<?xml version='1.0' encoding='utf-8'?>
<!DOCTYPE rfc [
  <!ENTITY nbsp    "&#160;">
  <!ENTITY zwsp   "&#8203;">
  <!ENTITY nbhy   "&#8209;">
  <!ENTITY wj     "&#8288;">
]>
<?xml-stylesheet type="text/xsl" href="rfc2629.xslt" ?>
<!-- generated by https://github.com/cabo/kramdown-rfc version 1.7.19 (Ruby 3.3.3) -->
<rfc xmlns:xi="http://www.w3.org/2001/XInclude" ipr="trust200902" docName="draft-ietf-lamps-x509-shbs-05" category="std" consensus="true" submissionType="IETF" tocInclude="true" sortRefs="true" symRefs="true" version="3">
  <!-- xml2rfc v2v3 conversion 3.23.1 -->
  <front>
    <title abbrev="HSS and XMSS for X.509">Internet X.509 Public Key Infrastructure: Algorithm Identifiers for HSS and XMSS</title>
    <seriesInfo name="Internet-Draft" value="draft-ietf-lamps-x509-shbs-05"/>
    <author initials="D." surname="Van Geest" fullname="Daniel Van Geest">
      <organization>CryptoNext Security</organization>
      <address>
        <email>daniel.vangeest@cryptonext-security.com</email>
      </address>
    </author>
    <author initials="K." surname="Bashiri" fullname="Kaveh Bashiri">
      <organization>BSI</organization>
      <address>
        <email>kaveh.bashiri.ietf@gmail.com</email>
      </address>
    </author>
    <author initials="S." surname="Fluhrer" fullname="Scott Fluhrer">
      <organization>Cisco Systems</organization>
      <address>
        <email>sfluhrer@cisco.com</email>
      </address>
    </author>
    <author initials="S." surname="Gazdag" fullname="Stefan Gazdag">
      <organization>genua GmbH</organization>
      <address>
        <email>ietf@gazdag.de</email>
      </address>
    </author>
    <author initials="S." surname="Kousidis" fullname="Stavros Kousidis">
      <organization>BSI</organization>
      <address>
        <email>kousidis.ietf@gmail.com</email>
      </address>
    </author>
    <date year="2024" month="September" day="25"/>
    <area>sec</area>
    <workgroup>LAMPS - Limited Additional Mechanisms for PKIX and SMIME</workgroup>
    <keyword>Internet-Draft</keyword>
    <abstract>
      <?line 141?>

<t>This document specifies algorithm identifiers and ASN.1 encoding formats for
the Stateful Hash-Based Signature Schemes (S-HBS) Hierarchical Signature System
(HSS), eXtended Merkle Signature Scheme (XMSS), and XMSS^MT, a multi-tree
variant of XMSS. This specification applies to the Internet X.509 Public Key
infrastructure (PKI) when those digital signatures are used in Internet X.509
certificates and certificate revocation lists.</t>
    </abstract>
    <note removeInRFC="true">
      <name>About This Document</name>
      <t>
        Status information for this document may be found at <eref target="https://datatracker.ietf.org/doc/draft-ietf-lamps-x509-shbs/"/>.
      </t>
      <t>
        Discussion of this document takes place on the
        LAMPS Working Group mailing list (<eref target="mailto:spasm@ietf.org"/>),
        which is archived at <eref target="https://mailarchive.ietf.org/arch/browse/spasm/"/>.
        Subscribe at <eref target="https://www.ietf.org/mailman/listinfo/spasm/"/>.
      </t>
      <t>Source for this draft and an issue tracker can be found at
        <eref target="https://github.com/x509-hbs/draft-x509-shbs"/>.</t>
    </note>
  </front>
  <middle>
    <?line 150?>

<section anchor="introduction">
      <name>Introduction</name>
      <t>Stateful Hash-Based Signature Schemes (S-HBS) such as HSS, XMSS and XMSS^MT
combine Merkle trees with One Time Signatures (OTS) in order to provide digital
signature schemes that remain secure even when quantum computers become
available. Their theoretic security is well understood and depends only on the
security of the underlying hash function. As such they can serve as an
important building block for quantum computer resistant information and
communication technology.</t>
      <t>The private key of S-HBS is a finite collection of OTS keys, hence only a
limited number of messages can be signed and the private key's state must be
updated and persisted after signing to prevent reuse of OTS keys.  While the
right selection of algorithm parameters would allow a private key to sign a
virtually unbounded number of messages (e.g. 2^60), this is at the cost of a
larger signature size and longer signing time. Due to the statefulness of the
private key and the limited number of signatures that can be created, S-HBS
might not be appropriate for use in interactive protocols. However, in some use
cases the deployment of S-HBS may be appropriate. Such use cases are described
and discussed later in <xref target="use-cases-shbs-x509"/>.</t>
    </section>
    <section anchor="conventions-and-definitions">
      <name>Conventions and Definitions</name>
      <t>The key words "<bcp14>MUST</bcp14>", "<bcp14>MUST NOT</bcp14>", "<bcp14>REQUIRED</bcp14>", "<bcp14>SHALL</bcp14>", "<bcp14>SHALL
NOT</bcp14>", "<bcp14>SHOULD</bcp14>", "<bcp14>SHOULD NOT</bcp14>", "<bcp14>RECOMMENDED</bcp14>", "<bcp14>NOT RECOMMENDED</bcp14>",
"<bcp14>MAY</bcp14>", and "<bcp14>OPTIONAL</bcp14>" in this document are to be interpreted as
described in BCP 14 <xref target="RFC2119"/> <xref target="RFC8174"/> when, and only when, they
appear in all capitals, as shown here.</t>
      <?line -18?>

</section>
    <section anchor="use-cases-shbs-x509">
      <name>Use Cases of S-HBS in X.509</name>
      <t>As described in the Security Considerations of <xref target="sec-security"/>, it is
imperative that S-HBS implementations do not reuse OTS signatures. This makes
S-HBS algorithms inappropriate for general use cases. The exact conditions
under which S-HBS certificates may be used is left to certificate policies <xref target="RFC3647"/>.
However the intended use of S-HBS as described by <xref target="SP800208"/> can be used as a
guideline:</t>
      <blockquote>
        <t>1) it is necessary to implement a digital signature scheme in the near
future; <br/>
2) the implementation will have a long lifetime; and <br/>
3) it would not be practical to transition to a different digital signature
scheme once the implementation has been deployed.</t>
      </blockquote>
      <t>In addition, since an S-HBS private key can only generate a finite number of
signatures, use cases for S-HBS public keys in certificates should have a
predictable range of the number of signatures that will be generated, falling
safely below the maximum number of signatures that a private key can generate.</t>
      <t>Use cases where S-HBS public keys in certificates may be appropriate due to
the relatively small number of signatures generated and the signer's ability
to enforce security restrictions on the signing environment include:</t>
      <ul spacing="normal">
        <li>
          <t>Firmware signing (Section 1.1 of <xref target="SP800208"/>, Table IV of <xref target="CNSA2.0"/>, Section
6.7 of <xref target="BSI"/>)</t>
        </li>
        <li>
          <t>Software signing (Table IV of <xref target="CNSA2.0"/>, <xref target="ANSSI"/>)</t>
        </li>
        <li>
          <t>Certification Authority (CA) certificates.</t>
        </li>
      </ul>
      <t>In each of these cases, the operator is able to control their signing
environment such that signatures are generated in hardware cryptographic
modules and audited before the signature is published, in order to prevent OTS
key reuse.</t>
      <t>Generally speaking, S-HBS public keys are not appropriate for use
in end-entity certificates, however in the firmware and software signing cases
signature generation will often be more tightly controlled. Some
manufactures use common and well-established key formats like X.509 for their
code signing and update mechanisms. Also there are multi-party IoT ecosystems
where publicly trusted code signing certificates are useful.</t>
      <t>In general, root CAs <xref target="RFC4949"/> generate signatures in a more secure environment and issue
fewer certificates than subordinate CAs <xref target="RFC4949"/>. This makes the use of S-HBS public
keys more appropriate in root CA certificates than in subordinate CA
certificates. However, if a subordinate CA can match the security and
signature count restrictions of a root CA, for example if the subordinate CA
only issues code-signing certificates, then using an S-HBS public key in the
subordinate CA certificate may be possible.</t>
    </section>
    <section anchor="algorithm-identifiers-and-parameters">
      <name>Algorithm Identifiers and Parameters</name>
      <t>In this document, we define new OIDs for identifying the different stateful
hash-based signature algorithms. An additional OID is defined in <xref target="I-D.draft-ietf-lamps-rfc8708bis"/> and
repeated here for convenience. For all of the OIDs, the parameters <bcp14>MUST</bcp14> be
absent.</t>
      <section anchor="hss-algorithm-identifier">
        <name>HSS Algorithm Identifier</name>
        <t>The object identifier and public key algorithm identifier for HSS is defined in
<xref target="I-D.draft-ietf-lamps-rfc8708bis"/>. The definitions are repeated here for reference.</t>
        <t>The object identifier for an HSS public key is <tt>id-alg-hss-lms-hashsig</tt>:</t>
        <artwork><![CDATA[
   id-alg-hss-lms-hashsig  OBJECT IDENTIFIER ::= {
      iso(1) member-body(2) us(840) rsadsi(113549) pkcs(1) pkcs9(9)
      smime(16) alg(3) 17 }
]]></artwork>
        <t>Note that the <tt>id-alg-hss-lms-hashsig</tt> algorithm identifier is also referred to
as <tt>id-alg-mts-hashsig</tt>. This synonym is based on the terminology used in an
early draft of the document that became <xref target="RFC8554"/>.</t>
        <t>The public key and signature values identify the hash function and the height used in the
HSS/LMS tree. <xref target="RFC8554"/> and <xref target="SP800208"/> define these values, but an IANA registry
<xref target="IANA-LMS"/> permits the registration of additional identifiers in the future.</t>
      </section>
      <section anchor="xmss-algorithm-identifier">
        <name>XMSS Algorithm Identifier</name>
        <t>The object identifier for an XMSS public key is <tt>id-alg-xmss-hashsig</tt>:</t>
        <artwork><![CDATA[
   id-alg-xmss-hashsig  OBJECT IDENTIFIER ::= {
      iso(1) identified-organization(3) dod(6) internet(1)
      security(5) mechanisms(5) pkix(7) algorithms(6) 34 }
]]></artwork>
        <t>The public key and signature values identify the hash function and the height used in the
XMSS tree. <xref target="RFC8391"/> and <xref target="SP800208"/> define these values, but an IANA registry
<xref target="IANA-XMSS"/> permits the registration of additional identifiers in the future.</t>
      </section>
      <section anchor="xmssmt-algorithm-identifier">
        <name>XMSS^MT Algorithm Identifier</name>
        <t>The object identifier for an XMSS^MT public key is <tt>id-alg-xmssmt-hashsig</tt>:</t>
        <artwork><![CDATA[
   id-alg-xmssmt-hashsig  OBJECT IDENTIFIER ::= {
      iso(1) identified-organization(3) dod(6) internet(1)
      security(5) mechanisms(5) pkix(7) algorithms(6) 35 }
]]></artwork>
        <t>The public key and signature values identify the hash function and the height used in the
XMSS^MT tree. <xref target="RFC8391"/> and <xref target="SP800208"/> define these values, but an IANA registry
<xref target="IANA-XMSS"/> permits the registration of additional identifiers in the future.</t>
      </section>
    </section>
    <section anchor="public-key-identifiers">
      <name>Public Key Identifiers</name>
      <t>Certificates conforming to <xref target="RFC5280"/> can convey a public key for any public key
algorithm. The certificate indicates the algorithm through an algorithm
identifier. An algorithm identifier consists of an OID and optional parameters.</t>
      <t><xref target="RFC8554"/> and <xref target="RFC8391"/> define the raw octet string encodings of the public
keys used in this document. When used in a SubjectPublicKeyInfo type, the
subjectPublicKey BIT STRING contains the raw octet string encodings of the
public keys.</t>
      <t>This document defines ASN.1 OCTET STRING types for encoding the public keys
when not used in a SubjectPublicKeyInfo. The OCTET STRING is mapped to a
subjectPublicKey (a value of type BIT STRING) as follows: the most significant
bit of the OCTET STRING value becomes the most significant bit of the BIT
STRING value, and so on; the least significant bit of the OCTET STRING
becomes the least significant bit of the BIT STRING.</t>
      <section anchor="hss-public-keys">
        <name>HSS Public Keys</name>
        <t>The HSS public key identifier is as follows:</t>
        <artwork><![CDATA[
   pk-HSS-LMS-HashSig PUBLIC-KEY ::= {
      IDENTIFIER id-alg-hss-lms-hashsig
      -- KEY no ASN.1 wrapping --
      PARAMS ARE absent
      CERT-KEY-USAGE
         { digitalSignature, nonRepudiation, keyCertSign, cRLSign } }
]]></artwork>
        <t>The HSS public key is defined as follows:</t>
        <artwork><![CDATA[
   HSS-LMS-HashSig-PublicKey ::= OCTET STRING
]]></artwork>
        <t><xref target="RFC8554"/> defines the raw octet string encoding of an HSS public key using the
<tt>hss_public_key</tt> structure. See <xref target="SP800208"/> and <xref target="RFC8554"/> for more information on
the contents and format of an HSS public key. Note that the single-tree signature
scheme LMS is instantiated as HSS with number of levels being equal to 1.</t>
      </section>
      <section anchor="xmss-public-keys">
        <name>XMSS Public Keys</name>
        <t>The XMSS public key identifier is as follows:</t>
        <artwork><![CDATA[
   pk-XMSS-HashSig PUBLIC-KEY ::= {
      IDENTIFIER id-alg-xmss-hashsig
      -- KEY no ASN.1 wrapping --
      PARAMS ARE absent
      CERT-KEY-USAGE
         { digitalSignature, nonRepudiation, keyCertSign, cRLSign } }
]]></artwork>
        <t>The XMSS public key is defined as follows:</t>
        <artwork><![CDATA[
   XMSS-HashSig-PublicKey ::= OCTET STRING
]]></artwork>
        <t><xref target="RFC8391"/> defines the raw octet string encoding of an HSS public key using the
<tt>xmss_public_key</tt> structure. See <xref target="SP800208"/> and <xref target="RFC8391"/> for more information
on the contents and format of an XMSS public key.</t>
      </section>
      <section anchor="xmssmt-public-keys">
        <name>XMSS^MT Public Keys</name>
        <t>The XMSS^MT public key identifier is as follows:</t>
        <artwork><![CDATA[
   pk-XMSSMT-HashSig PUBLIC-KEY ::= {
      IDENTIFIER id-alg-xmssmt-hashsig
      -- KEY no ASN.1 wrapping --
      PARAMS ARE absent
      CERT-KEY-USAGE
         { digitalSignature, nonRepudiation, keyCertSign, cRLSign } }
]]></artwork>
        <t>The XMSS^MT public key is defined as follows:</t>
        <artwork><![CDATA[
   XMSSMT-HashSig-PublicKey ::= OCTET STRING
]]></artwork>
        <t><xref target="RFC8391"/> defines the raw octet string encoding of an HSS public key using the
<tt>xmssmt_public_key</tt> structure. See <xref target="SP800208"/> and <xref target="RFC8391"/> for more information
on the contents and format of an XMSS^MT public key.</t>
      </section>
    </section>
    <section anchor="key-usage-bits">
      <name>Key Usage Bits</name>
      <t>The intended application for the key is indicated in the keyUsage certificate
extension <xref target="RFC5280"/>.
When id-alg-hss-lms-hashsig, id-alg-xmss-hashsig or id-alg-xmssmt-hashsig appears in the SubjectPublicKeyInfo
field of a CA X.509 certificate <xref target="RFC5280"/>, the
certificate key usage extension <bcp14>MUST</bcp14> contain at least one of the
following values: digitalSignature, nonRepudiation, keyCertSign, or
cRLSign. However, it <bcp14>MUST NOT</bcp14> contain other values.</t>
      <t>When id-alg-hss-lms-hashsig, id-alg-xmss-hashsig or id-alg-xmssmt-hashsig appears in the SubjectPublicKeyInfo
field of an end entity X.509 certificate <xref target="RFC5280"/>, the certificate key usage
extension <bcp14>MUST</bcp14> contain at least one of the following values: digitalSignature,
nonRepudiation or cRLSign. However, it <bcp14>MUST NOT</bcp14> contain other values.</t>
    </section>
    <section anchor="signature-algorithms">
      <name>Signature Algorithms</name>
      <t>This section identifies OIDs for signing using HSS, XMSS, and XMSS^MT. When
these algorithm identifiers appear in the algorithm field as an
AlgorithmIdentifier, the encoding <bcp14>MUST</bcp14> omit the parameters field. That is, the
AlgorithmIdentifier <bcp14>SHALL</bcp14> be a SEQUENCE of one component, one of the OIDs
defined in the following subsections.</t>
      <t>When the signature algorithm identifiers described in this document are used to
create a signature on a message, no digest algorithm is applied to the message
before signing.  That is, the full data to be signed is signed rather than
a digest of the data.</t>
      <t>The format of an HSS signature is described in <xref section="6.2" sectionFormat="of" target="RFC8554"/>. The format
of an XMSS signature is described in <xref section="B.2" sectionFormat="of" target="RFC8391"/> and the format of
an XMSS^MT signature is described in <xref section="C.2" sectionFormat="of" target="RFC8391"/>.
The octet string representing the signature is encoded
directly in a BIT STRING without adding any additional ASN.1 wrapping. For
the Certificate and CertificateList structures, the octet string is encoded
in the "signatureValue" BIT STRING field.</t>
      <section anchor="hss-signature-algorithm">
        <name>HSS Signature Algorithm</name>
        <t>The HSS public key OID is also used to specify that an HSS signature was
generated on the full message, i.e. the message was not hashed before being
processed by the HSS signature algorithm.</t>
        <artwork><![CDATA[
   id-alg-hss-lms-hashsig OBJECT IDENTIFIER ::= {
      iso(1) member-body(2) us(840) rsadsi(113549) pkcs(1) pkcs9(9)
      smime(16) alg(3) 17 }
]]></artwork>
        <t>See <xref target="SP800208"/> and <xref target="RFC8554"/> for more information on the contents and
format of an HSS signature.</t>
      </section>
      <section anchor="xmss-signature-algorithm">
        <name>XMSS Signature Algorithm</name>
        <t>The id-alg-xmss-hashsig public key OID is also used to specify that an XMSS signature was
generated on the full message, i.e. the message was not hashed before being
processed by the XMSS signature algorithm.</t>
        <t>See <xref target="SP800208"/> and <xref target="RFC8391"/> for more information on the contents and
format of an XMSS signature.</t>
        <t>The signature generation <bcp14>MUST</bcp14> be performed according to 7.2 of
<xref target="SP800208"/>.</t>
      </section>
      <section anchor="xmssmt-signature-algorithm">
        <name>XMSS^MT Signature Algorithm</name>
        <t>The id-alg-xmssmt-hashsig public key OID is also used to specify that an XMSS^MT signature
was generated on the full message, i.e. the message was not hashed before being
processed by the XMSS^MT signature algorithm.</t>
        <t>See <xref target="SP800208"/> and <xref target="RFC8391"/> for more information on the contents and
format of an XMSS^MT signature.</t>
        <t>The signature generation <bcp14>MUST</bcp14> be performed according to 7.2 of
<xref target="SP800208"/>.</t>
      </section>
    </section>
    <section anchor="key-generation">
      <name>Key Generation</name>
      <t>The key generation for XMSS and XMSS^MT <bcp14>MUST</bcp14> be performed according to 7.2 of
<xref target="SP800208"/></t>
    </section>
    <section anchor="sec-asn1">
      <name>ASN.1 Module</name>
      <t>For reference purposes, the ASN.1 syntax is presented as an ASN.1 module here.
This ASN.1 Module builds upon the conventions established in <xref target="RFC5911"/>.</t>
      <artwork><![CDATA[
X509-SHBS-2024
  { iso(1) identified-organization(3) dod(6) internet(1) security(5)
    mechanisms(5) pkix(7) id-mod(0) id-mod-pkix1-shbs-2024(TBD) }

DEFINITIONS IMPLICIT TAGS ::= BEGIN

EXPORTS ALL;

IMPORTS
  PUBLIC-KEY, SIGNATURE-ALGORITHM
    FROM AlgorithmInformation-2009  -- RFC 5911 [CMSASN1]
      { iso(1) identified-organization(3) dod(6) internet(1)
        security(5) mechanisms(5) pkix(7) id-mod(0)
        id-mod-algorithmInformation-02(58) }

  sa-HSS-LMS-HashSig, pk-HSS-LMS-HashSig
    FROM MTS-HashSig-2013
      { iso(1) member-body(2) us(840) rsadsi(113549) pkcs(1) pkcs9(9)
        id-smime(16) id-mod(0) id-mod-mts-hashsig-2013(64) };

--
-- Object Identifiers
--

-- id-alg-hss-lms-hashsig is defined in {{I-D.draft-ietf-lamps-rfc8708bis}}

id-alg-xmss-hashsig  OBJECT IDENTIFIER ::= {
   iso(1) identified-organization(3) dod(6) internet(1) security(5)
   mechanisms(5) pkix(7) algorithms(6) 34 }

id-alg-xmssmt-hashsig  OBJECT IDENTIFIER ::= {
   iso(1) identified-organization(3) dod(6) internet(1) security(5)
   mechanisms(5) pkix(7) algorithms(6) 35 }

--
-- Signature Algorithms and Public Keys
--

-- sa-HSS-LMS-HashSig is defined in {{I-D.draft-ietf-lamps-rfc8708bis}}

sa-XMSS-HashSig SIGNATURE-ALGORITHM ::= {
   IDENTIFIER id-alg-xmss-hashsig
   PARAMS ARE absent
   PUBLIC-KEYS { pk-XMSS-HashSig }
   SMIME-CAPS { IDENTIFIED BY id-alg-xmss-hashsig } }

sa-XMSSMT-HashSig SIGNATURE-ALGORITHM ::= {
   IDENTIFIER id-alg-xmssmt-hashsig
   PARAMS ARE absent
   PUBLIC-KEYS { pk-XMSSMT-HashSig }
   SMIME-CAPS { IDENTIFIED BY id-alg-xmssmt-hashsig } }

-- pk-HSS-LMS-HashSig is defined in {{I-D.draft-ietf-lamps-rfc8708bis}}

pk-XMSS-HashSig PUBLIC-KEY ::= {
   IDENTIFIER id-alg-xmss-hashsig
   -- KEY no ASN.1 wrapping --
   PARAMS ARE absent
   CERT-KEY-USAGE
      { digitalSignature, nonRepudiation, keyCertSign, cRLSign } }

pk-XMSSMT-HashSig PUBLIC-KEY ::= {
   IDENTIFIER id-alg-xmssmt-hashsig
   -- KEY no ASN.1 wrapping --
   PARAMS ARE absent
   CERT-KEY-USAGE
      { digitalSignature, nonRepudiation, keyCertSign, cRLSign } }

--
-- Public Key (pk-) Algorithms
--
PublicKeys PUBLIC-KEY ::= {
   -- This expands PublicKeys from RFC 5912
   pk-HSS-LMS-HashSig |
   pk-XMSS-HashSig |
   pk-XMSSMT-HashSig,
   ...
}

--
-- Signature Algorithms (sa-)
--
SignatureAlgs SIGNATURE-ALGORITHM ::= {
   -- This expands SignatureAlgorithms from RFC 5912
   sa-HSS-LMS-HashSig |
   sa-XMSS-HashSig |
   sa-XMSSMT-HashSig,
   ...
}

END
]]></artwork>
    </section>
    <section anchor="sec-security">
      <name>Security Considerations</name>
      <t>The security requirements of <xref target="SP800208"/> <bcp14>MUST</bcp14> be taken into account.</t>
      <t>As S-HBS private keys can only generate a limited number of signatures, a
user needs to be aware of the total number of signatures they intend to
generate in their use case, otherwise they risk exhausting the number of OTS
keys in the private key associated with the S-HBS public key in their
certificate.</t>
      <t>For S-HBS it is crucial to stress the importance of a correct state management.
If an attacker were able to obtain signatures for two different messages
created using the same OTS key, then it would become computationally feasible
for that attacker to create forgeries <xref target="BH16"/>. As noted in <xref target="MCGREW"/> and
<xref target="ETSI-TR-103-692"/>, extreme care needs to be taken in order to avoid the risk
that an OTS key will be reused accidentally.  This is a new requirement that
most developers will not be familiar with and requires careful handling.</t>
      <t>Various strategies for a correct state management can be applied:</t>
      <ul spacing="normal">
        <li>
          <t>Implement a track record of all signatures generated by a key pair associated
to a S-HBS instance. This track record may be stored outside the
device which is used to generate the signature. Check the track record to
prevent OTS key reuse before a new signature is released. Drop the new
signature and hit your PANIC button if you spot OTS key reuse.</t>
        </li>
        <li>
          <t>Use a S-HBS instance only for a moderate number of signatures such
that it is always practical to keep a consistent track record and be able to
unambiguously trace back all generated signatures.</t>
        </li>
        <li>
          <t>Apply the state reservation strategy described in Section 5 of <xref target="MCGREW"/>, where
upcoming states are reserved in advance by the signer. In this way the number of
state synchronisations between nonvolatile and volatile memory is reduced.</t>
        </li>
      </ul>
    </section>
    <section anchor="backup-and-restore-management">
      <name>Backup and Restore Management</name>
      <t>Certificate Authorities have high demands in order to ensure the availability
of signature generation throughout the validity period of signing key pairs.</t>
      <t>Usual backup and restore strategies when using a stateless signature scheme
(e.g. SLH-DSA) are to duplicate private keying material and to operate
redundant signing devices or to store and safeguard a copy of the private
keying material such that it can be used to set up a new signing device in case
of technical difficulties.</t>
      <t>For S-HBS such straightforward backup and restore strategies will lead to OTS
reuse with high probability as a correct state management is not guaranteed.
Strategies for maintaining availability and keeping a correct state are
described in Section 7 of <xref target="SP800208"/>.</t>
    </section>
    <section anchor="iana-considerations">
      <name>IANA Considerations</name>
      <t>One object identifier for the ASN.1 module in Appendix A is requested
for the SMI Security for PKIX Module Identifiers (1.3.6.1.5.5.7.0)
registry:</t>
      <table>
        <thead>
          <tr>
            <th align="left">Decimal</th>
            <th align="left">Description</th>
            <th align="left">References</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">TBD</td>
            <td align="left">id-mod-pkix1-shbs-2024</td>
            <td align="left">[EDNOTE: THIS RFC]</td>
          </tr>
        </tbody>
      </table>
      <t>IANA has updated the "SMI Security for PKIX Algorithms" (1.3.6.1.5.5.7.6)
registry <xref target="SMI-PKIX"/> with two additional entries:</t>
      <table>
        <thead>
          <tr>
            <th align="left">Decimal</th>
            <th align="left">Description</th>
            <th align="left">References</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">34</td>
            <td align="left">id-alg-xmss-hashsig</td>
            <td align="left">[EDNOTE: THIS RFC]</td>
          </tr>
          <tr>
            <td align="left">35</td>
            <td align="left">id-alg-xmssmt-hashsig</td>
            <td align="left">[EDNOTE: THIS RFC]</td>
          </tr>
        </tbody>
      </table>
    </section>
  </middle>
  <back>
    <references anchor="sec-combined-references">
      <name>References</name>
      <references anchor="sec-normative-references">
        <name>Normative References</name>
        <reference anchor="I-D.draft-ietf-lamps-rfc8708bis">
          <front>
            <title>Use of the HSS/LMS Hash-Based Signature Algorithm in the Cryptographic Message Syntax (CMS)</title>
            <author fullname="R. Housley" initials="R." surname="Housley"/>
            <date month="February" year="2020"/>
            <abstract>
              <t>This document specifies the conventions for using the Hierarchical Signature System (HSS) / Leighton-Micali Signature (LMS) hash-based signature algorithm with the Cryptographic Message Syntax (CMS). In addition, the algorithm identifier and public key syntax are provided. The HSS/LMS algorithm is one form of hash-based digital signature; it is described in RFC 8554.</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="8708"/>
          <seriesInfo name="DOI" value="10.17487/RFC8708"/>
        </reference>
        <reference anchor="RFC5911">
          <front>
            <title>New ASN.1 Modules for Cryptographic Message Syntax (CMS) and S/MIME</title>
            <author fullname="P. Hoffman" initials="P." surname="Hoffman"/>
            <author fullname="J. Schaad" initials="J." surname="Schaad"/>
            <date month="June" year="2010"/>
            <abstract>
              <t>The Cryptographic Message Syntax (CMS) format, and many associated formats, are expressed using ASN.1. The current ASN.1 modules conform to the 1988 version of ASN.1. This document updates those ASN.1 modules to conform to the 2002 version of ASN.1. There are no bits-on-the-wire changes to any of the formats; this is simply a change to the syntax. This document is not an Internet Standards Track specification; it is published for informational purposes.</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="5911"/>
          <seriesInfo name="DOI" value="10.17487/RFC5911"/>
        </reference>
        <reference anchor="RFC5280">
          <front>
            <title>Internet X.509 Public Key Infrastructure Certificate and Certificate Revocation List (CRL) Profile</title>
            <author fullname="D. Cooper" initials="D." surname="Cooper"/>
            <author fullname="S. Santesson" initials="S." surname="Santesson"/>
            <author fullname="S. Farrell" initials="S." surname="Farrell"/>
            <author fullname="S. Boeyen" initials="S." surname="Boeyen"/>
            <author fullname="R. Housley" initials="R." surname="Housley"/>
            <author fullname="W. Polk" initials="W." surname="Polk"/>
            <date month="May" year="2008"/>
            <abstract>
              <t>This memo profiles the X.509 v3 certificate and X.509 v2 certificate revocation list (CRL) for use in the Internet. An overview of this approach and model is provided as an introduction. The X.509 v3 certificate format is described in detail, with additional information regarding the format and semantics of Internet name forms. Standard certificate extensions are described and two Internet-specific extensions are defined. A set of required certificate extensions is specified. The X.509 v2 CRL format is described in detail along with standard and Internet-specific extensions. An algorithm for X.509 certification path validation is described. An ASN.1 module and examples are provided in the appendices. [STANDARDS-TRACK]</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="5280"/>
          <seriesInfo name="DOI" value="10.17487/RFC5280"/>
        </reference>
        <reference anchor="RFC8391">
          <front>
            <title>XMSS: eXtended Merkle Signature Scheme</title>
            <author fullname="A. Huelsing" initials="A." surname="Huelsing"/>
            <author fullname="D. Butin" initials="D." surname="Butin"/>
            <author fullname="S. Gazdag" initials="S." surname="Gazdag"/>
            <author fullname="J. Rijneveld" initials="J." surname="Rijneveld"/>
            <author fullname="A. Mohaisen" initials="A." surname="Mohaisen"/>
            <date month="May" year="2018"/>
            <abstract>
              <t>This note describes the eXtended Merkle Signature Scheme (XMSS), a hash-based digital signature system that is based on existing descriptions in scientific literature. This note specifies Winternitz One-Time Signature Plus (WOTS+), a one-time signature scheme; XMSS, a single-tree scheme; and XMSS^MT, a multi-tree variant of XMSS. Both XMSS and XMSS^MT use WOTS+ as a main building block. XMSS provides cryptographic digital signatures without relying on the conjectured hardness of mathematical problems. Instead, it is proven that it only relies on the properties of cryptographic hash functions. XMSS provides strong security guarantees and is even secure when the collision resistance of the underlying hash function is broken. It is suitable for compact implementations, is relatively simple to implement, and naturally resists side-channel attacks. Unlike most other signature systems, hash-based signatures can so far withstand known attacks using quantum computers.</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="8391"/>
          <seriesInfo name="DOI" value="10.17487/RFC8391"/>
        </reference>
        <reference anchor="RFC8554">
          <front>
            <title>Leighton-Micali Hash-Based Signatures</title>
            <author fullname="D. McGrew" initials="D." surname="McGrew"/>
            <author fullname="M. Curcio" initials="M." surname="Curcio"/>
            <author fullname="S. Fluhrer" initials="S." surname="Fluhrer"/>
            <date month="April" year="2019"/>
            <abstract>
              <t>This note describes a digital-signature system based on cryptographic hash functions, following the seminal work in this area of Lamport, Diffie, Winternitz, and Merkle, as adapted by Leighton and Micali in 1995. It specifies a one-time signature scheme and a general signature scheme. These systems provide asymmetric authentication without using large integer mathematics and can achieve a high security level. They are suitable for compact implementations, are relatively simple to implement, and are naturally resistant to side-channel attacks. Unlike many other signature systems, hash-based signatures would still be secure even if it proves feasible for an attacker to build a quantum computer.</t>
              <t>This document is a product of the Crypto Forum Research Group (CFRG) in the IRTF. This has been reviewed by many researchers, both in the research group and outside of it. The Acknowledgements section lists many of them.</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="8554"/>
          <seriesInfo name="DOI" value="10.17487/RFC8554"/>
        </reference>
        <reference anchor="SP800208" target="https://doi.org/10.6028/NIST.SP.800-208">
          <front>
            <title>Recommendation for Stateful Hash-Based Signature Schemes</title>
            <author initials="" surname="National Institute of Standards and Technology (NIST)">
              <organization/>
            </author>
            <date year="2020" month="October" day="29"/>
          </front>
        </reference>
        <reference anchor="RFC2119">
          <front>
            <title>Key words for use in RFCs to Indicate Requirement Levels</title>
            <author fullname="S. Bradner" initials="S." surname="Bradner"/>
            <date month="March" year="1997"/>
            <abstract>
              <t>In many standards track documents several words are used to signify the requirements in the specification. These words are often capitalized. This document defines these words as they should be interpreted in IETF documents. This document specifies an Internet Best Current Practices for the Internet Community, and requests discussion and suggestions for improvements.</t>
            </abstract>
          </front>
          <seriesInfo name="BCP" value="14"/>
          <seriesInfo name="RFC" value="2119"/>
          <seriesInfo name="DOI" value="10.17487/RFC2119"/>
        </reference>
        <reference anchor="RFC8174">
          <front>
            <title>Ambiguity of Uppercase vs Lowercase in RFC 2119 Key Words</title>
            <author fullname="B. Leiba" initials="B." surname="Leiba"/>
            <date month="May" year="2017"/>
            <abstract>
              <t>RFC 2119 specifies common key words that may be used in protocol specifications. This document aims to reduce the ambiguity by clarifying that only UPPERCASE usage of the key words have the defined special meanings.</t>
            </abstract>
          </front>
          <seriesInfo name="BCP" value="14"/>
          <seriesInfo name="RFC" value="8174"/>
          <seriesInfo name="DOI" value="10.17487/RFC8174"/>
        </reference>
      </references>
      <references anchor="sec-informative-references">
        <name>Informative References</name>
        <reference anchor="RFC3279">
          <front>
            <title>Algorithms and Identifiers for the Internet X.509 Public Key Infrastructure Certificate and Certificate Revocation List (CRL) Profile</title>
            <author fullname="L. Bassham" initials="L." surname="Bassham"/>
            <author fullname="W. Polk" initials="W." surname="Polk"/>
            <author fullname="R. Housley" initials="R." surname="Housley"/>
            <date month="April" year="2002"/>
            <abstract>
              <t>This document specifies algorithm identifiers and ASN.1 encoding formats for digital signatures and subject public keys used in the Internet X.509 Public Key Infrastructure (PKI). Digital signatures are used to sign certificates and certificate revocation list (CRLs). Certificates include the public key of the named subject. [STANDARDS-TRACK]</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="3279"/>
          <seriesInfo name="DOI" value="10.17487/RFC3279"/>
        </reference>
        <reference anchor="RFC3647">
          <front>
            <title>Internet X.509 Public Key Infrastructure Certificate Policy and Certification Practices Framework</title>
            <author fullname="S. Chokhani" initials="S." surname="Chokhani"/>
            <author fullname="W. Ford" initials="W." surname="Ford"/>
            <author fullname="R. Sabett" initials="R." surname="Sabett"/>
            <author fullname="C. Merrill" initials="C." surname="Merrill"/>
            <author fullname="S. Wu" initials="S." surname="Wu"/>
            <date month="November" year="2003"/>
            <abstract>
              <t>This document presents a framework to assist the writers of certificate policies or certification practice statements for participants within public key infrastructures, such as certification authorities, policy authorities, and communities of interest that wish to rely on certificates. In particular, the framework provides a comprehensive list of topics that potentially (at the writer's discretion) need to be covered in a certificate policy or a certification practice statement. This document supersedes RFC 2527.</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="3647"/>
          <seriesInfo name="DOI" value="10.17487/RFC3647"/>
        </reference>
        <reference anchor="RFC4949">
          <front>
            <title>Internet Security Glossary, Version 2</title>
            <author fullname="R. Shirey" initials="R." surname="Shirey"/>
            <date month="August" year="2007"/>
            <abstract>
              <t>This Glossary provides definitions, abbreviations, and explanations of terminology for information system security. The 334 pages of entries offer recommendations to improve the comprehensibility of written material that is generated in the Internet Standards Process (RFC 2026). The recommendations follow the principles that such writing should (a) use the same term or definition whenever the same concept is mentioned; (b) use terms in their plainest, dictionary sense; (c) use terms that are already well-established in open publications; and (d) avoid terms that either favor a particular vendor or favor a particular technology or mechanism over other, competing techniques that already exist or could be developed. This memo provides information for the Internet community.</t>
            </abstract>
          </front>
          <seriesInfo name="FYI" value="36"/>
          <seriesInfo name="RFC" value="4949"/>
          <seriesInfo name="DOI" value="10.17487/RFC4949"/>
        </reference>
        <reference anchor="RFC8410">
          <front>
            <title>Algorithm Identifiers for Ed25519, Ed448, X25519, and X448 for Use in the Internet X.509 Public Key Infrastructure</title>
            <author fullname="S. Josefsson" initials="S." surname="Josefsson"/>
            <author fullname="J. Schaad" initials="J." surname="Schaad"/>
            <date month="August" year="2018"/>
            <abstract>
              <t>This document specifies algorithm identifiers and ASN.1 encoding formats for elliptic curve constructs using the curve25519 and curve448 curves. The signature algorithms covered are Ed25519 and Ed448. The key agreement algorithms covered are X25519 and X448. The encoding for public key, private key, and Edwards-curve Digital Signature Algorithm (EdDSA) structures is provided.</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="8410"/>
          <seriesInfo name="DOI" value="10.17487/RFC8410"/>
        </reference>
        <reference anchor="RFC8411">
          <front>
            <title>IANA Registration for the Cryptographic Algorithm Object Identifier Range</title>
            <author fullname="J. Schaad" initials="J." surname="Schaad"/>
            <author fullname="R. Andrews" initials="R." surname="Andrews"/>
            <date month="August" year="2018"/>
            <abstract>
              <t>When the Curdle Security Working Group was chartered, a range of object identifiers was donated by DigiCert, Inc. for the purpose of registering the Edwards Elliptic Curve key agreement and signature algorithms. This donated set of OIDs allowed for shorter values than would be possible using the existing S/MIME or PKIX arcs. This document describes the donated range and the identifiers that were assigned from that range, transfers control of that range to IANA, and establishes IANA allocation policies for any future assignments within that range.</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="8411"/>
          <seriesInfo name="DOI" value="10.17487/RFC8411"/>
        </reference>
        <reference anchor="MCGREW" target="https://tubiblio.ulb.tu-darmstadt.de/id/eprint/101633">
          <front>
            <title>State Management for Hash-Based Signatures</title>
            <author initials="D." surname="McGrew">
              <organization/>
            </author>
            <author initials="P." surname="Kampanakis">
              <organization/>
            </author>
            <author initials="S." surname="Fluhrer">
              <organization/>
            </author>
            <author initials="S." surname="Gazdag">
              <organization/>
            </author>
            <author initials="D." surname="Butin">
              <organization/>
            </author>
            <author initials="J." surname="Buchmann">
              <organization/>
            </author>
            <date year="2016" month="November" day="02"/>
          </front>
        </reference>
        <reference anchor="BH16" target="https://eprint.iacr.org/2016/1042.pdf">
          <front>
            <title>Oops, I did it again – Security of One-Time Signatures under Two-Message Attacks.</title>
            <author initials="L." surname="Bruinderink">
              <organization/>
            </author>
            <author initials="S." surname="Hülsing">
              <organization/>
            </author>
            <date year="2016"/>
          </front>
        </reference>
        <reference anchor="CNSA2.0" target="https://media.defense.gov/2022/Sep/07/2003071834/-1/-1/0/CSA_CNSA_2.0_ALGORITHMS_.PDF">
          <front>
            <title>Commercial National Security Algorithm Suite 2.0 (CNSA 2.0) Cybersecurity Advisory (CSA)</title>
            <author initials="" surname="National Security Agency (NSA)">
              <organization/>
            </author>
            <date year="2022" month="September" day="07"/>
          </front>
        </reference>
        <reference anchor="ETSI-TR-103-692" target="https://www.etsi.org/deliver/etsi_tr/103600_103699/103692/01.01.01_60/tr_103692v010101p.pdf">
          <front>
            <title>State management for stateful authentication mechanisms</title>
            <author initials="" surname="European Telecommunications Standards Institute (ETSI)">
              <organization/>
            </author>
            <date year="2021" month="November"/>
          </front>
        </reference>
        <reference anchor="IANA-LMS" target="https://www.iana.org/assignments/leighton-micali-signatures/">
          <front>
            <title>Leighton-Micali Signatures (LMS)</title>
            <author initials="" surname="IANA">
              <organization/>
            </author>
            <date>n.d.</date>
          </front>
        </reference>
        <reference anchor="IANA-XMSS" target="https://iana.org/assignments/xmss-extended-hash-based-signatures/">
          <front>
            <title>XMSS: Extended Hash-Based Signatures</title>
            <author initials="" surname="IANA">
              <organization/>
            </author>
            <date>n.d.</date>
          </front>
        </reference>
        <reference anchor="SMI-PKIX" target="https://www.iana.org/assignments/smi-numbers/smi-numbers.xhtml#smi-numbers-1.3.6.1.5.5.7.6">
          <front>
            <title>SMI Security for PKIX Algorithms</title>
            <author initials="" surname="IANA">
              <organization/>
            </author>
            <date>n.d.</date>
          </front>
        </reference>
        <reference anchor="ANSSI" target="https://cyber.gouv.fr/sites/default/files/document/follow_up_position_paper_on_post_quantum_cryptography.pdf">
          <front>
            <title>ANSSI views on the Post-Quantum Cryptography transition (2023 follow up)</title>
            <author initials="" surname="Agence nationale de la sécurité des systèmes d'information (ANSSI)">
              <organization/>
            </author>
            <date year="2023" month="December" day="21"/>
          </front>
        </reference>
        <reference anchor="BSI" target="https://www.bsi.bund.de/SharedDocs/Downloads/EN/BSI/Publications/Brochure/quantum-safe-cryptography.pdf">
          <front>
            <title>Quantum-safe cryptography – fundamentals, current developments and recommendations</title>
            <author initials="" surname="Bundesamt für Sicherheit in der Informationstechnik (BSI)">
              <organization/>
            </author>
            <date year="2022" month="May" day="18"/>
          </front>
        </reference>
      </references>
    </references>
    <?line 637?>

<section anchor="hss-x509-v3-certificate-example">
      <name>HSS X.509 v3 Certificate Example</name>
      <t>This section shows a self-signed X.509 v3 certificate using HSS.</t>
      <artwork><![CDATA[
Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number:
            e8:91:d6:06:91:4f:ce:f3
        Signature Algorithm: hss
        Issuer: C = US, ST = VA, L = Herndon, O = Bogus CA
        Validity
            Not Before: May 14 08:58:11 2024 GMT
            Not After : May 14 08:58:11 2034 GMT
        Subject: C = US, ST = VA, L = Herndon, O = Bogus CA
        Subject Public Key Info:
            Public Key Algorithm: hss
                hss public key:
                PQ key material:
                    00:00:00:01:00:00:00:05:00:00:00:04:c0:96:12:
                    8b:ea:38:30:78:eb:f6:fb:43:d7:7f:9f:9e:81:39:
                    e2:7c:b9:34:4e:6e:53:19:f0:ee:68:75:85:83:d3:
                    2b:e9:7b:14:46:9e:4e:c5:e3:5a:18:0b:30:e5:13
        X509v3 extensions:
            X509v3 Subject Key Identifier:
                58:15:AB:F4:CF:03:69:02:60:7A:57:4D:C5:D5:B3:72:
                8A:19:21:68
            X509v3 Authority Key Identifier:
                58:15:AB:F4:CF:03:69:02:60:7A:57:4D:C5:D5:B3:72:
                8A:19:21:68
            X509v3 Basic Constraints: critical
                CA:TRUE
            X509v3 Key Usage: critical
                Certificate Sign, CRL Sign
    Signature Algorithm: hss
    Signature Value:
        00:00:00:00:00:00:00:00:00:00:00:04:9c:37:52:ff:b9:d7:
        df:f5:5b:01:ba:50:c2:50:cc:6f:f3:b1:73:df:0c:2a:ea:b3:
        ed:96:1e:ce:e7:58:05:da:8d:a7:77:21:42:32:d9:f9:4a:4d:
        f7:2b:18:2a:1c:5c:69:03:f3:1c:9c:95:6d:31:9a:c9:ca:84:
        4d:ae:b3:8b:c3:71:ac:3f:87:51:be:38:b4:bf:d9:dc:90:1f:
        1e:54:bd:f9:1a:65:70:d4:46:b6:ad:4d:6d:16:b9:fb:29:f4:
        e3:86:42:4a:3f:a4:8f:01:84:9b:44:0b:23:22:9c:97:6d:d5:
        b9:26:39:11:ab:46:82:bd:10:6c:b4:7a:64:ed:c7:40:b0:33:
        f0:b5:81:1c:b4:41:54:9c:30:d9:d2:93:ba:48:8c:4f:d0:25:
        41:60:7b:90:5e:12:20:b7:30:16:16:1e:b7:ee:d8:4b:ee:ed:
        3c:70:fc:ff:36:18:aa:24:23:87:91:65:a8:95:2d:b6:1c:d1:
        02:7b:70:81:8a:18:17:c0:45:62:fe:47:a1:3e:69:54:31:67:
        58:9a:e1:e3:c9:8d:ee:1e:2a:d1:46:75:e9:e4:90:67:01:57:
        92:54:db:b4:ea:de:8b:e7:eb:fc:27:80:9b:d5:da:e0:8e:b0:
        b3:08:ca:6f:a1:1c:f4:40:65:b0:f6:f8:c9:a7:97:04:c8:7c:
        9e:56:ec:2f:4b:cd:45:8b:d7:e6:a7:50:c7:e6:21:2c:17:31:
        23:11:7a:ae:9a:b5:84:5f:e6:5c:82:99:a8:3a:a9:91:87:9a:
        24:5c:83:01:91:7c:fc:cd:be:2e:92:50:fb:12:11:96:08:0d:
        c9:24:0d:bb:6f:fb:59:05:af:7f:96:bc:a3:f4:58:e2:fa:0a:
        4a:f2:4c:f7:b3:1b:81:dd:4a:41:a0:b1:dd:52:4c:bb:6d:c0:
        a8:d9:bb:29:c8:fc:e3:7e:f8:6a:e5:5e:c4:e4:e8:7c:0b:00:
        87:15:75:a2:06:50:97:c6:1f:14:52:79:04:a8:9c:ec:b1:c7:
        6a:46:33:98:b8:63:f7:a7:2c:d4:62:78:94:1c:5d:9d:4f:a6:
        0a:ae:39:50:85:b2:09:8d:62:c9:4c:11:9f:0c:91:a5:ac:2d:
        11:bd:71:b6:0c:ea:34:98:53:fc:2e:cc:7b:a4:9c:2e:7a:a4:
        8d:e2:e8:8c:01:a9:9c:3e:b5:34:77:33:82:01:d4:ef:72:04:
        d6:5b:e5:f6:2c:1b:ae:86:c4:73:02:44:85:d6:f7:ac:a3:e8:
        f6:a9:b5:5c:6d:46:88:da:55:b8:2b:7a:4c:0c:9a:e7:cd:5d:
        62:8a:ca:c8:96:ce:8d:71:7b:d2:c1:0d:9a:35:55:2b:84:3e:
        0e:a5:fa:d6:a0:76:8e:23:b3:df:c9:3b:4f:68:56:1e:e9:3c:
        79:5b:d3:25:54:11:ad:a6:ac:58:11:49:8f:4d:c4:c1:39:99:
        76:3a:a6:d1:2f:57:ad:bf:7c:9d:57:cc:37:0d:29:84:29:7b:
        cb:46:85:c3:81:c5:33:9a:65:c3:2f:01:48:ca:44:6c:f1:84:
        3d:d0:49:c2:c1:05:db:77:4c:b9:72:3d:6f:ce:69:f2:91:c6:
        15:25:8f:da:38:7e:ef:5b:3e:5f:35:ab:a6:78:16:28:42:c1:
        2c:2f:9e:11:53:2c:bd:c4:24:7b:e9:c4:ce:3d:d6:41:c7:5d:
        92:91:c3:37:cb:72:44:d7:0d:70:85:13:0b:ac:b3:0f:b0:e5:
        e3:2e:48:b9:9c:b8:d7:3e:7c:50:69:03:7a:5f:ae:f8:6c:09:
        61:97:6b:ce:cd:e5:f0:55:fe:05:f8:97:1d:9e:81:65:f5:ff:
        9a:7a:8c:96:d8:f8:cf:d8:dc:55:ce:67:7a:00:6b:fd:bb:3f:
        1b:3d:65:94:c1:5a:b6:a0:8e:be:a4:be:26:90:5f:1f:06:d4:
        ea:3f:a6:97:40:8e:bf:18:5c:92:0f:15:e3:05:4a:14:51:1e:
        23:81:ef:cf:f7:a8:88:75:f8:2d:28:37:26:87:27:63:5c:01:
        53:0e:5e:53:d2:a7:18:eb:2f:c0:82:49:05:b0:4d:33:6f:94:
        10:91:77:f8:90:9e:ca:fe:bb:3d:c4:42:d6:89:84:98:42:f4:
        24:b3:b4:db:5e:2b:66:a9:ff:6c:18:d4:79:f8:72:73:53:9b:
        02:ed:04:73:77:a4:68:cf:4b:be:4b:16:50:62:87:f9:49:99:
        e3:a1:0c:42:92:bc:a9:e3:2d:22:82:35:7f:71:15:88:70:6a:
        01:ab:44:64:ad:e5:52:d4:97:ee:bb:44:7b:6e:08:7f:dd:94:
        fd:c9:1c:6b:59:d1:92:51:29:03:ce:ec:bf:41:a5:14:69:54:
        3a:b4:39:d9:44:5d:f1:b2:f4:5c:6b:9f:c9:5f:bb:fc:c8:c7:
        a3:8b:e1:ec:e2:d0:69:5a:40:1c:9c:9d:8a:3d:77:3b:c1:5d:
        c0:72:61:4b:37:c5:96:8c:6d:8b:f8:56:da:ac:3e:3c:72:09:
        ce:f6:c3:fe:5d:cf:37:d9:68:cd:a7:dd:f7:96:63:da:8c:1d:
        df:b8:32:cf:eb:97:11:83:fe:6b:aa:b9:e2:4b:b2:ea:62:73:
        c3:1c:e9:40:90:56:4f:12:c3:ba:f4:2b:d9:1c:50:cc:e0:51:
        d8:eb:bf:67:28:0c:2d:13:8d:b3:6f:13:6a:1d:a7:54:20:ba:
        82:5b:b8:e5:1f:89:f1:67:26:c1:dc:1b:60:57:ed:a6:2c:f2:
        17:01:7f:a5:e7:5c:64:c9:3c:08:f2:cf:48:ec:88:84:ef:03:
        c2:f5:eb:05:31:7d:fe:7f:3c:71:41:28:17:64:5f:b9:ec:54:
        79:d0:b3:98:fb:84:9c:36:8b:43:0b:d4:c9:ec:09:4a:70:13:
        62:f2:36:c8:b4:75:cc:2a:77:08:a0:9d:ef:19:d6:88:dc:e2:
        b2:4e:40:61:71:cb:c7:c3:de:16:6f:49:7f:5e:d5:17:00:00:
        00:05:79:47:12:9f:ce:eb:1d:a8:fd:0d:b0:18:44:6a:ef:54:
        28:46:e4:19:f6:2d:3e:74:bb:9d:36:0a:ae:67:4a:28:7a:1b:
        80:39:a0:08:2a:28:a0:ec:55:ee:55:aa:a1:cc:94:d4:36:1a:
        b3:57:25:30:ad:2c:5e:63:ba:22:fc:aa:7a:59:64:f6:d8:03:
        20:28:71:f9:dc:09:fa:4c:81:b9:64:1b:ad:ea:cb:db:18:17:
        5d:d8:98:bd:d2:8d:c5:04:7c:5b:92:9a:89:f6:bc:d6:55:c7:
        08:5d:3c:58:8e:18:ac:6f:88:a8:d7:9e:d4:ee:5d:f5:21:4e:
        a5:8b:19:5f:e3:f4:66:f9:25:4d:f9:c6:60:62:31:72:5c:34:
        34:67:1a:a7:6a:7d:54:a3:d8:9b:1f:5b:f8:08:41:79:5b:43
]]></artwork>
      <artwork><![CDATA[
-----BEGIN CERTIFICATE-----
MIIGnjCCAXagAwIBAgIJAOiR1gaRT87zMA0GCyqGSIb3DQEJEAMRMD8xCzAJBgNV
BAYTAlVTMQswCQYDVQQIDAJWQTEQMA4GA1UEBwwHSGVybmRvbjERMA8GA1UECgwI
Qm9ndXMgQ0EwHhcNMjQwNTE0MDg1ODExWhcNMzQwNTE0MDg1ODExWjA/MQswCQYD
VQQGEwJVUzELMAkGA1UECAwCVkExEDAOBgNVBAcMB0hlcm5kb24xETAPBgNVBAoM
CEJvZ3VzIENBME4wDQYLKoZIhvcNAQkQAxEDPQAAAAABAAAABQAAAATAlhKL6jgw
eOv2+0PXf5+egTnifLk0Tm5TGfDuaHWFg9Mr6XsURp5OxeNaGAsw5ROjYzBhMB0G
A1UdDgQWBBRYFav0zwNpAmB6V03F1bNyihkhaDAfBgNVHSMEGDAWgBRYFav0zwNp
AmB6V03F1bNyihkhaDAPBgNVHRMBAf8EBTADAQH/MA4GA1UdDwEB/wQEAwIBBjAN
BgsqhkiG9w0BCRADEQOCBREAAAAAAAAAAAAAAAAEnDdS/7nX3/VbAbpQwlDMb/Ox
c98MKuqz7ZYezudYBdqNp3chQjLZ+UpN9ysYKhxcaQPzHJyVbTGaycqETa6zi8Nx
rD+HUb44tL/Z3JAfHlS9+RplcNRGtq1NbRa5+yn044ZCSj+kjwGEm0QLIyKcl23V
uSY5EatGgr0QbLR6ZO3HQLAz8LWBHLRBVJww2dKTukiMT9AlQWB7kF4SILcwFhYe
t+7YS+7tPHD8/zYYqiQjh5FlqJUtthzRAntwgYoYF8BFYv5HoT5pVDFnWJrh48mN
7h4q0UZ16eSQZwFXklTbtOrei+fr/CeAm9Xa4I6wswjKb6Ec9EBlsPb4yaeXBMh8
nlbsL0vNRYvX5qdQx+YhLBcxIxF6rpq1hF/mXIKZqDqpkYeaJFyDAZF8/M2+LpJQ
+xIRlggNySQNu2/7WQWvf5a8o/RY4voKSvJM97Mbgd1KQaCx3VJMu23AqNm7Kcj8
4374auVexOTofAsAhxV1ogZQl8YfFFJ5BKic7LHHakYzmLhj96cs1GJ4lBxdnU+m
Cq45UIWyCY1iyUwRnwyRpawtEb1xtgzqNJhT/C7Me6ScLnqkjeLojAGpnD61NHcz
ggHU73IE1lvl9iwbrobEcwJEhdb3rKPo9qm1XG1GiNpVuCt6TAya581dYorKyJbO
jXF70sENmjVVK4Q+DqX61qB2jiOz38k7T2hWHuk8eVvTJVQRraasWBFJj03EwTmZ
djqm0S9Xrb98nVfMNw0phCl7y0aFw4HFM5plwy8BSMpEbPGEPdBJwsEF23dMuXI9
b85p8pHGFSWP2jh+71s+XzWrpngWKELBLC+eEVMsvcQke+nEzj3WQcddkpHDN8ty
RNcNcIUTC6yzD7Dl4y5IuZy41z58UGkDel+u+GwJYZdrzs3l8FX+BfiXHZ6BZfX/
mnqMltj4z9jcVc5negBr/bs/Gz1llMFatqCOvqS+JpBfHwbU6j+ml0COvxhckg8V
4wVKFFEeI4Hvz/eoiHX4LSg3JocnY1wBUw5eU9KnGOsvwIJJBbBNM2+UEJF3+JCe
yv67PcRC1omEmEL0JLO0214rZqn/bBjUefhyc1ObAu0Ec3ekaM9LvksWUGKH+UmZ
46EMQpK8qeMtIoI1f3EViHBqAatEZK3lUtSX7rtEe24If92U/ckca1nRklEpA87s
v0GlFGlUOrQ52URd8bL0XGufyV+7/MjHo4vh7OLQaVpAHJydij13O8FdwHJhSzfF
loxti/hW2qw+PHIJzvbD/l3PN9lozafd95Zj2owd37gyz+uXEYP+a6q54kuy6mJz
wxzpQJBWTxLDuvQr2RxQzOBR2Ou/ZygMLRONs28Tah2nVCC6glu45R+J8Wcmwdwb
YFftpizyFwF/pedcZMk8CPLPSOyIhO8DwvXrBTF9/n88cUEoF2RfuexUedCzmPuE
nDaLQwvUyewJSnATYvI2yLR1zCp3CKCd7xnWiNzisk5AYXHLx8PeFm9Jf17VFwAA
AAV5RxKfzusdqP0NsBhEau9UKEbkGfYtPnS7nTYKrmdKKHobgDmgCCoooOxV7lWq
ocyU1DYas1clMK0sXmO6Ivyqellk9tgDIChx+dwJ+kyBuWQbrerL2xgXXdiYvdKN
xQR8W5Kaifa81lXHCF08WI4YrG+IqNee1O5d9SFOpYsZX+P0ZvklTfnGYGIxclw0
NGcap2p9VKPYmx9b+AhBeVtD
-----END CERTIFICATE-----
]]></artwork>
    </section>
    <section anchor="xmss-x509-v3-certificate-example">
      <name>XMSS X.509 v3 Certificate Example</name>
      <t>This section shows a self-signed X.509 v3 certificate using XMSS.</t>
      <artwork><![CDATA[
Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number:
            54:7e:64:70:29:9e:03:c5:7a:a5:5c:78:d1:27:87:8c:
            54:35:17:5d
        Signature Algorithm: xmss
        Issuer: C = FR, L = Paris, O = Bogus XMSS CA
        Validity
            Not Before: Jul 10 08:27:24 2024 GMT
            Not After : Jul  8 08:27:24 2034 GMT
        Subject: C = FR, L = Paris, O = Bogus XMSS CA
        Subject Public Key Info:
            Public Key Algorithm: xmss
                xmss public key:
                PQ key material:
                    00:00:00:01:2b:eb:bf:66:14:de:6f:96:5b:4d:2a:
                    50:00:7b:ad:5c:22:b0:13:79:72:02:14:a9:5f:fc:
                    96:e0:9b:78:8e:d6:be:8c:1c:70:3c:d8:dd:78:b2:
                    1a:14:47:be:1f:0d:74:72:3f:36:76:c2:cb:19:ad:
                    29:90:0b:82:de:9b:7f:df
        X509v3 extensions:
            X509v3 Subject Key Identifier:
                62:CE:35:A5:47:77:FF:21:87:2E:BC:2D:27:E7:8E:F4:
                35:6B:CF:D8
            X509v3 Authority Key Identifier:
                62:CE:35:A5:47:77:FF:21:87:2E:BC:2D:27:E7:8E:F4:
                35:6B:CF:D8
            X509v3 Basic Constraints: critical
                CA:TRUE
            X509v3 Key Usage: critical
                Certificate Sign, CRL Sign
    Signature Algorithm: xmss
    Signature Value:
        00:00:00:00:e5:88:a8:b8:73:ad:4d:92:f8:5c:81:c5:8a:63:
        57:6a:a7:3b:54:aa:b6:06:8a:d9:f1:c2:0b:c8:27:1e:4b:a2:
        cf:e2:da:44:ea:e8:f2:40:a8:b9:54:9c:49:36:12:24:df:74:
        ad:e5:29:ef:4f:da:88:0d:21:5d:3b:64:63:27:d0:84:b5:95:
        7a:30:18:37:cd:34:17:dd:ac:9d:9e:48:db:74:07:79:84:21:
        5a:f0:26:cd:21:64:7b:77:33:48:58:67:9b:2c:b2:85:6d:cc:
        ec:31:4b:2f:51:55:3a:85:e1:ca:04:15:ce:6e:47:39:f5:e9:
        31:45:41:ed:71:c6:4f:96:f5:ae:64:6a:bd:72:d0:8c:17:02:
        99:10:1d:14:34:ca:e5:47:e3:f7:66:96:96:11:d5:97:76:76:
        83:f1:84:a5:b6:00:5e:3e:67:97:7a:32:dc:c8:eb:4c:29:46:
        77:99:d6:da:45:e6:7b:8c:45:6d:b5:29:6b:fd:98:a2:89:8d:
        0c:30:42:f5:0b:7c:97:c5:b1:1d:e2:da:67:a9:48:a4:9e:29:
        f4:60:3f:4d:1d:48:83:82:38:ef:fa:cb:1d:86:11:a1:15:94:
        fb:d5:ee:68:f9:44:b9:3d:54:70:f3:be:17:8d:d7:2e:85:2d:
        5c:d0:a0:c5:99:52:cc:79:e7:1c:18:d9:6e:3d:0f:6c:05:51:
        33:28:35:e2:02:59:5f:1f:ed:78:0a:c6:62:f0:7d:fe:73:96:
        03:4c:b4:42:e3:00:c2:d7:cb:eb:51:10:c4:0c:64:b8:37:fe:
        85:d0:8e:11:6d:a6:16:77:b1:1e:01:d9:1e:f3:10:9c:dd:01:
        bc:38:75:5e:8f:58:9e:5b:6c:7b:0a:41:08:59:35:a9:3a:83:
        19:e0:7d:a1:f5:cf:a3:1c:4e:07:e1:ad:03:95:f2:d3:8b:79:
        33:f8:52:22:53:1b:1e:32:9a:61:3f:c4:7c:9a:e8:d5:b5:28:
        f1:84:65:d5:c1:fc:4d:16:93:88:93:69:ca:fa:94:a0:95:4e:
        23:ae:1e:60:e0:e8:b4:bf:ff:16:95:71:0f:31:74:bb:be:b8:
        5a:eb:24:95:8b:95:28:13:cd:e3:a9:65:f7:f5:6e:9b:a9:a9:
        7a:05:ce:ab:f0:54:62:d9:12:f8:a1:1a:68:df:af:15:8f:8a:
        df:67:27:c9:ed:bd:e1:81:a6:8d:9a:84:f3:91:36:d9:89:74:
        8e:ef:84:dc:5c:03:1a:08:e4:d7:f0:72:fc:6d:8a:01:34:94:
        e5:ff:08:51:1b:80:5f:e7:07:d8:9f:25:e4:1d:c3:f8:e5:d0:
        9c:50:cf:66:71:f9:cc:f7:c0:a7:d0:66:01:b7:17:a0:5f:66:
        97:a4:ff:62:ac:1c:a0:63:0d:30:28:e9:90:d5:59:a4:48:d8:
        07:87:02:4b:3f:68:23:a5:04:dc:b3:d7:45:f6:dc:b0:ec:c6:
        90:a6:1c:a1:f8:7e:84:ba:63:7e:5a:64:14:78:58:f5:75:c0:
        f5:e1:1d:bd:49:57:c0:40:08:07:99:7f:43:2e:e2:25:d8:ed:
        a3:1a:e3:78:f1:78:af:02:49:54:36:59:8e:d3:72:a5:0b:52:
        32:bd:17:a2:cf:e1:47:21:28:3d:ba:b6:24:d9:18:f9:44:73:
        35:ed:29:a4:18:bc:ed:68:cd:4a:9a:34:cb:1a:2f:b3:5f:ba:
        73:9b:18:ee:7a:a8:92:25:65:25:81:04:63:1c:22:2b:b8:ba:
        81:21:bc:f9:9d:a8:78:98:75:bc:ed:4a:c6:b7:6f:c0:91:24:
        eb:1d:f9:5d:e0:e3:78:4e:05:f6:34:0f:7b:41:54:49:20:a2:
        30:66:94:f1:da:c1:6c:3f:5e:10:92:92:a3:0c:7e:e8:8b:26:
        11:1c:d7:68:c9:31:79:b3:a4:d5:63:00:68:c3:e3:86:2d:09:
        92:4b:2d:63:7d:b8:03:a4:4c:60:b4:2c:12:d5:0b:9f:16:28:
        ea:88:2f:bb:1c:19:0b:0f:40:3d:67:e8:0b:fa:c6:e3:39:44:
        b2:bd:8a:3f:21:dd:aa:ec:a3:8c:48:dd:4c:99:43:86:d7:48:
        81:6b:e5:b9:bb:59:9f:1c:0f:3f:11:f7:7c:4b:67:a8:95:c2:
        7c:cb:3b:66:b0:79:a6:55:6f:6d:b0:29:8a:5e:7b:ee:30:68:
        f3:dd:41:29:91:f6:79:71:ae:8d:21:70:78:1d:5d:d2:f7:cf:
        e7:42:38:d1:8c:52:a6:a6:f6:b1:38:b1:2b:23:81:e1:1f:21:
        6d:99:3f:10:eb:b1:a9:73:b8:3e:31:99:cc:dd:2b:df:58:27:
        db:0b:5a:29:99:8f:b1:9f:e9:31:42:d0:26:db:53:b7:7e:30:
        41:95:c3:f0:07:83:bb:b0:63:b5:16:48:f2:a6:60:2f:32:5d:
        22:a1:da:76:4e:37:26:53:0d:95:7b:2d:b9:05:2f:93:2b:d4:
        df:c1:02:5b:f7:a5:a2:4f:11:5c:80:f4:f0:bd:c7:ea:3c:db:
        6f:e2:eb:6c:7f:c3:58:d9:31:77:4b:4d:f7:ce:bb:d6:c8:64:
        a3:01:d5:f9:a4:8d:e8:f0:ee:09:06:2c:0b:3c:ac:0a:57:d8:
        e4:81:79:ea:4a:bd:51:03:88:4c:d0:4c:0b:c4:0c:7e:2d:e7:
        df:1b:67:62:c0:d1:9c:ad:bb:d3:f0:75:dd:83:aa:70:99:2c:
        19:78:3d:26:2b:47:6f:24:c1:60:02:1e:4b:75:04:91:1f:08:
        1c:b3:79:a0:9b:db:fb:5d:3f:c7:e3:09:1f:41:3e:64:bb:ad:
        19:3d:35:e1:a6:f4:69:0b:a2:04:37:42:95:c6:c7:e5:f4:56:
        0e:67:5b:78:34:bb:07:f1:8f:e7:73:5b:87:d7:df:c9:2d:8d:
        8c:42:76:87:15:85:4b:23:03:20:34:e1:1b:f6:0c:1e:84:53:
        d9:1b:4e:d9:31:43:38:3b:88:12:84:d8:2a:38:b1:ce:0f:c7:
        07:d4:63:2d:97:89:1c:b3:44:99:eb:d4:df:32:74:be:0d:63:
        11:22:fd:fa:8e:e2:0b:56:12:56:0c:46:16:ad:44:10:26:98:
        dc:cf:c9:95:67:3e:11:c1:76:fa:b8:12:ea:96:f6:d9:91:ac:
        bf:49:b9:1c:8e:15:05:53:ac:9e:04:d2:5b:b8:87:bf:81:50:
        f7:02:a4:c0:9c:18:0f:45:ac:7a:82:cf:46:15:42:40:09:32:
        89:a5:ea:90:a5:99:68:f9:93:0c:7b:d6:7a:a8:e9:51:e2:90:
        9e:b9:ed:21:db:d9:7e:de:dc:62:6b:44:6b:9f:81:c5:77:39:
        8e:1d:78:30:de:dc:53:80:e0:c3:fa:fa:94:68:28:91:98:86:
        ff:86:04:a9:bd:58:7c:31:37:1f:db:9a:29:f3:c1:48:10:20:
        71:5f:fc:35:13:eb:7b:12:e2:7d:1c:cc:97:fe:8f:5c:a2:dd:
        f6:d2:a3:b2:ea:51:b3:ef:b1:1e:79:0b:00:53:f4:f2:52:75:
        5a:d7:17:c5:31:a0:54:4e:2b:28:2c:4f:6b:7a:27:3a:2c:04:
        da:b3:1d:04:4e:a4:4e:94:5c:a8:91:70:ab:c0:4b:75:9f:b3:
        6a:a9:4e:8a:22:e9:7f:fd:ec:53:e7:6a:6d:32:0b:8b:ab:4c:
        e7:7d:72:ec:04:62:1c:1a:45:1e:33:8e:37:ae:6a:2f:c8:fb:
        f3:69:ed:11:01:f3:f4:57:e9:29:d5:3b:0c:9c:0c:c4:cb:c3:
        38:5c:01:e7:d6:31:c3:d8:ce:24:d7:be:71:9b:c8:96:13:ca:
        5c:5d:e4:92:40:af:86:a0:4b:ff:a7:55:39:70:fd:ac:0a:e1:
        87:c7:01:4b:c3:41:36:c6:c6:33:8f:4f:25:4a:8d:70:92:ac:
        7c:95:cc:49:a9:dc:d6:6a:67:52:a5:5b:7f:2f:bb:91:e3:be:
        d6:28:fc:22:d0:72:66:e8:09:73:a7:23:c6:a6:89:38:0b:e5:
        d0:b3:f1:40:38:9c:4d:17:96:11:17:44:ef:e3:94:51:91:4c:
        5d:fe:d9:ed:c3:76:a0:2d:3b:dc:8d:b9:31:15:f6:75:58:74:
        2f:57:b4:29:21:29:6d:5f:eb:06:71:0a:f4:db:ff:c6:2f:16:
        73:a7:76:6b:d0:5b:a7:21:5c:fd:f0:11:e8:6f:9b:d0:c9:c9:
        fe:35:76:4a:4a:63:9b:ba:48:ac:af:4f:91:67:9c:5c:47:d8:
        e3:2d:03:12:5e:f1:cb:56:34:75:69:95:ad:68:96:6c:e7:4a:
        91:72:fb:9b:ba:e8:92:56:fb:9a:5b:5d:3b:9d:d3:c5:c4:52:
        42:1b:f9:4a:47:42:dd:77:49:da:2b:bd:d7:94:5f:7b:b8:64:
        b9:06:32:7c:ea:d1:36:f6:95:b8:57:41:1b:6e:66:31:2c:ee:
        87:7a:5c:19:2f:d8:95:4a:16:93:48:f3:97:25:3d:24:61:1e:
        d0:63:37:ee:3a:c9:a3:46:c5:94:a0:7e:24:cc:7f:72:8d:14:
        9e:3c:33:ec:cd:9a:dd:b5:08:90:98:19:95:85:38:ff:ff:d2:
        1e:bf:a6:c4:97:13:2b:3d:47:e9:57:59:d3:7d:99:01:6e:53:
        4d:c0:82:97:fb:89:d6:7c:b7:23:0e:7d:6e:23:88:53:06:8f:
        16:ff:40:0a:1b:cd:d5:1e:91:01:3e:77:3a:5f:c1:57:3a:7b:
        c6:d5:51:d7:e2:ec:89:12:6b:9d:03:e4:9d:bb:7d:4e:02:bf:
        67:8d:03:ca:90:56:f0:9a:97:4b:02:2d:4c:31:89:82:76:97:
        fe:2f:d5:0a:3d:ea:0d:38:6c:30:75:5f:ae:91:53:d7:45:64:
        df:ba:0b:22:80:44:85:6d:0e:5c:29:7f:82:9e:54:a3:7a:95:
        be:96:79:66:9d:5b:a2:d6:2e:47:c6:99:7d:2b:32:dc:f2:b6:
        02:91:6d:63:d4:93:45:60:c4:42:71:10:9e:fb:90:2f:e6:75:
        71:ce:78:70:c1:da:ff:e1:47:fe:79:2b:8e:9a:81:bf:dd:02:
        e3:78:39:71:17:b3:23:14:11:9d:29:8e:21:a1:98:b0:ac:03:
        5a:6c:9e:62:64:ef:4f:03:ca:37:a6:ed:e4:78:d5:0d:99:29:
        f5:5c:61:e6:48:cb:97:0e:5e:f9:2c:f6:b6:c7:7c:0c:a4:f7:
        1a:f7:67:b5:5c:03:bf:bf:7a:e2:4d:a2:9b:5d:5d:5f:51:d0:
        d6:52:8f:2a:20:68:08:bb:f0:9c:05:0e:ef:b3:49:0c:2a:1d:
        8f:f9:03:b7:61:09:71:88:7d:e2:8c:e4:b8:ac:98:1b:c3:80:
        55:a1:6b:dd:13:a2:29:4f:93:93:d3:d5:01:31:3f:7b:39:0e:
        3a:57:6c:eb:5c:6a:5f:1b:ad:97:bd:97:23:18:91:05:0e:2b:
        b4:b1:11:ee:f8:58:c7:08:d0:de:a2:3e:ba:54:8d:3d:63:da:
        91:50:3a:24:8d:19:18:23:2e:cf:30:8d:5d:e3:e7:02:93:fa:
        c8:f8:ea:05:e6:eb:06:80:90:4d:15:58:3d:26:98:13:4b:b0:
        ac:dd:90:2e:d0:e1:eb:71:32:83:5d:2a:a9:b9:b5:24:fc:e9:
        ec:18:ca:c9:a1:05:59:3e:fa:af:ed:4e:86:b1:fe:40:47:9b:
        42:77:af:9c:2b:a0:e2:3e:fd:51:ab:02:77:e8:f1:39:45:aa:
        54:b6:14:d4:14:20:fc:36:81:e6:04:98:8a:a0:c0:8a:cf:ae:
        f6:b5:dc:b7:eb:26:86:d3:cf:1c:38:65:54:04:b1:b5:09:48:
        f5:2d:07:ba:f8:eb:49:bd:d9:b1:54:ea:ac:c2:0d:20:10:79:
        c1:cb:e9:dc:2d:ff:55:50:4f:f6:05:02:78:31:33:6f:15:7e:
        24:5a:66:23:70:b3:b2:0c:17:39:ce:15:38:c5:ff:60:16:38:
        60:74:72:c9:70:d8:59:b7:80:7f:da:f6:67:3f:d0:ba:be:1b:
        a1:87:da:92:2d:a3:6c:99:29:57:aa:cb:d1:8d:66:f1:2d:c9:
        56:60:24:56:4b:19:9f:f5:65:84:89:86:7d:4d:8b:f8:5b:60:
        dd:af:2d:66:76:6c:66:d9:c6:f5:39:25:6c:e5:7b:43:97:64:
        5c:c5:20:1e:3d:b5:dc:92:b2:9c:d8:1b:1b:e0:bc:44:7b:9c:
        95:c5:53:48:91:b2:a5:46:16:bf:50:af:a5:44:cc:54:78:3f:
        ed:20:d8:2e:0b:41:3d:f1:04:9d:df:3c:4a:d7:81:04:ff:8c:
        b7:79:f8:51:8d:b7:2e:ac:2c:54:e6:fc:43:76:8e:f9:be:8c:
        b8:5c:ad:c4:13:af:b0:6e:3b:d1:82:57:1e:f5:52:84:ca:cc:
        d2:68:f3:2d:04:ff:27:0a:e6:a2:fa:c0:a9:97:d6:64:45:18:
        5c:6f:9e:c1:64:22:66:db:56:02:c3:a8:57:fc:87:1b:5c:43:
        15:8e:58:fc:f2:00:0b:4f:6a:4b:a0:5c:da:f2:e5:1b:82:4a:
        6b:ef:db:63:d7:7d:93:1d:2f:20:78:37:17:22:82:cd:6b:c1:
        83:61:05:81:99:0c:25:29:d6:5f:22:bc:06:67:7d:67
]]></artwork>
      <artwork><![CDATA[
-----BEGIN CERTIFICATE-----
MIILSDCCAW+gAwIBAgIUVH5kcCmeA8V6pVx40SeHjFQ1F10wCgYIKwYBBQUHBiIw
NTELMAkGA1UEBhMCRlIxDjAMBgNVBAcMBVBhcmlzMRYwFAYDVQQKDA1Cb2d1cyBY
TVNTIENBMB4XDTI0MDcxMDA4MjcyNFoXDTM0MDcwODA4MjcyNFowNTELMAkGA1UE
BhMCRlIxDjAMBgNVBAcMBVBhcmlzMRYwFAYDVQQKDA1Cb2d1cyBYTVNTIENBMFMw
CgYIKwYBBQUHBiIDRQAAAAABK+u/ZhTeb5ZbTSpQAHutXCKwE3lyAhSpX/yW4Jt4
jta+jBxwPNjdeLIaFEe+Hw10cj82dsLLGa0pkAuC3pt/36NjMGEwHQYDVR0OBBYE
FGLONaVHd/8hhy68LSfnjvQ1a8/YMB8GA1UdIwQYMBaAFGLONaVHd/8hhy68LSfn
jvQ1a8/YMA8GA1UdEwEB/wQFMAMBAf8wDgYDVR0PAQH/BAQDAgEGMAoGCCsGAQUF
BwYiA4IJxQAAAAAA5YiouHOtTZL4XIHFimNXaqc7VKq2BorZ8cILyCceS6LP4tpE
6ujyQKi5VJxJNhIk33St5SnvT9qIDSFdO2RjJ9CEtZV6MBg3zTQX3aydnkjbdAd5
hCFa8CbNIWR7dzNIWGebLLKFbczsMUsvUVU6heHKBBXObkc59ekxRUHtccZPlvWu
ZGq9ctCMFwKZEB0UNMrlR+P3ZpaWEdWXdnaD8YSltgBePmeXejLcyOtMKUZ3mdba
ReZ7jEVttSlr/ZiiiY0MMEL1C3yXxbEd4tpnqUiknin0YD9NHUiDgjjv+ssdhhGh
FZT71e5o+US5PVRw874XjdcuhS1c0KDFmVLMeeccGNluPQ9sBVEzKDXiAllfH+14
CsZi8H3+c5YDTLRC4wDC18vrURDEDGS4N/6F0I4RbaYWd7EeAdke8xCc3QG8OHVe
j1ieW2x7CkEIWTWpOoMZ4H2h9c+jHE4H4a0DlfLTi3kz+FIiUxseMpphP8R8mujV
tSjxhGXVwfxNFpOIk2nK+pSglU4jrh5g4Oi0v/8WlXEPMXS7vrha6ySVi5UoE83j
qWX39W6bqal6Bc6r8FRi2RL4oRpo368Vj4rfZyfJ7b3hgaaNmoTzkTbZiXSO74Tc
XAMaCOTX8HL8bYoBNJTl/whRG4Bf5wfYnyXkHcP45dCcUM9mcfnM98Cn0GYBtxeg
X2aXpP9irBygYw0wKOmQ1VmkSNgHhwJLP2gjpQTcs9dF9tyw7MaQphyh+H6EumN+
WmQUeFj1dcD14R29SVfAQAgHmX9DLuIl2O2jGuN48XivAklUNlmO03KlC1IyvRei
z+FHISg9urYk2Rj5RHM17SmkGLztaM1KmjTLGi+zX7pzmxjueqiSJWUlgQRjHCIr
uLqBIbz5nah4mHW87UrGt2/AkSTrHfld4ON4TgX2NA97QVRJIKIwZpTx2sFsP14Q
kpKjDH7oiyYRHNdoyTF5s6TVYwBow+OGLQmSSy1jfbgDpExgtCwS1QufFijqiC+7
HBkLD0A9Z+gL+sbjOUSyvYo/Id2q7KOMSN1MmUOG10iBa+W5u1mfHA8/Efd8S2eo
lcJ8yztmsHmmVW9tsCmKXnvuMGjz3UEpkfZ5ca6NIXB4HV3S98/nQjjRjFKmpvax
OLErI4HhHyFtmT8Q67Gpc7g+MZnM3SvfWCfbC1opmY+xn+kxQtAm21O3fjBBlcPw
B4O7sGO1FkjypmAvMl0iodp2TjcmUw2Vey25BS+TK9TfwQJb96WiTxFcgPTwvcfq
PNtv4utsf8NY2TF3S033zrvWyGSjAdX5pI3o8O4JBiwLPKwKV9jkgXnqSr1RA4hM
0EwLxAx+LeffG2diwNGcrbvT8HXdg6pwmSwZeD0mK0dvJMFgAh5LdQSRHwgcs3mg
m9v7XT/H4wkfQT5ku60ZPTXhpvRpC6IEN0KVxsfl9FYOZ1t4NLsH8Y/nc1uH19/J
LY2MQnaHFYVLIwMgNOEb9gwehFPZG07ZMUM4O4gShNgqOLHOD8cH1GMtl4kcs0SZ
69TfMnS+DWMRIv36juILVhJWDEYWrUQQJpjcz8mVZz4RwXb6uBLqlvbZkay/Sbkc
jhUFU6yeBNJbuIe/gVD3AqTAnBgPRax6gs9GFUJACTKJpeqQpZlo+ZMMe9Z6qOlR
4pCeue0h29l+3txia0Rrn4HFdzmOHXgw3txTgODD+vqUaCiRmIb/hgSpvVh8MTcf
25op88FIECBxX/w1E+t7EuJ9HMyX/o9cot320qOy6lGz77EeeQsAU/TyUnVa1xfF
MaBUTisoLE9reic6LATasx0ETqROlFyokXCrwEt1n7NqqU6KIul//exT52ptMguL
q0znfXLsBGIcGkUeM443rmovyPvzae0RAfP0V+kp1TsMnAzEy8M4XAHn1jHD2M4k
175xm8iWE8pcXeSSQK+GoEv/p1U5cP2sCuGHxwFLw0E2xsYzj08lSo1wkqx8lcxJ
qdzWamdSpVt/L7uR477WKPwi0HJm6AlzpyPGpok4C+XQs/FAOJxNF5YRF0Tv45RR
kUxd/tntw3agLTvcjbkxFfZ1WHQvV7QpISltX+sGcQr02//GLxZzp3Zr0FunIVz9
8BHob5vQycn+NXZKSmObukisr0+RZ5xcR9jjLQMSXvHLVjR1aZWtaJZs50qRcvub
uuiSVvuaW107ndPFxFJCG/lKR0Ldd0naK73XlF97uGS5BjJ86tE29pW4V0EbbmYx
LO6HelwZL9iVShaTSPOXJT0kYR7QYzfuOsmjRsWUoH4kzH9yjRSePDPszZrdtQiQ
mBmVhTj//9Iev6bElxMrPUfpV1nTfZkBblNNwIKX+4nWfLcjDn1uI4hTBo8W/0AK
G83VHpEBPnc6X8FXOnvG1VHX4uyJEmudA+Sdu31OAr9njQPKkFbwmpdLAi1MMYmC
dpf+L9UKPeoNOGwwdV+ukVPXRWTfugsigESFbQ5cKX+CnlSjepW+lnlmnVui1i5H
xpl9KzLc8rYCkW1j1JNFYMRCcRCe+5Av5nVxznhwwdr/4Uf+eSuOmoG/3QLjeDlx
F7MjFBGdKY4hoZiwrANabJ5iZO9PA8o3pu3keNUNmSn1XGHmSMuXDl75LPa2x3wM
pPca92e1XAO/v3riTaKbXV1fUdDWUo8qIGgIu/CcBQ7vs0kMKh2P+QO3YQlxiH3i
jOS4rJgbw4BVoWvdE6IpT5OT09UBMT97OQ46V2zrXGpfG62XvZcjGJEFDiu0sRHu
+FjHCNDeoj66VI09Y9qRUDokjRkYIy7PMI1d4+cCk/rI+OoF5usGgJBNFVg9JpgT
S7Cs3ZAu0OHrcTKDXSqpubUk/OnsGMrJoQVZPvqv7U6Gsf5AR5tCd6+cK6DiPv1R
qwJ36PE5RapUthTUFCD8NoHmBJiKoMCKz672tdy36yaG088cOGVUBLG1CUj1LQe6
+OtJvdmxVOqswg0gEHnBy+ncLf9VUE/2BQJ4MTNvFX4kWmYjcLOyDBc5zhU4xf9g
FjhgdHLJcNhZt4B/2vZnP9C6vhuhh9qSLaNsmSlXqsvRjWbxLclWYCRWSxmf9WWE
iYZ9TYv4W2Ddry1mdmxm2cb1OSVs5XtDl2RcxSAePbXckrKc2Bsb4LxEe5yVxVNI
kbKlRha/UK+lRMxUeD/tINguC0E98QSd3zxK14EE/4y3efhRjbcurCxU5vxDdo75
voy4XK3EE6+wbjvRglce9VKEyszSaPMtBP8nCuai+sCpl9ZkRRhcb57BZCJm21YC
w6hX/IcbXEMVjlj88gALT2pLoFza8uUbgkpr79tj132THS8geDcXIoLNa8GDYQWB
mQwlKdZfIrwGZ31n
-----END CERTIFICATE-----
]]></artwork>
    </section>
    <section anchor="xmssmt-x509-v3-certificate-example">
      <name>XMSS^MT X.509 v3 Certificate Example</name>
      <t>This section shows a self-signed X.509 v3 certificate using XMSS^MT.</t>
      <artwork><![CDATA[
Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number:
            5c:22:ad:8a:06:51:9e:67:02:6a:2d:43:3e:8b:c7:23:
            43:77:80:c8
        Signature Algorithm: xmssmt
        Issuer: C = FR, L = Paris, O = Bogus XMSSMT CA
        Validity
            Not Before: Jul 10 08:28:04 2024 GMT
            Not After : Jul  8 08:28:04 2034 GMT
        Subject: C = FR, L = Paris, O = Bogus XMSSMT CA
        Subject Public Key Info:
            Public Key Algorithm: xmssmt
                xmssmt public key:
                PQ key material:
                    00:00:00:01:4b:a7:89:11:6f:fc:1d:fb:d3:e7:71:
                    73:b8:a2:48:ef:53:b9:9d:1f:c6:8a:7c:be:4f:8a:
                    29:fa:41:fd:bd:da:20:7f:f6:3b:b0:c5:b8:a7:c2:
                    f2:5a:f2:26:14:eb:36:f0:26:2f:87:74:fb:0e:d5:
                    7e:17:a0:d1:4d:b6:cf:51
        X509v3 extensions:
            X509v3 Subject Key Identifier:
                7C:7D:59:B8:95:61:D5:03:6A:1E:3D:F1:24:AB:1D:ED:
                04:CD:DB:5F
            X509v3 Authority Key Identifier:
                7C:7D:59:B8:95:61:D5:03:6A:1E:3D:F1:24:AB:1D:ED:
                04:CD:DB:5F
            X509v3 Basic Constraints: critical
                CA:TRUE
            X509v3 Key Usage: critical
                Certificate Sign, CRL Sign
    Signature Algorithm: xmssmt
    Signature Value:
        00:00:00:57:c4:98:89:ff:d9:0a:8e:6e:6f:16:95:8c:ec:35:
        42:21:c2:ca:56:ed:f8:81:f1:b2:4f:2b:6d:73:f4:37:55:fc:
        f4:4e:15:eb:6b:90:de:34:fe:d6:96:70:94:8d:c1:e7:4a:32:
        49:30:3a:40:a4:67:d2:fb:da:f8:d8:a1:7a:48:22:1c:e3:98:
        bc:d0:68:85:29:c9:e5:f7:5c:56:d8:9c:80:be:68:ed:11:eb:
        39:0f:ef:cb:09:b2:28:30:a6:2b:05:bc:de:11:22:be:c4:dc:
        08:9a:3d:b4:49:37:1f:54:5e:5f:2d:93:62:b0:95:c5:5d:23:
        92:f3:55:40:78:19:00:56:9e:a2:f1:0e:4b:ae:75:d6:92:09:
        b1:79:ec:c9:18:67:19:09:86:83:74:5d:0a:06:ab:da:f0:af:
        02:97:4d:d7:73:06:8b:a2:84:c7:09:af:dd:8b:15:39:e4:30:
        9f:c9:00:25:a8:33:4d:de:e8:25:b6:35:0b:51:bf:7a:34:a7:
        e8:84:e8:fa:39:5b:aa:37:6e:95:89:ac:26:4a:4e:ca:be:29:
        08:4b:3c:28:a7:85:6a:ad:5a:d2:93:eb:12:e1:9a:87:1c:40:
        3b:cf:15:6c:43:4e:88:21:54:52:7e:0d:6d:17:29:8d:15:6f:
        ef:42:5a:a9:25:d0:97:80:61:31:22:a4:9f:25:17:51:ad:0b:
        a1:cb:93:b4:f5:a6:b0:22:1b:6d:50:64:2a:48:bd:05:16:88:
        00:e3:7b:56:d0:03:b3:7a:2d:6a:0b:f3:de:a2:8c:6e:81:80:
        2c:8f:e9:d8:78:ed:5b:99:c9:13:d1:b6:eb:78:c3:40:2b:a1:
        7a:84:0a:ba:12:87:5e:1d:38:24:22:8f:c0:a3:65:1c:1c:ce:
        2d:8e:e5:2f:1f:be:93:5c:fe:1c:cd:a8:9d:7e:7e:cf:18:e2:
        9c:c5:54:dc:62:61:74:23:55:64:66:21:96:4c:a7:2e:8a:94:
        a6:35:10:a5:e8:5e:6e:91:ac:a8:cb:ed:51:2b:66:45:03:f5:
        87:ed:4d:8c:4e:6d:54:80:a1:33:8a:84:9d:23:31:90:c6:05:
        11:a7:9d:bd:51:0a:73:47:bc:08:49:11:b3:98:ff:01:14:69:
        d7:c0:a0:0c:55:e4:5e:e2:fa:84:ac:27:b3:85:2c:99:71:52:
        9c:33:f8:9d:8c:d2:13:bc:6e:18:79:15:a7:02:ee:15:eb:27:
        d8:af:24:38:02:9c:ca:30:f3:e2:30:41:2f:62:a2:2c:a5:81:
        1b:71:6d:b1:94:bd:c6:3d:9e:5e:51:45:de:5b:f4:d7:e6:35:
        e7:d8:7c:d5:98:ec:7e:0e:f8:9d:c1:a7:7b:b3:65:b1:a1:4b:
        2d:ec:d9:12:45:6b:1f:0b:1c:6b:3b:0a:66:76:39:f4:cc:9b:
        e1:b7:17:f7:53:fc:c3:a6:18:f7:2e:45:52:b1:18:99:75:d1:
        69:bb:77:c8:1a:84:5f:06:b5:8b:cb:02:b0:b2:0f:bf:17:18:
        65:3d:a7:72:5b:71:9f:92:7e:3a:df:84:cc:65:5c:c4:5b:70:
        fd:cc:38:9e:12:6e:f9:ff:1f:02:fc:ca:f5:68:86:fc:ca:71:
        f1:3d:7b:32:b4:d4:c3:a2:20:16:3f:12:07:71:95:3b:d4:b1:
        1e:fc:8c:1f:34:8c:c8:ab:8c:bb:75:93:c1:1a:d2:85:3e:9a:
        e6:04:86:88:de:27:46:ca:f3:f7:f3:8e:54:18:ea:aa:ae:14:
        02:b1:4a:6a:e0:24:77:40:28:8d:37:27:9c:87:6a:81:09:d2:
        01:4d:20:7f:de:84:a8:80:8c:8e:63:82:be:66:df:87:30:5c:
        b8:71:0a:e9:91:68:71:6e:97:97:f0:27:4e:fa:ae:6a:85:ac:
        80:cd:38:48:49:c1:2b:9d:db:54:c5:f0:bf:fa:06:e8:96:3a:
        c0:95:f0:88:bd:8e:80:78:3d:dc:ad:5d:0a:56:dd:c7:80:9f:
        fc:64:58:4d:6d:27:f6:d7:1a:8c:b2:1c:09:ea:7d:4f:74:99:
        0d:4a:0c:b8:b0:ef:74:dd:6f:6f:dc:e5:83:e1:e3:c2:e8:58:
        17:b8:44:8a:2d:ec:df:54:f6:1f:67:a2:b3:c5:19:fb:b9:c7:
        1b:3c:ea:bd:2c:e1:43:65:d1:5a:17:dc:93:9d:c5:85:0c:55:
        34:13:49:15:92:e2:52:14:d1:81:aa:62:02:1a:ba:c9:b0:53:
        85:8e:7b:d1:4e:34:76:ac:79:d7:b3:48:92:bf:55:7e:2d:5c:
        cd:32:9b:c1:41:a7:a3:cd:b7:94:5c:96:1e:3e:27:4d:eb:f0:
        61:4b:a4:e3:3c:bb:69:85:37:e9:9c:98:f4:68:7a:61:77:8c:
        bd:b9:30:d6:f1:fd:69:78:3f:96:99:7b:69:39:90:b3:7c:b6:
        88:ed:cd:19:da:42:64:e5:32:4c:a2:30:f7:c4:e8:27:93:70:
        ed:fa:5e:ca:8e:7a:d1:13:af:15:b1:59:c9:9b:91:61:0b:06:
        d5:cc:2e:80:bb:49:93:dd:be:53:88:be:af:80:64:7c:5e:be:
        7b:8b:e7:5f:39:af:ab:67:42:6b:06:aa:ef:d6:69:af:a9:00:
        1f:a0:15:10:04:3e:db:93:b2:37:db:eb:85:59:43:a2:8d:8f:
        06:8c:cb:a2:1d:a8:3c:9f:f4:a4:7c:c8:cd:ff:f0:a8:79:0f:
        e7:d8:94:67:ec:17:3f:fa:6e:04:07:4f:bf:86:04:6c:fc:46:
        87:b5:10:85:a4:07:e8:af:a9:ec:5d:28:5c:80:8c:31:cc:c7:
        b3:81:17:0b:4b:7d:1c:9e:74:02:1e:ef:de:0d:1b:c1:c0:04:
        4d:46:fd:dc:0b:a4:c6:33:e6:85:0a:60:39:4d:0b:f9:49:44:
        33:e0:15:99:19:bf:c7:8a:c6:96:04:93:37:6b:5d:e8:be:73:
        d4:80:b8:81:0f:9a:91:44:cf:72:02:d3:c9:f8:e0:7d:d2:9b:
        2b:ff:eb:42:6e:38:7e:dc:cd:a7:90:c5:2c:2b:a0:23:37:b9:
        64:10:a6:27:68:47:c5:f1:e8:8d:41:c1:49:e8:35:48:ce:c8:
        08:4c:ad:f2:ad:5d:e9:62:eb:c9:3c:61:85:18:c6:34:73:fd:
        26:a4:f0:50:83:9b:64:54:aa:55:6c:d8:a2:21:81:ff:9c:27:
        39:1f:c3:a2:0e:e5:53:b1:d7:fa:1f:ef:29:8b:c2:90:98:ea:
        2e:dd:45:bf:c3:6c:a3:93:47:99:03:18:25:e8:a5:ee:2e:77:
        eb:7f:f4:49:49:59:98:c1:fc:ab:1e:ad:20:bd:f8:24:fd:21:
        1b:da:5a:07:55:c8:50:05:31:50:93:b2:f8:6e:db:73:4d:5f:
        34:aa:f3:34:83:90:f0:41:6d:c8:43:56:d1:75:07:f5:16:20:
        b3:99:b2:c7:34:25:c4:0e:74:5a:51:0f:7b:3b:7f:6a:a9:41:
        17:b5:47:62:2d:4f:b9:61:97:60:e9:ae:ca:ad:31:6e:4b:0a:
        47:9c:53:66:a3:4e:c3:96:7c:01:a0:8e:ae:83:45:42:e6:92:
        12:8e:97:6f:e8:a0:b7:7d:a6:74:24:aa:20:b0:fa:9e:98:e8:
        7c:b4:da:30:e9:94:08:96:b7:b9:53:4f:75:5f:0c:4d:82:e3:
        cf:6e:bc:fa:23:4f:fa:33:17:7c:98:b6:1e:47:89:3e:d9:a1:
        aa:42:19:25:ae:9e:3f:53:44:ac:91:96:d8:55:c3:40:1d:fa:
        ad:86:38:62:bd:27:2f:26:34:be:ad:9a:01:44:42:c8:54:a5:
        3a:e9:0a:ff:f8:41:6d:38:1e:e2:3d:08:3a:94:4f:1e:60:d0:
        b1:c2:8e:94:34:f0:30:3e:f0:91:25:ee:98:34:b4:8d:95:4e:
        cf:ed:1d:61:89:c9:59:10:68:f2:bc:2e:5c:bd:c0:0f:1d:9c:
        2f:7c:c0:27:25:14:9b:de:a3:74:64:28:14:2c:a2:b2:90:3a:
        a4:6a:50:e9:8e:ca:78:e5:b6:74:56:e0:92:69:7d:b4:2e:e0:
        e7:66:92:16:92:a0:c3:db:4f:d3:d0:57:4d:4a:28:ee:b7:cc:
        04:ef:17:d9:fc:01:bb:1e:b2:5b:02:3d:1f:5a:85:73:a1:81:
        96:b7:33:5d:79:e5:6b:c9:29:73:34:01:69:ea:57:f0:01:be:
        4e:f3:5c:f3:0a:a7:37:08:ad:18:9c:c7:4c:59:d0:5d:bb:01:
        f1:53:76:cb:cd:d9:84:5e:bc:22:11:76:01:d9:e3:af:17:03:
        01:ef:38:4c:ad:c1:7d:a9:c6:61:2b:ba:9c:81:95:86:af:bb:
        73:90:dc:d9:2f:d1:3f:95:6a:b9:46:0f:fb:84:64:7c:7d:86:
        65:aa:10:71:56:19:5f:60:52:7f:19:fa:d5:5a:e0:90:e4:b9:
        62:55:71:2a:61:f9:37:2f:5e:07:71:43:cf:06:ca:6a:d5:52:
        c8:33:e1:ad:b2:3e:a4:61:01:00:bc:55:5d:0a:f3:e6:4f:35:
        06:c4:a8:3f:4c:8b:9b:c9:41:4b:f4:c1:57:ee:3c:c0:44:68:
        52:5a:2d:b9:a7:f2:41:da:c4:8d:7d:db:40:b6:fc:47:63:5a:
        69:a1:c7:8c:cc:3f:af:51:94:37:95:58:82:79:d2:16:4a:bf:
        12:0b:59:a5:a5:11:71:e6:1c:63:3b:ea:f0:2f:10:e0:97:9a:
        a1:04:53:d0:72:f4:3c:77:3b:78:ee:b5:aa:6b:f5:bb:5c:e9:
        35:4f:69:65:87:29:24:ec:47:7b:78:5a:a7:c1:e5:f1:73:7d:
        4d:79:ef:ef:4e:75:87:db:8f:36:fd:50:3e:74:dc:17:d4:c3:
        3f:4f:82:24:51:1b:12:16:26:61:db:93:15:19:39:55:f5:05:
        2c:6e:85:dd:b2:cc:4f:c0:09:0a:76:46:d8:e4:f2:11:92:a1:
        e0:36:a8:25:c7:45:19:6c:98:eb:9a:fa:c1:ec:80:18:ce:d1:
        f8:c4:23:9a:f9:b8:1f:05:67:8e:45:cb:e6:ee:0b:fa:db:67:
        1f:62:2c:49:78:bb:55:98:1e:33:42:63:f2:db:ee:73:f7:60:
        80:6d:5f:9a:e8:8c:89:39:5b:b2:84:e2:c3:99:77:f3:5f:19:
        ec:b8:2b:ce:60:59:2c:66:06:f9:c1:43:b9:fd:94:35:9e:28:
        9d:a0:8e:fd:0d:c6:1a:bb:20:93:b0:63:6a:83:2f:0a:db:c2:
        b3:8e:b1:dd:f5:ab:19:09:53:7a:db:72:3f:1e:25:07:eb:1a:
        7d:21:da:88:22:e6:f0:ba:b3:15:6f:95:f3:72:d2:cb:6d:48:
        b8:ba:7b:aa:40:7f:81:fe:ba:15:c2:77:9d:86:58:bc:7d:89:
        2e:7b:3a:96:04:9f:f1:3a:50:48:5a:25:4d:91:b6:ed:de:f6:
        2e:4d:e5:77:11:6d:76:f4:23:5f:91:f0:0f:79:59:7a:f3:32:
        24:11:c4:88:30:21:26:3b:f1:79:0f:04:06:ad:82:6d:ea:58:
        4e:aa:4e:0a:7f:7b:5c:a5:ab:de:76:a9:a9:c7:d9:e3:eb:d6:
        84:80:02:ab:da:4c:5b:49:90:29:c5:cb:5b:1c:06:61:e8:9a:
        cf:a4:ea:9d:31:16:6a:21:3a:d9:22:25:b8:39:9d:4c:e3:86:
        76:a8:dd:d8:b4:db:88:f9:5e:61:c3:1d:87:df:a9:31:33:7a:
        b3:50:3e:f2:cd:ad:a0:9d:98:5f:6c:e2:f0:d8:27:b9:c2:37:
        7f:8d:b4:f8:84:13:5f:22:6d:9b:81:bd:1c:e5:75:ae:b5:95:
        d1:cb:d0:c6:e3:78:ec:8c:71:6d:8c:5d:40:79:7d:58:3d:5c:
        63:77:cc:2e:a2:63:a9:71:30:2f:59:2a:ec:82:b1:e5:b9:d6:
        bf:fb:21:e6:97:fc:70:45:9a:c7:e8:d2:81:73:b1:f5:bc:76:
        ca:b4:be:9f:39:b5:2d:f2:3e:c5:32:e3:ae:3c:fd:74:a1:36:
        5a:5c:4d:f6:de:d2:d5:66:61:74:88:2e:4b:69:7c:29:2f:e0:
        2a:d6:d8:93:99:41:bc:7b:7f:fc:c3:1c:84:ed:16:c0:08:78:
        fb:57:61:9e:83:7a:d1:e9:b7:ad:9a:85:1c:c3:ba:a3:e4:18:
        b6:00:f6:35:27:e2:27:1d:10:dc:44:1d:11:05:a2:db:df:0a:
        59:98:9c:f3:ca:3a:b3:26:2d:d1:c4:3c:fc:21:f3:3c:39:62:
        7f:f4:bd:91:74:ef:02:83:da:4a:22:40:60:9f:6a:9f:8b:8f:
        f1:e4:1e:99:d5:17:55:62:1c:60:01:7d:c7:41:db:19:9e:29:
        01:ba:a0:5f:41:f3:61:ed:9d:0c:9c:ef:32:8b:b0:8a:89:b1:
        e4:06:c9:2f:4d:42:2a:01:84:29:ac:f1:41:a0:a1:c9:b4:83:
        d9:87:1a:53:1f:7f:d4:85:12:2e:79:f3:2c:88:06:73:62:ee:
        16:bc:c7:8b:e7:09:96:ba:02:b5:56:ab:6f:c0:cf:76:64:62:
        0e:1e:b5:e4:69:42:4d:ed:56:96:d9:1d:8d:07:40:7a:c5:bd:
        d3:9f:43:07:e4:9d:b6:26:2b:33:6a:79:d9:8a:ec:ee:51:73:
        f1:91:b0:e8:90:42:db:11:55:57:1b:01:10:fc:11:ff:77:b4:
        09:01:6d:f8:8c:cf:72:16:df:09:12:09:bd:49:ef:33:b9:c5:
        8d:35:60:77:80:8f:ee:98:18:be:bb:3a:61:e9:5b:6a:09:b0:
        0a:1e:38:80:e9:71:46:77:a1:19:7a:c3:04:57:a5:77:e6:5a:
        01:77:d2:92:90:f6:99:50:87:3f:30:8a:37:3d:37:1e:6b:1d:
        a4:71:3c:6b:15:07:01:f6:3d:43:96:a3:f7:30:cf:08:2c:32:
        a3:ca:67:6e:59:da:51:2e:96:bc:97:41:4b:7c:5f:97:a3:cf:
        46:20:9e:64:96:08:f7:0c:03:4b:b4:83:09:db:6c:bb:94:23:
        4e:ff:7b:fb:2f:84:66:0a:96:f9:e1:58:ff:0d:3c:84:62:9c:
        6b:60:9f:7e:39:cf:33:f3:03:2f:c7:d0:8b:6f:f3:9a:62:cc:
        33:c4:bd:b4:fc:b8:80:9d:fe:9e:c2:f0:d0:9e:07:71:a8:f9:
        1f:a7:64:4d:63:f9:6b:ce:3e:44:0a:3f:05:58:90:0d:0c:20:
        7d:4e:c7:52:d0:e5:b7:61:d3:6a:52:08:37:91:15:3c:cf:41:
        ec:ef:88:56:dc:14:2a:12:55:cb:05:01:23:89:c0:fe:ca:de:
        40:d2:d0:96:a3:1f:07:4a:58:96:fa:b2:ef:78:96:f0:73:25:
        c8:2e:20:3b:d8:02:cf:e7:ca:b0:29:1a:25:7f:15:96:2d:fd:
        52:bb:29:c3:fc:bf:b1:7c:d8:0f:76:21:05:28:2e:89:d9:82:
        0e:cb:cd:03:1f:c3:71:b4:0f:75:52:e5:b4:93:8c:ac:ed:d5:
        30:5a:b9:33:84:fd:3c:da:dc:e6:84:6d:c2:66:be:93:ad:67:
        7f:db:d0:08:95:64:5a:2c:13:7f:e2:05:b5:dc:d0:bf:4d:6e:
        93:c2:3b:8c:3b:b1:5c:3a:28:e8:c3:96:ed:59:e2:62:52:8e:
        95:8d:b5:e1:c1:f2:34:5b:bf:5a:cc:f1:ee:ec:3d:6c:61:99:
        f2:c8:e4:05:5f:ea:d5:74:3c:ff:df:1b:20:bd:35:30:c0:27:
        f8:a4:6e:73:45:81:e2:b9:15:52:c7:a0:e7:c8:fd:7b:8e:f7:
        d2:0c:c4:e9:22:69:4e:70:62:c7:8a:a2:a6:61:7c:0b:5a:74:
        8d:0f:c0:e5:66:dc:18:7b:74:3b:72:ab:1a:53:b3:49:ef:50:
        aa:76:80:e7:11:53:90:ab:24:d1:2e:fc:66:41:cf:b3:cc:ae:
        ac:f9:eb:1e:19:f7:bc:54:00:16:da:b0:d4:2b:74:c7:35:fb:
        08:ff:67:14:83:5a:eb:6b:b7:b4:63:28:e2:b6:b8:d4:0c:13:
        6a:8c:bb:30:c1:fb:6c:42:df:23:c4:f0:be:25:df:2b:39:11:
        bb:82:c3:e7:f9:04:48:77:cf:d0:5e:3d:6e:19:7f:b3:c4:2f:
        c4:ec:51:5f:9d:c7:8f:88:9f:21:79:8d:a0:17:3e:17:73:b4:
        f5:a2:71:70:e6:99:c4:fd:4c:f2:63:64:23:22:c3:72:71:52:
        43:42:a5:90:e3:59:77:50:ff:a1:09:2e:c7:f6:7e:17:f2:a2:
        d6:7e:2c:75:f2:ab:9e:36:78:ab:57:be:c5:91:71:70:2c:ba:
        03:91:80:97:f4:9e:16:bc:fa:80:f4:22:2a:b5:75:15:57:d9:
        b0:92:9e:b1:35:db:26:96:77:28:9c:89:99:db:9b:55:d4:29:
        15:5f:54:8a:0d:58:a8:95:13:95:17:6c:6b:b0:2a:a3:fa:1a:
        ec:2e:b4:0e:08:ea:8f:e1:8c:59:cf:7d:60:00:f3:bf:b7:e4:
        5f:08:a6:02:ef:ce:d7:9c:8d:6f:56:d7:c9:35:e9:e5:cf:d2:
        f5:28:ca:e6:36:ef:c4:26:52:d5:4d:04:ec:50:73:87:dc:70:
        1f:1a:db:07:bf:4c:e9:ec:57:98:7f:bc:c8:31:9e:7e:e6:3a:
        b4:c4:77:93:39:56:57:67:05:84:8d:03:02:d9:bf:04:6b:fe:
        71:8a:be:b6:8a:ae:44:b0:dd:db:1f:6a:26:e5:50:d5:ff:03:
        81:d8:1b:9f:3f:a6:bc:1b:52:b5:49:93:b0:27:fd:59:d4:7d:
        69:e9:63:35:0b:9b:de:a1:d4:70:0c:08:41:4b:76:d6:cd:c8:
        65:8c:bb:9a:6e:e4:f1:e2:30:13:9d:a3:c7:67:16:0f:7d:bd:
        ac:dc:aa:9c:17:01:a6:27:14:fa:4a:c1:27:3f:07:7b:9f:2f:
        47:56:cc:f0:96:38:e9:58:7c:1f:6c:73:10:3c:11:68:2a:3c:
        5f:74:fe:37:ae:8b:e9:eb:c6:06:30:6f:62:3c:5c:6c:2d:c7:
        5b:24:6d:cc:75:3f:d7:d4:e6:72:64:8a:ad:03:67:ad:cd:cb:
        2d:7c:82:49:a9:ef:e8:b9:be:f2:6c:98:42:4e:26:46:04:58:
        a5:2b:c9:88:9b:a4:91:7f:22:09:12:52:2a:d1:4e:36:22:d8:
        53:bc:38:93:ad:11:19:c5:e7:c9:83:00:b4:b6:b0:ac:96:32:
        ca:d0:08:69:e4:d2:29:86:74:74:49:be:4a:b2:bf:f2:2f:c2:
        52:fd:15:3c:8d:07:12:3a:98:c7:49:67:81:1d:b1:5d:e8:f4:
        42:79:a0:f7:44:b8:95:9f:e1:37:41:5b:c9:b1:89:90:7b:66:
        96:eb:8e:dc:1b:d7:73:b2:eb:c1:42:41:e8:2d:28:ba:74:ea:
        7c:77:87:76:5b:36:10:3d:87:08:52:94:e6:60:95:c1:1b:c9:
        27:c1:42:aa:32:62:ed:ca:6f:04:4e:11:3a:3d:3d:e0:d8:3a:
        c0:ff:b9:9a:94:b1:79:f3:01:14:3a:99:34:59:8e:d9:ac:f1:
        a9:77:b5:2d:59:e1:29:96:1b:13:80:8b:10:94:3e:c2:51:db:
        c1:24:06:02:47:96:9b:ae:5d:25:34:af:4b:65:f3:8a:eb:65:
        7c:a5:5e:7c:a2:d6:1d:41:20:13:0b:5e:ea:67:b2:eb:bf:6c:
        44:fb:76:31:58:5e:d2:33:6d:6f:9c:3a:41:70:34:11:6f:99:
        8c:42:9d:d6:2b:14:79:b0:ac:d4:de:3a:b0:d8:d2:97:88:9a:
        17:68:3e:79:a8:b0:4a:d7:a7:3c:63:c5:29:c1:65:76:74:7e:
        c2:de:b8:49:ce:26:5f:d2:62:2d:0f:5c:cc:6c:53:c0:a4:75:
        05:52:d1:52:38:ae:72:17:7c:02:67:6b:76:38:e7:72:aa:38:
        70:5e:af:a2:98:c0:c1:7a:a0:6d:ec:90:51:8d:d5:99:8b:39:
        05:6a:eb:0c:87:37:5b:4b:00:91:2c:7d:8a:6d:c1:23:10:44:
        26:5a:47:f7:7f:8f:86:1c:c2:a7:9f:9e:48:f6:42:cd:d1:3c:
        d9:e8:95:de:00:3c:ec:db:a1:a3:c0:7f:f7:17:3b:4a:dc:d2:
        f5:d4:9b:12:19:0f:6d:13:38:72:06:21:eb:94:88:87:8f:a1:
        de:f6:d7:a0:88:aa:e3:47:bb:69:e8:30:59:82:d2:3a:6d:c7:
        26:95:92:a4:58:07:eb:db:a5:d1:bb:51:00:28:ef:6f:c8:ce:
        9c:0f:d9:8d:e0:b3:14:db:90:dd:f9:26:af:b0:88:48:ae:22:
        71:26:af:d5:e0:4d:5c:41:e6:0b:f2:5c:9b:bb:69:82:09:5a:
        58:63:b9:0c:8a:22:37:aa:a2:71:2a:a5:d9:a7:7b:9f:d5:f4:
        17:8d:bd:4e:de:08:6a:a4:20:ce:a6:85:c7:fa:05:c7:d8:03:
        77:0c:dd:40:32:11:43:2a:8c:50:22:4b:fa:a1:d1:f1:94:42:
        3f:d5:b8:a0:dd:01:71:6e:30:34:ff:a6:76:80:e6:c1:04:8b:
        f0:c3:38:14:98:ae:eb:fd:05:98:d1:96:7e:b4:bf:51:ce:aa:
        b4:66:71:30:9f:7a:45:b6:ed:d1:6e:8f:b0:6c:a5:f5:4f:ee:
        bc:ea:65:5e:24:43:73:4b:50:8e:c8:68:0f:23:48:ed:dd:ff:
        84:97:9b:31:0d:bb:2c:db:69:6b:0c:34:73:3e:ae:69:d2:f5:
        be:a8:99:be:7b:40:82:f4:fe:35:f5:3d:a3:b1:b4:e2:6c:79:
        b7:0b:29:ad:30:3d:56:9d:bc:24:e9:e6:a5:6d:cc:83:18:7b:
        d5:98:a3:5f:dd:71:72:29:71:45:8f:41:52:ce:86:99:5c:f1:
        40:0c:1e:b1:97:da:3a:14:4a:a7:02:48:d8:4e:63:12:99:da:
        28:e9:de:0d:17:90:3a:f5:da:9a:01:7c:15:12:bf:00:48:7d:
        63:8c:89:0b:b9:77:95:01:27:b2:33:73:4b:ab:a8:f3:24:ee:
        c1:d3:0c:a3:9e:26:fe:24:23:3b:82:b4:1a:5e:72:dc:9e:91:
        3a:7b:85:64:0d:30:2e:6b:55:53:7e:a2:4f:b7:10:e4:77:a1:
        01:4a:b2:d7:7f:1c:94:a6:a7:e5:66:e2:c7:e5:37:6d:89:2c:
        72:b1:53:cf:d6:67:0f:77:f8:bf:07:20:98:99:60:ef:2e:72:
        c0:72:9e:79:2a:ca:a2:f7:bc:82:db:53:f7:68:e3:ed:4f:38:
        64:83:1b:dd:a5:78:dc:db:08:a9:34:35:f6:f1:9c:76:85:5e:
        cd:59:a3:c8:89:50:5b:bd:a0:64:06:b4:d7:db:7a:e1:75:57:
        13:90:ce:05:4b:a0:f6:22:70:0b:78:a0:84:46:87:b4:a7:0d:
        88:c6:41:c5:93:cb:77:37:d1:af:37:48:b9:47:db:99:7a:98:
        36:82:cb:27:6a:9a:de:80:24:3a:29:eb:ab:bd:b0:40:0d:a6:
        50:e5:a4:72:a3:19:cb:f3:52:8e:2f:1d:10:ef:7d:0a:15:6c:
        49:08:53:55:84:85:5c:73:53:ce:3e:18:e5:04:92:a6:99:db:
        4d:7b:c7:a9:99:ce:aa:90:48:73:7a:61:f5:92:73:da:b4:26:
        74:a1:39:74:e3:82:f9:32:e0:08:ef:bc:2f:9f:6d:e1:da:3d:
        f0:a5:46:b6:17:95:b8:6b:13:7d:f3:a1:31:8d:b7:47:a0:45:
        aa:20:53:d6:f0:3c:eb:a2:e7:7a:26:8c:c6:c7:cb:0f:21:5a:
        df:46:06:c5:b2:2d:a5:3b:b7:01:fd:0f:55:1b:5e:58:00:70:
        94:a3:7f:48:8e:4a:67:a4:14:5d:e0:ba:b6:f9:9b:e7:de:61:
        d8:67:83:ac:b7:01:eb:62:c5:22:b8:48:3a:96:55:fb:1a:4a:
        c4:63:30:f3:78:05:a6:ab:0c:e7:33:a0:88:f7:e2:e3:4a:1b:
        fd:66:3c:14:be:ee:20:d1:32:95:db:97:ff:d9:c2:bc:7a:c8:
        e4:ba:24:c5:b2:2e:16:f8:53:af:b4:57:56:25:26:f5:36:48:
        eb:0c:20:f9:3b:73:ff:dd:bd:20:81:0c:f5:55:89:7d:46:1b:
        05:b6:25:df:96:99:ea:09:79:60:72:d8:37:92:a8:f1:75:a3:
        5c:6d:54:b7:f3:32:17:35:1a:2d:96:e5:5e:fc:cd:54:30:49:
        af:6f:1a:42:d9:98:52:72:73:74:72:b7:72:95:80:1d:31:5a:
        e4:83:b7:b6:d4:14:00:0b:59:ce:7c:bc:1d:72:24:ab:74:d6:
        2c:9c:20:b1:0a:78:6f:a9:76:8d:6c:37:02:35:bd:6f:99:ee:
        d1:45:36:f1:34:60:7a:12:57:27:68:05:26:14:75:3c:9f:0d:
        3e:b7:5d:b8:2a:6c:1d:a7:b0:41:c4:f4:3d:ae:8e:51:54:37:
        65:ad:0a:c9:28:a0:3f:04:ed:54:59:c4:9f:1d:3d:70:97:5f:
        f9:44:53:ff:15:9f:03:13:7b:41:6b:c0:f7:8f:a3:27:2b:03:
        39:37:8f:bd:91:65:4d:74:a9:9f:45:6a:a4:25:dc:4c:f9:7e:
        59:fc:4e:93:7c:89:8f:71:8e:a6:99:66:5e:6a:25:a4:c0:a6:
        fa:25:f7:68:5c:8a:02:f5:7b:49:cd:89:e1:77:78:95:1b:a9:
        21:78:6e:f4:7a:e2:04:e5:0e:21:52:bf:04:cd:0c:69:5d:d7:
        f2:57:71:9f:d8:01:e0:f3:10:cc:15:2d:fd:99:78:ff:dc:1f:
        8f:a9:31:0d:0f:9f:f4:2c:a1:3d:4f:b2:51:92:68:f0:ec:d8:
        5f:c4:55:a1:4c:c8:12:e9:05:7e:05:93:5f:f9:76:99:85:18:
        29:24:60:14:5d:b3:79:f9:4b:7c:e4:22:71:8a:c2:66:45:d2:
        41:14:5d:59:4c:0a:b5:2b:ab:bd:c6:50:f8:87:37:42:e6:d4:
        96:72:cf:45:f0:d4:bf:0d:c5:17:9f:f1:b9:12:5c:a8:74:89:
        9e:56:07:cf:8f:98:9a:da:d7:db:7f:c7:d0:3a:0a:14:cd:5a:
        66:0c:eb:02:76:a0:d4:56:e6:e8:be:a1:f0:c7:23:b3:4f:86:
        90:1a:5a:16:8e:07:0d:24:d1:ee:03:98:9f
]]></artwork>
      <artwork><![CDATA[
-----BEGIN CERTIFICATE-----
MIIU6zCCAXOgAwIBAgIUXCKtigZRnmcCai1DPovHI0N3gMgwCgYIKwYBBQUHBiMw
NzELMAkGA1UEBhMCRlIxDjAMBgNVBAcMBVBhcmlzMRgwFgYDVQQKDA9Cb2d1cyBY
TVNTTVQgQ0EwHhcNMjQwNzEwMDgyODA0WhcNMzQwNzA4MDgyODA0WjA3MQswCQYD
VQQGEwJGUjEOMAwGA1UEBwwFUGFyaXMxGDAWBgNVBAoMD0JvZ3VzIFhNU1NNVCBD
QTBTMAoGCCsGAQUFBwYjA0UAAAAAAUuniRFv/B370+dxc7iiSO9TuZ0fxop8vk+K
KfpB/b3aIH/2O7DFuKfC8lryJhTrNvAmL4d0+w7Vfheg0U22z1GjYzBhMB0GA1Ud
DgQWBBR8fVm4lWHVA2oePfEkqx3tBM3bXzAfBgNVHSMEGDAWgBR8fVm4lWHVA2oe
PfEkqx3tBM3bXzAPBgNVHRMBAf8EBTADAQH/MA4GA1UdDwEB/wQEAwIBBjAKBggr
BgEFBQcGIwOCE2QAAAAAV8SYif/ZCo5ubxaVjOw1QiHCylbt+IHxsk8rbXP0N1X8
9E4V62uQ3jT+1pZwlI3B50oySTA6QKRn0vva+NihekgiHOOYvNBohSnJ5fdcVtic
gL5o7RHrOQ/vywmyKDCmKwW83hEivsTcCJo9tEk3H1ReXy2TYrCVxV0jkvNVQHgZ
AFaeovEOS6511pIJsXnsyRhnGQmGg3RdCgar2vCvApdN13MGi6KExwmv3YsVOeQw
n8kAJagzTd7oJbY1C1G/ejSn6ITo+jlbqjdulYmsJkpOyr4pCEs8KKeFaq1a0pPr
EuGahxxAO88VbENOiCFUUn4NbRcpjRVv70JaqSXQl4BhMSKknyUXUa0LocuTtPWm
sCIbbVBkKki9BRaIAON7VtADs3otagvz3qKMboGALI/p2HjtW5nJE9G263jDQCuh
eoQKuhKHXh04JCKPwKNlHBzOLY7lLx++k1z+HM2onX5+zxjinMVU3GJhdCNVZGYh
lkynLoqUpjUQpehebpGsqMvtUStmRQP1h+1NjE5tVIChM4qEnSMxkMYFEaedvVEK
c0e8CEkRs5j/ARRp18CgDFXkXuL6hKwns4UsmXFSnDP4nYzSE7xuGHkVpwLuFesn
2K8kOAKcyjDz4jBBL2KiLKWBG3FtsZS9xj2eXlFF3lv01+Y159h81Zjsfg74ncGn
e7NlsaFLLezZEkVrHwscazsKZnY59Myb4bcX91P8w6YY9y5FUrEYmXXRabt3yBqE
Xwa1i8sCsLIPvxcYZT2ncltxn5J+Ot+EzGVcxFtw/cw4nhJu+f8fAvzK9WiG/Mpx
8T17MrTUw6IgFj8SB3GVO9SxHvyMHzSMyKuMu3WTwRrShT6a5gSGiN4nRsrz9/OO
VBjqqq4UArFKauAkd0AojTcnnIdqgQnSAU0gf96EqICMjmOCvmbfhzBcuHEK6ZFo
cW6Xl/AnTvquaoWsgM04SEnBK53bVMXwv/oG6JY6wJXwiL2OgHg93K1dClbdx4Cf
/GRYTW0n9tcajLIcCep9T3SZDUoMuLDvdN1vb9zlg+HjwuhYF7hEii3s31T2H2ei
s8UZ+7nHGzzqvSzhQ2XRWhfck53FhQxVNBNJFZLiUhTRgapiAhq6ybBThY570U40
dqx517NIkr9Vfi1czTKbwUGno823lFyWHj4nTevwYUuk4zy7aYU36ZyY9Gh6YXeM
vbkw1vH9aXg/lpl7aTmQs3y2iO3NGdpCZOUyTKIw98ToJ5Nw7fpeyo560ROvFbFZ
yZuRYQsG1cwugLtJk92+U4i+r4BkfF6+e4vnXzmvq2dCawaq79Zpr6kAH6AVEAQ+
25OyN9vrhVlDoo2PBozLoh2oPJ/0pHzIzf/wqHkP59iUZ+wXP/puBAdPv4YEbPxG
h7UQhaQH6K+p7F0oXICMMczHs4EXC0t9HJ50Ah7v3g0bwcAETUb93AukxjPmhQpg
OU0L+UlEM+AVmRm/x4rGlgSTN2td6L5z1IC4gQ+akUTPcgLTyfjgfdKbK//rQm44
ftzNp5DFLCugIze5ZBCmJ2hHxfHojUHBSeg1SM7ICEyt8q1d6WLryTxhhRjGNHP9
JqTwUIObZFSqVWzYoiGB/5wnOR/Dog7lU7HX+h/vKYvCkJjqLt1Fv8Nso5NHmQMY
Jeil7i5363/0SUlZmMH8qx6tIL34JP0hG9paB1XIUAUxUJOy+G7bc01fNKrzNIOQ
8EFtyENW0XUH9RYgs5myxzQlxA50WlEPezt/aqlBF7VHYi1PuWGXYOmuyq0xbksK
R5xTZqNOw5Z8AaCOroNFQuaSEo6Xb+igt32mdCSqILD6npjofLTaMOmUCJa3uVNP
dV8MTYLjz268+iNP+jMXfJi2HkeJPtmhqkIZJa6eP1NErJGW2FXDQB36rYY4Yr0n
LyY0vq2aAURCyFSlOukK//hBbTge4j0IOpRPHmDQscKOlDTwMD7wkSXumDS0jZVO
z+0dYYnJWRBo8rwuXL3ADx2cL3zAJyUUm96jdGQoFCyispA6pGpQ6Y7KeOW2dFbg
kml9tC7g52aSFpKgw9tP09BXTUoo7rfMBO8X2fwBux6yWwI9H1qFc6GBlrczXXnl
a8kpczQBaepX8AG+TvNc8wqnNwitGJzHTFnQXbsB8VN2y83ZhF68IhF2AdnjrxcD
Ae84TK3BfanGYSu6nIGVhq+7c5Dc2S/RP5VquUYP+4RkfH2GZaoQcVYZX2BSfxn6
1VrgkOS5YlVxKmH5Ny9eB3FDzwbKatVSyDPhrbI+pGEBALxVXQrz5k81BsSoP0yL
m8lBS/TBV+48wERoUlotuafyQdrEjX3bQLb8R2NaaaHHjMw/r1GUN5VYgnnSFkq/
EgtZpaURceYcYzvq8C8Q4JeaoQRT0HL0PHc7eO61qmv1u1zpNU9pZYcpJOxHe3ha
p8Hl8XN9TXnv7051h9uPNv1QPnTcF9TDP0+CJFEbEhYmYduTFRk5VfUFLG6F3bLM
T8AJCnZG2OTyEZKh4DaoJcdFGWyY65r6weyAGM7R+MQjmvm4HwVnjkXL5u4L+ttn
H2IsSXi7VZgeM0Jj8tvuc/dggG1fmuiMiTlbsoTiw5l3818Z7LgrzmBZLGYG+cFD
uf2UNZ4onaCO/Q3GGrsgk7BjaoMvCtvCs46x3fWrGQlTettyPx4lB+safSHaiCLm
8LqzFW+V83LSy21IuLp7qkB/gf66FcJ3nYZYvH2JLns6lgSf8TpQSFolTZG27d72
Lk3ldxFtdvQjX5HwD3lZevMyJBHEiDAhJjvxeQ8EBq2CbepYTqpOCn97XKWr3nap
qcfZ4+vWhIACq9pMW0mQKcXLWxwGYeiaz6TqnTEWaiE62SIluDmdTOOGdqjd2LTb
iPleYcMdh9+pMTN6s1A+8s2toJ2YX2zi8NgnucI3f420+IQTXyJtm4G9HOV1rrWV
0cvQxuN47IxxbYxdQHl9WD1cY3fMLqJjqXEwL1kq7IKx5bnWv/sh5pf8cEWax+jS
gXOx9bx2yrS+nzm1LfI+xTLjrjz9dKE2WlxN9t7S1WZhdIguS2l8KS/gKtbYk5lB
vHt//MMchO0WwAh4+1dhnoN60em3rZqFHMO6o+QYtgD2NSfiJx0Q3EQdEQWi298K
WZic88o6syYt0cQ8/CHzPDlif/S9kXTvAoPaSiJAYJ9qn4uP8eQemdUXVWIcYAF9
x0HbGZ4pAbqgX0HzYe2dDJzvMouwiomx5AbJL01CKgGEKazxQaChybSD2YcaUx9/
1IUSLnnzLIgGc2LuFrzHi+cJlroCtVarb8DPdmRiDh615GlCTe1WltkdjQdAesW9
059DB+SdtiYrM2p52Yrs7lFz8ZGw6JBC2xFVVxsBEPwR/3e0CQFt+IzPchbfCRIJ
vUnvM7nFjTVgd4CP7pgYvrs6YelbagmwCh44gOlxRnehGXrDBFeld+ZaAXfSkpD2
mVCHPzCKNz03HmsdpHE8axUHAfY9Q5aj9zDPCCwyo8pnblnaUS6WvJdBS3xfl6PP
RiCeZJYI9wwDS7SDCdtsu5QjTv97+y+EZgqW+eFY/w08hGKca2CffjnPM/MDL8fQ
i2/zmmLMM8S9tPy4gJ3+nsLw0J4Hcaj5H6dkTWP5a84+RAo/BViQDQwgfU7HUtDl
t2HTalIIN5EVPM9B7O+IVtwUKhJVywUBI4nA/sreQNLQlqMfB0pYlvqy73iW8HMl
yC4gO9gCz+fKsCkaJX8Vli39Urspw/y/sXzYD3YhBSguidmCDsvNAx/DcbQPdVLl
tJOMrO3VMFq5M4T9PNrc5oRtwma+k61nf9vQCJVkWiwTf+IFtdzQv01uk8I7jDux
XDoo6MOW7VniYlKOlY214cHyNFu/Wszx7uw9bGGZ8sjkBV/q1XQ8/98bIL01MMAn
+KRuc0WB4rkVUseg58j9e4730gzE6SJpTnBix4qipmF8C1p0jQ/A5WbcGHt0O3Kr
GlOzSe9QqnaA5xFTkKsk0S78ZkHPs8yurPnrHhn3vFQAFtqw1Ct0xzX7CP9nFINa
62u3tGMo4ra41AwTaoy7MMH7bELfI8TwviXfKzkRu4LD5/kESHfP0F49bhl/s8Qv
xOxRX53Hj4ifIXmNoBc+F3O09aJxcOaZxP1M8mNkIyLDcnFSQ0KlkONZd1D/oQku
x/Z+F/Ki1n4sdfKrnjZ4q1e+xZFxcCy6A5GAl/SeFrz6gPQiKrV1FVfZsJKesTXb
JpZ3KJyJmdubVdQpFV9Uig1YqJUTlRdsa7Aqo/oa7C60Dgjqj+GMWc99YADzv7fk
XwimAu/O15yNb1bXyTXp5c/S9SjK5jbvxCZS1U0E7FBzh9xwHxrbB79M6exXmH+8
yDGefuY6tMR3kzlWV2cFhI0DAtm/BGv+cYq+toquRLDd2x9qJuVQ1f8Dgdgbnz+m
vBtStUmTsCf9WdR9aeljNQub3qHUcAwIQUt21s3IZYy7mm7k8eIwE52jx2cWD329
rNyqnBcBpicU+krBJz8He58vR1bM8JY46Vh8H2xzEDwRaCo8X3T+N66L6evGBjBv
YjxcbC3HWyRtzHU/19TmcmSKrQNnrc3LLXyCSanv6Lm+8myYQk4mRgRYpSvJiJuk
kX8iCRJSKtFONiLYU7w4k60RGcXnyYMAtLawrJYyytAIaeTSKYZ0dEm+SrK/8i/C
Uv0VPI0HEjqYx0lngR2xXej0Qnmg90S4lZ/hN0FbybGJkHtmluuO3BvXc7LrwUJB
6C0ounTqfHeHdls2ED2HCFKU5mCVwRvJJ8FCqjJi7cpvBE4ROj094Ng6wP+5mpSx
efMBFDqZNFmO2azxqXe1LVnhKZYbE4CLEJQ+wlHbwSQGAkeWm65dJTSvS2Xziutl
fKVefKLWHUEgEwte6mey679sRPt2MVhe0jNtb5w6QXA0EW+ZjEKd1isUebCs1N46
sNjSl4iaF2g+eaiwStenPGPFKcFldnR+wt64Sc4mX9JiLQ9czGxTwKR1BVLRUjiu
chd8Amdrdjjncqo4cF6vopjAwXqgbeyQUY3VmYs5BWrrDIc3W0sAkSx9im3BIxBE
JlpH93+PhhzCp5+eSPZCzdE82eiV3gA87Nuho8B/9xc7StzS9dSbEhkPbRM4cgYh
65SIh4+h3vbXoIiq40e7aegwWYLSOm3HJpWSpFgH69ul0btRACjvb8jOnA/ZjeCz
FNuQ3fkmr7CISK4icSav1eBNXEHmC/Jcm7tpgglaWGO5DIoiN6qicSql2ad7n9X0
F429Tt4IaqQgzqaFx/oFx9gDdwzdQDIRQyqMUCJL+qHR8ZRCP9W4oN0BcW4wNP+m
doDmwQSL8MM4FJiu6/0FmNGWfrS/Uc6qtGZxMJ96Rbbt0W6PsGyl9U/uvOplXiRD
c0tQjshoDyNI7d3/hJebMQ27LNtpaww0cz6uadL1vqiZvntAgvT+NfU9o7G04mx5
twsprTA9Vp28JOnmpW3Mgxh71ZijX91xcilxRY9BUs6GmVzxQAwesZfaOhRKpwJI
2E5jEpnaKOneDReQOvXamgF8FRK/AEh9Y4yJC7l3lQEnsjNzS6uo8yTuwdMMo54m
/iQjO4K0Gl5y3J6ROnuFZA0wLmtVU36iT7cQ5HehAUqy138clKan5Wbix+U3bYks
crFTz9ZnD3f4vwcgmJlg7y5ywHKeeSrKove8gttT92jj7U84ZIMb3aV43NsIqTQ1
9vGcdoVezVmjyIlQW72gZAa019t64XVXE5DOBUug9iJwC3ighEaHtKcNiMZBxZPL
dzfRrzdIuUfbmXqYNoLLJ2qa3oAkOinrq72wQA2mUOWkcqMZy/NSji8dEO99ChVs
SQhTVYSFXHNTzj4Y5QSSppnbTXvHqZnOqpBIc3ph9ZJz2rQmdKE5dOOC+TLgCO+8
L59t4do98KVGtheVuGsTffOhMY23R6BFqiBT1vA866LneiaMxsfLDyFa30YGxbIt
pTu3Af0PVRteWABwlKN/SI5KZ6QUXeC6tvmb595h2GeDrLcB62LFIrhIOpZV+xpK
xGMw83gFpqsM5zOgiPfi40ob/WY8FL7uINEylduX/9nCvHrI5LokxbIuFvhTr7RX
ViUm9TZI6wwg+Ttz/929IIEM9VWJfUYbBbYl35aZ6gl5YHLYN5Ko8XWjXG1Ut/My
FzUaLZblXvzNVDBJr28aQtmYUnJzdHK3cpWAHTFa5IO3ttQUAAtZzny8HXIkq3TW
LJwgsQp4b6l2jWw3AjW9b5nu0UU28TRgehJXJ2gFJhR1PJ8NPrdduCpsHaewQcT0
Pa6OUVQ3Za0KySigPwTtVFnEnx09cJdf+URT/xWfAxN7QWvA94+jJysDOTePvZFl
TXSpn0VqpCXcTPl+WfxOk3yJj3GOpplmXmolpMCm+iX3aFyKAvV7Sc2J4Xd4lRup
IXhu9HriBOUOIVK/BM0MaV3X8ldxn9gB4PMQzBUt/Zl4/9wfj6kxDQ+f9CyhPU+y
UZJo8OzYX8RVoUzIEukFfgWTX/l2mYUYKSRgFF2zeflLfOQicYrCZkXSQRRdWUwK
tSurvcZQ+Ic3QubUlnLPRfDUvw3FF5/xuRJcqHSJnlYHz4+YmtrX23/H0DoKFM1a
ZgzrAnag1Fbm6L6h8Mcjs0+GkBpaFo4HDSTR7gOYnw==
-----END CERTIFICATE-----
]]></artwork>
    </section>
    <section numbered="false" anchor="acknowledgments">
      <name>Acknowledgments</name>
      <t>Thanks for Russ Housley, Panos Kampanakis, Michael StJohns and Corey Bonnell for helpful suggestions and reviews.</t>
      <t>This document uses a lot of text from similar documents <xref target="SP800208"/>,
(<xref target="RFC3279"/> and <xref target="RFC8410"/>) as well as <xref target="I-D.draft-ietf-lamps-rfc8708bis"/>. Thanks go to the authors of
those documents. "Copying always makes things easier and less error prone" -
<xref target="RFC8411"/>.</t>
    </section>
  </back>
  <!-- ##markdown-source:
H4sIAAAAAAAAA9S92XbjSJYg+I6vwEQ+tHvLJWJfWF3VxZ2UuIirKGVFRWEx
kOAGCuCqqKzT/9A/MI/T/9BPU38yXzL3XgNJUC6P8IjMrMr29OMhkYDZtbuv
lre3t8Im3CxYXvyhsdqweMU24vhOl2zxcesuQk98YEexsQpiJ9nEW2+zjeHR
wmISxeFmuhQbPlttwiBkcSIGUSzW+33RWfniuNXv/yA4rhuzHSyd/Zieoy1+
EDxnw2CpY15MNr6QbOCZn5xFtII9YDcm/kEcTMNEXLBNIm4T0Y/EwFl5R9HZ
bqLbCVux2NmE0UqMAjFmAYvZymOJEK5jej/ZKJJkS4og+JG3cpawqh87weY2
ZJvgduEs18ntAeC4TaZucivpQrJ1l2GSwIqb4xqeblQGVQHgVwUnZg4AyTxh
H8XzSRxt13mxWWg99sVbsRkuww3zxYLvhwiOsxBbzJs6qzBZcrQ8PjTGhIB+
q9GqCHN2hGV82CBF+W0Z4RJ2bLVleUEUsxvArxyaJ9g5XE3EGn4Jny6dcAEw
rZ1k+Y94orsonsDHTuxNAeXTzWad5HM5fAo/Cnfs7vRUDj/IuXG0T1iOFsj9
gLsCSbcuvEtIAZzkOLrOOPpBEADz0yjOC7fwvCiGqyQvlu/EkbMSa4wlG/qU
o7oM52eLd1/B5nmxFB/Xm6jNDhuxz7wtcNKRvmT8RD69eLdzVhN87x89enwF
j98m6eN3XrTMgvBwJxadZBrGYQaAB2fHplef0+7FfiO72xyfunP5U4Shf5zg
N++36N+J1cV2GrM4s0Xfizabq8/5AcPEi8T+MdmwZZLdLAn4o//o4RMfbFFz
3nxnkt1hwwLE4OVz2gF4f+uItaVbzy7PoadH73z2bumHaJuEfphcLe7s4ii5
/upDJKUPvMePsIriJYjgjri2cVu++0rA4sCzTMlyQ4Di8jM83auWdFuW8+mP
iiXlxT/sVNFj8Rdxp4hevOBfWaotw1eHZZK+Zum6Bh9Mk2RB6O0/WpKkSFae
QN448YRt8uJJAPwoJJ6XpTtDUqxcu9Ef3PUf7+CdW3iJv8NVYI/BoZZs5XOt
gpILKAIKbBdiHTjkFpgJ5LwfTlYOakKg/5QtGcfbSTJE+nOb/jfFf9tJFUNj
lcBm2w1DndVHhefEfkK6YQA6YxUtoslR/IRAfqYlABaATIHz3coAsC0I4SrI
Yh0QoiqmffrR0Mz0R83WTp9amixdfiSct0q1XuXpY5Rttm4Iyj+62y7cu832
FmBcgnL2N8BVudDPsXUcrjaAUdlQ1SwCCVtiy1k5E8DLasNtwgeY+w6UgVpp
ebWY7T/++hE4GhgMtpqnjPvVI+9E9qPvM3L1EQDF7SZcffztPX7rTZfOanVF
J9m4leVbMDqiWKzLxscI5gi8Cx0vJt7E1wCdmnK39oMsQjvROvkiNkQ/9MVw
IzoTJ1yJ/9//+J9nxYls1Fmx20G4ZBn0ituVz2JxsI9uWyxJgBxiYbNxvHly
9+uYb8LR4m2IK4Sr+TdxV//3/71IwCC9Oz78Wmr3C8qd9PHZl8wPHWCkgK0S
djeJdnB6Rcn12TonmfCzpEqmbKla7lbGv1Ku1C/8hCv+BEv+VGjWOr3GoN7q
/3T3WK5mcVVC2Y29EKTsLG5nNF1clv4WjLUIa4mfcFX86bNYOrrgwpwf9ndh
Am4JPNEvfP4N0n3ZDhS0h3J8ev8sxsotGFPJhA8rg37jdtADsVZvDVv5GFv7
/f4OvB+uwny2AKGPc/jBT5sYOEY1JOkn/I9t02+2kpPkO/r7kyHlNjH/UtlJ
Mv5v/Z6/uMAurwU2Oek8PDT6dx7Xh8uzU/PrKKls42jNwHIN2IK06naVLpNk
1N5FG35CbLxDlQyShGal0C7cNlv9byMoBPi5XwPO22SFB0lyCxZOpuA33C5h
40V4m5yFI5fFQPP0WIsey8rQJ9j0O6iP8J3ARAf3Yzg/hBFt2i04NmBymH87
RUXpoqL8FrA/0PpiJX3jY9X6w3eDDN7oLbqmvxGzyTK8XW2XKDHZn+8O081y
8YfMJ7fynXpn3Ml3OvzPvDOujgKbX+Tl7CSf5fQ3HKPQ7vcbH5/BQ7kGJbPd
3QVxLgHJB6cWPKrtYpMLwgX+FnlbPFYuiBaLaP/Tdv3TOkrIj/9p7axZ/BP+
ECWbn163zmqzXf7E/dFJ7Kynx/fyRKCIu5DtExEkBsRHfIR3b7v83dT15e9C
iOKs+E7iJ2B3VeQgiNv1d3AdaRgGjhxXPUz0mbhwxOTf/xeh9N//F3yQiAn4
oP/+/4CLIvr/5ew34H4E6Dt5U29l5VZBkSt+C5/IEy5oIxfsCzoD/SlERn45
8pJcOdqvFpHjJ7lKOwcL5HgAyWU+V4wjbwrcmUuxeJs4Abv9JVR2Mw+K2QfJ
/gUAgIN0cxZgIOHIMWovn+3YIloTm5JPFV95dN+ht4poOBNnCZrw3/83uH8h
eHjxlIHtBcOLJrVxwSK49+CxhXPxU/ErXIKa129lSxBub29Fx4Xg2fE2gkDh
7InlIHZjHgbPAOvZPIWZiBpPUOi372QRaB35GPzxzSmqFJC7vss/FT/1b+vF
/mexDstSMOihsbo8RpGK8AnC9M9fRDZOtUuLxfMF+2o58RNqIXjwFNH/c2sA
v4hLEKrwdhMzJuycGDTHBp0TfOCOh/HpcVNr4qzXCzz6JiIx+Wb2Af3dTPZB
/AR64rO4B8ME70UJMH4IgSuc56IzIQZm4hZRAUS7XliA8GLDgWAcwZkPgF12
UQreIkw24CwR/Zah7y+YIPwBF4sjHyCBRwThtyE/AXdRdBLMkXzhmZAMAgXg
UzdcsRPSEY2JuAeWQPdOfO/efeoMYEU4XRQjUwIO13G0A945YUM4Y0NMUjg2
U2cDJ1yiC0muDhNBXFYclalYigDGGuwxMJ+LosMEZ4cJBHfBkIgsjJFYUczA
KRDP/hLQds8WC+50Jpso8uloPlsDI6EiXBxTbSgkGb8VyU6vLI7I2mj+UK4J
uXdiIeEYg6eOoucgzPGOIQKdlRAu11G8QRZzt+GCJMNdRN6cDMn7s8ChkzCh
p7M6EEAUrjwTcXOOwO5QVBkgNdwhX8wZAUyExNM6YhCu0I30QGMz75SDAqLg
o6CQpqSc6eCOsEjzQ9wq4oNL7pMndC6XEesyjrTN9bb/JeHuGEhXAodlwnaN
OoY/C9YJD4a/BXhOXAZRQeyAtEV6gxxkYbsTxadpiBwG1IjR9wHEZs5w0URr
JwYNS7ywj7YL2ISsk3OFFdgKd4VT7sJ4s4VHjkBTN9qSBvngxJ/A578TlX82
JNAgG1QLiM8NndsDU0kwCAu0O7GYYeLwjdGZF9Fqkj0qCMadWN6ykx45Oa8r
2DBlMiEL8AnHXxMloz9IVFLaeDFDhH/h1BeWhLJVhMRAHQZuLug6WBw5D3EN
0hWiygF9D846yuUmAjYBxNejPRAl/oKPJCBb+LjggdZICCIQl0V0JMNw5rWl
c3y3zx0EMCAVuBN/FXUdmCwvDl3mCyR3YeJtE1RGCwfZArb7+Wd44ZZe4NlO
zOn96U93qNNK0QpZhVxzfL3MiLnJXpIUINowX5mIP7SG/cEPX/h/xXaHfu5V
usNGr1LGn/v1QrN5/kFIn+jXO8Nm+fLT5c1Sp9WqtMv8ZfhUvPpI+KFVeP6B
G5ofOo+DRqddaP6A59lc2VFEAZDfZRzzwPskE4lwxgu+Uyw9/r//t6wBLv6v
XrWkyDIgIP3Fkk0NfkFNyHcjyeW/ov4RgADMIUwChwPi1yF3PEAbJVNwfEDg
YwbY/K9/RMz8mBf/m+utZe0f0g/wwFcfnnB29SHh7OtPvnqZI/GDjz7Y5ozN
q8/fYfoa3sLz1e8nvGc+/G//fYGmCvyb//4PArLQELixRNx40ZKr1JL//IeP
WE8QQL9fkYe8mZN1AJ5MwJrFacQIq/78M5iOcwL4T3/6gvmQMEFLQI/tGJfa
dPflekEBbbqAH5HIcm2IqvAi7KlzsnTmLBH422cdCMpp9V7GedlhcZFAMowi
O4DAgwZb+ano8AzMHnytaQrUleuRSjb3UrDEEWyQh7PeyDoCFwhdpD+mib0f
74RUhxC2kNlJzaYqPgU+i1f3KP7xlB798aTRaE+0o8JkG2JOYcXygvBz/nUb
bdifhH8Q5c8cueKKeai3Y9LzZ5yCCfjK50q9jBMhVyAtQrDFb/5O/Kd/gjWV
zxzmK8KAgwPiNHXQrpNmB7UcMNTpf0diSG+qBA03QaneXZN2RScWtf4ljILf
ELaASkGbr6EUUigjtM4fgAMuCCzPVqkuZj6IdANkPi3sfIGV8E1AI8d11rAg
ckltpHUpdvESzjbm4pWB7riocEo08wW524uGGlF5xTGgaBAFHFtg05gfehv0
zMQYSyUnj+rbBo2QDdg7AQg2LQB1hik8DLIWyJBo4XGVpXMIl+BDfXs156vT
n9YFpA3PZ9ujZvyO031t6USfrDqFOTFbkIwDjMkSVfCHcJ0Pdrby5FjF4EQ5
brjAOhNwCEMfEKh4dkXh1U0ceqmqWZ1fRP+CrcCviSjxASB7i62PsnIrVsN4
uXfiy4Of+qkPJUO4BmBdxO6LOCAqNUb0eZochY/TNwTjzqRvIIr88TOs3Y+C
zfXa31jgjxTF0zulMy4RhgKFuHi2T6XC5ytEc45mDmglzjAnSpGlEyPSpsCP
6JXhpqiTIox6Fvh9ePa8hCxmUkcduOJdEHahSIjSFft0rkw0H3rCEgKqRRqM
OVufvDKXAY3YmRJcxQBIxEHJFFn3Ovjh3i5odiyucj0PJ61xXY1cA/Ybq6df
PmBFBAkVywfeHASfwAL+LfpHgM0sIsHJT3VxqvOCE0vgQZL3NCQcZ6KyTPWa
5BKeZ6Sdl3Rw9DIB7BT1C9BEwBYQji2d1TZwvDTJj7SDCIYHMxSD3QIvOymO
SDBPCYNFOGepRcazES0h/PEvEOISPLrIZHohDlsk5FnjwWKWRvkQGwA6GtFA
hCgxSQudXNQ5ZhdHXoEHKK42uQ6/eZgO3jrnytS0fhHjCMhRKnDLh3WsHy9a
NcNh6I5xfJ3i2QxP4nHCJNkyIWB7oNLVzsCr4INvXeAgsPCw6tVmWZeAR6lZ
A8sPKBDr0OZZvgGQUuA/2DB8v+dVNiIbIEAM9O5R0rBASR4RX5QXRrEXrvIg
8Nq8U2i4VgrTF6I9uCpo9nAXWuoaJLJhhLiESHf7EelIWawAL5xxvhKqVCaE
92fIeDepwl9HSRJiegH9yI8bS5CSj+dglDjlyv//ApwPFjtAn3TF9mKnUeY2
Nc2lUXaBIqyzZ3CKEoVLzj2jaC7+H7D/xfyDJwFLoxrim/k8ssqUuCGGQHrE
bE0xI0UFBIlHMVaIWYE7sQofOCTyBBWCy5VvJuKmqAHCfcdNAF5Ezh+oueYj
DPEoLXJnYE8y+UOeIriQ5KMc47lp5+pQwrtDcQ/Xv8SFJLlfn/Lcg3P3LZDw
KWAX3DHLLIn4L6F/CwDeTpPkdrFMqBYCBPkXMLb/9m//hrnVjx8QxU7xvlIa
iI1ypT1oVBuVnpjP/734c5rWDZPoE7izS4buwq0b+cdP4Iluk0+WJn0W48Tx
k/CTLKu6Zn8W13Mvwafxv/Yn+3O6RrIEh/STbHxGFH4Cd1Q2xT8RWEIbPGZu
+JB+3zrEx6hHC4u6lbAG3hz6Os4FE8vNZYFTAvW4ilbHJb7JWTZ1VoBjlmHa
OnBKezorAXxwEGXqyDjx2jlkJphd5gG/kd7DnoofT1mvDM+ssnKxcxaoFU5i
RSteZe3OfteUqmpnYFAVAM1zzVafMpt3lz3plUyMksoxd0z4hl9Ed4v6nOo9
gK5JCOrtKPzxVBj8ERNhy3DDdXX6/bkxLCO92dz6yWhTjMLli3Kyv0XAUm6m
9z5mZyrwfZOXs99+JyOfd/dvo3gCNvqNDopc6Uf+J+MzT4Gs2AaePvFvais+
6Z8zlh1/W8/Dwyfzc0bh4QqqdmLvvx43EM4yrKDa8p/NCrjmX5IX/rk1+L3s
gK9+myOWm1/micv3f0tcof/HcAWi7m+WMa66Yi8PCkIp6+yBtUe3O03F/zFt
b+P5F/IEjhg9XzDIGeeY+Ug4457b3qzjFK78s1OZ8VXgtzjaTqaIhPOHwuU0
3JX5yBB5mGxLNtxVXJGPQznQdYqRi1sCKHinuM8kutBEjJ29GHkbhm5WzINo
Xr08JeSvXOgL/TMu3Z34xP3L1JiJ/S2JG0c/YB/LsNQX++XkZ159LRYbA7E/
6DXaNYqhnHCVfB9sQiYyvHtfsOWHTNKibKc0qJx3QVi413mu1W6u5ITioxUF
mr98LE7xq8UpGFmvyUcQna9P+8nhYkBnAEAyx/+MmT7eWJDkeWoHqyzk1CND
rTaCG579g6td+ZK8Dph8+KqYeRW2FLIvfknjYHBS/o5XXJjz7bezGwvZLX/x
rcsxLx7yRULT8sV7Z/PaA7sg56yJ1/NbeAc9i1ss7PZBDT8Oi81G6fah8nyl
fjNa+WPX79RkcCviq6so5Zx9DNREFrk9tR88FnoFcI4KvYrIXf7081KlN8Bt
b4f9Qq1y7lUQfz4lN89F4S+w/KrH1ls/dHiyEk6Lagmf+CJ6vSb+IP4pq8W/
9sNPQcBHeHmHlNsL/yFOrihIO1xUxUluflECU/XzDiYeYqJg/gvg9if+zU/w
zb+I556AO7HPWNZAnFUT7Y5CSYF6tvobrQRecsQketotwr/9EI478drVR6gW
jLodvk4vo5uLhc0VFZ1DnpGkwj+v6F+SlwtsWMGcMyHidcsz2jLnZu5YfsXP
X7mb38PQ+NJv5+asg/o3zsofOOG/xMtZfHwfI2es3J/LyIjW38rJtP1HnCyk
QeC3Ofkdaq4d3A/Z6737+r0c1hr8Ph67OLz/B3DZ1779rzHaBS3/Kay23PwH
M9s1hshvxhMPqQ+9CD44R+a5fkmtYN5l6GKTNh2QDuXO7rlEDJ/zdTIusUAt
tDi3dXG27wTyID82y18+jMApY/hREMar/+dw4COnTQDpWPg82VoqpIn2rNd+
Bow7rNmvOMnwTJdzUP4v9VyxPYa7QdHqVOYTOKMhnXkAlP+t/B3FQsri2cTz
Rjz1K5x3jzD5n+4CtPzPQisVYsS0EPNr+BU/xK/w/fgVvwO/wjV+8aC/C6N/
yDQNXvqf09gjScuKZx2cXPLbp8w8l/dzX+FVZyaPpAQeK3+jzfTc3HIdUHLc
84a7M1yXqJcj+qyJ6JQRRNjvU9m0DAY1DvYUcPb/YDmRN7tgDVjsV7rDSrtU
QWIgTbCTD/6Lqf4MiRAPQiYVf002CJJS3J259rqc+DEy3vWkvG8zotBtEwm8
KwyrNOf1IqpG8T43lD1kGAZMldknSbte/VO3Wvq4kNY7U4LeiVfYEoPtYoGt
xU7a5ZS2CyJ38J9ihzgKi0yCc9r3lPKF99LE7lf+7VVt9erkP/98qmcbdwq+
kXrTp2IAX0rIOBjfs1bxshaYGF4tScmWQiZkTMj3rFh6t+Idz81lbWXM1jFD
D+EUk1+tS/zLfMEPY1hyceRxeSZ9gB57hLkl3+fFrmM2W3TtnlBth+KKTD6I
Dpn5vRkmm4sRPtXdsxBnwErZ+oczzCPUGj9kAeTydY5/P9AlHwZ7aSmLShAp
V6cd2se0weM9j+ydRLgU9KPVhTfPXB/egVeRYWx8h1IeqPMvdX2Kd4R1HGF7
EW9T2qQQfiCfd79WA/pPLQH9ntDzKx9K+LZoZmoT3yTtR2b3N5L6nQz/1Wn9
br8ssX+zV/rrGL3eLVWHHzZjpIVXzBbjCuideh7VsCmZa5K+ES7gXUdT30Oh
jAf0O2h0pRgFRPlfnUzXuvg/gFJXG/6liUWhSO28xqXFObMuXVHxbkLjN29G
DQ1kHlrU4ST+/AdsYXWSlfwnQahm6+XACPE6Ojdh8beSI3iLB+p64vYr7dpc
pd/zvqm085h8xavdaDAiEbfrC8rPbd7ZJqEwDZpsWf4x1bRjvPChXy/2bxVJ
0QQMnn9PoSlbYiI9+nGZCUQDjvJJOv10i1/IvFcY9/80KJY/g7YVypVqo93A
buS+2Gg9NhslMIKDQq1P6r5YqTXaglAZP3Z6g74IvuTfCQI8hr/B7pd8xBex
36i1C4Nhr3J7Hicm+Kq9TusiuJlJr1u8SISyEoApEVEl/rHU6gO+5R+FU37h
z6jFfU817oymy8AaR5fzEcCS8km3CGuwtvM+n/3lgxz3BQOtwSU1pkiy+v6E
f5YlJbAv5vQr4mfaHmjzT4YGx/g7HMSCv2KHV12ztTf4Ar/5hm/wi906gvBb
K/F/CTn47hq88Ntrwv9h8GE1OKXJR9Erb9rK5BZTKn3Ni79GIXjjKnn9gfBe
jv/rKewP84YX5dAHNn+fLv8TPkI399yWCo/4xHmbslh8/tD7wqzhCfRMVvR3
AH+dG/1+8DO7/oYDZNjsT5zCH5XDfoVk31Nv+HVK/UoO+ENMfJj9/bNSv8L3
pba/h3Z/IwfiQptpZPgER/yczTzBE+csXPLhcWEB8jjYYe3giGfm8SCOlicz
qXyjnPqvH1Wlsh9esP0FP727uxN+Wd18Aln7jA+cv4Uvk1+Wt/eHyL56Wver
03ygwP41/fzr03ylALKnqbTLPIL8wzfnnrjHeB56Sj3hy9zC6zaMGZ92vxo5
OPuqG2fOaB4xImd1S62kheTr8ZXkw/mVXxqS/CI6AgQqsbhizE/SzJRDPe9p
5mkT4fDNNyZIqEcY8/+YTTtvydMdYXwejvnCk6X7MGH8pThM5kCxqbNNzgmd
yxbpAMA5p3w1+ZkkkceLsVSFpZzzx33L2Bp/SdjccW89nSyjwSgv3tJFMxik
bWIcNd3waSKaSvYYLwRAdIBJpdME7/mWlTuhQbGOQ1fy4JQYdden4xaRS0ni
DLaoJrKPMv3Lp3HaNA/pX0o+wHNLdpr2Tdu0z+NTvLEiHYxOb44AigfMoR5s
gRdfMNg8QYbjHzzVCd9NWEzjaHix0Y80oQ1xZBpC8PukKAYU/vjuapsfv2Bl
AzkVaIrDFhmOOXHoZZjD2UUhzwoirYVT8Jse6TzFRDMeFIORs4MHobxpOlFM
neAZCaFzCdTAkt4SQYPNuFg6VBY4y3AROjHnDn57BL2eENQ45w9ukY/zUsAR
IycOoy1OZyPjTsKUTN8m+mn6Ls0A0xRRIzNShzdEzOnCipgXPBZXVxpconwX
u8cQE2sHBOXC1aBaaP7tNH+ZECemrcNXq6et98kmwrbjaLtBnUN5eRGREwL/
8rnFMDnnIs4iepVBvRNLUwYLk7hntwChFrNjOeJ5LOeUcOAUusrFxgzLMDjr
Uo6jNRdtuv8rk30AskyBn4/RNgaL2W6UsPFvgwWSAD8Uk3X0bkO8xIEmVN+j
hqs7TjUIPfjxPlRXON+E6KWk/IbnafbOMbkeRJwztiYGoHY64rksShB09yzm
sNx25SzdcLIFNqJxGQdAcvEFJP2F3hc46CQF4B+em+EchrmBeMfzFikzHq+z
5adcuU5GIhXUL3wyD8FYgz6gisnmPJXDF0271PwdYSvNCFHJIb4TT1MYgIdr
JYz0IsiS48qbxhFEEqk5c9lmz6gHbrWLcKBvwQl6/gUiS7x2i1jB33o0fwnm
sQhI2a7p0R4jrs3cMXfVe3mefEN5pEnJaTiZAjqWZOGzaoatkm06YpbeccEn
BLOUz+aE0vZKLAXgOztnEfpohUGPhJF/YhjE40k2ExqExJ4e93KAOD1ARm/s
M6M0HHULtCgXKHhbkcCvTug367flfuHzaerd3/Li+ZWxw7WWOPyPRoqKLFE6
2scERO3Kx066E8Bc5hMsYJJBi05DbE7AJlsHeRe4en2+tCPdSHi/0WUMMNxc
DRvjqmwjIgrOUn/ZmGZBQe4R9fxKHRQoNHahh9NmxPgXC0y7IPqwfRikd48A
/gqGUc2DbiFI0EfgmogUPTHIOo7clAEox/ZtLR7y5CmiBVDIkEX71yYAL1hB
C070zHAWAYc6ghP6egcgpvCh0JrXnh1lMKnH+dpVFAS8JubjnvRLSjFNGcLy
oEXA9woPYoFL2+uW4bCecHr+49u50tRidjjr0/UdX9Jn4dR8DRbuX8Uy88Il
UPNf0+RPmc5IncWnfBD/qne+v/f0MbyNl+/wR04/ffXnG1/h24NiOX3k48Qi
ffVPf6yU251BJS8O6o0+uvr/9CO8LRCOcR78dOEKleF+9dKy9/gwLvgAKqb3
rf2YOqDg0mVKiYBTdK/+09GmaqdHPkyOib+Etn/FxNDXb2eTV7+EdIQJJRmZ
HItgvM1jp16VUyt8fPFdfwRew4GCm7BFcJuWxc+vZ7tBzs0SabI7szS/E6zs
bJzT7WCiOMI7dqJVXlTFT9JBuaQx+1zntcnsXZ7HP8zK23LeN/KSgT9oQd5j
+UC9vPp1BJsXp0lyfqCB45dxXiyJfy8O+19ECOb+XhwVvohN+G+dxSsfQ/wO
/FKMJuCElgoXeFO7dAVQGzRWkdyuPFjOoyhromTldSsvyyJJQq01+OqFAt0p
9NEL6vULaePO7wI3fffdbePRNT4zX34DYac/8Fkmmst/9f1jl6zzyWJ9/QD+
kaR8+lfOX37WMz9reU/K20ZeVj5ewXLzzMmrVl6V8qaVZ24+MPKBm9fUvG/m
zSBvw1+Wt+S8an+8AlPyppd37byq5TWWN1heV/OynQ+kPINfrbyp5y34Cwuq
H6+gAAx23nTzMqxg4HawjqfnmZrXnbxs5SUXwWN6Xr5wJlZ+QF7OfVLJ9drp
1yeiXU/BfA0G8oueLxTzVS1fquYlNW/YeUnJG4CVQl4381o5X9LzZT1fVPPm
B7i0CnhmRYYDfwTH5ZqD/2xIihBAe2SS0S9ZbZI8hM0hRQZfLVUq5Ae9YeWj
Zc5dkr/0ekaX8exeqdekn+jRX9Qtly+pjeRyzAtrf+uvlre9vGrmdSUfBMiY
vnl53Q/ygZ7XXZQY18nrUt5T6F8vb8BXat6V8yawapCXvLzioHC4GbaFaBiF
iaGaZCaqGZA238lbft4BcTER75qSV5W8DxJg5zUnr/mX1wN4wEWOhpVlL697
RFwV94VfAWxbzxt+XpXztpP37LwHK2uX12EphyE8ILUeUF/OO3DSIG8BJHAc
hnLsank3wN19WE3Ky8HldQBbh299BEx28oaeN6W8TzLnGnnHR1Bhd9lApIEO
UODfzO4gjpaBp4NDwaaOlrcCRCNAaIPC0FBMFTWvKHQQE5fy9cvrsKZioBaR
AWwXN7UUBEaW8oaHYJsAkpYHDHvA5FLelfJqBvOgTlwd9ZBMD2syngUJLdFh
YVMVCapZectDO+ZLeSWzOzyPEuQiTnSG6lCBBU18Hc4rE03hV9BYvpXXXPyB
ZQineoirwEOOUg2koOPkFQ3PC8gHywnIdCwkn+IjMgFIX84wrYJbwwoAv0Uq
TTZRMWtAbuBSUHhm3gEVy5Af4FzAAEaGaYHNgB+YjBoRuAKYDcADgIGLYBfA
JKhY0KBMw9PBi0AUPfO6reCavot4A372GfIPcC8qe2ByM29JSEGfOJkBkAyR
fyGcmgeLCqwIAuIQ/oErgEBwZHgMzYWFUAH/A9HR4FhoEC67A9cZeQYbBYhY
z8dTAwAglczAt1D66GeQHcVDzKgZ1AGGgWGAN4DzAQnIA1peD/B5EB9gIdtG
zKvwgI2EQHJknCKgET6mIk7gWwAMjgwwgLAosCDJPrA68APsAqINJ5UydIdz
wQrwieuSfnDzuo0i7wRkG0FSvLyjIkKARmAJAycvZXYHSQlAXmBTE8VWdpEB
fJ/UAkiBhNoGftXpGdzCR644vw7nAt52SRIBqwA5MIDJEOGGg/YQONnTkO6M
cA4CKGVeB1SAKQHecBT07+CkQCDPQJ0AlhY2NW2kF/KthwQCYLwM28AWwFog
gzZoFdhRxVMAvYBGoDSAb8FfsDXSY6AVfRQ6x8jwPJEM5B32BfvvAgzEuvAi
YBXOiwgnNQt0cXRUZUoG8/AtKAdQcSBN8Aw6KRpCAs4FMi1DjQ0y5ZASgF+R
QzLKCmVEQbSANgDSI294KF/AP7AOKGo4FzAPfAVnYQFaUinzOnjEYCMAw8De
yJMungW0H2AbrAOIM6g7OBQ8hjghHmBWRlkZuCPshRreJ11noXDpOmISTABA
CxjAszsoicCQeubsgCLQEiBxQHTgMbA1FqECzguKzpORIeFFVccFYTWQCDVr
IhniE1gRwAMeMw2UaJAjl+waIF91kVjgmumk90B1qBmBBa6As4OzBvoT9Aaq
ax8pC8cktzqv2aj5wVgANjxyDO2MbwjboTAaqJpA5EERwetgkoA/gUngV4+s
MxwBuBogV8j1u0gcNw06GjgQFnADkQPJWsEnClkcjdQRkAAMRyBfmUjVR80P
EHocUTrqPSC3Ri4qUBkeMCjKAU0Lsgm852WYFuQFTg2n88kpBlkD3gBsAHpB
5wDCwXLB0YDzwWQoFlpDL6usSMuBxgMsAaPCry5hCXSISU4uYowhDEAajcQt
S3ebw6MifgAPJrGZT7gySYhkFWUcCIE6OUD1y/QrAw2CAMhxiduB0+BdgBww
DzLIPQ1gPDiIw3WIhyJ54TqZrLaLEAJDIvNLyGBgngCN8Dx8K/tpNADkAD8q
yHgXQCNYHMQNOBZsKBqFAH8APwQWQYSb+AAoKNgiII2qZp0Tl0ijo0oBlILj
7xL3ojFiKNqosQ0y3wFqMFBoftY54T6JgUBq/K0A7SwIIGAVcCVTPAEHAd2L
2k9Gzs9aGTgU0BpgRom2UGBNOjUoJSA0UAR2B40K5hI0oU5a5WKgYWWG2hh+
AAkFJSlTLAXMAPoc9IxGVgPoBVID/AwcaGeABxcIbZNJSJYQw8DegHaXcAI8
A2wGDGORvNjEdVnHDLgL+MElEw8wgEIwSP8AdYDEAAkgCoQaFgeOAvUFQNoZ
iQNtBq6ORJoNYABUG0Q7MNaAc/hXJtuBSskkn/Za3gGr4BWAKgOoANVoEG1E
NeJNwbOD1ICtBPUFJECsSmi8Lrtzb1BD388hrgPDBADb5Iy59BXIDoSVYJph
HTCXWdQBI4FCAxtkkGkGnYM2XUatAtyOXrqHnKCRiQG6c//qoi4cxBtoMLCz
sBEII+gTl9Cr05o2KUxgOZecJVDIWRPpkCuOjpmH5sYnKQPWBQ5M/XkfNTkQ
ES2OS4yd9S4kpAjIHSAZRV5H2bHIZMCyAelnUEQOWS50QZUrgcVUjYHqAlgF
lgWSwSJwECQfxSOAK2BmWBM41ifZlDO7gy0AFQGhCrwIvIrSLaOnBKvBwcG/
BTUCh0I2UND+GsQ8l90pZgGdBodFqTTQpoAf5ZEfDggEPvSJNDy8AsdSz4iM
TwICpAG1APIlkfUH/QaWziUBgZ+BT2Q6CJAM3fUM2wBfgVoG+DErEKBoBOQz
g5ACkn0y2eDwg7lhZLxAFQeZYFkmJxnYCbgC4zgP2c8jOwhsFhBOQJECWYFj
LfIQpOzZFdR+AD8INTirpo9Ig9WQRjIym0IevkGeKqLRu+I6EEZgFZc8q4DM
NzonBhJdIw3vEzCM9DPoKxAZObM7hgwKPu9RuAdqyqNYFXgMgAedCVwHAMs2
KQ3SwCxzdqCmxsiBlxFaMDTA0kA1iAtA0gHzIOBwFtAkEBEgoqQrr5JnmOAI
ELMAuW0ypoAKpJSFih29ZQnVDgq1QwY0q6wstO/gsmKKyECio4XSUL4AbDgU
9xuBlHBweBhMhpxRVhCqgLTCGSUKohU6LyMTA+oC/gW+BXUECAEtAWjEYC3D
NoBzYAkw8RD3gbYBroBjGsSxoKxAwB2yYqBJgHYBGbIs3YEJESQZ1aBP1AnI
kQPb4dIr6Cj6KCyAVd9NA72LmfBxQXSnfTQTwOog8qh4PWRmtP4OcTKFFeiC
6lfaBvOaPvIYuGFg4DAIpawFkNghWw+GA71Z0gbAn5iLyNg4h8IumbQZo5gF
zAQcBLChUU4AHCGD9DyytIJCoWZVpYZEAWSCPAJZgeeBrKAA8UQuyqBOKguA
BP7nPqSm8rYh/OcW/1DnM3WKNaqNUmFQoU+FVqNRW81KpcLYmRT2jWJh0rgv
dMKePHF6A8t8axWkWun4Wus3XLXcrdxXCq1eq2wdSm+F++KkPRKKhedBYTEa
tLrJvtR9Lo+63Ua5cP/UHVS6rYJWK8jDSnG/r/dro6O77O3cWaXXKlj0eWmy
bwjdpb3yx61JV6rs61Ov3Zp19+1BRWqVJ3KnXDk84Wdv7z6bFXKnDQXYsVbZ
34+Gb5VmqzDnKxf2pdG8cqiUCx0Es1jwWkVpuvCW+txVtENlUHjkn0ctoVS5
372oo7dGpV1sVbR9ufvcfIheGtOd1y50590CLPPYLeCfIv1DP8Oppw9NYzbZ
C6yzU26kx3Gg37DJYBUGzbk0WOqDWlDeOvWn6sRuxcY4GfbWeufA2k6tkOz1
Xmf2/FacAlg1AUD2y5PuU7HYe646O+lt314XlkVjJKlV2W0fw+l86pQLAYJc
77cqtXLhaZJ5VvjgYTpfvdcqFgKrUhwUyoVuPZdSxC/vK8XcvltBkhdnhbZQ
nCSv03lYs/dSsdQrlCvdTqnYqxTe/amsyn4/Z67Gam7kFtx1d78ot9xc5yB4
ttV62L6+mS/P7G3rPxf91/Za9abdWfPlZrhu28fk+WF68Jzu41v9/jhyBzXn
6L1WBo7xFlrtgxCXb+pDV9M2zdyLel8I6ou+fdNbL7x2r7Z5ldtuz9FvjitJ
015K/dnNfLavVZZSt9k4PngLRR0J2/6zXnE2tUksdd1mz3jpqPVus/BmNZ+K
9WavOLrf7xX/YbCdh62BXVgAus15Ves3mt6+On1mwubGfO7fmJvHetnKvT0/
v4bd2VSvLl7vh5vN9K1XWG32k+fouWoVq887vR4N9PWoXF093cdTzVq2BXOq
vUrDF9lg/e7LvjqeLwbuphOz8CaIcyVWWNpjR2sY+2Q/e3CNimdXiovk0dWO
DhsXW1NLWC3cpCnt2r3n3Vh/9buHm+dps+gdGoeqEa9f5Wk1txw3Hl5ey6/r
+TNz7qvHcuGlauVayk1zfd8Vbg6N3mIyaR/73fZWyZlP3addoDtWlOs9a7vo
ob+7b9lmy5348kPXKR3U0X1rq6iF1/bSfPBmlqCppuZsR+zQGURBISlMDyM5
mrx0F9ZzUK3e68WH0DOb9bozf35bNqcz2/ASuXavLYoHfzW8WQqlV00fNp6O
pWc5PA73vdX+2Fs7+03FlQ+bydtr+346yJXMFjP6XnP1Op+xZjQr1NarsiG3
696bMJnUh6baqMiL3cIO924cuRVvf1+Z+q4aPzxG9utSHtfkWthej7aljTEo
HB3dkv3nKH443rsdYTaumlJSaS9no9GD1r0pv44N+bWozMLOm2rNzYEyfapv
5xYb7Qb3o24vdpzkqVi9n0lqZT9Yvgj+7HUp9e1x7NrWahS02ntpPS0tzKPk
VPdavdrS14v90Sr2W+uK+1irPPrF+31SqSqq39qOG7bgWvraWtdr1f7TozKb
3phycjN+e4rXq8nTQ6VZbJZuWGXUSnZed85uVpW3mfrU9Xx/vq6X29bmKPTa
XttrDAcl4/hWNssL7ag3ti9HTX7TrWFtXmaLm+1NbX///OLHb4m6sKrjm2IQ
jusvRvElGOeE5eq1tdjMtDd75o08fcUmxTjnJrnam7xYtKrO5rXU2b32b+7X
xaC+d4fG7Ga5kOCzw9SbT6yRoO1HD9VqhTW0+u4tx6KwPtaa/Yl6H3mrZ3lf
HO51NrQfVrVOsts37u+LbrENTDis3FfVm/sSE447w3z0eiU5WlaWlaZ03+xI
iqzFL6+rnFucDVkwPXpyxy1spYqnsrnTspu7efI0rD3Ub4ZABc2otLrrB+uV
tTaNqCEHamUU1ouvBWdTeXlQF8NNf2zGmwpTtEZgK8OcN/ccedWbLyrrgmUm
wk6qLaq1xbATd3Vl2PMttymNa9vgOLoxc61ZPdJ2U7PT7DqjdQE0kh/OZLVj
Vf19/X7afwuqwiI6bMLc9El53d881hv3bzu3nFuoj217Eb05gW/rLzMl2vuq
OTm+3WzHlefHG8d41bX59mgs79+E/eFt3b0vPg0OzfJ2142V3qH71in2lM42
93KctJq9TjtRrIEzVVajUsmYLLaa3ru5t5685d7fu8JzNdisw7djdV/NrZnv
vbTmVumx+djvHBvTjlXe78ZxcVC1cyvL8oaVqKr0gi07DJlfels+bivCquw0
u/vd8Mj29/1VYfC8ayjHZk9+K63V0kPJNw+rp7D9FiZzvfA8rjcP1iOrLu37
QDZH1X2hIBQKI713eAjeton/+ii1k+K04mzt4UPFndeC583jqm+uBs8P8dJ/
eKhH7qS8nJRKURR1DiNz8fQqRN5xKJefnUT2Fq0HKRkvO0Zjd3xli8Xc3kzK
jdL0cOPv72/mx+L2qevGLG4qh8l47IfPO/+hLRy6PetJf3DCwLHkxbheqkrW
U0N7jms3jdc2Y3JH9+1+tbN+Tl7GN4/Syw7UbrCqPdcaB2+xl4R2zXPWytoe
PTw+Lw+2e1OYFtloU+Z+UaVd/torSjuuabrvr9deQP+vV3+1/gJwEU2GjjGE
MBCSg4OKUblO2VrKjpoW5QlNzC1Y3lcvqxSB6P4vNySk/4e7/E+2I6Ha45X9
RyfGGwoudX1C6m/pRbjfLkRZQhccYFW0X+9FwBdEK/vCL/UifDegf0YXwhWW
Tn/ww79sHwJW83lgb2DCBaJKgyolGA/4GLN9uIJOr5sUPgFbQDDmUtBrUtJW
UnAph0KXwPt4BdiCUR3LpOgIwieXUcqDSncQNWEu0sdv3W/0QsiUGYSwFl7E
DKOPcSmmjKnmZxqUU6YIyvE/XgFZXMIA3lLw4AhMkE//zwLxz1+2aQEitVIF
RaSgI9QQ/lerGPRhlrKSL5byShmZrwKSVcF2gq8WgFeNInYZlP/MpoW/NiR/
400LZ8n6rq4FpqcRu2thQo3X3SH4DyhbzWseloNZiUvigEJuh3KIGHVTclwy
8DGfMl/AmcB1HikbmZK2TobJMcGnYAZQowIwowyXJhEMdlpH12zKlShYq/AD
5PxL4oDSssDbLKDKuoPwY/2GspkAEuh3gBa29iVMZrk6FsIv2S6HquyUQ/d8
zCnIlJp0KD1qU8UCizRaXjJR3rEmlM2tO1iHwLwe7WhQOpgX8DRq9DJMFDSs
tShYI8EaakZFMA/TGRrl4nUZUyqqg48xGZPskoZZaY/aloBxVZvyepkcK76r
Y0aDUQXOoywnqBp4zCHDBnTBOiUlfy2qXksZzNs29jfIPioWOLhHVVvYiFEx
FTSkTX9lGXNttolKxsyUozAbS/UtMJZIcepdUCk7ZlM1BRtNKCsNKlfzkEZa
5nXAkk1JQCS9jiVzQB22RxCWXKIpL8bYFjKMRQXaC9NSd4VGuU7gLpO6OoA5
XRlPxDkKIAG1DITAQizDBS+peQ3TSSpVCuF57MygmqtqISMFlCODzy06vkPl
gavMPnUk8BaygLLz2GNGWSdsxVBJS5sIsG9i3cvSr+rHIEpAEUeirLqNRQUs
GNuY7ZV5UcRGosOCEpVJJP0qPQ3chVUfHY8JBNXttOzEyIJIDiXLFOTMNPmr
Ih0vqFOp4kiVGyw7UZuRT1U9oBQWnySs60iUd3ZJNIKMusDSMhWxADMG5a9l
A3nepaoVFq1t/AHbhiQUXpCmbDnK9ah4Sf0BVoAygk0YLh4TGECi5gNMJtpU
0bRJIjLaBgwco3MBUYD0oD0cyvVrDCWUUT0YDggyDmrEpxKIaV+hDlWZgkZc
p6YHAFWl5KYhIz94lPG0SREBiZEPs7VzYnhDx688Gc29Rj1Jtopqx6Z+OCyP
OcgtmOzWr7KcioqCCTsC78Ep2KkjKghoER2lGCiOKU5KOgMXudaVtsG6nYZP
wrlsgg38ECyIqogrLHyaiBaD7Dt84thXuk4ifeK4VD2lPgkkFql3ZHIH+RkU
rEMlSaCOlfGIfF4OMSn776NiAWyDRQAGsKjkD5gBotsy6mpYFgQ2q6gtKlfD
Mz71lgGNYDsgNKMqckDVpoCXlxxkGOyoyNZQqaCLjCFTqwqVWkFegOiY5A0w
U4yJe59qTlR68TOFAZtXesjx4ylyjxpfPIlqURJ+jl13JoqtQ4sbGZGxqfSI
NUsFTQPwGzwDZgUMjUppd0bOFXAF8C08iVYjQziJQgiJ6lUqNTcgJ1B63ad6
OWBAo34O/JVqBtnCP6zsUNsW8jwV/tGQkRWGn3VqTQMdbpLFCairJtupE5BB
kYlkYEl13t1FVQqJlDD4gRqV50GfABqx+pVRVg5RCpt7LFT48C+wh0RlY51q
GHBk9Gmp49MhbaxnrIzKG+lM1OFo62U0MQpVoUC/ueQtoFm3Ue9xXZqt5KGW
o24MwCo8ANoDfuVFRM2hRhONdLWDNhQrKMFVKc6kcjIWvHkXjoXODJzR4L0U
MpLAIAUCCkGhot1VJU9GUGFTAMymGpJJNRLAMIdEI2ULbGNQNR2YX8kyLRkR
eBdcEZR3wqHGWxYMhByEHZQe7xcEfCrSlWukEluCFADawZyBwjGopRJ7BCUq
ySio/UBRYy+IhTpByfaLUD8csJZBPXAqVT4ARYBJYFSDND9+peZ59yRYqGwF
1yZ2hQ+RzXzEjETvgu0A9QWKC3uPFFxKolI0bzrJNj2ASlSoOI1GzaYOsAAZ
D3spTAQYPgkIgQCASqTPFgJdXp8OkATokjkoF1jV9ki+fIQEuFcj4FGCrCvC
GdQj5VKPGrAoQuiRdg3QcoHsg56HAxpm2hzpZTAPXwFTqdSsAPIIeHOo4gVU
NqiCiO1BDhLCpHZMlTB5kTiVwKNKP7AE0BpDRZn6tMhRNKmhXabOKl8hRZRp
NwG1ppEr4st4WJAm7HAyqPYmUx8tRbJpX4iMpj/rlAKEgBY8pkTRLnWYgSCg
KWfUv0vaDyDEKjiZYCXbheySCDsEPHVTudQMx4iFNHImgc2wn0NFzjfp+OfX
4dQ2tUOBSke9p5IhI20JxhSYRCMP36F6HrAH6Ids2wGIoUPcDq4mSApvbdFJ
06J9JIZ0qWEFm5lUOoJ2ZaSws4oK8NgrQ/2FGlEc4xcJK4vYrUuNvNiX4+FB
LqijYIRxbyTAU+jkjKnUAaNRlgCJRc0fPhW5De1KVUrkLQekr7DPz0pnDUCy
JKr047yAh0YEXB3dvDITYL8sElIATCPXHYydRK6FRh6jRq9z3wzQDqhg1+3j
MvEzdjFK1G7iUX8bNcyhhdWR6EARh8r2QFwlE4yAhJqkkwHhgFWNdJpCDU9A
KcxyUOxmktmyieukDPAyGTKT6t82FZixIdUnn4piCsCATM0uKsUmrnuVqZDJ
f1bJVCGrUzeMRKEibKeSRCBfGbSaTk0wWZ+W4g6dEiwqLQ68h94aOQnYV+Si
CQYtwbsMAXXZaMKiDiGTmqhkGgnRSL4A+aCTYUFGXkdA7Z4y2V89Y6TQeLnI
rpxVQCPh0IqLhAMNiT4PNQRwyQXmkYLr2rlJTavUlgSehkWNKYBM0IdAI0Yc
7pOkmNRqJvlXATjwNvYH+KhLLTLiKL8UL+sEsEYuOsbyGuoE7FTLEA5jNMIJ
9vdTTx4sCEQHbMCCLh0BGNIm/eOTQnMybONST4ZLMGNQoFO0olIEzcjDOXXD
AG7hYeBwPeuckF/k8FEgin3QRlDHLXbs8WYXA5fVKC0AXKRmFDXgCrtkHPS+
HAqmeERmc7NIQsrtPqgvkCZAjp11Cxl1wJBO9qklCMTKZ+iGgRAZvPeLrBtP
fZjm1agRnpdiLmz0p7fg4Bb59qgAT4EA+ns0ywZotzJMC/4k/CpR8hCFnfqk
gX+A20FSAB6blDBYE4/6SpF2GeDBoPCUo0rNl8AnJjWL49CTj+TwKCgOeJzl
oSj52XkPg9oB1bSDCoc0VHTReRxn2mnHtk7dGKCxsSc7kzkBA+GTt+xRm5FD
AYVGHX5wWIXmHAxqJgbjAkEcqr6soqbZFZl6+zTqoYR/bepscwhXoKAgTkFP
lXSOHVzNuhjUUg+vWNQcw8iJBRFgRAJGKSkcViFZAL/IoRRE1sKalBhhBBXQ
Gl0USkRgPKgiJwMVMItCjqVHvVBZ+24Q24CkgMIPeJO9iWAAvUD/g+xL1GMH
/3rkoHpZn9ZKezQBDOBPldpqQUWAZlAoGgIZB+LabtpjjSFexinVqakdByp4
ooy4yCFEAUdhR5qOXIqJCD81NCzjHoAYetRhphFUGsVrHv3Fg1MaTaFWVIta
e23lSt5NGgTyKCnnUKcRHMGgZItO/r9OiWXu+Nk0FuJmQmCfvMSA/G2ftxga
5AqSi4Id/CpC4lBHqUouYraNmLemgWJHN5JmAzQKLnieCn7QqB8ONrWpjxbn
RjPA65QP8Yl2OKREeFMoTwgHsci1UCnbE9DgCopktj+MWsZd6gtXyLsDHtOp
Q1GiuFKi5kKfCAGnUMgrzgYjDqXRQC7gIIAoh0IhIChqbwmPAKjAkgQ9gENW
2ZwVo3ZVgyY0KPqDx/hYEXb5E+FsajS0KcTW3nkXZF8w7lbQcQ2ou06nMARO
apD+dyi2wqZMD5lTy3CdTX1XIAV8U0aRlE7zmKCmdDdNt0KU5FMVzdOuwkDQ
3mhA+dQZWXOfGk+Bi0AVYORFuTKbuhJNshdZz8ol90mlcU5Gk0Uq2SObhhZw
8pAMtMGQnVSa1WHsiuexc47CEIU6v23ebE2pG/RIVVSV2Hvnowwa1x3YPrmv
KnX9qjT8BmoTrJKnp3kekyTXI6fRpOY5WbuyMuDygXAxGu8BdPmU4ZR4R7WF
UNnkdQBLB5QO8rP9oNQv7tCABzbCktMLcGqkcODs2FtMMRqYP5BrPuV6wbyf
9nmjLXBRrNAmeui6K9QaDi8aNINh0QQLpu6zve8GwoOWl5odPRqcA5BsUn3Y
H0nqXSfHW6efr0YmDMqKyDRSRfrWooyTQawC3Ih6jHxUAANDYwUPe9HzlESV
SAHyRl4QE0CgTd44PKxQGAgUx/wwuXC2eSUySG4dgVep9xEzNjRdoJI/zOcN
bJqI4EkY4zqaAFbH0UEFzTqfqwGRx356SmgDuRGxLG03BB7LFhdA79kU+mEU
75O8U6+8Qvl8wAzmXigK46lyMLJu1qeliQuDnD1sOlcJPCntuTcpTwtbBzQ3
qNDUWdZAm+RqmtTU7lFIFZzSLwHZdxzOobk17BCl5vVsdYAnK1SKW2WaEMNp
Nxq5sfl4DEPd5ZBXA/Gd4111o2JWijxA9KO0tDrD6YiG1UANzChnhdQh1r3K
z/PxJBkPhRM11ALOxxgCClsCmgv1KIoHI4vZuQzdwZRjCcNMx5xgXzggzvk4
1DXuIyFsUlk6KXDkT+nKSIHuAinALl4K7UFUXcqa2pSNlyiZiS66nc7iZpvX
4cWAWvwxLySTaZNpuoAKExBrMMqro4dskUyR03hBnY5YRRtBTecAKpZOKNq1
aVAdMSaTo0iqEmgkZZSVSnElKnCXcEiyyXt/AYcu/YukJC+Ln0XJCCxmpGWy
RDSHo9NQARzfJxcXgMFBNQcZHgRT9dP2/ayZAPdepQFUVIOU1lMou4gzABJ+
qFO+mpHnb5OffFEXNJzDKFMNpOeG1aImfjT0ZJF5iGpT6ltzr8ZBHUproDgw
BBiHH1xEPsgXhL06lfgdilYwsa/R1GJ2XIQCEI9reEIOliEYQuhQeUWjQTvA
T0BN6pp5NayCUmnikzj151LzN6EroEDeIX1lUuIroMk0jTrCL3TXaDqXWsNl
GioIeOc9SYFE0zXg7mLZSKIZPNJdWX8eDuWTYmeUCcS0mIqPyVRzMWhkTiL6
ovWxrzJmAZWoIBTFAQles6OoBIc8KT/JaNgDi7k+wiZLV4UVj9wJRg4hrAOq
BtgYOAH4FqNmnc5uEdPyCQodjebFs9Ioj20gq5jk4+FMJh+4tVGPyWQcPaoC
GDQXrWaAx/FpaofwyO/1qX7k0vCwSUVhgAFjWxq9xpwzu2rcd6gbAB6zyaCA
Jje8VCPhiCDvmJdpQNRA2in+lWOm81wWZSQ06sGwaZLfoHlgNEwGWbfz5AyN
f1y0jY88o9DiJrleBgXaHlVyVWqCR3Gm9JdGjkrWSIGMA1qQIlQx5DyAw040
6+6ThoG/EJO6XjqwZGdHoHV8XScvyKb5IvDhecYAFKZO8QV+Qu6NTho7OxrH
iBkwv8HQUGI0QXNKEpl1n8ZONAoVebIdY95s9sBMp790Qq9L1VKctqW9gO2x
xKamY6KgVHnbzOV1iqQcmkNDVUljh1g55fRSkHxYi6TBLYtq3Nn6O3hZBvl+
ip/CBrEqhksGKjpMTUs0nUthGuAcw0PrCvMGTVR6VPpXKJbxyamWaNbIIdcU
joBpJdLGWjZvo+OhdIqGwPRL1JyDUbNDPRISPu/TkDbOEVHfTtYhx/w2ZQkM
fh2Kj7oUzBB4Agqll1UKz/mcG7hthns1Dgr60CAVZ1FCGK0Y1dzR9gXU4+Sh
7jVoZcP87mGJZr9cKhWebk7DEsNRXZ97pSUrWCNjPTpoUp/VZ9WuXJWlfWny
3HjYPxeL3WG9GDb2QntwGVEoTlul3qJxKM8KrfOIwqg49ZaLt1bveV8t0DDF
Q7kgl1zFl71j8VkYjNoDGlMoauPyoCG1yt6hVS5orZl3bFcj+KyFn+07l8/2
2U2F37PredNqay+8O1O5lw5GPNxscy/TAXP1F3fQX3cL9e1mXHrYV9TFsTDt
r8e545N2v9GE2ca5mRUP+8f2zGfNhlOtsJv6Xpa8maX4SbNZc6T1vLAtqetN
TjXas1atsq/jYElP6hSLzxWhWmt22s6o7ues6fRoWM1+sJrturJj5Z5bRZos
8Rv7LvzsFD56Vjg/zMdQ/Aofhqi2CjQssS9PaLdHHJgoFrrlwqRSaxWiWqmU
1ArdYVUo7p/Dgta4P/CzF/TnMNrWO5vBS1MbN+rVcNkeO6+eOXp4VYpR/GJ5
jeax5LG+0XzUNuuKYGxnx+5DqI/uD/ftaWOuqv2N3l/tBvZro9yv+h2lN7u3
S5XNy8gAMqlvg+5YdY7+aj5z/YKvC9NS1bFKbrvx1DP9N/hPjbnN5kPV9d6S
1jDZDUdDY8rqD8XiuOPOPd1m80NvWN943svjYve0FV5qr7a3KbWq+4eXSlEa
tlvxonfzqL6snaeK/zT2V07Zeu4vNpMie1yyMZs1vWNn03oYvqhL33WEHnsx
Z5XRZtNfxLmXMAyfpVar0pRL6nF8cCs+nHP1Ogznq3AlPZftdn0Yliez2e4m
SfzptDYVqi8DU2Z6dDPs64+j3t4ytfHM97bTvuxJD+XqctRsMeZ5tfZi+9i1
k+Ko8vZQHoeFxSKo38iaUEpeQquu3nj6c3nQ7JW0fbkkW7t42CtXyrW+1s4Z
Vamh9Vzn+ck3K6zgz5l1KHlqt2Z16iMmzOSQPSkHszSvNJ4GT+tO1HrR6srU
9m5m9YpW1xypvAiag1Cdv91UG+HwkLDWej19tHrWcjsbCZv+7DCtjUf74NCu
rjuNubJ6uFn3J4uhNoun+kTrhNIuZz0txpXH1rhv7uKpYxz7o1AfRhVLnQmv
T2PVfjLcV2dhFD0jtqq9UOk1tai3jlTDGs20OHg5Bvemq04njtNeRoO3+cB9
Ccf9jqkNPGFcaDmlzmBs1ZuW+xwV2/eDRW4/7dW0YqDvg+fVcTyve4+a7pe8
YcteesGqZVullVR7Lm4ObCKMFWe8frTDuHicPO+l/UNn2ZVHy3m/PalP9/fN
R2UyW3cHXmL7VXtz3Jstp7ueHqc3daOyXbZvhKdld8iqM9n3yrLWU+z+KCh0
C5P6cmyXm9vGQukos9q2rVnjcFeYL4btxbIjqQ+Lktw47nosFAC19UZ/Ym/j
5zmwvd6rt2Szv5zXmm8bpyU/LGeDZi28eRub67flYbZlr2H//mm4mHR7s3qp
EQvb5mux4b7pK2eqLetPljmMaxslV5j3B3E9WPhap60NJmOlXbDN7qh333ho
7F/Wg4OSVJNHWesK8/XDrFw3o/D43Ku3/eg4qOqJMRg974vR/qZTa3aX/f5R
ngXupLyuHCab0r4vd7dBNZy9hqUbU6gX582yVLBfbibNm8SddYb94+45yjV8
5dV86LT6bbm1HHZqshQWnZsnfSsvg3rBylUC3+orLBIW3r11fNssk/pyOXqy
N0lp+TBe7bat2uxNHVbW8+BF9xyj3RgXtfpI7dtWbtWdzXqz6sNyvXMOQqdZ
iRtafVo/VjfLgdU1zNraMyc3rZdVS+3vgqdS4JbkaL18vjmsbuaH7qawVOSO
GsyKxYX3uBeKWsdMah25Op8d18vCrrWQwshfK4OZtxzulRE7KnqxfzN4sAfB
vnvv2sZTODhUvcnjYL/zglfhsb3ZadtNEljtZ2VQVfuSqr7Fu6djrT8r+GN9
3VAjq6PdF8N98/Fh/zCyZ/PJePXaj+VeQZu2BKmybx4Kh5smC4Ka4of7ds2L
3d3Aqo/9ibHeL/v7F1aWlg+Sv7tvVSeFqd70u/1efT/xEnU5EZb2zhwPcnVt
Pw+6A32+NaSXx8F4ut711iUDDJj0MDokwcKuPnde5I3WbiZ16zm38uRtXbZz
90LzWWl1V069+jxqNvatSbtTce3Jnk2rjy81yXxpDVtaR5v0p+3Ja6dZ75Qt
ry7XWpuFNvcSqf8iGICc1qp/U35q9Ro71ZhtG83R9P6pXHl+iofd7v165r1Z
y9HLm9bbj11jW2y+Lnbuy9w55vqgpoXZdFgdGkcGcuxuGyw3GZXVwuugsCpO
HnvOwZgkdq06vC+UBg/3a/baXb8sopuXVovZL8ZrZ9ETtHWJbZk0VezFjbo5
hI7Ui1daveq/LTv18WQPnw0mnXL5Zvc6dEphb9lwc9NJf70bTa3WwAsERY/W
llVtVErFwzi3lys3G7OyvbfrreM4F9letFEV6bVzNBa1NxOUKusmhWFucByu
Ro58CKpCyykOB2ESNSt2zELPaBYGTnKQKoPXXmdRPUbzcSneVzbyymy/vg6N
h8Z2kcuxw0BX1pvWZNsUXqW3VTBuJsVaw6vNh6ylaWq8jHbHx92bw6ReIXiU
RjfztTxIWqvCW+VotbRxob6SZ/Wy0tLmgmzqh6UVPlWstTdm/X734aYWVXa5
tTzUvUclKW1r9cO+2txLFeWQPL/NJGvRj+T9/PVgLbzDvfDqvz05S7+/Hm1y
TXPb00zz6eFxH0r1+6VRWLytj4+1dTTXSjfjbpKrFjr3oP71515VGuw0vdcT
5sODn9usNnvVmTQHO2/mzg/V4EV+qnd3I7O7boBdHd8kNa8bS0ouV2seXt7W
6kssVberxujNFqxiPXL1XfforW7a45eH/rLjbudhEks3vRf94PXs2azZbfXH
u3pzNOvJzsvTxrl/SXTptefttq6w3Yb90W7rPMmSufIfq4fqfamWWzz0pKbv
SyvnwVTHi6ptbmt9vTi7t4xNRbHXT9pIqrju8vkgNDtGnS32L007HPWnzqD/
2BnfD6T5c8/sPr8F206ynPWSp2FU1+Zvdfs46/XZY/kxeXuJ/U037ArL4nI0
HcxyObvBdoZbWRxa8eMwWI/k1SB4mRfdRbu9bzyMb7TVU9D0ZuWVvG1o00Ex
sp5yUuFBqFnqqL6uFB9XnjG2quPOaleTR/Wxtj3eV5Zbv3DT97eq3CnE9mrW
fXyYV939cu03C6Hcaj0vS4K/Dm6a9vDhkUXtTm2/90c32/nocdx7GgTbSRJO
Kv2q29U9gKG0WvRnbP10s1gtlqvRNpRDvS4c1gv74a3pWfFzaf4kz+T7dvW5
1St5vRK70Qs7fTU6vK2msHKc04bBDetvO8uollO7zRkrLw5C1WzNqsWa//Cs
TaOXcB8X2o57r4cvHfuxYEXqeqvOWXvYXvZX8rhWX/Zb23F5YerNR0c5qPuW
sH70HFth8rjQye3UOBw4D+54JAdDvwyot14btUljmyt5xa65S6R562GqPN50
O+pzd3EI62oozDp9Lb6fuHutOIqedn7FaKwHemcg2cNia2Cbna5mjJS3eFxb
BzVDGe9evFntvlIth1sp6dW3wk0VjGy7zKKZYYwakv1sv/aG5Wg+682fG0fz
sdWQfe3GK81zceOmE1X1bVKb3Bfb1dHEvl9PBkLfLCXqS2ErdeqxNwAHrv+6
3rrDea6zSmqt+D7qjl4ed687c2jUkkAv9PRNyTduvAejHD7u5J7wur9XjceK
3nPWw810MKyWylY7qi+L9+FD1Co9vBmmsvGPqnF0apJleZ3aaFhs1uTScCY3
u8wQbjqb+52/PIw6r8l+Ik0q9VXxeLPymoE9GlZySrF7r7UG7V11rM2fls8z
r9k5loue/jYdaofAngjV2XTi15v3Xnv6stGKOWX3snq0S8Zuup1O7dd+02kn
y/5i/JrserMn99D0Fk/Ppd5T/7AM7KenihA+v9iD5532pJT9+CgvAZil4rly
pz9K9PGmvFB63qFfYI/u2JvHD55STFyteagw/Tg6jNoNYe4+LHpTJzd8uFn0
WochK+c2jfZkW5IqttXt++rb4UHWKpWcdlRZMO3NXG8blw5DfXco+5GpC7vo
qI0f1ErFuNm7s11vsvCYPXqoHJO3vvPY2hQfrVVp64Q3SQmY/mXe6009VzeL
L6V78BOeS8LemI5zDc8dV1qj2WJmWZNCc6Csm1H1zbG2Q3cyX8emvZnJqjKo
960JK3vjRtRsO1at/Nx9KgrL7n7x4L8EjXhfe1Hl1fdN3+H/pd5fdwAP/9+P
/3ozeFQIdnjTr0EVW+rkwUtFHSruqJhBtegeEOXdHa0a3QlkSXnvMpjzzRmY
5eb8zHdP4QFuf+ccnpWXftscXvrC757Duwb1z5zEy+Dq9Id//JedxtOoAG7R
rZsGdbJgtyx1q2GDhvzxCryTEdv6aFYDmxCpOVemkjvwEdY2GSbSrG/M8yn8
ahSZbvryqf5MeWLsyaV6gkdVZYDN+8Y0HrbDUGZOoYQ9c6kcTa1VCl15amp4
EIld3TJ6dQqWdprjJZl0LaeHZajzs3/ZaTyzlDfLmBMvUuXbkPGOXry+t5CX
K3m1nK9S43KhmJfL+Ur56wUkLV8q58vFvF79CI7vn8b7a0Pyf8A0Xipdvz6P
h536vOpD96X5NuamLZoHM04TIxbdjqlmb5NVsC6L46AOXW7qY3rdktPLw7C5
h+7yNKlpSaVuoezYakCdWDLdIGVQadln2CMS0Ngq1rMlbHrA+4HktEck25CH
o3pU/8POJLqVx6euEZ+qSj7NmZjUs6JQ0xVTr5oRXepzNSyamKL2F0YzLdjz
RDce2dTF69LkFW/AYplCDpZCA7oqz8X6FpxXoeY8h1paJera96nBERPcdEGp
nzm7RHfZYhGF2vF5H56u0eV5VKHBCR+a/k2rJv6VTcI5SRXxqfH2bpuISJeG
YzlBRn2g0W2dJl3PaV9fmeby3l+PLo2j0UFcgapHlooaBbaTyEw6HJ9Um7lq
FzBRl/jU8CrRlV0OL3uYuI5DNX68ZomqSky76tvml8lJdDMx3lmr0lI0V6DQ
gJ/KRzvktI4OLOFkKu6MX0VmoWZV6YIlhyr9OImkIwNjUYe3LtENgu71PJ5E
FxurHl2aZVKbhUPj1k56fTLjrY10+bRFY3JaBni8vo5qigaVWLBMa1FnFb9K
lrfMUqOYQmOEMrXyX4APsKNCp9qwQoNDNvkVBlXZFepP5SNGMt1mjTNm1+VD
bFCgaw5x9pJmBhRqeML+MImKQ8TzYG0kaoK3rCt5x2YLqhvB1hJdhmqS92NQ
90mgpqV3vH6PbrjMtgsoHnU52ygdJgkF3tdFsiOraF5cqqObNOkBSMPKdMa0
mjS4BXzlOtSsbNJ4CXXJKFTTsmiyBWuiOnVJeliOvezuU88xteODsGDLC91A
CepCpm4n7Ob0kQQmdQDI1tV9bzYVL3Xt1HFLk28KCZFBd4ApdPOx5lGrHLV7
ZqfCHGJLmXp/gfd00o28QdmhrhFGpXd+66RGhibIqEqLbuDDuiwNEBo0wAm4
dahKbRFmbJJxnJqQ0L+QMq/jaKhJ3Uu8U99BucMRfbqoTyO/Jr1Ij66G5Vc8
XqqPfPxMwtqbTtNrOkvvacapWrr9Gu9T17EaalMTiX6NOj7NaBP8ICZAbpc4
BJAMmgSY3CFPmp30+dWYB81xAYmxyZJKxR7NQgOzYdeCROMrfOBNQQAcqhRe
zk59FTgMIyNFcKDCQM1p86tGaTLZp8HOQEuv084aKUa9ieCp4Wgx3WWIQsrS
43iEWOwCJK5zqc1Ic6+4Dl7hs4vYFEV3vEluetemSnOkvJqu0j3x2AmdeZ2d
Jv3QstCdzVispavTA2IzjQrG2AdjEeb1qxvTDZopgtDDs7BpmN/5LVH7BQYq
1OcBGsClu13xqlfzqmxsUJchHpA6402arrFJTYHd9GlIEq/8p9YlbKOk29kv
BppmyFWam8VGOqqLB/zeWRqhxAFUnWyokf6adaUDqtCb1HPmUq+Jx3uMeFMF
XZMpkfdtUx+zT/0i2WZErGd7uB2YAIsGvB2a3HZ5ozZ1q8ukt7GjkV1dec4b
WSx+9SNDhsQ2SodaqE3816JeOpl6gBy6bTHbSSkRUbD5lS6DV+i2bI0mMLEb
icZTbSq3G9TWJtlXnZQS+drc2fdpigMv06XZeIuuWrTIK8AqPnnxKtXgs90G
vMeX0RSEQb+iwqGJd3T/TVQjgZM2jlv6Vec0BqqkVzVSDh7pJWySoHsTPLrS
2KXhc4laom26rPrSYUNeBzxjkR0BgC0pndjxqQeCuwdoRGi6CbumMjYuoHFu
3Ur/jxQA1ICm5mS6e9UlZ0yi0SOTrks3taubdCWadZTo5macUKUHfLqvGv76
1J7y/zf2JkvLK1mW6Jyn+C1H9xpVifrmmtUABEKIVkiARFkO1CMQohEgIC3f
veTLFfmLM7llFhZxzhdfA8J9+/a1V1N3KU0OANzNxbY6SCY/SAiUONfI5kVn
lcDxXYI6NABvmEW8Q32laytkWPQGMTRRhNoLjY2EXUlSWGRQXniUDvBoaUX9
2x6AHSKgJKoQSIgwbYmogBn2sUTghEOwPjcD5odBq4CoIYNTIqAZluE4LiO+
I6DUGfBWRbHRZbWXTQgdggr6hYDK5kOzHciN4IGmdvB0O0SIPmjtd2rBW3cg
RCRJnfhV7CzQf1WQCBOITGSI2OVfs6KAktoZ+MHjyiupDYlHpQxU/EIeAmbS
eIQ/JFQFHUUIJh9xaqBsTpG8IwGSEnJk4J4SQ0ao8j/FKoYqSUTLp0CCWz9D
ytRhUdhFNCoqpAKEjwLC399DitrHYqkHYKSpkFYGoDiTjRBD/4AWS4Zhalts
IAdNmgTxR0cD7EMgJ4B/TBppWMAScg/9f9UfN9l6ZdanM4sGg4GNfUTbPA5m
xrBLUMARFFBC6xLUZk4z8EsO0YRTA9r64yPMMIF8mjI1bAZVLoHdiYzLyz+O
SBV3qJgy4VAcJKiq6hIt4HChCiIJ2RFtfw0F5FcW1uw+vj9WmvcYQ0DCKY0k
UgF/un7O7R0XQFxKHEMCKHAgKFLhhkulgDFKaF0WWCzskPmR9wgIFkhQmhis
XioviWGfT05neOUKaKSpb3db/Uu+E0+eeJSo5G2SggapsEqpkKDjS6DwxlgG
bdF4hC4uwLW3fqSEL86CwZY0hk0RskoIzRFeEhH30x5w0G8QBiSOV+q1H4WN
cbUKfIj7F8WTwysJ2l71UNmRKyek1wIkUgmkHQpUwSFiCmJYeAiQ/YTt6wDU
nnU9T7imqtfbXIIqlZpA19tEAREtpOINnjznvy9eAhmaQbQFJCKk7MOXR8T9
KAJ4xqH0JZSr2vrceag0aUvAoLEXkTtEPBp8mIwkuEMFpMhT9ULcjjSJoXwW
8ZGBRumDtSzAaIAB7ZhDr+7DP4WDfuDvmod2KMHtm/gLqOT3U6MNH1YdPo7v
AJgG4e9GP8pnFvfi+kRgAGvUT1VkGhtsEjCCnUuyBbCRZdxwxeTnmPDRipDG
hifvLkEbTFx7FLLHRQRHEAUsXDaI4v03i0YF5lCv1fo3cNDAMNgyIvR1VO3P
4z02Ajb294iE/45EVQ0w525yDxiyBnxUUR8RTBKQhJ84Fyr74eGvjytwCNsX
mWaMwLGF6M+hIiDOL8Af/v51DmIAiH5jGFcHYP6RQAlkRPhASUmojk/qAPnc
W4tWhqFMhBsEOZUEiFvgjEBcnHh0FJBbMJBsKbCe+XtEJuQdEZ8Fn2woAYWu
LgIs+P1EYIAjUgBazEPB1b7D+jiYWFzeiZwjhksCBLQ+Ilxo7IMoNldgNvoh
nfsw+iEMaZgOEE+8BHlQUNv6UOwwKCAkUkPBbmp3F2gIGegrEqVZMPVvY3Gb
IyY+iACqnwkRosP8pS02CADWKVA/8ti5BECLITZgsVnwtMmLAez2D0+ZEMT0
+h1J0MCE2DUsMLQEJE4OYpUAKiCSNRH90H85hJ+E6F05pBAQ7VkMNQtyD4jF
DLwefEopZn6aUh8mUyI+dAXrU4b3SoBlI1LbOw4tB1A1YjLC/JxxEtYhi//2
oZuNwIIlOgdAoELUuK3HSMFq83cZCEtYBAskWOcBqkSAixWDh08QPLTiMrIg
2ndYuj55CANkII0SaiwHLSKx52Ch84SgIsHIot1dCDA5IlgHD2N4GdExClkw
LIDKENEuIgz1RWicmN+LmAhmc0hVVTAXE7ELOCQ+yVLjphTTfkn+EdgwiATh
/3VYhHD696lROm4WdSurwrKN4G8SuNGtM05GfYtwiSYSKYhJVMBuAYy6mKSx
/6edlRz9SJclSBeIBoCF1BwWVCTTgCPFjcWAhei+cE2r/1As/B6RHFpllsBi
Eux4eGw6MW7ungJ0CwzuhhL9VW3POOCT1OwpgMTCh2aPJk0GaP7pbShByyEk
P+ADAymdjx6YGORD0xiiGgvAK6iSLYZsL4Tuq+3uIQIqpD4U9YdO7OqoPwu2
p4wLHcmIo+R1GsnS5m2jdoXo0kP4ufgQIKlA41VIXBTkX0XYF8QJIvkp1AwM
TYi3hYh1An0IgT54crjE1JOO2n8AyWxfwH2w8EW+Ed+SEUDYBIDIdIvhkyXO
ayKcU34VMqRjScimINoGoKn10RDjbcr4DSI2AhkNoOeRoUtst4UyrPoI4goY
XEEjrcDFMgFYSiMXInS8FJ34+9ehIlPgA0h9oFg8Ig5rnjbnLK6QBIJGClAb
r+MofAoXjACeawKwTQbVmwhrcUzEkLuzSGtpnzL1w6xfpI8GJoRWsP5DEo6n
GCLYBB49MZpqFn1dGzUioUPANsl3qjBWSMjLIxJHIE4ErpTgFQJbnCj4ydlj
gcVx0F3LUKOJgM6oXp10qjwsz+BHI1MLv3beGtNolam1mQIdJgXqA8wIYigW
yH0QOIyIXfz3vYdNOFiI80uEBk+Cz2MCKEPAGDZBAE69SIjdXmvLEO8kdCA0
giNE8AXJjqNdGeS1EozeSIgW3nt79BoAF6J5dAlyruhkRAROHgWNESpJHURv
Fgc/wRoy9XeghkTofBKqAuKbQQDBVWBfFcFEVYp+lFHUE0rGREMAdqRAAEYA
c9gGyQCB6/IowqCKlMrWo+MAHfD+v24uCdRfODQF7BeacaFSoB4zl0T6+XEB
Hpey3DjuybBH4fAZEXchHOsyzn2Ztq+tR8dBsUlKEwZhRLWOKXfCNvdNcpeE
OUi9rSRIZNu4DbFmwMiGbBC0ryKgYB9Ngiw1HnOh3JxTMRw3/q46XMSIwQc6
cwFZIgKgBjLdw5oXAdsy2MKx8lOsQiR5EncPNL0sjAY4PD1ybMHJK4BIVYUM
mPpY/f3csVsjBJvQBCoF5iBkTADPBeLwCEcYX22UafI/8lhoJwb9jB818TUk
6A+2jDE8FiPgHgFS3fjWhiXrBD1PgtEYyze6GmLPhKzFAHfqmKYgxv90Jo0w
VIqYxh5LpoE/YYO6K7jCC9DgyVGjimyDThK4MRQ88VEcfEwQeBwNZP/CTksB
oEp9stofXIDTn8PJokLCJCMRlES/Akkg6C7KewAfRrLsWz8eIrqKDIMAvATQ
FiY4qUNgRzGcEHkYH9TV3oee/+8JC60+8VqS4KsClzFJasZDCsRmAmArGTJs
In5uT8SQLhjBkFHFsR7AC0ZOGqifWNUgzbVeUSGM8OS2EjKAgBZUJIVvMKsY
ekJ6F1AwCKNZUj4U7G14n3qhJph3cBC9c8imY9FuCfAoZKG88lGuo+TnHkfv
vCq6SjKRQZni4M4WYSPzgHo42I4QWwGAA+1Vl2Aco+JZxRgKKNDoCrBKIdlK
QIbrrUR8bYIfzIrAFALk/WqTsCSKjT2KhAZYphG4OG1Z9Z+2qjS4mPonCniF
EtxpidQffigxbIwUsGwUBAq1hwsxalGID5S0/RxZpTTFl8MEOWGbbFLSQam4
EP3aMCkAtImzJ0JQIyj2iXEwFO8JYg+JQbBElq7E/ZhEsIg2Io0ZMMP6fCEX
BB/THJF0uX7Q2PwRHAmCwPaTZ+DsGWCQV69MATpzMn8EZkVmVfCcYjCwqBcV
IRm1E8948nGQiC35X54IUmPFxeNwlBEEp2DbxhixtSGvBF4nAUxFVRjjkg8I
nsIixIcM/AISRJvWF1UZPiZ/Xzx1jqBckbAByljMQRhM2Ri1sY8knyDO+rA9
SIV1F1HhYu5A5tG4tLKA5gIcfxI2EdG++vht7dguH20MZjExypQAS1niSYpD
rd5rDBx2fJyDJF/3N6ZPBs9Exf00AaxN4C9ApjxWWl2ZeUyIWCTIteX6BIxl
AayBGsHAHCfBNFMAhOKjm+LxuTPwNmqfsD72qQSqgwiQnEyc4yaAV5WbawVB
pxPyrz7/Y/YnAERS4YlGM36JJRY8C4SgWeFkjAVPOmKpI/xwTsglFOdyAhdp
BUNzhtp1qeSKJNLpM7K5FKzY9vVfCppqICMON8SHm1DjM4CuxOo3aOLHVQxK
2hfw+ptDVJsAWvoAn6AKkx0ii6XnI94dvdb5OH9/AHaImQX4CCRqk/BZHxMC
OAk8OmQRS5pBDfkxwIIgP4TxUATvcmq4EGG/1F9kIIJVYejDY1W3AbcY5Uih
SYYhUA5QIES0JQxMFogrikq2fAJwI2pf/xkcTEyzQkgzDzaUCOCLWKdxGJPR
f2XIbm2Hfoc4xYi7XIAkN+qOKoMbg+6IRWcoY1Ciov63YV4ynqbZy5hfB/Dt
koHuMqhOHI4YDn9FoaXjt1hR2IHhG7yXpBlTQ1LctcnDBMyuwKww/s1LJ4NR
AAWEJgEYlodWmcwBJSyziHz6ktQQQvzo5y4jQ7cc4eRVwfQQYRBGMhXgwMiI
jY49wkhUgEPN39sEJow8hs48DC5JHBzFiJQG9iSFFxGREoZ9SvvHRTRm1Gad
RVuCIXsApCjEKRMjnJPYWwBvb09CE2CA5KgCnhkDnZDpuUwCFUixpRg1jyg/
iq21r4EErMAdTQCnon6RAUaTIqBjYhsBakGCMT25NLVpG1zjKRajAZZggiYj
GY+OSHzqrck2mdv1O5J/o6cZHGExGqoIhhcyDO55XKP8oDlAqblJnPy49fm4
Jit4hTRGWIVNG4dZKgdugETTg2GPUj/MtkWFDyPdGBgdwYhAlSGeFOAeRFj5
EcI5ZZDW6gfYtl1jUMoILw5Vkdph1xUjwFkmwRU9hodOgFxZJvyNpvQblgIP
Q5wEFZUclAlMx6gxKK6QEUiSPAg8f/s6KPBDcJMThJPX1zcZzq0R9b7HKmXh
ChTgF3KtOh8CJxHh2afSAT2KjwrzVhm0NDJtpA6MoPC1D+gE7aIMX7wYB1yI
fSfAO4Bcn3EucHiFMvdPspAAiIA4JIJsJuKaT+LlExidqPBnASWAEpMT7seJ
OMLX6x0qw1e9/sQJxo6saR/dcoDGXmWbV0gCD9oHNGzBFYBRCbz4aa9FmE6w
ZOXQ6QW4CrHoWKI2MZKaHQMB4BGazVEmKtJZVUAZKo5IFahIJPw0pSz2qQju
AYO7EjX8ZWETz8IrR0JHyqGfJ3Mu/+eYqB9OgFEOg2mXAh8lBdAu6ZQi9MbU
9z+B/UrbngM9gw9LiBh5pBHlqIA7IYKDEcLsPgYEHf6afyWo4SE8KeoHHsOh
noM/UQTcgKHrCueLAiKE/DvCZoGQMDDfFIDmke+XYWOdoOOFLYsKhl78yzmp
33UIjo0Kg+b61YqwVWKoswmODwYm8gGQBAIbtufvLHnmpAMEMd/HsU72ODBS
FneQ+r3EcIqJqMN7m3fBNvYlatIEaAfIzhXRkFMyQIDqmqDakyjpdlK9iskp
3zBXm7kGi28D6Y7GgZLeTIKZb/Qzh5XEplyomLnHsOGm1DgWVBPSyOFpsEDL
5einnydWRIhsVWnwBttMhOvaleAuFiJaikfbIOM9tsuFIJOnTQ4jNBg8NTAF
ZY4F+CAjX4FHPy9Re9nwZ9XJ4GxTF0sF1jxkggzIjthVA07kYRQowbKnPf0X
UdJpWkm9JYlvDsBYYjEGBojiN0ELEi7F5NH90vPksIkW9yneizSXAFgKhUwF
JP1yAF0Z4Qd0qssUB0BeQXyrD7thGeAJvYyIKBcNG0eClWQbnwcNkleaxoPF
JSJEljL5nfA9D+C1RG3LVOmnnydtHjoTCRzpCPZbCuZZMgbTRFyC7o6AJBz6
5NaPi7DipQ0nve7VL5igfzDSqn9cghUOC+YkZS+089IFrvFQTuBlGaBSqSg4
PK4SIp5MgGGfilSqn6ACcH2VuEmZplTwgJIHYN4tAGSjufEBeoP2+F7GLECB
SaUIUQsLu3YFg636ralYAxIlwAOBbxshcXLzV3yIAiSEt5PLUdLYvLLA7ngY
h8WAzv7BcEsw9VYxLaV8+IRvqLPkGapo1WjewL8Agb/LBocaxZpE3H04XOHJ
mAAOa4T6DvECj7uJyP54f4cQnjAo1AIcRVVw9QlVRgTdHbHzErBihfYe4s+j
8xFqIoeNzR9LLeBRLkgnFiOoXG4+jgC7+O/nDsGQDPNKEUzmeuGRiz+OCRX9
rYCzlRcavVS7KaUG1oRMCMSApEGozfKOkHPG0+YKwB0ht/8CrSyYKjxAEh8E
P+rZRGaamCuFVI7Bkrcs073QnkEjUSygtEZsahGnGGUyMHAfDlFn6r0ZQhjS
dipk0PpG6FjqbUv0EVwz+ic6QPB8ZFoDQZr1/R/zLxndF6E2cdhl6O5kwFAS
qIYq09hLRSAUKcGPiTODoWcMx14FM1wRlCeGzt8png834RD3QZb5oSpxwCIE
cIkJ5AtGFgujNEIWSpoQqbqzEgAjR+xPoY5ABFJBlmZQz2NY0tfnlI9nRQA9
cJXr/lzADesf7UGEkT0L/gODfAIW/uOE6YRrYAzQQIEBt5L8jLTorCHCpYPk
fiHngzDYAa7GGBmIuDlGKGLS7zHBQYKkQh8hKs3khbx4MDMDqEUYmo8Cmmio
/GgHVOQxRGh9Y5APWaD0KjoE4vMoNZZeCkiz9cLg2lAn23wDiWKCPyABjalZ
XgDHarC+G8Ikzo42akTSuQBkkc8d0CgPrzfaZnMIgYzUhoiu4q+0CzWNdwoA
QUToDAmlB7Z9JGIHPLcQpCkG//CPtHYZIE8EDJ/HtJFEsOCGIkI8ImAISNoV
SLdUkE/ak9CIihSZJmCJUpF51IcEzVJzU5OQiCCQZf932YBowYPaoeLBxoja
YjBSjECYkeMmnUiEkaj/2xbSHB2eYkcwzm6mV3gZCjViQ0lMMDJuA60BqLwS
qmVdcomMF2CXiBEhyVQAiMGBWEt+J0iS7aGSCuPFulQyoFVw2DIS4CMmbEhx
PPhOEsboya8rqw9Wf4DBnABv3IQ2S3i1PFq7AHhIjHalbXQYgBLJIWeRx+Eo
wt2V0DZwKyfmcf9KelP45n79d8fhCfsYBkWIbZPRYMhQTChAqAgOAKNJAmP+
nnEC0yQQBCCGRRgQkGBIv9F60OQhAWz2uiao6o87J00qanibckPmITXEbzhO
pL0EYE76eQwofzpqvhkcM2Boy6ArMOhjA5xW9HOsr4Q+tdUTfj73ENAcQzmB
OCYSLAAOvAUFegSWpqrAD1eFlufvmscQVgFe1AQvAcsVwVGU4ybqgyg7QDih
AHIbJaZtW4RCTeisAoJV5AYMibkmW4IwSzHDbcdjyJiUiQBvI/jiMUDREwXP
SgaKi3UlgR7P4V20exsZd1gZo7cQdYYCIArXhKkkOIXJFBX0vx+DSyAeLDxh
CQau4CAIcLVEU8TDsjxB5oeM4iO2nzw6InKgQEwqwnw8AOAgoecJINKJ4Ncf
g+IotrkHwHlCBBdRa8IEXbcMy0IZVajelQLyMwIIA5m2Hy6oqgISFAh2RyMS
ZVIr6urNI7mHkI7wAlQA/m1NKLFAxVyeg6xDBQyrQP3BIyAhxpILEMwjACj2
28NEgF0+7EEJTquSX0UYDkAFuaSZzcW4wTF+oyL8u+NUtL6QpCkYJ4m4fJGV
AKSaBeGNgR2/LzVAxN8fB4gXIolQVZtCqtKdxTeM/QRnqIwhXSD8ZDg1s1FE
qcXQpyQIwIhxQ4lxfydBODj3Y5Ac+OinzlM3T8KflBu3dAn9MIkGBCOO/5fz
poA2QGiVSsr5JGQhINg8PIXrdRvDTp2j/Ha4MIfIduLYnxM2QnQHA5/0gDqr
QlIU0AkL7QxhbSnCB5OE7LYVqdRTO0E6I+5cEmLYWKHJ06LhYQnkA4Qtj7H+
378OCa2CJBL6F0nHzqGV5dCsKg0rQwTMyPo/9pohEEUqiCOpitB1+jhfYpAG
acuUUFtzHm7y7RMWdq48xgr1QRMD6o/gRKwCwiJQGJqfECxNMuT6jQIK4KHc
PDogZgnWIemIMAurzx1i2UldYqUfygrtZomDsApcl8ffQrtSf5Gw4kOYokKZ
K4Or337xDE5zCoRSkUiMmZ2M4ibjuk0GKxzqPMqF3/b+DhspZSA3dBQWWC4L
1pxKAR9gxSG+jYgNWyesj16RBac3wjScsAqxQajJb4BbAIHxQeXlf1ddjFJJ
MGGpcVKmzqoidh8hKsNnQgaLzAfU3GY+cJhTEwCfKjqRx0Culog5JMbxOGd5
TG/pLax9xkU4x3mUYh4hozIdKsmNHIARG9MIWWz0IO1SyYPjKiJujYOFOgvR
QQAiOoF8BfQnMYRyEDi3OScSIhwYiJg4lGUeV+8Yz1kEaKyi4vE020P+IcDT
+D0Rq4UF7EDGQ3yTUSchjiWhlwhE6hJNfZueBxon6f1AP5CAT8qIt1ER6tN0
yJjsCJgFtG+RIki8AgZGMtqM+lcRCDFu6mq9oUSayCI2iUHtOp/g6/QMFdHS
M2j8ZDCOQhzoMSbFMoV/g590TA7RhkRNKTQ28QyETgxs7kWuQThDTCElRPpF
7bEOPmKq5SStPksKFM1ADdFT0fmdCvJeAsUc2+5p/8VBYlAVqUqIQ+IjT7UA
wCtUaliMhMgfyAuwMDWOF4DosgjFYaBHY3DsinCll/EklV8jY0rjJLbaKK00
x4ssBoytY+DzFMulQz2i7W0PF9jmB4kSCnkzARA8eijXBwQZNCjN5ZpKD9qZ
bSpAxRArJMEAKMCmCAHOU75cQHE/yLpl4YdfRxTHEmnAQty+VSAbkf+vfuZf
U+y61DNolcPol46LiKyYmrMjDyaixHWpERb5oNhR+6EA2gTlN5uTheSEhUU1
g86HjsMIkxPqbzX5v3ZP3khfTeu7y/92T3a16SNL9+viHGp+xg5Xl5cxYRZ8
Ok//4Z48rzqL7/+te3Ja6em/fIzVX/dkZ2ulFjOqjEO4mB+tqv6l1XyYfpbD
PrMjX/uSr/WF//7asc/PrbLSLG/YqX/jeFSZ481xtJz3K/pKqkrfjPWP787f
42F/R1/NZT5kzNee334n+mGxYReLrTYYdixn4LSthAeVd+wzG2ojvHkW2Vp/
9Qa8zHSjdyhnmb1UneeeSd6Xq/I6daedaXId9ALenxg9bikP9ec00ZT8/jEP
zn3x6p9nQsR0K3mbHOKU2XDclx0fvW/9tAYMvI47w9TaDQZrJdmehXxnbPvc
JV4lo9PtzT8Gcz5wv/2EvAXDno/I20n/8b2df3zzCt+8hnPyaOD0h8Q1ed4X
8NeG1Fl5RD7uwbE/HaTpvTNIR/rACseTaqmNOGqhvFVsL0t6e+0iPoO3vz0u
K9bKDO2TB4/uxHiXJ+UeuCtmwbpKRx0JW4l7WvzR6bLXfZVP+IHIXD6205es
6bpgXi+/u8gO8SnNjOXSey0Gl4NdmGIShdtHFnbSmXiR18Z9afVen+r8mQ61
87TaKfxhlL1KJ9TMi/oYnXiDXcfuh3O8u7Z9b5nj6bXYWka67/R1P768Rktb
Eln2OjFLtyg/60Mxts7jlF9HWurfuZf26l+jBcvPx5k0Hb2r84v3yu0ytqpO
oZz6pp9+nUi+mIHHauy4Fx/tQpo4l+4xD27H6Jl759I8XZefu3DVRqUynca6
f2N95rq6d0bPsX94v/tLRdkGo8Uy0/TNphAWwTq8Htfbl8yY/s12rVyoP3t7
eio+G3fjM7NL+HQeq925U2qTINgOTtNTpg7W/qS/XMjbR39Y8peHn76+/G06
Dy7j/mzSu3LG8bETC3OkjjmJPw4t7XnoxBdr+jxMDffACKY2XVXTRW4MvsuZ
J+ezd7d7Yr9dY85dClfsft/HrJhvN/zYPETaYrsfe4dOfvoUs8ttcz1urGt8
iIPruLzNX4+N/TivrRV76LKL40h8bCfaYS7cRoU9f5/mnj7y4+i1HU07IRMr
2ui0LsVjr79eX1lFS4e6e3KfM+kwrYpS2JRnV7eL4UoovK89kt/PsXHaXqvZ
U4/LosNNldOyPw0/x+FXOA4GM26azaa7wZjXH+XeVt9HLnZzXefzF8N2PVZU
Dwq7P5ZJKgtFOC46sbzIS1+fzeLvfnTa3o2qDP1vOd0XnqjOP4EQhK7KrpRK
8jz1I+qb+8g7u+7aDx78Z3AbddzKZzOl1MrZZPV6h97e4Yowf7wL0ewuH93R
d7wN3/qj6oWVUBzMZzdRkv7rO1V32bg3v747isPK87uzqaRJqh8Ve8CPt0vV
fhuvz9z42vPP9Dl/8junWt/tgyP5YmqPs4VQrMv7V+0tl53t4Hi73YRN/65P
/Wf/FDH9y9EJi2IS3VKrsPsbJk1UaXSbaPPjeam9zkFy+A7CpzGaSnv90gl3
kpv3+oXzuj39y65M54xgj4rBVOSD7dytXr3LWDI9qTLdKptxy9RIVX7KRloe
RG9BSzq98dpzdkyhPkL/OJuEWnxVHd7eDzeX+XM2fNVb6BWo3zztGsfqefB0
ud6mGV/yrMMZXJx1SmWz78qFMf5+by/7e7A4d707JOFJ5PWD9d4uBgtT38+y
zcFZp/416x9u0icYOAdPlJmNwHSi21tk5cXkdFe3ScaGX2caVJtxcVE4Ptc/
O+MoFE78qrzN8yR8P7LvbXhp//HU8UHy3HjeeQWnin0Zqu+mvfyay75ztkr+
w2VLfjGOrtp+ufk400mlKs7FFBeVnFzjz0WUmPXypQf6vvPZP9eeVY7ZsHqm
s4d5UrnuRsi6d2FwSnSpGwuvwv2eXzcu0vzKv8nq/nqXTn1D6m9Hfavb4cTl
Z6G+7odtPrxcuNXg8p1dDtxlZfaYq/GdfJNedTNOK1HN6odVuave9TnoR6uX
4I2C1XvcOcgb6+BbhjTtXmWdubj15z0Pv0YpjFyNeaiGKTL9g/ziUyaowv7I
2QQq33+e3sfV+WBd085yw8y6m3w07/a35/W59xbu4zy1nQX3iKSZ+GUnmpBa
Xf+0cVZhOnM+yTFNomkw7fXu1lkQOsnju7iKQ32mPdPJNxb3A+1scgfjnRiX
Y90C2HHK2nN5oo0+D+XGRtJudv8478NhfRwvjJXaMW9OtZksg71u37a7r3fJ
xoOeWBXLdW94SeV8Ixtu99B7Tb2XdjKPt9mD1V/KoryIC+Nszb2OGWe5nIm8
xPcYe5Pvz3NDub2lx2TGC+aKOYzVqz9g3cmmv3lvzOWnO5aDkGGTxfT+XUyW
VkcZ6Y/PaLFj3I2hrr20FM+f99fK332R2eWjVfx99PxbPtDlreFl7Oq5G7ve
8vz83Jh3cCqnnbX4dva3xbIS90rf15b3y0K3nr49ukhu0M3SB8+dI82+TWZD
qbgeL8nM8efL80Yzff65Xaw60VaZO97s+OUkpZstVt3j3E3MjDNOsbl6nA+3
02Rv+lK8Yhejuznecbo7tAa8dPc8wbszRWf28Zh6mfn9zVr76Ha+fJ7qT+gw
CJw0Fo7MZHldr4zz0CrD6TIfOnXvJFcn232ehzZz3G+XnW+XiTyvMHfrwUW5
V093xveHby6c8d+++dlszqp0jMbWRdc+WXntS9fx1ZI8eRovd1ykB2nndM7V
hyanIufb+nWaVupjxagD19lcLvI9mQ+Wissl1eD5lj67aqIa7E0PpfEgv4df
1y3yjq+cruHXGvjx1VX6467zWoRKdSsWVfYYm1/D0QvLDcqBsl1wH4XfH3RJ
mRx0rh8Vx/s7HHb6sSI4U36Q+MXYs59SMRlvD7euHIrDkLN765W4vT033qor
rE+JwY33/sUKt97e5QZ28i6kDru9p6elLXr59j09G+Lio8YDXh9+q2DqP7b2
Z7g63INJ9zoeDfqz99a17l/xpLCD0r6smM+sc1bygd1zBtuuoFSj9WWTXx5P
P/lY0X10dPnAmgXKmlv4vm8Yx3nVu7PjzULcemlR2Prp1uuM0sf+6m/WYeyF
3vd1UzTFEsy4fqFrhzFmzMoI5Xgpsbfzi32y3+tio173Xng1l28j5g9+56oY
ueIuVMct6mZCZA/qc7V4sdaqcEJddYYrpquZ+igYHbyzFz0dfX0St8lGn40l
nQ9m846j9E2t2I+5pfMZ7acHYehfzDDSx7uPJ4l3qYo//fFcXnfn1vH8OgtG
tS2OJ3cmPoVZ9/EoOgY3KW03k7f7NJ4z5lF5vJ5hL0rTMZucn9k8c/KgvDhZ
Jea8wip7eZbev+fBfjb2xt1QH3aeCbdZ7IVLUW+knsWPx/cyPcmDo3+Zv7TH
SysF6c0nu/vYyp348fis3kI+6JZ+Yht+ps3OHWV2++q77lbhZ/aHYyfP2VW+
nQa9NJEkPTT5wtt7L4MzZ0Up1aUuUZyrZeuX3KnftRzJXGd24vOoPr+jl3V0
RaMa8vk+fs0/5sAYZcP+wTy+3rFV9803Tgviq+fcrkutUGV3urvzhX/t3MJk
L3Rfu8Okr93U63zHnK1p6M5272rsxZn/lZxb4Yx2fjaSOHuSP4fnyFkux1Hd
QHIzJ+hkq7xeAfPooHavc2chlWy/q5Tc42Jynst9M2WRFs9wwicCx3QnluN+
zMdZGKvGcsve77tthwlf1vu5EOTJ+x1478gycnU3ZEOPT+azW11F3VE1Y083
eTJ9i0Gxe/XKg3hNlLB+Ue/u0e6k7vKtBm/uc7e7xffMzpJJ9+3MjvfjV42m
I26XvxfqQ7bZ3f4QTdKnzeXK1O6l00fgncR80HkZj16vPosOS2ZX9Q9Cl40O
xWUhMfGZv+9vujFfSpeu5T3SIbewk8x8MxY/sqKRtcs4VZl2dvssVJSLVH68
BxNaSk8zvqthXt83bPXkOq/+ZeXbmdn3TPVWCM+VElvxOdq4290k9Pq62nkz
RjDeC9d+cEtdxvh6MRcNze9rfnlW2eX8FvuBOWNYbZqOR1P/+7Z87fAJ7CHn
hf7mrfY67GRjz4riO5uk45Cru8/718i6oZnfL9pj698DZbiKzutseJBYcZxr
Tszu8scpOlpRPy53aocR1eGga0ePzLvPuavIefdSzvWvsh9XkjnQuLe+3b7L
wWhVrXt8zGiWXt+bvqvwECTaemJ2XpviNZcL/ehs00jQVvI19V73UvLiPPDT
c6UdBCFd5u91ER/G7n040OM86u79vpvYp+uQ65y3mrH6atPFl+GNcxldjZHi
vzdGP/FUS/SP6ne40rTqc1GuRZAX/saWdi8zGtj8O8ml1aqzzrR4b3oTtaqG
tmwPtehRPkXr6LxUufvpjvbpbdeNda9XMcphPA19TkuSY7Ga9+bDmZJYnYzr
fc/n2Xyu2PWJ8BFSk+8W5axiTMGoO0fRkKKTs1uJviJ01/1Lb7DNrKFVpUl9
7m8ew7zz4AzHzyeThTjarubqQF52J9tHtZkezO2n2gwmQtHvlffYWsys/DZP
BszVy1+3j8xnO8WY551P3cEs1VT7dpNpqZ1801W2ecarm3t5rXqfXul+vSHv
HQZ2+syiszYsX4v+uzcMA2sVbWf1KzCX8/uS3871mzgXHHW1uIfiZf2ozn73
JLFFor4szdyedlnlJN1JXTi+Vn31eJ6UiXwcPt8dt27upPlyJ2+LzMvrE9jj
WCE0Pgv92duV37f8rNRgPN4r5fE02PZurFsvd1UJJvXynM/7Rac7XT9DZjcQ
7qftpoxTUTmqsSDzTPodSbZ5dYpB9hZu2fWsKxp7ZY5Wry/ugnBsPJglP713
xvnya8eqdSv8vvjWndO0PDG2rOxPxqpUPs/7qrgbh4J/6VZff9wqVnsw768r
ayu10CcLv1Pf3PnHeH4R7r7A9ivHv3zk+dyQg1FdGRSnemVuMv2e1vUxMBR7
p5FtJCtGF9TgkPdKxXp13sv32hX5uinPkol7XlwGYVfnl4zqm+9w6e/fK3au
nBenyWc2DAvdtphpflou9hE77F2s07Pz7u27em+asYVQRsn0Xhz3wo2Nu++9
/g61j9QXx/28Z8f1LpXSlZVN71tW3yb70pzGpeMGHfO656fmxzxHz2AbWVd9
q26ylPVu5sbJ11Hpy/3bpXfxZU1ihunxduyO57tQVb3+8PuSk1N97cvO/Wdv
yYqfRcAG7sdxr2JYlyP7OBWPweut7W12w4xkffA9qO/KeN+DgazOpfjtno2u
0vkMx3Hy9KTHfM2fvvluy4X6YcIM+49zbzB+dUPv1n1cbs/1bBhxb/VmPrcW
myjDNEqD4ts9d16Dh/3YnJ1SS9RdtFb9OD8urGfA34xN2K8m1ubBsSU/2Xsf
+XyWT0o8qUYid6wbud2Q59TOffG5FYNwcM3CTfd0H5hfxYhF5bVmg7lieoK0
PSgG9/6OhtXa1y6KyzvdhSTNpPg1HhwHr453fIeBxhu7z/rxNTY9VnXO4dme
3q1FcQ/52cz9aLZfvKTZuaucP551Es7rdO1d7ZeZmc9T5+QqmbY27elDXy6y
mbeRK+FUX6nGoVt8vHn/MfOru+l9Po/+xI8de+rtmWh07tr3aU/Jelpn82K2
qwljjI43783kRbrm3m58ZKzinKqMLeT73mHB6MEnGJsn43HOn88lP3i5oTy7
Vxtz0JE05vIsnFtixEaUl9xoyBmaPt2IZ21brV+mqeja7Whmcnh9DUbCenlk
VGGRStWqK56v9rsT192sPrztF/p5ydUHx82N2dm2OEz3XjAStNnItLpVbgSV
bY37p3h3lsTIdOyXzbnf7PnIO8l0GyfT2c7YjNJR9Yilc/yRZLVcrx7cfHuI
mePiEYiVZLl9ZrTr7o+jacRm5SYOtJJdCFKnXBztXMh8nUu7sZ9V9iMuVuOV
Pg31PCrW3eohCXYonF3VzGaWGn7Hb6eartnBdrbeHLNnJzxESv8c3aPjsQhv
FyHUpdfleuxX7i0N4o+18fjt2SvFwe5+H05CfseU/ZP9VrMzP5i8B6OOmV8N
le+uDoevdhW7sb3aa99opNQ3+y2f9hV58TxclEFPfYey/fjaamTXTedpFazn
Qph6h44k2pO6Kzjwr8C9TLKbwMSyH6fVzpvZyzNvmNedfdVTQ1KfORM81n3t
+AqU47Iu9vtjrH07+uJp8cnpfJe1iT0VstD2X2w8WLgj46z1zPAsP65pmvu7
8VIcTi7ZQrrV33PLOT+SC9VlOrrAqc5DmPg3K/3efP3du+hvNR1G1TeyhpO1
9bnN6yvarHsz1sp+XZfCnXBZMINwJ1T1Fe3ciS7Dc2XZM2U+F3Qze0o9Rj8v
xrvkbvc2oXR7jPfvualK6yB4MDtpVY4/ubrpPV/La+5m62EnZB7WsTxchp/F
RI743sGMg7nFybPF4+pXFRN+pacfzdjXLdu/ikc/fdW7MdmoF3nMCHUD03lU
5fXu9NXtlVPMZXG+7vh5+j7I7D47uir7DrO6N/DUwaaUxudt3eL0q7jcJ/7y
sJ5eK3PS4UbicXQt/OmyiIfr2Fq+XP+c6oq+nvb6o4PqCR9Tk3M+t0ZFeVx8
bel5UT7Os4rm84sonDu9zDouhSkzzsUPb0rrZfHU932mmp0f2w0vZY4cWqIR
H/qb24fllTCf+kV9MmXv7oavO8WyE95156vui2HdzL6qMD2beSp/xE9lTOO4
3vSXV6ykj4ejcsejvFGE/WQe8P5W4Bfl5OZYbEd9jcPoso2/2/PxM8mtncyl
+77PsGq9CdytOxKHy8HmmaqZWWl8lh5GvvGYhotsvh+896tZJ/om6/s3mjw3
SXB2b97iMpuZ3M3nL/3TMivuN5mrrD533ix3p/A23396C/uYKdFoqaraYVt2
bOvgbD1bd42F8z0KnmjZ9rXupxz3Zdz2xfJ2HdRb6HpQ9+aXu1vnun8Wo+VS
6zqzVFvW58JMVB9CdKm73u34cYi3z3HpJMnyMPc4fi0N9Fs2cNhXX6kLcVFf
H+bvMpkNP7rPM974HUwenavz5PsJs9quH/GuP6jy6aJnT8TpXrI2bqxJj9c5
EFXxwI3j4X0WDiRupk/uh8nyut9239dp5z2eVwqf6tdbORe/yzRbJZnAXILe
zlP0mfycLEafPHq6PbXQXsZ9Is4up/ovP/XXwbnLa7ezzTZn1dlPpKpKu87j
21M5dTIZzdXtzkw2XjAIvJwX/b2U5qJnzLyFOK1Pl93RHbObR2/+6ejfjT/b
B7n7+i62w4F55xTfepy9TWF+I2PKh9dd33B0X5ws+cfD2vT7j/23+CiGOznd
eGfXmZlVWlpXIZBy7rir+P5xpwZi8WQ2G05x1ml8MF2TS3XzsGZXprJY3aPo
qV1Lw48rK3SYzsqXlputxe99Zvqxs3RVOY+tXoyKN6OGZpR0N2un994l/fdC
tnavvip0j+anHC6dePXa63nHce1rwWxvV80NnVXe3SXv5Yn/mEd+vLxe87N7
vuTXuXbuZi7v659p/7WV7ZAzBTcS8vXz2pm4h6dq3LPBcrOcbKe9wZyZ+1ve
VerraKGmA2E1t76D+nntc6GnVslROr2HVjdRtc9htel+Opu9eVGWX89V1tvL
5jsZPU96ku4ct5dz9aP0pvY61XXuGyf5LFlaWejdtf3Jta31OtptqmnnYT/v
r3BvdesFW/cVm7yYrdbJcPOqeF0Xe+/n2gxvhm0WuWd8ha53ftxdju8ZzPAy
1ees39mn33u/8FNWD85123BQ5uGxZLrj0+Dq6xfBGNrOWk6XXlH9r//1/x8m
0w9PxaXK4yg9x8Wj7Pzn/1cgryWO/te/JX5exv/2XyRLxi9O5Z/kcv+zfpbl
H+PyLPP48z/+rPziUv6Z+uerX/gnEk8yz8JD3TP9sR/m5VCUf/wi+qNd7vHn
z+BSFHGe47cc4vyaPPM/5TNN45JE1NDvvMevLK7Kf2/ia6JL+CQv68+zjEl8
TX55/Lkkfx7x+/EnuV/Of8rsnOX+/b+/sfzzv+2VwjAco/zH/+j8P/97rWs8
J6v/gV9O/k0RWOY//t8/fvmnIq+l/t///M//eU9CRWaUICv/67/+/U/zZtPL
n0f9n0P8x0fKRVn/5U79D2X896/9+59/0y7XD4nM8fPK/5R/zv6pfqWPQ/2l
8k/sl1l8x9/O4/qxxfd7/d6v90sR/9uf/9lpXg/7H//e+T8AeSHxShoBAA==

-->

</rfc>
