<?xml version='1.0' encoding='utf-8'?>
<!DOCTYPE rfc [
  <!ENTITY nbsp    "&#160;">
  <!ENTITY zwsp   "&#8203;">
  <!ENTITY nbhy   "&#8209;">
  <!ENTITY wj     "&#8288;">
]>
<?xml-stylesheet type="text/xsl" href="rfc2629.xslt" ?>
<!-- generated by https://github.com/cabo/kramdown-rfc version 1.7.29 (Ruby 3.4.4) -->
<rfc xmlns:xi="http://www.w3.org/2001/XInclude" ipr="trust200902" docName="draft-ietf-tls-rfc8447bis-14" category="std" consensus="true" submissionType="IETF" updates="8447" tocInclude="true" sortRefs="true" symRefs="true" version="3">
  <!-- xml2rfc v2v3 conversion 3.28.1 -->
  <front>
    <title abbrev="(D)TLS IANA Registry Updates">IANA Registry Updates for TLS and DTLS</title>
    <seriesInfo name="Internet-Draft" value="draft-ietf-tls-rfc8447bis-14"/>
    <author initials="J." surname="Salowey" fullname="Joe Salowey">
      <organization>Venafi</organization>
      <address>
        <email>joe@salowey.net</email>
      </address>
    </author>
    <author initials="S." surname="Turner" fullname="Sean Turner">
      <organization>sn3rd</organization>
      <address>
        <email>sean@sn3rd.com</email>
      </address>
    </author>
    <date year="2025" month="June" day="16"/>
    <area>Security</area>
    <workgroup>Transport Layer Security</workgroup>
    <keyword>Internet-Draft</keyword>
    <abstract>
      <?line 41?>

<t>This document updates the changes to TLS and DTLS IANA registries
made in RFC 8447. It adds a new value "D" for discouraged
to the Recommended column of the selected TLS registries and
adds a "Comment" column to all active registries that do not
already have a "Comment" column. Finally, it updates the
registration request instructions.</t>
      <t>This document updates RFC 8447.</t>
    </abstract>
    <note removeInRFC="true">
      <name>About This Document</name>
      <t>
        Status information for this document may be found at <eref target="https://datatracker.ietf.org/doc/draft-ietf-tls-rfc8447bis/"/>.
      </t>
      <t>
        Discussion of this document takes place on the
        Transport Layer Security Working Group mailing list (<eref target="mailto:tls@ietf.org"/>),
        which is archived at <eref target="https://mailarchive.ietf.org/arch/browse/tls/"/>.
        Subscribe at <eref target="https://www.ietf.org/mailman/listinfo/tls/"/>.
      </t>
      <t>Source for this draft and an issue tracker can be found at
        <eref target="https://github.com/tlswg/rfc8447bis"/>.</t>
    </note>
  </front>
  <middle>
    <?line 52?>

<section anchor="introduction">
      <name>Introduction</name>
      <t>This document instructs IANA to make changes to a number of the IANA
registries related to Transport Layer Security (TLS) and Datagram
Transport Layer Security (DTLS). These changes update the changes made
in <xref target="RFC8447"/>.</t>
      <aside>
        <t>RFC EDITOR NOTE: Please remove the note that follows.</t>
      </aside>
      <aside>
        <t>NOTE for IANA: This document specifies changes to the registry to update
  the changes made in <xref target="RFC8447"/>.</t>
      </aside>
      <t>This specification adds a new value "D" for discouraged to the Recommended
column of the selected TLS registries and adds a "Comment" column to all
active registries that do not already have a "Comment" column.</t>
      <t>This specication also updates the registration request instructions.</t>
    </section>
    <section anchor="terminology">
      <name>Terminology</name>
      <t>The key words "<bcp14>MUST</bcp14>", "<bcp14>MUST NOT</bcp14>", "<bcp14>REQUIRED</bcp14>", "<bcp14>SHALL</bcp14>", "<bcp14>SHALL
NOT</bcp14>", "<bcp14>SHOULD</bcp14>", "<bcp14>SHOULD NOT</bcp14>", "<bcp14>RECOMMENDED</bcp14>", "<bcp14>NOT RECOMMENDED</bcp14>",
"<bcp14>MAY</bcp14>", and "<bcp14>OPTIONAL</bcp14>" in this document are to be interpreted as
described in BCP 14 <xref target="RFC2119"/> <xref target="RFC8174"/> when, and only when, they
appear in all capitals, as shown here.</t>
      <?line -18?>

</section>
    <section anchor="updating-recommended-columns-values">
      <name>Updating "Recommended" Column's Values</name>
      <t>The instructions in this document update the Recommended column,
originally added in <xref target="RFC8447"/> to add a third value, "D",
indicating that a value is "Discouraged". The permitted values
of the "Recommended" column are:</t>
      <dl>
        <dt>Y:</dt>
        <dd>
          <t>Indicates that the IETF has consensus that the
  item is <bcp14>RECOMMENDED</bcp14>. This only means that the associated
  mechanism is fit for the purpose for which it was defined.
  Careful reading of the documentation for the mechanism is
  necessary to understand the applicability of that mechanism.
  The IETF could recommend mechanisms that have limited
  applicability, but will provide applicability statements that
  describe any limitations of the mechanism or necessary constraints
  on its use.</t>
        </dd>
        <dt>N:</dt>
        <dd>
          <t>Indicates that the item has not been evaluated by
  the IETF and that the IETF has made no statement about the
  suitability of the associated mechanism. This does not necessarily
  mean that the mechanism is flawed, only that no consensus exists.
  The IETF might have consensus to leave an items marked as "N" on
  the basis of its having limited applicability or usage constraints.</t>
        </dd>
        <dt>D:</dt>
        <dd>
          <t>Indicates that the item is discouraged. This marking could be used to identify
  mechanisms that might result in problems if they are used, such as
  a weak cryptographic algorithm or a mechanism that might cause
  interoperability problems in deployment. When marking a registry entry as
  “D”, either the References or the Comments Column <bcp14>MUST</bcp14> include sufficient
  information to determine why the marking has been applied. Implementers and
  users <bcp14>SHOULD</bcp14> consult the linked references associated with the item to
  determine the conditions under which the item <bcp14>SHOULD NOT</bcp14> or <bcp14>MUST NOT</bcp14> be used.</t>
        </dd>
      </dl>
      <t>Setting a value to "Y" or "D" or transitioning the value from "Y" or "D" in the "Recommended" column requires
IETF Standards Action with Expert Review or IESG Approval <xref target="RFC8126"/>. Not all items defined
in Standards Track RFCs need to be set
to "Y" or "D". Any item not otherwise specified is set to "N". The column is
blank for values that are unassigned or reserved unless specifically set.</t>
      <section anchor="rec-note">
        <name>Recommended Note</name>
        <t>Existing registries have a note on the meaning of the Recommended column. For the
registries discussed in the subsequent sections this note is updated
with a sentence describing the "D" value as follows:</t>
        <dl>
          <dt>Note:</dt>
          <dd>
            <t>If "Recommended" column is set to "N", it does not necessarily mean
that it is flawed; rather, it indicates that the item either has not
been through the IETF consensus process, has limited applicability, or
is intended only for specific use cases.  If the "Recommended" column
is set to "D" the item is discouraged and <bcp14>SHOULD NOT</bcp14> or <bcp14>MUST NOT</bcp14> be used,
depending upon the situation; consult the item’s references for clarity.</t>
          </dd>
        </dl>
      </section>
    </section>
    <section anchor="tls-extensiontype-values-registry">
      <name>TLS ExtensionType Values Registry</name>
      <t>In order to reflect the changes in the Recommended column allocation,
IANA is requested to update the TLS ExtensionType Values registry as follows:</t>
      <ul spacing="normal">
        <li>
          <t>Adjust the registration procedure related to setting the “Recommended” column as follows:</t>
        </li>
      </ul>
      <artwork><![CDATA[
    Setting a value to "Y" or "D" or transitioning the value from
    "Y" or "D" in the "Recommended" column requires
    IETF Standards Action or IESG Approval [RFC8126].
]]></artwork>
      <ul spacing="normal">
        <li>
          <t>Add a reference to this document under the reference heading.</t>
        </li>
        <li>
          <t>Update the "Recommended" column with the changes as listed below.  Entries
keep their existing "Y" and "N" entries except for the entries in following table.
IANA is requested to add a reference to this document for these entries.</t>
        </li>
      </ul>
      <table>
        <thead>
          <tr>
            <th align="left">Value</th>
            <th align="left">Extension</th>
            <th align="right">Recommended</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">4</td>
            <td align="left">truncated_hmac</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">53</td>
            <td align="left">connection_id (deprecated)</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">40</td>
            <td align="left">Reserved</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">46</td>
            <td align="left">Reserved</td>
            <td align="right">D</td>
          </tr>
        </tbody>
      </table>
      <ul spacing="normal">
        <li>
          <t>Update note on the Recommended column with text in <xref target="rec-note"/>.</t>
        </li>
        <li>
          <t>For the truncated_hmac, add the following link to Reference column:
https://www.iacr.org/archive/asiacrypt2011/70730368/70730368.pdf</t>
        </li>
        <li>
          <t>For the two Reserved values above, add the following link in the Reference column:
https://mailarchive.ietf.org/arch/msg/tls-reg-review/5BD62HBFjo_AsW-Y8ohVuWEe1gI/</t>
        </li>
      </ul>
    </section>
    <section anchor="tls-cipher-suites-registry">
      <name>TLS Cipher Suites Registry</name>
      <t>Several categories of ciphersuites are discouraged for general use and
are marked as "D".</t>
      <t>Ciphersuites that use NULL encryption do not provide the confidentiality
normally expected of TLS. Protocols and applications are often designed
to require confidentiality as a security property. These
ciphersuites <bcp14>MUST NOT</bcp14> be used in those cases.</t>
      <t>Ciphersuites marked as EXPORT use weak ciphers and were deprecated in
TLS 1.1 <xref target="RFC4346"/>.</t>
      <t>Cipher suites marked as anon do not provide any authentication and are
vulnerable to on-path attacks and are deprecated in TLS 1.1
<xref target="RFC4346"/>.</t>
      <t>RC4 is a weak cipher and is deprecated in <xref target="RFC7465"/>.</t>
      <t>DES and IDEA are not considered secure for general use and are deprecated
in <xref target="RFC5469"/>. Nor is MD5 or SHA-1 and these are deprecated in <xref target="RFC9155"/>.</t>
      <t>In order to reflect the changes in the Recommended column allocation,
IANA is requested to update the TLS ExtensionType Values registry as follows:</t>
      <ul spacing="normal">
        <li>
          <t>Adjust the registration procedure related to setting the “Recommended” column as follows:</t>
        </li>
      </ul>
      <artwork><![CDATA[
    Setting a value to "Y" or "D" or transitioning the value from
    "Y" or "D" in the "Recommended" column requires
    IETF Standards Action or IESG Approval [RFC8126].
]]></artwork>
      <ul spacing="normal">
        <li>
          <t>Add a reference to this document under the reference heading.</t>
        </li>
        <li>
          <t>Update the "Recommended" column with the changes as listed below.  Entries
keep their existing "Y" and "N" entries except for the entries in following table.
IANA is requested to add a reference to this document for these entries. This document does not
make any changes to the DTLS-OK column.</t>
        </li>
      </ul>
      <table>
        <thead>
          <tr>
            <th align="left">Value</th>
            <th align="left">Cipher Suite Name</th>
            <th align="right">Recommended</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">0x00,0x1E</td>
            <td align="left">TLS_KRB5_WITH_DES_CBC_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x20</td>
            <td align="left">TLS_KRB5_WITH_RC4_128_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x21</td>
            <td align="left">TLS_KRB5_WITH_IDEA_CBC_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x22</td>
            <td align="left">TLS_KRB5_WITH_DES_CBC_MD5</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x24</td>
            <td align="left">TLS_KRB5_WITH_RC4_128_MD5</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x25</td>
            <td align="left">TLS_KRB5_WITH_IDEA_CBC_MD5</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x26</td>
            <td align="left">TLS_KRB5_EXPORT_WITH_DES_CBC_40_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x27</td>
            <td align="left">TLS_KRB5_EXPORT_WITH_RC2_CBC_40_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x28</td>
            <td align="left">TLS_KRB5_EXPORT_WITH_RC4_40_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x29</td>
            <td align="left">TLS_KRB5_EXPORT_WITH_DES_CBC_40_MD5</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x2A</td>
            <td align="left">TLS_KRB5_EXPORT_WITH_RC2_CBC_40_MD5</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x2B</td>
            <td align="left">TLS_KRB5_EXPORT_WITH_RC4_40_MD5</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x2C</td>
            <td align="left">TLS_PSK_WITH_NULL_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0x8A</td>
            <td align="left">TLS_PSK_WITH_RC4_128_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0xB0</td>
            <td align="left">TLS_PSK_WITH_NULL_SHA256</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0x00,0xB1</td>
            <td align="left">TLS_PSK_WITH_NULL_SHA384</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0xC0,0x06</td>
            <td align="left">TLS_ECDHE_ECDSA_WITH_NULL_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0xC0,0x07</td>
            <td align="left">TLS_ECDHE_ECDSA_WITH_RC4_128_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0xC0,0x10</td>
            <td align="left">TLS_ECDHE_RSA_WITH_NULL_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0xC0,0x11</td>
            <td align="left">TLS_ECDHE_RSA_WITH_RC4_128_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0xC0,0x33</td>
            <td align="left">TLS_ECDHE_PSK_WITH_RC4_128_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0xC0,0x39</td>
            <td align="left">TLS_ECDHE_PSK_WITH_NULL_SHA</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0xC0,0x3A</td>
            <td align="left">TLS_ECDHE_PSK_WITH_NULL_SHA256</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0xC0,0x3B</td>
            <td align="left">TLS_ECDHE_PSK_WITH_NULL_SHA384</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0xC0,0xB4</td>
            <td align="left">TLS_SHA256_SHA256</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">0xC0,0xB5</td>
            <td align="left">TLS_SHA384_SHA384</td>
            <td align="right">D</td>
          </tr>
        </tbody>
      </table>
      <ul spacing="normal">
        <li>
          <t>Update note on the Recommended column with text in <xref target="rec-note"/>.</t>
        </li>
      </ul>
    </section>
    <section anchor="tls-supported-groups-registry">
      <name>TLS Supported Groups Registry</name>
      <t>In order to reflect the changes in the Recommended column allocation,
IANA is requested to update the TLS Supported Groups registry as follows:</t>
      <ul spacing="normal">
        <li>
          <t>Update the registration policy to include:</t>
        </li>
      </ul>
      <artwork><![CDATA[
    Setting a value to "Y" or "D" or transitioning the value from
    "Y" or "D" in the "Recommended" column requires
    IETF Standards Action or IESG Approval [RFC8126].
]]></artwork>
      <ul spacing="normal">
        <li>
          <t>Add a reference to this document under the reference heading.</t>
        </li>
        <li>
          <t>Update the "Recommended" column with the changes as listed below.  Entries
keep their existing "Y" and "N" entries except for the entries in following table.
IANA is requested to add a reference to this document for these entries.</t>
        </li>
      </ul>
      <table>
        <thead>
          <tr>
            <th align="left">Value</th>
            <th align="left">Curve</th>
            <th align="right">Recommended</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">1</td>
            <td align="left">sect163k1</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">2</td>
            <td align="left">sect163r1</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">3</td>
            <td align="left">sect163r2</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">4</td>
            <td align="left">sect193r1</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">5</td>
            <td align="left">sect193r2</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">6</td>
            <td align="left">sect233k1</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">7</td>
            <td align="left">sect233r1</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">8</td>
            <td align="left">sect239k1</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">15</td>
            <td align="left">secp160k1</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">16</td>
            <td align="left">secp160r1</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">17</td>
            <td align="left">secp160r2</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">18</td>
            <td align="left">secp192k1</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">19</td>
            <td align="left">secp192r1</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">20</td>
            <td align="left">secp224k1</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">21</td>
            <td align="left">secp224r1</td>
            <td align="right">D</td>
          </tr>
        </tbody>
      </table>
      <ul spacing="normal">
        <li>
          <t>Update note on the Recommended column with text in <xref target="rec-note"/>.</t>
        </li>
        <li>
          <t>Remove the "Elliptic curve groups" note from the registration
procedures table.</t>
        </li>
        <li>
          <t>For each of the entries above, add the following link to the
Comment column:
https://datatracker.ietf.org/meeting/118/materials/slides-118-tls-rfc8447bis-00</t>
        </li>
      </ul>
    </section>
    <section anchor="tls-exporter-labels-registry">
      <name>TLS Exporter Labels Registry</name>
      <t>This document updates the registration procedure for the TLS Exporter
Labels registry and updates the Recommended column allocation.
IANA is requested to update the TLS Exporter Labels Registry as follows:</t>
      <ul spacing="normal">
        <li>
          <t>Change the registration procedure from Specification Required to
Expert Review and update it to include:</t>
        </li>
      </ul>
      <artwork><![CDATA[
    Setting a value to "Y" or "D" or transitioning the value from
    "Y" or "D" in the "Recommended" column requires
    IETF Standards Action or IESG Approval [RFC8126].
]]></artwork>
      <ul spacing="normal">
        <li>
          <t>Add a reference to this document under the reference heading.</t>
        </li>
        <li>
          <t>Entries keep their existing Recommended column "Y" and "N" entries</t>
        </li>
        <li>
          <t>Update note on the Recommended column with text in <xref target="rec-note"/>.</t>
        </li>
        <li>
          <t>Update the note on the role of the expert reviewer as follows.</t>
        </li>
      </ul>
      <dl>
        <dt>Note:</dt>
        <dd>
          <t>The role of the designated expert is described in <xref section="17" sectionFormat="comma" target="RFC8447"/>.
Even though this registry does not require a specification, the
designated expert <xref target="RFC8126"/> will strongly encourage registrants
to provide a link to a publicly available specification. An
Internet-Draft (that is posted and never published as an RFC)
or a document from another standards body, industry consortium,
university site, etc. are suitable for these purposes.
The expert may provide more in-depth reviews, but their approval
should not be taken as an endorsement of the exporter label.  The
expert also verifies that the label is a string consisting of
printable ASCII characters beginning with "EXPORTER".  IANA <bcp14>MUST</bcp14>
also verify that one label is not a prefix of any other label.
For example, labels "key" or "master secretary" are forbidden.</t>
        </dd>
      </dl>
    </section>
    <section anchor="tls-certificate-types-registry">
      <name>TLS Certificate Types Registry</name>
      <t>In order to reflect the changes in the Recommended column allocation,
IANA is requested to update the TLS Certificate Types registry as follows:</t>
      <ul spacing="normal">
        <li>
          <t>Adjust the registration procedure related to setting the “Recommended” column as follows:</t>
        </li>
      </ul>
      <artwork><![CDATA[
    Setting a value to "Y" or "D" or transitioning the value from
    "Y" or "D" in the "Recommended" column requires
    IETF Standards Action or IESG Approval [RFC8126].
]]></artwork>
      <ul spacing="normal">
        <li>
          <t>Add a reference to this document under the reference heading.</t>
        </li>
        <li>
          <t>Entries keep their existing Recommended column "Y" and "N" entries.</t>
        </li>
        <li>
          <t>Update note on the Recommended column with text in <xref target="rec-note"/>.</t>
        </li>
      </ul>
    </section>
    <section anchor="tls-hashalgorithm-registry">
      <name>TLS HashAlgorithm Registry</name>
      <t>Though TLS 1.0 and TLS 1.1 were deprecated <xref target="RFC8996"/>, TLS 1.2 will
be in use for some time. In order to reflect the changes in the Recommended
column allocation, IANA is requested to update the TLS HashAlgorithm Registry
as follows:</t>
      <ul spacing="normal">
        <li>
          <t>Update the registration procedure to include:</t>
        </li>
      </ul>
      <artwork><![CDATA[
    Setting a value to "Y" or "D" or transitioning the value from
    "Y" or "D"  in the "Recommended" column requires
    IETF Standards Action or IESG Approval [RFC8126].
]]></artwork>
      <ul spacing="normal">
        <li>
          <t>Add a reference to this document under the reference heading.</t>
        </li>
        <li>
          <t>Update the TLS HashAlgorithm registry to add a "Recommended" column
as follows:</t>
        </li>
      </ul>
      <table>
        <thead>
          <tr>
            <th align="left">Value</th>
            <th align="left">Description</th>
            <th align="right">Recommended</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">0</td>
            <td align="left">none</td>
            <td align="right">Y</td>
          </tr>
          <tr>
            <td align="left">1</td>
            <td align="left">md5</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">2</td>
            <td align="left">sha1</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">3</td>
            <td align="left">sha224</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">4</td>
            <td align="left">sha256</td>
            <td align="right">Y</td>
          </tr>
          <tr>
            <td align="left">5</td>
            <td align="left">sha384</td>
            <td align="right">Y</td>
          </tr>
          <tr>
            <td align="left">6</td>
            <td align="left">sha512</td>
            <td align="right">Y</td>
          </tr>
          <tr>
            <td align="left">8</td>
            <td align="left">Intrinsic</td>
            <td align="right">Y</td>
          </tr>
        </tbody>
      </table>
      <ul spacing="normal">
        <li>
          <t>Add note on the Recommended column with text in <xref target="rec-note"/>.</t>
        </li>
      </ul>
    </section>
    <section anchor="tls-signaturealgorithm-registry">
      <name>TLS SignatureAlgorithm Registry</name>
      <t>Though TLS 1.0 and TLS 1.1 were deprecated <xref target="RFC8996"/>, TLS 1.2 will
be in use for some time. In order to reflect the changes in the Recommended
column allocation, IANA is requested to update the TLS SignatureAlgorithm registry
as follows:</t>
      <ul spacing="normal">
        <li>
          <t>Update the registration procedure to include:</t>
        </li>
      </ul>
      <artwork><![CDATA[
    Setting a value to "Y" or "D" or transitioning the value from
    "Y" or "D"  in the "Recommended" column requires
    IETF Standards Action or IESG Approval [RFC8126].
]]></artwork>
      <ul spacing="normal">
        <li>
          <t>Add a reference to this document under the reference heading.</t>
        </li>
        <li>
          <t>Update the TLS SignatureAlgorithm registry to add a "Recommended"
column as follows:</t>
        </li>
      </ul>
      <table>
        <thead>
          <tr>
            <th align="left">Value</th>
            <th align="left">Description</th>
            <th align="right">Recommended</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">0</td>
            <td align="left">anonymous</td>
            <td align="right">N</td>
          </tr>
          <tr>
            <td align="left">1</td>
            <td align="left">rsa</td>
            <td align="right">Y</td>
          </tr>
          <tr>
            <td align="left">2</td>
            <td align="left">dsa</td>
            <td align="right">N</td>
          </tr>
          <tr>
            <td align="left">3</td>
            <td align="left">ecdsa</td>
            <td align="right">Y</td>
          </tr>
          <tr>
            <td align="left">7</td>
            <td align="left">ed25519</td>
            <td align="right">Y</td>
          </tr>
          <tr>
            <td align="left">8</td>
            <td align="left">ed448</td>
            <td align="right">Y</td>
          </tr>
          <tr>
            <td align="left">64</td>
            <td align="left">gostr34102012_256</td>
            <td align="right">N</td>
          </tr>
          <tr>
            <td align="left">65</td>
            <td align="left">gostr34102012_512</td>
            <td align="right">N</td>
          </tr>
        </tbody>
      </table>
      <ul spacing="normal">
        <li>
          <t>Add note on the Recommended column with text in <xref target="rec-note"/>.</t>
        </li>
      </ul>
    </section>
    <section anchor="tls-clientcertificatetype-identifiers-registry">
      <name>TLS ClientCertificateType Identifiers Registry</name>
      <t>Though TLS 1.0 and TLS 1.1 were deprecated <xref target="RFC8996"/>, TLS 1.2 will
be in use for some time. In order to refect the changes in the Recommended
column allocation, IANA is requested to update the TLS ClientCertificateType Identifiers
registry as follows:</t>
      <ul spacing="normal">
        <li>
          <t>Update the registration procedure to include:</t>
        </li>
      </ul>
      <artwork><![CDATA[
    Setting a value to "Y" or "D" or transitioning the value from
    "Y" or "D"  in the "Recommended" column requires
    IETF Standards Action or IESG Approval [RFC8126].
]]></artwork>
      <ul spacing="normal">
        <li>
          <t>Add a reference to this document under the reference heading.</t>
        </li>
        <li>
          <t>Update the TLS ClientCertificateType Identifiers registry to add a "Recommended"
column as follows:</t>
        </li>
      </ul>
      <table>
        <thead>
          <tr>
            <th align="left">Value</th>
            <th align="left">Description</th>
            <th align="right">Recommended</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">1</td>
            <td align="left">rsa_sign</td>
            <td align="right">Y</td>
          </tr>
          <tr>
            <td align="left">2</td>
            <td align="left">dss_sign</td>
            <td align="right">N</td>
          </tr>
          <tr>
            <td align="left">3</td>
            <td align="left">rsa_fixed_dh</td>
            <td align="right">N</td>
          </tr>
          <tr>
            <td align="left">4</td>
            <td align="left">dss_fixed_dh</td>
            <td align="right">N</td>
          </tr>
          <tr>
            <td align="left">5</td>
            <td align="left">rsa_ephemeral_dh_RESERVED</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">6</td>
            <td align="left">dss_ephemeral_dh_RESERVED</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">20</td>
            <td align="left">fortezza_dms_RESERVED</td>
            <td align="right">D</td>
          </tr>
          <tr>
            <td align="left">64</td>
            <td align="left">ecdsa_sign</td>
            <td align="right">Y</td>
          </tr>
          <tr>
            <td align="left">65</td>
            <td align="left">rsa_fixed_ecdh</td>
            <td align="right">N</td>
          </tr>
          <tr>
            <td align="left">66</td>
            <td align="left">ecdsa_fixed_ecdh</td>
            <td align="right">N</td>
          </tr>
          <tr>
            <td align="left">67</td>
            <td align="left">gost_sign256</td>
            <td align="right">N</td>
          </tr>
          <tr>
            <td align="left">68</td>
            <td align="left">gost_sign512</td>
            <td align="right">N</td>
          </tr>
        </tbody>
      </table>
      <ul spacing="normal">
        <li>
          <t>Add note on the Recommended column with text in <xref target="rec-note"/>.</t>
        </li>
      </ul>
    </section>
    <section anchor="tls-pskkeyexchangemode-registry">
      <name>TLS PskKeyExchangeMode Registry</name>
      <t>In order to reflect the changes in the Recommended column allocation,
IANA is requested to update the TLS PskKeyExchangeMode registry as follows:</t>
      <ul spacing="normal">
        <li>
          <t>Update the registration procedure to include:</t>
        </li>
      </ul>
      <artwork><![CDATA[
    Setting a value to "Y" or "D" or transitioning the value from
    "Y" or "D"  in the "Recommended" column requires
    IETF Standards Action or IESG Approval [RFC8126].
]]></artwork>
      <ul spacing="normal">
        <li>
          <t>Add a reference to this document under the reference heading.</t>
        </li>
        <li>
          <t>Entries keep their existing Recommended column "Y" and "N" entries.</t>
        </li>
        <li>
          <t>Update note on the Recommended column with text in <xref target="rec-note"/>.</t>
        </li>
      </ul>
    </section>
    <section anchor="tls-signaturescheme-registry">
      <name>TLS SignatureScheme Registry</name>
      <t>In order to reflect the changes in the Recommended column allocation,
IANA is requested to update the TLS SignatureScheme registry as follows:</t>
      <ul spacing="normal">
        <li>
          <t>Update the registration procedure to include:</t>
        </li>
      </ul>
      <artwork><![CDATA[
    Setting a value to "Y" or "D" or transitioning the value from
    "Y" or "D"  in the "Recommended" column requires
    IETF Standards Action or IESG Approval [RFC8126].
]]></artwork>
      <ul spacing="normal">
        <li>
          <t>IANA is requested to add a reference to this document under the reference heading.</t>
        </li>
        <li>
          <t>Entries keep their existing Recommended column "Y" and "N" entries.</t>
        </li>
        <li>
          <t>Update note on the Recommended column with text in <xref target="rec-note"/>.</t>
        </li>
      </ul>
    </section>
    <section anchor="adding-comment-column">
      <name>Adding "Comment" Column</name>
      <t>IANA is requested to add a "Comment" column to the following registries:</t>
      <ul spacing="normal">
        <li>
          <t>TLS ExtensionType Values</t>
        </li>
        <li>
          <t>TLS Application-Layer Protocol Negotiation (ALPN) Protocol IDs</t>
        </li>
        <li>
          <t>TLS CachedInformationType Values</t>
        </li>
        <li>
          <t>TLS Certificate Compression Algorithm IDs</t>
        </li>
        <li>
          <t>TLS Cipher Suites</t>
        </li>
        <li>
          <t>TLS ContentType</t>
        </li>
        <li>
          <t>TLS EC Point Formats</t>
        </li>
        <li>
          <t>TLS EC Curve Types</t>
        </li>
        <li>
          <t>TLS Supplemental Data Formats (SupplementalDataType)</t>
        </li>
        <li>
          <t>TLS UserMappingType Values</t>
        </li>
        <li>
          <t>TLS Authorization Data Formats</t>
        </li>
        <li>
          <t>TLS Heartbeat Message Types</t>
        </li>
        <li>
          <t>TLS Heartbeat Modes</t>
        </li>
        <li>
          <t>TLS SignatureScheme</t>
        </li>
        <li>
          <t>TLS PskKeyExchangeMode</t>
        </li>
        <li>
          <t>TLS KDF Identifiers</t>
        </li>
      </ul>
      <t>This list of registries is all registries that do not already have a
"Comment" or "Notes" column or that were not orphaned by TLS 1.3.</t>
    </section>
    <section anchor="expert-review-of-current-and-potential-ietf-and-irtf-documents">
      <name>Expert Review of Current and Potential IETF and IRTF Documents</name>
      <t>The intent of the Specification Required choice for TLS code points
is to allow for easy registration for code points associated with
protocols and algorithms that are not being actively developed inside
IETF or IRTF. When TLS-based technologies are being developed inside
the IRTF/IETF they should be done in coordination with the TLS WG in
order to provide appropriate review. For this reason, unless the TLS WG
chairs indicate otherwise via email, designated
experts should decline code point registrations for documents which
have already been adopted or are being proposed for adoption by IETF
working groups or IRTF research groups.</t>
    </section>
    <section anchor="registration-requests">
      <name>Registration Requests</name>
      <t>Registration requests <bcp14>MUST</bcp14> be submitted in one of two ways:</t>
      <ol spacing="normal" type="1"><li>
          <t>By sending email to iana@iana.org; this email <bcp14>SHOULD</bcp14>
use an appropriate subject (e.g., "Request to register value in TLS
bar registry").</t>
        </li>
        <li>
          <t>Using the online form at
https://www.iana.org/form/protocol-assignment.</t>
        </li>
      </ol>
      <t>Specification Required <xref target="RFC8126"/> registry requests are registered after
a three-week review period on the advice of one or more designated
experts. However, to allow for the allocation of values prior to
publication, the designated experts may approve registration once they
are satisfied that such a specification will be published.</t>
    </section>
    <section anchor="security-considerations">
      <name>Security Considerations</name>
      <t>The change to Specification Required from IETF Review lowers the amount
of review provided for cipher suites and supported groups.
This change reflects reality in that the TLS WG essentially provided no
cryptographic review of the cipher suites or supported groups.  This
was especially true of national cipher suites.</t>
      <t>Recommended algorithms are regarded as secure for general use at the
time of registration; however, cryptographic algorithms and parameters
will be broken or weakened over time.  It is possible that the
"Recommended" status in the registry lags behind the most recent advances
in cryptanalysis.  Implementers and users need to check that the
cryptographic algorithms listed continue to provide the expected level
of security.</t>
      <t>Designated experts ensure the specification is publicly available.  They may
provide more in-depth reviews.  Their review should not be taken as an
endorsement of the cipher suite, extension, supported group, etc.</t>
    </section>
    <section anchor="iana-considerations">
      <name>IANA Considerations</name>
      <t>This document is entirely about changes to TLS-related IANA registries.</t>
      <t>IANA is requested to modify the note applied to all TLS Specification
Required registries instructing where to send registration requests as
follows:</t>
      <aside>
        <t>RFC EDITOR: Please replace "This RFC" in the following with the RFC number
  assigned to this specification.</t>
      </aside>
      <t>Requests for assignments from the registry's Specification Required
range should be sent to the mailing list described in [This RFC, Section 16].
If approved, designated experts should notify IANA within three weeks. For
assistance, please contact iana@iana.org.</t>
    </section>
  </middle>
  <back>
    <references anchor="sec-normative-references">
      <name>Normative References</name>
      <reference anchor="RFC8447">
        <front>
          <title>IANA Registry Updates for TLS and DTLS</title>
          <author fullname="J. Salowey" initials="J." surname="Salowey"/>
          <author fullname="S. Turner" initials="S." surname="Turner"/>
          <date month="August" year="2018"/>
          <abstract>
            <t>This document describes a number of changes to TLS and DTLS IANA registries that range from adding notes to the registry all the way to changing the registration policy. These changes were mostly motivated by WG review of the TLS- and DTLS-related registries undertaken as part of the TLS 1.3 development process.</t>
            <t>This document updates the following RFCs: 3749, 5077, 4680, 5246, 5705, 5878, 6520, and 7301.</t>
          </abstract>
        </front>
        <seriesInfo name="RFC" value="8447"/>
        <seriesInfo name="DOI" value="10.17487/RFC8447"/>
      </reference>
      <reference anchor="RFC2119">
        <front>
          <title>Key words for use in RFCs to Indicate Requirement Levels</title>
          <author fullname="S. Bradner" initials="S." surname="Bradner"/>
          <date month="March" year="1997"/>
          <abstract>
            <t>In many standards track documents several words are used to signify the requirements in the specification. These words are often capitalized. This document defines these words as they should be interpreted in IETF documents. This document specifies an Internet Best Current Practices for the Internet Community, and requests discussion and suggestions for improvements.</t>
          </abstract>
        </front>
        <seriesInfo name="BCP" value="14"/>
        <seriesInfo name="RFC" value="2119"/>
        <seriesInfo name="DOI" value="10.17487/RFC2119"/>
      </reference>
      <reference anchor="RFC8174">
        <front>
          <title>Ambiguity of Uppercase vs Lowercase in RFC 2119 Key Words</title>
          <author fullname="B. Leiba" initials="B." surname="Leiba"/>
          <date month="May" year="2017"/>
          <abstract>
            <t>RFC 2119 specifies common key words that may be used in protocol specifications. This document aims to reduce the ambiguity by clarifying that only UPPERCASE usage of the key words have the defined special meanings.</t>
          </abstract>
        </front>
        <seriesInfo name="BCP" value="14"/>
        <seriesInfo name="RFC" value="8174"/>
        <seriesInfo name="DOI" value="10.17487/RFC8174"/>
      </reference>
      <reference anchor="RFC8126">
        <front>
          <title>Guidelines for Writing an IANA Considerations Section in RFCs</title>
          <author fullname="M. Cotton" initials="M." surname="Cotton"/>
          <author fullname="B. Leiba" initials="B." surname="Leiba"/>
          <author fullname="T. Narten" initials="T." surname="Narten"/>
          <date month="June" year="2017"/>
          <abstract>
            <t>Many protocols make use of points of extensibility that use constants to identify various protocol parameters. To ensure that the values in these fields do not have conflicting uses and to promote interoperability, their allocations are often coordinated by a central record keeper. For IETF protocols, that role is filled by the Internet Assigned Numbers Authority (IANA).</t>
            <t>To make assignments in a given registry prudently, guidance describing the conditions under which new values should be assigned, as well as when and how modifications to existing values can be made, is needed. This document defines a framework for the documentation of these guidelines by specification authors, in order to assure that the provided guidance for the IANA Considerations is clear and addresses the various issues that are likely in the operation of a registry.</t>
            <t>This is the third edition of this document; it obsoletes RFC 5226.</t>
          </abstract>
        </front>
        <seriesInfo name="BCP" value="26"/>
        <seriesInfo name="RFC" value="8126"/>
        <seriesInfo name="DOI" value="10.17487/RFC8126"/>
      </reference>
      <reference anchor="RFC4346">
        <front>
          <title>The Transport Layer Security (TLS) Protocol Version 1.1</title>
          <author fullname="T. Dierks" initials="T." surname="Dierks"/>
          <author fullname="E. Rescorla" initials="E." surname="Rescorla"/>
          <date month="April" year="2006"/>
          <abstract>
            <t>This document specifies Version 1.1 of the Transport Layer Security (TLS) protocol. The TLS protocol provides communications security over the Internet. The protocol allows client/server applications to communicate in a way that is designed to prevent eavesdropping, tampering, or message forgery.</t>
          </abstract>
        </front>
        <seriesInfo name="RFC" value="4346"/>
        <seriesInfo name="DOI" value="10.17487/RFC4346"/>
      </reference>
      <reference anchor="RFC7465">
        <front>
          <title>Prohibiting RC4 Cipher Suites</title>
          <author fullname="A. Popov" initials="A." surname="Popov"/>
          <date month="February" year="2015"/>
          <abstract>
            <t>This document requires that Transport Layer Security (TLS) clients and servers never negotiate the use of RC4 cipher suites when they establish connections. This applies to all TLS versions. This document updates RFCs 5246, 4346, and 2246.</t>
          </abstract>
        </front>
        <seriesInfo name="RFC" value="7465"/>
        <seriesInfo name="DOI" value="10.17487/RFC7465"/>
      </reference>
      <reference anchor="RFC5469">
        <front>
          <title>DES and IDEA Cipher Suites for Transport Layer Security (TLS)</title>
          <author fullname="P. Eronen" initials="P." role="editor" surname="Eronen"/>
          <date month="February" year="2009"/>
          <abstract>
            <t>Transport Layer Security (TLS) versions 1.0 (RFC 2246) and 1.1 (RFC 4346) include cipher suites based on DES (Data Encryption Standard) and IDEA (International Data Encryption Algorithm) algorithms. DES (when used in single-DES mode) and IDEA are no longer recommended for general use in TLS, and have been removed from TLS version 1.2 (RFC 5246). This document specifies these cipher suites for completeness and discusses reasons why their use is no longer recommended. This memo provides information for the Internet community.</t>
          </abstract>
        </front>
        <seriesInfo name="RFC" value="5469"/>
        <seriesInfo name="DOI" value="10.17487/RFC5469"/>
      </reference>
      <reference anchor="RFC9155">
        <front>
          <title>Deprecating MD5 and SHA-1 Signature Hashes in TLS 1.2 and DTLS 1.2</title>
          <author fullname="L. Velvindron" initials="L." surname="Velvindron"/>
          <author fullname="K. Moriarty" initials="K." surname="Moriarty"/>
          <author fullname="A. Ghedini" initials="A." surname="Ghedini"/>
          <date month="December" year="2021"/>
          <abstract>
            <t>The MD5 and SHA-1 hashing algorithms are increasingly vulnerable to attack, and this document deprecates their use in TLS 1.2 and DTLS 1.2 digital signatures. However, this document does not deprecate SHA-1 with Hashed Message Authentication Code (HMAC), as used in record protection. This document updates RFC 5246.</t>
          </abstract>
        </front>
        <seriesInfo name="RFC" value="9155"/>
        <seriesInfo name="DOI" value="10.17487/RFC9155"/>
      </reference>
      <reference anchor="RFC8996">
        <front>
          <title>Deprecating TLS 1.0 and TLS 1.1</title>
          <author fullname="K. Moriarty" initials="K." surname="Moriarty"/>
          <author fullname="S. Farrell" initials="S." surname="Farrell"/>
          <date month="March" year="2021"/>
          <abstract>
            <t>This document formally deprecates Transport Layer Security (TLS) versions 1.0 (RFC 2246) and 1.1 (RFC 4346). Accordingly, those documents have been moved to Historic status. These versions lack support for current and recommended cryptographic algorithms and mechanisms, and various government and industry profiles of applications using TLS now mandate avoiding these old TLS versions. TLS version 1.2 became the recommended version for IETF protocols in 2008 (subsequently being obsoleted by TLS version 1.3 in 2018), providing sufficient time to transition away from older versions. Removing support for older versions from implementations reduces the attack surface, reduces opportunity for misconfiguration, and streamlines library and product maintenance.</t>
            <t>This document also deprecates Datagram TLS (DTLS) version 1.0 (RFC 4347) but not DTLS version 1.2, and there is no DTLS version 1.1.</t>
            <t>This document updates many RFCs that normatively refer to TLS version 1.0 or TLS version 1.1, as described herein. This document also updates the best practices for TLS usage in RFC 7525; hence, it is part of BCP 195.</t>
          </abstract>
        </front>
        <seriesInfo name="BCP" value="195"/>
        <seriesInfo name="RFC" value="8996"/>
        <seriesInfo name="DOI" value="10.17487/RFC8996"/>
      </reference>
    </references>
  </back>
  <!-- ##markdown-source:
H4sIAAAAAAAAA+087XIbN5L/8RQ45sfaVyIlUpQsKblsZJGOtbFlnyTH50ql
VOAMSE40nJkFZkQzkVN5jau6q7pnuUfJk1x/YGYw/JCUPW+lsmtXYksYoIH+
7kYDaLfbIo/yWB/J0+OzY3muJ5HNzUK+yUKVayvHqZGXLy6kSkI5gB+EGo2M
vjmSjwaPsX3tKBGmQaJmADQ0apy3I52P23ls22YcHPT7T0aRbXf7whajWWRt
lCb5IsMVDC+fiQAATFKzOJI2D0XBAI8kDhMw7a4QUWaOZG4Km/d2dg53ekIZ
rY5k60IHhYnyRUvMU3M9MWmRQeulUYnNUpPLF2qhjax7XesFdAxh3iTXJtF5
e4CrFTc6KfSRkPJ+EFLyyltvYcYomcivcQi2z1QUQzsg/RVi30nNBJuVCabQ
PM3zzB5tb2MvbIpudKfsto0N2yOTzq3ehvHbOG4S5dNixADnk+2aji0hbA7M
uVJxmsBKFkB9O1Mmv/prkRLlklRk0ZH8Lk+DLWkBC6PHFn5azPCH74VQRT5N
DSDchomkjBIY9JeOvACIc72gNmbmX1LdaIXFqiT6UeXAwSP5rU7UOKIPmrH/
IdVfWe7fAfI2JrjoyMsCiG48+BdaJX5rE75Ndk3og7fQ/Stq7QTpTIgkNTPo
ewO8E1Ey9n5rt9tSjUBCVZALcTmNrAQJLWY6yaWTMJlPtQymKpngz2lD5lnI
DQt5BASeqVADGvL82QkJZkee5lKFoZVKJnoub1RcaNkatEh9wsgGaWHURIcC
IONE5xpWDNOHOpRBGhezRKZj+mJ1rIMcmnHeekpci3AztE5obN4qhwJQFccS
kAN0/UH5VOWAKYhALlQMWhIu5FRBn1UgHfksSgDKYktGDaIIB4+4AMD/Wmib
Iw9BAwNss51NJK3IwxyYRWEYayE+Q4UzacjDlweXkC1THXCbqesGa4DGxWwE
euhIhv2Eh7XRsUIKIhc3aK58BOR9zAxWuZoYNROb+6IMPAZ5nWpbL4SRbIgN
igVInvzpp38B1BHzDx8A9y+UjUBeQCmvw3Se/FtrFKfBdetLkGWk0HBwevnq
XJ69uhweydexVhZ5OEtvGDjwTjMjx2kMugTk/mKbIH55J2iER+KH5DmSTSLb
TAfRGInl0RVnM6Ulh98ZQ7RxSzhKwtFDsV4QTeOgBywyD9ELuaoX4sF6Ie/W
C3GnXsj79MLHqcQotmnDbjxERT6Tl9rMoiSN08kCgWoJDkiiB7Ky9fLNxWVr
i/9F1uHP58N/f3N6PhzgzxfPj1+8qH4QrsfF81dvXgzqn+qRJ69evhyeDXgw
tMpGk2i9PH4HX5B4rVevL09fnR2/aCFb84aYgGNFIo6Q4+AiM6ORAwr8u7aB
iUbwC4x5evL6f/+n23di3+t2Dz98KHWg+6QPv8ynOuHZ0iReuF+BcAuhskwr
g1DQggUqi3KgLvQFik9BouVUGw3U+9fvkDLfH8kvRkHW7X/pGhDhRmNJs0Yj
0Wy1ZWUwE3FN05ppKmo22pco3Vzv8bvG7yXdvcYv/hxHiZbt7sGfQZdAZCie
wrii5WlGS56QaP7Jym9RoSxLky9vq6z0zNWq89kSqYkmbP9Rm5ivnoqTKoXA
eoRqQlbkLdTkLTB4ISkGrJL0Sjk1h9lbg1rFW2RAZYZKkKMY3fDanX43EXQK
DPIH3vvdkcAYjWYplZfsPoSLoLZgwwBjndii/sZxRq5nuAqPIR22gySFMwgf
PGjK2jSI0HHQ4JlGixdZgjCOcrJY2C8rTJaCicbf59MomKK/nMMqQj0G5oUd
Gn4CSx8XsUTbgpRxWJbsYEtRgvTn4nBIB9pa5cwwkMRQjMfrzLIYKDGKYvRN
BBcwqEDw9JcleYD6cQircLSt+znMyerFEbDE4d0AvyVHBSAXgWpmJr1BV9Oc
HpYFRAaEGBxBKG0D6PuCQSuWSUeDGltAv8YUmQgmFAwN0wDoEwHYwqL6n20Q
AWIxigBa8pHWidQoVuT+RxykVpLCBFyWHfJnSVpjAoFiWtRCZAtYv09sX1I8
spcOVvNaSryieOHESSX17E3hitVch1sslNQFllOLtH4PrsUusXUWTaaOeZ7w
pxKiB/RiCRHGUlxABht8QAsmqAgyAn9NDEESAxgUUScFywJmgAWgvz5/gCGD
uxiChKgV35EG14LTsESCeABnye+DVCV5NF401c7BZESNtkWMHhXFcBQjahHx
YkEuCiFBQlOALioWHiXnWl3LwCyyPIXoLgNFBQ8DeSXkUSR4ymOCN1OgAJjL
UsDjpWCuSkrUUycg41mcLlBcOvIteLMKO1VHUPAR/nYL+vWX/xr8+st/b0kN
C9DG2eExOLcEBEU6Q+BiD+sMvCQXFyVBXICQ2mIMMVUE3936XIaTUqATgmvG
8EKDUVqwkLkloZSTahBjkR+nsywmWQe7QokFwgO84Tfn75DZSHGEAy4JhcjU
q/UUYA7o1IzPU2cByrVQ5JiCmLAFIFPmrGY1qHaxSIbSq5cSArJ2ofOcacuO
BbBtvWthZ4wkkXQYudMU7IS06zg26czvSk5xg6vBqC0COROkXxdobhVGZsfk
UBnP4XsQhxz4dhNBMIuh9fDia3mcoW1UcRXy9PYhJpZnFFvGThOdc8DsoIYN
GUdwjTkA2AzNyjDCSDcXDRQ78hgsKdEKTUuKAjSPwAWVUXyIGgfDiDJnztE6
vMCjjGKVXJOzYZfr3DQqTgKsjCawMJwKsNfmBn4ukhiMVx3GY1QA4DGI/awR
PZxhbvLTZ+Be2pimfBBiiNYKueBF2y6ypkQmTZwBVInnFlcjEkhHWSf8xA6N
SmEtRyeUFBQji9E2ZjTaRT4U9tBcUZmkhYLYp6ATyDyIcOmjSnFB4WCRUbZM
syDwQPTgHzB04/VC0yA7Jc7rHABhK4jo0KOy+J9LSBiAlTQu2mBKnblwLk6Q
HudTkxaTae3HahcAkojTbtGAtQYd/IwRkSXzRvQmt4PCUbIb1Q7soNW2IxHz
TSojPOyBfhusP7ndu1V8C9KJDEAjN4rMSQjoc0HG7fOGMcIZfv3lP61vjnDx
QawwV+9Q1Iwp4vA94Idbi5eLTLs4udqnFOIUEkuDxghWD6Awt2ykuU7A1uzT
gDaknAduCdqhiGyZ8rEKe5H2xoVUTqIhb215HP5Q2Hw1pyS+hoXR/uaGdXYR
e4N/8dYKnqZarj/Bzz//TAb6/2VRCcJvtao4Zr1lXTGj3zkj+n2H1ktUCcmx
Oo7zZkEjuSG/wlQrO0058sa9J7ctvXmZlRcr2U/aQwwdaaAdKMIw4a0/CVm7
zrBzZDg2o/QMyEHJNIRZmnvCx0Bndd5QNkeJYwhRVkFIgbHdWklS9+HtYNsK
OmB7SyImb2vBk/f8uW2I+a24PWrjH/fPPX9u/V+OYHAfAEIemqA1C6+mMxWs
m7H8M8D59nblLSh5wib8KgrlI7AI4FUQxOO1Q/o78va89Fcb8WoO2f+tQ2rJ
8X3XGpvA8qPf55w2V/7wA0mf82SySZUtYi+21+KAoRZyuYoM3QRHoiwYzOfz
TqQCUxUKohuNm2+KQt3eTre7/WTnye7O7v5B9UMnC8eNdcxxBkcIFxJA0nOj
Ny6psoablrW5jjGzk22q/OgJ/I+B0/be08F+7/nTZz+kV8f2bfvdQTr9tng7
1N3J6XZlv0+iDB3fBaRfDcN9oW8gJMetIioToUZBEBFQb8udMbLxPRBqyUQn
NAx9G22lG+1nRxBkCXHiAyE3jL3P3rx4AepF9EVlctuGZT7sItwxZzEKXSwX
IjBo0hAw0qYlLBGQ6sjXJs1TIJ7bt2THzHELrigdg8picEIxmSDfRAZ0eQpc
NIYzboc6o0QF3B/vUYsGOZbdLXMzrZz8EuI1VYb/8frV+SURgbMp7kZLn2sk
cqWkAFMg17qdrguD+7v9fZJ/x8gV6CpZJSbuGGA1CvEs91qRTkaLmyJGDoK5
RAVJk3amMKTLcwihbdmruSLpViSWVnR+0kdTq3ysCAKa1gYAHvikv79HAwdD
rgmdDobHNB2uHaMTWLuBEcQPvU7elhZXFwn2+vuHnC0YnP7lYA8d4sXz43bX
bVigdV9FjUcfdvd4ZZ/CmU/hzD9iOLNUtiqzK6qvX7O9WCpgYa2u/eqbunpz
K8uAyHcp8kzN9N8SFT0wLFobH2F4JHfe7+xs7bzvDmEGWOvVN+dP967enl4+
vwLzcnXy9OQKtH85JhlI6Y3t7ayMBZt21e0dPGBsd2UsmrMHTtzbuGi0XHeP
7W9c9P1j9zYvujl4zdh9fyz7tObS+zuM+S3HidXAJ5sGnp/0/IHL4w42j+tv
GnP4gEUipsvjjh+wxnXjnt6zxnVjTtyY1xffcF8MjdZhc3C83NMXz6XOT3c2
ge3t7a907m7qvHvQ9zqfYOedkvPDk8HzIf59cbxx4TziyaYR6xGgQd2dxqDz
+ybpdtf3v2OK3d3GkHvIykMO1w/ZtKrd47v7N5nBQ57ePWQNS56WRoAhbgD8
dK/uBUCasD5KUuaSjIsiwwMfMIbObf0+G0Qri9gUTXluvxlNpZBFUKnQlQo+
hUb/BKFRI7IpIJdfF7Hgfxx2gNHBLfLu/u51t9I3dOeu1dStu15rr2rtl62H
ft89r7Xuu+9ae7v+bE/qVg/CQdV66PXtOsBZd3/Hb96vmz0Y3Sdec72M7kHZ
fNjzgRzWzR4Qiqqwudfr+zTq1s1V74+0M3ReH/NqDeM4yiDtlQExk86e2hbD
p0LWst6DLFV5lC3ly23zaBVMy+JKKY53b/Fw+AwwXQ1yZYsHsFV4gPJam3qL
Z6Y1asV2t3uwPQNymEjFdtvGkBDbNjQuH/rd2fE26MnqGflCgeb5pnfz+cwN
SWSpeD5Y4cDWxhSU1od1p+XuPDAXXo/CsuE+IVtzJwbI4IvGsblzNqghF1Wb
pccaF6wdfTL8AMBZ7bU2ew2r15jxj6XUngvy4Zg01pVKMjd5PxQ3n2x9uNNV
HY+oiOsP4m1B2i1x42m/yjuIVx3Y2sLDq0T6Lp3PHN5Q2dBVDSNPK6p6ZbnR
qJqnN+mYnlid2q918wEhAJcmE9z0TNzOayXseKQHGFrt8lUWR8msGEHwgqfO
bnALGbf3GvNj7Vs0z+fLR1xKtRD4kGIiHxPcFmZodlpuMGJp/bGgwx61I0VN
UwkV0aWtJHWUhnjyOQkLIgtu6oFqR8VsSxRJBLAtHXeKcrCgOg86tCXHZ4Ni
7XlndzoM+HhZ83mmFhXys9TgUb12CBHD1EmA5XNWLLXKKYmwUzopwyebwL5f
68ShBcKYGsunlWqJYlMUoynq0FEh4aan46qAAh/4rerL1JM3QrG+TkdzwCKw
yqRjkUEbo3d8cXJ6ihETnp/HHeARMDYhu0Gq0OIEcnje6rj4BvecRT2vO9eU
Jt6sdPYWyKLH0XvEAvdymCuMgiA/9l7hWZUtbrOyda0XbJVmyiK64JiNzpWB
VsWeYBSFoU7qGP8ESMDiBEZ7kf1OVeDVVXzaM/2D+YfOR009nys7Pa4OpPnB
D1lpLl3s0BrKwspyzcXZ4MNDsMFbrlePjLGgE9tUfKCTHekMKBbNdEf+dokX
qxK/PodZkvgNCD40p62k/e8f3fwRxPfNXcT1L21wJrn2vI5sWoI6fRxQEMHl
zfXb3lIubXuvlP0lZk8JWvhb+U66jFPOwr16X5WyzalaSjSnqter94n6rok2
hd7VKeZU8Q7Quzq/nKq9bq9qwlQPrxVFwPbAtTrCf4R9Iop+QBr/oTV2DZbm
k9p+TLW9g8IbdBfWv86L3z5cdZcLVus1F6vxi1la2Ft5VmmvsarSL9S0kH4/
q3RXB6HXA/dgdNjb26P9lVorddjvH9Sqi1o8gcDd7Pa7O72dbu+KlZ3B7u+t
fGYtP/so+uxCwhhPUXshGdWyT/kceoQB7u+l3X8/5b4XZ/Gbt50/6fpdun6/
kN2n+msV/zc47QeovtPyK0zvl1Tdlo21vmNPyNZ0eBVOqw9913vlw54bobMp
pKpGxfDx6nx4MTz/djhobBXj8Lt70d7sGDPcH39UV+HMrgHULy1SE5v9vcbK
oUe9xP39asy6r0+cLSKADSt14H/5+Abqtb3+Ri+G79kMvExD/bskrWuW8clI
/IOkoUuB7UWA6vf71D+X1vBPLmJ/W33wDyR3oENUSK0u2vNlN7FeWJxjXHO1
v1nEqq8JkbBsOqroPh3XJ2/b/NpDeTJXnulJmkcsWo+OX7w+e1x/Ox2UAE4U
CGt4Wt/BW53D3/KD5UOYSE/dyDr298D5p53LthSv6OQIuEToRL5OI+D2M5rV
1s1cAKaNRdeIpwr4kh9IGb5xUQ6Sj/xP+AWHPXbD3lhtXqosA5KuoRo9FOMe
ZGkAdR2ea2XykVa5fImXnybNJXlfwZVUC22qv2tddT3uwzeDZ42olauFWMLH
TWTvshhubMfxw159ELV8oaJjBcZWokZ7+zCSwn26gGcyWBXdMHZR/i4J9tL1
wDFyxdCNYtCk12nOp7fry8in5/DDwGlwdYk/93b1N1QEg2kaBbp6milAx5yl
dHM6su7Vi3RO37Wyi6a5pNtS9Yjly5wiax5RL4XVuzXIFQmyqfSyRryALAj+
STMqQ+FpaL5FidYOcHRXZPFg5kjRpV8dTOkdjMid1mdoK0CQBAhgm6DleN3X
FUVGeJU+oaQqSMFPRYmqr2mWjuXt13gsvfJi3g12k2YGUXb1l/KyIdkeZTGl
clcga1ACJDEytrqo513DvIkUP0m05dXoXPHFlisOdUBvO9Skb7CFb7GV5tzy
HVnB0ulEle/whmmW83XNmnCIT2rdTQfqgbQA6aQHtebuaSo+UVAyhW574g0N
104SfO4LyjmbYRDMRrOzzu5ewYguYboXHYAbyBQU3nkq52qBtrjbkU/x+ijf
7yM6kaNWifoK/8JzBJ8z8fkjXxYUfHK+wS2Y6QeMQx7pzqSDz5y4l1YoRMEl
alO+PUHiJkbKVOFE6zGguNsBC1e6+TQhjqAJlypfumLDC9vGj9ulSrT5tixd
+xZig3JyEZYLo1UoUxFNGV2tFcuUYzyqgK9qGK3bc62vnUjiOxlRGpZOVoU3
qPFAWSKw4TLiqrR15PN0jqXQraYZIBhVXIZw3L0foCx+TgUXYuua72q52VId
k8uTSyFYSjEJveeCZVFotHQtmUwG38tfehSISsYjXVdsSf6qJ5dO3KUK1g02
jYE7RZFuMotU2iVT4UwwvjxmWInVLC2SXJCLYPqyNWCdCRp3VNDu2epQXqke
5GfcGlxATOaCruNE3uMOzvSA+WCDHy/qyZJUNN8kMJWzoOC6sQ7cKVpehqQT
8QLfG9FEUYKfm4KEg60g3o7yAeGVFy9I80y6k0aIULlkvukCCz+HgTtWnpN1
t3OnpcBteGyB6Zkpo2b4LACs3bF+ZFIsaeMzKhqL22jVsIjPG2P4ohqX+G1E
l37Kl12aoTc+21FU2Uilb7GaYJV6GrlHU2aQq+MrKOSNwxuF94bxEg6tGXQ9
XtiIrjsvvYzgXkUob+dDhBJc10vZiLE7URhABBclnHP498Wqa2ExejwUyvIm
F14yWtU7vNtteGhTi5BAKwcouPi/QG0Vd5464I6RKYVw44EDsebAgS9hW7BS
F2pvLYssH5egSgrF96ua3Xj8DZHNQZsRIXqHpfkkX7usfS+9yNfZkD3M0pBP
H7icxT2BUb6YR/GnT1FRGRM/kiwfVsLzDvgeFVfek7BpBGsbb0Wdtz7o8Tfv
3bcsVmBLW0QW6FDV1utMp4pxcDy/hEelPfeQQ5kaNo/ReE+0lX6do4XKo9mV
U4aLP9kNplYYMoN1MIamrszJ0InzsULQucb5pO9KrLzzSZj5no5LtxJurfM7
tWAiM4nRSASiDPhNiX7TUhAnEB881ROAUGZMU9RCCFSbEYd7knCkgmvxf1w5
yKwEVQAA

-->

</rfc>
