[TLS] Re: draft-sheffer-tls-pqc-continuity-02: four commen ts on the client cache rules
Yaron Sheffer <[email protected]> Mon, 3 Aug 2026 22:26:41 +0300
| Newsgroups | gmane.ietf.tls |
|---|---|
| Message-ID | <[email protected]> |
--===============0793069061164351992==
Content-Language: en-US
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: 8bit
<!DOCTYPE html>
<html style="direction: ltr;">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
<style id="bidiui-paragraph-margins" type="text/css">body p { margin-bottom: 0cm; margin-top: 0pt; } </style>
</head>
<body bidimailui-charset-is-forced="true"
bidimailui-detected-decoding-type="UTF-8" style="direction: ltr;">
<p>Hi Nazmus,</p>
<p><br>
</p>
<p>Thank you for your review and the issues you submitted. We will
review and address them shortly.</p>
<p><br>
</p>
<p>Best,</p>
<p> Yaron</p>
<p><br>
</p>
<div class="moz-cite-prefix">On 02/08/2026 7:43, Nazmus Salehin
Sammo wrote:<br>
</div>
<blockquote type="cite"
cite="mid:SEZPR02MB7994150469B3D1468943F4C7A1D62@SEZPR02MB7994.apcprd02.prod.outlook.com">
<meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
<div
style="direction: ltr; text-align: justify; font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
Hi all,</div>
<div
style="direction: ltr; text-align: justify; font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div
style="text-align: justify; font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
I have been doing a formal analysis of the PQ authentication
negotiation</div>
<div
style="text-align: justify; font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
drafts as part of an MRes, and I have read</div>
<div
style="text-align: justify; font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
draft-sheffer-tls-pqc-continuity-02 in full. Four comments on
the</div>
<div
style="text-align: justify; font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
client-side cache rules. All four are filed on the draft's
tracker with</div>
<div
style="text-align: justify; font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
the detail and the suggested text. I am summarising them here
for the</div>
<div
style="text-align: justify; font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
record, rather than starting four threads.</div>
<div
style="direction: ltr; text-align: justify; font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div
style="text-align: justify; font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
1. Resumption is not addressed. [1]</div>
<div
style="direction: ltr; text-align: justify; font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div
style="text-align: justify; font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
Enforcement is anchored entirely on the server Certificate
message</div>
<div
style="text-align: justify; font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
(S3.2: "apply its PQC policy to every CertificateEntry in the</div>
<div
style="text-align: justify; font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
server's Certificate message"). Per RFC 8446 S4.4.2 the
server sends</div>
<div
style="text-align: justify; font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
Certificate for every key exchange method "except PSK", and
S2.2 says</div>
<div
style="text-align: justify; font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
directly that on resumption the server "does not send a
Certificate</div>
<div
style="text-align: justify; font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
or a CertificateVerify message". So on a resumed handshake
that</div>
<div
style="text-align: justify; font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
obligation applies to an empty set. It is satisfied with
nothing to</div>
<div
style="text-align: justify; font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
check, the MUST-abort cannot fire, and the commitment is
never</div>
<div
style="text-align: justify; font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
consulted. Confirmed on OpenSSL 3.6.2 with a genuine
ML-DSA-65 chain:</div>
<div
style="text-align: justify; font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
the resumed handshake completed (Reused, TLSv1.3) with 0
Certificate</div>
<div
style="text-align: justify; font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
and 0 CertificateVerify messages. The draft has no occurrence
of</div>
<div
style="text-align: justify; font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
resumption, PSK, ticket or 0-RTT.</div>
<div
style="direction: ltr; text-align: justify; font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div
style="text-align: justify; font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
RFC 8672 S2, covering the same TLS-layer pinning pattern,
handled</div>
<div
style="text-align: justify; font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
this explicitly: "As a result, PSK handshakes MUST NOT
include the</div>
<div
style="text-align: justify; font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
extension defined here." That reasoning rested on the
misissuance</div>
<div
style="text-align: justify; font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
threat model and does not carry over unchanged to the
undisclosed</div>
<div
style="text-align: justify; font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
CRQC attacker of S1, but it is a ready precedent.
Exploitation is</div>
<div
style="text-align: justify; font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
bounded by the 7-day ticket cap in RFC 8446 S4.6.1. This is
not a</div>
<div
style="text-align: justify; font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
harvest-now, decrypt-later attack and I am not claiming it
is. The</div>
<div
style="text-align: justify; font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
specification gap stands on its own, independent of any
attacker.</div>
<div
style="direction: ltr; text-align: justify; font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div
style="text-align: justify; font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
2. The withdrawal path lacks the condition its own rule 1 has.
[2]</div>
<div
style="direction: ltr; text-align: justify; font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div
style="text-align: justify; font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
S3.6 rule 1 conditions caching on "after the handshake
completes</div>
<div
style="text-align: justify; font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
successfully". Rule 2 conditions clearing only on receiving
the</div>
<div
style="text-align: justify; font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
extension. The suggested fix is one clause, copied from rule
1.</div>
<div
style="direction: ltr; text-align: justify; font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div
style="text-align: justify; font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
Two things to be clear about. First, the condition is not
new:</div>
<div
style="text-align: justify; font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
RFC 6797 S8.1 has gated all HSTS state change, including the</div>
<div
style="text-align: justify; font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
max-age=0 removal, on a clean secure transport since 2012,
and</div>
<div
style="text-align: justify; font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
RFC 7469 S2.3.1 does the same for pin deletion. Since S1 says
this</div>
<div
style="text-align: justify; font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
extension is modelled on HSTS, the honest description is that
the</div>
<div
style="text-align: justify; font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
normative text did not restate a condition the stated model
already</div>
<div
style="text-align: justify; font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
has. Second, the reference implementation already does the
right</div>
<div
style="text-align: justify; font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
thing: it defers both the cache update and the cache delete
to</div>
<div
style="text-align: justify; font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
SSL_CB_HANDSHAKE_DONE behind an X509_V_OK check, and says why
in a</div>
<div
style="text-align: justify; font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
source comment. So there is no exploitable instance that I
know of.</div>
<div
style="text-align: justify; font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
My concern is only that none of that appears in the normative
text,</div>
<div
style="text-align: justify; font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
and a second implementer reading rule 2 literally would be
conformant</div>
<div
style="text-align: justify; font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
without it. S4 of the draft already says the intended thing</div>
<div
style="text-align: justify; font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
non-normatively ("until they observe zero on a completed
handshake"),</div>
<div
style="text-align: justify; font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
which is why I think this is editorial rather than a design
change.</div>
<div
style="direction: ltr; text-align: justify; font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div
style="text-align: justify; font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
3. A question about the port in the cache key. [3]</div>
<div
style="direction: ltr; text-align: justify; font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div
style="text-align: justify; font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
S3.4 keys entries by (RFC 9525 identity, port, TLS/DTLS) and
says</div>
<div
style="text-align: justify; font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
entries differing in any of these MUST NOT be merged, while
the</div>
<div
style="text-align: justify; font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
server's obligation in S3.7 carries no port qualifier and the</div>
<div
style="text-align: justify; font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
reference identity is port-independent. So the client
enforces</div>
<div
style="text-align: justify; font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
something narrower than the server has committed to. I am
asking</div>
<div
style="text-align: justify; font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
rather than asserting: I do not think this is a bypass, since
under</div>
<div
style="text-align: justify; font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
S3.4 no commitment is in force for the key that gets used,
but I also</div>
<div
style="text-align: justify; font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
do not think it is the trust-on-first-use case S5.1
documents, since</div>
<div
style="text-align: justify; font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
S5.1's own justification depends on the client eventually
connecting</div>
<div
style="text-align: justify; font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
directly, which never happens for a port it never uses.
Related: S1</div>
<div
style="text-align: justify; font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
invokes HSTS, but RFC 6797 S8.3 says "the HSTS Policy applies
to HTTP</div>
<div
style="text-align: justify; font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
over any TCP port of an HSTS Host", so the scoping differs
from the</div>
<div
style="text-align: justify; font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
named model. That may be deliberate for DTLS and non-web use.
If so</div>
<div
style="text-align: justify; font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
it would be worth saying.</div>
<div
style="direction: ltr; text-align: justify; font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div
style="text-align: justify; font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
Martin's IETF-126 comments on this cache key not working for</div>
<div
style="text-align: justify; font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
browsers, and on non-uniform multi-CDN deployment, are in the
same</div>
<div
style="text-align: justify; font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
area. I am not claiming new ground there, only asking about
the port</div>
<div
style="text-align: justify; font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
dimension specifically.</div>
<div
style="direction: ltr; text-align: justify; font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div
style="text-align: justify; font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
4. "The port" is not defined. [4]</div>
<div
style="direction: ltr; text-align: justify; font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div
style="text-align: justify; font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
S3.4 does not say whether "the port" is the authority port
from the</div>
<div
style="text-align: justify; font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
URI or the TCP port actually connected to. These differ under
an</div>
<div
style="text-align: justify; font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
HTTPS RR carrying a port SvcParam, where per RFC 9460 S9.1
the origin</div>
<div
style="text-align: justify; font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
does not change. The two readings give opposite answers about
whether</div>
<div
style="text-align: justify; font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
a cached commitment applies, and that decides whether the
scope</div>
<div
style="text-align: justify; font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
question in (3) is reachable at all. Two sentences would fix
it.</div>
<div
style="direction: ltr; text-align: justify; font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div
style="text-align: justify; font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
None of this touches issue #23. I have Tamarin models behind (1)
and</div>
<div
style="text-align: justify; font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
(2) and am happy to share them, with the caveat that they are
models of</div>
<div
style="text-align: justify; font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
the S3.2, S3.5 and S3.6 client state machine, not security
proofs of</div>
<div
style="text-align: justify; font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
TLS 1.3. The OpenSSL result behind (1) is the stronger evidence.</div>
<div
style="direction: ltr; text-align: justify; font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div
style="text-align: justify; font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
Thanks for the draft. Rule 3 of S3.6 and the S4 text made the
first two</div>
<div
style="text-align: justify; font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
of these much easier to pin down than they would otherwise have
been.</div>
<div
style="direction: ltr; text-align: justify; font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div
style="text-align: justify; font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
Nazmus Salehin Sammo</div>
<div
style="text-align: justify; font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
Melbourne Institute of Technology, Melbourne, Australia</div>
<div
style="text-align: justify; font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
Student ID: MIT252100</div>
<div
style="text-align: justify; font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<a class="moz-txt-link-abbreviated" href="mailto:[email protected]">[email protected]</a></div>
<div
style="direction: ltr; text-align: justify; font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div
style="text-align: justify; font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
[1]
<a class="moz-txt-link-freetext" href="https://github.com/yaronf/draft-sheffer-tls-pqc-continuity/issues/29">https://github.com/yaronf/draft-sheffer-tls-pqc-continuity/issues/29</a></div>
<div
style="text-align: justify; font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
[2]
<a class="moz-txt-link-freetext" href="https://github.com/yaronf/draft-sheffer-tls-pqc-continuity/issues/27">https://github.com/yaronf/draft-sheffer-tls-pqc-continuity/issues/27</a></div>
<div
style="text-align: justify; font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
[3]
<a class="moz-txt-link-freetext" href="https://github.com/yaronf/draft-sheffer-tls-pqc-continuity/issues/28">https://github.com/yaronf/draft-sheffer-tls-pqc-continuity/issues/28</a></div>
<div
style="text-align: justify; font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
[4] <a
href="https://github.com/yaronf/draft-sheffer-tls-pqc-continuity/issues/26"
data-outlook-id="e3302138-653d-45d0-b4b5-e310f5596ce0"
moz-do-not-send="true" class="moz-txt-link-freetext">
https://github.com/yaronf/draft-sheffer-tls-pqc-continuity/issues/26</a></div>
<div id="ms-outlook-mobile-signature" dir="ltr"
style="color: inherit; background-color: inherit;">
</div>
<br>
<fieldset class="moz-mime-attachment-header"></fieldset>
<pre wrap="" class="moz-quote-pre">_______________________________________________
TLS mailing list -- <a class="moz-txt-link-abbreviated" href="mailto:[email protected]">[email protected]</a>
To unsubscribe send an email to <a class="moz-txt-link-abbreviated" href="mailto:[email protected]">[email protected]</a>
</pre>
</blockquote>
</body>
</html>
--===============0793069061164351992==
Content-Type: text/plain; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: base64
Content-Disposition: inline
X19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX18KVExTIG1haWxp
bmcgbGlzdCAtLSB0bHNAaWV0Zi5vcmcKVG8gdW5zdWJzY3JpYmUgc2VuZCBhbiBlbWFpbCB0byB0
bHMtbGVhdmVAaWV0Zi5vcmcK
--===============0793069061164351992==--