<?xml version='1.0' encoding='utf-8'?>
<!DOCTYPE rfc [
  <!ENTITY nbsp    "&#160;">
  <!ENTITY zwsp   "&#8203;">
  <!ENTITY nbhy   "&#8209;">
  <!ENTITY wj     "&#8288;">
]>
<?xml-stylesheet type="text/xsl" href="rfc2629.xslt" ?>
<!-- generated by https://github.com/cabo/kramdown-rfc version 1.6.22 (Ruby 3.1.3) -->
<rfc xmlns:xi="http://www.w3.org/2001/XInclude" ipr="trust200902" docName="draft-ietf-tls-rfc8447bis-03" category="std" consensus="true" updates="3749, 5077, 4680, 5246, 5705, 5878, 6520, 7301, 8447" tocInclude="true" sortRefs="true" symRefs="true" version="3">
  <!-- xml2rfc v2v3 conversion 3.16.0 -->
  <front>
    <title abbrev="(D)TLS IANA Registry Updates">IANA Registry Updates for TLS and DTLS</title>
    <seriesInfo name="Internet-Draft" value="draft-ietf-tls-rfc8447bis-03"/>
    <author initials="J." surname="Salowey" fullname="Joe Salowey">
      <organization>Venafi</organization>
      <address>
        <email>joe@salowey.net</email>
      </address>
    </author>
    <author initials="S." surname="Turner" fullname="Sean Turner">
      <organization>sn3rd</organization>
      <address>
        <email>sean@sn3rd.com</email>
      </address>
    </author>
    <date year="2023" month="February" day="02"/>
    <area>Security</area>
    <workgroup>Transport Layer Security</workgroup>
    <keyword>Internet-Draft</keyword>
    <abstract>
      <t>This document updates the changes to TLS and DTLS IANA registries
made in RFC 8447. It adds a new value "D" for discouraged
to the recommended column of the selected TLS registries.</t>
      <t>This document updates the following RFCs:
3749, 5077, 4680, 5246, 5705, 5878, 6520, 7301, and 8447.</t>
    </abstract>
    <note removeInRFC="true">
      <name>About This Document</name>
      <t>
        Status information for this document may be found at <eref target="https://datatracker.ietf.org/doc/draft-ietf-tls-rfc8447bis/"/>.
      </t>
      <t>
        Discussion of this document takes place on the
        Transport Layer Security Working Group mailing list (<eref target="mailto:tls@ietf.org"/>),
        which is archived at <eref target="https://mailarchive.ietf.org/arch/browse/tls/"/>.
        Subscribe at <eref target="https://www.ietf.org/mailman/listinfo/tls/"/>.
      </t>
      <t>Source for this draft and an issue tracker can be found at
        <eref target="https://github.com/tlswg/rfc8447bis"/>.</t>
    </note>
  </front>
  <middle>
    <section anchor="introduction">
      <name>Introduction</name>
      <t>This document instructs IANA to make changes to a number of the IANA
registries related to Transport Layer Security (TLS) and Datagram
Transport Layer Security (DTLS). These changes update the changes made
in <xref target="RFC8447"/>.</t>
      <aside>
        <t>NOTE for IANA: This document specifies changes to the registry to update
  the changes made in <xref target="RFC8447"/>.</t>
      </aside>
      <t>This specification updates the "Recommended" column in TLS
registries to define a third value "D" for items that are discouraged.</t>
    </section>
    <section anchor="terminology">
      <name>Terminology</name>
      <t>The key words "<bcp14>MUST</bcp14>", "<bcp14>MUST NOT</bcp14>", "<bcp14>REQUIRED</bcp14>", "<bcp14>SHALL</bcp14>", "<bcp14>SHALL
NOT</bcp14>", "<bcp14>SHOULD</bcp14>", "<bcp14>SHOULD NOT</bcp14>", "<bcp14>RECOMMENDED</bcp14>", "<bcp14>NOT RECOMMENDED</bcp14>",
"<bcp14>MAY</bcp14>", and "<bcp14>OPTIONAL</bcp14>" in this document are to be interpreted as
described in BCP 14 <xref target="RFC2119"/> <xref target="RFC8174"/> when, and only when, they
appear in all capitals, as shown here.</t>
    </section>
    <section anchor="adding-recommended-column">
      <name>Adding "Recommended" Column</name>
      <t>The instructions in this document update the Recommended column,
originally added in <xref target="RFC8447"/> to add a third value, "D",
indicating that a value is "Discouraged". The permitted values
are:</t>
      <ul spacing="normal">
        <li>Y: Indicates that the IETF has consensus that the
  item is <bcp14>RECOMMENDED</bcp14>. This only means that the associated
  mechanism is fit for the purpose for which it was defined.
  Careful reading of the documentation for the mechanism is
  necessary to understand the applicability of that mechanism.
  The IETF could recommend mechanisms that have limited
  applicability, but will provide applicability statements that
  describe any limitations of the mechanism or necessary constraints
  on its use.</li>
        <li>N: Indicates that the item has not been evaluated by
  the IETF and that the IETF has made no statement about the
  suitability of the associated mechanism. This does not necessarily
  mean that the mechanism is flawed, only that no consensus exists.
  The IETF might have consensus to leave an items marked as "N" on
  the basis of it having limited applicability or usage constraints.</li>
        <li>D: Indicates that the item is discouraged. This marking could be used to identify
  mechanisms that might result in problems if they are used, such as
  a weak cryptographic algorithm or a mechanism that might cause
  interoperability problems in deployment. Implementers <bcp14>SHOULD</bcp14>
  consult the linked references associated with the item to
  determine the conditions under which it <bcp14>SHOULD NOT</bcp14> or <bcp14>MUST NOT</bcp14> be used.</li>
      </ul>
      <t>Setting a value to "Y" or "D" in the "Recommended" column requires IETF Standards
Action <xref target="RFC8126"/>.  Any state transition to or from a "Y" or "D" value requires
IESG Apporval. Not all items defined in Standards Track RFCs need to be set
to "Y" or "D". Any item not otherwise specified is set to "N". The column is
blank for values that are unassigned or reserved unless specifically set.</t>
      <section anchor="rec-note">
        <name>Recommended Note</name>
        <t>Existing registries have a note on the meaning of the recommended column. For the
registries discussed in the subsequent sections this note is updated
with a sentence describing the 'D' vaue as follows:</t>
        <dl>
          <dt>Note:</dt>
          <dd>
            <t>If "Recommended" column is set to "N", it does not necessarily mean
that it is flawed; rather, it indicates that the item either has not
been through the IETF consensus process, has limited applicability, or
is intended only for specific use cases.  If the "Recommended" column
is set to "D" the item is discouraged and <bcp14>SHOULD NOT</bcp14> or <bcp14>MUST NOT</bcp14> be used.</t>
          </dd>
        </dl>
      </section>
    </section>
    <section anchor="tls-extensiontype-values">
      <name>TLS ExtensionType Values</name>
      <t>In order to refect the changes in the Recommended column allocation,
IANA <bcp14>SHALL</bcp14> update the TLS ExtensionType Values registry as follows:</t>
      <ul spacing="normal">
        <li>Change the registration procedure to:</li>
      </ul>
      <artwork><![CDATA[
    Values with the first byte in the range 0-254 (decimal) are assigned
    via Specification Required [RFC8126].  Values with the first byte
    255 (decimal) are reserved for Private Use [RFC8126].  Setting a
    "Recommended" column value to Y or D requires Standards Action {{RFC8126}}.
    Any state transition to or from a "Y" or "D" value requires
    IESG Apporval.
]]></artwork>
      <ul spacing="normal">
        <li>Add a reference to this document under the reference heading.</li>
        <li>Update the "Recommended" column with the changes as listed below.  Entries
keep their existing "Y" and "N" entries except for the entries in following table.
A reference to this document <bcp14>SHALL</bcp14> be added to these entries.</li>
      </ul>
      <table>
        <thead>
          <tr>
            <th align="left">Value</th>
            <th align="left">Extension</th>
            <th align="right">Recommended</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">4</td>
            <td align="left">truncated_hmac</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">53</td>
            <td align="left">connection_id (deprecated)</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">40</td>
            <td align="left">Reserved</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">46</td>
            <td align="left">Reserved</td>
            <td align="right">D</td>
          </tr>
        </tbody>
      </table>
      <ul spacing="normal">
        <li>Update note on the recommended column with text in <xref target="rec-note"/>.</li>
      </ul>
    </section>
    <section anchor="tls-cipher-suites-registry">
      <name>TLS Cipher Suites Registry</name>
      <aside>
        <t>Note: Review in light of <xref target="I-D.ietf-tls-deprecate-obsolete-kex"/>.</t>
      </aside>
      <t>In order to refect the changes in the Recommended column allocation,
IANA <bcp14>SHALL</bcp14> update the TLS ExtensionType Values registry as follows:</t>
      <ul spacing="normal">
        <li>Change the registration procedure to:</li>
      </ul>
      <artwork><![CDATA[
    Values with the first byte in the range 0-254 (decimal) are
    assigned via Specification Required [RFC8126].  Values with the
    first byte 255 (decimal) are reserved for Private Use [RFC8126].
    Setting a "Recommended" column value to Y or D requires Standards
    Action {{RFC8126}}. Any state transition to or from a "Y" or "D"
    value requires IESG Apporval.
]]></artwork>
      <ul spacing="normal">
        <li>Add a reference to this document under the reference heading.</li>
        <li>Update the "Recommended" column with the changes as listed below.  Entries
keep their existing "Y" and "N" entries except for the entries in following table.
A reference to this document <bcp14>SHALL</bcp14> be added to these entries.</li>
      </ul>
      <table>
        <thead>
          <tr>
            <th align="left">Value</th>
            <th align="left">Cipher Suite Name</th>
            <th align="right">Recommeded</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">0x00,0x01</td>
            <td align="left">TLS_RSA_WITH_NULL_MD5</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x02</td>
            <td align="left">TLS_RSA_WITH_NULL_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x03</td>
            <td align="left">TLS_RSA_EXPORT_WITH_RC4_40_MD5</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x04</td>
            <td align="left">TLS_RSA_WITH_RC4_128_MD5</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x05</td>
            <td align="left">TLS_RSA_WITH_RC4_128_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x06</td>
            <td align="left">TLS_RSA_EXPORT_WITH_RC2_CBC_40_MD5</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x07</td>
            <td align="left">TLS_RSA_WITH_IDEA_CBC_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x08</td>
            <td align="left">TLS_RSA_EXPORT_WITH_DES40_CBC_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x09</td>
            <td align="left">TLS_RSA_WITH_DES_CBC_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x0B</td>
            <td align="left">TLS_DH_DSS_EXPORT_WITH_DES40_CBC_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x0C</td>
            <td align="left">TLS_DH_DSS_WITH_DES_CBC_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x0D</td>
            <td align="left">TLS_DH_DSS_WITH_3DES_EDE_CBC_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x0E</td>
            <td align="left">TLS_DH_RSA_EXPORT_WITH_DES40_CBC_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x0F</td>
            <td align="left">TLS_DH_RSA_WITH_DES_CBC_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x11</td>
            <td align="left">TLS_DHE_DSS_EXPORT_WITH_DES40_CBC_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x12</td>
            <td align="left">TLS_DHE_DSS_WITH_DES_CBC_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x13</td>
            <td align="left">TLS_DHE_DSS_WITH_3DES_EDE_CBC_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x14</td>
            <td align="left">TLS_DHE_RSA_EXPORT_WITH_DES40_CBC_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x15</td>
            <td align="left">TLS_DHE_RSA_WITH_DES_CBC_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x17</td>
            <td align="left">TLS_DH_anon_EXPORT_WITH_RC4_40_MD5</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x18</td>
            <td align="left">TLS_DH_anon_WITH_RC4_128_MD5</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x19</td>
            <td align="left">TLS_DH_anon_EXPORT_WITH_DES40_CBC_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x1A</td>
            <td align="left">TLS_DH_anon_WITH_DES_CBC_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x1B</td>
            <td align="left">TLS_DH_anon_WITH_3DES_EDE_CBC_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x19</td>
            <td align="left">TLS_DH_anon_EXPORT_WITH_DES40_CBC_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x1E</td>
            <td align="left">TLS_KRB5_WITH_DES_CBC_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x20</td>
            <td align="left">TLS_KRB5_WITH_RC4_128_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x21</td>
            <td align="left">TLS_KRB5_WITH_IDEA_CBC_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x22</td>
            <td align="left">TLS_KRB5_WITH_DES_CBC_MD5</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x23</td>
            <td align="left">TLS_KRB5_WITH_3DES_EDE_CBC_MD5</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x24</td>
            <td align="left">TLS_KRB5_WITH_RC4_128_MD5</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x25</td>
            <td align="left">TLS_KRB5_WITH_IDEA_CBC_MD5</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x26</td>
            <td align="left">TLS_KRB5_EXPORT_WITH_DES_CBC_40_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x27</td>
            <td align="left">TLS_KRB5_EXPORT_WITH_RC2_CBC_40_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x28</td>
            <td align="left">TLS_KRB5_EXPORT_WITH_RC4_40_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x29</td>
            <td align="left">TLS_KRB5_EXPORT_WITH_DES_CBC_40_MD5</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x2A</td>
            <td align="left">TLS_KRB5_EXPORT_WITH_RC2_CBC_40_MD5</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x2B</td>
            <td align="left">TLS_KRB5_EXPORT_WITH_RC4_40_MD5</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x8A</td>
            <td align="left">TLS_PSK_WITH_RC4_128_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x8E</td>
            <td align="left">TLS_DHE_PSK_WITH_RC4_128_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x92</td>
            <td align="left">TLS_RSA_PSK_WITH_RC4_128_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0xC0,0x02</td>
            <td align="left">TLS_ECDH_ECDSA_WITH_RC4_128_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0xC0,0x07</td>
            <td align="left">TLS_ECDHE_ECDSA_WITH_RC4_128_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0xC0,0x0C</td>
            <td align="left">TLS_ECDH_RSA_WITH_RC4_128_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0xC0,0x11</td>
            <td align="left">TLS_ECDHE_RSA_WITH_RC4_128_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0xC0,0x16</td>
            <td align="left">TLS_ECDH_anon_WITH_RC4_128_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0xC0,0x33</td>
            <td align="left">TLS_ECDHE_PSK_WITH_RC4_128_SHA</td>
            <td align="right">D</td>
          </tr>
        </tbody>
      </table>
      <ul spacing="normal">
        <li>Update note on the recommended column with text in <xref target="rec-note"/>.</li>
      </ul>
    </section>
    <section anchor="tls-supported-groups">
      <name>TLS Supported Groups</name>
      <t>In order to refect the changes in the Recommended column allocation,
IANA <bcp14>SHALL</bcp14> update the TLS Supported Groups registry as follows:</t>
      <ul spacing="normal">
        <li>Update the registration policy to include:</li>
      </ul>
      <artwork><![CDATA[
    Setting a "Recommended" column value to Y or D requires Standards
    Action {{RFC8126}}. Any state transition to or from a "Y" or "D"
    value requires IESG Apporval.
]]></artwork>
      <ul spacing="normal">
        <li>Add a reference to this document under the reference heading.</li>
        <li>Entries keep their existing Recommended column "Y" and "N" entries.</li>
      </ul>
      <aside>
        <t>Note: Review in light of <xref target="I-D.ietf-tls-deprecate-obsolete-kex"/>
  also there are some weaker elliptic curves in this list.</t>
      </aside>
      <ul spacing="normal">
        <li>Update note on the recommended column with text in <xref target="rec-note"/>.</li>
      </ul>
    </section>
    <section anchor="tls-exporter-labels-registry">
      <name>TLS Exporter Labels Registry</name>
      <t>This document updates the registration procedure for the TLS Exporter
registry and updates the Recommended column allocation.
IANA <bcp14>SHALL</bcp14> update the TLS Exporter Labels Registry as follows:</t>
      <ul spacing="normal">
        <li>Change the registration procedure from Specification Required to
Expert Review and update it to include:</li>
      </ul>
      <artwork><![CDATA[
    Setting a "Recommended" column value to Y or D requires Standards
    Action {{RFC8126}}. Any state transition to or from a "Y" or "D"
    value requires IESG Apporval.
]]></artwork>
      <ul spacing="normal">
        <li>Add a reference to this document under the reference heading.</li>
        <li>Entries keep their existing Recommended column "Y" and "N" entries</li>
        <li>Update note on the recommended column with text in <xref target="rec-note"/>.</li>
        <li>update the note on the role of the expert reviewer as follows.</li>
      </ul>
      <dl>
        <dt>Note:</dt>
        <dd>
          <t>The role of the designated expert is described in <xref target="RFC8447"/>.
Even though this registry does not require a specification, the
designated expert <xref target="RFC8126"/> will highly encourage registrants
to provide a link to a publicly available specification. An
Internet-Draft (that is posted and never published as an RFC)
or a document from another standards body, industry consortium,
university site, etc. are suitable for these purposes.
The expert may provide more in-depth reviews, but their approval
should not be taken as an endorsement of the exporter label.  The
expert also verifies that the label is a string consisting of
printable ASCII characters beginning with "EXPORTER".  IANA <bcp14>MUST</bcp14>
also verify that one label is not a prefix of any other label.
For example, labels "key" or "master secretary" are forbidden.</t>
        </dd>
      </dl>
    </section>
    <section anchor="tls-certificate-types">
      <name>TLS Certificate Types</name>
      <t>In order to refect the changes in the Recommended column allocation,
IANA <bcp14>SHALL</bcp14> update the the TLS Certificate Types registry as follows:</t>
      <ul spacing="normal">
        <li>Change the registration procedure to:</li>
      </ul>
      <artwork><![CDATA[
    Values in the range 0-223 (decimal) are assigned via Specification
    Required [RFC8126]. Values in the range 224-255 (decimal) are
    reserved for Private Use [RFC8126]. Setting a "Recommended" column
    value to Y or D requires Standards
    Action {{RFC8126}}. Any state transition to or from a "Y" or "D"
    value requires IESG Apporval.
]]></artwork>
      <ul spacing="normal">
        <li>Add a reference to this document under the reference heading.</li>
        <li>Entries keep their existing Recommended column "Y" and "N" entries.</li>
        <li>Update note on the recommended column with text in <xref target="rec-note"/>.</li>
      </ul>
    </section>
    <section anchor="tls-hashalgorithm-registry">
      <name>TLS HashAlgorithm Registry</name>
      <t>Though TLS 1.0 and TLS 1.1 were deprecated <xref target="RFC8996"/>, TLS 1.2 will
be in use for some time. In order to refect the changes in the Recommended
column allocation, IANA <bcp14>SHALL</bcp14> update the TLS HashAlgorithm Registry
registry as follows:</t>
      <ul spacing="normal">
        <li>Update the registration procedure to include:</li>
      </ul>
      <artwork><![CDATA[
    Setting a "Recommended" column value to Y or D requires Standards
    Action {{RFC8126}}. Any state transition to or from a "Y" or "D"
    value requires IESG Apporval.
]]></artwork>
      <ul spacing="normal">
        <li>Add a reference to this document under the reference heading.</li>
        <li>Update the TLS HashAlgorithm registry to add a "Recommended" column
as follows:</li>
      </ul>
      <table>
        <thead>
          <tr>
            <th align="left">Value</th>
            <th align="left">Descsription</th>
            <th align="right">Recommended</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">0</td>
            <td align="left">none</td>
            <td align="right">Y</td>
          </tr>
          <tr>
            <td align="left">1</td>
            <td align="left">md5</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">2</td>
            <td align="left">sha1</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">3</td>
            <td align="left">sha224</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">4</td>
            <td align="left">sha256</td>
            <td align="right">Y</td>
          </tr>
          <tr>
            <td align="left">5</td>
            <td align="left">sha384</td>
            <td align="right">Y</td>
          </tr>
          <tr>
            <td align="left">6</td>
            <td align="left">sha512</td>
            <td align="right">Y</td>
          </tr>
          <tr>
            <td align="left">8</td>
            <td align="left">Intrinsic</td>
            <td align="right">Y</td>
          </tr>
        </tbody>
      </table>
      <ul spacing="normal">
        <li>Add note on the recommended column with text in <xref target="rec-note"/>.</li>
      </ul>
    </section>
    <section anchor="tls-signaturealgorithm-registry">
      <name>TLS SignatureAlgorithm registry</name>
      <t>Though TLS 1.0 and TLS 1.1 were deprecated <xref target="RFC8996"/>, TLS 1.2 will
be in use for some time. In order to refect the changes in the Recommended
column allocation, IANA <bcp14>SHALL</bcp14> update the TLS SignatureAlgorithm registry
registry as follows:</t>
      <ul spacing="normal">
        <li>Update the registration procedure to include:</li>
      </ul>
      <artwork><![CDATA[
    Setting a "Recommended" column value to Y or D requires Standards
    Action {{RFC8126}}. Any state transition to or from a "Y" or "D"
    value requires IESG Apporval.
]]></artwork>
      <ul spacing="normal">
        <li>Add a reference to this document under the reference heading.</li>
        <li>Update the TLS SignatureAlgorithm registry to add a "Recommended"
column as follows:</li>
      </ul>
      <table>
        <thead>
          <tr>
            <th align="left">Value</th>
            <th align="left">Descsription</th>
            <th align="right">Recommended</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">0</td>
            <td align="left">anonymous</td>
            <td align="right">N</td>
          </tr>
          <tr>
            <td align="left">1</td>
            <td align="left">rsa</td>
            <td align="right">Y</td>
          </tr>
          <tr>
            <td align="left">2</td>
            <td align="left">dsa</td>
            <td align="right">N</td>
          </tr>
          <tr>
            <td align="left">3</td>
            <td align="left">ecdsa</td>
            <td align="right">Y</td>
          </tr>
          <tr>
            <td align="left">7</td>
            <td align="left">ed25519</td>
            <td align="right">Y</td>
          </tr>
          <tr>
            <td align="left">8</td>
            <td align="left">ed448</td>
            <td align="right">Y</td>
          </tr>
          <tr>
            <td align="left">64</td>
            <td align="left">gostr34102012_256</td>
            <td align="right">N</td>
          </tr>
          <tr>
            <td align="left">65</td>
            <td align="left">gostr34102012_512</td>
            <td align="right">N</td>
          </tr>
        </tbody>
      </table>
      <ul spacing="normal">
        <li>Add note on the recommended column with text in <xref target="rec-note"/>.</li>
      </ul>
    </section>
    <section anchor="tls-clientcertificatetypes-registry">
      <name>TLS ClientCertificateTypes registry</name>
      <t>Though TLS 1.0 and TLS 1.1 were deprecated <xref target="RFC8996"/>, TLS 1.2 will
be in use for some time. In order to refect the changes in the Recommended
column allocation, IANA <bcp14>SHALL</bcp14> update the  TLS ClientCertificateTypes
registry as follows:</t>
      <ul spacing="normal">
        <li>Update the registration procedure to include:</li>
      </ul>
      <artwork><![CDATA[
    Setting a "Recommended" column value to Y or D requires Standards
    Action {{RFC8126}}. Any state transition to or from a "Y" or "D"
    value requires IESG Apporval.
]]></artwork>
      <ul spacing="normal">
        <li>Add a reference to this document under the reference heading.</li>
        <li>Update the TLS ClientCertificateTypes registry to add a "Recommended"
column as follows:</li>
      </ul>
      <table>
        <thead>
          <tr>
            <th align="left">Value</th>
            <th align="left">Descsription</th>
            <th align="right">Recommended</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">1</td>
            <td align="left">rsa_sign</td>
            <td align="right">Y</td>
          </tr>
          <tr>
            <td align="left">2</td>
            <td align="left">dss_sign</td>
            <td align="right">N</td>
          </tr>
          <tr>
            <td align="left">3</td>
            <td align="left">rsa_fixed_dh</td>
            <td align="right">N</td>
          </tr>
          <tr>
            <td align="left">4</td>
            <td align="left">dss_fixed_dh</td>
            <td align="right">N</td>
          </tr>
          <tr>
            <td align="left">5</td>
            <td align="left">rsa_ephemeral_dh_RESERVED</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">6</td>
            <td align="left">dss_ephemeral_dh_RESERVED</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">20</td>
            <td align="left">fortezza_dms_RESERVED</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">64</td>
            <td align="left">ecdsa_sign</td>
            <td align="right">Y</td>
          </tr>
          <tr>
            <td align="left">65</td>
            <td align="left">rsa_fixed_ecdh</td>
            <td align="right">N</td>
          </tr>
          <tr>
            <td align="left">66</td>
            <td align="left">ecdsa_fixed_ecdh</td>
            <td align="right">N</td>
          </tr>
          <tr>
            <td align="left">67</td>
            <td align="left">gost_sign256</td>
            <td align="right">N</td>
          </tr>
          <tr>
            <td align="left">68</td>
            <td align="left">gost_sign512</td>
            <td align="right">N</td>
          </tr>
        </tbody>
      </table>
      <ul spacing="normal">
        <li>Add note on the recommended column with text in <xref target="rec-note"/>.</li>
      </ul>
    </section>
    <section anchor="tls-pskkeyexchangemode-registry">
      <name>TLS PskKeyExchangeMode registry</name>
      <t>In order to refect the changes in the Recommended column allocation,
IANA <bcp14>SHALL</bcp14> update the TLS PskKeyExchangeMode registry as follows:</t>
      <ul spacing="normal">
        <li>Update the registration procedure to include:</li>
      </ul>
      <artwork><![CDATA[
    Setting a "Recommended" column value to Y or D requires Standards
    Action {{RFC8126}}. Any state transition to or from a "Y" or "D"
    value requires IESG Apporval.
]]></artwork>
      <ul spacing="normal">
        <li>Add a reference to this document under the reference heading.</li>
        <li>Entries keep their existing recommended column "Y" and "N" entries.</li>
        <li>Update note on the recommended column with text in <xref target="rec-note"/>.</li>
      </ul>
    </section>
    <section anchor="security-considerations">
      <name>Security Considerations</name>
      <t>The change to Specification Required from IETF Review lowers the amount
of review provided by the WG for cipher suites and supported groups.
This change reflects reality in that the WG essentially provided no
cryptographic review of the cipher suites or supported groups.  This
was especially true of national cipher suites.</t>
      <t>Recommended algorithms are regarded as secure for general use at the
time of registration; however, cryptographic algorithms and parameters
will be broken or weakened over time.  It is possible that the
"Recommended" status in the registry lags behind the most recent advances
in cryptanalysis.  Implementers and users need to check that the
cryptographic algorithms listed continue to provide the expected level
of security.</t>
      <t>Designated experts ensure the specification is publicly available.  They may
provide more in-depth reviews.  Their review should not be taken as an
endorsement of the cipher suite, extension, supported group, etc.</t>
    </section>
    <section anchor="iana-considerations">
      <name>IANA Considerations</name>
      <t>This document is entirely about changes to TLS-related IANA registries.</t>
    </section>
  </middle>
  <back>
    <references>
      <name>Normative References</name>
      <reference anchor="RFC8447">
        <front>
          <title>IANA Registry Updates for TLS and DTLS</title>
          <author fullname="J. Salowey" initials="J." surname="Salowey">
            <organization/>
          </author>
          <author fullname="S. Turner" initials="S." surname="Turner">
            <organization/>
          </author>
          <date month="August" year="2018"/>
          <abstract>
            <t>This document describes a number of changes to TLS and DTLS IANA registries that range from adding notes to the registry all the way to changing the registration policy.  These changes were mostly motivated by WG review of the TLS- and DTLS-related registries undertaken as part of the TLS 1.3 development process.</t>
            <t>This document updates the following RFCs: 3749, 5077, 4680, 5246, 5705, 5878, 6520, and 7301.</t>
          </abstract>
        </front>
        <seriesInfo name="RFC" value="8447"/>
        <seriesInfo name="DOI" value="10.17487/RFC8447"/>
      </reference>
      <reference anchor="RFC2119">
        <front>
          <title>Key words for use in RFCs to Indicate Requirement Levels</title>
          <author fullname="S. Bradner" initials="S." surname="Bradner">
            <organization/>
          </author>
          <date month="March" year="1997"/>
          <abstract>
            <t>In many standards track documents several words are used to signify the requirements in the specification.  These words are often capitalized. This document defines these words as they should be interpreted in IETF documents.  This document specifies an Internet Best Current Practices for the Internet Community, and requests discussion and suggestions for improvements.</t>
          </abstract>
        </front>
        <seriesInfo name="BCP" value="14"/>
        <seriesInfo name="RFC" value="2119"/>
        <seriesInfo name="DOI" value="10.17487/RFC2119"/>
      </reference>
      <reference anchor="RFC8174">
        <front>
          <title>Ambiguity of Uppercase vs Lowercase in RFC 2119 Key Words</title>
          <author fullname="B. Leiba" initials="B." surname="Leiba">
            <organization/>
          </author>
          <date month="May" year="2017"/>
          <abstract>
            <t>RFC 2119 specifies common key words that may be used in protocol  specifications.  This document aims to reduce the ambiguity by clarifying that only UPPERCASE usage of the key words have the  defined special meanings.</t>
          </abstract>
        </front>
        <seriesInfo name="BCP" value="14"/>
        <seriesInfo name="RFC" value="8174"/>
        <seriesInfo name="DOI" value="10.17487/RFC8174"/>
      </reference>
      <reference anchor="RFC8126">
        <front>
          <title>Guidelines for Writing an IANA Considerations Section in RFCs</title>
          <author fullname="M. Cotton" initials="M." surname="Cotton">
            <organization/>
          </author>
          <author fullname="B. Leiba" initials="B." surname="Leiba">
            <organization/>
          </author>
          <author fullname="T. Narten" initials="T." surname="Narten">
            <organization/>
          </author>
          <date month="June" year="2017"/>
          <abstract>
            <t>Many protocols make use of points of extensibility that use constants to identify various protocol parameters.  To ensure that the values in these fields do not have conflicting uses and to promote interoperability, their allocations are often coordinated by a central record keeper.  For IETF protocols, that role is filled by the Internet Assigned Numbers Authority (IANA).</t>
            <t>To make assignments in a given registry prudently, guidance describing the conditions under which new values should be assigned, as well as when and how modifications to existing values can be made, is needed.  This document defines a framework for the documentation of these guidelines by specification authors, in order to assure that the provided guidance for the IANA Considerations is clear and addresses the various issues that are likely in the operation of a registry.</t>
            <t>This is the third edition of this document; it obsoletes RFC 5226.</t>
          </abstract>
        </front>
        <seriesInfo name="BCP" value="26"/>
        <seriesInfo name="RFC" value="8126"/>
        <seriesInfo name="DOI" value="10.17487/RFC8126"/>
      </reference>
      <reference anchor="I-D.ietf-tls-deprecate-obsolete-kex">
        <front>
          <title>Deprecating Obsolete Key Exchange Methods in TLS</title>
          <author fullname="Carrick Bartle" initials="C." surname="Bartle">
            <organization>Apple, Inc.</organization>
          </author>
          <author fullname="Nimrod Aviram" initials="N." surname="Aviram">
         </author>
          <date day="11" month="December" year="2022"/>
          <abstract>
            <t>   This document makes several prescriptions regarding the following key
   exchange methods in TLS, most of which have been superseded by better
   options:

            </t>
          </abstract>
        </front>
        <seriesInfo name="Internet-Draft" value="draft-ietf-tls-deprecate-obsolete-kex-01"/>
      </reference>
      <reference anchor="RFC8996">
        <front>
          <title>Deprecating TLS 1.0 and TLS 1.1</title>
          <author fullname="K. Moriarty" initials="K." surname="Moriarty">
            <organization/>
          </author>
          <author fullname="S. Farrell" initials="S." surname="Farrell">
            <organization/>
          </author>
          <date month="March" year="2021"/>
          <abstract>
            <t>This document formally deprecates Transport Layer Security (TLS) versions 1.0 (RFC 2246) and 1.1 (RFC 4346). Accordingly, those documents have been moved to Historic status. These versions lack support for current and recommended cryptographic algorithms and mechanisms, and various government and industry profiles of applications using TLS now mandate avoiding these old TLS versions. TLS version 1.2 became the recommended version for IETF protocols in 2008 (subsequently being obsoleted by TLS version 1.3 in 2018), providing sufficient time to transition away from older versions. Removing support for older versions from implementations reduces the attack surface, reduces opportunity for misconfiguration, and streamlines library and product maintenance. </t>
            <t>This document also deprecates Datagram TLS (DTLS) version 1.0 (RFC 4347) but not DTLS version 1.2, and there is no DTLS version 1.1.</t>
            <t>This document updates many RFCs that normatively refer to TLS version 1.0 or TLS version 1.1, as described herein. This document also updates the best practices for TLS usage in RFC 7525; hence, it is part of BCP 195.</t>
          </abstract>
        </front>
        <seriesInfo name="BCP" value="195"/>
        <seriesInfo name="RFC" value="8996"/>
        <seriesInfo name="DOI" value="10.17487/RFC8996"/>
      </reference>
    </references>
  </back>
  <!-- ##markdown-source:
H4sIAAAAAAAAA+1c63LbRpb+j6fopX9MvEXSJEXqNtlsZJFJNLFlrygn60ql
VE2gSfYKBDhoQDITOc8yzzJPtt85jSsJUpIj/5gaq8oy2Ow+fa7fOX2BWq2W
E+vYV8fi7OT8RFyomTZxtBLvlp6MlRHTMBKXr8ZCBp4Y4sGRk0mkbo7FV8Pn
1F47yvFCN5ALEPUiOY1bWsXTVuybVjR1D/v9g4k2rc6e46LvLIxWx8LEnpPY
scdi76B/1BSDzsFBU/T3Dzt47vX38fugM8Dvw4PDptgf9NB+sNfpNgVRdMDR
nuPoZXQs4igxca/TOer0HBkpeSwaY+UmkY5XDec2jK5nUZgs0XoZycAswygW
r+RKRaLoda1W6OhBKUGsokDFrSEJ4tyoIFHHjhD3kxAiXi2hgcbPmFEHM/E9
DaH2hdQ+2qGPb0kx7TCaUbOM3Dma53G8NMcvXlAvatI3qp11e0ENLyZReGvU
C4x/QeNmOp4nE0vwdvaiUHHDcUwMu11JPwzAyQqGMQsZxVd/T0LWdBA6S30s
folDtykMpIjU1OBptaCHXx1HJvE8jCBwCxMJoQMM+ltbjEHxVq24zdr5b6Gq
tIJZGejfZKzD4Fj8pAI51fyFstL/X6i+NbZ/G+qtTDBui8sESo9K9MdKBuXW
Kn0T7EVembxB92+5te2GC8cJwmiBvjewnaODaelTq9UScgLnlW7sOJdzbQSc
N1moIBapR4p4roQ7l8GMnsNKOFj/j6z/ayh4IT0FMcTFd6fsmG1xFgvpeUZI
EahbcSP9RInGsMGR5WnjhkkkZ8pzQJkmihQ4xvSe8oQb+skiEOGUvzHKV26M
Zpq3mLK9i+1p6EPJ5H5gyBw7j40tkpPFsJpaaM/zleM8o8CIQi9xyQDrDMCK
iEE3NlY7EGwhrysqhC6SxQTxkopG/ZxCJEjnS5KUtL0lwsRXUMNzawgZy1kk
F872vmSr5/CruTIFI1ZRFfOS+eAh4vff/xsKI8k/foTsX0ujYVcEz7UX3gb/
1Zj4oXvd+AY+d/7mcsS2JBmORVUTZqlcPSWJSsJbK6eIic+WDQKMNUbEBiNf
v2BGvkk1npJ3OQwqdm9cFG7UyPwI5AjBS3rG7J6a6kDBIvFcR96af+pYLYig
hA9HquyubXKCSxUtdBD64WxFHCkB3BQEnEY0Xr8bXzaa9n9SEj1fjP7n3dnF
aEjP4x9OXr3KH5y0x/iHN+9eDYunYuTpm9evR+dDOxitotLkNF6fvG9Yf228
eXt59ub85FWDJI4rBiEpIPSEdAtkX0aK3EwiYynjRnqCDxjz8vTtP//R7UP5
/wHl97rdo48f0w+H3YM+PtzOVWBnCwN/lX6E4leOXC6VjIiK9H3hyqWOpQ9Q
lTDXHL4j5ipS0N5//kKa+fVYfD1xl93+N2kDCVxpzHRWaWSdbbZsDLZKrGmq
mSbXZqV9TdNVfk/eVz5nei81kpeceB4BUNUlT9klrddkeAEnNpsmK0XpxQY2
Np0w0jMdQNcrgllrv3LQMNx4XtXBm+ThTQS6x8ED7qyPp+6P6RvDwtcbDBxi
Sd4ek79wL0PFBWUQ8Z7qBKak0mBhTBtdfifmMLsLsVRgkuI7m+sQWzRTSbtt
Cx/sUguksBI1aUzoagJFHrxQBBTaMIWpjjlaqd8yiZahUfz5dq7dOeYRt+DC
xjniloafgvVp4gOGJNsmheFM5xZPMpLluWxKVq4yRqboBWtEXGdYPpdLH5qY
aJ9wl+lCgpyEnf4yUw807HtFyiv6pZLP5Y0SvobaU7kr5JtikkA4jThbRuEN
IXR1erAFJUMgS44pZIGO4F1Z0tI6XqqDQlqIX0hKRkSRANSwOoB+NMgmBrHc
Eue1HsAWJg8IwhiQowKhyHM4s01snZQ7itXfuutwFgjCQhDUKmFS+JBJwH5Z
12VHKWk9S0vK8pKJpf1V6k0yKGav+pYvb5XXtD7JXcBO4dHqA1KJWbPqQs/m
qe1Kvh8KX1GTDNK0QtmUwRd43sAEuUImSHJsD81UyEFTH1h3rwgGQISWrUPm
GG43B6mhlMWsYogTmsW6I3wDZuXiAy4VxHq6qsZcStOKGSmT+FTzkA9OfBJM
syVWnGyIEirqBIEoredIcavktXCj1TIOUbYsEaXIFVgIoZBnr5MlE5RmciWI
pWUyclcIPMoUUUwdwMGXfrgiZ0HtuVj67DcIUWGRnwmQvohrUouvAzIDAAGJ
KYBjlF3oFjwVyovDNIRiTvxp6RRC1TaEGAsK2ClSDUmVZbdMv8iBYxUz+Ga4
C4033jeoMxUgnAm2lDKR+nuioXrrcGOCH4mywznhLJLn6t4+qiYhToIUC7A2
BKoytzQZJppG4QLzl6a1rGQTOGej8ffiZImqEl+0xTnChxK7deEUVInVnAeq
WN1rrrcRaNaPJlS9x05FvjazxXqlmAwha3SrAd1Z0eiRs2IYq+U8TUJZKWec
iS+DawZpm46KMi0JYEE9I8bwLYRQ0Q2ek8BH1BdFI6VMkKdK7lkltUJGJX5/
BlhugTP10XFGFOZkqVLtyPEtiXdFaGiRA05bpJPNpUxbfGeTSrkIpXhMjLFq
5IVOMjFQPxfQKi0LuCbguXRWuHsOe6dEJzg4PDfDdpvPlfjL8C/QTUKYmC6E
sAJySDr8B4iYbimTy1pvkiPXAScL67DO0SNHyr+KSJIleZzeAkJKU5csNTic
GuJ5FCazeYH/BXQiumnaJg+oRULgc+Row8DA6ma4Jt/IrE0hBwQxWC8Kknxb
ZDkl6REMW3CT09W94f2MV6qjD+DJwIiXq6USP9nSyTnDsjYitMBEBD1uXFn+
pJ6wWfBR8IV2wdN0eHlpK99Slbht0mLRVfGHljjlScvrMlsAsd69hJcM6PjH
H38w/KXUcmicatQ/SOixytiOmF6n1Rv0xVceDLCQ/nMOzSwwmdCNlmJcWcJd
WNTxxC8pfP3a3jUfU+kNBmuT5BFPDvA20jekmXewf5lqjr1MpDYQclB+TwYe
FqBbYF0d3jLBPwO5NL4Ku6x7WOqEC/k8VdnVdGWxwBnIWjLrNLdFLm1hpBuU
2/NKruTMETniDFdsCg4DxY0Cu9MjsNpVS+qsI1sH8SoHUvEiFCWNsj3xpauW
RYmeNeugtD2DMs5XpLqTXeJZX6filZc6djPB5CQh4h17i7grIkDc83NXibI7
5+64RT/pf/f83JU/HGNwHwSxmAsI9ryr+UK6dTNmP0Oab7An7gB2gYX6K+2R
O2NlziSe1w7pd8TdReblW+WqDtl/7JDCXco5rmZ/zjqN+hDbtWeeN2nnKEPB
U70kyB+jYIfpsw3z3TtLlKjQ9UarW6LscxWI3IpoO2sN2/mueq6tVjgxoY/q
rHWtPlT3i/498dYW3Fkx9Gl4yzRKc34S3jKRotz9RLi1yFpX4j4Gbm3uqUDu
F7j9VLgVGd6WA1ycy4XajriiBLoVzH0g6NaiL4Gv6HzodJr41U0nQWheXYxP
rn4+u/zh6vzdq1dXr4eDDcgbClEe3Ns6GPq4Z+ze2tjR/759c3FpSVyc9q/6
nXUOaoj06xig0d3e4QOGD3YNv1+E/Z0i9K5OX54+TIyDOj7OhqMTJnE/I4c7
GBmOxuDhYXSO6vgAgQcOf5kOHWLQePzJXJyWuEhJPZKR4RYKe0RiNBw9kMyo
SubPaPa7Kpk6ee7WB3W7lflHf0ap3V4Nrcdptbu3jcTj1Nrtr9H5E3rtDmpo
7RCrhsJBhcKVDFBY3odFNWQOa8g8Do26R/dw8hi9nGxj58F6ebmNwg5rf2ah
yvH448XLwSMduNepHf9gvO91a8c/HKd7vVoCmQD3ekhvr3Z8xSBVIjU0+rU0
HuylvUHt+FwJ986/vz5+zRuyrMnavLMrsnzwwa7BpZRLg9fHHu4e288nTftV
Rx89kO1U/vXhJw9kfMvwlw/gnYaujTssT/t2/OOmw68PqKa80YMGHa2XgfcM
Ot2oHUengAb8qivB1scdrI0bPXTg6fqEtRXf2qhKDrbTPWjY/vpkmwmhZtje
3sZsO3T5RNsOdtdhnNCSjpZTfPvs8++7rk+4dQ+gtDKs7gGEvnb5YFkHrp94
qrQR8O+3fk4Xv7VL3xob1ayG2591h4muLfqGl8W0uY1/JsTKlw44IZfyfb2M
tSvcJLpRxdUOWuGX96aewuGzswb2vki8khPll/fZtl+R27IFlW0flMk6hTdD
y2UiOwOmvXPjrJ7jx++ZsZ9u2d7ig1tMpaI4M3chAZ1UfYm3J4q3p/HmVtlN
KnQQfNnxqrL2jNieEKvwmHZ2ynnMZ8blQZ6izVA+20/Hk37Kl99SQ6U3Dkc3
fDaZHk3qEqDnh6KpUeggtux9fB/O2Zyv7Aj28s4csOOvoMH0eDH3cLpsAxvm
l3v4roK9P7pMJkgUdOnrhi5KT3xVnZ1czKne3hZf2dNagyTDW4xkukDdQHVM
zcztbRTJt3efO3wTI3cd65YBH9MLkx+ATUJv1aSD3oSVQoe2iGedLJpOEmjQ
NnwRSceqKVTsti1I8rUdPwcZk9/bgukuC9Mu5CoXfhFGtN9NUAy/sUY39gaU
dVS5pK7Sd8ycr7HYS0ciBhQHqVjwvzAy9iJR4UQWf3zCnzbf4nHS6RnaIYK9
wZofYXNPUiMMDp/nezMIYRsl4dRZos2KdzI+PTuj2oJuV9MVlAkMG/AVAfb+
hi14RxcNOpQmjKRTZKeYN71yFAalWUku2B8BrD+QFHSPy1rFiuDQFQP1QdLV
l6ZtM6JxrVYWTxbSkLhGuZGKZYRWadF+oj1PBUXtdAoVWHcCUq+Wn/nQOssH
G7M+8SnK+okJVp/1J9SbpyVMpu7EpI50r9dvbZyUMIWHnE7vzjylhPAl+6xV
e0+5evhBmvlJfjGtXEtxOqAu3XaHebDPXVR+dE08P73N9H50BL030149Rn2H
72DztRS+p0J1Y6wXqi0eHWXOZpSJ7RXXFqkevVAphdmX2qmqqE01l993sLex
twR2RfvF6doQFYqJaDUBWetvLGCFfbz1dCw9HsPQgJLJHfRODV08LbxBsTXT
w5OZy27esGcbAGd5Uz9tGuzndAa2ae+wnzft26ZBt5c3HeKJ3pvRMJqbtqaa
f4KlPpdZ8MdNpf+rR+wu0b6E7dOG7Q5db4ldR+RVTiV2HxG66+fe9ZFLm22r
RZiYO3GeR29kZB5fFGkefz7PY1e5XqnHAbV4qEu6R5WoVF6/f1iELkXxDGuE
aK/f7fQ63d6VDXZLdn+w8bWN8vMniee0+vQ1rFeqBqvF4L9ySO+Q70s4P3E4
3+NG20K6NqAfk4wfENJp9F7RcmMthE3WWMQx9cSCT3lX3jz/op/23vhikI5Q
yzlWu5H08eXVxWg8uvhpNMwT+X46fHevHmHPlBbJv/0mr7yFqSHUz5CmKs3+
oMI5ehQs7u/nY+q+PUgxhglW0Oew/M3TA89bc/2jWo0+2Eh/HXqqBDqf+fRg
x9xfAOEzLCprHOTzLSqfFa9jn9J+Edi2b97Zl0DddDsj3LaHzUrkNyPSHWz6
6wGR3X6XKAuC2Amn6cZYtmtG79lxh5+/5wTn2kt6xt7CJTlNfmDFf9KB9990
9ro2qZTeuSfAlPyilS69JweaytC7J5pfpcmnDEKn+nJXylO641blgbLuOguC
30pz6K1NxZuaTD+OEt7FDVgv0q8SgoLLYZe/T2bSG6ozOK/d3jRkBZvvZyog
2OP8n76ZStlfsB6LoPqrmEPVN/RSy5a31qwulzKSC3o3DLzTvi6Ki0kU0vYj
vYxKZ0L8ShJtuNoig/42gt2ONZr2C/P3Y6vBSVGVFPtLGSL4ckY7inOdvnq6
ACiSU/Jrkt6NpHfZ6F1+5llCYyuj+e2X8ktxfAxi6Cl7V8udK/e6YGWrxOk9
VTeEAwQWNbK92mx3nv9agw/N+eSaJnV/mGq4visOSweGUWu+tpHNCtrY7LYb
tSvaIXZ27hDbjjrKnHDr5rBTszlc9rAmOE3veDfXXdZubfNSlMF9M74rfx6C
hI0R0yQQv85a/eMareyvP6z9bQ2agNb5E+leO/8PeqYRI7lGAAA=

-->

</rfc>
