<?xml version='1.0' encoding='utf-8'?>
<!DOCTYPE rfc [
  <!ENTITY nbsp    "&#160;">
  <!ENTITY zwsp   "&#8203;">
  <!ENTITY nbhy   "&#8209;">
  <!ENTITY wj     "&#8288;">
]>
<?xml-stylesheet type="text/xsl" href="rfc2629.xslt" ?>
<!-- generated by https://github.com/cabo/kramdown-rfc version 1.7.19 (Ruby 3.3.3) -->
<rfc xmlns:xi="http://www.w3.org/2001/XInclude" ipr="trust200902" docName="draft-ietf-lamps-x509-shbs-06" category="std" consensus="true" submissionType="IETF" tocInclude="true" sortRefs="true" symRefs="true" version="3">
  <!-- xml2rfc v2v3 conversion 3.23.2 -->
  <front>
    <title abbrev="HSS and XMSS for X.509">Internet X.509 Public Key Infrastructure: Algorithm Identifiers for HSS and XMSS</title>
    <seriesInfo name="Internet-Draft" value="draft-ietf-lamps-x509-shbs-06"/>
    <author initials="D." surname="Van Geest" fullname="Daniel Van Geest">
      <organization>CryptoNext Security</organization>
      <address>
        <email>daniel.vangeest@cryptonext-security.com</email>
      </address>
    </author>
    <author initials="K." surname="Bashiri" fullname="Kaveh Bashiri">
      <organization>BSI</organization>
      <address>
        <email>kaveh.bashiri.ietf@gmail.com</email>
      </address>
    </author>
    <author initials="S." surname="Fluhrer" fullname="Scott Fluhrer">
      <organization>Cisco Systems</organization>
      <address>
        <email>sfluhrer@cisco.com</email>
      </address>
    </author>
    <author initials="S." surname="Gazdag" fullname="Stefan Gazdag">
      <organization>genua GmbH</organization>
      <address>
        <email>ietf@gazdag.de</email>
      </address>
    </author>
    <author initials="S." surname="Kousidis" fullname="Stavros Kousidis">
      <organization>BSI</organization>
      <address>
        <email>kousidis.ietf@gmail.com</email>
      </address>
    </author>
    <date year="2024" month="October" day="04"/>
    <area>sec</area>
    <workgroup>LAMPS - Limited Additional Mechanisms for PKIX and SMIME</workgroup>
    <keyword>Internet-Draft</keyword>
    <abstract>
      <?line 141?>

<t>This document specifies algorithm identifiers and ASN.1 encoding formats for
the stateful hash-based signature (HBS) schemes Hierarchical Signature System
(HSS), eXtended Merkle Signature Scheme (XMSS), and XMSS^MT, a multi-tree
variant of XMSS. This specification applies to the Internet X.509 Public Key
infrastructure (PKI) when those digital signatures are used in Internet X.509
certificates and certificate revocation lists.</t>
    </abstract>
    <note removeInRFC="true">
      <name>About This Document</name>
      <t>
        Status information for this document may be found at <eref target="https://datatracker.ietf.org/doc/draft-ietf-lamps-x509-shbs/"/>.
      </t>
      <t>
        Discussion of this document takes place on the
        LAMPS Working Group mailing list (<eref target="mailto:spasm@ietf.org"/>),
        which is archived at <eref target="https://mailarchive.ietf.org/arch/browse/spasm/"/>.
        Subscribe at <eref target="https://www.ietf.org/mailman/listinfo/spasm/"/>.
      </t>
      <t>Source for this draft and an issue tracker can be found at
        <eref target="https://github.com/x509-hbs/draft-x509-shbs"/>.</t>
    </note>
  </front>
  <middle>
    <?line 150?>

<section anchor="introduction">
      <name>Introduction</name>
      <t>Stateful HBS schemes such as HSS, XMSS and XMSS^MT
combine Merkle trees with One Time Signatures (OTS) in order to provide digital
signature schemes that remain secure even when quantum computers become
available. Their theoretic security is well understood and depends only on the
security of the underlying hash function. As such they can serve as an
important building block for quantum computer resistant information and
communication technology.</t>
      <t>A stateful HBS private key is a finite collection of OTS keys, hence only a
limited number of messages can be signed and the private key's state must be
updated and persisted after signing to prevent reuse of OTS keys.  While the
right selection of algorithm parameters would allow a private key to sign a
virtually unbounded number of messages (e.g. 2^60), this is at the cost of a
larger signature size and longer signing time. Due to the statefulness of the
private key and the limited number of signatures that can be created, stateful HBS schemes
might not be appropriate for use in interactive protocols. However, in some use
cases the deployment of stateful HBS schemes may be appropriate. Such use cases are described
and discussed in <xref target="use-cases-shbs-x509"/>.</t>
    </section>
    <section anchor="conventions-and-definitions">
      <name>Conventions and Definitions</name>
      <t>The key words "<bcp14>MUST</bcp14>", "<bcp14>MUST NOT</bcp14>", "<bcp14>REQUIRED</bcp14>", "<bcp14>SHALL</bcp14>", "<bcp14>SHALL
NOT</bcp14>", "<bcp14>SHOULD</bcp14>", "<bcp14>SHOULD NOT</bcp14>", "<bcp14>RECOMMENDED</bcp14>", "<bcp14>NOT RECOMMENDED</bcp14>",
"<bcp14>MAY</bcp14>", and "<bcp14>OPTIONAL</bcp14>" in this document are to be interpreted as
described in BCP 14 <xref target="RFC2119"/> <xref target="RFC8174"/> when, and only when, they
appear in all capitals, as shown here.</t>
      <?line -18?>

</section>
    <section anchor="use-cases-shbs-x509">
      <name>Use Cases of Stateful HBS Schemes in X.509</name>
      <t>As described in the Security Considerations of <xref target="sec-security"/>, it is
imperative that stateful HBS implementations do not reuse OTS signatures. This makes
stateful HBS algorithms inappropriate for general use cases. The exact conditions
under which stateful HBS certificates may be used is left to certificate policies <xref target="RFC3647"/>.
However the intended use of stateful HBS schemes as described by <xref target="SP800208"/> can be used as a
guideline:</t>
      <blockquote>
        <t>1) it is necessary to implement a digital signature scheme in the near
future; <br/>
2) the implementation will have a long lifetime; and <br/>
3) it would not be practical to transition to a different digital signature
scheme once the implementation has been deployed.</t>
      </blockquote>
      <t>In addition, since a stateful HBS private key can only generate a finite number of
signatures, use cases for stateful HBS public keys in certificates should have a
predictable range of the number of signatures that will be generated, falling
safely below the maximum number of signatures that a private key can generate.</t>
      <t>Use cases where stateful HBS public keys in certificates may be appropriate due to
the relatively small number of signatures generated and the signer's ability
to enforce security restrictions on the signing environment include:</t>
      <ul spacing="normal">
        <li>
          <t>Firmware signing (Section 1.1 of <xref target="SP800208"/>, Table IV of <xref target="CNSA2.0"/>, Section
6.7 of <xref target="BSI"/>)</t>
        </li>
        <li>
          <t>Software signing (Table IV of <xref target="CNSA2.0"/>, <xref target="ANSSI"/>)</t>
        </li>
        <li>
          <t>Certification Authority (CA) certificates.</t>
        </li>
      </ul>
      <t>In each of these cases, the operator is able to control their signing
environment such that signatures are generated in hardware cryptographic
modules and audited before the signature is published, in order to prevent OTS
key reuse.</t>
      <t>Generally speaking, stateful HBS public keys are not appropriate for use
in end-entity certificates, however in the firmware and software signing cases
signature generation will often be more tightly controlled. Some
manufactures use common and well-established key formats like X.509 for their
code signing and update mechanisms. Also there are multi-party IoT ecosystems
where publicly trusted code signing certificates are useful.</t>
      <t>In general, root CAs <xref target="RFC4949"/> generate signatures in a more secure environment and issue
fewer certificates than subordinate CAs <xref target="RFC4949"/>. This makes the use of stateful HBS public
keys more appropriate in root CA certificates than in subordinate CA
certificates. However, if a subordinate CA can match the security and
signature count restrictions of a root CA, for example if the subordinate CA
only issues code-signing certificates, then using a stateful HBS public key in the
subordinate CA certificate may be possible.</t>
    </section>
    <section anchor="algorithm-identifiers-and-parameters">
      <name>Algorithm Identifiers and Parameters</name>
      <t>In this document, we define new OIDs for identifying the different stateful
hash-based signature algorithms. An additional OID is defined in <xref target="I-D.draft-ietf-lamps-rfc8708bis"/> and
repeated here for convenience. For all of the OIDs, the parameters <bcp14>MUST</bcp14> be
absent.</t>
      <section anchor="hss-algorithm-identifier">
        <name>HSS Algorithm Identifier</name>
        <t>The object identifier and public key algorithm identifier for HSS is defined in
<xref target="I-D.draft-ietf-lamps-rfc8708bis"/>. The definitions are repeated here for reference.</t>
        <t>The object identifier for an HSS public key is <tt>id-alg-hss-lms-hashsig</tt>:</t>
        <artwork><![CDATA[
   id-alg-hss-lms-hashsig  OBJECT IDENTIFIER ::= {
      iso(1) member-body(2) us(840) rsadsi(113549) pkcs(1) pkcs9(9)
      smime(16) alg(3) 17 }
]]></artwork>
        <t>Note that the <tt>id-alg-hss-lms-hashsig</tt> algorithm identifier is also referred to
as <tt>id-alg-mts-hashsig</tt>. This synonym is based on the terminology used in an
early draft of the document that became <xref target="RFC8554"/>.</t>
        <t>The public key and signature values identify the hash function and the height used in the
HSS/LMS tree. <xref target="RFC8554"/> and <xref target="SP800208"/> define these values, but an IANA registry
<xref target="IANA-LMS"/> permits the registration of additional identifiers in the future.</t>
      </section>
      <section anchor="xmss-algorithm-identifier">
        <name>XMSS Algorithm Identifier</name>
        <t>The object identifier for an XMSS public key is <tt>id-alg-xmss-hashsig</tt>:</t>
        <artwork><![CDATA[
   id-alg-xmss-hashsig  OBJECT IDENTIFIER ::= {
      iso(1) identified-organization(3) dod(6) internet(1)
      security(5) mechanisms(5) pkix(7) algorithms(6) 34 }
]]></artwork>
        <t>The public key and signature values identify the hash function and the height used in the
XMSS tree. <xref target="RFC8391"/> and <xref target="SP800208"/> define these values, but an IANA registry
<xref target="IANA-XMSS"/> permits the registration of additional identifiers in the future.</t>
      </section>
      <section anchor="xmssmt-algorithm-identifier">
        <name>XMSS^MT Algorithm Identifier</name>
        <t>The object identifier for an XMSS^MT public key is <tt>id-alg-xmssmt-hashsig</tt>:</t>
        <artwork><![CDATA[
   id-alg-xmssmt-hashsig  OBJECT IDENTIFIER ::= {
      iso(1) identified-organization(3) dod(6) internet(1)
      security(5) mechanisms(5) pkix(7) algorithms(6) 35 }
]]></artwork>
        <t>The public key and signature values identify the hash function and the height used in the
XMSS^MT tree. <xref target="RFC8391"/> and <xref target="SP800208"/> define these values, but an IANA registry
<xref target="IANA-XMSS"/> permits the registration of additional identifiers in the future.</t>
      </section>
    </section>
    <section anchor="public-key-identifiers">
      <name>Public Key Identifiers</name>
      <t>Certificates conforming to <xref target="RFC5280"/> can convey a public key for any public key
algorithm. The certificate indicates the algorithm through an algorithm
identifier. An algorithm identifier consists of an OID and optional parameters.</t>
      <t><xref target="RFC8554"/> and <xref target="RFC8391"/> define the raw octet string encodings of the public
keys used in this document. When used in a SubjectPublicKeyInfo type, the
subjectPublicKey BIT STRING contains the raw octet string encodings of the
public keys.</t>
      <t>This document defines ASN.1 OCTET STRING types for encoding the public keys
when not used in a SubjectPublicKeyInfo. The OCTET STRING is mapped to a
subjectPublicKey (a value of type BIT STRING) as follows: the most significant
bit of the OCTET STRING value becomes the most significant bit of the BIT
STRING value, and so on; the least significant bit of the OCTET STRING
becomes the least significant bit of the BIT STRING.</t>
      <section anchor="hss-public-keys">
        <name>HSS Public Keys</name>
        <t>The HSS public key identifier is as follows:</t>
        <artwork><![CDATA[
   pk-HSS-LMS-HashSig PUBLIC-KEY ::= {
      IDENTIFIER id-alg-hss-lms-hashsig
      -- KEY no ASN.1 wrapping --
      PARAMS ARE absent
      CERT-KEY-USAGE
         { digitalSignature, nonRepudiation, keyCertSign, cRLSign } }
]]></artwork>
        <t>The HSS public key is defined as follows:</t>
        <artwork><![CDATA[
   HSS-LMS-HashSig-PublicKey ::= OCTET STRING
]]></artwork>
        <t><xref target="RFC8554"/> defines the raw octet string encoding of an HSS public key using the
<tt>hss_public_key</tt> structure. See <xref target="SP800208"/> and <xref target="RFC8554"/> for more information on
the contents and format of an HSS public key. Note that the single-tree signature
scheme LMS is instantiated as HSS with number of levels being equal to 1.</t>
      </section>
      <section anchor="xmss-public-keys">
        <name>XMSS Public Keys</name>
        <t>The XMSS public key identifier is as follows:</t>
        <artwork><![CDATA[
   pk-XMSS-HashSig PUBLIC-KEY ::= {
      IDENTIFIER id-alg-xmss-hashsig
      -- KEY no ASN.1 wrapping --
      PARAMS ARE absent
      CERT-KEY-USAGE
         { digitalSignature, nonRepudiation, keyCertSign, cRLSign } }
]]></artwork>
        <t>The XMSS public key is defined as follows:</t>
        <artwork><![CDATA[
   XMSS-HashSig-PublicKey ::= OCTET STRING
]]></artwork>
        <t><xref target="RFC8391"/> defines the raw octet string encoding of an HSS public key using the
<tt>xmss_public_key</tt> structure. See <xref target="SP800208"/> and <xref target="RFC8391"/> for more information
on the contents and format of an XMSS public key.</t>
      </section>
      <section anchor="xmssmt-public-keys">
        <name>XMSS^MT Public Keys</name>
        <t>The XMSS^MT public key identifier is as follows:</t>
        <artwork><![CDATA[
   pk-XMSSMT-HashSig PUBLIC-KEY ::= {
      IDENTIFIER id-alg-xmssmt-hashsig
      -- KEY no ASN.1 wrapping --
      PARAMS ARE absent
      CERT-KEY-USAGE
         { digitalSignature, nonRepudiation, keyCertSign, cRLSign } }
]]></artwork>
        <t>The XMSS^MT public key is defined as follows:</t>
        <artwork><![CDATA[
   XMSSMT-HashSig-PublicKey ::= OCTET STRING
]]></artwork>
        <t><xref target="RFC8391"/> defines the raw octet string encoding of an HSS public key using the
<tt>xmssmt_public_key</tt> structure. See <xref target="SP800208"/> and <xref target="RFC8391"/> for more information
on the contents and format of an XMSS^MT public key.</t>
      </section>
    </section>
    <section anchor="key-usage-bits">
      <name>Key Usage Bits</name>
      <t>The intended application for the key is indicated in the keyUsage certificate
extension <xref target="RFC5280"/>.
When id-alg-hss-lms-hashsig, id-alg-xmss-hashsig or id-alg-xmssmt-hashsig appears in the SubjectPublicKeyInfo
field of a CA X.509 certificate <xref target="RFC5280"/>, the
certificate key usage extension <bcp14>MUST</bcp14> contain at least one of the
following values: digitalSignature, nonRepudiation, keyCertSign, or
cRLSign. However, it <bcp14>MUST NOT</bcp14> contain other values.</t>
      <t>When id-alg-hss-lms-hashsig, id-alg-xmss-hashsig or id-alg-xmssmt-hashsig appears in the SubjectPublicKeyInfo
field of an end entity X.509 certificate <xref target="RFC5280"/>, the certificate key usage
extension <bcp14>MUST</bcp14> contain at least one of the following values: digitalSignature,
nonRepudiation or cRLSign. However, it <bcp14>MUST NOT</bcp14> contain other values.</t>
    </section>
    <section anchor="signature-algorithms">
      <name>Signature Algorithms</name>
      <t>This section identifies OIDs for signing using HSS, XMSS, and XMSS^MT. When
these algorithm identifiers appear in the algorithm field as an
AlgorithmIdentifier, the encoding <bcp14>MUST</bcp14> omit the parameters field. That is, the
AlgorithmIdentifier <bcp14>SHALL</bcp14> be a SEQUENCE of one component, one of the OIDs
defined in the following subsections.</t>
      <t>When the signature algorithm identifiers described in this document are used to
create a signature on a message, no digest algorithm is applied to the message
before signing.  That is, the full data to be signed is signed rather than
a digest of the data.</t>
      <t>The format of an HSS signature is described in <xref section="6.2" sectionFormat="of" target="RFC8554"/>. The format
of an XMSS signature is described in <xref section="B.2" sectionFormat="of" target="RFC8391"/> and the format of
an XMSS^MT signature is described in <xref section="C.2" sectionFormat="of" target="RFC8391"/>.
The octet string representing the signature is encoded
directly in a BIT STRING without adding any additional ASN.1 wrapping. For
the Certificate and CertificateList structures, the octet string is encoded
in the "signatureValue" BIT STRING field.</t>
      <section anchor="hss-signature-algorithm">
        <name>HSS Signature Algorithm</name>
        <t>The HSS public key OID is also used to specify that an HSS signature was
generated on the full message, i.e. the message was not hashed before being
processed by the HSS signature algorithm.</t>
        <artwork><![CDATA[
   id-alg-hss-lms-hashsig OBJECT IDENTIFIER ::= {
      iso(1) member-body(2) us(840) rsadsi(113549) pkcs(1) pkcs9(9)
      smime(16) alg(3) 17 }
]]></artwork>
        <t>See <xref target="SP800208"/> and <xref target="RFC8554"/> for more information on the contents and
format of an HSS signature.</t>
      </section>
      <section anchor="xmss-signature-algorithm">
        <name>XMSS Signature Algorithm</name>
        <t>The id-alg-xmss-hashsig public key OID is also used to specify that an XMSS signature was
generated on the full message, i.e. the message was not hashed before being
processed by the XMSS signature algorithm.</t>
        <t>See <xref target="SP800208"/> and <xref target="RFC8391"/> for more information on the contents and
format of an XMSS signature.</t>
        <t>The signature generation <bcp14>MUST</bcp14> be performed according to 7.2 of
<xref target="SP800208"/>.</t>
      </section>
      <section anchor="xmssmt-signature-algorithm">
        <name>XMSS^MT Signature Algorithm</name>
        <t>The id-alg-xmssmt-hashsig public key OID is also used to specify that an XMSS^MT signature
was generated on the full message, i.e. the message was not hashed before being
processed by the XMSS^MT signature algorithm.</t>
        <t>See <xref target="SP800208"/> and <xref target="RFC8391"/> for more information on the contents and
format of an XMSS^MT signature.</t>
        <t>The signature generation <bcp14>MUST</bcp14> be performed according to 7.2 of
<xref target="SP800208"/>.</t>
      </section>
    </section>
    <section anchor="key-generation">
      <name>Key Generation</name>
      <t>The key generation for XMSS and XMSS^MT <bcp14>MUST</bcp14> be performed according to 7.2 of
<xref target="SP800208"/></t>
    </section>
    <section anchor="sec-asn1">
      <name>ASN.1 Module</name>
      <t>For reference purposes, the ASN.1 syntax is presented as an ASN.1 module here.
This ASN.1 Module builds upon the conventions established in <xref target="RFC5911"/>.</t>
      <artwork><![CDATA[
X509-SHBS-2024
  { iso(1) identified-organization(3) dod(6) internet(1) security(5)
    mechanisms(5) pkix(7) id-mod(0) id-mod-pkix1-shbs-2024(TBD) }

DEFINITIONS IMPLICIT TAGS ::= BEGIN

EXPORTS ALL;

IMPORTS
  PUBLIC-KEY, SIGNATURE-ALGORITHM
    FROM AlgorithmInformation-2009  -- [RFC5911]
      { iso(1) identified-organization(3) dod(6) internet(1)
        security(5) mechanisms(5) pkix(7) id-mod(0)
        id-mod-algorithmInformation-02(58) }

  sa-HSS-LMS-HashSig, pk-HSS-LMS-HashSig
    FROM MTS-HashSig-2013
      { iso(1) member-body(2) us(840) rsadsi(113549) pkcs(1) pkcs9(9)
        id-smime(16) id-mod(0) id-mod-mts-hashsig-2013(64) };

--
-- Object Identifiers
--

-- id-alg-hss-lms-hashsig is defined in {{I-D.draft-ietf-lamps-rfc8708bis}}

id-alg-xmss-hashsig  OBJECT IDENTIFIER ::= {
   iso(1) identified-organization(3) dod(6) internet(1) security(5)
   mechanisms(5) pkix(7) algorithms(6) 34 }

id-alg-xmssmt-hashsig  OBJECT IDENTIFIER ::= {
   iso(1) identified-organization(3) dod(6) internet(1) security(5)
   mechanisms(5) pkix(7) algorithms(6) 35 }

--
-- Signature Algorithms and Public Keys
--

-- sa-HSS-LMS-HashSig is defined in {{I-D.draft-ietf-lamps-rfc8708bis}}

sa-XMSS-HashSig SIGNATURE-ALGORITHM ::= {
   IDENTIFIER id-alg-xmss-hashsig
   PARAMS ARE absent
   PUBLIC-KEYS { pk-XMSS-HashSig }
   SMIME-CAPS { IDENTIFIED BY id-alg-xmss-hashsig } }

sa-XMSSMT-HashSig SIGNATURE-ALGORITHM ::= {
   IDENTIFIER id-alg-xmssmt-hashsig
   PARAMS ARE absent
   PUBLIC-KEYS { pk-XMSSMT-HashSig }
   SMIME-CAPS { IDENTIFIED BY id-alg-xmssmt-hashsig } }

-- pk-HSS-LMS-HashSig is defined in {{I-D.draft-ietf-lamps-rfc8708bis}}

pk-XMSS-HashSig PUBLIC-KEY ::= {
   IDENTIFIER id-alg-xmss-hashsig
   -- KEY no ASN.1 wrapping --
   PARAMS ARE absent
   CERT-KEY-USAGE
      { digitalSignature, nonRepudiation, keyCertSign, cRLSign } }

pk-XMSSMT-HashSig PUBLIC-KEY ::= {
   IDENTIFIER id-alg-xmssmt-hashsig
   -- KEY no ASN.1 wrapping --
   PARAMS ARE absent
   CERT-KEY-USAGE
      { digitalSignature, nonRepudiation, keyCertSign, cRLSign } }

--
-- Public Key (pk-) Algorithms
--
PublicKeys PUBLIC-KEY ::= {
   -- This expands PublicKeys from RFC 5912
   pk-HSS-LMS-HashSig |
   pk-XMSS-HashSig |
   pk-XMSSMT-HashSig,
   ...
}

--
-- Signature Algorithms (sa-)
--
SignatureAlgs SIGNATURE-ALGORITHM ::= {
   -- This expands SignatureAlgorithms from RFC 5912
   sa-HSS-LMS-HashSig |
   sa-XMSS-HashSig |
   sa-XMSSMT-HashSig,
   ...
}

END
]]></artwork>
    </section>
    <section anchor="sec-security">
      <name>Security Considerations</name>
      <t>The security requirements of <xref target="SP800208"/> <bcp14>MUST</bcp14> be taken into account.</t>
      <t>As stateful HBS private keys can only generate a limited number of signatures, a
user needs to be aware of the total number of signatures they intend to
generate in their use case, otherwise they risk exhausting the number of OTS
keys in their private key.</t>
      <t>For stateful HBS schemes, it is crucial to stress the importance of correct state management.
If an attacker were able to obtain signatures for two different messages
created using the same OTS key, then it would become computationally feasible
for that attacker to create forgeries <xref target="BH16"/>. As noted in <xref target="MCGREW"/> and
<xref target="ETSI-TR-103-692"/>, extreme care needs to be taken in order to avoid the risk
that an OTS key will be reused accidentally.  This is a new requirement that
most developers will not be familiar with and requires careful handling.</t>
      <t>Various strategies for a correct state management can be applied:</t>
      <ul spacing="normal">
        <li>
          <t>Implement a record of all signatures generated by a key pair associated
with a stateful HBS instance. This record may be stored outside the
device which is used to generate the signature. Check the record to
prevent OTS key reuse before a new signature is released. Drop the new
signature and hit your PANIC button if you spot OTS key reuse.</t>
        </li>
        <li>
          <t>Use a stateful HBS instance only for a moderate number of signatures such
that it is always practical to keep a consistent record and be able to
unambiguously trace back all generated signatures.</t>
        </li>
        <li>
          <t>Apply the state reservation strategy described in Section 5 of <xref target="MCGREW"/>, where
upcoming states are reserved in advance by the signer. In this way the number of
state synchronisations between nonvolatile and volatile memory is reduced.</t>
        </li>
      </ul>
    </section>
    <section anchor="backup-and-restore-management">
      <name>Backup and Restore Management</name>
      <t>Certificate Authorities have high demands in order to ensure the availability
of signature generation throughout the validity period of signing key pairs.</t>
      <t>Usual backup and restore strategies when using a stateless signature scheme
(e.g. SLH-DSA) are to duplicate private keying material and to operate
redundant signing devices or to store and safeguard a copy of the private
keying material such that it can be used to set up a new signing device in case
of technical difficulties.</t>
      <t>For stateful HBS schemes, such straightforward backup and restore strategies will lead to OTS
reuse with high probability as a correct state management is not guaranteed.
Strategies for maintaining availability and keeping a correct state are
described in Section 7 of <xref target="SP800208"/>.</t>
    </section>
    <section anchor="iana-considerations">
      <name>IANA Considerations</name>
      <t>One object identifier for the ASN.1 module in {sec-asn1} is requested
for the SMI Security for PKIX Module Identifiers (1.3.6.1.5.5.7.0)
registry:</t>
      <table>
        <thead>
          <tr>
            <th align="left">Decimal</th>
            <th align="left">Description</th>
            <th align="left">References</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">TBD</td>
            <td align="left">id-mod-pkix1-shbs-2024</td>
            <td align="left">[EDNOTE: THIS RFC]</td>
          </tr>
        </tbody>
      </table>
      <t>IANA has updated the "SMI Security for PKIX Algorithms" (1.3.6.1.5.5.7.6)
registry <xref target="SMI-PKIX"/> with two additional entries:</t>
      <table>
        <thead>
          <tr>
            <th align="left">Decimal</th>
            <th align="left">Description</th>
            <th align="left">References</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">34</td>
            <td align="left">id-alg-xmss-hashsig</td>
            <td align="left">[EDNOTE: THIS RFC]</td>
          </tr>
          <tr>
            <td align="left">35</td>
            <td align="left">id-alg-xmssmt-hashsig</td>
            <td align="left">[EDNOTE: THIS RFC]</td>
          </tr>
        </tbody>
      </table>
    </section>
  </middle>
  <back>
    <references anchor="sec-combined-references">
      <name>References</name>
      <references anchor="sec-normative-references">
        <name>Normative References</name>
        <reference anchor="I-D.draft-ietf-lamps-rfc8708bis">
          <front>
            <title>Use of the HSS/LMS Hash-Based Signature Algorithm in the Cryptographic Message Syntax (CMS)</title>
            <author fullname="R. Housley" initials="R." surname="Housley"/>
            <date month="February" year="2020"/>
            <abstract>
              <t>This document specifies the conventions for using the Hierarchical Signature System (HSS) / Leighton-Micali Signature (LMS) hash-based signature algorithm with the Cryptographic Message Syntax (CMS). In addition, the algorithm identifier and public key syntax are provided. The HSS/LMS algorithm is one form of hash-based digital signature; it is described in RFC 8554.</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="8708"/>
          <seriesInfo name="DOI" value="10.17487/RFC8708"/>
        </reference>
        <reference anchor="RFC5911">
          <front>
            <title>New ASN.1 Modules for Cryptographic Message Syntax (CMS) and S/MIME</title>
            <author fullname="P. Hoffman" initials="P." surname="Hoffman"/>
            <author fullname="J. Schaad" initials="J." surname="Schaad"/>
            <date month="June" year="2010"/>
            <abstract>
              <t>The Cryptographic Message Syntax (CMS) format, and many associated formats, are expressed using ASN.1. The current ASN.1 modules conform to the 1988 version of ASN.1. This document updates those ASN.1 modules to conform to the 2002 version of ASN.1. There are no bits-on-the-wire changes to any of the formats; this is simply a change to the syntax. This document is not an Internet Standards Track specification; it is published for informational purposes.</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="5911"/>
          <seriesInfo name="DOI" value="10.17487/RFC5911"/>
        </reference>
        <reference anchor="RFC5280">
          <front>
            <title>Internet X.509 Public Key Infrastructure Certificate and Certificate Revocation List (CRL) Profile</title>
            <author fullname="D. Cooper" initials="D." surname="Cooper"/>
            <author fullname="S. Santesson" initials="S." surname="Santesson"/>
            <author fullname="S. Farrell" initials="S." surname="Farrell"/>
            <author fullname="S. Boeyen" initials="S." surname="Boeyen"/>
            <author fullname="R. Housley" initials="R." surname="Housley"/>
            <author fullname="W. Polk" initials="W." surname="Polk"/>
            <date month="May" year="2008"/>
            <abstract>
              <t>This memo profiles the X.509 v3 certificate and X.509 v2 certificate revocation list (CRL) for use in the Internet. An overview of this approach and model is provided as an introduction. The X.509 v3 certificate format is described in detail, with additional information regarding the format and semantics of Internet name forms. Standard certificate extensions are described and two Internet-specific extensions are defined. A set of required certificate extensions is specified. The X.509 v2 CRL format is described in detail along with standard and Internet-specific extensions. An algorithm for X.509 certification path validation is described. An ASN.1 module and examples are provided in the appendices. [STANDARDS-TRACK]</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="5280"/>
          <seriesInfo name="DOI" value="10.17487/RFC5280"/>
        </reference>
        <reference anchor="RFC8391">
          <front>
            <title>XMSS: eXtended Merkle Signature Scheme</title>
            <author fullname="A. Huelsing" initials="A." surname="Huelsing"/>
            <author fullname="D. Butin" initials="D." surname="Butin"/>
            <author fullname="S. Gazdag" initials="S." surname="Gazdag"/>
            <author fullname="J. Rijneveld" initials="J." surname="Rijneveld"/>
            <author fullname="A. Mohaisen" initials="A." surname="Mohaisen"/>
            <date month="May" year="2018"/>
            <abstract>
              <t>This note describes the eXtended Merkle Signature Scheme (XMSS), a hash-based digital signature system that is based on existing descriptions in scientific literature. This note specifies Winternitz One-Time Signature Plus (WOTS+), a one-time signature scheme; XMSS, a single-tree scheme; and XMSS^MT, a multi-tree variant of XMSS. Both XMSS and XMSS^MT use WOTS+ as a main building block. XMSS provides cryptographic digital signatures without relying on the conjectured hardness of mathematical problems. Instead, it is proven that it only relies on the properties of cryptographic hash functions. XMSS provides strong security guarantees and is even secure when the collision resistance of the underlying hash function is broken. It is suitable for compact implementations, is relatively simple to implement, and naturally resists side-channel attacks. Unlike most other signature systems, hash-based signatures can so far withstand known attacks using quantum computers.</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="8391"/>
          <seriesInfo name="DOI" value="10.17487/RFC8391"/>
        </reference>
        <reference anchor="RFC8554">
          <front>
            <title>Leighton-Micali Hash-Based Signatures</title>
            <author fullname="D. McGrew" initials="D." surname="McGrew"/>
            <author fullname="M. Curcio" initials="M." surname="Curcio"/>
            <author fullname="S. Fluhrer" initials="S." surname="Fluhrer"/>
            <date month="April" year="2019"/>
            <abstract>
              <t>This note describes a digital-signature system based on cryptographic hash functions, following the seminal work in this area of Lamport, Diffie, Winternitz, and Merkle, as adapted by Leighton and Micali in 1995. It specifies a one-time signature scheme and a general signature scheme. These systems provide asymmetric authentication without using large integer mathematics and can achieve a high security level. They are suitable for compact implementations, are relatively simple to implement, and are naturally resistant to side-channel attacks. Unlike many other signature systems, hash-based signatures would still be secure even if it proves feasible for an attacker to build a quantum computer.</t>
              <t>This document is a product of the Crypto Forum Research Group (CFRG) in the IRTF. This has been reviewed by many researchers, both in the research group and outside of it. The Acknowledgements section lists many of them.</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="8554"/>
          <seriesInfo name="DOI" value="10.17487/RFC8554"/>
        </reference>
        <reference anchor="SP800208" target="https://doi.org/10.6028/NIST.SP.800-208">
          <front>
            <title>Recommendation for Stateful Hash-Based Signature Schemes</title>
            <author initials="" surname="National Institute of Standards and Technology (NIST)">
              <organization/>
            </author>
            <date year="2020" month="October" day="29"/>
          </front>
        </reference>
        <reference anchor="RFC2119">
          <front>
            <title>Key words for use in RFCs to Indicate Requirement Levels</title>
            <author fullname="S. Bradner" initials="S." surname="Bradner"/>
            <date month="March" year="1997"/>
            <abstract>
              <t>In many standards track documents several words are used to signify the requirements in the specification. These words are often capitalized. This document defines these words as they should be interpreted in IETF documents. This document specifies an Internet Best Current Practices for the Internet Community, and requests discussion and suggestions for improvements.</t>
            </abstract>
          </front>
          <seriesInfo name="BCP" value="14"/>
          <seriesInfo name="RFC" value="2119"/>
          <seriesInfo name="DOI" value="10.17487/RFC2119"/>
        </reference>
        <reference anchor="RFC8174">
          <front>
            <title>Ambiguity of Uppercase vs Lowercase in RFC 2119 Key Words</title>
            <author fullname="B. Leiba" initials="B." surname="Leiba"/>
            <date month="May" year="2017"/>
            <abstract>
              <t>RFC 2119 specifies common key words that may be used in protocol specifications. This document aims to reduce the ambiguity by clarifying that only UPPERCASE usage of the key words have the defined special meanings.</t>
            </abstract>
          </front>
          <seriesInfo name="BCP" value="14"/>
          <seriesInfo name="RFC" value="8174"/>
          <seriesInfo name="DOI" value="10.17487/RFC8174"/>
        </reference>
      </references>
      <references anchor="sec-informative-references">
        <name>Informative References</name>
        <reference anchor="RFC3279">
          <front>
            <title>Algorithms and Identifiers for the Internet X.509 Public Key Infrastructure Certificate and Certificate Revocation List (CRL) Profile</title>
            <author fullname="L. Bassham" initials="L." surname="Bassham"/>
            <author fullname="W. Polk" initials="W." surname="Polk"/>
            <author fullname="R. Housley" initials="R." surname="Housley"/>
            <date month="April" year="2002"/>
            <abstract>
              <t>This document specifies algorithm identifiers and ASN.1 encoding formats for digital signatures and subject public keys used in the Internet X.509 Public Key Infrastructure (PKI). Digital signatures are used to sign certificates and certificate revocation list (CRLs). Certificates include the public key of the named subject. [STANDARDS-TRACK]</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="3279"/>
          <seriesInfo name="DOI" value="10.17487/RFC3279"/>
        </reference>
        <reference anchor="RFC3647">
          <front>
            <title>Internet X.509 Public Key Infrastructure Certificate Policy and Certification Practices Framework</title>
            <author fullname="S. Chokhani" initials="S." surname="Chokhani"/>
            <author fullname="W. Ford" initials="W." surname="Ford"/>
            <author fullname="R. Sabett" initials="R." surname="Sabett"/>
            <author fullname="C. Merrill" initials="C." surname="Merrill"/>
            <author fullname="S. Wu" initials="S." surname="Wu"/>
            <date month="November" year="2003"/>
            <abstract>
              <t>This document presents a framework to assist the writers of certificate policies or certification practice statements for participants within public key infrastructures, such as certification authorities, policy authorities, and communities of interest that wish to rely on certificates. In particular, the framework provides a comprehensive list of topics that potentially (at the writer's discretion) need to be covered in a certificate policy or a certification practice statement. This document supersedes RFC 2527.</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="3647"/>
          <seriesInfo name="DOI" value="10.17487/RFC3647"/>
        </reference>
        <reference anchor="RFC4949">
          <front>
            <title>Internet Security Glossary, Version 2</title>
            <author fullname="R. Shirey" initials="R." surname="Shirey"/>
            <date month="August" year="2007"/>
            <abstract>
              <t>This Glossary provides definitions, abbreviations, and explanations of terminology for information system security. The 334 pages of entries offer recommendations to improve the comprehensibility of written material that is generated in the Internet Standards Process (RFC 2026). The recommendations follow the principles that such writing should (a) use the same term or definition whenever the same concept is mentioned; (b) use terms in their plainest, dictionary sense; (c) use terms that are already well-established in open publications; and (d) avoid terms that either favor a particular vendor or favor a particular technology or mechanism over other, competing techniques that already exist or could be developed. This memo provides information for the Internet community.</t>
            </abstract>
          </front>
          <seriesInfo name="FYI" value="36"/>
          <seriesInfo name="RFC" value="4949"/>
          <seriesInfo name="DOI" value="10.17487/RFC4949"/>
        </reference>
        <reference anchor="RFC8410">
          <front>
            <title>Algorithm Identifiers for Ed25519, Ed448, X25519, and X448 for Use in the Internet X.509 Public Key Infrastructure</title>
            <author fullname="S. Josefsson" initials="S." surname="Josefsson"/>
            <author fullname="J. Schaad" initials="J." surname="Schaad"/>
            <date month="August" year="2018"/>
            <abstract>
              <t>This document specifies algorithm identifiers and ASN.1 encoding formats for elliptic curve constructs using the curve25519 and curve448 curves. The signature algorithms covered are Ed25519 and Ed448. The key agreement algorithms covered are X25519 and X448. The encoding for public key, private key, and Edwards-curve Digital Signature Algorithm (EdDSA) structures is provided.</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="8410"/>
          <seriesInfo name="DOI" value="10.17487/RFC8410"/>
        </reference>
        <reference anchor="RFC8411">
          <front>
            <title>IANA Registration for the Cryptographic Algorithm Object Identifier Range</title>
            <author fullname="J. Schaad" initials="J." surname="Schaad"/>
            <author fullname="R. Andrews" initials="R." surname="Andrews"/>
            <date month="August" year="2018"/>
            <abstract>
              <t>When the Curdle Security Working Group was chartered, a range of object identifiers was donated by DigiCert, Inc. for the purpose of registering the Edwards Elliptic Curve key agreement and signature algorithms. This donated set of OIDs allowed for shorter values than would be possible using the existing S/MIME or PKIX arcs. This document describes the donated range and the identifiers that were assigned from that range, transfers control of that range to IANA, and establishes IANA allocation policies for any future assignments within that range.</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="8411"/>
          <seriesInfo name="DOI" value="10.17487/RFC8411"/>
        </reference>
        <reference anchor="MCGREW" target="https://eprint.iacr.org/2016/357">
          <front>
            <title>State Management for Hash-Based Signatures</title>
            <author initials="D." surname="McGrew">
              <organization/>
            </author>
            <author initials="P." surname="Kampanakis">
              <organization/>
            </author>
            <author initials="S." surname="Fluhrer">
              <organization/>
            </author>
            <author initials="S." surname="Gazdag">
              <organization/>
            </author>
            <author initials="D." surname="Butin">
              <organization/>
            </author>
            <author initials="J." surname="Buchmann">
              <organization/>
            </author>
            <date year="2016" month="November" day="02"/>
          </front>
        </reference>
        <reference anchor="BH16" target="https://eprint.iacr.org/2016/1042.pdf">
          <front>
            <title>Oops, I did it again – Security of One-Time Signatures under Two-Message Attacks.</title>
            <author initials="L." surname="Bruinderink">
              <organization/>
            </author>
            <author initials="S." surname="Hülsing">
              <organization/>
            </author>
            <date year="2016"/>
          </front>
        </reference>
        <reference anchor="CNSA2.0" target="https://media.defense.gov/2022/Sep/07/2003071834/-1/-1/0/CSA_CNSA_2.0_ALGORITHMS_.PDF">
          <front>
            <title>Commercial National Security Algorithm Suite 2.0 (CNSA 2.0) Cybersecurity Advisory (CSA)</title>
            <author initials="" surname="National Security Agency (NSA)">
              <organization/>
            </author>
            <date year="2022" month="September" day="07"/>
          </front>
        </reference>
        <reference anchor="ETSI-TR-103-692" target="https://www.etsi.org/deliver/etsi_tr/103600_103699/103692/01.01.01_60/tr_103692v010101p.pdf">
          <front>
            <title>State management for stateful authentication mechanisms</title>
            <author initials="" surname="European Telecommunications Standards Institute (ETSI)">
              <organization/>
            </author>
            <date year="2021" month="November"/>
          </front>
        </reference>
        <reference anchor="IANA-LMS" target="https://www.iana.org/assignments/leighton-micali-signatures/">
          <front>
            <title>Leighton-Micali Signatures (LMS)</title>
            <author initials="" surname="IANA">
              <organization/>
            </author>
            <date>n.d.</date>
          </front>
        </reference>
        <reference anchor="IANA-XMSS" target="https://iana.org/assignments/xmss-extended-hash-based-signatures/">
          <front>
            <title>XMSS: Extended Hash-Based Signatures</title>
            <author initials="" surname="IANA">
              <organization/>
            </author>
            <date>n.d.</date>
          </front>
        </reference>
        <reference anchor="SMI-PKIX" target="https://www.iana.org/assignments/smi-numbers/smi-numbers.xhtml#smi-numbers-1.3.6.1.5.5.7.6">
          <front>
            <title>SMI Security for PKIX Algorithms</title>
            <author initials="" surname="IANA">
              <organization/>
            </author>
            <date>n.d.</date>
          </front>
        </reference>
        <reference anchor="ANSSI" target="https://cyber.gouv.fr/sites/default/files/document/follow_up_position_paper_on_post_quantum_cryptography.pdf">
          <front>
            <title>ANSSI views on the Post-Quantum Cryptography transition (2023 follow up)</title>
            <author initials="" surname="Agence nationale de la sécurité des systèmes d'information (ANSSI)">
              <organization/>
            </author>
            <date year="2023" month="December" day="21"/>
          </front>
        </reference>
        <reference anchor="BSI" target="https://www.bsi.bund.de/SharedDocs/Downloads/EN/BSI/Publications/Brochure/quantum-safe-cryptography.pdf">
          <front>
            <title>Quantum-safe cryptography – fundamentals, current developments and recommendations</title>
            <author initials="" surname="Bundesamt für Sicherheit in der Informationstechnik (BSI)">
              <organization/>
            </author>
            <date year="2022" month="May" day="18"/>
          </front>
        </reference>
      </references>
    </references>
    <?line 636?>

<section anchor="hss-x509-v3-certificate-example">
      <name>HSS X.509 v3 Certificate Example</name>
      <t>This section shows a self-signed X.509 v3 certificate using HSS.</t>
      <artwork><![CDATA[
Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number:
            e8:91:d6:06:91:4f:ce:f3
        Signature Algorithm: hss
        Issuer: C = US, ST = VA, L = Herndon, O = Bogus CA
        Validity
            Not Before: May 14 08:58:11 2024 GMT
            Not After : May 14 08:58:11 2034 GMT
        Subject: C = US, ST = VA, L = Herndon, O = Bogus CA
        Subject Public Key Info:
            Public Key Algorithm: hss
                hss public key:
                PQ key material:
                    00:00:00:01:00:00:00:05:00:00:00:04:c0:96:12:
                    8b:ea:38:30:78:eb:f6:fb:43:d7:7f:9f:9e:81:39:
                    e2:7c:b9:34:4e:6e:53:19:f0:ee:68:75:85:83:d3:
                    2b:e9:7b:14:46:9e:4e:c5:e3:5a:18:0b:30:e5:13
        X509v3 extensions:
            X509v3 Subject Key Identifier:
                58:15:AB:F4:CF:03:69:02:60:7A:57:4D:C5:D5:B3:72:
                8A:19:21:68
            X509v3 Authority Key Identifier:
                58:15:AB:F4:CF:03:69:02:60:7A:57:4D:C5:D5:B3:72:
                8A:19:21:68
            X509v3 Basic Constraints: critical
                CA:TRUE
            X509v3 Key Usage: critical
                Certificate Sign, CRL Sign
    Signature Algorithm: hss
    Signature Value:
        00:00:00:00:00:00:00:00:00:00:00:04:9c:37:52:ff:b9:d7:
        df:f5:5b:01:ba:50:c2:50:cc:6f:f3:b1:73:df:0c:2a:ea:b3:
        ed:96:1e:ce:e7:58:05:da:8d:a7:77:21:42:32:d9:f9:4a:4d:
        f7:2b:18:2a:1c:5c:69:03:f3:1c:9c:95:6d:31:9a:c9:ca:84:
        4d:ae:b3:8b:c3:71:ac:3f:87:51:be:38:b4:bf:d9:dc:90:1f:
        1e:54:bd:f9:1a:65:70:d4:46:b6:ad:4d:6d:16:b9:fb:29:f4:
        e3:86:42:4a:3f:a4:8f:01:84:9b:44:0b:23:22:9c:97:6d:d5:
        b9:26:39:11:ab:46:82:bd:10:6c:b4:7a:64:ed:c7:40:b0:33:
        f0:b5:81:1c:b4:41:54:9c:30:d9:d2:93:ba:48:8c:4f:d0:25:
        41:60:7b:90:5e:12:20:b7:30:16:16:1e:b7:ee:d8:4b:ee:ed:
        3c:70:fc:ff:36:18:aa:24:23:87:91:65:a8:95:2d:b6:1c:d1:
        02:7b:70:81:8a:18:17:c0:45:62:fe:47:a1:3e:69:54:31:67:
        58:9a:e1:e3:c9:8d:ee:1e:2a:d1:46:75:e9:e4:90:67:01:57:
        92:54:db:b4:ea:de:8b:e7:eb:fc:27:80:9b:d5:da:e0:8e:b0:
        b3:08:ca:6f:a1:1c:f4:40:65:b0:f6:f8:c9:a7:97:04:c8:7c:
        9e:56:ec:2f:4b:cd:45:8b:d7:e6:a7:50:c7:e6:21:2c:17:31:
        23:11:7a:ae:9a:b5:84:5f:e6:5c:82:99:a8:3a:a9:91:87:9a:
        24:5c:83:01:91:7c:fc:cd:be:2e:92:50:fb:12:11:96:08:0d:
        c9:24:0d:bb:6f:fb:59:05:af:7f:96:bc:a3:f4:58:e2:fa:0a:
        4a:f2:4c:f7:b3:1b:81:dd:4a:41:a0:b1:dd:52:4c:bb:6d:c0:
        a8:d9:bb:29:c8:fc:e3:7e:f8:6a:e5:5e:c4:e4:e8:7c:0b:00:
        87:15:75:a2:06:50:97:c6:1f:14:52:79:04:a8:9c:ec:b1:c7:
        6a:46:33:98:b8:63:f7:a7:2c:d4:62:78:94:1c:5d:9d:4f:a6:
        0a:ae:39:50:85:b2:09:8d:62:c9:4c:11:9f:0c:91:a5:ac:2d:
        11:bd:71:b6:0c:ea:34:98:53:fc:2e:cc:7b:a4:9c:2e:7a:a4:
        8d:e2:e8:8c:01:a9:9c:3e:b5:34:77:33:82:01:d4:ef:72:04:
        d6:5b:e5:f6:2c:1b:ae:86:c4:73:02:44:85:d6:f7:ac:a3:e8:
        f6:a9:b5:5c:6d:46:88:da:55:b8:2b:7a:4c:0c:9a:e7:cd:5d:
        62:8a:ca:c8:96:ce:8d:71:7b:d2:c1:0d:9a:35:55:2b:84:3e:
        0e:a5:fa:d6:a0:76:8e:23:b3:df:c9:3b:4f:68:56:1e:e9:3c:
        79:5b:d3:25:54:11:ad:a6:ac:58:11:49:8f:4d:c4:c1:39:99:
        76:3a:a6:d1:2f:57:ad:bf:7c:9d:57:cc:37:0d:29:84:29:7b:
        cb:46:85:c3:81:c5:33:9a:65:c3:2f:01:48:ca:44:6c:f1:84:
        3d:d0:49:c2:c1:05:db:77:4c:b9:72:3d:6f:ce:69:f2:91:c6:
        15:25:8f:da:38:7e:ef:5b:3e:5f:35:ab:a6:78:16:28:42:c1:
        2c:2f:9e:11:53:2c:bd:c4:24:7b:e9:c4:ce:3d:d6:41:c7:5d:
        92:91:c3:37:cb:72:44:d7:0d:70:85:13:0b:ac:b3:0f:b0:e5:
        e3:2e:48:b9:9c:b8:d7:3e:7c:50:69:03:7a:5f:ae:f8:6c:09:
        61:97:6b:ce:cd:e5:f0:55:fe:05:f8:97:1d:9e:81:65:f5:ff:
        9a:7a:8c:96:d8:f8:cf:d8:dc:55:ce:67:7a:00:6b:fd:bb:3f:
        1b:3d:65:94:c1:5a:b6:a0:8e:be:a4:be:26:90:5f:1f:06:d4:
        ea:3f:a6:97:40:8e:bf:18:5c:92:0f:15:e3:05:4a:14:51:1e:
        23:81:ef:cf:f7:a8:88:75:f8:2d:28:37:26:87:27:63:5c:01:
        53:0e:5e:53:d2:a7:18:eb:2f:c0:82:49:05:b0:4d:33:6f:94:
        10:91:77:f8:90:9e:ca:fe:bb:3d:c4:42:d6:89:84:98:42:f4:
        24:b3:b4:db:5e:2b:66:a9:ff:6c:18:d4:79:f8:72:73:53:9b:
        02:ed:04:73:77:a4:68:cf:4b:be:4b:16:50:62:87:f9:49:99:
        e3:a1:0c:42:92:bc:a9:e3:2d:22:82:35:7f:71:15:88:70:6a:
        01:ab:44:64:ad:e5:52:d4:97:ee:bb:44:7b:6e:08:7f:dd:94:
        fd:c9:1c:6b:59:d1:92:51:29:03:ce:ec:bf:41:a5:14:69:54:
        3a:b4:39:d9:44:5d:f1:b2:f4:5c:6b:9f:c9:5f:bb:fc:c8:c7:
        a3:8b:e1:ec:e2:d0:69:5a:40:1c:9c:9d:8a:3d:77:3b:c1:5d:
        c0:72:61:4b:37:c5:96:8c:6d:8b:f8:56:da:ac:3e:3c:72:09:
        ce:f6:c3:fe:5d:cf:37:d9:68:cd:a7:dd:f7:96:63:da:8c:1d:
        df:b8:32:cf:eb:97:11:83:fe:6b:aa:b9:e2:4b:b2:ea:62:73:
        c3:1c:e9:40:90:56:4f:12:c3:ba:f4:2b:d9:1c:50:cc:e0:51:
        d8:eb:bf:67:28:0c:2d:13:8d:b3:6f:13:6a:1d:a7:54:20:ba:
        82:5b:b8:e5:1f:89:f1:67:26:c1:dc:1b:60:57:ed:a6:2c:f2:
        17:01:7f:a5:e7:5c:64:c9:3c:08:f2:cf:48:ec:88:84:ef:03:
        c2:f5:eb:05:31:7d:fe:7f:3c:71:41:28:17:64:5f:b9:ec:54:
        79:d0:b3:98:fb:84:9c:36:8b:43:0b:d4:c9:ec:09:4a:70:13:
        62:f2:36:c8:b4:75:cc:2a:77:08:a0:9d:ef:19:d6:88:dc:e2:
        b2:4e:40:61:71:cb:c7:c3:de:16:6f:49:7f:5e:d5:17:00:00:
        00:05:79:47:12:9f:ce:eb:1d:a8:fd:0d:b0:18:44:6a:ef:54:
        28:46:e4:19:f6:2d:3e:74:bb:9d:36:0a:ae:67:4a:28:7a:1b:
        80:39:a0:08:2a:28:a0:ec:55:ee:55:aa:a1:cc:94:d4:36:1a:
        b3:57:25:30:ad:2c:5e:63:ba:22:fc:aa:7a:59:64:f6:d8:03:
        20:28:71:f9:dc:09:fa:4c:81:b9:64:1b:ad:ea:cb:db:18:17:
        5d:d8:98:bd:d2:8d:c5:04:7c:5b:92:9a:89:f6:bc:d6:55:c7:
        08:5d:3c:58:8e:18:ac:6f:88:a8:d7:9e:d4:ee:5d:f5:21:4e:
        a5:8b:19:5f:e3:f4:66:f9:25:4d:f9:c6:60:62:31:72:5c:34:
        34:67:1a:a7:6a:7d:54:a3:d8:9b:1f:5b:f8:08:41:79:5b:43
]]></artwork>
      <artwork><![CDATA[
-----BEGIN CERTIFICATE-----
MIIGnjCCAXagAwIBAgIJAOiR1gaRT87zMA0GCyqGSIb3DQEJEAMRMD8xCzAJBgNV
BAYTAlVTMQswCQYDVQQIDAJWQTEQMA4GA1UEBwwHSGVybmRvbjERMA8GA1UECgwI
Qm9ndXMgQ0EwHhcNMjQwNTE0MDg1ODExWhcNMzQwNTE0MDg1ODExWjA/MQswCQYD
VQQGEwJVUzELMAkGA1UECAwCVkExEDAOBgNVBAcMB0hlcm5kb24xETAPBgNVBAoM
CEJvZ3VzIENBME4wDQYLKoZIhvcNAQkQAxEDPQAAAAABAAAABQAAAATAlhKL6jgw
eOv2+0PXf5+egTnifLk0Tm5TGfDuaHWFg9Mr6XsURp5OxeNaGAsw5ROjYzBhMB0G
A1UdDgQWBBRYFav0zwNpAmB6V03F1bNyihkhaDAfBgNVHSMEGDAWgBRYFav0zwNp
AmB6V03F1bNyihkhaDAPBgNVHRMBAf8EBTADAQH/MA4GA1UdDwEB/wQEAwIBBjAN
BgsqhkiG9w0BCRADEQOCBREAAAAAAAAAAAAAAAAEnDdS/7nX3/VbAbpQwlDMb/Ox
c98MKuqz7ZYezudYBdqNp3chQjLZ+UpN9ysYKhxcaQPzHJyVbTGaycqETa6zi8Nx
rD+HUb44tL/Z3JAfHlS9+RplcNRGtq1NbRa5+yn044ZCSj+kjwGEm0QLIyKcl23V
uSY5EatGgr0QbLR6ZO3HQLAz8LWBHLRBVJww2dKTukiMT9AlQWB7kF4SILcwFhYe
t+7YS+7tPHD8/zYYqiQjh5FlqJUtthzRAntwgYoYF8BFYv5HoT5pVDFnWJrh48mN
7h4q0UZ16eSQZwFXklTbtOrei+fr/CeAm9Xa4I6wswjKb6Ec9EBlsPb4yaeXBMh8
nlbsL0vNRYvX5qdQx+YhLBcxIxF6rpq1hF/mXIKZqDqpkYeaJFyDAZF8/M2+LpJQ
+xIRlggNySQNu2/7WQWvf5a8o/RY4voKSvJM97Mbgd1KQaCx3VJMu23AqNm7Kcj8
4374auVexOTofAsAhxV1ogZQl8YfFFJ5BKic7LHHakYzmLhj96cs1GJ4lBxdnU+m
Cq45UIWyCY1iyUwRnwyRpawtEb1xtgzqNJhT/C7Me6ScLnqkjeLojAGpnD61NHcz
ggHU73IE1lvl9iwbrobEcwJEhdb3rKPo9qm1XG1GiNpVuCt6TAya581dYorKyJbO
jXF70sENmjVVK4Q+DqX61qB2jiOz38k7T2hWHuk8eVvTJVQRraasWBFJj03EwTmZ
djqm0S9Xrb98nVfMNw0phCl7y0aFw4HFM5plwy8BSMpEbPGEPdBJwsEF23dMuXI9
b85p8pHGFSWP2jh+71s+XzWrpngWKELBLC+eEVMsvcQke+nEzj3WQcddkpHDN8ty
RNcNcIUTC6yzD7Dl4y5IuZy41z58UGkDel+u+GwJYZdrzs3l8FX+BfiXHZ6BZfX/
mnqMltj4z9jcVc5negBr/bs/Gz1llMFatqCOvqS+JpBfHwbU6j+ml0COvxhckg8V
4wVKFFEeI4Hvz/eoiHX4LSg3JocnY1wBUw5eU9KnGOsvwIJJBbBNM2+UEJF3+JCe
yv67PcRC1omEmEL0JLO0214rZqn/bBjUefhyc1ObAu0Ec3ekaM9LvksWUGKH+UmZ
46EMQpK8qeMtIoI1f3EViHBqAatEZK3lUtSX7rtEe24If92U/ckca1nRklEpA87s
v0GlFGlUOrQ52URd8bL0XGufyV+7/MjHo4vh7OLQaVpAHJydij13O8FdwHJhSzfF
loxti/hW2qw+PHIJzvbD/l3PN9lozafd95Zj2owd37gyz+uXEYP+a6q54kuy6mJz
wxzpQJBWTxLDuvQr2RxQzOBR2Ou/ZygMLRONs28Tah2nVCC6glu45R+J8Wcmwdwb
YFftpizyFwF/pedcZMk8CPLPSOyIhO8DwvXrBTF9/n88cUEoF2RfuexUedCzmPuE
nDaLQwvUyewJSnATYvI2yLR1zCp3CKCd7xnWiNzisk5AYXHLx8PeFm9Jf17VFwAA
AAV5RxKfzusdqP0NsBhEau9UKEbkGfYtPnS7nTYKrmdKKHobgDmgCCoooOxV7lWq
ocyU1DYas1clMK0sXmO6Ivyqellk9tgDIChx+dwJ+kyBuWQbrerL2xgXXdiYvdKN
xQR8W5Kaifa81lXHCF08WI4YrG+IqNee1O5d9SFOpYsZX+P0ZvklTfnGYGIxclw0
NGcap2p9VKPYmx9b+AhBeVtD
-----END CERTIFICATE-----
]]></artwork>
    </section>
    <section anchor="xmss-x509-v3-certificate-example">
      <name>XMSS X.509 v3 Certificate Example</name>
      <t>This section shows a self-signed X.509 v3 certificate using XMSS.</t>
      <artwork><![CDATA[
Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number:
            54:7e:64:70:29:9e:03:c5:7a:a5:5c:78:d1:27:87:8c:
            54:35:17:5d
        Signature Algorithm: xmss
        Issuer: C = FR, L = Paris, O = Bogus XMSS CA
        Validity
            Not Before: Jul 10 08:27:24 2024 GMT
            Not After : Jul  8 08:27:24 2034 GMT
        Subject: C = FR, L = Paris, O = Bogus XMSS CA
        Subject Public Key Info:
            Public Key Algorithm: xmss
                xmss public key:
                PQ key material:
                    00:00:00:01:2b:eb:bf:66:14:de:6f:96:5b:4d:2a:
                    50:00:7b:ad:5c:22:b0:13:79:72:02:14:a9:5f:fc:
                    96:e0:9b:78:8e:d6:be:8c:1c:70:3c:d8:dd:78:b2:
                    1a:14:47:be:1f:0d:74:72:3f:36:76:c2:cb:19:ad:
                    29:90:0b:82:de:9b:7f:df
        X509v3 extensions:
            X509v3 Subject Key Identifier:
                62:CE:35:A5:47:77:FF:21:87:2E:BC:2D:27:E7:8E:F4:
                35:6B:CF:D8
            X509v3 Authority Key Identifier:
                62:CE:35:A5:47:77:FF:21:87:2E:BC:2D:27:E7:8E:F4:
                35:6B:CF:D8
            X509v3 Basic Constraints: critical
                CA:TRUE
            X509v3 Key Usage: critical
                Certificate Sign, CRL Sign
    Signature Algorithm: xmss
    Signature Value:
        00:00:00:00:e5:88:a8:b8:73:ad:4d:92:f8:5c:81:c5:8a:63:
        57:6a:a7:3b:54:aa:b6:06:8a:d9:f1:c2:0b:c8:27:1e:4b:a2:
        cf:e2:da:44:ea:e8:f2:40:a8:b9:54:9c:49:36:12:24:df:74:
        ad:e5:29:ef:4f:da:88:0d:21:5d:3b:64:63:27:d0:84:b5:95:
        7a:30:18:37:cd:34:17:dd:ac:9d:9e:48:db:74:07:79:84:21:
        5a:f0:26:cd:21:64:7b:77:33:48:58:67:9b:2c:b2:85:6d:cc:
        ec:31:4b:2f:51:55:3a:85:e1:ca:04:15:ce:6e:47:39:f5:e9:
        31:45:41:ed:71:c6:4f:96:f5:ae:64:6a:bd:72:d0:8c:17:02:
        99:10:1d:14:34:ca:e5:47:e3:f7:66:96:96:11:d5:97:76:76:
        83:f1:84:a5:b6:00:5e:3e:67:97:7a:32:dc:c8:eb:4c:29:46:
        77:99:d6:da:45:e6:7b:8c:45:6d:b5:29:6b:fd:98:a2:89:8d:
        0c:30:42:f5:0b:7c:97:c5:b1:1d:e2:da:67:a9:48:a4:9e:29:
        f4:60:3f:4d:1d:48:83:82:38:ef:fa:cb:1d:86:11:a1:15:94:
        fb:d5:ee:68:f9:44:b9:3d:54:70:f3:be:17:8d:d7:2e:85:2d:
        5c:d0:a0:c5:99:52:cc:79:e7:1c:18:d9:6e:3d:0f:6c:05:51:
        33:28:35:e2:02:59:5f:1f:ed:78:0a:c6:62:f0:7d:fe:73:96:
        03:4c:b4:42:e3:00:c2:d7:cb:eb:51:10:c4:0c:64:b8:37:fe:
        85:d0:8e:11:6d:a6:16:77:b1:1e:01:d9:1e:f3:10:9c:dd:01:
        bc:38:75:5e:8f:58:9e:5b:6c:7b:0a:41:08:59:35:a9:3a:83:
        19:e0:7d:a1:f5:cf:a3:1c:4e:07:e1:ad:03:95:f2:d3:8b:79:
        33:f8:52:22:53:1b:1e:32:9a:61:3f:c4:7c:9a:e8:d5:b5:28:
        f1:84:65:d5:c1:fc:4d:16:93:88:93:69:ca:fa:94:a0:95:4e:
        23:ae:1e:60:e0:e8:b4:bf:ff:16:95:71:0f:31:74:bb:be:b8:
        5a:eb:24:95:8b:95:28:13:cd:e3:a9:65:f7:f5:6e:9b:a9:a9:
        7a:05:ce:ab:f0:54:62:d9:12:f8:a1:1a:68:df:af:15:8f:8a:
        df:67:27:c9:ed:bd:e1:81:a6:8d:9a:84:f3:91:36:d9:89:74:
        8e:ef:84:dc:5c:03:1a:08:e4:d7:f0:72:fc:6d:8a:01:34:94:
        e5:ff:08:51:1b:80:5f:e7:07:d8:9f:25:e4:1d:c3:f8:e5:d0:
        9c:50:cf:66:71:f9:cc:f7:c0:a7:d0:66:01:b7:17:a0:5f:66:
        97:a4:ff:62:ac:1c:a0:63:0d:30:28:e9:90:d5:59:a4:48:d8:
        07:87:02:4b:3f:68:23:a5:04:dc:b3:d7:45:f6:dc:b0:ec:c6:
        90:a6:1c:a1:f8:7e:84:ba:63:7e:5a:64:14:78:58:f5:75:c0:
        f5:e1:1d:bd:49:57:c0:40:08:07:99:7f:43:2e:e2:25:d8:ed:
        a3:1a:e3:78:f1:78:af:02:49:54:36:59:8e:d3:72:a5:0b:52:
        32:bd:17:a2:cf:e1:47:21:28:3d:ba:b6:24:d9:18:f9:44:73:
        35:ed:29:a4:18:bc:ed:68:cd:4a:9a:34:cb:1a:2f:b3:5f:ba:
        73:9b:18:ee:7a:a8:92:25:65:25:81:04:63:1c:22:2b:b8:ba:
        81:21:bc:f9:9d:a8:78:98:75:bc:ed:4a:c6:b7:6f:c0:91:24:
        eb:1d:f9:5d:e0:e3:78:4e:05:f6:34:0f:7b:41:54:49:20:a2:
        30:66:94:f1:da:c1:6c:3f:5e:10:92:92:a3:0c:7e:e8:8b:26:
        11:1c:d7:68:c9:31:79:b3:a4:d5:63:00:68:c3:e3:86:2d:09:
        92:4b:2d:63:7d:b8:03:a4:4c:60:b4:2c:12:d5:0b:9f:16:28:
        ea:88:2f:bb:1c:19:0b:0f:40:3d:67:e8:0b:fa:c6:e3:39:44:
        b2:bd:8a:3f:21:dd:aa:ec:a3:8c:48:dd:4c:99:43:86:d7:48:
        81:6b:e5:b9:bb:59:9f:1c:0f:3f:11:f7:7c:4b:67:a8:95:c2:
        7c:cb:3b:66:b0:79:a6:55:6f:6d:b0:29:8a:5e:7b:ee:30:68:
        f3:dd:41:29:91:f6:79:71:ae:8d:21:70:78:1d:5d:d2:f7:cf:
        e7:42:38:d1:8c:52:a6:a6:f6:b1:38:b1:2b:23:81:e1:1f:21:
        6d:99:3f:10:eb:b1:a9:73:b8:3e:31:99:cc:dd:2b:df:58:27:
        db:0b:5a:29:99:8f:b1:9f:e9:31:42:d0:26:db:53:b7:7e:30:
        41:95:c3:f0:07:83:bb:b0:63:b5:16:48:f2:a6:60:2f:32:5d:
        22:a1:da:76:4e:37:26:53:0d:95:7b:2d:b9:05:2f:93:2b:d4:
        df:c1:02:5b:f7:a5:a2:4f:11:5c:80:f4:f0:bd:c7:ea:3c:db:
        6f:e2:eb:6c:7f:c3:58:d9:31:77:4b:4d:f7:ce:bb:d6:c8:64:
        a3:01:d5:f9:a4:8d:e8:f0:ee:09:06:2c:0b:3c:ac:0a:57:d8:
        e4:81:79:ea:4a:bd:51:03:88:4c:d0:4c:0b:c4:0c:7e:2d:e7:
        df:1b:67:62:c0:d1:9c:ad:bb:d3:f0:75:dd:83:aa:70:99:2c:
        19:78:3d:26:2b:47:6f:24:c1:60:02:1e:4b:75:04:91:1f:08:
        1c:b3:79:a0:9b:db:fb:5d:3f:c7:e3:09:1f:41:3e:64:bb:ad:
        19:3d:35:e1:a6:f4:69:0b:a2:04:37:42:95:c6:c7:e5:f4:56:
        0e:67:5b:78:34:bb:07:f1:8f:e7:73:5b:87:d7:df:c9:2d:8d:
        8c:42:76:87:15:85:4b:23:03:20:34:e1:1b:f6:0c:1e:84:53:
        d9:1b:4e:d9:31:43:38:3b:88:12:84:d8:2a:38:b1:ce:0f:c7:
        07:d4:63:2d:97:89:1c:b3:44:99:eb:d4:df:32:74:be:0d:63:
        11:22:fd:fa:8e:e2:0b:56:12:56:0c:46:16:ad:44:10:26:98:
        dc:cf:c9:95:67:3e:11:c1:76:fa:b8:12:ea:96:f6:d9:91:ac:
        bf:49:b9:1c:8e:15:05:53:ac:9e:04:d2:5b:b8:87:bf:81:50:
        f7:02:a4:c0:9c:18:0f:45:ac:7a:82:cf:46:15:42:40:09:32:
        89:a5:ea:90:a5:99:68:f9:93:0c:7b:d6:7a:a8:e9:51:e2:90:
        9e:b9:ed:21:db:d9:7e:de:dc:62:6b:44:6b:9f:81:c5:77:39:
        8e:1d:78:30:de:dc:53:80:e0:c3:fa:fa:94:68:28:91:98:86:
        ff:86:04:a9:bd:58:7c:31:37:1f:db:9a:29:f3:c1:48:10:20:
        71:5f:fc:35:13:eb:7b:12:e2:7d:1c:cc:97:fe:8f:5c:a2:dd:
        f6:d2:a3:b2:ea:51:b3:ef:b1:1e:79:0b:00:53:f4:f2:52:75:
        5a:d7:17:c5:31:a0:54:4e:2b:28:2c:4f:6b:7a:27:3a:2c:04:
        da:b3:1d:04:4e:a4:4e:94:5c:a8:91:70:ab:c0:4b:75:9f:b3:
        6a:a9:4e:8a:22:e9:7f:fd:ec:53:e7:6a:6d:32:0b:8b:ab:4c:
        e7:7d:72:ec:04:62:1c:1a:45:1e:33:8e:37:ae:6a:2f:c8:fb:
        f3:69:ed:11:01:f3:f4:57:e9:29:d5:3b:0c:9c:0c:c4:cb:c3:
        38:5c:01:e7:d6:31:c3:d8:ce:24:d7:be:71:9b:c8:96:13:ca:
        5c:5d:e4:92:40:af:86:a0:4b:ff:a7:55:39:70:fd:ac:0a:e1:
        87:c7:01:4b:c3:41:36:c6:c6:33:8f:4f:25:4a:8d:70:92:ac:
        7c:95:cc:49:a9:dc:d6:6a:67:52:a5:5b:7f:2f:bb:91:e3:be:
        d6:28:fc:22:d0:72:66:e8:09:73:a7:23:c6:a6:89:38:0b:e5:
        d0:b3:f1:40:38:9c:4d:17:96:11:17:44:ef:e3:94:51:91:4c:
        5d:fe:d9:ed:c3:76:a0:2d:3b:dc:8d:b9:31:15:f6:75:58:74:
        2f:57:b4:29:21:29:6d:5f:eb:06:71:0a:f4:db:ff:c6:2f:16:
        73:a7:76:6b:d0:5b:a7:21:5c:fd:f0:11:e8:6f:9b:d0:c9:c9:
        fe:35:76:4a:4a:63:9b:ba:48:ac:af:4f:91:67:9c:5c:47:d8:
        e3:2d:03:12:5e:f1:cb:56:34:75:69:95:ad:68:96:6c:e7:4a:
        91:72:fb:9b:ba:e8:92:56:fb:9a:5b:5d:3b:9d:d3:c5:c4:52:
        42:1b:f9:4a:47:42:dd:77:49:da:2b:bd:d7:94:5f:7b:b8:64:
        b9:06:32:7c:ea:d1:36:f6:95:b8:57:41:1b:6e:66:31:2c:ee:
        87:7a:5c:19:2f:d8:95:4a:16:93:48:f3:97:25:3d:24:61:1e:
        d0:63:37:ee:3a:c9:a3:46:c5:94:a0:7e:24:cc:7f:72:8d:14:
        9e:3c:33:ec:cd:9a:dd:b5:08:90:98:19:95:85:38:ff:ff:d2:
        1e:bf:a6:c4:97:13:2b:3d:47:e9:57:59:d3:7d:99:01:6e:53:
        4d:c0:82:97:fb:89:d6:7c:b7:23:0e:7d:6e:23:88:53:06:8f:
        16:ff:40:0a:1b:cd:d5:1e:91:01:3e:77:3a:5f:c1:57:3a:7b:
        c6:d5:51:d7:e2:ec:89:12:6b:9d:03:e4:9d:bb:7d:4e:02:bf:
        67:8d:03:ca:90:56:f0:9a:97:4b:02:2d:4c:31:89:82:76:97:
        fe:2f:d5:0a:3d:ea:0d:38:6c:30:75:5f:ae:91:53:d7:45:64:
        df:ba:0b:22:80:44:85:6d:0e:5c:29:7f:82:9e:54:a3:7a:95:
        be:96:79:66:9d:5b:a2:d6:2e:47:c6:99:7d:2b:32:dc:f2:b6:
        02:91:6d:63:d4:93:45:60:c4:42:71:10:9e:fb:90:2f:e6:75:
        71:ce:78:70:c1:da:ff:e1:47:fe:79:2b:8e:9a:81:bf:dd:02:
        e3:78:39:71:17:b3:23:14:11:9d:29:8e:21:a1:98:b0:ac:03:
        5a:6c:9e:62:64:ef:4f:03:ca:37:a6:ed:e4:78:d5:0d:99:29:
        f5:5c:61:e6:48:cb:97:0e:5e:f9:2c:f6:b6:c7:7c:0c:a4:f7:
        1a:f7:67:b5:5c:03:bf:bf:7a:e2:4d:a2:9b:5d:5d:5f:51:d0:
        d6:52:8f:2a:20:68:08:bb:f0:9c:05:0e:ef:b3:49:0c:2a:1d:
        8f:f9:03:b7:61:09:71:88:7d:e2:8c:e4:b8:ac:98:1b:c3:80:
        55:a1:6b:dd:13:a2:29:4f:93:93:d3:d5:01:31:3f:7b:39:0e:
        3a:57:6c:eb:5c:6a:5f:1b:ad:97:bd:97:23:18:91:05:0e:2b:
        b4:b1:11:ee:f8:58:c7:08:d0:de:a2:3e:ba:54:8d:3d:63:da:
        91:50:3a:24:8d:19:18:23:2e:cf:30:8d:5d:e3:e7:02:93:fa:
        c8:f8:ea:05:e6:eb:06:80:90:4d:15:58:3d:26:98:13:4b:b0:
        ac:dd:90:2e:d0:e1:eb:71:32:83:5d:2a:a9:b9:b5:24:fc:e9:
        ec:18:ca:c9:a1:05:59:3e:fa:af:ed:4e:86:b1:fe:40:47:9b:
        42:77:af:9c:2b:a0:e2:3e:fd:51:ab:02:77:e8:f1:39:45:aa:
        54:b6:14:d4:14:20:fc:36:81:e6:04:98:8a:a0:c0:8a:cf:ae:
        f6:b5:dc:b7:eb:26:86:d3:cf:1c:38:65:54:04:b1:b5:09:48:
        f5:2d:07:ba:f8:eb:49:bd:d9:b1:54:ea:ac:c2:0d:20:10:79:
        c1:cb:e9:dc:2d:ff:55:50:4f:f6:05:02:78:31:33:6f:15:7e:
        24:5a:66:23:70:b3:b2:0c:17:39:ce:15:38:c5:ff:60:16:38:
        60:74:72:c9:70:d8:59:b7:80:7f:da:f6:67:3f:d0:ba:be:1b:
        a1:87:da:92:2d:a3:6c:99:29:57:aa:cb:d1:8d:66:f1:2d:c9:
        56:60:24:56:4b:19:9f:f5:65:84:89:86:7d:4d:8b:f8:5b:60:
        dd:af:2d:66:76:6c:66:d9:c6:f5:39:25:6c:e5:7b:43:97:64:
        5c:c5:20:1e:3d:b5:dc:92:b2:9c:d8:1b:1b:e0:bc:44:7b:9c:
        95:c5:53:48:91:b2:a5:46:16:bf:50:af:a5:44:cc:54:78:3f:
        ed:20:d8:2e:0b:41:3d:f1:04:9d:df:3c:4a:d7:81:04:ff:8c:
        b7:79:f8:51:8d:b7:2e:ac:2c:54:e6:fc:43:76:8e:f9:be:8c:
        b8:5c:ad:c4:13:af:b0:6e:3b:d1:82:57:1e:f5:52:84:ca:cc:
        d2:68:f3:2d:04:ff:27:0a:e6:a2:fa:c0:a9:97:d6:64:45:18:
        5c:6f:9e:c1:64:22:66:db:56:02:c3:a8:57:fc:87:1b:5c:43:
        15:8e:58:fc:f2:00:0b:4f:6a:4b:a0:5c:da:f2:e5:1b:82:4a:
        6b:ef:db:63:d7:7d:93:1d:2f:20:78:37:17:22:82:cd:6b:c1:
        83:61:05:81:99:0c:25:29:d6:5f:22:bc:06:67:7d:67
]]></artwork>
      <artwork><![CDATA[
-----BEGIN CERTIFICATE-----
MIILSDCCAW+gAwIBAgIUVH5kcCmeA8V6pVx40SeHjFQ1F10wCgYIKwYBBQUHBiIw
NTELMAkGA1UEBhMCRlIxDjAMBgNVBAcMBVBhcmlzMRYwFAYDVQQKDA1Cb2d1cyBY
TVNTIENBMB4XDTI0MDcxMDA4MjcyNFoXDTM0MDcwODA4MjcyNFowNTELMAkGA1UE
BhMCRlIxDjAMBgNVBAcMBVBhcmlzMRYwFAYDVQQKDA1Cb2d1cyBYTVNTIENBMFMw
CgYIKwYBBQUHBiIDRQAAAAABK+u/ZhTeb5ZbTSpQAHutXCKwE3lyAhSpX/yW4Jt4
jta+jBxwPNjdeLIaFEe+Hw10cj82dsLLGa0pkAuC3pt/36NjMGEwHQYDVR0OBBYE
FGLONaVHd/8hhy68LSfnjvQ1a8/YMB8GA1UdIwQYMBaAFGLONaVHd/8hhy68LSfn
jvQ1a8/YMA8GA1UdEwEB/wQFMAMBAf8wDgYDVR0PAQH/BAQDAgEGMAoGCCsGAQUF
BwYiA4IJxQAAAAAA5YiouHOtTZL4XIHFimNXaqc7VKq2BorZ8cILyCceS6LP4tpE
6ujyQKi5VJxJNhIk33St5SnvT9qIDSFdO2RjJ9CEtZV6MBg3zTQX3aydnkjbdAd5
hCFa8CbNIWR7dzNIWGebLLKFbczsMUsvUVU6heHKBBXObkc59ekxRUHtccZPlvWu
ZGq9ctCMFwKZEB0UNMrlR+P3ZpaWEdWXdnaD8YSltgBePmeXejLcyOtMKUZ3mdba
ReZ7jEVttSlr/ZiiiY0MMEL1C3yXxbEd4tpnqUiknin0YD9NHUiDgjjv+ssdhhGh
FZT71e5o+US5PVRw874XjdcuhS1c0KDFmVLMeeccGNluPQ9sBVEzKDXiAllfH+14
CsZi8H3+c5YDTLRC4wDC18vrURDEDGS4N/6F0I4RbaYWd7EeAdke8xCc3QG8OHVe
j1ieW2x7CkEIWTWpOoMZ4H2h9c+jHE4H4a0DlfLTi3kz+FIiUxseMpphP8R8mujV
tSjxhGXVwfxNFpOIk2nK+pSglU4jrh5g4Oi0v/8WlXEPMXS7vrha6ySVi5UoE83j
qWX39W6bqal6Bc6r8FRi2RL4oRpo368Vj4rfZyfJ7b3hgaaNmoTzkTbZiXSO74Tc
XAMaCOTX8HL8bYoBNJTl/whRG4Bf5wfYnyXkHcP45dCcUM9mcfnM98Cn0GYBtxeg
X2aXpP9irBygYw0wKOmQ1VmkSNgHhwJLP2gjpQTcs9dF9tyw7MaQphyh+H6EumN+
WmQUeFj1dcD14R29SVfAQAgHmX9DLuIl2O2jGuN48XivAklUNlmO03KlC1IyvRei
z+FHISg9urYk2Rj5RHM17SmkGLztaM1KmjTLGi+zX7pzmxjueqiSJWUlgQRjHCIr
uLqBIbz5nah4mHW87UrGt2/AkSTrHfld4ON4TgX2NA97QVRJIKIwZpTx2sFsP14Q
kpKjDH7oiyYRHNdoyTF5s6TVYwBow+OGLQmSSy1jfbgDpExgtCwS1QufFijqiC+7
HBkLD0A9Z+gL+sbjOUSyvYo/Id2q7KOMSN1MmUOG10iBa+W5u1mfHA8/Efd8S2eo
lcJ8yztmsHmmVW9tsCmKXnvuMGjz3UEpkfZ5ca6NIXB4HV3S98/nQjjRjFKmpvax
OLErI4HhHyFtmT8Q67Gpc7g+MZnM3SvfWCfbC1opmY+xn+kxQtAm21O3fjBBlcPw
B4O7sGO1FkjypmAvMl0iodp2TjcmUw2Vey25BS+TK9TfwQJb96WiTxFcgPTwvcfq
PNtv4utsf8NY2TF3S033zrvWyGSjAdX5pI3o8O4JBiwLPKwKV9jkgXnqSr1RA4hM
0EwLxAx+LeffG2diwNGcrbvT8HXdg6pwmSwZeD0mK0dvJMFgAh5LdQSRHwgcs3mg
m9v7XT/H4wkfQT5ku60ZPTXhpvRpC6IEN0KVxsfl9FYOZ1t4NLsH8Y/nc1uH19/J
LY2MQnaHFYVLIwMgNOEb9gwehFPZG07ZMUM4O4gShNgqOLHOD8cH1GMtl4kcs0SZ
69TfMnS+DWMRIv36juILVhJWDEYWrUQQJpjcz8mVZz4RwXb6uBLqlvbZkay/Sbkc
jhUFU6yeBNJbuIe/gVD3AqTAnBgPRax6gs9GFUJACTKJpeqQpZlo+ZMMe9Z6qOlR
4pCeue0h29l+3txia0Rrn4HFdzmOHXgw3txTgODD+vqUaCiRmIb/hgSpvVh8MTcf
25op88FIECBxX/w1E+t7EuJ9HMyX/o9cot320qOy6lGz77EeeQsAU/TyUnVa1xfF
MaBUTisoLE9reic6LATasx0ETqROlFyokXCrwEt1n7NqqU6KIul//exT52ptMguL
q0znfXLsBGIcGkUeM443rmovyPvzae0RAfP0V+kp1TsMnAzEy8M4XAHn1jHD2M4k
175xm8iWE8pcXeSSQK+GoEv/p1U5cP2sCuGHxwFLw0E2xsYzj08lSo1wkqx8lcxJ
qdzWamdSpVt/L7uR477WKPwi0HJm6AlzpyPGpok4C+XQs/FAOJxNF5YRF0Tv45RR
kUxd/tntw3agLTvcjbkxFfZ1WHQvV7QpISltX+sGcQr02//GLxZzp3Zr0FunIVz9
8BHob5vQycn+NXZKSmObukisr0+RZ5xcR9jjLQMSXvHLVjR1aZWtaJZs50qRcvub
uuiSVvuaW107ndPFxFJCG/lKR0Ldd0naK73XlF97uGS5BjJ86tE29pW4V0EbbmYx
LO6HelwZL9iVShaTSPOXJT0kYR7QYzfuOsmjRsWUoH4kzH9yjRSePDPszZrdtQiQ
mBmVhTj//9Iev6bElxMrPUfpV1nTfZkBblNNwIKX+4nWfLcjDn1uI4hTBo8W/0AK
G83VHpEBPnc6X8FXOnvG1VHX4uyJEmudA+Sdu31OAr9njQPKkFbwmpdLAi1MMYmC
dpf+L9UKPeoNOGwwdV+ukVPXRWTfugsigESFbQ5cKX+CnlSjepW+lnlmnVui1i5H
xpl9KzLc8rYCkW1j1JNFYMRCcRCe+5Av5nVxznhwwdr/4Uf+eSuOmoG/3QLjeDlx
F7MjFBGdKY4hoZiwrANabJ5iZO9PA8o3pu3keNUNmSn1XGHmSMuXDl75LPa2x3wM
pPca92e1XAO/v3riTaKbXV1fUdDWUo8qIGgIu/CcBQ7vs0kMKh2P+QO3YQlxiH3i
jOS4rJgbw4BVoWvdE6IpT5OT09UBMT97OQ46V2zrXGpfG62XvZcjGJEFDiu0sRHu
+FjHCNDeoj66VI09Y9qRUDokjRkYIy7PMI1d4+cCk/rI+OoF5usGgJBNFVg9JpgT
S7Cs3ZAu0OHrcTKDXSqpubUk/OnsGMrJoQVZPvqv7U6Gsf5AR5tCd6+cK6DiPv1R
qwJ36PE5RapUthTUFCD8NoHmBJiKoMCKz672tdy36yaG088cOGVUBLG1CUj1LQe6
+OtJvdmxVOqswg0gEHnBy+ncLf9VUE/2BQJ4MTNvFX4kWmYjcLOyDBc5zhU4xf9g
FjhgdHLJcNhZt4B/2vZnP9C6vhuhh9qSLaNsmSlXqsvRjWbxLclWYCRWSxmf9WWE
iYZ9TYv4W2Ddry1mdmxm2cb1OSVs5XtDl2RcxSAePbXckrKc2Bsb4LxEe5yVxVNI
kbKlRha/UK+lRMxUeD/tINguC0E98QSd3zxK14EE/4y3efhRjbcurCxU5vxDdo75
voy4XK3EE6+wbjvRglce9VKEyszSaPMtBP8nCuai+sCpl9ZkRRhcb57BZCJm21YC
w6hX/IcbXEMVjlj88gALT2pLoFza8uUbgkpr79tj132THS8geDcXIoLNa8GDYQWB
mQwlKdZfIrwGZ31n
-----END CERTIFICATE-----
]]></artwork>
    </section>
    <section anchor="xmssmt-x509-v3-certificate-example">
      <name>XMSS^MT X.509 v3 Certificate Example</name>
      <t>This section shows a self-signed X.509 v3 certificate using XMSS^MT.</t>
      <artwork><![CDATA[
Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number:
            5c:22:ad:8a:06:51:9e:67:02:6a:2d:43:3e:8b:c7:23:
            43:77:80:c8
        Signature Algorithm: xmssmt
        Issuer: C = FR, L = Paris, O = Bogus XMSSMT CA
        Validity
            Not Before: Jul 10 08:28:04 2024 GMT
            Not After : Jul  8 08:28:04 2034 GMT
        Subject: C = FR, L = Paris, O = Bogus XMSSMT CA
        Subject Public Key Info:
            Public Key Algorithm: xmssmt
                xmssmt public key:
                PQ key material:
                    00:00:00:01:4b:a7:89:11:6f:fc:1d:fb:d3:e7:71:
                    73:b8:a2:48:ef:53:b9:9d:1f:c6:8a:7c:be:4f:8a:
                    29:fa:41:fd:bd:da:20:7f:f6:3b:b0:c5:b8:a7:c2:
                    f2:5a:f2:26:14:eb:36:f0:26:2f:87:74:fb:0e:d5:
                    7e:17:a0:d1:4d:b6:cf:51
        X509v3 extensions:
            X509v3 Subject Key Identifier:
                7C:7D:59:B8:95:61:D5:03:6A:1E:3D:F1:24:AB:1D:ED:
                04:CD:DB:5F
            X509v3 Authority Key Identifier:
                7C:7D:59:B8:95:61:D5:03:6A:1E:3D:F1:24:AB:1D:ED:
                04:CD:DB:5F
            X509v3 Basic Constraints: critical
                CA:TRUE
            X509v3 Key Usage: critical
                Certificate Sign, CRL Sign
    Signature Algorithm: xmssmt
    Signature Value:
        00:00:00:57:c4:98:89:ff:d9:0a:8e:6e:6f:16:95:8c:ec:35:
        42:21:c2:ca:56:ed:f8:81:f1:b2:4f:2b:6d:73:f4:37:55:fc:
        f4:4e:15:eb:6b:90:de:34:fe:d6:96:70:94:8d:c1:e7:4a:32:
        49:30:3a:40:a4:67:d2:fb:da:f8:d8:a1:7a:48:22:1c:e3:98:
        bc:d0:68:85:29:c9:e5:f7:5c:56:d8:9c:80:be:68:ed:11:eb:
        39:0f:ef:cb:09:b2:28:30:a6:2b:05:bc:de:11:22:be:c4:dc:
        08:9a:3d:b4:49:37:1f:54:5e:5f:2d:93:62:b0:95:c5:5d:23:
        92:f3:55:40:78:19:00:56:9e:a2:f1:0e:4b:ae:75:d6:92:09:
        b1:79:ec:c9:18:67:19:09:86:83:74:5d:0a:06:ab:da:f0:af:
        02:97:4d:d7:73:06:8b:a2:84:c7:09:af:dd:8b:15:39:e4:30:
        9f:c9:00:25:a8:33:4d:de:e8:25:b6:35:0b:51:bf:7a:34:a7:
        e8:84:e8:fa:39:5b:aa:37:6e:95:89:ac:26:4a:4e:ca:be:29:
        08:4b:3c:28:a7:85:6a:ad:5a:d2:93:eb:12:e1:9a:87:1c:40:
        3b:cf:15:6c:43:4e:88:21:54:52:7e:0d:6d:17:29:8d:15:6f:
        ef:42:5a:a9:25:d0:97:80:61:31:22:a4:9f:25:17:51:ad:0b:
        a1:cb:93:b4:f5:a6:b0:22:1b:6d:50:64:2a:48:bd:05:16:88:
        00:e3:7b:56:d0:03:b3:7a:2d:6a:0b:f3:de:a2:8c:6e:81:80:
        2c:8f:e9:d8:78:ed:5b:99:c9:13:d1:b6:eb:78:c3:40:2b:a1:
        7a:84:0a:ba:12:87:5e:1d:38:24:22:8f:c0:a3:65:1c:1c:ce:
        2d:8e:e5:2f:1f:be:93:5c:fe:1c:cd:a8:9d:7e:7e:cf:18:e2:
        9c:c5:54:dc:62:61:74:23:55:64:66:21:96:4c:a7:2e:8a:94:
        a6:35:10:a5:e8:5e:6e:91:ac:a8:cb:ed:51:2b:66:45:03:f5:
        87:ed:4d:8c:4e:6d:54:80:a1:33:8a:84:9d:23:31:90:c6:05:
        11:a7:9d:bd:51:0a:73:47:bc:08:49:11:b3:98:ff:01:14:69:
        d7:c0:a0:0c:55:e4:5e:e2:fa:84:ac:27:b3:85:2c:99:71:52:
        9c:33:f8:9d:8c:d2:13:bc:6e:18:79:15:a7:02:ee:15:eb:27:
        d8:af:24:38:02:9c:ca:30:f3:e2:30:41:2f:62:a2:2c:a5:81:
        1b:71:6d:b1:94:bd:c6:3d:9e:5e:51:45:de:5b:f4:d7:e6:35:
        e7:d8:7c:d5:98:ec:7e:0e:f8:9d:c1:a7:7b:b3:65:b1:a1:4b:
        2d:ec:d9:12:45:6b:1f:0b:1c:6b:3b:0a:66:76:39:f4:cc:9b:
        e1:b7:17:f7:53:fc:c3:a6:18:f7:2e:45:52:b1:18:99:75:d1:
        69:bb:77:c8:1a:84:5f:06:b5:8b:cb:02:b0:b2:0f:bf:17:18:
        65:3d:a7:72:5b:71:9f:92:7e:3a:df:84:cc:65:5c:c4:5b:70:
        fd:cc:38:9e:12:6e:f9:ff:1f:02:fc:ca:f5:68:86:fc:ca:71:
        f1:3d:7b:32:b4:d4:c3:a2:20:16:3f:12:07:71:95:3b:d4:b1:
        1e:fc:8c:1f:34:8c:c8:ab:8c:bb:75:93:c1:1a:d2:85:3e:9a:
        e6:04:86:88:de:27:46:ca:f3:f7:f3:8e:54:18:ea:aa:ae:14:
        02:b1:4a:6a:e0:24:77:40:28:8d:37:27:9c:87:6a:81:09:d2:
        01:4d:20:7f:de:84:a8:80:8c:8e:63:82:be:66:df:87:30:5c:
        b8:71:0a:e9:91:68:71:6e:97:97:f0:27:4e:fa:ae:6a:85:ac:
        80:cd:38:48:49:c1:2b:9d:db:54:c5:f0:bf:fa:06:e8:96:3a:
        c0:95:f0:88:bd:8e:80:78:3d:dc:ad:5d:0a:56:dd:c7:80:9f:
        fc:64:58:4d:6d:27:f6:d7:1a:8c:b2:1c:09:ea:7d:4f:74:99:
        0d:4a:0c:b8:b0:ef:74:dd:6f:6f:dc:e5:83:e1:e3:c2:e8:58:
        17:b8:44:8a:2d:ec:df:54:f6:1f:67:a2:b3:c5:19:fb:b9:c7:
        1b:3c:ea:bd:2c:e1:43:65:d1:5a:17:dc:93:9d:c5:85:0c:55:
        34:13:49:15:92:e2:52:14:d1:81:aa:62:02:1a:ba:c9:b0:53:
        85:8e:7b:d1:4e:34:76:ac:79:d7:b3:48:92:bf:55:7e:2d:5c:
        cd:32:9b:c1:41:a7:a3:cd:b7:94:5c:96:1e:3e:27:4d:eb:f0:
        61:4b:a4:e3:3c:bb:69:85:37:e9:9c:98:f4:68:7a:61:77:8c:
        bd:b9:30:d6:f1:fd:69:78:3f:96:99:7b:69:39:90:b3:7c:b6:
        88:ed:cd:19:da:42:64:e5:32:4c:a2:30:f7:c4:e8:27:93:70:
        ed:fa:5e:ca:8e:7a:d1:13:af:15:b1:59:c9:9b:91:61:0b:06:
        d5:cc:2e:80:bb:49:93:dd:be:53:88:be:af:80:64:7c:5e:be:
        7b:8b:e7:5f:39:af:ab:67:42:6b:06:aa:ef:d6:69:af:a9:00:
        1f:a0:15:10:04:3e:db:93:b2:37:db:eb:85:59:43:a2:8d:8f:
        06:8c:cb:a2:1d:a8:3c:9f:f4:a4:7c:c8:cd:ff:f0:a8:79:0f:
        e7:d8:94:67:ec:17:3f:fa:6e:04:07:4f:bf:86:04:6c:fc:46:
        87:b5:10:85:a4:07:e8:af:a9:ec:5d:28:5c:80:8c:31:cc:c7:
        b3:81:17:0b:4b:7d:1c:9e:74:02:1e:ef:de:0d:1b:c1:c0:04:
        4d:46:fd:dc:0b:a4:c6:33:e6:85:0a:60:39:4d:0b:f9:49:44:
        33:e0:15:99:19:bf:c7:8a:c6:96:04:93:37:6b:5d:e8:be:73:
        d4:80:b8:81:0f:9a:91:44:cf:72:02:d3:c9:f8:e0:7d:d2:9b:
        2b:ff:eb:42:6e:38:7e:dc:cd:a7:90:c5:2c:2b:a0:23:37:b9:
        64:10:a6:27:68:47:c5:f1:e8:8d:41:c1:49:e8:35:48:ce:c8:
        08:4c:ad:f2:ad:5d:e9:62:eb:c9:3c:61:85:18:c6:34:73:fd:
        26:a4:f0:50:83:9b:64:54:aa:55:6c:d8:a2:21:81:ff:9c:27:
        39:1f:c3:a2:0e:e5:53:b1:d7:fa:1f:ef:29:8b:c2:90:98:ea:
        2e:dd:45:bf:c3:6c:a3:93:47:99:03:18:25:e8:a5:ee:2e:77:
        eb:7f:f4:49:49:59:98:c1:fc:ab:1e:ad:20:bd:f8:24:fd:21:
        1b:da:5a:07:55:c8:50:05:31:50:93:b2:f8:6e:db:73:4d:5f:
        34:aa:f3:34:83:90:f0:41:6d:c8:43:56:d1:75:07:f5:16:20:
        b3:99:b2:c7:34:25:c4:0e:74:5a:51:0f:7b:3b:7f:6a:a9:41:
        17:b5:47:62:2d:4f:b9:61:97:60:e9:ae:ca:ad:31:6e:4b:0a:
        47:9c:53:66:a3:4e:c3:96:7c:01:a0:8e:ae:83:45:42:e6:92:
        12:8e:97:6f:e8:a0:b7:7d:a6:74:24:aa:20:b0:fa:9e:98:e8:
        7c:b4:da:30:e9:94:08:96:b7:b9:53:4f:75:5f:0c:4d:82:e3:
        cf:6e:bc:fa:23:4f:fa:33:17:7c:98:b6:1e:47:89:3e:d9:a1:
        aa:42:19:25:ae:9e:3f:53:44:ac:91:96:d8:55:c3:40:1d:fa:
        ad:86:38:62:bd:27:2f:26:34:be:ad:9a:01:44:42:c8:54:a5:
        3a:e9:0a:ff:f8:41:6d:38:1e:e2:3d:08:3a:94:4f:1e:60:d0:
        b1:c2:8e:94:34:f0:30:3e:f0:91:25:ee:98:34:b4:8d:95:4e:
        cf:ed:1d:61:89:c9:59:10:68:f2:bc:2e:5c:bd:c0:0f:1d:9c:
        2f:7c:c0:27:25:14:9b:de:a3:74:64:28:14:2c:a2:b2:90:3a:
        a4:6a:50:e9:8e:ca:78:e5:b6:74:56:e0:92:69:7d:b4:2e:e0:
        e7:66:92:16:92:a0:c3:db:4f:d3:d0:57:4d:4a:28:ee:b7:cc:
        04:ef:17:d9:fc:01:bb:1e:b2:5b:02:3d:1f:5a:85:73:a1:81:
        96:b7:33:5d:79:e5:6b:c9:29:73:34:01:69:ea:57:f0:01:be:
        4e:f3:5c:f3:0a:a7:37:08:ad:18:9c:c7:4c:59:d0:5d:bb:01:
        f1:53:76:cb:cd:d9:84:5e:bc:22:11:76:01:d9:e3:af:17:03:
        01:ef:38:4c:ad:c1:7d:a9:c6:61:2b:ba:9c:81:95:86:af:bb:
        73:90:dc:d9:2f:d1:3f:95:6a:b9:46:0f:fb:84:64:7c:7d:86:
        65:aa:10:71:56:19:5f:60:52:7f:19:fa:d5:5a:e0:90:e4:b9:
        62:55:71:2a:61:f9:37:2f:5e:07:71:43:cf:06:ca:6a:d5:52:
        c8:33:e1:ad:b2:3e:a4:61:01:00:bc:55:5d:0a:f3:e6:4f:35:
        06:c4:a8:3f:4c:8b:9b:c9:41:4b:f4:c1:57:ee:3c:c0:44:68:
        52:5a:2d:b9:a7:f2:41:da:c4:8d:7d:db:40:b6:fc:47:63:5a:
        69:a1:c7:8c:cc:3f:af:51:94:37:95:58:82:79:d2:16:4a:bf:
        12:0b:59:a5:a5:11:71:e6:1c:63:3b:ea:f0:2f:10:e0:97:9a:
        a1:04:53:d0:72:f4:3c:77:3b:78:ee:b5:aa:6b:f5:bb:5c:e9:
        35:4f:69:65:87:29:24:ec:47:7b:78:5a:a7:c1:e5:f1:73:7d:
        4d:79:ef:ef:4e:75:87:db:8f:36:fd:50:3e:74:dc:17:d4:c3:
        3f:4f:82:24:51:1b:12:16:26:61:db:93:15:19:39:55:f5:05:
        2c:6e:85:dd:b2:cc:4f:c0:09:0a:76:46:d8:e4:f2:11:92:a1:
        e0:36:a8:25:c7:45:19:6c:98:eb:9a:fa:c1:ec:80:18:ce:d1:
        f8:c4:23:9a:f9:b8:1f:05:67:8e:45:cb:e6:ee:0b:fa:db:67:
        1f:62:2c:49:78:bb:55:98:1e:33:42:63:f2:db:ee:73:f7:60:
        80:6d:5f:9a:e8:8c:89:39:5b:b2:84:e2:c3:99:77:f3:5f:19:
        ec:b8:2b:ce:60:59:2c:66:06:f9:c1:43:b9:fd:94:35:9e:28:
        9d:a0:8e:fd:0d:c6:1a:bb:20:93:b0:63:6a:83:2f:0a:db:c2:
        b3:8e:b1:dd:f5:ab:19:09:53:7a:db:72:3f:1e:25:07:eb:1a:
        7d:21:da:88:22:e6:f0:ba:b3:15:6f:95:f3:72:d2:cb:6d:48:
        b8:ba:7b:aa:40:7f:81:fe:ba:15:c2:77:9d:86:58:bc:7d:89:
        2e:7b:3a:96:04:9f:f1:3a:50:48:5a:25:4d:91:b6:ed:de:f6:
        2e:4d:e5:77:11:6d:76:f4:23:5f:91:f0:0f:79:59:7a:f3:32:
        24:11:c4:88:30:21:26:3b:f1:79:0f:04:06:ad:82:6d:ea:58:
        4e:aa:4e:0a:7f:7b:5c:a5:ab:de:76:a9:a9:c7:d9:e3:eb:d6:
        84:80:02:ab:da:4c:5b:49:90:29:c5:cb:5b:1c:06:61:e8:9a:
        cf:a4:ea:9d:31:16:6a:21:3a:d9:22:25:b8:39:9d:4c:e3:86:
        76:a8:dd:d8:b4:db:88:f9:5e:61:c3:1d:87:df:a9:31:33:7a:
        b3:50:3e:f2:cd:ad:a0:9d:98:5f:6c:e2:f0:d8:27:b9:c2:37:
        7f:8d:b4:f8:84:13:5f:22:6d:9b:81:bd:1c:e5:75:ae:b5:95:
        d1:cb:d0:c6:e3:78:ec:8c:71:6d:8c:5d:40:79:7d:58:3d:5c:
        63:77:cc:2e:a2:63:a9:71:30:2f:59:2a:ec:82:b1:e5:b9:d6:
        bf:fb:21:e6:97:fc:70:45:9a:c7:e8:d2:81:73:b1:f5:bc:76:
        ca:b4:be:9f:39:b5:2d:f2:3e:c5:32:e3:ae:3c:fd:74:a1:36:
        5a:5c:4d:f6:de:d2:d5:66:61:74:88:2e:4b:69:7c:29:2f:e0:
        2a:d6:d8:93:99:41:bc:7b:7f:fc:c3:1c:84:ed:16:c0:08:78:
        fb:57:61:9e:83:7a:d1:e9:b7:ad:9a:85:1c:c3:ba:a3:e4:18:
        b6:00:f6:35:27:e2:27:1d:10:dc:44:1d:11:05:a2:db:df:0a:
        59:98:9c:f3:ca:3a:b3:26:2d:d1:c4:3c:fc:21:f3:3c:39:62:
        7f:f4:bd:91:74:ef:02:83:da:4a:22:40:60:9f:6a:9f:8b:8f:
        f1:e4:1e:99:d5:17:55:62:1c:60:01:7d:c7:41:db:19:9e:29:
        01:ba:a0:5f:41:f3:61:ed:9d:0c:9c:ef:32:8b:b0:8a:89:b1:
        e4:06:c9:2f:4d:42:2a:01:84:29:ac:f1:41:a0:a1:c9:b4:83:
        d9:87:1a:53:1f:7f:d4:85:12:2e:79:f3:2c:88:06:73:62:ee:
        16:bc:c7:8b:e7:09:96:ba:02:b5:56:ab:6f:c0:cf:76:64:62:
        0e:1e:b5:e4:69:42:4d:ed:56:96:d9:1d:8d:07:40:7a:c5:bd:
        d3:9f:43:07:e4:9d:b6:26:2b:33:6a:79:d9:8a:ec:ee:51:73:
        f1:91:b0:e8:90:42:db:11:55:57:1b:01:10:fc:11:ff:77:b4:
        09:01:6d:f8:8c:cf:72:16:df:09:12:09:bd:49:ef:33:b9:c5:
        8d:35:60:77:80:8f:ee:98:18:be:bb:3a:61:e9:5b:6a:09:b0:
        0a:1e:38:80:e9:71:46:77:a1:19:7a:c3:04:57:a5:77:e6:5a:
        01:77:d2:92:90:f6:99:50:87:3f:30:8a:37:3d:37:1e:6b:1d:
        a4:71:3c:6b:15:07:01:f6:3d:43:96:a3:f7:30:cf:08:2c:32:
        a3:ca:67:6e:59:da:51:2e:96:bc:97:41:4b:7c:5f:97:a3:cf:
        46:20:9e:64:96:08:f7:0c:03:4b:b4:83:09:db:6c:bb:94:23:
        4e:ff:7b:fb:2f:84:66:0a:96:f9:e1:58:ff:0d:3c:84:62:9c:
        6b:60:9f:7e:39:cf:33:f3:03:2f:c7:d0:8b:6f:f3:9a:62:cc:
        33:c4:bd:b4:fc:b8:80:9d:fe:9e:c2:f0:d0:9e:07:71:a8:f9:
        1f:a7:64:4d:63:f9:6b:ce:3e:44:0a:3f:05:58:90:0d:0c:20:
        7d:4e:c7:52:d0:e5:b7:61:d3:6a:52:08:37:91:15:3c:cf:41:
        ec:ef:88:56:dc:14:2a:12:55:cb:05:01:23:89:c0:fe:ca:de:
        40:d2:d0:96:a3:1f:07:4a:58:96:fa:b2:ef:78:96:f0:73:25:
        c8:2e:20:3b:d8:02:cf:e7:ca:b0:29:1a:25:7f:15:96:2d:fd:
        52:bb:29:c3:fc:bf:b1:7c:d8:0f:76:21:05:28:2e:89:d9:82:
        0e:cb:cd:03:1f:c3:71:b4:0f:75:52:e5:b4:93:8c:ac:ed:d5:
        30:5a:b9:33:84:fd:3c:da:dc:e6:84:6d:c2:66:be:93:ad:67:
        7f:db:d0:08:95:64:5a:2c:13:7f:e2:05:b5:dc:d0:bf:4d:6e:
        93:c2:3b:8c:3b:b1:5c:3a:28:e8:c3:96:ed:59:e2:62:52:8e:
        95:8d:b5:e1:c1:f2:34:5b:bf:5a:cc:f1:ee:ec:3d:6c:61:99:
        f2:c8:e4:05:5f:ea:d5:74:3c:ff:df:1b:20:bd:35:30:c0:27:
        f8:a4:6e:73:45:81:e2:b9:15:52:c7:a0:e7:c8:fd:7b:8e:f7:
        d2:0c:c4:e9:22:69:4e:70:62:c7:8a:a2:a6:61:7c:0b:5a:74:
        8d:0f:c0:e5:66:dc:18:7b:74:3b:72:ab:1a:53:b3:49:ef:50:
        aa:76:80:e7:11:53:90:ab:24:d1:2e:fc:66:41:cf:b3:cc:ae:
        ac:f9:eb:1e:19:f7:bc:54:00:16:da:b0:d4:2b:74:c7:35:fb:
        08:ff:67:14:83:5a:eb:6b:b7:b4:63:28:e2:b6:b8:d4:0c:13:
        6a:8c:bb:30:c1:fb:6c:42:df:23:c4:f0:be:25:df:2b:39:11:
        bb:82:c3:e7:f9:04:48:77:cf:d0:5e:3d:6e:19:7f:b3:c4:2f:
        c4:ec:51:5f:9d:c7:8f:88:9f:21:79:8d:a0:17:3e:17:73:b4:
        f5:a2:71:70:e6:99:c4:fd:4c:f2:63:64:23:22:c3:72:71:52:
        43:42:a5:90:e3:59:77:50:ff:a1:09:2e:c7:f6:7e:17:f2:a2:
        d6:7e:2c:75:f2:ab:9e:36:78:ab:57:be:c5:91:71:70:2c:ba:
        03:91:80:97:f4:9e:16:bc:fa:80:f4:22:2a:b5:75:15:57:d9:
        b0:92:9e:b1:35:db:26:96:77:28:9c:89:99:db:9b:55:d4:29:
        15:5f:54:8a:0d:58:a8:95:13:95:17:6c:6b:b0:2a:a3:fa:1a:
        ec:2e:b4:0e:08:ea:8f:e1:8c:59:cf:7d:60:00:f3:bf:b7:e4:
        5f:08:a6:02:ef:ce:d7:9c:8d:6f:56:d7:c9:35:e9:e5:cf:d2:
        f5:28:ca:e6:36:ef:c4:26:52:d5:4d:04:ec:50:73:87:dc:70:
        1f:1a:db:07:bf:4c:e9:ec:57:98:7f:bc:c8:31:9e:7e:e6:3a:
        b4:c4:77:93:39:56:57:67:05:84:8d:03:02:d9:bf:04:6b:fe:
        71:8a:be:b6:8a:ae:44:b0:dd:db:1f:6a:26:e5:50:d5:ff:03:
        81:d8:1b:9f:3f:a6:bc:1b:52:b5:49:93:b0:27:fd:59:d4:7d:
        69:e9:63:35:0b:9b:de:a1:d4:70:0c:08:41:4b:76:d6:cd:c8:
        65:8c:bb:9a:6e:e4:f1:e2:30:13:9d:a3:c7:67:16:0f:7d:bd:
        ac:dc:aa:9c:17:01:a6:27:14:fa:4a:c1:27:3f:07:7b:9f:2f:
        47:56:cc:f0:96:38:e9:58:7c:1f:6c:73:10:3c:11:68:2a:3c:
        5f:74:fe:37:ae:8b:e9:eb:c6:06:30:6f:62:3c:5c:6c:2d:c7:
        5b:24:6d:cc:75:3f:d7:d4:e6:72:64:8a:ad:03:67:ad:cd:cb:
        2d:7c:82:49:a9:ef:e8:b9:be:f2:6c:98:42:4e:26:46:04:58:
        a5:2b:c9:88:9b:a4:91:7f:22:09:12:52:2a:d1:4e:36:22:d8:
        53:bc:38:93:ad:11:19:c5:e7:c9:83:00:b4:b6:b0:ac:96:32:
        ca:d0:08:69:e4:d2:29:86:74:74:49:be:4a:b2:bf:f2:2f:c2:
        52:fd:15:3c:8d:07:12:3a:98:c7:49:67:81:1d:b1:5d:e8:f4:
        42:79:a0:f7:44:b8:95:9f:e1:37:41:5b:c9:b1:89:90:7b:66:
        96:eb:8e:dc:1b:d7:73:b2:eb:c1:42:41:e8:2d:28:ba:74:ea:
        7c:77:87:76:5b:36:10:3d:87:08:52:94:e6:60:95:c1:1b:c9:
        27:c1:42:aa:32:62:ed:ca:6f:04:4e:11:3a:3d:3d:e0:d8:3a:
        c0:ff:b9:9a:94:b1:79:f3:01:14:3a:99:34:59:8e:d9:ac:f1:
        a9:77:b5:2d:59:e1:29:96:1b:13:80:8b:10:94:3e:c2:51:db:
        c1:24:06:02:47:96:9b:ae:5d:25:34:af:4b:65:f3:8a:eb:65:
        7c:a5:5e:7c:a2:d6:1d:41:20:13:0b:5e:ea:67:b2:eb:bf:6c:
        44:fb:76:31:58:5e:d2:33:6d:6f:9c:3a:41:70:34:11:6f:99:
        8c:42:9d:d6:2b:14:79:b0:ac:d4:de:3a:b0:d8:d2:97:88:9a:
        17:68:3e:79:a8:b0:4a:d7:a7:3c:63:c5:29:c1:65:76:74:7e:
        c2:de:b8:49:ce:26:5f:d2:62:2d:0f:5c:cc:6c:53:c0:a4:75:
        05:52:d1:52:38:ae:72:17:7c:02:67:6b:76:38:e7:72:aa:38:
        70:5e:af:a2:98:c0:c1:7a:a0:6d:ec:90:51:8d:d5:99:8b:39:
        05:6a:eb:0c:87:37:5b:4b:00:91:2c:7d:8a:6d:c1:23:10:44:
        26:5a:47:f7:7f:8f:86:1c:c2:a7:9f:9e:48:f6:42:cd:d1:3c:
        d9:e8:95:de:00:3c:ec:db:a1:a3:c0:7f:f7:17:3b:4a:dc:d2:
        f5:d4:9b:12:19:0f:6d:13:38:72:06:21:eb:94:88:87:8f:a1:
        de:f6:d7:a0:88:aa:e3:47:bb:69:e8:30:59:82:d2:3a:6d:c7:
        26:95:92:a4:58:07:eb:db:a5:d1:bb:51:00:28:ef:6f:c8:ce:
        9c:0f:d9:8d:e0:b3:14:db:90:dd:f9:26:af:b0:88:48:ae:22:
        71:26:af:d5:e0:4d:5c:41:e6:0b:f2:5c:9b:bb:69:82:09:5a:
        58:63:b9:0c:8a:22:37:aa:a2:71:2a:a5:d9:a7:7b:9f:d5:f4:
        17:8d:bd:4e:de:08:6a:a4:20:ce:a6:85:c7:fa:05:c7:d8:03:
        77:0c:dd:40:32:11:43:2a:8c:50:22:4b:fa:a1:d1:f1:94:42:
        3f:d5:b8:a0:dd:01:71:6e:30:34:ff:a6:76:80:e6:c1:04:8b:
        f0:c3:38:14:98:ae:eb:fd:05:98:d1:96:7e:b4:bf:51:ce:aa:
        b4:66:71:30:9f:7a:45:b6:ed:d1:6e:8f:b0:6c:a5:f5:4f:ee:
        bc:ea:65:5e:24:43:73:4b:50:8e:c8:68:0f:23:48:ed:dd:ff:
        84:97:9b:31:0d:bb:2c:db:69:6b:0c:34:73:3e:ae:69:d2:f5:
        be:a8:99:be:7b:40:82:f4:fe:35:f5:3d:a3:b1:b4:e2:6c:79:
        b7:0b:29:ad:30:3d:56:9d:bc:24:e9:e6:a5:6d:cc:83:18:7b:
        d5:98:a3:5f:dd:71:72:29:71:45:8f:41:52:ce:86:99:5c:f1:
        40:0c:1e:b1:97:da:3a:14:4a:a7:02:48:d8:4e:63:12:99:da:
        28:e9:de:0d:17:90:3a:f5:da:9a:01:7c:15:12:bf:00:48:7d:
        63:8c:89:0b:b9:77:95:01:27:b2:33:73:4b:ab:a8:f3:24:ee:
        c1:d3:0c:a3:9e:26:fe:24:23:3b:82:b4:1a:5e:72:dc:9e:91:
        3a:7b:85:64:0d:30:2e:6b:55:53:7e:a2:4f:b7:10:e4:77:a1:
        01:4a:b2:d7:7f:1c:94:a6:a7:e5:66:e2:c7:e5:37:6d:89:2c:
        72:b1:53:cf:d6:67:0f:77:f8:bf:07:20:98:99:60:ef:2e:72:
        c0:72:9e:79:2a:ca:a2:f7:bc:82:db:53:f7:68:e3:ed:4f:38:
        64:83:1b:dd:a5:78:dc:db:08:a9:34:35:f6:f1:9c:76:85:5e:
        cd:59:a3:c8:89:50:5b:bd:a0:64:06:b4:d7:db:7a:e1:75:57:
        13:90:ce:05:4b:a0:f6:22:70:0b:78:a0:84:46:87:b4:a7:0d:
        88:c6:41:c5:93:cb:77:37:d1:af:37:48:b9:47:db:99:7a:98:
        36:82:cb:27:6a:9a:de:80:24:3a:29:eb:ab:bd:b0:40:0d:a6:
        50:e5:a4:72:a3:19:cb:f3:52:8e:2f:1d:10:ef:7d:0a:15:6c:
        49:08:53:55:84:85:5c:73:53:ce:3e:18:e5:04:92:a6:99:db:
        4d:7b:c7:a9:99:ce:aa:90:48:73:7a:61:f5:92:73:da:b4:26:
        74:a1:39:74:e3:82:f9:32:e0:08:ef:bc:2f:9f:6d:e1:da:3d:
        f0:a5:46:b6:17:95:b8:6b:13:7d:f3:a1:31:8d:b7:47:a0:45:
        aa:20:53:d6:f0:3c:eb:a2:e7:7a:26:8c:c6:c7:cb:0f:21:5a:
        df:46:06:c5:b2:2d:a5:3b:b7:01:fd:0f:55:1b:5e:58:00:70:
        94:a3:7f:48:8e:4a:67:a4:14:5d:e0:ba:b6:f9:9b:e7:de:61:
        d8:67:83:ac:b7:01:eb:62:c5:22:b8:48:3a:96:55:fb:1a:4a:
        c4:63:30:f3:78:05:a6:ab:0c:e7:33:a0:88:f7:e2:e3:4a:1b:
        fd:66:3c:14:be:ee:20:d1:32:95:db:97:ff:d9:c2:bc:7a:c8:
        e4:ba:24:c5:b2:2e:16:f8:53:af:b4:57:56:25:26:f5:36:48:
        eb:0c:20:f9:3b:73:ff:dd:bd:20:81:0c:f5:55:89:7d:46:1b:
        05:b6:25:df:96:99:ea:09:79:60:72:d8:37:92:a8:f1:75:a3:
        5c:6d:54:b7:f3:32:17:35:1a:2d:96:e5:5e:fc:cd:54:30:49:
        af:6f:1a:42:d9:98:52:72:73:74:72:b7:72:95:80:1d:31:5a:
        e4:83:b7:b6:d4:14:00:0b:59:ce:7c:bc:1d:72:24:ab:74:d6:
        2c:9c:20:b1:0a:78:6f:a9:76:8d:6c:37:02:35:bd:6f:99:ee:
        d1:45:36:f1:34:60:7a:12:57:27:68:05:26:14:75:3c:9f:0d:
        3e:b7:5d:b8:2a:6c:1d:a7:b0:41:c4:f4:3d:ae:8e:51:54:37:
        65:ad:0a:c9:28:a0:3f:04:ed:54:59:c4:9f:1d:3d:70:97:5f:
        f9:44:53:ff:15:9f:03:13:7b:41:6b:c0:f7:8f:a3:27:2b:03:
        39:37:8f:bd:91:65:4d:74:a9:9f:45:6a:a4:25:dc:4c:f9:7e:
        59:fc:4e:93:7c:89:8f:71:8e:a6:99:66:5e:6a:25:a4:c0:a6:
        fa:25:f7:68:5c:8a:02:f5:7b:49:cd:89:e1:77:78:95:1b:a9:
        21:78:6e:f4:7a:e2:04:e5:0e:21:52:bf:04:cd:0c:69:5d:d7:
        f2:57:71:9f:d8:01:e0:f3:10:cc:15:2d:fd:99:78:ff:dc:1f:
        8f:a9:31:0d:0f:9f:f4:2c:a1:3d:4f:b2:51:92:68:f0:ec:d8:
        5f:c4:55:a1:4c:c8:12:e9:05:7e:05:93:5f:f9:76:99:85:18:
        29:24:60:14:5d:b3:79:f9:4b:7c:e4:22:71:8a:c2:66:45:d2:
        41:14:5d:59:4c:0a:b5:2b:ab:bd:c6:50:f8:87:37:42:e6:d4:
        96:72:cf:45:f0:d4:bf:0d:c5:17:9f:f1:b9:12:5c:a8:74:89:
        9e:56:07:cf:8f:98:9a:da:d7:db:7f:c7:d0:3a:0a:14:cd:5a:
        66:0c:eb:02:76:a0:d4:56:e6:e8:be:a1:f0:c7:23:b3:4f:86:
        90:1a:5a:16:8e:07:0d:24:d1:ee:03:98:9f
]]></artwork>
      <artwork><![CDATA[
-----BEGIN CERTIFICATE-----
MIIU6zCCAXOgAwIBAgIUXCKtigZRnmcCai1DPovHI0N3gMgwCgYIKwYBBQUHBiMw
NzELMAkGA1UEBhMCRlIxDjAMBgNVBAcMBVBhcmlzMRgwFgYDVQQKDA9Cb2d1cyBY
TVNTTVQgQ0EwHhcNMjQwNzEwMDgyODA0WhcNMzQwNzA4MDgyODA0WjA3MQswCQYD
VQQGEwJGUjEOMAwGA1UEBwwFUGFyaXMxGDAWBgNVBAoMD0JvZ3VzIFhNU1NNVCBD
QTBTMAoGCCsGAQUFBwYjA0UAAAAAAUuniRFv/B370+dxc7iiSO9TuZ0fxop8vk+K
KfpB/b3aIH/2O7DFuKfC8lryJhTrNvAmL4d0+w7Vfheg0U22z1GjYzBhMB0GA1Ud
DgQWBBR8fVm4lWHVA2oePfEkqx3tBM3bXzAfBgNVHSMEGDAWgBR8fVm4lWHVA2oe
PfEkqx3tBM3bXzAPBgNVHRMBAf8EBTADAQH/MA4GA1UdDwEB/wQEAwIBBjAKBggr
BgEFBQcGIwOCE2QAAAAAV8SYif/ZCo5ubxaVjOw1QiHCylbt+IHxsk8rbXP0N1X8
9E4V62uQ3jT+1pZwlI3B50oySTA6QKRn0vva+NihekgiHOOYvNBohSnJ5fdcVtic
gL5o7RHrOQ/vywmyKDCmKwW83hEivsTcCJo9tEk3H1ReXy2TYrCVxV0jkvNVQHgZ
AFaeovEOS6511pIJsXnsyRhnGQmGg3RdCgar2vCvApdN13MGi6KExwmv3YsVOeQw
n8kAJagzTd7oJbY1C1G/ejSn6ITo+jlbqjdulYmsJkpOyr4pCEs8KKeFaq1a0pPr
EuGahxxAO88VbENOiCFUUn4NbRcpjRVv70JaqSXQl4BhMSKknyUXUa0LocuTtPWm
sCIbbVBkKki9BRaIAON7VtADs3otagvz3qKMboGALI/p2HjtW5nJE9G263jDQCuh
eoQKuhKHXh04JCKPwKNlHBzOLY7lLx++k1z+HM2onX5+zxjinMVU3GJhdCNVZGYh
lkynLoqUpjUQpehebpGsqMvtUStmRQP1h+1NjE5tVIChM4qEnSMxkMYFEaedvVEK
c0e8CEkRs5j/ARRp18CgDFXkXuL6hKwns4UsmXFSnDP4nYzSE7xuGHkVpwLuFesn
2K8kOAKcyjDz4jBBL2KiLKWBG3FtsZS9xj2eXlFF3lv01+Y159h81Zjsfg74ncGn
e7NlsaFLLezZEkVrHwscazsKZnY59Myb4bcX91P8w6YY9y5FUrEYmXXRabt3yBqE
Xwa1i8sCsLIPvxcYZT2ncltxn5J+Ot+EzGVcxFtw/cw4nhJu+f8fAvzK9WiG/Mpx
8T17MrTUw6IgFj8SB3GVO9SxHvyMHzSMyKuMu3WTwRrShT6a5gSGiN4nRsrz9/OO
VBjqqq4UArFKauAkd0AojTcnnIdqgQnSAU0gf96EqICMjmOCvmbfhzBcuHEK6ZFo
cW6Xl/AnTvquaoWsgM04SEnBK53bVMXwv/oG6JY6wJXwiL2OgHg93K1dClbdx4Cf
/GRYTW0n9tcajLIcCep9T3SZDUoMuLDvdN1vb9zlg+HjwuhYF7hEii3s31T2H2ei
s8UZ+7nHGzzqvSzhQ2XRWhfck53FhQxVNBNJFZLiUhTRgapiAhq6ybBThY570U40
dqx517NIkr9Vfi1czTKbwUGno823lFyWHj4nTevwYUuk4zy7aYU36ZyY9Gh6YXeM
vbkw1vH9aXg/lpl7aTmQs3y2iO3NGdpCZOUyTKIw98ToJ5Nw7fpeyo560ROvFbFZ
yZuRYQsG1cwugLtJk92+U4i+r4BkfF6+e4vnXzmvq2dCawaq79Zpr6kAH6AVEAQ+
25OyN9vrhVlDoo2PBozLoh2oPJ/0pHzIzf/wqHkP59iUZ+wXP/puBAdPv4YEbPxG
h7UQhaQH6K+p7F0oXICMMczHs4EXC0t9HJ50Ah7v3g0bwcAETUb93AukxjPmhQpg
OU0L+UlEM+AVmRm/x4rGlgSTN2td6L5z1IC4gQ+akUTPcgLTyfjgfdKbK//rQm44
ftzNp5DFLCugIze5ZBCmJ2hHxfHojUHBSeg1SM7ICEyt8q1d6WLryTxhhRjGNHP9
JqTwUIObZFSqVWzYoiGB/5wnOR/Dog7lU7HX+h/vKYvCkJjqLt1Fv8Nso5NHmQMY
Jeil7i5363/0SUlZmMH8qx6tIL34JP0hG9paB1XIUAUxUJOy+G7bc01fNKrzNIOQ
8EFtyENW0XUH9RYgs5myxzQlxA50WlEPezt/aqlBF7VHYi1PuWGXYOmuyq0xbksK
R5xTZqNOw5Z8AaCOroNFQuaSEo6Xb+igt32mdCSqILD6npjofLTaMOmUCJa3uVNP
dV8MTYLjz268+iNP+jMXfJi2HkeJPtmhqkIZJa6eP1NErJGW2FXDQB36rYY4Yr0n
LyY0vq2aAURCyFSlOukK//hBbTge4j0IOpRPHmDQscKOlDTwMD7wkSXumDS0jZVO
z+0dYYnJWRBo8rwuXL3ADx2cL3zAJyUUm96jdGQoFCyispA6pGpQ6Y7KeOW2dFbg
kml9tC7g52aSFpKgw9tP09BXTUoo7rfMBO8X2fwBux6yWwI9H1qFc6GBlrczXXnl
a8kpczQBaepX8AG+TvNc8wqnNwitGJzHTFnQXbsB8VN2y83ZhF68IhF2AdnjrxcD
Ae84TK3BfanGYSu6nIGVhq+7c5Dc2S/RP5VquUYP+4RkfH2GZaoQcVYZX2BSfxn6
1VrgkOS5YlVxKmH5Ny9eB3FDzwbKatVSyDPhrbI+pGEBALxVXQrz5k81BsSoP0yL
m8lBS/TBV+48wERoUlotuafyQdrEjX3bQLb8R2NaaaHHjMw/r1GUN5VYgnnSFkq/
EgtZpaURceYcYzvq8C8Q4JeaoQRT0HL0PHc7eO61qmv1u1zpNU9pZYcpJOxHe3ha
p8Hl8XN9TXnv7051h9uPNv1QPnTcF9TDP0+CJFEbEhYmYduTFRk5VfUFLG6F3bLM
T8AJCnZG2OTyEZKh4DaoJcdFGWyY65r6weyAGM7R+MQjmvm4HwVnjkXL5u4L+ttn
H2IsSXi7VZgeM0Jj8tvuc/dggG1fmuiMiTlbsoTiw5l3818Z7LgrzmBZLGYG+cFD
uf2UNZ4onaCO/Q3GGrsgk7BjaoMvCtvCs46x3fWrGQlTettyPx4lB+safSHaiCLm
8LqzFW+V83LSy21IuLp7qkB/gf66FcJ3nYZYvH2JLns6lgSf8TpQSFolTZG27d72
Lk3ldxFtdvQjX5HwD3lZevMyJBHEiDAhJjvxeQ8EBq2CbepYTqpOCn97XKWr3nap
qcfZ4+vWhIACq9pMW0mQKcXLWxwGYeiaz6TqnTEWaiE62SIluDmdTOOGdqjd2LTb
iPleYcMdh9+pMTN6s1A+8s2toJ2YX2zi8NgnucI3f420+IQTXyJtm4G9HOV1rrWV
0cvQxuN47IxxbYxdQHl9WD1cY3fMLqJjqXEwL1kq7IKx5bnWv/sh5pf8cEWax+jS
gXOx9bx2yrS+nzm1LfI+xTLjrjz9dKE2WlxN9t7S1WZhdIguS2l8KS/gKtbYk5lB
vHt//MMchO0WwAh4+1dhnoN60em3rZqFHMO6o+QYtgD2NSfiJx0Q3EQdEQWi298K
WZic88o6syYt0cQ8/CHzPDlif/S9kXTvAoPaSiJAYJ9qn4uP8eQemdUXVWIcYAF9
x0HbGZ4pAbqgX0HzYe2dDJzvMouwiomx5AbJL01CKgGEKazxQaChybSD2YcaUx9/
1IUSLnnzLIgGc2LuFrzHi+cJlroCtVarb8DPdmRiDh615GlCTe1WltkdjQdAesW9
059DB+SdtiYrM2p52Yrs7lFz8ZGw6JBC2xFVVxsBEPwR/3e0CQFt+IzPchbfCRIJ
vUnvM7nFjTVgd4CP7pgYvrs6YelbagmwCh44gOlxRnehGXrDBFeld+ZaAXfSkpD2
mVCHPzCKNz03HmsdpHE8axUHAfY9Q5aj9zDPCCwyo8pnblnaUS6WvJdBS3xfl6PP
RiCeZJYI9wwDS7SDCdtsu5QjTv97+y+EZgqW+eFY/w08hGKca2CffjnPM/MDL8fQ
i2/zmmLMM8S9tPy4gJ3+nsLw0J4Hcaj5H6dkTWP5a84+RAo/BViQDQwgfU7HUtDl
t2HTalIIN5EVPM9B7O+IVtwUKhJVywUBI4nA/sreQNLQlqMfB0pYlvqy73iW8HMl
yC4gO9gCz+fKsCkaJX8Vli39Urspw/y/sXzYD3YhBSguidmCDsvNAx/DcbQPdVLl
tJOMrO3VMFq5M4T9PNrc5oRtwma+k61nf9vQCJVkWiwTf+IFtdzQv01uk8I7jDux
XDoo6MOW7VniYlKOlY214cHyNFu/Wszx7uw9bGGZ8sjkBV/q1XQ8/98bIL01MMAn
+KRuc0WB4rkVUseg58j9e4730gzE6SJpTnBix4qipmF8C1p0jQ/A5WbcGHt0O3Kr
GlOzSe9QqnaA5xFTkKsk0S78ZkHPs8yurPnrHhn3vFQAFtqw1Ct0xzX7CP9nFINa
62u3tGMo4ra41AwTaoy7MMH7bELfI8TwviXfKzkRu4LD5/kESHfP0F49bhl/s8Qv
xOxRX53Hj4ifIXmNoBc+F3O09aJxcOaZxP1M8mNkIyLDcnFSQ0KlkONZd1D/oQku
x/Z+F/Ki1n4sdfKrnjZ4q1e+xZFxcCy6A5GAl/SeFrz6gPQiKrV1FVfZsJKesTXb
JpZ3KJyJmdubVdQpFV9Uig1YqJUTlRdsa7Aqo/oa7C60Dgjqj+GMWc99YADzv7fk
XwimAu/O15yNb1bXyTXp5c/S9SjK5jbvxCZS1U0E7FBzh9xwHxrbB79M6exXmH+8
yDGefuY6tMR3kzlWV2cFhI0DAtm/BGv+cYq+toquRLDd2x9qJuVQ1f8Dgdgbnz+m
vBtStUmTsCf9WdR9aeljNQub3qHUcAwIQUt21s3IZYy7mm7k8eIwE52jx2cWD329
rNyqnBcBpicU+krBJz8He58vR1bM8JY46Vh8H2xzEDwRaCo8X3T+N66L6evGBjBv
YjxcbC3HWyRtzHU/19TmcmSKrQNnrc3LLXyCSanv6Lm+8myYQk4mRgRYpSvJiJuk
kX8iCRJSKtFONiLYU7w4k60RGcXnyYMAtLawrJYyytAIaeTSKYZ0dEm+SrK/8i/C
Uv0VPI0HEjqYx0lngR2xXej0Qnmg90S4lZ/hN0FbybGJkHtmluuO3BvXc7LrwUJB
6C0ounTqfHeHdls2ED2HCFKU5mCVwRvJJ8FCqjJi7cpvBE4ROj094Ng6wP+5mpSx
efMBFDqZNFmO2azxqXe1LVnhKZYbE4CLEJQ+wlHbwSQGAkeWm65dJTSvS2Xziutl
fKVefKLWHUEgEwte6mey679sRPt2MVhe0jNtb5w6QXA0EW+ZjEKd1isUebCs1N46
sNjSl4iaF2g+eaiwStenPGPFKcFldnR+wt64Sc4mX9JiLQ9czGxTwKR1BVLRUjiu
chd8Amdrdjjncqo4cF6vopjAwXqgbeyQUY3VmYs5BWrrDIc3W0sAkSx9im3BIxBE
JlpH93+PhhzCp5+eSPZCzdE82eiV3gA87Nuho8B/9xc7StzS9dSbEhkPbRM4cgYh
65SIh4+h3vbXoIiq40e7aegwWYLSOm3HJpWSpFgH69ul0btRACjvb8jOnA/ZjeCz
FNuQ3fkmr7CISK4icSav1eBNXEHmC/Jcm7tpgglaWGO5DIoiN6qicSql2ad7n9X0
F429Tt4IaqQgzqaFx/oFx9gDdwzdQDIRQyqMUCJL+qHR8ZRCP9W4oN0BcW4wNP+m
doDmwQSL8MM4FJiu6/0FmNGWfrS/Uc6qtGZxMJ96Rbbt0W6PsGyl9U/uvOplXiRD
c0tQjshoDyNI7d3/hJebMQ27LNtpaww0cz6uadL1vqiZvntAgvT+NfU9o7G04mx5
twsprTA9Vp28JOnmpW3Mgxh71ZijX91xcilxRY9BUs6GmVzxQAwesZfaOhRKpwJI
2E5jEpnaKOneDReQOvXamgF8FRK/AEh9Y4yJC7l3lQEnsjNzS6uo8yTuwdMMo54m
/iQjO4K0Gl5y3J6ROnuFZA0wLmtVU36iT7cQ5HehAUqy138clKan5Wbix+U3bYks
crFTz9ZnD3f4vwcgmJlg7y5ywHKeeSrKove8gttT92jj7U84ZIMb3aV43NsIqTQ1
9vGcdoVezVmjyIlQW72gZAa019t64XVXE5DOBUug9iJwC3ighEaHtKcNiMZBxZPL
dzfRrzdIuUfbmXqYNoLLJ2qa3oAkOinrq72wQA2mUOWkcqMZy/NSji8dEO99ChVs
SQhTVYSFXHNTzj4Y5QSSppnbTXvHqZnOqpBIc3ph9ZJz2rQmdKE5dOOC+TLgCO+8
L59t4do98KVGtheVuGsTffOhMY23R6BFqiBT1vA866LneiaMxsfLDyFa30YGxbIt
pTu3Af0PVRteWABwlKN/SI5KZ6QUXeC6tvmb595h2GeDrLcB62LFIrhIOpZV+xpK
xGMw83gFpqsM5zOgiPfi40ob/WY8FL7uINEylduX/9nCvHrI5LokxbIuFvhTr7RX
ViUm9TZI6wwg+Ttz/929IIEM9VWJfUYbBbYl35aZ6gl5YHLYN5Ko8XWjXG1Ut/My
FzUaLZblXvzNVDBJr28aQtmYUnJzdHK3cpWAHTFa5IO3ttQUAAtZzny8HXIkq3TW
LJwgsQp4b6l2jWw3AjW9b5nu0UU28TRgehJXJ2gFJhR1PJ8NPrdduCpsHaewQcT0
Pa6OUVQ3Za0KySigPwTtVFnEnx09cJdf+URT/xWfAxN7QWvA94+jJysDOTePvZFl
TXSpn0VqpCXcTPl+WfxOk3yJj3GOpplmXmolpMCm+iX3aFyKAvV7Sc2J4Xd4lRup
IXhu9HriBOUOIVK/BM0MaV3X8ldxn9gB4PMQzBUt/Zl4/9wfj6kxDQ+f9CyhPU+y
UZJo8OzYX8RVoUzIEukFfgWTX/l2mYUYKSRgFF2zeflLfOQicYrCZkXSQRRdWUwK
tSurvcZQ+Ic3QubUlnLPRfDUvw3FF5/xuRJcqHSJnlYHz4+YmtrX23/H0DoKFM1a
ZgzrAnag1Fbm6L6h8Mcjs0+GkBpaFo4HDSTR7gOYnw==
-----END CERTIFICATE-----
]]></artwork>
    </section>
    <section numbered="false" anchor="acknowledgments">
      <name>Acknowledgments</name>
      <t>Thanks for Russ Housley, Panos Kampanakis, Michael StJohns and Corey Bonnell for helpful suggestions and reviews.</t>
      <t>This document uses a lot of text from similar documents <xref target="SP800208"/>,
(<xref target="RFC3279"/> and <xref target="RFC8410"/>) as well as <xref target="I-D.draft-ietf-lamps-rfc8708bis"/>. Thanks go to the authors of
those documents. "Copying always makes things easier and less error prone" -
<xref target="RFC8411"/>.</t>
    </section>
  </back>
  <!-- ##markdown-source:
H4sIAAAAAAAAA9S9WZbjWHYg+I9VoCM/yr3oZsQ8UCWVOJPGyTgaaalQCMMD
CU6gARwtlDq1h9pAf3btob5aO+mV9L0XIAma0yM8IjOlLE8/nmYk8N59dx5f
PDw8cFt/u2Q5/of6esvCNdvy40dVMPnnnb30Hb7BTnx97YVWtA13znYXwqP5
5TQI/e1sxdddtt76ns/CiPeCkK/1+7y1dvlxq9//gbNsO2R7WDr9MT1HW/zA
OdaWwVKnHB9tXS7awjM/WctgDXvAboz/Az+Y+RG/ZNuI30W8G/CetXZOvLXb
Bg9TtmahtfWDNR94fMg8FrK1wyLO34T0frSVBMEUJI5zA2dtrWBVN7S87YPP
tt7D0lptoocjwPEQzezoQdC4aGev/CiCFbenDTxdLw8qHMAvc1bILACSOdwh
CBfTMNhtcnwz33ru8w9801/5W+byedf1ERxrybeYM7PWfrSK0fLcqI8JAf1W
vVXmFuwEy7iwQYLyhxLCxe3ZesdyHM+nN4BfY2heYGd/PeWr+CV8urL8JcC0
saLVP+KJHoNwCh9boTMDlM+2202Uy2bxKfzI37PH81NZ/CBrh8EhYllaIPsD
7gok3dnwLiEFcJKN0XXB0Q8cB5ifBWGOe4Dned5fRzm+9MiPrDVfZSza0qcx
qktwfrb88BVsnuOL4WmzDdrsuOX7zNkBJ53oSxafyKUXH/fWeorv/aNDj6/h
8YcoefzRCVZpEBqPfMGKZn7opwBoWHs2u/mcdi/06+ndFvjUox0/RRj6xyl+
83GL/iNfWe5mIQtTW/SdYLu9+Tw+oB85Ad8/RVu2itKbRV786D86+MSdLarW
u2tN0ztsmYcYvH5OOwDv7yy+urJr6eVj6OnRR5d9WLoR7CLf9aObxa19GES3
X91FUvLAR/xw6yBcgQjuiWvrD6XHrwQs9BxDFwzbByiuP8PTvUpRNUUxl/wo
GUKO/8Ne5h0WfuH3Eu+Ey/grQzZF+Oq4ipLXDFVV4INZFC0Jvf1nQxAkwcgR
yFsrnLJtjj8LgBv4xPOi8KgJkpFt1/uDx/7zI7zzAC/F78QqsMfgUCu2dmOt
gpILKAIK7JZ8DTjkAZgJ5LzvT9cWakKg/4ytWIy3s2Tw9Och+f8E/20rUQz1
dQSb7bYMdVYfFZ4VuhHphgHojHWwDKYn/hMC+ZmWAFgAMgnO9yACwCbH+Wsv
jXVAiCzp5vlHTdGTHxVTOX9qKKJw/ZFw3ipWe+WX+yhjm9Bfbx99ywkJdZIg
allZ1dO4IsTwLWttTQEF622s/u8g6TuwAxqk5VRDdrj/9TMwL/ASbLVIePSr
Rz5I573vUyJ0D4DCbuuv73/7hN86s5W1Xt+QRNQeRPEB7AvPF2qi9htwKQqK
9LhxvTRCO8Em+sLXedd3eX/LW1PLX/P/3//4nxcdiRzTWbOHgb9iKfTyu7XL
Qn5wCB5aLIqAHHx+u7WcRfT465hvwtHCnY8r+OvFN3FX+/f/vYzA9nw4Pvxa
bPfz0qNw/+wr5voWaCKPrSP2OA32cHpJyvbZJivo8LMgC7poyEr2QcS/QrbY
z/+EK/4ES/6Ub1Y7vfqg1ur/9PhcqqRxVUQxDR0fBOoiWRc0Xb2T/g7sMg9r
8Z9wVfzpM1882eCtXB52934EHgg80c9//g2CfN0OdLGDInt+/yKx0gPYTQGl
pjzo1x8GPZBg+UEzpfvYOhwOj+DoxNrKZUuQ7zCLH/y0DYFjZE0QfsL/M036
zZSygvhIf3/ShOw2jL+U9oKI/9t85K9YYFe3Ahud1RseGl05J1Z9q4v/8uso
Ke/CYMPASA3YkhTobp0sE6U03FXxfUJsfECVCJKEFiTfzj80W/1vI8gH+GMX
Bvy06RoPEmWXzJ/OwEV4WMHGS/8hughHNo2B5vmxFj2WlqFPsOl3UB/hO4OJ
vux9OO/CiObrAXwYsC7MfZihorRRUX4L2B9ofb6cvHFftf7w3SCD4/mAXuhv
xGy08h/WuxVKTPrnx+Nsu1r+IfXJg/goP2qP4qMK/9MftZujwOZXebn4wxc5
/Q3HyLf7/fr9Mzgo16BkdvtHL8xGIPngv4LztFtus56/xN8CZ4fHynrBchkc
ftptftoEEbnsP22sDQt/wh+CaPvT285ab3ern2LXcxpam9npozwRKPzeZ4eI
B4kB8eGf4d2Hbvxu4uXG70I0Yq3jnfhPwO4yH4PA7zbfwXWkYRj4bLHqYbzL
+KXFR//+vwil//6/4IOIj8Dd/Pf/B7wR3v0vFxcB9yNAP8ib/CBKDxKKXOFb
+ESesEEb2WBfQIdn+zMIgtxS4ETZUnBYLwPLjbLldhYWyMaxYizz2UIYODPg
zmyCxYfI8tjDL6Gym3qQTz9I9s8DACykm7UEAwlHDlF7uWzPlsGG2JTcp/DG
efsOvVVAwxlZK9CE//6/wdPzwZkLZwxsLxheNKn1KxbBkwfnzF/wnwpf4RLU
vPogGhz38PDAWzbEyZaz5TiKXM8sB2EaczBOBlgv5slPBc94gny//SjyQOvA
xTgv3pwCSA6566Krr8qDvygP/lOt0P/MR7FDytdgUYr6HDRVV3+VQhLuE8Tj
n7/wbJzolhYLF0v2lV/Lf0IdBA+eQ/d/bg3gF34FIuU/bEPGuL0Vgt7YomuC
DzzG8Xpy2MSWWJvNEg++DUhIvplmQMc2lWbgP4GW+MwfwCzBe0EEbO9DhArn
uWpMCHYZv0NEAMluF+YgjtjGQLAYvakPgFn2QQLe0o+24CoR9Va+6y4Zx/0B
FwsDFyCBRzjuGgUU+hccR+AT8laEOY8vcWYjhScOmNH21+yMW8RWxB+A7ujD
8R99uE+dAVAPDhGEyHmAqk0Y7IFBzofmrpQ+77+dWVs4yAr9RPJnGA8ysY4x
lsgeD2BswOgCh9koH4yz9pgQsJcMacX8EGkShAwsP39xioCEB7Zcxp5ltA0C
l47msg3wC2q75SlReVyUck6RuvTK8oT8i2yKwks4fOTzCcbgqRPvWAhzuGeI
QGvN+atNEG6Rk+ydvyT2t5eBsyBr8fEscOjIj+jptKIDELkb94PfXiIqoG/+
KkBIRXDL98gJC0bntXjPX6O36IBiZs45qwRkwSdA78xIB9PRLW6ZZHxi44cP
rmLXO6KT2Yx4lMVoQ7SkdvsvUQwIiFEEx2XcboOqJH4WjBAeDX/z8KS4DCKD
GAKpixQHhk/D9sjzLzMfeQzoEaKLA6hNneGqcDZWCIqUuOEQ7JawCRkh6wYZ
sBXuCqfc++F2B4+cgKp2sCNVcefEn8C1f+Slf9YEUBVblH/E55bO7YBFJBi4
JZqXMKWwIv+d0ZmXwXqaPiqIxiNf2rGzwjiTbQ0bJmzGpQE+4/hroqQUBQlL
QhsnZIjwL7cMkYgVtyIMrgOkDeoucG5Bx8FeyIqIehA3H1UNaHlw0VFQtwFw
DdChFhyARuEXfCQCYcPHOQcUdUQAgvwsgxOZAwTunk5ZWacP2z5CFANSgxvH
K6HKA7vlhL7NXI7k0o+cXZRowZ9/hkcf6NE4r4nZuz/96RGVWjFYIwuRZ44v
lhgxPZlLsFcxOjEzGfE/tIb9wQ9f4v/n2x36uVfuDuu9cgl/7tfyzeblBy55
ol/rDJul60/XN4udVqvcLsUvw6f8zUfcD6385IfY0vzQeR7UO+188wc8z/bG
jOLhgS1sFpMAZIJkJeIuGMF3CsXn//f/FhXAxf/VqxQlUQQEJL8Yoq7AL6gj
491IouNfUTNxgHpmhbgKcD6gfOPHfgfoqWgGfg8ogpABNv/rHxEzP+b4/2Y7
G1H5h+QDPPDNh2ec3XxIOPv6k69ejpF456M721ywefP5B0zfwpuf3Px+xnvq
w//235doxMC9+e//wCELDYEPi8SHcf7qysJJLgwxF1v2n/9wjxNBEUf8DbVQ
NC7RAbBoBGYvTOJH2OTnn8HGXDK/f/rTF8yO+BGaDHpsz2LhvpEn+HJJUW6y
jhuQRMe6ExXnVTUkPsvKWoDw3yxyUZx4qI+aIK4+LK+CSfaUZ0dQC6D21m4i
V3F25gCe2OwWxBv/JJH72JXBgoe3RT5PuyybAPwk9KP+mKT5fnzkEoVDKESB
IBWdmIe7+sVK494+8X88505/PCtHAgGNMjfd+ZiFWLMcx/2ce9sFW/Yn7h94
8XNMAH7NHDQBIZmMC8LBmnzlpyXbn4m9BgHjvB1+83f8P/0TrCl9jo9wQzXw
lpbo7KKTQEYCNLzH0Dz8HUkuvSkTNLE1S3T2hjQzOr5oQK6BF/yGsHlUJ9p+
DSWXQBmgob8DDvgzsDxbJ3qcuaAF6qAmkqoPmBMf37S+7WcgiknfJKUrdnU7
Lkbr6uiB0rlq/ZtkDa0b+83oACBeb7gJFBXiI0Yd2Erm+s4WfT4+xKLK2Vf7
tqEkzAMqz3CCrfRAHWIGEGO0JTIreg64yso6+ivwzr69mvUVEs7rAgaHlyMe
ULN+/yG/NpW8S04DBUshW5JuAFCjFWryu+BdzndxIshvC8FHs2x/iYUp4BqG
TiZQ9uLrwqvb0HcSFbW+vIjuC1uD2xRQ+gRAdpY7F+Xnga/44epghdcHP/UT
F02EoA/AuoriF35AxKqP6PMkxQofJ29w2qNO30As+uNnWLsfeNvbtb+xwB8p
F0DvFC+4RBjyFCjj2T4V859vEB1zObNAf8V8cyYYGUw+IC0M3IlOH26KaivA
6GmJ3/sXx45LYyaJBFBt3wZzV4r4KHGhS+dK5QR8h1tBYLZMgjpr55LTZzOg
EbtQIlY7ABJxUDRDDr6NrmJnGkwBVmNjwwAnrcZaHbkG3AAst375NkciZKhz
7jiJEMsCJ7gP6G0BUtP4hFAi0dqJOvTOnIHniT6SklCdiv5SVW+SUniekeJe
0fnReQXoEwosQUkBd0DYt7LWO89ykooBkhAipThooljvAVjaSlBFYnrOPiz9
BUsMOp6NSAphlnuFEJeIY5hU2hjivWVE/jseLGRJ0gAiEEBHPRjwEI1GSYE0
FvwYs8tTXLkHKG42uY3m46gfaBIzZ2KLv/BhAOQo5mMbifWvH6+qNsVo6NzF
+DrHzSnWxOP4UbRjnMcOQKWbnYFlwbXf2cBI4BLAqjebpV2JOBq+Y4rjc3LE
QQRDmn0AsuQMd/b1P259k+NIhx8eWqGbR0ntAkHjAPyqyjBovjKXA1He9oN6
w7USmL4QC4CLg4YRd6GlbkEi+0b4i4iCD/coSKpjDegh/vmWhCUCwn08Scop
SozAJogiH3Ma6KLe705Bsj5f4l9im5vQ4guIAVh2D93dNTvwnXoptrpJlo5S
GhTFXTyIM9jc3YTc1XsEWbi6CeBxwNKomuLNkqAtVSeH8ASpErINhakUcBAk
DoVvPiYiHvkKfGCR/BNUCG6skFNBPgUkNuMsOwJ4ETl/oA6dexiKA8DAnoON
SWUm46zElST3speXzp+bQ3EfDhX7x+415CQx/vqUl0aex2+BhE8BN+OOaWaJ
+H/x3QcA8GEWRQ/LVURVFiDIv4AB/rd/+zfM2t5/gOc7hadyccDXS+X2oF6p
l3t8Lvf3/M9JwtiPgk/g9q4YuhAPduCePoHHuos+GYrwmQ8jy438T6Ioq4r5
md8snAifxv83P5mfkzWiFTiun0TtM6LwE7itos7/icDi2uBZx8YQ6fetQ9xH
PVpdVLSENXD00P+xrphYba8LnJOzp3WwPq3wzZhlEwcGOGblJ/0H55SqtebA
VweBpraOM69donGC2WYO8BspQWzM+DEhW5pn1mm52FtL1A1nsaIVb1KFF19s
RvW6CzCoCoDm2WarT+nUx+ue9EoqlknkOHZW4g2/8PYOlTtVkgBdUx+U3In7
47nk+CPm3lb+NlbcyfeX7rKU9Kaz9mcLTrFMLF+UCP4tApZwM713n52pdPhN
Xk5/+52MfNndfQjCKRjsdzoocqUbuJ+0z3F2Zc228PSZfxOL8Un9nDLz+Ntm
4R8/6Z9TCg9XkJUze//1uIFwlmIF2RT/bFbANf+SvPDPrcHvZQd89dscsdr+
Mk9cv/9b4gr1P4YrEHV/s4xx01p7fZDjimmXD6w9+uBJ9v+PSY9cnKchT+CE
gfUVgzHjnFIfcRfcx7Y37Tj5a/fiWqZ8FfgtDHbTGSLh8iF3PU3sytwzRA4m
7qJt7DCuyceh9OomwcjVLQEUfFDcFxJdacKH1oEPnC1DNyuMA+u4LnquAdw4
0lf6p1y6R/4l9jITY8b3dyRuMfoB+1jgpebaL2c/8+ZrvlAf8P1Br96uUkBl
+evo+2DjUmHi48dScHzIKCn3doqD8mUXhCX2Oi9V4O2NnFCwtKao85ePFVP8
ZnGKTDYb8hF46+vTfrJiMaAzACCp43/GjGDcshDl4qwPFnbItUeGWm8527/4
Bze7xkvGxcfo7qt86lXYkku/+CUJisFJ+bu4yMOsb7+d3phLb/mLb12PefWQ
rxKaVEY+Opu3HtgVORdNvFk8wDvoWTxg604f1PDzsNCsFx8a5cmN+k1p5fuu
37l94YHHV9dBwjmHEKiJLPJwbmx4zvfy4Bzle2U+dvmTz4vl3gC3fRj289Xy
pQuC//mcBL1Uor/A8use2+xc34qTmnBaVEv4xBfe6TXxB/5PaS3+tR9+DgLu
4eUDUh6u/Ic4uaEg7XBVFWe5+UUJTNTPB5jiQBMF818Atz/F3/wE3/wLf+k3
eOT7jKUNxEU10e4olBSup0vOwZqLq5yYe0/6UOJv78LxyN+6+gjVklEnxddp
aHRzsZa6pkq3H2cpqdsgbiO4JjSX2AqDuWlCxNsuznyLMTfHjuVX/PyVu/k9
DI0v/XZuTjuof+OsfMcJ/yVeTuPj+xg5ZeX+XEZGtP5WTqbt73EylwSB3+bk
D6i5dXDvstdH9/V7Oaw1+H08dnV4/w/gsq99+19jtCta/lNYbbX9D2a2WwyR
34wnHlKHewF88BiZl7IntZk518mN7ezS3HN2di/lZvg8XiflEnPUnIvDX1dn
+5EjD/K+Wf5yNwKnjOG9ICxuLLiEA/ecNg6kY+nGKddiPsm6p732C2Cxw5r+
KiYZnul6Dsr/JZ4rduTEblCwPlcAuZjRkM5xAJT7rfwdhFzC4un085Y/t0Jc
dg+wEpDsArT8z0IrVWX4pCrza/jl7+KX+3788t+BX+4Wv3jQ34XRP6TaN6+d
1UnsESWlxosOjq757XN+Ppb3SzPjTddnHElxcaz8jQbWS9/MbUAZ4z7u8rvA
dY16Y0RfNBGdMoAI+2Mqm5bBoMbC3oOY/e8sx8d9NFgX5vvl7rDcLpaRGEgT
bB+E/8dUf4pEiAculYq/JRsESQnuLlx7W2K8j4wP/S0fO5godNsGXNyIhgWQ
y3oBlabi1jqUPWQYBkyV2idKOmrdc4Nc8jiX1EATgj7yN9jivd1yiU3LVtJA
lXQoInfEP4UWcRSWmjjrvO855QvvJYndr/zbm3rrzcl//vlc49YeJXwj8abP
xYB4KS7lYHzPWoXrWmBi4mpJQrYEMi5lQr5nxeKHFR/j3FzaVoZsEzL0EM4x
+c26xL/M5Vw/hCWXpzguT6UP0GMPMLfkunHJ9JTOFt26J1TbobgilQ+iQ6Z+
b/rR9mqEz7X4NMQpsBK2/uEC8wi1xg9pAGP5usS/d3TJ3WAvKWVRCSLh6qT7
+5T0fnzkkYMVcdcif7C+8uaF6/1H8CpSjI3vUMoDdf611k/xDrcJA2xDituZ
tgmEd+Tz8ddqQP+pJaDfE3p+5UNx3xbNVG3im6S9Z3Z/I6k/yPBfndYf9ksT
+zd7pb+O0dvdEnV4tzMjKbxithhXQO/UcaiGTclcnfQNdwXvNpr6HgqlPKDf
QaMbxcghyv/qZLrVxf8BlLrZ8C9NLApFqpc1rt3TqXXpnosPYyG/eTNqaCDz
0KKuJ/7nP2A7rBWtxT9xXCVdLwdGCDfBpTErfis6gbd4pE6o2H4l3Z3r5Pu4
lyppaiZf8WY3msaI+N3mivJLB3m6Y8hPgiZTFH9MNO0Yb43o1wr9B0mQFA6D
599TaEqXmEiP3i8zgWjAUT4J558e8Asx7jvG/T8NCqXPoG25UrlSb9ex0bnP
11vPzXoRjOAgX+2Tui+Uq/U2x5XHz53eoM+DL/l3HAeP4W+w+zUf8YXv16vt
/GDYKz9cBpUJvkqv07oKbmqG7AFvI6GsxAVV3Dmt8GeU4L6nCHfBznUCLsaS
dQ9OQfqkGoQsWNv6mMb+cie1fT14a3DNiEmCKH884Z9lQAnsqxX9iuapbgfa
/JOmwDH+Dme74C/fiYut6ZIbfIHffMMl+MUmHY77rQX4vwT7f3fpnfvtpeD/
MPiwCJzQ5F7QGvdqpVKKCZW+5sVfoxC8cZOzviOz1+P/eub6brrwqhP6wOYf
s+R/wkfo1p+HYv4Zn7hsU+ILk7tOFyYLz6CnkqG/A/jblOj3g5/a9TccIMVm
f4opfK8K9isk+54yw69T6ldSv3cxcTfp+2dlfLnvy2h/D+3+Rg4UC22qf+ET
HPFzOuEET1ySb9Hd48IC5Giw48bCcdLU414YrDAM58E6St+oov7rvWJU+sMr
tr/gp4+Pj9wvq5tPIGuf8YHLt/Bl9Mvy9vEQ6VfP6351mjsK7F+Tz78+zVcK
IH2acrsUB45/+OboVOwoXuamEgf4OsLwtvNDFo/P30wfXFzUrbVgNOoYkI+6
ow7SfPTN8Zbo7nzLL01lfuEtDsKUkF8z5kZJXsqi9vck77QNcETnG6Ml1CGM
2X/MpV22jJMdfngZnvkSp0oPfsTil0I/WgDhZtYuuqRzrlskIwHRdaHUGR9j
n/vebFUyl8Y74Y4upsHQaxvizOo2niWiAWeHjgYePyaKzoPAlztZHrk6xS8W
XeCDc2PUPp+MVQQ2JX5TOKA6xyFI9SSfp3KT3KJ7LeMAQ63YeWg4acC+jE7F
zRLJhHVyzwTQ0WMW9VVzcUEFA8gzZDjmEacv4bspC2kyDa9B+pFGvSE2TMKC
+KIpiuu4P364COfHL1itQDYESuE0RYoPzux3Hdqw9oEfZ/qQgtw5oE2OdBla
olkOiqvIk8GDUC40GUym7u4U+9O5OGpKSe6UoPloXCwZKPOslb/0rTCuu8d3
TdDrEUEdX8mwdnE8CvhjZIV+sEMxQXac+gmZrG8S/Tx5l2R1aVqonhqnw4st
wrh8sby5/OAas9vYC4Y42FjAr1YUBQ41DIDGiGH+MB1JPQUOSzqCkw2SXvpo
G2AfcbDbojahRDuPmPGBdeMxRj+6JBcuUneTEn3kizPmLJImOVocJJRPT93w
l6mbc+4gJsxNWjVkWFHBGZZSGGxiOaVLwlKJBKDGDNj4FOxCsILtehF7+LZY
6/DwQz7aBB82xLseaI71G1iJVVhMM4gq4vPdVUE4xQTQECPGwm8tD9Ypuh1B
XDC2IfJTg1w8wk84Qdjti3jDQru1tbL96Q7Yh+ZgLADGBnEjwl+pfYWAjpIH
vonzLDFnYZwf7uMcRMKEp9vM9znvrZLmTwT0SzyAh2BsQA9Q9WN7GbeJF006
ztw94SnJ7lD5IHzkzxMVgIFblYoEI8ii09qZhQGEB4mNstn2wKifbb0PcGBv
GVP08guEi3g5F/GCu3No5hJsXgGQstvQoz1GDJu6ie6mj/Iy2YZySAORM386
A3SsyGyn1QtbR7tkhCy5JCOeAEzTPJ3fSVolMa2P7+ytpe+iaQX94QfumVUQ
j2fJjGjeEftz7OsBwuQAKX1x+Go4Zol25ApFbHK4+OaFfrP2UOrnP5+H491d
XAi/uXUC14LwHkCD3algEiSje4xD1K5d7Io7AxyLe4TFSDJjwXk6zfLYdGch
7wI/by63fiQbcR83uo75+dubAWNclW15RMFF7K8b06wnCD6iPr54B0UJjZzv
4BgZMf637TDtiujE1mCQ4wMC/CsYR3UPyoYgQw8gVk2kPIlhNmFgJwxB+bNv
a3M/TowimgClDFm2f2sK8MYWtORE3xSnEXCoLWLC3+4AxOXuCrF+675RdpL6
l2/9QY7De2fu95tf04VJOhADs0uaMZa+tx3DqTzu/Pz9O72StGF68OrT7c1g
wmfu3FgNlu5f+RJz/BVQ91+TDE+Jzkhdw+ekT/xV73LB7/ljeBsv7YkfOf/0
1Z9vfIVvDwql5JH7SUP66p/+WC61O4Nyjh/U6n305//pR3ibIxzjTPj5/hYq
sf3qVWcf8aFd8QFUTG5p+zHmPHTtUmVCwCm6Wf/paJOV8yN3M2D8L6HtXzH7
8/Xb6QzVLyEdYUJJRibHAlfcwrGXb0ql5XhA8UPvA97egYIbsaX3kJS8L6+n
Oz0ujRBJIju1dHyTWMnaWuc7xXh+hFf2BOscL/OfhKN0zVX2Yx3YJjN4fR7/
MCNnijlXywka/qB4OYflPPn66tdhao6fRdHlgToOWIY5vsj/PT/sf+EhYvt7
fpT/wjfh/2ssXLsYx3fgl0IwBWe0mL/Cm9ipG4DaoLEK5IflwJKeeFHhBSOn
GjlR5EkSqq3BVy/k6Yqiey/Ity8kTTm/C9zk3Q/XkQe3+Ex9+Q2Enf/AZ6mC
We6r75+7ZK3PFuzrB/CPIOSSv2Lu+rOa+lnJOULO1HKidH8Fw84xKycbOVnI
6UaO2TlPy3l2TpFzrp7TvZwJf1nOEHOyeX8FJuV0J2ebOVnJKSynsZwq50Qz
5wk5Br8aOV3NGfAXFpTvryABDGZOt3MirKDhdrCOo+aYnFOtnGjkBBvBY2pO
vHImVnVAXi49UNHt2snXZ6LdTrh8DQbyi5rLF3IVJVes5AQ5p5k5QcppgJV8
TtVzSilXVHMlNVeQc/odXBp5PLMkwoHvwXG91uA/G5ICBNIOmWT0S9bbKAfh
s08xwldLFfO5QW9YvrfMpQPyl15P6bI4hVfsNeknevQXdcv1S2oRuR7zytrf
+qvkTCcn6zlVynkeMqarX193vZyn5lQbJca2cqqQcyT618lp8JWcs8WcDqzq
5QQnJ1koHHaKbSEqRmFiqCaZjmoGpM21coabs0BcdMS7IuVkKeeCBJg5xcop
7vV1Dx6wkaNhZdHJqQ4RV8Z94VcA21RzmpuTxZxp5Rwz58DKyvV1WMpiCA9I
rQPUF3MWnNTLGQAJHIehHNtKzvZwdxdWE3Kid30dwFbhWxcBE62cpuZ0IeeS
zNlaznIRVNhd1BBpoAMk+De1O4ijoeHp4FCwqaXkDA/RCBCaoDAUFFNJzkkS
HUTHpVz1+jqsKWmoRUQA28ZNDQmBEYWc5iDYOoCk5ADDDjC5kLOFnJzCPKgT
W0U9JNLDiohnQUILdFjYVEaCKkbOcNCOuUJOSu0Oz6ME2YgTlaE6lGBBHV+H
84pEU/gVNJZr5BQbf2ApwskO4spzkKNkDSloWTlJwfMC8sFyAjItA8knuYhM
ANIVU0wr4dawAsBvkEoTdVTMCpAbuBQUnp6zQMUy5Ac4FzCAlmJaYDPgByai
RgSuAGYD8ABg4CLYBTAJKhY0KFPwdPAiEEVNvW5KuKZrI96An12G/APci8oe
mFzPGQJS0CVOZgAkQ+RfCSfnwKICK4KAWIR/4AogEBwZHkNzYSBUwP9AdDQ4
BhqE6+7AdVqOwUYeItZx8dQAAEgl0/AtlD76GWRHchAzcgp1gGFgGOAN4HxA
AvKAklM9fB7EB1jINBHzMjxgIiGQHCmnCGiEj8mIE/gWAIMjAwwgLBIsSLIP
rA78ALuAaMNJhRTd4VywAnxi26Qf7JxqoshbHtlGkBQnZ8mIEKARWELPygmp
3UFSPJAX2FRHsRVtZADXJbUAUiCgtoFfVXoGt3CRKy6vw7mAt22SRMAqQA4M
oDNEuGahPQROdhSkOyOcgwAKqdcBFWBKgDcsCf07OCkQyNFQJ4ClhU11E+mF
fOsggQAYJ8U2sAWwFsigCVoFdpTxFEAvoBEoDeBb8BdMhfQYaEUXhc7SUjxP
JAN5h33B/tsAA7EuvAhYhfMiwknNAl0sFVWZlMI8fAvKAVQcSBM8g06KgpCA
c4FMy1Bjg0xZpATgV+SQlLJCGZEQLaANgPTIGw7KF/APrAOKGs4FzANfwVmY
h5ZUSL0OHjHYCMAwsDfypI1nAe0H2AbrAOIM6g4OBY8hTogHmJFSVhruCHuh
hndJ1xkoXKqKmAQTANACBvDsFkoiMKSaOjugCLQESBwQHXgMbI1BqIDzgqJz
RGRIeFFWcUFYDSRCTptIhvgEVgTwgMd0DSUa5MgmuwbIl20kFrhmKuk9UB1y
SmCBK+Ds4KyB/gS9geraRcrCMcmtzikman4wFoANhxxDM+UbwnYojBqqJhB5
UETwOpgk4E9gEvjVIesMRwCuBsglcv2uEhebBhUNHAgLuIHIgWSt4BOJLI5C
6ghIAIbDE29MpOyi5gcInRhRKuo9ILdCLipQGR7QKMoBTQuyCbznpJgW5AVO
DadzySkGWQPeAGwAekHnAMLBcsHRgPPBZEgGWkMnraxIy4HGAywBo8KvNmEJ
dIhOTi5ijCEMQBqFxC1NdzOGR0b8AB50YjOXcKWTEIkyyjgQAnWyh+qXqTcG
GgQBkGMTtwOnwbsAOWAeZDD2NIDx4CBWrEMcFMkr14lktW2EEBgSmV9ABgPz
BGiE5+Fb0U2iASAH+FFeyrsAGsHiIG7AsWBD0Sh4+AP4IbAIIlzHB0BBwRYe
aVQ57ZzYRBoVVQqgFBx/m7gXjRFD0UaNrZH59lCDgUJz085J7JNoCKQSv+Wh
nQUBBKwCrkSKJ+AgoHtR+4nI+WkrA4cCWgPMKNEGCqxOpwalBIQGisDuoFHB
XIImVEmrXA00rMxQG8MPIKGgJEWKpYAZQJ+DnlHIagC9QGqAn4EDzRTw4AKh
bdIJyQJiGNgb0G4TToBngM2AYQySF5O4Lu2YAXcBP9hk4gEGUAga6R+gDpAY
IAFEgVDD4sBRoL4ASDMlcaDNwNURSLMBDIBqjWgHxhpwDv+KZDtQKenk097K
O2AVvAJQZQAVoBoNoomoRrxJeHaQGrCVoL6ABIhVAY3XdffYG1TQ97OI68Aw
AcAmOWM2fQWyA2ElmGZYB8xlGnXASKDQwAZpZJpB56BNF1GrALejl+4gJyhk
YoDusX91VRcW4g00GNhZ2AiEEfSJTehVaU2TFCawnE3OEijktIm0yBVHx8xB
c+OSlAHrAgcm/ryLmhyIiBbHJsZOexcCUgTkDpCMIq+i7BhkMmBZj/QzKCKL
LBe6oNKNwGKqRkN1AawCywLJYBE4CJKP4hHAFTAzrAkc65JsiqndwRaAioBQ
BV4EXkXpFtFTgtXg4ODfghqBQyEbSGh/NWKe6+4Us4BOg8OiVGpoU8CPcsgP
BwQCH7pEmji8AsdSTYmMSwICpAG1APIlkPUH/QaWziYBgZ+BT0Q6CJAM3fUU
2wBfgVoG+DEr4KFoeOQzg5ACkl0y2eDwg7lhZLxAFXupYFkkJxnYCbgC4zgH
2c8hOwhs5hFOQJECWYFjDfIQhPTZJdR+AD8INTiruotIg9WQRiIym0Qevkae
KqLRueE6EEZgFZs8K4/MNzonGhJdIQ3vEjCM9DPoKxAZMbU7hgwSPu9QuAdq
yqFYFXgMgAedCVwHAIsmKQ3SwCx1dqCmwsiBFxFaMDTA0kA1iAtA0gHzIOBw
FtAkEBEgooQbrzLOMMERIGYBcptkTAEVSCkDFTt6ywKqHRRqiwxoWlkZaN/B
ZcUUkYZERwuloHwB2HCo2G8EUsLB4WEwGWJKWUGoAtIKZxQoiJbovIxMDKgL
+Bf4FtQRIAS0BKARg7UU2wDOgSXAxEPcB9oGuAKOqRHHgrICAbfIioEmAdp5
ZMjSdAcmRJBEVIMuUccjRw5sh02voKPoorAAVl07CfSuZsLFBdGddtFMAKuD
yKPidZCZ0fpbxMkUVqALqt5oG8xrushj4IaBgcMglLIWQGKLbD0YDvRmSRsA
f2IuImXjLAq7RNJmjGIWMBNwEMCGQjkBcIQ00vPI0hIKhZxWlQoSBZAJ8ghk
BZ4HsoICxBPZKIMqqSwAEvg/9iEVOe4Nwn8e8A91NVM7WL1SL+YHZfqUa9Xr
1fW8WMyPrWn+UC/kp/WnfMfviVOrNzD091ZeqBZPb9V+3ZZL3fJTOd/qtUrG
sfiefypM2yOukJ8M8svRoNWNDsXupDTqduul/NNLd1DutvJKNS8Oy4XDodav
jk72qre35+VeK2/Q58Xpoc51V+baHbemXaF8qM2cdmvePbQHZaFVmoqdUvn4
gp+9f/hsns+eN+Rgx2r58DQavpebrfwiXjl/KI4W5WO5lO8gmIW80yoIs6Wz
Uhe2pBzLg/xz/HnQ4orlp/2rPHqvl9uFVlk5lLqTZiN4rc/2TjvfXXTzsMxz
N49/CvQP/QynnjWa2nx64FhnL2WE57GnZth0sPa95kIYrNRB1SvtrNpLZWq2
Qm0cDXsbtXNkbauajw5qrzOfvBdmAFaVA5Dd0rT7Uij0JhVrL7wf2pv8qqCN
BLki2u2TP1vMrFLeQ5Br/Va5Wsq/TFPPcncepvPVeq1C3jPKhUG+lO/WsglF
3NKhXMgeumUkeWGeb3OFafQ2W/hV8yAUir18qdztFAu9cv7Dn/K65Paz+nos
Z0d23t50D8tSy852jpxjGq3G7u1df52w9507Kbhv7Y3szLrz5mtmuGmbp2jS
mB0dq/v8Xns6jexB1To5b+WBpb37RvvIhaVMbWgryraZfZWf8l5t2Tczvc3S
afeq2zexbfcsNXNaC4ryWuzPM4v5oVpeCd1m/dRwlpI84nb9iVq2ttVpKHTt
Zk977ci1bjP/bjRfCrVmrzB6OhwktzHYLfzWwMwvAd36oqL0603nUJlNGLfN
6JN+Rt8+10pG9n0yefO785laWb49Dbfb2Xsvv94eppNgUjEKlclerQUDdTMq
VdYvT+FMMVZtTp8pb8LwVdRYv/t6qIwXy4G97YTMz3hhtsjyK3NsKXXtEB3m
DVsrO2a5sIyebeVksXGhNTO49dKOmsK+3Zvsx+qb2z1mJrNmwTnWjxUt3LyJ
s0p2Na43Xt9Kb5vFhFlPlVMp/1oxsi0p09w8dbnMsd5bTqftU7/b3klZ/aX7
svdUywiyvYmyDxr9/VPL1Fv21BUbXat4lEdPrZ0k59/aK73hzA1OkXXF2o3Y
sTMIvHyUnx1HYjB97S6NiVepPKmFhu/ozVrNWkzeV83Z3NScSKw+KcvC0V0P
Myuu+Kaow/rLqTgR/dPw0FsfTr2NddiWbfG4nb6/tZ9mg2xRbzGt7zTXb4s5
awbzfHWzLmliu+a8c9NpbajL9bK43C9N/2CHgV12Dk/lmWvLYeM5MN9W4rgq
Vv32ZrQrbrVB/mSphuhOgrBxerI73Hxc0YWo3F7NR6OG0s2U3saa+FaQ5n7n
XTYW+kCavdR2C4ON9oOnUbcXWlb0Uqg8zQW5fBisXjl3/rYS+uY4tE1jPfJa
7YOwmRWX+kmwKgelVmmpm+XhZBT6rU3Zfq6Wn93C0yEqVyTZbe3GdZOzDXVj
bGrVSv/lWZrPMroYZcbvL+FmPX1plJuFZjHDyqNWtHe6C5ZZl9/n8kvXcd3F
plZqG9sT12s7bac+HBS103tJLy2Vk1rfvZ4U8V01htVFiS0zu0z18DR5dcP3
SF4alXGm4Pnj2qtWePXGWW61fmstt3Pl3Zw7I0dds2khzNpRtvouLpetirV9
K3b2b/3M06bg1Q72UJtnVksBPjvOnMXUGHHKYdSoVMqsrtT271kW+LWx0uxP
5afAWU/EQ2F4UNnQbKyrnWh/qD89FexCG5hwWH6qyJmnIuNOe01/dnpFMViV
V+Wm8NTsCJKohK9v66xdmA+ZNzs5YsfO74SyI7OF1TKb+0X0Mqw2apkhUEHR
yq3upmG8sda2HtRFTy6P/FrhLW9ty68NeTnc9sd6uC0zSal7pjTMOgvHEte9
xbK8yRt6xO2F6rJSXQ47YVeVhj3XsJvCuLrzTqOMnm3Na4Gyn+mdZtcabfKg
kVx/Lsodo+Ieak+z/rtX4ZbBcetnZy/S2yHzXKs/ve/tUnYpP7fNZfBuea6p
vs6l4ODK+vT0ntmNy5PnjKW9qcpid9JWT+/c4fi+6T4VXgbHZmm374ZS79h9
7xR6UmeXfT1NW81epx1JxsCaSetRsahNlztF7WWejBdndXAPNjepeNuN/36q
HCrZDXOd19bCKD43n/udU33WMUqH/TgsDCpmdm0YzrAcVKSet2PHIXOL76vn
XZlbl6xm97Afntjhqb/ODyb7unRq9sT34kYuNoqufly/+O13P1qo+cm41jwa
z6yyMp88UR9VDvk8l8+P1N6x4b3vIvftWWhHhVnZ2pnDRtleVL3J9nnd19eD
SSNcuY1GLbCnpdW0WAyCoHMc6cuXNy5wTkOxNLEi0Vm2GkI0XnW0+v70xpbL
hbmdlurF2THjHp4yi1Nh99K1QxY2peN0PHb9yd5ttLljt2e8qA3L9yxDXI5r
xYpgvNSVSVjN1N/ajIkd1TX7lc5mEr2OM8/C6x7UrreuTqr1o7M8CFy76lgb
aWOOGs+T1dG0M/lZgY22pdgvKrdLX3tFSVs1Te799doL6L+W9VfrLwAXUWfo
GEMIAyE5OKgYlauUraXsqG5QnlDH3ILhfPWyTBGI6v5yQ0LyX+SN/6Q7Eiq9
uLL/bIV4+8C1rk9I/S29CE+7JS8K6IIDrJLy670I+AJvpF/4pV6E7wb0z+hC
uMHS+Q9++JftQ8BqfhzYa5hwgahSo0oJxgMuxmx3V1DpdZ3CJ2ALCMZsCnp1
StoKEi5lUejiOfdXgC0Y1bF0io4gfLIZpTyodAdRE+YiXfzW/kYvhEiZQQhr
4UXMMLoYl2LKmGp+ukY5ZYqgLPf+CsjiAgbwhoQHR2C8XPKfGMQ/f9mmBYjU
imUUkbyKUEP4X6lg0IdZynKuUMxJJWS+MkhWGdsJvloAXtUK2GVQ+jObFv7a
kPyNNy1cJOu7uhaYmkTstoEJtbjuDsG/R9nquOZhWJiVuCYOKOS2KIeIUTcl
xwUNH3Mp8wWcCVznkLIRKWlrpZgcE3wSZgAVKgAzynApAsFgJnV0xaRciYS1
CtdDzr8mDigtC7zNPKqsWwg/1m8omwkggX4HaGFrV8Bklq1iIfya7bKoyk45
dMfFnIJIqUmL0qMmVSywSKPkBB3lHWtC6dy6hXUIzOvRjhqlg+MCnkKNXpqO
goa1FglrJFhDTakI5mA6Q6FcvCpiSkW28DEmYpJdUDAr7VDbEjCubFJeL5Vj
xXdVzGgwqsA5lOUEVQOPWWTYgC5Yp6Tkr0HVayGFedPE/gbRRcUCB3eoagsb
MSqmgoY06a8oYq7N1FHJ6KlyFGZjqb4FxhIpTr0LMmXHTKqmYKMJZaVB5SoO
0khJvQ5YMikJiKRXsWQOqMP2CMKSTTSNizGmgQxjUIH2yrTUXaFQrhO4S6eu
DmBOW8QTxRwFkIBaBkJgIZbhgtfUvILpJJkqhfA8dmZQzVU2kJE8ypHB5wYd
36LywE1mnzoS4hYyj7Lz2GNGWSdsxZBJS+sIsKtj3ctQb+rHIEpAEUugrLqJ
RQUsGJuY7RXjooiJRIcFBSqTCOpNehq4C6s+Kh4TCKqaSdmJkQURLEqWSciZ
SfJXRjpeUSdTxZEqN1h2ojYjl6p6QCksPglY1xEo72yTaHgpdYGlZSpiAWY0
yl+LGvK8TVUrLFqb+AO2DQkovCBN6XKU7VDxkvoDDA9lBJswbDwmMIBAzQeY
TDSpommSRKS0DRg4RucCogDpQXtYlOtXGEooo3owHBBkHNSISyUQ3bxBHaoy
CY24Sk0PAKpMyU1NRH5wKONpkiICEiMfpmvnxPCail85Ipp7hXqSTBnVjkn9
cFges5BbMNmt3mQ5JRkFE3YE3oNTsHNHlOfRIipKMVAcU5yUdAYuso0bbYN1
OwWfhHOZBBv4IVgQlRFXWPjUES0a2Xf4xDJvdJ1A+sSyqXpKfRJILFLvyOQW
8jMoWItKkkAdI+URuXE5RKfsv4uKBbANFgEYwKCSP2AGiG6KqKthWRDYtKI2
qFwNz7jUWwY0gu2A0IyqyB5Vm7y4vGQhw2BHRbqGSgVdZAyRWlWo1AryAkTH
JK+HmWJM3LtUc6LSi5sqDJhxpYccvzhF7lDjiyNQLUrAz7HrTkextWhxLSUy
JpUesWYpoWkAfoNnwKyAoZEp7c7IuQKuAL6FJ9FqpAgnUAghUL1KpuYG5ARK
r7tULwcMKNTPgb9SzSBd+IeVLWrbQp6nwj8aMrLC8LNKrWmgw3WyOB511aQ7
dTwyKCKRDCypGnd3UZVCICUMfqBC5XnQJ4BGrH6llJVFlMLmHgMVPvwL7CFQ
2VilGgYcGX1a6vi0SBurKSsjx410OupwtPUimhiJqlCg32zyFtCsm6j3Yl2a
ruShlqNuDMAqPADaA36Ni4iKRY0mCulqC20oVlC8m1KcTuVkLHjHXTgGOjNw
Ri3upRCRBBopEFAIEhXtbip5IoIKmwJgJtWQdKqRAIZjSBRStsA2GlXTgfml
NNOSEYF3wRVBeSccKnHLgoaQg7CD0ov7BQGfknDjGsnEliAFgHYwZ6BwNGqp
xB5BgUoyEmo/UNTYC2KgTpDS/SLUDwespVEPnEyVD0ARYBIYVSPNj1/Jubh7
EixUuoJrErvCh8hmLmJGoHfBdoD6AsWFvUcSLiVQKTpuOkk3PYBKlKg4jUbN
pA4wDxkPeyl0BBg+8QiBAIBMpE8XAu24Pu0hCdAls1AusKrtkHy5CAlwr0LA
owQZN4TTqEfKph41YFGE0CHt6qHlAtkHPQ8H1PSkOdJJYR6+AqaSqVkB5BHw
ZlHFC6isUQUR24MsJIRO7ZgyYfIqcTKBR5V+YAmgNYaKIvVpkaOoU0O7SJ1V
rkSKKNVuAmpNIVfEFfGwIE3Y4aRR7U2kPlqKZJO+EBFNf9opBQgBLXhMgaJd
6jADQUBTzqh/l7QfQIhVcDLBUroL2SYRtgh46qayqRmOEQsp5EwCm2E/h4yc
r9PxL6/DqU1qhwKVjnpPJkNG2hKMKTCJQh6+RfU8YA/QD+m2AxBDi7gdXE2Q
lLi1RSVNi/aRGNKmhhVsZpLpCMqNkcLOKirAY68M9RcqRHGMXwSsLGK3LjXy
Yl+Ogwe5oo6CERZ7Ix6eQiVnTKYOGIWyBEgsav5wqcitKTeqUiBv2SN9hX1+
RjJrAJIlUKUf5wUcNCLg6qj6jZkA+2WQkAJgCrnuYOwEci0U8hgVej32zQDt
gAp22z4uEj9jF6NA7SYO9bdRwxxaWBWJDhSxqGwPxJVSwQhIqE46GRAOWFVI
p0nU8ASUwiwHxW46mS2TuE5IAS+SIdOp/m1SgRkbUl3yqSimAAyI1OwiU2xi
2zeZCpH8Z5lMFbI6dcMIFCrCdjJJBPKVRqup1AST9mkp7lApwSLT4sB76K2R
k4B9RTaaYNAScZchoC4dTRjUIaRTE5VIIyEKyRcgH3QyLMjI6/Co3VMk+6um
jBQaLxvZNWYV0Eg4tGIj4UBDos9DDQGx5ALzCN5t7VynplVqSwJPw6DGFEAm
6EOgESMOd0lSdGo1E9ybABx4G/sDXNSlBhlxlF+Kl1UCWCEXHWN5BXUCdqql
CIcxGuEE+/upJw8WBKIDNmBBm44ADGmS/nFJoVkptrGpJ8MmmDEoUClakSmC
ZuThnLthALfwMHC4mnZOyC+y4lEgin3QRlDHLXbsxc0uGi6rUFoAuEhOKWrA
FXbJWOh9WRRMxRGZGZtFEtLY7oP6AmkC5Jhpt5BRBwzpZJdagkCsXIZuGAiR
Fvd+kXWLUx+6fjNqhOelmAsb/ektOLhBvj0qwHMggP4ezbIB2o0U04I/Cb8K
lDxEYac+aeAf4HaQFIDHJCUM1sShvlKkXQp4MChxylGm5kvgE52axXHoyUVy
OBQUe3Gc5aAouel5D43aAeWkgwqHNGR00eM4TjeTjm2VujFAY2NPdipzAgbC
JW/ZoTYjiwIKhTr84LASzTlo1EwMxgWCOFR9aUVNsysi9fYp1EMJ/5rU2WYR
rkBBQZyCnirpHNO7mXXRqKUeXjGoOYaREwsiwIgEjFJSOKxCsgB+kUUpiLSF
1SkxwggqoDW6KJSIwHhQRk4GKmAWhRxLh3qh0vZdI7YBSQGF78VN9jqCAfQC
/Q+yL1CPHfzrkIPqpH1aI+nRBDCAP2VqqwUVAZpBomgIZByIa9pJjzWGeCmn
VKWmdhyoiBNlxEUWIQo4CjvSVORSTES4iaFhKfcAxNChDjOFoFIoXnPoLx6c
0mgStaIa1NprSjfyrtMgkENJOYs6jeAIGiVbVPL/VUosx46fSWMhdioEdslL
9MjfduMWQ41cQXJRsINfRkgs6iiVyUVMtxHHrWmg2NGNpNkAhYKLOE8FPyjU
DwebmtRHi3OjKeBVyoe4RDscUiK8SZQnhIMY5FrIlO3xaHAFRTLdH0Yt4zb1
hUvk3QGPqdShKFBcKVBzoUuEgFNI5BWngxGL0mggF3AQQJRFoRAQFLW3gEcA
VGBJgh7AIat0zopRu6pGExoU/cFj8VgRdvkT4UxqNDQpxFY+eBdkXzDultBx
9ai7TqUwBE6qkf63KLbCpkwHmVNJcZ1JfVcgBfGmjCIpleYxQU2pdpJuhSjJ
pSqao9yEgaC90YDGU2dkzV1qPAUuAlWAkRflykzqStTJXqQ9K5vcJ5nGORlN
Fslkj0waWsDJQzLQGkN2kmlWh7EbnsfOOQpDJOr8NuNma0rdoEcqo6rE3jsX
ZVC77cB2yX2VqetXpuE3UJtglRw1yfPoJLkOOY06Nc+Jyo2VAZcPhIvReA+g
y6UMpxB3VBsIlUleB7C0R+kgN90PSv3iFg14YCMsOb0Ap0IKB86OvcUUo4H5
A7mOp1yvmHeTPm+0BTaKFdpEB113iVrD4UWNZjAMmmDB1H26911DeNDyUrOj
Q4NzAJJJqg/7I0m9q+R4q/TzzciERlkRkUaqSN8alHHSiFWAG1GPkY8KYGBo
LOFhr3qekqgCKcC4kRfEBBBokjcOD0sUBgLFMT9MLpyp34gMkltF4GXqfcSM
DU0XyOQPx/MGJk1ExEkY7TaaAFbH0UEJzXo8VwMij/30lNAGciNiWdJuCDyW
Li6A3jMp9MMo3iV5p155ifL5gBnMvVAUFqfKwcjaaZ+WJi40cvaw6Vwm8ISk
516nPC1s7dHcoERTZ2kDrZOrqVNTu0MhlXdOv3hk33E4h+bWsEOUmtfT1YE4
WSFT3CrShBhOu9HIjRmPxzDUXRZ5NRDfWc5NNypmpcgDRD9KSaozMR3RsGqo
gRnlrJA6xLo3+fl4PEnEQ+FEDbWAx2MMHoUtHs2FOhTFg5HF7FyK7mDKsYSh
J2NOsC8cEOd8LOoad5EQJqkslRQ48qdwY6RAd4EUYBcvhfYgqjZlTU3KxguU
zEQX3UxmcdPN6/CiRy3+mBcSybSJNF1AhQmINRjl1dFDNkimyGm8ok5FrKKN
oKZzABVLJxTtmjSojhgTyVEkVQk0ElLKSqa4EhW4TTgk2Yx7fwGHNv2LpCQv
Kz6LlBJYzEiLZIloDkeloQI4vksuLgCDg2oWMjwIpuwm7ftpMwHuvUwDqKgG
Ka0nUXYRZwAE/FClfDUjz98kP/mqLmg4h1GmGkgfG1aDmvjR0JNFjkNUk1Lf
in0zDmpRWgPFgSHAOPxgI/JBviDsVanEb1G0gol9haYW0+MiFIA4sYYn5GAZ
giGEFpVXFBq0A/x41KSu6DfDKiiVOj6JU382NX8TujwK5C3SVzolvjyaTFOo
I/xKd4Wmc6k1XKShAi/uvCcpEGi6BtxdLBsJNINHuivtz8OhXFLsjDKBmBaT
8TGRai4ajcwJRF+0PuZNxsyjEhWEojggEdfsKCrBIU/KTzIa9sBirouwicJN
YcUhd4KRQwjrgKoBNgZOAL7FqFmlsxvEtPEEhYpG8+pZKZTH1pBVdPLxcCYz
Hrg1UY+JZBwdqgJoNBctp4DH8Wlqh3DI73WpfmTT8LBORWGAAWNbGr3GnDO7
ady3qBsAHjPJoIAm15xEI+GIYNwxL9KAqIa0k9wbx0yNc1mUkVCoB8OkSX6N
5oHRMGlk3S6TMzT+cdU2LvKMRIvr5HppFGg7VMmVqQkexZnSXwo5KmkjBTIO
aEGKUMUw5gEcdqJZd5c0DPyFmNR2koElMz0CreLrKnlBJs0XgQ8fZwxAYaoU
X+An5N6opLHTo3GMmAHzGwwNJUYTNKckkFl3aexEoVAxTrZjzJvOHujJ9JdK
6LWpWorTtrQXsD2W2ORkTBSUatw2c32dIimL5tBQVdLYIVZOY3pJSD6sRdLg
lkE17nT9HbwsjXw/yU1gg1gVwyUNFR2mpgWazqUwDXCO4aFxg3mNJiodKv1L
FMu45FQLNGtkkWsKR8C0EmljJZ23UfFQKkVDYPoFas7BqNmiHgkBn3dpSBvn
iKhvJ+2QY36bsgRafB2Ki7oUzBB4AhKll2UKz+M5N3DbNPtmHBT0oUYqzqCE
MFoxqrmj7fOox8lB3avRypr+3cMSzX6pWMy/ZM7DEsNRTV04xRXLGyNtMzoq
Qp/V5pWuWBGFQ3E6qTcOk0KhO6wV/PqBaw+uIwqFWavYW9aPpXm+dRlRGBVm
zmr53upNDpU8DVM0SnmxaEuu6JwKE24wag9oTKGgjEuDutAqOcdWKa+05s6p
XQngsxZ+duhcPzukN+V+z66XTSutA/fhTKVeMhjRyOyyr7MBs9VXe9DfdPO1
3XZcbBzK8vKUn/U34+zpRXnaKtx8a2XmhePhuT13WbNuVcosUzuIgjM3JDdq
NquWsFnkd0V5s83KWnveqpYPNRws6QmdQmFS5irVZqdtjWpu1pjNTprR7Hvr
+b4rWkZ20irQZIlbP3ThZyt/71nu8nA8huKW42GISitPwxKH0pR2e8aBiUK+
W8pPy9VWPqgWi1E13x1WuMJh4ueV+tMxPntenfjBrtbZDl6byrheq/ir9th6
c/RR400qBOGr4dSbp6LD+lrzWdluypy2m5+6DV8dPR2f2rP6Qpb7W7W/3g/M
t3qpX3E7Um/+ZBbL29eRBmSS3wfdsWyd3PVibrt5V+VmxYplFO12/aWnu+/w
f1VmN5uNiu28R61htB+OhtqM1RqFwrhjLxzVZItjb1jbOs7r83L/suNeq2+m
sy22KofGa7kgDNutcNnLPMuvG+ul7L6M3bVVMib95XZaYM8rNmbzpnPqbFuN
4au8cm2L67FXfV4ebbf9ZZh99X1/IrRa5aZYlE/jo1124Zzrt6G/WPtrYVIy
27WhX5rO5/tMFLmzWXXGVV4HusjUIDPsq8+j3sHQlfHcdXazvugIjVJlNWq2
GHOcanu5e+6aUWFUfm+Uxn5+ufRqGVHhitGrb9TkjKNOSoNmr6gcSkXR2IfD
XqlcqvaVdlarCHWlZ1uTF1cvs7y7YMax6MjdqtGpjRg3F332Ih314qJcfxm8
bDpB61WpSTPTycxrZaWmWEJp6TUHvrx4z1Tq/vAYsdZmM3s2esZqNx9x2/78
OKuORwfv2K5sOvWFtG5kNv3pcqjMw5k6VTq+sM8aL8tx+bk17uv7cGZpp/7I
V4dB2ZDn3NvLWDZfNPvNWmoFRwuNSs+Xek0l6G0CWTNGcyX0Xk/ek27Ls6ll
tVfB4H0xsF/9cb+jKwOHG+dbVrEzGBu1pmFPgkL7abDMHma9qlLw1IM3WZ/G
i5rzrKhu0Rm2zJXjrVumUVwL1Ulhe2RTbixZ482z6YeF03RyEA6NzqorjlaL
fntamx2ems/SdL7pDpzIdCvm9nTQW1Z3MzvNMjWtvFu1M9zLqjtklbnoOiVR
6Ulmf+Tlu/lpbTU2S81dfSl1pHl111aMsb/PL5bD9nLVEeTGsijWT/se8zlA
ba3en5q7cLIAtld7tZao91eLavN9a7XExmo+aFb9zPtY37yvjvMde/P7Ty/D
5bTbm9eK9ZDbNd8KdftdXVszZVV7MfRhWN1K2fyiPwhr3tJVOm1lMB1L7byp
d0e9p3qjfnjdDI5SVImeRaXLLTaNeammB/5p0qu13eA0qKiRNhhNDoXgkOlU
m91Vv38S5549LW3Kx+m2eOiL3Z1X8edvfjGjc7XColkS8uZrZtrMRPa8M+yf
9pMgW3elN73RafXbYms17FRFwS9YmRd1J668Wt7Ilj3X6Ess4JbOk3F6366i
2mo1ejG3UXHVGK/3u1Z1/i4Py5uF96o6ltaujwtKbST3TSO77s7nvXmlsdrs
rSPXaZbDulKb1U6V7WpgdDW9unH0aab1um7J/b33UvTsohhsVpPMcZ1ZHLvb
/EoSO7I3LxSWzvOBKygdPap2xMpiftqs8vvWUvADdyMN5s5qeJBG7CSphX5m
0DAH3qH7ZJvaiz84Vpzp8+Cwd7w37rm93Su7beQZ7Yk0qMh9QZbfw/3Lqdqf
592xuqnLgdFRngr+ofncODRG5nwxHa/f+qHYyyuzFieUD81j/phpMs+rSq5/
aFed0N4PjNrYnWqbw6p/eGUlYdUQ3P1TqzLNz9Sm2+33aoepE8mrKbcy9/p4
kK0ph4XXHaiLnSa8Pg/Gs82+tylqYMCExugYeUuzMum8ilul3YxqxiS7dsRd
TTSzT1xzIrW6a6tWmYya9UNr2u6UbXN6YLPK82tV0F9bw5bSUab9WXv61mnW
OiXDqYnV1napLJxI6L9yGiCnte5nSi+tXn0va/NdvTmaPb2UypOXcNjtPm3m
zruxGr2+K73D2NZ2hebbcm+/LqxTtg9qmpvPhpWhdmIgx/auzrLTUUnOvw3y
68L0uWcdtWlkVivDp3xx0HjasLfu5nUZZF5bLWa+am+dZY9TNkW2Y8JMMpcZ
eXv0LaEXrpVaxX1fdWrj6QE+G0w7pVJm/za0in5vVbezs2l/sx/NjNbA8ThJ
DTaGUamXi4XjOHsQy5mtXt49mbXWaZwNTCfYypLw1jlpy+q7DkqVdaP8MDs4
DdcjSzx6Fa5lFYYDPwqaZTNkvqM18wMrOgrlwVuvs6ycgsW4GB7KW3Gtt9/e
hlqjvltms+w4UKXNtjXdNbk34X3tjZtRoVp3qoshaymKHK6C/el5/24xoZf3
noVRZrERB1FrnX8vn4yWMs7X1uK8VpJayoITdfW4MvyXsrFxxqzf7zYy1aC8
z27Eoeo8S1FxV60dD5XmQShLx2jyPheMZT8QD4u3o7F0jk/cm/v+Yq3c/ma0
zTb1XU/R9ZfG88EXak8rLb9835yeq5tgoRQz426UreQ7T6D+1UmvIgz2itrr
cYvh0c1u19uDbE2bg70ztxfHivcqvtS6+5He3dTBro4zUdXphoKUzVabx9f3
jfwaCpXduj56NzmjUAtsdd89OetMe/za6K869m7hR6GQ6b2qR6dnzufNbqs/
3teao3lPtF5fttbTa6QKbz1nv7O53c7vj/Y760UU9LX7XDlWnorV7LLRE5qu
K6ythi6PlxVT31X7amH+ZGjbsmRuXpSRULbt1eTINTtajS0Pr03TH/Vn1qD/
3Bk/DYTFpKd3J+/erhOt5r3oZRjUlMV7zTzNe332XHqO3l9Dd9v1u9yqsBrN
BvNs1qyzvWaXl8dW+Dz0NiNxPfBeFwV72W4f6o1xRlm/eE1nXlqLu7oyGxQC
4yUr5Btc1ZBHtU258Lx2tLFRGXfW+6o4qo2V3empvNq5+Uzf3cliJx+a63n3
ubGo2IfVxm3mfbHVmqyKnLvxMk1z2HhmQbtTPRzcUWa3GD2Pey8DbzeN/Gm5
X7G7qgMwFNfL/pxtXjLL9XK1Hu180Vdr3HGzNBvvTccIJ8XFizgXn9qVSatX
dHpFllHze3U9Or6vZ7BymFWGXob1d51VUM3K3eaclZZHrqK35pVC1W1MlFnw
6h/CfNuyn1T/tWM+541A3uzkBWsP26v+WhxXa6t+azcuLXW1+WxJR/nQ4jbP
jmVKTBznO9m9HPoDq2GPR6I3dEuAeuOtXp3Wd9miU+jq+0hYtBoz6TnT7ciT
7vLo12Sfm3f6Svg0tQ9KYRS87N2yVt8M1M5AMIeF1sDUO11FG0nv4bi68aqa
NN6/OvPqU7lS8ndC1KvtuEwFjGy7xIK5po3qgjkx33rDUrCY9xaT+kl/btVF
V8k4xUU2rGc6QUXdRdXpU6FdGU3Np810wPX1YiS/5ndCpxY6A3Dg+m+bnT1c
ZDvrqNoKn4Lu6PV5/7bXh1o18tR8T90WXS3jNLSS/7wXe9zb4UnWnstqz9oM
t7PBsFIsGe2gtio8+Y2gVWy8a7q0dU+ydrKqgmE4nepoWGhWxeJwLja7TOMy
ne3T3l0dR5236DAVpuXaunDKrJ2mZ46G5axU6D4prUF7Xxkri5fVZO40O6dS
wVHfZ0Pl6JlTrjKfTd1a88lpz163SiEr7V/Xz2ZR2892s5n51m9a7WjVX47f
on1v/mIfm87yZVLsvfSPK898eSlz/uTVHEz2yotUcsOTuAJgVpJji53+KFLH
29JS6jnHfp4922NnETYcqRDZSvNYZuppdBy169zCbix7Mys7bGSWvdZxyErZ
bb093RWFsml0+678fmyISrmcVU4y82a9ue3swuJxqO6PJTfQVW4fnJRxQy6X
tczBnu9706XDzFGjfIre+9Zza1t4NtbFneVnoiIw/eui15s5tqoXXotP4CdM
itxBm42zdccel1uj+XJuGNN8cyBtmkHl3TJ2Q3u62IS6uZ2LsjSo9Y0pKznj
etBsW0a1NOm+FLhV97BsuK9ePTxUX2Vx/X3Td/ify/vrDuDhf9n4rzeDR4Vg
K2761ahiS508eKmoRcUdGTOoBt0DIn24o1WhO4EMIedcB3O+OQOz2l6e+e4p
PMDt75zDM3LCb5vDS1743XN4t6D+mZN4KVyd/8Qf/2Wn8RQqgBt066ZGnSzY
LUvdatigId5fIe5kxLY+mtXAJkRqzhWp5A58hLVNhok04xvzfFJ8NYpIN325
VH+mPDH25FI9waGqMsDmfGMaD9thKDMnUcKe2VSOptYqia481RU8iMBubhm9
OQVLOs3xkky6ltPBMtTl2b/sNJ5ezOklzIkXqPKtiXhHL17fm8+J5ZxcylWo
cTlfyImlXLn09QKCkiuWcqVCTq3cg+P7p/H+2pD8HzCNl0jXr8/jYad+XPWh
+9JcE3PTBs2DaeeJEYNux5TTt8lKWJfFcVCLLjd1Mb1uiMnlYdjcQ3d56tS0
JFO3UHps1aNOLJFukNKotOwy7BHxaGwV69kCNj3g/UBi0iOSbsjDUT2q/2Fn
Et3K41LXiEtVJZfmTHTqWZGo6YrJN82INvW5agZNTFH7C6OZFux5ohuPTOri
tWnyKm7AYqlCDpZCPboqz8b6FpxXouY8i1paBerad6nBERPcdEGpmzq7QHfZ
YhGF2vHjPjxVocvzqEKDEz40/ZtUTdwbm4RzkjLiU4nbu00iIl0ajuUEEfWB
Qrd16nQ9p3l7ZZod9/46dGkcjQ7iClQ9MmTUKLCdQGbSivFJtZmbdgEddYlL
Da8CXdllxWUPHdexqMaP1yxRVYkpN33b8WVyAt1MjHfWyrQUzRVINOAnx6Md
YlJHB5awUhV3Fl9FZqBmlemCJYsq/TiJpCIDY1Enbl2iGwTt23k8gS42lh26
NEunNguLxq2t5PpkFrc20uXTBo3JKSng8fo6qilqVGLBMq1BnVXxVbJxyyw1
ikk0RihSK/8VeA87KlSqDUs0OGSSX6FRlV2i/tR4xEik26xxxuy2fIgNCnTN
Ic5e0syARA1P2B8mUHGIeB6sjUBN8IZxI+/YbEF1I9haoMtQdfJ+NOo+8eSk
9I7X79ENl+l2AcmhLmcTpUMnocD7ukh2RBnNi011dJ0mPQBpWJlOmVadBreA
r2yLmpV1Gi+hLhmJaloGTbZgTVSlLkkHy7HX3V3qOaZ2fBAWbHmhGyhBXYjU
7YTdnC6SQKcOANG4ue/NpOKlqpw7bmnyTSIh0ugOMIluPlYcapWjds/0VJhF
bClS7y/wnkq6MW5QtqhrhFHpPb51UiFD46VUpUE38GFdlgYINRrgBNxaVKU2
CDMmyThOTQjoXwip13E0VKfupbhT30K5wxF9uqhPIb8muUiProaNr3i8Vh/j
8TMBa28qTa+pLLmnGadq6fZrvE9dxWqoSU0k6i3q4mlGk+AHMQFy28QhgGTQ
JMDkFnnS7KzPb8Y8aI4LSIxNllQqdmgWGpgNuxYEGl+JB94kBMCiSuH17NRX
gcMwIlIEByo01JxmfNUoTSa7NNjpKcl12mkjxag3ETw1HC2muwxRSFlyHIcQ
i12AxHU2tRkp9g3XwSvx7CI2RdEdb4Kd3LUp0xxpXE2X6Z547IROvc7Ok35o
WejOZizW0tXpHrGZQgVj7IMxCPPqzY3pGs0UQejhGNg0HN/5LVD7BQYq1OcB
GsCmu13xqlf9pmysUZchHpA643WarjFJTYHddGlIEq/8p9YlbKOk29mvBppm
yGWam8VGOqqLe/G9szRCiQOoKtlQLfk17Up7VKHXqefMpl4TJ+4xipsq6JpM
gbxvk/qYXeoXSTcjYj3bwe3ABBg04G3R5LYdN2pTt7pIehs7GtnNledxI4sR
X/3IkCGxjdKiFmod/zWol06kHiCLbltMd1IKRBRsfqXL4CW6LVuhCUzsRqLx
VJPK7Rq1tQnmTSelQL527Oy7NMWBl+nSbLxBVy0a5BVgFZ+8eJlq8Olug7jH
l9EUhEa/osKhiXd0/3VUI56VNI4b6k3nNAaqpFcVUg4O6SVskqB7Exy60tim
4XOBWqJNuqz62mFDXgc8Y5AdAYANIZnYcakHInYP0IjQdBN2TaVsnEfj3KqR
/IcUAFSPpuZEunvVJmdMoNEjna5L15Wbm3QFmnUU6OZmnFClB1y6rxr+utSe
Al5K8t8BoNvN1fR0kI4vYgMl2TUUXvKsPLrxXaPpUJv6hkX6zztASJeekBHJ
N2A0E4WtvTRjo5FU4n+FRaeWF5lUB/XRxhr16h5Qd4jy/zf2Jsuqa1mWaJ+v
OBat94zMQHXxzLIBAiFEKSRAIi0aqhFIohAgICz+PbXGkseB23lp5uZ+7/F9
2CBWMeeYo8CRqEIgIcK0JaICZtjHEoETLsHm3gyYHwatAqKGDE6JgGJYhuO4
jPiOgFJnwFsVxVaX9b1sQugQVNAvBJxsPjTbgdwKHmhqB0+3Q4Tog6/9Ti14
mwqEiCSpE7+KnQX6rwoSYQKRiQwRu/xrVhRQUjsDP3i0vJLaknhUykDFC/IQ
MJPCI/whoSqoKEIw+YhTA2VziuQTCZCUkCsDfUoMGaHK/xxWMVRJIko+BRLc
5hlSpg6Lg11EoaJCKkD4KCD8/b2kqH0slnoARpoKaWUAijPZCDH0DyixZBim
fosN5KBNkyD+6CiAfQjkBPCPSSENC1hC7qH/r/rjJtuszOZ2ZlFgMLCxj2iZ
x8HMGHYJCjiCAo7Q5gj6Zk4z8EsOUYRTA9rm6yPMMIF8mzI1bAZVLoHdiYzm
5R9XpIoeKqZMOBwOElRVzREt4HKhCiIJ2RHf/hoKyK8srNl9/HystJ8xhoCE
U1pJpAL+dPOcv3dcAHEpcQwJoMCBoEiFGy6VAsY4QptjgcXCDpkfeY+AYIEE
RxOD1UvlJTHs88ntDK9cAYU09e3+Vv+Sn8STJx4lKvmY5ECDVFilVEjQ8SVQ
eGMsg2/ReIQqLkDb2zxSwhdnwWBLWsOmCFklhOYIL4mI+ykPOOg3CAMS1yv1
2o/C1rhaBT7E/YviyeGdBN9e9VDZkZYT0msBEqkE0g4FquAQMQUxLDwEyH7C
73YAas/mPE+49lRvtrkEVSo1gW62iQIiWkjFGzx5zn/fvAQyNINoC0hEyLEP
Xx4R/VEE8IzD0ZdQrurX985DpUlLAgaFvYjcIeLR4MNkJEEPFZBDnqoX4u9I
kxjKZxFfGWiUPljLAowGGNCOOdTqPvxTOOgH/q55aIcSdN/EX0Alr0+NNnxY
dfi4vgNgGoS/G/0on1n0xc2NwADWaJ6qyLQ22CRgBDuXZAtgI8vocMXk55rw
UYqQwoYnny5BGUxcexSyx0UERxAFLFw2iOL9N4tGBebQrNXmFThoYBhsGRH6
Oqr25/EZWwEb+3tFwn9HoqoGmHO3uQcMWQM+TlEfEUwSkISfOBcq++Hhr48W
OITti0wzRuDYQvTnUBEQ5xfgD39/OwcxAES/MYyrAzD/SKAEMiJ8oKQkVMcn
5wD53r8WrQxDmQgdBLmVBIhb4IxAXJx4VBSQWzCQbCmwnvl7RSbkExGfBZ9s
KAEHXXMIsOD3E4EBrkgBaDEPBdd3D+vjYmLRvBM5RwyXBAhofUS40NgHUWxb
YDb6IZ37MPohDGmYDhBPvAR5UFDb+lDsMDhASKSGgt30XV2gIGSgr0iUdsE0
r8aimyMmPogAap4JEaLD/OVbbBAArFOgfuSxcwmAFkNswGKz4GmTNwPY7R+e
MiGI6c0nkqCBCbFrWGBoCUicHMQqAVRAJGsi+qH/cgg/CVG7ckghINqzGGoW
5B4Qixl4PfiUUsz8FKU+TKZEfOkK1qcM75UAy0aktnccSg6gasRkhPm54ySs
Qxb/7UM3G4EFS3QOgECFqHVbj5GC9c3fZSAsYREskGCdBzglAjRWDB4+QfBQ
isvIgvjuYen65CEMkIE0SjhjOWgRiT0HC50nBBUJRhbf1YUAkyOCdfAwhpcR
HaOQBcMCqAwR7SLCUF+Exon5bcREMJtDqqqCuZiIXcAh8UmWWjelmNZL8o/A
hkEkCP+vyyKE079PjdLRWTSlrArLNoK/SeBGf91xMs63CE00kUhBTKICdgtg
1MUkrf0/razk6Ee6LEG6QDQALKTmsKAimQYcOdxYDFiI7gttWvOLYuH3iuRQ
KrMEFpNgx8Nj04lx23sK0C0w6A0l+lLfnnHAJ6nZUwCJhQ/NHk2aDFD8024o
QckhJD/gAwMpnY8amBjkQ9MY4jQWgFdQJVsM2V4I3de3u4cIqJD6UDRfOrGr
o/4s2J4yGjqSEUfJ6zSS5Zu3jbMrRJUews/FhwBJBRqvQuKiIP8qwr4gThDJ
z0HNwNCEeFuIWCfQhxDogyeXS0w96aj9B5DM7wbcBwtf5FvxLRkBhG0AiEy3
GL5Z4rwmwjnlVyFDKpaEbAqibQCa2lwNMT6mjFcQsRHIaAA1jwxd4ndZKMOq
jyCugMEVFNIKXCwTgKU0ciFCxUvRib+/HSoyBT6A1AeKxSPisOZpcc6ihSQQ
NFKAvvE6jsKncMEI4LkmANtkcHoTYS2uiRhydxZpLd+3TPMwmzfpo4AJoRVs
fpGE6ymGCDaBR0+MoppFXfeNGpHQIWCb5CdVGCsk5O0RiSMQJwJXSvAKgS1O
FPzk7LHA4jjormWo0URAZ1SvTipVHpZn8KORqYXfd94a02qVqbWZAh0mBeoD
zAhiKBZIPwgcRsQu/vvZwzYcLMT9JUKDJ8HnMQGUIWAMmyAAp1kkxG7va8sQ
7yRUIDSCI0TwBcmOo1UZ5LUSjN5IiBY++/foNQAuRPPoEuRc0cmICJw8Cloj
VJI6iNosDn6CNWTq70ANiVD5JFQFxLeDAIKrwL4qgomqFP0oo6gnlIyJhgDs
SIEAjADmsA2SAQI3x6MIgypyVH49Og7QAe//q3NJoP7CpSlgv9CMC5UC9Zi5
JNLPXxfgcSnLreOeDHsUDt8RcRfCtS7j3pdp+fr16DgoNsnRhEEYUa1jyp2w
bb9JekmYgzTbSoJE9hu3IdYMGNmQDYLyVQQU7KNIkKXWYy6U23sqhuPG31WH
RowYfKAyF5AlIgBqINM9rHkRsC2DLRwrP4dViCRP4u6BopeF0QCHp0euLTh5
BRCpqpABUx+rv987dmuEYBOaQKXAHISMCeC5QBwe4Qjjq60yTf5HHgutxKCf
8aM2voYE/cGWMYbHYgTcI0CqG/+1Yck6Qc2TYDTG8q2uhtgzIWsxQE8d0xTE
+J/OpBGGShHT2mPJNPAnbFF3BS28AA2eHLWqyG/QSQI3hoInPg4HHxMEHlcD
2b+w01IAqFKfrO8vLsDtz+FmUSFhkpEISqJfgSQQdBfHewAfRrLsv/56iOgq
MgwC8BJAW5jgpg6BHcVwQuRhfNCc9j70/H9vWGj1ideSBF8VuIxJUjseUiA2
EwBbyZBhE/Hz90QM6YIRDBlVXOsBvGDkpIX6iVUN0lybFRXCCE/+VkIGENCC
iqTwLWYVQ09IewEFgzCaJeVDwf4N71Mv1ATzDg6idw7ZdCzKLQEehSyUVz6O
6yj56eNoz6uiqiQTGRxTHNzZImxkHlAPB9sRYisAcOB71SUYx6h4VjGGAgo0
ugKsUki2EpDhZisRX5vgB7MiMIUAeb/aJiyJYmuPIqEAlmkELm5bVv2nrSoN
Lqb+iQLeoQR3WiL1hx9KDBsjBSwbBYFC38OFGGdRiC+UlP0cWaU0xZfDBDlh
22xSUkGpaIh+bZgUANrE2RMhqBEU+8Q4GIr3BLGHxCBYIktX4n5MIlhEG5HC
DJhhc7+QBsHHNEckVa4ftDZ/BEeCIPD7yTNw9gwwyGtWpgCdOZk/ArMisyp4
TjEYWDSLipCMvhPPePJ1kIgt+V+eCFJrxcXjcpQRBKdg28YYsX1DXgm8TgKY
iqowxiVfEDyFRYgPGfgFJIg2bRpVGT4mf988dY6gXJGwBcpYzEEYTNkYtbWP
JN8g7vrwe5AK6y6iwsXcgcyj0bSygOYCXH8SNhHRvvp4te/YLh9lDGYxMY4p
AZayxJMUl1qz1xg47Pi4B0m+7m9MnwyeiYr+NAGsTeAvQKY8VlpzMvOYELFI
kPuW6xMwlgWwBmoEA3OcBNNMARCKj2qKx/fOwNvo+4b1sU8lUB1EgORk4hy3
Abyq3LYVBJ1OyL/6/I/ZnwAQSYUnGs34JZZY8CwQgnaFkzEWPOmIpY7wwzkh
TSju5QQu0gqG5gy161JJiyTS6TOyuRSs2O/2Xwra00BGHG6ILzehxmcAXYnV
b9DGj6sYlHw34M0PhzhtAmjpA3yDKkx2iCyW3o/4dLSt83H//gDsEDML8BFI
1Dbhs7kmBHASeFTIIpY0gzPkxwALgvwQxkMRvMup4UKE/dL8IQMRrApDHx6r
+htwi3EcKTTJMATKAQqEiLKEgckCcUVRyZZPAG5E3+0/g4uJaVcIKebBhhIB
fBHrNA5jMvqvDNmt36HfIW4x4i4XIMmNuqPK4MagOmJRGcoYlKg4/79hXjKe
ptnLmF8H8O2Sge4yOJ04XDEcfotCj47fw4rCDgzf4r0kzZgakqLXJg8TMLsC
s8L4Ny+dDEYBFBCaBGBYHlplMgeUsMwi8u1LUksI8aOfXkaGbjnCzauC6SHC
IIxkKsCBkRFbHXuEkagAh5q/3QQmjDyGzjwMLkkcHMWIlBb2JAcvIiIlDPuU
778uojCjNussyhIM2QMgRSFumRjhnMTeAnj79yQ0AQZIrirgmTHQCZneyyRQ
gRy2FKPmEeVHsbXvNpCAFejRBHAqmjcZYDQpAjomthGgFiQY05Om6Zu2wbWe
YjEKYAkmaDKS8eiIxKfemmybud18Ivk3eprBFRajoIpgeCHD4J5HG+UH7QVK
zU3i5Metz0ebrOAd0hhhFTZtHGapHLgBEk0Phj1K8zC/LSp8GOnGwOgIRgSq
DPGkAPcgwsqPEM4pg7TWPMBv2zUGRxnhxeFUpHbYzYkR4C6T4Ioew0MnQK4s
E/5GU/otS4GHIU6CE5VclAlMx6gxKFrICCRJHgSev3UdFPghuMkJwsmb9k2G
c2tEve+xSlm4AgV4Qe7rnA+Bk4jw7FPpgB6HjwrzVhm0NDJtpA6MoPB9X9AJ
ykUZvngxLrgQ+06AdwBpn3EvcHiHMvdPspAAiIA4JIJsJqLNJ/HyCYxOVPiz
gBJAickJ9+NEHOHPmx0qw1e9+cYJxo6saR/VcoDCXmXbd0gCD74vaNiCKwCj
Enjx01qLMJ1gycqh0gvQCrGoWKJvYiQ1OwYCwCM0m6NMVKSzqoAyVFyRKlCR
SPgpSlnsUxHcAwa9EjX8ZWETz8IrR0JFyqGeJ3Mu/+eaaB5OgFEOg2mXAh8l
BdAuqZQi1MbU9z+B/cq3PQdqBh+WEDHySCPKUQF3QgQHI4TZfQwIOvw1/0pw
hofwpGgeeAyHeg7+RBFwA4auK9wvCogQ8u8ImwVCwsB8UwCaR35eho11gooX
tiwqGHrxL+ek+dQhODYqDJqbdyvCVomhzia4PhiYyAdAEghs+D1/Z8kzJxUg
iPk+rnWyx4GRsuhBms8Swykmog7v37wLtrUvUZM2QDtAdq6IgpySAQKcrglO
exIl/Z1Ur2JyyrfM1XauweLHQLqjcaCkNpNg5hv9zGElsT0uVMzcY9hwU2oc
C6oJKeTwNFig5XL0U88TKyJEtqo0eINtJ8LN2ZWgFwsRLcWjbJDxGb+PC0Em
T5tcRigweGpgCsocC/BBRr4Cj3peovay4c+qk8HZpi6WCqx5yAQZkB2xqwac
yMMoUIJlz/f0X8SRTtNKmi1JfHMAxhKLMTBAFL8NWpDQFJNH90vPk8M2Wtyn
eC/SXAJgKRQyFZD0ywF0ZYQf0Kk5pjgA8griW33YDcsAT2gzIuK4aNk4Eqwk
v/F50CB5pS08WDQRIbKUyWvC9zyA1xK1LVOln3qelHmoTCRwpCPYbymYZ8kY
TBNxCao7ApJwqJO//roIK15acNJ2r3nDBP2DkVbz1yVY4bBgTlL2wndeusC1
HsoJvCwDnFQqDhwerYSIJxNg2KcileonqABcXyVuU6YpFTyg5AGYdwsA2Whu
fIDa4Ht8L2MWoMCkUoSohYVdu4LBVvPRVKwBiRLggcB/GyFxcvtbfIgCJIS3
k+YoaW1eWWB3PIzDYkBn/2C4JZh6q5iWUj58wrfUWfIMVZRqNG/gX4DA32WD
S41iTSJ6Hw4tPBkTwGGNUN8hXuDRm4jsj/d3COEJg4NagKOoCq4+ocqIoLsj
dl4CVqzQ2kP8eXQ+Qk3ksLX5Y6kFPI4LUonFCCqX268jwC7++71DMCTDvFIE
k7lZeKTxxzWhor4VcLfyQquX+i5KqYE1IRMCMSBpEGq7vCPknPG0uAJwR8jt
v0ArC6YKD5DEB8GPejaRmSbmSiGVY7DkI8t0L3zPoJEoFlBaIza1iFuMMhkY
uA+HOGeavRlCGPLtVMig9I1QsTTblugjuHb0T3SA4PnI9AwEadb3f8y/ZFRf
hNrEYZehupMBQ0mgGqpMay8VgVCkBD8mzgyGnjEcexXMcEVQnhg6f6d4PtyE
Q/SDLPNDVeKARQjgEhPIF4wsFkZphCyUtCFSTWUlAEaO2J+DOgIRSAVZmsF5
HsOSvrmnfDwrAuiBq9zU5wI6rH+UBxFG9iz4DwzyCVj4jxOmE9rAGKCBAgNu
JfkZadFZQ4Smg+R+IeeDMNgBrsYYGYjoHCMcYtLvNcFBgqRCHyEq7eSFvHkw
MwOoRRiajwKaaKj8aAdU5DFEKH1jkA9ZoPQqKgTi8yi1ll4KSLPNwuC+oU62
/QESxQR/QAIaU7O8AI7VYH23hEncHd+oEUnnApBFvndAozy83miZzSEEMlJb
IrqK3/J9UNN4pwAQRITKkFB6YNtHInbAcwtBmmLwD/9Ia5cB8kTA8HlMG0kE
CzoUEeIRAUNAUq5AuqWCfPI9CY2oSJFpA5YoFZnH+ZCgWGo7NQmJCAJZ9n+X
DYgWPKgdKh5sjKgtBiPFCIQZOW7TiUQYifq/ZSHN0eEpdgTj7HZ6hbehUCM2
HIkJRsbfQGsAKq+E07I5comMF2CXiBEhyVQAiMGBWEteEyTJ76GSCuPF5qhk
QKvgsGUkwEdM2JLiePCdJIzRk19XVh+s/gCDOQHeuAktlvBueZR2AfCQGOXK
t9FhAEokh5xFHpejCHdXQttAV07M4/6V9KbwbX/9d8fhCfsYBkWIbZNRYMhQ
TChAqAgOAKNJAmP+3nEC0yYQBCCGRRgQkGBIv9V60OQhAWz25kxQ1R93TppU
1PI25ZbMQ84Qv+U4kfISgDmp5zGg/Kmo+XZwzIChLYOuwKCODXBb0e+xaQl9
aqsn/HzvIaA5hnICcU0kWAAceAsK9AgsTVWBH64KLc/fNY8hrAK8qA1eApYr
gqMox23UB1F2gHBCAeRvlJiWbREOakJnFRCsIrdgSMy12RKEWYoZ7nc8hoxJ
mQjwNoIvHgMUPVHwrGSguFhXEujxHD7Fd20jo4eVMXoLcc5QAETh2jCVBLcw
maKC/vdjcAnEg4UnLMHAFVwEAVpLFEU8LMsTZH7IOHzE7yePiohcKBCTijAf
DwA4SKh5Aoh0Ivj1x6A4it/cA+A8IYKLqDVhgqpbhmWhjFOo2ZUC8jMCCAOZ
bz9cUFUFJCgQ7I5GJMrkrGhObx7JPYR0hDegAvD/1oQSC1TM5TnIOlTAsArU
HzwCEmIsuQDBPAKAYv97mAiwy4c9KMFpVfJShOEAVJBL2tlcjA6O8VsV4d8d
p6L0hSRNwThJRPNFVgKQahaENwZ2/L7UAhF//zpAvBBJhKraHqQq3Vl8y9hP
cIfKGNIFwk+GUzsbRZRaDH1KggCMGB1KjP6dBOHg3o9BcuCjn3OeunkS/qTc
uqVLqIdJNCAYcfy/nDcFlAHC11FJOZ+ELAQEm4encLNuY9ipc5TfDhfmENlO
HPtzw0aI7mDgkx5QZ1VIigI6YaGVIawtRfhgkpDdb0Uq9dROkM6InktCDBsr
tHlaNDwsgXyAsOUx1v/72yGhVZBEQn8jqdg5lLIcilWlZWWIgBlZ/8deMwSi
SAVxJFURuk4f90sM0iAtmRJqa87DTf77hoWdK4+xQnPRxID6IzgRq4CwCBSG
4icES5MMuX6jgAJ4KLePDohZgnVIKiLMwpp7h1h2UpdY6YeyQqtZ4iCsAtfl
8btQrjR/SFjxIUxRocyVwdX/fvMMbnMKhFKRSIyZnYzDTUa7TQYrHM55HBf+
t/d32EopA7mlo7DAclmw5lQK+AArDvFjRGz4dcP6qBVZcHojTMMJqxAbhJr8
BugCCIwPKi//u+piHJUEE5ZaJ2XqrCpi9xGiMnwmZLDIfEDN38wHDnNqAuBT
RSfyGEhriZhDYhyPe5bH9JZ2Yd93XIR7nMdRzCNkVKZDJbmVAzBiaxohi60e
5Puo5MFxFRG3xsFCnYXoIAARnUC+AuqTGEI5CJy/OScSIhwYiJg4HMs8Wu8Y
z1kEaKzixONptof8Q4Cn8XsiVgsL2IGMh/g2o05CHEtCmwhE6hJN/Tc9DzRO
UvuBfiABn5QRb6Mi1KetkDHZETAL+O4iRZB4BQyMZJQZzUsRCDFuz9VmQ4k0
kUVsE4O+z/kEf07vUBElPYPCTwbjKMSFHmNSLFP4N/hJx+QQbUjUlEJrE89A
6MTA5l7kWoQzxBRSQqRf9D3WwVdMtZyk1GfJAUUzUEPUVHR+p4K8l0Axx37X
tP/iIDE4FalKiEPiI0+1AMArVGpYjITIH8gLsDA1jheA6LIIxWGgR2Nw7Ypw
pZfxJJVfI2NK4yS22jhaaY4XWQwYW8fA5ymWS4d6RNv7PVxg279IlFDImwmA
4NFLubkgyKBBaZtrKj34zmxTASqGWCEJBkABNkUIcJ7y5QKK+0HWLQs//Dqi
OJZIARai+1aBbET+v+qZf02xm6OeQakcRr90XERkxdScHXkwESWuS62wyAfF
jtoPBdAmKL/ZnCwkJywsqhlUPnQcRpicUH+ryf+1e/JG+mha313+t3uyq03v
Wbpfl0Wo+Rk7XJ2fxoRZ8Ok8/Yd78rzuLD7/t+7Jaa2n//IxVn/dk52tlVrM
qDYO4WJ+tOrmRev5MH0vh31mR/7sQ/6sL/z3nx37/Nyqas3yhp3mFcej2hxv
jqPlvF/Td1LX+masv313/hoP+zv6bs7zIWM+9/z2M9EPiw27WGy1wbBjOQPn
20p4UHvHPrOhNsKbR5mt9WdvwMtMN3qFcpbZS9V57Jnkdb4oz1N32pkml0Ev
4P2J0eOW8lB/TBNNyW9v8+DcFs9+MRMiplvL2+QQp8yG4z7s+Oh9mqc1YOB1
3Bmm1m4wWCvJthDynbHtc+d4lYxO1xd/H8z5wP30E/IRDHs+Ih8n/cfPdv7x
wyv88BrOyaOB0x8S1+R5X8BvG1Jn5RH5ugfH/nSQprfOIB3pAyscT+qlNuKo
hfJWsb0s6e21s/gIXv72uKxZKzO0dx7cuxPjVZ2UW+CumAXrKh11JGwl7mHx
R6fLXvZ1PuEHInN+205fsqbrknk+/e4iO8SnNDOWS++5GJwPdmmKSRRu71nY
SWfiWV4bt6XVe77r4j0dasW03in8YZQ9KyfUzLN6H514g13H7ptzvJu2fW2Z
4+m52FpGuu/0dT8+P0dLWxJZ9jIxK7es3utDObaKccqvIy31b9xTe/Yv0YLl
5+NMmo5edfHkvWq7jK26UyqnvumnHyeSz2bgsRo77sVHu5Qmzrl7zIPrMXrk
XlGZp8vyfRMu2qhSptNY96+sz1xWt87oMfYPr1d/qSjbYLRYZpq+2ZTCIliH
l+N6+5QZ07/arpULzXdvT0/le+NufGZ2Dh/OfbUrOpU2CYLt4DQ9Zepg7U/6
y4W8vfeHFX++++nzw1+n8+A87s8mvQtnHO87sTRH6piT+OPQ0h6HTny2po/D
1HAPjGBq01U9XeTG4LOceXI+e3W7J/bTNebcuXTF7ud1zMr5dsOPzUOkLbb7
sXfo5Kd3OTtfN5fjxrrEhzi4jKvr/Hnf2Pdiba3YQ5ddHEfifTvRDnPhOirt
+es09/SRH0fP7WjaCZlY0UandSUee/31+sIqWjrU3ZP7mEmHaV1WwqYqXN0u
hyuh9D72SH49xsZpe6lnDz2uyg43VU7L/jR8H4cf4TgYzLhpNpvuBmNev1d7
W30dudjNdZ3Pnwzb9VhRPSjs/lglqSyU4bjsxPIir3x9Nos/+9FpezPqKvQ/
1XRfeqI6fwdCELoqu1JqyfPUt6hvbiOvcN21H9z59+A66ri1z2ZKpVWzyer5
Cr29w5Vhfn+Votld3rujz3gbvvR73QtroTyYj26iJP3nZ6rusnFvfnl1FIeV
5zdnU0uTVD8q9oAfb5eq/TKe77nxsefv6WP+4HdOvb7ZB0fyxdQeZwuhXFe3
j9pbLjvbwfF6vQqb/k2f+o/+KWL656MTluUkuqZWafc3TJqo0ug60ebHYqk9
iyA5fAbhwxhNpb1+7oQ7yc17/dJ5Xh/+eVelc0awR+VgKvLBdu7Wz955LJme
VJtunc24ZWqkKj9lIy0PopegJZ3eeO05O6ZU76F/nE1CLb6oDm/vh5vz/DEb
Ppst9AzUT552jWP9OHi63GzTjK941uEMLs46lbLZd+XSGH8+16f9OVicu94d
kvAk8vrBem0Xg4Wp72fZ5uCsU/+S9Q9X6R0MnIMnysxGYDrR9SWy8mJyuqnb
JGPDjzMN6s24PCscn+vvnXEUSid+1t7mcRI+b9n3Nry0f3vq+CB5bjzvPINT
zT4N1XfTXn7JZd8prIp/c9mSX4yji7Zfbt7OdFKrinM2xUUtJ5f4fRYlZr18
6oG+77z3j7VnVWM2rB/p7G6eVK67EbLuTRicEl3qxsKzdD/F88pFml/7V1nd
X27SqW9I/e2ob3U7nLh8L9Tn7bDNh+cztxqcP7PzgTuvzB5zMT6TT9Krr8Zp
JapZ87Bqd9W7PAb9aPUUvFGweo07B3ljHXzLkKbdi6wzZ7f5vufhx6iEkasx
d9UwRaZ/kJ98ygR12B85m0Dl+4/T67gqDtYl7Sw3zKy7yUfzbn9brIveS7iN
89R2Ftw9kmbih51oQmp1/dPGWYXpzHknxzSJpsG017tZhSB0kvtncRGH+kx7
pJNPLO4HWmFyB+OVGOdjUwLYccrac3mijd535cpG0m52ezuvw2F9HC+Mldox
r069mSyDvW5ft7uPd87Gg55Yl8t1b3hO5XwjG2730HtOvad2Mo/X2Z3Vn8qi
OosLo7DmXseMs1zORF7ie4y9yffF3FCuL+k+mfGCuWIOY/XiD1h3sulvXhtz
+e6O5SBk2GQxvX0Wk6XVUUb6/T1a7Bh3Y6hrL63E4v36WPmrLzK7fLSKP/ee
f80Hurw1vIxdPXZj11sWj/eVeQWnatpZiy9nf10sa3Gv9H1teTsvdOvh26Oz
5AbdLL3zXBFp9nUyG0rl5XhOZo4/XxYbzfT5x3ax6kRbZe54s+OHk5Rutlh1
j3M3MTPOOMXm6l4crqfJ3vSleMUuRjdzvON0d2gNeOnmeYJ3Y8rO7O0xzTLz
+5u19tbtfPk4Nd/QYRA4aSwcmcnysl4ZxdCqwukyHzpN7STXJ9t9FEObOe63
y86ny0SeV5q79eCs3OqHO+P7wxcXzvhP33xvNoUqHaOxdda1d1Zd+tJlfLEk
T57Gyx0X6UHaORW5etfkVOR8W79M01q9rxh14Dqb81m+JfPBUnG5pB48XtJ7
V09Ug73qoTQe5Lfw47pl3vGV0yX8WAM/vrhKf9x1notQqa/los7uY/NjOHpp
uUE1ULYL7q3w+4MuKZODzvWj8nh7hcNOP1YEZ8oPEr8ce/ZDKifj7eHalUNx
GHJ2b70St9fHxlt1hfUpMbjx3j9b4dbbu9zATl6l1GG3t/S0tEUv376mhSEu
3mo84PXhpw6m/n1rv4erwy2YdC/j0aA/e21d6/YRTwo7qOzzinnPOoWSD+ye
M9h2BaUerc+b/Hx/+Mnbim6jo8sH1ixQ1tzC933DOM7r3o0dbxbi1kvL0tZP
115nlN73F3+zDmMv9D7Pq6IplmDGzRtdO4wxY1ZGKMdLib0WT/bBfi6LjXrZ
e+HFXL6MmD/4nYti5Iq7UB23bIoJkT2oj9XiyVqr0gl11RmumK5m6qNgdPAK
L3o4+vokbpONPhtLOh/M5h1H6ZtauR9zS+c92k8PwtA/m2Gkj3dvTxJvUh2/
++O5vO7OrWPxLASj3pbHkzsTH8Kse7+XHYObVLabydt9Gs8Z86jcn4+wF6Xp
mE2KRzbPnDyozk5WizmvsMpenqW3TzHYz8beuBvqw84j4TaLvXAum43Us/jx
+FalJ3lw9M/zp3Z/apUgvfhkdxtbuRPf7+/VS8gH3cpPbMPPtFnRUWbXj77r
bhV+Zr85dvKYXeTradBLE0nSQ5Mvvb33NDhzVlZSc9QlinOxbP2cO82nliOZ
68xOfB4193f0tI6uaNRDPt/Hz/nbHBijbNg/mMfnK7aauvnKaUF88ZzrZamV
quxOdze+9C+da5jshe5zd5j0tat6me+YwpqG7mz3qsdenPkfybmWzmjnZyOJ
syf5Y1hEznI5jpoCkps5QSdb5c0KmEcHtXuZOwupYvtdpeLuZ5PzXO6TKYu0
fIQTPhE4pjuxHPdt3gthrBrLLXu77bYdJnxar8dCkCevV+C9IsvI1d2QDT0+
mc+uzSnqjuoZe7rKk+lLDMrds1cdxEuihM2benWPdid1ly81eHHvm90tPwU7
SybdlzM73o4fNZqOuF3+Wqh32WZ3+0M0SR82lytTu5dO74F3EvNB52nce73m
LjosmV3dPwhdNjqU54XExAV/2191Y76Uzl3Lu6dDbmEnmfliLH5kRSNrl3Gq
Mu3s9lmoKGepent3JrSUnmZ8VsO86Tds9eQ6z/555duZ2fdM9VoKj5USW3ER
bdztbhJ6fV3tvBgjGO+FSz+4pi5jfLyYi4bm5zk/P+rsXLzEfmDOGFabpuPR
1P+8LF87vAN7yHmhv3mpvQ472dizsvzMJuk45Jrq8/Yxsm5o5rezdt/6t0AZ
rqJinQ0PEiuOc82J2V1+P0VHK+rH1U7tMKI6HHTt6J55tzl3ETnvVsm5/lH2
41oyBxr30rfbVzUYrep1j48ZzdKbvumzCg9Boq0nZue5KZ9zudSPzjaNBG0l
X1LveaskL84DPy1q7SAI6TJ/rcv4MHZvw4Ee51F37/fdxD5dhlyn2GrG6qNN
Fx+GN4oquhgjxX9tjH7iqZboH9XPcKVp9fusXMogL/2NLe2eZjSw+VeSS6tV
Z51p8d70JmpdD23ZHmrRvXqI1tF5qnL33R3t0+uuG+ter2aUw3ga+pyWJMdy
Ne/NhzMlsToZ1/sUxWw+V+zmRngLqcl3y2pWM6ZgNJWjaEjRydmtRF8Ruuv+
uTfYZtbQqtOkufc392HeuXOG4+eTyUIcbVdzdSAvu5Ptvd5MD+b2XW8GE6Hs
96pbbC1mVn6dJwPm4uXP61vms51izPPOu6lglmqqfbrJtNJOvukq2zzj1c2t
utS9d69yP96Q9w4DO31kUaENq+ei/+oNw8BaRdtZ8w7M5fy25Ldz/SrOBUdd
LW6heF7f68LvniS2TNSnpZnb0y6rnaQ7aQ6Oj9W0Ho+TMpGPw8er4zbFnTRf
7uRtmXl5cwN7HCuExnuhP3q76vOSH7UajMd7pTqeBtvelXWb5a4qwaRZnvN5
v+x0p+tHyOwGwu203VRxKipHNRZknkk/I8k2L045yF7CNbsUuqKxF+Zo9fri
LgjHxp1Z8tNbZ5wvP3asWtfS74sv3TlNqxNjy8r+ZKwq5f24rcqbcSj5p271
9fu1ZrU78/q4srZSS32y8DtN587fx/OzcPMFtl87/vktz+eGHIyak0Fx6mfm
JtPPad1cA0OxdxrZRrJidEENDnmvUqxn57V8rV2Rb4ryLJm4xeI8CLs6v2RU
33yFS3//WrFzpVicJu/ZMCx122Km+Wm52EfssHe2To/Oq7fv6r1pxpZCFSXT
W3ncC1c27r72+ivU3lJfHPfznh03u1RKV1Y2vW1ZfZvsK3MaV44bdMzLnp+a
b7OIHsE2si76Vt1kKetdzY2Tr6PKl/vXc+/sy5rEDNPj9dgdz3ehqnr94ecp
J6em7cuK/qO3ZMX3ImAD9+24FzFsjiP7OBWPwfOl7W12w4xkffA5qK/aeN2C
gazOpfjlFkZX6byH4zh5eNJ9vuZPn3y35UL9MGGG/XvRG4yf3dC7du/n62M9
G0bcS72aj63FJsowjdKg/HSLznNwt++bwqm0RN1Fa9WP8+PCegT81diE/Xpi
be4cW/GTvfeWi0I+KfGkHoncsSnkdkOeUzu3xftaDsLBJQs33dNtYH4UIxaV
55oN5orpCdL2oBjc6zMa1mtfOysu73QXkjST4ud4cBw8O97xFQYab+ze6/vH
2PRY1SnCwp7erEV5C/nZzH1rtl8+pVnRVYq3Z52EYp2uvYv9NDPzceqcXCXT
1qY9vevLRTbzNnItnJqWahy65dub9+8zv76Z3vt970/82LGn3p6JRkXXvk17
StbTOpsns11NGGN0vHovJi/TNfdy4yNjlUWqMraQ73uHBaMH72Bsnox7kT8e
S37wdEN5dqs35qAjacz5UTrXxIiNKK+40ZAzNH26EQttW6+fpqno2vVoZnJ4
eQ5Gwnp5ZFRhkUr1qisWF/vViZtqVh9e9wu9WHLNxXF1Y3a2LQ/TvReMBG02
Mq1unRtBbVvj/ineFZIYmY79tDn3kz3ueSeZbuNkOtsZm1E6qu+xVMRvSVar
9erOzbeHmDku7oFYS5bbZ0a77v44mkZsVm3iQKvYhSB1qsXRzoXM17m0G/tZ
bd/jcjVe6dNQz6Ny3a3vkmCHQuGqZjaz1PAzfjn1dM0OtrP15pg9OuEhUvpF
dIuOxzK8noVQl57ny7Ffu9c0iN/WxuO3hVeJg93tNpyE/I6p+if7pWYFP5i8
BqOOmV8Mle+uDoePdhG7sb3aa59opDSd/ZZP+4q8eBzOyqCnvkLZvn9sNbKb
ovO0CtZzIUy9Q0cS7UlTFRz4Z+CeJ9lVYGLZj9N6583sZcEb5mVnX/TUkNRH
zgT3dV87PgPluGwO+/0x1j4dffGw+ORU3GRtYk+FLLT9JxsPFu7IKLSeGRby
/ZKmub8bL8Xh5JwtpGvzM9ec8yO5VF2mowuc6tyFiX+10s/V11+9s/5S02FU
fyJrOFlb7+u8adFm3auxVvbr5ijcCecFMwh3Qt20aEUnOg+L2rJnynwu6Gb2
kHqMXizGu+Rm9zahdL2P96+5qUrrILgzO2lVjd+5uuk9nstL7mbrYSdk7tax
OpyH78VEjvjewYyDucXJs8X94tc1E36khx/N2Oc12z/Lez99Nrsx2ahnecwI
TQHTudfV5eb01e2FU8xlWVx2/Dx9HWR2nx1dlX2FWVMbeOpgU0njYtuUOP06
rvaJvzysp5fanHS4kXgcXUp/uizj4Tq2lk/XL1Jd0dfTXn90UD3hbWpyzufW
qKyOi48tPc7K23nU0Xx+FoWi08us41KYMuNcfPOmtF6WD33fZ+pZcd9ueClz
5NASjfjQ31zfLK+E+dQvm5spe3U3fFMpVp3wpjsfdV8Om2L2WYdpYeap/Bbf
tTGN42bTn5+xkt7vjsodj/JGEfaTecD7W4FfVJOrY7Ed9TkOo/M2/myL43uS
WzuZS/d9n2HVZhO4W3ckDpeDzSNVM7PW+Cw9jHzjPg0X2Xw/eO1Xs070Sda3
TzR5bJKgcK/e4jybmdzV58/90zIrb1eZq60+V2yWu1N4ne/fvYV9zJRotFRV
7bCtOrZ1cLaerbvGwvkcBU+0bPvS1FOO+zSu+3J5vQyaLXQ5qHvzw92soqmf
xWi51LrOLNWWzb0wE9W7EJ2bqnc7vh/i7WNcOUmyPMw9jl9LA/2aDRz22Vea
g7hs2of5q0pmw7fu84w3fgWTe+fiPPh+wqy263u86w/qfLro2RNxupesjRtr
0v1ZBKIqHrhxPLzNwoHEzfTJ7TBZXvbb7usy7bzG81rhU/1yrebiZ5lmqyQT
mHPQ23mKPpMfk8XonUcPt6eW2tO4TcTZ+dT85of+PDg3ee12ttmmUJ39RKrr
tOvcPz2VUyeT0Vzd7sxk4wWDwMt50d9LaS56xsxbiNPmdtkd3TG7uffm747+
2fizfZC7z89iOxyYN07xrXvhbUrzExlTPrzs+oaj++Jkyd/v1qbfv+8/5Vsx
3Mnpyju7zsys08q6CIGUc8ddzfePOzUQywez2XCKs07jg+maXKqbhzW7MpXF
6hZFD+1SGX5cW6HDdFa+tNxsLX7vM9O3naWr2rlv9XJUvhg1NKOku1k7vdcu
6b8WsrV79lWhezTf1XDpxKvnXs87jmtfSmZ7vWhu6Kzy7i55LU/82zzy4+Xl
khducc4vc63oZi7v6+9p/7mV7ZAzBTcS8vXj0pm4h4dq3LLBcrOcbKe9wZyZ
+1veVZp2tFTTgbCaW59B87z2udBT6+QonV5Dq5uo2vuw2nTfnc3ePCvLj+cq
6+1585mMHic9SXeO28u55lF6U3ud6jr3iZN8liytLPRu2v7k2tZ6He029bRz
tx+3Z7i3us2CbeqKTV7OVutkuHnWvK6LvddjbYZXwzbL3DM+Qtcr7jeX43sG
MzxP9Tnrd/bp59Yv/ZTVg6IpGw7KPDxWTHd8Glx8/SwYQ9tZy+nSK+v/9b/+
/8Nk+uGpPNd5HKVFXN6rzn/+fyXyWuLof/1b4udV/G//RbJk/PJU/UnOtz/r
R1X9Mc6PKo/f/+PPyi/P1Z+pX1z80j+ReJJ5Fh6amumPfTfPh7L645fRH+18
i99/BueyjPMcr3KI80vyyP9UjzSNKxJRQ3/yFj+zuK7+vY2vic7hg7ytP48q
JvE1+fn+55z8ucev+5/kdi7+VFmR5f7tv3+w+vO/7ZXCMByj/Mf/6Pw//3ut
azwnq/+BFyf/pggs8x//7x+/+lOT99L873/+5/+8JaEiM0qQVf/1X//+p/2w
6fnPvfnPIf7jI+Wian5zp/mHKv772/79z79p58ubROb4ee2/qz+Ff2re6f3Q
/FH1J/arLL7hd+dx89ji26357JfbuYz/7c//7LTvh/2Pf+/8H9M/DktrGgEA

-->

</rfc>
