[OAUTH-WG] Re: Call for adoption for RFC8725bis

Michael Jones <michael_b_jones@hotmail.com> Mon, 01 December 2025 15:33 UTC

Return-Path: <michael_b_jones@hotmail.com>
X-Original-To: oauth@mail2.ietf.org
Delivered-To: oauth@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 56AD793447EE for <oauth@mail2.ietf.org>; Mon, 1 Dec 2025 07:33:06 -0800 (PST)
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -0.222
X-Spam-Level:
X-Spam-Status: No, score=-0.222 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FORGED_HOTMAIL_RCVD2=0.874, FREEMAIL_FROM=0.001, FREEMAIL_REPLY=1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=0.001, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, RCVD_IN_VALIDITY_SAFE_BLOCKED=0.001, SPF_PASS=-0.001] autolearn=no autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=hotmail.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id hr4W-uB86RAw for <oauth@mail2.ietf.org>; Mon, 1 Dec 2025 07:33:05 -0800 (PST)
Received: from DM1PR04CU001.outbound.protection.outlook.com (mail-centralusazolkn19010018.outbound.protection.outlook.com [52.103.13.18]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange ECDHE (P-384) server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 7623193447E2 for <oauth@ietf.org>; Mon, 1 Dec 2025 07:33:05 -0800 (PST)
ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=AmoFDg71fz1A9CQv2cUFfQbDi8NtErFC3yxYcXav0QiwyiHzIF0k9zHr65jyd5UyGQXtm9gY2uqrnTDGDD/+rWICoFbVHEi/NQklEogM+YfRoN/ufr+w4uDVdtTzlNYqHRgWW2zTmCoseyBM9vDPOSwgLrks+NF7rB0yGeLkQz1UJlBsHNoloXsLTlJcumRE0SgtpljoaQ+saM0Lg55dT2lp56A2hbsudyP4UJ0uuaY24NCqYPDJWsgdDismHE1YoRHYWvciJzz99tOs9hiBZ9qg0H+stoZRvJcYGuZGDvV3k+4gNQXaixPZ9P1iDcSUXt5HBscIKqb2CF3G1IpFWQ==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=jnAhHE9mEmZfYojDjoGxjcBJ0uTFNSIyCp5z4dOtrew=; b=yIpfoITaSlo/kItlpQVL2oVXkRuQC7oKjLdxEKiE43LF3kQSkuwgrvy44HAg6UyGyoj61tWoBjgKXVCPBLm/q2+w23J+99i1xvlTMknUuGnhowjH8zNOZ3RJv/ngDsynDHDsGU4GvL0CYDcgJ85b4Znf0Oe+SiXsFu66Ke+DcgMdfi+8sumV2x4E667fXWFuPFMs2lLwIi6unzR9BP1VgSFyyLUm7l5z+zLYzYcQ+5NmEDI4mOh62iQla831mFDTZxsJ7dnJhX9LJU3UQ2hEgVriTPw4LRP/dCXRxQZXqj+QsayRRFCrjDQmCqW/t0PZCjRfXG7u84Tb5BBOQj9ucA==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=none; dmarc=none; dkim=none; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=hotmail.com; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=jnAhHE9mEmZfYojDjoGxjcBJ0uTFNSIyCp5z4dOtrew=; b=PYhsh/2In7t/K4R1zHpu/Ej5PaJ1Epj9xxvMrRa2ntgdLCWVrxEewDD9IGrvjl25GQqftxExAAS6RoXAoBL0spjZyWKqfXzOOquzbSyYBe4zJuJELOvlmuEyLVaOEAEBIhovzRKGUip3pRDMBSPi8kT2FnN1TKRO486sU5o35ay7K9PZtQrVs+CM8MhyZEp8c5xZli4SdZoLUJ08edvqudP3ZuznXo9kFENMMy91Gfb8gPfVLzVrN+4MGIIEjOi0evZ3cjhincXeDGML3+Ftd3M7NvNC+oXGBHM5HS5KgGMm6L5fC3sWjRPNyNZJChUtsaDPetWqu2Ne/V8YXmYppA==
Received: from MW2PR12MB2508.namprd12.prod.outlook.com (2603:10b6:907:9::23) by MN2PR12MB4472.namprd12.prod.outlook.com (2603:10b6:208:267::11) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.9366.17; Mon, 1 Dec 2025 15:32:53 +0000
Received: from MW2PR12MB2508.namprd12.prod.outlook.com ([fe80::2a25:1f86:facd:ef9f]) by MW2PR12MB2508.namprd12.prod.outlook.com ([fe80::2a25:1f86:facd:ef9f%6]) with mapi id 15.20.9366.012; Mon, 1 Dec 2025 15:32:53 +0000
From: Michael Jones <michael_b_jones@hotmail.com>
To: Brian Campbell <bcampbell=40pingidentity.com@dmarc.ietf.org>, Rifaat Shekh-Yusef <rifaat.s.ietf@gmail.com>
Thread-Topic: [OAUTH-WG] Re: Call for adoption for RFC8725bis
Thread-Index: AQHcCK0llguLbwfTlUKWq4XxEEcnybToaQUAgCUrynA=
Date: Mon, 01 Dec 2025 15:32:52 +0000
Message-ID: <MW2PR12MB2508FF65A2CD11F5F6035C5AB7DBA@MW2PR12MB2508.namprd12.prod.outlook.com>
References: <CADNypP-Ve=+6qyjeSEHhs+AFK14vGA35PrHGyjs3DmNHysRVtg@mail.gmail.com> <CA+k3eCT9M4PqwAEw+1fhW8B+wb++O6VWa1gpuadZQnkX1jpSDA@mail.gmail.com> <CA+k3eCR2yDy_i9HjAk8EUUaq=KDeR8hxmPs7iiNGxe5r1nPdVw@mail.gmail.com>
In-Reply-To: <CA+k3eCR2yDy_i9HjAk8EUUaq=KDeR8hxmPs7iiNGxe5r1nPdVw@mail.gmail.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-ms-publictraffictype: Email
x-ms-traffictypediagnostic: MW2PR12MB2508:EE_|MN2PR12MB4472:EE_
x-ms-office365-filtering-correlation-id: 737a70d0-b989-4688-c50e-08de30eee4b9
x-ms-exchange-slblob-mailprops: Om8TgR6f4EAHrybcsZlnerrpy0z03AC+N5loTOYW1PidLlQw5HcHUHLNLFSBerdCCnzVSVEl0mLsW4rgZD9tOBaQZt/MI8wqjEm3S0/uvzYN+I5gp2jx/IEN31hz7faMKoS3iFwbzi64SKvZVGPYhY7gYsP9T/tqIEDHLG2eEX8mQz5li6hq4MitauK6qQNEYUrMJKnyEfeQaRAWdH/QXn9ryIEznzFHlPw7bMoeltDR2xZBinmm5VnL2PMmFQXEqR6+szeb3xhdjxmqJwncUJ2SBVuVg/jdZxANqX45XExE1NjS92N9kG8qWeM0FsNsMxt1RgDsrwGWXlqNS/Kz0uXuXqlffAkEsLEu2XR30zDiBtOUsyzN4si8pelMUcTEUMxyVHOY1qEfnNyd+5jIuu23F0QqMmQSS9/2IFWLYLsDS/rwJz+HZTiVP9vss86EpJXlCCDLVsYhzfKCqim8ESXsU3nyEyxZDzHFP62if9UC4DENToyAD4UBe3zIb60J4hHkCHDAeHl2qmIyA/79+Aw4jT4ZLOh6iNfZFLZX69GzjYkMawnfv5oK96NOQIprzCHm235MjAj6rkLgs49Ri0QNkza4xwEniqLfNYH7n6iR+kcEj1Syh5joILmaMKbKQE054vt6L5oI0sCrzR4v701cNfiSbxzOWkNAMlD1JysykenCkVcEK3hPaWg2mnvvZZ+dDU46XHYFrwF+K8byEHIgwqP5k30r7DZX/JZRENI0KnCEEIB2B70xmNkq7n9R2Z1XXbyRvmJR1ZKLRc+dkUE/9NF0F+cJdKekIOZLEEsuf6ezC7k0QhWVIwDB5Fx/SgckuisCIZv14lcjKuG8dEcLPDZXvS8E
x-microsoft-antispam: BCL:0;ARA:14566002|461199028|19110799012|8062599012|12050799012|13091999003|15080799012|9400799040|31061999003|8060799015|56899033|1602099012|52005399003|40105399003|4302099013|440099028|3412199025|10035399007|102099032|30101999003;
x-microsoft-antispam-message-info: QITbRqWbw1FNxdQygHFw354nGL2O/Jefq2M83LJAX9qwHoQRcHxLMZmub8W1JGVU0kiUTGJH68WGaJIpp4EbnHgCJiWkQwp1m2t3uxhkoHHOcfMT+CBK7s3gk474tSw+cLab/7ZyS0xsvK9Pi5MIgRz7kBemR+WXB+VLkiHK+OlUX8mQ8AV3ILW/t0fskSdyxFJ2Q8grpuNOc4TgS3pIWz6OhNZT0dkqH4H4El9hQ/ulWVpqFO/lKuIwVTdmtHW8zyWiDHDRrW8q6ZD6wYiLRXmWOiomMwXkf6Nxz7OK5Wtf+cBwmKOwmDEDAlmyOceLfEfqLe3rQyQxuAEq/OKPNJTT0arOds7btsdd+uUrtlaxogh6Y/BrmWn8uDVmaJI3/JcCqddHeRO7JuBRDCz7fLKWS8QzHd9akrg3/sL6o+Jn2VyZ3jfoi+I5263c8m+p6AlsnfzS30OTrmDZgjr+j2erAAF36YPhQ8zPd4bkBGtuH1pPrCSnswvfIRL/NiD1Fd4lGNVAIgwPhpkL5z1HS6chqVb0PVdvfxRxpDbrgZxY6HjyZcUvA+0VlmsijANA9YA0/NU+NFuNNen5m/Nvfe8szrg7Xqb8dE+Z5a3Y9zkQTReT2zT7CxKk21z1xKN3wfYm3N7Dpi0be4kGV1LhpWnu6IKq42ysAFWbFaIboiJwzICZRF15ZTNTUMRS+QYu43UYT0KrX92H3K4EmPfEFRD2D3G/yWAA48iNR4Ts3M+isVjbSHappIsGEDCpXnAePiFeyy0Ye8luL2c+f1hVA6cvrDeL1taU0+mTBZNks8rqTdFt1oVpKA7tZBADB0A1QDC7k4F9s14Xp/EBnvuMcZjOIYlBKiOmE5dS0wXCHtp6rFmALg0PZc7xbmRa96ci1yJywaimqmQJEoQOovY/NgxkSbd0CBswoYZqyE3kCrJc4csyUdeP3zFwIKndAFodcYpFvGUklGg5qb0JSJfEKhhuv8hH3XdvyB5o26A8t4ZGw/YxlB/eJR83okIdVrarzO+/VCDVCyZjA/MhBo68ZOvDXUsIByoX6SAjKX4RBQ25XwxDPXcygZ0NqiVNQrF2lzAJnPxSOvKro1zcsTr+dNrkNrpr/lu5VEagITyBnxwOR+acTQtQ5hvEL0a271lshFFa9iihsyXTkQZxxvE4ySzKfPAJbgLGpKQ+5c0vsPo88UHIdAbvmrYpmxJKNFCLapBYo7s1ZRKo1s7EEKigB869Q/zJqZns4O6B3cqC+i9k003yd/afk5PDjcPcOJ3jqdhT44Hh0cKC83+bhhfcp9zi5GHAysghaMph8lY7+sSZmtMS6bvvQYfj9gs/MpMkGG4b3FrclYZCnQG82mcLjrq7BMqpQw+0NBEn9bALA2X9MTHqpVKnuGGeHs35ge2RqNqfZi0odAQ1TgDbc/AiHPfucK3huHSufB7s5lgSir6t7smg2z5j90gB4CNFIBGk
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: tTERz5GXe8U+fj7q5c79w7vJCi4uMK+mBJORyIndmDFdGHwVgkzj+EKhJRha3w+QcvvdZLSYKV4ZTYqWQ2VtVamkEq02BMNBQktRFfCoemGLYUQRkOiDjPN+2CWc47Ls6kysvMIoaJGkdQPFY7Fyd+NEfslOoG5WrYtt6YWrCSjLLc8FgsfMrdd34bWJcOHzctzLdh3/4n8cTAOJBdc8LIvBHf/cor600JWA6x5vEkEAap1TW82HwnKFDSrACqgJtqMyfSa8V5R1wTzi2uz6S65jTvAhnWBvcqPBYMTbckJjIjmqcZDwvyzdwKkjWQ2cYmY7VAeXwp8fKXpTJbUKDnAuGRnR4bA3zWc92q84fn9NyRQi2hi7Fs4EdbgHp0VTiQliSYPCXcAY71GZciAa/+bBFwFe1NpG0kHxILxgScqaujU2xNJwugv5dW6DBKnaqlJ3dB63UJEUxCOJZzD15i+MXBTO8zZZcuRToalRKDs51zc0rDNQ5t6m69RGPP67aT9/WSqawv+rpBiK7wwrk5V6WH9rosX2rbJwOkFqF8CxWueAoL7ocKAfg59LTXS2xQ+tzfhicShzKkkEXpiI6cWhBzlPY/To5urf9Gw7EU48k3+PJv8iar8ggvXmb4mWwMS4/oth1EfqVYGffnT0snuq6vYryHpz15Kb+jzac7LsGF2CKO+2wPUV3MYBsvOyl0Q0zxZo3JrOius+ymKAKyIrRe3Z4A0L7ukBs1s2QWRTtrsWTjuLeISw3U+Sodb86YqZkS0h/8LgNvqCTXMly9v7UxE9/AmQuemAubOQVKuRim9kz5HST2/3Cm+3OUaOu1wli8EQfJ4M+zl8ArEnDT7JvJ95ozXlw2wxLvxAxUGDd5H/8NL+Aifc+2N/I9kltVJunk/tvck4ZLSTkMJDQvv9Sxeu7JLs4HnHDDY2CpQ7laF88y7ahQRjHUIjNsE/dHtdJm8hfuAw9OQgFSKqNSrWuNXcQHG/loAEXW2hg0Bst9/VpkRjdfBfIF8hRJNYDy7yJdzej4I0wyWqzf1lponyAi/9cn6OF0eGA7f3Y9p3ruKhAyoSGoh+F+6heJ4dibhSjF4ZSQiSki8ioH5USeXPOu/09X4vlz6R+kmW+FTZliS4xcYHtVXQ2HRHNGpUSwYJHC926gRN25Ndg6PQHqddTE6mOA5VoKdajd2hIHppbFqg6SuiAeJfuu+ruhT9U7Klxt/Q9jnCZOIwVeU72TLx7Rwx/mOuWpqqibxRMdRdBREr8Dn8sBiDY87ZMRyC
Content-Type: multipart/alternative; boundary="_000_MW2PR12MB2508FF65A2CD11F5F6035C5AB7DBAMW2PR12MB2508namp_"
MIME-Version: 1.0
X-OriginatorOrg: sct-15-20-8534-20-msonline-outlook-ecb43.templateTenant
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: MW2PR12MB2508.namprd12.prod.outlook.com
X-MS-Exchange-CrossTenant-RMS-PersistedConsumerOrg: 00000000-0000-0000-0000-000000000000
X-MS-Exchange-CrossTenant-Network-Message-Id: 737a70d0-b989-4688-c50e-08de30eee4b9
X-MS-Exchange-CrossTenant-originalarrivaltime: 01 Dec 2025 15:32:53.0296 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 84df9e7f-e9f6-40af-b435-aaaaaaaaaaaa
X-MS-Exchange-CrossTenant-rms-persistedconsumerorg: 00000000-0000-0000-0000-000000000000
X-MS-Exchange-Transport-CrossTenantHeadersStamped: MN2PR12MB4472
Message-ID-Hash: LGTVGVS2LCLMCEZHPIYVC4NC4AIJBVRX
X-Message-ID-Hash: LGTVGVS2LCLMCEZHPIYVC4NC4AIJBVRX
X-MailFrom: michael_b_jones@hotmail.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-oauth.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: oauth <oauth@ietf.org>
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [OAUTH-WG] Re: Call for adoption for RFC8725bis
List-Id: OAUTH WG <oauth.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/oauth/fPW14HPAi3CwIqczP6sOKJIU-Do>
List-Archive: <https://mailarchive.ietf.org/arch/browse/oauth>
List-Help: <mailto:oauth-request@ietf.org?subject=help>
List-Owner: <mailto:oauth-owner@ietf.org>
List-Post: <mailto:oauth@ietf.org>
List-Subscribe: <mailto:oauth-join@ietf.org>
List-Unsubscribe: <mailto:oauth-leave@ietf.org>

Hi Brian,

Your message was sent about the same time as I was sending the “Next steps for draft-ietf-oauth-rfc8725bis<https://mailarchive.ietf.org/arch/msg/oauth/pz9Frw1P5t8nndEkPhVC3ApkZ8c/>” message summarizing what we’d achieved to date with the RFC8725bis draft.  Now that working group last call has started, I wanted to also explicitly reply to your message saying what the authors have done as a result of your feedback, which we appreciate.

I’ll reply to the rest of the points in your note inline below, with my responses prefixed by “Mike>”.

From: Brian Campbell <bcampbell=40pingidentity.com@dmarc.ietf.org>
Sent: Friday, November 7, 2025 3:21 PM
To: Rifaat Shekh-Yusef <rifaat.s.ietf@gmail.com>
Cc: oauth <oauth@ietf.org>
Subject: [OAUTH-WG] Re: Call for adoption for RFC8725bis

The acknowledgements updates did happen and a changes from RFC8725 part was added but I don't believe anything in the first paragraph has been addressed or acknowledged.

On Fri, Aug 8, 2025 at 5:39 PM Brian Campbell <bcampbell@pingidentity.com<mailto:bcampbell@pingidentity.com>> wrote:
As I said during the meeting, I am supportive of doing this work but do hope the authors have appetite for what they might be signing up for. Aaron's review points to some of the work needed.

Mike> Aaron’s review comments were addressed in draft-ietf-oauth-rfc8725bis-02 in a PR that he approved.

The https://datatracker.ietf.org/doc/draft-ietf-jose-deprecate-none-rsa15/ work should almost certainly be referred to.

Mike> First, I’ll observe that RFC 8725 already included substantial treatment of “alg”: “none”, which was retained in this draft, so I believe this topic is already well covered in the specification.  Next, I’ll note that the draft you cite has not reached WGLC and is still subject to change.  As I wrote in my next steps message “There’s precedent in OAuth for not holding up publishing a BCP because other developments may update the BCP later.  In particular, we decided not to hold the OAuth Security BCP [RFC 9700] until we’d addressed already known vulnerabilities, including the one being addressed in rfc7523bis.  Our logic was that it is better to publish the BCP in a timely fashion to get a set of useful information out to people and that the BCP will be updated when the mitigations for additional vulnerabilities are settled.  As an individual I’ll say that I think that precedent should also apply here.”

I believe the current text around compression in JWE is a bit overreaching and lacking in subtlety about when it's reasonable to use.

Mike> As asked on the OAuth office hours call on Monday, November 17, 2025, are there new JWT best practices that have emerged on this topic since RFC 8725 was published that you can cite that you believe should be included in the draft, Brian?  If so, please provide proposed text.

I'm not terribly thrilled about the way explicit typing has worked in practice but I'm admittedly not sure how it could be improved at this point. I'm sure there's more once the box is opened.

Mike> As asked on the OAuth office hours call on Monday, November 17, 2025, are there new JWT best practices that have emerged on this topic since RFC 8725 was published that you can cite that you believe should be included in the draft, Brian?  If so, please provide proposed text.

It seems the draft is largely a rehash of RFC8725 with some additions and likely other updates. It should probably explicitly obsolete RFC8725 and indicate that it updates BCP 225 by replacing 8725.

Mike> The specification does both of these things (and says so in the Abstract).

A more formal section that describes the changes from RFC8725 would also be nice and is AFAIK common practice in such a document.

Mike> Appendix A does this.

Similarly it'd be good etiquette to, in the acknowledgements, distinguish between contributors to the original document and those that have contributed to the updates. I know from some github interactions, for one example, that ⁨Filip Skokan⁩ has helped guide some of the updated text but he's not mentioned at present.

Mike> Section 6.1 is the acknowledgements from RFC 8725.  Section 6.2 is the acknowledgements for this specification.

As also somewhat gratuitously mentioned at the meeting, a few years back I did a talk a few times on JWT vulnerabilities and tried to take a balanced look at many of the criticisms. I don't think there's anything novel or unknown in it, but I think it might provide some useful perspective. If anyone is interested in seeing that, or just helping drive the meager view count up, a recording of one instance of the talk is here https://www.youtube.com/watch?v=IgKRGS6cQWw

Mike> Again, if there are additional JWT best current practices that have emerged since RFC 8725 was published that you believe should be included, please cite them and provide proposed text for the draft.

                                                           Thanks,
                                                           -- Mike

On Wed, Aug 6, 2025 at 11:03 AM Rifaat Shekh-Yusef <rifaat.s.ietf@gmail.com<mailto:rifaat.s.ietf@gmail.com>> wrote:
All,

This is a call for adoption for the RFC8725bis draft that was discussed during the last IETF meeting in Madrid:
https://datatracker.ietf.org/doc/draft-sheffer-oauth-rfc8725bis/

Remember that adoption does not mean a document is finished, only that it is an acceptable starting point.

Please, reply on the mailing list and let us know if you are in favor or against adopting this draft as WG document, by August 22nd.

Regards,
 Rifaat & Hannes
_______________________________________________
OAuth mailing list -- oauth@ietf.org<mailto:oauth@ietf.org>
To unsubscribe send an email to oauth-leave@ietf.org<mailto:oauth-leave@ietf.org>

CONFIDENTIALITY NOTICE: This email may contain confidential and privileged material for the sole use of the intended recipient(s). Any review, use, distribution or disclosure by others is strictly prohibited.  If you have received this communication in error, please notify the sender immediately by e-mail and delete the message and any file attachments from your computer. Thank you.