[openpgp] Re: draft-ietf-openpgp-nist-bp-comp: add Categor y-5/P-384 combinations
Falko Strenzke <[email protected]> Tue, 07 Jul 2026 07:36:33 +0200
| Newsgroups | gmane.ietf.openpgp |
|---|---|
| Message-ID | <[email protected]> |
--===============8533406413271407222== Content-Type: multipart/signed; micalg="sha-256"; protocol="application/pkcs7-signature"; boundary="=-T/BS6SbYgjC7ESRG7F5v" --=-T/BS6SbYgjC7ESRG7F5v Content-Type: multipart/alternative; boundary="=-wWmc4qGUJcIp4ZG1Mhkm" --=-wWmc4qGUJcIp4ZG1Mhkm Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable Hi Gergely, the picture is still not clear to me. You have to be aware that the draft i= s in an advanced state and that the algorithm combinations currently specif= ied have already undergone discussions in the working group and seem to be = the consensus we arrived at. Most importantly, adding new code points is a = somewhat critical thing since the WG has been quite restrictive regarding t= he number of new code points they allow. Already in=C2=A0[RFC 9980](https:/= /www.rfc-editor.org/info/rfc9980/), we had to cut down the number of code p= oints, especially for SLH-DSA, where only 3 of the 6 SHAKE-variants have be= en included. What I =E2=80=93 from my personal point of view =E2=80=93 am t= rying to say is that if you want to motivate the addition of further code p= oints, you will need to describe the specific use case that requires them t= o sufficient detail and with concrete references. Otherwise I don't expect = that the WG will vote for the addition of further code points. Best regards, Falko=20 =20 On Mon, 2026-07-06 at 17:04 +0200, NGG wrote: > Hello Falko, > Thanks for the question. > I did not mean that any single one of the existing profiles requires both= hybrid use and category-5 ML-* alone. > My point is interoperability across profiles: some environments allow P-3= 84 but not P-521, while other requirements may call for category-5 ML-*. Im= plementations may need one standardized hybrid option that works across as = many such environments as possible. > So the goal is not to satisfy a single profile with one algorithm choice,= but to define an optional P-384/category-5 combination that is broadly usa= ble across multiple profiles and avoids private, non-standard combinations. > Best regards, =20 > Gergely >=20 > Falko Strenzke <[[email protected]](mailto:[email protected])> ez= t =C3=ADrta (id=C5=91pont: 2026. j=C3=BAl. 6., H, 16:35): >=20 > > Hi Gergely, > >=20 > > On Sat, 2026-06-20 at 22:56 +0200, NGG wrote: > >=20 > > > Hello OpenPGP WG, =20 > > > =20 > > > I would like to suggest adding the following optional combinations to= =C2=A0draft-ietf-openpgp-nist-bp-comp: =20 > > > =20 > > > * ML-KEM-1024+ECDH-NIST-P-384 =20 > > > * ML-DSA-87+ECDSA-NIST-P-384 =20 > > > =20 > > > The current draft pairs the category-5 ML-* parameter sets only with= =C2=A0P-521, while P-384 is paired with category-3. =20 > > > =20 > > > The motivation is compliance interoperability.Some deployed profiles,= =C2=A0including CNSA 1.0 and NATO FMN certificate profiles,=C2=A0admit P-38= 4 but not P-521.Separately, other policies or deployment requirements=C2=A0= may call for the category-5 ML-* parameter sets. > >=20 > > What requirements of profiles are you exactly referring to? CNSA does n= ot require multi-algorithm at all, so for this purpose the security level o= f the traditional component should not matter. In fact it could simply be i= gnored for the signature at least. > >=20 > > Falko > >=20 > > > =20 > > > These are not necessarily requirements imposed by the same profile, b= ut=C2=A0software may need to operate across several such environments. > > > Standardized P-384/category-5 combinations would provide a useful=C2= =A0intersection. =20 > > > =20 > > > There is already relevant IETF precedent: =20 > > > =20 > > > * The TLS ECDHE-MLKEM specification defines SecP384r1MLKEM1024. =20 > > > * The LAMPS composite-signature specification defines id-MLDSA87-ECDS= A-P384-SHA512. =20 > > > =20 > > > These combinations could be added alongside the existing P-521 varian= ts,=C2=A0without changing or replacing them. =20 > > > =20 > > > Would the WG consider adding them? =20 > > > =20 > > > Best regards,Gergely Nagy > > > ``` _______________________________________________ openpgp mailing list -- [[email protected]](mailto:[email protected]) To unsubscribe send an email to [[email protected]](mailto:openpgp-lea= [email protected]) ``` > >=20 > > ``` _______________________________________________ > > openpgp mailing list -- [[email protected]](mailto:[email protected]) > > To unsubscribe send an email to [[email protected]](mailto:openpgp= [email protected]) ``` > ``` --=20 ``` MTG AG =20 Dr. Falko Strenzke Phone: +49 6151 8000 24 =20 E-Mail: [[email protected]](mailto:[email protected]) =20 Web: mtg.de MTG AG - Dolivostr. 11 - 64293 Darmstadt, Germany =20 Commercial register: HRB 8901 =20 Register Court: Amtsgericht Darmstadt =20 Management Board: J=C3=BCrgen Ruf (CEO), Tamer Kemer=C3=B6z =20 Chairman of the Supervisory Board: Dr. Thomas Milde This email may contain confidential and/or privileged information. If you a= re not the correct recipient or have received this email in error, =20 please inform the sender immediately and delete this email.Unauthorised cop= ying or distribution of this email is not permitted. Data protection information: Privacy policy --=-wWmc4qGUJcIp4ZG1Mhkm Content-Type: text/html; charset="utf-8" Content-Transfer-Encoding: quoted-printable <p>Hi Gergely,</p> <p>the picture is still not clear to me. You have to be aware that the draf= t is in an advanced state and that the algorithm combinations currently spe= cified have already undergone discussions in the working group and seem to = be the consensus we arrived at. Most importantly, adding new code points is= a somewhat critical thing since the WG has been quite restrictive regardin= g the number of new code points they allow. Already in=C2=A0<a href=3D"http= s://www.rfc-editor.org/info/rfc9980/">RFC 9980</a>, we had to cut down the = number of code points, especially for SLH-DSA, where only 3 of the 6 SHAKE-= variants have been included. What I =E2=80=93 from my personal point of vie= w =E2=80=93 am trying to say is that if you want to motivate the addition o= f further code points, you will need to describe the specific use case that= requires them to sufficient detail and with concrete references. Otherwise= I don't expect that the WG will vote for the addition of further code poin= ts.</p> <p>Best regards, Falko</p> <p>On Mon, 2026-07-06 at 17:04 +0200, NGG wrote:</p> <blockquote type=3D"cite"> <p>Hello Falko, Thanks for the question. I did not mean that any single one of the existing profiles requires both h= ybrid use and category-5 ML-* alone. My point is interoperability across profiles: some environments allow P-384= but not P-521, while other requirements may call for category-5 ML-*. Impl= ementations may need one standardized hybrid option that works across as ma= ny such environments as possible. So the goal is not to satisfy a single profile with one algorithm choice, b= ut to define an optional P-384/category-5 combination that is broadly usabl= e across multiple profiles and avoids private, non-standard combinations. Best regards,<br /> Gergely</p> <p>Falko Strenzke <<a href=3D"mailto:[email protected]">falko.strenz= [email protected]</a>> ezt =C3=ADrta (id=C5=91pont: 2026. j=C3=BAl. 6., H, 16:35= ):</p> <blockquote type=3D"cite"> <p>Hi Gergely,</p> <p>On Sat, 2026-06-20 at 22:56 +0200, NGG wrote:</p> <blockquote type=3D"cite"> <p>Hello OpenPGP WG,</p> <p>I would like to suggest adding the following optional combinations to=C2= =A0draft-ietf-openpgp-nist-bp-comp:</p> <ul> <li>ML-KEM-1024+ECDH-NIST-P-384</li> <li>ML-DSA-87+ECDSA-NIST-P-384</li> </ul> <p>The current draft pairs the category-5 ML-* parameter sets only with=C2= =A0P-521, while P-384 is paired with category-3.</p> <p>The motivation is compliance interoperability.Some deployed profiles,=C2= =A0including CNSA 1.0 and NATO FMN certificate profiles,=C2=A0admit P-384 b= ut not P-521.Separately, other policies or deployment requirements=C2=A0may= call for the category-5 ML-* parameter sets.</p> </blockquote> <p>What requirements of profiles are you exactly referring to? CNSA does no= t require multi-algorithm at all, so for this purpose the security level of= the traditional component should not matter. In fact it could simply be ig= nored for the signature at least.</p> <p>Falko</p> <blockquote type=3D"cite"> <p>These are not necessarily requirements imposed by the same profile, but= =C2=A0software may need to operate across several such environments. Standardized P-384/category-5 combinations would provide a useful=C2=A0inte= rsection.</p> <p>There is already relevant IETF precedent:</p> <ul> <li>The TLS ECDHE-MLKEM specification defines SecP384r1MLKEM1024.</li> <li>The LAMPS composite-signature specification defines id-MLDSA87-ECDSA-P3= 84-SHA512.</li> </ul> <p>These combinations could be added alongside the existing P-521 variants,= =C2=A0without changing or replacing them.</p> <p>Would the WG consider adding them?</p> <p>Best regards,Gergely Nagy</p> <pre><code></code></pre> </blockquote> </blockquote> </blockquote> <hr /> <p>openpgp mailing list -- <a href=3D"mailto:[email protected]">openpgp@ietf= .org</a> To unsubscribe send an email to <a href=3D"mailto:[email protected]">o= [email protected]</a></p> <pre><code> > >=20 > > ``` _______________________________________________ > > openpgp mailing list -- [[email protected]](mailto:[email protected]= g) > > To unsubscribe send an email to [[email protected]](mailto:o= [email protected]) </code></pre> <blockquote type=3D"cite"> </blockquote> <pre><code>--=20 </code></pre> <p>MTG AG<br /> Dr. Falko Strenzke</p> <p>Phone: +49 6151 8000 24<br /> E-Mail: <a href=3D"mailto:[email protected]">[email protected]</a><= br /> Web: mtg.de</p> <p>MTG AG - Dolivostr. 11 - 64293 Darmstadt, Germany<br /> Commercial register: HRB 8901<br /> Register Court: Amtsgericht Darmstadt<br /> Management Board: J=C3=BCrgen Ruf (CEO), Tamer Kemer=C3=B6z<br /> Chairman of the Supervisory Board: Dr. Thomas Milde</p> <p>This email may contain confidential and/or privileged information. If yo= u are not the correct recipient or have received this email in error,<br /> please inform the sender immediately and delete this email.Unauthorised cop= ying or distribution of this email is not permitted.</p> <p>Data protection information: Privacy policy</p> --=-wWmc4qGUJcIp4ZG1Mhkm-- --=-T/BS6SbYgjC7ESRG7F5v Content-Type: application/pkcs7-signature; name="smime.p7s" Content-Disposition: attachment; filename="smime.p7s" Content-Transfer-Encoding: base64 MIAGCSqGSIb3DQEHAqCAMIACAQExDzANBglghkgBZQMEAgEFADCABgkqhkiG9w0BBwEAAKCCFaMw ggX1MIIE3aADAgECAhAroJrQUI3BFzEId5iozbOpMA0GCSqGSIb3DQEBCwUAMIGCMQswCQYDVQQG EwJERTErMCkGA1UECgwiVC1TeXN0ZW1zIEVudGVycHJpc2UgU2VydmljZXMgR21iSDEfMB0GA1UE CwwWVC1TeXN0ZW1zIFRydXN0IENlbnRlcjElMCMGA1UEAwwcVC1UZWxlU2VjIEdsb2JhbFJvb3Qg Q2xhc3MgMjAeFw0yMzA2MjAwOTIxNDVaFw0zMzA2MTkyMzU5NTlaMGoxCzAJBgNVBAYTAkRFMScw JQYDVQQKDB5EZXV0c2NoZSBUZWxla29tIFNlY3VyaXR5IEdtYkgxMjAwBgNVBAMMKVRlbGVrb20g U2VjdXJpdHkgQnVzaW5lc3NJRCBTTUlNRSBDQSAyMDIzMIICIjANBgkqhkiG9w0BAQEFAAOCAg8A MIICCgKCAgEAyoz9UVaSMcy4APCm8VWUlWlt53YyshJ+3twBxE0HfwIFJw3dkmK5rGKyYjYvDzag v+b3t/9M0TUDEPnE86Lci+l8rNVYVS2cI4EZ/BYd1A+DhiExZhGynR9J4PRaxFTdQGersTrmCpxP 4XkQkXzO2Yoa40iLGxjvkRRtG5oFBQXErvaxsquqPgdPWpk5on5VfGIbgU6/WH0HzpCmWE/dK+w1 CTWZHtiKcPsDq+Axd1N9v+1CbvDP4FdSA0WoCJILtaTo+WHy3UVTw/WVK/IlF/UN7DmR0xv2S+1j UJ6MgktrLNumbmGMGuE4wFbX95hv0jmQ8FSg1RFa3JdWBJDPLzNx9Zrpuxo6jki6tTS6b/qzpgOh 5Lm9JLI/C27R07Z6oCB/QIOYv0Ns9NiMd/5DcsbOMRrEU03RtDoMGlvdXqZKFwBE2dfW2D/d1ugC niegBOwVKkIWXP4wDJ9FnCgnQKSsf4iFhBTohvON4gcrkTrcFOl+2JUNZIVBPrSL7OMnn/EuAxAH l4IZDHRBd+h3gVBLcGtzcJHD2+eGeiZObyzD3oh8MosycX1rdO+2NyPDXPBWmSPZ9ai9SafT5azN xiudTgfXYurXZJUKE4dcP8dCQoQTHSjK3RlBhL8kFMT2Lz04OZC85CH0iBYl5MG5EbiDL1NTGgcx mgWomhD2Di0CAwEAAaOCAXwwggF4MA4GA1UdDwEB/wQEAwIBBjAdBgNVHQ4EFgQUmAjzq5VeiQ6o DicQgW0Fh3gGx6EwHwYDVR0jBBgwFoAUv1kgNgB5oKAia4zV8mHSuCzLgkowEgYDVR0TAQH/BAgw BgEB/wIBADAdBgNVHSUEFjAUBggrBgEFBQcDAgYIKwYBBQUHAwQwUAYDVR0fBEkwRzBFoEOgQYY/ aHR0cDovL2dyY2wyLmNybC50ZWxlc2VjLmRlL3JsL1QtVGVsZVNlY19HbG9iYWxSb290X0NsYXNz XzIuY3JsMIGNBggrBgEFBQcBAQSBgDB+MC4GCCsGAQUFBzABhiJodHRwOi8vZ3JjbDIub2NzcC50 ZWxlc2VjLmRlL29jc3ByMEwGCCsGAQUFBzAChkBodHRwOi8vZ3JjbDIuY3J0LnRlbGVzZWMuZGUv Y3J0L1QtVGVsZVNlY19HbG9iYWxSb290X0NsYXNzXzIuY3J0MBEGA1UdIAQKMAgwBgYEVR0gADAN BgkqhkiG9w0BAQsFAAOCAQEAYDtthBPLCV2JFK6d//AxLidCeTVjbC4cwZQEDl7k8XfEmeGYeYXf YW/0aziMnOFYulL+MLP2ZxvPG8Dfo/LN7qnOccnfY8sU7+eku1Ih6WIkXZCX9mxwe5BSCbE1M4kw QfGvjEbZxkMEDL0v5hYr67f5V/+AS/YnxdYW6h9+vbUP6n1OkGXNnytZv98/MIDK/fTmPcRogsU4 bOwzzKn1/h+rONAtNkYABYmfc5SZzneqyLcGlGvJgd8piuqXj/0MaDBUZvUfQXNgwxKGEbX1p1/7 WLtYVqUE+e30RQJtwfwCTS8PB78WwODBRQTRjo1LHMz6iGGW40bCpLe/BbRnnzCCB9EwggW5oAMC AQICEAN0/CXGPa9kCnhddoNFf4owDQYJKoZIhvcNAQELBQAwajELMAkGA1UEBhMCREUxJzAlBgNV BAoMHkRldXRzY2hlIFRlbGVrb20gU2VjdXJpdHkgR21iSDEyMDAGA1UEAwwpVGVsZWtvbSBTZWN1 cml0eSBCdXNpbmVzc0lEIFNNSU1FIENBIDIwMjMwHhcNMjUxMTI3MTQyNDIyWhcNMjgwMjI5MjM1 OTU5WjCBmzELMAkGA1UEBhMCREUxDzANBgNVBAoTBk1URyBBRzEXMBUGA1UEAxMORmFsa28gU3Ry ZW56a2UxDjAMBgNVBCoTBUZhbGtvMREwDwYDVQQEEwhTdHJlbnprZTEfMB0GCSqGSIb3DQEJARYQ ZnN0cmVuemtlQG10Zy5kZTEeMBwGA1UEYRMVTlRSREUtREVNMTEwMy5IUkI4OTAxMIICIjANBgkq hkiG9w0BAQEFAAOCAg8AMIICCgKCAgEAtAepqpOmQpJK695PdwwD+tWDCwViGSZ1mffQtikgy3W8 vqb0cHGTX7JqbnN7LilQ6f01ilMV7qDMhaYziM7iDHXnbChGMUgmxXKREIY3/j3zzUNlixIT9FWA fxP7oDdH3LcT8GQkL09twsYK2VuPldAVT+etFqFM6GPmAugXPZ8GF4pRYbZdXHOE1N/0w1WKKLR3 ABWN9MV5x2MhoBuzPrevyWHEPiNCk2S3k/n2U9yFe1k/0oeGg0801hNMdovjOmUBKv3eJFec7e1g KPvo1HPnqBu/qolghhdoEk87ZCg4s18fRUMRYGsP9eP1NpaeHdRKHQNNMTn9hES2BJ4rc14DzJhZ CUyEpCPQbzzcOkmjD8sHMBxdYTAgr2YiQ1eCHabRHUdQu3vOuQwv0hcRx2jD1+AIW9VkZcRfWVxr +bqZklw6jowZD2z+lWINigCMx79nDBRaRL1u47vhhXGGlKinIY5lGG1lzH/76LxvXIOVBS214RAz DoQNl0IOT+YIDa0qP3+JJXz0+NQWnVbdpf5j5JICFfl7bGsYp/zKrCXqZwddz8Nm1/aUHztHhvLi wOTWFPvbYliIy++afAMS7kg/GCMYPCZ7O4GHatl/E9s7UjzkCPYEAbTVelXQAE9lU4xEI2F5uY2W geEnj7FAbyYiRtTgvRnrRIyUweicMV8CAwEAAaOCAj8wggI7MB8GA1UdIwQYMBaAFJgI86uVXokO qA4nEIFtBYd4BsehMB0GA1UdDgQWBBQsFTSrP6hoDUGamae95XeOd3L1SDAOBgNVHQ8BAf8EBAMC BaAwHQYDVR0lBBYwFAYIKwYBBQUHAwIGCCsGAQUFBwMEMFgGA1UdIARRME8wTQYHZ4EMAQUDAjBC MEAGCCsGAQUFBwIBFjRodHRwOi8vZG9jcy5idXNpbmVzc2lkLnRlbGVzZWMuZGUvY3BzL2J1c2lu ZXNzaWQuaHRtMAwGA1UdEwEB/wQCMAAwYgYDVR0fBFswWTBXoFWgU4ZRaHR0cDovL2NybC5idXNp bmVzc2lkLnRlbGVzZWMuZGUvcmwvVGVsZWtvbV9TZWN1cml0eV9CdXNpbmVzc0lEX1NNSU1FX0NB XzIwMjMuY3JsMIGlBggrBgEFBQcBAQSBmDCBlTAzBggrBgEFBQcwAYYnaHR0cDovL29jc3AuYnVz aW5lc3NpZC50ZWxlc2VjLmRlL29jc3ByMF4GCCsGAQUFBzAChlJodHRwOi8vY3J0LmJ1c2luZXNz aWQudGVsZXNlYy5kZS9jcnQvVGVsZWtvbV9TZWN1cml0eV9CdXNpbmVzc0lEX1NNSU1FX0NBXzIw MjMuY3J0MFYGA1UdEQRPME2BEGZzdHJlbnprZUBtdGcuZGWBFWZhbGtvLnN0cmVuemtlQG10Zy5k ZYERZi5zdHJlbnprZUBtdGcuZGWBD3N0cmVuemtlQG10Zy5kZTANBgkqhkiG9w0BAQsFAAOCAgEA indObv5kqnaLMy8strwWR893ZJTUX6mNlOZnzvmE34nTVxrmO0LgC+VrmInYJEiSFTUpB82Dhb4P 9GJ5n0sH9Na0CW4ujfTtoFYoTM4e/CwxvEzXKO8nTZ9fFCNWf2SJ2Elcyeuv5vwDb04WZkrxJcLK WgNnu7RSk1pm0F15aUkHre6t/Sko26fOzIztH6RVjtZAZjt4UWKXUpxdMLfqj+y7qgyVyM/qe158 xb/AfCYgzfbG2iqlN9G+OZ2EgSg4h4PERA5N4in70Ft7Wu0NVrO0mZT1tWqYEm7GGM+yQ7GS2cNH CbVlvYIbLJhocQJ1wx5LHixSTRQvaVSYidmnqYvMEU0iZwIeDoHLKrIRjSdV/ssHwLzoRS1qIfP5 eJPExNG141iju2Th4YaZ9UF5oZ5v27whYk9jPV4sXFE0ZADgGOHG5pJoae8u4c2OIztm6lU+18SS YDQQHlgmjBIO/XWvya/Ps7NSl2Fd2SWV4URfMLPrdXD0QcIeg6nrTRXwKczX/pwpF0Q4Q6cRvMkT oV6Suxc5tfYA3lMFv1Tfz9OEe+hGM7U4dIxPx+qOFF1Hq0f+y2fUF1QSMUko0DJQD5HVoPfYtcf5 2MovV5Cm183u/lfgL/zmP77vjhPg7DpE9bKZ2P8rFdNBme93RVlM/WH3/mTp8nq1KzxuUnI5gyIw ggfRMIIFuaADAgECAhADdPwlxj2vZAp4XXaDRX+KMA0GCSqGSIb3DQEBCwUAMGoxCzAJBgNVBAYT AkRFMScwJQYDVQQKDB5EZXV0c2NoZSBUZWxla29tIFNlY3VyaXR5IEdtYkgxMjAwBgNVBAMMKVRl bGVrb20gU2VjdXJpdHkgQnVzaW5lc3NJRCBTTUlNRSBDQSAyMDIzMB4XDTI1MTEyNzE0MjQyMloX DTI4MDIyOTIzNTk1OVowgZsxCzAJBgNVBAYTAkRFMQ8wDQYDVQQKEwZNVEcgQUcxFzAVBgNVBAMT DkZhbGtvIFN0cmVuemtlMQ4wDAYDVQQqEwVGYWxrbzERMA8GA1UEBBMIU3RyZW56a2UxHzAdBgkq hkiG9w0BCQEWEGZzdHJlbnprZUBtdGcuZGUxHjAcBgNVBGETFU5UUkRFLURFTTExMDMuSFJCODkw MTCCAiIwDQYJKoZIhvcNAQEBBQADggIPADCCAgoCggIBALQHqaqTpkKSSuveT3cMA/rVgwsFYhkm dZn30LYpIMt1vL6m9HBxk1+yam5zey4pUOn9NYpTFe6gzIWmM4jO4gx152woRjFIJsVykRCGN/49 881DZYsSE/RVgH8T+6A3R9y3E/BkJC9PbcLGCtlbj5XQFU/nrRahTOhj5gLoFz2fBheKUWG2XVxz hNTf9MNViii0dwAVjfTFecdjIaAbsz63r8lhxD4jQpNkt5P59lPchXtZP9KHhoNPNNYTTHaL4zpl ASr93iRXnO3tYCj76NRz56gbv6qJYIYXaBJPO2QoOLNfH0VDEWBrD/Xj9TaWnh3USh0DTTE5/YRE tgSeK3NeA8yYWQlMhKQj0G883DpJow/LBzAcXWEwIK9mIkNXgh2m0R1HULt7zrkML9IXEcdow9fg CFvVZGXEX1lca/m6mZJcOo6MGQ9s/pViDYoAjMe/ZwwUWkS9buO74YVxhpSopyGOZRhtZcx/++i8 b1yDlQUtteEQMw6EDZdCDk/mCA2tKj9/iSV89PjUFp1W3aX+Y+SSAhX5e2xrGKf8yqwl6mcHXc/D Ztf2lB87R4by4sDk1hT722JYiMvvmnwDEu5IPxgjGDwmezuBh2rZfxPbO1I85Aj2BAG01XpV0ABP ZVOMRCNhebmNloHhJ4+xQG8mIkbU4L0Z60SMlMHonDFfAgMBAAGjggI/MIICOzAfBgNVHSMEGDAW gBSYCPOrlV6JDqgOJxCBbQWHeAbHoTAdBgNVHQ4EFgQULBU0qz+oaA1BmpmnveV3jndy9UgwDgYD VR0PAQH/BAQDAgWgMB0GA1UdJQQWMBQGCCsGAQUFBwMCBggrBgEFBQcDBDBYBgNVHSAEUTBPME0G B2eBDAEFAwIwQjBABggrBgEFBQcCARY0aHR0cDovL2RvY3MuYnVzaW5lc3NpZC50ZWxlc2VjLmRl L2Nwcy9idXNpbmVzc2lkLmh0bTAMBgNVHRMBAf8EAjAAMGIGA1UdHwRbMFkwV6BVoFOGUWh0dHA6 Ly9jcmwuYnVzaW5lc3NpZC50ZWxlc2VjLmRlL3JsL1RlbGVrb21fU2VjdXJpdHlfQnVzaW5lc3NJ RF9TTUlNRV9DQV8yMDIzLmNybDCBpQYIKwYBBQUHAQEEgZgwgZUwMwYIKwYBBQUHMAGGJ2h0dHA6 Ly9vY3NwLmJ1c2luZXNzaWQudGVsZXNlYy5kZS9vY3NwcjBeBggrBgEFBQcwAoZSaHR0cDovL2Ny dC5idXNpbmVzc2lkLnRlbGVzZWMuZGUvY3J0L1RlbGVrb21fU2VjdXJpdHlfQnVzaW5lc3NJRF9T TUlNRV9DQV8yMDIzLmNydDBWBgNVHREETzBNgRBmc3RyZW56a2VAbXRnLmRlgRVmYWxrby5zdHJl bnprZUBtdGcuZGWBEWYuc3RyZW56a2VAbXRnLmRlgQ9zdHJlbnprZUBtdGcuZGUwDQYJKoZIhvcN AQELBQADggIBAIp3Tm7+ZKp2izMvLLa8FkfPd2SU1F+pjZTmZ875hN+J01ca5jtC4Avla5iJ2CRI khU1KQfNg4W+D/RieZ9LB/TWtAluLo307aBWKEzOHvwsMbxM1yjvJ02fXxQjVn9kidhJXMnrr+b8 A29OFmZK8SXCyloDZ7u0UpNaZtBdeWlJB63urf0pKNunzsyM7R+kVY7WQGY7eFFil1KcXTC36o/s u6oMlcjP6ntefMW/wHwmIM32xtoqpTfRvjmdhIEoOIeDxEQOTeIp+9Bbe1rtDVaztJmU9bVqmBJu xhjPskOxktnDRwm1Zb2CGyyYaHECdcMeSx4sUk0UL2lUmInZp6mLzBFNImcCHg6ByyqyEY0nVf7L B8C86EUtaiHz+XiTxMTRteNYo7tk4eGGmfVBeaGeb9u8IWJPYz1eLFxRNGQA4BjhxuaSaGnvLuHN jiM7ZupVPtfEkmA0EB5YJowSDv11r8mvz7OzUpdhXdklleFEXzCz63Vw9EHCHoOp600V8CnM1/6c KRdEOEOnEbzJE6FekrsXObX2AN5TBb9U38/ThHvoRjO1OHSMT8fqjhRdR6tH/stn1BdUEjFJKNAy UA+R1aD32LXH+djKL1eQptfN7v5X4C/85j++744T4Ow6RPWymdj/KxXTQZnvd0VZTP1h9/5k6fJ6 tSs8blJyOYMiMYIEOjCCBDYCAQEwfjBqMQswCQYDVQQGEwJERTEnMCUGA1UECgweRGV1dHNjaGUg VGVsZWtvbSBTZWN1cml0eSBHbWJIMTIwMAYDVQQDDClUZWxla29tIFNlY3VyaXR5IEJ1c2luZXNz SUQgU01JTUUgQ0EgMjAyMwIQA3T8JcY9r2QKeF12g0V/ijANBglghkgBZQMEAgEFAKCCAY0wGAYJ KoZIhvcNAQkDMQsGCSqGSIb3DQEHATAcBgkqhkiG9w0BCQUxDxcNMjYwNzA3MDUzNjMzWjAvBgkq hkiG9w0BCQQxIgQg830zFBIYwwCBI+faxAobenHWEg6wGKRKhNfn70PKUdAwgY4GCSsGAQQBgjcQ BDGBgDB+MGoxCzAJBgNVBAYTAkRFMScwJQYDVQQKDB5EZXV0c2NoZSBUZWxla29tIFNlY3VyaXR5 IEdtYkgxMjAwBgNVBAMMKVRlbGVrb20gU2VjdXJpdHkgQnVzaW5lc3NJRCBTTUlNRSBDQSAyMDIz AhADdPwlxj2vZAp4XXaDRX+KMIGQBgsqhkiG9w0BCRACCzGBgKB+MGoxCzAJBgNVBAYTAkRFMScw JQYDVQQKDB5EZXV0c2NoZSBUZWxla29tIFNlY3VyaXR5IEdtYkgxMjAwBgNVBAMMKVRlbGVrb20g U2VjdXJpdHkgQnVzaW5lc3NJRCBTTUlNRSBDQSAyMDIzAhADdPwlxj2vZAp4XXaDRX+KMA0GCSqG SIb3DQEBAQUABIICADDzmk0SsGWmgDEfpONZx+nh/KCwxkTye4FS3/qByLeP00sezZUbkWz1t/GL 3NShHftFyUeYC8YD0iWIUBDFI+4APtJfUn2/xn35/ntd3XBjoHuLljWKM3krreZxQkpB3wmzaMBr EvPrCdSBn4ihD/zxOdkW+6uOkCVJpMtdlKkC1GDQwgpXS0guL9YO6NaayEV+NJHQjiI2mEGIYYfD u8VV6oeCBGXRAKdf6FQ1eRfisaSmpRey2NevgtvgpWjifF2ZzmBxbEfcTgABe++89AWVCjnh84tB ZnRNH+sAIGbAd+k8MepsxNFnZPvk/gVmzkJ6e5SOSUeXuttOZxS7r+napVxVp8UFMM9Bn3kbYbiM vgoEnjk8+eudSsXjeJbGdeDs3BipRTgqnMNLn616Je0GJqymns3v8NfTmY+x0OoLhrPVBer4dAMS smKKYu6ggmHhfeMd/HkR+Qtk9+kQMqaxEIV6my97iQCHoaIGy0P9i/wPceX0nuy6gPgGDBAKSrBY KXbSCDM7Mz5SLRzZ1J5WiGsfSB7ouEPMLMz9zni4stXjGsiKWO4cazhhKbqd4xizt+WCzKteLsjC +b3hWfhXBqdHJ1d2Qot8VZoRdkmsUHHlO3M/mqo/lsYvFkWByhprjh53Df7TpCNctM8M6vQq1xJG 1Ei8lsRM22z6etYCAAAAAAAA --=-T/BS6SbYgjC7ESRG7F5v-- --===============8533406413271407222== Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: base64 Content-Disposition: inline X19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX18Kb3BlbnBncCBt YWlsaW5nIGxpc3QgLS0gb3BlbnBncEBpZXRmLm9yZwpUbyB1bnN1YnNjcmliZSBzZW5kIGFuIGVt YWlsIHRvIG9wZW5wZ3AtbGVhdmVAaWV0Zi5vcmcK --===============8533406413271407222==--