Re: [mpls] on MIAD ADI requirement draft RE: Agenda for the MPLS Open DT 2021-10-14

"Bocci, Matthew (Nokia - GB)" <matthew.bocci@nokia.com> Mon, 18 October 2021 08:55 UTC

Return-Path: <matthew.bocci@nokia.com>
X-Original-To: mpls@ietfa.amsl.com
Delivered-To: mpls@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 74CA33A0A9B; Mon, 18 Oct 2021 01:55:33 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.252
X-Spam-Level:
X-Spam-Status: No, score=-2.252 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.452, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, HTML_MESSAGE=0.001, HTTPS_HTTP_MISMATCH=0.1, RCVD_IN_MSPIKE_H2=-0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=nokia.onmicrosoft.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id o2kRRk7w2WZX; Mon, 18 Oct 2021 01:55:27 -0700 (PDT)
Received: from EUR03-DB5-obe.outbound.protection.outlook.com (mail-eopbgr40100.outbound.protection.outlook.com [40.107.4.100]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 64CAA3A0A98; Mon, 18 Oct 2021 01:55:27 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=TiWfZZJJPihO2GhLwOhLXjWeXx9m8hgDyz0J+uqAc60A6GYdSCOZTIVF/J1OqEVY2/0quUmNY2aHzQUnD0uTeMXMDQ0+dOc+xmix+Eu+iovdF75fDBtf9nBFCQi8uKJBEKa+e1StB7SPTipGgsvsmQ8vsjUOlHejNNxf5EQhOgFtn6MFuFBRvBOB0k98/rbEqmrOJ8cP4PMr2xMXuaubFy1WlWCKTbpkejBRYnvkKJZYcefM629+6nqWOFq5/6pEc+VbxX9sP5k2AejkvApuxVwcYGhUB3j21kCCoZPRoeg3+xdG5GYWLQ+lMxlCCt8gPb5o6H4mcQ1E68UvZlTUmw==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=cckLpv5QW8Nt49hRMv+PuwqYiZs/TLLHISorJDlWNbg=; b=hrDL1N6qU5yEn7ZDqlKB/ju64Yeixbek/9YOV0mdLEIZifwyjpZV1Mcpwmv2a+fhKJa82bz/6KzI1h5+Uk6LeHuzq4xEWH9H8yN9LKXpeAT0ge8yKe1qXN2vIc4LQvXyWK04Mb/FUBXGbJQOE7xicvRXquU4YaeeE4aa+IKvwkCGkuZRErHDqG2Cd5HzjWkh8JGdAEjgFJuIKjjsFAgA20GTegTmyYAGZ4f7zssrdQVNJIMpyH9pc+wD24IeUXgUC7ScJ8cpuCY0Aey+ApKOP6CfRhWJwYzkbCr/DpSxhBBn1ict8siVzwtjRg3pIzMAa88drxFJuzHC/Hb01Uykjw==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=nokia.com; dmarc=pass action=none header.from=nokia.com; dkim=pass header.d=nokia.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=nokia.onmicrosoft.com; s=selector1-nokia-onmicrosoft-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=cckLpv5QW8Nt49hRMv+PuwqYiZs/TLLHISorJDlWNbg=; b=TrRkjH9u+wfOzbzqncMwOI3atfpna3KXOFHW708d4ZSQ6Ay57O0bCcieaPYGnWcrv7hyiAjwu3dcWnj8ulFN7Il2iz06FY9y2miRYjlX1yQ5R+bJPtI8PGYKb21SWd1QUzpU8Eyu3IZ6QLUFjSGvBLad6mdO/g/mHsVUttZrG3o=
Received: from VI1PR0701MB6991.eurprd07.prod.outlook.com (2603:10a6:800:17d::22) by VI1PR0701MB2414.eurprd07.prod.outlook.com (2603:10a6:800:65::19) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.4628.9; Mon, 18 Oct 2021 08:55:23 +0000
Received: from VI1PR0701MB6991.eurprd07.prod.outlook.com ([fe80::549:123e:6d6:514c]) by VI1PR0701MB6991.eurprd07.prod.outlook.com ([fe80::549:123e:6d6:514c%5]) with mapi id 15.20.4628.013; Mon, 18 Oct 2021 08:55:23 +0000
From: "Bocci, Matthew (Nokia - GB)" <matthew.bocci@nokia.com>
To: Haoyu Song <haoyu.song@futurewei.com>, Loa Andersson <loa@pi.nu>, "mpls@ietf.org" <mpls@ietf.org>
CC: "pals-chairs@ietf.org" <pals-chairs@ietf.org>, "mpls-chairs@ietf.org" <mpls-chairs@ietf.org>, DetNet Chairs <detnet-chairs@ietf.org>
Thread-Topic: on MIAD ADI requirement draft RE: [mpls] Agenda for the MPLS Open DT 2021-10-14
Thread-Index: AdfBJztNDN3PN1joSQiWvfq+gF5sdgApEMhK
Date: Mon, 18 Oct 2021 08:55:23 +0000
Message-ID: <DBAPR07MB6984AD1BF19BD11556B20AD3EBB99@DBAPR07MB6984.eurprd07.prod.outlook.com>
References: <BY3PR13MB478755C56CF5982C510B9E329AB89@BY3PR13MB4787.namprd13.prod.outlook.com>
In-Reply-To: <BY3PR13MB478755C56CF5982C510B9E329AB89@BY3PR13MB4787.namprd13.prod.outlook.com>
Accept-Language: en-GB, en-US
Content-Language: en-GB
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
authentication-results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=nokia.com;
x-ms-publictraffictype: Email
x-ms-office365-filtering-correlation-id: 25627200-f938-4ae1-2418-08d992150579
x-ms-traffictypediagnostic: VI1PR0701MB2414:
x-microsoft-antispam-prvs: <VI1PR0701MB241463CF836EF63FAA61CF3BEBBC9@VI1PR0701MB2414.eurprd07.prod.outlook.com>
x-ms-oob-tlc-oobclassifiers: OLM:10000;
x-ms-exchange-senderadcheck: 1
x-ms-exchange-antispam-relay: 0
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: teuzXKTtUawVLkforSFeZF/401yNRaIk/TFRAbJ/+Hzy5CYtbgIn/M17WaXksGy2lVqD62LPlPxpGsaCOvMaiRK14c6ZoURwbMySq+FJ3KvUIHAM67s9pfwwANQHpmkaGXI0VFDxrrqCja75pxDHMMjjMG3jBLwm4pwJCR0zIaacEdfknuTgZJhHigbLIkPi4GAwFjsM0YOwv7ZgHtfmhwh3+uVNMm/BHKRxo0GzMi0w8tzm/cawt4GF52M0xJWMytWMi3bxYgrmOoqiWu2MHwzWreHYxdkl1cJvQkMieqv2tIwkavbTPlWSF+MTM/3JIqcmnY+vzXRfylX3DFtPaqZ3en8TbjZlfP1AOWEsOhIcmoGSZwjAdoPUnaSe0x6s6obdj79O4mVCDVAr/PLef1VQ4aDFIH50RQGSqjHznJFgsgUlG/KIgjzw8wVIz3QjqzN5OyrfSf+bwYup4/Tdz/sL52RrP5nHK00EtiiQTiOFJjrYXx1D2H7tIjnSdARpLX1ynlW4dV9YhHuC+LxgCBX2rk7tLSoD2bX+7m7QUIb3YTmWd6uZgnYupIptDuzOxM40JS90tREpGKZtn6/ZEHLGFn1LtuvqA3cg0bJzYbMwEGG2ztv822zro/PAzQsToYLSqOgJqQU28ur4N+FU5vqUgOheQtQes8N2BkEvzKHEh4OXQzLvYg0AL7Mbg2RMdhYMIJvlnfk1Usp5Vhwy7LRrii+OHHGRNAggjlNwPJGc4LYFM3NALkSxtcj94WTXVvvBTlhgs8HJNSD23tuLW151vrCgOVyxMbADypMVRBlLxXsB8aaUV+O/A7WWkkTfLHBaD5m5UIejLKZS1rIkGQ==
x-forefront-antispam-report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:VI1PR0701MB6991.eurprd07.prod.outlook.com; PTR:; CAT:NONE; SFS:(4636009)(366004)(26005)(186003)(53546011)(5660300002)(38100700002)(54906003)(166002)(110136005)(6506007)(966005)(8676002)(8936002)(33656002)(122000001)(86362001)(52536014)(82960400001)(2906002)(38070700005)(91956017)(508600001)(66446008)(64756008)(6512007)(71200400001)(83380400001)(6486002)(66574015)(9686003)(316002)(66476007)(76116006)(66556008)(4326008)(4001150100001)(66946007); DIR:OUT; SFP:1102;
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: BXS03pkFq2ufc0X9EoZd+qWP59N4w3BGozTSmLDNVbaytjx3/Swm0CfMpACXPiuU/7iwj5D0BHZh0dUZRukM9fmNig/rY2TbytWZhgnfONYD1qM7wRw2CUspEW6keGcLcumySnzqDAQKXSQRBtKC5Lq+SjaIsrxyq9h9qn+UnQRdGGhxAIzi/Yyg/Xk9UGwFOdN2pDZzRgLOXTR1oNJCyL/Huo+oOIsRBNHyf7n/QOuHhUADRtzEBDD+1t4AftCcIFgCr857EP1/dxiJW8J6w1vj+MESDY+xXtqMgLxRmlvDJO3jhKoRrnbNQ2GFF3XaQY4Y/WZdbcrfdRGdqXMFxEKvFt3RHTiTJMFViK9D2qal2nsNFOYFgjsnXT56x1unjDd+9Q6JRsk9LAnJSDBmUTZbdiyzI0mETR8Y81qB/nv2ekaZxFRfnuPpaeykDXllkVBzs15XEzjEcQtLI31cKV7+zL/pRfHjEUvnxTS15t+n355GRxp+e4eAMAf+szsN6oFO1F3g5aMFEXX6xGVt1nFF0E5KQiBs9lz0eLzDu2pEzkp9IwBrqVPrQtut7bR45k57aJSpuZCYn8DBTnMy4NtGzBOSE0XmbwWtsD6mCiSphj8WGuvM27bzEapf3r7ES3H4zlpLwcz7Mw6jLK6PHnQQT9SmrQDHgeSzYnuNGP9NaG5g07YlITViiRuW094ya5LhJlp4f5uF9yGaWTxPI3Z7g/b7atDEsigX70rd3WDLk5PS1NNuAHJlKE36keqhPGKPpoYfH9ynm+xxeAwAwttrQLhz86/G/WwLARhebaOlV2JJFRyfazpwXKhgmYvZoV3WDnvqJxAy0n9zmoff/ZEybYFN1725UuxZDPj96Tb2ddepbULprZnqa23GLZF7pAiPOAWXBd7r16sFJlbZGTWhUOqipCzm8Lm8JaQ346pn5NdgBT4P0aTaF5cL11RGXhaD/EogM/0MiF1EjKWA22stJGCosYlErjLLT1pZ7Sdb+J4iZNcPi4sm+P6UdMTtEFMRL0dhNwrk8QVkS7ASJOUn2hSajVpDAZDYFSBl6Yop+xAwnVQH8ZRo1hdcYNrPZrJx7XdwrdrAB08KHNRk2mkR44oFGL//5LjkCGgYlY6fnTS5E1NJmOIxWjVnEIH269NudiunDyAcRDiWndON9YzviNIY2x6vA4XHkBGhPxLpFlys8IN2xfpLdyjpKq59PWZgsxSTYeGtKKeGo5WMGYABbKAOcqrfwcSNfcrZJtxT/EGJ03eRzD4rxQE7rozLuU8slOEd7fqp1mCuXABFLcule4FfF1NxQHormNcFOOKzh79XUl7+ZtFW4OW6px+g+DDbpt1UApOiXk1+VVWf3TD7egx/4nKE5IqJxS+q5/r/io94yPVmQA00yxT3SUNsa1zPSLjLegGItkDW6m8Na8nJLafFpeQYeZePMeof3gX3U+XIDCuPLGOixw1LYovB+bUvcU7C31awcVoGL9DGkZpKcGLQwI2Uj868o+ALlUItywrBv5yPyERNPrtR2sR0X+7qZMAsKgkNv0f83iKAGJtrQZST4GDjiUJCfgYolc9MVrH1o74Y4Z8aoDdXAP6nmDf/xe7G5Tzjlzj88kI4yDvYWUAZYS7MsjfyJxR2W7g=
Content-Type: multipart/alternative; boundary="_000_DBAPR07MB6984AD1BF19BD11556B20AD3EBB99DBAPR07MB6984eurp_"
MIME-Version: 1.0
X-OriginatorOrg: nokia.com
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: VI1PR0701MB6991.eurprd07.prod.outlook.com
X-MS-Exchange-CrossTenant-Network-Message-Id: 25627200-f938-4ae1-2418-08d992150579
X-MS-Exchange-CrossTenant-originalarrivaltime: 18 Oct 2021 08:55:23.2981 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 5d471751-9675-428d-917b-70f44f9630b0
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: cVpaLGeK6cPlCM/7dBzQvyIXfw9Her/riuvCb6f7fzgHZ9cRhJc5NJu/7hBm7zUE/Yda2x10ljf93nGCP6Xh6g==
X-MS-Exchange-Transport-CrossTenantHeadersStamped: VI1PR0701MB2414
Archived-At: <https://mailarchive.ietf.org/arch/msg/mpls/d9fne9cD5HL_J9K_fGxTFswqIz4>
Subject: Re: [mpls] on MIAD ADI requirement draft RE: Agenda for the MPLS Open DT 2021-10-14
X-BeenThere: mpls@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Multi-Protocol Label Switching WG <mpls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/mpls>, <mailto:mpls-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/mpls/>
List-Post: <mailto:mpls@ietf.org>
List-Help: <mailto:mpls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/mpls>, <mailto:mpls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 18 Oct 2021 08:55:35 -0000

Hi Haoyu

Thank you for your comments.

Please see below.

Matthew

From: Haoyu Song <haoyu.song@futurewei.com>
Date: Thursday, 14 October 2021 at 19:15
To: Bocci, Matthew (Nokia - GB) <matthew.bocci@nokia.com>, Loa Andersson <loa@pi.nu>, mpls@ietf.org <mpls@ietf.org>
Cc: pals-chairs@ietf.org <pals-chairs@ietf.org>, mpls-chairs@ietf.org <mpls-chairs@ietf.org>, DetNet Chairs <detnet-chairs@ietf.org>
Subject: on MIAD ADI requirement draft RE: [mpls] Agenda for the MPLS Open DT 2021-10-14
Hi Matthew and Stewart,

Thank you for publishing the draft! This is a great start for further discussion. Below are some of my questions after a quick review. Thanks!


  1.  “Neither an ADI or ancilliary data must be delivered to a node that is not capable of processing it.”
I guess this sentence means “An ADI or ancillary data must not be …”. If so, what does the “node” mean? If it can be a network node (e.g., P router), I think it’s possible for it to be unaware of the ADI/AD but still can forward the packet. Any clarification here?


MB> Yes, agreed. What we meant here was, assuming we have some sort of exception mechanism for ancillary data that causes the data to be inspected, for example an SPL, that exception must only be targeted to occur at LSRs that are capable of processing the ancillary data. i.e. we must be sure it can recognize the ADI and process it rather than drop or mis-route the packet.


  1.  “The mechanism to indicate that Ancilliary Data is present MUST operate in the context of the top of stack LSE.”
Do you mean the ADI must be top of stack label?

MB> This is something we need a discussion on but, in essence, what we are saying is that it must be consistent with the MPLS architecture. An LSR just does a swap of the top label, or a pop and forward, but unless it is doing something like scanning the stack looking for an ELI it doesn’t change the fundamentals of MPLS forwarding behaviour based on labels below the top of stack. Even in the ELI case, it still forwards to an ECMP next hop where that top label is valid. Besides, the ADI is for ancillary data so it is subordinate to the basic MPLS forwarding decision.



  1.  “ADIs can only be inserted at LERs, …”
Do we formally decide that we’ll never allow an LSR to initiate or terminate a network function/AD? If so, what makes we believe this must be limited to LER?

MB> Well, it could terminate it similar to what we do with GAL when TTL expires, but if it was to insert it in an LSP wouldn’ it effectively require a pair of back-to-back LERs (although I suppose it is possible that you could have a ‘swap-to-ADI’ function if an ADI at the top of stack is all you need)?


  1.  ” A solition must be provided to verify the authenticity of ancillary data processed to LSRs. “
Do you mean “solution …. processed by”? Not sure we need this to be a “must”, otherwise this may create unbearable burden to the system.

MB> This is only a requirement on the development work, not on an implementation.


  1.  “The design of the ADIs and ancillary data must not expose confidential information to the LSRs.”
What are considered “confidential information”? Any example or definition? I think this needs to be clarified.

MB> I think we need to continue to maintain the existing principles of separation /isolation between the underlying MPLS network and overlay. One example might be if we encode ancillary data in the stack then that might be based on an IP SA/DA in the payload, but the mechanism shouldn’t require us to encode the actual SA/DA in the stack but rather some anonymized version of it that only achieves what we want to achieve for the network function. I think this is solution-specific, though, and any solution drafts need to have security considerations text that addresses these concerns.

Best regards,
Haoyu

From: mpls <mpls-bounces@ietf.org> On Behalf Of Bocci, Matthew (Nokia - GB)
Sent: Thursday, October 14, 2021 5:45 AM
To: Loa Andersson <loa@pi.nu>; mpls@ietf.org
Cc: pals-chairs@ietf.org; mpls-chairs@ietf.org; DetNet Chairs <detnet-chairs@ietf.org>
Subject: Re: [mpls] Agenda for the MPLS Open DT 2021-10-14

Loa

I have posted a first draft for the MIAD requirements here.

draft-bocci-mpls-miad-adi-requirements-00 - Requirements for MPLS Label Stack Indicators for Ancillary Data (ietf.org)<https://nam11.safelinks.protection.outlook.com/?url=https%3A%2F%2Fdatatracker.ietf.org%2Fdoc%2Fdraft-bocci-mpls-miad-adi-requirements%2F&data=04%7C01%7Chaoyu.song%40futurewei.com%7Cb6c20ceda8734c7bb4ca08d98f108617%7C0fee8ff2a3b240189c753a1d5591fedc%7C1%7C1%7C637698123407271600%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&sdata=GinuVkgLbjoz0M7rulzo4C%2BvPRMpP8yERqhQ6EeI8R8%3D&reserved=0>

Maybe we can take a look during the Requirements slot on the Open DT agenda.

Matthew

From: mpls <mpls-bounces@ietf.org<mailto:mpls-bounces@ietf.org>> on behalf of Loa Andersson <loa@pi.nu<mailto:loa@pi.nu>>
Date: Wednesday, 13 October 2021 at 10:12
To: mpls@ietf.org<mailto:mpls@ietf.org> <mpls@ietf.org<mailto:mpls@ietf.org>>
Cc: pals-chairs@ietf.org<mailto:pals-chairs@ietf.org> <pals-chairs@ietf.org<mailto:pals-chairs@ietf.org>>, mpls-chairs@ietf.org<mailto:mpls-chairs@ietf.org> <mpls-chairs@ietf.org<mailto:mpls-chairs@ietf.org>>, DetNet Chairs <detnet-chairs@ietf.org<mailto:detnet-chairs@ietf.org>>
Subject: [mpls] Agenda for the MPLS Open DT 2021-10-14
MPLS Open DT,

I have posted the agenda for tomorrow:

https://trac.ietf.org/trac/mpls/wiki/2021-10-14-agenda<https://nam11.safelinks.protection.outlook.com/?url=https%3A%2F%2Ftrac.ietf.org%2Ftrac%2Fmpls%2Fwiki%2F2021-10-14-agenda&data=04%7C01%7Chaoyu.song%40futurewei.com%7Cb6c20ceda8734c7bb4ca08d98f108617%7C0fee8ff2a3b240189c753a1d5591fedc%7C1%7C1%7C637698123407271600%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&sdata=ZigZ8bL%2BhJhcnxx2VFTk6ym7YsZ%2BGkRNizELJdCGtrM%3D&reserved=0>

/Loa


--

Loa Andersson                        email: loa@pi.nu<mailto:loa@pi.nu>
Senior MPLS Expert                          loa.pi.nu@gmail.com<mailto:loa.pi.nu@gmail.com>
Bronze Dragon Consulting             phone: +46 739 81 21 64

_______________________________________________
mpls mailing list
mpls@ietf.org<mailto:mpls@ietf.org>
https://www.ietf.org/mailman/listinfo/mpls<https://nam11.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.ietf.org%2Fmailman%2Flistinfo%2Fmpls&data=04%7C01%7Chaoyu.song%40futurewei.com%7Cb6c20ceda8734c7bb4ca08d98f108617%7C0fee8ff2a3b240189c753a1d5591fedc%7C1%7C1%7C637698123407281557%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&sdata=5572UBJD4YqBJsDmTncYB9K5XO%2FI15WaNxilNlwSW1Q%3D&reserved=0>