIUMyWtRBcO9cIan+82SNgAByR4x2BKIWgFvSPNo
GXKn1nOi0W0CAwEAAaOCAcAwggG8MEgGA1UdHwRBMD8wPaA7oDmGN2h0dHA6Ly9jcmwudHJ1
c3QudGVsaWEuY29tL2VyaWNzc29ubmxpbmRpdmlkdWFsY2F2My5jcmwwgYIGCCsGAQUFBwEB
BHYwdDAoBggrBgEFBQcwAYYcaHR0cDovL29jc3AyLnRydXN0LnRlbGlhLmNvbTBIBggrBgEF
BQcwAoY8aHR0cDovL2NhLnRydXN0LnRlbGlhc29uZXJhLmNvbS9lcmljc3Nvbm5saW5kaXZp
ZHVhbGNhdjMuY2VyMCUGA1UdEQQeMByBGm1vaGl0Lm0uc2V0aGlAZXJpY3Nzb24uY29tMFUG
A1UdIAROMEwwSgYMKwYBBAGCDwIDAQESMDowOAYIKwYBBQUHAgEWLGh0dHBzOi8vcmVwb3Np
dG9yeS50cnVzdC50ZWxpYXNvbmVyYS5jb20vQ1BTMB0GA1UdJQQWMBQGCCsGAQUFBwMEBggr
BgEFBQcDAjAdBgNVHQ4EFgQUM0z7o31aA+qQasQqDc7/Ppn7u5MwHwYDVR0jBBgwFoAUHHsZ
npecdqwgPdjc45Fq49stplMwDgYDVR0PAQH/BAQDAgWgMA0GCSqGSIb3DQEBCwUAA4ICAQCB
35yJmyIRJUmxQmpYX7hNdQJXxJdIAMzCe+rQsz+0F1zA8xsYn4Rn5m7SVGKbE4ONC+EUHHzQ
o1OpA5txlK+IPRMqZTM2cQpAet8Qy2vRqFVd0pFDmPx0Az/SPooz7gnuIaPaCGeXOSSxtSOu
rX+7fE2EiE/SuCFKmtsFmwnZH62hDDtzd3XTwmJia/5Ab+8/elAstT5a1cP52SorrkuLPgAB
ny/XJzsU3LOQQ37Wm5DMyMPEK+zkBG/+2t1cOGgryvu7Hq14NfkAUZxHMei6Yf2UABNxbapB
4tyxqpZuPZDl1AwRKMGYHPsnywK4PZDdsD6R+O/YCWdfq9Q3MMCT3C6vu38phy1r6QDCVHVI
IPdirDfZ2ypbeqHAwkswioykkBTln9DEyaTYMlxb41EYh/3JwUQmuQQ4ozSfcLTwoaQ+M+Z4
1J/n7AARwD7u3Lb2ls+fmvOLrC+tc0pXlvTKspIhpaNC1Cz7sbsjMSbSqBW9PtY+Vex7GB2J
zI8fDHTT/8Jx+33cta2BE6mPFeUY2lu12zQiqNVUc9zEQ7WqGz4VTGFZDnzfU2gCAAYsuimf
kQJD+Sr2G3wXs38yN1OhWHBuG1fglz0k5URhXMNC8HtRityIm2504ym5GpTrriJ8X1fQDYN1
WlOPvv4xJpfHAz4NMKJKQmCNtfuZ8BNNyTCCBsIwggSqoAMCAQICEFO4foPhnJkok7CbSRzs
uOswDQYJKoZIhvcNAQELBQAwNzEUMBIGA1UECgwLVGVsaWFTb25lcmExHzAdBgNVBAMMFlRl
bGlhU29uZXJhIFJvb3QgQ0EgdjEwHhcNMTUxMDI3MTIxNjQ2WhcNMjUxMDI3MTIxNjQ2WjBH
MQswCQYDVQQGEwJTRTERMA8GA1UECgwIRXJpY3Nzb24xJTAjBgNVBAMMHEVyaWNzc29uIE5M
IEluZGl2aWR1YWwgQ0EgdjMwggIiMA0GCSqGSIb3DQEBAQUAA4ICDwAwggIKAoICAQDs8t8A
ALhQ8qe72FS3xpP348GqO9TDRjS0s85eQ7Y0LTLZdmSz2cl+lYqs0zfSTm+7meisbhkqUXkL
7fFzoe4iIZCh/VuYUaW407CZlDCXes4n4TqTSuoklN6uOPhY7EC9ZVbXILlLhRummTdDdxhV
W4Leo0awEhfLf98MvWxzwCHzMj8m6YOmNjx+f9TcJE3qaA0piuvSxlfpVdiCulPTlmsmV2RS
BSAwqBshZYRcQBIDfqmdvkaoP9EzNKAh7yjthC0hpgHZyZMIs0eNo4v2PUmE0rhu+Zs0nujn
whljPA2/8b8v9tGixD1zbtT7zoM2Ot1menJpFp4zJVSfdKVgtoWqg5t2H/E0XY1LwJez89W0
7nscEocyBmpC+zJAmKxKhzEWqIyP1UrZaEIFu+hO+s0Nm8sOUMa4TlG4rAUikc5U5TmUIGBR
QGxulYhfAzqSYf8oLUMLky1DOa9eRu3sp0FdQDEzQlnF/h1L4AK1MOkX1vS+fLgOvBo5LRU1
fLPUZQ7FKrDXC6nl2ldvEtljHWstGBmqv25aEvAA+yrrplCh/kYvSBjvZibz9Obbwx4yqS77
/NHN1iyZyVP2s52B2BLdvo4yhzk6nRk8S/8zHaUUkBUrrvijPDaGK5FNVSaioGvkC7IKioIT
KffYLtT9XuirKrHlh3VzkazG46pAVwIDAQABo4IBuDCCAbQwgYoGCCsGAQUFBwEBBH4wfDAt
BggrBgEFBQcwAYYhaHR0cDovL29jc3AudHJ1c3QudGVsaWFzb25lcmEuY29tMEsGCCsGAQUF
BzAChj9odHRwOi8vcmVwb3NpdG9yeS50cnVzdC50ZWxpYXNvbmVyYS5jb20vdGVsaWFzb25l
cmFyb290Y2F2MS5jZXIwEgYDVR0TAQH/BAgwBgEB/wIBADBVBgNVHSAETjBMMEoGDCsGAQQB
gg8CAwEBAjA6MDgGCCsGAQUFBwIBFixodHRwczovL3JlcG9zaXRvcnkudHJ1c3QudGVsaWFz
b25lcmEuY29tL0NQUzBLBgNVHR8ERDBCMECgPqA8hjpodHRwOi8vY3JsLTMudHJ1c3QudGVs
aWFzb25lcmEuY29tL3RlbGlhc29uZXJhcm9vdGNhdjEuY3JsMB0GA1UdJQQWMBQGCCsGAQUF
BwMCBggrBgEFBQcDBDAOBgNVHQ8BAf8EBAMCAQYwHQYDVR0OBBYEFBx7GZ6XnHasID3Y3OOR
auPbLaZTMB8GA1UdIwQYMBaAFPCPWTgAs/WPmpYM1ev6e6oX6BMSMA0GCSqGSIb3DQEBCwUA
A4ICAQBQWGvx1Yw7tC6rV0PIjKfDyxaanIX+NZLEGOkdQLKGW2gVLtDUJQEPRs5QtaZiObNH
CZ7mmSNMVek4lkt/0dqfVIFutVw/QkyFGwC99ZmNwXSX9z+OoMyoEBHGvw5RY6vRlZrj0uKv
dASzYL4KMaB7m3NwurNDmmNbG52suRIZ76wBOEOddRZcZiTy50ZkBqYnnl2t3D3oBX2NZCQy
sshUcqRdUbkS13HTCIChMuTV9W0tzPXUOJoJlJlU9nd91IikhGEOrPwfixWms+C8sF0r9qN1
uJGx6ELPOiFrLfNtcMNMMbAqRHwpSLxe3wcNkJGxv9T8LswLi1UrRIQ85AKjqzBnLSsjRGgb
MgJ+xKtngmvEA155JmoKfUD7DRbP6Kp14/Y9XFbR/WuDj84bYNKXe4HdDc1P+UMYm16m2L6L
kIIoRlx0A5mi+K7jewuGqzFKkaPNmJ0RLCi+4d4/47Zs3DC3PUNOxdOEEHf4kkdWOaSIuj3T
QYhNv+LsgF0uijiBmaz2zUFDa2bcIkKakDZfAFM4HoHz8K2BZRaHKWhd3dZua/tlSiqokUFX
2DxmHmZ1n5HM9OiaAIXP/Zo2x10j/Yb1mM3i0bqGahxlHYzl/QyEG/dujp3lewuVjCI0mPDk
ZGphvxyqp4Jo8qS94EnOqBvxOgftYug7OY9EKY+WkDGCAzswggM3AgEBMFswRzELMAkGA1UE
BhMCU0UxETAPBgNVBAoMCEVyaWNzc29uMSUwIwYDVQQDDBxFcmljc3NvbiBOTCBJbmRpdmlk
dWFsIENBIHYzAhBcf8Ki080s7KKjg2APnSBWMA0GCWCGSAFlAwQCAQUAoIIBsTAYBgkqhkiG
9w0BCQMxCwYJKoZIhvcNAQcBMBwGCSqGSIb3DQEJBTEPFw0xODAyMjYxOTQyMDVaMC8GCSqG
SIb3DQEJBDEiBCBN8IyEO7tpWImsgzsWdAqp4byWcGHKuk0UZUbSECtanDBqBgkrBgEEAYI3
EAQxXTBbMEcxCzAJBgNVBAYTAlNFMREwDwYDVQQKDAhFcmljc3NvbjElMCMGA1UEAwwcRXJp
Y3Nzb24gTkwgSW5kaXZpZHVhbCBDQSB2MwIQXH/CotPNLOyio4NgD50gVjBsBgkqhkiG9w0B
CQ8xXzBdMAsGCWCGSAFlAwQBKjALBglghkgBZQMEAQIwCgYIKoZIhvcNAwcwDgYIKoZIhvcN
AwICAgCAMA0GCCqGSIb3DQMCAgFAMAcGBSsOAwIHMA0GCCqGSIb3DQMCAgEoMGwGCyqGSIb3
DQEJEAILMV2gWzBHMQswCQYDVQQGEwJTRTERMA8GA1UECgwIRXJpY3Nzb24xJTAjBgNVBAMM
HEVyaWNzc29uIE5MIEluZGl2aWR1YWwgQ0EgdjMCEFx/wqLTzSzsoqODYA+dIFYwDQYJKoZI
hvcNAQEBBQAEggEAaa3CTZEBV4A3jRcEDT/FKWkyTD5UuQfBq4dTdbIUNnF3zFCOJ92Bj4G7
LxAD+iguGC2SgYz0yCA0tgJFRr0FVXs3UsDgF7qaMSDorLx3ZxLcGpn8K6TV/3R6iHHoVNlb
WYJKWSGowMCN+/0bDvqj/nfF+ZRNzr+Xhj5tvwf2KJmEoaJhz5n4KR3Mdf92ijnWUlCurLJX
AQqTfqynsKz+284jVb3F2INWOrjA5aBap9vYfQ5ZQlacPIgdiHUhNW4Nr4Wu1bkcTbbR0OcM
050+kNZ/Iu9gGmCCgQmMGizqVHsORDGanx10S08LP/nK7pzE4eXUWF9D5Rytx8TAWE9tugAA
AAAAAA==
--------------ms070204030708090905040601--

