Re: [lamps] [EXTERNAL] FYI: New Version Notification for draft-housley-lamps-cms-sphincs-plus-00.txt

Mike Ounsworth <Mike.Ounsworth@entrust.com> Fri, 19 August 2022 21:35 UTC

Return-Path: <Mike.Ounsworth@entrust.com>
X-Original-To: spasm@ietfa.amsl.com
Delivered-To: spasm@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 0B384C14CE46 for <spasm@ietfa.amsl.com>; Fri, 19 Aug 2022 14:35:52 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.106
X-Spam-Level:
X-Spam-Status: No, score=-2.106 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=entrust.com
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id AepyeNm12984 for <spasm@ietfa.amsl.com>; Fri, 19 Aug 2022 14:35:48 -0700 (PDT)
Received: from mx08-0015a003.pphosted.com (mx08-0015a003.pphosted.com [185.183.30.227]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 5B393C1522A7 for <spasm@ietf.org>; Fri, 19 Aug 2022 14:35:29 -0700 (PDT)
Received: from pps.filterd (m0242863.ppops.net [127.0.0.1]) by mx08-0015a003.pphosted.com (8.17.1.5/8.17.1.5) with ESMTP id 27JK7Dx6030265; Fri, 19 Aug 2022 16:35:26 -0500
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=entrust.com; h=from : to : subject : date : message-id : references : in-reply-to : content-type : content-transfer-encoding : mime-version; s=mail1; bh=Nq2lwFfHMIzuZMF/4CYoLoJ7YXUtcir1AZtWPPdqnWc=; b=cZ2vo3YW9drejjg7+IeAC7w3Vd4n7X5+VH/LjvYmhOWg4SrpUNbV5QuMoPkveD0QSsvf BQ4QqeYPgk/PXYKcQ+yMV35Tm2sXxtCqeEPnnDIHd20ZhMnRweMM2bOmgZd0vbvvwyW9 wmTr/MCHzAd72zBy3NYOldMkf5SMUjwBbCWfObQUZo2i9Ij2GKAaV5LMI/dSo9uCKjp2 NloaBgpws/p1aIVNwmTwLiqUTOtl2wRiptcVr6BQ4MSh1v7hqWYXfMjrdbOd1f2JhLX1 xjhFyTcFG7+VjxsBhI560YJNjRsotSDsIKi5gFMFlrIgLt5mXC1SU0qOLnM0CI3ENNcb eQ==
Received: from nam02-bn1-obe.outbound.protection.outlook.com (mail-bn1nam07lp2044.outbound.protection.outlook.com [104.47.51.44]) by mx08-0015a003.pphosted.com (PPS) with ESMTPS id 3hyv2h5ppc-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Fri, 19 Aug 2022 16:35:26 -0500
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=AY1SOrBhN8kNX0vlHtC0chRhxvkwQNf6OeGIV34iLakaCqRtLX4Ikr48BEzWjbP8Ip8QvPqR6ssoBQD3ltQw82qwsnsIKDS9FTgJzR7vIrwWq7E8q1IOEL8F6Knqv03lNFvw5Wh6wniKVi4ZbvknyFGvB9NY7yFcweHDMSq6jqWEad09pun439vEhLNsRqPhYl4iWUn6wksP/xTjfqSTTLoq3kbHJp2lr0C9r7Af8HXneVre7Kdrjd+jXNA8GRSkU8JN7da6ODGn17b8LQDA2ECkOZyR37Pe3MURIP50c0QjXDaHPn2QHP6pPWhVHShadOnEb0VUpCmKT7JMQfFfMg==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=Nq2lwFfHMIzuZMF/4CYoLoJ7YXUtcir1AZtWPPdqnWc=; b=Zifa1XznobzRSjDavB0nsmlBkoLmWfhQQz0jW2G8ZapflMU/lG8FPgbWxdVJjeV8mL8Qx/YlzJLYd/ZZt58cuLmVzYIQxdhK2m1tbbeVfYgM5d1iBMQPQ+VTAikPiK72KUBakSojaCzq/xtTqoeHbSSpbKn5iP+nAB19kOhMuYF6qU/VrQFMFvb43IyC9Udis1lIo/B1P5S3SjeOs/qyQU9OVp5zlBQ+LJNB1YC2avddl4x46Z5QmYqEnEb3NzicrNAKUzigED9kEdYCjR/+kJ7vgVlrYL66FJS3NpXyNgmskNFCdAeSyeJbFaUDjZHjdgD6q47Enp2G0WInNPKD+Q==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=entrust.com; dmarc=pass action=none header.from=entrust.com; dkim=pass header.d=entrust.com; arc=none
Received: from CH0PR11MB5739.namprd11.prod.outlook.com (2603:10b6:610:100::20) by MWHPR1101MB2206.namprd11.prod.outlook.com (2603:10b6:301:51::23) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.5504.17; Fri, 19 Aug 2022 21:35:23 +0000
Received: from CH0PR11MB5739.namprd11.prod.outlook.com ([fe80::ed02:6e67:98f7:f33d]) by CH0PR11MB5739.namprd11.prod.outlook.com ([fe80::ed02:6e67:98f7:f33d%7]) with mapi id 15.20.5546.018; Fri, 19 Aug 2022 21:35:23 +0000
From: Mike Ounsworth <Mike.Ounsworth@entrust.com>
To: Russ Housley <housley@vigilsec.com>, LAMPS <spasm@ietf.org>
Thread-Topic: [EXTERNAL] [lamps] FYI: New Version Notification for draft-housley-lamps-cms-sphincs-plus-00.txt
Thread-Index: AQHYtALG/LY/uTawgUyicGmFRsEDma22sitw
Date: Fri, 19 Aug 2022 21:35:23 +0000
Message-ID: <CH0PR11MB5739956DEAB4C7E4FB14A25B9F6C9@CH0PR11MB5739.namprd11.prod.outlook.com>
References: <166093755880.14050.354126874269583313@ietfa.amsl.com> <5B780BF2-A5AE-4B6E-AC19-E8BBDB60EB5C@vigilsec.com>
In-Reply-To: <5B780BF2-A5AE-4B6E-AC19-E8BBDB60EB5C@vigilsec.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-ms-publictraffictype: Email
x-ms-office365-filtering-correlation-id: 3f0789a7-e72e-481c-9b36-08da822ab929
x-ms-traffictypediagnostic: MWHPR1101MB2206:EE_
x-ms-exchange-senderadcheck: 1
x-ms-exchange-antispam-relay: 0
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: FjpGPVstK8h9ZgrCCd6EMtD6fEYfbIxREG2RsPv9its2buawi/5VgSJfbm+G7QZ43R8yDlWgwUpKUE9XlMzyWuTKAxYTzGc193JO4d7GFeSID3aZ0M7oJxavJUwuLWzXRbhn1VgEj8XEWfH/9bGBTlchUPsrcP0qRcjGyeWI5AdaedI5gsY15mOT22sSWyw57ELFOGqufvb6RS9oOO+e1yajnVJHoinpUQ9R+KyLgDkK7kKsRfix0Bq+txsbbstZl2WT/iVL5Gg7pRWnSbbZ112tAMfKiJINj1uMVzJzMic+cHxJ7nXaIqL6nOP5kwhNImmBVZtTfdrTonR44io3Y3TuohNzQIatayb4E/FTTeNm7b5ETjr3R2IB0IadPYMzN1xlC6aOGn9SRY0uQJSiGUxeLDli+QbhVSvV/bQI4CvoTMlETRZo+wO0qrO1PXLCHk0Orrq0+xdDwk949cmlawrL6GXqGRvHCFzbdRC3p387kZwwcCrUu96RV05VOUycOZ0bMHA1sCKxoJSCXYF7Go13M6hniE7LBkdDvpt3ykmZGdU7Nyb/8fwnpj4sLsLsI825VvP7kFv0jorJ13jIqX4QOtgKfvD25a6hfCYsBfRdbEOReFXcoKt1ceHcnCna7b20YlEHWlJar4q3+ISLMhMmJqbiqOO/MtfzXQaoefb7/9LU4kvhvU00zHvMHjGpw35G5mwDY+RNzmts3qNNdj/QcrCoZP7r9Gr2LyTv8RKFoYk504XuqwRyOQpCQq2jGssMx5rXWudT88IwpO+1GqtObHBKktAkkFbjTINP2UE2uZ1lb2sZU7eUFqDYAz5n4FTkI/ws+2h/rrTXvpLzwA==
x-forefront-antispam-report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:CH0PR11MB5739.namprd11.prod.outlook.com; PTR:; CAT:NONE; SFS:(13230016)(39860400002)(396003)(136003)(366004)(376002)(346002)(5660300002)(66946007)(110136005)(64756008)(66556008)(55016003)(66446008)(66476007)(76116006)(8676002)(52536014)(2906002)(8936002)(38100700002)(316002)(15650500001)(33656002)(41300700001)(53546011)(71200400001)(66574015)(9686003)(26005)(6506007)(7696005)(86362001)(478600001)(83380400001)(122000001)(38070700005)(966005)(186003); DIR:OUT; SFP:1102;
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: JZeZh4JQMK+AHsjlfgQM6+ncLDMUtF8SoHcP5i9bmBZlfAr4Ev10e8GQdS3rY9QIoRIaA5g8bb5CIly5oVuLwYX+2JUAAp6fI9tlKJzJu846O282lqdnF7Uxj6gDzAErHXYggNu3mR+NErg2bIcOPNzezVyUCNHcwyoGGlUxt/suNBIFAB+btcdEbOpmv1mfJ3ZepqNNuwBRDQxsuIUXt4QsYT9ly8PjwmYIRogjw44I1JtrD4TgNhUBFc6VLg9XrzlLJ6Tryt+OWESMjykKkHzpSuJFfw2e8HVs6SmaoovJLmZi2PY6+VVtQfmCuh7CEVwN1d/YtA07trJyf25oRaCS7N8251mgFxbAxY7ylzqgLbMt/jLvbf5ymQarC5t8wmUAYx4sLzcs/avh58ZN/RUyQJrX4A25LBC+wRt+AKfZ8nyjBreGuDnAg4k2IQ7EcuYdhgIkq5PvmCynhGAw4whbcT6IRY10m+IV+1n2cjBv0IW2Y8M3uXqo2OW7KLxjulIrnG0jp1LD4WlfgHzJxqLJc2z6syDf1suSgeB+Z+/xZc9npSJ4dbICo2xP6Sv5JQAVg5dRKtqEK0RUHYSd7jsvjOHjJ/e+YVgCXvtqOtqAEH95ulIU76lUbOqCoTrq75IIqS1hAdj1CaI0bVk/r7eNfWZE9/UGGL07NNna78GwMeG4VfvgUuJVkHM4OTwv+8S7fwcI0vVVpFdk3mU4DobveHxaoxW5TLJ7ppF3wUSKypMqsAKo1NTBexSWSgHfDWV3EQa/bJynZ4WfzFvybFuF0DZgRYyMMXsqcbuhaInnvQdZ5+ai+re1b07XIX5H2qDL9sU5dStbePmdViCp+oiS4TZWl9uPs/M3FveNUtX7237mtqXeZOhKO1VijDCyhPv3RFZuRE4lGqnBPuqOpRlbEh7V3b0O4+o3CKfpINyhG+AnlmeBrdWrOqXBy68j9h0lBTo7Htu+4Binn4PlOG7Q1sj/I/xl5m0v+gdLk+Tq1CJx00JvYV2RkSRPHQgv9pMU9tASbHuDOe3sAEJ3A04geMF0g1FdlEub1bU9mKDCM6l+uA0ydd1u3vOM2c8evwl2Q/vA4QOcUOB6VZ4WjGQkdJlM6dSCUS5UNpVfoCH1RDZHUrw+cj68+W3MIPHlr78Joe6RNlBDA0LI9ErJ+QfekjIiNwgofqWbqnQzJoEfG8ftk+L80E0XmCdcc1x9y5jw/07jZP5r+z74lX+gkxbe1AAdswGyGz08ESfUGuAJB/g5EVcmgOu13vngmZhxrr+qCxJ1xWJCwUX45ABtiG2nSq8nI96NZiVEurdENAnSv8kYrhFT4JskEdQMuKcu2NYR/ZsgAu4T0JuHAqs9G70g7bjvoLxk+NmaThdQnFV4H68lcwMEOzDX5TEmD1JMCmQHRKeZ2SaYvsRputE9pU4XiS7ha1VthvladweFntvp9U9huqOjXAge8TLKHREOqdh7XGW/42pv1TJ/UtagHGvUUVCDWDy5AGSqDRYD/QR1LyFDfkGA1zVYdpAKBC+lexv9FsRJvurTvm71tQGs8blRVP3Vw5bzrC00epO0Az9b/8RehiExLS9shdaJGayWMv0sBm5DCSsNZyfgLdzqQg==
Content-Type: text/plain; charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
X-OriginatorOrg: entrust.com
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: CH0PR11MB5739.namprd11.prod.outlook.com
X-MS-Exchange-CrossTenant-Network-Message-Id: 3f0789a7-e72e-481c-9b36-08da822ab929
X-MS-Exchange-CrossTenant-originalarrivaltime: 19 Aug 2022 21:35:23.2939 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: f46cf439-27ef-4acf-a800-15072bb7ddc1
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: NGKWkk+Guotvak9aoABxiD4YhdXl/4bCaSdt/xJB5aA9r/+obDfHIGHBrtr4c66Jt11DcuQqziRls2/itg1Y/WT8xm4GjjIrD8rb3+J1DKU=
X-MS-Exchange-Transport-CrossTenantHeadersStamped: MWHPR1101MB2206
X-Proofpoint-GUID: c58auGOM-nr-ciO3MH5rBHUQzCMKQgs6
X-Proofpoint-ORIG-GUID: c58auGOM-nr-ciO3MH5rBHUQzCMKQgs6
X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.205,Aquarius:18.0.895,Hydra:6.0.517,FMLib:17.11.122.1 definitions=2022-08-19_12,2022-08-18_01,2022-06-22_01
X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 impostorscore=0 clxscore=1015 spamscore=0 mlxlogscore=999 priorityscore=1501 suspectscore=0 bulkscore=0 adultscore=0 lowpriorityscore=0 malwarescore=0 phishscore=0 mlxscore=0 classifier=spam adjust=0 reason=mlx scancount=1 engine=8.12.0-2207270000 definitions=main-2208190081
Archived-At: <https://mailarchive.ietf.org/arch/msg/spasm/A0P-k5QRlQ-9jAGJn0vPn6Cog3o>
Subject: Re: [lamps] [EXTERNAL] FYI: New Version Notification for draft-housley-lamps-cms-sphincs-plus-00.txt
X-BeenThere: spasm@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: "This is a venue for discussion of doing Some Pkix And SMime \(spasm\) work." <spasm.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/spasm>, <mailto:spasm-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/spasm/>
List-Post: <mailto:spasm@ietf.org>
List-Help: <mailto:spasm-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/spasm>, <mailto:spasm-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 19 Aug 2022 21:35:52 -0000

I support this document. Here is my review:


1.
Section 2: " The corresponding FIPS public keys are the leaves in k binary trees." Is that a typo? What does the Federal Information Processing Standards have to do with these leaf nodes?

2.
The "WOTS+" acronym should probably be expanded.

3.
The paragraph starting "A SPHINCS+ signature consists of..." is likely rather confusing to someone not already an expert in this. Perhaps some ascii art depicting both the subtree relationships, as well as showing which nodes are involved in a given signature would be illustrative?


4.
The intro paragraph of section 3 says "The AlgorithmIdentifier for an SPHINCS+ public key uses *the* id-alg-sphincs-plus object identifier" ... emphasis on "*THE* id-alg-sphincs-plus OID", implying there's a single one, but in the ASN.1 definitions you have:

   IDENTIFIER id-alg-sphincs-plus-128
   IDENTIFIER id-alg-sphincs-plus-192
   IDENTIFIER id-alg-sphincs-plus-256

I assume the opening paragraph should read "... uses one of the id-alg-sphincs-plus-* object identifiers"?


5.
I see the asn.1 module has the above OIDs as TBDs; I assume they will eventually cross-reference NIST-assigned OIDs?

Can I request you stick in temporary OIDs for now for interoperable prototyping?


6.

  "The SPHINCS+ public key value is an OCTET STRING.  (Should we say something more here about the size?)"

I vote "No", but you should include an appendix with a PEM-encoded pub key, priv key, and signature over the string "The quick brown fox jumps over... you know what" (nod to OQS [footnote1]) for each security level; size can be inferred from the sample data.

7.
Section 4:

  "   IF (signed attributes are absent)
      THEN SPHINCS+_Sign(content)
      ELSE message-digest attribute = Hash(content);
           SPHINCS+_Sign(DER(SignedAttributes)) "

Naïve question: is this business of what string you're actually signing not already covered by the CMS spec? Seems a bit odd to have protocol logic in an algorithm spec.


8.
Section 5:

  " Along with the private key, the implementation MUST keep track of which leaf nodes in the tree have been used.  Loss of integrity of this tracking data can cause a one-time key to be used more than once.  As a result, when a private key and the tracking data are stored on non-volatile media ..."


Uhh, that seems copy/pasted from a stateful HBS draft, isn't the whole point of SPHICS+ that that not be the case?


9.
Section 5:

   "A SPHINCS+ tree MUST NOT be used for more than 2^64 signing operations."

This sentence probably needs expanding; horizontally-scaled instances using copies of the same keys, or backup-and-restore scenarios are gonna make it super annoying to track how many signatures a given key has performed. Needing a centralized usage counter pretty much kills scalability; and requires disaster recovery sites to have unique keys from the primary site.

Granted, 2^64 is _a lot_, and if you're building a system that's gonna have anywhere near that amount of throughput, then you probably have bigger scalability issues to solve first. Most people will never be anywhere close to 2^64 signatures and are safe to completely ignore this security consideration.



[Footnote1]: https://github.com/open-quantum-safe/oqs-provider/blob/b159e4fe659e2d9e57a30435f9d8f5ab11533597/test/oqs_test_signatures.c#L41
---
Mike Ounsworth

-----Original Message-----
From: Spasm <spasm-bounces@ietf.org> On Behalf Of Russ Housley
Sent: August 19, 2022 2:35 PM
To: LAMPS <spasm@ietf.org>
Subject: [EXTERNAL] [lamps] FYI: New Version Notification for draft-housley-lamps-cms-sphincs-plus-00.txt

WARNING: This email originated outside of Entrust.
DO NOT CLICK links or attachments unless you trust the sender and know the content is safe.

______________________________________________________________________

A new version of I-D, draft-housley-lamps-cms-sphincs-plus-00.txt
has been successfully submitted by Russ Housley and posted to the IETF repository.

Name:           draft-housley-lamps-cms-sphincs-plus
Revision:       00
Title:          Use of the SPHINCS+ Signature Algorithm in the Cryptographic Message Syntax (CMS)
Document date:  2022-08-19
Group:          Individual Submission
Pages:          11
URL:            https://urldefense.com/v3/__https://www.ietf.org/archive/id/draft-housley-lamps-cms-sphincs-plus-00.txt__;!!FJ-Y8qCqXTj2!aqZazqUu1skhae2xlUOrC2SFN3zLh0XQHO3U7OGsZsUEV1iZg0cyf4KxvEn2lIeKq3F6Lf_4BrQg-pRPz3haAJ84GYsN$
Status:         https://urldefense.com/v3/__https://datatracker.ietf.org/doc/draft-housley-lamps-cms-sphincs-plus/__;!!FJ-Y8qCqXTj2!aqZazqUu1skhae2xlUOrC2SFN3zLh0XQHO3U7OGsZsUEV1iZg0cyf4KxvEn2lIeKq3F6Lf_4BrQg-pRPz3haAAqcmAJ0$
Html:           https://urldefense.com/v3/__https://www.ietf.org/archive/id/draft-housley-lamps-cms-sphincs-plus-00.html__;!!FJ-Y8qCqXTj2!aqZazqUu1skhae2xlUOrC2SFN3zLh0XQHO3U7OGsZsUEV1iZg0cyf4KxvEn2lIeKq3F6Lf_4BrQg-pRPz3haAGRbuc3g$
Htmlized:       https://urldefense.com/v3/__https://datatracker.ietf.org/doc/html/draft-housley-lamps-cms-sphincs-plus__;!!FJ-Y8qCqXTj2!aqZazqUu1skhae2xlUOrC2SFN3zLh0XQHO3U7OGsZsUEV1iZg0cyf4KxvEn2lIeKq3F6Lf_4BrQg-pRPz3haAHRh0nHN$


Abstract:
  SPHINCS+ is a stateless hash-based signature scheme.  This document
  specifies the conventions for using the SPHINCS+ stateless hash-based
  signature algorithm with the Cryptographic Message Syntax (CMS).  In
  addition, the algorithm identifier and public key syntax are
  provided.

_______________________________________________
Spasm mailing list
Spasm@ietf.org
https://urldefense.com/v3/__https://www.ietf.org/mailman/listinfo/spasm__;!!FJ-Y8qCqXTj2!aqZazqUu1skhae2xlUOrC2SFN3zLh0XQHO3U7OGsZsUEV1iZg0cyf4KxvEn2lIeKq3F6Lf_4BrQg-pRPz3haACt-2oqH$
Any email and files/attachments transmitted with it are confidential and are intended solely for the use of the individual or entity to whom they are addressed. If this message has been sent to you in error, you must not copy, distribute or disclose of the information it contains. Please notify Entrust immediately and delete the message from your system.