<?xml version='1.0' encoding='utf-8'?>
<!DOCTYPE rfc [
  <!ENTITY nbsp    "&#160;">
  <!ENTITY zwsp   "&#8203;">
  <!ENTITY nbhy   "&#8209;">
  <!ENTITY wj     "&#8288;">
]>
<?xml-stylesheet type="text/xsl" href="rfc2629.xslt" ?>
<!-- generated by https://github.com/cabo/kramdown-rfc version 1.7.19 (Ruby 3.3.3) -->
<rfc xmlns:xi="http://www.w3.org/2001/XInclude" ipr="trust200902" docName="draft-ietf-lamps-x509-shbs-07" category="std" consensus="true" submissionType="IETF" tocInclude="true" sortRefs="true" symRefs="true" version="3">
  <!-- xml2rfc v2v3 conversion 3.23.2 -->
  <front>
    <title abbrev="HSS and XMSS for X.509">Internet X.509 Public Key Infrastructure: Algorithm Identifiers for HSS and XMSS</title>
    <seriesInfo name="Internet-Draft" value="draft-ietf-lamps-x509-shbs-07"/>
    <author initials="D." surname="Van Geest" fullname="Daniel Van Geest">
      <organization>CryptoNext Security</organization>
      <address>
        <email>daniel.vangeest@cryptonext-security.com</email>
      </address>
    </author>
    <author initials="K." surname="Bashiri" fullname="Kaveh Bashiri">
      <organization>BSI</organization>
      <address>
        <email>kaveh.bashiri.ietf@gmail.com</email>
      </address>
    </author>
    <author initials="S." surname="Fluhrer" fullname="Scott Fluhrer">
      <organization>Cisco Systems</organization>
      <address>
        <email>sfluhrer@cisco.com</email>
      </address>
    </author>
    <author initials="S." surname="Gazdag" fullname="Stefan Gazdag">
      <organization>genua GmbH</organization>
      <address>
        <email>ietf@gazdag.de</email>
      </address>
    </author>
    <author initials="S." surname="Kousidis" fullname="Stavros Kousidis">
      <organization>BSI</organization>
      <address>
        <email>kousidis.ietf@gmail.com</email>
      </address>
    </author>
    <date year="2024" month="October" day="04"/>
    <area>sec</area>
    <workgroup>LAMPS - Limited Additional Mechanisms for PKIX and SMIME</workgroup>
    <keyword>Internet-Draft</keyword>
    <abstract>
      <?line 141?>

<t>This document specifies algorithm identifiers and ASN.1 encoding formats for
the stateful hash-based signature (HBS) schemes Hierarchical Signature System
(HSS), eXtended Merkle Signature Scheme (XMSS), and XMSS^MT, a multi-tree
variant of XMSS. This specification applies to the Internet X.509 Public Key
infrastructure (PKI) when those digital signatures are used in Internet X.509
certificates and certificate revocation lists.</t>
    </abstract>
    <note removeInRFC="true">
      <name>About This Document</name>
      <t>
        Status information for this document may be found at <eref target="https://datatracker.ietf.org/doc/draft-ietf-lamps-x509-shbs/"/>.
      </t>
      <t>
        Discussion of this document takes place on the
        LAMPS Working Group mailing list (<eref target="mailto:spasm@ietf.org"/>),
        which is archived at <eref target="https://mailarchive.ietf.org/arch/browse/spasm/"/>.
        Subscribe at <eref target="https://www.ietf.org/mailman/listinfo/spasm/"/>.
      </t>
      <t>Source for this draft and an issue tracker can be found at
        <eref target="https://github.com/x509-hbs/draft-x509-shbs"/>.</t>
    </note>
  </front>
  <middle>
    <?line 150?>

<section anchor="introduction">
      <name>Introduction</name>
      <t>Stateful HBS schemes such as HSS, XMSS and XMSS^MT
combine Merkle trees with One Time Signatures (OTS) in order to provide digital
signature schemes that remain secure even when quantum computers become
available. Their theoretic security is well understood and depends only on the
security of the underlying hash function. As such they can serve as an
important building block for quantum computer resistant information and
communication technology.</t>
      <t>A stateful HBS private key is a finite collection of OTS keys, hence only a
limited number of messages can be signed and the private key's state must be
updated and persisted after signing to prevent reuse of OTS keys.  While the
right selection of algorithm parameters would allow a private key to sign a
virtually unbounded number of messages (e.g. 2^60), this is at the cost of a
larger signature size and longer signing time. Due to the statefulness of the
private key and the limited number of signatures that can be created, stateful HBS schemes
might not be appropriate for use in interactive protocols. However, in some use
cases the deployment of stateful HBS schemes may be appropriate. Such use cases are described
and discussed in <xref target="use-cases-shbs-x509"/>.</t>
    </section>
    <section anchor="conventions-and-definitions">
      <name>Conventions and Definitions</name>
      <t>The key words "<bcp14>MUST</bcp14>", "<bcp14>MUST NOT</bcp14>", "<bcp14>REQUIRED</bcp14>", "<bcp14>SHALL</bcp14>", "<bcp14>SHALL
NOT</bcp14>", "<bcp14>SHOULD</bcp14>", "<bcp14>SHOULD NOT</bcp14>", "<bcp14>RECOMMENDED</bcp14>", "<bcp14>NOT RECOMMENDED</bcp14>",
"<bcp14>MAY</bcp14>", and "<bcp14>OPTIONAL</bcp14>" in this document are to be interpreted as
described in BCP 14 <xref target="RFC2119"/> <xref target="RFC8174"/> when, and only when, they
appear in all capitals, as shown here.</t>
      <?line -18?>

</section>
    <section anchor="use-cases-shbs-x509">
      <name>Use Cases of Stateful HBS Schemes in X.509</name>
      <t>As described in the Security Considerations of <xref target="sec-security"/>, it is
imperative that stateful HBS implementations do not reuse OTS signatures. This makes
stateful HBS algorithms inappropriate for general use cases. The exact conditions
under which stateful HBS certificates may be used is left to certificate policies <xref target="RFC3647"/>.
However the intended use of stateful HBS schemes as described by <xref target="SP800208"/> can be used as a
guideline:</t>
      <blockquote>
        <t>1) it is necessary to implement a digital signature scheme in the near
future; <br/>
2) the implementation will have a long lifetime; and <br/>
3) it would not be practical to transition to a different digital signature
scheme once the implementation has been deployed.</t>
      </blockquote>
      <t>In addition, since a stateful HBS private key can only generate a finite number of
signatures, use cases for stateful HBS public keys in certificates should have a
predictable range of the number of signatures that will be generated, falling
safely below the maximum number of signatures that a private key can generate.</t>
      <t>Use cases where stateful HBS public keys in certificates may be appropriate due to
the relatively small number of signatures generated and the signer's ability
to enforce security restrictions on the signing environment include:</t>
      <ul spacing="normal">
        <li>
          <t>Firmware signing (Section 1.1 of <xref target="SP800208"/>, Table IV of <xref target="CNSA2.0"/>, Section
6.7 of <xref target="BSI"/>)</t>
        </li>
        <li>
          <t>Software signing (Table IV of <xref target="CNSA2.0"/>, <xref target="ANSSI"/>)</t>
        </li>
        <li>
          <t>Certification Authority (CA) certificates.</t>
        </li>
      </ul>
      <t>In each of these cases, the operator is able to control their signing
environment such that signatures are generated in hardware cryptographic
modules and audited before the signature is published, in order to prevent OTS
key reuse.</t>
      <t>Generally speaking, stateful HBS public keys are not appropriate for use
in end-entity certificates, however in the firmware and software signing cases
signature generation will often be more tightly controlled. Some
manufactures use common and well-established key formats like X.509 for their
code signing and update mechanisms. Also there are multi-party IoT ecosystems
where publicly trusted code signing certificates are useful.</t>
      <t>In general, root CAs <xref target="RFC4949"/> generate signatures in a more secure environment and issue
fewer certificates than subordinate CAs <xref target="RFC4949"/>. This makes the use of stateful HBS public
keys more appropriate in root CA certificates than in subordinate CA
certificates. However, if a subordinate CA can match the security and
signature count restrictions of a root CA, for example if the subordinate CA
only issues code-signing certificates, then using a stateful HBS public key in the
subordinate CA certificate may be possible.</t>
    </section>
    <section anchor="algorithm-identifiers-and-parameters">
      <name>Algorithm Identifiers and Parameters</name>
      <t>In this document, we define new OIDs for identifying the different stateful
hash-based signature algorithms. An additional OID is defined in <xref target="I-D.draft-ietf-lamps-rfc8708bis"/> and
repeated here for convenience. For all of the OIDs, the parameters <bcp14>MUST</bcp14> be
absent.</t>
      <section anchor="hss-algorithm-identifier">
        <name>HSS Algorithm Identifier</name>
        <t>The object identifier and public key algorithm identifier for HSS is defined in
<xref target="I-D.draft-ietf-lamps-rfc8708bis"/>. The definitions are repeated here for reference.</t>
        <t>The object identifier for an HSS public key is <tt>id-alg-hss-lms-hashsig</tt>:</t>
        <artwork><![CDATA[
   id-alg-hss-lms-hashsig  OBJECT IDENTIFIER ::= {
      iso(1) member-body(2) us(840) rsadsi(113549) pkcs(1) pkcs9(9)
      smime(16) alg(3) 17 }
]]></artwork>
        <t>Note that the <tt>id-alg-hss-lms-hashsig</tt> algorithm identifier is also referred to
as <tt>id-alg-mts-hashsig</tt>. This synonym is based on the terminology used in an
early draft of the document that became <xref target="RFC8554"/>.</t>
        <t>The public key and signature values identify the hash function and the height used in the
HSS/LMS tree. <xref target="RFC8554"/> and <xref target="SP800208"/> define these values, but an IANA registry
<xref target="IANA-LMS"/> permits the registration of additional identifiers in the future.</t>
      </section>
      <section anchor="xmss-algorithm-identifier">
        <name>XMSS Algorithm Identifier</name>
        <t>The object identifier for an XMSS public key is <tt>id-alg-xmss-hashsig</tt>:</t>
        <artwork><![CDATA[
   id-alg-xmss-hashsig  OBJECT IDENTIFIER ::= {
      iso(1) identified-organization(3) dod(6) internet(1)
      security(5) mechanisms(5) pkix(7) algorithms(6) 34 }
]]></artwork>
        <t>The public key and signature values identify the hash function and the height used in the
XMSS tree. <xref target="RFC8391"/> and <xref target="SP800208"/> define these values, but an IANA registry
<xref target="IANA-XMSS"/> permits the registration of additional identifiers in the future.</t>
      </section>
      <section anchor="xmssmt-algorithm-identifier">
        <name>XMSS^MT Algorithm Identifier</name>
        <t>The object identifier for an XMSS^MT public key is <tt>id-alg-xmssmt-hashsig</tt>:</t>
        <artwork><![CDATA[
   id-alg-xmssmt-hashsig  OBJECT IDENTIFIER ::= {
      iso(1) identified-organization(3) dod(6) internet(1)
      security(5) mechanisms(5) pkix(7) algorithms(6) 35 }
]]></artwork>
        <t>The public key and signature values identify the hash function and the height used in the
XMSS^MT tree. <xref target="RFC8391"/> and <xref target="SP800208"/> define these values, but an IANA registry
<xref target="IANA-XMSS"/> permits the registration of additional identifiers in the future.</t>
      </section>
    </section>
    <section anchor="public-key-identifiers">
      <name>Public Key Identifiers</name>
      <t>Certificates conforming to <xref target="RFC5280"/> can convey a public key for any public key
algorithm. The certificate indicates the algorithm through an algorithm
identifier. An algorithm identifier consists of an OID and optional parameters.</t>
      <t><xref target="RFC8554"/> and <xref target="RFC8391"/> define the raw octet string encodings of the public
keys used in this document. When used in a SubjectPublicKeyInfo type, the
subjectPublicKey BIT STRING contains the raw octet string encodings of the
public keys.</t>
      <t>This document defines ASN.1 OCTET STRING types for encoding the public keys
when not used in a SubjectPublicKeyInfo. The OCTET STRING is mapped to a
subjectPublicKey (a value of type BIT STRING) as follows: the most significant
bit of the OCTET STRING value becomes the most significant bit of the BIT
STRING value, and so on; the least significant bit of the OCTET STRING
becomes the least significant bit of the BIT STRING.</t>
      <section anchor="hss-public-keys">
        <name>HSS Public Keys</name>
        <t>The HSS public key identifier is as follows:</t>
        <artwork><![CDATA[
   pk-HSS-LMS-HashSig PUBLIC-KEY ::= {
      IDENTIFIER id-alg-hss-lms-hashsig
      -- KEY no ASN.1 wrapping --
      PARAMS ARE absent
      CERT-KEY-USAGE
         { digitalSignature, nonRepudiation, keyCertSign, cRLSign } }
]]></artwork>
        <t>The HSS public key is defined as follows:</t>
        <artwork><![CDATA[
   HSS-LMS-HashSig-PublicKey ::= OCTET STRING
]]></artwork>
        <t><xref target="RFC8554"/> defines the raw octet string encoding of an HSS public key using the
<tt>hss_public_key</tt> structure. See <xref target="SP800208"/> and <xref target="RFC8554"/> for more information on
the contents and format of an HSS public key. Note that the single-tree signature
scheme LMS is instantiated as HSS with number of levels being equal to 1.</t>
      </section>
      <section anchor="xmss-public-keys">
        <name>XMSS Public Keys</name>
        <t>The XMSS public key identifier is as follows:</t>
        <artwork><![CDATA[
   pk-XMSS-HashSig PUBLIC-KEY ::= {
      IDENTIFIER id-alg-xmss-hashsig
      -- KEY no ASN.1 wrapping --
      PARAMS ARE absent
      CERT-KEY-USAGE
         { digitalSignature, nonRepudiation, keyCertSign, cRLSign } }
]]></artwork>
        <t>The XMSS public key is defined as follows:</t>
        <artwork><![CDATA[
   XMSS-HashSig-PublicKey ::= OCTET STRING
]]></artwork>
        <t><xref target="RFC8391"/> defines the raw octet string encoding of an HSS public key using the
<tt>xmss_public_key</tt> structure. See <xref target="SP800208"/> and <xref target="RFC8391"/> for more information
on the contents and format of an XMSS public key.</t>
      </section>
      <section anchor="xmssmt-public-keys">
        <name>XMSS^MT Public Keys</name>
        <t>The XMSS^MT public key identifier is as follows:</t>
        <artwork><![CDATA[
   pk-XMSSMT-HashSig PUBLIC-KEY ::= {
      IDENTIFIER id-alg-xmssmt-hashsig
      -- KEY no ASN.1 wrapping --
      PARAMS ARE absent
      CERT-KEY-USAGE
         { digitalSignature, nonRepudiation, keyCertSign, cRLSign } }
]]></artwork>
        <t>The XMSS^MT public key is defined as follows:</t>
        <artwork><![CDATA[
   XMSSMT-HashSig-PublicKey ::= OCTET STRING
]]></artwork>
        <t><xref target="RFC8391"/> defines the raw octet string encoding of an HSS public key using the
<tt>xmssmt_public_key</tt> structure. See <xref target="SP800208"/> and <xref target="RFC8391"/> for more information
on the contents and format of an XMSS^MT public key.</t>
      </section>
    </section>
    <section anchor="key-usage-bits">
      <name>Key Usage Bits</name>
      <t>The intended application for the key is indicated in the keyUsage certificate
extension <xref target="RFC5280"/>.
When id-alg-hss-lms-hashsig, id-alg-xmss-hashsig or id-alg-xmssmt-hashsig appears in the SubjectPublicKeyInfo
field of a CA X.509 certificate <xref target="RFC5280"/>, the
certificate key usage extension <bcp14>MUST</bcp14> contain at least one of the
following values: digitalSignature, nonRepudiation, keyCertSign, or
cRLSign. However, it <bcp14>MUST NOT</bcp14> contain other values.</t>
      <t>When id-alg-hss-lms-hashsig, id-alg-xmss-hashsig or id-alg-xmssmt-hashsig appears in the SubjectPublicKeyInfo
field of an end entity X.509 certificate <xref target="RFC5280"/>, the certificate key usage
extension <bcp14>MUST</bcp14> contain at least one of the following values: digitalSignature,
nonRepudiation or cRLSign. However, it <bcp14>MUST NOT</bcp14> contain other values.</t>
    </section>
    <section anchor="signature-algorithms">
      <name>Signature Algorithms</name>
      <t>This section identifies OIDs for signing using HSS, XMSS, and XMSS^MT. When
these algorithm identifiers appear in the algorithm field as an
AlgorithmIdentifier, the encoding <bcp14>MUST</bcp14> omit the parameters field. That is, the
AlgorithmIdentifier <bcp14>SHALL</bcp14> be a SEQUENCE of one component, one of the OIDs
defined in the following subsections.</t>
      <t>When the signature algorithm identifiers described in this document are used to
create a signature on a message, no digest algorithm is applied to the message
before signing.  That is, the full data to be signed is signed rather than
a digest of the data.</t>
      <t>The format of an HSS signature is described in <xref section="6.2" sectionFormat="of" target="RFC8554"/>. The format
of an XMSS signature is described in <xref section="B.2" sectionFormat="of" target="RFC8391"/> and the format of
an XMSS^MT signature is described in <xref section="C.2" sectionFormat="of" target="RFC8391"/>.
The octet string representing the signature is encoded
directly in a BIT STRING without adding any additional ASN.1 wrapping. For
the Certificate and CertificateList structures, the octet string is encoded
in the "signatureValue" BIT STRING field.</t>
      <section anchor="hss-signature-algorithm">
        <name>HSS Signature Algorithm</name>
        <t>The HSS public key OID is also used to specify that an HSS signature was
generated on the full message, i.e. the message was not hashed before being
processed by the HSS signature algorithm.</t>
        <artwork><![CDATA[
   id-alg-hss-lms-hashsig OBJECT IDENTIFIER ::= {
      iso(1) member-body(2) us(840) rsadsi(113549) pkcs(1) pkcs9(9)
      smime(16) alg(3) 17 }
]]></artwork>
        <t>See <xref target="SP800208"/> and <xref target="RFC8554"/> for more information on the contents and
format of an HSS signature.</t>
      </section>
      <section anchor="xmss-signature-algorithm">
        <name>XMSS Signature Algorithm</name>
        <t>The id-alg-xmss-hashsig public key OID is also used to specify that an XMSS signature was
generated on the full message, i.e. the message was not hashed before being
processed by the XMSS signature algorithm.</t>
        <t>See <xref target="SP800208"/> and <xref target="RFC8391"/> for more information on the contents and
format of an XMSS signature.</t>
        <t>The signature generation <bcp14>MUST</bcp14> be performed according to 7.2 of
<xref target="SP800208"/>.</t>
      </section>
      <section anchor="xmssmt-signature-algorithm">
        <name>XMSS^MT Signature Algorithm</name>
        <t>The id-alg-xmssmt-hashsig public key OID is also used to specify that an XMSS^MT signature
was generated on the full message, i.e. the message was not hashed before being
processed by the XMSS^MT signature algorithm.</t>
        <t>See <xref target="SP800208"/> and <xref target="RFC8391"/> for more information on the contents and
format of an XMSS^MT signature.</t>
        <t>The signature generation <bcp14>MUST</bcp14> be performed according to 7.2 of
<xref target="SP800208"/>.</t>
      </section>
    </section>
    <section anchor="key-generation">
      <name>Key Generation</name>
      <t>The key generation for XMSS and XMSS^MT <bcp14>MUST</bcp14> be performed according to 7.2 of
<xref target="SP800208"/></t>
    </section>
    <section anchor="sec-asn1">
      <name>ASN.1 Module</name>
      <t>For reference purposes, the ASN.1 syntax is presented as an ASN.1 module here.
This ASN.1 Module builds upon the conventions established in <xref target="RFC5911"/>.</t>
      <artwork><![CDATA[
X509-SHBS-2024
  { iso(1) identified-organization(3) dod(6) internet(1) security(5)
    mechanisms(5) pkix(7) id-mod(0) id-mod-pkix1-shbs-2024(TBD) }

DEFINITIONS IMPLICIT TAGS ::= BEGIN

EXPORTS ALL;

IMPORTS
  PUBLIC-KEY, SIGNATURE-ALGORITHM
    FROM AlgorithmInformation-2009  -- [RFC5911]
      { iso(1) identified-organization(3) dod(6) internet(1)
        security(5) mechanisms(5) pkix(7) id-mod(0)
        id-mod-algorithmInformation-02(58) }

  sa-HSS-LMS-HashSig, pk-HSS-LMS-HashSig
    FROM MTS-HashSig-2013
      { iso(1) member-body(2) us(840) rsadsi(113549) pkcs(1) pkcs9(9)
        id-smime(16) id-mod(0) id-mod-mts-hashsig-2013(64) };

--
-- Object Identifiers
--

-- id-alg-hss-lms-hashsig is defined in {{I-D.draft-ietf-lamps-rfc8708bis}}

id-alg-xmss-hashsig  OBJECT IDENTIFIER ::= {
   iso(1) identified-organization(3) dod(6) internet(1) security(5)
   mechanisms(5) pkix(7) algorithms(6) 34 }

id-alg-xmssmt-hashsig  OBJECT IDENTIFIER ::= {
   iso(1) identified-organization(3) dod(6) internet(1) security(5)
   mechanisms(5) pkix(7) algorithms(6) 35 }

--
-- Signature Algorithms and Public Keys
--

-- sa-HSS-LMS-HashSig is defined in {{I-D.draft-ietf-lamps-rfc8708bis}}

sa-XMSS-HashSig SIGNATURE-ALGORITHM ::= {
   IDENTIFIER id-alg-xmss-hashsig
   PARAMS ARE absent
   PUBLIC-KEYS { pk-XMSS-HashSig }
   SMIME-CAPS { IDENTIFIED BY id-alg-xmss-hashsig } }

sa-XMSSMT-HashSig SIGNATURE-ALGORITHM ::= {
   IDENTIFIER id-alg-xmssmt-hashsig
   PARAMS ARE absent
   PUBLIC-KEYS { pk-XMSSMT-HashSig }
   SMIME-CAPS { IDENTIFIED BY id-alg-xmssmt-hashsig } }

-- pk-HSS-LMS-HashSig is defined in {{I-D.draft-ietf-lamps-rfc8708bis}}

pk-XMSS-HashSig PUBLIC-KEY ::= {
   IDENTIFIER id-alg-xmss-hashsig
   -- KEY no ASN.1 wrapping --
   PARAMS ARE absent
   CERT-KEY-USAGE
      { digitalSignature, nonRepudiation, keyCertSign, cRLSign } }

pk-XMSSMT-HashSig PUBLIC-KEY ::= {
   IDENTIFIER id-alg-xmssmt-hashsig
   -- KEY no ASN.1 wrapping --
   PARAMS ARE absent
   CERT-KEY-USAGE
      { digitalSignature, nonRepudiation, keyCertSign, cRLSign } }

--
-- Public Key (pk-) Algorithms
--
PublicKeys PUBLIC-KEY ::= {
   -- This expands PublicKeys from RFC 5912
   pk-HSS-LMS-HashSig |
   pk-XMSS-HashSig |
   pk-XMSSMT-HashSig,
   ...
}

--
-- Signature Algorithms (sa-)
--
SignatureAlgs SIGNATURE-ALGORITHM ::= {
   -- This expands SignatureAlgorithms from RFC 5912
   sa-HSS-LMS-HashSig |
   sa-XMSS-HashSig |
   sa-XMSSMT-HashSig,
   ...
}

END
]]></artwork>
    </section>
    <section anchor="sec-security">
      <name>Security Considerations</name>
      <t>The security requirements of <xref target="SP800208"/> <bcp14>MUST</bcp14> be taken into account.</t>
      <t>As stateful HBS private keys can only generate a limited number of signatures, a
user needs to be aware of the total number of signatures they intend to
generate in their use case, otherwise they risk exhausting the number of OTS
keys in their private key.</t>
      <t>For stateful HBS schemes, it is crucial to stress the importance of correct state management.
If an attacker were able to obtain signatures for two different messages
created using the same OTS key, then it would become computationally feasible
for that attacker to create forgeries <xref target="BH16"/>. As noted in <xref target="MCGREW"/> and
<xref target="ETSI-TR-103-692"/>, extreme care needs to be taken in order to avoid the risk
that an OTS key will be reused accidentally.  This is a new requirement that
most developers will not be familiar with and requires careful handling.</t>
      <t>Various strategies for a correct state management can be applied:</t>
      <ul spacing="normal">
        <li>
          <t>Implement a record of all signatures generated by a key pair associated
with a stateful HBS instance. This record may be stored outside the
device which is used to generate the signature. Check the record to
prevent OTS key reuse before a new signature is released. Drop the new
signature and hit your PANIC button if you spot OTS key reuse.</t>
        </li>
        <li>
          <t>Use a stateful HBS instance only for a moderate number of signatures such
that it is always practical to keep a consistent record and be able to
unambiguously trace back all generated signatures.</t>
        </li>
        <li>
          <t>Apply the state reservation strategy described in Section 5 of <xref target="MCGREW"/>, where
upcoming states are reserved in advance by the signer. In this way the number of
state synchronisations between nonvolatile and volatile memory is reduced.</t>
        </li>
      </ul>
    </section>
    <section anchor="backup-and-restore-management">
      <name>Backup and Restore Management</name>
      <t>Certificate Authorities have high demands in order to ensure the availability
of signature generation throughout the validity period of signing key pairs.</t>
      <t>Usual backup and restore strategies when using a stateless signature scheme
(e.g. SLH-DSA) are to duplicate private keying material and to operate
redundant signing devices or to store and safeguard a copy of the private
keying material such that it can be used to set up a new signing device in case
of technical difficulties.</t>
      <t>For stateful HBS schemes, such straightforward backup and restore strategies will lead to OTS
reuse with high probability as a correct state management is not guaranteed.
Strategies for maintaining availability and keeping a correct state are
described in Section 7 of <xref target="SP800208"/>.</t>
    </section>
    <section anchor="iana-considerations">
      <name>IANA Considerations</name>
      <t>One object identifier for the ASN.1 module in <xref target="sec-asn1"/> is requested
for the SMI Security for PKIX Module Identifiers (1.3.6.1.5.5.7.0)
registry:</t>
      <table>
        <thead>
          <tr>
            <th align="left">Decimal</th>
            <th align="left">Description</th>
            <th align="left">References</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">TBD</td>
            <td align="left">id-mod-pkix1-shbs-2024</td>
            <td align="left">[EDNOTE: THIS RFC]</td>
          </tr>
        </tbody>
      </table>
      <t>IANA has updated the "SMI Security for PKIX Algorithms" (1.3.6.1.5.5.7.6)
registry <xref target="SMI-PKIX"/> with two additional entries:</t>
      <table>
        <thead>
          <tr>
            <th align="left">Decimal</th>
            <th align="left">Description</th>
            <th align="left">References</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">34</td>
            <td align="left">id-alg-xmss-hashsig</td>
            <td align="left">[EDNOTE: THIS RFC]</td>
          </tr>
          <tr>
            <td align="left">35</td>
            <td align="left">id-alg-xmssmt-hashsig</td>
            <td align="left">[EDNOTE: THIS RFC]</td>
          </tr>
        </tbody>
      </table>
    </section>
  </middle>
  <back>
    <references anchor="sec-combined-references">
      <name>References</name>
      <references anchor="sec-normative-references">
        <name>Normative References</name>
        <reference anchor="I-D.draft-ietf-lamps-rfc8708bis">
          <front>
            <title>Use of the HSS/LMS Hash-Based Signature Algorithm in the Cryptographic Message Syntax (CMS)</title>
            <author fullname="R. Housley" initials="R." surname="Housley"/>
            <date month="February" year="2020"/>
            <abstract>
              <t>This document specifies the conventions for using the Hierarchical Signature System (HSS) / Leighton-Micali Signature (LMS) hash-based signature algorithm with the Cryptographic Message Syntax (CMS). In addition, the algorithm identifier and public key syntax are provided. The HSS/LMS algorithm is one form of hash-based digital signature; it is described in RFC 8554.</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="8708"/>
          <seriesInfo name="DOI" value="10.17487/RFC8708"/>
        </reference>
        <reference anchor="RFC5911">
          <front>
            <title>New ASN.1 Modules for Cryptographic Message Syntax (CMS) and S/MIME</title>
            <author fullname="P. Hoffman" initials="P." surname="Hoffman"/>
            <author fullname="J. Schaad" initials="J." surname="Schaad"/>
            <date month="June" year="2010"/>
            <abstract>
              <t>The Cryptographic Message Syntax (CMS) format, and many associated formats, are expressed using ASN.1. The current ASN.1 modules conform to the 1988 version of ASN.1. This document updates those ASN.1 modules to conform to the 2002 version of ASN.1. There are no bits-on-the-wire changes to any of the formats; this is simply a change to the syntax. This document is not an Internet Standards Track specification; it is published for informational purposes.</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="5911"/>
          <seriesInfo name="DOI" value="10.17487/RFC5911"/>
        </reference>
        <reference anchor="RFC5280">
          <front>
            <title>Internet X.509 Public Key Infrastructure Certificate and Certificate Revocation List (CRL) Profile</title>
            <author fullname="D. Cooper" initials="D." surname="Cooper"/>
            <author fullname="S. Santesson" initials="S." surname="Santesson"/>
            <author fullname="S. Farrell" initials="S." surname="Farrell"/>
            <author fullname="S. Boeyen" initials="S." surname="Boeyen"/>
            <author fullname="R. Housley" initials="R." surname="Housley"/>
            <author fullname="W. Polk" initials="W." surname="Polk"/>
            <date month="May" year="2008"/>
            <abstract>
              <t>This memo profiles the X.509 v3 certificate and X.509 v2 certificate revocation list (CRL) for use in the Internet. An overview of this approach and model is provided as an introduction. The X.509 v3 certificate format is described in detail, with additional information regarding the format and semantics of Internet name forms. Standard certificate extensions are described and two Internet-specific extensions are defined. A set of required certificate extensions is specified. The X.509 v2 CRL format is described in detail along with standard and Internet-specific extensions. An algorithm for X.509 certification path validation is described. An ASN.1 module and examples are provided in the appendices. [STANDARDS-TRACK]</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="5280"/>
          <seriesInfo name="DOI" value="10.17487/RFC5280"/>
        </reference>
        <reference anchor="RFC8391">
          <front>
            <title>XMSS: eXtended Merkle Signature Scheme</title>
            <author fullname="A. Huelsing" initials="A." surname="Huelsing"/>
            <author fullname="D. Butin" initials="D." surname="Butin"/>
            <author fullname="S. Gazdag" initials="S." surname="Gazdag"/>
            <author fullname="J. Rijneveld" initials="J." surname="Rijneveld"/>
            <author fullname="A. Mohaisen" initials="A." surname="Mohaisen"/>
            <date month="May" year="2018"/>
            <abstract>
              <t>This note describes the eXtended Merkle Signature Scheme (XMSS), a hash-based digital signature system that is based on existing descriptions in scientific literature. This note specifies Winternitz One-Time Signature Plus (WOTS+), a one-time signature scheme; XMSS, a single-tree scheme; and XMSS^MT, a multi-tree variant of XMSS. Both XMSS and XMSS^MT use WOTS+ as a main building block. XMSS provides cryptographic digital signatures without relying on the conjectured hardness of mathematical problems. Instead, it is proven that it only relies on the properties of cryptographic hash functions. XMSS provides strong security guarantees and is even secure when the collision resistance of the underlying hash function is broken. It is suitable for compact implementations, is relatively simple to implement, and naturally resists side-channel attacks. Unlike most other signature systems, hash-based signatures can so far withstand known attacks using quantum computers.</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="8391"/>
          <seriesInfo name="DOI" value="10.17487/RFC8391"/>
        </reference>
        <reference anchor="RFC8554">
          <front>
            <title>Leighton-Micali Hash-Based Signatures</title>
            <author fullname="D. McGrew" initials="D." surname="McGrew"/>
            <author fullname="M. Curcio" initials="M." surname="Curcio"/>
            <author fullname="S. Fluhrer" initials="S." surname="Fluhrer"/>
            <date month="April" year="2019"/>
            <abstract>
              <t>This note describes a digital-signature system based on cryptographic hash functions, following the seminal work in this area of Lamport, Diffie, Winternitz, and Merkle, as adapted by Leighton and Micali in 1995. It specifies a one-time signature scheme and a general signature scheme. These systems provide asymmetric authentication without using large integer mathematics and can achieve a high security level. They are suitable for compact implementations, are relatively simple to implement, and are naturally resistant to side-channel attacks. Unlike many other signature systems, hash-based signatures would still be secure even if it proves feasible for an attacker to build a quantum computer.</t>
              <t>This document is a product of the Crypto Forum Research Group (CFRG) in the IRTF. This has been reviewed by many researchers, both in the research group and outside of it. The Acknowledgements section lists many of them.</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="8554"/>
          <seriesInfo name="DOI" value="10.17487/RFC8554"/>
        </reference>
        <reference anchor="SP800208" target="https://doi.org/10.6028/NIST.SP.800-208">
          <front>
            <title>Recommendation for Stateful Hash-Based Signature Schemes</title>
            <author initials="" surname="National Institute of Standards and Technology (NIST)">
              <organization/>
            </author>
            <date year="2020" month="October" day="29"/>
          </front>
        </reference>
        <reference anchor="RFC2119">
          <front>
            <title>Key words for use in RFCs to Indicate Requirement Levels</title>
            <author fullname="S. Bradner" initials="S." surname="Bradner"/>
            <date month="March" year="1997"/>
            <abstract>
              <t>In many standards track documents several words are used to signify the requirements in the specification. These words are often capitalized. This document defines these words as they should be interpreted in IETF documents. This document specifies an Internet Best Current Practices for the Internet Community, and requests discussion and suggestions for improvements.</t>
            </abstract>
          </front>
          <seriesInfo name="BCP" value="14"/>
          <seriesInfo name="RFC" value="2119"/>
          <seriesInfo name="DOI" value="10.17487/RFC2119"/>
        </reference>
        <reference anchor="RFC8174">
          <front>
            <title>Ambiguity of Uppercase vs Lowercase in RFC 2119 Key Words</title>
            <author fullname="B. Leiba" initials="B." surname="Leiba"/>
            <date month="May" year="2017"/>
            <abstract>
              <t>RFC 2119 specifies common key words that may be used in protocol specifications. This document aims to reduce the ambiguity by clarifying that only UPPERCASE usage of the key words have the defined special meanings.</t>
            </abstract>
          </front>
          <seriesInfo name="BCP" value="14"/>
          <seriesInfo name="RFC" value="8174"/>
          <seriesInfo name="DOI" value="10.17487/RFC8174"/>
        </reference>
      </references>
      <references anchor="sec-informative-references">
        <name>Informative References</name>
        <reference anchor="RFC3279">
          <front>
            <title>Algorithms and Identifiers for the Internet X.509 Public Key Infrastructure Certificate and Certificate Revocation List (CRL) Profile</title>
            <author fullname="L. Bassham" initials="L." surname="Bassham"/>
            <author fullname="W. Polk" initials="W." surname="Polk"/>
            <author fullname="R. Housley" initials="R." surname="Housley"/>
            <date month="April" year="2002"/>
            <abstract>
              <t>This document specifies algorithm identifiers and ASN.1 encoding formats for digital signatures and subject public keys used in the Internet X.509 Public Key Infrastructure (PKI). Digital signatures are used to sign certificates and certificate revocation list (CRLs). Certificates include the public key of the named subject. [STANDARDS-TRACK]</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="3279"/>
          <seriesInfo name="DOI" value="10.17487/RFC3279"/>
        </reference>
        <reference anchor="RFC3647">
          <front>
            <title>Internet X.509 Public Key Infrastructure Certificate Policy and Certification Practices Framework</title>
            <author fullname="S. Chokhani" initials="S." surname="Chokhani"/>
            <author fullname="W. Ford" initials="W." surname="Ford"/>
            <author fullname="R. Sabett" initials="R." surname="Sabett"/>
            <author fullname="C. Merrill" initials="C." surname="Merrill"/>
            <author fullname="S. Wu" initials="S." surname="Wu"/>
            <date month="November" year="2003"/>
            <abstract>
              <t>This document presents a framework to assist the writers of certificate policies or certification practice statements for participants within public key infrastructures, such as certification authorities, policy authorities, and communities of interest that wish to rely on certificates. In particular, the framework provides a comprehensive list of topics that potentially (at the writer's discretion) need to be covered in a certificate policy or a certification practice statement. This document supersedes RFC 2527.</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="3647"/>
          <seriesInfo name="DOI" value="10.17487/RFC3647"/>
        </reference>
        <reference anchor="RFC4949">
          <front>
            <title>Internet Security Glossary, Version 2</title>
            <author fullname="R. Shirey" initials="R." surname="Shirey"/>
            <date month="August" year="2007"/>
            <abstract>
              <t>This Glossary provides definitions, abbreviations, and explanations of terminology for information system security. The 334 pages of entries offer recommendations to improve the comprehensibility of written material that is generated in the Internet Standards Process (RFC 2026). The recommendations follow the principles that such writing should (a) use the same term or definition whenever the same concept is mentioned; (b) use terms in their plainest, dictionary sense; (c) use terms that are already well-established in open publications; and (d) avoid terms that either favor a particular vendor or favor a particular technology or mechanism over other, competing techniques that already exist or could be developed. This memo provides information for the Internet community.</t>
            </abstract>
          </front>
          <seriesInfo name="FYI" value="36"/>
          <seriesInfo name="RFC" value="4949"/>
          <seriesInfo name="DOI" value="10.17487/RFC4949"/>
        </reference>
        <reference anchor="RFC8410">
          <front>
            <title>Algorithm Identifiers for Ed25519, Ed448, X25519, and X448 for Use in the Internet X.509 Public Key Infrastructure</title>
            <author fullname="S. Josefsson" initials="S." surname="Josefsson"/>
            <author fullname="J. Schaad" initials="J." surname="Schaad"/>
            <date month="August" year="2018"/>
            <abstract>
              <t>This document specifies algorithm identifiers and ASN.1 encoding formats for elliptic curve constructs using the curve25519 and curve448 curves. The signature algorithms covered are Ed25519 and Ed448. The key agreement algorithms covered are X25519 and X448. The encoding for public key, private key, and Edwards-curve Digital Signature Algorithm (EdDSA) structures is provided.</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="8410"/>
          <seriesInfo name="DOI" value="10.17487/RFC8410"/>
        </reference>
        <reference anchor="RFC8411">
          <front>
            <title>IANA Registration for the Cryptographic Algorithm Object Identifier Range</title>
            <author fullname="J. Schaad" initials="J." surname="Schaad"/>
            <author fullname="R. Andrews" initials="R." surname="Andrews"/>
            <date month="August" year="2018"/>
            <abstract>
              <t>When the Curdle Security Working Group was chartered, a range of object identifiers was donated by DigiCert, Inc. for the purpose of registering the Edwards Elliptic Curve key agreement and signature algorithms. This donated set of OIDs allowed for shorter values than would be possible using the existing S/MIME or PKIX arcs. This document describes the donated range and the identifiers that were assigned from that range, transfers control of that range to IANA, and establishes IANA allocation policies for any future assignments within that range.</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="8411"/>
          <seriesInfo name="DOI" value="10.17487/RFC8411"/>
        </reference>
        <reference anchor="MCGREW" target="https://eprint.iacr.org/2016/357">
          <front>
            <title>State Management for Hash-Based Signatures</title>
            <author initials="D." surname="McGrew">
              <organization/>
            </author>
            <author initials="P." surname="Kampanakis">
              <organization/>
            </author>
            <author initials="S." surname="Fluhrer">
              <organization/>
            </author>
            <author initials="S." surname="Gazdag">
              <organization/>
            </author>
            <author initials="D." surname="Butin">
              <organization/>
            </author>
            <author initials="J." surname="Buchmann">
              <organization/>
            </author>
            <date year="2016" month="November" day="02"/>
          </front>
        </reference>
        <reference anchor="BH16" target="https://eprint.iacr.org/2016/1042.pdf">
          <front>
            <title>Oops, I did it again – Security of One-Time Signatures under Two-Message Attacks.</title>
            <author initials="L." surname="Bruinderink">
              <organization/>
            </author>
            <author initials="S." surname="Hülsing">
              <organization/>
            </author>
            <date year="2016"/>
          </front>
        </reference>
        <reference anchor="CNSA2.0" target="https://media.defense.gov/2022/Sep/07/2003071834/-1/-1/0/CSA_CNSA_2.0_ALGORITHMS_.PDF">
          <front>
            <title>Commercial National Security Algorithm Suite 2.0 (CNSA 2.0) Cybersecurity Advisory (CSA)</title>
            <author initials="" surname="National Security Agency (NSA)">
              <organization/>
            </author>
            <date year="2022" month="September" day="07"/>
          </front>
        </reference>
        <reference anchor="ETSI-TR-103-692" target="https://www.etsi.org/deliver/etsi_tr/103600_103699/103692/01.01.01_60/tr_103692v010101p.pdf">
          <front>
            <title>State management for stateful authentication mechanisms</title>
            <author initials="" surname="European Telecommunications Standards Institute (ETSI)">
              <organization/>
            </author>
            <date year="2021" month="November"/>
          </front>
        </reference>
        <reference anchor="IANA-LMS" target="https://www.iana.org/assignments/leighton-micali-signatures/">
          <front>
            <title>Leighton-Micali Signatures (LMS)</title>
            <author initials="" surname="IANA">
              <organization/>
            </author>
            <date>n.d.</date>
          </front>
        </reference>
        <reference anchor="IANA-XMSS" target="https://iana.org/assignments/xmss-extended-hash-based-signatures/">
          <front>
            <title>XMSS: Extended Hash-Based Signatures</title>
            <author initials="" surname="IANA">
              <organization/>
            </author>
            <date>n.d.</date>
          </front>
        </reference>
        <reference anchor="SMI-PKIX" target="https://www.iana.org/assignments/smi-numbers/smi-numbers.xhtml#smi-numbers-1.3.6.1.5.5.7.6">
          <front>
            <title>SMI Security for PKIX Algorithms</title>
            <author initials="" surname="IANA">
              <organization/>
            </author>
            <date>n.d.</date>
          </front>
        </reference>
        <reference anchor="ANSSI" target="https://cyber.gouv.fr/sites/default/files/document/follow_up_position_paper_on_post_quantum_cryptography.pdf">
          <front>
            <title>ANSSI views on the Post-Quantum Cryptography transition (2023 follow up)</title>
            <author initials="" surname="Agence nationale de la sécurité des systèmes d'information (ANSSI)">
              <organization/>
            </author>
            <date year="2023" month="December" day="21"/>
          </front>
        </reference>
        <reference anchor="BSI" target="https://www.bsi.bund.de/SharedDocs/Downloads/EN/BSI/Publications/Brochure/quantum-safe-cryptography.pdf">
          <front>
            <title>Quantum-safe cryptography – fundamentals, current developments and recommendations</title>
            <author initials="" surname="Bundesamt für Sicherheit in der Informationstechnik (BSI)">
              <organization/>
            </author>
            <date year="2022" month="May" day="18"/>
          </front>
        </reference>
      </references>
    </references>
    <?line 636?>

<section anchor="hss-x509-v3-certificate-example">
      <name>HSS X.509 v3 Certificate Example</name>
      <t>This section shows a self-signed X.509 v3 certificate using HSS.</t>
      <artwork><![CDATA[
Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number:
            e8:91:d6:06:91:4f:ce:f3
        Signature Algorithm: hss
        Issuer: C = US, ST = VA, L = Herndon, O = Bogus CA
        Validity
            Not Before: May 14 08:58:11 2024 GMT
            Not After : May 14 08:58:11 2034 GMT
        Subject: C = US, ST = VA, L = Herndon, O = Bogus CA
        Subject Public Key Info:
            Public Key Algorithm: hss
                hss public key:
                PQ key material:
                    00:00:00:01:00:00:00:05:00:00:00:04:c0:96:12:
                    8b:ea:38:30:78:eb:f6:fb:43:d7:7f:9f:9e:81:39:
                    e2:7c:b9:34:4e:6e:53:19:f0:ee:68:75:85:83:d3:
                    2b:e9:7b:14:46:9e:4e:c5:e3:5a:18:0b:30:e5:13
        X509v3 extensions:
            X509v3 Subject Key Identifier:
                58:15:AB:F4:CF:03:69:02:60:7A:57:4D:C5:D5:B3:72:
                8A:19:21:68
            X509v3 Authority Key Identifier:
                58:15:AB:F4:CF:03:69:02:60:7A:57:4D:C5:D5:B3:72:
                8A:19:21:68
            X509v3 Basic Constraints: critical
                CA:TRUE
            X509v3 Key Usage: critical
                Certificate Sign, CRL Sign
    Signature Algorithm: hss
    Signature Value:
        00:00:00:00:00:00:00:00:00:00:00:04:9c:37:52:ff:b9:d7:
        df:f5:5b:01:ba:50:c2:50:cc:6f:f3:b1:73:df:0c:2a:ea:b3:
        ed:96:1e:ce:e7:58:05:da:8d:a7:77:21:42:32:d9:f9:4a:4d:
        f7:2b:18:2a:1c:5c:69:03:f3:1c:9c:95:6d:31:9a:c9:ca:84:
        4d:ae:b3:8b:c3:71:ac:3f:87:51:be:38:b4:bf:d9:dc:90:1f:
        1e:54:bd:f9:1a:65:70:d4:46:b6:ad:4d:6d:16:b9:fb:29:f4:
        e3:86:42:4a:3f:a4:8f:01:84:9b:44:0b:23:22:9c:97:6d:d5:
        b9:26:39:11:ab:46:82:bd:10:6c:b4:7a:64:ed:c7:40:b0:33:
        f0:b5:81:1c:b4:41:54:9c:30:d9:d2:93:ba:48:8c:4f:d0:25:
        41:60:7b:90:5e:12:20:b7:30:16:16:1e:b7:ee:d8:4b:ee:ed:
        3c:70:fc:ff:36:18:aa:24:23:87:91:65:a8:95:2d:b6:1c:d1:
        02:7b:70:81:8a:18:17:c0:45:62:fe:47:a1:3e:69:54:31:67:
        58:9a:e1:e3:c9:8d:ee:1e:2a:d1:46:75:e9:e4:90:67:01:57:
        92:54:db:b4:ea:de:8b:e7:eb:fc:27:80:9b:d5:da:e0:8e:b0:
        b3:08:ca:6f:a1:1c:f4:40:65:b0:f6:f8:c9:a7:97:04:c8:7c:
        9e:56:ec:2f:4b:cd:45:8b:d7:e6:a7:50:c7:e6:21:2c:17:31:
        23:11:7a:ae:9a:b5:84:5f:e6:5c:82:99:a8:3a:a9:91:87:9a:
        24:5c:83:01:91:7c:fc:cd:be:2e:92:50:fb:12:11:96:08:0d:
        c9:24:0d:bb:6f:fb:59:05:af:7f:96:bc:a3:f4:58:e2:fa:0a:
        4a:f2:4c:f7:b3:1b:81:dd:4a:41:a0:b1:dd:52:4c:bb:6d:c0:
        a8:d9:bb:29:c8:fc:e3:7e:f8:6a:e5:5e:c4:e4:e8:7c:0b:00:
        87:15:75:a2:06:50:97:c6:1f:14:52:79:04:a8:9c:ec:b1:c7:
        6a:46:33:98:b8:63:f7:a7:2c:d4:62:78:94:1c:5d:9d:4f:a6:
        0a:ae:39:50:85:b2:09:8d:62:c9:4c:11:9f:0c:91:a5:ac:2d:
        11:bd:71:b6:0c:ea:34:98:53:fc:2e:cc:7b:a4:9c:2e:7a:a4:
        8d:e2:e8:8c:01:a9:9c:3e:b5:34:77:33:82:01:d4:ef:72:04:
        d6:5b:e5:f6:2c:1b:ae:86:c4:73:02:44:85:d6:f7:ac:a3:e8:
        f6:a9:b5:5c:6d:46:88:da:55:b8:2b:7a:4c:0c:9a:e7:cd:5d:
        62:8a:ca:c8:96:ce:8d:71:7b:d2:c1:0d:9a:35:55:2b:84:3e:
        0e:a5:fa:d6:a0:76:8e:23:b3:df:c9:3b:4f:68:56:1e:e9:3c:
        79:5b:d3:25:54:11:ad:a6:ac:58:11:49:8f:4d:c4:c1:39:99:
        76:3a:a6:d1:2f:57:ad:bf:7c:9d:57:cc:37:0d:29:84:29:7b:
        cb:46:85:c3:81:c5:33:9a:65:c3:2f:01:48:ca:44:6c:f1:84:
        3d:d0:49:c2:c1:05:db:77:4c:b9:72:3d:6f:ce:69:f2:91:c6:
        15:25:8f:da:38:7e:ef:5b:3e:5f:35:ab:a6:78:16:28:42:c1:
        2c:2f:9e:11:53:2c:bd:c4:24:7b:e9:c4:ce:3d:d6:41:c7:5d:
        92:91:c3:37:cb:72:44:d7:0d:70:85:13:0b:ac:b3:0f:b0:e5:
        e3:2e:48:b9:9c:b8:d7:3e:7c:50:69:03:7a:5f:ae:f8:6c:09:
        61:97:6b:ce:cd:e5:f0:55:fe:05:f8:97:1d:9e:81:65:f5:ff:
        9a:7a:8c:96:d8:f8:cf:d8:dc:55:ce:67:7a:00:6b:fd:bb:3f:
        1b:3d:65:94:c1:5a:b6:a0:8e:be:a4:be:26:90:5f:1f:06:d4:
        ea:3f:a6:97:40:8e:bf:18:5c:92:0f:15:e3:05:4a:14:51:1e:
        23:81:ef:cf:f7:a8:88:75:f8:2d:28:37:26:87:27:63:5c:01:
        53:0e:5e:53:d2:a7:18:eb:2f:c0:82:49:05:b0:4d:33:6f:94:
        10:91:77:f8:90:9e:ca:fe:bb:3d:c4:42:d6:89:84:98:42:f4:
        24:b3:b4:db:5e:2b:66:a9:ff:6c:18:d4:79:f8:72:73:53:9b:
        02:ed:04:73:77:a4:68:cf:4b:be:4b:16:50:62:87:f9:49:99:
        e3:a1:0c:42:92:bc:a9:e3:2d:22:82:35:7f:71:15:88:70:6a:
        01:ab:44:64:ad:e5:52:d4:97:ee:bb:44:7b:6e:08:7f:dd:94:
        fd:c9:1c:6b:59:d1:92:51:29:03:ce:ec:bf:41:a5:14:69:54:
        3a:b4:39:d9:44:5d:f1:b2:f4:5c:6b:9f:c9:5f:bb:fc:c8:c7:
        a3:8b:e1:ec:e2:d0:69:5a:40:1c:9c:9d:8a:3d:77:3b:c1:5d:
        c0:72:61:4b:37:c5:96:8c:6d:8b:f8:56:da:ac:3e:3c:72:09:
        ce:f6:c3:fe:5d:cf:37:d9:68:cd:a7:dd:f7:96:63:da:8c:1d:
        df:b8:32:cf:eb:97:11:83:fe:6b:aa:b9:e2:4b:b2:ea:62:73:
        c3:1c:e9:40:90:56:4f:12:c3:ba:f4:2b:d9:1c:50:cc:e0:51:
        d8:eb:bf:67:28:0c:2d:13:8d:b3:6f:13:6a:1d:a7:54:20:ba:
        82:5b:b8:e5:1f:89:f1:67:26:c1:dc:1b:60:57:ed:a6:2c:f2:
        17:01:7f:a5:e7:5c:64:c9:3c:08:f2:cf:48:ec:88:84:ef:03:
        c2:f5:eb:05:31:7d:fe:7f:3c:71:41:28:17:64:5f:b9:ec:54:
        79:d0:b3:98:fb:84:9c:36:8b:43:0b:d4:c9:ec:09:4a:70:13:
        62:f2:36:c8:b4:75:cc:2a:77:08:a0:9d:ef:19:d6:88:dc:e2:
        b2:4e:40:61:71:cb:c7:c3:de:16:6f:49:7f:5e:d5:17:00:00:
        00:05:79:47:12:9f:ce:eb:1d:a8:fd:0d:b0:18:44:6a:ef:54:
        28:46:e4:19:f6:2d:3e:74:bb:9d:36:0a:ae:67:4a:28:7a:1b:
        80:39:a0:08:2a:28:a0:ec:55:ee:55:aa:a1:cc:94:d4:36:1a:
        b3:57:25:30:ad:2c:5e:63:ba:22:fc:aa:7a:59:64:f6:d8:03:
        20:28:71:f9:dc:09:fa:4c:81:b9:64:1b:ad:ea:cb:db:18:17:
        5d:d8:98:bd:d2:8d:c5:04:7c:5b:92:9a:89:f6:bc:d6:55:c7:
        08:5d:3c:58:8e:18:ac:6f:88:a8:d7:9e:d4:ee:5d:f5:21:4e:
        a5:8b:19:5f:e3:f4:66:f9:25:4d:f9:c6:60:62:31:72:5c:34:
        34:67:1a:a7:6a:7d:54:a3:d8:9b:1f:5b:f8:08:41:79:5b:43
]]></artwork>
      <artwork><![CDATA[
-----BEGIN CERTIFICATE-----
MIIGnjCCAXagAwIBAgIJAOiR1gaRT87zMA0GCyqGSIb3DQEJEAMRMD8xCzAJBgNV
BAYTAlVTMQswCQYDVQQIDAJWQTEQMA4GA1UEBwwHSGVybmRvbjERMA8GA1UECgwI
Qm9ndXMgQ0EwHhcNMjQwNTE0MDg1ODExWhcNMzQwNTE0MDg1ODExWjA/MQswCQYD
VQQGEwJVUzELMAkGA1UECAwCVkExEDAOBgNVBAcMB0hlcm5kb24xETAPBgNVBAoM
CEJvZ3VzIENBME4wDQYLKoZIhvcNAQkQAxEDPQAAAAABAAAABQAAAATAlhKL6jgw
eOv2+0PXf5+egTnifLk0Tm5TGfDuaHWFg9Mr6XsURp5OxeNaGAsw5ROjYzBhMB0G
A1UdDgQWBBRYFav0zwNpAmB6V03F1bNyihkhaDAfBgNVHSMEGDAWgBRYFav0zwNp
AmB6V03F1bNyihkhaDAPBgNVHRMBAf8EBTADAQH/MA4GA1UdDwEB/wQEAwIBBjAN
BgsqhkiG9w0BCRADEQOCBREAAAAAAAAAAAAAAAAEnDdS/7nX3/VbAbpQwlDMb/Ox
c98MKuqz7ZYezudYBdqNp3chQjLZ+UpN9ysYKhxcaQPzHJyVbTGaycqETa6zi8Nx
rD+HUb44tL/Z3JAfHlS9+RplcNRGtq1NbRa5+yn044ZCSj+kjwGEm0QLIyKcl23V
uSY5EatGgr0QbLR6ZO3HQLAz8LWBHLRBVJww2dKTukiMT9AlQWB7kF4SILcwFhYe
t+7YS+7tPHD8/zYYqiQjh5FlqJUtthzRAntwgYoYF8BFYv5HoT5pVDFnWJrh48mN
7h4q0UZ16eSQZwFXklTbtOrei+fr/CeAm9Xa4I6wswjKb6Ec9EBlsPb4yaeXBMh8
nlbsL0vNRYvX5qdQx+YhLBcxIxF6rpq1hF/mXIKZqDqpkYeaJFyDAZF8/M2+LpJQ
+xIRlggNySQNu2/7WQWvf5a8o/RY4voKSvJM97Mbgd1KQaCx3VJMu23AqNm7Kcj8
4374auVexOTofAsAhxV1ogZQl8YfFFJ5BKic7LHHakYzmLhj96cs1GJ4lBxdnU+m
Cq45UIWyCY1iyUwRnwyRpawtEb1xtgzqNJhT/C7Me6ScLnqkjeLojAGpnD61NHcz
ggHU73IE1lvl9iwbrobEcwJEhdb3rKPo9qm1XG1GiNpVuCt6TAya581dYorKyJbO
jXF70sENmjVVK4Q+DqX61qB2jiOz38k7T2hWHuk8eVvTJVQRraasWBFJj03EwTmZ
djqm0S9Xrb98nVfMNw0phCl7y0aFw4HFM5plwy8BSMpEbPGEPdBJwsEF23dMuXI9
b85p8pHGFSWP2jh+71s+XzWrpngWKELBLC+eEVMsvcQke+nEzj3WQcddkpHDN8ty
RNcNcIUTC6yzD7Dl4y5IuZy41z58UGkDel+u+GwJYZdrzs3l8FX+BfiXHZ6BZfX/
mnqMltj4z9jcVc5negBr/bs/Gz1llMFatqCOvqS+JpBfHwbU6j+ml0COvxhckg8V
4wVKFFEeI4Hvz/eoiHX4LSg3JocnY1wBUw5eU9KnGOsvwIJJBbBNM2+UEJF3+JCe
yv67PcRC1omEmEL0JLO0214rZqn/bBjUefhyc1ObAu0Ec3ekaM9LvksWUGKH+UmZ
46EMQpK8qeMtIoI1f3EViHBqAatEZK3lUtSX7rtEe24If92U/ckca1nRklEpA87s
v0GlFGlUOrQ52URd8bL0XGufyV+7/MjHo4vh7OLQaVpAHJydij13O8FdwHJhSzfF
loxti/hW2qw+PHIJzvbD/l3PN9lozafd95Zj2owd37gyz+uXEYP+a6q54kuy6mJz
wxzpQJBWTxLDuvQr2RxQzOBR2Ou/ZygMLRONs28Tah2nVCC6glu45R+J8Wcmwdwb
YFftpizyFwF/pedcZMk8CPLPSOyIhO8DwvXrBTF9/n88cUEoF2RfuexUedCzmPuE
nDaLQwvUyewJSnATYvI2yLR1zCp3CKCd7xnWiNzisk5AYXHLx8PeFm9Jf17VFwAA
AAV5RxKfzusdqP0NsBhEau9UKEbkGfYtPnS7nTYKrmdKKHobgDmgCCoooOxV7lWq
ocyU1DYas1clMK0sXmO6Ivyqellk9tgDIChx+dwJ+kyBuWQbrerL2xgXXdiYvdKN
xQR8W5Kaifa81lXHCF08WI4YrG+IqNee1O5d9SFOpYsZX+P0ZvklTfnGYGIxclw0
NGcap2p9VKPYmx9b+AhBeVtD
-----END CERTIFICATE-----
]]></artwork>
    </section>
    <section anchor="xmss-x509-v3-certificate-example">
      <name>XMSS X.509 v3 Certificate Example</name>
      <t>This section shows a self-signed X.509 v3 certificate using XMSS.</t>
      <artwork><![CDATA[
Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number:
            54:7e:64:70:29:9e:03:c5:7a:a5:5c:78:d1:27:87:8c:
            54:35:17:5d
        Signature Algorithm: xmss
        Issuer: C = FR, L = Paris, O = Bogus XMSS CA
        Validity
            Not Before: Jul 10 08:27:24 2024 GMT
            Not After : Jul  8 08:27:24 2034 GMT
        Subject: C = FR, L = Paris, O = Bogus XMSS CA
        Subject Public Key Info:
            Public Key Algorithm: xmss
                xmss public key:
                PQ key material:
                    00:00:00:01:2b:eb:bf:66:14:de:6f:96:5b:4d:2a:
                    50:00:7b:ad:5c:22:b0:13:79:72:02:14:a9:5f:fc:
                    96:e0:9b:78:8e:d6:be:8c:1c:70:3c:d8:dd:78:b2:
                    1a:14:47:be:1f:0d:74:72:3f:36:76:c2:cb:19:ad:
                    29:90:0b:82:de:9b:7f:df
        X509v3 extensions:
            X509v3 Subject Key Identifier:
                62:CE:35:A5:47:77:FF:21:87:2E:BC:2D:27:E7:8E:F4:
                35:6B:CF:D8
            X509v3 Authority Key Identifier:
                62:CE:35:A5:47:77:FF:21:87:2E:BC:2D:27:E7:8E:F4:
                35:6B:CF:D8
            X509v3 Basic Constraints: critical
                CA:TRUE
            X509v3 Key Usage: critical
                Certificate Sign, CRL Sign
    Signature Algorithm: xmss
    Signature Value:
        00:00:00:00:e5:88:a8:b8:73:ad:4d:92:f8:5c:81:c5:8a:63:
        57:6a:a7:3b:54:aa:b6:06:8a:d9:f1:c2:0b:c8:27:1e:4b:a2:
        cf:e2:da:44:ea:e8:f2:40:a8:b9:54:9c:49:36:12:24:df:74:
        ad:e5:29:ef:4f:da:88:0d:21:5d:3b:64:63:27:d0:84:b5:95:
        7a:30:18:37:cd:34:17:dd:ac:9d:9e:48:db:74:07:79:84:21:
        5a:f0:26:cd:21:64:7b:77:33:48:58:67:9b:2c:b2:85:6d:cc:
        ec:31:4b:2f:51:55:3a:85:e1:ca:04:15:ce:6e:47:39:f5:e9:
        31:45:41:ed:71:c6:4f:96:f5:ae:64:6a:bd:72:d0:8c:17:02:
        99:10:1d:14:34:ca:e5:47:e3:f7:66:96:96:11:d5:97:76:76:
        83:f1:84:a5:b6:00:5e:3e:67:97:7a:32:dc:c8:eb:4c:29:46:
        77:99:d6:da:45:e6:7b:8c:45:6d:b5:29:6b:fd:98:a2:89:8d:
        0c:30:42:f5:0b:7c:97:c5:b1:1d:e2:da:67:a9:48:a4:9e:29:
        f4:60:3f:4d:1d:48:83:82:38:ef:fa:cb:1d:86:11:a1:15:94:
        fb:d5:ee:68:f9:44:b9:3d:54:70:f3:be:17:8d:d7:2e:85:2d:
        5c:d0:a0:c5:99:52:cc:79:e7:1c:18:d9:6e:3d:0f:6c:05:51:
        33:28:35:e2:02:59:5f:1f:ed:78:0a:c6:62:f0:7d:fe:73:96:
        03:4c:b4:42:e3:00:c2:d7:cb:eb:51:10:c4:0c:64:b8:37:fe:
        85:d0:8e:11:6d:a6:16:77:b1:1e:01:d9:1e:f3:10:9c:dd:01:
        bc:38:75:5e:8f:58:9e:5b:6c:7b:0a:41:08:59:35:a9:3a:83:
        19:e0:7d:a1:f5:cf:a3:1c:4e:07:e1:ad:03:95:f2:d3:8b:79:
        33:f8:52:22:53:1b:1e:32:9a:61:3f:c4:7c:9a:e8:d5:b5:28:
        f1:84:65:d5:c1:fc:4d:16:93:88:93:69:ca:fa:94:a0:95:4e:
        23:ae:1e:60:e0:e8:b4:bf:ff:16:95:71:0f:31:74:bb:be:b8:
        5a:eb:24:95:8b:95:28:13:cd:e3:a9:65:f7:f5:6e:9b:a9:a9:
        7a:05:ce:ab:f0:54:62:d9:12:f8:a1:1a:68:df:af:15:8f:8a:
        df:67:27:c9:ed:bd:e1:81:a6:8d:9a:84:f3:91:36:d9:89:74:
        8e:ef:84:dc:5c:03:1a:08:e4:d7:f0:72:fc:6d:8a:01:34:94:
        e5:ff:08:51:1b:80:5f:e7:07:d8:9f:25:e4:1d:c3:f8:e5:d0:
        9c:50:cf:66:71:f9:cc:f7:c0:a7:d0:66:01:b7:17:a0:5f:66:
        97:a4:ff:62:ac:1c:a0:63:0d:30:28:e9:90:d5:59:a4:48:d8:
        07:87:02:4b:3f:68:23:a5:04:dc:b3:d7:45:f6:dc:b0:ec:c6:
        90:a6:1c:a1:f8:7e:84:ba:63:7e:5a:64:14:78:58:f5:75:c0:
        f5:e1:1d:bd:49:57:c0:40:08:07:99:7f:43:2e:e2:25:d8:ed:
        a3:1a:e3:78:f1:78:af:02:49:54:36:59:8e:d3:72:a5:0b:52:
        32:bd:17:a2:cf:e1:47:21:28:3d:ba:b6:24:d9:18:f9:44:73:
        35:ed:29:a4:18:bc:ed:68:cd:4a:9a:34:cb:1a:2f:b3:5f:ba:
        73:9b:18:ee:7a:a8:92:25:65:25:81:04:63:1c:22:2b:b8:ba:
        81:21:bc:f9:9d:a8:78:98:75:bc:ed:4a:c6:b7:6f:c0:91:24:
        eb:1d:f9:5d:e0:e3:78:4e:05:f6:34:0f:7b:41:54:49:20:a2:
        30:66:94:f1:da:c1:6c:3f:5e:10:92:92:a3:0c:7e:e8:8b:26:
        11:1c:d7:68:c9:31:79:b3:a4:d5:63:00:68:c3:e3:86:2d:09:
        92:4b:2d:63:7d:b8:03:a4:4c:60:b4:2c:12:d5:0b:9f:16:28:
        ea:88:2f:bb:1c:19:0b:0f:40:3d:67:e8:0b:fa:c6:e3:39:44:
        b2:bd:8a:3f:21:dd:aa:ec:a3:8c:48:dd:4c:99:43:86:d7:48:
        81:6b:e5:b9:bb:59:9f:1c:0f:3f:11:f7:7c:4b:67:a8:95:c2:
        7c:cb:3b:66:b0:79:a6:55:6f:6d:b0:29:8a:5e:7b:ee:30:68:
        f3:dd:41:29:91:f6:79:71:ae:8d:21:70:78:1d:5d:d2:f7:cf:
        e7:42:38:d1:8c:52:a6:a6:f6:b1:38:b1:2b:23:81:e1:1f:21:
        6d:99:3f:10:eb:b1:a9:73:b8:3e:31:99:cc:dd:2b:df:58:27:
        db:0b:5a:29:99:8f:b1:9f:e9:31:42:d0:26:db:53:b7:7e:30:
        41:95:c3:f0:07:83:bb:b0:63:b5:16:48:f2:a6:60:2f:32:5d:
        22:a1:da:76:4e:37:26:53:0d:95:7b:2d:b9:05:2f:93:2b:d4:
        df:c1:02:5b:f7:a5:a2:4f:11:5c:80:f4:f0:bd:c7:ea:3c:db:
        6f:e2:eb:6c:7f:c3:58:d9:31:77:4b:4d:f7:ce:bb:d6:c8:64:
        a3:01:d5:f9:a4:8d:e8:f0:ee:09:06:2c:0b:3c:ac:0a:57:d8:
        e4:81:79:ea:4a:bd:51:03:88:4c:d0:4c:0b:c4:0c:7e:2d:e7:
        df:1b:67:62:c0:d1:9c:ad:bb:d3:f0:75:dd:83:aa:70:99:2c:
        19:78:3d:26:2b:47:6f:24:c1:60:02:1e:4b:75:04:91:1f:08:
        1c:b3:79:a0:9b:db:fb:5d:3f:c7:e3:09:1f:41:3e:64:bb:ad:
        19:3d:35:e1:a6:f4:69:0b:a2:04:37:42:95:c6:c7:e5:f4:56:
        0e:67:5b:78:34:bb:07:f1:8f:e7:73:5b:87:d7:df:c9:2d:8d:
        8c:42:76:87:15:85:4b:23:03:20:34:e1:1b:f6:0c:1e:84:53:
        d9:1b:4e:d9:31:43:38:3b:88:12:84:d8:2a:38:b1:ce:0f:c7:
        07:d4:63:2d:97:89:1c:b3:44:99:eb:d4:df:32:74:be:0d:63:
        11:22:fd:fa:8e:e2:0b:56:12:56:0c:46:16:ad:44:10:26:98:
        dc:cf:c9:95:67:3e:11:c1:76:fa:b8:12:ea:96:f6:d9:91:ac:
        bf:49:b9:1c:8e:15:05:53:ac:9e:04:d2:5b:b8:87:bf:81:50:
        f7:02:a4:c0:9c:18:0f:45:ac:7a:82:cf:46:15:42:40:09:32:
        89:a5:ea:90:a5:99:68:f9:93:0c:7b:d6:7a:a8:e9:51:e2:90:
        9e:b9:ed:21:db:d9:7e:de:dc:62:6b:44:6b:9f:81:c5:77:39:
        8e:1d:78:30:de:dc:53:80:e0:c3:fa:fa:94:68:28:91:98:86:
        ff:86:04:a9:bd:58:7c:31:37:1f:db:9a:29:f3:c1:48:10:20:
        71:5f:fc:35:13:eb:7b:12:e2:7d:1c:cc:97:fe:8f:5c:a2:dd:
        f6:d2:a3:b2:ea:51:b3:ef:b1:1e:79:0b:00:53:f4:f2:52:75:
        5a:d7:17:c5:31:a0:54:4e:2b:28:2c:4f:6b:7a:27:3a:2c:04:
        da:b3:1d:04:4e:a4:4e:94:5c:a8:91:70:ab:c0:4b:75:9f:b3:
        6a:a9:4e:8a:22:e9:7f:fd:ec:53:e7:6a:6d:32:0b:8b:ab:4c:
        e7:7d:72:ec:04:62:1c:1a:45:1e:33:8e:37:ae:6a:2f:c8:fb:
        f3:69:ed:11:01:f3:f4:57:e9:29:d5:3b:0c:9c:0c:c4:cb:c3:
        38:5c:01:e7:d6:31:c3:d8:ce:24:d7:be:71:9b:c8:96:13:ca:
        5c:5d:e4:92:40:af:86:a0:4b:ff:a7:55:39:70:fd:ac:0a:e1:
        87:c7:01:4b:c3:41:36:c6:c6:33:8f:4f:25:4a:8d:70:92:ac:
        7c:95:cc:49:a9:dc:d6:6a:67:52:a5:5b:7f:2f:bb:91:e3:be:
        d6:28:fc:22:d0:72:66:e8:09:73:a7:23:c6:a6:89:38:0b:e5:
        d0:b3:f1:40:38:9c:4d:17:96:11:17:44:ef:e3:94:51:91:4c:
        5d:fe:d9:ed:c3:76:a0:2d:3b:dc:8d:b9:31:15:f6:75:58:74:
        2f:57:b4:29:21:29:6d:5f:eb:06:71:0a:f4:db:ff:c6:2f:16:
        73:a7:76:6b:d0:5b:a7:21:5c:fd:f0:11:e8:6f:9b:d0:c9:c9:
        fe:35:76:4a:4a:63:9b:ba:48:ac:af:4f:91:67:9c:5c:47:d8:
        e3:2d:03:12:5e:f1:cb:56:34:75:69:95:ad:68:96:6c:e7:4a:
        91:72:fb:9b:ba:e8:92:56:fb:9a:5b:5d:3b:9d:d3:c5:c4:52:
        42:1b:f9:4a:47:42:dd:77:49:da:2b:bd:d7:94:5f:7b:b8:64:
        b9:06:32:7c:ea:d1:36:f6:95:b8:57:41:1b:6e:66:31:2c:ee:
        87:7a:5c:19:2f:d8:95:4a:16:93:48:f3:97:25:3d:24:61:1e:
        d0:63:37:ee:3a:c9:a3:46:c5:94:a0:7e:24:cc:7f:72:8d:14:
        9e:3c:33:ec:cd:9a:dd:b5:08:90:98:19:95:85:38:ff:ff:d2:
        1e:bf:a6:c4:97:13:2b:3d:47:e9:57:59:d3:7d:99:01:6e:53:
        4d:c0:82:97:fb:89:d6:7c:b7:23:0e:7d:6e:23:88:53:06:8f:
        16:ff:40:0a:1b:cd:d5:1e:91:01:3e:77:3a:5f:c1:57:3a:7b:
        c6:d5:51:d7:e2:ec:89:12:6b:9d:03:e4:9d:bb:7d:4e:02:bf:
        67:8d:03:ca:90:56:f0:9a:97:4b:02:2d:4c:31:89:82:76:97:
        fe:2f:d5:0a:3d:ea:0d:38:6c:30:75:5f:ae:91:53:d7:45:64:
        df:ba:0b:22:80:44:85:6d:0e:5c:29:7f:82:9e:54:a3:7a:95:
        be:96:79:66:9d:5b:a2:d6:2e:47:c6:99:7d:2b:32:dc:f2:b6:
        02:91:6d:63:d4:93:45:60:c4:42:71:10:9e:fb:90:2f:e6:75:
        71:ce:78:70:c1:da:ff:e1:47:fe:79:2b:8e:9a:81:bf:dd:02:
        e3:78:39:71:17:b3:23:14:11:9d:29:8e:21:a1:98:b0:ac:03:
        5a:6c:9e:62:64:ef:4f:03:ca:37:a6:ed:e4:78:d5:0d:99:29:
        f5:5c:61:e6:48:cb:97:0e:5e:f9:2c:f6:b6:c7:7c:0c:a4:f7:
        1a:f7:67:b5:5c:03:bf:bf:7a:e2:4d:a2:9b:5d:5d:5f:51:d0:
        d6:52:8f:2a:20:68:08:bb:f0:9c:05:0e:ef:b3:49:0c:2a:1d:
        8f:f9:03:b7:61:09:71:88:7d:e2:8c:e4:b8:ac:98:1b:c3:80:
        55:a1:6b:dd:13:a2:29:4f:93:93:d3:d5:01:31:3f:7b:39:0e:
        3a:57:6c:eb:5c:6a:5f:1b:ad:97:bd:97:23:18:91:05:0e:2b:
        b4:b1:11:ee:f8:58:c7:08:d0:de:a2:3e:ba:54:8d:3d:63:da:
        91:50:3a:24:8d:19:18:23:2e:cf:30:8d:5d:e3:e7:02:93:fa:
        c8:f8:ea:05:e6:eb:06:80:90:4d:15:58:3d:26:98:13:4b:b0:
        ac:dd:90:2e:d0:e1:eb:71:32:83:5d:2a:a9:b9:b5:24:fc:e9:
        ec:18:ca:c9:a1:05:59:3e:fa:af:ed:4e:86:b1:fe:40:47:9b:
        42:77:af:9c:2b:a0:e2:3e:fd:51:ab:02:77:e8:f1:39:45:aa:
        54:b6:14:d4:14:20:fc:36:81:e6:04:98:8a:a0:c0:8a:cf:ae:
        f6:b5:dc:b7:eb:26:86:d3:cf:1c:38:65:54:04:b1:b5:09:48:
        f5:2d:07:ba:f8:eb:49:bd:d9:b1:54:ea:ac:c2:0d:20:10:79:
        c1:cb:e9:dc:2d:ff:55:50:4f:f6:05:02:78:31:33:6f:15:7e:
        24:5a:66:23:70:b3:b2:0c:17:39:ce:15:38:c5:ff:60:16:38:
        60:74:72:c9:70:d8:59:b7:80:7f:da:f6:67:3f:d0:ba:be:1b:
        a1:87:da:92:2d:a3:6c:99:29:57:aa:cb:d1:8d:66:f1:2d:c9:
        56:60:24:56:4b:19:9f:f5:65:84:89:86:7d:4d:8b:f8:5b:60:
        dd:af:2d:66:76:6c:66:d9:c6:f5:39:25:6c:e5:7b:43:97:64:
        5c:c5:20:1e:3d:b5:dc:92:b2:9c:d8:1b:1b:e0:bc:44:7b:9c:
        95:c5:53:48:91:b2:a5:46:16:bf:50:af:a5:44:cc:54:78:3f:
        ed:20:d8:2e:0b:41:3d:f1:04:9d:df:3c:4a:d7:81:04:ff:8c:
        b7:79:f8:51:8d:b7:2e:ac:2c:54:e6:fc:43:76:8e:f9:be:8c:
        b8:5c:ad:c4:13:af:b0:6e:3b:d1:82:57:1e:f5:52:84:ca:cc:
        d2:68:f3:2d:04:ff:27:0a:e6:a2:fa:c0:a9:97:d6:64:45:18:
        5c:6f:9e:c1:64:22:66:db:56:02:c3:a8:57:fc:87:1b:5c:43:
        15:8e:58:fc:f2:00:0b:4f:6a:4b:a0:5c:da:f2:e5:1b:82:4a:
        6b:ef:db:63:d7:7d:93:1d:2f:20:78:37:17:22:82:cd:6b:c1:
        83:61:05:81:99:0c:25:29:d6:5f:22:bc:06:67:7d:67
]]></artwork>
      <artwork><![CDATA[
-----BEGIN CERTIFICATE-----
MIILSDCCAW+gAwIBAgIUVH5kcCmeA8V6pVx40SeHjFQ1F10wCgYIKwYBBQUHBiIw
NTELMAkGA1UEBhMCRlIxDjAMBgNVBAcMBVBhcmlzMRYwFAYDVQQKDA1Cb2d1cyBY
TVNTIENBMB4XDTI0MDcxMDA4MjcyNFoXDTM0MDcwODA4MjcyNFowNTELMAkGA1UE
BhMCRlIxDjAMBgNVBAcMBVBhcmlzMRYwFAYDVQQKDA1Cb2d1cyBYTVNTIENBMFMw
CgYIKwYBBQUHBiIDRQAAAAABK+u/ZhTeb5ZbTSpQAHutXCKwE3lyAhSpX/yW4Jt4
jta+jBxwPNjdeLIaFEe+Hw10cj82dsLLGa0pkAuC3pt/36NjMGEwHQYDVR0OBBYE
FGLONaVHd/8hhy68LSfnjvQ1a8/YMB8GA1UdIwQYMBaAFGLONaVHd/8hhy68LSfn
jvQ1a8/YMA8GA1UdEwEB/wQFMAMBAf8wDgYDVR0PAQH/BAQDAgEGMAoGCCsGAQUF
BwYiA4IJxQAAAAAA5YiouHOtTZL4XIHFimNXaqc7VKq2BorZ8cILyCceS6LP4tpE
6ujyQKi5VJxJNhIk33St5SnvT9qIDSFdO2RjJ9CEtZV6MBg3zTQX3aydnkjbdAd5
hCFa8CbNIWR7dzNIWGebLLKFbczsMUsvUVU6heHKBBXObkc59ekxRUHtccZPlvWu
ZGq9ctCMFwKZEB0UNMrlR+P3ZpaWEdWXdnaD8YSltgBePmeXejLcyOtMKUZ3mdba
ReZ7jEVttSlr/ZiiiY0MMEL1C3yXxbEd4tpnqUiknin0YD9NHUiDgjjv+ssdhhGh
FZT71e5o+US5PVRw874XjdcuhS1c0KDFmVLMeeccGNluPQ9sBVEzKDXiAllfH+14
CsZi8H3+c5YDTLRC4wDC18vrURDEDGS4N/6F0I4RbaYWd7EeAdke8xCc3QG8OHVe
j1ieW2x7CkEIWTWpOoMZ4H2h9c+jHE4H4a0DlfLTi3kz+FIiUxseMpphP8R8mujV
tSjxhGXVwfxNFpOIk2nK+pSglU4jrh5g4Oi0v/8WlXEPMXS7vrha6ySVi5UoE83j
qWX39W6bqal6Bc6r8FRi2RL4oRpo368Vj4rfZyfJ7b3hgaaNmoTzkTbZiXSO74Tc
XAMaCOTX8HL8bYoBNJTl/whRG4Bf5wfYnyXkHcP45dCcUM9mcfnM98Cn0GYBtxeg
X2aXpP9irBygYw0wKOmQ1VmkSNgHhwJLP2gjpQTcs9dF9tyw7MaQphyh+H6EumN+
WmQUeFj1dcD14R29SVfAQAgHmX9DLuIl2O2jGuN48XivAklUNlmO03KlC1IyvRei
z+FHISg9urYk2Rj5RHM17SmkGLztaM1KmjTLGi+zX7pzmxjueqiSJWUlgQRjHCIr
uLqBIbz5nah4mHW87UrGt2/AkSTrHfld4ON4TgX2NA97QVRJIKIwZpTx2sFsP14Q
kpKjDH7oiyYRHNdoyTF5s6TVYwBow+OGLQmSSy1jfbgDpExgtCwS1QufFijqiC+7
HBkLD0A9Z+gL+sbjOUSyvYo/Id2q7KOMSN1MmUOG10iBa+W5u1mfHA8/Efd8S2eo
lcJ8yztmsHmmVW9tsCmKXnvuMGjz3UEpkfZ5ca6NIXB4HV3S98/nQjjRjFKmpvax
OLErI4HhHyFtmT8Q67Gpc7g+MZnM3SvfWCfbC1opmY+xn+kxQtAm21O3fjBBlcPw
B4O7sGO1FkjypmAvMl0iodp2TjcmUw2Vey25BS+TK9TfwQJb96WiTxFcgPTwvcfq
PNtv4utsf8NY2TF3S033zrvWyGSjAdX5pI3o8O4JBiwLPKwKV9jkgXnqSr1RA4hM
0EwLxAx+LeffG2diwNGcrbvT8HXdg6pwmSwZeD0mK0dvJMFgAh5LdQSRHwgcs3mg
m9v7XT/H4wkfQT5ku60ZPTXhpvRpC6IEN0KVxsfl9FYOZ1t4NLsH8Y/nc1uH19/J
LY2MQnaHFYVLIwMgNOEb9gwehFPZG07ZMUM4O4gShNgqOLHOD8cH1GMtl4kcs0SZ
69TfMnS+DWMRIv36juILVhJWDEYWrUQQJpjcz8mVZz4RwXb6uBLqlvbZkay/Sbkc
jhUFU6yeBNJbuIe/gVD3AqTAnBgPRax6gs9GFUJACTKJpeqQpZlo+ZMMe9Z6qOlR
4pCeue0h29l+3txia0Rrn4HFdzmOHXgw3txTgODD+vqUaCiRmIb/hgSpvVh8MTcf
25op88FIECBxX/w1E+t7EuJ9HMyX/o9cot320qOy6lGz77EeeQsAU/TyUnVa1xfF
MaBUTisoLE9reic6LATasx0ETqROlFyokXCrwEt1n7NqqU6KIul//exT52ptMguL
q0znfXLsBGIcGkUeM443rmovyPvzae0RAfP0V+kp1TsMnAzEy8M4XAHn1jHD2M4k
175xm8iWE8pcXeSSQK+GoEv/p1U5cP2sCuGHxwFLw0E2xsYzj08lSo1wkqx8lcxJ
qdzWamdSpVt/L7uR477WKPwi0HJm6AlzpyPGpok4C+XQs/FAOJxNF5YRF0Tv45RR
kUxd/tntw3agLTvcjbkxFfZ1WHQvV7QpISltX+sGcQr02//GLxZzp3Zr0FunIVz9
8BHob5vQycn+NXZKSmObukisr0+RZ5xcR9jjLQMSXvHLVjR1aZWtaJZs50qRcvub
uuiSVvuaW107ndPFxFJCG/lKR0Ldd0naK73XlF97uGS5BjJ86tE29pW4V0EbbmYx
LO6HelwZL9iVShaTSPOXJT0kYR7QYzfuOsmjRsWUoH4kzH9yjRSePDPszZrdtQiQ
mBmVhTj//9Iev6bElxMrPUfpV1nTfZkBblNNwIKX+4nWfLcjDn1uI4hTBo8W/0AK
G83VHpEBPnc6X8FXOnvG1VHX4uyJEmudA+Sdu31OAr9njQPKkFbwmpdLAi1MMYmC
dpf+L9UKPeoNOGwwdV+ukVPXRWTfugsigESFbQ5cKX+CnlSjepW+lnlmnVui1i5H
xpl9KzLc8rYCkW1j1JNFYMRCcRCe+5Av5nVxznhwwdr/4Uf+eSuOmoG/3QLjeDlx
F7MjFBGdKY4hoZiwrANabJ5iZO9PA8o3pu3keNUNmSn1XGHmSMuXDl75LPa2x3wM
pPca92e1XAO/v3riTaKbXV1fUdDWUo8qIGgIu/CcBQ7vs0kMKh2P+QO3YQlxiH3i
jOS4rJgbw4BVoWvdE6IpT5OT09UBMT97OQ46V2zrXGpfG62XvZcjGJEFDiu0sRHu
+FjHCNDeoj66VI09Y9qRUDokjRkYIy7PMI1d4+cCk/rI+OoF5usGgJBNFVg9JpgT
S7Cs3ZAu0OHrcTKDXSqpubUk/OnsGMrJoQVZPvqv7U6Gsf5AR5tCd6+cK6DiPv1R
qwJ36PE5RapUthTUFCD8NoHmBJiKoMCKz672tdy36yaG088cOGVUBLG1CUj1LQe6
+OtJvdmxVOqswg0gEHnBy+ncLf9VUE/2BQJ4MTNvFX4kWmYjcLOyDBc5zhU4xf9g
FjhgdHLJcNhZt4B/2vZnP9C6vhuhh9qSLaNsmSlXqsvRjWbxLclWYCRWSxmf9WWE
iYZ9TYv4W2Ddry1mdmxm2cb1OSVs5XtDl2RcxSAePbXckrKc2Bsb4LxEe5yVxVNI
kbKlRha/UK+lRMxUeD/tINguC0E98QSd3zxK14EE/4y3efhRjbcurCxU5vxDdo75
voy4XK3EE6+wbjvRglce9VKEyszSaPMtBP8nCuai+sCpl9ZkRRhcb57BZCJm21YC
w6hX/IcbXEMVjlj88gALT2pLoFza8uUbgkpr79tj132THS8geDcXIoLNa8GDYQWB
mQwlKdZfIrwGZ31n
-----END CERTIFICATE-----
]]></artwork>
    </section>
    <section anchor="xmssmt-x509-v3-certificate-example">
      <name>XMSS^MT X.509 v3 Certificate Example</name>
      <t>This section shows a self-signed X.509 v3 certificate using XMSS^MT.</t>
      <artwork><![CDATA[
Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number:
            5c:22:ad:8a:06:51:9e:67:02:6a:2d:43:3e:8b:c7:23:
            43:77:80:c8
        Signature Algorithm: xmssmt
        Issuer: C = FR, L = Paris, O = Bogus XMSSMT CA
        Validity
            Not Before: Jul 10 08:28:04 2024 GMT
            Not After : Jul  8 08:28:04 2034 GMT
        Subject: C = FR, L = Paris, O = Bogus XMSSMT CA
        Subject Public Key Info:
            Public Key Algorithm: xmssmt
                xmssmt public key:
                PQ key material:
                    00:00:00:01:4b:a7:89:11:6f:fc:1d:fb:d3:e7:71:
                    73:b8:a2:48:ef:53:b9:9d:1f:c6:8a:7c:be:4f:8a:
                    29:fa:41:fd:bd:da:20:7f:f6:3b:b0:c5:b8:a7:c2:
                    f2:5a:f2:26:14:eb:36:f0:26:2f:87:74:fb:0e:d5:
                    7e:17:a0:d1:4d:b6:cf:51
        X509v3 extensions:
            X509v3 Subject Key Identifier:
                7C:7D:59:B8:95:61:D5:03:6A:1E:3D:F1:24:AB:1D:ED:
                04:CD:DB:5F
            X509v3 Authority Key Identifier:
                7C:7D:59:B8:95:61:D5:03:6A:1E:3D:F1:24:AB:1D:ED:
                04:CD:DB:5F
            X509v3 Basic Constraints: critical
                CA:TRUE
            X509v3 Key Usage: critical
                Certificate Sign, CRL Sign
    Signature Algorithm: xmssmt
    Signature Value:
        00:00:00:57:c4:98:89:ff:d9:0a:8e:6e:6f:16:95:8c:ec:35:
        42:21:c2:ca:56:ed:f8:81:f1:b2:4f:2b:6d:73:f4:37:55:fc:
        f4:4e:15:eb:6b:90:de:34:fe:d6:96:70:94:8d:c1:e7:4a:32:
        49:30:3a:40:a4:67:d2:fb:da:f8:d8:a1:7a:48:22:1c:e3:98:
        bc:d0:68:85:29:c9:e5:f7:5c:56:d8:9c:80:be:68:ed:11:eb:
        39:0f:ef:cb:09:b2:28:30:a6:2b:05:bc:de:11:22:be:c4:dc:
        08:9a:3d:b4:49:37:1f:54:5e:5f:2d:93:62:b0:95:c5:5d:23:
        92:f3:55:40:78:19:00:56:9e:a2:f1:0e:4b:ae:75:d6:92:09:
        b1:79:ec:c9:18:67:19:09:86:83:74:5d:0a:06:ab:da:f0:af:
        02:97:4d:d7:73:06:8b:a2:84:c7:09:af:dd:8b:15:39:e4:30:
        9f:c9:00:25:a8:33:4d:de:e8:25:b6:35:0b:51:bf:7a:34:a7:
        e8:84:e8:fa:39:5b:aa:37:6e:95:89:ac:26:4a:4e:ca:be:29:
        08:4b:3c:28:a7:85:6a:ad:5a:d2:93:eb:12:e1:9a:87:1c:40:
        3b:cf:15:6c:43:4e:88:21:54:52:7e:0d:6d:17:29:8d:15:6f:
        ef:42:5a:a9:25:d0:97:80:61:31:22:a4:9f:25:17:51:ad:0b:
        a1:cb:93:b4:f5:a6:b0:22:1b:6d:50:64:2a:48:bd:05:16:88:
        00:e3:7b:56:d0:03:b3:7a:2d:6a:0b:f3:de:a2:8c:6e:81:80:
        2c:8f:e9:d8:78:ed:5b:99:c9:13:d1:b6:eb:78:c3:40:2b:a1:
        7a:84:0a:ba:12:87:5e:1d:38:24:22:8f:c0:a3:65:1c:1c:ce:
        2d:8e:e5:2f:1f:be:93:5c:fe:1c:cd:a8:9d:7e:7e:cf:18:e2:
        9c:c5:54:dc:62:61:74:23:55:64:66:21:96:4c:a7:2e:8a:94:
        a6:35:10:a5:e8:5e:6e:91:ac:a8:cb:ed:51:2b:66:45:03:f5:
        87:ed:4d:8c:4e:6d:54:80:a1:33:8a:84:9d:23:31:90:c6:05:
        11:a7:9d:bd:51:0a:73:47:bc:08:49:11:b3:98:ff:01:14:69:
        d7:c0:a0:0c:55:e4:5e:e2:fa:84:ac:27:b3:85:2c:99:71:52:
        9c:33:f8:9d:8c:d2:13:bc:6e:18:79:15:a7:02:ee:15:eb:27:
        d8:af:24:38:02:9c:ca:30:f3:e2:30:41:2f:62:a2:2c:a5:81:
        1b:71:6d:b1:94:bd:c6:3d:9e:5e:51:45:de:5b:f4:d7:e6:35:
        e7:d8:7c:d5:98:ec:7e:0e:f8:9d:c1:a7:7b:b3:65:b1:a1:4b:
        2d:ec:d9:12:45:6b:1f:0b:1c:6b:3b:0a:66:76:39:f4:cc:9b:
        e1:b7:17:f7:53:fc:c3:a6:18:f7:2e:45:52:b1:18:99:75:d1:
        69:bb:77:c8:1a:84:5f:06:b5:8b:cb:02:b0:b2:0f:bf:17:18:
        65:3d:a7:72:5b:71:9f:92:7e:3a:df:84:cc:65:5c:c4:5b:70:
        fd:cc:38:9e:12:6e:f9:ff:1f:02:fc:ca:f5:68:86:fc:ca:71:
        f1:3d:7b:32:b4:d4:c3:a2:20:16:3f:12:07:71:95:3b:d4:b1:
        1e:fc:8c:1f:34:8c:c8:ab:8c:bb:75:93:c1:1a:d2:85:3e:9a:
        e6:04:86:88:de:27:46:ca:f3:f7:f3:8e:54:18:ea:aa:ae:14:
        02:b1:4a:6a:e0:24:77:40:28:8d:37:27:9c:87:6a:81:09:d2:
        01:4d:20:7f:de:84:a8:80:8c:8e:63:82:be:66:df:87:30:5c:
        b8:71:0a:e9:91:68:71:6e:97:97:f0:27:4e:fa:ae:6a:85:ac:
        80:cd:38:48:49:c1:2b:9d:db:54:c5:f0:bf:fa:06:e8:96:3a:
        c0:95:f0:88:bd:8e:80:78:3d:dc:ad:5d:0a:56:dd:c7:80:9f:
        fc:64:58:4d:6d:27:f6:d7:1a:8c:b2:1c:09:ea:7d:4f:74:99:
        0d:4a:0c:b8:b0:ef:74:dd:6f:6f:dc:e5:83:e1:e3:c2:e8:58:
        17:b8:44:8a:2d:ec:df:54:f6:1f:67:a2:b3:c5:19:fb:b9:c7:
        1b:3c:ea:bd:2c:e1:43:65:d1:5a:17:dc:93:9d:c5:85:0c:55:
        34:13:49:15:92:e2:52:14:d1:81:aa:62:02:1a:ba:c9:b0:53:
        85:8e:7b:d1:4e:34:76:ac:79:d7:b3:48:92:bf:55:7e:2d:5c:
        cd:32:9b:c1:41:a7:a3:cd:b7:94:5c:96:1e:3e:27:4d:eb:f0:
        61:4b:a4:e3:3c:bb:69:85:37:e9:9c:98:f4:68:7a:61:77:8c:
        bd:b9:30:d6:f1:fd:69:78:3f:96:99:7b:69:39:90:b3:7c:b6:
        88:ed:cd:19:da:42:64:e5:32:4c:a2:30:f7:c4:e8:27:93:70:
        ed:fa:5e:ca:8e:7a:d1:13:af:15:b1:59:c9:9b:91:61:0b:06:
        d5:cc:2e:80:bb:49:93:dd:be:53:88:be:af:80:64:7c:5e:be:
        7b:8b:e7:5f:39:af:ab:67:42:6b:06:aa:ef:d6:69:af:a9:00:
        1f:a0:15:10:04:3e:db:93:b2:37:db:eb:85:59:43:a2:8d:8f:
        06:8c:cb:a2:1d:a8:3c:9f:f4:a4:7c:c8:cd:ff:f0:a8:79:0f:
        e7:d8:94:67:ec:17:3f:fa:6e:04:07:4f:bf:86:04:6c:fc:46:
        87:b5:10:85:a4:07:e8:af:a9:ec:5d:28:5c:80:8c:31:cc:c7:
        b3:81:17:0b:4b:7d:1c:9e:74:02:1e:ef:de:0d:1b:c1:c0:04:
        4d:46:fd:dc:0b:a4:c6:33:e6:85:0a:60:39:4d:0b:f9:49:44:
        33:e0:15:99:19:bf:c7:8a:c6:96:04:93:37:6b:5d:e8:be:73:
        d4:80:b8:81:0f:9a:91:44:cf:72:02:d3:c9:f8:e0:7d:d2:9b:
        2b:ff:eb:42:6e:38:7e:dc:cd:a7:90:c5:2c:2b:a0:23:37:b9:
        64:10:a6:27:68:47:c5:f1:e8:8d:41:c1:49:e8:35:48:ce:c8:
        08:4c:ad:f2:ad:5d:e9:62:eb:c9:3c:61:85:18:c6:34:73:fd:
        26:a4:f0:50:83:9b:64:54:aa:55:6c:d8:a2:21:81:ff:9c:27:
        39:1f:c3:a2:0e:e5:53:b1:d7:fa:1f:ef:29:8b:c2:90:98:ea:
        2e:dd:45:bf:c3:6c:a3:93:47:99:03:18:25:e8:a5:ee:2e:77:
        eb:7f:f4:49:49:59:98:c1:fc:ab:1e:ad:20:bd:f8:24:fd:21:
        1b:da:5a:07:55:c8:50:05:31:50:93:b2:f8:6e:db:73:4d:5f:
        34:aa:f3:34:83:90:f0:41:6d:c8:43:56:d1:75:07:f5:16:20:
        b3:99:b2:c7:34:25:c4:0e:74:5a:51:0f:7b:3b:7f:6a:a9:41:
        17:b5:47:62:2d:4f:b9:61:97:60:e9:ae:ca:ad:31:6e:4b:0a:
        47:9c:53:66:a3:4e:c3:96:7c:01:a0:8e:ae:83:45:42:e6:92:
        12:8e:97:6f:e8:a0:b7:7d:a6:74:24:aa:20:b0:fa:9e:98:e8:
        7c:b4:da:30:e9:94:08:96:b7:b9:53:4f:75:5f:0c:4d:82:e3:
        cf:6e:bc:fa:23:4f:fa:33:17:7c:98:b6:1e:47:89:3e:d9:a1:
        aa:42:19:25:ae:9e:3f:53:44:ac:91:96:d8:55:c3:40:1d:fa:
        ad:86:38:62:bd:27:2f:26:34:be:ad:9a:01:44:42:c8:54:a5:
        3a:e9:0a:ff:f8:41:6d:38:1e:e2:3d:08:3a:94:4f:1e:60:d0:
        b1:c2:8e:94:34:f0:30:3e:f0:91:25:ee:98:34:b4:8d:95:4e:
        cf:ed:1d:61:89:c9:59:10:68:f2:bc:2e:5c:bd:c0:0f:1d:9c:
        2f:7c:c0:27:25:14:9b:de:a3:74:64:28:14:2c:a2:b2:90:3a:
        a4:6a:50:e9:8e:ca:78:e5:b6:74:56:e0:92:69:7d:b4:2e:e0:
        e7:66:92:16:92:a0:c3:db:4f:d3:d0:57:4d:4a:28:ee:b7:cc:
        04:ef:17:d9:fc:01:bb:1e:b2:5b:02:3d:1f:5a:85:73:a1:81:
        96:b7:33:5d:79:e5:6b:c9:29:73:34:01:69:ea:57:f0:01:be:
        4e:f3:5c:f3:0a:a7:37:08:ad:18:9c:c7:4c:59:d0:5d:bb:01:
        f1:53:76:cb:cd:d9:84:5e:bc:22:11:76:01:d9:e3:af:17:03:
        01:ef:38:4c:ad:c1:7d:a9:c6:61:2b:ba:9c:81:95:86:af:bb:
        73:90:dc:d9:2f:d1:3f:95:6a:b9:46:0f:fb:84:64:7c:7d:86:
        65:aa:10:71:56:19:5f:60:52:7f:19:fa:d5:5a:e0:90:e4:b9:
        62:55:71:2a:61:f9:37:2f:5e:07:71:43:cf:06:ca:6a:d5:52:
        c8:33:e1:ad:b2:3e:a4:61:01:00:bc:55:5d:0a:f3:e6:4f:35:
        06:c4:a8:3f:4c:8b:9b:c9:41:4b:f4:c1:57:ee:3c:c0:44:68:
        52:5a:2d:b9:a7:f2:41:da:c4:8d:7d:db:40:b6:fc:47:63:5a:
        69:a1:c7:8c:cc:3f:af:51:94:37:95:58:82:79:d2:16:4a:bf:
        12:0b:59:a5:a5:11:71:e6:1c:63:3b:ea:f0:2f:10:e0:97:9a:
        a1:04:53:d0:72:f4:3c:77:3b:78:ee:b5:aa:6b:f5:bb:5c:e9:
        35:4f:69:65:87:29:24:ec:47:7b:78:5a:a7:c1:e5:f1:73:7d:
        4d:79:ef:ef:4e:75:87:db:8f:36:fd:50:3e:74:dc:17:d4:c3:
        3f:4f:82:24:51:1b:12:16:26:61:db:93:15:19:39:55:f5:05:
        2c:6e:85:dd:b2:cc:4f:c0:09:0a:76:46:d8:e4:f2:11:92:a1:
        e0:36:a8:25:c7:45:19:6c:98:eb:9a:fa:c1:ec:80:18:ce:d1:
        f8:c4:23:9a:f9:b8:1f:05:67:8e:45:cb:e6:ee:0b:fa:db:67:
        1f:62:2c:49:78:bb:55:98:1e:33:42:63:f2:db:ee:73:f7:60:
        80:6d:5f:9a:e8:8c:89:39:5b:b2:84:e2:c3:99:77:f3:5f:19:
        ec:b8:2b:ce:60:59:2c:66:06:f9:c1:43:b9:fd:94:35:9e:28:
        9d:a0:8e:fd:0d:c6:1a:bb:20:93:b0:63:6a:83:2f:0a:db:c2:
        b3:8e:b1:dd:f5:ab:19:09:53:7a:db:72:3f:1e:25:07:eb:1a:
        7d:21:da:88:22:e6:f0:ba:b3:15:6f:95:f3:72:d2:cb:6d:48:
        b8:ba:7b:aa:40:7f:81:fe:ba:15:c2:77:9d:86:58:bc:7d:89:
        2e:7b:3a:96:04:9f:f1:3a:50:48:5a:25:4d:91:b6:ed:de:f6:
        2e:4d:e5:77:11:6d:76:f4:23:5f:91:f0:0f:79:59:7a:f3:32:
        24:11:c4:88:30:21:26:3b:f1:79:0f:04:06:ad:82:6d:ea:58:
        4e:aa:4e:0a:7f:7b:5c:a5:ab:de:76:a9:a9:c7:d9:e3:eb:d6:
        84:80:02:ab:da:4c:5b:49:90:29:c5:cb:5b:1c:06:61:e8:9a:
        cf:a4:ea:9d:31:16:6a:21:3a:d9:22:25:b8:39:9d:4c:e3:86:
        76:a8:dd:d8:b4:db:88:f9:5e:61:c3:1d:87:df:a9:31:33:7a:
        b3:50:3e:f2:cd:ad:a0:9d:98:5f:6c:e2:f0:d8:27:b9:c2:37:
        7f:8d:b4:f8:84:13:5f:22:6d:9b:81:bd:1c:e5:75:ae:b5:95:
        d1:cb:d0:c6:e3:78:ec:8c:71:6d:8c:5d:40:79:7d:58:3d:5c:
        63:77:cc:2e:a2:63:a9:71:30:2f:59:2a:ec:82:b1:e5:b9:d6:
        bf:fb:21:e6:97:fc:70:45:9a:c7:e8:d2:81:73:b1:f5:bc:76:
        ca:b4:be:9f:39:b5:2d:f2:3e:c5:32:e3:ae:3c:fd:74:a1:36:
        5a:5c:4d:f6:de:d2:d5:66:61:74:88:2e:4b:69:7c:29:2f:e0:
        2a:d6:d8:93:99:41:bc:7b:7f:fc:c3:1c:84:ed:16:c0:08:78:
        fb:57:61:9e:83:7a:d1:e9:b7:ad:9a:85:1c:c3:ba:a3:e4:18:
        b6:00:f6:35:27:e2:27:1d:10:dc:44:1d:11:05:a2:db:df:0a:
        59:98:9c:f3:ca:3a:b3:26:2d:d1:c4:3c:fc:21:f3:3c:39:62:
        7f:f4:bd:91:74:ef:02:83:da:4a:22:40:60:9f:6a:9f:8b:8f:
        f1:e4:1e:99:d5:17:55:62:1c:60:01:7d:c7:41:db:19:9e:29:
        01:ba:a0:5f:41:f3:61:ed:9d:0c:9c:ef:32:8b:b0:8a:89:b1:
        e4:06:c9:2f:4d:42:2a:01:84:29:ac:f1:41:a0:a1:c9:b4:83:
        d9:87:1a:53:1f:7f:d4:85:12:2e:79:f3:2c:88:06:73:62:ee:
        16:bc:c7:8b:e7:09:96:ba:02:b5:56:ab:6f:c0:cf:76:64:62:
        0e:1e:b5:e4:69:42:4d:ed:56:96:d9:1d:8d:07:40:7a:c5:bd:
        d3:9f:43:07:e4:9d:b6:26:2b:33:6a:79:d9:8a:ec:ee:51:73:
        f1:91:b0:e8:90:42:db:11:55:57:1b:01:10:fc:11:ff:77:b4:
        09:01:6d:f8:8c:cf:72:16:df:09:12:09:bd:49:ef:33:b9:c5:
        8d:35:60:77:80:8f:ee:98:18:be:bb:3a:61:e9:5b:6a:09:b0:
        0a:1e:38:80:e9:71:46:77:a1:19:7a:c3:04:57:a5:77:e6:5a:
        01:77:d2:92:90:f6:99:50:87:3f:30:8a:37:3d:37:1e:6b:1d:
        a4:71:3c:6b:15:07:01:f6:3d:43:96:a3:f7:30:cf:08:2c:32:
        a3:ca:67:6e:59:da:51:2e:96:bc:97:41:4b:7c:5f:97:a3:cf:
        46:20:9e:64:96:08:f7:0c:03:4b:b4:83:09:db:6c:bb:94:23:
        4e:ff:7b:fb:2f:84:66:0a:96:f9:e1:58:ff:0d:3c:84:62:9c:
        6b:60:9f:7e:39:cf:33:f3:03:2f:c7:d0:8b:6f:f3:9a:62:cc:
        33:c4:bd:b4:fc:b8:80:9d:fe:9e:c2:f0:d0:9e:07:71:a8:f9:
        1f:a7:64:4d:63:f9:6b:ce:3e:44:0a:3f:05:58:90:0d:0c:20:
        7d:4e:c7:52:d0:e5:b7:61:d3:6a:52:08:37:91:15:3c:cf:41:
        ec:ef:88:56:dc:14:2a:12:55:cb:05:01:23:89:c0:fe:ca:de:
        40:d2:d0:96:a3:1f:07:4a:58:96:fa:b2:ef:78:96:f0:73:25:
        c8:2e:20:3b:d8:02:cf:e7:ca:b0:29:1a:25:7f:15:96:2d:fd:
        52:bb:29:c3:fc:bf:b1:7c:d8:0f:76:21:05:28:2e:89:d9:82:
        0e:cb:cd:03:1f:c3:71:b4:0f:75:52:e5:b4:93:8c:ac:ed:d5:
        30:5a:b9:33:84:fd:3c:da:dc:e6:84:6d:c2:66:be:93:ad:67:
        7f:db:d0:08:95:64:5a:2c:13:7f:e2:05:b5:dc:d0:bf:4d:6e:
        93:c2:3b:8c:3b:b1:5c:3a:28:e8:c3:96:ed:59:e2:62:52:8e:
        95:8d:b5:e1:c1:f2:34:5b:bf:5a:cc:f1:ee:ec:3d:6c:61:99:
        f2:c8:e4:05:5f:ea:d5:74:3c:ff:df:1b:20:bd:35:30:c0:27:
        f8:a4:6e:73:45:81:e2:b9:15:52:c7:a0:e7:c8:fd:7b:8e:f7:
        d2:0c:c4:e9:22:69:4e:70:62:c7:8a:a2:a6:61:7c:0b:5a:74:
        8d:0f:c0:e5:66:dc:18:7b:74:3b:72:ab:1a:53:b3:49:ef:50:
        aa:76:80:e7:11:53:90:ab:24:d1:2e:fc:66:41:cf:b3:cc:ae:
        ac:f9:eb:1e:19:f7:bc:54:00:16:da:b0:d4:2b:74:c7:35:fb:
        08:ff:67:14:83:5a:eb:6b:b7:b4:63:28:e2:b6:b8:d4:0c:13:
        6a:8c:bb:30:c1:fb:6c:42:df:23:c4:f0:be:25:df:2b:39:11:
        bb:82:c3:e7:f9:04:48:77:cf:d0:5e:3d:6e:19:7f:b3:c4:2f:
        c4:ec:51:5f:9d:c7:8f:88:9f:21:79:8d:a0:17:3e:17:73:b4:
        f5:a2:71:70:e6:99:c4:fd:4c:f2:63:64:23:22:c3:72:71:52:
        43:42:a5:90:e3:59:77:50:ff:a1:09:2e:c7:f6:7e:17:f2:a2:
        d6:7e:2c:75:f2:ab:9e:36:78:ab:57:be:c5:91:71:70:2c:ba:
        03:91:80:97:f4:9e:16:bc:fa:80:f4:22:2a:b5:75:15:57:d9:
        b0:92:9e:b1:35:db:26:96:77:28:9c:89:99:db:9b:55:d4:29:
        15:5f:54:8a:0d:58:a8:95:13:95:17:6c:6b:b0:2a:a3:fa:1a:
        ec:2e:b4:0e:08:ea:8f:e1:8c:59:cf:7d:60:00:f3:bf:b7:e4:
        5f:08:a6:02:ef:ce:d7:9c:8d:6f:56:d7:c9:35:e9:e5:cf:d2:
        f5:28:ca:e6:36:ef:c4:26:52:d5:4d:04:ec:50:73:87:dc:70:
        1f:1a:db:07:bf:4c:e9:ec:57:98:7f:bc:c8:31:9e:7e:e6:3a:
        b4:c4:77:93:39:56:57:67:05:84:8d:03:02:d9:bf:04:6b:fe:
        71:8a:be:b6:8a:ae:44:b0:dd:db:1f:6a:26:e5:50:d5:ff:03:
        81:d8:1b:9f:3f:a6:bc:1b:52:b5:49:93:b0:27:fd:59:d4:7d:
        69:e9:63:35:0b:9b:de:a1:d4:70:0c:08:41:4b:76:d6:cd:c8:
        65:8c:bb:9a:6e:e4:f1:e2:30:13:9d:a3:c7:67:16:0f:7d:bd:
        ac:dc:aa:9c:17:01:a6:27:14:fa:4a:c1:27:3f:07:7b:9f:2f:
        47:56:cc:f0:96:38:e9:58:7c:1f:6c:73:10:3c:11:68:2a:3c:
        5f:74:fe:37:ae:8b:e9:eb:c6:06:30:6f:62:3c:5c:6c:2d:c7:
        5b:24:6d:cc:75:3f:d7:d4:e6:72:64:8a:ad:03:67:ad:cd:cb:
        2d:7c:82:49:a9:ef:e8:b9:be:f2:6c:98:42:4e:26:46:04:58:
        a5:2b:c9:88:9b:a4:91:7f:22:09:12:52:2a:d1:4e:36:22:d8:
        53:bc:38:93:ad:11:19:c5:e7:c9:83:00:b4:b6:b0:ac:96:32:
        ca:d0:08:69:e4:d2:29:86:74:74:49:be:4a:b2:bf:f2:2f:c2:
        52:fd:15:3c:8d:07:12:3a:98:c7:49:67:81:1d:b1:5d:e8:f4:
        42:79:a0:f7:44:b8:95:9f:e1:37:41:5b:c9:b1:89:90:7b:66:
        96:eb:8e:dc:1b:d7:73:b2:eb:c1:42:41:e8:2d:28:ba:74:ea:
        7c:77:87:76:5b:36:10:3d:87:08:52:94:e6:60:95:c1:1b:c9:
        27:c1:42:aa:32:62:ed:ca:6f:04:4e:11:3a:3d:3d:e0:d8:3a:
        c0:ff:b9:9a:94:b1:79:f3:01:14:3a:99:34:59:8e:d9:ac:f1:
        a9:77:b5:2d:59:e1:29:96:1b:13:80:8b:10:94:3e:c2:51:db:
        c1:24:06:02:47:96:9b:ae:5d:25:34:af:4b:65:f3:8a:eb:65:
        7c:a5:5e:7c:a2:d6:1d:41:20:13:0b:5e:ea:67:b2:eb:bf:6c:
        44:fb:76:31:58:5e:d2:33:6d:6f:9c:3a:41:70:34:11:6f:99:
        8c:42:9d:d6:2b:14:79:b0:ac:d4:de:3a:b0:d8:d2:97:88:9a:
        17:68:3e:79:a8:b0:4a:d7:a7:3c:63:c5:29:c1:65:76:74:7e:
        c2:de:b8:49:ce:26:5f:d2:62:2d:0f:5c:cc:6c:53:c0:a4:75:
        05:52:d1:52:38:ae:72:17:7c:02:67:6b:76:38:e7:72:aa:38:
        70:5e:af:a2:98:c0:c1:7a:a0:6d:ec:90:51:8d:d5:99:8b:39:
        05:6a:eb:0c:87:37:5b:4b:00:91:2c:7d:8a:6d:c1:23:10:44:
        26:5a:47:f7:7f:8f:86:1c:c2:a7:9f:9e:48:f6:42:cd:d1:3c:
        d9:e8:95:de:00:3c:ec:db:a1:a3:c0:7f:f7:17:3b:4a:dc:d2:
        f5:d4:9b:12:19:0f:6d:13:38:72:06:21:eb:94:88:87:8f:a1:
        de:f6:d7:a0:88:aa:e3:47:bb:69:e8:30:59:82:d2:3a:6d:c7:
        26:95:92:a4:58:07:eb:db:a5:d1:bb:51:00:28:ef:6f:c8:ce:
        9c:0f:d9:8d:e0:b3:14:db:90:dd:f9:26:af:b0:88:48:ae:22:
        71:26:af:d5:e0:4d:5c:41:e6:0b:f2:5c:9b:bb:69:82:09:5a:
        58:63:b9:0c:8a:22:37:aa:a2:71:2a:a5:d9:a7:7b:9f:d5:f4:
        17:8d:bd:4e:de:08:6a:a4:20:ce:a6:85:c7:fa:05:c7:d8:03:
        77:0c:dd:40:32:11:43:2a:8c:50:22:4b:fa:a1:d1:f1:94:42:
        3f:d5:b8:a0:dd:01:71:6e:30:34:ff:a6:76:80:e6:c1:04:8b:
        f0:c3:38:14:98:ae:eb:fd:05:98:d1:96:7e:b4:bf:51:ce:aa:
        b4:66:71:30:9f:7a:45:b6:ed:d1:6e:8f:b0:6c:a5:f5:4f:ee:
        bc:ea:65:5e:24:43:73:4b:50:8e:c8:68:0f:23:48:ed:dd:ff:
        84:97:9b:31:0d:bb:2c:db:69:6b:0c:34:73:3e:ae:69:d2:f5:
        be:a8:99:be:7b:40:82:f4:fe:35:f5:3d:a3:b1:b4:e2:6c:79:
        b7:0b:29:ad:30:3d:56:9d:bc:24:e9:e6:a5:6d:cc:83:18:7b:
        d5:98:a3:5f:dd:71:72:29:71:45:8f:41:52:ce:86:99:5c:f1:
        40:0c:1e:b1:97:da:3a:14:4a:a7:02:48:d8:4e:63:12:99:da:
        28:e9:de:0d:17:90:3a:f5:da:9a:01:7c:15:12:bf:00:48:7d:
        63:8c:89:0b:b9:77:95:01:27:b2:33:73:4b:ab:a8:f3:24:ee:
        c1:d3:0c:a3:9e:26:fe:24:23:3b:82:b4:1a:5e:72:dc:9e:91:
        3a:7b:85:64:0d:30:2e:6b:55:53:7e:a2:4f:b7:10:e4:77:a1:
        01:4a:b2:d7:7f:1c:94:a6:a7:e5:66:e2:c7:e5:37:6d:89:2c:
        72:b1:53:cf:d6:67:0f:77:f8:bf:07:20:98:99:60:ef:2e:72:
        c0:72:9e:79:2a:ca:a2:f7:bc:82:db:53:f7:68:e3:ed:4f:38:
        64:83:1b:dd:a5:78:dc:db:08:a9:34:35:f6:f1:9c:76:85:5e:
        cd:59:a3:c8:89:50:5b:bd:a0:64:06:b4:d7:db:7a:e1:75:57:
        13:90:ce:05:4b:a0:f6:22:70:0b:78:a0:84:46:87:b4:a7:0d:
        88:c6:41:c5:93:cb:77:37:d1:af:37:48:b9:47:db:99:7a:98:
        36:82:cb:27:6a:9a:de:80:24:3a:29:eb:ab:bd:b0:40:0d:a6:
        50:e5:a4:72:a3:19:cb:f3:52:8e:2f:1d:10:ef:7d:0a:15:6c:
        49:08:53:55:84:85:5c:73:53:ce:3e:18:e5:04:92:a6:99:db:
        4d:7b:c7:a9:99:ce:aa:90:48:73:7a:61:f5:92:73:da:b4:26:
        74:a1:39:74:e3:82:f9:32:e0:08:ef:bc:2f:9f:6d:e1:da:3d:
        f0:a5:46:b6:17:95:b8:6b:13:7d:f3:a1:31:8d:b7:47:a0:45:
        aa:20:53:d6:f0:3c:eb:a2:e7:7a:26:8c:c6:c7:cb:0f:21:5a:
        df:46:06:c5:b2:2d:a5:3b:b7:01:fd:0f:55:1b:5e:58:00:70:
        94:a3:7f:48:8e:4a:67:a4:14:5d:e0:ba:b6:f9:9b:e7:de:61:
        d8:67:83:ac:b7:01:eb:62:c5:22:b8:48:3a:96:55:fb:1a:4a:
        c4:63:30:f3:78:05:a6:ab:0c:e7:33:a0:88:f7:e2:e3:4a:1b:
        fd:66:3c:14:be:ee:20:d1:32:95:db:97:ff:d9:c2:bc:7a:c8:
        e4:ba:24:c5:b2:2e:16:f8:53:af:b4:57:56:25:26:f5:36:48:
        eb:0c:20:f9:3b:73:ff:dd:bd:20:81:0c:f5:55:89:7d:46:1b:
        05:b6:25:df:96:99:ea:09:79:60:72:d8:37:92:a8:f1:75:a3:
        5c:6d:54:b7:f3:32:17:35:1a:2d:96:e5:5e:fc:cd:54:30:49:
        af:6f:1a:42:d9:98:52:72:73:74:72:b7:72:95:80:1d:31:5a:
        e4:83:b7:b6:d4:14:00:0b:59:ce:7c:bc:1d:72:24:ab:74:d6:
        2c:9c:20:b1:0a:78:6f:a9:76:8d:6c:37:02:35:bd:6f:99:ee:
        d1:45:36:f1:34:60:7a:12:57:27:68:05:26:14:75:3c:9f:0d:
        3e:b7:5d:b8:2a:6c:1d:a7:b0:41:c4:f4:3d:ae:8e:51:54:37:
        65:ad:0a:c9:28:a0:3f:04:ed:54:59:c4:9f:1d:3d:70:97:5f:
        f9:44:53:ff:15:9f:03:13:7b:41:6b:c0:f7:8f:a3:27:2b:03:
        39:37:8f:bd:91:65:4d:74:a9:9f:45:6a:a4:25:dc:4c:f9:7e:
        59:fc:4e:93:7c:89:8f:71:8e:a6:99:66:5e:6a:25:a4:c0:a6:
        fa:25:f7:68:5c:8a:02:f5:7b:49:cd:89:e1:77:78:95:1b:a9:
        21:78:6e:f4:7a:e2:04:e5:0e:21:52:bf:04:cd:0c:69:5d:d7:
        f2:57:71:9f:d8:01:e0:f3:10:cc:15:2d:fd:99:78:ff:dc:1f:
        8f:a9:31:0d:0f:9f:f4:2c:a1:3d:4f:b2:51:92:68:f0:ec:d8:
        5f:c4:55:a1:4c:c8:12:e9:05:7e:05:93:5f:f9:76:99:85:18:
        29:24:60:14:5d:b3:79:f9:4b:7c:e4:22:71:8a:c2:66:45:d2:
        41:14:5d:59:4c:0a:b5:2b:ab:bd:c6:50:f8:87:37:42:e6:d4:
        96:72:cf:45:f0:d4:bf:0d:c5:17:9f:f1:b9:12:5c:a8:74:89:
        9e:56:07:cf:8f:98:9a:da:d7:db:7f:c7:d0:3a:0a:14:cd:5a:
        66:0c:eb:02:76:a0:d4:56:e6:e8:be:a1:f0:c7:23:b3:4f:86:
        90:1a:5a:16:8e:07:0d:24:d1:ee:03:98:9f
]]></artwork>
      <artwork><![CDATA[
-----BEGIN CERTIFICATE-----
MIIU6zCCAXOgAwIBAgIUXCKtigZRnmcCai1DPovHI0N3gMgwCgYIKwYBBQUHBiMw
NzELMAkGA1UEBhMCRlIxDjAMBgNVBAcMBVBhcmlzMRgwFgYDVQQKDA9Cb2d1cyBY
TVNTTVQgQ0EwHhcNMjQwNzEwMDgyODA0WhcNMzQwNzA4MDgyODA0WjA3MQswCQYD
VQQGEwJGUjEOMAwGA1UEBwwFUGFyaXMxGDAWBgNVBAoMD0JvZ3VzIFhNU1NNVCBD
QTBTMAoGCCsGAQUFBwYjA0UAAAAAAUuniRFv/B370+dxc7iiSO9TuZ0fxop8vk+K
KfpB/b3aIH/2O7DFuKfC8lryJhTrNvAmL4d0+w7Vfheg0U22z1GjYzBhMB0GA1Ud
DgQWBBR8fVm4lWHVA2oePfEkqx3tBM3bXzAfBgNVHSMEGDAWgBR8fVm4lWHVA2oe
PfEkqx3tBM3bXzAPBgNVHRMBAf8EBTADAQH/MA4GA1UdDwEB/wQEAwIBBjAKBggr
BgEFBQcGIwOCE2QAAAAAV8SYif/ZCo5ubxaVjOw1QiHCylbt+IHxsk8rbXP0N1X8
9E4V62uQ3jT+1pZwlI3B50oySTA6QKRn0vva+NihekgiHOOYvNBohSnJ5fdcVtic
gL5o7RHrOQ/vywmyKDCmKwW83hEivsTcCJo9tEk3H1ReXy2TYrCVxV0jkvNVQHgZ
AFaeovEOS6511pIJsXnsyRhnGQmGg3RdCgar2vCvApdN13MGi6KExwmv3YsVOeQw
n8kAJagzTd7oJbY1C1G/ejSn6ITo+jlbqjdulYmsJkpOyr4pCEs8KKeFaq1a0pPr
EuGahxxAO88VbENOiCFUUn4NbRcpjRVv70JaqSXQl4BhMSKknyUXUa0LocuTtPWm
sCIbbVBkKki9BRaIAON7VtADs3otagvz3qKMboGALI/p2HjtW5nJE9G263jDQCuh
eoQKuhKHXh04JCKPwKNlHBzOLY7lLx++k1z+HM2onX5+zxjinMVU3GJhdCNVZGYh
lkynLoqUpjUQpehebpGsqMvtUStmRQP1h+1NjE5tVIChM4qEnSMxkMYFEaedvVEK
c0e8CEkRs5j/ARRp18CgDFXkXuL6hKwns4UsmXFSnDP4nYzSE7xuGHkVpwLuFesn
2K8kOAKcyjDz4jBBL2KiLKWBG3FtsZS9xj2eXlFF3lv01+Y159h81Zjsfg74ncGn
e7NlsaFLLezZEkVrHwscazsKZnY59Myb4bcX91P8w6YY9y5FUrEYmXXRabt3yBqE
Xwa1i8sCsLIPvxcYZT2ncltxn5J+Ot+EzGVcxFtw/cw4nhJu+f8fAvzK9WiG/Mpx
8T17MrTUw6IgFj8SB3GVO9SxHvyMHzSMyKuMu3WTwRrShT6a5gSGiN4nRsrz9/OO
VBjqqq4UArFKauAkd0AojTcnnIdqgQnSAU0gf96EqICMjmOCvmbfhzBcuHEK6ZFo
cW6Xl/AnTvquaoWsgM04SEnBK53bVMXwv/oG6JY6wJXwiL2OgHg93K1dClbdx4Cf
/GRYTW0n9tcajLIcCep9T3SZDUoMuLDvdN1vb9zlg+HjwuhYF7hEii3s31T2H2ei
s8UZ+7nHGzzqvSzhQ2XRWhfck53FhQxVNBNJFZLiUhTRgapiAhq6ybBThY570U40
dqx517NIkr9Vfi1czTKbwUGno823lFyWHj4nTevwYUuk4zy7aYU36ZyY9Gh6YXeM
vbkw1vH9aXg/lpl7aTmQs3y2iO3NGdpCZOUyTKIw98ToJ5Nw7fpeyo560ROvFbFZ
yZuRYQsG1cwugLtJk92+U4i+r4BkfF6+e4vnXzmvq2dCawaq79Zpr6kAH6AVEAQ+
25OyN9vrhVlDoo2PBozLoh2oPJ/0pHzIzf/wqHkP59iUZ+wXP/puBAdPv4YEbPxG
h7UQhaQH6K+p7F0oXICMMczHs4EXC0t9HJ50Ah7v3g0bwcAETUb93AukxjPmhQpg
OU0L+UlEM+AVmRm/x4rGlgSTN2td6L5z1IC4gQ+akUTPcgLTyfjgfdKbK//rQm44
ftzNp5DFLCugIze5ZBCmJ2hHxfHojUHBSeg1SM7ICEyt8q1d6WLryTxhhRjGNHP9
JqTwUIObZFSqVWzYoiGB/5wnOR/Dog7lU7HX+h/vKYvCkJjqLt1Fv8Nso5NHmQMY
Jeil7i5363/0SUlZmMH8qx6tIL34JP0hG9paB1XIUAUxUJOy+G7bc01fNKrzNIOQ
8EFtyENW0XUH9RYgs5myxzQlxA50WlEPezt/aqlBF7VHYi1PuWGXYOmuyq0xbksK
R5xTZqNOw5Z8AaCOroNFQuaSEo6Xb+igt32mdCSqILD6npjofLTaMOmUCJa3uVNP
dV8MTYLjz268+iNP+jMXfJi2HkeJPtmhqkIZJa6eP1NErJGW2FXDQB36rYY4Yr0n
LyY0vq2aAURCyFSlOukK//hBbTge4j0IOpRPHmDQscKOlDTwMD7wkSXumDS0jZVO
z+0dYYnJWRBo8rwuXL3ADx2cL3zAJyUUm96jdGQoFCyispA6pGpQ6Y7KeOW2dFbg
kml9tC7g52aSFpKgw9tP09BXTUoo7rfMBO8X2fwBux6yWwI9H1qFc6GBlrczXXnl
a8kpczQBaepX8AG+TvNc8wqnNwitGJzHTFnQXbsB8VN2y83ZhF68IhF2AdnjrxcD
Ae84TK3BfanGYSu6nIGVhq+7c5Dc2S/RP5VquUYP+4RkfH2GZaoQcVYZX2BSfxn6
1VrgkOS5YlVxKmH5Ny9eB3FDzwbKatVSyDPhrbI+pGEBALxVXQrz5k81BsSoP0yL
m8lBS/TBV+48wERoUlotuafyQdrEjX3bQLb8R2NaaaHHjMw/r1GUN5VYgnnSFkq/
EgtZpaURceYcYzvq8C8Q4JeaoQRT0HL0PHc7eO61qmv1u1zpNU9pZYcpJOxHe3ha
p8Hl8XN9TXnv7051h9uPNv1QPnTcF9TDP0+CJFEbEhYmYduTFRk5VfUFLG6F3bLM
T8AJCnZG2OTyEZKh4DaoJcdFGWyY65r6weyAGM7R+MQjmvm4HwVnjkXL5u4L+ttn
H2IsSXi7VZgeM0Jj8tvuc/dggG1fmuiMiTlbsoTiw5l3818Z7LgrzmBZLGYG+cFD
uf2UNZ4onaCO/Q3GGrsgk7BjaoMvCtvCs46x3fWrGQlTettyPx4lB+safSHaiCLm
8LqzFW+V83LSy21IuLp7qkB/gf66FcJ3nYZYvH2JLns6lgSf8TpQSFolTZG27d72
Lk3ldxFtdvQjX5HwD3lZevMyJBHEiDAhJjvxeQ8EBq2CbepYTqpOCn97XKWr3nap
qcfZ4+vWhIACq9pMW0mQKcXLWxwGYeiaz6TqnTEWaiE62SIluDmdTOOGdqjd2LTb
iPleYcMdh9+pMTN6s1A+8s2toJ2YX2zi8NgnucI3f420+IQTXyJtm4G9HOV1rrWV
0cvQxuN47IxxbYxdQHl9WD1cY3fMLqJjqXEwL1kq7IKx5bnWv/sh5pf8cEWax+jS
gXOx9bx2yrS+nzm1LfI+xTLjrjz9dKE2WlxN9t7S1WZhdIguS2l8KS/gKtbYk5lB
vHt//MMchO0WwAh4+1dhnoN60em3rZqFHMO6o+QYtgD2NSfiJx0Q3EQdEQWi298K
WZic88o6syYt0cQ8/CHzPDlif/S9kXTvAoPaSiJAYJ9qn4uP8eQemdUXVWIcYAF9
x0HbGZ4pAbqgX0HzYe2dDJzvMouwiomx5AbJL01CKgGEKazxQaChybSD2YcaUx9/
1IUSLnnzLIgGc2LuFrzHi+cJlroCtVarb8DPdmRiDh615GlCTe1WltkdjQdAesW9
059DB+SdtiYrM2p52Yrs7lFz8ZGw6JBC2xFVVxsBEPwR/3e0CQFt+IzPchbfCRIJ
vUnvM7nFjTVgd4CP7pgYvrs6YelbagmwCh44gOlxRnehGXrDBFeld+ZaAXfSkpD2
mVCHPzCKNz03HmsdpHE8axUHAfY9Q5aj9zDPCCwyo8pnblnaUS6WvJdBS3xfl6PP
RiCeZJYI9wwDS7SDCdtsu5QjTv97+y+EZgqW+eFY/w08hGKca2CffjnPM/MDL8fQ
i2/zmmLMM8S9tPy4gJ3+nsLw0J4Hcaj5H6dkTWP5a84+RAo/BViQDQwgfU7HUtDl
t2HTalIIN5EVPM9B7O+IVtwUKhJVywUBI4nA/sreQNLQlqMfB0pYlvqy73iW8HMl
yC4gO9gCz+fKsCkaJX8Vli39Urspw/y/sXzYD3YhBSguidmCDsvNAx/DcbQPdVLl
tJOMrO3VMFq5M4T9PNrc5oRtwma+k61nf9vQCJVkWiwTf+IFtdzQv01uk8I7jDux
XDoo6MOW7VniYlKOlY214cHyNFu/Wszx7uw9bGGZ8sjkBV/q1XQ8/98bIL01MMAn
+KRuc0WB4rkVUseg58j9e4730gzE6SJpTnBix4qipmF8C1p0jQ/A5WbcGHt0O3Kr
GlOzSe9QqnaA5xFTkKsk0S78ZkHPs8yurPnrHhn3vFQAFtqw1Ct0xzX7CP9nFINa
62u3tGMo4ra41AwTaoy7MMH7bELfI8TwviXfKzkRu4LD5/kESHfP0F49bhl/s8Qv
xOxRX53Hj4ifIXmNoBc+F3O09aJxcOaZxP1M8mNkIyLDcnFSQ0KlkONZd1D/oQku
x/Z+F/Ki1n4sdfKrnjZ4q1e+xZFxcCy6A5GAl/SeFrz6gPQiKrV1FVfZsJKesTXb
JpZ3KJyJmdubVdQpFV9Uig1YqJUTlRdsa7Aqo/oa7C60Dgjqj+GMWc99YADzv7fk
XwimAu/O15yNb1bXyTXp5c/S9SjK5jbvxCZS1U0E7FBzh9xwHxrbB79M6exXmH+8
yDGefuY6tMR3kzlWV2cFhI0DAtm/BGv+cYq+toquRLDd2x9qJuVQ1f8Dgdgbnz+m
vBtStUmTsCf9WdR9aeljNQub3qHUcAwIQUt21s3IZYy7mm7k8eIwE52jx2cWD329
rNyqnBcBpicU+krBJz8He58vR1bM8JY46Vh8H2xzEDwRaCo8X3T+N66L6evGBjBv
YjxcbC3HWyRtzHU/19TmcmSKrQNnrc3LLXyCSanv6Lm+8myYQk4mRgRYpSvJiJuk
kX8iCRJSKtFONiLYU7w4k60RGcXnyYMAtLawrJYyytAIaeTSKYZ0dEm+SrK/8i/C
Uv0VPI0HEjqYx0lngR2xXej0Qnmg90S4lZ/hN0FbybGJkHtmluuO3BvXc7LrwUJB
6C0ounTqfHeHdls2ED2HCFKU5mCVwRvJJ8FCqjJi7cpvBE4ROj094Ng6wP+5mpSx
efMBFDqZNFmO2azxqXe1LVnhKZYbE4CLEJQ+wlHbwSQGAkeWm65dJTSvS2Xziutl
fKVefKLWHUEgEwte6mey679sRPt2MVhe0jNtb5w6QXA0EW+ZjEKd1isUebCs1N46
sNjSl4iaF2g+eaiwStenPGPFKcFldnR+wt64Sc4mX9JiLQ9czGxTwKR1BVLRUjiu
chd8Amdrdjjncqo4cF6vopjAwXqgbeyQUY3VmYs5BWrrDIc3W0sAkSx9im3BIxBE
JlpH93+PhhzCp5+eSPZCzdE82eiV3gA87Nuho8B/9xc7StzS9dSbEhkPbRM4cgYh
65SIh4+h3vbXoIiq40e7aegwWYLSOm3HJpWSpFgH69ul0btRACjvb8jOnA/ZjeCz
FNuQ3fkmr7CISK4icSav1eBNXEHmC/Jcm7tpgglaWGO5DIoiN6qicSql2ad7n9X0
F429Tt4IaqQgzqaFx/oFx9gDdwzdQDIRQyqMUCJL+qHR8ZRCP9W4oN0BcW4wNP+m
doDmwQSL8MM4FJiu6/0FmNGWfrS/Uc6qtGZxMJ96Rbbt0W6PsGyl9U/uvOplXiRD
c0tQjshoDyNI7d3/hJebMQ27LNtpaww0cz6uadL1vqiZvntAgvT+NfU9o7G04mx5
twsprTA9Vp28JOnmpW3Mgxh71ZijX91xcilxRY9BUs6GmVzxQAwesZfaOhRKpwJI
2E5jEpnaKOneDReQOvXamgF8FRK/AEh9Y4yJC7l3lQEnsjNzS6uo8yTuwdMMo54m
/iQjO4K0Gl5y3J6ROnuFZA0wLmtVU36iT7cQ5HehAUqy138clKan5Wbix+U3bYks
crFTz9ZnD3f4vwcgmJlg7y5ywHKeeSrKove8gttT92jj7U84ZIMb3aV43NsIqTQ1
9vGcdoVezVmjyIlQW72gZAa019t64XVXE5DOBUug9iJwC3ighEaHtKcNiMZBxZPL
dzfRrzdIuUfbmXqYNoLLJ2qa3oAkOinrq72wQA2mUOWkcqMZy/NSji8dEO99ChVs
SQhTVYSFXHNTzj4Y5QSSppnbTXvHqZnOqpBIc3ph9ZJz2rQmdKE5dOOC+TLgCO+8
L59t4do98KVGtheVuGsTffOhMY23R6BFqiBT1vA866LneiaMxsfLDyFa30YGxbIt
pTu3Af0PVRteWABwlKN/SI5KZ6QUXeC6tvmb595h2GeDrLcB62LFIrhIOpZV+xpK
xGMw83gFpqsM5zOgiPfi40ob/WY8FL7uINEylduX/9nCvHrI5LokxbIuFvhTr7RX
ViUm9TZI6wwg+Ttz/929IIEM9VWJfUYbBbYl35aZ6gl5YHLYN5Ko8XWjXG1Ut/My
FzUaLZblXvzNVDBJr28aQtmYUnJzdHK3cpWAHTFa5IO3ttQUAAtZzny8HXIkq3TW
LJwgsQp4b6l2jWw3AjW9b5nu0UU28TRgehJXJ2gFJhR1PJ8NPrdduCpsHaewQcT0
Pa6OUVQ3Za0KySigPwTtVFnEnx09cJdf+URT/xWfAxN7QWvA94+jJysDOTePvZFl
TXSpn0VqpCXcTPl+WfxOk3yJj3GOpplmXmolpMCm+iX3aFyKAvV7Sc2J4Xd4lRup
IXhu9HriBOUOIVK/BM0MaV3X8ldxn9gB4PMQzBUt/Zl4/9wfj6kxDQ+f9CyhPU+y
UZJo8OzYX8RVoUzIEukFfgWTX/l2mYUYKSRgFF2zeflLfOQicYrCZkXSQRRdWUwK
tSurvcZQ+Ic3QubUlnLPRfDUvw3FF5/xuRJcqHSJnlYHz4+YmtrX23/H0DoKFM1a
ZgzrAnag1Fbm6L6h8Mcjs0+GkBpaFo4HDSTR7gOYnw==
-----END CERTIFICATE-----
]]></artwork>
    </section>
    <section numbered="false" anchor="acknowledgments">
      <name>Acknowledgments</name>
      <t>Thanks for Russ Housley, Panos Kampanakis, Michael StJohns and Corey Bonnell for helpful suggestions and reviews.</t>
      <t>This document uses a lot of text from similar documents <xref target="SP800208"/>,
(<xref target="RFC3279"/> and <xref target="RFC8410"/>) as well as <xref target="I-D.draft-ietf-lamps-rfc8708bis"/>. Thanks go to the authors of
those documents. "Copying always makes things easier and less error prone" -
<xref target="RFC8411"/>.</t>
    </section>
  </back>
  <!-- ##markdown-source:
H4sIAAAAAAAAA9S9WZbjWHYg+I9VoCM/yr3oZsQ8UCWVOJPGyTgaaamoEIYH
EpxAAzhaKHR6D72B/uzaQ321dtIr6XsvQBI0p0d4RGZKKk8/nmYk8N59dx5f
PDw8cFt/u2Q5/of6esvCNdvy40dVMPnnnb30Hb7BTnx97YVWtA13znYXwqP5
5TQI/e1sxdddtt76ns/CiPeCkK/1+7y1dvlxq9//gbNsO2R7WDr9MT1HW/zA
OdaWwVKnHB9tXS7awjM/WctgDXvAboz/Ez+Y+RG/ZNuI30W8G/CetXZOvLXb
Bg9TtmahtfWDNR94fMg8FrK1wyLO34T0frSVBMEUJI5zA2dtrWBVN7S87YPP
tt7D0lptoocjwPEQzezoQdC5aGev/CiCFbenDTxdLw8qHMAvc1bILACSOdwh
CBfTMNhtcnwz33ru8w9801/5W+byedf1ERxrybeYM7PWfrSK0fLcqI8JAf1W
vVXmFuwEy7iwQYLyhxLCxe3ZesdyHM+nN4BfY2heYGd/PeWr+CV8urL8JcC0
saLVP+KJHoNwCh9boTMDlM+2202Uy2bxKfzI37PH81NZ/CBrh8EhYllaIPsD
7gok3dnwLiEFcJKN0XXB0Q8cB5ifBWGOe4Dned5fRzm+9MiPrDVfZSza0qcx
qktwfrb88BVsnuOL4WmzDdrsuOX7zNkBJ53oSxafyKUXH/fWeorv/aNDj6/h
8YcoefzRCVZpEBqPfMGKZn7opwBoWHs2u/mcdi/06+ndFvjUox0/RRj6xyl+
83GL/iNfWe5mIQtTW/SdYLu9+Tw+oB85Ad8/RVu2itKbRV786D86+MSdLarW
u2tN0ztsmYcYvH5OOwDv7yy+urJr6eVj6OnRR5d9WLoR7CLf9aObxa19GES3
X91FUvLAR/xw6yBcgQjuiWvrD6XHrwQs9BxDFwzbByiuP8PTvUpRNUUxl/wo
GUKO/9Ne5h0WfuH3Eu+Ey/grQzZF+Oq4ipLXDFVV4INZFC0Jvf1nQxAkwcgR
yFsrnLJtjj8LgBv4xPOi8KgJkpFt1/uDx/7zI7zzAC/F78QqsMfgUCu2dmOt
gpILKAIK7JZ8DTjkAZgJ5LzvT9cWakKg/4ytWIy3s2Tw9Och+f8E/20rUQz1
dQSb7bYMdVYfFZ4VuhHphgHojHWwDKYn/hMC+ZmWAFgAMgnO9yACwCbH+Wsv
jXVAiCzp5vlHTdGTHxVTOX9qKKJw/ZFw3ipWe+WX+yhjm9Bfbx99ywkJdZIg
allZ1dO4IsTwLWttTQEF622s/u8g6TuwAxqk5VRDdrj/9TMwL/ASbLVIePSr
Rz5I573vUyJ0D4DCbuuv73/7hN86s5W1Xt+QRNQeRPEB7AvPF2qi9jtwKQqK
9LhxvTRCO8Em+sLXedd3eX/LW1PLX/P/3//5f110JHJMZ80eBv6KpdDL79Yu
C/nBIXhosSgCcvD57dZyFtHjb2O+CUcLdz6u4K8X38Rd7d/+1zIC2/Ph+PBr
sd3PS4/C/bOvmOtboIk8to7Y4zTYw+klKdtnm6ygw8+CLOiiISvZBxH/Ctli
P/8TrvgTLPlTvlnt9OqDWqv/0+NzqZLGVRHFNHR8EKiLZF3QdPVO+juwyzys
xX/CVfGnz3zxZIO3cnnY3fsReCDwRD//+XcI8nU70MUOiuz5/YvESg9gNwWU
mvKgX38Y9ECC5QfNlO5j63A4PIKjE2srly1BvsMsfvDTNgSOkTVB+An/zzTp
N1PKCuIj/f1JE7LbMP5S2gsi/m/zkb9igV3dCmx0Vm94aHTlnFj1rS7+y2+j
pLwLgw0DIzVgS1Kgu3WyTJTScFfF9wmx8QFVIkgSWpB8O//QbPW/jSAf4I9d
GPDTpms8SJRdMn86AxfhYQUbL/2H6CIc2TQGmufHWvRYWoY+wabfQX2E7wwm
+rL34bwLI5qvB/BhwLow92GGitJGRfktYH+g9fly8sZ91frDd4MMjucDeqG/
E7PRyn9Y71YoMemfH4+z7Wr5p9QnD+Kj/Kg9io8q/E9/1G6OAptf5eXiD1/k
9HccI9/u9+v3z+CgXIOS2e0fvTAbgeSD/wrO0265zXr+En8LnB0eK+sFy2Vw
+Gm3+WkTROSy/7SxNiz8CX8Iou1Pbztrvd2tfopdz2lobWanj/JEoPB7nx0i
HiQGxId/hncfuvG7iZcbvwvRiLWOd+I/AbvLfAwCv9t8B9eRhmHgs8Wqh/Eu
45cWH/3b/ySU/tv/hA8iPgJ389/+H/BGePe/XFwE3I8A/SBv8oMoPUgocoVv
4RN5wgZtZIN9AR2e7c8gCHJLgRNlS8FhvQwsN8qW21lYIBvHirHMZwth4MyA
O7MJFh8iy2MPv4bKbupBPv0g2T8PALCQbtYSDCQcOUTt5bI9WwYbYlNyn8Ib
5+079FYBDWdkrUAT/tv/Ak/PB2cunDGwvWB40aTWr1gETx6cM3/Bfyp8hUtQ
8+qDaHDcw8MDb9kQJ1vOluMocj2zHIRpzME4GWC9mCc/FTzjCfL99qPIA60D
F+O8eHMKIDnkrouuvioP/qI8+E+1Qv8zH8UOKV+DRSnqc9BUXf1VCkm4TxCP
f/7Cs3GiW1osXCzZV34t/wl1EDx4Dt3/R2sAv/ArECn/YRsyxu2tEPTGFl0T
fOAxjteTwya2xNpslnjwbUBC8s00Azq2qTQD/wm0xGf+AGYJ3gsiYHsfIlQ4
z1VjQrDL+B0iAkh2uzAHccQ2BoLF6E19AMyyDxLwln60BVeJqLfyXXfJOO5P
uFgYuAAJPMJx1yig0L/gOAKfkLcizHl8iTMbKTxxwIy2v2Zn3CK2Iv4AdEcf
jv/ow33qDIB6cIggRM4DVG3CYA8Mcj40d6X0ef/tzNrCQVboJ5I/w3iQiXWM
sUT2eABjA0YXOMxG+WCctceEgL1kSCvmh0iTIGRg+fmLUwQkPLDlMvYso20Q
uHQ0l22AX1DbLU+JyuOilHOK1KVXlifkX2RTFF7C4SOfTzAGT514x0KYwz1D
BFprzl9tgnCLnGTv/CWxv70MnAVZi49ngUNHfkRPpxUdgMjduB/89hJRAX3z
VwFCKoJbvkdOWDA6r8V7/hq9RQcUM3POWSUgCz4BemdGOpiObnHLJOMTGz98
cBW73hGdzGbEoyxGG6Iltdt/iWJAQIwiOC7jdhtUJfGzYITwaPibhyfFZRAZ
xBBIXaQ4MHwatkeef5n5yGNAjxBdHEBt6gxXhbOxQlCkxA2HYLeETcgIWTfI
gK1wVzjl3g+3O3jkBFS1gx2pijsn/gSu/SMv/Q9NAFWxRflHfG7p3A5YRIKB
W6J5CVMKK/LfGZ15Gayn6aOCaDzypR07K4wz2dawYcJmXBrgM46/JkpKUZCw
JLRxQoYI/3LLEIlYcSvC4DpA2qDuAucWdBzshayIqAdx81HVgJYHFx0FdRsA
1wAdasEBaBR+wUciEDZ8nHNAUUcEIMjPMjiROUDg7umUlXX6sO0jRDEgNbhx
vBKqPLBbTujbzOVILv3I2UWJFvz5Z3j0gR6N85qYvfvll0dUasVgjSxEnjm+
WGLE9GQuwV7F6MTMZMT/0Br2Bz98if+fb3fo5165O6z3yiX8uV/LN5uXH7jk
iX6tM2yWrj9d3yx2Wq1yuxS/DJ/yNx9xP7Tykx9iS/ND53lQ77TzzR/wPNsb
M4qHB7awWUwCkAmSlYi7YATfKRSf/9//W1QAF/9Hr1KURBEQkPxiiLoCv6CO
jHcjiY5/Rc3EAeqZFeIqwPmA8o0f+x2gp6IZ+D2gCEIG2Pyvf0bM/Jjj/5vt
bETlH5IP8MA3H55xdvMh4ezrT756OUbinY/ubHPB5s3nHzB9C29+cvP7Ge+p
D//bf1+iEQP35r//A4csNAQ+LBIfxvmrKwsnuTDEXGzZf/7TPU4ERRzxN9RC
0bhEB8CiEZi9MIkfYZOffwYbc8n8/vLLF8yO+BGaDHpsz2LhvpEn+HJJUW6y
jhuQRMe6ExXnVTUkPsvKWoDw3yxyUZx4qI+aIK4+LK+CSfaUZ0dQC6D21m4i
V3F25gCe2OwWxBv/JJH72JXBgoe3RT5PuyybAPwk9KP+nKT5fnzkEoVDKESB
IBWdmIe7+sVK494+8X8+505/PCtHAgGNMjfd+ZiFWLMcx/2ce9sFW/YL9w+8
+DkmAL9mDpqAkEzGBeFgTb7y05Ltz8Reg4Bx3g6/+Tv+n/4J1pQ+x0e4oRp4
S0t0dtFJICMBGt5jaB7+jiSX3pQJmtiaJTp7Q5oZHV80INfAC35D2DyqE22/
hpJLoAzQ0N8BB/wZWJ6tEz3OXNACdVATSdUHzImPb1rf9jMQxaRvktIVu7od
F6N1dfRA6Vy1/k2yhtaN/WZ0ABCvN9wEigrxEaMObCVzfWeLPh8fYlHl7Kt9
21AS5gGVZzjBVnqgDjEDiDHaEpkVPQdcZWUd/RV4Z99ezfoKCed1AYPDyxEP
qFm//5Bfm0reJaeBgqWQLUk3AKjRCjX5XfAu57s4EeS3heCjWba/xMIUcA1D
JxMoe/F14dVt6DuJilpfXkT3ha3BbQoofQIgO8udi/LzwFf8cHWwwuuDn/qJ
iyZC0AdgXUXxCz8gYtVH9HmSYoWPkzc47VGnbyAW/fEzrN0PvO3t2t9Y4M+U
C6B3ihdcIgx5CpTxbJ+K+c83iI65nFmgv2K+OROMDCYfkBYG7kSnDzdFtRVg
9LTE7/2LY8elMZNEAqi2b4O5K0V8lLjQpXOlcgK+w60gMFsmQZ21c8npsxnQ
iF0oEasdAIk4KJohB99GV7EzDaYAq7GxYYCTVmOtjlwDbgCWW798myMRMtQ5
d5xEiGWBE9wH9LYAqWl8QiiRaO1EHXpnzsDzRB9JSahORX+pqjdJKTzPSHGv
6PzovAL0CQWWoKSAOyDsW1nrnWc5ScUASQiRUhw0Uaz3ACxtJagiMT1nH5b+
giUGHc9GJIUwy71CiEvEMUwqbQzx3jIi/x0PFrIkaQARCKCjHgx4iEajpEAa
C36M2eUprtwDFDeb3EbzcdQPNImZM7HFX/gwAHIU87GNxPrXj1dVm2I0dO5i
fJ3j5hRr4nH8KNoxzmMHoNLNzsCy4NrvbGAkcAlg1ZvN0q5EHA3fMcXxOTni
IIIhzT4AWXKGO/v6H7e+yXGkww8PrdDNo6R2gaBxAH5VZRg0X5nLgShv+0G9
4VoJTF+IBcDFQcOIu9BStyCRfSP8RUTBh3sUJNWxBvQQ/3xLwhIB4T6eJOUU
JUZgE0SRjzkNdFHvd6cgWZ8v8S+xzU1o8QXEACy7h+7umh34Tr0UW90kS0cp
DYriLh7EGWzubkLu6j2CLFzdBPA4YGlUTfFmSdCWqpNDeIJUCdmGwlQKOAgS
h8I3HxMRj3wFPrBI/gkqBDdWyKkgnwISm3GWHQG8iJw/UYfOPQzFAWBgz8HG
pDKTcVbiSpJ72ctL58/NobgPh4r9Y/cacpIYf33KSyPP47dAwqeAm3HHNLNE
/D/77gMA+DCLooflKqIqCxDkn8EA/+u//itmbe8/wPOdwlO5OODrpXJ7UK/U
yz0+l/t7/uckYexHwSdwe1cMXYgHO3BPn8Bj3UWfDEX4zIeR5Ub+J1GUVcX8
zG8WToRP4/+bn8zPyRrRChzXT6L2GVH4CdxWUed/IbC4NnjWsTFE+n3rEPdR
j1YXFS1hDRw99H+sKyZW2+sC5+TsaR2sTyt8M2bZxIEBjln5Sf/BOaVqrTnw
1UGgqa3jzGuXaJxgtpkD/EZKEBszfkzIluaZdVou9tYSdcNZrGjFm1ThxReb
Ub3uAgyqAqB5ttnqUzr18bonvZKKZRI5jp2VeMMvvL1D5U6VJEDX1Acld+L+
fC45/oi5t5W/jRV38v2luywlvems/dmCUywTyxclgn+PgCXcTO/dZ2cqHX6T
l9PfficjX3Z3H4JwCgb7nQ6KXOkG7iftc5xdWbMtPH3m38RifFI/p8w8/rZZ
+MdP+ueUwsMVZOXM3n87biCcpVhBNsW/mBVwzb8mL/yP1uCPsgO++m2OWG1/
nSeu3/9n4gr134crEHX/aRnjprX2+iDHFdMuH1h79MGT7P+fkx65OE9DnsAJ
A+srBmPGOaU+4i64j21v2nHy1+7FtUz5KvBbGOymM0TC5UPueprYlblniBxM
3EXb2GFck49D6dVNgpGrWwIo+KC4LyS60oQPrQMfOFuGblYYB9ZxXfRcA7hx
pK/0T7l0j/xL7GUmxozv70jcYvQD9rHAS821X85+5s3XfKE+4PuDXr1dpYDK
8tfR98HGpcLEx4+l4PiQUVLu7RQH5csuCEvsdV6qwNsbOaFgaU1R568fK6b4
zeIUmWw25CPw1ten/WTFYkBnAEBSx/+MGcG4ZSHKxVkfLOyQa48Mtd5ytn/x
D252jZeMi4/R3Vf51KuwJZd+8UsSFIOT8ndxkYdZ3347vTGX3vJX37oe8+oh
XyU0qYx8dDZvPbArci6aeLN4gHfQs3jA1p0+qOHnYaFZLz40ypMb9ZvSyvdd
v3P7wgOPr66DhHMOIVATWeTh3NjwnO/lwTnK98p87PInnxfLvQFu+zDs56vl
SxcE//M5CXqpRH+B5dc9ttm5vhUnNeG0qJbwiS+802viD/wvaS3+tR9+DgLu
4eUDUh6u/Ic4uaEg7XBVFWe5+VUJTNTPB5jiQBMF858Btz/F3/wE3/wzf+k3
eOT7jKUNxEU10e4olBSup0vOwZqLq5yYe0/6UOJv78LxyN+6+gjVklEnxddp
aHRzsZa6pkq3H2cpqdsgbiO4JjSX2AqDuWlCxNsuznyLMTfHjuVX/PyVu/k9
DI0v/X5uTjuo/8lZ+Y4T/mu8nMbH9zFyysr9pYyMaP29nEzb3+NkLgkCv83J
H1Bz6+DeZa+P7uv3clhr8Md47Orw/m/AZV/79r/FaFe0/Iew2mr778xstxgi
vxlPPKQO9wL44DEyL2VPajNzrpMb29mluefs7F7KzfB5vE7KJeaoOReHv67O
9iNHHuR9s/zlbgROGcN7QVjcWHAJB+45bRxIx9KNU67FfJJ1T3vtF8BihzX9
VUwyPNP1HJT/SzxX7MiJ3aBgfa4AcjGjIZ3jACj3e/k7CLmExdPp5y1/boW4
7B5gJSDZBWj5H4VWqsrwSVXmt/DL38Uv9/345b8Dv9wtfvGgfwijf0q1b147
q5PYI0pKjRcdHF3z2+f8fCzvl2bGm67POJLi4lj5Gw2sl76Z24Ayxn3c5XeB
6xr1xoi+aCI6ZQAR9sdUNi2DQY2FvQcx+99Zjo/7aLAuzPfL3WG5XSwjMZAm
2D4I/4+p/hSJEA9cKhV/SzYIkhLcXbj2tsR4Hxkf+ls+djBR6LYNuLgRDQsg
l/UCKk3FrXUoe8gwDJgqtU+UdNS65wa55HEuqYEmBH3kb7DFe7vlEpuWraSB
KulQRO6Ifwot4igsNXHWed9zyhfeSxK7X/m3N/XWm5P//PO5xq09SvhG4k2f
iwHxUlzKwfietQrXtcDExNWShGwJZFzKhHzPisUPKz7Gubm0rQzZJmToIZxj
8pt1iX+Zy7l+CEsuT3FcnkofoMceYG7JdeOS6SmdLbp1T6i2Q3FFKh9Eh0z9
3vSj7dUIn2vxaYhTYCVs/cMF5hFqjR/SAMbydYl/7+iSu8FeUsqiEkTC1Un3
9ynp/fjIIwcr4q5F/mB95c0L1/uP4FWkGBvfoZQH6vxrrZ/iHW4TBtiGFLcz
bRMI78jn42/VgP5DS0B/JPT8yofivi2aqdrEN0l7z+z+TlJ/kOG/Oa0/7Jcm
9u/2Sn8bo7e7JerwbmdGUnjFbDGugN6p41ANm5K5Oukb7grebTT1PRRKeUB/
gEY3ipFDlP/NyXSri/8dKHWz4V+bWBSKVC9rXLunU+vSPRcfxkJ+92bU0EDm
oUVdT/zPf8J2WCtai79wXCVdLwdGCDfBpTErfis6gbd4pE6o2H4l3Z3r5Pu4
lyppaiZf8WY3msaI+N3mivJLB3m6Y8hPgiZTFH9MNO0Yb43o1wr9B0mQFA6D
5z9SaEqXmEiP3i8zgWjAUT4J558e8Asx7jvG/T8NCqXPoG25UrlSb9ex0bnP
11vPzXoRjOAgX+2Tui+Uq/U2x5XHz53eoM+DL/l3HAeP4W+w+zUf8YXv16vt
/GDYKz9cBpUJvkqv07oKbmqG7AFvI6GsxAVV3Dmt8BeU4L6nCHfBznUCLsaS
dQ9OQfqkGoQsWNv6mMb+cie1fT14a3DNiEmCKH884V9kQAnsqxX9iuapbgfa
/JOmwDH+Dme74C/fiYut6ZIbfIHffMMl+NUmHY77vQX4vwb7f3fpnfv9peB/
N/iwCJzQ5F7QGvdqpVKKCZW+5sXfohC8cZOzviOz1+P/dub6brrwqhP6wOYf
s+S/4CN0689DMf+MT1y2KfGFyV2nC5OFZ9BTydA/APxtSvT7wU/t+jsOkGKz
X2IK36uC/QbJvqfM8NuU+o3U711M3E36/kUZX+77MtrfQ7v/JAeKhTbVv/AJ
jvg5nXCCJy7Jt+jucWEBcjTYcWPhOGnqcS8MVhiG82AdpW9UUf/lXjEq/eEV
21/w08fHR+7X1c0nkLXP+MDlW/gy+nV5+3iI9Kvndb86zR0F9i/J51+f5isF
kD5NuV2KA8c/fXN0KnYUL3NTiQN8HWF42/khi8fnb6YPLi7q1lowGnUMyEfd
UQdpPvrmeEt0d77l16Yyv/AWB2FKyK8Zc6MkL2VR+3uSd9oGOKLzjdES6hDG
7D/m0i5bxskOP7wMz3yJU6UHP2LxS6EfLYBwM2sXXdI51y2SkYDoulDqjI+x
z31vtiqZS+OdcEcX02DotQ1xZnUbzxLRgLNDRwOPHxNF50Hgy50sj1yd4heL
LvDBuTFqn0/GKgKbEr8pHFCd4xCkepLPU7lJbtG9lnGAoVbsPDScNGBfRqfi
Zolkwjq5ZwLo6DGL+qq5uKCCAeQZMhzziNOX8N2UhTSZhtcg/Uij3hAbJmFB
fNEUxXXcnz9chPPjF6xWIBsCpXCaIsUHZ/a7Dm1Y+8CPM31IQe4c0CZHugwt
0SwHxVXkyeBBKBeaDCZTd3eK/elcHDWlJHdK0Hw0LpYMlHnWyl/6VhjX3eO7
Juj1iKCOr2RYuzgeBfwxskI/2KGYIDtO/YRM1jeJfp68S7K6NC1UT43T4cUW
YVy+WN5cfnCN2W3sBUMcbCzgVyuKAocaBkBjxDB/mI6kngKHJR3ByQZJL320
DbCPONhtUZtQop1HzPjAuvEYox9dkgsXqbtJiT7yxRlzFkmTHC0OEsqnp274
y9TNOXcQE+YmrRoyrKjgDEspDDaxnNIlYalEAlBjBmx8CnYhWMF2vYg9fFus
dXj4IR9tgg8b4l0PNMf6DazEKiymGUQV8fnuqiCcYgJoiBFj4beWB+sU3Y4g
LhjbEPmpQS4e4SecIOz2Rbxhod3aWtn+dAfsQ3MwFgBjg7gR4a/UvkJAR8kD
38R5lpizMM4P93EOImHC023m+5z3VknzJwL6JR7AQzA2oAeo+rG9jNvEiyYd
Z+6e8JRkd6h8ED7y54kKwMCtSkWCEWTRae3MwgDCg8RG2Wx7YNTPtt4HOLC3
jCl6+QXCRbyci3jB3Tk0cwk2rwBI2W3o0R4jhk3dRHfTR3mZbEM5pIHImT+d
ATpWZLbT6oWto10yQpZckhFPAKZpns7vJK2SmNbHd/bW0nfRtIL+8AP3zCqI
x7NkRjTviP059vUAYXKAlL44fDUcs0Q7coUiNjlcfPNCv1l7KPXzn8/D8e4u
LoTf3DqBa0F4D6DB7lQwCZLRPcYhatcudsWdAY7FPcJiJJmx4DydZnlsurOQ
d4GfN5dbP5KNuI8bXcf8/O3NgDGuyrY8ouAi9teNadYTBB9RH1+8g6KERs53
cIyMGP/bdph2RXRiazDI8QEB/g2Mo7oHZUOQoQcQqyZSnsQwmzCwE4ag/Nm3
tbkfJ0YRTYBShizbvzUFeGMLWnKib4rTCDjUFjHhb3cA4nJ3hVi/dd8oO0n9
y7f+IMfhvTP3+82v6cIkHUiB2SXP+Essf287hnN53PmN+7d6JYnD9OjVp9u7
wYTP3Lm1Gmzdv/Al5vgroO+/JDmeEp2S+obPaZ/4q97lit/zx/A2XtsTP3L+
6as/3/gK3x4USskj99OG9NU//blcancG5Rw/qNX76NH/04/wNkdYxqnw8w0u
VGT7zcvOPuJDu+ID6Jjc0/ZjzHvo3KUKhYBTdLT+w9EmK+dH7ubA+F9D279g
/ufrt9M5ql9DOsKEsoxsjiWuuIljL98US8vxiOKH7ge8vwNFN2JL7yEpel9e
T/d6XFohklR2aun4LrGStbXOt4rx/Agv7QnWOV7mPwlH6Zqt7MdasE2G8Po8
/mFGzhRzrpYTNPxB8XIOy3ny9dWvA9UcP4uiywN1HLEMc3yR/3t+2P/CQ8z2
9/wo/4Vvwv/XWLh2MZLvwC+FYAruaDF/hTexVDcAtUFnFcgTy4EtPfGiwgtG
TjVyosiTJFRbg69eyNMlRfdekG9fSNpy/hC4ybsfLiQPbvGZ+vIbCDv/gc9S
JbPcV98/d8len23Y1w/gH0HIJX/F3PVnNfWzknOEnKnlROn+CoadY1ZONnKy
kNONHLNznpbz7Jwi51w9p3s5E/6ynCHmZPP+CkzK6U7ONnOyklNYTmM5Vc6J
Zs4Tcgx+NXK6mjPgLywo319BAhjMnG7nRFhBw+1gHUfNMTmnWjnRyAk2gsfU
nHjlTKzrgLxcuqCi27WTr89Eu51x+RoM5Bc1ly/kKkquWMkJck4zc4KU0wAr
+Zyq55RSrqjmSmquIOf0O7g08nhmSYQD34PjerHBfzQkBQilHTLK6Jmst1EO
AmifooSvlirmc4PesHxvmUsP5K+9ntJlcRKv2GvST/Tor+qW65fUJHI95pW1
v/VXyZlOTtZzqpTzPGRMV7++7no5T82pNkqMbeVUIedI9K+T0+ArOWeLOR1Y
1csJTk6yUDjsFNtCXIzCxFBNMh3VDEiba+UMN2eBuOiId0XKyVLOBQkwc4qV
U9zr6x48YCNHw8qik1MdIq6M+8KvALap5jQ3J4s508o5Zs6BlZXr67CUxRAe
kFoHqC/mLDiplzMAEjgOQzm2lZzt4e4urCbkRO/6OoCtwrcuAiZaOU3N6ULO
JZmztZzlIqiwu6gh0kAHSPBvancQR0PD08GhYFNLyRkeohEgNEFhKCimkpyT
JDqIjku56vV1WFPSUIuIALaNmxoSAiMKOc1BsHUASckBhh1gciFnCzk5hXlQ
J7aKekikhxURz4KEFuiwsKmMBFWMnOGgHXOFnJTaHZ5HCbIRJypDdSjBgjq+
DucViabwK2gs18gpNv7AUoSTHcSV5yBHyRpS0LJykoLnBeSD5QRkWgaST3IR
mQCkK6aYVsKtYQWA3yCVJuqomBUgN3ApKDw9Z4GKZcgPcC5gAC3FtMBmwA9M
RI0IXAHMBuABwMBFsAtgElQsaFCm4OngRSCKmnrdlHBN10a8AT+7DPkHuBeV
PTC5njMEpKBLnMwASIbIvxJOzoFFBVYEAbEI/8AVQCA4MjyG5sJAqID/geho
cAw0CNfdgeu0HIONPESs4+KpAQCQSqbhWyh99DPIjuQgZuQU6gDDwDDAG8D5
gATkASWnevg8iA+wkGki5mV4wERCIDlSThHQCB+TESfwLQAGRwYYQFgkWJBk
H1gd+AF2AdGGkwopusO5YAX4xLZJP9g51USRtzyyjSApTs6SESFAI7CEnpUT
UruDpHggL7CpjmIr2sgArktqAaRAQG0Dv6r0DG7hIldcXodzAW/bJImAVYAc
GEBniHDNQnsInOwoSHdGOAcBFFKvAyrAlABvWBL6d3BSIJCjoU4ASwub6ibS
C/nWQQIBME6KbWALYC2QQRO0Cuwo4ymAXkAjUBrAt+AvmArpMdCKLgqdpaV4
nkgG8g77gv23AQZiXXgRsArnRYSTmgW6WCqqMimFefgWlAOoOJAmeAadFAUh
AecCmZahxgaZskgJwK/IISllhTIiIVpAGwDpkTcclC/gH1gHFDWcC5gHvoKz
MA8tqZB6HTxisBGAYWBv5EkbzwLaD7AN1gHEGdQdHAoeQ5wQDzAjpaw03BH2
Qg3vkq4zULhUFTEJJgCgBQzg2S2URGBINXV2QBFoCZA4IDrwGNgag1AB5wVF
54jIkPCirOKCsBpIhJw2kQzxCawI4AGP6RpKNMiRTXYNkC/bSCxwzVTSe6A6
5JTAAlfA2cFZA/0JegPVtYuUhWOSW51TTNT8YCwAGw45hmbKN4TtUBg1VE0g
8qCI4HUwScCfwCTwq0PWGY4AXA2QS+T6XSUuNg0qGjgQFnADkQPJWsEnElkc
hdQRkAAMhyfemEjZRc0PEDoxolTUe0BuhVxUoDI8oFGUA5oWZBN4z0kxLcgL
nBpO55JTDLIGvAHYAPSCzgGEg+WCowHng8mQDLSGTlpZkZYDjQdYAkaFX23C
EugQnZxcxBhDGIA0Colbmu5mDI+M+AE86MRmLuFKJyESZZRxIATqZA/VL1Nv
DDQIAiDHJm4HToN3AXLAPMhg7GkA48FBrFiHOCiSV64TyWrbCCEwJDK/gAwG
5gnQCM/Dt6KbRANADvCjvJR3ATSCxUHcgGPBhqJR8PAH8ENgEUS4jg+AgoIt
PNKocto5sYk0KqoUQCk4/jZxLxojhqKNGlsj8+2hBgOF5qadk9gn0RBIJX7L
QzsLAghYBVyJFE/AQUD3ovYTkfPTVgYOBbQGmFGiDRRYnU4NSgkIDRSB3UGj
grkETaiSVrkaaFiZoTaGH0BCQUmKFEsBM4A+Bz2jkNUAeoHUAD8DB5op4MEF
QtukE5IFxDCwN6DdJpwAzwCbAcMYJC8mcV3aMQPuAn6wycQDDKAQNNI/QB0g
MUACiAKhhsWBo0B9AZBmSuJAm4GrI5BmAxgA1RrRDow14Bz+Fcl2oFLSyae9
lXfAKngFoMoAKkA1GkQTUY14k/DsIDVgK0F9AQkQqwIar+vusTeooO9nEdeB
YQKATXLGbPoKZAfCSjDNsA6YyzTqgJFAoYEN0sg0g85Bmy6iVgFuRy/dQU5Q
yMQA3WP/6qouLMQbaDCws7ARCCPoE5vQq9KaJilMYDmbnCVQyGkTaZErjo6Z
g+bGJSkD1gUOTPx5FzU5EBEtjk2MnfYuBKQIyB0gGUVeRdkxyGTAsh7pZ1BE
FlkudEGlG4HFVI2G6gJYBZYFksEicBAkH8UjgCtgZlgTONYl2RRTu4MtABUB
oQq8CLyK0i2ipwSrwcHBvwU1AodCNpDQ/mrEPNfdKWYBnQaHRanU0KaAH+WQ
Hw4IBD50iTRxeAWOpZoSGZcEBEgDagHkSyDrD/oNLJ1NAgI/A5+IdBAgGbrr
KbYBvgK1DPBjVsBD0fDIZwYhBSS7ZLLB4Qdzw8h4gSr2UsGySE4ysBNwBcZx
DrKfQ3YQ2MwjnIAiBbICxxrkIQjps0uo/QB+EGpwVnUXkQarIY1EZDaJPHyN
PFVEo3PDdSCMwCo2eVYemW90TjQkukIa3iVgGOln0FcgMmJqdwwZJHzeoXAP
1JRDsSrwGAAPOhO4DgAWTVIapIFZ6uxATYWRAy8itGBogKWBahAXgKQD5kHA
4SygSSAiQEQJN15lnGGCI0DMAuQ2yZgCKpBSBip29JYFVDso1BYZ0LSyMtC+
g8uKKSINiY4WSkH5ArDhULHfCKSEg8PDYDLElLKCUAWkFc4oUBAt0XkZmRhQ
F/Av8C2oI0AIaAlAIwZrKbYBnANLgImHuA+0DXAFHFMjjgVlBQJukRUDTQK0
88iQpekOTIggiagGXaKOR44c2A6bXkFH0UVhAay6dhLoXc2EiwuiO+2imQBW
B5FHxesgM6P1t4iTKaxAF1S90TaY13SRx8ANAwOHQShlLYDEFtl6MBzozZI2
AP7EXETKxlkUdomkzRjFLGAm4CCADYVyAuAIaaTnkaUlFAo5rSoVJAogE+QR
yAo8D2QFBYgnslEGVVJZACTwf+xDKnLcHYT/POAf6mumhrB6pV7MD8r0Kdeq
16vrebGYH1vT/KFeyE/rT/mO3xOnVm9g6O+tvFAtnt6q/botl7rlp3K+1WuV
jGPxPf9UmLZHXCE/GeSXo0GrGx2K3Ulp1O3WS/mnl+6g3G3llWpeHJYLh0Ot
Xx2d7FVvb8/LvVbeoM+L00Od667MtTtuTbtC+VCbOe3WvHtoD8pCqzQVO6Xy
8QU/e//w2TyfPW/IwY7V8uFpNHwvN1v5Rbxy/lAcLcrHcinfQTALeadVEGZL
Z6UubEk5lgf55/jzoMUVy0/7V3n0Xi+3C62ycih1J81G8Fqf7Z12vrvo5mGZ
524e/xToH/oZTj1rNLX59MCxzl7KCM9jT82w6WDte82FMFipg6pX2lm1l8rU
bIXaOBr2NmrnyNpWNR8d1F5nPnkvzACsKgcgu6Vp96VQ6E0q1l54P7Q3+VVB
GwlyRbTbJ3+2mFmlvIcg1/qtcrWUf5mmnuXuPEznq/VahbxnlAuDfCnfrWUT
irilQ7mQPXTLSPLCPN/mCtPobbbwq+ZBKBR7+VK52ykWeuX8hz/ldcntZ/X1
WM6O7Ly96R6WpZad7Rw5xzRajd3bu/46Ye87d1Jw39ob2Zl1583XzHDTNk/R
pDE7Olb3+b32dBrZg6p1ct7KA0t79432kQtLmdrQVpRtM/sqP+W92rJvZnqb
pdPuVbdvYtvuWWrmtBYU5bXYn2cW80O1vBK6zfqp4SwlecTt+hO1bG2r01Do
2s2e9tqRa91m/t1ovhRqzV5h9HQ4SG5jsFv4rYGZXwK69UVF6debzqEymzBu
m9En/Yy+fa6VjOz7ZPLmd+cztbJ8exput7P3Xn69PUwnwaRiFCqTvVoLBupm
VKqsX57CmWKs2pw+U96E4auosX739VAZL5YDe9sJmZ/xwmyR5Vfm2FLq2iE6
zBu2VnbMcmEZPdvKyWLjQmtmcOulHTWFfbs32Y/VN7d7zExmzYJzrB8rWrh5
E2eV7Gpcb7y+ld42iwmzniqnUv61YmRbUqa5eepymWO9t5xO26d+t72TsvpL
92XvqZYRZHsTZR80+vunlqm37KkrNrpW8SiPnlo7Sc6/tVd6w5kbnCLrirUb
sWNnEHj5KD87jsRg+tpdGhOvUnlSCw3f0Zu1mrWYvK+as7mpOZFYfVKWhaO7
HmZWXPFNUYf1l1NxIvqn4aG3Ppx6G+uwLdvicTt9f2s/zQbZot5iWt9prt8W
c9YM5vnqZl3SxHbNeeem09pQl+tlcblfmv7BDgO77ByeyjPXlsPGc2C+rcRx
Vaz67c1oV9xqg/zJUg3RnQRh4/Rkd7j5uKILUbm9mo9GDaWbKb2NNfGtIM39
zrtsLPSBNHup7RYGG+0HT6NuL7Ss6KVQeZoLcvkwWL1y7vxtJfTNcWibxnrk
tdoHYTMrLvWTYFUOSq3SUjfLw8ko9Fubsv1cLT+7hadDVK5IstvajesmZxvq
xtjUqpX+y7M0n2V0McqM31/CzXr60ig3C81ihpVHrWjvdBcssy6/z+WXruO6
i02t1Da2J67XdtpOfTgoaqf3kl5aKie1vns9KeK7agyrixJbZnaZ6uFp8uqG
75G8NCrjTMHzx7VXrfDqjbPcav3WWm7nyrs5d0aOumbTQpi1o2z1XVwuWxVr
+1bs7N/6madNwasd7KE2z6yWAnx2nDmLqTHilMOoUamUWV2p7d+zLPBrY6XZ
n8pPgbOeiIfC8KCyodlYVzvR/lB/eirYhTYw4bD8VJEzT0XGnfaa/uz0imKw
Kq/KTeGp2REkUQlf39ZZuzAfMm92csSOnd8JZUdmC6tlNveL6GVYbdQyQ6CC
opVb3U3DeGOtbT2oi55cHvm1wlve2pZfG/JyuO2P9XBbZpJS90xpmHUWjiWu
e4tleZM39IjbC9VlpbocdsKuKg17rmE3hXF1551GGT3bmtcCZT/TO82uNdrk
QSO5/lyUO0bFPdSeZv13r8Itg+PWz85epLdD5rlWf3rf26XsUn5um8vg3fJc
U32dS8HBlfXp6T2zG5cnzxlLe1OVxe6krZ7eucPxfdN9KrwMjs3Sbt8Npd6x
+94p9KTOLvt6mraavU47koyBNZPWo2JRmy53itrLPBkvzurgHmxuUvG2G//9
VDlUshvmOq+thVF8bj73O6f6rGOUDvtxWBhUzOzaMJxhOahIPW/HjkPmFt9X
z7syty5Zze5hPzyxw1N/nR9M9nXp1OyJ78WNXGwUXf24fvHb7360UPOTca15
NJ5ZZWU+eaI+qhzyeS6fH6m9Y8N730Xu27PQjgqzsrUzh42yvah6k+3zuq+v
B5NGuHIbjVpgT0urabEYBEHnONKXL29c4JyGYmliRaKzbDWEaLzqaPX96Y0t
lwtzOy3Vi7Njxj08ZRanwu6la4csbErH6Xjs+pO922hzx27PeFEblu9Zhrgc
14oVwXipK5Owmqm/tRkTO6pr9iudzSR6HWeehdc9qF1vXZ1U60dneRC4dtWx
NtLGHDWeJ6ujaWfyswIbbUuxX1Rul772ipLGaprd+9u1F9B/L+tv1l8ALqLO
0DGGEAZCcnBQMSpXKVtL2VHdoDyhjrkFw/nqZZkiENX99YaE5L/JG/9JdyRU
enFl/9kK8f6Ba12fkPp7ehGedkteFNAFB1gl5bd7EfAF3ki/8Gu9CN8N6F/Q
hXCDpfMf/PCv24eA1fw4sNcw4QJRpUaVEowHXIzZ7q6g0us6hU/AFhCM2RT0
6pS0FSRcyqLQxXPurwBbMKpj6RQdQfhkM0p5UOkOoibMRbr4rf2NXgiRMoMQ
1sKLmGF0MS7FlDHV/HSNcsoUQVnu/RWQxQUM4A0JD47AeLnkPzKIf/66TQsQ
qRXLKCJ5FaGG8L9SwaAPs5TlXKGYk0rIfGWQrDK2E3y1ALyqFbDLoPQXNi38
rSH5T960cJGs7+paYGoSsdsGJtTiujsE/x5lq+Oah2FhVuKaOKCQ26IcIkbd
lBwXNHzMpcwXcCZwnUPKRqSkrZVickzwSZgBVKgAzCjDpQgEg5nU0RWTciUS
1ipcDzn/mjigtCzwNvOosm4h/Fi/oWwmgAT6HaCFrV0Bk1m2ioXwa7bLoio7
5dAdF3MKIqUmLUqPmlSxwCKNkhN0lHesCaVz6xbWITCvRztqlA6OC3gKNXpp
Ogoa1lokrJFgDTWlIpiD6QyFcvGqiCkV2cLHmIhJdkHBrLRDbUvAuLJJeb1U
jhXfVTGjwagC51CWE1QNPGaRYQO6YJ2Skr8GVa+FFOZNE/sbRBcVCxzcoaot
bMSomAoa0qS/ooi5NlNHJaOnylGYjaX6FhhLpDj1LsiUHTOpmoKNJpSVBpWr
OEgjJfU6YMmkJCCSXsWSOaAO2yMISzbRNC7GmAYyjEEF2ivTUneFQrlO4C6d
ujqAOW0RTxRzFEACahkIgYVYhgteU/MKppNkqhTC89iZQTVX2UBG8ihHBp8b
dHyLygM3mX3qSIhbyDzKzmOPGWWdsBVDJi2tI8CujnUvQ72pH4MoAUUsgbLq
JhYVsGBsYrZXjIsiJhIdFhSoTCKoN+lp4C6s+qh4TCCoaiZlJ0YWRLAoWSYh
ZybJXxnpeEWdTBVHqtxg2YnajFyq6gGlsPgkYF1HoLyzTaLhpdQFlpapiAWY
0Sh/LWrI8zZVrbBobeIP2DYkoPCCNKXLUbZDxUvqDzA8lBFswrDxmMAAAjUf
YDLRpIqmSRKR0jZg4BidC4gCpAftYVGuX2EooYzqwXBAkHFQIy6VQHTzBnWo
yiQ04io1PQCoMiU3NRH5waGMp0mKCEiMfJiunRPDayp+5Yho7hXqSTJlVDsm
9cNhecxCbsFkt3qT5ZRkFEzYEXgPTsHOHVGeR4uoKMVAcUxxUtIZuMg2brQN
1u0UfBLOZRJs4IdgQVRGXGHhU0e0aGTf4RPLvNF1AukTy6bqKfVJILFIvSOT
W8jPoGAtKkkCdYyUR+TG5RCdsv8uKhbANlgEYACDSv6AGSC6KaKuhmVBYNOK
2qByNTzjUm8Z0Ai2A0IzqiJ7VG3y4vKShQyDHRXpGioVdJExRGpVoVIryAsQ
HZO8HmaKMXHvUs2JSi9uqjBgxpUecvziFLlDjS+OQLUoAT/HrjsdxdaixbWU
yJhUesSapYSmAfgNngGzAoZGprQ7I+cKuAL4Fp5Eq5EinEAhhED1KpmaG5AT
KL3uUr0cMKBQPwf+SjWDdOEfVraobQt5ngr/aMjICsPPKrWmgQ7XyeJ41FWT
7tTxyKCIRDKwpGrc3UVVCoGUMPiBCpXnQZ8AGrH6lVJWFlEKm3sMVPjwL7CH
QGVjlWoYcGT0aanj0yJtrKasjBw30umow9HWi2hiJKpCgX6zyVtAs26i3ot1
abqSh1qOujEAq/AAaA/4NS4iKhY1miikqy20oVhB8W5KcTqVk7HgHXfhGOjM
wBm1uJdCRBJopEBAIUhUtLup5IkIKmwKgJlUQ9KpRgIYjiFRSNkC22hUTQfm
l9JMS0YE3gVXBOWdcKjELQsaQg7CDkov7hcEfErCjWskE1uCFADawZyBwtGo
pRJ7BAUqyUio/UBRYy+IgTpBSveLUD8csJZGPXAyVT4ARYBJYFSNND9+Jefi
7kmwUOkKrknsCh8im7mIGYHeBdsB6gsUF/YeSbiUQKXouOkk3fQAKlGi4jQa
NZM6wDxkPOyl0BFg+MQjBAIAMpE+XQi04/q0hyRAl8xCucCqtkPy5SIkwL0K
AY8SZNwQTqMeKZt61IBFEUKHtKuHlgtkH/Q8HFDTk+ZIJ4V5+AqYSqZmBZBH
wJtFFS+gskYVRGwPspAQOrVjyoTJq8TJBB5V+oElgNYYKorUp0WOok4N7SJ1
VrkSKaJUuwmoNYVcEVfEw4I0YYeTRrU3kfpoKZJN+kJENP1ppxQgBLTgMQWK
dqnDDAQBTTmj/l3SfgAhVsHJBEvpLmSbRNgi4KmbyqZmOEYspJAzCWyG/Rwy
cr5Ox7+8Dqc2qR0KVDrqPZkMGWlLMKbAJAp5+BbV84A9QD+k2w5ADC3idnA1
QVLi1haVNC3aR2JImxpWsJlJpiMoN0YKO6uoAI+9MtRfqBDFMX4RsLKI3brU
yIt9OQ4e5Io6CkZY7I14eAqVnDGZOmAUyhIgsaj5w6Uit6bcqEqBvGWP9BX2
+RnJrAFIlkCVfpwXcNCIgKuj6jdmAuyXQUIKgCnkuoOxE8i1UMhjVOj12DcD
tAMq2G37uEj8jF2MArWbONTfRg1zaGFVJDpQxKKyPRBXSgUjIKE66WRAOGBV
IZ0mUcMTUAqzHBS76WS2TOI6IQW8SIZMp/q3SQVmbEh1yaeimAIwIFKzi0yx
iW3fZCpE8p9lMlXI6tQNI1CoCNvJJBHIVxqtplITTNqnpbhDpQSLTIsD76G3
Rk4C9hXZaIJBS8RdhoC6dDRhUIeQTk1UIo2EKCRfgHzQybAgI6/Do3ZPkeyv
mjJSaLxsZNeYVUAj4dCKjYQDDYk+DzUExJILzCN4t7VznZpWqS0JPA2DGlMA
maAPgUaMONwlSdGp1UxwbwJw4G3sD3BRlxpkxFF+KV5WCWCFXHSM5RXUCdip
liIcxmiEE+zvp548WBCIDtiABW06AjCkSfrHJYVmpdjGpp4Mm2DGoEClaEWm
CJqRh3PuhgHcwsPA4WraOSG/yIpHgSj2QRtBHbfYsRc3u2i4rEJpAeAiOaWo
AVfYJWOh92VRMBVHZGZsFklIY7sP6gukCZBjpt1CRh0wpJNdagkCsXIZumEg
RFrc+0XWLU596PrNqBGel2IubPSnt+DgBvn2qADPgQD6ezTLBmg3UkwL/iT8
KlDyEIWd+qSBf4DbQVIAHpOUMFgTh/pKkXYp4MGgxClHmZovgU90ahbHoScX
yeFQUOzFcZaDouSm5z00ageUkw4qHNKQ0UWP4zjdTDq2VerGAI2NPdmpzAkY
CJe8ZYfajCwKKBTq8IPDSjTnoFEzMRgXCOJQ9aUVNc2uiNTbp1APJfxrUmeb
RbgCBQVxCnqqpHNM72bWRaOWenjFoOYYRk4siAAjEjBKSeGwCskC+EUWpSDS
FlanxAgjqIDW6KJQIgLjQRk5GaiAWRRyLB3qhUrbd43YBiQFFL4XN9nrCAbQ
C/Q/yL5APXbwr0MOqpP2aY2kRxPAAP6Uqa0WVARoBomiIZBxIK5pJz3WGOKl
nFKVmtpxoCJOlBEXWYQo4CjsSFORSzER4SaGhqXcAxBDhzrMFIJKoXjNob94
cEqjSdSKalBrryndyLtOg0AOJeUs6jSCI2iUbFHJ/1cpsRw7fiaNhdipENgl
L9Ejf9uNWww1cgXJRcEOfhkhsaijVCYXMd1GHLemgWJHN5JmAxQKLuI8Ffyg
UD8cbGpSHy3OjaaAVykf4hLtcEiJ8CZRnhAOYpBrIVO2x6PBFRTJdH8YtYzb
1BcukXcHPKZSh6JAcaVAzYUuEQJOIZFXnA5GLEqjgVzAQQBRFoVCQFDU3gIe
AVCBJQl6AIes0jkrRu2qGk1oUPQHj8VjRdjlT4QzqdHQpBBb+eBdkH3BuFtC
x9Wj7jqVwhA4qUb636LYCpsyHWROJcV1JvVdgRTEmzKKpFSaxwQ1pdpJuhWi
JJeqaI5yEwaC9kYDGk+dkTV3qfEUuAhUAUZelCszqStRJ3uR9qxscp9kGudk
NFkkkz0yaWgBJw/JQGsM2UmmWR3GbngeO+coDJGo89uMm60pdYMeqYyqEnvv
XJRB7bYD2yX3VaauX5mG30BtglVy1CTPo5PkOuQ06tQ8Jyo3VgZcPhAuRuM9
gC6XMpxC3FFtIFQmeR3A0h6lg9x0Pyj1i1s04IGNsOT0ApwKKRw4O/YWU4wG
5g/kOp5yvWLeTfq80RbYKFZoEx103SVqDYcXNZrBMGiCBVP36d53DeFBy0vN
jg4NzgFIJqk+7I8k9a6S463SzzcjExplRUQaqSJ9a1DGSSNWAW5EPUY+KoCB
obGEh73qeUqiCqQA40ZeEBNAoEneODwsURgIFMf8MLlwpn4jMkhuFYGXqfcR
MzY0XSCTPxzPG5g0EREnYbTbaAJYHUcHJTTr8VwNiDz201NCG8iNiGVJuyHw
WLq4AHrPpNAPo3iX5J165SXK5wNmMPdCUVicKgcja6d9Wpq40MjZw6ZzmcAT
kp57nfK0sLVHc4MSTZ2lDbROrqZOTe0OhVTeOf3ikX3H4RyaW8MOUWpeT1cH
4mSFTHGrSBNiOO1GIzdmPB7DUHdZ5NVAfGc5N92omJUiDxD9KCWpzsR0RMOq
oQZmlLNC6hDr3uTn4/EkEQ+FEzXUAh6PMXgUtng0F+pQFA9GFrNzKbqDKccS
hp6MOcG+cECc87Goa9xFQpikslRS4Mifwo2RAt0FUoBdvBTag6jalDU1KRsv
UDITXXQzmcVNN6/Dix61+GNeSCTTJtJ0ARUmINZglFdHD9kgmSKn8Yo6FbGK
NoKazgFULJ1QtGvSoDpiTCRHkVQl0EhIKSuZ4kpU4DbhkGQz7v0FHNr0L5KS
vKz4LFJKYDEjLZIlojkclYYK4PguubgADA6qWcjwIJiym7Tvp80EuPcyDaCi
GqS0nkTZRZwBEPBDlfLVjDx/k/zkq7qg4RxGmWogfWxYDWriR0NPFjkOUU1K
fSv2zTioRWkNFAeGAOPwg43IB/mCsFelEr9F0Qom9hWaWkyPi1AA4sQanpCD
ZQiGEFpUXlFo0A7w41GTuqLfDKugVOr4JE792dT8TejyKJC3SF/plPjyaDJN
oY7wK90Vms6l1nCRhgq8uPOepECg6Rpwd7FsJNAMHumutD8Ph3JJsTPKBGJa
TMbHRKq5aDQyJxB90fqYNxkzj0pUEIrigERcs6OoBIc8KT/JaNgDi7kuwiYK
N4UVh9wJRg4hrAOqBtgYOAH4FqNmlc5uENPGExQqGs2rZ6VQHltDVtHJx8OZ
zHjg1kQ9JpJxdKgKoNFctJwCHsenqR3CIb/XpfqRTcPDOhWFAQaMbWn0GnPO
7KZx36JuAHjMJIMCmlxzEo2EI4Jxx7xIA6Ia0k5ybxwzNc5lUUZCoR4Mkyb5
NZoHRsOkkXW7TM7Q+MdV27jIMxItrpPrpVGg7VAlV6YmeBRnSn8p5KikjRTI
OKAFKUIVw5gHcNiJZt1d0jDwF2JS20kGlsz0CLSKr6vkBZk0XwQ+fJwxAIWp
UnyBn5B7o5LGTo/GMWIGzG8wNJQYTdCckkBm3aWxE4VCxTjZjjFvOnugJ9Nf
KqHXpmopTtvSXsD2WGKTkzFRUKpx28z1dYqkLJpDQ1VJY4dYOY3pJSH5sBZJ
g1sG1bjT9XfwsjTy/SQ3gQ1iVQyXNFR0mJoWaDqXwjTAOYaHxg3mNZqodKj0
L1Es45JTLdCskUWuKRwB00qkjZV03kbFQ6kUDYHpF6g5B6Nmi3okBHzepSFt
nCOivp20Q475bcoSaPF1KC7qUjBD4AlIlF6WKTyP59zAbdPsm3FQ0IcaqTiD
EsJoxajmjrbPox4nB3WvRitr+ncPSzT7pWIx/5I5D0sMRzV14RRXLG+MtM3o
qAh9VptXumJFFA7F6aTeOEwKhe6wVvDrB649uI4oFGatYm9ZP5bm+dZlRGFU
mDmr5XurNzlU8jRM0SjlxaItuaJzKky4wag9oDGFgjIuDepCq+QcW6W80po7
p3YlgM9a+Nmhc/3skN6U+yO7XjattA7chzOVeslgRCOzy77OBsxWX+1Bf9PN
13bbcbFxKMvLU37W34yzpxflaatw862VmReOh+f23GXNulUps0ztIArO3JDc
qNmsWsJmkd8V5c02K2vteataPtRwsKQndAqFSZmrVJudtjWquVljNjtpRrPv
ref7rmgZ2UmrQJMlbv3QhZ+t/L1nucvD8RiKW46HISqtPA1LHEpT2u0ZByYK
+W4pPy1XW/mgWixG1Xx3WOEKh4mfV+pPx/jseXXiB7taZzt4bSrjeq3ir9pj
683RR403qRCEr4ZTb56KDutrzWdluylz2m5+6jZ8dfR0fGrP6gtZ7m/V/no/
MN/qpX7F7Ui9+ZNZLG9fRxqQSX4fdMeydXLXi7nt5l2VmxUrllG02/WXnu6+
w/9Vmd1sNiq28x61htF+OBpqM1ZrFArjjr1wVJMtjr1hbes4r8/L/cuOe62+
mc622KocGq/lgjBst8JlL/Msv26sl7L7MnbXVsmY9JfbaYE9r9iYzZvOqbNt
NYav8sq1La7HXvV5ebTd9pdh9tX3/YnQapWbYlE+jY922YVzrt+G/mLtr4VJ
yWzXhn5pOp/vM1HkzmbVGVd5HegiU4PMsK8+j3oHQ1fGc9fZzfqiIzRKldWo
2WLMcart5e65a0aFUfm9URr7+eXSq2VEhStGr75RkzOOOikNmr2icigVRWMf
DnulcqnaV9pZrSLUlZ5tTV5cvczy7oIZx6Ijd6tGpzZi3Fz02Yt01IuLcv1l
8LLpBK1XpSbNTCczr5WVmmIJpaXXHPjy4j1TqfvDY8Ram83s2egZq918xG37
8+OsOh4dvGO7sunUF9K6kdn0p8uhMg9n6lTp+MI+a7wsx+Xn1riv78OZpZ36
I18dBmVDnnNvL2PZfNHsN2upFRwtNCo9X+o1laC3CWTNGM2V0Hs9eU+6Lc+m
ltVeBYP3xcB+9cf9jq4MHG6cb1nFzmBs1JqGPQkK7afBMnuY9apKwVMP3mR9
Gi9qzrOiukVn2DJXjrdumUZxLVQnhe2RTbmxZI03z6YfFk7TyUE4NDqrrjha
LfrtaW12eGo+S9P5pjtwItOtmNvTQW9Z3c3sNMvUtPJu1c5wL6vukFXmouuU
RKUnmf2Rl+/mp7XV2Cw1d/Wl1JHm1V1bMcb+Pr9YDtvLVUeQG8uiWD/te8zn
ALW1en9q7sLJAthe7dVaot5fLarN963VEhur+aBZ9TPvY33zvjrOd+zN7z+9
DJfTbm9eK9ZDbtd8K9Ttd3VtzZRV7cXQh2F1K2Xzi/4grHlLV+m0lcF0LLXz
pt4d9Z7qjfrhdTM4SlElehaVLrfYNOalmh74p0mv1naD06CiRtpgNDkUgkOm
U212V/3+SZx79rS0KR+n2+KhL3Z3XsWfv/nFjM7VCotmScibr5lpMxPZ886w
f9pPgmzdld70RqfVb4ut1bBTFQW/YGVe1J248mp5I1v2XKMvsYBbOk/G6X27
imqr1ejF3EbFVWO83u9a1fm7PCxvFt6r6lhauz4uKLWR3DeN7Lo7n/fmlcZq
s7eOXKdZDutKbVY7VbargdHV9OrG0aeZ1uu6Jff33kvRs4tisFlNMsd1ZnHs
bvMrSezI3rxQWDrPB66gdPSo2hEri/lps8rvW0vBD9yNNJg7q+FBGrGTpBb6
mUHDHHiH7pNtai/+4Fhxps+Dw97x3rjn9nav7LaRZ7Qn0qAi9wVZfg/3L6dq
f553x+qmLgdGR3kq+Ifmc+PQGJnzxXS8fuuHYi+vzFqcUD40j/ljpsk8ryq5
/qFddUJ7PzBqY3eqbQ6r/uGVlYRVQ3D3T63KND9Tm26336sdpk4kr6bcytzr
40G2phwWXnegLnaa8Po8GM82+96mqIEBExqjY+Qtzcqk8ypulXYzqhmT7NoR
dzXRzD5xzYnU6q6tWmUyatYPrWm7U7bN6YHNKs+vVUF/bQ1bSkeZ9mft6Vun
WeuUDKcmVlvbpbJwIqH/ymmAnNa6nym9tHr1vazNd/XmaPb0UipPXsJht/u0
mTvvxmr0+q70DmNb2xWab8u9/bqwTtk+qGluPhtWhtqJgRzbuzrLTkclOf82
yK8L0+eeddSmkVmtDJ/yxUHjacPeupvXZZB5bbWY+aq9dZY9TtkU2Y4JM8lc
ZuTt0beEXrhWahX3fdWpjacH+Gww7ZRKmf3b0Cr6vVXdzs6m/c1+NDNaA8fj
JDXYGEalXi4WjuPsQSxntnp592TWWqdxNjCdYCtLwlvnpC2r7zooVdaN8sPs
4DRcjyzx6FW4llUYDvwoaJbNkPmO1swPrOgolAdvvc6ycgoW42J4KG/Ftd5+
extqjfpumc2y40CVNtvWdNfk3oT3tTduRoVq3akuhqylKHK4Cvan5/27xYRe
3nsWRpnFRhxErXX+vXwyWso4X1uL81pJaikLTtTV48rwX8rGxhmzfr/byFSD
8j67EYeq8yxFxV21djxUmgehLB2jyftcMJb9QDws3o7G0jk+cW/u+4u1cvub
0Tbb1Hc9RddfGs8HX6g9rbT88n1zeq5ugoVSzIy7UbaS7zyB+lcnvYow2Ctq
r8cthkc3u11vD7I1bQ72ztxeHCveq/hS6+5HendTB7s6zkRVpxsKUjZbbR5f
3zfyayhUduv66N3kjEItsNV99+SsM+3xa6O/6ti7hR+FQqb3qh6dnjmfN7ut
/nhfa47mPdF6fdlaT6+RKrz1nP3O5nY7vz/a76wXUdDX7nPlWHkqVrPLRk9o
uq6wthq6PF5WTH1X7auF+ZOhbcuSuXlRRkLZtleTI9fsaDW2PLw2TX/Un1mD
/nNn/DQQFpOe3p28e7tOtJr3opdhUFMW7zXzNO/12XPpOXp/Dd1t1+9yq8Jq
NBvMs1mzzvaaXV4eW+Hz0NuMxPXAe10U7GW7fag3xhll/eI1nXlpLe7qymxQ
CIyXrJBvcFVDHtU25cLz2tHGRmXcWe+r4qg2Vnanp/Jq5+YzfXcni518aK7n
3efGomIfVhu3mffFVmuyKnLuxss0zWHjmQXtTvVwcEeZ3WL0PO69DLzdNPKn
5X7F7qoOwFBcL/tztnnJLNfL1Xq080VfrXHHzdJsvDcdI5wUFy/iXHxqVyat
XtHpFVlGze/V9ej4vp7BymFWGXoZ1t91VkE1K3ebc1ZaHrmK3ppXClW3MVFm
wat/CPNty35S/deO+Zw3AnmzkxesPWyv+mtxXK2t+q3duLTU1eazJR3lQ4vb
PDuWKTFxnO9k93LoD6yGPR6J3tAtAeqNt3p1Wt9li06hq+8jYdFqzKTnTLcj
T7rLo1+TfW7e6Svh09Q+KIVR8LJ3y1p9M1A7A8EcFloDU+90FW0kvYfj6sar
atJ4/+rMq0/lSsnfCVGvtuMyFTCy7RIL5po2qgvmxHzrDUvBYt5bTOon/blV
F10l4xQX2bCe6QQVdRdVp0+FdmU0NZ820wHX14uR/JrfCZ1a6AzAgeu/bXb2
cJHtrKNqK3wKuqPX5/3bXh9q1chT8z11W3S1jNPQSv7zXuxxb4cnWXsuqz1r
M9zOBsNKsWS0g9qq8OQ3glax8a7p0tY9ydrJqgqG4XSqo2GhWRWLw7nY7DKN
y3S2T3t3dRx13qLDVJiWa+vCKbN2mp45GpazUqH7pLQG7X1lrCxeVpO50+yc
SgVHfZ8NlaNnTrnKfDZ1a80npz173SqFrLR/XT+bRW0/281m5lu/abWjVX85
fov2vfmLfWw6y5dJsffSP6488+WlzPmTV3Mw2SsvUskNT+IKgFlJji12+qNI
HW9LS6nnHPt59myPnUXYcKRCZCvNY5mpp9Fx1K5zC7ux7M2s7LCRWfZaxyEr
Zbf19nRXFMqm0e278vuxISrlclY5ycyb9ea2swuLx6G6P5bcQFe5fXBSxg25
XNYyB3u+702XDjNHjfIpeu9bz61t4dlYF3eWn4mKwPSvi15v5tiqXngtPoGf
MClyB202ztYde1xujebLuWFM882BtGkGlXfL2A3t6WIT6uZ2LsrSoNY3pqzk
jOtBs20Z1dKk+1LgVt3DsuG+evXwUH2VxfX3Td/hfzDvbzuAh/9t47/dDB4V
gq246Vejii118uClohYVd2TMoBp0D4j04Y5Whe4EMoSccx3M+eYMzGp7eea7
p/AAt39wDs/ICb9vDi954Q/P4d2C+hdO4qVwdf4Tf/zXncZTqABu0K2bGnWy
YLcsdathg4Z4f4W4kxHb+mhWA5sQqTlXpJI78BHWNhkm0oxvzPNJ8dUoIt30
5VL9mfLE2JNL9QSHqsoAm/ONaTxsh6HMnEQJe2ZTOZpaqyS68lRX8CACu7ll
9OYULOk0x0sy6VpOB8tQl2f/utN4ejGnlzAnXqDKtybiHb14fW8+J5ZzcilX
ocblfCEnlnLl0tcLCEquWMqVCjm1cg+O75/G+1tD8r/BNF4iXb89j4ed+nHV
h+5Lc03MTRs0D6adJ0YMuh1TTt8mK2FdFsdBLbrc1MX0uiEml4dhcw/d5alT
05JM3ULpsVWPOrFEukFKo9Kyy7BHxKOxVaxnC9j0gPcDiUmPSLohD0f1qP6H
nUl0K49LXSMuVZVcmjPRqWdFoqYrJt80I9rU56oZNDFF7S+MZlqw54luPDKp
i9emyau4AYulCjlYCvXoqjwb61twXoma8yxqaRWoa9+lBkdMcNMFpW7q7ALd
ZYtFFGrHj/vwVIUuz6MKDU740PRvUjVxb2wSzknKiE8lbu82iYh0aTiWE0TU
Bwrd1qnT9Zzm7ZVpdtz769ClcTQ6iCtQ9ciQUaPAdgKZSSvGJ9VmbtoFdNQl
LjW8CnRllxWXPXRcx6IaP16zRFUlptz0bceXyQl0MzHeWSvTUjRXINGAnxyP
dohJHR1YwkpV3Fl8FZmBmlWmC5YsqvTjJJKKDIxFnbh1iW4QtG/n8QS62Fh2
6NIsndosLBq3tpLrk1nc2kiXTxs0JqekgMfr66imqFGJBcu0BnVWxVfJxi2z
1Cgm0RihSK38V+A97KhQqTYs0eCQSX6FRlV2ifpT4xEjkW6zxhmz2/IhNijQ
NYc4e0kzAxI1PGF/mEDFIeJ5sDYCNcEbxo28Y7MF1Y1ga4EuQ9XJ+9Go+8ST
k9I7Xr9HN1ym2wUkh7qcTZQOnYQC7+si2RFlNC821dF1mvQApGFlOmVadRrc
Ar6yLWpW1mm8hLpkJKppGTTZgjVRlbokHSzHXnd3qeeY2vFBWLDlhW6gBHUh
UrcTdnO6SAKdOgBE4+a+N5OKl6py7rilyTeJhEijO8AkuvlYcahVjto901Nh
FrGlSL2/wHsq6ca4QdmirhFGpff41kmFDI2XUpUG3cCHdVkaINRogBNwa1GV
2iDMmCTjODUhoH8hpF7H0VCdupfiTn0L5Q5H9OmiPoX8muQiPboaNr7i8Vp9
jMfPBKy9qTS9prLknmacqqXbr/E+dRWroSY1kai3qIunGU2CH8QEyG0ThwCS
QZMAk1vkSbOzPr8Z86A5LiAxNllSqdihWWhgNuxaEGh8JR54kxAAiyqF17NT
XwUOw4hIERyo0FBzmvFVozSZ7NJgp6ck12mnjRSj3kTw1HC0mO4yRCFlyXEc
Qix2ARLX2dRmpNg3XAevxLOL2BRFd7wJdnLXpkxzpHE1XaZ74rETOvU6O0/6
oWWhO5uxWEtXp3vEZgoVjLEPxiDMqzc3pms0UwShh2Ng03B857dA7RcYqFCf
B2gAm+52xate9ZuysUZdhnhA6ozXabrGJDUFdtOlIUm88p9al7CNkm5nvxpo
miGXaW4WG+moLu7F987SCCUOoKpkQ7Xk17Qr7VGFXqeeM5t6TZy4xyhuqqBr
MgXyvk3qY3apXyTdjIj1bAe3AxNg0IC3RZPbdtyoTd3qIult7GhkN1eex40s
Rnz1I0OGxDZKi1qodfzXoF46kXqALLptMd1JKRBRsPmVLoOX6LZshSYwsRuJ
xlNNKrdr1NYmmDedlAL52rGz79IUB16mS7PxBl21aJBXgFV88uJlqsGnuw3i
Hl9GUxAa/YoKhybe0f3XUY14VtI4bqg3ndMYqJJeVUg5OKSXsEmC7k1w6Epj
m4bPBWqJNumy6muHDXkd8IxBdgQANoRkYselHojYPUAjQtNN2DWVsnEejXOr
RvIfUgBQPZqaE+nuVZucMYFGj3S6Ll1Xbm7SFWjWUaCbm3FClR5w6b5q+OtS
ewp4Kcl/B4BuN1fT00E6vogNlGTXUHjJs/LoxneNpkNt6hsW6T/vACFdekJG
JN+A0UwUtvbSjI1GUon/FRadWl5kUh3URxtr1Kt7QN0h/39jb7KsupZlifb5
imPRes/IDFQXzywbIBBClEICJNKioRqBJAoBAsLi31NrLHkcuJ2XZm7u9x7f
hw1iFXOOOQoBR6IKgYQI05aICphhH0sETrgEm3szYH4YtAqIGjI4JQKKYRmO
4zLiOwJKnQFvVRRbXdb3sgmhQ1BBvxBwsvnQbAdyK3igqR083Q4Rog++9ju1
4G0qECKSpE78KnYW6L8qSIQJRCYyROzyr1lRQEntDPzg0fJKakviUSkDFS/I
Q8BMCo/wh4SqoKIIweQjTg2UzSmSTyRAUkKuDPQpMWSEKv9zWMVQJYko+RRI
cJtnSJk6LA52EYWKCqkA4aOA8Pf3kqL2sVjqARhpKqSVASjOZCPE0D+gxJJh
mPotNpCDNk2C+KOjAPYhkBPAPyaFNCxgCbmH/r/qj5tsszKb25lFgcHAxj6i
ZR4HM2PYJSjgCAo4Qpsj6Js5zcAvOUQRTg1om6+PMMME8m3K1LAZVLkEdicy
mpd/XJEqeqiYMuFwOEhQVTVHtIDLhSqIJGRHfPtrKCC/srBm9/HzsdJ+xhgC
Ek5pJZEK+NPNc/7ecQHEpcQxJIACB4IiFW64VAoY4whtjgUWCztkfuQ9AoIF
EhxNDFYvlZfEsM8ntzO8cgUU0tS3+1v9S34ST554lKjkY5IDDVJhlVIhQceX
QOGNsQy+ReMRqrgAbW/zSAlfnAWDLWkNmyJklRCaI7wkIu6nPOCg3yAMSFyv
1Gs/ClvjahX4EPcviieHdxJ8e9VDZUdaTkivBUikEkg7FKiCQ8QUxLDwECD7
Cb/bAag9m/M84dpTvdnmElSp1AS62SYKiGghFW/w5Dn/ffMSyNAMoi0gESHH
Pnx5RPRHEcAzDkdfQrmqX987D5UmLQkYFPYicoeIR4MPk5EEPVRADnmqXoi/
I01iKJ9FfGWgUfpgLQswGmBAO+ZQq/vwT+GgH/i75qEdStB9E38Blbw+Ndrw
YdXh4/oOgGkQ/m70o3xm0Rc3NwIDWKN5qiLT2mCTgBHsXJItgI0so8MVk59r
wkcpQgobnny6BGUwce1RyB4XERxBFLBw2SCK998sGhWYQ7NWm1fgoIFhsGVE
6Ouo2p/HZ2wFbOzvFQn/HYmqGmDO3eYeMGQN+DhFfUQwSUASfuJcqOyHh78+
WuAQti8yzRiBYwvRn0NFQJxfgD/8/e0cxAAQ/cYwrg7A/COBEsiI8IGSklAd
n5wD5Hv/WrQyDGUidBDkVhIgboEzAnFx4lFRQG7BQLKlwHrm7xWZkE9EfBZ8
sqEEHHTNIcCC308EBrgiBaDFPBRc3z2sj4uJRfNO5BwxXBIgoPUR4UJjH0Sx
bYHZ6Id07sPohzCkYTpAPPES5EFBbetDscPgACGRGgp203d1gYKQgb4iUdoF
07wai26OmPggAqh5JkSIDvOXb7FBALBOgfqRx84lAFoMsQGLzYKnTd4MYLd/
eMqEIKY3n0iCBibErmGBoSUgcXIQqwRQAZGsieiH/ssh/CRE7cohhYBoz2Ko
WZB7QCxm4PXgU0ox81OU+jCZEvGlK1ifMrxXAiwbkdrecSg5gKoRkxHm546T
sA5Z/LcP3WwEFizROQACFaLWbT1GCtY3f5eBsIRFsECCdR7glAjQWDF4+ATB
QykuIwviu4el65OHMEAG0ijhjOWgRST2HCx0nhBUJBhZfFcXAkyOCNbBwxhe
RnSMQhYMC6AyRLSLCEN9ERon5rcRE8FsDqmqCuZiInYBh8QnWWrdlGJaL8k/
AhsGkSD8vy6LEE7/PjVKR2fRlLIqLNsI/iaBG/11x8k43yI00UQiBTGJCtgt
gFEXk7T2/7SykqMf6bIE6QLRALCQmsOCimQacORwYzFgIbovtGnNL4qF3yuS
Q6nMElhMgh0Pj00nxm3vKUC3wKA3lOhLfXvGAZ+kZk8BJBY+NHs0aTJA8U+7
oQQlh5D8gA8MpHQ+amBikA9NY4jTWABeQZVsMWR7IXRf3+4eIqBC6kPRfOnE
ro76s2B7ymjoSEYcJa/TSJZv3jbOrhBVegg/Fx8CJBVovAqJi4L8qwj7gjhB
JD8HNQNDE+JtIWKdQB9CoA+eXC4x9aSj9h9AMr8bcB8sfJFvxbdkBBC2ASAy
3WL4ZonzmgjnlF+FDKlYErIpiLYBaGpzNcT4mDJeQcRGIKMB1DwydInfZaEM
qz6CuAIGV1BIK3CxTACW0siFCBUvRSf+/naoyBT4AFIfKBaPiMOap8U5ixaS
QNBIAfrG6zgKn8IFI4DnmgBsk8HpTYS1uCZiyN1ZpLV83zLNw2zepI8CJoRW
sPlFEq6nGCLYBB49MYpqFnXdN2pEQoeAbZKfVGGskJC3RySOQJwIXCnBKwS2
OFHwk7PHAovjoLuWoUYTAZ1RvTqpVHlYnsGPRqYWft95a0yrVabWZgp0mBSo
DzAjiKFYIP0gcBgRu/jvZw/bcLAQ95cIDZ4En8cEUIaAMWyCAJxmkRC7va8t
Q7yTUIHQCI4QwRckO45WZZDXSjB6IyFa+Ozfo9cAuBDNo0uQc0UnIyJw8iho
jVBJ6iBqszj4CdaQqb8DNSRC5ZNQFRDfDgIIrgL7qggmqlL0o4yinlAyJhoC
sCMFAjACmMM2SAYI3ByPIgyqyFH59eg4QAe8/6/OJYH6C5emgP1CMy5UCtRj
5pJIP39dgMelLLeOezLsUTh8R8RdCNe6jHtfpuXr16PjoNgkRxMGYUS1jil3
wrb9JuklYQ7SbCsJEtlv3IZYM2BkQzYIylcRULCPIkGWWo+5UG7vqRiOG39X
HRoxYvCBylxAlogAqIFM97DmRcC2DLZwrPwcViGSPIm7B4peFkYDHJ4eubbg
5BVApKpCBkx9rP5+79itEYJNaAKVAnMQMiaA5wJxeIQjjK+2yjT5H3kstBKD
fsaP2vgaEvQHW8YYHosRcI8AqW7814Yl6wQ1T4LRGMu3uhpiz4SsxQA9dUxT
EON/OpNGGCpFTGuPJdPAn7BF3RW08AI0eHLUqiK/QScJ3BgKnvg4HHxMEHhc
DWT/wk5LAaBKfbK+v7gAtz+Hm0WFhElGIiiJfgWSQNBdHO8BfBjJsv/66yGi
q8gwCMBLAG1hgps6BHYUwwmRh/FBc9r70PP/vWGh1SdeSxJ8VeAyJknteEiB
2EwAbCVDhk3Ez98TMaQLRjBkVHGtB/CCkZMW6idWNUhzbVZUCCM8+VsJGUBA
CyqSwreYVQw9Ie0FFAzCaJaUDwX7N7xPvVATzDs4iN45ZNOxKLcEeBSyUF75
OK6j5KePoz2viqqSTGRwTHFwZ4uwkXlAPRxsR4itAMCB71WXYByj4lnFGAoo
0OgKsEoh2UpAhputRHxtgh/MisAUAuT9apuwJIqtPYqEAlimEbi4bVn1n7aq
NLiY+icKeIcS3GmJ1B9+KDFsjBSwbBQECn0PF2KcRSG+UFL2c2SV0hRfDhPk
hG2zSUkFpaIh+rVhUgBoE2dPhKBGUOwT42Ao3hPEHhKDYIksXYn7MYlgEW1E
CjNghs39QhoEH9MckVS5ftDa/BEcCYLA7yfPwNkzwCCvWZkCdOZk/gjMisyq
4DnFYGDRLCpCMvpOPOPJ10EituR/eSJIrRUXj8tRRhCcgm0bY8T2DXkl8DoJ
YCqqwhiXfEHwFBYhPmTgF5Ag2rRpVGX4mPx989Q5gnJFwhYoYzEHYTBlY9TW
PpJ8g7jrw+9BKqy7iAoXcwcyj0bTygKaC3D9SdhERPvq49W+Y7t8lDGYxcQ4
pgRYyhJPUlxqzV5j4LDj4x4k+bq/MX0yeCYq+tMEsDaBvwCZ8lhpzcnMY0LE
IkHuW65PwFgWwBqoEQzMcRJMMwVAKD6qKR7fOwNvo+8b1sc+lUB1EAGSk4lz
3AbwqnLbVhB0OiH/6vM/Zn8CQCQVnmg045dYYsGzQAjaFU7GWPCkI5Y6wg/n
hDShuJcTuEgrGJoz1K5LJS2SSKfPyOZSsGK/238paE8DGXG4Ib7chBqfAXQl
Vr9BGz+uYlDy3YA3PxzitAmgpQ/wDaow2SGyWHo/4tPRts7H/fsDsEPMLMBH
IFHbhM/mmhDASeBRIYtY0gzOkB8DLAjyQxgPRfAup4YLEfZL84cMRLAqDH14
rOpvwC3GcaTQJMMQKAcoECLKEgYmC8QVRSVbPgG4EX23/wwuJqZdIaSYBxtK
BPBFrNM4jMnovzJkt36Hfoe4xYi7XIAkN+qOKoMbg+qIRWUoY1Ci4vz/hnnJ
eJpmL2N+HcC3Swa6y+B04nDFcPgtCj06fg8rCjswfIv3kjRjakiKXps8TMDs
CswK49+8dDIYBVBAaBKAYXlolckcUMIyi8i3L0ktIcSPfnoZGbrlCDevCqaH
CIMwkqkAB0ZGbHXsEUaiAhxq/nYTmDDyGDrzMLgkcXAUI1Ja2JMcvIiIlDDs
U77/uojCjNqssyhLMGQPgBSFuGVihHMSewvg7d+T0AQYILmqgGfGQCdkei+T
QAVy2FKMmkeUH8XWvttAAlagRxPAqWjeZIDRpAjomNhGgFqQYExPmqZv2gbX
eorFKIAlmKDJSMajIxKfemuybeZ284nk3+hpBldYjIIqguGFDIN7Hm2UH7QX
KDU3iZMftz4fbbKCd0hjhFXYtHGYpXLgBkg0PRj2KM3D/Lao8GGkGwOjIxgR
qDLEkwLcgwgrP0I4pwzSWvMAv23XGBxlhBeHU5HaYTcnRoC7TIIregwPnQC5
skz4G03ptywFHoY4CU5UclEmMB2jxqBoISOQJHkQeP7WdVDgh+AmJwgnb9o3
Gc6tEfW+xypl4QoU4AW5r3M+BE4iwrNPpQN6HD4qzFtl0NLItJE6MILC931B
JygXZfjixbjgQuw7Ad4BpH3GvcDhHcrcP8lCAiAC4pAIspmINp/EyycwOlHh
zwJKACUmJ9yPE3GEP292qAxf9eYbJxg7sqZ9VMsBCnuVbd8hCTz4vqBhC64A
jErgxU9rLcJ0giUrh0ovQCvEomKJvomR1OwYCACP0GyOMlGRzqoCylBxRapA
RSLhpyhlsU9FcA8Y9ErU8JeFTTwLrxwJFSmHep7Mufyfa6J5OAFGOQymXQp8
lBRAu6RSilAbU9//BPYr3/YcqBl8WELEyCONKEcF3AkRHIwQZvcxIOjw1/wr
wRkewpOieeAxHOo5+BNFwA0Yuq5wvyggQsi/I2wWCAkD800BaB75eRk21gkq
XtiyqGDoxb+ck+ZTh+DYqDBobt6tCFslhjqb4PpgYCIfAEkgsOH3/J0lz5xU
gCDm+7jWyR4HRsqiB2k+SwynmIg6vH/zLtjWvkRN2gDtANm5IgpySgYIcLom
OO1JlPR3Ur2KySnfMlfbuQaLHwPpjsaBktpMgplv9DOHlcT2uFAxc49hw02p
cSyoJqSQw9NggZbL0U89T6yIENmq0uANtp0IN2dXgl4sRLQUj7JBxmf8Pi4E
mTxtchmhwOCpgSkocyzABxn5CjzqeYnay4Y/q04GZ5u6WCqw5iETZEB2xK4a
cCIPo0AJlj3f038RRzpNK2m2JPHNARhLLMbAAFH8NmhBQlNMHt0vPU8O22hx
n+K9SHMJgKVQyFRA0i8H0JURfkCn5pjiAMgriG/1YTcsAzyhzYiI46Jl40iw
kvzG50GD5JW28GDRRITIUiavCd/zAF5L1LZMlX7qeVLmoTKRwJGOYL+lYJ4l
YzBNxCWo7ghIwqFO/vrrIqx4acFJ273mDRP0D0ZazV+XYIXDgjlJ2QvfeekC
13ooJ/CyDHBSqThweLQSIp5MgGGfilSqn6ACcH2VuE2ZplTwgJIHYN4tAGSj
ufEBaoPv8b2MWYACk0oRohYWdu0KBlvNR1OxBiRKgAcC/22ExMntb/EhCpAQ
3k6ao6S1eWWB3fEwDosBnf2D4ZZg6q1iWkr58AnfUmfJM1RRqtG8gX8BAn+X
DS41ijWJ6H04tPBkTACHNUJ9h3iBR28isj/e3yGEJwwOagGOoiq4+oQqI4Lu
jth5CVixQmsP8efR+Qg1kcPW5o+lFvA4LkglFiOoXG6/jgC7+O/3DsGQDPNK
EUzmZuGRxh/XhIr6VsDdygutXuq7KKUG1oRMCMSApEGo7fKOkHPG0+IKwB0h
t/8CrSyYKjxAEh8EP+rZRGaamCuFVI7Bko8s073wPYNGolhAaY3Y1CJuMcpk
YOA+HOKcafZmCGHIt1Mhg9I3QsXSbFuij+Da0T/RAYLnI9MzEKRZ3/8x/5JR
fRFqE4ddhupOBgwlgWqoMq29VARCkRL8mDgzGHrGcOxVMMMVQXli6Pyd4vlw
Ew7RD7LMD1WJAxYhgEtMIF8wslgYpRGyUNKGSDWVlQAYOWJ/DuoIRCAVZGkG
53kMS/rmnvLxrAigB65yU58L6LD+UR5EGNmz4D8wyCdg4T9OmE5oA2OABgoM
uJXkZ6RFZw0Rmg6S+4WcD8JgB7gaY2QgonOMcIhJv9cEBwmSCn2EqLSTF/Lm
wcwMoBZhaD4KaKKh8qMdUJHHEKH0jUE+ZIHSq6gQiM+j1Fp6KSDNNguD+4Y6
2fYHSBQT/AEJaEzN8gI4VoP13RImcXd8o0YknQtAFvneAY3y8HqjZTaHEMhI
bYnoKn7L90FN450CQBARKkNC6YFtH4nYAc8tBGmKwT/8I61dBsgTAcPnMW0k
ESzoUESIRwQMAUm5AumWCvLJ9yQ0oiJFpg1YolRkHudDgmKp7dQkJCIIZNn/
XTYgWvCgdqh4sDGithiMFCMQZuS4TScSYSTq/5aFNEeHp9gRjLPb6RXehkKN
2HAkJhgZfwOtAai8Ek7L5sglMl6AXSJGhCRTASAGB2IteU2QJL+HSiqMF5uj
kgGtgsOWkQAfMWFLiuPBd5IwRk9+XVl9sPoDDOYEeOMmtFjCu+VR2gXAQ2KU
K99GhwEokRxyFnlcjiLcXQltA105MY/7V9Kbwrf99d8dhyfsYxgUIbZNRoEh
QzGhAKEiOACMJgmM+XvHCUybQBCAGBZhQECCIf1W60GThwSw2ZszQVV/3Dlp
UlHL25RbMg85Q/yW40TKSwDmpJ7HgPKnoubbwTEDhrYMugKDOjbAbUW/x6Yl
9KmtnvDzvYeA5hjKCcQ1kWABcOAtKNAjsDRVBX64KrQ8f9c8hrAK8KI2eAlY
rgiOohy3UR9E2QHCCQWQv1FiWrZFOKgJnVVAsIrcgiEx12ZLEGYpZrjf8Rgy
JmUiwNsIvngMUPREwbOSgeJiXUmgx3P4FN+1jYweVsboLcQ5QwEQhWvDVBLc
wmSKCvrfj8ElEA8WnrAEA1dwEQRoLVEU8bAsT5D5IePwEb+fPCoicqFATCrC
fDwA4CCh5gkg0ong1x+D4ih+cw+A84QILqLWhAmqbhmWhTJOoWZXCsjPCCAM
ZL79cEFVFZCgQLA7GpEok7OiOb15JPcQ0hHegArA/1sTSixQMZfnIOtQAcMq
UH/wCEiIseQCBPMIAIr972EiwC4f9qAEp1XJSxGGA1BBLmlnczE6OMZvVYR/
d5yK0heSNAXjJBHNF1kJQKpZEN4Y2PH7UgtE/P3rAPFCJBGqanuQqnRn8S1j
P8EdKmNIFwg/GU7tbBRRajH0KQkCMGJ0KDH6dxKEg3s/BsmBj37OeermSfiT
cuuWLqEeJtGAYMTx/3LeFFAGCF9HJeV8ErIQEGwensLNuo1hp85RfjtcmENk
O3Hszw0bIbqDgU96QJ1VISkK6ISFVoawthThg0lCdr8VqdRTO0E6I3ouCTFs
rNDmadHwsATyAcKWx1j/72+HhFZBEgn9jaRi51DKcihWlZaVIQJmZP0fe80Q
iCIVxJFUReg6fdwvMUiDtGRKqK05Dzf57xsWdq48xgrNRRMD6o/gRKwCwiJQ
GIqfECxNMuT6jQIK4KHcPjogZgnWIamIMAtr7h1i2UldYqUfygqtZomDsApc
l8fvQrnS/CFhxYcwRYUyVwZX//vNM7jNKRBKRSIxZnYyDjcZ7TYZrHA453Fc
+N/e32ErpQzklo7CAstlwZpTKeADrDjEjxGx4dcN66NWZMHpjTANJ6xCbBBq
8hugCyAwPqi8/O+qi3FUEkxYap2UqbOqiN1HiMrwmZDBIvMBNX8zHzjMqQmA
TxWdyGMgrSViDolxPO5ZHtNb2oV933ER7nEeRzGPkFGZDpXkVg7AiK1phCy2
epDvo5IHx1VE3BoHC3UWooMARHQC+QqoT2II5SBw/uacSIhwYCBi4nAs82i9
YzxnEaCxihOPp9ke8g8BnsbviVgtLGAHMh7i24w6CXEsCW0iEKlLNPXf9DzQ
OEntB/qBBHxSRryNilCftkLGZEfALOC7ixRB4hUwMJJRZjQvRSDEuD1Xmw0l
0kQWsU0M+j7nE/w5vUNFlPQMCj8ZjKMQF3qMSbFM4d/gJx2TQ7QhUVMKrU08
A6ETA5t7kWsRzhBTSAmRftH3WAdfMdVyklKfJQcUzUANUVPR+Z0K8l4CxRz7
XdP+i4PE4FSkKiEOiY881QIAr1CpYTESIn8gL8DC1DheAKLLIhSHgR6NwbUr
wpVexpNUfo2MKY2T2GrjaKU5XmQxYGwdA5+nWC4d6hFt7/dwgW3/IlFCIW8m
AIJHL+XmgiCDBqVtrqn04DuzTQWoGGKFJBgABdgUIcB5ypcLKO4HWbcs/PDr
iOJYIgVYiO5bBbIR+f+qZ/41xW6Oegalchj90nERkRVTc3bkwUSUuC61wiIf
FDtqPxRAm6D8ZnOykJywsKhmUPnQcRhhckL9rSb/1+7JG+mjaX13+d/uya42
vWfpfl0WoeZn7HB1fhoTZsGn8/Qf7snzurP4/N+6J6e1nv7Lx1j9dU92tlZq
MaPaOISL+dGqmxet58P0vRz2mR35sw/5s77w33927PNzq6o1yxt2mlccj2pz
vDmOlvN+Td9JXeubsf723flrPOzv6Ls5z4eM+dzz289EPyw27GKx1QbDjuUM
nG8r4UHtHfvMhtoIbx5lttafvQEvM93oFcpZZi9V57Fnktf5ojxP3WlnmlwG
vYD3J0aPW8pD/TFNNCW/vc2Dc1s8+8VMiJhuLW+TQ5wyG477sOOj92me1oCB
13FnmFq7wWCtJNtCyHfGts+d41UyOl1f/H0w5wP300/IRzDs+Yh8nPQfP9v5
xw+v8MNrOCePBk5/SFyT530Bv21InZVH5OseHPvTQZreOoN0pA+scDypl9qI
oxbKW8X2sqS3187iI3j52+OyZq3M0N55cO9OjFd1Um6Bu2IWrKt01JGwlbiH
xR+dLnvZ1/mEH4jM+W07fcmarkvm+fS7i+wQn9LMWC6952JwPtilKSZRuL1n
YSediWd5bdyWVu/5rov3dKgV03qn8IdR9qycUDPP6n104g12HbtvzvFu2va1
ZY6n52JrGem+09f9+PwcLW1JZNnLxKzcsnqvD+XYKsYpv4601L9xT+3Zv0QL
lp+PM2k6etXFk/eq7TK26k6pnPqmn36cSD6bgcdq7LgXH+1Smjjn7jEPrsfo
kXtFZZ4uy/dNuGijSplOY92/sj5zWd06o8fYP7xe/aWibIPRYplp+mZTCotg
HV6O6+1TZkz/artWLjTfvT09le+Nu/GZ2Tl8OPfVruhU2iQItoPT9JSpg7U/
6S8X8vbeH1b8+e6nzw9/nc6D87g/m/QunHG878TSHKljTuKPQ0t7HDrx2Zo+
DlPDPTCCqU1X9XSRG4PPcubJ+ezV7Z7YT9eYc+fSFbuf1zEr59sNPzYPkbbY
7sfeoZOf3uXsfN1cjhvrEh/i4DKurvPnfWPfi7W1Yg9ddnEcifftRDvMheuo
tOev09zTR34cPbejaSdkYkUbndaVeOz11+sLq2jpUHdP7mMmHaZ1WQmbqnB1
uxyuhNL72CP59Rgbp+2lnj30uCo73FQ5LfvT8H0cfoTjYDDjptlsuhuMef1e
7W31deRiN9d1Pn8ybNdjRfWgsPtjlaSyUIbjshPLi7zy9dks/uxHp+3NqKvQ
/1TTfemJ6vwdCEHoquxKqSXPU9+ivrmNvMJ1135w59+D66jj1j6bKZVWzSar
5yv09g5Xhvn9VYpmd3nvjj7jbfjS73UvrIXyYD66iZL0n5+pusvGvfnl1VEc
Vp7fnE0tTVL9qNgDfrxdqvbLeL7nxseev6eP+YPfOfX6Zh8cyRdTe5wthHJd
3T5qb7nsbAfH6/UqbPo3feo/+qeI6Z+PTliWk+iaWqXd3zBpokqj60SbH4ul
9iyC5PAZhA9jNJX2+rkT7iQ37/VL53l9+Oddlc4ZwR6Vg6nIB9u5Wz9757Fk
elJtunU245apkar8lI20PIhegpZ0euO15+yYUr2H/nE2CbX4ojq8vR9uzvPH
bPhsttAzUD952jWO9ePg6XKzTTO+4lmHM7g461TKZt+VS2P8+Vyf9udgce56
d0jCk8jrB+u1XQwWpr6fZZuDs079S9Y/XKV3MHAOnigzG4HpRNeXyMqLyemm
bpOMDT/ONKg34/KscHyuv3fGUSid+Fl7m8dJ+Lxl39vw0v7tqeOD5LnxvPMM
TjX7NFTfTXv5JZd9p7Aq/s1lS34xji7afrl5O9NJrSrO2RQXtZxc4vdZlJj1
8qkH+r7z3j/WnlWN2bB+pLO7eVK57kbIujdhcEp0qRsLz9L9FM8rF2l+7V9l
dX+5Sae+IfW3o77V7XDi8r1Qn7fDNh+ez9xqcP7MzgfuvDJ7zMX4TD5Jr74a
p5WoZs3Dqt1V7/IY9KPVU/BGweo17hzkjXXwLUOadi+yzpzd5vuehx+jEkau
xtxVwxSZ/kF+8ikT1GF/5GwCle8/Tq/jqjhYl7Sz3DCz7iYfzbv9bbEuei/h
Ns5T21lw90iaiR92ogmp1fVPG2cVpjPnnRzTJJoG017vZhWC0Enun8VFHOoz
7ZFOPrG4H2iFyR2MV2Kcj00JYMcpa8/liTZ635UrG0m72e3tvA6H9XG8MFZq
x7w69WayDPa6fd3uPt45Gw96Yl0u173hOZXzjWy43UPvOfWe2sk8Xmd3Vn8q
i+osLozCmnsdM85yORN5ie8x9ibfF3NDub6k+2TGC+aKOYzViz9g3cmmv3lt
zOW7O5aDkGGTxfT2WUyWVkcZ6ff3aLFj3I2hrr20Eov362Plr77I7PLRKv7c
e/41H+jy1vAydvXYjV1vWTzeV+YVnKppZy2+nP11sazFvdL3teXtvNCth2+P
zpIbdLP0znNFpNnXyWwolZfjOZk5/nxZbDTT5x/bxaoTbZW5482OH05Sutli
1T3O3cTMOOMUm6t7cbieJnvTl+IVuxjdzPGO092hNeClm+cJ3o0pO7O3xzTL
zO9v1tpbt/Pl49R8Q4dB4KSxcGQmy8t6ZRRDqwqny3zoNLWTXJ9s91EMbea4
3y47ny4TeV5p7taDs3KrH+6M7w9fXDjjP33zvdkUqnSMxtZZ195ZdelLl/HF
kjx5Gi93XKQHaedU5Opdk1OR8239Mk1r9b5i1IHrbM5n+ZbMB0vF5ZJ68HhJ
7109UQ32qofSeJDfwo/rlnnHV06X8GMN/PjiKv1x13kuQqW+los6u4/Nj+Ho
peUG1UDZLri3wu8PuqRMDjrXj8rj7RUOO/1YEZwpP0j8cuzZD6mcjLeHa1cO
xWHI2b31StxeHxtv1RXWp8Tgxnv/bIVbb+9yAzt5lVKH3d7S09IWvXz7mhaG
uHir8YDXh586mPr3rf0erg63YNK9jEeD/uy1da3bRzwp7KCyzyvmPesUSj6w
e85g2xWUerQ+b/Lz/eEnbyu6jY4uH1izQFlzC9/3DeM4r3s3drxZiFsvLUtb
P117nVF631/8zTqMvdD7PK+KpliCGTdvdO0wxoxZGaEcLyX2WjzZB/u5LDbq
Ze+FF3P5MmL+4HcuipEr7kJ13LIpJkT2oD5WiydrrUon1FVnuGK6mqmPgtHB
K7zo4ejrk7hNNvpsLOl8MJt3HKVvauV+zC2d92g/PQhD/2yGkT7evT1JvEl1
/O6P5/K6O7eOxbMQjHpbHk/uTHwIs+79XnYMblLZbiZv92k8Z8yjcn8+wl6U
pmM2KR7ZPHPyoDo7WS3mvMIqe3mW3j7FYD8be+NuqA87j4TbLPbCuWw2Us/i
x+NblZ7kwdE/z5/a/alVgvTik91tbOVOfL+/Vy8hH3QrP7ENP9NmRUeZXT/6
rrtV+Jn95tjJY3aRr6dBL00kSQ9NvvT23tPgzFlZSc1RlyjOxbL1c+40n1qO
ZK4zO/F51Nzf0dM6uqJRD/l8Hz/nb3NgjLJh/2Aen6/YaurmK6cF8cVzrpel
VqqyO93d+NK/dK5hshe6z91h0teu6mW+YwprGrqz3asee3HmfyTnWjqjnZ+N
JM6e5I9hETnL5ThqCkhu5gSdbJU3K2AeHdTuZe4spIrtd5WKu59NznO5T6Ys
0vIRTvhE4JjuxHLct3kvhLFqLLfs7bbbdpjwab0eC0GevF6B94osI1d3Qzb0
+GQ+uzanqDuqZ+zpKk+mLzEod89edRAviRI2b+rVPdqd1F2+1ODFvW92t/wU
7CyZdF/O7Hg7ftRoOuJ2+Wuh3mWb3e0P0SR92FyuTO1eOr0H3knMB52nce/1
mrvosGR2df8gdNnoUJ4XEhMX/G1/1Y35Ujp3Le+eDrmFnWTmi7H4kRWNrF3G
qcq0s9tnoaKcpert3ZnQUnqa8VkN86bfsNWT6zz755VvZ2bfM9VrKTxWSmzF
RbRxt7tJ6PV1tfNijGC8Fy794Jq6jPHxYi4amp/n/Pyos3PxEvuBOWNYbZqO
R1P/87J87fAO7CHnhf7mpfY67GRjz8ryM5uk45Brqs/bx8i6oZnfztp9698C
ZbiKinU2PEisOM41J2Z3+f0UHa2oH1c7tcOI6nDQtaN75t3m3EXkvFsl5/pH
2Y9ryRxo3Evfbl/VYLSq1z0+ZjRLb/qmzyo8BIm2npid56Z8zuVSPzrbNBK0
lXxJveetkrw4D/y0qLWDIKTL/LUu48PYvQ0HepxH3b3fdxP7dBlynWKrGauP
Nl18GN4oquhijBT/tTH6iadaon9UP8OVptXvs3Ipg7z0N7a0e5rRwOZfSS6t
Vp11psV705uodT20ZXuoRffqIVpH56nK3Xd3tE+vu26se72aUQ7jaehzWpIc
y9W8Nx/OlMTqZFzvUxSz+VyxmxvhLaQm3y2rWc2YgtFUjqIhRSdntxJ9Reiu
++feYJtZQ6tOk+be39yHeefOGY6fTyYLcbRdzdWBvOxOtvd6Mz2Y23e9GUyE
st+rbrG1mFn5dZ4MmIuXP69vmc92ijHPO++mglmqqfbpJtNKO/mmq2zzjFc3
t+pS9969yv14Q947DOz0kUWFNqyei/6rNwwDaxVtZ807MJfz25LfzvWrOBcc
dbW4heJ5fa8Lv3uS2DJRn5Zmbk+7rHaS7qQ5OD5W03o8TspEPg4fr47bFHfS
fLmTt2Xm5c0N7HGsEBrvhf7o7arPS37UajAe75XqeBpse1fWbZa7qgSTZnnO
5/2y052uHyGzGwi303ZTxamoHNVYkHkm/Ywk27w45SB7CdfsUuiKxl6Yo9Xr
i7sgHBt3ZslPb51xvvzYsWpdS78vvnTnNK1OjC0r+5OxqpT347Yqb8ah5J+6
1dfv15rV7szr48raSi31ycLvNJ07fx/Pz8LNF9h+7fjntzyfG3Iwak4Gxamf
mZtMP6d1cw0Mxd5pZBvJitEFNTjkvUqxnp3X8rV2Rb4pyrNk4haL8yDs6vyS
UX3zFS79/WvFzpVicZq8Z8Ow1G2Lmean5WIfscPe2To9Oq/evqv3phlbClWU
TG/lcS9c2bj72uuvUHtLfXHcz3t23OxSKV1Z2fS2ZfVtsq/MaVw5btAxL3t+
ar7NInoE28i66Ft1k6WsdzU3Tr6OKl/uX8+9sy9rEjNMj9djdzzfharq9Yef
p5ycmrYvK/qP3pIV34uADdy3417EsDmO7ONUPAbPl7a32Q0zkvXB56C+auN1
CwayOpfil1sYXaXzHo7j5OFJ9/maP33y3ZYL9cOEGfbvRW8wfnZD79q9n6+P
9WwYcS/1aj62FpsowzRKg/LTLTrPwd2+bwqn0hJ1F61VP86PC+sR8FdjE/br
ibW5c2zFT/beWy4K+aTEk3okcsemkNsNeU7t3BbvazkIB5cs3HRPt4H5UYxY
VJ5rNpgrpidI24NicK/PaFivfe2suLzTXUjSTIqf48Fx8Ox4x1cYaLyxe6/v
H2PTY1WnCAt7erMW5S3kZzP3rdl++ZRmRVcp3p51Eop1uvYu9tPMzMepc3KV
TFub9vSuLxfZzNvItXBqWqpx6JZvb96/z/z6Znrv970/8WPHnnp7JhoVXfs2
7SlZT+tsnsx2NWGM0fHqvZi8TNfcy42PjFUWqcrYQr7vHRaMHryDsXky7kX+
eCz5wdMN5dmt3piDjqQx50fpXBMjNqK84kZDztD06UYstG29fpqmomvXo5nJ
4eU5GAnr5ZFRhUUq1auuWFzsVyduqll9eN0v9GLJNRfH1Y3Z2bY8TPdeMBK0
2ci0unVuBLVtjfuneFdIYmQ69tPm3E/2uOedZLqNk+lsZ2xG6ai+x1IRvyVZ
rdarOzffHmLmuLgHYi1Zbp8Z7br742gasVm1iQOtYheC1KkWRzsXMl/n0m7s
Z7V9j8vVeKVPQz2PynW3vkuCHQqFq5rZzFLDz/jl1NM1O9jO1ptj9uiEh0jp
F9EtOh7L8HoWQl16ni/Hfu1e0yB+WxuP3xZeJQ52t9twEvI7puqf7JeaFfxg
8hqMOmZ+MVS+uzocPtpF7Mb2aq99opHSdPZbPu0r8uJxOCuDnvoKZfv+sdXI
borO0ypYz4Uw9Q4dSbQnTVVw4J+Be55kV4GJZT9O6503s5cFb5iXnX3RU0NS
HzkT3Nd97fgMlOOyOez3x1j7dPTFw+KTU3GTtYk9FbLQ9p9sPFi4I6PQemZY
yPdLmub+brwUh5NztpCuzc9cc86P5FJ1mY4ucKpzFyb+1Uo/V19/9c76S02H
Uf2JrOFkbb2v86ZFm3WvxlrZr5ujcCecF8wg3Al106IVneg8LGrLninzuaCb
2UPqMXqxGO+Sm93bhNL1Pt6/5qYqrYPgzuykVTV+5+qm93guL7mbrYedkLlb
x+pwHr4XEzniewczDuYWJ88W94tf10z4kR5+NGOf12z/LO/99NnsxmSjnuUx
IzQFTOdeV5eb01e3F04xl2Vx2fHz9HWQ2X12dFX2FWZNbeCpg00ljYttU+L0
67jaJ/7ysJ5eanPS4UbicXQp/emyjIfr2Fo+Xb9IdUVfT3v90UH1hLepyTmf
W6OyOi4+tvQ4K2/nUUfz+VkUik4vs45LYcqMc/HNm9J6WT70fZ+pZ8V9u+Gl
zJFDSzTiQ39zfbO8EuZTv2xupuzV3fBNpVh1wpvufNR9OWyK2WcdpoWZp/Jb
fNfGNI6bTX9+xkp6vzsqdzzKG0XYT+YB728FflFNro7FdtTnOIzO2/izLY7v
SW7tZC7d932GVZtN4G7dkThcDjaPVM3MWuOz9DDyjfs0XGTz/eC1X8060SdZ
3z7R5LFJgsK9eovzbGZyV58/90/LrLxdZa62+lyxWe5O4XW+f/cW9jFTotFS
VbXDturY1sHZerbuGgvncxQ80bLtS1NPOe7TuO7L5fUyaLbQ5aDuzQ93s4qm
fhaj5VLrOrNUWzb3wkxU70J0bqre7fh+iLePceUkyfIw9zh+LQ30azZw2Gdf
aQ7ismkf5q8qmQ3fus8z3vgVTO6di/Pg+wmz2q7v8a4/qPPpomdPxOlesjZu
rEn3ZxGIqnjgxvHwNgsHEjfTJ7fDZHnZb7uvy7TzGs9rhU/1y7Wai59lmq2S
TGDOQW/nKfpMfkwWo3cePdyeWmpP4zYRZ+dT85sf+vPg3OS129lmm0J19hOp
rtOuc//0VE6dTEZzdbszk40XDAIv50V/L6W56BkzbyFOm9tld3TH7Obem787
+mfjz/ZB7j4/i+1wYN44xbfuhbcpzU9kTPnwsusbju6LkyV/v1ubfv++/5Rv
xXAnpyvv7Dozs04r6yIEUs4ddzXfP+7UQCwfzGbDKc46jQ+ma3Kpbh7W7MpU
FqtbFD20S2X4cW2FDtNZ+dJys7X4vc9M33aWrmrnvtXLUfli1NCMku5m7fRe
u6T/WsjW7tlXhe7RfFfDpROvnns97ziufSmZ7fWiuaGzyru75LU88W/zyI+X
l0teuMU5v8y1opu5vK+/p/3nVrZDzhTcSMjXj0tn4h4eqnHLBsvNcrKd9gZz
Zu5veVdp2tFSTQfCam59Bs3z2udCT62To3R6Da1uomrvw2rTfXc2e/OsLD+e
q6y3581nMnqc9CTdOW4v55pH6U3tdarr3CdO8lmytLLQu2n7k2tb63W029TT
zt1+3J7h3uo2C7apKzZ5OVutk+HmWfO6LvZej7UZXg3bLHPP+Ahdr7jfXI7v
GczwPNXnrN/Zp59bv/RTVg+Kpmw4KPPwWDHd8Wlw8fWzYAxtZy2nS6+s/9f/
+v8Pk+mHp/Jc53GUFnF5rzr/+f+VyGuJo//1b4mfV/G//RfJkvHLU/UnOd/+
rB9V9cc4P6o8fv+PPyu/PFd/pn5x8Uv/ROJJ5ll4aGqmP/bdPB/K6o9fRn+0
8y1+/xmcyzLOc7zKIc4vySP/Uz3SNK5IRA39yVv8zOK6+vc2viY6hw/ytv48
qpjE1+Tn+59z8ucev+5/ktu5+FNlRZb7t//+werP/7ZXCsNwjPIf/6Pz//zv
ta7xnKz+B16c/JsisMx//L9//OpPTd5L87//+Z//85aEiswoQVb913/9+5/2
w6bnP/fmP4f4j4+Ui6r5zZ3mH6r472/79z//pp0vbxKZ4+e1/67+FP6peaf3
Q/NH1Z/Yr7L4ht+dx81ji2+35rNfbucy/rc//7PTvh/2P/69838AVpjS6m0a
AQA=

-->

</rfc>
