<?xml version='1.0' encoding='utf-8'?>
<!DOCTYPE rfc [
  <!ENTITY nbsp    "&#160;">
  <!ENTITY zwsp   "&#8203;">
  <!ENTITY nbhy   "&#8209;">
  <!ENTITY wj     "&#8288;">
]>
<?xml-stylesheet type="text/xsl" href="rfc2629.xslt" ?>
<!-- generated by https://github.com/cabo/kramdown-rfc version 1.7.18 (Ruby 3.3.3) -->
<rfc xmlns:xi="http://www.w3.org/2001/XInclude" ipr="trust200902" docName="draft-ietf-lamps-x509-shbs-04" category="std" consensus="true" submissionType="IETF" tocInclude="true" sortRefs="true" symRefs="true" version="3">
  <!-- xml2rfc v2v3 conversion 3.22.0 -->
  <front>
    <title abbrev="HSS and XMSS for X.509">Internet X.509 Public Key Infrastructure: Algorithm Identifiers for HSS and XMSS</title>
    <seriesInfo name="Internet-Draft" value="draft-ietf-lamps-x509-shbs-04"/>
    <author initials="D." surname="Van Geest" fullname="Daniel Van Geest">
      <organization>CryptoNext Security</organization>
      <address>
        <email>daniel.vangeest@cryptonext-security.com</email>
      </address>
    </author>
    <author initials="K." surname="Bashiri" fullname="Kaveh Bashiri">
      <organization>BSI</organization>
      <address>
        <email>kaveh.bashiri.ietf@gmail.com</email>
      </address>
    </author>
    <author initials="S." surname="Fluhrer" fullname="Scott Fluhrer">
      <organization>Cisco Systems</organization>
      <address>
        <email>sfluhrer@cisco.com</email>
      </address>
    </author>
    <author initials="S." surname="Gazdag" fullname="Stefan Gazdag">
      <organization>genua GmbH</organization>
      <address>
        <email>ietf@gazdag.de</email>
      </address>
    </author>
    <author initials="S." surname="Kousidis" fullname="Stavros Kousidis">
      <organization>BSI</organization>
      <address>
        <email>kousidis.ietf@gmail.com</email>
      </address>
    </author>
    <date year="2024" month="July" day="25"/>
    <area>sec</area>
    <workgroup>LAMPS - Limited Additional Mechanisms for PKIX and SMIME</workgroup>
    <keyword>Internet-Draft</keyword>
    <abstract>
      <?line 125?>

<t>This document specifies algorithm identifiers and ASN.1 encoding formats for
the Stateful Hash-Based Signature Schemes (S-HBS) Hierarchical Signature System
(HSS), eXtended Merkle Signature Scheme (XMSS), and XMSS^MT, a multi-tree
variant of XMSS. This specification applies to the Internet X.509 Public Key
infrastructure (PKI) when those digital signatures are used in Internet X.509
certificates and certificate revocation lists.</t>
    </abstract>
    <note removeInRFC="true">
      <name>About This Document</name>
      <t>
        Status information for this document may be found at <eref target="https://datatracker.ietf.org/doc/draft-ietf-lamps-x509-shbs/"/>.
      </t>
      <t>
        Discussion of this document takes place on the
        LAMPS Working Group mailing list (<eref target="mailto:spasm@ietf.org"/>),
        which is archived at <eref target="https://mailarchive.ietf.org/arch/browse/spasm/"/>.
        Subscribe at <eref target="https://www.ietf.org/mailman/listinfo/spasm/"/>.
      </t>
      <t>Source for this draft and an issue tracker can be found at
        <eref target="https://github.com/x509-hbs/draft-x509-shbs"/>.</t>
    </note>
  </front>
  <middle>
    <?line 134?>

<section anchor="introduction">
      <name>Introduction</name>
      <t>Stateful Hash-Based Signature Schemes (S-HBS) such as HSS, XMSS and XMSS^MT
combine Merkle trees with One Time Signatures (OTS) in order to provide digital
signature schemes that remain secure even when quantum computers become
available. Their theoretic security is well understood and depends only on the
security of the underlying hash function. As such they can serve as an
important building block for quantum computer resistant information and
communication technology.</t>
      <t>The private key of S-HBS is a finite collection of OTS keys, hence only a
limited number of messages can be signed and the private key's state must be
updated and persisted after signing to prevent reuse of OTS keys.  While the
right selection of algorithm parameters would allow a private key to sign a
virtually unbounded number of messages (e.g. 2^60), this is at the cost of a
larger signature size and longer signing time. Due to the statefulness of the
private key and the limited number of signatures that can be created, S-HBS
might not be appropriate for use in interactive protocols. However, in some use
cases the deployment of S-HBS may be appropriate. Such use cases are described
and discussed later in <xref target="use-cases-shbs-x509"/>.</t>
    </section>
    <section anchor="conventions-and-definitions">
      <name>Conventions and Definitions</name>
      <t>The key words "<bcp14>MUST</bcp14>", "<bcp14>MUST NOT</bcp14>", "<bcp14>REQUIRED</bcp14>", "<bcp14>SHALL</bcp14>", "<bcp14>SHALL
NOT</bcp14>", "<bcp14>SHOULD</bcp14>", "<bcp14>SHOULD NOT</bcp14>", "<bcp14>RECOMMENDED</bcp14>", "<bcp14>NOT RECOMMENDED</bcp14>",
"<bcp14>MAY</bcp14>", and "<bcp14>OPTIONAL</bcp14>" in this document are to be interpreted as
described in BCP 14 <xref target="RFC2119"/> <xref target="RFC8174"/> when, and only when, they
appear in all capitals, as shown here.</t>
      <?line -18?>

</section>
    <section anchor="use-cases-shbs-x509">
      <name>Use Cases of S-HBS in X.509</name>
      <t>As many cryptographic algorithms that are considered to be quantum-resistant,
S-HBS have several pros and cons regarding their practical usage. On the
positive side they are considered to be secure against a classical as well as a
quantum adversary, and a secure instantiation of S-HBS may always be built as
long as a cryptographically secure hash function exists. Moreover, S-HBS offer
small public key sizes, and, in comparison to other post-quantum signature
schemes, the S-HBS can offer relatively small signature sizes (for certain
parameter sets). While key generation and signature generation may take longer
than classical alternatives, fast and minimal verification routines can be
built.  The major negative aspect is the statefulness.  Private keys always
have to be handled in a secure manner, S-HBS necessitate a special treatment of
the private key in order to avoid security incidents like signature forgery
<xref target="MCGREW"/>, <xref target="SP800208"/>. Therefore, for S-HBS, a secure environment <bcp14>MUST</bcp14> be used
for key generation and key management.</t>
      <t>Note that, in general, root CAs offer such a secure environment and the number
of issued signatures (including signed certificates and CRLs) is often moderate
due to the fact that many root CAs delegate OCSP services or the signing of
end-entity certificates to other entities (such as subordinate CAs) that use
stateless signature schemes. Therefore, many root CAs should be able to handle
the required state management, and S-HBS offer a viable solution.</t>
      <t>As the above reasoning for root CAs usually does not apply for subordinate CAs,
it is <bcp14>NOT RECOMMENDED</bcp14> for subordinate CAs to use S-HBS for issuing end-entity
certificates. Moreover, S-HBS <bcp14>MUST NOT</bcp14> be used for end-entity certificates.</t>
      <t>However, S-HBS <bcp14>MAY</bcp14> be used for code signing certificates, since they are
suitable and recommended in such non-interactive contexts. For example, see the
recommendations for software and firmware signing in <xref target="CNSA2.0"/>. Some
manufactures use common and well-established key formats like X.509 for their
code signing and update mechanisms. Also there are multi-party IoT ecosystems
where publicly trusted code signing certificates are useful.</t>
    </section>
    <section anchor="algorithm-identifiers-and-parameters">
      <name>Algorithm Identifiers and Parameters</name>
      <t>In this document, we define new OIDs for identifying the different stateful
hash-based signature algorithms. An additional OID is defined in <xref target="I-D.draft-ietf-lamps-rfc8708bis"/> and
repeated here for convenience. For all of the OIDs, the parameters <bcp14>MUST</bcp14> be
absent.</t>
      <section anchor="hss-algorithm-identifier">
        <name>HSS Algorithm Identifier</name>
        <t>The object identifier and public key algorithm identifier for HSS is defined in
<xref target="I-D.draft-ietf-lamps-rfc8708bis"/>. The definitions are repeated here for reference.</t>
        <t>The object identifier for an HSS public key is <tt>id-alg-hss-lms-hashsig</tt>:</t>
        <artwork><![CDATA[
id-alg-hss-lms-hashsig  OBJECT IDENTIFIER ::= {
   iso(1) member-body(2) us(840) rsadsi(113549) pkcs(1) pkcs9(9)
   smime(16) alg(3) 17 }
]]></artwork>
        <t>Note that the <tt>id-alg-hss-lms-hashsig</tt> algorithm identifier is also referred to
as <tt>id-alg-mts-hashsig</tt>. This synonym is based on the terminology used in an
early draft of the document that became <xref target="RFC8554"/>.</t>
        <t>The public key and signature values identify the hash function and the height used in the
HSS/LMS tree. <xref target="RFC8554"/> and <xref target="SP800208"/> define these values, but an IANA registry
<xref target="IANA-LMS"/> permits the registration of additional identifiers in the future.</t>
      </section>
      <section anchor="xmss-algorithm-identifier">
        <name>XMSS Algorithm Identifier</name>
        <t>The object identifier for an XMSS public key is <tt>id-alg-xmss-hashsig</tt>:</t>
        <artwork><![CDATA[
id-alg-xmss-hashsig  OBJECT IDENTIFIER ::= {
   iso(1) identified-organization(3) dod(6) internet(1) security(5)
   mechanisms(5) pkix(7) algorithms(6) 34 }
]]></artwork>
        <t>The public key and signature values identify the hash function and the height used in the
XMSS tree. <xref target="RFC8391"/> and <xref target="SP800208"/> define these values, but an IANA registry
<xref target="IANA-XMSS"/> permits the registration of additional identifiers in the future.</t>
      </section>
      <section anchor="xmssmt-algorithm-identifier">
        <name>XMSS^MT Algorithm Identifier</name>
        <t>The object identifier for an XMSS^MT public key is <tt>id-alg-xmssmt-hashsig</tt>:</t>
        <artwork><![CDATA[
id-alg-xmssmt-hashsig  OBJECT IDENTIFIER ::= {
   iso(1) identified-organization(3) dod(6) internet(1) security(5)
   mechanisms(5) pkix(7) algorithms(6) 35 }
]]></artwork>
        <t>The public key and signature values identify the hash function and the height used in the
XMSS^MT tree. <xref target="RFC8391"/> and <xref target="SP800208"/> define these values, but an IANA registry
<xref target="IANA-XMSS"/> permits the registration of additional identifiers in the future.</t>
      </section>
    </section>
    <section anchor="public-key-identifiers">
      <name>Public Key Identifiers</name>
      <t>Certificates conforming to <xref target="RFC5280"/> can convey a public key for any public key
algorithm. The certificate indicates the algorithm through an algorithm
identifier. An algorithm identifier consists of an OID and optional parameters.</t>
      <t><xref target="RFC8554"/> and <xref target="RFC8391"/> define the raw octet string encodings of the public
keys used in this document. When used in a SubjectPublicKeyInfo type, the
subjectPublicKey BIT STRING contains the raw octet string encodings of the
public keys.</t>
      <t>This document defines ASN.1 OCTET STRING types for encoding the public keys
when not used in a SubjectPublicKeyInfo. The OCTET STRING is mapped to a
subjectPublicKey (a value of type BIT STRING) as follows: the most significant
bit of the OCTET STRING value becomes the most significant bit of the BIT
STRING value, and so on; the least significant bit of the OCTET STRING
becomes the least significant bit of the BIT STRING.</t>
      <section anchor="hss-public-keys">
        <name>HSS Public Keys</name>
        <t>The HSS public key identifier is as follows:</t>
        <artwork><![CDATA[
pk-HSS-LMS-HashSig PUBLIC-KEY ::= {
   IDENTIFIER id-alg-hss-lms-hashsig
   -- KEY no ASN.1 wrapping --
   PARAMS ARE absent
   CERT-KEY-USAGE
      { digitalSignature, nonRepudiation, keyCertSign, cRLSign } }
]]></artwork>
        <t>The HSS public key is defined as follows:</t>
        <artwork><![CDATA[
HSS-LMS-HashSig-PublicKey ::= OCTET STRING
]]></artwork>
        <t><xref target="RFC8554"/> defines the raw octet string encoding of an HSS public key using the
<tt>hss_public_key</tt> structure. See <xref target="SP800208"/> and <xref target="RFC8554"/> for more information on
the contents and format of an HSS public key. Note that the single-tree signature
scheme LMS is instantiated as HSS with number of levels being equal to 1.</t>
      </section>
      <section anchor="xmss-public-keys">
        <name>XMSS Public Keys</name>
        <t>The XMSS public key identifier is as follows:</t>
        <artwork><![CDATA[
pk-XMSS-HashSig PUBLIC-KEY ::= {
   IDENTIFIER id-alg-xmss-hashsig
   -- KEY no ASN.1 wrapping --
   PARAMS ARE absent
   CERT-KEY-USAGE
      { digitalSignature, nonRepudiation, keyCertSign, cRLSign } }
]]></artwork>
        <t>The XMSS public key is defined as follows:</t>
        <artwork><![CDATA[
XMSS-HashSig-PublicKey ::= OCTET STRING
]]></artwork>
        <t><xref target="RFC8391"/> defines the raw octet string encoding of an HSS public key using the
<tt>xmss_public_key</tt> structure. See <xref target="SP800208"/> and <xref target="RFC8391"/> for more information
on the contents and format of an XMSS public key.</t>
      </section>
      <section anchor="xmssmt-public-keys">
        <name>XMSS^MT Public Keys</name>
        <t>The XMSS^MT public key identifier is as follows:</t>
        <artwork><![CDATA[
pk-XMSSMT-HashSig PUBLIC-KEY ::= {
   IDENTIFIER id-alg-xmssmt-hashsig
   -- KEY no ASN.1 wrapping --
   PARAMS ARE absent
   CERT-KEY-USAGE
      { digitalSignature, nonRepudiation, keyCertSign, cRLSign } }
]]></artwork>
        <t>The XMSS^MT public key is defined as follows:</t>
        <artwork><![CDATA[
XMSSMT-HashSig-PublicKey ::= OCTET STRING
]]></artwork>
        <t><xref target="RFC8391"/> defines the raw octet string encoding of an HSS public key using the
<tt>xmssmt_public_key</tt> structure. See <xref target="SP800208"/> and <xref target="RFC8391"/> for more information
on the contents and format of an XMSS^MT public key.</t>
      </section>
    </section>
    <section anchor="key-usage-bits">
      <name>Key Usage Bits</name>
      <t>The intended application for the key is indicated in the keyUsage certificate
extension <xref target="RFC5280"/>.
When one of the AlgorithmIdentifiers specified in this document appears in the SubjectPublicKeyInfo
field of a certification authority (CA) X.509 certificate <xref target="RFC5280"/>, the
certificate key usage extension <bcp14>MUST</bcp14> contain at least one of the
following values: digitalSignature, nonRepudiation, keyCertSign, or
cRLSign. However, it <bcp14>MUST NOT</bcp14> contain other values.</t>
      <t>When one of these AlgorithmIdentifiers appears in the SubjectPublicKeyInfo
field of an end entity X.509 certificate <xref target="RFC5280"/>, the certificate key usage
extension <bcp14>MUST</bcp14> contain at least one of the following values: digitalSignature
or nonRepudiation. However, it <bcp14>MUST NOT</bcp14> contain other values.</t>
      <t>Note that for certificates that indicate <tt>id-alg-hss-lms-hashsig</tt> the above
definitions are more restrictive than the requirement defined in <xref section="4" sectionFormat="of" target="I-D.draft-ietf-lamps-rfc8708bis"/>.</t>
    </section>
    <section anchor="signature-algorithms">
      <name>Signature Algorithms</name>
      <t>This section identifies OIDs for signing using HSS, XMSS, and XMSS^MT. When
these algorithm identifiers appear in the algorithm field as an
AlgorithmIdentifier, the encoding <bcp14>MUST</bcp14> omit the parameters field. That is, the
AlgorithmIdentifier <bcp14>SHALL</bcp14> be a SEQUENCE of one component, one of the OIDs
defined in the following subsections.</t>
      <t>When the signature algorithm identifiers described in this document are used to
create a signature on a message, no digest algorithm is applied to the message
before signing.  That is, the full data to be signed is signed rather than
a digest of the data.</t>
      <t>For HSS, the signature value is described in section 6.4 of <xref target="RFC8554"/>. For XMSS
and XMSS^MT the signature values are described in sections B.2 and C.2 of
<xref target="RFC8391"/>, respectively. The octet string representing the signature is encoded
directly in the OCTET STRING without adding any additional ASN.1 wrapping. For
the Certificate and CertificateList structures, the signature value is wrapped
in the "signatureValue" OCTET STRING field.</t>
      <section anchor="hss-signature-algorithm">
        <name>HSS Signature Algorithm</name>
        <t>The HSS public key OID is also used to specify that an HSS signature was
generated on the full message, i.e. the message was not hashed before being
processed by the HSS signature algorithm.</t>
        <artwork><![CDATA[
id-alg-hss-lms-hashsig OBJECT IDENTIFIER ::= {
   iso(1) member-body(2) us(840) rsadsi(113549) pkcs(1) pkcs9(9)
   smime(16) alg(3) 17 }
]]></artwork>
        <t>The HSS signature is defined as follows:</t>
        <artwork><![CDATA[
HSS-LMS-HashSig-Signature ::= OCTET STRING
]]></artwork>
        <t>See <xref target="SP800208"/> and <xref target="RFC8554"/> for more information on the contents and
format of an HSS signature.</t>
      </section>
      <section anchor="xmss-signature-algorithm">
        <name>XMSS Signature Algorithm</name>
        <t>The id-alg-xmss-hashsig public key OID is also used to specify that an XMSS signature was
generated on the full message, i.e. the message was not hashed before being
processed by the XMSS signature algorithm.</t>
        <t>The XMSS signature is defined as follows:</t>
        <artwork><![CDATA[
XMSS-HashSig-Signature ::= OCTET STRING
]]></artwork>
        <t>See <xref target="SP800208"/> and <xref target="RFC8391"/> for more information on the contents and
format of an XMSS signature.</t>
        <t>The signature generation <bcp14>MUST</bcp14> be performed according to 7.2 of
<xref target="SP800208"/>.</t>
      </section>
      <section anchor="xmssmt-signature-algorithm">
        <name>XMSS^MT Signature Algorithm</name>
        <t>The id-alg-xmssmt-hashsig public key OID is also used to specify that an XMSS^MT signature
was generated on the full message, i.e. the message was not hashed before being
processed by the XMSS^MT signature algorithm.</t>
        <t>The XMSS^MT signature is defined as follows:</t>
        <artwork><![CDATA[
XMSSMT-HashSig-Signature ::= OCTET STRING
]]></artwork>
        <t>See <xref target="SP800208"/> and <xref target="RFC8391"/> for more information on the contents and
format of an XMSS^MT signature.</t>
        <t>The signature generation <bcp14>MUST</bcp14> be performed according to 7.2 of
<xref target="SP800208"/>.</t>
      </section>
    </section>
    <section anchor="key-generation">
      <name>Key Generation</name>
      <t>The key generation for XMSS and XMSS^MT <bcp14>MUST</bcp14> be performed according to 7.2 of
<xref target="SP800208"/></t>
    </section>
    <section anchor="sec-asn1">
      <name>ASN.1 Module</name>
      <t>For reference purposes, the ASN.1 syntax is presented as an ASN.1 module here.
This ASN.1 Module builds upon the conventions established in <xref target="RFC5911"/>.</t>
      <artwork><![CDATA[
X509-SHBS-2024
  { iso(1) identified-organization(3) dod(6) internet(1) security(5)
    mechanisms(5) pkix(7) id-mod(0) id-mod-pkix1-shbs-2024(TBD) }

DEFINITIONS IMPLICIT TAGS ::= BEGIN

EXPORTS ALL;

IMPORTS
  PUBLIC-KEY, SIGNATURE-ALGORITHM
    FROM AlgorithmInformation-2009  -- RFC 5911 [CMSASN1]
      { iso(1) identified-organization(3) dod(6) internet(1)
        security(5) mechanisms(5) pkix(7) id-mod(0)
        id-mod-algorithmInformation-02(58) }

  sa-HSS-LMS-HashSig, pk-HSS-LMS-HashSig
    FROM MTS-HashSig-2013
      { iso(1) member-body(2) us(840) rsadsi(113549) pkcs(1) pkcs9(9)
        id-smime(16) id-mod(0) id-mod-mts-hashsig-2013(64) };

--
-- Object Identifiers
--

-- id-alg-hss-lms-hashsig is defined in [RFC8708]

id-alg-xmss-hashsig  OBJECT IDENTIFIER ::= {
   iso(1) identified-organization(3) dod(6) internet(1) security(5)
   mechanisms(5) pkix(7) algorithms(6) 34 }

id-alg-xmssmt-hashsig  OBJECT IDENTIFIER ::= {
   iso(1) identified-organization(3) dod(6) internet(1) security(5)
   mechanisms(5) pkix(7) algorithms(6) 35 }

--
-- Signature Algorithms and Public Keys
--

-- sa-HSS-LMS-HashSig is defined in [RFC8708]

sa-XMSS-HashSig SIGNATURE-ALGORITHM ::= {
   IDENTIFIER id-alg-xmss-hashsig
   PARAMS ARE absent
   PUBLIC-KEYS { pk-XMSS-HashSig }
   SMIME-CAPS { IDENTIFIED BY id-alg-xmss-hashsig } }

sa-XMSSMT-HashSig SIGNATURE-ALGORITHM ::= {
   IDENTIFIER id-alg-xmssmt-hashsig
   PARAMS ARE absent
   PUBLIC-KEYS { pk-XMSSMT-HashSig }
   SMIME-CAPS { IDENTIFIED BY id-alg-xmssmt-hashsig } }

-- pk-HSS-LMS-HashSig is defined in [RFC8708]

pk-XMSS-HashSig PUBLIC-KEY ::= {
   IDENTIFIER id-alg-xmss-hashsig
   -- KEY no ASN.1 wrapping --
   PARAMS ARE absent
   CERT-KEY-USAGE
      { digitalSignature, nonRepudiation, keyCertSign, cRLSign } }

pk-XMSSMT-HashSig PUBLIC-KEY ::= {
   IDENTIFIER id-alg-xmssmt-hashsig
   -- KEY no ASN.1 wrapping --
   PARAMS ARE absent
   CERT-KEY-USAGE
      { digitalSignature, nonRepudiation, keyCertSign, cRLSign } }

--
-- Public Key (pk-) Algorithms
--
PublicKeys PUBLIC-KEY ::= {
   -- This expands PublicKeys from RFC 5912
   pk-HSS-LMS-HashSig |
   pk-XMSS-HashSig |
   pk-XMSSMT-HashSig,
   ...
}

--
-- Signature Algorithms (sa-)
--
SignatureAlgs SIGNATURE-ALGORITHM ::= {
   -- This expands SignatureAlgorithms from RFC 5912
   sa-HSS-LMS-HashSig |
   sa-XMSS-HashSig |
   sa-XMSSMT-HashSig,
   ...
}

END
]]></artwork>
    </section>
    <section anchor="security-considerations">
      <name>Security Considerations</name>
      <t>The security requirements of <xref target="SP800208"/> <bcp14>MUST</bcp14> be taken into account.</t>
      <t>For S-HBS it is crucial to stress the importance of a correct state management.
If an attacker were able to obtain signatures for two different messages
created using the same OTS key, then it would become computationally feasible
for that attacker to create forgeries <xref target="BH16"/>. As noted in <xref target="MCGREW"/> and
<xref target="ETSI-TR-103-692"/>, extreme care needs to be taken in order to avoid the risk
that an OTS key will be reused accidentally.  This is a new requirement that
most developers will not be familiar with and requires careful handling.</t>
      <t>Various strategies for a correct state management can be applied:</t>
      <ul spacing="normal">
        <li>
          <t>Implement a track record of all signatures generated by a key pair associated
to a S-HBS instance. This track record may be stored outside the
device which is used to generate the signature. Check the track record to
prevent OTS key reuse before a new signature is released. Drop the new
signature and hit your PANIC button if you spot OTS key reuse.</t>
        </li>
        <li>
          <t>Use a S-HBS instance only for a moderate number of signatures such
that it is always practical to keep a consistent track record and be able to
unambiguously trace back all generated signatures.</t>
        </li>
        <li>
          <t>Apply the state reservation strategy described in Section 5 of <xref target="MCGREW"/>, where
upcoming states are reserved in advance by the signer. In this way the number of
state synchronisations between nonvolatile and volatile memory is reduced.</t>
        </li>
      </ul>
    </section>
    <section anchor="backup-and-restore-management">
      <name>Backup and Restore Management</name>
      <t>Certificate Authorities have high demands in order to ensure the availability
of signature generation throughout the validity period of signing key pairs.</t>
      <t>Usual backup and restore strategies when using a stateless signature scheme
(e.g. SLH-DSA) are to duplicate private keying material and to operate
redundant signing devices or to store and safeguard a copy of the private
keying material such that it can be used to set up a new signing device in case
of technical difficulties.</t>
      <t>For S-HBS such straightforward backup and restore strategies will lead to OTS
reuse with high probability as a correct state management is not guaranteed.
Strategies for maintaining availability and keeping a correct state are
described in Section 7 of <xref target="SP800208"/>.</t>
    </section>
    <section anchor="iana-considerations">
      <name>IANA Considerations</name>
      <t>One object identifier for the ASN.1 module in Appendix A is requested
for the SMI Security for PKIX Module Identifiers (1.3.6.1.5.5.7.0)
registry:</t>
      <table>
        <thead>
          <tr>
            <th align="left">Decimal</th>
            <th align="left">Description</th>
            <th align="left">References</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">TBD</td>
            <td align="left">id-mod-pkix1-shbs-2024</td>
            <td align="left">[EDNOTE: THIS RFC]</td>
          </tr>
        </tbody>
      </table>
      <t>IANA has updated the "SMI Security for PKIX Algorithms" (1.3.6.1.5.5.7.6)
registry <xref target="SMI-PKIX"/> with two additional entries:</t>
      <table>
        <thead>
          <tr>
            <th align="left">Decimal</th>
            <th align="left">Description</th>
            <th align="left">References</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">34</td>
            <td align="left">id-alg-xmss-hashsig</td>
            <td align="left">[EDNOTE: THIS RFC]</td>
          </tr>
          <tr>
            <td align="left">35</td>
            <td align="left">id-alg-xmssmt-hashsig</td>
            <td align="left">[EDNOTE: THIS RFC]</td>
          </tr>
        </tbody>
      </table>
    </section>
  </middle>
  <back>
    <references anchor="sec-combined-references">
      <name>References</name>
      <references anchor="sec-normative-references">
        <name>Normative References</name>
        <reference anchor="I-D.draft-ietf-lamps-rfc8708bis">
          <front>
            <title>Use of the HSS/LMS Hash-Based Signature Algorithm in the Cryptographic Message Syntax (CMS)</title>
            <author fullname="R. Housley" initials="R." surname="Housley"/>
            <date month="February" year="2020"/>
            <abstract>
              <t>This document specifies the conventions for using the Hierarchical Signature System (HSS) / Leighton-Micali Signature (LMS) hash-based signature algorithm with the Cryptographic Message Syntax (CMS). In addition, the algorithm identifier and public key syntax are provided. The HSS/LMS algorithm is one form of hash-based digital signature; it is described in RFC 8554.</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="8708"/>
          <seriesInfo name="DOI" value="10.17487/RFC8708"/>
        </reference>
        <reference anchor="RFC5911">
          <front>
            <title>New ASN.1 Modules for Cryptographic Message Syntax (CMS) and S/MIME</title>
            <author fullname="P. Hoffman" initials="P." surname="Hoffman"/>
            <author fullname="J. Schaad" initials="J." surname="Schaad"/>
            <date month="June" year="2010"/>
            <abstract>
              <t>The Cryptographic Message Syntax (CMS) format, and many associated formats, are expressed using ASN.1. The current ASN.1 modules conform to the 1988 version of ASN.1. This document updates those ASN.1 modules to conform to the 2002 version of ASN.1. There are no bits-on-the-wire changes to any of the formats; this is simply a change to the syntax. This document is not an Internet Standards Track specification; it is published for informational purposes.</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="5911"/>
          <seriesInfo name="DOI" value="10.17487/RFC5911"/>
        </reference>
        <reference anchor="RFC5280">
          <front>
            <title>Internet X.509 Public Key Infrastructure Certificate and Certificate Revocation List (CRL) Profile</title>
            <author fullname="D. Cooper" initials="D." surname="Cooper"/>
            <author fullname="S. Santesson" initials="S." surname="Santesson"/>
            <author fullname="S. Farrell" initials="S." surname="Farrell"/>
            <author fullname="S. Boeyen" initials="S." surname="Boeyen"/>
            <author fullname="R. Housley" initials="R." surname="Housley"/>
            <author fullname="W. Polk" initials="W." surname="Polk"/>
            <date month="May" year="2008"/>
            <abstract>
              <t>This memo profiles the X.509 v3 certificate and X.509 v2 certificate revocation list (CRL) for use in the Internet. An overview of this approach and model is provided as an introduction. The X.509 v3 certificate format is described in detail, with additional information regarding the format and semantics of Internet name forms. Standard certificate extensions are described and two Internet-specific extensions are defined. A set of required certificate extensions is specified. The X.509 v2 CRL format is described in detail along with standard and Internet-specific extensions. An algorithm for X.509 certification path validation is described. An ASN.1 module and examples are provided in the appendices. [STANDARDS-TRACK]</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="5280"/>
          <seriesInfo name="DOI" value="10.17487/RFC5280"/>
        </reference>
        <reference anchor="RFC8391">
          <front>
            <title>XMSS: eXtended Merkle Signature Scheme</title>
            <author fullname="A. Huelsing" initials="A." surname="Huelsing"/>
            <author fullname="D. Butin" initials="D." surname="Butin"/>
            <author fullname="S. Gazdag" initials="S." surname="Gazdag"/>
            <author fullname="J. Rijneveld" initials="J." surname="Rijneveld"/>
            <author fullname="A. Mohaisen" initials="A." surname="Mohaisen"/>
            <date month="May" year="2018"/>
            <abstract>
              <t>This note describes the eXtended Merkle Signature Scheme (XMSS), a hash-based digital signature system that is based on existing descriptions in scientific literature. This note specifies Winternitz One-Time Signature Plus (WOTS+), a one-time signature scheme; XMSS, a single-tree scheme; and XMSS^MT, a multi-tree variant of XMSS. Both XMSS and XMSS^MT use WOTS+ as a main building block. XMSS provides cryptographic digital signatures without relying on the conjectured hardness of mathematical problems. Instead, it is proven that it only relies on the properties of cryptographic hash functions. XMSS provides strong security guarantees and is even secure when the collision resistance of the underlying hash function is broken. It is suitable for compact implementations, is relatively simple to implement, and naturally resists side-channel attacks. Unlike most other signature systems, hash-based signatures can so far withstand known attacks using quantum computers.</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="8391"/>
          <seriesInfo name="DOI" value="10.17487/RFC8391"/>
        </reference>
        <reference anchor="RFC8554">
          <front>
            <title>Leighton-Micali Hash-Based Signatures</title>
            <author fullname="D. McGrew" initials="D." surname="McGrew"/>
            <author fullname="M. Curcio" initials="M." surname="Curcio"/>
            <author fullname="S. Fluhrer" initials="S." surname="Fluhrer"/>
            <date month="April" year="2019"/>
            <abstract>
              <t>This note describes a digital-signature system based on cryptographic hash functions, following the seminal work in this area of Lamport, Diffie, Winternitz, and Merkle, as adapted by Leighton and Micali in 1995. It specifies a one-time signature scheme and a general signature scheme. These systems provide asymmetric authentication without using large integer mathematics and can achieve a high security level. They are suitable for compact implementations, are relatively simple to implement, and are naturally resistant to side-channel attacks. Unlike many other signature systems, hash-based signatures would still be secure even if it proves feasible for an attacker to build a quantum computer.</t>
              <t>This document is a product of the Crypto Forum Research Group (CFRG) in the IRTF. This has been reviewed by many researchers, both in the research group and outside of it. The Acknowledgements section lists many of them.</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="8554"/>
          <seriesInfo name="DOI" value="10.17487/RFC8554"/>
        </reference>
        <reference anchor="SP800208" target="https://doi.org/10.6028/NIST.SP.800-208">
          <front>
            <title>Recommendation for Stateful Hash-Based Signature Schemes</title>
            <author initials="" surname="National Institute of Standards and Technology (NIST)">
              <organization/>
            </author>
            <date year="2020" month="October" day="29"/>
          </front>
        </reference>
        <reference anchor="RFC2119">
          <front>
            <title>Key words for use in RFCs to Indicate Requirement Levels</title>
            <author fullname="S. Bradner" initials="S." surname="Bradner"/>
            <date month="March" year="1997"/>
            <abstract>
              <t>In many standards track documents several words are used to signify the requirements in the specification. These words are often capitalized. This document defines these words as they should be interpreted in IETF documents. This document specifies an Internet Best Current Practices for the Internet Community, and requests discussion and suggestions for improvements.</t>
            </abstract>
          </front>
          <seriesInfo name="BCP" value="14"/>
          <seriesInfo name="RFC" value="2119"/>
          <seriesInfo name="DOI" value="10.17487/RFC2119"/>
        </reference>
        <reference anchor="RFC8174">
          <front>
            <title>Ambiguity of Uppercase vs Lowercase in RFC 2119 Key Words</title>
            <author fullname="B. Leiba" initials="B." surname="Leiba"/>
            <date month="May" year="2017"/>
            <abstract>
              <t>RFC 2119 specifies common key words that may be used in protocol specifications. This document aims to reduce the ambiguity by clarifying that only UPPERCASE usage of the key words have the defined special meanings.</t>
            </abstract>
          </front>
          <seriesInfo name="BCP" value="14"/>
          <seriesInfo name="RFC" value="8174"/>
          <seriesInfo name="DOI" value="10.17487/RFC8174"/>
        </reference>
      </references>
      <references anchor="sec-informative-references">
        <name>Informative References</name>
        <reference anchor="RFC3279">
          <front>
            <title>Algorithms and Identifiers for the Internet X.509 Public Key Infrastructure Certificate and Certificate Revocation List (CRL) Profile</title>
            <author fullname="L. Bassham" initials="L." surname="Bassham"/>
            <author fullname="W. Polk" initials="W." surname="Polk"/>
            <author fullname="R. Housley" initials="R." surname="Housley"/>
            <date month="April" year="2002"/>
            <abstract>
              <t>This document specifies algorithm identifiers and ASN.1 encoding formats for digital signatures and subject public keys used in the Internet X.509 Public Key Infrastructure (PKI). Digital signatures are used to sign certificates and certificate revocation list (CRLs). Certificates include the public key of the named subject. [STANDARDS-TRACK]</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="3279"/>
          <seriesInfo name="DOI" value="10.17487/RFC3279"/>
        </reference>
        <reference anchor="RFC8410">
          <front>
            <title>Algorithm Identifiers for Ed25519, Ed448, X25519, and X448 for Use in the Internet X.509 Public Key Infrastructure</title>
            <author fullname="S. Josefsson" initials="S." surname="Josefsson"/>
            <author fullname="J. Schaad" initials="J." surname="Schaad"/>
            <date month="August" year="2018"/>
            <abstract>
              <t>This document specifies algorithm identifiers and ASN.1 encoding formats for elliptic curve constructs using the curve25519 and curve448 curves. The signature algorithms covered are Ed25519 and Ed448. The key agreement algorithms covered are X25519 and X448. The encoding for public key, private key, and Edwards-curve Digital Signature Algorithm (EdDSA) structures is provided.</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="8410"/>
          <seriesInfo name="DOI" value="10.17487/RFC8410"/>
        </reference>
        <reference anchor="RFC8411">
          <front>
            <title>IANA Registration for the Cryptographic Algorithm Object Identifier Range</title>
            <author fullname="J. Schaad" initials="J." surname="Schaad"/>
            <author fullname="R. Andrews" initials="R." surname="Andrews"/>
            <date month="August" year="2018"/>
            <abstract>
              <t>When the Curdle Security Working Group was chartered, a range of object identifiers was donated by DigiCert, Inc. for the purpose of registering the Edwards Elliptic Curve key agreement and signature algorithms. This donated set of OIDs allowed for shorter values than would be possible using the existing S/MIME or PKIX arcs. This document describes the donated range and the identifiers that were assigned from that range, transfers control of that range to IANA, and establishes IANA allocation policies for any future assignments within that range.</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="8411"/>
          <seriesInfo name="DOI" value="10.17487/RFC8411"/>
        </reference>
        <reference anchor="MCGREW" target="https://tubiblio.ulb.tu-darmstadt.de/id/eprint/101633">
          <front>
            <title>State Management for Hash-Based Signatures</title>
            <author initials="D." surname="McGrew">
              <organization/>
            </author>
            <author initials="P." surname="Kampanakis">
              <organization/>
            </author>
            <author initials="S." surname="Fluhrer">
              <organization/>
            </author>
            <author initials="S." surname="Gazdag">
              <organization/>
            </author>
            <author initials="D." surname="Butin">
              <organization/>
            </author>
            <author initials="J." surname="Buchmann">
              <organization/>
            </author>
            <date year="2016" month="November" day="02"/>
          </front>
        </reference>
        <reference anchor="BH16" target="https://eprint.iacr.org/2016/1042.pdf">
          <front>
            <title>Oops, I did it again – Security of One-Time Signatures under Two-Message Attacks.</title>
            <author initials="L." surname="Bruinderink">
              <organization/>
            </author>
            <author initials="S." surname="Hülsing">
              <organization/>
            </author>
            <date year="2016"/>
          </front>
        </reference>
        <reference anchor="CNSA2.0" target="https://media.defense.gov/2022/Sep/07/2003071834/-1/-1/0/CSA_CNSA_2.0_ALGORITHMS_.PDF">
          <front>
            <title>Commercial National Security Algorithm Suite 2.0 (CNSA 2.0) Cybersecurity Advisory (CSA)</title>
            <author initials="" surname="National Security Agency (NSA)">
              <organization/>
            </author>
            <date year="2022" month="September" day="07"/>
          </front>
        </reference>
        <reference anchor="ETSI-TR-103-692" target="https://www.etsi.org/deliver/etsi_tr/103600_103699/103692/01.01.01_60/tr_103692v010101p.pdf">
          <front>
            <title>State management for stateful authentication mechanisms</title>
            <author initials="" surname="European Telecommunications Standards Institute (ETSI)">
              <organization/>
            </author>
            <date year="2021" month="November"/>
          </front>
        </reference>
        <reference anchor="IANA-LMS" target="https://www.iana.org/assignments/leighton-micali-signatures/">
          <front>
            <title>Leighton-Micali Signatures (LMS)</title>
            <author initials="" surname="IANA">
              <organization/>
            </author>
            <date>n.d.</date>
          </front>
        </reference>
        <reference anchor="IANA-XMSS" target="https://iana.org/assignments/xmss-extended-hash-based-signatures/">
          <front>
            <title>XMSS: Extended Hash-Based Signatures</title>
            <author initials="" surname="IANA">
              <organization/>
            </author>
            <date>n.d.</date>
          </front>
        </reference>
        <reference anchor="SMI-PKIX" target="https://www.iana.org/assignments/smi-numbers/smi-numbers.xhtml#smi-numbers-1.3.6.1.5.5.7.6">
          <front>
            <title>SMI Security for PKIX Algorithms</title>
            <author initials="" surname="IANA">
              <organization/>
            </author>
            <date>n.d.</date>
          </front>
        </reference>
      </references>
    </references>
    <?line 595?>

<section anchor="hss-x509-v3-certificate-example">
      <name>HSS X.509 v3 Certificate Example</name>
      <t>This section shows a self-signed X.509 v3 certificate using HSS.</t>
      <artwork><![CDATA[
Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number:
            e8:91:d6:06:91:4f:ce:f3
        Signature Algorithm: hss
        Issuer: C = US, ST = VA, L = Herndon, O = Bogus CA
        Validity
            Not Before: May 14 08:58:11 2024 GMT
            Not After : May 14 08:58:11 2034 GMT
        Subject: C = US, ST = VA, L = Herndon, O = Bogus CA
        Subject Public Key Info:
            Public Key Algorithm: hss
                hss public key:
                PQ key material:
                    00:00:00:01:00:00:00:05:00:00:00:04:c0:96:12:
                    8b:ea:38:30:78:eb:f6:fb:43:d7:7f:9f:9e:81:39:
                    e2:7c:b9:34:4e:6e:53:19:f0:ee:68:75:85:83:d3:
                    2b:e9:7b:14:46:9e:4e:c5:e3:5a:18:0b:30:e5:13
        X509v3 extensions:
            X509v3 Subject Key Identifier:
                58:15:AB:F4:CF:03:69:02:60:7A:57:4D:C5:D5:B3:72:
                8A:19:21:68
            X509v3 Authority Key Identifier:
                58:15:AB:F4:CF:03:69:02:60:7A:57:4D:C5:D5:B3:72:
                8A:19:21:68
            X509v3 Basic Constraints: critical
                CA:TRUE
            X509v3 Key Usage: critical
                Certificate Sign, CRL Sign
    Signature Algorithm: hss
    Signature Value:
        00:00:00:00:00:00:00:00:00:00:00:04:9c:37:52:ff:b9:d7:
        df:f5:5b:01:ba:50:c2:50:cc:6f:f3:b1:73:df:0c:2a:ea:b3:
        ed:96:1e:ce:e7:58:05:da:8d:a7:77:21:42:32:d9:f9:4a:4d:
        f7:2b:18:2a:1c:5c:69:03:f3:1c:9c:95:6d:31:9a:c9:ca:84:
        4d:ae:b3:8b:c3:71:ac:3f:87:51:be:38:b4:bf:d9:dc:90:1f:
        1e:54:bd:f9:1a:65:70:d4:46:b6:ad:4d:6d:16:b9:fb:29:f4:
        e3:86:42:4a:3f:a4:8f:01:84:9b:44:0b:23:22:9c:97:6d:d5:
        b9:26:39:11:ab:46:82:bd:10:6c:b4:7a:64:ed:c7:40:b0:33:
        f0:b5:81:1c:b4:41:54:9c:30:d9:d2:93:ba:48:8c:4f:d0:25:
        41:60:7b:90:5e:12:20:b7:30:16:16:1e:b7:ee:d8:4b:ee:ed:
        3c:70:fc:ff:36:18:aa:24:23:87:91:65:a8:95:2d:b6:1c:d1:
        02:7b:70:81:8a:18:17:c0:45:62:fe:47:a1:3e:69:54:31:67:
        58:9a:e1:e3:c9:8d:ee:1e:2a:d1:46:75:e9:e4:90:67:01:57:
        92:54:db:b4:ea:de:8b:e7:eb:fc:27:80:9b:d5:da:e0:8e:b0:
        b3:08:ca:6f:a1:1c:f4:40:65:b0:f6:f8:c9:a7:97:04:c8:7c:
        9e:56:ec:2f:4b:cd:45:8b:d7:e6:a7:50:c7:e6:21:2c:17:31:
        23:11:7a:ae:9a:b5:84:5f:e6:5c:82:99:a8:3a:a9:91:87:9a:
        24:5c:83:01:91:7c:fc:cd:be:2e:92:50:fb:12:11:96:08:0d:
        c9:24:0d:bb:6f:fb:59:05:af:7f:96:bc:a3:f4:58:e2:fa:0a:
        4a:f2:4c:f7:b3:1b:81:dd:4a:41:a0:b1:dd:52:4c:bb:6d:c0:
        a8:d9:bb:29:c8:fc:e3:7e:f8:6a:e5:5e:c4:e4:e8:7c:0b:00:
        87:15:75:a2:06:50:97:c6:1f:14:52:79:04:a8:9c:ec:b1:c7:
        6a:46:33:98:b8:63:f7:a7:2c:d4:62:78:94:1c:5d:9d:4f:a6:
        0a:ae:39:50:85:b2:09:8d:62:c9:4c:11:9f:0c:91:a5:ac:2d:
        11:bd:71:b6:0c:ea:34:98:53:fc:2e:cc:7b:a4:9c:2e:7a:a4:
        8d:e2:e8:8c:01:a9:9c:3e:b5:34:77:33:82:01:d4:ef:72:04:
        d6:5b:e5:f6:2c:1b:ae:86:c4:73:02:44:85:d6:f7:ac:a3:e8:
        f6:a9:b5:5c:6d:46:88:da:55:b8:2b:7a:4c:0c:9a:e7:cd:5d:
        62:8a:ca:c8:96:ce:8d:71:7b:d2:c1:0d:9a:35:55:2b:84:3e:
        0e:a5:fa:d6:a0:76:8e:23:b3:df:c9:3b:4f:68:56:1e:e9:3c:
        79:5b:d3:25:54:11:ad:a6:ac:58:11:49:8f:4d:c4:c1:39:99:
        76:3a:a6:d1:2f:57:ad:bf:7c:9d:57:cc:37:0d:29:84:29:7b:
        cb:46:85:c3:81:c5:33:9a:65:c3:2f:01:48:ca:44:6c:f1:84:
        3d:d0:49:c2:c1:05:db:77:4c:b9:72:3d:6f:ce:69:f2:91:c6:
        15:25:8f:da:38:7e:ef:5b:3e:5f:35:ab:a6:78:16:28:42:c1:
        2c:2f:9e:11:53:2c:bd:c4:24:7b:e9:c4:ce:3d:d6:41:c7:5d:
        92:91:c3:37:cb:72:44:d7:0d:70:85:13:0b:ac:b3:0f:b0:e5:
        e3:2e:48:b9:9c:b8:d7:3e:7c:50:69:03:7a:5f:ae:f8:6c:09:
        61:97:6b:ce:cd:e5:f0:55:fe:05:f8:97:1d:9e:81:65:f5:ff:
        9a:7a:8c:96:d8:f8:cf:d8:dc:55:ce:67:7a:00:6b:fd:bb:3f:
        1b:3d:65:94:c1:5a:b6:a0:8e:be:a4:be:26:90:5f:1f:06:d4:
        ea:3f:a6:97:40:8e:bf:18:5c:92:0f:15:e3:05:4a:14:51:1e:
        23:81:ef:cf:f7:a8:88:75:f8:2d:28:37:26:87:27:63:5c:01:
        53:0e:5e:53:d2:a7:18:eb:2f:c0:82:49:05:b0:4d:33:6f:94:
        10:91:77:f8:90:9e:ca:fe:bb:3d:c4:42:d6:89:84:98:42:f4:
        24:b3:b4:db:5e:2b:66:a9:ff:6c:18:d4:79:f8:72:73:53:9b:
        02:ed:04:73:77:a4:68:cf:4b:be:4b:16:50:62:87:f9:49:99:
        e3:a1:0c:42:92:bc:a9:e3:2d:22:82:35:7f:71:15:88:70:6a:
        01:ab:44:64:ad:e5:52:d4:97:ee:bb:44:7b:6e:08:7f:dd:94:
        fd:c9:1c:6b:59:d1:92:51:29:03:ce:ec:bf:41:a5:14:69:54:
        3a:b4:39:d9:44:5d:f1:b2:f4:5c:6b:9f:c9:5f:bb:fc:c8:c7:
        a3:8b:e1:ec:e2:d0:69:5a:40:1c:9c:9d:8a:3d:77:3b:c1:5d:
        c0:72:61:4b:37:c5:96:8c:6d:8b:f8:56:da:ac:3e:3c:72:09:
        ce:f6:c3:fe:5d:cf:37:d9:68:cd:a7:dd:f7:96:63:da:8c:1d:
        df:b8:32:cf:eb:97:11:83:fe:6b:aa:b9:e2:4b:b2:ea:62:73:
        c3:1c:e9:40:90:56:4f:12:c3:ba:f4:2b:d9:1c:50:cc:e0:51:
        d8:eb:bf:67:28:0c:2d:13:8d:b3:6f:13:6a:1d:a7:54:20:ba:
        82:5b:b8:e5:1f:89:f1:67:26:c1:dc:1b:60:57:ed:a6:2c:f2:
        17:01:7f:a5:e7:5c:64:c9:3c:08:f2:cf:48:ec:88:84:ef:03:
        c2:f5:eb:05:31:7d:fe:7f:3c:71:41:28:17:64:5f:b9:ec:54:
        79:d0:b3:98:fb:84:9c:36:8b:43:0b:d4:c9:ec:09:4a:70:13:
        62:f2:36:c8:b4:75:cc:2a:77:08:a0:9d:ef:19:d6:88:dc:e2:
        b2:4e:40:61:71:cb:c7:c3:de:16:6f:49:7f:5e:d5:17:00:00:
        00:05:79:47:12:9f:ce:eb:1d:a8:fd:0d:b0:18:44:6a:ef:54:
        28:46:e4:19:f6:2d:3e:74:bb:9d:36:0a:ae:67:4a:28:7a:1b:
        80:39:a0:08:2a:28:a0:ec:55:ee:55:aa:a1:cc:94:d4:36:1a:
        b3:57:25:30:ad:2c:5e:63:ba:22:fc:aa:7a:59:64:f6:d8:03:
        20:28:71:f9:dc:09:fa:4c:81:b9:64:1b:ad:ea:cb:db:18:17:
        5d:d8:98:bd:d2:8d:c5:04:7c:5b:92:9a:89:f6:bc:d6:55:c7:
        08:5d:3c:58:8e:18:ac:6f:88:a8:d7:9e:d4:ee:5d:f5:21:4e:
        a5:8b:19:5f:e3:f4:66:f9:25:4d:f9:c6:60:62:31:72:5c:34:
        34:67:1a:a7:6a:7d:54:a3:d8:9b:1f:5b:f8:08:41:79:5b:43
]]></artwork>
      <artwork><![CDATA[
-----BEGIN CERTIFICATE-----
MIIGnjCCAXagAwIBAgIJAOiR1gaRT87zMA0GCyqGSIb3DQEJEAMRMD8xCzAJBgNV
BAYTAlVTMQswCQYDVQQIDAJWQTEQMA4GA1UEBwwHSGVybmRvbjERMA8GA1UECgwI
Qm9ndXMgQ0EwHhcNMjQwNTE0MDg1ODExWhcNMzQwNTE0MDg1ODExWjA/MQswCQYD
VQQGEwJVUzELMAkGA1UECAwCVkExEDAOBgNVBAcMB0hlcm5kb24xETAPBgNVBAoM
CEJvZ3VzIENBME4wDQYLKoZIhvcNAQkQAxEDPQAAAAABAAAABQAAAATAlhKL6jgw
eOv2+0PXf5+egTnifLk0Tm5TGfDuaHWFg9Mr6XsURp5OxeNaGAsw5ROjYzBhMB0G
A1UdDgQWBBRYFav0zwNpAmB6V03F1bNyihkhaDAfBgNVHSMEGDAWgBRYFav0zwNp
AmB6V03F1bNyihkhaDAPBgNVHRMBAf8EBTADAQH/MA4GA1UdDwEB/wQEAwIBBjAN
BgsqhkiG9w0BCRADEQOCBREAAAAAAAAAAAAAAAAEnDdS/7nX3/VbAbpQwlDMb/Ox
c98MKuqz7ZYezudYBdqNp3chQjLZ+UpN9ysYKhxcaQPzHJyVbTGaycqETa6zi8Nx
rD+HUb44tL/Z3JAfHlS9+RplcNRGtq1NbRa5+yn044ZCSj+kjwGEm0QLIyKcl23V
uSY5EatGgr0QbLR6ZO3HQLAz8LWBHLRBVJww2dKTukiMT9AlQWB7kF4SILcwFhYe
t+7YS+7tPHD8/zYYqiQjh5FlqJUtthzRAntwgYoYF8BFYv5HoT5pVDFnWJrh48mN
7h4q0UZ16eSQZwFXklTbtOrei+fr/CeAm9Xa4I6wswjKb6Ec9EBlsPb4yaeXBMh8
nlbsL0vNRYvX5qdQx+YhLBcxIxF6rpq1hF/mXIKZqDqpkYeaJFyDAZF8/M2+LpJQ
+xIRlggNySQNu2/7WQWvf5a8o/RY4voKSvJM97Mbgd1KQaCx3VJMu23AqNm7Kcj8
4374auVexOTofAsAhxV1ogZQl8YfFFJ5BKic7LHHakYzmLhj96cs1GJ4lBxdnU+m
Cq45UIWyCY1iyUwRnwyRpawtEb1xtgzqNJhT/C7Me6ScLnqkjeLojAGpnD61NHcz
ggHU73IE1lvl9iwbrobEcwJEhdb3rKPo9qm1XG1GiNpVuCt6TAya581dYorKyJbO
jXF70sENmjVVK4Q+DqX61qB2jiOz38k7T2hWHuk8eVvTJVQRraasWBFJj03EwTmZ
djqm0S9Xrb98nVfMNw0phCl7y0aFw4HFM5plwy8BSMpEbPGEPdBJwsEF23dMuXI9
b85p8pHGFSWP2jh+71s+XzWrpngWKELBLC+eEVMsvcQke+nEzj3WQcddkpHDN8ty
RNcNcIUTC6yzD7Dl4y5IuZy41z58UGkDel+u+GwJYZdrzs3l8FX+BfiXHZ6BZfX/
mnqMltj4z9jcVc5negBr/bs/Gz1llMFatqCOvqS+JpBfHwbU6j+ml0COvxhckg8V
4wVKFFEeI4Hvz/eoiHX4LSg3JocnY1wBUw5eU9KnGOsvwIJJBbBNM2+UEJF3+JCe
yv67PcRC1omEmEL0JLO0214rZqn/bBjUefhyc1ObAu0Ec3ekaM9LvksWUGKH+UmZ
46EMQpK8qeMtIoI1f3EViHBqAatEZK3lUtSX7rtEe24If92U/ckca1nRklEpA87s
v0GlFGlUOrQ52URd8bL0XGufyV+7/MjHo4vh7OLQaVpAHJydij13O8FdwHJhSzfF
loxti/hW2qw+PHIJzvbD/l3PN9lozafd95Zj2owd37gyz+uXEYP+a6q54kuy6mJz
wxzpQJBWTxLDuvQr2RxQzOBR2Ou/ZygMLRONs28Tah2nVCC6glu45R+J8Wcmwdwb
YFftpizyFwF/pedcZMk8CPLPSOyIhO8DwvXrBTF9/n88cUEoF2RfuexUedCzmPuE
nDaLQwvUyewJSnATYvI2yLR1zCp3CKCd7xnWiNzisk5AYXHLx8PeFm9Jf17VFwAA
AAV5RxKfzusdqP0NsBhEau9UKEbkGfYtPnS7nTYKrmdKKHobgDmgCCoooOxV7lWq
ocyU1DYas1clMK0sXmO6Ivyqellk9tgDIChx+dwJ+kyBuWQbrerL2xgXXdiYvdKN
xQR8W5Kaifa81lXHCF08WI4YrG+IqNee1O5d9SFOpYsZX+P0ZvklTfnGYGIxclw0
NGcap2p9VKPYmx9b+AhBeVtD
-----END CERTIFICATE-----
]]></artwork>
    </section>
    <section anchor="xmss-x509-v3-certificate-example">
      <name>XMSS X.509 v3 Certificate Example</name>
      <t>This section shows a self-signed X.509 v3 certificate using XMSS.</t>
      <artwork><![CDATA[
Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number:
            54:7e:64:70:29:9e:03:c5:7a:a5:5c:78:d1:27:87:8c:
            54:35:17:5d
        Signature Algorithm: xmss
        Issuer: C = FR, L = Paris, O = Bogus XMSS CA
        Validity
            Not Before: Jul 10 08:27:24 2024 GMT
            Not After : Jul  8 08:27:24 2034 GMT
        Subject: C = FR, L = Paris, O = Bogus XMSS CA
        Subject Public Key Info:
            Public Key Algorithm: xmss
                xmss public key:
                PQ key material:
                    00:00:00:01:2b:eb:bf:66:14:de:6f:96:5b:4d:2a:
                    50:00:7b:ad:5c:22:b0:13:79:72:02:14:a9:5f:fc:
                    96:e0:9b:78:8e:d6:be:8c:1c:70:3c:d8:dd:78:b2:
                    1a:14:47:be:1f:0d:74:72:3f:36:76:c2:cb:19:ad:
                    29:90:0b:82:de:9b:7f:df
        X509v3 extensions:
            X509v3 Subject Key Identifier:
                62:CE:35:A5:47:77:FF:21:87:2E:BC:2D:27:E7:8E:F4:
                35:6B:CF:D8
            X509v3 Authority Key Identifier:
                62:CE:35:A5:47:77:FF:21:87:2E:BC:2D:27:E7:8E:F4:
                35:6B:CF:D8
            X509v3 Basic Constraints: critical
                CA:TRUE
            X509v3 Key Usage: critical
                Certificate Sign, CRL Sign
    Signature Algorithm: xmss
    Signature Value:
        00:00:00:00:e5:88:a8:b8:73:ad:4d:92:f8:5c:81:c5:8a:63:
        57:6a:a7:3b:54:aa:b6:06:8a:d9:f1:c2:0b:c8:27:1e:4b:a2:
        cf:e2:da:44:ea:e8:f2:40:a8:b9:54:9c:49:36:12:24:df:74:
        ad:e5:29:ef:4f:da:88:0d:21:5d:3b:64:63:27:d0:84:b5:95:
        7a:30:18:37:cd:34:17:dd:ac:9d:9e:48:db:74:07:79:84:21:
        5a:f0:26:cd:21:64:7b:77:33:48:58:67:9b:2c:b2:85:6d:cc:
        ec:31:4b:2f:51:55:3a:85:e1:ca:04:15:ce:6e:47:39:f5:e9:
        31:45:41:ed:71:c6:4f:96:f5:ae:64:6a:bd:72:d0:8c:17:02:
        99:10:1d:14:34:ca:e5:47:e3:f7:66:96:96:11:d5:97:76:76:
        83:f1:84:a5:b6:00:5e:3e:67:97:7a:32:dc:c8:eb:4c:29:46:
        77:99:d6:da:45:e6:7b:8c:45:6d:b5:29:6b:fd:98:a2:89:8d:
        0c:30:42:f5:0b:7c:97:c5:b1:1d:e2:da:67:a9:48:a4:9e:29:
        f4:60:3f:4d:1d:48:83:82:38:ef:fa:cb:1d:86:11:a1:15:94:
        fb:d5:ee:68:f9:44:b9:3d:54:70:f3:be:17:8d:d7:2e:85:2d:
        5c:d0:a0:c5:99:52:cc:79:e7:1c:18:d9:6e:3d:0f:6c:05:51:
        33:28:35:e2:02:59:5f:1f:ed:78:0a:c6:62:f0:7d:fe:73:96:
        03:4c:b4:42:e3:00:c2:d7:cb:eb:51:10:c4:0c:64:b8:37:fe:
        85:d0:8e:11:6d:a6:16:77:b1:1e:01:d9:1e:f3:10:9c:dd:01:
        bc:38:75:5e:8f:58:9e:5b:6c:7b:0a:41:08:59:35:a9:3a:83:
        19:e0:7d:a1:f5:cf:a3:1c:4e:07:e1:ad:03:95:f2:d3:8b:79:
        33:f8:52:22:53:1b:1e:32:9a:61:3f:c4:7c:9a:e8:d5:b5:28:
        f1:84:65:d5:c1:fc:4d:16:93:88:93:69:ca:fa:94:a0:95:4e:
        23:ae:1e:60:e0:e8:b4:bf:ff:16:95:71:0f:31:74:bb:be:b8:
        5a:eb:24:95:8b:95:28:13:cd:e3:a9:65:f7:f5:6e:9b:a9:a9:
        7a:05:ce:ab:f0:54:62:d9:12:f8:a1:1a:68:df:af:15:8f:8a:
        df:67:27:c9:ed:bd:e1:81:a6:8d:9a:84:f3:91:36:d9:89:74:
        8e:ef:84:dc:5c:03:1a:08:e4:d7:f0:72:fc:6d:8a:01:34:94:
        e5:ff:08:51:1b:80:5f:e7:07:d8:9f:25:e4:1d:c3:f8:e5:d0:
        9c:50:cf:66:71:f9:cc:f7:c0:a7:d0:66:01:b7:17:a0:5f:66:
        97:a4:ff:62:ac:1c:a0:63:0d:30:28:e9:90:d5:59:a4:48:d8:
        07:87:02:4b:3f:68:23:a5:04:dc:b3:d7:45:f6:dc:b0:ec:c6:
        90:a6:1c:a1:f8:7e:84:ba:63:7e:5a:64:14:78:58:f5:75:c0:
        f5:e1:1d:bd:49:57:c0:40:08:07:99:7f:43:2e:e2:25:d8:ed:
        a3:1a:e3:78:f1:78:af:02:49:54:36:59:8e:d3:72:a5:0b:52:
        32:bd:17:a2:cf:e1:47:21:28:3d:ba:b6:24:d9:18:f9:44:73:
        35:ed:29:a4:18:bc:ed:68:cd:4a:9a:34:cb:1a:2f:b3:5f:ba:
        73:9b:18:ee:7a:a8:92:25:65:25:81:04:63:1c:22:2b:b8:ba:
        81:21:bc:f9:9d:a8:78:98:75:bc:ed:4a:c6:b7:6f:c0:91:24:
        eb:1d:f9:5d:e0:e3:78:4e:05:f6:34:0f:7b:41:54:49:20:a2:
        30:66:94:f1:da:c1:6c:3f:5e:10:92:92:a3:0c:7e:e8:8b:26:
        11:1c:d7:68:c9:31:79:b3:a4:d5:63:00:68:c3:e3:86:2d:09:
        92:4b:2d:63:7d:b8:03:a4:4c:60:b4:2c:12:d5:0b:9f:16:28:
        ea:88:2f:bb:1c:19:0b:0f:40:3d:67:e8:0b:fa:c6:e3:39:44:
        b2:bd:8a:3f:21:dd:aa:ec:a3:8c:48:dd:4c:99:43:86:d7:48:
        81:6b:e5:b9:bb:59:9f:1c:0f:3f:11:f7:7c:4b:67:a8:95:c2:
        7c:cb:3b:66:b0:79:a6:55:6f:6d:b0:29:8a:5e:7b:ee:30:68:
        f3:dd:41:29:91:f6:79:71:ae:8d:21:70:78:1d:5d:d2:f7:cf:
        e7:42:38:d1:8c:52:a6:a6:f6:b1:38:b1:2b:23:81:e1:1f:21:
        6d:99:3f:10:eb:b1:a9:73:b8:3e:31:99:cc:dd:2b:df:58:27:
        db:0b:5a:29:99:8f:b1:9f:e9:31:42:d0:26:db:53:b7:7e:30:
        41:95:c3:f0:07:83:bb:b0:63:b5:16:48:f2:a6:60:2f:32:5d:
        22:a1:da:76:4e:37:26:53:0d:95:7b:2d:b9:05:2f:93:2b:d4:
        df:c1:02:5b:f7:a5:a2:4f:11:5c:80:f4:f0:bd:c7:ea:3c:db:
        6f:e2:eb:6c:7f:c3:58:d9:31:77:4b:4d:f7:ce:bb:d6:c8:64:
        a3:01:d5:f9:a4:8d:e8:f0:ee:09:06:2c:0b:3c:ac:0a:57:d8:
        e4:81:79:ea:4a:bd:51:03:88:4c:d0:4c:0b:c4:0c:7e:2d:e7:
        df:1b:67:62:c0:d1:9c:ad:bb:d3:f0:75:dd:83:aa:70:99:2c:
        19:78:3d:26:2b:47:6f:24:c1:60:02:1e:4b:75:04:91:1f:08:
        1c:b3:79:a0:9b:db:fb:5d:3f:c7:e3:09:1f:41:3e:64:bb:ad:
        19:3d:35:e1:a6:f4:69:0b:a2:04:37:42:95:c6:c7:e5:f4:56:
        0e:67:5b:78:34:bb:07:f1:8f:e7:73:5b:87:d7:df:c9:2d:8d:
        8c:42:76:87:15:85:4b:23:03:20:34:e1:1b:f6:0c:1e:84:53:
        d9:1b:4e:d9:31:43:38:3b:88:12:84:d8:2a:38:b1:ce:0f:c7:
        07:d4:63:2d:97:89:1c:b3:44:99:eb:d4:df:32:74:be:0d:63:
        11:22:fd:fa:8e:e2:0b:56:12:56:0c:46:16:ad:44:10:26:98:
        dc:cf:c9:95:67:3e:11:c1:76:fa:b8:12:ea:96:f6:d9:91:ac:
        bf:49:b9:1c:8e:15:05:53:ac:9e:04:d2:5b:b8:87:bf:81:50:
        f7:02:a4:c0:9c:18:0f:45:ac:7a:82:cf:46:15:42:40:09:32:
        89:a5:ea:90:a5:99:68:f9:93:0c:7b:d6:7a:a8:e9:51:e2:90:
        9e:b9:ed:21:db:d9:7e:de:dc:62:6b:44:6b:9f:81:c5:77:39:
        8e:1d:78:30:de:dc:53:80:e0:c3:fa:fa:94:68:28:91:98:86:
        ff:86:04:a9:bd:58:7c:31:37:1f:db:9a:29:f3:c1:48:10:20:
        71:5f:fc:35:13:eb:7b:12:e2:7d:1c:cc:97:fe:8f:5c:a2:dd:
        f6:d2:a3:b2:ea:51:b3:ef:b1:1e:79:0b:00:53:f4:f2:52:75:
        5a:d7:17:c5:31:a0:54:4e:2b:28:2c:4f:6b:7a:27:3a:2c:04:
        da:b3:1d:04:4e:a4:4e:94:5c:a8:91:70:ab:c0:4b:75:9f:b3:
        6a:a9:4e:8a:22:e9:7f:fd:ec:53:e7:6a:6d:32:0b:8b:ab:4c:
        e7:7d:72:ec:04:62:1c:1a:45:1e:33:8e:37:ae:6a:2f:c8:fb:
        f3:69:ed:11:01:f3:f4:57:e9:29:d5:3b:0c:9c:0c:c4:cb:c3:
        38:5c:01:e7:d6:31:c3:d8:ce:24:d7:be:71:9b:c8:96:13:ca:
        5c:5d:e4:92:40:af:86:a0:4b:ff:a7:55:39:70:fd:ac:0a:e1:
        87:c7:01:4b:c3:41:36:c6:c6:33:8f:4f:25:4a:8d:70:92:ac:
        7c:95:cc:49:a9:dc:d6:6a:67:52:a5:5b:7f:2f:bb:91:e3:be:
        d6:28:fc:22:d0:72:66:e8:09:73:a7:23:c6:a6:89:38:0b:e5:
        d0:b3:f1:40:38:9c:4d:17:96:11:17:44:ef:e3:94:51:91:4c:
        5d:fe:d9:ed:c3:76:a0:2d:3b:dc:8d:b9:31:15:f6:75:58:74:
        2f:57:b4:29:21:29:6d:5f:eb:06:71:0a:f4:db:ff:c6:2f:16:
        73:a7:76:6b:d0:5b:a7:21:5c:fd:f0:11:e8:6f:9b:d0:c9:c9:
        fe:35:76:4a:4a:63:9b:ba:48:ac:af:4f:91:67:9c:5c:47:d8:
        e3:2d:03:12:5e:f1:cb:56:34:75:69:95:ad:68:96:6c:e7:4a:
        91:72:fb:9b:ba:e8:92:56:fb:9a:5b:5d:3b:9d:d3:c5:c4:52:
        42:1b:f9:4a:47:42:dd:77:49:da:2b:bd:d7:94:5f:7b:b8:64:
        b9:06:32:7c:ea:d1:36:f6:95:b8:57:41:1b:6e:66:31:2c:ee:
        87:7a:5c:19:2f:d8:95:4a:16:93:48:f3:97:25:3d:24:61:1e:
        d0:63:37:ee:3a:c9:a3:46:c5:94:a0:7e:24:cc:7f:72:8d:14:
        9e:3c:33:ec:cd:9a:dd:b5:08:90:98:19:95:85:38:ff:ff:d2:
        1e:bf:a6:c4:97:13:2b:3d:47:e9:57:59:d3:7d:99:01:6e:53:
        4d:c0:82:97:fb:89:d6:7c:b7:23:0e:7d:6e:23:88:53:06:8f:
        16:ff:40:0a:1b:cd:d5:1e:91:01:3e:77:3a:5f:c1:57:3a:7b:
        c6:d5:51:d7:e2:ec:89:12:6b:9d:03:e4:9d:bb:7d:4e:02:bf:
        67:8d:03:ca:90:56:f0:9a:97:4b:02:2d:4c:31:89:82:76:97:
        fe:2f:d5:0a:3d:ea:0d:38:6c:30:75:5f:ae:91:53:d7:45:64:
        df:ba:0b:22:80:44:85:6d:0e:5c:29:7f:82:9e:54:a3:7a:95:
        be:96:79:66:9d:5b:a2:d6:2e:47:c6:99:7d:2b:32:dc:f2:b6:
        02:91:6d:63:d4:93:45:60:c4:42:71:10:9e:fb:90:2f:e6:75:
        71:ce:78:70:c1:da:ff:e1:47:fe:79:2b:8e:9a:81:bf:dd:02:
        e3:78:39:71:17:b3:23:14:11:9d:29:8e:21:a1:98:b0:ac:03:
        5a:6c:9e:62:64:ef:4f:03:ca:37:a6:ed:e4:78:d5:0d:99:29:
        f5:5c:61:e6:48:cb:97:0e:5e:f9:2c:f6:b6:c7:7c:0c:a4:f7:
        1a:f7:67:b5:5c:03:bf:bf:7a:e2:4d:a2:9b:5d:5d:5f:51:d0:
        d6:52:8f:2a:20:68:08:bb:f0:9c:05:0e:ef:b3:49:0c:2a:1d:
        8f:f9:03:b7:61:09:71:88:7d:e2:8c:e4:b8:ac:98:1b:c3:80:
        55:a1:6b:dd:13:a2:29:4f:93:93:d3:d5:01:31:3f:7b:39:0e:
        3a:57:6c:eb:5c:6a:5f:1b:ad:97:bd:97:23:18:91:05:0e:2b:
        b4:b1:11:ee:f8:58:c7:08:d0:de:a2:3e:ba:54:8d:3d:63:da:
        91:50:3a:24:8d:19:18:23:2e:cf:30:8d:5d:e3:e7:02:93:fa:
        c8:f8:ea:05:e6:eb:06:80:90:4d:15:58:3d:26:98:13:4b:b0:
        ac:dd:90:2e:d0:e1:eb:71:32:83:5d:2a:a9:b9:b5:24:fc:e9:
        ec:18:ca:c9:a1:05:59:3e:fa:af:ed:4e:86:b1:fe:40:47:9b:
        42:77:af:9c:2b:a0:e2:3e:fd:51:ab:02:77:e8:f1:39:45:aa:
        54:b6:14:d4:14:20:fc:36:81:e6:04:98:8a:a0:c0:8a:cf:ae:
        f6:b5:dc:b7:eb:26:86:d3:cf:1c:38:65:54:04:b1:b5:09:48:
        f5:2d:07:ba:f8:eb:49:bd:d9:b1:54:ea:ac:c2:0d:20:10:79:
        c1:cb:e9:dc:2d:ff:55:50:4f:f6:05:02:78:31:33:6f:15:7e:
        24:5a:66:23:70:b3:b2:0c:17:39:ce:15:38:c5:ff:60:16:38:
        60:74:72:c9:70:d8:59:b7:80:7f:da:f6:67:3f:d0:ba:be:1b:
        a1:87:da:92:2d:a3:6c:99:29:57:aa:cb:d1:8d:66:f1:2d:c9:
        56:60:24:56:4b:19:9f:f5:65:84:89:86:7d:4d:8b:f8:5b:60:
        dd:af:2d:66:76:6c:66:d9:c6:f5:39:25:6c:e5:7b:43:97:64:
        5c:c5:20:1e:3d:b5:dc:92:b2:9c:d8:1b:1b:e0:bc:44:7b:9c:
        95:c5:53:48:91:b2:a5:46:16:bf:50:af:a5:44:cc:54:78:3f:
        ed:20:d8:2e:0b:41:3d:f1:04:9d:df:3c:4a:d7:81:04:ff:8c:
        b7:79:f8:51:8d:b7:2e:ac:2c:54:e6:fc:43:76:8e:f9:be:8c:
        b8:5c:ad:c4:13:af:b0:6e:3b:d1:82:57:1e:f5:52:84:ca:cc:
        d2:68:f3:2d:04:ff:27:0a:e6:a2:fa:c0:a9:97:d6:64:45:18:
        5c:6f:9e:c1:64:22:66:db:56:02:c3:a8:57:fc:87:1b:5c:43:
        15:8e:58:fc:f2:00:0b:4f:6a:4b:a0:5c:da:f2:e5:1b:82:4a:
        6b:ef:db:63:d7:7d:93:1d:2f:20:78:37:17:22:82:cd:6b:c1:
        83:61:05:81:99:0c:25:29:d6:5f:22:bc:06:67:7d:67
]]></artwork>
      <artwork><![CDATA[
-----BEGIN CERTIFICATE-----
MIILSDCCAW+gAwIBAgIUVH5kcCmeA8V6pVx40SeHjFQ1F10wCgYIKwYBBQUHBiIw
NTELMAkGA1UEBhMCRlIxDjAMBgNVBAcMBVBhcmlzMRYwFAYDVQQKDA1Cb2d1cyBY
TVNTIENBMB4XDTI0MDcxMDA4MjcyNFoXDTM0MDcwODA4MjcyNFowNTELMAkGA1UE
BhMCRlIxDjAMBgNVBAcMBVBhcmlzMRYwFAYDVQQKDA1Cb2d1cyBYTVNTIENBMFMw
CgYIKwYBBQUHBiIDRQAAAAABK+u/ZhTeb5ZbTSpQAHutXCKwE3lyAhSpX/yW4Jt4
jta+jBxwPNjdeLIaFEe+Hw10cj82dsLLGa0pkAuC3pt/36NjMGEwHQYDVR0OBBYE
FGLONaVHd/8hhy68LSfnjvQ1a8/YMB8GA1UdIwQYMBaAFGLONaVHd/8hhy68LSfn
jvQ1a8/YMA8GA1UdEwEB/wQFMAMBAf8wDgYDVR0PAQH/BAQDAgEGMAoGCCsGAQUF
BwYiA4IJxQAAAAAA5YiouHOtTZL4XIHFimNXaqc7VKq2BorZ8cILyCceS6LP4tpE
6ujyQKi5VJxJNhIk33St5SnvT9qIDSFdO2RjJ9CEtZV6MBg3zTQX3aydnkjbdAd5
hCFa8CbNIWR7dzNIWGebLLKFbczsMUsvUVU6heHKBBXObkc59ekxRUHtccZPlvWu
ZGq9ctCMFwKZEB0UNMrlR+P3ZpaWEdWXdnaD8YSltgBePmeXejLcyOtMKUZ3mdba
ReZ7jEVttSlr/ZiiiY0MMEL1C3yXxbEd4tpnqUiknin0YD9NHUiDgjjv+ssdhhGh
FZT71e5o+US5PVRw874XjdcuhS1c0KDFmVLMeeccGNluPQ9sBVEzKDXiAllfH+14
CsZi8H3+c5YDTLRC4wDC18vrURDEDGS4N/6F0I4RbaYWd7EeAdke8xCc3QG8OHVe
j1ieW2x7CkEIWTWpOoMZ4H2h9c+jHE4H4a0DlfLTi3kz+FIiUxseMpphP8R8mujV
tSjxhGXVwfxNFpOIk2nK+pSglU4jrh5g4Oi0v/8WlXEPMXS7vrha6ySVi5UoE83j
qWX39W6bqal6Bc6r8FRi2RL4oRpo368Vj4rfZyfJ7b3hgaaNmoTzkTbZiXSO74Tc
XAMaCOTX8HL8bYoBNJTl/whRG4Bf5wfYnyXkHcP45dCcUM9mcfnM98Cn0GYBtxeg
X2aXpP9irBygYw0wKOmQ1VmkSNgHhwJLP2gjpQTcs9dF9tyw7MaQphyh+H6EumN+
WmQUeFj1dcD14R29SVfAQAgHmX9DLuIl2O2jGuN48XivAklUNlmO03KlC1IyvRei
z+FHISg9urYk2Rj5RHM17SmkGLztaM1KmjTLGi+zX7pzmxjueqiSJWUlgQRjHCIr
uLqBIbz5nah4mHW87UrGt2/AkSTrHfld4ON4TgX2NA97QVRJIKIwZpTx2sFsP14Q
kpKjDH7oiyYRHNdoyTF5s6TVYwBow+OGLQmSSy1jfbgDpExgtCwS1QufFijqiC+7
HBkLD0A9Z+gL+sbjOUSyvYo/Id2q7KOMSN1MmUOG10iBa+W5u1mfHA8/Efd8S2eo
lcJ8yztmsHmmVW9tsCmKXnvuMGjz3UEpkfZ5ca6NIXB4HV3S98/nQjjRjFKmpvax
OLErI4HhHyFtmT8Q67Gpc7g+MZnM3SvfWCfbC1opmY+xn+kxQtAm21O3fjBBlcPw
B4O7sGO1FkjypmAvMl0iodp2TjcmUw2Vey25BS+TK9TfwQJb96WiTxFcgPTwvcfq
PNtv4utsf8NY2TF3S033zrvWyGSjAdX5pI3o8O4JBiwLPKwKV9jkgXnqSr1RA4hM
0EwLxAx+LeffG2diwNGcrbvT8HXdg6pwmSwZeD0mK0dvJMFgAh5LdQSRHwgcs3mg
m9v7XT/H4wkfQT5ku60ZPTXhpvRpC6IEN0KVxsfl9FYOZ1t4NLsH8Y/nc1uH19/J
LY2MQnaHFYVLIwMgNOEb9gwehFPZG07ZMUM4O4gShNgqOLHOD8cH1GMtl4kcs0SZ
69TfMnS+DWMRIv36juILVhJWDEYWrUQQJpjcz8mVZz4RwXb6uBLqlvbZkay/Sbkc
jhUFU6yeBNJbuIe/gVD3AqTAnBgPRax6gs9GFUJACTKJpeqQpZlo+ZMMe9Z6qOlR
4pCeue0h29l+3txia0Rrn4HFdzmOHXgw3txTgODD+vqUaCiRmIb/hgSpvVh8MTcf
25op88FIECBxX/w1E+t7EuJ9HMyX/o9cot320qOy6lGz77EeeQsAU/TyUnVa1xfF
MaBUTisoLE9reic6LATasx0ETqROlFyokXCrwEt1n7NqqU6KIul//exT52ptMguL
q0znfXLsBGIcGkUeM443rmovyPvzae0RAfP0V+kp1TsMnAzEy8M4XAHn1jHD2M4k
175xm8iWE8pcXeSSQK+GoEv/p1U5cP2sCuGHxwFLw0E2xsYzj08lSo1wkqx8lcxJ
qdzWamdSpVt/L7uR477WKPwi0HJm6AlzpyPGpok4C+XQs/FAOJxNF5YRF0Tv45RR
kUxd/tntw3agLTvcjbkxFfZ1WHQvV7QpISltX+sGcQr02//GLxZzp3Zr0FunIVz9
8BHob5vQycn+NXZKSmObukisr0+RZ5xcR9jjLQMSXvHLVjR1aZWtaJZs50qRcvub
uuiSVvuaW107ndPFxFJCG/lKR0Ldd0naK73XlF97uGS5BjJ86tE29pW4V0EbbmYx
LO6HelwZL9iVShaTSPOXJT0kYR7QYzfuOsmjRsWUoH4kzH9yjRSePDPszZrdtQiQ
mBmVhTj//9Iev6bElxMrPUfpV1nTfZkBblNNwIKX+4nWfLcjDn1uI4hTBo8W/0AK
G83VHpEBPnc6X8FXOnvG1VHX4uyJEmudA+Sdu31OAr9njQPKkFbwmpdLAi1MMYmC
dpf+L9UKPeoNOGwwdV+ukVPXRWTfugsigESFbQ5cKX+CnlSjepW+lnlmnVui1i5H
xpl9KzLc8rYCkW1j1JNFYMRCcRCe+5Av5nVxznhwwdr/4Uf+eSuOmoG/3QLjeDlx
F7MjFBGdKY4hoZiwrANabJ5iZO9PA8o3pu3keNUNmSn1XGHmSMuXDl75LPa2x3wM
pPca92e1XAO/v3riTaKbXV1fUdDWUo8qIGgIu/CcBQ7vs0kMKh2P+QO3YQlxiH3i
jOS4rJgbw4BVoWvdE6IpT5OT09UBMT97OQ46V2zrXGpfG62XvZcjGJEFDiu0sRHu
+FjHCNDeoj66VI09Y9qRUDokjRkYIy7PMI1d4+cCk/rI+OoF5usGgJBNFVg9JpgT
S7Cs3ZAu0OHrcTKDXSqpubUk/OnsGMrJoQVZPvqv7U6Gsf5AR5tCd6+cK6DiPv1R
qwJ36PE5RapUthTUFCD8NoHmBJiKoMCKz672tdy36yaG088cOGVUBLG1CUj1LQe6
+OtJvdmxVOqswg0gEHnBy+ncLf9VUE/2BQJ4MTNvFX4kWmYjcLOyDBc5zhU4xf9g
FjhgdHLJcNhZt4B/2vZnP9C6vhuhh9qSLaNsmSlXqsvRjWbxLclWYCRWSxmf9WWE
iYZ9TYv4W2Ddry1mdmxm2cb1OSVs5XtDl2RcxSAePbXckrKc2Bsb4LxEe5yVxVNI
kbKlRha/UK+lRMxUeD/tINguC0E98QSd3zxK14EE/4y3efhRjbcurCxU5vxDdo75
voy4XK3EE6+wbjvRglce9VKEyszSaPMtBP8nCuai+sCpl9ZkRRhcb57BZCJm21YC
w6hX/IcbXEMVjlj88gALT2pLoFza8uUbgkpr79tj132THS8geDcXIoLNa8GDYQWB
mQwlKdZfIrwGZ31n
-----END CERTIFICATE-----
]]></artwork>
    </section>
    <section anchor="xmssmt-x509-v3-certificate-example">
      <name>XMSS^MT X.509 v3 Certificate Example</name>
      <t>This section shows a self-signed X.509 v3 certificate using XMSS^MT.</t>
      <artwork><![CDATA[
Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number:
            5c:22:ad:8a:06:51:9e:67:02:6a:2d:43:3e:8b:c7:23:
            43:77:80:c8
        Signature Algorithm: xmssmt
        Issuer: C = FR, L = Paris, O = Bogus XMSSMT CA
        Validity
            Not Before: Jul 10 08:28:04 2024 GMT
            Not After : Jul  8 08:28:04 2034 GMT
        Subject: C = FR, L = Paris, O = Bogus XMSSMT CA
        Subject Public Key Info:
            Public Key Algorithm: xmssmt
                xmssmt public key:
                PQ key material:
                    00:00:00:01:4b:a7:89:11:6f:fc:1d:fb:d3:e7:71:
                    73:b8:a2:48:ef:53:b9:9d:1f:c6:8a:7c:be:4f:8a:
                    29:fa:41:fd:bd:da:20:7f:f6:3b:b0:c5:b8:a7:c2:
                    f2:5a:f2:26:14:eb:36:f0:26:2f:87:74:fb:0e:d5:
                    7e:17:a0:d1:4d:b6:cf:51
        X509v3 extensions:
            X509v3 Subject Key Identifier:
                7C:7D:59:B8:95:61:D5:03:6A:1E:3D:F1:24:AB:1D:ED:
                04:CD:DB:5F
            X509v3 Authority Key Identifier:
                7C:7D:59:B8:95:61:D5:03:6A:1E:3D:F1:24:AB:1D:ED:
                04:CD:DB:5F
            X509v3 Basic Constraints: critical
                CA:TRUE
            X509v3 Key Usage: critical
                Certificate Sign, CRL Sign
    Signature Algorithm: xmssmt
    Signature Value:
        00:00:00:57:c4:98:89:ff:d9:0a:8e:6e:6f:16:95:8c:ec:35:
        42:21:c2:ca:56:ed:f8:81:f1:b2:4f:2b:6d:73:f4:37:55:fc:
        f4:4e:15:eb:6b:90:de:34:fe:d6:96:70:94:8d:c1:e7:4a:32:
        49:30:3a:40:a4:67:d2:fb:da:f8:d8:a1:7a:48:22:1c:e3:98:
        bc:d0:68:85:29:c9:e5:f7:5c:56:d8:9c:80:be:68:ed:11:eb:
        39:0f:ef:cb:09:b2:28:30:a6:2b:05:bc:de:11:22:be:c4:dc:
        08:9a:3d:b4:49:37:1f:54:5e:5f:2d:93:62:b0:95:c5:5d:23:
        92:f3:55:40:78:19:00:56:9e:a2:f1:0e:4b:ae:75:d6:92:09:
        b1:79:ec:c9:18:67:19:09:86:83:74:5d:0a:06:ab:da:f0:af:
        02:97:4d:d7:73:06:8b:a2:84:c7:09:af:dd:8b:15:39:e4:30:
        9f:c9:00:25:a8:33:4d:de:e8:25:b6:35:0b:51:bf:7a:34:a7:
        e8:84:e8:fa:39:5b:aa:37:6e:95:89:ac:26:4a:4e:ca:be:29:
        08:4b:3c:28:a7:85:6a:ad:5a:d2:93:eb:12:e1:9a:87:1c:40:
        3b:cf:15:6c:43:4e:88:21:54:52:7e:0d:6d:17:29:8d:15:6f:
        ef:42:5a:a9:25:d0:97:80:61:31:22:a4:9f:25:17:51:ad:0b:
        a1:cb:93:b4:f5:a6:b0:22:1b:6d:50:64:2a:48:bd:05:16:88:
        00:e3:7b:56:d0:03:b3:7a:2d:6a:0b:f3:de:a2:8c:6e:81:80:
        2c:8f:e9:d8:78:ed:5b:99:c9:13:d1:b6:eb:78:c3:40:2b:a1:
        7a:84:0a:ba:12:87:5e:1d:38:24:22:8f:c0:a3:65:1c:1c:ce:
        2d:8e:e5:2f:1f:be:93:5c:fe:1c:cd:a8:9d:7e:7e:cf:18:e2:
        9c:c5:54:dc:62:61:74:23:55:64:66:21:96:4c:a7:2e:8a:94:
        a6:35:10:a5:e8:5e:6e:91:ac:a8:cb:ed:51:2b:66:45:03:f5:
        87:ed:4d:8c:4e:6d:54:80:a1:33:8a:84:9d:23:31:90:c6:05:
        11:a7:9d:bd:51:0a:73:47:bc:08:49:11:b3:98:ff:01:14:69:
        d7:c0:a0:0c:55:e4:5e:e2:fa:84:ac:27:b3:85:2c:99:71:52:
        9c:33:f8:9d:8c:d2:13:bc:6e:18:79:15:a7:02:ee:15:eb:27:
        d8:af:24:38:02:9c:ca:30:f3:e2:30:41:2f:62:a2:2c:a5:81:
        1b:71:6d:b1:94:bd:c6:3d:9e:5e:51:45:de:5b:f4:d7:e6:35:
        e7:d8:7c:d5:98:ec:7e:0e:f8:9d:c1:a7:7b:b3:65:b1:a1:4b:
        2d:ec:d9:12:45:6b:1f:0b:1c:6b:3b:0a:66:76:39:f4:cc:9b:
        e1:b7:17:f7:53:fc:c3:a6:18:f7:2e:45:52:b1:18:99:75:d1:
        69:bb:77:c8:1a:84:5f:06:b5:8b:cb:02:b0:b2:0f:bf:17:18:
        65:3d:a7:72:5b:71:9f:92:7e:3a:df:84:cc:65:5c:c4:5b:70:
        fd:cc:38:9e:12:6e:f9:ff:1f:02:fc:ca:f5:68:86:fc:ca:71:
        f1:3d:7b:32:b4:d4:c3:a2:20:16:3f:12:07:71:95:3b:d4:b1:
        1e:fc:8c:1f:34:8c:c8:ab:8c:bb:75:93:c1:1a:d2:85:3e:9a:
        e6:04:86:88:de:27:46:ca:f3:f7:f3:8e:54:18:ea:aa:ae:14:
        02:b1:4a:6a:e0:24:77:40:28:8d:37:27:9c:87:6a:81:09:d2:
        01:4d:20:7f:de:84:a8:80:8c:8e:63:82:be:66:df:87:30:5c:
        b8:71:0a:e9:91:68:71:6e:97:97:f0:27:4e:fa:ae:6a:85:ac:
        80:cd:38:48:49:c1:2b:9d:db:54:c5:f0:bf:fa:06:e8:96:3a:
        c0:95:f0:88:bd:8e:80:78:3d:dc:ad:5d:0a:56:dd:c7:80:9f:
        fc:64:58:4d:6d:27:f6:d7:1a:8c:b2:1c:09:ea:7d:4f:74:99:
        0d:4a:0c:b8:b0:ef:74:dd:6f:6f:dc:e5:83:e1:e3:c2:e8:58:
        17:b8:44:8a:2d:ec:df:54:f6:1f:67:a2:b3:c5:19:fb:b9:c7:
        1b:3c:ea:bd:2c:e1:43:65:d1:5a:17:dc:93:9d:c5:85:0c:55:
        34:13:49:15:92:e2:52:14:d1:81:aa:62:02:1a:ba:c9:b0:53:
        85:8e:7b:d1:4e:34:76:ac:79:d7:b3:48:92:bf:55:7e:2d:5c:
        cd:32:9b:c1:41:a7:a3:cd:b7:94:5c:96:1e:3e:27:4d:eb:f0:
        61:4b:a4:e3:3c:bb:69:85:37:e9:9c:98:f4:68:7a:61:77:8c:
        bd:b9:30:d6:f1:fd:69:78:3f:96:99:7b:69:39:90:b3:7c:b6:
        88:ed:cd:19:da:42:64:e5:32:4c:a2:30:f7:c4:e8:27:93:70:
        ed:fa:5e:ca:8e:7a:d1:13:af:15:b1:59:c9:9b:91:61:0b:06:
        d5:cc:2e:80:bb:49:93:dd:be:53:88:be:af:80:64:7c:5e:be:
        7b:8b:e7:5f:39:af:ab:67:42:6b:06:aa:ef:d6:69:af:a9:00:
        1f:a0:15:10:04:3e:db:93:b2:37:db:eb:85:59:43:a2:8d:8f:
        06:8c:cb:a2:1d:a8:3c:9f:f4:a4:7c:c8:cd:ff:f0:a8:79:0f:
        e7:d8:94:67:ec:17:3f:fa:6e:04:07:4f:bf:86:04:6c:fc:46:
        87:b5:10:85:a4:07:e8:af:a9:ec:5d:28:5c:80:8c:31:cc:c7:
        b3:81:17:0b:4b:7d:1c:9e:74:02:1e:ef:de:0d:1b:c1:c0:04:
        4d:46:fd:dc:0b:a4:c6:33:e6:85:0a:60:39:4d:0b:f9:49:44:
        33:e0:15:99:19:bf:c7:8a:c6:96:04:93:37:6b:5d:e8:be:73:
        d4:80:b8:81:0f:9a:91:44:cf:72:02:d3:c9:f8:e0:7d:d2:9b:
        2b:ff:eb:42:6e:38:7e:dc:cd:a7:90:c5:2c:2b:a0:23:37:b9:
        64:10:a6:27:68:47:c5:f1:e8:8d:41:c1:49:e8:35:48:ce:c8:
        08:4c:ad:f2:ad:5d:e9:62:eb:c9:3c:61:85:18:c6:34:73:fd:
        26:a4:f0:50:83:9b:64:54:aa:55:6c:d8:a2:21:81:ff:9c:27:
        39:1f:c3:a2:0e:e5:53:b1:d7:fa:1f:ef:29:8b:c2:90:98:ea:
        2e:dd:45:bf:c3:6c:a3:93:47:99:03:18:25:e8:a5:ee:2e:77:
        eb:7f:f4:49:49:59:98:c1:fc:ab:1e:ad:20:bd:f8:24:fd:21:
        1b:da:5a:07:55:c8:50:05:31:50:93:b2:f8:6e:db:73:4d:5f:
        34:aa:f3:34:83:90:f0:41:6d:c8:43:56:d1:75:07:f5:16:20:
        b3:99:b2:c7:34:25:c4:0e:74:5a:51:0f:7b:3b:7f:6a:a9:41:
        17:b5:47:62:2d:4f:b9:61:97:60:e9:ae:ca:ad:31:6e:4b:0a:
        47:9c:53:66:a3:4e:c3:96:7c:01:a0:8e:ae:83:45:42:e6:92:
        12:8e:97:6f:e8:a0:b7:7d:a6:74:24:aa:20:b0:fa:9e:98:e8:
        7c:b4:da:30:e9:94:08:96:b7:b9:53:4f:75:5f:0c:4d:82:e3:
        cf:6e:bc:fa:23:4f:fa:33:17:7c:98:b6:1e:47:89:3e:d9:a1:
        aa:42:19:25:ae:9e:3f:53:44:ac:91:96:d8:55:c3:40:1d:fa:
        ad:86:38:62:bd:27:2f:26:34:be:ad:9a:01:44:42:c8:54:a5:
        3a:e9:0a:ff:f8:41:6d:38:1e:e2:3d:08:3a:94:4f:1e:60:d0:
        b1:c2:8e:94:34:f0:30:3e:f0:91:25:ee:98:34:b4:8d:95:4e:
        cf:ed:1d:61:89:c9:59:10:68:f2:bc:2e:5c:bd:c0:0f:1d:9c:
        2f:7c:c0:27:25:14:9b:de:a3:74:64:28:14:2c:a2:b2:90:3a:
        a4:6a:50:e9:8e:ca:78:e5:b6:74:56:e0:92:69:7d:b4:2e:e0:
        e7:66:92:16:92:a0:c3:db:4f:d3:d0:57:4d:4a:28:ee:b7:cc:
        04:ef:17:d9:fc:01:bb:1e:b2:5b:02:3d:1f:5a:85:73:a1:81:
        96:b7:33:5d:79:e5:6b:c9:29:73:34:01:69:ea:57:f0:01:be:
        4e:f3:5c:f3:0a:a7:37:08:ad:18:9c:c7:4c:59:d0:5d:bb:01:
        f1:53:76:cb:cd:d9:84:5e:bc:22:11:76:01:d9:e3:af:17:03:
        01:ef:38:4c:ad:c1:7d:a9:c6:61:2b:ba:9c:81:95:86:af:bb:
        73:90:dc:d9:2f:d1:3f:95:6a:b9:46:0f:fb:84:64:7c:7d:86:
        65:aa:10:71:56:19:5f:60:52:7f:19:fa:d5:5a:e0:90:e4:b9:
        62:55:71:2a:61:f9:37:2f:5e:07:71:43:cf:06:ca:6a:d5:52:
        c8:33:e1:ad:b2:3e:a4:61:01:00:bc:55:5d:0a:f3:e6:4f:35:
        06:c4:a8:3f:4c:8b:9b:c9:41:4b:f4:c1:57:ee:3c:c0:44:68:
        52:5a:2d:b9:a7:f2:41:da:c4:8d:7d:db:40:b6:fc:47:63:5a:
        69:a1:c7:8c:cc:3f:af:51:94:37:95:58:82:79:d2:16:4a:bf:
        12:0b:59:a5:a5:11:71:e6:1c:63:3b:ea:f0:2f:10:e0:97:9a:
        a1:04:53:d0:72:f4:3c:77:3b:78:ee:b5:aa:6b:f5:bb:5c:e9:
        35:4f:69:65:87:29:24:ec:47:7b:78:5a:a7:c1:e5:f1:73:7d:
        4d:79:ef:ef:4e:75:87:db:8f:36:fd:50:3e:74:dc:17:d4:c3:
        3f:4f:82:24:51:1b:12:16:26:61:db:93:15:19:39:55:f5:05:
        2c:6e:85:dd:b2:cc:4f:c0:09:0a:76:46:d8:e4:f2:11:92:a1:
        e0:36:a8:25:c7:45:19:6c:98:eb:9a:fa:c1:ec:80:18:ce:d1:
        f8:c4:23:9a:f9:b8:1f:05:67:8e:45:cb:e6:ee:0b:fa:db:67:
        1f:62:2c:49:78:bb:55:98:1e:33:42:63:f2:db:ee:73:f7:60:
        80:6d:5f:9a:e8:8c:89:39:5b:b2:84:e2:c3:99:77:f3:5f:19:
        ec:b8:2b:ce:60:59:2c:66:06:f9:c1:43:b9:fd:94:35:9e:28:
        9d:a0:8e:fd:0d:c6:1a:bb:20:93:b0:63:6a:83:2f:0a:db:c2:
        b3:8e:b1:dd:f5:ab:19:09:53:7a:db:72:3f:1e:25:07:eb:1a:
        7d:21:da:88:22:e6:f0:ba:b3:15:6f:95:f3:72:d2:cb:6d:48:
        b8:ba:7b:aa:40:7f:81:fe:ba:15:c2:77:9d:86:58:bc:7d:89:
        2e:7b:3a:96:04:9f:f1:3a:50:48:5a:25:4d:91:b6:ed:de:f6:
        2e:4d:e5:77:11:6d:76:f4:23:5f:91:f0:0f:79:59:7a:f3:32:
        24:11:c4:88:30:21:26:3b:f1:79:0f:04:06:ad:82:6d:ea:58:
        4e:aa:4e:0a:7f:7b:5c:a5:ab:de:76:a9:a9:c7:d9:e3:eb:d6:
        84:80:02:ab:da:4c:5b:49:90:29:c5:cb:5b:1c:06:61:e8:9a:
        cf:a4:ea:9d:31:16:6a:21:3a:d9:22:25:b8:39:9d:4c:e3:86:
        76:a8:dd:d8:b4:db:88:f9:5e:61:c3:1d:87:df:a9:31:33:7a:
        b3:50:3e:f2:cd:ad:a0:9d:98:5f:6c:e2:f0:d8:27:b9:c2:37:
        7f:8d:b4:f8:84:13:5f:22:6d:9b:81:bd:1c:e5:75:ae:b5:95:
        d1:cb:d0:c6:e3:78:ec:8c:71:6d:8c:5d:40:79:7d:58:3d:5c:
        63:77:cc:2e:a2:63:a9:71:30:2f:59:2a:ec:82:b1:e5:b9:d6:
        bf:fb:21:e6:97:fc:70:45:9a:c7:e8:d2:81:73:b1:f5:bc:76:
        ca:b4:be:9f:39:b5:2d:f2:3e:c5:32:e3:ae:3c:fd:74:a1:36:
        5a:5c:4d:f6:de:d2:d5:66:61:74:88:2e:4b:69:7c:29:2f:e0:
        2a:d6:d8:93:99:41:bc:7b:7f:fc:c3:1c:84:ed:16:c0:08:78:
        fb:57:61:9e:83:7a:d1:e9:b7:ad:9a:85:1c:c3:ba:a3:e4:18:
        b6:00:f6:35:27:e2:27:1d:10:dc:44:1d:11:05:a2:db:df:0a:
        59:98:9c:f3:ca:3a:b3:26:2d:d1:c4:3c:fc:21:f3:3c:39:62:
        7f:f4:bd:91:74:ef:02:83:da:4a:22:40:60:9f:6a:9f:8b:8f:
        f1:e4:1e:99:d5:17:55:62:1c:60:01:7d:c7:41:db:19:9e:29:
        01:ba:a0:5f:41:f3:61:ed:9d:0c:9c:ef:32:8b:b0:8a:89:b1:
        e4:06:c9:2f:4d:42:2a:01:84:29:ac:f1:41:a0:a1:c9:b4:83:
        d9:87:1a:53:1f:7f:d4:85:12:2e:79:f3:2c:88:06:73:62:ee:
        16:bc:c7:8b:e7:09:96:ba:02:b5:56:ab:6f:c0:cf:76:64:62:
        0e:1e:b5:e4:69:42:4d:ed:56:96:d9:1d:8d:07:40:7a:c5:bd:
        d3:9f:43:07:e4:9d:b6:26:2b:33:6a:79:d9:8a:ec:ee:51:73:
        f1:91:b0:e8:90:42:db:11:55:57:1b:01:10:fc:11:ff:77:b4:
        09:01:6d:f8:8c:cf:72:16:df:09:12:09:bd:49:ef:33:b9:c5:
        8d:35:60:77:80:8f:ee:98:18:be:bb:3a:61:e9:5b:6a:09:b0:
        0a:1e:38:80:e9:71:46:77:a1:19:7a:c3:04:57:a5:77:e6:5a:
        01:77:d2:92:90:f6:99:50:87:3f:30:8a:37:3d:37:1e:6b:1d:
        a4:71:3c:6b:15:07:01:f6:3d:43:96:a3:f7:30:cf:08:2c:32:
        a3:ca:67:6e:59:da:51:2e:96:bc:97:41:4b:7c:5f:97:a3:cf:
        46:20:9e:64:96:08:f7:0c:03:4b:b4:83:09:db:6c:bb:94:23:
        4e:ff:7b:fb:2f:84:66:0a:96:f9:e1:58:ff:0d:3c:84:62:9c:
        6b:60:9f:7e:39:cf:33:f3:03:2f:c7:d0:8b:6f:f3:9a:62:cc:
        33:c4:bd:b4:fc:b8:80:9d:fe:9e:c2:f0:d0:9e:07:71:a8:f9:
        1f:a7:64:4d:63:f9:6b:ce:3e:44:0a:3f:05:58:90:0d:0c:20:
        7d:4e:c7:52:d0:e5:b7:61:d3:6a:52:08:37:91:15:3c:cf:41:
        ec:ef:88:56:dc:14:2a:12:55:cb:05:01:23:89:c0:fe:ca:de:
        40:d2:d0:96:a3:1f:07:4a:58:96:fa:b2:ef:78:96:f0:73:25:
        c8:2e:20:3b:d8:02:cf:e7:ca:b0:29:1a:25:7f:15:96:2d:fd:
        52:bb:29:c3:fc:bf:b1:7c:d8:0f:76:21:05:28:2e:89:d9:82:
        0e:cb:cd:03:1f:c3:71:b4:0f:75:52:e5:b4:93:8c:ac:ed:d5:
        30:5a:b9:33:84:fd:3c:da:dc:e6:84:6d:c2:66:be:93:ad:67:
        7f:db:d0:08:95:64:5a:2c:13:7f:e2:05:b5:dc:d0:bf:4d:6e:
        93:c2:3b:8c:3b:b1:5c:3a:28:e8:c3:96:ed:59:e2:62:52:8e:
        95:8d:b5:e1:c1:f2:34:5b:bf:5a:cc:f1:ee:ec:3d:6c:61:99:
        f2:c8:e4:05:5f:ea:d5:74:3c:ff:df:1b:20:bd:35:30:c0:27:
        f8:a4:6e:73:45:81:e2:b9:15:52:c7:a0:e7:c8:fd:7b:8e:f7:
        d2:0c:c4:e9:22:69:4e:70:62:c7:8a:a2:a6:61:7c:0b:5a:74:
        8d:0f:c0:e5:66:dc:18:7b:74:3b:72:ab:1a:53:b3:49:ef:50:
        aa:76:80:e7:11:53:90:ab:24:d1:2e:fc:66:41:cf:b3:cc:ae:
        ac:f9:eb:1e:19:f7:bc:54:00:16:da:b0:d4:2b:74:c7:35:fb:
        08:ff:67:14:83:5a:eb:6b:b7:b4:63:28:e2:b6:b8:d4:0c:13:
        6a:8c:bb:30:c1:fb:6c:42:df:23:c4:f0:be:25:df:2b:39:11:
        bb:82:c3:e7:f9:04:48:77:cf:d0:5e:3d:6e:19:7f:b3:c4:2f:
        c4:ec:51:5f:9d:c7:8f:88:9f:21:79:8d:a0:17:3e:17:73:b4:
        f5:a2:71:70:e6:99:c4:fd:4c:f2:63:64:23:22:c3:72:71:52:
        43:42:a5:90:e3:59:77:50:ff:a1:09:2e:c7:f6:7e:17:f2:a2:
        d6:7e:2c:75:f2:ab:9e:36:78:ab:57:be:c5:91:71:70:2c:ba:
        03:91:80:97:f4:9e:16:bc:fa:80:f4:22:2a:b5:75:15:57:d9:
        b0:92:9e:b1:35:db:26:96:77:28:9c:89:99:db:9b:55:d4:29:
        15:5f:54:8a:0d:58:a8:95:13:95:17:6c:6b:b0:2a:a3:fa:1a:
        ec:2e:b4:0e:08:ea:8f:e1:8c:59:cf:7d:60:00:f3:bf:b7:e4:
        5f:08:a6:02:ef:ce:d7:9c:8d:6f:56:d7:c9:35:e9:e5:cf:d2:
        f5:28:ca:e6:36:ef:c4:26:52:d5:4d:04:ec:50:73:87:dc:70:
        1f:1a:db:07:bf:4c:e9:ec:57:98:7f:bc:c8:31:9e:7e:e6:3a:
        b4:c4:77:93:39:56:57:67:05:84:8d:03:02:d9:bf:04:6b:fe:
        71:8a:be:b6:8a:ae:44:b0:dd:db:1f:6a:26:e5:50:d5:ff:03:
        81:d8:1b:9f:3f:a6:bc:1b:52:b5:49:93:b0:27:fd:59:d4:7d:
        69:e9:63:35:0b:9b:de:a1:d4:70:0c:08:41:4b:76:d6:cd:c8:
        65:8c:bb:9a:6e:e4:f1:e2:30:13:9d:a3:c7:67:16:0f:7d:bd:
        ac:dc:aa:9c:17:01:a6:27:14:fa:4a:c1:27:3f:07:7b:9f:2f:
        47:56:cc:f0:96:38:e9:58:7c:1f:6c:73:10:3c:11:68:2a:3c:
        5f:74:fe:37:ae:8b:e9:eb:c6:06:30:6f:62:3c:5c:6c:2d:c7:
        5b:24:6d:cc:75:3f:d7:d4:e6:72:64:8a:ad:03:67:ad:cd:cb:
        2d:7c:82:49:a9:ef:e8:b9:be:f2:6c:98:42:4e:26:46:04:58:
        a5:2b:c9:88:9b:a4:91:7f:22:09:12:52:2a:d1:4e:36:22:d8:
        53:bc:38:93:ad:11:19:c5:e7:c9:83:00:b4:b6:b0:ac:96:32:
        ca:d0:08:69:e4:d2:29:86:74:74:49:be:4a:b2:bf:f2:2f:c2:
        52:fd:15:3c:8d:07:12:3a:98:c7:49:67:81:1d:b1:5d:e8:f4:
        42:79:a0:f7:44:b8:95:9f:e1:37:41:5b:c9:b1:89:90:7b:66:
        96:eb:8e:dc:1b:d7:73:b2:eb:c1:42:41:e8:2d:28:ba:74:ea:
        7c:77:87:76:5b:36:10:3d:87:08:52:94:e6:60:95:c1:1b:c9:
        27:c1:42:aa:32:62:ed:ca:6f:04:4e:11:3a:3d:3d:e0:d8:3a:
        c0:ff:b9:9a:94:b1:79:f3:01:14:3a:99:34:59:8e:d9:ac:f1:
        a9:77:b5:2d:59:e1:29:96:1b:13:80:8b:10:94:3e:c2:51:db:
        c1:24:06:02:47:96:9b:ae:5d:25:34:af:4b:65:f3:8a:eb:65:
        7c:a5:5e:7c:a2:d6:1d:41:20:13:0b:5e:ea:67:b2:eb:bf:6c:
        44:fb:76:31:58:5e:d2:33:6d:6f:9c:3a:41:70:34:11:6f:99:
        8c:42:9d:d6:2b:14:79:b0:ac:d4:de:3a:b0:d8:d2:97:88:9a:
        17:68:3e:79:a8:b0:4a:d7:a7:3c:63:c5:29:c1:65:76:74:7e:
        c2:de:b8:49:ce:26:5f:d2:62:2d:0f:5c:cc:6c:53:c0:a4:75:
        05:52:d1:52:38:ae:72:17:7c:02:67:6b:76:38:e7:72:aa:38:
        70:5e:af:a2:98:c0:c1:7a:a0:6d:ec:90:51:8d:d5:99:8b:39:
        05:6a:eb:0c:87:37:5b:4b:00:91:2c:7d:8a:6d:c1:23:10:44:
        26:5a:47:f7:7f:8f:86:1c:c2:a7:9f:9e:48:f6:42:cd:d1:3c:
        d9:e8:95:de:00:3c:ec:db:a1:a3:c0:7f:f7:17:3b:4a:dc:d2:
        f5:d4:9b:12:19:0f:6d:13:38:72:06:21:eb:94:88:87:8f:a1:
        de:f6:d7:a0:88:aa:e3:47:bb:69:e8:30:59:82:d2:3a:6d:c7:
        26:95:92:a4:58:07:eb:db:a5:d1:bb:51:00:28:ef:6f:c8:ce:
        9c:0f:d9:8d:e0:b3:14:db:90:dd:f9:26:af:b0:88:48:ae:22:
        71:26:af:d5:e0:4d:5c:41:e6:0b:f2:5c:9b:bb:69:82:09:5a:
        58:63:b9:0c:8a:22:37:aa:a2:71:2a:a5:d9:a7:7b:9f:d5:f4:
        17:8d:bd:4e:de:08:6a:a4:20:ce:a6:85:c7:fa:05:c7:d8:03:
        77:0c:dd:40:32:11:43:2a:8c:50:22:4b:fa:a1:d1:f1:94:42:
        3f:d5:b8:a0:dd:01:71:6e:30:34:ff:a6:76:80:e6:c1:04:8b:
        f0:c3:38:14:98:ae:eb:fd:05:98:d1:96:7e:b4:bf:51:ce:aa:
        b4:66:71:30:9f:7a:45:b6:ed:d1:6e:8f:b0:6c:a5:f5:4f:ee:
        bc:ea:65:5e:24:43:73:4b:50:8e:c8:68:0f:23:48:ed:dd:ff:
        84:97:9b:31:0d:bb:2c:db:69:6b:0c:34:73:3e:ae:69:d2:f5:
        be:a8:99:be:7b:40:82:f4:fe:35:f5:3d:a3:b1:b4:e2:6c:79:
        b7:0b:29:ad:30:3d:56:9d:bc:24:e9:e6:a5:6d:cc:83:18:7b:
        d5:98:a3:5f:dd:71:72:29:71:45:8f:41:52:ce:86:99:5c:f1:
        40:0c:1e:b1:97:da:3a:14:4a:a7:02:48:d8:4e:63:12:99:da:
        28:e9:de:0d:17:90:3a:f5:da:9a:01:7c:15:12:bf:00:48:7d:
        63:8c:89:0b:b9:77:95:01:27:b2:33:73:4b:ab:a8:f3:24:ee:
        c1:d3:0c:a3:9e:26:fe:24:23:3b:82:b4:1a:5e:72:dc:9e:91:
        3a:7b:85:64:0d:30:2e:6b:55:53:7e:a2:4f:b7:10:e4:77:a1:
        01:4a:b2:d7:7f:1c:94:a6:a7:e5:66:e2:c7:e5:37:6d:89:2c:
        72:b1:53:cf:d6:67:0f:77:f8:bf:07:20:98:99:60:ef:2e:72:
        c0:72:9e:79:2a:ca:a2:f7:bc:82:db:53:f7:68:e3:ed:4f:38:
        64:83:1b:dd:a5:78:dc:db:08:a9:34:35:f6:f1:9c:76:85:5e:
        cd:59:a3:c8:89:50:5b:bd:a0:64:06:b4:d7:db:7a:e1:75:57:
        13:90:ce:05:4b:a0:f6:22:70:0b:78:a0:84:46:87:b4:a7:0d:
        88:c6:41:c5:93:cb:77:37:d1:af:37:48:b9:47:db:99:7a:98:
        36:82:cb:27:6a:9a:de:80:24:3a:29:eb:ab:bd:b0:40:0d:a6:
        50:e5:a4:72:a3:19:cb:f3:52:8e:2f:1d:10:ef:7d:0a:15:6c:
        49:08:53:55:84:85:5c:73:53:ce:3e:18:e5:04:92:a6:99:db:
        4d:7b:c7:a9:99:ce:aa:90:48:73:7a:61:f5:92:73:da:b4:26:
        74:a1:39:74:e3:82:f9:32:e0:08:ef:bc:2f:9f:6d:e1:da:3d:
        f0:a5:46:b6:17:95:b8:6b:13:7d:f3:a1:31:8d:b7:47:a0:45:
        aa:20:53:d6:f0:3c:eb:a2:e7:7a:26:8c:c6:c7:cb:0f:21:5a:
        df:46:06:c5:b2:2d:a5:3b:b7:01:fd:0f:55:1b:5e:58:00:70:
        94:a3:7f:48:8e:4a:67:a4:14:5d:e0:ba:b6:f9:9b:e7:de:61:
        d8:67:83:ac:b7:01:eb:62:c5:22:b8:48:3a:96:55:fb:1a:4a:
        c4:63:30:f3:78:05:a6:ab:0c:e7:33:a0:88:f7:e2:e3:4a:1b:
        fd:66:3c:14:be:ee:20:d1:32:95:db:97:ff:d9:c2:bc:7a:c8:
        e4:ba:24:c5:b2:2e:16:f8:53:af:b4:57:56:25:26:f5:36:48:
        eb:0c:20:f9:3b:73:ff:dd:bd:20:81:0c:f5:55:89:7d:46:1b:
        05:b6:25:df:96:99:ea:09:79:60:72:d8:37:92:a8:f1:75:a3:
        5c:6d:54:b7:f3:32:17:35:1a:2d:96:e5:5e:fc:cd:54:30:49:
        af:6f:1a:42:d9:98:52:72:73:74:72:b7:72:95:80:1d:31:5a:
        e4:83:b7:b6:d4:14:00:0b:59:ce:7c:bc:1d:72:24:ab:74:d6:
        2c:9c:20:b1:0a:78:6f:a9:76:8d:6c:37:02:35:bd:6f:99:ee:
        d1:45:36:f1:34:60:7a:12:57:27:68:05:26:14:75:3c:9f:0d:
        3e:b7:5d:b8:2a:6c:1d:a7:b0:41:c4:f4:3d:ae:8e:51:54:37:
        65:ad:0a:c9:28:a0:3f:04:ed:54:59:c4:9f:1d:3d:70:97:5f:
        f9:44:53:ff:15:9f:03:13:7b:41:6b:c0:f7:8f:a3:27:2b:03:
        39:37:8f:bd:91:65:4d:74:a9:9f:45:6a:a4:25:dc:4c:f9:7e:
        59:fc:4e:93:7c:89:8f:71:8e:a6:99:66:5e:6a:25:a4:c0:a6:
        fa:25:f7:68:5c:8a:02:f5:7b:49:cd:89:e1:77:78:95:1b:a9:
        21:78:6e:f4:7a:e2:04:e5:0e:21:52:bf:04:cd:0c:69:5d:d7:
        f2:57:71:9f:d8:01:e0:f3:10:cc:15:2d:fd:99:78:ff:dc:1f:
        8f:a9:31:0d:0f:9f:f4:2c:a1:3d:4f:b2:51:92:68:f0:ec:d8:
        5f:c4:55:a1:4c:c8:12:e9:05:7e:05:93:5f:f9:76:99:85:18:
        29:24:60:14:5d:b3:79:f9:4b:7c:e4:22:71:8a:c2:66:45:d2:
        41:14:5d:59:4c:0a:b5:2b:ab:bd:c6:50:f8:87:37:42:e6:d4:
        96:72:cf:45:f0:d4:bf:0d:c5:17:9f:f1:b9:12:5c:a8:74:89:
        9e:56:07:cf:8f:98:9a:da:d7:db:7f:c7:d0:3a:0a:14:cd:5a:
        66:0c:eb:02:76:a0:d4:56:e6:e8:be:a1:f0:c7:23:b3:4f:86:
        90:1a:5a:16:8e:07:0d:24:d1:ee:03:98:9f
]]></artwork>
      <artwork><![CDATA[
-----BEGIN CERTIFICATE-----
MIIU6zCCAXOgAwIBAgIUXCKtigZRnmcCai1DPovHI0N3gMgwCgYIKwYBBQUHBiMw
NzELMAkGA1UEBhMCRlIxDjAMBgNVBAcMBVBhcmlzMRgwFgYDVQQKDA9Cb2d1cyBY
TVNTTVQgQ0EwHhcNMjQwNzEwMDgyODA0WhcNMzQwNzA4MDgyODA0WjA3MQswCQYD
VQQGEwJGUjEOMAwGA1UEBwwFUGFyaXMxGDAWBgNVBAoMD0JvZ3VzIFhNU1NNVCBD
QTBTMAoGCCsGAQUFBwYjA0UAAAAAAUuniRFv/B370+dxc7iiSO9TuZ0fxop8vk+K
KfpB/b3aIH/2O7DFuKfC8lryJhTrNvAmL4d0+w7Vfheg0U22z1GjYzBhMB0GA1Ud
DgQWBBR8fVm4lWHVA2oePfEkqx3tBM3bXzAfBgNVHSMEGDAWgBR8fVm4lWHVA2oe
PfEkqx3tBM3bXzAPBgNVHRMBAf8EBTADAQH/MA4GA1UdDwEB/wQEAwIBBjAKBggr
BgEFBQcGIwOCE2QAAAAAV8SYif/ZCo5ubxaVjOw1QiHCylbt+IHxsk8rbXP0N1X8
9E4V62uQ3jT+1pZwlI3B50oySTA6QKRn0vva+NihekgiHOOYvNBohSnJ5fdcVtic
gL5o7RHrOQ/vywmyKDCmKwW83hEivsTcCJo9tEk3H1ReXy2TYrCVxV0jkvNVQHgZ
AFaeovEOS6511pIJsXnsyRhnGQmGg3RdCgar2vCvApdN13MGi6KExwmv3YsVOeQw
n8kAJagzTd7oJbY1C1G/ejSn6ITo+jlbqjdulYmsJkpOyr4pCEs8KKeFaq1a0pPr
EuGahxxAO88VbENOiCFUUn4NbRcpjRVv70JaqSXQl4BhMSKknyUXUa0LocuTtPWm
sCIbbVBkKki9BRaIAON7VtADs3otagvz3qKMboGALI/p2HjtW5nJE9G263jDQCuh
eoQKuhKHXh04JCKPwKNlHBzOLY7lLx++k1z+HM2onX5+zxjinMVU3GJhdCNVZGYh
lkynLoqUpjUQpehebpGsqMvtUStmRQP1h+1NjE5tVIChM4qEnSMxkMYFEaedvVEK
c0e8CEkRs5j/ARRp18CgDFXkXuL6hKwns4UsmXFSnDP4nYzSE7xuGHkVpwLuFesn
2K8kOAKcyjDz4jBBL2KiLKWBG3FtsZS9xj2eXlFF3lv01+Y159h81Zjsfg74ncGn
e7NlsaFLLezZEkVrHwscazsKZnY59Myb4bcX91P8w6YY9y5FUrEYmXXRabt3yBqE
Xwa1i8sCsLIPvxcYZT2ncltxn5J+Ot+EzGVcxFtw/cw4nhJu+f8fAvzK9WiG/Mpx
8T17MrTUw6IgFj8SB3GVO9SxHvyMHzSMyKuMu3WTwRrShT6a5gSGiN4nRsrz9/OO
VBjqqq4UArFKauAkd0AojTcnnIdqgQnSAU0gf96EqICMjmOCvmbfhzBcuHEK6ZFo
cW6Xl/AnTvquaoWsgM04SEnBK53bVMXwv/oG6JY6wJXwiL2OgHg93K1dClbdx4Cf
/GRYTW0n9tcajLIcCep9T3SZDUoMuLDvdN1vb9zlg+HjwuhYF7hEii3s31T2H2ei
s8UZ+7nHGzzqvSzhQ2XRWhfck53FhQxVNBNJFZLiUhTRgapiAhq6ybBThY570U40
dqx517NIkr9Vfi1czTKbwUGno823lFyWHj4nTevwYUuk4zy7aYU36ZyY9Gh6YXeM
vbkw1vH9aXg/lpl7aTmQs3y2iO3NGdpCZOUyTKIw98ToJ5Nw7fpeyo560ROvFbFZ
yZuRYQsG1cwugLtJk92+U4i+r4BkfF6+e4vnXzmvq2dCawaq79Zpr6kAH6AVEAQ+
25OyN9vrhVlDoo2PBozLoh2oPJ/0pHzIzf/wqHkP59iUZ+wXP/puBAdPv4YEbPxG
h7UQhaQH6K+p7F0oXICMMczHs4EXC0t9HJ50Ah7v3g0bwcAETUb93AukxjPmhQpg
OU0L+UlEM+AVmRm/x4rGlgSTN2td6L5z1IC4gQ+akUTPcgLTyfjgfdKbK//rQm44
ftzNp5DFLCugIze5ZBCmJ2hHxfHojUHBSeg1SM7ICEyt8q1d6WLryTxhhRjGNHP9
JqTwUIObZFSqVWzYoiGB/5wnOR/Dog7lU7HX+h/vKYvCkJjqLt1Fv8Nso5NHmQMY
Jeil7i5363/0SUlZmMH8qx6tIL34JP0hG9paB1XIUAUxUJOy+G7bc01fNKrzNIOQ
8EFtyENW0XUH9RYgs5myxzQlxA50WlEPezt/aqlBF7VHYi1PuWGXYOmuyq0xbksK
R5xTZqNOw5Z8AaCOroNFQuaSEo6Xb+igt32mdCSqILD6npjofLTaMOmUCJa3uVNP
dV8MTYLjz268+iNP+jMXfJi2HkeJPtmhqkIZJa6eP1NErJGW2FXDQB36rYY4Yr0n
LyY0vq2aAURCyFSlOukK//hBbTge4j0IOpRPHmDQscKOlDTwMD7wkSXumDS0jZVO
z+0dYYnJWRBo8rwuXL3ADx2cL3zAJyUUm96jdGQoFCyispA6pGpQ6Y7KeOW2dFbg
kml9tC7g52aSFpKgw9tP09BXTUoo7rfMBO8X2fwBux6yWwI9H1qFc6GBlrczXXnl
a8kpczQBaepX8AG+TvNc8wqnNwitGJzHTFnQXbsB8VN2y83ZhF68IhF2AdnjrxcD
Ae84TK3BfanGYSu6nIGVhq+7c5Dc2S/RP5VquUYP+4RkfH2GZaoQcVYZX2BSfxn6
1VrgkOS5YlVxKmH5Ny9eB3FDzwbKatVSyDPhrbI+pGEBALxVXQrz5k81BsSoP0yL
m8lBS/TBV+48wERoUlotuafyQdrEjX3bQLb8R2NaaaHHjMw/r1GUN5VYgnnSFkq/
EgtZpaURceYcYzvq8C8Q4JeaoQRT0HL0PHc7eO61qmv1u1zpNU9pZYcpJOxHe3ha
p8Hl8XN9TXnv7051h9uPNv1QPnTcF9TDP0+CJFEbEhYmYduTFRk5VfUFLG6F3bLM
T8AJCnZG2OTyEZKh4DaoJcdFGWyY65r6weyAGM7R+MQjmvm4HwVnjkXL5u4L+ttn
H2IsSXi7VZgeM0Jj8tvuc/dggG1fmuiMiTlbsoTiw5l3818Z7LgrzmBZLGYG+cFD
uf2UNZ4onaCO/Q3GGrsgk7BjaoMvCtvCs46x3fWrGQlTettyPx4lB+safSHaiCLm
8LqzFW+V83LSy21IuLp7qkB/gf66FcJ3nYZYvH2JLns6lgSf8TpQSFolTZG27d72
Lk3ldxFtdvQjX5HwD3lZevMyJBHEiDAhJjvxeQ8EBq2CbepYTqpOCn97XKWr3nap
qcfZ4+vWhIACq9pMW0mQKcXLWxwGYeiaz6TqnTEWaiE62SIluDmdTOOGdqjd2LTb
iPleYcMdh9+pMTN6s1A+8s2toJ2YX2zi8NgnucI3f420+IQTXyJtm4G9HOV1rrWV
0cvQxuN47IxxbYxdQHl9WD1cY3fMLqJjqXEwL1kq7IKx5bnWv/sh5pf8cEWax+jS
gXOx9bx2yrS+nzm1LfI+xTLjrjz9dKE2WlxN9t7S1WZhdIguS2l8KS/gKtbYk5lB
vHt//MMchO0WwAh4+1dhnoN60em3rZqFHMO6o+QYtgD2NSfiJx0Q3EQdEQWi298K
WZic88o6syYt0cQ8/CHzPDlif/S9kXTvAoPaSiJAYJ9qn4uP8eQemdUXVWIcYAF9
x0HbGZ4pAbqgX0HzYe2dDJzvMouwiomx5AbJL01CKgGEKazxQaChybSD2YcaUx9/
1IUSLnnzLIgGc2LuFrzHi+cJlroCtVarb8DPdmRiDh615GlCTe1WltkdjQdAesW9
059DB+SdtiYrM2p52Yrs7lFz8ZGw6JBC2xFVVxsBEPwR/3e0CQFt+IzPchbfCRIJ
vUnvM7nFjTVgd4CP7pgYvrs6YelbagmwCh44gOlxRnehGXrDBFeld+ZaAXfSkpD2
mVCHPzCKNz03HmsdpHE8axUHAfY9Q5aj9zDPCCwyo8pnblnaUS6WvJdBS3xfl6PP
RiCeZJYI9wwDS7SDCdtsu5QjTv97+y+EZgqW+eFY/w08hGKca2CffjnPM/MDL8fQ
i2/zmmLMM8S9tPy4gJ3+nsLw0J4Hcaj5H6dkTWP5a84+RAo/BViQDQwgfU7HUtDl
t2HTalIIN5EVPM9B7O+IVtwUKhJVywUBI4nA/sreQNLQlqMfB0pYlvqy73iW8HMl
yC4gO9gCz+fKsCkaJX8Vli39Urspw/y/sXzYD3YhBSguidmCDsvNAx/DcbQPdVLl
tJOMrO3VMFq5M4T9PNrc5oRtwma+k61nf9vQCJVkWiwTf+IFtdzQv01uk8I7jDux
XDoo6MOW7VniYlKOlY214cHyNFu/Wszx7uw9bGGZ8sjkBV/q1XQ8/98bIL01MMAn
+KRuc0WB4rkVUseg58j9e4730gzE6SJpTnBix4qipmF8C1p0jQ/A5WbcGHt0O3Kr
GlOzSe9QqnaA5xFTkKsk0S78ZkHPs8yurPnrHhn3vFQAFtqw1Ct0xzX7CP9nFINa
62u3tGMo4ra41AwTaoy7MMH7bELfI8TwviXfKzkRu4LD5/kESHfP0F49bhl/s8Qv
xOxRX53Hj4ifIXmNoBc+F3O09aJxcOaZxP1M8mNkIyLDcnFSQ0KlkONZd1D/oQku
x/Z+F/Ki1n4sdfKrnjZ4q1e+xZFxcCy6A5GAl/SeFrz6gPQiKrV1FVfZsJKesTXb
JpZ3KJyJmdubVdQpFV9Uig1YqJUTlRdsa7Aqo/oa7C60Dgjqj+GMWc99YADzv7fk
XwimAu/O15yNb1bXyTXp5c/S9SjK5jbvxCZS1U0E7FBzh9xwHxrbB79M6exXmH+8
yDGefuY6tMR3kzlWV2cFhI0DAtm/BGv+cYq+toquRLDd2x9qJuVQ1f8Dgdgbnz+m
vBtStUmTsCf9WdR9aeljNQub3qHUcAwIQUt21s3IZYy7mm7k8eIwE52jx2cWD329
rNyqnBcBpicU+krBJz8He58vR1bM8JY46Vh8H2xzEDwRaCo8X3T+N66L6evGBjBv
YjxcbC3HWyRtzHU/19TmcmSKrQNnrc3LLXyCSanv6Lm+8myYQk4mRgRYpSvJiJuk
kX8iCRJSKtFONiLYU7w4k60RGcXnyYMAtLawrJYyytAIaeTSKYZ0dEm+SrK/8i/C
Uv0VPI0HEjqYx0lngR2xXej0Qnmg90S4lZ/hN0FbybGJkHtmluuO3BvXc7LrwUJB
6C0ounTqfHeHdls2ED2HCFKU5mCVwRvJJ8FCqjJi7cpvBE4ROj094Ng6wP+5mpSx
efMBFDqZNFmO2azxqXe1LVnhKZYbE4CLEJQ+wlHbwSQGAkeWm65dJTSvS2Xziutl
fKVefKLWHUEgEwte6mey679sRPt2MVhe0jNtb5w6QXA0EW+ZjEKd1isUebCs1N46
sNjSl4iaF2g+eaiwStenPGPFKcFldnR+wt64Sc4mX9JiLQ9czGxTwKR1BVLRUjiu
chd8Amdrdjjncqo4cF6vopjAwXqgbeyQUY3VmYs5BWrrDIc3W0sAkSx9im3BIxBE
JlpH93+PhhzCp5+eSPZCzdE82eiV3gA87Nuho8B/9xc7StzS9dSbEhkPbRM4cgYh
65SIh4+h3vbXoIiq40e7aegwWYLSOm3HJpWSpFgH69ul0btRACjvb8jOnA/ZjeCz
FNuQ3fkmr7CISK4icSav1eBNXEHmC/Jcm7tpgglaWGO5DIoiN6qicSql2ad7n9X0
F429Tt4IaqQgzqaFx/oFx9gDdwzdQDIRQyqMUCJL+qHR8ZRCP9W4oN0BcW4wNP+m
doDmwQSL8MM4FJiu6/0FmNGWfrS/Uc6qtGZxMJ96Rbbt0W6PsGyl9U/uvOplXiRD
c0tQjshoDyNI7d3/hJebMQ27LNtpaww0cz6uadL1vqiZvntAgvT+NfU9o7G04mx5
twsprTA9Vp28JOnmpW3Mgxh71ZijX91xcilxRY9BUs6GmVzxQAwesZfaOhRKpwJI
2E5jEpnaKOneDReQOvXamgF8FRK/AEh9Y4yJC7l3lQEnsjNzS6uo8yTuwdMMo54m
/iQjO4K0Gl5y3J6ROnuFZA0wLmtVU36iT7cQ5HehAUqy138clKan5Wbix+U3bYks
crFTz9ZnD3f4vwcgmJlg7y5ywHKeeSrKove8gttT92jj7U84ZIMb3aV43NsIqTQ1
9vGcdoVezVmjyIlQW72gZAa019t64XVXE5DOBUug9iJwC3ighEaHtKcNiMZBxZPL
dzfRrzdIuUfbmXqYNoLLJ2qa3oAkOinrq72wQA2mUOWkcqMZy/NSji8dEO99ChVs
SQhTVYSFXHNTzj4Y5QSSppnbTXvHqZnOqpBIc3ph9ZJz2rQmdKE5dOOC+TLgCO+8
L59t4do98KVGtheVuGsTffOhMY23R6BFqiBT1vA866LneiaMxsfLDyFa30YGxbIt
pTu3Af0PVRteWABwlKN/SI5KZ6QUXeC6tvmb595h2GeDrLcB62LFIrhIOpZV+xpK
xGMw83gFpqsM5zOgiPfi40ob/WY8FL7uINEylduX/9nCvHrI5LokxbIuFvhTr7RX
ViUm9TZI6wwg+Ttz/929IIEM9VWJfUYbBbYl35aZ6gl5YHLYN5Ko8XWjXG1Ut/My
FzUaLZblXvzNVDBJr28aQtmYUnJzdHK3cpWAHTFa5IO3ttQUAAtZzny8HXIkq3TW
LJwgsQp4b6l2jWw3AjW9b5nu0UU28TRgehJXJ2gFJhR1PJ8NPrdduCpsHaewQcT0
Pa6OUVQ3Za0KySigPwTtVFnEnx09cJdf+URT/xWfAxN7QWvA94+jJysDOTePvZFl
TXSpn0VqpCXcTPl+WfxOk3yJj3GOpplmXmolpMCm+iX3aFyKAvV7Sc2J4Xd4lRup
IXhu9HriBOUOIVK/BM0MaV3X8ldxn9gB4PMQzBUt/Zl4/9wfj6kxDQ+f9CyhPU+y
UZJo8OzYX8RVoUzIEukFfgWTX/l2mYUYKSRgFF2zeflLfOQicYrCZkXSQRRdWUwK
tSurvcZQ+Ic3QubUlnLPRfDUvw3FF5/xuRJcqHSJnlYHz4+YmtrX23/H0DoKFM1a
ZgzrAnag1Fbm6L6h8Mcjs0+GkBpaFo4HDSTR7gOYnw==
-----END CERTIFICATE-----
]]></artwork>
    </section>
    <section numbered="false" anchor="acknowledgments">
      <name>Acknowledgments</name>
      <t>Thanks for Russ Housley and Panos Kampanakis for helpful suggestions.</t>
      <t>This document uses a lot of text from similar documents <xref target="SP800208"/>,
(<xref target="RFC3279"/> and <xref target="RFC8410"/>) as well as <xref target="I-D.draft-ietf-lamps-rfc8708bis"/>. Thanks go to the authors of
those documents. "Copying always makes things easier and less error prone" -
<xref target="RFC8411"/>.</t>
    </section>
  </back>
  <!-- ##markdown-source:
H4sIAAAAAAAAA9S9WXrjWpIm+I5VoG88tHvRJWIemJVVyZkUJ3EUqaioSAwH
JDiBIjgqM/LrPfQGeiH91L2TXkmb2QFJUC6/U0RkZnncz0MigTPYsdl+O/7w
8CDswt2S5cSf6usd267ZThw/6pItPu/dZeiJDXYW6+tg68S77d7b7bfwaH45
jbbhbrYS6z5b78IgZNtYDKKtWOv3RWfti+NWv/+T4Ljulh1g6PTH9BxN8ZPg
OTsGQ51zYrzzhXgHz/zZWUZrmANmY+IfxMEsjMUl28XiPhb9SAyctXcWnf0u
epiyNds6uzBai1EgblnAtmztsVgIN1t6P94pkmRLiiD4kbd2VjCqv3WC3UPI
dsHD0llt4ocTrOMhnrnxg6QJ8d5dhXEMI+7OG3i6Xh5UBFi/Kjhb5sAimScc
o+1iuo32m5zYzLee++KD2AxX4Y75Yt73Q1yOsxRbzJs56zBecbI8N+pjIkC/
VW+VhQU7wzA+TJCQ/KGE6xIObL1nOUEU0xPAr3w1LzBzuJ6KVfwSPl054RLW
tHHi1T/hjh6j7RQ+drbeDEg+2+02cS6bxafwo/DAHi9PZfGDrLuNjjHL0gDZ
n3BWONK9C+8SUYAmWU6uK41+EgSg/Cza5oQHeF4Uw3WcE0uP4shZi1XG4h19
ykldgv2z5YevYPKcWNyeN7uozU47sc+8PXDSmb5kfEc+vfh4cNZTfO+fPHp8
DY8/xMnjj160Si+h8SgWnHgWbsPUAhrOgc3uPqfZC/16erYFPvXo8qeIQv80
xW8+TtF/FCvL/WzLtqkp+l602919zjcYxl4k9s/xjq3i9GRxwB/9Jw+f+GSK
qvPuO9P0DDsWIAVvn9MMwPt7R6yu3Fp6eL56evTRZx+GbkT7OPTD+G5w57CN
4vuvPiVS8sBH+gjraLsCETwQ19YfSo/fCdg28CxTstwQVnH7GZ7uVYq6Lcu5
5EfFknLiHw6q6LHtN/GgiN52yb+yVFuGr06rOHnN0nUNPpjF8ZLI23+2JEmR
rBwteedsp2yXEy8C4Ech8bwsPRqSYmXb9f7gsf/8CO88wEv8Ha4Ceww2tWJr
n2sVlFwgEZzAfinWgEMegJlAzvvhdO2gJoTzn7EV43S7SIZIfx6S/0/o33YS
xVBfxzDZfsdQZ/VR4TlbPybdMACdsY6W0fQsfsFFfqUhYC2wMgX29yDDgm1B
CNdBmupAEFUx7eRHS5Ol249E3Vax2iu/fE6c3d4NQc1Hj/ul+7jbP8BqVqCG
/R3wTzb0s2yzDdc7oJ1sqGqaVEQXseWsnSlQYL3j2v8TGv0K4oACaXnVLTt+
/vUz8C6wEky1SFj0u0c+COdn36ck6LMFFPa7cP35t0/4rTdbOev13YnIxoMs
P4B5EcVCTTY+JzAn4GPoeFviQnwNyKkpjxs/SBO0E23ib2Jd9ENfDHeiM3XC
tfj//R//51VFIsN01uxhEK5Yirzifu2zrTg4Rg8tFsdwHGJ+t3O8Rfz4y5Rv
wta2+xBHCNeLH9Ku9v/+38sYTM+H7cOvxXY/rzxKn+99xfzQAUYK2Dpmj9Po
ALtXlGyfbbKSCT9LqmTKlqplH2T8T8oW+/k/44h/hiH/nG9WO736oNbq//nx
uVRJ06qIUrr1QpCnq2BdyXRzTvp7MMsijCV+wVHxp69i8eyCs3J92D+EMTgg
8EQ///U3yPFtOlDFHkrs5f2rwCoPYDYlEz4sD/r1h0EPBFh9MGzlc2odj8dH
8HO4svLZEsR7m8UP/rzbAseohiT9Gf/Ptuk3W8lK8iP992dDyu62/EvlIMn4
v81H/uICu7oX2Pii3XDT6Ml5XPOtru7LL5OkvN9GGwY2asCWpD/362SYOKXg
bnrvC1LjA6lkkCQ0IPl2/qHZ6v+YQCGsn3sw4KZN17iROLtk4XQGHsLDCiZe
hg/xVTiyaQo0L4+16LG0DH2BSX/F6eP6LstEV/bzdX66RrReD+DCgHFh/sMM
FaWLivJHi/2JxhfLyRufq9affvWSwe98QCf0N1I2XoUP6/0KJSb98+Nptlst
/5D65EF+VB+NR/lRh/+Zj8bdVmDym7xc3eGrnP7qbQgPDw+i40Ig4ng7QaDQ
ADz7PbFzvGEeBiJgS68KIExFJ2hh8/32oyyCvEY+OtLcjJKHLgD7/zpbL37p
P9QK/a9iDYYlx9pDdXB7jLw+4QuEPF+/iWycnF+LbRdL9t1w4hc8Z3jwEh39
z9YAfhFX++UufNhtGRMOzhbOZofqHx945CFRst1EXp3NZolb30UibuSHkRz6
DqlITvwCJ/FVPILow3tRzMD6QBAA+7lxJcQTDGIv2ALYo/uBBXDVdnwRjBM4
9QEEZIcoWd4yjHdgjuj8VqHvL5kg/AEH20Y+rAQeEYTfRvwYDLLoxBhvfuNR
ZYqAAmghN1yzC9GRjLF4BJZAAyp+NKBfOgMYEXYHIRlYUqDhZhsdgHcu1BCu
1BDjZB27mbODHa7QSJMxYSKD6I2T8m0P57VfibCMDWg8YD4XFSMTnAMGY+6S
4SGycIuHFW0ZqF3xapHgbI9sueRmPd5FkU9b89kGGCkWo/USPAE8LibEKc8A
j51eWZ6RtVHBiMF+TcR9FPMxpxg8dRY9B9e8PTAkoLMWwtUm2u6Qxdx9uCTJ
cJeRtyBR/bgX2HQcxvT01Q9FBlz7wp3uF3dXb/YRRZUBUcMD8gUEv+T74kHi
bh0xCNdoqL1oCQbkEs/DoeCj4BPNMKrnG3eEZRJrc72DD6641xPTvlxGrMs4
0Xb30/7vMTd4IF0xbJYJ+w1aIP7sBqgNG8PfAtwnDoOkIHbAs8XzBjlIr+1R
FF9mIXIYnMYWrQsQNrWHmybaOFuIuIgXjtF+CZMsl9ER9p6mCkyFs8IuD+F2
t4dHznCmbrQnDfLJjr+AV/UoKv/TkECD7FAtID13tG8viklnAMlQ22/FFBOH
74z2vIzW0/RWQTAexdKeXfTIxT1Yw4QJkwnpBV9o/P2hpPQHiUpyNt6WIcG/
8dMXVkSydYSHgToMHAnQdTA4ch7SGqQrRJUD+h7cIZTLXQRsAoSvRUc4FIgU
UQBBtvBxwQOtEdOKQFyW0ZkMw5XXVs75wzyP4CKCVOBM/FXUdT6LvW3oMl8g
uYNAfR+jMlo6yBYw3b/8C7zwQC/wzBHmR/7yl0fUacVojaxCzg++XmLE3Pg7
lwIkG+Z+YvGn1rA/+Okb/3+x3aGfe+XusN4rl/Dnfi3fbF5/EJIn+rXOsFm6
/XR7s9hptcrtEn8ZPhXvPhJ+auUnP3FD81PneVDvtPPNn3A/uzs7iiSA43cZ
pzzwPslELFzpgu8Uis//z/8la0CL/w0iTUWWgQDJL5ZsavALakI+G0ku/xX1
jwAHwByiJHA4EH6DOhbkHLRRPIuOaxD4LQNq/pc/ImX+lBP/q+ttZO2/JR/g
hu8+vNDs7kOi2feffPcyJ+InH30yzZWad59/oPT9evOTu98vdE99+F//+xJN
1YNs/ff/JiALDYEbi8SNNy25Tiz5v/zhM9YTBNDv4NmDaqdU2XTrbMAtuamf
RAjxaD3gRDBtWzhGfsqJgn+46vVvAp905oDExShk4A9sME1EFh45e8um4NST
yiAztiEBRT9oj4rpEcws1xVRHJLg4pTc+Hy6hsSCUswLWssRvSV6oTigk5hD
NFXCxRg5PqwqdrZnzmDOZQB8G54Ir0nhm+A7y6NzRkNMRm6HDI3aj8a9Jxup
3WTAOzMqshP5MWILbHZEyoePHwUB2wrxCtl5w30tFHNUszGtkLQUWlBw5WK0
jZEYATWAcKCkHy67uupMIfEySF6SOVCB0jxA/CXlfnCVNOW9YgergNoTPTGg
pnA1PLClXfz1MTFYuL5U/hypeBsm9QWSbucsWGIqwE2GdaROZ4n+IC0HVhs4
eHgw1Ap0HixNBBrdfNRthCmWq50W6BzAgqJWXDlzWPMa2IrYxUHvdofG7KMV
guefbwYoTo5VIF7lvAQLBP+SlNSVLzB1czuuNfNgpJA8AYc70rDWHZqmxGAI
HxyHO+fQOUShn/LX1h6FGTFYwQVLURFOASh2Fv7I829/+ib+8ZKo/BP5f1sG
j7BvPM2IK/t2WzFbgwsQURQmktJzuRMu4MOfHB5+dIvtQXm2ox0jqSfe408v
v8EhgLEt5uOEl7gb/dmkF9POTboAshTG8Z75acv+Bfa+3JMeSJyu7wKCYq8Z
f8WDjMCpAnaKfFw1E/ybkxGA7uD6iVTYdYU+eFJTPIBOsf9MDmvooVLccqZI
fBY4LPCLH9DmwmHczX+VMvoSw6Mvl7Ah3rsRKjAcHub6yudHF4KYbYn+zndO
/92h3a8V7BY6dehduEvaGWdDYqQte9uHqOziDykYrr1SOgSO4hDSCHG03JPr
TrodR3FcUDkwlgMKJAleb/PvY+4t+hHsEv0pDAh5rP1hq9+EkATrg9X67FHc
BrpGfIH4ALIAzn2j+F0I+L1mvNjrC/vSKD84L9jq1alL3s5P7l6EsP128OlX
v8GnGCNcLIwAy9wRHZHA20tWn2sF4oF1tH5Ie5ZgknbshMq9gis8OavNEk45
Zolvf1cY4DW9GFj6iOYM5wjC7Yp+uSwPJvpjkhwFae9j9AcHv0dm51lb9Dlh
zER+0cY9sBgXHcYzxgX6kp8gxcIdgICzf7gV7oiBQ/BgJpW6g7BvGZOM4SJR
DVJSASwCUL4eDUTYVJzUqI70EDdewDhUPEV5/hHFL1kBUMvk935eEcZlPV8j
H0Gof3A2v8G+Qc4DdIDW7Ch26iVO2yRxc05cDPDCA6ru7q7GQLil0FKSevN4
YPNA2VtBFoZGtueT+dyNT9WmwGHFEHYLUTZFhEQOznPo0IcYgnLeQIubxNu4
XG6jU+Fdoq0Fx425Jv7DH6gq/hmFeEgQuXOydtePeTx6cyQ+S2hdq+13mxI+
bIpUFv8+TIKSLSqRj7u8Fs8ff7QkfArsNs6YWhlM/s+h/wALfJjF8cNyFVNq
Ew7kn3MCrz5++q0odgpP5eJArJfK7UG9Ui/3xFzuH8V/uWT9wE36In8FZkbr
8+BG/vmL8hUY7oulSV9F8P38OPwiy6qu2V/FzcKL8Wn8f/uL/fUySLyCgPaL
bHxFCn5Rv4qyKf4lZRrp6H60/s+pjvE1ChURjDuwgnMjwmp3G+CSqDuDrjmv
8E3OrTx5IwKzgJvEy32X9JqzFiAyQj2OVdQLm11DM1qzyzxgNfGPSR30T5fs
Sopd7py5g7Pcg7xeJIpGvHdrL6Z+Rvnx62JQ78FxZ5utPmXQHm9z0is3b+Yi
wvBGfJnwG/jZ6EVQ5hYDBnCd0Rm6pPj/hAmXVbjjxi35/uq3pwQ3ncPlq4KV
4864aFHu77fIVsLI9N7nnEyp+s/ZOP3Vr+Xh69z+A3iEoJrfaZvIj37kfzG+
8kB7zXb49MWv/KJf2fim0eFDYPLw9MX8mlJ1OISqIWf//RiByJXiAtWW/2ou
wDH/lmzwP1uD38sJ+OqPmWG1+xl2uH35n4sh9L8/QyDV/tPyxB1+7fagIBTT
bgyYd/SykkTvHxMgyp8oRiXTf8Yc7Y2CnGfOqY+EK925sU2XQMK1f4lFZinn
BH6DYHg6QyJcPxRuu+G+y2fmhzIn8Y5SQ/AyOjWUYdskFLn5IUCCD+r6ekS3
MxG3zlGMvB1Dv2rLPXteG7uke5ONChRs384/5cNhRgEiu6sJE/t7kjROfqB+
HShMCLZvvGjx4WuxUB+I/UGv3q6SF44poF+3NuF2CPHjx3Ig32SclPw6xUH5
OguuJU4ikaQSuLuTE3KH1xRH/fy2+InfDR5iJm6z4akt5/vdfnG4GNAeYCGp
7X/FyDSIsDAQ52hJK8zhk/uNDLXeCW549QruZuVD8ipT/OmrYupVmFJIv8jj
UPBqovU/8Hw+c378dnpiIT3lz7512+bNJb5JaJIc/+hd3vtdN+JwJbxZPMAL
6Ew8YM2wDxr4eVho1osPjfLkXvOmNPLn7t7lwYcHEV9eRwnjHLdwmMghD9eC
9HO+lweXKN8ri9zHv3xRLPcGOPXDsJ+vlq/1a1H8l0sh8Vp0/IYBaI9t9j7P
VX7D/aJiwie+iV6viT+If7no8O/d7ovP/x1VPpDk4cZ6SJG7w0tpiIu4/Kzg
JVrnw2L2cSJBwj8DUf/Mv/kzfPPP4rXQDBEwRNIpu3DVSDQ7yuIqogTuraQY
rQVexwJjiOk1CrPp20/X8Sje+/W4qiWjEvp3mVURfVqsll3zxZySOCKViW+F
rCU7sCXmjYkQb3vMFEaizJmYe5HfsfF3vuUv8jG+8TuYOO2O/ifn4E/87R+y
cJoav8y/KZv21/Iv0vO3MjBN/xkDC0mg92MG/kCTe0/2U6766Kf+KsZqDX4n
a91c2/8FmOt7F/5n+etGlH93Dlvt/p157J405BzjbocEFi2Ao82piFEHJUkJ
TeTdMNC7pG5NGpN7tJc4AD/n46T8XoFwbthGcfOoHwVyE6M1u3gE11AtnTG8
oLi+9zNFXja+evqf+WMCvLn0aeep9VAkQ+AyTDl/Kea/JsnUtKt+XSj3UtNf
8SPEPd72RVm+xF1FxAX3fW67EzjH4bnzqCf3W5k82goJn6fBDrtbSv0yO69x
8FngbD+QOf4BoX8bNdeYtBeTpP0vEU/8lHjCryee+MvEE7BceEe+30alm69w
KZbeykb46YXPf5wevNZkhI/pVRLSLUPVwIsLVDRNVYJSAUqSie4nmCEN61n3
GVyU1hsO7gaaTAKeOHnzagriWxb9krjn+ucKlbsDG/LwTeCc8gPk5BWvcR/F
cvbgGLJPeIzzwlUz0olEENZ/TJjTMBhJIdl5Pv2z4USO38ASm9gvd4fldrGM
/IJsg6V1+H8sKKS4COkgpMh8z1kQmSW0u0rNpa74oZZwR4w7FMz3yBmKF3eR
wIFOWFq9joda6ALdQtlHnmZYML/NEydATv9SG00ehzALq46XA6Wi+Y1aYrBf
LhFL7VzgFLwYG8aXn7YOcT/yoeBc5r1kl+E9IECFlxO+fSACDyzDD/u+MJ3x
iAybykVThQQ5S0ix2GdDfoBapQaNxcKjwmvH8P8gDlcL+A2FCoEBBH7gsfed
Fd6yDTyBZ5WE9LdJYQfEicwXfJBAb7c8X1jiLpBG7z/C9JTv87raOZ1wund6
aLcUo6RSSnzlt9+bYby7mfj4h/SlQWF1yaJ+uj4ywid+ul8lF5lrHP2Jevg0
bExqYFTASBg1MbjnBCDEXZfb8o5OLCRIg1vlgtjtysjhIzguKV7Fdyh1gpqS
YU2cWJcCKGGzjRB7gR/zfOP9dLdU2s8Wj/4Da0eD79b8W2Lx20F972n+ngD5
O99P+C5Avi40VS75Ib98VuX4jfxDE/w7MtCH+dIcNPj+618ddf6ek/qhl/7L
J3W/zGTtnwKyLmCgDdviCLgRz4sSMF4kmonOvCGN7oLKX3PyqYLG7zh7nOWW
bsGj/Lsf/92Un3LA/RO/ITT8D2CDu7X+rTmB4r7qdYwbJDk1bpCY8LSX+Jsn
I0wIWctW5O+XTPyXP4B9f3DitfwX7mxcIQfAZdtNFF9sI38rPoPbfsKjSkw6
SzzN5PsVH5UjhckRvpuNGhlicb+5kfwKy06jbMIkQrVlGenzb//2b8IYm937
tUL/QZEUTcD0xN+kbvd50Q7kDrbyRbr89IBfyBzbi/N/GRRKX9HwlMqVeruO
6OG+WG89N+vF+kAc5Kt94sxCuVpvC0J5/NzpDfoiOMr/IAjwGP4Gs9/SPt/E
fr3azg+GvfLDtcGS1lfpdVqpUPHGtg94iQKlfoBSIpJK/GOx1Qd6y38SLhmc
30OiawooRapfItOtK4yTy/lswZLyRbeIajC287FI8O2TwsGNAq3BzQgokqx+
3OFf51Xgsm+exXeHn4KP0ORfDA228Q/YOAX/iR1ewk5XM+EL/OYHjtI94Im0
k0nC+VvhDH8LCfj1MIbfXl3/d1sfVdX5aXwWlHPEWypzm5zP91z447OBZ+/K
AZ8I7G3jv1wT+DQfe1MIfWDtjwWIv+AjdFPJQzH/jE9cpymJhcmnbiLlYpOl
pxLOv2Px91nnX7/81Ky/YQMpBvsLP9vP6oo/PKxfU7v55TP6hbT6pzT4NJ3+
16XSf1294Nec2n+SDXFBTQFBvsAWv6aTaPDENecZf7pdGID8C3baONiAmXo8
2Eari1HEWyA+45x/FcTvK3zpD2/U/oafPj4+Cj+vYr6AlH3FB67fwpfxz0va
x02kX72M+91uPlFa/5p8/v1uvhP99G7K7RL5VpjKvPRNFJMmICfVHHdtqkgl
SgntkfKzL54odqVQd2BEruiesLaVSyuFyFHu3nbPmzsizMEgqh+9wUvDq8eS
UkG0xZTQd/j8R6FObrlD92mwrXgkJHWC8I9cSiyn+iGoVnKMUmjlS6dmkg/0
b6UgINiKXRpJyfNd45qPSR8BoiqSntvkxgmE8zMnDmF2gRdlMOi6rAzWk6Qc
edsJ5oH/iLeS/ImafyGeSlRX0oxCsccfP9xL8advWOFAsosepufWjPlxklO8
kPtjHwyltcN4IVyCwGRL4jGEKM9lvGmWwgWyzrgRyl8mzaqE+07nxXEcgdAr
Ppbeow31zOJgSZ9o4KzCZehseaWeA/zp9ZhWjS3k1HyBGTpBGDnbMNpj4y/G
oNMwOaYfH/qlVTXJxEJc+CDWsRuA53hFvHxgQT0FW14bWd51y9+iXRehY0iJ
jRPChHEceQQ0ALlA6l1b+2LixAQtfDd60rAa7yJEGkf73aWNDoYA4oTAv8dZ
6M2QkJeY/DL/fZ7xUSzOGAxMwOP0FLsIxrr0N1+Ojvc5J4E3P6G76HnLsGLD
/EextI02vE2ILu9JReFwLDPg53O034K6b9eLiPrbYaEiwA/FeBN9mBDvB6Dm
x4+k4Q2k/NQuDUSftxpjaweSl5LjO56voLa/W4MikGjB2IYYgLB0xHNpkuDS
b408MNx+7azccLoHNqLWCAeW5OILePS3876tg3aSpw6c3aV/DXPXbHvgIXbC
jOf7BPilCKSTxrt2jVFrBi5jA/qAKhe7awcGHzSBqPkHolaSGaHU//ZRvPRc
HB3++ZVweF60Moi1vdk2Atc36W5x2e7ICAC3PkTYbJg00lx/gSAI78whVvD3
HsNcNOj2AhBlv6FHe4y4NnVB1B3wUswn9ViUR2rem4XTGZBjReYprWbYOkaG
otITvz4BpH93FtInn05fJNhKTOLjOwdnGfpoUkCPhJF/YRik40U28byG2EBF
p5psYJtsIKU3jhznSHUB8cd9YgLvyu83aw+lfv7rpaHa3/Oi+l1jIY61wr5y
NFKEtgW7suEtckjatY8wusuCuczzFriIqwWO3HMCNt07yLvA1ZvrfRDJRMLH
iZKrILiQJOrumtNjOxFJcJX628TUxApyj6Sn2x1IoNDYhR52FhHj3ywwzYLk
Q+wwSO8RF/gLFEY1D7qFVgLKQeCaiBQ9MchmG7kJAySduz/S4iFPIiJZgIQM
WbR/bwLw7g604HSeKc5K+inZhh/0/QzYXPap0Jr3bgol2wjg/NHPwRtIPsei
37JfSXYLhgctwtZ+eBLzXNre9gwbs4TL859frZNkwdL1/i/3F/RIX4UL8hos
3L+KJeZRx+6/JnmKEu2RYMWX1AX/qne9ZvPyMbyN97rwRy4/fffnB1/h24NC
KXnk8xwYffU//lgutTuDck4c1Op99FP/x5/gbYFoDJGHeLnLg6pnv3jj0Ed6
GDd6wCkmlyX9iXMeunSpIiDQFN2r/3CyqdrlkU+zOeLPke1fMZPx/dvpbMvP
ER3XhJKMTI5FJo4IOah3hdAyb6L8gFPAGx5iajleBg9Jefr6eho4cgUtJHnZ
1ND8jqiSs3Mut0WJ4givb4nWOVEVv0gn5ZZx63Od1yazd3se/zArZ8s538hJ
Bv6gBTmP5QL19ur34VdOnMXx9YE6tkRvc2JR/Edx2P8mQmTyj+Io/01swv/X
2HbtY3zagV8K0RSc0GL+tt7ELt0tqA0aq0BuVw4s51mUNVGycrqVk2WRJKHa
Gnz3Qp6uq/nsBfX+hQTj87uWm7z74VLg6J6eqS9/QLDLH/gsVVzKfff9czfp
aOcW6/sH8I8k5ZL/5NztZz31s5bzpJxt5GTl8xEsN8ecnGrlVClnWjnm5gIj
F7g5Tc35Zs4Mcjb8x3KWnFPtz0dgSs70cq6dU7WcxnIGy+lqTrZzgZRj8KuV
M/WcBf/BgOrnIyiwBjtnujkZRjBwOhjH03NMzelOTrZykovLY3pOvnEmFilA
Xq6Qqvh+7OTry6Hdt8B8vwzkFz2XL+QqWq5YyUlqzrBzkpIzgCr5nG7mtFKu
qOdKeq6g5sxPaGnlcc+KDBv+bB35K/juP3olBQigPTLJ6Jesd3EOwuaQIoPv
hirmc4PesPzZMFf05M+9ntJlPDVV7DXpJ3r0Z3XL7UtCf9y2eWPtH/2n5Wwv
p5o5XckFATImMPL1dT/IBXpOd1FiXCenSzlPob+9nAFfqTlXzpnAqkFO8nKK
g8LhptgWomEUJoZqkpmoZkDafCdn+TkHxMVEumtKTlVyPkiAndOcnObfXg/g
ARc5GkaWvZzu0eGqOC/8Csu29Zzh51Q5Zzs5z855MLJ2ex2GchiuB6TWg9OX
cw7sNMhZsBLYDkM5drWcG+DsPowm5eTg9josW4dvfVyY7OQMPWdKOZ9kzjVy
jo9LhdllA4kGOkCBv1OzgzhaBu4ONgWTOlrOCpCMsEIbFIaGYqqoOUWhjZg4
lK/fXocxFQO1iAzLdnFSS8HFyFLO8HDZJixJywGFPWByKedKOTVFeVAnro56
SKaHNRn3ggct0WZhUhUPVLNylod2zJdySmp2eB4lyEWa6AzVoQIDmvg67Fem
M4VfQWP5Vk5z8QeWOjjVQ1oFHnKUauAJOk5O0XC/QHywnEBMx8LjU3wkJizS
l1NMq+DUMAKs3yKVJpuomDU4buBSUHhmzgEVy5AfYF/AAEaKaYHNgB+YjBoR
uAKYDZYHCwYuglmAkqBiQYMyDXcHL8Kh6KnXbQXH9F2kG/Czz5B/gHtR2QOT
mzlLwhP0iZMZLJIh8W8Hp+bAogIrgoA4RH/gCjgg2DI8hubCwlUB/8Oho8Gx
0CDcZgeuM3IMJgqQsJ6Pu4YFgFQyA99C6aOfQXYUDymjpkgHFAaGAd4Azgci
IA9oOT3A50F8gIVsGymvwgM2HgQeR8opgjPCx1SkCXwLC4MtwxpAWBQYkGQf
WB34AWYB0YadSqlzh33BCPCJ65J+cHO6jSLvBGQbQVK8nKMiQeCMwBIGTk5K
zQ6SEoC8wKQmiq3sIgP4PqkFkAIJtQ38qtMzOIWPXHF9HfYFvO2SJAJVYeXA
ACZDghsO2kPgZE/Dc2dEcxBAKfU6kAJMCfCGo6B/BzuFA/IM1AlgaWFS08bz
Qr718IBgMV6KbWAKYC2QQRu0Csyo4i7gvOCMQGkA34K/YGukx0Ar+ih0jpHi
eToykHeYF+y/C2sg1oUXgaqwXyQ4qVk4F0dHVaakKA/fgnIAFQfSBM+gk6Lh
SsC5QKZlqLFBphxSAvArckhKWaGMKEgW0AZw9MgbHsoX8A+MA4oa9gXMA1/B
XliAllRKvQ4eMdgIoDCwN/Kki3sB7QfUBusA4gzqDjYFjyFNiAeYlVJWBs4I
c6GG90nXWShcuo6UBBMAqwUK4N4dlERgSD21dyARaAmQODh04DGwNRaRAvYL
is6TkSHhRVXHAWE0kAg1bSIZ0hNYEZYHPGYaKNEgRy7ZNSC+6uJhgWumk94D
1aGmBBa4AvYOzhroT9AbqK59PFnYJrnVOc1GzQ/GAqjhkWNop3xDmA6F0UDV
BCIPigheB5ME/AlMAr96ZJ1hC8DVsHKFXL+bxHHToKOBA2EBNxA5kKwVfKKQ
xdFIHcERgOEI5DsTqfqo+WGFHieUjnoPjlsjFxVOGR4wKMoBTQuyCbznpZgW
5AV2DbvzySkGWQPeAGoAeUHnAMHBcsHWgPPBZCgWWkMvraxIy4HGAyoBo8Kv
LlEJdIhJTi5SjOEa4Gg0Erf0udt8PSrSB+hgEpv5RCuThEhWUcbhIFAnB6h+
mX5noEEQgDgucTtwGrwLKwfKgwxyTwMYDzbicB3ioUjeuE4mq+3iCoEhkfkl
ZDAwT0BGeB6+lf0kGoDjAD8qSHkXcEYwOIgbcCzYUDQKAf4AfggMggQ38QFQ
UDBFQBpVTTsnLh2NjioFSAqOv0vci8aIoWijxjbIfAeowUCh+WnnhPskBi5S
428FaGdBAIGqQCuZ4gnYCOhe1H4ycn7aysCm4KxhzSjRFgqsSbsGpQQHDScC
s4NGBXMJmlAnrXIz0DAyQ20MP4CEgpKUKZYCZgB9DnpGI6sB5wVSA/wMHGin
Fg8uENomk4gsIYWBvYHsLtEEeAbYDBjGInmxievSjhlwF/CDSyYe1gAKwSD9
A6cDRwwrAUKBUMPgwFGgvmCRdkriQJuBqyORZoM1AKkNOjsw1kBz+Fsm24FK
ySSf9l7egargFYAqg1UBqdEg2khqpJuCewepAVsJ6guOAKkqofG6zc69QQ19
P4e4DgwTLNgmZ8ylr0B2IKwE0wzjgLlMkw4YCRQa2CCDTDPoHLTpMmoV4Hb0
0j3kBI1MDJw7969u6sJBuoEGAzsLE4Ewgj5xibw6jWmTwgSWc8lZAoWcNpEO
ueLomHlobnySMmBd4MDEn/dRk8MhosVxibHT3oWEJwJyB0RGkddRdiwyGTBs
QPoZFJFDlgtdUOVOYDFVY6C6AFaBYeHIYBDYCB4fxSNAK2BmGBM41ifZlFOz
gy0AFQGhCrwIvIrSLaOnBKPBxsG/BTUCm0I2UND+GsQ8t9kpZgGdBptFqTTQ
poAf5ZEfDgQEPvTpaHh4BY6lnhIZnwQEjgbUAsiXRNYf9BtYOpcEBH4GPpFp
I3Bk6K6n2Ab4CtQyrB+zAgGKRkA+MwgpENknkw0OP5gbRsYLVHGQCpZlcpKB
nYArMI7zkP08soPAZgHRBBQpHCtwrEUegpTeu4LaD9YPQg3Oqukj0WA0PCMZ
mU0hD98gTxXJ6N1xHQgjsIpLnlVA5hudEwMPXSMN79NiGOln0FcgMnJqdgwZ
FHzeo3AP1JRHsSrwGCwedCZwHSxYtklpkAZmqb3DaWqMHHgZVwuGBlgaTg3i
ApB0oDwIOOwFNAlEBEgo6c6r5Bkm2ALELHDcNhlTIAWelIWKHb1lCdUOCrVD
BjStrCy07+CyYorIwENHC6WhfMGyYVPcb4SjhI3Dw2Ay5JSyglAFpBX2KFEQ
rdB+GZkYUBfwN/AtqCMgCGgJICMGaym2AZoDS4CJh7gPtA1wBWzTII4FZQUC
7pAVA00CZxeQIUufOzAhLklGNejT6QTkyIHtcOkVdBR9FBagqu8mgd7NTPg4
ILrTPpoJYHUQeVS8HjIzWn+HOJnCCnRB9Tttg3lNH3kM3DAwcBiEUtYCjtgh
Ww+GA71Z0gbAn5iLSNk4h8IumbQZo5gFzARsBKihUU4AHCGD9DyytIJCoaZV
pYaHAsQEeYRjBZ6HYwUFiDtyUQZ1UlmwSOB/7kNqKse84F8P+IdAugRzqlfq
xfygTJ8KrXq9up4Xi/mxM80f64X8tP6U74Q9eer0Bpb53spL1eL5rdqvu2qp
W34q51u9Vsk6Fd/zT4VpeyQU8pNBfjkatLrxsdidlEbdbr2Uf3rpDsrdVl6r
5uVhuXA81vrV0dld9Q7uvNxr5S36vDg91oXuyl7749a0K5WPtZnXbs27x/ag
LLVKU7lTKp9e8LP3D5/N89nLhALMWC0fn0bD93KzlV/wkfPH4mhRPpVL+Q4u
s5D3WgVptvRW+sJVtFN5kH/mn0ctoVh+Oryqo/d6uV1olbVjqTtpNqLX+uzg
tfPdRTcPwzx38/inQH/Rz7DrWaNpzKdHgXUOSkZ6Hgd6hk0H6zBoLqTBSh9U
g9Leqb1UpnZra4zjYW+jd06s7VTz8VHvdeaT98IMllUVYMl+adp9KRR6k4pz
kN6P7U1+VTBGklqR3fY5nC1mTikf4JJr/Va5Wsq/TFPPCp88TPur9VqFfGCV
C4N8Kd+tZZMT8UvHciF77JbxyAvzfFsoTOO32SKs2kepUOzlS+Vup1jolfMf
/pTXJb+fNddjNTty8+6me1yWWm62cxI822o19m/v5uuEve/9ScF/a29Ub9ad
N18zw03bPseTxuzkOd3n99rTeeQOqs7ZeysPHOM9tNonYVvK1Iaupu2a2Vf1
KR/Uln0709ssvXavunuT227P0TPntaRpr8X+PLOYH6vlldRt1s8Nb6moI2Hf
n+hlZ1edbqWu2+wZrx211m3m363mS6HW7BVGT8ej4jcG+0XYGtj5JZDbXFS0
fr3pHSuzCRN2GXPSz5i751rJyr5PJm9hdz7TK8u3p+FuN3vv5de743QSTSpW
oTI56LVooG9Gpcr65Wk706xVWzBn2ps0fJUN1u++HivjxXLg7jpbFmaCbbbI
8it77Gh14xgf5w3XKHt2ubCMn13t7LBxoTWzhPXSjZvSod2bHMb6m989ZSaz
ZsE71U8VY7t5k2eV7Gpcb7y+ld42iwlznirnUv61YmVbSqa5eeoKmVO9t5xO
2+d+t71XsuZL9+UQ6I4VZXsT7RA1+oenlm223KkvN7pO8aSOnlp7Rc2/tVdm
w5tbgqaamrMfsVNnEAX5OD87jeRo+tpdWpOgUnnSC43QM5u1mrOYvK+as7lt
eLFcfdKWhZO/HmZWQvFN04f1l3NxIofn4bG3Pp57G+e4K7vyaTd9f2s/zQbZ
otliRt9rrt8Wc9aM5vnqZl0y5HbNexem09rQVOtleXlY2uHR3UZu2Ts+lWe+
q24bz5H9tpLHVbkatjejfXFnDPJnR7dkfxJtG+cntyPMxxVTisvt1Xw0amjd
TOltbMhvBWUedt5Va2EOlNlLbb+w2OgweBp1e1vHiV8Klae5pJaPg9Wr4M/f
VlLfHm9d21qPglb7KG1mxaV5lpzKUatVWvpmeTxbhX5rU3afq+Vnv/B0jMsV
RfVb+3HdFlxL31ibWrXSf3lW5rOMKceZ8fvLdrOevjTKzUKzmGHlUSs+eN0F
y6zL73P1pev5/mJTK7Wt3Vnotb22Vx8Oisb5vWSWltpZr+9fz5r8rlvD6qLE
lpl9pnp8mrz62/dYXVqVcaYQhOPaq1F4DcZZYbV+ay13c+3dnnsjT1+zaWGb
deNs9V1eLlsVZ/dW7Bze+pmnTSGoHd2hMc+slhJ8dpp5i6k1ErTjqFGplFld
qx3esywKa2Ot2Z+qT5G3nsjHwvCos6HdWFc78eFYf3oquIU2MOGw/FRRM09F
JpwPhvns9YpytCqvyk3pqdmRFFnbvr6ts25hPmTB7OzJHTe/l8qeyhZOy24e
FvHLsNqoZYZwCppRbnU3DeuNtXb1qC4HankU1gpveWdXfm2oy+GuPza3uzJT
tHpgK8Ost/Aced1bLMubvGXGwkGqLivV5bCz7erKsOdbblMaV/fBeZQxs615
LdIOM7PT7DqjTR40kh/OZbVjVfxj7WnWfw8qwjI67cLs7EV5O2aea/Wn94Nb
yi7V57a9jN6dwLf117kSHX3VnJ7fM/txefKccYw3XVvsz8bq6V04nt433afC
y+DULO0P3a3SO3XfO4We0tlnX8/TVrPXaceKNXBmynpULBrT5V7Te5kn68Vb
Hf2jK0wqwW4Tvp8rx0p2w3zvtbWwis/N537nXJ91rNLxMN4WBhU7u7Ysb1iO
Kkov2LPTkPnF99XzviysS06zezwMz+z41F/nB5NDXTk3e/J7caMWG0XfPK1f
wvZ7GC/0/GRca56sZ1ZZ2U+BbI4qx3xeyOdHeu/UCN73sf/2LLXjwqzs7O1h
o+wuqsFk97zum+vBpLFd+Y1GLXKnpdW0WIyiqHMamcuXNyHyzkO5NHFi2Vu2
GlI8XnWM+uH8xpbLhb2blurF2SnjH58yi3Nh/9J1t2zbVE7T8dgPJwe/0RZO
3Z71ojecMHAseTmuFSuS9VLXJttqpv7WZkzu6L7dr3Q2k/h1nHmWXg+gdoN1
dVKtn7zlURLaVc/ZKBt71HierE62m8nPCmy0K3G/qNwufe8VJXBhakT7+8EL
6B9U+rvhC8BFNBk6xhDCQEgODipG5Tplayk7alqUJzQxt2B5372sUgSi+z8P
SEj+XUz+J41IqPR4Zf8Z/9WBdF2fiPpbsAhP+6UoS+iCw1oV7ZexCPiCaKVf
+Dkswq9e6F+BQrij0uUPfvi3xSFgNZ8H9gYmXCCqNKhSgvGAjzHbpyPo9LpJ
4ROwBQRjLgW9JiVtJQWHcih0CbzPR4ApGNWxTIqOIHxyGaU8qHQHURPmIn38
1v0BFkKmzCCEtfAiZhh9jEsxZUw1P9OgnDJFUI7/+QjI4hIG8JaCG8fFBLnk
HyHEP39b0AJEasUyikhex1VD+F+pYNCHWcpyrlDMKSVkvjJIVhnhBN8NAK8a
BUQZlP5K0MLfeyX/yUELV8n6VagFpicRu2thQo3X3SH4DyhbzWseloNZiVvi
gEJuh3KIGHVTclwy8DGfMl/AmcB1HikbmZK2TorJMcGnYAZQowIwowyXJtEa
7KSOrtmUK1GwVuEHyPm3xAGlZYG3WUCVdQfXj/UbymbCkkC/w2phal/CZJar
YyH8lu1yqMpOOXTPx5yCTKlJh9KjNlUssEij5SQT5R1rQuncuoN1CMzr0YwG
pYN5AU8joJdhoqBhrUXBGgnWUFMqgnmYztAoF6/LmFJRHXyMyZhklzTMSnsE
WwLGVW3K66VyrPiujhkNRhU4j7KcoGrgMYcMG5wL1ikp+WtR9VpKUd62Ed8g
+6hYYOMeVW1hIkbFVNCQNv0ny5hrs01UMmaqHIXZWKpvgbHEEyfsgkrZMZuq
KQg0oaw0qFzNwzPSUq8DlWxKAuLR61gyB9IhPIKo5NKZ8mKMbSHDWFSgvTEt
oSs0ynUCd5mE6gDmdGXcEecoWAmoZTgILMQyHPCWmtcwnaRSpRCeR2QG1VxV
CxkpoBwZfG7R9h0qD9xl9gmRwCFkAWXnEWNGWSeEYqikpU1csG9i3cvS7+rH
IEpwIo5EWXUbiwpYMLYx2yvzooiNhw4DSlQmkfS79DRwF1Z9dNwmHKhuJ2Un
RhZEcihZpiBnJslfFc/xRjqVKo5UucGyE8GMfKrqwUlh8UnCuo5EeWeXRCNI
qQssLVMRCyhjUP5aNpDnXapaYdHaxh8QNiSh8II0pctRrkfFS8IHWAHKCIIw
XNwmMIBE4ANMJtpU0bRJIlLaBgwco33BocDRg/ZwKNevMZRQRvVg2CDIOKgR
n0ogpn1HOlRlChpxnUAPsFSVkpuGjPzgUcbTJkUER4x8mK6dE8MbOn7lyWju
NcIk2SqqHZvwcFgec5BbMNmt32U5FRUFE2YE3oNdsAsiKghoEB2lGE4cU5yU
dAYucq07bYN1Ow2fhH3ZtDbwQ7AgqiKtsPBpIlkMsu/wiWPf6TqJ9InjUvWU
cBJ4WKTekckd5GdQsA6VJOF0rJRH5PNyiEnZfx8VC1AbLAIwgEUlf6AMHLot
o66GYUFg04raonI1POMTtgzOCKaDg2ZURQ6o2hTw8pKDDIOIinQNlQq6yBgy
QVWo1AryAoeOSd4AM8WYuPep5kSlFz9VGLB5pYccP54i9wj44klUi5Lwc0Td
mSi2Dg1upETGptIj1iwVNA3Ab/AMmBUwNCql3Rk5V8AVwLfwJFqN1MFJFEJI
VK9SCdyAnEDpdZ/q5UABjfAc+CvVDNKFfxjZIdgW8jwV/tGQkRWGn3WCpoEO
N8niBISqSSN1AjIoMh0ZWFKdo7uoSiGREgY/UKPyPOgTICNWv1LKyqGTQnCP
hQof/gb2kKhsrFMNA7aMPi0hPh3SxnrKyqgcSGeiDkdbL6OJUagKBfrNJW8B
zbqNeo/r0nQlD7UcoTGAqvAAaA/4lRcRNYeAJhrpagdtKFZQgrtSnEnlZCx4
cxSOhc4M7NHgWAoZj8AgBQIKQaGi3V0lT8alwqSwMJtqSCbVSIDCfCUaKVtg
G4Oq6cD8SpppyYjAu+CKoLwTDTUOWTBw5SDsoPQ4XhDoqUh3rpFKbAlSAGQH
cwYKxyBIJWIEJSrJKKj9QFEjFsRCnaCk8SKEhwPWMggDp1LlA0gElARGNUjz
41dqjqMnwUKlK7g2sSt8iGzmI2UkehdsB6gvUFyIPVJwKIlK0Rx0kgY9gEpU
qDiNRs0mBFiAjIdYChMXDJ8EREBYgEpHny4Eurw+HeARoEvmoFxgVdsj+fJx
JcC9Gi0eJci6OziDMFIuYdSARXGFHmnXAC0XyD7oedigYSbgSC9FefgKmEol
sALII9DNoYoXnLJBFUSEBzl4ECbBMVWi5E3iVFoeVfqBJeCsMVSUCadFjqJJ
gHaZkFW+QoooBTcBtaaRK+LLuFmQJkQ4GVR7kwlHS5FsgguR0fSnnVJYIZAF
tylRtEsIMxAENOWM8Luk/WCFWAUnE6ykUcguibBDiyc0lUtgOEYspJEzCWyG
eA4VOd+k7V9fh13bBIcClY56TyVDRtoSjCkwiUYevkP1PGAP0A9p2AGIoUPc
Dq4mSAqHtuikadE+EkO6BFhBMJNKW9DujBQiq6gAj1gZwhdqdOIYv0hYWUS0
LgF5EZfj4UZupKNghHFvJMBd6OSMqYSA0ShLgIdF4A+fityGdqcqJfKWA9JX
iPOzkl4DkCyJKv3YL+ChEQFXRzfvzATYL4uEFBamkesOxk4i10Ijj1Gj17lv
BmQHUrB7+LhM/IwoRongJh7h2wgwhxZWx0OHE3GobA+Hq6SCEZBQk3QyEByo
qpFOUwjwBCeFWQ6K3UwyWzZxnZRavEyGzKT6t00FZgSk+uRTUUwBFJAJ7KJS
bOK6d5kKmfxnlUwVsjqhYSQKFWE6lSQC+cqg0XQCwaR9Woo7dEqwqDQ48B56
a+QkIK7IRRMMWoKjDIF06WjCIoSQSSAqmVpCNJIvID7oZBiQkdcRENxTJvur
p4wUGi8X2ZWzCmgkbFpx8eBAQ6LPQ4AALrnAPFJwXzs3CbRKsCTwNCwCpgAx
QR/CGTHicJ8kxSSomeTfBeDA24gP8FGXWmTEUX4pXtZpwRq56BjLa6gTEKmW
OjiM0YgmiO8nTB4MCIcO1IABXdoCMKRN+scnheak2MYlTIZLa8agQKdoRaUI
mpGHc0HDAG3hYeBwPe2ckF/k8FYgin3QRhDiFhF7HOxi4LAapQWAi9SUogZa
IUrGQe/LoWCKR2Q2N4skpNzug/oCaQLi2Gm3kBEChnSyT5AgECufoRsGQmRw
7BdZN576MM27ViPcL8VcCPSnt2DjFvn2qAAvgQD6e9TLBmS3UkwL/iT8KlHy
EIWdcNLAP8DtICmwHpuUMFgTj3CleHapxYNB4SlHlcCXwCcmgcWx6cnH4/Ao
KA54nOWhKPnpfg+D4IBqgqDCJg0VXXQex5l2gtjWCY0BGhsx2anMCRgIn7xl
j2BGDgUUGiH8YLMK9TkYBCYG4wJBHKq+tKKm3hWZsH0aYSjhb5uQbQ7RChQU
xCnoqZLOsYO7XheDIPXwikXgGEZOLIgAoyNglJLCZhWSBfCLHEpBpC2sSYkR
RquCs0YXhRIRGA+qyMlwCphFIcfSIyxU2r4bxDYgKaDwAw6yN3EZcF6g/0H2
JcLYwd8eOahe2qe1EowmLAP4UyVYLagI0AwKRUMg43C4tptgrDHESzmlOoHa
saGCJ8qIixwiFHAUItJ05FJMRPiJoWEp9wDE0COEmUar0ihe8+g/3Dil0RSC
oloE7bWVO3k3qRHIo6ScQ0gj2IJByRad/H+dEsvc8bOpLcRNhcA+eYkB+ds+
hxga5AqSi4IIfhVX4hCiVCUXMQ0j5tA0UOzoRlJvgEbBBc9TwQ8a4eFgUptw
tNg3mlq8TvkQn84Om5SIbgrlCWEjFrkWKmV7AmpcQZFM48MIMu4SLlwh7w54
TCeEokRxpUTgQp8OAnahkFecDkYcSqOBXMBGgFAOhUJwoKi9JdwCkAJLEvQA
Nlmlc1aM4KoGdWhQ9AeP8bYiRPnTwdkENLQpxNY+eBdkXzDuVtBxDQhdp1MY
Ajs1SP87FFshKNND5tRSXGcT7gqkgE/KKJLSqR8T1JTuJulWiJJ8qqJ52l0Y
CNobDSjvOiNr7hPwFLgIVAFGXpQrswmVaJK9SHtWLrlPKrVzMuosUske2dS0
gJ2HZKANhuykUq8OY3c8j8g5CkMUQn7bHGxNqRv0SFVUlYi981EGjXsEtk/u
q0qoX5Wa30BtglXy9CTPY5LkeuQ0mgSek7U7KwMuHwgXo/YeIJdPGU6JI6ot
XJVNXgewdEDpID+NByW8uEMNHgiEJacX1qmRwoG9I7aYYjQwfyDXvMv1Rnk/
wXmjLXBRrNAmeui6KwQNhxcN6sGwqIMFU/dp7LuB60HLS2BHjxrnYEk2qT7E
R5J618nx1unnu5YJg7IiMrVUkb61KONkEKsAN6IeIx8VloGhsYKbvel5SqJK
pAA5kBfEBAhokzcODysUBsKJY36YXDjbvBMZPG4dF68S9hEzNtRdoJI/zPsN
bOqI4EkY4z6aAFbH1kEFzTrvqwGRRzw9JbThuJGwLIEbAo+liwug92wK/TCK
90neCSuvUD4fKIO5F4rCeKocjKyb9mmp48IgZw9B5yotT0ow9yblaWHqgPoG
Feo6Sxtok1xNk0DtHoVUwSX9EpB9x+Yc6ltDhCiB19PVAZ6sUClulalDDLvd
qOXG5u0xDHWXQ14NxHeOd4dGxawUeYDoR2lJdYafIxpWAzUwo5wVng6x7l1+
nrcnybgp7KghCDhvYwgobAmoL9SjKB6MLGbnUucOphxLGGbS5gTzwgaxz8ch
1LiPB2GTytJJgSN/SndGCnQXSAGieCm0B1F1KWtqUzZeomQmuuh20oubBq/D
iwFB/DEvJJNpk6m7gAoTEGswyqujh2yRTJHTeCOdjlRFG0Ggc1gqlk4o2rWp
UR0pJpOjSKoSzkhKKSuV4kpU4C7RkGSTY3+Bhi79jUdJXhbfi5ISWMxIy2SJ
qA9Hp6YC2L5PLi4sBhvVHGR4EEzVT+D7aTMB7r1KDaioBimtp1B2EXsAJPxQ
p3w1I8/fJj/5pi6oOYdRphqOnhtWi0D8aOjJIvMQ1abUt+betYM6lNZAcWC4
YGx+cJH4IF8Q9upU4ncoWsHEvkZdi+l2EQpAPK7hiThYhmC4QofKKxo12gF9
AgKpa+ZdswpKpYlPYtefS+BvIldAgbxD+sqkxFdAnWkaIcJv565Rdy5Bw2Vq
Kgg48p6kQKLuGnB3sWwkUQ8e6a60Pw+b8kmxM8oEYlpMxcdkqrkY1DIn0fmi
9bHvMmYBlaggFMUGCV6zo6gEmzwpP8mo2QOLuT6uTZbuCiseuROMHEIYB1QN
sDFwAvAtRs067d0ipuUdFDoazZtnpVEe20BWMcnHw55M3nBrox6TyTh6VAUw
qC9aTS0e26cJDuGR3+tT/cil5mGTisKwBoxtqfUac87sDrjvEBoAHrPJoIAm
N7xEI2GLIEfMy9QgauDZKf6dY6bzXBZlJDTCYNjUyW9QPzAaJoOs27Vzhto/
btrGR55RaHCTXC+DAm2PKrkqgeBRnCn9pZGjkjZSIONAFjwRqhhyHsBmJ+p1
90nDwH8Qk7pe0rBkp1ugdXxdJy/Ipv4i8OF5xgAUpk7xBX5C7o1OGjvdGseI
GTC/wdBQYjRBfUoSmXWf2k40ChV5sh1j3nT2wEy6v3Qir0vVUuy2pbmA7bHE
piZtoqBUOWzm9jpFUg71oaGqpLZDrJzy81Lw+LAWSY1bFtW40/V38LIM8v0U
P1kbxKoYLhmo6DA1LVF3LoVpQHMMD607yhvUUelR6V+hWMYnp1qiXiOHXFPY
AqaVSBtr6byNjpvSKRoC0y8ROAejZocwEhI+71OTNvYREW4n7ZBjfpuyBAa/
DsVHXQpmCDwBhdLLKoXnvM8N3DbDvWsHBX1okIqzKCGMVoxq7mj7AsI4eah7
DRrZMH91s0SzXyoW8y+ZS7PEcFTTF15xxfLWyNiMTprUZ7V5pStXZOlYnE7q
jeOkUOgOa4WwfhTag1uLQmHWKvaW9VNpnm9dWxRGhZm3Wr63epNjJU/NFI1S
Xi66ii9758JEGIzaA2pTKGjj0qAutUreqVXKa625d25XIvishZ8dO7fPjulJ
hd8z63XSSusofNhTqZc0RjQy++zrbMBc/dUd9DfdfG2/Gxcbx7K6POdn/c04
e37RnnaaMN85mXnhdHxuz33WrDuVMsvUjrLkzS3Fj5vNqiNtFvl9Ud3ssqrR
nreq5WMNG0t6UqdQmJSFSrXZaTujmp+1ZrOzYTX7wXp+6MqOlZ20CtRZ4teP
XfjZyX/2rHB9mLeh+GXeDFFp5alZ4lia0mzP2DBRyHdL+Wm52spH1WIxrua7
w4pQOE7CvFZ/OvG95/VJGO1rnd3gtamN67VKuGqPnTfPHDXelEK0fbW8evNc
9FjfaD5ru01ZMPbzc7cR6qOn01N7Vl+oan+n99eHgf1WL/UrfkfpzZ/sYnn3
OjLgmNT3QXesOmd/vZi7ft7XhVmx4lhFt11/6Zn+O/xflbnNZqPieu9xaxgf
hqOhMWO1RqEw7rgLT7fZ4tQb1nae9/q8PLzshdfqm+3tiq3KsfFaLkjDdmu7
7GWe1deN81L2X8b+2ilZk/5yNy2w5xUbs3nTO3d2rcbwVV35riP02Ks5L492
u/5ym30Nw3AitVrlplxUz+OTW/Zhn+u3YbhYh2tpUrLbtWFYms7nh0wc+7NZ
dSZUXgemzPQoM+zrz6Pe0TK18dz39rO+7EmNUmU1arYY87xqe7l/7tpxYVR+
b5TGYX65DGoZWROK8Wto1dSMp09Kg2avqB1LRdk6bIe9UrlU7WvtrFGR6lrP
dSYvvllmeX/BrFPRU7tVq1MbMWEuh+xFOZnFRbn+MnjZdKLWq1ZTZraXmdfK
Wk1zpNIyaA5CdfGeqdTD4Slmrc1m9mz1rNV+PhJ2/flpVh2PjsGpXdl06gtl
3chs+tPlUJtvZ/pU64TSIWu9LMfl59a4bx62M8c490ehPozKljoX3l7Gqv1i
uG/O0ih4xtaq9EKl19Si3iZSDWs017bB6zl4Ml11NnWc9ioavC8G7ms47ndM
beAJ43zLKXYGY6vWtNxJVGg/DZbZ46xX1QqBfgwm6/N4UfOeNd0vesOWvfKC
dcu2imupOinsTmwqjBVnvHm2w23hPJ0cpWOjs+rKo9Wi357WZsen5rMynW+6
Ay+2/Yq9Ox/NltPdzM6zTM0o71ftjPCy6g5ZZS77XknWeordHwX5bn5aW43t
UnNfXyodZV7dtzVrHB7yi+WwvVx1JLWxLMr186HHQgFIW6v3p/Z+O1kA2+u9
Wks2+6tFtfm+c1pyYzUfNKth5n1sbt5Xp/mevYX9p5fhctrtzWvF+lbYN98K
dfddXzszbVV7sczhtrpTsvlFf7CtBUtf67S1wXSstPO22R31nuqN+vF1Mzgp
cSV+lrWusNg05qWaGYXnSa/W9qPzoKLHxmA0ORaiY6ZTbXZX/f5ZngfutLQp
n6a74rEvd/dBJZy/hcWMKdQKi2ZJytuvmWkzE7vzzrB/PkyibN1X3sxGp9Vv
y63VsFOVpbDgZF70vbwKankrWw58q6+wSFh6T9b5fbeKa6vV6MXexcVVY7w+
7FvV+bs6LG8WwavuOUa7Pi5otZHat63sujuf9+aVxmpzcE5Cp1ne1rXarHau
7FYDq2uY1Y1nTjOt13VL7R+Cl2LgFuVos5pkTuvM4tTd5VeK3FGDeaGw9J6P
QkHrmHG1I1cW8/NmlT+0llIY+RtlMPdWw6MyYmdFL/Qzg4Y9CI7dJ9c2XsLB
qeJNnwfHgxe8Cc/t3UHb7+LAak+UQUXtS6r6vj28nKv9ed4f65u6Glkd7akQ
HpvPjWNjZM8X0/H6rb+Ve3lt1hKk8rF5yp8yTRYEVcUPj+2qt3UPA6s29qfG
5rjqH19ZSVo1JP/w1KpM8zO96Xf7vdpx6sXqaiqs7IM5HmRr2nERdAf6Ym9I
r8+D8Wxz6G2KBhgwqTE6xcHSrkw6r/JOazfjmjXJrj15X5Pt7JPQnCit7tqp
VSajZv3YmrY7ZdeeHtms8vxalczX1rCldbRpf9aevnWatU7J8mpytbVbagsv
lvqvggHEaa37mdJLq1c/qMZ8X2+OZk8vpfLkZTvsdp82c+/dWo1e37Xecewa
+0LzbXlwXxfOOdsHNS3MZ8PK0DgzkGN3X2fZ6aik5t8G+XVh+txzTsY0tquV
4VO+OGg8bdhbd/O6jDKvrRazX423zrInaJsi2zNpptjLjLo7hY7U2661WsV/
X3Vq4+kRPhtMO6VS5vA2dIphb1V3s7Npf3MYzazWwAsERY82llWpl4uF0zh7
lMuZnVneP9m11nmcjWwv2qmK9NY5G8vquwlKlXXj/DA7OA/XI0c+BRWh5RSG
gzCOmmV7y0LPaOYHTnySyoO3XmdZOUeLcXF7LO/ktdl+exsajfp+mc2y00BX
NrvWdN8U3qT3dTBuxoVq3asuhqylaep2FR3Oz4d3h0m9fPAsjTKLjTyIW+v8
e/lstbRxvraW57WS0tIWgmzqp5UVvpStjTdm/X63kalG5UN2Iw9171mJi/tq
7XSsNI9SWTnFk/e5ZC37kXxcvJ2spXd6Et789xdn5fc3o122ae57mmm+NJ6P
oVR7Whn55fvm/FzdRAutmBl342wl33kC9a9PehVpcND0Xk9YDE9+drfeHVVn
2hwcvLm7OFWCV/ml1j2MzO6mDnZ1nImrXncrKdlstXl6fd+or1upsl/XR++2
YBVqkasfumdvnWmPXxv9VcfdL8J4K2V6r/rJ69nzebPb6o8PteZo3pOd15ed
8/Qa69JbzzvsXWG/D/ujw955kSVz7T9XTpWnYjW7bPSkpu9La6dhquNlxTb3
1b5emD9Zxq6s2JsXbSSVXXc1OQnNjlFjy+Nr0w5H/Zkz6D93xk8DaTHpmd3J
e7DvxKt5L34ZRjVt8V6zz/Nenz2XnuP3162/64ZdYVVYjWaDeTZr19nBcMvL
U2v7PAw2I3k9CF4XBXfZbh/rjXFGW78ETW9eWsv7ujYbFCLrJSvlG0LVUke1
TbnwvPaMsVUZd9aHqjyqjbX9+am82vv5TN/fq3Inv7XX8+5zY1Fxj6uN38yH
cqs1WRUFfxNkmvaw8cyidqd6PPqjzH4xeh73XgbBfhqH03K/4nZ1D9ZQXC/7
c7Z5ySzXy9V6tA/lUK8Jp83Sbrw3PWs7KS5e5Ln81K5MWr2i1yuyjJ4/6OvR
6X09g5G3WW0YZFh/31lF1azabc5ZaXkSKmZrXilU/cZEm0Wv4XGbbzvukx6+
duznvBWpm726YO1he9Vfy+NqbdVv7celpak3nx3lpB5bwubZc2yFyeN8J3tQ
t+HAabjjkRwM/RKQ3nqrV6f1fbboFbrmIZYWrcZMec50O+qkuzyFNTUU5p2+
tn2auketMIpeDn7ZqG8Gemcg2cNCa2Cbna5mjJT37bi6CaqGMj68evPqU7lS
CvdS3KvthUwFjGy7xKK5YYzqkj2x33rDUrSY9xaT+tl8btVlX8t4xUV2W890
ooq+j6vTp0K7MpraT5vpQOibxVh9ze+lTm3rDcCB679t9u5wke2s42pr+xR1
R6/Ph7eDOTSqcaDne/qu6BsZr2GUwueD3BPejk+q8VzWe85muJsNhpViyWpH
tVXhKWxErWLj3TCVnX9WjbNTlSzL61RHw0KzKheHc7nZZYaQ6eyeDv7qNOq8
xcepNC3X1oVzZu01A3s0LGeVQvdJaw3ah8pYW7ysJnOv2TmXCp7+Phtqp8Ce
CpX5bOrXmk9ee/a60wpZ5fC6fraLxmG2n83st37Tacer/nL8Fh968xf31PSW
L5Ni76V/WgX2y0tZCCev9mBy0F6Ukr89yytYzErxXLnTH8X6eFdaKj3v1M+z
Z3fsLbYNTynErtY8lZl+Hp1G7bqwcBvL3szJDhuZZa91GrJSdldvT/dFqWxb
3b6vvp8aslYuZ7WzyoJZb+56+23xNNQPp5IfmbpwiM7auKGWy0bm6M4PvenS
Y/aoUT7H733nubUrPFvr4t4JM3ERmP510evNPFc3C6/FJ/ATJkXhaMzG2brn
jsut0Xw5t6xpvjlQNs2o8u5Y+6E7XWy2pr2by6oyqPWtKSt543rUbDtWtTTp
vhSEVfe4bPivQX17rL6q8vrXdd/hv/72923Aw3+F+O/Xg0eFYIeDfg2q2BKS
By8Vdai4o2IG1aJ7QJQPd7RqdCeQJeW8W2POD3tgVtd/6f7Xd+EBbX9nH56V
k35bH17ywu/uw7tf6l/ZiZei1eUP//hv242nUQHcols3DUKyIFqW0GoI0JA/
H4EjGRHWR70aCEIkcK5MJXfgI6xtMkykWT/o51P41Sgy3fTlU/2Z8sSIyaV6
gkdVZVib94NuPITDUGZOoYQ9c6kcTdAqha48NTXciMTubhm92wVLkOZ4SSZd
y+lhGer67N+2G88s5swS5sQLVPk2ZLyjF6/vzefkck4t5SoEXM4XcnIpVy59
P4Ck5YqlXKmQ0yufrePXd+P9vVfyv0A3XiJdv9yPh0h9XvWh+9J8G3PTFvWD
GZeOEYtux1TTt8kqWJfFdlCHLjf1Mb1uycnlYQjuobs8TQItqYQWSretBoTE
kukGKYNKyz5DjEhAbatYz5YQ9ID3A8kJRiQNyMNWPar/ITKJbuXxCTXiU1XJ
pz4TkzArCoGumHoHRnQJ52pY1DFF8BdGPS2IeaIbj2xC8brUecUBWCxVyMFS
aEBX5blY34L9KgTOcwjSKhFq3yeAIya46YJSP7V3ie6yxSIKwfE5Dk/X6PI8
qtBghw91/yZVE//OJmGfpIr01Di826ZDpEvDsZwgoz7Q6LZOk67ntO+vTHM5
9tejS+OodRBHoOqRpaJGgekkMpMOpyfVZu7gAibqEp8ArxJd2eXwsoeJ4zhU
48drlqiqxLQ73Da/TE6im4nxzlqVhqK+AoUa/FTe2iEndXRgCSdVcWf8KjIL
NatKFyw5VOnHTiQdGRiLOhy6RDcIuvf9eBJdbKx6dGmWSTALh9qtneT6ZMah
jXT5tEVtclpq8Xh9HdUUDSqxYJnWImQVv0qWQ2YJKKZQG6FMUP7b4gNEVOhU
G1aoccgmv8KgKrtC+FTeYiTTbdbYY3ZfPkSAAl1ziL2X1DOgEOAJ8WESFYeI
58HaSASCt6w7eUewBdWNYGqJLkM1yfsxCH0SqEnpHa/foxsu03ABxSOUs43S
YZJQ4H1dJDuyiubFpTq6SZ0eQDSsTKdMq0mNW8BXrkNgZZPaSwglo1BNy6LO
FqyJ6oSS9LAce5vdJ8wxwfFBWBDyQjdQgrqQCe2EaE4fj8AkBIBs3d33ZlPx
UtcuiFvqfFNIiAy6A0yhm481j6ByBPdMd4U5xJYyYX+B93TSjRyg7BBqhFHp
nd86qZGhCVKq0qIb+LAuSw2EBjVwAm0dqlJbRBmbZBy7JiT0L6TU69gaahJ6
iSP1HZQ7bNGni/o08muSi/Toalh+xeOt+sjbzySsvenUvaaz5J5m7Kql26/x
PnUdq6E2gUj0e9Lxbkab1g9iAsftEocAkUGTAJM75Emziz6/a/OgPi44YgRZ
UqnYo15oYDZELUjUvsIb3hRcgEOVwtveCVeBzTAyngg2VBioOW1+1Sh1JvvU
2BloyXXaaSPFCJsInhq2FtNdhiikLNmOR4RFFCBxnUswI8294zp4hfcuIiiK
7niT3OSuTZX6SHk1XaV74hEJnXqdXTr90LLQnc1YrKWr0wNiM40KxoiDsYjy
+t2N6Qb1FEHo4VkIGuZ3fksEv8BAhXAeoAFcutsVr3o178rGBqEMcYOEjDep
u8YmNQV206cmSbzyn6BLCKOk29lvBpp6yFXqm0UgHdXFA37vLLVQYgOqTjbU
SH5Nu9IBVehNwpy5hDXxOMaIgyromkyJvG+bcMw+4UXSYESsZ3s4HZgAixq8
HercdjlQm9DqMultRDSyuyvPOZDF4lc/MmRIhFE6BKE28W+LsHQyYYAcum0x
jaSU6FAQ/EqXwSt0W7ZGHZiIRqL2VJvK7QbB2iT7Dkkpka/NnX2fujjwMl3q
jbfoqkWLvAKs4pMXr1INPo024BhfRl0QBv2KCoc63tH9N1GNBE4CHLf0O+Q0
BqqkVzVSDh7pJQRJ0L0JHl1p7FLzuUSQaJsuq74hbMjrgGcssiOwYEtKOnZ8
wkBw9wCNCHU3IWoqZeMCaufWreQfUoClBtQ1J9Pdqy45YxK1Hpl0Xbqp3d2k
K1Gvo0Q3N2OHKj3g033V8J9P8BTwUpJ/B4BuN9fT3UEmvogASrJrKLzkWQV0
47tB3aEu4YZl+ucdIKRLd8jI5Bsw6olCaC/12BgklfivsJgEeVFJdRCOlmvU
m3tA6BCNVKJNDRI6Xdri8wZmuj4WG5zICILddKU7BK1FQA2TMCUaOcMm3Thu
0j/f4XLoDOFWdT3py0qzjUd9CDbBLzTSbA71bLtm0vDA/9UOlYuDT//0QUre
+RW84IFgkyS/id8mySL4r00gwoCaTExqYjfvLytyOahdovvgKeQ17ATEY3ME
Kg2oUgMzOh7eHQjVIo/CIyQf3tTA0Zw67kijlhI0GRSnMGojtNU7ZcWoK0kn
l8+iFlygIUfqyKTYdXJUbGoVQDwKAf5uRopfH0us7hIizabWSpcgzigIjPof
yMUy6cLUdLOB6Sb/mgTej04OsEMNchrhj9GRpitgEdzDv7XvbpMFzgTrLJOD
IdE19j538xS6zJiuS7AII6iRCgUVlEZOS3RfskdOOL+AFo4PkWEanqbJL2wm
qFxA152YFLx8MJE2xVCMI+FIORjUVQUqWiPjwjuIDPq3I9L3a1gEfpXpanaH
nmdWskdGDSSKlbREWoSfBjqnJc6l5lK8McSlDhxqKLLpNlzeCshIhYJakImx
PemuvUejf1ggINUkEffy9hJG1+ejdaa7cjVypPm93enuX3ySKI93lNi4TVRo
1Cr8/zf2Zk2rqmu24D2/YkZeVYV1UvqmIvJCUURsEVTwRF7QiwI2oKgZ+d+L
d8DKqfumTsSOtdea8c1Pxbd5nvGMRmmpkKDji6DwRlgG36LxEFWcj7a3eaSE
L86AwRZ3hk0hskoIzRFeEiH7Ux6w0G8QBiSu19ZrPww642oF+BD7D8WTxTvx
v73qobIjLSek1zwkUjGkHTJUwQFiCiJYePCQ/QTf7QDUns15HrPdqd5scxGq
1NYEutkmMohoQSve4Mhz/vvmRZChaURbQCJCjn348gjoj0KAZyyOvrjlqn59
7xxUmm1JQKOwF5A7RDwaPJiMxOihfHLIt+qF6DvSJILyWcBXBhqlB9YyD6MB
GrRjFrW6B/8UFvqBv2se2qEY3TfxF1DI72+NNjxYdXi4vn1gGoS/G/4onxn0
xc2NQAPWaJ6qQHc22CRgBDuXZAtgI0vocIX455rwUIqQwoYjny5GGUxce2Sy
xwUERxAFLFw2iOL9N4tGAebQrNXmN7DQwNDYMgL0da3an8Nn7ARszO8VCf8d
sVU1wJy7yz2gyRrwcIp6iGASgST8xLm0sh8O/vpogQPYvkhtxggcW4j+HCoC
4vwC/OHvq7MQA0D0G8G42gfzjwRKICPCA0pKQnU8cg6Q7/1r0UowlAnRQZBb
iYe4Bc4IxMWJQ0UBuQUNyZYM65m/V2RMPhHxWfDIhuJx0DWHAAN+PxEY4Irk
gRZzUHB997AeLiYGzTuRc0RwSYCA1kOESxv7IAhdC8yEP6RzD0Y/hCEN0wHi
iRcjDwpqWw+KHRoHCInUkLGbvqsLFIQ09BWx3C2Y5rcx6OaIiQ8igJpnQoTo
MH/5Fhv4AOtkqB857FwCoEUQGzDYLHja5M0AdvsXT5kAxPTmE4nQwATYNQww
tBgkThZiFR8qIJI1Ef7Qf1mEnwSoXVmkEBDtWQQ1C3IPiMUMvB68llJM/xSl
HkymBHzpMtanBO8VH8tGaG3vWJQcQNWIyQj9c8eJWIcM/ulBNxuCBUt0DoBA
+bBzW4+QgvXN36UhLGEQLBBjnfs4JXw0VjQePkHwUIpLyIL47mHb9clBGCAB
aRRxxrLQIhJ7DgY6TwgqYowsvqsLHiZHBOvgYAwvITpGJguGAVAZINpFgKG+
AI0T/duICWA2B62qCuZiAnYBi8QnSezclKK2XpJ+BDY0IkG4fy6LAE7/XmuU
js6iKWUVWLYR/E0EN/rrjpNwvoVooolECmISBbCbD6MuOu7s/9vKSgp/pMsi
pAtEA8BAag4LKpJpwJLDjcGAhei+0KY1LxTxv1cki1KZIbCYCDseDptOiLre
k4dugUZvKLa/6tszDvhka/bkQ2LhQbPXJk36KP7bbihGycHHP+ADDSmdhxqY
GORD0xjgNOaBV7RKtgiyvQC6r293DwFQYetD0XzpxK6u9WfB9pTQ0JGMuJa8
3kayfPO2cXYFqNID+Ll4ECApQOMVSFxk5F+F2BfECSL+OahpGJoQbwsB6wT6
EAJ9cORyiVpPutb+A0jmdwPugYUvcJ34lowAgi4ARGq3GL5Z4rwmwDnlVyFD
KpaYbAqibQCa2lwNET6mhN8gYCOQ0QBqHgm6xO+yUIJVH0FcAYPLKKRluFjG
AEvbyIUQFW+LTvx9dajIZPgAtj5QDB4RizXfFucMWkgCQSMF6BuvY1v4FC4Y
PjzXeGCbNE5vIqzFNRFB7s4greX7lmkeZvMmPRQwAbSCzQuJuJ4iiGBjePRE
KKoZ1HXfqBEJHQK2SX5SgbFCTN4ekTgCcSJwpQivENjihP5Pzh4DLI6F7lqC
Gk0AdNbq1UmlysHyDH40Umvh9523Rnda5dbaTIYOswXqfcwIIigWSD8IHEbA
Lv772YMuHCzA/SVAgyfC5zEGlMFjDBsjAKdZJMRu72vLEO8kVCBtBEeA4AuS
HddWZZDXijB6IyFa+Ozfo1cfuFCbRxcj56qdjAjAyUO/M0IlqYOozSL/J1hD
av0dWkMiVD5xqwLiukEAwVVgXxXCRFUMf5RRrSeUhIkGD+xIhgCMAOawDZIA
AjfHowCDKnJUfj06FtAB5/3TucRQf+HS5LFf2owLpQXqMXOJxZ+/zsPjUpI6
xz0J9igsviPiLoRrXcK9L7Xl69ejY6HYJEcTBmFEtY4pd8x0/SbpJWEO0mwr
ERLZb9yGWDNgZEM2CMpXAVCwhyJBEjuPuUDq7qkIjht/Vx0aMWLwgcqcR5YI
D6iBTPew5gXAtjS2cCT/HFYBkjyJuweKXgZGAyyeHrm24OTlQ6SqQAbc+lj9
/d6xW0MEm7QJVDLMQciYAJ4LxOERjjCe0inTpH/JY2krMehnvLCLryFBf7Bl
jOCxGAL38JHqxn1tWLJOUPPEGI0xXKerIfZMyFr00VNHbQpi9K/OpCGGSiHd
2WNJbeBP0KHuMlp4Hho8KexUkd+gkwhuTAueeDgcPEwQOFwNZP/CTksGoNr6
ZH1/cT5ufxY3iwIJk4REUBL9CiSBoLs43n34MJJl//XXA0RXkWEQgBcf2sIY
N3UA7CiCEyIH44PmtPeg5/97w0KrT7yWRPiqwGVMFLvxkAyxGQ/YSoIMm4if
vydiSBcMYcio4Fr34QUjxR3UT6xqkObarKgARnjStxLSh4AWVCSZ6zCrCHrC
theQMQhrs6Q8KNi/4f3WCzXGvIOF6J1FNh2DcouHRyED5ZWH4zqMf/q4tudV
UFWSiQyOKRbubCE2Mgeoh4XtCLEVADjwvepijGMUPKsIQwEZGl0eVikkWwnI
cLOViK+N/4NZEZiCh7xf6RKWBKGzRxFRAEttBC5uW0b5V1vVNri49U/k8Q5F
uNMSqT/8UCLYGMlg2cgIFPoeLkQ4iwJ8oaTsZ8kqbVN8WUyQY6bLJiUVlIKG
6NeGSQagTZw9EYIaQrFPjIOheI8Re0gMgkWydEX2xySCQbQRKcyAGTb3C2kQ
PExzBFLlen5n80dwJAgCv588DWdPH4O8ZmXy0JmT+SMwKzKrgucUjYFFs6gI
yeg78YwjXweJ2JL+8UQQOysuDpejhCA4Gds2wojtG/KK4XXiw1RUgTEu+YLg
KSxAfEjDLyBGtGnTqErwMfn75lvniJYrEnRAGYM5CI0pG6109pHkG8RdH3wP
UmHdRVS4mDuQeTSaVgbQnI/rT8QmItpXD7/tO7bLQxmDWUyEY4qHpSzxJMWl
1uw1Gg47Hu5Bkq/7G9MngWeioD+NAWsT+AuQKYeV1pzMHCZEDBLkvuX6BIxl
AKyBGkHDHCfGNJMHhOKhmuLwvdPwNvq+YT3sUxFUBwEgOZk4R10AryJ1bQVB
p2Pynx73Y/bHA0RS4InWZvwSSyx4FvB+t8LJGAuedMRSh//hnJAmFPdyDBdp
GUNzurXrUkiLJLTTZ2RzyVix3+2/6HengYQ43ABfbtwanwF0JVa/fhc/rmBQ
8t2ANz8c4LTxoaX38Q0qMNkhstj2fsSna9s6D/fvD8AOMTMPH4FY6RI+m2uC
ByeBQ4UsYEnTOEN+DLAgyA9gPBTCu7w1XAixX5o/pCGCVWDow2FVfwNuEY4j
uU0yDIBygAIhoCyhYbJAXFEUsuVjgBvhd/tP42KiuxVCinmwoQQAX8Q6jcWY
rP1PmuzW79DvALcYcZfzkeTWuqNK4MagOmJQGUoYlCg4/79hXjKebrOXMb/2
4dslAd2lcTqxuGJYvIrcHh2/h1ULO9Bch/eSNOPWkBS9NnmYgNllmBVGv3np
ZDAKoIDQJADDctAqkzmgiGUWkm9fFDtCiBf+9DISdMshbl4FTA8BBmEkUwEO
jLTQ6dhDjER5ONT87SYwYeQwdOZgcEni4FqMSO5gT3LwIiJSxLBP/v7rAgqz
1madQVmCIbsPpCjALRMhnJPYWwBv/56ExsAAyVUFPDMCOiG19zIJVCCHbYtR
c4jya7G17zaQgBXo0XhwKpo36WM0KQA6JrYRoBbEGNOTpumbtsF2nmIRCmAR
JmgSkvHaEYnXemsyXeZ284mk3+hpGldYhIIqhOGFBIN7Dm2U53cXaGtuEsU/
bn0e2mQZ77CNEVZg08ZilsqCGyC26cGwR2ke5rdFhQcj3QgYHcGIQJUhnhTg
HoRY+SHCOSWQ1poH+G27RuMoI7w4nIqtHXZzYvi4y0S4okfw0PGRK0sHv9GU
XsdS4GCIE+NEJRdlDNOx1hgULWQIkiQHAs/fug4K/ADc5Bjh5E37JsG5NWy9
77FKGbgC+fiF7Nc5HwAnEeDZp7QDehw+CsxbJdDSyLSxdWAEhe/7go5RLkrw
xYtwwQXYdzy8A0j7jHuBxTuU2H8lC/GACIhDIshmAtp8Ei8fw+hEgT8LKAEt
MTlmf5yIQ/x5s0Ml+Ko33zjB2JE17aFa9lHYK0z3DkngwfcFDVtwGWBUDC/+
ttYiTCdYsrKo9Hy0QgwqlvCbGNmaHQMB4BCazbZMVKSzKoAyFFyRClCRkP8p
ShnsUwHcAxq9Umv4y8AmnoFXjoiKlEU9T+Zc3s810TwcH6McGtMuGT5KMqBd
UimFqI1b3/8Y9ivf9hyoGTxYQkTIIw1bjgq4EwI4GAHM7iNA0MGv+VeMMzyA
J0XzwCM41LPwJwqBG9DtusL9IoMIIf2OsBkgJDTMN3mgeeTnJdhYx6h4Ycui
gKEX/XJOmk8dgGOjwKC5ebcCbJXo1tkE1wcNE3kfSAKBDb/n7wx55qQCBDHf
w7VO9jgwUgY9SPNZIjjFhK3D+zfvgunsS5S4C9D2kZ0roCBvyQA+TtcYpz2J
kv5OqlcwOeU65mo312DwYyDdtXGgpDYTYeYb/sxhRaE7LhTM3CPYcLfUOAZU
E1LI4WkwQMul8KeeJ1ZEiGxV2uANppsIN2dXjF4sQLQUh7JBwmf8Pi54iTxt
chmhwOBaA1NQ5hiADxLyFTjU82JrLxv8rDoJnO3WxVKGNQ+ZIAOyI3bVgBM5
GAWKsOz5nv4LONLbtJJmSxLfHICxxGIMDBDZ64IWRDTF5NH90vOkoIsW91q8
F2kuPrCUFjLlkfTLAnSl+R/QqTmmWADyMuJbPdgNSwBP2mZEwHHRsXFEWEl+
4/OgQXJyV3gwaCICZCmT3wnfcx9eS61tmSL+1POkzENlIoIjHcJ+S8Y8S8Jg
mohLUN0RkIRFnfz11wVY8bYFZ9vuNW+YoH8w0mr+uggrHAbMyZa98J2XzrOd
h3IML0sfJ5WCA4dDKyHgyfgY9ilIpfoJKgDXV466lOmWCu635AGYd/MA2drc
eB+1wff4XsIsQIZJpQBRCwO7dhmDreajKVgDYkuABwL/bYTESt2reBAFiAhv
J81R3Nm8MsDuOBiHRYDO/oXhFmPqrWBa2vLhY66jzpJnqKBUa/MG/gEE/i4b
XGot1iSg92HRwpMxARzWCPUd4gUOvYnA/Hh/BxCe0DioeTiKKuDqE6qMALo7
YudFYMVyW3sIP4/OQ6iJFHQ2f0xrAY/jglRiEYLKpe7r8LGL/37vEAxJMK8U
wGRuFh5p/HFNKKhvedytHN/ppb6L0tbAmpAJgRiQNAilW94hcs64trgCcEfI
7b9AKwOmCgeQxAPBr/VsIjNNzJWCVo7BkI8stXvhewaNRDG/pTViUwu4xVom
Aw334QDnTLM3AwhDvp0KaZS+ISqWZtsSfQTbjf6JDhA8H6k9A0Ga9bwf8y8J
1RehNrHYZajuJMBQIqiGCt3ZS4UgFMn+j4kzjaFnBMdeGTNcAZQnup2/t3g+
3IQD9IMM/UNVYoFF8OASE8gXjCwGRmmELBR3IVJNZcUDRg6Zn4M6BBFIAVma
xnkewZK+uac8PCsC6IGr3NTnPDqsfykPQozsGfAfaOQTMPAfJ0wntIERQAMZ
Btxy/DPSamcNIZoOkvuFnA/CYAe4GmFkIKBzDHGIib/XBAsJkgJ9hCB3kxfy
5sHM9KEWodt8FNBEA/lHO6AgjyFE6RuBfMgApVdQIRCfR7Gz9JJBmm0WBvsN
dTLdD5AoJvgDEtC4Ncvz4VgN1ndHmMTd8Y0akXQuAFnkewc0ysHrrS2zWYRA
hkpHRFfwKt8HdRvv5AOCCFEZEkoPbPtIxA54bgFIUzT+5V/S2iWAPCEwfA7T
RhLBgg5FgHiExxCQlCuQbikgn3xPQsNWpEh3AUstFZnD+RCjWOo6NRGJCDxZ
9n+XDYgWHKgdCh5shKgtGiPFEIQZKerSiQQYiXq/ZWGbo8O12BGMs7vpFd6G
3Bqx4UiMMTL+Blp9UHlFnJbNkUtkvAC7BIwISaYCQAwWxFryO0GS/B4qKTBe
bI5KGrQKFltGBHxEBx0pjgPfScQYPf51ZfXA6vcxmOPhjRu3xRLeLYfSzgce
EqFc+TY69EGJZJGzyOFyFODuSmgb6MqJedw/SW8y1/XXf3ccnrCHYVCI2DYJ
BYYExYQMhIrgADCaJDDm7x3H010CgQ9iWIgBAQmG9DqtR5s8xIPN3pwJivLj
ztkmFXW8Takj85AzxOs4TqS8BGBO6nkMKH8qaq4bHNNgaEugK9CoY33cVu33
2LSEXmurx/987wGgObrlBOKaiLEAWPAWZOgRmDZVBX64CrQ8f9c8hrAy8KIu
eAlYrgCOohR1UR9E2QHCSQsgf6PEbdkW4qAmdFYewSpSB4ZEbJctQZilmOF+
x2NImJQJAG9D+OLRQNFjGc9KAoqLdSWCHs/iU3zXNhJ6WAmjtwDnTAuAyGwX
phLjFiZTVND/fgwugXgw8IQlGLiMi8BHa4miiINleYzMDwmHj/D95FERkQsF
YlIB5uM+AAcRNY8PkU4Iv/4IFEfhm3sAnCdAcFFrTRij6pZgWSjhFGp2JY/8
DB/CQPrbDxdUVR4JCgS7ayMSJXJWNKc3h+QeQjrCG1AA+H9rQokFKubyLGQd
CmBYGeoPDgEJEZacj2AeHkCx9z1MBNjlwR6U4LQK+VWE4QBUkI272VyEDo72
OhXh3x2noPSFJE3GOElA80VWApBqBoQ3Gnb8ntgBEX//OkC8AEmEitIdpEq7
s7iOsR/jDpUwpPP5nwynbjaKKLUI+pQYARgROpQI/TsJwsG9H4HkwIU/53zr
5kn4k1Lnli6iHibRgGDEcf84b/IoA/ivo7LlfBKyEBBsDp7CzbqNYKfOtvx2
uDAHyHZimZ8bNkR0Bw2fdL91VoWkyG8nLG1lCGtLAT6YJGT3W5HaemrHSGdE
zyUiho3huzytNjwshnyAsOUx1v/76pDQykgiaV+RVOwsSlkWxarcsTIEwIyM
92OvGQBRbAVxJFURuk4P90sE0mBbMsWtrTkHN/nvGxZ2rhzGCs1FEwHqD+FE
rADCIlAYip8ALE0y5PqNAvLhodw9OiBmMdYhqYgwC2vuHWLZ2brEij+Ulbaa
JQ7CCnBdDq+FcqX5Q8KKD2CKCmWuBK7+95uncZu3QGgrEokws5NwuElot8lg
hcU5j+PC+/b+DjoppS91dBQGWC4D1pzSAj7AigP8GBEbft2wHmpFBpzeENNw
wirEBmlNfn10AQTGB5WX+111EY5KggmLnZNy66wqYPcRojJ8JiSwyDxAzd/M
BxZzagLgt4pO5DGQ1hIxh8Q4Hvcsh+lt24V933Eh7nEORzGHkFGpHSpJnRyA
FjrTCEno9CDfRyUHjquAuDUWFuoMRAc+iOgE8uVRn0QQykHg/M05ERHhQEPE
xOJY5tB6R3jOAkBjBSce12Z7SD8E+DZ+T8BqYQA7kPEQ12XUiYhjidsmApG6
RFP/Tc8DjZPUfqAfiMAnJcTbKAj16SpkTHZ4zAK+u0gBJF4eAyMJZUbzqwiE
GHXnarOhhDaRRegSg77P+Rh/3t6hAkp6GoWfBMZRgAs9wqRYauFf/ycdk0W0
IVFT8p1NPA2hEw2be4HtEM4AU0gRkX7h91gHX3Gr5SSlPkMOqDYDNUBN1c7v
FJD3YijmmO+a9h8OEo1TsVUJsUh85FotAPAKpTUsRkLkD+QFWLg1jueB6DII
xaGhR6Nx7QpwpZfwJOVfI+OWxklstXG0tjleZDFgbB0Bn2+x3HaoR7S938MF
pvuLRAmFvBkfCF57KTcXBBk0yF1z3UoPvjPbFICKAVZIjAGQj00RAJxv+XJ+
i/tB1i3xP/w6ojgWSQEWoPtWgGyE3j/1zD9T7Oaop1EqB+EvHRcRWVFrzo48
mLAlroudsMgDxa61H/KhTZB/szkZSE4YWFTTqHzacRhhckL9rcT/x+7JW/Gj
qgNn9T/uyY46q9LksCnyQPVSZrS+PPUpveSSRfIv7smLmlp+/k/dk5NaS/7x
MVZ+3ZPtnZmY9LjWj8FycTLr5pfWi1HyXo0G9J782Yf82YD/nz87DbiFWdaq
6Y6o5jdOxrUx2Z7Gq8Wgbt9JXWvbifb2nMVrMhrs23dzWYxo43ngdp+pdlxu
meVypw5HlGkP7W8r4WHtngb0trUR3j6KdKM9+0NOonvhK5DS1Fop9uNAx6/L
VX6eezNqFl+HfZ/zpnqfXUkj7TGLVTm7v42jfV8+B/mcD+leLe3iY5TQW5b9
MJOT+2me1pCG1zE1Ssz9cLiR413OZ3t9N2Av0Toen28vrhouON/5DGLyEXRr
MSYfJ/mXn6X+5YfX+OENnJPHQ3swIq7JiwGPVxu1zspj8nUPT4PZMEnu1DAZ
a0MzmEzrlTpmWwvlnWy5adw/qBfh4b+83WlVM2aqq+/Mr3pT/VWe5bvvrOkl
48iUMuZ3IvswuZPdY66HOptyQ4G+vC17IJqzTUE/n15vmR6jc5Lqq5X7XA4v
R6swhDgMdlUaUMlcuEgb/b4y+893nb9nIzWf1XuZO47TZ2kHqnFRqvGZ05lN
5LxZ272ru9eOPp2fy52pJwdqoHnR5TleWaLAMNepUTpF+d4ci4mZTxJuE6qJ
d2ef6nNwDZcMt5ik4mz8qvMn55a7VWTWVCGfB4aXfOxQuhi+y6jMpB+drEKc
2pfeKfNvp/CRuXlpnK+r952/quNSns0izbsxHn1d36nxY+IdX6/BSpZ3/ni5
SlVtuy34pb8JrqfN7inRhnezHDPjm+/emp2L99bZevT8Ejzsar3PqVKd+v5u
eJ6dU2W48aaD1VLaVYNRyV0qL3l+uNts4V8mg/m0f2X1U7UXCmOsTFiRO41M
9XGkoos5exxnunOkeUOdrevZMtOHn9XclbL5q9c7M5+evmAvhSP0Pq9TWix2
W25iHEN1uTtM3COVnd/F/HLbXk9b8xodI/86KW+LZ7W1qnxjrpljj1mexkK1
m6rHBX8bF9bidV642tiLwuduPKMCOpLV8XlTCqf+YLO5MrKajDTn7Dzm4nFW
FyW/LXNHs4rRmi/cjzWWXo+Jft5d6/lDi8qCYmfyeTWYBe/T6MOfhsM5O0vn
s/1wwmlVebCU14mNnEzTuOxJMz2XEZSjzBxOZZxIfBFMCiqSllnpafN59DmM
z7u7XpeB9ylnh8IVlMXb5/3AUZi1XIuuq7wFbXsfu7njbDy/4t7D25hyao9J
5VIt59P18xW4B5stgqx6FYLRW1W98WeyC15aVfeDmi+OxqMXy/Hg+Zkp+3TS
X1xflGwz0uJub2txmmgn2Rpyk91KsV76873QP9biPXssHtzerjd362iLnpBY
k3TJF5vy/lH6qxW1G55utxu/Hdy1mfcYnEN6cDnZQVFMw1tiFtZgSyexIo5v
U3VxylfqM/fj42cYPPTxTDxoFyrYi07WHxT28/bwLvsyWdC8NS6GM4Hzdwun
fvYvE9Fwxdpw6nTOrhI9UbgZE6qZH754Nab6k41r7+lCqQLvNJ8GanRVbM46
jLaXxWM+ejZb6Okrnyzp6af6cXQ1qdmmKVdyjM3qbJRSpbw99KRCn3w+t6f1
OZqss9kf4+AscNrRfO2Ww6WhHebp9mhvEu+aDo438e0P7aMrSPSWp6nw9hIY
aTk935VdnDLBx5759XZSXGSWy7T3Xj/xhR09a3f7OPOft+S5W048vF1lchRd
J1pQT/9cM09d8Zykn10zybNzs+TebLrilpPwqh5W27c9m9aKbF8MYVlL8TV6
XwSR3qyemq8dqPfhsXHNcsIE9SOZV8ZZYXtbPu3d+eE51sRexD8L55M/b2yo
erV3k5TD9S6eB7o42I0HZo9ihdV7qTzvx102ulzY9fDymV+O7GVt9Omr/pl+
4n59089rQUmbh1U76/71MRyE6yfvjv31a0Idpa159ExdnPWukkZfnOb7XgQf
veTHjkpXim4I9OAoPbmE9utgMLa3vsINHufXaZ0fzWtCrbb0vLfNxoveYJdv
8v6Lv0+yxLKXbBWKc+HDTFU+MXveeWuvg2Ruv+NTEoczf9bv382c56m4+iyv
wkibq49k+omEw1DNDfaov2L9cmpKACtKGGshTdXxu5JvTCju5/e3/ToeN6fJ
Ul8rlHGz6+105R8067bbf9xLOhn2hbpYbfqjSyJlW0l3esf+c+Y+1bNxus0r
RnvKy/IiLPXcXLiUEaWZlAqcyPVpa5sd8oUu315iNZ1zvLGmjxPl6g0ZZ7od
bF9bY/XuTSQ/oJl4Obt/ltOVScljrXqPl3va2erKxk1KIX+/Pmb2Ggj0Phuv
o0/V927ZUJN2upsy68d+4rir/PG+0S//XM6ojfCyD7flqhYO8sBTV/fLUjMf
njW+iI7fS5OKY/NQtW7T+UgsrqdLPLe9xSrfqobHPXbLNRXu5IXtzk8fVpR7
6XLdOy2c2EhZ/RwZ6yo/3s7Tg+GJ0ZpZju/GZM9qzsgccuLddXn3ThfU/O3S
zTLzBtuN+tasbPU4N9/QcejbScSf6Onqulnr+cgsg9kqG9lN7STVZ8t55COL
Ph12K+rTo0PXLYz9ZniR7/XDmXOD0YsN5txnYLy321wRT+HEvGjqOy2vA/E6
uZqiK82i1Z4NNT+hznmmVKqUCKxnaddZUivVmlaGjr29XKR7vBiuZIeN6+Hj
Jb739VTRmZsWiJNhdg8+jlNklCefr8HHHHrR1ZEHk579XAZyfSuWdVpNjI9u
a4Xp+OVQ3i3Zt8wdjpooT48aOwiL0/0VjKhBJPP2jBvGXjFxrYdYTCe7460n
BcIoYK3+Zi3sbo+tu+7xm3Oss5ODdzGDnXtw2KEVvwqRYnb35LyyBDfbvWa5
LizfSjTktNGn9mdetbPeo/Xx7k9718l4OJi/do55/whnmRmW1mVNv+dULmdD
q28Pdz1ersebyza7VA8vfpvhfXxyON+c+/KGXXqep+unRd2/M5PtUti5SVFY
2vnWp8ZJdbh6200QuYH7ed5kVTZ5I2re6Mam9Tm91gMpWonMLX8yD+ZzXW6V
68ENrsbqpUfc0aOusp7JzlKxnaIpJgTmqDzWyydjrgs70BR7tKZ7qqGN/fHR
zd3wYWubs7CLt9p8ImqcP19Qtjww1OIwYVf2e3yYHfmRdzGCUJvs364o3MU6
eg8mC2nTW5in/Jnzer0rTmdnLjz4ea+qCkpnp6XlpNLukEQL2jjJ1fMR9MMk
mTBx/kgXqZ355cVOayHjZEY+SPPk/smHh/nEnfQCbUQ9Yna7PPCXotlIfZOb
TO5lcpaGJ++yeKrVUy158cXF+/vEzOyoqt7rF58Ne6UXW7qXqvOckue3j7bv
7WRubr1ZZvqYX6XbedhPYlHUAoMr3IP71FljXpRic9TFsn01Le2S2c2nlkKJ
peZnLgub+zt8midH0OsRlx2i5+JtDPVxOhocjdPzFZlN3XxjVT+6uvbtulIL
RXJm+ztXeFfqFsQHvvfcH6cD9aZcF3s6N2eBM9+/6okbpd5HtG+FPd576Vhk
rWn2GOWhvVpNwqaAZOe2T6XrrFkBi/Co9K4LeymWzKAnl2x1MVjXYT+pvEyK
RzDlYp6le1PTdt5GlfMTRV/tmPt9v6Po4Gm+Hktemr5evvsKTT1T9iMmcLl4
Mb81p6gzrufM+SZNZy/BL/bPfnkUrrEcNG/q1TtZVOKsXor/Yt93q1d8cmYe
T3sve366nz5KOBuz++y1VCrJYvaHYzhNHhabyTOrn8wq3z0L2ZB66lW/39xF
xxW9rwdHvseEx+KyFOko5+6Hm6YvVuKlZ7pVMmKXVpwaL9rkxmY4Nvcpq8gz
an9IA1m+iOXbrejAlPuq/lmPsqbfsJSzYz8Hl7VnpcbANZRbwT/WcmRGebh1
dvtp4A40hXrRuj858NeBf0scWv+4ERuOjM9zcXnU6SV/CQPfmNOMOksm45n3
eZmeenz71oh1A2/7UvoUM91a86L4zKfJJGCb6vP+0dNeYGT3i1rtvLsvj9Zh
vklHR5ERJplqR8w+q87hyQwHUblXKFpQRsOeFVape1+wV4F176WUaR/5MKlF
Y6iyL223e5XD8bre9LmIVk2t6Zs+6+Dox+pmalDPbfFcSIV2sndJyKtr6Zq4
z3spulHme0leq0eeT1bZa1NEx4lzHw21KAt7B2/gxNb5OmKpfKfq6486W35o
Ts/L8KqPZe+11Qexq5iCd1I+o7Wq1u+LfC38rPC2lrh/GuHQ4l5xJq7X1CZV
o4PhTpW6HlmSNVLDqnwI5sl+KlLv3Rsfktu+F2luv6bl42QWeKwax6divegv
RnM5NqmU7X/yfL5YyFZzI7z5xOB6RTmvaYPXm8pR0MXwbO/Xgifzvc3g0h/u
UnNk1knc3PvbapRRFavbXjadLoXxbr1QhtKqN91V9XZ2NHbvejuc8sWgX94j
czk3s9siHtJXN3ve3hKX7mV9kVHvpoJZKYn66cWzUj17hiPvspRTtvfyWvff
/dL5uCPOPQ6t5JGGuToqn8vBqz8KfHMd7ubNOzBWi/uK2y20m7DgbWW9vAfC
ZVPVudc7i0wRK09TNXbnfVrbcW/aHBwfs2k9Hmd5Kp1GjxflNMWduFjtpV2R
ullzA7sswwf6e6k9+vvy85IeteJPJge5PJ2Hu/6NcZrlrsj+tFmei8WgoHqz
zSOg90P+ft5tyygR5JMS8RJHJ5+xaBlXuximL/6WXnNNVpkrfTL7A2HvBxO9
olfc7E5NstXHihTzVngD4aXZ51l5pi1JPpz1dSm/H/d1cdePBffUzIFW3WpG
rejXx5HUtVJo06VHNZ07V00WF/7u8cygtr3LW1osdMkfNyeDbNfP1Ilnn/Om
uQZGQv88tvR4TWu84h+zfimbT+q1em0cgWuK8jSeOvnyMgx6GreiFc94BSvv
8FozCzlfnqfv+SgoNMukZ9l5tTyEzKh/Mc8P6tU/9LT+LGUKvgzj2b04Hfgb
E/VeB+0VqG9xIEwGWd+Kml0qJmsznd13jLaLD6Uxi0rb8SnjeuBmxtvIw4e/
C82rtlO2acK4N2NrZ5uw9KTB7dK/eJIq0qPkdDv1Jot9oCjuYPR5SvG5afvS
fPDorxjhvfQZ33nbzlUImuPIOs2Ek/98qQeL2dJjSRt+jsqr1l93fygpCzF6
Obnek6n3aBLFD1esFhvu/Mn2OzbQjlN6NKjy/nDy7AXurVddbo/NfBSyL+Vm
PHYmE8ujJEz84tPLqeewsqptbpdqrOzDjeJF2WlpPnzupm+DQT01txXLlNz0
4L6lPJfOcjStxwJ7agq5/YhjFeq+fN+KYTC8psG2d74PjY+sR4L83DD+QjZc
XtwdZZ19fcajeuOpF9nh7N5SFOdi9JwMT8Mn5Z5ega9y+v69qT76ts8odh7k
1uxuLot7wM3nzlu1vOIpzvOenL9d88znm2TjXq2nkRqPM3V25FTdGNas0lbL
dO5upZo/Ny3VJHCKt7sYVHOvvhvu+10Npl5kWzP3QIfjvGfdZ3057avU9knv
1lNaH59u7ovOimTDvpzoRJtFnii0xWeH/nFJa/7bnxhnvcqzx2PFDZ9OIM3v
9dYYUqJKXx6FfYv1SA+zkh2PWF3VZlshV3f15mkYsqbeTkYqBdfncMxvVida
4ZeJWK97Qn61XlTUVLPa6HZYavmKbS6OmxMx811xnB1cf8yr87Fh9upM92vL
nAzO0T4XhdCwrafFOp/0UWVUPNtF8Wy+17fjZFxXkZhHb1FSys26Yhe7Y0Sf
lpUv1KLpDOjxvnc4jWchk5bbyFdLZsmLVLk8WRmfehqb9CIvra0qKtaTtTYL
tCwsNr26Enkr4HNHMdK5qQSfycuuZxtmuJtvtqf0QQXHUB7k4T08nYrgduED
TXxerqdB7dwSP3qbW5fb5W4pDPf3+2gacHu6HJytl5Lm3HD6Go4pI7vqCtdb
H48f9Sr0Imt9UD/hWG46+x2XDGRp+The5GFfeQWSVX0sJbSaovO89jcLPkjc
IyUK1rSpCo7c03cu0/TG05HkRUm9d+fWKud047q3rlqii8ojo/1qM1BPT18+
rZrD/nCK1A+lLR8mF5/zu6ROrRmfBpb3ZKLh0hnrudo3glyqrkmSefvJShhN
L+lSvDU/c8tYL5QKxaEpjWcVu+Kn3s1MPjdPe/Uv2ktJRmH9Cc3RdGO+b4um
RZv3bvpGPmyao3DPX5b0MNjzddOi5VR4GeW1ac3lxYLXjPQh9mktX0728d3q
bwPxVk0Or4WhiBvfr+i9uC4n70zZ9h/P1TVz0s2ICujKPJXHy+i9nEoh1z8a
kb8wWWm+rK5eXdPBR3x44Zx53tLDs6gGybPZjfFWuUgTmm8KGKqqy+vdHii7
KysbqyK/7rlF8jpKzCE9OQrzCtKmNnCV4bYUJ/muKXEGdVQeYm913MyutTGl
2LFwGl8Lb7YqotEmMldPx8sTTdY2s/5gfFRc/m2oUsZl5rgoT8uPJT4u8tt+
1OFicRH4nOqn5mnFz+hJJrw5Q9ysiod2GND1PK92W05MbSkwBT06Dra3N8PJ
QTbziuZmSl+9LddUiiUV3DX7oxyKUVPMPusgyY0skd7Cu9ZnUdRs+sszkpOq
shX2dJK2Mn+YLnzO2/HcspzebJOhlOckCC+76LPLT+9pZu4lNjkMPJpRmk3g
7JyxMFoNt49ESY1a5dLkOPb0ahYs08Vh+Dqs51T4iTf3Tzh9bGM/d27u8jKf
G+zN4y6D8yot7jeJrc0Bm29X+3NwWxze/aV1SuVwvFIU9bgrKcs82jvX0hx9
aX9OvCuYlnVt6inbeeq3Q7G6XYfNFroelYPxYe9m3tTPQrhaqT17nqir5l6Y
C0rFh5em6t1NqmO0e0xKO45Xx4XLchtxqN3Soc08B3JzEBdN+7B4lfF89NY8
jnYnL39aUVf7wQ1ier3bVNF+MKyz2bJvTYXZQTS3TqSK1TP3BUU4spNodJ8H
Q5Gda9P7cbq6Hna913VGvSaLWuYS7XorF8JnlaTrOOXpi9/fu7I2lx7T5fid
hQ+nrxTqU79Phfnl3LzyQ3se7bu0cahdus0V+zAV6zrp2dWnr7DKdDpeKLu9
EW9df+i7GSd4BzHJBFefu0th1twu+5MzYbZVf/GmtM/Wmx/8zHl+lrvR0Liz
smdWubstjE+oz7jguh/otuYJ0xVXVeZ2MKgOn+It6870fOPsPTU36qQ0r7wv
ZuxpX3OD017xheJBb7esbG+S6Gg4BptoxnHDrA15ub6H4UO9lroX1WZg09Ta
E1fbnckdPHr2ttJkXdvVTivGxYtWAiOMe9uN3X/t48FrKZn750DheyfjXY5W
drR+HrSMsh3rWtC721V1Anud9fbxa3Xm3saJm6yu1yx38kt2Xah5L3U4T3vP
Bs+dZAWswTshn20eV2rqHB+Kfk+Hq+1qupv1hwt64e04R27a0UJJhvx6YX6G
zfM6ZHxfqeOTeH6NzF6sqO/jett7U9uDcZFXH9eRN7vL9jMdP85anOxtp5+x
zaN0Z9Ym0TT2E8XZPF6ZaeDe1cPZsczNJtxv6xlVWY/7MziYvWbBNnXFNivm
60082j5rTtOE/uuxMYKbbhlF5uofvufm1d1hub5Ojy4zbcF41CH53AeFlzCa
nzdlw1FeBKeS7k3Ow6unXXh9ZNkbKVm5Rf0f//H/HyYzCM7Fpc6iMMmjoiqp
//p/C+S1ROF//FvsZWX0b/9NsmS84lz+iS/3P5tHWf7RL48yi95/vCL8s/aK
S/ln5uVXr/DOaftTxyi7xo/sT/lIkqgkETTlv3eRNOEleJCX+vMoIxJJk12q
P5f4TxW9qj/x/ZL/KdM8zbz7//xg+ed/W2uZplla/s//h/q//vdGUzlWUv4T
r07+S+YZ+j//7z9e+aeOsoz8/3/91/+6x4Es0bKflv/93//+p/sAyeVP1fzv
GP3xkFxRNq9MNf9SRn9f7d///Jt6ub5JDI6X1d67/JN75+adVsfmj8o/kVem
0R2vnUXNo4ju9+bzXu+XIvq3P/+L6t4P85//Tv1/jn2i0sUVAQA=

-->

</rfc>
