[ippm] Re: WG Last Call: draft-ietf-ippm-alt-mark-deployme nt-05 (Ends 2026-05-28)
Tim Chown <Tim.Chown=40jisc.ac.uk-Tr9gZwTxerDR74oF6e/[email protected]> Fri, 29 May 2026 08:42:56 +0000
| Newsgroups | gmane.ietf.ippm,gmane.ietf.bmwg |
|---|---|
| Message-ID | <DB9PR07MB7771C5F1718223B2E891BB84D6162@DB9PR07MB7771.eurprd07.prod.outlook.com> |
--===============5406423469840948437== Content-Language: en-GB Content-Type: multipart/related; boundary="_004_DB9PR07MB7771C5F1718223B2E891BB84D6162DB9PR07MB7771eurp_"; type="multipart/alternative" --_004_DB9PR07MB7771C5F1718223B2E891BB84D6162DB9PR07MB7771eurp_ Content-Type: multipart/alternative; boundary="_000_DB9PR07MB7771C5F1718223B2E891BB84D6162DB9PR07MB7771eurp_" --_000_DB9PR07MB7771C5F1718223B2E891BB84D6162DB9PR07MB7771eurp_ Content-Type: text/plain; charset="Windows-1252" Content-Transfer-Encoding: quoted-printable Hi, Some of Tjeerd=92s comments align with what I just posted. In R&E networks traffic from a university would typically traverse that uni= versity=92s national research and education network (NREN), out to some R&E= backbone, perhaps across a transatlantic link, into another NREN, and then= on to the destination university. We=92d expect DSCP to be conveyed end t= o end, and EHs to be carried end to end. And VPN/IPsec to not be used for = that. There is a L3VPN overlay for the International CERN experiment traffic (spa= nning over 100 of around 170 participating sites in 40 countries) but that= =92s not the norm - the overlay is principally to allow differential traffi= c handling by NRENs and by security policy on entry/exit from sites. Tim On 28/05/2026, 17:15, "Pinkert, Tjeerd" <tjeerd.pinkert=3D40siemens.com@dma= rc.ietf.org> wrote: Dear Guiseppe, A clarification in the draft would be appreciated. VPNs or IPsec tunnels are rigid methods of creating user-domains, so that i= s always possible. When asking the question, I was thinking about something else, namely, the = cases where such virtual networks are not used or not necessarily needed. E.g. in situations where the network is controlled by entity A and entity B= uses that network. When entity B, partially trusts entity A (e.g. that the network provided is= private), but still has need to check the quality. When entity A and B use the same alternate marker technology (and B signs),= what measures must the network owner (A) take to honour the network user (= B) his alternate markers? Is that possible with the currently designed methods? (Should it be?) Slightly OT some thoughts on use of the DSCP field: When using DSCP, or the reserved Flag on IPv4 (these were exactly the field= s I had in mind as usable). A signature over the IP header, added as IP option could be a possibility f= or the user to ensure that the packet was not manipulated. Internal to the controlled domain, the DSCP field should than not be change= d uncontrolled (e.g. it should be reset to the original value on exit of th= e controlled domain). DSCP has the disadvantage of being designed to be changed by nodes an-route= , especially when certain traffic classes are used. The DSCP field is thus basically only possible for a controlled domain, not= for an end-user, unless this would be explicitly specified by the network = owner how to do this. In my I-D for the IP measurement option, I added a flag field as alternate = marker, that could be used when the DSCP field is not feasible. All other fields can be zeroed out in that case. Next to that, it contains = the possibility of adding a cryptographic signature. In that sense it would be usable for both controlled and end-user domains. Best regards, Tjeerd From: Giuseppe Fioccola <[email protected]> Sent: Donnerstag, 28. Mai 2026 16:20 To: Pinkert, Tjeerd (SMO RI ML COC SM 2) <[email protected]>; draf= [email protected]; IPPM Chairs <[email protected]= >; [email protected]; [email protected]; [email protected] Subject: RE: WG Last Call: draft-ietf-ippm-alt-mark-deployment-05 (Ends 202= 6-05-28) Hi Tjeerd, I agree with you regarding the use of cryptography for the controlled domai= n. Indeed, if you look at section 2.1 of RFC9343, it is also mentioned that= multiple domains can create a whole controlled domain while traversing the= external domain by employing IPsec authentication and encryption or other = VPN technology. I can clarify this point in draft-ietf-ippm-alt-mark-deploy= ment too. Regarding the AltMark encapsulations, note that RFC9343 defines the extensi= on for IPv6, while in RFC9714 it is defined the extension for MPLS. There i= s no standard extension for IPv4, but, just to satisfy your curiosity, we i= nitially experimented the method by marking the DSCP field (see RFC8321) or= the last reserved bit of the Flag field (see draft-chen-ippm-coloring-base= d-ipfpm-framework). Other extensions are in progress, as you can notice in section 8 of draft-i= etf-ippm-alt-mark-deployment. Regards, Giuseppe From: Pinkert, Tjeerd <[email protected]<mailto:tjeerd.pinkert@sie= mens.com>> Sent: Wednesday, May 27, 2026 3:10 PM To: Giuseppe Fioccola <[email protected]<mailto:giuseppe.fioccol= [email protected]>>; [email protected]<mailto:draft-i= [email protected]>; IPPM Chairs <[email protected]<m= ailto:[email protected]>>; [email protected]<mailto:[email protected]>; bmwg@iet= f.org<mailto:[email protected]>; [email protected]<mailto:[email protected]= rg> Subject: RE: WG Last Call: draft-ietf-ippm-alt-mark-deployment-05 (Ends 202= 6-05-28) Dear Guiseppe, OK, so that scenario is possible. You may notice that I am interested in the network performance from the net= work user perspective. It is the question if the user domain could form such a controlled domain, = and the packets are allowed to travel though a foreign domain. >From a security perspective, one needs to know one thing: was my packet (th= e alternate marker) manipulated by the foreign domain? This can be achieved with cryptographic signatures, so that would need to b= e designed into the measurement protocols (alternate marker data). (Removal of alternate marker data is also a manipulation of the packet and = can be detected by the user.) I think a controlled user domain would be characterised by a shared secret = for signing / encryption. A user on the network edge, owning ten- to hundred-thousand machines formin= g a distributed system, is a common use-case. In particular, when the distributed system must be capable of adjusting to = the network conditions, alternate marking methods could also be used. Then the use of alternate markers by the user and the network owner should = not collide. One (off topic) thing I would be interested in, is what fields are typicall= y used for alternate marking methods, and if signatures come into question = for that? Best regards, Tjeerd From: Giuseppe Fioccola <[email protected]<mailto:giuseppe.fiocc= [email protected]>> Sent: Donnerstag, 21. Mai 2026 10:32 To: Pinkert, Tjeerd (SMO RI ML COC SM 2) <[email protected]<mailto= :[email protected]>>; [email protected]= <mailto:[email protected]>; IPPM Chairs <ippm-ch= [email protected]<mailto:[email protected]>>; [email protected]<mailto:ippm@ietf= .org>; [email protected]<mailto:[email protected]>; [email protected]<mailto:bmw= [email protected]> Subject: RE: WG Last Call: draft-ietf-ippm-alt-mark-deployment-05 (Ends 202= 6-05-28) Hi Tjeerd, Thank you for the question. Yes, it would be possible. But, for security reasons, In-Data-Packet OAM me= thods, such as Alternate-Marking and IOAM, should be applied to limited/con= trolled domains. You can find more details about this requirement in RFC 93= 41 and RFC 9197. It was initially discussed in RFC 8799. Regards, Giuseppe From: Pinkert, Tjeerd <[email protected]<mailto:tjeerd.pinkert@sie= mens.com>> Sent: Wednesday, May 20, 2026 4:19 PM To: [email protected]<mailto:draft-ietf-ippm-alt= [email protected]>; IPPM Chairs <[email protected]<mailto:ippm-c= [email protected]>>; [email protected]<mailto:[email protected]>; [email protected]<mailto= :[email protected]>; [email protected]<mailto:[email protected]> Subject: Re: WG Last Call: draft-ietf-ippm-alt-mark-deployment-05 (Ends 202= 6-05-28) Dear all, I=92m just wondering, can internet users form a controlled (boundary) domai= n and apply the alternate marking method independently of the controlled ne= twork domain? This should be possible, but is not very deeply explored? (Or maybe I=92m just missing the point, and the remarks on encapsulating tr= affic cover this sufficiently?) With best regards, Dr. Tjeerd Pinkert Siemens Mobility GmbH Mobility Rail Infrastructure System Management 2 SMO RI ML COC SM 2 Ackerstr. 22 38126 Braunschweig, Germany Phone: +49 (1520) 2884088 Mobile: +49 (1520) 2884088 mailto:[email protected] www.siemens.com<https://www.siemens.com> [Logo] Siemens Mobility GmbH; Chairman of the Supervisory Board: Roland Busch; Man= agement Board: Beatrice Bock, Michael Peter; Registered office: Munich, Ger= many; Commercial registry Munich, HRB 237219; WEEE-Reg.-No. DE 92917817 --_000_DB9PR07MB7771C5F1718223B2E891BB84D6162DB9PR07MB7771eurp_ Content-Type: text/html; charset="Windows-1252" Content-Transfer-Encoding: quoted-printable <html> <head> <meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3DWindows-1= 252"> </head> <body> <div style=3D"direction: ltr; font-family: Aptos, Arial, Helvetica, sans-se= rif; font-size: 12pt; color: rgb(0, 0, 0);"> Hi,</div> <div style=3D"direction: ltr; font-family: Aptos, Arial, Helvetica, sans-se= rif; font-size: 12pt; color: rgb(0, 0, 0);"> <br> </div> <div style=3D"direction: ltr; font-family: Aptos, Arial, Helvetica, sans-se= rif; font-size: 12pt; color: rgb(0, 0, 0);"> Some of Tjeerd=92s comments align with what I just posted. </div> <div style=3D"direction: ltr; font-family: Aptos, Arial, Helvetica, sans-se= rif; font-size: 12pt; color: rgb(0, 0, 0);"> <br> </div> <div style=3D"direction: ltr; font-family: Aptos, Arial, Helvetica, sans-se= rif; font-size: 12pt; color: rgb(0, 0, 0);"> In R&E networks traffic from a university would typically traverse that= university=92s national research and education network (NREN), out to some= R&E backbone, perhaps across a transatlantic link, into another NREN, = and then on to the destination university. We=92d expect DSCP to be conveyed end to end, and EHs to be carried = end to end. And VPN/IPsec to not be used for that.</div> <div style=3D"direction: ltr; font-family: Aptos, Arial, Helvetica, sans-se= rif; font-size: 12pt; color: rgb(0, 0, 0);"> <br> </div> <div style=3D"direction: ltr; font-family: Aptos, Arial, Helvetica, sans-se= rif; font-size: 12pt; color: rgb(0, 0, 0);"> There is a L3VPN overlay for the International CERN experiment traffic (spa= nning over 100 of around 170 participating sites in 40 countries) but that= =92s not the norm - the overlay is principally to allow differential traffi= c handling by NRENs and by security policy on entry/exit from sites.</div> <div style=3D"direction: ltr; font-family: Aptos, Arial, Helvetica, sans-se= rif; font-size: 12pt; color: rgb(0, 0, 0);"> <br> </div> <div style=3D"direction: ltr; font-family: Aptos, Arial, Helvetica, sans-se= rif; font-size: 12pt; color: rgb(0, 0, 0);"> Tim</div> <div style=3D"direction: ltr; font-family: Aptos, Arial, Helvetica, sans-se= rif; font-size: 12pt; color: rgb(0, 0, 0);"> <br> </div> <div id=3D"mail-editor-reference-message-container"> <div class=3D"ms-outlook-mobile-reference-message skipProofing" style=3D"di= rection: ltr;"> <meta name=3D"Generator" content=3D"Microsoft Word 15 (filtered medium)"> </div> <div class=3D"ms-outlook-mobile-reference-message skipProofing">On 28/05/20= 26, 17:15, "Pinkert, Tjeerd" <tjeerd.pinkert=3D40siemens.com@d= marc.ietf.org> wrote:</div> <div class=3D"ms-outlook-mobile-reference-message skipProofing" style=3D"di= rection: ltr;"> <br> </div> <p class=3D"MsoNormal" style=3D"margin: 0cm; font-family: Calibri, sans-ser= if; font-size: 10pt;"> <span style=3D"font-size: 12pt;">Dear Guiseppe,</span></p> <p class=3D"MsoNormal" style=3D"margin: 0cm; font-family: Calibri, sans-ser= if; font-size: 10pt;"> <span style=3D"font-size: 12pt;"> </span></p> <p class=3D"MsoNormal" style=3D"margin: 0cm; font-family: Calibri, sans-ser= if; font-size: 10pt;"> <span style=3D"font-size: 12pt;">A clarification in the draft would be appr= eciated.</span></p> <p class=3D"MsoNormal" style=3D"margin: 0cm; font-family: Calibri, sans-ser= if; font-size: 10pt;"> <span style=3D"font-size: 12pt;">VPNs or IPsec tunnels are rigid methods of= creating user-domains, so that is always possible.</span></p> <p class=3D"MsoNormal" style=3D"margin: 0cm; font-family: Calibri, sans-ser= if; font-size: 10pt;"> <span style=3D"font-size: 12pt;"> </span></p> <p class=3D"MsoNormal" style=3D"margin: 0cm; font-family: Calibri, sans-ser= if; font-size: 10pt;"> <span style=3D"font-size: 12pt;">When asking the question, I was thinking a= bout something else, namely, the cases where such virtual networks are not = used or not necessarily needed.</span></p> <p class=3D"MsoNormal" style=3D"margin: 0cm; font-family: Calibri, sans-ser= if; font-size: 10pt;"> <span style=3D"font-size: 12pt;">E.g. in situations where the network is co= ntrolled by entity A and entity B uses that network.</span></p> <p class=3D"MsoNormal" style=3D"margin: 0cm; font-family: Calibri, sans-ser= if; font-size: 10pt;"> <span style=3D"font-size: 12pt;">When entity B, partially trusts entity A (= e.g. that the network provided is private), but still has need to check the= quality.</span></p> <p class=3D"MsoNormal" style=3D"margin: 0cm; font-family: Calibri, sans-ser= if; font-size: 10pt;"> <span style=3D"font-size: 12pt;">When entity A and B use the same alternate= marker technology (and B signs), what measures must the network owner (A) = take to honour the network user (B) his alternate markers?</span></p> <p class=3D"MsoNormal" style=3D"margin: 0cm; font-family: Calibri, sans-ser= if; font-size: 10pt;"> <span style=3D"font-size: 12pt;">Is that possible with the currently design= ed methods? (Should it be?)</span></p> <p class=3D"MsoNormal" style=3D"margin: 0cm; font-family: Calibri, sans-ser= if; font-size: 10pt;"> <span style=3D"font-size: 12pt;"> </span></p> <p class=3D"MsoNormal" style=3D"margin: 0cm; font-family: Calibri, sans-ser= if; font-size: 10pt;"> <span style=3D"font-size: 12pt;">Slightly OT some thoughts on use of the DS= CP field:</span></p> <p class=3D"MsoNormal" style=3D"margin: 0cm; font-family: Calibri, sans-ser= if; font-size: 10pt;"> <span style=3D"font-size: 12pt;">When using DSCP, or the reserved Flag on I= Pv4 (these were exactly the fields I had in mind as usable).</span></p> <p class=3D"MsoNormal" style=3D"margin: 0cm; font-family: Calibri, sans-ser= if; font-size: 10pt;"> <span style=3D"font-size: 12pt;">A signature over the IP header, added as I= P option could be a possibility for the user to ensure that the packet was = not manipulated.</span></p> <p class=3D"MsoNormal" style=3D"margin: 0cm; font-family: Calibri, sans-ser= if; font-size: 10pt;"> <span style=3D"font-size: 12pt;">Internal to the controlled domain, the DSC= P field should than not be changed uncontrolled (e.g. it should be reset to= the original value on exit of the controlled domain).</span></p> <p class=3D"MsoNormal" style=3D"margin: 0cm; font-family: Calibri, sans-ser= if; font-size: 10pt;"> <span style=3D"font-size: 12pt;">DSCP has the disadvantage of being designe= d to be changed by nodes an-route, especially when certain traffic classes = are used.</span></p> <p class=3D"MsoNormal" style=3D"margin: 0cm; font-family: Calibri, sans-ser= if; font-size: 10pt;"> <span style=3D"font-size: 12pt;">The DSCP field is thus basically only poss= ible for a controlled domain, not for an end-user, unless this would be exp= licitly specified by the network owner how to do this.</span></p> <p class=3D"MsoNormal" style=3D"margin: 0cm; font-family: Calibri, sans-ser= if; font-size: 10pt;"> <span style=3D"font-size: 12pt;"> </span></p> <p class=3D"MsoNormal" style=3D"margin: 0cm; font-family: Calibri, sans-ser= if; font-size: 10pt;"> <span style=3D"font-size: 12pt;">In my I-D for the IP measurement option, I= added a flag field as alternate marker, that could be used when the DSCP f= ield is not feasible.</span></p> <p class=3D"MsoNormal" style=3D"margin: 0cm; font-family: Calibri, sans-ser= if; font-size: 10pt;"> <span style=3D"font-size: 12pt;">All other fields can be zeroed out in that= case. Next to that, it contains the possibility of adding a cryptographic = signature.</span></p> <p class=3D"MsoNormal" style=3D"margin: 0cm; font-family: Calibri, sans-ser= if; font-size: 10pt;"> <span style=3D"font-size: 12pt;">In that sense it would be usable for both = controlled and end-user domains.</span></p> <p class=3D"MsoNormal" style=3D"margin: 0cm; font-family: Calibri, sans-ser= if; font-size: 10pt;"> <span style=3D"font-size: 12pt;"> </span></p> <p class=3D"MsoNormal" style=3D"margin: 0cm; font-family: Calibri, sans-ser= if; font-size: 10pt;"> <span style=3D"font-size: 12pt;">Best regards,</span></p> <p class=3D"MsoNormal" style=3D"margin: 0cm; font-family: Calibri, sans-ser= if; font-size: 10pt;"> <span style=3D"font-size: 12pt;"> </span></p> <p class=3D"MsoNormal" style=3D"margin: 0cm; font-family: Calibri, sans-ser= if; font-size: 10pt;"> <span style=3D"font-size: 12pt;"><br> Tjeerd</span></p> <p class=3D"MsoNormal" style=3D"margin: 0cm; font-family: Calibri, sans-ser= if; font-size: 10pt;"> <span style=3D"font-size: 12pt;"> </span></p> <p class=3D"MsoNormal" style=3D"margin: 0cm; font-family: Calibri, sans-ser= if; font-size: 10pt;"> </p> <div style=3D"padding: 3pt 0cm 0cm; border-width: 1pt medium medium; border= -style: solid none none; border-color: rgb(225, 225, 225) currentcolor curr= entcolor;"> <p class=3D"MsoNormal" style=3D"margin: 0cm; font-family: Calibri, sans-ser= if; font-size: 10pt;"> <span style=3D"font-size: 11pt;"><b>From:</b> Giuseppe Fioccola <gi= [email protected]><br> <b>Sent:</b> Donnerstag, 28. Mai 2026 16:20<br> <b>To:</b> Pinkert, Tjeerd (SMO RI ML COC SM 2) <tjeerd.pinkert@sie= mens.com>; [email protected]; IPPM Chairs <= ;[email protected]>; [email protected]; [email protected]; [email protected]= rg<br> <b>Subject:</b> RE: WG Last Call: draft-ietf-ippm-alt-mark-deployment-= 05 (Ends 2026-05-28)</span></p> </div> <p class=3D"MsoNormal" style=3D"margin: 0cm; font-family: Calibri, sans-ser= if; font-size: 10pt;"> </p> <p class=3D"MsoNormal" style=3D"margin: 0cm; font-family: Calibri, sans-ser= if; font-size: 10pt;"> <span style=3D"font-size: 11pt;">Hi Tjeerd,</span></p> <p class=3D"MsoNormal" style=3D"margin: 0cm; font-family: Calibri, sans-ser= if; font-size: 10pt;"> <span style=3D"font-size: 11pt;"> </span></p> <p class=3D"MsoNormal" style=3D"margin: 0cm; font-family: Calibri, sans-ser= if; font-size: 10pt;"> <span style=3D"font-size: 11pt;">I agree with you regarding the use of cryp= tography for the controlled domain. Indeed, if you look at section 2.1 of R= FC9343, it is also mentioned that multiple domains can create a whole contr= olled domain while traversing the external domain by employing IPsec authentication and encryption or other = VPN technology. I can clarify this point in draft-ietf-ippm-alt-mark-deploy= ment too.</span></p> <p class=3D"MsoNormal" style=3D"margin: 0cm; font-family: Calibri, sans-ser= if; font-size: 10pt;"> <span style=3D"font-size: 11pt;"> </span></p> <p class=3D"MsoNormal" style=3D"margin: 0cm; font-family: Calibri, sans-ser= if; font-size: 10pt;"> <span style=3D"font-size: 11pt;">Regarding the AltMark encapsulations, note= that RFC9343 defines the extension for IPv6, while in RFC9714 it is define= d the extension for MPLS. There is no standard extension for IPv4, but, jus= t to satisfy your curiosity, we initially experimented the method by marking the DSCP field (see RFC8321) or the las= t reserved bit of the Flag field (see draft-chen-ippm-coloring-based-ipfpm-= framework).</span></p> <p class=3D"MsoNormal" style=3D"margin: 0cm; font-family: Calibri, sans-ser= if; font-size: 10pt;"> <span style=3D"font-size: 11pt;">Other extensions are in progress, as you c= an notice in section 8 of draft-ietf-ippm-alt-mark-deployment.</span></p> <p class=3D"MsoNormal" style=3D"margin: 0cm; font-family: Calibri, sans-ser= if; font-size: 10pt;"> <span style=3D"font-size: 11pt;"> </span></p> <p class=3D"MsoNormal" style=3D"margin: 0cm; font-family: Calibri, sans-ser= if; font-size: 10pt;"> <span style=3D"font-size: 11pt;"> </span></p> <p class=3D"MsoNormal" style=3D"margin: 0cm; font-family: Calibri, sans-ser= if; font-size: 10pt;"> <span style=3D"font-size: 11pt;">Regards,</span></p> <p class=3D"MsoNormal" style=3D"margin: 0cm; font-family: Calibri, sans-ser= if; font-size: 10pt;"> <span style=3D"font-size: 11pt;"> </span></p> <p class=3D"MsoNormal" style=3D"margin: 0cm; font-family: Calibri, sans-ser= if; font-size: 10pt;"> <span style=3D"font-size: 11pt;">Giuseppe</span></p> <p class=3D"MsoNormal" style=3D"margin: 0cm; font-family: Calibri, sans-ser= if; font-size: 10pt;"> <span style=3D"font-size: 11pt;"> </span></p> <p class=3D"MsoNormal" style=3D"margin: 0cm; font-family: Calibri, sans-ser= if; font-size: 10pt;"> <span style=3D"font-size: 11pt;"> </span></p> <div style=3D"padding: 3pt 0cm 0cm; border-width: 1pt medium medium; border= -style: solid none none; border-color: rgb(225, 225, 225) currentcolor curr= entcolor;"> <p class=3D"MsoNormal" style=3D"margin: 0cm; font-family: Calibri, sans-ser= if; font-size: 10pt;"> <span style=3D"font-size: 11pt;"><b>From:</b> Pinkert, Tjeerd <</sp= an><span style=3D"font-size: 11pt; color: rgb(5, 99, 193);"><a href=3D"mail= to:[email protected]" data-outlook-id=3D"69925ac8-3801-4863-8a3e-5= 1d6a4973f18" style=3D"color: rgb(5, 99, 193); margin-top: 0px; margin-botto= m: 0px;"><u>[email protected]</u></a></span><span style=3D"font-si= ze: 11pt;">><br> <b>Sent:</b> Wednesday, May 27, 2026 3:10 PM<br> <b>To:</b> Giuseppe Fioccola <</span><span style=3D"font-size: 11pt= ; color: rgb(5, 99, 193);"><a href=3D"mailto:[email protected]" = data-outlook-id=3D"4bf22952-6ef2-4d2d-9866-4e09fd957c25" style=3D"color: rg= b(5, 99, 193); margin-top: 0px; margin-bottom: 0px;"><u>giuseppe.fioccola@h= uawei.com</u></a></span><span style=3D"font-size: 11pt;">>; </span><span style=3D"font-size: 11pt; color: rgb(5, 99, 193);"><a href=3D"= mailto:[email protected]" data-outlook-id=3D"080= 588f6-f92b-4542-96dc-37f529f5a047" style=3D"color: rgb(5, 99, 193); margin-= top: 0px; margin-bottom: 0px;"><u>draft-ietf-ippm-alt-mark-deployment@ietf.= org</u></a></span><span style=3D"font-size: 11pt;">; IPPM Chairs <</span><span style=3D"font-size: 11pt; color: rgb(5, 99, 1= 93);"><a href=3D"mailto:[email protected]" data-outlook-id=3D"d3a5852d-1= 882-442c-afdc-e5f8fc403105" style=3D"color: rgb(5, 99, 193); margin-top: 0p= x; margin-bottom: 0px;"><u>[email protected]</u></a></span><span style= =3D"font-size: 11pt;">>; </span><span style=3D"font-size: 11pt; color: rgb(5, 99, 193);"><a href=3D"= mailto:[email protected]" data-outlook-id=3D"91ea379a-8d20-400c-a9f6-7fbad1bfa2= 1d" style=3D"color: rgb(5, 99, 193); margin-top: 0px; margin-bottom: 0px;">= <u>[email protected]</u></a></span><span style=3D"font-size: 11pt;">; </span><span style=3D"font-size: 11pt; color: rgb(5, 99, 193);"><a href=3D"= mailto:[email protected]" data-outlook-id=3D"e245e1d9-3120-4a8a-8625-13df581f82= 8c" style=3D"color: rgb(5, 99, 193); margin-top: 0px; margin-bottom: 0px;">= <u>[email protected]</u></a></span><span style=3D"font-size: 11pt;">; </span><span style=3D"font-size: 11pt; color: rgb(5, 99, 193);"><a href=3D"= mailto:[email protected]" data-outlook-id=3D"9e886d6c-4945-4d8b-9ee8-084= 47b1f8d7c" style=3D"color: rgb(5, 99, 193); margin-top: 0px; margin-bottom:= 0px;"><u>[email protected]</u></a></span><span style=3D"font-size: 11pt= ;"><br> <b>Subject:</b> RE: WG Last Call: draft-ietf-ippm-alt-mark-deployment-= 05 (Ends 2026-05-28)</span></p> </div> <p class=3D"MsoNormal" style=3D"margin: 0cm; font-family: Calibri, sans-ser= if; font-size: 10pt;"> </p> <p class=3D"MsoNormal" style=3D"margin: 0cm; font-family: Calibri, sans-ser= if; font-size: 10pt;"> <span style=3D"font-size: 12pt;">Dear Guiseppe,</span></p> <p class=3D"MsoNormal" style=3D"margin: 0cm; font-family: Calibri, sans-ser= if; font-size: 10pt;"> <span style=3D"font-size: 12pt;"> </span></p> <p class=3D"MsoNormal" style=3D"margin: 0cm; font-family: Calibri, sans-ser= if; font-size: 10pt;"> <span style=3D"font-size: 12pt;">OK, so that scenario is possible.</span></= p> <p class=3D"MsoNormal" style=3D"margin: 0cm; font-family: Calibri, sans-ser= if; font-size: 10pt;"> <span style=3D"font-size: 12pt;">You may notice that I am interested in the= network performance from the network user perspective.</span></p> <p class=3D"MsoNormal" style=3D"margin: 0cm; font-family: Calibri, sans-ser= if; font-size: 10pt;"> <span style=3D"font-size: 12pt;"> </span></p> <p class=3D"MsoNormal" style=3D"margin: 0cm; font-family: Calibri, sans-ser= if; font-size: 10pt;"> <span style=3D"font-size: 12pt;">It is the question if the user domain coul= d form such a controlled domain, and the packets are allowed to travel thou= gh a foreign domain.</span></p> <p class=3D"MsoNormal" style=3D"margin: 0cm; font-family: Calibri, sans-ser= if; font-size: 10pt;"> <span style=3D"font-size: 12pt;">From a security perspective, one needs to = know one thing: was my packet (the alternate marker) manipulated by the for= eign domain?</span></p> <p class=3D"MsoNormal" style=3D"margin: 0cm; font-family: Calibri, sans-ser= if; font-size: 10pt;"> <span style=3D"font-size: 12pt;">This can be achieved with cryptographic si= gnatures, so that would need to be designed into the measurement protocols = (alternate marker data).</span></p> <p class=3D"MsoNormal" style=3D"margin: 0cm; font-family: Calibri, sans-ser= if; font-size: 10pt;"> <span style=3D"font-size: 12pt;">(Removal of alternate marker data is also = a manipulation of the packet and can be detected by the user.)</span></p> <p class=3D"MsoNormal" style=3D"margin: 0cm; font-family: Calibri, sans-ser= if; font-size: 10pt;"> <span style=3D"font-size: 12pt;">I think a controlled user domain would be = characterised by a shared secret for signing / encryption.</span></p> <p class=3D"MsoNormal" style=3D"margin: 0cm; font-family: Calibri, sans-ser= if; font-size: 10pt;"> <span style=3D"font-size: 12pt;"> </span></p> <p class=3D"MsoNormal" style=3D"margin: 0cm; font-family: Calibri, sans-ser= if; font-size: 10pt;"> <span style=3D"font-size: 12pt;">A user on the network edge, owning ten- to= hundred-thousand machines forming a distributed system, is a common use-ca= se.</span></p> <p class=3D"MsoNormal" style=3D"margin: 0cm; font-family: Calibri, sans-ser= if; font-size: 10pt;"> <span style=3D"font-size: 12pt;">In particular, when the distributed system= must be capable of adjusting to the network conditions, alternate marking = methods could also be used.</span></p> <p class=3D"MsoNormal" style=3D"margin: 0cm; font-family: Calibri, sans-ser= if; font-size: 10pt;"> <span style=3D"font-size: 12pt;">Then the use of alternate markers by the u= ser and the network owner should not collide.</span></p> <p class=3D"MsoNormal" style=3D"margin: 0cm; font-family: Calibri, sans-ser= if; font-size: 10pt;"> <span style=3D"font-size: 12pt;"> </span></p> <p class=3D"MsoNormal" style=3D"margin: 0cm; font-family: Calibri, sans-ser= if; font-size: 10pt;"> <span style=3D"font-size: 12pt;">One (off topic) thing I would be intereste= d in, is what fields are typically used for alternate marking methods, and = if signatures come into question for that?</span></p> <p class=3D"MsoNormal" style=3D"margin: 0cm; font-family: Calibri, sans-ser= if; font-size: 10pt;"> <span style=3D"font-size: 12pt;"> </span></p> <p class=3D"MsoNormal" style=3D"margin: 0cm; font-family: Calibri, sans-ser= if; font-size: 10pt;"> <span style=3D"font-size: 12pt;">Best regards,</span></p> <p class=3D"MsoNormal" style=3D"margin: 0cm; font-family: Calibri, sans-ser= if; font-size: 10pt;"> <span style=3D"font-size: 12pt;"> </span></p> <p class=3D"MsoNormal" style=3D"margin: 0cm; font-family: Calibri, sans-ser= if; font-size: 10pt;"> <span style=3D"font-size: 12pt;"> </span></p> <p class=3D"MsoNormal" style=3D"margin: 0cm; font-family: Calibri, sans-ser= if; font-size: 10pt;"> <span style=3D"font-size: 12pt;">Tjeerd</span></p> <p class=3D"MsoNormal" style=3D"margin: 0cm; font-family: Calibri, sans-ser= if; font-size: 10pt;"> <span style=3D"font-size: 12pt;"> </span></p> <p class=3D"MsoNormal" style=3D"margin: 0cm; font-family: Calibri, sans-ser= if; font-size: 10pt;"> </p> <div style=3D"padding: 3pt 0cm 0cm; border-width: 1pt medium medium; border= -style: solid none none; border-color: rgb(225, 225, 225) currentcolor curr= entcolor;"> <p class=3D"MsoNormal" style=3D"margin: 0cm; font-family: Calibri, sans-ser= if; font-size: 10pt;"> <span style=3D"font-size: 11pt;"><b>From:</b> Giuseppe Fioccola <</= span><span style=3D"font-size: 11pt; color: rgb(5, 99, 193);"><a href=3D"ma= ilto:[email protected]" data-outlook-id=3D"499bdf42-ec63-48d2-8b= 63-9242160ae325" style=3D"color: rgb(5, 99, 193); margin-top: 0px; margin-b= ottom: 0px;"><u>[email protected]</u></a></span><span style=3D"f= ont-size: 11pt;">><br> <b>Sent:</b> Donnerstag, 21. Mai 2026 10:32<br> <b>To:</b> Pinkert, Tjeerd (SMO RI ML COC SM 2) <</span><span style= =3D"font-size: 11pt; color: rgb(5, 99, 193);"><a href=3D"mailto:tjeerd.pink= [email protected]" data-outlook-id=3D"acc6299f-a7c9-4d3e-8f26-44d0ab2b50be" s= tyle=3D"color: rgb(5, 99, 193); margin-top: 0px; margin-bottom: 0px;"><u>tj= [email protected]</u></a></span><span style=3D"font-size: 11pt;">>= ;; </span><span style=3D"font-size: 11pt; color: rgb(5, 99, 193);"><a href=3D"= mailto:[email protected]" data-outlook-id=3D"7fe= c394f-52ff-45e9-b948-fa497f47f875" style=3D"color: rgb(5, 99, 193); margin-= top: 0px; margin-bottom: 0px;"><u>draft-ietf-ippm-alt-mark-deployment@ietf.= org</u></a></span><span style=3D"font-size: 11pt;">; IPPM Chairs <</span><span style=3D"font-size: 11pt; color: rgb(5, 99, 1= 93);"><a href=3D"mailto:[email protected]" data-outlook-id=3D"3a438d5d-4= 5b6-4ec9-9e21-ef595d931fce" style=3D"color: rgb(5, 99, 193); margin-top: 0p= x; margin-bottom: 0px;"><u>[email protected]</u></a></span><span style= =3D"font-size: 11pt;">>; </span><span style=3D"font-size: 11pt; color: rgb(5, 99, 193);"><a href=3D"= mailto:[email protected]" data-outlook-id=3D"78c00606-4a0d-473a-a34e-3dc1e9c454= d0" style=3D"color: rgb(5, 99, 193); margin-top: 0px; margin-bottom: 0px;">= <u>[email protected]</u></a></span><span style=3D"font-size: 11pt;">; </span><span style=3D"font-size: 11pt; color: rgb(5, 99, 193);"><a href=3D"= mailto:[email protected]" data-outlook-id=3D"3bb5911a-3478-40af-b334-c5413c83e8= 66" style=3D"color: rgb(5, 99, 193); margin-top: 0px; margin-bottom: 0px;">= <u>[email protected]</u></a></span><span style=3D"font-size: 11pt;">; </span><span style=3D"font-size: 11pt; color: rgb(5, 99, 193);"><a href=3D"= mailto:[email protected]" data-outlook-id=3D"efd59bd9-9c8a-44c7-a47f-4c8= 8bdf9c54e" style=3D"color: rgb(5, 99, 193); margin-top: 0px; margin-bottom:= 0px;"><u>[email protected]</u></a></span><span style=3D"font-size: 11pt= ;"><br> <b>Subject:</b> RE: WG Last Call: draft-ietf-ippm-alt-mark-deployment-= 05 (Ends 2026-05-28)</span></p> </div> <p class=3D"MsoNormal" style=3D"margin: 0cm; font-family: Calibri, sans-ser= if; font-size: 10pt;"> </p> <p class=3D"MsoNormal" style=3D"margin: 0cm; font-family: Calibri, sans-ser= if; font-size: 10pt;"> <span style=3D"font-size: 11pt;">Hi Tjeerd,</span></p> <p class=3D"MsoNormal" style=3D"margin: 0cm; font-family: Calibri, sans-ser= if; font-size: 10pt;"> <span style=3D"font-size: 11pt;">Thank you for the question.</span></p> <p class=3D"MsoNormal" style=3D"margin: 0cm; font-family: Calibri, sans-ser= if; font-size: 10pt;"> <span style=3D"font-size: 11pt;">Yes, it would be possible. But, for securi= ty reasons,</span> <span style=3D"font-size: 11pt;">In-Data-Packet OAM methods, such as Altern= ate-Marking and IOAM, should be applied to limited/controlled domains. You = can find more details about this requirement in RFC 9341 and RFC 9197. It w= as initially discussed in RFC 8799.</span></p> <p class=3D"MsoNormal" style=3D"margin: 0cm; font-family: Calibri, sans-ser= if; font-size: 10pt;"> <span style=3D"font-size: 11pt;"> </span></p> <p class=3D"MsoNormal" style=3D"margin: 0cm; font-family: Calibri, sans-ser= if; font-size: 10pt;"> <span style=3D"font-size: 11pt;">Regards,</span></p> <p class=3D"MsoNormal" style=3D"margin: 0cm; font-family: Calibri, sans-ser= if; font-size: 10pt;"> <span style=3D"font-size: 11pt;"> </span></p> <p class=3D"MsoNormal" style=3D"margin: 0cm; font-family: Calibri, sans-ser= if; font-size: 10pt;"> <span style=3D"font-size: 11pt;">Giuseppe</span></p> <p class=3D"MsoNormal" style=3D"margin: 0cm; font-family: Calibri, sans-ser= if; font-size: 10pt;"> <span style=3D"font-size: 11pt;"> </span></p> <div style=3D"padding: 3pt 0cm 0cm; border-width: 1pt medium medium; border= -style: solid none none; border-color: rgb(225, 225, 225) currentcolor curr= entcolor;"> <p class=3D"MsoNormal" style=3D"margin: 0cm; font-family: Calibri, sans-ser= if; font-size: 10pt;"> <span style=3D"font-size: 11pt;"><b>From:</b> Pinkert, Tjeerd <</sp= an><span style=3D"font-size: 11pt; color: rgb(5, 99, 193);"><a href=3D"mail= to:[email protected]" data-outlook-id=3D"38dc76ac-8d3f-4d31-bb94-f= 2dad780a7a7" style=3D"color: rgb(5, 99, 193); margin-top: 0px; margin-botto= m: 0px;"><u>[email protected]</u></a></span><span style=3D"font-si= ze: 11pt;">><br> <b>Sent:</b> Wednesday, May 20, 2026 4:19 PM<br> <b>To:</b> </span><span style=3D"font-size: 11pt; color: rgb(5, 99, 193);">= <a href=3D"mailto:[email protected]" data-outloo= k-id=3D"f1ab213c-c21b-4786-b5d4-26a5da525881" style=3D"color: rgb(5, 99, 19= 3); margin-top: 0px; margin-bottom: 0px;"><u>draft-ietf-ippm-alt-mark-deplo= [email protected]</u></a></span><span style=3D"font-size: 11pt;">; IPPM Chairs <</span><span style=3D"font-size: 11pt; color: rgb(5, 99, 1= 93);"><a href=3D"mailto:[email protected]" data-outlook-id=3D"45e36182-b= 217-4eb9-9264-a5bbed1e3a3f" style=3D"color: rgb(5, 99, 193); margin-top: 0p= x; margin-bottom: 0px;"><u>[email protected]</u></a></span><span style= =3D"font-size: 11pt;">>; </span><span style=3D"font-size: 11pt; color: rgb(5, 99, 193);"><a href=3D"= mailto:[email protected]" data-outlook-id=3D"2803cdbb-9018-4dc7-954e-512cfb928b= 49" style=3D"color: rgb(5, 99, 193); margin-top: 0px; margin-bottom: 0px;">= <u>[email protected]</u></a></span><span style=3D"font-size: 11pt;">; </span><span style=3D"font-size: 11pt; color: rgb(5, 99, 193);"><a href=3D"= mailto:[email protected]" data-outlook-id=3D"9ee17e65-1ff4-4fe0-a703-0822798694= 49" style=3D"color: rgb(5, 99, 193); margin-top: 0px; margin-bottom: 0px;">= <u>[email protected]</u></a></span><span style=3D"font-size: 11pt;">; </span><span style=3D"font-size: 11pt; color: rgb(5, 99, 193);"><a href=3D"= mailto:[email protected]" data-outlook-id=3D"001e1748-cd43-423b-bfc0-0c5= fadec69cf" style=3D"color: rgb(5, 99, 193); margin-top: 0px; margin-bottom:= 0px;"><u>[email protected]</u></a></span><span style=3D"font-size: 11pt= ;"><br> <b>Subject:</b> Re: WG Last Call: draft-ietf-ippm-alt-mark-deployment-= 05 (Ends 2026-05-28)</span></p> </div> <p class=3D"MsoNormal" style=3D"margin: 0cm; font-family: Calibri, sans-ser= if; font-size: 10pt;"> </p> <p class=3D"MsoNormal" style=3D"margin: 0cm; font-family: Calibri, sans-ser= if; font-size: 10pt;"> <span style=3D"font-size: 12pt;">Dear all,</span></p> <p class=3D"MsoNormal" style=3D"margin: 0cm; font-family: Calibri, sans-ser= if; font-size: 10pt;"> <span style=3D"font-size: 12pt;"> </span></p> <p class=3D"MsoNormal" style=3D"margin: 0cm; font-family: Calibri, sans-ser= if; font-size: 10pt;"> <span style=3D"font-size: 12pt;">I=92m just wondering, can internet users f= orm a controlled (boundary) domain and apply the alternate marking method i= ndependently of the controlled network domain?</span></p> <p class=3D"MsoNormal" style=3D"margin: 0cm; font-family: Calibri, sans-ser= if; font-size: 10pt;"> <span style=3D"font-size: 12pt;">This should be possible, but is not very d= eeply explored?</span></p> <p class=3D"MsoNormal" style=3D"margin: 0cm; font-family: Calibri, sans-ser= if; font-size: 10pt;"> <span style=3D"font-size: 12pt;">(Or maybe I=92m just missing the point, an= d the remarks on encapsulating traffic cover this sufficiently?)</span></p> <p class=3D"MsoNormal" style=3D"margin: 0cm; font-family: Calibri, sans-ser= if; font-size: 10pt;"> <span style=3D"font-size: 12pt;"> </span></p> <p class=3D"MsoNormal" style=3D"margin: 0cm; font-family: Calibri, sans-ser= if; font-size: 10pt;"> <span style=3D"font-family: Arial, sans-serif; color: black;">With best reg= ards,<br> Dr. Tjeerd Pinkert<br> <br> Siemens Mobility GmbH<br> Mobility<br> Rail Infrastructure<br> System Management 2<br> SMO RI ML COC SM 2<br> Ackerstr. 22<br> 38126 Braunschweig, Germany<br> Phone: +49 (1520) 2884088<br> Mobile: +49 (1520) 2884088<br> </span><span style=3D"font-family: Arial, sans-serif; color: blue;"><a href= =3D"mailto:[email protected]" data-outlook-id=3D"632d6502-2e3d-4db= 9-b1c5-db333179278b" style=3D"color: blue; margin-top: 0px; margin-bottom: = 0px;"><u>mailto:[email protected]</u></a></span><span style=3D"fon= t-family: Arial, sans-serif; color: black;"><br> </span><span style=3D"font-family: Arial, sans-serif; color: blue;"><a href= =3D"https://www.siemens.com" target=3D"_blank" data-outlook-id=3D"364f83c6-= fd73-4407-8073-130f4c3af740" style=3D"color: blue; margin-top: 0px; margin-= bottom: 0px;"><u>www.siemens.com</u></a></span><span style=3D"font-family: = Arial, sans-serif; color: black;"><br> <img src=3D"cid:image001.gif-I/[email protected]" alt=3D"Logo" id=3D"Picture_= x0020_1" width=3D"201" height=3D"79" style=3D"width: 2.1041in; height: 0.83= 33in; margin-top: 0px; margin-bottom: 0px;"><br> </span><span style=3D"font-family: Arial, sans-serif; font-size: 8pt; color= : black;">Siemens Mobility GmbH; Chairman of the Supervisory Board: Roland = Busch; Management Board: Beatrice Bock, Michael Peter; Registered office: M= unich, Germany; Commercial registry Munich, HRB 237219; WEEE-Reg.-No. DE 92917817</span></p> </div> </body> </html> --_000_DB9PR07MB7771C5F1718223B2E891BB84D6162DB9PR07MB7771eurp_-- --_004_DB9PR07MB7771C5F1718223B2E891BB84D6162DB9PR07MB7771eurp_ Content-Type: image/gif; name="image001.gif" Content-Description: image001.gif Content-Disposition: inline; filename="image001.gif"; size=2730; creation-date="Thu, 28 May 2026 16:12:40 GMT"; modification-date="Fri, 29 May 2026 08:38:50 GMT" Content-ID: <image001.gif-I/[email protected]> Content-Transfer-Encoding: base64 R0lGODlhygBQAPcAAAAAAP///wCZmQCamgCYmACXlwCUlACTkwCRkQCOjgCNjQCLiwKamgKZmQKT kwOXlwSZmQSVlQWamgWXlwabmwaXlweZmQiYmAmbmwmXlwqdnQqamgqWlguZmQ2eng2amg6cnA2X lw6amhCfnxGcnBGbmxKcnBOenhKWlhSfnxWdnRafnxeiohehoRednRihoRmfnxqiohugoBygoBub mx2jox6kpB6ioiCkpB+hoSCjoyChoSKlpSKioiWnpySkpCenpyelpSqrqymoqCmnpyikpCqoqCun pyqlpSqjoyyqqiypqS6pqS+qqi6npzCrqzKrqzGoqDOsrDStrTWurjatrTWrqzeurjeqqjmtrTuw sDqsrD2xsT+ysj2trT+xsT6urj+vr0Kzs0GxsUCurkCtrUO0tEKxsUOyska0tEe1tUezs0m2tkex sUm1tUiysku2tky3t0y1tU+4uE63t020tE2zs1C4uE+1tVG3t1K4uFW7u1W5uVe6ule5uVq8vFu7 u129vV27u1+9vWC+vmG/v2C9vWK/v2TBwWPAwGfDw2bAwGnCwmvDw2nAwGrAwG3ExGzCwm/FxXPH x3HDw3XGxn3Ly3rGxn3JyYDMzH/Ly4HLy4XOzofPz4XMzIfNzYnPz4jNzYrPz43S0ovQ0IzQ0I7R 0ZHS0pHR0ZTU1JPT05LR0ZfW1pXT05fV1ZjV1ZnW1prW1prU1J3Y2J3X15/Y2J7X153V1aLa2qHY 2KXb26PZ2afb26nc3Kve3qnb263f36vd3azd3a/f37Lh4bHg4LDf37Xh4bfi4rbg4Lvk5L3m5rvj 473l5b/m5r7l5cHn58Ln58bp6cTn58nq6sbn58rq6sjo6Mzr687s7NHt7dPt7dXu7tnw8Nrw8Nnv 793y8tzx8d/z8+H09OL09OHz8+T19eLz8+f29un39+f19ev4+Or39+75+fH6+u/4+PH5+fX8/PP6 +vX7+/f8/Pb7+/n9/fv+/vr9/fz+/v7//////wAAAAAAAAAAAAAAACH/C05FVFNDQVBFMi4wAwEA AAAh+QQFAAD7ACwAAAAAygBQAAAI/wADCBxIsKDBgwgTKlzIsKHDhxAjSpxIsaLFixgzatzIsaPH jyBDihxJsqTJkyhTqlzJsqXLlzBjypxJs6bNmzhz6tzJs6fPn0CDCh1KtKjRo0iTKl3KtKnTp1Cj Sp1KtarVq1izat3KtavXr2DDih1LtqzZs2gh5ku37Zo2cvX0GcxHt27Bunjz0pUrMN+9vAv16b37 V29evgEEA55rF6G7btaseWuXbym2UGhaUIBAYcQQOpe0EZwEBg0aL47aDUwnqLTp17DRlME1sNQW 2GEI2UPYrc6X12H8mBt4D5OX2MjBWBqIjMyZ115q3V0U5ksd0QTR2QLEQwMECRpsfP95FAypKBMI DhQgwL5AgQMKQBHkksCAgQRO0A0Ul6O+/f8A3qfJQIQoAOABByCDkCUG/oeACt0MZI8dDQYIYAJs DMRKAgf8l8AQ9BB0DxEIIMDBMwQpEwWC67FHQAEGKEDFUad0OIAABnQIo30ImEKQGgYIIMABVqQz EDlBBCnAADsGmEAmAyFygJBUGqDHQflMYcCNQhpwQzgS5jHlkgRYeB8cA81iAAFU4piKiFAYUEAJ 0QyEzQkILPnefx0i0IVR2qgQ5ItMaNJLMKxAUgUKpfyoJJFGCoSkkgS0sIQRmGaaxCtRjkllASZQ Y9AzD7SJ45dhjkmAB5dmimkSkKT/uWabBuCgDnFxzllnAPjAkacABazAyC7C5GKJGzT8WVQnB7Bp ABD6EUTPNN84KiSkRyZ5rSbyvOPtt++EKJCUpg65XEF6eNolqgLZI2aXcXQLrrfzyMomlQQcgAmu ctIpEDYqFADsB8MYxM00RiHyqwFUVLYQkNcWme2jnTBELrBUHnBGvXaSIPC9p4LZ7rtDXrmQmmyC fMARkd6Tq78B+DKBwAWoYI1TiqhKAB7VPPyoxJJqOyQnFjfLgBD3FvAAigNZggB7PkiwrsgBuDvm AXcwhLIAFAh8bcUBuNzvrsNU4HUBRNjiDlM1qrzBIcSIaxDEQwIdwKTXNrqQlC9y/+KD1wcEMpA8 Y6jXAiMXTJ3qtXtovaYBd1yhZAEtgBP2y7tyA4OSOGoMSzlKmaODp0wicEEWvSA2EN3YBj35FIkU Irvsf0hDELkHAPPJmAVgUG0AyERAAAKE6FJqyIsDa0PssxcCiC4EoXxAJcQ0KyQCklw+tkD6JPKr kPka0IMm7yQVTAfqAtshHzdbW3ekdwutPoL0K0DL7VMe4Is2D9x7wLnpIkAEiCEMJXmJalb7FP3q 54jorekAjEjHEcZkAB7cCnMDOQcTEFAALgmgTAhgwi7wgRRkYKFDpspXCWizup/BD29Ces8C4TML /A0JF/OowtW4oA9tWKBMVaAHLf8oyK6qkWx+C1TAIxyYr0MEgBUOSJm+AiCF7Q0EHIEwwNNMlaNF qOYo7IhFFuzjtSUd4ALKaGHEXii0AiyhD3qIYxzrwLRx5a+GprBeATogjVLkr1GxICICSVaAGPBB jnG0wy2YeABCBGAeX5hcCrLBBSsOJB/HAMQF1AOyAiTgXEipRy64kIFZXW8RfGGd3WB4gIrp45Ww LAjuaiiOGxjwD1xYjwW4EYBAKm5kV7sSLGPJSEcGoBeeQkAlxGDJgkwjEC5QT8Z+QI6l2OMYfVjP taqwDoGoko2PItre7igQSHCuAWbsg1x8iTxgXitrJ3ugMd1hhS0B6wUseBHMEIL/jUyA4GwFaEZT 6OEGAwZhHN504cSuJU6FzFIgyiijiwrADIGw84DJw5rj8mXMABjDlNrUFUNOQSkDAIMo+FDdaK62 hfIF4JsLHZKPxjmkGgaAHk3g3JDWwLGLFjGBQ2pcPDlKHD58L4Ywy8duDoKN/n2wANAgCjUM4Qpl ZIMc7niHN3pRA68hoBFqfF9MDTCHWMDirGhNhYLsWNOB1AhfBxjFQHw6SAo+waxoPWsqeBEPgUiv o8DLQBmBBTN6SMISxaBGON4BD3I4g3VHiJZQlHEABHwABj9QghFuMLNrhUCgCV1jTIFlpgSYoVNt FUg5eGDAE2Cnl4JMHmkthIAd/0Trr9JKg7pEetMhJOACKtCBEZbwgxJM7pNFWYYI5OQeMhKgdCS4 X1hbFz/Ouei6+coQWw9gU4FMYkoDCBxB6CrbD2K3TD+IFG4JEo0ffgpm9piCeppLxmsdwIvJrQCH EGQfBHGwDVEliBYUgCAFIEGy4pABgWc4QwWIYSCBWAB8WEGQYZQIAQaw3UBaseAEnMAbEnqDhBm8 wATMIFobQsAC+mCQQiz4AAmIAGjxIYX98jdHCCqCKo4Cj2KcAhOGkMMYxiCHSJQCGfIwiDFQoQpV rOIXfRWIPHaxiiZb+cpNXkUxBtIMJqOClwNpxycoQQlSqI4bVXZyLeBxyWQwGXTLWF7FLjiGZidX tCDgeLMqTiGL4QjkGq/wRCTugIYvpGEQm9DFOZqiGJWmZSCKcdijJ03pSlv60pjOtKY3zelOe/rT oA61qEdN6lKb+tSoTrWqV83qVrv61bCOtaxnTeta2/rWuM61rnfN6177+tfAtklAAAA7 --_004_DB9PR07MB7771C5F1718223B2E891BB84D6162DB9PR07MB7771eurp_-- --===============5406423469840948437== Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: base64 Content-Disposition: inline X19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX18KaXBwbSBtYWls aW5nIGxpc3QgLS0gaXBwbUBpZXRmLm9yZwpUbyB1bnN1YnNjcmliZSBzZW5kIGFuIGVtYWlsIHRv IGlwcG0tbGVhdmVAaWV0Zi5vcmcK --===============5406423469840948437==--