
From nobody Sat May  3 12:32:12 2014
Return-Path: <mcr@sandelman.ca>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id B4E911A011B for <6tisch-security@ietfa.amsl.com>; Sat,  3 May 2014 12:32:10 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.633
X-Spam-Level: 
X-Spam-Status: No, score=-2.633 tagged_above=-999 required=5 tests=[BAYES_20=-0.001, GB_I_LETTER=-2, RP_MATCHES_RCVD=-0.651, SPF_PASS=-0.001, T_MIME_NO_TEXT=0.01, T_TVD_MIME_NO_HEADERS=0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id ZmgfDGS9q26O for <6tisch-security@ietfa.amsl.com>; Sat,  3 May 2014 12:32:08 -0700 (PDT)
Received: from tuna.sandelman.ca (tuna.sandelman.ca [IPv6:2607:f0b0:f:3::184]) by ietfa.amsl.com (Postfix) with ESMTP id DA7841A011A for <6tisch-security@ietf.org>; Sat,  3 May 2014 12:32:07 -0700 (PDT)
Received: from sandelman.ca (obiwan.sandelman.ca [IPv6:2607:f0b0:f:2::247]) by tuna.sandelman.ca (Postfix) with ESMTP id E857020028; Sat,  3 May 2014 15:33:24 -0400 (EDT)
Received: by sandelman.ca (Postfix, from userid 179) id 0C4AA63ABD; Sat,  3 May 2014 15:32:00 -0400 (EDT)
Received: from sandelman.ca (localhost [127.0.0.1]) by sandelman.ca (Postfix) with ESMTP id E7E5863AB6; Sat,  3 May 2014 15:32:00 -0400 (EDT)
From: Michael Richardson <mcr+ietf@sandelman.ca>
To: tisch-security <6tisch-security@ietf.org>
X-Attribution: mcr
X-Mailer: MH-E 8.2; nmh 1.3-dev; GNU Emacs 23.4.1
X-Face: $\n1pF)h^`}$H>Hk{L"x@)JS7<%Az}5RyS@k9X%29-lHB$Ti.V>2bi.~ehC0; <'$9xN5Ub# z!G,p`nR&p7Fz@^UXIn156S8.~^@MJ*mMsD7=QFeq%AL4m<nPbLgmtKK-5dC@#:k
MIME-Version: 1.0
Content-Type: multipart/signed; boundary="=-=-="; micalg=pgp-sha1; protocol="application/pgp-signature"
Date: Sat, 03 May 2014 15:32:00 -0400
Message-ID: <7591.1399145520@sandelman.ca>
Sender: mcr@sandelman.ca
Archived-At: http://mailarchive.ietf.org/arch/msg/6tisch-security/33NPtj7frbOrpt0JNVzYJzgDmXU
Cc: max pritikin <pritikin@cisco.com>, rgm@htt-consult.com, Michael Behringer <mbehring@cisco.com>
Subject: [6tisch-security] a different explanation of autonomic bootstrap
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sat, 03 May 2014 19:32:10 -0000

--=-=-=


(LookOut, AppleMail and web mail people will need a fixed font to understand this email.
Sorry, if you got pretty proportional wrapped emails, your program violated rfc5822...
Try viewing through the mailarchive link that is now in every email that goes through
ietf.org...)

I think that draft-pritikin-bootstrapping-keyinfrastructures needs to explain things a
bit differently.  I'm not sure if this represents significant "on-the-wire" changes
yet, or just details.

Michael: I'd like to go through this on Monday's call, and I will attempt to prepare
some slides to go with it. Maybe Max would be able to join us?
I also CC'ed Bob Moskovitz of Verizon Business, as he had indicated to me privately
that they were doing extensive use of 802.1AR certificates for deployment of
VoIP phones/systems.

Bob: if you should be available 10am EDT Monday (yeah, that would be first
thing for you, and you might not even read this), you might join our call,
details in next email, but I'll understand if you can not make it.

I think that I am making up something on the operator claiming side of
things; because the IEEE 802.1AR specification does not (unless I missed it)
say anything about how the device is claimed by the network (how it trusts
the network), only how the network trusts the device.  Perhaps there are some
specifications which I've missed, or perhaps some things which are simply unspecified.

I had copied the various steps out of pritikin-bootstrapping document with
the intention of making them more precise in the 6tisch security (creating a
profile), and then found that everything wound up in the first two steps, and
then noticed that there was "Claiming" way at the bottom!!

So clearly, I got something wrong!!!!

Let's start with the diagram mentioned above.
See another email about if we reverse who initiates the TLS.

I'm adding some letters to each arc so that they be mapped back to the steps,
which I show below.

I'm also going to have to add a whole bunch of details, because they matter here,
and I've made this very much (EAP-)TLS specific.  TLS does not send the ClientCertificate
until after the Server has sent it's certificate, which presentes a problem that
I'll explain below.


   +---------+                +----------+                +-----------+
   |  New    |                |          |                |  Factory  |
   | Entity  |                |  Domain  |                |   Cloud   |
   |         |                |          |                |  Service  |
   +---------+                +----------+                +-----------+
       |                           |                            |
       |<-------discovery-(A)----->|                            |
       |-----TLS ClientHello (B)-->|                            |
       |     (802.1AR cred)        |                            |
       |                           |---802.1AR identity(C)----->|
       |                           |---Domain ID--------------->|
       |                           |                    [device belongs]
       |                           |                    [to domain?    ]
       |                           |                            |
       |                           |<---device history log(D)---|
       |                    [ accept device? ]                  |
       |<------ServerHello-(E)-----|                            |
       |                           |------- claim device -(F)-->|
       |                           |                  [update audit log]
       |                           |<----- authz token --(G)----|
       |                           |      (802.1AR cert)        |
       |                           |                            |
       |                  [ still accept device?]               |
       |<----ServerCertificate-(H)-|                            |
       |                           |                            |
  [validate cert chain? (I)]       |                            |
       |                           |                            |
       |---ClientCertificate-(J)-->|                            |
       |                           |                            |
       |                           |                            |
       |----domain enrolment------>|                            |
       |<----domain certificate----|                            |


A  Proxy Discovery (A)
B  TLS ClientHello
   This part has to include two things which are not exactly common TLS.
   1) it must have a TrustedAuthorities (6066) indicating what it's Factor CA
   2) it must include its IDevID somewhere, TBD.

C  (optional) Query to Factory Cloud Service/MASA
D  (optional) reply with device history leading to accept device decision.
E  Domain Auth* server sends ServerHello
   (otherwise, if one does not accept the device, then one sends back
   an error message, which naturally could be forged, so the device
   really takes this a clue to back off a bit, listen some more,
   and try again later)
F  claim device.  The Domain Auth* may need to talk to a cloud
         service in order to get an appropriate certificate issued
         to it.  That also would update the audit log.
G  an appropriate certificate is issues to the Domain Auth*, that
   both identifies the domain owner, and binds the device to that
   domain owner.   This certificate could also be delivered by
   USB key, QR code, etc.
H  the certificate (chain) is sent as the ServerCertificate
   to the device.
I  the device validates the certificate chain.  The device
   has a trusted certificate store which contains the Factory
   CA certificate.  In addition, it has its per-device IDevID
   certificate signed by said Factory CA.

   The device can therefore validate a chain of certificates
   that start at the Vendor Factor CA, and may chain through
   multiple resellers, and finally end with a certificate
   permitting the Domain Owner to claim the device.  It is
   unclear what the subject of each of the certificates in
   the chain is, as each part must in fact list the IDevID
   being claimed.

J  the device, accepting the claim would respond with the
   next step in the TLS protocol, the ClientCertificate
   message, proving the device is in fact the IDevID it claimed
   to be.

Now, the bootstrap process then suggests that using the resulting
secure channel, that a certificate enrollment process (CET) be done.

I feel neither here nor there about that.

PRO:
  - It certainly would shorten then process of authenticating, and 802.1AR
    devices certainly are expected to be able to deal with that.
  - It permits all devices to have a common (short) root, such that
    adjacent devices could in fact authenticate each other easily.
    This very much matters to PCE-less 6top!

CON:
  - it seems like it is a whole chunk of additional infrastructure (operating
    a CA), and I'm afraid that it may scare many off.
  - I'm not sure that running CET over EAP-TLS is such a good idea, fragmentation
    wise.
  - it kinda implies that there may be a  lot more async operations
    during operation, and I think that a very long lived TLS Session Resumption Token,
    (rfc5077), stored into flash on the device is closer to what people
    expect to use.   Given that, one can resume the created TLS session,
    perhaps outside of the EAP-TLS.

--
Michael Richardson <mcr+IETF@sandelman.ca>, Sandelman Software Works
 -= IPv6 IoT consulting =-


--=-=-=
Content-Type: application/pgp-signature

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iQEVAwUBU2U/KYCLcPvd0N1lAQLDfwgAhW98oZSiectiBwtrp4UpaZQsHdVdATSm
tCd0vi4vwVQjE39WozZ1UNUhkCOXlTMAaOGKmZoVYd134q2zCD4Kz1nfw1Sxtfdx
hQ/KbkA3dmPV6BypL/paZO5rCEEYDfRMUcPCeSFE7Ajpy2Z8Cx0p5ovydAnpVpfm
U9iOISLOySqBV4sX+DRM0m/Pmzp6QHRM1FYvTQkpX+Vt0iIGzL3hM9Du2DV0RlDg
LVZlD2JpUIuTCI4i0+RKTw7d5ul4BCoVfY+J6kn2Ax9vHu4bkviR0jrn8XIisjdF
+xOhagPAveUEPgNXY2fGqBv7iAP9yY+rso1CoyHc91B4yJzY5nG/JQ==
=xkIR
-----END PGP SIGNATURE-----
--=-=-=--


From nobody Sun May  4 09:46:10 2014
Return-Path: <mcr@sandelman.ca>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 18CEB1A00E8 for <6tisch-security@ietfa.amsl.com>; Sun,  4 May 2014 09:46:00 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.542
X-Spam-Level: 
X-Spam-Status: No, score=-2.542 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RP_MATCHES_RCVD=-0.651, SPF_PASS=-0.001, T_TVD_MIME_NO_HEADERS=0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id zuEeiC0oG9RP for <6tisch-security@ietfa.amsl.com>; Sun,  4 May 2014 09:45:57 -0700 (PDT)
Received: from tuna.sandelman.ca (tuna.sandelman.ca [209.87.252.184]) by ietfa.amsl.com (Postfix) with ESMTP id CD5A51A00CB for <6tisch-security@ietf.org>; Sun,  4 May 2014 09:45:57 -0700 (PDT)
Received: from sandelman.ca (obiwan.sandelman.ca [IPv6:2607:f0b0:f:2::247]) by tuna.sandelman.ca (Postfix) with ESMTP id 1481820028; Sun,  4 May 2014 12:47:17 -0400 (EDT)
Received: by sandelman.ca (Postfix, from userid 179) id 1FFF763ABD; Sun,  4 May 2014 12:45:53 -0400 (EDT)
Received: from sandelman.ca (localhost [127.0.0.1]) by sandelman.ca (Postfix) with ESMTP id 0C7B963AB6; Sun,  4 May 2014 12:45:53 -0400 (EDT)
From: Michael Richardson <mcr+ietf@sandelman.ca>
to: tisch-security <6tisch-security@ietf.org>, rgm@htt-consult.com, Michael Behringer <mbehring@cisco.com>, max pritikin <pritikin@cisco.com>
In-Reply-To: <7591.1399145520@sandelman.ca>
References: <7591.1399145520@sandelman.ca>
X-Mailer: MH-E 8.2; nmh 1.3-dev; GNU Emacs 23.4.1
X-Face: $\n1pF)h^`}$H>Hk{L"x@)JS7<%Az}5RyS@k9X%29-lHB$Ti.V>2bi.~ehC0; <'$9xN5Ub# z!G,p`nR&p7Fz@^UXIn156S8.~^@MJ*mMsD7=QFeq%AL4m<nPbLgmtKK-5dC@#:k
MIME-Version: 1.0
Content-Type: multipart/signed; boundary="=-=-="; micalg=pgp-sha1; protocol="application/pgp-signature"
Date: Sun, 04 May 2014 12:45:53 -0400
Message-ID: <10913.1399221953@sandelman.ca>
Sender: mcr@sandelman.ca
Archived-At: http://mailarchive.ietf.org/arch/msg/6tisch-security/3Nvk0138XOxCJFI61qWH0uMDjU8
Subject: Re: [6tisch-security] a different explanation of autonomic bootstrap
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sun, 04 May 2014 16:46:00 -0000

--=-=-=


So I ask Google for:
   example of 802.1AR certificate

and the first three hits are my draft where I have an empty box.

--
Michael Richardson <mcr+IETF@sandelman.ca>, Sandelman Software Works
 -= IPv6 IoT consulting =-




--=-=-=
Content-Type: application/pgp-signature

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iQEVAwUBU2ZuwICLcPvd0N1lAQIbrQf/cbj0ocnQCpHM1Ka6C2ydTVr+JTsrW29H
FVaT5VEnZVt1QB7W3w+puRVSMZfeT5PeidfEXkrCPwV6qgL5DToVoY+/eaNeLfhm
CzFOOGrzIORwIG12Ezy8FyyOzdh8EyrjntE6z50Gnc0EomgKvI8NJ26dQqnUwG5G
CwwLeE0cOKvEnzVA+Y49IfLNrZmgtOnApmKPB6/j3MXoEs3ffzTVKRIodCKP2XLh
Pz46eqSsbOgrq2uamirLRBTi4fVRgDLL/qoXq7ounuKdzJWbySFm01BaVUkKfSIU
YFDImj4DYsjmrocsG4WRGh4uSXAYPaTno7MnUUP7QtdhsAkYvyGSBA==
=K2/e
-----END PGP SIGNATURE-----
--=-=-=--


From nobody Sun May  4 12:36:07 2014
Return-Path: <rgm@htt-consult.com>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id BE8F51A0144 for <6tisch-security@ietfa.amsl.com>; Sat,  3 May 2014 20:59:36 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.551
X-Spam-Level: 
X-Spam-Status: No, score=-4.551 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, GB_I_LETTER=-2, RP_MATCHES_RCVD=-0.651] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id wdqaVEJLOmCK for <6tisch-security@ietfa.amsl.com>; Sat,  3 May 2014 20:59:35 -0700 (PDT)
Received: from klovia.htt-consult.com (klovia.htt-consult.com [IPv6:2607:f4b8:3:0:218:71ff:fe83:66b9]) by ietfa.amsl.com (Postfix) with ESMTP id AC5C71A0140 for <6tisch-security@ietf.org>; Sat,  3 May 2014 20:59:34 -0700 (PDT)
Received: from localhost (unknown [127.0.0.1]) by klovia.htt-consult.com (Postfix) with ESMTP id 2009462AB1; Sun,  4 May 2014 03:59:31 +0000 (UTC)
X-Virus-Scanned: amavisd-new at localhost
Received: from klovia.htt-consult.com ([127.0.0.1]) by localhost (klovia.htt-consult.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 6-0zMGgQK+I2; Sat,  3 May 2014 23:59:16 -0400 (EDT)
Received: from lx120e.htt-consult.com (lx120e2.htt-consult.com [208.83.67.155]) (Authenticated sender: rgm@htt-consult.com) by klovia.htt-consult.com (Postfix) with ESMTPSA id C07F062AA7; Sat,  3 May 2014 23:59:15 -0400 (EDT)
Message-ID: <5365BB13.50201@htt-consult.com>
Date: Sat, 03 May 2014 23:59:15 -0400
From: Robert Moskowitz <rgm@htt-consult.com>
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:24.0) Gecko/20100101 Thunderbird/24.4.0
MIME-Version: 1.0
To: Michael Richardson <mcr+ietf@sandelman.ca>,  tisch-security <6tisch-security@ietf.org>
References: <7591.1399145520@sandelman.ca>
In-Reply-To: <7591.1399145520@sandelman.ca>
Content-Type: text/plain; charset=ISO-8859-1; format=flowed
Content-Transfer-Encoding: 7bit
Archived-At: http://mailarchive.ietf.org/arch/msg/6tisch-security/owdvX2w8vDEPa8Y8WKrhGffQATI
X-Mailman-Approved-At: Sun, 04 May 2014 12:36:05 -0700
Cc: max pritikin <pritikin@cisco.com>, Michael Behringer <mbehring@cisco.com>
Subject: Re: [6tisch-security] a different explanation of autonomic bootstrap
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sun, 04 May 2014 03:59:37 -0000

Quick response.

If I get a few reports written, I am available.  I have 3 calls monday 
afternoon.  I can't even read this until I get 3 more reports written (3 
down, 3 to go).  And one of them I am recommending 802.1AR as the 
deployment model.  It is NOT VoIP; it is big. Another is HIP's HITs and 
it is also big.  Each have their place in the scheme of things.  Another 
is totally 'off the wall', due to some interesting constraints and 
require some original thinking. ARGH!!!! :)

On 05/03/2014 03:32 PM, Michael Richardson wrote:
> (LookOut, AppleMail and web mail people will need a fixed font to understand this email.
> Sorry, if you got pretty proportional wrapped emails, your program violated rfc5822...
> Try viewing through the mailarchive link that is now in every email that goes through
> ietf.org...)
>
> I think that draft-pritikin-bootstrapping-keyinfrastructures needs to explain things a
> bit differently.  I'm not sure if this represents significant "on-the-wire" changes
> yet, or just details.
>
> Michael: I'd like to go through this on Monday's call, and I will attempt to prepare
> some slides to go with it. Maybe Max would be able to join us?
> I also CC'ed Bob Moskovitz of Verizon Business, as he had indicated to me privately
> that they were doing extensive use of 802.1AR certificates for deployment of
> VoIP phones/systems.
>
> Bob: if you should be available 10am EDT Monday (yeah, that would be first
> thing for you, and you might not even read this), you might join our call,
> details in next email, but I'll understand if you can not make it.
>
> I think that I am making up something on the operator claiming side of
> things; because the IEEE 802.1AR specification does not (unless I missed it)
> say anything about how the device is claimed by the network (how it trusts
> the network), only how the network trusts the device.  Perhaps there are some
> specifications which I've missed, or perhaps some things which are simply unspecified.
>
> I had copied the various steps out of pritikin-bootstrapping document with
> the intention of making them more precise in the 6tisch security (creating a
> profile), and then found that everything wound up in the first two steps, and
> then noticed that there was "Claiming" way at the bottom!!
>
> So clearly, I got something wrong!!!!
>
> Let's start with the diagram mentioned above.
> See another email about if we reverse who initiates the TLS.
>
> I'm adding some letters to each arc so that they be mapped back to the steps,
> which I show below.
>
> I'm also going to have to add a whole bunch of details, because they matter here,
> and I've made this very much (EAP-)TLS specific.  TLS does not send the ClientCertificate
> until after the Server has sent it's certificate, which presentes a problem that
> I'll explain below.
>
>
>     +---------+                +----------+                +-----------+
>     |  New    |                |          |                |  Factory  |
>     | Entity  |                |  Domain  |                |   Cloud   |
>     |         |                |          |                |  Service  |
>     +---------+                +----------+                +-----------+
>         |                           |                            |
>         |<-------discovery-(A)----->|                            |
>         |-----TLS ClientHello (B)-->|                            |
>         |     (802.1AR cred)        |                            |
>         |                           |---802.1AR identity(C)----->|
>         |                           |---Domain ID--------------->|
>         |                           |                    [device belongs]
>         |                           |                    [to domain?    ]
>         |                           |                            |
>         |                           |<---device history log(D)---|
>         |                    [ accept device? ]                  |
>         |<------ServerHello-(E)-----|                            |
>         |                           |------- claim device -(F)-->|
>         |                           |                  [update audit log]
>         |                           |<----- authz token --(G)----|
>         |                           |      (802.1AR cert)        |
>         |                           |                            |
>         |                  [ still accept device?]               |
>         |<----ServerCertificate-(H)-|                            |
>         |                           |                            |
>    [validate cert chain? (I)]       |                            |
>         |                           |                            |
>         |---ClientCertificate-(J)-->|                            |
>         |                           |                            |
>         |                           |                            |
>         |----domain enrolment------>|                            |
>         |<----domain certificate----|                            |
>
>
> A  Proxy Discovery (A)
> B  TLS ClientHello
>     This part has to include two things which are not exactly common TLS.
>     1) it must have a TrustedAuthorities (6066) indicating what it's Factor CA
>     2) it must include its IDevID somewhere, TBD.
>
> C  (optional) Query to Factory Cloud Service/MASA
> D  (optional) reply with device history leading to accept device decision.
> E  Domain Auth* server sends ServerHello
>     (otherwise, if one does not accept the device, then one sends back
>     an error message, which naturally could be forged, so the device
>     really takes this a clue to back off a bit, listen some more,
>     and try again later)
> F  claim device.  The Domain Auth* may need to talk to a cloud
>           service in order to get an appropriate certificate issued
>           to it.  That also would update the audit log.
> G  an appropriate certificate is issues to the Domain Auth*, that
>     both identifies the domain owner, and binds the device to that
>     domain owner.   This certificate could also be delivered by
>     USB key, QR code, etc.
> H  the certificate (chain) is sent as the ServerCertificate
>     to the device.
> I  the device validates the certificate chain.  The device
>     has a trusted certificate store which contains the Factory
>     CA certificate.  In addition, it has its per-device IDevID
>     certificate signed by said Factory CA.
>
>     The device can therefore validate a chain of certificates
>     that start at the Vendor Factor CA, and may chain through
>     multiple resellers, and finally end with a certificate
>     permitting the Domain Owner to claim the device.  It is
>     unclear what the subject of each of the certificates in
>     the chain is, as each part must in fact list the IDevID
>     being claimed.
>
> J  the device, accepting the claim would respond with the
>     next step in the TLS protocol, the ClientCertificate
>     message, proving the device is in fact the IDevID it claimed
>     to be.
>
> Now, the bootstrap process then suggests that using the resulting
> secure channel, that a certificate enrollment process (CET) be done.
>
> I feel neither here nor there about that.
>
> PRO:
>    - It certainly would shorten then process of authenticating, and 802.1AR
>      devices certainly are expected to be able to deal with that.
>    - It permits all devices to have a common (short) root, such that
>      adjacent devices could in fact authenticate each other easily.
>      This very much matters to PCE-less 6top!
>
> CON:
>    - it seems like it is a whole chunk of additional infrastructure (operating
>      a CA), and I'm afraid that it may scare many off.
>    - I'm not sure that running CET over EAP-TLS is such a good idea, fragmentation
>      wise.
>    - it kinda implies that there may be a  lot more async operations
>      during operation, and I think that a very long lived TLS Session Resumption Token,
>      (rfc5077), stored into flash on the device is closer to what people
>      expect to use.   Given that, one can resume the created TLS session,
>      perhaps outside of the EAP-TLS.
>
> --
> Michael Richardson <mcr+IETF@sandelman.ca>, Sandelman Software Works
>   -= IPv6 IoT consulting =-
>


From nobody Sun May  4 19:06:40 2014
Return-Path: <mcr@sandelman.ca>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id BA7841A01FA for <6tisch-security@ietfa.amsl.com>; Sun,  4 May 2014 19:06:38 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.541
X-Spam-Level: 
X-Spam-Status: No, score=-2.541 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RP_MATCHES_RCVD=-0.651, SPF_PASS=-0.001, T_TVD_MIME_NO_HEADERS=0.01, WEIRD_PORT=0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id iVOY16UZVssY for <6tisch-security@ietfa.amsl.com>; Sun,  4 May 2014 19:06:37 -0700 (PDT)
Received: from tuna.sandelman.ca (tuna.sandelman.ca [209.87.252.184]) by ietfa.amsl.com (Postfix) with ESMTP id E83D61A014C for <6tisch-security@ietf.org>; Sun,  4 May 2014 19:06:36 -0700 (PDT)
Received: from sandelman.ca (obiwan.sandelman.ca [IPv6:2607:f0b0:f:2::247]) by tuna.sandelman.ca (Postfix) with ESMTP id 13B0920030 for <6tisch-security@ietf.org>; Sun,  4 May 2014 22:07:56 -0400 (EDT)
Received: by sandelman.ca (Postfix, from userid 179) id A5C7563ABF; Sun,  4 May 2014 22:06:27 -0400 (EDT)
Received: from sandelman.ca (localhost [127.0.0.1]) by sandelman.ca (Postfix) with ESMTP id 9355763AA2 for <6tisch-security@ietf.org>; Sun,  4 May 2014 22:06:27 -0400 (EDT)
From: Michael Richardson <mcr+ietf@sandelman.ca>
to: 6tisch-security@ietf.org
In-Reply-To: <28192.1398644294@sandelman.ca>
References: <E045AECD98228444A58C61C200AE1BD8416F3AF4@xmb-rcd-x01.cisco.com> <bomn1n01Q3zUFux01ompsd> <531DD632.2060009@cox.net> <531DDB20.5050600@gmail.com> <10925.1394631496@sandelman.ca> <532069C8.2050005@gmail.com> <23590.1394999032@sandelman.ca> <18106.1395625035@sandelman.ca> <19609.1396839403@sandelman.ca> <11557.1397444260@sandelman.ca> <28192.1398644294@sandelman.ca>
X-Mailer: MH-E 8.2; nmh 1.3-dev; GNU Emacs 23.4.1
X-Face: $\n1pF)h^`}$H>Hk{L"x@)JS7<%Az}5RyS@k9X%29-lHB$Ti.V>2bi.~ehC0; <'$9xN5Ub# z!G,p`nR&p7Fz@^UXIn156S8.~^@MJ*mMsD7=QFeq%AL4m<nPbLgmtKK-5dC@#:k
MIME-Version: 1.0
Content-Type: multipart/signed; boundary="=-=-="; micalg=pgp-sha1; protocol="application/pgp-signature"
Date: Sun, 04 May 2014 22:06:27 -0400
Message-ID: <29064.1399255587@sandelman.ca>
Sender: mcr@sandelman.ca
Archived-At: http://mailarchive.ietf.org/arch/msg/6tisch-security/m8smnAL0lQVgNBX9ATH8iWTcjAU
Subject: [6tisch-security] agenda for 2014-05-05 6tisch security call
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 05 May 2014 02:06:38 -0000

--=-=-=


Agenda.

1) notewell.
2) intros
3) pritikin-bootstrapping/autonomic vs EAP-TLS vs 6top/COAP/DTLS.
4) if possible, how is 802.1AR being used in the VoIP space.

-- remember that the call is recorded, and the NoteWell applies.

-- The URL to access the webex, which will we use for audio only:
  https://cisco.webex.com/cisco/j.php?MTID=m2fe139bf876cea3ec62750cd580b7908

-- we will resume with the etherpad at:
   http://etherpad.tools.ietf.org:9000/p/notes-ietf-89-6tisch-security

I'm at +1 613 276-6809, IM: mcr@xmpp.credil.org or mcharlesr@gmail.com,
if you need more than that to get in, or are having difficulties.
Please make sure your audio works, and that you mute when not talking.

--
Michael Richardson <mcr+IETF@sandelman.ca>, Sandelman Software Works
 -= IPv6 IoT consulting =-




--=-=-=
Content-Type: application/pgp-signature

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iQEVAwUBU2byI4CLcPvd0N1lAQK8tQgAtPnBkHWaBnv/cbqjUoLdehDg/P9PF3xF
zUK2WdS/7Agi0ul+v/1bCUU54hON94uI+VekacvAatRsHYIa9C2szjZG8zg0PX4L
xHCWbF1QmNKaqbGCEDxYaI2qZoo+zQB4WRX1R2Iw493KL2YYAvb6EthKUNQA6/rL
j2/tRbQ6T/153guq7bjVywdzqqjvfZm6T1SMZLshD1o2AcvmnErMD9/NKZL28U5+
v7uRpBKcZjV7dSM4vaICtow5YUx+S6filU8hN5wRMXUzYEFuaA44RMvEmEnwakWY
5QFHRZVB9unGZ7G4RuhMiU+5suyO/a0J0E8hKEXKa+Or03VEiEpmNQ==
=IfB4
-----END PGP SIGNATURE-----
--=-=-=--


From nobody Mon May  5 06:32:16 2014
Return-Path: <rgm@htt-consult.com>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 5F5451A0329 for <6tisch-security@ietfa.amsl.com>; Mon,  5 May 2014 06:32:16 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.55
X-Spam-Level: 
X-Spam-Status: No, score=-2.55 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RP_MATCHES_RCVD=-0.651, WEIRD_PORT=0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id NQbtzRKXGLwJ for <6tisch-security@ietfa.amsl.com>; Mon,  5 May 2014 06:32:14 -0700 (PDT)
Received: from klovia.htt-consult.com (klovia.htt-consult.com [IPv6:2607:f4b8:3:0:218:71ff:fe83:66b9]) by ietfa.amsl.com (Postfix) with ESMTP id BAA071A0326 for <6tisch-security@ietf.org>; Mon,  5 May 2014 06:32:14 -0700 (PDT)
Received: from localhost (unknown [127.0.0.1]) by klovia.htt-consult.com (Postfix) with ESMTP id D389A62C1A; Mon,  5 May 2014 13:32:10 +0000 (UTC)
X-Virus-Scanned: amavisd-new at localhost
Received: from klovia.htt-consult.com ([127.0.0.1]) by localhost (klovia.htt-consult.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id EsQSM-9WJCSx; Mon,  5 May 2014 09:32:00 -0400 (EDT)
Received: from lx120e.htt-consult.com (lx120e2.htt-consult.com [208.83.67.155]) (Authenticated sender: rgm@htt-consult.com) by klovia.htt-consult.com (Postfix) with ESMTPSA id 3157D62A78; Mon,  5 May 2014 09:32:00 -0400 (EDT)
Message-ID: <536792CF.3090307@htt-consult.com>
Date: Mon, 05 May 2014 09:31:59 -0400
From: Robert Moskowitz <rgm@htt-consult.com>
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:24.0) Gecko/20100101 Thunderbird/24.4.0
MIME-Version: 1.0
To: Michael Richardson <mcr+ietf@sandelman.ca>, 6tisch-security@ietf.org
References: <E045AECD98228444A58C61C200AE1BD8416F3AF4@xmb-rcd-x01.cisco.com> <bomn1n01Q3zUFux01ompsd> <531DD632.2060009@cox.net> <531DDB20.5050600@gmail.com> <10925.1394631496@sandelman.ca> <532069C8.2050005@gmail.com> <23590.1394999032@sandelman.ca> <18106.1395625035@sandelman.ca> <19609.1396839403@sandelman.ca> <11557.1397444260@sandelman.ca> <28192.1398644294@sandelman.ca> <29064.1399255587@sandelman.ca>
In-Reply-To: <29064.1399255587@sandelman.ca>
Content-Type: text/plain; charset=ISO-8859-1; format=flowed
Content-Transfer-Encoding: 7bit
Archived-At: http://mailarchive.ietf.org/arch/msg/6tisch-security/_ibGW9q0uZijholl5SAavfceUgE
Subject: Re: [6tisch-security] agenda for 2014-05-05 6tisch security call
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 05 May 2014 13:32:16 -0000

On 05/04/2014 10:06 PM, Michael Richardson wrote:
> Agenda.
>
> 1) notewell.
> 2) intros
> 3) pritikin-bootstrapping/autonomic vs EAP-TLS vs 6top/COAP/DTLS.
> 4) if possible, how is 802.1AR being used in the VoIP space.
>
> -- remember that the call is recorded, and the NoteWell applies.
>
> -- The URL to access the webex, which will we use for audio only:
>    https://cisco.webex.com/cisco/j.php?MTID=m2fe139bf876cea3ec62750cd580b7908

I will most likely not be talking.  As I have really not set up my corp 
system for miking.  And I have to go through the corp VPN for it.  My 
Fedora system has grief with WebEx.  There has been a discussion on how 
to get WebEx working on the Fedora list, but I just don't have the time.

>
> -- we will resume with the etherpad at:
>     http://etherpad.tools.ietf.org:9000/p/notes-ietf-89-6tisch-security
>
> I'm at +1 613 276-6809, IM: mcr@xmpp.credil.org or mcharlesr@gmail.com,
> if you need more than that to get in, or are having difficulties.
> Please make sure your audio works, and that you mute when not talking.
>
> --
> Michael Richardson <mcr+IETF@sandelman.ca>, Sandelman Software Works
>   -= IPv6 IoT consulting =-
>
>
>


From nobody Mon May  5 08:27:16 2014
Return-Path: <rstruik.ext@gmail.com>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 232B71A00B8 for <6tisch-security@ietfa.amsl.com>; Mon,  5 May 2014 08:27:13 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -0.998
X-Spam-Level: 
X-Spam-Status: No, score=-0.998 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, FREEMAIL_REPLY=1, HTML_MESSAGE=0.001, SPF_PASS=-0.001, WEIRD_PORT=0.001] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id DP_y5XDImQEe for <6tisch-security@ietfa.amsl.com>; Mon,  5 May 2014 08:27:07 -0700 (PDT)
Received: from mail-ig0-x231.google.com (mail-ig0-x231.google.com [IPv6:2607:f8b0:4001:c05::231]) by ietfa.amsl.com (Postfix) with ESMTP id 5886B1A03A1 for <6tisch-security@ietf.org>; Mon,  5 May 2014 08:27:07 -0700 (PDT)
Received: by mail-ig0-f177.google.com with SMTP id l13so2423011iga.4 for <6tisch-security@ietf.org>; Mon, 05 May 2014 08:27:03 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113;  h=message-id:date:from:user-agent:mime-version:to:subject:references :in-reply-to:content-type; bh=oAGDPVhP4ovpsNqwv2Cs7IB/PZdynZYYTgl3JNFvMOU=; b=Lz8RdvcDvmFO6nUsQ4rpTU5M/K+BRaCSX6KCajDbxr/PqQOG5u6yOHzrFoaE/cw8NS 2JQQ1d8g3Is1z5Z9X5mmtkJEaORhmRT2OoSwoYsyBCcbBPjCWeIRqRRtCw/FrWq44hv1 hPHo5WRAIZbbfSM6MM/COJiRS01YvpCZcMTGbBvVwpcODtFJP8n6vznVWBazT/XG3OGp yaNL1c9RfZEMiU2XcD2IKHexF9IXRtOhNPoUjRiQy3tl8XIY12KOhjNyvK2y+7z+9n+5 DaNSjTpgdKYV8sTEmMo1Z1tls1jreuI9OK084gYiv1d70Dy/BhQkO1hhXm4zc+rmxA4F RiLQ==
X-Received: by 10.42.50.3 with SMTP id y3mr34020659icf.12.1399303623818; Mon, 05 May 2014 08:27:03 -0700 (PDT)
Received: from [192.168.1.103] (CPE0013100e2c51-CM001cea35caa6.cpe.net.cable.rogers.com. [99.231.3.110]) by mx.google.com with ESMTPSA id u2sm359133igs.10.2014.05.05.08.27.01 for <multiple recipients> (version=TLSv1 cipher=ECDHE-RSA-RC4-SHA bits=128/128); Mon, 05 May 2014 08:27:02 -0700 (PDT)
Message-ID: <5367ADC1.8090907@gmail.com>
Date: Mon, 05 May 2014 11:26:57 -0400
From: Rene Struik <rstruik.ext@gmail.com>
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:24.0) Gecko/20100101 Thunderbird/24.5.0
MIME-Version: 1.0
To: Michael Richardson <mcr+ietf@sandelman.ca>, 6tisch-security@ietf.org
References: <E045AECD98228444A58C61C200AE1BD8416F3AF4@xmb-rcd-x01.cisco.com> <bomn1n01Q3zUFux01ompsd> <531DD632.2060009@cox.net> <531DDB20.5050600@gmail.com> <10925.1394631496@sandelman.ca> <532069C8.2050005@gmail.com> <23590.1394999032@sandelman.ca> <18106.1395625035@sandelman.ca> <19609.1396839403@sandelman.ca> <11557.1397444260@sandelman.ca> <28192.1398644294@sandelman.ca> <29064.1399255587@sandelman.ca>
In-Reply-To: <29064.1399255587@sandelman.ca>
Content-Type: multipart/alternative; boundary="------------000903010703020902080804"
Archived-At: http://mailarchive.ietf.org/arch/msg/6tisch-security/nRN2oQAugzG-Ob3pjbyDfd4NhCI
Subject: Re: [6tisch-security] agenda for 2014-05-05 6tisch security call
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 05 May 2014 15:27:13 -0000

This is a multi-part message in MIME format.
--------------000903010703020902080804
Content-Type: text/plain; charset=ISO-8859-1; format=flowed
Content-Transfer-Encoding: 7bit

Dear colleagues:

During the 6tisch security conf call today, discussion referenced the 
notion of "domain". Somewhat unfortunately, the diagrams referred to 
communications between a new entity and the domain, whereas in real life 
communications is between devices (i.e., between a new entity and 
another network node [who may be a representative of a domain]).

It seems to be useful to define the notion of domain somewhat more 
precisely. One can imagine various levels of granularity:
a) universe: in this case, the new entity would accept to become part of 
any network.
b) single PAN: in this case, the new entity would accept to become part 
of the specific PAN that is singled out here. {This also means that if a 
device moves from one PAN to another one, e.g., in the same 
manufacturing plant, it has to get another "domain cert"}.
c) bunch of PANs: in this case the new entity would accept to become 
part of any PAN that is in the "bunch of PANs" list.

In all cases, the "domain" notion captures an element that is used for 
authorization and not authentication.

Now for a thought experiment:
a) provisioning step. Suppose one has a single global CA for which the 
public key Q_{CA} is embedded with every device during manufacturing.
b) authentication step. Now, any successful execution of an 
authenticated key agreement scheme where devices present certs vouched 
for by that single CA will result in mutual authentication between the 
new entity and any network representative.
c) authorization step. More fine-grained access control could depend on 
new entity or network representative having configuration settings that 
allow further filtering (e.g., network representative has access control 
list where new entity shows up as a member (and may inquire with third 
party authorization device if new entity does not show up on this list, 
in which case third party could  trigger update of this access control 
list/configuration setting).

Some of this may be intertwined in message flows. However, 
authentication can be done locally (if devices have each others' root CA 
key) and only authorization may involve third party that my be somewhere 
many hops away in the cloud. Here, one should note that the 
authentication flows and authorization flows do not necessarily create 
hierarchical flow dependencies.

Wouldn't this be simpler?

As a final note: TLS does not have message elements that can carry 
authorization tokens (the protocol data elements are simply not there). 
So, any protocol that may rely on carrying "piggy-backed data" cannot 
possibly be mapped to TLS (or DTLS for that matter). Hence, my email 
question a few weeks ago (April 10, 2014, 11:37am EDT) on "TLS/DTLS 
piggy-backing".



On 5/4/2014 10:06 PM, Michael Richardson wrote:
> Agenda.
>
> 1) notewell.
> 2) intros
> 3) pritikin-bootstrapping/autonomic vs EAP-TLS vs 6top/COAP/DTLS.
> 4) if possible, how is 802.1AR being used in the VoIP space.
>
> -- remember that the call is recorded, and the NoteWell applies.
>
> -- The URL to access the webex, which will we use for audio only:
>    https://cisco.webex.com/cisco/j.php?MTID=m2fe139bf876cea3ec62750cd580b7908
>
> -- we will resume with the etherpad at:
>     http://etherpad.tools.ietf.org:9000/p/notes-ietf-89-6tisch-security
>
> I'm at +1 613 276-6809, IM: mcr@xmpp.credil.org or mcharlesr@gmail.com,
> if you need more than that to get in, or are having difficulties.
> Please make sure your audio works, and that you mute when not talking.
>
> --
> Michael Richardson <mcr+IETF@sandelman.ca>, Sandelman Software Works
>   -= IPv6 IoT consulting =-
>
>
>
>
>
> _______________________________________________
> 6tisch-security mailing list
> 6tisch-security@ietf.org
> https://www.ietf.org/mailman/listinfo/6tisch-security


-- 
email: rstruik.ext@gmail.com | Skype: rstruik
cell: +1 (647) 867-5658 | US: +1 (415) 690-7363


--------------000903010703020902080804
Content-Type: text/html; charset=ISO-8859-1
Content-Transfer-Encoding: 7bit

<html>
  <head>
    <meta content="text/html; charset=ISO-8859-1"
      http-equiv="Content-Type">
  </head>
  <body bgcolor="#FFFFFF" text="#000000">
    <div class="moz-cite-prefix">Dear colleagues:<br>
      <br>
      During the 6tisch security conf call today, discussion referenced
      the notion of "domain". Somewhat unfortunately, the diagrams
      referred to communications between a new entity and the domain,
      whereas in real life communications is between devices (i.e.,
      between a new entity and another network node [who may be a
      representative of a domain]).<br>
      <br>
      It seems to be useful to define the notion of domain somewhat more
      precisely. One can imagine various levels of granularity:<br>
      a) universe: in this case, the new entity would accept to become
      part of any network.<br>
      b) single PAN: in this case, the new entity would accept to become
      part of the specific PAN that is singled out here. {This also
      means that if a device moves from one PAN to another one, e.g., in
      the same manufacturing plant, it has to get another "domain
      cert"}.<br>
      c) bunch of PANs: in this case the new entity would accept to
      become part of any PAN that is in the "bunch of PANs" list.<br>
      <br>
      In all cases, the "domain" notion captures an element that is used
      for authorization and not authentication.<br>
      <br>
      Now for a thought experiment:<br>
      a) provisioning step. Suppose one has a single global CA for which
      the public key Q_{CA} is embedded with every device during
      manufacturing.<br>
      b) authentication step. Now, any successful execution of an
      authenticated key agreement scheme where devices present certs
      vouched for by that single CA will result in mutual authentication
      between the new entity and any network representative. <br>
      c) authorization step. More fine-grained access control could
      depend on new entity or network representative having
      configuration settings that allow further filtering (e.g., network
      representative has access control list where new entity shows up
      as a member (and may inquire with third party authorization device
      if new entity does not show up on this list, in which case third
      party could&nbsp; trigger update of this access control
      list/configuration setting).<br>
      <br>
      Some of this may be intertwined in message flows. However,
      authentication can be done locally (if devices have each others'
      root CA key) and only authorization may involve third party that
      my be somewhere many hops away in the cloud. Here, one should note
      that the authentication flows and authorization flows do not
      necessarily create hierarchical flow dependencies.<br>
      <br>
      Wouldn't this be simpler?<br>
      <br>
      As a final note: TLS does not have message elements that can carry
      authorization tokens (the protocol data elements are simply not
      there). So, any protocol that may rely on carrying "piggy-backed
      data" cannot possibly be mapped to TLS (or DTLS for that matter).
      Hence, my email question a few weeks ago (April 10, 2014, 11:37am
      EDT) on "TLS/DTLS piggy-backing".<br>
      <br>
      <br>
      <br>
      On 5/4/2014 10:06 PM, Michael Richardson wrote:<br>
    </div>
    <blockquote cite="mid:29064.1399255587@sandelman.ca" type="cite">
      <pre wrap="">
Agenda.

1) notewell.
2) intros
3) pritikin-bootstrapping/autonomic vs EAP-TLS vs 6top/COAP/DTLS.
4) if possible, how is 802.1AR being used in the VoIP space.

-- remember that the call is recorded, and the NoteWell applies.

-- The URL to access the webex, which will we use for audio only:
  <a class="moz-txt-link-freetext" href="https://cisco.webex.com/cisco/j.php?MTID=m2fe139bf876cea3ec62750cd580b7908">https://cisco.webex.com/cisco/j.php?MTID=m2fe139bf876cea3ec62750cd580b7908</a>

-- we will resume with the etherpad at:
   <a class="moz-txt-link-freetext" href="http://etherpad.tools.ietf.org:9000/p/notes-ietf-89-6tisch-security">http://etherpad.tools.ietf.org:9000/p/notes-ietf-89-6tisch-security</a>

I'm at +1 613 276-6809, IM: <a class="moz-txt-link-abbreviated" href="mailto:mcr@xmpp.credil.org">mcr@xmpp.credil.org</a> or <a class="moz-txt-link-abbreviated" href="mailto:mcharlesr@gmail.com">mcharlesr@gmail.com</a>,
if you need more than that to get in, or are having difficulties.
Please make sure your audio works, and that you mute when not talking.

--
Michael Richardson <a class="moz-txt-link-rfc2396E" href="mailto:mcr+IETF@sandelman.ca">&lt;mcr+IETF@sandelman.ca&gt;</a>, Sandelman Software Works
 -= IPv6 IoT consulting =-



</pre>
      <br>
      <fieldset class="mimeAttachmentHeader"></fieldset>
      <br>
      <pre wrap="">_______________________________________________
6tisch-security mailing list
<a class="moz-txt-link-abbreviated" href="mailto:6tisch-security@ietf.org">6tisch-security@ietf.org</a>
<a class="moz-txt-link-freetext" href="https://www.ietf.org/mailman/listinfo/6tisch-security">https://www.ietf.org/mailman/listinfo/6tisch-security</a>
</pre>
    </blockquote>
    <br>
    <br>
    <pre class="moz-signature" cols="72">-- 
email: <a class="moz-txt-link-abbreviated" href="mailto:rstruik.ext@gmail.com">rstruik.ext@gmail.com</a> | Skype: rstruik
cell: +1 (647) 867-5658 | US: +1 (415) 690-7363</pre>
  </body>
</html>

--------------000903010703020902080804--


From nobody Mon May  5 11:04:00 2014
Return-Path: <pthubert@cisco.com>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id B73141A03CE; Mon,  5 May 2014 11:03:58 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -15.151
X-Spam-Level: 
X-Spam-Status: No, score=-15.151 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_HI=-5, RP_MATCHES_RCVD=-0.651, SPF_PASS=-0.001, USER_IN_DEF_DKIM_WL=-7.5] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id H8PmiCuqGW0W; Mon,  5 May 2014 11:03:57 -0700 (PDT)
Received: from rcdn-iport-3.cisco.com (rcdn-iport-3.cisco.com [173.37.86.74]) by ietfa.amsl.com (Postfix) with ESMTP id 1AB421A03C8; Mon,  5 May 2014 11:03:57 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cisco.com; i=@cisco.com; l=3974; q=dns/txt; s=iport; t=1399313034; x=1400522634; h=from:to:cc:subject:date:message-id:mime-version; bh=It/fP0+Q6ep24u+M7OteE2tutByyqKmRrusXSo6iEDA=; b=Zb2fH6ietDviOA4QpMk3YptB2y89hD2vkw5mqcDvEAiUO83h8F8gm3Yt DcJUBZQrfdzMEejoxi+J4DCXUDefA0JnoAMQgkaOodZd+mtv3DqC5dclL yUu8qyodgb0HY32OtppQhirkkmPjnwqOr2pWp1c+5a8yGgZ2Ye04PKiYl I=;
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-Anti-Spam-Result: AgMFAOjRZ1OtJA2J/2dsb2JhbAA/GoJCRE9YxEaBGBZ0gicBBC1MEgEMHlYmAQQBDQ2IOQ02y0YTBI4hLQSDMYEVBKwogzRtgUI
X-IronPort-AV: E=Sophos;i="4.97,990,1389744000";  d="scan'208,217";a="322533050"
Received: from alln-core-4.cisco.com ([173.36.13.137]) by rcdn-iport-3.cisco.com with ESMTP; 05 May 2014 18:03:53 +0000
Received: from xhc-aln-x03.cisco.com (xhc-aln-x03.cisco.com [173.36.12.77]) by alln-core-4.cisco.com (8.14.5/8.14.5) with ESMTP id s45I3rnP004275 (version=TLSv1/SSLv3 cipher=AES128-SHA bits=128 verify=FAIL); Mon, 5 May 2014 18:03:53 GMT
Received: from xmb-rcd-x01.cisco.com ([169.254.1.229]) by xhc-aln-x03.cisco.com ([173.36.12.77]) with mapi id 14.03.0123.003; Mon, 5 May 2014 13:03:53 -0500
From: "Pascal Thubert (pthubert)" <pthubert@cisco.com>
To: "6tisch@ietf.org" <6tisch@ietf.org>, Robert Moskowitz <rgm@htt-consult.com>
Thread-Topic: Minutes for the security call 
Thread-Index: Ac9ogTTwVASlDFzfQQ2eV8ucggSZcw==
Date: Mon, 5 May 2014 18:03:53 +0000
Deferred-Delivery: Mon, 5 May 2014 16:44:00 +0000
Message-ID: <E045AECD98228444A58C61C200AE1BD8426378CB@xmb-rcd-x01.cisco.com>
Accept-Language: fr-FR, en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
x-originating-ip: [10.55.22.4]
Content-Type: multipart/alternative; boundary="_000_E045AECD98228444A58C61C200AE1BD8426378CBxmbrcdx01ciscoc_"
MIME-Version: 1.0
Archived-At: http://mailarchive.ietf.org/arch/msg/6tisch-security/ntKTc5s5UdnDjp4qBbnLQizLnnU
Cc: "6tisch-security@ietf.org" <6tisch-security@ietf.org>
Subject: [6tisch-security] Minutes for the security call
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 05 May 2014 18:03:59 -0000

--_000_E045AECD98228444A58C61C200AE1BD8426378CBxmbrcdx01ciscoc_
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable

Dear all

The minutes for the security call on Monday 5/5 are now available: https://=
bitbucket.org/6tisch/meetings/wiki/140505_webex_security

Webex recording: https://cisco.webex.com/ciscosales/lsr.php?RCID=3Dbbbf6234=
52844df8bdd59cc3efcf56b2

A link to past meetings and summary of coming meetings can be found on our =
Meetings WiKi page<https://bitbucket.org/6tisch/meetings/wiki/Home>.

Cheers;

Pascal


--_000_E045AECD98228444A58C61C200AE1BD8426378CBxmbrcdx01ciscoc_
Content-Type: text/html; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable

<html xmlns:v=3D"urn:schemas-microsoft-com:vml" xmlns:o=3D"urn:schemas-micr=
osoft-com:office:office" xmlns:w=3D"urn:schemas-microsoft-com:office:word" =
xmlns:m=3D"http://schemas.microsoft.com/office/2004/12/omml" xmlns=3D"http:=
//www.w3.org/TR/REC-html40">
<head>
<meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3Dus-ascii"=
>
<meta name=3D"Generator" content=3D"Microsoft Word 14 (filtered medium)">
<style><!--
/* Font Definitions */
@font-face
	{font-family:Calibri;
	panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
	{font-family:Tahoma;
	panose-1:2 11 6 4 3 5 4 4 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
	{margin:0cm;
	margin-bottom:.0001pt;
	font-size:11.0pt;
	font-family:"Calibri","sans-serif";}
a:link, span.MsoHyperlink
	{mso-style-priority:99;
	color:blue;
	text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
	{mso-style-priority:99;
	color:purple;
	text-decoration:underline;}
p.MsoAcetate, li.MsoAcetate, div.MsoAcetate
	{mso-style-priority:99;
	mso-style-link:"Balloon Text Char";
	margin:0cm;
	margin-bottom:.0001pt;
	font-size:8.0pt;
	font-family:"Tahoma","sans-serif";}
span.EmailStyle17
	{mso-style-type:personal-compose;
	font-family:"Calibri","sans-serif";
	color:windowtext;}
span.BalloonTextChar
	{mso-style-name:"Balloon Text Char";
	mso-style-priority:99;
	mso-style-link:"Balloon Text";
	font-family:"Tahoma","sans-serif";}
.MsoChpDefault
	{mso-style-type:export-only;
	font-family:"Calibri","sans-serif";}
@page WordSection1
	{size:612.0pt 792.0pt;
	margin:70.85pt 70.85pt 70.85pt 70.85pt;}
div.WordSection1
	{page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext=3D"edit" spidmax=3D"1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext=3D"edit">
<o:idmap v:ext=3D"edit" data=3D"1" />
</o:shapelayout></xml><![endif]-->
</head>
<body lang=3D"EN-US" link=3D"blue" vlink=3D"purple">
<div class=3D"WordSection1">
<p class=3D"MsoNormal">Dear all<o:p></o:p></p>
<p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoNormal">The minutes for the security call on Monday 5/5 are =
now available:
<a href=3D"https://bitbucket.org/6tisch/meetings/wiki/140505_webex_security=
">https://bitbucket.org/6tisch/meetings/wiki/140505_webex_security</a>
<o:p></o:p></p>
<p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoNormal">Webex recording: <a href=3D"https://cisco.webex.com/=
ciscosales/lsr.php?RCID=3Dbbbf623452844df8bdd59cc3efcf56b2">
https://cisco.webex.com/ciscosales/lsr.php?RCID=3Dbbbf623452844df8bdd59cc3e=
fcf56b2</a>
<o:p></o:p></p>
<p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoNormal">A link to past meetings and summary of coming meetin=
gs can be found on our
<a href=3D"https://bitbucket.org/6tisch/meetings/wiki/Home">Meetings WiKi p=
age</a>.
<o:p></o:p></p>
<p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoNormal">Cheers;<o:p></o:p></p>
<p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoNormal">Pascal<o:p></o:p></p>
<p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p>
</div>
</body>
</html>

--_000_E045AECD98228444A58C61C200AE1BD8426378CBxmbrcdx01ciscoc_--


From nobody Mon May  5 11:12:36 2014
Return-Path: <pritikin@cisco.com>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 923941A037B for <6tisch-security@ietfa.amsl.com>; Mon,  5 May 2014 11:10:56 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -15.752
X-Spam-Level: 
X-Spam-Status: No, score=-15.752 tagged_above=-999 required=5 tests=[BAYES_05=-0.5, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, GB_I_LETTER=-2, RCVD_IN_DNSWL_HI=-5, RP_MATCHES_RCVD=-0.651, SPF_PASS=-0.001, USER_IN_DEF_DKIM_WL=-7.5] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id YUkyReMnXjcr for <6tisch-security@ietfa.amsl.com>; Mon,  5 May 2014 11:10:53 -0700 (PDT)
Received: from rcdn-iport-1.cisco.com (rcdn-iport-1.cisco.com [173.37.86.72]) by ietfa.amsl.com (Postfix) with ESMTP id E42F81A02DE for <6tisch-security@ietf.org>; Mon,  5 May 2014 11:10:52 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cisco.com; i=@cisco.com; l=12256; q=dns/txt; s=iport; t=1399313449; x=1400523049; h=from:to:cc:subject:date:message-id:references: in-reply-to:content-id:content-transfer-encoding: mime-version; bh=50Dm88WexO6InvTO8bHMnxs88hNL+AXkMoeTniqnFdU=; b=B53bD/LswNkpM3UqJ0izynjjQKmp2Z2rNVgxCTm4QCSf81lh/jNbZag8 V9cz9pdxKlKVuj/UpH7CEiSTHH488he2TH2MtkSQLATIIJmLQYlH5LZDM 7wdTKBjXwdzQ0gdpVouSG1k5kzvZ87aXB7OS9RGvEmmy7Xiez3cR1msYF s=;
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-Anti-Spam-Result: AgIFAFnTZ1OtJA2M/2dsb2JhbABQCYMGgSfERoEYFnSCJQEBAQMBDBtSBQsCAQhGMiUCBA4FH4gaCMwPF41wBwkCARwzB4MqgRUElT6DdpJ0gzSBbyQc
X-IronPort-AV: E=Sophos;i="4.97,990,1389744000"; d="scan'208";a="322313539"
Received: from alln-core-7.cisco.com ([173.36.13.140]) by rcdn-iport-1.cisco.com with ESMTP; 05 May 2014 18:10:48 +0000
Received: from xhc-aln-x01.cisco.com (xhc-aln-x01.cisco.com [173.36.12.75]) by alln-core-7.cisco.com (8.14.5/8.14.5) with ESMTP id s45IAmPr003594 (version=TLSv1/SSLv3 cipher=AES128-SHA bits=128 verify=FAIL); Mon, 5 May 2014 18:10:48 GMT
Received: from xmb-rcd-x03.cisco.com ([169.254.7.199]) by xhc-aln-x01.cisco.com ([173.36.12.75]) with mapi id 14.03.0123.003; Mon, 5 May 2014 13:10:48 -0500
From: "Max Pritikin (pritikin)" <pritikin@cisco.com>
To: Michael Richardson <mcr+ietf@sandelman.ca>
Thread-Topic: a different explanation of autonomic bootstrap
Thread-Index: AQHPZwZfgzRoqzgCkkiMkZTG8uHFBJsyoJWA
Date: Mon, 5 May 2014 18:10:47 +0000
Message-ID: <07C02745-0562-4B95-828A-6B1DCDD390FA@cisco.com>
References: <7591.1399145520@sandelman.ca>
In-Reply-To: <7591.1399145520@sandelman.ca>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
x-originating-ip: [10.21.122.95]
Content-Type: text/plain; charset="Windows-1252"
Content-ID: <A58AB7380C941E4189C754E70103F467@emea.cisco.com>
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
Archived-At: http://mailarchive.ietf.org/arch/msg/6tisch-security/lYNdW2SzWAJY2_xXWmNA_RXh31c
X-Mailman-Approved-At: Mon, 05 May 2014 11:12:35 -0700
Cc: Robert Moskowitz <rgm@htt-consult.com>, "Michael Behringer \(mbehring\)" <mbehring@cisco.com>, tisch-security <6tisch-security@ietf.org>
Subject: Re: [6tisch-security] a different explanation of autonomic bootstrap
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 05 May 2014 18:10:56 -0000

On May 3, 2014, at 1:32 PM, Michael Richardson <mcr+ietf@sandelman.ca> wrot=
e:

>=20
> (LookOut, AppleMail and web mail people will need a fixed font to underst=
and this email.
> Sorry, if you got pretty proportional wrapped emails, your program violat=
ed rfc5822...
> Try viewing through the mailarchive link that is now in every email that =
goes through
> ietf.org...)
>=20
> I think that draft-pritikin-bootstrapping-keyinfrastructures needs to exp=
lain things a
> bit differently.  I'm not sure if this represents significant "on-the-wir=
e" changes
> yet, or just details.
>=20
> Michael: I'd like to go through this on Monday's call, and I will attempt=
 to prepare
> some slides to go with it. Maybe Max would be able to join us?

I=92m sorry, I=92m reading this now and its presumably after the call time.=
=20

> I also CC'ed Bob Moskovitz of Verizon Business, as he had indicated to me=
 privately
> that they were doing extensive use of 802.1AR certificates for deployment=
 of
> VoIP phones/systems.
>=20
> Bob: if you should be available 10am EDT Monday (yeah, that would be firs=
t
> thing for you, and you might not even read this), you might join our call=
,
> details in next email, but I'll understand if you can not make it.
>=20
> I think that I am making up something on the operator claiming side of
> things; because the IEEE 802.1AR specification does not (unless I missed =
it)
> say anything about how the device is claimed by the network (how it trust=
s
> the network), only how the network trusts the device.  Perhaps there are =
some
> specifications which I've missed, or perhaps some things which are simply=
 unspecified.

That is not specified in 802.1AR which focusses on the device identity.=20

>=20
> I had copied the various steps out of pritikin-bootstrapping document wit=
h
> the intention of making them more precise in the 6tisch security (creatin=
g a
> profile), and then found that everything wound up in the first two steps,=
 and
> then noticed that there was "Claiming" way at the bottom!!
>=20
> So clearly, I got something wrong!!!!
>=20
> Let's start with the diagram mentioned above.
> See another email about if we reverse who initiates the TLS.
>=20
> I'm adding some letters to each arc so that they be mapped back to the st=
eps,
> which I show below.
>=20
> I'm also going to have to add a whole bunch of details, because they matt=
er here,
> and I've made this very much (EAP-)TLS specific.  TLS does not send the C=
lientCertificate
> until after the Server has sent it's certificate, which presentes a probl=
em that
> I'll explain below.

Interesting that you are communicating to the Factory Cloud Service inline =
with the TLS handshake. In our discussions we would have imagined completin=
g the TLS handshake and then communicating with the factory service. I see =
how this causes the difficulty you=92re referencing below.

Discussion included inline but at a high level consider this flow as more c=
losely matching my mental model:=20

  +---------+                +----------+                +-----------+
  |  New    |                |          |                |  Factory  |
  | Entity  |                |  Domain  |                |   Cloud   |
  |         |                |          |                |  Service  |
  +---------+                +----------+                +-----------+
      |                           |                            |
      |<-------discovery-(A)----->|                            |
      |-----TLS ClientHello (B)-->|                            |
      |                           |                            |
      |<------ServerHello-(E)-----|                            |
      |<----ServerCertificate-(H)-|                            |
      |                           |                            |
 [validate cert chain? (I)]       |                            |
 [PROVISIONAL ACCEPT: Enter bootstrapping mode!]               |
      |                           |                            |
      |---ClientCertificate-(J)-->|                            |
      |   (802.1AR cred)          |                            |
      |                           |                            |
   [TLS handshake is run to completion]                        |
      |                           |                            |
      |---/BootstrapRequest------>|                            |=20
      |                           |                            |
      |                           |---802.1AR identity(C)----->|
      |                           |---Domain ID--------------->|
      |                           |                    [device belongs]
      |                           |                    [to domain?    ]
      |                           |                    [PREFERRED: JUST LOG=
, NO DECISIONS]
      |                           |                            |
      |                           |<---device history log(D)---|
      |                    [ accept device? ]                  |
      |                           |------- claim device -(F)-->|
      |                           |                  [update audit log]
      |                           |<----- authz token --(G)----|
      |                           |      [SIGNED LOG ENTRY]    |
      |                           |                            |
      |                  [ still accept device?]               |
      |                           |                            |
      |<=97[authz token]------------|                            |
  [validate token using factory root cert]
  [Join this domain?]             |                            |
      |                           |                            |
  [Initiate EST/RFC7030 on this TLS connection]                |
      |----domain enrolment------>|                            |
      |<----domain certificate----|                            |

In this fashion it is a =93/BootstrapRequest=94 extension to RFC7030 Enroll=
ment over Secure Transport. The basic message elements are all as you descr=
ibed but I=92ve simply re-ordered them to better match the TLS and EST flow=
s which minimizes the integration efforts.=20

>=20
>=20
>   +---------+                +----------+                +-----------+
>   |  New    |                |          |                |  Factory  |
>   | Entity  |                |  Domain  |                |   Cloud   |
>   |         |                |          |                |  Service  |
>   +---------+                +----------+                +-----------+
>       |                           |                            |
>       |<-------discovery-(A)----->|                            |
>       |-----TLS ClientHello (B)-->|                            |
>       |     (802.1AR cred)        |                            |
>       |                           |---802.1AR identity(C)----->|
>       |                           |---Domain ID--------------->|
>       |                           |                    [device belongs]
>       |                           |                    [to domain?    ]
>       |                           |                            |
>       |                           |<---device history log(D)---|
>       |                    [ accept device? ]                  |
>       |<------ServerHello-(E)-----|                            |
>       |                           |------- claim device -(F)-->|
>       |                           |                  [update audit log]
>       |                           |<----- authz token --(G)----|
>       |                           |      (802.1AR cert)        |
>       |                           |                            |
>       |                  [ still accept device?]               |
>       |<----ServerCertificate-(H)-|                            |
>       |                           |                            |
>  [validate cert chain? (I)]       |                            |
>       |                           |                            |
>       |---ClientCertificate-(J)-->|                            |
>       |                           |                            |
>       |                           |                            |
>       |----domain enrolment------>|                            |
>       |<----domain certificate----|                            |
>=20
>=20
> A  Proxy Discovery (A)
> B  TLS ClientHello
>   This part has to include two things which are not exactly common TLS.
>   1) it must have a TrustedAuthorities (6066) indicating what it's Factor=
 CA
>   2) it must include its IDevID somewhere, TBD.

RFC6066 TrustedAuthority won=92t help here because Domain is unlikely to ha=
ve a useful certificate issued by the Factory Cloud Service.

Instead the New Entity would provisionally accept the TLS communications w/=
o being able to verify the Domain credential. It submits its IDevID in resp=
onse (during =91J=92) but the entire session is still provisional.=20

- max

> C  (optional) Query to Factory Cloud Service/MASA
> D  (optional) reply with device history leading to accept device decision=
.
> E  Domain Auth* server sends ServerHello
>   (otherwise, if one does not accept the device, then one sends back
>   an error message, which naturally could be forged, so the device
>   really takes this a clue to back off a bit, listen some more,
>   and try again later)
> F  claim device.  The Domain Auth* may need to talk to a cloud
>         service in order to get an appropriate certificate issued
>         to it.  That also would update the audit log.
> G  an appropriate certificate is issues to the Domain Auth*, that
>   both identifies the domain owner, and binds the device to that
>   domain owner.   This certificate could also be delivered by
>   USB key, QR code, etc.
> H  the certificate (chain) is sent as the ServerCertificate
>   to the device.
> I  the device validates the certificate chain.  The device
>   has a trusted certificate store which contains the Factory
>   CA certificate.  In addition, it has its per-device IDevID
>   certificate signed by said Factory CA.
>=20
>   The device can therefore validate a chain of certificates
>   that start at the Vendor Factor CA, and may chain through
>   multiple resellers, and finally end with a certificate
>   permitting the Domain Owner to claim the device.  It is
>   unclear what the subject of each of the certificates in
>   the chain is, as each part must in fact list the IDevID
>   being claimed.
>=20
> J  the device, accepting the claim would respond with the
>   next step in the TLS protocol, the ClientCertificate
>   message, proving the device is in fact the IDevID it claimed
>   to be.
>=20
> Now, the bootstrap process then suggests that using the resulting
> secure channel, that a certificate enrollment process (CET) be done.
>=20
> I feel neither here nor there about that.
>=20
> PRO:
>  - It certainly would shorten then process of authenticating, and 802.1AR
>    devices certainly are expected to be able to deal with that.
>  - It permits all devices to have a common (short) root, such that
>    adjacent devices could in fact authenticate each other easily.
>    This very much matters to PCE-less 6top!
>=20
> CON:
>  - it seems like it is a whole chunk of additional infrastructure (operat=
ing
>    a CA), and I'm afraid that it may scare many off.
>  - I'm not sure that running CET over EAP-TLS is such a good idea, fragme=
ntation
>    wise.
>  - it kinda implies that there may be a  lot more async operations
>    during operation, and I think that a very long lived TLS Session Resum=
ption Token,
>    (rfc5077), stored into flash on the device is closer to what people
>    expect to use.   Given that, one can resume the created TLS session,
>    perhaps outside of the EAP-TLS.
>=20
> --
> Michael Richardson <mcr+IETF@sandelman.ca>, Sandelman Software Works
> -=3D IPv6 IoT consulting =3D-
>=20


From nobody Mon May  5 11:12:56 2014
Return-Path: <mcr@sandelman.ca>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 42C1B1A02DE for <6tisch-security@ietfa.amsl.com>; Mon,  5 May 2014 11:12:51 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.542
X-Spam-Level: 
X-Spam-Status: No, score=-2.542 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RP_MATCHES_RCVD=-0.651, SPF_PASS=-0.001, T_TVD_MIME_NO_HEADERS=0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Zxfx6yj5KTat for <6tisch-security@ietfa.amsl.com>; Mon,  5 May 2014 11:12:48 -0700 (PDT)
Received: from tuna.sandelman.ca (tuna.sandelman.ca [IPv6:2607:f0b0:f:3::184]) by ietfa.amsl.com (Postfix) with ESMTP id 0E0221A038E for <6tisch-security@ietf.org>; Mon,  5 May 2014 11:12:48 -0700 (PDT)
Received: from sandelman.ca (obiwan.sandelman.ca [IPv6:2607:f0b0:f:2::247]) by tuna.sandelman.ca (Postfix) with ESMTP id 55B1C20011; Mon,  5 May 2014 14:14:11 -0400 (EDT)
Received: by sandelman.ca (Postfix, from userid 179) id AB94563ABD; Mon,  5 May 2014 14:12:40 -0400 (EDT)
Received: from sandelman.ca (localhost [127.0.0.1]) by sandelman.ca (Postfix) with ESMTP id 990F263AB6; Mon,  5 May 2014 14:12:40 -0400 (EDT)
From: Michael Richardson <mcr+ietf@sandelman.ca>
To: Rene Struik <rstruik.ext@gmail.com>
In-Reply-To: <5367ADC1.8090907@gmail.com>
References: <E045AECD98228444A58C61C200AE1BD8416F3AF4@xmb-rcd-x01.cisco.com> <bomn1n01Q3zUFux01ompsd> <531DD632.2060009@cox.net> <531DDB20.5050600@gmail.com> <10925.1394631496@sandelman.ca> <532069C8.2050005@gmail.com> <23590.1394999032@sandelman.ca> <18106.1395625035@sandelman.ca> <19609.1396839403@sandelman.ca> <11557.1397444260@sandelman.ca> <28192.1398644294@sandelman.ca> <29064.1399255587@sandelman.ca> <5367ADC1.8090907@gmail.com>
X-Mailer: MH-E 8.2; nmh 1.3-dev; GNU Emacs 23.4.1
X-Face: $\n1pF)h^`}$H>Hk{L"x@)JS7<%Az}5RyS@k9X%29-lHB$Ti.V>2bi.~ehC0; <'$9xN5Ub# z!G,p`nR&p7Fz@^UXIn156S8.~^@MJ*mMsD7=QFeq%AL4m<nPbLgmtKK-5dC@#:k
MIME-Version: 1.0
Content-Type: multipart/signed; boundary="=-=-="; micalg=pgp-sha1; protocol="application/pgp-signature"
Date: Mon, 05 May 2014 14:12:40 -0400
Message-ID: <3286.1399313560@sandelman.ca>
Sender: mcr@sandelman.ca
Archived-At: http://mailarchive.ietf.org/arch/msg/6tisch-security/tQizR7mtFbMcw-qS_mVafU5Fo8s
Cc: 6tisch-security@ietf.org
Subject: Re: [6tisch-security] agenda for 2014-05-05 6tisch security call
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 05 May 2014 18:12:51 -0000

--=-=-=


Rene Struik <rstruik.ext@gmail.com> wrote:
    > During the 6tisch security conf call today, discussion referenced the
    > notion of "domain". Somewhat unfortunately, the diagrams referred to
    > communications between a new entity and the domain, whereas in real
    > life communications is between devices (i.e., between a new entity and
    > another network node [who may be a representative of a domain]).

please see section 1.3 at:
      http://tools.ietf.org/html/draft-richardson-6tisch-security-architecture-02#section-1.3

which refers to:
  http://tools.ietf.org/html/draft-irtf-nmrg-autonomic-network-definitions-00#section-2
and:
  http://tools.ietf.org/html/draft-pritikin-bootstrapping-keyinfrastructures-00#section-2

While it is true that communication is between two nodes, and while it is
possible that some members of an LLN may be sufficiently capable to run an
entire CA, but abstracting that role out elsewhere, we make it possible for
everyone to play.

802.1X and PANA uses of EAP-TLS have three parties that they identify:
  - supplicant    (new entity)
  - authenticator (second device, proxy)
  - authorization server (more capable, central device)

--
Michael Richardson <mcr+IETF@sandelman.ca>, Sandelman Software Works
 -= IPv6 IoT consulting =-




--=-=-=
Content-Type: application/pgp-signature

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iQEVAwUBU2fUmICLcPvd0N1lAQKTXwf+PTLMDAkWVwhYH0JSidcZFBp37t8bleYn
Cf0G0vSkaqSsDFn7JAxiM8keUI+r3F52BrD1ER73o4X5SaA1RWD0JRYUqPF1Dupx
XUUC8gYL7Mwx0/ToW6ETMxfY65uHlR/to92fos+l09jLfPI9fRZ6kUqUFNBIu8Bm
+8qaWVKaYbUfpRpzx6dh2ejtlRBBn1PWo1+rejjIzp7BMrILQUJxebDETrlyQZx9
SH74W/ZgkC+UcUquUd94z293zMw/sCx7LNrXVI+6kKTXc3xwPDXpRBXNPdbFysJN
3quxDPnslnugdTMNKPjpG5UjayY2WZaW4+adxnY11X4+i9NNkZahCA==
=spSp
-----END PGP SIGNATURE-----
--=-=-=--


From nobody Mon May  5 11:44:29 2014
Return-Path: <rstruik.ext@gmail.com>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 3DA171A0426 for <6tisch-security@ietfa.amsl.com>; Mon,  5 May 2014 11:44:26 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2
X-Spam-Level: 
X-Spam-Status: No, score=-2 tagged_above=-999 required=5 tests=[BAYES_00=-1.9,  DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id hfIS1_c9TwWB for <6tisch-security@ietfa.amsl.com>; Mon,  5 May 2014 11:44:24 -0700 (PDT)
Received: from mail-ie0-x235.google.com (mail-ie0-x235.google.com [IPv6:2607:f8b0:4001:c03::235]) by ietfa.amsl.com (Postfix) with ESMTP id 1669F1A0424 for <6tisch-security@ietf.org>; Mon,  5 May 2014 11:44:24 -0700 (PDT)
Received: by mail-ie0-f181.google.com with SMTP id y20so8570564ier.40 for <6tisch-security@ietf.org>; Mon, 05 May 2014 11:44:20 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113;  h=message-id:date:from:user-agent:mime-version:to:cc:subject :references:in-reply-to:content-type:content-transfer-encoding; bh=B4Yol6BKnWkSAmCuHQoHiF5nnv8KbXEGaWHcjP1+FEk=; b=Kh01xqcMH/iUaPuR8Wwr/plTUvuQU6DMgZEvMmYdxpb/nn/o/jyMII75GNTaA+V43R v7DG8P4FKk6zne3+CYVOnwGUkZTE0KitS9iUGXe2pfs1Ui2/0DQliQr1Xhy9E4pI1Brv DtiaerhBBFvhebYwiepAcb9ZTavb1NWflKLTBXwZq/aDbB06E9HUw96Jq6XIpDUAhGI4 mQd92ETFj9j6glH3XhdfHXsPypIhzaVmYyRcHnmG9c3OyQJ4mLUfIml1LItXP6tCZ009 i4SgR1ZaoVV0qTMlGGtzmET77Zr2hhjxo2Uj7X0p0enWA4bv61USFUwMXRYCwU+zl0pP vfhA==
X-Received: by 10.50.47.12 with SMTP id z12mr26183398igm.37.1399315460541; Mon, 05 May 2014 11:44:20 -0700 (PDT)
Received: from [192.168.1.103] (CPE0013100e2c51-CM001cea35caa6.cpe.net.cable.rogers.com. [99.231.3.110]) by mx.google.com with ESMTPSA id p4sm29969105igy.7.2014.05.05.11.44.18 for <multiple recipients> (version=TLSv1 cipher=ECDHE-RSA-RC4-SHA bits=128/128); Mon, 05 May 2014 11:44:19 -0700 (PDT)
Message-ID: <5367DBFD.5090905@gmail.com>
Date: Mon, 05 May 2014 14:44:13 -0400
From: Rene Struik <rstruik.ext@gmail.com>
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:24.0) Gecko/20100101 Thunderbird/24.5.0
MIME-Version: 1.0
To: Michael Richardson <mcr+ietf@sandelman.ca>
References: <E045AECD98228444A58C61C200AE1BD8416F3AF4@xmb-rcd-x01.cisco.com> <bomn1n01Q3zUFux01ompsd> <531DD632.2060009@cox.net> <531DDB20.5050600@gmail.com> <10925.1394631496@sandelman.ca> <532069C8.2050005@gmail.com> <23590.1394999032@sandelman.ca> <18106.1395625035@sandelman.ca> <19609.1396839403@sandelman.ca> <11557.1397444260@sandelman.ca> <28192.1398644294@sandelman.ca> <29064.1399255587@sandelman.ca> <5367ADC1.8090907@gmail.com> <3286.1399313560@sandelman.ca>
In-Reply-To: <3286.1399313560@sandelman.ca>
Content-Type: text/plain; charset=ISO-8859-1; format=flowed
Content-Transfer-Encoding: 7bit
Archived-At: http://mailarchive.ietf.org/arch/msg/6tisch-security/Go96hZdnJg9lXX4bL1BgdC_31ZI
Cc: 6tisch-security@ietf.org
Subject: Re: [6tisch-security] agenda for 2014-05-05 6tisch security call
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 05 May 2014 18:44:26 -0000

Hi Michael:

Some comments below.
> Rene Struik <rstruik.ext@gmail.com> wrote:
>      > During the 6tisch security conf call today, discussion referenced the
>      > notion of "domain". Somewhat unfortunately, the diagrams referred to
>      > communications between a new entity and the domain, whereas in real
>      > life communications is between devices (i.e., between a new entity and
>      > another network node [who may be a representative of a domain]).
>
> please see section 1.3 at:
>        http://tools.ietf.org/html/draft-richardson-6tisch-security-architecture-02#section-1.3
>
> which refers to:
>    http://tools.ietf.org/html/draft-irtf-nmrg-autonomic-network-definitions-00#section-2
> and:
>    http://tools.ietf.org/html/draft-pritikin-bootstrapping-keyinfrastructures-00#section-2
>
> While it is true that communication is between two nodes, and while it is
> possible that some members of an LLN may be sufficiently capable to run an
> entire CA, but abstracting that role out elsewhere, we make it possible for
> everyone to play.
RS>>
I do not understand the para above, since in my email this morning after 
the 6tisch security conf call, I did not refer to devices playing their 
own CA at all. Besides, to my knowledge, there has been no conclusion 
yet that devices would not be capable of executing a public key protocol.
<<RS
>
> 802.1X and PANA uses of EAP-TLS have three parties that they identify:
>    - supplicant    (new entity)
>    - authenticator (second device, proxy)
>    - authorization server (more capable, central device)
RS>>
802.1x and PANA all seem to involve an inline third party, which is 
highly undesirable in spotty communication networks and, in particular, 
TSCH-based networks, due to communication time latencies. To my 
knowledge, we have not picked either of these schemes (in case I am 
missing something here, I would be curious about the quantified analysis 
that supports this pick, except to say that protocols "are out there").
<<RS
>
> --
> Michael Richardson <mcr+IETF@sandelman.ca>, Sandelman Software Works
>   -= IPv6 IoT consulting =-
>
>
>


-- 
email: rstruik.ext@gmail.com | Skype: rstruik
cell: +1 (647) 867-5658 | US: +1 (415) 690-7363


From nobody Mon May  5 12:08:13 2014
Return-Path: <rstruik.ext@gmail.com>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 6E3E91A03F0 for <6tisch-security@ietfa.amsl.com>; Mon,  5 May 2014 12:08:12 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2
X-Spam-Level: 
X-Spam-Status: No, score=-2 tagged_above=-999 required=5 tests=[BAYES_00=-1.9,  DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id wTAUsYNj5a62 for <6tisch-security@ietfa.amsl.com>; Mon,  5 May 2014 12:08:10 -0700 (PDT)
Received: from mail-ig0-x22f.google.com (mail-ig0-x22f.google.com [IPv6:2607:f8b0:4001:c05::22f]) by ietfa.amsl.com (Postfix) with ESMTP id A01321A00ED for <6tisch-security@ietf.org>; Mon,  5 May 2014 12:08:10 -0700 (PDT)
Received: by mail-ig0-f175.google.com with SMTP id uq10so2711800igb.14 for <6tisch-security@ietf.org>; Mon, 05 May 2014 12:08:07 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113;  h=message-id:date:from:user-agent:mime-version:to:cc:subject :references:in-reply-to:content-type:content-transfer-encoding; bh=X7cDSZbl68Mg/E7UJCM8IcRao7alx509CD5ggwYM4qw=; b=DNPVFQMhqFf50PMKeiBVk+z+CXNKcl5KGwUwKIJyltE8ed6egqbsVYGUUOb7h5+9eP p34PqI9WXap09dfJAbQDEQ+DlqeqSQE4dJvyljtKGx/i9d3fENXxlkbksRR1IF+LVRM3 0tmx10I6k0M4FIDPypWYy2sD21Bdl1SOKL1596PbsJxd9UICDbUxTtbU4sc3RZ3nUmAr 0pSYabWL1YDo9oxTPvlwnZ8b8afGWYsmAMmDutcrt3A0vCY7RgrkWz6bY+eLBPF9df8M QvC/W49dkoyNPBinUh0p9WswE5Cq08FA7FwQsgK5ZnQQ4ASAIGiDiUeFh7PrPtBn/e7U NDKg==
X-Received: by 10.42.102.201 with SMTP id j9mr5596219ico.58.1399316887078; Mon, 05 May 2014 12:08:07 -0700 (PDT)
Received: from [192.168.1.103] (CPE0013100e2c51-CM001cea35caa6.cpe.net.cable.rogers.com. [99.231.3.110]) by mx.google.com with ESMTPSA id k8sm30130587ige.0.2014.05.05.12.08.04 for <multiple recipients> (version=TLSv1 cipher=ECDHE-RSA-RC4-SHA bits=128/128); Mon, 05 May 2014 12:08:05 -0700 (PDT)
Message-ID: <5367E18F.4080202@gmail.com>
Date: Mon, 05 May 2014 15:07:59 -0400
From: Rene Struik <rstruik.ext@gmail.com>
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:24.0) Gecko/20100101 Thunderbird/24.5.0
MIME-Version: 1.0
To: "Max Pritikin (pritikin)" <pritikin@cisco.com>,  Michael Richardson <mcr+ietf@sandelman.ca>
References: <7591.1399145520@sandelman.ca> <07C02745-0562-4B95-828A-6B1DCDD390FA@cisco.com>
In-Reply-To: <07C02745-0562-4B95-828A-6B1DCDD390FA@cisco.com>
Content-Type: text/plain; charset=windows-1252; format=flowed
Content-Transfer-Encoding: 8bit
Archived-At: http://mailarchive.ietf.org/arch/msg/6tisch-security/YptGbg0RohvQfIrYfZAh7ldbNtk
Cc: Robert Moskowitz <rgm@htt-consult.com>, tisch-security <6tisch-security@ietf.org>, "Michael Behringer \(mbehring\)" <mbehring@cisco.com>
Subject: Re: [6tisch-security] a different explanation of autonomic bootstrap
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 05 May 2014 19:08:12 -0000

Hi Max:

Some comments below.

Rene

On 5/5/2014 2:10 PM, Max Pritikin (pritikin) wrote:
[snip]
> |<----domain certificate----| | In this fashion it is a 
> “/BootstrapRequest” extension to RFC7030 Enrollment over Secure 
> Transport. The basic message elements are all as you described but 
> I’ve simply re-ordered them to better match the TLS and EST flows 
> which minimizes the integration efforts.
>>
>>    +---------+                +----------+                +-----------+
>>    |  New    |                |          |                |  Factory  |
>>    | Entity  |                |  Domain  |                |   Cloud   |
>>    |         |                |          |                |  Service  |
>>    +---------+                +----------+                +-----------+
>>        |                           |                            |
>>        |<-------discovery-(A)----->|                            |
>>        |-----TLS ClientHello (B)-->|                            |
>>        |     (802.1AR cred)        |                            |
>>        |                           |---802.1AR identity(C)----->|
>>        |                           |---Domain ID--------------->|
>>        |                           |                    [device belongs]
>>        |                           |                    [to domain?    ]
>>        |                           |                            |
>>        |                           |<---device history log(D)---|
>>        |                    [ accept device? ]                  |
>>        |<------ServerHello-(E)-----|                            |
>>        |                           |------- claim device -(F)-->|
>>        |                           |                  [update audit log]
>>        |                           |<----- authz token --(G)----|
>>        |                           |      (802.1AR cert)        |
>>        |                           |                            |
>>        |                  [ still accept device?]               |
>>        |<----ServerCertificate-(H)-|                            |
>>        |                           |                            |
>>   [validate cert chain? (I)]       |                            |
>>        |                           |                            |
>>        |---ClientCertificate-(J)-->|                            |
>>        |                           |                            |
>>        |                           |                            |
>>        |----domain enrolment------>|                            |
>>        |<----domain certificate----|                            |
>>
>>
>> A  Proxy Discovery (A)
>> B  TLS ClientHello
>>    This part has to include two things which are not exactly common TLS.
>>    1) it must have a TrustedAuthorities (6066) indicating what it's Factor CA
>>    2) it must include its IDevID somewhere, TBD.
> RFC6066 TrustedAuthority won’t help here because Domain is unlikely to have a useful certificate issued by the Factory Cloud Service.
>
> Instead the New Entity would provisionally accept the TLS communications w/o being able to verify the Domain credential. It submits its IDevID in response (during ‘J’) but the entire session is still provisional.
>
RS>>
It may be undesirable to have provisional sessions, if only because of 
the amount of dangling state one has to keep and because of time-outs 
and nesting issues. Once some of the missing info that prevented proper 
authentication has been provided to the new entity and/or network 
representative, proper authenticated key agreement can be realized.
<<RS

-- 
email: rstruik.ext@gmail.com | Skype: rstruik
cell: +1 (647) 867-5658 | US: +1 (415) 690-7363


From nobody Mon May  5 12:57:08 2014
Return-Path: <pritikin@cisco.com>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 4971D1A049C for <6tisch-security@ietfa.amsl.com>; Mon,  5 May 2014 12:57:07 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -10.152
X-Spam-Level: 
X-Spam-Status: No, score=-10.152 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RP_MATCHES_RCVD=-0.651, SPF_PASS=-0.001, USER_IN_DEF_DKIM_WL=-7.5] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id d5NkBq_YDkLZ for <6tisch-security@ietfa.amsl.com>; Mon,  5 May 2014 12:57:06 -0700 (PDT)
Received: from alln-iport-6.cisco.com (alln-iport-6.cisco.com [173.37.142.93]) by ietfa.amsl.com (Postfix) with ESMTP id BA8BC1A0494 for <6tisch-security@ietf.org>; Mon,  5 May 2014 12:57:05 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cisco.com; i=@cisco.com; l=4665; q=dns/txt; s=iport; t=1399319822; x=1400529422; h=from:to:cc:subject:date:message-id:references: in-reply-to:content-id:content-transfer-encoding: mime-version; bh=FzusNb561wG5mUAIN43AjoguT8P3vuwmM4S9h8eINFA=; b=CWAzrF3O/+DY3L8Poz7CjvCkgr35VpBZ7HTQHYJR9T0RyJvYkcJKz8jS vd3R3dgKPuc2vnZW1LB04qLD71HoRYBAnRV7TVcM4o6twnqzMp0DGjgxs H7UK5ld2kGGhJm3GdC3nmc8Kw8+sdI9cfKN3S7C6o5I6S11Suco/uhINr I=;
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-Anti-Spam-Result: AjoFAKHsZ1OtJA2L/2dsb2JhbABQBgODBoEnxEaBGhZ0giUBAQEDAQwbUgULAgEIDgouIRElAgQOBR+IDgMJCMZzDYZCF4w7gTUHAwcBHQgbEAcRgxmBFQSMIosggXKNF4VdgzSBbQIHFwYc
X-IronPort-AV: E=Sophos;i="4.97,991,1389744000"; d="scan'208";a="41182914"
Received: from alln-core-6.cisco.com ([173.36.13.139]) by alln-iport-6.cisco.com with ESMTP; 05 May 2014 19:57:02 +0000
Received: from xhc-aln-x02.cisco.com (xhc-aln-x02.cisco.com [173.36.12.76]) by alln-core-6.cisco.com (8.14.5/8.14.5) with ESMTP id s45Jv2B9020731 (version=TLSv1/SSLv3 cipher=AES128-SHA bits=128 verify=FAIL); Mon, 5 May 2014 19:57:02 GMT
Received: from xmb-rcd-x03.cisco.com ([169.254.7.199]) by xhc-aln-x02.cisco.com ([173.36.12.76]) with mapi id 14.03.0123.003; Mon, 5 May 2014 14:57:01 -0500
From: "Max Pritikin (pritikin)" <pritikin@cisco.com>
To: Rene Struik <rstruik.ext@gmail.com>
Thread-Topic: [6tisch-security] a different explanation of autonomic bootstrap
Thread-Index: AQHPZwZfgzRoqzgCkkiMkZTG8uHFBJsyoJWAgAAP2ICAAA3YAA==
Date: Mon, 5 May 2014 19:57:01 +0000
Message-ID: <D0C4F41B-D7E6-40C9-B1AB-0641BDEBD175@cisco.com>
References: <7591.1399145520@sandelman.ca> <07C02745-0562-4B95-828A-6B1DCDD390FA@cisco.com> <5367E18F.4080202@gmail.com>
In-Reply-To: <5367E18F.4080202@gmail.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
x-originating-ip: [10.21.122.95]
Content-Type: text/plain; charset="Windows-1252"
Content-ID: <03C4500A16A8914FAA9AAC58FBD4644B@emea.cisco.com>
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
Archived-At: http://mailarchive.ietf.org/arch/msg/6tisch-security/dnLZesalEjxjb6P7jhba_X6SQI8
Cc: Michael Richardson <mcr+ietf@sandelman.ca>, Robert Moskowitz <rgm@htt-consult.com>, tisch-security <6tisch-security@ietf.org>, "Michael Behringer \(mbehring\)" <mbehring@cisco.com>
Subject: Re: [6tisch-security] a different explanation of autonomic bootstrap
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 05 May 2014 19:57:07 -0000

I understand the concern regarding "dangling state=94 but counter that this=
:
	* is on the client that initiated the connection (no scaling issues)
	* consistent with the current TLS handshake (no extensions)
	* consistent with common TLS APIs (easy to develop using off the shelf com=
ponents)
	* does not persist across connections (there is no need to maintain state =
that spans TLS sessions)
	* minimal integration/modification of the TLS handshake minimizes potentia=
l difficulties with TLSv3=20

Since bootstrapping is a limited occurrence, and all state is on the client=
 anyway, I=92d lean in that direction over a more optimized handshake.=20

- max


On May 5, 2014, at 1:07 PM, Rene Struik <rstruik.ext@gmail.com> wrote:

> Hi Max:
>=20
> Some comments below.
>=20
> Rene
>=20
> On 5/5/2014 2:10 PM, Max Pritikin (pritikin) wrote:
> [snip]
>> |<----domain certificate----| | In this fashion it is a =93/BootstrapReq=
uest=94 extension to RFC7030 Enrollment over Secure Transport. The basic me=
ssage elements are all as you described but I=92ve simply re-ordered them t=
o better match the TLS and EST flows which minimizes the integration effort=
s.
>>>=20
>>>   +---------+                +----------+                +-----------+
>>>   |  New    |                |          |                |  Factory  |
>>>   | Entity  |                |  Domain  |                |   Cloud   |
>>>   |         |                |          |                |  Service  |
>>>   +---------+                +----------+                +-----------+
>>>       |                           |                            |
>>>       |<-------discovery-(A)----->|                            |
>>>       |-----TLS ClientHello (B)-->|                            |
>>>       |     (802.1AR cred)        |                            |
>>>       |                           |---802.1AR identity(C)----->|
>>>       |                           |---Domain ID--------------->|
>>>       |                           |                    [device belongs]
>>>       |                           |                    [to domain?    ]
>>>       |                           |                            |
>>>       |                           |<---device history log(D)---|
>>>       |                    [ accept device? ]                  |
>>>       |<------ServerHello-(E)-----|                            |
>>>       |                           |------- claim device -(F)-->|
>>>       |                           |                  [update audit log]
>>>       |                           |<----- authz token --(G)----|
>>>       |                           |      (802.1AR cert)        |
>>>       |                           |                            |
>>>       |                  [ still accept device?]               |
>>>       |<----ServerCertificate-(H)-|                            |
>>>       |                           |                            |
>>>  [validate cert chain? (I)]       |                            |
>>>       |                           |                            |
>>>       |---ClientCertificate-(J)-->|                            |
>>>       |                           |                            |
>>>       |                           |                            |
>>>       |----domain enrolment------>|                            |
>>>       |<----domain certificate----|                            |
>>>=20
>>>=20
>>> A  Proxy Discovery (A)
>>> B  TLS ClientHello
>>>   This part has to include two things which are not exactly common TLS.
>>>   1) it must have a TrustedAuthorities (6066) indicating what it's Fact=
or CA
>>>   2) it must include its IDevID somewhere, TBD.
>> RFC6066 TrustedAuthority won=92t help here because Domain is unlikely to=
 have a useful certificate issued by the Factory Cloud Service.
>>=20
>> Instead the New Entity would provisionally accept the TLS communications=
 w/o being able to verify the Domain credential. It submits its IDevID in r=
esponse (during =91J=92) but the entire session is still provisional.
>>=20
> RS>>
> It may be undesirable to have provisional sessions, if only because of th=
e amount of dangling state one has to keep and because of time-outs and nes=
ting issues. Once some of the missing info that prevented proper authentica=
tion has been provided to the new entity and/or network representative, pro=
per authenticated key agreement can be realized.
> <<RS
>=20
> --=20
> email: rstruik.ext@gmail.com | Skype: rstruik
> cell: +1 (647) 867-5658 | US: +1 (415) 690-7363
>=20


From nobody Mon May  5 13:18:45 2014
Return-Path: <rstruik.ext@gmail.com>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 8AB231A04C5 for <6tisch-security@ietfa.amsl.com>; Mon,  5 May 2014 13:18:43 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2
X-Spam-Level: 
X-Spam-Status: No, score=-2 tagged_above=-999 required=5 tests=[BAYES_00=-1.9,  DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id U294DaXgrHZd for <6tisch-security@ietfa.amsl.com>; Mon,  5 May 2014 13:18:41 -0700 (PDT)
Received: from mail-ig0-x22d.google.com (mail-ig0-x22d.google.com [IPv6:2607:f8b0:4001:c05::22d]) by ietfa.amsl.com (Postfix) with ESMTP id C93621A04CD for <6tisch-security@ietf.org>; Mon,  5 May 2014 13:18:41 -0700 (PDT)
Received: by mail-ig0-f173.google.com with SMTP id hn18so5266834igb.0 for <6tisch-security@ietf.org>; Mon, 05 May 2014 13:18:38 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113;  h=message-id:date:from:user-agent:mime-version:to:cc:subject :references:in-reply-to:content-type:content-transfer-encoding; bh=FX+bkFY6D2z3xVMiYR5wc11W+pBy+Ubn3XQyF3CzroM=; b=XUYuT89c7yUx0uRp7jyTG/QGzFoz9muIzzMkzCIy83ibUWyo1PaSIYGn2i0ELTRKpP IWotCFGKEIE5k+Q3dqSZ/a9WgkbIUnHlMcB80/HBk3q0V7QRmx/1D6QnD2HfWMrVgBlS +um2aZpGO7BrFxieOP92QelaZleOzyZCMylt5Hr8WckyE0m5WMTAqZcEIzK0zgSgUecP R5hm2XZBaKhGu6WCKRdpNAWoWJRZQ8KduI4EwCVJtUZyrRbU5T9jZyFMlgV/IOVEncS5 eKC44CKBD+OSG4u0tSrvtke8CRoHmQ+EU+qugyXQKpcBR0YzE8ARPFFpmSQ2Z7BcqDCA tsBQ==
X-Received: by 10.50.138.72 with SMTP id qo8mr26943575igb.26.1399321118128; Mon, 05 May 2014 13:18:38 -0700 (PDT)
Received: from [192.168.1.103] (CPE0013100e2c51-CM001cea35caa6.cpe.net.cable.rogers.com. [99.231.3.110]) by mx.google.com with ESMTPSA id s1sm30518511igr.14.2014.05.05.13.18.36 for <multiple recipients> (version=TLSv1 cipher=ECDHE-RSA-RC4-SHA bits=128/128); Mon, 05 May 2014 13:18:37 -0700 (PDT)
Message-ID: <5367F217.2020701@gmail.com>
Date: Mon, 05 May 2014 16:18:31 -0400
From: Rene Struik <rstruik.ext@gmail.com>
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:24.0) Gecko/20100101 Thunderbird/24.5.0
MIME-Version: 1.0
To: "Max Pritikin (pritikin)" <pritikin@cisco.com>
References: <7591.1399145520@sandelman.ca> <07C02745-0562-4B95-828A-6B1DCDD390FA@cisco.com> <5367E18F.4080202@gmail.com> <D0C4F41B-D7E6-40C9-B1AB-0641BDEBD175@cisco.com>
In-Reply-To: <D0C4F41B-D7E6-40C9-B1AB-0641BDEBD175@cisco.com>
Content-Type: text/plain; charset=windows-1252; format=flowed
Content-Transfer-Encoding: 8bit
Archived-At: http://mailarchive.ietf.org/arch/msg/6tisch-security/5ovCh-85dG6--R1wP8nV1hlORu0
Cc: Michael Richardson <mcr+ietf@sandelman.ca>, Robert Moskowitz <rgm@htt-consult.com>, tisch-security <6tisch-security@ietf.org>, "Michael Behringer \(mbehring\)" <mbehring@cisco.com>
Subject: Re: [6tisch-security] a different explanation of autonomic bootstrap
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 05 May 2014 20:18:43 -0000

Hi Max:

Perhaps, I am missing something here: in the picture, the network 
representative ("Domain") has a message exchange with the third party 
("Factory Cloud Service"), which can be viewed as a subroutine inside 
the TLS protocol. During this subroutine, the server has to maintain 
state and triggers lots of bandwidth consumption in the network, without 
having any cryptographic assurances on the new entity (it simply acts on 
a received string that seems to be an ar-certificate).

It would help to have a more complete picture of the TLS handshake in 
the ascii diagrams, including key confirmation messages ("finished" 
messages). I could then try and describe cryptographic and other 
relevant properties and compare with other options.

Best regards, Rene



On 5/5/2014 3:57 PM, Max Pritikin (pritikin) wrote:
> I understand the concern regarding "dangling state” but counter that this:
> 	* is on the client that initiated the connection (no scaling issues)
> 	* consistent with the current TLS handshake (no extensions)
> 	* consistent with common TLS APIs (easy to develop using off the shelf components)
> 	* does not persist across connections (there is no need to maintain state that spans TLS sessions)
> 	* minimal integration/modification of the TLS handshake minimizes potential difficulties with TLSv3
>
> Since bootstrapping is a limited occurrence, and all state is on the client anyway, I’d lean in that direction over a more optimized handshake.
>
> - max
>
>
> On May 5, 2014, at 1:07 PM, Rene Struik <rstruik.ext@gmail.com> wrote:
>
>> Hi Max:
>>
>> Some comments below.
>>
>> Rene
>>
>> On 5/5/2014 2:10 PM, Max Pritikin (pritikin) wrote:
>> [snip]
>>> |<----domain certificate----| | In this fashion it is a “/BootstrapRequest” extension to RFC7030 Enrollment over Secure Transport. The basic message elements are all as you described but I’ve simply re-ordered them to better match the TLS and EST flows which minimizes the integration efforts.
>>>>    +---------+                +----------+                +-----------+
>>>>    |  New    |                |          |                |  Factory  |
>>>>    | Entity  |                |  Domain  |                |   Cloud   |
>>>>    |         |                |          |                |  Service  |
>>>>    +---------+                +----------+                +-----------+
>>>>        |                           |                            |
>>>>        |<-------discovery-(A)----->|                            |
>>>>        |-----TLS ClientHello (B)-->|                            |
>>>>        |     (802.1AR cred)        |                            |
>>>>        |                           |---802.1AR identity(C)----->|
>>>>        |                           |---Domain ID--------------->|
>>>>        |                           |                    [device belongs]
>>>>        |                           |                    [to domain?    ]
>>>>        |                           |                            |
>>>>        |                           |<---device history log(D)---|
>>>>        |                    [ accept device? ]                  |
>>>>        |<------ServerHello-(E)-----|                            |
>>>>        |                           |------- claim device -(F)-->|
>>>>        |                           |                  [update audit log]
>>>>        |                           |<----- authz token --(G)----|
>>>>        |                           |      (802.1AR cert)        |
>>>>        |                           |                            |
>>>>        |                  [ still accept device?]               |
>>>>        |<----ServerCertificate-(H)-|                            |
>>>>        |                           |                            |
>>>>   [validate cert chain? (I)]       |                            |
>>>>        |                           |                            |
>>>>        |---ClientCertificate-(J)-->|                            |
>>>>        |                           |                            |
>>>>        |                           |                            |
>>>>        |----domain enrolment------>|                            |
>>>>        |<----domain certificate----|                            |
>>>>
>>>>
>>>> A  Proxy Discovery (A)
>>>> B  TLS ClientHello
>>>>    This part has to include two things which are not exactly common TLS.
>>>>    1) it must have a TrustedAuthorities (6066) indicating what it's Factor CA
>>>>    2) it must include its IDevID somewhere, TBD.
>>> RFC6066 TrustedAuthority won’t help here because Domain is unlikely to have a useful certificate issued by the Factory Cloud Service.
>>>
>>> Instead the New Entity would provisionally accept the TLS communications w/o being able to verify the Domain credential. It submits its IDevID in response (during ‘J’) but the entire session is still provisional.
>>>
>> RS>>
>> It may be undesirable to have provisional sessions, if only because of the amount of dangling state one has to keep and because of time-outs and nesting issues. Once some of the missing info that prevented proper authentication has been provided to the new entity and/or network representative, proper authenticated key agreement can be realized.
>> <<RS
>>
>> -- 
>> email: rstruik.ext@gmail.com | Skype: rstruik
>> cell: +1 (647) 867-5658 | US: +1 (415) 690-7363
>>


-- 
email: rstruik.ext@gmail.com | Skype: rstruik
cell: +1 (647) 867-5658 | US: +1 (415) 690-7363


From nobody Mon May  5 13:39:24 2014
Return-Path: <pritikin@cisco.com>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id A89F61A0552 for <6tisch-security@ietfa.amsl.com>; Mon,  5 May 2014 13:39:20 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -15.152
X-Spam-Level: 
X-Spam-Status: No, score=-15.152 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_HI=-5, RP_MATCHES_RCVD=-0.651, SPF_PASS=-0.001, USER_IN_DEF_DKIM_WL=-7.5] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 7CUUF0tWoemp for <6tisch-security@ietfa.amsl.com>; Mon,  5 May 2014 13:39:18 -0700 (PDT)
Received: from rcdn-iport-2.cisco.com (rcdn-iport-2.cisco.com [173.37.86.73]) by ietfa.amsl.com (Postfix) with ESMTP id 0D2E31A0502 for <6tisch-security@ietf.org>; Mon,  5 May 2014 13:39:18 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cisco.com; i=@cisco.com; l=10569; q=dns/txt; s=iport; t=1399322355; x=1400531955; h=from:to:cc:subject:date:message-id:references: in-reply-to:content-id:content-transfer-encoding: mime-version; bh=nhP92RbTiltCDX8KqgkDlyenh6nsI222yve9PdENLQo=; b=YHIiNYCMQyjLImB+drhP5FAXexRboIGr//PwK6AmdfP39SS0b1I+OqWV Mk2Zt0c53LcXME5i6+Sz77/NTDnkxSqDAXhiwjfKbp7buQ9wfi/YRtuIU LFFUB71lIDw+BxpHv3C9IQMBOnQ9eS7FRChWTg+G8xsEo+hr7TO3IFhdr 4=;
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-Anti-Spam-Result: AjsFAHX2Z1OtJA2L/2dsb2JhbABQBgODBk9YxEaBGhZ0giUBAQEDAQwbUgULAgEIDgouIRElAgQOBR+IDgMJCMZ2DYZEF4kxgwqBNQcDBwEdCBsQBwIPgxmBFQSMIosggXKNF4VdgzSBbQIHFwYc
X-IronPort-AV: E=Sophos;i="4.97,991,1389744000"; d="scan'208";a="322501302"
Received: from alln-core-6.cisco.com ([173.36.13.139]) by rcdn-iport-2.cisco.com with ESMTP; 05 May 2014 20:39:14 +0000
Received: from xhc-rcd-x03.cisco.com (xhc-rcd-x03.cisco.com [173.37.183.77]) by alln-core-6.cisco.com (8.14.5/8.14.5) with ESMTP id s45KdEls011346 (version=TLSv1/SSLv3 cipher=AES128-SHA bits=128 verify=FAIL); Mon, 5 May 2014 20:39:14 GMT
Received: from xmb-rcd-x03.cisco.com ([169.254.7.199]) by xhc-rcd-x03.cisco.com ([173.37.183.77]) with mapi id 14.03.0123.003; Mon, 5 May 2014 15:39:13 -0500
From: "Max Pritikin (pritikin)" <pritikin@cisco.com>
To: Rene Struik <rstruik.ext@gmail.com>
Thread-Topic: [6tisch-security] a different explanation of autonomic bootstrap
Thread-Index: AQHPZwZfgzRoqzgCkkiMkZTG8uHFBJsyoJWAgAAP2ICAAA3YAIAABd2AgAAF7QA=
Date: Mon, 5 May 2014 20:39:13 +0000
Message-ID: <B67EF6A7-3F5B-4F84-AF21-01F880DA2904@cisco.com>
References: <7591.1399145520@sandelman.ca> <07C02745-0562-4B95-828A-6B1DCDD390FA@cisco.com> <5367E18F.4080202@gmail.com> <D0C4F41B-D7E6-40C9-B1AB-0641BDEBD175@cisco.com> <5367F217.2020701@gmail.com>
In-Reply-To: <5367F217.2020701@gmail.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
x-originating-ip: [10.21.122.95]
Content-Type: text/plain; charset="Windows-1252"
Content-ID: <A87D9C24C902B64D882B954A22C7043F@emea.cisco.com>
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
Archived-At: http://mailarchive.ietf.org/arch/msg/6tisch-security/BxyutEiRQDemkhqXfgmOEfJe6L4
Cc: Michael Richardson <mcr+ietf@sandelman.ca>, Robert Moskowitz <rgm@htt-consult.com>, tisch-security <6tisch-security@ietf.org>, "Michael Behringer \(mbehring\)" <mbehring@cisco.com>
Subject: Re: [6tisch-security] a different explanation of autonomic bootstrap
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 05 May 2014 20:39:20 -0000

On May 5, 2014, at 2:18 PM, Rene Struik <rstruik.ext@gmail.com> wrote:

> Hi Max:
>=20
> Perhaps, I am missing something here: in the picture, the network represe=
ntative ("Domain") has a message exchange with the third party ("Factory Cl=
oud Service"), which can be viewed as a subroutine inside the TLS protocol.=
 During this subroutine, the server has to maintain state and triggers lots=
 of bandwidth consumption in the network, without having any cryptographic =
assurances on the new entity (it simply acts on a received string that seem=
s to be an ar-certificate).
>=20
> It would help to have a more complete picture of the TLS handshake in the=
 ascii diagrams, including key confirmation messages ("finished" messages).=
 I could then try and describe cryptographic and other relevant properties =
and compare with other options.

As shown below (in my simplified mental model diagram) the TLS handshake ru=
ns to completion (the Finished message etc) before any communication with t=
he Cloud Service. Details aren=92t included but they=92re also just standar=
d off-the-shelf TLS:=20


 +---------+                +----------+                +-----------+
 |  New    |                |          |                |  Factory  |
 | Entity  |                |  Domain  |                |   Cloud   |
 |         |                |          |                |  Service  |
 +---------+                +----------+                +-----------+
     |                           |                            |
     |<-------discovery-(A)----->|                            |
     |-----TLS ClientHello (B)-->|                            |
     |                           |                            |
     |<------ServerHello-(E)-----|                            |
     |<----ServerCertificate-(H)-|                            |
     |                           |                            |
[validate cert chain? (I)]       |                            |
[PROVISIONAL ACCEPT: Enter bootstrapping mode!]               |
     |                           |                            |
     |---ClientCertificate-(J)-->|                            |
     |   (802.1AR cred)          |                            |
     |                           |                            |
  [TLS handshake is run to completion]   <------------------------------ TL=
S is established

At this point there is a TLS session between the New Entity and the Domain =
that is only *provisionally* authenticated. The Domain absolutely knows the=
 identity of the new device (leveraging 802.1AR) but the New Entity is stil=
l waiting to see if this is the correct domain.

     |                           |                            |
     |---/BootstrapRequest------>|                            |=20

This is an artifact of =93domain enrollment=94 from below. Because I was an=
 author of EST/RFC7030 I=92m structuring this conversation around that prot=
ocol which is HTTPS based. Thus this expectation that the first data messag=
e is initiated by the client.

     |                           |                            |
     |                           |---802.1AR identity(C)----->|
     |                           |---Domain ID [nonce]------->|
     |                           |                    [device belongs]
     |                           |                    [to domain?    ]
     |                           |                    [PREFERRED: JUST LOG,=
 NO DECISIONS]
     |                           |                            |
     |                           |<---device history log(D)---|
     |                    [ accept device? ]                  |
     |                           |------- claim device -(F)-->|
     |                           |                  [update audit log]
     |                           |<----- authz token --(G)----|
     |                           |      [SIGNED LOG ENTRY]    |
     |                           |                            |
     |                  [ still accept device?]               |

This entire sequence occurs while the TLS connection is held open. You are =
correct that the server has to maintain the TLS session and HTTPS session d=
uring this. Notice though that the New Entity isn=92t involved in this exch=
ange and only the Domain ID (and optionally a nonce) are sent to the server=
. Therefore in an environment where scalability is a greater concern these =
operations can occur in advance (assuming the device IDs are known out-of-b=
and, such as via bill-of-sale integration). There is a cost to this scalabi=
lity which is losing the nonce information but that choice is made by the D=
omain and captured in the Cloud logs.=20


     |                           |                            |
     |<=97[authz token]------------|                            |
 [validate token using factory root cert]
 [Join this domain?]             |                            |
     |                           |                            |
 [Initiate EST/RFC7030 on this TLS connection]                |
     |----domain enrolment------>|                            |
     |<----domain certificate----|                            |

This portion then is the authz response (which may be nonce-less) and basic=
 enrollment mechanism. Again shown here as being EST/RFC7030 HTTPS messages=
.=20

- max


>=20
> Best regards, Rene
>=20
>=20
>=20
> On 5/5/2014 3:57 PM, Max Pritikin (pritikin) wrote:
>> I understand the concern regarding "dangling state=94 but counter that t=
his:
>> 	* is on the client that initiated the connection (no scaling issues)
>> 	* consistent with the current TLS handshake (no extensions)
>> 	* consistent with common TLS APIs (easy to develop using off the shelf =
components)
>> 	* does not persist across connections (there is no need to maintain sta=
te that spans TLS sessions)
>> 	* minimal integration/modification of the TLS handshake minimizes poten=
tial difficulties with TLSv3
>>=20
>> Since bootstrapping is a limited occurrence, and all state is on the cli=
ent anyway, I=92d lean in that direction over a more optimized handshake.
>>=20
>> - max
>>=20
>>=20
>> On May 5, 2014, at 1:07 PM, Rene Struik <rstruik.ext@gmail.com> wrote:
>>=20
>>> Hi Max:
>>>=20
>>> Some comments below.
>>>=20
>>> Rene
>>>=20
>>> On 5/5/2014 2:10 PM, Max Pritikin (pritikin) wrote:
>>> [snip]
>>>> |<----domain certificate----| | In this fashion it is a =93/BootstrapR=
equest=94 extension to RFC7030 Enrollment over Secure Transport. The basic =
message elements are all as you described but I=92ve simply re-ordered them=
 to better match the TLS and EST flows which minimizes the integration effo=
rts.
>>>>>   +---------+                +----------+                +-----------=
+
>>>>>   |  New    |                |          |                |  Factory  =
|
>>>>>   | Entity  |                |  Domain  |                |   Cloud   =
|
>>>>>   |         |                |          |                |  Service  =
|
>>>>>   +---------+                +----------+                +-----------=
+
>>>>>       |                           |                            |
>>>>>       |<-------discovery-(A)----->|                            |
>>>>>       |-----TLS ClientHello (B)-->|                            |
>>>>>       |     (802.1AR cred)        |                            |
>>>>>       |                           |---802.1AR identity(C)----->|
>>>>>       |                           |---Domain ID--------------->|
>>>>>       |                           |                    [device belong=
s]
>>>>>       |                           |                    [to domain?   =
 ]
>>>>>       |                           |                            |
>>>>>       |                           |<---device history log(D)---|
>>>>>       |                    [ accept device? ]                  |
>>>>>       |<------ServerHello-(E)-----|                            |
>>>>>       |                           |------- claim device -(F)-->|
>>>>>       |                           |                  [update audit lo=
g]
>>>>>       |                           |<----- authz token --(G)----|
>>>>>       |                           |      (802.1AR cert)        |
>>>>>       |                           |                            |
>>>>>       |                  [ still accept device?]               |
>>>>>       |<----ServerCertificate-(H)-|                            |
>>>>>       |                           |                            |
>>>>>  [validate cert chain? (I)]       |                            |
>>>>>       |                           |                            |
>>>>>       |---ClientCertificate-(J)-->|                            |
>>>>>       |                           |                            |
>>>>>       |                           |                            |
>>>>>       |----domain enrolment------>|                            |
>>>>>       |<----domain certificate----|                            |
>>>>>=20
>>>>>=20
>>>>> A  Proxy Discovery (A)
>>>>> B  TLS ClientHello
>>>>>   This part has to include two things which are not exactly common TL=
S.
>>>>>   1) it must have a TrustedAuthorities (6066) indicating what it's Fa=
ctor CA
>>>>>   2) it must include its IDevID somewhere, TBD.
>>>> RFC6066 TrustedAuthority won=92t help here because Domain is unlikely =
to have a useful certificate issued by the Factory Cloud Service.
>>>>=20
>>>> Instead the New Entity would provisionally accept the TLS communicatio=
ns w/o being able to verify the Domain credential. It submits its IDevID in=
 response (during =91J=92) but the entire session is still provisional.
>>>>=20
>>> RS>>
>>> It may be undesirable to have provisional sessions, if only because of =
the amount of dangling state one has to keep and because of time-outs and n=
esting issues. Once some of the missing info that prevented proper authenti=
cation has been provided to the new entity and/or network representative, p=
roper authenticated key agreement can be realized.
>>> <<RS
>>>=20
>>> --=20
>>> email: rstruik.ext@gmail.com | Skype: rstruik
>>> cell: +1 (647) 867-5658 | US: +1 (415) 690-7363
>>>=20
>=20
>=20
> --=20
> email: rstruik.ext@gmail.com | Skype: rstruik
> cell: +1 (647) 867-5658 | US: +1 (415) 690-7363
>=20


From nobody Wed May  7 13:39:56 2014
Return-Path: <mcr@sandelman.ca>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 410471A03DF for <6tisch-security@ietfa.amsl.com>; Wed,  7 May 2014 13:39:55 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.532
X-Spam-Level: 
X-Spam-Status: No, score=-2.532 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RP_MATCHES_RCVD=-0.651, SPF_PASS=-0.001, T_MIME_NO_TEXT=0.01, T_TVD_MIME_NO_HEADERS=0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id L-tmgL9apJDN for <6tisch-security@ietfa.amsl.com>; Wed,  7 May 2014 13:39:54 -0700 (PDT)
Received: from tuna.sandelman.ca (tuna.sandelman.ca [IPv6:2607:f0b0:f:3::184]) by ietfa.amsl.com (Postfix) with ESMTP id EAD8B1A01AC for <6tisch-security@ietf.org>; Wed,  7 May 2014 13:39:53 -0700 (PDT)
Received: from sandelman.ca (obiwan.sandelman.ca [IPv6:2607:f0b0:f:2::247]) by tuna.sandelman.ca (Postfix) with ESMTP id 01EC12002C for <6tisch-security@ietf.org>; Wed,  7 May 2014 16:41:24 -0400 (EDT)
Received: by sandelman.ca (Postfix, from userid 179) id 0874A63ABD; Wed,  7 May 2014 16:39:48 -0400 (EDT)
Received: from sandelman.ca (localhost [127.0.0.1]) by sandelman.ca (Postfix) with ESMTP id EB09863AB6 for <6tisch-security@ietf.org>; Wed,  7 May 2014 16:39:48 -0400 (EDT)
From: Michael Richardson <mcr+ietf@sandelman.ca>
To: 6tisch-security <6tisch-security@ietf.org>
X-Attribution: mcr
X-Mailer: MH-E 8.2; nmh 1.3-dev; GNU Emacs 23.4.1
X-Face: $\n1pF)h^`}$H>Hk{L"x@)JS7<%Az}5RyS@k9X%29-lHB$Ti.V>2bi.~ehC0; <'$9xN5Ub# z!G,p`nR&p7Fz@^UXIn156S8.~^@MJ*mMsD7=QFeq%AL4m<nPbLgmtKK-5dC@#:k
MIME-Version: 1.0
Content-Type: multipart/signed; boundary="=-=-="; micalg=pgp-sha1; protocol="application/pgp-signature"
Date: Wed, 07 May 2014 16:39:48 -0400
Message-ID: <13631.1399495188@sandelman.ca>
Sender: mcr@sandelman.ca
Archived-At: http://mailarchive.ietf.org/arch/msg/6tisch-security/BWQszQGNoVskhf037ihPS8IkxPo
Subject: [6tisch-security] conference call schedule
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 07 May 2014 20:39:55 -0000

--=-=-=


Looking at my calendar, I realized that I'm supposed to be in a doctor's
office on the morning of Monday May 26th.  In addition, that is US Memorial Day.
I propose to either reschedule the call or cancel it.

Monday May 19th is Victoria Day in Canada, an important holiday for all
Canadians who like beer. (Canadians who don't like beer spend the day
complaining about beer)

Despite that, let's go ahead with the call if that is okay.

--
Michael Richardson <mcr+IETF@sandelman.ca>, Sandelman Software Works
 -= IPv6 IoT consulting =-




--=-=-=
Content-Type: application/pgp-signature

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iQEVAwUBU2qaFICLcPvd0N1lAQKVcQf+PX1aWEkNoWoFDn13kwf1DY165m72gLDC
VO5D+BJsdfX7oj+axsCOv97a+obhuLJmf+8pdqP6goOhn5LPjcN9ArIge0Th4Nym
UbOl5oX3c47V2IJZQfDG/5/ZHdwhFJfkOS8drv0/0esrIVTOZI/FIWvakk6mdxXF
f4bw5QGt/M/MWXNyQex42jNWEem2H5B7ubHLMTP6jAeS4QCYnngLSOEnf3jWQulc
9kKg5Hfmu/wv2NMXekwza0YbKql0pTF3hDsrydPjQHKfUi1j8CjK3OsGPWtm/F2x
l3ur23Bekl+27SybBIwAH5hzQkw+mWA4Fa8DhULinrzHZ3QxTnmmqw==
=9fSO
-----END PGP SIGNATURE-----
--=-=-=--


From nobody Wed May  7 18:50:57 2014
Return-Path: <rstruik.ext@gmail.com>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 606AB1A0469 for <6tisch-security@ietfa.amsl.com>; Wed,  7 May 2014 18:50:42 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.999
X-Spam-Level: 
X-Spam-Status: No, score=-1.999 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id WYnA-27u6NmA for <6tisch-security@ietfa.amsl.com>; Wed,  7 May 2014 18:50:38 -0700 (PDT)
Received: from mail-ie0-x22a.google.com (mail-ie0-x22a.google.com [IPv6:2607:f8b0:4001:c03::22a]) by ietfa.amsl.com (Postfix) with ESMTP id 7A8B41A045E for <6tisch-security@ietf.org>; Wed,  7 May 2014 18:50:38 -0700 (PDT)
Received: by mail-ie0-f170.google.com with SMTP id rd18so1940194iec.29 for <6tisch-security@ietf.org>; Wed, 07 May 2014 18:50:34 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113;  h=message-id:date:from:user-agent:mime-version:to:subject:references :in-reply-to:content-type; bh=t60+KTyUXyg0pxdX/RPpSiWgCugtWOAkOoYnsmwJNho=; b=X1nqsIun+3m0yM+Kk6TRSd2QtYYCgsDH+GFqt6HVyB6MsadCRhYAEPx+u2aVs/mYeO 1qxQpzAx6xtNsUdPm4W9EKQ/MyuC/Smre6JpU+Lu9pHCFJ0HAICAsvzdxmNBo10O7etA bynDrWhd61D70zs3xS1CMo+/8lz2uV9XyX9APMAfTMF0ZTJDGdm/K5DoaVmSPPHlkNqJ GTfoWYbo9xSq+xhmxpRc0F0bLn57o7jhNHpxVMvQe+VzEh/0Yb7TMGxCZXgj7HUpaI2C AmQCeMm5DMPQinnfC0eqlTAGigx/zNe8wnslW1CaCnSdrtaF4EojqWVGQ8RF0Qb26LAn DAvg==
X-Received: by 10.50.43.134 with SMTP id w6mr2704885igl.3.1399513834096; Wed, 07 May 2014 18:50:34 -0700 (PDT)
Received: from [192.168.1.104] (CPE0013100e2c51-CM001cea35caa6.cpe.net.cable.rogers.com. [99.231.3.110]) by mx.google.com with ESMTPSA id qh3sm1865478igb.17.2014.05.07.18.50.32 for <multiple recipients> (version=TLSv1 cipher=ECDHE-RSA-RC4-SHA bits=128/128); Wed, 07 May 2014 18:50:33 -0700 (PDT)
Message-ID: <536AE2E5.6000106@gmail.com>
Date: Wed, 07 May 2014 21:50:29 -0400
From: Rene Struik <rstruik.ext@gmail.com>
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:24.0) Gecko/20100101 Thunderbird/24.5.0
MIME-Version: 1.0
To: Michael Richardson <mcr+ietf@sandelman.ca>,  6tisch-security <6tisch-security@ietf.org>
References: <13631.1399495188@sandelman.ca>
In-Reply-To: <13631.1399495188@sandelman.ca>
Content-Type: multipart/alternative; boundary="------------030903020407010504060500"
Archived-At: http://mailarchive.ietf.org/arch/msg/6tisch-security/rqhqXC2Cwaj_idJKsL01cRkYSU0
Subject: Re: [6tisch-security] conference call schedule
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 08 May 2014 01:50:42 -0000

This is a multi-part message in MIME format.
--------------030903020407010504060500
Content-Type: text/plain; charset=ISO-8859-1; format=flowed
Content-Transfer-Encoding: 7bit

Hi Michael:

I do not want to disrupt planning, but would prefer the Canadian holiday 
(Mon May 19th) to be kept free. I will be away and, although I can 
dial-in, will not have internet access.

What about we have a call on Tuesday (same time) instead?

One suggestion: I think we should look into detailed technical topics 
that need to be addressed. I brought up some (e.g., piggy-backing 
configuration info, advantage of using local scheduling for join, 
heterogeneous deployment models) and so did others, but there is no 
closure on any of these. Perhaps, we need to rethink how we best make 
progress.

Best regards, Rene


On 5/7/2014 4:39 PM, Michael Richardson wrote:
> Looking at my calendar, I realized that I'm supposed to be in a doctor's
> office on the morning of Monday May 26th.  In addition, that is US Memorial Day.
> I propose to either reschedule the call or cancel it.
>
> Monday May 19th is Victoria Day in Canada, an important holiday for all
> Canadians who like beer. (Canadians who don't like beer spend the day
> complaining about beer)
>
> Despite that, let's go ahead with the call if that is okay.
>
> --
> Michael Richardson <mcr+IETF@sandelman.ca>, Sandelman Software Works
>   -= IPv6 IoT consulting =-
>
>
>
>
>
> _______________________________________________
> 6tisch-security mailing list
> 6tisch-security@ietf.org
> https://www.ietf.org/mailman/listinfo/6tisch-security


-- 
email: rstruik.ext@gmail.com | Skype: rstruik
cell: +1 (647) 867-5658 | US: +1 (415) 690-7363


--------------030903020407010504060500
Content-Type: text/html; charset=ISO-8859-1
Content-Transfer-Encoding: 7bit

<html>
  <head>
    <meta content="text/html; charset=ISO-8859-1"
      http-equiv="Content-Type">
  </head>
  <body bgcolor="#FFFFFF" text="#000000">
    <div class="moz-cite-prefix">Hi Michael:<br>
      <br>
      I do not want to disrupt planning, but would prefer the Canadian
      holiday (Mon May 19th) to be kept free. I will be away and,
      although I can dial-in, will not have internet access.<br>
      <br>
      What about we have a call on Tuesday (same time) instead? <br>
      <br>
      One suggestion: I think we should look into detailed technical
      topics that need to be addressed. I brought up some (e.g.,
      piggy-backing configuration info, advantage of using local
      scheduling for join, heterogeneous deployment models) and so did
      others, but there is no closure on any of these. Perhaps, we need
      to rethink how we best make progress.<br>
      <br>
      Best regards, Rene<br>
      <br>
      <br>
      On 5/7/2014 4:39 PM, Michael Richardson wrote:<br>
    </div>
    <blockquote cite="mid:13631.1399495188@sandelman.ca" type="cite">
      <pre wrap="">
Looking at my calendar, I realized that I'm supposed to be in a doctor's
office on the morning of Monday May 26th.  In addition, that is US Memorial Day.
I propose to either reschedule the call or cancel it.

Monday May 19th is Victoria Day in Canada, an important holiday for all
Canadians who like beer. (Canadians who don't like beer spend the day
complaining about beer)

Despite that, let's go ahead with the call if that is okay.

--
Michael Richardson <a class="moz-txt-link-rfc2396E" href="mailto:mcr+IETF@sandelman.ca">&lt;mcr+IETF@sandelman.ca&gt;</a>, Sandelman Software Works
 -= IPv6 IoT consulting =-



</pre>
      <br>
      <fieldset class="mimeAttachmentHeader"></fieldset>
      <br>
      <pre wrap="">_______________________________________________
6tisch-security mailing list
<a class="moz-txt-link-abbreviated" href="mailto:6tisch-security@ietf.org">6tisch-security@ietf.org</a>
<a class="moz-txt-link-freetext" href="https://www.ietf.org/mailman/listinfo/6tisch-security">https://www.ietf.org/mailman/listinfo/6tisch-security</a>
</pre>
    </blockquote>
    <br>
    <br>
    <pre class="moz-signature" cols="72">-- 
email: <a class="moz-txt-link-abbreviated" href="mailto:rstruik.ext@gmail.com">rstruik.ext@gmail.com</a> | Skype: rstruik
cell: +1 (647) 867-5658 | US: +1 (415) 690-7363</pre>
  </body>
</html>

--------------030903020407010504060500--


From nobody Thu May  8 06:50:29 2014
Return-Path: <mcr@sandelman.ca>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 60AAC1A065E for <6tisch-security@ietfa.amsl.com>; Thu,  8 May 2014 06:50:26 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.542
X-Spam-Level: 
X-Spam-Status: No, score=-2.542 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RP_MATCHES_RCVD=-0.651, SPF_PASS=-0.001, T_TVD_MIME_NO_HEADERS=0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 6FMDdsnQEAyA for <6tisch-security@ietfa.amsl.com>; Thu,  8 May 2014 06:50:21 -0700 (PDT)
Received: from tuna.sandelman.ca (tuna.sandelman.ca [209.87.252.184]) by ietfa.amsl.com (Postfix) with ESMTP id B30B31A02D0 for <6tisch-security@ietf.org>; Thu,  8 May 2014 06:50:21 -0700 (PDT)
Received: from sandelman.ca (desk.marajade.sandelman.ca [209.87.252.247]) by tuna.sandelman.ca (Postfix) with ESMTP id 7F2F420033; Thu,  8 May 2014 09:51:51 -0400 (EDT)
Received: by sandelman.ca (Postfix, from userid 179) id 285E463ABD; Thu,  8 May 2014 09:50:10 -0400 (EDT)
Received: from sandelman.ca (localhost [127.0.0.1]) by sandelman.ca (Postfix) with ESMTP id 0F22A63AB6; Thu,  8 May 2014 09:50:10 -0400 (EDT)
From: Michael Richardson <mcr+ietf@sandelman.ca>
To: Rene Struik <rstruik.ext@gmail.com>
In-Reply-To: <536AE2E5.6000106@gmail.com>
References: <13631.1399495188@sandelman.ca> <536AE2E5.6000106@gmail.com>
X-Mailer: MH-E 8.2; nmh 1.3-dev; GNU Emacs 23.4.1
X-Face: $\n1pF)h^`}$H>Hk{L"x@)JS7<%Az}5RyS@k9X%29-lHB$Ti.V>2bi.~ehC0; <'$9xN5Ub# z!G,p`nR&p7Fz@^UXIn156S8.~^@MJ*mMsD7=QFeq%AL4m<nPbLgmtKK-5dC@#:k
MIME-Version: 1.0
Content-Type: multipart/signed; boundary="=-=-="; micalg=pgp-sha1; protocol="application/pgp-signature"
Date: Thu, 08 May 2014 09:50:10 -0400
Message-ID: <9280.1399557010@sandelman.ca>
Sender: mcr@sandelman.ca
Archived-At: http://mailarchive.ietf.org/arch/msg/6tisch-security/VMENiG0elJCWYxDX7mTo5nVozgQ
Cc: 6tisch-security <6tisch-security@ietf.org>
Subject: Re: [6tisch-security] conference call schedule
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 08 May 2014 13:50:26 -0000

--=-=-=


Rene Struik <rstruik.ext@gmail.com> wrote:
    > What about we have a call on Tuesday (same time) instead?

I'm open to this.
Objections to moving the call from the 19th to the 20th?

    > One suggestion: I think we should look into detailed technical topics
    > that need to be addressed. I brought up some (e.g., piggy-backing
    > configuration info, advantage of using local scheduling for join,
    > heterogeneous deployment models) and so did others, but there is no
    > closure on any of these. Perhaps, we need to rethink how we best make
    > progress.

can you please suggest:
1) the detailed questions.
2) the possible answers.

--
Michael Richardson <mcr+IETF@sandelman.ca>, Sandelman Software Works
 -= IPv6 IoT consulting =-

--=-=-=
Content-Type: application/pgp-signature

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iQEVAwUBU2uLjYCLcPvd0N1lAQLxOAf/ZmbVnZB+Tj1K/5YiNRNCGRty2NHB7Pv4
8H4T9OEHJw24xOTL6MBv6uPYLh+gckF70zyjU41cu2dP0q2VzO/eJyd9e87vt4Go
d2OvYuhK7YFcflrojkg/wkxiVOZB0fqwh3c3WfceknQOZ6IlkqWi7gueJOhHaZ/o
cPw6dPV5kK97TQOdBq1xsADhrtmDPH8az2nXGdBHabvTwcMEtsFtJ7QHWfHbtF/6
D9j9VQB5WcCsJbSw0wd6xLBQRQGmZuAajYywMHJ3mX4Y3BUq6OzwOgZdslyQlryN
C8FVITD9pFRCyK2rRGPUBMl36DC8zSmgdWaeL6+GmjciOkvvhwpNEw==
=nNEX
-----END PGP SIGNATURE-----
--=-=-=--


From nobody Thu May  8 06:56:17 2014
Return-Path: <rstruik.ext@gmail.com>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 159441A0667 for <6tisch-security@ietfa.amsl.com>; Thu,  8 May 2014 06:56:14 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2
X-Spam-Level: 
X-Spam-Status: No, score=-2 tagged_above=-999 required=5 tests=[BAYES_00=-1.9,  DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id zakD5uA2qaGT for <6tisch-security@ietfa.amsl.com>; Thu,  8 May 2014 06:56:12 -0700 (PDT)
Received: from mail-ie0-x234.google.com (mail-ie0-x234.google.com [IPv6:2607:f8b0:4001:c03::234]) by ietfa.amsl.com (Postfix) with ESMTP id 8B94C1A02F0 for <6tisch-security@ietf.org>; Thu,  8 May 2014 06:56:12 -0700 (PDT)
Received: by mail-ie0-f180.google.com with SMTP id as1so2595151iec.39 for <6tisch-security@ietf.org>; Thu, 08 May 2014 06:56:08 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113;  h=message-id:date:from:user-agent:mime-version:to:cc:subject :references:in-reply-to:content-type:content-transfer-encoding; bh=mRRR92UYhQTf0awACfRaOJkqL6Al6d6x5j/croqpIfo=; b=FZL99/uLHFHMXcr4J5yTrZqlLzr4rg8u97Qyhkhjg6YccNME61Ag27HLw9YVE0lLku iPNVp1hmTpe69vZkxqOuD2SBoCtoJZQBAj8ePEANm2Fms4m/sDcDUSReyOoP9S4fJoWu vpVeLxtu76mLroweohks85GYoKCK/y2PO7DH9C+4ERqoT29rQ/6tJLQmdzDRGu7ogplI OwenUSScaH6gj3myelzaBJyxROOSZ1OIPhhCLWjb577me9NPHGrrmMJAUZyDEwevVJHQ IPHl0gl0gFsKFOQ9qkjYcUlFfeerIjUoXb5VOV6RWGY/DLFgCDX0RTbDQrObGBJY+ydp 1Qcw==
X-Received: by 10.50.143.34 with SMTP id sb2mr55773080igb.48.1399557368066; Thu, 08 May 2014 06:56:08 -0700 (PDT)
Received: from [192.168.1.103] (CPE0013100e2c51-CM001cea35caa6.cpe.net.cable.rogers.com. [99.231.3.110]) by mx.google.com with ESMTPSA id k8sm4942528ige.0.2014.05.08.06.56.05 for <multiple recipients> (version=TLSv1 cipher=ECDHE-RSA-RC4-SHA bits=128/128); Thu, 08 May 2014 06:56:06 -0700 (PDT)
Message-ID: <536B8CF2.1080402@gmail.com>
Date: Thu, 08 May 2014 09:56:02 -0400
From: Rene Struik <rstruik.ext@gmail.com>
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:24.0) Gecko/20100101 Thunderbird/24.5.0
MIME-Version: 1.0
To: Michael Richardson <mcr+ietf@sandelman.ca>
References: <13631.1399495188@sandelman.ca> <536AE2E5.6000106@gmail.com> <9280.1399557010@sandelman.ca>
In-Reply-To: <9280.1399557010@sandelman.ca>
Content-Type: text/plain; charset=ISO-8859-1; format=flowed
Content-Transfer-Encoding: 7bit
Archived-At: http://mailarchive.ietf.org/arch/msg/6tisch-security/Aj237JPZGkgmtauuDXvSZ8yACM8
Cc: 6tisch-security <6tisch-security@ietf.org>
Subject: Re: [6tisch-security] conference call schedule
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 08 May 2014 13:56:14 -0000

Hi Michael:

Thanks! (There will be some drinking of beer on Canada Day, but also 
some remoteness aspects [and good reminder that online connectivity is 
not always assured]).

I will prepare some material on detailed technical topics and potential 
solution directions for the next conf call.

Best regards, Rene

On 5/8/2014 9:50 AM, Michael Richardson wrote:
> Rene Struik <rstruik.ext@gmail.com> wrote:
>      > What about we have a call on Tuesday (same time) instead?
>
> I'm open to this.
> Objections to moving the call from the 19th to the 20th?
>
>      > One suggestion: I think we should look into detailed technical topics
>      > that need to be addressed. I brought up some (e.g., piggy-backing
>      > configuration info, advantage of using local scheduling for join,
>      > heterogeneous deployment models) and so did others, but there is no
>      > closure on any of these. Perhaps, we need to rethink how we best make
>      > progress.
>
> can you please suggest:
> 1) the detailed questions.
> 2) the possible answers.
>
> --
> Michael Richardson <mcr+IETF@sandelman.ca>, Sandelman Software Works
>   -= IPv6 IoT consulting =-


-- 
email: rstruik.ext@gmail.com | Skype: rstruik
cell: +1 (647) 867-5658 | US: +1 (415) 690-7363


From nobody Thu May  8 08:39:08 2014
Return-Path: <tom.phinney@cox.net>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 7346C1A0096 for <6tisch-security@ietfa.amsl.com>; Thu,  8 May 2014 08:39:06 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.542
X-Spam-Level: 
X-Spam-Status: No, score=-2.542 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_NONE=-0.0001, RP_MATCHES_RCVD=-0.651, SPF_PASS=-0.001, T_FSL_HELO_BARE_IP_2=0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 8aQVwNBg0RQt for <6tisch-security@ietfa.amsl.com>; Thu,  8 May 2014 08:39:05 -0700 (PDT)
Received: from fed1rmfepo101.cox.net (fed1rmfepo101.cox.net [68.230.241.143]) by ietfa.amsl.com (Postfix) with ESMTP id ADCED1A00A8 for <6tisch-security@ietf.org>; Thu,  8 May 2014 08:39:03 -0700 (PDT)
Received: from fed1rmimpo306 ([68.230.241.174]) by fed1rmfepo101.cox.net (InterMail vM.8.01.05.15 201-2260-151-145-20131218) with ESMTP id <20140508153859.HOVP11537.fed1rmfepo101.cox.net@fed1rmimpo306> for <6tisch-security@ietf.org>; Thu, 8 May 2014 11:38:59 -0400
Received: from 192.168.1.102 ([68.110.82.164]) by fed1rmimpo306 with cox id zTey1n00c3YjG0401TeyRe; Thu, 08 May 2014 11:38:58 -0400
X-CT-Class: Clean
X-CT-Score: 0.00
X-CT-RefID: str=0001.0A020203.536BA513.000F,ss=1,re=0.000,fgs=0
X-CT-Spam: 0
X-Authority-Analysis: v=2.0 cv=Ve8pyiV9 c=1 sm=1 a=/lROMdMM8hnpqyhFWVF1XA==:17 a=IuL6hPCtAYgA:10 a=qxAvoatswAUA:10 a=G8Uczd0VNMoA:10 a=Wajolswj7cQA:10 a=IkcTkHD0fZMA:10 a=kviXuzpPAAAA:8 a=pGLkceISAAAA:8 a=TFfGn3-5wTgLKj4wVqMA:9 a=QEXdDO2ut3YA:10 a=MSl-tDqOz04A:10 a=/lROMdMM8hnpqyhFWVF1XA==:117
X-CM-Score: 0.00
Authentication-Results: cox.net; none
Message-ID: <536BA512.1090403@cox.net>
Date: Thu, 08 May 2014 08:38:58 -0700
From: Tom Phinney <tom.phinney@cox.net>
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.6; rv:24.0) Gecko/20100101 Thunderbird/24.5.0
MIME-Version: 1.0
To: 6tisch-security@ietf.org
References: <13631.1399495188@sandelman.ca> <536AE2E5.6000106@gmail.com> <9280.1399557010@sandelman.ca> <zRwB1n00l0xxhYs01RwC8G>
In-Reply-To: <zRwB1n00l0xxhYs01RwC8G>
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 8bit
Archived-At: http://mailarchive.ietf.org/arch/msg/6tisch-security/5bety2HG4y99Vf1TBzyOXS4l3rM
Subject: Re: [6tisch-security] conference call schedule
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
Reply-To: Tom Phinney <tom.phinney@cox.net>
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 08 May 2014 15:39:06 -0000

If we are going to delay a scheduled conference call by one day for a 
Canadian holiday, why not do the same one week later for the US holiday? 
I'm not averse to this precedent but it should apply to all active 
participants' countries of residence.

Incidentally, I thought that May 19 was Victoria Day and July 1 was 
Canada Day (Fête du Canada).
-Tom
====
On 2014.05.08 06:56, Rene Struik wrote:
> Hi Michael:
>
> Thanks! (There will be some drinking of beer on Canada Day, but also 
> some remoteness aspects [and good reminder that online connectivity is 
> not always assured]).
>
> I will prepare some material on detailed technical topics and 
> potential solution directions for the next conf call.
>
> Best regards, Rene
>
> On 5/8/2014 9:50 AM, Michael Richardson wrote:
>> Rene Struik <rstruik.ext@gmail.com> wrote:
>>      > What about we have a call on Tuesday (same time) instead?
>>
>> I'm open to this.
>> Objections to moving the call from the 19th to the 20th?
>>
>>      > One suggestion: I think we should look into detailed technical 
>> topics
>>      > that need to be addressed. I brought up some (e.g., piggy-backing
>>      > configuration info, advantage of using local scheduling for join,
>>      > heterogeneous deployment models) and so did others, but there 
>> is no
>>      > closure on any of these. Perhaps, we need to rethink how we 
>> best make
>>      > progress.
>>
>> can you please suggest:
>> 1) the detailed questions.
>> 2) the possible answers.
>>
>> -- 
>> Michael Richardson <mcr+IETF@sandelman.ca>, Sandelman Software Works
>>   -= IPv6 IoT consulting =-
>
>


From nobody Thu May  8 12:48:36 2014
Return-Path: <mcr@sandelman.ca>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id A46921A00F2 for <6tisch-security@ietfa.amsl.com>; Thu,  8 May 2014 12:48:26 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.552
X-Spam-Level: 
X-Spam-Status: No, score=-2.552 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RP_MATCHES_RCVD=-0.651, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Bnzstu1nTzts for <6tisch-security@ietfa.amsl.com>; Thu,  8 May 2014 12:48:25 -0700 (PDT)
Received: from tuna.sandelman.ca (tuna.sandelman.ca [IPv6:2607:f0b0:f:3::184]) by ietfa.amsl.com (Postfix) with ESMTP id E11401A00EF for <6tisch-security@ietf.org>; Thu,  8 May 2014 12:48:24 -0700 (PDT)
Received: from sandelman.ca (desk.marajade.sandelman.ca [209.87.252.247]) by tuna.sandelman.ca (Postfix) with ESMTP id D25AA2002D; Thu,  8 May 2014 15:49:57 -0400 (EDT)
Received: by sandelman.ca (Postfix, from userid 179) id 5646B63ABD; Thu,  8 May 2014 15:48:16 -0400 (EDT)
Received: from sandelman.ca (localhost [127.0.0.1]) by sandelman.ca (Postfix) with ESMTP id 4128363AB6; Thu,  8 May 2014 15:48:16 -0400 (EDT)
From: Michael Richardson <mcr+ietf@sandelman.ca>
To: 6tisch-security@ietf.org
In-Reply-To: <536BA512.1090403@cox.net>
References: <13631.1399495188@sandelman.ca> <536AE2E5.6000106@gmail.com> <9280.1399557010@sandelman.ca> <zRwB1n00l0xxhYs01RwC8G> <536BA512.1090403@cox.net>
X-Mailer: MH-E 8.2; nmh 1.3-dev; GNU Emacs 23.4.1
X-Face: $\n1pF)h^`}$H>Hk{L"x@)JS7<%Az}5RyS@k9X%29-lHB$Ti.V>2bi.~ehC0; <'$9xN5Ub# z!G,p`nR&p7Fz@^UXIn156S8.~^@MJ*mMsD7=QFeq%AL4m<nPbLgmtKK-5dC@#:k
MIME-Version: 1.0
Content-Type: multipart/signed; boundary="=-=-="; micalg=pgp-sha1; protocol="application/pgp-signature"
Date: Thu, 08 May 2014 15:48:16 -0400
Message-ID: <19029.1399578496@sandelman.ca>
Sender: mcr@sandelman.ca
Archived-At: http://mailarchive.ietf.org/arch/msg/6tisch-security/3sGkRvmh43EdiKR78DQPhBqMpLM
Cc: Tom Phinney <tom.phinney@cox.net>
Subject: Re: [6tisch-security] conference call schedule
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 08 May 2014 19:48:26 -0000

--=-=-=
Content-Type: text/plain; charset=utf-8
Content-Transfer-Encoding: quoted-printable


Tom Phinney <tom.phinney@cox.net> wrote:
    > If we are going to delay a scheduled conference call by one day for a
    > Canadian holiday, why not do the same one week later for the US
    > holiday? I'm

okay.

    > Incidentally, I thought that May 19 was Victoria Day and July 1 was
    > Canada  Day (F=C3=AAte du Canada).

True. Not sure why Rene wrote differently.
In general the May "24th" weekend, is the beer drinking weekend, because it
involves opening cottages up, and partaking of a two-four, which is the
largest unit of beer (bottles/cans) which is sold.

So revised schedule is:
   2014-05-12 10:00am
   2014-05-20 10:00am
   2014-05-27 10:00am
   2014-05-02 10:00am

If you want to be added to my iCal event, drop me an email and say so.


=2D-
Michael Richardson <mcr+IETF@sandelman.ca>, Sandelman Software Works
 -=3D IPv6 IoT consulting =3D-




--=-=-=
Content-Type: application/pgp-signature

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iQEVAwUBU2vffYCLcPvd0N1lAQJp+Af9Hte/hVrsH9fGAlxtHESWuREkgMHefq2m
lgNN+8h3dB+MhYm2GZnFcEijiNeq32afq1QwLOqFWMSPMogNf/tlYTGr9cJApRrI
ZFjUtaA1lDkRu/fOtLzgJd+1/7fgMY0svlzaoRtGwBLoIn8+Ky0HOzjE8XpDPMC9
P6wZyY/G8LCz/zwkvtjnQ94WRd8/UlhMLWFWkYfNvEsI+kZlIXiERPX8BEQyi1IB
fomysMNaYCDGNdhrZFvmq5AKCB3/BNCJKF6VqUxkyvbUhunM3yX5O18eWvl73LvT
6G4O3uXrnKMfA7ZOuVnZ8i6i7dB+zAssoMtTTcprZQDc1Sn8KJxBAQ==
=ac40
-----END PGP SIGNATURE-----
--=-=-=--


From nobody Thu May  8 23:41:32 2014
Return-Path: <pthubert@cisco.com>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id AE2891A01F0 for <6tisch-security@ietfa.amsl.com>; Thu,  8 May 2014 23:41:31 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.15
X-Spam-Level: 
X-Spam-Status: No, score=-1.15 tagged_above=-999 required=5 tests=[BAYES_05=-0.5, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, HTML_MESSAGE=0.001, LOTS_OF_MONEY=0.001, RP_MATCHES_RCVD=-0.651, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id BqEqQHs3Dqb0 for <6tisch-security@ietfa.amsl.com>; Thu,  8 May 2014 23:41:29 -0700 (PDT)
Received: from alln-iport-8.cisco.com (alln-iport-8.cisco.com [173.37.142.95]) by ietfa.amsl.com (Postfix) with ESMTP id 86CC61A01EB for <6tisch-security@ietf.org>; Thu,  8 May 2014 23:41:29 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cisco.com; i=@cisco.com; l=17852; q=dns/txt; s=iport; t=1399617685; x=1400827285; h=from:to:subject:sender:date:message-id:references: in-reply-to:mime-version; bh=HaAimUM5aXOttLYepgVGceai/9L8p4wb75DxcifDXGY=; b=PpMzFF+hxQta2XDOlAKNtm2cqPnI6y2e2vSnqmX2Ce+VCQXwRJ2kNkI3 5LgcL38mNwR1kF0AQNiOqEGeonxG014AAyTeq3k4YG+/422M39G+vIMXG RcWROR+4MBi3heZO2x2TP/BnVQzoalvtMLncBBpy6k64cF/vhPWzb0a+B 4=;
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-Anti-Spam-Result: AhQFACF4bFOtJV2a/2dsb2JhbAA/FwOCQkRPWIJnwlABGXsWdIIlAQEBBCMKGw0RIwEBAQgRAwEBAQsKAQMMAwMCAgIwFAcBAQUCAQEBAQMTCIg5DTaraYQqEaAgF44OMw0KCwcHgl02gRUEhFpximSKT5FAgmNTbYEJOXg
X-IronPort-AV: E=Sophos;i="4.97,1016,1389744000";  d="scan'208,217";a="42376699"
Received: from rcdn-core-3.cisco.com ([173.37.93.154]) by alln-iport-8.cisco.com with ESMTP; 09 May 2014 06:41:10 +0000
Received: from xhc-aln-x01.cisco.com (xhc-aln-x01.cisco.com [173.36.12.75]) by rcdn-core-3.cisco.com (8.14.5/8.14.5) with ESMTP id s496fAad009566 (version=TLSv1/SSLv3 cipher=AES128-SHA bits=128 verify=FAIL) for <6tisch-security@ietf.org>; Fri, 9 May 2014 06:41:10 GMT
Received: from xmb-rcd-x01.cisco.com ([169.254.1.229]) by xhc-aln-x01.cisco.com ([173.36.12.75]) with mapi id 14.03.0123.003; Fri, 9 May 2014 01:41:09 -0500
From: webex <messenger@webex.com>
To: "6tisch-security@ietf.org" <6tisch-security@ietf.org>
Thread-Topic: Meeting scheduled: 6TiSCH security
Thread-Index: Ac8hAcvT7HcH1CFASnWDc4zjKF6UTRKT61qA
Sender: "Pascal Thubert (pthubert)" <pthubert@cisco.com>
Date: Fri, 9 May 2014 06:41:09 +0000
Deferred-Delivery: Fri, 9 May 2014 06:41:00 +0000
Message-ID: <E045AECD98228444A58C61C200AE1BD842642141@xmb-rcd-x01.cisco.com>
References: <E045AECD98228444A58C61C200AE1BD8416F3AD3@xmb-rcd-x01.cisco.com>
In-Reply-To: <E045AECD98228444A58C61C200AE1BD8416F3AD3@xmb-rcd-x01.cisco.com>
Accept-Language: fr-FR, en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
x-originating-ip: [10.55.22.4]
Content-Type: multipart/alternative; boundary="_000_E045AECD98228444A58C61C200AE1BD842642141xmbrcdx01ciscoc_"
MIME-Version: 1.0
Archived-At: http://mailarchive.ietf.org/arch/msg/6tisch-security/oz0QCRcfS25H6o45FHTY0y-HCtk
Subject: [6tisch-security] FW: Meeting scheduled: 6TiSCH security
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 09 May 2014 06:41:31 -0000

--_000_E045AECD98228444A58C61C200AE1BD842642141xmbrcdx01ciscoc_
Content-Type: text/plain; charset="Windows-1252"
Content-Transfer-Encoding: quoted-printable



-----Original Appointment-----
From: webex [mailto:messenger@webex.com]
Sent: lundi 3 f=E9vrier 2014 18:03
Subject: Meeting scheduled: 6TiSCH security
When: mardi 20 mai 2014 07:00-08:00 Pacific Time.
Where: https://cisco.webex.com/cisco


You are the host for this online meeting.
Topic:  6TiSCH security
Date:   Every Monday, from Monday, February 10, 2014 to Monday, February 9,=
 2015
Time:   7:00 am, Pacific Standard Time (San Francisco, GMT-08:00)
Meeting Number: 201 046 958
Meeting Password:       6urity
Host Key:       772928 (use this to reclaim host privileges)



To start the online meeting

  1.    Go to https://cisco.webex.com/cisco/j.php?MTID=3Dm2fe139bf876cea3ec=
62750cd580b7908
  2.    Log in to your account.
  3.    Click =93Start Now=94.
  4.    Follow the instructions that appear on your screen.



ALERT =96 PLEASE READ: DO NOT DIAL THE TOLL FREE NUMBERS FROM WITHIN THE (4=
08) OR (919) AREA CODES

Please dial the local access number for your area from the list below:
=95       San Jose/Milpitas (408) area:  525-6800
=95       RTP (919) area:  392-3330

Dialing the WebEx toll free numbers from within 408 or 919 area codes is no=
t enabled (non-Cisco phones).  =93 If you dial the toll-free numbers within=
 the 408 or 919 area codes you will be instructed to hang up and dial the l=
ocal access number.=94 Please use the call-back option whenever possible an=
d otherwise dial local numbers only.  The affected toll free numbers are: (=
866) 432-9903 for the San Jose/Milpitas area and (866) 349-3520 for the RTP=
 area.

-------------------------------------------------------

To join the teleconference only
-------------------------------------------------------

1.      Dial into Cisco WebEx (view all Global Access Numbers at

http://cisco.com/en/US/about/doing_business/conferencing/index.html <http:/=
/cisco.com/en/US/about/doing_business/conferencing/index.html%202>
2.      Follow the prompts to enter the Meeting Number (listed above) or Ac=
cess Code followed by the # sign.

San Jose, CA: +1.408.525.6800  RTP: +1.919.392.3330
US/Canada: +1.866.432.9903  United Kingdom: +44.20.8824.0117
India: +91.80.4350.1111  Germany: +49.619.6773.9002
Japan: +81.3.5763.9394  China: +86.10.8515.5666



For assistance

  1.    Go to https://cisco.webex.com/cisco/mc
  2.    On the left navigation bar, click =93Support=94.
To add this meeting to your calendar program (for example Microsoft Outlook=
), click this link:
https://cisco.webex.com/cisco/j.php?MTID=3Dm4cb181b8d4a0965221bb278991ac9bf=
3
To check whether you have the appropriate players installed for UCF (Univer=
sal Communications Format) rich media files, go to https://cisco.webex.com/=
cisco/systemdiagnosis.php.
http://www.webex.com
CCM:+14085256800x201046958#



--_000_E045AECD98228444A58C61C200AE1BD842642141xmbrcdx01ciscoc_
Content-Type: text/html; charset="Windows-1252"
Content-Transfer-Encoding: quoted-printable

<html>
<head>
<meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3DWindows-1=
252">
<meta name=3D"Generator" content=3D"Microsoft Exchange Server">
<!-- converted from rtf -->
<style><!-- .EmailQuote { margin-left: 1pt; padding-left: 4pt; border-left:=
 #800000 2px solid; } --></style>
</head>
<body>
<font face=3D"Calibri" size=3D"2"><span style=3D"font-size:11pt;">
<div><font color=3D"#1F497D">&nbsp;</font></div>
<div><font color=3D"#1F497D">&nbsp;</font></div>
<div style=3D"margin-bottom:6pt;">-----Original Appointment-----<br>

<b>From:</b> webex [<a href=3D"mailto:messenger@webex.com"><font face=3D"Ta=
homa" size=3D"2" color=3D"blue"><span style=3D"font-size:10pt;"><u>mailto:m=
essenger@webex.com</u></span></font></a>]
<br>

<b>Sent:</b> lundi 3 f=E9vrier 2014 18:03<br>

<b>Subject:</b> Meeting scheduled: 6TiSCH security<br>

<b>When:</b> mardi 20 mai 2014 07:00-08:00 Pacific Time.<br>

<b>Where:</b> <a href=3D"https://cisco.webex.com/cisco"><font face=3D"Tahom=
a" size=3D"2" color=3D"blue"><span style=3D"font-size:10pt;"><u>https://cis=
co.webex.com/cisco</u></span></font></a></div>
<div>&nbsp;</div>
<div>&nbsp;</div>
<div style=3D"margin-bottom:6pt;">You are the host for this online meeting.=
</div>
<div>Topic:&nbsp; 6TiSCH security</div>
<div>Date:&nbsp;&nbsp; Every Monday, from Monday, February 10, 2014 to Mond=
ay, February 9, 2015</div>
<div>Time:&nbsp;&nbsp; 7:00 am, Pacific Standard Time (San Francisco, GMT-0=
8:00)</div>
<div>Meeting Number: 201 046 958</div>
<div>Meeting Password:&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 6urity</div>
<div>Host Key:&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 772928 (use this to recl=
aim host privileges)</div>
<div>&nbsp;</div>
<div><font face=3D"Arial" size=3D"2"><span style=3D"font-size:10pt;">&nbsp;=
</span></font></div>
<div style=3D"margin-top:24pt;"><font face=3D"Cambria" size=3D"4" color=3D"=
#365F91"><span style=3D"font-size:14pt;"><b>To start the online meeting</b>=
</span></font></div>
<div><font face=3D"Arial" size=3D"2"><span style=3D"font-size:10pt;">&nbsp;=
</span></font></div>
<div style=3D"text-indent:-14.15pt;padding-left:14.15pt;">1.&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp; Go to <a href=3D"https://cisco.webex.com/cisco/j.php?MTID=
=3Dm2fe139bf876cea3ec62750cd580b7908"><font face=3D"Arial" size=3D"2" color=
=3D"blue"><span style=3D"font-size:10pt;"><u>https://cisco.webex.com/cisco/=
j.php?MTID=3Dm2fe139bf876cea3ec62750cd580b7908</u></span></font></a></div>
<div style=3D"text-indent:-14.15pt;padding-left:14.15pt;">2.&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp; Log in to your account.</div>
<div style=3D"text-indent:-14.15pt;padding-left:14.15pt;">3.&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp; Click <font color=3D"#1F497D">=93</font>Start Now<font colo=
r=3D"#1F497D">=94</font>.</div>
<div style=3D"text-indent:-14.15pt;padding-left:14.15pt;">4.&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp; Follow the instructions that appear on your screen.</div>
<div>&nbsp;</div>
<div><font face=3D"Arial" size=3D"2"><span style=3D"font-size:10pt;">&nbsp;=
</span></font></div>
<div style=3D"margin-top:10pt;"><font face=3D"Cambria" size=3D"3" color=3D"=
#4F81BD"><span style=3D"font-size:13pt;"><b>ALERT =96 PLEASE READ: DO NOT D=
IAL THE TOLL FREE NUMBERS FROM WITHIN THE (408) OR (919) AREA CODES</b></sp=
an></font></div>
<div><font face=3D"Arial" size=3D"2"><span style=3D"font-size:10pt;">&nbsp;=
</span></font></div>
<div style=3D"margin-bottom:6pt;">Please dial the local access number for y=
our area from the list below:</div>
<ul style=3D"margin:0;padding-left:18pt;">
<li>San Jose/Milpitas (408) area:&nbsp; 525-6800</li><li>RTP (919) area:&nb=
sp; 392-3330</li></ul>
<div><font face=3D"Arial" size=3D"2"><span style=3D"font-size:10pt;">&nbsp;=
</span></font></div>
<div style=3D"margin-bottom:6pt;">Dialing the WebEx toll free numbers from =
within 408 or 919 area codes is not enabled (non-Cisco phones).&nbsp; =93 I=
f you dial the toll-free numbers within the 408 or 919 area codes you will =
be instructed to hang up and dial the local
access number.=94 Please use the call-back option whenever possible and oth=
erwise dial local numbers only.&nbsp; The affected toll free numbers are: (=
866) 432-9903 for the San Jose/Milpitas area and (866) 349-3520 for the RTP=
 area.</div>
<div>&nbsp;</div>
<div><font face=3D"Arial" size=3D"2"><span style=3D"font-size:10pt;">------=
------------------------------------------------- </span></font></div>
<div style=3D"margin-top:24pt;"><font face=3D"Cambria" size=3D"4" color=3D"=
#365F91"><span style=3D"font-size:14pt;"><b>To join the teleconference only=
 </b></span></font></div>
<div><font face=3D"Arial" size=3D"2"><span style=3D"font-size:10pt;">------=
------------------------------------------------- </span></font></div>
<div style=3D"margin-top:10pt;"><font face=3D"Cambria" size=3D"3" color=3D"=
#4F81BD"><span style=3D"font-size:13pt;"><b>1.&nbsp;&nbsp;&nbsp;&nbsp;&nbsp=
; </b><b>Dial into Cisco WebEx (view all Global Access Numbers at </b></spa=
n></font></div>
<div style=3D"margin-top:10pt;"><font face=3D"Cambria" size=3D"3" color=3D"=
#4F81BD"><span style=3D"font-size:13pt;"><a href=3D"http://cisco.com/en/US/=
about/doing_business/conferencing/index.html 2"><font color=3D"blue"><b><u>=
http://cisco.com/en/US/about/doing_business/conferencing/index.html
</u></b></font></a></span></font></div>
<div style=3D"margin-top:10pt;"><font face=3D"Arial" size=3D"2" color=3D"bl=
ue"><span style=3D"font-size:10pt;"><b><u>2</u></b><font color=3D"#4F81BD">=
<b>.&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </b></font><font color=3D"#4F81BD"><b>Fo=
llow the prompts to enter the Meeting Number (listed above) or Access Code
followed by the # sign. </b></font></span></font></div>
<div>&nbsp;</div>
<div style=3D"margin-bottom:6pt;">San Jose, CA: &#43;1.408.525.6800&nbsp; R=
TP: &#43;1.919.392.3330 </div>
<div style=3D"margin-bottom:6pt;">US/Canada: &#43;1.866.432.9903&nbsp; Unit=
ed Kingdom: &#43;44.20.8824.0117 </div>
<div style=3D"margin-bottom:6pt;">India: &#43;91.80.4350.1111&nbsp; Germany=
: &#43;49.619.6773.9002 </div>
<div style=3D"margin-bottom:6pt;">Japan: &#43;81.3.5763.9394&nbsp; China: &=
#43;86.10.8515.5666</div>
<div>&nbsp;</div>
<div><font face=3D"Arial" size=3D"2"><span style=3D"font-size:10pt;">&nbsp;=
</span></font></div>
<div style=3D"margin-top:24pt;"><font face=3D"Cambria" size=3D"4" color=3D"=
#365F91"><span style=3D"font-size:14pt;"><b>For assistance</b></span></font=
></div>
<div><font face=3D"Arial" size=3D"2"><span style=3D"font-size:10pt;">&nbsp;=
</span></font></div>
<div style=3D"text-indent:-14.15pt;padding-left:14.15pt;">1.&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp; Go to <a href=3D"https://cisco.webex.com/cisco/mc"><font fa=
ce=3D"Arial" size=3D"2" color=3D"blue"><span style=3D"font-size:10pt;"><u>h=
ttps://cisco.webex.com/cisco/mc</u></span></font></a></div>
<div style=3D"text-indent:-14.15pt;padding-left:14.15pt;">2.&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp; On the left navigation bar, click <font color=3D"#1F497D">=
=93</font>Support<font color=3D"#1F497D">=94</font>.</div>
<div style=3D"margin-bottom:6pt;">To add this meeting to your calendar prog=
ram (for example Microsoft Outlook), click this link:</div>
<div style=3D"margin-bottom:6pt;"><a href=3D"https://cisco.webex.com/cisco/=
j.php?MTID=3Dm4cb181b8d4a0965221bb278991ac9bf3"><font face=3D"Arial" size=
=3D"2" color=3D"blue"><span style=3D"font-size:10pt;"><u>https://cisco.webe=
x.com/cisco/j.php?MTID=3Dm4cb181b8d4a0965221bb278991ac9bf3</u></span></font=
></a></div>
<div style=3D"margin-bottom:6pt;">To check whether you have the appropriate=
 players installed for UCF (Universal Communications Format) rich media fil=
es, go to <a href=3D"https://cisco.webex.com/cisco/systemdiagnosis.php"><fo=
nt face=3D"Arial" size=3D"2" color=3D"blue"><span style=3D"font-size:10pt;"=
><u>https://cisco.webex.com/cisco/systemdiagnosis.php</u></span></font></a>=
.</div>
<div style=3D"margin-bottom:6pt;"><a href=3D"http://www.webex.com"><font fa=
ce=3D"Arial" size=3D"2" color=3D"blue"><span style=3D"font-size:10pt;"><u>h=
ttp://www.webex.com</u></span></font></a></div>
<div style=3D"margin-bottom:6pt;">CCM:&#43;14085256800x201046958# </div>
<div>&nbsp;</div>
<div>&nbsp;</div>
</span></font>
</body>
</html>

--_000_E045AECD98228444A58C61C200AE1BD842642141xmbrcdx01ciscoc_
Content-Type: text/calendar; charset="utf-8"; method=REQUEST
Content-Transfer-Encoding: base64

QkVHSU46VkNBTEVOREFSDQpNRVRIT0Q6UkVRVUVTVA0KUFJPRElEOk1pY3Jvc29mdCBFeGNoYW5n
ZSBTZXJ2ZXIgMjAxMA0KVkVSU0lPTjoyLjANCkJFR0lOOlZUSU1FWk9ORQ0KVFpJRDpQYWNpZmlj
IFRpbWUNCkJFR0lOOlNUQU5EQVJEDQpEVFNUQVJUOjE2MDEwMTAxVDAyMDAwMA0KVFpPRkZTRVRG
Uk9NOi0wNzAwDQpUWk9GRlNFVFRPOi0wODAwDQpSUlVMRTpGUkVRPVlFQVJMWTtJTlRFUlZBTD0x
O0JZREFZPTFTVTtCWU1PTlRIPTExDQpFTkQ6U1RBTkRBUkQNCkJFR0lOOkRBWUxJR0hUDQpEVFNU
QVJUOjE2MDEwMTAxVDAyMDAwMA0KVFpPRkZTRVRGUk9NOi0wODAwDQpUWk9GRlNFVFRPOi0wNzAw
DQpSUlVMRTpGUkVRPVlFQVJMWTtJTlRFUlZBTD0xO0JZREFZPTJTVTtCWU1PTlRIPTMNCkVORDpE
QVlMSUdIVA0KRU5EOlZUSU1FWk9ORQ0KQkVHSU46VkVWRU5UDQpPUkdBTklaRVI7Q049d2ViZXg7
U0VOVC1CWT0iTUFJTFRPOnB0aHViZXJ0QGNpc2NvLmNvbSI6TUFJTFRPOm1lc3NlbmdlckB3ZWJl
eA0KIC5jb20NCkFUVEVOREVFO1JPTEU9UkVRLVBBUlRJQ0lQQU5UO1BBUlRTVEFUPU5FRURTLUFD
VElPTjtSU1ZQPUZBTFNFO0NOPTZ0aXNjaC1zZQ0KIGN1cml0eUBpZXRmLm9yZzpNQUlMVE86NnRp
c2NoLXNlY3VyaXR5QGlldGYub3JnDQpERVNDUklQVElPTjtMQU5HVUFHRT1lbi1VUzpcblxuLS0t
LS1PcmlnaW5hbCBBcHBvaW50bWVudC0tLS0tXG5Gcm9tOiB3ZWJleCANCiBbbWFpbHRvOm1lc3Nl
bmdlckB3ZWJleC5jb21dXG5TZW50OiBsdW5kaSAzIGbDqXZyaWVyIDIwMTQgMTg6MDNcblN1Ympl
Y3Q6IA0KIE1lZXRpbmcgc2NoZWR1bGVkOiA2VGlTQ0ggc2VjdXJpdHlcbldoZW46IG1hcmRpIDIw
IG1haSAyMDE0IDA3OjAwLTA4OjAwIFBhDQogY2lmaWMgVGltZS5cbldoZXJlOiBodHRwczovL2Np
c2NvLndlYmV4LmNvbS9jaXNjb1xuXG5cbllvdSBhcmUgdGhlIGhvc3QgZm8NCiByIHRoaXMgb25s
aW5lIG1lZXRpbmcuXG5Ub3BpYzogIDZUaVNDSCBzZWN1cml0eVxuRGF0ZTogICBFdmVyeSBNb25k
YXlcLCBmcg0KIG9tIE1vbmRheVwsIEZlYnJ1YXJ5IDEwXCwgMjAxNCB0byBNb25kYXlcLCBGZWJy
dWFyeSA5XCwgMjAxNVxuVGltZTogICA3OjAwDQogIGFtXCwgUGFjaWZpYyBTdGFuZGFyZCBUaW1l
IChTYW4gRnJhbmNpc2NvXCwgR01ULTA4OjAwKVxuTWVldGluZyBOdW1iZXI6IDINCiAwMSAwNDYg
OTU4XG5NZWV0aW5nIFBhc3N3b3JkOiAgICAgICA2dXJpdHlcbkhvc3QgS2V5OiAgICAgICA3NzI5
MjggKHVzZSB0aA0KIGlzIHRvIHJlY2xhaW0gaG9zdCBwcml2aWxlZ2VzKVxuXG5cblxuVG8gc3Rh
cnQgdGhlIG9ubGluZSBtZWV0aW5nXG5cbiAgMS4gDQogICAgR28gdG8gaHR0cHM6Ly9jaXNjby53
ZWJleC5jb20vY2lzY28vai5waHA/TVRJRD1tMmZlMTM5YmY4NzZjZWEzZWM2Mjc1MGMNCiBkNTgw
Yjc5MDhcbiAgMi4gICAgTG9nIGluIHRvIHlvdXIgYWNjb3VudC5cbiAgMy4gICAgQ2xpY2sg4oCc
U3RhcnQgTm934oCdLg0KIFxuICA0LiAgICBGb2xsb3cgdGhlIGluc3RydWN0aW9ucyB0aGF0IGFw
cGVhciBvbiB5b3VyIHNjcmVlbi5cblxuXG5cbkFMRVJUDQogIOKAkyBQTEVBU0UgUkVBRDogRE8g
Tk9UIERJQUwgVEhFIFRPTEwgRlJFRSBOVU1CRVJTIEZST00gV0lUSElOIFRIRSAoNDA4KSANCiBP
UiAoOTE5KSBBUkVBIENPREVTXG5cblBsZWFzZSBkaWFsIHRoZSBsb2NhbCBhY2Nlc3MgbnVtYmVy
IGZvciB5b3VyIGFyZWEgZg0KIHJvbSB0aGUgbGlzdCBiZWxvdzpcbuKAoiAgICAgICBTYW4gSm9z
ZS9NaWxwaXRhcyAoNDA4KSBhcmVhOiAgNTI1LTY4MDBcbg0KIOKAoiAgICAgICBSVFAgKDkxOSkg
YXJlYTogIDM5Mi0zMzMwXG5cbkRpYWxpbmcgdGhlIFdlYkV4IHRvbGwgZnJlZSBudW1iZXJzDQog
IGZyb20gd2l0aGluIDQwOCBvciA5MTkgYXJlYSBjb2RlcyBpcyBub3QgZW5hYmxlZCAobm9uLUNp
c2NvIHBob25lcykuICDigJwNCiAgSWYgeW91IGRpYWwgdGhlIHRvbGwtZnJlZSBudW1iZXJzIHdp
dGhpbiB0aGUgNDA4IG9yIDkxOSBhcmVhIGNvZGVzIHlvdSB3aQ0KIGxsIGJlIGluc3RydWN0ZWQg
dG8gaGFuZyB1cCBhbmQgZGlhbCB0aGUgbG9jYWwgYWNjZXNzIG51bWJlci7igJ0gUGxlYXNlIHVz
DQogZSB0aGUgY2FsbC1iYWNrIG9wdGlvbiB3aGVuZXZlciBwb3NzaWJsZSBhbmQgb3RoZXJ3aXNl
IGRpYWwgbG9jYWwgbnVtYmVycyANCiBvbmx5LiAgVGhlIGFmZmVjdGVkIHRvbGwgZnJlZSBudW1i
ZXJzIGFyZTogKDg2NikgNDMyLTk5MDMgZm9yIHRoZSBTYW4gSm9zZQ0KIC9NaWxwaXRhcyBhcmVh
IGFuZCAoODY2KSAzNDktMzUyMCBmb3IgdGhlIFJUUCBhcmVhLlxuXG4tLS0tLS0tLS0tLS0tLS0t
LS0tDQogLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tXG5cblRvIGpvaW4gdGhl
IHRlbGVjb25mZXJlbmNlIG9ubHlcbi0NCiAtLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0t
LS0tLS0tLS0tLS0tLS0tLS0tLS0tLS1cblxuMS4gICAgICBEaWFsIGludA0KIG8gQ2lzY28gV2Vi
RXggKHZpZXcgYWxsIEdsb2JhbCBBY2Nlc3MgTnVtYmVycyBhdFxuXG5odHRwOi8vY2lzY28uY29t
L2VuL1VTDQogL2Fib3V0L2RvaW5nX2J1c2luZXNzL2NvbmZlcmVuY2luZy9pbmRleC5odG1sIDxo
dHRwOi8vY2lzY28uY29tL2VuL1VTL2Fib3UNCiB0L2RvaW5nX2J1c2luZXNzL2NvbmZlcmVuY2lu
Zy9pbmRleC5odG1sJTIwMj5cbjIuICAgICAgRm9sbG93IHRoZSBwcm9tcHRzIA0KIHRvIGVudGVy
IHRoZSBNZWV0aW5nIE51bWJlciAobGlzdGVkIGFib3ZlKSBvciBBY2Nlc3MgQ29kZSBmb2xsb3dl
ZCBieSB0aGUgDQogIyBzaWduLlxuXG5TYW4gSm9zZVwsIENBOiArMS40MDguNTI1LjY4MDAgIFJU
UDogKzEuOTE5LjM5Mi4zMzMwXG5VUy9DYW5hZGENCiA6ICsxLjg2Ni40MzIuOTkwMyAgVW5pdGVk
IEtpbmdkb206ICs0NC4yMC44ODI0LjAxMTdcbkluZGlhOiArOTEuODAuNDM1MC4xMQ0KIDExICBH
ZXJtYW55OiArNDkuNjE5LjY3NzMuOTAwMlxuSmFwYW46ICs4MS4zLjU3NjMuOTM5NCAgQ2hpbmE6
ICs4Ni4xMC44NTE1DQogLjU2NjZcblxuXG5cbkZvciBhc3Npc3RhbmNlXG5cbiAgMS4gICAgR28g
dG8gaHR0cHM6Ly9jaXNjby53ZWJleC5jb20vY2lzY28NCiAvbWNcbiAgMi4gICAgT24gdGhlIGxl
ZnQgbmF2aWdhdGlvbiBiYXJcLCBjbGljayDigJxTdXBwb3J04oCdLlxuVG8gYWRkIHRoaQ0KIHMg
bWVldGluZyB0byB5b3VyIGNhbGVuZGFyIHByb2dyYW0gKGZvciBleGFtcGxlIE1pY3Jvc29mdCBP
dXRsb29rKVwsIGNsaWNrDQogIHRoaXMgbGluazpcbmh0dHBzOi8vY2lzY28ud2ViZXguY29tL2Np
c2NvL2oucGhwP01USUQ9bTRjYjE4MWI4ZDRhMDk2NTIyMWINCiBiMjc4OTkxYWM5YmYzXG5UbyBj
aGVjayB3aGV0aGVyIHlvdSBoYXZlIHRoZSBhcHByb3ByaWF0ZSBwbGF5ZXJzIGluc3RhbGxlZA0K
ICBmb3IgVUNGIChVbml2ZXJzYWwgQ29tbXVuaWNhdGlvbnMgRm9ybWF0KSByaWNoIG1lZGlhIGZp
bGVzXCwgZ28gdG8gaHR0cHM6DQogLy9jaXNjby53ZWJleC5jb20vY2lzY28vc3lzdGVtZGlhZ25v
c2lzLnBocC5cbmh0dHA6Ly93d3cud2ViZXguY29tXG5DQ006KzENCiA0MDg1MjU2ODAweDIwMTA0
Njk1OCNcblxuXG4NClNVTU1BUlk7TEFOR1VBR0U9ZW4tVVM6Rlc6IE1lZXRpbmcgc2NoZWR1bGVk
OiA2VGlTQ0ggc2VjdXJpdHkNCkRUU1RBUlQ7VFpJRD1QYWNpZmljIFRpbWU6MjAxNDA1MjBUMDcw
MDAwDQpEVEVORDtUWklEPVBhY2lmaWMgVGltZToyMDE0MDUyMFQwODAwMDANClVJRDpXRUJFWC1N
RUVUSU5HIENFTlRFUi02LjAzMDM3OTAtMjUzNDczNTMyLVNVPWNpc2NvLU1LPTIwMTA0Njk1OC1Q
Vz02dXJpdA0KIHktSE49cHRodWJlcnQNClJFQ1VSUkVOQ0UtSUQ7VFpJRD1QYWNpZmljIFRpbWU6
MjAxNDA1MTlUMDcwMDAwDQpDTEFTUzpQVUJMSUMNClBSSU9SSVRZOjUNCkRUU1RBTVA6MjAxNDAy
MTBUMTUwMDAwWg0KVFJBTlNQOk9QQVFVRQ0KU1RBVFVTOkNPTkZJUk1FRA0KU0VRVUVOQ0U6MQ0K
TE9DQVRJT047TEFOR1VBR0U9ZW4tVVM6aHR0cHM6Ly9jaXNjby53ZWJleC5jb20vY2lzY28NClgt
TUlDUk9TT0ZULUNETy1BUFBULVNFUVVFTkNFOjENClgtTUlDUk9TT0ZULUNETy1PV05FUkFQUFRJ
RDotMQ0KWC1NSUNST1NPRlQtQ0RPLUJVU1lTVEFUVVM6VEVOVEFUSVZFDQpYLU1JQ1JPU09GVC1D
RE8tSU5URU5ERURTVEFUVVM6QlVTWQ0KWC1NSUNST1NPRlQtQ0RPLUFMTERBWUVWRU5UOkZBTFNF
DQpYLU1JQ1JPU09GVC1DRE8tSU1QT1JUQU5DRToxDQpYLU1JQ1JPU09GVC1DRE8tSU5TVFRZUEU6
Mw0KWC1NSUNST1NPRlQtRElTQUxMT1ctQ09VTlRFUjpGQUxTRQ0KQkVHSU46VkFMQVJNDQpBQ1RJ
T046RElTUExBWQ0KREVTQ1JJUFRJT046UkVNSU5ERVINClRSSUdHRVI7UkVMQVRFRD1TVEFSVDot
UFQxNU0NCkVORDpWQUxBUk0NCkVORDpWRVZFTlQNCkVORDpWQ0FMRU5EQVINCg==

--_000_E045AECD98228444A58C61C200AE1BD842642141xmbrcdx01ciscoc_--


From nobody Thu May  8 23:45:10 2014
Return-Path: <pthubert@cisco.com>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id E09141A01EE for <6tisch-security@ietfa.amsl.com>; Thu,  8 May 2014 23:45:08 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.55
X-Spam-Level: 
X-Spam-Status: No, score=-2.55 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, HTML_MESSAGE=0.001, LOTS_OF_MONEY=0.001, RP_MATCHES_RCVD=-0.651, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id E8VVUd8aAlhR for <6tisch-security@ietfa.amsl.com>; Thu,  8 May 2014 23:45:06 -0700 (PDT)
Received: from alln-iport-4.cisco.com (alln-iport-4.cisco.com [173.37.142.91]) by ietfa.amsl.com (Postfix) with ESMTP id 8E8101A01EB for <6tisch-security@ietf.org>; Thu,  8 May 2014 23:45:06 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cisco.com; i=@cisco.com; l=17852; q=dns/txt; s=iport; t=1399617902; x=1400827502; h=from:to:subject:sender:date:message-id:references: in-reply-to:mime-version; bh=EArgpxvlsa5VnODW5CqUkWElkhXrgNFS9ZL63o2VjW4=; b=HDf2I2GInIt7xKjk8E3q0U2DavuOacBEq/54Gz2IKAmL6O4M+TnWNOmi MPcOeqjCrW/f/8NJyMxgAgw+OJGUbqrrDbjLDuawjvtOD0jKWrRBdy9AM Yi7HogbDIvYlBGy6b7tEOU2vvW5RdkNhPs0Rv7tj9ZD7Acc1I9OOjm1SD 0=;
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-Anti-Spam-Result: AhQFACF4bFOtJA2G/2dsb2JhbAA/FwOCQkRPWIJnwlABGXsWdIIlAQEBBCMKGw0RIwEBAQgRAwEBAQsKAQMMAwMCAgIwFAcBAQUCAQEBAQMTCIg5DTaraYQqEaAgF44OMw0KCwcHgl02gRUEhFpximSKT5FAgmNTbYEJOXg
X-IronPort-AV: E=Sophos;i="4.97,1016,1389744000";  d="scan'208,217";a="42378097"
Received: from alln-core-12.cisco.com ([173.36.13.134]) by alln-iport-4.cisco.com with ESMTP; 09 May 2014 06:45:01 +0000
Received: from xhc-aln-x05.cisco.com (xhc-aln-x05.cisco.com [173.36.12.79]) by alln-core-12.cisco.com (8.14.5/8.14.5) with ESMTP id s496j1OR016329 (version=TLSv1/SSLv3 cipher=AES128-SHA bits=128 verify=FAIL) for <6tisch-security@ietf.org>; Fri, 9 May 2014 06:45:01 GMT
Received: from xmb-rcd-x01.cisco.com ([169.254.1.229]) by xhc-aln-x05.cisco.com ([173.36.12.79]) with mapi id 14.03.0123.003; Fri, 9 May 2014 01:45:01 -0500
From: webex <messenger@webex.com>
To: "6tisch-security@ietf.org" <6tisch-security@ietf.org>
Thread-Topic: Meeting scheduled: 6TiSCH security
Thread-Index: Ac8hAcvT7HcH1CFASnWDc4zjKF6UTRKUCEog
Sender: "Pascal Thubert (pthubert)" <pthubert@cisco.com>
Date: Fri, 9 May 2014 06:45:00 +0000
Deferred-Delivery: Fri, 9 May 2014 06:44:00 +0000
Message-ID: <E045AECD98228444A58C61C200AE1BD8426421A3@xmb-rcd-x01.cisco.com>
References: <E045AECD98228444A58C61C200AE1BD8416F3AD3@xmb-rcd-x01.cisco.com>
In-Reply-To: <E045AECD98228444A58C61C200AE1BD8416F3AD3@xmb-rcd-x01.cisco.com>
Accept-Language: fr-FR, en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
x-originating-ip: [10.55.22.4]
Content-Type: multipart/alternative; boundary="_000_E045AECD98228444A58C61C200AE1BD8426421A3xmbrcdx01ciscoc_"
MIME-Version: 1.0
Archived-At: http://mailarchive.ietf.org/arch/msg/6tisch-security/_lAqwottX5eKZ-bw_M3RtsT7_IY
Subject: [6tisch-security] FW: Meeting scheduled: 6TiSCH security
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 09 May 2014 06:45:09 -0000

--_000_E045AECD98228444A58C61C200AE1BD8426421A3xmbrcdx01ciscoc_
Content-Type: text/plain; charset="Windows-1252"
Content-Transfer-Encoding: quoted-printable



-----Original Appointment-----
From: webex [mailto:messenger@webex.com]
Sent: lundi 3 f=E9vrier 2014 18:03
Subject: Meeting scheduled: 6TiSCH security
When: mardi 27 mai 2014 07:00-08:00 Pacific Time.
Where: https://cisco.webex.com/cisco


You are the host for this online meeting.
Topic:  6TiSCH security
Date:   Every Monday, from Monday, February 10, 2014 to Monday, February 9,=
 2015
Time:   7:00 am, Pacific Standard Time (San Francisco, GMT-08:00)
Meeting Number: 201 046 958
Meeting Password:       6urity
Host Key:       772928 (use this to reclaim host privileges)



To start the online meeting

  1.    Go to https://cisco.webex.com/cisco/j.php?MTID=3Dm2fe139bf876cea3ec=
62750cd580b7908
  2.    Log in to your account.
  3.    Click =93Start Now=94.
  4.    Follow the instructions that appear on your screen.



ALERT =96 PLEASE READ: DO NOT DIAL THE TOLL FREE NUMBERS FROM WITHIN THE (4=
08) OR (919) AREA CODES

Please dial the local access number for your area from the list below:
=95       San Jose/Milpitas (408) area:  525-6800
=95       RTP (919) area:  392-3330

Dialing the WebEx toll free numbers from within 408 or 919 area codes is no=
t enabled (non-Cisco phones).  =93 If you dial the toll-free numbers within=
 the 408 or 919 area codes you will be instructed to hang up and dial the l=
ocal access number.=94 Please use the call-back option whenever possible an=
d otherwise dial local numbers only.  The affected toll free numbers are: (=
866) 432-9903 for the San Jose/Milpitas area and (866) 349-3520 for the RTP=
 area.

-------------------------------------------------------

To join the teleconference only
-------------------------------------------------------

1.      Dial into Cisco WebEx (view all Global Access Numbers at

http://cisco.com/en/US/about/doing_business/conferencing/index.html <http:/=
/cisco.com/en/US/about/doing_business/conferencing/index.html%202>
2.      Follow the prompts to enter the Meeting Number (listed above) or Ac=
cess Code followed by the # sign.

San Jose, CA: +1.408.525.6800  RTP: +1.919.392.3330
US/Canada: +1.866.432.9903  United Kingdom: +44.20.8824.0117
India: +91.80.4350.1111  Germany: +49.619.6773.9002
Japan: +81.3.5763.9394  China: +86.10.8515.5666



For assistance

  1.    Go to https://cisco.webex.com/cisco/mc
  2.    On the left navigation bar, click =93Support=94.
To add this meeting to your calendar program (for example Microsoft Outlook=
), click this link:
https://cisco.webex.com/cisco/j.php?MTID=3Dm4cb181b8d4a0965221bb278991ac9bf=
3
To check whether you have the appropriate players installed for UCF (Univer=
sal Communications Format) rich media files, go to https://cisco.webex.com/=
cisco/systemdiagnosis.php.
http://www.webex.com
CCM:+14085256800x201046958#



--_000_E045AECD98228444A58C61C200AE1BD8426421A3xmbrcdx01ciscoc_
Content-Type: text/html; charset="Windows-1252"
Content-Transfer-Encoding: quoted-printable

<html>
<head>
<meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3DWindows-1=
252">
<meta name=3D"Generator" content=3D"Microsoft Exchange Server">
<!-- converted from rtf -->
<style><!-- .EmailQuote { margin-left: 1pt; padding-left: 4pt; border-left:=
 #800000 2px solid; } --></style>
</head>
<body>
<font face=3D"Calibri" size=3D"2"><span style=3D"font-size:11pt;">
<div><font color=3D"#1F497D">&nbsp;</font></div>
<div><font color=3D"#1F497D">&nbsp;</font></div>
<div style=3D"margin-bottom:6pt;">-----Original Appointment-----<br>

<b>From:</b> webex [<a href=3D"mailto:messenger@webex.com"><font face=3D"Ta=
homa" size=3D"2" color=3D"blue"><span style=3D"font-size:10pt;"><u>mailto:m=
essenger@webex.com</u></span></font></a>]
<br>

<b>Sent:</b> lundi 3 f=E9vrier 2014 18:03<br>

<b>Subject:</b> Meeting scheduled: 6TiSCH security<br>

<b>When:</b> mardi 27 mai 2014 07:00-08:00 Pacific Time.<br>

<b>Where:</b> <a href=3D"https://cisco.webex.com/cisco"><font face=3D"Tahom=
a" size=3D"2" color=3D"blue"><span style=3D"font-size:10pt;"><u>https://cis=
co.webex.com/cisco</u></span></font></a></div>
<div>&nbsp;</div>
<div>&nbsp;</div>
<div style=3D"margin-bottom:6pt;">You are the host for this online meeting.=
</div>
<div>Topic:&nbsp; 6TiSCH security</div>
<div>Date:&nbsp;&nbsp; Every Monday, from Monday, February 10, 2014 to Mond=
ay, February 9, 2015</div>
<div>Time:&nbsp;&nbsp; 7:00 am, Pacific Standard Time (San Francisco, GMT-0=
8:00)</div>
<div>Meeting Number: 201 046 958</div>
<div>Meeting Password:&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 6urity</div>
<div>Host Key:&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 772928 (use this to recl=
aim host privileges)</div>
<div>&nbsp;</div>
<div><font face=3D"Arial" size=3D"2"><span style=3D"font-size:10pt;">&nbsp;=
</span></font></div>
<div style=3D"margin-top:24pt;"><font face=3D"Cambria" size=3D"4" color=3D"=
#365F91"><span style=3D"font-size:14pt;"><b>To start the online meeting</b>=
</span></font></div>
<div><font face=3D"Arial" size=3D"2"><span style=3D"font-size:10pt;">&nbsp;=
</span></font></div>
<div style=3D"text-indent:-14.15pt;padding-left:14.15pt;">1.&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp; Go to <a href=3D"https://cisco.webex.com/cisco/j.php?MTID=
=3Dm2fe139bf876cea3ec62750cd580b7908"><font face=3D"Arial" size=3D"2" color=
=3D"blue"><span style=3D"font-size:10pt;"><u>https://cisco.webex.com/cisco/=
j.php?MTID=3Dm2fe139bf876cea3ec62750cd580b7908</u></span></font></a></div>
<div style=3D"text-indent:-14.15pt;padding-left:14.15pt;">2.&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp; Log in to your account.</div>
<div style=3D"text-indent:-14.15pt;padding-left:14.15pt;">3.&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp; Click <font color=3D"#1F497D">=93</font>Start Now<font colo=
r=3D"#1F497D">=94</font>.</div>
<div style=3D"text-indent:-14.15pt;padding-left:14.15pt;">4.&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp; Follow the instructions that appear on your screen.</div>
<div>&nbsp;</div>
<div><font face=3D"Arial" size=3D"2"><span style=3D"font-size:10pt;">&nbsp;=
</span></font></div>
<div style=3D"margin-top:10pt;"><font face=3D"Cambria" size=3D"3" color=3D"=
#4F81BD"><span style=3D"font-size:13pt;"><b>ALERT =96 PLEASE READ: DO NOT D=
IAL THE TOLL FREE NUMBERS FROM WITHIN THE (408) OR (919) AREA CODES</b></sp=
an></font></div>
<div><font face=3D"Arial" size=3D"2"><span style=3D"font-size:10pt;">&nbsp;=
</span></font></div>
<div style=3D"margin-bottom:6pt;">Please dial the local access number for y=
our area from the list below:</div>
<ul style=3D"margin:0;padding-left:18pt;">
<li>San Jose/Milpitas (408) area:&nbsp; 525-6800</li><li>RTP (919) area:&nb=
sp; 392-3330</li></ul>
<div><font face=3D"Arial" size=3D"2"><span style=3D"font-size:10pt;">&nbsp;=
</span></font></div>
<div style=3D"margin-bottom:6pt;">Dialing the WebEx toll free numbers from =
within 408 or 919 area codes is not enabled (non-Cisco phones).&nbsp; =93 I=
f you dial the toll-free numbers within the 408 or 919 area codes you will =
be instructed to hang up and dial the local
access number.=94 Please use the call-back option whenever possible and oth=
erwise dial local numbers only.&nbsp; The affected toll free numbers are: (=
866) 432-9903 for the San Jose/Milpitas area and (866) 349-3520 for the RTP=
 area.</div>
<div>&nbsp;</div>
<div><font face=3D"Arial" size=3D"2"><span style=3D"font-size:10pt;">------=
------------------------------------------------- </span></font></div>
<div style=3D"margin-top:24pt;"><font face=3D"Cambria" size=3D"4" color=3D"=
#365F91"><span style=3D"font-size:14pt;"><b>To join the teleconference only=
 </b></span></font></div>
<div><font face=3D"Arial" size=3D"2"><span style=3D"font-size:10pt;">------=
------------------------------------------------- </span></font></div>
<div style=3D"margin-top:10pt;"><font face=3D"Cambria" size=3D"3" color=3D"=
#4F81BD"><span style=3D"font-size:13pt;"><b>1.&nbsp;&nbsp;&nbsp;&nbsp;&nbsp=
; </b><b>Dial into Cisco WebEx (view all Global Access Numbers at </b></spa=
n></font></div>
<div style=3D"margin-top:10pt;"><font face=3D"Cambria" size=3D"3" color=3D"=
#4F81BD"><span style=3D"font-size:13pt;"><a href=3D"http://cisco.com/en/US/=
about/doing_business/conferencing/index.html 2"><font color=3D"blue"><b><u>=
http://cisco.com/en/US/about/doing_business/conferencing/index.html
</u></b></font></a></span></font></div>
<div style=3D"margin-top:10pt;"><font face=3D"Arial" size=3D"2" color=3D"bl=
ue"><span style=3D"font-size:10pt;"><b><u>2</u></b><font color=3D"#4F81BD">=
<b>.&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </b></font><font color=3D"#4F81BD"><b>Fo=
llow the prompts to enter the Meeting Number (listed above) or Access Code
followed by the # sign. </b></font></span></font></div>
<div>&nbsp;</div>
<div style=3D"margin-bottom:6pt;">San Jose, CA: &#43;1.408.525.6800&nbsp; R=
TP: &#43;1.919.392.3330 </div>
<div style=3D"margin-bottom:6pt;">US/Canada: &#43;1.866.432.9903&nbsp; Unit=
ed Kingdom: &#43;44.20.8824.0117 </div>
<div style=3D"margin-bottom:6pt;">India: &#43;91.80.4350.1111&nbsp; Germany=
: &#43;49.619.6773.9002 </div>
<div style=3D"margin-bottom:6pt;">Japan: &#43;81.3.5763.9394&nbsp; China: &=
#43;86.10.8515.5666</div>
<div>&nbsp;</div>
<div><font face=3D"Arial" size=3D"2"><span style=3D"font-size:10pt;">&nbsp;=
</span></font></div>
<div style=3D"margin-top:24pt;"><font face=3D"Cambria" size=3D"4" color=3D"=
#365F91"><span style=3D"font-size:14pt;"><b>For assistance</b></span></font=
></div>
<div><font face=3D"Arial" size=3D"2"><span style=3D"font-size:10pt;">&nbsp;=
</span></font></div>
<div style=3D"text-indent:-14.15pt;padding-left:14.15pt;">1.&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp; Go to <a href=3D"https://cisco.webex.com/cisco/mc"><font fa=
ce=3D"Arial" size=3D"2" color=3D"blue"><span style=3D"font-size:10pt;"><u>h=
ttps://cisco.webex.com/cisco/mc</u></span></font></a></div>
<div style=3D"text-indent:-14.15pt;padding-left:14.15pt;">2.&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp; On the left navigation bar, click <font color=3D"#1F497D">=
=93</font>Support<font color=3D"#1F497D">=94</font>.</div>
<div style=3D"margin-bottom:6pt;">To add this meeting to your calendar prog=
ram (for example Microsoft Outlook), click this link:</div>
<div style=3D"margin-bottom:6pt;"><a href=3D"https://cisco.webex.com/cisco/=
j.php?MTID=3Dm4cb181b8d4a0965221bb278991ac9bf3"><font face=3D"Arial" size=
=3D"2" color=3D"blue"><span style=3D"font-size:10pt;"><u>https://cisco.webe=
x.com/cisco/j.php?MTID=3Dm4cb181b8d4a0965221bb278991ac9bf3</u></span></font=
></a></div>
<div style=3D"margin-bottom:6pt;">To check whether you have the appropriate=
 players installed for UCF (Universal Communications Format) rich media fil=
es, go to <a href=3D"https://cisco.webex.com/cisco/systemdiagnosis.php"><fo=
nt face=3D"Arial" size=3D"2" color=3D"blue"><span style=3D"font-size:10pt;"=
><u>https://cisco.webex.com/cisco/systemdiagnosis.php</u></span></font></a>=
.</div>
<div style=3D"margin-bottom:6pt;"><a href=3D"http://www.webex.com"><font fa=
ce=3D"Arial" size=3D"2" color=3D"blue"><span style=3D"font-size:10pt;"><u>h=
ttp://www.webex.com</u></span></font></a></div>
<div style=3D"margin-bottom:6pt;">CCM:&#43;14085256800x201046958# </div>
<div>&nbsp;</div>
<div>&nbsp;</div>
</span></font>
</body>
</html>

--_000_E045AECD98228444A58C61C200AE1BD8426421A3xmbrcdx01ciscoc_
Content-Type: text/calendar; charset="utf-8"; method=REQUEST
Content-Transfer-Encoding: base64

QkVHSU46VkNBTEVOREFSDQpNRVRIT0Q6UkVRVUVTVA0KUFJPRElEOk1pY3Jvc29mdCBFeGNoYW5n
ZSBTZXJ2ZXIgMjAxMA0KVkVSU0lPTjoyLjANCkJFR0lOOlZUSU1FWk9ORQ0KVFpJRDpQYWNpZmlj
IFRpbWUNCkJFR0lOOlNUQU5EQVJEDQpEVFNUQVJUOjE2MDEwMTAxVDAyMDAwMA0KVFpPRkZTRVRG
Uk9NOi0wNzAwDQpUWk9GRlNFVFRPOi0wODAwDQpSUlVMRTpGUkVRPVlFQVJMWTtJTlRFUlZBTD0x
O0JZREFZPTFTVTtCWU1PTlRIPTExDQpFTkQ6U1RBTkRBUkQNCkJFR0lOOkRBWUxJR0hUDQpEVFNU
QVJUOjE2MDEwMTAxVDAyMDAwMA0KVFpPRkZTRVRGUk9NOi0wODAwDQpUWk9GRlNFVFRPOi0wNzAw
DQpSUlVMRTpGUkVRPVlFQVJMWTtJTlRFUlZBTD0xO0JZREFZPTJTVTtCWU1PTlRIPTMNCkVORDpE
QVlMSUdIVA0KRU5EOlZUSU1FWk9ORQ0KQkVHSU46VkVWRU5UDQpPUkdBTklaRVI7Q049d2ViZXg7
U0VOVC1CWT0iTUFJTFRPOnB0aHViZXJ0QGNpc2NvLmNvbSI6TUFJTFRPOm1lc3NlbmdlckB3ZWJl
eA0KIC5jb20NCkFUVEVOREVFO1JPTEU9UkVRLVBBUlRJQ0lQQU5UO1BBUlRTVEFUPU5FRURTLUFD
VElPTjtSU1ZQPUZBTFNFO0NOPTZ0aXNjaC1zZQ0KIGN1cml0eUBpZXRmLm9yZzpNQUlMVE86NnRp
c2NoLXNlY3VyaXR5QGlldGYub3JnDQpERVNDUklQVElPTjtMQU5HVUFHRT1lbi1VUzpcblxuLS0t
LS1PcmlnaW5hbCBBcHBvaW50bWVudC0tLS0tXG5Gcm9tOiB3ZWJleCANCiBbbWFpbHRvOm1lc3Nl
bmdlckB3ZWJleC5jb21dXG5TZW50OiBsdW5kaSAzIGbDqXZyaWVyIDIwMTQgMTg6MDNcblN1Ympl
Y3Q6IA0KIE1lZXRpbmcgc2NoZWR1bGVkOiA2VGlTQ0ggc2VjdXJpdHlcbldoZW46IG1hcmRpIDI3
IG1haSAyMDE0IDA3OjAwLTA4OjAwIFBhDQogY2lmaWMgVGltZS5cbldoZXJlOiBodHRwczovL2Np
c2NvLndlYmV4LmNvbS9jaXNjb1xuXG5cbllvdSBhcmUgdGhlIGhvc3QgZm8NCiByIHRoaXMgb25s
aW5lIG1lZXRpbmcuXG5Ub3BpYzogIDZUaVNDSCBzZWN1cml0eVxuRGF0ZTogICBFdmVyeSBNb25k
YXlcLCBmcg0KIG9tIE1vbmRheVwsIEZlYnJ1YXJ5IDEwXCwgMjAxNCB0byBNb25kYXlcLCBGZWJy
dWFyeSA5XCwgMjAxNVxuVGltZTogICA3OjAwDQogIGFtXCwgUGFjaWZpYyBTdGFuZGFyZCBUaW1l
IChTYW4gRnJhbmNpc2NvXCwgR01ULTA4OjAwKVxuTWVldGluZyBOdW1iZXI6IDINCiAwMSAwNDYg
OTU4XG5NZWV0aW5nIFBhc3N3b3JkOiAgICAgICA2dXJpdHlcbkhvc3QgS2V5OiAgICAgICA3NzI5
MjggKHVzZSB0aA0KIGlzIHRvIHJlY2xhaW0gaG9zdCBwcml2aWxlZ2VzKVxuXG5cblxuVG8gc3Rh
cnQgdGhlIG9ubGluZSBtZWV0aW5nXG5cbiAgMS4gDQogICAgR28gdG8gaHR0cHM6Ly9jaXNjby53
ZWJleC5jb20vY2lzY28vai5waHA/TVRJRD1tMmZlMTM5YmY4NzZjZWEzZWM2Mjc1MGMNCiBkNTgw
Yjc5MDhcbiAgMi4gICAgTG9nIGluIHRvIHlvdXIgYWNjb3VudC5cbiAgMy4gICAgQ2xpY2sg4oCc
U3RhcnQgTm934oCdLg0KIFxuICA0LiAgICBGb2xsb3cgdGhlIGluc3RydWN0aW9ucyB0aGF0IGFw
cGVhciBvbiB5b3VyIHNjcmVlbi5cblxuXG5cbkFMRVJUDQogIOKAkyBQTEVBU0UgUkVBRDogRE8g
Tk9UIERJQUwgVEhFIFRPTEwgRlJFRSBOVU1CRVJTIEZST00gV0lUSElOIFRIRSAoNDA4KSANCiBP
UiAoOTE5KSBBUkVBIENPREVTXG5cblBsZWFzZSBkaWFsIHRoZSBsb2NhbCBhY2Nlc3MgbnVtYmVy
IGZvciB5b3VyIGFyZWEgZg0KIHJvbSB0aGUgbGlzdCBiZWxvdzpcbuKAoiAgICAgICBTYW4gSm9z
ZS9NaWxwaXRhcyAoNDA4KSBhcmVhOiAgNTI1LTY4MDBcbg0KIOKAoiAgICAgICBSVFAgKDkxOSkg
YXJlYTogIDM5Mi0zMzMwXG5cbkRpYWxpbmcgdGhlIFdlYkV4IHRvbGwgZnJlZSBudW1iZXJzDQog
IGZyb20gd2l0aGluIDQwOCBvciA5MTkgYXJlYSBjb2RlcyBpcyBub3QgZW5hYmxlZCAobm9uLUNp
c2NvIHBob25lcykuICDigJwNCiAgSWYgeW91IGRpYWwgdGhlIHRvbGwtZnJlZSBudW1iZXJzIHdp
dGhpbiB0aGUgNDA4IG9yIDkxOSBhcmVhIGNvZGVzIHlvdSB3aQ0KIGxsIGJlIGluc3RydWN0ZWQg
dG8gaGFuZyB1cCBhbmQgZGlhbCB0aGUgbG9jYWwgYWNjZXNzIG51bWJlci7igJ0gUGxlYXNlIHVz
DQogZSB0aGUgY2FsbC1iYWNrIG9wdGlvbiB3aGVuZXZlciBwb3NzaWJsZSBhbmQgb3RoZXJ3aXNl
IGRpYWwgbG9jYWwgbnVtYmVycyANCiBvbmx5LiAgVGhlIGFmZmVjdGVkIHRvbGwgZnJlZSBudW1i
ZXJzIGFyZTogKDg2NikgNDMyLTk5MDMgZm9yIHRoZSBTYW4gSm9zZQ0KIC9NaWxwaXRhcyBhcmVh
IGFuZCAoODY2KSAzNDktMzUyMCBmb3IgdGhlIFJUUCBhcmVhLlxuXG4tLS0tLS0tLS0tLS0tLS0t
LS0tDQogLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tXG5cblRvIGpvaW4gdGhl
IHRlbGVjb25mZXJlbmNlIG9ubHlcbi0NCiAtLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0t
LS0tLS0tLS0tLS0tLS0tLS0tLS0tLS1cblxuMS4gICAgICBEaWFsIGludA0KIG8gQ2lzY28gV2Vi
RXggKHZpZXcgYWxsIEdsb2JhbCBBY2Nlc3MgTnVtYmVycyBhdFxuXG5odHRwOi8vY2lzY28uY29t
L2VuL1VTDQogL2Fib3V0L2RvaW5nX2J1c2luZXNzL2NvbmZlcmVuY2luZy9pbmRleC5odG1sIDxo
dHRwOi8vY2lzY28uY29tL2VuL1VTL2Fib3UNCiB0L2RvaW5nX2J1c2luZXNzL2NvbmZlcmVuY2lu
Zy9pbmRleC5odG1sJTIwMj5cbjIuICAgICAgRm9sbG93IHRoZSBwcm9tcHRzIA0KIHRvIGVudGVy
IHRoZSBNZWV0aW5nIE51bWJlciAobGlzdGVkIGFib3ZlKSBvciBBY2Nlc3MgQ29kZSBmb2xsb3dl
ZCBieSB0aGUgDQogIyBzaWduLlxuXG5TYW4gSm9zZVwsIENBOiArMS40MDguNTI1LjY4MDAgIFJU
UDogKzEuOTE5LjM5Mi4zMzMwXG5VUy9DYW5hZGENCiA6ICsxLjg2Ni40MzIuOTkwMyAgVW5pdGVk
IEtpbmdkb206ICs0NC4yMC44ODI0LjAxMTdcbkluZGlhOiArOTEuODAuNDM1MC4xMQ0KIDExICBH
ZXJtYW55OiArNDkuNjE5LjY3NzMuOTAwMlxuSmFwYW46ICs4MS4zLjU3NjMuOTM5NCAgQ2hpbmE6
ICs4Ni4xMC44NTE1DQogLjU2NjZcblxuXG5cbkZvciBhc3Npc3RhbmNlXG5cbiAgMS4gICAgR28g
dG8gaHR0cHM6Ly9jaXNjby53ZWJleC5jb20vY2lzY28NCiAvbWNcbiAgMi4gICAgT24gdGhlIGxl
ZnQgbmF2aWdhdGlvbiBiYXJcLCBjbGljayDigJxTdXBwb3J04oCdLlxuVG8gYWRkIHRoaQ0KIHMg
bWVldGluZyB0byB5b3VyIGNhbGVuZGFyIHByb2dyYW0gKGZvciBleGFtcGxlIE1pY3Jvc29mdCBP
dXRsb29rKVwsIGNsaWNrDQogIHRoaXMgbGluazpcbmh0dHBzOi8vY2lzY28ud2ViZXguY29tL2Np
c2NvL2oucGhwP01USUQ9bTRjYjE4MWI4ZDRhMDk2NTIyMWINCiBiMjc4OTkxYWM5YmYzXG5UbyBj
aGVjayB3aGV0aGVyIHlvdSBoYXZlIHRoZSBhcHByb3ByaWF0ZSBwbGF5ZXJzIGluc3RhbGxlZA0K
ICBmb3IgVUNGIChVbml2ZXJzYWwgQ29tbXVuaWNhdGlvbnMgRm9ybWF0KSByaWNoIG1lZGlhIGZp
bGVzXCwgZ28gdG8gaHR0cHM6DQogLy9jaXNjby53ZWJleC5jb20vY2lzY28vc3lzdGVtZGlhZ25v
c2lzLnBocC5cbmh0dHA6Ly93d3cud2ViZXguY29tXG5DQ006KzENCiA0MDg1MjU2ODAweDIwMTA0
Njk1OCNcblxuXG4NClNVTU1BUlk7TEFOR1VBR0U9ZW4tVVM6Rlc6IE1lZXRpbmcgc2NoZWR1bGVk
OiA2VGlTQ0ggc2VjdXJpdHkNCkRUU1RBUlQ7VFpJRD1QYWNpZmljIFRpbWU6MjAxNDA1MjdUMDcw
MDAwDQpEVEVORDtUWklEPVBhY2lmaWMgVGltZToyMDE0MDUyN1QwODAwMDANClVJRDpXRUJFWC1N
RUVUSU5HIENFTlRFUi02LjAzMDM3OTAtMjUzNDczNTMyLVNVPWNpc2NvLU1LPTIwMTA0Njk1OC1Q
Vz02dXJpdA0KIHktSE49cHRodWJlcnQNClJFQ1VSUkVOQ0UtSUQ7VFpJRD1QYWNpZmljIFRpbWU6
MjAxNDA1MjZUMDcwMDAwDQpDTEFTUzpQVUJMSUMNClBSSU9SSVRZOjUNCkRUU1RBTVA6MjAxNDAy
MTBUMTUwMDAwWg0KVFJBTlNQOk9QQVFVRQ0KU1RBVFVTOkNPTkZJUk1FRA0KU0VRVUVOQ0U6MQ0K
TE9DQVRJT047TEFOR1VBR0U9ZW4tVVM6aHR0cHM6Ly9jaXNjby53ZWJleC5jb20vY2lzY28NClgt
TUlDUk9TT0ZULUNETy1BUFBULVNFUVVFTkNFOjENClgtTUlDUk9TT0ZULUNETy1PV05FUkFQUFRJ
RDotMQ0KWC1NSUNST1NPRlQtQ0RPLUJVU1lTVEFUVVM6VEVOVEFUSVZFDQpYLU1JQ1JPU09GVC1D
RE8tSU5URU5ERURTVEFUVVM6QlVTWQ0KWC1NSUNST1NPRlQtQ0RPLUFMTERBWUVWRU5UOkZBTFNF
DQpYLU1JQ1JPU09GVC1DRE8tSU1QT1JUQU5DRToxDQpYLU1JQ1JPU09GVC1DRE8tSU5TVFRZUEU6
Mw0KWC1NSUNST1NPRlQtRElTQUxMT1ctQ09VTlRFUjpGQUxTRQ0KQkVHSU46VkFMQVJNDQpBQ1RJ
T046RElTUExBWQ0KREVTQ1JJUFRJT046UkVNSU5ERVINClRSSUdHRVI7UkVMQVRFRD1TVEFSVDot
UFQxNU0NCkVORDpWQUxBUk0NCkVORDpWRVZFTlQNCkVORDpWQ0FMRU5EQVINCg==

--_000_E045AECD98228444A58C61C200AE1BD8426421A3xmbrcdx01ciscoc_--


From nobody Thu May  8 23:51:34 2014
Return-Path: <pthubert@cisco.com>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 4E05B1A01F4 for <6tisch-security@ietfa.amsl.com>; Thu,  8 May 2014 23:51:30 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.55
X-Spam-Level: 
X-Spam-Status: No, score=-2.55 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, HTML_MESSAGE=0.001, LOTS_OF_MONEY=0.001, RP_MATCHES_RCVD=-0.651, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id wpdD1NsCNEoe for <6tisch-security@ietfa.amsl.com>; Thu,  8 May 2014 23:51:28 -0700 (PDT)
Received: from alln-iport-4.cisco.com (alln-iport-4.cisco.com [173.37.142.91]) by ietfa.amsl.com (Postfix) with ESMTP id A3AB91A01DE for <6tisch-security@ietf.org>; Thu,  8 May 2014 23:51:27 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cisco.com; i=@cisco.com; l=21470; q=dns/txt; s=iport; t=1399618283; x=1400827883; h=from:to:subject:sender:date:message-id:references: in-reply-to:mime-version; bh=0uEX+A18m6AGc82VoMY/kE5ctTTCGfDCIkokJ3HMlR8=; b=iWZlrX+mpSQEygbskLSaX/gCnhzQjGy2o1+eZwhqbbG7O7dToNvO/4Kp lQf1MH90R2rTblM1JNH2PDBc2GM5+SnK6z0pR55MRW2AuynqDzxCItzo+ l+/gSUYlW8o7J0JpJfqKI2UAq6jw0B3cAwn8PPrbayR2f7/rp/RvnK76a I=;
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-Anti-Spam-Result: AhQFAKF6bFOtJV2c/2dsb2JhbAA/FwOCQkRPWIJnwlEBGXsWdIIlAQEBBCMKGw0RIwEBAQgRAwEBAQsKAQMMAwMCAgIwFAcBAQUCAQEBAQMBEgiIOQ02q2qEKhGgIBeODjMNCgsHB4JdNoEVBIRacYpkik+RQIJjU22BCTl4
X-IronPort-AV: E=Sophos;i="4.97,1016,1389744000";  d="scan'208,217";a="42379371"
Received: from rcdn-core-5.cisco.com ([173.37.93.156]) by alln-iport-4.cisco.com with ESMTP; 09 May 2014 06:51:22 +0000
Received: from xhc-rcd-x06.cisco.com (xhc-rcd-x06.cisco.com [173.37.183.80]) by rcdn-core-5.cisco.com (8.14.5/8.14.5) with ESMTP id s496pMp4001408 (version=TLSv1/SSLv3 cipher=AES128-SHA bits=128 verify=FAIL); Fri, 9 May 2014 06:51:22 GMT
Received: from xmb-rcd-x01.cisco.com ([169.254.1.229]) by xhc-rcd-x06.cisco.com ([173.37.183.80]) with mapi id 14.03.0123.003; Fri, 9 May 2014 01:51:21 -0500
From: webex <messenger@webex.com>
To: "6tisch-security@ietf.org" <6tisch-security@ietf.org>, Pat Kinney <pat.kinney@KINNEYCONSULTINGLLC.COM>
Thread-Topic: Meeting scheduled: 6TiSCH security
Thread-Index: Ac8hAcvT7HcH1CFASnWDc4zjKF6UTRKUPd/A
Sender: "Pascal Thubert (pthubert)" <pthubert@cisco.com>
Date: Fri, 9 May 2014 06:51:21 +0000
Deferred-Delivery: Fri, 9 May 2014 06:51:00 +0000
Message-ID: <E045AECD98228444A58C61C200AE1BD84264229D@xmb-rcd-x01.cisco.com>
References: <E045AECD98228444A58C61C200AE1BD8416F3AD3@xmb-rcd-x01.cisco.com>
In-Reply-To: <E045AECD98228444A58C61C200AE1BD8416F3AD3@xmb-rcd-x01.cisco.com>
Accept-Language: fr-FR, en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
x-originating-ip: [10.55.22.4]
Content-Type: multipart/alternative; boundary="_000_E045AECD98228444A58C61C200AE1BD84264229Dxmbrcdx01ciscoc_"
MIME-Version: 1.0
Archived-At: http://mailarchive.ietf.org/arch/msg/6tisch-security/wBQpPBy6I2ONaILPgaIGuF_-KJc
Subject: [6tisch-security] FW: Meeting scheduled: 6TiSCH security
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 09 May 2014 06:51:30 -0000

--_000_E045AECD98228444A58C61C200AE1BD84264229Dxmbrcdx01ciscoc_
Content-Type: text/plain; charset="Windows-1252"
Content-Transfer-Encoding: quoted-printable

So revised schedule is:
   2014-05-12 10:00am
   2014-05-20 10:00am
   2014-05-27 10:00am
   2014-05-02 10:00am


-----Original Appointment-----
From: webex [mailto:messenger@webex.com]
Sent: lundi 3 f=E9vrier 2014 18:03
To: webex; Pascal Thubert (pthubert); Michael Behringer (mbehring); Patrick=
 Wetterwald (pwetterw); Paul Duffy (paduffy); Maik Seewald (maseewal); Mich=
ael Richardson; Rene Struik
Subject: Meeting scheduled: 6TiSCH security
When: Occurs every lundi effective 10/02/2014 until 09/02/2015 from 07:00 t=
o 08:00 (UTC-08:00) Pacifique (=C9.-U. et Canada).
Where: https://cisco.webex.com/cisco


You are the host for this online meeting.
Topic:  6TiSCH security
Date:   Every Monday, from Monday, February 10, 2014 to Monday, February 9,=
 2015
Time:   7:00 am, Pacific Standard Time (San Francisco, GMT-08:00)
Meeting Number: 201 046 958
Meeting Password:       6urity
Host Key:       772928 (use this to reclaim host privileges)



To start the online meeting

  1.    Go to https://cisco.webex.com/cisco/j.php?MTID=3Dm2fe139bf876cea3ec=
62750cd580b7908
  2.    Log in to your account.
  3.    Click =93Start Now=94.
  4.    Follow the instructions that appear on your screen.



ALERT =96 PLEASE READ: DO NOT DIAL THE TOLL FREE NUMBERS FROM WITHIN THE (4=
08) OR (919) AREA CODES

Please dial the local access number for your area from the list below:
=95       San Jose/Milpitas (408) area:  525-6800
=95       RTP (919) area:  392-3330

Dialing the WebEx toll free numbers from within 408 or 919 area codes is no=
t enabled (non-Cisco phones).  =93 If you dial the toll-free numbers within=
 the 408 or 919 area codes you will be instructed to hang up and dial the l=
ocal access number.=94 Please use the call-back option whenever possible an=
d otherwise dial local numbers only.  The affected toll free numbers are: (=
866) 432-9903 for the San Jose/Milpitas area and (866) 349-3520 for the RTP=
 area.

-------------------------------------------------------

To join the teleconference only
-------------------------------------------------------

1.      Dial into Cisco WebEx (view all Global Access Numbers at

http://cisco.com/en/US/about/doing_business/conferencing/index.html <http:/=
/cisco.com/en/US/about/doing_business/conferencing/index.html%202>
2.      Follow the prompts to enter the Meeting Number (listed above) or Ac=
cess Code followed by the # sign.

San Jose, CA: +1.408.525.6800  RTP: +1.919.392.3330
US/Canada: +1.866.432.9903  United Kingdom: +44.20.8824.0117
India: +91.80.4350.1111  Germany: +49.619.6773.9002
Japan: +81.3.5763.9394  China: +86.10.8515.5666



For assistance

  1.    Go to https://cisco.webex.com/cisco/mc
  2.    On the left navigation bar, click =93Support=94.
To add this meeting to your calendar program (for example Microsoft Outlook=
), click this link:
https://cisco.webex.com/cisco/j.php?MTID=3Dm4cb181b8d4a0965221bb278991ac9bf=
3
To check whether you have the appropriate players installed for UCF (Univer=
sal Communications Format) rich media files, go to https://cisco.webex.com/=
cisco/systemdiagnosis.php.
http://www.webex.com
CCM:+14085256800x201046958#



--_000_E045AECD98228444A58C61C200AE1BD84264229Dxmbrcdx01ciscoc_
Content-Type: text/html; charset="Windows-1252"
Content-Transfer-Encoding: quoted-printable

<html>
<head>
<meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3DWindows-1=
252">
<meta name=3D"Generator" content=3D"Microsoft Exchange Server">
<!-- converted from rtf -->
<style><!-- .EmailQuote { margin-left: 1pt; padding-left: 4pt; border-left:=
 #800000 2px solid; } --></style>
</head>
<body>
<font face=3D"Calibri" size=3D"2"><span style=3D"font-size:11pt;">
<div>So revised schedule is:</div>
<div>&nbsp;&nbsp; 2014-05-12 10:00am</div>
<div>&nbsp;&nbsp; 2014-05-20 10:00am</div>
<div>&nbsp;&nbsp; 2014-05-27 10:00am</div>
<div>&nbsp;&nbsp; 2014-05-02 10:00am</div>
<div><font color=3D"#1F497D">&nbsp;</font></div>
<div><font color=3D"#1F497D">&nbsp;</font></div>
<div style=3D"margin-bottom:6pt;">-----Original Appointment-----<br>

<b>From:</b> webex [<a href=3D"mailto:messenger@webex.com"><font face=3D"Ta=
homa" size=3D"2" color=3D"blue"><span style=3D"font-size:10pt;"><u>mailto:m=
essenger@webex.com</u></span></font></a>]
<br>

<b>Sent:</b> lundi 3 f=E9vrier 2014 18:03<br>

<b>To:</b> webex; Pascal Thubert (pthubert); Michael Behringer (mbehring); =
Patrick Wetterwald (pwetterw); Paul Duffy (paduffy); Maik Seewald (maseewal=
); Michael Richardson; Rene Struik<br>

<b>Subject:</b> Meeting scheduled: 6TiSCH security<br>

<b>When:</b> Occurs every lundi effective 10/02/2014 until 09/02/2015 from =
07:00 to 08:00 (UTC-08:00) Pacifique (=C9.-U. et Canada).<br>

<b>Where:</b> <a href=3D"https://cisco.webex.com/cisco"><font face=3D"Tahom=
a" size=3D"2" color=3D"blue"><span style=3D"font-size:10pt;"><u>https://cis=
co.webex.com/cisco</u></span></font></a></div>
<div>&nbsp;</div>
<div>&nbsp;</div>
<div style=3D"margin-bottom:6pt;">You are the host for this online meeting.=
</div>
<div>Topic:&nbsp; 6TiSCH security</div>
<div>Date:&nbsp;&nbsp; Every Monday, from Monday, February 10, 2014 to Mond=
ay, February 9, 2015</div>
<div>Time:&nbsp;&nbsp; 7:00 am, Pacific Standard Time (San Francisco, GMT-0=
8:00)</div>
<div>Meeting Number: 201 046 958</div>
<div>Meeting Password:&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 6urity</div>
<div>Host Key:&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 772928 (use this to recl=
aim host privileges)</div>
<div>&nbsp;</div>
<div><font face=3D"Arial" size=3D"2"><span style=3D"font-size:10pt;">&nbsp;=
</span></font></div>
<div style=3D"margin-top:24pt;"><font face=3D"Cambria" size=3D"4" color=3D"=
#365F91"><span style=3D"font-size:14pt;"><b>To start the online meeting</b>=
</span></font></div>
<div><font face=3D"Arial" size=3D"2"><span style=3D"font-size:10pt;">&nbsp;=
</span></font></div>
<div style=3D"text-indent:-14.15pt;padding-left:14.15pt;">1.&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp; Go to <a href=3D"https://cisco.webex.com/cisco/j.php?MTID=
=3Dm2fe139bf876cea3ec62750cd580b7908"><font face=3D"Arial" size=3D"2" color=
=3D"blue"><span style=3D"font-size:10pt;"><u>https://cisco.webex.com/cisco/=
j.php?MTID=3Dm2fe139bf876cea3ec62750cd580b7908</u></span></font></a></div>
<div style=3D"text-indent:-14.15pt;padding-left:14.15pt;">2.&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp; Log in to your account.</div>
<div style=3D"text-indent:-14.15pt;padding-left:14.15pt;">3.&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp; Click <font color=3D"#1F497D">=93</font>Start Now<font colo=
r=3D"#1F497D">=94</font>.</div>
<div style=3D"text-indent:-14.15pt;padding-left:14.15pt;">4.&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp; Follow the instructions that appear on your screen.</div>
<div>&nbsp;</div>
<div><font face=3D"Arial" size=3D"2"><span style=3D"font-size:10pt;">&nbsp;=
</span></font></div>
<div style=3D"margin-top:10pt;"><font face=3D"Cambria" size=3D"3" color=3D"=
#4F81BD"><span style=3D"font-size:13pt;"><b>ALERT =96 PLEASE READ: DO NOT D=
IAL THE TOLL FREE NUMBERS FROM WITHIN THE (408) OR (919) AREA CODES</b></sp=
an></font></div>
<div><font face=3D"Arial" size=3D"2"><span style=3D"font-size:10pt;">&nbsp;=
</span></font></div>
<div style=3D"margin-bottom:6pt;">Please dial the local access number for y=
our area from the list below:</div>
<ul style=3D"margin:0;padding-left:18pt;">
<li>San Jose/Milpitas (408) area:&nbsp; 525-6800</li><li>RTP (919) area:&nb=
sp; 392-3330</li></ul>
<div><font face=3D"Arial" size=3D"2"><span style=3D"font-size:10pt;">&nbsp;=
</span></font></div>
<div style=3D"margin-bottom:6pt;">Dialing the WebEx toll free numbers from =
within 408 or 919 area codes is not enabled (non-Cisco phones).&nbsp; =93 I=
f you dial the toll-free numbers within the 408 or 919 area codes you will =
be instructed to hang up and dial the local
access number.=94 Please use the call-back option whenever possible and oth=
erwise dial local numbers only.&nbsp; The affected toll free numbers are: (=
866) 432-9903 for the San Jose/Milpitas area and (866) 349-3520 for the RTP=
 area.</div>
<div>&nbsp;</div>
<div><font face=3D"Arial" size=3D"2"><span style=3D"font-size:10pt;">------=
------------------------------------------------- </span></font></div>
<div style=3D"margin-top:24pt;"><font face=3D"Cambria" size=3D"4" color=3D"=
#365F91"><span style=3D"font-size:14pt;"><b>To join the teleconference only=
 </b></span></font></div>
<div><font face=3D"Arial" size=3D"2"><span style=3D"font-size:10pt;">------=
------------------------------------------------- </span></font></div>
<div style=3D"margin-top:10pt;"><font face=3D"Cambria" size=3D"3" color=3D"=
#4F81BD"><span style=3D"font-size:13pt;"><b>1.&nbsp;&nbsp;&nbsp;&nbsp;&nbsp=
; </b><b>Dial into Cisco WebEx (view all Global Access Numbers at </b></spa=
n></font></div>
<div style=3D"margin-top:10pt;"><font face=3D"Cambria" size=3D"3" color=3D"=
#4F81BD"><span style=3D"font-size:13pt;"><a href=3D"http://cisco.com/en/US/=
about/doing_business/conferencing/index.html 2"><font color=3D"blue"><b><u>=
http://cisco.com/en/US/about/doing_business/conferencing/index.html
</u></b></font></a></span></font></div>
<div style=3D"margin-top:10pt;"><font face=3D"Arial" size=3D"2" color=3D"bl=
ue"><span style=3D"font-size:10pt;"><b><u>2</u></b><font color=3D"#4F81BD">=
<b>.&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </b></font><font color=3D"#4F81BD"><b>Fo=
llow the prompts to enter the Meeting Number (listed above) or Access Code
followed by the # sign. </b></font></span></font></div>
<div>&nbsp;</div>
<div style=3D"margin-bottom:6pt;">San Jose, CA: &#43;1.408.525.6800&nbsp; R=
TP: &#43;1.919.392.3330 </div>
<div style=3D"margin-bottom:6pt;">US/Canada: &#43;1.866.432.9903&nbsp; Unit=
ed Kingdom: &#43;44.20.8824.0117 </div>
<div style=3D"margin-bottom:6pt;">India: &#43;91.80.4350.1111&nbsp; Germany=
: &#43;49.619.6773.9002 </div>
<div style=3D"margin-bottom:6pt;">Japan: &#43;81.3.5763.9394&nbsp; China: &=
#43;86.10.8515.5666</div>
<div>&nbsp;</div>
<div><font face=3D"Arial" size=3D"2"><span style=3D"font-size:10pt;">&nbsp;=
</span></font></div>
<div style=3D"margin-top:24pt;"><font face=3D"Cambria" size=3D"4" color=3D"=
#365F91"><span style=3D"font-size:14pt;"><b>For assistance</b></span></font=
></div>
<div><font face=3D"Arial" size=3D"2"><span style=3D"font-size:10pt;">&nbsp;=
</span></font></div>
<div style=3D"text-indent:-14.15pt;padding-left:14.15pt;">1.&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp; Go to <a href=3D"https://cisco.webex.com/cisco/mc"><font fa=
ce=3D"Arial" size=3D"2" color=3D"blue"><span style=3D"font-size:10pt;"><u>h=
ttps://cisco.webex.com/cisco/mc</u></span></font></a></div>
<div style=3D"text-indent:-14.15pt;padding-left:14.15pt;">2.&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp; On the left navigation bar, click <font color=3D"#1F497D">=
=93</font>Support<font color=3D"#1F497D">=94</font>.</div>
<div style=3D"margin-bottom:6pt;">To add this meeting to your calendar prog=
ram (for example Microsoft Outlook), click this link:</div>
<div style=3D"margin-bottom:6pt;"><a href=3D"https://cisco.webex.com/cisco/=
j.php?MTID=3Dm4cb181b8d4a0965221bb278991ac9bf3"><font face=3D"Arial" size=
=3D"2" color=3D"blue"><span style=3D"font-size:10pt;"><u>https://cisco.webe=
x.com/cisco/j.php?MTID=3Dm4cb181b8d4a0965221bb278991ac9bf3</u></span></font=
></a></div>
<div style=3D"margin-bottom:6pt;">To check whether you have the appropriate=
 players installed for UCF (Universal Communications Format) rich media fil=
es, go to <a href=3D"https://cisco.webex.com/cisco/systemdiagnosis.php"><fo=
nt face=3D"Arial" size=3D"2" color=3D"blue"><span style=3D"font-size:10pt;"=
><u>https://cisco.webex.com/cisco/systemdiagnosis.php</u></span></font></a>=
.</div>
<div style=3D"margin-bottom:6pt;"><a href=3D"http://www.webex.com"><font fa=
ce=3D"Arial" size=3D"2" color=3D"blue"><span style=3D"font-size:10pt;"><u>h=
ttp://www.webex.com</u></span></font></a></div>
<div style=3D"margin-bottom:6pt;">CCM:&#43;14085256800x201046958# </div>
<div>&nbsp;</div>
<div>&nbsp;</div>
</span></font>
</body>
</html>

--_000_E045AECD98228444A58C61C200AE1BD84264229Dxmbrcdx01ciscoc_
Content-Type: text/calendar; charset="utf-8"; method=REQUEST
Content-Transfer-Encoding: base64

QkVHSU46VkNBTEVOREFSDQpNRVRIT0Q6UkVRVUVTVA0KUFJPRElEOk1pY3Jvc29mdCBFeGNoYW5n
ZSBTZXJ2ZXIgMjAxMA0KVkVSU0lPTjoyLjANCkJFR0lOOlZUSU1FWk9ORQ0KVFpJRDpQYWNpZmlj
IFRpbWUNCkJFR0lOOlNUQU5EQVJEDQpEVFNUQVJUOjE2MDEwMTAxVDAyMDAwMA0KVFpPRkZTRVRG
Uk9NOi0wNzAwDQpUWk9GRlNFVFRPOi0wODAwDQpSUlVMRTpGUkVRPVlFQVJMWTtJTlRFUlZBTD0x
O0JZREFZPTFTVTtCWU1PTlRIPTExDQpFTkQ6U1RBTkRBUkQNCkJFR0lOOkRBWUxJR0hUDQpEVFNU
QVJUOjE2MDEwMTAxVDAyMDAwMA0KVFpPRkZTRVRGUk9NOi0wODAwDQpUWk9GRlNFVFRPOi0wNzAw
DQpSUlVMRTpGUkVRPVlFQVJMWTtJTlRFUlZBTD0xO0JZREFZPTJTVTtCWU1PTlRIPTMNCkVORDpE
QVlMSUdIVA0KRU5EOlZUSU1FWk9ORQ0KQkVHSU46VkVWRU5UDQpPUkdBTklaRVI7Q049d2ViZXg7
U0VOVC1CWT0iTUFJTFRPOnB0aHViZXJ0QGNpc2NvLmNvbSI6TUFJTFRPOm1lc3NlbmdlckB3ZWJl
eA0KIC5jb20NCkFUVEVOREVFO1JPTEU9UkVRLVBBUlRJQ0lQQU5UO1BBUlRTVEFUPU5FRURTLUFD
VElPTjtSU1ZQPUZBTFNFO0NOPTZ0aXNjaC1zZQ0KIGN1cml0eUBpZXRmLm9yZzpNQUlMVE86NnRp
c2NoLXNlY3VyaXR5QGlldGYub3JnDQpBVFRFTkRFRTtST0xFPVJFUS1QQVJUSUNJUEFOVDtQQVJU
U1RBVD1ORUVEUy1BQ1RJT047UlNWUD1GQUxTRTtDTj1QYXQgS2lubmUNCiB5Ok1BSUxUTzpwYXQu
a2lubmV5QEtJTk5FWUNPTlNVTFRJTkdMTEMuQ09NDQpERVNDUklQVElPTjtMQU5HVUFHRT1lbi1V
UzpTbyByZXZpc2VkIHNjaGVkdWxlIGlzOlxuICAgMjAxNC0wNS0xMiAxMDowMGFtXG4NCiAgICAy
MDE0LTA1LTIwIDEwOjAwYW1cbiAgIDIwMTQtMDUtMjcgMTA6MDBhbVxuICAgMjAxNC0wNS0wMiAx
MDowMGFtXG5cblxuLQ0KIC0tLS1PcmlnaW5hbCBBcHBvaW50bWVudC0tLS0tXG5Gcm9tOiB3ZWJl
eCBbbWFpbHRvOm1lc3NlbmdlckB3ZWJleC5jb21dXG5TDQogZW50OiBsdW5kaSAzIGbDqXZyaWVy
IDIwMTQgMTg6MDNcblRvOiB3ZWJleFw7IFBhc2NhbCBUaHViZXJ0IChwdGh1YmVydClcOyANCiBN
aWNoYWVsIEJlaHJpbmdlciAobWJlaHJpbmcpXDsgUGF0cmljayBXZXR0ZXJ3YWxkIChwd2V0dGVy
dylcOyBQYXVsIER1ZmZ5IA0KIChwYWR1ZmZ5KVw7IE1haWsgU2Vld2FsZCAobWFzZWV3YWwpXDsg
TWljaGFlbCBSaWNoYXJkc29uXDsgUmVuZSBTdHJ1aWtcblN1DQogYmplY3Q6IE1lZXRpbmcgc2No
ZWR1bGVkOiA2VGlTQ0ggc2VjdXJpdHlcbldoZW46IE9jY3VycyBldmVyeSBsdW5kaSBlZmZlY3QN
CiBpdmUgMTAvMDIvMjAxNCB1bnRpbCAwOS8wMi8yMDE1IGZyb20gMDc6MDAgdG8gMDg6MDAgKFVU
Qy0wODowMCkgUGFjaWZpcXVlIA0KICjDiS4tVS4gZXQgQ2FuYWRhKS5cbldoZXJlOiBodHRwczov
L2Npc2NvLndlYmV4LmNvbS9jaXNjb1xuXG5cbllvdSBhcmUgdGhlDQogIGhvc3QgZm9yIHRoaXMg
b25saW5lIG1lZXRpbmcuXG5Ub3BpYzogIDZUaVNDSCBzZWN1cml0eVxuRGF0ZTogICBFdmVyeSBN
b24NCiBkYXlcLCBmcm9tIE1vbmRheVwsIEZlYnJ1YXJ5IDEwXCwgMjAxNCB0byBNb25kYXlcLCBG
ZWJydWFyeSA5XCwgMjAxNVxuVGltZQ0KIDogICA3OjAwIGFtXCwgUGFjaWZpYyBTdGFuZGFyZCBU
aW1lIChTYW4gRnJhbmNpc2NvXCwgR01ULTA4OjAwKVxuTWVldGluZyBODQogdW1iZXI6IDIwMSAw
NDYgOTU4XG5NZWV0aW5nIFBhc3N3b3JkOiAgICAgICA2dXJpdHlcbkhvc3QgS2V5OiAgICAgICA3
NzI5MjgNCiAgKHVzZSB0aGlzIHRvIHJlY2xhaW0gaG9zdCBwcml2aWxlZ2VzKVxuXG5cblxuVG8g
c3RhcnQgdGhlIG9ubGluZSBtZWV0aW5nXA0KIG5cbiAgMS4gICAgR28gdG8gaHR0cHM6Ly9jaXNj
by53ZWJleC5jb20vY2lzY28vai5waHA/TVRJRD1tMmZlMTM5YmY4NzZjZWEzDQogZWM2Mjc1MGNk
NTgwYjc5MDhcbiAgMi4gICAgTG9nIGluIHRvIHlvdXIgYWNjb3VudC5cbiAgMy4gICAgQ2xpY2sg
4oCcU3RhcnQNCiAgTm934oCdLlxuICA0LiAgICBGb2xsb3cgdGhlIGluc3RydWN0aW9ucyB0aGF0
IGFwcGVhciBvbiB5b3VyIHNjcmVlbi5cblxuXA0KIG5cbkFMRVJUIOKAkyBQTEVBU0UgUkVBRDog
RE8gTk9UIERJQUwgVEhFIFRPTEwgRlJFRSBOVU1CRVJTIEZST00gV0lUSElOIFRIDQogRSAoNDA4
KSBPUiAoOTE5KSBBUkVBIENPREVTXG5cblBsZWFzZSBkaWFsIHRoZSBsb2NhbCBhY2Nlc3MgbnVt
YmVyIGZvciB5b3UNCiByIGFyZWEgZnJvbSB0aGUgbGlzdCBiZWxvdzpcbuKAoiAgICAgICBTYW4g
Sm9zZS9NaWxwaXRhcyAoNDA4KSBhcmVhOiAgNTI1LQ0KIDY4MDBcbuKAoiAgICAgICBSVFAgKDkx
OSkgYXJlYTogIDM5Mi0zMzMwXG5cbkRpYWxpbmcgdGhlIFdlYkV4IHRvbGwgZnJlZSBuDQogdW1i
ZXJzIGZyb20gd2l0aGluIDQwOCBvciA5MTkgYXJlYSBjb2RlcyBpcyBub3QgZW5hYmxlZCAobm9u
LUNpc2NvIHBob25lcykNCiAuICDigJwgSWYgeW91IGRpYWwgdGhlIHRvbGwtZnJlZSBudW1iZXJz
IHdpdGhpbiB0aGUgNDA4IG9yIDkxOSBhcmVhIGNvZGVzIA0KIHlvdSB3aWxsIGJlIGluc3RydWN0
ZWQgdG8gaGFuZyB1cCBhbmQgZGlhbCB0aGUgbG9jYWwgYWNjZXNzIG51bWJlci7igJ0gUGxlDQog
YXNlIHVzZSB0aGUgY2FsbC1iYWNrIG9wdGlvbiB3aGVuZXZlciBwb3NzaWJsZSBhbmQgb3RoZXJ3
aXNlIGRpYWwgbG9jYWwgbnUNCiBtYmVycyBvbmx5LiAgVGhlIGFmZmVjdGVkIHRvbGwgZnJlZSBu
dW1iZXJzIGFyZTogKDg2NikgNDMyLTk5MDMgZm9yIHRoZSBTYQ0KIG4gSm9zZS9NaWxwaXRhcyBh
cmVhIGFuZCAoODY2KSAzNDktMzUyMCBmb3IgdGhlIFJUUCBhcmVhLlxuXG4tLS0tLS0tLS0tLS0t
DQogLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tXG5cblRvIGpvaW4g
dGhlIHRlbGVjb25mZXJlbmNlIG8NCiBubHlcbi0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0t
LS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS1cblxuMS4gICAgICBEaQ0KIGFsIGludG8gQ2lzY28g
V2ViRXggKHZpZXcgYWxsIEdsb2JhbCBBY2Nlc3MgTnVtYmVycyBhdFxuXG5odHRwOi8vY2lzY28u
Y29tDQogL2VuL1VTL2Fib3V0L2RvaW5nX2J1c2luZXNzL2NvbmZlcmVuY2luZy9pbmRleC5odG1s
IDxodHRwOi8vY2lzY28uY29tL2VuL1UNCiBTL2Fib3V0L2RvaW5nX2J1c2luZXNzL2NvbmZlcmVu
Y2luZy9pbmRleC5odG1sJTIwMj5cbjIuICAgICAgRm9sbG93IHRoZSBwcg0KIG9tcHRzIHRvIGVu
dGVyIHRoZSBNZWV0aW5nIE51bWJlciAobGlzdGVkIGFib3ZlKSBvciBBY2Nlc3MgQ29kZSBmb2xs
b3dlZCBiDQogeSB0aGUgIyBzaWduLlxuXG5TYW4gSm9zZVwsIENBOiArMS40MDguNTI1LjY4MDAg
IFJUUDogKzEuOTE5LjM5Mi4zMzMwXG5VUy8NCiBDYW5hZGE6ICsxLjg2Ni40MzIuOTkwMyAgVW5p
dGVkIEtpbmdkb206ICs0NC4yMC44ODI0LjAxMTdcbkluZGlhOiArOTEuODAuNA0KIDM1MC4xMTEx
ICBHZXJtYW55OiArNDkuNjE5LjY3NzMuOTAwMlxuSmFwYW46ICs4MS4zLjU3NjMuOTM5NCAgQ2hp
bmE6ICs4Ni4xDQogMC44NTE1LjU2NjZcblxuXG5cbkZvciBhc3Npc3RhbmNlXG5cbiAgMS4gICAg
R28gdG8gaHR0cHM6Ly9jaXNjby53ZWJleC5jb20NCiAvY2lzY28vbWNcbiAgMi4gICAgT24gdGhl
IGxlZnQgbmF2aWdhdGlvbiBiYXJcLCBjbGljayDigJxTdXBwb3J04oCdLlxuVG8gYQ0KIGRkIHRo
aXMgbWVldGluZyB0byB5b3VyIGNhbGVuZGFyIHByb2dyYW0gKGZvciBleGFtcGxlIE1pY3Jvc29m
dCBPdXRsb29rKVwsDQogIGNsaWNrIHRoaXMgbGluazpcbmh0dHBzOi8vY2lzY28ud2ViZXguY29t
L2Npc2NvL2oucGhwP01USUQ9bTRjYjE4MWI4ZDRhMDkNCiA2NTIyMWJiMjc4OTkxYWM5YmYzXG5U
byBjaGVjayB3aGV0aGVyIHlvdSBoYXZlIHRoZSBhcHByb3ByaWF0ZSBwbGF5ZXJzIGlucw0KIHRh
bGxlZCBmb3IgVUNGIChVbml2ZXJzYWwgQ29tbXVuaWNhdGlvbnMgRm9ybWF0KSByaWNoIG1lZGlh
IGZpbGVzXCwgZ28gdG8gDQogaHR0cHM6Ly9jaXNjby53ZWJleC5jb20vY2lzY28vc3lzdGVtZGlh
Z25vc2lzLnBocC5cbmh0dHA6Ly93d3cud2ViZXguY29tXG4NCiBDQ006KzE0MDg1MjU2ODAweDIw
MTA0Njk1OCNcblxuXG4NClJSVUxFOkZSRVE9V0VFS0xZO1VOVElMPTIwMTUwMjA5VDE1MDAwMFo7
SU5URVJWQUw9MTtCWURBWT1NTztXS1NUPVNVDQpFWERBVEU7VFpJRD1QYWNpZmljIFRpbWU6MjAx
NDAzMDNUMDcwMDAwLDIwMTQwMzE3VDA3MDAwMA0KU1VNTUFSWTtMQU5HVUFHRT1lbi1VUzpGVzog
TWVldGluZyBzY2hlZHVsZWQ6IDZUaVNDSCBzZWN1cml0eQ0KRFRTVEFSVDtUWklEPVBhY2lmaWMg
VGltZToyMDE0MDIxMFQwNzAwMDANCkRURU5EO1RaSUQ9UGFjaWZpYyBUaW1lOjIwMTQwMjEwVDA4
MDAwMA0KVUlEOldFQkVYLU1FRVRJTkcgQ0VOVEVSLTYuMDMwMzc5MC0yNTM0NzM1MzItU1U9Y2lz
Y28tTUs9MjAxMDQ2OTU4LVBXPTZ1cml0DQogeS1ITj1wdGh1YmVydA0KQ0xBU1M6UFVCTElDDQpQ
UklPUklUWTo1DQpEVFNUQU1QOjIwMTQwMjEwVDE1MDAwMFoNClRSQU5TUDpPUEFRVUUNClNUQVRV
UzpDT05GSVJNRUQNClNFUVVFTkNFOjENCkxPQ0FUSU9OO0xBTkdVQUdFPWVuLVVTOmh0dHBzOi8v
Y2lzY28ud2ViZXguY29tL2Npc2NvDQpYLU1JQ1JPU09GVC1DRE8tQVBQVC1TRVFVRU5DRToxDQpY
LU1JQ1JPU09GVC1DRE8tT1dORVJBUFBUSUQ6LTENClgtTUlDUk9TT0ZULUNETy1CVVNZU1RBVFVT
OlRFTlRBVElWRQ0KWC1NSUNST1NPRlQtQ0RPLUlOVEVOREVEU1RBVFVTOkJVU1kNClgtTUlDUk9T
T0ZULUNETy1BTExEQVlFVkVOVDpGQUxTRQ0KWC1NSUNST1NPRlQtQ0RPLUlNUE9SVEFOQ0U6MQ0K
WC1NSUNST1NPRlQtQ0RPLUlOU1RUWVBFOjENClgtTUlDUk9TT0ZULURJU0FMTE9XLUNPVU5URVI6
RkFMU0UNCkJFR0lOOlZBTEFSTQ0KQUNUSU9OOkRJU1BMQVkNCkRFU0NSSVBUSU9OOlJFTUlOREVS
DQpUUklHR0VSO1JFTEFURUQ9U1RBUlQ6LVBUMTVNDQpFTkQ6VkFMQVJNDQpFTkQ6VkVWRU5UDQpC
RUdJTjpWRVZFTlQNClNVTU1BUlk6Rlc6IE1lZXRpbmcgc2NoZWR1bGVkOiA2VGlTQ0ggc2VjdXJp
dHkNCkRUU1RBUlQ7VFpJRD1QYWNpZmljIFRpbWU6MjAxNDA1MjBUMDcwMDAwDQpEVEVORDtUWklE
PVBhY2lmaWMgVGltZToyMDE0MDUyMFQwODAwMDANClVJRDpXRUJFWC1NRUVUSU5HIENFTlRFUi02
LjAzMDM3OTAtMjUzNDczNTMyLVNVPWNpc2NvLU1LPTIwMTA0Njk1OC1QVz02dXJpdA0KIHktSE49
cHRodWJlcnQNClJFQ1VSUkVOQ0UtSUQ7VFpJRD1QYWNpZmljIFRpbWU6MjAxNDA1MTlUMDAwMDAw
DQpDTEFTUzpQVUJMSUMNClBSSU9SSVRZOjUNCkRUU1RBTVA6MjAxNDAyMTBUMTUwMDAwWg0KVFJB
TlNQOk9QQVFVRQ0KU1RBVFVTOkNPTkZJUk1FRA0KU0VRVUVOQ0U6MQ0KTE9DQVRJT046aHR0cHM6
Ly9jaXNjby53ZWJleC5jb20vY2lzY28NClgtTUlDUk9TT0ZULUNETy1BUFBULVNFUVVFTkNFOjEN
ClgtTUlDUk9TT0ZULUNETy1PV05FUkFQUFRJRDotMQ0KWC1NSUNST1NPRlQtQ0RPLUJVU1lTVEFU
VVM6VEVOVEFUSVZFDQpYLU1JQ1JPU09GVC1DRE8tSU5URU5ERURTVEFUVVM6QlVTWQ0KWC1NSUNS
T1NPRlQtQ0RPLUFMTERBWUVWRU5UOkZBTFNFDQpYLU1JQ1JPU09GVC1DRE8tSU1QT1JUQU5DRTox
DQpYLU1JQ1JPU09GVC1DRE8tSU5TVFRZUEU6MQ0KWC1NSUNST1NPRlQtRElTQUxMT1ctQ09VTlRF
UjpGQUxTRQ0KRU5EOlZFVkVOVA0KQkVHSU46VkVWRU5UDQpTVU1NQVJZOkZXOiBNZWV0aW5nIHNj
aGVkdWxlZDogNlRpU0NIIHNlY3VyaXR5DQpEVFNUQVJUO1RaSUQ9UGFjaWZpYyBUaW1lOjIwMTQw
NTI3VDA3MDAwMA0KRFRFTkQ7VFpJRD1QYWNpZmljIFRpbWU6MjAxNDA1MjdUMDgwMDAwDQpVSUQ6
V0VCRVgtTUVFVElORyBDRU5URVItNi4wMzAzNzkwLTI1MzQ3MzUzMi1TVT1jaXNjby1NSz0yMDEw
NDY5NTgtUFc9NnVyaXQNCiB5LUhOPXB0aHViZXJ0DQpSRUNVUlJFTkNFLUlEO1RaSUQ9UGFjaWZp
YyBUaW1lOjIwMTQwNTI2VDAwMDAwMA0KQ0xBU1M6UFVCTElDDQpQUklPUklUWTo1DQpEVFNUQU1Q
OjIwMTQwMjEwVDE1MDAwMFoNClRSQU5TUDpPUEFRVUUNClNUQVRVUzpDT05GSVJNRUQNClNFUVVF
TkNFOjENCkxPQ0FUSU9OOmh0dHBzOi8vY2lzY28ud2ViZXguY29tL2Npc2NvDQpYLU1JQ1JPU09G
VC1DRE8tQVBQVC1TRVFVRU5DRToxDQpYLU1JQ1JPU09GVC1DRE8tT1dORVJBUFBUSUQ6LTENClgt
TUlDUk9TT0ZULUNETy1CVVNZU1RBVFVTOlRFTlRBVElWRQ0KWC1NSUNST1NPRlQtQ0RPLUlOVEVO
REVEU1RBVFVTOkJVU1kNClgtTUlDUk9TT0ZULUNETy1BTExEQVlFVkVOVDpGQUxTRQ0KWC1NSUNS
T1NPRlQtQ0RPLUlNUE9SVEFOQ0U6MQ0KWC1NSUNST1NPRlQtQ0RPLUlOU1RUWVBFOjENClgtTUlD
Uk9TT0ZULURJU0FMTE9XLUNPVU5URVI6RkFMU0UNCkVORDpWRVZFTlQNCkVORDpWQ0FMRU5EQVIN
Cg==

--_000_E045AECD98228444A58C61C200AE1BD84264229Dxmbrcdx01ciscoc_--


From nobody Thu May  8 23:51:35 2014
Return-Path: <pthubert@cisco.com>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 66D9C1A01DE for <6tisch-security@ietfa.amsl.com>; Thu,  8 May 2014 23:51:32 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -7.55
X-Spam-Level: 
X-Spam-Status: No, score=-7.55 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, HTML_MESSAGE=0.001, LOTS_OF_MONEY=0.001, RCVD_IN_DNSWL_HI=-5, RP_MATCHES_RCVD=-0.651, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id DfnGBPAFnO9M for <6tisch-security@ietfa.amsl.com>; Thu,  8 May 2014 23:51:30 -0700 (PDT)
Received: from rcdn-iport-8.cisco.com (rcdn-iport-8.cisco.com [173.37.86.79]) by ietfa.amsl.com (Postfix) with ESMTP id DCFC51A01F1 for <6tisch-security@ietf.org>; Thu,  8 May 2014 23:51:29 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cisco.com; i=@cisco.com; l=19065; q=dns/txt; s=iport; t=1399618285; x=1400827885; h=from:to:subject:sender:date:message-id:references: in-reply-to:mime-version; bh=mfmwY3DC4VOamYKp8Pn9HCU2Rk8FNusrDB0bFAArf0A=; b=Nd7Hnam/MenFu+BeEC5o9jY4o08m3h5+1Gv55RErKGIa3gmCl2zts1oT oS8xMNGlxHyoo5fOKkyLK44ImoT1usURQW3ctMm/vl6rCcj+WY2yw1t1e bks05HhO4WFQiW8p7RH90BWRVPVZ1MCaPhJOy+l64icc2STJPntUrYVaz c=;
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-Anti-Spam-Result: AhQFAK95bFOtJA2B/2dsb2JhbAA/FwOCQkRPWIJnwlEBGXsWdIIlAQEBBCMKGw0RIwEBAQgRAwEBAQsKAQMMAwMCAgIwFAcBAQUCAQEBAQMBEgiIOQ02q2iEKhGgIBeODjMNCgsHB4JdNoEVBIRacYpkik+RQIJjU22BCTl4
X-IronPort-AV: E=Sophos;i="4.97,1016,1389744000";  d="scan'208,217";a="323592632"
Received: from alln-core-9.cisco.com ([173.36.13.129]) by rcdn-iport-8.cisco.com with ESMTP; 09 May 2014 06:51:24 +0000
Received: from xhc-rcd-x02.cisco.com (xhc-rcd-x02.cisco.com [173.37.183.76]) by alln-core-9.cisco.com (8.14.5/8.14.5) with ESMTP id s496pOcq029406 (version=TLSv1/SSLv3 cipher=AES128-SHA bits=128 verify=FAIL); Fri, 9 May 2014 06:51:24 GMT
Received: from xmb-rcd-x01.cisco.com ([169.254.1.229]) by xhc-rcd-x02.cisco.com ([173.37.183.76]) with mapi id 14.03.0123.003; Fri, 9 May 2014 01:51:24 -0500
From: webex <messenger@webex.com>
To: "6tisch-security@ietf.org" <6tisch-security@ietf.org>, Pat Kinney <pat.kinney@KINNEYCONSULTINGLLC.COM>
Thread-Topic: Meeting scheduled: 6TiSCH security
Thread-Index: Ac8hAcvT7HcH1CFASnWDc4zjKF6UTRKUStrA
Sender: "Pascal Thubert (pthubert)" <pthubert@cisco.com>
Date: Fri, 9 May 2014 06:51:24 +0000
Deferred-Delivery: Fri, 9 May 2014 06:51:00 +0000
Message-ID: <E045AECD98228444A58C61C200AE1BD8426422A4@xmb-rcd-x01.cisco.com>
References: <E045AECD98228444A58C61C200AE1BD8416F3AD3@xmb-rcd-x01.cisco.com>
In-Reply-To: <E045AECD98228444A58C61C200AE1BD8416F3AD3@xmb-rcd-x01.cisco.com>
Accept-Language: fr-FR, en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
x-originating-ip: [10.55.22.4]
Content-Type: multipart/alternative; boundary="_000_E045AECD98228444A58C61C200AE1BD8426422A4xmbrcdx01ciscoc_"
MIME-Version: 1.0
Archived-At: http://mailarchive.ietf.org/arch/msg/6tisch-security/r8MNC7tysAeb8-oKnTLM2cEP76I
Subject: [6tisch-security] FW: Meeting scheduled: 6TiSCH security
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 09 May 2014 06:51:32 -0000

--_000_E045AECD98228444A58C61C200AE1BD8426422A4xmbrcdx01ciscoc_
Content-Type: text/plain; charset="Windows-1252"
Content-Transfer-Encoding: quoted-printable



-----Original Appointment-----
From: webex [mailto:messenger@webex.com]
Sent: lundi 3 f=E9vrier 2014 18:03
To: webex; Pascal Thubert (pthubert); Michael Behringer (mbehring); Patrick=
 Wetterwald (pwetterw); Paul Duffy (paduffy); Maik Seewald (maseewal); Mich=
ael Richardson; Rene Struik; 6tisch-security@ietf.org<mailto:6tisch-securit=
y@ietf.org>; Pat Kinney
Subject: Meeting scheduled: 6TiSCH security
When: mardi 27 mai 2014 07:00-08:00 Pacific Time.
Where: https://cisco.webex.com/cisco


You are the host for this online meeting.
Topic:  6TiSCH security
Date:   Every Monday, from Monday, February 10, 2014 to Monday, February 9,=
 2015
Time:   7:00 am, Pacific Standard Time (San Francisco, GMT-08:00)
Meeting Number: 201 046 958
Meeting Password:       6urity
Host Key:       772928 (use this to reclaim host privileges)



To start the online meeting

  1.    Go to https://cisco.webex.com/cisco/j.php?MTID=3Dm2fe139bf876cea3ec=
62750cd580b7908
  2.    Log in to your account.
  3.    Click =93Start Now=94.
  4.    Follow the instructions that appear on your screen.



ALERT =96 PLEASE READ: DO NOT DIAL THE TOLL FREE NUMBERS FROM WITHIN THE (4=
08) OR (919) AREA CODES

Please dial the local access number for your area from the list below:
=95       San Jose/Milpitas (408) area:  525-6800
=95       RTP (919) area:  392-3330

Dialing the WebEx toll free numbers from within 408 or 919 area codes is no=
t enabled (non-Cisco phones).  =93 If you dial the toll-free numbers within=
 the 408 or 919 area codes you will be instructed to hang up and dial the l=
ocal access number.=94 Please use the call-back option whenever possible an=
d otherwise dial local numbers only.  The affected toll free numbers are: (=
866) 432-9903 for the San Jose/Milpitas area and (866) 349-3520 for the RTP=
 area.

-------------------------------------------------------

To join the teleconference only
-------------------------------------------------------

1.      Dial into Cisco WebEx (view all Global Access Numbers at

http://cisco.com/en/US/about/doing_business/conferencing/index.html <http:/=
/cisco.com/en/US/about/doing_business/conferencing/index.html%202>
2.      Follow the prompts to enter the Meeting Number (listed above) or Ac=
cess Code followed by the # sign.

San Jose, CA: +1.408.525.6800  RTP: +1.919.392.3330
US/Canada: +1.866.432.9903  United Kingdom: +44.20.8824.0117
India: +91.80.4350.1111  Germany: +49.619.6773.9002
Japan: +81.3.5763.9394  China: +86.10.8515.5666



For assistance

  1.    Go to https://cisco.webex.com/cisco/mc
  2.    On the left navigation bar, click =93Support=94.
To add this meeting to your calendar program (for example Microsoft Outlook=
), click this link:
https://cisco.webex.com/cisco/j.php?MTID=3Dm4cb181b8d4a0965221bb278991ac9bf=
3
To check whether you have the appropriate players installed for UCF (Univer=
sal Communications Format) rich media files, go to https://cisco.webex.com/=
cisco/systemdiagnosis.php.
http://www.webex.com
CCM:+14085256800x201046958#



--_000_E045AECD98228444A58C61C200AE1BD8426422A4xmbrcdx01ciscoc_
Content-Type: text/html; charset="Windows-1252"
Content-Transfer-Encoding: quoted-printable

<html>
<head>
<meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3DWindows-1=
252">
<meta name=3D"Generator" content=3D"Microsoft Exchange Server">
<!-- converted from rtf -->
<style><!-- .EmailQuote { margin-left: 1pt; padding-left: 4pt; border-left:=
 #800000 2px solid; } --></style>
</head>
<body>
<font face=3D"Calibri" size=3D"2"><span style=3D"font-size:11pt;">
<div><font color=3D"#1F497D">&nbsp;</font></div>
<div><font color=3D"#1F497D">&nbsp;</font></div>
<div style=3D"margin-bottom:6pt;">-----Original Appointment-----<br>

<b>From:</b> webex [<a href=3D"mailto:messenger@webex.com"><font face=3D"Ta=
homa" size=3D"2" color=3D"blue"><span style=3D"font-size:10pt;"><u>mailto:m=
essenger@webex.com</u></span></font></a>]
<br>

<b>Sent:</b> lundi 3 f=E9vrier 2014 18:03<br>

<b>To:</b> webex; Pascal Thubert (pthubert); Michael Behringer (mbehring); =
Patrick Wetterwald (pwetterw); Paul Duffy (paduffy); Maik Seewald (maseewal=
); Michael Richardson; Rene Struik; <a href=3D"mailto:6tisch-security@ietf.=
org"><font face=3D"Tahoma" size=3D"2" color=3D"blue"><span style=3D"font-si=
ze:10pt;"><u>6tisch-security@ietf.org</u></span></font></a>;
Pat Kinney<br>

<b>Subject:</b> Meeting scheduled: 6TiSCH security<br>

<b>When:</b> mardi 27 mai 2014 07:00-08:00 Pacific Time.<br>

<b>Where:</b> <a href=3D"https://cisco.webex.com/cisco"><font face=3D"Tahom=
a" size=3D"2" color=3D"blue"><span style=3D"font-size:10pt;"><u>https://cis=
co.webex.com/cisco</u></span></font></a></div>
<div>&nbsp;</div>
<div>&nbsp;</div>
<div style=3D"margin-bottom:6pt;">You are the host for this online meeting.=
</div>
<div>Topic:&nbsp; 6TiSCH security</div>
<div>Date:&nbsp;&nbsp; Every Monday, from Monday, February 10, 2014 to Mond=
ay, February 9, 2015</div>
<div>Time:&nbsp;&nbsp; 7:00 am, Pacific Standard Time (San Francisco, GMT-0=
8:00)</div>
<div>Meeting Number: 201 046 958</div>
<div>Meeting Password:&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 6urity</div>
<div>Host Key:&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 772928 (use this to recl=
aim host privileges)</div>
<div>&nbsp;</div>
<div><font face=3D"Arial" size=3D"2"><span style=3D"font-size:10pt;">&nbsp;=
</span></font></div>
<div style=3D"margin-top:24pt;"><font face=3D"Cambria" size=3D"4" color=3D"=
#365F91"><span style=3D"font-size:14pt;"><b>To start the online meeting</b>=
</span></font></div>
<div><font face=3D"Arial" size=3D"2"><span style=3D"font-size:10pt;">&nbsp;=
</span></font></div>
<div style=3D"text-indent:-14.15pt;padding-left:14.15pt;">1.&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp; Go to <a href=3D"https://cisco.webex.com/cisco/j.php?MTID=
=3Dm2fe139bf876cea3ec62750cd580b7908"><font face=3D"Arial" size=3D"2" color=
=3D"blue"><span style=3D"font-size:10pt;"><u>https://cisco.webex.com/cisco/=
j.php?MTID=3Dm2fe139bf876cea3ec62750cd580b7908</u></span></font></a></div>
<div style=3D"text-indent:-14.15pt;padding-left:14.15pt;">2.&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp; Log in to your account.</div>
<div style=3D"text-indent:-14.15pt;padding-left:14.15pt;">3.&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp; Click <font color=3D"#1F497D">=93</font>Start Now<font colo=
r=3D"#1F497D">=94</font>.</div>
<div style=3D"text-indent:-14.15pt;padding-left:14.15pt;">4.&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp; Follow the instructions that appear on your screen.</div>
<div>&nbsp;</div>
<div><font face=3D"Arial" size=3D"2"><span style=3D"font-size:10pt;">&nbsp;=
</span></font></div>
<div style=3D"margin-top:10pt;"><font face=3D"Cambria" size=3D"3" color=3D"=
#4F81BD"><span style=3D"font-size:13pt;"><b>ALERT =96 PLEASE READ: DO NOT D=
IAL THE TOLL FREE NUMBERS FROM WITHIN THE (408) OR (919) AREA CODES</b></sp=
an></font></div>
<div><font face=3D"Arial" size=3D"2"><span style=3D"font-size:10pt;">&nbsp;=
</span></font></div>
<div style=3D"margin-bottom:6pt;">Please dial the local access number for y=
our area from the list below:</div>
<ul style=3D"margin:0;padding-left:18pt;">
<li>San Jose/Milpitas (408) area:&nbsp; 525-6800</li><li>RTP (919) area:&nb=
sp; 392-3330</li></ul>
<div><font face=3D"Arial" size=3D"2"><span style=3D"font-size:10pt;">&nbsp;=
</span></font></div>
<div style=3D"margin-bottom:6pt;">Dialing the WebEx toll free numbers from =
within 408 or 919 area codes is not enabled (non-Cisco phones).&nbsp; =93 I=
f you dial the toll-free numbers within the 408 or 919 area codes you will =
be instructed to hang up and dial the local
access number.=94 Please use the call-back option whenever possible and oth=
erwise dial local numbers only.&nbsp; The affected toll free numbers are: (=
866) 432-9903 for the San Jose/Milpitas area and (866) 349-3520 for the RTP=
 area.</div>
<div>&nbsp;</div>
<div><font face=3D"Arial" size=3D"2"><span style=3D"font-size:10pt;">------=
------------------------------------------------- </span></font></div>
<div style=3D"margin-top:24pt;"><font face=3D"Cambria" size=3D"4" color=3D"=
#365F91"><span style=3D"font-size:14pt;"><b>To join the teleconference only=
 </b></span></font></div>
<div><font face=3D"Arial" size=3D"2"><span style=3D"font-size:10pt;">------=
------------------------------------------------- </span></font></div>
<div style=3D"margin-top:10pt;"><font face=3D"Cambria" size=3D"3" color=3D"=
#4F81BD"><span style=3D"font-size:13pt;"><b>1.&nbsp;&nbsp;&nbsp;&nbsp;&nbsp=
; </b><b>Dial into Cisco WebEx (view all Global Access Numbers at </b></spa=
n></font></div>
<div style=3D"margin-top:10pt;"><font face=3D"Times New Roman" size=3D"3" c=
olor=3D"#4F81BD"><span style=3D"font-size:13pt;"><a href=3D"http://cisco.co=
m/en/US/about/doing_business/conferencing/index.html 2"><font face=3D"Cambr=
ia" color=3D"blue"><b><u>http://cisco.com/en/US/about/doing_business/confer=
encing/index.html
</u></b></font></a></span></font></div>
<div style=3D"margin-top:10pt;"><font face=3D"Arial" size=3D"2" color=3D"bl=
ue"><span style=3D"font-size:10pt;"><b><u>2</u></b><font color=3D"#4F81BD">=
<b>.&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </b></font><font color=3D"#4F81BD"><b>Fo=
llow the prompts to enter the Meeting Number (listed above) or Access Code
followed by the # sign. </b></font></span></font></div>
<div>&nbsp;</div>
<div style=3D"margin-bottom:6pt;">San Jose, CA: &#43;1.408.525.6800&nbsp; R=
TP: &#43;1.919.392.3330 </div>
<div style=3D"margin-bottom:6pt;">US/Canada: &#43;1.866.432.9903&nbsp; Unit=
ed Kingdom: &#43;44.20.8824.0117 </div>
<div style=3D"margin-bottom:6pt;">India: &#43;91.80.4350.1111&nbsp; Germany=
: &#43;49.619.6773.9002 </div>
<div style=3D"margin-bottom:6pt;">Japan: &#43;81.3.5763.9394&nbsp; China: &=
#43;86.10.8515.5666</div>
<div>&nbsp;</div>
<div><font face=3D"Arial" size=3D"2"><span style=3D"font-size:10pt;">&nbsp;=
</span></font></div>
<div style=3D"margin-top:24pt;"><font face=3D"Cambria" size=3D"4" color=3D"=
#365F91"><span style=3D"font-size:14pt;"><b>For assistance</b></span></font=
></div>
<div><font face=3D"Arial" size=3D"2"><span style=3D"font-size:10pt;">&nbsp;=
</span></font></div>
<div style=3D"text-indent:-14.15pt;padding-left:14.15pt;">1.&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp; Go to <a href=3D"https://cisco.webex.com/cisco/mc"><font fa=
ce=3D"Arial" size=3D"2" color=3D"blue"><span style=3D"font-size:10pt;"><u>h=
ttps://cisco.webex.com/cisco/mc</u></span></font></a></div>
<div style=3D"text-indent:-14.15pt;padding-left:14.15pt;">2.&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp; On the left navigation bar, click <font color=3D"#1F497D">=
=93</font>Support<font color=3D"#1F497D">=94</font>.</div>
<div style=3D"margin-bottom:6pt;">To add this meeting to your calendar prog=
ram (for example Microsoft Outlook), click this link:</div>
<div style=3D"margin-bottom:6pt;"><a href=3D"https://cisco.webex.com/cisco/=
j.php?MTID=3Dm4cb181b8d4a0965221bb278991ac9bf3"><font face=3D"Arial" size=
=3D"2" color=3D"blue"><span style=3D"font-size:10pt;"><u>https://cisco.webe=
x.com/cisco/j.php?MTID=3Dm4cb181b8d4a0965221bb278991ac9bf3</u></span></font=
></a></div>
<div style=3D"margin-bottom:6pt;">To check whether you have the appropriate=
 players installed for UCF (Universal Communications Format) rich media fil=
es, go to <a href=3D"https://cisco.webex.com/cisco/systemdiagnosis.php"><fo=
nt face=3D"Arial" size=3D"2" color=3D"blue"><span style=3D"font-size:10pt;"=
><u>https://cisco.webex.com/cisco/systemdiagnosis.php</u></span></font></a>=
.</div>
<div style=3D"margin-bottom:6pt;"><a href=3D"http://www.webex.com"><font fa=
ce=3D"Arial" size=3D"2" color=3D"blue"><span style=3D"font-size:10pt;"><u>h=
ttp://www.webex.com</u></span></font></a></div>
<div style=3D"margin-bottom:6pt;">CCM:&#43;14085256800x201046958# </div>
<div>&nbsp;</div>
<div>&nbsp;</div>
</span></font>
</body>
</html>

--_000_E045AECD98228444A58C61C200AE1BD8426422A4xmbrcdx01ciscoc_
Content-Type: text/calendar; charset="utf-8"; method=REQUEST
Content-Transfer-Encoding: base64

QkVHSU46VkNBTEVOREFSDQpNRVRIT0Q6UkVRVUVTVA0KUFJPRElEOk1pY3Jvc29mdCBFeGNoYW5n
ZSBTZXJ2ZXIgMjAxMA0KVkVSU0lPTjoyLjANCkJFR0lOOlZUSU1FWk9ORQ0KVFpJRDpQYWNpZmlj
IFRpbWUNCkJFR0lOOlNUQU5EQVJEDQpEVFNUQVJUOjE2MDEwMTAxVDAyMDAwMA0KVFpPRkZTRVRG
Uk9NOi0wNzAwDQpUWk9GRlNFVFRPOi0wODAwDQpSUlVMRTpGUkVRPVlFQVJMWTtJTlRFUlZBTD0x
O0JZREFZPTFTVTtCWU1PTlRIPTExDQpFTkQ6U1RBTkRBUkQNCkJFR0lOOkRBWUxJR0hUDQpEVFNU
QVJUOjE2MDEwMTAxVDAyMDAwMA0KVFpPRkZTRVRGUk9NOi0wODAwDQpUWk9GRlNFVFRPOi0wNzAw
DQpSUlVMRTpGUkVRPVlFQVJMWTtJTlRFUlZBTD0xO0JZREFZPTJTVTtCWU1PTlRIPTMNCkVORDpE
QVlMSUdIVA0KRU5EOlZUSU1FWk9ORQ0KQkVHSU46VkVWRU5UDQpPUkdBTklaRVI7Q049d2ViZXg7
U0VOVC1CWT0iTUFJTFRPOnB0aHViZXJ0QGNpc2NvLmNvbSI6TUFJTFRPOm1lc3NlbmdlckB3ZWJl
eA0KIC5jb20NCkFUVEVOREVFO1JPTEU9UkVRLVBBUlRJQ0lQQU5UO1BBUlRTVEFUPU5FRURTLUFD
VElPTjtSU1ZQPUZBTFNFO0NOPTZ0aXNjaC1zZQ0KIGN1cml0eUBpZXRmLm9yZzpNQUlMVE86NnRp
c2NoLXNlY3VyaXR5QGlldGYub3JnDQpBVFRFTkRFRTtST0xFPVJFUS1QQVJUSUNJUEFOVDtQQVJU
U1RBVD1ORUVEUy1BQ1RJT047UlNWUD1GQUxTRTtDTj1QYXQgS2lubmUNCiB5Ok1BSUxUTzpwYXQu
a2lubmV5QEtJTk5FWUNPTlNVTFRJTkdMTEMuQ09NDQpERVNDUklQVElPTjtMQU5HVUFHRT1lbi1V
UzpcblxuLS0tLS1PcmlnaW5hbCBBcHBvaW50bWVudC0tLS0tXG5Gcm9tOiB3ZWJleCANCiBbbWFp
bHRvOm1lc3NlbmdlckB3ZWJleC5jb21dXG5TZW50OiBsdW5kaSAzIGbDqXZyaWVyIDIwMTQgMTg6
MDNcblRvOiB3ZWJleA0KIFw7IFBhc2NhbCBUaHViZXJ0IChwdGh1YmVydClcOyBNaWNoYWVsIEJl
aHJpbmdlciAobWJlaHJpbmcpXDsgUGF0cmljayBXZXR0DQogZXJ3YWxkIChwd2V0dGVydylcOyBQ
YXVsIER1ZmZ5IChwYWR1ZmZ5KVw7IE1haWsgU2Vld2FsZCAobWFzZWV3YWwpXDsgTWljaGENCiBl
bCBSaWNoYXJkc29uXDsgUmVuZSBTdHJ1aWtcOyA2dGlzY2gtc2VjdXJpdHlAaWV0Zi5vcmc8bWFp
bHRvOjZ0aXNjaC1zZWN1cg0KIGl0eUBpZXRmLm9yZz5cOyBQYXQgS2lubmV5XG5TdWJqZWN0OiBN
ZWV0aW5nIHNjaGVkdWxlZDogNlRpU0NIIHNlY3VyaXR5XG5XDQogaGVuOiBtYXJkaSAyNyBtYWkg
MjAxNCAwNzowMC0wODowMCBQYWNpZmljIFRpbWUuXG5XaGVyZTogaHR0cHM6Ly9jaXNjby53ZWIN
CiBleC5jb20vY2lzY29cblxuXG5Zb3UgYXJlIHRoZSBob3N0IGZvciB0aGlzIG9ubGluZSBtZWV0
aW5nLlxuVG9waWM6ICA2VGlTQw0KIEggc2VjdXJpdHlcbkRhdGU6ICAgRXZlcnkgTW9uZGF5XCwg
ZnJvbSBNb25kYXlcLCBGZWJydWFyeSAxMFwsIDIwMTQgdG8gTW9uDQogZGF5XCwgRmVicnVhcnkg
OVwsIDIwMTVcblRpbWU6ICAgNzowMCBhbVwsIFBhY2lmaWMgU3RhbmRhcmQgVGltZSAoU2FuIEZy
YW4NCiBjaXNjb1wsIEdNVC0wODowMClcbk1lZXRpbmcgTnVtYmVyOiAyMDEgMDQ2IDk1OFxuTWVl
dGluZyBQYXNzd29yZDogICAgICAgNg0KIHVyaXR5XG5Ib3N0IEtleTogICAgICAgNzcyOTI4ICh1
c2UgdGhpcyB0byByZWNsYWltIGhvc3QgcHJpdmlsZWdlcylcblxuXG5cDQogblRvIHN0YXJ0IHRo
ZSBvbmxpbmUgbWVldGluZ1xuXG4gIDEuICAgIEdvIHRvIGh0dHBzOi8vY2lzY28ud2ViZXguY29t
L2Npc2MNCiBvL2oucGhwP01USUQ9bTJmZTEzOWJmODc2Y2VhM2VjNjI3NTBjZDU4MGI3OTA4XG4g
IDIuICAgIExvZyBpbiB0byB5b3VyIGFjYw0KIG91bnQuXG4gIDMuICAgIENsaWNrIOKAnFN0YXJ0
IE5vd+KAnS5cbiAgNC4gICAgRm9sbG93IHRoZSBpbnN0cnVjdGlvbnMgdGhhDQogdCBhcHBlYXIg
b24geW91ciBzY3JlZW4uXG5cblxuXG5BTEVSVCDigJMgUExFQVNFIFJFQUQ6IERPIE5PVCBESUFM
IFRIRSBUT0wNCiBMIEZSRUUgTlVNQkVSUyBGUk9NIFdJVEhJTiBUSEUgKDQwOCkgT1IgKDkxOSkg
QVJFQSBDT0RFU1xuXG5QbGVhc2UgZGlhbCB0aA0KIGUgbG9jYWwgYWNjZXNzIG51bWJlciBmb3Ig
eW91ciBhcmVhIGZyb20gdGhlIGxpc3QgYmVsb3c6XG7igKIgICAgICAgU2FuIEpvDQogc2UvTWls
cGl0YXMgKDQwOCkgYXJlYTogIDUyNS02ODAwXG7igKIgICAgICAgUlRQICg5MTkpIGFyZWE6ICAz
OTItMzMzMFxuXG4NCiBEaWFsaW5nIHRoZSBXZWJFeCB0b2xsIGZyZWUgbnVtYmVycyBmcm9tIHdp
dGhpbiA0MDggb3IgOTE5IGFyZWEgY29kZXMgaXMgbg0KIG90IGVuYWJsZWQgKG5vbi1DaXNjbyBw
aG9uZXMpLiAg4oCcIElmIHlvdSBkaWFsIHRoZSB0b2xsLWZyZWUgbnVtYmVycyB3aXRoDQogaW4g
dGhlIDQwOCBvciA5MTkgYXJlYSBjb2RlcyB5b3Ugd2lsbCBiZSBpbnN0cnVjdGVkIHRvIGhhbmcg
dXAgYW5kIGRpYWwgdGgNCiBlIGxvY2FsIGFjY2VzcyBudW1iZXIu4oCdIFBsZWFzZSB1c2UgdGhl
IGNhbGwtYmFjayBvcHRpb24gd2hlbmV2ZXIgcG9zc2libA0KIGUgYW5kIG90aGVyd2lzZSBkaWFs
IGxvY2FsIG51bWJlcnMgb25seS4gIFRoZSBhZmZlY3RlZCB0b2xsIGZyZWUgbnVtYmVycyBhDQog
cmU6ICg4NjYpIDQzMi05OTAzIGZvciB0aGUgU2FuIEpvc2UvTWlscGl0YXMgYXJlYSBhbmQgKDg2
NikgMzQ5LTM1MjAgZm9yIHQNCiBoZSBSVFAgYXJlYS5cblxuLS0tLS0tLS0tLS0tLS0tLS0tLS0t
LS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLVxuXA0KIG5UbyBqb2luIHRoZSB0ZWxl
Y29uZmVyZW5jZSBvbmx5XG4tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0t
DQogLS0tLS0tLS0tLS0tLS0tXG5cbjEuICAgICAgRGlhbCBpbnRvIENpc2NvIFdlYkV4ICh2aWV3
IGFsbCBHbG9iYWwgQWNjZXNzIE4NCiB1bWJlcnMgYXRcblxuaHR0cDovL2Npc2NvLmNvbS9lbi9V
Uy9hYm91dC9kb2luZ19idXNpbmVzcy9jb25mZXJlbmNpbmcvaW5kZQ0KIHguaHRtbCA8aHR0cDov
L2Npc2NvLmNvbS9lbi9VUy9hYm91dC9kb2luZ19idXNpbmVzcy9jb25mZXJlbmNpbmcvaW5kZXgu
aHRtDQogbCUyMDI+XG4yLiAgICAgIEZvbGxvdyB0aGUgcHJvbXB0cyB0byBlbnRlciB0aGUgTWVl
dGluZyBOdW1iZXIgKGxpc3RlZCBhYm8NCiB2ZSkgb3IgQWNjZXNzIENvZGUgZm9sbG93ZWQgYnkg
dGhlICMgc2lnbi5cblxuU2FuIEpvc2VcLCBDQTogKzEuNDA4LjUyNS42OA0KIDAwICBSVFA6ICsx
LjkxOS4zOTIuMzMzMFxuVVMvQ2FuYWRhOiArMS44NjYuNDMyLjk5MDMgIFVuaXRlZCBLaW5nZG9t
OiArNDQuDQogMjAuODgyNC4wMTE3XG5JbmRpYTogKzkxLjgwLjQzNTAuMTExMSAgR2VybWFueTog
KzQ5LjYxOS42NzczLjkwMDJcbkphcGFuOiANCiArODEuMy41NzYzLjkzOTQgIENoaW5hOiArODYu
MTAuODUxNS41NjY2XG5cblxuXG5Gb3IgYXNzaXN0YW5jZVxuXG4gIDEuICAgIA0KIEdvIHRvIGh0
dHBzOi8vY2lzY28ud2ViZXguY29tL2Npc2NvL21jXG4gIDIuICAgIE9uIHRoZSBsZWZ0IG5hdmln
YXRpb24gYmFyDQogXCwgY2xpY2sg4oCcU3VwcG9ydOKAnS5cblRvIGFkZCB0aGlzIG1lZXRpbmcg
dG8geW91ciBjYWxlbmRhciBwcm9ncmFtIChmb3INCiAgZXhhbXBsZSBNaWNyb3NvZnQgT3V0bG9v
aylcLCBjbGljayB0aGlzIGxpbms6XG5odHRwczovL2Npc2NvLndlYmV4LmNvbS9jaQ0KIHNjby9q
LnBocD9NVElEPW00Y2IxODFiOGQ0YTA5NjUyMjFiYjI3ODk5MWFjOWJmM1xuVG8gY2hlY2sgd2hl
dGhlciB5b3UgaGF2DQogZSB0aGUgYXBwcm9wcmlhdGUgcGxheWVycyBpbnN0YWxsZWQgZm9yIFVD
RiAoVW5pdmVyc2FsIENvbW11bmljYXRpb25zIEZvcm0NCiBhdCkgcmljaCBtZWRpYSBmaWxlc1ws
IGdvIHRvIGh0dHBzOi8vY2lzY28ud2ViZXguY29tL2Npc2NvL3N5c3RlbWRpYWdub3Npcw0KIC5w
aHAuXG5odHRwOi8vd3d3LndlYmV4LmNvbVxuQ0NNOisxNDA4NTI1NjgwMHgyMDEwNDY5NTgjXG5c
blxuDQpTVU1NQVJZO0xBTkdVQUdFPWVuLVVTOkZXOiBNZWV0aW5nIHNjaGVkdWxlZDogNlRpU0NI
IHNlY3VyaXR5DQpEVFNUQVJUO1RaSUQ9UGFjaWZpYyBUaW1lOjIwMTQwNTI3VDA3MDAwMA0KRFRF
TkQ7VFpJRD1QYWNpZmljIFRpbWU6MjAxNDA1MjdUMDgwMDAwDQpVSUQ6V0VCRVgtTUVFVElORyBD
RU5URVItNi4wMzAzNzkwLTI1MzQ3MzUzMi1TVT1jaXNjby1NSz0yMDEwNDY5NTgtUFc9NnVyaXQN
CiB5LUhOPXB0aHViZXJ0DQpSRUNVUlJFTkNFLUlEO1RaSUQ9UGFjaWZpYyBUaW1lOjIwMTQwNTI2
VDA3MDAwMA0KQ0xBU1M6UFVCTElDDQpQUklPUklUWTo1DQpEVFNUQU1QOjIwMTQwMjEwVDE1MDAw
MFoNClRSQU5TUDpPUEFRVUUNClNUQVRVUzpDT05GSVJNRUQNClNFUVVFTkNFOjENCkxPQ0FUSU9O
O0xBTkdVQUdFPWVuLVVTOmh0dHBzOi8vY2lzY28ud2ViZXguY29tL2Npc2NvDQpYLU1JQ1JPU09G
VC1DRE8tQVBQVC1TRVFVRU5DRToxDQpYLU1JQ1JPU09GVC1DRE8tT1dORVJBUFBUSUQ6LTENClgt
TUlDUk9TT0ZULUNETy1CVVNZU1RBVFVTOlRFTlRBVElWRQ0KWC1NSUNST1NPRlQtQ0RPLUlOVEVO
REVEU1RBVFVTOkJVU1kNClgtTUlDUk9TT0ZULUNETy1BTExEQVlFVkVOVDpGQUxTRQ0KWC1NSUNS
T1NPRlQtQ0RPLUlNUE9SVEFOQ0U6MQ0KWC1NSUNST1NPRlQtQ0RPLUlOU1RUWVBFOjMNClgtTUlD
Uk9TT0ZULURJU0FMTE9XLUNPVU5URVI6RkFMU0UNCkJFR0lOOlZBTEFSTQ0KQUNUSU9OOkRJU1BM
QVkNCkRFU0NSSVBUSU9OOlJFTUlOREVSDQpUUklHR0VSO1JFTEFURUQ9U1RBUlQ6LVBUMTVNDQpF
TkQ6VkFMQVJNDQpFTkQ6VkVWRU5UDQpFTkQ6VkNBTEVOREFSDQo=

--_000_E045AECD98228444A58C61C200AE1BD8426422A4xmbrcdx01ciscoc_--


From nobody Thu May  8 23:51:39 2014
Return-Path: <pthubert@cisco.com>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id AD5101A0201 for <6tisch-security@ietfa.amsl.com>; Thu,  8 May 2014 23:51:34 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -7.55
X-Spam-Level: 
X-Spam-Status: No, score=-7.55 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, HTML_MESSAGE=0.001, LOTS_OF_MONEY=0.001, RCVD_IN_DNSWL_HI=-5, RP_MATCHES_RCVD=-0.651, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id BI7RnKyfqO7J for <6tisch-security@ietfa.amsl.com>; Thu,  8 May 2014 23:51:32 -0700 (PDT)
Received: from rcdn-iport-8.cisco.com (rcdn-iport-8.cisco.com [173.37.86.79]) by ietfa.amsl.com (Postfix) with ESMTP id 95FFE1A01EE for <6tisch-security@ietf.org>; Thu,  8 May 2014 23:51:32 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cisco.com; i=@cisco.com; l=19065; q=dns/txt; s=iport; t=1399618288; x=1400827888; h=from:to:subject:sender:date:message-id:references: in-reply-to:mime-version; bh=VBv7Dw/ooB6ner8gcDg61RP/+5p95qGnTZGUAK34M1c=; b=lk8ikqKOZp5Yq4PsgsvzEbqOv4+FPDehp3ofoL50vL8SABJjmaaZtbmu 35qdny417WbODVmjoVKqzU3r2Kf7dXtXZ9f+XFv4AB79epmGGWTxTvARA exp7T5M7RDsmqXmuTJ0A0FDcLRDGPIxdgl6Y1AP+LXnW8rT6dGgIA3RKk 0=;
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-Anti-Spam-Result: AhQFAK95bFOtJA2N/2dsb2JhbAA/FwOCQkRPWIJnwlEBGXsWdIIlAQEBBCMKGw0RIwEBAQgRAwEBAQsKAQMMAwMCAgIwFAcBAQUCAQEBAQMBEgiIOQ02q2iEKhGgIBeODjMNCgsHB4JdNoEVBIRacYpkik+RQIJjU22BCTl4
X-IronPort-AV: E=Sophos;i="4.97,1016,1389744000";  d="scan'208,217";a="323592642"
Received: from alln-core-8.cisco.com ([173.36.13.141]) by rcdn-iport-8.cisco.com with ESMTP; 09 May 2014 06:51:27 +0000
Received: from xhc-rcd-x07.cisco.com (xhc-rcd-x07.cisco.com [173.37.183.81]) by alln-core-8.cisco.com (8.14.5/8.14.5) with ESMTP id s496pRje010616 (version=TLSv1/SSLv3 cipher=AES128-SHA bits=128 verify=FAIL); Fri, 9 May 2014 06:51:27 GMT
Received: from xmb-rcd-x01.cisco.com ([169.254.1.229]) by xhc-rcd-x07.cisco.com ([173.37.183.81]) with mapi id 14.03.0123.003; Fri, 9 May 2014 01:51:27 -0500
From: webex <messenger@webex.com>
To: "6tisch-security@ietf.org" <6tisch-security@ietf.org>, Pat Kinney <pat.kinney@KINNEYCONSULTINGLLC.COM>
Thread-Topic: Meeting scheduled: 6TiSCH security
Thread-Index: Ac8hAcvT7HcH1CFASnWDc4zjKF6UTRKUS9mA
Sender: "Pascal Thubert (pthubert)" <pthubert@cisco.com>
Date: Fri, 9 May 2014 06:51:26 +0000
Deferred-Delivery: Fri, 9 May 2014 06:51:00 +0000
Message-ID: <E045AECD98228444A58C61C200AE1BD8426422AB@xmb-rcd-x01.cisco.com>
References: <E045AECD98228444A58C61C200AE1BD8416F3AD3@xmb-rcd-x01.cisco.com>
In-Reply-To: <E045AECD98228444A58C61C200AE1BD8416F3AD3@xmb-rcd-x01.cisco.com>
Accept-Language: fr-FR, en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
x-originating-ip: [10.55.22.4]
Content-Type: multipart/alternative; boundary="_000_E045AECD98228444A58C61C200AE1BD8426422ABxmbrcdx01ciscoc_"
MIME-Version: 1.0
Archived-At: http://mailarchive.ietf.org/arch/msg/6tisch-security/DghFpzScHE59qmw5A628ukq6AKk
Subject: [6tisch-security] FW: Meeting scheduled: 6TiSCH security
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 09 May 2014 06:51:34 -0000

--_000_E045AECD98228444A58C61C200AE1BD8426422ABxmbrcdx01ciscoc_
Content-Type: text/plain; charset="Windows-1252"
Content-Transfer-Encoding: quoted-printable



-----Original Appointment-----
From: webex [mailto:messenger@webex.com]
Sent: lundi 3 f=E9vrier 2014 18:03
To: webex; Pascal Thubert (pthubert); Michael Behringer (mbehring); Patrick=
 Wetterwald (pwetterw); Paul Duffy (paduffy); Maik Seewald (maseewal); Mich=
ael Richardson; Rene Struik; 6tisch-security@ietf.org<mailto:6tisch-securit=
y@ietf.org>; Pat Kinney
Subject: Meeting scheduled: 6TiSCH security
When: mardi 20 mai 2014 07:00-08:00 Pacific Time.
Where: https://cisco.webex.com/cisco


You are the host for this online meeting.
Topic:  6TiSCH security
Date:   Every Monday, from Monday, February 10, 2014 to Monday, February 9,=
 2015
Time:   7:00 am, Pacific Standard Time (San Francisco, GMT-08:00)
Meeting Number: 201 046 958
Meeting Password:       6urity
Host Key:       772928 (use this to reclaim host privileges)



To start the online meeting

  1.    Go to https://cisco.webex.com/cisco/j.php?MTID=3Dm2fe139bf876cea3ec=
62750cd580b7908
  2.    Log in to your account.
  3.    Click =93Start Now=94.
  4.    Follow the instructions that appear on your screen.



ALERT =96 PLEASE READ: DO NOT DIAL THE TOLL FREE NUMBERS FROM WITHIN THE (4=
08) OR (919) AREA CODES

Please dial the local access number for your area from the list below:
=95       San Jose/Milpitas (408) area:  525-6800
=95       RTP (919) area:  392-3330

Dialing the WebEx toll free numbers from within 408 or 919 area codes is no=
t enabled (non-Cisco phones).  =93 If you dial the toll-free numbers within=
 the 408 or 919 area codes you will be instructed to hang up and dial the l=
ocal access number.=94 Please use the call-back option whenever possible an=
d otherwise dial local numbers only.  The affected toll free numbers are: (=
866) 432-9903 for the San Jose/Milpitas area and (866) 349-3520 for the RTP=
 area.

-------------------------------------------------------

To join the teleconference only
-------------------------------------------------------

1.      Dial into Cisco WebEx (view all Global Access Numbers at

http://cisco.com/en/US/about/doing_business/conferencing/index.html <http:/=
/cisco.com/en/US/about/doing_business/conferencing/index.html%202>
2.      Follow the prompts to enter the Meeting Number (listed above) or Ac=
cess Code followed by the # sign.

San Jose, CA: +1.408.525.6800  RTP: +1.919.392.3330
US/Canada: +1.866.432.9903  United Kingdom: +44.20.8824.0117
India: +91.80.4350.1111  Germany: +49.619.6773.9002
Japan: +81.3.5763.9394  China: +86.10.8515.5666



For assistance

  1.    Go to https://cisco.webex.com/cisco/mc
  2.    On the left navigation bar, click =93Support=94.
To add this meeting to your calendar program (for example Microsoft Outlook=
), click this link:
https://cisco.webex.com/cisco/j.php?MTID=3Dm4cb181b8d4a0965221bb278991ac9bf=
3
To check whether you have the appropriate players installed for UCF (Univer=
sal Communications Format) rich media files, go to https://cisco.webex.com/=
cisco/systemdiagnosis.php.
http://www.webex.com
CCM:+14085256800x201046958#



--_000_E045AECD98228444A58C61C200AE1BD8426422ABxmbrcdx01ciscoc_
Content-Type: text/html; charset="Windows-1252"
Content-Transfer-Encoding: quoted-printable

<html>
<head>
<meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3DWindows-1=
252">
<meta name=3D"Generator" content=3D"Microsoft Exchange Server">
<!-- converted from rtf -->
<style><!-- .EmailQuote { margin-left: 1pt; padding-left: 4pt; border-left:=
 #800000 2px solid; } --></style>
</head>
<body>
<font face=3D"Calibri" size=3D"2"><span style=3D"font-size:11pt;">
<div><font color=3D"#1F497D">&nbsp;</font></div>
<div><font color=3D"#1F497D">&nbsp;</font></div>
<div style=3D"margin-bottom:6pt;">-----Original Appointment-----<br>

<b>From:</b> webex [<a href=3D"mailto:messenger@webex.com"><font face=3D"Ta=
homa" size=3D"2" color=3D"blue"><span style=3D"font-size:10pt;"><u>mailto:m=
essenger@webex.com</u></span></font></a>]
<br>

<b>Sent:</b> lundi 3 f=E9vrier 2014 18:03<br>

<b>To:</b> webex; Pascal Thubert (pthubert); Michael Behringer (mbehring); =
Patrick Wetterwald (pwetterw); Paul Duffy (paduffy); Maik Seewald (maseewal=
); Michael Richardson; Rene Struik; <a href=3D"mailto:6tisch-security@ietf.=
org"><font face=3D"Tahoma" size=3D"2" color=3D"blue"><span style=3D"font-si=
ze:10pt;"><u>6tisch-security@ietf.org</u></span></font></a>;
Pat Kinney<br>

<b>Subject:</b> Meeting scheduled: 6TiSCH security<br>

<b>When:</b> mardi 20 mai 2014 07:00-08:00 Pacific Time.<br>

<b>Where:</b> <a href=3D"https://cisco.webex.com/cisco"><font face=3D"Tahom=
a" size=3D"2" color=3D"blue"><span style=3D"font-size:10pt;"><u>https://cis=
co.webex.com/cisco</u></span></font></a></div>
<div>&nbsp;</div>
<div>&nbsp;</div>
<div style=3D"margin-bottom:6pt;">You are the host for this online meeting.=
</div>
<div>Topic:&nbsp; 6TiSCH security</div>
<div>Date:&nbsp;&nbsp; Every Monday, from Monday, February 10, 2014 to Mond=
ay, February 9, 2015</div>
<div>Time:&nbsp;&nbsp; 7:00 am, Pacific Standard Time (San Francisco, GMT-0=
8:00)</div>
<div>Meeting Number: 201 046 958</div>
<div>Meeting Password:&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 6urity</div>
<div>Host Key:&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 772928 (use this to recl=
aim host privileges)</div>
<div>&nbsp;</div>
<div><font face=3D"Arial" size=3D"2"><span style=3D"font-size:10pt;">&nbsp;=
</span></font></div>
<div style=3D"margin-top:24pt;"><font face=3D"Cambria" size=3D"4" color=3D"=
#365F91"><span style=3D"font-size:14pt;"><b>To start the online meeting</b>=
</span></font></div>
<div><font face=3D"Arial" size=3D"2"><span style=3D"font-size:10pt;">&nbsp;=
</span></font></div>
<div style=3D"text-indent:-14.15pt;padding-left:14.15pt;">1.&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp; Go to <a href=3D"https://cisco.webex.com/cisco/j.php?MTID=
=3Dm2fe139bf876cea3ec62750cd580b7908"><font face=3D"Arial" size=3D"2" color=
=3D"blue"><span style=3D"font-size:10pt;"><u>https://cisco.webex.com/cisco/=
j.php?MTID=3Dm2fe139bf876cea3ec62750cd580b7908</u></span></font></a></div>
<div style=3D"text-indent:-14.15pt;padding-left:14.15pt;">2.&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp; Log in to your account.</div>
<div style=3D"text-indent:-14.15pt;padding-left:14.15pt;">3.&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp; Click <font color=3D"#1F497D">=93</font>Start Now<font colo=
r=3D"#1F497D">=94</font>.</div>
<div style=3D"text-indent:-14.15pt;padding-left:14.15pt;">4.&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp; Follow the instructions that appear on your screen.</div>
<div>&nbsp;</div>
<div><font face=3D"Arial" size=3D"2"><span style=3D"font-size:10pt;">&nbsp;=
</span></font></div>
<div style=3D"margin-top:10pt;"><font face=3D"Cambria" size=3D"3" color=3D"=
#4F81BD"><span style=3D"font-size:13pt;"><b>ALERT =96 PLEASE READ: DO NOT D=
IAL THE TOLL FREE NUMBERS FROM WITHIN THE (408) OR (919) AREA CODES</b></sp=
an></font></div>
<div><font face=3D"Arial" size=3D"2"><span style=3D"font-size:10pt;">&nbsp;=
</span></font></div>
<div style=3D"margin-bottom:6pt;">Please dial the local access number for y=
our area from the list below:</div>
<ul style=3D"margin:0;padding-left:18pt;">
<li>San Jose/Milpitas (408) area:&nbsp; 525-6800</li><li>RTP (919) area:&nb=
sp; 392-3330</li></ul>
<div><font face=3D"Arial" size=3D"2"><span style=3D"font-size:10pt;">&nbsp;=
</span></font></div>
<div style=3D"margin-bottom:6pt;">Dialing the WebEx toll free numbers from =
within 408 or 919 area codes is not enabled (non-Cisco phones).&nbsp; =93 I=
f you dial the toll-free numbers within the 408 or 919 area codes you will =
be instructed to hang up and dial the local
access number.=94 Please use the call-back option whenever possible and oth=
erwise dial local numbers only.&nbsp; The affected toll free numbers are: (=
866) 432-9903 for the San Jose/Milpitas area and (866) 349-3520 for the RTP=
 area.</div>
<div>&nbsp;</div>
<div><font face=3D"Arial" size=3D"2"><span style=3D"font-size:10pt;">------=
------------------------------------------------- </span></font></div>
<div style=3D"margin-top:24pt;"><font face=3D"Cambria" size=3D"4" color=3D"=
#365F91"><span style=3D"font-size:14pt;"><b>To join the teleconference only=
 </b></span></font></div>
<div><font face=3D"Arial" size=3D"2"><span style=3D"font-size:10pt;">------=
------------------------------------------------- </span></font></div>
<div style=3D"margin-top:10pt;"><font face=3D"Cambria" size=3D"3" color=3D"=
#4F81BD"><span style=3D"font-size:13pt;"><b>1.&nbsp;&nbsp;&nbsp;&nbsp;&nbsp=
; </b><b>Dial into Cisco WebEx (view all Global Access Numbers at </b></spa=
n></font></div>
<div style=3D"margin-top:10pt;"><font face=3D"Times New Roman" size=3D"3" c=
olor=3D"#4F81BD"><span style=3D"font-size:13pt;"><a href=3D"http://cisco.co=
m/en/US/about/doing_business/conferencing/index.html 2"><font face=3D"Cambr=
ia" color=3D"blue"><b><u>http://cisco.com/en/US/about/doing_business/confer=
encing/index.html
</u></b></font></a></span></font></div>
<div style=3D"margin-top:10pt;"><font face=3D"Arial" size=3D"2" color=3D"bl=
ue"><span style=3D"font-size:10pt;"><b><u>2</u></b><font color=3D"#4F81BD">=
<b>.&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </b></font><font color=3D"#4F81BD"><b>Fo=
llow the prompts to enter the Meeting Number (listed above) or Access Code
followed by the # sign. </b></font></span></font></div>
<div>&nbsp;</div>
<div style=3D"margin-bottom:6pt;">San Jose, CA: &#43;1.408.525.6800&nbsp; R=
TP: &#43;1.919.392.3330 </div>
<div style=3D"margin-bottom:6pt;">US/Canada: &#43;1.866.432.9903&nbsp; Unit=
ed Kingdom: &#43;44.20.8824.0117 </div>
<div style=3D"margin-bottom:6pt;">India: &#43;91.80.4350.1111&nbsp; Germany=
: &#43;49.619.6773.9002 </div>
<div style=3D"margin-bottom:6pt;">Japan: &#43;81.3.5763.9394&nbsp; China: &=
#43;86.10.8515.5666</div>
<div>&nbsp;</div>
<div><font face=3D"Arial" size=3D"2"><span style=3D"font-size:10pt;">&nbsp;=
</span></font></div>
<div style=3D"margin-top:24pt;"><font face=3D"Cambria" size=3D"4" color=3D"=
#365F91"><span style=3D"font-size:14pt;"><b>For assistance</b></span></font=
></div>
<div><font face=3D"Arial" size=3D"2"><span style=3D"font-size:10pt;">&nbsp;=
</span></font></div>
<div style=3D"text-indent:-14.15pt;padding-left:14.15pt;">1.&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp; Go to <a href=3D"https://cisco.webex.com/cisco/mc"><font fa=
ce=3D"Arial" size=3D"2" color=3D"blue"><span style=3D"font-size:10pt;"><u>h=
ttps://cisco.webex.com/cisco/mc</u></span></font></a></div>
<div style=3D"text-indent:-14.15pt;padding-left:14.15pt;">2.&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp; On the left navigation bar, click <font color=3D"#1F497D">=
=93</font>Support<font color=3D"#1F497D">=94</font>.</div>
<div style=3D"margin-bottom:6pt;">To add this meeting to your calendar prog=
ram (for example Microsoft Outlook), click this link:</div>
<div style=3D"margin-bottom:6pt;"><a href=3D"https://cisco.webex.com/cisco/=
j.php?MTID=3Dm4cb181b8d4a0965221bb278991ac9bf3"><font face=3D"Arial" size=
=3D"2" color=3D"blue"><span style=3D"font-size:10pt;"><u>https://cisco.webe=
x.com/cisco/j.php?MTID=3Dm4cb181b8d4a0965221bb278991ac9bf3</u></span></font=
></a></div>
<div style=3D"margin-bottom:6pt;">To check whether you have the appropriate=
 players installed for UCF (Universal Communications Format) rich media fil=
es, go to <a href=3D"https://cisco.webex.com/cisco/systemdiagnosis.php"><fo=
nt face=3D"Arial" size=3D"2" color=3D"blue"><span style=3D"font-size:10pt;"=
><u>https://cisco.webex.com/cisco/systemdiagnosis.php</u></span></font></a>=
.</div>
<div style=3D"margin-bottom:6pt;"><a href=3D"http://www.webex.com"><font fa=
ce=3D"Arial" size=3D"2" color=3D"blue"><span style=3D"font-size:10pt;"><u>h=
ttp://www.webex.com</u></span></font></a></div>
<div style=3D"margin-bottom:6pt;">CCM:&#43;14085256800x201046958# </div>
<div>&nbsp;</div>
<div>&nbsp;</div>
</span></font>
</body>
</html>

--_000_E045AECD98228444A58C61C200AE1BD8426422ABxmbrcdx01ciscoc_
Content-Type: text/calendar; charset="utf-8"; method=REQUEST
Content-Transfer-Encoding: base64

QkVHSU46VkNBTEVOREFSDQpNRVRIT0Q6UkVRVUVTVA0KUFJPRElEOk1pY3Jvc29mdCBFeGNoYW5n
ZSBTZXJ2ZXIgMjAxMA0KVkVSU0lPTjoyLjANCkJFR0lOOlZUSU1FWk9ORQ0KVFpJRDpQYWNpZmlj
IFRpbWUNCkJFR0lOOlNUQU5EQVJEDQpEVFNUQVJUOjE2MDEwMTAxVDAyMDAwMA0KVFpPRkZTRVRG
Uk9NOi0wNzAwDQpUWk9GRlNFVFRPOi0wODAwDQpSUlVMRTpGUkVRPVlFQVJMWTtJTlRFUlZBTD0x
O0JZREFZPTFTVTtCWU1PTlRIPTExDQpFTkQ6U1RBTkRBUkQNCkJFR0lOOkRBWUxJR0hUDQpEVFNU
QVJUOjE2MDEwMTAxVDAyMDAwMA0KVFpPRkZTRVRGUk9NOi0wODAwDQpUWk9GRlNFVFRPOi0wNzAw
DQpSUlVMRTpGUkVRPVlFQVJMWTtJTlRFUlZBTD0xO0JZREFZPTJTVTtCWU1PTlRIPTMNCkVORDpE
QVlMSUdIVA0KRU5EOlZUSU1FWk9ORQ0KQkVHSU46VkVWRU5UDQpPUkdBTklaRVI7Q049d2ViZXg7
U0VOVC1CWT0iTUFJTFRPOnB0aHViZXJ0QGNpc2NvLmNvbSI6TUFJTFRPOm1lc3NlbmdlckB3ZWJl
eA0KIC5jb20NCkFUVEVOREVFO1JPTEU9UkVRLVBBUlRJQ0lQQU5UO1BBUlRTVEFUPU5FRURTLUFD
VElPTjtSU1ZQPUZBTFNFO0NOPTZ0aXNjaC1zZQ0KIGN1cml0eUBpZXRmLm9yZzpNQUlMVE86NnRp
c2NoLXNlY3VyaXR5QGlldGYub3JnDQpBVFRFTkRFRTtST0xFPVJFUS1QQVJUSUNJUEFOVDtQQVJU
U1RBVD1ORUVEUy1BQ1RJT047UlNWUD1GQUxTRTtDTj1QYXQgS2lubmUNCiB5Ok1BSUxUTzpwYXQu
a2lubmV5QEtJTk5FWUNPTlNVTFRJTkdMTEMuQ09NDQpERVNDUklQVElPTjtMQU5HVUFHRT1lbi1V
UzpcblxuLS0tLS1PcmlnaW5hbCBBcHBvaW50bWVudC0tLS0tXG5Gcm9tOiB3ZWJleCANCiBbbWFp
bHRvOm1lc3NlbmdlckB3ZWJleC5jb21dXG5TZW50OiBsdW5kaSAzIGbDqXZyaWVyIDIwMTQgMTg6
MDNcblRvOiB3ZWJleA0KIFw7IFBhc2NhbCBUaHViZXJ0IChwdGh1YmVydClcOyBNaWNoYWVsIEJl
aHJpbmdlciAobWJlaHJpbmcpXDsgUGF0cmljayBXZXR0DQogZXJ3YWxkIChwd2V0dGVydylcOyBQ
YXVsIER1ZmZ5IChwYWR1ZmZ5KVw7IE1haWsgU2Vld2FsZCAobWFzZWV3YWwpXDsgTWljaGENCiBl
bCBSaWNoYXJkc29uXDsgUmVuZSBTdHJ1aWtcOyA2dGlzY2gtc2VjdXJpdHlAaWV0Zi5vcmc8bWFp
bHRvOjZ0aXNjaC1zZWN1cg0KIGl0eUBpZXRmLm9yZz5cOyBQYXQgS2lubmV5XG5TdWJqZWN0OiBN
ZWV0aW5nIHNjaGVkdWxlZDogNlRpU0NIIHNlY3VyaXR5XG5XDQogaGVuOiBtYXJkaSAyMCBtYWkg
MjAxNCAwNzowMC0wODowMCBQYWNpZmljIFRpbWUuXG5XaGVyZTogaHR0cHM6Ly9jaXNjby53ZWIN
CiBleC5jb20vY2lzY29cblxuXG5Zb3UgYXJlIHRoZSBob3N0IGZvciB0aGlzIG9ubGluZSBtZWV0
aW5nLlxuVG9waWM6ICA2VGlTQw0KIEggc2VjdXJpdHlcbkRhdGU6ICAgRXZlcnkgTW9uZGF5XCwg
ZnJvbSBNb25kYXlcLCBGZWJydWFyeSAxMFwsIDIwMTQgdG8gTW9uDQogZGF5XCwgRmVicnVhcnkg
OVwsIDIwMTVcblRpbWU6ICAgNzowMCBhbVwsIFBhY2lmaWMgU3RhbmRhcmQgVGltZSAoU2FuIEZy
YW4NCiBjaXNjb1wsIEdNVC0wODowMClcbk1lZXRpbmcgTnVtYmVyOiAyMDEgMDQ2IDk1OFxuTWVl
dGluZyBQYXNzd29yZDogICAgICAgNg0KIHVyaXR5XG5Ib3N0IEtleTogICAgICAgNzcyOTI4ICh1
c2UgdGhpcyB0byByZWNsYWltIGhvc3QgcHJpdmlsZWdlcylcblxuXG5cDQogblRvIHN0YXJ0IHRo
ZSBvbmxpbmUgbWVldGluZ1xuXG4gIDEuICAgIEdvIHRvIGh0dHBzOi8vY2lzY28ud2ViZXguY29t
L2Npc2MNCiBvL2oucGhwP01USUQ9bTJmZTEzOWJmODc2Y2VhM2VjNjI3NTBjZDU4MGI3OTA4XG4g
IDIuICAgIExvZyBpbiB0byB5b3VyIGFjYw0KIG91bnQuXG4gIDMuICAgIENsaWNrIOKAnFN0YXJ0
IE5vd+KAnS5cbiAgNC4gICAgRm9sbG93IHRoZSBpbnN0cnVjdGlvbnMgdGhhDQogdCBhcHBlYXIg
b24geW91ciBzY3JlZW4uXG5cblxuXG5BTEVSVCDigJMgUExFQVNFIFJFQUQ6IERPIE5PVCBESUFM
IFRIRSBUT0wNCiBMIEZSRUUgTlVNQkVSUyBGUk9NIFdJVEhJTiBUSEUgKDQwOCkgT1IgKDkxOSkg
QVJFQSBDT0RFU1xuXG5QbGVhc2UgZGlhbCB0aA0KIGUgbG9jYWwgYWNjZXNzIG51bWJlciBmb3Ig
eW91ciBhcmVhIGZyb20gdGhlIGxpc3QgYmVsb3c6XG7igKIgICAgICAgU2FuIEpvDQogc2UvTWls
cGl0YXMgKDQwOCkgYXJlYTogIDUyNS02ODAwXG7igKIgICAgICAgUlRQICg5MTkpIGFyZWE6ICAz
OTItMzMzMFxuXG4NCiBEaWFsaW5nIHRoZSBXZWJFeCB0b2xsIGZyZWUgbnVtYmVycyBmcm9tIHdp
dGhpbiA0MDggb3IgOTE5IGFyZWEgY29kZXMgaXMgbg0KIG90IGVuYWJsZWQgKG5vbi1DaXNjbyBw
aG9uZXMpLiAg4oCcIElmIHlvdSBkaWFsIHRoZSB0b2xsLWZyZWUgbnVtYmVycyB3aXRoDQogaW4g
dGhlIDQwOCBvciA5MTkgYXJlYSBjb2RlcyB5b3Ugd2lsbCBiZSBpbnN0cnVjdGVkIHRvIGhhbmcg
dXAgYW5kIGRpYWwgdGgNCiBlIGxvY2FsIGFjY2VzcyBudW1iZXIu4oCdIFBsZWFzZSB1c2UgdGhl
IGNhbGwtYmFjayBvcHRpb24gd2hlbmV2ZXIgcG9zc2libA0KIGUgYW5kIG90aGVyd2lzZSBkaWFs
IGxvY2FsIG51bWJlcnMgb25seS4gIFRoZSBhZmZlY3RlZCB0b2xsIGZyZWUgbnVtYmVycyBhDQog
cmU6ICg4NjYpIDQzMi05OTAzIGZvciB0aGUgU2FuIEpvc2UvTWlscGl0YXMgYXJlYSBhbmQgKDg2
NikgMzQ5LTM1MjAgZm9yIHQNCiBoZSBSVFAgYXJlYS5cblxuLS0tLS0tLS0tLS0tLS0tLS0tLS0t
LS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLVxuXA0KIG5UbyBqb2luIHRoZSB0ZWxl
Y29uZmVyZW5jZSBvbmx5XG4tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0t
DQogLS0tLS0tLS0tLS0tLS0tXG5cbjEuICAgICAgRGlhbCBpbnRvIENpc2NvIFdlYkV4ICh2aWV3
IGFsbCBHbG9iYWwgQWNjZXNzIE4NCiB1bWJlcnMgYXRcblxuaHR0cDovL2Npc2NvLmNvbS9lbi9V
Uy9hYm91dC9kb2luZ19idXNpbmVzcy9jb25mZXJlbmNpbmcvaW5kZQ0KIHguaHRtbCA8aHR0cDov
L2Npc2NvLmNvbS9lbi9VUy9hYm91dC9kb2luZ19idXNpbmVzcy9jb25mZXJlbmNpbmcvaW5kZXgu
aHRtDQogbCUyMDI+XG4yLiAgICAgIEZvbGxvdyB0aGUgcHJvbXB0cyB0byBlbnRlciB0aGUgTWVl
dGluZyBOdW1iZXIgKGxpc3RlZCBhYm8NCiB2ZSkgb3IgQWNjZXNzIENvZGUgZm9sbG93ZWQgYnkg
dGhlICMgc2lnbi5cblxuU2FuIEpvc2VcLCBDQTogKzEuNDA4LjUyNS42OA0KIDAwICBSVFA6ICsx
LjkxOS4zOTIuMzMzMFxuVVMvQ2FuYWRhOiArMS44NjYuNDMyLjk5MDMgIFVuaXRlZCBLaW5nZG9t
OiArNDQuDQogMjAuODgyNC4wMTE3XG5JbmRpYTogKzkxLjgwLjQzNTAuMTExMSAgR2VybWFueTog
KzQ5LjYxOS42NzczLjkwMDJcbkphcGFuOiANCiArODEuMy41NzYzLjkzOTQgIENoaW5hOiArODYu
MTAuODUxNS41NjY2XG5cblxuXG5Gb3IgYXNzaXN0YW5jZVxuXG4gIDEuICAgIA0KIEdvIHRvIGh0
dHBzOi8vY2lzY28ud2ViZXguY29tL2Npc2NvL21jXG4gIDIuICAgIE9uIHRoZSBsZWZ0IG5hdmln
YXRpb24gYmFyDQogXCwgY2xpY2sg4oCcU3VwcG9ydOKAnS5cblRvIGFkZCB0aGlzIG1lZXRpbmcg
dG8geW91ciBjYWxlbmRhciBwcm9ncmFtIChmb3INCiAgZXhhbXBsZSBNaWNyb3NvZnQgT3V0bG9v
aylcLCBjbGljayB0aGlzIGxpbms6XG5odHRwczovL2Npc2NvLndlYmV4LmNvbS9jaQ0KIHNjby9q
LnBocD9NVElEPW00Y2IxODFiOGQ0YTA5NjUyMjFiYjI3ODk5MWFjOWJmM1xuVG8gY2hlY2sgd2hl
dGhlciB5b3UgaGF2DQogZSB0aGUgYXBwcm9wcmlhdGUgcGxheWVycyBpbnN0YWxsZWQgZm9yIFVD
RiAoVW5pdmVyc2FsIENvbW11bmljYXRpb25zIEZvcm0NCiBhdCkgcmljaCBtZWRpYSBmaWxlc1ws
IGdvIHRvIGh0dHBzOi8vY2lzY28ud2ViZXguY29tL2Npc2NvL3N5c3RlbWRpYWdub3Npcw0KIC5w
aHAuXG5odHRwOi8vd3d3LndlYmV4LmNvbVxuQ0NNOisxNDA4NTI1NjgwMHgyMDEwNDY5NTgjXG5c
blxuDQpTVU1NQVJZO0xBTkdVQUdFPWVuLVVTOkZXOiBNZWV0aW5nIHNjaGVkdWxlZDogNlRpU0NI
IHNlY3VyaXR5DQpEVFNUQVJUO1RaSUQ9UGFjaWZpYyBUaW1lOjIwMTQwNTIwVDA3MDAwMA0KRFRF
TkQ7VFpJRD1QYWNpZmljIFRpbWU6MjAxNDA1MjBUMDgwMDAwDQpVSUQ6V0VCRVgtTUVFVElORyBD
RU5URVItNi4wMzAzNzkwLTI1MzQ3MzUzMi1TVT1jaXNjby1NSz0yMDEwNDY5NTgtUFc9NnVyaXQN
CiB5LUhOPXB0aHViZXJ0DQpSRUNVUlJFTkNFLUlEO1RaSUQ9UGFjaWZpYyBUaW1lOjIwMTQwNTE5
VDA3MDAwMA0KQ0xBU1M6UFVCTElDDQpQUklPUklUWTo1DQpEVFNUQU1QOjIwMTQwMjEwVDE1MDAw
MFoNClRSQU5TUDpPUEFRVUUNClNUQVRVUzpDT05GSVJNRUQNClNFUVVFTkNFOjENCkxPQ0FUSU9O
O0xBTkdVQUdFPWVuLVVTOmh0dHBzOi8vY2lzY28ud2ViZXguY29tL2Npc2NvDQpYLU1JQ1JPU09G
VC1DRE8tQVBQVC1TRVFVRU5DRToxDQpYLU1JQ1JPU09GVC1DRE8tT1dORVJBUFBUSUQ6LTENClgt
TUlDUk9TT0ZULUNETy1CVVNZU1RBVFVTOlRFTlRBVElWRQ0KWC1NSUNST1NPRlQtQ0RPLUlOVEVO
REVEU1RBVFVTOkJVU1kNClgtTUlDUk9TT0ZULUNETy1BTExEQVlFVkVOVDpGQUxTRQ0KWC1NSUNS
T1NPRlQtQ0RPLUlNUE9SVEFOQ0U6MQ0KWC1NSUNST1NPRlQtQ0RPLUlOU1RUWVBFOjMNClgtTUlD
Uk9TT0ZULURJU0FMTE9XLUNPVU5URVI6RkFMU0UNCkJFR0lOOlZBTEFSTQ0KQUNUSU9OOkRJU1BM
QVkNCkRFU0NSSVBUSU9OOlJFTUlOREVSDQpUUklHR0VSO1JFTEFURUQ9U1RBUlQ6LVBUMTVNDQpF
TkQ6VkFMQVJNDQpFTkQ6VkVWRU5UDQpFTkQ6VkNBTEVOREFSDQo=

--_000_E045AECD98228444A58C61C200AE1BD8426422ABxmbrcdx01ciscoc_--


From nobody Fri May  9 00:01:16 2014
Return-Path: <pthubert@cisco.com>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 12CC41A01D8 for <6tisch-security@ietfa.amsl.com>; Fri,  9 May 2014 00:01:15 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -10.152
X-Spam-Level: 
X-Spam-Status: No, score=-10.152 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RP_MATCHES_RCVD=-0.651, SPF_PASS=-0.001, USER_IN_DEF_DKIM_WL=-7.5] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id nGPeYmwjJ90H for <6tisch-security@ietfa.amsl.com>; Fri,  9 May 2014 00:01:12 -0700 (PDT)
Received: from alln-iport-6.cisco.com (alln-iport-6.cisco.com [173.37.142.93]) by ietfa.amsl.com (Postfix) with ESMTP id AA2B51A0166 for <6tisch-security@ietf.org>; Fri,  9 May 2014 00:01:12 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cisco.com; i=@cisco.com; l=2058; q=dns/txt; s=iport; t=1399618868; x=1400828468; h=from:to:cc:subject:date:message-id:references: in-reply-to:content-transfer-encoding:mime-version; bh=/AO/8LC7UmAPnvbZyFqrPsrAKFb/FNvUX4huSLO7R9M=; b=GjDuZSY4bLPwREcLs+S64z6d4/WJm5r272zSFdqQtH8oGeHmM/X7FMze lPzPyNwHGkTOx+ZG3znQCV0hfFifwkVr79PURcU0oH+HJa8JtBo0vyu3M PXmLbFCDIdrA0dgNbbBMgLPDwLUlYqS96gRxLhEFOgbs5/y6Iyg839ADm Q=;
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-Anti-Spam-Result: AhAFAEh8bFOtJV2T/2dsb2JhbABZgwaBJ4JnwlEBGXsWdIIlAQEBAwEjETICEQUHBAIBCBEEAQEBAgIGHQMCAgIwFAEICAIEAQ0FCIgxCKwupFsXgSqMRhEBHxYbBwaCbzaBFQSsPoM2gXY5
X-IronPort-AV: E=Sophos;i="4.97,1016,1389744000"; d="scan'208";a="42364874"
Received: from rcdn-core-11.cisco.com ([173.37.93.147]) by alln-iport-6.cisco.com with ESMTP; 09 May 2014 07:01:07 +0000
Received: from xhc-rcd-x02.cisco.com (xhc-rcd-x02.cisco.com [173.37.183.76]) by rcdn-core-11.cisco.com (8.14.5/8.14.5) with ESMTP id s49717Ti018768 (version=TLSv1/SSLv3 cipher=AES128-SHA bits=128 verify=FAIL); Fri, 9 May 2014 07:01:07 GMT
Received: from xmb-rcd-x01.cisco.com ([169.254.1.229]) by xhc-rcd-x02.cisco.com ([173.37.183.76]) with mapi id 14.03.0123.003; Fri, 9 May 2014 02:01:07 -0500
From: "Pascal Thubert (pthubert)" <pthubert@cisco.com>
To: Michael Richardson <mcr+ietf@sandelman.ca>, "6tisch-security@ietf.org" <6tisch-security@ietf.org>
Thread-Topic: [6tisch-security] conference call schedule
Thread-Index: AQHPajSB5etuISEoUESXdUTaBMFLW5s2Py+AgADJFAD//8qplYAAmWQAgABnlYA=
Date: Fri, 9 May 2014 07:01:06 +0000
Deferred-Delivery: Fri, 9 May 2014 07:01:00 +0000
Message-ID: <E045AECD98228444A58C61C200AE1BD84264238C@xmb-rcd-x01.cisco.com>
References: <13631.1399495188@sandelman.ca> <536AE2E5.6000106@gmail.com> <9280.1399557010@sandelman.ca> <zRwB1n00l0xxhYs01RwC8G> <536BA512.1090403@cox.net> <19029.1399578496@sandelman.ca>
In-Reply-To: <19029.1399578496@sandelman.ca>
Accept-Language: fr-FR, en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
x-originating-ip: [10.55.22.4]
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: base64
MIME-Version: 1.0
Archived-At: http://mailarchive.ietf.org/arch/msg/6tisch-security/atdMj_VOg8GzgowFJsTTpzSV1hA
Cc: Tom Phinney <tom.phinney@cox.net>
Subject: Re: [6tisch-security] conference call schedule
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 09 May 2014 07:01:15 -0000

RGVhciBhbGw6DQoNCkxldCB1cyBlbmpveSB0aGUgYmVhdXRpZnVsIG1vbnRoIG9mIE1heTohDQoN
CkZvciB0aGUgcmVhc29ucyBiZWxvdywgdGhlIG5leHQgc2VjdXJpdHkgY2FsbHMgYXJlIHNldCB0
bzoNCg0KPiAgICAyMDE0LTA1LTEyIDEwOjAwYW0gRUFTVEVSTg0KPiAgICAyMDE0LTA1LTIwIDEw
OjAwYW0gRUFTVEVSTg0KPiAgICAyMDE0LTA1LTI3IDEwOjAwYW0gRUFTVEVSTg0KPiAgICAyMDE0
LTA2LTAyIDEwOjAwYW0gRUFTVEVSTg0KDQpDaGVlcnMsDQoNClBhc2NhbA0KDQoNCj4gLS0tLS1P
cmlnaW5hbCBNZXNzYWdlLS0tLS0NCj4gRnJvbTogNnRpc2NoLXNlY3VyaXR5IFttYWlsdG86NnRp
c2NoLXNlY3VyaXR5LWJvdW5jZXNAaWV0Zi5vcmddIE9uIEJlaGFsZiBPZg0KPiBNaWNoYWVsIFJp
Y2hhcmRzb24NCj4gU2VudDogamV1ZGkgOCBtYWkgMjAxNCAyMTo0OA0KPiBUbzogNnRpc2NoLXNl
Y3VyaXR5QGlldGYub3JnDQo+IENjOiBUb20gUGhpbm5leQ0KPiBTdWJqZWN0OiBSZTogWzZ0aXNj
aC1zZWN1cml0eV0gY29uZmVyZW5jZSBjYWxsIHNjaGVkdWxlDQo+IA0KPiANCj4gVG9tIFBoaW5u
ZXkgPHRvbS5waGlubmV5QGNveC5uZXQ+IHdyb3RlOg0KPiAgICAgPiBJZiB3ZSBhcmUgZ29pbmcg
dG8gZGVsYXkgYSBzY2hlZHVsZWQgY29uZmVyZW5jZSBjYWxsIGJ5IG9uZSBkYXkgZm9yIGENCj4g
ICAgID4gQ2FuYWRpYW4gaG9saWRheSwgd2h5IG5vdCBkbyB0aGUgc2FtZSBvbmUgd2VlayBsYXRl
ciBmb3IgdGhlIFVTDQo+ICAgICA+IGhvbGlkYXk/IEknbQ0KPiANCj4gb2theS4NCj4gDQo+ICAg
ICA+IEluY2lkZW50YWxseSwgSSB0aG91Z2h0IHRoYXQgTWF5IDE5IHdhcyBWaWN0b3JpYSBEYXkg
YW5kIEp1bHkgMSB3YXMNCj4gICAgID4gQ2FuYWRhICBEYXkgKEbDqnRlIGR1IENhbmFkYSkuDQo+
IA0KPiBUcnVlLiBOb3Qgc3VyZSB3aHkgUmVuZSB3cm90ZSBkaWZmZXJlbnRseS4NCj4gSW4gZ2Vu
ZXJhbCB0aGUgTWF5ICIyNHRoIiB3ZWVrZW5kLCBpcyB0aGUgYmVlciBkcmlua2luZyB3ZWVrZW5k
LCBiZWNhdXNlIGl0DQo+IGludm9sdmVzIG9wZW5pbmcgY290dGFnZXMgdXAsIGFuZCBwYXJ0YWtp
bmcgb2YgYSB0d28tZm91ciwgd2hpY2ggaXMgdGhlDQo+IGxhcmdlc3QgdW5pdCBvZiBiZWVyIChi
b3R0bGVzL2NhbnMpIHdoaWNoIGlzIHNvbGQuDQo+IA0KPiBTbyByZXZpc2VkIHNjaGVkdWxlIGlz
Og0KPiAgICAyMDE0LTA1LTEyIDEwOjAwYW0NCj4gICAgMjAxNC0wNS0yMCAxMDowMGFtDQo+ICAg
IDIwMTQtMDUtMjcgMTA6MDBhbQ0KPiAgICAyMDE0LTA1LTAyIDEwOjAwYW0NCj4gDQo+IElmIHlv
dSB3YW50IHRvIGJlIGFkZGVkIHRvIG15IGlDYWwgZXZlbnQsIGRyb3AgbWUgYW4gZW1haWwgYW5k
IHNheSBzby4NCj4gDQo+IA0KPiAtLQ0KPiBNaWNoYWVsIFJpY2hhcmRzb24gPG1jcitJRVRGQHNh
bmRlbG1hbi5jYT4sIFNhbmRlbG1hbiBTb2Z0d2FyZSBXb3Jrcw0KPiAtPSBJUHY2IElvVCBjb25z
dWx0aW5nID0tDQo+IA0KPiANCg0K


From nobody Mon May 12 04:18:32 2014
Return-Path: <mcr@sandelman.ca>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id B56651A067F for <6tisch-security@ietfa.amsl.com>; Mon, 12 May 2014 04:18:29 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.132
X-Spam-Level: 
X-Spam-Status: No, score=-1.132 tagged_above=-999 required=5 tests=[BAYES_05=-0.5, RP_MATCHES_RCVD=-0.651, SPF_PASS=-0.001, T_MIME_NO_TEXT=0.01, T_TVD_MIME_NO_HEADERS=0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id x_nRNENSA4yI for <6tisch-security@ietfa.amsl.com>; Mon, 12 May 2014 04:18:28 -0700 (PDT)
Received: from tuna.sandelman.ca (tuna.sandelman.ca [209.87.252.184]) by ietfa.amsl.com (Postfix) with ESMTP id 808C41A067C for <6tisch-security@ietf.org>; Mon, 12 May 2014 04:18:28 -0700 (PDT)
Received: from sandelman.ca (desk.marajade.sandelman.ca [209.87.252.247]) by tuna.sandelman.ca (Postfix) with ESMTP id 62CEA20029 for <6tisch-security@ietf.org>; Mon, 12 May 2014 07:20:10 -0400 (EDT)
Received: by sandelman.ca (Postfix, from userid 179) id BAED363B1C; Mon, 12 May 2014 07:18:15 -0400 (EDT)
Received: from sandelman.ca (localhost [127.0.0.1]) by sandelman.ca (Postfix) with ESMTP id A0E2763AB6 for <6tisch-security@ietf.org>; Mon, 12 May 2014 07:18:15 -0400 (EDT)
From: Michael Richardson <mcr+ietf@sandelman.ca>
To: 6tisch-security@ietf.org
X-Attribution: mcr
X-Mailer: MH-E 8.2; nmh 1.3-dev; GNU Emacs 23.4.1
X-Face: $\n1pF)h^`}$H>Hk{L"x@)JS7<%Az}5RyS@k9X%29-lHB$Ti.V>2bi.~ehC0; <'$9xN5Ub# z!G,p`nR&p7Fz@^UXIn156S8.~^@MJ*mMsD7=QFeq%AL4m<nPbLgmtKK-5dC@#:k
MIME-Version: 1.0
Content-Type: multipart/signed; boundary="=-=-="; micalg=pgp-sha1; protocol="application/pgp-signature"
Date: Mon, 12 May 2014 07:18:15 -0400
Message-ID: <27538.1399893495@sandelman.ca>
Sender: mcr@sandelman.ca
Archived-At: http://mailarchive.ietf.org/arch/msg/6tisch-security/SkfJ-vNJ22uPpCmDzUASA9CnZHM
Subject: [6tisch-security] agenda(?) for call today
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 12 May 2014 11:18:29 -0000

--=-=-=


My goal would be to continue the discussion about what the certificates
contain, and how/when/if to trust them.  However, I'm home with a sick
child today, and I don't know if I'll make the call; because I'm home
sick too!

--
Michael Richardson <mcr+IETF@sandelman.ca>, Sandelman Software Works
 -= IPv6 IoT consulting =-




--=-=-=
Content-Type: application/pgp-signature

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iQEVAwUBU3Ct84CLcPvd0N1lAQKTdgf/cu/5wtFBBg9iIiBxzbvVdG3bwBkRtTgB
SzLH/ZtYB8gJdUDMNmsqQRxa5SQeHPK1s9BuXgRE1w89PVK2nmWvwj5wioKYpaDP
x8AJ75Jx9jcUGDGrD8JDxC0BaDzNerozlg+iyMZnhZiUQUH9wpATN9ICzTTC+bjR
C2NtXJIlN6QBFQL9dfconQMeDV2T02RUisVI5nsglyRp8uykRL1LwHAE7mWtxMnD
92VhYkW3A1aoBlJpnD9zKKGnzKVR2drm2MmhYl7Lhod1v64Nw3RZaQISy8NpOSNa
Oi2kNuS2VgdihvUW0yblCAI9HUybdTogCj8T3cTgxiVzFEKg7B+WjA==
=k9Vu
-----END PGP SIGNATURE-----
--=-=-=--


From nobody Mon May 12 06:53:55 2014
Return-Path: <rstruik.ext@gmail.com>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id AE6281A070E for <6tisch-security@ietfa.amsl.com>; Mon, 12 May 2014 06:53:53 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.999
X-Spam-Level: 
X-Spam-Status: No, score=-1.999 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id vLhglJktpnLP for <6tisch-security@ietfa.amsl.com>; Mon, 12 May 2014 06:53:51 -0700 (PDT)
Received: from mail-ie0-x231.google.com (mail-ie0-x231.google.com [IPv6:2607:f8b0:4001:c03::231]) by ietfa.amsl.com (Postfix) with ESMTP id 754F21A06FA for <6tisch-security@ietf.org>; Mon, 12 May 2014 06:53:51 -0700 (PDT)
Received: by mail-ie0-f177.google.com with SMTP id rp18so6913564iec.22 for <6tisch-security@ietf.org>; Mon, 12 May 2014 06:53:45 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113;  h=message-id:date:from:user-agent:mime-version:to:subject:references :in-reply-to:content-type; bh=dumST0KvlOzQTebSj2glZCDQ3hon9OSs86EzyEd9EZM=; b=pNcrkeu+Nd8oFgrCHFZhdH58p2dHzHxHVGB0O6tCiCCCR6va7ee704ThKnJb5Q3yBd +oyu6I8WS0fsZUz9vI6y2CN573XKCPBBLKqw6I1BBPBS5+bbRIGzepQoogiH2ji1xL1Z h2juaY/K2czhP5JhNZif7eKIMXPaqxZ4yPDOQXkUnM8bq2z4lwO7tj2T60juyu6ynfjy lTCGHOE9C5lgn+aaYiBeUBQ1gLAMC7lIjMVfaxvwMAgxICJaWAHV1ZCDcT6omIO62xED 8JgZU/a3cenu5Je0UKQOz9d/CtinVrcms+lOGt5UikHMUQWMsFI7C5wCWWO50DTbJ29J EO7Q==
X-Received: by 10.50.153.49 with SMTP id vd17mr44438189igb.40.1399902825286; Mon, 12 May 2014 06:53:45 -0700 (PDT)
Received: from [192.168.1.104] (CPE0013100e2c51-CM001cea35caa6.cpe.net.cable.rogers.com. [99.231.3.110]) by mx.google.com with ESMTPSA id mu2sm22440572igb.21.2014.05.12.06.53.42 for <multiple recipients> (version=TLSv1 cipher=ECDHE-RSA-RC4-SHA bits=128/128); Mon, 12 May 2014 06:53:43 -0700 (PDT)
Message-ID: <5370D261.4090306@gmail.com>
Date: Mon, 12 May 2014 09:53:37 -0400
From: Rene Struik <rstruik.ext@gmail.com>
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:24.0) Gecko/20100101 Thunderbird/24.5.0
MIME-Version: 1.0
To: Michael Richardson <mcr+ietf@sandelman.ca>, 6tisch-security@ietf.org
References: <27538.1399893495@sandelman.ca>
In-Reply-To: <27538.1399893495@sandelman.ca>
Content-Type: multipart/alternative; boundary="------------070605080301010605080500"
Archived-At: http://mailarchive.ietf.org/arch/msg/6tisch-security/mgu9sW219fDtlWkKN_ml-LdXLFs
Subject: Re: [6tisch-security] agenda(?) for call today
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 12 May 2014 13:53:53 -0000

This is a multi-part message in MIME format.
--------------070605080301010605080500
Content-Type: text/plain; charset=ISO-8859-1; format=flowed
Content-Transfer-Encoding: 7bit

Hi Michael et al:

Another topic worth exploring more is the join protocol details.

(There are many other aspects, including certs, as you mentioned, more 
general security architecture, provisioning, etc., but below only deals 
with join.)

With w/HART, the join process only interacts with the network manager 
(62591, Annex A.3, Fig. A.1) for
-forwarded join from joining node to network manager;
-passing configuration parms from network manager to joining node (keys, 
links, frame links) and neighbor report from joined node to network manager.
All other communications are local, between joining device and neighbor 
(resp. with maintenance tool).

It may have merit if we could use similar communication flows with 
6tisch, i.e., keep most traffic local to the joining device, except for 
configuration parms exchange and authorization info passing.

Most important consideration (from communication perspective) would be 
that non-local traffic would be minimized, as also w/HART does. From a 
marketing perspective, mimicking the communication flows w/HART already 
has would keep all time scheduling considerations for w/HART as 
currently there and 6TiSCH as to be detailed roughly the same. This 
would longer term help in pushing 6tisch-style security scheme to 
w/HART, since from a distance it looks the same (although trying to 
scrap the maintenance tool).

Of course, this does not deal with the details of the joining protocol 
itself; only the flows.

What about we look at some of the flows, and enumerate all issues that 
need to be addressed here, both from a security perspective and 
otherwise. We can then assign people to find missing information (I am 
esp. curious about how devices know when to send/receive and 
contributions of cycling efforts to total time latency).

We could go over w/HART join flows during the call, to trigger these 
questions.

Best regards, Rene

On 5/12/2014 7:18 AM, Michael Richardson wrote:
> My goal would be to continue the discussion about what the certificates
> contain, and how/when/if to trust them.  However, I'm home with a sick
> child today, and I don't know if I'll make the call; because I'm home
> sick too!
>
> --
> Michael Richardson <mcr+IETF@sandelman.ca>, Sandelman Software Works
>   -= IPv6 IoT consulting =-
>
>
>
>
>
> _______________________________________________
> 6tisch-security mailing list
> 6tisch-security@ietf.org
> https://www.ietf.org/mailman/listinfo/6tisch-security


-- 
email: rstruik.ext@gmail.com | Skype: rstruik
cell: +1 (647) 867-5658 | US: +1 (415) 690-7363


--------------070605080301010605080500
Content-Type: text/html; charset=ISO-8859-1
Content-Transfer-Encoding: 7bit

<html>
  <head>
    <meta content="text/html; charset=ISO-8859-1"
      http-equiv="Content-Type">
  </head>
  <body bgcolor="#FFFFFF" text="#000000">
    <div class="moz-cite-prefix">Hi Michael et al:<br>
      <br>
      Another topic worth exploring more is the join protocol details. <br>
      <br>
      (There are many other aspects, including certs, as you mentioned,
      more general security architecture, provisioning, etc., but below
      only deals with join.)<br>
      <br>
      With w/HART, the join process only interacts with the network
      manager (62591, Annex A.3, Fig. A.1) for <br>
      -forwarded join from joining node to network manager;<br>
      -passing configuration parms from network manager to joining node
      (keys, links, frame links) and neighbor report from joined node to
      network manager.<br>
      All other communications are local, between joining device and
      neighbor (resp. with maintenance tool).<br>
      <br>
      It may have merit if we could use similar communication flows with
      6tisch, i.e., keep most traffic local to the joining device,
      except for configuration parms exchange and authorization info
      passing. <br>
      <br>
      Most important consideration (from communication perspective)
      would be that non-local traffic would be minimized, as also w/HART
      does. From a marketing perspective, mimicking the communication
      flows w/HART already has would keep all time scheduling
      considerations for w/HART as currently there and 6TiSCH as to be
      detailed roughly the same. This would longer term help in pushing
      6tisch-style security scheme to w/HART, since from a distance it
      looks the same (although trying to scrap the maintenance tool).<br>
      <br>
      Of course, this does not deal with the details of the joining
      protocol itself; only the flows.<br>
      <br>
      What about we look at some of the flows, and enumerate all issues
      that need to be addressed here, both from a security perspective
      and otherwise. We can then assign people to find missing
      information (I am esp. curious about how devices know when to
      send/receive and contributions of cycling efforts to total time
      latency). <br>
      <br>
      We could go over w/HART join flows during the call, to trigger
      these questions.<br>
      <br>
      Best regards, Rene<br>
      <br>
      On 5/12/2014 7:18 AM, Michael Richardson wrote:<br>
    </div>
    <blockquote cite="mid:27538.1399893495@sandelman.ca" type="cite">
      <pre wrap="">
My goal would be to continue the discussion about what the certificates
contain, and how/when/if to trust them.  However, I'm home with a sick
child today, and I don't know if I'll make the call; because I'm home
sick too!

--
Michael Richardson <a class="moz-txt-link-rfc2396E" href="mailto:mcr+IETF@sandelman.ca">&lt;mcr+IETF@sandelman.ca&gt;</a>, Sandelman Software Works
 -= IPv6 IoT consulting =-



</pre>
      <br>
      <fieldset class="mimeAttachmentHeader"></fieldset>
      <br>
      <pre wrap="">_______________________________________________
6tisch-security mailing list
<a class="moz-txt-link-abbreviated" href="mailto:6tisch-security@ietf.org">6tisch-security@ietf.org</a>
<a class="moz-txt-link-freetext" href="https://www.ietf.org/mailman/listinfo/6tisch-security">https://www.ietf.org/mailman/listinfo/6tisch-security</a>
</pre>
    </blockquote>
    <br>
    <br>
    <pre class="moz-signature" cols="72">-- 
email: <a class="moz-txt-link-abbreviated" href="mailto:rstruik.ext@gmail.com">rstruik.ext@gmail.com</a> | Skype: rstruik
cell: +1 (647) 867-5658 | US: +1 (415) 690-7363</pre>
  </body>
</html>

--------------070605080301010605080500--


From nobody Tue May 13 17:42:04 2014
Return-Path: <mcr@sandelman.ca>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id D2CE81A00DC; Tue, 13 May 2014 17:42:02 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.532
X-Spam-Level: 
X-Spam-Status: No, score=-2.532 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RP_MATCHES_RCVD=-0.651, SPF_PASS=-0.001, T_MIME_NO_TEXT=0.01, T_TVD_MIME_NO_HEADERS=0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id XDxQWyCq0lgu; Tue, 13 May 2014 17:41:58 -0700 (PDT)
Received: from tuna.sandelman.ca (tuna.sandelman.ca [209.87.252.184]) by ietfa.amsl.com (Postfix) with ESMTP id 40B251A00DB; Tue, 13 May 2014 17:41:58 -0700 (PDT)
Received: from sandelman.ca (obiwan.sandelman.ca [IPv6:2607:f0b0:f:2::247]) by tuna.sandelman.ca (Postfix) with ESMTP id 5C63E2002B; Tue, 13 May 2014 20:43:47 -0400 (EDT)
Received: by sandelman.ca (Postfix, from userid 179) id 989E563B1C; Tue, 13 May 2014 20:41:50 -0400 (EDT)
Received: from sandelman.ca (localhost [127.0.0.1]) by sandelman.ca (Postfix) with ESMTP id 84A9D63B17; Tue, 13 May 2014 20:41:50 -0400 (EDT)
From: Michael Richardson <mcr+ietf@sandelman.ca>
To: draft-piro-6tisch-security-issues@tools.ietf.org
X-Attribution: mcr
X-Mailer: MH-E 8.2; nmh 1.3-dev; GNU Emacs 23.4.1
X-Face: $\n1pF)h^`}$H>Hk{L"x@)JS7<%Az}5RyS@k9X%29-lHB$Ti.V>2bi.~ehC0; <'$9xN5Ub# z!G,p`nR&p7Fz@^UXIn156S8.~^@MJ*mMsD7=QFeq%AL4m<nPbLgmtKK-5dC@#:k
MIME-Version: 1.0
Content-Type: multipart/signed; boundary="=-=-="; micalg=pgp-sha1; protocol="application/pgp-signature"
Date: Tue, 13 May 2014 20:41:50 -0400
Message-ID: <11990.1400028110@sandelman.ca>
Sender: mcr@sandelman.ca
Archived-At: http://mailarchive.ietf.org/arch/msg/6tisch-security/JRqlOQnf1Bm-2Kt31YIVJaMYES0
Cc: 6tisch@ietf.org, 6tisch-security@ietf.org
Subject: [6tisch-security] comments on draft-piro-6tisch-security-issues
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 14 May 2014 00:42:03 -0000

--=-=-=


I found this document to be a useful overview of 802.15.4 physical/layer-2
security options.

I don't agree with your title! I don't see how this is a "security
framework". It is something much more useful and important.
The analysis in section 3 is very useful.

I am not sure that I understand section 4.

Thank you for giving the network definitions in section 5.0.
It would be worth making it clear in the definition of fully secure that all
broadcasts are encrypted, including the beacon.

The _Hybrid Secured network_ is likely the most common, and not because nodes
are not capable of encryption, but because they don't have the key (yet!!).

The Setting-up Phase seems to assume a provisioning process to distribute
this MasterKey.  It could be that the MasterKey comes from something like
1x/PANA?

I like that the document uses 6top API to set things up.
My understanding is that 6.3 describes a way to get fresh per-cluster keying.
It appears that this is done over a layer-2 protocol.  Why not MLE?


Some editorial nits:
in section 6.1.1 the word "exploit"(ed) is technically correct, but perhaps
   an unfortunate choice for many non-english/french speakers.
   "exploiter" en francois is perhaps best translated as "leverage"
   In IT circles, many understand an "exploit" to be a security flaw..

--
Michael Richardson <mcr+IETF@sandelman.ca>, Sandelman Software Works
 -= IPv6 IoT consulting =-




--=-=-=
Content-Type: application/pgp-signature

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iQEVAwUBU3K7zoCLcPvd0N1lAQLjgggAuZ5skKSLZKAtMsh244N/9kkUhg/6wwI+
5c6ayvaJEIrxUQ5+NLA4O9Z08UWup/ijdVgJ1NI6dYu47rH1gSyP7RG28zaumiJT
bm2smXGSxX51wF5PW3qkBC0qfr+Or1d4fcwf+YVbEzBKsCd7svMBLLHkm2M0eOdy
Vo8M7U3UcJgRKR5FpLh2U2LXu/pNrkBb3SSrL4BBeEYAsJrkM4SdCakkkKv1RSqm
EgUa0qcgG5EP5q/4qznIyohFPgwwyabPwHrQdxJatC7Kgc2PafxhnazgHRG43po9
wQYcjITTN1URfN+0sxN37uPPh7/97Z880XxJPP+zGNvUJ3HVBczGdA==
=wj6r
-----END PGP SIGNATURE-----
--=-=-=--


From nobody Wed May 14 09:40:10 2014
Return-Path: <peppe@giuseppepiro.com>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 702491A02DF for <6tisch-security@ietfa.amsl.com>; Wed, 14 May 2014 09:40:04 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: 0.603
X-Spam-Level: 
X-Spam-Status: No, score=0.603 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, FM_FORGED_GMAIL=0.622, HELO_EQ_IT=0.635, HOST_EQ_IT=1.245, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id YVfzoWbH1tjg for <6tisch-security@ietfa.amsl.com>; Wed, 14 May 2014 09:40:01 -0700 (PDT)
Received: from smtpdb4.aruba.it (smtpdb5.aruba.it [62.149.158.247]) by ietfa.amsl.com (Postfix) with ESMTP id D34631A02BF for <6tisch-security@ietf.org>; Wed, 14 May 2014 09:39:59 -0700 (PDT)
Received: from mail-oa0-f50.google.com ([209.85.219.50]) by smtpcmd02.ad.aruba.it with bizsmtp id 1sfp1o00Q15q9lt01sfqsx; Wed, 14 May 2014 18:39:51 +0200
Received: by mail-oa0-f50.google.com with SMTP id i7so2469417oag.23 for <multiple recipients>; Wed, 14 May 2014 09:39:49 -0700 (PDT)
X-Received: by 10.60.131.210 with SMTP id oo18mr4659778oeb.70.1400085589331; Wed, 14 May 2014 09:39:49 -0700 (PDT)
MIME-Version: 1.0
Received: by 10.76.151.227 with HTTP; Wed, 14 May 2014 09:39:29 -0700 (PDT)
In-Reply-To: <11990.1400028110@sandelman.ca>
References: <11990.1400028110@sandelman.ca>
From: Giuseppe Piro <peppe@giuseppepiro.com>
Date: Wed, 14 May 2014 18:39:29 +0200
Message-ID: <CAH-9zkqejz5LZkQHyNKQg=W6eyy4RBbyqqTW_+NsboRc66WjRA@mail.gmail.com>
To: Michael Richardson <mcr+ietf@sandelman.ca>
Content-Type: multipart/alternative; boundary=047d7b4723dc35159d04f95ed47a
Archived-At: http://mailarchive.ietf.org/arch/msg/6tisch-security/FZHD-7iZUe7ju721pGjWB-EiyJY
Cc: "6tisch@ietf.org" <6tisch@ietf.org>, "draft-piro-6tisch-security-issues@tools.ietf.org" <draft-piro-6tisch-security-issues@tools.ietf.org>, 6tisch-security@ietf.org
Subject: Re: [6tisch-security] comments on draft-piro-6tisch-security-issues
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 14 May 2014 16:40:04 -0000

--047d7b4723dc35159d04f95ed47a
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

Hi Michael,



thank you very much for your mail and you precious comments. See my answers
below.


On Wed, May 14, 2014 at 2:41 AM, Michael Richardson
<mcr+ietf@sandelman.ca>wrote:

>
> I found this document to be a useful overview of 802.15.4 physical/layer-=
2
> security options.
>
> I don't agree with your title! I don't see how this is a "security
> framework". It is something much more useful and important.
> The analysis in section 3 is very useful.
>

=E2=80=8BAs you understood, we are focusing on the layer-2 security. I agre=
e with
you that the title should be modified. What do you think about =E2=80=9CLay=
er-2
security aspects in IEEE 802.15.4(e) networks =E2=80=9D ? Do you have a bet=
ter
proposal ?=E2=80=8B


>
> I am not sure that I understand section 4.
>

Probably this issue arises from the concept of =E2=80=9Cdomain=E2=80=9D tha=
t we introduced
in this section. In our draft (written few months ago), the domain
identifies a portion of the network where the conceived procedures work.

I=E2=80=99ve realized that this definition is, now, no more useful because =
it goes
against the =E2=80=9Cconcept of domain=E2=80=9D recently discussed within t=
he 6tisch
security task force (I read Rene=E2=80=99s comment on that topic).

As suggested by Thomas (see
http://www.ietf.org/mail-archive/web/6tisch/current/msg01741.html), we can
use the term =E2=80=9Cone-hop neighborhood=E2=80=9D for indicating that the=
 presented
approach just enable (for the moment) the establishment of a secured link
at the MAC layer.

What do you think ?
=E2=80=8B


>
> Thank you for giving the network definitions in section 5.0.
> It would be worth making it clear in the definition of fully secure that
> all
> broadcasts are encrypted, including the beacon.
>
> The _Hybrid Secured network_ is likely the most common, and not because
> nodes
> are not capable of encryption, but because they don't have the key (yet!!=
).
>
>
=E2=80=8BOk, I've understood your point of view about the _Hybrid=E2=80=8B =
Secured_
configuration. We can modify the definition accordingly. However, according
to your comment, do you think that the _Fully Secured network_ still
identifies a realistic scenario ?

In that configuration, all packets, included the Beacon, are protected.
This means that all nodes needs to know the key before starting any
connections (included the join procedure).

To address this issue, we introduced the Default Key (I believe that it has
the same meaning of the "fake key" used by Rene in some mails few weeks
ago).

Do you think that this is still a useful and correct approach ?



> The Setting-up Phase seems to assume a provisioning process to distribute
> this MasterKey.  It could be that the MasterKey comes from something like
> 1x/PANA?
>

=E2=80=8BIn the current version of the draft, it is assumed that the Master=
Key is
stored into the device by the manufacturer or by the network administrator
(like a certificate).

We can think to a more generic scheme that enables its distribution through
1x/PANA approaches. However, we have to understand how this scheme
maintains the compatibility with the _Fully Secured_ configuration.
=E2=80=8B

>
> I like that the document uses 6top API to set things up.
> My understanding is that 6.3 describes a way to get fresh per-cluster
> keying.
> It appears that this is done over a layer-2 protocol.  Why not MLE?
>
>
I agree with you. Qin has already pointed out this issue in the past.

We have already re-designed the whole KMP by using only Information
Elements but we didn=E2=80=99t yet included this into the draft).
Please, can you confirm that the adoption of only IEs handled by the MLME
is the right approach ?=E2=80=8B


>
> Some editorial nits:
> in section 6.1.1 the word "exploit"(ed) is technically correct, but perha=
ps
>    an unfortunate choice for many non-english/french speakers.
>    "exploiter" en francois is perhaps best translated as "leverage"
>    In IT circles, many understand an "exploit" to be a security flaw..
>
>
.... I I will delete this term from my dictionary, thanks :-)
=E2=80=8B




Finally, I would remark that we are working for upgrading the draft by
considering comments provided within these discussions:

http://www.ietf.org/mail-archive/web/6tisch/current/msg01691.html
http://www.ietf.org/mail-archive/web/6tisch/current/msg01680.html
 http://www.ietf.org/mail-archive/web/6tisch/current/msg01685.html

and obviously, your comments will be also carefully taken into account.

Apart of these comments, can you provide further suggestions and highlight
in which direction this draft can be upgraded, thus being more useful for
the work conducted within the security task force ?

Thanks
Giuseppe





--=20
*Giuseppe Piro, PhD*
Post Doc Researcher
DEI, Politecnico di Bari
via Orabona 4 - 70125 (Bari), Italy.
email: peppe@giuseppepiro.com
phone: +39 080 5963301
web: g <http://telematics.poliba.it/piro>iuseppepiro.com

--047d7b4723dc35159d04f95ed47a
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><div class=3D"gmail_default"><span style=3D"line-height:8.=
54285717010498px"><font color=3D"#000099"><p dir=3D"ltr" style=3D"margin-to=
p:0pt;margin-bottom:0pt">
Hi Michael,=C2=A0</p><p dir=3D"ltr" style=3D"margin-top:0pt;margin-bottom:0=
pt"><br></p><p dir=3D"ltr" style=3D"margin-top:0pt;margin-bottom:0pt"><br><=
/p><p dir=3D"ltr" style=3D"margin-top:0pt;margin-bottom:0pt">thank you very=
 much for your mail and you precious comments. See my answers below.</p>


</font></span></div><div class=3D"gmail_extra"><br><br><div class=3D"gmail_=
quote">On Wed, May 14, 2014 at 2:41 AM, Michael Richardson <span dir=3D"ltr=
">&lt;<a href=3D"mailto:mcr+ietf@sandelman.ca" target=3D"_blank">mcr+ietf@s=
andelman.ca</a>&gt;</span> wrote:<br>


<blockquote class=3D"gmail_quote" style=3D"margin:0px 0px 0px 0.8ex;border-=
left-width:1px;border-left-color:rgb(204,204,204);border-left-style:solid;p=
adding-left:1ex"><br>
I found this document to be a useful overview of 802.15.4 physical/layer-2<=
br>
security options.<br>
<br>
I don&#39;t agree with your title! I don&#39;t see how this is a &quot;secu=
rity<br>
framework&quot;. It is something much more useful and important.<br>
The analysis in section 3 is very useful.<br></blockquote><div><br></div><d=
iv class=3D"gmail_default" style=3D"color:rgb(0,0,153)">=E2=80=8BAs you und=
erstood, we are focusing on the layer-2 security. I agree with you that the=
 title should be modified. What do you think about =E2=80=9CLayer-2 securit=
y aspects in IEEE 802.15.4(e) networks =E2=80=9D ? Do you have a better pro=
posal ?=E2=80=8B</div>


<div>=C2=A0<br></div><blockquote class=3D"gmail_quote" style=3D"margin:0px =
0px 0px 0.8ex;border-left-width:1px;border-left-color:rgb(204,204,204);bord=
er-left-style:solid;padding-left:1ex">
<br>
I am not sure that I understand section 4.<br></blockquote><div><br></div><=
div class=3D"gmail_default" style=3D"color:rgb(0,0,153)">Probably this issu=
e arises from the concept of =E2=80=9Cdomain=E2=80=9D that we introduced in=
 this section. In our draft (written few months ago), the domain identifies=
 a portion of the network where the conceived procedures work.=C2=A0</div>


<div class=3D"gmail_default" style=3D"color:rgb(0,0,153)"><br></div><div cl=
ass=3D"gmail_default" style=3D"color:rgb(0,0,153)">I=E2=80=99ve realized th=
at this definition is, now, no more useful because it goes against the =E2=
=80=9Cconcept of domain=E2=80=9D recently discussed within the 6tisch secur=
ity task force (I read Rene=E2=80=99s comment on that topic).=C2=A0</div>


<div class=3D"gmail_default" style=3D"color:rgb(0,0,153)"><br></div><div cl=
ass=3D"gmail_default" style=3D"color:rgb(0,0,153)">As suggested by Thomas (=
see <a href=3D"http://www.ietf.org/mail-archive/web/6tisch/current/msg01741=
.html" target=3D"_blank">http://www.ietf.org/mail-archive/web/6tisch/curren=
t/msg01741.html</a>), we can use the term =E2=80=9Cone-hop neighborhood=E2=
=80=9D for indicating that the presented approach just enable (for the mome=
nt) the establishment of a secured link at the MAC layer.=C2=A0</div>


<div class=3D"gmail_default" style=3D"color:rgb(0,0,153)"><br></div><div cl=
ass=3D"gmail_default" style=3D"color:rgb(0,0,153)">What do you think ?</div=
><div class=3D"gmail_default" style=3D"color:rgb(0,0,153)">=E2=80=8B</div><=
div>=C2=A0</div><blockquote class=3D"gmail_quote" style=3D"margin:0px 0px 0=
px 0.8ex;border-left-width:1px;border-left-color:rgb(204,204,204);border-le=
ft-style:solid;padding-left:1ex">



<br>
Thank you for giving the network definitions in section 5.0.<br>
It would be worth making it clear in the definition of fully secure that al=
l<br>
broadcasts are encrypted, including the beacon.<br>
<br>
The _Hybrid Secured network_ is likely the most common, and not because nod=
es<br>
are not capable of encryption, but because they don&#39;t have the key (yet=
!!).<br>
<br></blockquote><div><br></div><div><div class=3D"gmail_default" style=3D"=
color:rgb(0,0,153)">=E2=80=8BOk, I&#39;ve understood your point of view abo=
ut the _Hybrid=E2=80=8B Secured_ configuration. We can modify the definitio=
n accordingly. However, according to your comment, do you think that the _F=
ully Secured network_ still identifies a realistic scenario ?=C2=A0</div>


<div class=3D"gmail_default" style=3D"color:rgb(0,0,153)"><br></div><div cl=
ass=3D"gmail_default" style=3D"color:rgb(0,0,153)">In that configuration, a=
ll packets, included the Beacon, are protected. This means that all nodes n=
eeds to know the key before starting any connections (included the join pro=
cedure).=C2=A0</div>


<div class=3D"gmail_default" style=3D"color:rgb(0,0,153)"><br></div><div cl=
ass=3D"gmail_default" style=3D"color:rgb(0,0,153)">To address this issue, w=
e introduced the Default Key (I believe that it has the same meaning of the=
 &quot;fake key&quot; used by Rene in some mails few weeks ago).</div>


<div class=3D"gmail_default" style=3D"color:rgb(0,0,153)"><br></div><div cl=
ass=3D"gmail_default" style=3D"color:rgb(0,0,153)">Do you think that this i=
s still a useful and correct approach ?=C2=A0<br></div><br></div><div>=C2=
=A0</div><blockquote class=3D"gmail_quote" style=3D"margin:0px 0px 0px 0.8e=
x;border-left-width:1px;border-left-color:rgb(204,204,204);border-left-styl=
e:solid;padding-left:1ex">



The Setting-up Phase seems to assume a provisioning process to distribute<b=
r>
this MasterKey. =C2=A0It could be that the MasterKey comes from something l=
ike<br>
1x/PANA?<br></blockquote><div><br></div><div class=3D"gmail_default"><span =
style=3D"color:rgb(0,0,153)">=E2=80=8B</span><font color=3D"#000099">In the=
 current version of the draft, it is assumed that the MasterKey is stored i=
nto the device by the manufacturer or by the network administrator (like a =
certificate).=C2=A0</font></div>


<div class=3D"gmail_default"><font color=3D"#000099"><br></font></div><div =
class=3D"gmail_default"><font color=3D"#000099">We can think to a more gene=
ric scheme that enables its distribution through 1x/PANA approaches. Howeve=
r, we have to understand how this scheme maintains the compatibility with t=
he _Fully Secured_ configuration.</font></div>


<div class=3D"gmail_default" style=3D"color:rgb(0,0,153)">=E2=80=8B</div><b=
lockquote class=3D"gmail_quote" style=3D"margin:0px 0px 0px 0.8ex;border-le=
ft-width:1px;border-left-color:rgb(204,204,204);border-left-style:solid;pad=
ding-left:1ex">



<br>
I like that the document uses 6top API to set things up.<br>
My understanding is that 6.3 describes a way to get fresh per-cluster keyin=
g.<br>
It appears that this is done over a layer-2 protocol. =C2=A0Why not MLE?<br=
>
<br></blockquote><div><br></div><div class=3D"gmail_default" style=3D"color=
:rgb(0,0,153)">I agree with you. Qin has already pointed out this issue in =
the past.=C2=A0</div><div class=3D"gmail_default" style=3D"color:rgb(0,0,15=
3)"><br>


</div><div class=3D"gmail_default" style=3D"color:rgb(0,0,153)">We have alr=
eady re-designed the whole KMP by using only Information Elements but we di=
dn=E2=80=99t yet included this into the draft).=C2=A0</div><div class=3D"gm=
ail_default" style=3D"color:rgb(0,0,153)">


Please, can you confirm that the adoption of only IEs handled by the MLME i=
s the right approach ?=E2=80=8B</div><div>=C2=A0</div><blockquote class=3D"=
gmail_quote" style=3D"margin:0px 0px 0px 0.8ex;border-left-width:1px;border=
-left-color:rgb(204,204,204);border-left-style:solid;padding-left:1ex">



<br>
Some editorial nits:<br>
in section 6.1.1 the word &quot;exploit&quot;(ed) is technically correct, b=
ut perhaps<br>
=C2=A0 =C2=A0an unfortunate choice for many non-english/french speakers.<br=
>
=C2=A0 =C2=A0&quot;exploiter&quot; en francois is perhaps best translated a=
s &quot;leverage&quot;<br>
=C2=A0 =C2=A0In IT circles, many understand an &quot;exploit&quot; to be a =
security flaw..<br>
<br></blockquote><div><br></div><div class=3D"gmail_default" style=3D"color=
:rgb(0,0,153)">.... I I will delete this term from my dictionary, thanks :-=
)</div><div class=3D"gmail_default" style=3D"color:rgb(0,0,153)">=E2=80=8B<=
/div><div class=3D"gmail_default" style=3D"color:rgb(0,0,153)">


<br></div><div class=3D"gmail_default" style=3D"color:rgb(0,0,153)"><br></d=
iv><div class=3D"gmail_default" style=3D"color:rgb(0,0,153)"><br></div><div=
 class=3D"gmail_default" style=3D"color:rgb(0,0,153)"><br></div><div class=
=3D"gmail_default">


<div class=3D"gmail_default"><font color=3D"#000099">Finally, I would remar=
k that we are working for upgrading the draft by considering comments provi=
ded within these discussions:=C2=A0</font></div><div class=3D"gmail_default=
"><font color=3D"#000099"><br>


</font></div><div class=3D"gmail_default"><font color=3D"#000099"><a href=
=3D"http://www.ietf.org/mail-archive/web/6tisch/current/msg01691.html" targ=
et=3D"_blank">http://www.ietf.org/mail-archive/web/6tisch/current/msg01691.=
html</a>=C2=A0</font></div>


<div class=3D"gmail_default"><span style=3D"color:rgb(0,0,153)"><a href=3D"=
http://www.ietf.org/mail-archive/web/6tisch/current/msg01680.html" target=
=3D"_blank">http://www.ietf.org/mail-archive/web/6tisch/current/msg01680.ht=
ml</a>=C2=A0</span><br>

</div>
<div class=3D"gmail_default"><span style=3D"color:rgb(0,0,153)"><a href=3D"=
http://www.ietf.org/mail-archive/web/6tisch/current/msg01685.html" target=
=3D"_blank">http://www.ietf.org/mail-archive/web/6tisch/current/msg01685.ht=
ml</a>=C2=A0</span><br>

</div>
<div class=3D"gmail_default"><font color=3D"#000099"><br></font></div><div =
class=3D"gmail_default"><font color=3D"#000099">and obviously, your comment=
s will be also carefully taken into account.=C2=A0</font></div><div class=
=3D"gmail_default">


<font color=3D"#000099"><br></font></div><div class=3D"gmail_default"><font=
 color=3D"#000099">Apart of these comments, can you provide further suggest=
ions and highlight in which direction this draft can be upgraded, thus bein=
g more useful for the work conducted within the security task force ?=C2=A0=
</font></div>


<div class=3D"gmail_default"><font color=3D"#000099"><br></font></div><div =
class=3D"gmail_default"><font color=3D"#000099">Thanks=C2=A0</font></div><d=
iv class=3D"gmail_default"><font color=3D"#000099">Giuseppe</font></div></d=
iv><div class=3D"gmail_default" style=3D"color:rgb(0,0,153)">


<br></div><div class=3D"gmail_default" style=3D"color:rgb(0,0,153)"></div><=
/div><div class=3D"gmail_extra"><br></div><br><br clear=3D"all"><div><br></=
div>-- <br><div dir=3D"ltr"><font style=3D"background-color:rgb(255,255,255=
)" color=3D"#000099"><b>Giuseppe Piro, PhD</b><br>


Post Doc Researcher<br>DEI, Politecnico di Bari<br>via Orabona 4 - 70125 (B=
ari), Italy.<br>email: <a href=3D"mailto:peppe@giuseppepiro.com" target=3D"=
_blank">peppe@giuseppepiro.com</a></font><div><font style=3D"background-col=
or:rgb(255,255,255)" color=3D"#000099">phone: <a href=3D"tel:%2B39%20080%20=
5963301" value=3D"+390805963301" target=3D"_blank">+39 080 5963301</a><br>


web: <a href=3D"http://telematics.poliba.it/piro" target=3D"_blank">g</a><a=
 href=3D"http://iuseppepiro.com" target=3D"_blank">iuseppepiro.com</a></fon=
t></div></div>
</div></div>

--047d7b4723dc35159d04f95ed47a--


From nobody Fri May 16 11:30:43 2014
Return-Path: <mcr@sandelman.ca>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 561741A0332 for <6tisch-security@ietfa.amsl.com>; Fri, 16 May 2014 11:30:37 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -0.653
X-Spam-Level: 
X-Spam-Status: No, score=-0.653 tagged_above=-999 required=5 tests=[BAYES_40=-0.001, RP_MATCHES_RCVD=-0.651, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Fwzm24HBNCot for <6tisch-security@ietfa.amsl.com>; Fri, 16 May 2014 11:30:34 -0700 (PDT)
Received: from tuna.sandelman.ca (tuna.sandelman.ca [209.87.252.184]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id AAF351A032C for <6tisch-security@ietf.org>; Fri, 16 May 2014 11:30:33 -0700 (PDT)
Received: from sandelman.ca (obiwan.sandelman.ca [IPv6:2607:f0b0:f:2::247]) by tuna.sandelman.ca (Postfix) with ESMTP id 4977C2002A; Fri, 16 May 2014 14:32:31 -0400 (EDT)
Received: by sandelman.ca (Postfix, from userid 179) id 48D4E63B1C; Fri, 16 May 2014 14:30:25 -0400 (EDT)
Received: from sandelman.ca (localhost [127.0.0.1]) by sandelman.ca (Postfix) with ESMTP id 3099A63B17; Fri, 16 May 2014 14:30:25 -0400 (EDT)
From: Michael Richardson <mcr+ietf@sandelman.ca>
To: 6tisch-security@ietf.org
In-Reply-To: <07C02745-0562-4B95-828A-6B1DCDD390FA@cisco.com>
References: <7591.1399145520@sandelman.ca> <07C02745-0562-4B95-828A-6B1DCDD390FA@cisco.com>
X-Mailer: MH-E 8.2; nmh 1.3-dev; GNU Emacs 23.4.1
X-Face: $\n1pF)h^`}$H>Hk{L"x@)JS7<%Az}5RyS@k9X%29-lHB$Ti.V>2bi.~ehC0; <'$9xN5Ub# z!G,p`nR&p7Fz@^UXIn156S8.~^@MJ*mMsD7=QFeq%AL4m<nPbLgmtKK-5dC@#:k
MIME-Version: 1.0
Content-Type: multipart/signed; boundary="=-=-="; micalg=pgp-sha1; protocol="application/pgp-signature"
Date: Fri, 16 May 2014 14:30:25 -0400
Message-ID: <28998.1400265025@sandelman.ca>
Sender: mcr@sandelman.ca
Archived-At: http://mailarchive.ietf.org/arch/msg/6tisch-security/QDYruPWy5RH4oATbiQLu8juMgsk
Cc: "Max Pritikin \(pritikin\)" <pritikin@cisco.com>, Robert Moskowitz <rgm@htt-consult.com>
Subject: Re: [6tisch-security] a different explanation of autonomic bootstrap
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 16 May 2014 18:30:37 -0000

--=-=-=
Content-Type: text/plain; charset=utf-8
Content-Transfer-Encoding: quoted-printable


Michael Richardson wrote:
    mcr> I think that I am making up something on the operator claiming sid=
e of
    mcr> things; because the IEEE 802.1AR specification does not (unless I
    mcr> missed it)
    mcr> say anything about how the device is claimed by the network (how it
    mcr> trusts
    mcr> the network), only how the network trusts the device.  Perhaps the=
re
    mcr> are some
    mcr> specifications which I've missed, or perhaps some things which are
    mcr> simply unspecified.

Max Pritikin (pritikin) <pritikin@cisco.com> wrote:
    > That is not specified in 802.1AR which focusses on the device identit=
y.

So, the good news is that we don't need to read and profile another
specification.  The bad news is that we need to make something up....
I'm hoping that Bob Moskowitz might have something.... Bob, would it be wor=
th
involving someone from a vendor of the phones that are involved?  Part of
this model was first described by Cullen Jennings... if that vendor is
involved...

    mcr> I'll explain below.

    > Interesting that you are communicating to the Factory Cloud Service
    > inline with the TLS handshake. In our discussions we would have
    > imagined completing the TLS handshake and then communicating with the
    > factory service. I see how this causes the difficulty you=E2=80=99re
    > referencing below.

Good that you see that in particular, in order for the device to complete
it's TLS certificate validation, the domain may need to use a different
certificate.  You are proposing that the one could complete the handshake
first, and then there is an interaction with the factory.   How does
this work in offline mode, or when the factory has gone out of business?
(Pulled a Nortel)

    > In this fashion it is a =E2=80=9C/BootstrapRequest=E2=80=9D extension=
 to RFC7030
    > Enrollment over Secure Transport. The basic message elements are all =
as
    > you described but I=E2=80=99ve simply re-ordered them to better match=
 the TLS
    > and EST flows which minimizes the integration efforts.

Is there some precedent on how the signed authz token looks?
I assume that it must bind the domain identity and the DeviceID.

    > RFC6066 TrustedAuthority won=E2=80=99t help here because Domain is un=
likely to
    > have a useful certificate issued by the Factory Cloud Service.

okay.  I though that this was the point of the authz token.

    > Instead the New Entity would provisionally accept the TLS
    > communications w/o being able to verify the Domain credential. It
    > submits its IDevID in response (during =E2=80=98J=E2=80=99) but the e=
ntire session is
    > still provisional.

In another email people complained about having open dangling TLS sessions.
I agree with your analysis that the constrained device is in charge of the
situation, and it needs to maintain at most one such session, but it does
need to remember (and blacklist for a period of time) peers which offer it
networks but which can not validate themselves after a period of time.

That period of time might need to be long: enough days to survive reasonable
business processes.  Enough the service might be up, the authorizations mig=
ht
not catch up until someone in accounts payable returns to work.  On the oth=
er
hand, should another offer come along the mote might be wiser to try that
network out.

=2D-
Michael Richardson <mcr+IETF@sandelman.ca>, Sandelman Software Works
 -=3D IPv6 IoT consulting =3D-




--=-=-=
Content-Type: application/pgp-signature

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iQEVAwUBU3ZZPoCLcPvd0N1lAQL3FQgAlq0zFirxdKa/geAqKUQ1NpxCuE1QReB5
zfMIx8OqmCpSmP2KS+zJjPRyUYNBva+6NIkmaQ9cpsUHfjObpH5H2cDIjK11TWCp
xicouFi3LU70E18ondlix6jbRMnKChkHwUXKnx/8xV4l/dzsB3TnA9t9qVUH58Sf
aJ+9Ig/u9+S4pDRQIgcooClmBHdLBs1KqoP+XtOW3gTMiZmvyBJlxeKhUs7HNEL9
9Ha3VXN0JOlg9q29GSe4DCRLJiu2AKzAVbQ9QoDUxQHGIOhw9eNy0HHBfwDF212z
teuDFrfA5s9M26e890ZM0vFb4Kp/b+oBhMOGz4QaHBOwMkt59RxDeA==
=gU/1
-----END PGP SIGNATURE-----
--=-=-=--


From nobody Mon May 19 08:15:24 2014
Return-Path: <pritikin@cisco.com>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 252D91A010F for <6tisch-security@ietfa.amsl.com>; Mon, 19 May 2014 08:15:23 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -12.452
X-Spam-Level: 
X-Spam-Status: No, score=-12.452 tagged_above=-999 required=5 tests=[BAYES_50=0.8, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_HI=-5, RP_MATCHES_RCVD=-0.651, SPF_PASS=-0.001, USER_IN_DEF_DKIM_WL=-7.5] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id EeeI0IMv8eID for <6tisch-security@ietfa.amsl.com>; Mon, 19 May 2014 08:15:18 -0700 (PDT)
Received: from alln-iport-7.cisco.com (alln-iport-7.cisco.com [173.37.142.94]) (using TLSv1 with cipher RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id A194C1A008D for <6tisch-security@ietf.org>; Mon, 19 May 2014 08:15:18 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cisco.com; i=@cisco.com; l=6105; q=dns/txt; s=iport; t=1400512518; x=1401722118; h=from:to:cc:subject:date:message-id:references: in-reply-to:content-id:content-transfer-encoding: mime-version; bh=779No3JxniD8RJVwsdPxySH8PUOhRta4CKO+iw7yVZw=; b=ljCXJcnfl+tvEfGVNFCaw14lL+LecJhbZ2odPCHE5ts0HGhsbLln8GPn ndgBGgc1MUysmbdnpcqMieFWqGRm2GMOIgz1mfWH+tabrn09IQUlBO2Rb p8+/LYXILhNUdjwygkzb/uUskOQy/ma7mUfi/0HS10T9UVEkNJNsUJVxN Y=;
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-Anti-Spam-Result: Am8FANseelOtJV2S/2dsb2JhbABPAQmDBlFYvEqGbFEBgRUWdIIlAQEBAwEBAQEJYgsFCwIBCBguJwslAgQOAwIaBYgaCA3SCxMEi0IBgisGAQoBHTMHgyuBFQSEXAKRAIN8kxqDN0GBLwcXBhw
X-IronPort-AV: E=Sophos;i="4.98,868,1392163200"; d="scan'208";a="45156927"
Received: from rcdn-core-10.cisco.com ([173.37.93.146]) by alln-iport-7.cisco.com with ESMTP; 19 May 2014 15:15:12 +0000
Received: from xhc-aln-x07.cisco.com (xhc-aln-x07.cisco.com [173.36.12.81]) by rcdn-core-10.cisco.com (8.14.5/8.14.5) with ESMTP id s4JFFCAr002748 (version=TLSv1/SSLv3 cipher=AES128-SHA bits=128 verify=FAIL); Mon, 19 May 2014 15:15:12 GMT
Received: from xmb-rcd-x03.cisco.com ([169.254.7.16]) by xhc-aln-x07.cisco.com ([173.36.12.81]) with mapi id 14.03.0123.003; Mon, 19 May 2014 10:15:12 -0500
From: "Max Pritikin (pritikin)" <pritikin@cisco.com>
To: Michael Richardson <mcr+ietf@sandelman.ca>
Thread-Topic: [6tisch-security] a different explanation of autonomic bootstrap
Thread-Index: AQHPZwZfgzRoqzgCkkiMkZTG8uHFBJsyoJWAgBFO/oCABIBygA==
Date: Mon, 19 May 2014 15:15:12 +0000
Message-ID: <7DB70E52-D3D9-4545-AF4F-CBFE11EEF352@cisco.com>
References: <7591.1399145520@sandelman.ca> <07C02745-0562-4B95-828A-6B1DCDD390FA@cisco.com> <28998.1400265025@sandelman.ca>
In-Reply-To: <28998.1400265025@sandelman.ca>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
x-originating-ip: [10.21.116.54]
Content-Type: text/plain; charset="Windows-1252"
Content-ID: <A6FFBAAE7F71EB4691AFBEB03C43A3CE@emea.cisco.com>
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
Archived-At: http://mailarchive.ietf.org/arch/msg/6tisch-security/zREAipfud5ukwfYB9lwRjGGcpAM
Cc: Robert Moskowitz <rgm@htt-consult.com>, "6tisch-security@ietf.org" <6tisch-security@ietf.org>
Subject: Re: [6tisch-security] a different explanation of autonomic bootstrap
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 19 May 2014 15:15:23 -0000

Conversation continued inline for context. =20

On May 16, 2014, at 12:30 PM, Michael Richardson <mcr+ietf@sandelman.ca> wr=
ote:

>=20
> Michael Richardson wrote:
>    mcr> I think that I am making up something on the operator claiming si=
de of
>    mcr> things; because the IEEE 802.1AR specification does not (unless I
>    mcr> missed it)
>    mcr> say anything about how the device is claimed by the network (how =
it
>    mcr> trusts
>    mcr> the network), only how the network trusts the device.  Perhaps th=
ere
>    mcr> are some
>    mcr> specifications which I've missed, or perhaps some things which ar=
e
>    mcr> simply unspecified.
>=20
> Max Pritikin (pritikin) <pritikin@cisco.com> wrote:
>> That is not specified in 802.1AR which focusses on the device identity.
>=20
> So, the good news is that we don't need to read and profile another
> specification.  The bad news is that we need to make something up....
> I'm hoping that Bob Moskowitz might have something.... Bob, would it be w=
orth
> involving someone from a vendor of the phones that are involved?  Part of
> this model was first described by Cullen Jennings... if that vendor is
> involved...
>=20
>    mcr> I'll explain below.
>=20
>> Interesting that you are communicating to the Factory Cloud Service
>> inline with the TLS handshake. In our discussions we would have
>> imagined completing the TLS handshake and then communicating with the
>> factory service. I see how this causes the difficulty you=92re
>> referencing below.
>=20
> Good that you see that in particular, in order for the device to complete
> it's TLS certificate validation, the domain may need to use a different
> certificate.  You are proposing that the one could complete the handshake
> first, and then there is an interaction with the factory.   How does
> this work in offline mode, or when the factory has gone out of business?
> (Pulled a Nortel)

The communication channel between the Domain and the Factory does not requi=
re the New Entity to cryptographically identify itself, therefore offline N=
ew Entities are supported.=20
The messages from the Factory are store-and-forward (e.g. signed) so they c=
an be obtained in advanced and presented once the New Entity/Domain communi=
cation is established.=20
Nonceless signed replies from the Factory never expire, so they can persist=
 beyond factories going out of business.=20
If there are a large number of New Entities in the world then the Factory k=
eys have value and perhaps that service could be spun off? A consortium app=
roach could insulate one particular factory from an individual business. (A=
s long as the consortium stays alive. See discussion below about Certificat=
e Transparency).
Ultimately though if the Factory option totally goes away then physical pos=
session of a device is sufficient to take ownership of it. What you can=92t=
 do is remotely claim ownership of it (zero touch provisioning).

>=20
>> In this fashion it is a =93/BootstrapRequest=94 extension to RFC7030
>> Enrollment over Secure Transport. The basic message elements are all as
>> you described but I=92ve simply re-ordered them to better match the TLS
>> and EST flows which minimizes the integration efforts.
>=20
> Is there some precedent on how the signed authz token looks?
> I assume that it must bind the domain identity and the DeviceID.

In my prototype I build the Factory response like so:

# build response
# It contains:
#	Device Identity
#	Hash of the Domain root key
# 	The client nonce (if provided)
TMP_RESP=3D"$(mktemp)"
echo $UDI > $TMP_RESP
echo $DOMAINHASH >> $TMP_RESP
echo $CLIENTNONCE >> $TMP_RESP

# use smime to sign response using the Factory Key
# Here called a =93Manufacturing Authorized Signing Authority (MASA)=94 key
$OPENSSLCMD smime -sign -in $TMP_RESP -aes128 -signer $MASA_DBDIR/masacrtan=
dkey.pem -out $TMP_RESP.smime -nodetach

My current thinking would be to move this more toward leveraging a Merkle H=
ash Tree similar to the methods proposed by Google for their Certificate Tr=
ansparency work as described in RFC6962. Effectively what we=92re looking f=
or here is very similar =97 we=92re building a transparent log of the event=
 (here "binding a device identity to a domain hash" rather than the issuanc=
e of a certificate which is the "binding of a principle name to key=94).=20

>> RFC6066 TrustedAuthority won=92t help here because Domain is unlikely to
>> have a useful certificate issued by the Factory Cloud Service.
>=20
> okay.  I though that this was the point of the authz token.
>=20
>> Instead the New Entity would provisionally accept the TLS
>> communications w/o being able to verify the Domain credential. It
>> submits its IDevID in response (during =91J=92) but the entire session i=
s
>> still provisional.
>=20
> In another email people complained about having open dangling TLS session=
s.
> I agree with your analysis that the constrained device is in charge of th=
e
> situation, and it needs to maintain at most one such session, but it does
> need to remember (and blacklist for a period of time) peers which offer i=
t
> networks but which can not validate themselves after a period of time.

agreed.

> That period of time might need to be long: enough days to survive reasona=
ble
> business processes.  Enough the service might be up, the authorizations m=
ight
> not catch up until someone in accounts payable returns to work.  On the o=
ther
> hand, should another offer come along the mote might be wiser to try that
> network out.

An interesting point. I haven=92t thought enough about how the device behav=
es if its left hanging for a long period of time.

- max=20

>=20
> --
> Michael Richardson <mcr+IETF@sandelman.ca>, Sandelman Software Works
> -=3D IPv6 IoT consulting =3D-
>=20
>=20
>=20
> _______________________________________________
> 6tisch-security mailing list
> 6tisch-security@ietf.org
> https://www.ietf.org/mailman/listinfo/6tisch-security


From nobody Tue May 20 05:26:34 2014
Return-Path: <mcr@sandelman.ca>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 57E351A06D0 for <6tisch-security@ietfa.amsl.com>; Tue, 20 May 2014 05:26:33 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.541
X-Spam-Level: 
X-Spam-Status: No, score=-2.541 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RP_MATCHES_RCVD=-0.651, SPF_PASS=-0.001, T_TVD_MIME_NO_HEADERS=0.01, WEIRD_PORT=0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id bG2AnaIcG_08 for <6tisch-security@ietfa.amsl.com>; Tue, 20 May 2014 05:26:31 -0700 (PDT)
Received: from tuna.sandelman.ca (tuna.sandelman.ca [IPv6:2607:f0b0:f:3::184]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 3C2A61A03A9 for <6tisch-security@ietf.org>; Tue, 20 May 2014 05:26:31 -0700 (PDT)
Received: from sandelman.ca (desk.marajade.sandelman.ca [209.87.252.247]) by tuna.sandelman.ca (Postfix) with ESMTP id DE47220028 for <6tisch-security@ietf.org>; Tue, 20 May 2014 08:28:45 -0400 (EDT)
Received: by sandelman.ca (Postfix, from userid 179) id A0AFA63B1E; Tue, 20 May 2014 08:26:23 -0400 (EDT)
Received: from sandelman.ca (localhost [127.0.0.1]) by sandelman.ca (Postfix) with ESMTP id 8E64A63B1C for <6tisch-security@ietf.org>; Tue, 20 May 2014 08:26:23 -0400 (EDT)
From: Michael Richardson <mcr+ietf@sandelman.ca>
to: 6tisch-security@ietf.org
In-Reply-To: <29064.1399255587@sandelman.ca>
References: <E045AECD98228444A58C61C200AE1BD8416F3AF4@xmb-rcd-x01.cisco.com> <bomn1n01Q3zUFux01ompsd> <531DD632.2060009@cox.net> <531DDB20.5050600@gmail.com> <10925.1394631496@sandelman.ca> <532069C8.2050005@gmail.com> <23590.1394999032@sandelman.ca> <18106.1395625035@sandelman.ca> <19609.1396839403@sandelman.ca> <11557.1397444260@sandelman.ca> <28192.1398644294@sandelman.ca> <29064.1399255587@sandelman.ca>
X-Mailer: MH-E 8.2; nmh 1.3-dev; GNU Emacs 23.4.1
X-Face: $\n1pF)h^`}$H>Hk{L"x@)JS7<%Az}5RyS@k9X%29-lHB$Ti.V>2bi.~ehC0; <'$9xN5Ub# z!G,p`nR&p7Fz@^UXIn156S8.~^@MJ*mMsD7=QFeq%AL4m<nPbLgmtKK-5dC@#:k
MIME-Version: 1.0
Content-Type: multipart/signed; boundary="=-=-="; micalg=pgp-sha1; protocol="application/pgp-signature"
Date: Tue, 20 May 2014 08:26:23 -0400
Message-ID: <19475.1400588783@sandelman.ca>
Sender: mcr@sandelman.ca
Archived-At: http://mailarchive.ietf.org/arch/msg/6tisch-security/M9bzrPMVHIuxpMCfktNSfE6tlUM
Subject: [6tisch-security] agenda for 2014-05-20 6tisch security call
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 20 May 2014 12:26:33 -0000

--=-=-=


To remind, we moved the call from the 19th to the 20th at 10am EDT.
That's 90 minutes from this email.

1) notewell.
2) intros
3) Rene had some material to present?  Did it happen last week,
   it seems not?
4) review of claim certificate process, vs EST with token.

-- remember that the call is recorded, and the NoteWell applies.

-- The URL to access the webex, which will we use for audio only:
  https://cisco.webex.com/cisco/j.php?MTID=m2fe139bf876cea3ec62750cd580b7908

-- we will resume with the etherpad at:
   http://etherpad.tools.ietf.org:9000/p/notes-ietf-89-6tisch-security

I'm at +1 613 276-6809, IM: mcr@xmpp.credil.org or mcharlesr@gmail.com,
if you need more than that to get in, or are having difficulties.
Please make sure your audio works, and that you mute when not talking.


--
Michael Richardson <mcr+IETF@sandelman.ca>, Sandelman Software Works
 -= IPv6 IoT consulting =-




--=-=-=
Content-Type: application/pgp-signature

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iQEVAwUBU3tJ7ICLcPvd0N1lAQK8GwgAqMS1vywe58kdZ4VdIJLG8H43ks9DkMGi
vXuMG1TJBiwPyebDaRgiSQs7CCp6DB7sPPRQ1aJA5knbE/kMcGe1kkPXvB2s/LgD
b9XOdDY4Lvvvm9LUAsrz/V5yorvvSWJ8twBtyXSSygiVAXe1noN8X3s/34lFT6GW
glQv1oybTYzEk5Za9RK25R6HFhgIIlA8Tmju/SEMrZkxDmkdQ3nrMGJiQ7mc8qrc
u8OhFZhzMNX2EvunQSybTjGAoHmA1gnEkccjXsxmtWk3V1V9k2OVwzHAmobFu+ud
zufjt5laRdc4DYzrY35iOz2aRwuxzTw7rPsC4jLRJqCOT1j7NmC9wg==
=DtEz
-----END PGP SIGNATURE-----
--=-=-=--


From nobody Tue May 20 06:45:43 2014
Return-Path: <rstruik.ext@gmail.com>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 7D37A1A06E8 for <6tisch-security@ietfa.amsl.com>; Tue, 20 May 2014 06:45:41 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.998
X-Spam-Level: 
X-Spam-Status: No, score=-1.998 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, SPF_PASS=-0.001, WEIRD_PORT=0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id VhoSC6D3rOMY for <6tisch-security@ietfa.amsl.com>; Tue, 20 May 2014 06:45:38 -0700 (PDT)
Received: from mail-ig0-x22c.google.com (mail-ig0-x22c.google.com [IPv6:2607:f8b0:4001:c05::22c]) (using TLSv1 with cipher ECDHE-RSA-RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 795411A035C for <6tisch-security@ietf.org>; Tue, 20 May 2014 06:45:38 -0700 (PDT)
Received: by mail-ig0-f172.google.com with SMTP id uy17so4855473igb.11 for <6tisch-security@ietf.org>; Tue, 20 May 2014 06:45:37 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113;  h=message-id:date:from:user-agent:mime-version:to:subject:references :in-reply-to:content-type; bh=HMWd6q/A185yq3YUTEni3HIkDZPoN6E0/U2W1YCJuic=; b=wkray6AiURxtPcsMO99W/o/jNpKV77n0k7UjSQm8XFNIjm5rjbxXhlvC6g8uKUiAqG sLZWv0sCuRfaVvh55AgLpOcMOtcZqMJnz/B7HLgYSWKHqVcuvjPwrD1ZlvYFl3TcIVBV Wu52tYAXsrjtSxmu1rq+fOHDwsZStO13kr31QyCcCQJu+XESFoQ+5ji+GLPyNFWFQyyi K03TTYpPA9PI6uhVBE6lykr7HPrB5THbNkbqCyr+qA3uJQCns7LUuHI03a5qBZoitkZz 9YcCJNJW6oI4hia+qNy51h/TnFUsBncuLx9R4EoW9I6+zHrKANbbCt7bqqB7CEA1caQb /6XQ==
X-Received: by 10.50.109.163 with SMTP id ht3mr5187801igb.4.1400593535196; Tue, 20 May 2014 06:45:35 -0700 (PDT)
Received: from [192.168.1.104] (CPE0013100e2c51-CM001cea35caa6.cpe.net.cable.rogers.com. [99.231.3.110]) by mx.google.com with ESMTPSA id sc2sm29082494igb.5.2014.05.20.06.45.33 for <multiple recipients> (version=TLSv1 cipher=ECDHE-RSA-RC4-SHA bits=128/128); Tue, 20 May 2014 06:45:33 -0700 (PDT)
Message-ID: <537B5C77.5020800@gmail.com>
Date: Tue, 20 May 2014 09:45:27 -0400
From: Rene Struik <rstruik.ext@gmail.com>
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:24.0) Gecko/20100101 Thunderbird/24.5.0
MIME-Version: 1.0
To: Michael Richardson <mcr+ietf@sandelman.ca>, 6tisch-security@ietf.org
References: <E045AECD98228444A58C61C200AE1BD8416F3AF4@xmb-rcd-x01.cisco.com> <bomn1n01Q3zUFux01ompsd> <531DD632.2060009@cox.net> <531DDB20.5050600@gmail.com> <10925.1394631496@sandelman.ca> <532069C8.2050005@gmail.com> <23590.1394999032@sandelman.ca> <18106.1395625035@sandelman.ca> <19609.1396839403@sandelman.ca> <11557.1397444260@sandelman.ca> <28192.1398644294@sandelman.ca> <29064.1399255587@sandelman.ca> <19475.1400588783@sandelman.ca>
In-Reply-To: <19475.1400588783@sandelman.ca>
Content-Type: multipart/alternative; boundary="------------020709090600000504020004"
Archived-At: http://mailarchive.ietf.org/arch/msg/6tisch-security/Y-e4AIFI_9_N0bUKZ9Nh7_mKXls
Subject: [6tisch-security] (some outstanding issues re join protocol -- personal perspective) Re: agenda for 2014-05-20 6tisch security call
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 20 May 2014 13:45:41 -0000

This is a multi-part message in MIME format.
--------------020709090600000504020004
Content-Type: text/plain; charset=ISO-8859-1; format=flowed
Content-Transfer-Encoding: 7bit

Hi Michael:

At the previous conf call of May 12, 2014, we discussed message flows of 
w/HART join process, as also alluded to in my email below (the specs 
could not be distributed due to copyright restrictions).

In my mind, 6TiSCH protocol can use similar communication flows as 
w/HART where only non-local communication flows (between joining node 
and network manager) would be
i) passing join/authentication information from joining node to network 
manager (and back);
ii) passing configuration parms from network manager to joining node 
(keys, links, frame links) and neighbor report from joined node to 
network manager.

MAIN OUTSTANDING ISSUES (in my mind):
a) Packet sizes:
get more info on packet sizes configuration parms, as w/HART uses. Note 
RS: during call, Tom Phinney suggested contacting Wally Bratt from HART 
Comm. Foundation for this).  Note RS: Shouldn't, e.g., Dust Networks 
have info on packet sizes/structure?; ISA SP100.11a metrics would also 
help, as would ZigBee 2.0 config parms. Does, e.g., Cisco have useful 
data points here?
b) Device Ids:
With industrial control, network manager would look up "tag name" device 
in pre-configured database. Details on tag name syntax, how assigned, 
and how bound to, e.g., EUI-64 are missing. Note RS: Perhaps, Tom 
Phinney could point at tag name syntax and lifecycle aspects here?
c) Join process impact on network:
Pascal Thubert asked "when network would explode with join". Note RS: 
the following questions come to mind:
- how does joining  node find a time slot to send first join packet to 
neighbor node (presumably, this would require listening for Enhanced 
Beacon, but details on schedule in terms of time and channels seems 
incomplete [min-schedule suggests 101x15ms slotframe and "less than 10s 
repeat of EBs, but that leaves lots of dead time and does not suggest a 
schedule that would create a common time window where two devices would 
both be awake).
- how does joining node negotiate a local schedule with neighbor node 
for execution of join protocol (draft-watteyne-6tisch-tisch-00 refers to 
local schedule negotiation need, but unclear whether this has been 
looked into in detail).
- for local traffic (joining node/neighbor), it seems Pascal Thubert's 
"exploding network" may not happen easily. Nevertheless, unclear what 
impact of "join priority flag TSCH 802.15.4e frames is [that seems to 
have been designed with legacy w/HART in mind (centralized solution). 
With centralized tree-like solution, lots of traffic happens close to 
the root, thus potentially amplifying congestion around root node 
(=network manager?).
d) crypto protocol details of join protocol:
Note RS: I can solve this (close to optimal design already done 
[assuming I can do this "without hands tied behind the back"])
e) authorization/trust management:
it is here where binding of ids to public keys via certs and lifecycle 
aspects play a role, as well as syntax/semantics of authorization 
messages. Note RS: question is whether ACE could play a role here 
(current charter discussions seem to be endless, though). As has been 
brought up before, a potential instantiation of certs would be the use 
of 802.1ar certs, but this is certainly not the only way of doing things.

There are lots of other things we should consider, outside the join 
protocol realm.

------- Original Message --------
Subject: 	Re: [6tisch-security] agenda(?) for call today
Date: 	Mon, 12 May 2014 09:53:37 -0400
From: 	Rene Struik <rstruik.ext@gmail.com>
To: 	Michael Richardson <mcr+ietf@sandelman.ca>, 6tisch-security@ietf.org



Hi Michael et al:

Another topic worth exploring more is the join protocol details.

(There are many other aspects, including certs, as you mentioned, more 
general security architecture, provisioning, etc., but below only deals 
with join.)

With w/HART, the join process only interacts with the network manager 
(62591, Annex A.3, Fig. A.1) for
-forwarded join from joining node to network manager;
-passing configuration parms from network manager to joining node (keys, 
links, frame links) and neighbor report from joined node to network manager.
All other communications are local, between joining device and neighbor 
(resp. with maintenance tool).

It may have merit if we could use similar communication flows with 
6tisch, i.e., keep most traffic local to the joining device, except for 
configuration parms exchange and authorization info passing.

Most important consideration (from communication perspective) would be 
that non-local traffic would be minimized, as also w/HART does. From a 
marketing perspective, mimicking the communication flows w/HART already 
has would keep all time scheduling considerations for w/HART as 
currently there and 6TiSCH as to be detailed roughly the same. This 
would longer term help in pushing 6tisch-style security scheme to 
w/HART, since from a distance it looks the same (although trying to 
scrap the maintenance tool).

Of course, this does not deal with the details of the joining protocol 
itself; only the flows.

What about we look at some of the flows, and enumerate all issues that 
need to be addressed here, both from a security perspective and 
otherwise. We can then assign people to find missing information (I am 
esp. curious about how devices know when to send/receive and 
contributions of cycling efforts to total time latency).

We could go over w/HART join flows during the call, to trigger these 
questions.

Best regards, Rene


On 5/20/2014 8:26 AM, Michael Richardson wrote:
> To remind, we moved the call from the 19th to the 20th at 10am EDT.
> That's 90 minutes from this email.
>
> 1) notewell.
> 2) intros
> 3) Rene had some material to present?  Did it happen last week,
>     it seems not?
> 4) review of claim certificate process, vs EST with token.
>
> -- remember that the call is recorded, and the NoteWell applies.
>
> -- The URL to access the webex, which will we use for audio only:
>    https://cisco.webex.com/cisco/j.php?MTID=m2fe139bf876cea3ec62750cd580b7908
>
> -- we will resume with the etherpad at:
>     http://etherpad.tools.ietf.org:9000/p/notes-ietf-89-6tisch-security
>
> I'm at +1 613 276-6809, IM: mcr@xmpp.credil.org or mcharlesr@gmail.com,
> if you need more than that to get in, or are having difficulties.
> Please make sure your audio works, and that you mute when not talking.
>
>
> --
> Michael Richardson <mcr+IETF@sandelman.ca>, Sandelman Software Works
>   -= IPv6 IoT consulting =-
>
>
>
>
>
> _______________________________________________
> 6tisch-security mailing list
> 6tisch-security@ietf.org
> https://www.ietf.org/mailman/listinfo/6tisch-security


-- 
email: rstruik.ext@gmail.com | Skype: rstruik
cell: +1 (647) 867-5658 | US: +1 (415) 690-7363


--------------020709090600000504020004
Content-Type: text/html; charset=ISO-8859-1
Content-Transfer-Encoding: 7bit

<html>
  <head>
    <meta content="text/html; charset=ISO-8859-1"
      http-equiv="Content-Type">
  </head>
  <body bgcolor="#FFFFFF" text="#000000">
    <div class="moz-cite-prefix">Hi Michael:<br>
      <br>
      At the previous conf call of May 12, 2014, we discussed message
      flows of w/HART join process, as also alluded to in my email below
      (the specs could not be distributed due to copyright
      restrictions).<br>
      <br>
      In my mind, 6TiSCH protocol can use similar communication flows as
      w/HART where only non-local communication flows (between joining
      node and network manager) would be <br>
      i) passing join/authentication information from joining node to
      network manager (and back);<br>
      ii) passing configuration parms from network manager to joining
      node (keys, links, frame links) and neighbor report from joined
      node to network manager.<br>
      <br>
      MAIN OUTSTANDING ISSUES (in my mind): <br>
      a) Packet sizes: <br>
      get more info on packet sizes configuration parms, as w/HART uses.
      Note RS: during call, Tom Phinney suggested contacting Wally Bratt
      from HART Comm. Foundation for this).&nbsp; Note RS: Shouldn't, e.g.,
      Dust Networks have info on packet sizes/structure?; ISA SP100.11a
      metrics would also help, as would ZigBee 2.0 config parms. Does,
      e.g., Cisco have useful data points here?<br>
      b) Device Ids:<br>
      With industrial control, network manager would look up "tag name"
      device in pre-configured database. Details on tag name syntax, how
      assigned, and how bound to, e.g., EUI-64 are missing. Note RS:
      Perhaps, Tom Phinney could point at tag name syntax and lifecycle
      aspects here?<br>
      c) Join process impact on network: <br>
      Pascal Thubert asked "when network would explode with join". Note
      RS: the following questions come to mind:<br>
      - how does joining&nbsp; node find a time slot to send first join
      packet to neighbor node (presumably, this would require listening
      for Enhanced Beacon, but details on schedule in terms of time and
      channels seems incomplete [min-schedule suggests 101x15ms
      slotframe and "less than 10s repeat of EBs, but that leaves lots
      of dead time and does not suggest a schedule that would create a
      common time window where two devices would both be awake).<br>
      - how does joining node negotiate a local schedule with neighbor
      node for execution of join protocol
      (draft-watteyne-6tisch-tisch-00 refers to local schedule
      negotiation need, but unclear whether this has been looked into in
      detail).<br>
      - for local traffic (joining node/neighbor), it seems Pascal
      Thubert's "exploding network" may not happen easily. Nevertheless,
      unclear what impact of "join priority flag TSCH 802.15.4e frames
      is [that seems to have been designed with legacy w/HART in mind
      (centralized solution). With centralized tree-like solution, lots
      of traffic happens close to the root, thus potentially amplifying
      congestion around root node (=network manager?).<br>
      d) crypto protocol details of join protocol:<br>
      Note RS: I can solve this (close to optimal design already done
      [assuming I can do this "without hands tied behind the back"])<br>
      e) authorization/trust management:<br>
      it is here where binding of ids to public keys via certs and
      lifecycle aspects play a role, as well as syntax/semantics of
      authorization messages. Note RS: question is whether ACE could
      play a role here (current charter discussions seem to be endless,
      though). As has been brought up before, a potential instantiation
      of certs would be the use of 802.1ar certs, but this is certainly
      not the only way of doing things.<br>
      <br>
      There are lots of other things we should consider, outside the
      join protocol realm.<br>
      <br>
      ------- Original Message --------
      <table class="moz-email-headers-table" cellpadding="0"
        cellspacing="0" border="0">
        <tbody>
          <tr>
            <th align="RIGHT" nowrap="nowrap" valign="BASELINE">Subject:
            </th>
            <td>Re: [6tisch-security] agenda(?) for call today</td>
          </tr>
          <tr>
            <th align="RIGHT" nowrap="nowrap" valign="BASELINE">Date: </th>
            <td>Mon, 12 May 2014 09:53:37 -0400</td>
          </tr>
          <tr>
            <th align="RIGHT" nowrap="nowrap" valign="BASELINE">From: </th>
            <td>Rene Struik <a class="moz-txt-link-rfc2396E" href="mailto:rstruik.ext@gmail.com">&lt;rstruik.ext@gmail.com&gt;</a></td>
          </tr>
          <tr>
            <th align="RIGHT" nowrap="nowrap" valign="BASELINE">To: </th>
            <td>Michael Richardson <a class="moz-txt-link-rfc2396E" href="mailto:mcr+ietf@sandelman.ca">&lt;mcr+ietf@sandelman.ca&gt;</a>,
              <a class="moz-txt-link-abbreviated" href="mailto:6tisch-security@ietf.org">6tisch-security@ietf.org</a></td>
          </tr>
        </tbody>
      </table>
      <br>
      <br>
      <div class="moz-cite-prefix">Hi Michael et al:<br>
        <br>
        Another topic worth exploring more is the join protocol details.
        <br>
        <br>
        (There are many other aspects, including certs, as you
        mentioned, more general security architecture, provisioning,
        etc., but below only deals with join.)<br>
        <br>
        With w/HART, the join process only interacts with the network
        manager (62591, Annex A.3, Fig. A.1) for <br>
        -forwarded join from joining node to network manager;<br>
        -passing configuration parms from network manager to joining
        node (keys, links, frame links) and neighbor report from joined
        node to network manager.<br>
        All other communications are local, between joining device and
        neighbor (resp. with maintenance tool).<br>
        <br>
        It may have merit if we could use similar communication flows
        with 6tisch, i.e., keep most traffic local to the joining
        device, except for configuration parms exchange and
        authorization info passing. <br>
        <br>
        Most important consideration (from communication perspective)
        would be that non-local traffic would be minimized, as also
        w/HART does. From a marketing perspective, mimicking the
        communication flows w/HART already has would keep all time
        scheduling considerations for w/HART as currently there and
        6TiSCH as to be detailed roughly the same. This would longer
        term help in pushing 6tisch-style security scheme to w/HART,
        since from a distance it looks the same (although trying to
        scrap the maintenance tool).<br>
        <br>
        Of course, this does not deal with the details of the joining
        protocol itself; only the flows.<br>
        <br>
        What about we look at some of the flows, and enumerate all
        issues that need to be addressed here, both from a security
        perspective and otherwise. We can then assign people to find
        missing information (I am esp. curious about how devices know
        when to send/receive and contributions of cycling efforts to
        total time latency). <br>
        <br>
        We could go over w/HART join flows during the call, to trigger
        these questions.<br>
        <br>
        Best regards, Rene<br>
      </div>
      <br>
      <br>
      On 5/20/2014 8:26 AM, Michael Richardson wrote:<br>
    </div>
    <blockquote cite="mid:19475.1400588783@sandelman.ca" type="cite">
      <pre wrap="">
To remind, we moved the call from the 19th to the 20th at 10am EDT.
That's 90 minutes from this email.

1) notewell.
2) intros
3) Rene had some material to present?  Did it happen last week,
   it seems not?
4) review of claim certificate process, vs EST with token.

-- remember that the call is recorded, and the NoteWell applies.

-- The URL to access the webex, which will we use for audio only:
  <a class="moz-txt-link-freetext" href="https://cisco.webex.com/cisco/j.php?MTID=m2fe139bf876cea3ec62750cd580b7908">https://cisco.webex.com/cisco/j.php?MTID=m2fe139bf876cea3ec62750cd580b7908</a>

-- we will resume with the etherpad at:
   <a class="moz-txt-link-freetext" href="http://etherpad.tools.ietf.org:9000/p/notes-ietf-89-6tisch-security">http://etherpad.tools.ietf.org:9000/p/notes-ietf-89-6tisch-security</a>

I'm at +1 613 276-6809, IM: <a class="moz-txt-link-abbreviated" href="mailto:mcr@xmpp.credil.org">mcr@xmpp.credil.org</a> or <a class="moz-txt-link-abbreviated" href="mailto:mcharlesr@gmail.com">mcharlesr@gmail.com</a>,
if you need more than that to get in, or are having difficulties.
Please make sure your audio works, and that you mute when not talking.


--
Michael Richardson <a class="moz-txt-link-rfc2396E" href="mailto:mcr+IETF@sandelman.ca">&lt;mcr+IETF@sandelman.ca&gt;</a>, Sandelman Software Works
 -= IPv6 IoT consulting =-



</pre>
      <br>
      <fieldset class="mimeAttachmentHeader"></fieldset>
      <br>
      <pre wrap="">_______________________________________________
6tisch-security mailing list
<a class="moz-txt-link-abbreviated" href="mailto:6tisch-security@ietf.org">6tisch-security@ietf.org</a>
<a class="moz-txt-link-freetext" href="https://www.ietf.org/mailman/listinfo/6tisch-security">https://www.ietf.org/mailman/listinfo/6tisch-security</a>
</pre>
    </blockquote>
    <br>
    <br>
    <pre class="moz-signature" cols="72">-- 
email: <a class="moz-txt-link-abbreviated" href="mailto:rstruik.ext@gmail.com">rstruik.ext@gmail.com</a> | Skype: rstruik
cell: +1 (647) 867-5658 | US: +1 (415) 690-7363</pre>
  </body>
</html>

--------------020709090600000504020004--


From nobody Tue May 20 06:55:16 2014
Return-Path: <mcr@sandelman.ca>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id C543F1A0336 for <6tisch-security@ietfa.amsl.com>; Tue, 20 May 2014 06:55:13 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.542
X-Spam-Level: 
X-Spam-Status: No, score=-2.542 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RP_MATCHES_RCVD=-0.651, SPF_PASS=-0.001, T_TVD_MIME_NO_HEADERS=0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id g1tVx1uShbuQ for <6tisch-security@ietfa.amsl.com>; Tue, 20 May 2014 06:55:12 -0700 (PDT)
Received: from tuna.sandelman.ca (tuna.sandelman.ca [209.87.252.184]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 43DBB1A035B for <6tisch-security@ietf.org>; Tue, 20 May 2014 06:55:12 -0700 (PDT)
Received: from sandelman.ca (obiwan.sandelman.ca [IPv6:2607:f0b0:f:2::247]) by tuna.sandelman.ca (Postfix) with ESMTP id 2EC8D20028; Tue, 20 May 2014 09:57:30 -0400 (EDT)
Received: by sandelman.ca (Postfix, from userid 179) id F394B63B1E; Tue, 20 May 2014 09:55:10 -0400 (EDT)
Received: from sandelman.ca (localhost [127.0.0.1]) by sandelman.ca (Postfix) with ESMTP id DEF7C63B1C; Tue, 20 May 2014 09:55:10 -0400 (EDT)
From: Michael Richardson <mcr+ietf@sandelman.ca>
to: Pascal Thubert <pthubert@cisco.com>
In-Reply-To: <19475.1400588783@sandelman.ca>
References: <E045AECD98228444A58C61C200AE1BD8416F3AF4@xmb-rcd-x01.cisco.com> <bomn1n01Q3zUFux01ompsd> <531DD632.2060009@cox.net> <531DDB20.5050600@gmail.com> <10925.1394631496@sandelman.ca> <532069C8.2050005@gmail.com> <23590.1394999032@sandelman.ca> <18106.1395625035@sandelman.ca> <19609.1396839403@sandelman.ca> <11557.1397444260@sandelman.ca> <28192.1398644294@sandelman.ca> <29064.1399255587@sandelman.ca> <19475.1400588783@sandelman.ca>
X-Mailer: MH-E 8.2; nmh 1.3-dev; GNU Emacs 23.4.1
X-Face: $\n1pF)h^`}$H>Hk{L"x@)JS7<%Az}5RyS@k9X%29-lHB$Ti.V>2bi.~ehC0; <'$9xN5Ub# z!G,p`nR&p7Fz@^UXIn156S8.~^@MJ*mMsD7=QFeq%AL4m<nPbLgmtKK-5dC@#:k
MIME-Version: 1.0
Content-Type: multipart/signed; boundary="=-=-="; micalg=pgp-sha1; protocol="application/pgp-signature"
Date: Tue, 20 May 2014 09:55:10 -0400
Message-ID: <5757.1400594110@sandelman.ca>
Sender: mcr@sandelman.ca
Archived-At: http://mailarchive.ietf.org/arch/msg/6tisch-security/VXuQWmw5Y7sOS3bAA2-0Fqb1ndc
Cc: 6tisch-security@ietf.org
Subject: Re: [6tisch-security] agenda for 2014-05-20 6tisch security call
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 20 May 2014 13:55:13 -0000

--=-=-=


Michael Richardson <mcr+ietf@sandelman.ca> wrote:
    > -- The URL to access the webex, which will we use for audio only:
    > https://cisco.webex.com/cisco/j.php?MTID=m2fe139bf876cea3ec62750cd580b7908

Pascal, this URL does not work for today.


--
Michael Richardson <mcr+IETF@sandelman.ca>, Sandelman Software Works
 -= IPv6 IoT consulting =-




--=-=-=
Content-Type: application/pgp-signature

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iQEVAwUBU3tevICLcPvd0N1lAQLc4gf/b9g99Jp4O+fJbUcmEf22UYIjH9KtrBur
QiAXz/lUq23eirNiXB5vgQ9aae1CuH6/xmBsEGqmUFXTvEynKMydbEthwu2Qvqpz
58bowkeVkznwAbK2llHSLnAiqK40MbDxRZwMvvm7y2QkGAyKT3O2pybvmZPGF860
+AsHuEOQCC4irJXkSvChYeiRK0KfsLKzHYqA6uRb4jrrleQbQEpEqUDXI8v88dMK
j64w8zVLZdI7o1mk8sE+2Miy1mHriNiAhqCW5Pyvwbb1veH8trpbO709wYTMJxvM
Pq+CFih/A+ljfpSEi739gzdL/+RWjBe+ci+kCnA+ndivrDiukZ2SWA==
=VvX4
-----END PGP SIGNATURE-----
--=-=-=--


From nobody Tue May 20 07:51:14 2014
Return-Path: <mbehring@cisco.com>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 909F31A06FB for <6tisch-security@ietfa.amsl.com>; Tue, 20 May 2014 07:51:13 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -15.152
X-Spam-Level: 
X-Spam-Status: No, score=-15.152 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_HI=-5, RP_MATCHES_RCVD=-0.651, SPF_PASS=-0.001, USER_IN_DEF_DKIM_WL=-7.5] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 92G72D2W6_Rm for <6tisch-security@ietfa.amsl.com>; Tue, 20 May 2014 07:51:10 -0700 (PDT)
Received: from alln-iport-7.cisco.com (alln-iport-7.cisco.com [173.37.142.94]) (using TLSv1 with cipher RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 17EC51A005C for <6tisch-security@ietf.org>; Tue, 20 May 2014 07:51:05 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cisco.com; i=@cisco.com; l=11156; q=dns/txt; s=iport; t=1400597464; x=1401807064; h=from:to:subject:date:message-id:references:in-reply-to: content-transfer-encoding:mime-version; bh=34pzv9bKbIRYbM8UohCbu2P/noj3UrtXKxS4IZTsgKA=; b=HgPlFLhs09P9c7YUDpHx6OuZpp4RyAVhCDD7IP4ky0At9cQKmxBrj5+t p+HFEbSHoJbXDeI9jvUV2apSIHqpBSMAYeEyR+fCt6FKaoIIlhsuvoVL1 w9M1ZkaBKbTDu2TbCFrz4xtjSvq9EBGg92YSZDMR5/Ip4fl8KZvTMpvmd A=;
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-Anti-Spam-Result: AhoGACFre1OtJA2J/2dsb2JhbABQBgODBlFYqV4BAQEBAQeaLAGBGxZ0giUBAQEDAScTRAcEAgEIEQQBAQEKFBAhERsBAQUDAgQTCIglAwkIzQwNhi8XhVWDW4IQAXiBMwcDBwEfBhsXAgQLgxqBFQSMO4s5jyOFcYM4gW4CBxcGHA
X-IronPort-AV: E=Sophos;i="4.98,874,1392163200"; d="scan'208";a="45515164"
Received: from alln-core-4.cisco.com ([173.36.13.137]) by alln-iport-7.cisco.com with ESMTP; 20 May 2014 14:51:03 +0000
Received: from xhc-rcd-x11.cisco.com (xhc-rcd-x11.cisco.com [173.37.183.85]) by alln-core-4.cisco.com (8.14.5/8.14.5) with ESMTP id s4KEp3kO009768 (version=TLSv1/SSLv3 cipher=AES128-SHA bits=128 verify=FAIL) for <6tisch-security@ietf.org>; Tue, 20 May 2014 14:51:03 GMT
Received: from xmb-rcd-x14.cisco.com ([169.254.4.213]) by xhc-rcd-x11.cisco.com ([173.37.183.85]) with mapi id 14.03.0123.003; Tue, 20 May 2014 09:51:03 -0500
From: "Michael Behringer (mbehring)" <mbehring@cisco.com>
To: "6tisch-security@ietf.org" <6tisch-security@ietf.org>
Thread-Topic: [6tisch-security] a different explanation of autonomic bootstrap
Thread-Index: AQHPZwZfaGP8uBSgpUeEf+RqOCRlmpsyoHKAgAAP+4CAAA2zgIAABgKAgAAFyICAFt3RAA==
Date: Tue, 20 May 2014 14:51:03 +0000
Message-ID: <3AA7118E69D7CD4BA3ECD5716BAF28DF210A976C@xmb-rcd-x14.cisco.com>
References: <7591.1399145520@sandelman.ca> <07C02745-0562-4B95-828A-6B1DCDD390FA@cisco.com> <5367E18F.4080202@gmail.com> <D0C4F41B-D7E6-40C9-B1AB-0641BDEBD175@cisco.com> <5367F217.2020701@gmail.com> <B67EF6A7-3F5B-4F84-AF21-01F880DA2904@cisco.com>
In-Reply-To: <B67EF6A7-3F5B-4F84-AF21-01F880DA2904@cisco.com>
Accept-Language: en-GB, en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
x-originating-ip: [10.49.80.46]
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
Archived-At: http://mailarchive.ietf.org/arch/msg/6tisch-security/TEom-T9sKRwAVVqkuUM8uYcP4Bo
Subject: [6tisch-security] FW: a different explanation of autonomic bootstrap
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 20 May 2014 14:51:13 -0000

> -----Original Message-----
> From: Max Pritikin (pritikin)
> Sent: 05 May 2014 22:39
> To: Rene Struik
> Cc: Michael Richardson; Robert Moskowitz; Michael Behringer (mbehring);
> tisch-security
> Subject: Re: [6tisch-security] a different explanation of autonomic boots=
trap
>=20
>=20
>=20
>=20
>=20
> On May 5, 2014, at 2:18 PM, Rene Struik <rstruik.ext@gmail.com> wrote:
>=20
> > Hi Max:
> >
> > Perhaps, I am missing something here: in the picture, the network
> representative ("Domain") has a message exchange with the third party
> ("Factory Cloud Service"), which can be viewed as a subroutine inside the
> TLS protocol. During this subroutine, the server has to maintain state an=
d
> triggers lots of bandwidth consumption in the network, without having any
> cryptographic assurances on the new entity (it simply acts on a received
> string that seems to be an ar-certificate).
> >
> > It would help to have a more complete picture of the TLS handshake in t=
he
> ascii diagrams, including key confirmation messages ("finished" messages)=
.
> I could then try and describe cryptographic and other relevant properties
> and compare with other options.
>=20
> As shown below (in my simplified mental model diagram) the TLS
> handshake runs to completion (the Finished message etc) before any
> communication with the Cloud Service. Details aren't included but they're
> also just standard off-the-shelf TLS:
>=20
>=20
>  +---------+                +----------+                +-----------+
>  |  New    |                |          |                |  Factory  |
>  | Entity  |                |  Domain  |                |   Cloud   |
>  |         |                |          |                |  Service  |
>  +---------+                +----------+                +-----------+
>      |                           |                            |
>      |<-------discovery-(A)----->|                            |
>      |-----TLS ClientHello (B)-->|                            |
>      |                           |                            |
>      |<------ServerHello-(E)-----|                            |
>      |<----ServerCertificate-(H)-|                            |
>      |                           |                            |
> [validate cert chain? (I)]       |                            |
> [PROVISIONAL ACCEPT: Enter bootstrapping mode!]               |
>      |                           |                            |
>      |---ClientCertificate-(J)-->|                            |
>      |   (802.1AR cred)          |                            |
>      |                           |                            |
>   [TLS handshake is run to completion]   <------------------------------ =
TLS is
> established
>=20
> At this point there is a TLS session between the New Entity and the Domai=
n
> that is only *provisionally* authenticated. The Domain absolutely knows
> the identity of the new device (leveraging 802.1AR) but the New Entity is
> still waiting to see if this is the correct domain.
>=20
>      |                           |                            |
>      |---/BootstrapRequest------>|                            |
>=20
> This is an artifact of "domain enrollment" from below. Because I was an
> author of EST/RFC7030 I'm structuring this conversation around that proto=
col
> which is HTTPS based. Thus this expectation that the first data message i=
s
> initiated by the client.
>=20
>      |                           |                            |
>      |                           |---802.1AR identity(C)----->|
>      |                           |---Domain ID [nonce]------->|
>      |                           |                    [device belongs]
>      |                           |                    [to domain?    ]
>      |                           |                    [PREFERRED: JUST LO=
G, NO DECISIONS]
>      |                           |                            |
>      |                           |<---device history log(D)---|
>      |                    [ accept device? ]                  |
>      |                           |------- claim device -(F)-->|
>      |                           |                  [update audit log]
>      |                           |<----- authz token --(G)----|
>      |                           |      [SIGNED LOG ENTRY]    |
>      |                           |                            |
>      |                  [ still accept device?]               |
>=20
> This entire sequence occurs while the TLS connection is held open. You ar=
e
> correct that the server has to maintain the TLS session and HTTPS session
> during this. Notice though that the New Entity isn't involved in this
> exchange and only the Domain ID (and optionally a nonce) are sent to the
> server. Therefore in an environment where scalability is a greater concer=
n
> these operations can occur in advance (assuming the device IDs are known
> out-of-band, such as via bill-of-sale integration). There is a cost to th=
is
> scalability which is losing the nonce information but that choice is made=
 by
> the Domain and captured in the Cloud logs.
>=20
>=20
>      |                           |                            |
>      |<-[authz token]------------|                            |
>  [validate token using factory root cert]
>  [Join this domain?]             |                            |
>      |                           |                            |
>  [Initiate EST/RFC7030 on this TLS connection]                |
>      |----domain enrolment------>|                            |
>      |<----domain certificate----|                            |
>=20
> This portion then is the authz response (which may be nonce-less) and bas=
ic
> enrollment mechanism. Again shown here as being EST/RFC7030 HTTPS
> messages.
>=20
> - max
>=20
>=20
> >
> > Best regards, Rene
> >
> >
> >
> > On 5/5/2014 3:57 PM, Max Pritikin (pritikin) wrote:
> >> I understand the concern regarding "dangling state" but counter that t=
his:
> >> 	* is on the client that initiated the connection (no scaling issues)
> >> 	* consistent with the current TLS handshake (no extensions)
> >> 	* consistent with common TLS APIs (easy to develop using off the
> shelf components)
> >> 	* does not persist across connections (there is no need to maintain
> state that spans TLS sessions)
> >> 	* minimal integration/modification of the TLS handshake minimizes
> potential difficulties with TLSv3
> >>
> >> Since bootstrapping is a limited occurrence, and all state is on the c=
lient
> anyway, I'd lean in that direction over a more optimized handshake.
> >>
> >> - max
> >>
> >>
> >> On May 5, 2014, at 1:07 PM, Rene Struik <rstruik.ext@gmail.com> wrote:
> >>
> >>> Hi Max:
> >>>
> >>> Some comments below.
> >>>
> >>> Rene
> >>>
> >>> On 5/5/2014 2:10 PM, Max Pritikin (pritikin) wrote:
> >>> [snip]
> >>>> |<----domain certificate----| | In this fashion it is a
> "/BootstrapRequest" extension to RFC7030 Enrollment over Secure
> Transport. The basic message elements are all as you described but I've
> simply re-ordered them to better match the TLS and EST flows which
> minimizes the integration efforts.
> >>>>>   +---------+                +----------+                +---------=
--+
> >>>>>   |  New    |                |          |                |  Factory=
  |
> >>>>>   | Entity  |                |  Domain  |                |   Cloud =
  |
> >>>>>   |         |                |          |                |  Service=
  |
> >>>>>   +---------+                +----------+                +---------=
--+
> >>>>>       |                           |                            |
> >>>>>       |<-------discovery-(A)----->|                            |
> >>>>>       |-----TLS ClientHello (B)-->|                            |
> >>>>>       |     (802.1AR cred)        |                            |
> >>>>>       |                           |---802.1AR identity(C)----->|
> >>>>>       |                           |---Domain ID--------------->|
> >>>>>       |                           |                    [device belo=
ngs]
> >>>>>       |                           |                    [to domain? =
   ]
> >>>>>       |                           |                            |
> >>>>>       |                           |<---device history log(D)---|
> >>>>>       |                    [ accept device? ]                  |
> >>>>>       |<------ServerHello-(E)-----|                            |
> >>>>>       |                           |------- claim device -(F)-->|
> >>>>>       |                           |                  [update audit =
log]
> >>>>>       |                           |<----- authz token --(G)----|
> >>>>>       |                           |      (802.1AR cert)        |
> >>>>>       |                           |                            |
> >>>>>       |                  [ still accept device?]               |
> >>>>>       |<----ServerCertificate-(H)-|                            |
> >>>>>       |                           |                            |
> >>>>>  [validate cert chain? (I)]       |                            |
> >>>>>       |                           |                            |
> >>>>>       |---ClientCertificate-(J)-->|                            |
> >>>>>       |                           |                            |
> >>>>>       |                           |                            |
> >>>>>       |----domain enrolment------>|                            |
> >>>>>       |<----domain certificate----|                            |
> >>>>>
> >>>>>
> >>>>> A  Proxy Discovery (A)
> >>>>> B  TLS ClientHello
> >>>>>   This part has to include two things which are not exactly common
> TLS.
> >>>>>   1) it must have a TrustedAuthorities (6066) indicating what it's =
Factor
> CA
> >>>>>   2) it must include its IDevID somewhere, TBD.
> >>>> RFC6066 TrustedAuthority won't help here because Domain is unlikely
> to have a useful certificate issued by the Factory Cloud Service.
> >>>>
> >>>> Instead the New Entity would provisionally accept the TLS
> communications w/o being able to verify the Domain credential. It submits
> its IDevID in response (during 'J') but the entire session is still provi=
sional.
> >>>>
> >>> RS>>
> >>> It may be undesirable to have provisional sessions, if only because o=
f
> the amount of dangling state one has to keep and because of time-outs and
> nesting issues. Once some of the missing info that prevented proper
> authentication has been provided to the new entity and/or network
> representative, proper authenticated key agreement can be realized.
> >>> <<RS
> >>>
> >>> --
> >>> email: rstruik.ext@gmail.com | Skype: rstruik
> >>> cell: +1 (647) 867-5658 | US: +1 (415) 690-7363
> >>>
> >
> >
> > --
> > email: rstruik.ext@gmail.com | Skype: rstruik
> > cell: +1 (647) 867-5658 | US: +1 (415) 690-7363
> >


From nobody Tue May 20 08:45:19 2014
Return-Path: <pthubert@cisco.com>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id C9B7D1A0077 for <6tisch-security@ietfa.amsl.com>; Tue, 20 May 2014 08:38:22 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -15.151
X-Spam-Level: 
X-Spam-Status: No, score=-15.151 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_HI=-5, RP_MATCHES_RCVD=-0.651, SPF_PASS=-0.001, USER_IN_DEF_DKIM_WL=-7.5] autolearn=unavailable
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id npk2c3KvulPH for <6tisch-security@ietfa.amsl.com>; Tue, 20 May 2014 08:38:21 -0700 (PDT)
Received: from alln-iport-5.cisco.com (alln-iport-5.cisco.com [173.37.142.92]) (using TLSv1 with cipher RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id DD49B1A06FA for <6tisch-security@ietf.org>; Tue, 20 May 2014 08:38:14 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cisco.com; i=@cisco.com; l=55440; q=dns/txt; s=iport; t=1400600294; x=1401809894; h=from:to:subject:date:message-id:mime-version; bh=N3TVPaMh51vhX5Q5eCAxeCFlwr7Yor2fyN7o2KOxz4c=; b=i2UCJhY1H6kSGjU4D8QPRGV1l8BXr24bpHCD5R0JilolViJVlyQ+qMn/ meCFw2KuNQEyG7A9IVBf5K+SIo78vTsPirVA1G1lDuc2yem0//lejp92S s2ThtTnNFXao1euKy7EaG0C9DZlV+4svrS6yAqizb3dGKAQllinCWjcXZ Y=;
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-Anti-Spam-Result: AgwFAJt2e1OtJV2Q/2dsb2JhbAA/GoJCRFFYxBYBgRwWdIIlAQEBBC1FGQEaEBYBPxcPAQQbiDkNNp8UtAYTBItAAYI2BgEBHi2DNoEVBIlloyODOG2BAgEHFwYc
X-IronPort-AV: E=Sophos; i="4.98,874,1392163200"; d="scan'208,217"; a="45525195"
Received: from rcdn-core-8.cisco.com ([173.37.93.144]) by alln-iport-5.cisco.com with ESMTP; 20 May 2014 15:38:13 +0000
Received: from xhc-rcd-x10.cisco.com (xhc-rcd-x10.cisco.com [173.37.183.84]) by rcdn-core-8.cisco.com (8.14.5/8.14.5) with ESMTP id s4KFcCaH007865 (version=TLSv1/SSLv3 cipher=AES128-SHA bits=128 verify=FAIL) for <6tisch-security@ietf.org>; Tue, 20 May 2014 15:38:13 GMT
Received: from xmb-rcd-x01.cisco.com ([169.254.1.6]) by xhc-rcd-x10.cisco.com ([173.37.183.84]) with mapi id 14.03.0123.003; Tue, 20 May 2014 10:38:12 -0500
From: "Pascal Thubert (pthubert)" <pthubert@cisco.com>
To: "6tisch@ietf.org" <6tisch@ietf.org>
Thread-Topic: Minutes Webex 20th May 2014, 6TiSCH Security
Thread-Index: Ac90QWctUMvrSZJcSSy4AfdIpFS0yQ==
Date: Tue, 20 May 2014 15:38:12 +0000
Deferred-Delivery: Tue, 20 May 2014 15:38:00 +0000
Message-ID: <E045AECD98228444A58C61C200AE1BD84266FEED@xmb-rcd-x01.cisco.com>
Accept-Language: fr-FR, en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
x-originating-ip: [10.49.80.52]
Content-Type: multipart/alternative; boundary="_000_E045AECD98228444A58C61C200AE1BD84266FEEDxmbrcdx01ciscoc_"
MIME-Version: 1.0
Archived-At: http://mailarchive.ietf.org/arch/msg/6tisch-security/PkIqW1XL-Kg7orGXqvMiEuK7R-E
X-Mailman-Approved-At: Tue, 20 May 2014 08:45:14 -0700
Subject: [6tisch-security] Minutes Webex 20th May 2014, 6TiSCH Security
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 20 May 2014 15:38:23 -0000

--_000_E045AECD98228444A58C61C200AE1BD84266FEEDxmbrcdx01ciscoc_
Content-Type: text/plain; charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable

Minutes Webex 20th May 2014, 6TiSCH Security
________________________________
Taking notes (using Etherpad)
1.     Pascal Thubert
Present (alphabetically)
1.     Hank Mauldin
2.     Michael Behringer
3.     Michael Richardson
4.     Maik Seewald
5.     Ren=E9 Struik
6.     Tom Phinney
7.     Yoshihiro Ohba
Recording
=B7        Webex recording<https://cisco.webex.com/ciscosales/lsr.php?RCID=
=3Dcf234f58e8f94d2f86fbe15e7d6862df>
Agenda
1.     Look at Join Protocol
Action Items
1.     Michael R. to suggest to the list a review of draft piro
2.     Michael B. to check with Max Pritikin about format on authorization =
token.
Minutes
=B7        [07.10] Meeting starts

Michael Richardson: network manager programs the device, no particular auth=
orization of the network to the device, nor way for device to prove it is a=
uthorized apart from having the join key provisioned

Ren=E9 Struik: unless missing something, need size of configuration message=
s. How to get tag names in the device and map that into 802.15.4 MAC addres=
ses. Details we do not really have. Unclear how device can discover the net=
work. Ties in AR certificate issue

Michael Richardson: problem exists regardless of actual enrolment process.

Ren=E9 Struik: there is also a control element when certificate can be used

Michael Richardson: sent message on Wile coyote; is it realistic?

Ren=E9 Struik: quick feedback. say vendor generates cert for bunch of devic=
es and it goes along a chain and then more attributes allow link back to fa=
ctory. works, does not have to be AR certificate

Michael Richardson: I expected the kind of certificate I describe in AR but=
 it is not the point of AR. They do not even specify the format of device I=
D. AR is really about an API not about content of certificate apart from si=
gnature algorithm for which they have requirements. They do not even define=
 their own extensions. One extension with multiple values

Michael Richardson if you use secure enrolment, you can replace the cert bu=
t you still need to validate the device. Need Michael B. and Max to describ=
e their token

Michael Behringer: AR or not AR? process is about an institution that owns =
a device and has a secured relationship based on a certificate that tit sig=
ned. Can be 1AR or anything, e.g. an institution which owned the device bef=
ore. Need that cert from old organization to help bootstrap in new organiza=
tion.

Michael Richardson: did you define how the authorization token can be passe=
d in an interoperable fashion

Michael Behringer: leverage secure relationship between vendor and device t=
o pass a signed message to the device

Michael Richardson: does it bind to the new owner? which way, not subject t=
o standardization or is it?

Michael Behringer: May not need standard, but if multivendor network user w=
ould like a common format. between vendor and new device can be proprietary

Michael Richardson: need ot define when how the token is transported, and t=
hat is not end to end. reasons of trust, rate limit etc...

Michael Behringer: new device sends along a nonce and expect that nonce in =
response from vendor site; without nonce, token could come from the past. B=
oth models are required in the market. Some want fresh, others e.g. militar=
y there cannot be comm at the deployment time.

Michael Richardson: content of token may or not be standard. transport of t=
oken must be standard.

Michael Richardson: using RFC 3779 would address cert that had 1AR IdevID i=
n them. need a range in the certificate otherwise one certificate per devic=
e

Michael Behringer: token or certificate?

Michael Richardson if the token is a certificate need a way to delegate dow=
n the chain. But breach along the way breaches it all below. no good. Do yo=
u have to maintain a cert for every device?

Michael Behringer: that's the starting point. You assume that's a scalabili=
ty issue at some point right

Michael Richardson: provisioning trouble is possible. Tracking by bulk coul=
d be more palatable

Michael Behringer: if name space is aggregatable could work. In early appro=
ach, token is not a cert and stealing the token does not help.

Michael Richardson: anxious about spare parts that did not join, and go uns=
erviceable

Michael Behringer: yes, we can take the req in draft-pritikin

Michael Richardson proposing do something like RFC 3779. It as AS numbers t=
o allow reg to delegate using cert; these are live devIDs from a pool. shou=
ld look at that doc and we could change all AS to IdevID and we'd be done.

Michael Behringer: sounds like an idea we'll look at it

Michael Richardson: draft pritikin does not tell whether the enrolment allo=
w transport of authorization token back and forth and then the cert for the=
 TLS transport can be validated. Then you have a secure transport and can e=
nrol replacing the vendor cert with a domain cert.

Michael Behringer: refer to a mail by Max Pritikin "[6tisch-security] a dif=
ferent explanation of autonomic" .

Michael Richardson: where is the process ?

Michael Behringer: explained in message. We need to mail this down so peopl=
e understand.

Michael Richardson: non normative

Pascal Thubert: yes that is what we want in the security architecture

Michael Behringer I need to leave soon

Michael Richardson: I answered to draft piro descries low level stuff. I wa=
nt to encourage people to read and suggest that this becomes WG doc in L2 l=
ayer 2 security. It is a very good draft. We may need to change the authori=
zation but after that, great stuff can be found. Should be WG doc somewhere=
.

Ren=E9 Struik: thoughts appreciated on mail I sent today

Pascal: Next call on Tuesday next week same time
=B7        [08.06] meeting ends

=3D=3D=3D=3D=3D=3D


--_000_E045AECD98228444A58C61C200AE1BD84266FEEDxmbrcdx01ciscoc_
Content-Type: text/html; charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable

<html xmlns:v=3D"urn:schemas-microsoft-com:vml" xmlns:o=3D"urn:schemas-micr=
osoft-com:office:office" xmlns:w=3D"urn:schemas-microsoft-com:office:word" =
xmlns:m=3D"http://schemas.microsoft.com/office/2004/12/omml" xmlns=3D"http:=
//www.w3.org/TR/REC-html40">
<head>
<meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3Diso-8859-=
1">
<meta name=3D"Generator" content=3D"Microsoft Word 14 (filtered medium)">
<!--[if !mso]><style>v\:* {behavior:url(#default#VML);}
o\:* {behavior:url(#default#VML);}
w\:* {behavior:url(#default#VML);}
.shape {behavior:url(#default#VML);}
</style><![endif]--><style><!--
/* Font Definitions */
@font-face
	{font-family:Wingdings;
	panose-1:5 0 0 0 0 0 0 0 0 0;}
@font-face
	{font-family:Wingdings;
	panose-1:5 0 0 0 0 0 0 0 0 0;}
@font-face
	{font-family:Calibri;
	panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
	{font-family:Tahoma;
	panose-1:2 11 6 4 3 5 4 4 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
	{margin:0cm;
	margin-bottom:.0001pt;
	font-size:11.0pt;
	font-family:"Calibri","sans-serif";}
h1
	{mso-style-priority:9;
	mso-style-link:"Heading 1 Char";
	mso-margin-top-alt:auto;
	margin-right:0cm;
	mso-margin-bottom-alt:auto;
	margin-left:0cm;
	font-size:24.0pt;
	font-family:"Times New Roman","serif";
	font-weight:bold;}
h2
	{mso-style-priority:9;
	mso-style-link:"Heading 2 Char";
	mso-margin-top-alt:auto;
	margin-right:0cm;
	mso-margin-bottom-alt:auto;
	margin-left:0cm;
	font-size:18.0pt;
	font-family:"Times New Roman","serif";
	font-weight:bold;}
a:link, span.MsoHyperlink
	{mso-style-priority:99;
	color:blue;
	text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
	{mso-style-priority:99;
	color:purple;
	text-decoration:underline;}
p
	{mso-style-priority:99;
	mso-margin-top-alt:auto;
	margin-right:0cm;
	mso-margin-bottom-alt:auto;
	margin-left:0cm;
	font-size:12.0pt;
	font-family:"Times New Roman","serif";}
p.MsoAcetate, li.MsoAcetate, div.MsoAcetate
	{mso-style-priority:99;
	mso-style-link:"Balloon Text Char";
	margin:0cm;
	margin-bottom:.0001pt;
	font-size:8.0pt;
	font-family:"Tahoma","sans-serif";}
span.EmailStyle17
	{mso-style-type:personal-compose;
	font-family:"Calibri","sans-serif";
	color:windowtext;}
span.BalloonTextChar
	{mso-style-name:"Balloon Text Char";
	mso-style-priority:99;
	mso-style-link:"Balloon Text";
	font-family:"Tahoma","sans-serif";}
span.Heading1Char
	{mso-style-name:"Heading 1 Char";
	mso-style-priority:9;
	mso-style-link:"Heading 1";
	font-family:"Times New Roman","serif";
	font-weight:bold;}
span.Heading2Char
	{mso-style-name:"Heading 2 Char";
	mso-style-priority:9;
	mso-style-link:"Heading 2";
	font-family:"Times New Roman","serif";
	font-weight:bold;}
span.apple-converted-space
	{mso-style-name:apple-converted-space;}
.MsoChpDefault
	{mso-style-type:export-only;
	font-family:"Calibri","sans-serif";}
@page WordSection1
	{size:612.0pt 792.0pt;
	margin:70.85pt 70.85pt 70.85pt 70.85pt;}
div.WordSection1
	{page:WordSection1;}
/* List Definitions */
@list l0
	{mso-list-id:15347732;
	mso-list-template-ids:1149267428;}
@list l1
	{mso-list-id:298346911;
	mso-list-template-ids:-1990059266;}
@list l2
	{mso-list-id:410661324;
	mso-list-template-ids:862720772;}
@list l3
	{mso-list-id:419913662;
	mso-list-template-ids:1939343024;}
@list l4
	{mso-list-id:755715481;
	mso-list-template-ids:1539483424;}
@list l4:level1
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:36.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l4:level2
	{mso-level-number-format:bullet;
	mso-level-text:o;
	mso-level-tab-stop:72.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:"Courier New";
	mso-bidi-font-family:"Times New Roman";}
@list l4:level3
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:108.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l4:level4
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:144.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l4:level5
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:180.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l4:level6
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:216.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l4:level7
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:252.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l4:level8
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:288.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l4:level9
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:324.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l5
	{mso-list-id:795804602;
	mso-list-template-ids:1885534928;}
@list l5:level1
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:36.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l5:level2
	{mso-level-number-format:bullet;
	mso-level-text:o;
	mso-level-tab-stop:72.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:"Courier New";
	mso-bidi-font-family:"Times New Roman";}
@list l5:level3
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:108.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l5:level4
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:144.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l5:level5
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:180.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l5:level6
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:216.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l5:level7
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:252.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l5:level8
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:288.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l5:level9
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:324.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l6
	{mso-list-id:1308902986;
	mso-list-template-ids:1846212050;}
@list l7
	{mso-list-id:1514879373;
	mso-list-template-ids:585418842;}
@list l7:level1
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:36.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l7:level2
	{mso-level-number-format:bullet;
	mso-level-text:o;
	mso-level-tab-stop:72.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:"Courier New";
	mso-bidi-font-family:"Times New Roman";}
@list l7:level3
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:108.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l7:level4
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:144.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l7:level5
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:180.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l7:level6
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:216.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l7:level7
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:252.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l7:level8
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:288.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l7:level9
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:324.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l8
	{mso-list-id:1735615244;
	mso-list-template-ids:612942284;}
@list l9
	{mso-list-id:1863981381;
	mso-list-template-ids:709014192;}
@list l10
	{mso-list-id:1916742795;
	mso-list-template-ids:798656480;}
@list l10:level1
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:36.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l10:level2
	{mso-level-number-format:bullet;
	mso-level-text:o;
	mso-level-tab-stop:72.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:"Courier New";
	mso-bidi-font-family:"Times New Roman";}
@list l10:level3
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:108.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l10:level4
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:144.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l10:level5
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:180.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l10:level6
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:216.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l10:level7
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:252.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l10:level8
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:288.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l10:level9
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:324.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l11
	{mso-list-id:2016230055;
	mso-list-template-ids:-1235608234;}
@list l11:level1
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:36.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l11:level2
	{mso-level-number-format:bullet;
	mso-level-text:o;
	mso-level-tab-stop:72.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:"Courier New";
	mso-bidi-font-family:"Times New Roman";}
@list l11:level3
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:108.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l11:level4
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:144.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l11:level5
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:180.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l11:level6
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:216.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l11:level7
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:252.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l11:level8
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:288.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l11:level9
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:324.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l12
	{mso-list-id:2076000766;
	mso-list-template-ids:-758356318;}
@list l12:level1
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:36.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l12:level2
	{mso-level-number-format:bullet;
	mso-level-text:o;
	mso-level-tab-stop:72.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:"Courier New";
	mso-bidi-font-family:"Times New Roman";}
@list l12:level3
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:108.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l12:level4
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:144.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l12:level5
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:180.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l12:level6
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:216.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l12:level7
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:252.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l12:level8
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:288.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l12:level9
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:324.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
ol
	{margin-bottom:0cm;}
ul
	{margin-bottom:0cm;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext=3D"edit" spidmax=3D"1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext=3D"edit">
<o:idmap v:ext=3D"edit" data=3D"1" />
</o:shapelayout></xml><![endif]-->
</head>
<body lang=3D"EN-US" link=3D"blue" vlink=3D"purple">
<div class=3D"WordSection1">
<h1 style=3D"mso-margin-top-alt:0cm;margin-right:0cm;margin-bottom:7.5pt;ma=
rgin-left:0cm;background:white">
<span style=3D"font-size:18.0pt;font-family:&quot;Arial&quot;,&quot;sans-se=
rif&quot;;color:#333333;font-weight:normal">Minutes Webex 20th May 2014, 6T=
iSCH Security<o:p></o:p></span></h1>
<div class=3D"MsoNormal" align=3D"center" style=3D"mso-margin-top-alt:15.0p=
t;margin-right:0cm;margin-bottom:15.0pt;margin-left:0cm;text-align:center">
<hr size=3D"3" width=3D"100%" noshade=3D"" style=3D"color:#333333" align=3D=
"center">
</div>
<h2 style=3D"mso-margin-top-alt:15.0pt;margin-right:0cm;margin-bottom:0cm;m=
argin-left:0cm;margin-bottom:.0001pt;background:white;orphans: auto;text-al=
ign:start;widows: auto;-webkit-text-stroke-width: 0px;word-spacing:0px" id=
=3D"markdown-header-taking-notes-using-etherpad">
<span style=3D"font-size:15.0pt;font-family:&quot;Arial&quot;,&quot;sans-se=
rif&quot;;color:#333333;font-weight:normal">Taking notes<span class=3D"appl=
e-converted-space">&nbsp;</span><em><span style=3D"font-family:&quot;Arial&=
quot;,&quot;sans-serif&quot;">(using Etherpad)</span></em><o:p></o:p></span=
></h2>
<p class=3D"MsoNormal" style=3D"mso-margin-top-alt:auto;mso-margin-bottom-a=
lt:auto;margin-left:0cm;text-indent:-18.0pt;line-height:15.0pt;mso-list:l1 =
level1 lfo7;background:white">
<![if !supportLists]><span style=3D"font-size:10.5pt;font-family:&quot;Aria=
l&quot;,&quot;sans-serif&quot;;color:#333333"><span style=3D"mso-list:Ignor=
e">1.<span style=3D"font:7.0pt &quot;Times New Roman&quot;">&nbsp;&nbsp;&nb=
sp;&nbsp;
</span></span></span><![endif]><span style=3D"font-size:10.5pt;font-family:=
&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">Pascal Thubert<o:p>=
</o:p></span></p>
<h2 style=3D"mso-margin-top-alt:15.0pt;margin-right:0cm;margin-bottom:0cm;m=
argin-left:0cm;margin-bottom:.0001pt;background:white;orphans: auto;text-al=
ign:start;widows: auto;-webkit-text-stroke-width: 0px;word-spacing:0px" id=
=3D"markdown-header-present-alphabetically">
<span style=3D"font-size:15.0pt;font-family:&quot;Arial&quot;,&quot;sans-se=
rif&quot;;color:#333333;font-weight:normal">Present<span class=3D"apple-con=
verted-space">&nbsp;</span><em><span style=3D"font-family:&quot;Arial&quot;=
,&quot;sans-serif&quot;">(alphabetically)</span></em><o:p></o:p></span></h2=
>
<p class=3D"MsoNormal" style=3D"mso-margin-top-alt:auto;mso-margin-bottom-a=
lt:auto;margin-left:0cm;text-indent:-18.0pt;line-height:15.0pt;mso-list:l0 =
level1 lfo8;background:white">
<![if !supportLists]><span style=3D"font-size:10.5pt;font-family:&quot;Aria=
l&quot;,&quot;sans-serif&quot;;color:#333333"><span style=3D"mso-list:Ignor=
e">1.<span style=3D"font:7.0pt &quot;Times New Roman&quot;">&nbsp;&nbsp;&nb=
sp;&nbsp;
</span></span></span><![endif]><span style=3D"font-size:10.5pt;font-family:=
&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">Hank Mauldin<o:p></=
o:p></span></p>
<p class=3D"MsoNormal" style=3D"mso-margin-top-alt:auto;mso-margin-bottom-a=
lt:auto;margin-left:0cm;text-indent:-18.0pt;line-height:15.0pt;mso-list:l0 =
level1 lfo8;background:white">
<![if !supportLists]><span style=3D"font-size:10.5pt;font-family:&quot;Aria=
l&quot;,&quot;sans-serif&quot;;color:#333333"><span style=3D"mso-list:Ignor=
e">2.<span style=3D"font:7.0pt &quot;Times New Roman&quot;">&nbsp;&nbsp;&nb=
sp;&nbsp;
</span></span></span><![endif]><span style=3D"font-size:10.5pt;font-family:=
&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">Michael Behringer<o=
:p></o:p></span></p>
<p class=3D"MsoNormal" style=3D"mso-margin-top-alt:auto;mso-margin-bottom-a=
lt:auto;margin-left:0cm;text-indent:-18.0pt;line-height:15.0pt;mso-list:l0 =
level1 lfo8;background:white">
<![if !supportLists]><span style=3D"font-size:10.5pt;font-family:&quot;Aria=
l&quot;,&quot;sans-serif&quot;;color:#333333"><span style=3D"mso-list:Ignor=
e">3.<span style=3D"font:7.0pt &quot;Times New Roman&quot;">&nbsp;&nbsp;&nb=
sp;&nbsp;
</span></span></span><![endif]><span style=3D"font-size:10.5pt;font-family:=
&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">Michael Richardson<=
o:p></o:p></span></p>
<p class=3D"MsoNormal" style=3D"mso-margin-top-alt:auto;mso-margin-bottom-a=
lt:auto;margin-left:0cm;text-indent:-18.0pt;line-height:15.0pt;mso-list:l0 =
level1 lfo8;background:white">
<![if !supportLists]><span style=3D"font-size:10.5pt;font-family:&quot;Aria=
l&quot;,&quot;sans-serif&quot;;color:#333333"><span style=3D"mso-list:Ignor=
e">4.<span style=3D"font:7.0pt &quot;Times New Roman&quot;">&nbsp;&nbsp;&nb=
sp;&nbsp;
</span></span></span><![endif]><span style=3D"font-size:10.5pt;font-family:=
&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">Maik Seewald<o:p></=
o:p></span></p>
<p class=3D"MsoNormal" style=3D"mso-margin-top-alt:auto;mso-margin-bottom-a=
lt:auto;margin-left:0cm;text-indent:-18.0pt;line-height:15.0pt;mso-list:l0 =
level1 lfo8;background:white">
<![if !supportLists]><span style=3D"font-size:10.5pt;font-family:&quot;Aria=
l&quot;,&quot;sans-serif&quot;;color:#333333"><span style=3D"mso-list:Ignor=
e">5.<span style=3D"font:7.0pt &quot;Times New Roman&quot;">&nbsp;&nbsp;&nb=
sp;&nbsp;
</span></span></span><![endif]><span style=3D"font-size:10.5pt;font-family:=
&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">Ren=E9 Struik<o:p><=
/o:p></span></p>
<p class=3D"MsoNormal" style=3D"mso-margin-top-alt:auto;mso-margin-bottom-a=
lt:auto;margin-left:0cm;text-indent:-18.0pt;line-height:15.0pt;mso-list:l0 =
level1 lfo8;background:white">
<![if !supportLists]><span style=3D"font-size:10.5pt;font-family:&quot;Aria=
l&quot;,&quot;sans-serif&quot;;color:#333333"><span style=3D"mso-list:Ignor=
e">6.<span style=3D"font:7.0pt &quot;Times New Roman&quot;">&nbsp;&nbsp;&nb=
sp;&nbsp;
</span></span></span><![endif]><span style=3D"font-size:10.5pt;font-family:=
&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">Tom Phinney<o:p></o=
:p></span></p>
<p class=3D"MsoNormal" style=3D"mso-margin-top-alt:auto;mso-margin-bottom-a=
lt:auto;margin-left:0cm;text-indent:-18.0pt;line-height:15.0pt;mso-list:l0 =
level1 lfo8;background:white">
<![if !supportLists]><span style=3D"font-size:10.5pt;font-family:&quot;Aria=
l&quot;,&quot;sans-serif&quot;;color:#333333"><span style=3D"mso-list:Ignor=
e">7.<span style=3D"font:7.0pt &quot;Times New Roman&quot;">&nbsp;&nbsp;&nb=
sp;&nbsp;
</span></span></span><![endif]><span style=3D"font-size:10.5pt;font-family:=
&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">Yoshihiro Ohba<o:p>=
</o:p></span></p>
<h2 style=3D"mso-margin-top-alt:15.0pt;margin-right:0cm;margin-bottom:0cm;m=
argin-left:0cm;margin-bottom:.0001pt;background:white;orphans: auto;text-al=
ign:start;widows: auto;-webkit-text-stroke-width: 0px;word-spacing:0px" id=
=3D"markdown-header-recording">
<span style=3D"font-size:15.0pt;font-family:&quot;Arial&quot;,&quot;sans-se=
rif&quot;;color:#333333;font-weight:normal">Recording<o:p></o:p></span></h2=
>
<p class=3D"MsoNormal" style=3D"mso-margin-top-alt:auto;mso-margin-bottom-a=
lt:auto;margin-left:0cm;text-indent:-18.0pt;line-height:15.0pt;mso-list:l5 =
level1 lfo9;background:white">
<![if !supportLists]><span style=3D"font-size:10.0pt;font-family:Symbol;col=
or:#333333"><span style=3D"mso-list:Ignore">=B7<span style=3D"font:7.0pt &q=
uot;Times New Roman&quot;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
</span></span></span><![endif]><span style=3D"font-size:10.5pt;font-family:=
&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333"><a href=3D"https://=
cisco.webex.com/ciscosales/lsr.php?RCID=3Dcf234f58e8f94d2f86fbe15e7d6862df"=
><span style=3D"color:#3B73AF">Webex recording</span></a><o:p></o:p></span>=
</p>
<h2 style=3D"mso-margin-top-alt:15.0pt;margin-right:0cm;margin-bottom:0cm;m=
argin-left:0cm;margin-bottom:.0001pt;background:white;orphans: auto;text-al=
ign:start;widows: auto;-webkit-text-stroke-width: 0px;word-spacing:0px" id=
=3D"markdown-header-agenda">
<span style=3D"font-size:15.0pt;font-family:&quot;Arial&quot;,&quot;sans-se=
rif&quot;;color:#333333;font-weight:normal">Agenda<o:p></o:p></span></h2>
<p class=3D"MsoNormal" style=3D"mso-margin-top-alt:auto;mso-margin-bottom-a=
lt:auto;margin-left:0cm;text-indent:-18.0pt;line-height:15.0pt;mso-list:l6 =
level1 lfo10;background:white">
<![if !supportLists]><span style=3D"font-size:10.5pt;font-family:&quot;Aria=
l&quot;,&quot;sans-serif&quot;;color:#333333"><span style=3D"mso-list:Ignor=
e">1.<span style=3D"font:7.0pt &quot;Times New Roman&quot;">&nbsp;&nbsp;&nb=
sp;&nbsp;
</span></span></span><![endif]><span style=3D"font-size:10.5pt;font-family:=
&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">Look at Join Protoc=
ol<o:p></o:p></span></p>
<h2 style=3D"mso-margin-top-alt:15.0pt;margin-right:0cm;margin-bottom:0cm;m=
argin-left:0cm;margin-bottom:.0001pt;background:white;orphans: auto;text-al=
ign:start;widows: auto;-webkit-text-stroke-width: 0px;word-spacing:0px" id=
=3D"markdown-header-action-items">
<span style=3D"font-size:15.0pt;font-family:&quot;Arial&quot;,&quot;sans-se=
rif&quot;;color:#333333;font-weight:normal">Action Items<o:p></o:p></span><=
/h2>
<p class=3D"MsoNormal" style=3D"mso-margin-top-alt:auto;mso-margin-bottom-a=
lt:auto;margin-left:0cm;text-indent:-18.0pt;line-height:15.0pt;mso-list:l2 =
level1 lfo11;background:white">
<![if !supportLists]><span style=3D"font-size:10.5pt;font-family:&quot;Aria=
l&quot;,&quot;sans-serif&quot;;color:#333333"><span style=3D"mso-list:Ignor=
e">1.<span style=3D"font:7.0pt &quot;Times New Roman&quot;">&nbsp;&nbsp;&nb=
sp;&nbsp;
</span></span></span><![endif]><span style=3D"font-size:10.5pt;font-family:=
&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">Michael R. to sugge=
st to the list a review of draft piro<o:p></o:p></span></p>
<p class=3D"MsoNormal" style=3D"mso-margin-top-alt:auto;mso-margin-bottom-a=
lt:auto;margin-left:0cm;text-indent:-18.0pt;line-height:15.0pt;mso-list:l2 =
level1 lfo11;background:white">
<![if !supportLists]><span style=3D"font-size:10.5pt;font-family:&quot;Aria=
l&quot;,&quot;sans-serif&quot;;color:#333333"><span style=3D"mso-list:Ignor=
e">2.<span style=3D"font:7.0pt &quot;Times New Roman&quot;">&nbsp;&nbsp;&nb=
sp;&nbsp;
</span></span></span><![endif]><span style=3D"font-size:10.5pt;font-family:=
&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">Michael B. to check=
 with Max Pritikin about format on authorization token.<o:p></o:p></span></=
p>
<h2 style=3D"mso-margin-top-alt:15.0pt;margin-right:0cm;margin-bottom:0cm;m=
argin-left:0cm;margin-bottom:.0001pt;background:white;orphans: auto;text-al=
ign:start;widows: auto;-webkit-text-stroke-width: 0px;word-spacing:0px" id=
=3D"markdown-header-minutes">
<span style=3D"font-size:15.0pt;font-family:&quot;Arial&quot;,&quot;sans-se=
rif&quot;;color:#333333;font-weight:normal">Minutes<o:p></o:p></span></h2>
<p class=3D"MsoNormal" style=3D"mso-margin-top-alt:auto;mso-margin-bottom-a=
lt:auto;margin-left:0cm;text-indent:-18.0pt;line-height:15.0pt;mso-list:l11=
 level1 lfo12;background:white">
<![if !supportLists]><span style=3D"font-size:10.0pt;font-family:Symbol;col=
or:#333333"><span style=3D"mso-list:Ignore">=B7<span style=3D"font:7.0pt &q=
uot;Times New Roman&quot;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
</span></span></span><![endif]><em><span style=3D"font-size:10.5pt;font-fam=
ily:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">[07.10]</span><=
/em><span class=3D"apple-converted-space"><span style=3D"font-size:10.5pt;f=
ont-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">&nbsp;</=
span></span><span style=3D"font-size:10.5pt;font-family:&quot;Arial&quot;,&=
quot;sans-serif&quot;;color:#333333">Meeting
 starts<o:p></o:p></span></p>
<p style=3D"mso-margin-top-alt:7.5pt;margin-right:0cm;margin-bottom:0cm;mar=
gin-left:0cm;margin-bottom:.0001pt;line-height:15.0pt;background:white;word=
-wrap: break-word;orphans: auto;text-align:start;widows: auto;-webkit-text-=
stroke-width: 0px;word-spacing:0px">
<span style=3D"font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-se=
rif&quot;;color:#333333">Michael Richardson: network manager programs the d=
evice, no particular authorization of the network to the device, nor way fo=
r device to prove it is authorized apart from having the
 join key provisioned<o:p></o:p></span></p>
<p style=3D"mso-margin-top-alt:7.5pt;margin-right:0cm;margin-bottom:0cm;mar=
gin-left:0cm;margin-bottom:.0001pt;line-height:15.0pt;background:white;word=
-wrap: break-word;orphans: auto;text-align:start;widows: auto;-webkit-text-=
stroke-width: 0px;word-spacing:0px">
<span style=3D"font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-se=
rif&quot;;color:#333333">Ren=E9 Struik: unless missing something, need size=
 of configuration messages. How to get tag names in the device and map that=
 into 802.15.4 MAC addresses. Details we do not really have.
 Unclear how device can discover the network. Ties in AR certificate issue<=
o:p></o:p></span></p>
<p style=3D"mso-margin-top-alt:7.5pt;margin-right:0cm;margin-bottom:0cm;mar=
gin-left:0cm;margin-bottom:.0001pt;line-height:15.0pt;background:white;word=
-wrap: break-word;orphans: auto;text-align:start;widows: auto;-webkit-text-=
stroke-width: 0px;word-spacing:0px">
<span style=3D"font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-se=
rif&quot;;color:#333333">Michael Richardson: problem exists regardless of a=
ctual enrolment process.<o:p></o:p></span></p>
<p style=3D"mso-margin-top-alt:7.5pt;margin-right:0cm;margin-bottom:0cm;mar=
gin-left:0cm;margin-bottom:.0001pt;line-height:15.0pt;background:white;word=
-wrap: break-word;orphans: auto;text-align:start;widows: auto;-webkit-text-=
stroke-width: 0px;word-spacing:0px">
<span style=3D"font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-se=
rif&quot;;color:#333333">Ren=E9 Struik: there is also a control element whe=
n certificate can be used<o:p></o:p></span></p>
<p style=3D"mso-margin-top-alt:7.5pt;margin-right:0cm;margin-bottom:0cm;mar=
gin-left:0cm;margin-bottom:.0001pt;line-height:15.0pt;background:white;word=
-wrap: break-word;orphans: auto;text-align:start;widows: auto;-webkit-text-=
stroke-width: 0px;word-spacing:0px">
<span style=3D"font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-se=
rif&quot;;color:#333333">Michael Richardson: sent message on Wile coyote; i=
s it realistic?<o:p></o:p></span></p>
<p style=3D"mso-margin-top-alt:7.5pt;margin-right:0cm;margin-bottom:0cm;mar=
gin-left:0cm;margin-bottom:.0001pt;line-height:15.0pt;background:white;word=
-wrap: break-word;orphans: auto;text-align:start;widows: auto;-webkit-text-=
stroke-width: 0px;word-spacing:0px">
<span style=3D"font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-se=
rif&quot;;color:#333333">Ren=E9 Struik: quick feedback. say vendor generate=
s cert for bunch of devices and it goes along a chain and then more attribu=
tes allow link back to factory. works, does not have to
 be AR certificate<o:p></o:p></span></p>
<p style=3D"mso-margin-top-alt:7.5pt;margin-right:0cm;margin-bottom:0cm;mar=
gin-left:0cm;margin-bottom:.0001pt;line-height:15.0pt;background:white;word=
-wrap: break-word;orphans: auto;text-align:start;widows: auto;-webkit-text-=
stroke-width: 0px;word-spacing:0px">
<span style=3D"font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-se=
rif&quot;;color:#333333">Michael Richardson: I expected the kind of certifi=
cate I describe in AR but it is not the point of AR. They do not even speci=
fy the format of device ID. AR is really about an API
 not about content of certificate apart from signature algorithm for which =
they have requirements. They do not even define their own extensions. One e=
xtension with multiple values<o:p></o:p></span></p>
<p style=3D"mso-margin-top-alt:7.5pt;margin-right:0cm;margin-bottom:0cm;mar=
gin-left:0cm;margin-bottom:.0001pt;line-height:15.0pt;background:white;word=
-wrap: break-word;orphans: auto;text-align:start;widows: auto;-webkit-text-=
stroke-width: 0px;word-spacing:0px">
<span style=3D"font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-se=
rif&quot;;color:#333333">Michael Richardson if you use secure enrolment, yo=
u can replace the cert but you still need to validate the device. Need Mich=
ael B. and Max to describe their token<o:p></o:p></span></p>
<p style=3D"mso-margin-top-alt:7.5pt;margin-right:0cm;margin-bottom:0cm;mar=
gin-left:0cm;margin-bottom:.0001pt;line-height:15.0pt;background:white;word=
-wrap: break-word;orphans: auto;text-align:start;widows: auto;-webkit-text-=
stroke-width: 0px;word-spacing:0px">
<span style=3D"font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-se=
rif&quot;;color:#333333">Michael Behringer: AR or not AR? process is about =
an institution that owns a device and has a secured relationship based on a=
 certificate that tit signed. Can be 1AR or anything,
 e.g. an institution which owned the device before. Need that cert from old=
 organization to help bootstrap in new organization.<o:p></o:p></span></p>
<p style=3D"mso-margin-top-alt:7.5pt;margin-right:0cm;margin-bottom:0cm;mar=
gin-left:0cm;margin-bottom:.0001pt;line-height:15.0pt;background:white;word=
-wrap: break-word;orphans: auto;text-align:start;widows: auto;-webkit-text-=
stroke-width: 0px;word-spacing:0px">
<span style=3D"font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-se=
rif&quot;;color:#333333">Michael Richardson: did you define how the authori=
zation token can be passed in an interoperable fashion<o:p></o:p></span></p=
>
<p style=3D"mso-margin-top-alt:7.5pt;margin-right:0cm;margin-bottom:0cm;mar=
gin-left:0cm;margin-bottom:.0001pt;line-height:15.0pt;background:white;word=
-wrap: break-word;orphans: auto;text-align:start;widows: auto;-webkit-text-=
stroke-width: 0px;word-spacing:0px">
<span style=3D"font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-se=
rif&quot;;color:#333333">Michael Behringer: leverage secure relationship be=
tween vendor and device to pass a signed message to the device<o:p></o:p></=
span></p>
<p style=3D"mso-margin-top-alt:7.5pt;margin-right:0cm;margin-bottom:0cm;mar=
gin-left:0cm;margin-bottom:.0001pt;line-height:15.0pt;background:white;word=
-wrap: break-word;orphans: auto;text-align:start;widows: auto;-webkit-text-=
stroke-width: 0px;word-spacing:0px">
<span style=3D"font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-se=
rif&quot;;color:#333333">Michael Richardson: does it bind to the new owner?=
 which way, not subject to standardization or is it?<o:p></o:p></span></p>
<p style=3D"mso-margin-top-alt:7.5pt;margin-right:0cm;margin-bottom:0cm;mar=
gin-left:0cm;margin-bottom:.0001pt;line-height:15.0pt;background:white;word=
-wrap: break-word;orphans: auto;text-align:start;widows: auto;-webkit-text-=
stroke-width: 0px;word-spacing:0px">
<span style=3D"font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-se=
rif&quot;;color:#333333">Michael Behringer: May not need standard, but if m=
ultivendor network user would like a common format. between vendor and new =
device can be proprietary<o:p></o:p></span></p>
<p style=3D"mso-margin-top-alt:7.5pt;margin-right:0cm;margin-bottom:0cm;mar=
gin-left:0cm;margin-bottom:.0001pt;line-height:15.0pt;background:white;word=
-wrap: break-word;orphans: auto;text-align:start;widows: auto;-webkit-text-=
stroke-width: 0px;word-spacing:0px">
<span style=3D"font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-se=
rif&quot;;color:#333333">Michael Richardson: need ot define when how the to=
ken is transported, and that is not end to end. reasons of trust, rate limi=
t etc...<o:p></o:p></span></p>
<p style=3D"mso-margin-top-alt:7.5pt;margin-right:0cm;margin-bottom:0cm;mar=
gin-left:0cm;margin-bottom:.0001pt;line-height:15.0pt;background:white;word=
-wrap: break-word;orphans: auto;text-align:start;widows: auto;-webkit-text-=
stroke-width: 0px;word-spacing:0px">
<span style=3D"font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-se=
rif&quot;;color:#333333">Michael Behringer: new device sends along a nonce =
and expect that nonce in response from vendor site; without nonce, token co=
uld come from the past. Both models are required in the
 market. Some want fresh, others e.g. military there cannot be comm at the =
deployment time.<o:p></o:p></span></p>
<p style=3D"mso-margin-top-alt:7.5pt;margin-right:0cm;margin-bottom:0cm;mar=
gin-left:0cm;margin-bottom:.0001pt;line-height:15.0pt;background:white;word=
-wrap: break-word;orphans: auto;text-align:start;widows: auto;-webkit-text-=
stroke-width: 0px;word-spacing:0px">
<span style=3D"font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-se=
rif&quot;;color:#333333">Michael Richardson: content of token may or not be=
 standard. transport of token must be standard.<o:p></o:p></span></p>
<p style=3D"mso-margin-top-alt:7.5pt;margin-right:0cm;margin-bottom:0cm;mar=
gin-left:0cm;margin-bottom:.0001pt;line-height:15.0pt;background:white;word=
-wrap: break-word;orphans: auto;text-align:start;widows: auto;-webkit-text-=
stroke-width: 0px;word-spacing:0px">
<span style=3D"font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-se=
rif&quot;;color:#333333">Michael Richardson: using RFC 3779 would address c=
ert that had 1AR IdevID in them. need a range in the certificate otherwise =
one certificate per device<o:p></o:p></span></p>
<p style=3D"mso-margin-top-alt:7.5pt;margin-right:0cm;margin-bottom:0cm;mar=
gin-left:0cm;margin-bottom:.0001pt;line-height:15.0pt;background:white;word=
-wrap: break-word;orphans: auto;text-align:start;widows: auto;-webkit-text-=
stroke-width: 0px;word-spacing:0px">
<span style=3D"font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-se=
rif&quot;;color:#333333">Michael Behringer: token or certificate?<o:p></o:p=
></span></p>
<p style=3D"mso-margin-top-alt:7.5pt;margin-right:0cm;margin-bottom:0cm;mar=
gin-left:0cm;margin-bottom:.0001pt;line-height:15.0pt;background:white;word=
-wrap: break-word;orphans: auto;text-align:start;widows: auto;-webkit-text-=
stroke-width: 0px;word-spacing:0px">
<span style=3D"font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-se=
rif&quot;;color:#333333">Michael Richardson if the token is a certificate n=
eed a way to delegate down the chain. But breach along the way breaches it =
all below. no good. Do you have to maintain a cert for
 every device?<o:p></o:p></span></p>
<p style=3D"mso-margin-top-alt:7.5pt;margin-right:0cm;margin-bottom:0cm;mar=
gin-left:0cm;margin-bottom:.0001pt;line-height:15.0pt;background:white;word=
-wrap: break-word;orphans: auto;text-align:start;widows: auto;-webkit-text-=
stroke-width: 0px;word-spacing:0px">
<span style=3D"font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-se=
rif&quot;;color:#333333">Michael Behringer: that's the starting point. You =
assume that's a scalability issue at some point right<o:p></o:p></span></p>
<p style=3D"mso-margin-top-alt:7.5pt;margin-right:0cm;margin-bottom:0cm;mar=
gin-left:0cm;margin-bottom:.0001pt;line-height:15.0pt;background:white;word=
-wrap: break-word;orphans: auto;text-align:start;widows: auto;-webkit-text-=
stroke-width: 0px;word-spacing:0px">
<span style=3D"font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-se=
rif&quot;;color:#333333">Michael Richardson: provisioning trouble is possib=
le. Tracking by bulk could be more palatable<o:p></o:p></span></p>
<p style=3D"mso-margin-top-alt:7.5pt;margin-right:0cm;margin-bottom:0cm;mar=
gin-left:0cm;margin-bottom:.0001pt;line-height:15.0pt;background:white;word=
-wrap: break-word;orphans: auto;text-align:start;widows: auto;-webkit-text-=
stroke-width: 0px;word-spacing:0px">
<span style=3D"font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-se=
rif&quot;;color:#333333">Michael Behringer: if name space is aggregatable c=
ould work. In early approach, token is not a cert and stealing the token do=
es not help.<o:p></o:p></span></p>
<p style=3D"mso-margin-top-alt:7.5pt;margin-right:0cm;margin-bottom:0cm;mar=
gin-left:0cm;margin-bottom:.0001pt;line-height:15.0pt;background:white;word=
-wrap: break-word;orphans: auto;text-align:start;widows: auto;-webkit-text-=
stroke-width: 0px;word-spacing:0px">
<span style=3D"font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-se=
rif&quot;;color:#333333">Michael Richardson: anxious about spare parts that=
 did not join, and go unserviceable<o:p></o:p></span></p>
<p style=3D"mso-margin-top-alt:7.5pt;margin-right:0cm;margin-bottom:0cm;mar=
gin-left:0cm;margin-bottom:.0001pt;line-height:15.0pt;background:white;word=
-wrap: break-word;orphans: auto;text-align:start;widows: auto;-webkit-text-=
stroke-width: 0px;word-spacing:0px">
<span style=3D"font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-se=
rif&quot;;color:#333333">Michael Behringer: yes, we can take the req in dra=
ft-pritikin<o:p></o:p></span></p>
<p style=3D"mso-margin-top-alt:7.5pt;margin-right:0cm;margin-bottom:0cm;mar=
gin-left:0cm;margin-bottom:.0001pt;line-height:15.0pt;background:white;word=
-wrap: break-word;orphans: auto;text-align:start;widows: auto;-webkit-text-=
stroke-width: 0px;word-spacing:0px">
<span style=3D"font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-se=
rif&quot;;color:#333333">Michael Richardson proposing do something like RFC=
 3779. It as AS numbers to allow reg to delegate using cert; these are live=
 devIDs from a pool. should look at that doc and we could
 change all AS to IdevID and we'd be done.<o:p></o:p></span></p>
<p style=3D"mso-margin-top-alt:7.5pt;margin-right:0cm;margin-bottom:0cm;mar=
gin-left:0cm;margin-bottom:.0001pt;line-height:15.0pt;background:white;word=
-wrap: break-word;orphans: auto;text-align:start;widows: auto;-webkit-text-=
stroke-width: 0px;word-spacing:0px">
<span style=3D"font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-se=
rif&quot;;color:#333333">Michael Behringer: sounds like an idea we'll look =
at it<o:p></o:p></span></p>
<p style=3D"mso-margin-top-alt:7.5pt;margin-right:0cm;margin-bottom:0cm;mar=
gin-left:0cm;margin-bottom:.0001pt;line-height:15.0pt;background:white;word=
-wrap: break-word;orphans: auto;text-align:start;widows: auto;-webkit-text-=
stroke-width: 0px;word-spacing:0px">
<span style=3D"font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-se=
rif&quot;;color:#333333">Michael Richardson: draft pritikin does not tell w=
hether the enrolment allow transport of authorization token back and forth =
and then the cert for the TLS transport can be validated.
 Then you have a secure transport and can enrol replacing the vendor cert w=
ith a domain cert.<o:p></o:p></span></p>
<p style=3D"mso-margin-top-alt:7.5pt;margin-right:0cm;margin-bottom:0cm;mar=
gin-left:0cm;margin-bottom:.0001pt;line-height:15.0pt;background:white;word=
-wrap: break-word;orphans: auto;text-align:start;widows: auto;-webkit-text-=
stroke-width: 0px;word-spacing:0px">
<span style=3D"font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-se=
rif&quot;;color:#333333">Michael Behringer: refer to a mail by Max Pritikin=
 &quot;[6tisch-security] a different explanation of autonomic&quot; .<o:p><=
/o:p></span></p>
<p style=3D"mso-margin-top-alt:7.5pt;margin-right:0cm;margin-bottom:0cm;mar=
gin-left:0cm;margin-bottom:.0001pt;line-height:15.0pt;background:white;word=
-wrap: break-word;orphans: auto;text-align:start;widows: auto;-webkit-text-=
stroke-width: 0px;word-spacing:0px">
<span style=3D"font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-se=
rif&quot;;color:#333333">Michael Richardson: where is the process ?<o:p></o=
:p></span></p>
<p style=3D"mso-margin-top-alt:7.5pt;margin-right:0cm;margin-bottom:0cm;mar=
gin-left:0cm;margin-bottom:.0001pt;line-height:15.0pt;background:white;word=
-wrap: break-word;orphans: auto;text-align:start;widows: auto;-webkit-text-=
stroke-width: 0px;word-spacing:0px">
<span style=3D"font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-se=
rif&quot;;color:#333333">Michael Behringer: explained in message. We need t=
o mail this down so people understand.<o:p></o:p></span></p>
<p style=3D"mso-margin-top-alt:7.5pt;margin-right:0cm;margin-bottom:0cm;mar=
gin-left:0cm;margin-bottom:.0001pt;line-height:15.0pt;background:white;word=
-wrap: break-word;orphans: auto;text-align:start;widows: auto;-webkit-text-=
stroke-width: 0px;word-spacing:0px">
<span style=3D"font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-se=
rif&quot;;color:#333333">Michael Richardson: non normative<o:p></o:p></span=
></p>
<p style=3D"mso-margin-top-alt:7.5pt;margin-right:0cm;margin-bottom:0cm;mar=
gin-left:0cm;margin-bottom:.0001pt;line-height:15.0pt;background:white;word=
-wrap: break-word;orphans: auto;text-align:start;widows: auto;-webkit-text-=
stroke-width: 0px;word-spacing:0px">
<span style=3D"font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-se=
rif&quot;;color:#333333">Pascal Thubert: yes that is what we want in the se=
curity architecture<o:p></o:p></span></p>
<p style=3D"mso-margin-top-alt:7.5pt;margin-right:0cm;margin-bottom:0cm;mar=
gin-left:0cm;margin-bottom:.0001pt;line-height:15.0pt;background:white;word=
-wrap: break-word;orphans: auto;text-align:start;widows: auto;-webkit-text-=
stroke-width: 0px;word-spacing:0px">
<span style=3D"font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-se=
rif&quot;;color:#333333">Michael Behringer I need to leave soon<o:p></o:p><=
/span></p>
<p style=3D"mso-margin-top-alt:7.5pt;margin-right:0cm;margin-bottom:0cm;mar=
gin-left:0cm;margin-bottom:.0001pt;line-height:15.0pt;background:white;word=
-wrap: break-word;orphans: auto;text-align:start;widows: auto;-webkit-text-=
stroke-width: 0px;word-spacing:0px">
<span style=3D"font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-se=
rif&quot;;color:#333333">Michael Richardson: I answered to draft piro descr=
ies low level stuff. I want to encourage people to read and suggest that th=
is becomes WG doc in L2 layer 2 security. It is a very
 good draft. We may need to change the authorization but after that, great =
stuff can be found. Should be WG doc somewhere.<o:p></o:p></span></p>
<p style=3D"mso-margin-top-alt:7.5pt;margin-right:0cm;margin-bottom:0cm;mar=
gin-left:0cm;margin-bottom:.0001pt;line-height:15.0pt;background:white;word=
-wrap: break-word;orphans: auto;text-align:start;widows: auto;-webkit-text-=
stroke-width: 0px;word-spacing:0px">
<span style=3D"font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-se=
rif&quot;;color:#333333">Ren=E9 Struik: thoughts appreciated on mail I sent=
 today<o:p></o:p></span></p>
<p style=3D"mso-margin-top-alt:7.5pt;margin-right:0cm;margin-bottom:0cm;mar=
gin-left:0cm;margin-bottom:.0001pt;line-height:15.0pt;background:white;word=
-wrap: break-word;orphans: auto;text-align:start;widows: auto;-webkit-text-=
stroke-width: 0px;word-spacing:0px">
<span style=3D"font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-se=
rif&quot;;color:#333333">Pascal: Next call on Tuesday next week same time<o=
:p></o:p></span></p>
<p class=3D"MsoNormal" style=3D"mso-margin-top-alt:auto;mso-margin-bottom-a=
lt:auto;margin-left:0cm;text-indent:-18.0pt;line-height:15.0pt;mso-list:l10=
 level1 lfo13;background:white">
<![if !supportLists]><span style=3D"font-size:10.0pt;font-family:Symbol;col=
or:#333333"><span style=3D"mso-list:Ignore">=B7<span style=3D"font:7.0pt &q=
uot;Times New Roman&quot;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
</span></span></span><![endif]><em><span style=3D"font-size:10.5pt;font-fam=
ily:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">[08.06]</span><=
/em><span class=3D"apple-converted-space"><span style=3D"font-size:10.5pt;f=
ont-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">&nbsp;</=
span></span><span style=3D"font-size:10.5pt;font-family:&quot;Arial&quot;,&=
quot;sans-serif&quot;;color:#333333">meeting
 ends<o:p></o:p></span></p>
<p style=3D"mso-margin-top-alt:7.5pt;margin-right:0cm;margin-bottom:0cm;mar=
gin-left:0cm;margin-bottom:.0001pt;line-height:15.0pt;background:white;word=
-wrap: break-word;orphans: auto;text-align:start;widows: auto;-webkit-text-=
stroke-width: 0px;word-spacing:0px">
<span style=3D"font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-se=
rif&quot;;color:#333333">=3D=3D=3D=3D=3D=3D<o:p></o:p></span></p>
<p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p>
</div>
</body>
</html>

--_000_E045AECD98228444A58C61C200AE1BD84266FEEDxmbrcdx01ciscoc_--


From nobody Tue May 20 08:53:42 2014
Return-Path: <rstruik.ext@gmail.com>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 597971A072B for <6tisch-security@ietfa.amsl.com>; Tue, 20 May 2014 08:53:37 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.999
X-Spam-Level: 
X-Spam-Status: No, score=-1.999 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id YRyx3fULZXu3 for <6tisch-security@ietfa.amsl.com>; Tue, 20 May 2014 08:53:34 -0700 (PDT)
Received: from mail-ig0-x234.google.com (mail-ig0-x234.google.com [IPv6:2607:f8b0:4001:c05::234]) (using TLSv1 with cipher ECDHE-RSA-RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 5FCE21A036B for <6tisch-security@ietf.org>; Tue, 20 May 2014 08:53:34 -0700 (PDT)
Received: by mail-ig0-f180.google.com with SMTP id c1so910870igq.7 for <6tisch-security@ietf.org>; Tue, 20 May 2014 08:53:33 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113;  h=message-id:date:from:user-agent:mime-version:to:subject:references :in-reply-to:content-type; bh=dSDMRTauCW3RUsyvWPx+2CDcH1YEFZ73yLiyi0qFkJM=; b=glr0wDawKFWh2jKKJTpayPJlS6qFbRUoOv5X+ewpKLZhVf73UmXoHlOANskw7DVCJ1 ljHDwo21C81w03kQV5taj8NAnvduV8umsZShjGunWDiFS4ESDtFK/HAKNXBAjWw5Tdix VQRXwV31FxPxHOjMx2yrjKJhKzGzGQzNvucKelVj+Y8PYpFkKCIlHBgA+jhyl+6v3BRd BvDOjdIIiq6hVTV8P66Jtk1qBOQ5U8sNIo9aB3vaTdpo952xQwebmrMFzY6E6bAXy9nk 8C/93sjQetA6EHyWJRYBSq7xSO7Q3UEmSedwUS1zt9o6cp49KdskcKxnDneleAUyy55f 1/XQ==
X-Received: by 10.42.157.74 with SMTP id c10mr11016307icx.74.1400601213482; Tue, 20 May 2014 08:53:33 -0700 (PDT)
Received: from [192.168.1.104] (CPE0013100e2c51-CM001cea35caa6.cpe.net.cable.rogers.com. [99.231.3.110]) by mx.google.com with ESMTPSA id j13sm12076214igf.11.2014.05.20.08.53.31 for <multiple recipients> (version=TLSv1 cipher=ECDHE-RSA-RC4-SHA bits=128/128); Tue, 20 May 2014 08:53:32 -0700 (PDT)
Message-ID: <537B7A76.7030201@gmail.com>
Date: Tue, 20 May 2014 11:53:26 -0400
From: Rene Struik <rstruik.ext@gmail.com>
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:24.0) Gecko/20100101 Thunderbird/24.5.0
MIME-Version: 1.0
To: "Pascal Thubert (pthubert)" <pthubert@cisco.com>,  tisch-security <6tisch-security@ietf.org>
References: <E045AECD98228444A58C61C200AE1BD84266FEED@xmb-rcd-x01.cisco.com> <537B7A32.9090900@gmail.com>
In-Reply-To: <537B7A32.9090900@gmail.com>
Content-Type: multipart/alternative; boundary="------------070403000507030705050304"
Archived-At: http://mailarchive.ietf.org/arch/msg/6tisch-security/uJBVy25zqMh4FxynRSSAdz3gEag
Subject: Re: [6tisch-security] [6tisch] Minutes Webex 20th May 2014, 6TiSCH Security
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 20 May 2014 15:53:37 -0000

This is a multi-part message in MIME format.
--------------070403000507030705050304
Content-Type: text/plain; charset=ISO-8859-1; format=flowed
Content-Transfer-Encoding: 8bit

now also to the 6tisch-security list (rather than 6tisch list).

On 5/20/2014 11:52 AM, Rene Struik wrote:
> Hi Pascal:
>
> I would like to suggest adding one more action item:
> All to review email RS as of May 20, 2014, 9:45am EDT and give 
> feedback re details identified outstanding issues.
>
> Rene
>
> ==
> René Struik: thoughts appreciated on mail I sent today
>
> On 5/20/2014 11:38 AM, Pascal Thubert (pthubert) wrote:
>>
>>
>>   Minutes Webex 20th May 2014, 6TiSCH Security
>>
>> ------------------------------------------------------------------------
>>
>>
>>     Taking notes/(using Etherpad)/
>>
>> 1.Pascal Thubert
>>
>>
>>     Present/(alphabetically)/
>>
>> 1.Hank Mauldin
>>
>> 2.Michael Behringer
>>
>> 3.Michael Richardson
>>
>> 4.Maik Seewald
>>
>> 5.René Struik
>>
>> 6.Tom Phinney
>>
>> 7.Yoshihiro Ohba
>>
>>
>>     Recording
>>
>> ·Webex recording 
>> <https://cisco.webex.com/ciscosales/lsr.php?RCID=cf234f58e8f94d2f86fbe15e7d6862df>
>>
>>
>>     Agenda
>>
>> 1.Look at Join Protocol
>>
>>
>>     Action Items
>>
>> 1.Michael R. to suggest to the list a review of draft piro
>>
>> 2.Michael B. to check with Max Pritikin about format on authorization 
>> token.
>>
>>
>>     Minutes
>>
>> ·/[07.10]/Meeting starts
>>
>> Michael Richardson: network manager programs the device, no 
>> particular authorization of the network to the device, nor way for 
>> device to prove it is authorized apart from having the join key 
>> provisioned
>>
>> René Struik: unless missing something, need size of configuration 
>> messages. How to get tag names in the device and map that into 
>> 802.15.4 MAC addresses. Details we do not really have. Unclear how 
>> device can discover the network. Ties in AR certificate issue
>>
>> Michael Richardson: problem exists regardless of actual enrolment 
>> process.
>>
>> René Struik: there is also a control element when certificate can be used
>>
>> Michael Richardson: sent message on Wile coyote; is it realistic?
>>
>> René Struik: quick feedback. say vendor generates cert for bunch of 
>> devices and it goes along a chain and then more attributes allow link 
>> back to factory. works, does not have to be AR certificate
>>
>> Michael Richardson: I expected the kind of certificate I describe in 
>> AR but it is not the point of AR. They do not even specify the format 
>> of device ID. AR is really about an API not about content of 
>> certificate apart from signature algorithm for which they have 
>> requirements. They do not even define their own extensions. One 
>> extension with multiple values
>>
>> Michael Richardson if you use secure enrolment, you can replace the 
>> cert but you still need to validate the device. Need Michael B. and 
>> Max to describe their token
>>
>> Michael Behringer: AR or not AR? process is about an institution that 
>> owns a device and has a secured relationship based on a certificate 
>> that tit signed. Can be 1AR or anything, e.g. an institution which 
>> owned the device before. Need that cert from old organization to help 
>> bootstrap in new organization.
>>
>> Michael Richardson: did you define how the authorization token can be 
>> passed in an interoperable fashion
>>
>> Michael Behringer: leverage secure relationship between vendor and 
>> device to pass a signed message to the device
>>
>> Michael Richardson: does it bind to the new owner? which way, not 
>> subject to standardization or is it?
>>
>> Michael Behringer: May not need standard, but if multivendor network 
>> user would like a common format. between vendor and new device can be 
>> proprietary
>>
>> Michael Richardson: need ot define when how the token is transported, 
>> and that is not end to end. reasons of trust, rate limit etc...
>>
>> Michael Behringer: new device sends along a nonce and expect that 
>> nonce in response from vendor site; without nonce, token could come 
>> from the past. Both models are required in the market. Some want 
>> fresh, others e.g. military there cannot be comm at the deployment time.
>>
>> Michael Richardson: content of token may or not be standard. 
>> transport of token must be standard.
>>
>> Michael Richardson: using RFC 3779 would address cert that had 1AR 
>> IdevID in them. need a range in the certificate otherwise one 
>> certificate per device
>>
>> Michael Behringer: token or certificate?
>>
>> Michael Richardson if the token is a certificate need a way to 
>> delegate down the chain. But breach along the way breaches it all 
>> below. no good. Do you have to maintain a cert for every device?
>>
>> Michael Behringer: that's the starting point. You assume that's a 
>> scalability issue at some point right
>>
>> Michael Richardson: provisioning trouble is possible. Tracking by 
>> bulk could be more palatable
>>
>> Michael Behringer: if name space is aggregatable could work. In early 
>> approach, token is not a cert and stealing the token does not help.
>>
>> Michael Richardson: anxious about spare parts that did not join, and 
>> go unserviceable
>>
>> Michael Behringer: yes, we can take the req in draft-pritikin
>>
>> Michael Richardson proposing do something like RFC 3779. It as AS 
>> numbers to allow reg to delegate using cert; these are live devIDs 
>> from a pool. should look at that doc and we could change all AS to 
>> IdevID and we'd be done.
>>
>> Michael Behringer: sounds like an idea we'll look at it
>>
>> Michael Richardson: draft pritikin does not tell whether the 
>> enrolment allow transport of authorization token back and forth and 
>> then the cert for the TLS transport can be validated. Then you have a 
>> secure transport and can enrol replacing the vendor cert with a 
>> domain cert.
>>
>> Michael Behringer: refer to a mail by Max Pritikin "[6tisch-security] 
>> a different explanation of autonomic" .
>>
>> Michael Richardson: where is the process ?
>>
>> Michael Behringer: explained in message. We need to mail this down so 
>> people understand.
>>
>> Michael Richardson: non normative
>>
>> Pascal Thubert: yes that is what we want in the security architecture
>>
>> Michael Behringer I need to leave soon
>>
>> Michael Richardson: I answered to draft piro descries low level 
>> stuff. I want to encourage people to read and suggest that this 
>> becomes WG doc in L2 layer 2 security. It is a very good draft. We 
>> may need to change the authorization but after that, great stuff can 
>> be found. Should be WG doc somewhere.
>>
>> René Struik: thoughts appreciated on mail I sent today
>>
>> Pascal: Next call on Tuesday next week same time
>>
>> ·/[08.06]/meeting ends
>>
>> ======
>>
>>
>>
>> _______________________________________________
>> 6tisch mailing list
>> 6tisch@ietf.org
>> https://www.ietf.org/mailman/listinfo/6tisch
>
>
> -- 
> email:rstruik.ext@gmail.com  | Skype: rstruik
> cell: +1 (647) 867-5658 | US: +1 (415) 690-7363


-- 
email: rstruik.ext@gmail.com | Skype: rstruik
cell: +1 (647) 867-5658 | US: +1 (415) 690-7363


--------------070403000507030705050304
Content-Type: text/html; charset=ISO-8859-1
Content-Transfer-Encoding: 7bit

<html>
  <head>
    <meta content="text/html; charset=ISO-8859-1"
      http-equiv="Content-Type">
  </head>
  <body bgcolor="#FFFFFF" text="#000000">
    <div class="moz-cite-prefix">now also to the 6tisch-security list
      (rather than 6tisch list).<br>
      <br>
      On 5/20/2014 11:52 AM, Rene Struik wrote:<br>
    </div>
    <blockquote cite="mid:537B7A32.9090900@gmail.com" type="cite">
      <meta content="text/html; charset=ISO-8859-1"
        http-equiv="Content-Type">
      <div class="moz-cite-prefix">Hi Pascal:<br>
        <br>
        I would like to suggest adding one more action item:<br>
        <span
style="font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">All

          to review email RS as of May 20, 2014, 9:45am EDT and give
          feedback re details identified outstanding issues.<br>
          <br>
          Rene<br>
          <br>
          ==<br>
          Ren&eacute; Struik: thoughts appreciated on mail I sent today</span><br>
        <br>
        On 5/20/2014 11:38 AM, Pascal Thubert (pthubert) wrote:<br>
      </div>
      <blockquote
cite="mid:E045AECD98228444A58C61C200AE1BD84266FEED@xmb-rcd-x01.cisco.com"
        type="cite">
        <meta http-equiv="Content-Type" content="text/html;
          charset=ISO-8859-1">
        <meta name="Generator" content="Microsoft Word 14 (filtered
          medium)">
        <!--[if !mso]><style>v\:* {behavior:url(#default#VML);}
o\:* {behavior:url(#default#VML);}
w\:* {behavior:url(#default#VML);}
.shape {behavior:url(#default#VML);}
</style><![endif]-->
        <style><!--
/* Font Definitions */
@font-face
	{font-family:Wingdings;
	panose-1:5 0 0 0 0 0 0 0 0 0;}
@font-face
	{font-family:Wingdings;
	panose-1:5 0 0 0 0 0 0 0 0 0;}
@font-face
	{font-family:Calibri;
	panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
	{font-family:Tahoma;
	panose-1:2 11 6 4 3 5 4 4 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
	{margin:0cm;
	margin-bottom:.0001pt;
	font-size:11.0pt;
	font-family:"Calibri","sans-serif";}
h1
	{mso-style-priority:9;
	mso-style-link:"Heading 1 Char";
	mso-margin-top-alt:auto;
	margin-right:0cm;
	mso-margin-bottom-alt:auto;
	margin-left:0cm;
	font-size:24.0pt;
	font-family:"Times New Roman","serif";
	font-weight:bold;}
h2
	{mso-style-priority:9;
	mso-style-link:"Heading 2 Char";
	mso-margin-top-alt:auto;
	margin-right:0cm;
	mso-margin-bottom-alt:auto;
	margin-left:0cm;
	font-size:18.0pt;
	font-family:"Times New Roman","serif";
	font-weight:bold;}
a:link, span.MsoHyperlink
	{mso-style-priority:99;
	color:blue;
	text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
	{mso-style-priority:99;
	color:purple;
	text-decoration:underline;}
p
	{mso-style-priority:99;
	mso-margin-top-alt:auto;
	margin-right:0cm;
	mso-margin-bottom-alt:auto;
	margin-left:0cm;
	font-size:12.0pt;
	font-family:"Times New Roman","serif";}
p.MsoAcetate, li.MsoAcetate, div.MsoAcetate
	{mso-style-priority:99;
	mso-style-link:"Balloon Text Char";
	margin:0cm;
	margin-bottom:.0001pt;
	font-size:8.0pt;
	font-family:"Tahoma","sans-serif";}
span.EmailStyle17
	{mso-style-type:personal-compose;
	font-family:"Calibri","sans-serif";
	color:windowtext;}
span.BalloonTextChar
	{mso-style-name:"Balloon Text Char";
	mso-style-priority:99;
	mso-style-link:"Balloon Text";
	font-family:"Tahoma","sans-serif";}
span.Heading1Char
	{mso-style-name:"Heading 1 Char";
	mso-style-priority:9;
	mso-style-link:"Heading 1";
	font-family:"Times New Roman","serif";
	font-weight:bold;}
span.Heading2Char
	{mso-style-name:"Heading 2 Char";
	mso-style-priority:9;
	mso-style-link:"Heading 2";
	font-family:"Times New Roman","serif";
	font-weight:bold;}
span.apple-converted-space
	{mso-style-name:apple-converted-space;}
.MsoChpDefault
	{mso-style-type:export-only;
	font-family:"Calibri","sans-serif";}
@page WordSection1
	{size:612.0pt 792.0pt;
	margin:70.85pt 70.85pt 70.85pt 70.85pt;}
div.WordSection1
	{page:WordSection1;}
/* List Definitions */
@list l0
	{mso-list-id:15347732;
	mso-list-template-ids:1149267428;}
@list l1
	{mso-list-id:298346911;
	mso-list-template-ids:-1990059266;}
@list l2
	{mso-list-id:410661324;
	mso-list-template-ids:862720772;}
@list l3
	{mso-list-id:419913662;
	mso-list-template-ids:1939343024;}
@list l4
	{mso-list-id:755715481;
	mso-list-template-ids:1539483424;}
@list l4:level1
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:36.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l4:level2
	{mso-level-number-format:bullet;
	mso-level-text:o;
	mso-level-tab-stop:72.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:"Courier New";
	mso-bidi-font-family:"Times New Roman";}
@list l4:level3
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:108.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l4:level4
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:144.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l4:level5
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:180.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l4:level6
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:216.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l4:level7
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:252.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l4:level8
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:288.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l4:level9
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:324.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l5
	{mso-list-id:795804602;
	mso-list-template-ids:1885534928;}
@list l5:level1
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:36.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l5:level2
	{mso-level-number-format:bullet;
	mso-level-text:o;
	mso-level-tab-stop:72.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:"Courier New";
	mso-bidi-font-family:"Times New Roman";}
@list l5:level3
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:108.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l5:level4
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:144.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l5:level5
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:180.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l5:level6
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:216.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l5:level7
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:252.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l5:level8
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:288.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l5:level9
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:324.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l6
	{mso-list-id:1308902986;
	mso-list-template-ids:1846212050;}
@list l7
	{mso-list-id:1514879373;
	mso-list-template-ids:585418842;}
@list l7:level1
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:36.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l7:level2
	{mso-level-number-format:bullet;
	mso-level-text:o;
	mso-level-tab-stop:72.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:"Courier New";
	mso-bidi-font-family:"Times New Roman";}
@list l7:level3
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:108.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l7:level4
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:144.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l7:level5
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:180.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l7:level6
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:216.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l7:level7
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:252.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l7:level8
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:288.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l7:level9
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:324.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l8
	{mso-list-id:1735615244;
	mso-list-template-ids:612942284;}
@list l9
	{mso-list-id:1863981381;
	mso-list-template-ids:709014192;}
@list l10
	{mso-list-id:1916742795;
	mso-list-template-ids:798656480;}
@list l10:level1
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:36.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l10:level2
	{mso-level-number-format:bullet;
	mso-level-text:o;
	mso-level-tab-stop:72.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:"Courier New";
	mso-bidi-font-family:"Times New Roman";}
@list l10:level3
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:108.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l10:level4
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:144.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l10:level5
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:180.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l10:level6
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:216.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l10:level7
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:252.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l10:level8
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:288.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l10:level9
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:324.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l11
	{mso-list-id:2016230055;
	mso-list-template-ids:-1235608234;}
@list l11:level1
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:36.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l11:level2
	{mso-level-number-format:bullet;
	mso-level-text:o;
	mso-level-tab-stop:72.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:"Courier New";
	mso-bidi-font-family:"Times New Roman";}
@list l11:level3
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:108.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l11:level4
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:144.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l11:level5
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:180.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l11:level6
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:216.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l11:level7
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:252.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l11:level8
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:288.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l11:level9
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:324.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l12
	{mso-list-id:2076000766;
	mso-list-template-ids:-758356318;}
@list l12:level1
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:36.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l12:level2
	{mso-level-number-format:bullet;
	mso-level-text:o;
	mso-level-tab-stop:72.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:"Courier New";
	mso-bidi-font-family:"Times New Roman";}
@list l12:level3
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:108.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l12:level4
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:144.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l12:level5
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:180.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l12:level6
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:216.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l12:level7
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:252.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l12:level8
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:288.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l12:level9
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:324.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
ol
	{margin-bottom:0cm;}
ul
	{margin-bottom:0cm;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]-->
        <div class="WordSection1">
          <h1
style="mso-margin-top-alt:0cm;margin-right:0cm;margin-bottom:7.5pt;margin-left:0cm;background:white"><span
style="font-size:18.0pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333;font-weight:normal">Minutes

              Webex 20th May 2014, 6TiSCH Security<o:p></o:p></span></h1>
          <div class="MsoNormal"
style="mso-margin-top-alt:15.0pt;margin-right:0cm;margin-bottom:15.0pt;margin-left:0cm;text-align:center"
            align="center">
            <hr style="color:#333333" align="center" noshade="noshade"
              size="3" width="100%"> </div>
          <h2
            style="mso-margin-top-alt:15.0pt;margin-right:0cm;margin-bottom:0cm;margin-left:0cm;margin-bottom:.0001pt;background:white;orphans:

            auto;text-align:start;widows:
            auto;-webkit-text-stroke-width: 0px;word-spacing:0px"
            id="markdown-header-taking-notes-using-etherpad"> <span
style="font-size:15.0pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333;font-weight:normal">Taking

              notes<span class="apple-converted-space">&nbsp;</span><em><span
style="font-family:&quot;Arial&quot;,&quot;sans-serif&quot;">(using
                  Etherpad)</span></em><o:p></o:p></span></h2>
          <p class="MsoNormal"
            style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;margin-left:0cm;text-indent:-18.0pt;line-height:15.0pt;mso-list:l1

            level1 lfo7;background:white">
            <!--[if !supportLists]--><span
style="font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333"><span
                style="mso-list:Ignore">1.<span style="font:7.0pt
                  &quot;Times New Roman&quot;">&nbsp;&nbsp;&nbsp;&nbsp; </span></span></span><!--[endif]--><span
style="font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">Pascal

              Thubert<o:p></o:p></span></p>
          <h2
            style="mso-margin-top-alt:15.0pt;margin-right:0cm;margin-bottom:0cm;margin-left:0cm;margin-bottom:.0001pt;background:white;orphans:

            auto;text-align:start;widows:
            auto;-webkit-text-stroke-width: 0px;word-spacing:0px"
            id="markdown-header-present-alphabetically"> <span
style="font-size:15.0pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333;font-weight:normal">Present<span
                class="apple-converted-space">&nbsp;</span><em><span
                  style="font-family:&quot;Arial&quot;,&quot;sans-serif&quot;">(alphabetically)</span></em><o:p></o:p></span></h2>
          <p class="MsoNormal"
            style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;margin-left:0cm;text-indent:-18.0pt;line-height:15.0pt;mso-list:l0

            level1 lfo8;background:white">
            <!--[if !supportLists]--><span
style="font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333"><span
                style="mso-list:Ignore">1.<span style="font:7.0pt
                  &quot;Times New Roman&quot;">&nbsp;&nbsp;&nbsp;&nbsp; </span></span></span><!--[endif]--><span
style="font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">Hank

              Mauldin<o:p></o:p></span></p>
          <p class="MsoNormal"
            style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;margin-left:0cm;text-indent:-18.0pt;line-height:15.0pt;mso-list:l0

            level1 lfo8;background:white">
            <!--[if !supportLists]--><span
style="font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333"><span
                style="mso-list:Ignore">2.<span style="font:7.0pt
                  &quot;Times New Roman&quot;">&nbsp;&nbsp;&nbsp;&nbsp; </span></span></span><!--[endif]--><span
style="font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">Michael

              Behringer<o:p></o:p></span></p>
          <p class="MsoNormal"
            style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;margin-left:0cm;text-indent:-18.0pt;line-height:15.0pt;mso-list:l0

            level1 lfo8;background:white">
            <!--[if !supportLists]--><span
style="font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333"><span
                style="mso-list:Ignore">3.<span style="font:7.0pt
                  &quot;Times New Roman&quot;">&nbsp;&nbsp;&nbsp;&nbsp; </span></span></span><!--[endif]--><span
style="font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">Michael

              Richardson<o:p></o:p></span></p>
          <p class="MsoNormal"
            style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;margin-left:0cm;text-indent:-18.0pt;line-height:15.0pt;mso-list:l0

            level1 lfo8;background:white">
            <!--[if !supportLists]--><span
style="font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333"><span
                style="mso-list:Ignore">4.<span style="font:7.0pt
                  &quot;Times New Roman&quot;">&nbsp;&nbsp;&nbsp;&nbsp; </span></span></span><!--[endif]--><span
style="font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">Maik

              Seewald<o:p></o:p></span></p>
          <p class="MsoNormal"
            style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;margin-left:0cm;text-indent:-18.0pt;line-height:15.0pt;mso-list:l0

            level1 lfo8;background:white">
            <!--[if !supportLists]--><span
style="font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333"><span
                style="mso-list:Ignore">5.<span style="font:7.0pt
                  &quot;Times New Roman&quot;">&nbsp;&nbsp;&nbsp;&nbsp; </span></span></span><!--[endif]--><span
style="font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">Ren&eacute;

              Struik<o:p></o:p></span></p>
          <p class="MsoNormal"
            style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;margin-left:0cm;text-indent:-18.0pt;line-height:15.0pt;mso-list:l0

            level1 lfo8;background:white">
            <!--[if !supportLists]--><span
style="font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333"><span
                style="mso-list:Ignore">6.<span style="font:7.0pt
                  &quot;Times New Roman&quot;">&nbsp;&nbsp;&nbsp;&nbsp; </span></span></span><!--[endif]--><span
style="font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">Tom

              Phinney<o:p></o:p></span></p>
          <p class="MsoNormal"
            style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;margin-left:0cm;text-indent:-18.0pt;line-height:15.0pt;mso-list:l0

            level1 lfo8;background:white">
            <!--[if !supportLists]--><span
style="font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333"><span
                style="mso-list:Ignore">7.<span style="font:7.0pt
                  &quot;Times New Roman&quot;">&nbsp;&nbsp;&nbsp;&nbsp; </span></span></span><!--[endif]--><span
style="font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">Yoshihiro

              Ohba<o:p></o:p></span></p>
          <h2
            style="mso-margin-top-alt:15.0pt;margin-right:0cm;margin-bottom:0cm;margin-left:0cm;margin-bottom:.0001pt;background:white;orphans:

            auto;text-align:start;widows:
            auto;-webkit-text-stroke-width: 0px;word-spacing:0px"
            id="markdown-header-recording"> <span
style="font-size:15.0pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333;font-weight:normal">Recording<o:p></o:p></span></h2>
          <p class="MsoNormal"
            style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;margin-left:0cm;text-indent:-18.0pt;line-height:15.0pt;mso-list:l5

            level1 lfo9;background:white">
            <!--[if !supportLists]--><span
              style="font-size:10.0pt;font-family:Symbol;color:#333333"><span
                style="mso-list:Ignore">&middot;<span style="font:7.0pt
                  &quot;Times New Roman&quot;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span></span><!--[endif]--><span
style="font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333"><a
                moz-do-not-send="true"
href="https://cisco.webex.com/ciscosales/lsr.php?RCID=cf234f58e8f94d2f86fbe15e7d6862df"><span
                  style="color:#3B73AF">Webex recording</span></a><o:p></o:p></span></p>
          <h2
            style="mso-margin-top-alt:15.0pt;margin-right:0cm;margin-bottom:0cm;margin-left:0cm;margin-bottom:.0001pt;background:white;orphans:

            auto;text-align:start;widows:
            auto;-webkit-text-stroke-width: 0px;word-spacing:0px"
            id="markdown-header-agenda"> <span
style="font-size:15.0pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333;font-weight:normal">Agenda<o:p></o:p></span></h2>
          <p class="MsoNormal"
            style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;margin-left:0cm;text-indent:-18.0pt;line-height:15.0pt;mso-list:l6

            level1 lfo10;background:white">
            <!--[if !supportLists]--><span
style="font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333"><span
                style="mso-list:Ignore">1.<span style="font:7.0pt
                  &quot;Times New Roman&quot;">&nbsp;&nbsp;&nbsp;&nbsp; </span></span></span><!--[endif]--><span
style="font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">Look

              at Join Protocol<o:p></o:p></span></p>
          <h2
            style="mso-margin-top-alt:15.0pt;margin-right:0cm;margin-bottom:0cm;margin-left:0cm;margin-bottom:.0001pt;background:white;orphans:

            auto;text-align:start;widows:
            auto;-webkit-text-stroke-width: 0px;word-spacing:0px"
            id="markdown-header-action-items"> <span
style="font-size:15.0pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333;font-weight:normal">Action

              Items<o:p></o:p></span></h2>
          <p class="MsoNormal"
            style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;margin-left:0cm;text-indent:-18.0pt;line-height:15.0pt;mso-list:l2

            level1 lfo11;background:white">
            <!--[if !supportLists]--><span
style="font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333"><span
                style="mso-list:Ignore">1.<span style="font:7.0pt
                  &quot;Times New Roman&quot;">&nbsp;&nbsp;&nbsp;&nbsp; </span></span></span><!--[endif]--><span
style="font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">Michael

              R. to suggest to the list a review of draft piro<o:p></o:p></span></p>
          <p class="MsoNormal"
            style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;margin-left:0cm;text-indent:-18.0pt;line-height:15.0pt;mso-list:l2

            level1 lfo11;background:white">
            <!--[if !supportLists]--><span
style="font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333"><span
                style="mso-list:Ignore">2.<span style="font:7.0pt
                  &quot;Times New Roman&quot;">&nbsp;&nbsp;&nbsp;&nbsp; </span></span></span><!--[endif]--><span
style="font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">Michael

              B. to check with Max Pritikin about format on
              authorization token.<o:p></o:p></span></p>
          <h2
            style="mso-margin-top-alt:15.0pt;margin-right:0cm;margin-bottom:0cm;margin-left:0cm;margin-bottom:.0001pt;background:white;orphans:

            auto;text-align:start;widows:
            auto;-webkit-text-stroke-width: 0px;word-spacing:0px"
            id="markdown-header-minutes"> <span
style="font-size:15.0pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333;font-weight:normal">Minutes<o:p></o:p></span></h2>
          <p class="MsoNormal"
            style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;margin-left:0cm;text-indent:-18.0pt;line-height:15.0pt;mso-list:l11

            level1 lfo12;background:white">
            <!--[if !supportLists]--><span
              style="font-size:10.0pt;font-family:Symbol;color:#333333"><span
                style="mso-list:Ignore">&middot;<span style="font:7.0pt
                  &quot;Times New Roman&quot;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span></span><!--[endif]--><em><span
style="font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">[07.10]</span></em><span
              class="apple-converted-space"><span
style="font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">&nbsp;</span></span><span
style="font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">Meeting


              starts<o:p></o:p></span></p>
          <p
            style="mso-margin-top-alt:7.5pt;margin-right:0cm;margin-bottom:0cm;margin-left:0cm;margin-bottom:.0001pt;line-height:15.0pt;background:white;word-wrap:

            break-word;orphans: auto;text-align:start;widows:
            auto;-webkit-text-stroke-width: 0px;word-spacing:0px"> <span
style="font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">Michael

              Richardson: network manager programs the device, no
              particular authorization of the network to the device, nor
              way for device to prove it is authorized apart from having
              the join key provisioned<o:p></o:p></span></p>
          <p
            style="mso-margin-top-alt:7.5pt;margin-right:0cm;margin-bottom:0cm;margin-left:0cm;margin-bottom:.0001pt;line-height:15.0pt;background:white;word-wrap:

            break-word;orphans: auto;text-align:start;widows:
            auto;-webkit-text-stroke-width: 0px;word-spacing:0px"> <span
style="font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">Ren&eacute;

              Struik: unless missing something, need size of
              configuration messages. How to get tag names in the device
              and map that into 802.15.4 MAC addresses. Details we do
              not really have. Unclear how device can discover the
              network. Ties in AR certificate issue<o:p></o:p></span></p>
          <p
            style="mso-margin-top-alt:7.5pt;margin-right:0cm;margin-bottom:0cm;margin-left:0cm;margin-bottom:.0001pt;line-height:15.0pt;background:white;word-wrap:

            break-word;orphans: auto;text-align:start;widows:
            auto;-webkit-text-stroke-width: 0px;word-spacing:0px"> <span
style="font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">Michael

              Richardson: problem exists regardless of actual enrolment
              process.<o:p></o:p></span></p>
          <p
            style="mso-margin-top-alt:7.5pt;margin-right:0cm;margin-bottom:0cm;margin-left:0cm;margin-bottom:.0001pt;line-height:15.0pt;background:white;word-wrap:

            break-word;orphans: auto;text-align:start;widows:
            auto;-webkit-text-stroke-width: 0px;word-spacing:0px"> <span
style="font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">Ren&eacute;

              Struik: there is also a control element when certificate
              can be used<o:p></o:p></span></p>
          <p
            style="mso-margin-top-alt:7.5pt;margin-right:0cm;margin-bottom:0cm;margin-left:0cm;margin-bottom:.0001pt;line-height:15.0pt;background:white;word-wrap:

            break-word;orphans: auto;text-align:start;widows:
            auto;-webkit-text-stroke-width: 0px;word-spacing:0px"> <span
style="font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">Michael

              Richardson: sent message on Wile coyote; is it realistic?<o:p></o:p></span></p>
          <p
            style="mso-margin-top-alt:7.5pt;margin-right:0cm;margin-bottom:0cm;margin-left:0cm;margin-bottom:.0001pt;line-height:15.0pt;background:white;word-wrap:

            break-word;orphans: auto;text-align:start;widows:
            auto;-webkit-text-stroke-width: 0px;word-spacing:0px"> <span
style="font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">Ren&eacute;

              Struik: quick feedback. say vendor generates cert for
              bunch of devices and it goes along a chain and then more
              attributes allow link back to factory. works, does not
              have to be AR certificate<o:p></o:p></span></p>
          <p
            style="mso-margin-top-alt:7.5pt;margin-right:0cm;margin-bottom:0cm;margin-left:0cm;margin-bottom:.0001pt;line-height:15.0pt;background:white;word-wrap:

            break-word;orphans: auto;text-align:start;widows:
            auto;-webkit-text-stroke-width: 0px;word-spacing:0px"> <span
style="font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">Michael

              Richardson: I expected the kind of certificate I describe
              in AR but it is not the point of AR. They do not even
              specify the format of device ID. AR is really about an API
              not about content of certificate apart from signature
              algorithm for which they have requirements. They do not
              even define their own extensions. One extension with
              multiple values<o:p></o:p></span></p>
          <p
            style="mso-margin-top-alt:7.5pt;margin-right:0cm;margin-bottom:0cm;margin-left:0cm;margin-bottom:.0001pt;line-height:15.0pt;background:white;word-wrap:

            break-word;orphans: auto;text-align:start;widows:
            auto;-webkit-text-stroke-width: 0px;word-spacing:0px"> <span
style="font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">Michael

              Richardson if you use secure enrolment, you can replace
              the cert but you still need to validate the device. Need
              Michael B. and Max to describe their token<o:p></o:p></span></p>
          <p
            style="mso-margin-top-alt:7.5pt;margin-right:0cm;margin-bottom:0cm;margin-left:0cm;margin-bottom:.0001pt;line-height:15.0pt;background:white;word-wrap:

            break-word;orphans: auto;text-align:start;widows:
            auto;-webkit-text-stroke-width: 0px;word-spacing:0px"> <span
style="font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">Michael

              Behringer: AR or not AR? process is about an institution
              that owns a device and has a secured relationship based on
              a certificate that tit signed. Can be 1AR or anything,
              e.g. an institution which owned the device before. Need
              that cert from old organization to help bootstrap in new
              organization.<o:p></o:p></span></p>
          <p
            style="mso-margin-top-alt:7.5pt;margin-right:0cm;margin-bottom:0cm;margin-left:0cm;margin-bottom:.0001pt;line-height:15.0pt;background:white;word-wrap:

            break-word;orphans: auto;text-align:start;widows:
            auto;-webkit-text-stroke-width: 0px;word-spacing:0px"> <span
style="font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">Michael

              Richardson: did you define how the authorization token can
              be passed in an interoperable fashion<o:p></o:p></span></p>
          <p
            style="mso-margin-top-alt:7.5pt;margin-right:0cm;margin-bottom:0cm;margin-left:0cm;margin-bottom:.0001pt;line-height:15.0pt;background:white;word-wrap:

            break-word;orphans: auto;text-align:start;widows:
            auto;-webkit-text-stroke-width: 0px;word-spacing:0px"> <span
style="font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">Michael

              Behringer: leverage secure relationship between vendor and
              device to pass a signed message to the device<o:p></o:p></span></p>
          <p
            style="mso-margin-top-alt:7.5pt;margin-right:0cm;margin-bottom:0cm;margin-left:0cm;margin-bottom:.0001pt;line-height:15.0pt;background:white;word-wrap:

            break-word;orphans: auto;text-align:start;widows:
            auto;-webkit-text-stroke-width: 0px;word-spacing:0px"> <span
style="font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">Michael

              Richardson: does it bind to the new owner? which way, not
              subject to standardization or is it?<o:p></o:p></span></p>
          <p
            style="mso-margin-top-alt:7.5pt;margin-right:0cm;margin-bottom:0cm;margin-left:0cm;margin-bottom:.0001pt;line-height:15.0pt;background:white;word-wrap:

            break-word;orphans: auto;text-align:start;widows:
            auto;-webkit-text-stroke-width: 0px;word-spacing:0px"> <span
style="font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">Michael

              Behringer: May not need standard, but if multivendor
              network user would like a common format. between vendor
              and new device can be proprietary<o:p></o:p></span></p>
          <p
            style="mso-margin-top-alt:7.5pt;margin-right:0cm;margin-bottom:0cm;margin-left:0cm;margin-bottom:.0001pt;line-height:15.0pt;background:white;word-wrap:

            break-word;orphans: auto;text-align:start;widows:
            auto;-webkit-text-stroke-width: 0px;word-spacing:0px"> <span
style="font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">Michael

              Richardson: need ot define when how the token is
              transported, and that is not end to end. reasons of trust,
              rate limit etc...<o:p></o:p></span></p>
          <p
            style="mso-margin-top-alt:7.5pt;margin-right:0cm;margin-bottom:0cm;margin-left:0cm;margin-bottom:.0001pt;line-height:15.0pt;background:white;word-wrap:

            break-word;orphans: auto;text-align:start;widows:
            auto;-webkit-text-stroke-width: 0px;word-spacing:0px"> <span
style="font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">Michael

              Behringer: new device sends along a nonce and expect that
              nonce in response from vendor site; without nonce, token
              could come from the past. Both models are required in the
              market. Some want fresh, others e.g. military there cannot
              be comm at the deployment time.<o:p></o:p></span></p>
          <p
            style="mso-margin-top-alt:7.5pt;margin-right:0cm;margin-bottom:0cm;margin-left:0cm;margin-bottom:.0001pt;line-height:15.0pt;background:white;word-wrap:

            break-word;orphans: auto;text-align:start;widows:
            auto;-webkit-text-stroke-width: 0px;word-spacing:0px"> <span
style="font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">Michael

              Richardson: content of token may or not be standard.
              transport of token must be standard.<o:p></o:p></span></p>
          <p
            style="mso-margin-top-alt:7.5pt;margin-right:0cm;margin-bottom:0cm;margin-left:0cm;margin-bottom:.0001pt;line-height:15.0pt;background:white;word-wrap:

            break-word;orphans: auto;text-align:start;widows:
            auto;-webkit-text-stroke-width: 0px;word-spacing:0px"> <span
style="font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">Michael

              Richardson: using RFC 3779 would address cert that had 1AR
              IdevID in them. need a range in the certificate otherwise
              one certificate per device<o:p></o:p></span></p>
          <p
            style="mso-margin-top-alt:7.5pt;margin-right:0cm;margin-bottom:0cm;margin-left:0cm;margin-bottom:.0001pt;line-height:15.0pt;background:white;word-wrap:

            break-word;orphans: auto;text-align:start;widows:
            auto;-webkit-text-stroke-width: 0px;word-spacing:0px"> <span
style="font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">Michael

              Behringer: token or certificate?<o:p></o:p></span></p>
          <p
            style="mso-margin-top-alt:7.5pt;margin-right:0cm;margin-bottom:0cm;margin-left:0cm;margin-bottom:.0001pt;line-height:15.0pt;background:white;word-wrap:

            break-word;orphans: auto;text-align:start;widows:
            auto;-webkit-text-stroke-width: 0px;word-spacing:0px"> <span
style="font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">Michael

              Richardson if the token is a certificate need a way to
              delegate down the chain. But breach along the way breaches
              it all below. no good. Do you have to maintain a cert for
              every device?<o:p></o:p></span></p>
          <p
            style="mso-margin-top-alt:7.5pt;margin-right:0cm;margin-bottom:0cm;margin-left:0cm;margin-bottom:.0001pt;line-height:15.0pt;background:white;word-wrap:

            break-word;orphans: auto;text-align:start;widows:
            auto;-webkit-text-stroke-width: 0px;word-spacing:0px"> <span
style="font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">Michael

              Behringer: that's the starting point. You assume that's a
              scalability issue at some point right<o:p></o:p></span></p>
          <p
            style="mso-margin-top-alt:7.5pt;margin-right:0cm;margin-bottom:0cm;margin-left:0cm;margin-bottom:.0001pt;line-height:15.0pt;background:white;word-wrap:

            break-word;orphans: auto;text-align:start;widows:
            auto;-webkit-text-stroke-width: 0px;word-spacing:0px"> <span
style="font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">Michael

              Richardson: provisioning trouble is possible. Tracking by
              bulk could be more palatable<o:p></o:p></span></p>
          <p
            style="mso-margin-top-alt:7.5pt;margin-right:0cm;margin-bottom:0cm;margin-left:0cm;margin-bottom:.0001pt;line-height:15.0pt;background:white;word-wrap:

            break-word;orphans: auto;text-align:start;widows:
            auto;-webkit-text-stroke-width: 0px;word-spacing:0px"> <span
style="font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">Michael

              Behringer: if name space is aggregatable could work. In
              early approach, token is not a cert and stealing the token
              does not help.<o:p></o:p></span></p>
          <p
            style="mso-margin-top-alt:7.5pt;margin-right:0cm;margin-bottom:0cm;margin-left:0cm;margin-bottom:.0001pt;line-height:15.0pt;background:white;word-wrap:

            break-word;orphans: auto;text-align:start;widows:
            auto;-webkit-text-stroke-width: 0px;word-spacing:0px"> <span
style="font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">Michael

              Richardson: anxious about spare parts that did not join,
              and go unserviceable<o:p></o:p></span></p>
          <p
            style="mso-margin-top-alt:7.5pt;margin-right:0cm;margin-bottom:0cm;margin-left:0cm;margin-bottom:.0001pt;line-height:15.0pt;background:white;word-wrap:

            break-word;orphans: auto;text-align:start;widows:
            auto;-webkit-text-stroke-width: 0px;word-spacing:0px"> <span
style="font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">Michael

              Behringer: yes, we can take the req in draft-pritikin<o:p></o:p></span></p>
          <p
            style="mso-margin-top-alt:7.5pt;margin-right:0cm;margin-bottom:0cm;margin-left:0cm;margin-bottom:.0001pt;line-height:15.0pt;background:white;word-wrap:

            break-word;orphans: auto;text-align:start;widows:
            auto;-webkit-text-stroke-width: 0px;word-spacing:0px"> <span
style="font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">Michael

              Richardson proposing do something like RFC 3779. It as AS
              numbers to allow reg to delegate using cert; these are
              live devIDs from a pool. should look at that doc and we
              could change all AS to IdevID and we'd be done.<o:p></o:p></span></p>
          <p
            style="mso-margin-top-alt:7.5pt;margin-right:0cm;margin-bottom:0cm;margin-left:0cm;margin-bottom:.0001pt;line-height:15.0pt;background:white;word-wrap:

            break-word;orphans: auto;text-align:start;widows:
            auto;-webkit-text-stroke-width: 0px;word-spacing:0px"> <span
style="font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">Michael

              Behringer: sounds like an idea we'll look at it<o:p></o:p></span></p>
          <p
            style="mso-margin-top-alt:7.5pt;margin-right:0cm;margin-bottom:0cm;margin-left:0cm;margin-bottom:.0001pt;line-height:15.0pt;background:white;word-wrap:

            break-word;orphans: auto;text-align:start;widows:
            auto;-webkit-text-stroke-width: 0px;word-spacing:0px"> <span
style="font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">Michael

              Richardson: draft pritikin does not tell whether the
              enrolment allow transport of authorization token back and
              forth and then the cert for the TLS transport can be
              validated. Then you have a secure transport and can enrol
              replacing the vendor cert with a domain cert.<o:p></o:p></span></p>
          <p
            style="mso-margin-top-alt:7.5pt;margin-right:0cm;margin-bottom:0cm;margin-left:0cm;margin-bottom:.0001pt;line-height:15.0pt;background:white;word-wrap:

            break-word;orphans: auto;text-align:start;widows:
            auto;-webkit-text-stroke-width: 0px;word-spacing:0px"> <span
style="font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">Michael

              Behringer: refer to a mail by Max Pritikin
              "[6tisch-security] a different explanation of autonomic" .<o:p></o:p></span></p>
          <p
            style="mso-margin-top-alt:7.5pt;margin-right:0cm;margin-bottom:0cm;margin-left:0cm;margin-bottom:.0001pt;line-height:15.0pt;background:white;word-wrap:

            break-word;orphans: auto;text-align:start;widows:
            auto;-webkit-text-stroke-width: 0px;word-spacing:0px"> <span
style="font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">Michael

              Richardson: where is the process ?<o:p></o:p></span></p>
          <p
            style="mso-margin-top-alt:7.5pt;margin-right:0cm;margin-bottom:0cm;margin-left:0cm;margin-bottom:.0001pt;line-height:15.0pt;background:white;word-wrap:

            break-word;orphans: auto;text-align:start;widows:
            auto;-webkit-text-stroke-width: 0px;word-spacing:0px"> <span
style="font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">Michael

              Behringer: explained in message. We need to mail this down
              so people understand.<o:p></o:p></span></p>
          <p
            style="mso-margin-top-alt:7.5pt;margin-right:0cm;margin-bottom:0cm;margin-left:0cm;margin-bottom:.0001pt;line-height:15.0pt;background:white;word-wrap:

            break-word;orphans: auto;text-align:start;widows:
            auto;-webkit-text-stroke-width: 0px;word-spacing:0px"> <span
style="font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">Michael

              Richardson: non normative<o:p></o:p></span></p>
          <p
            style="mso-margin-top-alt:7.5pt;margin-right:0cm;margin-bottom:0cm;margin-left:0cm;margin-bottom:.0001pt;line-height:15.0pt;background:white;word-wrap:

            break-word;orphans: auto;text-align:start;widows:
            auto;-webkit-text-stroke-width: 0px;word-spacing:0px"> <span
style="font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">Pascal

              Thubert: yes that is what we want in the security
              architecture<o:p></o:p></span></p>
          <p
            style="mso-margin-top-alt:7.5pt;margin-right:0cm;margin-bottom:0cm;margin-left:0cm;margin-bottom:.0001pt;line-height:15.0pt;background:white;word-wrap:

            break-word;orphans: auto;text-align:start;widows:
            auto;-webkit-text-stroke-width: 0px;word-spacing:0px"> <span
style="font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">Michael

              Behringer I need to leave soon<o:p></o:p></span></p>
          <p
            style="mso-margin-top-alt:7.5pt;margin-right:0cm;margin-bottom:0cm;margin-left:0cm;margin-bottom:.0001pt;line-height:15.0pt;background:white;word-wrap:

            break-word;orphans: auto;text-align:start;widows:
            auto;-webkit-text-stroke-width: 0px;word-spacing:0px"> <span
style="font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">Michael

              Richardson: I answered to draft piro descries low level
              stuff. I want to encourage people to read and suggest that
              this becomes WG doc in L2 layer 2 security. It is a very
              good draft. We may need to change the authorization but
              after that, great stuff can be found. Should be WG doc
              somewhere.<o:p></o:p></span></p>
          <p
            style="mso-margin-top-alt:7.5pt;margin-right:0cm;margin-bottom:0cm;margin-left:0cm;margin-bottom:.0001pt;line-height:15.0pt;background:white;word-wrap:

            break-word;orphans: auto;text-align:start;widows:
            auto;-webkit-text-stroke-width: 0px;word-spacing:0px"> <span
style="font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">Ren&eacute;

              Struik: thoughts appreciated on mail I sent today<o:p></o:p></span></p>
          <p
            style="mso-margin-top-alt:7.5pt;margin-right:0cm;margin-bottom:0cm;margin-left:0cm;margin-bottom:.0001pt;line-height:15.0pt;background:white;word-wrap:

            break-word;orphans: auto;text-align:start;widows:
            auto;-webkit-text-stroke-width: 0px;word-spacing:0px"> <span
style="font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">Pascal:

              Next call on Tuesday next week same time<o:p></o:p></span></p>
          <p class="MsoNormal"
            style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;margin-left:0cm;text-indent:-18.0pt;line-height:15.0pt;mso-list:l10

            level1 lfo13;background:white">
            <!--[if !supportLists]--><span
              style="font-size:10.0pt;font-family:Symbol;color:#333333"><span
                style="mso-list:Ignore">&middot;<span style="font:7.0pt
                  &quot;Times New Roman&quot;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span></span><!--[endif]--><em><span
style="font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">[08.06]</span></em><span
              class="apple-converted-space"><span
style="font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">&nbsp;</span></span><span
style="font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">meeting


              ends<o:p></o:p></span></p>
          <p
            style="mso-margin-top-alt:7.5pt;margin-right:0cm;margin-bottom:0cm;margin-left:0cm;margin-bottom:.0001pt;line-height:15.0pt;background:white;word-wrap:

            break-word;orphans: auto;text-align:start;widows:
            auto;-webkit-text-stroke-width: 0px;word-spacing:0px"> <span
style="font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">======<o:p></o:p></span></p>
          <p class="MsoNormal"><o:p>&nbsp;</o:p></p>
        </div>
        <br>
        <fieldset class="mimeAttachmentHeader"></fieldset>
        <br>
        <pre wrap="">_______________________________________________
6tisch mailing list
<a moz-do-not-send="true" class="moz-txt-link-abbreviated" href="mailto:6tisch@ietf.org">6tisch@ietf.org</a>
<a moz-do-not-send="true" class="moz-txt-link-freetext" href="https://www.ietf.org/mailman/listinfo/6tisch">https://www.ietf.org/mailman/listinfo/6tisch</a>
</pre>
      </blockquote>
      <br>
      <br>
      <pre class="moz-signature" cols="72">-- 
email: <a moz-do-not-send="true" class="moz-txt-link-abbreviated" href="mailto:rstruik.ext@gmail.com">rstruik.ext@gmail.com</a> | Skype: rstruik
cell: +1 (647) 867-5658 | US: +1 (415) 690-7363</pre>
    </blockquote>
    <br>
    <br>
    <pre class="moz-signature" cols="72">-- 
email: <a class="moz-txt-link-abbreviated" href="mailto:rstruik.ext@gmail.com">rstruik.ext@gmail.com</a> | Skype: rstruik
cell: +1 (647) 867-5658 | US: +1 (415) 690-7363</pre>
  </body>
</html>

--------------070403000507030705050304--


From nobody Tue May 20 09:47:16 2014
Return-Path: <rstruik.ext@gmail.com>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 65A6A1A0116 for <6tisch-security@ietfa.amsl.com>; Tue, 20 May 2014 09:47:13 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.999
X-Spam-Level: 
X-Spam-Status: No, score=-1.999 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id EG_YIIuG_pLo for <6tisch-security@ietfa.amsl.com>; Tue, 20 May 2014 09:47:10 -0700 (PDT)
Received: from mail-ie0-x231.google.com (mail-ie0-x231.google.com [IPv6:2607:f8b0:4001:c03::231]) (using TLSv1 with cipher ECDHE-RSA-RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 4E0721A00E5 for <6tisch-security@ietf.org>; Tue, 20 May 2014 09:47:10 -0700 (PDT)
Received: by mail-ie0-f177.google.com with SMTP id y20so704088ier.8 for <6tisch-security@ietf.org>; Tue, 20 May 2014 09:47:09 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113;  h=message-id:date:from:user-agent:mime-version:to:subject:references :in-reply-to:content-type; bh=6ZCNbUgWmiLcSLgQU2qLxKSvIBBJA4di60rc9jOQ5IM=; b=P48XQSgUe2+FmWJFF+8pEUHZ5AZb2WtWuF12BeK6k/HE9pvBvZsu6GHXe0dqU6EU1I yWKnK7DZg7igAYgTWfPfSf6JsJX0CtiHiSz5Mls/pRmshBcGfIy0o9XCspd7F3vOV+3E btJuHvND1Fjnr0Fmp1OJ3EtlirpEcgXu6fwraBT0ysGobt0pKfkue1O9FUyAH+2D9sqf 64e1JATyR3+2XBtBxU8bOiWMpTE1JGcIwxSVSmPeXfqz3eBmCX2HpCp6DTOAYny9L1Ro XZKHMLBF9EGyxdCEtNvhXkeP/A5tumVC42MjOIRGh4jSROnm2J3ZX4YPotRCK3d3VHD+ 6+ug==
X-Received: by 10.50.79.226 with SMTP id m2mr6642559igx.11.1400604429529; Tue, 20 May 2014 09:47:09 -0700 (PDT)
Received: from [192.168.1.104] (CPE0013100e2c51-CM001cea35caa6.cpe.net.cable.rogers.com. [99.231.3.110]) by mx.google.com with ESMTPSA id d10sm30149493igc.8.2014.05.20.09.47.06 for <multiple recipients> (version=TLSv1 cipher=ECDHE-RSA-RC4-SHA bits=128/128); Tue, 20 May 2014 09:47:08 -0700 (PDT)
Message-ID: <537B8705.1090609@gmail.com>
Date: Tue, 20 May 2014 12:47:01 -0400
From: Rene Struik <rstruik.ext@gmail.com>
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:24.0) Gecko/20100101 Thunderbird/24.5.0
MIME-Version: 1.0
To: "Pascal Thubert (pthubert)" <pthubert@cisco.com>,  tisch-security <6tisch-security@ietf.org>
References: <E045AECD98228444A58C61C200AE1BD84266FEED@xmb-rcd-x01.cisco.com>
In-Reply-To: <E045AECD98228444A58C61C200AE1BD84266FEED@xmb-rcd-x01.cisco.com>
Content-Type: multipart/alternative; boundary="------------050002050903010104000808"
Archived-At: http://mailarchive.ietf.org/arch/msg/6tisch-security/SycBwsSvv5aTt8bSCUVwXsanceU
Subject: [6tisch-security] (review draft-piro-6tisch-security-issues-01) Re: [6tisch] Minutes Webex 20th May 2014, 6TiSCH Security
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 20 May 2014 16:47:13 -0000

This is a multi-part message in MIME format.
--------------050002050903010104000808
Content-Type: text/plain; charset=ISO-8859-1; format=flowed
Content-Transfer-Encoding: 8bit

Dear colleagues:

As suggested by Michael Richardson, I briefly reviewed the 
draft-piro-6tisch-security-issues-01.

Some suggestions/feedback:
a) the draft relates to 802.15.4-2011. I would suggest making this 
relative to 802.15.4e-2012 (which describes the TSCH protocol and 
corresponding MAC extensions).
b) the draft introduces new 802.15.4-command frames to implement the key 
negotiation phase (Section 6.3). As such, this would constitute a change 
to the 802.15.4-2011 and 802.15.4e-2012 specification. Besides, this 
also implies that the key negotiation phase can only deal with one-hop 
behavior.
c) the key negotiation protocol deals with authenticated key agreement 
and does not consider potential authorization steps.
d) it is assumed that each node is preconfigured with a master key M_k 
that is shared amongst all devices (Section 6.1.1), from which default 
keys D_k are derived using a publicly known function (with potentially 
other inputs, which are to be assumed publicly known). This seems to 
imply that all default keys can be considered as publicly known strings (!).
e) the key negotiation phase using the anonymous Diffie-Hellman scheme 
(Section 6.3.3) that uses ordinary Diffie-Hellman groups in the ring of 
integers Zp, where p is a prime number that indexed by a publicly 
computable integer (Section 6.3.1, Step c1)) and where p has at least 
bit-size 128 (see Appendix A.1). The ordinary Diffie-Hellman problem in 
integer rings Zp of this order of magnitude sizes is efficiently 
computable, thereby rendering this scheme completely insecure (I already 
commented on this when reviewing draft r0 of which this draft is an 
update (see 
http://www.ietf.org/mail-archive/web/6tisch/current/msg01481.html))
f) the 802.15.4-2011 specification mistakenly does not allow mixing of 
secured and unsecured traffic (see, e.g., my emails of end of January 
2014 on this). In particular, the hybrid security network (as mentioned 
in Section 5) is not possible with 802.15.4-2011 or 802.15.4e-2012.

Best regards, Rene

On 5/20/2014 11:38 AM, Pascal Thubert (pthubert) wrote:
>
>
>   Minutes Webex 20th May 2014, 6TiSCH Security
>
> ------------------------------------------------------------------------
>
>
>     Taking notes/(using Etherpad)/
>
> 1.Pascal Thubert
>
>
>     Present/(alphabetically)/
>
> 1.Hank Mauldin
>
> 2.Michael Behringer
>
> 3.Michael Richardson
>
> 4.Maik Seewald
>
> 5.René Struik
>
> 6.Tom Phinney
>
> 7.Yoshihiro Ohba
>
>
>     Recording
>
> ·Webex recording 
> <https://cisco.webex.com/ciscosales/lsr.php?RCID=cf234f58e8f94d2f86fbe15e7d6862df>
>
>
>     Agenda
>
> 1.Look at Join Protocol
>
>
>     Action Items
>
> 1.Michael R. to suggest to the list a review of draft piro
>
> 2.Michael B. to check with Max Pritikin about format on authorization 
> token.
>
>
>     Minutes
>
> ·/[07.10]/Meeting starts
>
> Michael Richardson: network manager programs the device, no particular 
> authorization of the network to the device, nor way for device to 
> prove it is authorized apart from having the join key provisioned
>
> René Struik: unless missing something, need size of configuration 
> messages. How to get tag names in the device and map that into 
> 802.15.4 MAC addresses. Details we do not really have. Unclear how 
> device can discover the network. Ties in AR certificate issue
>
> Michael Richardson: problem exists regardless of actual enrolment process.
>
> René Struik: there is also a control element when certificate can be used
>
> Michael Richardson: sent message on Wile coyote; is it realistic?
>
> René Struik: quick feedback. say vendor generates cert for bunch of 
> devices and it goes along a chain and then more attributes allow link 
> back to factory. works, does not have to be AR certificate
>
> Michael Richardson: I expected the kind of certificate I describe in 
> AR but it is not the point of AR. They do not even specify the format 
> of device ID. AR is really about an API not about content of 
> certificate apart from signature algorithm for which they have 
> requirements. They do not even define their own extensions. One 
> extension with multiple values
>
> Michael Richardson if you use secure enrolment, you can replace the 
> cert but you still need to validate the device. Need Michael B. and 
> Max to describe their token
>
> Michael Behringer: AR or not AR? process is about an institution that 
> owns a device and has a secured relationship based on a certificate 
> that tit signed. Can be 1AR or anything, e.g. an institution which 
> owned the device before. Need that cert from old organization to help 
> bootstrap in new organization.
>
> Michael Richardson: did you define how the authorization token can be 
> passed in an interoperable fashion
>
> Michael Behringer: leverage secure relationship between vendor and 
> device to pass a signed message to the device
>
> Michael Richardson: does it bind to the new owner? which way, not 
> subject to standardization or is it?
>
> Michael Behringer: May not need standard, but if multivendor network 
> user would like a common format. between vendor and new device can be 
> proprietary
>
> Michael Richardson: need ot define when how the token is transported, 
> and that is not end to end. reasons of trust, rate limit etc...
>
> Michael Behringer: new device sends along a nonce and expect that 
> nonce in response from vendor site; without nonce, token could come 
> from the past. Both models are required in the market. Some want 
> fresh, others e.g. military there cannot be comm at the deployment time.
>
> Michael Richardson: content of token may or not be standard. transport 
> of token must be standard.
>
> Michael Richardson: using RFC 3779 would address cert that had 1AR 
> IdevID in them. need a range in the certificate otherwise one 
> certificate per device
>
> Michael Behringer: token or certificate?
>
> Michael Richardson if the token is a certificate need a way to 
> delegate down the chain. But breach along the way breaches it all 
> below. no good. Do you have to maintain a cert for every device?
>
> Michael Behringer: that's the starting point. You assume that's a 
> scalability issue at some point right
>
> Michael Richardson: provisioning trouble is possible. Tracking by bulk 
> could be more palatable
>
> Michael Behringer: if name space is aggregatable could work. In early 
> approach, token is not a cert and stealing the token does not help.
>
> Michael Richardson: anxious about spare parts that did not join, and 
> go unserviceable
>
> Michael Behringer: yes, we can take the req in draft-pritikin
>
> Michael Richardson proposing do something like RFC 3779. It as AS 
> numbers to allow reg to delegate using cert; these are live devIDs 
> from a pool. should look at that doc and we could change all AS to 
> IdevID and we'd be done.
>
> Michael Behringer: sounds like an idea we'll look at it
>
> Michael Richardson: draft pritikin does not tell whether the enrolment 
> allow transport of authorization token back and forth and then the 
> cert for the TLS transport can be validated. Then you have a secure 
> transport and can enrol replacing the vendor cert with a domain cert.
>
> Michael Behringer: refer to a mail by Max Pritikin "[6tisch-security] 
> a different explanation of autonomic" .
>
> Michael Richardson: where is the process ?
>
> Michael Behringer: explained in message. We need to mail this down so 
> people understand.
>
> Michael Richardson: non normative
>
> Pascal Thubert: yes that is what we want in the security architecture
>
> Michael Behringer I need to leave soon
>
> Michael Richardson: I answered to draft piro descries low level stuff. 
> I want to encourage people to read and suggest that this becomes WG 
> doc in L2 layer 2 security. It is a very good draft. We may need to 
> change the authorization but after that, great stuff can be found. 
> Should be WG doc somewhere.
>
> René Struik: thoughts appreciated on mail I sent today
>
> Pascal: Next call on Tuesday next week same time
>
> ·/[08.06]/meeting ends
>
> ======
>
>
>
> _______________________________________________
> 6tisch mailing list
> 6tisch@ietf.org
> https://www.ietf.org/mailman/listinfo/6tisch


-- 
email: rstruik.ext@gmail.com | Skype: rstruik
cell: +1 (647) 867-5658 | US: +1 (415) 690-7363


--------------050002050903010104000808
Content-Type: text/html; charset=ISO-8859-1
Content-Transfer-Encoding: 7bit

<html>
  <head>
    <meta content="text/html; charset=ISO-8859-1"
      http-equiv="Content-Type">
  </head>
  <body bgcolor="#FFFFFF" text="#000000">
    <div class="moz-cite-prefix">Dear colleagues:<br>
      <br>
      As suggested by Michael Richardson, I briefly reviewed the
      draft-piro-6tisch-security-issues-01. <br>
      <br>
      Some suggestions/feedback:<br>
      a) the draft relates to 802.15.4-2011. I would suggest making this
      relative to 802.15.4e-2012 (which describes the TSCH protocol and
      corresponding MAC extensions).<br>
      b) the draft introduces new 802.15.4-command frames to implement
      the key negotiation phase (Section 6.3). As such, this would
      constitute a change to the 802.15.4-2011 and 802.15.4e-2012
      specification. Besides, this also implies that the key negotiation
      phase can only deal with one-hop behavior.<br>
      c) the key negotiation protocol deals with authenticated key
      agreement and does not consider potential authorization steps. <br>
      d) it is assumed that each node is preconfigured with a master key
      M_k that is shared amongst all devices (Section 6.1.1), from which
      default keys D_k are derived using a publicly known function (with
      potentially other inputs, which are to be assumed publicly known).
      This seems to imply that all default keys can be considered as
      publicly known strings (!).<br>
      e) the key negotiation phase using the anonymous Diffie-Hellman
      scheme (Section 6.3.3) that uses ordinary Diffie-Hellman groups in
      the ring of integers Zp, where p is a prime number that indexed by
      a publicly computable integer (Section 6.3.1, Step c1)) and where
      p has at least bit-size 128 (see Appendix A.1). The ordinary
      Diffie-Hellman problem in integer rings Zp of this order of
      magnitude sizes is efficiently computable, thereby rendering this
      scheme completely insecure (I already commented on this when
      reviewing draft r0 of which this draft is an update (see
      <a class="moz-txt-link-freetext" href="http://www.ietf.org/mail-archive/web/6tisch/current/msg01481.html">http://www.ietf.org/mail-archive/web/6tisch/current/msg01481.html</a>))<br>
      f) the 802.15.4-2011 specification mistakenly does not allow
      mixing of secured and unsecured traffic (see, e.g., my emails of
      end of January 2014 on this). In particular, the hybrid security
      network (as mentioned in Section 5) is not possible with
      802.15.4-2011 or 802.15.4e-2012.<br>
      <br>
      Best regards, Rene<br>
      <br>
      On 5/20/2014 11:38 AM, Pascal Thubert (pthubert) wrote:<br>
    </div>
    <blockquote
cite="mid:E045AECD98228444A58C61C200AE1BD84266FEED@xmb-rcd-x01.cisco.com"
      type="cite">
      <meta http-equiv="Content-Type" content="text/html;
        charset=ISO-8859-1">
      <meta name="Generator" content="Microsoft Word 14 (filtered
        medium)">
      <!--[if !mso]><style>v\:* {behavior:url(#default#VML);}
o\:* {behavior:url(#default#VML);}
w\:* {behavior:url(#default#VML);}
.shape {behavior:url(#default#VML);}
</style><![endif]-->
      <style><!--
/* Font Definitions */
@font-face
	{font-family:Wingdings;
	panose-1:5 0 0 0 0 0 0 0 0 0;}
@font-face
	{font-family:Wingdings;
	panose-1:5 0 0 0 0 0 0 0 0 0;}
@font-face
	{font-family:Calibri;
	panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
	{font-family:Tahoma;
	panose-1:2 11 6 4 3 5 4 4 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
	{margin:0cm;
	margin-bottom:.0001pt;
	font-size:11.0pt;
	font-family:"Calibri","sans-serif";}
h1
	{mso-style-priority:9;
	mso-style-link:"Heading 1 Char";
	mso-margin-top-alt:auto;
	margin-right:0cm;
	mso-margin-bottom-alt:auto;
	margin-left:0cm;
	font-size:24.0pt;
	font-family:"Times New Roman","serif";
	font-weight:bold;}
h2
	{mso-style-priority:9;
	mso-style-link:"Heading 2 Char";
	mso-margin-top-alt:auto;
	margin-right:0cm;
	mso-margin-bottom-alt:auto;
	margin-left:0cm;
	font-size:18.0pt;
	font-family:"Times New Roman","serif";
	font-weight:bold;}
a:link, span.MsoHyperlink
	{mso-style-priority:99;
	color:blue;
	text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
	{mso-style-priority:99;
	color:purple;
	text-decoration:underline;}
p
	{mso-style-priority:99;
	mso-margin-top-alt:auto;
	margin-right:0cm;
	mso-margin-bottom-alt:auto;
	margin-left:0cm;
	font-size:12.0pt;
	font-family:"Times New Roman","serif";}
p.MsoAcetate, li.MsoAcetate, div.MsoAcetate
	{mso-style-priority:99;
	mso-style-link:"Balloon Text Char";
	margin:0cm;
	margin-bottom:.0001pt;
	font-size:8.0pt;
	font-family:"Tahoma","sans-serif";}
span.EmailStyle17
	{mso-style-type:personal-compose;
	font-family:"Calibri","sans-serif";
	color:windowtext;}
span.BalloonTextChar
	{mso-style-name:"Balloon Text Char";
	mso-style-priority:99;
	mso-style-link:"Balloon Text";
	font-family:"Tahoma","sans-serif";}
span.Heading1Char
	{mso-style-name:"Heading 1 Char";
	mso-style-priority:9;
	mso-style-link:"Heading 1";
	font-family:"Times New Roman","serif";
	font-weight:bold;}
span.Heading2Char
	{mso-style-name:"Heading 2 Char";
	mso-style-priority:9;
	mso-style-link:"Heading 2";
	font-family:"Times New Roman","serif";
	font-weight:bold;}
span.apple-converted-space
	{mso-style-name:apple-converted-space;}
.MsoChpDefault
	{mso-style-type:export-only;
	font-family:"Calibri","sans-serif";}
@page WordSection1
	{size:612.0pt 792.0pt;
	margin:70.85pt 70.85pt 70.85pt 70.85pt;}
div.WordSection1
	{page:WordSection1;}
/* List Definitions */
@list l0
	{mso-list-id:15347732;
	mso-list-template-ids:1149267428;}
@list l1
	{mso-list-id:298346911;
	mso-list-template-ids:-1990059266;}
@list l2
	{mso-list-id:410661324;
	mso-list-template-ids:862720772;}
@list l3
	{mso-list-id:419913662;
	mso-list-template-ids:1939343024;}
@list l4
	{mso-list-id:755715481;
	mso-list-template-ids:1539483424;}
@list l4:level1
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:36.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l4:level2
	{mso-level-number-format:bullet;
	mso-level-text:o;
	mso-level-tab-stop:72.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:"Courier New";
	mso-bidi-font-family:"Times New Roman";}
@list l4:level3
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:108.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l4:level4
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:144.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l4:level5
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:180.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l4:level6
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:216.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l4:level7
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:252.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l4:level8
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:288.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l4:level9
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:324.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l5
	{mso-list-id:795804602;
	mso-list-template-ids:1885534928;}
@list l5:level1
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:36.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l5:level2
	{mso-level-number-format:bullet;
	mso-level-text:o;
	mso-level-tab-stop:72.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:"Courier New";
	mso-bidi-font-family:"Times New Roman";}
@list l5:level3
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:108.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l5:level4
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:144.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l5:level5
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:180.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l5:level6
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:216.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l5:level7
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:252.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l5:level8
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:288.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l5:level9
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:324.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l6
	{mso-list-id:1308902986;
	mso-list-template-ids:1846212050;}
@list l7
	{mso-list-id:1514879373;
	mso-list-template-ids:585418842;}
@list l7:level1
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:36.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l7:level2
	{mso-level-number-format:bullet;
	mso-level-text:o;
	mso-level-tab-stop:72.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:"Courier New";
	mso-bidi-font-family:"Times New Roman";}
@list l7:level3
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:108.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l7:level4
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:144.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l7:level5
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:180.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l7:level6
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:216.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l7:level7
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:252.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l7:level8
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:288.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l7:level9
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:324.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l8
	{mso-list-id:1735615244;
	mso-list-template-ids:612942284;}
@list l9
	{mso-list-id:1863981381;
	mso-list-template-ids:709014192;}
@list l10
	{mso-list-id:1916742795;
	mso-list-template-ids:798656480;}
@list l10:level1
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:36.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l10:level2
	{mso-level-number-format:bullet;
	mso-level-text:o;
	mso-level-tab-stop:72.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:"Courier New";
	mso-bidi-font-family:"Times New Roman";}
@list l10:level3
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:108.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l10:level4
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:144.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l10:level5
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:180.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l10:level6
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:216.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l10:level7
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:252.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l10:level8
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:288.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l10:level9
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:324.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l11
	{mso-list-id:2016230055;
	mso-list-template-ids:-1235608234;}
@list l11:level1
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:36.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l11:level2
	{mso-level-number-format:bullet;
	mso-level-text:o;
	mso-level-tab-stop:72.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:"Courier New";
	mso-bidi-font-family:"Times New Roman";}
@list l11:level3
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:108.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l11:level4
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:144.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l11:level5
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:180.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l11:level6
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:216.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l11:level7
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:252.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l11:level8
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:288.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l11:level9
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:324.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l12
	{mso-list-id:2076000766;
	mso-list-template-ids:-758356318;}
@list l12:level1
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:36.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l12:level2
	{mso-level-number-format:bullet;
	mso-level-text:o;
	mso-level-tab-stop:72.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:"Courier New";
	mso-bidi-font-family:"Times New Roman";}
@list l12:level3
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:108.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l12:level4
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:144.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l12:level5
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:180.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l12:level6
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:216.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l12:level7
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:252.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l12:level8
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:288.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l12:level9
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:324.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
ol
	{margin-bottom:0cm;}
ul
	{margin-bottom:0cm;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]-->
      <div class="WordSection1">
        <h1
style="mso-margin-top-alt:0cm;margin-right:0cm;margin-bottom:7.5pt;margin-left:0cm;background:white"><span
style="font-size:18.0pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333;font-weight:normal">Minutes
            Webex 20th May 2014, 6TiSCH Security<o:p></o:p></span></h1>
        <div class="MsoNormal"
style="mso-margin-top-alt:15.0pt;margin-right:0cm;margin-bottom:15.0pt;margin-left:0cm;text-align:center"
          align="center">
          <hr style="color:#333333" align="center" noshade="noshade"
            size="3" width="100%">
        </div>
        <h2
          style="mso-margin-top-alt:15.0pt;margin-right:0cm;margin-bottom:0cm;margin-left:0cm;margin-bottom:.0001pt;background:white;orphans:
          auto;text-align:start;widows: auto;-webkit-text-stroke-width:
          0px;word-spacing:0px"
          id="markdown-header-taking-notes-using-etherpad">
          <span
style="font-size:15.0pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333;font-weight:normal">Taking
            notes<span class="apple-converted-space">&nbsp;</span><em><span
                style="font-family:&quot;Arial&quot;,&quot;sans-serif&quot;">(using
                Etherpad)</span></em><o:p></o:p></span></h2>
        <p class="MsoNormal"
          style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;margin-left:0cm;text-indent:-18.0pt;line-height:15.0pt;mso-list:l1
          level1 lfo7;background:white">
          <!--[if !supportLists]--><span
style="font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333"><span
              style="mso-list:Ignore">1.<span style="font:7.0pt
                &quot;Times New Roman&quot;">&nbsp;&nbsp;&nbsp;&nbsp;
              </span></span></span><!--[endif]--><span
style="font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">Pascal
            Thubert<o:p></o:p></span></p>
        <h2
          style="mso-margin-top-alt:15.0pt;margin-right:0cm;margin-bottom:0cm;margin-left:0cm;margin-bottom:.0001pt;background:white;orphans:
          auto;text-align:start;widows: auto;-webkit-text-stroke-width:
          0px;word-spacing:0px"
          id="markdown-header-present-alphabetically">
          <span
style="font-size:15.0pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333;font-weight:normal">Present<span
              class="apple-converted-space">&nbsp;</span><em><span
                style="font-family:&quot;Arial&quot;,&quot;sans-serif&quot;">(alphabetically)</span></em><o:p></o:p></span></h2>
        <p class="MsoNormal"
          style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;margin-left:0cm;text-indent:-18.0pt;line-height:15.0pt;mso-list:l0
          level1 lfo8;background:white">
          <!--[if !supportLists]--><span
style="font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333"><span
              style="mso-list:Ignore">1.<span style="font:7.0pt
                &quot;Times New Roman&quot;">&nbsp;&nbsp;&nbsp;&nbsp;
              </span></span></span><!--[endif]--><span
style="font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">Hank
            Mauldin<o:p></o:p></span></p>
        <p class="MsoNormal"
          style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;margin-left:0cm;text-indent:-18.0pt;line-height:15.0pt;mso-list:l0
          level1 lfo8;background:white">
          <!--[if !supportLists]--><span
style="font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333"><span
              style="mso-list:Ignore">2.<span style="font:7.0pt
                &quot;Times New Roman&quot;">&nbsp;&nbsp;&nbsp;&nbsp;
              </span></span></span><!--[endif]--><span
style="font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">Michael
            Behringer<o:p></o:p></span></p>
        <p class="MsoNormal"
          style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;margin-left:0cm;text-indent:-18.0pt;line-height:15.0pt;mso-list:l0
          level1 lfo8;background:white">
          <!--[if !supportLists]--><span
style="font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333"><span
              style="mso-list:Ignore">3.<span style="font:7.0pt
                &quot;Times New Roman&quot;">&nbsp;&nbsp;&nbsp;&nbsp;
              </span></span></span><!--[endif]--><span
style="font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">Michael
            Richardson<o:p></o:p></span></p>
        <p class="MsoNormal"
          style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;margin-left:0cm;text-indent:-18.0pt;line-height:15.0pt;mso-list:l0
          level1 lfo8;background:white">
          <!--[if !supportLists]--><span
style="font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333"><span
              style="mso-list:Ignore">4.<span style="font:7.0pt
                &quot;Times New Roman&quot;">&nbsp;&nbsp;&nbsp;&nbsp;
              </span></span></span><!--[endif]--><span
style="font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">Maik
            Seewald<o:p></o:p></span></p>
        <p class="MsoNormal"
          style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;margin-left:0cm;text-indent:-18.0pt;line-height:15.0pt;mso-list:l0
          level1 lfo8;background:white">
          <!--[if !supportLists]--><span
style="font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333"><span
              style="mso-list:Ignore">5.<span style="font:7.0pt
                &quot;Times New Roman&quot;">&nbsp;&nbsp;&nbsp;&nbsp;
              </span></span></span><!--[endif]--><span
style="font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">Ren&eacute;
            Struik<o:p></o:p></span></p>
        <p class="MsoNormal"
          style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;margin-left:0cm;text-indent:-18.0pt;line-height:15.0pt;mso-list:l0
          level1 lfo8;background:white">
          <!--[if !supportLists]--><span
style="font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333"><span
              style="mso-list:Ignore">6.<span style="font:7.0pt
                &quot;Times New Roman&quot;">&nbsp;&nbsp;&nbsp;&nbsp;
              </span></span></span><!--[endif]--><span
style="font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">Tom
            Phinney<o:p></o:p></span></p>
        <p class="MsoNormal"
          style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;margin-left:0cm;text-indent:-18.0pt;line-height:15.0pt;mso-list:l0
          level1 lfo8;background:white">
          <!--[if !supportLists]--><span
style="font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333"><span
              style="mso-list:Ignore">7.<span style="font:7.0pt
                &quot;Times New Roman&quot;">&nbsp;&nbsp;&nbsp;&nbsp;
              </span></span></span><!--[endif]--><span
style="font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">Yoshihiro
            Ohba<o:p></o:p></span></p>
        <h2
          style="mso-margin-top-alt:15.0pt;margin-right:0cm;margin-bottom:0cm;margin-left:0cm;margin-bottom:.0001pt;background:white;orphans:
          auto;text-align:start;widows: auto;-webkit-text-stroke-width:
          0px;word-spacing:0px" id="markdown-header-recording">
          <span
style="font-size:15.0pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333;font-weight:normal">Recording<o:p></o:p></span></h2>
        <p class="MsoNormal"
          style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;margin-left:0cm;text-indent:-18.0pt;line-height:15.0pt;mso-list:l5
          level1 lfo9;background:white">
          <!--[if !supportLists]--><span
            style="font-size:10.0pt;font-family:Symbol;color:#333333"><span
              style="mso-list:Ignore">&middot;<span style="font:7.0pt
                &quot;Times New Roman&quot;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
              </span></span></span><!--[endif]--><span
style="font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333"><a
              moz-do-not-send="true"
href="https://cisco.webex.com/ciscosales/lsr.php?RCID=cf234f58e8f94d2f86fbe15e7d6862df"><span
                style="color:#3B73AF">Webex recording</span></a><o:p></o:p></span></p>
        <h2
          style="mso-margin-top-alt:15.0pt;margin-right:0cm;margin-bottom:0cm;margin-left:0cm;margin-bottom:.0001pt;background:white;orphans:
          auto;text-align:start;widows: auto;-webkit-text-stroke-width:
          0px;word-spacing:0px" id="markdown-header-agenda">
          <span
style="font-size:15.0pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333;font-weight:normal">Agenda<o:p></o:p></span></h2>
        <p class="MsoNormal"
          style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;margin-left:0cm;text-indent:-18.0pt;line-height:15.0pt;mso-list:l6
          level1 lfo10;background:white">
          <!--[if !supportLists]--><span
style="font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333"><span
              style="mso-list:Ignore">1.<span style="font:7.0pt
                &quot;Times New Roman&quot;">&nbsp;&nbsp;&nbsp;&nbsp;
              </span></span></span><!--[endif]--><span
style="font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">Look
            at Join Protocol<o:p></o:p></span></p>
        <h2
          style="mso-margin-top-alt:15.0pt;margin-right:0cm;margin-bottom:0cm;margin-left:0cm;margin-bottom:.0001pt;background:white;orphans:
          auto;text-align:start;widows: auto;-webkit-text-stroke-width:
          0px;word-spacing:0px" id="markdown-header-action-items">
          <span
style="font-size:15.0pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333;font-weight:normal">Action
            Items<o:p></o:p></span></h2>
        <p class="MsoNormal"
          style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;margin-left:0cm;text-indent:-18.0pt;line-height:15.0pt;mso-list:l2
          level1 lfo11;background:white">
          <!--[if !supportLists]--><span
style="font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333"><span
              style="mso-list:Ignore">1.<span style="font:7.0pt
                &quot;Times New Roman&quot;">&nbsp;&nbsp;&nbsp;&nbsp;
              </span></span></span><!--[endif]--><span
style="font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">Michael
            R. to suggest to the list a review of draft piro<o:p></o:p></span></p>
        <p class="MsoNormal"
          style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;margin-left:0cm;text-indent:-18.0pt;line-height:15.0pt;mso-list:l2
          level1 lfo11;background:white">
          <!--[if !supportLists]--><span
style="font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333"><span
              style="mso-list:Ignore">2.<span style="font:7.0pt
                &quot;Times New Roman&quot;">&nbsp;&nbsp;&nbsp;&nbsp;
              </span></span></span><!--[endif]--><span
style="font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">Michael
            B. to check with Max Pritikin about format on authorization
            token.<o:p></o:p></span></p>
        <h2
          style="mso-margin-top-alt:15.0pt;margin-right:0cm;margin-bottom:0cm;margin-left:0cm;margin-bottom:.0001pt;background:white;orphans:
          auto;text-align:start;widows: auto;-webkit-text-stroke-width:
          0px;word-spacing:0px" id="markdown-header-minutes">
          <span
style="font-size:15.0pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333;font-weight:normal">Minutes<o:p></o:p></span></h2>
        <p class="MsoNormal"
          style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;margin-left:0cm;text-indent:-18.0pt;line-height:15.0pt;mso-list:l11
          level1 lfo12;background:white">
          <!--[if !supportLists]--><span
            style="font-size:10.0pt;font-family:Symbol;color:#333333"><span
              style="mso-list:Ignore">&middot;<span style="font:7.0pt
                &quot;Times New Roman&quot;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
              </span></span></span><!--[endif]--><em><span
style="font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">[07.10]</span></em><span
            class="apple-converted-space"><span
style="font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">&nbsp;</span></span><span
style="font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">Meeting

            starts<o:p></o:p></span></p>
        <p
          style="mso-margin-top-alt:7.5pt;margin-right:0cm;margin-bottom:0cm;margin-left:0cm;margin-bottom:.0001pt;line-height:15.0pt;background:white;word-wrap:
          break-word;orphans: auto;text-align:start;widows:
          auto;-webkit-text-stroke-width: 0px;word-spacing:0px">
          <span
style="font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">Michael
            Richardson: network manager programs the device, no
            particular authorization of the network to the device, nor
            way for device to prove it is authorized apart from having
            the join key provisioned<o:p></o:p></span></p>
        <p
          style="mso-margin-top-alt:7.5pt;margin-right:0cm;margin-bottom:0cm;margin-left:0cm;margin-bottom:.0001pt;line-height:15.0pt;background:white;word-wrap:
          break-word;orphans: auto;text-align:start;widows:
          auto;-webkit-text-stroke-width: 0px;word-spacing:0px">
          <span
style="font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">Ren&eacute;
            Struik: unless missing something, need size of configuration
            messages. How to get tag names in the device and map that
            into 802.15.4 MAC addresses. Details we do not really have.
            Unclear how device can discover the network. Ties in AR
            certificate issue<o:p></o:p></span></p>
        <p
          style="mso-margin-top-alt:7.5pt;margin-right:0cm;margin-bottom:0cm;margin-left:0cm;margin-bottom:.0001pt;line-height:15.0pt;background:white;word-wrap:
          break-word;orphans: auto;text-align:start;widows:
          auto;-webkit-text-stroke-width: 0px;word-spacing:0px">
          <span
style="font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">Michael
            Richardson: problem exists regardless of actual enrolment
            process.<o:p></o:p></span></p>
        <p
          style="mso-margin-top-alt:7.5pt;margin-right:0cm;margin-bottom:0cm;margin-left:0cm;margin-bottom:.0001pt;line-height:15.0pt;background:white;word-wrap:
          break-word;orphans: auto;text-align:start;widows:
          auto;-webkit-text-stroke-width: 0px;word-spacing:0px">
          <span
style="font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">Ren&eacute;
            Struik: there is also a control element when certificate can
            be used<o:p></o:p></span></p>
        <p
          style="mso-margin-top-alt:7.5pt;margin-right:0cm;margin-bottom:0cm;margin-left:0cm;margin-bottom:.0001pt;line-height:15.0pt;background:white;word-wrap:
          break-word;orphans: auto;text-align:start;widows:
          auto;-webkit-text-stroke-width: 0px;word-spacing:0px">
          <span
style="font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">Michael
            Richardson: sent message on Wile coyote; is it realistic?<o:p></o:p></span></p>
        <p
          style="mso-margin-top-alt:7.5pt;margin-right:0cm;margin-bottom:0cm;margin-left:0cm;margin-bottom:.0001pt;line-height:15.0pt;background:white;word-wrap:
          break-word;orphans: auto;text-align:start;widows:
          auto;-webkit-text-stroke-width: 0px;word-spacing:0px">
          <span
style="font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">Ren&eacute;
            Struik: quick feedback. say vendor generates cert for bunch
            of devices and it goes along a chain and then more
            attributes allow link back to factory. works, does not have
            to be AR certificate<o:p></o:p></span></p>
        <p
          style="mso-margin-top-alt:7.5pt;margin-right:0cm;margin-bottom:0cm;margin-left:0cm;margin-bottom:.0001pt;line-height:15.0pt;background:white;word-wrap:
          break-word;orphans: auto;text-align:start;widows:
          auto;-webkit-text-stroke-width: 0px;word-spacing:0px">
          <span
style="font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">Michael
            Richardson: I expected the kind of certificate I describe in
            AR but it is not the point of AR. They do not even specify
            the format of device ID. AR is really about an API not about
            content of certificate apart from signature algorithm for
            which they have requirements. They do not even define their
            own extensions. One extension with multiple values<o:p></o:p></span></p>
        <p
          style="mso-margin-top-alt:7.5pt;margin-right:0cm;margin-bottom:0cm;margin-left:0cm;margin-bottom:.0001pt;line-height:15.0pt;background:white;word-wrap:
          break-word;orphans: auto;text-align:start;widows:
          auto;-webkit-text-stroke-width: 0px;word-spacing:0px">
          <span
style="font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">Michael
            Richardson if you use secure enrolment, you can replace the
            cert but you still need to validate the device. Need Michael
            B. and Max to describe their token<o:p></o:p></span></p>
        <p
          style="mso-margin-top-alt:7.5pt;margin-right:0cm;margin-bottom:0cm;margin-left:0cm;margin-bottom:.0001pt;line-height:15.0pt;background:white;word-wrap:
          break-word;orphans: auto;text-align:start;widows:
          auto;-webkit-text-stroke-width: 0px;word-spacing:0px">
          <span
style="font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">Michael
            Behringer: AR or not AR? process is about an institution
            that owns a device and has a secured relationship based on a
            certificate that tit signed. Can be 1AR or anything, e.g. an
            institution which owned the device before. Need that cert
            from old organization to help bootstrap in new organization.<o:p></o:p></span></p>
        <p
          style="mso-margin-top-alt:7.5pt;margin-right:0cm;margin-bottom:0cm;margin-left:0cm;margin-bottom:.0001pt;line-height:15.0pt;background:white;word-wrap:
          break-word;orphans: auto;text-align:start;widows:
          auto;-webkit-text-stroke-width: 0px;word-spacing:0px">
          <span
style="font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">Michael
            Richardson: did you define how the authorization token can
            be passed in an interoperable fashion<o:p></o:p></span></p>
        <p
          style="mso-margin-top-alt:7.5pt;margin-right:0cm;margin-bottom:0cm;margin-left:0cm;margin-bottom:.0001pt;line-height:15.0pt;background:white;word-wrap:
          break-word;orphans: auto;text-align:start;widows:
          auto;-webkit-text-stroke-width: 0px;word-spacing:0px">
          <span
style="font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">Michael
            Behringer: leverage secure relationship between vendor and
            device to pass a signed message to the device<o:p></o:p></span></p>
        <p
          style="mso-margin-top-alt:7.5pt;margin-right:0cm;margin-bottom:0cm;margin-left:0cm;margin-bottom:.0001pt;line-height:15.0pt;background:white;word-wrap:
          break-word;orphans: auto;text-align:start;widows:
          auto;-webkit-text-stroke-width: 0px;word-spacing:0px">
          <span
style="font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">Michael
            Richardson: does it bind to the new owner? which way, not
            subject to standardization or is it?<o:p></o:p></span></p>
        <p
          style="mso-margin-top-alt:7.5pt;margin-right:0cm;margin-bottom:0cm;margin-left:0cm;margin-bottom:.0001pt;line-height:15.0pt;background:white;word-wrap:
          break-word;orphans: auto;text-align:start;widows:
          auto;-webkit-text-stroke-width: 0px;word-spacing:0px">
          <span
style="font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">Michael
            Behringer: May not need standard, but if multivendor network
            user would like a common format. between vendor and new
            device can be proprietary<o:p></o:p></span></p>
        <p
          style="mso-margin-top-alt:7.5pt;margin-right:0cm;margin-bottom:0cm;margin-left:0cm;margin-bottom:.0001pt;line-height:15.0pt;background:white;word-wrap:
          break-word;orphans: auto;text-align:start;widows:
          auto;-webkit-text-stroke-width: 0px;word-spacing:0px">
          <span
style="font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">Michael
            Richardson: need ot define when how the token is
            transported, and that is not end to end. reasons of trust,
            rate limit etc...<o:p></o:p></span></p>
        <p
          style="mso-margin-top-alt:7.5pt;margin-right:0cm;margin-bottom:0cm;margin-left:0cm;margin-bottom:.0001pt;line-height:15.0pt;background:white;word-wrap:
          break-word;orphans: auto;text-align:start;widows:
          auto;-webkit-text-stroke-width: 0px;word-spacing:0px">
          <span
style="font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">Michael
            Behringer: new device sends along a nonce and expect that
            nonce in response from vendor site; without nonce, token
            could come from the past. Both models are required in the
            market. Some want fresh, others e.g. military there cannot
            be comm at the deployment time.<o:p></o:p></span></p>
        <p
          style="mso-margin-top-alt:7.5pt;margin-right:0cm;margin-bottom:0cm;margin-left:0cm;margin-bottom:.0001pt;line-height:15.0pt;background:white;word-wrap:
          break-word;orphans: auto;text-align:start;widows:
          auto;-webkit-text-stroke-width: 0px;word-spacing:0px">
          <span
style="font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">Michael
            Richardson: content of token may or not be standard.
            transport of token must be standard.<o:p></o:p></span></p>
        <p
          style="mso-margin-top-alt:7.5pt;margin-right:0cm;margin-bottom:0cm;margin-left:0cm;margin-bottom:.0001pt;line-height:15.0pt;background:white;word-wrap:
          break-word;orphans: auto;text-align:start;widows:
          auto;-webkit-text-stroke-width: 0px;word-spacing:0px">
          <span
style="font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">Michael
            Richardson: using RFC 3779 would address cert that had 1AR
            IdevID in them. need a range in the certificate otherwise
            one certificate per device<o:p></o:p></span></p>
        <p
          style="mso-margin-top-alt:7.5pt;margin-right:0cm;margin-bottom:0cm;margin-left:0cm;margin-bottom:.0001pt;line-height:15.0pt;background:white;word-wrap:
          break-word;orphans: auto;text-align:start;widows:
          auto;-webkit-text-stroke-width: 0px;word-spacing:0px">
          <span
style="font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">Michael
            Behringer: token or certificate?<o:p></o:p></span></p>
        <p
          style="mso-margin-top-alt:7.5pt;margin-right:0cm;margin-bottom:0cm;margin-left:0cm;margin-bottom:.0001pt;line-height:15.0pt;background:white;word-wrap:
          break-word;orphans: auto;text-align:start;widows:
          auto;-webkit-text-stroke-width: 0px;word-spacing:0px">
          <span
style="font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">Michael
            Richardson if the token is a certificate need a way to
            delegate down the chain. But breach along the way breaches
            it all below. no good. Do you have to maintain a cert for
            every device?<o:p></o:p></span></p>
        <p
          style="mso-margin-top-alt:7.5pt;margin-right:0cm;margin-bottom:0cm;margin-left:0cm;margin-bottom:.0001pt;line-height:15.0pt;background:white;word-wrap:
          break-word;orphans: auto;text-align:start;widows:
          auto;-webkit-text-stroke-width: 0px;word-spacing:0px">
          <span
style="font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">Michael
            Behringer: that's the starting point. You assume that's a
            scalability issue at some point right<o:p></o:p></span></p>
        <p
          style="mso-margin-top-alt:7.5pt;margin-right:0cm;margin-bottom:0cm;margin-left:0cm;margin-bottom:.0001pt;line-height:15.0pt;background:white;word-wrap:
          break-word;orphans: auto;text-align:start;widows:
          auto;-webkit-text-stroke-width: 0px;word-spacing:0px">
          <span
style="font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">Michael
            Richardson: provisioning trouble is possible. Tracking by
            bulk could be more palatable<o:p></o:p></span></p>
        <p
          style="mso-margin-top-alt:7.5pt;margin-right:0cm;margin-bottom:0cm;margin-left:0cm;margin-bottom:.0001pt;line-height:15.0pt;background:white;word-wrap:
          break-word;orphans: auto;text-align:start;widows:
          auto;-webkit-text-stroke-width: 0px;word-spacing:0px">
          <span
style="font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">Michael
            Behringer: if name space is aggregatable could work. In
            early approach, token is not a cert and stealing the token
            does not help.<o:p></o:p></span></p>
        <p
          style="mso-margin-top-alt:7.5pt;margin-right:0cm;margin-bottom:0cm;margin-left:0cm;margin-bottom:.0001pt;line-height:15.0pt;background:white;word-wrap:
          break-word;orphans: auto;text-align:start;widows:
          auto;-webkit-text-stroke-width: 0px;word-spacing:0px">
          <span
style="font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">Michael
            Richardson: anxious about spare parts that did not join, and
            go unserviceable<o:p></o:p></span></p>
        <p
          style="mso-margin-top-alt:7.5pt;margin-right:0cm;margin-bottom:0cm;margin-left:0cm;margin-bottom:.0001pt;line-height:15.0pt;background:white;word-wrap:
          break-word;orphans: auto;text-align:start;widows:
          auto;-webkit-text-stroke-width: 0px;word-spacing:0px">
          <span
style="font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">Michael
            Behringer: yes, we can take the req in draft-pritikin<o:p></o:p></span></p>
        <p
          style="mso-margin-top-alt:7.5pt;margin-right:0cm;margin-bottom:0cm;margin-left:0cm;margin-bottom:.0001pt;line-height:15.0pt;background:white;word-wrap:
          break-word;orphans: auto;text-align:start;widows:
          auto;-webkit-text-stroke-width: 0px;word-spacing:0px">
          <span
style="font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">Michael
            Richardson proposing do something like RFC 3779. It as AS
            numbers to allow reg to delegate using cert; these are live
            devIDs from a pool. should look at that doc and we could
            change all AS to IdevID and we'd be done.<o:p></o:p></span></p>
        <p
          style="mso-margin-top-alt:7.5pt;margin-right:0cm;margin-bottom:0cm;margin-left:0cm;margin-bottom:.0001pt;line-height:15.0pt;background:white;word-wrap:
          break-word;orphans: auto;text-align:start;widows:
          auto;-webkit-text-stroke-width: 0px;word-spacing:0px">
          <span
style="font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">Michael
            Behringer: sounds like an idea we'll look at it<o:p></o:p></span></p>
        <p
          style="mso-margin-top-alt:7.5pt;margin-right:0cm;margin-bottom:0cm;margin-left:0cm;margin-bottom:.0001pt;line-height:15.0pt;background:white;word-wrap:
          break-word;orphans: auto;text-align:start;widows:
          auto;-webkit-text-stroke-width: 0px;word-spacing:0px">
          <span
style="font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">Michael
            Richardson: draft pritikin does not tell whether the
            enrolment allow transport of authorization token back and
            forth and then the cert for the TLS transport can be
            validated. Then you have a secure transport and can enrol
            replacing the vendor cert with a domain cert.<o:p></o:p></span></p>
        <p
          style="mso-margin-top-alt:7.5pt;margin-right:0cm;margin-bottom:0cm;margin-left:0cm;margin-bottom:.0001pt;line-height:15.0pt;background:white;word-wrap:
          break-word;orphans: auto;text-align:start;widows:
          auto;-webkit-text-stroke-width: 0px;word-spacing:0px">
          <span
style="font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">Michael
            Behringer: refer to a mail by Max Pritikin
            "[6tisch-security] a different explanation of autonomic" .<o:p></o:p></span></p>
        <p
          style="mso-margin-top-alt:7.5pt;margin-right:0cm;margin-bottom:0cm;margin-left:0cm;margin-bottom:.0001pt;line-height:15.0pt;background:white;word-wrap:
          break-word;orphans: auto;text-align:start;widows:
          auto;-webkit-text-stroke-width: 0px;word-spacing:0px">
          <span
style="font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">Michael
            Richardson: where is the process ?<o:p></o:p></span></p>
        <p
          style="mso-margin-top-alt:7.5pt;margin-right:0cm;margin-bottom:0cm;margin-left:0cm;margin-bottom:.0001pt;line-height:15.0pt;background:white;word-wrap:
          break-word;orphans: auto;text-align:start;widows:
          auto;-webkit-text-stroke-width: 0px;word-spacing:0px">
          <span
style="font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">Michael
            Behringer: explained in message. We need to mail this down
            so people understand.<o:p></o:p></span></p>
        <p
          style="mso-margin-top-alt:7.5pt;margin-right:0cm;margin-bottom:0cm;margin-left:0cm;margin-bottom:.0001pt;line-height:15.0pt;background:white;word-wrap:
          break-word;orphans: auto;text-align:start;widows:
          auto;-webkit-text-stroke-width: 0px;word-spacing:0px">
          <span
style="font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">Michael
            Richardson: non normative<o:p></o:p></span></p>
        <p
          style="mso-margin-top-alt:7.5pt;margin-right:0cm;margin-bottom:0cm;margin-left:0cm;margin-bottom:.0001pt;line-height:15.0pt;background:white;word-wrap:
          break-word;orphans: auto;text-align:start;widows:
          auto;-webkit-text-stroke-width: 0px;word-spacing:0px">
          <span
style="font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">Pascal
            Thubert: yes that is what we want in the security
            architecture<o:p></o:p></span></p>
        <p
          style="mso-margin-top-alt:7.5pt;margin-right:0cm;margin-bottom:0cm;margin-left:0cm;margin-bottom:.0001pt;line-height:15.0pt;background:white;word-wrap:
          break-word;orphans: auto;text-align:start;widows:
          auto;-webkit-text-stroke-width: 0px;word-spacing:0px">
          <span
style="font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">Michael
            Behringer I need to leave soon<o:p></o:p></span></p>
        <p
          style="mso-margin-top-alt:7.5pt;margin-right:0cm;margin-bottom:0cm;margin-left:0cm;margin-bottom:.0001pt;line-height:15.0pt;background:white;word-wrap:
          break-word;orphans: auto;text-align:start;widows:
          auto;-webkit-text-stroke-width: 0px;word-spacing:0px">
          <span
style="font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">Michael
            Richardson: I answered to draft piro descries low level
            stuff. I want to encourage people to read and suggest that
            this becomes WG doc in L2 layer 2 security. It is a very
            good draft. We may need to change the authorization but
            after that, great stuff can be found. Should be WG doc
            somewhere.<o:p></o:p></span></p>
        <p
          style="mso-margin-top-alt:7.5pt;margin-right:0cm;margin-bottom:0cm;margin-left:0cm;margin-bottom:.0001pt;line-height:15.0pt;background:white;word-wrap:
          break-word;orphans: auto;text-align:start;widows:
          auto;-webkit-text-stroke-width: 0px;word-spacing:0px">
          <span
style="font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">Ren&eacute;
            Struik: thoughts appreciated on mail I sent today<o:p></o:p></span></p>
        <p
          style="mso-margin-top-alt:7.5pt;margin-right:0cm;margin-bottom:0cm;margin-left:0cm;margin-bottom:.0001pt;line-height:15.0pt;background:white;word-wrap:
          break-word;orphans: auto;text-align:start;widows:
          auto;-webkit-text-stroke-width: 0px;word-spacing:0px">
          <span
style="font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">Pascal:
            Next call on Tuesday next week same time<o:p></o:p></span></p>
        <p class="MsoNormal"
          style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;margin-left:0cm;text-indent:-18.0pt;line-height:15.0pt;mso-list:l10
          level1 lfo13;background:white">
          <!--[if !supportLists]--><span
            style="font-size:10.0pt;font-family:Symbol;color:#333333"><span
              style="mso-list:Ignore">&middot;<span style="font:7.0pt
                &quot;Times New Roman&quot;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
              </span></span></span><!--[endif]--><em><span
style="font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">[08.06]</span></em><span
            class="apple-converted-space"><span
style="font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">&nbsp;</span></span><span
style="font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">meeting

            ends<o:p></o:p></span></p>
        <p
          style="mso-margin-top-alt:7.5pt;margin-right:0cm;margin-bottom:0cm;margin-left:0cm;margin-bottom:.0001pt;line-height:15.0pt;background:white;word-wrap:
          break-word;orphans: auto;text-align:start;widows:
          auto;-webkit-text-stroke-width: 0px;word-spacing:0px">
          <span
style="font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">======<o:p></o:p></span></p>
        <p class="MsoNormal"><o:p>&nbsp;</o:p></p>
      </div>
      <br>
      <fieldset class="mimeAttachmentHeader"></fieldset>
      <br>
      <pre wrap="">_______________________________________________
6tisch mailing list
<a class="moz-txt-link-abbreviated" href="mailto:6tisch@ietf.org">6tisch@ietf.org</a>
<a class="moz-txt-link-freetext" href="https://www.ietf.org/mailman/listinfo/6tisch">https://www.ietf.org/mailman/listinfo/6tisch</a>
</pre>
    </blockquote>
    <br>
    <br>
    <pre class="moz-signature" cols="72">-- 
email: <a class="moz-txt-link-abbreviated" href="mailto:rstruik.ext@gmail.com">rstruik.ext@gmail.com</a> | Skype: rstruik
cell: +1 (647) 867-5658 | US: +1 (415) 690-7363</pre>
  </body>
</html>

--------------050002050903010104000808--


From nobody Wed May 21 02:22:53 2014
Return-Path: <pthubert@cisco.com>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 960081A0496 for <6tisch-security@ietfa.amsl.com>; Wed, 21 May 2014 02:22:51 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -15.151
X-Spam-Level: 
X-Spam-Status: No, score=-15.151 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_HI=-5, RP_MATCHES_RCVD=-0.651, SPF_PASS=-0.001, USER_IN_DEF_DKIM_WL=-7.5] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id rNnCUiQUoLMW for <6tisch-security@ietfa.amsl.com>; Wed, 21 May 2014 02:22:46 -0700 (PDT)
Received: from alln-iport-8.cisco.com (alln-iport-8.cisco.com [173.37.142.95]) (using TLSv1 with cipher RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id BC5701A04A1 for <6tisch-security@ietf.org>; Wed, 21 May 2014 02:22:44 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cisco.com; i=@cisco.com; l=60477; q=dns/txt; s=iport; t=1400664164; x=1401873764; h=from:to:subject:date:message-id:references:in-reply-to: mime-version; bh=yWyQ2bQjEHY9ca8nEXl8Rg1DPOvbkvsmHOhAYZEYA7k=; b=B+tJlNRVAKk41ClibsTPqSD6oLik1pX/dZx5EXEQEUIQOIwQVVQmmEOm AumOQFH0IbEoUcf4wDsc4k/ZyaYJv7wNzNFmywxQzLjy22syL1kIvipis dY+zN8SaRXZBgA0wKygH9e/z866tRnz4/Oya3lR08DsIFy+04EYG/7VZS Q=;
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-Anti-Spam-Result: AhUFAFlvfFOtJV2c/2dsb2JhbAA/FwOCQkRRWLxeAYZpUQGBERZ0giUBAQEEAQEBKkEEFwIBCA4DAQMBAQsWAQIEByEGCxQDBggBAQQBEggBiCQDEQ02zkENhiQXiTCCEAF4gSgLCwUCAR4fAgwKAQYLgxqBFQSJZoJUAok0ggmPJ4VygXiBQG2BAgEeBhw
X-IronPort-AV: E=Sophos; i="4.98,879,1392163200"; d="scan'208,217"; a="45802551"
Received: from rcdn-core-5.cisco.com ([173.37.93.156]) by alln-iport-8.cisco.com with ESMTP; 21 May 2014 09:22:42 +0000
Received: from xhc-aln-x01.cisco.com (xhc-aln-x01.cisco.com [173.36.12.75]) by rcdn-core-5.cisco.com (8.14.5/8.14.5) with ESMTP id s4L9MgKM020515 (version=TLSv1/SSLv3 cipher=AES128-SHA bits=128 verify=FAIL); Wed, 21 May 2014 09:22:42 GMT
Received: from xmb-rcd-x01.cisco.com ([169.254.1.6]) by xhc-aln-x01.cisco.com ([173.36.12.75]) with mapi id 14.03.0123.003; Wed, 21 May 2014 04:22:42 -0500
From: "Pascal Thubert (pthubert)" <pthubert@cisco.com>
To: Rene Struik <rstruik.ext@gmail.com>, tisch-security <6tisch-security@ietf.org>
Thread-Topic: (review draft-piro-6tisch-security-issues-01) Re: [6tisch] Minutes Webex 20th May 2014, 6TiSCH Security
Thread-Index: Ac90QWctUMvrSZJcSSy4AfdIpFS0yQAM6C+AABg6yTA=
Date: Wed, 21 May 2014 09:22:42 +0000
Deferred-Delivery: Wed, 21 May 2014 09:22:00 +0000
Message-ID: <E045AECD98228444A58C61C200AE1BD842672168@xmb-rcd-x01.cisco.com>
References: <E045AECD98228444A58C61C200AE1BD84266FEED@xmb-rcd-x01.cisco.com> <537B8705.1090609@gmail.com>
In-Reply-To: <537B8705.1090609@gmail.com>
Accept-Language: fr-FR, en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
x-originating-ip: [10.49.80.52]
Content-Type: multipart/alternative; boundary="_000_E045AECD98228444A58C61C200AE1BD842672168xmbrcdx01ciscoc_"
MIME-Version: 1.0
Archived-At: http://mailarchive.ietf.org/arch/msg/6tisch-security/bdj7vQFSywfl0-cPRUtxZwzXKtM
Subject: Re: [6tisch-security] (review draft-piro-6tisch-security-issues-01) Re: [6tisch] Minutes Webex 20th May 2014, 6TiSCH Security
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 21 May 2014 09:22:52 -0000

--_000_E045AECD98228444A58C61C200AE1BD842672168xmbrcdx01ciscoc_
Content-Type: text/plain; charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable

Ren=E9,

Thanks for this : )
Could you please copy the 6TISCH ML?

Cheers,

Pascal

From: Rene Struik [mailto:rstruik.ext@gmail.com]
Sent: mardi 20 mai 2014 18:47
To: Pascal Thubert (pthubert); tisch-security
Subject: (review draft-piro-6tisch-security-issues-01) Re: [6tisch] Minutes=
 Webex 20th May 2014, 6TiSCH Security

Dear colleagues:

As suggested by Michael Richardson, I briefly reviewed the draft-piro-6tisc=
h-security-issues-01.

Some suggestions/feedback:
a) the draft relates to 802.15.4-2011. I would suggest making this relative=
 to 802.15.4e-2012 (which describes the TSCH protocol and corresponding MAC=
 extensions).
b) the draft introduces new 802.15.4-command frames to implement the key ne=
gotiation phase (Section 6.3). As such, this would constitute a change to t=
he 802.15.4-2011 and 802.15.4e-2012 specification. Besides, this also impli=
es that the key negotiation phase can only deal with one-hop behavior.
c) the key negotiation protocol deals with authenticated key agreement and =
does not consider potential authorization steps.
d) it is assumed that each node is preconfigured with a master key M_k that=
 is shared amongst all devices (Section 6.1.1), from which default keys D_k=
 are derived using a publicly known function (with potentially other inputs=
, which are to be assumed publicly known). This seems to imply that all def=
ault keys can be considered as publicly known strings (!).
e) the key negotiation phase using the anonymous Diffie-Hellman scheme (Sec=
tion 6.3.3) that uses ordinary Diffie-Hellman groups in the ring of integer=
s Zp, where p is a prime number that indexed by a publicly computable integ=
er (Section 6.3.1, Step c1)) and where p has at least bit-size 128 (see App=
endix A.1). The ordinary Diffie-Hellman problem in integer rings Zp of this=
 order of magnitude sizes is efficiently computable, thereby rendering this=
 scheme completely insecure (I already commented on this when reviewing dra=
ft r0 of which this draft is an update (see http://www.ietf.org/mail-archiv=
e/web/6tisch/current/msg01481.html))
f) the 802.15.4-2011 specification mistakenly does not allow mixing of secu=
red and unsecured traffic (see, e.g., my emails of end of January 2014 on t=
his). In particular, the hybrid security network (as mentioned in Section 5=
) is not possible with 802.15.4-2011 or 802.15.4e-2012.

Best regards, Rene

On 5/20/2014 11:38 AM, Pascal Thubert (pthubert) wrote:
Minutes Webex 20th May 2014, 6TiSCH Security
________________________________
Taking notes (using Etherpad)
1.   Pascal Thubert
Present (alphabetically)
1.   Hank Mauldin
2.   Michael Behringer
3.   Michael Richardson
4.   Maik Seewald
5.   Ren=E9 Struik
6.   Tom Phinney
7.   Yoshihiro Ohba
Recording
=B7     Webex recording<https://cisco.webex.com/ciscosales/lsr.php?RCID=3Dc=
f234f58e8f94d2f86fbe15e7d6862df>
Agenda
1.   Look at Join Protocol
Action Items
1.   Michael R. to suggest to the list a review of draft piro
2.   Michael B. to check with Max Pritikin about format on authorization to=
ken.
Minutes
=B7     [07.10] Meeting starts

Michael Richardson: network manager programs the device, no particular auth=
orization of the network to the device, nor way for device to prove it is a=
uthorized apart from having the join key provisioned

Ren=E9 Struik: unless missing something, need size of configuration message=
s. How to get tag names in the device and map that into 802.15.4 MAC addres=
ses. Details we do not really have. Unclear how device can discover the net=
work. Ties in AR certificate issue

Michael Richardson: problem exists regardless of actual enrolment process.

Ren=E9 Struik: there is also a control element when certificate can be used

Michael Richardson: sent message on Wile coyote; is it realistic?

Ren=E9 Struik: quick feedback. say vendor generates cert for bunch of devic=
es and it goes along a chain and then more attributes allow link back to fa=
ctory. works, does not have to be AR certificate

Michael Richardson: I expected the kind of certificate I describe in AR but=
 it is not the point of AR. They do not even specify the format of device I=
D. AR is really about an API not about content of certificate apart from si=
gnature algorithm for which they have requirements. They do not even define=
 their own extensions. One extension with multiple values

Michael Richardson if you use secure enrolment, you can replace the cert bu=
t you still need to validate the device. Need Michael B. and Max to describ=
e their token

Michael Behringer: AR or not AR? process is about an institution that owns =
a device and has a secured relationship based on a certificate that tit sig=
ned. Can be 1AR or anything, e.g. an institution which owned the device bef=
ore. Need that cert from old organization to help bootstrap in new organiza=
tion.

Michael Richardson: did you define how the authorization token can be passe=
d in an interoperable fashion

Michael Behringer: leverage secure relationship between vendor and device t=
o pass a signed message to the device

Michael Richardson: does it bind to the new owner? which way, not subject t=
o standardization or is it?

Michael Behringer: May not need standard, but if multivendor network user w=
ould like a common format. between vendor and new device can be proprietary

Michael Richardson: need ot define when how the token is transported, and t=
hat is not end to end. reasons of trust, rate limit etc...

Michael Behringer: new device sends along a nonce and expect that nonce in =
response from vendor site; without nonce, token could come from the past. B=
oth models are required in the market. Some want fresh, others e.g. militar=
y there cannot be comm at the deployment time.

Michael Richardson: content of token may or not be standard. transport of t=
oken must be standard.

Michael Richardson: using RFC 3779 would address cert that had 1AR IdevID i=
n them. need a range in the certificate otherwise one certificate per devic=
e

Michael Behringer: token or certificate?

Michael Richardson if the token is a certificate need a way to delegate dow=
n the chain. But breach along the way breaches it all below. no good. Do yo=
u have to maintain a cert for every device?

Michael Behringer: that's the starting point. You assume that's a scalabili=
ty issue at some point right

Michael Richardson: provisioning trouble is possible. Tracking by bulk coul=
d be more palatable

Michael Behringer: if name space is aggregatable could work. In early appro=
ach, token is not a cert and stealing the token does not help.

Michael Richardson: anxious about spare parts that did not join, and go uns=
erviceable

Michael Behringer: yes, we can take the req in draft-pritikin

Michael Richardson proposing do something like RFC 3779. It as AS numbers t=
o allow reg to delegate using cert; these are live devIDs from a pool. shou=
ld look at that doc and we could change all AS to IdevID and we'd be done.

Michael Behringer: sounds like an idea we'll look at it

Michael Richardson: draft pritikin does not tell whether the enrolment allo=
w transport of authorization token back and forth and then the cert for the=
 TLS transport can be validated. Then you have a secure transport and can e=
nrol replacing the vendor cert with a domain cert.

Michael Behringer: refer to a mail by Max Pritikin "[6tisch-security] a dif=
ferent explanation of autonomic" .

Michael Richardson: where is the process ?

Michael Behringer: explained in message. We need to mail this down so peopl=
e understand.

Michael Richardson: non normative

Pascal Thubert: yes that is what we want in the security architecture

Michael Behringer I need to leave soon

Michael Richardson: I answered to draft piro descries low level stuff. I wa=
nt to encourage people to read and suggest that this becomes WG doc in L2 l=
ayer 2 security. It is a very good draft. We may need to change the authori=
zation but after that, great stuff can be found. Should be WG doc somewhere=
.

Ren=E9 Struik: thoughts appreciated on mail I sent today

Pascal: Next call on Tuesday next week same time
=B7     [08.06] meeting ends

=3D=3D=3D=3D=3D=3D





_______________________________________________

6tisch mailing list

6tisch@ietf.org<mailto:6tisch@ietf.org>

https://www.ietf.org/mailman/listinfo/6tisch




--

email: rstruik.ext@gmail.com<mailto:rstruik.ext@gmail.com> | Skype: rstruik

cell: +1 (647) 867-5658 | US: +1 (415) 690-7363

--_000_E045AECD98228444A58C61C200AE1BD842672168xmbrcdx01ciscoc_
Content-Type: text/html; charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable

<html xmlns:v=3D"urn:schemas-microsoft-com:vml" xmlns:o=3D"urn:schemas-micr=
osoft-com:office:office" xmlns:w=3D"urn:schemas-microsoft-com:office:word" =
xmlns:m=3D"http://schemas.microsoft.com/office/2004/12/omml" xmlns=3D"http:=
//www.w3.org/TR/REC-html40">
<head>
<meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3Diso-8859-=
1">
<meta name=3D"Generator" content=3D"Microsoft Word 14 (filtered medium)">
<!--[if !mso]><style>v\:* {behavior:url(#default#VML);}
o\:* {behavior:url(#default#VML);}
w\:* {behavior:url(#default#VML);}
.shape {behavior:url(#default#VML);}
</style><![endif]--><style><!--
/* Font Definitions */
@font-face
	{font-family:Wingdings;
	panose-1:5 0 0 0 0 0 0 0 0 0;}
@font-face
	{font-family:Wingdings;
	panose-1:5 0 0 0 0 0 0 0 0 0;}
@font-face
	{font-family:Calibri;
	panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
	{font-family:Tahoma;
	panose-1:2 11 6 4 3 5 4 4 2 4;}
@font-face
	{font-family:Consolas;
	panose-1:2 11 6 9 2 2 4 3 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
	{margin:0cm;
	margin-bottom:.0001pt;
	font-size:11.0pt;
	font-family:"Calibri","sans-serif";
	color:black;}
h1
	{mso-style-priority:9;
	mso-style-link:"Heading 1 Char";
	mso-margin-top-alt:auto;
	margin-right:0cm;
	mso-margin-bottom-alt:auto;
	margin-left:0cm;
	font-size:24.0pt;
	font-family:"Times New Roman","serif";
	color:black;
	font-weight:bold;}
h2
	{mso-style-priority:9;
	mso-style-link:"Heading 2 Char";
	mso-margin-top-alt:auto;
	margin-right:0cm;
	mso-margin-bottom-alt:auto;
	margin-left:0cm;
	font-size:18.0pt;
	font-family:"Times New Roman","serif";
	color:black;
	font-weight:bold;}
a:link, span.MsoHyperlink
	{mso-style-priority:99;
	color:blue;
	text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
	{mso-style-priority:99;
	color:purple;
	text-decoration:underline;}
p
	{mso-style-priority:99;
	mso-margin-top-alt:auto;
	margin-right:0cm;
	mso-margin-bottom-alt:auto;
	margin-left:0cm;
	font-size:12.0pt;
	font-family:"Times New Roman","serif";
	color:black;}
pre
	{mso-style-priority:99;
	mso-style-link:"HTML Preformatted Char";
	margin:0cm;
	margin-bottom:.0001pt;
	font-size:10.0pt;
	font-family:"Courier New";
	color:black;}
p.MsoAcetate, li.MsoAcetate, div.MsoAcetate
	{mso-style-priority:99;
	mso-style-link:"Balloon Text Char";
	margin:0cm;
	margin-bottom:.0001pt;
	font-size:8.0pt;
	font-family:"Tahoma","sans-serif";
	color:black;}
span.Heading1Char
	{mso-style-name:"Heading 1 Char";
	mso-style-priority:9;
	mso-style-link:"Heading 1";
	font-family:"Times New Roman","serif";
	font-weight:bold;}
span.Heading2Char
	{mso-style-name:"Heading 2 Char";
	mso-style-priority:9;
	mso-style-link:"Heading 2";
	font-family:"Times New Roman","serif";
	font-weight:bold;}
span.BalloonTextChar
	{mso-style-name:"Balloon Text Char";
	mso-style-priority:99;
	mso-style-link:"Balloon Text";
	font-family:"Tahoma","sans-serif";}
span.EmailStyle22
	{mso-style-type:personal;
	font-family:"Calibri","sans-serif";
	color:windowtext;}
span.apple-converted-space
	{mso-style-name:apple-converted-space;}
span.HTMLPreformattedChar
	{mso-style-name:"HTML Preformatted Char";
	mso-style-priority:99;
	mso-style-link:"HTML Preformatted";
	font-family:"Consolas","serif";
	color:black;}
span.EmailStyle27
	{mso-style-type:personal-reply;
	font-family:"Calibri","sans-serif";
	color:#1F497D;}
.MsoChpDefault
	{mso-style-type:export-only;
	font-size:10.0pt;}
@page WordSection1
	{size:612.0pt 792.0pt;
	margin:70.85pt 70.85pt 70.85pt 70.85pt;}
div.WordSection1
	{page:WordSection1;}
/* List Definitions */
@list l0
	{mso-list-id:15347732;
	mso-list-template-ids:1149267428;}
@list l0:level1
	{mso-level-tab-stop:36.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;}
@list l0:level2
	{mso-level-tab-stop:72.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;}
@list l0:level3
	{mso-level-tab-stop:108.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;}
@list l0:level4
	{mso-level-tab-stop:144.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;}
@list l0:level5
	{mso-level-tab-stop:180.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;}
@list l0:level6
	{mso-level-tab-stop:216.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;}
@list l0:level7
	{mso-level-tab-stop:252.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;}
@list l0:level8
	{mso-level-tab-stop:288.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;}
@list l0:level9
	{mso-level-tab-stop:324.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;}
@list l1
	{mso-list-id:298346911;
	mso-list-template-ids:-1990059266;}
@list l1:level1
	{mso-level-tab-stop:36.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;}
@list l1:level2
	{mso-level-tab-stop:72.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;}
@list l1:level3
	{mso-level-tab-stop:108.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;}
@list l1:level4
	{mso-level-tab-stop:144.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;}
@list l1:level5
	{mso-level-tab-stop:180.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;}
@list l1:level6
	{mso-level-tab-stop:216.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;}
@list l1:level7
	{mso-level-tab-stop:252.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;}
@list l1:level8
	{mso-level-tab-stop:288.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;}
@list l1:level9
	{mso-level-tab-stop:324.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;}
@list l2
	{mso-list-id:410661324;
	mso-list-template-ids:862720772;}
@list l2:level1
	{mso-level-tab-stop:36.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;}
@list l2:level2
	{mso-level-tab-stop:72.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;}
@list l2:level3
	{mso-level-tab-stop:108.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;}
@list l2:level4
	{mso-level-tab-stop:144.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;}
@list l2:level5
	{mso-level-tab-stop:180.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;}
@list l2:level6
	{mso-level-tab-stop:216.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;}
@list l2:level7
	{mso-level-tab-stop:252.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;}
@list l2:level8
	{mso-level-tab-stop:288.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;}
@list l2:level9
	{mso-level-tab-stop:324.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;}
@list l3
	{mso-list-id:795804602;
	mso-list-template-ids:1885534928;}
@list l3:level1
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:36.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l3:level2
	{mso-level-number-format:bullet;
	mso-level-text:o;
	mso-level-tab-stop:72.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:"Courier New";
	mso-bidi-font-family:"Times New Roman";}
@list l3:level3
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:108.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l3:level4
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:144.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l3:level5
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:180.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l3:level6
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:216.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l3:level7
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:252.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l3:level8
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:288.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l3:level9
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:324.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l4
	{mso-list-id:1308902986;
	mso-list-template-ids:1846212050;}
@list l4:level1
	{mso-level-tab-stop:36.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;}
@list l4:level2
	{mso-level-tab-stop:72.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;}
@list l4:level3
	{mso-level-tab-stop:108.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;}
@list l4:level4
	{mso-level-tab-stop:144.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;}
@list l4:level5
	{mso-level-tab-stop:180.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;}
@list l4:level6
	{mso-level-tab-stop:216.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;}
@list l4:level7
	{mso-level-tab-stop:252.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;}
@list l4:level8
	{mso-level-tab-stop:288.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;}
@list l4:level9
	{mso-level-tab-stop:324.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;}
@list l5
	{mso-list-id:1916742795;
	mso-list-template-ids:798656480;}
@list l5:level1
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:36.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l5:level2
	{mso-level-number-format:bullet;
	mso-level-text:o;
	mso-level-tab-stop:72.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:"Courier New";
	mso-bidi-font-family:"Times New Roman";}
@list l5:level3
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:108.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l5:level4
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:144.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l5:level5
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:180.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l5:level6
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:216.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l5:level7
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:252.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l5:level8
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:288.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l5:level9
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:324.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l6
	{mso-list-id:2016230055;
	mso-list-template-ids:-1235608234;}
@list l6:level1
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:36.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l6:level2
	{mso-level-number-format:bullet;
	mso-level-text:o;
	mso-level-tab-stop:72.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:"Courier New";
	mso-bidi-font-family:"Times New Roman";}
@list l6:level3
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:108.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l6:level4
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:144.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l6:level5
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:180.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l6:level6
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:216.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l6:level7
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:252.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l6:level8
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:288.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l6:level9
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:324.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
ol
	{margin-bottom:0cm;}
ul
	{margin-bottom:0cm;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext=3D"edit" spidmax=3D"1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext=3D"edit">
<o:idmap v:ext=3D"edit" data=3D"1" />
</o:shapelayout></xml><![endif]-->
</head>
<body bgcolor=3D"white" lang=3D"EN-US" link=3D"blue" vlink=3D"purple">
<div class=3D"WordSection1">
<p class=3D"MsoNormal"><span style=3D"color:#1F497D">Ren=E9, <o:p></o:p></s=
pan></p>
<p class=3D"MsoNormal"><span style=3D"color:#1F497D"><o:p>&nbsp;</o:p></spa=
n></p>
<p class=3D"MsoNormal"><span style=3D"color:#1F497D">Thanks for this : )<o:=
p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"color:#1F497D">Could you please copy =
the 6TISCH ML?<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"color:#1F497D"><o:p>&nbsp;</o:p></spa=
n></p>
<div>
<p class=3D"MsoNormal"><span lang=3D"FR" style=3D"color:#1F497D">Cheers,<o:=
p></o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"FR" style=3D"color:#1F497D"><o:p>&nbsp=
;</o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"FR" style=3D"color:#1F497D">Pascal<o:p=
></o:p></span></p>
</div>
<p class=3D"MsoNormal"><span style=3D"color:#1F497D"><o:p>&nbsp;</o:p></spa=
n></p>
<div style=3D"border:none;border-left:solid blue 1.5pt;padding:0cm 0cm 0cm =
4.0pt">
<div>
<div style=3D"border:none;border-top:solid #B5C4DF 1.0pt;padding:3.0pt 0cm =
0cm 0cm">
<p class=3D"MsoNormal"><b><span style=3D"font-size:10.0pt;font-family:&quot=
;Tahoma&quot;,&quot;sans-serif&quot;;color:windowtext">From:</span></b><spa=
n style=3D"font-size:10.0pt;font-family:&quot;Tahoma&quot;,&quot;sans-serif=
&quot;;color:windowtext"> Rene Struik [mailto:rstruik.ext@gmail.com]
<br>
<b>Sent:</b> mardi 20 mai 2014 18:47<br>
<b>To:</b> Pascal Thubert (pthubert); tisch-security<br>
<b>Subject:</b> (review draft-piro-6tisch-security-issues-01) Re: [6tisch] =
Minutes Webex 20th May 2014, 6TiSCH Security<o:p></o:p></span></p>
</div>
</div>
<p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p>
<div>
<p class=3D"MsoNormal">Dear colleagues:<br>
<br>
As suggested by Michael Richardson, I briefly reviewed the draft-piro-6tisc=
h-security-issues-01.
<br>
<br>
Some suggestions/feedback:<br>
a) the draft relates to 802.15.4-2011. I would suggest making this relative=
 to 802.15.4e-2012 (which describes the TSCH protocol and corresponding MAC=
 extensions).<br>
b) the draft introduces new 802.15.4-command frames to implement the key ne=
gotiation phase (Section 6.3). As such, this would constitute a change to t=
he 802.15.4-2011 and 802.15.4e-2012 specification. Besides, this also impli=
es that the key negotiation phase
 can only deal with one-hop behavior.<br>
c) the key negotiation protocol deals with authenticated key agreement and =
does not consider potential authorization steps.
<br>
d) it is assumed that each node is preconfigured with a master key M_k that=
 is shared amongst all devices (Section 6.1.1), from which default keys D_k=
 are derived using a publicly known function (with potentially other inputs=
, which are to be assumed publicly
 known). This seems to imply that all default keys can be considered as pub=
licly known strings (!).<br>
e) the key negotiation phase using the anonymous Diffie-Hellman scheme (Sec=
tion 6.3.3) that uses ordinary Diffie-Hellman groups in the ring of integer=
s Zp, where p is a prime number that indexed by a publicly computable integ=
er (Section 6.3.1, Step c1)) and
 where p has at least bit-size 128 (see Appendix A.1). The ordinary Diffie-=
Hellman problem in integer rings Zp of this order of magnitude sizes is eff=
iciently computable, thereby rendering this scheme completely insecure (I a=
lready commented on this when reviewing
 draft r0 of which this draft is an update (see <a href=3D"http://www.ietf.=
org/mail-archive/web/6tisch/current/msg01481.html">
http://www.ietf.org/mail-archive/web/6tisch/current/msg01481.html</a>))<br>
f) the 802.15.4-2011 specification mistakenly does not allow mixing of secu=
red and unsecured traffic (see, e.g., my emails of end of January 2014 on t=
his). In particular, the hybrid security network (as mentioned in Section 5=
) is not possible with 802.15.4-2011
 or 802.15.4e-2012.<br>
<br>
Best regards, Rene<br>
<br>
On 5/20/2014 11:38 AM, Pascal Thubert (pthubert) wrote:<o:p></o:p></p>
</div>
<blockquote style=3D"margin-top:5.0pt;margin-bottom:5.0pt">
<h1 style=3D"mso-margin-top-alt:0cm;margin-right:0cm;margin-bottom:7.5pt;ma=
rgin-left:0cm;background:white">
<span style=3D"font-size:18.0pt;font-family:&quot;Arial&quot;,&quot;sans-se=
rif&quot;;color:#333333;font-weight:normal">Minutes Webex 20th May 2014, 6T=
iSCH Security</span><o:p></o:p></h1>
<div style=3D"margin-top:15.0pt;margin-bottom:15.0pt">
<div class=3D"MsoNormal" align=3D"center" style=3D"text-align:center">
<hr size=3D"3" width=3D"100%" noshade=3D"" style=3D"color:#333333" align=3D=
"center">
</div>
</div>
<h2 style=3D"mso-margin-top-alt:15.0pt;margin-right:0cm;margin-bottom:0cm;m=
argin-left:0cm;margin-bottom:.0001pt;background:white;orphans:
          auto;text-align:start;widows: auto;-webkit-text-stroke-width:
          0px;word-spacing:0px" id=3D"markdown-header-taking-notes-using-et=
herpad">
<span style=3D"font-size:15.0pt;font-family:&quot;Arial&quot;,&quot;sans-se=
rif&quot;;color:#333333;font-weight:normal">Taking notes<span class=3D"appl=
e-converted-space">&nbsp;</span><em><span style=3D"font-family:&quot;Arial&=
quot;,&quot;sans-serif&quot;">(using Etherpad)</span></em></span><o:p></o:p=
></h2>
<p class=3D"MsoNormal" style=3D"mso-margin-top-alt:auto;mso-margin-bottom-a=
lt:auto;margin-left:0cm;text-indent:-18.0pt;line-height:15.0pt;mso-list:l1 =
level1 lfo2;background:white">
<![if !supportLists]><span style=3D"mso-list:Ignore">1.<span style=3D"font:=
7.0pt &quot;Times New Roman&quot;">&nbsp;&nbsp;
</span></span><![endif]><span style=3D"font-size:10.5pt;font-family:&quot;A=
rial&quot;,&quot;sans-serif&quot;;color:#333333">Pascal Thubert</span><o:p>=
</o:p></p>
<h2 style=3D"mso-margin-top-alt:15.0pt;margin-right:0cm;margin-bottom:0cm;m=
argin-left:0cm;margin-bottom:.0001pt;background:white;orphans:
          auto;text-align:start;widows: auto;-webkit-text-stroke-width:
          0px;word-spacing:0px" id=3D"markdown-header-present-alphabeticall=
y">
<span style=3D"font-size:15.0pt;font-family:&quot;Arial&quot;,&quot;sans-se=
rif&quot;;color:#333333;font-weight:normal">Present<span class=3D"apple-con=
verted-space">&nbsp;</span><em><span style=3D"font-family:&quot;Arial&quot;=
,&quot;sans-serif&quot;">(alphabetically)</span></em></span><o:p></o:p></h2=
>
<p class=3D"MsoNormal" style=3D"mso-margin-top-alt:auto;mso-margin-bottom-a=
lt:auto;margin-left:0cm;text-indent:-18.0pt;line-height:15.0pt;mso-list:l0 =
level1 lfo4;background:white">
<![if !supportLists]><span style=3D"mso-list:Ignore">1.<span style=3D"font:=
7.0pt &quot;Times New Roman&quot;">&nbsp;&nbsp;
</span></span><![endif]><span style=3D"font-size:10.5pt;font-family:&quot;A=
rial&quot;,&quot;sans-serif&quot;;color:#333333">Hank Mauldin</span><o:p></=
o:p></p>
<p class=3D"MsoNormal" style=3D"mso-margin-top-alt:auto;mso-margin-bottom-a=
lt:auto;margin-left:0cm;text-indent:-18.0pt;line-height:15.0pt;mso-list:l0 =
level1 lfo4;background:white">
<![if !supportLists]><span style=3D"mso-list:Ignore">2.<span style=3D"font:=
7.0pt &quot;Times New Roman&quot;">&nbsp;&nbsp;
</span></span><![endif]><span style=3D"font-size:10.5pt;font-family:&quot;A=
rial&quot;,&quot;sans-serif&quot;;color:#333333">Michael Behringer</span><o=
:p></o:p></p>
<p class=3D"MsoNormal" style=3D"mso-margin-top-alt:auto;mso-margin-bottom-a=
lt:auto;margin-left:0cm;text-indent:-18.0pt;line-height:15.0pt;mso-list:l0 =
level1 lfo4;background:white">
<![if !supportLists]><span style=3D"mso-list:Ignore">3.<span style=3D"font:=
7.0pt &quot;Times New Roman&quot;">&nbsp;&nbsp;
</span></span><![endif]><span style=3D"font-size:10.5pt;font-family:&quot;A=
rial&quot;,&quot;sans-serif&quot;;color:#333333">Michael Richardson</span><=
o:p></o:p></p>
<p class=3D"MsoNormal" style=3D"mso-margin-top-alt:auto;mso-margin-bottom-a=
lt:auto;margin-left:0cm;text-indent:-18.0pt;line-height:15.0pt;mso-list:l0 =
level1 lfo4;background:white">
<![if !supportLists]><span style=3D"mso-list:Ignore">4.<span style=3D"font:=
7.0pt &quot;Times New Roman&quot;">&nbsp;&nbsp;
</span></span><![endif]><span style=3D"font-size:10.5pt;font-family:&quot;A=
rial&quot;,&quot;sans-serif&quot;;color:#333333">Maik Seewald</span><o:p></=
o:p></p>
<p class=3D"MsoNormal" style=3D"mso-margin-top-alt:auto;mso-margin-bottom-a=
lt:auto;margin-left:0cm;text-indent:-18.0pt;line-height:15.0pt;mso-list:l0 =
level1 lfo4;background:white">
<![if !supportLists]><span style=3D"mso-list:Ignore">5.<span style=3D"font:=
7.0pt &quot;Times New Roman&quot;">&nbsp;&nbsp;
</span></span><![endif]><span style=3D"font-size:10.5pt;font-family:&quot;A=
rial&quot;,&quot;sans-serif&quot;;color:#333333">Ren=E9 Struik</span><o:p><=
/o:p></p>
<p class=3D"MsoNormal" style=3D"mso-margin-top-alt:auto;mso-margin-bottom-a=
lt:auto;margin-left:0cm;text-indent:-18.0pt;line-height:15.0pt;mso-list:l0 =
level1 lfo4;background:white">
<![if !supportLists]><span style=3D"mso-list:Ignore">6.<span style=3D"font:=
7.0pt &quot;Times New Roman&quot;">&nbsp;&nbsp;
</span></span><![endif]><span style=3D"font-size:10.5pt;font-family:&quot;A=
rial&quot;,&quot;sans-serif&quot;;color:#333333">Tom Phinney</span><o:p></o=
:p></p>
<p class=3D"MsoNormal" style=3D"mso-margin-top-alt:auto;mso-margin-bottom-a=
lt:auto;margin-left:0cm;text-indent:-18.0pt;line-height:15.0pt;mso-list:l0 =
level1 lfo4;background:white">
<![if !supportLists]><span style=3D"mso-list:Ignore">7.<span style=3D"font:=
7.0pt &quot;Times New Roman&quot;">&nbsp;&nbsp;
</span></span><![endif]><span style=3D"font-size:10.5pt;font-family:&quot;A=
rial&quot;,&quot;sans-serif&quot;;color:#333333">Yoshihiro Ohba</span><o:p>=
</o:p></p>
<h2 style=3D"mso-margin-top-alt:15.0pt;margin-right:0cm;margin-bottom:0cm;m=
argin-left:0cm;margin-bottom:.0001pt;background:white;orphans:
          auto;text-align:start;widows: auto;-webkit-text-stroke-width:
          0px;word-spacing:0px" id=3D"markdown-header-recording">
<span style=3D"font-size:15.0pt;font-family:&quot;Arial&quot;,&quot;sans-se=
rif&quot;;color:#333333;font-weight:normal">Recording</span><o:p></o:p></h2=
>
<p class=3D"MsoNormal" style=3D"mso-margin-top-alt:auto;mso-margin-bottom-a=
lt:auto;margin-left:0cm;text-indent:-18.0pt;line-height:15.0pt;mso-list:l3 =
level1 lfo6;background:white">
<![if !supportLists]><span style=3D"font-size:10.0pt;font-family:Symbol"><s=
pan style=3D"mso-list:Ignore">=B7<span style=3D"font:7.0pt &quot;Times New =
Roman&quot;">&nbsp;&nbsp;&nbsp;&nbsp;
</span></span></span><![endif]><span style=3D"font-size:10.5pt;font-family:=
&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333"><a href=3D"https://=
cisco.webex.com/ciscosales/lsr.php?RCID=3Dcf234f58e8f94d2f86fbe15e7d6862df"=
><span style=3D"color:#3B73AF">Webex recording</span></a></span><o:p></o:p>=
</p>
<h2 style=3D"mso-margin-top-alt:15.0pt;margin-right:0cm;margin-bottom:0cm;m=
argin-left:0cm;margin-bottom:.0001pt;background:white;orphans:
          auto;text-align:start;widows: auto;-webkit-text-stroke-width:
          0px;word-spacing:0px" id=3D"markdown-header-agenda">
<span style=3D"font-size:15.0pt;font-family:&quot;Arial&quot;,&quot;sans-se=
rif&quot;;color:#333333;font-weight:normal">Agenda</span><o:p></o:p></h2>
<p class=3D"MsoNormal" style=3D"mso-margin-top-alt:auto;mso-margin-bottom-a=
lt:auto;margin-left:0cm;text-indent:-18.0pt;line-height:15.0pt;mso-list:l4 =
level1 lfo8;background:white">
<![if !supportLists]><span style=3D"mso-list:Ignore">1.<span style=3D"font:=
7.0pt &quot;Times New Roman&quot;">&nbsp;&nbsp;
</span></span><![endif]><span style=3D"font-size:10.5pt;font-family:&quot;A=
rial&quot;,&quot;sans-serif&quot;;color:#333333">Look at Join Protocol</spa=
n><o:p></o:p></p>
<h2 style=3D"mso-margin-top-alt:15.0pt;margin-right:0cm;margin-bottom:0cm;m=
argin-left:0cm;margin-bottom:.0001pt;background:white;orphans:
          auto;text-align:start;widows: auto;-webkit-text-stroke-width:
          0px;word-spacing:0px" id=3D"markdown-header-action-items">
<span style=3D"font-size:15.0pt;font-family:&quot;Arial&quot;,&quot;sans-se=
rif&quot;;color:#333333;font-weight:normal">Action Items</span><o:p></o:p><=
/h2>
<p class=3D"MsoNormal" style=3D"mso-margin-top-alt:auto;mso-margin-bottom-a=
lt:auto;margin-left:0cm;text-indent:-18.0pt;line-height:15.0pt;mso-list:l2 =
level1 lfo10;background:white">
<![if !supportLists]><span style=3D"mso-list:Ignore">1.<span style=3D"font:=
7.0pt &quot;Times New Roman&quot;">&nbsp;&nbsp;
</span></span><![endif]><span style=3D"font-size:10.5pt;font-family:&quot;A=
rial&quot;,&quot;sans-serif&quot;;color:#333333">Michael R. to suggest to t=
he list a review of draft piro</span><o:p></o:p></p>
<p class=3D"MsoNormal" style=3D"mso-margin-top-alt:auto;mso-margin-bottom-a=
lt:auto;margin-left:0cm;text-indent:-18.0pt;line-height:15.0pt;mso-list:l2 =
level1 lfo10;background:white">
<![if !supportLists]><span style=3D"mso-list:Ignore">2.<span style=3D"font:=
7.0pt &quot;Times New Roman&quot;">&nbsp;&nbsp;
</span></span><![endif]><span style=3D"font-size:10.5pt;font-family:&quot;A=
rial&quot;,&quot;sans-serif&quot;;color:#333333">Michael B. to check with M=
ax Pritikin about format on authorization token.</span><o:p></o:p></p>
<h2 style=3D"mso-margin-top-alt:15.0pt;margin-right:0cm;margin-bottom:0cm;m=
argin-left:0cm;margin-bottom:.0001pt;background:white;orphans:
          auto;text-align:start;widows: auto;-webkit-text-stroke-width:
          0px;word-spacing:0px" id=3D"markdown-header-minutes">
<span style=3D"font-size:15.0pt;font-family:&quot;Arial&quot;,&quot;sans-se=
rif&quot;;color:#333333;font-weight:normal">Minutes</span><o:p></o:p></h2>
<p class=3D"MsoNormal" style=3D"mso-margin-top-alt:auto;mso-margin-bottom-a=
lt:auto;margin-left:0cm;text-indent:-18.0pt;line-height:15.0pt;mso-list:l6 =
level1 lfo12;background:white">
<![if !supportLists]><span style=3D"font-size:10.0pt;font-family:Symbol"><s=
pan style=3D"mso-list:Ignore">=B7<span style=3D"font:7.0pt &quot;Times New =
Roman&quot;">&nbsp;&nbsp;&nbsp;&nbsp;
</span></span></span><![endif]><em><span style=3D"font-size:10.5pt;font-fam=
ily:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">[07.10]</span><=
/em><span class=3D"apple-converted-space"><span style=3D"font-size:10.5pt;f=
ont-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">&nbsp;</=
span></span><span style=3D"font-size:10.5pt;font-family:&quot;Arial&quot;,&=
quot;sans-serif&quot;;color:#333333">Meeting
 starts</span><o:p></o:p></p>
<p style=3D"mso-margin-top-alt:7.5pt;margin-right:0cm;margin-bottom:0cm;mar=
gin-left:0cm;margin-bottom:.0001pt;line-height:15.0pt;background:white;word=
-wrap:
          break-word;orphans: auto;text-align:start;widows:
          auto;-webkit-text-stroke-width: 0px;word-spacing:0px">
<span style=3D"font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-se=
rif&quot;;color:#333333">Michael Richardson: network manager programs the d=
evice, no particular authorization of the network to the device, nor way fo=
r device to prove it is authorized apart from having the
 join key provisioned</span><o:p></o:p></p>
<p style=3D"mso-margin-top-alt:7.5pt;margin-right:0cm;margin-bottom:0cm;mar=
gin-left:0cm;margin-bottom:.0001pt;line-height:15.0pt;background:white;word=
-wrap:
          break-word;orphans: auto;text-align:start;widows:
          auto;-webkit-text-stroke-width: 0px;word-spacing:0px">
<span style=3D"font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-se=
rif&quot;;color:#333333">Ren=E9 Struik: unless missing something, need size=
 of configuration messages. How to get tag names in the device and map that=
 into 802.15.4 MAC addresses. Details we do not really have.
 Unclear how device can discover the network. Ties in AR certificate issue<=
/span><o:p></o:p></p>
<p style=3D"mso-margin-top-alt:7.5pt;margin-right:0cm;margin-bottom:0cm;mar=
gin-left:0cm;margin-bottom:.0001pt;line-height:15.0pt;background:white;word=
-wrap:
          break-word;orphans: auto;text-align:start;widows:
          auto;-webkit-text-stroke-width: 0px;word-spacing:0px">
<span style=3D"font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-se=
rif&quot;;color:#333333">Michael Richardson: problem exists regardless of a=
ctual enrolment process.</span><o:p></o:p></p>
<p style=3D"mso-margin-top-alt:7.5pt;margin-right:0cm;margin-bottom:0cm;mar=
gin-left:0cm;margin-bottom:.0001pt;line-height:15.0pt;background:white;word=
-wrap:
          break-word;orphans: auto;text-align:start;widows:
          auto;-webkit-text-stroke-width: 0px;word-spacing:0px">
<span style=3D"font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-se=
rif&quot;;color:#333333">Ren=E9 Struik: there is also a control element whe=
n certificate can be used</span><o:p></o:p></p>
<p style=3D"mso-margin-top-alt:7.5pt;margin-right:0cm;margin-bottom:0cm;mar=
gin-left:0cm;margin-bottom:.0001pt;line-height:15.0pt;background:white;word=
-wrap:
          break-word;orphans: auto;text-align:start;widows:
          auto;-webkit-text-stroke-width: 0px;word-spacing:0px">
<span style=3D"font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-se=
rif&quot;;color:#333333">Michael Richardson: sent message on Wile coyote; i=
s it realistic?</span><o:p></o:p></p>
<p style=3D"mso-margin-top-alt:7.5pt;margin-right:0cm;margin-bottom:0cm;mar=
gin-left:0cm;margin-bottom:.0001pt;line-height:15.0pt;background:white;word=
-wrap:
          break-word;orphans: auto;text-align:start;widows:
          auto;-webkit-text-stroke-width: 0px;word-spacing:0px">
<span style=3D"font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-se=
rif&quot;;color:#333333">Ren=E9 Struik: quick feedback. say vendor generate=
s cert for bunch of devices and it goes along a chain and then more attribu=
tes allow link back to factory. works, does not have to
 be AR certificate</span><o:p></o:p></p>
<p style=3D"mso-margin-top-alt:7.5pt;margin-right:0cm;margin-bottom:0cm;mar=
gin-left:0cm;margin-bottom:.0001pt;line-height:15.0pt;background:white;word=
-wrap:
          break-word;orphans: auto;text-align:start;widows:
          auto;-webkit-text-stroke-width: 0px;word-spacing:0px">
<span style=3D"font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-se=
rif&quot;;color:#333333">Michael Richardson: I expected the kind of certifi=
cate I describe in AR but it is not the point of AR. They do not even speci=
fy the format of device ID. AR is really about an API
 not about content of certificate apart from signature algorithm for which =
they have requirements. They do not even define their own extensions. One e=
xtension with multiple values</span><o:p></o:p></p>
<p style=3D"mso-margin-top-alt:7.5pt;margin-right:0cm;margin-bottom:0cm;mar=
gin-left:0cm;margin-bottom:.0001pt;line-height:15.0pt;background:white;word=
-wrap:
          break-word;orphans: auto;text-align:start;widows:
          auto;-webkit-text-stroke-width: 0px;word-spacing:0px">
<span style=3D"font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-se=
rif&quot;;color:#333333">Michael Richardson if you use secure enrolment, yo=
u can replace the cert but you still need to validate the device. Need Mich=
ael B. and Max to describe their token</span><o:p></o:p></p>
<p style=3D"mso-margin-top-alt:7.5pt;margin-right:0cm;margin-bottom:0cm;mar=
gin-left:0cm;margin-bottom:.0001pt;line-height:15.0pt;background:white;word=
-wrap:
          break-word;orphans: auto;text-align:start;widows:
          auto;-webkit-text-stroke-width: 0px;word-spacing:0px">
<span style=3D"font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-se=
rif&quot;;color:#333333">Michael Behringer: AR or not AR? process is about =
an institution that owns a device and has a secured relationship based on a=
 certificate that tit signed. Can be 1AR or anything,
 e.g. an institution which owned the device before. Need that cert from old=
 organization to help bootstrap in new organization.</span><o:p></o:p></p>
<p style=3D"mso-margin-top-alt:7.5pt;margin-right:0cm;margin-bottom:0cm;mar=
gin-left:0cm;margin-bottom:.0001pt;line-height:15.0pt;background:white;word=
-wrap:
          break-word;orphans: auto;text-align:start;widows:
          auto;-webkit-text-stroke-width: 0px;word-spacing:0px">
<span style=3D"font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-se=
rif&quot;;color:#333333">Michael Richardson: did you define how the authori=
zation token can be passed in an interoperable fashion</span><o:p></o:p></p=
>
<p style=3D"mso-margin-top-alt:7.5pt;margin-right:0cm;margin-bottom:0cm;mar=
gin-left:0cm;margin-bottom:.0001pt;line-height:15.0pt;background:white;word=
-wrap:
          break-word;orphans: auto;text-align:start;widows:
          auto;-webkit-text-stroke-width: 0px;word-spacing:0px">
<span style=3D"font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-se=
rif&quot;;color:#333333">Michael Behringer: leverage secure relationship be=
tween vendor and device to pass a signed message to the device</span><o:p><=
/o:p></p>
<p style=3D"mso-margin-top-alt:7.5pt;margin-right:0cm;margin-bottom:0cm;mar=
gin-left:0cm;margin-bottom:.0001pt;line-height:15.0pt;background:white;word=
-wrap:
          break-word;orphans: auto;text-align:start;widows:
          auto;-webkit-text-stroke-width: 0px;word-spacing:0px">
<span style=3D"font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-se=
rif&quot;;color:#333333">Michael Richardson: does it bind to the new owner?=
 which way, not subject to standardization or is it?</span><o:p></o:p></p>
<p style=3D"mso-margin-top-alt:7.5pt;margin-right:0cm;margin-bottom:0cm;mar=
gin-left:0cm;margin-bottom:.0001pt;line-height:15.0pt;background:white;word=
-wrap:
          break-word;orphans: auto;text-align:start;widows:
          auto;-webkit-text-stroke-width: 0px;word-spacing:0px">
<span style=3D"font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-se=
rif&quot;;color:#333333">Michael Behringer: May not need standard, but if m=
ultivendor network user would like a common format. between vendor and new =
device can be proprietary</span><o:p></o:p></p>
<p style=3D"mso-margin-top-alt:7.5pt;margin-right:0cm;margin-bottom:0cm;mar=
gin-left:0cm;margin-bottom:.0001pt;line-height:15.0pt;background:white;word=
-wrap:
          break-word;orphans: auto;text-align:start;widows:
          auto;-webkit-text-stroke-width: 0px;word-spacing:0px">
<span style=3D"font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-se=
rif&quot;;color:#333333">Michael Richardson: need ot define when how the to=
ken is transported, and that is not end to end. reasons of trust, rate limi=
t etc...</span><o:p></o:p></p>
<p style=3D"mso-margin-top-alt:7.5pt;margin-right:0cm;margin-bottom:0cm;mar=
gin-left:0cm;margin-bottom:.0001pt;line-height:15.0pt;background:white;word=
-wrap:
          break-word;orphans: auto;text-align:start;widows:
          auto;-webkit-text-stroke-width: 0px;word-spacing:0px">
<span style=3D"font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-se=
rif&quot;;color:#333333">Michael Behringer: new device sends along a nonce =
and expect that nonce in response from vendor site; without nonce, token co=
uld come from the past. Both models are required in the
 market. Some want fresh, others e.g. military there cannot be comm at the =
deployment time.</span><o:p></o:p></p>
<p style=3D"mso-margin-top-alt:7.5pt;margin-right:0cm;margin-bottom:0cm;mar=
gin-left:0cm;margin-bottom:.0001pt;line-height:15.0pt;background:white;word=
-wrap:
          break-word;orphans: auto;text-align:start;widows:
          auto;-webkit-text-stroke-width: 0px;word-spacing:0px">
<span style=3D"font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-se=
rif&quot;;color:#333333">Michael Richardson: content of token may or not be=
 standard. transport of token must be standard.</span><o:p></o:p></p>
<p style=3D"mso-margin-top-alt:7.5pt;margin-right:0cm;margin-bottom:0cm;mar=
gin-left:0cm;margin-bottom:.0001pt;line-height:15.0pt;background:white;word=
-wrap:
          break-word;orphans: auto;text-align:start;widows:
          auto;-webkit-text-stroke-width: 0px;word-spacing:0px">
<span style=3D"font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-se=
rif&quot;;color:#333333">Michael Richardson: using RFC 3779 would address c=
ert that had 1AR IdevID in them. need a range in the certificate otherwise =
one certificate per device</span><o:p></o:p></p>
<p style=3D"mso-margin-top-alt:7.5pt;margin-right:0cm;margin-bottom:0cm;mar=
gin-left:0cm;margin-bottom:.0001pt;line-height:15.0pt;background:white;word=
-wrap:
          break-word;orphans: auto;text-align:start;widows:
          auto;-webkit-text-stroke-width: 0px;word-spacing:0px">
<span style=3D"font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-se=
rif&quot;;color:#333333">Michael Behringer: token or certificate?</span><o:=
p></o:p></p>
<p style=3D"mso-margin-top-alt:7.5pt;margin-right:0cm;margin-bottom:0cm;mar=
gin-left:0cm;margin-bottom:.0001pt;line-height:15.0pt;background:white;word=
-wrap:
          break-word;orphans: auto;text-align:start;widows:
          auto;-webkit-text-stroke-width: 0px;word-spacing:0px">
<span style=3D"font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-se=
rif&quot;;color:#333333">Michael Richardson if the token is a certificate n=
eed a way to delegate down the chain. But breach along the way breaches it =
all below. no good. Do you have to maintain a cert for
 every device?</span><o:p></o:p></p>
<p style=3D"mso-margin-top-alt:7.5pt;margin-right:0cm;margin-bottom:0cm;mar=
gin-left:0cm;margin-bottom:.0001pt;line-height:15.0pt;background:white;word=
-wrap:
          break-word;orphans: auto;text-align:start;widows:
          auto;-webkit-text-stroke-width: 0px;word-spacing:0px">
<span style=3D"font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-se=
rif&quot;;color:#333333">Michael Behringer: that's the starting point. You =
assume that's a scalability issue at some point right</span><o:p></o:p></p>
<p style=3D"mso-margin-top-alt:7.5pt;margin-right:0cm;margin-bottom:0cm;mar=
gin-left:0cm;margin-bottom:.0001pt;line-height:15.0pt;background:white;word=
-wrap:
          break-word;orphans: auto;text-align:start;widows:
          auto;-webkit-text-stroke-width: 0px;word-spacing:0px">
<span style=3D"font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-se=
rif&quot;;color:#333333">Michael Richardson: provisioning trouble is possib=
le. Tracking by bulk could be more palatable</span><o:p></o:p></p>
<p style=3D"mso-margin-top-alt:7.5pt;margin-right:0cm;margin-bottom:0cm;mar=
gin-left:0cm;margin-bottom:.0001pt;line-height:15.0pt;background:white;word=
-wrap:
          break-word;orphans: auto;text-align:start;widows:
          auto;-webkit-text-stroke-width: 0px;word-spacing:0px">
<span style=3D"font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-se=
rif&quot;;color:#333333">Michael Behringer: if name space is aggregatable c=
ould work. In early approach, token is not a cert and stealing the token do=
es not help.</span><o:p></o:p></p>
<p style=3D"mso-margin-top-alt:7.5pt;margin-right:0cm;margin-bottom:0cm;mar=
gin-left:0cm;margin-bottom:.0001pt;line-height:15.0pt;background:white;word=
-wrap:
          break-word;orphans: auto;text-align:start;widows:
          auto;-webkit-text-stroke-width: 0px;word-spacing:0px">
<span style=3D"font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-se=
rif&quot;;color:#333333">Michael Richardson: anxious about spare parts that=
 did not join, and go unserviceable</span><o:p></o:p></p>
<p style=3D"mso-margin-top-alt:7.5pt;margin-right:0cm;margin-bottom:0cm;mar=
gin-left:0cm;margin-bottom:.0001pt;line-height:15.0pt;background:white;word=
-wrap:
          break-word;orphans: auto;text-align:start;widows:
          auto;-webkit-text-stroke-width: 0px;word-spacing:0px">
<span style=3D"font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-se=
rif&quot;;color:#333333">Michael Behringer: yes, we can take the req in dra=
ft-pritikin</span><o:p></o:p></p>
<p style=3D"mso-margin-top-alt:7.5pt;margin-right:0cm;margin-bottom:0cm;mar=
gin-left:0cm;margin-bottom:.0001pt;line-height:15.0pt;background:white;word=
-wrap:
          break-word;orphans: auto;text-align:start;widows:
          auto;-webkit-text-stroke-width: 0px;word-spacing:0px">
<span style=3D"font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-se=
rif&quot;;color:#333333">Michael Richardson proposing do something like RFC=
 3779. It as AS numbers to allow reg to delegate using cert; these are live=
 devIDs from a pool. should look at that doc and we could
 change all AS to IdevID and we'd be done.</span><o:p></o:p></p>
<p style=3D"mso-margin-top-alt:7.5pt;margin-right:0cm;margin-bottom:0cm;mar=
gin-left:0cm;margin-bottom:.0001pt;line-height:15.0pt;background:white;word=
-wrap:
          break-word;orphans: auto;text-align:start;widows:
          auto;-webkit-text-stroke-width: 0px;word-spacing:0px">
<span style=3D"font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-se=
rif&quot;;color:#333333">Michael Behringer: sounds like an idea we'll look =
at it</span><o:p></o:p></p>
<p style=3D"mso-margin-top-alt:7.5pt;margin-right:0cm;margin-bottom:0cm;mar=
gin-left:0cm;margin-bottom:.0001pt;line-height:15.0pt;background:white;word=
-wrap:
          break-word;orphans: auto;text-align:start;widows:
          auto;-webkit-text-stroke-width: 0px;word-spacing:0px">
<span style=3D"font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-se=
rif&quot;;color:#333333">Michael Richardson: draft pritikin does not tell w=
hether the enrolment allow transport of authorization token back and forth =
and then the cert for the TLS transport can be validated.
 Then you have a secure transport and can enrol replacing the vendor cert w=
ith a domain cert.</span><o:p></o:p></p>
<p style=3D"mso-margin-top-alt:7.5pt;margin-right:0cm;margin-bottom:0cm;mar=
gin-left:0cm;margin-bottom:.0001pt;line-height:15.0pt;background:white;word=
-wrap:
          break-word;orphans: auto;text-align:start;widows:
          auto;-webkit-text-stroke-width: 0px;word-spacing:0px">
<span style=3D"font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-se=
rif&quot;;color:#333333">Michael Behringer: refer to a mail by Max Pritikin=
 &quot;[6tisch-security] a different explanation of autonomic&quot; .</span=
><o:p></o:p></p>
<p style=3D"mso-margin-top-alt:7.5pt;margin-right:0cm;margin-bottom:0cm;mar=
gin-left:0cm;margin-bottom:.0001pt;line-height:15.0pt;background:white;word=
-wrap:
          break-word;orphans: auto;text-align:start;widows:
          auto;-webkit-text-stroke-width: 0px;word-spacing:0px">
<span style=3D"font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-se=
rif&quot;;color:#333333">Michael Richardson: where is the process ?</span><=
o:p></o:p></p>
<p style=3D"mso-margin-top-alt:7.5pt;margin-right:0cm;margin-bottom:0cm;mar=
gin-left:0cm;margin-bottom:.0001pt;line-height:15.0pt;background:white;word=
-wrap:
          break-word;orphans: auto;text-align:start;widows:
          auto;-webkit-text-stroke-width: 0px;word-spacing:0px">
<span style=3D"font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-se=
rif&quot;;color:#333333">Michael Behringer: explained in message. We need t=
o mail this down so people understand.</span><o:p></o:p></p>
<p style=3D"mso-margin-top-alt:7.5pt;margin-right:0cm;margin-bottom:0cm;mar=
gin-left:0cm;margin-bottom:.0001pt;line-height:15.0pt;background:white;word=
-wrap:
          break-word;orphans: auto;text-align:start;widows:
          auto;-webkit-text-stroke-width: 0px;word-spacing:0px">
<span style=3D"font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-se=
rif&quot;;color:#333333">Michael Richardson: non normative</span><o:p></o:p=
></p>
<p style=3D"mso-margin-top-alt:7.5pt;margin-right:0cm;margin-bottom:0cm;mar=
gin-left:0cm;margin-bottom:.0001pt;line-height:15.0pt;background:white;word=
-wrap:
          break-word;orphans: auto;text-align:start;widows:
          auto;-webkit-text-stroke-width: 0px;word-spacing:0px">
<span style=3D"font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-se=
rif&quot;;color:#333333">Pascal Thubert: yes that is what we want in the se=
curity architecture</span><o:p></o:p></p>
<p style=3D"mso-margin-top-alt:7.5pt;margin-right:0cm;margin-bottom:0cm;mar=
gin-left:0cm;margin-bottom:.0001pt;line-height:15.0pt;background:white;word=
-wrap:
          break-word;orphans: auto;text-align:start;widows:
          auto;-webkit-text-stroke-width: 0px;word-spacing:0px">
<span style=3D"font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-se=
rif&quot;;color:#333333">Michael Behringer I need to leave soon</span><o:p>=
</o:p></p>
<p style=3D"mso-margin-top-alt:7.5pt;margin-right:0cm;margin-bottom:0cm;mar=
gin-left:0cm;margin-bottom:.0001pt;line-height:15.0pt;background:white;word=
-wrap:
          break-word;orphans: auto;text-align:start;widows:
          auto;-webkit-text-stroke-width: 0px;word-spacing:0px">
<span style=3D"font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-se=
rif&quot;;color:#333333">Michael Richardson: I answered to draft piro descr=
ies low level stuff. I want to encourage people to read and suggest that th=
is becomes WG doc in L2 layer 2 security. It is a very
 good draft. We may need to change the authorization but after that, great =
stuff can be found. Should be WG doc somewhere.</span><o:p></o:p></p>
<p style=3D"mso-margin-top-alt:7.5pt;margin-right:0cm;margin-bottom:0cm;mar=
gin-left:0cm;margin-bottom:.0001pt;line-height:15.0pt;background:white;word=
-wrap:
          break-word;orphans: auto;text-align:start;widows:
          auto;-webkit-text-stroke-width: 0px;word-spacing:0px">
<span style=3D"font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-se=
rif&quot;;color:#333333">Ren=E9 Struik: thoughts appreciated on mail I sent=
 today</span><o:p></o:p></p>
<p style=3D"mso-margin-top-alt:7.5pt;margin-right:0cm;margin-bottom:0cm;mar=
gin-left:0cm;margin-bottom:.0001pt;line-height:15.0pt;background:white;word=
-wrap:
          break-word;orphans: auto;text-align:start;widows:
          auto;-webkit-text-stroke-width: 0px;word-spacing:0px">
<span style=3D"font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-se=
rif&quot;;color:#333333">Pascal: Next call on Tuesday next week same time</=
span><o:p></o:p></p>
<p class=3D"MsoNormal" style=3D"mso-margin-top-alt:auto;mso-margin-bottom-a=
lt:auto;margin-left:0cm;text-indent:-18.0pt;line-height:15.0pt;mso-list:l5 =
level1 lfo14;background:white">
<![if !supportLists]><span style=3D"font-size:10.0pt;font-family:Symbol"><s=
pan style=3D"mso-list:Ignore">=B7<span style=3D"font:7.0pt &quot;Times New =
Roman&quot;">&nbsp;&nbsp;&nbsp;&nbsp;
</span></span></span><![endif]><em><span style=3D"font-size:10.5pt;font-fam=
ily:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">[08.06]</span><=
/em><span class=3D"apple-converted-space"><span style=3D"font-size:10.5pt;f=
ont-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">&nbsp;</=
span></span><span style=3D"font-size:10.5pt;font-family:&quot;Arial&quot;,&=
quot;sans-serif&quot;;color:#333333">meeting
 ends</span><o:p></o:p></p>
<p style=3D"mso-margin-top-alt:7.5pt;margin-right:0cm;margin-bottom:0cm;mar=
gin-left:0cm;margin-bottom:.0001pt;line-height:15.0pt;background:white;word=
-wrap:
          break-word;orphans: auto;text-align:start;widows:
          auto;-webkit-text-stroke-width: 0px;word-spacing:0px">
<span style=3D"font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-se=
rif&quot;;color:#333333">=3D=3D=3D=3D=3D=3D</span><o:p></o:p></p>
<p class=3D"MsoNormal">&nbsp;<o:p></o:p></p>
<p class=3D"MsoNormal"><span style=3D"font-size:12.0pt;font-family:&quot;Ti=
mes New Roman&quot;,&quot;serif&quot;"><br>
<br>
<br>
<o:p></o:p></span></p>
<pre>_______________________________________________<o:p></o:p></pre>
<pre>6tisch mailing list<o:p></o:p></pre>
<pre><a href=3D"mailto:6tisch@ietf.org">6tisch@ietf.org</a><o:p></o:p></pre=
>
<pre><a href=3D"https://www.ietf.org/mailman/listinfo/6tisch">https://www.i=
etf.org/mailman/listinfo/6tisch</a><o:p></o:p></pre>
</blockquote>
<p class=3D"MsoNormal"><span style=3D"font-size:12.0pt;font-family:&quot;Ti=
mes New Roman&quot;,&quot;serif&quot;"><br>
<br>
<br>
<o:p></o:p></span></p>
<pre>-- <o:p></o:p></pre>
<pre>email: <a href=3D"mailto:rstruik.ext@gmail.com">rstruik.ext@gmail.com<=
/a> | Skype: rstruik<o:p></o:p></pre>
<pre>cell: &#43;1 (647) 867-5658 | US: &#43;1 (415) 690-7363<o:p></o:p></pr=
e>
</div>
</div>
</body>
</html>

--_000_E045AECD98228444A58C61C200AE1BD842672168xmbrcdx01ciscoc_--


From nobody Wed May 21 05:23:29 2014
Return-Path: <mcr@sandelman.ca>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 74C501A0349; Wed, 21 May 2014 05:23:26 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.542
X-Spam-Level: 
X-Spam-Status: No, score=-2.542 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RP_MATCHES_RCVD=-0.651, SPF_PASS=-0.001, T_TVD_MIME_NO_HEADERS=0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 3jBj7OfvgJUu; Wed, 21 May 2014 05:23:24 -0700 (PDT)
Received: from tuna.sandelman.ca (tuna.sandelman.ca [IPv6:2607:f0b0:f:3::184]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id ADC671A0425; Wed, 21 May 2014 05:23:24 -0700 (PDT)
Received: from sandelman.ca (desk.marajade.sandelman.ca [209.87.252.247]) by tuna.sandelman.ca (Postfix) with ESMTP id 9206A20028; Wed, 21 May 2014 08:25:42 -0400 (EDT)
Received: by sandelman.ca (Postfix, from userid 179) id B453D63B1E; Wed, 21 May 2014 08:23:14 -0400 (EDT)
Received: from sandelman.ca (localhost [127.0.0.1]) by sandelman.ca (Postfix) with ESMTP id 9DDB963B1C; Wed, 21 May 2014 08:23:14 -0400 (EDT)
From: Michael Richardson <mcr+ietf@sandelman.ca>
To: 6tisch-security <6tisch-security@ietf.org>, 6tisch@ietf.org
In-Reply-To: <537B8705.1090609@gmail.com>
References: <E045AECD98228444A58C61C200AE1BD84266FEED@xmb-rcd-x01.cisco.com> <537B8705.1090609@gmail.com>
X-Mailer: MH-E 8.2; nmh 1.3-dev; GNU Emacs 23.4.1
X-Face: $\n1pF)h^`}$H>Hk{L"x@)JS7<%Az}5RyS@k9X%29-lHB$Ti.V>2bi.~ehC0; <'$9xN5Ub# z!G,p`nR&p7Fz@^UXIn156S8.~^@MJ*mMsD7=QFeq%AL4m<nPbLgmtKK-5dC@#:k
MIME-Version: 1.0
Content-Type: multipart/signed; boundary="=-=-="; micalg=pgp-sha1; protocol="application/pgp-signature"
Date: Wed, 21 May 2014 08:23:14 -0400
Message-ID: <26793.1400674994@sandelman.ca>
Sender: mcr@sandelman.ca
Archived-At: http://mailarchive.ietf.org/arch/msg/6tisch-security/dMAhvY2zIaJprnjveF-knFPUz1Q
Subject: Re: [6tisch-security] (review draft-piro-6tisch-security-issues-01) Re: [6tisch] Minutes Webex 20th May 2014, 6TiSCH Security
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 21 May 2014 12:23:26 -0000

--=-=-=


Rene Struik <rstruik.ext@gmail.com> wrote:

    > b) the draft introduces new 802.15.4-command frames to implement the key
    > negotiation phase (Section 6.3). As such, this would constitute a
    > change to the
    > 802.15.4-2011 and 802.15.4e-2012 specification. Besides, this also
    > implies that
    > the key negotiation phase can only deal with one-hop behavior.

It could be like, Zigbee with MLE, that one wants per-hop keys that are
unique across the network.  This has implications for broadcasts, of course.
If one looks at the M_k as not being pre-configured, but rather being
installed via the join process, then it isn't such an mismatch to what has
been proposed in the 6isch-security design team.
Otherwise, it wasn't so much the section on key derivation that I cared
about, as much as the rest of the document.

    > e) the key negotiation phase using the anonymous Diffie-Hellman scheme
    > (Section
    > 6.3.3) that uses ordinary Diffie-Hellman groups in the ring of integers
    > Zp, where p is a prime number that indexed by a publicly computable
    > integer

My opinion is that it is inappropriate to specify any crypto different from
what would already be there for (D)TLS.  Run it over PANA or MLE...

    > f) the 802.15.4-2011 specification mistakenly does not allow mixing of
    > secured
    > and unsecured traffic (see, e.g., my emails of end of January 2014 on
    > this). In
    > particular, the hybrid security network (as mentioned in Section 5) is
    > not
    > possible with 802.15.4-2011 or 802.15.4e-2012.

Agreed, and that's another reason to specify against 4e-2012.

--
Michael Richardson <mcr+IETF@sandelman.ca>, Sandelman Software Works
 -= IPv6 IoT consulting =-




--=-=-=
Content-Type: application/pgp-signature

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iQEVAwUBU3yasoCLcPvd0N1lAQKm8wf/ZjPho8zfT1q6Tk/5VsIaMnBwIjsGfTne
pgm4KxAbGQpZWjzHLfdxU66I7xJgWUaOL7j3nLkY3hq+NmZb+ZeKoqDp32nlObL4
S/axtlXQOf59fMVYuqkzsgbJA2KkpxR+phPvRNLXs1VcP+DdSQbub1tS7XNwfObq
QrudGO7cnKfbY2rqun7+DQzV49zLzOQPUw5DQ0fGn2WqiTlqfmXK3Q+l1tR/sg7a
+dcBTStz2VxmymskZHT4mBt5NJbwzudTrW+r1hwo1dw9jxmyCaO3dxB2W6nnKVN4
PaRZl6pimMN9aDGVYE0ByFvpk5GUthnFm8OduCwL75MNa9vrlQ191w==
=oD98
-----END PGP SIGNATURE-----
--=-=-=--


From nobody Thu May 22 07:28:32 2014
Return-Path: <pthubert@cisco.com>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id B93AF1A01B9; Thu, 22 May 2014 07:28:29 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -15.151
X-Spam-Level: 
X-Spam-Status: No, score=-15.151 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_HI=-5, RP_MATCHES_RCVD=-0.651, SPF_PASS=-0.001, USER_IN_DEF_DKIM_WL=-7.5] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id ki6kLRPoh-g9; Thu, 22 May 2014 07:28:26 -0700 (PDT)
Received: from mtv-iport-1.cisco.com (mtv-iport-1.cisco.com [173.36.130.12]) (using TLSv1 with cipher RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 2B0F61A017A; Thu, 22 May 2014 07:28:26 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cisco.com; i=@cisco.com; l=3465; q=dns/txt; s=iport; t=1400768905; x=1401978505; h=from:to:cc:subject:date:message-id:mime-version; bh=Zvmn8SYN4ZxlCQXLDnKwywwG54zdaGzkSR5uEB8V/5k=; b=XsxU3Tjar44ReGL64cRwIvBZgcsbAzggNwrbx4+eauCD4zPnpFqPay5p gwIe+tvncHww/D5z2K2bnDeMvPuhIXFIkqxfLU8AG54KLGbw8IveGNBWi u4JoefiMyFboHacYZdolwd1ZdRjD71lcLNy/75Qf+iNKsbT4SPzaufIdu M=;
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-Anti-Spam-Result: AkYFANMIflOtJA2E/2dsb2JhbABZgkJFUli7LIh+AYENFnSCJwEELUwSAQweViYBBA4NiDkN1jQXjh0xEIMigRUEmy6RaYM4bQGBQg
X-IronPort-AV: E=Sophos;i="4.98,887,1392163200";  d="scan'208,217";a="109151103"
Received: from alln-core-10.cisco.com ([173.36.13.132]) by mtv-iport-1.cisco.com with ESMTP; 22 May 2014 14:28:24 +0000
Received: from xhc-aln-x06.cisco.com (xhc-aln-x06.cisco.com [173.36.12.80]) by alln-core-10.cisco.com (8.14.5/8.14.5) with ESMTP id s4MESNne028794 (version=TLSv1/SSLv3 cipher=AES128-SHA bits=128 verify=FAIL); Thu, 22 May 2014 14:28:24 GMT
Received: from xmb-rcd-x01.cisco.com ([169.254.1.6]) by xhc-aln-x06.cisco.com ([173.36.12.80]) with mapi id 14.03.0123.003; Thu, 22 May 2014 09:28:23 -0500
From: "Pascal Thubert (pthubert)" <pthubert@cisco.com>
To: "6tisch@ietf.org" <6tisch@ietf.org>
Thread-Topic: XML2RFC
Thread-Index: Ac91yf/Um8rjErTBQ5GZpuEc0KwH6w==
Date: Thu, 22 May 2014 14:28:23 +0000
Deferred-Delivery: Thu, 22 May 2014 14:28:00 +0000
Message-ID: <E045AECD98228444A58C61C200AE1BD842676179@xmb-rcd-x01.cisco.com>
Accept-Language: fr-FR, en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
x-originating-ip: [10.55.22.4]
Content-Type: multipart/alternative; boundary="_000_E045AECD98228444A58C61C200AE1BD842676179xmbrcdx01ciscoc_"
MIME-Version: 1.0
Archived-At: http://mailarchive.ietf.org/arch/msg/6tisch-security/aY0P2GotuGQEjXY2Z4JrsdOnYbA
Cc: "6tisch-security@ietf.org" <6tisch-security@ietf.org>
Subject: [6tisch-security] XML2RFC
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 22 May 2014 14:28:29 -0000

--_000_E045AECD98228444A58C61C200AE1BD842676179xmbrcdx01ciscoc_
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable

Dear all,

For those using xml.resource.org on line to compile their I-Draft, the site=
 is unreachable but http://xml2rfc.tools.ietf.org/ is available with the ne=
w beta.
If you prefer to use the currently released version, you can go to the old =
xml2rfc<http://xml2rfc.tools.ietf.org/old.html> page.

Cheers

Pascal

--_000_E045AECD98228444A58C61C200AE1BD842676179xmbrcdx01ciscoc_
Content-Type: text/html; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable

<html xmlns:v=3D"urn:schemas-microsoft-com:vml" xmlns:o=3D"urn:schemas-micr=
osoft-com:office:office" xmlns:w=3D"urn:schemas-microsoft-com:office:word" =
xmlns:m=3D"http://schemas.microsoft.com/office/2004/12/omml" xmlns=3D"http:=
//www.w3.org/TR/REC-html40">
<head>
<meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3Dus-ascii"=
>
<meta name=3D"Generator" content=3D"Microsoft Word 14 (filtered medium)">
<style><!--
/* Font Definitions */
@font-face
	{font-family:Calibri;
	panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
	{font-family:Tahoma;
	panose-1:2 11 6 4 3 5 4 4 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
	{margin:0cm;
	margin-bottom:.0001pt;
	font-size:11.0pt;
	font-family:"Calibri","sans-serif";}
a:link, span.MsoHyperlink
	{mso-style-priority:99;
	color:blue;
	text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
	{mso-style-priority:99;
	color:purple;
	text-decoration:underline;}
p.MsoAcetate, li.MsoAcetate, div.MsoAcetate
	{mso-style-priority:99;
	mso-style-link:"Balloon Text Char";
	margin:0cm;
	margin-bottom:.0001pt;
	font-size:8.0pt;
	font-family:"Tahoma","sans-serif";}
span.EmailStyle17
	{mso-style-type:personal-compose;
	font-family:"Calibri","sans-serif";
	color:windowtext;}
span.BalloonTextChar
	{mso-style-name:"Balloon Text Char";
	mso-style-priority:99;
	mso-style-link:"Balloon Text";
	font-family:"Tahoma","sans-serif";}
.MsoChpDefault
	{mso-style-type:export-only;
	font-family:"Calibri","sans-serif";}
@page WordSection1
	{size:612.0pt 792.0pt;
	margin:70.85pt 70.85pt 70.85pt 70.85pt;}
div.WordSection1
	{page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext=3D"edit" spidmax=3D"1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext=3D"edit">
<o:idmap v:ext=3D"edit" data=3D"1" />
</o:shapelayout></xml><![endif]-->
</head>
<body lang=3D"EN-US" link=3D"blue" vlink=3D"purple">
<div class=3D"WordSection1">
<p class=3D"MsoNormal">Dear all,<o:p></o:p></p>
<p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoNormal">For those using xml.resource.org on line to compile =
their I-Draft, the site is unreachable but
<a href=3D"http://xml2rfc.tools.ietf.org/">http://xml2rfc.tools.ietf.org/</=
a> is available with the new beta.<o:p></o:p></p>
<p class=3D"MsoNormal">If you prefer to use the currently released version,=
 you can go to the
<a href=3D"http://xml2rfc.tools.ietf.org/old.html">old xml2rfc</a> page.<o:=
p></o:p></p>
<p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoNormal">Cheers<o:p></o:p></p>
<p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoNormal">Pascal<o:p></o:p></p>
</div>
</body>
</html>

--_000_E045AECD98228444A58C61C200AE1BD842676179xmbrcdx01ciscoc_--


From nobody Thu May 22 09:11:52 2014
Return-Path: <cabo@tzi.org>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id A5E4F1A01DD; Thu, 22 May 2014 07:33:21 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.551
X-Spam-Level: 
X-Spam-Status: No, score=-1.551 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HELO_EQ_DE=0.35, SPF_HELO_PASS=-0.001] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 78UiVzmGWgRT; Thu, 22 May 2014 07:33:20 -0700 (PDT)
Received: from informatik.uni-bremen.de (mailhost.informatik.uni-bremen.de [IPv6:2001:638:708:30c9::12]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 8AD801A01C7; Thu, 22 May 2014 07:32:33 -0700 (PDT)
X-Virus-Scanned: amavisd-new at informatik.uni-bremen.de
Received: from smtp-fb3.informatik.uni-bremen.de (smtp-fb3.informatik.uni-bremen.de [134.102.224.120]) by informatik.uni-bremen.de (8.14.5/8.14.5) with ESMTP id s4MEWKtQ023760; Thu, 22 May 2014 16:32:20 +0200 (CEST)
Received: from [192.168.217.145] (p54893706.dip0.t-ipconnect.de [84.137.55.6]) (using TLSv1 with cipher AES128-SHA (128/128 bits)) (No client certificate requested) by smtp-fb3.informatik.uni-bremen.de (Postfix) with ESMTPSA id 4BF64164D; Thu, 22 May 2014 16:32:19 +0200 (CEST)
Content-Type: text/plain; charset=iso-8859-1
Mime-Version: 1.0 (Mac OS X Mail 7.3 \(1878.2\))
From: Carsten Bormann <cabo@tzi.org>
In-Reply-To: <E045AECD98228444A58C61C200AE1BD842676179@xmb-rcd-x01.cisco.com>
Date: Thu, 22 May 2014 16:32:17 +0200
X-Mao-Original-Outgoing-Id: 422461937.62905-d0f4d0848065deb9034360a2e045fe17
Content-Transfer-Encoding: quoted-printable
Message-Id: <D706CD2B-E953-4520-BF1B-4C637331173A@tzi.org>
References: <E045AECD98228444A58C61C200AE1BD842676179@xmb-rcd-x01.cisco.com>
To: "Pascal Thubert (pthubert)" <pthubert@cisco.com>
X-Mailer: Apple Mail (2.1878.2)
Archived-At: http://mailarchive.ietf.org/arch/msg/6tisch-security/2Ol484IRII8Bm5jyQYUNS4rdlM8
X-Mailman-Approved-At: Thu, 22 May 2014 09:11:44 -0700
Cc: "6tisch@ietf.org" <6tisch@ietf.org>, "6tisch-security@ietf.org" <6tisch-security@ietf.org>
Subject: Re: [6tisch-security] [6tisch] XML2RFC
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 22 May 2014 14:33:21 -0000

On 22 May 2014, at 16:28, Pascal Thubert (pthubert) <pthubert@cisco.com> =
wrote:

> For those using xml.resource.org on line to compile their I-Draft, the =
site is unreachable but http://xml2rfc.tools.ietf.org/ is available with =
the new beta.
> If you prefer to use the currently released version, you can go to the =
old xml2rfc page.

You probably also need to fix all the entity references by replacing =
xml.resource.org with xml2rfc.tools.ietf.org in your XML.

If you are using kramdown-rfc2629 to build your drafts, I have pushed =
version 1.0.12 with an emergency fix:

	gem update kramdown-rfc2629=20

if you need this; no further hacking required.

Gr=FC=DFe, Carsten


From nobody Thu May 22 17:43:12 2014
Return-Path: <twatteyne@gmail.com>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 69AED1A0274; Thu, 22 May 2014 17:43:09 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.277
X-Spam-Level: 
X-Spam-Status: No, score=-1.277 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, FM_FORGED_GMAIL=0.622, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, SPF_PASS=-0.001] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id W1CObbXC2DVs; Thu, 22 May 2014 17:43:06 -0700 (PDT)
Received: from mail-pb0-x231.google.com (mail-pb0-x231.google.com [IPv6:2607:f8b0:400e:c01::231]) (using TLSv1 with cipher ECDHE-RSA-RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 6CF5A1A024F; Thu, 22 May 2014 17:43:06 -0700 (PDT)
Received: by mail-pb0-f49.google.com with SMTP id jt11so3263577pbb.22 for <multiple recipients>; Thu, 22 May 2014 17:43:05 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113;  h=mime-version:sender:in-reply-to:references:from:date:message-id :subject:to:content-type; bh=LNHG7rpFtCJJ8mnjhDY5ZT3J75oEebL6/lws3v4epRg=; b=GNpkbKzsejwEMMp6OUgxAg1PLHxTBqglxHSZDf7vI0Sd55QriD6+oHTEOT7Y8EVIWp 3ZOSPPEsbh4Yc4ykr+p8zx1yLQ4WzFvSieeOs3W/M4O3GqEWWswpDshA8IIGdYw+zzrf z9iqRwkkZYCxC3ai31nKK0360YMCyF6JSKZ3uLkAPsMoW9QWk80+T3HSKgrJEFnRlb74 aHduZ8TghWDYYKD/5x9mkUZ6JUNDN6vaU5Bt16oXqE2sTyDpr4sutepbNwPddP9EZWpf Jc5CFl/mAskxnPUzhjBmiTfZBhpe4hWi+ISE0AXo8qzQj02lObT+iuXBiS/mmnskVnsB am4Q==
X-Received: by 10.68.173.65 with SMTP id bi1mr1453743pbc.130.1400805784860; Thu, 22 May 2014 17:43:04 -0700 (PDT)
MIME-Version: 1.0
Sender: twatteyne@gmail.com
Received: by 10.66.154.130 with HTTP; Thu, 22 May 2014 17:42:44 -0700 (PDT)
In-Reply-To: <537B7A76.7030201@gmail.com>
References: <E045AECD98228444A58C61C200AE1BD84266FEED@xmb-rcd-x01.cisco.com> <537B7A32.9090900@gmail.com> <537B7A76.7030201@gmail.com>
From: Thomas Watteyne <watteyne@eecs.berkeley.edu>
Date: Thu, 22 May 2014 17:42:44 -0700
X-Google-Sender-Auth: QRgjRLd3X_Kth33fyfPa-NPUNJ8
Message-ID: <CADJ9OA8r2mMaKN9a7a=x1LevB4ArRpNtLOjnf_Mhx7Sm_+JDsA@mail.gmail.com>
To: tisch-security <6tisch-security@ietf.org>, "6tisch@ietf.org" <6tisch@ietf.org>
Content-Type: multipart/alternative; boundary=047d7b3a99d834c05404fa06831e
Archived-At: http://mailarchive.ietf.org/arch/msg/6tisch-security/x1d7JDOZFbt-aquj6F5BAotEcfs
Subject: Re: [6tisch-security] [6tisch] Minutes Webex 20th May 2014, 6TiSCH Security
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 23 May 2014 00:43:09 -0000

--047d7b3a99d834c05404fa06831e
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

Rene,
Minutes updated at
https://bitbucket.org/6tisch/meetings/wiki/140520_webex_security,
copy-pasted below.
Thomas

---

Minutes Webex 20th May 2014, 6TiSCH Security
------------------------------
Taking notes *(using Etherpad)*

   1. Pascal Thubert

Present *(alphabetically)*

   1. Hank Mauldin
   2. Michael Behringer
   3. Michael Richardson
   4. Maik Seewald
   5. Ren=C3=A9 Struik
   6. Tom Phinney
   7. Yoshihiro Ohba

Recording

   - Webex recording<https://cisco.webex.com/ciscosales/lsr.php?RCID=3Dcf23=
4f58e8f94d2f86fbe15e7d6862df>

Agenda

   1. Look at Join Protocol

Action Items

   1. Michael R. to suggest to the list a review of draft piro
   2. Michael B. to check with Max Pritikin about format on authorization
   token.
   3. All to review email RS as of May 20, 2014, 9:45am EDT and give
   feedback re details identified outstanding issues

   e-mail at:
   http://www.ietf.org/mail-archive/web/6tisch-security/current/msg00086.ht=
ml


Minutes

   - *[07.10]* Meeting starts

Michael Richardson: network manager programs the device, no particular
authorization of the network to the device, nor way for device to prove it
is authorized apart from having the join key provisioned

Ren=C3=A9 Struik: unless missing something, need size of configuration mess=
ages.
How to get tag names in the device and map that into 802.15.4 MAC
addresses. Details we do not really have. Unclear how device can discover
the network. Ties in AR certificate issue

Michael Richardson: problem exists regardless of actual enrolment process.

Ren=C3=A9 Struik: there is also a control element when certificate can be u=
sed

Michael Richardson: sent message on Wile coyote; is it realistic?

Ren=C3=A9 Struik: quick feedback. say vendor generates cert for bunch of de=
vices
and it goes along a chain and then more attributes allow link back to
factory. works, does not have to be AR certificate

Michael Richardson: I expected the kind of certificate I describe in AR but
it is not the point of AR. They do not even specify the format of device
ID. AR is really about an API not about content of certificate apart from
signature algorithm for which they have requirements. They do not even
define their own extensions. One extension with multiple values

Michael Richardson if you use secure enrolment, you can replace the cert
but you still need to validate the device. Need Michael B. and Max to
describe their token

Michael Behringer: AR or not AR? process is about an institution that owns
a device and has a secured relationship based on a certificate that tit
signed. Can be 1AR or anything, e.g. an institution which owned the device
before. Need that cert from old organization to help bootstrap in new
organization.

Michael Richardson: did you define how the authorization token can be
passed in an interoperable fashion

Michael Behringer: leverage secure relationship between vendor and device
to pass a signed message to the device

Michael Richardson: does it bind to the new owner? which way, not subject
to standardization or is it?

Michael Behringer: May not need standard, but if multivendor network user
would like a common format. between vendor and new device can be proprietar=
y

Michael Richardson: need ot define when how the token is transported, and
that is not end to end. reasons of trust, rate limit etc...

Michael Behringer: new device sends along a nonce and expect that nonce in
response from vendor site; without nonce, token could come from the past.
Both models are required in the market. Some want fresh, others e.g.
military there cannot be comm at the deployment time.

Michael Richardson: content of token may or not be standard. transport of
token must be standard.

Michael Richardson: using RFC 3779 would address cert that had 1AR IdevID
in them. need a range in the certificate otherwise one certificate per
device

Michael Behringer: token or certificate?

Michael Richardson if the token is a certificate need a way to delegate
down the chain. But breach along the way breaches it all below. no good. Do
you have to maintain a cert for every device?

Michael Behringer: that's the starting point. You assume that's a
scalability issue at some point right

Michael Richardson: provisioning trouble is possible. Tracking by bulk
could be more palatable

Michael Behringer: if name space is aggregatable could work. In early
approach, token is not a cert and stealing the token does not help.

Michael Richardson: anxious about spare parts that did not join, and go
unserviceable

Michael Behringer: yes, we can take the req in draft-pritikin

Michael Richardson proposing do something like RFC 3779. It as AS numbers
to allow reg to delegate using cert; these are live devIDs from a pool.
should look at that doc and we could change all AS to IdevID and we'd be
done.

Michael Behringer: sounds like an idea we'll look at it

Michael Richardson: draft pritikin does not tell whether the enrolment
allow transport of authorization token back and forth and then the cert for
the TLS transport can be validated. Then you have a secure transport and
can enrol replacing the vendor cert with a domain cert.

Michael Behringer: refer to a mail by Max Pritikin "[6tisch-security] a
different explanation of autonomic" .

Michael Richardson: where is the process ?

Michael Behringer: explained in message. We need to mail this down so
people understand.

Michael Richardson: non normative

Pascal Thubert: yes that is what we want in the security architecture

Michael Behringer I need to leave soon

Michael Richardson: I answered to draft piro descries low level stuff. I
want to encourage people to read and suggest that this becomes WG doc in L2
layer 2 security. It is a very good draft. We may need to change the
authorization but after that, great stuff can be found. Should be WG doc
somewhere.

Ren=C3=A9 Struik: thoughts appreciated on mail I sent today

Pascal: Next call on Tuesday next week same time

   - *[08.06]* meeting ends

=3D=3D=3D=3D=3D=3D


On Tue, May 20, 2014 at 8:53 AM, Rene Struik <rstruik.ext@gmail.com> wrote:

>  now also to the 6tisch-security list (rather than 6tisch list).
>
>
> On 5/20/2014 11:52 AM, Rene Struik wrote:
>
> Hi Pascal:
>
> I would like to suggest adding one more action item:
> All to review email RS as of May 20, 2014, 9:45am EDT and give feedback r=
e
> details identified outstanding issues.
>
> Rene
>
> =3D=3D
> Ren=C3=A9 Struik: thoughts appreciated on mail I sent today
>
> On 5/20/2014 11:38 AM, Pascal Thubert (pthubert) wrote:
>
>  Minutes Webex 20th May 2014, 6TiSCH Security
> ------------------------------
>  Taking notes *(using Etherpad)*
>
> 1.     Pascal Thubert
>  Present *(alphabetically)*
>
> 1.     Hank Mauldin
>
> 2.     Michael Behringer
>
> 3.     Michael Richardson
>
> 4.     Maik Seewald
>
> 5.     Ren=C3=A9 Struik
>
> 6.     Tom Phinney
>
> 7.     Yoshihiro Ohba
>  Recording
>
> =C2=B7        Webex recording<https://cisco.webex.com/ciscosales/lsr.php?=
RCID=3Dcf234f58e8f94d2f86fbe15e7d6862df>
>  Agenda
>
> 1.     Look at Join Protocol
>  Action Items
>
> 1.     Michael R. to suggest to the list a review of draft piro
>
> 2.     Michael B. to check with Max Pritikin about format on
> authorization token.
>  Minutes
>
> =C2=B7        *[07.10]* Meeting starts
>
> Michael Richardson: network manager programs the device, no particular
> authorization of the network to the device, nor way for device to prove i=
t
> is authorized apart from having the join key provisioned
>
> Ren=C3=A9 Struik: unless missing something, need size of configuration
> messages. How to get tag names in the device and map that into 802.15.4 M=
AC
> addresses. Details we do not really have. Unclear how device can discover
> the network. Ties in AR certificate issue
>
> Michael Richardson: problem exists regardless of actual enrolment process=
.
>
> Ren=C3=A9 Struik: there is also a control element when certificate can be=
 used
>
> Michael Richardson: sent message on Wile coyote; is it realistic?
>
> Ren=C3=A9 Struik: quick feedback. say vendor generates cert for bunch of
> devices and it goes along a chain and then more attributes allow link bac=
k
> to factory. works, does not have to be AR certificate
>
> Michael Richardson: I expected the kind of certificate I describe in AR
> but it is not the point of AR. They do not even specify the format of
> device ID. AR is really about an API not about content of certificate apa=
rt
> from signature algorithm for which they have requirements. They do not ev=
en
> define their own extensions. One extension with multiple values
>
> Michael Richardson if you use secure enrolment, you can replace the cert
> but you still need to validate the device. Need Michael B. and Max to
> describe their token
>
> Michael Behringer: AR or not AR? process is about an institution that own=
s
> a device and has a secured relationship based on a certificate that tit
> signed. Can be 1AR or anything, e.g. an institution which owned the devic=
e
> before. Need that cert from old organization to help bootstrap in new
> organization.
>
> Michael Richardson: did you define how the authorization token can be
> passed in an interoperable fashion
>
> Michael Behringer: leverage secure relationship between vendor and device
> to pass a signed message to the device
>
> Michael Richardson: does it bind to the new owner? which way, not subject
> to standardization or is it?
>
> Michael Behringer: May not need standard, but if multivendor network user
> would like a common format. between vendor and new device can be propriet=
ary
>
> Michael Richardson: need ot define when how the token is transported, and
> that is not end to end. reasons of trust, rate limit etc...
>
> Michael Behringer: new device sends along a nonce and expect that nonce i=
n
> response from vendor site; without nonce, token could come from the past.
> Both models are required in the market. Some want fresh, others e.g.
> military there cannot be comm at the deployment time.
>
> Michael Richardson: content of token may or not be standard. transport of
> token must be standard.
>
> Michael Richardson: using RFC 3779 would address cert that had 1AR IdevID
> in them. need a range in the certificate otherwise one certificate per
> device
>
> Michael Behringer: token or certificate?
>
> Michael Richardson if the token is a certificate need a way to delegate
> down the chain. But breach along the way breaches it all below. no good. =
Do
> you have to maintain a cert for every device?
>
> Michael Behringer: that's the starting point. You assume that's a
> scalability issue at some point right
>
> Michael Richardson: provisioning trouble is possible. Tracking by bulk
> could be more palatable
>
> Michael Behringer: if name space is aggregatable could work. In early
> approach, token is not a cert and stealing the token does not help.
>
> Michael Richardson: anxious about spare parts that did not join, and go
> unserviceable
>
> Michael Behringer: yes, we can take the req in draft-pritikin
>
> Michael Richardson proposing do something like RFC 3779. It as AS numbers
> to allow reg to delegate using cert; these are live devIDs from a pool.
> should look at that doc and we could change all AS to IdevID and we'd be
> done.
>
> Michael Behringer: sounds like an idea we'll look at it
>
> Michael Richardson: draft pritikin does not tell whether the enrolment
> allow transport of authorization token back and forth and then the cert f=
or
> the TLS transport can be validated. Then you have a secure transport and
> can enrol replacing the vendor cert with a domain cert.
>
> Michael Behringer: refer to a mail by Max Pritikin "[6tisch-security] a
> different explanation of autonomic" .
>
> Michael Richardson: where is the process ?
>
> Michael Behringer: explained in message. We need to mail this down so
> people understand.
>
> Michael Richardson: non normative
>
> Pascal Thubert: yes that is what we want in the security architecture
>
> Michael Behringer I need to leave soon
>
> Michael Richardson: I answered to draft piro descries low level stuff. I
> want to encourage people to read and suggest that this becomes WG doc in =
L2
> layer 2 security. It is a very good draft. We may need to change the
> authorization but after that, great stuff can be found. Should be WG doc
> somewhere.
>
> Ren=C3=A9 Struik: thoughts appreciated on mail I sent today
>
> Pascal: Next call on Tuesday next week same time
>
> =C2=B7        *[08.06]* meeting ends
>
> =3D=3D=3D=3D=3D=3D
>
>
>
>
> _______________________________________________
> 6tisch mailing list6tisch@ietf.orghttps://www.ietf.org/mailman/listinfo/6=
tisch
>
>
>
> --
> email: rstruik.ext@gmail.com | Skype: rstruik
> cell: +1 (647) 867-5658 | US: +1 (415) 690-7363
>
>
>
> --
> email: rstruik.ext@gmail.com | Skype: rstruik
> cell: +1 (647) 867-5658 | US: +1 (415) 690-7363
>
>
> _______________________________________________
> 6tisch-security mailing list
> 6tisch-security@ietf.org
> https://www.ietf.org/mailman/listinfo/6tisch-security
>
>

--047d7b3a99d834c05404fa06831e
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr">Rene,<div>Minutes updated at=C2=A0<a href=3D"https://bitbu=
cket.org/6tisch/meetings/wiki/140520_webex_security">https://bitbucket.org/=
6tisch/meetings/wiki/140520_webex_security</a>, copy-pasted below.</div><di=
v>Thomas</div>

<div><br></div><div>---</div><div><br></div><div><h1 id=3D"markdown-header-=
minutes-webex-20th-may-2014-6tisch-security" style=3D"margin:0px 0px 10px;p=
adding:0px;font-size:24px;font-weight:normal;line-height:1.25;color:rgb(51,=
51,51);font-family:Arial,sans-serif">

Minutes Webex 20th May 2014, 6TiSCH Security</h1><hr style=3D"margin:20px 0=
px;border-top-width:0px;border-right-width:0px;border-left-width:0px;border=
-bottom-style:solid;border-bottom-color:rgb(204,204,204);color:rgb(51,51,51=
);font-family:Arial,sans-serif;font-size:14px;line-height:20px">

<h2 id=3D"markdown-header-taking-notes-using-etherpad" style=3D"margin:20px=
 0px 0px;padding:0px;font-size:20px;font-weight:normal;line-height:1.5;colo=
r:rgb(51,51,51);font-family:Arial,sans-serif">Taking notes=C2=A0<em>(using =
Etherpad)</em></h2>

<ol style=3D"margin:10px 0px 0px;color:rgb(51,51,51);font-family:Arial,sans=
-serif;font-size:14px;line-height:20px"><li style=3D"word-wrap:break-word">=
Pascal Thubert</li></ol><h2 id=3D"markdown-header-present-alphabetically" s=
tyle=3D"margin:20px 0px 0px;padding:0px;font-size:20px;font-weight:normal;l=
ine-height:1.5;color:rgb(51,51,51);font-family:Arial,sans-serif">

Present=C2=A0<em>(alphabetically)</em></h2><ol style=3D"margin:10px 0px 0px=
;color:rgb(51,51,51);font-family:Arial,sans-serif;font-size:14px;line-heigh=
t:20px"><li style=3D"word-wrap:break-word">Hank Mauldin</li><li style=3D"wo=
rd-wrap:break-word">

Michael Behringer</li><li style=3D"word-wrap:break-word">Michael Richardson=
</li><li style=3D"word-wrap:break-word">Maik Seewald</li><li style=3D"word-=
wrap:break-word">Ren=C3=A9 Struik</li><li style=3D"word-wrap:break-word">To=
m Phinney</li>

<li style=3D"word-wrap:break-word">Yoshihiro Ohba</li></ol><h2 id=3D"markdo=
wn-header-recording" style=3D"margin:20px 0px 0px;padding:0px;font-size:20p=
x;font-weight:normal;line-height:1.5;color:rgb(51,51,51);font-family:Arial,=
sans-serif">

Recording</h2><ul style=3D"margin:10px 0px 0px;color:rgb(51,51,51);font-fam=
ily:Arial,sans-serif;font-size:14px;line-height:20px"><li style=3D"word-wra=
p:break-word"><a href=3D"https://cisco.webex.com/ciscosales/lsr.php?RCID=3D=
cf234f58e8f94d2f86fbe15e7d6862df" style=3D"color:rgb(59,115,175);text-decor=
ation:none">Webex recording</a></li>

</ul><h2 id=3D"markdown-header-agenda" style=3D"margin:20px 0px 0px;padding=
:0px;font-size:20px;font-weight:normal;line-height:1.5;color:rgb(51,51,51);=
font-family:Arial,sans-serif">Agenda</h2><ol style=3D"margin:10px 0px 0px;c=
olor:rgb(51,51,51);font-family:Arial,sans-serif;font-size:14px;line-height:=
20px">

<li style=3D"word-wrap:break-word">Look at Join Protocol</li></ol><h2 id=3D=
"markdown-header-action-items" style=3D"margin:20px 0px 0px;padding:0px;fon=
t-size:20px;font-weight:normal;line-height:1.5;color:rgb(51,51,51);font-fam=
ily:Arial,sans-serif">

Action Items</h2><ol style=3D"margin:10px 0px 0px;color:rgb(51,51,51);font-=
family:Arial,sans-serif;font-size:14px;line-height:20px"><li style=3D"word-=
wrap:break-word">Michael R. to suggest to the list a review of draft piro</=
li>

<li style=3D"word-wrap:break-word">Michael B. to check with Max Pritikin ab=
out format on authorization token.</li><li style=3D"word-wrap:break-word">A=
ll to review email RS as of May 20, 2014, 9:45am EDT and give feedback re d=
etails identified outstanding issues<blockquote style=3D"margin:0px 0px 0px=
 19px;border-left-width:1px;border-left-style:solid;border-left-color:rgb(2=
04,204,204);color:rgb(112,112,112);padding:10px 20px">

<p style=3D"margin:0px;padding:0px;word-wrap:break-word">e-mail at:=C2=A0<a=
 href=3D"http://www.ietf.org/mail-archive/web/6tisch-security/current/msg00=
086.html" rel=3D"nofollow" style=3D"color:rgb(59,115,175);text-decoration:n=
one">http://www.ietf.org/mail-archive/web/6tisch-security/current/msg00086.=
html</a></p>

</blockquote></li></ol><h2 id=3D"markdown-header-minutes" style=3D"margin:2=
0px 0px 0px;padding:0px;font-size:20px;font-weight:normal;line-height:1.5;c=
olor:rgb(51,51,51);font-family:Arial,sans-serif">Minutes</h2><ul style=3D"m=
argin:10px 0px 0px;color:rgb(51,51,51);font-family:Arial,sans-serif;font-si=
ze:14px;line-height:20px">

<li style=3D"word-wrap:break-word"><em>[07.10]</em>=C2=A0Meeting starts</li=
></ul><p style=3D"margin:10px 0px 0px;padding:0px;word-wrap:break-word;colo=
r:rgb(51,51,51);font-family:Arial,sans-serif;font-size:14px;line-height:20p=
x">Michael Richardson: network manager programs the device, no particular a=
uthorization of the network to the device, nor way for device to prove it i=
s authorized apart from having the join key provisioned</p>

<p style=3D"margin:10px 0px 0px;padding:0px;word-wrap:break-word;color:rgb(=
51,51,51);font-family:Arial,sans-serif;font-size:14px;line-height:20px">Ren=
=C3=A9 Struik: unless missing something, need size of configuration message=
s. How to get tag names in the device and map that into 802.15.4 MAC addres=
ses. Details we do not really have. Unclear how device can discover the net=
work. Ties in AR certificate issue</p>

<p style=3D"margin:10px 0px 0px;padding:0px;word-wrap:break-word;color:rgb(=
51,51,51);font-family:Arial,sans-serif;font-size:14px;line-height:20px">Mic=
hael Richardson: problem exists regardless of actual enrolment process.</p>

<p style=3D"margin:10px 0px 0px;padding:0px;word-wrap:break-word;color:rgb(=
51,51,51);font-family:Arial,sans-serif;font-size:14px;line-height:20px">Ren=
=C3=A9 Struik: there is also a control element when certificate can be used=
</p>

<p style=3D"margin:10px 0px 0px;padding:0px;word-wrap:break-word;color:rgb(=
51,51,51);font-family:Arial,sans-serif;font-size:14px;line-height:20px">Mic=
hael Richardson: sent message on Wile coyote; is it realistic?</p><p style=
=3D"margin:10px 0px 0px;padding:0px;word-wrap:break-word;color:rgb(51,51,51=
);font-family:Arial,sans-serif;font-size:14px;line-height:20px">

Ren=C3=A9 Struik: quick feedback. say vendor generates cert for bunch of de=
vices and it goes along a chain and then more attributes allow link back to=
 factory. works, does not have to be AR certificate</p><p style=3D"margin:1=
0px 0px 0px;padding:0px;word-wrap:break-word;color:rgb(51,51,51);font-famil=
y:Arial,sans-serif;font-size:14px;line-height:20px">

Michael Richardson: I expected the kind of certificate I describe in AR but=
 it is not the point of AR. They do not even specify the format of device I=
D. AR is really about an API not about content of certificate apart from si=
gnature algorithm for which they have requirements. They do not even define=
 their own extensions. One extension with multiple values</p>

<p style=3D"margin:10px 0px 0px;padding:0px;word-wrap:break-word;color:rgb(=
51,51,51);font-family:Arial,sans-serif;font-size:14px;line-height:20px">Mic=
hael Richardson if you use secure enrolment, you can replace the cert but y=
ou still need to validate the device. Need Michael B. and Max to describe t=
heir token</p>

<p style=3D"margin:10px 0px 0px;padding:0px;word-wrap:break-word;color:rgb(=
51,51,51);font-family:Arial,sans-serif;font-size:14px;line-height:20px">Mic=
hael Behringer: AR or not AR? process is about an institution that owns a d=
evice and has a secured relationship based on a certificate that tit signed=
. Can be 1AR or anything, e.g. an institution which owned the device before=
. Need that cert from old organization to help bootstrap in new organizatio=
n.</p>

<p style=3D"margin:10px 0px 0px;padding:0px;word-wrap:break-word;color:rgb(=
51,51,51);font-family:Arial,sans-serif;font-size:14px;line-height:20px">Mic=
hael Richardson: did you define how the authorization token can be passed i=
n an interoperable fashion</p>

<p style=3D"margin:10px 0px 0px;padding:0px;word-wrap:break-word;color:rgb(=
51,51,51);font-family:Arial,sans-serif;font-size:14px;line-height:20px">Mic=
hael Behringer: leverage secure relationship between vendor and device to p=
ass a signed message to the device</p>

<p style=3D"margin:10px 0px 0px;padding:0px;word-wrap:break-word;color:rgb(=
51,51,51);font-family:Arial,sans-serif;font-size:14px;line-height:20px">Mic=
hael Richardson: does it bind to the new owner? which way, not subject to s=
tandardization or is it?</p>

<p style=3D"margin:10px 0px 0px;padding:0px;word-wrap:break-word;color:rgb(=
51,51,51);font-family:Arial,sans-serif;font-size:14px;line-height:20px">Mic=
hael Behringer: May not need standard, but if multivendor network user woul=
d like a common format. between vendor and new device can be proprietary</p=
>

<p style=3D"margin:10px 0px 0px;padding:0px;word-wrap:break-word;color:rgb(=
51,51,51);font-family:Arial,sans-serif;font-size:14px;line-height:20px">Mic=
hael Richardson: need ot define when how the token is transported, and that=
 is not end to end. reasons of trust, rate limit etc...</p>

<p style=3D"margin:10px 0px 0px;padding:0px;word-wrap:break-word;color:rgb(=
51,51,51);font-family:Arial,sans-serif;font-size:14px;line-height:20px">Mic=
hael Behringer: new device sends along a nonce and expect that nonce in res=
ponse from vendor site; without nonce, token could come from the past. Both=
 models are required in the market. Some want fresh, others e.g. military t=
here cannot be comm at the deployment time.</p>

<p style=3D"margin:10px 0px 0px;padding:0px;word-wrap:break-word;color:rgb(=
51,51,51);font-family:Arial,sans-serif;font-size:14px;line-height:20px">Mic=
hael Richardson: content of token may or not be standard. transport of toke=
n must be standard.</p>

<p style=3D"margin:10px 0px 0px;padding:0px;word-wrap:break-word;color:rgb(=
51,51,51);font-family:Arial,sans-serif;font-size:14px;line-height:20px">Mic=
hael Richardson: using RFC 3779 would address cert that had 1AR IdevID in t=
hem. need a range in the certificate otherwise one certificate per device</=
p>

<p style=3D"margin:10px 0px 0px;padding:0px;word-wrap:break-word;color:rgb(=
51,51,51);font-family:Arial,sans-serif;font-size:14px;line-height:20px">Mic=
hael Behringer: token or certificate?</p><p style=3D"margin:10px 0px 0px;pa=
dding:0px;word-wrap:break-word;color:rgb(51,51,51);font-family:Arial,sans-s=
erif;font-size:14px;line-height:20px">

Michael Richardson if the token is a certificate need a way to delegate dow=
n the chain. But breach along the way breaches it all below. no good. Do yo=
u have to maintain a cert for every device?</p><p style=3D"margin:10px 0px =
0px;padding:0px;word-wrap:break-word;color:rgb(51,51,51);font-family:Arial,=
sans-serif;font-size:14px;line-height:20px">

Michael Behringer: that&#39;s the starting point. You assume that&#39;s a s=
calability issue at some point right</p><p style=3D"margin:10px 0px 0px;pad=
ding:0px;word-wrap:break-word;color:rgb(51,51,51);font-family:Arial,sans-se=
rif;font-size:14px;line-height:20px">

Michael Richardson: provisioning trouble is possible. Tracking by bulk coul=
d be more palatable</p><p style=3D"margin:10px 0px 0px;padding:0px;word-wra=
p:break-word;color:rgb(51,51,51);font-family:Arial,sans-serif;font-size:14p=
x;line-height:20px">

Michael Behringer: if name space is aggregatable could work. In early appro=
ach, token is not a cert and stealing the token does not help.</p><p style=
=3D"margin:10px 0px 0px;padding:0px;word-wrap:break-word;color:rgb(51,51,51=
);font-family:Arial,sans-serif;font-size:14px;line-height:20px">

Michael Richardson: anxious about spare parts that did not join, and go uns=
erviceable</p><p style=3D"margin:10px 0px 0px;padding:0px;word-wrap:break-w=
ord;color:rgb(51,51,51);font-family:Arial,sans-serif;font-size:14px;line-he=
ight:20px">

Michael Behringer: yes, we can take the req in draft-pritikin</p><p style=
=3D"margin:10px 0px 0px;padding:0px;word-wrap:break-word;color:rgb(51,51,51=
);font-family:Arial,sans-serif;font-size:14px;line-height:20px">Michael Ric=
hardson proposing do something like RFC 3779. It as AS numbers to allow reg=
 to delegate using cert; these are live devIDs from a pool. should look at =
that doc and we could change all AS to IdevID and we&#39;d be done.</p>

<p style=3D"margin:10px 0px 0px;padding:0px;word-wrap:break-word;color:rgb(=
51,51,51);font-family:Arial,sans-serif;font-size:14px;line-height:20px">Mic=
hael Behringer: sounds like an idea we&#39;ll look at it</p><p style=3D"mar=
gin:10px 0px 0px;padding:0px;word-wrap:break-word;color:rgb(51,51,51);font-=
family:Arial,sans-serif;font-size:14px;line-height:20px">

Michael Richardson: draft pritikin does not tell whether the enrolment allo=
w transport of authorization token back and forth and then the cert for the=
 TLS transport can be validated. Then you have a secure transport and can e=
nrol replacing the vendor cert with a domain cert.</p>

<p style=3D"margin:10px 0px 0px;padding:0px;word-wrap:break-word;color:rgb(=
51,51,51);font-family:Arial,sans-serif;font-size:14px;line-height:20px">Mic=
hael Behringer: refer to a mail by Max Pritikin &quot;[6tisch-security] a d=
ifferent explanation of autonomic&quot; .</p>

<p style=3D"margin:10px 0px 0px;padding:0px;word-wrap:break-word;color:rgb(=
51,51,51);font-family:Arial,sans-serif;font-size:14px;line-height:20px">Mic=
hael Richardson: where is the process ?</p><p style=3D"margin:10px 0px 0px;=
padding:0px;word-wrap:break-word;color:rgb(51,51,51);font-family:Arial,sans=
-serif;font-size:14px;line-height:20px">

Michael Behringer: explained in message. We need to mail this down so peopl=
e understand.</p><p style=3D"margin:10px 0px 0px;padding:0px;word-wrap:brea=
k-word;color:rgb(51,51,51);font-family:Arial,sans-serif;font-size:14px;line=
-height:20px">

Michael Richardson: non normative</p><p style=3D"margin:10px 0px 0px;paddin=
g:0px;word-wrap:break-word;color:rgb(51,51,51);font-family:Arial,sans-serif=
;font-size:14px;line-height:20px">Pascal Thubert: yes that is what we want =
in the security architecture</p>

<p style=3D"margin:10px 0px 0px;padding:0px;word-wrap:break-word;color:rgb(=
51,51,51);font-family:Arial,sans-serif;font-size:14px;line-height:20px">Mic=
hael Behringer I need to leave soon</p><p style=3D"margin:10px 0px 0px;padd=
ing:0px;word-wrap:break-word;color:rgb(51,51,51);font-family:Arial,sans-ser=
if;font-size:14px;line-height:20px">

Michael Richardson: I answered to draft piro descries low level stuff. I wa=
nt to encourage people to read and suggest that this becomes WG doc in L2 l=
ayer 2 security. It is a very good draft. We may need to change the authori=
zation but after that, great stuff can be found. Should be WG doc somewhere=
.</p>

<p style=3D"margin:10px 0px 0px;padding:0px;word-wrap:break-word;color:rgb(=
51,51,51);font-family:Arial,sans-serif;font-size:14px;line-height:20px">Ren=
=C3=A9 Struik: thoughts appreciated on mail I sent today</p><p style=3D"mar=
gin:10px 0px 0px;padding:0px;word-wrap:break-word;color:rgb(51,51,51);font-=
family:Arial,sans-serif;font-size:14px;line-height:20px">

Pascal: Next call on Tuesday next week same time</p><ul style=3D"margin:10p=
x 0px 0px;color:rgb(51,51,51);font-family:Arial,sans-serif;font-size:14px;l=
ine-height:20px"><li style=3D"word-wrap:break-word"><em>[08.06]</em>=C2=A0m=
eeting ends</li>

</ul><p style=3D"margin:10px 0px 0px;padding:0px;word-wrap:break-word;color=
:rgb(51,51,51);font-family:Arial,sans-serif;font-size:14px;line-height:20px=
">=3D=3D=3D=3D=3D=3D</p></div></div><div class=3D"gmail_extra"><br><br><div=
 class=3D"gmail_quote">

On Tue, May 20, 2014 at 8:53 AM, Rene Struik <span dir=3D"ltr">&lt;<a href=
=3D"mailto:rstruik.ext@gmail.com" target=3D"_blank">rstruik.ext@gmail.com</=
a>&gt;</span> wrote:<br><blockquote class=3D"gmail_quote" style=3D"margin:0=
 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">


 =20
   =20
 =20
  <div bgcolor=3D"#FFFFFF" text=3D"#000000">
    <div>now also to the 6tisch-security list
      (rather than 6tisch list).<div><div class=3D"h5"><br>
      <br>
      On 5/20/2014 11:52 AM, Rene Struik wrote:<br>
    </div></div></div><div><div class=3D"h5">
    <blockquote type=3D"cite">
     =20
      <div>Hi Pascal:<br>
        <br>
        I would like to suggest adding one more action item:<br>
        <span style=3D"font-size:10.5pt;font-family:&quot;Arial&quot;,&quot=
;sans-serif&quot;;color:#333333">All

          to review email RS as of May 20, 2014, 9:45am EDT and give
          feedback re details identified outstanding issues.<br>
          <br>
          Rene<br>
          <br>
          =3D=3D<br>
          Ren=C3=A9 Struik: thoughts appreciated on mail I sent today</span=
><br>
        <br>
        On 5/20/2014 11:38 AM, Pascal Thubert (pthubert) wrote:<br>
      </div>
      <blockquote type=3D"cite">
       =20
       =20
       =20
       =20
        <div>
          <h1 style=3D"margin-right:0cm;margin-bottom:7.5pt;margin-left:0cm=
;background:white"><span style=3D"font-size:18.0pt;font-family:&quot;Arial&=
quot;,&quot;sans-serif&quot;;color:#333333;font-weight:normal">Minutes

              Webex 20th May 2014, 6TiSCH Security<u></u><u></u></span></h1=
>
          <div class=3D"MsoNormal" style=3D"margin-right:0cm;margin-bottom:=
15.0pt;margin-left:0cm;text-align:center" align=3D"center">
            <hr style=3D"color:#333333" align=3D"center" noshade size=3D"3"=
 width=3D"100%"> </div>
          <h2 style=3D"margin-right:0cm;margin-bottom:0cm;margin-left:0cm;m=
argin-bottom:.0001pt;background:white;text-align:start;word-spacing:0px"> <=
span style=3D"font-size:15.0pt;font-family:&quot;Arial&quot;,&quot;sans-ser=
if&quot;;color:#333333;font-weight:normal">Taking

              notes<span>=C2=A0</span><em><span style=3D"font-family:&quot;=
Arial&quot;,&quot;sans-serif&quot;">(using
                  Etherpad)</span></em><u></u><u></u></span></h2>
          <p class=3D"MsoNormal" style=3D"margin-left:0cm;line-height:15.0p=
t;background:white">
            <span style=3D"font-size:10.5pt;font-family:&quot;Arial&quot;,&=
quot;sans-serif&quot;;color:#333333"><span>1.<span style=3D"font:7.0pt &quo=
t;Times New Roman&quot;">=C2=A0=C2=A0=C2=A0=C2=A0 </span></span></span><spa=
n style=3D"font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-serif&=
quot;;color:#333333">Pascal

              Thubert<u></u><u></u></span></p>
          <h2 style=3D"margin-right:0cm;margin-bottom:0cm;margin-left:0cm;m=
argin-bottom:.0001pt;background:white;text-align:start;word-spacing:0px"> <=
span style=3D"font-size:15.0pt;font-family:&quot;Arial&quot;,&quot;sans-ser=
if&quot;;color:#333333;font-weight:normal">Present<span>=C2=A0</span><em><s=
pan style=3D"font-family:&quot;Arial&quot;,&quot;sans-serif&quot;">(alphabe=
tically)</span></em><u></u><u></u></span></h2>


          <p class=3D"MsoNormal" style=3D"margin-left:0cm;line-height:15.0p=
t;background:white">
            <span style=3D"font-size:10.5pt;font-family:&quot;Arial&quot;,&=
quot;sans-serif&quot;;color:#333333"><span>1.<span style=3D"font:7.0pt &quo=
t;Times New Roman&quot;">=C2=A0=C2=A0=C2=A0=C2=A0 </span></span></span><spa=
n style=3D"font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-serif&=
quot;;color:#333333">Hank

              Mauldin<u></u><u></u></span></p>
          <p class=3D"MsoNormal" style=3D"margin-left:0cm;line-height:15.0p=
t;background:white">
            <span style=3D"font-size:10.5pt;font-family:&quot;Arial&quot;,&=
quot;sans-serif&quot;;color:#333333"><span>2.<span style=3D"font:7.0pt &quo=
t;Times New Roman&quot;">=C2=A0=C2=A0=C2=A0=C2=A0 </span></span></span><spa=
n style=3D"font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-serif&=
quot;;color:#333333">Michael

              Behringer<u></u><u></u></span></p>
          <p class=3D"MsoNormal" style=3D"margin-left:0cm;line-height:15.0p=
t;background:white">
            <span style=3D"font-size:10.5pt;font-family:&quot;Arial&quot;,&=
quot;sans-serif&quot;;color:#333333"><span>3.<span style=3D"font:7.0pt &quo=
t;Times New Roman&quot;">=C2=A0=C2=A0=C2=A0=C2=A0 </span></span></span><spa=
n style=3D"font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-serif&=
quot;;color:#333333">Michael

              Richardson<u></u><u></u></span></p>
          <p class=3D"MsoNormal" style=3D"margin-left:0cm;line-height:15.0p=
t;background:white">
            <span style=3D"font-size:10.5pt;font-family:&quot;Arial&quot;,&=
quot;sans-serif&quot;;color:#333333"><span>4.<span style=3D"font:7.0pt &quo=
t;Times New Roman&quot;">=C2=A0=C2=A0=C2=A0=C2=A0 </span></span></span><spa=
n style=3D"font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-serif&=
quot;;color:#333333">Maik

              Seewald<u></u><u></u></span></p>
          <p class=3D"MsoNormal" style=3D"margin-left:0cm;line-height:15.0p=
t;background:white">
            <span style=3D"font-size:10.5pt;font-family:&quot;Arial&quot;,&=
quot;sans-serif&quot;;color:#333333"><span>5.<span style=3D"font:7.0pt &quo=
t;Times New Roman&quot;">=C2=A0=C2=A0=C2=A0=C2=A0 </span></span></span><spa=
n style=3D"font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-serif&=
quot;;color:#333333">Ren=C3=A9

              Struik<u></u><u></u></span></p>
          <p class=3D"MsoNormal" style=3D"margin-left:0cm;line-height:15.0p=
t;background:white">
            <span style=3D"font-size:10.5pt;font-family:&quot;Arial&quot;,&=
quot;sans-serif&quot;;color:#333333"><span>6.<span style=3D"font:7.0pt &quo=
t;Times New Roman&quot;">=C2=A0=C2=A0=C2=A0=C2=A0 </span></span></span><spa=
n style=3D"font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-serif&=
quot;;color:#333333">Tom

              Phinney<u></u><u></u></span></p>
          <p class=3D"MsoNormal" style=3D"margin-left:0cm;line-height:15.0p=
t;background:white">
            <span style=3D"font-size:10.5pt;font-family:&quot;Arial&quot;,&=
quot;sans-serif&quot;;color:#333333"><span>7.<span style=3D"font:7.0pt &quo=
t;Times New Roman&quot;">=C2=A0=C2=A0=C2=A0=C2=A0 </span></span></span><spa=
n style=3D"font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-serif&=
quot;;color:#333333">Yoshihiro

              Ohba<u></u><u></u></span></p>
          <h2 style=3D"margin-right:0cm;margin-bottom:0cm;margin-left:0cm;m=
argin-bottom:.0001pt;background:white;text-align:start;word-spacing:0px"> <=
span style=3D"font-size:15.0pt;font-family:&quot;Arial&quot;,&quot;sans-ser=
if&quot;;color:#333333;font-weight:normal">Recording<u></u><u></u></span></=
h2>


          <p class=3D"MsoNormal" style=3D"margin-left:0cm;line-height:15.0p=
t;background:white">
            <span style=3D"font-size:10.0pt;font-family:Symbol;color:#33333=
3"><span>=C2=B7<span style=3D"font:7.0pt &quot;Times New Roman&quot;">=C2=
=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0 </span></span></span><span style=3D=
"font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;colo=
r:#333333"><a href=3D"https://cisco.webex.com/ciscosales/lsr.php?RCID=3Dcf2=
34f58e8f94d2f86fbe15e7d6862df" target=3D"_blank"><span style=3D"color:#3b73=
af">Webex recording</span></a><u></u><u></u></span></p>


          <h2 style=3D"margin-right:0cm;margin-bottom:0cm;margin-left:0cm;m=
argin-bottom:.0001pt;background:white;text-align:start;word-spacing:0px"> <=
span style=3D"font-size:15.0pt;font-family:&quot;Arial&quot;,&quot;sans-ser=
if&quot;;color:#333333;font-weight:normal">Agenda<u></u><u></u></span></h2>


          <p class=3D"MsoNormal" style=3D"margin-left:0cm;line-height:15.0p=
t;background:white">
            <span style=3D"font-size:10.5pt;font-family:&quot;Arial&quot;,&=
quot;sans-serif&quot;;color:#333333"><span>1.<span style=3D"font:7.0pt &quo=
t;Times New Roman&quot;">=C2=A0=C2=A0=C2=A0=C2=A0 </span></span></span><spa=
n style=3D"font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-serif&=
quot;;color:#333333">Look

              at Join Protocol<u></u><u></u></span></p>
          <h2 style=3D"margin-right:0cm;margin-bottom:0cm;margin-left:0cm;m=
argin-bottom:.0001pt;background:white;text-align:start;word-spacing:0px"> <=
span style=3D"font-size:15.0pt;font-family:&quot;Arial&quot;,&quot;sans-ser=
if&quot;;color:#333333;font-weight:normal">Action

              Items<u></u><u></u></span></h2>
          <p class=3D"MsoNormal" style=3D"margin-left:0cm;line-height:15.0p=
t;background:white">
            <span style=3D"font-size:10.5pt;font-family:&quot;Arial&quot;,&=
quot;sans-serif&quot;;color:#333333"><span>1.<span style=3D"font:7.0pt &quo=
t;Times New Roman&quot;">=C2=A0=C2=A0=C2=A0=C2=A0 </span></span></span><spa=
n style=3D"font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-serif&=
quot;;color:#333333">Michael

              R. to suggest to the list a review of draft piro<u></u><u></u=
></span></p>
          <p class=3D"MsoNormal" style=3D"margin-left:0cm;line-height:15.0p=
t;background:white">
            <span style=3D"font-size:10.5pt;font-family:&quot;Arial&quot;,&=
quot;sans-serif&quot;;color:#333333"><span>2.<span style=3D"font:7.0pt &quo=
t;Times New Roman&quot;">=C2=A0=C2=A0=C2=A0=C2=A0 </span></span></span><spa=
n style=3D"font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-serif&=
quot;;color:#333333">Michael

              B. to check with Max Pritikin about format on
              authorization token.<u></u><u></u></span></p>
          <h2 style=3D"margin-right:0cm;margin-bottom:0cm;margin-left:0cm;m=
argin-bottom:.0001pt;background:white;text-align:start;word-spacing:0px"> <=
span style=3D"font-size:15.0pt;font-family:&quot;Arial&quot;,&quot;sans-ser=
if&quot;;color:#333333;font-weight:normal">Minutes<u></u><u></u></span></h2=
>


          <p class=3D"MsoNormal" style=3D"margin-left:0cm;line-height:15.0p=
t;background:white">
            <span style=3D"font-size:10.0pt;font-family:Symbol;color:#33333=
3"><span>=C2=B7<span style=3D"font:7.0pt &quot;Times New Roman&quot;">=C2=
=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0 </span></span></span><em><span styl=
e=3D"font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;=
color:#333333">[07.10]</span></em><span><span style=3D"font-size:10.5pt;fon=
t-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">=C2=A0</sp=
an></span><span style=3D"font-size:10.5pt;font-family:&quot;Arial&quot;,&qu=
ot;sans-serif&quot;;color:#333333">Meeting


              starts<u></u><u></u></span></p>
          <p style=3D"margin-right:0cm;margin-bottom:0cm;margin-left:0cm;ma=
rgin-bottom:.0001pt;line-height:15.0pt;background:white;word-wrap:break-wor=
d;text-align:start;word-spacing:0px"> <span style=3D"font-size:10.5pt;font-=
family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">Michael

              Richardson: network manager programs the device, no
              particular authorization of the network to the device, nor
              way for device to prove it is authorized apart from having
              the join key provisioned<u></u><u></u></span></p>
          <p style=3D"margin-right:0cm;margin-bottom:0cm;margin-left:0cm;ma=
rgin-bottom:.0001pt;line-height:15.0pt;background:white;word-wrap:break-wor=
d;text-align:start;word-spacing:0px"> <span style=3D"font-size:10.5pt;font-=
family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">Ren=C3=A9

              Struik: unless missing something, need size of
              configuration messages. How to get tag names in the device
              and map that into 802.15.4 MAC addresses. Details we do
              not really have. Unclear how device can discover the
              network. Ties in AR certificate issue<u></u><u></u></span></p=
>
          <p style=3D"margin-right:0cm;margin-bottom:0cm;margin-left:0cm;ma=
rgin-bottom:.0001pt;line-height:15.0pt;background:white;word-wrap:break-wor=
d;text-align:start;word-spacing:0px"> <span style=3D"font-size:10.5pt;font-=
family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">Michael

              Richardson: problem exists regardless of actual enrolment
              process.<u></u><u></u></span></p>
          <p style=3D"margin-right:0cm;margin-bottom:0cm;margin-left:0cm;ma=
rgin-bottom:.0001pt;line-height:15.0pt;background:white;word-wrap:break-wor=
d;text-align:start;word-spacing:0px"> <span style=3D"font-size:10.5pt;font-=
family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">Ren=C3=A9

              Struik: there is also a control element when certificate
              can be used<u></u><u></u></span></p>
          <p style=3D"margin-right:0cm;margin-bottom:0cm;margin-left:0cm;ma=
rgin-bottom:.0001pt;line-height:15.0pt;background:white;word-wrap:break-wor=
d;text-align:start;word-spacing:0px"> <span style=3D"font-size:10.5pt;font-=
family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">Michael

              Richardson: sent message on Wile coyote; is it realistic?<u><=
/u><u></u></span></p>
          <p style=3D"margin-right:0cm;margin-bottom:0cm;margin-left:0cm;ma=
rgin-bottom:.0001pt;line-height:15.0pt;background:white;word-wrap:break-wor=
d;text-align:start;word-spacing:0px"> <span style=3D"font-size:10.5pt;font-=
family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">Ren=C3=A9

              Struik: quick feedback. say vendor generates cert for
              bunch of devices and it goes along a chain and then more
              attributes allow link back to factory. works, does not
              have to be AR certificate<u></u><u></u></span></p>
          <p style=3D"margin-right:0cm;margin-bottom:0cm;margin-left:0cm;ma=
rgin-bottom:.0001pt;line-height:15.0pt;background:white;word-wrap:break-wor=
d;text-align:start;word-spacing:0px"> <span style=3D"font-size:10.5pt;font-=
family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">Michael

              Richardson: I expected the kind of certificate I describe
              in AR but it is not the point of AR. They do not even
              specify the format of device ID. AR is really about an API
              not about content of certificate apart from signature
              algorithm for which they have requirements. They do not
              even define their own extensions. One extension with
              multiple values<u></u><u></u></span></p>
          <p style=3D"margin-right:0cm;margin-bottom:0cm;margin-left:0cm;ma=
rgin-bottom:.0001pt;line-height:15.0pt;background:white;word-wrap:break-wor=
d;text-align:start;word-spacing:0px"> <span style=3D"font-size:10.5pt;font-=
family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">Michael

              Richardson if you use secure enrolment, you can replace
              the cert but you still need to validate the device. Need
              Michael B. and Max to describe their token<u></u><u></u></spa=
n></p>
          <p style=3D"margin-right:0cm;margin-bottom:0cm;margin-left:0cm;ma=
rgin-bottom:.0001pt;line-height:15.0pt;background:white;word-wrap:break-wor=
d;text-align:start;word-spacing:0px"> <span style=3D"font-size:10.5pt;font-=
family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">Michael

              Behringer: AR or not AR? process is about an institution
              that owns a device and has a secured relationship based on
              a certificate that tit signed. Can be 1AR or anything,
              e.g. an institution which owned the device before. Need
              that cert from old organization to help bootstrap in new
              organization.<u></u><u></u></span></p>
          <p style=3D"margin-right:0cm;margin-bottom:0cm;margin-left:0cm;ma=
rgin-bottom:.0001pt;line-height:15.0pt;background:white;word-wrap:break-wor=
d;text-align:start;word-spacing:0px"> <span style=3D"font-size:10.5pt;font-=
family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">Michael

              Richardson: did you define how the authorization token can
              be passed in an interoperable fashion<u></u><u></u></span></p=
>
          <p style=3D"margin-right:0cm;margin-bottom:0cm;margin-left:0cm;ma=
rgin-bottom:.0001pt;line-height:15.0pt;background:white;word-wrap:break-wor=
d;text-align:start;word-spacing:0px"> <span style=3D"font-size:10.5pt;font-=
family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">Michael

              Behringer: leverage secure relationship between vendor and
              device to pass a signed message to the device<u></u><u></u></=
span></p>
          <p style=3D"margin-right:0cm;margin-bottom:0cm;margin-left:0cm;ma=
rgin-bottom:.0001pt;line-height:15.0pt;background:white;word-wrap:break-wor=
d;text-align:start;word-spacing:0px"> <span style=3D"font-size:10.5pt;font-=
family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">Michael

              Richardson: does it bind to the new owner? which way, not
              subject to standardization or is it?<u></u><u></u></span></p>
          <p style=3D"margin-right:0cm;margin-bottom:0cm;margin-left:0cm;ma=
rgin-bottom:.0001pt;line-height:15.0pt;background:white;word-wrap:break-wor=
d;text-align:start;word-spacing:0px"> <span style=3D"font-size:10.5pt;font-=
family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">Michael

              Behringer: May not need standard, but if multivendor
              network user would like a common format. between vendor
              and new device can be proprietary<u></u><u></u></span></p>
          <p style=3D"margin-right:0cm;margin-bottom:0cm;margin-left:0cm;ma=
rgin-bottom:.0001pt;line-height:15.0pt;background:white;word-wrap:break-wor=
d;text-align:start;word-spacing:0px"> <span style=3D"font-size:10.5pt;font-=
family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">Michael

              Richardson: need ot define when how the token is
              transported, and that is not end to end. reasons of trust,
              rate limit etc...<u></u><u></u></span></p>
          <p style=3D"margin-right:0cm;margin-bottom:0cm;margin-left:0cm;ma=
rgin-bottom:.0001pt;line-height:15.0pt;background:white;word-wrap:break-wor=
d;text-align:start;word-spacing:0px"> <span style=3D"font-size:10.5pt;font-=
family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">Michael

              Behringer: new device sends along a nonce and expect that
              nonce in response from vendor site; without nonce, token
              could come from the past. Both models are required in the
              market. Some want fresh, others e.g. military there cannot
              be comm at the deployment time.<u></u><u></u></span></p>
          <p style=3D"margin-right:0cm;margin-bottom:0cm;margin-left:0cm;ma=
rgin-bottom:.0001pt;line-height:15.0pt;background:white;word-wrap:break-wor=
d;text-align:start;word-spacing:0px"> <span style=3D"font-size:10.5pt;font-=
family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">Michael

              Richardson: content of token may or not be standard.
              transport of token must be standard.<u></u><u></u></span></p>
          <p style=3D"margin-right:0cm;margin-bottom:0cm;margin-left:0cm;ma=
rgin-bottom:.0001pt;line-height:15.0pt;background:white;word-wrap:break-wor=
d;text-align:start;word-spacing:0px"> <span style=3D"font-size:10.5pt;font-=
family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">Michael

              Richardson: using RFC 3779 would address cert that had 1AR
              IdevID in them. need a range in the certificate otherwise
              one certificate per device<u></u><u></u></span></p>
          <p style=3D"margin-right:0cm;margin-bottom:0cm;margin-left:0cm;ma=
rgin-bottom:.0001pt;line-height:15.0pt;background:white;word-wrap:break-wor=
d;text-align:start;word-spacing:0px"> <span style=3D"font-size:10.5pt;font-=
family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">Michael

              Behringer: token or certificate?<u></u><u></u></span></p>
          <p style=3D"margin-right:0cm;margin-bottom:0cm;margin-left:0cm;ma=
rgin-bottom:.0001pt;line-height:15.0pt;background:white;word-wrap:break-wor=
d;text-align:start;word-spacing:0px"> <span style=3D"font-size:10.5pt;font-=
family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">Michael

              Richardson if the token is a certificate need a way to
              delegate down the chain. But breach along the way breaches
              it all below. no good. Do you have to maintain a cert for
              every device?<u></u><u></u></span></p>
          <p style=3D"margin-right:0cm;margin-bottom:0cm;margin-left:0cm;ma=
rgin-bottom:.0001pt;line-height:15.0pt;background:white;word-wrap:break-wor=
d;text-align:start;word-spacing:0px"> <span style=3D"font-size:10.5pt;font-=
family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">Michael

              Behringer: that&#39;s the starting point. You assume that&#39=
;s a
              scalability issue at some point right<u></u><u></u></span></p=
>
          <p style=3D"margin-right:0cm;margin-bottom:0cm;margin-left:0cm;ma=
rgin-bottom:.0001pt;line-height:15.0pt;background:white;word-wrap:break-wor=
d;text-align:start;word-spacing:0px"> <span style=3D"font-size:10.5pt;font-=
family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">Michael

              Richardson: provisioning trouble is possible. Tracking by
              bulk could be more palatable<u></u><u></u></span></p>
          <p style=3D"margin-right:0cm;margin-bottom:0cm;margin-left:0cm;ma=
rgin-bottom:.0001pt;line-height:15.0pt;background:white;word-wrap:break-wor=
d;text-align:start;word-spacing:0px"> <span style=3D"font-size:10.5pt;font-=
family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">Michael

              Behringer: if name space is aggregatable could work. In
              early approach, token is not a cert and stealing the token
              does not help.<u></u><u></u></span></p>
          <p style=3D"margin-right:0cm;margin-bottom:0cm;margin-left:0cm;ma=
rgin-bottom:.0001pt;line-height:15.0pt;background:white;word-wrap:break-wor=
d;text-align:start;word-spacing:0px"> <span style=3D"font-size:10.5pt;font-=
family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">Michael

              Richardson: anxious about spare parts that did not join,
              and go unserviceable<u></u><u></u></span></p>
          <p style=3D"margin-right:0cm;margin-bottom:0cm;margin-left:0cm;ma=
rgin-bottom:.0001pt;line-height:15.0pt;background:white;word-wrap:break-wor=
d;text-align:start;word-spacing:0px"> <span style=3D"font-size:10.5pt;font-=
family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">Michael

              Behringer: yes, we can take the req in draft-pritikin<u></u><=
u></u></span></p>
          <p style=3D"margin-right:0cm;margin-bottom:0cm;margin-left:0cm;ma=
rgin-bottom:.0001pt;line-height:15.0pt;background:white;word-wrap:break-wor=
d;text-align:start;word-spacing:0px"> <span style=3D"font-size:10.5pt;font-=
family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">Michael

              Richardson proposing do something like RFC 3779. It as AS
              numbers to allow reg to delegate using cert; these are
              live devIDs from a pool. should look at that doc and we
              could change all AS to IdevID and we&#39;d be done.<u></u><u>=
</u></span></p>
          <p style=3D"margin-right:0cm;margin-bottom:0cm;margin-left:0cm;ma=
rgin-bottom:.0001pt;line-height:15.0pt;background:white;word-wrap:break-wor=
d;text-align:start;word-spacing:0px"> <span style=3D"font-size:10.5pt;font-=
family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">Michael

              Behringer: sounds like an idea we&#39;ll look at it<u></u><u>=
</u></span></p>
          <p style=3D"margin-right:0cm;margin-bottom:0cm;margin-left:0cm;ma=
rgin-bottom:.0001pt;line-height:15.0pt;background:white;word-wrap:break-wor=
d;text-align:start;word-spacing:0px"> <span style=3D"font-size:10.5pt;font-=
family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">Michael

              Richardson: draft pritikin does not tell whether the
              enrolment allow transport of authorization token back and
              forth and then the cert for the TLS transport can be
              validated. Then you have a secure transport and can enrol
              replacing the vendor cert with a domain cert.<u></u><u></u></=
span></p>
          <p style=3D"margin-right:0cm;margin-bottom:0cm;margin-left:0cm;ma=
rgin-bottom:.0001pt;line-height:15.0pt;background:white;word-wrap:break-wor=
d;text-align:start;word-spacing:0px"> <span style=3D"font-size:10.5pt;font-=
family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">Michael

              Behringer: refer to a mail by Max Pritikin
              &quot;[6tisch-security] a different explanation of autonomic&=
quot; .<u></u><u></u></span></p>
          <p style=3D"margin-right:0cm;margin-bottom:0cm;margin-left:0cm;ma=
rgin-bottom:.0001pt;line-height:15.0pt;background:white;word-wrap:break-wor=
d;text-align:start;word-spacing:0px"> <span style=3D"font-size:10.5pt;font-=
family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">Michael

              Richardson: where is the process ?<u></u><u></u></span></p>
          <p style=3D"margin-right:0cm;margin-bottom:0cm;margin-left:0cm;ma=
rgin-bottom:.0001pt;line-height:15.0pt;background:white;word-wrap:break-wor=
d;text-align:start;word-spacing:0px"> <span style=3D"font-size:10.5pt;font-=
family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">Michael

              Behringer: explained in message. We need to mail this down
              so people understand.<u></u><u></u></span></p>
          <p style=3D"margin-right:0cm;margin-bottom:0cm;margin-left:0cm;ma=
rgin-bottom:.0001pt;line-height:15.0pt;background:white;word-wrap:break-wor=
d;text-align:start;word-spacing:0px"> <span style=3D"font-size:10.5pt;font-=
family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">Michael

              Richardson: non normative<u></u><u></u></span></p>
          <p style=3D"margin-right:0cm;margin-bottom:0cm;margin-left:0cm;ma=
rgin-bottom:.0001pt;line-height:15.0pt;background:white;word-wrap:break-wor=
d;text-align:start;word-spacing:0px"> <span style=3D"font-size:10.5pt;font-=
family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">Pascal

              Thubert: yes that is what we want in the security
              architecture<u></u><u></u></span></p>
          <p style=3D"margin-right:0cm;margin-bottom:0cm;margin-left:0cm;ma=
rgin-bottom:.0001pt;line-height:15.0pt;background:white;word-wrap:break-wor=
d;text-align:start;word-spacing:0px"> <span style=3D"font-size:10.5pt;font-=
family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">Michael

              Behringer I need to leave soon<u></u><u></u></span></p>
          <p style=3D"margin-right:0cm;margin-bottom:0cm;margin-left:0cm;ma=
rgin-bottom:.0001pt;line-height:15.0pt;background:white;word-wrap:break-wor=
d;text-align:start;word-spacing:0px"> <span style=3D"font-size:10.5pt;font-=
family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">Michael

              Richardson: I answered to draft piro descries low level
              stuff. I want to encourage people to read and suggest that
              this becomes WG doc in L2 layer 2 security. It is a very
              good draft. We may need to change the authorization but
              after that, great stuff can be found. Should be WG doc
              somewhere.<u></u><u></u></span></p>
          <p style=3D"margin-right:0cm;margin-bottom:0cm;margin-left:0cm;ma=
rgin-bottom:.0001pt;line-height:15.0pt;background:white;word-wrap:break-wor=
d;text-align:start;word-spacing:0px"> <span style=3D"font-size:10.5pt;font-=
family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">Ren=C3=A9

              Struik: thoughts appreciated on mail I sent today<u></u><u></=
u></span></p>
          <p style=3D"margin-right:0cm;margin-bottom:0cm;margin-left:0cm;ma=
rgin-bottom:.0001pt;line-height:15.0pt;background:white;word-wrap:break-wor=
d;text-align:start;word-spacing:0px"> <span style=3D"font-size:10.5pt;font-=
family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">Pascal:

              Next call on Tuesday next week same time<u></u><u></u></span>=
</p>
          <p class=3D"MsoNormal" style=3D"margin-left:0cm;line-height:15.0p=
t;background:white">
            <span style=3D"font-size:10.0pt;font-family:Symbol;color:#33333=
3"><span>=C2=B7<span style=3D"font:7.0pt &quot;Times New Roman&quot;">=C2=
=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0 </span></span></span><em><span styl=
e=3D"font-size:10.5pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;=
color:#333333">[08.06]</span></em><span><span style=3D"font-size:10.5pt;fon=
t-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">=C2=A0</sp=
an></span><span style=3D"font-size:10.5pt;font-family:&quot;Arial&quot;,&qu=
ot;sans-serif&quot;;color:#333333">meeting


              ends<u></u><u></u></span></p>
          <p style=3D"margin-right:0cm;margin-bottom:0cm;margin-left:0cm;ma=
rgin-bottom:.0001pt;line-height:15.0pt;background:white;word-wrap:break-wor=
d;text-align:start;word-spacing:0px"> <span style=3D"font-size:10.5pt;font-=
family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#333333">=3D=3D=3D=3D=
=3D=3D<u></u><u></u></span></p>


          <p class=3D"MsoNormal"><u></u>=C2=A0<u></u></p>
        </div>
        <br>
        <fieldset></fieldset>
        <br>
        <pre>_______________________________________________
6tisch mailing list
<a href=3D"mailto:6tisch@ietf.org" target=3D"_blank">6tisch@ietf.org</a>
<a href=3D"https://www.ietf.org/mailman/listinfo/6tisch" target=3D"_blank">=
https://www.ietf.org/mailman/listinfo/6tisch</a>
</pre>
      </blockquote>
      <br>
      <br>
      <pre cols=3D"72">--=20
email: <a href=3D"mailto:rstruik.ext@gmail.com" target=3D"_blank">rstruik.e=
xt@gmail.com</a> | Skype: rstruik
cell: <a href=3D"tel:%2B1%20%28647%29%20867-5658" value=3D"+16478675658" ta=
rget=3D"_blank">+1 (647) 867-5658</a> | US: <a href=3D"tel:%2B1%20%28415%29=
%20690-7363" value=3D"+14156907363" target=3D"_blank">+1 (415) 690-7363</a>=
</pre>
    </blockquote>
    <br>
    <br>
    <pre cols=3D"72">--=20
email: <a href=3D"mailto:rstruik.ext@gmail.com" target=3D"_blank">rstruik.e=
xt@gmail.com</a> | Skype: rstruik
cell: <a href=3D"tel:%2B1%20%28647%29%20867-5658" value=3D"+16478675658" ta=
rget=3D"_blank">+1 (647) 867-5658</a> | US: <a href=3D"tel:%2B1%20%28415%29=
%20690-7363" value=3D"+14156907363" target=3D"_blank">+1 (415) 690-7363</a>=
</pre>
  </div></div></div>

<br>_______________________________________________<br>
6tisch-security mailing list<br>
<a href=3D"mailto:6tisch-security@ietf.org">6tisch-security@ietf.org</a><br=
>
<a href=3D"https://www.ietf.org/mailman/listinfo/6tisch-security" target=3D=
"_blank">https://www.ietf.org/mailman/listinfo/6tisch-security</a><br>
<br></blockquote></div><br></div>

--047d7b3a99d834c05404fa06831e--


From gpiro.poliba@gmail.com  Fri May 23 02:58:07 2014
Return-Path: <gpiro.poliba@gmail.com>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 1DC5D1A03E7; Fri, 23 May 2014 02:58:07 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.277
X-Spam-Level: 
X-Spam-Status: No, score=-1.277 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, FM_FORGED_GMAIL=0.622, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, SPF_PASS=-0.001] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id UQ-Bctf2O4tQ; Fri, 23 May 2014 02:58:04 -0700 (PDT)
Received: from mail-qc0-x235.google.com (mail-qc0-x235.google.com [IPv6:2607:f8b0:400d:c01::235]) (using TLSv1 with cipher ECDHE-RSA-RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id D2A731A03E4; Fri, 23 May 2014 02:58:03 -0700 (PDT)
Received: by mail-qc0-f181.google.com with SMTP id m20so7682388qcx.40 for <multiple recipients>; Fri, 23 May 2014 02:58:01 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113;  h=mime-version:sender:from:date:message-id:subject:to:cc:content-type;  bh=ONJUeL3tY0ZDIl/p2VIimQb/ndbivKRy8nD6nGdHtbQ=; b=FXVuiLVEOIMBp2zPLNFwEvPwK11EUl3JnA1GKItf8ZDRwPXMU3KyYQ++TKp7Q/SmSz g8PM3r8dp+19k3icwRcEmmz/5y2J3V2Zs4KShL4j/t1Rqgo/q0/dkP7NNrq3nH+GAKFH 0WvDMspppdpNsXAN976T4dzInmKliRBWvMX3vf9MtAa31BMXL8EVJpfbGyskBNoRaVFJ HyOB5NUgapmoMwcj35+Wj2jJm0YZSUNKeB328ZOAnXfmSyZwOgbp7M4CUzB6S+Lh6L66 Pe+yCcavhBMbOFxC6mDizlNvuunAOt7QPO8/glFzoe+hXsHtk8oAzOv6yEbNvjHr0aMw LLNA==
X-Received: by 10.224.36.141 with SMTP id t13mr1901097qad.75.1400839081724; Fri, 23 May 2014 02:58:01 -0700 (PDT)
MIME-Version: 1.0
Sender: gpiro.poliba@gmail.com
Received: by 10.229.219.10 with HTTP; Fri, 23 May 2014 02:57:41 -0700 (PDT)
From: Giuseppe Piro <giuseppe.piro@poliba.it>
Date: Fri, 23 May 2014 11:57:41 +0200
X-Google-Sender-Auth: 98wGG_NgHA4SMj3a5EMPHU2EK7k
Message-ID: <CAH-9zkqYfRiWaYu_EjdWifVQvBEKDV=Ra4A5F9K7Pf6xM8Lt-Q@mail.gmail.com>
To: Michael Richardson <mcr+ietf@sandelman.ca>, Rene Struik <rstruik.ext@gmail.com>, 6tisch-security@ietf.org
Content-Type: multipart/alternative; boundary=089e0149d0e4da91f304fa0e437a
Archived-At: http://mailarchive.ietf.org/arch/msg/6tisch-security/2LJI7EqbhYWGG-WwhVebAsHW08o
X-Mailman-Approved-At: Fri, 23 May 2014 06:24:48 -0700
Cc: Thomas Watteyne <watteyne@eecs.berkeley.edu>, Gennaro Boggia <gennaro.boggia@poliba.it>, "6tisch@ietf.org" <6tisch@ietf.org>, "Pascal Thubert \(pthubert\)" <pthubert@cisco.com>, Alfredo Grieco <alfredo.grieco@poliba.it>
Subject: [6tisch-security] about draft-piro-6tisch-security-issues-01
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 23 May 2014 10:00:02 -0000

--089e0149d0e4da91f304fa0e437a
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

Dear all,

 I tried to summarize main issues recently discussed on the
draft-piro-6tisch-security-issues-01 (many thanks to Michael and Ren=C3=A8 =
for
that).

 In what follows, they have been organized in macro categories, where both
your comments and my replies can be found.

 Please, let me know if my proposals have sense. Otherwise, indicate which
issues will remain still uncovered.

I'm looking forward to receive your further considerations.

 Thanks all,

Giuseppe

 -----


Issue #1 - Title of the draft

 [Michael R. @ Wed, May 14, 2014]: I don't agree with your title! I don't
see how  this is a "security framework". It is something much more useful
and important.

 The title will be changed with =E2=80=9CLayer-2 security aspects for the I=
EEE
802.15.4e MAC=E2=80=9D


Issue #2 =E2=80=93 Derivation of Master Default Keys and unsecured frames

 [Michael R. @ Wed, May 14, 2014]: The Setting-up Phase seems to assume a
provisioning process to distribuite this MasterKey.  It could be that the
MasterKey comes from something like 1x/PANA?

 [Rene S @ Tue, May 20, 2014]: it is assumed that each node is
preconfigured with a master key M_k that is shared amongst all devices
(Section 6.1.1), from which default keys D_k are derived using a publicly
known function (with potentially other inputs, which are to be assumed
publicly known). This seems to imply that all default keys can be
considered as publicly known strings (!).

 [Rene S @ Tue, May 20, 2014]: the 802.15.4-2011 specification mistakenly
does not allow mixing of secured and unsecured traffic (see, e.g., my
emails of end of January 2014 on this). In particular, the hybrid security
network (as mentioned in Section 5) is not possible with 802.15.4-2011 or
802.15.4e-2012.

  The goal is to have a secured network, where all packets are encrypted
and unsecured MAC frames are not supported (according to the condition =E2=
=80=98d=E2=80=99
in Sec. 7.3.2 of the IEEE 802.15.4 std).

 In this context, the Master Key refers to the =E2=80=9Cfake key=E2=80=9D t=
hat all all
nodes know from the beginning. It can be provided by the network
administrator or directly by the manufacturer. It is used to:

   1.

   protect beacon messages
   2.

   protect data frames storing messages of the join procedure handled by
   upper layers

 Thanks to the knowledge of the Master Key, all nodes, also those that has
not yet completed the join procedure, may communicate with secured MAC
frames (unsecured frames are not supported in a secured network).

 At the end of the join procedure, the node could obtain the Default Key
from the network by using high-level protocols like PANA/.1x (which also
offer authorization and authentication services). The Default Key, which
cannot be more considered as a publicly known strings, is used to protect
all broadcast messages and those exchanged between a couple of nodes for
negotiating a layer-2 key.

 Since the draft focuses on the MAC layer, I believe that this document is
not the right place where describing how PANA/.1x protocols can be used for
that purpose.  We can just assume that high level procedures (i.e., those
related to the join process) will obtain the Master Key from a specific
entity into the network.


 Issue #3 =E2=80=93 Definition of secured configurations

 [Michael R. @ Wed, May 14, 2014]: Thank you for giving the network
definitions in section 5.0. It would be worth making it clear in the
definition of fully secure that all

broadcasts are encrypted, including the beacon. The _Hybrid Secured
network_ is likely the most common, and not because nodes are not capable
of encryption, but because they don't have the key (yet!!).

 [Thomas W. @Tue, Jan 7, 2014]: About the functionality, the draft
describes 5 configurations (Full, Unsecured, Partial, Hybrid, Flexible),
some of which support a combination of secured and unsecured L2 frames
depending on the capabilities of the devices. Can you comment on the
rationale between these configurations? I believe it is useful to look at
desired functionality first, and determine the configurations afterwards.
Naively, I am a bit scared of combining secured and unsecured. TSCH
networks are envisioned in the context of the IT/OT convergence to operate
in mission critical environments, so I would lean towards having only a
single configuration: fully secured.

  Starting from the initial Thomas=E2=80=99s comment, I will focus the atte=
ntion
only to secured configurations.

 As indicated by Michael, the only two configurations that can be allowed
are (their definition is different to the one already present into the
draft):

   1.

   _fully_secured_configuration_: all devices have already ended the join
   procedure and have obtained the Default Key;
   2.

   _hybryd_secured_configuration_: some devices didn=E2=80=99t yet complete=
d the
   join procedure and they have not yet the Default Key.

 In both configurations, all packets are encrypted (it is not possible to
exchange unsecured frames in a secured network). However, there are
different levels of security:

   1.

   Beacon and data frames containing join messages are encrypted by means
   of the Master Key ( a =E2=80=9Cfake key=E2=80=9D provided by the network=
 administrator
   before the network deployment).
   2.

   Broadcast messages and data frames used to negotiate the layer-2 key are
   protected with the Default Key.
   3.

   Any other unicast messages are protected with the Link Key properly
   negotiated through a KMP algorithm.




Issue #4 =E2=80=93 Focus on the IEEE 802.15.4e

 [Rene S @ Tue, May 20, 2014] the draft relates to 802.15.4-2011. I would
suggest making this relative to 802.15.4e-2012 (which describes the TSCH
protocol and corresponding MAC extensions).

 With respect to security aspects, the IEEE 802.15.4e standards just
proposes few amendments. They will be taken into account for the writing of
the upgraded version of the draft.  However, the most of details provided
in Sec. 3 will remain still valid.


Issue #5 =E2=80=93 KMP

 [Michael R. @ Wed, May 14, 2014]: My understanding is that 6.3 describes a
way to get fresh per-cluster keying. It appears that this is done over a
layer-2 protocol.  Why not MLE?

 [Rene S @ Tue, May 20, 2014]: the draft introduces new 802.15.4-command
frames to implement the key negotiation phase (Section 6.3). As such, this
would constitute a change to the 802.15.4-2011 and 802.15.4e-2012
specification. Besides, this also implies that the key negotiation phase
can only deal with one-hop behavior.



[Rene S @ Tue, May 20, 2014]: the key negotiation phase using the anonymous
Diffie-Hellman scheme (Section 6.3.3) that uses ordinary Diffie-Hellman
groups in the ring of integers Zp, where p is a prime number that indexed
by a publicly computable integer (Section 6.3.1, Step c1)) and where p has
at least bit-size 128 (see Appendix A.1). The ordinary Diffie-Hellman
problem in integer rings Zp of this order of magnitude sizes is efficiently
computable, thereby rendering this scheme completely insecure

  The negotiation of the layer-2 key will be handled by MLE by using new
Information Elements (we have already designed the new approach).  Hence,
the next version of the draft will propose a KMP protocol fully based on
the adoption of IEEE 802.15.4e IEs.

 In the upgraded version of the draft, the KMP protocol will be handled by
using certified DH and Station-to-station protocol. No restrictions on the
key of the public/private key will be considered. As a consequence,
security issues related to the ordinary Diffie-Hellman problem in integer
rings Zp will be no more present.

   Issue #6 - Authorization step

 [Rene S @ Tue, May 20, 2014] the key negotiation protocol deals with
authenticated key agreement and does not consider potential authorization
steps.

 Should authorization be performed by higher layers during the join
procedure (see Issue #2) ? If so, KMP could still ignore this aspect.









--=20
*Giuseppe Piro, PhD*
Post Doc Researcher
DEI, Politecnico di Bari
via Orabona 4 - 70125 (Bari), Italy.
email: giuseppe.piro@poliba.it
phone: +39 080 5963301
web: telematics.poliba.it/piro

--089e0149d0e4da91f304fa0e437a
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><div class=3D"gmail_default" style=3D"color:rgb(0,0,153)">=
<span id=3D"docs-internal-guid-8f4d984b-2861-21c0-088d-6a025bbb2439"><p dir=
=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-bottom:0pt;text-al=
ign:justify">

<span style=3D"font-size:15px;font-family:Arial;color:rgb(0,0,0);vertical-a=
lign:baseline;white-space:pre-wrap;background-color:transparent">Dear all,<=
/span></p><p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-bo=
ttom:0pt;text-align:justify">

<span style=3D"font-size:15px;font-family:Arial;color:rgb(0,0,0);vertical-a=
lign:baseline;white-space:pre-wrap;background-color:transparent"> </span></=
p><p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-bottom:0pt=
;text-align:justify">

<span style=3D"font-size:15px;font-family:Arial;color:rgb(0,0,0);vertical-a=
lign:baseline;white-space:pre-wrap;background-color:transparent">I tried to=
 summarize main issues recently discussed on the draft-piro-6tisch-security=
-issues-01 (many thanks to Michael and Ren=C3=A8 for that).</span></p>

<p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-bottom:0pt;t=
ext-align:justify"><span style=3D"font-size:15px;font-family:Arial;color:rg=
b(0,0,0);vertical-align:baseline;white-space:pre-wrap;background-color:tran=
sparent"> </span></p>

<p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-bottom:0pt;t=
ext-align:justify"><span style=3D"font-size:15px;font-family:Arial;color:rg=
b(0,0,0);vertical-align:baseline;white-space:pre-wrap;background-color:tran=
sparent">In what follows, they have been organized in macro categories, whe=
re both your comments and my replies can be found.</span></p>

<p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-bottom:0pt;t=
ext-align:justify"><span style=3D"font-size:15px;font-family:Arial;color:rg=
b(0,0,0);vertical-align:baseline;white-space:pre-wrap;background-color:tran=
sparent"> </span></p>

<p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-bottom:0pt;t=
ext-align:justify"><span style=3D"font-size:15px;font-family:Arial;color:rg=
b(0,0,0);vertical-align:baseline;white-space:pre-wrap;background-color:tran=
sparent">Please, let me know if my proposals have sense. Otherwise, indicat=
e which issues will remain still uncovered. </span></p>

<br><p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-bottom:0=
pt;text-align:justify"><span style=3D"font-size:15px;font-family:Arial;colo=
r:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap;background-color:=
transparent">I&#39;m looking forward to receive your further considerations=
.</span></p>

<p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-bottom:0pt;t=
ext-align:justify"><span style=3D"font-size:15px;font-family:Arial;color:rg=
b(0,0,0);vertical-align:baseline;white-space:pre-wrap;background-color:tran=
sparent"> </span></p>

<p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-bottom:0pt;t=
ext-align:justify"><span style=3D"font-size:15px;font-family:Arial;color:rg=
b(0,0,0);vertical-align:baseline;white-space:pre-wrap;background-color:tran=
sparent">Thanks all,</span></p>

<p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-bottom:0pt;t=
ext-align:justify"><span style=3D"font-size:15px;font-family:Arial;color:rg=
b(0,0,0);vertical-align:baseline;white-space:pre-wrap;background-color:tran=
sparent"><span style=3D"font-size:15px;line-height:1.15;background-color:tr=
ansparent">Giuseppe</span></span></p>

<p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-bottom:0pt;t=
ext-align:justify"><span style=3D"font-size:15px;font-family:Arial;color:rg=
b(0,0,0);vertical-align:baseline;white-space:pre-wrap;background-color:tran=
sparent"> </span></p>

<p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-bottom:0pt;t=
ext-align:justify"><span style=3D"font-size:15px;font-family:Arial;color:rg=
b(0,0,0);vertical-align:baseline;white-space:pre-wrap;background-color:tran=
sparent">-----</span></p>

<p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-bottom:0pt;t=
ext-align:justify"><span style=3D"font-size:15px;font-family:Arial;color:rg=
b(0,0,0);vertical-align:baseline;white-space:pre-wrap;background-color:tran=
sparent"> </span></p>

<p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-bottom:0pt;t=
ext-align:justify"><span style=3D"font-size:15px;font-family:Arial;color:rg=
b(0,0,0);vertical-align:baseline;white-space:pre-wrap;background-color:tran=
sparent"> </span></p>

<br><p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-bottom:0=
pt;text-align:justify"><span style=3D"font-size:15px;font-family:Arial;colo=
r:rgb(0,0,0);font-weight:bold;vertical-align:baseline;white-space:pre-wrap;=
background-color:transparent">Issue #1 - Title of the draft</span></p>

<p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-bottom:0pt;t=
ext-align:justify"><span style=3D"font-size:15px;font-family:Arial;color:rg=
b(0,0,0);vertical-align:baseline;white-space:pre-wrap;background-color:tran=
sparent"> </span></p>

<p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-bottom:0pt;t=
ext-align:justify"><span style=3D"font-size:15px;font-family:Arial;color:rg=
b(255,0,0);vertical-align:baseline;white-space:pre-wrap;background-color:tr=
ansparent">[Michael R. @ Wed, May 14, 2014]: I don&#39;t agree with your ti=
tle! I don&#39;t see how =C2=A0this is a &quot;security framework&quot;. It=
 is something much more useful and important.</span></p>

<p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-bottom:0pt;t=
ext-align:justify"><span style=3D"font-size:15px;font-family:Arial;color:rg=
b(0,0,0);vertical-align:baseline;white-space:pre-wrap;background-color:tran=
sparent"> </span></p>

<p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-bottom:0pt;t=
ext-align:justify"><span style=3D"font-size:15px;font-family:Arial;color:rg=
b(0,0,0);vertical-align:baseline;white-space:pre-wrap;background-color:tran=
sparent">The title will be changed with =E2=80=9CLayer-2 security aspects f=
or the IEEE 802.15.4e MAC=E2=80=9D</span></p>

<p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-bottom:0pt;t=
ext-align:justify"><span style=3D"font-size:15px;font-family:Arial;color:rg=
b(0,0,0);vertical-align:baseline;white-space:pre-wrap;background-color:tran=
sparent"> </span></p>

<p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-bottom:0pt;t=
ext-align:justify"><span style=3D"font-size:15px;font-family:Arial;color:rg=
b(0,0,0);vertical-align:baseline;white-space:pre-wrap;background-color:tran=
sparent"> </span></p>

<br><p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-bottom:0=
pt;text-align:justify"><span style=3D"font-size:15px;font-family:Arial;colo=
r:rgb(0,0,0);font-weight:bold;vertical-align:baseline;white-space:pre-wrap;=
background-color:transparent">Issue #2 =E2=80=93 Derivation of Master Defau=
lt Keys and unsecured frames</span></p>

<p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-bottom:0pt;t=
ext-align:justify"><span style=3D"font-size:15px;font-family:Arial;color:rg=
b(0,0,0);vertical-align:baseline;white-space:pre-wrap;background-color:tran=
sparent"> </span></p>

<p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-bottom:0pt;t=
ext-align:justify"><span style=3D"font-size:15px;font-family:Arial;color:rg=
b(255,0,0);vertical-align:baseline;white-space:pre-wrap;background-color:tr=
ansparent">[Michael R. @ Wed, May 14, 2014]: The Setting-up Phase seems to =
assume a provisioning process to distribuite this MasterKey. =C2=A0It could=
 be that the MasterKey comes from something like 1x/PANA?</span></p>

<p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-bottom:0pt;t=
ext-align:justify"><span style=3D"font-size:15px;font-family:Arial;color:rg=
b(255,0,0);vertical-align:baseline;white-space:pre-wrap;background-color:tr=
ansparent"> </span></p>

<p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-bottom:0pt;t=
ext-align:justify"><span style=3D"font-size:15px;font-family:Arial;color:rg=
b(255,0,0);vertical-align:baseline;white-space:pre-wrap;background-color:tr=
ansparent">[Rene S @ Tue, May 20, 2014]: it is assumed that each node is pr=
econfigured with a master key M_k that is shared amongst all devices (Secti=
on 6.1.1), from which default keys D_k are derived using a publicly known f=
unction (with potentially other inputs, which are to be assumed publicly kn=
own). This seems to imply that all default keys can be considered as public=
ly known strings (!).</span></p>

<p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-bottom:0pt;t=
ext-align:justify"><span style=3D"font-size:15px;font-family:Arial;color:rg=
b(255,0,0);vertical-align:baseline;white-space:pre-wrap;background-color:tr=
ansparent"> </span></p>

<p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-bottom:0pt;t=
ext-align:justify"><span style=3D"font-size:15px;font-family:Arial;color:rg=
b(255,0,0);vertical-align:baseline;white-space:pre-wrap;background-color:tr=
ansparent">[Rene S @ Tue, May 20, 2014]: the 802.15.4-2011 specification mi=
stakenly does not allow mixing of secured and unsecured traffic (see, e.g.,=
 my emails of end of January 2014 on this). In particular, the hybrid secur=
ity network (as mentioned in Section 5) is not possible with 802.15.4-2011 =
or 802.15.4e-2012.</span></p>

<p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-bottom:0pt;t=
ext-align:justify"><span style=3D"font-size:15px;font-family:Arial;color:rg=
b(0,0,0);vertical-align:baseline;white-space:pre-wrap;background-color:tran=
sparent"> </span></p>

<p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-bottom:0pt;t=
ext-align:justify"><span style=3D"font-size:15px;font-family:Arial;color:rg=
b(0,0,0);vertical-align:baseline;white-space:pre-wrap;background-color:tran=
sparent"> </span></p>

<p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-bottom:0pt;t=
ext-align:justify"><span style=3D"font-size:15px;font-family:Arial;color:rg=
b(0,0,0);vertical-align:baseline;white-space:pre-wrap;background-color:tran=
sparent">The goal is to have a secured network, where all packets are encry=
pted and unsecured MAC frames are not supported (according to the condition=
 =E2=80=98d=E2=80=99 in Sec. 7.3.2 of the IEEE 802.15.4 std).</span></p>

<p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-bottom:0pt;t=
ext-align:justify"><span style=3D"font-size:15px;font-family:Arial;color:rg=
b(0,0,0);vertical-align:baseline;white-space:pre-wrap;background-color:tran=
sparent"> </span></p>

<p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-bottom:0pt;t=
ext-align:justify"><span style=3D"font-size:15px;font-family:Arial;color:rg=
b(0,0,0);vertical-align:baseline;white-space:pre-wrap;background-color:tran=
sparent">In this context, the Master Key refers to the =E2=80=9Cfake key=E2=
=80=9D that all all nodes know from the beginning. It can be provided by th=
e network administrator or directly by the manufacturer. It is used to:</sp=
an></p>

<ol style=3D"margin-top:0pt;margin-bottom:0pt"><li dir=3D"ltr" style=3D"lis=
t-style-type:decimal;font-size:15px;font-family:Arial;color:rgb(0,0,0);vert=
ical-align:baseline;background-color:transparent"><p dir=3D"ltr" style=3D"l=
ine-height:1.15;margin-top:0pt;margin-bottom:0pt;text-align:justify">

<span style=3D"font-size:15px;vertical-align:baseline;white-space:pre-wrap;=
background-color:transparent">protect beacon messages</span></p></li><li di=
r=3D"ltr" style=3D"list-style-type:decimal;font-size:15px;font-family:Arial=
;color:rgb(0,0,0);vertical-align:baseline;background-color:transparent">

<p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-bottom:0pt;t=
ext-align:justify"><span style=3D"font-size:15px;vertical-align:baseline;wh=
ite-space:pre-wrap;background-color:transparent">protect data frames storin=
g messages of the join procedure handled by upper layers</span></p>

</li></ol><p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-bo=
ttom:0pt;text-align:justify"><span style=3D"font-size:15px;font-family:Aria=
l;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap;background-=
color:transparent"> </span></p>

<p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-bottom:0pt;t=
ext-align:justify"><span style=3D"font-size:15px;font-family:Arial;color:rg=
b(0,0,0);vertical-align:baseline;white-space:pre-wrap;background-color:tran=
sparent">Thanks to the knowledge of the Master Key, all nodes, also those t=
hat has not yet completed the join procedure, may communicate with secured =
MAC frames (unsecured frames are not supported in a secured network).</span=
></p>

<p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-bottom:0pt;t=
ext-align:justify"><span style=3D"font-size:15px;font-family:Arial;color:rg=
b(0,0,0);vertical-align:baseline;white-space:pre-wrap;background-color:tran=
sparent"> </span></p>

<p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-bottom:0pt;t=
ext-align:justify"><span style=3D"font-size:15px;font-family:Arial;color:rg=
b(0,0,0);vertical-align:baseline;white-space:pre-wrap;background-color:tran=
sparent">At the end of the join procedure, the node could obtain the Defaul=
t Key from the network by using high-level protocols like PANA/.1x (which a=
lso offer authorization and authentication services). The Default Key, whic=
h cannot be more considered as a publicly known strings, is used to protect=
 all broadcast messages and those exchanged between a couple of nodes for n=
egotiating a layer-2 key.</span></p>

<p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-bottom:0pt;t=
ext-align:justify"><span style=3D"font-size:15px;font-family:Arial;color:rg=
b(0,0,0);vertical-align:baseline;white-space:pre-wrap;background-color:tran=
sparent"> </span></p>

<p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-bottom:0pt;t=
ext-align:justify"><span style=3D"font-size:15px;font-family:Arial;color:rg=
b(0,0,0);vertical-align:baseline;white-space:pre-wrap;background-color:tran=
sparent">Since the draft focuses on the MAC layer, I believe that this docu=
ment is not the right place where describing how PANA/.1x protocols can be =
used for that purpose. =C2=A0We can just assume that high level procedures =
(i.e., those related to the join process) will obtain the Master Key from a=
 specific entity into the network.</span></p>

<p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-bottom:0pt;t=
ext-align:justify"><span style=3D"font-size:15px;font-family:Arial;color:rg=
b(0,0,0);vertical-align:baseline;white-space:pre-wrap;background-color:tran=
sparent"> </span></p>

<br><p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-bottom:0=
pt;text-align:justify"><span style=3D"font-size:15px;font-family:Arial;colo=
r:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap;background-color:=
transparent"> </span></p>

<p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-bottom:0pt;t=
ext-align:justify"><span style=3D"font-size:15px;font-family:Arial;color:rg=
b(0,0,0);font-weight:bold;vertical-align:baseline;white-space:pre-wrap;back=
ground-color:transparent">Issue #3 =E2=80=93 Definition of secured configur=
ations</span></p>

<p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-bottom:0pt;t=
ext-align:justify"><span style=3D"font-size:15px;font-family:Arial;color:rg=
b(0,0,0);vertical-align:baseline;white-space:pre-wrap;background-color:tran=
sparent"> </span></p>

<p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-bottom:0pt;t=
ext-align:justify"><span style=3D"font-size:15px;font-family:Arial;color:rg=
b(255,0,0);vertical-align:baseline;white-space:pre-wrap;background-color:tr=
ansparent">[Michael R. @ Wed, May 14, 2014]: Thank you for giving the netwo=
rk definitions in section 5.0. It would be worth making it clear in the def=
inition of fully secure that all</span></p>

<p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-bottom:0pt;t=
ext-align:justify"><span style=3D"font-size:15px;font-family:Arial;color:rg=
b(255,0,0);vertical-align:baseline;white-space:pre-wrap;background-color:tr=
ansparent">broadcasts are encrypted, including the beacon. The _Hybrid Secu=
red network_ is likely the most common, and not because nodes are not capab=
le of encryption, but because they don&#39;t have the key (yet!!).</span></=
p>

<p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-bottom:0pt;t=
ext-align:justify"><span style=3D"font-size:15px;font-family:Arial;color:rg=
b(255,0,0);vertical-align:baseline;white-space:pre-wrap;background-color:tr=
ansparent"> </span></p>

<p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-bottom:0pt;t=
ext-align:justify"><span style=3D"font-size:15px;font-family:Arial;color:rg=
b(255,0,0);vertical-align:baseline;white-space:pre-wrap;background-color:tr=
ansparent">[Thomas W. @Tue, Jan 7, 2014]: About the functionality, the draf=
t describes 5 configurations (Full, Unsecured, Partial, Hybrid, Flexible), =
some of which support a combination of secured and unsecured L2 frames depe=
nding on the capabilities of the devices. Can you comment on the rationale =
between these configurations? I believe it is useful to look at desired fun=
ctionality first, and determine the configurations afterwards. Naively, I a=
m a bit scared of combining secured and unsecured. TSCH networks are envisi=
oned in the context of the IT/OT convergence to operate in mission critical=
 environments, so I would lean towards having only a single configuration: =
fully secured.</span></p>

<p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-bottom:0pt;t=
ext-align:justify"><span style=3D"font-size:15px;font-family:Arial;color:rg=
b(0,0,0);vertical-align:baseline;white-space:pre-wrap;background-color:tran=
sparent"> </span></p>

<p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-bottom:0pt;t=
ext-align:justify"><span style=3D"font-size:15px;font-family:Arial;color:rg=
b(0,0,0);vertical-align:baseline;white-space:pre-wrap;background-color:tran=
sparent"> </span></p>

<p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-bottom:0pt;t=
ext-align:justify"><span style=3D"font-size:15px;font-family:Arial;color:rg=
b(0,0,0);vertical-align:baseline;white-space:pre-wrap;background-color:tran=
sparent">Starting from the initial Thomas=E2=80=99s comment, I will focus t=
he attention only to secured configurations.</span></p>

<p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-bottom:0pt;t=
ext-align:justify"><span style=3D"font-size:15px;font-family:Arial;color:rg=
b(0,0,0);vertical-align:baseline;white-space:pre-wrap;background-color:tran=
sparent"> </span></p>

<p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-bottom:0pt;t=
ext-align:justify"><span style=3D"font-size:15px;font-family:Arial;color:rg=
b(0,0,0);vertical-align:baseline;white-space:pre-wrap;background-color:tran=
sparent">As indicated by Michael, the only two configurations that can be a=
llowed are (their definition is different to the one already present into t=
he draft):</span></p>

<ol style=3D"margin-top:0pt;margin-bottom:0pt"><li dir=3D"ltr" style=3D"lis=
t-style-type:decimal;font-size:15px;font-family:Arial;color:rgb(0,0,0);vert=
ical-align:baseline;background-color:transparent"><p dir=3D"ltr" style=3D"l=
ine-height:1.15;margin-top:0pt;margin-bottom:0pt;text-align:justify">

<span style=3D"font-size:15px;vertical-align:baseline;white-space:pre-wrap;=
background-color:transparent">_fully_secured_configuration_: all devices ha=
ve already ended the join procedure and have obtained the Default Key;</spa=
n></p>

</li><li dir=3D"ltr" style=3D"list-style-type:decimal;font-size:15px;font-f=
amily:Arial;color:rgb(0,0,0);vertical-align:baseline;background-color:trans=
parent"><p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-bott=
om:0pt;text-align:justify">

<span style=3D"font-size:15px;vertical-align:baseline;white-space:pre-wrap;=
background-color:transparent">_hybryd_secured_configuration_: some devices =
didn=E2=80=99t yet completed the join procedure and they have not yet the D=
efault Key.</span></p>

</li></ol><p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-bo=
ttom:0pt;text-align:justify"><span style=3D"font-size:15px;font-family:Aria=
l;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap;background-=
color:transparent"> </span></p>

<p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-bottom:0pt;t=
ext-align:justify"><span style=3D"font-size:15px;font-family:Arial;color:rg=
b(0,0,0);vertical-align:baseline;white-space:pre-wrap;background-color:tran=
sparent">In both configurations, all packets are encrypted (it is not possi=
ble to exchange unsecured frames in a secured network). However, there are =
different levels of security:</span></p>

<ol style=3D"margin-top:0pt;margin-bottom:0pt"><li dir=3D"ltr" style=3D"lis=
t-style-type:decimal;font-size:15px;font-family:Arial;color:rgb(0,0,0);vert=
ical-align:baseline;background-color:transparent"><p dir=3D"ltr" style=3D"l=
ine-height:1.15;margin-top:0pt;margin-bottom:0pt;text-align:justify">

<span style=3D"font-size:15px;vertical-align:baseline;white-space:pre-wrap;=
background-color:transparent">Beacon and data frames containing join messag=
es are encrypted by means of the Master Key ( a =E2=80=9Cfake key=E2=80=9D =
provided by the network administrator before the network deployment).</span=
></p>

</li><li dir=3D"ltr" style=3D"list-style-type:decimal;font-size:15px;font-f=
amily:Arial;color:rgb(0,0,0);vertical-align:baseline;background-color:trans=
parent"><p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-bott=
om:0pt;text-align:justify">

<span style=3D"font-size:15px;vertical-align:baseline;white-space:pre-wrap;=
background-color:transparent">Broadcast messages and data frames used to ne=
gotiate the layer-2 key are protected with the Default Key.</span></p></li>

<li dir=3D"ltr" style=3D"list-style-type:decimal;font-size:15px;font-family=
:Arial;color:rgb(0,0,0);vertical-align:baseline;background-color:transparen=
t"><p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-bottom:0p=
t;text-align:justify">

<span style=3D"font-size:15px;vertical-align:baseline;white-space:pre-wrap;=
background-color:transparent">Any other unicast messages are protected with=
 the Link Key properly negotiated through a KMP algorithm.</span></p></li>

</ol><p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-bottom:=
0pt;text-align:justify"><span style=3D"font-size:15px;font-family:Arial;col=
or:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap;background-color=
:transparent"> =C2=A0</span></p>

<p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-bottom:0pt;t=
ext-align:justify"><span style=3D"font-size:15px;font-family:Arial;color:rg=
b(0,0,0);vertical-align:baseline;white-space:pre-wrap;background-color:tran=
sparent"> </span></p>

<br><p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-bottom:0=
pt;text-align:justify"><span style=3D"font-size:15px;font-family:Arial;colo=
r:rgb(0,0,0);font-weight:bold;vertical-align:baseline;white-space:pre-wrap;=
background-color:transparent">Issue #4 =E2=80=93 Focus on the IEEE 802.15.4=
e</span></p>

<p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-bottom:0pt;t=
ext-align:justify"><span style=3D"font-size:15px;font-family:Arial;color:rg=
b(0,0,0);vertical-align:baseline;white-space:pre-wrap;background-color:tran=
sparent"> </span></p>

<p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-bottom:0pt;t=
ext-align:justify"><span style=3D"font-size:15px;font-family:Arial;color:rg=
b(255,0,0);vertical-align:baseline;white-space:pre-wrap;background-color:tr=
ansparent">[Rene S @ Tue, May 20, 2014] the draft relates to 802.15.4-2011.=
 I would suggest making this relative to 802.15.4e-2012 (which describes th=
e TSCH protocol and corresponding MAC extensions).</span></p>

<p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-bottom:0pt;t=
ext-align:justify"><span style=3D"font-size:15px;font-family:Arial;color:rg=
b(0,0,0);vertical-align:baseline;white-space:pre-wrap;background-color:tran=
sparent"> </span></p>

<p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-bottom:0pt;t=
ext-align:justify"><span style=3D"font-size:15px;font-family:Arial;color:rg=
b(0,0,0);vertical-align:baseline;white-space:pre-wrap;background-color:tran=
sparent">With respect to security aspects, the IEEE 802.15.4e standards jus=
t proposes few amendments. They will be taken into account for the writing =
of the upgraded version of the draft. =C2=A0However, the most of details pr=
ovided in Sec. 3 will remain still valid.</span></p>

<br><p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-bottom:0=
pt;text-align:justify"><span style=3D"font-size:15px;font-family:Arial;colo=
r:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap;background-color:=
transparent"> </span></p>

<p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-bottom:0pt;t=
ext-align:justify"><span style=3D"font-size:15px;font-family:Arial;color:rg=
b(0,0,0);vertical-align:baseline;white-space:pre-wrap;background-color:tran=
sparent"><br>

</span></p><p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-b=
ottom:0pt;text-align:justify"><span style=3D"font-size:15px;font-family:Ari=
al;color:rgb(0,0,0);font-weight:bold;vertical-align:baseline;white-space:pr=
e-wrap;background-color:transparent">Issue #5 =E2=80=93 KMP</span></p>

<p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-bottom:0pt;t=
ext-align:justify"><span style=3D"font-size:15px;font-family:Arial;color:rg=
b(0,0,0);vertical-align:baseline;white-space:pre-wrap;background-color:tran=
sparent"> </span></p>

<p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-bottom:0pt;t=
ext-align:justify"><span style=3D"font-size:15px;font-family:Arial;color:rg=
b(255,0,0);vertical-align:baseline;white-space:pre-wrap;background-color:tr=
ansparent">[Michael R. @ Wed, May 14, 2014]: My understanding is that 6.3 d=
escribes a way to get fresh per-cluster keying. It appears that this is don=
e over a layer-2 protocol. =C2=A0Why not MLE?</span></p>

<p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-bottom:0pt;t=
ext-align:justify"><span style=3D"font-size:15px;font-family:Arial;color:rg=
b(255,0,0);vertical-align:baseline;white-space:pre-wrap;background-color:tr=
ansparent"> </span></p>

<p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-bottom:0pt;t=
ext-align:justify"><span style=3D"font-size:15px;font-family:Arial;color:rg=
b(255,0,0);vertical-align:baseline;white-space:pre-wrap;background-color:tr=
ansparent">[Rene S @ Tue, May 20, 2014]: the draft introduces new 802.15.4-=
command frames to implement the key negotiation phase (Section 6.3). As suc=
h, this would constitute a change to the 802.15.4-2011 and 802.15.4e-2012 s=
pecification. Besides, this also implies that the key negotiation phase can=
 only deal with one-hop behavior.</span></p>

<p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-bottom:0pt;t=
ext-align:justify"><span style=3D"font-size:15px;font-family:Arial;color:rg=
b(255,0,0);vertical-align:baseline;white-space:pre-wrap;background-color:tr=
ansparent"> =C2=A0</span></p>

<p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-bottom:0pt;t=
ext-align:justify"><span style=3D"font-size:15px;font-family:Arial;color:rg=
b(255,0,0);vertical-align:baseline;white-space:pre-wrap;background-color:tr=
ansparent">[Rene S @ Tue, May 20, 2014]: the key negotiation phase using th=
e anonymous Diffie-Hellman scheme (Section 6.3.3) that uses ordinary Diffie=
-Hellman groups in the ring of integers Zp, where p is a prime number that =
indexed by a publicly computable integer (Section 6.3.1, Step c1)) and wher=
e p has at least bit-size 128 (see Appendix A.1). The ordinary Diffie-Hellm=
an problem in integer rings Zp of this order of magnitude sizes is efficien=
tly computable, thereby rendering this scheme completely insecure</span></p=
>

<p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-bottom:0pt;t=
ext-align:justify"><span style=3D"font-size:15px;font-family:Arial;color:rg=
b(0,0,0);vertical-align:baseline;white-space:pre-wrap;background-color:tran=
sparent"> </span></p>

<p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-bottom:0pt;t=
ext-align:justify"><span style=3D"font-size:15px;font-family:Arial;color:rg=
b(0,0,0);vertical-align:baseline;white-space:pre-wrap;background-color:tran=
sparent"> </span></p>

<p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-bottom:0pt;t=
ext-align:justify"><span style=3D"font-size:15px;font-family:Arial;color:rg=
b(0,0,0);vertical-align:baseline;white-space:pre-wrap;background-color:tran=
sparent">The negotiation of the layer-2 key will be handled by MLE by using=
 new Information Elements (we have already designed the new approach). =C2=
=A0Hence, the next version of the draft will propose a KMP protocol fully b=
ased on the adoption of IEEE 802.15.4e IEs.</span></p>

<p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-bottom:0pt;t=
ext-align:justify"><span style=3D"font-size:15px;font-family:Arial;color:rg=
b(0,0,0);vertical-align:baseline;white-space:pre-wrap;background-color:tran=
sparent"> </span></p>

<p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-bottom:0pt;t=
ext-align:justify"><span style=3D"font-size:15px;font-family:Arial;color:rg=
b(0,0,0);vertical-align:baseline;white-space:pre-wrap;background-color:tran=
sparent">In the upgraded version of the draft, the KMP protocol will be han=
dled by using certified DH and Station-to-station protocol. No restrictions=
 on the key of the public/private key will be considered. As a consequence,=
 security issues related to the ordinary Diffie-Hellman problem in integer =
rings Zp will be no more present.</span></p>

<p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-bottom:0pt;t=
ext-align:justify"><span style=3D"font-size:15px;font-family:Arial;color:rg=
b(0,0,0);vertical-align:baseline;white-space:pre-wrap;background-color:tran=
sparent"> </span></p>

<p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-bottom:0pt;t=
ext-align:justify"><span style=3D"font-size:15px;font-family:Arial;color:rg=
b(0,0,0);vertical-align:baseline;white-space:pre-wrap;background-color:tran=
sparent"> </span></p>

<p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-bottom:0pt;t=
ext-align:justify"><span style=3D"font-size:15px;font-family:Arial;color:rg=
b(0,0,0);vertical-align:baseline;white-space:pre-wrap;background-color:tran=
sparent"> </span></p>

<p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-bottom:0pt;t=
ext-align:justify"><span style=3D"font-size:15px;font-family:Arial;color:rg=
b(0,0,0);font-weight:bold;vertical-align:baseline;white-space:pre-wrap;back=
ground-color:transparent">Issue #6 - Authorization step</span></p>

<p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-bottom:0pt;t=
ext-align:justify"><span style=3D"font-size:15px;font-family:Arial;color:rg=
b(0,0,0);vertical-align:baseline;white-space:pre-wrap;background-color:tran=
sparent"> </span></p>

<p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-bottom:0pt;t=
ext-align:justify"><span style=3D"font-size:15px;font-family:Arial;color:rg=
b(255,0,0);vertical-align:baseline;white-space:pre-wrap;background-color:tr=
ansparent">[Rene S @ Tue, May 20, 2014] the key negotiation protocol deals =
with authenticated key agreement and does not consider potential authorizat=
ion steps.</span></p>

<p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-bottom:0pt;t=
ext-align:justify"><span style=3D"font-size:15px;font-family:Arial;color:rg=
b(0,0,0);vertical-align:baseline;white-space:pre-wrap;background-color:tran=
sparent"> </span></p>

<span style=3D"font-size:15px;font-family:Arial;color:rgb(0,0,0);vertical-a=
lign:baseline;white-space:pre-wrap;background-color:transparent">Should aut=
horization be performed by higher layers during the join procedure (see Iss=
ue #2) ? If so, KMP could still ignore this aspect.</span></span><br clear=
=3D"all">

</div><div class=3D"gmail_default" style=3D"color:rgb(0,0,153)"><span><span=
 style=3D"font-size:15px;font-family:Arial;color:rgb(0,0,0);vertical-align:=
baseline;white-space:pre-wrap;background-color:transparent"><br></span></sp=
an></div>

<div class=3D"gmail_default" style=3D"color:rgb(0,0,153)"><span><span style=
=3D"font-size:15px;font-family:Arial;color:rgb(0,0,0);vertical-align:baseli=
ne;white-space:pre-wrap;background-color:transparent"><br></span></span></d=
iv>

<div class=3D"gmail_default" style=3D"color:rgb(0,0,153)"><span><span style=
=3D"font-size:15px;font-family:Arial;color:rgb(0,0,0);vertical-align:baseli=
ne;white-space:pre-wrap;background-color:transparent"><br></span></span></d=
iv>

<div class=3D"gmail_default" style=3D"color:rgb(0,0,153)"><span><span style=
=3D"font-size:15px;font-family:Arial;color:rgb(0,0,0);vertical-align:baseli=
ne;white-space:pre-wrap;background-color:transparent"><br></span></span></d=
iv>

<div class=3D"gmail_default" style=3D"color:rgb(0,0,153)"><span><span style=
=3D"font-size:15px;font-family:Arial;color:rgb(0,0,0);vertical-align:baseli=
ne;white-space:pre-wrap;background-color:transparent"><br></span></span></d=
iv>

<div class=3D"gmail_default" style=3D"color:rgb(0,0,153)"><span><span style=
=3D"font-size:15px;font-family:Arial;color:rgb(0,0,0);vertical-align:baseli=
ne;white-space:pre-wrap;background-color:transparent"><br></span></span></d=
iv>

<div class=3D"gmail_default" style=3D"color:rgb(0,0,153)"><span><span style=
=3D"font-size:15px;font-family:Arial;color:rgb(0,0,0);vertical-align:baseli=
ne;white-space:pre-wrap;background-color:transparent"><br></span></span></d=
iv>

<br clear=3D"all"><div><br></div>-- <br><div dir=3D"ltr"><div dir=3D"ltr" s=
tyle=3D"font-family:arial;font-size:small"><font color=3D"#000099"><b>Giuse=
ppe Piro, PhD</b><br>Post Doc Researcher<br>DEI, Politecnico di Bari<br>via=
 Orabona 4 - 70125 (Bari), Italy.<br>

email: <a href=3D"mailto:giuseppe.piro@poliba.it" target=3D"_blank">giusepp=
e.piro@poliba.it</a></font></div><div dir=3D"ltr" style=3D"font-family:aria=
l;font-size:small"><font color=3D"#000099">phone: +39 080 5963301<br>web:=
=C2=A0<a href=3D"http://telematics.poliba.it/piro" style=3D"color:rgb(17,85=
,204)" target=3D"_blank">telematics.poliba.it/piro</a></font></div>

</div>
</div>

--089e0149d0e4da91f304fa0e437a--


From nobody Fri May 23 08:21:32 2014
Return-Path: <rstruik.ext@gmail.com>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 7DE6F1A056D; Fri, 23 May 2014 08:21:30 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.999
X-Spam-Level: 
X-Spam-Status: No, score=-1.999 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id JIvQByVuEZ5I; Fri, 23 May 2014 08:21:27 -0700 (PDT)
Received: from mail-ie0-x229.google.com (mail-ie0-x229.google.com [IPv6:2607:f8b0:4001:c03::229]) (using TLSv1 with cipher ECDHE-RSA-RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id BED3F1A0515; Fri, 23 May 2014 08:21:26 -0700 (PDT)
Received: by mail-ie0-f169.google.com with SMTP id at1so5255610iec.28 for <multiple recipients>; Fri, 23 May 2014 08:21:24 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113;  h=message-id:date:from:user-agent:mime-version:to:cc:subject :references:in-reply-to:content-type; bh=FZzJHI1rxXshTUoYsF+o4qkqrWGXx7qmKtuUFr3gESo=; b=WpRORdlgSUycnudLjdSpWRz30kXWlL889OBFtIhT/r66OJjcctdCVYm+nzjvWLuF5I 29XPskt6L1+WlUSdXlN8+lKwLUqQsXtg2SVLy4IJfUbFz2Bps2+j2LsKU9bLy9fm7+bP oEXd+uMAkxu6zmTaSlMJnY/IoQsMPhxBZ96MsD/MEIobjrLXpJRpbxNm8bXCpm8/Yb7/ JOK0NzUPvbdwlqrOpi9axaFjOjtLgOREVzFnjEDFoB44cxfLzeoUNkW27Ajie1/I8vDO O7ErcSo8L4Li1NzcRmkKTctknUn6VQcFr1vAcZjHYDS2dqrUCDr6wE4VbGwg5MooQjnC 0JBg==
X-Received: by 10.50.128.137 with SMTP id no9mr5320178igb.14.1400858484805; Fri, 23 May 2014 08:21:24 -0700 (PDT)
Received: from [192.168.1.103] (CPE0013100e2c51-CM001cea35caa6.cpe.net.cable.rogers.com. [99.231.3.110]) by mx.google.com with ESMTPSA id kw1sm4781071igb.4.2014.05.23.08.21.23 for <multiple recipients> (version=TLSv1 cipher=ECDHE-RSA-RC4-SHA bits=128/128); Fri, 23 May 2014 08:21:24 -0700 (PDT)
Message-ID: <537F676B.10500@gmail.com>
Date: Fri, 23 May 2014 11:21:15 -0400
From: Rene Struik <rstruik.ext@gmail.com>
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:24.0) Gecko/20100101 Thunderbird/24.5.0
MIME-Version: 1.0
To: Giuseppe Piro <giuseppe.piro@poliba.it>,  Michael Richardson <mcr+ietf@sandelman.ca>, 6tisch-security@ietf.org
References: <CAH-9zkqYfRiWaYu_EjdWifVQvBEKDV=Ra4A5F9K7Pf6xM8Lt-Q@mail.gmail.com>
In-Reply-To: <CAH-9zkqYfRiWaYu_EjdWifVQvBEKDV=Ra4A5F9K7Pf6xM8Lt-Q@mail.gmail.com>
Content-Type: multipart/alternative; boundary="------------080904060300010505000409"
Archived-At: http://mailarchive.ietf.org/arch/msg/6tisch-security/M8wOaXZ-gOSyTPZSx8xBUVycvdg
Cc: Thomas Watteyne <watteyne@eecs.berkeley.edu>, Gennaro Boggia <gennaro.boggia@poliba.it>, "6tisch@ietf.org" <6tisch@ietf.org>, "Pascal Thubert \(pthubert\)" <pthubert@cisco.com>, Alfredo Grieco <alfredo.grieco@poliba.it>
Subject: Re: [6tisch-security] about draft-piro-6tisch-security-issues-01
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 23 May 2014 15:21:30 -0000

This is a multi-part message in MIME format.
--------------080904060300010505000409
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 8bit

Hi Giuseppe:

Some further feedback below.

Best regards, Rene

On 5/23/2014 5:57 AM, Giuseppe Piro wrote:
>
> Dear all,
>
> I tried to summarize main issues recently discussed on the 
> draft-piro-6tisch-security-issues-01 (many thanks to Michael and Renè 
> for that).
>
> In what follows, they have been organized in macro categories, where 
> both your comments and my replies can be found.
>
> Please, let me know if my proposals have sense. Otherwise, indicate 
> which issues will remain still uncovered.
>
>
> I'm looking forward to receive your further considerations.
>
> Thanks all,
>
> Giuseppe
>
> -----
>
>
> Issue #1 - Title of the draft
>
> [Michael R. @ Wed, May 14, 2014]: I don't agree with your title! I 
> don't see how  this is a "security framework". It is something much 
> more useful and important.
>
> The title will be changed with “Layer-2 security aspects for the IEEE 
> 802.15.4e MAC”
>
>
> Issue #2 – Derivation of Master Default Keys and unsecured frames
>
> [Michael R. @ Wed, May 14, 2014]: The Setting-up Phase seems to assume 
> a provisioning process to distribuite this MasterKey.  It could be 
> that the MasterKey comes from something like 1x/PANA?
>
> [Rene S @ Tue, May 20, 2014]: it is assumed that each node is 
> preconfigured with a master key M_k that is shared amongst all devices 
> (Section 6.1.1), from which default keys D_k are derived using a 
> publicly known function (with potentially other inputs, which are to 
> be assumed publicly known). This seems to imply that all default keys 
> can be considered as publicly known strings (!).
>
> [Rene S @ Tue, May 20, 2014]: the 802.15.4-2011 specification 
> mistakenly does not allow mixing of secured and unsecured traffic 
> (see, e.g., my emails of end of January 2014 on this). In particular, 
> the hybrid security network (as mentioned in Section 5) is not 
> possible with 802.15.4-2011 or 802.15.4e-2012.
>
> The goal is to have a secured network, where all packets are encrypted 
> and unsecured MAC frames are not supported (according to the condition 
> ‘d’ in Sec. 7.3.2 of the IEEE 802.15.4 std).
>
> In this context, the Master Key refers to the “fake key” that all all 
> nodes know from the beginning. It can be provided by the network 
> administrator or directly by the manufacturer. It is used to:
>
> 1.
>
>     protect beacon messages
>
> 2.
>
>     protect data frames storing messages of the join procedure handled
>     by upper layers
>
RS>>
Of course, use of a master key that is "printed in a spec" is 
cryptographically the same as not using security at all. There are some 
caveats, though: (a) successful processing of secured incoming frames, 
results in a state change on the recipient device (update of nonce value 
- 802.15.4-2011, 7.2.3, Step q). With fake security, this would result 
in potential ways to set the frame counter to any value (including the 
"infinity" value). (b) processing of secured incoming frames requires 
the availability in a PIB table of the originator's address (see 
802.15.4-2011, 7.2.3, Step g). Without this, incoming security 
processing will fail. {BTW - for clarity: my comment was pointing at a 
mistake in 802.15.4-2011, which precludes the mixing of secured and 
unsecured traffic.}
<<RS
>
> 1.
>
>
> Thanks to the knowledge of the Master Key, all nodes, also those that 
> has not yet completed the join procedure, may communicate with secured 
> MAC frames (unsecured frames are not supported in a secured network).
>
> At the end of the join procedure, the node could obtain the Default 
> Key from the network by using high-level protocols like PANA/.1x 
> (which also offer authorization and authentication services). The 
> Default Key, which cannot be more considered as a publicly known 
> strings, is used to protect all broadcast messages and those exchanged 
> between a couple of nodes for negotiating a layer-2 key.
>
RS>>
Okay - it is indeed possible for the security manager to hand a 
network-wide key (which you call Default Key above) to the joining 
device, as part of the joining protocol and after successful completion 
of the authenticated key agreement scheme. In my understanding, this is 
not how this is written in your 01-draft, though.
<<RS

> Since the draft focuses on the MAC layer, I believe that this document 
> is not the right place where describing how PANA/.1x protocols can be 
> used for that purpose.  We can just assume that high level procedures 
> (i.e., those related to the join process) will obtain the Master Key 
> from a specific entity into the network.
>
>
> Issue #3 – Definition of secured configurations
>
> [Michael R. @ Wed, May 14, 2014]: Thank you for giving the network 
> definitions in section 5.0. It would be worth making it clear in the 
> definition of fully secure that all
>
> broadcasts are encrypted, including the beacon. The _Hybrid Secured 
> network_ is likely the most common, and not because nodes are not 
> capable of encryption, but because they don't have the key (yet!!).
>
> [Thomas W. @Tue, Jan 7, 2014]: About the functionality, the draft 
> describes 5 configurations (Full, Unsecured, Partial, Hybrid, 
> Flexible), some of which support a combination of secured and 
> unsecured L2 frames depending on the capabilities of the devices. Can 
> you comment on the rationale between these configurations? I believe 
> it is useful to look at desired functionality first, and determine the 
> configurations afterwards. Naively, I am a bit scared of combining 
> secured and unsecured. TSCH networks are envisioned in the context of 
> the IT/OT convergence to operate in mission critical environments, so 
> I would lean towards having only a single configuration: fully secured.
>
> Starting from the initial Thomas’s comment, I will focus the attention 
> only to secured configurations.
>
> As indicated by Michael, the only two configurations that can be 
> allowed are (their definition is different to the one already present 
> into the draft):
>
> 1.
>
>     _fully_secured_configuration_: all devices have already ended the
>     join procedure and have obtained the Default Key;
>
> 2.
>
>     _hybryd_secured_configuration_: some devices didn’t yet completed
>     the join procedure and they have not yet the Default Key.
>
> In both configurations, all packets are encrypted (it is not possible 
> to exchange unsecured frames in a secured network). However, there are 
> different levels of security:
>
> 1.
>
>     Beacon and data frames containing join messages are encrypted by
>     means of the Master Key ( a “fake key” provided by the network
>     administrator before the network deployment).
>
> 2.
>
>     Broadcast messages and data frames used to negotiate the layer-2
>     key are protected with the Default Key.
>
> 3.
>
>     Any other unicast messages are protected with the Link Key
>     properly negotiated through a KMP algorithm.
>
>
> Issue #4 – Focus on the IEEE 802.15.4e
>
> [Rene S @ Tue, May 20, 2014] the draft relates to 802.15.4-2011. I 
> would suggest making this relative to 802.15.4e-2012 (which describes 
> the TSCH protocol and corresponding MAC extensions).
>
> With respect to security aspects, the IEEE 802.15.4e standards just 
> proposes few amendments. They will be taken into account for the 
> writing of the upgraded version of the draft.  However, the most of 
> details provided in Sec. 3 will remain still valid.
>
>
RS>>
The difference is indeed not that huge. Please note, though, that 
security processing for TSCH is specified differently than for non-TSCH 
mode operations. (Whether this has been wisdom remains to be seen, since 
depending on unfallability of ASN numbers.)
<<RS
>
>
> Issue #5 – KMP
>
> [Michael R. @ Wed, May 14, 2014]: My understanding is that 6.3 
> describes a way to get fresh per-cluster keying. It appears that this 
> is done over a layer-2 protocol.  Why not MLE?
>
> [Rene S @ Tue, May 20, 2014]: the draft introduces new 
> 802.15.4-command frames to implement the key negotiation phase 
> (Section 6.3). As such, this would constitute a change to the 
> 802.15.4-2011 and 802.15.4e-2012 specification. Besides, this also 
> implies that the key negotiation phase can only deal with one-hop 
> behavior.
>
> [Rene S @ Tue, May 20, 2014]: the key negotiation phase using the 
> anonymous Diffie-Hellman scheme (Section 6.3.3) that uses ordinary 
> Diffie-Hellman groups in the ring of integers Zp, where p is a prime 
> number that indexed by a publicly computable integer (Section 6.3.1, 
> Step c1)) and where p has at least bit-size 128 (see Appendix A.1). 
> The ordinary Diffie-Hellman problem in integer rings Zp of this order 
> of magnitude sizes is efficiently computable, thereby rendering this 
> scheme completely insecure
>
> The negotiation of the layer-2 key will be handled by MLE by using new 
> Information Elements (we have already designed the new approach). 
>  Hence, the next version of the draft will propose a KMP protocol 
> fully based on the adoption of IEEE 802.15.4e IEs.
>
RS>>
The outcome of the join protocol should include a shared (link) key 
between the joining node and its neighbor or network manager, which will 
end up in the MAC PIB table, including associated keying related 
information. This join protocol should also deal with frame counter 
initialization and updates and resolving this with the ASN entry. I do 
not think it would necessarily be a good idea to treat join protocol 
messages as anything different from MAC data frames (i.e., it is higher 
layer traffic). This holds the more so, since join protocol will include 
some flows with the network manager, who may be multiple hops away (and 
MAC has no knowledge about anything more than one hop).
<<RS
>
> In the upgraded version of the draft, the KMP protocol will be handled 
> by using certified DH and Station-to-station protocol. No restrictions 
> on the key of the public/private key will be considered. As a 
> consequence, security issues related to the ordinary Diffie-Hellman 
> problem in integer rings Zp will be no more present.
>
RS>>
Ordinary Diffie-Hellman groups defined over the ring of integers mod p 
(when implemented at the right security level) will be prohibitively 
expensive on constrained devices. The only viabl option here would be to 
use elliptic curve based Diffie-Hellman groups.
<<RS
>
> Issue #6 - Authorization step
>
> [Rene S @ Tue, May 20, 2014] the key negotiation protocol deals with 
> authenticated key agreement and does not consider potential 
> authorization steps.
>
> Should authorization be performed by higher layers during the join 
> procedure (see Issue #2) ? If so, KMP could still ignore this aspect.
>
>
RS>>
An authenticated key agreement scheme can ignore authorization steps; a 
join protocol, which includes both key agreement, authorization, and 
configuration steps cannot.
<<RS
>
>
>
>
>
>
>
> -- 
> *Giuseppe Piro, PhD*
> Post Doc Researcher
> DEI, Politecnico di Bari
> via Orabona 4 - 70125 (Bari), Italy.
> email: giuseppe.piro@poliba.it <mailto:giuseppe.piro@poliba.it>
> phone: +39 080 5963301
> web: telematics.poliba.it/piro <http://telematics.poliba.it/piro>


-- 
email: rstruik.ext@gmail.com | Skype: rstruik
cell: +1 (647) 867-5658 | US: +1 (415) 690-7363


--------------080904060300010505000409
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: 8bit

<html>
  <head>
    <meta content="text/html; charset=UTF-8" http-equiv="Content-Type">
  </head>
  <body bgcolor="#FFFFFF" text="#000000">
    <div class="moz-cite-prefix">Hi Giuseppe:<br>
      <br>
      Some further feedback below.<br>
      <br>
      Best regards, Rene<br>
      <br>
      On 5/23/2014 5:57 AM, Giuseppe Piro wrote:<br>
    </div>
    <blockquote
cite="mid:CAH-9zkqYfRiWaYu_EjdWifVQvBEKDV=Ra4A5F9K7Pf6xM8Lt-Q@mail.gmail.com"
      type="cite">
      <div dir="ltr">
        <div class="gmail_default" style="color:rgb(0,0,153)"><span
            id="docs-internal-guid-8f4d984b-2861-21c0-088d-6a025bbb2439">
            <p dir="ltr"
style="line-height:1.15;margin-top:0pt;margin-bottom:0pt;text-align:justify"><span
style="font-size:15px;font-family:Arial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap;background-color:transparent">Dear
                all,</span></p>
            <p dir="ltr"
style="line-height:1.15;margin-top:0pt;margin-bottom:0pt;text-align:justify"><span
style="font-size:15px;font-family:Arial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap;background-color:transparent">
              </span></p>
            <p dir="ltr"
style="line-height:1.15;margin-top:0pt;margin-bottom:0pt;text-align:justify"><span
style="font-size:15px;font-family:Arial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap;background-color:transparent">I
                tried to summarize main issues recently discussed on the
                draft-piro-6tisch-security-issues-01 (many thanks to
                Michael and Renè for that).</span></p>
            <p dir="ltr"
style="line-height:1.15;margin-top:0pt;margin-bottom:0pt;text-align:justify"><span
style="font-size:15px;font-family:Arial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap;background-color:transparent">
              </span></p>
            <p dir="ltr"
style="line-height:1.15;margin-top:0pt;margin-bottom:0pt;text-align:justify"><span
style="font-size:15px;font-family:Arial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap;background-color:transparent">In
                what follows, they have been organized in macro
                categories, where both your comments and my replies can
                be found.</span></p>
            <p dir="ltr"
style="line-height:1.15;margin-top:0pt;margin-bottom:0pt;text-align:justify"><span
style="font-size:15px;font-family:Arial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap;background-color:transparent">
              </span></p>
            <p dir="ltr"
style="line-height:1.15;margin-top:0pt;margin-bottom:0pt;text-align:justify"><span
style="font-size:15px;font-family:Arial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap;background-color:transparent">Please,
                let me know if my proposals have sense. Otherwise,
                indicate which issues will remain still uncovered. </span></p>
            <br>
            <p dir="ltr"
style="line-height:1.15;margin-top:0pt;margin-bottom:0pt;text-align:justify"><span
style="font-size:15px;font-family:Arial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap;background-color:transparent">I'm
                looking forward to receive your further considerations.</span></p>
            <p dir="ltr"
style="line-height:1.15;margin-top:0pt;margin-bottom:0pt;text-align:justify"><span
style="font-size:15px;font-family:Arial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap;background-color:transparent">
              </span></p>
            <p dir="ltr"
style="line-height:1.15;margin-top:0pt;margin-bottom:0pt;text-align:justify"><span
style="font-size:15px;font-family:Arial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap;background-color:transparent">Thanks
                all,</span></p>
            <p dir="ltr"
style="line-height:1.15;margin-top:0pt;margin-bottom:0pt;text-align:justify"><span
style="font-size:15px;font-family:Arial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap;background-color:transparent"><span
style="font-size:15px;line-height:1.15;background-color:transparent">Giuseppe</span></span></p>
            <p dir="ltr"
style="line-height:1.15;margin-top:0pt;margin-bottom:0pt;text-align:justify"><span
style="font-size:15px;font-family:Arial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap;background-color:transparent">
              </span></p>
            <p dir="ltr"
style="line-height:1.15;margin-top:0pt;margin-bottom:0pt;text-align:justify"><span
style="font-size:15px;font-family:Arial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap;background-color:transparent">-----</span></p>
            <p dir="ltr"
style="line-height:1.15;margin-top:0pt;margin-bottom:0pt;text-align:justify"><span
style="font-size:15px;font-family:Arial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap;background-color:transparent">
              </span></p>
            <p dir="ltr"
style="line-height:1.15;margin-top:0pt;margin-bottom:0pt;text-align:justify"><span
style="font-size:15px;font-family:Arial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap;background-color:transparent">
              </span></p>
            <br>
            <p dir="ltr"
style="line-height:1.15;margin-top:0pt;margin-bottom:0pt;text-align:justify"><span
style="font-size:15px;font-family:Arial;color:rgb(0,0,0);font-weight:bold;vertical-align:baseline;white-space:pre-wrap;background-color:transparent">Issue
                #1 - Title of the draft</span></p>
            <p dir="ltr"
style="line-height:1.15;margin-top:0pt;margin-bottom:0pt;text-align:justify"><span
style="font-size:15px;font-family:Arial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap;background-color:transparent">
              </span></p>
            <p dir="ltr"
style="line-height:1.15;margin-top:0pt;margin-bottom:0pt;text-align:justify"><span
style="font-size:15px;font-family:Arial;color:rgb(255,0,0);vertical-align:baseline;white-space:pre-wrap;background-color:transparent">[Michael
                R. @ Wed, May 14, 2014]: I don't agree with your title!
                I don't see how  this is a "security framework". It is
                something much more useful and important.</span></p>
            <p dir="ltr"
style="line-height:1.15;margin-top:0pt;margin-bottom:0pt;text-align:justify"><span
style="font-size:15px;font-family:Arial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap;background-color:transparent">
              </span></p>
            <p dir="ltr"
style="line-height:1.15;margin-top:0pt;margin-bottom:0pt;text-align:justify"><span
style="font-size:15px;font-family:Arial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap;background-color:transparent">The
                title will be changed with “Layer-2 security aspects for
                the IEEE 802.15.4e MAC”</span></p>
            <p dir="ltr"
style="line-height:1.15;margin-top:0pt;margin-bottom:0pt;text-align:justify"><span
style="font-size:15px;font-family:Arial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap;background-color:transparent">
              </span></p>
            <p dir="ltr"
style="line-height:1.15;margin-top:0pt;margin-bottom:0pt;text-align:justify"><span
style="font-size:15px;font-family:Arial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap;background-color:transparent">
              </span></p>
            <br>
            <p dir="ltr"
style="line-height:1.15;margin-top:0pt;margin-bottom:0pt;text-align:justify"><span
style="font-size:15px;font-family:Arial;color:rgb(0,0,0);font-weight:bold;vertical-align:baseline;white-space:pre-wrap;background-color:transparent">Issue
                #2 – Derivation of Master Default Keys and unsecured
                frames</span></p>
            <p dir="ltr"
style="line-height:1.15;margin-top:0pt;margin-bottom:0pt;text-align:justify"><span
style="font-size:15px;font-family:Arial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap;background-color:transparent">
              </span></p>
            <p dir="ltr"
style="line-height:1.15;margin-top:0pt;margin-bottom:0pt;text-align:justify"><span
style="font-size:15px;font-family:Arial;color:rgb(255,0,0);vertical-align:baseline;white-space:pre-wrap;background-color:transparent">[Michael
                R. @ Wed, May 14, 2014]: The Setting-up Phase seems to
                assume a provisioning process to distribuite this
                MasterKey.  It could be that the MasterKey comes from
                something like 1x/PANA?</span></p>
            <p dir="ltr"
style="line-height:1.15;margin-top:0pt;margin-bottom:0pt;text-align:justify"><span
style="font-size:15px;font-family:Arial;color:rgb(255,0,0);vertical-align:baseline;white-space:pre-wrap;background-color:transparent">
              </span></p>
            <p dir="ltr"
style="line-height:1.15;margin-top:0pt;margin-bottom:0pt;text-align:justify"><span
style="font-size:15px;font-family:Arial;color:rgb(255,0,0);vertical-align:baseline;white-space:pre-wrap;background-color:transparent">[Rene
                S @ Tue, May 20, 2014]: it is assumed that each node is
                preconfigured with a master key M_k that is shared
                amongst all devices (Section 6.1.1), from which default
                keys D_k are derived using a publicly known function
                (with potentially other inputs, which are to be assumed
                publicly known). This seems to imply that all default
                keys can be considered as publicly known strings (!).</span></p>
            <p dir="ltr"
style="line-height:1.15;margin-top:0pt;margin-bottom:0pt;text-align:justify"><span
style="font-size:15px;font-family:Arial;color:rgb(255,0,0);vertical-align:baseline;white-space:pre-wrap;background-color:transparent">
              </span></p>
            <p dir="ltr"
style="line-height:1.15;margin-top:0pt;margin-bottom:0pt;text-align:justify"><span
style="font-size:15px;font-family:Arial;color:rgb(255,0,0);vertical-align:baseline;white-space:pre-wrap;background-color:transparent">[Rene
                S @ Tue, May 20, 2014]: the 802.15.4-2011 specification
                mistakenly does not allow mixing of secured and
                unsecured traffic (see, e.g., my emails of end of
                January 2014 on this). In particular, the hybrid
                security network (as mentioned in Section 5) is not
                possible with 802.15.4-2011 or 802.15.4e-2012.</span></p>
            <p dir="ltr"
style="line-height:1.15;margin-top:0pt;margin-bottom:0pt;text-align:justify"><span
style="font-size:15px;font-family:Arial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap;background-color:transparent">
              </span></p>
            <p dir="ltr"
style="line-height:1.15;margin-top:0pt;margin-bottom:0pt;text-align:justify"><span
style="font-size:15px;font-family:Arial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap;background-color:transparent">
              </span></p>
            <p dir="ltr"
style="line-height:1.15;margin-top:0pt;margin-bottom:0pt;text-align:justify"><span
style="font-size:15px;font-family:Arial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap;background-color:transparent">The
                goal is to have a secured network, where all packets are
                encrypted and unsecured MAC frames are not supported
                (according to the condition ‘d’ in Sec. 7.3.2 of the
                IEEE 802.15.4 std).</span></p>
            <p dir="ltr"
style="line-height:1.15;margin-top:0pt;margin-bottom:0pt;text-align:justify"><span
style="font-size:15px;font-family:Arial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap;background-color:transparent">
              </span></p>
            <p dir="ltr"
style="line-height:1.15;margin-top:0pt;margin-bottom:0pt;text-align:justify"><span
style="font-size:15px;font-family:Arial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap;background-color:transparent">In
                this context, the Master Key refers to the “fake key”
                that all all nodes know from the beginning. It can be
                provided by the network administrator or directly by the
                manufacturer. It is used to:</span></p>
            <ol style="margin-top:0pt;margin-bottom:0pt">
              <li dir="ltr"
style="list-style-type:decimal;font-size:15px;font-family:Arial;color:rgb(0,0,0);vertical-align:baseline;background-color:transparent">
                <p dir="ltr"
style="line-height:1.15;margin-top:0pt;margin-bottom:0pt;text-align:justify"><span
style="font-size:15px;vertical-align:baseline;white-space:pre-wrap;background-color:transparent">protect
                    beacon messages</span></p>
              </li>
              <li dir="ltr"
style="list-style-type:decimal;font-size:15px;font-family:Arial;color:rgb(0,0,0);vertical-align:baseline;background-color:transparent">
                <p dir="ltr"
style="line-height:1.15;margin-top:0pt;margin-bottom:0pt;text-align:justify"><span
style="font-size:15px;vertical-align:baseline;white-space:pre-wrap;background-color:transparent">protect
                    data frames storing messages of the join procedure
                    handled by upper layers</span></p>
              </li>
            </ol>
          </span></div>
      </div>
    </blockquote>
    RS&gt;&gt;<br>
    Of course, use of a master key that is "printed in a spec" is
    cryptographically the same as not using security at all. There are
    some caveats, though: (a) successful processing of secured incoming
    frames, results in a state change on the recipient device (update of
    nonce value - 802.15.4-2011, 7.2.3, Step q). With fake security,
    this would result in potential ways to set the frame counter to any
    value (including the "infinity" value). (b) processing of secured
    incoming frames requires the availability in a PIB table of the
    originator's address (see 802.15.4-2011, 7.2.3, Step g). Without
    this, incoming security processing will fail. {BTW - for clarity: my
    comment was pointing at a mistake in 802.15.4-2011, which precludes
    the mixing of secured and unsecured traffic.}<br>
    &lt;&lt;RS<br>
    <blockquote
cite="mid:CAH-9zkqYfRiWaYu_EjdWifVQvBEKDV=Ra4A5F9K7Pf6xM8Lt-Q@mail.gmail.com"
      type="cite">
      <div dir="ltr">
        <div class="gmail_default" style="color:rgb(0,0,153)"><span
            id="docs-internal-guid-8f4d984b-2861-21c0-088d-6a025bbb2439">
            <ol style="margin-top:0pt;margin-bottom:0pt">
              <li dir="ltr"
style="list-style-type:decimal;font-size:15px;font-family:Arial;color:rgb(0,0,0);vertical-align:baseline;background-color:transparent"><br>
              </li>
            </ol>
            <p dir="ltr"
style="line-height:1.15;margin-top:0pt;margin-bottom:0pt;text-align:justify"><span
style="font-size:15px;font-family:Arial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap;background-color:transparent">
              </span></p>
            <p dir="ltr"
style="line-height:1.15;margin-top:0pt;margin-bottom:0pt;text-align:justify"><span
style="font-size:15px;font-family:Arial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap;background-color:transparent">Thanks
                to the knowledge of the Master Key, all nodes, also
                those that has not yet completed the join procedure, may
                communicate with secured MAC frames (unsecured frames
                are not supported in a secured network).</span></p>
            <p dir="ltr"
style="line-height:1.15;margin-top:0pt;margin-bottom:0pt;text-align:justify"><span
style="font-size:15px;font-family:Arial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap;background-color:transparent">
              </span></p>
            <p dir="ltr"
style="line-height:1.15;margin-top:0pt;margin-bottom:0pt;text-align:justify"><span
style="font-size:15px;font-family:Arial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap;background-color:transparent">At
                the end of the join procedure, the node could obtain the
                Default Key from the network by using high-level
                protocols like PANA/.1x (which also offer authorization
                and authentication services). The Default Key, which
                cannot be more considered as a publicly known strings,
                is used to protect all broadcast messages and those
                exchanged between a couple of nodes for negotiating a
                layer-2 key.</span></p>
            <p dir="ltr"
style="line-height:1.15;margin-top:0pt;margin-bottom:0pt;text-align:justify"><span
style="font-size:15px;font-family:Arial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap;background-color:transparent">
              </span></p>
          </span></div>
      </div>
    </blockquote>
    RS&gt;&gt;<br>
    Okay - it is indeed possible for the security manager to hand a
    network-wide key (which you call Default Key above) to the joining
    device, as part of the joining protocol and after successful
    completion of the authenticated key agreement scheme. In my
    understanding, this is not how this is written in your 01-draft,
    though.<br>
    &lt;&lt;RS<br>
    <br>
    <blockquote
cite="mid:CAH-9zkqYfRiWaYu_EjdWifVQvBEKDV=Ra4A5F9K7Pf6xM8Lt-Q@mail.gmail.com"
      type="cite">
      <div dir="ltr">
        <div class="gmail_default" style="color:rgb(0,0,153)"><span
            id="docs-internal-guid-8f4d984b-2861-21c0-088d-6a025bbb2439">
            <p dir="ltr"
style="line-height:1.15;margin-top:0pt;margin-bottom:0pt;text-align:justify"><span
style="font-size:15px;font-family:Arial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap;background-color:transparent">Since
                the draft focuses on the MAC layer, I believe that this
                document is not the right place where describing how
                PANA/.1x protocols can be used for that purpose.  We can
                just assume that high level procedures (i.e., those
                related to the join process) will obtain the Master Key
                from a specific entity into the network.</span></p>
            <p dir="ltr"
style="line-height:1.15;margin-top:0pt;margin-bottom:0pt;text-align:justify"><span
style="font-size:15px;font-family:Arial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap;background-color:transparent">
              </span></p>
            <br>
            <p dir="ltr"
style="line-height:1.15;margin-top:0pt;margin-bottom:0pt;text-align:justify"><span
style="font-size:15px;font-family:Arial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap;background-color:transparent">
              </span></p>
            <p dir="ltr"
style="line-height:1.15;margin-top:0pt;margin-bottom:0pt;text-align:justify"><span
style="font-size:15px;font-family:Arial;color:rgb(0,0,0);font-weight:bold;vertical-align:baseline;white-space:pre-wrap;background-color:transparent">Issue
                #3 – Definition of secured configurations</span></p>
            <p dir="ltr"
style="line-height:1.15;margin-top:0pt;margin-bottom:0pt;text-align:justify"><span
style="font-size:15px;font-family:Arial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap;background-color:transparent">
              </span></p>
            <p dir="ltr"
style="line-height:1.15;margin-top:0pt;margin-bottom:0pt;text-align:justify"><span
style="font-size:15px;font-family:Arial;color:rgb(255,0,0);vertical-align:baseline;white-space:pre-wrap;background-color:transparent">[Michael
                R. @ Wed, May 14, 2014]: Thank you for giving the
                network definitions in section 5.0. It would be worth
                making it clear in the definition of fully secure that
                all</span></p>
            <p dir="ltr"
style="line-height:1.15;margin-top:0pt;margin-bottom:0pt;text-align:justify"><span
style="font-size:15px;font-family:Arial;color:rgb(255,0,0);vertical-align:baseline;white-space:pre-wrap;background-color:transparent">broadcasts
                are encrypted, including the beacon. The _Hybrid Secured
                network_ is likely the most common, and not because
                nodes are not capable of encryption, but because they
                don't have the key (yet!!).</span></p>
            <p dir="ltr"
style="line-height:1.15;margin-top:0pt;margin-bottom:0pt;text-align:justify"><span
style="font-size:15px;font-family:Arial;color:rgb(255,0,0);vertical-align:baseline;white-space:pre-wrap;background-color:transparent">
              </span></p>
            <p dir="ltr"
style="line-height:1.15;margin-top:0pt;margin-bottom:0pt;text-align:justify"><span
style="font-size:15px;font-family:Arial;color:rgb(255,0,0);vertical-align:baseline;white-space:pre-wrap;background-color:transparent">[Thomas
                W. @Tue, Jan 7, 2014]: About the functionality, the
                draft describes 5 configurations (Full, Unsecured,
                Partial, Hybrid, Flexible), some of which support a
                combination of secured and unsecured L2 frames depending
                on the capabilities of the devices. Can you comment on
                the rationale between these configurations? I believe it
                is useful to look at desired functionality first, and
                determine the configurations afterwards. Naively, I am a
                bit scared of combining secured and unsecured. TSCH
                networks are envisioned in the context of the IT/OT
                convergence to operate in mission critical environments,
                so I would lean towards having only a single
                configuration: fully secured.</span></p>
            <p dir="ltr"
style="line-height:1.15;margin-top:0pt;margin-bottom:0pt;text-align:justify"><span
style="font-size:15px;font-family:Arial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap;background-color:transparent">
              </span></p>
            <p dir="ltr"
style="line-height:1.15;margin-top:0pt;margin-bottom:0pt;text-align:justify"><span
style="font-size:15px;font-family:Arial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap;background-color:transparent">
              </span></p>
            <p dir="ltr"
style="line-height:1.15;margin-top:0pt;margin-bottom:0pt;text-align:justify"><span
style="font-size:15px;font-family:Arial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap;background-color:transparent">Starting
                from the initial Thomas’s comment, I will focus the
                attention only to secured configurations.</span></p>
            <p dir="ltr"
style="line-height:1.15;margin-top:0pt;margin-bottom:0pt;text-align:justify"><span
style="font-size:15px;font-family:Arial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap;background-color:transparent">
              </span></p>
            <p dir="ltr"
style="line-height:1.15;margin-top:0pt;margin-bottom:0pt;text-align:justify"><span
style="font-size:15px;font-family:Arial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap;background-color:transparent">As
                indicated by Michael, the only two configurations that
                can be allowed are (their definition is different to the
                one already present into the draft):</span></p>
            <ol style="margin-top:0pt;margin-bottom:0pt">
              <li dir="ltr"
style="list-style-type:decimal;font-size:15px;font-family:Arial;color:rgb(0,0,0);vertical-align:baseline;background-color:transparent">
                <p dir="ltr"
style="line-height:1.15;margin-top:0pt;margin-bottom:0pt;text-align:justify"><span
style="font-size:15px;vertical-align:baseline;white-space:pre-wrap;background-color:transparent">_fully_secured_configuration_:
                    all devices have already ended the join procedure
                    and have obtained the Default Key;</span></p>
              </li>
              <li dir="ltr"
style="list-style-type:decimal;font-size:15px;font-family:Arial;color:rgb(0,0,0);vertical-align:baseline;background-color:transparent">
                <p dir="ltr"
style="line-height:1.15;margin-top:0pt;margin-bottom:0pt;text-align:justify"><span
style="font-size:15px;vertical-align:baseline;white-space:pre-wrap;background-color:transparent">_hybryd_secured_configuration_:
                    some devices didn’t yet completed the join procedure
                    and they have not yet the Default Key.</span></p>
              </li>
            </ol>
            <p dir="ltr"
style="line-height:1.15;margin-top:0pt;margin-bottom:0pt;text-align:justify"><span
style="font-size:15px;font-family:Arial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap;background-color:transparent">
              </span></p>
            <p dir="ltr"
style="line-height:1.15;margin-top:0pt;margin-bottom:0pt;text-align:justify"><span
style="font-size:15px;font-family:Arial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap;background-color:transparent">In
                both configurations, all packets are encrypted (it is
                not possible to exchange unsecured frames in a secured
                network). However, there are different levels of
                security:</span></p>
            <ol style="margin-top:0pt;margin-bottom:0pt">
              <li dir="ltr"
style="list-style-type:decimal;font-size:15px;font-family:Arial;color:rgb(0,0,0);vertical-align:baseline;background-color:transparent">
                <p dir="ltr"
style="line-height:1.15;margin-top:0pt;margin-bottom:0pt;text-align:justify"><span
style="font-size:15px;vertical-align:baseline;white-space:pre-wrap;background-color:transparent">Beacon
                    and data frames containing join messages are
                    encrypted by means of the Master Key ( a “fake key”
                    provided by the network administrator before the
                    network deployment).</span></p>
              </li>
              <li dir="ltr"
style="list-style-type:decimal;font-size:15px;font-family:Arial;color:rgb(0,0,0);vertical-align:baseline;background-color:transparent">
                <p dir="ltr"
style="line-height:1.15;margin-top:0pt;margin-bottom:0pt;text-align:justify"><span
style="font-size:15px;vertical-align:baseline;white-space:pre-wrap;background-color:transparent">Broadcast
                    messages and data frames used to negotiate the
                    layer-2 key are protected with the Default Key.</span></p>
              </li>
              <li dir="ltr"
style="list-style-type:decimal;font-size:15px;font-family:Arial;color:rgb(0,0,0);vertical-align:baseline;background-color:transparent">
                <p dir="ltr"
style="line-height:1.15;margin-top:0pt;margin-bottom:0pt;text-align:justify"><span
style="font-size:15px;vertical-align:baseline;white-space:pre-wrap;background-color:transparent">Any
                    other unicast messages are protected with the Link
                    Key properly negotiated through a KMP algorithm.</span></p>
              </li>
            </ol>
            <p dir="ltr"
style="line-height:1.15;margin-top:0pt;margin-bottom:0pt;text-align:justify"><span
style="font-size:15px;font-family:Arial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap;background-color:transparent">
                 </span></p>
            <p dir="ltr"
style="line-height:1.15;margin-top:0pt;margin-bottom:0pt;text-align:justify"><span
style="font-size:15px;font-family:Arial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap;background-color:transparent">
              </span></p>
            <br>
            <p dir="ltr"
style="line-height:1.15;margin-top:0pt;margin-bottom:0pt;text-align:justify"><span
style="font-size:15px;font-family:Arial;color:rgb(0,0,0);font-weight:bold;vertical-align:baseline;white-space:pre-wrap;background-color:transparent">Issue
                #4 – Focus on the IEEE 802.15.4e</span></p>
            <p dir="ltr"
style="line-height:1.15;margin-top:0pt;margin-bottom:0pt;text-align:justify"><span
style="font-size:15px;font-family:Arial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap;background-color:transparent">
              </span></p>
            <p dir="ltr"
style="line-height:1.15;margin-top:0pt;margin-bottom:0pt;text-align:justify"><span
style="font-size:15px;font-family:Arial;color:rgb(255,0,0);vertical-align:baseline;white-space:pre-wrap;background-color:transparent">[Rene
                S @ Tue, May 20, 2014] the draft relates to
                802.15.4-2011. I would suggest making this relative to
                802.15.4e-2012 (which describes the TSCH protocol and
                corresponding MAC extensions).</span></p>
            <p dir="ltr"
style="line-height:1.15;margin-top:0pt;margin-bottom:0pt;text-align:justify"><span
style="font-size:15px;font-family:Arial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap;background-color:transparent">
              </span></p>
            <p dir="ltr"
style="line-height:1.15;margin-top:0pt;margin-bottom:0pt;text-align:justify"><span
style="font-size:15px;font-family:Arial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap;background-color:transparent">With
                respect to security aspects, the IEEE 802.15.4e
                standards just proposes few amendments. They will be
                taken into account for the writing of the upgraded
                version of the draft.  However, the most of details
                provided in Sec. 3 will remain still valid.</span></p>
            <br>
          </span></div>
      </div>
    </blockquote>
    RS&gt;&gt;<br>
    The difference is indeed not that huge. Please note, though, that
    security processing for TSCH is specified differently than for
    non-TSCH mode operations. (Whether this has been wisdom remains to
    be seen, since depending on unfallability of ASN numbers.)<br>
    &lt;&lt;RS<br>
    <blockquote
cite="mid:CAH-9zkqYfRiWaYu_EjdWifVQvBEKDV=Ra4A5F9K7Pf6xM8Lt-Q@mail.gmail.com"
      type="cite">
      <div dir="ltr">
        <div class="gmail_default" style="color:rgb(0,0,153)"><span
            id="docs-internal-guid-8f4d984b-2861-21c0-088d-6a025bbb2439">
            <p dir="ltr"
style="line-height:1.15;margin-top:0pt;margin-bottom:0pt;text-align:justify"><span
style="font-size:15px;font-family:Arial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap;background-color:transparent">
              </span></p>
            <p dir="ltr"
style="line-height:1.15;margin-top:0pt;margin-bottom:0pt;text-align:justify"><span
style="font-size:15px;font-family:Arial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap;background-color:transparent"><br>
              </span></p>
            <p dir="ltr"
style="line-height:1.15;margin-top:0pt;margin-bottom:0pt;text-align:justify"><span
style="font-size:15px;font-family:Arial;color:rgb(0,0,0);font-weight:bold;vertical-align:baseline;white-space:pre-wrap;background-color:transparent">Issue
                #5 – KMP</span></p>
            <p dir="ltr"
style="line-height:1.15;margin-top:0pt;margin-bottom:0pt;text-align:justify"><span
style="font-size:15px;font-family:Arial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap;background-color:transparent">
              </span></p>
            <p dir="ltr"
style="line-height:1.15;margin-top:0pt;margin-bottom:0pt;text-align:justify"><span
style="font-size:15px;font-family:Arial;color:rgb(255,0,0);vertical-align:baseline;white-space:pre-wrap;background-color:transparent">[Michael
                R. @ Wed, May 14, 2014]: My understanding is that 6.3
                describes a way to get fresh per-cluster keying. It
                appears that this is done over a layer-2 protocol.  Why
                not MLE?</span></p>
            <p dir="ltr"
style="line-height:1.15;margin-top:0pt;margin-bottom:0pt;text-align:justify"><span
style="font-size:15px;font-family:Arial;color:rgb(255,0,0);vertical-align:baseline;white-space:pre-wrap;background-color:transparent">
              </span></p>
            <p dir="ltr"
style="line-height:1.15;margin-top:0pt;margin-bottom:0pt;text-align:justify"><span
style="font-size:15px;font-family:Arial;color:rgb(255,0,0);vertical-align:baseline;white-space:pre-wrap;background-color:transparent">[Rene
                S @ Tue, May 20, 2014]: the draft introduces new
                802.15.4-command frames to implement the key negotiation
                phase (Section 6.3). As such, this would constitute a
                change to the 802.15.4-2011 and 802.15.4e-2012
                specification. Besides, this also implies that the key
                negotiation phase can only deal with one-hop behavior.</span></p>
            <p dir="ltr"
style="line-height:1.15;margin-top:0pt;margin-bottom:0pt;text-align:justify"><span
style="font-size:15px;font-family:Arial;color:rgb(255,0,0);vertical-align:baseline;white-space:pre-wrap;background-color:transparent">
                 </span></p>
            <p dir="ltr"
style="line-height:1.15;margin-top:0pt;margin-bottom:0pt;text-align:justify"><span
style="font-size:15px;font-family:Arial;color:rgb(255,0,0);vertical-align:baseline;white-space:pre-wrap;background-color:transparent">[Rene
                S @ Tue, May 20, 2014]: the key negotiation phase using
                the anonymous Diffie-Hellman scheme (Section 6.3.3) that
                uses ordinary Diffie-Hellman groups in the ring of
                integers Zp, where p is a prime number that indexed by a
                publicly computable integer (Section 6.3.1, Step c1))
                and where p has at least bit-size 128 (see Appendix
                A.1). The ordinary Diffie-Hellman problem in integer
                rings Zp of this order of magnitude sizes is efficiently
                computable, thereby rendering this scheme completely
                insecure</span></p>
            <p dir="ltr"
style="line-height:1.15;margin-top:0pt;margin-bottom:0pt;text-align:justify"><span
style="font-size:15px;font-family:Arial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap;background-color:transparent">
              </span></p>
            <p dir="ltr"
style="line-height:1.15;margin-top:0pt;margin-bottom:0pt;text-align:justify"><span
style="font-size:15px;font-family:Arial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap;background-color:transparent">
              </span></p>
            <p dir="ltr"
style="line-height:1.15;margin-top:0pt;margin-bottom:0pt;text-align:justify"><span
style="font-size:15px;font-family:Arial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap;background-color:transparent">The
                negotiation of the layer-2 key will be handled by MLE by
                using new Information Elements (we have already designed
                the new approach).  Hence, the next version of the draft
                will propose a KMP protocol fully based on the adoption
                of IEEE 802.15.4e IEs.</span></p>
          </span></div>
      </div>
    </blockquote>
    RS&gt;&gt;<br>
    The outcome of the join protocol should include a shared (link) key
    between the joining node and its neighbor or network manager, which
    will end up in the MAC PIB table, including associated keying
    related information. This join protocol should also deal with frame
    counter initialization and updates and resolving this with the ASN
    entry. I do not think it would necessarily be a good idea to treat
    join protocol messages as anything different from MAC data frames
    (i.e., it is higher layer traffic). This holds the more so, since
    join protocol will include some flows with the network manager, who
    may be multiple hops away (and MAC has no knowledge about anything
    more than one hop).<br>
    &lt;&lt;RS <br>
    <blockquote
cite="mid:CAH-9zkqYfRiWaYu_EjdWifVQvBEKDV=Ra4A5F9K7Pf6xM8Lt-Q@mail.gmail.com"
      type="cite">
      <div dir="ltr">
        <div class="gmail_default" style="color:rgb(0,0,153)"><span
            id="docs-internal-guid-8f4d984b-2861-21c0-088d-6a025bbb2439">
            <p dir="ltr"
style="line-height:1.15;margin-top:0pt;margin-bottom:0pt;text-align:justify"><span
style="font-size:15px;font-family:Arial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap;background-color:transparent">
              </span></p>
            <p dir="ltr"
style="line-height:1.15;margin-top:0pt;margin-bottom:0pt;text-align:justify"><span
style="font-size:15px;font-family:Arial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap;background-color:transparent">In
                the upgraded version of the draft, the KMP protocol will
                be handled by using certified DH and Station-to-station
                protocol. No restrictions on the key of the
                public/private key will be considered. As a consequence,
                security issues related to the ordinary Diffie-Hellman
                problem in integer rings Zp will be no more present.</span></p>
          </span></div>
      </div>
    </blockquote>
    RS&gt;&gt;<br>
    Ordinary Diffie-Hellman groups defined over the ring of integers mod
    p (when implemented at the right security level) will be
    prohibitively expensive on constrained devices. The only viabl
    option here would be to use elliptic curve based Diffie-Hellman
    groups.<br>
    &lt;&lt;RS<br>
    <blockquote
cite="mid:CAH-9zkqYfRiWaYu_EjdWifVQvBEKDV=Ra4A5F9K7Pf6xM8Lt-Q@mail.gmail.com"
      type="cite">
      <div dir="ltr">
        <div class="gmail_default" style="color:rgb(0,0,153)"><span
            id="docs-internal-guid-8f4d984b-2861-21c0-088d-6a025bbb2439">
            <p dir="ltr"
style="line-height:1.15;margin-top:0pt;margin-bottom:0pt;text-align:justify"><span
style="font-size:15px;font-family:Arial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap;background-color:transparent">
              </span></p>
            <p dir="ltr"
style="line-height:1.15;margin-top:0pt;margin-bottom:0pt;text-align:justify"><span
style="font-size:15px;font-family:Arial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap;background-color:transparent">
              </span></p>
            <p dir="ltr"
style="line-height:1.15;margin-top:0pt;margin-bottom:0pt;text-align:justify"><span
style="font-size:15px;font-family:Arial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap;background-color:transparent">
              </span></p>
            <p dir="ltr"
style="line-height:1.15;margin-top:0pt;margin-bottom:0pt;text-align:justify"><span
style="font-size:15px;font-family:Arial;color:rgb(0,0,0);font-weight:bold;vertical-align:baseline;white-space:pre-wrap;background-color:transparent">Issue
                #6 - Authorization step</span></p>
            <p dir="ltr"
style="line-height:1.15;margin-top:0pt;margin-bottom:0pt;text-align:justify"><span
style="font-size:15px;font-family:Arial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap;background-color:transparent">
              </span></p>
            <p dir="ltr"
style="line-height:1.15;margin-top:0pt;margin-bottom:0pt;text-align:justify"><span
style="font-size:15px;font-family:Arial;color:rgb(255,0,0);vertical-align:baseline;white-space:pre-wrap;background-color:transparent">[Rene
                S @ Tue, May 20, 2014] the key negotiation protocol
                deals with authenticated key agreement and does not
                consider potential authorization steps.</span></p>
            <p dir="ltr"
style="line-height:1.15;margin-top:0pt;margin-bottom:0pt;text-align:justify"><span
style="font-size:15px;font-family:Arial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap;background-color:transparent">
              </span></p>
            <span
style="font-size:15px;font-family:Arial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap;background-color:transparent">Should
              authorization be performed by higher layers during the
              join procedure (see Issue #2) ? If so, KMP could still
              ignore this aspect.</span></span><br clear="all">
        </div>
        <div class="gmail_default" style="color:rgb(0,0,153)"><span><span
style="font-size:15px;font-family:Arial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap;background-color:transparent"><br>
            </span></span></div>
        <div class="gmail_default" style="color:rgb(0,0,153)"><span><span
style="font-size:15px;font-family:Arial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap;background-color:transparent"><br>
            </span></span></div>
      </div>
    </blockquote>
    RS&gt;&gt;<br>
    An authenticated key agreement scheme can ignore authorization
    steps; a join protocol, which includes both key agreement,
    authorization, and configuration steps cannot.<br>
    &lt;&lt;RS<br>
    <blockquote
cite="mid:CAH-9zkqYfRiWaYu_EjdWifVQvBEKDV=Ra4A5F9K7Pf6xM8Lt-Q@mail.gmail.com"
      type="cite">
      <div dir="ltr">
        <div class="gmail_default" style="color:rgb(0,0,153)"><span><span
style="font-size:15px;font-family:Arial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap;background-color:transparent"><br>
            </span></span></div>
        <div class="gmail_default" style="color:rgb(0,0,153)"><span><span
style="font-size:15px;font-family:Arial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap;background-color:transparent"><br>
            </span></span></div>
        <div class="gmail_default" style="color:rgb(0,0,153)"><span><span
style="font-size:15px;font-family:Arial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap;background-color:transparent"><br>
            </span></span></div>
        <div class="gmail_default" style="color:rgb(0,0,153)"><span><span
style="font-size:15px;font-family:Arial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap;background-color:transparent"><br>
            </span></span></div>
        <div class="gmail_default" style="color:rgb(0,0,153)"><span><span
style="font-size:15px;font-family:Arial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap;background-color:transparent"><br>
            </span></span></div>
        <br clear="all">
        <div><br>
        </div>
        -- <br>
        <div dir="ltr">
          <div dir="ltr" style="font-family:arial;font-size:small"><font
              color="#000099"><b>Giuseppe Piro, PhD</b><br>
              Post Doc Researcher<br>
              DEI, Politecnico di Bari<br>
              via Orabona 4 - 70125 (Bari), Italy.<br>
              email: <a moz-do-not-send="true"
                href="mailto:giuseppe.piro@poliba.it" target="_blank">giuseppe.piro@poliba.it</a></font></div>
          <div dir="ltr" style="font-family:arial;font-size:small"><font
              color="#000099">phone: +39 080 5963301<br>
              web: <a moz-do-not-send="true"
                href="http://telematics.poliba.it/piro"
                style="color:rgb(17,85,204)" target="_blank">telematics.poliba.it/piro</a></font></div>
        </div>
      </div>
    </blockquote>
    <br>
    <br>
    <pre class="moz-signature" cols="72">-- 
email: <a class="moz-txt-link-abbreviated" href="mailto:rstruik.ext@gmail.com">rstruik.ext@gmail.com</a> | Skype: rstruik
cell: +1 (647) 867-5658 | US: +1 (415) 690-7363</pre>
  </body>
</html>

--------------080904060300010505000409--


From nobody Sat May 24 01:08:30 2014
Return-Path: <peppe@giuseppepiro.com>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 24F4D1A00F4 for <6tisch-security@ietfa.amsl.com>; Sat, 24 May 2014 01:08:27 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: 0.603
X-Spam-Level: 
X-Spam-Status: No, score=0.603 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, FM_FORGED_GMAIL=0.622, HELO_EQ_IT=0.635, HOST_EQ_IT=1.245, HTML_MESSAGE=0.001] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 4S4DneTgB4wn for <6tisch-security@ietfa.amsl.com>; Sat, 24 May 2014 01:08:23 -0700 (PDT)
Received: from smtpdb11.aruba.it (smtpdb11.aruba.it [62.149.158.253]) by ietfa.amsl.com (Postfix) with ESMTP id 7679A1A00F2 for <6tisch-security@ietf.org>; Sat, 24 May 2014 01:08:21 -0700 (PDT)
Received: from mail-oa0-f50.google.com ([209.85.219.50]) by smtpcmd04.ad.aruba.it with bizsmtp id 5k8G1o00C15q9lt01k8HzG; Sat, 24 May 2014 10:08:18 +0200
Received: by mail-oa0-f50.google.com with SMTP id i7so6551381oag.37 for <multiple recipients>; Sat, 24 May 2014 01:08:16 -0700 (PDT)
X-Received: by 10.60.132.207 with SMTP id ow15mr10562670oeb.59.1400918896010;  Sat, 24 May 2014 01:08:16 -0700 (PDT)
MIME-Version: 1.0
Received: by 10.76.151.227 with HTTP; Sat, 24 May 2014 01:07:55 -0700 (PDT)
In-Reply-To: <537F676B.10500@gmail.com>
References: <CAH-9zkqYfRiWaYu_EjdWifVQvBEKDV=Ra4A5F9K7Pf6xM8Lt-Q@mail.gmail.com> <537F676B.10500@gmail.com>
From: Giuseppe Piro <peppe@giuseppepiro.com>
Date: Sat, 24 May 2014 10:07:55 +0200
Message-ID: <CAH-9zko8jpcgWV6V+v-zw0mhms3wnTR8rh1UtFwvb19u9sF8jw@mail.gmail.com>
To: Rene Struik <rstruik.ext@gmail.com>
Content-Type: multipart/alternative; boundary=047d7b47283227eeba04fa20d9d1
Archived-At: http://mailarchive.ietf.org/arch/msg/6tisch-security/qVZjPAOIcJyof1kb9NflYwb6dtA
Cc: "Pascal Thubert \(pthubert\)" <pthubert@cisco.com>, 6tisch-security@ietf.org, Thomas Watteyne <watteyne@eecs.berkeley.edu>, Michael Richardson <mcr+ietf@sandelman.ca>, Alfredo Grieco <alfredo.grieco@poliba.it>, Gennaro Boggia <gennaro.boggia@poliba.it>, "6tisch@ietf.org" <6tisch@ietf.org>
Subject: Re: [6tisch-security] about draft-piro-6tisch-security-issues-01
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sat, 24 May 2014 08:08:27 -0000

--047d7b47283227eeba04fa20d9d1
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

Hi Ren=C3=A8,  thanks for you further comments.

Please, find my considerations below.


On Fri, May 23, 2014 at 5:21 PM, Rene Struik <rstruik.ext@gmail.com> wrote:

>  Hi Giuseppe:
>
> Some further feedback below.
>
> Best regards, Rene
>
>
> On 5/23/2014 5:57 AM, Giuseppe Piro wrote:
>
>  Dear all,
>
>  I tried to summarize main issues recently discussed on the
> draft-piro-6tisch-security-issues-01 (many thanks to Michael and Ren=C3=
=A8 for
> that).
>
>  In what follows, they have been organized in macro categories, where
> both your comments and my replies can be found.
>
>  Please, let me know if my proposals have sense. Otherwise, indicate
> which issues will remain still uncovered.
>
> I'm looking forward to receive your further considerations.
>
>  Thanks all,
>
> Giuseppe
>
>  -----
>
>
> Issue #1 - Title of the draft
>
>  [Michael R. @ Wed, May 14, 2014]: I don't agree with your title! I don't
> see how  this is a "security framework". It is something much more useful
> and important.
>
>  The title will be changed with =E2=80=9CLayer-2 security aspects for the=
 IEEE
> 802.15.4e MAC=E2=80=9D
>
>
> Issue #2 =E2=80=93 Derivation of Master Default Keys and unsecured frames
>
>  [Michael R. @ Wed, May 14, 2014]: The Setting-up Phase seems to assume a
> provisioning process to distribuite this MasterKey.  It could be that the
> MasterKey comes from something like 1x/PANA?
>
>  [Rene S @ Tue, May 20, 2014]: it is assumed that each node is
> preconfigured with a master key M_k that is shared amongst all devices
> (Section 6.1.1), from which default keys D_k are derived using a publicly
> known function (with potentially other inputs, which are to be assumed
> publicly known). This seems to imply that all default keys can be
> considered as publicly known strings (!).
>
>  [Rene S @ Tue, May 20, 2014]: the 802.15.4-2011 specification mistakenly
> does not allow mixing of secured and unsecured traffic (see, e.g., my
> emails of end of January 2014 on this). In particular, the hybrid securit=
y
> network (as mentioned in Section 5) is not possible with 802.15.4-2011 or
> 802.15.4e-2012.
>
>   The goal is to have a secured network, where all packets are encrypted
> and unsecured MAC frames are not supported (according to the condition =
=E2=80=98d=E2=80=99
> in Sec. 7.3.2 of the IEEE 802.15.4 std).
>
>  In this context, the Master Key refers to the =E2=80=9Cfake key=E2=80=9D=
 that all all
> nodes know from the beginning. It can be provided by the network
> administrator or directly by the manufacturer. It is used to:
>
>    1.
>
>    protect beacon messages
>     2.
>
>    protect data frames storing messages of the join procedure handled by
>    upper layers
>
>   RS>>
> Of course, use of a master key that is "printed in a spec" is
> cryptographically the same as not using security at all. There are some
> caveats, though: (a) successful processing of secured incoming frames,
> results in a state change on the recipient device (update of nonce value =
-
> 802.15.4-2011, 7.2.3, Step q). With fake security, this would result in
> potential ways to set the frame counter to any value (including the
> "infinity" value). (b) processing of secured incoming frames requires the
> availability in a PIB table of the originator's address (see 802.15.4-201=
1,
> 7.2.3, Step g). Without this, incoming security processing will fail. {BT=
W
> - for clarity: my comment was pointing at a mistake in 802.15.4-2011, whi=
ch
> precludes the mixing of secured and unsecured traffic.}
> <<RS
>

=E2=80=8BGP>>=E2=80=8B
I agree with comment (a) but at the moment I do not have a solution to that
problem : I have to reader more carefully the draft for that.
W.r.t comment (b), it is possible to avoid this issue by indexing the
Master Key implicitly (this allows the node that has not a Device
Descriptor of the sender to correctly decrypt the received packet).
 The Master Key may be identified implicitly by setting
KeyIDMode=3D0x00 and device_addressing_mode =3D NO_ADDRESS
In this case, the DeviceDescriptor, selected in the DeviceDescriptor lookup
procedure, is the one associated to the coordinator and no errors will
arise from the procedures.
 What do you think ?
If this has sense, we will describe in details such an aspect in the next
version of the draft.
 =E2=80=8B<<GP=E2=80=8B



>
>
>    1.
>
>  Thanks to the knowledge of the Master Key, all nodes, also those that
> has not yet completed the join procedure, may communicate with secured MA=
C
> frames (unsecured frames are not supported in a secured network).
>
>  At the end of the join procedure, the node could obtain the Default Key
> from the network by using high-level protocols like PANA/.1x (which also
> offer authorization and authentication services). The Default Key, which
> cannot be more considered as a publicly known strings, is used to protect
> all broadcast messages and those exchanged between a couple of nodes for
> negotiating a layer-2 key.
>
>   RS>>
> Okay - it is indeed possible for the security manager to hand a
> network-wide key (which you call Default Key above) to the joining device=
,
> as part of the joining protocol and after successful completion of the
> authenticated key agreement scheme. In my understanding, this is not how
> this is written in your 01-draft, though.
> <<RS
>

=E2=80=8BGP>>=E2=80=8B
=E2=80=8BThe derivation of the Default Key (or Network Key) as described in=
 this
mail has not been presented in the draft. It is just our proposal that we
will consider during the writing of the next version of the document.
=E2=80=8B<<GP=E2=80=8B
=E2=80=8B

=E2=80=8B
=E2=80=8B

>
>
>   Since the draft focuses on the MAC layer, I believe that this document
> is not the right place where describing how PANA/.1x protocols can be use=
d
> for that purpose.  We can just assume that high level procedures (i.e.,
> those related to the join process) will obtain the Master Key from a
> specific entity into the network.
>
>
>  Issue #3 =E2=80=93 Definition of secured configurations
>
>  [Michael R. @ Wed, May 14, 2014]: Thank you for giving the network
> definitions in section 5.0. It would be worth making it clear in the
> definition of fully secure that all
>
> broadcasts are encrypted, including the beacon. The _Hybrid Secured
> network_ is likely the most common, and not because nodes are not capable
> of encryption, but because they don't have the key (yet!!).
>
>  [Thomas W. @Tue, Jan 7, 2014]: About the functionality, the draft
> describes 5 configurations (Full, Unsecured, Partial, Hybrid, Flexible),
> some of which support a combination of secured and unsecured L2 frames
> depending on the capabilities of the devices. Can you comment on the
> rationale between these configurations? I believe it is useful to look at
> desired functionality first, and determine the configurations afterwards.
> Naively, I am a bit scared of combining secured and unsecured. TSCH
> networks are envisioned in the context of the IT/OT convergence to operat=
e
> in mission critical environments, so I would lean towards having only a
> single configuration: fully secured.
>
>   Starting from the initial Thomas=E2=80=99s comment, I will focus the at=
tention
> only to secured configurations.
>
>  As indicated by Michael, the only two configurations that can be allowed
> are (their definition is different to the one already present into the
> draft):
>
>    1.
>
>    _fully_secured_configuration_: all devices have already ended the join
>    procedure and have obtained the Default Key;
>     2.
>
>    _hybryd_secured_configuration_: some devices didn=E2=80=99t yet comple=
ted the
>    join procedure and they have not yet the Default Key.
>
>  In both configurations, all packets are encrypted (it is not possible to
> exchange unsecured frames in a secured network). However, there are
> different levels of security:
>
>    1.
>
>    Beacon and data frames containing join messages are encrypted by means
>    of the Master Key ( a =E2=80=9Cfake key=E2=80=9D provided by the netwo=
rk administrator
>    before the network deployment).
>     2.
>
>    Broadcast messages and data frames used to negotiate the layer-2 key
>    are protected with the Default Key.
>     3.
>
>    Any other unicast messages are protected with the Link Key properly
>    negotiated through a KMP algorithm.
>
>
>
>
> Issue #4 =E2=80=93 Focus on the IEEE 802.15.4e
>
>  [Rene S @ Tue, May 20, 2014] the draft relates to 802.15.4-2011. I would
> suggest making this relative to 802.15.4e-2012 (which describes the TSCH
> protocol and corresponding MAC extensions).
>
>  With respect to security aspects, the IEEE 802.15.4e standards just
> proposes few amendments. They will be taken into account for the writing =
of
> the upgraded version of the draft.  However, the most of details provided
> in Sec. 3 will remain still valid.
>
>   RS>>
> The difference is indeed not that huge. Please note, though, that securit=
y
> processing for TSCH is specified differently than for non-TSCH mode
> operations. (Whether this has been wisdom remains to be seen, since
> depending on unfallability of ASN numbers.)
> <<RS
>
>
=E2=80=8BGP>>=E2=80=8B
=E2=80=8BI will take care about the 802.15.4e amendments. =E2=80=8B
=E2=80=8B<<GP=E2=80=8B



>
>  Issue #5 =E2=80=93 KMP
>
>  [Michael R. @ Wed, May 14, 2014]: My understanding is that 6.3 describes
> a way to get fresh per-cluster keying. It appears that this is done over =
a
> layer-2 protocol.  Why not MLE?
>
>  [Rene S @ Tue, May 20, 2014]: the draft introduces new 802.15.4-command
> frames to implement the key negotiation phase (Section 6.3). As such, thi=
s
> would constitute a change to the 802.15.4-2011 and 802.15.4e-2012
> specification. Besides, this also implies that the key negotiation phase
> can only deal with one-hop behavior.
>
>
>
> [Rene S @ Tue, May 20, 2014]: the key negotiation phase using the
> anonymous Diffie-Hellman scheme (Section 6.3.3) that uses ordinary
> Diffie-Hellman groups in the ring of integers Zp, where p is a prime numb=
er
> that indexed by a publicly computable integer (Section 6.3.1, Step c1)) a=
nd
> where p has at least bit-size 128 (see Appendix A.1). The ordinary
> Diffie-Hellman problem in integer rings Zp of this order of magnitude siz=
es
> is efficiently computable, thereby rendering this scheme completely insec=
ure
>
>   The negotiation of the layer-2 key will be handled by MLE by using new
> Information Elements (we have already designed the new approach).  Hence,
> the next version of the draft will propose a KMP protocol fully based on
> the adoption of IEEE 802.15.4e IEs.
>
> RS>>
> The outcome of the join protocol should include a shared (link) key
> between the joining node and its neighbor or network manager, which will
> end up in the MAC PIB table, including associated keying related
> information. This join protocol should also deal with frame counter
> initialization and updates and resolving this with the ASN entry. I do no=
t
> think it would necessarily be a good idea to treat join protocol messages
> as anything different from MAC data frames (i.e., it is higher layer
> traffic). This holds the more so, since join protocol will include some
> flows with the network manager, who may be multiple hops away (and MAC ha=
s
> no knowledge about anything more than one hop).
> <<RS
>
 In the upgraded version of the draft, the KMP protocol will be handled by
> using certified DH and Station-to-station protocol. No restrictions on th=
e
> key of the public/private key will be considered. As a consequence,
> security issues related to the ordinary Diffie-Hellman problem in integer
> rings Zp will be no more present.
>
> RS>>
> Ordinary Diffie-Hellman groups defined over the ring of integers mod p
> (when implemented at the right security level) will be prohibitively
> expensive on constrained devices. The only viabl option here would be to
> use elliptic curve based Diffie-Hellman groups.
> <<RS
>

=E2=80=8BGP>>=E2=80=8B
=E2=80=8BOK, thanks for the clarification. We will include into the draft a
solution based on ECDH
=E2=80=8B<<GP=E2=80=8B



>      Issue #6 - Authorization step
>
>  [Rene S @ Tue, May 20, 2014] the key negotiation protocol deals with
> authenticated key agreement and does not consider potential authorization
> steps.
>
>  Should authorization be performed by higher layers during the join
> procedure (see Issue #2) ? If so, KMP could still ignore this aspect.
>
>
>   RS>>
> An authenticated key agreement scheme can ignore authorization steps; a
> join protocol, which includes both key agreement, authorization, and
> configuration steps cannot.
> <<RS
>

=E2=80=8BGP>>=E2=80=8B
=E2=80=8BOK, I agree
=E2=80=8B<<GP=E2=80=8B

--=20
*Giuseppe Piro, PhD*
Post Doc Researcher
DEI, Politecnico di Bari
via Orabona 4 - 70125 (Bari), Italy.
email: peppe@giuseppepiro.com
phone: +39 080 5963301
web: g <http://telematics.poliba.it/piro>iuseppepiro.com

--047d7b47283227eeba04fa20d9d1
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><div class=3D"gmail_default" style=3D"color:rgb(0,0,153)">=
Hi Ren=C3=A8, =C2=A0thanks for you further comments.=C2=A0</div><div class=
=3D"gmail_default" style=3D"color:rgb(0,0,153)"><br></div><div class=3D"gma=
il_default" style=3D"color:rgb(0,0,153)">


Please, find my considerations below.=C2=A0</div>
<div class=3D"gmail_extra"><br><br><div class=3D"gmail_quote">On Fri, May 2=
3, 2014 at 5:21 PM, Rene Struik <span dir=3D"ltr">&lt;<a href=3D"mailto:rst=
ruik.ext@gmail.com" target=3D"_blank">rstruik.ext@gmail.com</a>&gt;</span> =
wrote:<br>



<blockquote class=3D"gmail_quote" style=3D"margin:0px 0px 0px 0.8ex;border-=
left-width:1px;border-left-color:rgb(204,204,204);border-left-style:solid;p=
adding-left:1ex">
 =20
   =20
 =20
  <div bgcolor=3D"#FFFFFF" text=3D"#000000">
    <div>Hi Giuseppe:<br>
      <br>
      Some further feedback below.<br>
      <br>
      Best regards, Rene<div><br>
      <br>
      On 5/23/2014 5:57 AM, Giuseppe Piro wrote:<br>
    </div></div><div>
    <blockquote type=3D"cite">
      <div dir=3D"ltr">
        <div style=3D"color:rgb(0,0,153)"><span>
            <p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-=
bottom:0pt;text-align:justify"><span style=3D"font-size:15px;font-family:Ar=
ial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap;backgroun=
d-color:transparent">Dear
                all,</span></p>
            <p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-=
bottom:0pt;text-align:justify"><span style=3D"font-size:15px;font-family:Ar=
ial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap;backgroun=
d-color:transparent">
              </span></p>
            <p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-=
bottom:0pt;text-align:justify"><span style=3D"font-size:15px;font-family:Ar=
ial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap;backgroun=
d-color:transparent">I
                tried to summarize main issues recently discussed on the
                draft-piro-6tisch-security-issues-01 (many thanks to
                Michael and Ren=C3=A8 for that).</span></p>
            <p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-=
bottom:0pt;text-align:justify"><span style=3D"font-size:15px;font-family:Ar=
ial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap;backgroun=
d-color:transparent">
              </span></p>
            <p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-=
bottom:0pt;text-align:justify"><span style=3D"font-size:15px;font-family:Ar=
ial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap;backgroun=
d-color:transparent">In
                what follows, they have been organized in macro
                categories, where both your comments and my replies can
                be found.</span></p>
            <p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-=
bottom:0pt;text-align:justify"><span style=3D"font-size:15px;font-family:Ar=
ial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap;backgroun=
d-color:transparent">
              </span></p>
            <p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-=
bottom:0pt;text-align:justify"><span style=3D"font-size:15px;font-family:Ar=
ial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap;backgroun=
d-color:transparent">Please,
                let me know if my proposals have sense. Otherwise,
                indicate which issues will remain still uncovered. </span><=
/p>
            <br>
            <p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-=
bottom:0pt;text-align:justify"><span style=3D"font-size:15px;font-family:Ar=
ial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap;backgroun=
d-color:transparent">I&#39;m
                looking forward to receive your further considerations.</sp=
an></p>
            <p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-=
bottom:0pt;text-align:justify"><span style=3D"font-size:15px;font-family:Ar=
ial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap;backgroun=
d-color:transparent">
              </span></p>
            <p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-=
bottom:0pt;text-align:justify"><span style=3D"font-size:15px;font-family:Ar=
ial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap;backgroun=
d-color:transparent">Thanks
                all,</span></p>
            <p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-=
bottom:0pt;text-align:justify"><span style=3D"font-size:15px;font-family:Ar=
ial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap;backgroun=
d-color:transparent"><span style=3D"font-size:15px;line-height:1.15;backgro=
und-color:transparent">Giuseppe</span></span></p>




            <p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-=
bottom:0pt;text-align:justify"><span style=3D"font-size:15px;font-family:Ar=
ial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap;backgroun=
d-color:transparent">
              </span></p>
            <p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-=
bottom:0pt;text-align:justify"><span style=3D"font-size:15px;font-family:Ar=
ial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap;backgroun=
d-color:transparent">-----</span></p>




            <p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-=
bottom:0pt;text-align:justify"><span style=3D"font-size:15px;font-family:Ar=
ial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap;backgroun=
d-color:transparent">
              </span></p>
            <p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-=
bottom:0pt;text-align:justify"><span style=3D"font-size:15px;font-family:Ar=
ial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap;backgroun=
d-color:transparent">
              </span></p>
            <br>
            <p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-=
bottom:0pt;text-align:justify"><span style=3D"font-size:15px;font-family:Ar=
ial;color:rgb(0,0,0);font-weight:bold;vertical-align:baseline;white-space:p=
re-wrap;background-color:transparent">Issue
                #1 - Title of the draft</span></p>
            <p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-=
bottom:0pt;text-align:justify"><span style=3D"font-size:15px;font-family:Ar=
ial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap;backgroun=
d-color:transparent">
              </span></p>
            <p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-=
bottom:0pt;text-align:justify"><span style=3D"font-size:15px;font-family:Ar=
ial;color:rgb(255,0,0);vertical-align:baseline;white-space:pre-wrap;backgro=
und-color:transparent">[Michael
                R. @ Wed, May 14, 2014]: I don&#39;t agree with your title!
                I don&#39;t see how =C2=A0this is a &quot;security framewor=
k&quot;. It is
                something much more useful and important.</span></p>
            <p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-=
bottom:0pt;text-align:justify"><span style=3D"font-size:15px;font-family:Ar=
ial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap;backgroun=
d-color:transparent">
              </span></p>
            <p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-=
bottom:0pt;text-align:justify"><span style=3D"font-size:15px;font-family:Ar=
ial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap;backgroun=
d-color:transparent">The
                title will be changed with =E2=80=9CLayer-2 security aspect=
s for
                the IEEE 802.15.4e MAC=E2=80=9D</span></p>
            <p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-=
bottom:0pt;text-align:justify"><span style=3D"font-size:15px;font-family:Ar=
ial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap;backgroun=
d-color:transparent">
              </span></p>
            <p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-=
bottom:0pt;text-align:justify"><span style=3D"font-size:15px;font-family:Ar=
ial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap;backgroun=
d-color:transparent">
              </span></p>
            <br>
            <p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-=
bottom:0pt;text-align:justify"><span style=3D"font-size:15px;font-family:Ar=
ial;color:rgb(0,0,0);font-weight:bold;vertical-align:baseline;white-space:p=
re-wrap;background-color:transparent">Issue
                #2 =E2=80=93 Derivation of Master Default Keys and unsecure=
d
                frames</span></p>
            <p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-=
bottom:0pt;text-align:justify"><span style=3D"font-size:15px;font-family:Ar=
ial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap;backgroun=
d-color:transparent">
              </span></p>
            <p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-=
bottom:0pt;text-align:justify"><span style=3D"font-size:15px;font-family:Ar=
ial;color:rgb(255,0,0);vertical-align:baseline;white-space:pre-wrap;backgro=
und-color:transparent">[Michael
                R. @ Wed, May 14, 2014]: The Setting-up Phase seems to
                assume a provisioning process to distribuite this
                MasterKey. =C2=A0It could be that the MasterKey comes from
                something like 1x/PANA?</span></p>
            <p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-=
bottom:0pt;text-align:justify"><span style=3D"font-size:15px;font-family:Ar=
ial;color:rgb(255,0,0);vertical-align:baseline;white-space:pre-wrap;backgro=
und-color:transparent">
              </span></p>
            <p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-=
bottom:0pt;text-align:justify"><span style=3D"font-size:15px;font-family:Ar=
ial;color:rgb(255,0,0);vertical-align:baseline;white-space:pre-wrap;backgro=
und-color:transparent">[Rene
                S @ Tue, May 20, 2014]: it is assumed that each node is
                preconfigured with a master key M_k that is shared
                amongst all devices (Section 6.1.1), from which default
                keys D_k are derived using a publicly known function
                (with potentially other inputs, which are to be assumed
                publicly known). This seems to imply that all default
                keys can be considered as publicly known strings (!).</span=
></p>
            <p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-=
bottom:0pt;text-align:justify"><span style=3D"font-size:15px;font-family:Ar=
ial;color:rgb(255,0,0);vertical-align:baseline;white-space:pre-wrap;backgro=
und-color:transparent">
              </span></p>
            <p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-=
bottom:0pt;text-align:justify"><span style=3D"font-size:15px;font-family:Ar=
ial;color:rgb(255,0,0);vertical-align:baseline;white-space:pre-wrap;backgro=
und-color:transparent">[Rene
                S @ Tue, May 20, 2014]: the 802.15.4-2011 specification
                mistakenly does not allow mixing of secured and
                unsecured traffic (see, e.g., my emails of end of
                January 2014 on this). In particular, the hybrid
                security network (as mentioned in Section 5) is not
                possible with 802.15.4-2011 or 802.15.4e-2012.</span></p>
            <p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-=
bottom:0pt;text-align:justify"><span style=3D"font-size:15px;font-family:Ar=
ial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap;backgroun=
d-color:transparent">
              </span></p>
            <p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-=
bottom:0pt;text-align:justify"><span style=3D"font-size:15px;font-family:Ar=
ial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap;backgroun=
d-color:transparent">
              </span></p>
            <p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-=
bottom:0pt;text-align:justify"><span style=3D"font-size:15px;font-family:Ar=
ial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap;backgroun=
d-color:transparent">The
                goal is to have a secured network, where all packets are
                encrypted and unsecured MAC frames are not supported
                (according to the condition =E2=80=98d=E2=80=99 in Sec. 7.3=
.2 of the
                IEEE 802.15.4 std).</span></p>
            <p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-=
bottom:0pt;text-align:justify"><span style=3D"font-size:15px;font-family:Ar=
ial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap;backgroun=
d-color:transparent">
              </span></p>
            <p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-=
bottom:0pt;text-align:justify"><span style=3D"font-size:15px;font-family:Ar=
ial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap;backgroun=
d-color:transparent">In
                this context, the Master Key refers to the =E2=80=9Cfake ke=
y=E2=80=9D
                that all all nodes know from the beginning. It can be
                provided by the network administrator or directly by the
                manufacturer. It is used to:</span></p>
            <ol style=3D"margin-top:0pt;margin-bottom:0pt">
              <li dir=3D"ltr" style=3D"list-style-type:decimal;font-size:15=
px;font-family:Arial;color:rgb(0,0,0);vertical-align:baseline;background-co=
lor:transparent">
                <p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;mar=
gin-bottom:0pt;text-align:justify"><span style=3D"font-size:15px;vertical-a=
lign:baseline;white-space:pre-wrap;background-color:transparent">protect
                    beacon messages</span></p>
              </li>
              <li dir=3D"ltr" style=3D"list-style-type:decimal;font-size:15=
px;font-family:Arial;color:rgb(0,0,0);vertical-align:baseline;background-co=
lor:transparent">
                <p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;mar=
gin-bottom:0pt;text-align:justify"><span style=3D"font-size:15px;vertical-a=
lign:baseline;white-space:pre-wrap;background-color:transparent">protect
                    data frames storing messages of the join procedure
                    handled by upper layers</span></p>
              </li>
            </ol>
          </span></div>
      </div>
    </blockquote></div>
    RS&gt;&gt;<br>
    Of course, use of a master key that is &quot;printed in a spec&quot; is
    cryptographically the same as not using security at all. There are
    some caveats, though: (a) successful processing of secured incoming
    frames, results in a state change on the recipient device (update of
    nonce value - 802.15.4-2011, 7.2.3, Step q). With fake security,
    this would result in potential ways to set the frame counter to any
    value (including the &quot;infinity&quot; value). (b) processing of sec=
ured
    incoming frames requires the availability in a PIB table of the
    originator&#39;s address (see 802.15.4-2011, 7.2.3, Step g). Without
    this, incoming security processing will fail. {BTW - for clarity: my
    comment was pointing at a mistake in 802.15.4-2011, which precludes
    the mixing of secured and unsecured traffic.}<br>
    &lt;&lt;RS</div></blockquote><div><div class=3D"gmail_quote"><div><div =
class=3D"gmail_default" style=3D"color:rgb(0,0,153)"><br></div><div class=
=3D"gmail_default" style=3D"color:rgb(0,0,153)">=E2=80=8BGP&gt;&gt;=E2=80=
=8B</div></div><div class=3D"gmail_default" style=3D"color:rgb(0,0,153)">

I agree with comment (a) but at the moment I do not have a solution to that=
 problem : I have to reader more carefully the draft for that.<br></div></d=
iv></div><div>
<div class=3D"gmail_default" style=3D"color:rgb(0,0,153)">W.r.t comment (b)=
, it is possible to avoid this issue by indexing the Master Key implicitly =
(this allows the node that has not a Device Descriptor of the sender to cor=
rectly decrypt the received packet).<br>

</div>
<div class=3D"gmail_default" style=3D"color:rgb(0,0,153)">The Master Key ma=
y be identified implicitly by setting=C2=A0<br></div><div class=3D"gmail_de=
fault" style=3D"color:rgb(0,0,153)">
KeyIDMode=3D0x00 and device_addressing_mode =3D NO_ADDRESS=C2=A0</div><div =
class=3D"gmail_default" style=3D"color:rgb(0,0,153)">In this case, the Devi=
ceDescriptor, selected in the=C2=A0DeviceDescriptor lookup procedure, is th=
e one associated to the coordinator and no errors will arise from the proce=
dures.=C2=A0<br>

</div>
<div class=3D"gmail_default" style=3D"color:rgb(0,0,153)">What do you think=
 ?=C2=A0<br></div><div class=3D"gmail_default" style=3D"color:rgb(0,0,153)"=
>If this has sense, we will describe in details such an aspect in the next =
version of the draft.<br>

</div>
<div class=3D"gmail_default" style=3D"color:rgb(0,0,153)">=E2=80=8B&lt;&lt;=
GP=E2=80=8B<br></div><div class=3D"gmail_default" style=3D"color:rgb(0,0,15=
3)"><div style=3D"color:rgb(34,34,34)"><div><br></div></div></div></div><di=
v>=C2=A0</div><blockquote class=3D"gmail_quote" style=3D"margin:0px 0px 0px=
 0.8ex;border-left-width:1px;border-left-color:rgb(204,204,204);border-left=
-style:solid;padding-left:1ex">

<div bgcolor=3D"#FFFFFF" text=3D"#000000">
<div>
<br>
    <blockquote type=3D"cite">
      <div dir=3D"ltr">
        <div style=3D"color:rgb(0,0,153)"><span>
            <ol style=3D"margin-top:0pt;margin-bottom:0pt">
              <li dir=3D"ltr" style=3D"list-style-type:decimal;font-size:15=
px;font-family:Arial;color:rgb(0,0,0);vertical-align:baseline;background-co=
lor:transparent"><br>
              </li>
            </ol>
            <p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-=
bottom:0pt;text-align:justify"><span style=3D"font-size:15px;font-family:Ar=
ial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap;backgroun=
d-color:transparent">
              </span></p>
            <p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-=
bottom:0pt;text-align:justify"><span style=3D"font-size:15px;font-family:Ar=
ial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap;backgroun=
d-color:transparent">Thanks
                to the knowledge of the Master Key, all nodes, also
                those that has not yet completed the join procedure, may
                communicate with secured MAC frames (unsecured frames
                are not supported in a secured network).</span></p>
            <p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-=
bottom:0pt;text-align:justify"><span style=3D"font-size:15px;font-family:Ar=
ial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap;backgroun=
d-color:transparent">
              </span></p>
            <p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-=
bottom:0pt;text-align:justify"><span style=3D"font-size:15px;font-family:Ar=
ial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap;backgroun=
d-color:transparent">At
                the end of the join procedure, the node could obtain the
                Default Key from the network by using high-level
                protocols like PANA/.1x (which also offer authorization
                and authentication services). The Default Key, which
                cannot be more considered as a publicly known strings,
                is used to protect all broadcast messages and those
                exchanged between a couple of nodes for negotiating a
                layer-2 key.</span></p>
            <p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-=
bottom:0pt;text-align:justify"><span style=3D"font-size:15px;font-family:Ar=
ial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap;backgroun=
d-color:transparent">
              </span></p>
          </span></div>
      </div>
    </blockquote></div>
    RS&gt;&gt;<br>
    Okay - it is indeed possible for the security manager to hand a
    network-wide key (which you call Default Key above) to the joining
    device, as part of the joining protocol and after successful
    completion of the authenticated key agreement scheme. In my
    understanding, this is not how this is written in your 01-draft,
    though.<br>
    &lt;&lt;RS</div></blockquote><div><br></div><div><div class=3D"gmail_qu=
ote"><div><div class=3D"gmail_default" style=3D"color:rgb(0,0,153)">=E2=80=
=8BGP&gt;&gt;=E2=80=8B</div></div><div class=3D"gmail_default" style=3D"col=
or:rgb(0,0,153)">=E2=80=8BThe derivation of the Default Key (or Network Key=
) as described in this mail has not been presented in the draft. It is just=
 our proposal that we will consider during the writing of the next version =
of the document.<br>

</div></div></div><div><div class=3D"gmail_quote"><div><div class=3D"gmail_=
default" style=3D"color:rgb(0,0,153)">=E2=80=8B&lt;&lt;GP=E2=80=8B<br></div=
></div></div><div class=3D"gmail_default" style=3D"color:rgb(0,0,153)">=E2=
=80=8B</div><br></div><div class=3D"gmail_default" style=3D"color:rgb(0,0,1=
53)">

=E2=80=8B</div><div class=3D"gmail_default" style=3D"color:rgb(0,0,153)">=
=E2=80=8B</div><blockquote class=3D"gmail_quote" style=3D"margin:0px 0px 0p=
x 0.8ex;border-left-width:1px;border-left-color:rgb(204,204,204);border-lef=
t-style:solid;padding-left:1ex">

<div bgcolor=3D"#FFFFFF" text=3D"#000000"><div><br>
    <br>
    <blockquote type=3D"cite">
      <div dir=3D"ltr">
        <div style=3D"color:rgb(0,0,153)"><span>
            <p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-=
bottom:0pt;text-align:justify"><span style=3D"font-size:15px;font-family:Ar=
ial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap;backgroun=
d-color:transparent">Since
                the draft focuses on the MAC layer, I believe that this
                document is not the right place where describing how
                PANA/.1x protocols can be used for that purpose. =C2=A0We c=
an
                just assume that high level procedures (i.e., those
                related to the join process) will obtain the Master Key
                from a specific entity into the network.</span></p>
            <p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-=
bottom:0pt;text-align:justify"><span style=3D"font-size:15px;font-family:Ar=
ial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap;backgroun=
d-color:transparent">
              </span></p>
            <br>
            <p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-=
bottom:0pt;text-align:justify"><span style=3D"font-size:15px;font-family:Ar=
ial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap;backgroun=
d-color:transparent">
              </span></p>
            <p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-=
bottom:0pt;text-align:justify"><span style=3D"font-size:15px;font-family:Ar=
ial;color:rgb(0,0,0);font-weight:bold;vertical-align:baseline;white-space:p=
re-wrap;background-color:transparent">Issue
                #3 =E2=80=93 Definition of secured configurations</span></p=
>
            <p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-=
bottom:0pt;text-align:justify"><span style=3D"font-size:15px;font-family:Ar=
ial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap;backgroun=
d-color:transparent">
              </span></p>
            <p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-=
bottom:0pt;text-align:justify"><span style=3D"font-size:15px;font-family:Ar=
ial;color:rgb(255,0,0);vertical-align:baseline;white-space:pre-wrap;backgro=
und-color:transparent">[Michael
                R. @ Wed, May 14, 2014]: Thank you for giving the
                network definitions in section 5.0. It would be worth
                making it clear in the definition of fully secure that
                all</span></p>
            <p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-=
bottom:0pt;text-align:justify"><span style=3D"font-size:15px;font-family:Ar=
ial;color:rgb(255,0,0);vertical-align:baseline;white-space:pre-wrap;backgro=
und-color:transparent">broadcasts
                are encrypted, including the beacon. The _Hybrid Secured
                network_ is likely the most common, and not because
                nodes are not capable of encryption, but because they
                don&#39;t have the key (yet!!).</span></p>
            <p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-=
bottom:0pt;text-align:justify"><span style=3D"font-size:15px;font-family:Ar=
ial;color:rgb(255,0,0);vertical-align:baseline;white-space:pre-wrap;backgro=
und-color:transparent">
              </span></p>
            <p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-=
bottom:0pt;text-align:justify"><span style=3D"font-size:15px;font-family:Ar=
ial;color:rgb(255,0,0);vertical-align:baseline;white-space:pre-wrap;backgro=
und-color:transparent">[Thomas
                W. @Tue, Jan 7, 2014]: About the functionality, the
                draft describes 5 configurations (Full, Unsecured,
                Partial, Hybrid, Flexible), some of which support a
                combination of secured and unsecured L2 frames depending
                on the capabilities of the devices. Can you comment on
                the rationale between these configurations? I believe it
                is useful to look at desired functionality first, and
                determine the configurations afterwards. Naively, I am a
                bit scared of combining secured and unsecured. TSCH
                networks are envisioned in the context of the IT/OT
                convergence to operate in mission critical environments,
                so I would lean towards having only a single
                configuration: fully secured.</span></p>
            <p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-=
bottom:0pt;text-align:justify"><span style=3D"font-size:15px;font-family:Ar=
ial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap;backgroun=
d-color:transparent">
              </span></p>
            <p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-=
bottom:0pt;text-align:justify"><span style=3D"font-size:15px;font-family:Ar=
ial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap;backgroun=
d-color:transparent">
              </span></p>
            <p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-=
bottom:0pt;text-align:justify"><span style=3D"font-size:15px;font-family:Ar=
ial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap;backgroun=
d-color:transparent">Starting
                from the initial Thomas=E2=80=99s comment, I will focus the
                attention only to secured configurations.</span></p>
            <p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-=
bottom:0pt;text-align:justify"><span style=3D"font-size:15px;font-family:Ar=
ial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap;backgroun=
d-color:transparent">
              </span></p>
            <p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-=
bottom:0pt;text-align:justify"><span style=3D"font-size:15px;font-family:Ar=
ial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap;backgroun=
d-color:transparent">As
                indicated by Michael, the only two configurations that
                can be allowed are (their definition is different to the
                one already present into the draft):</span></p>
            <ol style=3D"margin-top:0pt;margin-bottom:0pt">
              <li dir=3D"ltr" style=3D"list-style-type:decimal;font-size:15=
px;font-family:Arial;color:rgb(0,0,0);vertical-align:baseline;background-co=
lor:transparent">
                <p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;mar=
gin-bottom:0pt;text-align:justify"><span style=3D"font-size:15px;vertical-a=
lign:baseline;white-space:pre-wrap;background-color:transparent">_fully_sec=
ured_configuration_:
                    all devices have already ended the join procedure
                    and have obtained the Default Key;</span></p>
              </li>
              <li dir=3D"ltr" style=3D"list-style-type:decimal;font-size:15=
px;font-family:Arial;color:rgb(0,0,0);vertical-align:baseline;background-co=
lor:transparent">
                <p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;mar=
gin-bottom:0pt;text-align:justify"><span style=3D"font-size:15px;vertical-a=
lign:baseline;white-space:pre-wrap;background-color:transparent">_hybryd_se=
cured_configuration_:
                    some devices didn=E2=80=99t yet completed the join proc=
edure
                    and they have not yet the Default Key.</span></p>
              </li>
            </ol>
            <p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-=
bottom:0pt;text-align:justify"><span style=3D"font-size:15px;font-family:Ar=
ial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap;backgroun=
d-color:transparent">
              </span></p>
            <p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-=
bottom:0pt;text-align:justify"><span style=3D"font-size:15px;font-family:Ar=
ial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap;backgroun=
d-color:transparent">In
                both configurations, all packets are encrypted (it is
                not possible to exchange unsecured frames in a secured
                network). However, there are different levels of
                security:</span></p>
            <ol style=3D"margin-top:0pt;margin-bottom:0pt">
              <li dir=3D"ltr" style=3D"list-style-type:decimal;font-size:15=
px;font-family:Arial;color:rgb(0,0,0);vertical-align:baseline;background-co=
lor:transparent">
                <p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;mar=
gin-bottom:0pt;text-align:justify"><span style=3D"font-size:15px;vertical-a=
lign:baseline;white-space:pre-wrap;background-color:transparent">Beacon
                    and data frames containing join messages are
                    encrypted by means of the Master Key ( a =E2=80=9Cfake =
key=E2=80=9D
                    provided by the network administrator before the
                    network deployment).</span></p>
              </li>
              <li dir=3D"ltr" style=3D"list-style-type:decimal;font-size:15=
px;font-family:Arial;color:rgb(0,0,0);vertical-align:baseline;background-co=
lor:transparent">
                <p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;mar=
gin-bottom:0pt;text-align:justify"><span style=3D"font-size:15px;vertical-a=
lign:baseline;white-space:pre-wrap;background-color:transparent">Broadcast
                    messages and data frames used to negotiate the
                    layer-2 key are protected with the Default Key.</span><=
/p>
              </li>
              <li dir=3D"ltr" style=3D"list-style-type:decimal;font-size:15=
px;font-family:Arial;color:rgb(0,0,0);vertical-align:baseline;background-co=
lor:transparent">
                <p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;mar=
gin-bottom:0pt;text-align:justify"><span style=3D"font-size:15px;vertical-a=
lign:baseline;white-space:pre-wrap;background-color:transparent">Any
                    other unicast messages are protected with the Link
                    Key properly negotiated through a KMP algorithm.</span>=
</p>
              </li>
            </ol>
            <p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-=
bottom:0pt;text-align:justify"><span style=3D"font-size:15px;font-family:Ar=
ial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap;backgroun=
d-color:transparent">
                =C2=A0</span></p>
            <p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-=
bottom:0pt;text-align:justify"><span style=3D"font-size:15px;font-family:Ar=
ial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap;backgroun=
d-color:transparent">
              </span></p>
            <br>
            <p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-=
bottom:0pt;text-align:justify"><span style=3D"font-size:15px;font-family:Ar=
ial;color:rgb(0,0,0);font-weight:bold;vertical-align:baseline;white-space:p=
re-wrap;background-color:transparent">Issue
                #4 =E2=80=93 Focus on the IEEE 802.15.4e</span></p>
            <p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-=
bottom:0pt;text-align:justify"><span style=3D"font-size:15px;font-family:Ar=
ial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap;backgroun=
d-color:transparent">
              </span></p>
            <p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-=
bottom:0pt;text-align:justify"><span style=3D"font-size:15px;font-family:Ar=
ial;color:rgb(255,0,0);vertical-align:baseline;white-space:pre-wrap;backgro=
und-color:transparent">[Rene
                S @ Tue, May 20, 2014] the draft relates to
                802.15.4-2011. I would suggest making this relative to
                802.15.4e-2012 (which describes the TSCH protocol and
                corresponding MAC extensions).</span></p>
            <p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-=
bottom:0pt;text-align:justify"><span style=3D"font-size:15px;font-family:Ar=
ial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap;backgroun=
d-color:transparent">
              </span></p>
            <p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-=
bottom:0pt;text-align:justify"><span style=3D"font-size:15px;font-family:Ar=
ial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap;backgroun=
d-color:transparent">With
                respect to security aspects, the IEEE 802.15.4e
                standards just proposes few amendments. They will be
                taken into account for the writing of the upgraded
                version of the draft. =C2=A0However, the most of details
                provided in Sec. 3 will remain still valid.</span></p>
            <br>
          </span></div>
      </div>
    </blockquote></div>
    RS&gt;&gt;<br>
    The difference is indeed not that huge. Please note, though, that
    security processing for TSCH is specified differently than for
    non-TSCH mode operations. (Whether this has been wisdom remains to
    be seen, since depending on unfallability of ASN numbers.)<br>
    &lt;&lt;RS<div><br></div></div></blockquote><div><br></div><div><div cl=
ass=3D"gmail_quote"><div><div class=3D"gmail_default" style=3D"color:rgb(0,=
0,153)">=E2=80=8BGP&gt;&gt;=E2=80=8B</div></div><div class=3D"gmail_default=
" style=3D"color:rgb(0,0,153)">

=E2=80=8BI will take care about the 802.15.4e amendments. =E2=80=8B<br></di=
v></div></div><div><div class=3D"gmail_quote"><div><div class=3D"gmail_defa=
ult" style=3D"color:rgb(0,0,153)">=E2=80=8B&lt;&lt;GP=E2=80=8B<br></div></d=
iv></div></div><div><br></div><div>

=C2=A0</div><blockquote class=3D"gmail_quote" style=3D"margin:0px 0px 0px 0=
.8ex;border-left-width:1px;border-left-color:rgb(204,204,204);border-left-s=
tyle:solid;padding-left:1ex"><div bgcolor=3D"#FFFFFF" text=3D"#000000"><div=
>
    <blockquote type=3D"cite">
      <div dir=3D"ltr">
        <div style=3D"color:rgb(0,0,153)"><span>
            <p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-=
bottom:0pt;text-align:justify"><span style=3D"font-size:15px;font-family:Ar=
ial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap;backgroun=
d-color:transparent">
              </span></p>
            <p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-=
bottom:0pt;text-align:justify"><span style=3D"font-size:15px;font-family:Ar=
ial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap;backgroun=
d-color:transparent"><br>




              </span></p>
            <p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-=
bottom:0pt;text-align:justify"><span style=3D"font-size:15px;font-family:Ar=
ial;color:rgb(0,0,0);font-weight:bold;vertical-align:baseline;white-space:p=
re-wrap;background-color:transparent">Issue
                #5 =E2=80=93 KMP</span></p>
            <p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-=
bottom:0pt;text-align:justify"><span style=3D"font-size:15px;font-family:Ar=
ial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap;backgroun=
d-color:transparent">
              </span></p>
            <p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-=
bottom:0pt;text-align:justify"><span style=3D"font-size:15px;font-family:Ar=
ial;color:rgb(255,0,0);vertical-align:baseline;white-space:pre-wrap;backgro=
und-color:transparent">[Michael
                R. @ Wed, May 14, 2014]: My understanding is that 6.3
                describes a way to get fresh per-cluster keying. It
                appears that this is done over a layer-2 protocol. =C2=A0Wh=
y
                not MLE?</span></p>
            <p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-=
bottom:0pt;text-align:justify"><span style=3D"font-size:15px;font-family:Ar=
ial;color:rgb(255,0,0);vertical-align:baseline;white-space:pre-wrap;backgro=
und-color:transparent">
              </span></p>
            <p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-=
bottom:0pt;text-align:justify"><span style=3D"font-size:15px;font-family:Ar=
ial;color:rgb(255,0,0);vertical-align:baseline;white-space:pre-wrap;backgro=
und-color:transparent">[Rene
                S @ Tue, May 20, 2014]: the draft introduces new
                802.15.4-command frames to implement the key negotiation
                phase (Section 6.3). As such, this would constitute a
                change to the 802.15.4-2011 and 802.15.4e-2012
                specification. Besides, this also implies that the key
                negotiation phase can only deal with one-hop behavior.</spa=
n></p>
            <p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-=
bottom:0pt;text-align:justify"><span style=3D"font-size:15px;font-family:Ar=
ial;color:rgb(255,0,0);vertical-align:baseline;white-space:pre-wrap;backgro=
und-color:transparent">
                =C2=A0</span></p>
            <p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-=
bottom:0pt;text-align:justify"><span style=3D"font-size:15px;font-family:Ar=
ial;color:rgb(255,0,0);vertical-align:baseline;white-space:pre-wrap;backgro=
und-color:transparent">[Rene
                S @ Tue, May 20, 2014]: the key negotiation phase using
                the anonymous Diffie-Hellman scheme (Section 6.3.3) that
                uses ordinary Diffie-Hellman groups in the ring of
                integers Zp, where p is a prime number that indexed by a
                publicly computable integer (Section 6.3.1, Step c1))
                and where p has at least bit-size 128 (see Appendix
                A.1). The ordinary Diffie-Hellman problem in integer
                rings Zp of this order of magnitude sizes is efficiently
                computable, thereby rendering this scheme completely
                insecure</span></p>
            <p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-=
bottom:0pt;text-align:justify"><span style=3D"font-size:15px;font-family:Ar=
ial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap;backgroun=
d-color:transparent">
              </span></p>
            <p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-=
bottom:0pt;text-align:justify"><span style=3D"font-size:15px;font-family:Ar=
ial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap;backgroun=
d-color:transparent">
              </span></p>
            <p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-=
bottom:0pt;text-align:justify"><span style=3D"font-size:15px;font-family:Ar=
ial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap;backgroun=
d-color:transparent">The
                negotiation of the layer-2 key will be handled by MLE by
                using new Information Elements (we have already designed
                the new approach). =C2=A0Hence, the next version of the dra=
ft
                will propose a KMP protocol fully based on the adoption
                of IEEE 802.15.4e IEs.</span></p>
          </span></div>
      </div>
    </blockquote></div>
    RS&gt;&gt;<br>
    The outcome of the join protocol should include a shared (link) key
    between the joining node and its neighbor or network manager, which
    will end up in the MAC PIB table, including associated keying
    related information. This join protocol should also deal with frame
    counter initialization and updates and resolving this with the ASN
    entry. I do not think it would necessarily be a good idea to treat
    join protocol messages as anything different from MAC data frames
    (i.e., it is higher layer traffic). This holds the more so, since
    join protocol will include some flows with the network manager, who
    may be multiple hops away (and MAC has no knowledge about anything
    more than one hop).<br>
    &lt;&lt;RS=C2=A0<span style=3D"color:rgb(0,0,0);font-family:Arial;font-=
size:15px;white-space:pre-wrap;line-height:1.15;text-align:justify;backgrou=
nd-color:transparent">              </span></div></blockquote><blockquote c=
lass=3D"gmail_quote" style=3D"margin:0px 0px 0px 0.8ex;border-left-width:1p=
x;border-left-color:rgb(204,204,204);border-left-style:solid;padding-left:1=
ex">

<div bgcolor=3D"#FFFFFF" text=3D"#000000"><div><blockquote type=3D"cite"><d=
iv dir=3D"ltr"><div style=3D"color:rgb(0,0,153)"><span>
            <p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-=
bottom:0pt;text-align:justify"><span style=3D"font-size:15px;font-family:Ar=
ial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap;backgroun=
d-color:transparent">In
                the upgraded version of the draft, the KMP protocol will
                be handled by using certified DH and Station-to-station
                protocol. No restrictions on the key of the
                public/private key will be considered. As a consequence,
                security issues related to the ordinary Diffie-Hellman
                problem in integer rings Zp will be no more present.</span>=
</p>
          </span></div>
      </div>
    </blockquote></div>
    RS&gt;&gt;<br>
    Ordinary Diffie-Hellman groups defined over the ring of integers mod
    p (when implemented at the right security level) will be
    prohibitively expensive on constrained devices. The only viabl
    option here would be to use elliptic curve based Diffie-Hellman
    groups.<br>
    &lt;&lt;RS</div></blockquote><div><div class=3D"gmail_default" style=3D=
"color:rgb(0,0,153)"><br></div><div class=3D"gmail_default" style=3D"color:=
rgb(0,0,153)"><div class=3D"gmail_quote" style=3D"color:rgb(34,34,34)"><div=
><div class=3D"gmail_default" style=3D"color:rgb(0,0,153)">

=E2=80=8BGP&gt;&gt;=E2=80=8B</div></div><div class=3D"gmail_default" style=
=3D"color:rgb(0,0,153)">=E2=80=8BOK, thanks for the clarification. We will =
include into the draft a solution based on ECDH<br></div></div></div></div>=
<div><div class=3D"gmail_quote">

<div><div class=3D"gmail_default" style=3D"color:rgb(0,0,153)">=E2=80=8B&lt=
;&lt;GP=E2=80=8B<br></div></div></div></div><div><br></div><div>=C2=A0</div=
><blockquote class=3D"gmail_quote" style=3D"margin:0px 0px 0px 0.8ex;border=
-left-width:1px;border-left-color:rgb(204,204,204);border-left-style:solid;=
padding-left:1ex">

<div bgcolor=3D"#FFFFFF" text=3D"#000000"><div>
    <blockquote type=3D"cite">
      <div dir=3D"ltr">
        <div style=3D"color:rgb(0,0,153)"><span>
            <p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-=
bottom:0pt;text-align:justify"><span style=3D"font-size:15px;font-family:Ar=
ial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap;backgroun=
d-color:transparent">
              </span></p>
            <p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-=
bottom:0pt;text-align:justify"><span style=3D"font-size:15px;font-family:Ar=
ial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap;backgroun=
d-color:transparent">
              </span></p>
            <p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-=
bottom:0pt;text-align:justify"><span style=3D"font-size:15px;font-family:Ar=
ial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap;backgroun=
d-color:transparent">
              </span></p>
            <p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-=
bottom:0pt;text-align:justify"><span style=3D"font-size:15px;font-family:Ar=
ial;color:rgb(0,0,0);font-weight:bold;vertical-align:baseline;white-space:p=
re-wrap;background-color:transparent">Issue
                #6 - Authorization step</span></p>
            <p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-=
bottom:0pt;text-align:justify"><span style=3D"font-size:15px;font-family:Ar=
ial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap;backgroun=
d-color:transparent">
              </span></p>
            <p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-=
bottom:0pt;text-align:justify"><span style=3D"font-size:15px;font-family:Ar=
ial;color:rgb(255,0,0);vertical-align:baseline;white-space:pre-wrap;backgro=
und-color:transparent">[Rene
                S @ Tue, May 20, 2014] the key negotiation protocol
                deals with authenticated key agreement and does not
                consider potential authorization steps.</span></p>
            <p dir=3D"ltr" style=3D"line-height:1.15;margin-top:0pt;margin-=
bottom:0pt;text-align:justify"><span style=3D"font-size:15px;font-family:Ar=
ial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap;backgroun=
d-color:transparent">
              </span></p>
            <span style=3D"font-size:15px;font-family:Arial;color:rgb(0,0,0=
);vertical-align:baseline;white-space:pre-wrap;background-color:transparent=
">Should
              authorization be performed by higher layers during the
              join procedure (see Issue #2) ? If so, KMP could still
              ignore this aspect.</span></span><br clear=3D"all">
        </div>
        <div style=3D"color:rgb(0,0,153)"><span><span style=3D"font-size:15=
px;font-family:Arial;color:rgb(0,0,0);vertical-align:baseline;white-space:p=
re-wrap;background-color:transparent"><br>
            </span></span></div>
        <div style=3D"color:rgb(0,0,153)"><span><span style=3D"font-size:15=
px;font-family:Arial;color:rgb(0,0,0);vertical-align:baseline;white-space:p=
re-wrap;background-color:transparent"><br>
            </span></span></div>
      </div>
    </blockquote></div>
    RS&gt;&gt;<br>
    An authenticated key agreement scheme can ignore authorization
    steps; a join protocol, which includes both key agreement,
    authorization, and configuration steps cannot.<br>
    &lt;&lt;RS</div></blockquote><div><br></div><div><div class=3D"gmail_de=
fault" style=3D"color:rgb(0,0,153)">=E2=80=8BGP&gt;&gt;=E2=80=8B</div></div=
><div class=3D"gmail_default" style=3D"color:rgb(0,0,153)">=E2=80=8BOK, I a=
gree</div><div class=3D"gmail_default" style=3D"color:rgb(0,0,153)">

</div></div><div><div class=3D"gmail_default" style=3D"color:rgb(0,0,153)">=
=E2=80=8B&lt;&lt;GP=E2=80=8B<br clear=3D"all"><div><br></div>-- <br><div di=
r=3D"ltr"><font style=3D"background-color:rgb(255,255,255)" color=3D"#00009=
9"><b>Giuseppe Piro, PhD</b><br>

Post Doc Researcher<br>DEI, Politecnico di Bari<br>via Orabona 4 - 70125 (B=
ari), Italy.<br>email: <a href=3D"mailto:peppe@giuseppepiro.com" target=3D"=
_blank">peppe@giuseppepiro.com</a></font><div><font style=3D"background-col=
or:rgb(255,255,255)" color=3D"#000099">phone: +39 080 5963301<br>

web: <a href=3D"http://telematics.poliba.it/piro" target=3D"_blank">g</a><a=
 href=3D"http://iuseppepiro.com" target=3D"_blank">iuseppepiro.com</a></fon=
t></div></div>
</div></div>
</div></div>

--047d7b47283227eeba04fa20d9d1--


From nobody Mon May 26 11:03:19 2014
Return-Path: <rstruik.ext@gmail.com>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 7F26C1A01EE; Mon, 26 May 2014 11:03:16 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2
X-Spam-Level: 
X-Spam-Status: No, score=-2 tagged_above=-999 required=5 tests=[BAYES_00=-1.9,  DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id NADYZQBxm1OW; Mon, 26 May 2014 11:03:15 -0700 (PDT)
Received: from mail-ig0-x22c.google.com (mail-ig0-x22c.google.com [IPv6:2607:f8b0:4001:c05::22c]) (using TLSv1 with cipher ECDHE-RSA-RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id F415B1A0204; Mon, 26 May 2014 11:03:14 -0700 (PDT)
Received: by mail-ig0-f172.google.com with SMTP id uy17so216479igb.17 for <multiple recipients>; Mon, 26 May 2014 11:03:11 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113;  h=message-id:date:from:user-agent:mime-version:to:cc:subject :references:in-reply-to:content-type:content-transfer-encoding; bh=CwoF5lRpEUb308MY+Tonfk5e/AD7LvN19tWcNK6QjS4=; b=cGIufShjaPQzgWd3o3Tu0hX8lGSvfgOsN/So9bY5XVYeiBFd+83urqPCI8Oyo7znfM Fx1bFG83YwIG4MlH0eH1k8El5qUVoemyEWedC2TP2W8RwoD+ObsVggsAndgiNxjPaAUF S7bJPtbQ9OWmmrAQ4tlTeX/xpR7db7ln2cOw1DBInGhWiZ+cqMpZBWQp+fViVGkNYJ+F 4+0ZgqbEQT04TpZzkQB4jXXCTR6SmVQfU249fqo++geQGzIwZuUg/gAbUPcLJG25i8wV SpNhMZcFh7Ment/EKVI7O65V6iHegB5mEqNUFlKsnKnbG1jCmonLG1bgjSAs14EXrhwv /D9Q==
X-Received: by 10.50.43.201 with SMTP id y9mr27703285igl.12.1401127391885; Mon, 26 May 2014 11:03:11 -0700 (PDT)
Received: from [192.168.1.101] (CPE0013100e2c51-CM001cea35caa6.cpe.net.cable.rogers.com. [99.231.3.110]) by mx.google.com with ESMTPSA id fk7sm1435052igb.9.2014.05.26.11.03.11 for <multiple recipients> (version=TLSv1 cipher=ECDHE-RSA-RC4-SHA bits=128/128); Mon, 26 May 2014 11:03:11 -0700 (PDT)
Message-ID: <538381DE.9060701@gmail.com>
Date: Mon, 26 May 2014 14:03:10 -0400
From: Rene Struik <rstruik.ext@gmail.com>
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:24.0) Gecko/20100101 Thunderbird/24.5.0
MIME-Version: 1.0
To: "Pascal Thubert (pthubert)" <pthubert@cisco.com>,  tisch-security <6tisch-security@ietf.org>
References: <E045AECD98228444A58C61C200AE1BD8426AE562@xmb-rcd-x01.cisco.com> <53837F7D.8080603@gmail.com>
In-Reply-To: <53837F7D.8080603@gmail.com>
Content-Type: text/plain; charset=ISO-8859-1; format=flowed
Content-Transfer-Encoding: 7bit
Archived-At: http://mailarchive.ietf.org/arch/msg/6tisch-security/yglvIsaaUGe2aqfz8h9jgcDU2AU
Cc: "6tisch@ietf.org" <6tisch@ietf.org>
Subject: Re: [6tisch-security] [6tisch] draft-piro-6tisch-security-issues vs. draft-ietf-6tisch-tsch
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 26 May 2014 18:03:16 -0000

[now also sent to 6TiSCH security mailing list]

On 5/26/2014 1:53 PM, Rene Struik wrote:
> Hi Pascal:
>
> I did review this draft Tue last week (May 20, 2014), after the 6tisch 
> security conf call, when Michael Richardson suggested to give this a 
> look. {Please see 
> http://www.ietf.org/mail-archive/web/6tisch-security/current/msg00091.html} 
> for brief review. Based on this review, I cannot really support the 
> current draft (and esp. Section 6).
>
> I would expect the authors to weigh-in on 6tisch security discussions 
> during the conf call created for this specific purpose. As such, I am 
> surprised that this has been brought up outside the specifically 
> created vehicle for security-specific discussions.
>
> Best regards, Rene
>
> On 5/26/2014 12:20 PM, Pascal Thubert (pthubert) wrote:
>> Dear all,
>>
>> During the last biweekly, Michael attracted out attention on the fact 
>> that  draft-piro (section 6) contains a lot of good information on 
>> the way a standard 802.15.4 network is bootstrapped. This information 
>> is descriptive of other standards as opposed to a standard of its 
>> own, and it appears that it would fit well within pir WG dioc 
>> draft-ietf-6tisch-tsch.
>>
>> What do you think?
>>
>> Pascal
>>
>> _______________________________________________
>> 6tisch mailing list
>> 6tisch@ietf.org
>> https://www.ietf.org/mailman/listinfo/6tisch
>
>


-- 
email: rstruik.ext@gmail.com | Skype: rstruik
cell: +1 (647) 867-5658 | US: +1 (415) 690-7363


From nobody Mon May 26 19:46:58 2014
Return-Path: <mcr@sandelman.ca>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 98BCD1A031B for <6tisch-security@ietfa.amsl.com>; Mon, 26 May 2014 19:46:55 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.542
X-Spam-Level: 
X-Spam-Status: No, score=-2.542 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RP_MATCHES_RCVD=-0.651, SPF_PASS=-0.001, T_TVD_MIME_NO_HEADERS=0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id FPPnbuCdgUSx for <6tisch-security@ietfa.amsl.com>; Mon, 26 May 2014 19:46:53 -0700 (PDT)
Received: from tuna.sandelman.ca (tuna.sandelman.ca [IPv6:2607:f0b0:f:3::184]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 9FCC31A02F8 for <6tisch-security@ietf.org>; Mon, 26 May 2014 19:46:52 -0700 (PDT)
Received: from sandelman.ca (obiwan.sandelman.ca [IPv6:2607:f0b0:f:2::247]) by tuna.sandelman.ca (Postfix) with ESMTP id E9CC72002B; Mon, 26 May 2014 22:49:29 -0400 (EDT)
Received: by sandelman.ca (Postfix, from userid 179) id 4643163B0F; Mon, 26 May 2014 22:46:44 -0400 (EDT)
Received: from sandelman.ca (localhost [127.0.0.1]) by sandelman.ca (Postfix) with ESMTP id 2F81963AB6; Mon, 26 May 2014 22:46:44 -0400 (EDT)
From: Michael Richardson <mcr+ietf@sandelman.ca>
to: tisch-security <6tisch-security@ietf.org>
In-Reply-To: <7591.1399145520@sandelman.ca>
References: <7591.1399145520@sandelman.ca>
X-Mailer: MH-E 8.2; nmh 1.3-dev; GNU Emacs 23.4.1
X-Face: $\n1pF)h^`}$H>Hk{L"x@)JS7<%Az}5RyS@k9X%29-lHB$Ti.V>2bi.~ehC0; <'$9xN5Ub# z!G,p`nR&p7Fz@^UXIn156S8.~^@MJ*mMsD7=QFeq%AL4m<nPbLgmtKK-5dC@#:k
MIME-Version: 1.0
Content-Type: multipart/signed; boundary="=-=-="; micalg=pgp-sha1; protocol="application/pgp-signature"
Date: Mon, 26 May 2014 22:46:44 -0400
Message-ID: <4097.1401158804@sandelman.ca>
Sender: mcr@sandelman.ca
Archived-At: http://mailarchive.ietf.org/arch/msg/6tisch-security/a3wd5qe8wHCvFlWTrb_bofmnF0E
Cc: max pritikin <pritikin@cisco.com>, rgm@htt-consult.com, Michael Behringer <mbehring@cisco.com>
Subject: [6tisch-security] using ARO and DTLS/CoAP for autonomic bootstrap
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 27 May 2014 02:46:55 -0000

--=-=-=


This is a change to the time sequence diagram that I posted a few weeks ago,
this time looking at the details if the secure connection is initiated from
the Authorization Server/Domain Owner (PCE).  This is the more about the
"WirelessHART" way, because it uses the same application layer protocol to
do the security as the application uses.  There is also some consistency with
the ideas in the OSCAR paper.

The interesting thing about doing it this way is that it changes which
end is the client and which is the server, and this may have significant
advantages from a TLS point of view.

The process would be initiated by the NewEntity sending an ND ARO.
There is a new document posted since I started writing this email:
  https://datatracker.ietf.org/doc/draft-sarikaya-ace-cga-nd/

which is rather useful, because if Behcet hadn't written that, I'd have to.
(Noting that Hosnieh Rafiee has some concerns about CGA, and also there have
been IPR issues with CGA, which I've never looked into myself).

If the LSEND ARO additionally contains the IDevID, ideally under LSEND
signature, then the Domain can consider if that IDevID belongs on the
network.  A DTLS session could be started using certificates
like have been described in previous messages, and a 6top control would
be used to update the L2 key, and/or set a MSK per the piro document.

The biggest challenge is figuring out whether end-to-end addressing and
routing is used to reach the new 6LN, or if a proxy/relay method is used
to some adjacent 6LN.    The EAP-TLS diagram implicitely had such a proxy
as PANA/1x goes from supplicant to neighbouring authenticator.

I also posted a really rough document:
    draft-richardson-6tisch-idevid-cert-00
which is cribbed directly from RFC3779.


   +---------+                +----------+                +-----------+
   |  New    |                |          |                |  Factory  |
   | Entity  |                |  Domain  |                |   Cloud   |
   |         |                |          |                |  Service  |
   +---------+                +----------+                +-----------+
       |                           |                            |
       |<-------RA-----------------|                            |
       |-------- LSEND ARO ------->|                            |
       |                           |---802.1AR identity( )----->|
       |                           |---Domain ID--------------->|
       |                           |                    [device belongs]
       |                           |                    [to domain?    ]
       |                           |                            |
       |                           |<---device history log( )---|
       |<-------- LSEND ARO -------|                            |
       |                           |------- claim device -( )-->|
       |                           |                  [update audit log]
       |                           |<----- authz token --( )----|
       |                           |      (802.1AR cert chain)  |
       |                           |                            |
       |                    [ accept device? ]                  |
       |<----DTLS ClientHello ( )--|                            |
       |-------ServerHello-( )---->|                            |
       |<----DTLS ClientCert  ( )--|                            |
       |  (IDevId Credential chain |                            |
       |-----DTLS ServerCert  ( )->|                            |
       |  (802.1AR certificate)    |                            |
       |                           |                            |
       |<----6top commands       --|                            |
       |                           |                            |

One advantage is that the Domain is control of which devices are enrolled,
and what rate.  New Entities that are waiting for their turn simply wind
up sending AROs to renew.
A second possible advantage is that the "clear" RAs could contain a different
ABRO than the secure RAs, so join traffic could go through the network in a
different way.

A downside is that the 6LR which advertises to the joining node need to deal
with what's going on; potentially the new node could be in a different
prefix, etc..

This process could also lead into EST, but it doesn't have to.
Or we could map the 802.1AR APIs into 6top API.

--
Michael Richardson <mcr+IETF@sandelman.ca>, Sandelman Software Works
 -= IPv6 IoT consulting =-




--=-=-=
Content-Type: application/pgp-signature

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iQEVAwUBU4P8k4CLcPvd0N1lAQKrWQf9Hmew9erWXE4NWzp/6f3bZFHf8+NWETX6
VjS/NjXoURx16OSy6VGf9RHungvFHIahzvfksaru7aVyhneE30RBIgJ4SxYYk/+l
NWJL84oCSUmqnjUMFRNs3pIWebyhyFLbgPS28sSIor0AhrNTbxRbmF+li7iV48mx
n3Mo3w8iRqRGpsxx8b/vQMRIvghBJmM+Oa6rs+n8su8/o02sQUbxR7iHSIfCQnMe
0CUFA1+jL5Kxya4ghYwWv06Q+dlEfkRnRIVF5UIdL8psHvqrHkvsCSeFGUkrK31L
WqMDEBsQb5EUAaLmiJcm9kBndC2e0Wbhm036S2y0Uxr3895rqZ3Dnw==
=7KM3
-----END PGP SIGNATURE-----
--=-=-=--


From nobody Mon May 26 19:50:10 2014
Return-Path: <mcr@sandelman.ca>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id C615D1A0322 for <6tisch-security@ietfa.amsl.com>; Mon, 26 May 2014 19:50:06 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.541
X-Spam-Level: 
X-Spam-Status: No, score=-2.541 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RP_MATCHES_RCVD=-0.651, SPF_PASS=-0.001, T_TVD_MIME_NO_HEADERS=0.01, WEIRD_PORT=0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id ivQS4pwkvDGQ for <6tisch-security@ietfa.amsl.com>; Mon, 26 May 2014 19:50:04 -0700 (PDT)
Received: from tuna.sandelman.ca (tuna.sandelman.ca [IPv6:2607:f0b0:f:3::184]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 53AA51A031B for <6tisch-security@ietf.org>; Mon, 26 May 2014 19:50:04 -0700 (PDT)
Received: from sandelman.ca (desk.marajade.sandelman.ca [209.87.252.247]) by tuna.sandelman.ca (Postfix) with ESMTP id B08D520028 for <6tisch-security@ietf.org>; Mon, 26 May 2014 22:52:42 -0400 (EDT)
Received: by sandelman.ca (Postfix, from userid 179) id C1BB863B0E; Mon, 26 May 2014 22:49:57 -0400 (EDT)
Received: from sandelman.ca (localhost [127.0.0.1]) by sandelman.ca (Postfix) with ESMTP id AC93F63AB6 for <6tisch-security@ietf.org>; Mon, 26 May 2014 22:49:57 -0400 (EDT)
From: Michael Richardson <mcr+ietf@sandelman.ca>
to: 6tisch-security@ietf.org
In-Reply-To: <19475.1400588783@sandelman.ca>
References: <E045AECD98228444A58C61C200AE1BD8416F3AF4@xmb-rcd-x01.cisco.com> <bomn1n01Q3zUFux01ompsd> <531DD632.2060009@cox.net> <531DDB20.5050600@gmail.com> <10925.1394631496@sandelman.ca> <532069C8.2050005@gmail.com> <23590.1394999032@sandelman.ca> <18106.1395625035@sandelman.ca> <19609.1396839403@sandelman.ca> <11557.1397444260@sandelman.ca> <28192.1398644294@sandelman.ca> <29064.1399255587@sandelman.ca> <19475.1400588783@sandelman.ca>
X-Mailer: MH-E 8.2; nmh 1.3-dev; GNU Emacs 23.4.1
X-Face: $\n1pF)h^`}$H>Hk{L"x@)JS7<%Az}5RyS@k9X%29-lHB$Ti.V>2bi.~ehC0; <'$9xN5Ub# z!G,p`nR&p7Fz@^UXIn156S8.~^@MJ*mMsD7=QFeq%AL4m<nPbLgmtKK-5dC@#:k
MIME-Version: 1.0
Content-Type: multipart/signed; boundary="=-=-="; micalg=pgp-sha1; protocol="application/pgp-signature"
Date: Mon, 26 May 2014 22:49:57 -0400
Message-ID: <4903.1401158997@sandelman.ca>
Sender: mcr@sandelman.ca
Archived-At: http://mailarchive.ietf.org/arch/msg/6tisch-security/wdnxd2at3PUjwhnPVX2D6Y6L0nA
Subject: [6tisch-security] agenda for 2014-05-27 6tisch security call
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 27 May 2014 02:50:06 -0000

--=-=-=


To remind, we moved the call from the 26th to the 27th at 10am EDT.
That's 90 minutes from this email.

1) notewell.
2) intros
3) recap of draft-piro-
4) wirelesshart -way --- how does the communication work?
5) how to summarize all of this to the working group
6) how to close this process up?

-- remember that the call is recorded, and the NoteWell applies.

-- The URL to access the webex, which will we use for audio only:
  https://cisco.webex.com/cisco/j.php?MTID=m2fe139bf876cea3ec62750cd580b7908

-- we will resume with the etherpad at:
   http://etherpad.tools.ietf.org:9000/p/notes-ietf-89-6tisch-security

I'm at +1 613 276-6809, IM: mcr@xmpp.credil.org or mcharlesr@gmail.com,
if you need more than that to get in, or are having difficulties.
Please make sure your audio works, and that you mute when not talking.

--
Michael Richardson <mcr+IETF@sandelman.ca>, Sandelman Software Works
 -= IPv6 IoT consulting =-




--=-=-=
Content-Type: application/pgp-signature

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iQEVAwUBU4P9VYCLcPvd0N1lAQJFjAgAwodF9Ou/KpWZPCIIs8psEfVWIp1EqCur
SUjYdhVALBh1zmt+WTLstZxdUYX0AVXFKrV1TNvatzjiIOh7Uk8g49MaXJ/eKCaJ
cjOXbOnA0YhGIlrBAVUdbCZLvyHRt7SV2Mq/u2fCW1Xlz/3CMAqHsLzhDk/k2ink
E/jKdCk/5xrysxirLMqusK3/hXGo6pRpERjarsbZSC+GkuQjXni78jo01z8kR4jA
68ZrxuoX9nC856d1llz8tXUfAzMM6h5T0DpZ2H0XXmWJ4qk2ZZLN+kuRcTqam3F/
2LJOI/kLnpYZyiEDyoSuLeh1PBDowHT1ltvswJ8Q8yb6hXPzNN6Wkw==
=LsCq
-----END PGP SIGNATURE-----
--=-=-=--


From nobody Mon May 26 20:10:05 2014
Return-Path: <rstruik.ext@gmail.com>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id C6A9A1A0341 for <6tisch-security@ietfa.amsl.com>; Mon, 26 May 2014 20:10:03 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -0.998
X-Spam-Level: 
X-Spam-Status: No, score=-0.998 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, FREEMAIL_REPLY=1, HTML_MESSAGE=0.001, SPF_PASS=-0.001, WEIRD_PORT=0.001] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id qU2TQgwhHPoH for <6tisch-security@ietfa.amsl.com>; Mon, 26 May 2014 20:10:02 -0700 (PDT)
Received: from mail-ig0-x22b.google.com (mail-ig0-x22b.google.com [IPv6:2607:f8b0:4001:c05::22b]) (using TLSv1 with cipher ECDHE-RSA-RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 68D891A0343 for <6tisch-security@ietf.org>; Mon, 26 May 2014 20:10:02 -0700 (PDT)
Received: by mail-ig0-f171.google.com with SMTP id c1so585614igq.4 for <6tisch-security@ietf.org>; Mon, 26 May 2014 20:09:59 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113;  h=message-id:date:from:user-agent:mime-version:to:subject:references :in-reply-to:content-type; bh=qSIu3G2mLwiehqPGQJYt3vgbfs5N30kfFZooKS2xj8s=; b=AbFcQ6VkvPPppmPGlfxIElFbMRL5d1Ni0ClFQ9nUH0fBz6sKtyUGkXfKQQgBdU1U5y fzHn7E1uuhJ4u9K1FhVp1uIN2fgVFf3qCju0QY3MvmS414a13VXG2CmJ1+ufUBpfUmbQ agdcEmVyUKabnLuM9ae9uQ43s2s+e7wNUEo6PEZHWkXm8Q4WslC9QpfpSglapYpaiOAJ PnshxvFfJMu29Zfb5l3AAZ1zdYwVrr8ZPunEP3aovBcY3OMXBUz/E3T0P7vo5tbBuCBh niT6Tq6aJaAC8AHxeOg0YdzwH809eLR926S5pw1/2HYZtOWEKImC7SmMmjg4jexGIzQx BzjQ==
X-Received: by 10.50.143.34 with SMTP id sb2mr29953983igb.11.1401160199082; Mon, 26 May 2014 20:09:59 -0700 (PDT)
Received: from [192.168.1.101] (CPE0013100e2c51-CM001cea35caa6.cpe.net.cable.rogers.com. [99.231.3.110]) by mx.google.com with ESMTPSA id lr6sm4489185igb.15.2014.05.26.20.09.58 for <multiple recipients> (version=TLSv1 cipher=ECDHE-RSA-RC4-SHA bits=128/128); Mon, 26 May 2014 20:09:58 -0700 (PDT)
Message-ID: <53840205.2070103@gmail.com>
Date: Mon, 26 May 2014 23:09:57 -0400
From: Rene Struik <rstruik.ext@gmail.com>
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:24.0) Gecko/20100101 Thunderbird/24.5.0
MIME-Version: 1.0
To: Michael Richardson <mcr+ietf@sandelman.ca>, 6tisch-security@ietf.org
References: <E045AECD98228444A58C61C200AE1BD8416F3AF4@xmb-rcd-x01.cisco.com> <bomn1n01Q3zUFux01ompsd> <531DD632.2060009@cox.net> <531DDB20.5050600@gmail.com> <10925.1394631496@sandelman.ca> <532069C8.2050005@gmail.com> <23590.1394999032@sandelman.ca> <18106.1395625035@sandelman.ca> <19609.1396839403@sandelman.ca> <11557.1397444260@sandelman.ca> <28192.1398644294@sandelman.ca> <29064.1399255587@sandelman.ca> <19475.1400588783@sandelman.ca> <4903.1401158997@sandelman.ca>
In-Reply-To: <4903.1401158997@sandelman.ca>
Content-Type: multipart/alternative; boundary="------------040902080601030509020203"
Archived-At: http://mailarchive.ietf.org/arch/msg/6tisch-security/gc38Sv9QE7l9qTKyuWLLiZidIh4
Subject: Re: [6tisch-security] agenda for 2014-05-27 6tisch security call
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 27 May 2014 03:10:03 -0000

This is a multi-part message in MIME format.
--------------040902080601030509020203
Content-Type: text/plain; charset=ISO-8859-1; format=flowed
Content-Transfer-Encoding: 7bit

Hi Michael:

I would like to discuss the outstanding issues I summarized in my email 
of Tue last week, May 20, 2014, 9:45am EDT (see 
http://www.ietf.org/mail-archive/web/6tisch-security/current/msg00086.html). 
This was also one of the action items at the conclusion of last week's 
6TiSCH security call.

FYI - the w/HART communication flows were discussed during the 6TiSCH 
security conf call the week before, on Mon May 12, 2014. If one wishes 
to go over this again, that is fine, but I would prefer us giving 
preference to taking on already articulated issues (which were assigned 
as homework assignment to reflect upon) first (i.e., prior to item #4 of 
the proposed agenda).

As another agenda point, I would like us to discuss the frequency of 
future calls (as part of EOB).

Best regards, Rene


On 5/26/2014 10:49 PM, Michael Richardson wrote:
> To remind, we moved the call from the 26th to the 27th at 10am EDT.
> That's 90 minutes from this email.
>
> 1) notewell.
> 2) intros
> 3) recap of draft-piro-
> 4) wirelesshart -way --- how does the communication work?
> 5) how to summarize all of this to the working group
> 6) how to close this process up?
>
> -- remember that the call is recorded, and the NoteWell applies.
>
> -- The URL to access the webex, which will we use for audio only:
>    https://cisco.webex.com/cisco/j.php?MTID=m2fe139bf876cea3ec62750cd580b7908
>
> -- we will resume with the etherpad at:
>     http://etherpad.tools.ietf.org:9000/p/notes-ietf-89-6tisch-security
>
> I'm at +1 613 276-6809, IM: mcr@xmpp.credil.org or mcharlesr@gmail.com,
> if you need more than that to get in, or are having difficulties.
> Please make sure your audio works, and that you mute when not talking.
>
> --
> Michael Richardson <mcr+IETF@sandelman.ca>, Sandelman Software Works
>   -= IPv6 IoT consulting =-
>
>
>
>
>
> _______________________________________________
> 6tisch-security mailing list
> 6tisch-security@ietf.org
> https://www.ietf.org/mailman/listinfo/6tisch-security


-- 
email: rstruik.ext@gmail.com | Skype: rstruik
cell: +1 (647) 867-5658 | US: +1 (415) 690-7363


--------------040902080601030509020203
Content-Type: text/html; charset=ISO-8859-1
Content-Transfer-Encoding: 7bit

<html>
  <head>
    <meta content="text/html; charset=ISO-8859-1"
      http-equiv="Content-Type">
  </head>
  <body bgcolor="#FFFFFF" text="#000000">
    <div class="moz-cite-prefix">Hi Michael:<br>
      <br>
      I would like to discuss the outstanding issues I summarized in my
      email of Tue last week, May 20, 2014, 9:45am EDT (see
      <a class="moz-txt-link-freetext" href="http://www.ietf.org/mail-archive/web/6tisch-security/current/msg00086.html">http://www.ietf.org/mail-archive/web/6tisch-security/current/msg00086.html</a>).
      This was also one of the action items at the conclusion of last
      week's 6TiSCH security call.<br>
      <br>
      FYI - the w/HART communication flows were discussed during the
      6TiSCH security conf call the week before, on Mon May 12, 2014. If
      one wishes to go over this again, that is fine, but I would prefer
      us giving preference to taking on already articulated issues
      (which were assigned as homework assignment to reflect upon) first
      (i.e., prior to item #4 of the proposed agenda).<br>
      <br>
      As another agenda point, I would like us to discuss the frequency
      of future calls (as part of EOB).<br>
      <br>
      Best regards, Rene<br>
      <br>
      <br>
      On 5/26/2014 10:49 PM, Michael Richardson wrote:<br>
    </div>
    <blockquote cite="mid:4903.1401158997@sandelman.ca" type="cite">
      <pre wrap="">
To remind, we moved the call from the 26th to the 27th at 10am EDT.
That's 90 minutes from this email.

1) notewell.
2) intros
3) recap of draft-piro-
4) wirelesshart -way --- how does the communication work?
5) how to summarize all of this to the working group
6) how to close this process up?

-- remember that the call is recorded, and the NoteWell applies.

-- The URL to access the webex, which will we use for audio only:
  <a class="moz-txt-link-freetext" href="https://cisco.webex.com/cisco/j.php?MTID=m2fe139bf876cea3ec62750cd580b7908">https://cisco.webex.com/cisco/j.php?MTID=m2fe139bf876cea3ec62750cd580b7908</a>

-- we will resume with the etherpad at:
   <a class="moz-txt-link-freetext" href="http://etherpad.tools.ietf.org:9000/p/notes-ietf-89-6tisch-security">http://etherpad.tools.ietf.org:9000/p/notes-ietf-89-6tisch-security</a>

I'm at +1 613 276-6809, IM: <a class="moz-txt-link-abbreviated" href="mailto:mcr@xmpp.credil.org">mcr@xmpp.credil.org</a> or <a class="moz-txt-link-abbreviated" href="mailto:mcharlesr@gmail.com">mcharlesr@gmail.com</a>,
if you need more than that to get in, or are having difficulties.
Please make sure your audio works, and that you mute when not talking.

--
Michael Richardson <a class="moz-txt-link-rfc2396E" href="mailto:mcr+IETF@sandelman.ca">&lt;mcr+IETF@sandelman.ca&gt;</a>, Sandelman Software Works
 -= IPv6 IoT consulting =-



</pre>
      <br>
      <fieldset class="mimeAttachmentHeader"></fieldset>
      <br>
      <pre wrap="">_______________________________________________
6tisch-security mailing list
<a class="moz-txt-link-abbreviated" href="mailto:6tisch-security@ietf.org">6tisch-security@ietf.org</a>
<a class="moz-txt-link-freetext" href="https://www.ietf.org/mailman/listinfo/6tisch-security">https://www.ietf.org/mailman/listinfo/6tisch-security</a>
</pre>
    </blockquote>
    <br>
    <br>
    <pre class="moz-signature" cols="72">-- 
email: <a class="moz-txt-link-abbreviated" href="mailto:rstruik.ext@gmail.com">rstruik.ext@gmail.com</a> | Skype: rstruik
cell: +1 (647) 867-5658 | US: +1 (415) 690-7363</pre>
  </body>
</html>

--------------040902080601030509020203--


From nobody Mon May 26 20:20:19 2014
Return-Path: <rstruik.ext@gmail.com>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 6F5121A0349 for <6tisch-security@ietfa.amsl.com>; Mon, 26 May 2014 20:20:18 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.998
X-Spam-Level: 
X-Spam-Status: No, score=-1.998 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, SPF_PASS=-0.001, WEIRD_PORT=0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id q2mXjJQwDJLg for <6tisch-security@ietfa.amsl.com>; Mon, 26 May 2014 20:20:16 -0700 (PDT)
Received: from mail-ig0-x22e.google.com (mail-ig0-x22e.google.com [IPv6:2607:f8b0:4001:c05::22e]) (using TLSv1 with cipher ECDHE-RSA-RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id A868C1A0348 for <6tisch-security@ietf.org>; Mon, 26 May 2014 20:20:16 -0700 (PDT)
Received: by mail-ig0-f174.google.com with SMTP id h3so589241igd.13 for <6tisch-security@ietf.org>; Mon, 26 May 2014 20:20:13 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113;  h=message-id:date:from:user-agent:mime-version:to:subject:references :in-reply-to:content-type; bh=l2mCRuHyTC8z8Bb31tcAKGqgFwTKvsS8B12Pq+TJE+8=; b=Kwyk6y+4OwS/njsviR1Lm+4tP45+QlszMWADTqPhItz3zyCs1CRPXdIN6X0CMt0+zM EJLjkp0Z/+RX5uUaQgLyYN7GQ9AJraJm+iShp872VCdEem0ZnxxSvDabAVgTV33hFc66 GHs3G3Yfd5g6u591KaDP5LFY6MWc8TE6u1gbS+2rdgtBaid46HS6b7JQw0bpoffCnhN/ G7GCxy+ayUpjUnIshnOt3Elq0KuIW3aSBQLwpXHNVayhSOTnYje5WDj15dJ+G0i6DpsB xJo62nzITUaqc9P0qhemp4pWbAnnlsasUmDuRHkEYzWLKq4Z78FbyfcrPNWTuJTVwL+K rW8g==
X-Received: by 10.42.191.202 with SMTP id dn10mr27035089icb.14.1401160812255;  Mon, 26 May 2014 20:20:12 -0700 (PDT)
Received: from [192.168.1.101] (CPE0013100e2c51-CM001cea35caa6.cpe.net.cable.rogers.com. [99.231.3.110]) by mx.google.com with ESMTPSA id m1sm4542786ige.22.2014.05.26.20.20.11 for <multiple recipients> (version=TLSv1 cipher=ECDHE-RSA-RC4-SHA bits=128/128); Mon, 26 May 2014 20:20:11 -0700 (PDT)
Message-ID: <5384046A.6080706@gmail.com>
Date: Mon, 26 May 2014 23:20:10 -0400
From: Rene Struik <rstruik.ext@gmail.com>
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:24.0) Gecko/20100101 Thunderbird/24.5.0
MIME-Version: 1.0
To: Michael Richardson <mcr+ietf@sandelman.ca>, 6tisch-security@ietf.org
References: <E045AECD98228444A58C61C200AE1BD8416F3AF4@xmb-rcd-x01.cisco.com> <bomn1n01Q3zUFux01ompsd> <531DD632.2060009@cox.net> <531DDB20.5050600@gmail.com> <10925.1394631496@sandelman.ca> <532069C8.2050005@gmail.com> <23590.1394999032@sandelman.ca> <18106.1395625035@sandelman.ca> <19609.1396839403@sandelman.ca> <11557.1397444260@sandelman.ca> <28192.1398644294@sandelman.ca> <29064.1399255587@sandelman.ca> <19475.1400588783@sandelman.ca> <4903.1401158997@sandelman.ca> <53840205.2070103@gmail.com>
In-Reply-To: <53840205.2070103@gmail.com>
Content-Type: multipart/alternative; boundary="------------060701090907050208060500"
Archived-At: http://mailarchive.ietf.org/arch/msg/6tisch-security/hRYB9VEim40BE9sgp3dRlF1NInc
Subject: Re: [6tisch-security] agenda for 2014-05-27 6tisch security call
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 27 May 2014 03:20:18 -0000

This is a multi-part message in MIME format.
--------------060701090907050208060500
Content-Type: text/plain; charset=ISO-8859-1; format=flowed
Content-Transfer-Encoding: 7bit

Dear colleagues:

I would like add one more topic to the mix: initialization and 
synchronization of ASN numbers. This relates to item c) "join process 
and impact on the network" of my outstanding topic last of Tue last week 
(referenced below).

Best regards, Rene

On 5/26/2014 11:09 PM, Rene Struik wrote:
> Hi Michael:
>
> I would like to discuss the outstanding issues I summarized in my 
> email of Tue last week, May 20, 2014, 9:45am EDT (see 
> http://www.ietf.org/mail-archive/web/6tisch-security/current/msg00086.html). 
> This was also one of the action items at the conclusion of last week's 
> 6TiSCH security call.
>
> FYI - the w/HART communication flows were discussed during the 6TiSCH 
> security conf call the week before, on Mon May 12, 2014. If one wishes 
> to go over this again, that is fine, but I would prefer us giving 
> preference to taking on already articulated issues (which were 
> assigned as homework assignment to reflect upon) first (i.e., prior to 
> item #4 of the proposed agenda).
>
> As another agenda point, I would like us to discuss the frequency of 
> future calls (as part of EOB).
>
> Best regards, Rene
>
>
> On 5/26/2014 10:49 PM, Michael Richardson wrote:
>> To remind, we moved the call from the 26th to the 27th at 10am EDT.
>> That's 90 minutes from this email.
>>
>> 1) notewell.
>> 2) intros
>> 3) recap of draft-piro-
>> 4) wirelesshart -way --- how does the communication work?
>> 5) how to summarize all of this to the working group
>> 6) how to close this process up?
>>
>> -- remember that the call is recorded, and the NoteWell applies.
>>
>> -- The URL to access the webex, which will we use for audio only:
>>    https://cisco.webex.com/cisco/j.php?MTID=m2fe139bf876cea3ec62750cd580b7908
>>
>> -- we will resume with the etherpad at:
>>     http://etherpad.tools.ietf.org:9000/p/notes-ietf-89-6tisch-security
>>
>> I'm at +1 613 276-6809, IM:mcr@xmpp.credil.org  ormcharlesr@gmail.com,
>> if you need more than that to get in, or are having difficulties.
>> Please make sure your audio works, and that you mute when not talking.
>>
>> --
>> Michael Richardson<mcr+IETF@sandelman.ca>, Sandelman Software Works
>>   -= IPv6 IoT consulting =-
>>
>>
>>
>>
>>
>> _______________________________________________
>> 6tisch-security mailing list
>> 6tisch-security@ietf.org
>> https://www.ietf.org/mailman/listinfo/6tisch-security
>
>
> -- 
> email:rstruik.ext@gmail.com  | Skype: rstruik
> cell: +1 (647) 867-5658 | US: +1 (415) 690-7363


-- 
email: rstruik.ext@gmail.com | Skype: rstruik
cell: +1 (647) 867-5658 | US: +1 (415) 690-7363


--------------060701090907050208060500
Content-Type: text/html; charset=ISO-8859-1
Content-Transfer-Encoding: 7bit

<html>
  <head>
    <meta content="text/html; charset=ISO-8859-1"
      http-equiv="Content-Type">
  </head>
  <body bgcolor="#FFFFFF" text="#000000">
    <div class="moz-cite-prefix">Dear colleagues:<br>
      <br>
      I would like add one more topic to the mix: initialization and
      synchronization of ASN numbers. This relates to item c) "join
      process and impact on the network" of my outstanding topic last of
      Tue last week (referenced below).<br>
      <br>
      Best regards, Rene<br>
      <br>
      On 5/26/2014 11:09 PM, Rene Struik wrote:<br>
    </div>
    <blockquote cite="mid:53840205.2070103@gmail.com" type="cite">
      <meta content="text/html; charset=ISO-8859-1"
        http-equiv="Content-Type">
      <div class="moz-cite-prefix">Hi Michael:<br>
        <br>
        I would like to discuss the outstanding issues I summarized in
        my email of Tue last week, May 20, 2014, 9:45am EDT (see <a
          moz-do-not-send="true" class="moz-txt-link-freetext"
href="http://www.ietf.org/mail-archive/web/6tisch-security/current/msg00086.html">http://www.ietf.org/mail-archive/web/6tisch-security/current/msg00086.html</a>).

        This was also one of the action items at the conclusion of last
        week's 6TiSCH security call.<br>
        <br>
        FYI - the w/HART communication flows were discussed during the
        6TiSCH security conf call the week before, on Mon May 12, 2014.
        If one wishes to go over this again, that is fine, but I would
        prefer us giving preference to taking on already articulated
        issues (which were assigned as homework assignment to reflect
        upon) first (i.e., prior to item #4 of the proposed agenda).<br>
        <br>
        As another agenda point, I would like us to discuss the
        frequency of future calls (as part of EOB).<br>
        <br>
        Best regards, Rene<br>
        <br>
        <br>
        On 5/26/2014 10:49 PM, Michael Richardson wrote:<br>
      </div>
      <blockquote cite="mid:4903.1401158997@sandelman.ca" type="cite">
        <pre wrap="">To remind, we moved the call from the 26th to the 27th at 10am EDT.
That's 90 minutes from this email.

1) notewell.
2) intros
3) recap of draft-piro-
4) wirelesshart -way --- how does the communication work?
5) how to summarize all of this to the working group
6) how to close this process up?

-- remember that the call is recorded, and the NoteWell applies.

-- The URL to access the webex, which will we use for audio only:
  <a moz-do-not-send="true" class="moz-txt-link-freetext" href="https://cisco.webex.com/cisco/j.php?MTID=m2fe139bf876cea3ec62750cd580b7908">https://cisco.webex.com/cisco/j.php?MTID=m2fe139bf876cea3ec62750cd580b7908</a>

-- we will resume with the etherpad at:
   <a moz-do-not-send="true" class="moz-txt-link-freetext" href="http://etherpad.tools.ietf.org:9000/p/notes-ietf-89-6tisch-security">http://etherpad.tools.ietf.org:9000/p/notes-ietf-89-6tisch-security</a>

I'm at +1 613 276-6809, IM: <a moz-do-not-send="true" class="moz-txt-link-abbreviated" href="mailto:mcr@xmpp.credil.org">mcr@xmpp.credil.org</a> or <a moz-do-not-send="true" class="moz-txt-link-abbreviated" href="mailto:mcharlesr@gmail.com">mcharlesr@gmail.com</a>,
if you need more than that to get in, or are having difficulties.
Please make sure your audio works, and that you mute when not talking.

--
Michael Richardson <a moz-do-not-send="true" class="moz-txt-link-rfc2396E" href="mailto:mcr+IETF@sandelman.ca">&lt;mcr+IETF@sandelman.ca&gt;</a>, Sandelman Software Works
 -= IPv6 IoT consulting =-



</pre>
        <br>
        <fieldset class="mimeAttachmentHeader"></fieldset>
        <br>
        <pre wrap="">_______________________________________________
6tisch-security mailing list
<a moz-do-not-send="true" class="moz-txt-link-abbreviated" href="mailto:6tisch-security@ietf.org">6tisch-security@ietf.org</a>
<a moz-do-not-send="true" class="moz-txt-link-freetext" href="https://www.ietf.org/mailman/listinfo/6tisch-security">https://www.ietf.org/mailman/listinfo/6tisch-security</a>
</pre>
      </blockquote>
      <br>
      <br>
      <pre class="moz-signature" cols="72">-- 
email: <a moz-do-not-send="true" class="moz-txt-link-abbreviated" href="mailto:rstruik.ext@gmail.com">rstruik.ext@gmail.com</a> | Skype: rstruik
cell: +1 (647) 867-5658 | US: +1 (415) 690-7363</pre>
    </blockquote>
    <br>
    <br>
    <pre class="moz-signature" cols="72">-- 
email: <a class="moz-txt-link-abbreviated" href="mailto:rstruik.ext@gmail.com">rstruik.ext@gmail.com</a> | Skype: rstruik
cell: +1 (647) 867-5658 | US: +1 (415) 690-7363</pre>
  </body>
</html>

--------------060701090907050208060500--


From nobody Mon May 26 20:34:09 2014
Return-Path: <rstruik.ext@gmail.com>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 493841A0356 for <6tisch-security@ietfa.amsl.com>; Mon, 26 May 2014 20:34:08 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2
X-Spam-Level: 
X-Spam-Status: No, score=-2 tagged_above=-999 required=5 tests=[BAYES_00=-1.9,  DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id ha2PLK4cPoFW for <6tisch-security@ietfa.amsl.com>; Mon, 26 May 2014 20:34:07 -0700 (PDT)
Received: from mail-ie0-x236.google.com (mail-ie0-x236.google.com [IPv6:2607:f8b0:4001:c03::236]) (using TLSv1 with cipher ECDHE-RSA-RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 40B141A0350 for <6tisch-security@ietf.org>; Mon, 26 May 2014 20:34:07 -0700 (PDT)
Received: by mail-ie0-f182.google.com with SMTP id x19so956308ier.27 for <6tisch-security@ietf.org>; Mon, 26 May 2014 20:34:04 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113;  h=message-id:date:from:user-agent:mime-version:to:subject :content-type:content-transfer-encoding; bh=U3ABuLOBgBXJJMhf000IXfqreeOm8K6JPB3GmRi3bWc=; b=cL8XKYOKqiwYJyJEyeiPw79/yWZftkXQ01F6I6puQT/l/dvA0sRDqc+l+8Nz/UBcb9 1bqkT1cOaBVGFAB4UfFxeJWoAtK7rekWE7O7qXzZdeooj7XOUu7gxxntn0hKioJEF9Pm IxkSX3wPZ612uaJYfN3rN8sKkT7ruj74+UiJVhD/NzZLYhVJJzJIOpa58vnA2ipntF2u cIIfOv4/EWSqIZezl3DH1a5r+GCqREnY+GrAkyiuyl7z8z4aJcftl2kVUJlKb2TMfXr8 PD1f4RhG2sK7Gple8HV2l181WAYilY2MRw3KlAIIMxpMQrOYZ1CpPag53K6xHEqshygU JRTw==
X-Received: by 10.50.138.72 with SMTP id qo8mr30085519igb.26.1401161643918; Mon, 26 May 2014 20:34:03 -0700 (PDT)
Received: from [192.168.1.101] (CPE0013100e2c51-CM001cea35caa6.cpe.net.cable.rogers.com. [99.231.3.110]) by mx.google.com with ESMTPSA id jh7sm4604007igb.22.2014.05.26.20.34.03 for <6tisch-security@ietf.org> (version=TLSv1 cipher=ECDHE-RSA-RC4-SHA bits=128/128); Mon, 26 May 2014 20:34:03 -0700 (PDT)
Message-ID: <538407AA.704@gmail.com>
Date: Mon, 26 May 2014 23:34:02 -0400
From: Rene Struik <rstruik.ext@gmail.com>
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:24.0) Gecko/20100101 Thunderbird/24.5.0
MIME-Version: 1.0
To: tisch-security <6tisch-security@ietf.org>
Content-Type: text/plain; charset=ISO-8859-1; format=flowed
Content-Transfer-Encoding: 7bit
Archived-At: http://mailarchive.ietf.org/arch/msg/6tisch-security/_sBvRE49zNeiLicxh89qwE29Py0
Subject: [6tisch-security] suggested brainstorm session 6TiSCH security around IETF-90 week in Toronto
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 27 May 2014 03:34:08 -0000

Dear colleagues:

Reflecting on the upcoming IETF-90 meeting in Toronto end of July, it 
may be a good idea to have a brainstorm-type side meeting either just 
prior to the meeting or at the end of the meeting. Since Toronto is my 
home town, I could inquire about facilities via some of my contacts. In 
theory, I could pull in some other security people, but - frankly - I 
think we do not need any (to be discussed).

Let us discuss this prior to people already making travel arrangements.

Note - there may be an ACE WG brainstorm in Toronto Fri prior to the 
IETF-90 meeting (I extended the same offer as above to the ACE 
not-yet-group). Not sure when 6TiSCH would meet, but we should work 
around potential ACE requirements/desiderata. I do expect we need room 
for roughly 15 people, which should come at very limited cost.

Best regards, Rene

-- 
email: rstruik.ext@gmail.com | Skype: rstruik
cell: +1 (647) 867-5658 | US: +1 (415) 690-7363


From nobody Mon May 26 23:50:23 2014
Return-Path: <pthubert@cisco.com>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 648DA1A03A1 for <6tisch-security@ietfa.amsl.com>; Mon, 26 May 2014 23:50:15 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -15.15
X-Spam-Level: 
X-Spam-Status: No, score=-15.15 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_HI=-5, RP_MATCHES_RCVD=-0.651, SPF_PASS=-0.001, USER_IN_DEF_DKIM_WL=-7.5, WEIRD_PORT=0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 9Gt8U_j2V6Js for <6tisch-security@ietfa.amsl.com>; Mon, 26 May 2014 23:50:11 -0700 (PDT)
Received: from rcdn-iport-7.cisco.com (rcdn-iport-7.cisco.com [173.37.86.78]) (using TLSv1 with cipher RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id C70341A03AE for <6tisch-security@ietf.org>; Mon, 26 May 2014 23:50:10 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cisco.com; i=@cisco.com; l=14653; q=dns/txt; s=iport; t=1401173408; x=1402383008; h=from:to:subject:date:message-id:references:in-reply-to: mime-version; bh=5Gio0HqkVWubLJywNQ4kGPXP+EmrigEjUOABQQq+d0c=; b=Oo7AADQhFg7inbU0V6HL+xpfvWRwiCS8CZl+ORGJBsXTvQg/XFY0K0k0 rk4sgR0BvqZ+mrY2eiaAZfqfQVjaFxk/FOX6he+RZUvTiJoXVM+QiBgt9 M2xcY9/UPHpyH0ei6IfQxTxfrldEm37rT343KQIWFLEUDsApZaiJehJ17 U=;
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-Anti-Spam-Result: AjYFAD00hFOtJA2G/2dsb2JhbAA/FwOCQkUfM1i5G4FCAYZoUQGBCxZ0giUBAQEEAQEBKkEbAgEIDgMEAQELHQchBgsUCQgCBAESCAGIJQMRDTbNKg2GGheLQwF4gTQQAgEeIQwKARGCI1MkgRUEiWeCVAKLQIMzi3iFcoM4bIFD
X-IronPort-AV: E=Sophos;i="4.98,917,1392163200";  d="scan'208,217";a="328118114"
Received: from alln-core-12.cisco.com ([173.36.13.134]) by rcdn-iport-7.cisco.com with ESMTP; 27 May 2014 06:50:06 +0000
Received: from xhc-rcd-x15.cisco.com (xhc-rcd-x15.cisco.com [173.37.183.89]) by alln-core-12.cisco.com (8.14.5/8.14.5) with ESMTP id s4R6o6TS023713 (version=TLSv1/SSLv3 cipher=AES128-SHA bits=128 verify=FAIL); Tue, 27 May 2014 06:50:06 GMT
Received: from xmb-rcd-x01.cisco.com ([169.254.1.203]) by xhc-rcd-x15.cisco.com ([173.37.183.89]) with mapi id 14.03.0123.003; Tue, 27 May 2014 01:50:06 -0500
From: "Pascal Thubert (pthubert)" <pthubert@cisco.com>
To: Rene Struik <rstruik.ext@gmail.com>, Michael Richardson <mcr+ietf@sandelman.ca>, "6tisch-security@ietf.org" <6tisch-security@ietf.org>
Thread-Topic: [6tisch-security] agenda for 2014-05-27 6tisch security call
Thread-Index: AQHPeVZg32OTIkXrJkabUw8SGOwfuZtUE2uAgAAC2wD//+NfMA==
Date: Tue, 27 May 2014 06:50:05 +0000
Deferred-Delivery: Tue, 27 May 2014 06:49:00 +0000
Message-ID: <E045AECD98228444A58C61C200AE1BD8426B036B@xmb-rcd-x01.cisco.com>
References: <E045AECD98228444A58C61C200AE1BD8416F3AF4@xmb-rcd-x01.cisco.com> <bomn1n01Q3zUFux01ompsd> <531DD632.2060009@cox.net> <531DDB20.5050600@gmail.com> <10925.1394631496@sandelman.ca> <532069C8.2050005@gmail.com> <23590.1394999032@sandelman.ca> <18106.1395625035@sandelman.ca> <19609.1396839403@sandelman.ca> <11557.1397444260@sandelman.ca> <28192.1398644294@sandelman.ca> <29064.1399255587@sandelman.ca> <19475.1400588783@sandelman.ca> <4903.1401158997@sandelman.ca> <53840205.2070103@gmail.com> <5384046A.6080706@gmail.com>
In-Reply-To: <5384046A.6080706@gmail.com>
Accept-Language: fr-FR, en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
x-originating-ip: [10.61.76.106]
Content-Type: multipart/alternative; boundary="_000_E045AECD98228444A58C61C200AE1BD8426B036Bxmbrcdx01ciscoc_"
MIME-Version: 1.0
Archived-At: http://mailarchive.ietf.org/arch/msg/6tisch-security/lDOw9deP_FKW_5WWV64F43x07wY
Subject: Re: [6tisch-security] agenda for 2014-05-27 6tisch security call
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 27 May 2014 06:50:15 -0000

--_000_E045AECD98228444A58C61C200AE1BD8426B036Bxmbrcdx01ciscoc_
Content-Type: text/plain; charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable

Hi Ren=E9:

I'm interested in following up with the ND ARO thread (ARO and DTLS/CoAP) t=
hat Michael just launched. If that's what the wireless HART discussion is a=
bout then I think we're not done yet with it.

Still I agree we need to report on the homework. Could you please propose a=
 list of specific items like the topic below and evaluate the time that is =
required at the call to present the issue and get initial feedback?

With this, we can work on spreading the time over the next calls.

I think we could have a wiki page on pending flows and issues on the repo o=
r the IETF site, and I can help with that if you like.

Many thanks for all this!

Pascal

From: 6tisch-security [mailto:6tisch-security-bounces@ietf.org] On Behalf O=
f Rene Struik
Sent: mardi 27 mai 2014 05:20
To: Michael Richardson; 6tisch-security@ietf.org
Subject: Re: [6tisch-security] agenda for 2014-05-27 6tisch security call

Dear colleagues:

I would like add one more topic to the mix: initialization and synchronizat=
ion of ASN numbers. This relates to item c) "join process and impact on the=
 network" of my outstanding topic last of Tue last week (referenced below).

Best regards, Rene

On 5/26/2014 11:09 PM, Rene Struik wrote:
Hi Michael:

I would like to discuss the outstanding issues I summarized in my email of =
Tue last week, May 20, 2014, 9:45am EDT (see http://www.ietf.org/mail-archi=
ve/web/6tisch-security/current/msg00086.html). This was also one of the act=
ion items at the conclusion of last week's 6TiSCH security call.

FYI - the w/HART communication flows were discussed during the 6TiSCH secur=
ity conf call the week before, on Mon May 12, 2014. If one wishes to go ove=
r this again, that is fine, but I would prefer us giving preference to taki=
ng on already articulated issues (which were assigned as homework assignmen=
t to reflect upon) first (i.e., prior to item #4 of the proposed agenda).

As another agenda point, I would like us to discuss the frequency of future=
 calls (as part of EOB).

Best regards, Rene


On 5/26/2014 10:49 PM, Michael Richardson wrote:

To remind, we moved the call from the 26th to the 27th at 10am EDT.

That's 90 minutes from this email.



1) notewell.

2) intros

3) recap of draft-piro-

4) wirelesshart -way --- how does the communication work?

5) how to summarize all of this to the working group

6) how to close this process up?



-- remember that the call is recorded, and the NoteWell applies.



-- The URL to access the webex, which will we use for audio only:

  https://cisco.webex.com/cisco/j.php?MTID=3Dm2fe139bf876cea3ec62750cd580b7=
908



-- we will resume with the etherpad at:

   http://etherpad.tools.ietf.org:9000/p/notes-ietf-89-6tisch-security



I'm at +1 613 276-6809, IM: mcr@xmpp.credil.org<mailto:mcr@xmpp.credil.org>=
 or mcharlesr@gmail.com<mailto:mcharlesr@gmail.com>,

if you need more than that to get in, or are having difficulties.

Please make sure your audio works, and that you mute when not talking.



--

Michael Richardson <mcr+IETF@sandelman.ca><mailto:mcr+IETF@sandelman.ca>, S=
andelman Software Works

 -=3D IPv6 IoT consulting =3D-










_______________________________________________

6tisch-security mailing list

6tisch-security@ietf.org<mailto:6tisch-security@ietf.org>

https://www.ietf.org/mailman/listinfo/6tisch-security




--

email: rstruik.ext@gmail.com<mailto:rstruik.ext@gmail.com> | Skype: rstruik

cell: +1 (647) 867-5658 | US: +1 (415) 690-7363




--

email: rstruik.ext@gmail.com<mailto:rstruik.ext@gmail.com> | Skype: rstruik

cell: +1 (647) 867-5658 | US: +1 (415) 690-7363

--_000_E045AECD98228444A58C61C200AE1BD8426B036Bxmbrcdx01ciscoc_
Content-Type: text/html; charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable

<html xmlns:v=3D"urn:schemas-microsoft-com:vml" xmlns:o=3D"urn:schemas-micr=
osoft-com:office:office" xmlns:w=3D"urn:schemas-microsoft-com:office:word" =
xmlns:m=3D"http://schemas.microsoft.com/office/2004/12/omml" xmlns=3D"http:=
//www.w3.org/TR/REC-html40">
<head>
<meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3Diso-8859-=
1">
<meta name=3D"Generator" content=3D"Microsoft Word 14 (filtered medium)">
<style><!--
/* Font Definitions */
@font-face
	{font-family:Calibri;
	panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
	{font-family:Tahoma;
	panose-1:2 11 6 4 3 5 4 4 2 4;}
@font-face
	{font-family:Consolas;
	panose-1:2 11 6 9 2 2 4 3 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
	{margin:0cm;
	margin-bottom:.0001pt;
	font-size:12.0pt;
	font-family:"Times New Roman","serif";
	color:black;}
a:link, span.MsoHyperlink
	{mso-style-priority:99;
	color:blue;
	text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
	{mso-style-priority:99;
	color:purple;
	text-decoration:underline;}
pre
	{mso-style-priority:99;
	mso-style-link:"HTML Preformatted Char";
	margin:0cm;
	margin-bottom:.0001pt;
	font-size:10.0pt;
	font-family:"Courier New","serif";
	color:black;}
span.HTMLPreformattedChar
	{mso-style-name:"HTML Preformatted Char";
	mso-style-priority:99;
	mso-style-link:"HTML Preformatted";
	font-family:Consolas;
	color:black;}
span.EmailStyle19
	{mso-style-type:personal-reply;
	font-family:"Calibri","sans-serif";
	color:#1F497D;}
.MsoChpDefault
	{mso-style-type:export-only;
	font-size:10.0pt;}
@page WordSection1
	{size:612.0pt 792.0pt;
	margin:70.85pt 70.85pt 70.85pt 70.85pt;}
div.WordSection1
	{page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext=3D"edit" spidmax=3D"1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext=3D"edit">
<o:idmap v:ext=3D"edit" data=3D"1" />
</o:shapelayout></xml><![endif]-->
</head>
<body bgcolor=3D"white" lang=3D"EN-US" link=3D"blue" vlink=3D"purple">
<div class=3D"WordSection1">
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;;color:#1F497D">Hi Ren=E9:<o:p></o:p></sp=
an></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;;color:#1F497D"><o:p>&nbsp;</o:p></span><=
/p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;;color:#1F497D">I&#8217;m interested in f=
ollowing up with the ND ARO thread (ARO and DTLS/CoAP) that Michael just la=
unched. If that&#8217;s what the wireless HART discussion is about then
 I think we&#8217;re not done yet with it.<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;;color:#1F497D"><o:p>&nbsp;</o:p></span><=
/p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;;color:#1F497D">Still I agree we need to =
report on the homework. Could you please propose a list of specific items l=
ike the topic below and evaluate the time that is required
 at the call to present the issue and get initial feedback?<o:p></o:p></spa=
n></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;;color:#1F497D"><o:p>&nbsp;</o:p></span><=
/p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;;color:#1F497D">With this, we can work on=
 spreading the time over the next calls.<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;;color:#1F497D"><o:p>&nbsp;</o:p></span><=
/p>
<div>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;;color:#1F497D">I think we could have a w=
iki page on pending flows and issues on the repo or the IETF site, and I ca=
n help with that if you like.<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;;color:#1F497D"><o:p>&nbsp;</o:p></span><=
/p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;;color:#1F497D">Many thanks for all this!=
<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;;color:#1F497D"><o:p>&nbsp;</o:p></span><=
/p>
<p class=3D"MsoNormal"><span lang=3D"FR" style=3D"font-size:11.0pt;font-fam=
ily:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:#1F497D">Pascal<o:p></=
o:p></span></p>
</div>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;;color:#1F497D"><o:p>&nbsp;</o:p></span><=
/p>
<div style=3D"border:none;border-left:solid blue 1.5pt;padding:0cm 0cm 0cm =
4.0pt">
<div>
<div style=3D"border:none;border-top:solid #B5C4DF 1.0pt;padding:3.0pt 0cm =
0cm 0cm">
<p class=3D"MsoNormal"><b><span style=3D"font-size:10.0pt;font-family:&quot=
;Tahoma&quot;,&quot;sans-serif&quot;;color:windowtext">From:</span></b><spa=
n style=3D"font-size:10.0pt;font-family:&quot;Tahoma&quot;,&quot;sans-serif=
&quot;;color:windowtext"> 6tisch-security [mailto:6tisch-security-bounces@i=
etf.org]
<b>On Behalf Of </b>Rene Struik<br>
<b>Sent:</b> mardi 27 mai 2014 05:20<br>
<b>To:</b> Michael Richardson; 6tisch-security@ietf.org<br>
<b>Subject:</b> Re: [6tisch-security] agenda for 2014-05-27 6tisch security=
 call<o:p></o:p></span></p>
</div>
</div>
<p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p>
<div>
<p class=3D"MsoNormal">Dear colleagues:<br>
<br>
I would like add one more topic to the mix: initialization and synchronizat=
ion of ASN numbers. This relates to item c) &quot;join process and impact o=
n the network&quot; of my outstanding topic last of Tue last week (referenc=
ed below).<br>
<br>
Best regards, Rene<br>
<br>
On 5/26/2014 11:09 PM, Rene Struik wrote:<o:p></o:p></p>
</div>
<blockquote style=3D"margin-top:5.0pt;margin-bottom:5.0pt">
<div>
<p class=3D"MsoNormal">Hi Michael:<br>
<br>
I would like to discuss the outstanding issues I summarized in my email of =
Tue last week, May 20, 2014, 9:45am EDT (see
<a href=3D"http://www.ietf.org/mail-archive/web/6tisch-security/current/msg=
00086.html">
http://www.ietf.org/mail-archive/web/6tisch-security/current/msg00086.html<=
/a>). This was also one of the action items at the conclusion of last week'=
s 6TiSCH security call.<br>
<br>
FYI - the w/HART communication flows were discussed during the 6TiSCH secur=
ity conf call the week before, on Mon May 12, 2014. If one wishes to go ove=
r this again, that is fine, but I would prefer us giving preference to taki=
ng on already articulated issues
 (which were assigned as homework assignment to reflect upon) first (i.e., =
prior to item #4 of the proposed agenda).<br>
<br>
As another agenda point, I would like us to discuss the frequency of future=
 calls (as part of EOB).<br>
<br>
Best regards, Rene<br>
<br>
<br>
On 5/26/2014 10:49 PM, Michael Richardson wrote:<o:p></o:p></p>
</div>
<blockquote style=3D"margin-top:5.0pt;margin-bottom:5.0pt">
<pre>To remind, we moved the call from the 26th to the 27th at 10am EDT.<o:=
p></o:p></pre>
<pre>That's 90 minutes from this email.<o:p></o:p></pre>
<pre><o:p>&nbsp;</o:p></pre>
<pre>1) notewell.<o:p></o:p></pre>
<pre>2) intros<o:p></o:p></pre>
<pre>3) recap of draft-piro-<o:p></o:p></pre>
<pre>4) wirelesshart -way --- how does the communication work?<o:p></o:p></=
pre>
<pre>5) how to summarize all of this to the working group<o:p></o:p></pre>
<pre>6) how to close this process up?<o:p></o:p></pre>
<pre><o:p>&nbsp;</o:p></pre>
<pre>-- remember that the call is recorded, and the NoteWell applies.<o:p><=
/o:p></pre>
<pre><o:p>&nbsp;</o:p></pre>
<pre>-- The URL to access the webex, which will we use for audio only:<o:p>=
</o:p></pre>
<pre> &nbsp;<a href=3D"https://cisco.webex.com/cisco/j.php?MTID=3Dm2fe139bf=
876cea3ec62750cd580b7908">https://cisco.webex.com/cisco/j.php?MTID=3Dm2fe13=
9bf876cea3ec62750cd580b7908</a><o:p></o:p></pre>
<pre><o:p>&nbsp;</o:p></pre>
<pre>-- we will resume with the etherpad at:<o:p></o:p></pre>
<pre>&nbsp; &nbsp;<a href=3D"http://etherpad.tools.ietf.org:9000/p/notes-ie=
tf-89-6tisch-security">http://etherpad.tools.ietf.org:9000/p/notes-ietf-89-=
6tisch-security</a><o:p></o:p></pre>
<pre><o:p>&nbsp;</o:p></pre>
<pre>I'm at &#43;1 613 276-6809, IM: <a href=3D"mailto:mcr@xmpp.credil.org"=
>mcr@xmpp.credil.org</a> or <a href=3D"mailto:mcharlesr@gmail.com">mcharles=
r@gmail.com</a>,<o:p></o:p></pre>
<pre>if you need more than that to get in, or are having difficulties.<o:p>=
</o:p></pre>
<pre>Please make sure your audio works, and that you mute when not talking.=
<o:p></o:p></pre>
<pre><o:p>&nbsp;</o:p></pre>
<pre>--<o:p></o:p></pre>
<pre>Michael Richardson <a href=3D"mailto:mcr&#43;IETF@sandelman.ca">&lt;mc=
r&#43;IETF@sandelman.ca&gt;</a>, Sandelman Software Works<o:p></o:p></pre>
<pre> -=3D IPv6 IoT consulting =3D-<o:p></o:p></pre>
<pre><o:p>&nbsp;</o:p></pre>
<pre><o:p>&nbsp;</o:p></pre>
<pre><o:p>&nbsp;</o:p></pre>
<p class=3D"MsoNormal"><br>
<br>
<br>
<o:p></o:p></p>
<pre>_______________________________________________<o:p></o:p></pre>
<pre>6tisch-security mailing list<o:p></o:p></pre>
<pre><a href=3D"mailto:6tisch-security@ietf.org">6tisch-security@ietf.org</=
a><o:p></o:p></pre>
<pre><a href=3D"https://www.ietf.org/mailman/listinfo/6tisch-security">http=
s://www.ietf.org/mailman/listinfo/6tisch-security</a><o:p></o:p></pre>
</blockquote>
<p class=3D"MsoNormal"><br>
<br>
<br>
<o:p></o:p></p>
<pre>-- <o:p></o:p></pre>
<pre>email: <a href=3D"mailto:rstruik.ext@gmail.com">rstruik.ext@gmail.com<=
/a> | Skype: rstruik<o:p></o:p></pre>
<pre>cell: &#43;1 (647) 867-5658 | US: &#43;1 (415) 690-7363<o:p></o:p></pr=
e>
</blockquote>
<p class=3D"MsoNormal"><br>
<br>
<br>
<o:p></o:p></p>
<pre>-- <o:p></o:p></pre>
<pre>email: <a href=3D"mailto:rstruik.ext@gmail.com">rstruik.ext@gmail.com<=
/a> | Skype: rstruik<o:p></o:p></pre>
<pre>cell: &#43;1 (647) 867-5658 | US: &#43;1 (415) 690-7363<o:p></o:p></pr=
e>
</div>
</div>
</body>
</html>

--_000_E045AECD98228444A58C61C200AE1BD8426B036Bxmbrcdx01ciscoc_--


From nobody Tue May 27 06:40:17 2014
Return-Path: <mcr@sandelman.ca>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 7266E1A034B for <6tisch-security@ietfa.amsl.com>; Tue, 27 May 2014 06:40:15 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.542
X-Spam-Level: 
X-Spam-Status: No, score=-2.542 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RP_MATCHES_RCVD=-0.651, SPF_PASS=-0.001, T_TVD_MIME_NO_HEADERS=0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id CE55ZFH_CdF2 for <6tisch-security@ietfa.amsl.com>; Tue, 27 May 2014 06:40:12 -0700 (PDT)
Received: from tuna.sandelman.ca (tuna.sandelman.ca [209.87.252.184]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 774F01A0148 for <6tisch-security@ietf.org>; Tue, 27 May 2014 06:40:12 -0700 (PDT)
Received: from sandelman.ca (obiwan.sandelman.ca [IPv6:2607:f0b0:f:2::247]) by tuna.sandelman.ca (Postfix) with ESMTP id 8F30B20028; Tue, 27 May 2014 09:42:51 -0400 (EDT)
Received: by sandelman.ca (Postfix, from userid 179) id 18D6763B0E; Tue, 27 May 2014 09:40:05 -0400 (EDT)
Received: from sandelman.ca (localhost [127.0.0.1]) by sandelman.ca (Postfix) with ESMTP id 00D2163B09; Tue, 27 May 2014 09:40:04 -0400 (EDT)
From: Michael Richardson <mcr+ietf@sandelman.ca>
To: Rene Struik <rstruik.ext@gmail.com>
In-Reply-To: <53840205.2070103@gmail.com>
References: <E045AECD98228444A58C61C200AE1BD8416F3AF4@xmb-rcd-x01.cisco.com> <bomn1n01Q3zUFux01ompsd> <531DD632.2060009@cox.net> <531DDB20.5050600@gmail.com> <10925.1394631496@sandelman.ca> <532069C8.2050005@gmail.com> <23590.1394999032@sandelman.ca> <18106.1395625035@sandelman.ca> <19609.1396839403@sandelman.ca> <11557.1397444260@sandelman.ca> <28192.1398644294@sandelman.ca> <29064.1399255587@sandelman.ca> <19475.1400588783@sandelman.ca> <4903.1401158997@sandelman.ca> <53840205.2070103@gmail.com>
X-Mailer: MH-E 8.2; nmh 1.3-dev; GNU Emacs 23.4.1
X-Face: $\n1pF)h^`}$H>Hk{L"x@)JS7<%Az}5RyS@k9X%29-lHB$Ti.V>2bi.~ehC0; <'$9xN5Ub# z!G,p`nR&p7Fz@^UXIn156S8.~^@MJ*mMsD7=QFeq%AL4m<nPbLgmtKK-5dC@#:k
MIME-Version: 1.0
Content-Type: multipart/signed; boundary="=-=-="; micalg=pgp-sha1; protocol="application/pgp-signature"
Date: Tue, 27 May 2014 09:40:04 -0400
Message-ID: <9411.1401198004@sandelman.ca>
Sender: mcr@sandelman.ca
Archived-At: http://mailarchive.ietf.org/arch/msg/6tisch-security/H8lulXaTnbWd6lhsgxiZvvtv7Pw
Cc: 6tisch-security@ietf.org
Subject: Re: [6tisch-security] agenda for 2014-05-27 6tisch security call
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 27 May 2014 13:40:15 -0000

--=-=-=


Rene Struik <rstruik.ext@gmail.com> wrote:
    > I would like to discuss the outstanding issues I summarized in my email
    > of Tue last week, May 20, 2014, 9:45am EDT (see
    > http://www.ietf.org/mail-archive/web/
    > 6tisch-security/current/msg00086.html). This was also one of the action
    > items at the conclusion of last week's 6TiSCH security call.

Good, let's do that.

    > FYI - the w/HART communication flows were discussed during the 6TiSCH
    > security conf call the week before, on Mon May 12, 2014. If one wishes
    > to go over this again, that is fine, but I would prefer us giving
    > preference to taking on already articulated issues (which were assigned
    > as homework assignment to reflect upon) first (i.e., prior to item #4
    > of the proposed agenda).

I agree; it was my goal to bring closure to that part.

    > As another agenda point, I would like us to discuss the frequency of
    > future calls (as part of EOB).

Good idea.

--
Michael Richardson <mcr+IETF@sandelman.ca>, Sandelman Software Works
 -= IPv6 IoT consulting =-




--=-=-=
Content-Type: application/pgp-signature

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iQEVAwUBU4SVsoCLcPvd0N1lAQKHaAf/W8LZFGHsB43wTbGhK9IFey7FfK1hgJNR
M4WT6OVR5RzdmDQuo6K2glq31eK0BtE02HO7PRptRNGaqTQPT7oVmOsqdaGIYX83
Pb/xqYrjnCs8UBVdr4FrwbacRN7MIjt8QWB0f6mL4hzlH/MB1sB34LK3FQs2ao67
KPjeO0UCEp+B4PwuH7cadbdnFQlTWyshQ0B8H8gpynUbnI7DuPpaL68Jbo6NYotn
p2kSLsDQyXpkScGjSO/xH7DrdDePI7iSAwfuD5svdYhqCQdNh8vh7qbeP6AV7IDc
EvEtSkm/oa3hSDhGxx8w4NkKkWR7GXsneDOhHqfpAiizLEj1cbs1qQ==
=S0Qo
-----END PGP SIGNATURE-----
--=-=-=--


From nobody Tue May 27 06:41:04 2014
Return-Path: <jsimon@linear.com>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 52AAC1A014E for <6tisch-security@ietfa.amsl.com>; Tue, 27 May 2014 06:41:02 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.587
X-Spam-Level: 
X-Spam-Status: No, score=-1.587 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, FM_FORGED_GMAIL=0.622, HTML_MESSAGE=0.001, HTTPS_HTTP_MISMATCH=1.989, RCVD_IN_DNSWL_MED=-2.3, WEIRD_PORT=0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id eJBLuor1evyR for <6tisch-security@ietfa.amsl.com>; Tue, 27 May 2014 06:40:59 -0700 (PDT)
Received: from p01c12o148.mxlogic.net (p01c12o148.mxlogic.net [208.65.145.71]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id C8D781A014C for <6tisch-security@ietf.org>; Tue, 27 May 2014 06:40:40 -0700 (PDT)
Received: from unknown [12.218.215.72] (EHLO smtpauth1.linear.com) by p01c12o148.mxlogic.net(mxl_mta-8.0.0-1) with ESMTP id 4d594835.0.8466.00-250.22587.p01c12o148.mxlogic.net (envelope-from <jsimon@linear.com>);  Tue, 27 May 2014 07:40:38 -0600 (MDT)
X-MXL-Hash: 538495d619faf12d-44a58d5ad96382f82ee9f7c57e73973a8f5e42f0
Received: from mail-qg0-f51.google.com (mail-qg0-f51.google.com [209.85.192.51]) by smtpauth1.linear.com (Postfix) with ESMTPSA id 5ACCB740C7 for <6tisch-security@ietf.org>; Tue, 27 May 2014 06:40:35 -0700 (PDT)
Received: by mail-qg0-f51.google.com with SMTP id q107so13814037qgd.24 for <6tisch-security@ietf.org>; Tue, 27 May 2014 06:40:35 -0700 (PDT)
MIME-Version: 1.0
X-Received: by 10.224.30.70 with SMTP id t6mr43233698qac.30.1401198035584; Tue, 27 May 2014 06:40:35 -0700 (PDT)
Received: by 10.229.117.74 with HTTP; Tue, 27 May 2014 06:40:35 -0700 (PDT)
In-Reply-To: <53840205.2070103@gmail.com>
References: <E045AECD98228444A58C61C200AE1BD8416F3AF4@xmb-rcd-x01.cisco.com> <531DD632.2060009@cox.net> <531DDB20.5050600@gmail.com> <10925.1394631496@sandelman.ca> <532069C8.2050005@gmail.com> <23590.1394999032@sandelman.ca> <18106.1395625035@sandelman.ca> <19609.1396839403@sandelman.ca> <11557.1397444260@sandelman.ca> <28192.1398644294@sandelman.ca> <29064.1399255587@sandelman.ca> <19475.1400588783@sandelman.ca> <4903.1401158997@sandelman.ca> <53840205.2070103@gmail.com>
Date: Tue, 27 May 2014 06:40:35 -0700
Message-ID: <CAJeFcoS3PNFX2obx3uNDJDtH=QvNLmaPhw2R468sNaeqpo8QBQ@mail.gmail.com>
From: Jonathan Simon <jsimon@linear.com>
To: Rene Struik <rstruik.ext@gmail.com>
Content-Type: multipart/alternative; boundary=047d7bdca66a2beebb04fa61d7e1
X-AnalysisOut: [v=2.1 cv=NZVo1gz4 c=1 sm=1 tr=0 a=glloKNylpeYNumXQcclYyA==]
X-AnalysisOut: [:117 a=glloKNylpeYNumXQcclYyA==:17 a=9iaqTFGLkfwA:10 a=D2_]
X-AnalysisOut: [GN2MmYMYA:10 a=AxOM2Z2vSZ8A:10 a=BLceEmwcHowA:10 a=MqDINYq]
X-AnalysisOut: [SAAAA:8 a=pGLkceISAAAA:8 a=YlVTAMxIAAAA:8 a=1XWaLZrsAAAA:8]
X-AnalysisOut: [ a=48vgC7mUAAAA:8 a=SyYMxH9GAAAA:8 a=NojvYFcnAAAA:8 a=rWPl]
X-AnalysisOut: [ndbxAAAA:8 a=07xDYRY_YWtYpDXrbQQA:9 a=2847LzV-qUdmLHL5:21 ]
X-AnalysisOut: [a=Ce8NPR-0ha2L2x3A:21 a=QEXdDO2ut3YA:10 a=wUAfXdCGL-oA:10 ]
X-AnalysisOut: [a=G1HyQLfxkfkA:10 a=19wCD08tTksA:10 a=vsVyj9psLt0A:10 a=xE]
X-AnalysisOut: [eETXzOXN8A:10 a=yRLhjdVT-pYA:10 a=uztyEWA5df8A:10 a=qVizmW]
X-AnalysisOut: [-ZYBIA:10 a=p-HxVa_ds0YA:10 a=AeFSex2-gKoA:10 a=QxAq9r8ObN]
X-AnalysisOut: [gA:10 a=ULth79YsAAUA:10 a=MSl-tDqOz04A:10 a=lZB815dzVvQA:1]
X-AnalysisOut: [0 a=xLpt9-x9cSEA:10 a=QV-tR3pPfjiHP0PDIs0A:9 a=tlHEKwvFqhT]
X-AnalysisOut: [X2m9Q:21 a=3LU24-qxkduWaGKp:21 a=JH-OAX8QlGG7W7LQ:21 a=tXs]
X-AnalysisOut: [nliwV7b4A:10]
X-Spam: [F=0.5000000000; CM=0.500; MH=0.500(2014052710); S=0.200(2014051901)]
X-MAIL-FROM: <jsimon@linear.com>
X-SOURCE-IP: [12.218.215.72]
Archived-At: http://mailarchive.ietf.org/arch/msg/6tisch-security/s_LQeq8urO70A16rYnfEEXyjsts
Cc: Michael Richardson <mcr+ietf@sandelman.ca>, 6tisch-security@ietf.org
Subject: Re: [6tisch-security] agenda for 2014-05-27 6tisch security call
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
Reply-To: jsimon@linear.com
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 27 May 2014 13:41:02 -0000

--047d7bdca66a2beebb04fa61d7e1
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

Rene had asked on a previous call for someone to summarize WirelessHART
joining - here you go.

* One or more devices are sending beacons to advertise the presence of the
network. In WirelessHART, this frame is unencrypted, but authenticated with
a well known key.  The beacon contains the current ASN, which the joining
device uses to synchronize its clock.

* Once the joining node has heard a beacon, it continues listening for
additional beacons for a short specified timeout.

* The joining node encrypts a frame containing some HART specific content,
including a list of beaconing neighbors it heard in the previous steps. The
size of the payload is ~ 60 bytes.  The packet is routed by a "proxy" node
- the joining parent. The frame is authenticated using the well-known key,
and encrypted using a shared symmetric key known only by the node and the
manager.

* The manager responds with a frame containing the run-time link-layer key,
the node's new short address (this takes the place of PAN coordinator
association), and a unicast session key and starting nonce for the manager.
This frame is encrypted with the symmetric key. The payload is ~ 60 bytes,
and is routed to the proxy for delivery to the joining node - the proxy
uses the link-layer well known key on the frame.

* At this point the joining node transitions to using the run-time
link-layer key for all link-layer frames, and the manager unicast session
for end-to-end manager traffic. This ends the initial security handshake.

* Over a number of additional frames, the manager assigns additional
sessions, including broadcast sessions, and a unicast session to the
Gateway (sink for all data traffic), and additional communications
resources, routing information, etc.  There is no explicit transition from
joining to joined - the mote transitions when certain key frames are
received.

* Note that a WirelessHART link-layer frame contains and additional frame
type byte and a 4-byte link-layer MIC, on top of the unsecured 15.4 frame.
A network frame contains an additional 16-40 bytes of addressing, routing,
security and other information.

Hope this help!

Jonathan



On Mon, May 26, 2014 at 8:09 PM, Rene Struik <rstruik.ext@gmail.com> wrote:

>  Hi Michael:
>
> I would like to discuss the outstanding issues I summarized in my email o=
f
> Tue last week, May 20, 2014, 9:45am EDT (see
> http://www.ietf.org/mail-archive/web/6tisch-security/current/msg00086.htm=
l<http://cp.mcafee.com/d/5fHCMUp41ESyNt55OWtSjtPqbwVBcSyUepvdEK3zhOyCOqejrz=
PPPz5XCN6ABqM1hYEvIundDOx-NVsTJQXIfcLZvC4TQTS6eLsKCO-PPXX3XUVzBHFShjlKepVkf=
fGhBrwqrhdI6XYyMCY-ehojd79KVI05bVKY01MjbX6NehDY05zAVkIjbQ-PspjbppKcvxf5q4rT=
KYVMedKjBiNcLjXdNBcIn8lrxrW0GnPtU02rhhuhKr1vF6y0QJKjBiNcLjXdNBcIqnjh1F7U8qq=
87qNd42tQm2ZTOWoUQgejBiNcQgk-Pspjb6y2SDDCT63pO_o>).
> This was also one of the action items at the conclusion of last week's
> 6TiSCH security call.
>
> FYI - the w/HART communication flows were discussed during the 6TiSCH
> security conf call the week before, on Mon May 12, 2014. If one wishes to
> go over this again, that is fine, but I would prefer us giving preference
> to taking on already articulated issues (which were assigned as homework
> assignment to reflect upon) first (i.e., prior to item #4 of the proposed
> agenda).
>
> As another agenda point, I would like us to discuss the frequency of
> future calls (as part of EOB).
>
> Best regards, Rene
>
>
> On 5/26/2014 10:49 PM, Michael Richardson wrote:
>
> To remind, we moved the call from the 26th to the 27th at 10am EDT.
> That's 90 minutes from this email.
>
> 1) notewell.
> 2) intros
> 3) recap of draft-piro-
> 4) wirelesshart -way --- how does the communication work?
> 5) how to summarize all of this to the working group
> 6) how to close this process up?
>
> -- remember that the call is recorded, and the NoteWell applies.
>
> -- The URL to access the webex, which will we use for audio only:
>   https://cisco.webex.com/cisco/j.php?MTID=3Dm2fe139bf876cea3ec62750cd580=
b7908 <http://cp.mcafee.com/d/5fHCN0SyNt55OWtSjtPqbwVBcSyUepvdEK3zhOyCOqejr=
zPPPz5XCN6ABqM1hYEvIundDOx-NVsTJQXIfcLZvC4TQTS6eLsKCO-PPXX3XUVzBHFShjlKepVk=
ffGhBrwqrjdI6XYyMCY-ehojd79KVIDeqR4IOQGmHM0L3-nOQGmHwzMh93o93gUVldTQmjhOgtu=
7em_mvIUCevLp1ZWV0sqerL6T9OFoCnFZCUOCmbAaJMJZ0lbVKY01dEEL8TdwLQzh0qmT9OFoCn=
FZCUOCmdbFEwQzY4dd43JoCy1eWb1uXVtcsq879OFoCq8avpKcFBzh1rjPPrz1LmTw7w17>
>
> -- we will resume with the etherpad at:
>    http://etherpad.tools.ietf.org:9000/p/notes-ietf-89-6tisch-security <h=
ttp://cp.mcafee.com/d/2DRPow71NJ5yWabBQXICXCQn1PapJ5MsO-rhs76zB5dAQsCT7DDD6=
bTdyd9aRw2zVg_oYKrfB3ZzOVLrFToupvW_c9LFLIctuVtdBZDDTS7TNP7bnjIyCHssPOEuvkza=
T0QSOrodTV5xdVYsyMCqejtPo0fVA_yJG7jHk-Di-rL00kzhPuZYmO5p_gLbVKBTzhOnsDaBypu=
DSrzapoSVelb4OZfIT6kONsxlK5LE2FvdTw09J55V6VI5-Aq83iSVelb4OZfIT6kONFtd46Avwx=
FEwtH4Qg9ThobTvbFzzh0Velb4Ph1jXdNBcIq8bquursodJiZvpmK6GwY>
>
> I'm at +1 613 276-6809, IM: mcr@xmpp.credil.org or mcharlesr@gmail.com,
> if you need more than that to get in, or are having difficulties.
> Please make sure your audio works, and that you mute when not talking.
>
> --
> Michael Richardson <mcr+IETF@sandelman.ca> <mcr+IETF@sandelman.ca>, Sande=
lman Software Works
>  -=3D IPv6 IoT consulting =3D-
>
>
>
>
>
>
> _______________________________________________
> 6tisch-security mailing list6tisch-security@ietf.orghttps://www.ietf.org/=
mailman/listinfo/6tisch-security <http://cp.mcafee.com/d/2DRPoO86QmbEEKnjKO=
rKrhs7cFCQn1PbVJ5MsqekkSjhOrsuuusoLsS8QAHm0afB3ZzOVI-kfSfbCZKDtxVB_HYMC-C-M=
NRXBQSnSuvvovv7csJteOaqJNPfaxVZicHs3jr1JwTvAm4TDNOb2pEVdTdAVPmEBC5eBYTu00U9=
GX33VkDa3JssDaBypuDSrzapoSVelb4OZfIT6kONsxlK5LE2FvdTw09J55V6VI5-Aq83iSVelb4=
OZfIT6kONFtd46AvwxFEwtH4Qg9ThobTvbFzzh0Velb4Ph1jXdNBcIq8bquursodLWbv>
>
>
>
> --
> email: rstruik.ext@gmail.com | Skype: rstruik
> cell: +1 (647) 867-5658 | US: +1 (415) 690-7363
>
>
> _______________________________________________
> 6tisch-security mailing list
> 6tisch-security@ietf.org
>
> http://cp.mcafee.com/d/avndzgQ93gArhoKyyVteX9KVJ5MsOCrhs7cLCQn1NEVhjpd79J=
NVVVNyZPoziiJo0E-kfSfbCPVg_oYKrSWtS7Cn-LP2rWrX37nKnjpvpVZZxZYsNORQX8FGT7cYG=
7DR8OJMddECQjt-hojuv78I9CzATsSjDdqymokWnPtU03wCHIcfBisEeRNOsGm9BWvpKcFBzrAV=
kIjbQ-Pspjb5O5mUm-waBYTu00CQknArCMnWhEwdbrAVkIjbQ-Pspjb6BQQgqh-26Cy1SIjh0Dt=
5wLtYKCed43AVkIjd45fIT6kONEwJFVVJNwSeVhsrLe-Fkd
>
>


--=20
--=20
Jonathan Simon, Ph. D
Director of Systems Engineering
Dust Networks at Linear Technology
30695 Huntwood Ave
Hayward, CA 94544-7021
(510) 400-2936
(510) 489-3799 FAX
jsimon@linear.com

**LINEAR TECHNOLOGY CORPORATION**
*****Internet Email Confidentiality Notice*****
 This e-mail transmission, and any documents, files or previous
e-mail messages attached to it may contain confidential information that
is legally privileged. If you are not the intended recipient, or a
person responsible for delivering it to the intended recipient, you are
hereby notified that any disclosure, copying, distribution or use of any of
the information contained in or attached to this transmission is
STRICTLY PROHIBITED. If you have received this transmission in error,
please immediately notify me by reply e-mail, or by telephone at (510)
400-2936, and destroy the original transmission and its attachments without
reading or saving in any manner. Thank you.

--047d7bdca66a2beebb04fa61d7e1
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><div><div>Rene had asked on a previous call for someone to=
 summarize WirelessHART joining - here you go.<br><br>* One or more devices=
 are sending beacons to advertise=20
the presence of the network. In WirelessHART, this frame is unencrypted,
 but authenticated with a well known key.=C2=A0 The beacon contains the=20
current ASN, which the joining device uses to synchronize its clock.<br>


<br><div>* Once the joining node has heard a beacon, it continues listening=
 for additional beacons for a short specified timeout.<br><br></div>*
 The joining node encrypts a frame containing some HART specific=20
content, including a list of beaconing neighbors it heard in the previous=
=20
steps. The size of the payload is ~ 60 bytes.=C2=A0 The packet is routed by=
 a
 &quot;proxy&quot; node - the joining parent. The frame is authenticated us=
ing the
 well-known key, and encrypted using a shared symmetric key known only=20
by the node and the manager.<br>


<br>* The manager responds with a frame containing the run-time=20
link-layer key, the node&#39;s new short address (this takes the place of=
=20
PAN coordinator association), and a unicast session key and starting=20
nonce for the manager. This frame is encrypted with the symmetric key.=20
The payload is ~ 60 bytes, and is routed to the proxy for delivery to=20
the joining node - the proxy uses the link-layer well known key on the=20
frame.<br>


<br><div>* At this point the joining node transitions to using the
 run-time link-layer key for all link-layer frames, and the manager=20
unicast session for end-to-end manager traffic. This ends the initial secur=
ity handshake.<br><br></div><div>* Over
 a number of additional frames, the manager assigns additional sessions,
 including broadcast sessions, and a unicast session to the Gateway=20
(sink for all data traffic), and additional communications resources, routi=
ng information, etc.=C2=A0=20
There is no explicit transition from joining to joined - the mote=20
transitions when certain key frames are received.<br>


<br></div>* Note that a WirelessHART link-layer frame contains and=20
additional frame type byte and a 4-byte link-layer MIC, on top of the unsec=
ured 15.4 frame.=C2=A0 A network frame
 contains an additional 16-40 bytes of addressing, routing, security and
 other information.<br><br></div>Hope this help!<br><br></div>Jonathan<br><=
div><div><div>


<br></div></div></div></div><div class=3D"gmail_extra"><br><br><div class=
=3D"gmail_quote">On Mon, May 26, 2014 at 8:09 PM, Rene Struik <span dir=3D"=
ltr">&lt;<a href=3D"mailto:rstruik.ext@gmail.com" target=3D"_blank">rstruik=
.ext@gmail.com</a>&gt;</span> wrote:<br>
<blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;border-left:1p=
x #ccc solid;padding-left:1ex">
 =20
   =20
 =20
  <div bgcolor=3D"#FFFFFF" text=3D"#000000">
    <div>Hi Michael:<br>
      <br>
      I would like to discuss the outstanding issues I summarized in my
      email of Tue last week, May 20, 2014, 9:45am EDT (see
      <a href=3D"http://cp.mcafee.com/d/5fHCMUp41ESyNt55OWtSjtPqbwVBcSyUepv=
dEK3zhOyCOqejrzPPPz5XCN6ABqM1hYEvIundDOx-NVsTJQXIfcLZvC4TQTS6eLsKCO-PPXX3XU=
VzBHFShjlKepVkffGhBrwqrhdI6XYyMCY-ehojd79KVI05bVKY01MjbX6NehDY05zAVkIjbQ-Ps=
pjbppKcvxf5q4rTKYVMedKjBiNcLjXdNBcIn8lrxrW0GnPtU02rhhuhKr1vF6y0QJKjBiNcLjXd=
NBcIqnjh1F7U8qq87qNd42tQm2ZTOWoUQgejBiNcQgk-Pspjb6y2SDDCT63pO_o" target=3D"=
_blank">http://www.ietf.org/mail-archive/web/6tisch-security/current/msg000=
86.html</a>).
      This was also one of the action items at the conclusion of last
      week&#39;s 6TiSCH security call.<br>
      <br>
      FYI - the w/HART communication flows were discussed during the
      6TiSCH security conf call the week before, on Mon May 12, 2014. If
      one wishes to go over this again, that is fine, but I would prefer
      us giving preference to taking on already articulated issues
      (which were assigned as homework assignment to reflect upon) first
      (i.e., prior to item #4 of the proposed agenda).<br>
      <br>
      As another agenda point, I would like us to discuss the frequency
      of future calls (as part of EOB).<br>
      <br>
      Best regards, Rene<br>
      <br>
      <br>
      On 5/26/2014 10:49 PM, Michael Richardson wrote:<br>
    </div>
    <blockquote type=3D"cite">
      <pre>To remind, we moved the call from the 26th to the 27th at 10am E=
DT.
That&#39;s 90 minutes from this email.

1) notewell.
2) intros
3) recap of draft-piro-
4) wirelesshart -way --- how does the communication work?
5) how to summarize all of this to the working group
6) how to close this process up?

-- remember that the call is recorded, and the NoteWell applies.

-- The URL to access the webex, which will we use for audio only:
  <a href=3D"http://cp.mcafee.com/d/5fHCN0SyNt55OWtSjtPqbwVBcSyUepvdEK3zhOy=
COqejrzPPPz5XCN6ABqM1hYEvIundDOx-NVsTJQXIfcLZvC4TQTS6eLsKCO-PPXX3XUVzBHFShj=
lKepVkffGhBrwqrjdI6XYyMCY-ehojd79KVIDeqR4IOQGmHM0L3-nOQGmHwzMh93o93gUVldTQm=
jhOgtu7em_mvIUCevLp1ZWV0sqerL6T9OFoCnFZCUOCmbAaJMJZ0lbVKY01dEEL8TdwLQzh0qmT=
9OFoCnFZCUOCmdbFEwQzY4dd43JoCy1eWb1uXVtcsq879OFoCq8avpKcFBzh1rjPPrz1LmTw7w1=
7" target=3D"_blank">https://cisco.webex.com/cisco/j.php?MTID=3Dm2fe139bf87=
6cea3ec62750cd580b7908</a>

-- we will resume with the etherpad at:
   <a href=3D"http://cp.mcafee.com/d/2DRPow71NJ5yWabBQXICXCQn1PapJ5MsO-rhs7=
6zB5dAQsCT7DDD6bTdyd9aRw2zVg_oYKrfB3ZzOVLrFToupvW_c9LFLIctuVtdBZDDTS7TNP7bn=
jIyCHssPOEuvkzaT0QSOrodTV5xdVYsyMCqejtPo0fVA_yJG7jHk-Di-rL00kzhPuZYmO5p_gLb=
VKBTzhOnsDaBypuDSrzapoSVelb4OZfIT6kONsxlK5LE2FvdTw09J55V6VI5-Aq83iSVelb4OZf=
IT6kONFtd46AvwxFEwtH4Qg9ThobTvbFzzh0Velb4Ph1jXdNBcIq8bquursodJiZvpmK6GwY" t=
arget=3D"_blank">http://etherpad.tools.ietf.org:9000/p/notes-ietf-89-6tisch=
-security</a>

I&#39;m at <a href=3D"tel:%2B1%20613%20276-6809" value=3D"+16132766809" tar=
get=3D"_blank">+1 613 276-6809</a>, IM: <a href=3D"mailto:mcr@xmpp.credil.o=
rg" target=3D"_blank">mcr@xmpp.credil.org</a> or <a href=3D"mailto:mcharles=
r@gmail.com" target=3D"_blank">mcharlesr@gmail.com</a>,
if you need more than that to get in, or are having difficulties.
Please make sure your audio works, and that you mute when not talking.

--
Michael Richardson <a href=3D"mailto:mcr+IETF@sandelman.ca" target=3D"_blan=
k">&lt;mcr+IETF@sandelman.ca&gt;</a>, Sandelman Software Works
 -=3D IPv6 IoT consulting =3D-



</pre><span class=3D"HOEnZb"><font color=3D"#888888">
      <br>
      <fieldset></fieldset>
      <br>
      <pre>_______________________________________________
6tisch-security mailing list
<a href=3D"mailto:6tisch-security@ietf.org" target=3D"_blank">6tisch-securi=
ty@ietf.org</a>
<a href=3D"http://cp.mcafee.com/d/2DRPoO86QmbEEKnjKOrKrhs7cFCQn1PbVJ5Msqekk=
SjhOrsuuusoLsS8QAHm0afB3ZzOVI-kfSfbCZKDtxVB_HYMC-C-MNRXBQSnSuvvovv7csJteOaq=
JNPfaxVZicHs3jr1JwTvAm4TDNOb2pEVdTdAVPmEBC5eBYTu00U9GX33VkDa3JssDaBypuDSrza=
poSVelb4OZfIT6kONsxlK5LE2FvdTw09J55V6VI5-Aq83iSVelb4OZfIT6kONFtd46AvwxFEwtH=
4Qg9ThobTvbFzzh0Velb4Ph1jXdNBcIq8bquursodLWbv" target=3D"_blank">https://ww=
w.ietf.org/mailman/listinfo/6tisch-security</a>
</pre>
    </font></span></blockquote><span class=3D"HOEnZb"><font color=3D"#88888=
8">
    <br>
    <br>
    <pre cols=3D"72">--=20
email: <a href=3D"mailto:rstruik.ext@gmail.com" target=3D"_blank">rstruik.e=
xt@gmail.com</a> | Skype: rstruik
cell: <a href=3D"tel:%2B1%20%28647%29%20867-5658" value=3D"+16478675658" ta=
rget=3D"_blank">+1 (647) 867-5658</a> | US: <a href=3D"tel:%2B1%20%28415%29=
%20690-7363" value=3D"+14156907363" target=3D"_blank">+1 (415) 690-7363</a>=
</pre>
  </font></span></div>

<br>_______________________________________________<br>
6tisch-security mailing list<br>
<a href=3D"mailto:6tisch-security@ietf.org">6tisch-security@ietf.org</a><br=
>
<a href=3D"http://cp.mcafee.com/d/avndzgQ93gArhoKyyVteX9KVJ5MsOCrhs7cLCQn1N=
EVhjpd79JNVVVNyZPoziiJo0E-kfSfbCPVg_oYKrSWtS7Cn-LP2rWrX37nKnjpvpVZZxZYsNORQ=
X8FGT7cYG7DR8OJMddECQjt-hojuv78I9CzATsSjDdqymokWnPtU03wCHIcfBisEeRNOsGm9BWv=
pKcFBzrAVkIjbQ-Pspjb5O5mUm-waBYTu00CQknArCMnWhEwdbrAVkIjbQ-Pspjb6BQQgqh-26C=
y1SIjh0Dt5wLtYKCed43AVkIjd45fIT6kONEwJFVVJNwSeVhsrLe-Fkd" target=3D"_blank"=
>http://cp.mcafee.com/d/avndzgQ93gArhoKyyVteX9KVJ5MsOCrhs7cLCQn1NEVhjpd79JN=
VVVNyZPoziiJo0E-kfSfbCPVg_oYKrSWtS7Cn-LP2rWrX37nKnjpvpVZZxZYsNORQX8FGT7cYG7=
DR8OJMddECQjt-hojuv78I9CzATsSjDdqymokWnPtU03wCHIcfBisEeRNOsGm9BWvpKcFBzrAVk=
IjbQ-Pspjb5O5mUm-waBYTu00CQknArCMnWhEwdbrAVkIjbQ-Pspjb6BQQgqh-26Cy1SIjh0Dt5=
wLtYKCed43AVkIjd45fIT6kONEwJFVVJNwSeVhsrLe-Fkd</a><br>

<br></blockquote></div><br><br clear=3D"all"><br>-- <br><div dir=3D"ltr"><s=
pan style=3D"font-size:13.5pt;font-family:&quot;Lucida Grande&quot;,&quot;s=
erif&quot;">--=C2=A0<br>
Jonathan Simon, Ph. D<br>
Director of Systems Engineering<br>
Dust Networks at Linear Technology<br>
30695 Huntwood Ave<br>
Hayward, CA 94544-7021<br>
<a>(510) 400-2936</a><br>
<a>(510) 489-3799</a> FAX<br>
<a href=3D"mailto:jsimon@linear.com" target=3D"_blank">jsimon@linear.com</a=
></span><br><br><span style=3D"font-size:13.5pt;font-family:&quot;Lucida Gr=
ande&quot;,&quot;serif&quot;">**LINEAR TECHNOLOGY=C2=A0CORPORATION**=C2=A0<=
br>
*****Internet Email Confidentiality=C2=A0Notice*****=C2=A0<br>
=C2=A0This e-mail transmission, and any=C2=A0documents, files or previous=
=20
e-mail=C2=A0messages attached to it may contain=C2=A0confidential informati=
on that
 is=C2=A0legally privileged. If you are not the=C2=A0intended recipient, or=
 a=20
person=C2=A0responsible for delivering it to the=C2=A0intended
 recipient, you are hereby=C2=A0notified that any disclosure,=20
copying,=C2=A0distribution or use of any of the=C2=A0information contained =
in or=20
attached=C2=A0to this transmission is STRICTLY=C2=A0PROHIBITED. If you have=
=20
received this=C2=A0transmission in error, please=C2=A0immediately notify
 me by reply e-mail, or by telephone at <a>
(510) 400-2936</a>, and destroy the original=C2=A0transmission and its atta=
chments=C2=A0without reading or saving in any=C2=A0manner. Thank you. </spa=
n></div>
</div>

--047d7bdca66a2beebb04fa61d7e1--


From nobody Tue May 27 06:43:11 2014
Return-Path: <twatteyne@gmail.com>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 3C2361A0137 for <6tisch-security@ietfa.amsl.com>; Tue, 27 May 2014 06:43:09 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.277
X-Spam-Level: 
X-Spam-Status: No, score=-1.277 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, FM_FORGED_GMAIL=0.622, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, SPF_PASS=-0.001] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 0nGZdfxbErmC for <6tisch-security@ietfa.amsl.com>; Tue, 27 May 2014 06:43:08 -0700 (PDT)
Received: from mail-pa0-x235.google.com (mail-pa0-x235.google.com [IPv6:2607:f8b0:400e:c03::235]) (using TLSv1 with cipher ECDHE-RSA-RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 0C8251A011D for <6tisch-security@ietf.org>; Tue, 27 May 2014 06:43:08 -0700 (PDT)
Received: by mail-pa0-f53.google.com with SMTP id kp14so9159942pab.40 for <6tisch-security@ietf.org>; Tue, 27 May 2014 06:43:04 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113;  h=mime-version:sender:in-reply-to:references:from:date:message-id :subject:to:content-type; bh=xuJ188WCK5q9fuTxmetinL5LFTnZa2ARD660ISxf4O4=; b=cbYHDfqdgZIxX67eIAJUN3gHiy7gc++7xvbsKU6AkX3lYO2dEiednX30NS1lNQUX0E QAx90rpJrEERMJfAxKzM7V5injMvc+KlCGJ5kHKh5ZL0JTETKirMvwhiy0Fsw6IiNhjo TNGyaHQIHwxlkUKasLtcvD+aBFmUMKA4QnHwxFw+6Y++VROpHMsNWsBQEIJmncnUfpAS 5p2OP6WjQ7HCIJi8UO0dW27RPErFmb/o0Be+8xTlup9PN2s/wZL2CfUazhYBZKCiPYFk 6rAwxIbOfgtDbCrHkpBOpHaMiICZyR6h9n0dr/pDBVVTKcvmtKES6Mxl2qYIkFVeIs8o FZtw==
X-Received: by 10.66.141.12 with SMTP id rk12mr36327255pab.152.1401198184814;  Tue, 27 May 2014 06:43:04 -0700 (PDT)
MIME-Version: 1.0
Sender: twatteyne@gmail.com
Received: by 10.66.154.130 with HTTP; Tue, 27 May 2014 06:42:44 -0700 (PDT)
In-Reply-To: <9411.1401198004@sandelman.ca>
References: <E045AECD98228444A58C61C200AE1BD8416F3AF4@xmb-rcd-x01.cisco.com> <531DD632.2060009@cox.net> <531DDB20.5050600@gmail.com> <10925.1394631496@sandelman.ca> <532069C8.2050005@gmail.com> <23590.1394999032@sandelman.ca> <18106.1395625035@sandelman.ca> <19609.1396839403@sandelman.ca> <11557.1397444260@sandelman.ca> <28192.1398644294@sandelman.ca> <29064.1399255587@sandelman.ca> <19475.1400588783@sandelman.ca> <4903.1401158997@sandelman.ca> <53840205.2070103@gmail.com> <9411.1401198004@sandelman.ca>
From: Thomas Watteyne <watteyne@eecs.berkeley.edu>
Date: Tue, 27 May 2014 06:42:44 -0700
X-Google-Sender-Auth: aomqtd_SPMD4Ks20j4G4KOj92bw
Message-ID: <CADJ9OA98vqeAJgioCY5o1-qCANKTqb8Kj2EX71HP9CrkD_3AKQ@mail.gmail.com>
To: "6tisch-security@ietf.org" <6tisch-security@ietf.org>
Content-Type: multipart/alternative; boundary=001a11c3272610e0b604fa61e06b
Archived-At: http://mailarchive.ietf.org/arch/msg/6tisch-security/K3GZQHEib-Jdvn4Po3l6vQ1uY4U
Subject: Re: [6tisch-security] agenda for 2014-05-27 6tisch security call
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 27 May 2014 13:43:09 -0000

--001a11c3272610e0b604fa61e06b
Content-Type: text/plain; charset=UTF-8

The IETF Etherpad instance is down. I propose we use
https://beta.etherpad.org/6tisch this week until it gets resolved.

In case this instance doesn't work well (we had some problems on Friday), I
can take notes locally.

Thomas


On Tue, May 27, 2014 at 6:40 AM, Michael Richardson <mcr+ietf@sandelman.ca>
wrote:

>
> Rene Struik <rstruik.ext@gmail.com> wrote:
>     > I would like to discuss the outstanding issues I summarized in my
> email
>     > of Tue last week, May 20, 2014, 9:45am EDT (see
>     > http://www.ietf.org/mail-archive/web/
>     > 6tisch-security/current/msg00086.html). This was also one of the
> action
>     > items at the conclusion of last week's 6TiSCH security call.
>
> Good, let's do that.
>
>     > FYI - the w/HART communication flows were discussed during the 6TiSCH
>     > security conf call the week before, on Mon May 12, 2014. If one
> wishes
>     > to go over this again, that is fine, but I would prefer us giving
>     > preference to taking on already articulated issues (which were
> assigned
>     > as homework assignment to reflect upon) first (i.e., prior to item #4
>     > of the proposed agenda).
>
> I agree; it was my goal to bring closure to that part.
>
>     > As another agenda point, I would like us to discuss the frequency of
>     > future calls (as part of EOB).
>
> Good idea.
>
> --
> Michael Richardson <mcr+IETF@sandelman.ca>, Sandelman Software Works
>  -= IPv6 IoT consulting =-
>
>
>
>
> _______________________________________________
> 6tisch-security mailing list
> 6tisch-security@ietf.org
> https://www.ietf.org/mailman/listinfo/6tisch-security
>
>

--001a11c3272610e0b604fa61e06b
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr">The IETF Etherpad instance is down. I propose we use=C2=A0=
<a href=3D"https://beta.etherpad.org/6tisch">https://beta.etherpad.org/6tis=
ch</a> this week until it gets resolved.<div><br></div><div>In case this in=
stance doesn&#39;t work well (we had some problems on Friday), I can take n=
otes locally.</div>

<div><br></div><div>Thomas</div></div><div class=3D"gmail_extra"><br><br><d=
iv class=3D"gmail_quote">On Tue, May 27, 2014 at 6:40 AM, Michael Richardso=
n <span dir=3D"ltr">&lt;<a href=3D"mailto:mcr+ietf@sandelman.ca" target=3D"=
_blank">mcr+ietf@sandelman.ca</a>&gt;</span> wrote:<br>

<blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;border-left:1p=
x #ccc solid;padding-left:1ex"><div class=3D""><br>
Rene Struik &lt;<a href=3D"mailto:rstruik.ext@gmail.com">rstruik.ext@gmail.=
com</a>&gt; wrote:<br>
=C2=A0 =C2=A0 &gt; I would like to discuss the outstanding issues I summari=
zed in my email<br>
=C2=A0 =C2=A0 &gt; of Tue last week, May 20, 2014, 9:45am EDT (see<br>
=C2=A0 =C2=A0 &gt; <a href=3D"http://www.ietf.org/mail-archive/web/" target=
=3D"_blank">http://www.ietf.org/mail-archive/web/</a><br>
=C2=A0 =C2=A0 &gt; 6tisch-security/current/msg00086.html). This was also on=
e of the action<br>
=C2=A0 =C2=A0 &gt; items at the conclusion of last week&#39;s 6TiSCH securi=
ty call.<br>
<br>
</div>Good, let&#39;s do that.<br>
<div class=3D""><br>
=C2=A0 =C2=A0 &gt; FYI - the w/HART communication flows were discussed duri=
ng the 6TiSCH<br>
=C2=A0 =C2=A0 &gt; security conf call the week before, on Mon May 12, 2014.=
 If one wishes<br>
=C2=A0 =C2=A0 &gt; to go over this again, that is fine, but I would prefer =
us giving<br>
=C2=A0 =C2=A0 &gt; preference to taking on already articulated issues (whic=
h were assigned<br>
=C2=A0 =C2=A0 &gt; as homework assignment to reflect upon) first (i.e., pri=
or to item #4<br>
=C2=A0 =C2=A0 &gt; of the proposed agenda).<br>
<br>
</div>I agree; it was my goal to bring closure to that part.<br>
<div class=3D""><br>
=C2=A0 =C2=A0 &gt; As another agenda point, I would like us to discuss the =
frequency of<br>
=C2=A0 =C2=A0 &gt; future calls (as part of EOB).<br>
<br>
</div>Good idea.<br>
<div class=3D"HOEnZb"><div class=3D"h5"><br>
--<br>
Michael Richardson &lt;<a href=3D"mailto:mcr%2BIETF@sandelman.ca">mcr+IETF@=
sandelman.ca</a>&gt;, Sandelman Software Works<br>
=C2=A0-=3D IPv6 IoT consulting =3D-<br>
<br>
<br>
<br>
</div></div><br>_______________________________________________<br>
6tisch-security mailing list<br>
<a href=3D"mailto:6tisch-security@ietf.org">6tisch-security@ietf.org</a><br=
>
<a href=3D"https://www.ietf.org/mailman/listinfo/6tisch-security" target=3D=
"_blank">https://www.ietf.org/mailman/listinfo/6tisch-security</a><br>
<br></blockquote></div><br></div>

--001a11c3272610e0b604fa61e06b--


From nobody Tue May 27 06:45:07 2014
Return-Path: <mcr@sandelman.ca>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 2D0601A014C for <6tisch-security@ietfa.amsl.com>; Tue, 27 May 2014 06:45:06 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.342
X-Spam-Level: 
X-Spam-Status: No, score=-1.342 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, J_CHICKENPOX_22=0.6, J_CHICKENPOX_41=0.6, RP_MATCHES_RCVD=-0.651, SPF_PASS=-0.001, T_TVD_MIME_NO_HEADERS=0.01] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id WMP1qgi6Z6An for <6tisch-security@ietfa.amsl.com>; Tue, 27 May 2014 06:45:05 -0700 (PDT)
Received: from tuna.sandelman.ca (tuna.sandelman.ca [IPv6:2607:f0b0:f:3::184]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 070C51A0137 for <6tisch-security@ietf.org>; Tue, 27 May 2014 06:45:05 -0700 (PDT)
Received: from sandelman.ca (obiwan.sandelman.ca [IPv6:2607:f0b0:f:2::247]) by tuna.sandelman.ca (Postfix) with ESMTP id 8840D20028; Tue, 27 May 2014 09:47:44 -0400 (EDT)
Received: by sandelman.ca (Postfix, from userid 179) id 257AB63B0E; Tue, 27 May 2014 09:44:58 -0400 (EDT)
Received: from sandelman.ca (localhost [127.0.0.1]) by sandelman.ca (Postfix) with ESMTP id 0F0F563B09; Tue, 27 May 2014 09:44:58 -0400 (EDT)
From: Michael Richardson <mcr+ietf@sandelman.ca>
To: "Pascal Thubert \(pthubert\)" <pthubert@cisco.com>
In-Reply-To: <E045AECD98228444A58C61C200AE1BD8426B036B@xmb-rcd-x01.cisco.com>
References: <E045AECD98228444A58C61C200AE1BD8416F3AF4@xmb-rcd-x01.cisco.com> <bomn1n01Q3zUFux01ompsd> <531DD632.2060009@cox.net> <531DDB20.5050600@gmail.com> <10925.1394631496@sandelman.ca> <532069C8.2050005@gmail.com> <23590.1394999032@sandelman.ca> <18106.1395625035@sandelman.ca> <19609.1396839403@sandelman.ca> <11557.1397444260@sandelman.ca> <28192.1398644294@sandelman.ca> <29064.1399255587@sandelman.ca> <19475.1400588783@sandelman.ca> <4903.1401158997@sandelman.ca> <53840205.2070103@gmail.com> <5384046A.6080706@gmail.com> <E045AECD98228444A58C61C200AE1BD8426B036B@xmb-rcd-x01.cisco.com>
X-Mailer: MH-E 8.2; nmh 1.3-dev; GNU Emacs 23.4.1
X-Face: $\n1pF)h^`}$H>Hk{L"x@)JS7<%Az}5RyS@k9X%29-lHB$Ti.V>2bi.~ehC0; <'$9xN5Ub# z!G,p`nR&p7Fz@^UXIn156S8.~^@MJ*mMsD7=QFeq%AL4m<nPbLgmtKK-5dC@#:k
MIME-Version: 1.0
Content-Type: multipart/signed; boundary="=-=-="; micalg=pgp-sha1; protocol="application/pgp-signature"
Date: Tue, 27 May 2014 09:44:58 -0400
Message-ID: <10436.1401198298@sandelman.ca>
Sender: mcr@sandelman.ca
Archived-At: http://mailarchive.ietf.org/arch/msg/6tisch-security/6oU5lCEAAEWNhmNJB9Y5gKOU3Hk
Cc: Rene Struik <rstruik.ext@gmail.com>, "6tisch-security@ietf.org" <6tisch-security@ietf.org>
Subject: Re: [6tisch-security] agenda for 2014-05-27 6tisch security call
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 27 May 2014 13:45:06 -0000

--=-=-=


Pascal Thubert (pthubert) <pthubert@cisco.com> wrote:
    > I?m interested in following up with the ND ARO thread (ARO and
    > DTLS/CoAP) that Michael just launched. If that?s what the wireless HART
    > discussion is about then I think we?re not done yet with it.

so, we are all in violent in agreement: we have all found an elephant,
we are just on different sides of things.
(cf: http://en.wikipedia.org/wiki/Blind_men_and_an_elephant )

    > With this, we can work on spreading the time over the next calls.

    > I think we could have a wiki page on pending flows and issues on the
    > repo or the IETF site, and I can help with that if you like.

When you say "pending flows", I think you mean people conversations,
not packet sequences?


--
Michael Richardson <mcr+IETF@sandelman.ca>, Sandelman Software Works
 -= IPv6 IoT consulting =-




--=-=-=
Content-Type: application/pgp-signature

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iQEVAwUBU4SW14CLcPvd0N1lAQJCagf/f6Z6vBvFVdPf+XKPzYkrJUSkFExBbVWs
WS868sZvmGGJa7wvFaLhqNovTdDv0khJPCv5tDv6QEl2HhPEa76owrT2Y2NYSP1u
y9Ce+S2+EOVf9IbtDXJpUw5NQlxUDpzIxb3V0RXOls7ew5QQbkWtV13JVMQVXnwn
Fz6Lef62fXFoy3MtctGS/tEhtQGVegN9n2t2g0jOQq+1KM2RM+9I6nfb6966XGZQ
SARdZTGw+0ttC7iEaG9vk9L5TfKLEovzyPm5qlEMduuota3ckIbOooYPQmLL8nqw
HaudDw+7lRZGZ55sEnnw+HSqB9wCheIX6Z0XDgklgcxsuikJf8w+cQ==
=p9Gg
-----END PGP SIGNATURE-----
--=-=-=--


From nobody Tue May 27 06:51:06 2014
Return-Path: <rstruik.ext@gmail.com>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 5CADE1A0155 for <6tisch-security@ietfa.amsl.com>; Tue, 27 May 2014 06:51:04 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -0.8
X-Spam-Level: 
X-Spam-Status: No, score=-0.8 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, J_CHICKENPOX_22=0.6, J_CHICKENPOX_41=0.6, SPF_PASS=-0.001] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id zRvF4FiaTIrE for <6tisch-security@ietfa.amsl.com>; Tue, 27 May 2014 06:51:03 -0700 (PDT)
Received: from mail-ie0-x229.google.com (mail-ie0-x229.google.com [IPv6:2607:f8b0:4001:c03::229]) (using TLSv1 with cipher ECDHE-RSA-RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 73A5A1A014C for <6tisch-security@ietf.org>; Tue, 27 May 2014 06:51:03 -0700 (PDT)
Received: by mail-ie0-f169.google.com with SMTP id at1so8891351iec.0 for <6tisch-security@ietf.org>; Tue, 27 May 2014 06:51:00 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113;  h=message-id:date:from:user-agent:mime-version:to:cc:subject :references:in-reply-to:content-type:content-transfer-encoding; bh=T9Zf+JvlqS3ohx6SbzryUPuKG79IlgpEO5faoq7Z1SQ=; b=ldo+TrRL+Y0ciYe7hZ645RX/rHOPJJuRb+GIKtqsIZTnbnH3fbHeUDrTBiO1/KSGxq lEwNekix+ghDVqAzofuJCMF2g8Ubo0M0rcC9g/pNgMMW7xJFZgiqjym4d4egQd9CC/rC 2tT+nORwYIg+oH6yGGptQb9qUqP3nElYdrSJCxMV+/7cs2f+sfwIQGyWtRXdDTwQqghk F7SFVx8dkPXpWTYs7bY6PL5nQBUhrjT/uQ2VkJklF+vBaUhOrvrL6VeuxO3Wve4x0G71 bVtWDbpZWoJpGd+zhLGpULKLOMqZGnlY9H36NETBvqXqq3Q4EPTC5iKJnxIu0hGj42Lc 3jzQ==
X-Received: by 10.50.62.104 with SMTP id x8mr33695475igr.37.1401198660178; Tue, 27 May 2014 06:51:00 -0700 (PDT)
Received: from [192.168.1.101] (CPE0013100e2c51-CM001cea35caa6.cpe.net.cable.rogers.com. [99.231.3.110]) by mx.google.com with ESMTPSA id 2sm7853021igs.17.2014.05.27.06.50.59 for <multiple recipients> (version=TLSv1 cipher=ECDHE-RSA-RC4-SHA bits=128/128); Tue, 27 May 2014 06:50:59 -0700 (PDT)
Message-ID: <53849841.4020401@gmail.com>
Date: Tue, 27 May 2014 09:50:57 -0400
From: Rene Struik <rstruik.ext@gmail.com>
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:24.0) Gecko/20100101 Thunderbird/24.5.0
MIME-Version: 1.0
To: Michael Richardson <mcr+ietf@sandelman.ca>,  "Pascal Thubert (pthubert)" <pthubert@cisco.com>
References: <E045AECD98228444A58C61C200AE1BD8416F3AF4@xmb-rcd-x01.cisco.com> <bomn1n01Q3zUFux01ompsd> <531DD632.2060009@cox.net> <531DDB20.5050600@gmail.com> <10925.1394631496@sandelman.ca> <532069C8.2050005@gmail.com> <23590.1394999032@sandelman.ca> <18106.1395625035@sandelman.ca> <19609.1396839403@sandelman.ca> <11557.1397444260@sandelman.ca> <28192.1398644294@sandelman.ca> <29064.1399255587@sandelman.ca> <19475.1400588783@sandelman.ca> <4903.1401158997@sandelman.ca> <53840205.2070103@gmail.com> <5384046A.6080706@gmail.com> <E045AECD98228444A58C61C200AE1BD8426B036B@xmb-rcd-x01.cisco.com> <10436.1401198298@sandelman.ca>
In-Reply-To: <10436.1401198298@sandelman.ca>
Content-Type: text/plain; charset=ISO-8859-1; format=flowed
Content-Transfer-Encoding: 7bit
Archived-At: http://mailarchive.ietf.org/arch/msg/6tisch-security/vHWez_i_jSTfOPcQ4sy2xFOpRgE
Cc: "6tisch-security@ietf.org" <6tisch-security@ietf.org>
Subject: Re: [6tisch-security] agenda for 2014-05-27 6tisch security call
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 27 May 2014 13:51:04 -0000

Can I read up on ARO and DTLS/CoAP in preparation for the call?


On 5/27/2014 9:44 AM, Michael Richardson wrote:
> Pascal Thubert (pthubert) <pthubert@cisco.com> wrote:
>      > I?m interested in following up with the ND ARO thread (ARO and
>      > DTLS/CoAP) that Michael just launched. If that?s what the wireless HART
>      > discussion is about then I think we?re not done yet with it.
>
> so, we are all in violent in agreement: we have all found an elephant,
> we are just on different sides of things.
> (cf: http://en.wikipedia.org/wiki/Blind_men_and_an_elephant )
>
>      > With this, we can work on spreading the time over the next calls.
>
>      > I think we could have a wiki page on pending flows and issues on the
>      > repo or the IETF site, and I can help with that if you like.
>
> When you say "pending flows", I think you mean people conversations,
> not packet sequences?
>
>
> --
> Michael Richardson <mcr+IETF@sandelman.ca>, Sandelman Software Works
>   -= IPv6 IoT consulting =-
>
>
>


-- 
email: rstruik.ext@gmail.com | Skype: rstruik
cell: +1 (647) 867-5658 | US: +1 (415) 690-7363


From nobody Tue May 27 07:03:00 2014
Return-Path: <mcr@sandelman.ca>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 6F3111A0411 for <6tisch-security@ietfa.amsl.com>; Tue, 27 May 2014 07:02:56 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.552
X-Spam-Level: 
X-Spam-Status: No, score=-2.552 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RP_MATCHES_RCVD=-0.651, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id jURyY7de2hdp for <6tisch-security@ietfa.amsl.com>; Tue, 27 May 2014 07:02:52 -0700 (PDT)
Received: from tuna.sandelman.ca (tuna.sandelman.ca [209.87.252.184]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 3E8C81A015C for <6tisch-security@ietf.org>; Tue, 27 May 2014 07:02:51 -0700 (PDT)
Received: from sandelman.ca (desk.marajade.sandelman.ca [209.87.252.247]) by tuna.sandelman.ca (Postfix) with ESMTP id 2B46920028; Tue, 27 May 2014 10:05:31 -0400 (EDT)
Received: by sandelman.ca (Postfix, from userid 179) id B75DD63B0E; Tue, 27 May 2014 10:02:44 -0400 (EDT)
Received: from sandelman.ca (localhost [127.0.0.1]) by sandelman.ca (Postfix) with ESMTP id 9F18163B09; Tue, 27 May 2014 10:02:44 -0400 (EDT)
From: Michael Richardson <mcr+ietf@sandelman.ca>
To: Thomas Watteyne <watteyne@eecs.berkeley.edu>
In-Reply-To: <CADJ9OA98vqeAJgioCY5o1-qCANKTqb8Kj2EX71HP9CrkD_3AKQ@mail.gmail.com>
References: <E045AECD98228444A58C61C200AE1BD8416F3AF4@xmb-rcd-x01.cisco.com> <531DD632.2060009@cox.net> <531DDB20.5050600@gmail.com> <10925.1394631496@sandelman.ca> <532069C8.2050005@gmail.com> <23590.1394999032@sandelman.ca> <18106.1395625035@sandelman.ca> <19609.1396839403@sandelman.ca> <11557.1397444260@sandelman.ca> <28192.1398644294@sandelman.ca> <29064.1399255587@sandelman.ca> <19475.1400588783@sandelman.ca> <4903.1401158997@sandelman.ca> <53840205.2070103@gmail.com> <9411.1401198004@sandelman.ca> <CADJ9OA98vqeAJgioCY5o1-qCANKTqb8Kj2EX71HP9CrkD_3AKQ@mail.gmail.com>
X-Mailer: MH-E 8.2; nmh 1.3-dev; GNU Emacs 23.4.1
X-Face: $\n1pF)h^`}$H>Hk{L"x@)JS7<%Az}5RyS@k9X%29-lHB$Ti.V>2bi.~ehC0; <'$9xN5Ub# z!G,p`nR&p7Fz@^UXIn156S8.~^@MJ*mMsD7=QFeq%AL4m<nPbLgmtKK-5dC@#:k
MIME-Version: 1.0
Content-Type: multipart/signed; boundary="=-=-="; micalg=pgp-sha1; protocol="application/pgp-signature"
Date: Tue, 27 May 2014 10:02:44 -0400
Message-ID: <14146.1401199364@sandelman.ca>
Sender: mcr@sandelman.ca
Archived-At: http://mailarchive.ietf.org/arch/msg/6tisch-security/2qrWIMGhuADsRNcL88IGqk8gi4A
Cc: "6tisch-security@ietf.org" <6tisch-security@ietf.org>
Subject: Re: [6tisch-security] agenda for 2014-05-27 6tisch security call
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 27 May 2014 14:02:56 -0000

--=-=-=
Content-Type: text/plain; charset=utf-8
Content-Transfer-Encoding: quoted-printable


Thomas Watteyne <watteyne@eecs.berkeley.edu> wrote:
    > The IETF Etherpad instance is down. I propose we
    > use=C2=A0https://beta.etherpad.org/ 6tisch this week until it gets re=
solved.

I couldn't connect to that one either... (I removed the space)
https://etherpad.mozilla.org/wJimt3mv1c

seems to work.

=2D-
Michael Richardson <mcr+IETF@sandelman.ca>, Sandelman Software Works
 -=3D IPv6 IoT consulting =3D-




--=-=-=
Content-Type: application/pgp-signature

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iQEVAwUBU4SbAYCLcPvd0N1lAQIPOAgAoifTKrjqtqcve4Re0DNnnYVFKA7SFHrx
XjcBTqhMma+8QnOk7cjiQ26xanj22sZrOAy+vCBDznLuBtdIlHkzDMJmSHs20WE7
SAWYBsGIsUuCo/m5E9AMy/Nzlae2L/q/dcFonPlgOz8gZbbzoiYUy7L79tpgXFXg
+DjZiUM4v/xa2xxz/psPt76alr+2hZpkBNNc3rYlnnNWrznPUPEaaFy0huwsawWs
oOIKEHhlcKqlBAgTWd/Ogxkb1wzqs7Nn2WPkHw30L0Ry5x/Top71bZZksht+iyAB
jf/ZwKJN8deiwXIZNwec3gEwzz8h9tjKjTjfQCe7gyCmD9asP26Dtg==
=Lggx
-----END PGP SIGNATURE-----
--=-=-=--


From nobody Tue May 27 08:31:32 2014
Return-Path: <mcr@sandelman.ca>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 4ED2A1A0181 for <6tisch-security@ietfa.amsl.com>; Tue, 27 May 2014 08:31:29 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.552
X-Spam-Level: 
X-Spam-Status: No, score=-2.552 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RP_MATCHES_RCVD=-0.651, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 5zmSiJjDA0Qt for <6tisch-security@ietfa.amsl.com>; Tue, 27 May 2014 08:31:24 -0700 (PDT)
Received: from tuna.sandelman.ca (tuna.sandelman.ca [209.87.252.184]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 121EB1A0254 for <6tisch-security@ietf.org>; Tue, 27 May 2014 08:31:24 -0700 (PDT)
Received: from sandelman.ca (obiwan.sandelman.ca [IPv6:2607:f0b0:f:2::247]) by tuna.sandelman.ca (Postfix) with ESMTP id BCE0C20028 for <6tisch-security@ietf.org>; Tue, 27 May 2014 11:34:03 -0400 (EDT)
Received: by sandelman.ca (Postfix, from userid 179) id 1F59863B0E; Tue, 27 May 2014 11:31:20 -0400 (EDT)
Received: from sandelman.ca (localhost [127.0.0.1]) by sandelman.ca (Postfix) with ESMTP id 09D8463B09 for <6tisch-security@ietf.org>; Tue, 27 May 2014 11:31:20 -0400 (EDT)
From: Michael Richardson <mcr+ietf@sandelman.ca>
To: 6tisch-security@ietf.org
In-Reply-To: <CAJeFcoS3PNFX2obx3uNDJDtH=QvNLmaPhw2R468sNaeqpo8QBQ@mail.gmail.com>
References: <E045AECD98228444A58C61C200AE1BD8416F3AF4@xmb-rcd-x01.cisco.com> <531DD632.2060009@cox.net> <531DDB20.5050600@gmail.com> <10925.1394631496@sandelman.ca> <532069C8.2050005@gmail.com> <23590.1394999032@sandelman.ca> <18106.1395625035@sandelman.ca> <19609.1396839403@sandelman.ca> <11557.1397444260@sandelman.ca> <28192.1398644294@sandelman.ca> <29064.1399255587@sandelman.ca> <19475.1400588783@sandelman.ca> <4903.1401158997@sandelman.ca> <53840205.2070103@gmail.com> <CAJeFcoS3PNFX2obx3uNDJDtH=QvNLmaPhw2R468sNaeqpo8QBQ@mail.gmail.com>
X-Mailer: MH-E 8.2; nmh 1.3-dev; GNU Emacs 23.4.1
X-Face: $\n1pF)h^`}$H>Hk{L"x@)JS7<%Az}5RyS@k9X%29-lHB$Ti.V>2bi.~ehC0; <'$9xN5Ub# z!G,p`nR&p7Fz@^UXIn156S8.~^@MJ*mMsD7=QFeq%AL4m<nPbLgmtKK-5dC@#:k
MIME-Version: 1.0
Content-Type: multipart/signed; boundary="=-=-="; micalg=pgp-sha1; protocol="application/pgp-signature"
Date: Tue, 27 May 2014 11:31:20 -0400
Message-ID: <32529.1401204680@sandelman.ca>
Sender: mcr@sandelman.ca
Archived-At: http://mailarchive.ietf.org/arch/msg/6tisch-security/KRkBvqEa3GumyilXlL6K06tdEXU
Subject: [6tisch-security] wirelessHART/6tisch join process
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 27 May 2014 15:31:29 -0000

--=-=-=
Content-Type: text/plain; charset=utf-8
Content-Transfer-Encoding: quoted-printable


Jonathan Simon <jsimon@linear.com> wrote:
    > * One or more devices are sending beacons to advertise the presence of
    > the network. In WirelessHART, this frame is unencrypted, but
    > authenticated with a well known key.=C2=A0 The beacon contains the cu=
rrent
    > ASN, which the joining device uses to synchronize its clock.

I think that this step won't change at all.
draft-piro-6tisch-security-issues-01 calls this a Partial and Hybrid Secure
Network.

    > * Once the joining node has heard a beacon, it continues listening for
    > additional beacons for a short specified timeout.

You don't explain this part, but one assumes one does this in order to:
  1) perhaps obtain a better (louder) beacon.
  2) in order to hear the correct (non-malicious beacon) as well.

We also need to listen for an RA during some slotted-Aloha period,
which the beacon(s) would tell us about.

    > * The joining node encrypts a frame containing some HART specific
    > content, including a list of beaconing neighbors it heard in the
    > previous steps. The size of the payload is ~ 60 bytes.=C2=A0 The pack=
et is
    > routed by a "proxy" node - the joining parent. The frame is
    > authenticated using the well-known key, and encrypted using a shared
    > symmetric key known only by the node and the manager.

The name for this message is the ND+ARO... That's how things map.
And the ND+ARO is "routed by a proxy node", exactly the same.
The frame is authenticated using a public key rather than a well known
symmetric key.  The message is probably not encrypted.

What is the purpose of including the list of beaconing neighbours?

    > * The manager responds with a frame containing the run-time link-layer
    > key, the node's new short address (this takes the place of PAN
    > coordinator association), and a unicast session key and starting nonce
    > for the manager. This frame is encrypted with the symmetric key. The
    > payload is ~ 60 bytes, and is routed to the proxy for delivery to the
    > joining node - the proxy uses the link-layer well known key on the
    > frame.

ND+ARO reply, but possibly not including all of this information.
My understanding is that in the WirelessHart case, that the format of this
frame is in the same sensor/acutator format as application layer traffic.

In the 6tisch situation, this is where we would like to insteed start
the DTLS/CoAP session.  Ideally, we'd like like it to be end-to-end, but the
node is not completely on the network, and so it might still require a
proxy.  That *could* be trivially in the form an IPIP header, or it could
more complex.

    > * At this point the joining node transitions to using the run-time
    > link-layer key for all link-layer frames, and the manager unicast
    > session for end-to-end manager traffic. This ends the initial security
    > handshake.

Agreed --- one can imagine that the node might remove the JOIN key from its
MAC, and replaces it with the run-time key, and that might even involve
resetting that chip or something.

    > * Over a number of additional frames, the manager assigns additional
    > sessions, including broadcast sessions, and a unicast session to the
    > Gateway (sink for all data traffic), and additional communications
    > resources, routing information, etc.=C2=A0 There is no explicit trans=
ition
    > from joining to joined - the mote transitions when certain key frames
    > are received.

This is akin to the 6top schedule distribution.

    > * Note that a WirelessHART link-layer frame contains and additional
    > frame type byte and a 4-byte link-layer MIC, on top of the unsecured
    > 15.4 frame.=C2=A0 A network frame contains an additional 16-40 bytes =
of
    > addressing, routing, security and other information.

=2D-
]               Never tell me the odds!                 | ipv6 mesh network=
s [
]   Michael Richardson, Sandelman Software Works        | network architect=
  [
]     mcr@sandelman.ca  http://www.sandelman.ca/        |   ruby on rails  =
  [


=2D-
Michael Richardson <mcr+IETF@sandelman.ca>, Sandelman Software Works
 -=3D IPv6 IoT consulting =3D-




--=-=-=
Content-Type: application/pgp-signature

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iQEVAwUBU4SvxYCLcPvd0N1lAQIMNQgAnD5rDXWhLCpXws5HMikkXF2Z2CBpUpqx
4bkndrI2/mZmLG7Su48CldPFjWBmej537bgG02MmDVoSFOvFmU4pBGugS2VPVwtW
YKIRqSfSwoAWqWlAGTYvQcHozbwRz9Yh/WpwIxTC0z+hP3tlhddqVx8FjSCtHCcS
s12wqDPfh77a0cOSt4CrxtVQU9pd59Wp33zy8Q8scL3HICgZsYubwRyxab9ETY2u
MT90xep5H3HSwyt0kOJgQ8NPAiQrhgzO+L7mg3QumhVCh5Vc7SzIyJhFkxlmRo/K
gjVixv8rcULyYp4tpzIgtkHoEhrhizYyBtV262k6lv23Y3t2WDX12Q==
=nM4W
-----END PGP SIGNATURE-----
--=-=-=--


From nobody Tue May 27 09:11:53 2014
Return-Path: <mcr@sandelman.ca>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 365B51A0186 for <6tisch-security@ietfa.amsl.com>; Tue, 27 May 2014 09:11:51 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.532
X-Spam-Level: 
X-Spam-Status: No, score=-2.532 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RP_MATCHES_RCVD=-0.651, SPF_PASS=-0.001, T_MIME_NO_TEXT=0.01, T_TVD_MIME_NO_HEADERS=0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id jjctTNsnxMjJ for <6tisch-security@ietfa.amsl.com>; Tue, 27 May 2014 09:11:49 -0700 (PDT)
Received: from tuna.sandelman.ca (tuna.sandelman.ca [209.87.252.184]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 775B71A0462 for <6tisch-security@ietf.org>; Tue, 27 May 2014 09:11:49 -0700 (PDT)
Received: from sandelman.ca (obiwan.sandelman.ca [IPv6:2607:f0b0:f:2::247]) by tuna.sandelman.ca (Postfix) with ESMTP id 0B8F920028 for <6tisch-security@ietf.org>; Tue, 27 May 2014 12:14:29 -0400 (EDT)
Received: by sandelman.ca (Postfix, from userid 179) id 4CCCD63B0E; Tue, 27 May 2014 12:11:45 -0400 (EDT)
Received: from sandelman.ca (localhost [127.0.0.1]) by sandelman.ca (Postfix) with ESMTP id 36F6F63B09 for <6tisch-security@ietf.org>; Tue, 27 May 2014 12:11:45 -0400 (EDT)
From: Michael Richardson <mcr+ietf@sandelman.ca>
To: tisch-security <6tisch-security@ietf.org>
X-Attribution: mcr
X-Mailer: MH-E 8.2; nmh 1.3-dev; GNU Emacs 23.4.1
X-Face: $\n1pF)h^`}$H>Hk{L"x@)JS7<%Az}5RyS@k9X%29-lHB$Ti.V>2bi.~ehC0; <'$9xN5Ub# z!G,p`nR&p7Fz@^UXIn156S8.~^@MJ*mMsD7=QFeq%AL4m<nPbLgmtKK-5dC@#:k
MIME-Version: 1.0
Content-Type: multipart/signed; boundary="=-=-="; micalg=pgp-sha1; protocol="application/pgp-signature"
Date: Tue, 27 May 2014 12:11:45 -0400
Message-ID: <9869.1401207105@sandelman.ca>
Sender: mcr@sandelman.ca
Archived-At: http://mailarchive.ietf.org/arch/msg/6tisch-security/MG8X9_3E2nbiB-xECmT2BSmz0O8
Subject: [6tisch-security] issues open
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 27 May 2014 16:11:51 -0000

--=-=-=


When I submitted the tickets, there were some temporary SMTP errors.
But in any case, the tickets aren't going to come to this mailing list.
Here they are:

http://tools.ietf.org/wg/6tisch/trac/ticket/11

http://tools.ietf.org/wg/6tisch/trac/ticket/12

http://tools.ietf.org/wg/6tisch/trac/ticket/13

http://tools.ietf.org/wg/6tisch/trac/ticket/14

http://tools.ietf.org/wg/6tisch/trac/ticket/15

http://tools.ietf.org/wg/6tisch/trac/ticket/16

Please read and comment on them.   Do we have solutions in WG or non-WG
documents?

Are there questions which are not yet resolved.
I would like to claim consensus on using 802.1AR certificates (ticket 16),
but in my opinion, we need a certificate extension to make
draft-pritikin-autonomic work.

--
Michael Richardson <mcr+IETF@sandelman.ca>, Sandelman Software Works
 -= IPv6 IoT consulting =-




--=-=-=
Content-Type: application/pgp-signature

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iQEVAwUBU4S5PoCLcPvd0N1lAQKCtwf+JbC5iXKa6WyOjnPgTBZ6eW3i76g3ST4H
SYbAeAAtsWh7+x95S653C5DKkQtqplDWr8/fQfhyEBGIVIbB4W+H1R/QTK7QUQ9h
gdTlGbziEUetybXTlrTLlqOxf87+McQsTfgUHINAJ91V+RHFyUbOoBkuANv47FSi
B5ux3MnYAVsx+/V05QNqwqaQzKBUORQ3TripBqzDsTrMRBXb/K6RV4Cbv9uSOcKY
ILhWIIGyq/+MCVgxYEW04+comA0ThmkpN0iEGfUtRaOMRG4A7MlmAa/A+ed5UdhC
FETNqvVQkoQG0EcCd8rQ+WHgwkc4y0fm21JtHu+7gi8VG/+VODCr+g==
=6N7M
-----END PGP SIGNATURE-----
--=-=-=--


From nobody Tue May 27 09:39:23 2014
Return-Path: <jsimon@linear.com>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id CE6BA1A01A8 for <6tisch-security@ietfa.amsl.com>; Tue, 27 May 2014 09:39:21 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.2
X-Spam-Level: 
X-Spam-Status: No, score=-4.2 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id xWYlcFAqadQf for <6tisch-security@ietfa.amsl.com>; Tue, 27 May 2014 09:39:19 -0700 (PDT)
Received: from p01c12o141.mxlogic.net (p01c12o141.mxlogic.net [208.65.145.64]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id D511D1A01AF for <6tisch-security@ietf.org>; Tue, 27 May 2014 09:39:16 -0700 (PDT)
Received: from unknown [12.218.215.72] (EHLO smtpauth1.linear.com) by p01c12o141.mxlogic.net(mxl_mta-8.0.0-1) with ESMTP id fafb4835.0.715.00-295.1694.p01c12o141.mxlogic.net (envelope-from <jsimon@linear.com>); Tue, 27 May 2014 10:39:16 -0600 (MDT)
X-MXL-Hash: 5384bfb45bbfb090-4618440e1264af21c77a45ad039aef3ebee9e3f8
Received: from jsimonmacmini.engineering.linear.com (unknown [10.70.48.25]) by smtpauth1.linear.com (Postfix) with ESMTPSA id 5AA44740A0; Tue, 27 May 2014 09:39:09 -0700 (PDT)
Content-Type: text/plain; charset=windows-1252
Mime-Version: 1.0 (Mac OS X Mail 7.3 \(1878.2\))
From: Jonathan Simon <jsimon@linear.com>
In-Reply-To: <32529.1401204680@sandelman.ca>
Date: Tue, 27 May 2014 09:41:12 -0700
Content-Transfer-Encoding: quoted-printable
Message-Id: <A469EA9C-6AB4-4D98-BF8F-FD8CF628DF59@linear.com>
References: <E045AECD98228444A58C61C200AE1BD8416F3AF4@xmb-rcd-x01.cisco.com> <531DD632.2060009@cox.net> <531DDB20.5050600@gmail.com> <10925.1394631496@sandelman.ca> <532069C8.2050005@gmail.com> <23590.1394999032@sandelman.ca> <18106.1395625035@sandelman.ca> <19609.1396839403@sandelman.ca> <11557.1397444260@sandelman.ca> <28192.1398644294@sandelman.ca> <29064.1399255587@sandelman.ca> <19475.1400588783@sandelman.ca> <4903.1401158997@sandelman.ca> <53840205.2070103@gmail.com> <CAJeFcoS3PNFX2obx3uNDJDtH=QvNLmaPhw2R468sNaeqpo8QBQ@mail.gmail.com> <32529.1401204680@sandelman.ca>
To: Michael Richardson <mcr+ietf@sandelman.ca>
X-Mailer: Apple Mail (2.1878.2)
X-AnalysisOut: [v=2.1 cv=AaA/HhnG c=1 sm=1 tr=0 a=glloKNylpeYNumXQcclYyA==]
X-AnalysisOut: [:117 a=glloKNylpeYNumXQcclYyA==:17 a=kxGRWJTf_DYA:10 a=D2_]
X-AnalysisOut: [GN2MmYMYA:10 a=BLceEmwcHowA:10 a=N659UExz7-8A:10 a=MqDINYq]
X-AnalysisOut: [SAAAA:8 a=YlVTAMxIAAAA:8 a=SyYMxH9GAAAA:8 a=48vgC7mUAAAA:8]
X-AnalysisOut: [ a=jAZBiwQmyI1jSaIP70AA:9 a=8dfgveM6c710LqtT:21 a=0RF6iuJb]
X-AnalysisOut: [Kvme4UTv:21 a=pILNOxqGKmIA:10 a=xLpt9-x9cSEA:10 a=lZB815dz]
X-AnalysisOut: [VvQA:10]
X-Spam: [F=0.5000000000; CM=0.500; MH=0.500(2014052717); S=0.200(2014051901)]
X-MAIL-FROM: <jsimon@linear.com>
X-SOURCE-IP: [12.218.215.72]
Archived-At: http://mailarchive.ietf.org/arch/msg/6tisch-security/VON7byf_VtqS4arjR7OxDq1tbjE
Cc: 6tisch-security@ietf.org
Subject: Re: [6tisch-security] wirelessHART/6tisch join process
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 27 May 2014 16:39:21 -0000

Responses inline

>=20
> Jonathan Simon <jsimon@linear.com> wrote:
>> * One or more devices are sending beacons to advertise the presence =
of
>> the network. In WirelessHART, this frame is unencrypted, but
>> authenticated with a well known key.  The beacon contains the current
>> ASN, which the joining device uses to synchronize its clock.
>=20
> I think that this step won't change at all.
> draft-piro-6tisch-security-issues-01 calls this a Partial and Hybrid =
Secure
> Network.

JS - How the joining node trusts the beacon appears to be one of Rene=92s =
questions.  A well-known key allows you to distinguish it from another =
protocol, but it doesn=92t protect you against an attacker. One option =
is generating the key based on one of the preconfigured certs.=20
>=20
>> * Once the joining node has heard a beacon, it continues listening =
for
>> additional beacons for a short specified timeout.
>=20
> You don't explain this part, but one assumes one does this in order =
to:
>  1) perhaps obtain a better (louder) beacon.
>  2) in order to hear the correct (non-malicious beacon) as well.
>=20
> We also need to listen for an RA during some slotted-Aloha period,
> which the beacon(s) would tell us about.

JS - it=92s to hear louder beacons, or beacons from devices closer to =
the manager (coordinator).
>=20
>> * The joining node encrypts a frame containing some HART specific
>> content, including a list of beaconing neighbors it heard in the
>> previous steps. The size of the payload is ~ 60 bytes.  The packet is
>> routed by a "proxy" node - the joining parent. The frame is
>> authenticated using the well-known key, and encrypted using a shared
>> symmetric key known only by the node and the manager.
>=20
> The name for this message is the ND+ARO... That's how things map.
> And the ND+ARO is "routed by a proxy node", exactly the same.
> The frame is authenticated using a public key rather than a well known
> symmetric key.  The message is probably not encrypted.
>=20
> What is the purpose of including the list of beaconing neighbours?

JS - WirelessHART is centrally managed, so the additional connnectivity =
information is there for mesh management.  There is a separate discovery =
process (analogous to ND) in the running network to gather the same =
information, but it is typically slow. =20
>=20
>> * The manager responds with a frame containing the run-time =
link-layer
>> key, the node's new short address (this takes the place of PAN
>> coordinator association), and a unicast session key and starting =
nonce
>> for the manager. This frame is encrypted with the symmetric key. The
>> payload is ~ 60 bytes, and is routed to the proxy for delivery to the
>> joining node - the proxy uses the link-layer well known key on the
>> frame.
>=20
> ND+ARO reply, but possibly not including all of this information.
> My understanding is that in the WirelessHart case, that the format of =
this
> frame is in the same sensor/acutator format as application layer =
traffic.
>=20
> In the 6tisch situation, this is where we would like to insteed start
> the DTLS/CoAP session.  Ideally, we'd like like it to be end-to-end, =
but the
> node is not completely on the network, and so it might still require a
> proxy.  That *could* be trivially in the form an IPIP header, or it =
could
> more complex.
>=20
>> * At this point the joining node transitions to using the run-time
>> link-layer key for all link-layer frames, and the manager unicast
>> session for end-to-end manager traffic. This ends the initial =
security
>> handshake.
>=20
> Agreed --- one can imagine that the node might remove the JOIN key =
from its
> MAC, and replaces it with the run-time key, and that might even =
involve
> resetting that chip or something.
>=20
>> * Over a number of additional frames, the manager assigns additional
>> sessions, including broadcast sessions, and a unicast session to the
>> Gateway (sink for all data traffic), and additional communications
>> resources, routing information, etc.  There is no explicit transition
>> from joining to joined - the mote transitions when certain key frames
>> are received.
>=20
> This is akin to the 6top schedule distribution.
>=20
>> * Note that a WirelessHART link-layer frame contains and additional
>> frame type byte and a 4-byte link-layer MIC, on top of the unsecured
>> 15.4 frame.  A network frame contains an additional 16-40 bytes of
>> addressing, routing, security and other information.
>=20
> --
> ]               Never tell me the odds!                 | ipv6 mesh =
networks [
> ]   Michael Richardson, Sandelman Software Works        | network =
architect  [
> ]     mcr@sandelman.ca  =
http://cp.mcafee.com/d/5fHCMUe6wUqdEInhjKMUqekjtPqbwVBcSyUepvdEK3zhOyCOqej=
rzPPPz5XCN6ABqM1hYEvIundDOx-NVsSCwXH3Pb_nVWZPhPRXBQSn7-hjjujVqWtAkRrCzAtOE=
uvkzaT0QSyrhdTV5xdVYsyMCqejtPo0aCMgYZnotrsdKjBiNcLjXdNBcIn8lrxrW0GnPtU02rd=
79EVjhdCBJOsGm9BWvpKcFBziWq834E-vZa1sg1o9NOsGm9Cy0hHa1EwmzmTQErvKr1ZiF   =
     |   ruby on rails    [
>=20
>=20
> --
> Michael Richardson <mcr+IETF@sandelman.ca>, Sandelman Software Works
> -=3D IPv6 IoT consulting =3D-
>=20
>=20
>=20
> _______________________________________________
> 6tisch-security mailing list
> 6tisch-security@ietf.org
> =
http://cp.mcafee.com/d/1jWVIpdEInhjKMUqekjtPqbwVBcSyUepvdEK3zhOyCOqejrzPPP=
z5XCN6ABqM1hYEvIundDOx-NVsSCwXH3Pb_nVWZPhPRXBQSn7-hjjujVqWtAkRrCzAtOEuvkza=
T0QSyrhdTV5xdVYsyMCqejtPpesRG9pxjFvdTw0e2qKMM-l9OwXn79OFoCnFZCUOCmdKjBiNcL=
jXdNBcIn8lrxrW0GnPtU02rd79EVjhdCBJOsGm9BWvpKcFBziWq834E-vZa1sg1o9NOsGm9Cy0=
hHa1EwmzmTQErvKrU8X-yrFc


From nobody Tue May 27 12:59:01 2014
Return-Path: <mcr@sandelman.ca>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id C77EA1A0762 for <6tisch-security@ietfa.amsl.com>; Tue, 27 May 2014 12:58:59 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.542
X-Spam-Level: 
X-Spam-Status: No, score=-2.542 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RP_MATCHES_RCVD=-0.651, SPF_PASS=-0.001, T_TVD_MIME_NO_HEADERS=0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id islvuwYcaKfw for <6tisch-security@ietfa.amsl.com>; Tue, 27 May 2014 12:58:58 -0700 (PDT)
Received: from tuna.sandelman.ca (tuna.sandelman.ca [209.87.252.184]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 560CD1A0676 for <6tisch-security@ietf.org>; Tue, 27 May 2014 12:58:58 -0700 (PDT)
Received: from sandelman.ca (obiwan.sandelman.ca [IPv6:2607:f0b0:f:2::247]) by tuna.sandelman.ca (Postfix) with ESMTP id 6592320028; Tue, 27 May 2014 16:01:35 -0400 (EDT)
Received: by sandelman.ca (Postfix, from userid 179) id 5B7C663B0E; Tue, 27 May 2014 15:58:50 -0400 (EDT)
Received: from sandelman.ca (localhost [127.0.0.1]) by sandelman.ca (Postfix) with ESMTP id 44CCF63B09; Tue, 27 May 2014 15:58:50 -0400 (EDT)
From: Michael Richardson <mcr+ietf@sandelman.ca>
To: "6tisch-security\@ietf.org" <6tisch-security@ietf.org>, Rene Struik <rstruik.ext@gmail.com>
In-Reply-To: <53849841.4020401@gmail.com>
References: <E045AECD98228444A58C61C200AE1BD8416F3AF4@xmb-rcd-x01.cisco.com> <bomn1n01Q3zUFux01ompsd> <531DD632.2060009@cox.net> <531DDB20.5050600@gmail.com> <10925.1394631496@sandelman.ca> <532069C8.2050005@gmail.com> <23590.1394999032@sandelman.ca> <18106.1395625035@sandelman.ca> <19609.1396839403@sandelman.ca> <11557.1397444260@sandelman.ca> <28192.1398644294@sandelman.ca> <29064.1399255587@sandelman.ca> <19475.1400588783@sandelman.ca> <4903.1401158997@sandelman.ca> <53840205.2070103@gmail.com> <5384046A.6080706@gmail.com> <E045AECD98228444A58C61C200AE1BD8426B036B@xmb-rcd-x01.cisco.com> <10436.1401198298@sandelman.ca> <53849841.4020401@gmail.com>
X-Mailer: MH-E 8.2; nmh 1.3-dev; GNU Emacs 23.4.1
X-Face: $\n1pF)h^`}$H>Hk{L"x@)JS7<%Az}5RyS@k9X%29-lHB$Ti.V>2bi.~ehC0; <'$9xN5Ub# z!G,p`nR&p7Fz@^UXIn156S8.~^@MJ*mMsD7=QFeq%AL4m<nPbLgmtKK-5dC@#:k
MIME-Version: 1.0
Content-Type: multipart/signed; boundary="=-=-="; micalg=pgp-sha1; protocol="application/pgp-signature"
Date: Tue, 27 May 2014 15:58:50 -0400
Message-ID: <25059.1401220730@sandelman.ca>
Sender: mcr@sandelman.ca
Archived-At: http://mailarchive.ietf.org/arch/msg/6tisch-security/JPsXDLK94j1tKRz0sEqdLG8Q2Q0
Subject: Re: [6tisch-security] agenda for 2014-05-27 6tisch security call
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 27 May 2014 19:59:00 -0000

--=-=-=


Rene Struik <rstruik.ext@gmail.com> wrote:
    > Can I read up on ARO and DTLS/CoAP in preparation for the call?

1) ARO is described in rfc6775.  It is an LLN extension to ND (including DAD),
   only without a requirement to multicast, or for all nodes to be listening.

2) draft-sarikaya-ace-cga-nd-01 describes adapting SEND to be more LLN
   happy.  Basically, ECDSA signatures on the ARO.

3) DTLS is described in rfc4347 and DTLS 1.2 [RFC6347], but really,
   you'll want to read some of the DICE drafts at:
   http://datatracker.ietf.org/wg/dice/
   the draft-ietf-dice-profile, but you may want to go deeper.
   We don't need to design any new cryptographic protocols or operations;
   we have a wealth of them already, we just need to explain how to use them.

4) CoAP is http://datatracker.ietf.org/doc/draft-ietf-core-coap/
   but, really, what is important is that the 6top API will use it:
   http://datatracker.ietf.org/doc/draft-ietf-6tisch-coap/

So regardless of what we might do, we can assume that the following
things will already be required, and code space will be allocated:
  1) IPv6 with 6lowpan-ND (ARO, etc.)
  2) DTLS + CoAP with some kind of authentication system.

That means the code space for DTLS and CoAP is free.  Anything else we
do will come with a code space impact.  Clearly, we may have a ram usage
impact as well, if we create many new DTLS sessions, and perhaps a custom
solution could use less ram, at least in principal.

If we specify a series of security objects, then it will map directly into
the /6t space that 6tisch-coap is creating and managing.  This is what
WirelessHART does.

--
Michael Richardson <mcr+IETF@sandelman.ca>, Sandelman Software Works
 -= IPv6 IoT consulting =-




--=-=-=
Content-Type: application/pgp-signature

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iQEVAwUBU4TudoCLcPvd0N1lAQLFDAgAjnyfldYBiB0Vg53Z+jtG0kMF69bv2f+I
MRG8NDpDE21O9zhGguv344DESYBeQStpO4VaqwFfYxIu5IqKEPOQVLZUYYbnzfYi
K3nW3lqgODZPeuPiNXzQJ4/f+8v32QTuUXTJL32y2sAdTbOsufwDYcz21+L2rSXL
oog3sGtg4kIm7wg9wQPkiIW6o+J8vFJB9iUIKNiWnYZDy7ONKpcriCkc1Dhwo7YS
ekLZf7PnzGHipnnwlpIjXJaYN7+yYjbA9aud6c0z7yjhPwMYSvMktNuzJMeHh1UA
TMNniyD/Anhdq8aKNca+G2/JLUAStoxJp6SN68KTrtdV2D9eb1T0Mw==
=tUV3
-----END PGP SIGNATURE-----
--=-=-=--


From nobody Tue May 27 14:05:38 2014
Return-Path: <rstruik.ext@gmail.com>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 686341A06B4 for <6tisch-security@ietfa.amsl.com>; Tue, 27 May 2014 14:05:36 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.999
X-Spam-Level: 
X-Spam-Status: No, score=-1.999 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id l5pYxnMK_Rvd for <6tisch-security@ietfa.amsl.com>; Tue, 27 May 2014 14:05:34 -0700 (PDT)
Received: from mail-ie0-x232.google.com (mail-ie0-x232.google.com [IPv6:2607:f8b0:4001:c03::232]) (using TLSv1 with cipher ECDHE-RSA-RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 7E5261A0698 for <6tisch-security@ietf.org>; Tue, 27 May 2014 14:05:34 -0700 (PDT)
Received: by mail-ie0-f178.google.com with SMTP id rl12so9100752iec.23 for <6tisch-security@ietf.org>; Tue, 27 May 2014 14:05:31 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113;  h=message-id:date:from:user-agent:mime-version:to:subject:references :in-reply-to:content-type; bh=HdV+diR3JbUnmkVucf0gVsNHGn8Q+UVrPk+eqSIti6c=; b=kjgQWS6ppyFzc/HiOk9iCMkgsjUBNLM+mQA6H8raqim7iED+o0AUG6ayZ2uv1/H0y7 aG0/MbJbHQUfqI4rT2DIHd1Bx4w3VDWom4dA4IuPDQ/Iywa0HNDBAef9JfD6/bQchngb zL3upPfEf1gtuizLtgg79+7r2JqPOJpgUtP2eqagfYtnz+v4Hx38Bkq3FlHr9AQichQC Z75BX4nGwcila7SoCQhZ4Ks/ULb8G5nZS4U2iphqur9Lh/pFJhEjaodQH0LF5xRKsAky KgM7fGdY9QGt946CdzjkKTFEjnMOaHXmj+NXheDn9FSyD5XFH4+EZkT2CEzTtmZZZ/kj rdlQ==
X-Received: by 10.50.79.161 with SMTP id k1mr37833605igx.31.1401224729882; Tue, 27 May 2014 14:05:29 -0700 (PDT)
Received: from [192.168.1.101] (CPE0013100e2c51-CM001cea35caa6.cpe.net.cable.rogers.com. [99.231.3.110]) by mx.google.com with ESMTPSA id nk1sm10386418igb.0.2014.05.27.14.05.28 for <6tisch-security@ietf.org> (version=TLSv1 cipher=ECDHE-RSA-RC4-SHA bits=128/128); Tue, 27 May 2014 14:05:29 -0700 (PDT)
Message-ID: <5384FE17.3000007@gmail.com>
Date: Tue, 27 May 2014 17:05:27 -0400
From: Rene Struik <rstruik.ext@gmail.com>
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:24.0) Gecko/20100101 Thunderbird/24.5.0
MIME-Version: 1.0
To: tisch-security <6tisch-security@ietf.org>
References: <5384FBB0.3040900@gmail.com>
In-Reply-To: <5384FBB0.3040900@gmail.com>
X-Forwarded-Message-Id: <5384FBB0.3040900@gmail.com>
Content-Type: multipart/alternative; boundary="------------040707070008030702000506"
Archived-At: http://mailarchive.ietf.org/arch/msg/6tisch-security/f_jd8yD3JN5YEWM306w7yfu99dU
Subject: [6tisch-security] Fwd: question on draft-kumar-dice-dtls-relay-01
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 27 May 2014 21:05:36 -0000

This is a multi-part message in MIME format.
--------------040707070008030702000506
Content-Type: text/plain; charset=ISO-8859-1; format=flowed
Content-Transfer-Encoding: 7bit

Of potential interest to 6TiSCH security people as well.

-------- Original Message --------
Subject: 	question on draft-kumar-dice-dtls-relay-01
Date: 	Tue, 27 May 2014 16:55:12 -0400
From: 	Rene Struik <rstruik.ext@gmail.com>
To: 	dtls-iot@ietf.org <dtls-iot@ietf.org>



Dear Sandeep, Oscar, Sye Loong:

I read draft-kumar-dice-dtls-relay-01 a few days ago. In the security
considerations section of that draft, you allude to potential denial of
services attacks in the context where a one-hop neighbor of a joining
node facilitates messaging between that joining node and the network
manager potentially many hops away, where the joining node and the
network manager act as DTLS Client and DTLS Server, respectively, and
where the one-hop neighbor acts as DTLS Relay. You also suggest some
measures to thwart/limit denial of service attack risk.

I would be curious as to whether you could provide some more insight as
to what type of denial of service attack you counter and how the DTLS
Relay "on/off switch" would work in practice. How would one detect a
potential DoS attack and turn on the "DTLS Relay on/off" knobs to
counter an influx of bogus join protocol messages that could be
amplified if this would travel to the network manager (in a scenario
where both are many hops away from each other)? Since with DTLS, client
authentication only happens in the third protocol flow, it seems that by
necessity one has to allow three subsequent message flows (key
establishment messages from client to server and back, key confirmation
message from client to server), without the DTLS Relay element having a
mechanism (except for throttling) to cryptographically arbitrage these
flows.

When does the newbee device get configuration info and, e.g., a routable
address assigned?

If you could expand on this scenario, that would be great.

Best regards, Rene



[excerpt from draft-kumar-dice-dtls-relay-01]
5. Security Considerations
Additional security considerations need to be taken into account about
forwarding of messages from devices through a network to which it has
not yet been admitted. This can lead to denial-of-service attacks or
misuse of network resources without proper authentication. One way to
overcome any large scale misuse of the network is to have a management
message from the Controller that initiates already authenticated devices
in the network to enter into a DTLS Relay mode. The devices can stay
such a Relay mode for a fixed period of time or until the Controller
sends a new management message blocking the DTLS Relay mode in all
devices in the network. This is often possible since the administrator
of the network can be aware when new devices join the network either
because of the "Introduction" phase or commissioning phase. Other
mechanisms based on IP destination filtering can be applied by the
controller to all Relay nodes to avoid misuse of the network resources.

-- 
email: rstruik.ext@gmail.com | Skype: rstruik
cell: +1 (647) 867-5658 | US: +1 (415) 690-7363







--------------040707070008030702000506
Content-Type: text/html; charset=ISO-8859-1
Content-Transfer-Encoding: 7bit

<html>
  <head>

    <meta http-equiv="content-type" content="text/html; charset=ISO-8859-1">
  </head>
  <body bgcolor="#FFFFFF" text="#000000">
    Of potential interest to 6TiSCH security people as well.<br>
    <div class="moz-forward-container"><br>
      -------- Original Message --------
      <table class="moz-email-headers-table" cellpadding="0"
        cellspacing="0" border="0">
        <tbody>
          <tr>
            <th align="RIGHT" nowrap="nowrap" valign="BASELINE">Subject:
            </th>
            <td>question on draft-kumar-dice-dtls-relay-01</td>
          </tr>
          <tr>
            <th align="RIGHT" nowrap="nowrap" valign="BASELINE">Date: </th>
            <td>Tue, 27 May 2014 16:55:12 -0400</td>
          </tr>
          <tr>
            <th align="RIGHT" nowrap="nowrap" valign="BASELINE">From: </th>
            <td>Rene Struik <a class="moz-txt-link-rfc2396E" href="mailto:rstruik.ext@gmail.com">&lt;rstruik.ext@gmail.com&gt;</a></td>
          </tr>
          <tr>
            <th align="RIGHT" nowrap="nowrap" valign="BASELINE">To: </th>
            <td><a class="moz-txt-link-abbreviated" href="mailto:dtls-iot@ietf.org">dtls-iot@ietf.org</a> <a class="moz-txt-link-rfc2396E" href="mailto:dtls-iot@ietf.org">&lt;dtls-iot@ietf.org&gt;</a></td>
          </tr>
        </tbody>
      </table>
      <br>
      <br>
      <pre>Dear Sandeep, Oscar, Sye Loong:

I read draft-kumar-dice-dtls-relay-01 a few days ago. In the security
considerations section of that draft, you allude to potential denial of
services attacks in the context where a one-hop neighbor of a joining
node facilitates messaging between that joining node and the network
manager potentially many hops away, where the joining node and the
network manager act as DTLS Client and DTLS Server, respectively, and
where the one-hop neighbor acts as DTLS Relay. You also suggest some
measures to thwart/limit denial of service attack risk.

I would be curious as to whether you could provide some more insight as
to what type of denial of service attack you counter and how the DTLS
Relay "on/off switch" would work in practice. How would one detect a
potential DoS attack and turn on the "DTLS Relay on/off" knobs to
counter an influx of bogus join protocol messages that could be
amplified if this would travel to the network manager (in a scenario
where both are many hops away from each other)? Since with DTLS, client
authentication only happens in the third protocol flow, it seems that by
necessity one has to allow three subsequent message flows (key
establishment messages from client to server and back, key confirmation
message from client to server), without the DTLS Relay element having a
mechanism (except for throttling) to cryptographically arbitrage these
flows.

When does the newbee device get configuration info and, e.g., a routable
address assigned?

If you could expand on this scenario, that would be great.

Best regards, Rene



[excerpt from draft-kumar-dice-dtls-relay-01]
5. Security Considerations
Additional security considerations need to be taken into account about
forwarding of messages from devices through a network to which it has
not yet been admitted. This can lead to denial-of-service attacks or
misuse of network resources without proper authentication. One way to
overcome any large scale misuse of the network is to have a management
message from the Controller that initiates already authenticated devices
in the network to enter into a DTLS Relay mode. The devices can stay
such a Relay mode for a fixed period of time or until the Controller
sends a new management message blocking the DTLS Relay mode in all
devices in the network. This is often possible since the administrator
of the network can be aware when new devices join the network either
because of the "Introduction" phase or commissioning phase. Other
mechanisms based on IP destination filtering can be applied by the
controller to all Relay nodes to avoid misuse of the network resources.

-- 
email: <a class="moz-txt-link-abbreviated" href="mailto:rstruik.ext@gmail.com">rstruik.ext@gmail.com</a> | Skype: rstruik
cell: +1 (647) 867-5658 | US: +1 (415) 690-7363




</pre>
      <br>
    </div>
    <br>
  </body>
</html>

--------------040707070008030702000506--


From nobody Tue May 27 14:15:56 2014
Return-Path: <rstruik.ext@gmail.com>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 377B91A06FE for <6tisch-security@ietfa.amsl.com>; Tue, 27 May 2014 14:15:55 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2
X-Spam-Level: 
X-Spam-Status: No, score=-2 tagged_above=-999 required=5 tests=[BAYES_00=-1.9,  DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id OiqEC0Dz02ep for <6tisch-security@ietfa.amsl.com>; Tue, 27 May 2014 14:15:53 -0700 (PDT)
Received: from mail-ig0-x235.google.com (mail-ig0-x235.google.com [IPv6:2607:f8b0:4001:c05::235]) (using TLSv1 with cipher ECDHE-RSA-RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id A42301A0428 for <6tisch-security@ietf.org>; Tue, 27 May 2014 14:15:53 -0700 (PDT)
Received: by mail-ig0-f181.google.com with SMTP id h3so1658093igd.2 for <6tisch-security@ietf.org>; Tue, 27 May 2014 14:15:50 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113;  h=message-id:date:from:user-agent:mime-version:to:subject:references :in-reply-to:content-type:content-transfer-encoding; bh=wUOq65KWLD6MV3SGpoiQaXyziD3O8440lbLsIO/3zHM=; b=Q3tY84QENcDV7fpRHyXpdlvfR5NzSKzzhjktxTkqsALoU5u62NVrcn1xgo736RmdkR POF86BrgrvSHClE8G8E9fyxaFjl13/tK/0Fh2Wlm19AW/3U+fwLwq0a2ltZL8tU2VnlT 4bcOUVW4kmbG880RtD6fVXk9jAoKXLjLPkKm8j/q01nU4taz2mcigGutHytQMqkvyT15 LxRVk5MtODPMcJwUq3BGB4nUd72kW/uyk3/Hzl88t19IMdVlQZsxVEQCFysuHJ8gjmYW g5JLMCIRhlNv0sZCw3YZe9Fg+KE1QisSuaJtlIZJVOhaRC8u1UwxZw6/Nzar3U1qReE/ 1jUg==
X-Received: by 10.50.122.67 with SMTP id lq3mr37569900igb.8.1401225350208; Tue, 27 May 2014 14:15:50 -0700 (PDT)
Received: from [192.168.1.101] (CPE0013100e2c51-CM001cea35caa6.cpe.net.cable.rogers.com. [99.231.3.110]) by mx.google.com with ESMTPSA id t16sm7904415igr.14.2014.05.27.14.15.49 for <multiple recipients> (version=TLSv1 cipher=ECDHE-RSA-RC4-SHA bits=128/128); Tue, 27 May 2014 14:15:49 -0700 (PDT)
Message-ID: <53850083.9040005@gmail.com>
Date: Tue, 27 May 2014 17:15:47 -0400
From: Rene Struik <rstruik.ext@gmail.com>
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:24.0) Gecko/20100101 Thunderbird/24.5.0
MIME-Version: 1.0
To: Michael Richardson <mcr+ietf@sandelman.ca>,  "6tisch-security@ietf.org" <6tisch-security@ietf.org>
References: <E045AECD98228444A58C61C200AE1BD8416F3AF4@xmb-rcd-x01.cisco.com> <bomn1n01Q3zUFux01ompsd> <531DD632.2060009@cox.net> <531DDB20.5050600@gmail.com> <10925.1394631496@sandelman.ca> <532069C8.2050005@gmail.com> <23590.1394999032@sandelman.ca> <18106.1395625035@sandelman.ca> <19609.1396839403@sandelman.ca> <11557.1397444260@sandelman.ca> <28192.1398644294@sandelman.ca> <29064.1399255587@sandelman.ca> <19475.1400588783@sandelman.ca> <4903.1401158997@sandelman.ca> <53840205.2070103@gmail.com> <5384046A.6080706@gmail.com> <E045AECD98228444A58C61C200AE1BD8426B036B@xmb-rcd-x01.cisco.com> <10436.1401198298@sandelman.ca> <53849841.4020401@gmail.com> <25059.1401220730@sandelman.ca>
In-Reply-To: <25059.1401220730@sandelman.ca>
Content-Type: text/plain; charset=ISO-8859-1; format=flowed
Content-Transfer-Encoding: 7bit
Archived-At: http://mailarchive.ietf.org/arch/msg/6tisch-security/Qyy1M5XgTA3uyNbhVzNsiKOlpkY
Subject: Re: [6tisch-security] agenda for 2014-05-27 6tisch security call
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 27 May 2014 21:15:55 -0000

Hi Michael:

Thanks for the references. Sorry - I have seen most of this stuff, but 
get easily confused by alphabet soup acronyms (which I have problems 
remembering).

Best regards, Rene

On 5/27/2014 3:58 PM, Michael Richardson wrote:
> Rene Struik <rstruik.ext@gmail.com> wrote:
>      > Can I read up on ARO and DTLS/CoAP in preparation for the call?
>
> 1) ARO is described in rfc6775.  It is an LLN extension to ND (including DAD),
>     only without a requirement to multicast, or for all nodes to be listening.
>
> 2) draft-sarikaya-ace-cga-nd-01 describes adapting SEND to be more LLN
>     happy.  Basically, ECDSA signatures on the ARO.
>
> 3) DTLS is described in rfc4347 and DTLS 1.2 [RFC6347], but really,
>     you'll want to read some of the DICE drafts at:
>     http://datatracker.ietf.org/wg/dice/
>     the draft-ietf-dice-profile, but you may want to go deeper.
>     We don't need to design any new cryptographic protocols or operations;
>     we have a wealth of them already, we just need to explain how to use them.
>
> 4) CoAP is http://datatracker.ietf.org/doc/draft-ietf-core-coap/
>     but, really, what is important is that the 6top API will use it:
>     http://datatracker.ietf.org/doc/draft-ietf-6tisch-coap/
>
> So regardless of what we might do, we can assume that the following
> things will already be required, and code space will be allocated:
>    1) IPv6 with 6lowpan-ND (ARO, etc.)
>    2) DTLS + CoAP with some kind of authentication system.
>
> That means the code space for DTLS and CoAP is free.  Anything else we
> do will come with a code space impact.  Clearly, we may have a ram usage
> impact as well, if we create many new DTLS sessions, and perhaps a custom
> solution could use less ram, at least in principal.
>
> If we specify a series of security objects, then it will map directly into
> the /6t space that 6tisch-coap is creating and managing.  This is what
> WirelessHART does.
>
> --
> Michael Richardson <mcr+IETF@sandelman.ca>, Sandelman Software Works
>   -= IPv6 IoT consulting =-
>
>
>


-- 
email: rstruik.ext@gmail.com | Skype: rstruik
cell: +1 (647) 867-5658 | US: +1 (415) 690-7363


From nobody Tue May 27 23:19:07 2014
Return-Path: <yoshihiro.ohba@toshiba.co.jp>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 98E941A0365 for <6tisch-security@ietfa.amsl.com>; Tue, 27 May 2014 23:19:05 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -3.052
X-Spam-Level: 
X-Spam-Status: No, score=-3.052 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HELO_EQ_JP=1.244, HOST_EQ_JP=1.265, HTML_MESSAGE=0.001, HTTPS_HTTP_MISMATCH=1.989, RCVD_IN_DNSWL_HI=-5, RP_MATCHES_RCVD=-0.651, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001, UNPARSEABLE_RELAY=0.001, WEIRD_PORT=0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id IlqaqwOF_MAv for <6tisch-security@ietfa.amsl.com>; Tue, 27 May 2014 23:19:02 -0700 (PDT)
Received: from imx12.toshiba.co.jp (imx12.toshiba.co.jp [61.202.160.132]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id D0F401A0357 for <6tisch-security@ietf.org>; Tue, 27 May 2014 23:19:01 -0700 (PDT)
Received: from arc11.toshiba.co.jp ([133.199.90.127]) by imx12.toshiba.co.jp  with ESMTP id s4S6Irju026154; Wed, 28 May 2014 15:18:53 +0900 (JST)
Received: (from root@localhost) by arc11.toshiba.co.jp  id s4S6IrnW011165; Wed, 28 May 2014 15:18:53 +0900 (JST)
Received: from ovp11.toshiba.co.jp [133.199.90.148]  by arc11.toshiba.co.jp with ESMTP id RAA11164; Wed, 28 May 2014 15:18:53 +0900
Received: from mx12.toshiba.co.jp (localhost [127.0.0.1]) by ovp11.toshiba.co.jp  with ESMTP id s4S6Ir59002663; Wed, 28 May 2014 15:18:53 +0900 (JST)
Received: from TGXML207.toshiba.local by toshiba.co.jp id s4S6Iic5003572; Wed, 28 May 2014 15:18:44 +0900 (JST)
Received: from TGXML210.toshiba.local ([169.254.4.46]) by TGXML207.toshiba.local ([133.199.70.16]) with mapi id 14.03.0181.006; Wed, 28 May 2014 15:18:44 +0900
From: <yoshihiro.ohba@toshiba.co.jp>
To: <jsimon@linear.com>, <rstruik.ext@gmail.com>
Thread-Topic: [6tisch-security] agenda for 2014-05-27 6tisch security call
Thread-Index: AQHPeVZhw54BHDP0SE+00Qrnll9n8JtTKLqAgACwMoCAAayJwA==
Date: Wed, 28 May 2014 06:18:43 +0000
Message-ID: <674F70E5F2BE564CB06B6901FD3DD78B2723B576@TGXML210.toshiba.local>
References: <E045AECD98228444A58C61C200AE1BD8416F3AF4@xmb-rcd-x01.cisco.com> <531DD632.2060009@cox.net> <531DDB20.5050600@gmail.com> <10925.1394631496@sandelman.ca> <532069C8.2050005@gmail.com> <23590.1394999032@sandelman.ca> <18106.1395625035@sandelman.ca> <19609.1396839403@sandelman.ca> <11557.1397444260@sandelman.ca> <28192.1398644294@sandelman.ca> <29064.1399255587@sandelman.ca> <19475.1400588783@sandelman.ca> <4903.1401158997@sandelman.ca> <53840205.2070103@gmail.com> <CAJeFcoS3PNFX2obx3uNDJDtH=QvNLmaPhw2R468sNaeqpo8QBQ@mail.gmail.com>
In-Reply-To: <CAJeFcoS3PNFX2obx3uNDJDtH=QvNLmaPhw2R468sNaeqpo8QBQ@mail.gmail.com>
Accept-Language: ja-JP, en-US
Content-Language: ja-JP
x-originating-ip: [133.196.20.156]
msscp.transfermailtomossagent: 103
Content-Type: multipart/alternative; boundary="_000_674F70E5F2BE564CB06B6901FD3DD78B2723B576TGXML210toshiba_"
MIME-Version: 1.0
Archived-At: http://mailarchive.ietf.org/arch/msg/6tisch-security/yPrGc5mJ1aCs1T8OVWu6Fgo2wt0
Cc: mcr+ietf@sandelman.ca, 6tisch-security@ietf.org
Subject: Re: [6tisch-security] agenda for 2014-05-27 6tisch security call
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 28 May 2014 06:19:05 -0000

--_000_674F70E5F2BE564CB06B6901FD3DD78B2723B576TGXML210toshiba_
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: base64

SGkgSm9uYXRoYW4sDQoNClRoYW5rIHlvdSBmb3Igc2VuZGluZyB0aGUgc3VtbWFyeSBvZiB3L0hB
UlQgam9pbmluZy4NCg0KSSBoYXZlIHF1ZXN0aW9uLg0KDQpJbiB3L0hBUlQsIGFyZSBhbGwgYmVh
Y29uIGZyYW1lcyBhdXRoZW50aWNhdGVkIHdpdGggYSB3ZWxsLWtub3duIGtleSBldmVuIGFmdGVy
IGEgam9pbmluZyBub2RlIG9idGFpbmVkIHRoZSBydW50aW1lIGxpbmsgbGF5ZXIga2V5Pw0KDQpS
ZWdhcmRzLA0KWW9zaGloaXJvIE9oYmENCg0KDQoNCg0KRnJvbTogNnRpc2NoLXNlY3VyaXR5IFtt
YWlsdG86NnRpc2NoLXNlY3VyaXR5LWJvdW5jZXNAaWV0Zi5vcmddIE9uIEJlaGFsZiBPZiBKb25h
dGhhbiBTaW1vbg0KU2VudDogVHVlc2RheSwgTWF5IDI3LCAyMDE0IDEwOjQxIFBNDQpUbzogUmVu
ZSBTdHJ1aWsNCkNjOiBNaWNoYWVsIFJpY2hhcmRzb247IDZ0aXNjaC1zZWN1cml0eUBpZXRmLm9y
Zw0KU3ViamVjdDogUmU6IFs2dGlzY2gtc2VjdXJpdHldIGFnZW5kYSBmb3IgMjAxNC0wNS0yNyA2
dGlzY2ggc2VjdXJpdHkgY2FsbA0KDQpSZW5lIGhhZCBhc2tlZCBvbiBhIHByZXZpb3VzIGNhbGwg
Zm9yIHNvbWVvbmUgdG8gc3VtbWFyaXplIFdpcmVsZXNzSEFSVCBqb2luaW5nIC0gaGVyZSB5b3Ug
Z28uDQoNCiogT25lIG9yIG1vcmUgZGV2aWNlcyBhcmUgc2VuZGluZyBiZWFjb25zIHRvIGFkdmVy
dGlzZSB0aGUgcHJlc2VuY2Ugb2YgdGhlIG5ldHdvcmsuIEluIFdpcmVsZXNzSEFSVCwgdGhpcyBm
cmFtZSBpcyB1bmVuY3J5cHRlZCwgYnV0IGF1dGhlbnRpY2F0ZWQgd2l0aCBhIHdlbGwga25vd24g
a2V5LiAgVGhlIGJlYWNvbiBjb250YWlucyB0aGUgY3VycmVudCBBU04sIHdoaWNoIHRoZSBqb2lu
aW5nIGRldmljZSB1c2VzIHRvIHN5bmNocm9uaXplIGl0cyBjbG9jay4NCiogT25jZSB0aGUgam9p
bmluZyBub2RlIGhhcyBoZWFyZCBhIGJlYWNvbiwgaXQgY29udGludWVzIGxpc3RlbmluZyBmb3Ig
YWRkaXRpb25hbCBiZWFjb25zIGZvciBhIHNob3J0IHNwZWNpZmllZCB0aW1lb3V0Lg0KKiBUaGUg
am9pbmluZyBub2RlIGVuY3J5cHRzIGEgZnJhbWUgY29udGFpbmluZyBzb21lIEhBUlQgc3BlY2lm
aWMgY29udGVudCwgaW5jbHVkaW5nIGEgbGlzdCBvZiBiZWFjb25pbmcgbmVpZ2hib3JzIGl0IGhl
YXJkIGluIHRoZSBwcmV2aW91cyBzdGVwcy4gVGhlIHNpemUgb2YgdGhlIHBheWxvYWQgaXMgfiA2
MCBieXRlcy4gIFRoZSBwYWNrZXQgaXMgcm91dGVkIGJ5IGEgInByb3h5IiBub2RlIC0gdGhlIGpv
aW5pbmcgcGFyZW50LiBUaGUgZnJhbWUgaXMgYXV0aGVudGljYXRlZCB1c2luZyB0aGUgd2VsbC1r
bm93biBrZXksIGFuZCBlbmNyeXB0ZWQgdXNpbmcgYSBzaGFyZWQgc3ltbWV0cmljIGtleSBrbm93
biBvbmx5IGJ5IHRoZSBub2RlIGFuZCB0aGUgbWFuYWdlci4NCg0KKiBUaGUgbWFuYWdlciByZXNw
b25kcyB3aXRoIGEgZnJhbWUgY29udGFpbmluZyB0aGUgcnVuLXRpbWUgbGluay1sYXllciBrZXks
IHRoZSBub2RlJ3MgbmV3IHNob3J0IGFkZHJlc3MgKHRoaXMgdGFrZXMgdGhlIHBsYWNlIG9mIFBB
TiBjb29yZGluYXRvciBhc3NvY2lhdGlvbiksIGFuZCBhIHVuaWNhc3Qgc2Vzc2lvbiBrZXkgYW5k
IHN0YXJ0aW5nIG5vbmNlIGZvciB0aGUgbWFuYWdlci4gVGhpcyBmcmFtZSBpcyBlbmNyeXB0ZWQg
d2l0aCB0aGUgc3ltbWV0cmljIGtleS4gVGhlIHBheWxvYWQgaXMgfiA2MCBieXRlcywgYW5kIGlz
IHJvdXRlZCB0byB0aGUgcHJveHkgZm9yIGRlbGl2ZXJ5IHRvIHRoZSBqb2luaW5nIG5vZGUgLSB0
aGUgcHJveHkgdXNlcyB0aGUgbGluay1sYXllciB3ZWxsIGtub3duIGtleSBvbiB0aGUgZnJhbWUu
DQoqIEF0IHRoaXMgcG9pbnQgdGhlIGpvaW5pbmcgbm9kZSB0cmFuc2l0aW9ucyB0byB1c2luZyB0
aGUgcnVuLXRpbWUgbGluay1sYXllciBrZXkgZm9yIGFsbCBsaW5rLWxheWVyIGZyYW1lcywgYW5k
IHRoZSBtYW5hZ2VyIHVuaWNhc3Qgc2Vzc2lvbiBmb3IgZW5kLXRvLWVuZCBtYW5hZ2VyIHRyYWZm
aWMuIFRoaXMgZW5kcyB0aGUgaW5pdGlhbCBzZWN1cml0eSBoYW5kc2hha2UuDQoqIE92ZXIgYSBu
dW1iZXIgb2YgYWRkaXRpb25hbCBmcmFtZXMsIHRoZSBtYW5hZ2VyIGFzc2lnbnMgYWRkaXRpb25h
bCBzZXNzaW9ucywgaW5jbHVkaW5nIGJyb2FkY2FzdCBzZXNzaW9ucywgYW5kIGEgdW5pY2FzdCBz
ZXNzaW9uIHRvIHRoZSBHYXRld2F5IChzaW5rIGZvciBhbGwgZGF0YSB0cmFmZmljKSwgYW5kIGFk
ZGl0aW9uYWwgY29tbXVuaWNhdGlvbnMgcmVzb3VyY2VzLCByb3V0aW5nIGluZm9ybWF0aW9uLCBl
dGMuICBUaGVyZSBpcyBubyBleHBsaWNpdCB0cmFuc2l0aW9uIGZyb20gam9pbmluZyB0byBqb2lu
ZWQgLSB0aGUgbW90ZSB0cmFuc2l0aW9ucyB3aGVuIGNlcnRhaW4ga2V5IGZyYW1lcyBhcmUgcmVj
ZWl2ZWQuDQoqIE5vdGUgdGhhdCBhIFdpcmVsZXNzSEFSVCBsaW5rLWxheWVyIGZyYW1lIGNvbnRh
aW5zIGFuZCBhZGRpdGlvbmFsIGZyYW1lIHR5cGUgYnl0ZSBhbmQgYSA0LWJ5dGUgbGluay1sYXll
ciBNSUMsIG9uIHRvcCBvZiB0aGUgdW5zZWN1cmVkIDE1LjQgZnJhbWUuICBBIG5ldHdvcmsgZnJh
bWUgY29udGFpbnMgYW4gYWRkaXRpb25hbCAxNi00MCBieXRlcyBvZiBhZGRyZXNzaW5nLCByb3V0
aW5nLCBzZWN1cml0eSBhbmQgb3RoZXIgaW5mb3JtYXRpb24uDQpIb3BlIHRoaXMgaGVscCENCkpv
bmF0aGFuDQoNCg0KT24gTW9uLCBNYXkgMjYsIDIwMTQgYXQgODowOSBQTSwgUmVuZSBTdHJ1aWsg
PHJzdHJ1aWsuZXh0QGdtYWlsLmNvbTxtYWlsdG86cnN0cnVpay5leHRAZ21haWwuY29tPj4gd3Jv
dGU6DQpIaSBNaWNoYWVsOg0KDQpJIHdvdWxkIGxpa2UgdG8gZGlzY3VzcyB0aGUgb3V0c3RhbmRp
bmcgaXNzdWVzIEkgc3VtbWFyaXplZCBpbiBteSBlbWFpbCBvZiBUdWUgbGFzdCB3ZWVrLCBNYXkg
MjAsIDIwMTQsIDk6NDVhbSBFRFQgKHNlZSBodHRwOi8vd3d3LmlldGYub3JnL21haWwtYXJjaGl2
ZS93ZWIvNnRpc2NoLXNlY3VyaXR5L2N1cnJlbnQvbXNnMDAwODYuaHRtbDxodHRwOi8vY3AubWNh
ZmVlLmNvbS9kLzVmSENNVXA0MUVTeU50NTVPV3RTanRQcWJ3VkJjU3lVZXB2ZEVLM3poT3lDT3Fl
anJ6UFBQejVYQ042QUJxTTFoWUV2SXVuZERPeC1OVnNUSlFYSWZjTFp2QzRUUVRTNmVMc0tDTy1Q
UFhYM1hVVnpCSEZTaGpsS2VwVmtmZkdoQnJ3cXJoZEk2WFl5TUNZLWVob2pkNzlLVkkwNWJWS1kw
MU1qYlg2TmVoRFkwNXpBVmtJamJRLVBzcGpicHBLY3Z4ZjVxNHJUS1lWTWVkS2pCaU5jTGpYZE5C
Y0luOGxyeHJXMEduUHRVMDJyaGh1aEtyMXZGNnkwUUpLakJpTmNMalhkTkJjSXFuamgxRjdVOHFx
ODdxTmQ0MnRRbTJaVE9Xb1VRZ2VqQmlOY1Fnay1Qc3BqYjZ5MlNERENUNjNwT19vPikuIFRoaXMg
d2FzIGFsc28gb25lIG9mIHRoZSBhY3Rpb24gaXRlbXMgYXQgdGhlIGNvbmNsdXNpb24gb2YgbGFz
dCB3ZWVrJ3MgNlRpU0NIIHNlY3VyaXR5IGNhbGwuDQoNCkZZSSAtIHRoZSB3L0hBUlQgY29tbXVu
aWNhdGlvbiBmbG93cyB3ZXJlIGRpc2N1c3NlZCBkdXJpbmcgdGhlIDZUaVNDSCBzZWN1cml0eSBj
b25mIGNhbGwgdGhlIHdlZWsgYmVmb3JlLCBvbiBNb24gTWF5IDEyLCAyMDE0LiBJZiBvbmUgd2lz
aGVzIHRvIGdvIG92ZXIgdGhpcyBhZ2FpbiwgdGhhdCBpcyBmaW5lLCBidXQgSSB3b3VsZCBwcmVm
ZXIgdXMgZ2l2aW5nIHByZWZlcmVuY2UgdG8gdGFraW5nIG9uIGFscmVhZHkgYXJ0aWN1bGF0ZWQg
aXNzdWVzICh3aGljaCB3ZXJlIGFzc2lnbmVkIGFzIGhvbWV3b3JrIGFzc2lnbm1lbnQgdG8gcmVm
bGVjdCB1cG9uKSBmaXJzdCAoaS5lLiwgcHJpb3IgdG8gaXRlbSAjNCBvZiB0aGUgcHJvcG9zZWQg
YWdlbmRhKS4NCg0KQXMgYW5vdGhlciBhZ2VuZGEgcG9pbnQsIEkgd291bGQgbGlrZSB1cyB0byBk
aXNjdXNzIHRoZSBmcmVxdWVuY3kgb2YgZnV0dXJlIGNhbGxzIChhcyBwYXJ0IG9mIEVPQikuDQoN
CkJlc3QgcmVnYXJkcywgUmVuZQ0KDQoNCk9uIDUvMjYvMjAxNCAxMDo0OSBQTSwgTWljaGFlbCBS
aWNoYXJkc29uIHdyb3RlOg0KDQpUbyByZW1pbmQsIHdlIG1vdmVkIHRoZSBjYWxsIGZyb20gdGhl
IDI2dGggdG8gdGhlIDI3dGggYXQgMTBhbSBFRFQuDQoNClRoYXQncyA5MCBtaW51dGVzIGZyb20g
dGhpcyBlbWFpbC4NCg0KDQoNCjEpIG5vdGV3ZWxsLg0KDQoyKSBpbnRyb3MNCg0KMykgcmVjYXAg
b2YgZHJhZnQtcGlyby0NCg0KNCkgd2lyZWxlc3NoYXJ0IC13YXkgLS0tIGhvdyBkb2VzIHRoZSBj
b21tdW5pY2F0aW9uIHdvcms/DQoNCjUpIGhvdyB0byBzdW1tYXJpemUgYWxsIG9mIHRoaXMgdG8g
dGhlIHdvcmtpbmcgZ3JvdXANCg0KNikgaG93IHRvIGNsb3NlIHRoaXMgcHJvY2VzcyB1cD8NCg0K
DQoNCi0tIHJlbWVtYmVyIHRoYXQgdGhlIGNhbGwgaXMgcmVjb3JkZWQsIGFuZCB0aGUgTm90ZVdl
bGwgYXBwbGllcy4NCg0KDQoNCi0tIFRoZSBVUkwgdG8gYWNjZXNzIHRoZSB3ZWJleCwgd2hpY2gg
d2lsbCB3ZSB1c2UgZm9yIGF1ZGlvIG9ubHk6DQoNCiAgaHR0cHM6Ly9jaXNjby53ZWJleC5jb20v
Y2lzY28vai5waHA/TVRJRD1tMmZlMTM5YmY4NzZjZWEzZWM2Mjc1MGNkNTgwYjc5MDg8aHR0cDov
L2NwLm1jYWZlZS5jb20vZC81ZkhDTjBTeU50NTVPV3RTanRQcWJ3VkJjU3lVZXB2ZEVLM3poT3lD
T3FlanJ6UFBQejVYQ042QUJxTTFoWUV2SXVuZERPeC1OVnNUSlFYSWZjTFp2QzRUUVRTNmVMc0tD
Ty1QUFhYM1hVVnpCSEZTaGpsS2VwVmtmZkdoQnJ3cXJqZEk2WFl5TUNZLWVob2pkNzlLVklEZXFS
NElPUUdtSE0wTDMtbk9RR21Id3pNaDkzbzkzZ1VWbGRUUW1qaE9ndHU3ZW1fbXZJVUNldkxwMVpX
VjBzcWVyTDZUOU9Gb0NuRlpDVU9DbWJBYUpNSlowbGJWS1kwMWRFRUw4VGR3TFF6aDBxbVQ5T0Zv
Q25GWkNVT0NtZGJGRXdRelk0ZGQ0M0pvQ3kxZVdiMXVYVnRjc3E4NzlPRm9DcThhdnBLY0ZCemgx
cmpQUHJ6MUxtVHc3dzE3Pg0KDQoNCg0KLS0gd2Ugd2lsbCByZXN1bWUgd2l0aCB0aGUgZXRoZXJw
YWQgYXQ6DQoNCiAgIGh0dHA6Ly9ldGhlcnBhZC50b29scy5pZXRmLm9yZzo5MDAwL3Avbm90ZXMt
aWV0Zi04OS02dGlzY2gtc2VjdXJpdHk8aHR0cDovL2NwLm1jYWZlZS5jb20vZC8yRFJQb3c3MU5K
NXlXYWJCUVhJQ1hDUW4xUGFwSjVNc08tcmhzNzZ6QjVkQVFzQ1Q3RERENmJUZHlkOWFSdzJ6Vmdf
b1lLcmZCM1p6T1ZMckZUb3VwdldfYzlMRkxJY3R1VnRkQlpERFRTN1ROUDdibmpJeUNIc3NQT0V1
dmt6YVQwUVNPcm9kVFY1eGRWWXN5TUNxZWp0UG8wZlZBX3lKRzdqSGstRGktckwwMGt6aFB1Wllt
TzVwX2dMYlZLQlR6aE9uc0RhQnlwdURTcnphcG9TVmVsYjRPWmZJVDZrT05zeGxLNUxFMkZ2ZFR3
MDlKNTVWNlZJNS1BcTgzaVNWZWxiNE9aZklUNmtPTkZ0ZDQ2QXZ3eEZFd3RINFFnOVRob2JUdmJG
enpoMFZlbGI0UGgxalhkTkJjSXE4YnF1dXJzb2RKaVp2cG1LNkd3WT4NCg0KDQoNCkknbSBhdCAr
MSA2MTMgMjc2LTY4MDk8dGVsOiUyQjElMjA2MTMlMjAyNzYtNjgwOT4sIElNOiBtY3JAeG1wcC5j
cmVkaWwub3JnPG1haWx0bzptY3JAeG1wcC5jcmVkaWwub3JnPiBvciBtY2hhcmxlc3JAZ21haWwu
Y29tPG1haWx0bzptY2hhcmxlc3JAZ21haWwuY29tPiwNCg0KaWYgeW91IG5lZWQgbW9yZSB0aGFu
IHRoYXQgdG8gZ2V0IGluLCBvciBhcmUgaGF2aW5nIGRpZmZpY3VsdGllcy4NCg0KUGxlYXNlIG1h
a2Ugc3VyZSB5b3VyIGF1ZGlvIHdvcmtzLCBhbmQgdGhhdCB5b3UgbXV0ZSB3aGVuIG5vdCB0YWxr
aW5nLg0KDQoNCg0KLS0NCg0KTWljaGFlbCBSaWNoYXJkc29uIDxtY3IrSUVURkBzYW5kZWxtYW4u
Y2E+PG1haWx0bzptY3IrSUVURkBzYW5kZWxtYW4uY2E+LCBTYW5kZWxtYW4gU29mdHdhcmUgV29y
a3MNCg0KIC09IElQdjYgSW9UIGNvbnN1bHRpbmcgPS0NCg0KDQoNCg0KDQoNCg0KDQpfX19fX19f
X19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fXw0KDQo2dGlzY2gtc2VjdXJp
dHkgbWFpbGluZyBsaXN0DQoNCjZ0aXNjaC1zZWN1cml0eUBpZXRmLm9yZzxtYWlsdG86NnRpc2No
LXNlY3VyaXR5QGlldGYub3JnPg0KDQpodHRwczovL3d3dy5pZXRmLm9yZy9tYWlsbWFuL2xpc3Rp
bmZvLzZ0aXNjaC1zZWN1cml0eTxodHRwOi8vY3AubWNhZmVlLmNvbS9kLzJEUlBvTzg2UW1iRUVL
bmpLT3JLcmhzN2NGQ1FuMVBiVko1TXNxZWtrU2poT3JzdXV1c29Mc1M4UUFIbTBhZkIzWnpPVkkt
a2ZTZmJDWktEdHhWQl9IWU1DLUMtTU5SWEJRU25TdXZ2b3Z2N2NzSnRlT2FxSk5QZmF4VlppY0hz
M2pyMUp3VHZBbTRURE5PYjJwRVZkVGRBVlBtRUJDNWVCWVR1MDBVOUdYMzNWa0RhM0pzc0RhQnlw
dURTcnphcG9TVmVsYjRPWmZJVDZrT05zeGxLNUxFMkZ2ZFR3MDlKNTVWNlZJNS1BcTgzaVNWZWxi
NE9aZklUNmtPTkZ0ZDQ2QXZ3eEZFd3RINFFnOVRob2JUdmJGenpoMFZlbGI0UGgxalhkTkJjSXE4
YnF1dXJzb2RMV2J2Pg0KDQoNCg0KDQotLQ0KDQplbWFpbDogcnN0cnVpay5leHRAZ21haWwuY29t
PG1haWx0bzpyc3RydWlrLmV4dEBnbWFpbC5jb20+IHwgU2t5cGU6IHJzdHJ1aWsNCg0KY2VsbDog
KzEgKDY0NykgODY3LTU2NTg8dGVsOiUyQjElMjAlMjg2NDclMjklMjA4NjctNTY1OD4gfCBVUzog
KzEgKDQxNSkgNjkwLTczNjM8dGVsOiUyQjElMjAlMjg0MTUlMjklMjA2OTAtNzM2Mz4NCg0KX19f
X19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX18NCjZ0aXNjaC1zZWN1
cml0eSBtYWlsaW5nIGxpc3QNCjZ0aXNjaC1zZWN1cml0eUBpZXRmLm9yZzxtYWlsdG86NnRpc2No
LXNlY3VyaXR5QGlldGYub3JnPg0KaHR0cDovL2NwLm1jYWZlZS5jb20vZC9hdm5kemdROTNnQXJo
b0t5eVZ0ZVg5S1ZKNU1zT0NyaHM3Y0xDUW4xTkVWaGpwZDc5Sk5WVlZOeVpQb3ppaUpvMEUta2ZT
ZmJDUFZnX29ZS3JTV3RTN0NuLUxQMnJXclgzN25LbmpwdnBWWlp4WllzTk9SUVg4RkdUN2NZRzdE
UjhPSk1kZEVDUWp0LWhvanV2NzhJOUN6QVRzU2pEZHF5bW9rV25QdFUwM3dDSEljZkJpc0VlUk5P
c0dtOUJXdnBLY0ZCenJBVmtJamJRLVBzcGpiNU81bVVtLXdhQllUdTAwQ1FrbkFyQ01uV2hFd2Ri
ckFWa0lqYlEtUHNwamI2QlFRZ3FoLTI2Q3kxU0lqaDBEdDV3THRZS0NlZDQzQVZrSWpkNDVmSVQ2
a09ORXdKRlZWSk53U2VWaHNyTGUtRmtkDQoNCg0KDQotLQ0KLS0NCkpvbmF0aGFuIFNpbW9uLCBQ
aC4gRA0KRGlyZWN0b3Igb2YgU3lzdGVtcyBFbmdpbmVlcmluZw0KRHVzdCBOZXR3b3JrcyBhdCBM
aW5lYXIgVGVjaG5vbG9neQ0KMzA2OTUgSHVudHdvb2QgQXZlDQpIYXl3YXJkLCBDQSA5NDU0NC03
MDIxDQooNTEwKSA0MDAtMjkzNg0KKDUxMCkgNDg5LTM3OTkgRkFYDQpqc2ltb25AbGluZWFyLmNv
bTxtYWlsdG86anNpbW9uQGxpbmVhci5jb20+DQoNCioqTElORUFSIFRFQ0hOT0xPR1kgQ09SUE9S
QVRJT04qKg0KKioqKipJbnRlcm5ldCBFbWFpbCBDb25maWRlbnRpYWxpdHkgTm90aWNlKioqKioN
CiBUaGlzIGUtbWFpbCB0cmFuc21pc3Npb24sIGFuZCBhbnkgZG9jdW1lbnRzLCBmaWxlcyBvciBw
cmV2aW91cyBlLW1haWwgbWVzc2FnZXMgYXR0YWNoZWQgdG8gaXQgbWF5IGNvbnRhaW4gY29uZmlk
ZW50aWFsIGluZm9ybWF0aW9uIHRoYXQgaXMgbGVnYWxseSBwcml2aWxlZ2VkLiBJZiB5b3UgYXJl
IG5vdCB0aGUgaW50ZW5kZWQgcmVjaXBpZW50LCBvciBhIHBlcnNvbiByZXNwb25zaWJsZSBmb3Ig
ZGVsaXZlcmluZyBpdCB0byB0aGUgaW50ZW5kZWQgcmVjaXBpZW50LCB5b3UgYXJlIGhlcmVieSBu
b3RpZmllZCB0aGF0IGFueSBkaXNjbG9zdXJlLCBjb3B5aW5nLCBkaXN0cmlidXRpb24gb3IgdXNl
IG9mIGFueSBvZiB0aGUgaW5mb3JtYXRpb24gY29udGFpbmVkIGluIG9yIGF0dGFjaGVkIHRvIHRo
aXMgdHJhbnNtaXNzaW9uIGlzIFNUUklDVExZIFBST0hJQklURUQuIElmIHlvdSBoYXZlIHJlY2Vp
dmVkIHRoaXMgdHJhbnNtaXNzaW9uIGluIGVycm9yLCBwbGVhc2UgaW1tZWRpYXRlbHkgbm90aWZ5
IG1lIGJ5IHJlcGx5IGUtbWFpbCwgb3IgYnkgdGVsZXBob25lIGF0ICg1MTApIDQwMC0yOTM2LCBh
bmQgZGVzdHJveSB0aGUgb3JpZ2luYWwgdHJhbnNtaXNzaW9uIGFuZCBpdHMgYXR0YWNobWVudHMg
d2l0aG91dCByZWFkaW5nIG9yIHNhdmluZyBpbiBhbnkgbWFubmVyLiBUaGFuayB5b3UuDQo=

--_000_674F70E5F2BE564CB06B6901FD3DD78B2723B576TGXML210toshiba_
Content-Type: text/html; charset="utf-8"
Content-Transfer-Encoding: base64

PGh0bWwgeG1sbnM6dj0idXJuOnNjaGVtYXMtbWljcm9zb2Z0LWNvbTp2bWwiIHhtbG5zOm89InVy
bjpzY2hlbWFzLW1pY3Jvc29mdC1jb206b2ZmaWNlOm9mZmljZSIgeG1sbnM6dz0idXJuOnNjaGVt
YXMtbWljcm9zb2Z0LWNvbTpvZmZpY2U6d29yZCIgeG1sbnM6bT0iaHR0cDovL3NjaGVtYXMubWlj
cm9zb2Z0LmNvbS9vZmZpY2UvMjAwNC8xMi9vbW1sIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcv
VFIvUkVDLWh0bWw0MCI+DQo8aGVhZD4NCjxtZXRhIGh0dHAtZXF1aXY9IkNvbnRlbnQtVHlwZSIg
Y29udGVudD0idGV4dC9odG1sOyBjaGFyc2V0PXV0Zi04Ij4NCjxtZXRhIG5hbWU9IkdlbmVyYXRv
ciIgY29udGVudD0iTWljcm9zb2Z0IFdvcmQgMTUgKGZpbHRlcmVkIG1lZGl1bSkiPg0KPHN0eWxl
PjwhLS0NCi8qIEZvbnQgRGVmaW5pdGlvbnMgKi8NCkBmb250LWZhY2UNCgl7Zm9udC1mYW1pbHk6
Iu+8re+8syDjgrTjgrfjg4Pjgq8iOw0KCXBhbm9zZS0xOjIgMTEgNiA5IDcgMiA1IDggMiA0O30N
CkBmb250LWZhY2UNCgl7Zm9udC1mYW1pbHk6IkNhbWJyaWEgTWF0aCI7DQoJcGFub3NlLTE6MiA0
IDUgMyA1IDQgNiAzIDIgNDt9DQpAZm9udC1mYWNlDQoJe2ZvbnQtZmFtaWx5OiLvvK3vvLMg77yw
44K044K344OD44KvIjsNCglwYW5vc2UtMToyIDExIDYgMCA3IDIgNSA4IDIgNDt9DQpAZm9udC1m
YWNlDQoJe2ZvbnQtZmFtaWx5OkNhbGlicmk7DQoJcGFub3NlLTE6MiAxNSA1IDIgMiAyIDQgMyAy
IDQ7fQ0KQGZvbnQtZmFjZQ0KCXtmb250LWZhbWlseToiXEDvvK3vvLMg44K044K344OD44KvIjsN
CglwYW5vc2UtMToyIDExIDYgOSA3IDIgNSA4IDIgNDt9DQpAZm9udC1mYWNlDQoJe2ZvbnQtZmFt
aWx5OiJcQO+8re+8syDvvLDjgrTjgrfjg4Pjgq8iOw0KCXBhbm9zZS0xOjIgMTEgNiAwIDcgMiA1
IDggMiA0O30NCi8qIFN0eWxlIERlZmluaXRpb25zICovDQpwLk1zb05vcm1hbCwgbGkuTXNvTm9y
bWFsLCBkaXYuTXNvTm9ybWFsDQoJe21hcmdpbjowbW07DQoJbWFyZ2luLWJvdHRvbTouMDAwMXB0
Ow0KCWZvbnQtc2l6ZToxMi4wcHQ7DQoJZm9udC1mYW1pbHk6Iu+8re+8syDvvLDjgrTjgrfjg4Pj
gq8iO30NCmE6bGluaywgc3Bhbi5Nc29IeXBlcmxpbmsNCgl7bXNvLXN0eWxlLXByaW9yaXR5Ojk5
Ow0KCWNvbG9yOmJsdWU7DQoJdGV4dC1kZWNvcmF0aW9uOnVuZGVybGluZTt9DQphOnZpc2l0ZWQs
IHNwYW4uTXNvSHlwZXJsaW5rRm9sbG93ZWQNCgl7bXNvLXN0eWxlLXByaW9yaXR5Ojk5Ow0KCWNv
bG9yOnB1cnBsZTsNCgl0ZXh0LWRlY29yYXRpb246dW5kZXJsaW5lO30NCnByZQ0KCXttc28tc3R5
bGUtcHJpb3JpdHk6OTk7DQoJbXNvLXN0eWxlLWxpbms6IkhUTUwg5pu45byP5LuY44GNIFwo5paH
5a2XXCkiOw0KCW1hcmdpbjowbW07DQoJbWFyZ2luLWJvdHRvbTouMDAwMXB0Ow0KCWZvbnQtc2l6
ZToxMi4wcHQ7DQoJZm9udC1mYW1pbHk6Iu+8re+8syDjgrTjgrfjg4Pjgq8iO30NCnNwYW4uSFRN
TA0KCXttc28tc3R5bGUtbmFtZToiSFRNTCDmm7jlvI/ku5jjgY0gXCjmloflrZdcKSI7DQoJbXNv
LXN0eWxlLXByaW9yaXR5Ojk5Ow0KCW1zby1zdHlsZS1saW5rOiJIVE1MIOabuOW8j+S7mOOBjSI7
DQoJZm9udC1mYW1pbHk6IkNvdXJpZXIgTmV3Ijt9DQpzcGFuLmhvZW56Yg0KCXttc28tc3R5bGUt
bmFtZTpob2VuemI7fQ0Kc3Bhbi4yMA0KCXttc28tc3R5bGUtdHlwZTpwZXJzb25hbC1yZXBseTsN
Cglmb250LWZhbWlseToiQXJpYWwiLCJzYW5zLXNlcmlmIjsNCgljb2xvcjojMUY0OTdEO30NCi5N
c29DaHBEZWZhdWx0DQoJe21zby1zdHlsZS10eXBlOmV4cG9ydC1vbmx5Ow0KCWZvbnQtZmFtaWx5
OiJBcmlhbCIsInNhbnMtc2VyaWYiO30NCkBwYWdlIFdvcmRTZWN0aW9uMQ0KCXtzaXplOjYxMi4w
cHQgNzkyLjBwdDsNCgltYXJnaW46OTkuMjVwdCAzMC4wbW0gMzAuMG1tIDMwLjBtbTt9DQpkaXYu
V29yZFNlY3Rpb24xDQoJe3BhZ2U6V29yZFNlY3Rpb24xO30NCi0tPjwvc3R5bGU+PCEtLVtpZiBn
dGUgbXNvIDldPjx4bWw+DQo8bzpzaGFwZWRlZmF1bHRzIHY6ZXh0PSJlZGl0IiBzcGlkbWF4PSIx
MDI2Ij4NCjx2OnRleHRib3ggaW5zZXQ9IjUuODVwdCwuN3B0LDUuODVwdCwuN3B0IiAvPg0KPC9v
OnNoYXBlZGVmYXVsdHM+PC94bWw+PCFbZW5kaWZdLS0+PCEtLVtpZiBndGUgbXNvIDldPjx4bWw+
DQo8bzpzaGFwZWxheW91dCB2OmV4dD0iZWRpdCI+DQo8bzppZG1hcCB2OmV4dD0iZWRpdCIgZGF0
YT0iMSIgLz4NCjwvbzpzaGFwZWxheW91dD48L3htbD48IVtlbmRpZl0tLT4NCjwvaGVhZD4NCjxi
b2R5IGxhbmc9IkpBIiBsaW5rPSJibHVlIiB2bGluaz0icHVycGxlIj4NCjxkaXYgY2xhc3M9Ildv
cmRTZWN0aW9uMSI+DQo8cCBjbGFzcz0iTXNvTm9ybWFsIj48c3BhbiBsYW5nPSJFTi1VUyIgc3R5
bGU9ImZvbnQtc2l6ZToxMC4wcHQ7Zm9udC1mYW1pbHk6JnF1b3Q7QXJpYWwmcXVvdDssJnF1b3Q7
c2Fucy1zZXJpZiZxdW90Oztjb2xvcjojMUY0OTdEIj5IaSBKb25hdGhhbiw8bzpwPjwvbzpwPjwv
c3Bhbj48L3A+DQo8cCBjbGFzcz0iTXNvTm9ybWFsIj48c3BhbiBsYW5nPSJFTi1VUyIgc3R5bGU9
ImZvbnQtc2l6ZToxMC4wcHQ7Zm9udC1mYW1pbHk6JnF1b3Q7QXJpYWwmcXVvdDssJnF1b3Q7c2Fu
cy1zZXJpZiZxdW90Oztjb2xvcjojMUY0OTdEIj48bzpwPiZuYnNwOzwvbzpwPjwvc3Bhbj48L3A+
DQo8cCBjbGFzcz0iTXNvTm9ybWFsIj48c3BhbiBsYW5nPSJFTi1VUyIgc3R5bGU9ImZvbnQtc2l6
ZToxMC4wcHQ7Zm9udC1mYW1pbHk6JnF1b3Q7QXJpYWwmcXVvdDssJnF1b3Q7c2Fucy1zZXJpZiZx
dW90Oztjb2xvcjojMUY0OTdEIj5UaGFuayB5b3UgZm9yIHNlbmRpbmcgdGhlIHN1bW1hcnkgb2Yg
dy9IQVJUIGpvaW5pbmcuDQo8bzpwPjwvbzpwPjwvc3Bhbj48L3A+DQo8cCBjbGFzcz0iTXNvTm9y
bWFsIj48c3BhbiBsYW5nPSJFTi1VUyIgc3R5bGU9ImZvbnQtc2l6ZToxMC4wcHQ7Zm9udC1mYW1p
bHk6JnF1b3Q7QXJpYWwmcXVvdDssJnF1b3Q7c2Fucy1zZXJpZiZxdW90Oztjb2xvcjojMUY0OTdE
Ij48bzpwPiZuYnNwOzwvbzpwPjwvc3Bhbj48L3A+DQo8cCBjbGFzcz0iTXNvTm9ybWFsIj48c3Bh
biBsYW5nPSJFTi1VUyIgc3R5bGU9ImZvbnQtc2l6ZToxMC4wcHQ7Zm9udC1mYW1pbHk6JnF1b3Q7
QXJpYWwmcXVvdDssJnF1b3Q7c2Fucy1zZXJpZiZxdW90Oztjb2xvcjojMUY0OTdEIj5JIGhhdmUg
cXVlc3Rpb24uPG86cD48L286cD48L3NwYW4+PC9wPg0KPHAgY2xhc3M9Ik1zb05vcm1hbCI+PHNw
YW4gbGFuZz0iRU4tVVMiIHN0eWxlPSJmb250LXNpemU6MTAuMHB0O2ZvbnQtZmFtaWx5OiZxdW90
O0FyaWFsJnF1b3Q7LCZxdW90O3NhbnMtc2VyaWYmcXVvdDs7Y29sb3I6IzFGNDk3RCI+PG86cD4m
bmJzcDs8L286cD48L3NwYW4+PC9wPg0KPHAgY2xhc3M9Ik1zb05vcm1hbCI+PHNwYW4gbGFuZz0i
RU4tVVMiIHN0eWxlPSJmb250LXNpemU6MTAuMHB0O2ZvbnQtZmFtaWx5OiZxdW90O0FyaWFsJnF1
b3Q7LCZxdW90O3NhbnMtc2VyaWYmcXVvdDs7Y29sb3I6IzFGNDk3RCI+SW4gdy9IQVJULCBhcmUg
YWxsIGJlYWNvbiBmcmFtZXMgYXV0aGVudGljYXRlZCB3aXRoIGEgd2VsbC1rbm93biBrZXkgZXZl
biBhZnRlciBhIGpvaW5pbmcgbm9kZSBvYnRhaW5lZCB0aGUgcnVudGltZSBsaW5rIGxheWVyIGtl
eT8mbmJzcDsNCjxvOnA+PC9vOnA+PC9zcGFuPjwvcD4NCjxwIGNsYXNzPSJNc29Ob3JtYWwiPjxz
cGFuIGxhbmc9IkVOLVVTIiBzdHlsZT0iZm9udC1zaXplOjEwLjBwdDtmb250LWZhbWlseTomcXVv
dDtBcmlhbCZxdW90OywmcXVvdDtzYW5zLXNlcmlmJnF1b3Q7O2NvbG9yOiMxRjQ5N0QiPjxvOnA+
Jm5ic3A7PC9vOnA+PC9zcGFuPjwvcD4NCjxwIGNsYXNzPSJNc29Ob3JtYWwiPjxzcGFuIGxhbmc9
IkVOLVVTIiBzdHlsZT0iZm9udC1zaXplOjEwLjBwdDtmb250LWZhbWlseTomcXVvdDtBcmlhbCZx
dW90OywmcXVvdDtzYW5zLXNlcmlmJnF1b3Q7O2NvbG9yOiMxRjQ5N0QiPlJlZ2FyZHMsPG86cD48
L286cD48L3NwYW4+PC9wPg0KPHAgY2xhc3M9Ik1zb05vcm1hbCI+PHNwYW4gbGFuZz0iRU4tVVMi
IHN0eWxlPSJmb250LXNpemU6MTAuMHB0O2ZvbnQtZmFtaWx5OiZxdW90O0FyaWFsJnF1b3Q7LCZx
dW90O3NhbnMtc2VyaWYmcXVvdDs7Y29sb3I6IzFGNDk3RCI+WW9zaGloaXJvIE9oYmE8bzpwPjwv
bzpwPjwvc3Bhbj48L3A+DQo8cCBjbGFzcz0iTXNvTm9ybWFsIj48c3BhbiBsYW5nPSJFTi1VUyIg
c3R5bGU9ImZvbnQtc2l6ZToxMC4wcHQ7Zm9udC1mYW1pbHk6JnF1b3Q7QXJpYWwmcXVvdDssJnF1
b3Q7c2Fucy1zZXJpZiZxdW90Oztjb2xvcjojMUY0OTdEIj48bzpwPiZuYnNwOzwvbzpwPjwvc3Bh
bj48L3A+DQo8cCBjbGFzcz0iTXNvTm9ybWFsIj48c3BhbiBsYW5nPSJFTi1VUyIgc3R5bGU9ImZv
bnQtc2l6ZToxMC4wcHQ7Zm9udC1mYW1pbHk6JnF1b3Q7QXJpYWwmcXVvdDssJnF1b3Q7c2Fucy1z
ZXJpZiZxdW90Oztjb2xvcjojMUY0OTdEIj48bzpwPiZuYnNwOzwvbzpwPjwvc3Bhbj48L3A+DQo8
cCBjbGFzcz0iTXNvTm9ybWFsIj48c3BhbiBsYW5nPSJFTi1VUyIgc3R5bGU9ImZvbnQtc2l6ZTox
MC4wcHQ7Zm9udC1mYW1pbHk6JnF1b3Q7QXJpYWwmcXVvdDssJnF1b3Q7c2Fucy1zZXJpZiZxdW90
Oztjb2xvcjojMUY0OTdEIj48bzpwPiZuYnNwOzwvbzpwPjwvc3Bhbj48L3A+DQo8cCBjbGFzcz0i
TXNvTm9ybWFsIj48c3BhbiBsYW5nPSJFTi1VUyIgc3R5bGU9ImZvbnQtc2l6ZToxMC4wcHQ7Zm9u
dC1mYW1pbHk6JnF1b3Q7QXJpYWwmcXVvdDssJnF1b3Q7c2Fucy1zZXJpZiZxdW90Oztjb2xvcjoj
MUY0OTdEIj48bzpwPiZuYnNwOzwvbzpwPjwvc3Bhbj48L3A+DQo8cCBjbGFzcz0iTXNvTm9ybWFs
Ij48Yj48c3BhbiBsYW5nPSJFTi1VUyIgc3R5bGU9ImZvbnQtc2l6ZToxMS4wcHQ7Zm9udC1mYW1p
bHk6JnF1b3Q7Q2FsaWJyaSZxdW90OywmcXVvdDtzYW5zLXNlcmlmJnF1b3Q7Ij5Gcm9tOjwvc3Bh
bj48L2I+PHNwYW4gbGFuZz0iRU4tVVMiIHN0eWxlPSJmb250LXNpemU6MTEuMHB0O2ZvbnQtZmFt
aWx5OiZxdW90O0NhbGlicmkmcXVvdDssJnF1b3Q7c2Fucy1zZXJpZiZxdW90OyI+IDZ0aXNjaC1z
ZWN1cml0eSBbbWFpbHRvOjZ0aXNjaC1zZWN1cml0eS1ib3VuY2VzQGlldGYub3JnXQ0KPGI+T24g
QmVoYWxmIE9mIDwvYj5Kb25hdGhhbiBTaW1vbjxicj4NCjxiPlNlbnQ6PC9iPiBUdWVzZGF5LCBN
YXkgMjcsIDIwMTQgMTA6NDEgUE08YnI+DQo8Yj5Ubzo8L2I+IFJlbmUgU3RydWlrPGJyPg0KPGI+
Q2M6PC9iPiBNaWNoYWVsIFJpY2hhcmRzb247IDZ0aXNjaC1zZWN1cml0eUBpZXRmLm9yZzxicj4N
CjxiPlN1YmplY3Q6PC9iPiBSZTogWzZ0aXNjaC1zZWN1cml0eV0gYWdlbmRhIGZvciAyMDE0LTA1
LTI3IDZ0aXNjaCBzZWN1cml0eSBjYWxsPG86cD48L286cD48L3NwYW4+PC9wPg0KPHAgY2xhc3M9
Ik1zb05vcm1hbCI+PHNwYW4gbGFuZz0iRU4tVVMiPjxvOnA+Jm5ic3A7PC9vOnA+PC9zcGFuPjwv
cD4NCjxkaXY+DQo8ZGl2Pg0KPGRpdj4NCjxwIGNsYXNzPSJNc29Ob3JtYWwiIHN0eWxlPSJtYXJn
aW4tYm90dG9tOjEyLjBwdCI+PHNwYW4gbGFuZz0iRU4tVVMiPlJlbmUgaGFkIGFza2VkIG9uIGEg
cHJldmlvdXMgY2FsbCBmb3Igc29tZW9uZSB0byBzdW1tYXJpemUgV2lyZWxlc3NIQVJUIGpvaW5p
bmcgLSBoZXJlIHlvdSBnby48YnI+DQo8YnI+DQoqIE9uZSBvciBtb3JlIGRldmljZXMgYXJlIHNl
bmRpbmcgYmVhY29ucyB0byBhZHZlcnRpc2UgdGhlIHByZXNlbmNlIG9mIHRoZSBuZXR3b3JrLiBJ
biBXaXJlbGVzc0hBUlQsIHRoaXMgZnJhbWUgaXMgdW5lbmNyeXB0ZWQsIGJ1dCBhdXRoZW50aWNh
dGVkIHdpdGggYSB3ZWxsIGtub3duIGtleS4mbmJzcDsgVGhlIGJlYWNvbiBjb250YWlucyB0aGUg
Y3VycmVudCBBU04sIHdoaWNoIHRoZSBqb2luaW5nIGRldmljZSB1c2VzIHRvIHN5bmNocm9uaXpl
IGl0cyBjbG9jay48bzpwPjwvbzpwPjwvc3Bhbj48L3A+DQo8ZGl2Pg0KPHAgY2xhc3M9Ik1zb05v
cm1hbCIgc3R5bGU9Im1hcmdpbi1ib3R0b206MTIuMHB0Ij48c3BhbiBsYW5nPSJFTi1VUyI+KiBP
bmNlIHRoZSBqb2luaW5nIG5vZGUgaGFzIGhlYXJkIGEgYmVhY29uLCBpdCBjb250aW51ZXMgbGlz
dGVuaW5nIGZvciBhZGRpdGlvbmFsIGJlYWNvbnMgZm9yIGEgc2hvcnQgc3BlY2lmaWVkIHRpbWVv
dXQuPG86cD48L286cD48L3NwYW4+PC9wPg0KPC9kaXY+DQo8cCBjbGFzcz0iTXNvTm9ybWFsIiBz
dHlsZT0ibWFyZ2luLWJvdHRvbToxMi4wcHQiPjxzcGFuIGxhbmc9IkVOLVVTIj4qIFRoZSBqb2lu
aW5nIG5vZGUgZW5jcnlwdHMgYSBmcmFtZSBjb250YWluaW5nIHNvbWUgSEFSVCBzcGVjaWZpYyBj
b250ZW50LCBpbmNsdWRpbmcgYSBsaXN0IG9mIGJlYWNvbmluZyBuZWlnaGJvcnMgaXQgaGVhcmQg
aW4gdGhlIHByZXZpb3VzIHN0ZXBzLiBUaGUgc2l6ZSBvZiB0aGUgcGF5bG9hZCBpcyB+IDYwIGJ5
dGVzLiZuYnNwOyBUaGUNCiBwYWNrZXQgaXMgcm91dGVkIGJ5IGEgJnF1b3Q7cHJveHkmcXVvdDsg
bm9kZSAtIHRoZSBqb2luaW5nIHBhcmVudC4gVGhlIGZyYW1lIGlzIGF1dGhlbnRpY2F0ZWQgdXNp
bmcgdGhlIHdlbGwta25vd24ga2V5LCBhbmQgZW5jcnlwdGVkIHVzaW5nIGEgc2hhcmVkIHN5bW1l
dHJpYyBrZXkga25vd24gb25seSBieSB0aGUgbm9kZSBhbmQgdGhlIG1hbmFnZXIuPGJyPg0KPGJy
Pg0KKiBUaGUgbWFuYWdlciByZXNwb25kcyB3aXRoIGEgZnJhbWUgY29udGFpbmluZyB0aGUgcnVu
LXRpbWUgbGluay1sYXllciBrZXksIHRoZSBub2RlJ3MgbmV3IHNob3J0IGFkZHJlc3MgKHRoaXMg
dGFrZXMgdGhlIHBsYWNlIG9mIFBBTiBjb29yZGluYXRvciBhc3NvY2lhdGlvbiksIGFuZCBhIHVu
aWNhc3Qgc2Vzc2lvbiBrZXkgYW5kIHN0YXJ0aW5nIG5vbmNlIGZvciB0aGUgbWFuYWdlci4gVGhp
cyBmcmFtZSBpcyBlbmNyeXB0ZWQgd2l0aCB0aGUgc3ltbWV0cmljDQoga2V5LiBUaGUgcGF5bG9h
ZCBpcyB+IDYwIGJ5dGVzLCBhbmQgaXMgcm91dGVkIHRvIHRoZSBwcm94eSBmb3IgZGVsaXZlcnkg
dG8gdGhlIGpvaW5pbmcgbm9kZSAtIHRoZSBwcm94eSB1c2VzIHRoZSBsaW5rLWxheWVyIHdlbGwg
a25vd24ga2V5IG9uIHRoZSBmcmFtZS48bzpwPjwvbzpwPjwvc3Bhbj48L3A+DQo8ZGl2Pg0KPHAg
Y2xhc3M9Ik1zb05vcm1hbCIgc3R5bGU9Im1hcmdpbi1ib3R0b206MTIuMHB0Ij48c3BhbiBsYW5n
PSJFTi1VUyI+KiBBdCB0aGlzIHBvaW50IHRoZSBqb2luaW5nIG5vZGUgdHJhbnNpdGlvbnMgdG8g
dXNpbmcgdGhlIHJ1bi10aW1lIGxpbmstbGF5ZXIga2V5IGZvciBhbGwgbGluay1sYXllciBmcmFt
ZXMsIGFuZCB0aGUgbWFuYWdlciB1bmljYXN0IHNlc3Npb24gZm9yIGVuZC10by1lbmQgbWFuYWdl
ciB0cmFmZmljLiBUaGlzIGVuZHMgdGhlIGluaXRpYWwNCiBzZWN1cml0eSBoYW5kc2hha2UuPG86
cD48L286cD48L3NwYW4+PC9wPg0KPC9kaXY+DQo8ZGl2Pg0KPHAgY2xhc3M9Ik1zb05vcm1hbCIg
c3R5bGU9Im1hcmdpbi1ib3R0b206MTIuMHB0Ij48c3BhbiBsYW5nPSJFTi1VUyI+KiBPdmVyIGEg
bnVtYmVyIG9mIGFkZGl0aW9uYWwgZnJhbWVzLCB0aGUgbWFuYWdlciBhc3NpZ25zIGFkZGl0aW9u
YWwgc2Vzc2lvbnMsIGluY2x1ZGluZyBicm9hZGNhc3Qgc2Vzc2lvbnMsIGFuZCBhIHVuaWNhc3Qg
c2Vzc2lvbiB0byB0aGUgR2F0ZXdheSAoc2luayBmb3IgYWxsIGRhdGEgdHJhZmZpYyksIGFuZCBh
ZGRpdGlvbmFsDQogY29tbXVuaWNhdGlvbnMgcmVzb3VyY2VzLCByb3V0aW5nIGluZm9ybWF0aW9u
LCBldGMuJm5ic3A7IFRoZXJlIGlzIG5vIGV4cGxpY2l0IHRyYW5zaXRpb24gZnJvbSBqb2luaW5n
IHRvIGpvaW5lZCAtIHRoZSBtb3RlIHRyYW5zaXRpb25zIHdoZW4gY2VydGFpbiBrZXkgZnJhbWVz
IGFyZSByZWNlaXZlZC48bzpwPjwvbzpwPjwvc3Bhbj48L3A+DQo8L2Rpdj4NCjxwIGNsYXNzPSJN
c29Ob3JtYWwiIHN0eWxlPSJtYXJnaW4tYm90dG9tOjEyLjBwdCI+PHNwYW4gbGFuZz0iRU4tVVMi
PiogTm90ZSB0aGF0IGEgV2lyZWxlc3NIQVJUIGxpbmstbGF5ZXIgZnJhbWUgY29udGFpbnMgYW5k
IGFkZGl0aW9uYWwgZnJhbWUgdHlwZSBieXRlIGFuZCBhIDQtYnl0ZSBsaW5rLWxheWVyIE1JQywg
b24gdG9wIG9mIHRoZSB1bnNlY3VyZWQgMTUuNCBmcmFtZS4mbmJzcDsgQSBuZXR3b3JrIGZyYW1l
IGNvbnRhaW5zIGFuIGFkZGl0aW9uYWwNCiAxNi00MCBieXRlcyBvZiBhZGRyZXNzaW5nLCByb3V0
aW5nLCBzZWN1cml0eSBhbmQgb3RoZXIgaW5mb3JtYXRpb24uPG86cD48L286cD48L3NwYW4+PC9w
Pg0KPC9kaXY+DQo8cCBjbGFzcz0iTXNvTm9ybWFsIiBzdHlsZT0ibWFyZ2luLWJvdHRvbToxMi4w
cHQiPjxzcGFuIGxhbmc9IkVOLVVTIj5Ib3BlIHRoaXMgaGVscCE8bzpwPjwvbzpwPjwvc3Bhbj48
L3A+DQo8L2Rpdj4NCjxwIGNsYXNzPSJNc29Ob3JtYWwiPjxzcGFuIGxhbmc9IkVOLVVTIj5Kb25h
dGhhbjxvOnA+PC9vOnA+PC9zcGFuPjwvcD4NCjxkaXY+DQo8ZGl2Pg0KPGRpdj4NCjxwIGNsYXNz
PSJNc29Ob3JtYWwiPjxzcGFuIGxhbmc9IkVOLVVTIj48bzpwPiZuYnNwOzwvbzpwPjwvc3Bhbj48
L3A+DQo8L2Rpdj4NCjwvZGl2Pg0KPC9kaXY+DQo8L2Rpdj4NCjxkaXY+DQo8cCBjbGFzcz0iTXNv
Tm9ybWFsIiBzdHlsZT0ibWFyZ2luLWJvdHRvbToxMi4wcHQiPjxzcGFuIGxhbmc9IkVOLVVTIj48
bzpwPiZuYnNwOzwvbzpwPjwvc3Bhbj48L3A+DQo8ZGl2Pg0KPHAgY2xhc3M9Ik1zb05vcm1hbCI+
PHNwYW4gbGFuZz0iRU4tVVMiPk9uIE1vbiwgTWF5IDI2LCAyMDE0IGF0IDg6MDkgUE0sIFJlbmUg
U3RydWlrICZsdDs8YSBocmVmPSJtYWlsdG86cnN0cnVpay5leHRAZ21haWwuY29tIiB0YXJnZXQ9
Il9ibGFuayI+cnN0cnVpay5leHRAZ21haWwuY29tPC9hPiZndDsgd3JvdGU6PG86cD48L286cD48
L3NwYW4+PC9wPg0KPGJsb2NrcXVvdGUgc3R5bGU9ImJvcmRlcjpub25lO2JvcmRlci1sZWZ0OnNv
bGlkICNDQ0NDQ0MgMS4wcHQ7cGFkZGluZzowbW0gMG1tIDBtbSA2LjBwdDttYXJnaW4tbGVmdDo0
LjhwdDttYXJnaW4tcmlnaHQ6MG1tIj4NCjxkaXY+DQo8ZGl2Pg0KPHAgY2xhc3M9Ik1zb05vcm1h
bCI+PHNwYW4gbGFuZz0iRU4tVVMiPkhpIE1pY2hhZWw6PGJyPg0KPGJyPg0KSSB3b3VsZCBsaWtl
IHRvIGRpc2N1c3MgdGhlIG91dHN0YW5kaW5nIGlzc3VlcyBJIHN1bW1hcml6ZWQgaW4gbXkgZW1h
aWwgb2YgVHVlIGxhc3Qgd2VlaywgTWF5IDIwLCAyMDE0LCA5OjQ1YW0gRURUIChzZWUNCjxhIGhy
ZWY9Imh0dHA6Ly9jcC5tY2FmZWUuY29tL2QvNWZIQ01VcDQxRVN5TnQ1NU9XdFNqdFBxYndWQmNT
eVVlcHZkRUszemhPeUNPcWVqcnpQUFB6NVhDTjZBQnFNMWhZRXZJdW5kRE94LU5Wc1RKUVhJZmNM
WnZDNFRRVFM2ZUxzS0NPLVBQWFgzWFVWekJIRlNoamxLZXBWa2ZmR2hCcndxcmhkSTZYWXlNQ1kt
ZWhvamQ3OUtWSTA1YlZLWTAxTWpiWDZOZWhEWTA1ekFWa0lqYlEtUHNwamJwcEtjdnhmNXE0clRL
WVZNZWRLakJpTmNMalhkTkJjSW44bHJ4clcwR25QdFUwMnJoaHVoS3IxdkY2eTBRSktqQmlOY0xq
WGROQmNJcW5qaDFGN1U4cXE4N3FOZDQydFFtMlpUT1dvVVFnZWpCaU5jUWdrLVBzcGpiNnkyU0RE
Q1Q2M3BPX28iIHRhcmdldD0iX2JsYW5rIj4NCmh0dHA6Ly93d3cuaWV0Zi5vcmcvbWFpbC1hcmNo
aXZlL3dlYi82dGlzY2gtc2VjdXJpdHkvY3VycmVudC9tc2cwMDA4Ni5odG1sPC9hPikuIFRoaXMg
d2FzIGFsc28gb25lIG9mIHRoZSBhY3Rpb24gaXRlbXMgYXQgdGhlIGNvbmNsdXNpb24gb2YgbGFz
dCB3ZWVrJ3MgNlRpU0NIIHNlY3VyaXR5IGNhbGwuPGJyPg0KPGJyPg0KRllJIC0gdGhlIHcvSEFS
VCBjb21tdW5pY2F0aW9uIGZsb3dzIHdlcmUgZGlzY3Vzc2VkIGR1cmluZyB0aGUgNlRpU0NIIHNl
Y3VyaXR5IGNvbmYgY2FsbCB0aGUgd2VlayBiZWZvcmUsIG9uIE1vbiBNYXkgMTIsIDIwMTQuIElm
IG9uZSB3aXNoZXMgdG8gZ28gb3ZlciB0aGlzIGFnYWluLCB0aGF0IGlzIGZpbmUsIGJ1dCBJIHdv
dWxkIHByZWZlciB1cyBnaXZpbmcgcHJlZmVyZW5jZSB0byB0YWtpbmcgb24gYWxyZWFkeSBhcnRp
Y3VsYXRlZCBpc3N1ZXMNCiAod2hpY2ggd2VyZSBhc3NpZ25lZCBhcyBob21ld29yayBhc3NpZ25t
ZW50IHRvIHJlZmxlY3QgdXBvbikgZmlyc3QgKGkuZS4sIHByaW9yIHRvIGl0ZW0gIzQgb2YgdGhl
IHByb3Bvc2VkIGFnZW5kYSkuPGJyPg0KPGJyPg0KQXMgYW5vdGhlciBhZ2VuZGEgcG9pbnQsIEkg
d291bGQgbGlrZSB1cyB0byBkaXNjdXNzIHRoZSBmcmVxdWVuY3kgb2YgZnV0dXJlIGNhbGxzIChh
cyBwYXJ0IG9mIEVPQikuPGJyPg0KPGJyPg0KQmVzdCByZWdhcmRzLCBSZW5lPGJyPg0KPGJyPg0K
PGJyPg0KT24gNS8yNi8yMDE0IDEwOjQ5IFBNLCBNaWNoYWVsIFJpY2hhcmRzb24gd3JvdGU6PG86
cD48L286cD48L3NwYW4+PC9wPg0KPC9kaXY+DQo8YmxvY2txdW90ZSBzdHlsZT0ibWFyZ2luLXRv
cDo1LjBwdDttYXJnaW4tYm90dG9tOjUuMHB0Ij4NCjxwcmU+PHNwYW4gbGFuZz0iRU4tVVMiPlRv
IHJlbWluZCwgd2UgbW92ZWQgdGhlIGNhbGwgZnJvbSB0aGUgMjZ0aCB0byB0aGUgMjd0aCBhdCAx
MGFtIEVEVC48bzpwPjwvbzpwPjwvc3Bhbj48L3ByZT4NCjxwcmU+PHNwYW4gbGFuZz0iRU4tVVMi
PlRoYXQncyA5MCBtaW51dGVzIGZyb20gdGhpcyBlbWFpbC48bzpwPjwvbzpwPjwvc3Bhbj48L3By
ZT4NCjxwcmU+PHNwYW4gbGFuZz0iRU4tVVMiPjxvOnA+Jm5ic3A7PC9vOnA+PC9zcGFuPjwvcHJl
Pg0KPHByZT48c3BhbiBsYW5nPSJFTi1VUyI+MSkgbm90ZXdlbGwuPG86cD48L286cD48L3NwYW4+
PC9wcmU+DQo8cHJlPjxzcGFuIGxhbmc9IkVOLVVTIj4yKSBpbnRyb3M8bzpwPjwvbzpwPjwvc3Bh
bj48L3ByZT4NCjxwcmU+PHNwYW4gbGFuZz0iRU4tVVMiPjMpIHJlY2FwIG9mIGRyYWZ0LXBpcm8t
PG86cD48L286cD48L3NwYW4+PC9wcmU+DQo8cHJlPjxzcGFuIGxhbmc9IkVOLVVTIj40KSB3aXJl
bGVzc2hhcnQgLXdheSAtLS0gaG93IGRvZXMgdGhlIGNvbW11bmljYXRpb24gd29yaz88bzpwPjwv
bzpwPjwvc3Bhbj48L3ByZT4NCjxwcmU+PHNwYW4gbGFuZz0iRU4tVVMiPjUpIGhvdyB0byBzdW1t
YXJpemUgYWxsIG9mIHRoaXMgdG8gdGhlIHdvcmtpbmcgZ3JvdXA8bzpwPjwvbzpwPjwvc3Bhbj48
L3ByZT4NCjxwcmU+PHNwYW4gbGFuZz0iRU4tVVMiPjYpIGhvdyB0byBjbG9zZSB0aGlzIHByb2Nl
c3MgdXA/PG86cD48L286cD48L3NwYW4+PC9wcmU+DQo8cHJlPjxzcGFuIGxhbmc9IkVOLVVTIj48
bzpwPiZuYnNwOzwvbzpwPjwvc3Bhbj48L3ByZT4NCjxwcmU+PHNwYW4gbGFuZz0iRU4tVVMiPi0t
IHJlbWVtYmVyIHRoYXQgdGhlIGNhbGwgaXMgcmVjb3JkZWQsIGFuZCB0aGUgTm90ZVdlbGwgYXBw
bGllcy48bzpwPjwvbzpwPjwvc3Bhbj48L3ByZT4NCjxwcmU+PHNwYW4gbGFuZz0iRU4tVVMiPjxv
OnA+Jm5ic3A7PC9vOnA+PC9zcGFuPjwvcHJlPg0KPHByZT48c3BhbiBsYW5nPSJFTi1VUyI+LS0g
VGhlIFVSTCB0byBhY2Nlc3MgdGhlIHdlYmV4LCB3aGljaCB3aWxsIHdlIHVzZSBmb3IgYXVkaW8g
b25seTo8bzpwPjwvbzpwPjwvc3Bhbj48L3ByZT4NCjxwcmU+PHNwYW4gbGFuZz0iRU4tVVMiPiZu
YnNwOyA8YSBocmVmPSJodHRwOi8vY3AubWNhZmVlLmNvbS9kLzVmSENOMFN5TnQ1NU9XdFNqdFBx
YndWQmNTeVVlcHZkRUszemhPeUNPcWVqcnpQUFB6NVhDTjZBQnFNMWhZRXZJdW5kRE94LU5Wc1RK
UVhJZmNMWnZDNFRRVFM2ZUxzS0NPLVBQWFgzWFVWekJIRlNoamxLZXBWa2ZmR2hCcndxcmpkSTZY
WXlNQ1ktZWhvamQ3OUtWSURlcVI0SU9RR21ITTBMMy1uT1FHbUh3ek1oOTNvOTNnVVZsZFRRbWpo
T2d0dTdlbV9tdklVQ2V2THAxWldWMHNxZXJMNlQ5T0ZvQ25GWkNVT0NtYkFhSk1KWjBsYlZLWTAx
ZEVFTDhUZHdMUXpoMHFtVDlPRm9DbkZaQ1VPQ21kYkZFd1F6WTRkZDQzSm9DeTFlV2IxdVhWdGNz
cTg3OU9Gb0NxOGF2cEtjRkJ6aDFyalBQcnoxTG1Udzd3MTciIHRhcmdldD0iX2JsYW5rIj5odHRw
czovL2Npc2NvLndlYmV4LmNvbS9jaXNjby9qLnBocD9NVElEPW0yZmUxMzliZjg3NmNlYTNlYzYy
NzUwY2Q1ODBiNzkwODwvYT48bzpwPjwvbzpwPjwvc3Bhbj48L3ByZT4NCjxwcmU+PHNwYW4gbGFu
Zz0iRU4tVVMiPjxvOnA+Jm5ic3A7PC9vOnA+PC9zcGFuPjwvcHJlPg0KPHByZT48c3BhbiBsYW5n
PSJFTi1VUyI+LS0gd2Ugd2lsbCByZXN1bWUgd2l0aCB0aGUgZXRoZXJwYWQgYXQ6PG86cD48L286
cD48L3NwYW4+PC9wcmU+DQo8cHJlPjxzcGFuIGxhbmc9IkVOLVVTIj4mbmJzcDsmbmJzcDsgPGEg
aHJlZj0iaHR0cDovL2NwLm1jYWZlZS5jb20vZC8yRFJQb3c3MU5KNXlXYWJCUVhJQ1hDUW4xUGFw
SjVNc08tcmhzNzZ6QjVkQVFzQ1Q3RERENmJUZHlkOWFSdzJ6Vmdfb1lLcmZCM1p6T1ZMckZUb3Vw
dldfYzlMRkxJY3R1VnRkQlpERFRTN1ROUDdibmpJeUNIc3NQT0V1dmt6YVQwUVNPcm9kVFY1eGRW
WXN5TUNxZWp0UG8wZlZBX3lKRzdqSGstRGktckwwMGt6aFB1WlltTzVwX2dMYlZLQlR6aE9uc0Rh
QnlwdURTcnphcG9TVmVsYjRPWmZJVDZrT05zeGxLNUxFMkZ2ZFR3MDlKNTVWNlZJNS1BcTgzaVNW
ZWxiNE9aZklUNmtPTkZ0ZDQ2QXZ3eEZFd3RINFFnOVRob2JUdmJGenpoMFZlbGI0UGgxalhkTkJj
SXE4YnF1dXJzb2RKaVp2cG1LNkd3WSIgdGFyZ2V0PSJfYmxhbmsiPmh0dHA6Ly9ldGhlcnBhZC50
b29scy5pZXRmLm9yZzo5MDAwL3Avbm90ZXMtaWV0Zi04OS02dGlzY2gtc2VjdXJpdHk8L2E+PG86
cD48L286cD48L3NwYW4+PC9wcmU+DQo8cHJlPjxzcGFuIGxhbmc9IkVOLVVTIj48bzpwPiZuYnNw
OzwvbzpwPjwvc3Bhbj48L3ByZT4NCjxwcmU+PHNwYW4gbGFuZz0iRU4tVVMiPkknbSBhdCA8YSBo
cmVmPSJ0ZWw6JTJCMSUyMDYxMyUyMDI3Ni02ODA5IiB0YXJnZXQ9Il9ibGFuayI+JiM0MzsxIDYx
MyAyNzYtNjgwOTwvYT4sIElNOiA8YSBocmVmPSJtYWlsdG86bWNyQHhtcHAuY3JlZGlsLm9yZyIg
dGFyZ2V0PSJfYmxhbmsiPm1jckB4bXBwLmNyZWRpbC5vcmc8L2E+IG9yIDxhIGhyZWY9Im1haWx0
bzptY2hhcmxlc3JAZ21haWwuY29tIiB0YXJnZXQ9Il9ibGFuayI+bWNoYXJsZXNyQGdtYWlsLmNv
bTwvYT4sPG86cD48L286cD48L3NwYW4+PC9wcmU+DQo8cHJlPjxzcGFuIGxhbmc9IkVOLVVTIj5p
ZiB5b3UgbmVlZCBtb3JlIHRoYW4gdGhhdCB0byBnZXQgaW4sIG9yIGFyZSBoYXZpbmcgZGlmZmlj
dWx0aWVzLjxvOnA+PC9vOnA+PC9zcGFuPjwvcHJlPg0KPHByZT48c3BhbiBsYW5nPSJFTi1VUyI+
UGxlYXNlIG1ha2Ugc3VyZSB5b3VyIGF1ZGlvIHdvcmtzLCBhbmQgdGhhdCB5b3UgbXV0ZSB3aGVu
IG5vdCB0YWxraW5nLjxvOnA+PC9vOnA+PC9zcGFuPjwvcHJlPg0KPHByZT48c3BhbiBsYW5nPSJF
Ti1VUyI+PG86cD4mbmJzcDs8L286cD48L3NwYW4+PC9wcmU+DQo8cHJlPjxzcGFuIGxhbmc9IkVO
LVVTIj4tLTxvOnA+PC9vOnA+PC9zcGFuPjwvcHJlPg0KPHByZT48c3BhbiBsYW5nPSJFTi1VUyI+
TWljaGFlbCBSaWNoYXJkc29uIDxhIGhyZWY9Im1haWx0bzptY3ImIzQzO0lFVEZAc2FuZGVsbWFu
LmNhIiB0YXJnZXQ9Il9ibGFuayI+Jmx0O21jciYjNDM7SUVURkBzYW5kZWxtYW4uY2EmZ3Q7PC9h
PiwgU2FuZGVsbWFuIFNvZnR3YXJlIFdvcmtzPG86cD48L286cD48L3NwYW4+PC9wcmU+DQo8cHJl
PjxzcGFuIGxhbmc9IkVOLVVTIj4gLT0gSVB2NiBJb1QgY29uc3VsdGluZyA9LTxvOnA+PC9vOnA+
PC9zcGFuPjwvcHJlPg0KPHByZT48c3BhbiBsYW5nPSJFTi1VUyI+PG86cD4mbmJzcDs8L286cD48
L3NwYW4+PC9wcmU+DQo8cHJlPjxzcGFuIGxhbmc9IkVOLVVTIj48bzpwPiZuYnNwOzwvbzpwPjwv
c3Bhbj48L3ByZT4NCjxwcmU+PHNwYW4gbGFuZz0iRU4tVVMiPjxvOnA+Jm5ic3A7PC9vOnA+PC9z
cGFuPjwvcHJlPg0KPHAgY2xhc3M9Ik1zb05vcm1hbCIgc3R5bGU9Im1hcmdpbi1ib3R0b206MTIu
MHB0Ij48c3BhbiBjbGFzcz0iaG9lbnpiIj48c3BhbiBsYW5nPSJFTi1VUyIgc3R5bGU9ImNvbG9y
OiM4ODg4ODgiPjxvOnA+Jm5ic3A7PC9vOnA+PC9zcGFuPjwvc3Bhbj48L3A+DQo8cHJlPjxzcGFu
IGxhbmc9IkVOLVVTIiBzdHlsZT0iY29sb3I6Izg4ODg4OCI+X19fX19fX19fX19fX19fX19fX19f
X19fX19fX19fX19fX19fX19fX19fX19fX188bzpwPjwvbzpwPjwvc3Bhbj48L3ByZT4NCjxwcmU+
PHNwYW4gbGFuZz0iRU4tVVMiIHN0eWxlPSJjb2xvcjojODg4ODg4Ij42dGlzY2gtc2VjdXJpdHkg
bWFpbGluZyBsaXN0PG86cD48L286cD48L3NwYW4+PC9wcmU+DQo8cHJlPjxzcGFuIGxhbmc9IkVO
LVVTIiBzdHlsZT0iY29sb3I6Izg4ODg4OCI+PGEgaHJlZj0ibWFpbHRvOjZ0aXNjaC1zZWN1cml0
eUBpZXRmLm9yZyIgdGFyZ2V0PSJfYmxhbmsiPjZ0aXNjaC1zZWN1cml0eUBpZXRmLm9yZzwvYT48
bzpwPjwvbzpwPjwvc3Bhbj48L3ByZT4NCjxwcmU+PHNwYW4gbGFuZz0iRU4tVVMiIHN0eWxlPSJj
b2xvcjojODg4ODg4Ij48YSBocmVmPSJodHRwOi8vY3AubWNhZmVlLmNvbS9kLzJEUlBvTzg2UW1i
RUVLbmpLT3JLcmhzN2NGQ1FuMVBiVko1TXNxZWtrU2poT3JzdXV1c29Mc1M4UUFIbTBhZkIzWnpP
Vkkta2ZTZmJDWktEdHhWQl9IWU1DLUMtTU5SWEJRU25TdXZ2b3Z2N2NzSnRlT2FxSk5QZmF4Vlpp
Y0hzM2pyMUp3VHZBbTRURE5PYjJwRVZkVGRBVlBtRUJDNWVCWVR1MDBVOUdYMzNWa0RhM0pzc0Rh
QnlwdURTcnphcG9TVmVsYjRPWmZJVDZrT05zeGxLNUxFMkZ2ZFR3MDlKNTVWNlZJNS1BcTgzaVNW
ZWxiNE9aZklUNmtPTkZ0ZDQ2QXZ3eEZFd3RINFFnOVRob2JUdmJGenpoMFZlbGI0UGgxalhkTkJj
SXE4YnF1dXJzb2RMV2J2IiB0YXJnZXQ9Il9ibGFuayI+aHR0cHM6Ly93d3cuaWV0Zi5vcmcvbWFp
bG1hbi9saXN0aW5mby82dGlzY2gtc2VjdXJpdHk8L2E+PG86cD48L286cD48L3NwYW4+PC9wcmU+
DQo8L2Jsb2NrcXVvdGU+DQo8cCBjbGFzcz0iTXNvTm9ybWFsIj48c3BhbiBsYW5nPSJFTi1VUyIg
c3R5bGU9ImNvbG9yOiM4ODg4ODgiPjxicj4NCjxicj4NCjxicj4NCjxzcGFuIGNsYXNzPSJob2Vu
emIiPjxvOnA+PC9vOnA+PC9zcGFuPjwvc3Bhbj48L3A+DQo8cHJlPjxzcGFuIGxhbmc9IkVOLVVT
IiBzdHlsZT0iY29sb3I6Izg4ODg4OCI+LS0gPG86cD48L286cD48L3NwYW4+PC9wcmU+DQo8cHJl
PjxzcGFuIGxhbmc9IkVOLVVTIiBzdHlsZT0iY29sb3I6Izg4ODg4OCI+ZW1haWw6IDxhIGhyZWY9
Im1haWx0bzpyc3RydWlrLmV4dEBnbWFpbC5jb20iIHRhcmdldD0iX2JsYW5rIj5yc3RydWlrLmV4
dEBnbWFpbC5jb208L2E+IHwgU2t5cGU6IHJzdHJ1aWs8bzpwPjwvbzpwPjwvc3Bhbj48L3ByZT4N
CjxwcmU+PHNwYW4gbGFuZz0iRU4tVVMiIHN0eWxlPSJjb2xvcjojODg4ODg4Ij5jZWxsOiA8YSBo
cmVmPSJ0ZWw6JTJCMSUyMCUyODY0NyUyOSUyMDg2Ny01NjU4IiB0YXJnZXQ9Il9ibGFuayI+JiM0
MzsxICg2NDcpIDg2Ny01NjU4PC9hPiB8IFVTOiA8YSBocmVmPSJ0ZWw6JTJCMSUyMCUyODQxNSUy
OSUyMDY5MC03MzYzIiB0YXJnZXQ9Il9ibGFuayI+JiM0MzsxICg0MTUpIDY5MC03MzYzPC9hPjwv
c3Bhbj48c3BhbiBsYW5nPSJFTi1VUyI+PG86cD48L286cD48L3NwYW4+PC9wcmU+DQo8L2Rpdj4N
CjxwIGNsYXNzPSJNc29Ob3JtYWwiIHN0eWxlPSJtYXJnaW4tYm90dG9tOjEyLjBwdCI+PHNwYW4g
bGFuZz0iRU4tVVMiPjxicj4NCl9fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19f
X19fX19fX19fPGJyPg0KNnRpc2NoLXNlY3VyaXR5IG1haWxpbmcgbGlzdDxicj4NCjxhIGhyZWY9
Im1haWx0bzo2dGlzY2gtc2VjdXJpdHlAaWV0Zi5vcmciPjZ0aXNjaC1zZWN1cml0eUBpZXRmLm9y
ZzwvYT48YnI+DQo8YSBocmVmPSJodHRwOi8vY3AubWNhZmVlLmNvbS9kL2F2bmR6Z1E5M2dBcmhv
S3l5VnRlWDlLVko1TXNPQ3JoczdjTENRbjFORVZoanBkNzlKTlZWVk55WlBvemlpSm8wRS1rZlNm
YkNQVmdfb1lLclNXdFM3Q24tTFAycldyWDM3bktuanB2cFZaWnhaWXNOT1JRWDhGR1Q3Y1lHN0RS
OE9KTWRkRUNRanQtaG9qdXY3OEk5Q3pBVHNTakRkcXltb2tXblB0VTAzd0NISWNmQmlzRWVSTk9z
R205Qld2cEtjRkJ6ckFWa0lqYlEtUHNwamI1TzVtVW0td2FCWVR1MDBDUWtuQXJDTW5XaEV3ZGJy
QVZrSWpiUS1Qc3BqYjZCUVFncWgtMjZDeTFTSWpoMER0NXdMdFlLQ2VkNDNBVmtJamQ0NWZJVDZr
T05Fd0pGVlZKTndTZVZoc3JMZS1Ga2QiIHRhcmdldD0iX2JsYW5rIj5odHRwOi8vY3AubWNhZmVl
LmNvbS9kL2F2bmR6Z1E5M2dBcmhvS3l5VnRlWDlLVko1TXNPQ3JoczdjTENRbjFORVZoanBkNzlK
TlZWVk55WlBvemlpSm8wRS1rZlNmYkNQVmdfb1lLclNXdFM3Q24tTFAycldyWDM3bktuanB2cFZa
WnhaWXNOT1JRWDhGR1Q3Y1lHN0RSOE9KTWRkRUNRanQtaG9qdXY3OEk5Q3pBVHNTakRkcXltb2tX
blB0VTAzd0NISWNmQmlzRWVSTk9zR205Qld2cEtjRkJ6ckFWa0lqYlEtUHNwamI1TzVtVW0td2FC
WVR1MDBDUWtuQXJDTW5XaEV3ZGJyQVZrSWpiUS1Qc3BqYjZCUVFncWgtMjZDeTFTSWpoMER0NXdM
dFlLQ2VkNDNBVmtJamQ0NWZJVDZrT05Fd0pGVlZKTndTZVZoc3JMZS1Ga2Q8L2E+PG86cD48L286
cD48L3NwYW4+PC9wPg0KPC9ibG9ja3F1b3RlPg0KPC9kaXY+DQo8cCBjbGFzcz0iTXNvTm9ybWFs
Ij48c3BhbiBsYW5nPSJFTi1VUyI+PGJyPg0KPGJyIGNsZWFyPSJhbGwiPg0KPGJyPg0KLS0gPG86
cD48L286cD48L3NwYW4+PC9wPg0KPGRpdj4NCjxwIGNsYXNzPSJNc29Ob3JtYWwiPjxzcGFuIGxh
bmc9IkVOLVVTIiBzdHlsZT0iZm9udC1zaXplOjEzLjVwdDtmb250LWZhbWlseTomcXVvdDtUaW1l
cyBOZXcgUm9tYW4mcXVvdDssJnF1b3Q7c2VyaWYmcXVvdDsiPi0tJm5ic3A7PGJyPg0KSm9uYXRo
YW4gU2ltb24sIFBoLiBEPGJyPg0KRGlyZWN0b3Igb2YgU3lzdGVtcyBFbmdpbmVlcmluZzxicj4N
CkR1c3QgTmV0d29ya3MgYXQgTGluZWFyIFRlY2hub2xvZ3k8YnI+DQozMDY5NSBIdW50d29vZCBB
dmU8YnI+DQpIYXl3YXJkLCBDQSA5NDU0NC03MDIxPGJyPg0KKDUxMCkgNDAwLTI5MzY8YnI+DQoo
NTEwKSA0ODktMzc5OSBGQVg8YnI+DQo8YSBocmVmPSJtYWlsdG86anNpbW9uQGxpbmVhci5jb20i
IHRhcmdldD0iX2JsYW5rIj5qc2ltb25AbGluZWFyLmNvbTwvYT48L3NwYW4+PHNwYW4gbGFuZz0i
RU4tVVMiPjxicj4NCjxicj4NCjwvc3Bhbj48c3BhbiBsYW5nPSJFTi1VUyIgc3R5bGU9ImZvbnQt
c2l6ZToxMy41cHQ7Zm9udC1mYW1pbHk6JnF1b3Q7VGltZXMgTmV3IFJvbWFuJnF1b3Q7LCZxdW90
O3NlcmlmJnF1b3Q7Ij4qKkxJTkVBUiBURUNITk9MT0dZJm5ic3A7Q09SUE9SQVRJT04qKiZuYnNw
Ozxicj4NCioqKioqSW50ZXJuZXQgRW1haWwgQ29uZmlkZW50aWFsaXR5Jm5ic3A7Tm90aWNlKioq
KiombmJzcDs8YnI+DQombmJzcDtUaGlzIGUtbWFpbCB0cmFuc21pc3Npb24sIGFuZCBhbnkmbmJz
cDtkb2N1bWVudHMsIGZpbGVzIG9yIHByZXZpb3VzIGUtbWFpbCZuYnNwO21lc3NhZ2VzIGF0dGFj
aGVkIHRvIGl0IG1heSBjb250YWluJm5ic3A7Y29uZmlkZW50aWFsIGluZm9ybWF0aW9uIHRoYXQg
aXMmbmJzcDtsZWdhbGx5IHByaXZpbGVnZWQuIElmIHlvdSBhcmUgbm90IHRoZSZuYnNwO2ludGVu
ZGVkIHJlY2lwaWVudCwgb3IgYSBwZXJzb24mbmJzcDtyZXNwb25zaWJsZSBmb3IgZGVsaXZlcmlu
ZyBpdCB0byB0aGUmbmJzcDtpbnRlbmRlZA0KIHJlY2lwaWVudCwgeW91IGFyZSBoZXJlYnkmbmJz
cDtub3RpZmllZCB0aGF0IGFueSBkaXNjbG9zdXJlLCBjb3B5aW5nLCZuYnNwO2Rpc3RyaWJ1dGlv
biBvciB1c2Ugb2YgYW55IG9mIHRoZSZuYnNwO2luZm9ybWF0aW9uIGNvbnRhaW5lZCBpbiBvciBh
dHRhY2hlZCZuYnNwO3RvIHRoaXMgdHJhbnNtaXNzaW9uIGlzIFNUUklDVExZJm5ic3A7UFJPSElC
SVRFRC4gSWYgeW91IGhhdmUgcmVjZWl2ZWQgdGhpcyZuYnNwO3RyYW5zbWlzc2lvbiBpbiBlcnJv
ciwgcGxlYXNlJm5ic3A7aW1tZWRpYXRlbHkgbm90aWZ5DQogbWUgYnkgcmVwbHkgZS1tYWlsLCBv
ciBieSB0ZWxlcGhvbmUgYXQgKDUxMCkgNDAwLTI5MzYsIGFuZCBkZXN0cm95IHRoZSBvcmlnaW5h
bCZuYnNwO3RyYW5zbWlzc2lvbiBhbmQgaXRzIGF0dGFjaG1lbnRzJm5ic3A7d2l0aG91dCByZWFk
aW5nIG9yIHNhdmluZyBpbiBhbnkmbmJzcDttYW5uZXIuIFRoYW5rIHlvdS4NCjwvc3Bhbj48c3Bh
biBsYW5nPSJFTi1VUyI+PG86cD48L286cD48L3NwYW4+PC9wPg0KPC9kaXY+DQo8L2Rpdj4NCjwv
ZGl2Pg0KPC9ib2R5Pg0KPC9odG1sPg0K

--_000_674F70E5F2BE564CB06B6901FD3DD78B2723B576TGXML210toshiba_--


From nobody Wed May 28 02:56:18 2014
Return-Path: <pthubert@cisco.com>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id A63681A03DB; Wed, 28 May 2014 02:56:11 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -14.551
X-Spam-Level: 
X-Spam-Status: No, score=-14.551 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_MESSAGE=0.001, J_CHICKENPOX_21=0.6, RCVD_IN_DNSWL_HI=-5, RP_MATCHES_RCVD=-0.651, SPF_PASS=-0.001, USER_IN_DEF_DKIM_WL=-7.5] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 0ZxgQd66lnnk; Wed, 28 May 2014 02:56:07 -0700 (PDT)
Received: from alln-iport-1.cisco.com (alln-iport-1.cisco.com [173.37.142.88]) (using TLSv1 with cipher RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 7A06F1A03ED; Wed, 28 May 2014 02:56:06 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cisco.com; i=@cisco.com; l=51979; q=dns/txt; s=iport; t=1401270963; x=1402480563; h=from:to:cc:subject:date:message-id:mime-version; bh=kjlPl7nFkc7wA2Y5/6xelTkMBXwbMRR4uIZPu2Sz5C0=; b=TVbXu3wCzx9b7Rm8dww9MLiNkROXaFhoFQjhU8sfg4uLxkgZV9f8+3LP wSDCCHGIrK0v3BpDcV3qfcptHdnv6QlT0WLNfn5BdmbzqUn8MBpS0nEqW hJ3o2+wRVs7sYycvVEdo07En2X+wUrzbZnEWB2w9Edbv4dIYUiZ5TiLEW A=;
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-Anti-Spam-Result: AjwFAEGyhVOtJV2R/2dsb2JhbAA/EAqCQkVSWMIiAYELFnSCJwEEGhNMEgEaEBYBPxcPAQQODQESiCcNNtUoF4kzghABgjIEAQYBAR4tBIMygRUEiWiFWIYzlymDOGyBAQEIFyI
X-IronPort-AV: E=Sophos; i="4.98,927,1392163200"; d="scan'208,217"; a="47862002"
Received: from rcdn-core-9.cisco.com ([173.37.93.145]) by alln-iport-1.cisco.com with ESMTP; 28 May 2014 09:55:59 +0000
Received: from xhc-aln-x08.cisco.com (xhc-aln-x08.cisco.com [173.36.12.82]) by rcdn-core-9.cisco.com (8.14.5/8.14.5) with ESMTP id s4S9txX7029638 (version=TLSv1/SSLv3 cipher=AES128-SHA bits=128 verify=FAIL); Wed, 28 May 2014 09:55:59 GMT
Received: from xmb-rcd-x01.cisco.com ([169.254.1.203]) by xhc-aln-x08.cisco.com ([173.36.12.82]) with mapi id 14.03.0123.003; Wed, 28 May 2014 04:55:59 -0500
From: "Pascal Thubert (pthubert)" <pthubert@cisco.com>
To: "6tisch@ietf.org" <6tisch@ietf.org>
Thread-Topic: Minutes Webex 27 May 2014, 6TiSCH Security Design Team
Thread-Index: Ac96Wt/wjwLJijpjSDG+X4Rv/vbVjA==
Date: Wed, 28 May 2014 09:55:59 +0000
Deferred-Delivery: Wed, 28 May 2014 09:55:00 +0000
Message-ID: <E045AECD98228444A58C61C200AE1BD8426B8F97@xmb-rcd-x01.cisco.com>
Accept-Language: fr-FR, en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
x-originating-ip: [10.49.80.52]
Content-Type: multipart/alternative; boundary="_000_E045AECD98228444A58C61C200AE1BD8426B8F97xmbrcdx01ciscoc_"
MIME-Version: 1.0
Archived-At: http://mailarchive.ietf.org/arch/msg/6tisch-security/_ZgKhimlvHgYviTIwx1ChM0XakI
Cc: "6tisch-security@ietf.org" <6tisch-security@ietf.org>
Subject: [6tisch-security] Minutes Webex 27 May 2014, 6TiSCH Security Design Team
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 28 May 2014 09:56:11 -0000

--_000_E045AECD98228444A58C61C200AE1BD8426B8F97xmbrcdx01ciscoc_
Content-Type: text/plain; charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable

Note: timestamps in PDT.

Taking notes (using Etherpad)

  1.  Thomas Watteyne
  2.  Pascal Thubert

Present (alphabetically)

  1.  Thomas Watteyne
  2.  Pascal Thubert
  3.  Michael Richardson
  4.  Giuseppe Piro
  5.  Jonathan Simon
  6.  Michael Behringer
  7.  Nancy Cam-Winget
  8.  Pat Kinney
  9.  Rene Struik
  10. Subir Das
  11. Tom Phinney
  12. Yoshihiro Ohba

Recording

  *   Webex recording<https://cisco.webex.com/ciscosales/lsr.php?RCID=3D29d=
3c286fdaa4c4e97d0e057044029f6>[69min]

Agenda

  1.  note well
  2.  intros
  3.  open issues summarized in: http://www.ietf.org/mail-archive/web/6tisc=
h-security/current/msg00086.html
  4.  recap of draft-piro-
  5.  Wireless Hart -way --- how does the communication work?
  6.  how to summarize all of this to the working group
  7.  how to close this process up?

Action Items

  1.  Michael R. to create issues in the tracker for problems the group nee=
ds to address based on Ren=E9's list

Minutes

  *   [7.04] Meeting starts
  *   Michael Richardson adds agenda item per Rene's suggestion (open issue=
s)
  *   [7.05] note well applies, recording started
  *   [] outstanding issues:
     *   packet sizes
     *   device ID
     *   http://www.ietf.org/mail-archive/web/6tisch-security/current/msg00=
086.html
  *   Michael Richardson: think we all agree, why this order?
  *   Ren=E9 Struik: no real reason with order, anything works
  *   Ren=E9 Struik: what to design a protocol and see what missing pieces,=
 list based on calls, including call on Wireless HART, including tag name T=
om Phinney identified.
     *   tad name
     *   packet size: how much non-security bytes can be keep in packet. Be=
cause of time scheduling, every packet costs latency. We need to see whethe=
r we are close to packet size limit.
     *   join process impact on network: when take mote out of box, how doe=
s it join the network. To some degree, unclear how this really happens with=
 multiple channels and schedule
     *   protocol details: not so hard to do (crypto side), Security policy=
 side: AR, access to network is determined by having certificate. If cert v=
erifies, then by implication authorization. Different from ACL. different c=
alls about 1AR; it's all about cert and particular CA.
     *   hence issues: worried we have had many calls, we have meeting in J=
uly. If we want to discuss a real protocol, what do need to create a protoc=
ol. Outstanding issues are missing pieces.
     *   other: l looked at HART, ZigBee, etc. Supposed we want the HART fo=
undation to adopt, would be sad they refuse because too different. Maybe we=
 could reuse flows from HART to a very large degree, then from a HART persp=
ective, looks exactly the same. Would allows SDOs (e.g. HART) to move towar=
ds 6TiSCH long term.
  *   Michael Richardson: propose, go down room and see whether list is com=
plete, or whether things are missing. Are there things on list as solved, a=
nd remove with list.
  *   Pascal Thubert: did you expect exhaustive? [non-crypto details are no=
n defines]. packet size and number of packets. Match with the minimal suppo=
rt, in case of density impact of timers elapsing.
  *   Giuseppe Piro:
  *   Jonathan Simon: posted brief summary of HART join to 6TiSCH-sec group=
, including some of information. Joining process in Wireless HART, payload =
size are very on network header. Wireless HART has long/short address, grap=
h or source routing, sizes change quite a bit. Summary: very short security=
 handshake process because symmetric. sent a while ago proposal to use Pat =
Kinney. addresses issues such as how big flows are.
  *   Michael Richardson: can you find e-mail and paste in minutes: https:/=
/mailarchive.ietf.org/arch/msg/6tisch-security/s_LQeq8urO70A16rYnfEEXyjsts =
is recent message, and old message is:
  *   Ren=E9 Struik: remark: have not seen e-mail. Question what about tota=
l packet sizes, including configuration parameters. What needs to be togeth=
er?
  *   Jonathan Simon: in e-mail, indicates contents on the different packet=
s, including total. Can break out more is needed.
  *   Michael Behringer: problem is that don't know Wireless HART, coming f=
rom IP side. Needs to sit down and map to flows. we need to map out the flo=
w in draft-pritikin, see what kind of info is exchanged and packet size. we=
 can know what information is being exchanged. would need help from people =
who konw about e.g. packet iD. Useful?
  *   Michael Richardson: yes, would like to know how your diagrams are dif=
ferent from what posted already?
  *   Michael Behringer: yes, will have a loop.
  *   Giuseppe Piro: very important to understand size of packets during de=
sign of protocol. We are discussing size at MAC layer, can we consider frag=
mentations at MAC layer?
  *   Pat Kinney: 15.4e does not limit size of packets, the PHYs do. 15.4g =
have large size. Original PHYs remain at 127B.
  *   Ren=E9 Struik: why would we limit to 127B?
  *   Jonathan Simon: 4e designed to work on older PHY and 4g. Certainly th=
e first TSCH implementations on older PHY limited to 127B.
  *   Michael Richardson: might be more efficient on 4g PHY, but we must as=
sume that we wish to support older PHYs.
  *   Nancy Cam-Winget: trying to undeRen=E9 Struiktand: you can transmit o=
ne packet. In .11 there is fragmentation built into it. Does 15.4?
  *   Pat Kinney: no
  *   Michael Richardson: if we want to transmit a low payload, we need to =
fragment at adaptation layer, e.g. 6LoWPAN
  *   Subir Das: are we trying to design for old/new PHY.
  *   TW: we have to support legacy 15.4
  *   Pascal Thubert: agree. for the time being PHY includes legacy 15.4. w=
e have fragmentation, whatever we can do to limit amount of data needs to b=
e done, fragmentation needs to be done.
  *   Subir Das: sounds good, but are we restricting ourselves.
  *   TW: "old PHY" is not good name
  *   Jonathan Simon: newer PHYs have slower datarate
  *   Michael Richardson: back to Giuseppe Piro, more thoughts about crypto=
 details?
  *   Giuseppe Piro: only MAC or also upper layers?
  *   Michael Richardson: probably the latter.
  *   Giuseppe Piro: have to think further, will provide later
  *   Nancy Cam-Winget: would break it down. there may be different sensiti=
vities. From protocol details, we need to separate sessions establishment f=
rom provisioning.
  *   Michael Richardson: sessions establishment?
  *   Nancy Cam-Winget: how device connects to communicate securely. Provis=
ioning; draft-pri could be more heavier weight on how device comes up and c=
ommunicates securely.
  *   Michael Richardson: with provisioning, we also talk about distributio=
n of TS schedule. Is that it?
  *   Nancy Cam-Winget: more
  *   Pat Kinney: didn't have time to go through this list in enough detail
  *   Subir Das: goes through list now, will comment on ML.
  *   TP: no response
  *   YO: joined late today, a bit out of context
  *   TW:
  *   Jonathan Simon: will send link to e-mail later
  *   Michael Richardson: I think we have found what we want to do, list is=
 helpful. Preference is to do it the Wireless HART way, seems like an obvio=
us and easily solved update. Don't expect reuse bit from Wireless HART, but=
 only concepts.
     *   In my mind, of the 5 issues that Rene has brought up, packets size=
s is important and needs to be documented, but not show-stoppers of any kin=
d. We know that items will take more than 1 frame to deliver.
     *   device ID: aren't those replaceable by 1AR ID? can be make them lo=
ok like Wireless HART tagbane. Not sure what problems is with 64bit.
  *   Jonathan Simon: for Wireless HART, nodes are mostly always address th=
rough 16-bit ID. there are other application-layer tags to address devices,=
 bu=3Dt may be out of scope. frames themselves have 16-bit address
  *   Michael Richardson: multicast behavior? i.e. turn on all of all hallw=
ay light bulbs.
  *   Jonathan Simon: not really, in general address all devices, or one. N=
ot true multicast.
  *   Michael Richardson: Pascal is worried about AROs for joining. Part of=
 the reason of ARO is to go from 8-byte EUI to short address you will be as=
signed one. We hae not discussed whether 16-bit is assigned, or random and =
using DAD
  *   Michael Richardson: assume Rene can solve cryptography protocols, but=
 if we can use DTLS, we should. Assume is solved: we need to reuse DTLS.
  *   Michael Richardson: part e: just certificates, and doesn't matter? We=
 need to be very clear of what kind of cert is in place and needs to be. Th=
at's where the difficult problem is.
  *   Michael Richardson: list is complete, but many of the items are proba=
bly solved
  *   Ren=E9 Struik: not sure DTLS fits with 6TiSCH. wants to know what lat=
ency, etc. DTLS doesn't give all properties.
  *   Michael Richardson: not an advocate of DTLS, would replace by other p=
rotocols, but CoAP over DTLS is a thing, and people in app space want to us=
e it. Would be foolish to tell people to implement a second solution. not p=
erfect, but good enough. About 100 tune-able things in DTLS to get many beh=
avioRen=E9 Struik.
  *   Michael Richardson: how will we summarize to the WG, in the next 6 we=
eks before draft cutoff. What do we want to do?
  *   Pascal Thubert: would like to present the flows to the WG, show what =
happens. Also highlight shortcomings of DTLS.
  *   Michael Richardson: single answer. single answer with variations. e.g=
. 1X EAP-TLS is out?
  *   Pascal Thubert: hopefully not
  *   Ren=E9 Struik: could not hear
  *   Pascal Thubert: important it we make a choice like DTLS. interface be=
tween device and router. .can it be 1X or not, would like to see the flows =
for DTLS vs. EAP TLS vs Wireless HART to express what the options are.
  *   Michael Richardson: what level of detail?
  *   Pascal Thubert: we should see amount of messages and idea of what goe=
s in there. what's in the device, rough message size etc...
  *   Michael Richardson: number of packets, size of packets, abstraction o=
f contents.
  *   Pascal Thubert: size can be approximate, we need to know whether 1B o=
f 100kB.
  *   Michael Richardson: how do we arrive at conclusion about EAP-TLS. how=
 do we arrive at conclusion?
  *   Ren=E9 Struik: I don't understand how we have discussions. This is no=
t a technical discussion. We went over this list.
  *   Michael Richardson: in list, don't see questions.
  *   Ren=E9 Struik: e.g. simple topic, join process impact on network. Som=
e of these things should have a way of expressing it in 4e, right now some =
of these things. We have protocol flows, effectiveness is small. Why not go=
 through it with systematic way.
  *   Michael Richardson: we cannot have a draft until we answer the questi=
on. draft-piro answers many
  *   Ren=E9 Struik: only focus on 15.4. Does not answer the question how a=
 joining device joins, many many details. We need to have reached an overal=
l architecture.
  *   Subir Das: let';s consider solutions are work on architecture.
  *   Jonathan Simon: believe that the 4e spec is very clear on how device =
synchronizes, how send upstream traffic to coordinator, and get information=
 back if that's desired.
  *   Ren=E9 Struik: would be great
  *   Michael Richardson: should we turn those points in issues on issue tr=
acker.
  *   Ren=E9 Struik: if e.g. we have EB and get ASN, that doesn't mean the =
ASN time is the right one. only when the device gets the ASN, can we inject=
 it in the MAC table.
  *   Ren=E9 Struik: we need to move from initial state to synchronized ad =
security. how hears EB in 4e spec.
  *   Michael Richardson: device listens to EB, sync's, then send in a e.g.=
 ARO
  *   Ren=E9 Struik: if node wants to send the first packets, we need to kn=
ow where to send in. If we want to solve, would like to see how we're going=
 to solve it.
  *   Michael Richardson: will turn points in issue tracker. Then we can tr=
ack when things are solved. Trying to find process.
  *   Michael Richardson: would it be acceptable to walk through the issues=
 next week, or should be leave for later on?
  *   Ren=E9 Struik: fine, doesn't need to be number 1 on agenda. Main poin=
t is whether we want to mimic Wireless HART.
  *   Michael Richardson: major architectural decision, we need to reach co=
nsensus issue. Highest level.
  *   TW: would it be useful to have
  *   Michael Richardson: AOB?
  *   Ren=E9 Struik: can get slides with protocol flows, need until end of =
weeks, include HART flows
  *   Michael Richardson: OK. Maybe put on bitbucket, whatever you like
  *   Pascal Thubert: we have seen a number of flows to get the idea of wha=
t different with Wireless HART: what you get, what you need. Then, people w=
ill identify what properties we needs. We then will identify a approach and=
 comment on it. That's why interested in ARO.
  *   Michael Richardson: hard to hear you. repeat in e-mail?
  *   Pascal Thubert: Would like to see the flows, EAP/TLS, DTLS, Wireless =
HART and see variations between them. Then there is the ND ARO-based flows =
that Michael has ntrofuced in the ML, not sure whether this is the same as =
DTLS.
  *   Michael Richardson: AOB?

None other issues.

  *   Michael Richardson: will copy


--_000_E045AECD98228444A58C61C200AE1BD8426B8F97xmbrcdx01ciscoc_
Content-Type: text/html; charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable

<html xmlns:v=3D"urn:schemas-microsoft-com:vml" xmlns:o=3D"urn:schemas-micr=
osoft-com:office:office" xmlns:w=3D"urn:schemas-microsoft-com:office:word" =
xmlns:m=3D"http://schemas.microsoft.com/office/2004/12/omml" xmlns=3D"http:=
//www.w3.org/TR/REC-html40">
<head>
<meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3Diso-8859-=
1">
<meta name=3D"Generator" content=3D"Microsoft Word 14 (filtered medium)">
<style><!--
/* Font Definitions */
@font-face
	{font-family:Wingdings;
	panose-1:5 0 0 0 0 0 0 0 0 0;}
@font-face
	{font-family:Wingdings;
	panose-1:5 0 0 0 0 0 0 0 0 0;}
@font-face
	{font-family:Calibri;
	panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
	{font-family:Tahoma;
	panose-1:2 11 6 4 3 5 4 4 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
	{margin:0cm;
	margin-bottom:.0001pt;
	font-size:11.0pt;
	font-family:"Calibri","sans-serif";}
h1
	{mso-style-priority:9;
	mso-style-link:"Heading 1 Char";
	mso-margin-top-alt:auto;
	margin-right:0cm;
	mso-margin-bottom-alt:auto;
	margin-left:0cm;
	font-size:24.0pt;
	font-family:"Times New Roman","serif";
	font-weight:bold;}
h2
	{mso-style-priority:9;
	mso-style-link:"Heading 2 Char";
	mso-margin-top-alt:auto;
	margin-right:0cm;
	mso-margin-bottom-alt:auto;
	margin-left:0cm;
	font-size:18.0pt;
	font-family:"Times New Roman","serif";
	font-weight:bold;}
a:link, span.MsoHyperlink
	{mso-style-priority:99;
	color:blue;
	text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
	{mso-style-priority:99;
	color:purple;
	text-decoration:underline;}
p
	{mso-style-priority:99;
	mso-margin-top-alt:auto;
	margin-right:0cm;
	mso-margin-bottom-alt:auto;
	margin-left:0cm;
	font-size:12.0pt;
	font-family:"Times New Roman","serif";}
p.MsoAcetate, li.MsoAcetate, div.MsoAcetate
	{mso-style-priority:99;
	mso-style-link:"Balloon Text Char";
	margin:0cm;
	margin-bottom:.0001pt;
	font-size:8.0pt;
	font-family:"Tahoma","sans-serif";}
span.EmailStyle17
	{mso-style-type:personal-compose;
	font-family:"Calibri","sans-serif";
	color:windowtext;}
span.BalloonTextChar
	{mso-style-name:"Balloon Text Char";
	mso-style-priority:99;
	mso-style-link:"Balloon Text";
	font-family:"Tahoma","sans-serif";}
span.Heading1Char
	{mso-style-name:"Heading 1 Char";
	mso-style-priority:9;
	mso-style-link:"Heading 1";
	font-family:"Times New Roman","serif";
	font-weight:bold;}
span.Heading2Char
	{mso-style-name:"Heading 2 Char";
	mso-style-priority:9;
	mso-style-link:"Heading 2";
	font-family:"Times New Roman","serif";
	font-weight:bold;}
.MsoChpDefault
	{mso-style-type:export-only;
	font-family:"Calibri","sans-serif";}
@page WordSection1
	{size:612.0pt 792.0pt;
	margin:70.85pt 70.85pt 70.85pt 70.85pt;}
div.WordSection1
	{page:WordSection1;}
/* List Definitions */
@list l0
	{mso-list-id:199126935;
	mso-list-template-ids:-1469577472;}
@list l1
	{mso-list-id:873733358;
	mso-list-template-ids:-129616450;}
@list l2
	{mso-list-id:936641851;
	mso-list-template-ids:-1173326232;}
@list l3
	{mso-list-id:1449660946;
	mso-list-template-ids:83656500;}
@list l4
	{mso-list-id:2051026055;
	mso-list-template-ids:-804599740;}
@list l4:level1
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:36.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l4:level2
	{mso-level-number-format:bullet;
	mso-level-text:o;
	mso-level-tab-stop:72.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:"Courier New";
	mso-bidi-font-family:"Times New Roman";}
@list l4:level3
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:108.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l4:level4
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:144.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l4:level5
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:180.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l4:level6
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:216.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l4:level7
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:252.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l4:level8
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:288.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l4:level9
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:324.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l5
	{mso-list-id:2138713609;
	mso-list-template-ids:-1911751334;}
@list l5:level1
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:36.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l5:level2
	{mso-level-number-format:bullet;
	mso-level-text:o;
	mso-level-tab-stop:72.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:"Courier New";
	mso-bidi-font-family:"Times New Roman";}
@list l5:level3
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:108.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l5:level4
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:144.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l5:level5
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:180.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l5:level6
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:216.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l5:level7
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:252.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l5:level8
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:288.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l5:level9
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:324.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
ol
	{margin-bottom:0cm;}
ul
	{margin-bottom:0cm;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext=3D"edit" spidmax=3D"1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext=3D"edit">
<o:idmap v:ext=3D"edit" data=3D"1" />
</o:shapelayout></xml><![endif]-->
</head>
<body lang=3D"EN-US" link=3D"blue" vlink=3D"purple">
<div class=3D"WordSection1">
<p>Note: timestamps in PDT.<o:p></o:p></p>
<h2 id=3D"markdown-header-taking-notes-using-etherpad">Taking notes <em>(us=
ing Etherpad)</em><o:p></o:p></h2>
<ol start=3D"1" type=3D"1">
<li class=3D"MsoNormal" style=3D"mso-margin-top-alt:auto;mso-margin-bottom-=
alt:auto;mso-list:l3 level1 lfo1">
Thomas Watteyne<o:p></o:p></li><li class=3D"MsoNormal" style=3D"mso-margin-=
top-alt:auto;mso-margin-bottom-alt:auto;mso-list:l3 level1 lfo1">
Pascal Thubert<o:p></o:p></li></ol>
<h2 id=3D"markdown-header-present-alphabetically">Present <em>(alphabetical=
ly)</em><o:p></o:p></h2>
<ol start=3D"1" type=3D"1">
<li class=3D"MsoNormal" style=3D"mso-margin-top-alt:auto;mso-margin-bottom-=
alt:auto;mso-list:l2 level1 lfo2">
Thomas Watteyne<o:p></o:p></li><li class=3D"MsoNormal" style=3D"mso-margin-=
top-alt:auto;mso-margin-bottom-alt:auto;mso-list:l2 level1 lfo2">
Pascal Thubert<o:p></o:p></li><li class=3D"MsoNormal" style=3D"mso-margin-t=
op-alt:auto;mso-margin-bottom-alt:auto;mso-list:l2 level1 lfo2">
Michael Richardson<o:p></o:p></li><li class=3D"MsoNormal" style=3D"mso-marg=
in-top-alt:auto;mso-margin-bottom-alt:auto;mso-list:l2 level1 lfo2">
Giuseppe Piro<o:p></o:p></li><li class=3D"MsoNormal" style=3D"mso-margin-to=
p-alt:auto;mso-margin-bottom-alt:auto;mso-list:l2 level1 lfo2">
Jonathan Simon<o:p></o:p></li><li class=3D"MsoNormal" style=3D"mso-margin-t=
op-alt:auto;mso-margin-bottom-alt:auto;mso-list:l2 level1 lfo2">
Michael Behringer<o:p></o:p></li><li class=3D"MsoNormal" style=3D"mso-margi=
n-top-alt:auto;mso-margin-bottom-alt:auto;mso-list:l2 level1 lfo2">
Nancy Cam-Winget<o:p></o:p></li><li class=3D"MsoNormal" style=3D"mso-margin=
-top-alt:auto;mso-margin-bottom-alt:auto;mso-list:l2 level1 lfo2">
Pat Kinney<o:p></o:p></li><li class=3D"MsoNormal" style=3D"mso-margin-top-a=
lt:auto;mso-margin-bottom-alt:auto;mso-list:l2 level1 lfo2">
Rene Struik<o:p></o:p></li><li class=3D"MsoNormal" style=3D"mso-margin-top-=
alt:auto;mso-margin-bottom-alt:auto;mso-list:l2 level1 lfo2">
Subir Das<o:p></o:p></li><li class=3D"MsoNormal" style=3D"mso-margin-top-al=
t:auto;mso-margin-bottom-alt:auto;mso-list:l2 level1 lfo2">
Tom Phinney<o:p></o:p></li><li class=3D"MsoNormal" style=3D"mso-margin-top-=
alt:auto;mso-margin-bottom-alt:auto;mso-list:l2 level1 lfo2">
Yoshihiro Ohba<o:p></o:p></li></ol>
<h2 id=3D"markdown-header-recording">Recording<o:p></o:p></h2>
<ul type=3D"disc">
<li class=3D"MsoNormal" style=3D"mso-margin-top-alt:auto;mso-margin-bottom-=
alt:auto;mso-list:l4 level1 lfo3">
<a href=3D"https://cisco.webex.com/ciscosales/lsr.php?RCID=3D29d3c286fdaa4c=
4e97d0e057044029f6">Webex recording</a><em><span style=3D"font-family:&quot=
;Calibri&quot;,&quot;sans-serif&quot;">[69min]</span></em><o:p></o:p></li><=
/ul>
<h2 id=3D"markdown-header-agenda">Agenda<o:p></o:p></h2>
<ol start=3D"1" type=3D"1">
<li class=3D"MsoNormal" style=3D"mso-margin-top-alt:auto;mso-margin-bottom-=
alt:auto;mso-list:l1 level1 lfo4">
note well<o:p></o:p></li><li class=3D"MsoNormal" style=3D"mso-margin-top-al=
t:auto;mso-margin-bottom-alt:auto;mso-list:l1 level1 lfo4">
intros<o:p></o:p></li><li class=3D"MsoNormal" style=3D"mso-margin-top-alt:a=
uto;mso-margin-bottom-alt:auto;mso-list:l1 level1 lfo4">
open issues summarized in: <a href=3D"http://www.ietf.org/mail-archive/web/=
6tisch-security/current/msg00086.html">
http://www.ietf.org/mail-archive/web/6tisch-security/current/msg00086.html<=
/a><o:p></o:p></li><li class=3D"MsoNormal" style=3D"mso-margin-top-alt:auto=
;mso-margin-bottom-alt:auto;mso-list:l1 level1 lfo4">
recap of draft-piro-<o:p></o:p></li><li class=3D"MsoNormal" style=3D"mso-ma=
rgin-top-alt:auto;mso-margin-bottom-alt:auto;mso-list:l1 level1 lfo4">
Wireless Hart -way --- how does the communication work?<o:p></o:p></li><li =
class=3D"MsoNormal" style=3D"mso-margin-top-alt:auto;mso-margin-bottom-alt:=
auto;mso-list:l1 level1 lfo4">
how to summarize all of this to the working group<o:p></o:p></li><li class=
=3D"MsoNormal" style=3D"mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;=
mso-list:l1 level1 lfo4">
how to close this process up?<o:p></o:p></li></ol>
<h2 id=3D"markdown-header-action-items">Action Items<o:p></o:p></h2>
<ol start=3D"1" type=3D"1">
<li class=3D"MsoNormal" style=3D"mso-margin-top-alt:auto;mso-margin-bottom-=
alt:auto;mso-list:l0 level1 lfo5">
Michael R. to create issues in the tracker for problems the group needs to =
address based on Ren=E9's list<o:p></o:p></li></ol>
<h2 id=3D"markdown-header-minutes">Minutes<o:p></o:p></h2>
<ul type=3D"disc">
<li class=3D"MsoNormal" style=3D"mso-margin-top-alt:auto;mso-margin-bottom-=
alt:auto;mso-list:l5 level1 lfo6">
[7.04] Meeting starts<o:p></o:p></li><li class=3D"MsoNormal" style=3D"mso-m=
argin-top-alt:auto;mso-margin-bottom-alt:auto;mso-list:l5 level1 lfo6">
Michael Richardson adds agenda item per Rene's suggestion (open issues)<o:p=
></o:p></li><li class=3D"MsoNormal" style=3D"mso-margin-top-alt:auto;mso-ma=
rgin-bottom-alt:auto;mso-list:l5 level1 lfo6">
[7.05] note well applies, recording started<o:p></o:p></li><li class=3D"Mso=
Normal" style=3D"mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;mso-lis=
t:l5 level1 lfo6">
[] outstanding issues:<o:p></o:p>
<ul type=3D"circle">
<li class=3D"MsoNormal" style=3D"mso-margin-top-alt:auto;mso-margin-bottom-=
alt:auto;mso-list:l5 level2 lfo6">
packet sizes<o:p></o:p></li><li class=3D"MsoNormal" style=3D"mso-margin-top=
-alt:auto;mso-margin-bottom-alt:auto;mso-list:l5 level2 lfo6">
device ID<o:p></o:p></li><li class=3D"MsoNormal" style=3D"mso-margin-top-al=
t:auto;mso-margin-bottom-alt:auto;mso-list:l5 level2 lfo6">
<a href=3D"http://www.ietf.org/mail-archive/web/6tisch-security/current/msg=
00086.html">http://www.ietf.org/mail-archive/web/6tisch-security/current/ms=
g00086.html</a><o:p></o:p></li></ul>
</li><li class=3D"MsoNormal" style=3D"mso-margin-top-alt:auto;mso-margin-bo=
ttom-alt:auto;mso-list:l5 level1 lfo6">
Michael Richardson: think we all agree, why this order?<o:p></o:p></li><li =
class=3D"MsoNormal" style=3D"mso-margin-top-alt:auto;mso-margin-bottom-alt:=
auto;mso-list:l5 level1 lfo6">
Ren=E9 Struik: no real reason with order, anything works<o:p></o:p></li><li=
 class=3D"MsoNormal" style=3D"mso-margin-top-alt:auto;mso-margin-bottom-alt=
:auto;mso-list:l5 level1 lfo6">
Ren=E9 Struik: what to design a protocol and see what missing pieces, list =
based on calls, including call on Wireless HART, including tag name Tom Phi=
nney identified.<o:p></o:p>
<ul type=3D"circle">
<li class=3D"MsoNormal" style=3D"mso-margin-top-alt:auto;mso-margin-bottom-=
alt:auto;mso-list:l5 level2 lfo6">
tad name<o:p></o:p></li><li class=3D"MsoNormal" style=3D"mso-margin-top-alt=
:auto;mso-margin-bottom-alt:auto;mso-list:l5 level2 lfo6">
packet size: how much non-security bytes can be keep in packet. Because of =
time scheduling, every packet costs latency. We need to see whether we are =
close to packet size limit.<o:p></o:p></li><li class=3D"MsoNormal" style=3D=
"mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;mso-list:l5 level2 lfo6=
">
join process impact on network: when take mote out of box, how does it join=
 the network. To some degree, unclear how this really happens with multiple=
 channels and schedule<o:p></o:p></li><li class=3D"MsoNormal" style=3D"mso-=
margin-top-alt:auto;mso-margin-bottom-alt:auto;mso-list:l5 level2 lfo6">
protocol details: not so hard to do (crypto side), Security policy side: AR=
, access to network is determined by having certificate. If cert verifies, =
then by implication authorization. Different from ACL. different calls abou=
t 1AR; it's all about cert and particular
 CA.<o:p></o:p></li><li class=3D"MsoNormal" style=3D"mso-margin-top-alt:aut=
o;mso-margin-bottom-alt:auto;mso-list:l5 level2 lfo6">
hence issues: worried we have had many calls, we have meeting in July. If w=
e want to discuss a real protocol, what do need to create a protocol. Outst=
anding issues are missing pieces.<o:p></o:p></li><li class=3D"MsoNormal" st=
yle=3D"mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;mso-list:l5 level=
2 lfo6">
other: l looked at HART, ZigBee, etc. Supposed we want the HART foundation =
to adopt, would be sad they refuse because too different. Maybe we could re=
use flows from HART to a very large degree, then from a HART perspective, l=
ooks exactly the same. Would allows
 SDOs (e.g. HART) to move towards 6TiSCH long term.<o:p></o:p></li></ul>
</li><li class=3D"MsoNormal" style=3D"mso-margin-top-alt:auto;mso-margin-bo=
ttom-alt:auto;mso-list:l5 level1 lfo6">
Michael Richardson: propose, go down room and see whether list is complete,=
 or whether things are missing. Are there things on list as solved, and rem=
ove with list.<o:p></o:p></li><li class=3D"MsoNormal" style=3D"mso-margin-t=
op-alt:auto;mso-margin-bottom-alt:auto;mso-list:l5 level1 lfo6">
Pascal Thubert: did you expect exhaustive? [non-crypto details are non defi=
nes]. packet size and number of packets. Match with the minimal support, in=
 case of density impact of timers elapsing.<o:p></o:p></li><li class=3D"Mso=
Normal" style=3D"mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;mso-lis=
t:l5 level1 lfo6">
Giuseppe Piro: <o:p></o:p></li><li class=3D"MsoNormal" style=3D"mso-margin-=
top-alt:auto;mso-margin-bottom-alt:auto;mso-list:l5 level1 lfo6">
Jonathan Simon: posted brief summary of HART join to 6TiSCH-sec group, incl=
uding some of information. Joining process in Wireless HART, payload size a=
re very on network header. Wireless HART has long/short address, graph or s=
ource routing, sizes change quite
 a bit. Summary: very short security handshake process because symmetric. s=
ent a while ago proposal to use Pat Kinney. addresses issues such as how bi=
g flows are.<o:p></o:p></li><li class=3D"MsoNormal" style=3D"mso-margin-top=
-alt:auto;mso-margin-bottom-alt:auto;mso-list:l5 level1 lfo6">
Michael Richardson: can you find e-mail and paste in minutes: <a href=3D"ht=
tps://mailarchive.ietf.org/arch/msg/6tisch-security/s_LQeq8urO70A16rYnfEEXy=
jsts">
https://mailarchive.ietf.org/arch/msg/6tisch-security/s_LQeq8urO70A16rYnfEE=
Xyjsts</a> is recent message, and old message is:
<o:p></o:p></li><li class=3D"MsoNormal" style=3D"mso-margin-top-alt:auto;ms=
o-margin-bottom-alt:auto;mso-list:l5 level1 lfo6">
Ren=E9 Struik: remark: have not seen e-mail. Question what about total pack=
et sizes, including configuration parameters. What needs to be together?<o:=
p></o:p></li><li class=3D"MsoNormal" style=3D"mso-margin-top-alt:auto;mso-m=
argin-bottom-alt:auto;mso-list:l5 level1 lfo6">
Jonathan Simon: in e-mail, indicates contents on the different packets, inc=
luding total. Can break out more is needed.<o:p></o:p></li><li class=3D"Mso=
Normal" style=3D"mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;mso-lis=
t:l5 level1 lfo6">
Michael Behringer: problem is that don't know Wireless HART, coming from IP=
 side. Needs to sit down and map to flows. we need to map out the flow in d=
raft-pritikin, see what kind of info is exchanged and packet size. we can k=
now what information is being exchanged.
 would need help from people who konw about e.g. packet iD. Useful?<o:p></o=
:p></li><li class=3D"MsoNormal" style=3D"mso-margin-top-alt:auto;mso-margin=
-bottom-alt:auto;mso-list:l5 level1 lfo6">
Michael Richardson: yes, would like to know how your diagrams are different=
 from what posted already?<o:p></o:p></li><li class=3D"MsoNormal" style=3D"=
mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;mso-list:l5 level1 lfo6"=
>
Michael Behringer: yes, will have a loop.<o:p></o:p></li><li class=3D"MsoNo=
rmal" style=3D"mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;mso-list:=
l5 level1 lfo6">
Giuseppe Piro: very important to understand size of packets during design o=
f protocol. We are discussing size at MAC layer, can we consider fragmentat=
ions at MAC layer?<o:p></o:p></li><li class=3D"MsoNormal" style=3D"mso-marg=
in-top-alt:auto;mso-margin-bottom-alt:auto;mso-list:l5 level1 lfo6">
Pat Kinney: 15.4e does not limit size of packets, the PHYs do. 15.4g have l=
arge size. Original PHYs remain at 127B.<o:p></o:p></li><li class=3D"MsoNor=
mal" style=3D"mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;mso-list:l=
5 level1 lfo6">
Ren=E9 Struik: why would we limit to 127B?<o:p></o:p></li><li class=3D"MsoN=
ormal" style=3D"mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;mso-list=
:l5 level1 lfo6">
Jonathan Simon: 4e designed to work on older PHY and 4g. Certainly the firs=
t TSCH implementations on older PHY limited to 127B.<o:p></o:p></li><li cla=
ss=3D"MsoNormal" style=3D"mso-margin-top-alt:auto;mso-margin-bottom-alt:aut=
o;mso-list:l5 level1 lfo6">
Michael Richardson: might be more efficient on 4g PHY, but we must assume t=
hat we wish to support older PHYs.<o:p></o:p></li><li class=3D"MsoNormal" s=
tyle=3D"mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;mso-list:l5 leve=
l1 lfo6">
Nancy Cam-Winget: trying to undeRen=E9 Struiktand: you can transmit one pac=
ket. In .11 there is fragmentation built into it. Does 15.4?<o:p></o:p></li=
><li class=3D"MsoNormal" style=3D"mso-margin-top-alt:auto;mso-margin-bottom=
-alt:auto;mso-list:l5 level1 lfo6">
Pat Kinney: no<o:p></o:p></li><li class=3D"MsoNormal" style=3D"mso-margin-t=
op-alt:auto;mso-margin-bottom-alt:auto;mso-list:l5 level1 lfo6">
Michael Richardson: if we want to transmit a low payload, we need to fragme=
nt at adaptation layer, e.g. 6LoWPAN<o:p></o:p></li><li class=3D"MsoNormal"=
 style=3D"mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;mso-list:l5 le=
vel1 lfo6">
Subir Das: are we trying to design for old/new PHY.<o:p></o:p></li><li clas=
s=3D"MsoNormal" style=3D"mso-margin-top-alt:auto;mso-margin-bottom-alt:auto=
;mso-list:l5 level1 lfo6">
TW: we have to support legacy 15.4<o:p></o:p></li><li class=3D"MsoNormal" s=
tyle=3D"mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;mso-list:l5 leve=
l1 lfo6">
Pascal Thubert: agree. for the time being PHY includes legacy 15.4. we have=
 fragmentation, whatever we can do to limit amount of data needs to be done=
, fragmentation needs to be done.<o:p></o:p></li><li class=3D"MsoNormal" st=
yle=3D"mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;mso-list:l5 level=
1 lfo6">
Subir Das: sounds good, but are we restricting ourselves.<o:p></o:p></li><l=
i class=3D"MsoNormal" style=3D"mso-margin-top-alt:auto;mso-margin-bottom-al=
t:auto;mso-list:l5 level1 lfo6">
TW: &quot;old PHY&quot; is not good name<o:p></o:p></li><li class=3D"MsoNor=
mal" style=3D"mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;mso-list:l=
5 level1 lfo6">
Jonathan Simon: newer PHYs have slower datarate<o:p></o:p></li><li class=3D=
"MsoNormal" style=3D"mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;mso=
-list:l5 level1 lfo6">
Michael Richardson: back to Giuseppe Piro, more thoughts about crypto detai=
ls?<o:p></o:p></li><li class=3D"MsoNormal" style=3D"mso-margin-top-alt:auto=
;mso-margin-bottom-alt:auto;mso-list:l5 level1 lfo6">
Giuseppe Piro: only MAC or also upper layers?<o:p></o:p></li><li class=3D"M=
soNormal" style=3D"mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;mso-l=
ist:l5 level1 lfo6">
Michael Richardson: probably the latter.<o:p></o:p></li><li class=3D"MsoNor=
mal" style=3D"mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;mso-list:l=
5 level1 lfo6">
Giuseppe Piro: have to think further, will provide later<o:p></o:p></li><li=
 class=3D"MsoNormal" style=3D"mso-margin-top-alt:auto;mso-margin-bottom-alt=
:auto;mso-list:l5 level1 lfo6">
Nancy Cam-Winget: would break it down. there may be different sensitivities=
. From protocol details, we need to separate sessions establishment from pr=
ovisioning.<o:p></o:p></li><li class=3D"MsoNormal" style=3D"mso-margin-top-=
alt:auto;mso-margin-bottom-alt:auto;mso-list:l5 level1 lfo6">
Michael Richardson: sessions establishment?<o:p></o:p></li><li class=3D"Mso=
Normal" style=3D"mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;mso-lis=
t:l5 level1 lfo6">
Nancy Cam-Winget: how device connects to communicate securely. Provisioning=
; draft-pri could be more heavier weight on how device comes up and communi=
cates securely.<o:p></o:p></li><li class=3D"MsoNormal" style=3D"mso-margin-=
top-alt:auto;mso-margin-bottom-alt:auto;mso-list:l5 level1 lfo6">
Michael Richardson: with provisioning, we also talk about distribution of T=
S schedule. Is that it?<o:p></o:p></li><li class=3D"MsoNormal" style=3D"mso=
-margin-top-alt:auto;mso-margin-bottom-alt:auto;mso-list:l5 level1 lfo6">
Nancy Cam-Winget: more <o:p></o:p></li><li class=3D"MsoNormal" style=3D"mso=
-margin-top-alt:auto;mso-margin-bottom-alt:auto;mso-list:l5 level1 lfo6">
Pat Kinney: didn't have time to go through this list in enough detail<o:p><=
/o:p></li><li class=3D"MsoNormal" style=3D"mso-margin-top-alt:auto;mso-marg=
in-bottom-alt:auto;mso-list:l5 level1 lfo6">
Subir Das: goes through list now, will comment on ML.<o:p></o:p></li><li cl=
ass=3D"MsoNormal" style=3D"mso-margin-top-alt:auto;mso-margin-bottom-alt:au=
to;mso-list:l5 level1 lfo6">
TP: no response<o:p></o:p></li><li class=3D"MsoNormal" style=3D"mso-margin-=
top-alt:auto;mso-margin-bottom-alt:auto;mso-list:l5 level1 lfo6">
YO: joined late today, a bit out of context<o:p></o:p></li><li class=3D"Mso=
Normal" style=3D"mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;mso-lis=
t:l5 level1 lfo6">
TW:<o:p></o:p></li><li class=3D"MsoNormal" style=3D"mso-margin-top-alt:auto=
;mso-margin-bottom-alt:auto;mso-list:l5 level1 lfo6">
Jonathan Simon: will send link to e-mail later<o:p></o:p></li><li class=3D"=
MsoNormal" style=3D"mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;mso-=
list:l5 level1 lfo6">
Michael Richardson: I think we have found what we want to do, list is helpf=
ul. Preference is to do it the Wireless HART way, seems like an obvious and=
 easily solved update. Don't expect reuse bit from Wireless HART, but only =
concepts.<o:p></o:p>
<ul type=3D"circle">
<li class=3D"MsoNormal" style=3D"mso-margin-top-alt:auto;mso-margin-bottom-=
alt:auto;mso-list:l5 level2 lfo6">
In my mind, of the 5 issues that Rene has brought up, packets sizes is impo=
rtant and needs to be documented, but not show-stoppers of any kind. We kno=
w that items will take more than 1 frame to deliver.<o:p></o:p></li><li cla=
ss=3D"MsoNormal" style=3D"mso-margin-top-alt:auto;mso-margin-bottom-alt:aut=
o;mso-list:l5 level2 lfo6">
device ID: aren't those replaceable by 1AR ID? can be make them look like W=
ireless HART tagbane. Not sure what problems is with 64bit.<o:p></o:p></li>=
</ul>
</li><li class=3D"MsoNormal" style=3D"mso-margin-top-alt:auto;mso-margin-bo=
ttom-alt:auto;mso-list:l5 level1 lfo6">
Jonathan Simon: for Wireless HART, nodes are mostly always address through =
16-bit ID. there are other application-layer tags to address devices, bu=3D=
t may be out of scope. frames themselves have 16-bit address<o:p></o:p></li=
><li class=3D"MsoNormal" style=3D"mso-margin-top-alt:auto;mso-margin-bottom=
-alt:auto;mso-list:l5 level1 lfo6">
Michael Richardson: multicast behavior? i.e. turn on all of all hallway lig=
ht bulbs.<o:p></o:p></li><li class=3D"MsoNormal" style=3D"mso-margin-top-al=
t:auto;mso-margin-bottom-alt:auto;mso-list:l5 level1 lfo6">
Jonathan Simon: not really, in general address all devices, or one. Not tru=
e multicast.<o:p></o:p></li><li class=3D"MsoNormal" style=3D"mso-margin-top=
-alt:auto;mso-margin-bottom-alt:auto;mso-list:l5 level1 lfo6">
Michael Richardson: Pascal is worried about AROs for joining. Part of the r=
eason of ARO is to go from 8-byte EUI to short address you will be assigned=
 one. We hae not discussed whether 16-bit is assigned, or random and using =
DAD<o:p></o:p></li><li class=3D"MsoNormal" style=3D"mso-margin-top-alt:auto=
;mso-margin-bottom-alt:auto;mso-list:l5 level1 lfo6">
Michael Richardson: assume Rene can solve cryptography protocols, but if we=
 can use DTLS, we should. Assume is solved: we need to reuse DTLS.<o:p></o:=
p></li><li class=3D"MsoNormal" style=3D"mso-margin-top-alt:auto;mso-margin-=
bottom-alt:auto;mso-list:l5 level1 lfo6">
Michael Richardson: part e: just certificates, and doesn't matter? We need =
to be very clear of what kind of cert is in place and needs to be. That's w=
here the difficult problem is.<o:p></o:p></li><li class=3D"MsoNormal" style=
=3D"mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;mso-list:l5 level1 l=
fo6">
Michael Richardson: list is complete, but many of the items are probably so=
lved<o:p></o:p></li><li class=3D"MsoNormal" style=3D"mso-margin-top-alt:aut=
o;mso-margin-bottom-alt:auto;mso-list:l5 level1 lfo6">
Ren=E9 Struik: not sure DTLS fits with 6TiSCH. wants to know what latency, =
etc. DTLS doesn't give all properties.<o:p></o:p></li><li class=3D"MsoNorma=
l" style=3D"mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;mso-list:l5 =
level1 lfo6">
Michael Richardson: not an advocate of DTLS, would replace by other protoco=
ls, but CoAP over DTLS is a thing, and people in app space want to use it. =
Would be foolish to tell people to implement a second solution. not perfect=
, but good enough. About 100 tune-able
 things in DTLS to get many behavioRen=E9 Struik.<o:p></o:p></li><li class=
=3D"MsoNormal" style=3D"mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;=
mso-list:l5 level1 lfo6">
Michael Richardson: how will we summarize to the WG, in the next 6 weeks be=
fore draft cutoff. What do we want to do?<o:p></o:p></li><li class=3D"MsoNo=
rmal" style=3D"mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;mso-list:=
l5 level1 lfo6">
Pascal Thubert: would like to present the flows to the WG, show what happen=
s. Also highlight shortcomings of DTLS.<o:p></o:p></li><li class=3D"MsoNorm=
al" style=3D"mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;mso-list:l5=
 level1 lfo6">
Michael Richardson: single answer. single answer with variations. e.g. 1X E=
AP-TLS is out?<o:p></o:p></li><li class=3D"MsoNormal" style=3D"mso-margin-t=
op-alt:auto;mso-margin-bottom-alt:auto;mso-list:l5 level1 lfo6">
Pascal Thubert: hopefully not<o:p></o:p></li><li class=3D"MsoNormal" style=
=3D"mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;mso-list:l5 level1 l=
fo6">
Ren=E9 Struik: could not hear<o:p></o:p></li><li class=3D"MsoNormal" style=
=3D"mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;mso-list:l5 level1 l=
fo6">
Pascal Thubert: important it we make a choice like DTLS. interface between =
device and router. .can it be 1X or not, would like to see the flows for DT=
LS vs. EAP TLS vs Wireless HART to express what the options are.<o:p></o:p>=
</li><li class=3D"MsoNormal" style=3D"mso-margin-top-alt:auto;mso-margin-bo=
ttom-alt:auto;mso-list:l5 level1 lfo6">
Michael Richardson: what level of detail?<o:p></o:p></li><li class=3D"MsoNo=
rmal" style=3D"mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;mso-list:=
l5 level1 lfo6">
Pascal Thubert: we should see amount of messages and idea of what goes in t=
here. what's in the device, rough message size etc...<o:p></o:p></li><li cl=
ass=3D"MsoNormal" style=3D"mso-margin-top-alt:auto;mso-margin-bottom-alt:au=
to;mso-list:l5 level1 lfo6">
Michael Richardson: number of packets, size of packets, abstraction of cont=
ents.<o:p></o:p></li><li class=3D"MsoNormal" style=3D"mso-margin-top-alt:au=
to;mso-margin-bottom-alt:auto;mso-list:l5 level1 lfo6">
Pascal Thubert: size can be approximate, we need to know whether 1B of 100k=
B.<o:p></o:p></li><li class=3D"MsoNormal" style=3D"mso-margin-top-alt:auto;=
mso-margin-bottom-alt:auto;mso-list:l5 level1 lfo6">
Michael Richardson: how do we arrive at conclusion about EAP-TLS. how do we=
 arrive at conclusion?<o:p></o:p></li><li class=3D"MsoNormal" style=3D"mso-=
margin-top-alt:auto;mso-margin-bottom-alt:auto;mso-list:l5 level1 lfo6">
Ren=E9 Struik: I don't understand how we have discussions. This is not a te=
chnical discussion. We went over this list.<o:p></o:p></li><li class=3D"Mso=
Normal" style=3D"mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;mso-lis=
t:l5 level1 lfo6">
Michael Richardson: in list, don't see questions.<o:p></o:p></li><li class=
=3D"MsoNormal" style=3D"mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;=
mso-list:l5 level1 lfo6">
Ren=E9 Struik: e.g. simple topic, join process impact on network. Some of t=
hese things should have a way of expressing it in 4e, right now some of the=
se things. We have protocol flows, effectiveness is small. Why not go throu=
gh it with systematic way.<o:p></o:p></li><li class=3D"MsoNormal" style=3D"=
mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;mso-list:l5 level1 lfo6"=
>
Michael Richardson: we cannot have a draft until we answer the question. dr=
aft-piro answers many<o:p></o:p></li><li class=3D"MsoNormal" style=3D"mso-m=
argin-top-alt:auto;mso-margin-bottom-alt:auto;mso-list:l5 level1 lfo6">
Ren=E9 Struik: only focus on 15.4. Does not answer the question how a joini=
ng device joins, many many details. We need to have reached an overall arch=
itecture.<o:p></o:p></li><li class=3D"MsoNormal" style=3D"mso-margin-top-al=
t:auto;mso-margin-bottom-alt:auto;mso-list:l5 level1 lfo6">
Subir Das: let';s consider solutions are work on architecture.<o:p></o:p></=
li><li class=3D"MsoNormal" style=3D"mso-margin-top-alt:auto;mso-margin-bott=
om-alt:auto;mso-list:l5 level1 lfo6">
Jonathan Simon: believe that the 4e spec is very clear on how device synchr=
onizes, how send upstream traffic to coordinator, and get information back =
if that's desired.<o:p></o:p></li><li class=3D"MsoNormal" style=3D"mso-marg=
in-top-alt:auto;mso-margin-bottom-alt:auto;mso-list:l5 level1 lfo6">
Ren=E9 Struik: would be great<o:p></o:p></li><li class=3D"MsoNormal" style=
=3D"mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;mso-list:l5 level1 l=
fo6">
Michael Richardson: should we turn those points in issues on issue tracker.=
<o:p></o:p></li><li class=3D"MsoNormal" style=3D"mso-margin-top-alt:auto;ms=
o-margin-bottom-alt:auto;mso-list:l5 level1 lfo6">
Ren=E9 Struik: if e.g. we have EB and get ASN, that doesn't mean the ASN ti=
me is the right one. only when the device gets the ASN, can we inject it in=
 the MAC table.
<o:p></o:p></li><li class=3D"MsoNormal" style=3D"mso-margin-top-alt:auto;ms=
o-margin-bottom-alt:auto;mso-list:l5 level1 lfo6">
Ren=E9 Struik: we need to move from initial state to synchronized ad securi=
ty. how hears EB in 4e spec.<o:p></o:p></li><li class=3D"MsoNormal" style=
=3D"mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;mso-list:l5 level1 l=
fo6">
Michael Richardson: device listens to EB, sync's, then send in a e.g. ARO<o=
:p></o:p></li><li class=3D"MsoNormal" style=3D"mso-margin-top-alt:auto;mso-=
margin-bottom-alt:auto;mso-list:l5 level1 lfo6">
Ren=E9 Struik: if node wants to send the first packets, we need to know whe=
re to send in. If we want to solve, would like to see how we're going to so=
lve it.<o:p></o:p></li><li class=3D"MsoNormal" style=3D"mso-margin-top-alt:=
auto;mso-margin-bottom-alt:auto;mso-list:l5 level1 lfo6">
Michael Richardson: will turn points in issue tracker. Then we can track wh=
en things are solved. Trying to find process.<o:p></o:p></li><li class=3D"M=
soNormal" style=3D"mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;mso-l=
ist:l5 level1 lfo6">
Michael Richardson: would it be acceptable to walk through the issues next =
week, or should be leave for later on?<o:p></o:p></li><li class=3D"MsoNorma=
l" style=3D"mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;mso-list:l5 =
level1 lfo6">
Ren=E9 Struik: fine, doesn't need to be number 1 on agenda. Main point is w=
hether we want to mimic Wireless HART.<o:p></o:p></li><li class=3D"MsoNorma=
l" style=3D"mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;mso-list:l5 =
level1 lfo6">
Michael Richardson: major architectural decision, we need to reach consensu=
s issue. Highest level.
<o:p></o:p></li><li class=3D"MsoNormal" style=3D"mso-margin-top-alt:auto;ms=
o-margin-bottom-alt:auto;mso-list:l5 level1 lfo6">
TW: would it be useful to have <o:p></o:p></li><li class=3D"MsoNormal" styl=
e=3D"mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;mso-list:l5 level1 =
lfo6">
Michael Richardson: AOB?<o:p></o:p></li><li class=3D"MsoNormal" style=3D"ms=
o-margin-top-alt:auto;mso-margin-bottom-alt:auto;mso-list:l5 level1 lfo6">
Ren=E9 Struik: can get slides with protocol flows, need until end of weeks,=
 include HART flows<o:p></o:p></li><li class=3D"MsoNormal" style=3D"mso-mar=
gin-top-alt:auto;mso-margin-bottom-alt:auto;mso-list:l5 level1 lfo6">
Michael Richardson: OK. Maybe put on bitbucket, whatever you like<o:p></o:p=
></li><li class=3D"MsoNormal" style=3D"mso-margin-top-alt:auto;mso-margin-b=
ottom-alt:auto;mso-list:l5 level1 lfo6">
Pascal Thubert: we have seen a number of flows to get the idea of what diff=
erent with Wireless HART: what you get, what you need. Then, people will id=
entify what properties we needs. We then will identify a approach and comme=
nt on it. That's why interested
 in ARO.<o:p></o:p></li><li class=3D"MsoNormal" style=3D"mso-margin-top-alt=
:auto;mso-margin-bottom-alt:auto;mso-list:l5 level1 lfo6">
Michael Richardson: hard to hear you. repeat in e-mail?<o:p></o:p></li><li =
class=3D"MsoNormal" style=3D"mso-margin-top-alt:auto;mso-margin-bottom-alt:=
auto;mso-list:l5 level1 lfo6">
Pascal Thubert: Would like to see the flows, EAP/TLS, DTLS, Wireless HART a=
nd see variations between them. Then there is the ND ARO-based flows that M=
ichael has ntrofuced in the ML, not sure whether this is the same as DTLS.<=
o:p></o:p></li><li class=3D"MsoNormal" style=3D"mso-margin-top-alt:auto;mso=
-margin-bottom-alt:auto;mso-list:l5 level1 lfo6">
Michael Richardson: AOB?<o:p></o:p></li></ul>
<p style=3D"margin-left:36.0pt">None other issues.<o:p></o:p></p>
<ul type=3D"disc">
<li class=3D"MsoNormal" style=3D"mso-margin-top-alt:auto;mso-margin-bottom-=
alt:auto;mso-list:l5 level1 lfo6">
Michael Richardson: will copy<o:p></o:p></li></ul>
<p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p>
</div>
</body>
</html>

--_000_E045AECD98228444A58C61C200AE1BD8426B8F97xmbrcdx01ciscoc_--


From nobody Wed May 28 07:49:34 2014
Return-Path: <jsimon@linear.com>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id B668B1A035B for <6tisch-security@ietfa.amsl.com>; Wed, 28 May 2014 07:49:32 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.587
X-Spam-Level: 
X-Spam-Status: No, score=-1.587 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, FM_FORGED_GMAIL=0.622, HTML_MESSAGE=0.001, HTTPS_HTTP_MISMATCH=1.989, RCVD_IN_DNSWL_MED=-2.3, WEIRD_PORT=0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id F7MNQYEhKifX for <6tisch-security@ietfa.amsl.com>; Wed, 28 May 2014 07:49:28 -0700 (PDT)
Received: from p02c11o141.mxlogic.net (p02c11o141.mxlogic.net [208.65.144.74]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 13E491A09B3 for <6tisch-security@ietf.org>; Wed, 28 May 2014 07:49:28 -0700 (PDT)
Received: from unknown [12.218.215.72] (EHLO smtpauth1.linear.com) by p02c11o141.mxlogic.net(mxl_mta-8.0.0-1) with ESMTP id 477f5835.0.16588.00-374.47223.p02c11o141.mxlogic.net (envelope-from <jsimon@linear.com>);  Wed, 28 May 2014 08:49:24 -0600 (MDT)
X-MXL-Hash: 5385f7746a9539f3-fc425da912b20851289f86c2395ef6bbd954c035
Received: from mail-qg0-f50.google.com (mail-qg0-f50.google.com [209.85.192.50]) by smtpauth1.linear.com (Postfix) with ESMTPSA id ACFAE740AF for <6tisch-security@ietf.org>; Wed, 28 May 2014 07:49:22 -0700 (PDT)
Received: by mail-qg0-f50.google.com with SMTP id z60so17849023qgd.37 for <6tisch-security@ietf.org>; Wed, 28 May 2014 07:49:23 -0700 (PDT)
MIME-Version: 1.0
X-Received: by 10.224.30.70 with SMTP id t6mr203515qac.30.1401288562985; Wed, 28 May 2014 07:49:22 -0700 (PDT)
Received: by 10.229.117.74 with HTTP; Wed, 28 May 2014 07:49:22 -0700 (PDT)
In-Reply-To: <674F70E5F2BE564CB06B6901FD3DD78B2723B576@TGXML210.toshiba.local>
References: <E045AECD98228444A58C61C200AE1BD8416F3AF4@xmb-rcd-x01.cisco.com> <531DD632.2060009@cox.net> <531DDB20.5050600@gmail.com> <10925.1394631496@sandelman.ca> <532069C8.2050005@gmail.com> <23590.1394999032@sandelman.ca> <18106.1395625035@sandelman.ca> <19609.1396839403@sandelman.ca> <11557.1397444260@sandelman.ca> <28192.1398644294@sandelman.ca> <29064.1399255587@sandelman.ca> <19475.1400588783@sandelman.ca> <4903.1401158997@sandelman.ca> <53840205.2070103@gmail.com> <CAJeFcoS3PNFX2obx3uNDJDtH=QvNLmaPhw2R468sNaeqpo8QBQ@mail.gmail.com> <674F70E5F2BE564CB06B6901FD3DD78B2723B576@TGXML210.toshiba.local>
Date: Wed, 28 May 2014 07:49:22 -0700
Message-ID: <CAJeFcoQBp1A7pwZHWoesvrjSySW0UZ0k11-s3-MFAozSuR0Yrw@mail.gmail.com>
From: Jonathan Simon <jsimon@linear.com>
To: yoshihiro.ohba@toshiba.co.jp
Content-Type: multipart/alternative; boundary=047d7bdca66a06732604fa76ebbb
X-AnalysisOut: [v=2.1 cv=J7Qk7WXS c=1 sm=1 tr=0 a=glloKNylpeYNumXQcclYyA==]
X-AnalysisOut: [:117 a=glloKNylpeYNumXQcclYyA==:17 a=9iaqTFGLkfwA:10 a=D2_]
X-AnalysisOut: [GN2MmYMYA:10 a=AxOM2Z2vSZ8A:10 a=BLceEmwcHowA:10 a=MqDINYq]
X-AnalysisOut: [SAAAA:8 a=pGLkceISAAAA:8 a=YlVTAMxIAAAA:8 a=1XWaLZrsAAAA:8]
X-AnalysisOut: [ a=48vgC7mUAAAA:8 a=SyYMxH9GAAAA:8 a=NojvYFcnAAAA:8 a=rWPl]
X-AnalysisOut: [ndbxAAAA:8 a=9BiSVd4ctCLiA8iWL7kA:9 a=Bjt1Ku3yZevH13TT:21 ]
X-AnalysisOut: [a=Ic2-UitD8F1lZw_w:21 a=QEXdDO2ut3YA:10 a=wUAfXdCGL-oA:10 ]
X-AnalysisOut: [a=G1HyQLfxkfkA:10 a=19wCD08tTksA:10 a=vsVyj9psLt0A:10 a=xE]
X-AnalysisOut: [eETXzOXN8A:10 a=yRLhjdVT-pYA:10 a=uztyEWA5df8A:10 a=qVizmW]
X-AnalysisOut: [-ZYBIA:10 a=p-HxVa_ds0YA:10 a=AeFSex2-gKoA:10 a=QxAq9r8ObN]
X-AnalysisOut: [gA:10 a=ULth79YsAAUA:10 a=lZB815dzVvQA:10 a=MSl-tDqOz04A:1]
X-AnalysisOut: [0 a=xLpt9-x9cSEA:10 a=626ZrK9bvACbFQp6nAoA:9 a=YrXjJPw_62g]
X-AnalysisOut: [SbfKF:21 a=-gtAHO40v2rEyuMx:21 a=4bKHBrH_YvKMtNP-:21 a=tXs]
X-AnalysisOut: [nliwV7b4A:10]
X-Spam: [F=0.5000000000; CM=0.500; MH=0.500(2014052812); S=0.200(2014051901)]
X-MAIL-FROM: <jsimon@linear.com>
X-SOURCE-IP: [12.218.215.72]
Archived-At: http://mailarchive.ietf.org/arch/msg/6tisch-security/YWbG1eCoGVIeBIQqY7MM7ILFPrs
Cc: Michael Richardson <mcr+ietf@sandelman.ca>, Rene Struik <rstruik.ext@gmail.com>, 6tisch-security@ietf.org
Subject: Re: [6tisch-security] agenda for 2014-05-27 6tisch security call
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
Reply-To: jsimon@linear.com
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 28 May 2014 14:49:32 -0000

--047d7bdca66a06732604fa76ebbb
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

Yoshihiro -

Q. In w/HART, are all beacon frames authenticated with a well-known key
even after a joining node obtained the runtime link layer key?

A. Yes. In WirelessHART the beacons (called "advertisements" but they serve
the same purpose and have similar content) are intended for devices not yet
in the network, so they always use the well-known key.  To discover other
nodes within the network, they use frames secured with the runtime
link-layer key.

Jonathan


On Tue, May 27, 2014 at 11:18 PM, <yoshihiro.ohba@toshiba.co.jp> wrote:

>  Hi Jonathan,
>
>
>
> Thank you for sending the summary of w/HART joining.
>
>
>
> I have question.
>
>
>
> In w/HART, are all beacon frames authenticated with a well-known key even
> after a joining node obtained the runtime link layer key?
>
>
>
> Regards,
>
> Yoshihiro Ohba
>
>
>
>
>
>
>
>
>
> *From:* 6tisch-security [mailto:6tisch-security-bounces@ietf.org] *On
> Behalf Of *Jonathan Simon
> *Sent:* Tuesday, May 27, 2014 10:41 PM
> *To:* Rene Struik
> *Cc:* Michael Richardson; 6tisch-security@ietf.org
> *Subject:* Re: [6tisch-security] agenda for 2014-05-27 6tisch security
> call
>
>
>
> Rene had asked on a previous call for someone to summarize WirelessHART
> joining - here you go.
>
> * One or more devices are sending beacons to advertise the presence of th=
e
> network. In WirelessHART, this frame is unencrypted, but authenticated wi=
th
> a well known key.  The beacon contains the current ASN, which the joining
> device uses to synchronize its clock.
>
> * Once the joining node has heard a beacon, it continues listening for
> additional beacons for a short specified timeout.
>
> * The joining node encrypts a frame containing some HART specific content=
,
> including a list of beaconing neighbors it heard in the previous steps. T=
he
> size of the payload is ~ 60 bytes.  The packet is routed by a "proxy" nod=
e
> - the joining parent. The frame is authenticated using the well-known key=
,
> and encrypted using a shared symmetric key known only by the node and the
> manager.
>
> * The manager responds with a frame containing the run-time link-layer
> key, the node's new short address (this takes the place of PAN coordinato=
r
> association), and a unicast session key and starting nonce for the manage=
r.
> This frame is encrypted with the symmetric key. The payload is ~ 60 bytes=
,
> and is routed to the proxy for delivery to the joining node - the proxy
> uses the link-layer well known key on the frame.
>
> * At this point the joining node transitions to using the run-time
> link-layer key for all link-layer frames, and the manager unicast session
> for end-to-end manager traffic. This ends the initial security handshake.
>
> * Over a number of additional frames, the manager assigns additional
> sessions, including broadcast sessions, and a unicast session to the
> Gateway (sink for all data traffic), and additional communications
> resources, routing information, etc.  There is no explicit transition fro=
m
> joining to joined - the mote transitions when certain key frames are
> received.
>
> * Note that a WirelessHART link-layer frame contains and additional frame
> type byte and a 4-byte link-layer MIC, on top of the unsecured 15.4 frame=
.
> A network frame contains an additional 16-40 bytes of addressing, routing=
,
> security and other information.
>
> Hope this help!
>
> Jonathan
>
>
>
>
>
> On Mon, May 26, 2014 at 8:09 PM, Rene Struik <rstruik.ext@gmail.com>
> wrote:
>
>  Hi Michael:
>
> I would like to discuss the outstanding issues I summarized in my email o=
f
> Tue last week, May 20, 2014, 9:45am EDT (see
> http://www.ietf.org/mail-archive/web/6tisch-security/current/msg00086.htm=
l<http://cp.mcafee.com/d/5fHCMUp41ESyNt55OWtSjtPqbwVBcSyUepvdEK3zhOyCOqejrz=
PPPz5XCN6ABqM1hYEvIundDOx-NVsTJQXIfcLZvC4TQTS6eLsKCO-PPXX3XUVzBHFShjlKepVkf=
fGhBrwqrhdI6XYyMCY-ehojd79KVI05bVKY01MjbX6NehDY05zAVkIjbQ-PspjbppKcvxf5q4rT=
KYVMedKjBiNcLjXdNBcIn8lrxrW0GnPtU02rhhuhKr1vF6y0QJKjBiNcLjXdNBcIqnjh1F7U8qq=
87qNd42tQm2ZTOWoUQgejBiNcQgk-Pspjb6y2SDDCT63pO_o>).
> This was also one of the action items at the conclusion of last week's
> 6TiSCH security call.
>
> FYI - the w/HART communication flows were discussed during the 6TiSCH
> security conf call the week before, on Mon May 12, 2014. If one wishes to
> go over this again, that is fine, but I would prefer us giving preference
> to taking on already articulated issues (which were assigned as homework
> assignment to reflect upon) first (i.e., prior to item #4 of the proposed
> agenda).
>
> As another agenda point, I would like us to discuss the frequency of
> future calls (as part of EOB).
>
> Best regards, Rene
>
>
> On 5/26/2014 10:49 PM, Michael Richardson wrote:
>
> To remind, we moved the call from the 26th to the 27th at 10am EDT.
>
> That's 90 minutes from this email.
>
>
>
> 1) notewell.
>
> 2) intros
>
> 3) recap of draft-piro-
>
> 4) wirelesshart -way --- how does the communication work?
>
> 5) how to summarize all of this to the working group
>
> 6) how to close this process up?
>
>
>
> -- remember that the call is recorded, and the NoteWell applies.
>
>
>
> -- The URL to access the webex, which will we use for audio only:
>
>   https://cisco.webex.com/cisco/j.php?MTID=3Dm2fe139bf876cea3ec62750cd580=
b7908 <http://cp.mcafee.com/d/5fHCN0SyNt55OWtSjtPqbwVBcSyUepvdEK3zhOyCOqejr=
zPPPz5XCN6ABqM1hYEvIundDOx-NVsTJQXIfcLZvC4TQTS6eLsKCO-PPXX3XUVzBHFShjlKepVk=
ffGhBrwqrjdI6XYyMCY-ehojd79KVIDeqR4IOQGmHM0L3-nOQGmHwzMh93o93gUVldTQmjhOgtu=
7em_mvIUCevLp1ZWV0sqerL6T9OFoCnFZCUOCmbAaJMJZ0lbVKY01dEEL8TdwLQzh0qmT9OFoCn=
FZCUOCmdbFEwQzY4dd43JoCy1eWb1uXVtcsq879OFoCq8avpKcFBzh1rjPPrz1LmTw7w17>
>
>
>
> -- we will resume with the etherpad at:
>
>    http://etherpad.tools.ietf.org:9000/p/notes-ietf-89-6tisch-security <h=
ttp://cp.mcafee.com/d/2DRPow71NJ5yWabBQXICXCQn1PapJ5MsO-rhs76zB5dAQsCT7DDD6=
bTdyd9aRw2zVg_oYKrfB3ZzOVLrFToupvW_c9LFLIctuVtdBZDDTS7TNP7bnjIyCHssPOEuvkza=
T0QSOrodTV5xdVYsyMCqejtPo0fVA_yJG7jHk-Di-rL00kzhPuZYmO5p_gLbVKBTzhOnsDaBypu=
DSrzapoSVelb4OZfIT6kONsxlK5LE2FvdTw09J55V6VI5-Aq83iSVelb4OZfIT6kONFtd46Avwx=
FEwtH4Qg9ThobTvbFzzh0Velb4Ph1jXdNBcIq8bquursodJiZvpmK6GwY>
>
>
>
> I'm at +1 613 276-6809, IM: mcr@xmpp.credil.org or mcharlesr@gmail.com,
>
> if you need more than that to get in, or are having difficulties.
>
> Please make sure your audio works, and that you mute when not talking.
>
>
>
> --
>
> Michael Richardson <mcr+IETF@sandelman.ca> <mcr+IETF@sandelman.ca>, Sande=
lman Software Works
>
>  -=3D IPv6 IoT consulting =3D-
>
>
>
>
>
>
>
>
>
> _______________________________________________
>
> 6tisch-security mailing list
>
> 6tisch-security@ietf.org
>
> https://www.ietf.org/mailman/listinfo/6tisch-security <http://cp.mcafee.c=
om/d/2DRPoO86QmbEEKnjKOrKrhs7cFCQn1PbVJ5MsqekkSjhOrsuuusoLsS8QAHm0afB3ZzOVI=
-kfSfbCZKDtxVB_HYMC-C-MNRXBQSnSuvvovv7csJteOaqJNPfaxVZicHs3jr1JwTvAm4TDNOb2=
pEVdTdAVPmEBC5eBYTu00U9GX33VkDa3JssDaBypuDSrzapoSVelb4OZfIT6kONsxlK5LE2FvdT=
w09J55V6VI5-Aq83iSVelb4OZfIT6kONFtd46AvwxFEwtH4Qg9ThobTvbFzzh0Velb4Ph1jXdNB=
cIq8bquursodLWbv>
>
>
>
>
>  --
>
> email: rstruik.ext@gmail.com | Skype: rstruik
>
> cell: +1 (647) 867-5658 | US: +1 (415) 690-7363
>
>
> _______________________________________________
> 6tisch-security mailing list
> 6tisch-security@ietf.org
>
> http://cp.mcafee.com/d/avndzgQ93gArhoKyyVteX9KVJ5MsOCrhs7cLCQn1NEVhjpd79J=
NVVVNyZPoziiJo0E-kfSfbCPVg_oYKrSWtS7Cn-LP2rWrX37nKnjpvpVZZxZYsNORQX8FGT7cYG=
7DR8OJMddECQjt-hojuv78I9CzATsSjDdqymokWnPtU03wCHIcfBisEeRNOsGm9BWvpKcFBzrAV=
kIjbQ-Pspjb5O5mUm-waBYTu00CQknArCMnWhEwdbrAVkIjbQ-Pspjb6BQQgqh-26Cy1SIjh0Dt=
5wLtYKCed43AVkIjd45fIT6kONEwJFVVJNwSeVhsrLe-Fkd
>
>
>
>
> --
>
> --
> Jonathan Simon, Ph. D
> Director of Systems Engineering
> Dust Networks at Linear Technology
> 30695 Huntwood Ave
> Hayward, CA 94544-7021
> (510) 400-2936
> (510) 489-3799 FAX
> jsimon@linear.com
>
> **LINEAR TECHNOLOGY CORPORATION**
> *****Internet Email Confidentiality Notice*****
>  This e-mail transmission, and any documents, files or previous
> e-mail messages attached to it may contain confidential information that
> is legally privileged. If you are not the intended recipient, or a
> person responsible for delivering it to the intended recipient, you are
> hereby notified that any disclosure, copying, distribution or use of any =
of
> the information contained in or attached to this transmission is
> STRICTLY PROHIBITED. If you have received this transmission in error,
> please immediately notify me by reply e-mail, or by telephone at (510)
> 400-2936, and destroy the original transmission and its
> attachments without reading or saving in any manner. Thank you.
>
> _______________________________________________
> 6tisch-security mailing list
> 6tisch-security@ietf.org
>
> http://cp.mcafee.com/d/2DRPow76QmbEFLzzhOM-rKrhs7cFCQn1PbVJ5MsqekkSjhOrsu=
uusoLsS8QAHm0afB3ZzOVI-kfSfbCTA7hPXPb_nVNZNBVxzHTbEzHIYYepd7bz8XBHEShhlKM_O=
EuvkzaT0QSyrhdTV5xdVYsyMCqejtPpesRG9pxjFvdTw0e2qKMM-l9OwXn79OFoCnFZCUOCmdKj=
BiNcLjXdNBcIn8lrxrW0GnPtU02rojhKUr1vF6y0QJKjBiNcLjXdNBcIqnjh1F7U8qq87qNd42t=
Qm2ZTOWoUQgejBiNcQgk-Pspjb6y2SDDCT63rt_U2SVUlVB0
>
>


--=20
--=20
Jonathan Simon, Ph. D
Director of Systems Engineering
Dust Networks at Linear Technology
30695 Huntwood Ave
Hayward, CA 94544-7021
(510) 400-2936
(510) 489-3799 FAX
jsimon@linear.com

**LINEAR TECHNOLOGY CORPORATION**
*****Internet Email Confidentiality Notice*****
 This e-mail transmission, and any documents, files or previous
e-mail messages attached to it may contain confidential information that
is legally privileged. If you are not the intended recipient, or a
person responsible for delivering it to the intended recipient, you are
hereby notified that any disclosure, copying, distribution or use of any of
the information contained in or attached to this transmission is
STRICTLY PROHIBITED. If you have received this transmission in error,
please immediately notify me by reply e-mail, or by telephone at (510)
400-2936, and destroy the original transmission and its attachments without
reading or saving in any manner. Thank you.

--047d7bdca66a06732604fa76ebbb
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><div>Yoshihiro - <br><br>Q. <span style=3D"font-size:10pt;=
font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:rgb(31,73,125)" =
lang=3D"EN-US">In
 w/HART, are all beacon frames authenticated with a well-known key even=20
after a joining node obtained the runtime link layer key? <br><br></span></=
div><div><span style=3D"font-size:10pt;font-family:&quot;Arial&quot;,&quot;=
sans-serif&quot;;color:rgb(31,73,125)" lang=3D"EN-US">A. Yes. In WirelessHA=
RT the beacons (called &quot;advertisements&quot; but they serve the same p=
urpose and have similar content) are intended for devices not yet in the ne=
twork, so they always use the well-known key.=C2=A0 To discover other nodes=
 within the network, they use frames secured with the runtime link-layer ke=
y.<br>
<br></span></div><div><span style=3D"font-size:10pt;font-family:&quot;Arial=
&quot;,&quot;sans-serif&quot;;color:rgb(31,73,125)" lang=3D"EN-US">Jonathan=
<br>
</span></div><span style=3D"font-size:10pt;font-family:&quot;Arial&quot;,&q=
uot;sans-serif&quot;;color:rgb(31,73,125)" lang=3D"EN-US"></span></div><div=
 class=3D"gmail_extra"><br><br><div class=3D"gmail_quote">On Tue, May 27, 2=
014 at 11:18 PM,  <span dir=3D"ltr">&lt;<a href=3D"mailto:yoshihiro.ohba@to=
shiba.co.jp" target=3D"_blank">yoshihiro.ohba@toshiba.co.jp</a>&gt;</span> =
wrote:<br>
<blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;border-left:1p=
x #ccc solid;padding-left:1ex">





<div link=3D"blue" vlink=3D"purple" lang=3D"JA">
<div>
<p class=3D"MsoNormal"><span style=3D"font-size:10.0pt;font-family:&quot;Ar=
ial&quot;,&quot;sans-serif&quot;;color:#1f497d" lang=3D"EN-US">Hi Jonathan,=
<u></u><u></u></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:10.0pt;font-family:&quot;Ar=
ial&quot;,&quot;sans-serif&quot;;color:#1f497d" lang=3D"EN-US"><u></u>=C2=
=A0<u></u></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:10.0pt;font-family:&quot;Ar=
ial&quot;,&quot;sans-serif&quot;;color:#1f497d" lang=3D"EN-US">Thank you fo=
r sending the summary of w/HART joining.
<u></u><u></u></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:10.0pt;font-family:&quot;Ar=
ial&quot;,&quot;sans-serif&quot;;color:#1f497d" lang=3D"EN-US"><u></u>=C2=
=A0<u></u></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:10.0pt;font-family:&quot;Ar=
ial&quot;,&quot;sans-serif&quot;;color:#1f497d" lang=3D"EN-US">I have quest=
ion.<u></u><u></u></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:10.0pt;font-family:&quot;Ar=
ial&quot;,&quot;sans-serif&quot;;color:#1f497d" lang=3D"EN-US"><u></u>=C2=
=A0<u></u></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:10.0pt;font-family:&quot;Ar=
ial&quot;,&quot;sans-serif&quot;;color:#1f497d" lang=3D"EN-US">In w/HART, a=
re all beacon frames authenticated with a well-known key even after a joini=
ng node obtained the runtime link layer key?=C2=A0
<u></u><u></u></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:10.0pt;font-family:&quot;Ar=
ial&quot;,&quot;sans-serif&quot;;color:#1f497d" lang=3D"EN-US"><u></u>=C2=
=A0<u></u></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:10.0pt;font-family:&quot;Ar=
ial&quot;,&quot;sans-serif&quot;;color:#1f497d" lang=3D"EN-US">Regards,<u><=
/u><u></u></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:10.0pt;font-family:&quot;Ar=
ial&quot;,&quot;sans-serif&quot;;color:#1f497d" lang=3D"EN-US">Yoshihiro Oh=
ba<u></u><u></u></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:10.0pt;font-family:&quot;Ar=
ial&quot;,&quot;sans-serif&quot;;color:#1f497d" lang=3D"EN-US"><u></u>=C2=
=A0<u></u></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:10.0pt;font-family:&quot;Ar=
ial&quot;,&quot;sans-serif&quot;;color:#1f497d" lang=3D"EN-US"><u></u>=C2=
=A0<u></u></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:10.0pt;font-family:&quot;Ar=
ial&quot;,&quot;sans-serif&quot;;color:#1f497d" lang=3D"EN-US"><u></u>=C2=
=A0<u></u></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:10.0pt;font-family:&quot;Ar=
ial&quot;,&quot;sans-serif&quot;;color:#1f497d" lang=3D"EN-US"><u></u>=C2=
=A0<u></u></span></p>
<p class=3D"MsoNormal"><b><span style=3D"font-size:11.0pt;font-family:&quot=
;Calibri&quot;,&quot;sans-serif&quot;" lang=3D"EN-US">From:</span></b><span=
 style=3D"font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif=
&quot;" lang=3D"EN-US"> 6tisch-security [mailto:<a href=3D"mailto:6tisch-se=
curity-bounces@ietf.org" target=3D"_blank">6tisch-security-bounces@ietf.org=
</a>]
<b>On Behalf Of </b>Jonathan Simon<br>
<b>Sent:</b> Tuesday, May 27, 2014 10:41 PM<br>
<b>To:</b> Rene Struik<br>
<b>Cc:</b> Michael Richardson; <a href=3D"mailto:6tisch-security@ietf.org" =
target=3D"_blank">6tisch-security@ietf.org</a><br>
<b>Subject:</b> Re: [6tisch-security] agenda for 2014-05-27 6tisch security=
 call<u></u><u></u></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US"><u></u>=C2=A0<u></u></span></p>
<div>
<div>
<div>
<p class=3D"MsoNormal" style=3D"margin-bottom:12.0pt"><span lang=3D"EN-US">=
Rene had asked on a previous call for someone to summarize WirelessHART joi=
ning - here you go.<br>
<br>
* One or more devices are sending beacons to advertise the presence of the =
network. In WirelessHART, this frame is unencrypted, but authenticated with=
 a well known key.=C2=A0 The beacon contains the current ASN, which the joi=
ning device uses to synchronize its clock.<u></u><u></u></span></p>

<div>
<p class=3D"MsoNormal" style=3D"margin-bottom:12.0pt"><span lang=3D"EN-US">=
* Once the joining node has heard a beacon, it continues listening for addi=
tional beacons for a short specified timeout.<u></u><u></u></span></p>
</div>
<p class=3D"MsoNormal" style=3D"margin-bottom:12.0pt"><span lang=3D"EN-US">=
* The joining node encrypts a frame containing some HART specific content, =
including a list of beaconing neighbors it heard in the previous steps. The=
 size of the payload is ~ 60 bytes.=C2=A0 The
 packet is routed by a &quot;proxy&quot; node - the joining parent. The fra=
me is authenticated using the well-known key, and encrypted using a shared =
symmetric key known only by the node and the manager.<br>
<br>
* The manager responds with a frame containing the run-time link-layer key,=
 the node&#39;s new short address (this takes the place of PAN coordinator =
association), and a unicast session key and starting nonce for the manager.=
 This frame is encrypted with the symmetric
 key. The payload is ~ 60 bytes, and is routed to the proxy for delivery to=
 the joining node - the proxy uses the link-layer well known key on the fra=
me.<u></u><u></u></span></p>
<div>
<p class=3D"MsoNormal" style=3D"margin-bottom:12.0pt"><span lang=3D"EN-US">=
* At this point the joining node transitions to using the run-time link-lay=
er key for all link-layer frames, and the manager unicast session for end-t=
o-end manager traffic. This ends the initial
 security handshake.<u></u><u></u></span></p>
</div>
<div>
<p class=3D"MsoNormal" style=3D"margin-bottom:12.0pt"><span lang=3D"EN-US">=
* Over a number of additional frames, the manager assigns additional sessio=
ns, including broadcast sessions, and a unicast session to the Gateway (sin=
k for all data traffic), and additional
 communications resources, routing information, etc.=C2=A0 There is no expl=
icit transition from joining to joined - the mote transitions when certain =
key frames are received.<u></u><u></u></span></p>
</div>
<p class=3D"MsoNormal" style=3D"margin-bottom:12.0pt"><span lang=3D"EN-US">=
* Note that a WirelessHART link-layer frame contains and additional frame t=
ype byte and a 4-byte link-layer MIC, on top of the unsecured 15.4 frame.=
=C2=A0 A network frame contains an additional
 16-40 bytes of addressing, routing, security and other information.<u></u>=
<u></u></span></p>
</div>
<p class=3D"MsoNormal" style=3D"margin-bottom:12.0pt"><span lang=3D"EN-US">=
Hope this help!<u></u><u></u></span></p>
</div>
<p class=3D"MsoNormal"><span lang=3D"EN-US">Jonathan<u></u><u></u></span></=
p>
<div>
<div>
<div>
<p class=3D"MsoNormal"><span lang=3D"EN-US"><u></u>=C2=A0<u></u></span></p>
</div>
</div>
</div>
</div>
<div>
<p class=3D"MsoNormal" style=3D"margin-bottom:12.0pt"><span lang=3D"EN-US">=
<u></u>=C2=A0<u></u></span></p>
<div>
<p class=3D"MsoNormal"><span lang=3D"EN-US">On Mon, May 26, 2014 at 8:09 PM=
, Rene Struik &lt;<a href=3D"mailto:rstruik.ext@gmail.com" target=3D"_blank=
">rstruik.ext@gmail.com</a>&gt; wrote:<u></u><u></u></span></p>
<blockquote style=3D"border:none;border-left:solid #cccccc 1.0pt;padding:0m=
m 0mm 0mm 6.0pt;margin-left:4.8pt;margin-right:0mm">
<div>
<div>
<p class=3D"MsoNormal"><span lang=3D"EN-US">Hi Michael:<br>
<br>
I would like to discuss the outstanding issues I summarized in my email of =
Tue last week, May 20, 2014, 9:45am EDT (see
<a href=3D"http://cp.mcafee.com/d/5fHCMUp41ESyNt55OWtSjtPqbwVBcSyUepvdEK3zh=
OyCOqejrzPPPz5XCN6ABqM1hYEvIundDOx-NVsTJQXIfcLZvC4TQTS6eLsKCO-PPXX3XUVzBHFS=
hjlKepVkffGhBrwqrhdI6XYyMCY-ehojd79KVI05bVKY01MjbX6NehDY05zAVkIjbQ-PspjbppK=
cvxf5q4rTKYVMedKjBiNcLjXdNBcIn8lrxrW0GnPtU02rhhuhKr1vF6y0QJKjBiNcLjXdNBcIqn=
jh1F7U8qq87qNd42tQm2ZTOWoUQgejBiNcQgk-Pspjb6y2SDDCT63pO_o" target=3D"_blank=
">
http://www.ietf.org/mail-archive/web/6tisch-security/current/msg00086.html<=
/a>). This was also one of the action items at the conclusion of last week&=
#39;s 6TiSCH security call.<br>
<br>
FYI - the w/HART communication flows were discussed during the 6TiSCH secur=
ity conf call the week before, on Mon May 12, 2014. If one wishes to go ove=
r this again, that is fine, but I would prefer us giving preference to taki=
ng on already articulated issues
 (which were assigned as homework assignment to reflect upon) first (i.e., =
prior to item #4 of the proposed agenda).<br>
<br>
As another agenda point, I would like us to discuss the frequency of future=
 calls (as part of EOB).<br>
<br>
Best regards, Rene<br>
<br>
<br>
On 5/26/2014 10:49 PM, Michael Richardson wrote:<u></u><u></u></span></p>
</div>
<blockquote style=3D"margin-top:5.0pt;margin-bottom:5.0pt">
<pre><span lang=3D"EN-US">To remind, we moved the call from the 26th to the=
 27th at 10am EDT.<u></u><u></u></span></pre>
<pre><span lang=3D"EN-US">That&#39;s 90 minutes from this email.<u></u><u><=
/u></span></pre>
<pre><span lang=3D"EN-US"><u></u>=C2=A0<u></u></span></pre>
<pre><span lang=3D"EN-US">1) notewell.<u></u><u></u></span></pre>
<pre><span lang=3D"EN-US">2) intros<u></u><u></u></span></pre>
<pre><span lang=3D"EN-US">3) recap of draft-piro-<u></u><u></u></span></pre=
>
<pre><span lang=3D"EN-US">4) wirelesshart -way --- how does the communicati=
on work?<u></u><u></u></span></pre>
<pre><span lang=3D"EN-US">5) how to summarize all of this to the working gr=
oup<u></u><u></u></span></pre>
<pre><span lang=3D"EN-US">6) how to close this process up?<u></u><u></u></s=
pan></pre>
<pre><span lang=3D"EN-US"><u></u>=C2=A0<u></u></span></pre>
<pre><span lang=3D"EN-US">-- remember that the call is recorded, and the No=
teWell applies.<u></u><u></u></span></pre>
<pre><span lang=3D"EN-US"><u></u>=C2=A0<u></u></span></pre>
<pre><span lang=3D"EN-US">-- The URL to access the webex, which will we use=
 for audio only:<u></u><u></u></span></pre>
<pre><span lang=3D"EN-US">=C2=A0 <a href=3D"http://cp.mcafee.com/d/5fHCN0Sy=
Nt55OWtSjtPqbwVBcSyUepvdEK3zhOyCOqejrzPPPz5XCN6ABqM1hYEvIundDOx-NVsTJQXIfcL=
ZvC4TQTS6eLsKCO-PPXX3XUVzBHFShjlKepVkffGhBrwqrjdI6XYyMCY-ehojd79KVIDeqR4IOQ=
GmHM0L3-nOQGmHwzMh93o93gUVldTQmjhOgtu7em_mvIUCevLp1ZWV0sqerL6T9OFoCnFZCUOCm=
bAaJMJZ0lbVKY01dEEL8TdwLQzh0qmT9OFoCnFZCUOCmdbFEwQzY4dd43JoCy1eWb1uXVtcsq87=
9OFoCq8avpKcFBzh1rjPPrz1LmTw7w17" target=3D"_blank">https://cisco.webex.com=
/cisco/j.php?MTID=3Dm2fe139bf876cea3ec62750cd580b7908</a><u></u><u></u></sp=
an></pre>

<pre><span lang=3D"EN-US"><u></u>=C2=A0<u></u></span></pre>
<pre><span lang=3D"EN-US">-- we will resume with the etherpad at:<u></u><u>=
</u></span></pre>
<pre><span lang=3D"EN-US">=C2=A0=C2=A0 <a href=3D"http://cp.mcafee.com/d/2D=
RPow71NJ5yWabBQXICXCQn1PapJ5MsO-rhs76zB5dAQsCT7DDD6bTdyd9aRw2zVg_oYKrfB3ZzO=
VLrFToupvW_c9LFLIctuVtdBZDDTS7TNP7bnjIyCHssPOEuvkzaT0QSOrodTV5xdVYsyMCqejtP=
o0fVA_yJG7jHk-Di-rL00kzhPuZYmO5p_gLbVKBTzhOnsDaBypuDSrzapoSVelb4OZfIT6kONsx=
lK5LE2FvdTw09J55V6VI5-Aq83iSVelb4OZfIT6kONFtd46AvwxFEwtH4Qg9ThobTvbFzzh0Vel=
b4Ph1jXdNBcIq8bquursodJiZvpmK6GwY" target=3D"_blank">http://etherpad.tools.=
ietf.org:9000/p/notes-ietf-89-6tisch-security</a><u></u><u></u></span></pre=
>

<pre><span lang=3D"EN-US"><u></u>=C2=A0<u></u></span></pre>
<pre><span lang=3D"EN-US">I&#39;m at <a href=3D"tel:%2B1%20613%20276-6809" =
target=3D"_blank">+1 613 276-6809</a>, IM: <a href=3D"mailto:mcr@xmpp.credi=
l.org" target=3D"_blank">mcr@xmpp.credil.org</a> or <a href=3D"mailto:mchar=
lesr@gmail.com" target=3D"_blank">mcharlesr@gmail.com</a>,<u></u><u></u></s=
pan></pre>

<pre><span lang=3D"EN-US">if you need more than that to get in, or are havi=
ng difficulties.<u></u><u></u></span></pre>
<pre><span lang=3D"EN-US">Please make sure your audio works, and that you m=
ute when not talking.<u></u><u></u></span></pre>
<pre><span lang=3D"EN-US"><u></u>=C2=A0<u></u></span></pre>
<pre><span lang=3D"EN-US">--<u></u><u></u></span></pre>
<pre><span lang=3D"EN-US">Michael Richardson <a href=3D"mailto:mcr+IETF@san=
delman.ca" target=3D"_blank">&lt;mcr+IETF@sandelman.ca&gt;</a>, Sandelman S=
oftware Works<u></u><u></u></span></pre>
<pre><span lang=3D"EN-US"> -=3D IPv6 IoT consulting =3D-<u></u><u></u></spa=
n></pre>
<pre><span lang=3D"EN-US"><u></u>=C2=A0<u></u></span></pre>
<pre><span lang=3D"EN-US"><u></u>=C2=A0<u></u></span></pre>
<pre><span lang=3D"EN-US"><u></u>=C2=A0<u></u></span></pre>
<p class=3D"MsoNormal" style=3D"margin-bottom:12.0pt"><span><span style=3D"=
color:#888888" lang=3D"EN-US"><u></u>=C2=A0<u></u></span></span></p>
<pre><span style=3D"color:#888888" lang=3D"EN-US">_________________________=
______________________<u></u><u></u></span></pre>
<pre><span style=3D"color:#888888" lang=3D"EN-US">6tisch-security mailing l=
ist<u></u><u></u></span></pre>
<pre><span style=3D"color:#888888" lang=3D"EN-US"><a href=3D"mailto:6tisch-=
security@ietf.org" target=3D"_blank">6tisch-security@ietf.org</a><u></u><u>=
</u></span></pre>
<pre><span style=3D"color:#888888" lang=3D"EN-US"><a href=3D"http://cp.mcaf=
ee.com/d/2DRPoO86QmbEEKnjKOrKrhs7cFCQn1PbVJ5MsqekkSjhOrsuuusoLsS8QAHm0afB3Z=
zOVI-kfSfbCZKDtxVB_HYMC-C-MNRXBQSnSuvvovv7csJteOaqJNPfaxVZicHs3jr1JwTvAm4TD=
NOb2pEVdTdAVPmEBC5eBYTu00U9GX33VkDa3JssDaBypuDSrzapoSVelb4OZfIT6kONsxlK5LE2=
FvdTw09J55V6VI5-Aq83iSVelb4OZfIT6kONFtd46AvwxFEwtH4Qg9ThobTvbFzzh0Velb4Ph1j=
XdNBcIq8bquursodLWbv" target=3D"_blank">https://www.ietf.org/mailman/listin=
fo/6tisch-security</a><u></u><u></u></span></pre>

</blockquote>
<p class=3D"MsoNormal"><span style=3D"color:#888888" lang=3D"EN-US"><br>
<br>
<br>
<span><u></u><u></u></span></span></p>
<pre><span style=3D"color:#888888" lang=3D"EN-US">-- <u></u><u></u></span><=
/pre>
<pre><span style=3D"color:#888888" lang=3D"EN-US">email: <a href=3D"mailto:=
rstruik.ext@gmail.com" target=3D"_blank">rstruik.ext@gmail.com</a> | Skype:=
 rstruik<u></u><u></u></span></pre>
<pre><span style=3D"color:#888888" lang=3D"EN-US">cell: <a href=3D"tel:%2B1=
%20%28647%29%20867-5658" target=3D"_blank">+1 (647) 867-5658</a> | US: <a h=
ref=3D"tel:%2B1%20%28415%29%20690-7363" target=3D"_blank">+1 (415) 690-7363=
</a></span><span lang=3D"EN-US"><u></u><u></u></span></pre>

</div>
<p class=3D"MsoNormal" style=3D"margin-bottom:12.0pt"><span lang=3D"EN-US">=
<br>
_______________________________________________<br>
6tisch-security mailing list<br>
<a href=3D"mailto:6tisch-security@ietf.org" target=3D"_blank">6tisch-securi=
ty@ietf.org</a><br>
<a href=3D"http://cp.mcafee.com/d/avndzgQ93gArhoKyyVteX9KVJ5MsOCrhs7cLCQn1N=
EVhjpd79JNVVVNyZPoziiJo0E-kfSfbCPVg_oYKrSWtS7Cn-LP2rWrX37nKnjpvpVZZxZYsNORQ=
X8FGT7cYG7DR8OJMddECQjt-hojuv78I9CzATsSjDdqymokWnPtU03wCHIcfBisEeRNOsGm9BWv=
pKcFBzrAVkIjbQ-Pspjb5O5mUm-waBYTu00CQknArCMnWhEwdbrAVkIjbQ-Pspjb6BQQgqh-26C=
y1SIjh0Dt5wLtYKCed43AVkIjd45fIT6kONEwJFVVJNwSeVhsrLe-Fkd" target=3D"_blank"=
>http://cp.mcafee.com/d/avndzgQ93gArhoKyyVteX9KVJ5MsOCrhs7cLCQn1NEVhjpd79JN=
VVVNyZPoziiJo0E-kfSfbCPVg_oYKrSWtS7Cn-LP2rWrX37nKnjpvpVZZxZYsNORQX8FGT7cYG7=
DR8OJMddECQjt-hojuv78I9CzATsSjDdqymokWnPtU03wCHIcfBisEeRNOsGm9BWvpKcFBzrAVk=
IjbQ-Pspjb5O5mUm-waBYTu00CQknArCMnWhEwdbrAVkIjbQ-Pspjb6BQQgqh-26Cy1SIjh0Dt5=
wLtYKCed43AVkIjd45fIT6kONEwJFVVJNwSeVhsrLe-Fkd</a><u></u><u></u></span></p>

</blockquote>
</div>
<p class=3D"MsoNormal"><span lang=3D"EN-US"><br>
<br clear=3D"all">
<br>
-- <u></u><u></u></span></p>
<div>
<p class=3D"MsoNormal"><span style=3D"font-size:13.5pt;font-family:&quot;Ti=
mes New Roman&quot;,&quot;serif&quot;" lang=3D"EN-US">--=C2=A0<br>
Jonathan Simon, Ph. D<br>
Director of Systems Engineering<br>
Dust Networks at Linear Technology<br>
30695 Huntwood Ave<br>
Hayward, CA 94544-7021<br>
<a href=3D"tel:%28510%29%20400-2936" value=3D"+15104002936" target=3D"_blan=
k">(510) 400-2936</a><br>
<a href=3D"tel:%28510%29%20489-3799" value=3D"+15104893799" target=3D"_blan=
k">(510) 489-3799</a> FAX<br>
<a href=3D"mailto:jsimon@linear.com" target=3D"_blank">jsimon@linear.com</a=
></span><span lang=3D"EN-US"><br>
<br>
</span><span style=3D"font-size:13.5pt;font-family:&quot;Times New Roman&qu=
ot;,&quot;serif&quot;" lang=3D"EN-US">**LINEAR TECHNOLOGY=C2=A0CORPORATION*=
*=C2=A0<br>
*****Internet Email Confidentiality=C2=A0Notice*****=C2=A0<br>
=C2=A0This e-mail transmission, and any=C2=A0documents, files or previous e=
-mail=C2=A0messages attached to it may contain=C2=A0confidential informatio=
n that is=C2=A0legally privileged. If you are not the=C2=A0intended recipie=
nt, or a person=C2=A0responsible for delivering it to the=C2=A0intended
 recipient, you are hereby=C2=A0notified that any disclosure, copying,=C2=
=A0distribution or use of any of the=C2=A0information contained in or attac=
hed=C2=A0to this transmission is STRICTLY=C2=A0PROHIBITED. If you have rece=
ived this=C2=A0transmission in error, please=C2=A0immediately notify
 me by reply e-mail, or by telephone at <a href=3D"tel:%28510%29%20400-2936=
" value=3D"+15104002936" target=3D"_blank">(510) 400-2936</a>, and destroy =
the original=C2=A0transmission and its attachments=C2=A0without reading or =
saving in any=C2=A0manner. Thank you.
</span><span lang=3D"EN-US"><u></u><u></u></span></p>
</div>
</div>
</div>
</div>

<br>_______________________________________________<br>
6tisch-security mailing list<br>
<a href=3D"mailto:6tisch-security@ietf.org">6tisch-security@ietf.org</a><br=
>
<a href=3D"http://cp.mcafee.com/d/2DRPow76QmbEFLzzhOM-rKrhs7cFCQn1PbVJ5Msqe=
kkSjhOrsuuusoLsS8QAHm0afB3ZzOVI-kfSfbCTA7hPXPb_nVNZNBVxzHTbEzHIYYepd7bz8XBH=
EShhlKM_OEuvkzaT0QSyrhdTV5xdVYsyMCqejtPpesRG9pxjFvdTw0e2qKMM-l9OwXn79OFoCnF=
ZCUOCmdKjBiNcLjXdNBcIn8lrxrW0GnPtU02rojhKUr1vF6y0QJKjBiNcLjXdNBcIqnjh1F7U8q=
q87qNd42tQm2ZTOWoUQgejBiNcQgk-Pspjb6y2SDDCT63rt_U2SVUlVB0" target=3D"_blank=
">http://cp.mcafee.com/d/2DRPow76QmbEFLzzhOM-rKrhs7cFCQn1PbVJ5MsqekkSjhOrsu=
uusoLsS8QAHm0afB3ZzOVI-kfSfbCTA7hPXPb_nVNZNBVxzHTbEzHIYYepd7bz8XBHEShhlKM_O=
EuvkzaT0QSyrhdTV5xdVYsyMCqejtPpesRG9pxjFvdTw0e2qKMM-l9OwXn79OFoCnFZCUOCmdKj=
BiNcLjXdNBcIn8lrxrW0GnPtU02rojhKUr1vF6y0QJKjBiNcLjXdNBcIqnjh1F7U8qq87qNd42t=
Qm2ZTOWoUQgejBiNcQgk-Pspjb6y2SDDCT63rt_U2SVUlVB0</a><br>

<br></blockquote></div><br><br clear=3D"all"><br>-- <br><div dir=3D"ltr"><s=
pan style=3D"font-size:13.5pt;font-family:&quot;Lucida Grande&quot;,&quot;s=
erif&quot;">--=C2=A0<br>
Jonathan Simon, Ph. D<br>
Director of Systems Engineering<br>
Dust Networks at Linear Technology<br>
30695 Huntwood Ave<br>
Hayward, CA 94544-7021<br>
<a>(510) 400-2936</a><br>
<a>(510) 489-3799</a> FAX<br>
<a href=3D"mailto:jsimon@linear.com" target=3D"_blank">jsimon@linear.com</a=
></span><br><br><span style=3D"font-size:13.5pt;font-family:&quot;Lucida Gr=
ande&quot;,&quot;serif&quot;">**LINEAR TECHNOLOGY=C2=A0CORPORATION**=C2=A0<=
br>
*****Internet Email Confidentiality=C2=A0Notice*****=C2=A0<br>
=C2=A0This e-mail transmission, and any=C2=A0documents, files or previous=
=20
e-mail=C2=A0messages attached to it may contain=C2=A0confidential informati=
on that
 is=C2=A0legally privileged. If you are not the=C2=A0intended recipient, or=
 a=20
person=C2=A0responsible for delivering it to the=C2=A0intended
 recipient, you are hereby=C2=A0notified that any disclosure,=20
copying,=C2=A0distribution or use of any of the=C2=A0information contained =
in or=20
attached=C2=A0to this transmission is STRICTLY=C2=A0PROHIBITED. If you have=
=20
received this=C2=A0transmission in error, please=C2=A0immediately notify
 me by reply e-mail, or by telephone at <a>
(510) 400-2936</a>, and destroy the original=C2=A0transmission and its atta=
chments=C2=A0without reading or saving in any=C2=A0manner. Thank you. </spa=
n></div>
</div>

--047d7bdca66a06732604fa76ebbb--


From nobody Wed May 28 08:03:41 2014
Return-Path: <yoshihiro.ohba@toshiba.co.jp>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id E47D41A09E6 for <6tisch-security@ietfa.amsl.com>; Wed, 28 May 2014 08:03:34 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -0.352
X-Spam-Level: 
X-Spam-Status: No, score=-0.352 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HELO_EQ_JP=1.244, HOST_EQ_JP=1.265, HTML_MESSAGE=0.001, HTTPS_HTTP_MISMATCH=1.989, RCVD_IN_DNSWL_MED=-2.3, RP_MATCHES_RCVD=-0.651, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001, UNPARSEABLE_RELAY=0.001, WEIRD_PORT=0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id U6ql32nZf_hC for <6tisch-security@ietfa.amsl.com>; Wed, 28 May 2014 08:03:29 -0700 (PDT)
Received: from imx2.toshiba.co.jp (inet-tsb5.toshiba.co.jp [202.33.96.24]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 791EF1A09EC for <6tisch-security@ietf.org>; Wed, 28 May 2014 08:02:04 -0700 (PDT)
Received: from arc1.toshiba.co.jp ([133.199.194.235]) by imx2.toshiba.co.jp  with ESMTP id s4SF1vft019197; Thu, 29 May 2014 00:01:57 +0900 (JST)
Received: (from root@localhost) by arc1.toshiba.co.jp  id s4SF1vvJ021626; Thu, 29 May 2014 00:01:57 +0900 (JST)
Received: from unknown [133.199.192.144]  by arc1.toshiba.co.jp with ESMTP id AAA21625; Thu, 29 May 2014 00:01:57 +0900
Received: from mx12.toshiba.co.jp (localhost [127.0.0.1]) by ovp2.toshiba.co.jp  with ESMTP id s4SF1vBk009391; Thu, 29 May 2014 00:01:57 +0900 (JST)
Received: from TGXML208.toshiba.local by toshiba.co.jp id s4SF1uLQ010086; Thu, 29 May 2014 00:01:56 +0900 (JST)
Received: from TGXML210.toshiba.local ([169.254.4.46]) by TGXML208.toshiba.local ([133.199.70.17]) with mapi id 14.03.0181.006; Thu, 29 May 2014 00:01:56 +0900
From: <yoshihiro.ohba@toshiba.co.jp>
To: <jsimon@linear.com>
Thread-Topic: [6tisch-security] agenda for 2014-05-27 6tisch security call
Thread-Index: AQHPeVZhw54BHDP0SE+00Qrnll9n8JtTKLqAgACwMoCAAayJwP//+QQAgACYY+A=
Date: Wed, 28 May 2014 15:01:56 +0000
Message-ID: <674F70E5F2BE564CB06B6901FD3DD78B2723B85A@TGXML210.toshiba.local>
References: <E045AECD98228444A58C61C200AE1BD8416F3AF4@xmb-rcd-x01.cisco.com> <531DD632.2060009@cox.net> <531DDB20.5050600@gmail.com> <10925.1394631496@sandelman.ca> <532069C8.2050005@gmail.com> <23590.1394999032@sandelman.ca> <18106.1395625035@sandelman.ca> <19609.1396839403@sandelman.ca> <11557.1397444260@sandelman.ca> <28192.1398644294@sandelman.ca> <29064.1399255587@sandelman.ca> <19475.1400588783@sandelman.ca> <4903.1401158997@sandelman.ca> <53840205.2070103@gmail.com> <CAJeFcoS3PNFX2obx3uNDJDtH=QvNLmaPhw2R468sNaeqpo8QBQ@mail.gmail.com> <674F70E5F2BE564CB06B6901FD3DD78B2723B576@TGXML210.toshiba.local> <CAJeFcoQBp1A7pwZHWoesvrjSySW0UZ0k11-s3-MFAozSuR0Yrw@mail.gmail.com>
In-Reply-To: <CAJeFcoQBp1A7pwZHWoesvrjSySW0UZ0k11-s3-MFAozSuR0Yrw@mail.gmail.com>
Accept-Language: ja-JP, en-US
Content-Language: ja-JP
x-originating-ip: [133.199.16.137]
msscp.transfermailtomossagent: 103
Content-Type: multipart/alternative; boundary="_000_674F70E5F2BE564CB06B6901FD3DD78B2723B85ATGXML210toshiba_"
MIME-Version: 1.0
Archived-At: http://mailarchive.ietf.org/arch/msg/6tisch-security/u6Y3Qyj23zrdPTDgNFhODLK-1kQ
Cc: mcr+ietf@sandelman.ca, rstruik.ext@gmail.com, 6tisch-security@ietf.org
Subject: Re: [6tisch-security] agenda for 2014-05-27 6tisch security call
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 28 May 2014 15:03:35 -0000

--_000_674F70E5F2BE564CB06B6901FD3DD78B2723B85ATGXML210toshiba_
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: base64

SGkgSm9uYXRoYW4sDQoNClRoYW5rIHlvdSBmb3IgeW91ciBhbnN3ZXIuDQoNCkkgdGhpbmsgdGhp
cyBjYW4gYmUgYW4gaXNzdWUgaWYgYWxyZWFkeSBqb2luZWQgbm9kZXMgYWxzbyB1c2UgdGhlIGJl
YWNvbnMgcHJvdGVjdGVkIHdpdGggdGhlIHdlbGwta25vd24ga2V5IGZvciBtYWludGFpbmluZyBz
eW5jaHJvbml6YXRpb24gYW5kIHNsb3QgYWxsb2NhdGlvbnMsIGFzIGFuIGF0dGFja2VyIGNhbiBz
ZW5kIGZvcmdlZCBiZWFjb25zIHByb3RlY3RlZCB3aXRoIHRoZSB3ZWxsLWtub3duIGtleS4NCg0K
WW9zaGloaXJvIE9oYmENCg0KDQpGcm9tOiA2dGlzY2gtc2VjdXJpdHkgW21haWx0bzo2dGlzY2gt
c2VjdXJpdHktYm91bmNlc0BpZXRmLm9yZ10gT24gQmVoYWxmIE9mIEpvbmF0aGFuIFNpbW9uDQpT
ZW50OiBXZWRuZXNkYXksIE1heSAyOCwgMjAxNCAxMTo0OSBQTQ0KVG86IG9oYmEgeW9zaGloaXJv
KOWkp+WgtCDnvqnmtIsg4peL77yy77yk77yj4pah77yu77yz77ysKQ0KQ2M6IE1pY2hhZWwgUmlj
aGFyZHNvbjsgUmVuZSBTdHJ1aWs7IDZ0aXNjaC1zZWN1cml0eUBpZXRmLm9yZw0KU3ViamVjdDog
UmU6IFs2dGlzY2gtc2VjdXJpdHldIGFnZW5kYSBmb3IgMjAxNC0wNS0yNyA2dGlzY2ggc2VjdXJp
dHkgY2FsbA0KDQpZb3NoaWhpcm8gLQ0KDQpRLiBJbiB3L0hBUlQsIGFyZSBhbGwgYmVhY29uIGZy
YW1lcyBhdXRoZW50aWNhdGVkIHdpdGggYSB3ZWxsLWtub3duIGtleSBldmVuIGFmdGVyIGEgam9p
bmluZyBub2RlIG9idGFpbmVkIHRoZSBydW50aW1lIGxpbmsgbGF5ZXIga2V5Pw0KQS4gWWVzLiBJ
biBXaXJlbGVzc0hBUlQgdGhlIGJlYWNvbnMgKGNhbGxlZCAiYWR2ZXJ0aXNlbWVudHMiIGJ1dCB0
aGV5IHNlcnZlIHRoZSBzYW1lIHB1cnBvc2UgYW5kIGhhdmUgc2ltaWxhciBjb250ZW50KSBhcmUg
aW50ZW5kZWQgZm9yIGRldmljZXMgbm90IHlldCBpbiB0aGUgbmV0d29yaywgc28gdGhleSBhbHdh
eXMgdXNlIHRoZSB3ZWxsLWtub3duIGtleS4gIFRvIGRpc2NvdmVyIG90aGVyIG5vZGVzIHdpdGhp
biB0aGUgbmV0d29yaywgdGhleSB1c2UgZnJhbWVzIHNlY3VyZWQgd2l0aCB0aGUgcnVudGltZSBs
aW5rLWxheWVyIGtleS4NCkpvbmF0aGFuDQoNCk9uIFR1ZSwgTWF5IDI3LCAyMDE0IGF0IDExOjE4
IFBNLCA8eW9zaGloaXJvLm9oYmFAdG9zaGliYS5jby5qcDxtYWlsdG86eW9zaGloaXJvLm9oYmFA
dG9zaGliYS5jby5qcD4+IHdyb3RlOg0KSGkgSm9uYXRoYW4sDQoNClRoYW5rIHlvdSBmb3Igc2Vu
ZGluZyB0aGUgc3VtbWFyeSBvZiB3L0hBUlQgam9pbmluZy4NCg0KSSBoYXZlIHF1ZXN0aW9uLg0K
DQpJbiB3L0hBUlQsIGFyZSBhbGwgYmVhY29uIGZyYW1lcyBhdXRoZW50aWNhdGVkIHdpdGggYSB3
ZWxsLWtub3duIGtleSBldmVuIGFmdGVyIGEgam9pbmluZyBub2RlIG9idGFpbmVkIHRoZSBydW50
aW1lIGxpbmsgbGF5ZXIga2V5Pw0KDQpSZWdhcmRzLA0KWW9zaGloaXJvIE9oYmENCg0KDQoNCg0K
RnJvbTogNnRpc2NoLXNlY3VyaXR5IFttYWlsdG86NnRpc2NoLXNlY3VyaXR5LWJvdW5jZXNAaWV0
Zi5vcmc8bWFpbHRvOjZ0aXNjaC1zZWN1cml0eS1ib3VuY2VzQGlldGYub3JnPl0gT24gQmVoYWxm
IE9mIEpvbmF0aGFuIFNpbW9uDQpTZW50OiBUdWVzZGF5LCBNYXkgMjcsIDIwMTQgMTA6NDEgUE0N
ClRvOiBSZW5lIFN0cnVpaw0KQ2M6IE1pY2hhZWwgUmljaGFyZHNvbjsgNnRpc2NoLXNlY3VyaXR5
QGlldGYub3JnPG1haWx0bzo2dGlzY2gtc2VjdXJpdHlAaWV0Zi5vcmc+DQpTdWJqZWN0OiBSZTog
WzZ0aXNjaC1zZWN1cml0eV0gYWdlbmRhIGZvciAyMDE0LTA1LTI3IDZ0aXNjaCBzZWN1cml0eSBj
YWxsDQoNClJlbmUgaGFkIGFza2VkIG9uIGEgcHJldmlvdXMgY2FsbCBmb3Igc29tZW9uZSB0byBz
dW1tYXJpemUgV2lyZWxlc3NIQVJUIGpvaW5pbmcgLSBoZXJlIHlvdSBnby4NCg0KKiBPbmUgb3Ig
bW9yZSBkZXZpY2VzIGFyZSBzZW5kaW5nIGJlYWNvbnMgdG8gYWR2ZXJ0aXNlIHRoZSBwcmVzZW5j
ZSBvZiB0aGUgbmV0d29yay4gSW4gV2lyZWxlc3NIQVJULCB0aGlzIGZyYW1lIGlzIHVuZW5jcnlw
dGVkLCBidXQgYXV0aGVudGljYXRlZCB3aXRoIGEgd2VsbCBrbm93biBrZXkuICBUaGUgYmVhY29u
IGNvbnRhaW5zIHRoZSBjdXJyZW50IEFTTiwgd2hpY2ggdGhlIGpvaW5pbmcgZGV2aWNlIHVzZXMg
dG8gc3luY2hyb25pemUgaXRzIGNsb2NrLg0KKiBPbmNlIHRoZSBqb2luaW5nIG5vZGUgaGFzIGhl
YXJkIGEgYmVhY29uLCBpdCBjb250aW51ZXMgbGlzdGVuaW5nIGZvciBhZGRpdGlvbmFsIGJlYWNv
bnMgZm9yIGEgc2hvcnQgc3BlY2lmaWVkIHRpbWVvdXQuDQoqIFRoZSBqb2luaW5nIG5vZGUgZW5j
cnlwdHMgYSBmcmFtZSBjb250YWluaW5nIHNvbWUgSEFSVCBzcGVjaWZpYyBjb250ZW50LCBpbmNs
dWRpbmcgYSBsaXN0IG9mIGJlYWNvbmluZyBuZWlnaGJvcnMgaXQgaGVhcmQgaW4gdGhlIHByZXZp
b3VzIHN0ZXBzLiBUaGUgc2l6ZSBvZiB0aGUgcGF5bG9hZCBpcyB+IDYwIGJ5dGVzLiAgVGhlIHBh
Y2tldCBpcyByb3V0ZWQgYnkgYSAicHJveHkiIG5vZGUgLSB0aGUgam9pbmluZyBwYXJlbnQuIFRo
ZSBmcmFtZSBpcyBhdXRoZW50aWNhdGVkIHVzaW5nIHRoZSB3ZWxsLWtub3duIGtleSwgYW5kIGVu
Y3J5cHRlZCB1c2luZyBhIHNoYXJlZCBzeW1tZXRyaWMga2V5IGtub3duIG9ubHkgYnkgdGhlIG5v
ZGUgYW5kIHRoZSBtYW5hZ2VyLg0KDQoqIFRoZSBtYW5hZ2VyIHJlc3BvbmRzIHdpdGggYSBmcmFt
ZSBjb250YWluaW5nIHRoZSBydW4tdGltZSBsaW5rLWxheWVyIGtleSwgdGhlIG5vZGUncyBuZXcg
c2hvcnQgYWRkcmVzcyAodGhpcyB0YWtlcyB0aGUgcGxhY2Ugb2YgUEFOIGNvb3JkaW5hdG9yIGFz
c29jaWF0aW9uKSwgYW5kIGEgdW5pY2FzdCBzZXNzaW9uIGtleSBhbmQgc3RhcnRpbmcgbm9uY2Ug
Zm9yIHRoZSBtYW5hZ2VyLiBUaGlzIGZyYW1lIGlzIGVuY3J5cHRlZCB3aXRoIHRoZSBzeW1tZXRy
aWMga2V5LiBUaGUgcGF5bG9hZCBpcyB+IDYwIGJ5dGVzLCBhbmQgaXMgcm91dGVkIHRvIHRoZSBw
cm94eSBmb3IgZGVsaXZlcnkgdG8gdGhlIGpvaW5pbmcgbm9kZSAtIHRoZSBwcm94eSB1c2VzIHRo
ZSBsaW5rLWxheWVyIHdlbGwga25vd24ga2V5IG9uIHRoZSBmcmFtZS4NCiogQXQgdGhpcyBwb2lu
dCB0aGUgam9pbmluZyBub2RlIHRyYW5zaXRpb25zIHRvIHVzaW5nIHRoZSBydW4tdGltZSBsaW5r
LWxheWVyIGtleSBmb3IgYWxsIGxpbmstbGF5ZXIgZnJhbWVzLCBhbmQgdGhlIG1hbmFnZXIgdW5p
Y2FzdCBzZXNzaW9uIGZvciBlbmQtdG8tZW5kIG1hbmFnZXIgdHJhZmZpYy4gVGhpcyBlbmRzIHRo
ZSBpbml0aWFsIHNlY3VyaXR5IGhhbmRzaGFrZS4NCiogT3ZlciBhIG51bWJlciBvZiBhZGRpdGlv
bmFsIGZyYW1lcywgdGhlIG1hbmFnZXIgYXNzaWducyBhZGRpdGlvbmFsIHNlc3Npb25zLCBpbmNs
dWRpbmcgYnJvYWRjYXN0IHNlc3Npb25zLCBhbmQgYSB1bmljYXN0IHNlc3Npb24gdG8gdGhlIEdh
dGV3YXkgKHNpbmsgZm9yIGFsbCBkYXRhIHRyYWZmaWMpLCBhbmQgYWRkaXRpb25hbCBjb21tdW5p
Y2F0aW9ucyByZXNvdXJjZXMsIHJvdXRpbmcgaW5mb3JtYXRpb24sIGV0Yy4gIFRoZXJlIGlzIG5v
IGV4cGxpY2l0IHRyYW5zaXRpb24gZnJvbSBqb2luaW5nIHRvIGpvaW5lZCAtIHRoZSBtb3RlIHRy
YW5zaXRpb25zIHdoZW4gY2VydGFpbiBrZXkgZnJhbWVzIGFyZSByZWNlaXZlZC4NCiogTm90ZSB0
aGF0IGEgV2lyZWxlc3NIQVJUIGxpbmstbGF5ZXIgZnJhbWUgY29udGFpbnMgYW5kIGFkZGl0aW9u
YWwgZnJhbWUgdHlwZSBieXRlIGFuZCBhIDQtYnl0ZSBsaW5rLWxheWVyIE1JQywgb24gdG9wIG9m
IHRoZSB1bnNlY3VyZWQgMTUuNCBmcmFtZS4gIEEgbmV0d29yayBmcmFtZSBjb250YWlucyBhbiBh
ZGRpdGlvbmFsIDE2LTQwIGJ5dGVzIG9mIGFkZHJlc3NpbmcsIHJvdXRpbmcsIHNlY3VyaXR5IGFu
ZCBvdGhlciBpbmZvcm1hdGlvbi4NCkhvcGUgdGhpcyBoZWxwIQ0KSm9uYXRoYW4NCg0KDQpPbiBN
b24sIE1heSAyNiwgMjAxNCBhdCA4OjA5IFBNLCBSZW5lIFN0cnVpayA8cnN0cnVpay5leHRAZ21h
aWwuY29tPG1haWx0bzpyc3RydWlrLmV4dEBnbWFpbC5jb20+PiB3cm90ZToNCkhpIE1pY2hhZWw6
DQoNCkkgd291bGQgbGlrZSB0byBkaXNjdXNzIHRoZSBvdXRzdGFuZGluZyBpc3N1ZXMgSSBzdW1t
YXJpemVkIGluIG15IGVtYWlsIG9mIFR1ZSBsYXN0IHdlZWssIE1heSAyMCwgMjAxNCwgOTo0NWFt
IEVEVCAoc2VlIGh0dHA6Ly93d3cuaWV0Zi5vcmcvbWFpbC1hcmNoaXZlL3dlYi82dGlzY2gtc2Vj
dXJpdHkvY3VycmVudC9tc2cwMDA4Ni5odG1sPGh0dHA6Ly9jcC5tY2FmZWUuY29tL2QvNWZIQ01V
cDQxRVN5TnQ1NU9XdFNqdFBxYndWQmNTeVVlcHZkRUszemhPeUNPcWVqcnpQUFB6NVhDTjZBQnFN
MWhZRXZJdW5kRE94LU5Wc1RKUVhJZmNMWnZDNFRRVFM2ZUxzS0NPLVBQWFgzWFVWekJIRlNoamxL
ZXBWa2ZmR2hCcndxcmhkSTZYWXlNQ1ktZWhvamQ3OUtWSTA1YlZLWTAxTWpiWDZOZWhEWTA1ekFW
a0lqYlEtUHNwamJwcEtjdnhmNXE0clRLWVZNZWRLakJpTmNMalhkTkJjSW44bHJ4clcwR25QdFUw
MnJoaHVoS3IxdkY2eTBRSktqQmlOY0xqWGROQmNJcW5qaDFGN1U4cXE4N3FOZDQydFFtMlpUT1dv
VVFnZWpCaU5jUWdrLVBzcGpiNnkyU0REQ1Q2M3BPX28+KS4gVGhpcyB3YXMgYWxzbyBvbmUgb2Yg
dGhlIGFjdGlvbiBpdGVtcyBhdCB0aGUgY29uY2x1c2lvbiBvZiBsYXN0IHdlZWsncyA2VGlTQ0gg
c2VjdXJpdHkgY2FsbC4NCg0KRllJIC0gdGhlIHcvSEFSVCBjb21tdW5pY2F0aW9uIGZsb3dzIHdl
cmUgZGlzY3Vzc2VkIGR1cmluZyB0aGUgNlRpU0NIIHNlY3VyaXR5IGNvbmYgY2FsbCB0aGUgd2Vl
ayBiZWZvcmUsIG9uIE1vbiBNYXkgMTIsIDIwMTQuIElmIG9uZSB3aXNoZXMgdG8gZ28gb3ZlciB0
aGlzIGFnYWluLCB0aGF0IGlzIGZpbmUsIGJ1dCBJIHdvdWxkIHByZWZlciB1cyBnaXZpbmcgcHJl
ZmVyZW5jZSB0byB0YWtpbmcgb24gYWxyZWFkeSBhcnRpY3VsYXRlZCBpc3N1ZXMgKHdoaWNoIHdl
cmUgYXNzaWduZWQgYXMgaG9tZXdvcmsgYXNzaWdubWVudCB0byByZWZsZWN0IHVwb24pIGZpcnN0
IChpLmUuLCBwcmlvciB0byBpdGVtICM0IG9mIHRoZSBwcm9wb3NlZCBhZ2VuZGEpLg0KDQpBcyBh
bm90aGVyIGFnZW5kYSBwb2ludCwgSSB3b3VsZCBsaWtlIHVzIHRvIGRpc2N1c3MgdGhlIGZyZXF1
ZW5jeSBvZiBmdXR1cmUgY2FsbHMgKGFzIHBhcnQgb2YgRU9CKS4NCg0KQmVzdCByZWdhcmRzLCBS
ZW5lDQoNCg0KT24gNS8yNi8yMDE0IDEwOjQ5IFBNLCBNaWNoYWVsIFJpY2hhcmRzb24gd3JvdGU6
DQoNClRvIHJlbWluZCwgd2UgbW92ZWQgdGhlIGNhbGwgZnJvbSB0aGUgMjZ0aCB0byB0aGUgMjd0
aCBhdCAxMGFtIEVEVC4NCg0KVGhhdCdzIDkwIG1pbnV0ZXMgZnJvbSB0aGlzIGVtYWlsLg0KDQoN
Cg0KMSkgbm90ZXdlbGwuDQoNCjIpIGludHJvcw0KDQozKSByZWNhcCBvZiBkcmFmdC1waXJvLQ0K
DQo0KSB3aXJlbGVzc2hhcnQgLXdheSAtLS0gaG93IGRvZXMgdGhlIGNvbW11bmljYXRpb24gd29y
az8NCg0KNSkgaG93IHRvIHN1bW1hcml6ZSBhbGwgb2YgdGhpcyB0byB0aGUgd29ya2luZyBncm91
cA0KDQo2KSBob3cgdG8gY2xvc2UgdGhpcyBwcm9jZXNzIHVwPw0KDQoNCg0KLS0gcmVtZW1iZXIg
dGhhdCB0aGUgY2FsbCBpcyByZWNvcmRlZCwgYW5kIHRoZSBOb3RlV2VsbCBhcHBsaWVzLg0KDQoN
Cg0KLS0gVGhlIFVSTCB0byBhY2Nlc3MgdGhlIHdlYmV4LCB3aGljaCB3aWxsIHdlIHVzZSBmb3Ig
YXVkaW8gb25seToNCg0KICBodHRwczovL2Npc2NvLndlYmV4LmNvbS9jaXNjby9qLnBocD9NVElE
PW0yZmUxMzliZjg3NmNlYTNlYzYyNzUwY2Q1ODBiNzkwODxodHRwOi8vY3AubWNhZmVlLmNvbS9k
LzVmSENOMFN5TnQ1NU9XdFNqdFBxYndWQmNTeVVlcHZkRUszemhPeUNPcWVqcnpQUFB6NVhDTjZB
QnFNMWhZRXZJdW5kRE94LU5Wc1RKUVhJZmNMWnZDNFRRVFM2ZUxzS0NPLVBQWFgzWFVWekJIRlNo
amxLZXBWa2ZmR2hCcndxcmpkSTZYWXlNQ1ktZWhvamQ3OUtWSURlcVI0SU9RR21ITTBMMy1uT1FH
bUh3ek1oOTNvOTNnVVZsZFRRbWpoT2d0dTdlbV9tdklVQ2V2THAxWldWMHNxZXJMNlQ5T0ZvQ25G
WkNVT0NtYkFhSk1KWjBsYlZLWTAxZEVFTDhUZHdMUXpoMHFtVDlPRm9DbkZaQ1VPQ21kYkZFd1F6
WTRkZDQzSm9DeTFlV2IxdVhWdGNzcTg3OU9Gb0NxOGF2cEtjRkJ6aDFyalBQcnoxTG1Udzd3MTc+
DQoNCg0KDQotLSB3ZSB3aWxsIHJlc3VtZSB3aXRoIHRoZSBldGhlcnBhZCBhdDoNCg0KICAgaHR0
cDovL2V0aGVycGFkLnRvb2xzLmlldGYub3JnOjkwMDAvcC9ub3Rlcy1pZXRmLTg5LTZ0aXNjaC1z
ZWN1cml0eTxodHRwOi8vY3AubWNhZmVlLmNvbS9kLzJEUlBvdzcxTko1eVdhYkJRWElDWENRbjFQ
YXBKNU1zTy1yaHM3NnpCNWRBUXNDVDdEREQ2YlRkeWQ5YVJ3MnpWZ19vWUtyZkIzWnpPVkxyRlRv
dXB2V19jOUxGTEljdHVWdGRCWkREVFM3VE5QN2Juakl5Q0hzc1BPRXV2a3phVDBRU09yb2RUVjV4
ZFZZc3lNQ3FlanRQbzBmVkFfeUpHN2pIay1EaS1yTDAwa3poUHVaWW1PNXBfZ0xiVktCVHpoT25z
RGFCeXB1RFNyemFwb1NWZWxiNE9aZklUNmtPTnN4bEs1TEUyRnZkVHcwOUo1NVY2Vkk1LUFxODNp
U1ZlbGI0T1pmSVQ2a09ORnRkNDZBdnd4RkV3dEg0UWc5VGhvYlR2YkZ6emgwVmVsYjRQaDFqWGRO
QmNJcThicXV1cnNvZEppWnZwbUs2R3dZPg0KDQoNCg0KSSdtIGF0ICsxIDYxMyAyNzYtNjgwOTx0
ZWw6JTJCMSUyMDYxMyUyMDI3Ni02ODA5PiwgSU06IG1jckB4bXBwLmNyZWRpbC5vcmc8bWFpbHRv
Om1jckB4bXBwLmNyZWRpbC5vcmc+IG9yIG1jaGFybGVzckBnbWFpbC5jb208bWFpbHRvOm1jaGFy
bGVzckBnbWFpbC5jb20+LA0KDQppZiB5b3UgbmVlZCBtb3JlIHRoYW4gdGhhdCB0byBnZXQgaW4s
IG9yIGFyZSBoYXZpbmcgZGlmZmljdWx0aWVzLg0KDQpQbGVhc2UgbWFrZSBzdXJlIHlvdXIgYXVk
aW8gd29ya3MsIGFuZCB0aGF0IHlvdSBtdXRlIHdoZW4gbm90IHRhbGtpbmcuDQoNCg0KDQotLQ0K
DQpNaWNoYWVsIFJpY2hhcmRzb24gPG1jcitJRVRGQHNhbmRlbG1hbi5jYT48bWFpbHRvOm1jcitJ
RVRGQHNhbmRlbG1hbi5jYT4sIFNhbmRlbG1hbiBTb2Z0d2FyZSBXb3Jrcw0KDQogLT0gSVB2NiBJ
b1QgY29uc3VsdGluZyA9LQ0KDQoNCg0KDQoNCg0KDQoNCl9fX19fX19fX19fX19fX19fX19fX19f
X19fX19fX19fX19fX19fX19fX19fX19fDQoNCjZ0aXNjaC1zZWN1cml0eSBtYWlsaW5nIGxpc3QN
Cg0KNnRpc2NoLXNlY3VyaXR5QGlldGYub3JnPG1haWx0bzo2dGlzY2gtc2VjdXJpdHlAaWV0Zi5v
cmc+DQoNCmh0dHBzOi8vd3d3LmlldGYub3JnL21haWxtYW4vbGlzdGluZm8vNnRpc2NoLXNlY3Vy
aXR5PGh0dHA6Ly9jcC5tY2FmZWUuY29tL2QvMkRSUG9PODZRbWJFRUtuaktPcktyaHM3Y0ZDUW4x
UGJWSjVNc3Fla2tTamhPcnN1dXVzb0xzUzhRQUhtMGFmQjNaek9WSS1rZlNmYkNaS0R0eFZCX0hZ
TUMtQy1NTlJYQlFTblN1dnZvdnY3Y3NKdGVPYXFKTlBmYXhWWmljSHMzanIxSndUdkFtNFRETk9i
MnBFVmRUZEFWUG1FQkM1ZUJZVHUwMFU5R1gzM1ZrRGEzSnNzRGFCeXB1RFNyemFwb1NWZWxiNE9a
ZklUNmtPTnN4bEs1TEUyRnZkVHcwOUo1NVY2Vkk1LUFxODNpU1ZlbGI0T1pmSVQ2a09ORnRkNDZB
dnd4RkV3dEg0UWc5VGhvYlR2YkZ6emgwVmVsYjRQaDFqWGROQmNJcThicXV1cnNvZExXYnY+DQoN
Cg0KDQotLQ0KDQplbWFpbDogcnN0cnVpay5leHRAZ21haWwuY29tPG1haWx0bzpyc3RydWlrLmV4
dEBnbWFpbC5jb20+IHwgU2t5cGU6IHJzdHJ1aWsNCg0KY2VsbDogKzEgKDY0NykgODY3LTU2NTg8
dGVsOiUyQjElMjAlMjg2NDclMjklMjA4NjctNTY1OD4gfCBVUzogKzEgKDQxNSkgNjkwLTczNjM8
dGVsOiUyQjElMjAlMjg0MTUlMjklMjA2OTAtNzM2Mz4NCg0KX19fX19fX19fX19fX19fX19fX19f
X19fX19fX19fX19fX19fX19fX19fX19fX18NCjZ0aXNjaC1zZWN1cml0eSBtYWlsaW5nIGxpc3QN
CjZ0aXNjaC1zZWN1cml0eUBpZXRmLm9yZzxtYWlsdG86NnRpc2NoLXNlY3VyaXR5QGlldGYub3Jn
Pg0KaHR0cDovL2NwLm1jYWZlZS5jb20vZC9hdm5kemdROTNnQXJob0t5eVZ0ZVg5S1ZKNU1zT0Ny
aHM3Y0xDUW4xTkVWaGpwZDc5Sk5WVlZOeVpQb3ppaUpvMEUta2ZTZmJDUFZnX29ZS3JTV3RTN0Nu
LUxQMnJXclgzN25LbmpwdnBWWlp4WllzTk9SUVg4RkdUN2NZRzdEUjhPSk1kZEVDUWp0LWhvanV2
NzhJOUN6QVRzU2pEZHF5bW9rV25QdFUwM3dDSEljZkJpc0VlUk5Pc0dtOUJXdnBLY0ZCenJBVmtJ
amJRLVBzcGpiNU81bVVtLXdhQllUdTAwQ1FrbkFyQ01uV2hFd2RickFWa0lqYlEtUHNwamI2QlFR
Z3FoLTI2Q3kxU0lqaDBEdDV3THRZS0NlZDQzQVZrSWpkNDVmSVQ2a09ORXdKRlZWSk53U2VWaHNy
TGUtRmtkDQoNCg0KDQotLQ0KLS0NCkpvbmF0aGFuIFNpbW9uLCBQaC4gRA0KRGlyZWN0b3Igb2Yg
U3lzdGVtcyBFbmdpbmVlcmluZw0KRHVzdCBOZXR3b3JrcyBhdCBMaW5lYXIgVGVjaG5vbG9neQ0K
MzA2OTUgSHVudHdvb2QgQXZlDQpIYXl3YXJkLCBDQSA5NDU0NC03MDIxDQooNTEwKSA0MDAtMjkz
Njx0ZWw6JTI4NTEwJTI5JTIwNDAwLTI5MzY+DQooNTEwKSA0ODktMzc5OTx0ZWw6JTI4NTEwJTI5
JTIwNDg5LTM3OTk+IEZBWA0KanNpbW9uQGxpbmVhci5jb208bWFpbHRvOmpzaW1vbkBsaW5lYXIu
Y29tPg0KDQoqKkxJTkVBUiBURUNITk9MT0dZIENPUlBPUkFUSU9OKioNCioqKioqSW50ZXJuZXQg
RW1haWwgQ29uZmlkZW50aWFsaXR5IE5vdGljZSoqKioqDQogVGhpcyBlLW1haWwgdHJhbnNtaXNz
aW9uLCBhbmQgYW55IGRvY3VtZW50cywgZmlsZXMgb3IgcHJldmlvdXMgZS1tYWlsIG1lc3NhZ2Vz
IGF0dGFjaGVkIHRvIGl0IG1heSBjb250YWluIGNvbmZpZGVudGlhbCBpbmZvcm1hdGlvbiB0aGF0
IGlzIGxlZ2FsbHkgcHJpdmlsZWdlZC4gSWYgeW91IGFyZSBub3QgdGhlIGludGVuZGVkIHJlY2lw
aWVudCwgb3IgYSBwZXJzb24gcmVzcG9uc2libGUgZm9yIGRlbGl2ZXJpbmcgaXQgdG8gdGhlIGlu
dGVuZGVkIHJlY2lwaWVudCwgeW91IGFyZSBoZXJlYnkgbm90aWZpZWQgdGhhdCBhbnkgZGlzY2xv
c3VyZSwgY29weWluZywgZGlzdHJpYnV0aW9uIG9yIHVzZSBvZiBhbnkgb2YgdGhlIGluZm9ybWF0
aW9uIGNvbnRhaW5lZCBpbiBvciBhdHRhY2hlZCB0byB0aGlzIHRyYW5zbWlzc2lvbiBpcyBTVFJJ
Q1RMWSBQUk9ISUJJVEVELiBJZiB5b3UgaGF2ZSByZWNlaXZlZCB0aGlzIHRyYW5zbWlzc2lvbiBp
biBlcnJvciwgcGxlYXNlIGltbWVkaWF0ZWx5IG5vdGlmeSBtZSBieSByZXBseSBlLW1haWwsIG9y
IGJ5IHRlbGVwaG9uZSBhdCAoNTEwKSA0MDAtMjkzNjx0ZWw6JTI4NTEwJTI5JTIwNDAwLTI5MzY+
LCBhbmQgZGVzdHJveSB0aGUgb3JpZ2luYWwgdHJhbnNtaXNzaW9uIGFuZCBpdHMgYXR0YWNobWVu
dHMgd2l0aG91dCByZWFkaW5nIG9yIHNhdmluZyBpbiBhbnkgbWFubmVyLiBUaGFuayB5b3UuDQoN
Cl9fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fDQo2dGlzY2gt
c2VjdXJpdHkgbWFpbGluZyBsaXN0DQo2dGlzY2gtc2VjdXJpdHlAaWV0Zi5vcmc8bWFpbHRvOjZ0
aXNjaC1zZWN1cml0eUBpZXRmLm9yZz4NCmh0dHA6Ly9jcC5tY2FmZWUuY29tL2QvMkRSUG93NzZR
bWJFRkx6emhPTS1yS3JoczdjRkNRbjFQYlZKNU1zcWVra1NqaE9yc3V1dXNvTHNTOFFBSG0wYWZC
M1p6T1ZJLWtmU2ZiQ1RBN2hQWFBiX25WTlpOQlZ4ekhUYkV6SElZWWVwZDdiejhYQkhFU2hobEtN
X09FdXZremFUMFFTeXJoZFRWNXhkVllzeU1DcWVqdFBwZXNSRzlweGpGdmRUdzBlMnFLTU0tbDlP
d1huNzlPRm9DbkZaQ1VPQ21kS2pCaU5jTGpYZE5CY0luOGxyeHJXMEduUHRVMDJyb2poS1VyMXZG
NnkwUUpLakJpTmNMalhkTkJjSXFuamgxRjdVOHFxODdxTmQ0MnRRbTJaVE9Xb1VRZ2VqQmlOY1Fn
ay1Qc3BqYjZ5MlNERENUNjNydF9VMlNWVWxWQjANCg0KDQoNCi0tDQotLQ0KSm9uYXRoYW4gU2lt
b24sIFBoLiBEDQpEaXJlY3RvciBvZiBTeXN0ZW1zIEVuZ2luZWVyaW5nDQpEdXN0IE5ldHdvcmtz
IGF0IExpbmVhciBUZWNobm9sb2d5DQozMDY5NSBIdW50d29vZCBBdmUNCkhheXdhcmQsIENBIDk0
NTQ0LTcwMjENCig1MTApIDQwMC0yOTM2DQooNTEwKSA0ODktMzc5OSBGQVgNCmpzaW1vbkBsaW5l
YXIuY29tPG1haWx0bzpqc2ltb25AbGluZWFyLmNvbT4NCg0KKipMSU5FQVIgVEVDSE5PTE9HWSBD
T1JQT1JBVElPTioqDQoqKioqKkludGVybmV0IEVtYWlsIENvbmZpZGVudGlhbGl0eSBOb3RpY2Uq
KioqKg0KIFRoaXMgZS1tYWlsIHRyYW5zbWlzc2lvbiwgYW5kIGFueSBkb2N1bWVudHMsIGZpbGVz
IG9yIHByZXZpb3VzIGUtbWFpbCBtZXNzYWdlcyBhdHRhY2hlZCB0byBpdCBtYXkgY29udGFpbiBj
b25maWRlbnRpYWwgaW5mb3JtYXRpb24gdGhhdCBpcyBsZWdhbGx5IHByaXZpbGVnZWQuIElmIHlv
dSBhcmUgbm90IHRoZSBpbnRlbmRlZCByZWNpcGllbnQsIG9yIGEgcGVyc29uIHJlc3BvbnNpYmxl
IGZvciBkZWxpdmVyaW5nIGl0IHRvIHRoZSBpbnRlbmRlZCByZWNpcGllbnQsIHlvdSBhcmUgaGVy
ZWJ5IG5vdGlmaWVkIHRoYXQgYW55IGRpc2Nsb3N1cmUsIGNvcHlpbmcsIGRpc3RyaWJ1dGlvbiBv
ciB1c2Ugb2YgYW55IG9mIHRoZSBpbmZvcm1hdGlvbiBjb250YWluZWQgaW4gb3IgYXR0YWNoZWQg
dG8gdGhpcyB0cmFuc21pc3Npb24gaXMgU1RSSUNUTFkgUFJPSElCSVRFRC4gSWYgeW91IGhhdmUg
cmVjZWl2ZWQgdGhpcyB0cmFuc21pc3Npb24gaW4gZXJyb3IsIHBsZWFzZSBpbW1lZGlhdGVseSBu
b3RpZnkgbWUgYnkgcmVwbHkgZS1tYWlsLCBvciBieSB0ZWxlcGhvbmUgYXQgKDUxMCkgNDAwLTI5
MzYsIGFuZCBkZXN0cm95IHRoZSBvcmlnaW5hbCB0cmFuc21pc3Npb24gYW5kIGl0cyBhdHRhY2ht
ZW50cyB3aXRob3V0IHJlYWRpbmcgb3Igc2F2aW5nIGluIGFueSBtYW5uZXIuIFRoYW5rIHlvdS4N
Cg==

--_000_674F70E5F2BE564CB06B6901FD3DD78B2723B85ATGXML210toshiba_
Content-Type: text/html; charset="utf-8"
Content-Transfer-Encoding: base64

PGh0bWwgeG1sbnM6dj0idXJuOnNjaGVtYXMtbWljcm9zb2Z0LWNvbTp2bWwiIHhtbG5zOm89InVy
bjpzY2hlbWFzLW1pY3Jvc29mdC1jb206b2ZmaWNlOm9mZmljZSIgeG1sbnM6dz0idXJuOnNjaGVt
YXMtbWljcm9zb2Z0LWNvbTpvZmZpY2U6d29yZCIgeG1sbnM6bT0iaHR0cDovL3NjaGVtYXMubWlj
cm9zb2Z0LmNvbS9vZmZpY2UvMjAwNC8xMi9vbW1sIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcv
VFIvUkVDLWh0bWw0MCI+DQo8aGVhZD4NCjxtZXRhIGh0dHAtZXF1aXY9IkNvbnRlbnQtVHlwZSIg
Y29udGVudD0idGV4dC9odG1sOyBjaGFyc2V0PXV0Zi04Ij4NCjxtZXRhIG5hbWU9IkdlbmVyYXRv
ciIgY29udGVudD0iTWljcm9zb2Z0IFdvcmQgMTUgKGZpbHRlcmVkIG1lZGl1bSkiPg0KPHN0eWxl
PjwhLS0NCi8qIEZvbnQgRGVmaW5pdGlvbnMgKi8NCkBmb250LWZhY2UNCgl7Zm9udC1mYW1pbHk6
Iu+8re+8syDjgrTjgrfjg4Pjgq8iOw0KCXBhbm9zZS0xOjIgMTEgNiA5IDcgMiA1IDggMiA0O30N
CkBmb250LWZhY2UNCgl7Zm9udC1mYW1pbHk6IkNhbWJyaWEgTWF0aCI7DQoJcGFub3NlLTE6MiA0
IDUgMyA1IDQgNiAzIDIgNDt9DQpAZm9udC1mYWNlDQoJe2ZvbnQtZmFtaWx5OkNhbGlicmk7DQoJ
cGFub3NlLTE6MiAxNSA1IDIgMiAyIDQgMyAyIDQ7fQ0KQGZvbnQtZmFjZQ0KCXtmb250LWZhbWls
eToi77yt77yzIO+8sOOCtOOCt+ODg+OCryI7DQoJcGFub3NlLTE6MiAxMSA2IDAgNyAyIDUgOCAy
IDQ7fQ0KQGZvbnQtZmFjZQ0KCXtmb250LWZhbWlseToiXEDvvK3vvLMg44K044K344OD44KvIjsN
CglwYW5vc2UtMToyIDExIDYgOSA3IDIgNSA4IDIgNDt9DQpAZm9udC1mYWNlDQoJe2ZvbnQtZmFt
aWx5OiJcQO+8re+8syDvvLDjgrTjgrfjg4Pjgq8iOw0KCXBhbm9zZS0xOjIgMTEgNiAwIDcgMiA1
IDggMiA0O30NCi8qIFN0eWxlIERlZmluaXRpb25zICovDQpwLk1zb05vcm1hbCwgbGkuTXNvTm9y
bWFsLCBkaXYuTXNvTm9ybWFsDQoJe21hcmdpbjowbW07DQoJbWFyZ2luLWJvdHRvbTouMDAwMXB0
Ow0KCWZvbnQtc2l6ZToxMi4wcHQ7DQoJZm9udC1mYW1pbHk6Iu+8re+8syDvvLDjgrTjgrfjg4Pj
gq8iO30NCmE6bGluaywgc3Bhbi5Nc29IeXBlcmxpbmsNCgl7bXNvLXN0eWxlLXByaW9yaXR5Ojk5
Ow0KCWNvbG9yOmJsdWU7DQoJdGV4dC1kZWNvcmF0aW9uOnVuZGVybGluZTt9DQphOnZpc2l0ZWQs
IHNwYW4uTXNvSHlwZXJsaW5rRm9sbG93ZWQNCgl7bXNvLXN0eWxlLXByaW9yaXR5Ojk5Ow0KCWNv
bG9yOnB1cnBsZTsNCgl0ZXh0LWRlY29yYXRpb246dW5kZXJsaW5lO30NCnByZQ0KCXttc28tc3R5
bGUtcHJpb3JpdHk6OTk7DQoJbXNvLXN0eWxlLWxpbms6IkhUTUwg5pu45byP5LuY44GNIFwo5paH
5a2XXCkiOw0KCW1hcmdpbjowbW07DQoJbWFyZ2luLWJvdHRvbTouMDAwMXB0Ow0KCWZvbnQtc2l6
ZToxMi4wcHQ7DQoJZm9udC1mYW1pbHk6Iu+8re+8syDjgrTjgrfjg4Pjgq8iO30NCnNwYW4uSFRN
TA0KCXttc28tc3R5bGUtbmFtZToiSFRNTCDmm7jlvI/ku5jjgY0gXCjmloflrZdcKSI7DQoJbXNv
LXN0eWxlLXByaW9yaXR5Ojk5Ow0KCW1zby1zdHlsZS1saW5rOiJIVE1MIOabuOW8j+S7mOOBjSI7
DQoJZm9udC1mYW1pbHk6IkNvdXJpZXIgTmV3Ijt9DQpzcGFuLjE5DQoJe21zby1zdHlsZS10eXBl
OnBlcnNvbmFsLXJlcGx5Ow0KCWZvbnQtZmFtaWx5OiJBcmlhbCIsInNhbnMtc2VyaWYiOw0KCWNv
bG9yOiMxRjQ5N0Q7fQ0KLk1zb0NocERlZmF1bHQNCgl7bXNvLXN0eWxlLXR5cGU6ZXhwb3J0LW9u
bHk7DQoJZm9udC1mYW1pbHk6IkFyaWFsIiwic2Fucy1zZXJpZiI7fQ0KQHBhZ2UgV29yZFNlY3Rp
b24xDQoJe3NpemU6NjEyLjBwdCA3OTIuMHB0Ow0KCW1hcmdpbjo5OS4yNXB0IDMwLjBtbSAzMC4w
bW0gMzAuMG1tO30NCmRpdi5Xb3JkU2VjdGlvbjENCgl7cGFnZTpXb3JkU2VjdGlvbjE7fQ0KLS0+
PC9zdHlsZT48IS0tW2lmIGd0ZSBtc28gOV0+PHhtbD4NCjxvOnNoYXBlZGVmYXVsdHMgdjpleHQ9
ImVkaXQiIHNwaWRtYXg9IjEwMjYiPg0KPHY6dGV4dGJveCBpbnNldD0iNS44NXB0LC43cHQsNS44
NXB0LC43cHQiIC8+DQo8L286c2hhcGVkZWZhdWx0cz48L3htbD48IVtlbmRpZl0tLT48IS0tW2lm
IGd0ZSBtc28gOV0+PHhtbD4NCjxvOnNoYXBlbGF5b3V0IHY6ZXh0PSJlZGl0Ij4NCjxvOmlkbWFw
IHY6ZXh0PSJlZGl0IiBkYXRhPSIxIiAvPg0KPC9vOnNoYXBlbGF5b3V0PjwveG1sPjwhW2VuZGlm
XS0tPg0KPC9oZWFkPg0KPGJvZHkgbGFuZz0iSkEiIGxpbms9ImJsdWUiIHZsaW5rPSJwdXJwbGUi
Pg0KPGRpdiBjbGFzcz0iV29yZFNlY3Rpb24xIj4NCjxwIGNsYXNzPSJNc29Ob3JtYWwiPjxzcGFu
IGxhbmc9IkVOLVVTIiBzdHlsZT0iZm9udC1zaXplOjEwLjBwdDtmb250LWZhbWlseTomcXVvdDtB
cmlhbCZxdW90OywmcXVvdDtzYW5zLXNlcmlmJnF1b3Q7O2NvbG9yOiMxRjQ5N0QiPkhpIEpvbmF0
aGFuLA0KPG86cD48L286cD48L3NwYW4+PC9wPg0KPHAgY2xhc3M9Ik1zb05vcm1hbCI+PHNwYW4g
bGFuZz0iRU4tVVMiIHN0eWxlPSJmb250LXNpemU6MTAuMHB0O2ZvbnQtZmFtaWx5OiZxdW90O0Fy
aWFsJnF1b3Q7LCZxdW90O3NhbnMtc2VyaWYmcXVvdDs7Y29sb3I6IzFGNDk3RCI+PG86cD4mbmJz
cDs8L286cD48L3NwYW4+PC9wPg0KPHAgY2xhc3M9Ik1zb05vcm1hbCI+PHNwYW4gbGFuZz0iRU4t
VVMiIHN0eWxlPSJmb250LXNpemU6MTAuMHB0O2ZvbnQtZmFtaWx5OiZxdW90O0FyaWFsJnF1b3Q7
LCZxdW90O3NhbnMtc2VyaWYmcXVvdDs7Y29sb3I6IzFGNDk3RCI+VGhhbmsgeW91IGZvciB5b3Vy
IGFuc3dlci48bzpwPjwvbzpwPjwvc3Bhbj48L3A+DQo8cCBjbGFzcz0iTXNvTm9ybWFsIj48c3Bh
biBsYW5nPSJFTi1VUyIgc3R5bGU9ImZvbnQtc2l6ZToxMC4wcHQ7Zm9udC1mYW1pbHk6JnF1b3Q7
QXJpYWwmcXVvdDssJnF1b3Q7c2Fucy1zZXJpZiZxdW90Oztjb2xvcjojMUY0OTdEIj48bzpwPiZu
YnNwOzwvbzpwPjwvc3Bhbj48L3A+DQo8cCBjbGFzcz0iTXNvTm9ybWFsIj48c3BhbiBsYW5nPSJF
Ti1VUyIgc3R5bGU9ImZvbnQtc2l6ZToxMC4wcHQ7Zm9udC1mYW1pbHk6JnF1b3Q7QXJpYWwmcXVv
dDssJnF1b3Q7c2Fucy1zZXJpZiZxdW90Oztjb2xvcjojMUY0OTdEIj5JIHRoaW5rIHRoaXMgY2Fu
IGJlIGFuIGlzc3VlIGlmIGFscmVhZHkgam9pbmVkIG5vZGVzIGFsc28gdXNlIHRoZSBiZWFjb25z
IHByb3RlY3RlZCB3aXRoIHRoZSB3ZWxsLWtub3duIGtleSBmb3IgbWFpbnRhaW5pbmcgc3luY2hy
b25pemF0aW9uIGFuZCBzbG90DQogYWxsb2NhdGlvbnMsIGFzIGFuIGF0dGFja2VyIGNhbiBzZW5k
IGZvcmdlZCBiZWFjb25zIHByb3RlY3RlZCB3aXRoIHRoZSB3ZWxsLWtub3duIGtleS48bzpwPjwv
bzpwPjwvc3Bhbj48L3A+DQo8cCBjbGFzcz0iTXNvTm9ybWFsIj48c3BhbiBsYW5nPSJFTi1VUyIg
c3R5bGU9ImZvbnQtc2l6ZToxMC4wcHQ7Zm9udC1mYW1pbHk6JnF1b3Q7QXJpYWwmcXVvdDssJnF1
b3Q7c2Fucy1zZXJpZiZxdW90Oztjb2xvcjojMUY0OTdEIj48bzpwPiZuYnNwOzwvbzpwPjwvc3Bh
bj48L3A+DQo8cCBjbGFzcz0iTXNvTm9ybWFsIj48c3BhbiBsYW5nPSJFTi1VUyIgc3R5bGU9ImZv
bnQtc2l6ZToxMC4wcHQ7Zm9udC1mYW1pbHk6JnF1b3Q7QXJpYWwmcXVvdDssJnF1b3Q7c2Fucy1z
ZXJpZiZxdW90Oztjb2xvcjojMUY0OTdEIj5Zb3NoaWhpcm8gT2hiYTxvOnA+PC9vOnA+PC9zcGFu
PjwvcD4NCjxwIGNsYXNzPSJNc29Ob3JtYWwiPjxzcGFuIGxhbmc9IkVOLVVTIiBzdHlsZT0iZm9u
dC1zaXplOjEwLjBwdDtmb250LWZhbWlseTomcXVvdDtBcmlhbCZxdW90OywmcXVvdDtzYW5zLXNl
cmlmJnF1b3Q7O2NvbG9yOiMxRjQ5N0QiPjxvOnA+Jm5ic3A7PC9vOnA+PC9zcGFuPjwvcD4NCjxw
IGNsYXNzPSJNc29Ob3JtYWwiPjxzcGFuIGxhbmc9IkVOLVVTIiBzdHlsZT0iZm9udC1zaXplOjEw
LjBwdDtmb250LWZhbWlseTomcXVvdDtBcmlhbCZxdW90OywmcXVvdDtzYW5zLXNlcmlmJnF1b3Q7
O2NvbG9yOiMxRjQ5N0QiPjxvOnA+Jm5ic3A7PC9vOnA+PC9zcGFuPjwvcD4NCjxwIGNsYXNzPSJN
c29Ob3JtYWwiPjxiPjxzcGFuIGxhbmc9IkVOLVVTIiBzdHlsZT0iZm9udC1zaXplOjExLjBwdDtm
b250LWZhbWlseTomcXVvdDtDYWxpYnJpJnF1b3Q7LCZxdW90O3NhbnMtc2VyaWYmcXVvdDsiPkZy
b206PC9zcGFuPjwvYj48c3BhbiBsYW5nPSJFTi1VUyIgc3R5bGU9ImZvbnQtc2l6ZToxMS4wcHQ7
Zm9udC1mYW1pbHk6JnF1b3Q7Q2FsaWJyaSZxdW90OywmcXVvdDtzYW5zLXNlcmlmJnF1b3Q7Ij4g
NnRpc2NoLXNlY3VyaXR5IFttYWlsdG86NnRpc2NoLXNlY3VyaXR5LWJvdW5jZXNAaWV0Zi5vcmdd
DQo8Yj5PbiBCZWhhbGYgT2YgPC9iPkpvbmF0aGFuIFNpbW9uPGJyPg0KPGI+U2VudDo8L2I+IFdl
ZG5lc2RheSwgTWF5IDI4LCAyMDE0IDExOjQ5IFBNPGJyPg0KPGI+VG86PC9iPiBvaGJhIHlvc2hp
aGlybyg8L3NwYW4+PHNwYW4gc3R5bGU9ImZvbnQtc2l6ZToxMS4wcHQiPuWkp+WgtDwvc3Bhbj48
c3BhbiBzdHlsZT0iZm9udC1zaXplOjExLjBwdDtmb250LWZhbWlseTomcXVvdDtDYWxpYnJpJnF1
b3Q7LCZxdW90O3NhbnMtc2VyaWYmcXVvdDsiPg0KPC9zcGFuPjxzcGFuIHN0eWxlPSJmb250LXNp
emU6MTEuMHB0Ij7nvqnmtIs8L3NwYW4+PHNwYW4gbGFuZz0iRU4tVVMiIHN0eWxlPSJmb250LXNp
emU6MTEuMHB0O2ZvbnQtZmFtaWx5OiZxdW90O0NhbGlicmkmcXVvdDssJnF1b3Q7c2Fucy1zZXJp
ZiZxdW90OyI+IOKXizwvc3Bhbj48c3BhbiBzdHlsZT0iZm9udC1zaXplOjExLjBwdCI+77yy77yk
77yjPC9zcGFuPjxzcGFuIGxhbmc9IkVOLVVTIiBzdHlsZT0iZm9udC1zaXplOjExLjBwdDtmb250
LWZhbWlseTomcXVvdDtDYWxpYnJpJnF1b3Q7LCZxdW90O3NhbnMtc2VyaWYmcXVvdDsiPuKWoTwv
c3Bhbj48c3BhbiBzdHlsZT0iZm9udC1zaXplOjExLjBwdCI+77yu77yz77ysPC9zcGFuPjxzcGFu
IGxhbmc9IkVOLVVTIiBzdHlsZT0iZm9udC1zaXplOjExLjBwdDtmb250LWZhbWlseTomcXVvdDtD
YWxpYnJpJnF1b3Q7LCZxdW90O3NhbnMtc2VyaWYmcXVvdDsiPik8YnI+DQo8Yj5DYzo8L2I+IE1p
Y2hhZWwgUmljaGFyZHNvbjsgUmVuZSBTdHJ1aWs7IDZ0aXNjaC1zZWN1cml0eUBpZXRmLm9yZzxi
cj4NCjxiPlN1YmplY3Q6PC9iPiBSZTogWzZ0aXNjaC1zZWN1cml0eV0gYWdlbmRhIGZvciAyMDE0
LTA1LTI3IDZ0aXNjaCBzZWN1cml0eSBjYWxsPG86cD48L286cD48L3NwYW4+PC9wPg0KPHAgY2xh
c3M9Ik1zb05vcm1hbCI+PHNwYW4gbGFuZz0iRU4tVVMiPjxvOnA+Jm5ic3A7PC9vOnA+PC9zcGFu
PjwvcD4NCjxkaXY+DQo8ZGl2Pg0KPHAgY2xhc3M9Ik1zb05vcm1hbCIgc3R5bGU9Im1hcmdpbi1i
b3R0b206MTIuMHB0Ij48c3BhbiBsYW5nPSJFTi1VUyI+WW9zaGloaXJvIC0gPGJyPg0KPGJyPg0K
US4gPC9zcGFuPjxzcGFuIGxhbmc9IkVOLVVTIiBzdHlsZT0iZm9udC1zaXplOjEwLjBwdDtmb250
LWZhbWlseTomcXVvdDtBcmlhbCZxdW90OywmcXVvdDtzYW5zLXNlcmlmJnF1b3Q7O2NvbG9yOiMx
RjQ5N0QiPkluIHcvSEFSVCwgYXJlIGFsbCBiZWFjb24gZnJhbWVzIGF1dGhlbnRpY2F0ZWQgd2l0
aCBhIHdlbGwta25vd24ga2V5IGV2ZW4gYWZ0ZXIgYSBqb2luaW5nIG5vZGUgb2J0YWluZWQgdGhl
IHJ1bnRpbWUgbGluayBsYXllciBrZXk/DQo8L3NwYW4+PHNwYW4gbGFuZz0iRU4tVVMiPjxvOnA+
PC9vOnA+PC9zcGFuPjwvcD4NCjwvZGl2Pg0KPGRpdj4NCjxwIGNsYXNzPSJNc29Ob3JtYWwiIHN0
eWxlPSJtYXJnaW4tYm90dG9tOjEyLjBwdCI+PHNwYW4gbGFuZz0iRU4tVVMiIHN0eWxlPSJmb250
LXNpemU6MTAuMHB0O2ZvbnQtZmFtaWx5OiZxdW90O0FyaWFsJnF1b3Q7LCZxdW90O3NhbnMtc2Vy
aWYmcXVvdDs7Y29sb3I6IzFGNDk3RCI+QS4gWWVzLiBJbiBXaXJlbGVzc0hBUlQgdGhlIGJlYWNv
bnMgKGNhbGxlZCAmcXVvdDthZHZlcnRpc2VtZW50cyZxdW90OyBidXQgdGhleSBzZXJ2ZSB0aGUg
c2FtZSBwdXJwb3NlIGFuZCBoYXZlIHNpbWlsYXIgY29udGVudCkNCiBhcmUgaW50ZW5kZWQgZm9y
IGRldmljZXMgbm90IHlldCBpbiB0aGUgbmV0d29yaywgc28gdGhleSBhbHdheXMgdXNlIHRoZSB3
ZWxsLWtub3duIGtleS4mbmJzcDsgVG8gZGlzY292ZXIgb3RoZXIgbm9kZXMgd2l0aGluIHRoZSBu
ZXR3b3JrLCB0aGV5IHVzZSBmcmFtZXMgc2VjdXJlZCB3aXRoIHRoZSBydW50aW1lIGxpbmstbGF5
ZXIga2V5Ljwvc3Bhbj48c3BhbiBsYW5nPSJFTi1VUyI+PG86cD48L286cD48L3NwYW4+PC9wPg0K
PC9kaXY+DQo8ZGl2Pg0KPHAgY2xhc3M9Ik1zb05vcm1hbCI+PHNwYW4gbGFuZz0iRU4tVVMiIHN0
eWxlPSJmb250LXNpemU6MTAuMHB0O2ZvbnQtZmFtaWx5OiZxdW90O0FyaWFsJnF1b3Q7LCZxdW90
O3NhbnMtc2VyaWYmcXVvdDs7Y29sb3I6IzFGNDk3RCI+Sm9uYXRoYW48L3NwYW4+PHNwYW4gbGFu
Zz0iRU4tVVMiPjxvOnA+PC9vOnA+PC9zcGFuPjwvcD4NCjwvZGl2Pg0KPC9kaXY+DQo8ZGl2Pg0K
PHAgY2xhc3M9Ik1zb05vcm1hbCIgc3R5bGU9Im1hcmdpbi1ib3R0b206MTIuMHB0Ij48c3BhbiBs
YW5nPSJFTi1VUyI+PG86cD4mbmJzcDs8L286cD48L3NwYW4+PC9wPg0KPGRpdj4NCjxwIGNsYXNz
PSJNc29Ob3JtYWwiPjxzcGFuIGxhbmc9IkVOLVVTIj5PbiBUdWUsIE1heSAyNywgMjAxNCBhdCAx
MToxOCBQTSwgJmx0OzxhIGhyZWY9Im1haWx0bzp5b3NoaWhpcm8ub2hiYUB0b3NoaWJhLmNvLmpw
IiB0YXJnZXQ9Il9ibGFuayI+eW9zaGloaXJvLm9oYmFAdG9zaGliYS5jby5qcDwvYT4mZ3Q7IHdy
b3RlOjxvOnA+PC9vOnA+PC9zcGFuPjwvcD4NCjxibG9ja3F1b3RlIHN0eWxlPSJib3JkZXI6bm9u
ZTtib3JkZXItbGVmdDpzb2xpZCAjQ0NDQ0NDIDEuMHB0O3BhZGRpbmc6MG1tIDBtbSAwbW0gNi4w
cHQ7bWFyZ2luLWxlZnQ6NC44cHQ7bWFyZ2luLXJpZ2h0OjBtbSI+DQo8ZGl2Pg0KPGRpdj4NCjxw
IGNsYXNzPSJNc29Ob3JtYWwiIHN0eWxlPSJtc28tbWFyZ2luLXRvcC1hbHQ6YXV0bzttc28tbWFy
Z2luLWJvdHRvbS1hbHQ6YXV0byI+PHNwYW4gbGFuZz0iRU4tVVMiIHN0eWxlPSJmb250LXNpemU6
MTAuMHB0O2ZvbnQtZmFtaWx5OiZxdW90O0FyaWFsJnF1b3Q7LCZxdW90O3NhbnMtc2VyaWYmcXVv
dDs7Y29sb3I6IzFGNDk3RCI+SGkgSm9uYXRoYW4sPC9zcGFuPjxzcGFuIGxhbmc9IkVOLVVTIj48
bzpwPjwvbzpwPjwvc3Bhbj48L3A+DQo8cCBjbGFzcz0iTXNvTm9ybWFsIiBzdHlsZT0ibXNvLW1h
cmdpbi10b3AtYWx0OmF1dG87bXNvLW1hcmdpbi1ib3R0b20tYWx0OmF1dG8iPjxzcGFuIGxhbmc9
IkVOLVVTIiBzdHlsZT0iZm9udC1zaXplOjEwLjBwdDtmb250LWZhbWlseTomcXVvdDtBcmlhbCZx
dW90OywmcXVvdDtzYW5zLXNlcmlmJnF1b3Q7O2NvbG9yOiMxRjQ5N0QiPiZuYnNwOzwvc3Bhbj48
c3BhbiBsYW5nPSJFTi1VUyI+PG86cD48L286cD48L3NwYW4+PC9wPg0KPHAgY2xhc3M9Ik1zb05v
cm1hbCIgc3R5bGU9Im1zby1tYXJnaW4tdG9wLWFsdDphdXRvO21zby1tYXJnaW4tYm90dG9tLWFs
dDphdXRvIj48c3BhbiBsYW5nPSJFTi1VUyIgc3R5bGU9ImZvbnQtc2l6ZToxMC4wcHQ7Zm9udC1m
YW1pbHk6JnF1b3Q7QXJpYWwmcXVvdDssJnF1b3Q7c2Fucy1zZXJpZiZxdW90Oztjb2xvcjojMUY0
OTdEIj5UaGFuayB5b3UgZm9yIHNlbmRpbmcgdGhlIHN1bW1hcnkgb2Ygdy9IQVJUIGpvaW5pbmcu
DQo8L3NwYW4+PHNwYW4gbGFuZz0iRU4tVVMiPjxvOnA+PC9vOnA+PC9zcGFuPjwvcD4NCjxwIGNs
YXNzPSJNc29Ob3JtYWwiIHN0eWxlPSJtc28tbWFyZ2luLXRvcC1hbHQ6YXV0bzttc28tbWFyZ2lu
LWJvdHRvbS1hbHQ6YXV0byI+PHNwYW4gbGFuZz0iRU4tVVMiIHN0eWxlPSJmb250LXNpemU6MTAu
MHB0O2ZvbnQtZmFtaWx5OiZxdW90O0FyaWFsJnF1b3Q7LCZxdW90O3NhbnMtc2VyaWYmcXVvdDs7
Y29sb3I6IzFGNDk3RCI+Jm5ic3A7PC9zcGFuPjxzcGFuIGxhbmc9IkVOLVVTIj48bzpwPjwvbzpw
Pjwvc3Bhbj48L3A+DQo8cCBjbGFzcz0iTXNvTm9ybWFsIiBzdHlsZT0ibXNvLW1hcmdpbi10b3At
YWx0OmF1dG87bXNvLW1hcmdpbi1ib3R0b20tYWx0OmF1dG8iPjxzcGFuIGxhbmc9IkVOLVVTIiBz
dHlsZT0iZm9udC1zaXplOjEwLjBwdDtmb250LWZhbWlseTomcXVvdDtBcmlhbCZxdW90OywmcXVv
dDtzYW5zLXNlcmlmJnF1b3Q7O2NvbG9yOiMxRjQ5N0QiPkkgaGF2ZSBxdWVzdGlvbi48L3NwYW4+
PHNwYW4gbGFuZz0iRU4tVVMiPjxvOnA+PC9vOnA+PC9zcGFuPjwvcD4NCjxwIGNsYXNzPSJNc29O
b3JtYWwiIHN0eWxlPSJtc28tbWFyZ2luLXRvcC1hbHQ6YXV0bzttc28tbWFyZ2luLWJvdHRvbS1h
bHQ6YXV0byI+PHNwYW4gbGFuZz0iRU4tVVMiIHN0eWxlPSJmb250LXNpemU6MTAuMHB0O2ZvbnQt
ZmFtaWx5OiZxdW90O0FyaWFsJnF1b3Q7LCZxdW90O3NhbnMtc2VyaWYmcXVvdDs7Y29sb3I6IzFG
NDk3RCI+Jm5ic3A7PC9zcGFuPjxzcGFuIGxhbmc9IkVOLVVTIj48bzpwPjwvbzpwPjwvc3Bhbj48
L3A+DQo8cCBjbGFzcz0iTXNvTm9ybWFsIiBzdHlsZT0ibXNvLW1hcmdpbi10b3AtYWx0OmF1dG87
bXNvLW1hcmdpbi1ib3R0b20tYWx0OmF1dG8iPjxzcGFuIGxhbmc9IkVOLVVTIiBzdHlsZT0iZm9u
dC1zaXplOjEwLjBwdDtmb250LWZhbWlseTomcXVvdDtBcmlhbCZxdW90OywmcXVvdDtzYW5zLXNl
cmlmJnF1b3Q7O2NvbG9yOiMxRjQ5N0QiPkluIHcvSEFSVCwgYXJlIGFsbCBiZWFjb24gZnJhbWVz
IGF1dGhlbnRpY2F0ZWQgd2l0aCBhIHdlbGwta25vd24ga2V5IGV2ZW4gYWZ0ZXIgYSBqb2luaW5n
DQogbm9kZSBvYnRhaW5lZCB0aGUgcnVudGltZSBsaW5rIGxheWVyIGtleT8mbmJzcDsgPC9zcGFu
PjxzcGFuIGxhbmc9IkVOLVVTIj48bzpwPjwvbzpwPjwvc3Bhbj48L3A+DQo8cCBjbGFzcz0iTXNv
Tm9ybWFsIiBzdHlsZT0ibXNvLW1hcmdpbi10b3AtYWx0OmF1dG87bXNvLW1hcmdpbi1ib3R0b20t
YWx0OmF1dG8iPjxzcGFuIGxhbmc9IkVOLVVTIiBzdHlsZT0iZm9udC1zaXplOjEwLjBwdDtmb250
LWZhbWlseTomcXVvdDtBcmlhbCZxdW90OywmcXVvdDtzYW5zLXNlcmlmJnF1b3Q7O2NvbG9yOiMx
RjQ5N0QiPiZuYnNwOzwvc3Bhbj48c3BhbiBsYW5nPSJFTi1VUyI+PG86cD48L286cD48L3NwYW4+
PC9wPg0KPHAgY2xhc3M9Ik1zb05vcm1hbCIgc3R5bGU9Im1zby1tYXJnaW4tdG9wLWFsdDphdXRv
O21zby1tYXJnaW4tYm90dG9tLWFsdDphdXRvIj48c3BhbiBsYW5nPSJFTi1VUyIgc3R5bGU9ImZv
bnQtc2l6ZToxMC4wcHQ7Zm9udC1mYW1pbHk6JnF1b3Q7QXJpYWwmcXVvdDssJnF1b3Q7c2Fucy1z
ZXJpZiZxdW90Oztjb2xvcjojMUY0OTdEIj5SZWdhcmRzLDwvc3Bhbj48c3BhbiBsYW5nPSJFTi1V
UyI+PG86cD48L286cD48L3NwYW4+PC9wPg0KPHAgY2xhc3M9Ik1zb05vcm1hbCIgc3R5bGU9Im1z
by1tYXJnaW4tdG9wLWFsdDphdXRvO21zby1tYXJnaW4tYm90dG9tLWFsdDphdXRvIj48c3BhbiBs
YW5nPSJFTi1VUyIgc3R5bGU9ImZvbnQtc2l6ZToxMC4wcHQ7Zm9udC1mYW1pbHk6JnF1b3Q7QXJp
YWwmcXVvdDssJnF1b3Q7c2Fucy1zZXJpZiZxdW90Oztjb2xvcjojMUY0OTdEIj5Zb3NoaWhpcm8g
T2hiYTwvc3Bhbj48c3BhbiBsYW5nPSJFTi1VUyI+PG86cD48L286cD48L3NwYW4+PC9wPg0KPHAg
Y2xhc3M9Ik1zb05vcm1hbCIgc3R5bGU9Im1zby1tYXJnaW4tdG9wLWFsdDphdXRvO21zby1tYXJn
aW4tYm90dG9tLWFsdDphdXRvIj48c3BhbiBsYW5nPSJFTi1VUyIgc3R5bGU9ImZvbnQtc2l6ZTox
MC4wcHQ7Zm9udC1mYW1pbHk6JnF1b3Q7QXJpYWwmcXVvdDssJnF1b3Q7c2Fucy1zZXJpZiZxdW90
Oztjb2xvcjojMUY0OTdEIj4mbmJzcDs8L3NwYW4+PHNwYW4gbGFuZz0iRU4tVVMiPjxvOnA+PC9v
OnA+PC9zcGFuPjwvcD4NCjxwIGNsYXNzPSJNc29Ob3JtYWwiIHN0eWxlPSJtc28tbWFyZ2luLXRv
cC1hbHQ6YXV0bzttc28tbWFyZ2luLWJvdHRvbS1hbHQ6YXV0byI+PHNwYW4gbGFuZz0iRU4tVVMi
IHN0eWxlPSJmb250LXNpemU6MTAuMHB0O2ZvbnQtZmFtaWx5OiZxdW90O0FyaWFsJnF1b3Q7LCZx
dW90O3NhbnMtc2VyaWYmcXVvdDs7Y29sb3I6IzFGNDk3RCI+Jm5ic3A7PC9zcGFuPjxzcGFuIGxh
bmc9IkVOLVVTIj48bzpwPjwvbzpwPjwvc3Bhbj48L3A+DQo8cCBjbGFzcz0iTXNvTm9ybWFsIiBz
dHlsZT0ibXNvLW1hcmdpbi10b3AtYWx0OmF1dG87bXNvLW1hcmdpbi1ib3R0b20tYWx0OmF1dG8i
PjxzcGFuIGxhbmc9IkVOLVVTIiBzdHlsZT0iZm9udC1zaXplOjEwLjBwdDtmb250LWZhbWlseTom
cXVvdDtBcmlhbCZxdW90OywmcXVvdDtzYW5zLXNlcmlmJnF1b3Q7O2NvbG9yOiMxRjQ5N0QiPiZu
YnNwOzwvc3Bhbj48c3BhbiBsYW5nPSJFTi1VUyI+PG86cD48L286cD48L3NwYW4+PC9wPg0KPHAg
Y2xhc3M9Ik1zb05vcm1hbCIgc3R5bGU9Im1zby1tYXJnaW4tdG9wLWFsdDphdXRvO21zby1tYXJn
aW4tYm90dG9tLWFsdDphdXRvIj48c3BhbiBsYW5nPSJFTi1VUyIgc3R5bGU9ImZvbnQtc2l6ZTox
MC4wcHQ7Zm9udC1mYW1pbHk6JnF1b3Q7QXJpYWwmcXVvdDssJnF1b3Q7c2Fucy1zZXJpZiZxdW90
Oztjb2xvcjojMUY0OTdEIj4mbmJzcDs8L3NwYW4+PHNwYW4gbGFuZz0iRU4tVVMiPjxvOnA+PC9v
OnA+PC9zcGFuPjwvcD4NCjxwIGNsYXNzPSJNc29Ob3JtYWwiIHN0eWxlPSJtc28tbWFyZ2luLXRv
cC1hbHQ6YXV0bzttc28tbWFyZ2luLWJvdHRvbS1hbHQ6YXV0byI+PGI+PHNwYW4gbGFuZz0iRU4t
VVMiIHN0eWxlPSJmb250LXNpemU6MTEuMHB0O2ZvbnQtZmFtaWx5OiZxdW90O0NhbGlicmkmcXVv
dDssJnF1b3Q7c2Fucy1zZXJpZiZxdW90OyI+RnJvbTo8L3NwYW4+PC9iPjxzcGFuIGxhbmc9IkVO
LVVTIiBzdHlsZT0iZm9udC1zaXplOjExLjBwdDtmb250LWZhbWlseTomcXVvdDtDYWxpYnJpJnF1
b3Q7LCZxdW90O3NhbnMtc2VyaWYmcXVvdDsiPg0KIDZ0aXNjaC1zZWN1cml0eSBbbWFpbHRvOjxh
IGhyZWY9Im1haWx0bzo2dGlzY2gtc2VjdXJpdHktYm91bmNlc0BpZXRmLm9yZyIgdGFyZ2V0PSJf
YmxhbmsiPjZ0aXNjaC1zZWN1cml0eS1ib3VuY2VzQGlldGYub3JnPC9hPl0NCjxiPk9uIEJlaGFs
ZiBPZiA8L2I+Sm9uYXRoYW4gU2ltb248YnI+DQo8Yj5TZW50OjwvYj4gVHVlc2RheSwgTWF5IDI3
LCAyMDE0IDEwOjQxIFBNPGJyPg0KPGI+VG86PC9iPiBSZW5lIFN0cnVpazxicj4NCjxiPkNjOjwv
Yj4gTWljaGFlbCBSaWNoYXJkc29uOyA8YSBocmVmPSJtYWlsdG86NnRpc2NoLXNlY3VyaXR5QGll
dGYub3JnIiB0YXJnZXQ9Il9ibGFuayI+DQo2dGlzY2gtc2VjdXJpdHlAaWV0Zi5vcmc8L2E+PGJy
Pg0KPGI+U3ViamVjdDo8L2I+IFJlOiBbNnRpc2NoLXNlY3VyaXR5XSBhZ2VuZGEgZm9yIDIwMTQt
MDUtMjcgNnRpc2NoIHNlY3VyaXR5IGNhbGw8L3NwYW4+PHNwYW4gbGFuZz0iRU4tVVMiPjxvOnA+
PC9vOnA+PC9zcGFuPjwvcD4NCjxwIGNsYXNzPSJNc29Ob3JtYWwiIHN0eWxlPSJtc28tbWFyZ2lu
LXRvcC1hbHQ6YXV0bzttc28tbWFyZ2luLWJvdHRvbS1hbHQ6YXV0byI+PHNwYW4gbGFuZz0iRU4t
VVMiPiZuYnNwOzxvOnA+PC9vOnA+PC9zcGFuPjwvcD4NCjxkaXY+DQo8ZGl2Pg0KPGRpdj4NCjxw
IGNsYXNzPSJNc29Ob3JtYWwiIHN0eWxlPSJtc28tbWFyZ2luLXRvcC1hbHQ6YXV0bzttYXJnaW4t
Ym90dG9tOjEyLjBwdCI+PHNwYW4gbGFuZz0iRU4tVVMiPlJlbmUgaGFkIGFza2VkIG9uIGEgcHJl
dmlvdXMgY2FsbCBmb3Igc29tZW9uZSB0byBzdW1tYXJpemUgV2lyZWxlc3NIQVJUIGpvaW5pbmcg
LSBoZXJlIHlvdSBnby48YnI+DQo8YnI+DQoqIE9uZSBvciBtb3JlIGRldmljZXMgYXJlIHNlbmRp
bmcgYmVhY29ucyB0byBhZHZlcnRpc2UgdGhlIHByZXNlbmNlIG9mIHRoZSBuZXR3b3JrLiBJbiBX
aXJlbGVzc0hBUlQsIHRoaXMgZnJhbWUgaXMgdW5lbmNyeXB0ZWQsIGJ1dCBhdXRoZW50aWNhdGVk
IHdpdGggYSB3ZWxsIGtub3duIGtleS4mbmJzcDsgVGhlIGJlYWNvbiBjb250YWlucyB0aGUgY3Vy
cmVudCBBU04sIHdoaWNoIHRoZSBqb2luaW5nIGRldmljZSB1c2VzIHRvIHN5bmNocm9uaXplIGl0
cyBjbG9jay48bzpwPjwvbzpwPjwvc3Bhbj48L3A+DQo8ZGl2Pg0KPHAgY2xhc3M9Ik1zb05vcm1h
bCIgc3R5bGU9Im1zby1tYXJnaW4tdG9wLWFsdDphdXRvO21hcmdpbi1ib3R0b206MTIuMHB0Ij48
c3BhbiBsYW5nPSJFTi1VUyI+KiBPbmNlIHRoZSBqb2luaW5nIG5vZGUgaGFzIGhlYXJkIGEgYmVh
Y29uLCBpdCBjb250aW51ZXMgbGlzdGVuaW5nIGZvciBhZGRpdGlvbmFsIGJlYWNvbnMgZm9yIGEg
c2hvcnQgc3BlY2lmaWVkIHRpbWVvdXQuPG86cD48L286cD48L3NwYW4+PC9wPg0KPC9kaXY+DQo8
cCBjbGFzcz0iTXNvTm9ybWFsIiBzdHlsZT0ibXNvLW1hcmdpbi10b3AtYWx0OmF1dG87bWFyZ2lu
LWJvdHRvbToxMi4wcHQiPjxzcGFuIGxhbmc9IkVOLVVTIj4qIFRoZSBqb2luaW5nIG5vZGUgZW5j
cnlwdHMgYSBmcmFtZSBjb250YWluaW5nIHNvbWUgSEFSVCBzcGVjaWZpYyBjb250ZW50LCBpbmNs
dWRpbmcgYSBsaXN0IG9mIGJlYWNvbmluZyBuZWlnaGJvcnMgaXQgaGVhcmQgaW4gdGhlIHByZXZp
b3VzIHN0ZXBzLiBUaGUgc2l6ZSBvZiB0aGUgcGF5bG9hZA0KIGlzIH4gNjAgYnl0ZXMuJm5ic3A7
IFRoZSBwYWNrZXQgaXMgcm91dGVkIGJ5IGEgJnF1b3Q7cHJveHkmcXVvdDsgbm9kZSAtIHRoZSBq
b2luaW5nIHBhcmVudC4gVGhlIGZyYW1lIGlzIGF1dGhlbnRpY2F0ZWQgdXNpbmcgdGhlIHdlbGwt
a25vd24ga2V5LCBhbmQgZW5jcnlwdGVkIHVzaW5nIGEgc2hhcmVkIHN5bW1ldHJpYyBrZXkga25v
d24gb25seSBieSB0aGUgbm9kZSBhbmQgdGhlIG1hbmFnZXIuPGJyPg0KPGJyPg0KKiBUaGUgbWFu
YWdlciByZXNwb25kcyB3aXRoIGEgZnJhbWUgY29udGFpbmluZyB0aGUgcnVuLXRpbWUgbGluay1s
YXllciBrZXksIHRoZSBub2RlJ3MgbmV3IHNob3J0IGFkZHJlc3MgKHRoaXMgdGFrZXMgdGhlIHBs
YWNlIG9mIFBBTiBjb29yZGluYXRvciBhc3NvY2lhdGlvbiksIGFuZCBhIHVuaWNhc3Qgc2Vzc2lv
biBrZXkgYW5kIHN0YXJ0aW5nIG5vbmNlIGZvciB0aGUgbWFuYWdlci4gVGhpcyBmcmFtZSBpcyBl
bmNyeXB0ZWQgd2l0aCB0aGUgc3ltbWV0cmljDQoga2V5LiBUaGUgcGF5bG9hZCBpcyB+IDYwIGJ5
dGVzLCBhbmQgaXMgcm91dGVkIHRvIHRoZSBwcm94eSBmb3IgZGVsaXZlcnkgdG8gdGhlIGpvaW5p
bmcgbm9kZSAtIHRoZSBwcm94eSB1c2VzIHRoZSBsaW5rLWxheWVyIHdlbGwga25vd24ga2V5IG9u
IHRoZSBmcmFtZS48bzpwPjwvbzpwPjwvc3Bhbj48L3A+DQo8ZGl2Pg0KPHAgY2xhc3M9Ik1zb05v
cm1hbCIgc3R5bGU9Im1zby1tYXJnaW4tdG9wLWFsdDphdXRvO21hcmdpbi1ib3R0b206MTIuMHB0
Ij48c3BhbiBsYW5nPSJFTi1VUyI+KiBBdCB0aGlzIHBvaW50IHRoZSBqb2luaW5nIG5vZGUgdHJh
bnNpdGlvbnMgdG8gdXNpbmcgdGhlIHJ1bi10aW1lIGxpbmstbGF5ZXIga2V5IGZvciBhbGwgbGlu
ay1sYXllciBmcmFtZXMsIGFuZCB0aGUgbWFuYWdlciB1bmljYXN0IHNlc3Npb24gZm9yIGVuZC10
by1lbmQgbWFuYWdlcg0KIHRyYWZmaWMuIFRoaXMgZW5kcyB0aGUgaW5pdGlhbCBzZWN1cml0eSBo
YW5kc2hha2UuPG86cD48L286cD48L3NwYW4+PC9wPg0KPC9kaXY+DQo8ZGl2Pg0KPHAgY2xhc3M9
Ik1zb05vcm1hbCIgc3R5bGU9Im1zby1tYXJnaW4tdG9wLWFsdDphdXRvO21hcmdpbi1ib3R0b206
MTIuMHB0Ij48c3BhbiBsYW5nPSJFTi1VUyI+KiBPdmVyIGEgbnVtYmVyIG9mIGFkZGl0aW9uYWwg
ZnJhbWVzLCB0aGUgbWFuYWdlciBhc3NpZ25zIGFkZGl0aW9uYWwgc2Vzc2lvbnMsIGluY2x1ZGlu
ZyBicm9hZGNhc3Qgc2Vzc2lvbnMsIGFuZCBhIHVuaWNhc3Qgc2Vzc2lvbiB0byB0aGUgR2F0ZXdh
eSAoc2luayBmb3IgYWxsIGRhdGENCiB0cmFmZmljKSwgYW5kIGFkZGl0aW9uYWwgY29tbXVuaWNh
dGlvbnMgcmVzb3VyY2VzLCByb3V0aW5nIGluZm9ybWF0aW9uLCBldGMuJm5ic3A7IFRoZXJlIGlz
IG5vIGV4cGxpY2l0IHRyYW5zaXRpb24gZnJvbSBqb2luaW5nIHRvIGpvaW5lZCAtIHRoZSBtb3Rl
IHRyYW5zaXRpb25zIHdoZW4gY2VydGFpbiBrZXkgZnJhbWVzIGFyZSByZWNlaXZlZC48bzpwPjwv
bzpwPjwvc3Bhbj48L3A+DQo8L2Rpdj4NCjxwIGNsYXNzPSJNc29Ob3JtYWwiIHN0eWxlPSJtc28t
bWFyZ2luLXRvcC1hbHQ6YXV0bzttYXJnaW4tYm90dG9tOjEyLjBwdCI+PHNwYW4gbGFuZz0iRU4t
VVMiPiogTm90ZSB0aGF0IGEgV2lyZWxlc3NIQVJUIGxpbmstbGF5ZXIgZnJhbWUgY29udGFpbnMg
YW5kIGFkZGl0aW9uYWwgZnJhbWUgdHlwZSBieXRlIGFuZCBhIDQtYnl0ZSBsaW5rLWxheWVyIE1J
Qywgb24gdG9wIG9mIHRoZSB1bnNlY3VyZWQgMTUuNCBmcmFtZS4mbmJzcDsgQSBuZXR3b3JrIGZy
YW1lDQogY29udGFpbnMgYW4gYWRkaXRpb25hbCAxNi00MCBieXRlcyBvZiBhZGRyZXNzaW5nLCBy
b3V0aW5nLCBzZWN1cml0eSBhbmQgb3RoZXIgaW5mb3JtYXRpb24uPG86cD48L286cD48L3NwYW4+
PC9wPg0KPC9kaXY+DQo8cCBjbGFzcz0iTXNvTm9ybWFsIiBzdHlsZT0ibXNvLW1hcmdpbi10b3At
YWx0OmF1dG87bWFyZ2luLWJvdHRvbToxMi4wcHQiPjxzcGFuIGxhbmc9IkVOLVVTIj5Ib3BlIHRo
aXMgaGVscCE8bzpwPjwvbzpwPjwvc3Bhbj48L3A+DQo8L2Rpdj4NCjxwIGNsYXNzPSJNc29Ob3Jt
YWwiIHN0eWxlPSJtc28tbWFyZ2luLXRvcC1hbHQ6YXV0bzttc28tbWFyZ2luLWJvdHRvbS1hbHQ6
YXV0byI+PHNwYW4gbGFuZz0iRU4tVVMiPkpvbmF0aGFuPG86cD48L286cD48L3NwYW4+PC9wPg0K
PGRpdj4NCjxkaXY+DQo8ZGl2Pg0KPHAgY2xhc3M9Ik1zb05vcm1hbCIgc3R5bGU9Im1zby1tYXJn
aW4tdG9wLWFsdDphdXRvO21zby1tYXJnaW4tYm90dG9tLWFsdDphdXRvIj48c3BhbiBsYW5nPSJF
Ti1VUyI+Jm5ic3A7PG86cD48L286cD48L3NwYW4+PC9wPg0KPC9kaXY+DQo8L2Rpdj4NCjwvZGl2
Pg0KPC9kaXY+DQo8ZGl2Pg0KPHAgY2xhc3M9Ik1zb05vcm1hbCIgc3R5bGU9Im1zby1tYXJnaW4t
dG9wLWFsdDphdXRvO21hcmdpbi1ib3R0b206MTIuMHB0Ij48c3BhbiBsYW5nPSJFTi1VUyI+Jm5i
c3A7PG86cD48L286cD48L3NwYW4+PC9wPg0KPGRpdj4NCjxwIGNsYXNzPSJNc29Ob3JtYWwiIHN0
eWxlPSJtc28tbWFyZ2luLXRvcC1hbHQ6YXV0bzttc28tbWFyZ2luLWJvdHRvbS1hbHQ6YXV0byI+
PHNwYW4gbGFuZz0iRU4tVVMiPk9uIE1vbiwgTWF5IDI2LCAyMDE0IGF0IDg6MDkgUE0sIFJlbmUg
U3RydWlrICZsdDs8YSBocmVmPSJtYWlsdG86cnN0cnVpay5leHRAZ21haWwuY29tIiB0YXJnZXQ9
Il9ibGFuayI+cnN0cnVpay5leHRAZ21haWwuY29tPC9hPiZndDsgd3JvdGU6PG86cD48L286cD48
L3NwYW4+PC9wPg0KPGJsb2NrcXVvdGUgc3R5bGU9ImJvcmRlcjpub25lO2JvcmRlci1sZWZ0OnNv
bGlkICNDQ0NDQ0MgMS4wcHQ7cGFkZGluZzowbW0gMG1tIDBtbSA2LjBwdDttYXJnaW4tbGVmdDo0
LjhwdDttYXJnaW4tdG9wOjUuMHB0O21hcmdpbi1yaWdodDowbW07bWFyZ2luLWJvdHRvbTo1LjBw
dCI+DQo8ZGl2Pg0KPGRpdj4NCjxwIGNsYXNzPSJNc29Ob3JtYWwiIHN0eWxlPSJtc28tbWFyZ2lu
LXRvcC1hbHQ6YXV0bzttc28tbWFyZ2luLWJvdHRvbS1hbHQ6YXV0byI+PHNwYW4gbGFuZz0iRU4t
VVMiPkhpIE1pY2hhZWw6PGJyPg0KPGJyPg0KSSB3b3VsZCBsaWtlIHRvIGRpc2N1c3MgdGhlIG91
dHN0YW5kaW5nIGlzc3VlcyBJIHN1bW1hcml6ZWQgaW4gbXkgZW1haWwgb2YgVHVlIGxhc3Qgd2Vl
aywgTWF5IDIwLCAyMDE0LCA5OjQ1YW0gRURUIChzZWUNCjxhIGhyZWY9Imh0dHA6Ly9jcC5tY2Fm
ZWUuY29tL2QvNWZIQ01VcDQxRVN5TnQ1NU9XdFNqdFBxYndWQmNTeVVlcHZkRUszemhPeUNPcWVq
cnpQUFB6NVhDTjZBQnFNMWhZRXZJdW5kRE94LU5Wc1RKUVhJZmNMWnZDNFRRVFM2ZUxzS0NPLVBQ
WFgzWFVWekJIRlNoamxLZXBWa2ZmR2hCcndxcmhkSTZYWXlNQ1ktZWhvamQ3OUtWSTA1YlZLWTAx
TWpiWDZOZWhEWTA1ekFWa0lqYlEtUHNwamJwcEtjdnhmNXE0clRLWVZNZWRLakJpTmNMalhkTkJj
SW44bHJ4clcwR25QdFUwMnJoaHVoS3IxdkY2eTBRSktqQmlOY0xqWGROQmNJcW5qaDFGN1U4cXE4
N3FOZDQydFFtMlpUT1dvVVFnZWpCaU5jUWdrLVBzcGpiNnkyU0REQ1Q2M3BPX28iIHRhcmdldD0i
X2JsYW5rIj4NCmh0dHA6Ly93d3cuaWV0Zi5vcmcvbWFpbC1hcmNoaXZlL3dlYi82dGlzY2gtc2Vj
dXJpdHkvY3VycmVudC9tc2cwMDA4Ni5odG1sPC9hPikuIFRoaXMgd2FzIGFsc28gb25lIG9mIHRo
ZSBhY3Rpb24gaXRlbXMgYXQgdGhlIGNvbmNsdXNpb24gb2YgbGFzdCB3ZWVrJ3MgNlRpU0NIIHNl
Y3VyaXR5IGNhbGwuPGJyPg0KPGJyPg0KRllJIC0gdGhlIHcvSEFSVCBjb21tdW5pY2F0aW9uIGZs
b3dzIHdlcmUgZGlzY3Vzc2VkIGR1cmluZyB0aGUgNlRpU0NIIHNlY3VyaXR5IGNvbmYgY2FsbCB0
aGUgd2VlayBiZWZvcmUsIG9uIE1vbiBNYXkgMTIsIDIwMTQuIElmIG9uZSB3aXNoZXMgdG8gZ28g
b3ZlciB0aGlzIGFnYWluLCB0aGF0IGlzIGZpbmUsIGJ1dCBJIHdvdWxkIHByZWZlciB1cyBnaXZp
bmcgcHJlZmVyZW5jZSB0byB0YWtpbmcgb24gYWxyZWFkeSBhcnRpY3VsYXRlZCBpc3N1ZXMNCiAo
d2hpY2ggd2VyZSBhc3NpZ25lZCBhcyBob21ld29yayBhc3NpZ25tZW50IHRvIHJlZmxlY3QgdXBv
bikgZmlyc3QgKGkuZS4sIHByaW9yIHRvIGl0ZW0gIzQgb2YgdGhlIHByb3Bvc2VkIGFnZW5kYSku
PGJyPg0KPGJyPg0KQXMgYW5vdGhlciBhZ2VuZGEgcG9pbnQsIEkgd291bGQgbGlrZSB1cyB0byBk
aXNjdXNzIHRoZSBmcmVxdWVuY3kgb2YgZnV0dXJlIGNhbGxzIChhcyBwYXJ0IG9mIEVPQikuPGJy
Pg0KPGJyPg0KQmVzdCByZWdhcmRzLCBSZW5lPGJyPg0KPGJyPg0KPGJyPg0KT24gNS8yNi8yMDE0
IDEwOjQ5IFBNLCBNaWNoYWVsIFJpY2hhcmRzb24gd3JvdGU6PG86cD48L286cD48L3NwYW4+PC9w
Pg0KPC9kaXY+DQo8YmxvY2txdW90ZSBzdHlsZT0ibWFyZ2luLXRvcDo1LjBwdDttYXJnaW4tYm90
dG9tOjUuMHB0Ij4NCjxwcmU+PHNwYW4gbGFuZz0iRU4tVVMiPlRvIHJlbWluZCwgd2UgbW92ZWQg
dGhlIGNhbGwgZnJvbSB0aGUgMjZ0aCB0byB0aGUgMjd0aCBhdCAxMGFtIEVEVC48bzpwPjwvbzpw
Pjwvc3Bhbj48L3ByZT4NCjxwcmU+PHNwYW4gbGFuZz0iRU4tVVMiPlRoYXQncyA5MCBtaW51dGVz
IGZyb20gdGhpcyBlbWFpbC48bzpwPjwvbzpwPjwvc3Bhbj48L3ByZT4NCjxwcmU+PHNwYW4gbGFu
Zz0iRU4tVVMiPiZuYnNwOzxvOnA+PC9vOnA+PC9zcGFuPjwvcHJlPg0KPHByZT48c3BhbiBsYW5n
PSJFTi1VUyI+MSkgbm90ZXdlbGwuPG86cD48L286cD48L3NwYW4+PC9wcmU+DQo8cHJlPjxzcGFu
IGxhbmc9IkVOLVVTIj4yKSBpbnRyb3M8bzpwPjwvbzpwPjwvc3Bhbj48L3ByZT4NCjxwcmU+PHNw
YW4gbGFuZz0iRU4tVVMiPjMpIHJlY2FwIG9mIGRyYWZ0LXBpcm8tPG86cD48L286cD48L3NwYW4+
PC9wcmU+DQo8cHJlPjxzcGFuIGxhbmc9IkVOLVVTIj40KSB3aXJlbGVzc2hhcnQgLXdheSAtLS0g
aG93IGRvZXMgdGhlIGNvbW11bmljYXRpb24gd29yaz88bzpwPjwvbzpwPjwvc3Bhbj48L3ByZT4N
CjxwcmU+PHNwYW4gbGFuZz0iRU4tVVMiPjUpIGhvdyB0byBzdW1tYXJpemUgYWxsIG9mIHRoaXMg
dG8gdGhlIHdvcmtpbmcgZ3JvdXA8bzpwPjwvbzpwPjwvc3Bhbj48L3ByZT4NCjxwcmU+PHNwYW4g
bGFuZz0iRU4tVVMiPjYpIGhvdyB0byBjbG9zZSB0aGlzIHByb2Nlc3MgdXA/PG86cD48L286cD48
L3NwYW4+PC9wcmU+DQo8cHJlPjxzcGFuIGxhbmc9IkVOLVVTIj4mbmJzcDs8bzpwPjwvbzpwPjwv
c3Bhbj48L3ByZT4NCjxwcmU+PHNwYW4gbGFuZz0iRU4tVVMiPi0tIHJlbWVtYmVyIHRoYXQgdGhl
IGNhbGwgaXMgcmVjb3JkZWQsIGFuZCB0aGUgTm90ZVdlbGwgYXBwbGllcy48bzpwPjwvbzpwPjwv
c3Bhbj48L3ByZT4NCjxwcmU+PHNwYW4gbGFuZz0iRU4tVVMiPiZuYnNwOzxvOnA+PC9vOnA+PC9z
cGFuPjwvcHJlPg0KPHByZT48c3BhbiBsYW5nPSJFTi1VUyI+LS0gVGhlIFVSTCB0byBhY2Nlc3Mg
dGhlIHdlYmV4LCB3aGljaCB3aWxsIHdlIHVzZSBmb3IgYXVkaW8gb25seTo8bzpwPjwvbzpwPjwv
c3Bhbj48L3ByZT4NCjxwcmU+PHNwYW4gbGFuZz0iRU4tVVMiPiZuYnNwOyA8YSBocmVmPSJodHRw
Oi8vY3AubWNhZmVlLmNvbS9kLzVmSENOMFN5TnQ1NU9XdFNqdFBxYndWQmNTeVVlcHZkRUszemhP
eUNPcWVqcnpQUFB6NVhDTjZBQnFNMWhZRXZJdW5kRE94LU5Wc1RKUVhJZmNMWnZDNFRRVFM2ZUxz
S0NPLVBQWFgzWFVWekJIRlNoamxLZXBWa2ZmR2hCcndxcmpkSTZYWXlNQ1ktZWhvamQ3OUtWSURl
cVI0SU9RR21ITTBMMy1uT1FHbUh3ek1oOTNvOTNnVVZsZFRRbWpoT2d0dTdlbV9tdklVQ2V2THAx
WldWMHNxZXJMNlQ5T0ZvQ25GWkNVT0NtYkFhSk1KWjBsYlZLWTAxZEVFTDhUZHdMUXpoMHFtVDlP
Rm9DbkZaQ1VPQ21kYkZFd1F6WTRkZDQzSm9DeTFlV2IxdVhWdGNzcTg3OU9Gb0NxOGF2cEtjRkJ6
aDFyalBQcnoxTG1Udzd3MTciIHRhcmdldD0iX2JsYW5rIj5odHRwczovL2Npc2NvLndlYmV4LmNv
bS9jaXNjby9qLnBocD9NVElEPW0yZmUxMzliZjg3NmNlYTNlYzYyNzUwY2Q1ODBiNzkwODwvYT48
bzpwPjwvbzpwPjwvc3Bhbj48L3ByZT4NCjxwcmU+PHNwYW4gbGFuZz0iRU4tVVMiPiZuYnNwOzxv
OnA+PC9vOnA+PC9zcGFuPjwvcHJlPg0KPHByZT48c3BhbiBsYW5nPSJFTi1VUyI+LS0gd2Ugd2ls
bCByZXN1bWUgd2l0aCB0aGUgZXRoZXJwYWQgYXQ6PG86cD48L286cD48L3NwYW4+PC9wcmU+DQo8
cHJlPjxzcGFuIGxhbmc9IkVOLVVTIj4mbmJzcDsmbmJzcDsgPGEgaHJlZj0iaHR0cDovL2NwLm1j
YWZlZS5jb20vZC8yRFJQb3c3MU5KNXlXYWJCUVhJQ1hDUW4xUGFwSjVNc08tcmhzNzZ6QjVkQVFz
Q1Q3RERENmJUZHlkOWFSdzJ6Vmdfb1lLcmZCM1p6T1ZMckZUb3VwdldfYzlMRkxJY3R1VnRkQlpE
RFRTN1ROUDdibmpJeUNIc3NQT0V1dmt6YVQwUVNPcm9kVFY1eGRWWXN5TUNxZWp0UG8wZlZBX3lK
RzdqSGstRGktckwwMGt6aFB1WlltTzVwX2dMYlZLQlR6aE9uc0RhQnlwdURTcnphcG9TVmVsYjRP
WmZJVDZrT05zeGxLNUxFMkZ2ZFR3MDlKNTVWNlZJNS1BcTgzaVNWZWxiNE9aZklUNmtPTkZ0ZDQ2
QXZ3eEZFd3RINFFnOVRob2JUdmJGenpoMFZlbGI0UGgxalhkTkJjSXE4YnF1dXJzb2RKaVp2cG1L
Nkd3WSIgdGFyZ2V0PSJfYmxhbmsiPmh0dHA6Ly9ldGhlcnBhZC50b29scy5pZXRmLm9yZzo5MDAw
L3Avbm90ZXMtaWV0Zi04OS02dGlzY2gtc2VjdXJpdHk8L2E+PG86cD48L286cD48L3NwYW4+PC9w
cmU+DQo8cHJlPjxzcGFuIGxhbmc9IkVOLVVTIj4mbmJzcDs8bzpwPjwvbzpwPjwvc3Bhbj48L3By
ZT4NCjxwcmU+PHNwYW4gbGFuZz0iRU4tVVMiPkknbSBhdCA8YSBocmVmPSJ0ZWw6JTJCMSUyMDYx
MyUyMDI3Ni02ODA5IiB0YXJnZXQ9Il9ibGFuayI+JiM0MzsxIDYxMyAyNzYtNjgwOTwvYT4sIElN
OiA8YSBocmVmPSJtYWlsdG86bWNyQHhtcHAuY3JlZGlsLm9yZyIgdGFyZ2V0PSJfYmxhbmsiPm1j
ckB4bXBwLmNyZWRpbC5vcmc8L2E+IG9yIDxhIGhyZWY9Im1haWx0bzptY2hhcmxlc3JAZ21haWwu
Y29tIiB0YXJnZXQ9Il9ibGFuayI+bWNoYXJsZXNyQGdtYWlsLmNvbTwvYT4sPG86cD48L286cD48
L3NwYW4+PC9wcmU+DQo8cHJlPjxzcGFuIGxhbmc9IkVOLVVTIj5pZiB5b3UgbmVlZCBtb3JlIHRo
YW4gdGhhdCB0byBnZXQgaW4sIG9yIGFyZSBoYXZpbmcgZGlmZmljdWx0aWVzLjxvOnA+PC9vOnA+
PC9zcGFuPjwvcHJlPg0KPHByZT48c3BhbiBsYW5nPSJFTi1VUyI+UGxlYXNlIG1ha2Ugc3VyZSB5
b3VyIGF1ZGlvIHdvcmtzLCBhbmQgdGhhdCB5b3UgbXV0ZSB3aGVuIG5vdCB0YWxraW5nLjxvOnA+
PC9vOnA+PC9zcGFuPjwvcHJlPg0KPHByZT48c3BhbiBsYW5nPSJFTi1VUyI+Jm5ic3A7PG86cD48
L286cD48L3NwYW4+PC9wcmU+DQo8cHJlPjxzcGFuIGxhbmc9IkVOLVVTIj4tLTxvOnA+PC9vOnA+
PC9zcGFuPjwvcHJlPg0KPHByZT48c3BhbiBsYW5nPSJFTi1VUyI+TWljaGFlbCBSaWNoYXJkc29u
IDxhIGhyZWY9Im1haWx0bzptY3ImIzQzO0lFVEZAc2FuZGVsbWFuLmNhIiB0YXJnZXQ9Il9ibGFu
ayI+Jmx0O21jciYjNDM7SUVURkBzYW5kZWxtYW4uY2EmZ3Q7PC9hPiwgU2FuZGVsbWFuIFNvZnR3
YXJlIFdvcmtzPG86cD48L286cD48L3NwYW4+PC9wcmU+DQo8cHJlPjxzcGFuIGxhbmc9IkVOLVVT
Ij4gLT0gSVB2NiBJb1QgY29uc3VsdGluZyA9LTxvOnA+PC9vOnA+PC9zcGFuPjwvcHJlPg0KPHBy
ZT48c3BhbiBsYW5nPSJFTi1VUyI+Jm5ic3A7PG86cD48L286cD48L3NwYW4+PC9wcmU+DQo8cHJl
PjxzcGFuIGxhbmc9IkVOLVVTIj4mbmJzcDs8bzpwPjwvbzpwPjwvc3Bhbj48L3ByZT4NCjxwcmU+
PHNwYW4gbGFuZz0iRU4tVVMiPiZuYnNwOzxvOnA+PC9vOnA+PC9zcGFuPjwvcHJlPg0KPHAgY2xh
c3M9Ik1zb05vcm1hbCIgc3R5bGU9Im1zby1tYXJnaW4tdG9wLWFsdDphdXRvO21hcmdpbi1ib3R0
b206MTIuMHB0Ij48c3BhbiBsYW5nPSJFTi1VUyIgc3R5bGU9ImNvbG9yOiM4ODg4ODgiPiZuYnNw
Ozwvc3Bhbj48c3BhbiBsYW5nPSJFTi1VUyI+PG86cD48L286cD48L3NwYW4+PC9wPg0KPHByZT48
c3BhbiBsYW5nPSJFTi1VUyIgc3R5bGU9ImNvbG9yOiM4ODg4ODgiPl9fX19fX19fX19fX19fX19f
X19fX19fX19fX19fX19fX19fX19fX19fX19fX19fPC9zcGFuPjxzcGFuIGxhbmc9IkVOLVVTIj48
bzpwPjwvbzpwPjwvc3Bhbj48L3ByZT4NCjxwcmU+PHNwYW4gbGFuZz0iRU4tVVMiIHN0eWxlPSJj
b2xvcjojODg4ODg4Ij42dGlzY2gtc2VjdXJpdHkgbWFpbGluZyBsaXN0PC9zcGFuPjxzcGFuIGxh
bmc9IkVOLVVTIj48bzpwPjwvbzpwPjwvc3Bhbj48L3ByZT4NCjxwcmU+PHNwYW4gbGFuZz0iRU4t
VVMiIHN0eWxlPSJjb2xvcjojODg4ODg4Ij48YSBocmVmPSJtYWlsdG86NnRpc2NoLXNlY3VyaXR5
QGlldGYub3JnIiB0YXJnZXQ9Il9ibGFuayI+NnRpc2NoLXNlY3VyaXR5QGlldGYub3JnPC9hPjwv
c3Bhbj48c3BhbiBsYW5nPSJFTi1VUyI+PG86cD48L286cD48L3NwYW4+PC9wcmU+DQo8cHJlPjxz
cGFuIGxhbmc9IkVOLVVTIiBzdHlsZT0iY29sb3I6Izg4ODg4OCI+PGEgaHJlZj0iaHR0cDovL2Nw
Lm1jYWZlZS5jb20vZC8yRFJQb084NlFtYkVFS25qS09yS3JoczdjRkNRbjFQYlZKNU1zcWVra1Nq
aE9yc3V1dXNvTHNTOFFBSG0wYWZCM1p6T1ZJLWtmU2ZiQ1pLRHR4VkJfSFlNQy1DLU1OUlhCUVNu
U3V2dm92djdjc0p0ZU9hcUpOUGZheFZaaWNIczNqcjFKd1R2QW00VEROT2IycEVWZFRkQVZQbUVC
QzVlQllUdTAwVTlHWDMzVmtEYTNKc3NEYUJ5cHVEU3J6YXBvU1ZlbGI0T1pmSVQ2a09Oc3hsSzVM
RTJGdmRUdzA5SjU1VjZWSTUtQXE4M2lTVmVsYjRPWmZJVDZrT05GdGQ0NkF2d3hGRXd0SDRRZzlU
aG9iVHZiRnp6aDBWZWxiNFBoMWpYZE5CY0lxOGJxdXVyc29kTFdidiIgdGFyZ2V0PSJfYmxhbmsi
Pmh0dHBzOi8vd3d3LmlldGYub3JnL21haWxtYW4vbGlzdGluZm8vNnRpc2NoLXNlY3VyaXR5PC9h
Pjwvc3Bhbj48c3BhbiBsYW5nPSJFTi1VUyI+PG86cD48L286cD48L3NwYW4+PC9wcmU+DQo8L2Js
b2NrcXVvdGU+DQo8cCBjbGFzcz0iTXNvTm9ybWFsIiBzdHlsZT0ibXNvLW1hcmdpbi10b3AtYWx0
OmF1dG87bWFyZ2luLWJvdHRvbToxMi4wcHQiPjxzcGFuIGxhbmc9IkVOLVVTIiBzdHlsZT0iY29s
b3I6Izg4ODg4OCI+PGJyPg0KPGJyPg0KPC9zcGFuPjxzcGFuIGxhbmc9IkVOLVVTIj48bzpwPjwv
bzpwPjwvc3Bhbj48L3A+DQo8cHJlPjxzcGFuIGxhbmc9IkVOLVVTIiBzdHlsZT0iY29sb3I6Izg4
ODg4OCI+LS0gPC9zcGFuPjxzcGFuIGxhbmc9IkVOLVVTIj48bzpwPjwvbzpwPjwvc3Bhbj48L3By
ZT4NCjxwcmU+PHNwYW4gbGFuZz0iRU4tVVMiIHN0eWxlPSJjb2xvcjojODg4ODg4Ij5lbWFpbDog
PGEgaHJlZj0ibWFpbHRvOnJzdHJ1aWsuZXh0QGdtYWlsLmNvbSIgdGFyZ2V0PSJfYmxhbmsiPnJz
dHJ1aWsuZXh0QGdtYWlsLmNvbTwvYT4gfCBTa3lwZTogcnN0cnVpazwvc3Bhbj48c3BhbiBsYW5n
PSJFTi1VUyI+PG86cD48L286cD48L3NwYW4+PC9wcmU+DQo8cHJlPjxzcGFuIGxhbmc9IkVOLVVT
IiBzdHlsZT0iY29sb3I6Izg4ODg4OCI+Y2VsbDogPGEgaHJlZj0idGVsOiUyQjElMjAlMjg2NDcl
MjklMjA4NjctNTY1OCIgdGFyZ2V0PSJfYmxhbmsiPiYjNDM7MSAoNjQ3KSA4NjctNTY1ODwvYT4g
fCBVUzogPGEgaHJlZj0idGVsOiUyQjElMjAlMjg0MTUlMjklMjA2OTAtNzM2MyIgdGFyZ2V0PSJf
YmxhbmsiPiYjNDM7MSAoNDE1KSA2OTAtNzM2MzwvYT48L3NwYW4+PHNwYW4gbGFuZz0iRU4tVVMi
PjxvOnA+PC9vOnA+PC9zcGFuPjwvcHJlPg0KPC9kaXY+DQo8cCBjbGFzcz0iTXNvTm9ybWFsIiBz
dHlsZT0ibXNvLW1hcmdpbi10b3AtYWx0OmF1dG87bWFyZ2luLWJvdHRvbToxMi4wcHQiPjxzcGFu
IGxhbmc9IkVOLVVTIj48YnI+DQpfX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19f
X19fX19fX19fXzxicj4NCjZ0aXNjaC1zZWN1cml0eSBtYWlsaW5nIGxpc3Q8YnI+DQo8YSBocmVm
PSJtYWlsdG86NnRpc2NoLXNlY3VyaXR5QGlldGYub3JnIiB0YXJnZXQ9Il9ibGFuayI+NnRpc2No
LXNlY3VyaXR5QGlldGYub3JnPC9hPjxicj4NCjxhIGhyZWY9Imh0dHA6Ly9jcC5tY2FmZWUuY29t
L2QvYXZuZHpnUTkzZ0FyaG9LeXlWdGVYOUtWSjVNc09DcmhzN2NMQ1FuMU5FVmhqcGQ3OUpOVlZW
TnlaUG96aWlKbzBFLWtmU2ZiQ1BWZ19vWUtyU1d0UzdDbi1MUDJyV3JYMzduS25qcHZwVlpaeFpZ
c05PUlFYOEZHVDdjWUc3RFI4T0pNZGRFQ1FqdC1ob2p1djc4STlDekFUc1NqRGRxeW1va1duUHRV
MDN3Q0hJY2ZCaXNFZVJOT3NHbTlCV3ZwS2NGQnpyQVZrSWpiUS1Qc3BqYjVPNW1VbS13YUJZVHUw
MENRa25BckNNbldoRXdkYnJBVmtJamJRLVBzcGpiNkJRUWdxaC0yNkN5MVNJamgwRHQ1d0x0WUtD
ZWQ0M0FWa0lqZDQ1ZklUNmtPTkV3SkZWVkpOd1NlVmhzckxlLUZrZCIgdGFyZ2V0PSJfYmxhbmsi
Pmh0dHA6Ly9jcC5tY2FmZWUuY29tL2QvYXZuZHpnUTkzZ0FyaG9LeXlWdGVYOUtWSjVNc09Dcmhz
N2NMQ1FuMU5FVmhqcGQ3OUpOVlZWTnlaUG96aWlKbzBFLWtmU2ZiQ1BWZ19vWUtyU1d0UzdDbi1M
UDJyV3JYMzduS25qcHZwVlpaeFpZc05PUlFYOEZHVDdjWUc3RFI4T0pNZGRFQ1FqdC1ob2p1djc4
STlDekFUc1NqRGRxeW1va1duUHRVMDN3Q0hJY2ZCaXNFZVJOT3NHbTlCV3ZwS2NGQnpyQVZrSWpi
US1Qc3BqYjVPNW1VbS13YUJZVHUwMENRa25BckNNbldoRXdkYnJBVmtJamJRLVBzcGpiNkJRUWdx
aC0yNkN5MVNJamgwRHQ1d0x0WUtDZWQ0M0FWa0lqZDQ1ZklUNmtPTkV3SkZWVkpOd1NlVmhzckxl
LUZrZDwvYT48bzpwPjwvbzpwPjwvc3Bhbj48L3A+DQo8L2Jsb2NrcXVvdGU+DQo8L2Rpdj4NCjxw
IGNsYXNzPSJNc29Ob3JtYWwiIHN0eWxlPSJtc28tbWFyZ2luLXRvcC1hbHQ6YXV0bzttc28tbWFy
Z2luLWJvdHRvbS1hbHQ6YXV0byI+PHNwYW4gbGFuZz0iRU4tVVMiPjxicj4NCjxiciBjbGVhcj0i
YWxsIj4NCjxicj4NCi0tIDxvOnA+PC9vOnA+PC9zcGFuPjwvcD4NCjxkaXY+DQo8cCBjbGFzcz0i
TXNvTm9ybWFsIiBzdHlsZT0ibXNvLW1hcmdpbi10b3AtYWx0OmF1dG87bXNvLW1hcmdpbi1ib3R0
b20tYWx0OmF1dG8iPjxzcGFuIGxhbmc9IkVOLVVTIiBzdHlsZT0iZm9udC1zaXplOjEzLjVwdDtm
b250LWZhbWlseTomcXVvdDtUaW1lcyBOZXcgUm9tYW4mcXVvdDssJnF1b3Q7c2VyaWYmcXVvdDsi
Pi0tJm5ic3A7PGJyPg0KSm9uYXRoYW4gU2ltb24sIFBoLiBEPGJyPg0KRGlyZWN0b3Igb2YgU3lz
dGVtcyBFbmdpbmVlcmluZzxicj4NCkR1c3QgTmV0d29ya3MgYXQgTGluZWFyIFRlY2hub2xvZ3k8
YnI+DQozMDY5NSBIdW50d29vZCBBdmU8YnI+DQpIYXl3YXJkLCBDQSA5NDU0NC03MDIxPGJyPg0K
PGEgaHJlZj0idGVsOiUyODUxMCUyOSUyMDQwMC0yOTM2IiB0YXJnZXQ9Il9ibGFuayI+KDUxMCkg
NDAwLTI5MzY8L2E+PGJyPg0KPGEgaHJlZj0idGVsOiUyODUxMCUyOSUyMDQ4OS0zNzk5IiB0YXJn
ZXQ9Il9ibGFuayI+KDUxMCkgNDg5LTM3OTk8L2E+IEZBWDxicj4NCjxhIGhyZWY9Im1haWx0bzpq
c2ltb25AbGluZWFyLmNvbSIgdGFyZ2V0PSJfYmxhbmsiPmpzaW1vbkBsaW5lYXIuY29tPC9hPjwv
c3Bhbj48c3BhbiBsYW5nPSJFTi1VUyI+PGJyPg0KPGJyPg0KPC9zcGFuPjxzcGFuIGxhbmc9IkVO
LVVTIiBzdHlsZT0iZm9udC1zaXplOjEzLjVwdDtmb250LWZhbWlseTomcXVvdDtUaW1lcyBOZXcg
Um9tYW4mcXVvdDssJnF1b3Q7c2VyaWYmcXVvdDsiPioqTElORUFSIFRFQ0hOT0xPR1kmbmJzcDtD
T1JQT1JBVElPTioqJm5ic3A7PGJyPg0KKioqKipJbnRlcm5ldCBFbWFpbCBDb25maWRlbnRpYWxp
dHkmbmJzcDtOb3RpY2UqKioqKiZuYnNwOzxicj4NCiZuYnNwO1RoaXMgZS1tYWlsIHRyYW5zbWlz
c2lvbiwgYW5kIGFueSZuYnNwO2RvY3VtZW50cywgZmlsZXMgb3IgcHJldmlvdXMgZS1tYWlsJm5i
c3A7bWVzc2FnZXMgYXR0YWNoZWQgdG8gaXQgbWF5IGNvbnRhaW4mbmJzcDtjb25maWRlbnRpYWwg
aW5mb3JtYXRpb24gdGhhdCBpcyZuYnNwO2xlZ2FsbHkgcHJpdmlsZWdlZC4gSWYgeW91IGFyZSBu
b3QgdGhlJm5ic3A7aW50ZW5kZWQgcmVjaXBpZW50LCBvciBhIHBlcnNvbiZuYnNwO3Jlc3BvbnNp
YmxlIGZvciBkZWxpdmVyaW5nIGl0IHRvIHRoZSZuYnNwO2ludGVuZGVkDQogcmVjaXBpZW50LCB5
b3UgYXJlIGhlcmVieSZuYnNwO25vdGlmaWVkIHRoYXQgYW55IGRpc2Nsb3N1cmUsIGNvcHlpbmcs
Jm5ic3A7ZGlzdHJpYnV0aW9uIG9yIHVzZSBvZiBhbnkgb2YgdGhlJm5ic3A7aW5mb3JtYXRpb24g
Y29udGFpbmVkIGluIG9yIGF0dGFjaGVkJm5ic3A7dG8gdGhpcyB0cmFuc21pc3Npb24gaXMgU1RS
SUNUTFkmbmJzcDtQUk9ISUJJVEVELiBJZiB5b3UgaGF2ZSByZWNlaXZlZCB0aGlzJm5ic3A7dHJh
bnNtaXNzaW9uIGluIGVycm9yLCBwbGVhc2UmbmJzcDtpbW1lZGlhdGVseSBub3RpZnkNCiBtZSBi
eSByZXBseSBlLW1haWwsIG9yIGJ5IHRlbGVwaG9uZSBhdCA8YSBocmVmPSJ0ZWw6JTI4NTEwJTI5
JTIwNDAwLTI5MzYiIHRhcmdldD0iX2JsYW5rIj4NCig1MTApIDQwMC0yOTM2PC9hPiwgYW5kIGRl
c3Ryb3kgdGhlIG9yaWdpbmFsJm5ic3A7dHJhbnNtaXNzaW9uIGFuZCBpdHMgYXR0YWNobWVudHMm
bmJzcDt3aXRob3V0IHJlYWRpbmcgb3Igc2F2aW5nIGluIGFueSZuYnNwO21hbm5lci4gVGhhbmsg
eW91Lg0KPC9zcGFuPjxzcGFuIGxhbmc9IkVOLVVTIj48bzpwPjwvbzpwPjwvc3Bhbj48L3A+DQo8
L2Rpdj4NCjwvZGl2Pg0KPC9kaXY+DQo8L2Rpdj4NCjxwIGNsYXNzPSJNc29Ob3JtYWwiIHN0eWxl
PSJtYXJnaW4tYm90dG9tOjEyLjBwdCI+PHNwYW4gbGFuZz0iRU4tVVMiPjxicj4NCl9fX19fX19f
X19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fPGJyPg0KNnRpc2NoLXNlY3Vy
aXR5IG1haWxpbmcgbGlzdDxicj4NCjxhIGhyZWY9Im1haWx0bzo2dGlzY2gtc2VjdXJpdHlAaWV0
Zi5vcmciPjZ0aXNjaC1zZWN1cml0eUBpZXRmLm9yZzwvYT48YnI+DQo8YSBocmVmPSJodHRwOi8v
Y3AubWNhZmVlLmNvbS9kLzJEUlBvdzc2UW1iRUZMenpoT00tcktyaHM3Y0ZDUW4xUGJWSjVNc3Fl
a2tTamhPcnN1dXVzb0xzUzhRQUhtMGFmQjNaek9WSS1rZlNmYkNUQTdoUFhQYl9uVk5aTkJWeHpI
VGJFekhJWVllcGQ3Yno4WEJIRVNoaGxLTV9PRXV2a3phVDBRU3lyaGRUVjV4ZFZZc3lNQ3FlanRQ
cGVzUkc5cHhqRnZkVHcwZTJxS01NLWw5T3dYbjc5T0ZvQ25GWkNVT0NtZEtqQmlOY0xqWGROQmNJ
bjhscnhyVzBHblB0VTAycm9qaEtVcjF2RjZ5MFFKS2pCaU5jTGpYZE5CY0lxbmpoMUY3VThxcTg3
cU5kNDJ0UW0yWlRPV29VUWdlakJpTmNRZ2stUHNwamI2eTJTRERDVDYzcnRfVTJTVlVsVkIwIiB0
YXJnZXQ9Il9ibGFuayI+aHR0cDovL2NwLm1jYWZlZS5jb20vZC8yRFJQb3c3NlFtYkVGTHp6aE9N
LXJLcmhzN2NGQ1FuMVBiVko1TXNxZWtrU2poT3JzdXV1c29Mc1M4UUFIbTBhZkIzWnpPVkkta2ZT
ZmJDVEE3aFBYUGJfblZOWk5CVnh6SFRiRXpISVlZZXBkN2J6OFhCSEVTaGhsS01fT0V1dmt6YVQw
UVN5cmhkVFY1eGRWWXN5TUNxZWp0UHBlc1JHOXB4akZ2ZFR3MGUycUtNTS1sOU93WG43OU9Gb0Nu
RlpDVU9DbWRLakJpTmNMalhkTkJjSW44bHJ4clcwR25QdFUwMnJvamhLVXIxdkY2eTBRSktqQmlO
Y0xqWGROQmNJcW5qaDFGN1U4cXE4N3FOZDQydFFtMlpUT1dvVVFnZWpCaU5jUWdrLVBzcGpiNnky
U0REQ1Q2M3J0X1UyU1ZVbFZCMDwvYT48bzpwPjwvbzpwPjwvc3Bhbj48L3A+DQo8L2Jsb2NrcXVv
dGU+DQo8L2Rpdj4NCjxwIGNsYXNzPSJNc29Ob3JtYWwiPjxzcGFuIGxhbmc9IkVOLVVTIj48YnI+
DQo8YnIgY2xlYXI9ImFsbCI+DQo8YnI+DQotLSA8bzpwPjwvbzpwPjwvc3Bhbj48L3A+DQo8ZGl2
Pg0KPHAgY2xhc3M9Ik1zb05vcm1hbCI+PHNwYW4gbGFuZz0iRU4tVVMiIHN0eWxlPSJmb250LXNp
emU6MTMuNXB0O2ZvbnQtZmFtaWx5OiZxdW90O1RpbWVzIE5ldyBSb21hbiZxdW90OywmcXVvdDtz
ZXJpZiZxdW90OyI+LS0mbmJzcDs8YnI+DQpKb25hdGhhbiBTaW1vbiwgUGguIEQ8YnI+DQpEaXJl
Y3RvciBvZiBTeXN0ZW1zIEVuZ2luZWVyaW5nPGJyPg0KRHVzdCBOZXR3b3JrcyBhdCBMaW5lYXIg
VGVjaG5vbG9neTxicj4NCjMwNjk1IEh1bnR3b29kIEF2ZTxicj4NCkhheXdhcmQsIENBIDk0NTQ0
LTcwMjE8YnI+DQooNTEwKSA0MDAtMjkzNjxicj4NCig1MTApIDQ4OS0zNzk5IEZBWDxicj4NCjxh
IGhyZWY9Im1haWx0bzpqc2ltb25AbGluZWFyLmNvbSIgdGFyZ2V0PSJfYmxhbmsiPmpzaW1vbkBs
aW5lYXIuY29tPC9hPjwvc3Bhbj48c3BhbiBsYW5nPSJFTi1VUyI+PGJyPg0KPGJyPg0KPC9zcGFu
PjxzcGFuIGxhbmc9IkVOLVVTIiBzdHlsZT0iZm9udC1zaXplOjEzLjVwdDtmb250LWZhbWlseTom
cXVvdDtUaW1lcyBOZXcgUm9tYW4mcXVvdDssJnF1b3Q7c2VyaWYmcXVvdDsiPioqTElORUFSIFRF
Q0hOT0xPR1kmbmJzcDtDT1JQT1JBVElPTioqJm5ic3A7PGJyPg0KKioqKipJbnRlcm5ldCBFbWFp
bCBDb25maWRlbnRpYWxpdHkmbmJzcDtOb3RpY2UqKioqKiZuYnNwOzxicj4NCiZuYnNwO1RoaXMg
ZS1tYWlsIHRyYW5zbWlzc2lvbiwgYW5kIGFueSZuYnNwO2RvY3VtZW50cywgZmlsZXMgb3IgcHJl
dmlvdXMgZS1tYWlsJm5ic3A7bWVzc2FnZXMgYXR0YWNoZWQgdG8gaXQgbWF5IGNvbnRhaW4mbmJz
cDtjb25maWRlbnRpYWwgaW5mb3JtYXRpb24gdGhhdCBpcyZuYnNwO2xlZ2FsbHkgcHJpdmlsZWdl
ZC4gSWYgeW91IGFyZSBub3QgdGhlJm5ic3A7aW50ZW5kZWQgcmVjaXBpZW50LCBvciBhIHBlcnNv
biZuYnNwO3Jlc3BvbnNpYmxlIGZvciBkZWxpdmVyaW5nIGl0IHRvIHRoZSZuYnNwO2ludGVuZGVk
DQogcmVjaXBpZW50LCB5b3UgYXJlIGhlcmVieSZuYnNwO25vdGlmaWVkIHRoYXQgYW55IGRpc2Ns
b3N1cmUsIGNvcHlpbmcsJm5ic3A7ZGlzdHJpYnV0aW9uIG9yIHVzZSBvZiBhbnkgb2YgdGhlJm5i
c3A7aW5mb3JtYXRpb24gY29udGFpbmVkIGluIG9yIGF0dGFjaGVkJm5ic3A7dG8gdGhpcyB0cmFu
c21pc3Npb24gaXMgU1RSSUNUTFkmbmJzcDtQUk9ISUJJVEVELiBJZiB5b3UgaGF2ZSByZWNlaXZl
ZCB0aGlzJm5ic3A7dHJhbnNtaXNzaW9uIGluIGVycm9yLCBwbGVhc2UmbmJzcDtpbW1lZGlhdGVs
eSBub3RpZnkNCiBtZSBieSByZXBseSBlLW1haWwsIG9yIGJ5IHRlbGVwaG9uZSBhdCAoNTEwKSA0
MDAtMjkzNiwgYW5kIGRlc3Ryb3kgdGhlIG9yaWdpbmFsJm5ic3A7dHJhbnNtaXNzaW9uIGFuZCBp
dHMgYXR0YWNobWVudHMmbmJzcDt3aXRob3V0IHJlYWRpbmcgb3Igc2F2aW5nIGluIGFueSZuYnNw
O21hbm5lci4gVGhhbmsgeW91Lg0KPC9zcGFuPjxzcGFuIGxhbmc9IkVOLVVTIj48bzpwPjwvbzpw
Pjwvc3Bhbj48L3A+DQo8L2Rpdj4NCjwvZGl2Pg0KPC9kaXY+DQo8L2JvZHk+DQo8L2h0bWw+DQo=

--_000_674F70E5F2BE564CB06B6901FD3DD78B2723B85ATGXML210toshiba_--


From nobody Wed May 28 08:45:02 2014
Return-Path: <mcr@sandelman.ca>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 8EDE61A0491 for <6tisch-security@ietfa.amsl.com>; Wed, 28 May 2014 08:45:00 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.542
X-Spam-Level: 
X-Spam-Status: No, score=-2.542 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RP_MATCHES_RCVD=-0.651, SPF_PASS=-0.001, T_TVD_MIME_NO_HEADERS=0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id mpXNu0BX0VTr for <6tisch-security@ietfa.amsl.com>; Wed, 28 May 2014 08:44:59 -0700 (PDT)
Received: from tuna.sandelman.ca (tuna.sandelman.ca [IPv6:2607:f0b0:f:3::184]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 607A11A0426 for <6tisch-security@ietf.org>; Wed, 28 May 2014 08:44:59 -0700 (PDT)
Received: from sandelman.ca (desk.marajade.sandelman.ca [209.87.252.247]) by tuna.sandelman.ca (Postfix) with ESMTP id 8B4C420028; Wed, 28 May 2014 11:47:42 -0400 (EDT)
Received: by sandelman.ca (Postfix, from userid 179) id 6733363B0E; Wed, 28 May 2014 11:44:55 -0400 (EDT)
Received: from sandelman.ca (localhost [127.0.0.1]) by sandelman.ca (Postfix) with ESMTP id 4F4DA63B09; Wed, 28 May 2014 11:44:55 -0400 (EDT)
From: Michael Richardson <mcr+ietf@sandelman.ca>
To: yoshihiro.ohba@toshiba.co.jp
In-Reply-To: <674F70E5F2BE564CB06B6901FD3DD78B2723B85A@TGXML210.toshiba.local>
References: <E045AECD98228444A58C61C200AE1BD8416F3AF4@xmb-rcd-x01.cisco.com> <531DD632.2060009@cox.net> <531DDB20.5050600@gmail.com> <10925.1394631496@sandelman.ca> <532069C8.2050005@gmail.com> <23590.1394999032@sandelman.ca> <18106.1395625035@sandelman.ca> <19609.1396839403@sandelman.ca> <11557.1397444260@sandelman.ca> <28192.1398644294@sandelman.ca> <29064.1399255587@sandelman.ca> <19475.1400588783@sandelman.ca> <4903.1401158997@sandelman.ca> <53840205.2070103@gmail.com> <CAJeFcoS3PNFX2obx3uNDJDtH=QvNLmaPhw2R468sNaeqpo8QBQ@mail.gmail.com> <674F70E5F2BE564CB06B6901FD3DD78B2723B576@TGXML210.toshiba.local> <CAJeFcoQBp1A7pwZHWoesvrjSySW0UZ0k11-s3-MFAozSuR0Yrw@mail.gmail.com> <674F70E5F2BE564CB06B6901FD3DD78B2723B85A@TGXML210.toshiba.local>
X-Mailer: MH-E 8.2; nmh 1.3-dev; GNU Emacs 23.4.1
X-Face: $\n1pF)h^`}$H>Hk{L"x@)JS7<%Az}5RyS@k9X%29-lHB$Ti.V>2bi.~ehC0; <'$9xN5Ub# z!G,p`nR&p7Fz@^UXIn156S8.~^@MJ*mMsD7=QFeq%AL4m<nPbLgmtKK-5dC@#:k
MIME-Version: 1.0
Content-Type: multipart/signed; boundary="=-=-="; micalg=pgp-sha1; protocol="application/pgp-signature"
Date: Wed, 28 May 2014 11:44:55 -0400
Message-ID: <16047.1401291895@sandelman.ca>
Sender: mcr@sandelman.ca
Archived-At: http://mailarchive.ietf.org/arch/msg/6tisch-security/k9VeMjl45eoxfCneZ38TtvxrdAY
Cc: jsimon@linear.com, rstruik.ext@gmail.com, 6tisch-security@ietf.org
Subject: Re: [6tisch-security] agenda for 2014-05-27 6tisch security call
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 28 May 2014 15:45:00 -0000

--=-=-=


Jonathan wrote:
    > A. Yes. In WirelessHART the beacons (called "advertisements" but they serve the
    > same purpose and have similar content) are intended for devices not yet in the
    > network, so they always use the well-known key.  To discover other nodes within
    > the network, they use frames secured with the runtime link-layer key.

    > Jonathan

<yoshihiro.ohba@toshiba.co.jp> wrote:
    > Thank you for your answer.

    > I think this can be an issue if already joined nodes also use the beacons
    > protected with the well-known key for maintaining synchronization and slot
    > allocations, as an attacker can send forged beacons protected with the
    > well-known key.

So, beacons are not also sent using the runtime link-layer key?
I was envisioning that to be the case for 6tisch.



--
Michael Richardson <mcr+IETF@sandelman.ca>, Sandelman Software Works
 -= IPv6 IoT consulting =-




--=-=-=
Content-Type: application/pgp-signature

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iQEVAwUBU4YEd4CLcPvd0N1lAQJF6Qf+ItIYMILwhfUXSoB87oHghH2wbic2ekTr
dvg1Nu8AvWGYw4fYe4p0BHVDhY/i+gzcMCz6EgUHfhsvzWm7bMHBwPdeGM8Sd71J
YKarIKW2hKvEAdKVTIQi6+YmAQm6mxaJejV3cQ+Uo9X6VWzy4gK8iZmszGR3a9b6
SBxQ3zpGp9E51Zr1Dx1lGOpyBQ+qJdSxDAk6r5S3UpwiQBE3SkBts12Vrr8KhnwA
Hulj2Zeeb5E2Nf30vE9Z0c0mkfURa48QCnQH8l8wZ81zWWQGu7Oj4cfAjYrr1bJE
E1Glj4xXET4nSx1zdevyvc+NQFiF5fZtgKAZ0i8ELPY5p5slAX4Uhw==
=ciFz
-----END PGP SIGNATURE-----
--=-=-=--


From nobody Wed May 28 08:45:35 2014
Return-Path: <jsimon@linear.com>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 116461A0426 for <6tisch-security@ietfa.amsl.com>; Wed, 28 May 2014 08:45:23 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.209
X-Spam-Level: 
X-Spam-Status: No, score=-2.209 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HTML_MESSAGE=0.001, HTTPS_HTTP_MISMATCH=1.989, RCVD_IN_DNSWL_MED=-2.3, WEIRD_PORT=0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id lsYXofJBwadq for <6tisch-security@ietfa.amsl.com>; Wed, 28 May 2014 08:45:16 -0700 (PDT)
Received: from p01c11o148.mxlogic.net (p01c11o148.mxlogic.net [208.65.144.71]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id F1BE81A0491 for <6tisch-security@ietf.org>; Wed, 28 May 2014 08:45:13 -0700 (PDT)
Received: from unknown [12.218.215.72] (EHLO smtpauth1.linear.com) by p01c11o148.mxlogic.net(mxl_mta-8.0.0-1) with ESMTP id 68406835.2ab1bf65e940.70974.00-532.201008.p01c11o148.mxlogic.net (envelope-from <jsimon@linear.com>);  Wed, 28 May 2014 09:45:10 -0600 (MDT)
X-MXL-Hash: 538604866bce9602-0b80044389ad95af70b2c1e00fff418ece4b6ba9
Received: from unknown [12.218.215.72] (EHLO smtpauth1.linear.com) by p01c11o148.mxlogic.net(mxl_mta-8.0.0-1) with ESMTP id 08406835.0.70908.00-322.200765.p01c11o148.mxlogic.net (envelope-from <jsimon@linear.com>);  Wed, 28 May 2014 09:45:06 -0600 (MDT)
X-MXL-Hash: 538604824c117a13-a28d054e08609684c0f44a1e0b180e2f92104d46
Received: from jsimonmacmini.engineering.linear.com (unknown [10.70.48.25]) by smtpauth1.linear.com (Postfix) with ESMTPSA id 0A1A374095; Wed, 28 May 2014 08:45:02 -0700 (PDT)
Content-Type: multipart/alternative; boundary="Apple-Mail=_D825E0BB-475F-4275-BF8D-37EBB0DAD774"
Mime-Version: 1.0 (Mac OS X Mail 7.3 \(1878.2\))
From: Jonathan Simon <jsimon@linear.com>
In-Reply-To: <674F70E5F2BE564CB06B6901FD3DD78B2723B85A@TGXML210.toshiba.local>
Date: Wed, 28 May 2014 08:47:12 -0700
Message-Id: <1315B075-A0A5-4008-8CC9-4918F54CBED1@linear.com>
References: <E045AECD98228444A58C61C200AE1BD8416F3AF4@xmb-rcd-x01.cisco.com> <531DD632.2060009@cox.net> <531DDB20.5050600@gmail.com> <10925.1394631496@sandelman.ca> <532069C8.2050005@gmail.com> <23590.1394999032@sandelman.ca> <18106.1395625035@sandelman.ca> <19609.1396839403@sandelman.ca> <11557.1397444260@sandelman.ca> <28192.1398644294@sandelman.ca> <29064.1399255587@sandelman.ca> <19475.1400588783@sandelman.ca> <4903.1401158997@sandelman.ca> <53840205.2070103@gmail.com> <CAJeFcoS3PNFX2obx3uNDJDtH=QvNLmaPhw2R468sNaeqpo8QBQ@mail.gmail.com> <674F70E5F2BE564CB06B6901FD3DD78B2723B576@TGXML210.toshiba.local> <CAJeFcoQBp1A7pwZHWoesvrjSySW0UZ0k11-s3-MFAozSuR0Yrw@mail.gmail.com> <674F70E5F2BE564CB06B6901FD3DD78B2723B85A@TGXML210.toshiba.local>
To: yoshihiro.ohba@toshiba.co.jp
X-Mailer: Apple Mail (2.1878.2)
X-AnalysisOut: [v=2.1 cv=HKVNF+dv c=1 sm=1 tr=0 a=glloKNylpeYNumXQcclYyA==]
X-AnalysisOut: [:117 a=glloKNylpeYNumXQcclYyA==:17 a=9iaqTFGLkfwA:10 a=D2_]
X-AnalysisOut: [GN2MmYMYA:10 a=BLceEmwcHowA:10 a=MqDINYqSAAAA:8 a=YlVTAMxI]
X-AnalysisOut: [AAAA:8 a=48vgC7mUAAAA:8 a=pGLkceISAAAA:8 a=NojvYFcnAAAA:8 ]
X-AnalysisOut: [a=rWPlndbxAAAA:8 a=SyYMxH9GAAAA:8 a=hmoMHVBNAvfwr_aig9sA:9]
X-AnalysisOut: [ a=q1XwhpTjOhBg3YWl:21 a=vpVJyqRcafJSD0Bg:21 a=QEXdDO2ut3Y]
X-AnalysisOut: [A:10 a=19wCD08tTksA:10 a=vsVyj9psLt0A:10 a=wUAfXdCGL-oA:10]
X-AnalysisOut: [ a=G1HyQLfxkfkA:10 a=qVizmW-ZYBIA:10 a=p-HxVa_ds0YA:10 a=x]
X-AnalysisOut: [EeETXzOXN8A:10 a=yRLhjdVT-pYA:10 a=uztyEWA5df8A:10 a=AeFSe]
X-AnalysisOut: [x2-gKoA:10 a=QxAq9r8ObNgA:10 a=ULth79YsAAUA:10 a=xLpt9-x9c]
X-AnalysisOut: [SEA:10 a=lZB815dzVvQA:10 a=MSl-tDqOz04A:10 a=mVM6EhRi2tsA:]
X-AnalysisOut: [10 a=AxI3N9zt8-FzzBT7M1sA:9 a=ml4kTY82G7zcJurg:21 a=X2R_o6]
X-AnalysisOut: [fj01iq23Ln:21 a=HqYEXM9lUC7XZcfi:21 a=_W_S_7VecoQA:10 a=tX]
X-AnalysisOut: [snliwV7b4A:10]
X-Spam: [F=0.5000000000; CM=0.500; MH=0.500(2014052813); S=0.200(2014051901)]
X-MAIL-FROM: <jsimon@linear.com>
X-SOURCE-IP: [12.218.215.72]
Archived-At: http://mailarchive.ietf.org/arch/msg/6tisch-security/UlQdxDeGrEwnIDs0P2-fx_c12eI
Cc: mcr+ietf@sandelman.ca, rstruik.ext@gmail.com, 6tisch-security@ietf.org
Subject: Re: [6tisch-security] agenda for 2014-05-27 6tisch security call
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 28 May 2014 15:45:23 -0000

--Apple-Mail=_D825E0BB-475F-4275-BF8D-37EBB0DAD774
Content-Transfer-Encoding: quoted-printable
Content-Type: text/plain;
	charset=utf-8

Yoshihiro -

I don=E2=80=99t think this is a problem.  Nodes that are in the network =
reject incoming frames secured with the well-known key. The well-known =
key is only used to authenticate beacons, and authenticate join requests =
(which don=E2=80=99t carry synchronization information).  There is a DoS =
vector, in that an attacker can inject joining traffic (destined for the =
network mananager) that will ultimately be discarded, possibly =
preventing other nodes from joining, and increasing the traffic in the =
network.=20

Jonathan Simon, Ph. D
Director of Systems Engineering
Linear Technology, Dust Networks product group
30695 Huntwood Ave
Hayward, CA 94544-7021
(510) 400-2936
(510) 489-3799 FAX
jsimon@linear.com

**LINEAR TECHNOLOGY CORPORATION**=20
*****Internet Email Confidentiality Notice*****=20
 This e-mail transmission, and any documents, files or previous e-mail =
messages attached to it may contain confidential information that is =
legally privileged. If you are not the intended recipient, or a person =
responsible for delivering it to the intended recipient, you are hereby =
notified that any disclosure, copying, distribution or use of any of the =
information contained in or attached to this transmission is STRICTLY =
PROHIBITED. If you have received this transmission in error, please =
immediately notify me by reply e-mail, or by telephone at (510) =
400-2936, and destroy the original transmission and its attachments =
without reading or saving in any manner. Thank you.=20

On May 28, 2014, at 8:01 AM, <yoshihiro.ohba@toshiba.co.jp> =
<yoshihiro.ohba@toshiba.co.jp> wrote:

> Hi Jonathan,
> =20
> Thank you for your answer.
> =20
> I think this can be an issue if already joined nodes also use the =
beacons protected with the well-known key for maintaining =
synchronization and slot allocations, as an attacker can send forged =
beacons protected with the well-known key.
> =20
> Yoshihiro Ohba
> =20
> =20
> From: 6tisch-security [mailto:6tisch-security-bounces@ietf.org] On =
Behalf Of Jonathan Simon
> Sent: Wednesday, May 28, 2014 11:49 PM
> To: ohba yoshihiro(=E5=A4=A7=E5=A0=B4 =E7=BE=A9=E6=B4=8B =
=E2=97=8B=EF=BC=B2=EF=BC=A4=EF=BC=A3=E2=96=A1=EF=BC=AE=EF=BC=B3=EF=BC=AC)
> Cc: Michael Richardson; Rene Struik; 6tisch-security@ietf.org
> Subject: Re: [6tisch-security] agenda for 2014-05-27 6tisch security =
call
> =20
> Yoshihiro -=20
>=20
> Q. In w/HART, are all beacon frames authenticated with a well-known =
key even after a joining node obtained the runtime link layer key?
>=20
> A. Yes. In WirelessHART the beacons (called "advertisements" but they =
serve the same purpose and have similar content) are intended for =
devices not yet in the network, so they always use the well-known key.  =
To discover other nodes within the network, they use frames secured with =
the runtime link-layer key.
>=20
> Jonathan
> =20
>=20
> On Tue, May 27, 2014 at 11:18 PM, <yoshihiro.ohba@toshiba.co.jp> =
wrote:
> Hi Jonathan,
> =20
> Thank you for sending the summary of w/HART joining.
> =20
> I have question.
> =20
> In w/HART, are all beacon frames authenticated with a well-known key =
even after a joining node obtained the runtime link layer key?=20
> =20
> Regards,
> Yoshihiro Ohba
> =20
> =20
> =20
> =20
> From: 6tisch-security [mailto:6tisch-security-bounces@ietf.org] On =
Behalf Of Jonathan Simon
> Sent: Tuesday, May 27, 2014 10:41 PM
> To: Rene Struik
> Cc: Michael Richardson; 6tisch-security@ietf.org
> Subject: Re: [6tisch-security] agenda for 2014-05-27 6tisch security =
call
> =20
> Rene had asked on a previous call for someone to summarize =
WirelessHART joining - here you go.
>=20
> * One or more devices are sending beacons to advertise the presence of =
the network. In WirelessHART, this frame is unencrypted, but =
authenticated with a well known key.  The beacon contains the current =
ASN, which the joining device uses to synchronize its clock.
>=20
> * Once the joining node has heard a beacon, it continues listening for =
additional beacons for a short specified timeout.
>=20
> * The joining node encrypts a frame containing some HART specific =
content, including a list of beaconing neighbors it heard in the =
previous steps. The size of the payload is ~ 60 bytes.  The packet is =
routed by a "proxy" node - the joining parent. The frame is =
authenticated using the well-known key, and encrypted using a shared =
symmetric key known only by the node and the manager.
>=20
> * The manager responds with a frame containing the run-time link-layer =
key, the node's new short address (this takes the place of PAN =
coordinator association), and a unicast session key and starting nonce =
for the manager. This frame is encrypted with the symmetric key. The =
payload is ~ 60 bytes, and is routed to the proxy for delivery to the =
joining node - the proxy uses the link-layer well known key on the =
frame.
>=20
> * At this point the joining node transitions to using the run-time =
link-layer key for all link-layer frames, and the manager unicast =
session for end-to-end manager traffic. This ends the initial security =
handshake.
>=20
> * Over a number of additional frames, the manager assigns additional =
sessions, including broadcast sessions, and a unicast session to the =
Gateway (sink for all data traffic), and additional communications =
resources, routing information, etc.  There is no explicit transition =
from joining to joined - the mote transitions when certain key frames =
are received.
>=20
> * Note that a WirelessHART link-layer frame contains and additional =
frame type byte and a 4-byte link-layer MIC, on top of the unsecured =
15.4 frame.  A network frame contains an additional 16-40 bytes of =
addressing, routing, security and other information.
>=20
> Hope this help!
>=20
> Jonathan
> =20
> =20
>=20
> On Mon, May 26, 2014 at 8:09 PM, Rene Struik <rstruik.ext@gmail.com> =
wrote:
> Hi Michael:
>=20
> I would like to discuss the outstanding issues I summarized in my =
email of Tue last week, May 20, 2014, 9:45am EDT (see =
http://www.ietf.org/mail-archive/web/6tisch-security/current/msg00086.html=
). This was also one of the action items at the conclusion of last =
week's 6TiSCH security call.
>=20
> FYI - the w/HART communication flows were discussed during the 6TiSCH =
security conf call the week before, on Mon May 12, 2014. If one wishes =
to go over this again, that is fine, but I would prefer us giving =
preference to taking on already articulated issues (which were assigned =
as homework assignment to reflect upon) first (i.e., prior to item #4 of =
the proposed agenda).
>=20
> As another agenda point, I would like us to discuss the frequency of =
future calls (as part of EOB).
>=20
> Best regards, Rene
>=20
>=20
> On 5/26/2014 10:49 PM, Michael Richardson wrote:
> To remind, we moved the call from the 26th to the 27th at 10am EDT.
> That's 90 minutes from this email.
> =20
> 1) notewell.
> 2) intros
> 3) recap of draft-piro-
> 4) wirelesshart -way --- how does the communication work?
> 5) how to summarize all of this to the working group
> 6) how to close this process up?
> =20
> -- remember that the call is recorded, and the NoteWell applies.
> =20
> -- The URL to access the webex, which will we use for audio only:
>   =
https://cisco.webex.com/cisco/j.php?MTID=3Dm2fe139bf876cea3ec62750cd580b79=
08
> =20
> -- we will resume with the etherpad at:
>    http://etherpad.tools.ietf.org:9000/p/notes-ietf-89-6tisch-security
> =20
> I'm at +1 613 276-6809, IM: mcr@xmpp.credil.org or =
mcharlesr@gmail.com,
> if you need more than that to get in, or are having difficulties.
> Please make sure your audio works, and that you mute when not talking.
> =20
> --
> Michael Richardson <mcr+IETF@sandelman.ca>, Sandelman Software Works
>  -=3D IPv6 IoT consulting =3D-
> =20
> =20
> =20
> =20
>=20
> _______________________________________________
> 6tisch-security mailing list
> 6tisch-security@ietf.org
> https://www.ietf.org/mailman/listinfo/6tisch-security
>=20
>=20
>=20
> --=20
> email: rstruik.ext@gmail.com | Skype: rstruik
> cell: +1 (647) 867-5658 | US: +1 (415) 690-7363
>=20
> _______________________________________________
> 6tisch-security mailing list
> 6tisch-security@ietf.org
> =
http://cp.mcafee.com/d/avndzgQ93gArhoKyyVteX9KVJ5MsOCrhs7cLCQn1NEVhjpd79JN=
VVVNyZPoziiJo0E-kfSfbCPVg_oYKrSWtS7Cn-LP2rWrX37nKnjpvpVZZxZYsNORQX8FGT7cYG=
7DR8OJMddECQjt-hojuv78I9CzATsSjDdqymokWnPtU03wCHIcfBisEeRNOsGm9BWvpKcFBzrA=
VkIjbQ-Pspjb5O5mUm-waBYTu00CQknArCMnWhEwdbrAVkIjbQ-Pspjb6BQQgqh-26Cy1SIjh0=
Dt5wLtYKCed43AVkIjd45fIT6kONEwJFVVJNwSeVhsrLe-Fkd
>=20
>=20
>=20
>=20
> --
> --=20
> Jonathan Simon, Ph. D
> Director of Systems Engineering
> Dust Networks at Linear Technology
> 30695 Huntwood Ave
> Hayward, CA 94544-7021
> (510) 400-2936
> (510) 489-3799 FAX
> jsimon@linear.com
>=20
> **LINEAR TECHNOLOGY CORPORATION**=20
> *****Internet Email Confidentiality Notice*****=20
>  This e-mail transmission, and any documents, files or previous e-mail =
messages attached to it may contain confidential information that is =
legally privileged. If you are not the intended recipient, or a person =
responsible for delivering it to the intended recipient, you are hereby =
notified that any disclosure, copying, distribution or use of any of the =
information contained in or attached to this transmission is STRICTLY =
PROHIBITED. If you have received this transmission in error, please =
immediately notify me by reply e-mail, or by telephone at (510) =
400-2936, and destroy the original transmission and its attachments =
without reading or saving in any manner. Thank you.
>=20
> _______________________________________________
> 6tisch-security mailing list
> 6tisch-security@ietf.org
> =
http://cp.mcafee.com/d/2DRPow76QmbEFLzzhOM-rKrhs7cFCQn1PbVJ5MsqekkSjhOrsuu=
usoLsS8QAHm0afB3ZzOVI-kfSfbCTA7hPXPb_nVNZNBVxzHTbEzHIYYepd7bz8XBHEShhlKM_O=
EuvkzaT0QSyrhdTV5xdVYsyMCqejtPpesRG9pxjFvdTw0e2qKMM-l9OwXn79OFoCnFZCUOCmdK=
jBiNcLjXdNBcIn8lrxrW0GnPtU02rojhKUr1vF6y0QJKjBiNcLjXdNBcIqnjh1F7U8qq87qNd4=
2tQm2ZTOWoUQgejBiNcQgk-Pspjb6y2SDDCT63rt_U2SVUlVB0
>=20
>=20
>=20
>=20
> --
> --=20
> Jonathan Simon, Ph. D
> Director of Systems Engineering
> Dust Networks at Linear Technology
> 30695 Huntwood Ave
> Hayward, CA 94544-7021
> (510) 400-2936
> (510) 489-3799 FAX
> jsimon@linear.com
>=20
> **LINEAR TECHNOLOGY CORPORATION**=20
> *****Internet Email Confidentiality Notice*****=20
>  This e-mail transmission, and any documents, files or previous e-mail =
messages attached to it may contain confidential information that is =
legally privileged. If you are not the intended recipient, or a person =
responsible for delivering it to the intended recipient, you are hereby =
notified that any disclosure, copying, distribution or use of any of the =
information contained in or attached to this transmission is STRICTLY =
PROHIBITED. If you have received this transmission in error, please =
immediately notify me by reply e-mail, or by telephone at (510) =
400-2936, and destroy the original transmission and its attachments =
without reading or saving in any manner. Thank you.
> _______________________________________________
> 6tisch-security mailing list
> 6tisch-security@ietf.org
> =
http://cp.mcafee.com/d/1jWVIe3zqb5QkTzhOMC-rKrhs7cFCQn1PbVJ5MsqekkSjhOrsuu=
usoLsS8QAHm0afB3ZzOVI-kfSfbCO5JtvupvW_8CzBdBBfHTbECzBdzATC7xNEVVqWtAklrCzB=
7BgY-F6lK1FJ4SyrLOb2rPUV5xcQsCXCOsVHkiP2Di-rL00s4RtxxYGjB1SKejBiNcLjXdNBcI=
rsDaBypuDSrzapoKgGT2TQ1kLCXM04S-qem7T3obZ8Qg6BJOsGm9BWvpKcFBziWq8d8_13jh0X=
m9EwjKyMnK-nj76y1OsGm9Cy2DSrzapoQgmQYYSUMrDrkr2pAaTam


--Apple-Mail=_D825E0BB-475F-4275-BF8D-37EBB0DAD774
Content-Transfer-Encoding: quoted-printable
Content-Type: text/html;
	charset=utf-8

<html><head><meta http-equiv=3D"Content-Type" content=3D"text/html =
charset=3Dutf-8"></head><body style=3D"word-wrap: break-word; =
-webkit-nbsp-mode: space; -webkit-line-break: =
after-white-space;">Yoshihiro -<div><br></div><div>I don=E2=80=99t think =
this is a problem. &nbsp;Nodes that are in the network reject incoming =
frames secured with the well-known key. The well-known key is only used =
to authenticate beacons, and authenticate join requests (which don=E2=80=99=
t carry synchronization information). &nbsp;There is a DoS vector, in =
that an attacker can inject joining traffic (destined for the network =
mananager) that will ultimately be discarded, possibly preventing other =
nodes from joining, and increasing the traffic in the =
network.&nbsp;</div><div><br><div apple-content-edited=3D"true"><span =
class=3D"Apple-style-span" style=3D"border-collapse: separate; color: =
rgb(0, 0, 0); font-family: 'Lucida Grande'; font-style: normal; =
font-variant: normal; font-weight: normal; letter-spacing: normal; =
line-height: normal; orphans: 2; text-align: -webkit-auto; text-indent: =
0px; text-transform: none; white-space: normal; widows: 2; word-spacing: =
0px; -webkit-border-horizontal-spacing: 0px; =
-webkit-border-vertical-spacing: 0px; =
-webkit-text-decorations-in-effect: none; -webkit-text-size-adjust: =
auto; -webkit-text-stroke-width: 0px;  "><span class=3D"Apple-style-span" =
style=3D"border-collapse: separate; color: rgb(0, 0, 0); font-family: =
'Lucida Grande'; font-style: normal; font-variant: normal; font-weight: =
normal; letter-spacing: normal; line-height: normal; orphans: 2; =
text-align: -webkit-auto; text-indent: 0px; text-transform: none; =
white-space: normal; widows: 2; word-spacing: 0px; =
-webkit-border-horizontal-spacing: 0px; -webkit-border-vertical-spacing: =
0px; -webkit-text-decorations-in-effect: none; -webkit-text-size-adjust: =
auto; -webkit-text-stroke-width: 0px;  "><div style=3D"word-wrap: =
break-word; -webkit-nbsp-mode: space; -webkit-line-break: =
after-white-space; "><span class=3D"Apple-style-span" =
style=3D"border-collapse: separate; color: rgb(0, 0, 0); font-family: =
'Lucida Grande'; font-style: normal; font-variant: normal; font-weight: =
normal; letter-spacing: normal; line-height: normal; orphans: 2; =
text-align: -webkit-auto; text-indent: 0px; text-transform: none; =
white-space: normal; widows: 2; word-spacing: 0px; =
-webkit-border-horizontal-spacing: 0px; -webkit-border-vertical-spacing: =
0px; -webkit-text-decorations-in-effect: none; -webkit-text-size-adjust: =
auto; -webkit-text-stroke-width: 0px;  "><div style=3D"word-wrap: =
break-word; -webkit-nbsp-mode: space; -webkit-line-break: =
after-white-space; ">Jonathan Simon, Ph. D<br>Director of Systems =
Engineering<br>Linear Technology, Dust Networks product group<br>30695 =
Huntwood Ave<br>Hayward, CA 94544-7021<br>(510) 400-2936<br>(510) =
489-3799 FAX<br><a =
href=3D"mailto:jsimon@linear.com">jsimon@linear.com</a><br><br>**LINEAR =
TECHNOLOGY&nbsp;CORPORATION**&nbsp;<br>*****Internet Email =
Confidentiality&nbsp;Notice*****&nbsp;<br>&nbsp;This e-mail =
transmission, and any&nbsp;documents, files or previous =
e-mail&nbsp;messages attached to it may contain&nbsp;confidential =
information that is&nbsp;legally privileged. If you are not =
the&nbsp;intended recipient, or a person&nbsp;responsible for delivering =
it to the&nbsp;intended recipient, you are hereby&nbsp;notified that any =
disclosure, copying,&nbsp;distribution or use of any of =
the&nbsp;information contained in or attached&nbsp;to this transmission =
is STRICTLY&nbsp;PROHIBITED. If you have received this&nbsp;transmission =
in error, please&nbsp;immediately notify me by reply e-mail, or by =
telephone at (510) 400-2936, and destroy the original&nbsp;transmission =
and its attachments&nbsp;without reading or saving in any&nbsp;manner. =
Thank you.&nbsp;<br></div></span></div></span></span>
</div>
<br><div><div>On May 28, 2014, at 8:01 AM, &lt;<a =
href=3D"mailto:yoshihiro.ohba@toshiba.co.jp">yoshihiro.ohba@toshiba.co.jp<=
/a>&gt; &lt;<a =
href=3D"mailto:yoshihiro.ohba@toshiba.co.jp">yoshihiro.ohba@toshiba.co.jp<=
/a>&gt; wrote:</div><br class=3D"Apple-interchange-newline"><blockquote =
type=3D"cite"><div lang=3D"JA" link=3D"blue" vlink=3D"purple" =
style=3D"font-family: LucidaGrande; font-size: 14px; font-style: normal; =
font-variant: normal; font-weight: normal; letter-spacing: normal; =
line-height: normal; orphans: auto; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; widows: auto; word-spacing: =
0px; -webkit-text-stroke-width: 0px;"><div class=3D"WordSection1" =
style=3D"page: WordSection1;"><div style=3D"margin: 0mm 0mm 0.0001pt; =
font-size: 12pt; font-family: '=EF=BC=AD=EF=BC=B3 =
=EF=BC=B0=E3=82=B4=E3=82=B7=E3=83=83=E3=82=AF';"><span lang=3D"EN-US" =
style=3D"font-size: 10pt; font-family: Arial, sans-serif; color: rgb(31, =
73, 125);">Hi Jonathan,<o:p></o:p></span></div><div style=3D"margin: 0mm =
0mm 0.0001pt; font-size: 12pt; font-family: '=EF=BC=AD=EF=BC=B3 =
=EF=BC=B0=E3=82=B4=E3=82=B7=E3=83=83=E3=82=AF';"><span lang=3D"EN-US" =
style=3D"font-size: 10pt; font-family: Arial, sans-serif; color: rgb(31, =
73, 125);">&nbsp;</span></div><div style=3D"margin: 0mm 0mm 0.0001pt; =
font-size: 12pt; font-family: '=EF=BC=AD=EF=BC=B3 =
=EF=BC=B0=E3=82=B4=E3=82=B7=E3=83=83=E3=82=AF';"><span lang=3D"EN-US" =
style=3D"font-size: 10pt; font-family: Arial, sans-serif; color: rgb(31, =
73, 125);">Thank you for your answer.<o:p></o:p></span></div><div =
style=3D"margin: 0mm 0mm 0.0001pt; font-size: 12pt; font-family: '=EF=BC=AD=
=EF=BC=B3 =EF=BC=B0=E3=82=B4=E3=82=B7=E3=83=83=E3=82=AF';"><span =
lang=3D"EN-US" style=3D"font-size: 10pt; font-family: Arial, sans-serif; =
color: rgb(31, 73, 125);">&nbsp;</span></div><div style=3D"margin: 0mm =
0mm 0.0001pt; font-size: 12pt; font-family: '=EF=BC=AD=EF=BC=B3 =
=EF=BC=B0=E3=82=B4=E3=82=B7=E3=83=83=E3=82=AF';"><span lang=3D"EN-US" =
style=3D"font-size: 10pt; font-family: Arial, sans-serif; color: rgb(31, =
73, 125);">I think this can be an issue if already joined nodes also use =
the beacons protected with the well-known key for maintaining =
synchronization and slot allocations, as an attacker can send forged =
beacons protected with the well-known key.<o:p></o:p></span></div><div =
style=3D"margin: 0mm 0mm 0.0001pt; font-size: 12pt; font-family: '=EF=BC=AD=
=EF=BC=B3 =EF=BC=B0=E3=82=B4=E3=82=B7=E3=83=83=E3=82=AF';"><span =
lang=3D"EN-US" style=3D"font-size: 10pt; font-family: Arial, sans-serif; =
color: rgb(31, 73, 125);">&nbsp;</span></div><div style=3D"margin: 0mm =
0mm 0.0001pt; font-size: 12pt; font-family: '=EF=BC=AD=EF=BC=B3 =
=EF=BC=B0=E3=82=B4=E3=82=B7=E3=83=83=E3=82=AF';"><span lang=3D"EN-US" =
style=3D"font-size: 10pt; font-family: Arial, sans-serif; color: rgb(31, =
73, 125);">Yoshihiro Ohba<o:p></o:p></span></div><div style=3D"margin: =
0mm 0mm 0.0001pt; font-size: 12pt; font-family: '=EF=BC=AD=EF=BC=B3 =
=EF=BC=B0=E3=82=B4=E3=82=B7=E3=83=83=E3=82=AF';"><span lang=3D"EN-US" =
style=3D"font-size: 10pt; font-family: Arial, sans-serif; color: rgb(31, =
73, 125);">&nbsp;</span></div><div style=3D"margin: 0mm 0mm 0.0001pt; =
font-size: 12pt; font-family: '=EF=BC=AD=EF=BC=B3 =
=EF=BC=B0=E3=82=B4=E3=82=B7=E3=83=83=E3=82=AF';"><span lang=3D"EN-US" =
style=3D"font-size: 10pt; font-family: Arial, sans-serif; color: rgb(31, =
73, 125);">&nbsp;</span></div><div style=3D"margin: 0mm 0mm 0.0001pt; =
font-size: 12pt; font-family: '=EF=BC=AD=EF=BC=B3 =
=EF=BC=B0=E3=82=B4=E3=82=B7=E3=83=83=E3=82=AF';"><b><span lang=3D"EN-US" =
style=3D"font-size: 11pt; font-family: Calibri, =
sans-serif;">From:</span></b><span lang=3D"EN-US" style=3D"font-size: =
11pt; font-family: Calibri, sans-serif;"><span =
class=3D"Apple-converted-space">&nbsp;</span>6tisch-security [<a =
href=3D"mailto:6tisch-security-bounces@ietf.org" style=3D"color: purple; =
text-decoration: =
underline;">mailto:6tisch-security-bounces@ietf.org</a>]<span =
class=3D"Apple-converted-space">&nbsp;</span><b>On Behalf Of<span =
class=3D"Apple-converted-space">&nbsp;</span></b>Jonathan =
Simon<br><b>Sent:</b><span =
class=3D"Apple-converted-space">&nbsp;</span>Wednesday, May 28, 2014 =
11:49 PM<br><b>To:</b><span =
class=3D"Apple-converted-space">&nbsp;</span>ohba yoshihiro(</span><span =
style=3D"font-size: 11pt;">=E5=A4=A7=E5=A0=B4</span><span =
style=3D"font-size: 11pt; font-family: Calibri, =
sans-serif;">&nbsp;</span><span style=3D"font-size: =
11pt;">=E7=BE=A9=E6=B4=8B</span><span lang=3D"EN-US" style=3D"font-size: =
11pt; font-family: Calibri, sans-serif;"><span =
class=3D"Apple-converted-space">&nbsp;</span>=E2=97=8B</span><span =
style=3D"font-size: 11pt;">=EF=BC=B2=EF=BC=A4=EF=BC=A3</span><span =
lang=3D"EN-US" style=3D"font-size: 11pt; font-family: Calibri, =
sans-serif;">=E2=96=A1</span><span style=3D"font-size: =
11pt;">=EF=BC=AE=EF=BC=B3=EF=BC=AC</span><span lang=3D"EN-US" =
style=3D"font-size: 11pt; font-family: Calibri, =
sans-serif;">)<br><b>Cc:</b><span =
class=3D"Apple-converted-space">&nbsp;</span>Michael Richardson; Rene =
Struik;<span class=3D"Apple-converted-space">&nbsp;</span><a =
href=3D"mailto:6tisch-security@ietf.org" style=3D"color: purple; =
text-decoration: =
underline;">6tisch-security@ietf.org</a><br><b>Subject:</b><span =
class=3D"Apple-converted-space">&nbsp;</span>Re: [6tisch-security] =
agenda for 2014-05-27 6tisch security call<o:p></o:p></span></div><div =
style=3D"margin: 0mm 0mm 0.0001pt; font-size: 12pt; font-family: '=EF=BC=AD=
=EF=BC=B3 =EF=BC=B0=E3=82=B4=E3=82=B7=E3=83=83=E3=82=AF';"><span =
lang=3D"EN-US">&nbsp;</span></div><div><div><p class=3D"MsoNormal" =
style=3D"margin: 0mm 0mm 12pt; font-size: 12pt; font-family: '=EF=BC=AD=EF=
=BC=B3 =EF=BC=B0=E3=82=B4=E3=82=B7=E3=83=83=E3=82=AF';"><span =
lang=3D"EN-US">Yoshihiro -<span =
class=3D"Apple-converted-space">&nbsp;</span><br><br>Q.<span =
class=3D"Apple-converted-space">&nbsp;</span></span><span lang=3D"EN-US" =
style=3D"font-size: 10pt; font-family: Arial, sans-serif; color: rgb(31, =
73, 125);">In w/HART, are all beacon frames authenticated with a =
well-known key even after a joining node obtained the runtime link layer =
key?</span><span lang=3D"EN-US"><o:p></o:p></span></p></div><div><p =
class=3D"MsoNormal" style=3D"margin: 0mm 0mm 12pt; font-size: 12pt; =
font-family: '=EF=BC=AD=EF=BC=B3 =EF=BC=B0=E3=82=B4=E3=82=B7=E3=83=83=E3=82=
=AF';"><span lang=3D"EN-US" style=3D"font-size: 10pt; font-family: =
Arial, sans-serif; color: rgb(31, 73, 125);">A. Yes. In WirelessHART the =
beacons (called "advertisements" but they serve the same purpose and =
have similar content) are intended for devices not yet in the network, =
so they always use the well-known key.&nbsp; To discover other nodes =
within the network, they use frames secured with the runtime link-layer =
key.</span><span lang=3D"EN-US"><o:p></o:p></span></p></div><div><div =
style=3D"margin: 0mm 0mm 0.0001pt; font-size: 12pt; font-family: '=EF=BC=AD=
=EF=BC=B3 =EF=BC=B0=E3=82=B4=E3=82=B7=E3=83=83=E3=82=AF';"><span =
lang=3D"EN-US" style=3D"font-size: 10pt; font-family: Arial, sans-serif; =
color: rgb(31, 73, 125);">Jonathan</span><span =
lang=3D"EN-US"><o:p></o:p></span></div></div></div><div><p =
class=3D"MsoNormal" style=3D"margin: 0mm 0mm 12pt; font-size: 12pt; =
font-family: '=EF=BC=AD=EF=BC=B3 =EF=BC=B0=E3=82=B4=E3=82=B7=E3=83=83=E3=82=
=AF';"><span lang=3D"EN-US">&nbsp;</span></p><div><div style=3D"margin: =
0mm 0mm 0.0001pt; font-size: 12pt; font-family: '=EF=BC=AD=EF=BC=B3 =
=EF=BC=B0=E3=82=B4=E3=82=B7=E3=83=83=E3=82=AF';"><span lang=3D"EN-US">On =
Tue, May 27, 2014 at 11:18 PM, &lt;<a =
href=3D"mailto:yoshihiro.ohba@toshiba.co.jp" target=3D"_blank" =
style=3D"color: purple; text-decoration: =
underline;">yoshihiro.ohba@toshiba.co.jp</a>&gt; =
wrote:<o:p></o:p></span></div><blockquote style=3D"border-style: none =
none none solid; border-left-color: rgb(204, 204, 204); =
border-left-width: 1pt; padding: 0mm 0mm 0mm 6pt; margin-left: 4.8pt; =
margin-right: 0mm;"><div><div style=3D"margin: 0mm 0mm 0.0001pt; =
font-size: 12pt; font-family: '=EF=BC=AD=EF=BC=B3 =
=EF=BC=B0=E3=82=B4=E3=82=B7=E3=83=83=E3=82=AF';"><span lang=3D"EN-US" =
style=3D"font-size: 10pt; font-family: Arial, sans-serif; color: rgb(31, =
73, 125);">Hi Jonathan,</span><span =
lang=3D"EN-US"><o:p></o:p></span></div><div style=3D"margin: 0mm 0mm =
0.0001pt; font-size: 12pt; font-family: '=EF=BC=AD=EF=BC=B3 =
=EF=BC=B0=E3=82=B4=E3=82=B7=E3=83=83=E3=82=AF';"><span lang=3D"EN-US" =
style=3D"font-size: 10pt; font-family: Arial, sans-serif; color: rgb(31, =
73, 125);">&nbsp;</span><span lang=3D"EN-US"><o:p></o:p></span></div><div =
style=3D"margin: 0mm 0mm 0.0001pt; font-size: 12pt; font-family: '=EF=BC=AD=
=EF=BC=B3 =EF=BC=B0=E3=82=B4=E3=82=B7=E3=83=83=E3=82=AF';"><span =
lang=3D"EN-US" style=3D"font-size: 10pt; font-family: Arial, sans-serif; =
color: rgb(31, 73, 125);">Thank you for sending the summary of w/HART =
joining.</span><span lang=3D"EN-US"><o:p></o:p></span></div><div =
style=3D"margin: 0mm 0mm 0.0001pt; font-size: 12pt; font-family: '=EF=BC=AD=
=EF=BC=B3 =EF=BC=B0=E3=82=B4=E3=82=B7=E3=83=83=E3=82=AF';"><span =
lang=3D"EN-US" style=3D"font-size: 10pt; font-family: Arial, sans-serif; =
color: rgb(31, 73, 125);">&nbsp;</span><span =
lang=3D"EN-US"><o:p></o:p></span></div><div style=3D"margin: 0mm 0mm =
0.0001pt; font-size: 12pt; font-family: '=EF=BC=AD=EF=BC=B3 =
=EF=BC=B0=E3=82=B4=E3=82=B7=E3=83=83=E3=82=AF';"><span lang=3D"EN-US" =
style=3D"font-size: 10pt; font-family: Arial, sans-serif; color: rgb(31, =
73, 125);">I have question.</span><span =
lang=3D"EN-US"><o:p></o:p></span></div><div style=3D"margin: 0mm 0mm =
0.0001pt; font-size: 12pt; font-family: '=EF=BC=AD=EF=BC=B3 =
=EF=BC=B0=E3=82=B4=E3=82=B7=E3=83=83=E3=82=AF';"><span lang=3D"EN-US" =
style=3D"font-size: 10pt; font-family: Arial, sans-serif; color: rgb(31, =
73, 125);">&nbsp;</span><span lang=3D"EN-US"><o:p></o:p></span></div><div =
style=3D"margin: 0mm 0mm 0.0001pt; font-size: 12pt; font-family: '=EF=BC=AD=
=EF=BC=B3 =EF=BC=B0=E3=82=B4=E3=82=B7=E3=83=83=E3=82=AF';"><span =
lang=3D"EN-US" style=3D"font-size: 10pt; font-family: Arial, sans-serif; =
color: rgb(31, 73, 125);">In w/HART, are all beacon frames authenticated =
with a well-known key even after a joining node obtained the runtime =
link layer key?&nbsp;</span><span =
lang=3D"EN-US"><o:p></o:p></span></div><div style=3D"margin: 0mm 0mm =
0.0001pt; font-size: 12pt; font-family: '=EF=BC=AD=EF=BC=B3 =
=EF=BC=B0=E3=82=B4=E3=82=B7=E3=83=83=E3=82=AF';"><span lang=3D"EN-US" =
style=3D"font-size: 10pt; font-family: Arial, sans-serif; color: rgb(31, =
73, 125);">&nbsp;</span><span lang=3D"EN-US"><o:p></o:p></span></div><div =
style=3D"margin: 0mm 0mm 0.0001pt; font-size: 12pt; font-family: '=EF=BC=AD=
=EF=BC=B3 =EF=BC=B0=E3=82=B4=E3=82=B7=E3=83=83=E3=82=AF';"><span =
lang=3D"EN-US" style=3D"font-size: 10pt; font-family: Arial, sans-serif; =
color: rgb(31, 73, 125);">Regards,</span><span =
lang=3D"EN-US"><o:p></o:p></span></div><div style=3D"margin: 0mm 0mm =
0.0001pt; font-size: 12pt; font-family: '=EF=BC=AD=EF=BC=B3 =
=EF=BC=B0=E3=82=B4=E3=82=B7=E3=83=83=E3=82=AF';"><span lang=3D"EN-US" =
style=3D"font-size: 10pt; font-family: Arial, sans-serif; color: rgb(31, =
73, 125);">Yoshihiro Ohba</span><span =
lang=3D"EN-US"><o:p></o:p></span></div><div style=3D"margin: 0mm 0mm =
0.0001pt; font-size: 12pt; font-family: '=EF=BC=AD=EF=BC=B3 =
=EF=BC=B0=E3=82=B4=E3=82=B7=E3=83=83=E3=82=AF';"><span lang=3D"EN-US" =
style=3D"font-size: 10pt; font-family: Arial, sans-serif; color: rgb(31, =
73, 125);">&nbsp;</span><span lang=3D"EN-US"><o:p></o:p></span></div><div =
style=3D"margin: 0mm 0mm 0.0001pt; font-size: 12pt; font-family: '=EF=BC=AD=
=EF=BC=B3 =EF=BC=B0=E3=82=B4=E3=82=B7=E3=83=83=E3=82=AF';"><span =
lang=3D"EN-US" style=3D"font-size: 10pt; font-family: Arial, sans-serif; =
color: rgb(31, 73, 125);">&nbsp;</span><span =
lang=3D"EN-US"><o:p></o:p></span></div><div style=3D"margin: 0mm 0mm =
0.0001pt; font-size: 12pt; font-family: '=EF=BC=AD=EF=BC=B3 =
=EF=BC=B0=E3=82=B4=E3=82=B7=E3=83=83=E3=82=AF';"><span lang=3D"EN-US" =
style=3D"font-size: 10pt; font-family: Arial, sans-serif; color: rgb(31, =
73, 125);">&nbsp;</span><span lang=3D"EN-US"><o:p></o:p></span></div><div =
style=3D"margin: 0mm 0mm 0.0001pt; font-size: 12pt; font-family: '=EF=BC=AD=
=EF=BC=B3 =EF=BC=B0=E3=82=B4=E3=82=B7=E3=83=83=E3=82=AF';"><span =
lang=3D"EN-US" style=3D"font-size: 10pt; font-family: Arial, sans-serif; =
color: rgb(31, 73, 125);">&nbsp;</span><span =
lang=3D"EN-US"><o:p></o:p></span></div><div style=3D"margin: 0mm 0mm =
0.0001pt; font-size: 12pt; font-family: '=EF=BC=AD=EF=BC=B3 =
=EF=BC=B0=E3=82=B4=E3=82=B7=E3=83=83=E3=82=AF';"><b><span lang=3D"EN-US" =
style=3D"font-size: 11pt; font-family: Calibri, =
sans-serif;">From:</span></b><span lang=3D"EN-US" style=3D"font-size: =
11pt; font-family: Calibri, sans-serif;"><span =
class=3D"Apple-converted-space">&nbsp;</span>6tisch-security [mailto:<a =
href=3D"mailto:6tisch-security-bounces@ietf.org" target=3D"_blank" =
style=3D"color: purple; text-decoration: =
underline;">6tisch-security-bounces@ietf.org</a>]<span =
class=3D"Apple-converted-space">&nbsp;</span><b>On Behalf Of<span =
class=3D"Apple-converted-space">&nbsp;</span></b>Jonathan =
Simon<br><b>Sent:</b><span =
class=3D"Apple-converted-space">&nbsp;</span>Tuesday, May 27, 2014 10:41 =
PM<br><b>To:</b><span class=3D"Apple-converted-space">&nbsp;</span>Rene =
Struik<br><b>Cc:</b><span =
class=3D"Apple-converted-space">&nbsp;</span>Michael Richardson;<span =
class=3D"Apple-converted-space">&nbsp;</span><a =
href=3D"mailto:6tisch-security@ietf.org" target=3D"_blank" style=3D"color:=
 purple; text-decoration: =
underline;">6tisch-security@ietf.org</a><br><b>Subject:</b><span =
class=3D"Apple-converted-space">&nbsp;</span>Re: [6tisch-security] =
agenda for 2014-05-27 6tisch security call</span><span =
lang=3D"EN-US"><o:p></o:p></span></div><div style=3D"margin: 0mm 0mm =
0.0001pt; font-size: 12pt; font-family: '=EF=BC=AD=EF=BC=B3 =
=EF=BC=B0=E3=82=B4=E3=82=B7=E3=83=83=E3=82=AF';"><span =
lang=3D"EN-US">&nbsp;<o:p></o:p></span></div><div><div><div><p =
class=3D"MsoNormal" style=3D"margin: 0mm 0mm 12pt; font-size: 12pt; =
font-family: '=EF=BC=AD=EF=BC=B3 =EF=BC=B0=E3=82=B4=E3=82=B7=E3=83=83=E3=82=
=AF';"><span lang=3D"EN-US">Rene had asked on a previous call for =
someone to summarize WirelessHART joining - here you go.<br><br>* One or =
more devices are sending beacons to advertise the presence of the =
network. In WirelessHART, this frame is unencrypted, but authenticated =
with a well known key.&nbsp; The beacon contains the current ASN, which =
the joining device uses to synchronize its =
clock.<o:p></o:p></span></p><div><p class=3D"MsoNormal" style=3D"margin: =
0mm 0mm 12pt; font-size: 12pt; font-family: '=EF=BC=AD=EF=BC=B3 =
=EF=BC=B0=E3=82=B4=E3=82=B7=E3=83=83=E3=82=AF';"><span lang=3D"EN-US">* =
Once the joining node has heard a beacon, it continues listening for =
additional beacons for a short specified =
timeout.<o:p></o:p></span></p></div><p class=3D"MsoNormal" =
style=3D"margin: 0mm 0mm 12pt; font-size: 12pt; font-family: '=EF=BC=AD=EF=
=BC=B3 =EF=BC=B0=E3=82=B4=E3=82=B7=E3=83=83=E3=82=AF';"><span =
lang=3D"EN-US">* The joining node encrypts a frame containing some HART =
specific content, including a list of beaconing neighbors it heard in =
the previous steps. The size of the payload is ~ 60 bytes.&nbsp; The =
packet is routed by a "proxy" node - the joining parent. The frame is =
authenticated using the well-known key, and encrypted using a shared =
symmetric key known only by the node and the manager.<br><br>* The =
manager responds with a frame containing the run-time link-layer key, =
the node's new short address (this takes the place of PAN coordinator =
association), and a unicast session key and starting nonce for the =
manager. This frame is encrypted with the symmetric key. The payload is =
~ 60 bytes, and is routed to the proxy for delivery to the joining node =
- the proxy uses the link-layer well known key on the =
frame.<o:p></o:p></span></p><div><p class=3D"MsoNormal" style=3D"margin: =
0mm 0mm 12pt; font-size: 12pt; font-family: '=EF=BC=AD=EF=BC=B3 =
=EF=BC=B0=E3=82=B4=E3=82=B7=E3=83=83=E3=82=AF';"><span lang=3D"EN-US">* =
At this point the joining node transitions to using the run-time =
link-layer key for all link-layer frames, and the manager unicast =
session for end-to-end manager traffic. This ends the initial security =
handshake.<o:p></o:p></span></p></div><div><p class=3D"MsoNormal" =
style=3D"margin: 0mm 0mm 12pt; font-size: 12pt; font-family: '=EF=BC=AD=EF=
=BC=B3 =EF=BC=B0=E3=82=B4=E3=82=B7=E3=83=83=E3=82=AF';"><span =
lang=3D"EN-US">* Over a number of additional frames, the manager assigns =
additional sessions, including broadcast sessions, and a unicast session =
to the Gateway (sink for all data traffic), and additional =
communications resources, routing information, etc.&nbsp; There is no =
explicit transition from joining to joined - the mote transitions when =
certain key frames are received.<o:p></o:p></span></p></div><p =
class=3D"MsoNormal" style=3D"margin: 0mm 0mm 12pt; font-size: 12pt; =
font-family: '=EF=BC=AD=EF=BC=B3 =EF=BC=B0=E3=82=B4=E3=82=B7=E3=83=83=E3=82=
=AF';"><span lang=3D"EN-US">* Note that a WirelessHART link-layer frame =
contains and additional frame type byte and a 4-byte link-layer MIC, on =
top of the unsecured 15.4 frame.&nbsp; A network frame contains an =
additional 16-40 bytes of addressing, routing, security and other =
information.<o:p></o:p></span></p></div><p class=3D"MsoNormal" =
style=3D"margin: 0mm 0mm 12pt; font-size: 12pt; font-family: '=EF=BC=AD=EF=
=BC=B3 =EF=BC=B0=E3=82=B4=E3=82=B7=E3=83=83=E3=82=AF';"><span =
lang=3D"EN-US">Hope this help!<o:p></o:p></span></p></div><div =
style=3D"margin: 0mm 0mm 0.0001pt; font-size: 12pt; font-family: '=EF=BC=AD=
=EF=BC=B3 =EF=BC=B0=E3=82=B4=E3=82=B7=E3=83=83=E3=82=AF';"><span =
lang=3D"EN-US">Jonathan<o:p></o:p></span></div><div><div style=3D"margin: =
0mm 0mm 0.0001pt; font-size: 12pt; font-family: '=EF=BC=AD=EF=BC=B3 =
=EF=BC=B0=E3=82=B4=E3=82=B7=E3=83=83=E3=82=AF';"><span =
lang=3D"EN-US">&nbsp;<o:p></o:p></span></div></div></div><div><p =
class=3D"MsoNormal" style=3D"margin: 0mm 0mm 12pt; font-size: 12pt; =
font-family: '=EF=BC=AD=EF=BC=B3 =EF=BC=B0=E3=82=B4=E3=82=B7=E3=83=83=E3=82=
=AF';"><span lang=3D"EN-US">&nbsp;<o:p></o:p></span></p><div><div =
style=3D"margin: 0mm 0mm 0.0001pt; font-size: 12pt; font-family: '=EF=BC=AD=
=EF=BC=B3 =EF=BC=B0=E3=82=B4=E3=82=B7=E3=83=83=E3=82=AF';"><span =
lang=3D"EN-US">On Mon, May 26, 2014 at 8:09 PM, Rene Struik &lt;<a =
href=3D"mailto:rstruik.ext@gmail.com" target=3D"_blank" style=3D"color: =
purple; text-decoration: underline;">rstruik.ext@gmail.com</a>&gt; =
wrote:<o:p></o:p></span></div><blockquote style=3D"border-style: none =
none none solid; border-left-color: rgb(204, 204, 204); =
border-left-width: 1pt; padding: 0mm 0mm 0mm 6pt; margin: 5pt 0mm 5pt =
4.8pt;"><div><div><div style=3D"margin: 0mm 0mm 0.0001pt; font-size: =
12pt; font-family: '=EF=BC=AD=EF=BC=B3 =EF=BC=B0=E3=82=B4=E3=82=B7=E3=83=83=
=E3=82=AF';"><span lang=3D"EN-US">Hi Michael:<br><br>I would like to =
discuss the outstanding issues I summarized in my email of Tue last =
week, May 20, 2014, 9:45am EDT (see<span =
class=3D"Apple-converted-space">&nbsp;</span><a =
href=3D"http://cp.mcafee.com/d/5fHCMUp41ESyNt55OWtSjtPqbwVBcSyUepvdEK3zhOy=
COqejrzPPPz5XCN6ABqM1hYEvIundDOx-NVsTJQXIfcLZvC4TQTS6eLsKCO-PPXX3XUVzBHFSh=
jlKepVkffGhBrwqrhdI6XYyMCY-ehojd79KVI05bVKY01MjbX6NehDY05zAVkIjbQ-PspjbppK=
cvxf5q4rTKYVMedKjBiNcLjXdNBcIn8lrxrW0GnPtU02rhhuhKr1vF6y0QJKjBiNcLjXdNBcIq=
njh1F7U8qq87qNd42tQm2ZTOWoUQgejBiNcQgk-Pspjb6y2SDDCT63pO_o" =
target=3D"_blank" style=3D"color: purple; text-decoration: =
underline;">http://www.ietf.org/mail-archive/web/6tisch-security/current/m=
sg00086.html</a>). This was also one of the action items at the =
conclusion of last week's 6TiSCH security call.<br><br>FYI - the w/HART =
communication flows were discussed during the 6TiSCH security conf call =
the week before, on Mon May 12, 2014. If one wishes to go over this =
again, that is fine, but I would prefer us giving preference to taking =
on already articulated issues (which were assigned as homework =
assignment to reflect upon) first (i.e., prior to item #4 of the =
proposed agenda).<br><br>As another agenda point, I would like us to =
discuss the frequency of future calls (as part of EOB).<br><br>Best =
regards, Rene<br><br><br>On 5/26/2014 10:49 PM, Michael Richardson =
wrote:<o:p></o:p></span></div></div><blockquote style=3D"margin-top: =
5pt; margin-bottom: 5pt;"><pre style=3D"margin: 0mm 0mm 0.0001pt; =
font-size: 12pt; font-family: '=EF=BC=AD=EF=BC=B3 =E3=82=B4=E3=82=B7=E3=83=
=83=E3=82=AF';"><span lang=3D"EN-US">To remind, we moved the call from =
the 26th to the 27th at 10am EDT.<o:p></o:p></span></pre><pre =
style=3D"margin: 0mm 0mm 0.0001pt; font-size: 12pt; font-family: '=EF=BC=AD=
=EF=BC=B3 =E3=82=B4=E3=82=B7=E3=83=83=E3=82=AF';"><span =
lang=3D"EN-US">That's 90 minutes from this =
email.<o:p></o:p></span></pre><pre style=3D"margin: 0mm 0mm 0.0001pt; =
font-size: 12pt; font-family: '=EF=BC=AD=EF=BC=B3 =E3=82=B4=E3=82=B7=E3=83=
=83=E3=82=AF';"><span lang=3D"EN-US">&nbsp;<o:p></o:p></span></pre><pre =
style=3D"margin: 0mm 0mm 0.0001pt; font-size: 12pt; font-family: '=EF=BC=AD=
=EF=BC=B3 =E3=82=B4=E3=82=B7=E3=83=83=E3=82=AF';"><span lang=3D"EN-US">1) =
notewell.<o:p></o:p></span></pre><pre style=3D"margin: 0mm 0mm 0.0001pt; =
font-size: 12pt; font-family: '=EF=BC=AD=EF=BC=B3 =E3=82=B4=E3=82=B7=E3=83=
=83=E3=82=AF';"><span lang=3D"EN-US">2) =
intros<o:p></o:p></span></pre><pre style=3D"margin: 0mm 0mm 0.0001pt; =
font-size: 12pt; font-family: '=EF=BC=AD=EF=BC=B3 =E3=82=B4=E3=82=B7=E3=83=
=83=E3=82=AF';"><span lang=3D"EN-US">3) recap of =
draft-piro-<o:p></o:p></span></pre><pre style=3D"margin: 0mm 0mm =
0.0001pt; font-size: 12pt; font-family: '=EF=BC=AD=EF=BC=B3 =
=E3=82=B4=E3=82=B7=E3=83=83=E3=82=AF';"><span lang=3D"EN-US">4) =
wirelesshart -way --- how does the communication =
work?<o:p></o:p></span></pre><pre style=3D"margin: 0mm 0mm 0.0001pt; =
font-size: 12pt; font-family: '=EF=BC=AD=EF=BC=B3 =E3=82=B4=E3=82=B7=E3=83=
=83=E3=82=AF';"><span lang=3D"EN-US">5) how to summarize all of this to =
the working group<o:p></o:p></span></pre><pre style=3D"margin: 0mm 0mm =
0.0001pt; font-size: 12pt; font-family: '=EF=BC=AD=EF=BC=B3 =
=E3=82=B4=E3=82=B7=E3=83=83=E3=82=AF';"><span lang=3D"EN-US">6) how to =
close this process up?<o:p></o:p></span></pre><pre style=3D"margin: 0mm =
0mm 0.0001pt; font-size: 12pt; font-family: '=EF=BC=AD=EF=BC=B3 =
=E3=82=B4=E3=82=B7=E3=83=83=E3=82=AF';"><span =
lang=3D"EN-US">&nbsp;<o:p></o:p></span></pre><pre style=3D"margin: 0mm =
0mm 0.0001pt; font-size: 12pt; font-family: '=EF=BC=AD=EF=BC=B3 =
=E3=82=B4=E3=82=B7=E3=83=83=E3=82=AF';"><span lang=3D"EN-US">-- remember =
that the call is recorded, and the NoteWell =
applies.<o:p></o:p></span></pre><pre style=3D"margin: 0mm 0mm 0.0001pt; =
font-size: 12pt; font-family: '=EF=BC=AD=EF=BC=B3 =E3=82=B4=E3=82=B7=E3=83=
=83=E3=82=AF';"><span lang=3D"EN-US">&nbsp;<o:p></o:p></span></pre><pre =
style=3D"margin: 0mm 0mm 0.0001pt; font-size: 12pt; font-family: '=EF=BC=AD=
=EF=BC=B3 =E3=82=B4=E3=82=B7=E3=83=83=E3=82=AF';"><span lang=3D"EN-US">-- =
The URL to access the webex, which will we use for audio =
only:<o:p></o:p></span></pre><pre style=3D"margin: 0mm 0mm 0.0001pt; =
font-size: 12pt; font-family: '=EF=BC=AD=EF=BC=B3 =E3=82=B4=E3=82=B7=E3=83=
=83=E3=82=AF';"><span lang=3D"EN-US">&nbsp; <a =
href=3D"http://cp.mcafee.com/d/5fHCN0SyNt55OWtSjtPqbwVBcSyUepvdEK3zhOyCOqe=
jrzPPPz5XCN6ABqM1hYEvIundDOx-NVsTJQXIfcLZvC4TQTS6eLsKCO-PPXX3XUVzBHFShjlKe=
pVkffGhBrwqrjdI6XYyMCY-ehojd79KVIDeqR4IOQGmHM0L3-nOQGmHwzMh93o93gUVldTQmjh=
Ogtu7em_mvIUCevLp1ZWV0sqerL6T9OFoCnFZCUOCmbAaJMJZ0lbVKY01dEEL8TdwLQzh0qmT9=
OFoCnFZCUOCmdbFEwQzY4dd43JoCy1eWb1uXVtcsq879OFoCq8avpKcFBzh1rjPPrz1LmTw7w1=
7" target=3D"_blank" style=3D"color: purple; text-decoration: =
underline;">https://cisco.webex.com/cisco/j.php?MTID=3Dm2fe139bf876cea3ec6=
2750cd580b7908</a><o:p></o:p></span></pre><pre style=3D"margin: 0mm 0mm =
0.0001pt; font-size: 12pt; font-family: '=EF=BC=AD=EF=BC=B3 =
=E3=82=B4=E3=82=B7=E3=83=83=E3=82=AF';"><span =
lang=3D"EN-US">&nbsp;<o:p></o:p></span></pre><pre style=3D"margin: 0mm =
0mm 0.0001pt; font-size: 12pt; font-family: '=EF=BC=AD=EF=BC=B3 =
=E3=82=B4=E3=82=B7=E3=83=83=E3=82=AF';"><span lang=3D"EN-US">-- we will =
resume with the etherpad at:<o:p></o:p></span></pre><pre style=3D"margin: =
0mm 0mm 0.0001pt; font-size: 12pt; font-family: '=EF=BC=AD=EF=BC=B3 =
=E3=82=B4=E3=82=B7=E3=83=83=E3=82=AF';"><span lang=3D"EN-US">&nbsp;&nbsp; =
<a =
href=3D"http://cp.mcafee.com/d/2DRPow71NJ5yWabBQXICXCQn1PapJ5MsO-rhs76zB5d=
AQsCT7DDD6bTdyd9aRw2zVg_oYKrfB3ZzOVLrFToupvW_c9LFLIctuVtdBZDDTS7TNP7bnjIyC=
HssPOEuvkzaT0QSOrodTV5xdVYsyMCqejtPo0fVA_yJG7jHk-Di-rL00kzhPuZYmO5p_gLbVKB=
TzhOnsDaBypuDSrzapoSVelb4OZfIT6kONsxlK5LE2FvdTw09J55V6VI5-Aq83iSVelb4OZfIT=
6kONFtd46AvwxFEwtH4Qg9ThobTvbFzzh0Velb4Ph1jXdNBcIq8bquursodJiZvpmK6GwY" =
target=3D"_blank" style=3D"color: purple; text-decoration: =
underline;">http://etherpad.tools.ietf.org:9000/p/notes-ietf-89-6tisch-sec=
urity</a><o:p></o:p></span></pre><pre style=3D"margin: 0mm 0mm 0.0001pt; =
font-size: 12pt; font-family: '=EF=BC=AD=EF=BC=B3 =E3=82=B4=E3=82=B7=E3=83=
=83=E3=82=AF';"><span lang=3D"EN-US">&nbsp;<o:p></o:p></span></pre><pre =
style=3D"margin: 0mm 0mm 0.0001pt; font-size: 12pt; font-family: '=EF=BC=AD=
=EF=BC=B3 =E3=82=B4=E3=82=B7=E3=83=83=E3=82=AF';"><span lang=3D"EN-US">I'm=
 at <a href=3D"tel:%2B1%20613%20276-6809" target=3D"_blank" =
style=3D"color: purple; text-decoration: underline;">+1 613 =
276-6809</a>, IM: <a href=3D"mailto:mcr@xmpp.credil.org" target=3D"_blank"=
 style=3D"color: purple; text-decoration: =
underline;">mcr@xmpp.credil.org</a> or <a =
href=3D"mailto:mcharlesr@gmail.com" target=3D"_blank" style=3D"color: =
purple; text-decoration: =
underline;">mcharlesr@gmail.com</a>,<o:p></o:p></span></pre><pre =
style=3D"margin: 0mm 0mm 0.0001pt; font-size: 12pt; font-family: '=EF=BC=AD=
=EF=BC=B3 =E3=82=B4=E3=82=B7=E3=83=83=E3=82=AF';"><span lang=3D"EN-US">if =
you need more than that to get in, or are having =
difficulties.<o:p></o:p></span></pre><pre style=3D"margin: 0mm 0mm =
0.0001pt; font-size: 12pt; font-family: '=EF=BC=AD=EF=BC=B3 =
=E3=82=B4=E3=82=B7=E3=83=83=E3=82=AF';"><span lang=3D"EN-US">Please make =
sure your audio works, and that you mute when not =
talking.<o:p></o:p></span></pre><pre style=3D"margin: 0mm 0mm 0.0001pt; =
font-size: 12pt; font-family: '=EF=BC=AD=EF=BC=B3 =E3=82=B4=E3=82=B7=E3=83=
=83=E3=82=AF';"><span lang=3D"EN-US">&nbsp;<o:p></o:p></span></pre><pre =
style=3D"margin: 0mm 0mm 0.0001pt; font-size: 12pt; font-family: '=EF=BC=AD=
=EF=BC=B3 =E3=82=B4=E3=82=B7=E3=83=83=E3=82=AF';"><span =
lang=3D"EN-US">--<o:p></o:p></span></pre><pre style=3D"margin: 0mm 0mm =
0.0001pt; font-size: 12pt; font-family: '=EF=BC=AD=EF=BC=B3 =
=E3=82=B4=E3=82=B7=E3=83=83=E3=82=AF';"><span lang=3D"EN-US">Michael =
Richardson <a href=3D"mailto:mcr+IETF@sandelman.ca" target=3D"_blank" =
style=3D"color: purple; text-decoration: =
underline;">&lt;mcr+IETF@sandelman.ca&gt;</a>, Sandelman Software =
Works<o:p></o:p></span></pre><pre style=3D"margin: 0mm 0mm 0.0001pt; =
font-size: 12pt; font-family: '=EF=BC=AD=EF=BC=B3 =E3=82=B4=E3=82=B7=E3=83=
=83=E3=82=AF';"><span lang=3D"EN-US"> -=3D IPv6 IoT consulting =
=3D-<o:p></o:p></span></pre><pre style=3D"margin: 0mm 0mm 0.0001pt; =
font-size: 12pt; font-family: '=EF=BC=AD=EF=BC=B3 =E3=82=B4=E3=82=B7=E3=83=
=83=E3=82=AF';"><span lang=3D"EN-US">&nbsp;<o:p></o:p></span></pre><pre =
style=3D"margin: 0mm 0mm 0.0001pt; font-size: 12pt; font-family: '=EF=BC=AD=
=EF=BC=B3 =E3=82=B4=E3=82=B7=E3=83=83=E3=82=AF';"><span =
lang=3D"EN-US">&nbsp;<o:p></o:p></span></pre><pre style=3D"margin: 0mm =
0mm 0.0001pt; font-size: 12pt; font-family: '=EF=BC=AD=EF=BC=B3 =
=E3=82=B4=E3=82=B7=E3=83=83=E3=82=AF';"><span =
lang=3D"EN-US">&nbsp;<o:p></o:p></span></pre><p class=3D"MsoNormal" =
style=3D"margin: 0mm 0mm 12pt; font-size: 12pt; font-family: '=EF=BC=AD=EF=
=BC=B3 =EF=BC=B0=E3=82=B4=E3=82=B7=E3=83=83=E3=82=AF';"><span =
lang=3D"EN-US" style=3D"color: rgb(136, 136, 136);">&nbsp;</span><span =
lang=3D"EN-US"><o:p></o:p></span></p><pre style=3D"margin: 0mm 0mm =
0.0001pt; font-size: 12pt; font-family: '=EF=BC=AD=EF=BC=B3 =
=E3=82=B4=E3=82=B7=E3=83=83=E3=82=AF';"><span lang=3D"EN-US" =
style=3D"color: rgb(136, 136, =
136);">_______________________________________________</span><span =
lang=3D"EN-US"><o:p></o:p></span></pre><pre style=3D"margin: 0mm 0mm =
0.0001pt; font-size: 12pt; font-family: '=EF=BC=AD=EF=BC=B3 =
=E3=82=B4=E3=82=B7=E3=83=83=E3=82=AF';"><span lang=3D"EN-US" =
style=3D"color: rgb(136, 136, 136);">6tisch-security mailing =
list</span><span lang=3D"EN-US"><o:p></o:p></span></pre><pre =
style=3D"margin: 0mm 0mm 0.0001pt; font-size: 12pt; font-family: '=EF=BC=AD=
=EF=BC=B3 =E3=82=B4=E3=82=B7=E3=83=83=E3=82=AF';"><span lang=3D"EN-US" =
style=3D"color: rgb(136, 136, 136);"><a =
href=3D"mailto:6tisch-security@ietf.org" target=3D"_blank" style=3D"color:=
 purple; text-decoration: =
underline;">6tisch-security@ietf.org</a></span><span =
lang=3D"EN-US"><o:p></o:p></span></pre><pre style=3D"margin: 0mm 0mm =
0.0001pt; font-size: 12pt; font-family: '=EF=BC=AD=EF=BC=B3 =
=E3=82=B4=E3=82=B7=E3=83=83=E3=82=AF';"><span lang=3D"EN-US" =
style=3D"color: rgb(136, 136, 136);"><a =
href=3D"http://cp.mcafee.com/d/2DRPoO86QmbEEKnjKOrKrhs7cFCQn1PbVJ5MsqekkSj=
hOrsuuusoLsS8QAHm0afB3ZzOVI-kfSfbCZKDtxVB_HYMC-C-MNRXBQSnSuvvovv7csJteOaqJ=
NPfaxVZicHs3jr1JwTvAm4TDNOb2pEVdTdAVPmEBC5eBYTu00U9GX33VkDa3JssDaBypuDSrza=
poSVelb4OZfIT6kONsxlK5LE2FvdTw09J55V6VI5-Aq83iSVelb4OZfIT6kONFtd46AvwxFEwt=
H4Qg9ThobTvbFzzh0Velb4Ph1jXdNBcIq8bquursodLWbv" target=3D"_blank" =
style=3D"color: purple; text-decoration: =
underline;">https://www.ietf.org/mailman/listinfo/6tisch-security</a></spa=
n><span lang=3D"EN-US"><o:p></o:p></span></pre></blockquote><p =
class=3D"MsoNormal" style=3D"margin: 0mm 0mm 12pt; font-size: 12pt; =
font-family: '=EF=BC=AD=EF=BC=B3 =EF=BC=B0=E3=82=B4=E3=82=B7=E3=83=83=E3=82=
=AF';"><span lang=3D"EN-US" style=3D"color: rgb(136, 136, =
136);"><br><br></span><span lang=3D"EN-US"><o:p></o:p></span></p><pre =
style=3D"margin: 0mm 0mm 0.0001pt; font-size: 12pt; font-family: '=EF=BC=AD=
=EF=BC=B3 =E3=82=B4=E3=82=B7=E3=83=83=E3=82=AF';"><span lang=3D"EN-US" =
style=3D"color: rgb(136, 136, 136);">-- </span><span =
lang=3D"EN-US"><o:p></o:p></span></pre><pre style=3D"margin: 0mm 0mm =
0.0001pt; font-size: 12pt; font-family: '=EF=BC=AD=EF=BC=B3 =
=E3=82=B4=E3=82=B7=E3=83=83=E3=82=AF';"><span lang=3D"EN-US" =
style=3D"color: rgb(136, 136, 136);">email: <a =
href=3D"mailto:rstruik.ext@gmail.com" target=3D"_blank" style=3D"color: =
purple; text-decoration: underline;">rstruik.ext@gmail.com</a> | Skype: =
rstruik</span><span lang=3D"EN-US"><o:p></o:p></span></pre><pre =
style=3D"margin: 0mm 0mm 0.0001pt; font-size: 12pt; font-family: '=EF=BC=AD=
=EF=BC=B3 =E3=82=B4=E3=82=B7=E3=83=83=E3=82=AF';"><span lang=3D"EN-US" =
style=3D"color: rgb(136, 136, 136);">cell: <a =
href=3D"tel:%2B1%20%28647%29%20867-5658" target=3D"_blank" style=3D"color:=
 purple; text-decoration: underline;">+1 (647) 867-5658</a> | US: <a =
href=3D"tel:%2B1%20%28415%29%20690-7363" target=3D"_blank" style=3D"color:=
 purple; text-decoration: underline;">+1 (415) 690-7363</a></span><span =
lang=3D"EN-US"><o:p></o:p></span></pre></div><p class=3D"MsoNormal" =
style=3D"margin: 0mm 0mm 12pt; font-size: 12pt; font-family: '=EF=BC=AD=EF=
=BC=B3 =EF=BC=B0=E3=82=B4=E3=82=B7=E3=83=83=E3=82=AF';"><span =
lang=3D"EN-US"><br>_______________________________________________<br>6tis=
ch-security mailing list<br><a href=3D"mailto:6tisch-security@ietf.org" =
target=3D"_blank" style=3D"color: purple; text-decoration: =
underline;">6tisch-security@ietf.org</a><br><a =
href=3D"http://cp.mcafee.com/d/avndzgQ93gArhoKyyVteX9KVJ5MsOCrhs7cLCQn1NEV=
hjpd79JNVVVNyZPoziiJo0E-kfSfbCPVg_oYKrSWtS7Cn-LP2rWrX37nKnjpvpVZZxZYsNORQX=
8FGT7cYG7DR8OJMddECQjt-hojuv78I9CzATsSjDdqymokWnPtU03wCHIcfBisEeRNOsGm9BWv=
pKcFBzrAVkIjbQ-Pspjb5O5mUm-waBYTu00CQknArCMnWhEwdbrAVkIjbQ-Pspjb6BQQgqh-26=
Cy1SIjh0Dt5wLtYKCed43AVkIjd45fIT6kONEwJFVVJNwSeVhsrLe-Fkd" =
target=3D"_blank" style=3D"color: purple; text-decoration: =
underline;">http://cp.mcafee.com/d/avndzgQ93gArhoKyyVteX9KVJ5MsOCrhs7cLCQn=
1NEVhjpd79JNVVVNyZPoziiJo0E-kfSfbCPVg_oYKrSWtS7Cn-LP2rWrX37nKnjpvpVZZxZYsN=
ORQX8FGT7cYG7DR8OJMddECQjt-hojuv78I9CzATsSjDdqymokWnPtU03wCHIcfBisEeRNOsGm=
9BWvpKcFBzrAVkIjbQ-Pspjb5O5mUm-waBYTu00CQknArCMnWhEwdbrAVkIjbQ-Pspjb6BQQgq=
h-26Cy1SIjh0Dt5wLtYKCed43AVkIjd45fIT6kONEwJFVVJNwSeVhsrLe-Fkd</a><o:p></o:=
p></span></p></blockquote></div><div style=3D"margin: 0mm 0mm 0.0001pt; =
font-size: 12pt; font-family: '=EF=BC=AD=EF=BC=B3 =
=EF=BC=B0=E3=82=B4=E3=82=B7=E3=83=83=E3=82=AF';"><span =
lang=3D"EN-US"><br><br =
clear=3D"all"><br>--<o:p></o:p></span></div><div><div style=3D"margin: =
0mm 0mm 0.0001pt; font-size: 12pt; font-family: '=EF=BC=AD=EF=BC=B3 =
=EF=BC=B0=E3=82=B4=E3=82=B7=E3=83=83=E3=82=AF';"><span lang=3D"EN-US" =
style=3D"font-size: 13.5pt; font-family: 'Times New Roman', =
serif;">--&nbsp;<br>Jonathan Simon, Ph. D<br>Director of Systems =
Engineering<br>Dust Networks at Linear Technology<br>30695 Huntwood =
Ave<br>Hayward, CA 94544-7021<br><a href=3D"tel:%28510%29%20400-2936" =
target=3D"_blank" style=3D"color: purple; text-decoration: =
underline;">(510) 400-2936</a><br><a href=3D"tel:%28510%29%20489-3799" =
target=3D"_blank" style=3D"color: purple; text-decoration: =
underline;">(510) 489-3799</a><span =
class=3D"Apple-converted-space">&nbsp;</span>FAX<br><a =
href=3D"mailto:jsimon@linear.com" target=3D"_blank" style=3D"color: =
purple; text-decoration: underline;">jsimon@linear.com</a></span><span =
lang=3D"EN-US"><br><br></span><span lang=3D"EN-US" style=3D"font-size: =
13.5pt; font-family: 'Times New Roman', serif;">**LINEAR =
TECHNOLOGY&nbsp;CORPORATION**&nbsp;<br>*****Internet Email =
Confidentiality&nbsp;Notice*****&nbsp;<br>&nbsp;This e-mail =
transmission, and any&nbsp;documents, files or previous =
e-mail&nbsp;messages attached to it may contain&nbsp;confidential =
information that is&nbsp;legally privileged. If you are not =
the&nbsp;intended recipient, or a person&nbsp;responsible for delivering =
it to the&nbsp;intended recipient, you are hereby&nbsp;notified that any =
disclosure, copying,&nbsp;distribution or use of any of =
the&nbsp;information contained in or attached&nbsp;to this transmission =
is STRICTLY&nbsp;PROHIBITED. If you have received this&nbsp;transmission =
in error, please&nbsp;immediately notify me by reply e-mail, or by =
telephone at<span class=3D"Apple-converted-space">&nbsp;</span><a =
href=3D"tel:%28510%29%20400-2936" target=3D"_blank" style=3D"color: =
purple; text-decoration: underline;">(510) 400-2936</a>, and destroy the =
original&nbsp;transmission and its attachments&nbsp;without reading or =
saving in any&nbsp;manner. Thank you.</span><span =
lang=3D"EN-US"><o:p></o:p></span></div></div></div></div><p =
class=3D"MsoNormal" style=3D"margin: 0mm 0mm 12pt; font-size: 12pt; =
font-family: '=EF=BC=AD=EF=BC=B3 =EF=BC=B0=E3=82=B4=E3=82=B7=E3=83=83=E3=82=
=AF';"><span =
lang=3D"EN-US"><br>_______________________________________________<br>6tis=
ch-security mailing list<br><a href=3D"mailto:6tisch-security@ietf.org" =
style=3D"color: purple; text-decoration: =
underline;">6tisch-security@ietf.org</a><br><a =
href=3D"http://cp.mcafee.com/d/2DRPow76QmbEFLzzhOM-rKrhs7cFCQn1PbVJ5Msqekk=
SjhOrsuuusoLsS8QAHm0afB3ZzOVI-kfSfbCTA7hPXPb_nVNZNBVxzHTbEzHIYYepd7bz8XBHE=
ShhlKM_OEuvkzaT0QSyrhdTV5xdVYsyMCqejtPpesRG9pxjFvdTw0e2qKMM-l9OwXn79OFoCnF=
ZCUOCmdKjBiNcLjXdNBcIn8lrxrW0GnPtU02rojhKUr1vF6y0QJKjBiNcLjXdNBcIqnjh1F7U8=
qq87qNd42tQm2ZTOWoUQgejBiNcQgk-Pspjb6y2SDDCT63rt_U2SVUlVB0" =
target=3D"_blank" style=3D"color: purple; text-decoration: =
underline;">http://cp.mcafee.com/d/2DRPow76QmbEFLzzhOM-rKrhs7cFCQn1PbVJ5Ms=
qekkSjhOrsuuusoLsS8QAHm0afB3ZzOVI-kfSfbCTA7hPXPb_nVNZNBVxzHTbEzHIYYepd7bz8=
XBHEShhlKM_OEuvkzaT0QSyrhdTV5xdVYsyMCqejtPpesRG9pxjFvdTw0e2qKMM-l9OwXn79OF=
oCnFZCUOCmdKjBiNcLjXdNBcIn8lrxrW0GnPtU02rojhKUr1vF6y0QJKjBiNcLjXdNBcIqnjh1=
F7U8qq87qNd42tQm2ZTOWoUQgejBiNcQgk-Pspjb6y2SDDCT63rt_U2SVUlVB0</a><o:p></o=
:p></span></p></blockquote></div><div style=3D"margin: 0mm 0mm 0.0001pt; =
font-size: 12pt; font-family: '=EF=BC=AD=EF=BC=B3 =
=EF=BC=B0=E3=82=B4=E3=82=B7=E3=83=83=E3=82=AF';"><span =
lang=3D"EN-US"><br><br =
clear=3D"all"><br>--<o:p></o:p></span></div><div><div style=3D"margin: =
0mm 0mm 0.0001pt; font-size: 12pt; font-family: '=EF=BC=AD=EF=BC=B3 =
=EF=BC=B0=E3=82=B4=E3=82=B7=E3=83=83=E3=82=AF';"><span lang=3D"EN-US" =
style=3D"font-size: 13.5pt; font-family: 'Times New Roman', =
serif;">--&nbsp;<br>Jonathan Simon, Ph. D<br>Director of Systems =
Engineering<br>Dust Networks at Linear Technology<br>30695 Huntwood =
Ave<br>Hayward, CA 94544-7021<br>(510) 400-2936<br>(510) 489-3799 =
FAX<br><a href=3D"mailto:jsimon@linear.com" target=3D"_blank" =
style=3D"color: purple; text-decoration: =
underline;">jsimon@linear.com</a></span><span =
lang=3D"EN-US"><br><br></span><span lang=3D"EN-US" style=3D"font-size: =
13.5pt; font-family: 'Times New Roman', serif;">**LINEAR =
TECHNOLOGY&nbsp;CORPORATION**&nbsp;<br>*****Internet Email =
Confidentiality&nbsp;Notice*****&nbsp;<br>&nbsp;This e-mail =
transmission, and any&nbsp;documents, files or previous =
e-mail&nbsp;messages attached to it may contain&nbsp;confidential =
information that is&nbsp;legally privileged. If you are not =
the&nbsp;intended recipient, or a person&nbsp;responsible for delivering =
it to the&nbsp;intended recipient, you are hereby&nbsp;notified that any =
disclosure, copying,&nbsp;distribution or use of any of =
the&nbsp;information contained in or attached&nbsp;to this transmission =
is STRICTLY&nbsp;PROHIBITED. If you have received this&nbsp;transmission =
in error, please&nbsp;immediately notify me by reply e-mail, or by =
telephone at (510) 400-2936, and destroy the original&nbsp;transmission =
and its attachments&nbsp;without reading or saving in any&nbsp;manner. =
Thank you.</span><span =
lang=3D"EN-US"><o:p></o:p></span></div></div></div></div>_________________=
______________________________<br>6tisch-security mailing list<br><a =
href=3D"mailto:6tisch-security@ietf.org" style=3D"color: purple; =
text-decoration: underline;">6tisch-security@ietf.org</a><br><a =
href=3D"http://cp.mcafee.com/d/1jWVIe3zqb5QkTzhOMC-rKrhs7cFCQn1PbVJ5Msqekk=
SjhOrsuuusoLsS8QAHm0afB3ZzOVI-kfSfbCO5JtvupvW_8CzBdBBfHTbECzBdzATC7xNEVVqW=
tAklrCzB7BgY-F6lK1FJ4SyrLOb2rPUV5xcQsCXCOsVHkiP2Di-rL00s4RtxxYGjB1SKejBiNc=
LjXdNBcIrsDaBypuDSrzapoKgGT2TQ1kLCXM04S-qem7T3obZ8Qg6BJOsGm9BWvpKcFBziWq8d=
8_13jh0Xm9EwjKyMnK-nj76y1OsGm9Cy2DSrzapoQgmQYYSUMrDrkr2pAaTam" =
style=3D"color: purple; text-decoration: =
underline;">http://cp.mcafee.com/d/1jWVIe3zqb5QkTzhOMC-rKrhs7cFCQn1PbVJ5Ms=
qekkSjhOrsuuusoLsS8QAHm0afB3ZzOVI-kfSfbCO5JtvupvW_8CzBdBBfHTbECzBdzATC7xNE=
VVqWtAklrCzB7BgY-F6lK1FJ4SyrLOb2rPUV5xcQsCXCOsVHkiP2Di-rL00s4RtxxYGjB1SKej=
BiNcLjXdNBcIrsDaBypuDSrzapoKgGT2TQ1kLCXM04S-qem7T3obZ8Qg6BJOsGm9BWvpKcFBzi=
Wq8d8_13jh0Xm9EwjKyMnK-nj76y1OsGm9Cy2DSrzapoQgmQYYSUMrDrkr2pAaTam</a></div=
></blockquote></div><br></div></body></html>=

--Apple-Mail=_D825E0BB-475F-4275-BF8D-37EBB0DAD774--


From nobody Wed May 28 09:58:27 2014
Return-Path: <jsimon@linear.com>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 366A11A0A08 for <6tisch-security@ietfa.amsl.com>; Wed, 28 May 2014 09:58:25 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.199
X-Spam-Level: 
X-Spam-Status: No, score=-4.199 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_MED=-2.3] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id p1KoXRP3XJ9Z for <6tisch-security@ietfa.amsl.com>; Wed, 28 May 2014 09:58:22 -0700 (PDT)
Received: from p01c12o145.mxlogic.net (p01c12o145.mxlogic.net [208.65.145.68]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 7C3C01A04A6 for <6tisch-security@ietf.org>; Wed, 28 May 2014 09:58:22 -0700 (PDT)
Received: from unknown [12.218.215.72] (EHLO smtpauth1.linear.com) by p01c12o145.mxlogic.net(mxl_mta-8.0.0-1) with ESMTP id ba516835.2ae88fa18940.28833.00-542.83877.p01c12o145.mxlogic.net (envelope-from <jsimon@linear.com>);  Wed, 28 May 2014 10:58:19 -0600 (MDT)
X-MXL-Hash: 538615ab33b0382d-455378abd7277efab0ea8c0161319ad57aa9f526
Received: from unknown [12.218.215.72] (EHLO smtpauth1.linear.com) by p01c12o145.mxlogic.net(mxl_mta-8.0.0-1) with ESMTP id f3416835.0.25465.00-099.74017.p01c12o145.mxlogic.net (envelope-from <jsimon@linear.com>);  Wed, 28 May 2014 10:52:17 -0600 (MDT)
X-MXL-Hash: 53861441104a0bde-5e238ec721303f5fa99eab02e344e92b01eefea0
Received: from jsimonmacmini.engineering.linear.com (unknown [10.70.48.25]) by smtpauth1.linear.com (Postfix) with ESMTPSA id D7949740AD; Wed, 28 May 2014 09:52:11 -0700 (PDT)
Content-Type: multipart/alternative; boundary="Apple-Mail=_3C29AF60-9ACC-4FBD-8F6D-D02B5BEBC097"
Mime-Version: 1.0 (Mac OS X Mail 7.3 \(1878.2\))
From: Jonathan Simon <jsimon@linear.com>
In-Reply-To: <16047.1401291895@sandelman.ca>
Date: Wed, 28 May 2014 09:54:18 -0700
Message-Id: <03C29E57-7111-4CA0-9D8C-27391C66E72D@linear.com>
References: <E045AECD98228444A58C61C200AE1BD8416F3AF4@xmb-rcd-x01.cisco.com> <531DD632.2060009@cox.net> <531DDB20.5050600@gmail.com> <10925.1394631496@sandelman.ca> <532069C8.2050005@gmail.com> <23590.1394999032@sandelman.ca> <18106.1395625035@sandelman.ca> <19609.1396839403@sandelman.ca> <11557.1397444260@sandelman.ca> <28192.1398644294@sandelman.ca> <29064.1399255587@sandelman.ca> <19475.1400588783@sandelman.ca> <4903.1401158997@sandelman.ca> <53840205.2070103@gmail.com> <CAJeFcoS3PNFX2obx3uNDJDtH=QvNLmaPhw2R468sNaeqpo8QBQ@mail.gmail.com> <674F70E5F2BE564CB06B6901FD3DD78B2723B576@TGXML210.toshiba.local> <CAJeFcoQBp1A7pwZHWoesvrjSySW0UZ0k11-s3-MFAozSuR0Yrw@mail.gmail.com> <674F70E5F2BE564CB06B6901FD3DD78B2723B85A@TGXML210.toshiba.local> <16047.1401291895@sandelman.ca>
To: Michael Richardson <mcr+ietf@sandelman.ca>
X-Mailer: Apple Mail (2.1878.2)
X-AnalysisOut: [v=2.1 cv=PIyB+JaC c=1 sm=1 tr=0 a=glloKNylpeYNumXQcclYyA==]
X-AnalysisOut: [:117 a=glloKNylpeYNumXQcclYyA==:17 a=9iaqTFGLkfwA:10 a=D2_]
X-AnalysisOut: [GN2MmYMYA:10 a=BLceEmwcHowA:10 a=MqDINYqSAAAA:8 a=YlVTAMxI]
X-AnalysisOut: [AAAA:8 a=48vgC7mUAAAA:8 a=SyYMxH9GAAAA:8 a=x62zYttApk5LHcs]
X-AnalysisOut: [y9UQA:9 a=CjuIK1q_8ugA:10 a=19wCD08tTksA:10 a=vsVyj9psLt0A]
X-AnalysisOut: [:10 a=qVizmW-ZYBIA:10 a=p-HxVa_ds0YA:10 a=xLpt9-x9cSEA:10 ]
X-AnalysisOut: [a=lZB815dzVvQA:10 a=B4rHkF6HSED8dbi-tc8A:9 a=q13LiYN1qdePD]
X-AnalysisOut: [zth:21 a=_W_S_7VecoQA:10]
X-Spam: [F=0.5000000000; CM=0.500; MH=0.500(2014052813); S=0.200(2014051901)]
X-MAIL-FROM: <jsimon@linear.com>
X-SOURCE-IP: [12.218.215.72]
Archived-At: http://mailarchive.ietf.org/arch/msg/6tisch-security/btInEt9BZYVw1_vjh2FlMnUmL4w
Cc: 6tisch-security@ietf.org, rstruik.ext@gmail.com, yoshihiro.ohba@toshiba.co.jp
Subject: Re: [6tisch-security] agenda for 2014-05-27 6tisch security call
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 28 May 2014 16:58:25 -0000

--Apple-Mail=_3C29AF60-9ACC-4FBD-8F6D-D02B5BEBC097
Content-Transfer-Encoding: quoted-printable
Content-Type: text/plain;
	charset=us-ascii

Michael -=20

6TiSCH is free to use beacons any way they like.  In WH, they are only =
used to advertise the presence of a network, so they always use the =
well-known key. 15.4e allows you to use them to poll for information =
(using an enhanced beacon request).  They could be used for discovery, =
i.e. DIO or ND frames (with the runtime key) but this is out of scope =
for 4e. =20
--=20
Jonathan Simon, Ph. D
Director of Systems Engineering
Linear Technology, Dust Networks product group
30695 Huntwood Ave
Hayward, CA 94544-7021
(510) 400-2936
(510) 489-3799 FAX
jsimon@linear.com

**LINEAR TECHNOLOGY CORPORATION**=20
*****Internet Email Confidentiality Notice*****=20
 This e-mail transmission, and any documents, files or previous e-mail =
messages attached to it may contain confidential information that is =
legally privileged. If you are not the intended recipient, or a person =
responsible for delivering it to the intended recipient, you are hereby =
notified that any disclosure, copying, distribution or use of any of the =
information contained in or attached to this transmission is STRICTLY =
PROHIBITED. If you have received this transmission in error, please =
immediately notify me by reply e-mail, or by telephone at (510) =
400-2936, and destroy the original transmission and its attachments =
without reading or saving in any manner. Thank you.=20

On May 28, 2014, at 8:44 AM, Michael Richardson <mcr+ietf@sandelman.ca> =
wrote:

>=20
> Jonathan wrote:
>> A. Yes. In WirelessHART the beacons (called "advertisements" but they =
serve the
>> same purpose and have similar content) are intended for devices not =
yet in the
>> network, so they always use the well-known key.  To discover other =
nodes within
>> the network, they use frames secured with the runtime link-layer key.
>=20
>> Jonathan
>=20
> <yoshihiro.ohba@toshiba.co.jp> wrote:
>> Thank you for your answer.
>=20
>> I think this can be an issue if already joined nodes also use the =
beacons
>> protected with the well-known key for maintaining synchronization and =
slot
>> allocations, as an attacker can send forged beacons protected with =
the
>> well-known key.
>=20
> So, beacons are not also sent using the runtime link-layer key?
> I was envisioning that to be the case for 6tisch.
>=20
>=20
>=20
> --
> Michael Richardson <mcr+IETF@sandelman.ca>, Sandelman Software Works
> -=3D IPv6 IoT consulting =3D-
>=20
>=20
>=20
> _______________________________________________
> 6tisch-security mailing list
> 6tisch-security@ietf.org
> =
http://cp.mcafee.com/d/2DRPos76QmbEFCzB4QsThdTdEK3CkPqbwVBYSyUed7aar9EVdKf=
ffecnKr4qilH057Ox-NVsSva7X7BPtxP5T7Cn-LObzXzbP_nKnhuj7sCPtx55XBHFShjlhKVOE=
uvkzaT0QSyrhdTV5xdVYsyMCqejtPpesRG9pxjFvdTw0e2qKMM-l9OwXn79OFoCnFZCUOCmdKj=
BiNcLjXdNBcIn8lrxrW0GnPtU02rsuKqejobZ8Qg6BJOsGm9BWvpKcFBziWq8d8_13jh0Xm9Ew=
jKyMnK-nj76y1OsGm9Cy2DSrzapoQgmQYYSUMrCr5n


--Apple-Mail=_3C29AF60-9ACC-4FBD-8F6D-D02B5BEBC097
Content-Transfer-Encoding: quoted-printable
Content-Type: text/html;
	charset=us-ascii

<html><head><meta http-equiv=3D"Content-Type" content=3D"text/html =
charset=3Dus-ascii"></head><body style=3D"word-wrap: break-word; =
-webkit-nbsp-mode: space; -webkit-line-break: =
after-white-space;">Michael -&nbsp;<div><br></div><div>6TiSCH is free to =
use beacons any way they like. &nbsp;In WH, they are only used to =
advertise the presence of a network, so they always use the well-known =
key. 15.4e allows you to use them to poll for information (using an =
enhanced beacon request). &nbsp;They could be used for discovery, i.e. =
DIO or ND frames (with the runtime key) but this is out of scope for 4e. =
&nbsp;<br><div apple-content-edited=3D"true">
<span class=3D"Apple-style-span" style=3D"border-collapse: separate; =
color: rgb(0, 0, 0); font-family: 'Lucida Grande'; font-style: normal; =
font-variant: normal; font-weight: normal; letter-spacing: normal; =
line-height: normal; orphans: 2; text-align: -webkit-auto; text-indent: =
0px; text-transform: none; white-space: normal; widows: 2; word-spacing: =
0px; -webkit-border-horizontal-spacing: 0px; =
-webkit-border-vertical-spacing: 0px; =
-webkit-text-decorations-in-effect: none; -webkit-text-size-adjust: =
auto; -webkit-text-stroke-width: 0px;  "><span class=3D"Apple-style-span" =
style=3D"border-collapse: separate; color: rgb(0, 0, 0); font-family: =
'Lucida Grande'; font-style: normal; font-variant: normal; font-weight: =
normal; letter-spacing: normal; line-height: normal; orphans: 2; =
text-align: -webkit-auto; text-indent: 0px; text-transform: none; =
white-space: normal; widows: 2; word-spacing: 0px; =
-webkit-border-horizontal-spacing: 0px; -webkit-border-vertical-spacing: =
0px; -webkit-text-decorations-in-effect: none; -webkit-text-size-adjust: =
auto; -webkit-text-stroke-width: 0px;  "><div style=3D"word-wrap: =
break-word; -webkit-nbsp-mode: space; -webkit-line-break: =
after-white-space; "><span class=3D"Apple-style-span" =
style=3D"border-collapse: separate; color: rgb(0, 0, 0); font-family: =
'Lucida Grande'; font-style: normal; font-variant: normal; font-weight: =
normal; letter-spacing: normal; line-height: normal; orphans: 2; =
text-align: -webkit-auto; text-indent: 0px; text-transform: none; =
white-space: normal; widows: 2; word-spacing: 0px; =
-webkit-border-horizontal-spacing: 0px; -webkit-border-vertical-spacing: =
0px; -webkit-text-decorations-in-effect: none; -webkit-text-size-adjust: =
auto; -webkit-text-stroke-width: 0px;  "><div style=3D"word-wrap: =
break-word; -webkit-nbsp-mode: space; -webkit-line-break: =
after-white-space; ">--&nbsp;<br>Jonathan Simon, Ph. D<br>Director of =
Systems Engineering<br>Linear Technology, Dust Networks product =
group<br>30695 Huntwood Ave<br>Hayward, CA 94544-7021<br>(510) =
400-2936<br>(510) 489-3799 FAX<br><a =
href=3D"mailto:jsimon@linear.com">jsimon@linear.com</a><br><br>**LINEAR =
TECHNOLOGY&nbsp;CORPORATION**&nbsp;<br>*****Internet Email =
Confidentiality&nbsp;Notice*****&nbsp;<br>&nbsp;This e-mail =
transmission, and any&nbsp;documents, files or previous =
e-mail&nbsp;messages attached to it may contain&nbsp;confidential =
information that is&nbsp;legally privileged. If you are not =
the&nbsp;intended recipient, or a person&nbsp;responsible for delivering =
it to the&nbsp;intended recipient, you are hereby&nbsp;notified that any =
disclosure, copying,&nbsp;distribution or use of any of =
the&nbsp;information contained in or attached&nbsp;to this transmission =
is STRICTLY&nbsp;PROHIBITED. If you have received this&nbsp;transmission =
in error, please&nbsp;immediately notify me by reply e-mail, or by =
telephone at (510) 400-2936, and destroy the original&nbsp;transmission =
and its attachments&nbsp;without reading or saving in any&nbsp;manner. =
Thank you.&nbsp;<br></div></span></div></span></span>
</div>
<br><div><div>On May 28, 2014, at 8:44 AM, Michael Richardson &lt;<a =
href=3D"mailto:mcr+ietf@sandelman.ca">mcr+ietf@sandelman.ca</a>&gt; =
wrote:</div><br class=3D"Apple-interchange-newline"><blockquote =
type=3D"cite"><br>Jonathan wrote:<br><blockquote type=3D"cite">A. Yes. =
In WirelessHART the beacons (called "advertisements" but they serve =
the<br>same purpose and have similar content) are intended for devices =
not yet in the<br>network, so they always use the well-known key. =
&nbsp;To discover other nodes within<br>the network, they use frames =
secured with the runtime link-layer key.<br></blockquote><br><blockquote =
type=3D"cite">Jonathan<br></blockquote><br>&lt;<a =
href=3D"mailto:yoshihiro.ohba@toshiba.co.jp">yoshihiro.ohba@toshiba.co.jp<=
/a>&gt; wrote:<br><blockquote type=3D"cite">Thank you for your =
answer.<br></blockquote><br><blockquote type=3D"cite">I think this can =
be an issue if already joined nodes also use the beacons<br>protected =
with the well-known key for maintaining synchronization and =
slot<br>allocations, as an attacker can send forged beacons protected =
with the<br>well-known key.<br></blockquote><br>So, beacons are not also =
sent using the runtime link-layer key?<br>I was envisioning that to be =
the case for 6tisch.<br><br><br><br>--<br>Michael Richardson &lt;<a =
href=3D"mailto:mcr+IETF@sandelman.ca">mcr+IETF@sandelman.ca</a>&gt;, =
Sandelman Software Works<br> -=3D IPv6 IoT consulting =
=3D-<br><br><br><br>_______________________________________________<br>6ti=
sch-security mailing list<br><a =
href=3D"mailto:6tisch-security@ietf.org">6tisch-security@ietf.org</a><br>h=
ttp://cp.mcafee.com/d/2DRPos76QmbEFCzB4QsThdTdEK3CkPqbwVBYSyUed7aar9EVdKff=
fecnKr4qilH057Ox-NVsSva7X7BPtxP5T7Cn-LObzXzbP_nKnhuj7sCPtx55XBHFShjlhKVOEu=
vkzaT0QSyrhdTV5xdVYsyMCqejtPpesRG9pxjFvdTw0e2qKMM-l9OwXn79OFoCnFZCUOCmdKjB=
iNcLjXdNBcIn8lrxrW0GnPtU02rsuKqejobZ8Qg6BJOsGm9BWvpKcFBziWq8d8_13jh0Xm9Ewj=
KyMnK-nj76y1OsGm9Cy2DSrzapoQgmQYYSUMrCr5n<br></blockquote></div><br></div>=
</body></html>=

--Apple-Mail=_3C29AF60-9ACC-4FBD-8F6D-D02B5BEBC097--


From nobody Wed May 28 11:57:30 2014
Return-Path: <mcr@sandelman.ca>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id D4C4C1A0584 for <6tisch-security@ietfa.amsl.com>; Wed, 28 May 2014 11:57:28 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.542
X-Spam-Level: 
X-Spam-Status: No, score=-2.542 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RP_MATCHES_RCVD=-0.651, SPF_PASS=-0.001, T_TVD_MIME_NO_HEADERS=0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id g6EcltyvSSvF for <6tisch-security@ietfa.amsl.com>; Wed, 28 May 2014 11:57:27 -0700 (PDT)
Received: from tuna.sandelman.ca (tuna.sandelman.ca [209.87.252.184]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 4C6591A212D for <6tisch-security@ietf.org>; Wed, 28 May 2014 11:57:27 -0700 (PDT)
Received: from sandelman.ca (desk.marajade.sandelman.ca [209.87.252.247]) by tuna.sandelman.ca (Postfix) with ESMTP id 55DB420028 for <6tisch-security@ietf.org>; Wed, 28 May 2014 15:00:08 -0400 (EDT)
Received: by sandelman.ca (Postfix, from userid 179) id 0322663B0E; Wed, 28 May 2014 14:57:15 -0400 (EDT)
Received: from sandelman.ca (localhost [127.0.0.1]) by sandelman.ca (Postfix) with ESMTP id E132963B09 for <6tisch-security@ietf.org>; Wed, 28 May 2014 14:57:15 -0400 (EDT)
From: Michael Richardson <mcr+ietf@sandelman.ca>
to: "6tisch-security\@ietf.org" <6tisch-security@ietf.org>
In-Reply-To: <25059.1401220730@sandelman.ca>
References: <E045AECD98228444A58C61C200AE1BD8416F3AF4@xmb-rcd-x01.cisco.com> <bomn1n01Q3zUFux01ompsd> <531DD632.2060009@cox.net> <531DDB20.5050600@gmail.com> <10925.1394631496@sandelman.ca> <532069C8.2050005@gmail.com> <23590.1394999032@sandelman.ca> <18106.1395625035@sandelman.ca> <19609.1396839403@sandelman.ca> <11557.1397444260@sandelman.ca> <28192.1398644294@sandelman.ca> <29064.1399255587@sandelman.ca> <19475.1400588783@sandelman.ca> <4903.1401158997@sandelman.ca> <53840205.2070103@gmail.com> <5384046A.6080706@gmail.com> <E045AECD98228444A58C61C200AE1BD8426B036B@xmb-rcd-x01.cisco.com> <10436.1401198298@sandelman.ca> <53849841.4020401@gmail.com> <25059.1401220730@sandelman.ca>
X-Mailer: MH-E 8.2; nmh 1.3-dev; GNU Emacs 23.4.1
X-Face: $\n1pF)h^`}$H>Hk{L"x@)JS7<%Az}5RyS@k9X%29-lHB$Ti.V>2bi.~ehC0; <'$9xN5Ub# z!G,p`nR&p7Fz@^UXIn156S8.~^@MJ*mMsD7=QFeq%AL4m<nPbLgmtKK-5dC@#:k
MIME-Version: 1.0
Content-Type: multipart/signed; boundary="=-=-="; micalg=pgp-sha1; protocol="application/pgp-signature"
Date: Wed, 28 May 2014 14:57:15 -0400
Message-ID: <26563.1401303435@sandelman.ca>
Sender: mcr@sandelman.ca
Archived-At: http://mailarchive.ietf.org/arch/msg/6tisch-security/7KB-Nl4zCMoTValQe3mbocgiBVM
Subject: [6tisch-security] agenda for 2014-06-02 6tisch security call
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 28 May 2014 18:57:29 -0000

--=-=-=


To remind the calls will return to Monday mornings at:
    7am PDT, 10am EDT, 1400 UTC.

The plan is to come up with a table of contents for two
documents on the details of the packet flow/sizes/etc. for
the two possible mechanisms.   That will be item #1.

Thomas/Jonathan will be providing some additional background
slides on WirelessHART, as that will provide some of the context
for the table of contents.   I hope the slides will be ready by
EOB Friday, so that they can get distributed before Monday.

--
Michael Richardson <mcr+IETF@sandelman.ca>, Sandelman Software Works
 -= IPv6 IoT consulting =-




--=-=-=
Content-Type: application/pgp-signature

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iQEVAwUBU4Yxi4CLcPvd0N1lAQIHVgf/fLqsTrLHihBtnOW/hy+FGbLZfgb42piT
fHaqSH04oOoGAoCkPPPPxFHlLPLqirMchL6rHwvum14lf5WDVgoFW0eTHooC+j1J
ogvWtZGAqTZxlj0wNzZKetgFa9kxYUKrGi+nxdMJpAhEy+sbAaw97epvN2LMMO74
yo5Z6Ul/4RXX85vW2pDKBs5ODBvzAPk1OvBhrtPO5XbfXQEs41YyyXRH/lwP5iAe
bP/mKajI6nKLmNvt1PyWrRljxhzhSfkTW5gqe8YjZUfDDBRgQfTc054b+YY67OVy
5ciwHtaRhQ6XhSiNA+/90i5HR+v672jC1KBo1lB6cAi5tEqKvxXlLw==
=kbEX
-----END PGP SIGNATURE-----
--=-=-=--


From nobody Wed May 28 12:28:06 2014
Return-Path: <twatteyne@gmail.com>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id F0CB51A066B for <6tisch-security@ietfa.amsl.com>; Wed, 28 May 2014 12:27:59 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.277
X-Spam-Level: 
X-Spam-Status: No, score=-1.277 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, FM_FORGED_GMAIL=0.622, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, SPF_PASS=-0.001] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 4lan0DOW7v7K for <6tisch-security@ietfa.amsl.com>; Wed, 28 May 2014 12:27:58 -0700 (PDT)
Received: from mail-qg0-x234.google.com (mail-qg0-x234.google.com [IPv6:2607:f8b0:400d:c04::234]) (using TLSv1 with cipher ECDHE-RSA-RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id C376A1A0171 for <6tisch-security@ietf.org>; Wed, 28 May 2014 12:27:58 -0700 (PDT)
Received: by mail-qg0-f52.google.com with SMTP id a108so18783796qge.25 for <6tisch-security@ietf.org>; Wed, 28 May 2014 12:27:54 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113;  h=mime-version:sender:in-reply-to:references:from:date:message-id :subject:to:cc:content-type; bh=IAVahgyw+CyqIkbl5JgKP1fs87D9bH1gqGBBzqf0yaQ=; b=Qjfqi5dEz+CC5ilfLZVoAZsJfuNayntFzEf5RICj/Xwks6f9xZcOXGkAru/24VEIRf CeC6epqsQ3AYeQcsnwCsUyXESsWmFy7dBIf2n7UsVDCJBQXrB5p+PpD2WEJyeq7BNujY YLXmxhc2sJTliFV8P03T+jkv16ZWoqFyvekVnulfuDt+R14gwJW5pEPokJcWe29EbiS3 MrzZErQuSmQb5+y6qrOG3BCPcW/0+EHhPwWxREh8G21gV0zND68MQr/dczWH2Cs8cbw7 AQH8vrz4Y1xKCVnIyrBdKChtMetXVllyk3NtI+/nleRM/YmBFhhhkiiTVGCxTviDlLp+ 870w==
X-Received: by 10.224.103.129 with SMTP id k1mr2783945qao.62.1401305274688; Wed, 28 May 2014 12:27:54 -0700 (PDT)
MIME-Version: 1.0
Sender: twatteyne@gmail.com
Received: by 10.140.97.34 with HTTP; Wed, 28 May 2014 12:27:34 -0700 (PDT)
In-Reply-To: <26563.1401303435@sandelman.ca>
References: <E045AECD98228444A58C61C200AE1BD8416F3AF4@xmb-rcd-x01.cisco.com> <531DD632.2060009@cox.net> <531DDB20.5050600@gmail.com> <10925.1394631496@sandelman.ca> <532069C8.2050005@gmail.com> <23590.1394999032@sandelman.ca> <18106.1395625035@sandelman.ca> <19609.1396839403@sandelman.ca> <11557.1397444260@sandelman.ca> <28192.1398644294@sandelman.ca> <29064.1399255587@sandelman.ca> <19475.1400588783@sandelman.ca> <4903.1401158997@sandelman.ca> <53840205.2070103@gmail.com> <5384046A.6080706@gmail.com> <E045AECD98228444A58C61C200AE1BD8426B036B@xmb-rcd-x01.cisco.com> <10436.1401198298@sandelman.ca> <53849841.4020401@gmail.com> <25059.1401220730@sandelman.ca> <26563.1401303435@sandelman.ca>
From: Thomas Watteyne <watteyne@eecs.berkeley.edu>
Date: Wed, 28 May 2014 12:27:34 -0700
X-Google-Sender-Auth: kUPG7iEu7NpqbxyicH272ZiI4_g
Message-ID: <CADJ9OA_xYMWD5VU-THBTq=vL_cu9=0moHrQuLfOvZqK78OvbjQ@mail.gmail.com>
To: Michael Richardson <mcr+ietf@sandelman.ca>
Content-Type: multipart/alternative; boundary=047d7b66f74b1eac5704fa7acf01
Archived-At: http://mailarchive.ietf.org/arch/msg/6tisch-security/Y6tpv7xiIFsLnEF9aacLNBsneTU
Cc: "6tisch-security@ietf.org" <6tisch-security@ietf.org>
Subject: Re: [6tisch-security] agenda for 2014-06-02 6tisch security call
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 28 May 2014 19:28:00 -0000

--047d7b66f74b1eac5704fa7acf01
Content-Type: text/plain; charset=UTF-8

+1

I believe this is a good action plan.

Thomas


On Wed, May 28, 2014 at 11:57 AM, Michael Richardson
<mcr+ietf@sandelman.ca>wrote:

>
> To remind the calls will return to Monday mornings at:
>     7am PDT, 10am EDT, 1400 UTC.
>
> The plan is to come up with a table of contents for two
> documents on the details of the packet flow/sizes/etc. for
> the two possible mechanisms.   That will be item #1.
>
> Thomas/Jonathan will be providing some additional background
> slides on WirelessHART, as that will provide some of the context
> for the table of contents.   I hope the slides will be ready by
> EOB Friday, so that they can get distributed before Monday.
>
> --
> Michael Richardson <mcr+IETF@sandelman.ca>, Sandelman Software Works
>  -= IPv6 IoT consulting =-
>
>
>
>
> _______________________________________________
> 6tisch-security mailing list
> 6tisch-security@ietf.org
> https://www.ietf.org/mailman/listinfo/6tisch-security
>
>

--047d7b66f74b1eac5704fa7acf01
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr">+1<div><br></div><div>I believe this is a good action plan=
.</div><div><br></div><div>Thomas</div></div><div class=3D"gmail_extra"><br=
><br><div class=3D"gmail_quote">On Wed, May 28, 2014 at 11:57 AM, Michael R=
ichardson <span dir=3D"ltr">&lt;<a href=3D"mailto:mcr+ietf@sandelman.ca" ta=
rget=3D"_blank">mcr+ietf@sandelman.ca</a>&gt;</span> wrote:<br>

<blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;border-left:1p=
x #ccc solid;padding-left:1ex"><br>
To remind the calls will return to Monday mornings at:<br>
=C2=A0 =C2=A0 7am PDT, 10am EDT, 1400 UTC.<br>
<br>
The plan is to come up with a table of contents for two<br>
documents on the details of the packet flow/sizes/etc. for<br>
the two possible mechanisms. =C2=A0 That will be item #1.<br>
<br>
Thomas/Jonathan will be providing some additional background<br>
slides on WirelessHART, as that will provide some of the context<br>
for the table of contents. =C2=A0 I hope the slides will be ready by<br>
EOB Friday, so that they can get distributed before Monday.<br>
<br>
--<br>
Michael Richardson &lt;<a href=3D"mailto:mcr%2BIETF@sandelman.ca">mcr+IETF@=
sandelman.ca</a>&gt;, Sandelman Software Works<br>
=C2=A0-=3D IPv6 IoT consulting =3D-<br>
<br>
<br>
<br>
<br>_______________________________________________<br>
6tisch-security mailing list<br>
<a href=3D"mailto:6tisch-security@ietf.org">6tisch-security@ietf.org</a><br=
>
<a href=3D"https://www.ietf.org/mailman/listinfo/6tisch-security" target=3D=
"_blank">https://www.ietf.org/mailman/listinfo/6tisch-security</a><br>
<br></blockquote></div><br></div>

--047d7b66f74b1eac5704fa7acf01--


From nobody Wed May 28 12:35:08 2014
Return-Path: <rstruik.ext@gmail.com>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 1A6F01A068F for <6tisch-security@ietfa.amsl.com>; Wed, 28 May 2014 12:35:06 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.999
X-Spam-Level: 
X-Spam-Status: No, score=-1.999 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id RKd7JygVBycL for <6tisch-security@ietfa.amsl.com>; Wed, 28 May 2014 12:35:04 -0700 (PDT)
Received: from mail-ie0-x235.google.com (mail-ie0-x235.google.com [IPv6:2607:f8b0:4001:c03::235]) (using TLSv1 with cipher ECDHE-RSA-RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 0A3391A0684 for <6tisch-security@ietf.org>; Wed, 28 May 2014 12:35:03 -0700 (PDT)
Received: by mail-ie0-f181.google.com with SMTP id rp18so9228378iec.40 for <6tisch-security@ietf.org>; Wed, 28 May 2014 12:35:00 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113;  h=message-id:date:from:user-agent:mime-version:to:cc:subject :references:in-reply-to:content-type; bh=bdNMFg8Ng6p0Nwg/W4NnVpiom0L8KqlGlolF3z6T4CU=; b=LL2V0wB/sz1d/mMzjtdQOOush2EjGYAOYkyLk1sgpoabp5vgVVf44KR5QcouH8Babi 5mhhI7Ff147ohtghIrDfg/iudfuCS/Zj8YBaOSxS+EeTQ0zzeu6KSOlYRZdhVMIPC/tV Nheoic++BmE5Z0807mlzqjfys/RctFDCCZ4XHxOZJKFZsQydmUEtTh4oA1jq96y6mp8/ VbdYCNuUWqbkvjViCfTpUM6V6aiBYaculL66Ir6BEg/e72k2RoB8HdXpLVGwJ23ojYJC NVYASxpNDRekAcEUqjaIITlO2rrvU7zX+SSIfpUbwJX007SW40nJL3UMxLB8umlGYxIr IeeQ==
X-Received: by 10.50.120.3 with SMTP id ky3mr461502igb.24.1401305700167; Wed, 28 May 2014 12:35:00 -0700 (PDT)
Received: from [192.168.1.101] (CPE0013100e2c51-CM001cea35caa6.cpe.net.cable.rogers.com. [99.231.3.110]) by mx.google.com with ESMTPSA id d10sm18002380igc.8.2014.05.28.12.34.59 for <multiple recipients> (version=TLSv1 cipher=ECDHE-RSA-RC4-SHA bits=128/128); Wed, 28 May 2014 12:34:59 -0700 (PDT)
Message-ID: <53863A5F.3000707@gmail.com>
Date: Wed, 28 May 2014 15:34:55 -0400
From: Rene Struik <rstruik.ext@gmail.com>
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:24.0) Gecko/20100101 Thunderbird/24.5.0
MIME-Version: 1.0
To: Thomas Watteyne <watteyne@eecs.berkeley.edu>,  Michael Richardson <mcr+ietf@sandelman.ca>
References: <E045AECD98228444A58C61C200AE1BD8416F3AF4@xmb-rcd-x01.cisco.com> <531DD632.2060009@cox.net> <531DDB20.5050600@gmail.com> <10925.1394631496@sandelman.ca> <532069C8.2050005@gmail.com> <23590.1394999032@sandelman.ca> <18106.1395625035@sandelman.ca> <19609.1396839403@sandelman.ca> <11557.1397444260@sandelman.ca> <28192.1398644294@sandelman.ca> <29064.1399255587@sandelman.ca> <19475.1400588783@sandelman.ca> <4903.1401158997@sandelman.ca> <53840205.2070103@gmail.com> <5384046A.6080706@gmail.com> <E045AECD98228444A58C61C200AE1BD8426B036B@xmb-rcd-x01.cisco.com> <10436.1401198298@sandelman.ca> <53849841.4020401@gmail.com> <25059.1401220730@sandelman.ca> <26563.1401303435@sandelman.ca> <CADJ9OA_xYMWD5VU-THBTq=vL_cu9=0moHrQuLfOvZqK78OvbjQ@mail.gmail.com>
In-Reply-To: <CADJ9OA_xYMWD5VU-THBTq=vL_cu9=0moHrQuLfOvZqK78OvbjQ@mail.gmail.com>
Content-Type: multipart/alternative; boundary="------------070908090300060103090104"
Archived-At: http://mailarchive.ietf.org/arch/msg/6tisch-security/YefjZ6xlYO83qHiW3mf5Smv7b14
Cc: "6tisch-security@ietf.org" <6tisch-security@ietf.org>
Subject: Re: [6tisch-security] agenda for 2014-06-02 6tisch security call
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 28 May 2014 19:35:06 -0000

This is a multi-part message in MIME format.
--------------070908090300060103090104
Content-Type: text/plain; charset=ISO-8859-1; format=flowed
Content-Transfer-Encoding: 7bit

Hi Michael:

Fine with me, as long as we dive into more detail of how things 
could/should work as well.

Just curious, though: what are the "two possible mechanisms"???

Rene

On 5/28/2014 3:27 PM, Thomas Watteyne wrote:
> +1
>
> I believe this is a good action plan.
>
> Thomas
>
>
> On Wed, May 28, 2014 at 11:57 AM, Michael Richardson 
> <mcr+ietf@sandelman.ca <mailto:mcr+ietf@sandelman.ca>> wrote:
>
>
>     To remind the calls will return to Monday mornings at:
>         7am PDT, 10am EDT, 1400 UTC.
>
>     The plan is to come up with a table of contents for two
>     documents on the details of the packet flow/sizes/etc. for
>     the two possible mechanisms.   That will be item #1.
>
>     Thomas/Jonathan will be providing some additional background
>     slides on WirelessHART, as that will provide some of the context
>     for the table of contents.   I hope the slides will be ready by
>     EOB Friday, so that they can get distributed before Monday.
>
>     --
>     Michael Richardson <mcr+IETF@sandelman.ca
>     <mailto:mcr%2BIETF@sandelman.ca>>, Sandelman Software Works
>      -= IPv6 IoT consulting =-
>
>
>
>
>     _______________________________________________
>     6tisch-security mailing list
>     6tisch-security@ietf.org <mailto:6tisch-security@ietf.org>
>     https://www.ietf.org/mailman/listinfo/6tisch-security
>
>
>
>
> _______________________________________________
> 6tisch-security mailing list
> 6tisch-security@ietf.org
> https://www.ietf.org/mailman/listinfo/6tisch-security


-- 
email: rstruik.ext@gmail.com | Skype: rstruik
cell: +1 (647) 867-5658 | US: +1 (415) 690-7363


--------------070908090300060103090104
Content-Type: text/html; charset=ISO-8859-1
Content-Transfer-Encoding: 7bit

<html>
  <head>
    <meta content="text/html; charset=ISO-8859-1"
      http-equiv="Content-Type">
  </head>
  <body bgcolor="#FFFFFF" text="#000000">
    <div class="moz-cite-prefix">Hi Michael:<br>
      <br>
      Fine with me, as long as we dive into more detail of how things
      could/should work as well.<br>
      <br>
      Just curious, though: what are the "two possible mechanisms"???<br>
      <br>
      Rene<br>
      <br>
      On 5/28/2014 3:27 PM, Thomas Watteyne wrote:<br>
    </div>
    <blockquote
cite="mid:CADJ9OA_xYMWD5VU-THBTq=vL_cu9=0moHrQuLfOvZqK78OvbjQ@mail.gmail.com"
      type="cite">
      <div dir="ltr">+1
        <div><br>
        </div>
        <div>I believe this is a good action plan.</div>
        <div><br>
        </div>
        <div>Thomas</div>
      </div>
      <div class="gmail_extra"><br>
        <br>
        <div class="gmail_quote">On Wed, May 28, 2014 at 11:57 AM,
          Michael Richardson <span dir="ltr">&lt;<a
              moz-do-not-send="true" href="mailto:mcr+ietf@sandelman.ca"
              target="_blank">mcr+ietf@sandelman.ca</a>&gt;</span>
          wrote:<br>
          <blockquote class="gmail_quote" style="margin:0 0 0
            .8ex;border-left:1px #ccc solid;padding-left:1ex"><br>
            To remind the calls will return to Monday mornings at:<br>
            &nbsp; &nbsp; 7am PDT, 10am EDT, 1400 UTC.<br>
            <br>
            The plan is to come up with a table of contents for two<br>
            documents on the details of the packet flow/sizes/etc. for<br>
            the two possible mechanisms. &nbsp; That will be item #1.<br>
            <br>
            Thomas/Jonathan will be providing some additional background<br>
            slides on WirelessHART, as that will provide some of the
            context<br>
            for the table of contents. &nbsp; I hope the slides will be ready
            by<br>
            EOB Friday, so that they can get distributed before Monday.<br>
            <br>
            --<br>
            Michael Richardson &lt;<a moz-do-not-send="true"
              href="mailto:mcr%2BIETF@sandelman.ca">mcr+IETF@sandelman.ca</a>&gt;,
            Sandelman Software Works<br>
            &nbsp;-= IPv6 IoT consulting =-<br>
            <br>
            <br>
            <br>
            <br>
            _______________________________________________<br>
            6tisch-security mailing list<br>
            <a moz-do-not-send="true"
              href="mailto:6tisch-security@ietf.org">6tisch-security@ietf.org</a><br>
            <a moz-do-not-send="true"
              href="https://www.ietf.org/mailman/listinfo/6tisch-security"
              target="_blank">https://www.ietf.org/mailman/listinfo/6tisch-security</a><br>
            <br>
          </blockquote>
        </div>
        <br>
      </div>
      <br>
      <fieldset class="mimeAttachmentHeader"></fieldset>
      <br>
      <pre wrap="">_______________________________________________
6tisch-security mailing list
<a class="moz-txt-link-abbreviated" href="mailto:6tisch-security@ietf.org">6tisch-security@ietf.org</a>
<a class="moz-txt-link-freetext" href="https://www.ietf.org/mailman/listinfo/6tisch-security">https://www.ietf.org/mailman/listinfo/6tisch-security</a>
</pre>
    </blockquote>
    <br>
    <br>
    <pre class="moz-signature" cols="72">-- 
email: <a class="moz-txt-link-abbreviated" href="mailto:rstruik.ext@gmail.com">rstruik.ext@gmail.com</a> | Skype: rstruik
cell: +1 (647) 867-5658 | US: +1 (415) 690-7363</pre>
  </body>
</html>

--------------070908090300060103090104--


From nobody Wed May 28 13:59:16 2014
Return-Path: <mcr@sandelman.ca>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id C15081A0241 for <6tisch-security@ietfa.amsl.com>; Wed, 28 May 2014 13:59:14 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.542
X-Spam-Level: 
X-Spam-Status: No, score=-2.542 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RP_MATCHES_RCVD=-0.651, SPF_PASS=-0.001, T_TVD_MIME_NO_HEADERS=0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id x7iAGh3_ZsAd for <6tisch-security@ietfa.amsl.com>; Wed, 28 May 2014 13:59:13 -0700 (PDT)
Received: from tuna.sandelman.ca (tuna.sandelman.ca [209.87.252.184]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 13EEF1A022D for <6tisch-security@ietf.org>; Wed, 28 May 2014 13:59:13 -0700 (PDT)
Received: from sandelman.ca (desk.marajade.sandelman.ca [209.87.252.247]) by tuna.sandelman.ca (Postfix) with ESMTP id B4B5820028; Wed, 28 May 2014 17:01:55 -0400 (EDT)
Received: by sandelman.ca (Postfix, from userid 179) id 24CB263B0E; Wed, 28 May 2014 16:59:03 -0400 (EDT)
Received: from sandelman.ca (localhost [127.0.0.1]) by sandelman.ca (Postfix) with ESMTP id 107F063B09; Wed, 28 May 2014 16:59:03 -0400 (EDT)
From: Michael Richardson <mcr+ietf@sandelman.ca>
To: "6tisch-security\@ietf.org" <6tisch-security@ietf.org>
In-Reply-To: <53863A5F.3000707@gmail.com>
References: <E045AECD98228444A58C61C200AE1BD8416F3AF4@xmb-rcd-x01.cisco.com> <531DD632.2060009@cox.net> <531DDB20.5050600@gmail.com> <10925.1394631496@sandelman.ca> <532069C8.2050005@gmail.com> <23590.1394999032@sandelman.ca> <18106.1395625035@sandelman.ca> <19609.1396839403@sandelman.ca> <11557.1397444260@sandelman.ca> <28192.1398644294@sandelman.ca> <29064.1399255587@sandelman.ca> <19475.1400588783@sandelman.ca> <4903.1401158997@sandelman.ca> <53840205.2070103@gmail.com> <5384046A.6080706@gmail.com> <E045AECD98228444A58C61C200AE1BD8426B036B@xmb-rcd-x01.cisco.com> <10436.1401198298@sandelman.ca> <53849841.4020401@gmail.com> <25059.1401220730@sandelman.ca> <26563.1401303435@sandelman.ca> <CADJ9OA_xYMWD5VU-THBTq=vL_cu9=0moHrQuLfOvZqK78OvbjQ@mail.gmail.com> <53863A5F.3000707@gmail.com>
X-Mailer: MH-E 8.2; nmh 1.3-dev; GNU Emacs 23.4.1
X-Face: $\n1pF)h^`}$H>Hk{L"x@)JS7<%Az}5RyS@k9X%29-lHB$Ti.V>2bi.~ehC0; <'$9xN5Ub# z!G,p`nR&p7Fz@^UXIn156S8.~^@MJ*mMsD7=QFeq%AL4m<nPbLgmtKK-5dC@#:k
MIME-Version: 1.0
Content-Type: multipart/signed; boundary="=-=-="; micalg=pgp-sha1; protocol="application/pgp-signature"
Date: Wed, 28 May 2014 16:59:03 -0400
Message-ID: <20291.1401310743@sandelman.ca>
Sender: mcr@sandelman.ca
Archived-At: http://mailarchive.ietf.org/arch/msg/6tisch-security/T4s9HU23UWEkrIx83eiZ2LEEj-8
Cc: Thomas Watteyne <watteyne@eecs.berkeley.edu>, Rene Struik <rstruik.ext@gmail.com>
Subject: Re: [6tisch-security] agenda for 2014-06-02 6tisch security call
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 28 May 2014 20:59:14 -0000

--=-=-=


Rene Struik <rstruik.ext@gmail.com> wrote:
    > Fine with me, as long as we dive into more detail of how things could/should
    > work as well.

The goal of this group is presently to create an architecture; it needs to
speak to top-down design in the architecture document.

As such, the deep technical dive is appropriate to the extent that it reveals
exchanges or components that need to exist but that we would otherwise have missed.

    > Just curious, though: what are the "two possible mechanisms"???

1) ZigbeeIP-like {1x,PANA} transported EAP-TLS resulting in a MSK being "pulled"
   by the new 6LN.

2) WirelessHART-like JOIN-network (partial?) connectivity resulting in a MSK being
   "pushed" to the new 6LN using 6top over CoAP/DTLS.

Both methods probably involve a 6lowpan-ND ARO step before you start,
possibly including initialization of the 6lowpan compression contexts
(possibly; because that may present a leak of information!), and both methods
can be made to work with 802.1AR certificates in the 6LN, and the network
trusted by TBD authorization token/certificate.

Those elements are, I think common.

--
Michael Richardson <mcr+IETF@sandelman.ca>, Sandelman Software Works
 -= IPv6 IoT consulting =-




--=-=-=
Content-Type: application/pgp-signature

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iQEVAwUBU4ZOFoCLcPvd0N1lAQLINggAp8CRee2QRTstUuqHRvaHk9jTp5lt/FmQ
tSTHdlFcsbgJyKbSALBXLzzlgy7JqNlhTjynIu/pqHk5qnbN4mW96P5Jy9ES2x4l
AiKQ65tkvdi0hgKkjPf1sjfHIQuG8XVg/YkuTdZWjlo0Rn0x1El8f1wv6eiQfmOg
ZL8nqDDuYdWOWqFJlTc0QjxYU7FIORV9qowyOnkZsLYPb22ZQYGaFCACJTtRp86X
wskHo92itVRv2QXSFzknyLNCB/FhuciC7MaABbTeouR5vd/jTHkCPWmB68S6XMgz
DrdIU5kxrkARO32Y3n94AF6HkNwZUbFScNMm9UrqC9KOy+Iu0FoV8Q==
=0M+/
-----END PGP SIGNATURE-----
--=-=-=--


From nobody Wed May 28 14:09:24 2014
Return-Path: <rstruik.ext@gmail.com>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 9662C1A069C for <6tisch-security@ietfa.amsl.com>; Wed, 28 May 2014 14:09:23 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2
X-Spam-Level: 
X-Spam-Status: No, score=-2 tagged_above=-999 required=5 tests=[BAYES_00=-1.9,  DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id GbYAObc3r5Wy for <6tisch-security@ietfa.amsl.com>; Wed, 28 May 2014 14:09:21 -0700 (PDT)
Received: from mail-ie0-x22a.google.com (mail-ie0-x22a.google.com [IPv6:2607:f8b0:4001:c03::22a]) (using TLSv1 with cipher ECDHE-RSA-RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id A563A1A06A6 for <6tisch-security@ietf.org>; Wed, 28 May 2014 14:09:21 -0700 (PDT)
Received: by mail-ie0-f170.google.com with SMTP id at1so10929929iec.15 for <6tisch-security@ietf.org>; Wed, 28 May 2014 14:09:16 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113;  h=message-id:date:from:user-agent:mime-version:to:cc:subject :references:in-reply-to:content-type:content-transfer-encoding; bh=exrOm3X2Y5bHrE9Ndex7OOzilpMiSuGA2LlMXFKERqc=; b=fJLbgSEQ6BdsgI7sYiGapjwmDtX5KplqV8r0XHk29Hto4lbZgBzQ47fJRs7raX6kiY 8dVWRuG7j3T2B4OUrn9kzdF3k/xhR6uAt+h1utG6jCoyoafxgA2pmtxERR33zeTqtsiD yK8x2niQDg01tMtY2v2P9fqdsJjUGT5PnDZq4eH2/PPfq+F5WjVbBeLvSrNIYuL6QyJX xzpFQQdla+tkMN3l2QWa6U3Ie1CLNejFVbuWiydLkZm/Daj9NZJFaRYI5nzU6uC+lni+ yfkiTaksRNsZRXjtveSXDPeEFsXG9J15A1s4gnraU+UDb/2Xv6/WzTDkhQ7H8A7xcREk UAXw==
X-Received: by 10.43.178.197 with SMTP id ox5mr2886388icc.22.1401311356863; Wed, 28 May 2014 14:09:16 -0700 (PDT)
Received: from [192.168.1.101] (CPE0013100e2c51-CM001cea35caa6.cpe.net.cable.rogers.com. [99.231.3.110]) by mx.google.com with ESMTPSA id rr2sm18535965igb.19.2014.05.28.14.09.15 for <multiple recipients> (version=TLSv1 cipher=ECDHE-RSA-RC4-SHA bits=128/128); Wed, 28 May 2014 14:09:16 -0700 (PDT)
Message-ID: <53865078.7010606@gmail.com>
Date: Wed, 28 May 2014 17:09:12 -0400
From: Rene Struik <rstruik.ext@gmail.com>
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:24.0) Gecko/20100101 Thunderbird/24.5.0
MIME-Version: 1.0
To: Michael Richardson <mcr+ietf@sandelman.ca>,  "6tisch-security@ietf.org" <6tisch-security@ietf.org>
References: <E045AECD98228444A58C61C200AE1BD8416F3AF4@xmb-rcd-x01.cisco.com> <531DD632.2060009@cox.net> <531DDB20.5050600@gmail.com> <10925.1394631496@sandelman.ca> <532069C8.2050005@gmail.com> <23590.1394999032@sandelman.ca> <18106.1395625035@sandelman.ca> <19609.1396839403@sandelman.ca> <11557.1397444260@sandelman.ca> <28192.1398644294@sandelman.ca> <29064.1399255587@sandelman.ca> <19475.1400588783@sandelman.ca> <4903.1401158997@sandelman.ca> <53840205.2070103@gmail.com> <5384046A.6080706@gmail.com> <E045AECD98228444A58C61C200AE1BD8426B036B@xmb-rcd-x01.cisco.com> <10436.1401198298@sandelman.ca> <53849841.4020401@gmail.com> <25059.1401220730@sandelman.ca> <26563.1401303435@sandelman.ca> <CADJ9OA_xYMWD5VU-THBTq=vL_cu9=0moHrQuLfOvZqK78OvbjQ@mail.gmail.com> <53863A5F.3000707@gmail.com> <20291.1401310743@sandelman.ca>
In-Reply-To: <20291.1401310743@sandelman.ca>
Content-Type: text/plain; charset=ISO-8859-1; format=flowed
Content-Transfer-Encoding: 7bit
Archived-At: http://mailarchive.ietf.org/arch/msg/6tisch-security/khur-RbM6KM3ruQNFukcW3JQxfo
Cc: Thomas Watteyne <watteyne@eecs.berkeley.edu>
Subject: Re: [6tisch-security] agenda for 2014-06-02 6tisch security call
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 28 May 2014 21:09:23 -0000

Well, let us discuss at next Monday's call...

Rene


On 5/28/2014 4:59 PM, Michael Richardson wrote:
> Rene Struik <rstruik.ext@gmail.com> wrote:
>      > Fine with me, as long as we dive into more detail of how things could/should
>      > work as well.
>
> The goal of this group is presently to create an architecture; it needs to
> speak to top-down design in the architecture document.
>
> As such, the deep technical dive is appropriate to the extent that it reveals
> exchanges or components that need to exist but that we would otherwise have missed.
>
>      > Just curious, though: what are the "two possible mechanisms"???
>
> 1) ZigbeeIP-like {1x,PANA} transported EAP-TLS resulting in a MSK being "pulled"
>     by the new 6LN.
>
> 2) WirelessHART-like JOIN-network (partial?) connectivity resulting in a MSK being
>     "pushed" to the new 6LN using 6top over CoAP/DTLS.
>
> Both methods probably involve a 6lowpan-ND ARO step before you start,
> possibly including initialization of the 6lowpan compression contexts
> (possibly; because that may present a leak of information!), and both methods
> can be made to work with 802.1AR certificates in the 6LN, and the network
> trusted by TBD authorization token/certificate.
>
> Those elements are, I think common.
>
> --
> Michael Richardson <mcr+IETF@sandelman.ca>, Sandelman Software Works
>   -= IPv6 IoT consulting =-
>
>
>


-- 
email: rstruik.ext@gmail.com | Skype: rstruik
cell: +1 (647) 867-5658 | US: +1 (415) 690-7363


From nobody Wed May 28 16:19:57 2014
Return-Path: <yoshihiro.ohba@toshiba.co.jp>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id A687E1A077B for <6tisch-security@ietfa.amsl.com>; Wed, 28 May 2014 16:19:53 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -0.352
X-Spam-Level: 
X-Spam-Status: No, score=-0.352 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HELO_EQ_JP=1.244, HOST_EQ_JP=1.265, HTML_MESSAGE=0.001, HTTPS_HTTP_MISMATCH=1.989, RCVD_IN_DNSWL_MED=-2.3, RP_MATCHES_RCVD=-0.651, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001, UNPARSEABLE_RELAY=0.001, WEIRD_PORT=0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id oEWq4quB9X96 for <6tisch-security@ietfa.amsl.com>; Wed, 28 May 2014 16:19:49 -0700 (PDT)
Received: from imx2.toshiba.co.jp (inet-tsb5.toshiba.co.jp [202.33.96.24]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 93EBE1A0779 for <6tisch-security@ietf.org>; Wed, 28 May 2014 16:19:48 -0700 (PDT)
Received: from arc1.toshiba.co.jp ([133.199.194.235]) by imx2.toshiba.co.jp  with ESMTP id s4SNJfgn029356; Thu, 29 May 2014 08:19:41 +0900 (JST)
Received: (from root@localhost) by arc1.toshiba.co.jp  id s4SNJfmO002498; Thu, 29 May 2014 08:19:41 +0900 (JST)
Received: from unknown [133.199.192.144]  by arc1.toshiba.co.jp with ESMTP id JAA02497; Thu, 29 May 2014 08:19:41 +0900
Received: from mx12.toshiba.co.jp (localhost [127.0.0.1]) by ovp2.toshiba.co.jp  with ESMTP id s4SNJfhi018768; Thu, 29 May 2014 08:19:41 +0900 (JST)
Received: from TGXML207.toshiba.local by toshiba.co.jp id s4SNJeg7002767; Thu, 29 May 2014 08:19:40 +0900 (JST)
Received: from TGXML210.toshiba.local ([169.254.4.46]) by TGXML207.toshiba.local ([133.199.70.16]) with mapi id 14.03.0181.006; Thu, 29 May 2014 08:19:40 +0900
From: <yoshihiro.ohba@toshiba.co.jp>
To: <jsimon@linear.com>
Thread-Topic: [6tisch-security] agenda for 2014-05-27 6tisch security call
Thread-Index: AQHPeVZhw54BHDP0SE+00Qrnll9n8JtTKLqAgACwMoCAAayJwP//+QQAgACYY+D//3fFAIABEy3g
Date: Wed, 28 May 2014 23:19:40 +0000
Message-ID: <674F70E5F2BE564CB06B6901FD3DD78B2723BA32@TGXML210.toshiba.local>
References: <E045AECD98228444A58C61C200AE1BD8416F3AF4@xmb-rcd-x01.cisco.com> <531DD632.2060009@cox.net> <531DDB20.5050600@gmail.com> <10925.1394631496@sandelman.ca> <532069C8.2050005@gmail.com> <23590.1394999032@sandelman.ca> <18106.1395625035@sandelman.ca> <19609.1396839403@sandelman.ca> <11557.1397444260@sandelman.ca> <28192.1398644294@sandelman.ca> <29064.1399255587@sandelman.ca> <19475.1400588783@sandelman.ca> <4903.1401158997@sandelman.ca> <53840205.2070103@gmail.com> <CAJeFcoS3PNFX2obx3uNDJDtH=QvNLmaPhw2R468sNaeqpo8QBQ@mail.gmail.com> <674F70E5F2BE564CB06B6901FD3DD78B2723B576@TGXML210.toshiba.local> <CAJeFcoQBp1A7pwZHWoesvrjSySW0UZ0k11-s3-MFAozSuR0Yrw@mail.gmail.com> <674F70E5F2BE564CB06B6901FD3DD78B2723B85A@TGXML210.toshiba.local> <1315B075-A0A5-4008-8CC9-4918F54CBED1@linear.com>
In-Reply-To: <1315B075-A0A5-4008-8CC9-4918F54CBED1@linear.com>
Accept-Language: ja-JP, en-US
Content-Language: ja-JP
x-originating-ip: [133.196.20.156]
msscp.transfermailtomossagent: 103
Content-Type: multipart/alternative; boundary="_000_674F70E5F2BE564CB06B6901FD3DD78B2723BA32TGXML210toshiba_"
MIME-Version: 1.0
Archived-At: http://mailarchive.ietf.org/arch/msg/6tisch-security/_OFwiIoxJOoqKs3SnTY-QA1dohg
Cc: mcr+ietf@sandelman.ca, rstruik.ext@gmail.com, 6tisch-security@ietf.org
Subject: Re: [6tisch-security] agenda for 2014-05-27 6tisch security call
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 28 May 2014 23:19:53 -0000

--_000_674F70E5F2BE564CB06B6901FD3DD78B2723BA32TGXML210toshiba_
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: base64

SGkgSm9uYXRoYW4sDQoNCkkgYW0gbm90IGNhcmluZyBhYm91dCBhbiBhdHRhY2tlciB0byBpbmpl
Y3Qgam9pbmluZyB0cmFmZmljLCBidXQgd2hhdCBJIGNhcmUgaXMgYW4gYXR0YWNrZXIgYXR0ZW1w
dGluZyB0byBkZXN0cnVjdCBiYXNpYyBUU0NIIG9wZXJhdGlvbiBpbiB0aGUgbmV0d29yayBieSBz
ZW5kaW5nIGZvcmdlZCBiZWFjb25zIHByb3RlY3RlZCB3aXRoIHRoZSB3ZWxsLWtub3duIGtleS4N
Cg0KWW9zaGloaXJvIE9oYmENCg0KDQoNCkZyb206IDZ0aXNjaC1zZWN1cml0eSBbbWFpbHRvOjZ0
aXNjaC1zZWN1cml0eS1ib3VuY2VzQGlldGYub3JnXSBPbiBCZWhhbGYgT2YgSm9uYXRoYW4gU2lt
b24NClNlbnQ6IFRodXJzZGF5LCBNYXkgMjksIDIwMTQgMTI6NDcgQU0NClRvOiBvaGJhIHlvc2hp
aGlybyjlpKfloLQg576p5rSLIOKXi++8su+8pO+8o+KWoe+8ru+8s++8rCkNCkNjOiBtY3IraWV0
ZkBzYW5kZWxtYW4uY2E7IHJzdHJ1aWsuZXh0QGdtYWlsLmNvbTsgNnRpc2NoLXNlY3VyaXR5QGll
dGYub3JnDQpTdWJqZWN0OiBSZTogWzZ0aXNjaC1zZWN1cml0eV0gYWdlbmRhIGZvciAyMDE0LTA1
LTI3IDZ0aXNjaCBzZWN1cml0eSBjYWxsDQoNCllvc2hpaGlybyAtDQoNCkkgZG9u4oCZdCB0aGlu
ayB0aGlzIGlzIGEgcHJvYmxlbS4gIE5vZGVzIHRoYXQgYXJlIGluIHRoZSBuZXR3b3JrIHJlamVj
dCBpbmNvbWluZyBmcmFtZXMgc2VjdXJlZCB3aXRoIHRoZSB3ZWxsLWtub3duIGtleS4gVGhlIHdl
bGwta25vd24ga2V5IGlzIG9ubHkgdXNlZCB0byBhdXRoZW50aWNhdGUgYmVhY29ucywgYW5kIGF1
dGhlbnRpY2F0ZSBqb2luIHJlcXVlc3RzICh3aGljaCBkb27igJl0IGNhcnJ5IHN5bmNocm9uaXph
dGlvbiBpbmZvcm1hdGlvbikuICBUaGVyZSBpcyBhIERvUyB2ZWN0b3IsIGluIHRoYXQgYW4gYXR0
YWNrZXIgY2FuIGluamVjdCBqb2luaW5nIHRyYWZmaWMgKGRlc3RpbmVkIGZvciB0aGUgbmV0d29y
ayBtYW5hbmFnZXIpIHRoYXQgd2lsbCB1bHRpbWF0ZWx5IGJlIGRpc2NhcmRlZCwgcG9zc2libHkg
cHJldmVudGluZyBvdGhlciBub2RlcyBmcm9tIGpvaW5pbmcsIGFuZCBpbmNyZWFzaW5nIHRoZSB0
cmFmZmljIGluIHRoZSBuZXR3b3JrLg0KDQpKb25hdGhhbiBTaW1vbiwgUGguIEQNCkRpcmVjdG9y
IG9mIFN5c3RlbXMgRW5naW5lZXJpbmcNCkxpbmVhciBUZWNobm9sb2d5LCBEdXN0IE5ldHdvcmtz
IHByb2R1Y3QgZ3JvdXANCjMwNjk1IEh1bnR3b29kIEF2ZQ0KSGF5d2FyZCwgQ0EgOTQ1NDQtNzAy
MQ0KKDUxMCkgNDAwLTI5MzYNCig1MTApIDQ4OS0zNzk5IEZBWA0KanNpbW9uQGxpbmVhci5jb208
bWFpbHRvOmpzaW1vbkBsaW5lYXIuY29tPg0KDQoqKkxJTkVBUiBURUNITk9MT0dZIENPUlBPUkFU
SU9OKioNCioqKioqSW50ZXJuZXQgRW1haWwgQ29uZmlkZW50aWFsaXR5IE5vdGljZSoqKioqDQog
VGhpcyBlLW1haWwgdHJhbnNtaXNzaW9uLCBhbmQgYW55IGRvY3VtZW50cywgZmlsZXMgb3IgcHJl
dmlvdXMgZS1tYWlsIG1lc3NhZ2VzIGF0dGFjaGVkIHRvIGl0IG1heSBjb250YWluIGNvbmZpZGVu
dGlhbCBpbmZvcm1hdGlvbiB0aGF0IGlzIGxlZ2FsbHkgcHJpdmlsZWdlZC4gSWYgeW91IGFyZSBu
b3QgdGhlIGludGVuZGVkIHJlY2lwaWVudCwgb3IgYSBwZXJzb24gcmVzcG9uc2libGUgZm9yIGRl
bGl2ZXJpbmcgaXQgdG8gdGhlIGludGVuZGVkIHJlY2lwaWVudCwgeW91IGFyZSBoZXJlYnkgbm90
aWZpZWQgdGhhdCBhbnkgZGlzY2xvc3VyZSwgY29weWluZywgZGlzdHJpYnV0aW9uIG9yIHVzZSBv
ZiBhbnkgb2YgdGhlIGluZm9ybWF0aW9uIGNvbnRhaW5lZCBpbiBvciBhdHRhY2hlZCB0byB0aGlz
IHRyYW5zbWlzc2lvbiBpcyBTVFJJQ1RMWSBQUk9ISUJJVEVELiBJZiB5b3UgaGF2ZSByZWNlaXZl
ZCB0aGlzIHRyYW5zbWlzc2lvbiBpbiBlcnJvciwgcGxlYXNlIGltbWVkaWF0ZWx5IG5vdGlmeSBt
ZSBieSByZXBseSBlLW1haWwsIG9yIGJ5IHRlbGVwaG9uZSBhdCAoNTEwKSA0MDAtMjkzNiwgYW5k
IGRlc3Ryb3kgdGhlIG9yaWdpbmFsIHRyYW5zbWlzc2lvbiBhbmQgaXRzIGF0dGFjaG1lbnRzIHdp
dGhvdXQgcmVhZGluZyBvciBzYXZpbmcgaW4gYW55IG1hbm5lci4gVGhhbmsgeW91Lg0KDQpPbiBN
YXkgMjgsIDIwMTQsIGF0IDg6MDEgQU0sIDx5b3NoaWhpcm8ub2hiYUB0b3NoaWJhLmNvLmpwPG1h
aWx0bzp5b3NoaWhpcm8ub2hiYUB0b3NoaWJhLmNvLmpwPj4gPHlvc2hpaGlyby5vaGJhQHRvc2hp
YmEuY28uanA8bWFpbHRvOnlvc2hpaGlyby5vaGJhQHRvc2hpYmEuY28uanA+PiB3cm90ZToNCg0K
DQpIaSBKb25hdGhhbiwNCg0KVGhhbmsgeW91IGZvciB5b3VyIGFuc3dlci4NCg0KSSB0aGluayB0
aGlzIGNhbiBiZSBhbiBpc3N1ZSBpZiBhbHJlYWR5IGpvaW5lZCBub2RlcyBhbHNvIHVzZSB0aGUg
YmVhY29ucyBwcm90ZWN0ZWQgd2l0aCB0aGUgd2VsbC1rbm93biBrZXkgZm9yIG1haW50YWluaW5n
IHN5bmNocm9uaXphdGlvbiBhbmQgc2xvdCBhbGxvY2F0aW9ucywgYXMgYW4gYXR0YWNrZXIgY2Fu
IHNlbmQgZm9yZ2VkIGJlYWNvbnMgcHJvdGVjdGVkIHdpdGggdGhlIHdlbGwta25vd24ga2V5Lg0K
DQpZb3NoaWhpcm8gT2hiYQ0KDQoNCkZyb206IDZ0aXNjaC1zZWN1cml0eSBbbWFpbHRvOjZ0aXNj
aC1zZWN1cml0eS1ib3VuY2VzQGlldGYub3JnXSBPbiBCZWhhbGYgT2YgSm9uYXRoYW4gU2ltb24N
ClNlbnQ6IFdlZG5lc2RheSwgTWF5IDI4LCAyMDE0IDExOjQ5IFBNDQpUbzogb2hiYSB5b3NoaWhp
cm8o5aSn5aC0IOe+qea0iyDil4vvvLLvvKTvvKPilqHvvK7vvLPvvKwpDQpDYzogTWljaGFlbCBS
aWNoYXJkc29uOyBSZW5lIFN0cnVpazsgNnRpc2NoLXNlY3VyaXR5QGlldGYub3JnPG1haWx0bzo2
dGlzY2gtc2VjdXJpdHlAaWV0Zi5vcmc+DQpTdWJqZWN0OiBSZTogWzZ0aXNjaC1zZWN1cml0eV0g
YWdlbmRhIGZvciAyMDE0LTA1LTI3IDZ0aXNjaCBzZWN1cml0eSBjYWxsDQoNCllvc2hpaGlybyAt
DQoNClEuIEluIHcvSEFSVCwgYXJlIGFsbCBiZWFjb24gZnJhbWVzIGF1dGhlbnRpY2F0ZWQgd2l0
aCBhIHdlbGwta25vd24ga2V5IGV2ZW4gYWZ0ZXIgYSBqb2luaW5nIG5vZGUgb2J0YWluZWQgdGhl
IHJ1bnRpbWUgbGluayBsYXllciBrZXk/DQpBLiBZZXMuIEluIFdpcmVsZXNzSEFSVCB0aGUgYmVh
Y29ucyAoY2FsbGVkICJhZHZlcnRpc2VtZW50cyIgYnV0IHRoZXkgc2VydmUgdGhlIHNhbWUgcHVy
cG9zZSBhbmQgaGF2ZSBzaW1pbGFyIGNvbnRlbnQpIGFyZSBpbnRlbmRlZCBmb3IgZGV2aWNlcyBu
b3QgeWV0IGluIHRoZSBuZXR3b3JrLCBzbyB0aGV5IGFsd2F5cyB1c2UgdGhlIHdlbGwta25vd24g
a2V5LiAgVG8gZGlzY292ZXIgb3RoZXIgbm9kZXMgd2l0aGluIHRoZSBuZXR3b3JrLCB0aGV5IHVz
ZSBmcmFtZXMgc2VjdXJlZCB3aXRoIHRoZSBydW50aW1lIGxpbmstbGF5ZXIga2V5Lg0KSm9uYXRo
YW4NCg0KT24gVHVlLCBNYXkgMjcsIDIwMTQgYXQgMTE6MTggUE0sIDx5b3NoaWhpcm8ub2hiYUB0
b3NoaWJhLmNvLmpwPG1haWx0bzp5b3NoaWhpcm8ub2hiYUB0b3NoaWJhLmNvLmpwPj4gd3JvdGU6
DQpIaSBKb25hdGhhbiwNCg0KVGhhbmsgeW91IGZvciBzZW5kaW5nIHRoZSBzdW1tYXJ5IG9mIHcv
SEFSVCBqb2luaW5nLg0KDQpJIGhhdmUgcXVlc3Rpb24uDQoNCkluIHcvSEFSVCwgYXJlIGFsbCBi
ZWFjb24gZnJhbWVzIGF1dGhlbnRpY2F0ZWQgd2l0aCBhIHdlbGwta25vd24ga2V5IGV2ZW4gYWZ0
ZXIgYSBqb2luaW5nIG5vZGUgb2J0YWluZWQgdGhlIHJ1bnRpbWUgbGluayBsYXllciBrZXk/DQoN
ClJlZ2FyZHMsDQpZb3NoaWhpcm8gT2hiYQ0KDQoNCg0KDQpGcm9tOiA2dGlzY2gtc2VjdXJpdHkg
W21haWx0bzo2dGlzY2gtc2VjdXJpdHktYm91bmNlc0BpZXRmLm9yZzxtYWlsdG86NnRpc2NoLXNl
Y3VyaXR5LWJvdW5jZXNAaWV0Zi5vcmc+XSBPbiBCZWhhbGYgT2YgSm9uYXRoYW4gU2ltb24NClNl
bnQ6IFR1ZXNkYXksIE1heSAyNywgMjAxNCAxMDo0MSBQTQ0KVG86IFJlbmUgU3RydWlrDQpDYzog
TWljaGFlbCBSaWNoYXJkc29uOyA2dGlzY2gtc2VjdXJpdHlAaWV0Zi5vcmc8bWFpbHRvOjZ0aXNj
aC1zZWN1cml0eUBpZXRmLm9yZz4NClN1YmplY3Q6IFJlOiBbNnRpc2NoLXNlY3VyaXR5XSBhZ2Vu
ZGEgZm9yIDIwMTQtMDUtMjcgNnRpc2NoIHNlY3VyaXR5IGNhbGwNCg0KUmVuZSBoYWQgYXNrZWQg
b24gYSBwcmV2aW91cyBjYWxsIGZvciBzb21lb25lIHRvIHN1bW1hcml6ZSBXaXJlbGVzc0hBUlQg
am9pbmluZyAtIGhlcmUgeW91IGdvLg0KDQoqIE9uZSBvciBtb3JlIGRldmljZXMgYXJlIHNlbmRp
bmcgYmVhY29ucyB0byBhZHZlcnRpc2UgdGhlIHByZXNlbmNlIG9mIHRoZSBuZXR3b3JrLiBJbiBX
aXJlbGVzc0hBUlQsIHRoaXMgZnJhbWUgaXMgdW5lbmNyeXB0ZWQsIGJ1dCBhdXRoZW50aWNhdGVk
IHdpdGggYSB3ZWxsIGtub3duIGtleS4gIFRoZSBiZWFjb24gY29udGFpbnMgdGhlIGN1cnJlbnQg
QVNOLCB3aGljaCB0aGUgam9pbmluZyBkZXZpY2UgdXNlcyB0byBzeW5jaHJvbml6ZSBpdHMgY2xv
Y2suDQoqIE9uY2UgdGhlIGpvaW5pbmcgbm9kZSBoYXMgaGVhcmQgYSBiZWFjb24sIGl0IGNvbnRp
bnVlcyBsaXN0ZW5pbmcgZm9yIGFkZGl0aW9uYWwgYmVhY29ucyBmb3IgYSBzaG9ydCBzcGVjaWZp
ZWQgdGltZW91dC4NCiogVGhlIGpvaW5pbmcgbm9kZSBlbmNyeXB0cyBhIGZyYW1lIGNvbnRhaW5p
bmcgc29tZSBIQVJUIHNwZWNpZmljIGNvbnRlbnQsIGluY2x1ZGluZyBhIGxpc3Qgb2YgYmVhY29u
aW5nIG5laWdoYm9ycyBpdCBoZWFyZCBpbiB0aGUgcHJldmlvdXMgc3RlcHMuIFRoZSBzaXplIG9m
IHRoZSBwYXlsb2FkIGlzIH4gNjAgYnl0ZXMuICBUaGUgcGFja2V0IGlzIHJvdXRlZCBieSBhICJw
cm94eSIgbm9kZSAtIHRoZSBqb2luaW5nIHBhcmVudC4gVGhlIGZyYW1lIGlzIGF1dGhlbnRpY2F0
ZWQgdXNpbmcgdGhlIHdlbGwta25vd24ga2V5LCBhbmQgZW5jcnlwdGVkIHVzaW5nIGEgc2hhcmVk
IHN5bW1ldHJpYyBrZXkga25vd24gb25seSBieSB0aGUgbm9kZSBhbmQgdGhlIG1hbmFnZXIuDQoN
CiogVGhlIG1hbmFnZXIgcmVzcG9uZHMgd2l0aCBhIGZyYW1lIGNvbnRhaW5pbmcgdGhlIHJ1bi10
aW1lIGxpbmstbGF5ZXIga2V5LCB0aGUgbm9kZSdzIG5ldyBzaG9ydCBhZGRyZXNzICh0aGlzIHRh
a2VzIHRoZSBwbGFjZSBvZiBQQU4gY29vcmRpbmF0b3IgYXNzb2NpYXRpb24pLCBhbmQgYSB1bmlj
YXN0IHNlc3Npb24ga2V5IGFuZCBzdGFydGluZyBub25jZSBmb3IgdGhlIG1hbmFnZXIuIFRoaXMg
ZnJhbWUgaXMgZW5jcnlwdGVkIHdpdGggdGhlIHN5bW1ldHJpYyBrZXkuIFRoZSBwYXlsb2FkIGlz
IH4gNjAgYnl0ZXMsIGFuZCBpcyByb3V0ZWQgdG8gdGhlIHByb3h5IGZvciBkZWxpdmVyeSB0byB0
aGUgam9pbmluZyBub2RlIC0gdGhlIHByb3h5IHVzZXMgdGhlIGxpbmstbGF5ZXIgd2VsbCBrbm93
biBrZXkgb24gdGhlIGZyYW1lLg0KKiBBdCB0aGlzIHBvaW50IHRoZSBqb2luaW5nIG5vZGUgdHJh
bnNpdGlvbnMgdG8gdXNpbmcgdGhlIHJ1bi10aW1lIGxpbmstbGF5ZXIga2V5IGZvciBhbGwgbGlu
ay1sYXllciBmcmFtZXMsIGFuZCB0aGUgbWFuYWdlciB1bmljYXN0IHNlc3Npb24gZm9yIGVuZC10
by1lbmQgbWFuYWdlciB0cmFmZmljLiBUaGlzIGVuZHMgdGhlIGluaXRpYWwgc2VjdXJpdHkgaGFu
ZHNoYWtlLg0KKiBPdmVyIGEgbnVtYmVyIG9mIGFkZGl0aW9uYWwgZnJhbWVzLCB0aGUgbWFuYWdl
ciBhc3NpZ25zIGFkZGl0aW9uYWwgc2Vzc2lvbnMsIGluY2x1ZGluZyBicm9hZGNhc3Qgc2Vzc2lv
bnMsIGFuZCBhIHVuaWNhc3Qgc2Vzc2lvbiB0byB0aGUgR2F0ZXdheSAoc2luayBmb3IgYWxsIGRh
dGEgdHJhZmZpYyksIGFuZCBhZGRpdGlvbmFsIGNvbW11bmljYXRpb25zIHJlc291cmNlcywgcm91
dGluZyBpbmZvcm1hdGlvbiwgZXRjLiAgVGhlcmUgaXMgbm8gZXhwbGljaXQgdHJhbnNpdGlvbiBm
cm9tIGpvaW5pbmcgdG8gam9pbmVkIC0gdGhlIG1vdGUgdHJhbnNpdGlvbnMgd2hlbiBjZXJ0YWlu
IGtleSBmcmFtZXMgYXJlIHJlY2VpdmVkLg0KKiBOb3RlIHRoYXQgYSBXaXJlbGVzc0hBUlQgbGlu
ay1sYXllciBmcmFtZSBjb250YWlucyBhbmQgYWRkaXRpb25hbCBmcmFtZSB0eXBlIGJ5dGUgYW5k
IGEgNC1ieXRlIGxpbmstbGF5ZXIgTUlDLCBvbiB0b3Agb2YgdGhlIHVuc2VjdXJlZCAxNS40IGZy
YW1lLiAgQSBuZXR3b3JrIGZyYW1lIGNvbnRhaW5zIGFuIGFkZGl0aW9uYWwgMTYtNDAgYnl0ZXMg
b2YgYWRkcmVzc2luZywgcm91dGluZywgc2VjdXJpdHkgYW5kIG90aGVyIGluZm9ybWF0aW9uLg0K
SG9wZSB0aGlzIGhlbHAhDQpKb25hdGhhbg0KDQoNCk9uIE1vbiwgTWF5IDI2LCAyMDE0IGF0IDg6
MDkgUE0sIFJlbmUgU3RydWlrIDxyc3RydWlrLmV4dEBnbWFpbC5jb208bWFpbHRvOnJzdHJ1aWsu
ZXh0QGdtYWlsLmNvbT4+IHdyb3RlOg0KSGkgTWljaGFlbDoNCg0KSSB3b3VsZCBsaWtlIHRvIGRp
c2N1c3MgdGhlIG91dHN0YW5kaW5nIGlzc3VlcyBJIHN1bW1hcml6ZWQgaW4gbXkgZW1haWwgb2Yg
VHVlIGxhc3Qgd2VlaywgTWF5IDIwLCAyMDE0LCA5OjQ1YW0gRURUIChzZWUgaHR0cDovL3d3dy5p
ZXRmLm9yZy9tYWlsLWFyY2hpdmUvd2ViLzZ0aXNjaC1zZWN1cml0eS9jdXJyZW50L21zZzAwMDg2
Lmh0bWw8aHR0cDovL2NwLm1jYWZlZS5jb20vZC81ZkhDTVVwNDFFU3lOdDU1T1d0U2p0UHFid1ZC
Y1N5VWVwdmRFSzN6aE95Q09xZWpyelBQUHo1WENONkFCcU0xaFlFdkl1bmRET3gtTlZzVEpRWElm
Y0xadkM0VFFUUzZlTHNLQ08tUFBYWDNYVVZ6QkhGU2hqbEtlcFZrZmZHaEJyd3FyaGRJNlhZeU1D
WS1laG9qZDc5S1ZJMDViVktZMDFNamJYNk5laERZMDV6QVZrSWpiUS1Qc3BqYnBwS2N2eGY1cTRy
VEtZVk1lZEtqQmlOY0xqWGROQmNJbjhscnhyVzBHblB0VTAycmhodWhLcjF2RjZ5MFFKS2pCaU5j
TGpYZE5CY0lxbmpoMUY3VThxcTg3cU5kNDJ0UW0yWlRPV29VUWdlakJpTmNRZ2stUHNwamI2eTJT
RERDVDYzcE9fbz4pLiBUaGlzIHdhcyBhbHNvIG9uZSBvZiB0aGUgYWN0aW9uIGl0ZW1zIGF0IHRo
ZSBjb25jbHVzaW9uIG9mIGxhc3Qgd2VlaydzIDZUaVNDSCBzZWN1cml0eSBjYWxsLg0KDQpGWUkg
LSB0aGUgdy9IQVJUIGNvbW11bmljYXRpb24gZmxvd3Mgd2VyZSBkaXNjdXNzZWQgZHVyaW5nIHRo
ZSA2VGlTQ0ggc2VjdXJpdHkgY29uZiBjYWxsIHRoZSB3ZWVrIGJlZm9yZSwgb24gTW9uIE1heSAx
MiwgMjAxNC4gSWYgb25lIHdpc2hlcyB0byBnbyBvdmVyIHRoaXMgYWdhaW4sIHRoYXQgaXMgZmlu
ZSwgYnV0IEkgd291bGQgcHJlZmVyIHVzIGdpdmluZyBwcmVmZXJlbmNlIHRvIHRha2luZyBvbiBh
bHJlYWR5IGFydGljdWxhdGVkIGlzc3VlcyAod2hpY2ggd2VyZSBhc3NpZ25lZCBhcyBob21ld29y
ayBhc3NpZ25tZW50IHRvIHJlZmxlY3QgdXBvbikgZmlyc3QgKGkuZS4sIHByaW9yIHRvIGl0ZW0g
IzQgb2YgdGhlIHByb3Bvc2VkIGFnZW5kYSkuDQoNCkFzIGFub3RoZXIgYWdlbmRhIHBvaW50LCBJ
IHdvdWxkIGxpa2UgdXMgdG8gZGlzY3VzcyB0aGUgZnJlcXVlbmN5IG9mIGZ1dHVyZSBjYWxscyAo
YXMgcGFydCBvZiBFT0IpLg0KDQpCZXN0IHJlZ2FyZHMsIFJlbmUNCg0KDQpPbiA1LzI2LzIwMTQg
MTA6NDkgUE0sIE1pY2hhZWwgUmljaGFyZHNvbiB3cm90ZToNCg0KVG8gcmVtaW5kLCB3ZSBtb3Zl
ZCB0aGUgY2FsbCBmcm9tIHRoZSAyNnRoIHRvIHRoZSAyN3RoIGF0IDEwYW0gRURULg0KDQpUaGF0
J3MgOTAgbWludXRlcyBmcm9tIHRoaXMgZW1haWwuDQoNCg0KDQoxKSBub3Rld2VsbC4NCg0KMikg
aW50cm9zDQoNCjMpIHJlY2FwIG9mIGRyYWZ0LXBpcm8tDQoNCjQpIHdpcmVsZXNzaGFydCAtd2F5
IC0tLSBob3cgZG9lcyB0aGUgY29tbXVuaWNhdGlvbiB3b3JrPw0KDQo1KSBob3cgdG8gc3VtbWFy
aXplIGFsbCBvZiB0aGlzIHRvIHRoZSB3b3JraW5nIGdyb3VwDQoNCjYpIGhvdyB0byBjbG9zZSB0
aGlzIHByb2Nlc3MgdXA/DQoNCg0KDQotLSByZW1lbWJlciB0aGF0IHRoZSBjYWxsIGlzIHJlY29y
ZGVkLCBhbmQgdGhlIE5vdGVXZWxsIGFwcGxpZXMuDQoNCg0KDQotLSBUaGUgVVJMIHRvIGFjY2Vz
cyB0aGUgd2ViZXgsIHdoaWNoIHdpbGwgd2UgdXNlIGZvciBhdWRpbyBvbmx5Og0KDQogIGh0dHBz
Oi8vY2lzY28ud2ViZXguY29tL2Npc2NvL2oucGhwP01USUQ9bTJmZTEzOWJmODc2Y2VhM2VjNjI3
NTBjZDU4MGI3OTA4PGh0dHA6Ly9jcC5tY2FmZWUuY29tL2QvNWZIQ04wU3lOdDU1T1d0U2p0UHFi
d1ZCY1N5VWVwdmRFSzN6aE95Q09xZWpyelBQUHo1WENONkFCcU0xaFlFdkl1bmRET3gtTlZzVEpR
WElmY0xadkM0VFFUUzZlTHNLQ08tUFBYWDNYVVZ6QkhGU2hqbEtlcFZrZmZHaEJyd3FyamRJNlhZ
eU1DWS1laG9qZDc5S1ZJRGVxUjRJT1FHbUhNMEwzLW5PUUdtSHd6TWg5M285M2dVVmxkVFFtamhP
Z3R1N2VtX212SVVDZXZMcDFaV1Ywc3Flckw2VDlPRm9DbkZaQ1VPQ21iQWFKTUpaMGxiVktZMDFk
RUVMOFRkd0xRemgwcW1UOU9Gb0NuRlpDVU9DbWRiRkV3UXpZNGRkNDNKb0N5MWVXYjF1WFZ0Y3Nx
ODc5T0ZvQ3E4YXZwS2NGQnpoMXJqUFByejFMbVR3N3cxNz4NCg0KDQoNCi0tIHdlIHdpbGwgcmVz
dW1lIHdpdGggdGhlIGV0aGVycGFkIGF0Og0KDQogICBodHRwOi8vZXRoZXJwYWQudG9vbHMuaWV0
Zi5vcmc6OTAwMC9wL25vdGVzLWlldGYtODktNnRpc2NoLXNlY3VyaXR5PGh0dHA6Ly9jcC5tY2Fm
ZWUuY29tL2QvMkRSUG93NzFOSjV5V2FiQlFYSUNYQ1FuMVBhcEo1TXNPLXJoczc2ekI1ZEFRc0NU
N0RERDZiVGR5ZDlhUncyelZnX29ZS3JmQjNaek9WTHJGVG91cHZXX2M5TEZMSWN0dVZ0ZEJaRERU
UzdUTlA3Ym5qSXlDSHNzUE9FdXZremFUMFFTT3JvZFRWNXhkVllzeU1DcWVqdFBvMGZWQV95Skc3
akhrLURpLXJMMDBremhQdVpZbU81cF9nTGJWS0JUemhPbnNEYUJ5cHVEU3J6YXBvU1ZlbGI0T1pm
SVQ2a09Oc3hsSzVMRTJGdmRUdzA5SjU1VjZWSTUtQXE4M2lTVmVsYjRPWmZJVDZrT05GdGQ0NkF2
d3hGRXd0SDRRZzlUaG9iVHZiRnp6aDBWZWxiNFBoMWpYZE5CY0lxOGJxdXVyc29kSmladnBtSzZH
d1k+DQoNCg0KDQpJJ20gYXQgKzEgNjEzIDI3Ni02ODA5PHRlbDolMkIxJTIwNjEzJTIwMjc2LTY4
MDk+LCBJTTogbWNyQHhtcHAuY3JlZGlsLm9yZzxtYWlsdG86bWNyQHhtcHAuY3JlZGlsLm9yZz4g
b3IgbWNoYXJsZXNyQGdtYWlsLmNvbTxtYWlsdG86bWNoYXJsZXNyQGdtYWlsLmNvbT4sDQoNCmlm
IHlvdSBuZWVkIG1vcmUgdGhhbiB0aGF0IHRvIGdldCBpbiwgb3IgYXJlIGhhdmluZyBkaWZmaWN1
bHRpZXMuDQoNClBsZWFzZSBtYWtlIHN1cmUgeW91ciBhdWRpbyB3b3JrcywgYW5kIHRoYXQgeW91
IG11dGUgd2hlbiBub3QgdGFsa2luZy4NCg0KDQoNCi0tDQoNCk1pY2hhZWwgUmljaGFyZHNvbiA8
bWNyK0lFVEZAc2FuZGVsbWFuLmNhPjxtYWlsdG86bWNyK0lFVEZAc2FuZGVsbWFuLmNhPiwgU2Fu
ZGVsbWFuIFNvZnR3YXJlIFdvcmtzDQoNCiAtPSBJUHY2IElvVCBjb25zdWx0aW5nID0tDQoNCg0K
DQoNCg0KDQoNCg0KX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19f
X18NCg0KNnRpc2NoLXNlY3VyaXR5IG1haWxpbmcgbGlzdA0KDQo2dGlzY2gtc2VjdXJpdHlAaWV0
Zi5vcmc8bWFpbHRvOjZ0aXNjaC1zZWN1cml0eUBpZXRmLm9yZz4NCg0KaHR0cHM6Ly93d3cuaWV0
Zi5vcmcvbWFpbG1hbi9saXN0aW5mby82dGlzY2gtc2VjdXJpdHk8aHR0cDovL2NwLm1jYWZlZS5j
b20vZC8yRFJQb084NlFtYkVFS25qS09yS3JoczdjRkNRbjFQYlZKNU1zcWVra1NqaE9yc3V1dXNv
THNTOFFBSG0wYWZCM1p6T1ZJLWtmU2ZiQ1pLRHR4VkJfSFlNQy1DLU1OUlhCUVNuU3V2dm92djdj
c0p0ZU9hcUpOUGZheFZaaWNIczNqcjFKd1R2QW00VEROT2IycEVWZFRkQVZQbUVCQzVlQllUdTAw
VTlHWDMzVmtEYTNKc3NEYUJ5cHVEU3J6YXBvU1ZlbGI0T1pmSVQ2a09Oc3hsSzVMRTJGdmRUdzA5
SjU1VjZWSTUtQXE4M2lTVmVsYjRPWmZJVDZrT05GdGQ0NkF2d3hGRXd0SDRRZzlUaG9iVHZiRnp6
aDBWZWxiNFBoMWpYZE5CY0lxOGJxdXVyc29kTFdidj4NCg0KDQoNCg0KLS0NCg0KZW1haWw6IHJz
dHJ1aWsuZXh0QGdtYWlsLmNvbTxtYWlsdG86cnN0cnVpay5leHRAZ21haWwuY29tPiB8IFNreXBl
OiByc3RydWlrDQoNCmNlbGw6ICsxICg2NDcpIDg2Ny01NjU4PHRlbDolMkIxJTIwJTI4NjQ3JTI5
JTIwODY3LTU2NTg+IHwgVVM6ICsxICg0MTUpIDY5MC03MzYzPHRlbDolMkIxJTIwJTI4NDE1JTI5
JTIwNjkwLTczNjM+DQoNCl9fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19f
X19fX19fDQo2dGlzY2gtc2VjdXJpdHkgbWFpbGluZyBsaXN0DQo2dGlzY2gtc2VjdXJpdHlAaWV0
Zi5vcmc8bWFpbHRvOjZ0aXNjaC1zZWN1cml0eUBpZXRmLm9yZz4NCmh0dHA6Ly9jcC5tY2FmZWUu
Y29tL2QvYXZuZHpnUTkzZ0FyaG9LeXlWdGVYOUtWSjVNc09DcmhzN2NMQ1FuMU5FVmhqcGQ3OUpO
VlZWTnlaUG96aWlKbzBFLWtmU2ZiQ1BWZ19vWUtyU1d0UzdDbi1MUDJyV3JYMzduS25qcHZwVlpa
eFpZc05PUlFYOEZHVDdjWUc3RFI4T0pNZGRFQ1FqdC1ob2p1djc4STlDekFUc1NqRGRxeW1va1du
UHRVMDN3Q0hJY2ZCaXNFZVJOT3NHbTlCV3ZwS2NGQnpyQVZrSWpiUS1Qc3BqYjVPNW1VbS13YUJZ
VHUwMENRa25BckNNbldoRXdkYnJBVmtJamJRLVBzcGpiNkJRUWdxaC0yNkN5MVNJamgwRHQ1d0x0
WUtDZWQ0M0FWa0lqZDQ1ZklUNmtPTkV3SkZWVkpOd1NlVmhzckxlLUZrZA0KDQoNCg0KLS0NCi0t
DQpKb25hdGhhbiBTaW1vbiwgUGguIEQNCkRpcmVjdG9yIG9mIFN5c3RlbXMgRW5naW5lZXJpbmcN
CkR1c3QgTmV0d29ya3MgYXQgTGluZWFyIFRlY2hub2xvZ3kNCjMwNjk1IEh1bnR3b29kIEF2ZQ0K
SGF5d2FyZCwgQ0EgOTQ1NDQtNzAyMQ0KKDUxMCkgNDAwLTI5MzY8dGVsOiUyODUxMCUyOSUyMDQw
MC0yOTM2Pg0KKDUxMCkgNDg5LTM3OTk8dGVsOiUyODUxMCUyOSUyMDQ4OS0zNzk5PiBGQVgNCmpz
aW1vbkBsaW5lYXIuY29tPG1haWx0bzpqc2ltb25AbGluZWFyLmNvbT4NCg0KKipMSU5FQVIgVEVD
SE5PTE9HWSBDT1JQT1JBVElPTioqDQoqKioqKkludGVybmV0IEVtYWlsIENvbmZpZGVudGlhbGl0
eSBOb3RpY2UqKioqKg0KIFRoaXMgZS1tYWlsIHRyYW5zbWlzc2lvbiwgYW5kIGFueSBkb2N1bWVu
dHMsIGZpbGVzIG9yIHByZXZpb3VzIGUtbWFpbCBtZXNzYWdlcyBhdHRhY2hlZCB0byBpdCBtYXkg
Y29udGFpbiBjb25maWRlbnRpYWwgaW5mb3JtYXRpb24gdGhhdCBpcyBsZWdhbGx5IHByaXZpbGVn
ZWQuIElmIHlvdSBhcmUgbm90IHRoZSBpbnRlbmRlZCByZWNpcGllbnQsIG9yIGEgcGVyc29uIHJl
c3BvbnNpYmxlIGZvciBkZWxpdmVyaW5nIGl0IHRvIHRoZSBpbnRlbmRlZCByZWNpcGllbnQsIHlv
dSBhcmUgaGVyZWJ5IG5vdGlmaWVkIHRoYXQgYW55IGRpc2Nsb3N1cmUsIGNvcHlpbmcsIGRpc3Ry
aWJ1dGlvbiBvciB1c2Ugb2YgYW55IG9mIHRoZSBpbmZvcm1hdGlvbiBjb250YWluZWQgaW4gb3Ig
YXR0YWNoZWQgdG8gdGhpcyB0cmFuc21pc3Npb24gaXMgU1RSSUNUTFkgUFJPSElCSVRFRC4gSWYg
eW91IGhhdmUgcmVjZWl2ZWQgdGhpcyB0cmFuc21pc3Npb24gaW4gZXJyb3IsIHBsZWFzZSBpbW1l
ZGlhdGVseSBub3RpZnkgbWUgYnkgcmVwbHkgZS1tYWlsLCBvciBieSB0ZWxlcGhvbmUgYXQgKDUx
MCkgNDAwLTI5MzY8dGVsOiUyODUxMCUyOSUyMDQwMC0yOTM2PiwgYW5kIGRlc3Ryb3kgdGhlIG9y
aWdpbmFsIHRyYW5zbWlzc2lvbiBhbmQgaXRzIGF0dGFjaG1lbnRzIHdpdGhvdXQgcmVhZGluZyBv
ciBzYXZpbmcgaW4gYW55IG1hbm5lci4gVGhhbmsgeW91Lg0KDQpfX19fX19fX19fX19fX19fX19f
X19fX19fX19fX19fX19fX19fX19fX19fX19fXw0KNnRpc2NoLXNlY3VyaXR5IG1haWxpbmcgbGlz
dA0KNnRpc2NoLXNlY3VyaXR5QGlldGYub3JnPG1haWx0bzo2dGlzY2gtc2VjdXJpdHlAaWV0Zi5v
cmc+DQpodHRwOi8vY3AubWNhZmVlLmNvbS9kLzJEUlBvdzc2UW1iRUZMenpoT00tcktyaHM3Y0ZD
UW4xUGJWSjVNc3Fla2tTamhPcnN1dXVzb0xzUzhRQUhtMGFmQjNaek9WSS1rZlNmYkNUQTdoUFhQ
Yl9uVk5aTkJWeHpIVGJFekhJWVllcGQ3Yno4WEJIRVNoaGxLTV9PRXV2a3phVDBRU3lyaGRUVjV4
ZFZZc3lNQ3FlanRQcGVzUkc5cHhqRnZkVHcwZTJxS01NLWw5T3dYbjc5T0ZvQ25GWkNVT0NtZEtq
QmlOY0xqWGROQmNJbjhscnhyVzBHblB0VTAycm9qaEtVcjF2RjZ5MFFKS2pCaU5jTGpYZE5CY0lx
bmpoMUY3VThxcTg3cU5kNDJ0UW0yWlRPV29VUWdlakJpTmNRZ2stUHNwamI2eTJTRERDVDYzcnRf
VTJTVlVsVkIwDQoNCg0KDQotLQ0KLS0NCkpvbmF0aGFuIFNpbW9uLCBQaC4gRA0KRGlyZWN0b3Ig
b2YgU3lzdGVtcyBFbmdpbmVlcmluZw0KRHVzdCBOZXR3b3JrcyBhdCBMaW5lYXIgVGVjaG5vbG9n
eQ0KMzA2OTUgSHVudHdvb2QgQXZlDQpIYXl3YXJkLCBDQSA5NDU0NC03MDIxDQooNTEwKSA0MDAt
MjkzNg0KKDUxMCkgNDg5LTM3OTkgRkFYDQpqc2ltb25AbGluZWFyLmNvbTxtYWlsdG86anNpbW9u
QGxpbmVhci5jb20+DQoNCioqTElORUFSIFRFQ0hOT0xPR1kgQ09SUE9SQVRJT04qKg0KKioqKipJ
bnRlcm5ldCBFbWFpbCBDb25maWRlbnRpYWxpdHkgTm90aWNlKioqKioNCiBUaGlzIGUtbWFpbCB0
cmFuc21pc3Npb24sIGFuZCBhbnkgZG9jdW1lbnRzLCBmaWxlcyBvciBwcmV2aW91cyBlLW1haWwg
bWVzc2FnZXMgYXR0YWNoZWQgdG8gaXQgbWF5IGNvbnRhaW4gY29uZmlkZW50aWFsIGluZm9ybWF0
aW9uIHRoYXQgaXMgbGVnYWxseSBwcml2aWxlZ2VkLiBJZiB5b3UgYXJlIG5vdCB0aGUgaW50ZW5k
ZWQgcmVjaXBpZW50LCBvciBhIHBlcnNvbiByZXNwb25zaWJsZSBmb3IgZGVsaXZlcmluZyBpdCB0
byB0aGUgaW50ZW5kZWQgcmVjaXBpZW50LCB5b3UgYXJlIGhlcmVieSBub3RpZmllZCB0aGF0IGFu
eSBkaXNjbG9zdXJlLCBjb3B5aW5nLCBkaXN0cmlidXRpb24gb3IgdXNlIG9mIGFueSBvZiB0aGUg
aW5mb3JtYXRpb24gY29udGFpbmVkIGluIG9yIGF0dGFjaGVkIHRvIHRoaXMgdHJhbnNtaXNzaW9u
IGlzIFNUUklDVExZIFBST0hJQklURUQuIElmIHlvdSBoYXZlIHJlY2VpdmVkIHRoaXMgdHJhbnNt
aXNzaW9uIGluIGVycm9yLCBwbGVhc2UgaW1tZWRpYXRlbHkgbm90aWZ5IG1lIGJ5IHJlcGx5IGUt
bWFpbCwgb3IgYnkgdGVsZXBob25lIGF0ICg1MTApIDQwMC0yOTM2LCBhbmQgZGVzdHJveSB0aGUg
b3JpZ2luYWwgdHJhbnNtaXNzaW9uIGFuZCBpdHMgYXR0YWNobWVudHMgd2l0aG91dCByZWFkaW5n
IG9yIHNhdmluZyBpbiBhbnkgbWFubmVyLiBUaGFuayB5b3UuDQpfX19fX19fX19fX19fX19fX19f
X19fX19fX19fX19fX19fX19fX19fX19fX19fXw0KNnRpc2NoLXNlY3VyaXR5IG1haWxpbmcgbGlz
dA0KNnRpc2NoLXNlY3VyaXR5QGlldGYub3JnPG1haWx0bzo2dGlzY2gtc2VjdXJpdHlAaWV0Zi5v
cmc+DQpodHRwOi8vY3AubWNhZmVlLmNvbS9kLzFqV1ZJZTN6cWI1UWtUemhPTUMtcktyaHM3Y0ZD
UW4xUGJWSjVNc3Fla2tTamhPcnN1dXVzb0xzUzhRQUhtMGFmQjNaek9WSS1rZlNmYkNPNUp0dnVw
dldfOEN6QmRCQmZIVGJFQ3pCZHpBVEM3eE5FVlZxV3RBa2xyQ3pCN0JnWS1GNmxLMUZKNFN5ckxP
YjJyUFVWNXhjUXNDWENPc1ZIa2lQMkRpLXJMMDBzNFJ0eHhZR2pCMVNLZWpCaU5jTGpYZE5CY0ly
c0RhQnlwdURTcnphcG9LZ0dUMlRRMWtMQ1hNMDRTLXFlbTdUM29iWjhRZzZCSk9zR205Qld2cEtj
RkJ6aVdxOGQ4XzEzamgwWG05RXdqS3lNbkstbmo3NnkxT3NHbTlDeTJEU3J6YXBvUWdtUVlZU1VN
ckRya3IycEFhVGFtDQoNCg==

--_000_674F70E5F2BE564CB06B6901FD3DD78B2723BA32TGXML210toshiba_
Content-Type: text/html; charset="utf-8"
Content-Transfer-Encoding: base64

PGh0bWwgeG1sbnM6dj0idXJuOnNjaGVtYXMtbWljcm9zb2Z0LWNvbTp2bWwiIHhtbG5zOm89InVy
bjpzY2hlbWFzLW1pY3Jvc29mdC1jb206b2ZmaWNlOm9mZmljZSIgeG1sbnM6dz0idXJuOnNjaGVt
YXMtbWljcm9zb2Z0LWNvbTpvZmZpY2U6d29yZCIgeG1sbnM6bT0iaHR0cDovL3NjaGVtYXMubWlj
cm9zb2Z0LmNvbS9vZmZpY2UvMjAwNC8xMi9vbW1sIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcv
VFIvUkVDLWh0bWw0MCI+DQo8aGVhZD4NCjxtZXRhIGh0dHAtZXF1aXY9IkNvbnRlbnQtVHlwZSIg
Y29udGVudD0idGV4dC9odG1sOyBjaGFyc2V0PXV0Zi04Ij4NCjxtZXRhIG5hbWU9IkdlbmVyYXRv
ciIgY29udGVudD0iTWljcm9zb2Z0IFdvcmQgMTUgKGZpbHRlcmVkIG1lZGl1bSkiPg0KPHN0eWxl
PjwhLS0NCi8qIEZvbnQgRGVmaW5pdGlvbnMgKi8NCkBmb250LWZhY2UNCgl7Zm9udC1mYW1pbHk6
Iu+8re+8syDjgrTjgrfjg4Pjgq8iOw0KCXBhbm9zZS0xOjIgMTEgNiA5IDcgMiA1IDggMiA0O30N
CkBmb250LWZhY2UNCgl7Zm9udC1mYW1pbHk6IkNhbWJyaWEgTWF0aCI7DQoJcGFub3NlLTE6MiA0
IDUgMyA1IDQgNiAzIDIgNDt9DQpAZm9udC1mYWNlDQoJe2ZvbnQtZmFtaWx5OkNhbGlicmk7DQoJ
cGFub3NlLTE6MiAxNSA1IDIgMiAyIDQgMyAyIDQ7fQ0KQGZvbnQtZmFjZQ0KCXtmb250LWZhbWls
eToi77yt77yzIO+8sOOCtOOCt+ODg+OCryI7DQoJcGFub3NlLTE6MiAxMSA2IDAgNyAyIDUgOCAy
IDQ7fQ0KQGZvbnQtZmFjZQ0KCXtmb250LWZhbWlseToiXEDvvK3vvLMg44K044K344OD44KvIjsN
CglwYW5vc2UtMToyIDExIDYgOSA3IDIgNSA4IDIgNDt9DQpAZm9udC1mYWNlDQoJe2ZvbnQtZmFt
aWx5OiJcQO+8re+8syDvvLDjgrTjgrfjg4Pjgq8iOw0KCXBhbm9zZS0xOjIgMTEgNiAwIDcgMiA1
IDggMiA0O30NCkBmb250LWZhY2UNCgl7Zm9udC1mYW1pbHk6Ikx1Y2lkYSBHcmFuZGUiOw0KCXBh
bm9zZS0xOjAgMCAwIDAgMCAwIDAgMCAwIDA7fQ0KQGZvbnQtZmFjZQ0KCXtmb250LWZhbWlseTpM
dWNpZGFHcmFuZGU7DQoJcGFub3NlLTE6MCAwIDAgMCAwIDAgMCAwIDAgMDt9DQovKiBTdHlsZSBE
ZWZpbml0aW9ucyAqLw0KcC5Nc29Ob3JtYWwsIGxpLk1zb05vcm1hbCwgZGl2Lk1zb05vcm1hbA0K
CXttYXJnaW46MG1tOw0KCW1hcmdpbi1ib3R0b206LjAwMDFwdDsNCglmb250LXNpemU6MTIuMHB0
Ow0KCWZvbnQtZmFtaWx5OiLvvK3vvLMg77yw44K044K344OD44KvIjt9DQphOmxpbmssIHNwYW4u
TXNvSHlwZXJsaW5rDQoJe21zby1zdHlsZS1wcmlvcml0eTo5OTsNCgljb2xvcjpibHVlOw0KCXRl
eHQtZGVjb3JhdGlvbjp1bmRlcmxpbmU7fQ0KYTp2aXNpdGVkLCBzcGFuLk1zb0h5cGVybGlua0Zv
bGxvd2VkDQoJe21zby1zdHlsZS1wcmlvcml0eTo5OTsNCgljb2xvcjpwdXJwbGU7DQoJdGV4dC1k
ZWNvcmF0aW9uOnVuZGVybGluZTt9DQpwcmUNCgl7bXNvLXN0eWxlLXByaW9yaXR5Ojk5Ow0KCW1z
by1zdHlsZS1saW5rOiJIVE1MIOabuOW8j+S7mOOBjSBcKOaWh+Wtl1wpIjsNCgltYXJnaW46MG1t
Ow0KCW1hcmdpbi1ib3R0b206LjAwMDFwdDsNCglmb250LXNpemU6MTIuMHB0Ow0KCWZvbnQtZmFt
aWx5OiLvvK3vvLMg44K044K344OD44KvIjt9DQpzcGFuLmFwcGxlLXN0eWxlLXNwYW4NCgl7bXNv
LXN0eWxlLW5hbWU6YXBwbGUtc3R5bGUtc3Bhbjt9DQpzcGFuLmFwcGxlLWNvbnZlcnRlZC1zcGFj
ZQ0KCXttc28tc3R5bGUtbmFtZTphcHBsZS1jb252ZXJ0ZWQtc3BhY2U7fQ0Kc3Bhbi5IVE1MDQoJ
e21zby1zdHlsZS1uYW1lOiJIVE1MIOabuOW8j+S7mOOBjSBcKOaWh+Wtl1wpIjsNCgltc28tc3R5
bGUtcHJpb3JpdHk6OTk7DQoJbXNvLXN0eWxlLWxpbms6IkhUTUwg5pu45byP5LuY44GNIjsNCglm
b250LWZhbWlseToiQ291cmllciBOZXciO30NCnNwYW4uMjENCgl7bXNvLXN0eWxlLXR5cGU6cGVy
c29uYWwtcmVwbHk7DQoJZm9udC1mYW1pbHk6IkFyaWFsIiwic2Fucy1zZXJpZiI7DQoJY29sb3I6
IzFGNDk3RDt9DQouTXNvQ2hwRGVmYXVsdA0KCXttc28tc3R5bGUtdHlwZTpleHBvcnQtb25seTsN
Cglmb250LXNpemU6MTAuMHB0O30NCkBwYWdlIFdvcmRTZWN0aW9uMQ0KCXtzaXplOjYxMi4wcHQg
NzkyLjBwdDsNCgltYXJnaW46OTkuMjVwdCAzMC4wbW0gMzAuMG1tIDMwLjBtbTt9DQpkaXYuV29y
ZFNlY3Rpb24xDQoJe3BhZ2U6V29yZFNlY3Rpb24xO30NCi0tPjwvc3R5bGU+PCEtLVtpZiBndGUg
bXNvIDldPjx4bWw+DQo8bzpzaGFwZWRlZmF1bHRzIHY6ZXh0PSJlZGl0IiBzcGlkbWF4PSIxMDI2
Ij4NCjx2OnRleHRib3ggaW5zZXQ9IjUuODVwdCwuN3B0LDUuODVwdCwuN3B0IiAvPg0KPC9vOnNo
YXBlZGVmYXVsdHM+PC94bWw+PCFbZW5kaWZdLS0+PCEtLVtpZiBndGUgbXNvIDldPjx4bWw+DQo8
bzpzaGFwZWxheW91dCB2OmV4dD0iZWRpdCI+DQo8bzppZG1hcCB2OmV4dD0iZWRpdCIgZGF0YT0i
MSIgLz4NCjwvbzpzaGFwZWxheW91dD48L3htbD48IVtlbmRpZl0tLT4NCjwvaGVhZD4NCjxib2R5
IGxhbmc9IkpBIiBsaW5rPSJibHVlIiB2bGluaz0icHVycGxlIj4NCjxkaXYgY2xhc3M9IldvcmRT
ZWN0aW9uMSI+DQo8cCBjbGFzcz0iTXNvTm9ybWFsIj48c3BhbiBsYW5nPSJFTi1VUyIgc3R5bGU9
ImZvbnQtc2l6ZToxMC4wcHQ7Zm9udC1mYW1pbHk6JnF1b3Q7QXJpYWwmcXVvdDssJnF1b3Q7c2Fu
cy1zZXJpZiZxdW90Oztjb2xvcjojMUY0OTdEIj5IaSBKb25hdGhhbiw8bzpwPjwvbzpwPjwvc3Bh
bj48L3A+DQo8cCBjbGFzcz0iTXNvTm9ybWFsIj48c3BhbiBsYW5nPSJFTi1VUyIgc3R5bGU9ImZv
bnQtc2l6ZToxMC4wcHQ7Zm9udC1mYW1pbHk6JnF1b3Q7QXJpYWwmcXVvdDssJnF1b3Q7c2Fucy1z
ZXJpZiZxdW90Oztjb2xvcjojMUY0OTdEIj48bzpwPiZuYnNwOzwvbzpwPjwvc3Bhbj48L3A+DQo8
cCBjbGFzcz0iTXNvTm9ybWFsIj48c3BhbiBsYW5nPSJFTi1VUyIgc3R5bGU9ImZvbnQtc2l6ZTox
MC4wcHQ7Zm9udC1mYW1pbHk6JnF1b3Q7QXJpYWwmcXVvdDssJnF1b3Q7c2Fucy1zZXJpZiZxdW90
Oztjb2xvcjojMUY0OTdEIj5JIGFtIG5vdCBjYXJpbmcgYWJvdXQgYW4gYXR0YWNrZXIgdG8gaW5q
ZWN0IGpvaW5pbmcgdHJhZmZpYywgYnV0IHdoYXQgSSBjYXJlIGlzIGFuIGF0dGFja2VyIGF0dGVt
cHRpbmcgdG8gZGVzdHJ1Y3QgYmFzaWMgVFNDSCBvcGVyYXRpb24gaW4gdGhlIG5ldHdvcmsNCiBi
eSBzZW5kaW5nIGZvcmdlZCBiZWFjb25zIHByb3RlY3RlZCB3aXRoIHRoZSB3ZWxsLWtub3duIGtl
eS48bzpwPjwvbzpwPjwvc3Bhbj48L3A+DQo8cCBjbGFzcz0iTXNvTm9ybWFsIj48c3BhbiBsYW5n
PSJFTi1VUyIgc3R5bGU9ImZvbnQtc2l6ZToxMC4wcHQ7Zm9udC1mYW1pbHk6JnF1b3Q7QXJpYWwm
cXVvdDssJnF1b3Q7c2Fucy1zZXJpZiZxdW90Oztjb2xvcjojMUY0OTdEIj48bzpwPiZuYnNwOzwv
bzpwPjwvc3Bhbj48L3A+DQo8cCBjbGFzcz0iTXNvTm9ybWFsIj48c3BhbiBsYW5nPSJFTi1VUyIg
c3R5bGU9ImZvbnQtc2l6ZToxMC4wcHQ7Zm9udC1mYW1pbHk6JnF1b3Q7QXJpYWwmcXVvdDssJnF1
b3Q7c2Fucy1zZXJpZiZxdW90Oztjb2xvcjojMUY0OTdEIj5Zb3NoaWhpcm8gT2hiYTxvOnA+PC9v
OnA+PC9zcGFuPjwvcD4NCjxwIGNsYXNzPSJNc29Ob3JtYWwiPjxzcGFuIGxhbmc9IkVOLVVTIiBz
dHlsZT0iZm9udC1zaXplOjEwLjBwdDtmb250LWZhbWlseTomcXVvdDtBcmlhbCZxdW90OywmcXVv
dDtzYW5zLXNlcmlmJnF1b3Q7O2NvbG9yOiMxRjQ5N0QiPjxvOnA+Jm5ic3A7PC9vOnA+PC9zcGFu
PjwvcD4NCjxwIGNsYXNzPSJNc29Ob3JtYWwiPjxzcGFuIGxhbmc9IkVOLVVTIiBzdHlsZT0iZm9u
dC1zaXplOjEwLjBwdDtmb250LWZhbWlseTomcXVvdDtBcmlhbCZxdW90OywmcXVvdDtzYW5zLXNl
cmlmJnF1b3Q7O2NvbG9yOiMxRjQ5N0QiPjxvOnA+Jm5ic3A7PC9vOnA+PC9zcGFuPjwvcD4NCjxw
IGNsYXNzPSJNc29Ob3JtYWwiPjxzcGFuIGxhbmc9IkVOLVVTIiBzdHlsZT0iZm9udC1zaXplOjEw
LjBwdDtmb250LWZhbWlseTomcXVvdDtBcmlhbCZxdW90OywmcXVvdDtzYW5zLXNlcmlmJnF1b3Q7
O2NvbG9yOiMxRjQ5N0QiPjxvOnA+Jm5ic3A7PC9vOnA+PC9zcGFuPjwvcD4NCjxkaXY+DQo8ZGl2
IHN0eWxlPSJib3JkZXI6bm9uZTtib3JkZXItdG9wOnNvbGlkICNFMUUxRTEgMS4wcHQ7cGFkZGlu
ZzozLjBwdCAwbW0gMG1tIDBtbSI+DQo8cCBjbGFzcz0iTXNvTm9ybWFsIj48Yj48c3BhbiBsYW5n
PSJFTi1VUyIgc3R5bGU9ImZvbnQtc2l6ZToxMS4wcHQ7Zm9udC1mYW1pbHk6JnF1b3Q7Q2FsaWJy
aSZxdW90OywmcXVvdDtzYW5zLXNlcmlmJnF1b3Q7Ij5Gcm9tOjwvc3Bhbj48L2I+PHNwYW4gbGFu
Zz0iRU4tVVMiIHN0eWxlPSJmb250LXNpemU6MTEuMHB0O2ZvbnQtZmFtaWx5OiZxdW90O0NhbGli
cmkmcXVvdDssJnF1b3Q7c2Fucy1zZXJpZiZxdW90OyI+IDZ0aXNjaC1zZWN1cml0eSBbbWFpbHRv
OjZ0aXNjaC1zZWN1cml0eS1ib3VuY2VzQGlldGYub3JnXQ0KPGI+T24gQmVoYWxmIE9mIDwvYj5K
b25hdGhhbiBTaW1vbjxicj4NCjxiPlNlbnQ6PC9iPiBUaHVyc2RheSwgTWF5IDI5LCAyMDE0IDEy
OjQ3IEFNPGJyPg0KPGI+VG86PC9iPiBvaGJhIHlvc2hpaGlybyg8L3NwYW4+PHNwYW4gc3R5bGU9
ImZvbnQtc2l6ZToxMS4wcHQiPuWkp+WgtDwvc3Bhbj48c3BhbiBzdHlsZT0iZm9udC1zaXplOjEx
LjBwdDtmb250LWZhbWlseTomcXVvdDtDYWxpYnJpJnF1b3Q7LCZxdW90O3NhbnMtc2VyaWYmcXVv
dDsiPg0KPC9zcGFuPjxzcGFuIHN0eWxlPSJmb250LXNpemU6MTEuMHB0Ij7nvqnmtIs8L3NwYW4+
PHNwYW4gbGFuZz0iRU4tVVMiIHN0eWxlPSJmb250LXNpemU6MTEuMHB0O2ZvbnQtZmFtaWx5OiZx
dW90O0NhbGlicmkmcXVvdDssJnF1b3Q7c2Fucy1zZXJpZiZxdW90OyI+IOKXizwvc3Bhbj48c3Bh
biBzdHlsZT0iZm9udC1zaXplOjExLjBwdCI+77yy77yk77yjPC9zcGFuPjxzcGFuIGxhbmc9IkVO
LVVTIiBzdHlsZT0iZm9udC1zaXplOjExLjBwdDtmb250LWZhbWlseTomcXVvdDtDYWxpYnJpJnF1
b3Q7LCZxdW90O3NhbnMtc2VyaWYmcXVvdDsiPuKWoTwvc3Bhbj48c3BhbiBzdHlsZT0iZm9udC1z
aXplOjExLjBwdCI+77yu77yz77ysPC9zcGFuPjxzcGFuIGxhbmc9IkVOLVVTIiBzdHlsZT0iZm9u
dC1zaXplOjExLjBwdDtmb250LWZhbWlseTomcXVvdDtDYWxpYnJpJnF1b3Q7LCZxdW90O3NhbnMt
c2VyaWYmcXVvdDsiPik8YnI+DQo8Yj5DYzo8L2I+IG1jciYjNDM7aWV0ZkBzYW5kZWxtYW4uY2E7
IHJzdHJ1aWsuZXh0QGdtYWlsLmNvbTsgNnRpc2NoLXNlY3VyaXR5QGlldGYub3JnPGJyPg0KPGI+
U3ViamVjdDo8L2I+IFJlOiBbNnRpc2NoLXNlY3VyaXR5XSBhZ2VuZGEgZm9yIDIwMTQtMDUtMjcg
NnRpc2NoIHNlY3VyaXR5IGNhbGw8bzpwPjwvbzpwPjwvc3Bhbj48L3A+DQo8L2Rpdj4NCjwvZGl2
Pg0KPHAgY2xhc3M9Ik1zb05vcm1hbCI+PHNwYW4gbGFuZz0iRU4tVVMiPjxvOnA+Jm5ic3A7PC9v
OnA+PC9zcGFuPjwvcD4NCjxwIGNsYXNzPSJNc29Ob3JtYWwiPjxzcGFuIGxhbmc9IkVOLVVTIj5Z
b3NoaWhpcm8gLTxvOnA+PC9vOnA+PC9zcGFuPjwvcD4NCjxkaXY+DQo8cCBjbGFzcz0iTXNvTm9y
bWFsIj48c3BhbiBsYW5nPSJFTi1VUyI+PG86cD4mbmJzcDs8L286cD48L3NwYW4+PC9wPg0KPC9k
aXY+DQo8ZGl2Pg0KPHAgY2xhc3M9Ik1zb05vcm1hbCI+PHNwYW4gbGFuZz0iRU4tVVMiPkkgZG9u
4oCZdCB0aGluayB0aGlzIGlzIGEgcHJvYmxlbS4gJm5ic3A7Tm9kZXMgdGhhdCBhcmUgaW4gdGhl
IG5ldHdvcmsgcmVqZWN0IGluY29taW5nIGZyYW1lcyBzZWN1cmVkIHdpdGggdGhlIHdlbGwta25v
d24ga2V5LiBUaGUgd2VsbC1rbm93biBrZXkgaXMgb25seSB1c2VkIHRvIGF1dGhlbnRpY2F0ZSBi
ZWFjb25zLCBhbmQgYXV0aGVudGljYXRlIGpvaW4gcmVxdWVzdHMgKHdoaWNoIGRvbuKAmXQNCiBj
YXJyeSBzeW5jaHJvbml6YXRpb24gaW5mb3JtYXRpb24pLiAmbmJzcDtUaGVyZSBpcyBhIERvUyB2
ZWN0b3IsIGluIHRoYXQgYW4gYXR0YWNrZXIgY2FuIGluamVjdCBqb2luaW5nIHRyYWZmaWMgKGRl
c3RpbmVkIGZvciB0aGUgbmV0d29yayBtYW5hbmFnZXIpIHRoYXQgd2lsbCB1bHRpbWF0ZWx5IGJl
IGRpc2NhcmRlZCwgcG9zc2libHkgcHJldmVudGluZyBvdGhlciBub2RlcyBmcm9tIGpvaW5pbmcs
IGFuZCBpbmNyZWFzaW5nIHRoZSB0cmFmZmljIGluIHRoZQ0KIG5ldHdvcmsuJm5ic3A7PG86cD48
L286cD48L3NwYW4+PC9wPg0KPC9kaXY+DQo8ZGl2Pg0KPHAgY2xhc3M9Ik1zb05vcm1hbCI+PHNw
YW4gbGFuZz0iRU4tVVMiPjxvOnA+Jm5ic3A7PC9vOnA+PC9zcGFuPjwvcD4NCjxkaXY+DQo8ZGl2
Pg0KPGRpdj4NCjxwIGNsYXNzPSJNc29Ob3JtYWwiPjxzcGFuIGxhbmc9IkVOLVVTIiBzdHlsZT0i
Zm9udC1mYW1pbHk6JnF1b3Q7THVjaWRhIEdyYW5kZSZxdW90OywmcXVvdDtzZXJpZiZxdW90Oztj
b2xvcjpibGFjayI+Sm9uYXRoYW4gU2ltb24sIFBoLiBEPGJyPg0KRGlyZWN0b3Igb2YgU3lzdGVt
cyBFbmdpbmVlcmluZzxicj4NCkxpbmVhciBUZWNobm9sb2d5LCBEdXN0IE5ldHdvcmtzIHByb2R1
Y3QgZ3JvdXA8YnI+DQozMDY5NSBIdW50d29vZCBBdmU8YnI+DQpIYXl3YXJkLCBDQSA5NDU0NC03
MDIxPGJyPg0KKDUxMCkgNDAwLTI5MzY8YnI+DQooNTEwKSA0ODktMzc5OSBGQVg8YnI+DQo8YSBo
cmVmPSJtYWlsdG86anNpbW9uQGxpbmVhci5jb20iPmpzaW1vbkBsaW5lYXIuY29tPC9hPjxicj4N
Cjxicj4NCioqTElORUFSIFRFQ0hOT0xPR1kmbmJzcDtDT1JQT1JBVElPTioqJm5ic3A7PGJyPg0K
KioqKipJbnRlcm5ldCBFbWFpbCBDb25maWRlbnRpYWxpdHkmbmJzcDtOb3RpY2UqKioqKiZuYnNw
Ozxicj4NCiZuYnNwO1RoaXMgZS1tYWlsIHRyYW5zbWlzc2lvbiwgYW5kIGFueSZuYnNwO2RvY3Vt
ZW50cywgZmlsZXMgb3IgcHJldmlvdXMgZS1tYWlsJm5ic3A7bWVzc2FnZXMgYXR0YWNoZWQgdG8g
aXQgbWF5IGNvbnRhaW4mbmJzcDtjb25maWRlbnRpYWwgaW5mb3JtYXRpb24gdGhhdCBpcyZuYnNw
O2xlZ2FsbHkgcHJpdmlsZWdlZC4gSWYgeW91IGFyZSBub3QgdGhlJm5ic3A7aW50ZW5kZWQgcmVj
aXBpZW50LCBvciBhIHBlcnNvbiZuYnNwO3Jlc3BvbnNpYmxlIGZvciBkZWxpdmVyaW5nIGl0IHRv
IHRoZSZuYnNwO2ludGVuZGVkDQogcmVjaXBpZW50LCB5b3UgYXJlIGhlcmVieSZuYnNwO25vdGlm
aWVkIHRoYXQgYW55IGRpc2Nsb3N1cmUsIGNvcHlpbmcsJm5ic3A7ZGlzdHJpYnV0aW9uIG9yIHVz
ZSBvZiBhbnkgb2YgdGhlJm5ic3A7aW5mb3JtYXRpb24gY29udGFpbmVkIGluIG9yIGF0dGFjaGVk
Jm5ic3A7dG8gdGhpcyB0cmFuc21pc3Npb24gaXMgU1RSSUNUTFkmbmJzcDtQUk9ISUJJVEVELiBJ
ZiB5b3UgaGF2ZSByZWNlaXZlZCB0aGlzJm5ic3A7dHJhbnNtaXNzaW9uIGluIGVycm9yLCBwbGVh
c2UmbmJzcDtpbW1lZGlhdGVseSBub3RpZnkNCiBtZSBieSByZXBseSBlLW1haWwsIG9yIGJ5IHRl
bGVwaG9uZSBhdCAoNTEwKSA0MDAtMjkzNiwgYW5kIGRlc3Ryb3kgdGhlIG9yaWdpbmFsJm5ic3A7
dHJhbnNtaXNzaW9uIGFuZCBpdHMgYXR0YWNobWVudHMmbmJzcDt3aXRob3V0IHJlYWRpbmcgb3Ig
c2F2aW5nIGluIGFueSZuYnNwO21hbm5lci4gVGhhbmsgeW91LiZuYnNwOzxvOnA+PC9vOnA+PC9z
cGFuPjwvcD4NCjwvZGl2Pg0KPC9kaXY+DQo8L2Rpdj4NCjxwIGNsYXNzPSJNc29Ob3JtYWwiPjxz
cGFuIGxhbmc9IkVOLVVTIj48bzpwPiZuYnNwOzwvbzpwPjwvc3Bhbj48L3A+DQo8ZGl2Pg0KPGRp
dj4NCjxwIGNsYXNzPSJNc29Ob3JtYWwiPjxzcGFuIGxhbmc9IkVOLVVTIj5PbiBNYXkgMjgsIDIw
MTQsIGF0IDg6MDEgQU0sICZsdDs8YSBocmVmPSJtYWlsdG86eW9zaGloaXJvLm9oYmFAdG9zaGli
YS5jby5qcCI+eW9zaGloaXJvLm9oYmFAdG9zaGliYS5jby5qcDwvYT4mZ3Q7ICZsdDs8YSBocmVm
PSJtYWlsdG86eW9zaGloaXJvLm9oYmFAdG9zaGliYS5jby5qcCI+eW9zaGloaXJvLm9oYmFAdG9z
aGliYS5jby5qcDwvYT4mZ3Q7IHdyb3RlOjxvOnA+PC9vOnA+PC9zcGFuPjwvcD4NCjwvZGl2Pg0K
PHAgY2xhc3M9Ik1zb05vcm1hbCI+PHNwYW4gbGFuZz0iRU4tVVMiPjxicj4NCjxicj4NCjxvOnA+
PC9vOnA+PC9zcGFuPjwvcD4NCjxibG9ja3F1b3RlIHN0eWxlPSJtYXJnaW4tdG9wOjUuMHB0O21h
cmdpbi1ib3R0b206NS4wcHQiPg0KPGRpdj4NCjxkaXY+DQo8cCBjbGFzcz0iTXNvTm9ybWFsIj48
c3BhbiBsYW5nPSJFTi1VUyIgc3R5bGU9ImZvbnQtc2l6ZToxMC4wcHQ7Zm9udC1mYW1pbHk6JnF1
b3Q7QXJpYWwmcXVvdDssJnF1b3Q7c2Fucy1zZXJpZiZxdW90Oztjb2xvcjojMUY0OTdEIj5IaSBK
b25hdGhhbiw8L3NwYW4+PHNwYW4gbGFuZz0iRU4tVVMiPjxvOnA+PC9vOnA+PC9zcGFuPjwvcD4N
CjwvZGl2Pg0KPGRpdj4NCjxwIGNsYXNzPSJNc29Ob3JtYWwiPjxzcGFuIGxhbmc9IkVOLVVTIiBz
dHlsZT0iZm9udC1zaXplOjEwLjBwdDtmb250LWZhbWlseTomcXVvdDtBcmlhbCZxdW90OywmcXVv
dDtzYW5zLXNlcmlmJnF1b3Q7O2NvbG9yOiMxRjQ5N0QiPiZuYnNwOzwvc3Bhbj48c3BhbiBsYW5n
PSJFTi1VUyI+PG86cD48L286cD48L3NwYW4+PC9wPg0KPC9kaXY+DQo8ZGl2Pg0KPHAgY2xhc3M9
Ik1zb05vcm1hbCI+PHNwYW4gbGFuZz0iRU4tVVMiIHN0eWxlPSJmb250LXNpemU6MTAuMHB0O2Zv
bnQtZmFtaWx5OiZxdW90O0FyaWFsJnF1b3Q7LCZxdW90O3NhbnMtc2VyaWYmcXVvdDs7Y29sb3I6
IzFGNDk3RCI+VGhhbmsgeW91IGZvciB5b3VyIGFuc3dlci48L3NwYW4+PHNwYW4gbGFuZz0iRU4t
VVMiPjxvOnA+PC9vOnA+PC9zcGFuPjwvcD4NCjwvZGl2Pg0KPGRpdj4NCjxwIGNsYXNzPSJNc29O
b3JtYWwiPjxzcGFuIGxhbmc9IkVOLVVTIiBzdHlsZT0iZm9udC1zaXplOjEwLjBwdDtmb250LWZh
bWlseTomcXVvdDtBcmlhbCZxdW90OywmcXVvdDtzYW5zLXNlcmlmJnF1b3Q7O2NvbG9yOiMxRjQ5
N0QiPiZuYnNwOzwvc3Bhbj48c3BhbiBsYW5nPSJFTi1VUyI+PG86cD48L286cD48L3NwYW4+PC9w
Pg0KPC9kaXY+DQo8ZGl2Pg0KPHAgY2xhc3M9Ik1zb05vcm1hbCI+PHNwYW4gbGFuZz0iRU4tVVMi
IHN0eWxlPSJmb250LXNpemU6MTAuMHB0O2ZvbnQtZmFtaWx5OiZxdW90O0FyaWFsJnF1b3Q7LCZx
dW90O3NhbnMtc2VyaWYmcXVvdDs7Y29sb3I6IzFGNDk3RCI+SSB0aGluayB0aGlzIGNhbiBiZSBh
biBpc3N1ZSBpZiBhbHJlYWR5IGpvaW5lZCBub2RlcyBhbHNvIHVzZSB0aGUgYmVhY29ucyBwcm90
ZWN0ZWQgd2l0aCB0aGUgd2VsbC1rbm93biBrZXkgZm9yIG1haW50YWluaW5nIHN5bmNocm9uaXph
dGlvbiBhbmQgc2xvdA0KIGFsbG9jYXRpb25zLCBhcyBhbiBhdHRhY2tlciBjYW4gc2VuZCBmb3Jn
ZWQgYmVhY29ucyBwcm90ZWN0ZWQgd2l0aCB0aGUgd2VsbC1rbm93biBrZXkuPC9zcGFuPjxzcGFu
IGxhbmc9IkVOLVVTIj48bzpwPjwvbzpwPjwvc3Bhbj48L3A+DQo8L2Rpdj4NCjxkaXY+DQo8cCBj
bGFzcz0iTXNvTm9ybWFsIj48c3BhbiBsYW5nPSJFTi1VUyIgc3R5bGU9ImZvbnQtc2l6ZToxMC4w
cHQ7Zm9udC1mYW1pbHk6JnF1b3Q7QXJpYWwmcXVvdDssJnF1b3Q7c2Fucy1zZXJpZiZxdW90Oztj
b2xvcjojMUY0OTdEIj4mbmJzcDs8L3NwYW4+PHNwYW4gbGFuZz0iRU4tVVMiPjxvOnA+PC9vOnA+
PC9zcGFuPjwvcD4NCjwvZGl2Pg0KPGRpdj4NCjxwIGNsYXNzPSJNc29Ob3JtYWwiPjxzcGFuIGxh
bmc9IkVOLVVTIiBzdHlsZT0iZm9udC1zaXplOjEwLjBwdDtmb250LWZhbWlseTomcXVvdDtBcmlh
bCZxdW90OywmcXVvdDtzYW5zLXNlcmlmJnF1b3Q7O2NvbG9yOiMxRjQ5N0QiPllvc2hpaGlybyBP
aGJhPC9zcGFuPjxzcGFuIGxhbmc9IkVOLVVTIj48bzpwPjwvbzpwPjwvc3Bhbj48L3A+DQo8L2Rp
dj4NCjxkaXY+DQo8cCBjbGFzcz0iTXNvTm9ybWFsIj48c3BhbiBsYW5nPSJFTi1VUyIgc3R5bGU9
ImZvbnQtc2l6ZToxMC4wcHQ7Zm9udC1mYW1pbHk6JnF1b3Q7QXJpYWwmcXVvdDssJnF1b3Q7c2Fu
cy1zZXJpZiZxdW90Oztjb2xvcjojMUY0OTdEIj4mbmJzcDs8L3NwYW4+PHNwYW4gbGFuZz0iRU4t
VVMiPjxvOnA+PC9vOnA+PC9zcGFuPjwvcD4NCjwvZGl2Pg0KPGRpdj4NCjxwIGNsYXNzPSJNc29O
b3JtYWwiPjxzcGFuIGxhbmc9IkVOLVVTIiBzdHlsZT0iZm9udC1zaXplOjEwLjBwdDtmb250LWZh
bWlseTomcXVvdDtBcmlhbCZxdW90OywmcXVvdDtzYW5zLXNlcmlmJnF1b3Q7O2NvbG9yOiMxRjQ5
N0QiPiZuYnNwOzwvc3Bhbj48c3BhbiBsYW5nPSJFTi1VUyI+PG86cD48L286cD48L3NwYW4+PC9w
Pg0KPC9kaXY+DQo8ZGl2Pg0KPHAgY2xhc3M9Ik1zb05vcm1hbCI+PGI+PHNwYW4gbGFuZz0iRU4t
VVMiIHN0eWxlPSJmb250LXNpemU6MTEuMHB0O2ZvbnQtZmFtaWx5OiZxdW90O0NhbGlicmkmcXVv
dDssJnF1b3Q7c2Fucy1zZXJpZiZxdW90OyI+RnJvbTo8L3NwYW4+PC9iPjxzcGFuIGNsYXNzPSJh
cHBsZS1jb252ZXJ0ZWQtc3BhY2UiPjxzcGFuIGxhbmc9IkVOLVVTIiBzdHlsZT0iZm9udC1zaXpl
OjExLjBwdDtmb250LWZhbWlseTomcXVvdDtDYWxpYnJpJnF1b3Q7LCZxdW90O3NhbnMtc2VyaWYm
cXVvdDsiPiZuYnNwOzwvc3Bhbj48L3NwYW4+PHNwYW4gbGFuZz0iRU4tVVMiIHN0eWxlPSJmb250
LXNpemU6MTEuMHB0O2ZvbnQtZmFtaWx5OiZxdW90O0NhbGlicmkmcXVvdDssJnF1b3Q7c2Fucy1z
ZXJpZiZxdW90OyI+NnRpc2NoLXNlY3VyaXR5DQogWzxhIGhyZWY9Im1haWx0bzo2dGlzY2gtc2Vj
dXJpdHktYm91bmNlc0BpZXRmLm9yZyI+PHNwYW4gc3R5bGU9ImNvbG9yOnB1cnBsZSI+bWFpbHRv
OjZ0aXNjaC1zZWN1cml0eS1ib3VuY2VzQGlldGYub3JnPC9zcGFuPjwvYT5dPHNwYW4gY2xhc3M9
ImFwcGxlLWNvbnZlcnRlZC1zcGFjZSI+Jm5ic3A7PC9zcGFuPjxiPk9uIEJlaGFsZiBPZjxzcGFu
IGNsYXNzPSJhcHBsZS1jb252ZXJ0ZWQtc3BhY2UiPiZuYnNwOzwvc3Bhbj48L2I+Sm9uYXRoYW4g
U2ltb248YnI+DQo8Yj5TZW50OjwvYj48c3BhbiBjbGFzcz0iYXBwbGUtY29udmVydGVkLXNwYWNl
Ij4mbmJzcDs8L3NwYW4+V2VkbmVzZGF5LCBNYXkgMjgsIDIwMTQgMTE6NDkgUE08YnI+DQo8Yj5U
bzo8L2I+PHNwYW4gY2xhc3M9ImFwcGxlLWNvbnZlcnRlZC1zcGFjZSI+Jm5ic3A7PC9zcGFuPm9o
YmEgeW9zaGloaXJvKDwvc3Bhbj48c3BhbiBzdHlsZT0iZm9udC1zaXplOjExLjBwdCI+5aSn5aC0
PC9zcGFuPjxzcGFuIGxhbmc9IkVOLVVTIiBzdHlsZT0iZm9udC1zaXplOjExLjBwdDtmb250LWZh
bWlseTomcXVvdDtDYWxpYnJpJnF1b3Q7LCZxdW90O3NhbnMtc2VyaWYmcXVvdDsiPiZuYnNwOzwv
c3Bhbj48c3BhbiBzdHlsZT0iZm9udC1zaXplOjExLjBwdCI+576p5rSLPC9zcGFuPjxzcGFuIGNs
YXNzPSJhcHBsZS1jb252ZXJ0ZWQtc3BhY2UiPjxzcGFuIGxhbmc9IkVOLVVTIiBzdHlsZT0iZm9u
dC1zaXplOjExLjBwdDtmb250LWZhbWlseTomcXVvdDtDYWxpYnJpJnF1b3Q7LCZxdW90O3NhbnMt
c2VyaWYmcXVvdDsiPiZuYnNwOzwvc3Bhbj48L3NwYW4+PHNwYW4gbGFuZz0iRU4tVVMiIHN0eWxl
PSJmb250LXNpemU6MTEuMHB0O2ZvbnQtZmFtaWx5OiZxdW90O0NhbGlicmkmcXVvdDssJnF1b3Q7
c2Fucy1zZXJpZiZxdW90OyI+4peLPC9zcGFuPjxzcGFuIHN0eWxlPSJmb250LXNpemU6MTEuMHB0
Ij7vvLLvvKTvvKM8L3NwYW4+PHNwYW4gbGFuZz0iRU4tVVMiIHN0eWxlPSJmb250LXNpemU6MTEu
MHB0O2ZvbnQtZmFtaWx5OiZxdW90O0NhbGlicmkmcXVvdDssJnF1b3Q7c2Fucy1zZXJpZiZxdW90
OyI+4pahPC9zcGFuPjxzcGFuIHN0eWxlPSJmb250LXNpemU6MTEuMHB0Ij7vvK7vvLPvvKw8L3Nw
YW4+PHNwYW4gbGFuZz0iRU4tVVMiIHN0eWxlPSJmb250LXNpemU6MTEuMHB0O2ZvbnQtZmFtaWx5
OiZxdW90O0NhbGlicmkmcXVvdDssJnF1b3Q7c2Fucy1zZXJpZiZxdW90OyI+KTxicj4NCjxiPkNj
OjwvYj48c3BhbiBjbGFzcz0iYXBwbGUtY29udmVydGVkLXNwYWNlIj4mbmJzcDs8L3NwYW4+TWlj
aGFlbCBSaWNoYXJkc29uOyBSZW5lIFN0cnVpazs8c3BhbiBjbGFzcz0iYXBwbGUtY29udmVydGVk
LXNwYWNlIj4mbmJzcDs8L3NwYW4+PGEgaHJlZj0ibWFpbHRvOjZ0aXNjaC1zZWN1cml0eUBpZXRm
Lm9yZyI+PHNwYW4gc3R5bGU9ImNvbG9yOnB1cnBsZSI+NnRpc2NoLXNlY3VyaXR5QGlldGYub3Jn
PC9zcGFuPjwvYT48YnI+DQo8Yj5TdWJqZWN0OjwvYj48c3BhbiBjbGFzcz0iYXBwbGUtY29udmVy
dGVkLXNwYWNlIj4mbmJzcDs8L3NwYW4+UmU6IFs2dGlzY2gtc2VjdXJpdHldIGFnZW5kYSBmb3Ig
MjAxNC0wNS0yNyA2dGlzY2ggc2VjdXJpdHkgY2FsbDwvc3Bhbj48c3BhbiBsYW5nPSJFTi1VUyI+
PG86cD48L286cD48L3NwYW4+PC9wPg0KPC9kaXY+DQo8ZGl2Pg0KPHAgY2xhc3M9Ik1zb05vcm1h
bCI+PHNwYW4gbGFuZz0iRU4tVVMiPiZuYnNwOzxvOnA+PC9vOnA+PC9zcGFuPjwvcD4NCjwvZGl2
Pg0KPGRpdj4NCjxkaXY+DQo8cCBjbGFzcz0iTXNvTm9ybWFsIiBzdHlsZT0ibWFyZ2luLWJvdHRv
bToxMi4wcHQiPjxzcGFuIGxhbmc9IkVOLVVTIj5Zb3NoaWhpcm8gLTxzcGFuIGNsYXNzPSJhcHBs
ZS1jb252ZXJ0ZWQtc3BhY2UiPiZuYnNwOzwvc3Bhbj48YnI+DQo8YnI+DQpRLjxzcGFuIGNsYXNz
PSJhcHBsZS1jb252ZXJ0ZWQtc3BhY2UiPiZuYnNwOzwvc3Bhbj48L3NwYW4+PHNwYW4gbGFuZz0i
RU4tVVMiIHN0eWxlPSJmb250LXNpemU6MTAuMHB0O2ZvbnQtZmFtaWx5OiZxdW90O0FyaWFsJnF1
b3Q7LCZxdW90O3NhbnMtc2VyaWYmcXVvdDs7Y29sb3I6IzFGNDk3RCI+SW4gdy9IQVJULCBhcmUg
YWxsIGJlYWNvbiBmcmFtZXMgYXV0aGVudGljYXRlZCB3aXRoIGEgd2VsbC1rbm93biBrZXkgZXZl
biBhZnRlciBhIGpvaW5pbmcgbm9kZSBvYnRhaW5lZCB0aGUgcnVudGltZQ0KIGxpbmsgbGF5ZXIg
a2V5Pzwvc3Bhbj48c3BhbiBsYW5nPSJFTi1VUyI+PG86cD48L286cD48L3NwYW4+PC9wPg0KPC9k
aXY+DQo8ZGl2Pg0KPHAgY2xhc3M9Ik1zb05vcm1hbCIgc3R5bGU9Im1hcmdpbi1ib3R0b206MTIu
MHB0Ij48c3BhbiBsYW5nPSJFTi1VUyIgc3R5bGU9ImZvbnQtc2l6ZToxMC4wcHQ7Zm9udC1mYW1p
bHk6JnF1b3Q7QXJpYWwmcXVvdDssJnF1b3Q7c2Fucy1zZXJpZiZxdW90Oztjb2xvcjojMUY0OTdE
Ij5BLiBZZXMuIEluIFdpcmVsZXNzSEFSVCB0aGUgYmVhY29ucyAoY2FsbGVkICZxdW90O2FkdmVy
dGlzZW1lbnRzJnF1b3Q7IGJ1dCB0aGV5IHNlcnZlIHRoZSBzYW1lIHB1cnBvc2UgYW5kIGhhdmUg
c2ltaWxhciBjb250ZW50KQ0KIGFyZSBpbnRlbmRlZCBmb3IgZGV2aWNlcyBub3QgeWV0IGluIHRo
ZSBuZXR3b3JrLCBzbyB0aGV5IGFsd2F5cyB1c2UgdGhlIHdlbGwta25vd24ga2V5LiZuYnNwOyBU
byBkaXNjb3ZlciBvdGhlciBub2RlcyB3aXRoaW4gdGhlIG5ldHdvcmssIHRoZXkgdXNlIGZyYW1l
cyBzZWN1cmVkIHdpdGggdGhlIHJ1bnRpbWUgbGluay1sYXllciBrZXkuPC9zcGFuPjxzcGFuIGxh
bmc9IkVOLVVTIj48bzpwPjwvbzpwPjwvc3Bhbj48L3A+DQo8L2Rpdj4NCjxkaXY+DQo8ZGl2Pg0K
PHAgY2xhc3M9Ik1zb05vcm1hbCI+PHNwYW4gbGFuZz0iRU4tVVMiIHN0eWxlPSJmb250LXNpemU6
MTAuMHB0O2ZvbnQtZmFtaWx5OiZxdW90O0FyaWFsJnF1b3Q7LCZxdW90O3NhbnMtc2VyaWYmcXVv
dDs7Y29sb3I6IzFGNDk3RCI+Sm9uYXRoYW48L3NwYW4+PHNwYW4gbGFuZz0iRU4tVVMiPjxvOnA+
PC9vOnA+PC9zcGFuPjwvcD4NCjwvZGl2Pg0KPC9kaXY+DQo8L2Rpdj4NCjxkaXY+DQo8cCBjbGFz
cz0iTXNvTm9ybWFsIiBzdHlsZT0ibWFyZ2luLWJvdHRvbToxMi4wcHQiPjxzcGFuIGxhbmc9IkVO
LVVTIj4mbmJzcDs8bzpwPjwvbzpwPjwvc3Bhbj48L3A+DQo8ZGl2Pg0KPGRpdj4NCjxwIGNsYXNz
PSJNc29Ob3JtYWwiPjxzcGFuIGxhbmc9IkVOLVVTIj5PbiBUdWUsIE1heSAyNywgMjAxNCBhdCAx
MToxOCBQTSwgJmx0OzxhIGhyZWY9Im1haWx0bzp5b3NoaWhpcm8ub2hiYUB0b3NoaWJhLmNvLmpw
IiB0YXJnZXQ9Il9ibGFuayI+PHNwYW4gc3R5bGU9ImNvbG9yOnB1cnBsZSI+eW9zaGloaXJvLm9o
YmFAdG9zaGliYS5jby5qcDwvc3Bhbj48L2E+Jmd0OyB3cm90ZTo8bzpwPjwvbzpwPjwvc3Bhbj48
L3A+DQo8L2Rpdj4NCjxibG9ja3F1b3RlIHN0eWxlPSJib3JkZXI6bm9uZTtib3JkZXItbGVmdDpz
b2xpZCAjQ0NDQ0NDIDEuMHB0O3BhZGRpbmc6MG1tIDBtbSAwbW0gNi4wcHQ7bWFyZ2luLWxlZnQ6
NC44cHQ7bWFyZ2luLXRvcDo1LjBwdDttYXJnaW4tcmlnaHQ6MG1tO21hcmdpbi1ib3R0b206NS4w
cHQiPg0KPGRpdj4NCjxkaXY+DQo8cCBjbGFzcz0iTXNvTm9ybWFsIj48c3BhbiBsYW5nPSJFTi1V
UyIgc3R5bGU9ImZvbnQtc2l6ZToxMC4wcHQ7Zm9udC1mYW1pbHk6JnF1b3Q7QXJpYWwmcXVvdDss
JnF1b3Q7c2Fucy1zZXJpZiZxdW90Oztjb2xvcjojMUY0OTdEIj5IaSBKb25hdGhhbiw8L3NwYW4+
PHNwYW4gbGFuZz0iRU4tVVMiPjxvOnA+PC9vOnA+PC9zcGFuPjwvcD4NCjwvZGl2Pg0KPGRpdj4N
CjxwIGNsYXNzPSJNc29Ob3JtYWwiPjxzcGFuIGxhbmc9IkVOLVVTIiBzdHlsZT0iZm9udC1zaXpl
OjEwLjBwdDtmb250LWZhbWlseTomcXVvdDtBcmlhbCZxdW90OywmcXVvdDtzYW5zLXNlcmlmJnF1
b3Q7O2NvbG9yOiMxRjQ5N0QiPiZuYnNwOzwvc3Bhbj48c3BhbiBsYW5nPSJFTi1VUyI+PG86cD48
L286cD48L3NwYW4+PC9wPg0KPC9kaXY+DQo8ZGl2Pg0KPHAgY2xhc3M9Ik1zb05vcm1hbCI+PHNw
YW4gbGFuZz0iRU4tVVMiIHN0eWxlPSJmb250LXNpemU6MTAuMHB0O2ZvbnQtZmFtaWx5OiZxdW90
O0FyaWFsJnF1b3Q7LCZxdW90O3NhbnMtc2VyaWYmcXVvdDs7Y29sb3I6IzFGNDk3RCI+VGhhbmsg
eW91IGZvciBzZW5kaW5nIHRoZSBzdW1tYXJ5IG9mIHcvSEFSVCBqb2luaW5nLjwvc3Bhbj48c3Bh
biBsYW5nPSJFTi1VUyI+PG86cD48L286cD48L3NwYW4+PC9wPg0KPC9kaXY+DQo8ZGl2Pg0KPHAg
Y2xhc3M9Ik1zb05vcm1hbCI+PHNwYW4gbGFuZz0iRU4tVVMiIHN0eWxlPSJmb250LXNpemU6MTAu
MHB0O2ZvbnQtZmFtaWx5OiZxdW90O0FyaWFsJnF1b3Q7LCZxdW90O3NhbnMtc2VyaWYmcXVvdDs7
Y29sb3I6IzFGNDk3RCI+Jm5ic3A7PC9zcGFuPjxzcGFuIGxhbmc9IkVOLVVTIj48bzpwPjwvbzpw
Pjwvc3Bhbj48L3A+DQo8L2Rpdj4NCjxkaXY+DQo8cCBjbGFzcz0iTXNvTm9ybWFsIj48c3BhbiBs
YW5nPSJFTi1VUyIgc3R5bGU9ImZvbnQtc2l6ZToxMC4wcHQ7Zm9udC1mYW1pbHk6JnF1b3Q7QXJp
YWwmcXVvdDssJnF1b3Q7c2Fucy1zZXJpZiZxdW90Oztjb2xvcjojMUY0OTdEIj5JIGhhdmUgcXVl
c3Rpb24uPC9zcGFuPjxzcGFuIGxhbmc9IkVOLVVTIj48bzpwPjwvbzpwPjwvc3Bhbj48L3A+DQo8
L2Rpdj4NCjxkaXY+DQo8cCBjbGFzcz0iTXNvTm9ybWFsIj48c3BhbiBsYW5nPSJFTi1VUyIgc3R5
bGU9ImZvbnQtc2l6ZToxMC4wcHQ7Zm9udC1mYW1pbHk6JnF1b3Q7QXJpYWwmcXVvdDssJnF1b3Q7
c2Fucy1zZXJpZiZxdW90Oztjb2xvcjojMUY0OTdEIj4mbmJzcDs8L3NwYW4+PHNwYW4gbGFuZz0i
RU4tVVMiPjxvOnA+PC9vOnA+PC9zcGFuPjwvcD4NCjwvZGl2Pg0KPGRpdj4NCjxwIGNsYXNzPSJN
c29Ob3JtYWwiPjxzcGFuIGxhbmc9IkVOLVVTIiBzdHlsZT0iZm9udC1zaXplOjEwLjBwdDtmb250
LWZhbWlseTomcXVvdDtBcmlhbCZxdW90OywmcXVvdDtzYW5zLXNlcmlmJnF1b3Q7O2NvbG9yOiMx
RjQ5N0QiPkluIHcvSEFSVCwgYXJlIGFsbCBiZWFjb24gZnJhbWVzIGF1dGhlbnRpY2F0ZWQgd2l0
aCBhIHdlbGwta25vd24ga2V5IGV2ZW4gYWZ0ZXIgYSBqb2luaW5nIG5vZGUgb2J0YWluZWQgdGhl
IHJ1bnRpbWUgbGluayBsYXllciBrZXk/Jm5ic3A7PC9zcGFuPjxzcGFuIGxhbmc9IkVOLVVTIj48
bzpwPjwvbzpwPjwvc3Bhbj48L3A+DQo8L2Rpdj4NCjxkaXY+DQo8cCBjbGFzcz0iTXNvTm9ybWFs
Ij48c3BhbiBsYW5nPSJFTi1VUyIgc3R5bGU9ImZvbnQtc2l6ZToxMC4wcHQ7Zm9udC1mYW1pbHk6
JnF1b3Q7QXJpYWwmcXVvdDssJnF1b3Q7c2Fucy1zZXJpZiZxdW90Oztjb2xvcjojMUY0OTdEIj4m
bmJzcDs8L3NwYW4+PHNwYW4gbGFuZz0iRU4tVVMiPjxvOnA+PC9vOnA+PC9zcGFuPjwvcD4NCjwv
ZGl2Pg0KPGRpdj4NCjxwIGNsYXNzPSJNc29Ob3JtYWwiPjxzcGFuIGxhbmc9IkVOLVVTIiBzdHls
ZT0iZm9udC1zaXplOjEwLjBwdDtmb250LWZhbWlseTomcXVvdDtBcmlhbCZxdW90OywmcXVvdDtz
YW5zLXNlcmlmJnF1b3Q7O2NvbG9yOiMxRjQ5N0QiPlJlZ2FyZHMsPC9zcGFuPjxzcGFuIGxhbmc9
IkVOLVVTIj48bzpwPjwvbzpwPjwvc3Bhbj48L3A+DQo8L2Rpdj4NCjxkaXY+DQo8cCBjbGFzcz0i
TXNvTm9ybWFsIj48c3BhbiBsYW5nPSJFTi1VUyIgc3R5bGU9ImZvbnQtc2l6ZToxMC4wcHQ7Zm9u
dC1mYW1pbHk6JnF1b3Q7QXJpYWwmcXVvdDssJnF1b3Q7c2Fucy1zZXJpZiZxdW90Oztjb2xvcjoj
MUY0OTdEIj5Zb3NoaWhpcm8gT2hiYTwvc3Bhbj48c3BhbiBsYW5nPSJFTi1VUyI+PG86cD48L286
cD48L3NwYW4+PC9wPg0KPC9kaXY+DQo8ZGl2Pg0KPHAgY2xhc3M9Ik1zb05vcm1hbCI+PHNwYW4g
bGFuZz0iRU4tVVMiIHN0eWxlPSJmb250LXNpemU6MTAuMHB0O2ZvbnQtZmFtaWx5OiZxdW90O0Fy
aWFsJnF1b3Q7LCZxdW90O3NhbnMtc2VyaWYmcXVvdDs7Y29sb3I6IzFGNDk3RCI+Jm5ic3A7PC9z
cGFuPjxzcGFuIGxhbmc9IkVOLVVTIj48bzpwPjwvbzpwPjwvc3Bhbj48L3A+DQo8L2Rpdj4NCjxk
aXY+DQo8cCBjbGFzcz0iTXNvTm9ybWFsIj48c3BhbiBsYW5nPSJFTi1VUyIgc3R5bGU9ImZvbnQt
c2l6ZToxMC4wcHQ7Zm9udC1mYW1pbHk6JnF1b3Q7QXJpYWwmcXVvdDssJnF1b3Q7c2Fucy1zZXJp
ZiZxdW90Oztjb2xvcjojMUY0OTdEIj4mbmJzcDs8L3NwYW4+PHNwYW4gbGFuZz0iRU4tVVMiPjxv
OnA+PC9vOnA+PC9zcGFuPjwvcD4NCjwvZGl2Pg0KPGRpdj4NCjxwIGNsYXNzPSJNc29Ob3JtYWwi
PjxzcGFuIGxhbmc9IkVOLVVTIiBzdHlsZT0iZm9udC1zaXplOjEwLjBwdDtmb250LWZhbWlseTom
cXVvdDtBcmlhbCZxdW90OywmcXVvdDtzYW5zLXNlcmlmJnF1b3Q7O2NvbG9yOiMxRjQ5N0QiPiZu
YnNwOzwvc3Bhbj48c3BhbiBsYW5nPSJFTi1VUyI+PG86cD48L286cD48L3NwYW4+PC9wPg0KPC9k
aXY+DQo8ZGl2Pg0KPHAgY2xhc3M9Ik1zb05vcm1hbCI+PHNwYW4gbGFuZz0iRU4tVVMiIHN0eWxl
PSJmb250LXNpemU6MTAuMHB0O2ZvbnQtZmFtaWx5OiZxdW90O0FyaWFsJnF1b3Q7LCZxdW90O3Nh
bnMtc2VyaWYmcXVvdDs7Y29sb3I6IzFGNDk3RCI+Jm5ic3A7PC9zcGFuPjxzcGFuIGxhbmc9IkVO
LVVTIj48bzpwPjwvbzpwPjwvc3Bhbj48L3A+DQo8L2Rpdj4NCjxkaXY+DQo8cCBjbGFzcz0iTXNv
Tm9ybWFsIj48Yj48c3BhbiBsYW5nPSJFTi1VUyIgc3R5bGU9ImZvbnQtc2l6ZToxMS4wcHQ7Zm9u
dC1mYW1pbHk6JnF1b3Q7Q2FsaWJyaSZxdW90OywmcXVvdDtzYW5zLXNlcmlmJnF1b3Q7Ij5Gcm9t
Ojwvc3Bhbj48L2I+PHNwYW4gY2xhc3M9ImFwcGxlLWNvbnZlcnRlZC1zcGFjZSI+PHNwYW4gbGFu
Zz0iRU4tVVMiIHN0eWxlPSJmb250LXNpemU6MTEuMHB0O2ZvbnQtZmFtaWx5OiZxdW90O0NhbGli
cmkmcXVvdDssJnF1b3Q7c2Fucy1zZXJpZiZxdW90OyI+Jm5ic3A7PC9zcGFuPjwvc3Bhbj48c3Bh
biBsYW5nPSJFTi1VUyIgc3R5bGU9ImZvbnQtc2l6ZToxMS4wcHQ7Zm9udC1mYW1pbHk6JnF1b3Q7
Q2FsaWJyaSZxdW90OywmcXVvdDtzYW5zLXNlcmlmJnF1b3Q7Ij42dGlzY2gtc2VjdXJpdHkNCiBb
bWFpbHRvOjxhIGhyZWY9Im1haWx0bzo2dGlzY2gtc2VjdXJpdHktYm91bmNlc0BpZXRmLm9yZyIg
dGFyZ2V0PSJfYmxhbmsiPjxzcGFuIHN0eWxlPSJjb2xvcjpwdXJwbGUiPjZ0aXNjaC1zZWN1cml0
eS1ib3VuY2VzQGlldGYub3JnPC9zcGFuPjwvYT5dPHNwYW4gY2xhc3M9ImFwcGxlLWNvbnZlcnRl
ZC1zcGFjZSI+Jm5ic3A7PC9zcGFuPjxiPk9uIEJlaGFsZiBPZjxzcGFuIGNsYXNzPSJhcHBsZS1j
b252ZXJ0ZWQtc3BhY2UiPiZuYnNwOzwvc3Bhbj48L2I+Sm9uYXRoYW4NCiBTaW1vbjxicj4NCjxi
PlNlbnQ6PC9iPjxzcGFuIGNsYXNzPSJhcHBsZS1jb252ZXJ0ZWQtc3BhY2UiPiZuYnNwOzwvc3Bh
bj5UdWVzZGF5LCBNYXkgMjcsIDIwMTQgMTA6NDEgUE08YnI+DQo8Yj5Ubzo8L2I+PHNwYW4gY2xh
c3M9ImFwcGxlLWNvbnZlcnRlZC1zcGFjZSI+Jm5ic3A7PC9zcGFuPlJlbmUgU3RydWlrPGJyPg0K
PGI+Q2M6PC9iPjxzcGFuIGNsYXNzPSJhcHBsZS1jb252ZXJ0ZWQtc3BhY2UiPiZuYnNwOzwvc3Bh
bj5NaWNoYWVsIFJpY2hhcmRzb247PHNwYW4gY2xhc3M9ImFwcGxlLWNvbnZlcnRlZC1zcGFjZSI+
Jm5ic3A7PC9zcGFuPjxhIGhyZWY9Im1haWx0bzo2dGlzY2gtc2VjdXJpdHlAaWV0Zi5vcmciIHRh
cmdldD0iX2JsYW5rIj48c3BhbiBzdHlsZT0iY29sb3I6cHVycGxlIj42dGlzY2gtc2VjdXJpdHlA
aWV0Zi5vcmc8L3NwYW4+PC9hPjxicj4NCjxiPlN1YmplY3Q6PC9iPjxzcGFuIGNsYXNzPSJhcHBs
ZS1jb252ZXJ0ZWQtc3BhY2UiPiZuYnNwOzwvc3Bhbj5SZTogWzZ0aXNjaC1zZWN1cml0eV0gYWdl
bmRhIGZvciAyMDE0LTA1LTI3IDZ0aXNjaCBzZWN1cml0eSBjYWxsPC9zcGFuPjxzcGFuIGxhbmc9
IkVOLVVTIj48bzpwPjwvbzpwPjwvc3Bhbj48L3A+DQo8L2Rpdj4NCjxkaXY+DQo8cCBjbGFzcz0i
TXNvTm9ybWFsIj48c3BhbiBsYW5nPSJFTi1VUyI+Jm5ic3A7PG86cD48L286cD48L3NwYW4+PC9w
Pg0KPC9kaXY+DQo8ZGl2Pg0KPGRpdj4NCjxkaXY+DQo8cCBjbGFzcz0iTXNvTm9ybWFsIiBzdHls
ZT0ibWFyZ2luLWJvdHRvbToxMi4wcHQiPjxzcGFuIGxhbmc9IkVOLVVTIj5SZW5lIGhhZCBhc2tl
ZCBvbiBhIHByZXZpb3VzIGNhbGwgZm9yIHNvbWVvbmUgdG8gc3VtbWFyaXplIFdpcmVsZXNzSEFS
VCBqb2luaW5nIC0gaGVyZSB5b3UgZ28uPGJyPg0KPGJyPg0KKiBPbmUgb3IgbW9yZSBkZXZpY2Vz
IGFyZSBzZW5kaW5nIGJlYWNvbnMgdG8gYWR2ZXJ0aXNlIHRoZSBwcmVzZW5jZSBvZiB0aGUgbmV0
d29yay4gSW4gV2lyZWxlc3NIQVJULCB0aGlzIGZyYW1lIGlzIHVuZW5jcnlwdGVkLCBidXQgYXV0
aGVudGljYXRlZCB3aXRoIGEgd2VsbCBrbm93biBrZXkuJm5ic3A7IFRoZSBiZWFjb24gY29udGFp
bnMgdGhlIGN1cnJlbnQgQVNOLCB3aGljaCB0aGUgam9pbmluZyBkZXZpY2UgdXNlcyB0byBzeW5j
aHJvbml6ZSBpdHMgY2xvY2suPG86cD48L286cD48L3NwYW4+PC9wPg0KPGRpdj4NCjxwIGNsYXNz
PSJNc29Ob3JtYWwiIHN0eWxlPSJtYXJnaW4tYm90dG9tOjEyLjBwdCI+PHNwYW4gbGFuZz0iRU4t
VVMiPiogT25jZSB0aGUgam9pbmluZyBub2RlIGhhcyBoZWFyZCBhIGJlYWNvbiwgaXQgY29udGlu
dWVzIGxpc3RlbmluZyBmb3IgYWRkaXRpb25hbCBiZWFjb25zIGZvciBhIHNob3J0IHNwZWNpZmll
ZCB0aW1lb3V0LjxvOnA+PC9vOnA+PC9zcGFuPjwvcD4NCjwvZGl2Pg0KPHAgY2xhc3M9Ik1zb05v
cm1hbCIgc3R5bGU9Im1hcmdpbi1ib3R0b206MTIuMHB0Ij48c3BhbiBsYW5nPSJFTi1VUyI+KiBU
aGUgam9pbmluZyBub2RlIGVuY3J5cHRzIGEgZnJhbWUgY29udGFpbmluZyBzb21lIEhBUlQgc3Bl
Y2lmaWMgY29udGVudCwgaW5jbHVkaW5nIGEgbGlzdCBvZiBiZWFjb25pbmcgbmVpZ2hib3JzIGl0
IGhlYXJkIGluIHRoZSBwcmV2aW91cyBzdGVwcy4gVGhlIHNpemUgb2YgdGhlIHBheWxvYWQgaXMg
fiA2MCBieXRlcy4mbmJzcDsgVGhlDQogcGFja2V0IGlzIHJvdXRlZCBieSBhICZxdW90O3Byb3h5
JnF1b3Q7IG5vZGUgLSB0aGUgam9pbmluZyBwYXJlbnQuIFRoZSBmcmFtZSBpcyBhdXRoZW50aWNh
dGVkIHVzaW5nIHRoZSB3ZWxsLWtub3duIGtleSwgYW5kIGVuY3J5cHRlZCB1c2luZyBhIHNoYXJl
ZCBzeW1tZXRyaWMga2V5IGtub3duIG9ubHkgYnkgdGhlIG5vZGUgYW5kIHRoZSBtYW5hZ2VyLjxi
cj4NCjxicj4NCiogVGhlIG1hbmFnZXIgcmVzcG9uZHMgd2l0aCBhIGZyYW1lIGNvbnRhaW5pbmcg
dGhlIHJ1bi10aW1lIGxpbmstbGF5ZXIga2V5LCB0aGUgbm9kZSdzIG5ldyBzaG9ydCBhZGRyZXNz
ICh0aGlzIHRha2VzIHRoZSBwbGFjZSBvZiBQQU4gY29vcmRpbmF0b3IgYXNzb2NpYXRpb24pLCBh
bmQgYSB1bmljYXN0IHNlc3Npb24ga2V5IGFuZCBzdGFydGluZyBub25jZSBmb3IgdGhlIG1hbmFn
ZXIuIFRoaXMgZnJhbWUgaXMgZW5jcnlwdGVkIHdpdGggdGhlIHN5bW1ldHJpYw0KIGtleS4gVGhl
IHBheWxvYWQgaXMgfiA2MCBieXRlcywgYW5kIGlzIHJvdXRlZCB0byB0aGUgcHJveHkgZm9yIGRl
bGl2ZXJ5IHRvIHRoZSBqb2luaW5nIG5vZGUgLSB0aGUgcHJveHkgdXNlcyB0aGUgbGluay1sYXll
ciB3ZWxsIGtub3duIGtleSBvbiB0aGUgZnJhbWUuPG86cD48L286cD48L3NwYW4+PC9wPg0KPGRp
dj4NCjxwIGNsYXNzPSJNc29Ob3JtYWwiIHN0eWxlPSJtYXJnaW4tYm90dG9tOjEyLjBwdCI+PHNw
YW4gbGFuZz0iRU4tVVMiPiogQXQgdGhpcyBwb2ludCB0aGUgam9pbmluZyBub2RlIHRyYW5zaXRp
b25zIHRvIHVzaW5nIHRoZSBydW4tdGltZSBsaW5rLWxheWVyIGtleSBmb3IgYWxsIGxpbmstbGF5
ZXIgZnJhbWVzLCBhbmQgdGhlIG1hbmFnZXIgdW5pY2FzdCBzZXNzaW9uIGZvciBlbmQtdG8tZW5k
IG1hbmFnZXIgdHJhZmZpYy4gVGhpcyBlbmRzIHRoZSBpbml0aWFsDQogc2VjdXJpdHkgaGFuZHNo
YWtlLjxvOnA+PC9vOnA+PC9zcGFuPjwvcD4NCjwvZGl2Pg0KPGRpdj4NCjxwIGNsYXNzPSJNc29O
b3JtYWwiIHN0eWxlPSJtYXJnaW4tYm90dG9tOjEyLjBwdCI+PHNwYW4gbGFuZz0iRU4tVVMiPiog
T3ZlciBhIG51bWJlciBvZiBhZGRpdGlvbmFsIGZyYW1lcywgdGhlIG1hbmFnZXIgYXNzaWducyBh
ZGRpdGlvbmFsIHNlc3Npb25zLCBpbmNsdWRpbmcgYnJvYWRjYXN0IHNlc3Npb25zLCBhbmQgYSB1
bmljYXN0IHNlc3Npb24gdG8gdGhlIEdhdGV3YXkgKHNpbmsgZm9yIGFsbCBkYXRhIHRyYWZmaWMp
LCBhbmQgYWRkaXRpb25hbA0KIGNvbW11bmljYXRpb25zIHJlc291cmNlcywgcm91dGluZyBpbmZv
cm1hdGlvbiwgZXRjLiZuYnNwOyBUaGVyZSBpcyBubyBleHBsaWNpdCB0cmFuc2l0aW9uIGZyb20g
am9pbmluZyB0byBqb2luZWQgLSB0aGUgbW90ZSB0cmFuc2l0aW9ucyB3aGVuIGNlcnRhaW4ga2V5
IGZyYW1lcyBhcmUgcmVjZWl2ZWQuPG86cD48L286cD48L3NwYW4+PC9wPg0KPC9kaXY+DQo8cCBj
bGFzcz0iTXNvTm9ybWFsIiBzdHlsZT0ibWFyZ2luLWJvdHRvbToxMi4wcHQiPjxzcGFuIGxhbmc9
IkVOLVVTIj4qIE5vdGUgdGhhdCBhIFdpcmVsZXNzSEFSVCBsaW5rLWxheWVyIGZyYW1lIGNvbnRh
aW5zIGFuZCBhZGRpdGlvbmFsIGZyYW1lIHR5cGUgYnl0ZSBhbmQgYSA0LWJ5dGUgbGluay1sYXll
ciBNSUMsIG9uIHRvcCBvZiB0aGUgdW5zZWN1cmVkIDE1LjQgZnJhbWUuJm5ic3A7IEEgbmV0d29y
ayBmcmFtZSBjb250YWlucyBhbiBhZGRpdGlvbmFsDQogMTYtNDAgYnl0ZXMgb2YgYWRkcmVzc2lu
Zywgcm91dGluZywgc2VjdXJpdHkgYW5kIG90aGVyIGluZm9ybWF0aW9uLjxvOnA+PC9vOnA+PC9z
cGFuPjwvcD4NCjwvZGl2Pg0KPHAgY2xhc3M9Ik1zb05vcm1hbCIgc3R5bGU9Im1hcmdpbi1ib3R0
b206MTIuMHB0Ij48c3BhbiBsYW5nPSJFTi1VUyI+SG9wZSB0aGlzIGhlbHAhPG86cD48L286cD48
L3NwYW4+PC9wPg0KPC9kaXY+DQo8ZGl2Pg0KPHAgY2xhc3M9Ik1zb05vcm1hbCI+PHNwYW4gbGFu
Zz0iRU4tVVMiPkpvbmF0aGFuPG86cD48L286cD48L3NwYW4+PC9wPg0KPC9kaXY+DQo8ZGl2Pg0K
PGRpdj4NCjxwIGNsYXNzPSJNc29Ob3JtYWwiPjxzcGFuIGxhbmc9IkVOLVVTIj4mbmJzcDs8bzpw
PjwvbzpwPjwvc3Bhbj48L3A+DQo8L2Rpdj4NCjwvZGl2Pg0KPC9kaXY+DQo8ZGl2Pg0KPHAgY2xh
c3M9Ik1zb05vcm1hbCIgc3R5bGU9Im1hcmdpbi1ib3R0b206MTIuMHB0Ij48c3BhbiBsYW5nPSJF
Ti1VUyI+Jm5ic3A7PG86cD48L286cD48L3NwYW4+PC9wPg0KPGRpdj4NCjxkaXY+DQo8cCBjbGFz
cz0iTXNvTm9ybWFsIj48c3BhbiBsYW5nPSJFTi1VUyI+T24gTW9uLCBNYXkgMjYsIDIwMTQgYXQg
ODowOSBQTSwgUmVuZSBTdHJ1aWsgJmx0OzxhIGhyZWY9Im1haWx0bzpyc3RydWlrLmV4dEBnbWFp
bC5jb20iIHRhcmdldD0iX2JsYW5rIj48c3BhbiBzdHlsZT0iY29sb3I6cHVycGxlIj5yc3RydWlr
LmV4dEBnbWFpbC5jb208L3NwYW4+PC9hPiZndDsgd3JvdGU6PG86cD48L286cD48L3NwYW4+PC9w
Pg0KPC9kaXY+DQo8YmxvY2txdW90ZSBzdHlsZT0iYm9yZGVyOm5vbmU7Ym9yZGVyLWxlZnQ6c29s
aWQgI0NDQ0NDQyAxLjBwdDtwYWRkaW5nOjBtbSAwbW0gMG1tIDYuMHB0O21hcmdpbi1sZWZ0OjQu
OHB0O21hcmdpbi10b3A6NS4wcHQ7bWFyZ2luLXJpZ2h0OjBtbTttYXJnaW4tYm90dG9tOjUuMHB0
Ij4NCjxkaXY+DQo8ZGl2Pg0KPGRpdj4NCjxwIGNsYXNzPSJNc29Ob3JtYWwiPjxzcGFuIGxhbmc9
IkVOLVVTIj5IaSBNaWNoYWVsOjxicj4NCjxicj4NCkkgd291bGQgbGlrZSB0byBkaXNjdXNzIHRo
ZSBvdXRzdGFuZGluZyBpc3N1ZXMgSSBzdW1tYXJpemVkIGluIG15IGVtYWlsIG9mIFR1ZSBsYXN0
IHdlZWssIE1heSAyMCwgMjAxNCwgOTo0NWFtIEVEVCAoc2VlPHNwYW4gY2xhc3M9ImFwcGxlLWNv
bnZlcnRlZC1zcGFjZSI+Jm5ic3A7PC9zcGFuPjxhIGhyZWY9Imh0dHA6Ly9jcC5tY2FmZWUuY29t
L2QvNWZIQ01VcDQxRVN5TnQ1NU9XdFNqdFBxYndWQmNTeVVlcHZkRUszemhPeUNPcWVqcnpQUFB6
NVhDTjZBQnFNMWhZRXZJdW5kRE94LU5Wc1RKUVhJZmNMWnZDNFRRVFM2ZUxzS0NPLVBQWFgzWFVW
ekJIRlNoamxLZXBWa2ZmR2hCcndxcmhkSTZYWXlNQ1ktZWhvamQ3OUtWSTA1YlZLWTAxTWpiWDZO
ZWhEWTA1ekFWa0lqYlEtUHNwamJwcEtjdnhmNXE0clRLWVZNZWRLakJpTmNMalhkTkJjSW44bHJ4
clcwR25QdFUwMnJoaHVoS3IxdkY2eTBRSktqQmlOY0xqWGROQmNJcW5qaDFGN1U4cXE4N3FOZDQy
dFFtMlpUT1dvVVFnZWpCaU5jUWdrLVBzcGpiNnkyU0REQ1Q2M3BPX28iIHRhcmdldD0iX2JsYW5r
Ij48c3BhbiBzdHlsZT0iY29sb3I6cHVycGxlIj5odHRwOi8vd3d3LmlldGYub3JnL21haWwtYXJj
aGl2ZS93ZWIvNnRpc2NoLXNlY3VyaXR5L2N1cnJlbnQvbXNnMDAwODYuaHRtbDwvc3Bhbj48L2E+
KS4NCiBUaGlzIHdhcyBhbHNvIG9uZSBvZiB0aGUgYWN0aW9uIGl0ZW1zIGF0IHRoZSBjb25jbHVz
aW9uIG9mIGxhc3Qgd2VlaydzIDZUaVNDSCBzZWN1cml0eSBjYWxsLjxicj4NCjxicj4NCkZZSSAt
IHRoZSB3L0hBUlQgY29tbXVuaWNhdGlvbiBmbG93cyB3ZXJlIGRpc2N1c3NlZCBkdXJpbmcgdGhl
IDZUaVNDSCBzZWN1cml0eSBjb25mIGNhbGwgdGhlIHdlZWsgYmVmb3JlLCBvbiBNb24gTWF5IDEy
LCAyMDE0LiBJZiBvbmUgd2lzaGVzIHRvIGdvIG92ZXIgdGhpcyBhZ2FpbiwgdGhhdCBpcyBmaW5l
LCBidXQgSSB3b3VsZCBwcmVmZXIgdXMgZ2l2aW5nIHByZWZlcmVuY2UgdG8gdGFraW5nIG9uIGFs
cmVhZHkgYXJ0aWN1bGF0ZWQgaXNzdWVzDQogKHdoaWNoIHdlcmUgYXNzaWduZWQgYXMgaG9tZXdv
cmsgYXNzaWdubWVudCB0byByZWZsZWN0IHVwb24pIGZpcnN0IChpLmUuLCBwcmlvciB0byBpdGVt
ICM0IG9mIHRoZSBwcm9wb3NlZCBhZ2VuZGEpLjxicj4NCjxicj4NCkFzIGFub3RoZXIgYWdlbmRh
IHBvaW50LCBJIHdvdWxkIGxpa2UgdXMgdG8gZGlzY3VzcyB0aGUgZnJlcXVlbmN5IG9mIGZ1dHVy
ZSBjYWxscyAoYXMgcGFydCBvZiBFT0IpLjxicj4NCjxicj4NCkJlc3QgcmVnYXJkcywgUmVuZTxi
cj4NCjxicj4NCjxicj4NCk9uIDUvMjYvMjAxNCAxMDo0OSBQTSwgTWljaGFlbCBSaWNoYXJkc29u
IHdyb3RlOjxvOnA+PC9vOnA+PC9zcGFuPjwvcD4NCjwvZGl2Pg0KPC9kaXY+DQo8YmxvY2txdW90
ZSBzdHlsZT0ibWFyZ2luLXRvcDo1LjBwdDttYXJnaW4tYm90dG9tOjUuMHB0Ij4NCjxwcmU+PHNw
YW4gbGFuZz0iRU4tVVMiPlRvIHJlbWluZCwgd2UgbW92ZWQgdGhlIGNhbGwgZnJvbSB0aGUgMjZ0
aCB0byB0aGUgMjd0aCBhdCAxMGFtIEVEVC48bzpwPjwvbzpwPjwvc3Bhbj48L3ByZT4NCjxwcmU+
PHNwYW4gbGFuZz0iRU4tVVMiPlRoYXQncyA5MCBtaW51dGVzIGZyb20gdGhpcyBlbWFpbC48bzpw
PjwvbzpwPjwvc3Bhbj48L3ByZT4NCjxwcmU+PHNwYW4gbGFuZz0iRU4tVVMiPiZuYnNwOzxvOnA+
PC9vOnA+PC9zcGFuPjwvcHJlPg0KPHByZT48c3BhbiBsYW5nPSJFTi1VUyI+MSkgbm90ZXdlbGwu
PG86cD48L286cD48L3NwYW4+PC9wcmU+DQo8cHJlPjxzcGFuIGxhbmc9IkVOLVVTIj4yKSBpbnRy
b3M8bzpwPjwvbzpwPjwvc3Bhbj48L3ByZT4NCjxwcmU+PHNwYW4gbGFuZz0iRU4tVVMiPjMpIHJl
Y2FwIG9mIGRyYWZ0LXBpcm8tPG86cD48L286cD48L3NwYW4+PC9wcmU+DQo8cHJlPjxzcGFuIGxh
bmc9IkVOLVVTIj40KSB3aXJlbGVzc2hhcnQgLXdheSAtLS0gaG93IGRvZXMgdGhlIGNvbW11bmlj
YXRpb24gd29yaz88bzpwPjwvbzpwPjwvc3Bhbj48L3ByZT4NCjxwcmU+PHNwYW4gbGFuZz0iRU4t
VVMiPjUpIGhvdyB0byBzdW1tYXJpemUgYWxsIG9mIHRoaXMgdG8gdGhlIHdvcmtpbmcgZ3JvdXA8
bzpwPjwvbzpwPjwvc3Bhbj48L3ByZT4NCjxwcmU+PHNwYW4gbGFuZz0iRU4tVVMiPjYpIGhvdyB0
byBjbG9zZSB0aGlzIHByb2Nlc3MgdXA/PG86cD48L286cD48L3NwYW4+PC9wcmU+DQo8cHJlPjxz
cGFuIGxhbmc9IkVOLVVTIj4mbmJzcDs8bzpwPjwvbzpwPjwvc3Bhbj48L3ByZT4NCjxwcmU+PHNw
YW4gbGFuZz0iRU4tVVMiPi0tIHJlbWVtYmVyIHRoYXQgdGhlIGNhbGwgaXMgcmVjb3JkZWQsIGFu
ZCB0aGUgTm90ZVdlbGwgYXBwbGllcy48bzpwPjwvbzpwPjwvc3Bhbj48L3ByZT4NCjxwcmU+PHNw
YW4gbGFuZz0iRU4tVVMiPiZuYnNwOzxvOnA+PC9vOnA+PC9zcGFuPjwvcHJlPg0KPHByZT48c3Bh
biBsYW5nPSJFTi1VUyI+LS0gVGhlIFVSTCB0byBhY2Nlc3MgdGhlIHdlYmV4LCB3aGljaCB3aWxs
IHdlIHVzZSBmb3IgYXVkaW8gb25seTo8bzpwPjwvbzpwPjwvc3Bhbj48L3ByZT4NCjxwcmU+PHNw
YW4gbGFuZz0iRU4tVVMiPiZuYnNwOyA8YSBocmVmPSJodHRwOi8vY3AubWNhZmVlLmNvbS9kLzVm
SENOMFN5TnQ1NU9XdFNqdFBxYndWQmNTeVVlcHZkRUszemhPeUNPcWVqcnpQUFB6NVhDTjZBQnFN
MWhZRXZJdW5kRE94LU5Wc1RKUVhJZmNMWnZDNFRRVFM2ZUxzS0NPLVBQWFgzWFVWekJIRlNoamxL
ZXBWa2ZmR2hCcndxcmpkSTZYWXlNQ1ktZWhvamQ3OUtWSURlcVI0SU9RR21ITTBMMy1uT1FHbUh3
ek1oOTNvOTNnVVZsZFRRbWpoT2d0dTdlbV9tdklVQ2V2THAxWldWMHNxZXJMNlQ5T0ZvQ25GWkNV
T0NtYkFhSk1KWjBsYlZLWTAxZEVFTDhUZHdMUXpoMHFtVDlPRm9DbkZaQ1VPQ21kYkZFd1F6WTRk
ZDQzSm9DeTFlV2IxdVhWdGNzcTg3OU9Gb0NxOGF2cEtjRkJ6aDFyalBQcnoxTG1Udzd3MTciIHRh
cmdldD0iX2JsYW5rIj48c3BhbiBzdHlsZT0iY29sb3I6cHVycGxlIj5odHRwczovL2Npc2NvLndl
YmV4LmNvbS9jaXNjby9qLnBocD9NVElEPW0yZmUxMzliZjg3NmNlYTNlYzYyNzUwY2Q1ODBiNzkw
ODwvc3Bhbj48L2E+PG86cD48L286cD48L3NwYW4+PC9wcmU+DQo8cHJlPjxzcGFuIGxhbmc9IkVO
LVVTIj4mbmJzcDs8bzpwPjwvbzpwPjwvc3Bhbj48L3ByZT4NCjxwcmU+PHNwYW4gbGFuZz0iRU4t
VVMiPi0tIHdlIHdpbGwgcmVzdW1lIHdpdGggdGhlIGV0aGVycGFkIGF0OjxvOnA+PC9vOnA+PC9z
cGFuPjwvcHJlPg0KPHByZT48c3BhbiBsYW5nPSJFTi1VUyI+Jm5ic3A7Jm5ic3A7IDxhIGhyZWY9
Imh0dHA6Ly9jcC5tY2FmZWUuY29tL2QvMkRSUG93NzFOSjV5V2FiQlFYSUNYQ1FuMVBhcEo1TXNP
LXJoczc2ekI1ZEFRc0NUN0RERDZiVGR5ZDlhUncyelZnX29ZS3JmQjNaek9WTHJGVG91cHZXX2M5
TEZMSWN0dVZ0ZEJaRERUUzdUTlA3Ym5qSXlDSHNzUE9FdXZremFUMFFTT3JvZFRWNXhkVllzeU1D
cWVqdFBvMGZWQV95Skc3akhrLURpLXJMMDBremhQdVpZbU81cF9nTGJWS0JUemhPbnNEYUJ5cHVE
U3J6YXBvU1ZlbGI0T1pmSVQ2a09Oc3hsSzVMRTJGdmRUdzA5SjU1VjZWSTUtQXE4M2lTVmVsYjRP
WmZJVDZrT05GdGQ0NkF2d3hGRXd0SDRRZzlUaG9iVHZiRnp6aDBWZWxiNFBoMWpYZE5CY0lxOGJx
dXVyc29kSmladnBtSzZHd1kiIHRhcmdldD0iX2JsYW5rIj48c3BhbiBzdHlsZT0iY29sb3I6cHVy
cGxlIj5odHRwOi8vZXRoZXJwYWQudG9vbHMuaWV0Zi5vcmc6OTAwMC9wL25vdGVzLWlldGYtODkt
NnRpc2NoLXNlY3VyaXR5PC9zcGFuPjwvYT48bzpwPjwvbzpwPjwvc3Bhbj48L3ByZT4NCjxwcmU+
PHNwYW4gbGFuZz0iRU4tVVMiPiZuYnNwOzxvOnA+PC9vOnA+PC9zcGFuPjwvcHJlPg0KPHByZT48
c3BhbiBsYW5nPSJFTi1VUyI+SSdtIGF0IDxhIGhyZWY9InRlbDolMkIxJTIwNjEzJTIwMjc2LTY4
MDkiIHRhcmdldD0iX2JsYW5rIj48c3BhbiBzdHlsZT0iY29sb3I6cHVycGxlIj4mIzQzOzEgNjEz
IDI3Ni02ODA5PC9zcGFuPjwvYT4sIElNOiA8YSBocmVmPSJtYWlsdG86bWNyQHhtcHAuY3JlZGls
Lm9yZyIgdGFyZ2V0PSJfYmxhbmsiPjxzcGFuIHN0eWxlPSJjb2xvcjpwdXJwbGUiPm1jckB4bXBw
LmNyZWRpbC5vcmc8L3NwYW4+PC9hPiBvciA8YSBocmVmPSJtYWlsdG86bWNoYXJsZXNyQGdtYWls
LmNvbSIgdGFyZ2V0PSJfYmxhbmsiPjxzcGFuIHN0eWxlPSJjb2xvcjpwdXJwbGUiPm1jaGFybGVz
ckBnbWFpbC5jb208L3NwYW4+PC9hPiw8bzpwPjwvbzpwPjwvc3Bhbj48L3ByZT4NCjxwcmU+PHNw
YW4gbGFuZz0iRU4tVVMiPmlmIHlvdSBuZWVkIG1vcmUgdGhhbiB0aGF0IHRvIGdldCBpbiwgb3Ig
YXJlIGhhdmluZyBkaWZmaWN1bHRpZXMuPG86cD48L286cD48L3NwYW4+PC9wcmU+DQo8cHJlPjxz
cGFuIGxhbmc9IkVOLVVTIj5QbGVhc2UgbWFrZSBzdXJlIHlvdXIgYXVkaW8gd29ya3MsIGFuZCB0
aGF0IHlvdSBtdXRlIHdoZW4gbm90IHRhbGtpbmcuPG86cD48L286cD48L3NwYW4+PC9wcmU+DQo8
cHJlPjxzcGFuIGxhbmc9IkVOLVVTIj4mbmJzcDs8bzpwPjwvbzpwPjwvc3Bhbj48L3ByZT4NCjxw
cmU+PHNwYW4gbGFuZz0iRU4tVVMiPi0tPG86cD48L286cD48L3NwYW4+PC9wcmU+DQo8cHJlPjxz
cGFuIGxhbmc9IkVOLVVTIj5NaWNoYWVsIFJpY2hhcmRzb24gPGEgaHJlZj0ibWFpbHRvOm1jciYj
NDM7SUVURkBzYW5kZWxtYW4uY2EiIHRhcmdldD0iX2JsYW5rIj48c3BhbiBzdHlsZT0iY29sb3I6
cHVycGxlIj4mbHQ7bWNyJiM0MztJRVRGQHNhbmRlbG1hbi5jYSZndDs8L3NwYW4+PC9hPiwgU2Fu
ZGVsbWFuIFNvZnR3YXJlIFdvcmtzPG86cD48L286cD48L3NwYW4+PC9wcmU+DQo8cHJlPjxzcGFu
IGxhbmc9IkVOLVVTIj4gLT0gSVB2NiBJb1QgY29uc3VsdGluZyA9LTxvOnA+PC9vOnA+PC9zcGFu
PjwvcHJlPg0KPHByZT48c3BhbiBsYW5nPSJFTi1VUyI+Jm5ic3A7PG86cD48L286cD48L3NwYW4+
PC9wcmU+DQo8cHJlPjxzcGFuIGxhbmc9IkVOLVVTIj4mbmJzcDs8bzpwPjwvbzpwPjwvc3Bhbj48
L3ByZT4NCjxwcmU+PHNwYW4gbGFuZz0iRU4tVVMiPiZuYnNwOzxvOnA+PC9vOnA+PC9zcGFuPjwv
cHJlPg0KPHAgY2xhc3M9Ik1zb05vcm1hbCIgc3R5bGU9Im1hcmdpbi1ib3R0b206MTIuMHB0Ij48
c3BhbiBsYW5nPSJFTi1VUyIgc3R5bGU9ImNvbG9yOiM4ODg4ODgiPiZuYnNwOzwvc3Bhbj48c3Bh
biBsYW5nPSJFTi1VUyI+PG86cD48L286cD48L3NwYW4+PC9wPg0KPHByZT48c3BhbiBsYW5nPSJF
Ti1VUyIgc3R5bGU9ImNvbG9yOiM4ODg4ODgiPl9fX19fX19fX19fX19fX19fX19fX19fX19fX19f
X19fX19fX19fX19fX19fX19fPC9zcGFuPjxzcGFuIGxhbmc9IkVOLVVTIj48bzpwPjwvbzpwPjwv
c3Bhbj48L3ByZT4NCjxwcmU+PHNwYW4gbGFuZz0iRU4tVVMiIHN0eWxlPSJjb2xvcjojODg4ODg4
Ij42dGlzY2gtc2VjdXJpdHkgbWFpbGluZyBsaXN0PC9zcGFuPjxzcGFuIGxhbmc9IkVOLVVTIj48
bzpwPjwvbzpwPjwvc3Bhbj48L3ByZT4NCjxwcmU+PHNwYW4gbGFuZz0iRU4tVVMiIHN0eWxlPSJj
b2xvcjojODg4ODg4Ij48YSBocmVmPSJtYWlsdG86NnRpc2NoLXNlY3VyaXR5QGlldGYub3JnIiB0
YXJnZXQ9Il9ibGFuayI+PHNwYW4gc3R5bGU9ImNvbG9yOnB1cnBsZSI+NnRpc2NoLXNlY3VyaXR5
QGlldGYub3JnPC9zcGFuPjwvYT48L3NwYW4+PHNwYW4gbGFuZz0iRU4tVVMiPjxvOnA+PC9vOnA+
PC9zcGFuPjwvcHJlPg0KPHByZT48c3BhbiBsYW5nPSJFTi1VUyIgc3R5bGU9ImNvbG9yOiM4ODg4
ODgiPjxhIGhyZWY9Imh0dHA6Ly9jcC5tY2FmZWUuY29tL2QvMkRSUG9PODZRbWJFRUtuaktPckty
aHM3Y0ZDUW4xUGJWSjVNc3Fla2tTamhPcnN1dXVzb0xzUzhRQUhtMGFmQjNaek9WSS1rZlNmYkNa
S0R0eFZCX0hZTUMtQy1NTlJYQlFTblN1dnZvdnY3Y3NKdGVPYXFKTlBmYXhWWmljSHMzanIxSndU
dkFtNFRETk9iMnBFVmRUZEFWUG1FQkM1ZUJZVHUwMFU5R1gzM1ZrRGEzSnNzRGFCeXB1RFNyemFw
b1NWZWxiNE9aZklUNmtPTnN4bEs1TEUyRnZkVHcwOUo1NVY2Vkk1LUFxODNpU1ZlbGI0T1pmSVQ2
a09ORnRkNDZBdnd4RkV3dEg0UWc5VGhvYlR2YkZ6emgwVmVsYjRQaDFqWGROQmNJcThicXV1cnNv
ZExXYnYiIHRhcmdldD0iX2JsYW5rIj48c3BhbiBzdHlsZT0iY29sb3I6cHVycGxlIj5odHRwczov
L3d3dy5pZXRmLm9yZy9tYWlsbWFuL2xpc3RpbmZvLzZ0aXNjaC1zZWN1cml0eTwvc3Bhbj48L2E+
PC9zcGFuPjxzcGFuIGxhbmc9IkVOLVVTIj48bzpwPjwvbzpwPjwvc3Bhbj48L3ByZT4NCjwvYmxv
Y2txdW90ZT4NCjxwIGNsYXNzPSJNc29Ob3JtYWwiIHN0eWxlPSJtYXJnaW4tYm90dG9tOjEyLjBw
dCI+PHNwYW4gbGFuZz0iRU4tVVMiIHN0eWxlPSJjb2xvcjojODg4ODg4Ij48YnI+DQo8YnI+DQo8
YnI+DQo8L3NwYW4+PHNwYW4gbGFuZz0iRU4tVVMiPjxvOnA+PC9vOnA+PC9zcGFuPjwvcD4NCjxw
cmU+PHNwYW4gbGFuZz0iRU4tVVMiIHN0eWxlPSJjb2xvcjojODg4ODg4Ij4tLSA8L3NwYW4+PHNw
YW4gbGFuZz0iRU4tVVMiPjxvOnA+PC9vOnA+PC9zcGFuPjwvcHJlPg0KPHByZT48c3BhbiBsYW5n
PSJFTi1VUyIgc3R5bGU9ImNvbG9yOiM4ODg4ODgiPmVtYWlsOiA8YSBocmVmPSJtYWlsdG86cnN0
cnVpay5leHRAZ21haWwuY29tIiB0YXJnZXQ9Il9ibGFuayI+PHNwYW4gc3R5bGU9ImNvbG9yOnB1
cnBsZSI+cnN0cnVpay5leHRAZ21haWwuY29tPC9zcGFuPjwvYT4gfCBTa3lwZTogcnN0cnVpazwv
c3Bhbj48c3BhbiBsYW5nPSJFTi1VUyI+PG86cD48L286cD48L3NwYW4+PC9wcmU+DQo8cHJlPjxz
cGFuIGxhbmc9IkVOLVVTIiBzdHlsZT0iY29sb3I6Izg4ODg4OCI+Y2VsbDogPGEgaHJlZj0idGVs
OiUyQjElMjAlMjg2NDclMjklMjA4NjctNTY1OCIgdGFyZ2V0PSJfYmxhbmsiPjxzcGFuIHN0eWxl
PSJjb2xvcjpwdXJwbGUiPiYjNDM7MSAoNjQ3KSA4NjctNTY1ODwvc3Bhbj48L2E+IHwgVVM6IDxh
IGhyZWY9InRlbDolMkIxJTIwJTI4NDE1JTI5JTIwNjkwLTczNjMiIHRhcmdldD0iX2JsYW5rIj48
c3BhbiBzdHlsZT0iY29sb3I6cHVycGxlIj4mIzQzOzEgKDQxNSkgNjkwLTczNjM8L3NwYW4+PC9h
Pjwvc3Bhbj48c3BhbiBsYW5nPSJFTi1VUyI+PG86cD48L286cD48L3NwYW4+PC9wcmU+DQo8L2Rp
dj4NCjxwIGNsYXNzPSJNc29Ob3JtYWwiIHN0eWxlPSJtYXJnaW4tYm90dG9tOjEyLjBwdCI+PHNw
YW4gbGFuZz0iRU4tVVMiPjxicj4NCl9fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19f
X19fX19fX19fX19fPGJyPg0KNnRpc2NoLXNlY3VyaXR5IG1haWxpbmcgbGlzdDxicj4NCjxhIGhy
ZWY9Im1haWx0bzo2dGlzY2gtc2VjdXJpdHlAaWV0Zi5vcmciIHRhcmdldD0iX2JsYW5rIj48c3Bh
biBzdHlsZT0iY29sb3I6cHVycGxlIj42dGlzY2gtc2VjdXJpdHlAaWV0Zi5vcmc8L3NwYW4+PC9h
Pjxicj4NCjxhIGhyZWY9Imh0dHA6Ly9jcC5tY2FmZWUuY29tL2QvYXZuZHpnUTkzZ0FyaG9LeXlW
dGVYOUtWSjVNc09DcmhzN2NMQ1FuMU5FVmhqcGQ3OUpOVlZWTnlaUG96aWlKbzBFLWtmU2ZiQ1BW
Z19vWUtyU1d0UzdDbi1MUDJyV3JYMzduS25qcHZwVlpaeFpZc05PUlFYOEZHVDdjWUc3RFI4T0pN
ZGRFQ1FqdC1ob2p1djc4STlDekFUc1NqRGRxeW1va1duUHRVMDN3Q0hJY2ZCaXNFZVJOT3NHbTlC
V3ZwS2NGQnpyQVZrSWpiUS1Qc3BqYjVPNW1VbS13YUJZVHUwMENRa25BckNNbldoRXdkYnJBVmtJ
amJRLVBzcGpiNkJRUWdxaC0yNkN5MVNJamgwRHQ1d0x0WUtDZWQ0M0FWa0lqZDQ1ZklUNmtPTkV3
SkZWVkpOd1NlVmhzckxlLUZrZCIgdGFyZ2V0PSJfYmxhbmsiPjxzcGFuIHN0eWxlPSJjb2xvcjpw
dXJwbGUiPmh0dHA6Ly9jcC5tY2FmZWUuY29tL2QvYXZuZHpnUTkzZ0FyaG9LeXlWdGVYOUtWSjVN
c09DcmhzN2NMQ1FuMU5FVmhqcGQ3OUpOVlZWTnlaUG96aWlKbzBFLWtmU2ZiQ1BWZ19vWUtyU1d0
UzdDbi1MUDJyV3JYMzduS25qcHZwVlpaeFpZc05PUlFYOEZHVDdjWUc3RFI4T0pNZGRFQ1FqdC1o
b2p1djc4STlDekFUc1NqRGRxeW1va1duUHRVMDN3Q0hJY2ZCaXNFZVJOT3NHbTlCV3ZwS2NGQnpy
QVZrSWpiUS1Qc3BqYjVPNW1VbS13YUJZVHUwMENRa25BckNNbldoRXdkYnJBVmtJamJRLVBzcGpi
NkJRUWdxaC0yNkN5MVNJamgwRHQ1d0x0WUtDZWQ0M0FWa0lqZDQ1ZklUNmtPTkV3SkZWVkpOd1Nl
VmhzckxlLUZrZDwvc3Bhbj48L2E+PG86cD48L286cD48L3NwYW4+PC9wPg0KPC9ibG9ja3F1b3Rl
Pg0KPC9kaXY+DQo8ZGl2Pg0KPHAgY2xhc3M9Ik1zb05vcm1hbCI+PHNwYW4gbGFuZz0iRU4tVVMi
Pjxicj4NCjxiciBjbGVhcj0iYWxsIj4NCjxicj4NCi0tPG86cD48L286cD48L3NwYW4+PC9wPg0K
PC9kaXY+DQo8ZGl2Pg0KPGRpdj4NCjxwIGNsYXNzPSJNc29Ob3JtYWwiPjxzcGFuIGxhbmc9IkVO
LVVTIiBzdHlsZT0iZm9udC1zaXplOjEzLjVwdDtmb250LWZhbWlseTomcXVvdDtUaW1lcyBOZXcg
Um9tYW4mcXVvdDssJnF1b3Q7c2VyaWYmcXVvdDsiPi0tJm5ic3A7PGJyPg0KSm9uYXRoYW4gU2lt
b24sIFBoLiBEPGJyPg0KRGlyZWN0b3Igb2YgU3lzdGVtcyBFbmdpbmVlcmluZzxicj4NCkR1c3Qg
TmV0d29ya3MgYXQgTGluZWFyIFRlY2hub2xvZ3k8YnI+DQozMDY5NSBIdW50d29vZCBBdmU8YnI+
DQpIYXl3YXJkLCBDQSA5NDU0NC03MDIxPGJyPg0KPGEgaHJlZj0idGVsOiUyODUxMCUyOSUyMDQw
MC0yOTM2IiB0YXJnZXQ9Il9ibGFuayI+PHNwYW4gc3R5bGU9ImNvbG9yOnB1cnBsZSI+KDUxMCkg
NDAwLTI5MzY8L3NwYW4+PC9hPjxicj4NCjxhIGhyZWY9InRlbDolMjg1MTAlMjklMjA0ODktMzc5
OSIgdGFyZ2V0PSJfYmxhbmsiPjxzcGFuIHN0eWxlPSJjb2xvcjpwdXJwbGUiPig1MTApIDQ4OS0z
Nzk5PC9zcGFuPjwvYT48c3BhbiBjbGFzcz0iYXBwbGUtY29udmVydGVkLXNwYWNlIj4mbmJzcDs8
L3NwYW4+RkFYPGJyPg0KPGEgaHJlZj0ibWFpbHRvOmpzaW1vbkBsaW5lYXIuY29tIiB0YXJnZXQ9
Il9ibGFuayI+PHNwYW4gc3R5bGU9ImNvbG9yOnB1cnBsZSI+anNpbW9uQGxpbmVhci5jb208L3Nw
YW4+PC9hPjwvc3Bhbj48c3BhbiBsYW5nPSJFTi1VUyI+PGJyPg0KPGJyPg0KPC9zcGFuPjxzcGFu
IGxhbmc9IkVOLVVTIiBzdHlsZT0iZm9udC1zaXplOjEzLjVwdDtmb250LWZhbWlseTomcXVvdDtU
aW1lcyBOZXcgUm9tYW4mcXVvdDssJnF1b3Q7c2VyaWYmcXVvdDsiPioqTElORUFSIFRFQ0hOT0xP
R1kmbmJzcDtDT1JQT1JBVElPTioqJm5ic3A7PGJyPg0KKioqKipJbnRlcm5ldCBFbWFpbCBDb25m
aWRlbnRpYWxpdHkmbmJzcDtOb3RpY2UqKioqKiZuYnNwOzxicj4NCiZuYnNwO1RoaXMgZS1tYWls
IHRyYW5zbWlzc2lvbiwgYW5kIGFueSZuYnNwO2RvY3VtZW50cywgZmlsZXMgb3IgcHJldmlvdXMg
ZS1tYWlsJm5ic3A7bWVzc2FnZXMgYXR0YWNoZWQgdG8gaXQgbWF5IGNvbnRhaW4mbmJzcDtjb25m
aWRlbnRpYWwgaW5mb3JtYXRpb24gdGhhdCBpcyZuYnNwO2xlZ2FsbHkgcHJpdmlsZWdlZC4gSWYg
eW91IGFyZSBub3QgdGhlJm5ic3A7aW50ZW5kZWQgcmVjaXBpZW50LCBvciBhIHBlcnNvbiZuYnNw
O3Jlc3BvbnNpYmxlIGZvciBkZWxpdmVyaW5nIGl0IHRvIHRoZSZuYnNwO2ludGVuZGVkDQogcmVj
aXBpZW50LCB5b3UgYXJlIGhlcmVieSZuYnNwO25vdGlmaWVkIHRoYXQgYW55IGRpc2Nsb3N1cmUs
IGNvcHlpbmcsJm5ic3A7ZGlzdHJpYnV0aW9uIG9yIHVzZSBvZiBhbnkgb2YgdGhlJm5ic3A7aW5m
b3JtYXRpb24gY29udGFpbmVkIGluIG9yIGF0dGFjaGVkJm5ic3A7dG8gdGhpcyB0cmFuc21pc3Np
b24gaXMgU1RSSUNUTFkmbmJzcDtQUk9ISUJJVEVELiBJZiB5b3UgaGF2ZSByZWNlaXZlZCB0aGlz
Jm5ic3A7dHJhbnNtaXNzaW9uIGluIGVycm9yLCBwbGVhc2UmbmJzcDtpbW1lZGlhdGVseSBub3Rp
ZnkNCiBtZSBieSByZXBseSBlLW1haWwsIG9yIGJ5IHRlbGVwaG9uZSBhdDxzcGFuIGNsYXNzPSJh
cHBsZS1jb252ZXJ0ZWQtc3BhY2UiPiZuYnNwOzwvc3Bhbj48YSBocmVmPSJ0ZWw6JTI4NTEwJTI5
JTIwNDAwLTI5MzYiIHRhcmdldD0iX2JsYW5rIj48c3BhbiBzdHlsZT0iY29sb3I6cHVycGxlIj4o
NTEwKSA0MDAtMjkzNjwvc3Bhbj48L2E+LCBhbmQgZGVzdHJveSB0aGUgb3JpZ2luYWwmbmJzcDt0
cmFuc21pc3Npb24gYW5kIGl0cyBhdHRhY2htZW50cyZuYnNwO3dpdGhvdXQgcmVhZGluZw0KIG9y
IHNhdmluZyBpbiBhbnkmbmJzcDttYW5uZXIuIFRoYW5rIHlvdS48L3NwYW4+PHNwYW4gbGFuZz0i
RU4tVVMiPjxvOnA+PC9vOnA+PC9zcGFuPjwvcD4NCjwvZGl2Pg0KPC9kaXY+DQo8L2Rpdj4NCjwv
ZGl2Pg0KPHAgY2xhc3M9Ik1zb05vcm1hbCIgc3R5bGU9Im1hcmdpbi1ib3R0b206MTIuMHB0Ij48
c3BhbiBsYW5nPSJFTi1VUyI+PGJyPg0KX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19f
X19fX19fX19fX19fX188YnI+DQo2dGlzY2gtc2VjdXJpdHkgbWFpbGluZyBsaXN0PGJyPg0KPGEg
aHJlZj0ibWFpbHRvOjZ0aXNjaC1zZWN1cml0eUBpZXRmLm9yZyI+PHNwYW4gc3R5bGU9ImNvbG9y
OnB1cnBsZSI+NnRpc2NoLXNlY3VyaXR5QGlldGYub3JnPC9zcGFuPjwvYT48YnI+DQo8YSBocmVm
PSJodHRwOi8vY3AubWNhZmVlLmNvbS9kLzJEUlBvdzc2UW1iRUZMenpoT00tcktyaHM3Y0ZDUW4x
UGJWSjVNc3Fla2tTamhPcnN1dXVzb0xzUzhRQUhtMGFmQjNaek9WSS1rZlNmYkNUQTdoUFhQYl9u
Vk5aTkJWeHpIVGJFekhJWVllcGQ3Yno4WEJIRVNoaGxLTV9PRXV2a3phVDBRU3lyaGRUVjV4ZFZZ
c3lNQ3FlanRQcGVzUkc5cHhqRnZkVHcwZTJxS01NLWw5T3dYbjc5T0ZvQ25GWkNVT0NtZEtqQmlO
Y0xqWGROQmNJbjhscnhyVzBHblB0VTAycm9qaEtVcjF2RjZ5MFFKS2pCaU5jTGpYZE5CY0lxbmpo
MUY3VThxcTg3cU5kNDJ0UW0yWlRPV29VUWdlakJpTmNRZ2stUHNwamI2eTJTRERDVDYzcnRfVTJT
VlVsVkIwIiB0YXJnZXQ9Il9ibGFuayI+PHNwYW4gc3R5bGU9ImNvbG9yOnB1cnBsZSI+aHR0cDov
L2NwLm1jYWZlZS5jb20vZC8yRFJQb3c3NlFtYkVGTHp6aE9NLXJLcmhzN2NGQ1FuMVBiVko1TXNx
ZWtrU2poT3JzdXV1c29Mc1M4UUFIbTBhZkIzWnpPVkkta2ZTZmJDVEE3aFBYUGJfblZOWk5CVnh6
SFRiRXpISVlZZXBkN2J6OFhCSEVTaGhsS01fT0V1dmt6YVQwUVN5cmhkVFY1eGRWWXN5TUNxZWp0
UHBlc1JHOXB4akZ2ZFR3MGUycUtNTS1sOU93WG43OU9Gb0NuRlpDVU9DbWRLakJpTmNMalhkTkJj
SW44bHJ4clcwR25QdFUwMnJvamhLVXIxdkY2eTBRSktqQmlOY0xqWGROQmNJcW5qaDFGN1U4cXE4
N3FOZDQydFFtMlpUT1dvVVFnZWpCaU5jUWdrLVBzcGpiNnkyU0REQ1Q2M3J0X1UyU1ZVbFZCMDwv
c3Bhbj48L2E+PG86cD48L286cD48L3NwYW4+PC9wPg0KPC9ibG9ja3F1b3RlPg0KPC9kaXY+DQo8
ZGl2Pg0KPHAgY2xhc3M9Ik1zb05vcm1hbCI+PHNwYW4gbGFuZz0iRU4tVVMiPjxicj4NCjxiciBj
bGVhcj0iYWxsIj4NCjxicj4NCi0tPG86cD48L286cD48L3NwYW4+PC9wPg0KPC9kaXY+DQo8ZGl2
Pg0KPGRpdj4NCjxwIGNsYXNzPSJNc29Ob3JtYWwiPjxzcGFuIGxhbmc9IkVOLVVTIiBzdHlsZT0i
Zm9udC1zaXplOjEzLjVwdDtmb250LWZhbWlseTomcXVvdDtUaW1lcyBOZXcgUm9tYW4mcXVvdDss
JnF1b3Q7c2VyaWYmcXVvdDsiPi0tJm5ic3A7PGJyPg0KSm9uYXRoYW4gU2ltb24sIFBoLiBEPGJy
Pg0KRGlyZWN0b3Igb2YgU3lzdGVtcyBFbmdpbmVlcmluZzxicj4NCkR1c3QgTmV0d29ya3MgYXQg
TGluZWFyIFRlY2hub2xvZ3k8YnI+DQozMDY5NSBIdW50d29vZCBBdmU8YnI+DQpIYXl3YXJkLCBD
QSA5NDU0NC03MDIxPGJyPg0KKDUxMCkgNDAwLTI5MzY8YnI+DQooNTEwKSA0ODktMzc5OSBGQVg8
YnI+DQo8YSBocmVmPSJtYWlsdG86anNpbW9uQGxpbmVhci5jb20iIHRhcmdldD0iX2JsYW5rIj48
c3BhbiBzdHlsZT0iY29sb3I6cHVycGxlIj5qc2ltb25AbGluZWFyLmNvbTwvc3Bhbj48L2E+PC9z
cGFuPjxzcGFuIGxhbmc9IkVOLVVTIj48YnI+DQo8YnI+DQo8L3NwYW4+PHNwYW4gbGFuZz0iRU4t
VVMiIHN0eWxlPSJmb250LXNpemU6MTMuNXB0O2ZvbnQtZmFtaWx5OiZxdW90O1RpbWVzIE5ldyBS
b21hbiZxdW90OywmcXVvdDtzZXJpZiZxdW90OyI+KipMSU5FQVIgVEVDSE5PTE9HWSZuYnNwO0NP
UlBPUkFUSU9OKiombmJzcDs8YnI+DQoqKioqKkludGVybmV0IEVtYWlsIENvbmZpZGVudGlhbGl0
eSZuYnNwO05vdGljZSoqKioqJm5ic3A7PGJyPg0KJm5ic3A7VGhpcyBlLW1haWwgdHJhbnNtaXNz
aW9uLCBhbmQgYW55Jm5ic3A7ZG9jdW1lbnRzLCBmaWxlcyBvciBwcmV2aW91cyBlLW1haWwmbmJz
cDttZXNzYWdlcyBhdHRhY2hlZCB0byBpdCBtYXkgY29udGFpbiZuYnNwO2NvbmZpZGVudGlhbCBp
bmZvcm1hdGlvbiB0aGF0IGlzJm5ic3A7bGVnYWxseSBwcml2aWxlZ2VkLiBJZiB5b3UgYXJlIG5v
dCB0aGUmbmJzcDtpbnRlbmRlZCByZWNpcGllbnQsIG9yIGEgcGVyc29uJm5ic3A7cmVzcG9uc2li
bGUgZm9yIGRlbGl2ZXJpbmcgaXQgdG8gdGhlJm5ic3A7aW50ZW5kZWQNCiByZWNpcGllbnQsIHlv
dSBhcmUgaGVyZWJ5Jm5ic3A7bm90aWZpZWQgdGhhdCBhbnkgZGlzY2xvc3VyZSwgY29weWluZywm
bmJzcDtkaXN0cmlidXRpb24gb3IgdXNlIG9mIGFueSBvZiB0aGUmbmJzcDtpbmZvcm1hdGlvbiBj
b250YWluZWQgaW4gb3IgYXR0YWNoZWQmbmJzcDt0byB0aGlzIHRyYW5zbWlzc2lvbiBpcyBTVFJJ
Q1RMWSZuYnNwO1BST0hJQklURUQuIElmIHlvdSBoYXZlIHJlY2VpdmVkIHRoaXMmbmJzcDt0cmFu
c21pc3Npb24gaW4gZXJyb3IsIHBsZWFzZSZuYnNwO2ltbWVkaWF0ZWx5IG5vdGlmeQ0KIG1lIGJ5
IHJlcGx5IGUtbWFpbCwgb3IgYnkgdGVsZXBob25lIGF0ICg1MTApIDQwMC0yOTM2LCBhbmQgZGVz
dHJveSB0aGUgb3JpZ2luYWwmbmJzcDt0cmFuc21pc3Npb24gYW5kIGl0cyBhdHRhY2htZW50cyZu
YnNwO3dpdGhvdXQgcmVhZGluZyBvciBzYXZpbmcgaW4gYW55Jm5ic3A7bWFubmVyLiBUaGFuayB5
b3UuPC9zcGFuPjxzcGFuIGxhbmc9IkVOLVVTIj48bzpwPjwvbzpwPjwvc3Bhbj48L3A+DQo8L2Rp
dj4NCjwvZGl2Pg0KPC9kaXY+DQo8cCBjbGFzcz0iTXNvTm9ybWFsIj48c3BhbiBsYW5nPSJFTi1V
UyIgc3R5bGU9ImZvbnQtc2l6ZToxMC41cHQ7Zm9udC1mYW1pbHk6JnF1b3Q7THVjaWRhR3JhbmRl
JnF1b3Q7LCZxdW90O3NlcmlmJnF1b3Q7Ij5fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19f
X19fX19fX19fX19fX19fXzxicj4NCjZ0aXNjaC1zZWN1cml0eSBtYWlsaW5nIGxpc3Q8YnI+DQo8
YSBocmVmPSJtYWlsdG86NnRpc2NoLXNlY3VyaXR5QGlldGYub3JnIj48c3BhbiBzdHlsZT0iY29s
b3I6cHVycGxlIj42dGlzY2gtc2VjdXJpdHlAaWV0Zi5vcmc8L3NwYW4+PC9hPjxicj4NCjxhIGhy
ZWY9Imh0dHA6Ly9jcC5tY2FmZWUuY29tL2QvMWpXVkllM3pxYjVRa1R6aE9NQy1yS3JoczdjRkNR
bjFQYlZKNU1zcWVra1NqaE9yc3V1dXNvTHNTOFFBSG0wYWZCM1p6T1ZJLWtmU2ZiQ081SnR2dXB2
V184Q3pCZEJCZkhUYkVDekJkekFUQzd4TkVWVnFXdEFrbHJDekI3QmdZLUY2bEsxRko0U3lyTE9i
MnJQVVY1eGNRc0NYQ09zVkhraVAyRGktckwwMHM0UnR4eFlHakIxU0tlakJpTmNMalhkTkJjSXJz
RGFCeXB1RFNyemFwb0tnR1QyVFExa0xDWE0wNFMtcWVtN1Qzb2JaOFFnNkJKT3NHbTlCV3ZwS2NG
QnppV3E4ZDhfMTNqaDBYbTlFd2pLeU1uSy1uajc2eTFPc0dtOUN5MkRTcnphcG9RZ21RWVlTVU1y
RHJrcjJwQWFUYW0iPjxzcGFuIHN0eWxlPSJjb2xvcjpwdXJwbGUiPmh0dHA6Ly9jcC5tY2FmZWUu
Y29tL2QvMWpXVkllM3pxYjVRa1R6aE9NQy1yS3JoczdjRkNRbjFQYlZKNU1zcWVra1NqaE9yc3V1
dXNvTHNTOFFBSG0wYWZCM1p6T1ZJLWtmU2ZiQ081SnR2dXB2V184Q3pCZEJCZkhUYkVDekJkekFU
Qzd4TkVWVnFXdEFrbHJDekI3QmdZLUY2bEsxRko0U3lyTE9iMnJQVVY1eGNRc0NYQ09zVkhraVAy
RGktckwwMHM0UnR4eFlHakIxU0tlakJpTmNMalhkTkJjSXJzRGFCeXB1RFNyemFwb0tnR1QyVFEx
a0xDWE0wNFMtcWVtN1Qzb2JaOFFnNkJKT3NHbTlCV3ZwS2NGQnppV3E4ZDhfMTNqaDBYbTlFd2pL
eU1uSy1uajc2eTFPc0dtOUN5MkRTcnphcG9RZ21RWVlTVU1yRHJrcjJwQWFUYW08L3NwYW4+PC9h
PjxvOnA+PC9vOnA+PC9zcGFuPjwvcD4NCjwvZGl2Pg0KPC9ibG9ja3F1b3RlPg0KPC9kaXY+DQo8
cCBjbGFzcz0iTXNvTm9ybWFsIj48c3BhbiBsYW5nPSJFTi1VUyI+PG86cD4mbmJzcDs8L286cD48
L3NwYW4+PC9wPg0KPC9kaXY+DQo8L2Rpdj4NCjwvYm9keT4NCjwvaHRtbD4NCg==

--_000_674F70E5F2BE564CB06B6901FD3DD78B2723BA32TGXML210toshiba_--


From nobody Wed May 28 16:40:00 2014
Return-Path: <jsimon@linear.com>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 2459C1A0784 for <6tisch-security@ietfa.amsl.com>; Wed, 28 May 2014 16:39:55 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.209
X-Spam-Level: 
X-Spam-Status: No, score=-2.209 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HTML_MESSAGE=0.001, HTTPS_HTTP_MISMATCH=1.989, RCVD_IN_DNSWL_MED=-2.3, WEIRD_PORT=0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id A8XEVWoO5X-d for <6tisch-security@ietfa.amsl.com>; Wed, 28 May 2014 16:39:49 -0700 (PDT)
Received: from p02c12o148.mxlogic.net (p02c12o148.mxlogic.net [208.65.145.81]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 19B6F1A0760 for <6tisch-security@ietf.org>; Wed, 28 May 2014 16:39:49 -0700 (PDT)
Received: from unknown [12.218.215.72] (EHLO smtpauth1.linear.com) by p02c12o148.mxlogic.net(mxl_mta-8.0.0-1) with ESMTP id 1c376835.2ba577204940.2040.00-556.4758.p02c12o148.mxlogic.net (envelope-from <jsimon@linear.com>);  Wed, 28 May 2014 17:39:45 -0600 (MDT)
X-MXL-Hash: 538673c10bf55964-ff9021b33baccfc5996d9e87d59584afcbf8d428
Received: from unknown [12.218.215.72] (EHLO smtpauth1.linear.com) by p02c12o148.mxlogic.net(mxl_mta-8.0.0-1) with ESMTP id cb376835.0.2003.00-370.4667.p02c12o148.mxlogic.net (envelope-from <jsimon@linear.com>);  Wed, 28 May 2014 17:39:42 -0600 (MDT)
X-MXL-Hash: 538673be2a21572f-3e593d7e21e373605b1cd50e18d29fe558f6e507
Received: from jsimonmacmini.engineering.linear.com (unknown [10.70.48.25]) by smtpauth1.linear.com (Postfix) with ESMTPSA id 9517D74095; Wed, 28 May 2014 16:39:39 -0700 (PDT)
Content-Type: multipart/alternative; boundary="Apple-Mail=_EF40B035-D9C0-4787-BBD2-A45B5D246C54"
Mime-Version: 1.0 (Mac OS X Mail 7.3 \(1878.2\))
From: Jonathan Simon <jsimon@linear.com>
In-Reply-To: <674F70E5F2BE564CB06B6901FD3DD78B2723BA32@TGXML210.toshiba.local>
Date: Wed, 28 May 2014 16:41:49 -0700
Message-Id: <B9D502BD-C500-41E0-BA31-5BCD72090432@linear.com>
References: <E045AECD98228444A58C61C200AE1BD8416F3AF4@xmb-rcd-x01.cisco.com> <531DD632.2060009@cox.net> <531DDB20.5050600@gmail.com> <10925.1394631496@sandelman.ca> <532069C8.2050005@gmail.com> <23590.1394999032@sandelman.ca> <18106.1395625035@sandelman.ca> <19609.1396839403@sandelman.ca> <11557.1397444260@sandelman.ca> <28192.1398644294@sandelman.ca> <29064.1399255587@sandelman.ca> <19475.1400588783@sandelman.ca> <4903.1401158997@sandelman.ca> <53840205.2070103@gmail.com> <CAJeFcoS3PNFX2obx3uNDJDtH=QvNLmaPhw2R468sNaeqpo8QBQ@mail.gmail.com> <674F70E5F2BE564CB06B6901FD3DD78B2723B576@TGXML210.toshiba.local> <CAJeFcoQBp1A7pwZHWoesvrjSySW0UZ0k11-s3-MFAozSuR0Yrw@mail.gmail.com> <674F70E5F2BE564CB06B6901FD3DD78B2723B85A@TGXML210.toshiba.local> <1315B075-A0A5-4008-8CC9-4918F54CBED1@linear.com> <674F70E5F2BE564CB06B6901FD3DD78B2723BA32@TGXML210.toshiba.local>
To: yoshihiro.ohba@toshiba.co.jp
X-Mailer: Apple Mail (2.1878.2)
X-AnalysisOut: [v=2.1 cv=NqBfcqtJ c=1 sm=1 tr=0 a=glloKNylpeYNumXQcclYyA==]
X-AnalysisOut: [:117 a=glloKNylpeYNumXQcclYyA==:17 a=9iaqTFGLkfwA:10 a=D2_]
X-AnalysisOut: [GN2MmYMYA:10 a=BLceEmwcHowA:10 a=MqDINYqSAAAA:8 a=YlVTAMxI]
X-AnalysisOut: [AAAA:8 a=48vgC7mUAAAA:8 a=pGLkceISAAAA:8 a=NojvYFcnAAAA:8 ]
X-AnalysisOut: [a=rWPlndbxAAAA:8 a=SyYMxH9GAAAA:8 a=yKFlVHVKu-lx3rYSWk8A:9]
X-AnalysisOut: [ a=MQ1Z5_TIDG99Em0k:21 a=OKahDVbgqDMVj8KY:21 a=QEXdDO2ut3Y]
X-AnalysisOut: [A:10 a=19wCD08tTksA:10 a=vsVyj9psLt0A:10 a=wUAfXdCGL-oA:10]
X-AnalysisOut: [ a=G1HyQLfxkfkA:10 a=qVizmW-ZYBIA:10 a=p-HxVa_ds0YA:10 a=x]
X-AnalysisOut: [EeETXzOXN8A:10 a=yRLhjdVT-pYA:10 a=uztyEWA5df8A:10 a=AeFSe]
X-AnalysisOut: [x2-gKoA:10 a=QxAq9r8ObNgA:10 a=ULth79YsAAUA:10 a=xLpt9-x9c]
X-AnalysisOut: [SEA:10 a=lZB815dzVvQA:10 a=MSl-tDqOz04A:10 a=mVM6EhRi2tsA:]
X-AnalysisOut: [10 a=gx5ZDJWUnqwswCL2CSkA:9 a=kbLzOP0U9Gsuy2AP:21 a=ucQrNB]
X-AnalysisOut: [3lWCZj5hhH:21 a=Ak0qLDyO0UNPs6Mh:21 a=_W_S_7VecoQA:10 a=tX]
X-AnalysisOut: [snliwV7b4A:10]
X-Spam: [F=0.5000000000; CM=0.500; MH=0.500(2014052831); S=0.200(2014051901)]
X-MAIL-FROM: <jsimon@linear.com>
X-SOURCE-IP: [12.218.215.72]
Archived-At: http://mailarchive.ietf.org/arch/msg/6tisch-security/W2VfYwF2Rr70-zK18qVyRn478Po
Cc: mcr+ietf@sandelman.ca, rstruik.ext@gmail.com, 6tisch-security@ietf.org
Subject: Re: [6tisch-security] agenda for 2014-05-27 6tisch security call
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 28 May 2014 23:39:55 -0000

--Apple-Mail=_EF40B035-D9C0-4787-BBD2-A45B5D246C54
Content-Transfer-Encoding: quoted-printable
Content-Type: text/plain;
	charset=utf-8

Then as long as either
a) Beacons are only used for advertising a network to unsychronized =
devices, or
b) Devices only take timing information (time of arrival) from beacons =
coming from time parents and authenticated with the run-time key
you are good.=20

=20
--=20
Jonathan Simon, Ph. D
Director of Systems Engineering
Linear Technology, Dust Networks product group
30695 Huntwood Ave
Hayward, CA 94544-7021
(510) 400-2936
(510) 489-3799 FAX
jsimon@linear.com

**LINEAR TECHNOLOGY CORPORATION**=20
*****Internet Email Confidentiality Notice*****=20
 This e-mail transmission, and any documents, files or previous e-mail =
messages attached to it may contain confidential information that is =
legally privileged. If you are not the intended recipient, or a person =
responsible for delivering it to the intended recipient, you are hereby =
notified that any disclosure, copying, distribution or use of any of the =
information contained in or attached to this transmission is STRICTLY =
PROHIBITED. If you have received this transmission in error, please =
immediately notify me by reply e-mail, or by telephone at (510) =
400-2936, and destroy the original transmission and its attachments =
without reading or saving in any manner. Thank you.=20

On May 28, 2014, at 4:19 PM, <yoshihiro.ohba@toshiba.co.jp> =
<yoshihiro.ohba@toshiba.co.jp> wrote:

> Hi Jonathan,
> =20
> I am not caring about an attacker to inject joining traffic, but what =
I care is an attacker attempting to destruct basic TSCH operation in the =
network by sending forged beacons protected with the well-known key.
> =20
> Yoshihiro Ohba
> =20
> =20
> =20
> From: 6tisch-security [mailto:6tisch-security-bounces@ietf.org] On =
Behalf Of Jonathan Simon
> Sent: Thursday, May 29, 2014 12:47 AM
> To: ohba yoshihiro(=E5=A4=A7=E5=A0=B4 =E7=BE=A9=E6=B4=8B =
=E2=97=8B=EF=BC=B2=EF=BC=A4=EF=BC=A3=E2=96=A1=EF=BC=AE=EF=BC=B3=EF=BC=AC)
> Cc: mcr+ietf@sandelman.ca; rstruik.ext@gmail.com; =
6tisch-security@ietf.org
> Subject: Re: [6tisch-security] agenda for 2014-05-27 6tisch security =
call
> =20
> Yoshihiro -
> =20
> I don=E2=80=99t think this is a problem.  Nodes that are in the =
network reject incoming frames secured with the well-known key. The =
well-known key is only used to authenticate beacons, and authenticate =
join requests (which don=E2=80=99t carry synchronization information).  =
There is a DoS vector, in that an attacker can inject joining traffic =
(destined for the network mananager) that will ultimately be discarded, =
possibly preventing other nodes from joining, and increasing the traffic =
in the network.=20
> =20
> Jonathan Simon, Ph. D
> Director of Systems Engineering
> Linear Technology, Dust Networks product group
> 30695 Huntwood Ave
> Hayward, CA 94544-7021
> (510) 400-2936
> (510) 489-3799 FAX
> jsimon@linear.com
>=20
> **LINEAR TECHNOLOGY CORPORATION**=20
> *****Internet Email Confidentiality Notice*****=20
>  This e-mail transmission, and any documents, files or previous e-mail =
messages attached to it may contain confidential information that is =
legally privileged. If you are not the intended recipient, or a person =
responsible for delivering it to the intended recipient, you are hereby =
notified that any disclosure, copying, distribution or use of any of the =
information contained in or attached to this transmission is STRICTLY =
PROHIBITED. If you have received this transmission in error, please =
immediately notify me by reply e-mail, or by telephone at (510) =
400-2936, and destroy the original transmission and its attachments =
without reading or saving in any manner. Thank you.=20
> =20
> On May 28, 2014, at 8:01 AM, <yoshihiro.ohba@toshiba.co.jp> =
<yoshihiro.ohba@toshiba.co.jp> wrote:
>=20
>=20
> Hi Jonathan,
> =20
> Thank you for your answer.
> =20
> I think this can be an issue if already joined nodes also use the =
beacons protected with the well-known key for maintaining =
synchronization and slot allocations, as an attacker can send forged =
beacons protected with the well-known key.
> =20
> Yoshihiro Ohba
> =20
> =20
> From: 6tisch-security [mailto:6tisch-security-bounces@ietf.org] On =
Behalf Of Jonathan Simon
> Sent: Wednesday, May 28, 2014 11:49 PM
> To: ohba yoshihiro(=E5=A4=A7=E5=A0=B4 =E7=BE=A9=E6=B4=8B =
=E2=97=8B=EF=BC=B2=EF=BC=A4=EF=BC=A3=E2=96=A1=EF=BC=AE=EF=BC=B3=EF=BC=AC)
> Cc: Michael Richardson; Rene Struik; 6tisch-security@ietf.org
> Subject: Re: [6tisch-security] agenda for 2014-05-27 6tisch security =
call
> =20
> Yoshihiro -=20
>=20
> Q. In w/HART, are all beacon frames authenticated with a well-known =
key even after a joining node obtained the runtime link layer key?
>=20
> A. Yes. In WirelessHART the beacons (called "advertisements" but they =
serve the same purpose and have similar content) are intended for =
devices not yet in the network, so they always use the well-known key.  =
To discover other nodes within the network, they use frames secured with =
the runtime link-layer key.
>=20
> Jonathan
> =20
>=20
> On Tue, May 27, 2014 at 11:18 PM, <yoshihiro.ohba@toshiba.co.jp> =
wrote:
> Hi Jonathan,
> =20
> Thank you for sending the summary of w/HART joining.
> =20
> I have question.
> =20
> In w/HART, are all beacon frames authenticated with a well-known key =
even after a joining node obtained the runtime link layer key?=20
> =20
> Regards,
> Yoshihiro Ohba
> =20
> =20
> =20
> =20
> From: 6tisch-security [mailto:6tisch-security-bounces@ietf.org] On =
Behalf Of Jonathan Simon
> Sent: Tuesday, May 27, 2014 10:41 PM
> To: Rene Struik
> Cc: Michael Richardson; 6tisch-security@ietf.org
> Subject: Re: [6tisch-security] agenda for 2014-05-27 6tisch security =
call
> =20
> Rene had asked on a previous call for someone to summarize =
WirelessHART joining - here you go.
>=20
> * One or more devices are sending beacons to advertise the presence of =
the network. In WirelessHART, this frame is unencrypted, but =
authenticated with a well known key.  The beacon contains the current =
ASN, which the joining device uses to synchronize its clock.
>=20
> * Once the joining node has heard a beacon, it continues listening for =
additional beacons for a short specified timeout.
>=20
> * The joining node encrypts a frame containing some HART specific =
content, including a list of beaconing neighbors it heard in the =
previous steps. The size of the payload is ~ 60 bytes.  The packet is =
routed by a "proxy" node - the joining parent. The frame is =
authenticated using the well-known key, and encrypted using a shared =
symmetric key known only by the node and the manager.
>=20
> * The manager responds with a frame containing the run-time link-layer =
key, the node's new short address (this takes the place of PAN =
coordinator association), and a unicast session key and starting nonce =
for the manager. This frame is encrypted with the symmetric key. The =
payload is ~ 60 bytes, and is routed to the proxy for delivery to the =
joining node - the proxy uses the link-layer well known key on the =
frame.
>=20
> * At this point the joining node transitions to using the run-time =
link-layer key for all link-layer frames, and the manager unicast =
session for end-to-end manager traffic. This ends the initial security =
handshake.
>=20
> * Over a number of additional frames, the manager assigns additional =
sessions, including broadcast sessions, and a unicast session to the =
Gateway (sink for all data traffic), and additional communications =
resources, routing information, etc.  There is no explicit transition =
from joining to joined - the mote transitions when certain key frames =
are received.
>=20
> * Note that a WirelessHART link-layer frame contains and additional =
frame type byte and a 4-byte link-layer MIC, on top of the unsecured =
15.4 frame.  A network frame contains an additional 16-40 bytes of =
addressing, routing, security and other information.
>=20
> Hope this help!
>=20
> Jonathan
> =20
> =20
>=20
> On Mon, May 26, 2014 at 8:09 PM, Rene Struik <rstruik.ext@gmail.com> =
wrote:
> Hi Michael:
>=20
> I would like to discuss the outstanding issues I summarized in my =
email of Tue last week, May 20, 2014, 9:45am EDT (see =
http://www.ietf.org/mail-archive/web/6tisch-security/current/msg00086.html=
). This was also one of the action items at the conclusion of last =
week's 6TiSCH security call.
>=20
> FYI - the w/HART communication flows were discussed during the 6TiSCH =
security conf call the week before, on Mon May 12, 2014. If one wishes =
to go over this again, that is fine, but I would prefer us giving =
preference to taking on already articulated issues (which were assigned =
as homework assignment to reflect upon) first (i.e., prior to item #4 of =
the proposed agenda).
>=20
> As another agenda point, I would like us to discuss the frequency of =
future calls (as part of EOB).
>=20
> Best regards, Rene
>=20
>=20
> On 5/26/2014 10:49 PM, Michael Richardson wrote:
> To remind, we moved the call from the 26th to the 27th at 10am EDT.
> That's 90 minutes from this email.
> =20
> 1) notewell.
> 2) intros
> 3) recap of draft-piro-
> 4) wirelesshart -way --- how does the communication work?
> 5) how to summarize all of this to the working group
> 6) how to close this process up?
> =20
> -- remember that the call is recorded, and the NoteWell applies.
> =20
> -- The URL to access the webex, which will we use for audio only:
>   =
https://cisco.webex.com/cisco/j.php?MTID=3Dm2fe139bf876cea3ec62750cd580b79=
08
> =20
> -- we will resume with the etherpad at:
>    http://etherpad.tools.ietf.org:9000/p/notes-ietf-89-6tisch-security
> =20
> I'm at +1 613 276-6809, IM: mcr@xmpp.credil.org or =
mcharlesr@gmail.com,
> if you need more than that to get in, or are having difficulties.
> Please make sure your audio works, and that you mute when not talking.
> =20
> --
> Michael Richardson <mcr+IETF@sandelman.ca>, Sandelman Software Works
>  -=3D IPv6 IoT consulting =3D-
> =20
> =20
> =20
> =20
>=20
> _______________________________________________
> 6tisch-security mailing list
> 6tisch-security@ietf.org
> https://www.ietf.org/mailman/listinfo/6tisch-security
>=20
>=20
>=20
>=20
> --=20
> email: rstruik.ext@gmail.com | Skype: rstruik
> cell: +1 (647) 867-5658 | US: +1 (415) 690-7363
>=20
> _______________________________________________
> 6tisch-security mailing list
> 6tisch-security@ietf.org
> =
http://cp.mcafee.com/d/avndzgQ93gArhoKyyVteX9KVJ5MsOCrhs7cLCQn1NEVhjpd79JN=
VVVNyZPoziiJo0E-kfSfbCPVg_oYKrSWtS7Cn-LP2rWrX37nKnjpvpVZZxZYsNORQX8FGT7cYG=
7DR8OJMddECQjt-hojuv78I9CzATsSjDdqymokWnPtU03wCHIcfBisEeRNOsGm9BWvpKcFBzrA=
VkIjbQ-Pspjb5O5mUm-waBYTu00CQknArCMnWhEwdbrAVkIjbQ-Pspjb6BQQgqh-26Cy1SIjh0=
Dt5wLtYKCed43AVkIjd45fIT6kONEwJFVVJNwSeVhsrLe-Fkd
>=20
>=20
>=20
>=20
> --
> --=20
> Jonathan Simon, Ph. D
> Director of Systems Engineering
> Dust Networks at Linear Technology
> 30695 Huntwood Ave
> Hayward, CA 94544-7021
> (510) 400-2936
> (510) 489-3799 FAX
> jsimon@linear.com
>=20
> **LINEAR TECHNOLOGY CORPORATION**=20
> *****Internet Email Confidentiality Notice*****=20
>  This e-mail transmission, and any documents, files or previous e-mail =
messages attached to it may contain confidential information that is =
legally privileged. If you are not the intended recipient, or a person =
responsible for delivering it to the intended recipient, you are hereby =
notified that any disclosure, copying, distribution or use of any of the =
information contained in or attached to this transmission is STRICTLY =
PROHIBITED. If you have received this transmission in error, please =
immediately notify me by reply e-mail, or by telephone at (510) =
400-2936, and destroy the original transmission and its attachments =
without reading or saving in any manner. Thank you.
>=20
> _______________________________________________
> 6tisch-security mailing list
> 6tisch-security@ietf.org
> =
http://cp.mcafee.com/d/2DRPow76QmbEFLzzhOM-rKrhs7cFCQn1PbVJ5MsqekkSjhOrsuu=
usoLsS8QAHm0afB3ZzOVI-kfSfbCTA7hPXPb_nVNZNBVxzHTbEzHIYYepd7bz8XBHEShhlKM_O=
EuvkzaT0QSyrhdTV5xdVYsyMCqejtPpesRG9pxjFvdTw0e2qKMM-l9OwXn79OFoCnFZCUOCmdK=
jBiNcLjXdNBcIn8lrxrW0GnPtU02rojhKUr1vF6y0QJKjBiNcLjXdNBcIqnjh1F7U8qq87qNd4=
2tQm2ZTOWoUQgejBiNcQgk-Pspjb6y2SDDCT63rt_U2SVUlVB0
>=20
>=20
>=20
>=20
> --
> --=20
> Jonathan Simon, Ph. D
> Director of Systems Engineering
> Dust Networks at Linear Technology
> 30695 Huntwood Ave
> Hayward, CA 94544-7021
> (510) 400-2936
> (510) 489-3799 FAX
> jsimon@linear.com
>=20
> **LINEAR TECHNOLOGY CORPORATION**=20
> *****Internet Email Confidentiality Notice*****=20
>  This e-mail transmission, and any documents, files or previous e-mail =
messages attached to it may contain confidential information that is =
legally privileged. If you are not the intended recipient, or a person =
responsible for delivering it to the intended recipient, you are hereby =
notified that any disclosure, copying, distribution or use of any of the =
information contained in or attached to this transmission is STRICTLY =
PROHIBITED. If you have received this transmission in error, please =
immediately notify me by reply e-mail, or by telephone at (510) =
400-2936, and destroy the original transmission and its attachments =
without reading or saving in any manner. Thank you.
> _______________________________________________
> 6tisch-security mailing list
> 6tisch-security@ietf.org
> =
http://cp.mcafee.com/d/1jWVIe3zqb5QkTzhOMC-rKrhs7cFCQn1PbVJ5MsqekkSjhOrsuu=
usoLsS8QAHm0afB3ZzOVI-kfSfbCO5JtvupvW_8CzBdBBfHTbECzBdzATC7xNEVVqWtAklrCzB=
7BgY-F6lK1FJ4SyrLOb2rPUV5xcQsCXCOsVHkiP2Di-rL00s4RtxxYGjB1SKejBiNcLjXdNBcI=
rsDaBypuDSrzapoKgGT2TQ1kLCXM04S-qem7T3obZ8Qg6BJOsGm9BWvpKcFBziWq8d8_13jh0X=
m9EwjKyMnK-nj76y1OsGm9Cy2DSrzapoQgmQYYSUMrDrkr2pAaTam


--Apple-Mail=_EF40B035-D9C0-4787-BBD2-A45B5D246C54
Content-Transfer-Encoding: quoted-printable
Content-Type: text/html;
	charset=utf-8

<html><head><meta http-equiv=3D"Content-Type" content=3D"text/html =
charset=3Dutf-8"></head><body style=3D"word-wrap: break-word; =
-webkit-nbsp-mode: space; -webkit-line-break: after-white-space;">Then =
as long as either<div>a) Beacons are only used for advertising a network =
to unsychronized devices, or</div><div>b) Devices only take timing =
information (time of arrival) from beacons coming from time parents and =
authenticated with the run-time key</div><div>you are =
good.&nbsp;</div><div><br></div><div>&nbsp;</div><div><div =
apple-content-edited=3D"true">
<span class=3D"Apple-style-span" style=3D"border-collapse: separate; =
border-spacing: 0px;"><span class=3D"Apple-style-span" =
style=3D"border-collapse: separate; color: rgb(0, 0, 0); font-family: =
'Lucida Grande'; font-style: normal; font-variant: normal; font-weight: =
normal; letter-spacing: normal; line-height: normal; orphans: 2; =
text-align: -webkit-auto; text-indent: 0px; text-transform: none; =
white-space: normal; widows: 2; word-spacing: 0px; =
-webkit-border-horizontal-spacing: 0px; -webkit-border-vertical-spacing: =
0px; -webkit-text-decorations-in-effect: none; -webkit-text-size-adjust: =
auto; -webkit-text-stroke-width: 0px;  "><div style=3D"word-wrap: =
break-word; -webkit-nbsp-mode: space; -webkit-line-break: =
after-white-space; "><span class=3D"Apple-style-span" =
style=3D"border-collapse: separate; color: rgb(0, 0, 0); font-family: =
'Lucida Grande'; font-style: normal; font-variant: normal; font-weight: =
normal; letter-spacing: normal; line-height: normal; orphans: 2; =
text-align: -webkit-auto; text-indent: 0px; text-transform: none; =
white-space: normal; widows: 2; word-spacing: 0px; =
-webkit-border-horizontal-spacing: 0px; -webkit-border-vertical-spacing: =
0px; -webkit-text-decorations-in-effect: none; -webkit-text-size-adjust: =
auto; -webkit-text-stroke-width: 0px;  "><div style=3D"word-wrap: =
break-word; -webkit-nbsp-mode: space; -webkit-line-break: =
after-white-space; ">--&nbsp;<br>Jonathan Simon, Ph. D<br>Director of =
Systems Engineering<br>Linear Technology, Dust Networks product =
group<br>30695 Huntwood Ave<br>Hayward, CA 94544-7021<br>(510) =
400-2936<br>(510) 489-3799 FAX<br><a =
href=3D"mailto:jsimon@linear.com">jsimon@linear.com</a><br><br>**LINEAR =
TECHNOLOGY&nbsp;CORPORATION**&nbsp;<br>*****Internet Email =
Confidentiality&nbsp;Notice*****&nbsp;<br>&nbsp;This e-mail =
transmission, and any&nbsp;documents, files or previous =
e-mail&nbsp;messages attached to it may contain&nbsp;confidential =
information that is&nbsp;legally privileged. If you are not =
the&nbsp;intended recipient, or a person&nbsp;responsible for delivering =
it to the&nbsp;intended recipient, you are hereby&nbsp;notified that any =
disclosure, copying,&nbsp;distribution or use of any of =
the&nbsp;information contained in or attached&nbsp;to this transmission =
is STRICTLY&nbsp;PROHIBITED. If you have received this&nbsp;transmission =
in error, please&nbsp;immediately notify me by reply e-mail, or by =
telephone at (510) 400-2936, and destroy the original&nbsp;transmission =
and its attachments&nbsp;without reading or saving in any&nbsp;manner. =
Thank you.&nbsp;<br></div></span></div></span></span>
</div>
<br><div><div>On May 28, 2014, at 4:19 PM, &lt;<a =
href=3D"mailto:yoshihiro.ohba@toshiba.co.jp">yoshihiro.ohba@toshiba.co.jp<=
/a>&gt; &lt;<a =
href=3D"mailto:yoshihiro.ohba@toshiba.co.jp">yoshihiro.ohba@toshiba.co.jp<=
/a>&gt; wrote:</div><br class=3D"Apple-interchange-newline"><blockquote =
type=3D"cite"><div lang=3D"JA" link=3D"blue" vlink=3D"purple" =
style=3D"font-family: LucidaGrande; font-size: 14px; font-style: normal; =
font-variant: normal; font-weight: normal; letter-spacing: normal; =
line-height: normal; orphans: auto; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; widows: auto; word-spacing: =
0px; -webkit-text-stroke-width: 0px;"><div class=3D"WordSection1" =
style=3D"page: WordSection1;"><div style=3D"margin: 0mm 0mm 0.0001pt; =
font-size: 12pt; font-family: '=EF=BC=AD=EF=BC=B3 =
=EF=BC=B0=E3=82=B4=E3=82=B7=E3=83=83=E3=82=AF';"><span lang=3D"EN-US" =
style=3D"font-size: 10pt; font-family: Arial, sans-serif; color: rgb(31, =
73, 125);">Hi Jonathan,<o:p></o:p></span></div><div style=3D"margin: 0mm =
0mm 0.0001pt; font-size: 12pt; font-family: '=EF=BC=AD=EF=BC=B3 =
=EF=BC=B0=E3=82=B4=E3=82=B7=E3=83=83=E3=82=AF';"><span lang=3D"EN-US" =
style=3D"font-size: 10pt; font-family: Arial, sans-serif; color: rgb(31, =
73, 125);">&nbsp;</span></div><div style=3D"margin: 0mm 0mm 0.0001pt; =
font-size: 12pt; font-family: '=EF=BC=AD=EF=BC=B3 =
=EF=BC=B0=E3=82=B4=E3=82=B7=E3=83=83=E3=82=AF';"><span lang=3D"EN-US" =
style=3D"font-size: 10pt; font-family: Arial, sans-serif; color: rgb(31, =
73, 125);">I am not caring about an attacker to inject joining traffic, =
but what I care is an attacker attempting to destruct basic TSCH =
operation in the network by sending forged beacons protected with the =
well-known key.<o:p></o:p></span></div><div style=3D"margin: 0mm 0mm =
0.0001pt; font-size: 12pt; font-family: '=EF=BC=AD=EF=BC=B3 =
=EF=BC=B0=E3=82=B4=E3=82=B7=E3=83=83=E3=82=AF';"><span lang=3D"EN-US" =
style=3D"font-size: 10pt; font-family: Arial, sans-serif; color: rgb(31, =
73, 125);">&nbsp;</span></div><div style=3D"margin: 0mm 0mm 0.0001pt; =
font-size: 12pt; font-family: '=EF=BC=AD=EF=BC=B3 =
=EF=BC=B0=E3=82=B4=E3=82=B7=E3=83=83=E3=82=AF';"><span lang=3D"EN-US" =
style=3D"font-size: 10pt; font-family: Arial, sans-serif; color: rgb(31, =
73, 125);">Yoshihiro Ohba<o:p></o:p></span></div><div style=3D"margin: =
0mm 0mm 0.0001pt; font-size: 12pt; font-family: '=EF=BC=AD=EF=BC=B3 =
=EF=BC=B0=E3=82=B4=E3=82=B7=E3=83=83=E3=82=AF';"><span lang=3D"EN-US" =
style=3D"font-size: 10pt; font-family: Arial, sans-serif; color: rgb(31, =
73, 125);">&nbsp;</span></div><div style=3D"margin: 0mm 0mm 0.0001pt; =
font-size: 12pt; font-family: '=EF=BC=AD=EF=BC=B3 =
=EF=BC=B0=E3=82=B4=E3=82=B7=E3=83=83=E3=82=AF';"><span lang=3D"EN-US" =
style=3D"font-size: 10pt; font-family: Arial, sans-serif; color: rgb(31, =
73, 125);">&nbsp;</span></div><div style=3D"margin: 0mm 0mm 0.0001pt; =
font-size: 12pt; font-family: '=EF=BC=AD=EF=BC=B3 =
=EF=BC=B0=E3=82=B4=E3=82=B7=E3=83=83=E3=82=AF';"><span lang=3D"EN-US" =
style=3D"font-size: 10pt; font-family: Arial, sans-serif; color: rgb(31, =
73, 125);">&nbsp;</span></div><div><div style=3D"border-style: solid =
none none; border-top-color: rgb(225, 225, 225); border-top-width: 1pt; =
padding: 3pt 0mm 0mm;"><div style=3D"margin: 0mm 0mm 0.0001pt; =
font-size: 12pt; font-family: '=EF=BC=AD=EF=BC=B3 =
=EF=BC=B0=E3=82=B4=E3=82=B7=E3=83=83=E3=82=AF';"><b><span lang=3D"EN-US" =
style=3D"font-size: 11pt; font-family: Calibri, =
sans-serif;">From:</span></b><span lang=3D"EN-US" style=3D"font-size: =
11pt; font-family: Calibri, sans-serif;"><span =
class=3D"Apple-converted-space">&nbsp;</span>6tisch-security [<a =
href=3D"mailto:6tisch-security-bounces@ietf.org" style=3D"color: purple; =
text-decoration: =
underline;">mailto:6tisch-security-bounces@ietf.org</a>]<span =
class=3D"Apple-converted-space">&nbsp;</span><b>On Behalf Of<span =
class=3D"Apple-converted-space">&nbsp;</span></b>Jonathan =
Simon<br><b>Sent:</b><span =
class=3D"Apple-converted-space">&nbsp;</span>Thursday, May 29, 2014 =
12:47 AM<br><b>To:</b><span =
class=3D"Apple-converted-space">&nbsp;</span>ohba yoshihiro(</span><span =
style=3D"font-size: 11pt;">=E5=A4=A7=E5=A0=B4</span><span =
style=3D"font-size: 11pt; font-family: Calibri, =
sans-serif;">&nbsp;</span><span style=3D"font-size: =
11pt;">=E7=BE=A9=E6=B4=8B</span><span lang=3D"EN-US" style=3D"font-size: =
11pt; font-family: Calibri, sans-serif;"><span =
class=3D"Apple-converted-space">&nbsp;</span>=E2=97=8B</span><span =
style=3D"font-size: 11pt;">=EF=BC=B2=EF=BC=A4=EF=BC=A3</span><span =
lang=3D"EN-US" style=3D"font-size: 11pt; font-family: Calibri, =
sans-serif;">=E2=96=A1</span><span style=3D"font-size: =
11pt;">=EF=BC=AE=EF=BC=B3=EF=BC=AC</span><span lang=3D"EN-US" =
style=3D"font-size: 11pt; font-family: Calibri, =
sans-serif;">)<br><b>Cc:</b><span =
class=3D"Apple-converted-space">&nbsp;</span><a =
href=3D"mailto:mcr+ietf@sandelman.ca" style=3D"color: purple; =
text-decoration: underline;">mcr+ietf@sandelman.ca</a>;<span =
class=3D"Apple-converted-space">&nbsp;</span><a =
href=3D"mailto:rstruik.ext@gmail.com" style=3D"color: purple; =
text-decoration: underline;">rstruik.ext@gmail.com</a>;<span =
class=3D"Apple-converted-space">&nbsp;</span><a =
href=3D"mailto:6tisch-security@ietf.org" style=3D"color: purple; =
text-decoration: =
underline;">6tisch-security@ietf.org</a><br><b>Subject:</b><span =
class=3D"Apple-converted-space">&nbsp;</span>Re: [6tisch-security] =
agenda for 2014-05-27 6tisch security =
call<o:p></o:p></span></div></div></div><div style=3D"margin: 0mm 0mm =
0.0001pt; font-size: 12pt; font-family: '=EF=BC=AD=EF=BC=B3 =
=EF=BC=B0=E3=82=B4=E3=82=B7=E3=83=83=E3=82=AF';"><span =
lang=3D"EN-US">&nbsp;</span></div><div style=3D"margin: 0mm 0mm =
0.0001pt; font-size: 12pt; font-family: '=EF=BC=AD=EF=BC=B3 =
=EF=BC=B0=E3=82=B4=E3=82=B7=E3=83=83=E3=82=AF';"><span =
lang=3D"EN-US">Yoshihiro -<o:p></o:p></span></div><div><div =
style=3D"margin: 0mm 0mm 0.0001pt; font-size: 12pt; font-family: '=EF=BC=AD=
=EF=BC=B3 =EF=BC=B0=E3=82=B4=E3=82=B7=E3=83=83=E3=82=AF';"><span =
lang=3D"EN-US">&nbsp;</span></div></div><div><div style=3D"margin: 0mm =
0mm 0.0001pt; font-size: 12pt; font-family: '=EF=BC=AD=EF=BC=B3 =
=EF=BC=B0=E3=82=B4=E3=82=B7=E3=83=83=E3=82=AF';"><span lang=3D"EN-US">I =
don=E2=80=99t think this is a problem. &nbsp;Nodes that are in the =
network reject incoming frames secured with the well-known key. The =
well-known key is only used to authenticate beacons, and authenticate =
join requests (which don=E2=80=99t carry synchronization information). =
&nbsp;There is a DoS vector, in that an attacker can inject joining =
traffic (destined for the network mananager) that will ultimately be =
discarded, possibly preventing other nodes from joining, and increasing =
the traffic in the network.&nbsp;<o:p></o:p></span></div></div><div><div =
style=3D"margin: 0mm 0mm 0.0001pt; font-size: 12pt; font-family: '=EF=BC=AD=
=EF=BC=B3 =EF=BC=B0=E3=82=B4=E3=82=B7=E3=83=83=E3=82=AF';"><span =
lang=3D"EN-US">&nbsp;</span></div><div><div style=3D"margin: 0mm 0mm =
0.0001pt; font-size: 12pt; font-family: '=EF=BC=AD=EF=BC=B3 =
=EF=BC=B0=E3=82=B4=E3=82=B7=E3=83=83=E3=82=AF';"><span lang=3D"EN-US" =
style=3D"font-family: 'Lucida Grande', serif;">Jonathan Simon, Ph. =
D<br>Director of Systems Engineering<br>Linear Technology, Dust Networks =
product group<br>30695 Huntwood Ave<br>Hayward, CA 94544-7021<br>(510) =
400-2936<br>(510) 489-3799 FAX<br><a href=3D"mailto:jsimon@linear.com" =
style=3D"color: purple; text-decoration: =
underline;">jsimon@linear.com</a><br><br>**LINEAR =
TECHNOLOGY&nbsp;CORPORATION**&nbsp;<br>*****Internet Email =
Confidentiality&nbsp;Notice*****&nbsp;<br>&nbsp;This e-mail =
transmission, and any&nbsp;documents, files or previous =
e-mail&nbsp;messages attached to it may contain&nbsp;confidential =
information that is&nbsp;legally privileged. If you are not =
the&nbsp;intended recipient, or a person&nbsp;responsible for delivering =
it to the&nbsp;intended recipient, you are hereby&nbsp;notified that any =
disclosure, copying,&nbsp;distribution or use of any of =
the&nbsp;information contained in or attached&nbsp;to this transmission =
is STRICTLY&nbsp;PROHIBITED. If you have received this&nbsp;transmission =
in error, please&nbsp;immediately notify me by reply e-mail, or by =
telephone at (510) 400-2936, and destroy the original&nbsp;transmission =
and its attachments&nbsp;without reading or saving in any&nbsp;manner. =
Thank you.&nbsp;<o:p></o:p></span></div></div><div style=3D"margin: 0mm =
0mm 0.0001pt; font-size: 12pt; font-family: '=EF=BC=AD=EF=BC=B3 =
=EF=BC=B0=E3=82=B4=E3=82=B7=E3=83=83=E3=82=AF';"><span =
lang=3D"EN-US">&nbsp;</span></div><div><div><div style=3D"margin: 0mm =
0mm 0.0001pt; font-size: 12pt; font-family: '=EF=BC=AD=EF=BC=B3 =
=EF=BC=B0=E3=82=B4=E3=82=B7=E3=83=83=E3=82=AF';"><span lang=3D"EN-US">On =
May 28, 2014, at 8:01 AM, &lt;<a =
href=3D"mailto:yoshihiro.ohba@toshiba.co.jp" style=3D"color: purple; =
text-decoration: underline;">yoshihiro.ohba@toshiba.co.jp</a>&gt; &lt;<a =
href=3D"mailto:yoshihiro.ohba@toshiba.co.jp" style=3D"color: purple; =
text-decoration: underline;">yoshihiro.ohba@toshiba.co.jp</a>&gt; =
wrote:<o:p></o:p></span></div></div><div style=3D"margin: 0mm 0mm =
0.0001pt; font-size: 12pt; font-family: '=EF=BC=AD=EF=BC=B3 =
=EF=BC=B0=E3=82=B4=E3=82=B7=E3=83=83=E3=82=AF';"><span =
lang=3D"EN-US"><br><br><o:p></o:p></span></div><blockquote =
style=3D"margin-top: 5pt; margin-bottom: 5pt;"><div><div style=3D"margin: =
0mm 0mm 0.0001pt; font-size: 12pt; font-family: '=EF=BC=AD=EF=BC=B3 =
=EF=BC=B0=E3=82=B4=E3=82=B7=E3=83=83=E3=82=AF';"><span lang=3D"EN-US" =
style=3D"font-size: 10pt; font-family: Arial, sans-serif; color: rgb(31, =
73, 125);">Hi Jonathan,</span><span =
lang=3D"EN-US"><o:p></o:p></span></div></div><div><div style=3D"margin: =
0mm 0mm 0.0001pt; font-size: 12pt; font-family: '=EF=BC=AD=EF=BC=B3 =
=EF=BC=B0=E3=82=B4=E3=82=B7=E3=83=83=E3=82=AF';"><span lang=3D"EN-US" =
style=3D"font-size: 10pt; font-family: Arial, sans-serif; color: rgb(31, =
73, 125);">&nbsp;</span><span =
lang=3D"EN-US"><o:p></o:p></span></div></div><div><div style=3D"margin: =
0mm 0mm 0.0001pt; font-size: 12pt; font-family: '=EF=BC=AD=EF=BC=B3 =
=EF=BC=B0=E3=82=B4=E3=82=B7=E3=83=83=E3=82=AF';"><span lang=3D"EN-US" =
style=3D"font-size: 10pt; font-family: Arial, sans-serif; color: rgb(31, =
73, 125);">Thank you for your answer.</span><span =
lang=3D"EN-US"><o:p></o:p></span></div></div><div><div style=3D"margin: =
0mm 0mm 0.0001pt; font-size: 12pt; font-family: '=EF=BC=AD=EF=BC=B3 =
=EF=BC=B0=E3=82=B4=E3=82=B7=E3=83=83=E3=82=AF';"><span lang=3D"EN-US" =
style=3D"font-size: 10pt; font-family: Arial, sans-serif; color: rgb(31, =
73, 125);">&nbsp;</span><span =
lang=3D"EN-US"><o:p></o:p></span></div></div><div><div style=3D"margin: =
0mm 0mm 0.0001pt; font-size: 12pt; font-family: '=EF=BC=AD=EF=BC=B3 =
=EF=BC=B0=E3=82=B4=E3=82=B7=E3=83=83=E3=82=AF';"><span lang=3D"EN-US" =
style=3D"font-size: 10pt; font-family: Arial, sans-serif; color: rgb(31, =
73, 125);">I think this can be an issue if already joined nodes also use =
the beacons protected with the well-known key for maintaining =
synchronization and slot allocations, as an attacker can send forged =
beacons protected with the well-known key.</span><span =
lang=3D"EN-US"><o:p></o:p></span></div></div><div><div style=3D"margin: =
0mm 0mm 0.0001pt; font-size: 12pt; font-family: '=EF=BC=AD=EF=BC=B3 =
=EF=BC=B0=E3=82=B4=E3=82=B7=E3=83=83=E3=82=AF';"><span lang=3D"EN-US" =
style=3D"font-size: 10pt; font-family: Arial, sans-serif; color: rgb(31, =
73, 125);">&nbsp;</span><span =
lang=3D"EN-US"><o:p></o:p></span></div></div><div><div style=3D"margin: =
0mm 0mm 0.0001pt; font-size: 12pt; font-family: '=EF=BC=AD=EF=BC=B3 =
=EF=BC=B0=E3=82=B4=E3=82=B7=E3=83=83=E3=82=AF';"><span lang=3D"EN-US" =
style=3D"font-size: 10pt; font-family: Arial, sans-serif; color: rgb(31, =
73, 125);">Yoshihiro Ohba</span><span =
lang=3D"EN-US"><o:p></o:p></span></div></div><div><div style=3D"margin: =
0mm 0mm 0.0001pt; font-size: 12pt; font-family: '=EF=BC=AD=EF=BC=B3 =
=EF=BC=B0=E3=82=B4=E3=82=B7=E3=83=83=E3=82=AF';"><span lang=3D"EN-US" =
style=3D"font-size: 10pt; font-family: Arial, sans-serif; color: rgb(31, =
73, 125);">&nbsp;</span><span =
lang=3D"EN-US"><o:p></o:p></span></div></div><div><div style=3D"margin: =
0mm 0mm 0.0001pt; font-size: 12pt; font-family: '=EF=BC=AD=EF=BC=B3 =
=EF=BC=B0=E3=82=B4=E3=82=B7=E3=83=83=E3=82=AF';"><span lang=3D"EN-US" =
style=3D"font-size: 10pt; font-family: Arial, sans-serif; color: rgb(31, =
73, 125);">&nbsp;</span><span =
lang=3D"EN-US"><o:p></o:p></span></div></div><div><div style=3D"margin: =
0mm 0mm 0.0001pt; font-size: 12pt; font-family: '=EF=BC=AD=EF=BC=B3 =
=EF=BC=B0=E3=82=B4=E3=82=B7=E3=83=83=E3=82=AF';"><b><span lang=3D"EN-US" =
style=3D"font-size: 11pt; font-family: Calibri, =
sans-serif;">From:</span></b><span class=3D"apple-converted-space"><span =
lang=3D"EN-US" style=3D"font-size: 11pt; font-family: Calibri, =
sans-serif;">&nbsp;</span></span><span lang=3D"EN-US" style=3D"font-size: =
11pt; font-family: Calibri, sans-serif;">6tisch-security [<a =
href=3D"mailto:6tisch-security-bounces@ietf.org" style=3D"color: purple; =
text-decoration: underline;"><span style=3D"color: =
purple;">mailto:6tisch-security-bounces@ietf.org</span></a>]<span =
class=3D"apple-converted-space">&nbsp;</span><b>On Behalf Of<span =
class=3D"apple-converted-space">&nbsp;</span></b>Jonathan =
Simon<br><b>Sent:</b><span =
class=3D"apple-converted-space">&nbsp;</span>Wednesday, May 28, 2014 =
11:49 PM<br><b>To:</b><span =
class=3D"apple-converted-space">&nbsp;</span>ohba yoshihiro(</span><span =
style=3D"font-size: 11pt;">=E5=A4=A7=E5=A0=B4</span><span lang=3D"EN-US" =
style=3D"font-size: 11pt; font-family: Calibri, =
sans-serif;">&nbsp;</span><span style=3D"font-size: =
11pt;">=E7=BE=A9=E6=B4=8B</span><span =
class=3D"apple-converted-space"><span lang=3D"EN-US" style=3D"font-size: =
11pt; font-family: Calibri, sans-serif;">&nbsp;</span></span><span =
lang=3D"EN-US" style=3D"font-size: 11pt; font-family: Calibri, =
sans-serif;">=E2=97=8B</span><span style=3D"font-size: =
11pt;">=EF=BC=B2=EF=BC=A4=EF=BC=A3</span><span lang=3D"EN-US" =
style=3D"font-size: 11pt; font-family: Calibri, =
sans-serif;">=E2=96=A1</span><span style=3D"font-size: =
11pt;">=EF=BC=AE=EF=BC=B3=EF=BC=AC</span><span lang=3D"EN-US" =
style=3D"font-size: 11pt; font-family: Calibri, =
sans-serif;">)<br><b>Cc:</b><span =
class=3D"apple-converted-space">&nbsp;</span>Michael Richardson; Rene =
Struik;<span class=3D"apple-converted-space">&nbsp;</span><a =
href=3D"mailto:6tisch-security@ietf.org" style=3D"color: purple; =
text-decoration: underline;"><span style=3D"color: =
purple;">6tisch-security@ietf.org</span></a><br><b>Subject:</b><span =
class=3D"apple-converted-space">&nbsp;</span>Re: [6tisch-security] =
agenda for 2014-05-27 6tisch security call</span><span =
lang=3D"EN-US"><o:p></o:p></span></div></div><div><div style=3D"margin: =
0mm 0mm 0.0001pt; font-size: 12pt; font-family: '=EF=BC=AD=EF=BC=B3 =
=EF=BC=B0=E3=82=B4=E3=82=B7=E3=83=83=E3=82=AF';"><span =
lang=3D"EN-US">&nbsp;<o:p></o:p></span></div></div><div><div><p =
class=3D"MsoNormal" style=3D"margin: 0mm 0mm 12pt; font-size: 12pt; =
font-family: '=EF=BC=AD=EF=BC=B3 =EF=BC=B0=E3=82=B4=E3=82=B7=E3=83=83=E3=82=
=AF';"><span lang=3D"EN-US">Yoshihiro -<span =
class=3D"apple-converted-space">&nbsp;</span><br><br>Q.<span =
class=3D"apple-converted-space">&nbsp;</span></span><span lang=3D"EN-US" =
style=3D"font-size: 10pt; font-family: Arial, sans-serif; color: rgb(31, =
73, 125);">In w/HART, are all beacon frames authenticated with a =
well-known key even after a joining node obtained the runtime link layer =
key?</span><span lang=3D"EN-US"><o:p></o:p></span></p></div><div><p =
class=3D"MsoNormal" style=3D"margin: 0mm 0mm 12pt; font-size: 12pt; =
font-family: '=EF=BC=AD=EF=BC=B3 =EF=BC=B0=E3=82=B4=E3=82=B7=E3=83=83=E3=82=
=AF';"><span lang=3D"EN-US" style=3D"font-size: 10pt; font-family: =
Arial, sans-serif; color: rgb(31, 73, 125);">A. Yes. In WirelessHART the =
beacons (called "advertisements" but they serve the same purpose and =
have similar content) are intended for devices not yet in the network, =
so they always use the well-known key.&nbsp; To discover other nodes =
within the network, they use frames secured with the runtime link-layer =
key.</span><span lang=3D"EN-US"><o:p></o:p></span></p></div><div><div =
style=3D"margin: 0mm 0mm 0.0001pt; font-size: 12pt; font-family: '=EF=BC=AD=
=EF=BC=B3 =EF=BC=B0=E3=82=B4=E3=82=B7=E3=83=83=E3=82=AF';"><span =
lang=3D"EN-US" style=3D"font-size: 10pt; font-family: Arial, sans-serif; =
color: rgb(31, 73, 125);">Jonathan</span><span =
lang=3D"EN-US"><o:p></o:p></span></div></div></div><div><p =
class=3D"MsoNormal" style=3D"margin: 0mm 0mm 12pt; font-size: 12pt; =
font-family: '=EF=BC=AD=EF=BC=B3 =EF=BC=B0=E3=82=B4=E3=82=B7=E3=83=83=E3=82=
=AF';"><span lang=3D"EN-US">&nbsp;<o:p></o:p></span></p><div><div><div =
style=3D"margin: 0mm 0mm 0.0001pt; font-size: 12pt; font-family: '=EF=BC=AD=
=EF=BC=B3 =EF=BC=B0=E3=82=B4=E3=82=B7=E3=83=83=E3=82=AF';"><span =
lang=3D"EN-US">On Tue, May 27, 2014 at 11:18 PM, &lt;<a =
href=3D"mailto:yoshihiro.ohba@toshiba.co.jp" target=3D"_blank" =
style=3D"color: purple; text-decoration: underline;"><span style=3D"color:=
 purple;">yoshihiro.ohba@toshiba.co.jp</span></a>&gt; =
wrote:<o:p></o:p></span></div></div><blockquote style=3D"border-style: =
none none none solid; border-left-color: rgb(204, 204, 204); =
border-left-width: 1pt; padding: 0mm 0mm 0mm 6pt; margin: 5pt 0mm 5pt =
4.8pt;"><div><div><div style=3D"margin: 0mm 0mm 0.0001pt; font-size: =
12pt; font-family: '=EF=BC=AD=EF=BC=B3 =EF=BC=B0=E3=82=B4=E3=82=B7=E3=83=83=
=E3=82=AF';"><span lang=3D"EN-US" style=3D"font-size: 10pt; font-family: =
Arial, sans-serif; color: rgb(31, 73, 125);">Hi Jonathan,</span><span =
lang=3D"EN-US"><o:p></o:p></span></div></div><div><div style=3D"margin: =
0mm 0mm 0.0001pt; font-size: 12pt; font-family: '=EF=BC=AD=EF=BC=B3 =
=EF=BC=B0=E3=82=B4=E3=82=B7=E3=83=83=E3=82=AF';"><span lang=3D"EN-US" =
style=3D"font-size: 10pt; font-family: Arial, sans-serif; color: rgb(31, =
73, 125);">&nbsp;</span><span =
lang=3D"EN-US"><o:p></o:p></span></div></div><div><div style=3D"margin: =
0mm 0mm 0.0001pt; font-size: 12pt; font-family: '=EF=BC=AD=EF=BC=B3 =
=EF=BC=B0=E3=82=B4=E3=82=B7=E3=83=83=E3=82=AF';"><span lang=3D"EN-US" =
style=3D"font-size: 10pt; font-family: Arial, sans-serif; color: rgb(31, =
73, 125);">Thank you for sending the summary of w/HART =
joining.</span><span =
lang=3D"EN-US"><o:p></o:p></span></div></div><div><div style=3D"margin: =
0mm 0mm 0.0001pt; font-size: 12pt; font-family: '=EF=BC=AD=EF=BC=B3 =
=EF=BC=B0=E3=82=B4=E3=82=B7=E3=83=83=E3=82=AF';"><span lang=3D"EN-US" =
style=3D"font-size: 10pt; font-family: Arial, sans-serif; color: rgb(31, =
73, 125);">&nbsp;</span><span =
lang=3D"EN-US"><o:p></o:p></span></div></div><div><div style=3D"margin: =
0mm 0mm 0.0001pt; font-size: 12pt; font-family: '=EF=BC=AD=EF=BC=B3 =
=EF=BC=B0=E3=82=B4=E3=82=B7=E3=83=83=E3=82=AF';"><span lang=3D"EN-US" =
style=3D"font-size: 10pt; font-family: Arial, sans-serif; color: rgb(31, =
73, 125);">I have question.</span><span =
lang=3D"EN-US"><o:p></o:p></span></div></div><div><div style=3D"margin: =
0mm 0mm 0.0001pt; font-size: 12pt; font-family: '=EF=BC=AD=EF=BC=B3 =
=EF=BC=B0=E3=82=B4=E3=82=B7=E3=83=83=E3=82=AF';"><span lang=3D"EN-US" =
style=3D"font-size: 10pt; font-family: Arial, sans-serif; color: rgb(31, =
73, 125);">&nbsp;</span><span =
lang=3D"EN-US"><o:p></o:p></span></div></div><div><div style=3D"margin: =
0mm 0mm 0.0001pt; font-size: 12pt; font-family: '=EF=BC=AD=EF=BC=B3 =
=EF=BC=B0=E3=82=B4=E3=82=B7=E3=83=83=E3=82=AF';"><span lang=3D"EN-US" =
style=3D"font-size: 10pt; font-family: Arial, sans-serif; color: rgb(31, =
73, 125);">In w/HART, are all beacon frames authenticated with a =
well-known key even after a joining node obtained the runtime link layer =
key?&nbsp;</span><span =
lang=3D"EN-US"><o:p></o:p></span></div></div><div><div style=3D"margin: =
0mm 0mm 0.0001pt; font-size: 12pt; font-family: '=EF=BC=AD=EF=BC=B3 =
=EF=BC=B0=E3=82=B4=E3=82=B7=E3=83=83=E3=82=AF';"><span lang=3D"EN-US" =
style=3D"font-size: 10pt; font-family: Arial, sans-serif; color: rgb(31, =
73, 125);">&nbsp;</span><span =
lang=3D"EN-US"><o:p></o:p></span></div></div><div><div style=3D"margin: =
0mm 0mm 0.0001pt; font-size: 12pt; font-family: '=EF=BC=AD=EF=BC=B3 =
=EF=BC=B0=E3=82=B4=E3=82=B7=E3=83=83=E3=82=AF';"><span lang=3D"EN-US" =
style=3D"font-size: 10pt; font-family: Arial, sans-serif; color: rgb(31, =
73, 125);">Regards,</span><span =
lang=3D"EN-US"><o:p></o:p></span></div></div><div><div style=3D"margin: =
0mm 0mm 0.0001pt; font-size: 12pt; font-family: '=EF=BC=AD=EF=BC=B3 =
=EF=BC=B0=E3=82=B4=E3=82=B7=E3=83=83=E3=82=AF';"><span lang=3D"EN-US" =
style=3D"font-size: 10pt; font-family: Arial, sans-serif; color: rgb(31, =
73, 125);">Yoshihiro Ohba</span><span =
lang=3D"EN-US"><o:p></o:p></span></div></div><div><div style=3D"margin: =
0mm 0mm 0.0001pt; font-size: 12pt; font-family: '=EF=BC=AD=EF=BC=B3 =
=EF=BC=B0=E3=82=B4=E3=82=B7=E3=83=83=E3=82=AF';"><span lang=3D"EN-US" =
style=3D"font-size: 10pt; font-family: Arial, sans-serif; color: rgb(31, =
73, 125);">&nbsp;</span><span =
lang=3D"EN-US"><o:p></o:p></span></div></div><div><div style=3D"margin: =
0mm 0mm 0.0001pt; font-size: 12pt; font-family: '=EF=BC=AD=EF=BC=B3 =
=EF=BC=B0=E3=82=B4=E3=82=B7=E3=83=83=E3=82=AF';"><span lang=3D"EN-US" =
style=3D"font-size: 10pt; font-family: Arial, sans-serif; color: rgb(31, =
73, 125);">&nbsp;</span><span =
lang=3D"EN-US"><o:p></o:p></span></div></div><div><div style=3D"margin: =
0mm 0mm 0.0001pt; font-size: 12pt; font-family: '=EF=BC=AD=EF=BC=B3 =
=EF=BC=B0=E3=82=B4=E3=82=B7=E3=83=83=E3=82=AF';"><span lang=3D"EN-US" =
style=3D"font-size: 10pt; font-family: Arial, sans-serif; color: rgb(31, =
73, 125);">&nbsp;</span><span =
lang=3D"EN-US"><o:p></o:p></span></div></div><div><div style=3D"margin: =
0mm 0mm 0.0001pt; font-size: 12pt; font-family: '=EF=BC=AD=EF=BC=B3 =
=EF=BC=B0=E3=82=B4=E3=82=B7=E3=83=83=E3=82=AF';"><span lang=3D"EN-US" =
style=3D"font-size: 10pt; font-family: Arial, sans-serif; color: rgb(31, =
73, 125);">&nbsp;</span><span =
lang=3D"EN-US"><o:p></o:p></span></div></div><div><div style=3D"margin: =
0mm 0mm 0.0001pt; font-size: 12pt; font-family: '=EF=BC=AD=EF=BC=B3 =
=EF=BC=B0=E3=82=B4=E3=82=B7=E3=83=83=E3=82=AF';"><b><span lang=3D"EN-US" =
style=3D"font-size: 11pt; font-family: Calibri, =
sans-serif;">From:</span></b><span class=3D"apple-converted-space"><span =
lang=3D"EN-US" style=3D"font-size: 11pt; font-family: Calibri, =
sans-serif;">&nbsp;</span></span><span lang=3D"EN-US" style=3D"font-size: =
11pt; font-family: Calibri, sans-serif;">6tisch-security [mailto:<a =
href=3D"mailto:6tisch-security-bounces@ietf.org" target=3D"_blank" =
style=3D"color: purple; text-decoration: underline;"><span style=3D"color:=
 purple;">6tisch-security-bounces@ietf.org</span></a>]<span =
class=3D"apple-converted-space">&nbsp;</span><b>On Behalf Of<span =
class=3D"apple-converted-space">&nbsp;</span></b>Jonathan =
Simon<br><b>Sent:</b><span =
class=3D"apple-converted-space">&nbsp;</span>Tuesday, May 27, 2014 10:41 =
PM<br><b>To:</b><span class=3D"apple-converted-space">&nbsp;</span>Rene =
Struik<br><b>Cc:</b><span =
class=3D"apple-converted-space">&nbsp;</span>Michael Richardson;<span =
class=3D"apple-converted-space">&nbsp;</span><a =
href=3D"mailto:6tisch-security@ietf.org" target=3D"_blank" style=3D"color:=
 purple; text-decoration: underline;"><span style=3D"color: =
purple;">6tisch-security@ietf.org</span></a><br><b>Subject:</b><span =
class=3D"apple-converted-space">&nbsp;</span>Re: [6tisch-security] =
agenda for 2014-05-27 6tisch security call</span><span =
lang=3D"EN-US"><o:p></o:p></span></div></div><div><div style=3D"margin: =
0mm 0mm 0.0001pt; font-size: 12pt; font-family: '=EF=BC=AD=EF=BC=B3 =
=EF=BC=B0=E3=82=B4=E3=82=B7=E3=83=83=E3=82=AF';"><span =
lang=3D"EN-US">&nbsp;<o:p></o:p></span></div></div><div><div><div><p =
class=3D"MsoNormal" style=3D"margin: 0mm 0mm 12pt; font-size: 12pt; =
font-family: '=EF=BC=AD=EF=BC=B3 =EF=BC=B0=E3=82=B4=E3=82=B7=E3=83=83=E3=82=
=AF';"><span lang=3D"EN-US">Rene had asked on a previous call for =
someone to summarize WirelessHART joining - here you go.<br><br>* One or =
more devices are sending beacons to advertise the presence of the =
network. In WirelessHART, this frame is unencrypted, but authenticated =
with a well known key.&nbsp; The beacon contains the current ASN, which =
the joining device uses to synchronize its =
clock.<o:p></o:p></span></p><div><p class=3D"MsoNormal" style=3D"margin: =
0mm 0mm 12pt; font-size: 12pt; font-family: '=EF=BC=AD=EF=BC=B3 =
=EF=BC=B0=E3=82=B4=E3=82=B7=E3=83=83=E3=82=AF';"><span lang=3D"EN-US">* =
Once the joining node has heard a beacon, it continues listening for =
additional beacons for a short specified =
timeout.<o:p></o:p></span></p></div><p class=3D"MsoNormal" =
style=3D"margin: 0mm 0mm 12pt; font-size: 12pt; font-family: '=EF=BC=AD=EF=
=BC=B3 =EF=BC=B0=E3=82=B4=E3=82=B7=E3=83=83=E3=82=AF';"><span =
lang=3D"EN-US">* The joining node encrypts a frame containing some HART =
specific content, including a list of beaconing neighbors it heard in =
the previous steps. The size of the payload is ~ 60 bytes.&nbsp; The =
packet is routed by a "proxy" node - the joining parent. The frame is =
authenticated using the well-known key, and encrypted using a shared =
symmetric key known only by the node and the manager.<br><br>* The =
manager responds with a frame containing the run-time link-layer key, =
the node's new short address (this takes the place of PAN coordinator =
association), and a unicast session key and starting nonce for the =
manager. This frame is encrypted with the symmetric key. The payload is =
~ 60 bytes, and is routed to the proxy for delivery to the joining node =
- the proxy uses the link-layer well known key on the =
frame.<o:p></o:p></span></p><div><p class=3D"MsoNormal" style=3D"margin: =
0mm 0mm 12pt; font-size: 12pt; font-family: '=EF=BC=AD=EF=BC=B3 =
=EF=BC=B0=E3=82=B4=E3=82=B7=E3=83=83=E3=82=AF';"><span lang=3D"EN-US">* =
At this point the joining node transitions to using the run-time =
link-layer key for all link-layer frames, and the manager unicast =
session for end-to-end manager traffic. This ends the initial security =
handshake.<o:p></o:p></span></p></div><div><p class=3D"MsoNormal" =
style=3D"margin: 0mm 0mm 12pt; font-size: 12pt; font-family: '=EF=BC=AD=EF=
=BC=B3 =EF=BC=B0=E3=82=B4=E3=82=B7=E3=83=83=E3=82=AF';"><span =
lang=3D"EN-US">* Over a number of additional frames, the manager assigns =
additional sessions, including broadcast sessions, and a unicast session =
to the Gateway (sink for all data traffic), and additional =
communications resources, routing information, etc.&nbsp; There is no =
explicit transition from joining to joined - the mote transitions when =
certain key frames are received.<o:p></o:p></span></p></div><p =
class=3D"MsoNormal" style=3D"margin: 0mm 0mm 12pt; font-size: 12pt; =
font-family: '=EF=BC=AD=EF=BC=B3 =EF=BC=B0=E3=82=B4=E3=82=B7=E3=83=83=E3=82=
=AF';"><span lang=3D"EN-US">* Note that a WirelessHART link-layer frame =
contains and additional frame type byte and a 4-byte link-layer MIC, on =
top of the unsecured 15.4 frame.&nbsp; A network frame contains an =
additional 16-40 bytes of addressing, routing, security and other =
information.<o:p></o:p></span></p></div><p class=3D"MsoNormal" =
style=3D"margin: 0mm 0mm 12pt; font-size: 12pt; font-family: '=EF=BC=AD=EF=
=BC=B3 =EF=BC=B0=E3=82=B4=E3=82=B7=E3=83=83=E3=82=AF';"><span =
lang=3D"EN-US">Hope this help!<o:p></o:p></span></p></div><div><div =
style=3D"margin: 0mm 0mm 0.0001pt; font-size: 12pt; font-family: '=EF=BC=AD=
=EF=BC=B3 =EF=BC=B0=E3=82=B4=E3=82=B7=E3=83=83=E3=82=AF';"><span =
lang=3D"EN-US">Jonathan<o:p></o:p></span></div></div><div><div =
style=3D"margin: 0mm 0mm 0.0001pt; font-size: 12pt; font-family: '=EF=BC=AD=
=EF=BC=B3 =EF=BC=B0=E3=82=B4=E3=82=B7=E3=83=83=E3=82=AF';"><span =
lang=3D"EN-US">&nbsp;<o:p></o:p></span></div></div></div><div><p =
class=3D"MsoNormal" style=3D"margin: 0mm 0mm 12pt; font-size: 12pt; =
font-family: '=EF=BC=AD=EF=BC=B3 =EF=BC=B0=E3=82=B4=E3=82=B7=E3=83=83=E3=82=
=AF';"><span lang=3D"EN-US">&nbsp;<o:p></o:p></span></p><div><div><div =
style=3D"margin: 0mm 0mm 0.0001pt; font-size: 12pt; font-family: '=EF=BC=AD=
=EF=BC=B3 =EF=BC=B0=E3=82=B4=E3=82=B7=E3=83=83=E3=82=AF';"><span =
lang=3D"EN-US">On Mon, May 26, 2014 at 8:09 PM, Rene Struik &lt;<a =
href=3D"mailto:rstruik.ext@gmail.com" target=3D"_blank" style=3D"color: =
purple; text-decoration: underline;"><span style=3D"color: =
purple;">rstruik.ext@gmail.com</span></a>&gt; =
wrote:<o:p></o:p></span></div></div><blockquote style=3D"border-style: =
none none none solid; border-left-color: rgb(204, 204, 204); =
border-left-width: 1pt; padding: 0mm 0mm 0mm 6pt; margin: 5pt 0mm 5pt =
4.8pt;"><div><div><div style=3D"margin: 0mm 0mm 0.0001pt; font-size: =
12pt; font-family: '=EF=BC=AD=EF=BC=B3 =EF=BC=B0=E3=82=B4=E3=82=B7=E3=83=83=
=E3=82=AF';"><span lang=3D"EN-US">Hi Michael:<br><br>I would like to =
discuss the outstanding issues I summarized in my email of Tue last =
week, May 20, 2014, 9:45am EDT (see<span =
class=3D"apple-converted-space">&nbsp;</span><a =
href=3D"http://cp.mcafee.com/d/5fHCMUp41ESyNt55OWtSjtPqbwVBcSyUepvdEK3zhOy=
COqejrzPPPz5XCN6ABqM1hYEvIundDOx-NVsTJQXIfcLZvC4TQTS6eLsKCO-PPXX3XUVzBHFSh=
jlKepVkffGhBrwqrhdI6XYyMCY-ehojd79KVI05bVKY01MjbX6NehDY05zAVkIjbQ-PspjbppK=
cvxf5q4rTKYVMedKjBiNcLjXdNBcIn8lrxrW0GnPtU02rhhuhKr1vF6y0QJKjBiNcLjXdNBcIq=
njh1F7U8qq87qNd42tQm2ZTOWoUQgejBiNcQgk-Pspjb6y2SDDCT63pO_o" =
target=3D"_blank" style=3D"color: purple; text-decoration: =
underline;"><span style=3D"color: =
purple;">http://www.ietf.org/mail-archive/web/6tisch-security/current/msg0=
0086.html</span></a>). This was also one of the action items at the =
conclusion of last week's 6TiSCH security call.<br><br>FYI - the w/HART =
communication flows were discussed during the 6TiSCH security conf call =
the week before, on Mon May 12, 2014. If one wishes to go over this =
again, that is fine, but I would prefer us giving preference to taking =
on already articulated issues (which were assigned as homework =
assignment to reflect upon) first (i.e., prior to item #4 of the =
proposed agenda).<br><br>As another agenda point, I would like us to =
discuss the frequency of future calls (as part of EOB).<br><br>Best =
regards, Rene<br><br><br>On 5/26/2014 10:49 PM, Michael Richardson =
wrote:<o:p></o:p></span></div></div><blockquote style=3D"margin-top: =
5pt; margin-bottom: 5pt;"><pre style=3D"margin: 0mm 0mm 0.0001pt; =
font-size: 12pt; font-family: '=EF=BC=AD=EF=BC=B3 =E3=82=B4=E3=82=B7=E3=83=
=83=E3=82=AF';"><span lang=3D"EN-US">To remind, we moved the call from =
the 26th to the 27th at 10am EDT.<o:p></o:p></span></pre><pre =
style=3D"margin: 0mm 0mm 0.0001pt; font-size: 12pt; font-family: '=EF=BC=AD=
=EF=BC=B3 =E3=82=B4=E3=82=B7=E3=83=83=E3=82=AF';"><span =
lang=3D"EN-US">That's 90 minutes from this =
email.<o:p></o:p></span></pre><pre style=3D"margin: 0mm 0mm 0.0001pt; =
font-size: 12pt; font-family: '=EF=BC=AD=EF=BC=B3 =E3=82=B4=E3=82=B7=E3=83=
=83=E3=82=AF';"><span lang=3D"EN-US">&nbsp;<o:p></o:p></span></pre><pre =
style=3D"margin: 0mm 0mm 0.0001pt; font-size: 12pt; font-family: '=EF=BC=AD=
=EF=BC=B3 =E3=82=B4=E3=82=B7=E3=83=83=E3=82=AF';"><span lang=3D"EN-US">1) =
notewell.<o:p></o:p></span></pre><pre style=3D"margin: 0mm 0mm 0.0001pt; =
font-size: 12pt; font-family: '=EF=BC=AD=EF=BC=B3 =E3=82=B4=E3=82=B7=E3=83=
=83=E3=82=AF';"><span lang=3D"EN-US">2) =
intros<o:p></o:p></span></pre><pre style=3D"margin: 0mm 0mm 0.0001pt; =
font-size: 12pt; font-family: '=EF=BC=AD=EF=BC=B3 =E3=82=B4=E3=82=B7=E3=83=
=83=E3=82=AF';"><span lang=3D"EN-US">3) recap of =
draft-piro-<o:p></o:p></span></pre><pre style=3D"margin: 0mm 0mm =
0.0001pt; font-size: 12pt; font-family: '=EF=BC=AD=EF=BC=B3 =
=E3=82=B4=E3=82=B7=E3=83=83=E3=82=AF';"><span lang=3D"EN-US">4) =
wirelesshart -way --- how does the communication =
work?<o:p></o:p></span></pre><pre style=3D"margin: 0mm 0mm 0.0001pt; =
font-size: 12pt; font-family: '=EF=BC=AD=EF=BC=B3 =E3=82=B4=E3=82=B7=E3=83=
=83=E3=82=AF';"><span lang=3D"EN-US">5) how to summarize all of this to =
the working group<o:p></o:p></span></pre><pre style=3D"margin: 0mm 0mm =
0.0001pt; font-size: 12pt; font-family: '=EF=BC=AD=EF=BC=B3 =
=E3=82=B4=E3=82=B7=E3=83=83=E3=82=AF';"><span lang=3D"EN-US">6) how to =
close this process up?<o:p></o:p></span></pre><pre style=3D"margin: 0mm =
0mm 0.0001pt; font-size: 12pt; font-family: '=EF=BC=AD=EF=BC=B3 =
=E3=82=B4=E3=82=B7=E3=83=83=E3=82=AF';"><span =
lang=3D"EN-US">&nbsp;<o:p></o:p></span></pre><pre style=3D"margin: 0mm =
0mm 0.0001pt; font-size: 12pt; font-family: '=EF=BC=AD=EF=BC=B3 =
=E3=82=B4=E3=82=B7=E3=83=83=E3=82=AF';"><span lang=3D"EN-US">-- remember =
that the call is recorded, and the NoteWell =
applies.<o:p></o:p></span></pre><pre style=3D"margin: 0mm 0mm 0.0001pt; =
font-size: 12pt; font-family: '=EF=BC=AD=EF=BC=B3 =E3=82=B4=E3=82=B7=E3=83=
=83=E3=82=AF';"><span lang=3D"EN-US">&nbsp;<o:p></o:p></span></pre><pre =
style=3D"margin: 0mm 0mm 0.0001pt; font-size: 12pt; font-family: '=EF=BC=AD=
=EF=BC=B3 =E3=82=B4=E3=82=B7=E3=83=83=E3=82=AF';"><span lang=3D"EN-US">-- =
The URL to access the webex, which will we use for audio =
only:<o:p></o:p></span></pre><pre style=3D"margin: 0mm 0mm 0.0001pt; =
font-size: 12pt; font-family: '=EF=BC=AD=EF=BC=B3 =E3=82=B4=E3=82=B7=E3=83=
=83=E3=82=AF';"><span lang=3D"EN-US">&nbsp; <a =
href=3D"http://cp.mcafee.com/d/5fHCN0SyNt55OWtSjtPqbwVBcSyUepvdEK3zhOyCOqe=
jrzPPPz5XCN6ABqM1hYEvIundDOx-NVsTJQXIfcLZvC4TQTS6eLsKCO-PPXX3XUVzBHFShjlKe=
pVkffGhBrwqrjdI6XYyMCY-ehojd79KVIDeqR4IOQGmHM0L3-nOQGmHwzMh93o93gUVldTQmjh=
Ogtu7em_mvIUCevLp1ZWV0sqerL6T9OFoCnFZCUOCmbAaJMJZ0lbVKY01dEEL8TdwLQzh0qmT9=
OFoCnFZCUOCmdbFEwQzY4dd43JoCy1eWb1uXVtcsq879OFoCq8avpKcFBzh1rjPPrz1LmTw7w1=
7" target=3D"_blank" style=3D"color: purple; text-decoration: =
underline;"><span style=3D"color: =
purple;">https://cisco.webex.com/cisco/j.php?MTID=3Dm2fe139bf876cea3ec6275=
0cd580b7908</span></a><o:p></o:p></span></pre><pre style=3D"margin: 0mm =
0mm 0.0001pt; font-size: 12pt; font-family: '=EF=BC=AD=EF=BC=B3 =
=E3=82=B4=E3=82=B7=E3=83=83=E3=82=AF';"><span =
lang=3D"EN-US">&nbsp;<o:p></o:p></span></pre><pre style=3D"margin: 0mm =
0mm 0.0001pt; font-size: 12pt; font-family: '=EF=BC=AD=EF=BC=B3 =
=E3=82=B4=E3=82=B7=E3=83=83=E3=82=AF';"><span lang=3D"EN-US">-- we will =
resume with the etherpad at:<o:p></o:p></span></pre><pre style=3D"margin: =
0mm 0mm 0.0001pt; font-size: 12pt; font-family: '=EF=BC=AD=EF=BC=B3 =
=E3=82=B4=E3=82=B7=E3=83=83=E3=82=AF';"><span lang=3D"EN-US">&nbsp;&nbsp; =
<a =
href=3D"http://cp.mcafee.com/d/2DRPow71NJ5yWabBQXICXCQn1PapJ5MsO-rhs76zB5d=
AQsCT7DDD6bTdyd9aRw2zVg_oYKrfB3ZzOVLrFToupvW_c9LFLIctuVtdBZDDTS7TNP7bnjIyC=
HssPOEuvkzaT0QSOrodTV5xdVYsyMCqejtPo0fVA_yJG7jHk-Di-rL00kzhPuZYmO5p_gLbVKB=
TzhOnsDaBypuDSrzapoSVelb4OZfIT6kONsxlK5LE2FvdTw09J55V6VI5-Aq83iSVelb4OZfIT=
6kONFtd46AvwxFEwtH4Qg9ThobTvbFzzh0Velb4Ph1jXdNBcIq8bquursodJiZvpmK6GwY" =
target=3D"_blank" style=3D"color: purple; text-decoration: =
underline;"><span style=3D"color: =
purple;">http://etherpad.tools.ietf.org:9000/p/notes-ietf-89-6tisch-securi=
ty</span></a><o:p></o:p></span></pre><pre style=3D"margin: 0mm 0mm =
0.0001pt; font-size: 12pt; font-family: '=EF=BC=AD=EF=BC=B3 =
=E3=82=B4=E3=82=B7=E3=83=83=E3=82=AF';"><span =
lang=3D"EN-US">&nbsp;<o:p></o:p></span></pre><pre style=3D"margin: 0mm =
0mm 0.0001pt; font-size: 12pt; font-family: '=EF=BC=AD=EF=BC=B3 =
=E3=82=B4=E3=82=B7=E3=83=83=E3=82=AF';"><span lang=3D"EN-US">I'm at <a =
href=3D"tel:%2B1%20613%20276-6809" target=3D"_blank" style=3D"color: =
purple; text-decoration: underline;"><span style=3D"color: purple;">+1 =
613 276-6809</span></a>, IM: <a href=3D"mailto:mcr@xmpp.credil.org" =
target=3D"_blank" style=3D"color: purple; text-decoration: =
underline;"><span style=3D"color: =
purple;">mcr@xmpp.credil.org</span></a> or <a =
href=3D"mailto:mcharlesr@gmail.com" target=3D"_blank" style=3D"color: =
purple; text-decoration: underline;"><span style=3D"color: =
purple;">mcharlesr@gmail.com</span></a>,<o:p></o:p></span></pre><pre =
style=3D"margin: 0mm 0mm 0.0001pt; font-size: 12pt; font-family: '=EF=BC=AD=
=EF=BC=B3 =E3=82=B4=E3=82=B7=E3=83=83=E3=82=AF';"><span lang=3D"EN-US">if =
you need more than that to get in, or are having =
difficulties.<o:p></o:p></span></pre><pre style=3D"margin: 0mm 0mm =
0.0001pt; font-size: 12pt; font-family: '=EF=BC=AD=EF=BC=B3 =
=E3=82=B4=E3=82=B7=E3=83=83=E3=82=AF';"><span lang=3D"EN-US">Please make =
sure your audio works, and that you mute when not =
talking.<o:p></o:p></span></pre><pre style=3D"margin: 0mm 0mm 0.0001pt; =
font-size: 12pt; font-family: '=EF=BC=AD=EF=BC=B3 =E3=82=B4=E3=82=B7=E3=83=
=83=E3=82=AF';"><span lang=3D"EN-US">&nbsp;<o:p></o:p></span></pre><pre =
style=3D"margin: 0mm 0mm 0.0001pt; font-size: 12pt; font-family: '=EF=BC=AD=
=EF=BC=B3 =E3=82=B4=E3=82=B7=E3=83=83=E3=82=AF';"><span =
lang=3D"EN-US">--<o:p></o:p></span></pre><pre style=3D"margin: 0mm 0mm =
0.0001pt; font-size: 12pt; font-family: '=EF=BC=AD=EF=BC=B3 =
=E3=82=B4=E3=82=B7=E3=83=83=E3=82=AF';"><span lang=3D"EN-US">Michael =
Richardson <a href=3D"mailto:mcr+IETF@sandelman.ca" target=3D"_blank" =
style=3D"color: purple; text-decoration: underline;"><span style=3D"color:=
 purple;">&lt;mcr+IETF@sandelman.ca&gt;</span></a>, Sandelman Software =
Works<o:p></o:p></span></pre><pre style=3D"margin: 0mm 0mm 0.0001pt; =
font-size: 12pt; font-family: '=EF=BC=AD=EF=BC=B3 =E3=82=B4=E3=82=B7=E3=83=
=83=E3=82=AF';"><span lang=3D"EN-US"> -=3D IPv6 IoT consulting =
=3D-<o:p></o:p></span></pre><pre style=3D"margin: 0mm 0mm 0.0001pt; =
font-size: 12pt; font-family: '=EF=BC=AD=EF=BC=B3 =E3=82=B4=E3=82=B7=E3=83=
=83=E3=82=AF';"><span lang=3D"EN-US">&nbsp;<o:p></o:p></span></pre><pre =
style=3D"margin: 0mm 0mm 0.0001pt; font-size: 12pt; font-family: '=EF=BC=AD=
=EF=BC=B3 =E3=82=B4=E3=82=B7=E3=83=83=E3=82=AF';"><span =
lang=3D"EN-US">&nbsp;<o:p></o:p></span></pre><pre style=3D"margin: 0mm =
0mm 0.0001pt; font-size: 12pt; font-family: '=EF=BC=AD=EF=BC=B3 =
=E3=82=B4=E3=82=B7=E3=83=83=E3=82=AF';"><span =
lang=3D"EN-US">&nbsp;<o:p></o:p></span></pre><p class=3D"MsoNormal" =
style=3D"margin: 0mm 0mm 12pt; font-size: 12pt; font-family: '=EF=BC=AD=EF=
=BC=B3 =EF=BC=B0=E3=82=B4=E3=82=B7=E3=83=83=E3=82=AF';"><span =
lang=3D"EN-US" style=3D"color: rgb(136, 136, 136);">&nbsp;</span><span =
lang=3D"EN-US"><o:p></o:p></span></p><pre style=3D"margin: 0mm 0mm =
0.0001pt; font-size: 12pt; font-family: '=EF=BC=AD=EF=BC=B3 =
=E3=82=B4=E3=82=B7=E3=83=83=E3=82=AF';"><span lang=3D"EN-US" =
style=3D"color: rgb(136, 136, =
136);">_______________________________________________</span><span =
lang=3D"EN-US"><o:p></o:p></span></pre><pre style=3D"margin: 0mm 0mm =
0.0001pt; font-size: 12pt; font-family: '=EF=BC=AD=EF=BC=B3 =
=E3=82=B4=E3=82=B7=E3=83=83=E3=82=AF';"><span lang=3D"EN-US" =
style=3D"color: rgb(136, 136, 136);">6tisch-security mailing =
list</span><span lang=3D"EN-US"><o:p></o:p></span></pre><pre =
style=3D"margin: 0mm 0mm 0.0001pt; font-size: 12pt; font-family: '=EF=BC=AD=
=EF=BC=B3 =E3=82=B4=E3=82=B7=E3=83=83=E3=82=AF';"><span lang=3D"EN-US" =
style=3D"color: rgb(136, 136, 136);"><a =
href=3D"mailto:6tisch-security@ietf.org" target=3D"_blank" style=3D"color:=
 purple; text-decoration: underline;"><span style=3D"color: =
purple;">6tisch-security@ietf.org</span></a></span><span =
lang=3D"EN-US"><o:p></o:p></span></pre><pre style=3D"margin: 0mm 0mm =
0.0001pt; font-size: 12pt; font-family: '=EF=BC=AD=EF=BC=B3 =
=E3=82=B4=E3=82=B7=E3=83=83=E3=82=AF';"><span lang=3D"EN-US" =
style=3D"color: rgb(136, 136, 136);"><a =
href=3D"http://cp.mcafee.com/d/2DRPoO86QmbEEKnjKOrKrhs7cFCQn1PbVJ5MsqekkSj=
hOrsuuusoLsS8QAHm0afB3ZzOVI-kfSfbCZKDtxVB_HYMC-C-MNRXBQSnSuvvovv7csJteOaqJ=
NPfaxVZicHs3jr1JwTvAm4TDNOb2pEVdTdAVPmEBC5eBYTu00U9GX33VkDa3JssDaBypuDSrza=
poSVelb4OZfIT6kONsxlK5LE2FvdTw09J55V6VI5-Aq83iSVelb4OZfIT6kONFtd46AvwxFEwt=
H4Qg9ThobTvbFzzh0Velb4Ph1jXdNBcIq8bquursodLWbv" target=3D"_blank" =
style=3D"color: purple; text-decoration: underline;"><span style=3D"color:=
 =
purple;">https://www.ietf.org/mailman/listinfo/6tisch-security</span></a><=
/span><span lang=3D"EN-US"><o:p></o:p></span></pre></blockquote><p =
class=3D"MsoNormal" style=3D"margin: 0mm 0mm 12pt; font-size: 12pt; =
font-family: '=EF=BC=AD=EF=BC=B3 =EF=BC=B0=E3=82=B4=E3=82=B7=E3=83=83=E3=82=
=AF';"><span lang=3D"EN-US" style=3D"color: rgb(136, 136, =
136);"><br><br><br></span><span lang=3D"EN-US"><o:p></o:p></span></p><pre =
style=3D"margin: 0mm 0mm 0.0001pt; font-size: 12pt; font-family: '=EF=BC=AD=
=EF=BC=B3 =E3=82=B4=E3=82=B7=E3=83=83=E3=82=AF';"><span lang=3D"EN-US" =
style=3D"color: rgb(136, 136, 136);">-- </span><span =
lang=3D"EN-US"><o:p></o:p></span></pre><pre style=3D"margin: 0mm 0mm =
0.0001pt; font-size: 12pt; font-family: '=EF=BC=AD=EF=BC=B3 =
=E3=82=B4=E3=82=B7=E3=83=83=E3=82=AF';"><span lang=3D"EN-US" =
style=3D"color: rgb(136, 136, 136);">email: <a =
href=3D"mailto:rstruik.ext@gmail.com" target=3D"_blank" style=3D"color: =
purple; text-decoration: underline;"><span style=3D"color: =
purple;">rstruik.ext@gmail.com</span></a> | Skype: rstruik</span><span =
lang=3D"EN-US"><o:p></o:p></span></pre><pre style=3D"margin: 0mm 0mm =
0.0001pt; font-size: 12pt; font-family: '=EF=BC=AD=EF=BC=B3 =
=E3=82=B4=E3=82=B7=E3=83=83=E3=82=AF';"><span lang=3D"EN-US" =
style=3D"color: rgb(136, 136, 136);">cell: <a =
href=3D"tel:%2B1%20%28647%29%20867-5658" target=3D"_blank" style=3D"color:=
 purple; text-decoration: underline;"><span style=3D"color: purple;">+1 =
(647) 867-5658</span></a> | US: <a =
href=3D"tel:%2B1%20%28415%29%20690-7363" target=3D"_blank" style=3D"color:=
 purple; text-decoration: underline;"><span style=3D"color: purple;">+1 =
(415) 690-7363</span></a></span><span =
lang=3D"EN-US"><o:p></o:p></span></pre></div><p class=3D"MsoNormal" =
style=3D"margin: 0mm 0mm 12pt; font-size: 12pt; font-family: '=EF=BC=AD=EF=
=BC=B3 =EF=BC=B0=E3=82=B4=E3=82=B7=E3=83=83=E3=82=AF';"><span =
lang=3D"EN-US"><br>_______________________________________________<br>6tis=
ch-security mailing list<br><a href=3D"mailto:6tisch-security@ietf.org" =
target=3D"_blank" style=3D"color: purple; text-decoration: =
underline;"><span style=3D"color: =
purple;">6tisch-security@ietf.org</span></a><br><a =
href=3D"http://cp.mcafee.com/d/avndzgQ93gArhoKyyVteX9KVJ5MsOCrhs7cLCQn1NEV=
hjpd79JNVVVNyZPoziiJo0E-kfSfbCPVg_oYKrSWtS7Cn-LP2rWrX37nKnjpvpVZZxZYsNORQX=
8FGT7cYG7DR8OJMddECQjt-hojuv78I9CzATsSjDdqymokWnPtU03wCHIcfBisEeRNOsGm9BWv=
pKcFBzrAVkIjbQ-Pspjb5O5mUm-waBYTu00CQknArCMnWhEwdbrAVkIjbQ-Pspjb6BQQgqh-26=
Cy1SIjh0Dt5wLtYKCed43AVkIjd45fIT6kONEwJFVVJNwSeVhsrLe-Fkd" =
target=3D"_blank" style=3D"color: purple; text-decoration: =
underline;"><span style=3D"color: =
purple;">http://cp.mcafee.com/d/avndzgQ93gArhoKyyVteX9KVJ5MsOCrhs7cLCQn1NE=
Vhjpd79JNVVVNyZPoziiJo0E-kfSfbCPVg_oYKrSWtS7Cn-LP2rWrX37nKnjpvpVZZxZYsNORQ=
X8FGT7cYG7DR8OJMddECQjt-hojuv78I9CzATsSjDdqymokWnPtU03wCHIcfBisEeRNOsGm9BW=
vpKcFBzrAVkIjbQ-Pspjb5O5mUm-waBYTu00CQknArCMnWhEwdbrAVkIjbQ-Pspjb6BQQgqh-2=
6Cy1SIjh0Dt5wLtYKCed43AVkIjd45fIT6kONEwJFVVJNwSeVhsrLe-Fkd</span></a><o:p>=
</o:p></span></p></blockquote></div><div><div style=3D"margin: 0mm 0mm =
0.0001pt; font-size: 12pt; font-family: '=EF=BC=AD=EF=BC=B3 =
=EF=BC=B0=E3=82=B4=E3=82=B7=E3=83=83=E3=82=AF';"><span =
lang=3D"EN-US"><br><br =
clear=3D"all"><br>--<o:p></o:p></span></div></div><div><div =
style=3D"margin: 0mm 0mm 0.0001pt; font-size: 12pt; font-family: '=EF=BC=AD=
=EF=BC=B3 =EF=BC=B0=E3=82=B4=E3=82=B7=E3=83=83=E3=82=AF';"><span =
lang=3D"EN-US" style=3D"font-size: 13.5pt; font-family: 'Times New =
Roman', serif;">--&nbsp;<br>Jonathan Simon, Ph. D<br>Director of Systems =
Engineering<br>Dust Networks at Linear Technology<br>30695 Huntwood =
Ave<br>Hayward, CA 94544-7021<br><a href=3D"tel:%28510%29%20400-2936" =
target=3D"_blank" style=3D"color: purple; text-decoration: =
underline;"><span style=3D"color: purple;">(510) =
400-2936</span></a><br><a href=3D"tel:%28510%29%20489-3799" =
target=3D"_blank" style=3D"color: purple; text-decoration: =
underline;"><span style=3D"color: purple;">(510) =
489-3799</span></a><span =
class=3D"apple-converted-space">&nbsp;</span>FAX<br><a =
href=3D"mailto:jsimon@linear.com" target=3D"_blank" style=3D"color: =
purple; text-decoration: underline;"><span style=3D"color: =
purple;">jsimon@linear.com</span></a></span><span =
lang=3D"EN-US"><br><br></span><span lang=3D"EN-US" style=3D"font-size: =
13.5pt; font-family: 'Times New Roman', serif;">**LINEAR =
TECHNOLOGY&nbsp;CORPORATION**&nbsp;<br>*****Internet Email =
Confidentiality&nbsp;Notice*****&nbsp;<br>&nbsp;This e-mail =
transmission, and any&nbsp;documents, files or previous =
e-mail&nbsp;messages attached to it may contain&nbsp;confidential =
information that is&nbsp;legally privileged. If you are not =
the&nbsp;intended recipient, or a person&nbsp;responsible for delivering =
it to the&nbsp;intended recipient, you are hereby&nbsp;notified that any =
disclosure, copying,&nbsp;distribution or use of any of =
the&nbsp;information contained in or attached&nbsp;to this transmission =
is STRICTLY&nbsp;PROHIBITED. If you have received this&nbsp;transmission =
in error, please&nbsp;immediately notify me by reply e-mail, or by =
telephone at<span class=3D"apple-converted-space">&nbsp;</span><a =
href=3D"tel:%28510%29%20400-2936" target=3D"_blank" style=3D"color: =
purple; text-decoration: underline;"><span style=3D"color: =
purple;">(510) 400-2936</span></a>, and destroy the =
original&nbsp;transmission and its attachments&nbsp;without reading or =
saving in any&nbsp;manner. Thank you.</span><span =
lang=3D"EN-US"><o:p></o:p></span></div></div></div></div><p =
class=3D"MsoNormal" style=3D"margin: 0mm 0mm 12pt; font-size: 12pt; =
font-family: '=EF=BC=AD=EF=BC=B3 =EF=BC=B0=E3=82=B4=E3=82=B7=E3=83=83=E3=82=
=AF';"><span =
lang=3D"EN-US"><br>_______________________________________________<br>6tis=
ch-security mailing list<br><a href=3D"mailto:6tisch-security@ietf.org" =
style=3D"color: purple; text-decoration: underline;"><span style=3D"color:=
 purple;">6tisch-security@ietf.org</span></a><br><a =
href=3D"http://cp.mcafee.com/d/2DRPow76QmbEFLzzhOM-rKrhs7cFCQn1PbVJ5Msqekk=
SjhOrsuuusoLsS8QAHm0afB3ZzOVI-kfSfbCTA7hPXPb_nVNZNBVxzHTbEzHIYYepd7bz8XBHE=
ShhlKM_OEuvkzaT0QSyrhdTV5xdVYsyMCqejtPpesRG9pxjFvdTw0e2qKMM-l9OwXn79OFoCnF=
ZCUOCmdKjBiNcLjXdNBcIn8lrxrW0GnPtU02rojhKUr1vF6y0QJKjBiNcLjXdNBcIqnjh1F7U8=
qq87qNd42tQm2ZTOWoUQgejBiNcQgk-Pspjb6y2SDDCT63rt_U2SVUlVB0" =
target=3D"_blank" style=3D"color: purple; text-decoration: =
underline;"><span style=3D"color: =
purple;">http://cp.mcafee.com/d/2DRPow76QmbEFLzzhOM-rKrhs7cFCQn1PbVJ5Msqek=
kSjhOrsuuusoLsS8QAHm0afB3ZzOVI-kfSfbCTA7hPXPb_nVNZNBVxzHTbEzHIYYepd7bz8XBH=
EShhlKM_OEuvkzaT0QSyrhdTV5xdVYsyMCqejtPpesRG9pxjFvdTw0e2qKMM-l9OwXn79OFoCn=
FZCUOCmdKjBiNcLjXdNBcIn8lrxrW0GnPtU02rojhKUr1vF6y0QJKjBiNcLjXdNBcIqnjh1F7U=
8qq87qNd42tQm2ZTOWoUQgejBiNcQgk-Pspjb6y2SDDCT63rt_U2SVUlVB0</span></a><o:p=
></o:p></span></p></blockquote></div><div><div style=3D"margin: 0mm 0mm =
0.0001pt; font-size: 12pt; font-family: '=EF=BC=AD=EF=BC=B3 =
=EF=BC=B0=E3=82=B4=E3=82=B7=E3=83=83=E3=82=AF';"><span =
lang=3D"EN-US"><br><br =
clear=3D"all"><br>--<o:p></o:p></span></div></div><div><div =
style=3D"margin: 0mm 0mm 0.0001pt; font-size: 12pt; font-family: '=EF=BC=AD=
=EF=BC=B3 =EF=BC=B0=E3=82=B4=E3=82=B7=E3=83=83=E3=82=AF';"><span =
lang=3D"EN-US" style=3D"font-size: 13.5pt; font-family: 'Times New =
Roman', serif;">--&nbsp;<br>Jonathan Simon, Ph. D<br>Director of Systems =
Engineering<br>Dust Networks at Linear Technology<br>30695 Huntwood =
Ave<br>Hayward, CA 94544-7021<br>(510) 400-2936<br>(510) 489-3799 =
FAX<br><a href=3D"mailto:jsimon@linear.com" target=3D"_blank" =
style=3D"color: purple; text-decoration: underline;"><span style=3D"color:=
 purple;">jsimon@linear.com</span></a></span><span =
lang=3D"EN-US"><br><br></span><span lang=3D"EN-US" style=3D"font-size: =
13.5pt; font-family: 'Times New Roman', serif;">**LINEAR =
TECHNOLOGY&nbsp;CORPORATION**&nbsp;<br>*****Internet Email =
Confidentiality&nbsp;Notice*****&nbsp;<br>&nbsp;This e-mail =
transmission, and any&nbsp;documents, files or previous =
e-mail&nbsp;messages attached to it may contain&nbsp;confidential =
information that is&nbsp;legally privileged. If you are not =
the&nbsp;intended recipient, or a person&nbsp;responsible for delivering =
it to the&nbsp;intended recipient, you are hereby&nbsp;notified that any =
disclosure, copying,&nbsp;distribution or use of any of =
the&nbsp;information contained in or attached&nbsp;to this transmission =
is STRICTLY&nbsp;PROHIBITED. If you have received this&nbsp;transmission =
in error, please&nbsp;immediately notify me by reply e-mail, or by =
telephone at (510) 400-2936, and destroy the original&nbsp;transmission =
and its attachments&nbsp;without reading or saving in any&nbsp;manner. =
Thank you.</span><span =
lang=3D"EN-US"><o:p></o:p></span></div></div></div><div style=3D"margin: =
0mm 0mm 0.0001pt; font-size: 12pt; font-family: '=EF=BC=AD=EF=BC=B3 =
=EF=BC=B0=E3=82=B4=E3=82=B7=E3=83=83=E3=82=AF';"><span lang=3D"EN-US" =
style=3D"font-size: 10.5pt; font-family: LucidaGrande, =
serif;">_______________________________________________<br>6tisch-security=
 mailing list<br><a href=3D"mailto:6tisch-security@ietf.org" =
style=3D"color: purple; text-decoration: underline;"><span style=3D"color:=
 purple;">6tisch-security@ietf.org</span></a><br><a =
href=3D"http://cp.mcafee.com/d/1jWVIe3zqb5QkTzhOMC-rKrhs7cFCQn1PbVJ5Msqekk=
SjhOrsuuusoLsS8QAHm0afB3ZzOVI-kfSfbCO5JtvupvW_8CzBdBBfHTbECzBdzATC7xNEVVqW=
tAklrCzB7BgY-F6lK1FJ4SyrLOb2rPUV5xcQsCXCOsVHkiP2Di-rL00s4RtxxYGjB1SKejBiNc=
LjXdNBcIrsDaBypuDSrzapoKgGT2TQ1kLCXM04S-qem7T3obZ8Qg6BJOsGm9BWvpKcFBziWq8d=
8_13jh0Xm9EwjKyMnK-nj76y1OsGm9Cy2DSrzapoQgmQYYSUMrDrkr2pAaTam" =
style=3D"color: purple; text-decoration: underline;"><span style=3D"color:=
 =
purple;">http://cp.mcafee.com/d/1jWVIe3zqb5QkTzhOMC-rKrhs7cFCQn1PbVJ5Msqek=
kSjhOrsuuusoLsS8QAHm0afB3ZzOVI-kfSfbCO5JtvupvW_8CzBdBBfHTbECzBdzATC7xNEVVq=
WtAklrCzB7BgY-F6lK1FJ4SyrLOb2rPUV5xcQsCXCOsVHkiP2Di-rL00s4RtxxYGjB1SKejBiN=
cLjXdNBcIrsDaBypuDSrzapoKgGT2TQ1kLCXM04S-qem7T3obZ8Qg6BJOsGm9BWvpKcFBziWq8=
d8_13jh0Xm9EwjKyMnK-nj76y1OsGm9Cy2DSrzapoQgmQYYSUMrDrkr2pAaTam</span></a><=
/span></div></blockquote></div></div></div></div></blockquote></div><br></=
div></body></html>=

--Apple-Mail=_EF40B035-D9C0-4787-BBD2-A45B5D246C54--


From nobody Wed May 28 16:43:36 2014
Return-Path: <mcr@sandelman.ca>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 79CDB1A0756 for <6tisch-security@ietfa.amsl.com>; Wed, 28 May 2014 16:43:33 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.542
X-Spam-Level: 
X-Spam-Status: No, score=-2.542 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RP_MATCHES_RCVD=-0.651, SPF_PASS=-0.001, T_TVD_MIME_NO_HEADERS=0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id qKHEwdNhDytG for <6tisch-security@ietfa.amsl.com>; Wed, 28 May 2014 16:43:31 -0700 (PDT)
Received: from tuna.sandelman.ca (tuna.sandelman.ca [IPv6:2607:f0b0:f:3::184]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id BACE71A079F for <6tisch-security@ietf.org>; Wed, 28 May 2014 16:43:31 -0700 (PDT)
Received: from sandelman.ca (obiwan.sandelman.ca [IPv6:2607:f0b0:f:2::247]) by tuna.sandelman.ca (Postfix) with ESMTP id F31D920028 for <6tisch-security@ietf.org>; Wed, 28 May 2014 19:46:14 -0400 (EDT)
Received: by sandelman.ca (Postfix, from userid 179) id 992FF63B0E; Wed, 28 May 2014 19:43:23 -0400 (EDT)
Received: from sandelman.ca (localhost [127.0.0.1]) by sandelman.ca (Postfix) with ESMTP id 84BC863AED for <6tisch-security@ietf.org>; Wed, 28 May 2014 19:43:23 -0400 (EDT)
From: Michael Richardson <mcr+ietf@sandelman.ca>
To: 6tisch-security@ietf.org
In-Reply-To: <674F70E5F2BE564CB06B6901FD3DD78B2723BA32@TGXML210.toshiba.local>
References: <E045AECD98228444A58C61C200AE1BD8416F3AF4@xmb-rcd-x01.cisco.com> <531DD632.2060009@cox.net> <531DDB20.5050600@gmail.com> <10925.1394631496@sandelman.ca> <532069C8.2050005@gmail.com> <23590.1394999032@sandelman.ca> <18106.1395625035@sandelman.ca> <19609.1396839403@sandelman.ca> <11557.1397444260@sandelman.ca> <28192.1398644294@sandelman.ca> <29064.1399255587@sandelman.ca> <19475.1400588783@sandelman.ca> <4903.1401158997@sandelman.ca> <53840205.2070103@gmail.com> <CAJeFcoS3PNFX2obx3uNDJDtH=QvNLmaPhw2R468sNaeqpo8QBQ@mail.gmail.com> <674F70E5F2BE564CB06B6901FD3DD78B2723B576@TGXML210.toshiba.local> <CAJeFcoQBp1A7pwZHWoesvrjSySW0UZ0k11-s3-MFAozSuR0Yrw@mail.gmail.com> <674F70E5F2BE564CB06B6901FD3DD78B2723B85A@TGXML210.toshiba.local> <1315B075-A0A5-4008-8CC9-4918F54CBED1@linear.com> <674F70E5F2BE564CB06B6901FD3DD78B2723BA32@TGXML210.toshiba.local>
X-Mailer: MH-E 8.2; nmh 1.3-dev; GNU Emacs 23.4.1
X-Face: $\n1pF)h^`}$H>Hk{L"x@)JS7<%Az}5RyS@k9X%29-lHB$Ti.V>2bi.~ehC0; <'$9xN5Ub# z!G,p`nR&p7Fz@^UXIn156S8.~^@MJ*mMsD7=QFeq%AL4m<nPbLgmtKK-5dC@#:k
MIME-Version: 1.0
Content-Type: multipart/signed; boundary="=-=-="; micalg=pgp-sha1; protocol="application/pgp-signature"
Date: Wed, 28 May 2014 19:43:23 -0400
Message-ID: <22527.1401320603@sandelman.ca>
Sender: mcr@sandelman.ca
Archived-At: http://mailarchive.ietf.org/arch/msg/6tisch-security/u1VUMc5tLTgHLB_GlIl09T3op2U
Subject: Re: [6tisch-security] agenda for 2014-05-27 6tisch security call
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 28 May 2014 23:43:33 -0000

--=-=-=


<yoshihiro.ohba@toshiba.co.jp> wrote:
    > I am not caring about an attacker to inject joining traffic, but what I
    > care is
    > an attacker attempting to destruct basic TSCH operation in the network by
    > sending forged beacons protected with the well-known key.

I think therefore, that we ought to define either:

1) that 6tisch will two sets of beacons.
   JOIN beacons might be less frequent, less capable, etc.

2) a second authentication of the extended beacon, under the runtime-key,
   could be done.  It can't be verified by nodes that don't have the
   runtime-key, but as it would be authentication only, that's okay.

--
Michael Richardson <mcr+IETF@sandelman.ca>, Sandelman Software Works
 -= IPv6 IoT consulting =-




--=-=-=
Content-Type: application/pgp-signature

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iQEVAwUBU4Z0mYCLcPvd0N1lAQIb5Qf+J9PUdrcyBmDYsI/KeuNb0LCp0WENbHd7
Y3ke8fFDjuF8MB+MQbPSm3JcrMpApjXdpQaNA7nr6TU0/rK40wkQXTbome9+d3Zf
rqmXuZDg5RmHtXbwXO7kLeCduWTSu2Fhww16tMQuDxwBGfdIA8gfynrHQ+p+tJhV
i7OXPyNIZEI1CoxEk2TOaebTukNxEs3Ltq0nNTJS4b2mzUNHjMfm+zL0u2T0pJke
cK2YcVlzt1/z/WEPW3LHSylf3KZQ9nc2VC3zXz9GvYgHF6+SjK1HRCLskzXOlj9Y
1ZZjVwZYiSloaPYuRl3QS/ionyArGLNAWN3snLSzjGFNpeWSLy795A==
=fTfc
-----END PGP SIGNATURE-----
--=-=-=--


From nobody Wed May 28 16:43:49 2014
Return-Path: <yoshihiro.ohba@toshiba.co.jp>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id AE0471A0756 for <6tisch-security@ietfa.amsl.com>; Wed, 28 May 2014 16:43:45 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -0.352
X-Spam-Level: 
X-Spam-Status: No, score=-0.352 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HELO_EQ_JP=1.244, HOST_EQ_JP=1.265, HTML_MESSAGE=0.001, HTTPS_HTTP_MISMATCH=1.989, RCVD_IN_DNSWL_MED=-2.3, RP_MATCHES_RCVD=-0.651, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001, UNPARSEABLE_RELAY=0.001, WEIRD_PORT=0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id HmOFMMUGOjdx for <6tisch-security@ietfa.amsl.com>; Wed, 28 May 2014 16:43:40 -0700 (PDT)
Received: from imx2.toshiba.co.jp (inet-tsb5.toshiba.co.jp [202.33.96.24]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 3AC2E1A079F for <6tisch-security@ietf.org>; Wed, 28 May 2014 16:43:39 -0700 (PDT)
Received: from arc1.toshiba.co.jp ([133.199.194.235]) by imx2.toshiba.co.jp  with ESMTP id s4SNhWjk007810; Thu, 29 May 2014 08:43:32 +0900 (JST)
Received: (from root@localhost) by arc1.toshiba.co.jp  id s4SNhWur019564; Thu, 29 May 2014 08:43:32 +0900 (JST)
Received: from unknown [133.199.192.144]  by arc1.toshiba.co.jp with ESMTP id JAA19563; Thu, 29 May 2014 08:43:32 +0900
Received: from mx11.toshiba.co.jp (localhost [127.0.0.1]) by ovp2.toshiba.co.jp  with ESMTP id s4SNhV0a028735; Thu, 29 May 2014 08:43:32 +0900 (JST)
Received: from TGXML208.toshiba.local by toshiba.co.jp id s4SNhVWG010895; Thu, 29 May 2014 08:43:31 +0900 (JST)
Received: from TGXML210.toshiba.local ([169.254.4.46]) by TGXML208.toshiba.local ([133.199.70.17]) with mapi id 14.03.0181.006; Thu, 29 May 2014 08:43:31 +0900
From: <yoshihiro.ohba@toshiba.co.jp>
To: <jsimon@linear.com>
Thread-Topic: [6tisch-security] agenda for 2014-05-27 6tisch security call
Thread-Index: AQHPeVZhw54BHDP0SE+00Qrnll9n8JtTKLqAgACwMoCAAayJwP//+QQAgACYY+D//3fFAIABEy3g//9xb4AAEtR88A==
Date: Wed, 28 May 2014 23:43:31 +0000
Message-ID: <674F70E5F2BE564CB06B6901FD3DD78B2723BA70@TGXML210.toshiba.local>
References: <E045AECD98228444A58C61C200AE1BD8416F3AF4@xmb-rcd-x01.cisco.com> <531DD632.2060009@cox.net> <531DDB20.5050600@gmail.com> <10925.1394631496@sandelman.ca> <532069C8.2050005@gmail.com> <23590.1394999032@sandelman.ca> <18106.1395625035@sandelman.ca> <19609.1396839403@sandelman.ca> <11557.1397444260@sandelman.ca> <28192.1398644294@sandelman.ca> <29064.1399255587@sandelman.ca> <19475.1400588783@sandelman.ca> <4903.1401158997@sandelman.ca> <53840205.2070103@gmail.com> <CAJeFcoS3PNFX2obx3uNDJDtH=QvNLmaPhw2R468sNaeqpo8QBQ@mail.gmail.com> <674F70E5F2BE564CB06B6901FD3DD78B2723B576@TGXML210.toshiba.local> <CAJeFcoQBp1A7pwZHWoesvrjSySW0UZ0k11-s3-MFAozSuR0Yrw@mail.gmail.com> <674F70E5F2BE564CB06B6901FD3DD78B2723B85A@TGXML210.toshiba.local> <1315B075-A0A5-4008-8CC9-4918F54CBED1@linear.com> <674F70E5F2BE564CB06B6901FD3DD78B2723BA32@TGXML210.toshiba.local> <B9D502BD-C500-41E0-BA31-5BCD72090432@linear.com>
In-Reply-To: <B9D502BD-C500-41E0-BA31-5BCD72090432@linear.com>
Accept-Language: ja-JP, en-US
Content-Language: ja-JP
x-originating-ip: [133.196.20.156]
msscp.transfermailtomossagent: 103
Content-Type: multipart/alternative; boundary="_000_674F70E5F2BE564CB06B6901FD3DD78B2723BA70TGXML210toshiba_"
MIME-Version: 1.0
Archived-At: http://mailarchive.ietf.org/arch/msg/6tisch-security/fyuDR2TlIXLOXU4ty155wmz-ddw
Cc: mcr+ietf@sandelman.ca, rstruik.ext@gmail.com, 6tisch-security@ietf.org
Subject: Re: [6tisch-security] agenda for 2014-05-27 6tisch security call
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 28 May 2014 23:43:45 -0000

--_000_674F70E5F2BE564CB06B6901FD3DD78B2723BA70TGXML210toshiba_
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: base64

WWVzLg0KDQpZb3NoaWhpcm8gT2hiYQ0KDQpGcm9tOiBKb25hdGhhbiBTaW1vbiBbbWFpbHRvOmpz
aW1vbkBsaW5lYXIuY29tXQ0KU2VudDogVGh1cnNkYXksIE1heSAyOSwgMjAxNCA4OjQyIEFNDQpU
bzogb2hiYSB5b3NoaWhpcm8o5aSn5aC0IOe+qea0iyDil4vvvLLvvKTvvKPilqHvvK7vvLPvvKwp
DQpDYzogbWNyK2lldGZAc2FuZGVsbWFuLmNhOyByc3RydWlrLmV4dEBnbWFpbC5jb207IDZ0aXNj
aC1zZWN1cml0eUBpZXRmLm9yZw0KU3ViamVjdDogUmU6IFs2dGlzY2gtc2VjdXJpdHldIGFnZW5k
YSBmb3IgMjAxNC0wNS0yNyA2dGlzY2ggc2VjdXJpdHkgY2FsbA0KDQpUaGVuIGFzIGxvbmcgYXMg
ZWl0aGVyDQphKSBCZWFjb25zIGFyZSBvbmx5IHVzZWQgZm9yIGFkdmVydGlzaW5nIGEgbmV0d29y
ayB0byB1bnN5Y2hyb25pemVkIGRldmljZXMsIG9yDQpiKSBEZXZpY2VzIG9ubHkgdGFrZSB0aW1p
bmcgaW5mb3JtYXRpb24gKHRpbWUgb2YgYXJyaXZhbCkgZnJvbSBiZWFjb25zIGNvbWluZyBmcm9t
IHRpbWUgcGFyZW50cyBhbmQgYXV0aGVudGljYXRlZCB3aXRoIHRoZSBydW4tdGltZSBrZXkNCnlv
dSBhcmUgZ29vZC4NCg0KDQotLQ0KSm9uYXRoYW4gU2ltb24sIFBoLiBEDQpEaXJlY3RvciBvZiBT
eXN0ZW1zIEVuZ2luZWVyaW5nDQpMaW5lYXIgVGVjaG5vbG9neSwgRHVzdCBOZXR3b3JrcyBwcm9k
dWN0IGdyb3VwDQozMDY5NSBIdW50d29vZCBBdmUNCkhheXdhcmQsIENBIDk0NTQ0LTcwMjENCig1
MTApIDQwMC0yOTM2DQooNTEwKSA0ODktMzc5OSBGQVgNCmpzaW1vbkBsaW5lYXIuY29tPG1haWx0
bzpqc2ltb25AbGluZWFyLmNvbT4NCg0KKipMSU5FQVIgVEVDSE5PTE9HWSBDT1JQT1JBVElPTioq
DQoqKioqKkludGVybmV0IEVtYWlsIENvbmZpZGVudGlhbGl0eSBOb3RpY2UqKioqKg0KIFRoaXMg
ZS1tYWlsIHRyYW5zbWlzc2lvbiwgYW5kIGFueSBkb2N1bWVudHMsIGZpbGVzIG9yIHByZXZpb3Vz
IGUtbWFpbCBtZXNzYWdlcyBhdHRhY2hlZCB0byBpdCBtYXkgY29udGFpbiBjb25maWRlbnRpYWwg
aW5mb3JtYXRpb24gdGhhdCBpcyBsZWdhbGx5IHByaXZpbGVnZWQuIElmIHlvdSBhcmUgbm90IHRo
ZSBpbnRlbmRlZCByZWNpcGllbnQsIG9yIGEgcGVyc29uIHJlc3BvbnNpYmxlIGZvciBkZWxpdmVy
aW5nIGl0IHRvIHRoZSBpbnRlbmRlZCByZWNpcGllbnQsIHlvdSBhcmUgaGVyZWJ5IG5vdGlmaWVk
IHRoYXQgYW55IGRpc2Nsb3N1cmUsIGNvcHlpbmcsIGRpc3RyaWJ1dGlvbiBvciB1c2Ugb2YgYW55
IG9mIHRoZSBpbmZvcm1hdGlvbiBjb250YWluZWQgaW4gb3IgYXR0YWNoZWQgdG8gdGhpcyB0cmFu
c21pc3Npb24gaXMgU1RSSUNUTFkgUFJPSElCSVRFRC4gSWYgeW91IGhhdmUgcmVjZWl2ZWQgdGhp
cyB0cmFuc21pc3Npb24gaW4gZXJyb3IsIHBsZWFzZSBpbW1lZGlhdGVseSBub3RpZnkgbWUgYnkg
cmVwbHkgZS1tYWlsLCBvciBieSB0ZWxlcGhvbmUgYXQgKDUxMCkgNDAwLTI5MzYsIGFuZCBkZXN0
cm95IHRoZSBvcmlnaW5hbCB0cmFuc21pc3Npb24gYW5kIGl0cyBhdHRhY2htZW50cyB3aXRob3V0
IHJlYWRpbmcgb3Igc2F2aW5nIGluIGFueSBtYW5uZXIuIFRoYW5rIHlvdS4NCg0KT24gTWF5IDI4
LCAyMDE0LCBhdCA0OjE5IFBNLCA8eW9zaGloaXJvLm9oYmFAdG9zaGliYS5jby5qcDxtYWlsdG86
eW9zaGloaXJvLm9oYmFAdG9zaGliYS5jby5qcD4+IDx5b3NoaWhpcm8ub2hiYUB0b3NoaWJhLmNv
LmpwPG1haWx0bzp5b3NoaWhpcm8ub2hiYUB0b3NoaWJhLmNvLmpwPj4gd3JvdGU6DQoNCg0KSGkg
Sm9uYXRoYW4sDQoNCkkgYW0gbm90IGNhcmluZyBhYm91dCBhbiBhdHRhY2tlciB0byBpbmplY3Qg
am9pbmluZyB0cmFmZmljLCBidXQgd2hhdCBJIGNhcmUgaXMgYW4gYXR0YWNrZXIgYXR0ZW1wdGlu
ZyB0byBkZXN0cnVjdCBiYXNpYyBUU0NIIG9wZXJhdGlvbiBpbiB0aGUgbmV0d29yayBieSBzZW5k
aW5nIGZvcmdlZCBiZWFjb25zIHByb3RlY3RlZCB3aXRoIHRoZSB3ZWxsLWtub3duIGtleS4NCg0K
WW9zaGloaXJvIE9oYmENCg0KDQoNCkZyb206IDZ0aXNjaC1zZWN1cml0eSBbbWFpbHRvOjZ0aXNj
aC1zZWN1cml0eS1ib3VuY2VzQGlldGYub3JnXSBPbiBCZWhhbGYgT2YgSm9uYXRoYW4gU2ltb24N
ClNlbnQ6IFRodXJzZGF5LCBNYXkgMjksIDIwMTQgMTI6NDcgQU0NClRvOiBvaGJhIHlvc2hpaGly
byjlpKfloLQg576p5rSLIOKXi++8su+8pO+8o+KWoe+8ru+8s++8rCkNCkNjOiBtY3IraWV0ZkBz
YW5kZWxtYW4uY2E8bWFpbHRvOm1jcitpZXRmQHNhbmRlbG1hbi5jYT47IHJzdHJ1aWsuZXh0QGdt
YWlsLmNvbTxtYWlsdG86cnN0cnVpay5leHRAZ21haWwuY29tPjsgNnRpc2NoLXNlY3VyaXR5QGll
dGYub3JnPG1haWx0bzo2dGlzY2gtc2VjdXJpdHlAaWV0Zi5vcmc+DQpTdWJqZWN0OiBSZTogWzZ0
aXNjaC1zZWN1cml0eV0gYWdlbmRhIGZvciAyMDE0LTA1LTI3IDZ0aXNjaCBzZWN1cml0eSBjYWxs
DQoNCllvc2hpaGlybyAtDQoNCkkgZG9u4oCZdCB0aGluayB0aGlzIGlzIGEgcHJvYmxlbS4gIE5v
ZGVzIHRoYXQgYXJlIGluIHRoZSBuZXR3b3JrIHJlamVjdCBpbmNvbWluZyBmcmFtZXMgc2VjdXJl
ZCB3aXRoIHRoZSB3ZWxsLWtub3duIGtleS4gVGhlIHdlbGwta25vd24ga2V5IGlzIG9ubHkgdXNl
ZCB0byBhdXRoZW50aWNhdGUgYmVhY29ucywgYW5kIGF1dGhlbnRpY2F0ZSBqb2luIHJlcXVlc3Rz
ICh3aGljaCBkb27igJl0IGNhcnJ5IHN5bmNocm9uaXphdGlvbiBpbmZvcm1hdGlvbikuICBUaGVy
ZSBpcyBhIERvUyB2ZWN0b3IsIGluIHRoYXQgYW4gYXR0YWNrZXIgY2FuIGluamVjdCBqb2luaW5n
IHRyYWZmaWMgKGRlc3RpbmVkIGZvciB0aGUgbmV0d29yayBtYW5hbmFnZXIpIHRoYXQgd2lsbCB1
bHRpbWF0ZWx5IGJlIGRpc2NhcmRlZCwgcG9zc2libHkgcHJldmVudGluZyBvdGhlciBub2RlcyBm
cm9tIGpvaW5pbmcsIGFuZCBpbmNyZWFzaW5nIHRoZSB0cmFmZmljIGluIHRoZSBuZXR3b3JrLg0K
DQpKb25hdGhhbiBTaW1vbiwgUGguIEQNCkRpcmVjdG9yIG9mIFN5c3RlbXMgRW5naW5lZXJpbmcN
CkxpbmVhciBUZWNobm9sb2d5LCBEdXN0IE5ldHdvcmtzIHByb2R1Y3QgZ3JvdXANCjMwNjk1IEh1
bnR3b29kIEF2ZQ0KSGF5d2FyZCwgQ0EgOTQ1NDQtNzAyMQ0KKDUxMCkgNDAwLTI5MzYNCig1MTAp
IDQ4OS0zNzk5IEZBWA0KanNpbW9uQGxpbmVhci5jb208bWFpbHRvOmpzaW1vbkBsaW5lYXIuY29t
Pg0KDQoqKkxJTkVBUiBURUNITk9MT0dZIENPUlBPUkFUSU9OKioNCioqKioqSW50ZXJuZXQgRW1h
aWwgQ29uZmlkZW50aWFsaXR5IE5vdGljZSoqKioqDQogVGhpcyBlLW1haWwgdHJhbnNtaXNzaW9u
LCBhbmQgYW55IGRvY3VtZW50cywgZmlsZXMgb3IgcHJldmlvdXMgZS1tYWlsIG1lc3NhZ2VzIGF0
dGFjaGVkIHRvIGl0IG1heSBjb250YWluIGNvbmZpZGVudGlhbCBpbmZvcm1hdGlvbiB0aGF0IGlz
IGxlZ2FsbHkgcHJpdmlsZWdlZC4gSWYgeW91IGFyZSBub3QgdGhlIGludGVuZGVkIHJlY2lwaWVu
dCwgb3IgYSBwZXJzb24gcmVzcG9uc2libGUgZm9yIGRlbGl2ZXJpbmcgaXQgdG8gdGhlIGludGVu
ZGVkIHJlY2lwaWVudCwgeW91IGFyZSBoZXJlYnkgbm90aWZpZWQgdGhhdCBhbnkgZGlzY2xvc3Vy
ZSwgY29weWluZywgZGlzdHJpYnV0aW9uIG9yIHVzZSBvZiBhbnkgb2YgdGhlIGluZm9ybWF0aW9u
IGNvbnRhaW5lZCBpbiBvciBhdHRhY2hlZCB0byB0aGlzIHRyYW5zbWlzc2lvbiBpcyBTVFJJQ1RM
WSBQUk9ISUJJVEVELiBJZiB5b3UgaGF2ZSByZWNlaXZlZCB0aGlzIHRyYW5zbWlzc2lvbiBpbiBl
cnJvciwgcGxlYXNlIGltbWVkaWF0ZWx5IG5vdGlmeSBtZSBieSByZXBseSBlLW1haWwsIG9yIGJ5
IHRlbGVwaG9uZSBhdCAoNTEwKSA0MDAtMjkzNiwgYW5kIGRlc3Ryb3kgdGhlIG9yaWdpbmFsIHRy
YW5zbWlzc2lvbiBhbmQgaXRzIGF0dGFjaG1lbnRzIHdpdGhvdXQgcmVhZGluZyBvciBzYXZpbmcg
aW4gYW55IG1hbm5lci4gVGhhbmsgeW91Lg0KDQpPbiBNYXkgMjgsIDIwMTQsIGF0IDg6MDEgQU0s
IDx5b3NoaWhpcm8ub2hiYUB0b3NoaWJhLmNvLmpwPG1haWx0bzp5b3NoaWhpcm8ub2hiYUB0b3No
aWJhLmNvLmpwPj4gPHlvc2hpaGlyby5vaGJhQHRvc2hpYmEuY28uanA8bWFpbHRvOnlvc2hpaGly
by5vaGJhQHRvc2hpYmEuY28uanA+PiB3cm90ZToNCg0KDQoNCkhpIEpvbmF0aGFuLA0KDQpUaGFu
ayB5b3UgZm9yIHlvdXIgYW5zd2VyLg0KDQpJIHRoaW5rIHRoaXMgY2FuIGJlIGFuIGlzc3VlIGlm
IGFscmVhZHkgam9pbmVkIG5vZGVzIGFsc28gdXNlIHRoZSBiZWFjb25zIHByb3RlY3RlZCB3aXRo
IHRoZSB3ZWxsLWtub3duIGtleSBmb3IgbWFpbnRhaW5pbmcgc3luY2hyb25pemF0aW9uIGFuZCBz
bG90IGFsbG9jYXRpb25zLCBhcyBhbiBhdHRhY2tlciBjYW4gc2VuZCBmb3JnZWQgYmVhY29ucyBw
cm90ZWN0ZWQgd2l0aCB0aGUgd2VsbC1rbm93biBrZXkuDQoNCllvc2hpaGlybyBPaGJhDQoNCg0K
RnJvbTogNnRpc2NoLXNlY3VyaXR5IFttYWlsdG86NnRpc2NoLXNlY3VyaXR5LWJvdW5jZXNAaWV0
Zi5vcmddIE9uIEJlaGFsZiBPZiBKb25hdGhhbiBTaW1vbg0KU2VudDogV2VkbmVzZGF5LCBNYXkg
MjgsIDIwMTQgMTE6NDkgUE0NClRvOiBvaGJhIHlvc2hpaGlybyjlpKfloLQg576p5rSLIOKXi++8
su+8pO+8o+KWoe+8ru+8s++8rCkNCkNjOiBNaWNoYWVsIFJpY2hhcmRzb247IFJlbmUgU3RydWlr
OyA2dGlzY2gtc2VjdXJpdHlAaWV0Zi5vcmc8bWFpbHRvOjZ0aXNjaC1zZWN1cml0eUBpZXRmLm9y
Zz4NClN1YmplY3Q6IFJlOiBbNnRpc2NoLXNlY3VyaXR5XSBhZ2VuZGEgZm9yIDIwMTQtMDUtMjcg
NnRpc2NoIHNlY3VyaXR5IGNhbGwNCg0KWW9zaGloaXJvIC0NCg0KUS4gSW4gdy9IQVJULCBhcmUg
YWxsIGJlYWNvbiBmcmFtZXMgYXV0aGVudGljYXRlZCB3aXRoIGEgd2VsbC1rbm93biBrZXkgZXZl
biBhZnRlciBhIGpvaW5pbmcgbm9kZSBvYnRhaW5lZCB0aGUgcnVudGltZSBsaW5rIGxheWVyIGtl
eT8NCkEuIFllcy4gSW4gV2lyZWxlc3NIQVJUIHRoZSBiZWFjb25zIChjYWxsZWQgImFkdmVydGlz
ZW1lbnRzIiBidXQgdGhleSBzZXJ2ZSB0aGUgc2FtZSBwdXJwb3NlIGFuZCBoYXZlIHNpbWlsYXIg
Y29udGVudCkgYXJlIGludGVuZGVkIGZvciBkZXZpY2VzIG5vdCB5ZXQgaW4gdGhlIG5ldHdvcmss
IHNvIHRoZXkgYWx3YXlzIHVzZSB0aGUgd2VsbC1rbm93biBrZXkuICBUbyBkaXNjb3ZlciBvdGhl
ciBub2RlcyB3aXRoaW4gdGhlIG5ldHdvcmssIHRoZXkgdXNlIGZyYW1lcyBzZWN1cmVkIHdpdGgg
dGhlIHJ1bnRpbWUgbGluay1sYXllciBrZXkuDQpKb25hdGhhbg0KDQpPbiBUdWUsIE1heSAyNywg
MjAxNCBhdCAxMToxOCBQTSwgPHlvc2hpaGlyby5vaGJhQHRvc2hpYmEuY28uanA8bWFpbHRvOnlv
c2hpaGlyby5vaGJhQHRvc2hpYmEuY28uanA+PiB3cm90ZToNCkhpIEpvbmF0aGFuLA0KDQpUaGFu
ayB5b3UgZm9yIHNlbmRpbmcgdGhlIHN1bW1hcnkgb2Ygdy9IQVJUIGpvaW5pbmcuDQoNCkkgaGF2
ZSBxdWVzdGlvbi4NCg0KSW4gdy9IQVJULCBhcmUgYWxsIGJlYWNvbiBmcmFtZXMgYXV0aGVudGlj
YXRlZCB3aXRoIGEgd2VsbC1rbm93biBrZXkgZXZlbiBhZnRlciBhIGpvaW5pbmcgbm9kZSBvYnRh
aW5lZCB0aGUgcnVudGltZSBsaW5rIGxheWVyIGtleT8NCg0KUmVnYXJkcywNCllvc2hpaGlybyBP
aGJhDQoNCg0KDQoNCkZyb206IDZ0aXNjaC1zZWN1cml0eSBbbWFpbHRvOjZ0aXNjaC1zZWN1cml0
eS1ib3VuY2VzQGlldGYub3JnPG1haWx0bzo2dGlzY2gtc2VjdXJpdHktYm91bmNlc0BpZXRmLm9y
Zz5dIE9uIEJlaGFsZiBPZiBKb25hdGhhbiBTaW1vbg0KU2VudDogVHVlc2RheSwgTWF5IDI3LCAy
MDE0IDEwOjQxIFBNDQpUbzogUmVuZSBTdHJ1aWsNCkNjOiBNaWNoYWVsIFJpY2hhcmRzb247IDZ0
aXNjaC1zZWN1cml0eUBpZXRmLm9yZzxtYWlsdG86NnRpc2NoLXNlY3VyaXR5QGlldGYub3JnPg0K
U3ViamVjdDogUmU6IFs2dGlzY2gtc2VjdXJpdHldIGFnZW5kYSBmb3IgMjAxNC0wNS0yNyA2dGlz
Y2ggc2VjdXJpdHkgY2FsbA0KDQpSZW5lIGhhZCBhc2tlZCBvbiBhIHByZXZpb3VzIGNhbGwgZm9y
IHNvbWVvbmUgdG8gc3VtbWFyaXplIFdpcmVsZXNzSEFSVCBqb2luaW5nIC0gaGVyZSB5b3UgZ28u
DQoNCiogT25lIG9yIG1vcmUgZGV2aWNlcyBhcmUgc2VuZGluZyBiZWFjb25zIHRvIGFkdmVydGlz
ZSB0aGUgcHJlc2VuY2Ugb2YgdGhlIG5ldHdvcmsuIEluIFdpcmVsZXNzSEFSVCwgdGhpcyBmcmFt
ZSBpcyB1bmVuY3J5cHRlZCwgYnV0IGF1dGhlbnRpY2F0ZWQgd2l0aCBhIHdlbGwga25vd24ga2V5
LiAgVGhlIGJlYWNvbiBjb250YWlucyB0aGUgY3VycmVudCBBU04sIHdoaWNoIHRoZSBqb2luaW5n
IGRldmljZSB1c2VzIHRvIHN5bmNocm9uaXplIGl0cyBjbG9jay4NCiogT25jZSB0aGUgam9pbmlu
ZyBub2RlIGhhcyBoZWFyZCBhIGJlYWNvbiwgaXQgY29udGludWVzIGxpc3RlbmluZyBmb3IgYWRk
aXRpb25hbCBiZWFjb25zIGZvciBhIHNob3J0IHNwZWNpZmllZCB0aW1lb3V0Lg0KKiBUaGUgam9p
bmluZyBub2RlIGVuY3J5cHRzIGEgZnJhbWUgY29udGFpbmluZyBzb21lIEhBUlQgc3BlY2lmaWMg
Y29udGVudCwgaW5jbHVkaW5nIGEgbGlzdCBvZiBiZWFjb25pbmcgbmVpZ2hib3JzIGl0IGhlYXJk
IGluIHRoZSBwcmV2aW91cyBzdGVwcy4gVGhlIHNpemUgb2YgdGhlIHBheWxvYWQgaXMgfiA2MCBi
eXRlcy4gIFRoZSBwYWNrZXQgaXMgcm91dGVkIGJ5IGEgInByb3h5IiBub2RlIC0gdGhlIGpvaW5p
bmcgcGFyZW50LiBUaGUgZnJhbWUgaXMgYXV0aGVudGljYXRlZCB1c2luZyB0aGUgd2VsbC1rbm93
biBrZXksIGFuZCBlbmNyeXB0ZWQgdXNpbmcgYSBzaGFyZWQgc3ltbWV0cmljIGtleSBrbm93biBv
bmx5IGJ5IHRoZSBub2RlIGFuZCB0aGUgbWFuYWdlci4NCg0KKiBUaGUgbWFuYWdlciByZXNwb25k
cyB3aXRoIGEgZnJhbWUgY29udGFpbmluZyB0aGUgcnVuLXRpbWUgbGluay1sYXllciBrZXksIHRo
ZSBub2RlJ3MgbmV3IHNob3J0IGFkZHJlc3MgKHRoaXMgdGFrZXMgdGhlIHBsYWNlIG9mIFBBTiBj
b29yZGluYXRvciBhc3NvY2lhdGlvbiksIGFuZCBhIHVuaWNhc3Qgc2Vzc2lvbiBrZXkgYW5kIHN0
YXJ0aW5nIG5vbmNlIGZvciB0aGUgbWFuYWdlci4gVGhpcyBmcmFtZSBpcyBlbmNyeXB0ZWQgd2l0
aCB0aGUgc3ltbWV0cmljIGtleS4gVGhlIHBheWxvYWQgaXMgfiA2MCBieXRlcywgYW5kIGlzIHJv
dXRlZCB0byB0aGUgcHJveHkgZm9yIGRlbGl2ZXJ5IHRvIHRoZSBqb2luaW5nIG5vZGUgLSB0aGUg
cHJveHkgdXNlcyB0aGUgbGluay1sYXllciB3ZWxsIGtub3duIGtleSBvbiB0aGUgZnJhbWUuDQoq
IEF0IHRoaXMgcG9pbnQgdGhlIGpvaW5pbmcgbm9kZSB0cmFuc2l0aW9ucyB0byB1c2luZyB0aGUg
cnVuLXRpbWUgbGluay1sYXllciBrZXkgZm9yIGFsbCBsaW5rLWxheWVyIGZyYW1lcywgYW5kIHRo
ZSBtYW5hZ2VyIHVuaWNhc3Qgc2Vzc2lvbiBmb3IgZW5kLXRvLWVuZCBtYW5hZ2VyIHRyYWZmaWMu
IFRoaXMgZW5kcyB0aGUgaW5pdGlhbCBzZWN1cml0eSBoYW5kc2hha2UuDQoqIE92ZXIgYSBudW1i
ZXIgb2YgYWRkaXRpb25hbCBmcmFtZXMsIHRoZSBtYW5hZ2VyIGFzc2lnbnMgYWRkaXRpb25hbCBz
ZXNzaW9ucywgaW5jbHVkaW5nIGJyb2FkY2FzdCBzZXNzaW9ucywgYW5kIGEgdW5pY2FzdCBzZXNz
aW9uIHRvIHRoZSBHYXRld2F5IChzaW5rIGZvciBhbGwgZGF0YSB0cmFmZmljKSwgYW5kIGFkZGl0
aW9uYWwgY29tbXVuaWNhdGlvbnMgcmVzb3VyY2VzLCByb3V0aW5nIGluZm9ybWF0aW9uLCBldGMu
ICBUaGVyZSBpcyBubyBleHBsaWNpdCB0cmFuc2l0aW9uIGZyb20gam9pbmluZyB0byBqb2luZWQg
LSB0aGUgbW90ZSB0cmFuc2l0aW9ucyB3aGVuIGNlcnRhaW4ga2V5IGZyYW1lcyBhcmUgcmVjZWl2
ZWQuDQoqIE5vdGUgdGhhdCBhIFdpcmVsZXNzSEFSVCBsaW5rLWxheWVyIGZyYW1lIGNvbnRhaW5z
IGFuZCBhZGRpdGlvbmFsIGZyYW1lIHR5cGUgYnl0ZSBhbmQgYSA0LWJ5dGUgbGluay1sYXllciBN
SUMsIG9uIHRvcCBvZiB0aGUgdW5zZWN1cmVkIDE1LjQgZnJhbWUuICBBIG5ldHdvcmsgZnJhbWUg
Y29udGFpbnMgYW4gYWRkaXRpb25hbCAxNi00MCBieXRlcyBvZiBhZGRyZXNzaW5nLCByb3V0aW5n
LCBzZWN1cml0eSBhbmQgb3RoZXIgaW5mb3JtYXRpb24uDQpIb3BlIHRoaXMgaGVscCENCkpvbmF0
aGFuDQoNCg0KT24gTW9uLCBNYXkgMjYsIDIwMTQgYXQgODowOSBQTSwgUmVuZSBTdHJ1aWsgPHJz
dHJ1aWsuZXh0QGdtYWlsLmNvbTxtYWlsdG86cnN0cnVpay5leHRAZ21haWwuY29tPj4gd3JvdGU6
DQpIaSBNaWNoYWVsOg0KDQpJIHdvdWxkIGxpa2UgdG8gZGlzY3VzcyB0aGUgb3V0c3RhbmRpbmcg
aXNzdWVzIEkgc3VtbWFyaXplZCBpbiBteSBlbWFpbCBvZiBUdWUgbGFzdCB3ZWVrLCBNYXkgMjAs
IDIwMTQsIDk6NDVhbSBFRFQgKHNlZSBodHRwOi8vd3d3LmlldGYub3JnL21haWwtYXJjaGl2ZS93
ZWIvNnRpc2NoLXNlY3VyaXR5L2N1cnJlbnQvbXNnMDAwODYuaHRtbDxodHRwOi8vY3AubWNhZmVl
LmNvbS9kLzVmSENNVXA0MUVTeU50NTVPV3RTanRQcWJ3VkJjU3lVZXB2ZEVLM3poT3lDT3FlanJ6
UFBQejVYQ042QUJxTTFoWUV2SXVuZERPeC1OVnNUSlFYSWZjTFp2QzRUUVRTNmVMc0tDTy1QUFhY
M1hVVnpCSEZTaGpsS2VwVmtmZkdoQnJ3cXJoZEk2WFl5TUNZLWVob2pkNzlLVkkwNWJWS1kwMU1q
Ylg2TmVoRFkwNXpBVmtJamJRLVBzcGpicHBLY3Z4ZjVxNHJUS1lWTWVkS2pCaU5jTGpYZE5CY0lu
OGxyeHJXMEduUHRVMDJyaGh1aEtyMXZGNnkwUUpLakJpTmNMalhkTkJjSXFuamgxRjdVOHFxODdx
TmQ0MnRRbTJaVE9Xb1VRZ2VqQmlOY1Fnay1Qc3BqYjZ5MlNERENUNjNwT19vPikuIFRoaXMgd2Fz
IGFsc28gb25lIG9mIHRoZSBhY3Rpb24gaXRlbXMgYXQgdGhlIGNvbmNsdXNpb24gb2YgbGFzdCB3
ZWVrJ3MgNlRpU0NIIHNlY3VyaXR5IGNhbGwuDQoNCkZZSSAtIHRoZSB3L0hBUlQgY29tbXVuaWNh
dGlvbiBmbG93cyB3ZXJlIGRpc2N1c3NlZCBkdXJpbmcgdGhlIDZUaVNDSCBzZWN1cml0eSBjb25m
IGNhbGwgdGhlIHdlZWsgYmVmb3JlLCBvbiBNb24gTWF5IDEyLCAyMDE0LiBJZiBvbmUgd2lzaGVz
IHRvIGdvIG92ZXIgdGhpcyBhZ2FpbiwgdGhhdCBpcyBmaW5lLCBidXQgSSB3b3VsZCBwcmVmZXIg
dXMgZ2l2aW5nIHByZWZlcmVuY2UgdG8gdGFraW5nIG9uIGFscmVhZHkgYXJ0aWN1bGF0ZWQgaXNz
dWVzICh3aGljaCB3ZXJlIGFzc2lnbmVkIGFzIGhvbWV3b3JrIGFzc2lnbm1lbnQgdG8gcmVmbGVj
dCB1cG9uKSBmaXJzdCAoaS5lLiwgcHJpb3IgdG8gaXRlbSAjNCBvZiB0aGUgcHJvcG9zZWQgYWdl
bmRhKS4NCg0KQXMgYW5vdGhlciBhZ2VuZGEgcG9pbnQsIEkgd291bGQgbGlrZSB1cyB0byBkaXNj
dXNzIHRoZSBmcmVxdWVuY3kgb2YgZnV0dXJlIGNhbGxzIChhcyBwYXJ0IG9mIEVPQikuDQoNCkJl
c3QgcmVnYXJkcywgUmVuZQ0KDQoNCk9uIDUvMjYvMjAxNCAxMDo0OSBQTSwgTWljaGFlbCBSaWNo
YXJkc29uIHdyb3RlOg0KDQpUbyByZW1pbmQsIHdlIG1vdmVkIHRoZSBjYWxsIGZyb20gdGhlIDI2
dGggdG8gdGhlIDI3dGggYXQgMTBhbSBFRFQuDQoNClRoYXQncyA5MCBtaW51dGVzIGZyb20gdGhp
cyBlbWFpbC4NCg0KDQoNCjEpIG5vdGV3ZWxsLg0KDQoyKSBpbnRyb3MNCg0KMykgcmVjYXAgb2Yg
ZHJhZnQtcGlyby0NCg0KNCkgd2lyZWxlc3NoYXJ0IC13YXkgLS0tIGhvdyBkb2VzIHRoZSBjb21t
dW5pY2F0aW9uIHdvcms/DQoNCjUpIGhvdyB0byBzdW1tYXJpemUgYWxsIG9mIHRoaXMgdG8gdGhl
IHdvcmtpbmcgZ3JvdXANCg0KNikgaG93IHRvIGNsb3NlIHRoaXMgcHJvY2VzcyB1cD8NCg0KDQoN
Ci0tIHJlbWVtYmVyIHRoYXQgdGhlIGNhbGwgaXMgcmVjb3JkZWQsIGFuZCB0aGUgTm90ZVdlbGwg
YXBwbGllcy4NCg0KDQoNCi0tIFRoZSBVUkwgdG8gYWNjZXNzIHRoZSB3ZWJleCwgd2hpY2ggd2ls
bCB3ZSB1c2UgZm9yIGF1ZGlvIG9ubHk6DQoNCiAgaHR0cHM6Ly9jaXNjby53ZWJleC5jb20vY2lz
Y28vai5waHA/TVRJRD1tMmZlMTM5YmY4NzZjZWEzZWM2Mjc1MGNkNTgwYjc5MDg8aHR0cDovL2Nw
Lm1jYWZlZS5jb20vZC81ZkhDTjBTeU50NTVPV3RTanRQcWJ3VkJjU3lVZXB2ZEVLM3poT3lDT3Fl
anJ6UFBQejVYQ042QUJxTTFoWUV2SXVuZERPeC1OVnNUSlFYSWZjTFp2QzRUUVRTNmVMc0tDTy1Q
UFhYM1hVVnpCSEZTaGpsS2VwVmtmZkdoQnJ3cXJqZEk2WFl5TUNZLWVob2pkNzlLVklEZXFSNElP
UUdtSE0wTDMtbk9RR21Id3pNaDkzbzkzZ1VWbGRUUW1qaE9ndHU3ZW1fbXZJVUNldkxwMVpXVjBz
cWVyTDZUOU9Gb0NuRlpDVU9DbWJBYUpNSlowbGJWS1kwMWRFRUw4VGR3TFF6aDBxbVQ5T0ZvQ25G
WkNVT0NtZGJGRXdRelk0ZGQ0M0pvQ3kxZVdiMXVYVnRjc3E4NzlPRm9DcThhdnBLY0ZCemgxcmpQ
UHJ6MUxtVHc3dzE3Pg0KDQoNCg0KLS0gd2Ugd2lsbCByZXN1bWUgd2l0aCB0aGUgZXRoZXJwYWQg
YXQ6DQoNCiAgIGh0dHA6Ly9ldGhlcnBhZC50b29scy5pZXRmLm9yZzo5MDAwL3Avbm90ZXMtaWV0
Zi04OS02dGlzY2gtc2VjdXJpdHk8aHR0cDovL2NwLm1jYWZlZS5jb20vZC8yRFJQb3c3MU5KNXlX
YWJCUVhJQ1hDUW4xUGFwSjVNc08tcmhzNzZ6QjVkQVFzQ1Q3RERENmJUZHlkOWFSdzJ6Vmdfb1lL
cmZCM1p6T1ZMckZUb3VwdldfYzlMRkxJY3R1VnRkQlpERFRTN1ROUDdibmpJeUNIc3NQT0V1dmt6
YVQwUVNPcm9kVFY1eGRWWXN5TUNxZWp0UG8wZlZBX3lKRzdqSGstRGktckwwMGt6aFB1WlltTzVw
X2dMYlZLQlR6aE9uc0RhQnlwdURTcnphcG9TVmVsYjRPWmZJVDZrT05zeGxLNUxFMkZ2ZFR3MDlK
NTVWNlZJNS1BcTgzaVNWZWxiNE9aZklUNmtPTkZ0ZDQ2QXZ3eEZFd3RINFFnOVRob2JUdmJGenpo
MFZlbGI0UGgxalhkTkJjSXE4YnF1dXJzb2RKaVp2cG1LNkd3WT4NCg0KDQoNCkknbSBhdCArMSA2
MTMgMjc2LTY4MDk8dGVsOiUyQjElMjA2MTMlMjAyNzYtNjgwOT4sIElNOiBtY3JAeG1wcC5jcmVk
aWwub3JnPG1haWx0bzptY3JAeG1wcC5jcmVkaWwub3JnPiBvciBtY2hhcmxlc3JAZ21haWwuY29t
PG1haWx0bzptY2hhcmxlc3JAZ21haWwuY29tPiwNCg0KaWYgeW91IG5lZWQgbW9yZSB0aGFuIHRo
YXQgdG8gZ2V0IGluLCBvciBhcmUgaGF2aW5nIGRpZmZpY3VsdGllcy4NCg0KUGxlYXNlIG1ha2Ug
c3VyZSB5b3VyIGF1ZGlvIHdvcmtzLCBhbmQgdGhhdCB5b3UgbXV0ZSB3aGVuIG5vdCB0YWxraW5n
Lg0KDQoNCg0KLS0NCg0KTWljaGFlbCBSaWNoYXJkc29uIDxtY3IrSUVURkBzYW5kZWxtYW4uY2E+
PG1haWx0bzptY3IrSUVURkBzYW5kZWxtYW4uY2E+LCBTYW5kZWxtYW4gU29mdHdhcmUgV29ya3MN
Cg0KIC09IElQdjYgSW9UIGNvbnN1bHRpbmcgPS0NCg0KDQoNCg0KDQoNCg0KDQpfX19fX19fX19f
X19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fXw0KDQo2dGlzY2gtc2VjdXJpdHkg
bWFpbGluZyBsaXN0DQoNCjZ0aXNjaC1zZWN1cml0eUBpZXRmLm9yZzxtYWlsdG86NnRpc2NoLXNl
Y3VyaXR5QGlldGYub3JnPg0KDQpodHRwczovL3d3dy5pZXRmLm9yZy9tYWlsbWFuL2xpc3RpbmZv
LzZ0aXNjaC1zZWN1cml0eTxodHRwOi8vY3AubWNhZmVlLmNvbS9kLzJEUlBvTzg2UW1iRUVLbmpL
T3JLcmhzN2NGQ1FuMVBiVko1TXNxZWtrU2poT3JzdXV1c29Mc1M4UUFIbTBhZkIzWnpPVkkta2ZT
ZmJDWktEdHhWQl9IWU1DLUMtTU5SWEJRU25TdXZ2b3Z2N2NzSnRlT2FxSk5QZmF4VlppY0hzM2py
MUp3VHZBbTRURE5PYjJwRVZkVGRBVlBtRUJDNWVCWVR1MDBVOUdYMzNWa0RhM0pzc0RhQnlwdURT
cnphcG9TVmVsYjRPWmZJVDZrT05zeGxLNUxFMkZ2ZFR3MDlKNTVWNlZJNS1BcTgzaVNWZWxiNE9a
ZklUNmtPTkZ0ZDQ2QXZ3eEZFd3RINFFnOVRob2JUdmJGenpoMFZlbGI0UGgxalhkTkJjSXE4YnF1
dXJzb2RMV2J2Pg0KDQoNCg0KDQoNCi0tDQoNCmVtYWlsOiByc3RydWlrLmV4dEBnbWFpbC5jb208
bWFpbHRvOnJzdHJ1aWsuZXh0QGdtYWlsLmNvbT4gfCBTa3lwZTogcnN0cnVpaw0KDQpjZWxsOiAr
MSAoNjQ3KSA4NjctNTY1ODx0ZWw6JTJCMSUyMCUyODY0NyUyOSUyMDg2Ny01NjU4PiB8IFVTOiAr
MSAoNDE1KSA2OTAtNzM2Mzx0ZWw6JTJCMSUyMCUyODQxNSUyOSUyMDY5MC03MzYzPg0KDQpfX19f
X19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fXw0KNnRpc2NoLXNlY3Vy
aXR5IG1haWxpbmcgbGlzdA0KNnRpc2NoLXNlY3VyaXR5QGlldGYub3JnPG1haWx0bzo2dGlzY2gt
c2VjdXJpdHlAaWV0Zi5vcmc+DQpodHRwOi8vY3AubWNhZmVlLmNvbS9kL2F2bmR6Z1E5M2dBcmhv
S3l5VnRlWDlLVko1TXNPQ3JoczdjTENRbjFORVZoanBkNzlKTlZWVk55WlBvemlpSm8wRS1rZlNm
YkNQVmdfb1lLclNXdFM3Q24tTFAycldyWDM3bktuanB2cFZaWnhaWXNOT1JRWDhGR1Q3Y1lHN0RS
OE9KTWRkRUNRanQtaG9qdXY3OEk5Q3pBVHNTakRkcXltb2tXblB0VTAzd0NISWNmQmlzRWVSTk9z
R205Qld2cEtjRkJ6ckFWa0lqYlEtUHNwamI1TzVtVW0td2FCWVR1MDBDUWtuQXJDTW5XaEV3ZGJy
QVZrSWpiUS1Qc3BqYjZCUVFncWgtMjZDeTFTSWpoMER0NXdMdFlLQ2VkNDNBVmtJamQ0NWZJVDZr
T05Fd0pGVlZKTndTZVZoc3JMZS1Ga2QNCg0KDQoNCi0tDQotLQ0KSm9uYXRoYW4gU2ltb24sIFBo
LiBEDQpEaXJlY3RvciBvZiBTeXN0ZW1zIEVuZ2luZWVyaW5nDQpEdXN0IE5ldHdvcmtzIGF0IExp
bmVhciBUZWNobm9sb2d5DQozMDY5NSBIdW50d29vZCBBdmUNCkhheXdhcmQsIENBIDk0NTQ0LTcw
MjENCig1MTApIDQwMC0yOTM2PHRlbDolMjg1MTAlMjklMjA0MDAtMjkzNj4NCig1MTApIDQ4OS0z
Nzk5PHRlbDolMjg1MTAlMjklMjA0ODktMzc5OT4gRkFYDQpqc2ltb25AbGluZWFyLmNvbTxtYWls
dG86anNpbW9uQGxpbmVhci5jb20+DQoNCioqTElORUFSIFRFQ0hOT0xPR1kgQ09SUE9SQVRJT04q
Kg0KKioqKipJbnRlcm5ldCBFbWFpbCBDb25maWRlbnRpYWxpdHkgTm90aWNlKioqKioNCiBUaGlz
IGUtbWFpbCB0cmFuc21pc3Npb24sIGFuZCBhbnkgZG9jdW1lbnRzLCBmaWxlcyBvciBwcmV2aW91
cyBlLW1haWwgbWVzc2FnZXMgYXR0YWNoZWQgdG8gaXQgbWF5IGNvbnRhaW4gY29uZmlkZW50aWFs
IGluZm9ybWF0aW9uIHRoYXQgaXMgbGVnYWxseSBwcml2aWxlZ2VkLiBJZiB5b3UgYXJlIG5vdCB0
aGUgaW50ZW5kZWQgcmVjaXBpZW50LCBvciBhIHBlcnNvbiByZXNwb25zaWJsZSBmb3IgZGVsaXZl
cmluZyBpdCB0byB0aGUgaW50ZW5kZWQgcmVjaXBpZW50LCB5b3UgYXJlIGhlcmVieSBub3RpZmll
ZCB0aGF0IGFueSBkaXNjbG9zdXJlLCBjb3B5aW5nLCBkaXN0cmlidXRpb24gb3IgdXNlIG9mIGFu
eSBvZiB0aGUgaW5mb3JtYXRpb24gY29udGFpbmVkIGluIG9yIGF0dGFjaGVkIHRvIHRoaXMgdHJh
bnNtaXNzaW9uIGlzIFNUUklDVExZIFBST0hJQklURUQuIElmIHlvdSBoYXZlIHJlY2VpdmVkIHRo
aXMgdHJhbnNtaXNzaW9uIGluIGVycm9yLCBwbGVhc2UgaW1tZWRpYXRlbHkgbm90aWZ5IG1lIGJ5
IHJlcGx5IGUtbWFpbCwgb3IgYnkgdGVsZXBob25lIGF0ICg1MTApIDQwMC0yOTM2PHRlbDolMjg1
MTAlMjklMjA0MDAtMjkzNj4sIGFuZCBkZXN0cm95IHRoZSBvcmlnaW5hbCB0cmFuc21pc3Npb24g
YW5kIGl0cyBhdHRhY2htZW50cyB3aXRob3V0IHJlYWRpbmcgb3Igc2F2aW5nIGluIGFueSBtYW5u
ZXIuIFRoYW5rIHlvdS4NCg0KX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19f
X19fX19fX18NCjZ0aXNjaC1zZWN1cml0eSBtYWlsaW5nIGxpc3QNCjZ0aXNjaC1zZWN1cml0eUBp
ZXRmLm9yZzxtYWlsdG86NnRpc2NoLXNlY3VyaXR5QGlldGYub3JnPg0KaHR0cDovL2NwLm1jYWZl
ZS5jb20vZC8yRFJQb3c3NlFtYkVGTHp6aE9NLXJLcmhzN2NGQ1FuMVBiVko1TXNxZWtrU2poT3Jz
dXV1c29Mc1M4UUFIbTBhZkIzWnpPVkkta2ZTZmJDVEE3aFBYUGJfblZOWk5CVnh6SFRiRXpISVlZ
ZXBkN2J6OFhCSEVTaGhsS01fT0V1dmt6YVQwUVN5cmhkVFY1eGRWWXN5TUNxZWp0UHBlc1JHOXB4
akZ2ZFR3MGUycUtNTS1sOU93WG43OU9Gb0NuRlpDVU9DbWRLakJpTmNMalhkTkJjSW44bHJ4clcw
R25QdFUwMnJvamhLVXIxdkY2eTBRSktqQmlOY0xqWGROQmNJcW5qaDFGN1U4cXE4N3FOZDQydFFt
MlpUT1dvVVFnZWpCaU5jUWdrLVBzcGpiNnkyU0REQ1Q2M3J0X1UyU1ZVbFZCMA0KDQoNCg0KLS0N
Ci0tDQpKb25hdGhhbiBTaW1vbiwgUGguIEQNCkRpcmVjdG9yIG9mIFN5c3RlbXMgRW5naW5lZXJp
bmcNCkR1c3QgTmV0d29ya3MgYXQgTGluZWFyIFRlY2hub2xvZ3kNCjMwNjk1IEh1bnR3b29kIEF2
ZQ0KSGF5d2FyZCwgQ0EgOTQ1NDQtNzAyMQ0KKDUxMCkgNDAwLTI5MzYNCig1MTApIDQ4OS0zNzk5
IEZBWA0KanNpbW9uQGxpbmVhci5jb208bWFpbHRvOmpzaW1vbkBsaW5lYXIuY29tPg0KDQoqKkxJ
TkVBUiBURUNITk9MT0dZIENPUlBPUkFUSU9OKioNCioqKioqSW50ZXJuZXQgRW1haWwgQ29uZmlk
ZW50aWFsaXR5IE5vdGljZSoqKioqDQogVGhpcyBlLW1haWwgdHJhbnNtaXNzaW9uLCBhbmQgYW55
IGRvY3VtZW50cywgZmlsZXMgb3IgcHJldmlvdXMgZS1tYWlsIG1lc3NhZ2VzIGF0dGFjaGVkIHRv
IGl0IG1heSBjb250YWluIGNvbmZpZGVudGlhbCBpbmZvcm1hdGlvbiB0aGF0IGlzIGxlZ2FsbHkg
cHJpdmlsZWdlZC4gSWYgeW91IGFyZSBub3QgdGhlIGludGVuZGVkIHJlY2lwaWVudCwgb3IgYSBw
ZXJzb24gcmVzcG9uc2libGUgZm9yIGRlbGl2ZXJpbmcgaXQgdG8gdGhlIGludGVuZGVkIHJlY2lw
aWVudCwgeW91IGFyZSBoZXJlYnkgbm90aWZpZWQgdGhhdCBhbnkgZGlzY2xvc3VyZSwgY29weWlu
ZywgZGlzdHJpYnV0aW9uIG9yIHVzZSBvZiBhbnkgb2YgdGhlIGluZm9ybWF0aW9uIGNvbnRhaW5l
ZCBpbiBvciBhdHRhY2hlZCB0byB0aGlzIHRyYW5zbWlzc2lvbiBpcyBTVFJJQ1RMWSBQUk9ISUJJ
VEVELiBJZiB5b3UgaGF2ZSByZWNlaXZlZCB0aGlzIHRyYW5zbWlzc2lvbiBpbiBlcnJvciwgcGxl
YXNlIGltbWVkaWF0ZWx5IG5vdGlmeSBtZSBieSByZXBseSBlLW1haWwsIG9yIGJ5IHRlbGVwaG9u
ZSBhdCAoNTEwKSA0MDAtMjkzNiwgYW5kIGRlc3Ryb3kgdGhlIG9yaWdpbmFsIHRyYW5zbWlzc2lv
biBhbmQgaXRzIGF0dGFjaG1lbnRzIHdpdGhvdXQgcmVhZGluZyBvciBzYXZpbmcgaW4gYW55IG1h
bm5lci4gVGhhbmsgeW91Lg0KX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19f
X19fX19fX18NCjZ0aXNjaC1zZWN1cml0eSBtYWlsaW5nIGxpc3QNCjZ0aXNjaC1zZWN1cml0eUBp
ZXRmLm9yZzxtYWlsdG86NnRpc2NoLXNlY3VyaXR5QGlldGYub3JnPg0KaHR0cDovL2NwLm1jYWZl
ZS5jb20vZC8xaldWSWUzenFiNVFrVHpoT01DLXJLcmhzN2NGQ1FuMVBiVko1TXNxZWtrU2poT3Jz
dXV1c29Mc1M4UUFIbTBhZkIzWnpPVkkta2ZTZmJDTzVKdHZ1cHZXXzhDekJkQkJmSFRiRUN6QmR6
QVRDN3hORVZWcVd0QWtsckN6QjdCZ1ktRjZsSzFGSjRTeXJMT2IyclBVVjV4Y1FzQ1hDT3NWSGtp
UDJEaS1yTDAwczRSdHh4WUdqQjFTS2VqQmlOY0xqWGROQmNJcnNEYUJ5cHVEU3J6YXBvS2dHVDJU
UTFrTENYTTA0Uy1xZW03VDNvYlo4UWc2QkpPc0dtOUJXdnBLY0ZCemlXcThkOF8xM2poMFhtOUV3
akt5TW5LLW5qNzZ5MU9zR205Q3kyRFNyemFwb1FnbVFZWVNVTXJEcmtyMnBBYVRhbQ0KDQo=

--_000_674F70E5F2BE564CB06B6901FD3DD78B2723BA70TGXML210toshiba_
Content-Type: text/html; charset="utf-8"
Content-Transfer-Encoding: base64

PGh0bWwgeG1sbnM6dj0idXJuOnNjaGVtYXMtbWljcm9zb2Z0LWNvbTp2bWwiIHhtbG5zOm89InVy
bjpzY2hlbWFzLW1pY3Jvc29mdC1jb206b2ZmaWNlOm9mZmljZSIgeG1sbnM6dz0idXJuOnNjaGVt
YXMtbWljcm9zb2Z0LWNvbTpvZmZpY2U6d29yZCIgeG1sbnM6bT0iaHR0cDovL3NjaGVtYXMubWlj
cm9zb2Z0LmNvbS9vZmZpY2UvMjAwNC8xMi9vbW1sIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcv
VFIvUkVDLWh0bWw0MCI+DQo8aGVhZD4NCjxtZXRhIGh0dHAtZXF1aXY9IkNvbnRlbnQtVHlwZSIg
Y29udGVudD0idGV4dC9odG1sOyBjaGFyc2V0PXV0Zi04Ij4NCjxtZXRhIG5hbWU9IkdlbmVyYXRv
ciIgY29udGVudD0iTWljcm9zb2Z0IFdvcmQgMTUgKGZpbHRlcmVkIG1lZGl1bSkiPg0KPHN0eWxl
PjwhLS0NCi8qIEZvbnQgRGVmaW5pdGlvbnMgKi8NCkBmb250LWZhY2UNCgl7Zm9udC1mYW1pbHk6
Iu+8re+8syDmmI7mnJ0iOw0KCXBhbm9zZS0xOjIgMiA2IDkgNCAyIDUgOCAzIDQ7fQ0KQGZvbnQt
ZmFjZQ0KCXtmb250LWZhbWlseToi77yt77yzIOOCtOOCt+ODg+OCryI7DQoJcGFub3NlLTE6MiAx
MSA2IDkgNyAyIDUgOCAyIDQ7fQ0KQGZvbnQtZmFjZQ0KCXtmb250LWZhbWlseToiQ2FtYnJpYSBN
YXRoIjsNCglwYW5vc2UtMToyIDQgNSAzIDUgNCA2IDMgMiA0O30NCkBmb250LWZhY2UNCgl7Zm9u
dC1mYW1pbHk6Q2FsaWJyaTsNCglwYW5vc2UtMToyIDE1IDUgMiAyIDIgNCAzIDIgNDt9DQpAZm9u
dC1mYWNlDQoJe2ZvbnQtZmFtaWx5OiLvvK3vvLMg77yw44K044K344OD44KvIjsNCglwYW5vc2Ut
MToyIDExIDYgMCA3IDIgNSA4IDIgNDt9DQpAZm9udC1mYWNlDQoJe2ZvbnQtZmFtaWx5OiJcQO+8
re+8syDjgrTjgrfjg4Pjgq8iOw0KCXBhbm9zZS0xOjIgMTEgNiA5IDcgMiA1IDggMiA0O30NCkBm
b250LWZhY2UNCgl7Zm9udC1mYW1pbHk6IlxA77yt77yzIO+8sOOCtOOCt+ODg+OCryI7DQoJcGFu
b3NlLTE6MiAxMSA2IDAgNyAyIDUgOCAyIDQ7fQ0KQGZvbnQtZmFjZQ0KCXtmb250LWZhbWlseToi
THVjaWRhIEdyYW5kZSI7DQoJcGFub3NlLTE6MCAwIDAgMCAwIDAgMCAwIDAgMDt9DQpAZm9udC1m
YWNlDQoJe2ZvbnQtZmFtaWx5Okx1Y2lkYUdyYW5kZTsNCglwYW5vc2UtMTowIDAgMCAwIDAgMCAw
IDAgMCAwO30NCkBmb250LWZhY2UNCgl7Zm9udC1mYW1pbHk6IlxA77yt77yzIOaYjuacnSI7DQoJ
cGFub3NlLTE6MiAyIDYgOSA0IDIgNSA4IDMgNDt9DQovKiBTdHlsZSBEZWZpbml0aW9ucyAqLw0K
cC5Nc29Ob3JtYWwsIGxpLk1zb05vcm1hbCwgZGl2Lk1zb05vcm1hbA0KCXttYXJnaW46MG1tOw0K
CW1hcmdpbi1ib3R0b206LjAwMDFwdDsNCglmb250LXNpemU6MTIuMHB0Ow0KCWZvbnQtZmFtaWx5
OiLvvK3vvLMg77yw44K044K344OD44KvIjt9DQphOmxpbmssIHNwYW4uTXNvSHlwZXJsaW5rDQoJ
e21zby1zdHlsZS1wcmlvcml0eTo5OTsNCgljb2xvcjpibHVlOw0KCXRleHQtZGVjb3JhdGlvbjp1
bmRlcmxpbmU7fQ0KYTp2aXNpdGVkLCBzcGFuLk1zb0h5cGVybGlua0ZvbGxvd2VkDQoJe21zby1z
dHlsZS1wcmlvcml0eTo5OTsNCgljb2xvcjpwdXJwbGU7DQoJdGV4dC1kZWNvcmF0aW9uOnVuZGVy
bGluZTt9DQpwcmUNCgl7bXNvLXN0eWxlLXByaW9yaXR5Ojk5Ow0KCW1zby1zdHlsZS1saW5rOiJI
VE1MIOabuOW8j+S7mOOBjSBcKOaWh+Wtl1wpIjsNCgltYXJnaW46MG1tOw0KCW1hcmdpbi1ib3R0
b206LjAwMDFwdDsNCglmb250LXNpemU6MTIuMHB0Ow0KCWZvbnQtZmFtaWx5OiLvvK3vvLMg44K0
44K344OD44KvIjt9DQpzcGFuLmFwcGxlLXN0eWxlLXNwYW4NCgl7bXNvLXN0eWxlLW5hbWU6YXBw
bGUtc3R5bGUtc3Bhbjt9DQpzcGFuLmFwcGxlLWNvbnZlcnRlZC1zcGFjZQ0KCXttc28tc3R5bGUt
bmFtZTphcHBsZS1jb252ZXJ0ZWQtc3BhY2U7fQ0Kc3Bhbi5IVE1MDQoJe21zby1zdHlsZS1uYW1l
OiJIVE1MIOabuOW8j+S7mOOBjSBcKOaWh+Wtl1wpIjsNCgltc28tc3R5bGUtcHJpb3JpdHk6OTk7
DQoJbXNvLXN0eWxlLWxpbms6IkhUTUwg5pu45byP5LuY44GNIjsNCglmb250LWZhbWlseToiQ291
cmllciBOZXciO30NCnNwYW4uMjENCgl7bXNvLXN0eWxlLXR5cGU6cGVyc29uYWwtcmVwbHk7DQoJ
Zm9udC1mYW1pbHk6IkFyaWFsIiwic2Fucy1zZXJpZiI7DQoJY29sb3I6IzFGNDk3RDt9DQouTXNv
Q2hwRGVmYXVsdA0KCXttc28tc3R5bGUtdHlwZTpleHBvcnQtb25seTsNCglmb250LXNpemU6MTAu
MHB0O30NCkBwYWdlIFdvcmRTZWN0aW9uMQ0KCXtzaXplOjYxMi4wcHQgNzkyLjBwdDsNCgltYXJn
aW46OTkuMjVwdCAzMC4wbW0gMzAuMG1tIDMwLjBtbTt9DQpkaXYuV29yZFNlY3Rpb24xDQoJe3Bh
Z2U6V29yZFNlY3Rpb24xO30NCi0tPjwvc3R5bGU+PCEtLVtpZiBndGUgbXNvIDldPjx4bWw+DQo8
bzpzaGFwZWRlZmF1bHRzIHY6ZXh0PSJlZGl0IiBzcGlkbWF4PSIxMDI2Ij4NCjx2OnRleHRib3gg
aW5zZXQ9IjUuODVwdCwuN3B0LDUuODVwdCwuN3B0IiAvPg0KPC9vOnNoYXBlZGVmYXVsdHM+PC94
bWw+PCFbZW5kaWZdLS0+PCEtLVtpZiBndGUgbXNvIDldPjx4bWw+DQo8bzpzaGFwZWxheW91dCB2
OmV4dD0iZWRpdCI+DQo8bzppZG1hcCB2OmV4dD0iZWRpdCIgZGF0YT0iMSIgLz4NCjwvbzpzaGFw
ZWxheW91dD48L3htbD48IVtlbmRpZl0tLT4NCjwvaGVhZD4NCjxib2R5IGxhbmc9IkpBIiBsaW5r
PSJibHVlIiB2bGluaz0icHVycGxlIj4NCjxkaXYgY2xhc3M9IldvcmRTZWN0aW9uMSI+DQo8cCBj
bGFzcz0iTXNvTm9ybWFsIj48c3BhbiBsYW5nPSJFTi1VUyIgc3R5bGU9ImZvbnQtc2l6ZToxMC4w
cHQ7Zm9udC1mYW1pbHk6JnF1b3Q7QXJpYWwmcXVvdDssJnF1b3Q7c2Fucy1zZXJpZiZxdW90Oztj
b2xvcjojMUY0OTdEIj5ZZXMuPG86cD48L286cD48L3NwYW4+PC9wPg0KPHAgY2xhc3M9Ik1zb05v
cm1hbCI+PHNwYW4gbGFuZz0iRU4tVVMiIHN0eWxlPSJmb250LXNpemU6MTAuMHB0O2ZvbnQtZmFt
aWx5OiZxdW90O0FyaWFsJnF1b3Q7LCZxdW90O3NhbnMtc2VyaWYmcXVvdDs7Y29sb3I6IzFGNDk3
RCI+PG86cD4mbmJzcDs8L286cD48L3NwYW4+PC9wPg0KPHAgY2xhc3M9Ik1zb05vcm1hbCI+PHNw
YW4gbGFuZz0iRU4tVVMiIHN0eWxlPSJmb250LXNpemU6MTAuMHB0O2ZvbnQtZmFtaWx5OiZxdW90
O0FyaWFsJnF1b3Q7LCZxdW90O3NhbnMtc2VyaWYmcXVvdDs7Y29sb3I6IzFGNDk3RCI+WW9zaGlo
aXJvIE9oYmE8bzpwPjwvbzpwPjwvc3Bhbj48L3A+DQo8cCBjbGFzcz0iTXNvTm9ybWFsIj48c3Bh
biBsYW5nPSJFTi1VUyIgc3R5bGU9ImZvbnQtc2l6ZToxMC4wcHQ7Zm9udC1mYW1pbHk6JnF1b3Q7
QXJpYWwmcXVvdDssJnF1b3Q7c2Fucy1zZXJpZiZxdW90Oztjb2xvcjojMUY0OTdEIj48bzpwPiZu
YnNwOzwvbzpwPjwvc3Bhbj48L3A+DQo8ZGl2Pg0KPGRpdiBzdHlsZT0iYm9yZGVyOm5vbmU7Ym9y
ZGVyLXRvcDpzb2xpZCAjRTFFMUUxIDEuMHB0O3BhZGRpbmc6My4wcHQgMG1tIDBtbSAwbW0iPg0K
PHAgY2xhc3M9Ik1zb05vcm1hbCI+PGI+PHNwYW4gbGFuZz0iRU4tVVMiIHN0eWxlPSJmb250LXNp
emU6MTEuMHB0O2ZvbnQtZmFtaWx5OiZxdW90O0NhbGlicmkmcXVvdDssJnF1b3Q7c2Fucy1zZXJp
ZiZxdW90OyI+RnJvbTo8L3NwYW4+PC9iPjxzcGFuIGxhbmc9IkVOLVVTIiBzdHlsZT0iZm9udC1z
aXplOjExLjBwdDtmb250LWZhbWlseTomcXVvdDtDYWxpYnJpJnF1b3Q7LCZxdW90O3NhbnMtc2Vy
aWYmcXVvdDsiPiBKb25hdGhhbiBTaW1vbiBbbWFpbHRvOmpzaW1vbkBsaW5lYXIuY29tXQ0KPGJy
Pg0KPGI+U2VudDo8L2I+IFRodXJzZGF5LCBNYXkgMjksIDIwMTQgODo0MiBBTTxicj4NCjxiPlRv
OjwvYj4gb2hiYSB5b3NoaWhpcm8oPC9zcGFuPjxzcGFuIHN0eWxlPSJmb250LXNpemU6MTEuMHB0
Ij7lpKfloLQ8L3NwYW4+PHNwYW4gc3R5bGU9ImZvbnQtc2l6ZToxMS4wcHQ7Zm9udC1mYW1pbHk6
JnF1b3Q7Q2FsaWJyaSZxdW90OywmcXVvdDtzYW5zLXNlcmlmJnF1b3Q7Ij4NCjwvc3Bhbj48c3Bh
biBzdHlsZT0iZm9udC1zaXplOjExLjBwdCI+576p5rSLPC9zcGFuPjxzcGFuIGxhbmc9IkVOLVVT
IiBzdHlsZT0iZm9udC1zaXplOjExLjBwdDtmb250LWZhbWlseTomcXVvdDtDYWxpYnJpJnF1b3Q7
LCZxdW90O3NhbnMtc2VyaWYmcXVvdDsiPiDil4s8L3NwYW4+PHNwYW4gc3R5bGU9ImZvbnQtc2l6
ZToxMS4wcHQiPu+8su+8pO+8ozwvc3Bhbj48c3BhbiBsYW5nPSJFTi1VUyIgc3R5bGU9ImZvbnQt
c2l6ZToxMS4wcHQ7Zm9udC1mYW1pbHk6JnF1b3Q7Q2FsaWJyaSZxdW90OywmcXVvdDtzYW5zLXNl
cmlmJnF1b3Q7Ij7ilqE8L3NwYW4+PHNwYW4gc3R5bGU9ImZvbnQtc2l6ZToxMS4wcHQiPu+8ru+8
s++8rDwvc3Bhbj48c3BhbiBsYW5nPSJFTi1VUyIgc3R5bGU9ImZvbnQtc2l6ZToxMS4wcHQ7Zm9u
dC1mYW1pbHk6JnF1b3Q7Q2FsaWJyaSZxdW90OywmcXVvdDtzYW5zLXNlcmlmJnF1b3Q7Ij4pPGJy
Pg0KPGI+Q2M6PC9iPiBtY3ImIzQzO2lldGZAc2FuZGVsbWFuLmNhOyByc3RydWlrLmV4dEBnbWFp
bC5jb207IDZ0aXNjaC1zZWN1cml0eUBpZXRmLm9yZzxicj4NCjxiPlN1YmplY3Q6PC9iPiBSZTog
WzZ0aXNjaC1zZWN1cml0eV0gYWdlbmRhIGZvciAyMDE0LTA1LTI3IDZ0aXNjaCBzZWN1cml0eSBj
YWxsPG86cD48L286cD48L3NwYW4+PC9wPg0KPC9kaXY+DQo8L2Rpdj4NCjxwIGNsYXNzPSJNc29O
b3JtYWwiPjxzcGFuIGxhbmc9IkVOLVVTIj48bzpwPiZuYnNwOzwvbzpwPjwvc3Bhbj48L3A+DQo8
cCBjbGFzcz0iTXNvTm9ybWFsIj48c3BhbiBsYW5nPSJFTi1VUyI+VGhlbiBhcyBsb25nIGFzIGVp
dGhlcjxvOnA+PC9vOnA+PC9zcGFuPjwvcD4NCjxkaXY+DQo8cCBjbGFzcz0iTXNvTm9ybWFsIj48
c3BhbiBsYW5nPSJFTi1VUyI+YSkgQmVhY29ucyBhcmUgb25seSB1c2VkIGZvciBhZHZlcnRpc2lu
ZyBhIG5ldHdvcmsgdG8gdW5zeWNocm9uaXplZCBkZXZpY2VzLCBvcjxvOnA+PC9vOnA+PC9zcGFu
PjwvcD4NCjwvZGl2Pg0KPGRpdj4NCjxwIGNsYXNzPSJNc29Ob3JtYWwiPjxzcGFuIGxhbmc9IkVO
LVVTIj5iKSBEZXZpY2VzIG9ubHkgdGFrZSB0aW1pbmcgaW5mb3JtYXRpb24gKHRpbWUgb2YgYXJy
aXZhbCkgZnJvbSBiZWFjb25zIGNvbWluZyBmcm9tIHRpbWUgcGFyZW50cyBhbmQgYXV0aGVudGlj
YXRlZCB3aXRoIHRoZSBydW4tdGltZSBrZXk8bzpwPjwvbzpwPjwvc3Bhbj48L3A+DQo8L2Rpdj4N
CjxkaXY+DQo8cCBjbGFzcz0iTXNvTm9ybWFsIj48c3BhbiBsYW5nPSJFTi1VUyI+eW91IGFyZSBn
b29kLiZuYnNwOzxvOnA+PC9vOnA+PC9zcGFuPjwvcD4NCjwvZGl2Pg0KPGRpdj4NCjxwIGNsYXNz
PSJNc29Ob3JtYWwiPjxzcGFuIGxhbmc9IkVOLVVTIj48bzpwPiZuYnNwOzwvbzpwPjwvc3Bhbj48
L3A+DQo8L2Rpdj4NCjxkaXY+DQo8cCBjbGFzcz0iTXNvTm9ybWFsIj48c3BhbiBsYW5nPSJFTi1V
UyI+Jm5ic3A7PG86cD48L286cD48L3NwYW4+PC9wPg0KPC9kaXY+DQo8ZGl2Pg0KPGRpdj4NCjxk
aXY+DQo8ZGl2Pg0KPHAgY2xhc3M9Ik1zb05vcm1hbCI+PHNwYW4gbGFuZz0iRU4tVVMiIHN0eWxl
PSJmb250LWZhbWlseTomcXVvdDtMdWNpZGEgR3JhbmRlJnF1b3Q7LCZxdW90O3NlcmlmJnF1b3Q7
O2NvbG9yOmJsYWNrIj4tLSZuYnNwOzxicj4NCkpvbmF0aGFuIFNpbW9uLCBQaC4gRDxicj4NCkRp
cmVjdG9yIG9mIFN5c3RlbXMgRW5naW5lZXJpbmc8YnI+DQpMaW5lYXIgVGVjaG5vbG9neSwgRHVz
dCBOZXR3b3JrcyBwcm9kdWN0IGdyb3VwPGJyPg0KMzA2OTUgSHVudHdvb2QgQXZlPGJyPg0KSGF5
d2FyZCwgQ0EgOTQ1NDQtNzAyMTxicj4NCig1MTApIDQwMC0yOTM2PGJyPg0KKDUxMCkgNDg5LTM3
OTkgRkFYPGJyPg0KPGEgaHJlZj0ibWFpbHRvOmpzaW1vbkBsaW5lYXIuY29tIj5qc2ltb25AbGlu
ZWFyLmNvbTwvYT48YnI+DQo8YnI+DQoqKkxJTkVBUiBURUNITk9MT0dZJm5ic3A7Q09SUE9SQVRJ
T04qKiZuYnNwOzxicj4NCioqKioqSW50ZXJuZXQgRW1haWwgQ29uZmlkZW50aWFsaXR5Jm5ic3A7
Tm90aWNlKioqKiombmJzcDs8YnI+DQombmJzcDtUaGlzIGUtbWFpbCB0cmFuc21pc3Npb24sIGFu
ZCBhbnkmbmJzcDtkb2N1bWVudHMsIGZpbGVzIG9yIHByZXZpb3VzIGUtbWFpbCZuYnNwO21lc3Nh
Z2VzIGF0dGFjaGVkIHRvIGl0IG1heSBjb250YWluJm5ic3A7Y29uZmlkZW50aWFsIGluZm9ybWF0
aW9uIHRoYXQgaXMmbmJzcDtsZWdhbGx5IHByaXZpbGVnZWQuIElmIHlvdSBhcmUgbm90IHRoZSZu
YnNwO2ludGVuZGVkIHJlY2lwaWVudCwgb3IgYSBwZXJzb24mbmJzcDtyZXNwb25zaWJsZSBmb3Ig
ZGVsaXZlcmluZyBpdCB0byB0aGUmbmJzcDtpbnRlbmRlZA0KIHJlY2lwaWVudCwgeW91IGFyZSBo
ZXJlYnkmbmJzcDtub3RpZmllZCB0aGF0IGFueSBkaXNjbG9zdXJlLCBjb3B5aW5nLCZuYnNwO2Rp
c3RyaWJ1dGlvbiBvciB1c2Ugb2YgYW55IG9mIHRoZSZuYnNwO2luZm9ybWF0aW9uIGNvbnRhaW5l
ZCBpbiBvciBhdHRhY2hlZCZuYnNwO3RvIHRoaXMgdHJhbnNtaXNzaW9uIGlzIFNUUklDVExZJm5i
c3A7UFJPSElCSVRFRC4gSWYgeW91IGhhdmUgcmVjZWl2ZWQgdGhpcyZuYnNwO3RyYW5zbWlzc2lv
biBpbiBlcnJvciwgcGxlYXNlJm5ic3A7aW1tZWRpYXRlbHkgbm90aWZ5DQogbWUgYnkgcmVwbHkg
ZS1tYWlsLCBvciBieSB0ZWxlcGhvbmUgYXQgKDUxMCkgNDAwLTI5MzYsIGFuZCBkZXN0cm95IHRo
ZSBvcmlnaW5hbCZuYnNwO3RyYW5zbWlzc2lvbiBhbmQgaXRzIGF0dGFjaG1lbnRzJm5ic3A7d2l0
aG91dCByZWFkaW5nIG9yIHNhdmluZyBpbiBhbnkmbmJzcDttYW5uZXIuIFRoYW5rIHlvdS4mbmJz
cDs8bzpwPjwvbzpwPjwvc3Bhbj48L3A+DQo8L2Rpdj4NCjwvZGl2Pg0KPC9kaXY+DQo8cCBjbGFz
cz0iTXNvTm9ybWFsIj48c3BhbiBsYW5nPSJFTi1VUyI+PG86cD4mbmJzcDs8L286cD48L3NwYW4+
PC9wPg0KPGRpdj4NCjxkaXY+DQo8cCBjbGFzcz0iTXNvTm9ybWFsIj48c3BhbiBsYW5nPSJFTi1V
UyI+T24gTWF5IDI4LCAyMDE0LCBhdCA0OjE5IFBNLCAmbHQ7PGEgaHJlZj0ibWFpbHRvOnlvc2hp
aGlyby5vaGJhQHRvc2hpYmEuY28uanAiPnlvc2hpaGlyby5vaGJhQHRvc2hpYmEuY28uanA8L2E+
Jmd0OyAmbHQ7PGEgaHJlZj0ibWFpbHRvOnlvc2hpaGlyby5vaGJhQHRvc2hpYmEuY28uanAiPnlv
c2hpaGlyby5vaGJhQHRvc2hpYmEuY28uanA8L2E+Jmd0OyB3cm90ZTo8bzpwPjwvbzpwPjwvc3Bh
bj48L3A+DQo8L2Rpdj4NCjxwIGNsYXNzPSJNc29Ob3JtYWwiPjxzcGFuIGxhbmc9IkVOLVVTIj48
YnI+DQo8YnI+DQo8bzpwPjwvbzpwPjwvc3Bhbj48L3A+DQo8YmxvY2txdW90ZSBzdHlsZT0ibWFy
Z2luLXRvcDo1LjBwdDttYXJnaW4tYm90dG9tOjUuMHB0Ij4NCjxkaXY+DQo8ZGl2Pg0KPHAgY2xh
c3M9Ik1zb05vcm1hbCI+PHNwYW4gbGFuZz0iRU4tVVMiIHN0eWxlPSJmb250LXNpemU6MTAuMHB0
O2ZvbnQtZmFtaWx5OiZxdW90O0FyaWFsJnF1b3Q7LCZxdW90O3NhbnMtc2VyaWYmcXVvdDs7Y29s
b3I6IzFGNDk3RCI+SGkgSm9uYXRoYW4sPC9zcGFuPjxzcGFuIGxhbmc9IkVOLVVTIj48bzpwPjwv
bzpwPjwvc3Bhbj48L3A+DQo8L2Rpdj4NCjxkaXY+DQo8cCBjbGFzcz0iTXNvTm9ybWFsIj48c3Bh
biBsYW5nPSJFTi1VUyIgc3R5bGU9ImZvbnQtc2l6ZToxMC4wcHQ7Zm9udC1mYW1pbHk6JnF1b3Q7
QXJpYWwmcXVvdDssJnF1b3Q7c2Fucy1zZXJpZiZxdW90Oztjb2xvcjojMUY0OTdEIj4mbmJzcDs8
L3NwYW4+PHNwYW4gbGFuZz0iRU4tVVMiPjxvOnA+PC9vOnA+PC9zcGFuPjwvcD4NCjwvZGl2Pg0K
PGRpdj4NCjxwIGNsYXNzPSJNc29Ob3JtYWwiPjxzcGFuIGxhbmc9IkVOLVVTIiBzdHlsZT0iZm9u
dC1zaXplOjEwLjBwdDtmb250LWZhbWlseTomcXVvdDtBcmlhbCZxdW90OywmcXVvdDtzYW5zLXNl
cmlmJnF1b3Q7O2NvbG9yOiMxRjQ5N0QiPkkgYW0gbm90IGNhcmluZyBhYm91dCBhbiBhdHRhY2tl
ciB0byBpbmplY3Qgam9pbmluZyB0cmFmZmljLCBidXQgd2hhdCBJIGNhcmUgaXMgYW4gYXR0YWNr
ZXIgYXR0ZW1wdGluZyB0byBkZXN0cnVjdCBiYXNpYyBUU0NIIG9wZXJhdGlvbiBpbiB0aGUgbmV0
d29yaw0KIGJ5IHNlbmRpbmcgZm9yZ2VkIGJlYWNvbnMgcHJvdGVjdGVkIHdpdGggdGhlIHdlbGwt
a25vd24ga2V5Ljwvc3Bhbj48c3BhbiBsYW5nPSJFTi1VUyI+PG86cD48L286cD48L3NwYW4+PC9w
Pg0KPC9kaXY+DQo8ZGl2Pg0KPHAgY2xhc3M9Ik1zb05vcm1hbCI+PHNwYW4gbGFuZz0iRU4tVVMi
IHN0eWxlPSJmb250LXNpemU6MTAuMHB0O2ZvbnQtZmFtaWx5OiZxdW90O0FyaWFsJnF1b3Q7LCZx
dW90O3NhbnMtc2VyaWYmcXVvdDs7Y29sb3I6IzFGNDk3RCI+Jm5ic3A7PC9zcGFuPjxzcGFuIGxh
bmc9IkVOLVVTIj48bzpwPjwvbzpwPjwvc3Bhbj48L3A+DQo8L2Rpdj4NCjxkaXY+DQo8cCBjbGFz
cz0iTXNvTm9ybWFsIj48c3BhbiBsYW5nPSJFTi1VUyIgc3R5bGU9ImZvbnQtc2l6ZToxMC4wcHQ7
Zm9udC1mYW1pbHk6JnF1b3Q7QXJpYWwmcXVvdDssJnF1b3Q7c2Fucy1zZXJpZiZxdW90Oztjb2xv
cjojMUY0OTdEIj5Zb3NoaWhpcm8gT2hiYTwvc3Bhbj48c3BhbiBsYW5nPSJFTi1VUyI+PG86cD48
L286cD48L3NwYW4+PC9wPg0KPC9kaXY+DQo8ZGl2Pg0KPHAgY2xhc3M9Ik1zb05vcm1hbCI+PHNw
YW4gbGFuZz0iRU4tVVMiIHN0eWxlPSJmb250LXNpemU6MTAuMHB0O2ZvbnQtZmFtaWx5OiZxdW90
O0FyaWFsJnF1b3Q7LCZxdW90O3NhbnMtc2VyaWYmcXVvdDs7Y29sb3I6IzFGNDk3RCI+Jm5ic3A7
PC9zcGFuPjxzcGFuIGxhbmc9IkVOLVVTIj48bzpwPjwvbzpwPjwvc3Bhbj48L3A+DQo8L2Rpdj4N
CjxkaXY+DQo8cCBjbGFzcz0iTXNvTm9ybWFsIj48c3BhbiBsYW5nPSJFTi1VUyIgc3R5bGU9ImZv
bnQtc2l6ZToxMC4wcHQ7Zm9udC1mYW1pbHk6JnF1b3Q7QXJpYWwmcXVvdDssJnF1b3Q7c2Fucy1z
ZXJpZiZxdW90Oztjb2xvcjojMUY0OTdEIj4mbmJzcDs8L3NwYW4+PHNwYW4gbGFuZz0iRU4tVVMi
PjxvOnA+PC9vOnA+PC9zcGFuPjwvcD4NCjwvZGl2Pg0KPGRpdj4NCjxwIGNsYXNzPSJNc29Ob3Jt
YWwiPjxzcGFuIGxhbmc9IkVOLVVTIiBzdHlsZT0iZm9udC1zaXplOjEwLjBwdDtmb250LWZhbWls
eTomcXVvdDtBcmlhbCZxdW90OywmcXVvdDtzYW5zLXNlcmlmJnF1b3Q7O2NvbG9yOiMxRjQ5N0Qi
PiZuYnNwOzwvc3Bhbj48c3BhbiBsYW5nPSJFTi1VUyI+PG86cD48L286cD48L3NwYW4+PC9wPg0K
PC9kaXY+DQo8ZGl2Pg0KPGRpdiBzdHlsZT0iYm9yZGVyOm5vbmU7Ym9yZGVyLXRvcDpzb2xpZCAj
RTFFMUUxIDEuMHB0O3BhZGRpbmc6My4wcHQgMG1tIDBtbSAwbW0iPg0KPGRpdj4NCjxwIGNsYXNz
PSJNc29Ob3JtYWwiPjxiPjxzcGFuIGxhbmc9IkVOLVVTIiBzdHlsZT0iZm9udC1zaXplOjExLjBw
dDtmb250LWZhbWlseTomcXVvdDtDYWxpYnJpJnF1b3Q7LCZxdW90O3NhbnMtc2VyaWYmcXVvdDsi
PkZyb206PC9zcGFuPjwvYj48c3BhbiBjbGFzcz0iYXBwbGUtY29udmVydGVkLXNwYWNlIj48c3Bh
biBsYW5nPSJFTi1VUyIgc3R5bGU9ImZvbnQtc2l6ZToxMS4wcHQ7Zm9udC1mYW1pbHk6JnF1b3Q7
Q2FsaWJyaSZxdW90OywmcXVvdDtzYW5zLXNlcmlmJnF1b3Q7Ij4mbmJzcDs8L3NwYW4+PC9zcGFu
PjxzcGFuIGxhbmc9IkVOLVVTIiBzdHlsZT0iZm9udC1zaXplOjExLjBwdDtmb250LWZhbWlseTom
cXVvdDtDYWxpYnJpJnF1b3Q7LCZxdW90O3NhbnMtc2VyaWYmcXVvdDsiPjZ0aXNjaC1zZWN1cml0
eQ0KIFs8YSBocmVmPSJtYWlsdG86NnRpc2NoLXNlY3VyaXR5LWJvdW5jZXNAaWV0Zi5vcmciPjxz
cGFuIHN0eWxlPSJjb2xvcjpwdXJwbGUiPm1haWx0bzo2dGlzY2gtc2VjdXJpdHktYm91bmNlc0Bp
ZXRmLm9yZzwvc3Bhbj48L2E+XTxzcGFuIGNsYXNzPSJhcHBsZS1jb252ZXJ0ZWQtc3BhY2UiPiZu
YnNwOzwvc3Bhbj48Yj5PbiBCZWhhbGYgT2Y8c3BhbiBjbGFzcz0iYXBwbGUtY29udmVydGVkLXNw
YWNlIj4mbmJzcDs8L3NwYW4+PC9iPkpvbmF0aGFuIFNpbW9uPGJyPg0KPGI+U2VudDo8L2I+PHNw
YW4gY2xhc3M9ImFwcGxlLWNvbnZlcnRlZC1zcGFjZSI+Jm5ic3A7PC9zcGFuPlRodXJzZGF5LCBN
YXkgMjksIDIwMTQgMTI6NDcgQU08YnI+DQo8Yj5Ubzo8L2I+PHNwYW4gY2xhc3M9ImFwcGxlLWNv
bnZlcnRlZC1zcGFjZSI+Jm5ic3A7PC9zcGFuPm9oYmEgeW9zaGloaXJvKDwvc3Bhbj48c3BhbiBz
dHlsZT0iZm9udC1zaXplOjExLjBwdCI+5aSn5aC0PC9zcGFuPjxzcGFuIGxhbmc9IkVOLVVTIiBz
dHlsZT0iZm9udC1zaXplOjExLjBwdDtmb250LWZhbWlseTomcXVvdDtDYWxpYnJpJnF1b3Q7LCZx
dW90O3NhbnMtc2VyaWYmcXVvdDsiPiZuYnNwOzwvc3Bhbj48c3BhbiBzdHlsZT0iZm9udC1zaXpl
OjExLjBwdCI+576p5rSLPC9zcGFuPjxzcGFuIGNsYXNzPSJhcHBsZS1jb252ZXJ0ZWQtc3BhY2Ui
PjxzcGFuIGxhbmc9IkVOLVVTIiBzdHlsZT0iZm9udC1zaXplOjExLjBwdDtmb250LWZhbWlseTom
cXVvdDtDYWxpYnJpJnF1b3Q7LCZxdW90O3NhbnMtc2VyaWYmcXVvdDsiPiZuYnNwOzwvc3Bhbj48
L3NwYW4+PHNwYW4gbGFuZz0iRU4tVVMiIHN0eWxlPSJmb250LXNpemU6MTEuMHB0O2ZvbnQtZmFt
aWx5OiZxdW90O0NhbGlicmkmcXVvdDssJnF1b3Q7c2Fucy1zZXJpZiZxdW90OyI+4peLPC9zcGFu
PjxzcGFuIHN0eWxlPSJmb250LXNpemU6MTEuMHB0Ij7vvLLvvKTvvKM8L3NwYW4+PHNwYW4gbGFu
Zz0iRU4tVVMiIHN0eWxlPSJmb250LXNpemU6MTEuMHB0O2ZvbnQtZmFtaWx5OiZxdW90O0NhbGli
cmkmcXVvdDssJnF1b3Q7c2Fucy1zZXJpZiZxdW90OyI+4pahPC9zcGFuPjxzcGFuIHN0eWxlPSJm
b250LXNpemU6MTEuMHB0Ij7vvK7vvLPvvKw8L3NwYW4+PHNwYW4gbGFuZz0iRU4tVVMiIHN0eWxl
PSJmb250LXNpemU6MTEuMHB0O2ZvbnQtZmFtaWx5OiZxdW90O0NhbGlicmkmcXVvdDssJnF1b3Q7
c2Fucy1zZXJpZiZxdW90OyI+KTxicj4NCjxiPkNjOjwvYj48c3BhbiBjbGFzcz0iYXBwbGUtY29u
dmVydGVkLXNwYWNlIj4mbmJzcDs8L3NwYW4+PGEgaHJlZj0ibWFpbHRvOm1jciYjNDM7aWV0ZkBz
YW5kZWxtYW4uY2EiPjxzcGFuIHN0eWxlPSJjb2xvcjpwdXJwbGUiPm1jciYjNDM7aWV0ZkBzYW5k
ZWxtYW4uY2E8L3NwYW4+PC9hPjs8c3BhbiBjbGFzcz0iYXBwbGUtY29udmVydGVkLXNwYWNlIj4m
bmJzcDs8L3NwYW4+PGEgaHJlZj0ibWFpbHRvOnJzdHJ1aWsuZXh0QGdtYWlsLmNvbSI+PHNwYW4g
c3R5bGU9ImNvbG9yOnB1cnBsZSI+cnN0cnVpay5leHRAZ21haWwuY29tPC9zcGFuPjwvYT47PHNw
YW4gY2xhc3M9ImFwcGxlLWNvbnZlcnRlZC1zcGFjZSI+Jm5ic3A7PC9zcGFuPjxhIGhyZWY9Im1h
aWx0bzo2dGlzY2gtc2VjdXJpdHlAaWV0Zi5vcmciPjxzcGFuIHN0eWxlPSJjb2xvcjpwdXJwbGUi
PjZ0aXNjaC1zZWN1cml0eUBpZXRmLm9yZzwvc3Bhbj48L2E+PGJyPg0KPGI+U3ViamVjdDo8L2I+
PHNwYW4gY2xhc3M9ImFwcGxlLWNvbnZlcnRlZC1zcGFjZSI+Jm5ic3A7PC9zcGFuPlJlOiBbNnRp
c2NoLXNlY3VyaXR5XSBhZ2VuZGEgZm9yIDIwMTQtMDUtMjcgNnRpc2NoIHNlY3VyaXR5IGNhbGw8
L3NwYW4+PHNwYW4gbGFuZz0iRU4tVVMiPjxvOnA+PC9vOnA+PC9zcGFuPjwvcD4NCjwvZGl2Pg0K
PC9kaXY+DQo8L2Rpdj4NCjxkaXY+DQo8cCBjbGFzcz0iTXNvTm9ybWFsIj48c3BhbiBsYW5nPSJF
Ti1VUyI+Jm5ic3A7PG86cD48L286cD48L3NwYW4+PC9wPg0KPC9kaXY+DQo8ZGl2Pg0KPHAgY2xh
c3M9Ik1zb05vcm1hbCI+PHNwYW4gbGFuZz0iRU4tVVMiPllvc2hpaGlybyAtPG86cD48L286cD48
L3NwYW4+PC9wPg0KPC9kaXY+DQo8ZGl2Pg0KPGRpdj4NCjxwIGNsYXNzPSJNc29Ob3JtYWwiPjxz
cGFuIGxhbmc9IkVOLVVTIj4mbmJzcDs8bzpwPjwvbzpwPjwvc3Bhbj48L3A+DQo8L2Rpdj4NCjwv
ZGl2Pg0KPGRpdj4NCjxkaXY+DQo8cCBjbGFzcz0iTXNvTm9ybWFsIj48c3BhbiBsYW5nPSJFTi1V
UyI+SSBkb248L3NwYW4+4oCZPHNwYW4gbGFuZz0iRU4tVVMiPnQgdGhpbmsgdGhpcyBpcyBhIHBy
b2JsZW0uICZuYnNwO05vZGVzIHRoYXQgYXJlIGluIHRoZSBuZXR3b3JrIHJlamVjdCBpbmNvbWlu
ZyBmcmFtZXMgc2VjdXJlZCB3aXRoIHRoZSB3ZWxsLWtub3duIGtleS4gVGhlIHdlbGwta25vd24g
a2V5IGlzIG9ubHkgdXNlZCB0byBhdXRoZW50aWNhdGUgYmVhY29ucywgYW5kIGF1dGhlbnRpY2F0
ZQ0KIGpvaW4gcmVxdWVzdHMgKHdoaWNoIGRvbjwvc3Bhbj7igJk8c3BhbiBsYW5nPSJFTi1VUyI+
dCBjYXJyeSBzeW5jaHJvbml6YXRpb24gaW5mb3JtYXRpb24pLiAmbmJzcDtUaGVyZSBpcyBhIERv
UyB2ZWN0b3IsIGluIHRoYXQgYW4gYXR0YWNrZXIgY2FuIGluamVjdCBqb2luaW5nIHRyYWZmaWMg
KGRlc3RpbmVkIGZvciB0aGUgbmV0d29yayBtYW5hbmFnZXIpIHRoYXQgd2lsbCB1bHRpbWF0ZWx5
IGJlIGRpc2NhcmRlZCwgcG9zc2libHkgcHJldmVudGluZyBvdGhlcg0KIG5vZGVzIGZyb20gam9p
bmluZywgYW5kIGluY3JlYXNpbmcgdGhlIHRyYWZmaWMgaW4gdGhlIG5ldHdvcmsuJm5ic3A7PG86
cD48L286cD48L3NwYW4+PC9wPg0KPC9kaXY+DQo8L2Rpdj4NCjxkaXY+DQo8ZGl2Pg0KPHAgY2xh
c3M9Ik1zb05vcm1hbCI+PHNwYW4gbGFuZz0iRU4tVVMiPiZuYnNwOzxvOnA+PC9vOnA+PC9zcGFu
PjwvcD4NCjwvZGl2Pg0KPGRpdj4NCjxkaXY+DQo8cCBjbGFzcz0iTXNvTm9ybWFsIj48c3BhbiBs
YW5nPSJFTi1VUyIgc3R5bGU9ImZvbnQtZmFtaWx5OiZxdW90O0x1Y2lkYSBHcmFuZGUmcXVvdDss
JnF1b3Q7c2VyaWYmcXVvdDsiPkpvbmF0aGFuIFNpbW9uLCBQaC4gRDxicj4NCkRpcmVjdG9yIG9m
IFN5c3RlbXMgRW5naW5lZXJpbmc8YnI+DQpMaW5lYXIgVGVjaG5vbG9neSwgRHVzdCBOZXR3b3Jr
cyBwcm9kdWN0IGdyb3VwPGJyPg0KMzA2OTUgSHVudHdvb2QgQXZlPGJyPg0KSGF5d2FyZCwgQ0Eg
OTQ1NDQtNzAyMTxicj4NCig1MTApIDQwMC0yOTM2PGJyPg0KKDUxMCkgNDg5LTM3OTkgRkFYPGJy
Pg0KPGEgaHJlZj0ibWFpbHRvOmpzaW1vbkBsaW5lYXIuY29tIj48c3BhbiBzdHlsZT0iY29sb3I6
cHVycGxlIj5qc2ltb25AbGluZWFyLmNvbTwvc3Bhbj48L2E+PGJyPg0KPGJyPg0KKipMSU5FQVIg
VEVDSE5PTE9HWSZuYnNwO0NPUlBPUkFUSU9OKiombmJzcDs8YnI+DQoqKioqKkludGVybmV0IEVt
YWlsIENvbmZpZGVudGlhbGl0eSZuYnNwO05vdGljZSoqKioqJm5ic3A7PGJyPg0KJm5ic3A7VGhp
cyBlLW1haWwgdHJhbnNtaXNzaW9uLCBhbmQgYW55Jm5ic3A7ZG9jdW1lbnRzLCBmaWxlcyBvciBw
cmV2aW91cyBlLW1haWwmbmJzcDttZXNzYWdlcyBhdHRhY2hlZCB0byBpdCBtYXkgY29udGFpbiZu
YnNwO2NvbmZpZGVudGlhbCBpbmZvcm1hdGlvbiB0aGF0IGlzJm5ic3A7bGVnYWxseSBwcml2aWxl
Z2VkLiBJZiB5b3UgYXJlIG5vdCB0aGUmbmJzcDtpbnRlbmRlZCByZWNpcGllbnQsIG9yIGEgcGVy
c29uJm5ic3A7cmVzcG9uc2libGUgZm9yIGRlbGl2ZXJpbmcgaXQgdG8gdGhlJm5ic3A7aW50ZW5k
ZWQNCiByZWNpcGllbnQsIHlvdSBhcmUgaGVyZWJ5Jm5ic3A7bm90aWZpZWQgdGhhdCBhbnkgZGlz
Y2xvc3VyZSwgY29weWluZywmbmJzcDtkaXN0cmlidXRpb24gb3IgdXNlIG9mIGFueSBvZiB0aGUm
bmJzcDtpbmZvcm1hdGlvbiBjb250YWluZWQgaW4gb3IgYXR0YWNoZWQmbmJzcDt0byB0aGlzIHRy
YW5zbWlzc2lvbiBpcyBTVFJJQ1RMWSZuYnNwO1BST0hJQklURUQuIElmIHlvdSBoYXZlIHJlY2Vp
dmVkIHRoaXMmbmJzcDt0cmFuc21pc3Npb24gaW4gZXJyb3IsIHBsZWFzZSZuYnNwO2ltbWVkaWF0
ZWx5IG5vdGlmeQ0KIG1lIGJ5IHJlcGx5IGUtbWFpbCwgb3IgYnkgdGVsZXBob25lIGF0ICg1MTAp
IDQwMC0yOTM2LCBhbmQgZGVzdHJveSB0aGUgb3JpZ2luYWwmbmJzcDt0cmFuc21pc3Npb24gYW5k
IGl0cyBhdHRhY2htZW50cyZuYnNwO3dpdGhvdXQgcmVhZGluZyBvciBzYXZpbmcgaW4gYW55Jm5i
c3A7bWFubmVyLiBUaGFuayB5b3UuJm5ic3A7PC9zcGFuPjxzcGFuIGxhbmc9IkVOLVVTIj48bzpw
PjwvbzpwPjwvc3Bhbj48L3A+DQo8L2Rpdj4NCjwvZGl2Pg0KPGRpdj4NCjxwIGNsYXNzPSJNc29O
b3JtYWwiPjxzcGFuIGxhbmc9IkVOLVVTIj4mbmJzcDs8bzpwPjwvbzpwPjwvc3Bhbj48L3A+DQo8
L2Rpdj4NCjxkaXY+DQo8ZGl2Pg0KPGRpdj4NCjxwIGNsYXNzPSJNc29Ob3JtYWwiPjxzcGFuIGxh
bmc9IkVOLVVTIj5PbiBNYXkgMjgsIDIwMTQsIGF0IDg6MDEgQU0sICZsdDs8YSBocmVmPSJtYWls
dG86eW9zaGloaXJvLm9oYmFAdG9zaGliYS5jby5qcCI+PHNwYW4gc3R5bGU9ImNvbG9yOnB1cnBs
ZSI+eW9zaGloaXJvLm9oYmFAdG9zaGliYS5jby5qcDwvc3Bhbj48L2E+Jmd0OyAmbHQ7PGEgaHJl
Zj0ibWFpbHRvOnlvc2hpaGlyby5vaGJhQHRvc2hpYmEuY28uanAiPjxzcGFuIHN0eWxlPSJjb2xv
cjpwdXJwbGUiPnlvc2hpaGlyby5vaGJhQHRvc2hpYmEuY28uanA8L3NwYW4+PC9hPiZndDsNCiB3
cm90ZTo8bzpwPjwvbzpwPjwvc3Bhbj48L3A+DQo8L2Rpdj4NCjwvZGl2Pg0KPGRpdj4NCjxwIGNs
YXNzPSJNc29Ob3JtYWwiPjxzcGFuIGxhbmc9IkVOLVVTIj48YnI+DQo8YnI+DQo8YnI+DQo8bzpw
PjwvbzpwPjwvc3Bhbj48L3A+DQo8L2Rpdj4NCjxibG9ja3F1b3RlIHN0eWxlPSJtYXJnaW4tdG9w
OjUuMHB0O21hcmdpbi1ib3R0b206NS4wcHQiPg0KPGRpdj4NCjxkaXY+DQo8cCBjbGFzcz0iTXNv
Tm9ybWFsIj48c3BhbiBsYW5nPSJFTi1VUyIgc3R5bGU9ImZvbnQtc2l6ZToxMC4wcHQ7Zm9udC1m
YW1pbHk6JnF1b3Q7QXJpYWwmcXVvdDssJnF1b3Q7c2Fucy1zZXJpZiZxdW90Oztjb2xvcjojMUY0
OTdEIj5IaSBKb25hdGhhbiw8L3NwYW4+PHNwYW4gbGFuZz0iRU4tVVMiPjxvOnA+PC9vOnA+PC9z
cGFuPjwvcD4NCjwvZGl2Pg0KPC9kaXY+DQo8ZGl2Pg0KPGRpdj4NCjxwIGNsYXNzPSJNc29Ob3Jt
YWwiPjxzcGFuIGxhbmc9IkVOLVVTIiBzdHlsZT0iZm9udC1zaXplOjEwLjBwdDtmb250LWZhbWls
eTomcXVvdDtBcmlhbCZxdW90OywmcXVvdDtzYW5zLXNlcmlmJnF1b3Q7O2NvbG9yOiMxRjQ5N0Qi
PiZuYnNwOzwvc3Bhbj48c3BhbiBsYW5nPSJFTi1VUyI+PG86cD48L286cD48L3NwYW4+PC9wPg0K
PC9kaXY+DQo8L2Rpdj4NCjxkaXY+DQo8ZGl2Pg0KPHAgY2xhc3M9Ik1zb05vcm1hbCI+PHNwYW4g
bGFuZz0iRU4tVVMiIHN0eWxlPSJmb250LXNpemU6MTAuMHB0O2ZvbnQtZmFtaWx5OiZxdW90O0Fy
aWFsJnF1b3Q7LCZxdW90O3NhbnMtc2VyaWYmcXVvdDs7Y29sb3I6IzFGNDk3RCI+VGhhbmsgeW91
IGZvciB5b3VyIGFuc3dlci48L3NwYW4+PHNwYW4gbGFuZz0iRU4tVVMiPjxvOnA+PC9vOnA+PC9z
cGFuPjwvcD4NCjwvZGl2Pg0KPC9kaXY+DQo8ZGl2Pg0KPGRpdj4NCjxwIGNsYXNzPSJNc29Ob3Jt
YWwiPjxzcGFuIGxhbmc9IkVOLVVTIiBzdHlsZT0iZm9udC1zaXplOjEwLjBwdDtmb250LWZhbWls
eTomcXVvdDtBcmlhbCZxdW90OywmcXVvdDtzYW5zLXNlcmlmJnF1b3Q7O2NvbG9yOiMxRjQ5N0Qi
PiZuYnNwOzwvc3Bhbj48c3BhbiBsYW5nPSJFTi1VUyI+PG86cD48L286cD48L3NwYW4+PC9wPg0K
PC9kaXY+DQo8L2Rpdj4NCjxkaXY+DQo8ZGl2Pg0KPHAgY2xhc3M9Ik1zb05vcm1hbCI+PHNwYW4g
bGFuZz0iRU4tVVMiIHN0eWxlPSJmb250LXNpemU6MTAuMHB0O2ZvbnQtZmFtaWx5OiZxdW90O0Fy
aWFsJnF1b3Q7LCZxdW90O3NhbnMtc2VyaWYmcXVvdDs7Y29sb3I6IzFGNDk3RCI+SSB0aGluayB0
aGlzIGNhbiBiZSBhbiBpc3N1ZSBpZiBhbHJlYWR5IGpvaW5lZCBub2RlcyBhbHNvIHVzZSB0aGUg
YmVhY29ucyBwcm90ZWN0ZWQgd2l0aCB0aGUgd2VsbC1rbm93biBrZXkgZm9yIG1haW50YWluaW5n
IHN5bmNocm9uaXphdGlvbiBhbmQgc2xvdA0KIGFsbG9jYXRpb25zLCBhcyBhbiBhdHRhY2tlciBj
YW4gc2VuZCBmb3JnZWQgYmVhY29ucyBwcm90ZWN0ZWQgd2l0aCB0aGUgd2VsbC1rbm93biBrZXku
PC9zcGFuPjxzcGFuIGxhbmc9IkVOLVVTIj48bzpwPjwvbzpwPjwvc3Bhbj48L3A+DQo8L2Rpdj4N
CjwvZGl2Pg0KPGRpdj4NCjxkaXY+DQo8cCBjbGFzcz0iTXNvTm9ybWFsIj48c3BhbiBsYW5nPSJF
Ti1VUyIgc3R5bGU9ImZvbnQtc2l6ZToxMC4wcHQ7Zm9udC1mYW1pbHk6JnF1b3Q7QXJpYWwmcXVv
dDssJnF1b3Q7c2Fucy1zZXJpZiZxdW90Oztjb2xvcjojMUY0OTdEIj4mbmJzcDs8L3NwYW4+PHNw
YW4gbGFuZz0iRU4tVVMiPjxvOnA+PC9vOnA+PC9zcGFuPjwvcD4NCjwvZGl2Pg0KPC9kaXY+DQo8
ZGl2Pg0KPGRpdj4NCjxwIGNsYXNzPSJNc29Ob3JtYWwiPjxzcGFuIGxhbmc9IkVOLVVTIiBzdHls
ZT0iZm9udC1zaXplOjEwLjBwdDtmb250LWZhbWlseTomcXVvdDtBcmlhbCZxdW90OywmcXVvdDtz
YW5zLXNlcmlmJnF1b3Q7O2NvbG9yOiMxRjQ5N0QiPllvc2hpaGlybyBPaGJhPC9zcGFuPjxzcGFu
IGxhbmc9IkVOLVVTIj48bzpwPjwvbzpwPjwvc3Bhbj48L3A+DQo8L2Rpdj4NCjwvZGl2Pg0KPGRp
dj4NCjxkaXY+DQo8cCBjbGFzcz0iTXNvTm9ybWFsIj48c3BhbiBsYW5nPSJFTi1VUyIgc3R5bGU9
ImZvbnQtc2l6ZToxMC4wcHQ7Zm9udC1mYW1pbHk6JnF1b3Q7QXJpYWwmcXVvdDssJnF1b3Q7c2Fu
cy1zZXJpZiZxdW90Oztjb2xvcjojMUY0OTdEIj4mbmJzcDs8L3NwYW4+PHNwYW4gbGFuZz0iRU4t
VVMiPjxvOnA+PC9vOnA+PC9zcGFuPjwvcD4NCjwvZGl2Pg0KPC9kaXY+DQo8ZGl2Pg0KPGRpdj4N
CjxwIGNsYXNzPSJNc29Ob3JtYWwiPjxzcGFuIGxhbmc9IkVOLVVTIiBzdHlsZT0iZm9udC1zaXpl
OjEwLjBwdDtmb250LWZhbWlseTomcXVvdDtBcmlhbCZxdW90OywmcXVvdDtzYW5zLXNlcmlmJnF1
b3Q7O2NvbG9yOiMxRjQ5N0QiPiZuYnNwOzwvc3Bhbj48c3BhbiBsYW5nPSJFTi1VUyI+PG86cD48
L286cD48L3NwYW4+PC9wPg0KPC9kaXY+DQo8L2Rpdj4NCjxkaXY+DQo8ZGl2Pg0KPHAgY2xhc3M9
Ik1zb05vcm1hbCI+PGI+PHNwYW4gbGFuZz0iRU4tVVMiIHN0eWxlPSJmb250LXNpemU6MTEuMHB0
O2ZvbnQtZmFtaWx5OiZxdW90O0NhbGlicmkmcXVvdDssJnF1b3Q7c2Fucy1zZXJpZiZxdW90OyI+
RnJvbTo8L3NwYW4+PC9iPjxzcGFuIGNsYXNzPSJhcHBsZS1jb252ZXJ0ZWQtc3BhY2UiPjxzcGFu
IGxhbmc9IkVOLVVTIiBzdHlsZT0iZm9udC1zaXplOjExLjBwdDtmb250LWZhbWlseTomcXVvdDtD
YWxpYnJpJnF1b3Q7LCZxdW90O3NhbnMtc2VyaWYmcXVvdDsiPiZuYnNwOzwvc3Bhbj48L3NwYW4+
PHNwYW4gbGFuZz0iRU4tVVMiIHN0eWxlPSJmb250LXNpemU6MTEuMHB0O2ZvbnQtZmFtaWx5OiZx
dW90O0NhbGlicmkmcXVvdDssJnF1b3Q7c2Fucy1zZXJpZiZxdW90OyI+NnRpc2NoLXNlY3VyaXR5
DQogWzxhIGhyZWY9Im1haWx0bzo2dGlzY2gtc2VjdXJpdHktYm91bmNlc0BpZXRmLm9yZyI+PHNw
YW4gc3R5bGU9ImNvbG9yOnB1cnBsZSI+bWFpbHRvOjZ0aXNjaC1zZWN1cml0eS1ib3VuY2VzQGll
dGYub3JnPC9zcGFuPjwvYT5dPHNwYW4gY2xhc3M9ImFwcGxlLWNvbnZlcnRlZC1zcGFjZSI+Jm5i
c3A7PC9zcGFuPjxiPk9uIEJlaGFsZiBPZjxzcGFuIGNsYXNzPSJhcHBsZS1jb252ZXJ0ZWQtc3Bh
Y2UiPiZuYnNwOzwvc3Bhbj48L2I+Sm9uYXRoYW4gU2ltb248YnI+DQo8Yj5TZW50OjwvYj48c3Bh
biBjbGFzcz0iYXBwbGUtY29udmVydGVkLXNwYWNlIj4mbmJzcDs8L3NwYW4+V2VkbmVzZGF5LCBN
YXkgMjgsIDIwMTQgMTE6NDkgUE08YnI+DQo8Yj5Ubzo8L2I+PHNwYW4gY2xhc3M9ImFwcGxlLWNv
bnZlcnRlZC1zcGFjZSI+Jm5ic3A7PC9zcGFuPm9oYmEgeW9zaGloaXJvKDwvc3Bhbj48c3BhbiBz
dHlsZT0iZm9udC1zaXplOjExLjBwdCI+5aSn5aC0PC9zcGFuPjxzcGFuIGxhbmc9IkVOLVVTIiBz
dHlsZT0iZm9udC1zaXplOjExLjBwdDtmb250LWZhbWlseTomcXVvdDtDYWxpYnJpJnF1b3Q7LCZx
dW90O3NhbnMtc2VyaWYmcXVvdDsiPiZuYnNwOzwvc3Bhbj48c3BhbiBzdHlsZT0iZm9udC1zaXpl
OjExLjBwdCI+576p5rSLPC9zcGFuPjxzcGFuIGNsYXNzPSJhcHBsZS1jb252ZXJ0ZWQtc3BhY2Ui
PjxzcGFuIGxhbmc9IkVOLVVTIiBzdHlsZT0iZm9udC1zaXplOjExLjBwdDtmb250LWZhbWlseTom
cXVvdDtDYWxpYnJpJnF1b3Q7LCZxdW90O3NhbnMtc2VyaWYmcXVvdDsiPiZuYnNwOzwvc3Bhbj48
L3NwYW4+PHNwYW4gbGFuZz0iRU4tVVMiIHN0eWxlPSJmb250LXNpemU6MTEuMHB0O2ZvbnQtZmFt
aWx5OiZxdW90O0NhbGlicmkmcXVvdDssJnF1b3Q7c2Fucy1zZXJpZiZxdW90OyI+4peLPC9zcGFu
PjxzcGFuIHN0eWxlPSJmb250LXNpemU6MTEuMHB0Ij7vvLLvvKTvvKM8L3NwYW4+PHNwYW4gbGFu
Zz0iRU4tVVMiIHN0eWxlPSJmb250LXNpemU6MTEuMHB0O2ZvbnQtZmFtaWx5OiZxdW90O0NhbGli
cmkmcXVvdDssJnF1b3Q7c2Fucy1zZXJpZiZxdW90OyI+4pahPC9zcGFuPjxzcGFuIHN0eWxlPSJm
b250LXNpemU6MTEuMHB0Ij7vvK7vvLPvvKw8L3NwYW4+PHNwYW4gbGFuZz0iRU4tVVMiIHN0eWxl
PSJmb250LXNpemU6MTEuMHB0O2ZvbnQtZmFtaWx5OiZxdW90O0NhbGlicmkmcXVvdDssJnF1b3Q7
c2Fucy1zZXJpZiZxdW90OyI+KTxicj4NCjxiPkNjOjwvYj48c3BhbiBjbGFzcz0iYXBwbGUtY29u
dmVydGVkLXNwYWNlIj4mbmJzcDs8L3NwYW4+TWljaGFlbCBSaWNoYXJkc29uOyBSZW5lIFN0cnVp
azs8c3BhbiBjbGFzcz0iYXBwbGUtY29udmVydGVkLXNwYWNlIj4mbmJzcDs8L3NwYW4+PGEgaHJl
Zj0ibWFpbHRvOjZ0aXNjaC1zZWN1cml0eUBpZXRmLm9yZyI+PHNwYW4gc3R5bGU9ImNvbG9yOnB1
cnBsZSI+NnRpc2NoLXNlY3VyaXR5QGlldGYub3JnPC9zcGFuPjwvYT48YnI+DQo8Yj5TdWJqZWN0
OjwvYj48c3BhbiBjbGFzcz0iYXBwbGUtY29udmVydGVkLXNwYWNlIj4mbmJzcDs8L3NwYW4+UmU6
IFs2dGlzY2gtc2VjdXJpdHldIGFnZW5kYSBmb3IgMjAxNC0wNS0yNyA2dGlzY2ggc2VjdXJpdHkg
Y2FsbDwvc3Bhbj48c3BhbiBsYW5nPSJFTi1VUyI+PG86cD48L286cD48L3NwYW4+PC9wPg0KPC9k
aXY+DQo8L2Rpdj4NCjxkaXY+DQo8ZGl2Pg0KPHAgY2xhc3M9Ik1zb05vcm1hbCI+PHNwYW4gbGFu
Zz0iRU4tVVMiPiZuYnNwOzxvOnA+PC9vOnA+PC9zcGFuPjwvcD4NCjwvZGl2Pg0KPC9kaXY+DQo8
ZGl2Pg0KPGRpdj4NCjxwIGNsYXNzPSJNc29Ob3JtYWwiIHN0eWxlPSJtYXJnaW4tYm90dG9tOjEy
LjBwdCI+PHNwYW4gbGFuZz0iRU4tVVMiPllvc2hpaGlybyAtPHNwYW4gY2xhc3M9ImFwcGxlLWNv
bnZlcnRlZC1zcGFjZSI+Jm5ic3A7PC9zcGFuPjxicj4NCjxicj4NClEuPHNwYW4gY2xhc3M9ImFw
cGxlLWNvbnZlcnRlZC1zcGFjZSI+Jm5ic3A7PC9zcGFuPjwvc3Bhbj48c3BhbiBsYW5nPSJFTi1V
UyIgc3R5bGU9ImZvbnQtc2l6ZToxMC4wcHQ7Zm9udC1mYW1pbHk6JnF1b3Q7QXJpYWwmcXVvdDss
JnF1b3Q7c2Fucy1zZXJpZiZxdW90Oztjb2xvcjojMUY0OTdEIj5JbiB3L0hBUlQsIGFyZSBhbGwg
YmVhY29uIGZyYW1lcyBhdXRoZW50aWNhdGVkIHdpdGggYSB3ZWxsLWtub3duIGtleSBldmVuIGFm
dGVyIGEgam9pbmluZyBub2RlIG9idGFpbmVkIHRoZSBydW50aW1lDQogbGluayBsYXllciBrZXk/
PC9zcGFuPjxzcGFuIGxhbmc9IkVOLVVTIj48bzpwPjwvbzpwPjwvc3Bhbj48L3A+DQo8L2Rpdj4N
CjxkaXY+DQo8cCBjbGFzcz0iTXNvTm9ybWFsIiBzdHlsZT0ibWFyZ2luLWJvdHRvbToxMi4wcHQi
PjxzcGFuIGxhbmc9IkVOLVVTIiBzdHlsZT0iZm9udC1zaXplOjEwLjBwdDtmb250LWZhbWlseTom
cXVvdDtBcmlhbCZxdW90OywmcXVvdDtzYW5zLXNlcmlmJnF1b3Q7O2NvbG9yOiMxRjQ5N0QiPkEu
IFllcy4gSW4gV2lyZWxlc3NIQVJUIHRoZSBiZWFjb25zIChjYWxsZWQgJnF1b3Q7YWR2ZXJ0aXNl
bWVudHMmcXVvdDsgYnV0IHRoZXkgc2VydmUgdGhlIHNhbWUgcHVycG9zZSBhbmQgaGF2ZSBzaW1p
bGFyIGNvbnRlbnQpDQogYXJlIGludGVuZGVkIGZvciBkZXZpY2VzIG5vdCB5ZXQgaW4gdGhlIG5l
dHdvcmssIHNvIHRoZXkgYWx3YXlzIHVzZSB0aGUgd2VsbC1rbm93biBrZXkuJm5ic3A7IFRvIGRp
c2NvdmVyIG90aGVyIG5vZGVzIHdpdGhpbiB0aGUgbmV0d29yaywgdGhleSB1c2UgZnJhbWVzIHNl
Y3VyZWQgd2l0aCB0aGUgcnVudGltZSBsaW5rLWxheWVyIGtleS48L3NwYW4+PHNwYW4gbGFuZz0i
RU4tVVMiPjxvOnA+PC9vOnA+PC9zcGFuPjwvcD4NCjwvZGl2Pg0KPGRpdj4NCjxkaXY+DQo8cCBj
bGFzcz0iTXNvTm9ybWFsIj48c3BhbiBsYW5nPSJFTi1VUyIgc3R5bGU9ImZvbnQtc2l6ZToxMC4w
cHQ7Zm9udC1mYW1pbHk6JnF1b3Q7QXJpYWwmcXVvdDssJnF1b3Q7c2Fucy1zZXJpZiZxdW90Oztj
b2xvcjojMUY0OTdEIj5Kb25hdGhhbjwvc3Bhbj48c3BhbiBsYW5nPSJFTi1VUyI+PG86cD48L286
cD48L3NwYW4+PC9wPg0KPC9kaXY+DQo8L2Rpdj4NCjwvZGl2Pg0KPGRpdj4NCjxwIGNsYXNzPSJN
c29Ob3JtYWwiIHN0eWxlPSJtYXJnaW4tYm90dG9tOjEyLjBwdCI+PHNwYW4gbGFuZz0iRU4tVVMi
PiZuYnNwOzxvOnA+PC9vOnA+PC9zcGFuPjwvcD4NCjxkaXY+DQo8ZGl2Pg0KPGRpdj4NCjxwIGNs
YXNzPSJNc29Ob3JtYWwiPjxzcGFuIGxhbmc9IkVOLVVTIj5PbiBUdWUsIE1heSAyNywgMjAxNCBh
dCAxMToxOCBQTSwgJmx0OzxhIGhyZWY9Im1haWx0bzp5b3NoaWhpcm8ub2hiYUB0b3NoaWJhLmNv
LmpwIiB0YXJnZXQ9Il9ibGFuayI+PHNwYW4gc3R5bGU9ImNvbG9yOnB1cnBsZSI+eW9zaGloaXJv
Lm9oYmFAdG9zaGliYS5jby5qcDwvc3Bhbj48L2E+Jmd0OyB3cm90ZTo8bzpwPjwvbzpwPjwvc3Bh
bj48L3A+DQo8L2Rpdj4NCjwvZGl2Pg0KPGJsb2NrcXVvdGUgc3R5bGU9ImJvcmRlcjpub25lO2Jv
cmRlci1sZWZ0OnNvbGlkICNDQ0NDQ0MgMS4wcHQ7cGFkZGluZzowbW0gMG1tIDBtbSA2LjBwdDtt
YXJnaW4tbGVmdDo0LjhwdDttYXJnaW4tdG9wOjUuMHB0O21hcmdpbi1yaWdodDowbW07bWFyZ2lu
LWJvdHRvbTo1LjBwdCI+DQo8ZGl2Pg0KPGRpdj4NCjxkaXY+DQo8cCBjbGFzcz0iTXNvTm9ybWFs
Ij48c3BhbiBsYW5nPSJFTi1VUyIgc3R5bGU9ImZvbnQtc2l6ZToxMC4wcHQ7Zm9udC1mYW1pbHk6
JnF1b3Q7QXJpYWwmcXVvdDssJnF1b3Q7c2Fucy1zZXJpZiZxdW90Oztjb2xvcjojMUY0OTdEIj5I
aSBKb25hdGhhbiw8L3NwYW4+PHNwYW4gbGFuZz0iRU4tVVMiPjxvOnA+PC9vOnA+PC9zcGFuPjwv
cD4NCjwvZGl2Pg0KPC9kaXY+DQo8ZGl2Pg0KPGRpdj4NCjxwIGNsYXNzPSJNc29Ob3JtYWwiPjxz
cGFuIGxhbmc9IkVOLVVTIiBzdHlsZT0iZm9udC1zaXplOjEwLjBwdDtmb250LWZhbWlseTomcXVv
dDtBcmlhbCZxdW90OywmcXVvdDtzYW5zLXNlcmlmJnF1b3Q7O2NvbG9yOiMxRjQ5N0QiPiZuYnNw
Ozwvc3Bhbj48c3BhbiBsYW5nPSJFTi1VUyI+PG86cD48L286cD48L3NwYW4+PC9wPg0KPC9kaXY+
DQo8L2Rpdj4NCjxkaXY+DQo8ZGl2Pg0KPHAgY2xhc3M9Ik1zb05vcm1hbCI+PHNwYW4gbGFuZz0i
RU4tVVMiIHN0eWxlPSJmb250LXNpemU6MTAuMHB0O2ZvbnQtZmFtaWx5OiZxdW90O0FyaWFsJnF1
b3Q7LCZxdW90O3NhbnMtc2VyaWYmcXVvdDs7Y29sb3I6IzFGNDk3RCI+VGhhbmsgeW91IGZvciBz
ZW5kaW5nIHRoZSBzdW1tYXJ5IG9mIHcvSEFSVCBqb2luaW5nLjwvc3Bhbj48c3BhbiBsYW5nPSJF
Ti1VUyI+PG86cD48L286cD48L3NwYW4+PC9wPg0KPC9kaXY+DQo8L2Rpdj4NCjxkaXY+DQo8ZGl2
Pg0KPHAgY2xhc3M9Ik1zb05vcm1hbCI+PHNwYW4gbGFuZz0iRU4tVVMiIHN0eWxlPSJmb250LXNp
emU6MTAuMHB0O2ZvbnQtZmFtaWx5OiZxdW90O0FyaWFsJnF1b3Q7LCZxdW90O3NhbnMtc2VyaWYm
cXVvdDs7Y29sb3I6IzFGNDk3RCI+Jm5ic3A7PC9zcGFuPjxzcGFuIGxhbmc9IkVOLVVTIj48bzpw
PjwvbzpwPjwvc3Bhbj48L3A+DQo8L2Rpdj4NCjwvZGl2Pg0KPGRpdj4NCjxkaXY+DQo8cCBjbGFz
cz0iTXNvTm9ybWFsIj48c3BhbiBsYW5nPSJFTi1VUyIgc3R5bGU9ImZvbnQtc2l6ZToxMC4wcHQ7
Zm9udC1mYW1pbHk6JnF1b3Q7QXJpYWwmcXVvdDssJnF1b3Q7c2Fucy1zZXJpZiZxdW90Oztjb2xv
cjojMUY0OTdEIj5JIGhhdmUgcXVlc3Rpb24uPC9zcGFuPjxzcGFuIGxhbmc9IkVOLVVTIj48bzpw
PjwvbzpwPjwvc3Bhbj48L3A+DQo8L2Rpdj4NCjwvZGl2Pg0KPGRpdj4NCjxkaXY+DQo8cCBjbGFz
cz0iTXNvTm9ybWFsIj48c3BhbiBsYW5nPSJFTi1VUyIgc3R5bGU9ImZvbnQtc2l6ZToxMC4wcHQ7
Zm9udC1mYW1pbHk6JnF1b3Q7QXJpYWwmcXVvdDssJnF1b3Q7c2Fucy1zZXJpZiZxdW90Oztjb2xv
cjojMUY0OTdEIj4mbmJzcDs8L3NwYW4+PHNwYW4gbGFuZz0iRU4tVVMiPjxvOnA+PC9vOnA+PC9z
cGFuPjwvcD4NCjwvZGl2Pg0KPC9kaXY+DQo8ZGl2Pg0KPGRpdj4NCjxwIGNsYXNzPSJNc29Ob3Jt
YWwiPjxzcGFuIGxhbmc9IkVOLVVTIiBzdHlsZT0iZm9udC1zaXplOjEwLjBwdDtmb250LWZhbWls
eTomcXVvdDtBcmlhbCZxdW90OywmcXVvdDtzYW5zLXNlcmlmJnF1b3Q7O2NvbG9yOiMxRjQ5N0Qi
PkluIHcvSEFSVCwgYXJlIGFsbCBiZWFjb24gZnJhbWVzIGF1dGhlbnRpY2F0ZWQgd2l0aCBhIHdl
bGwta25vd24ga2V5IGV2ZW4gYWZ0ZXIgYSBqb2luaW5nIG5vZGUgb2J0YWluZWQgdGhlIHJ1bnRp
bWUgbGluayBsYXllciBrZXk/Jm5ic3A7PC9zcGFuPjxzcGFuIGxhbmc9IkVOLVVTIj48bzpwPjwv
bzpwPjwvc3Bhbj48L3A+DQo8L2Rpdj4NCjwvZGl2Pg0KPGRpdj4NCjxkaXY+DQo8cCBjbGFzcz0i
TXNvTm9ybWFsIj48c3BhbiBsYW5nPSJFTi1VUyIgc3R5bGU9ImZvbnQtc2l6ZToxMC4wcHQ7Zm9u
dC1mYW1pbHk6JnF1b3Q7QXJpYWwmcXVvdDssJnF1b3Q7c2Fucy1zZXJpZiZxdW90Oztjb2xvcjoj
MUY0OTdEIj4mbmJzcDs8L3NwYW4+PHNwYW4gbGFuZz0iRU4tVVMiPjxvOnA+PC9vOnA+PC9zcGFu
PjwvcD4NCjwvZGl2Pg0KPC9kaXY+DQo8ZGl2Pg0KPGRpdj4NCjxwIGNsYXNzPSJNc29Ob3JtYWwi
PjxzcGFuIGxhbmc9IkVOLVVTIiBzdHlsZT0iZm9udC1zaXplOjEwLjBwdDtmb250LWZhbWlseTom
cXVvdDtBcmlhbCZxdW90OywmcXVvdDtzYW5zLXNlcmlmJnF1b3Q7O2NvbG9yOiMxRjQ5N0QiPlJl
Z2FyZHMsPC9zcGFuPjxzcGFuIGxhbmc9IkVOLVVTIj48bzpwPjwvbzpwPjwvc3Bhbj48L3A+DQo8
L2Rpdj4NCjwvZGl2Pg0KPGRpdj4NCjxkaXY+DQo8cCBjbGFzcz0iTXNvTm9ybWFsIj48c3BhbiBs
YW5nPSJFTi1VUyIgc3R5bGU9ImZvbnQtc2l6ZToxMC4wcHQ7Zm9udC1mYW1pbHk6JnF1b3Q7QXJp
YWwmcXVvdDssJnF1b3Q7c2Fucy1zZXJpZiZxdW90Oztjb2xvcjojMUY0OTdEIj5Zb3NoaWhpcm8g
T2hiYTwvc3Bhbj48c3BhbiBsYW5nPSJFTi1VUyI+PG86cD48L286cD48L3NwYW4+PC9wPg0KPC9k
aXY+DQo8L2Rpdj4NCjxkaXY+DQo8ZGl2Pg0KPHAgY2xhc3M9Ik1zb05vcm1hbCI+PHNwYW4gbGFu
Zz0iRU4tVVMiIHN0eWxlPSJmb250LXNpemU6MTAuMHB0O2ZvbnQtZmFtaWx5OiZxdW90O0FyaWFs
JnF1b3Q7LCZxdW90O3NhbnMtc2VyaWYmcXVvdDs7Y29sb3I6IzFGNDk3RCI+Jm5ic3A7PC9zcGFu
PjxzcGFuIGxhbmc9IkVOLVVTIj48bzpwPjwvbzpwPjwvc3Bhbj48L3A+DQo8L2Rpdj4NCjwvZGl2
Pg0KPGRpdj4NCjxkaXY+DQo8cCBjbGFzcz0iTXNvTm9ybWFsIj48c3BhbiBsYW5nPSJFTi1VUyIg
c3R5bGU9ImZvbnQtc2l6ZToxMC4wcHQ7Zm9udC1mYW1pbHk6JnF1b3Q7QXJpYWwmcXVvdDssJnF1
b3Q7c2Fucy1zZXJpZiZxdW90Oztjb2xvcjojMUY0OTdEIj4mbmJzcDs8L3NwYW4+PHNwYW4gbGFu
Zz0iRU4tVVMiPjxvOnA+PC9vOnA+PC9zcGFuPjwvcD4NCjwvZGl2Pg0KPC9kaXY+DQo8ZGl2Pg0K
PGRpdj4NCjxwIGNsYXNzPSJNc29Ob3JtYWwiPjxzcGFuIGxhbmc9IkVOLVVTIiBzdHlsZT0iZm9u
dC1zaXplOjEwLjBwdDtmb250LWZhbWlseTomcXVvdDtBcmlhbCZxdW90OywmcXVvdDtzYW5zLXNl
cmlmJnF1b3Q7O2NvbG9yOiMxRjQ5N0QiPiZuYnNwOzwvc3Bhbj48c3BhbiBsYW5nPSJFTi1VUyI+
PG86cD48L286cD48L3NwYW4+PC9wPg0KPC9kaXY+DQo8L2Rpdj4NCjxkaXY+DQo8ZGl2Pg0KPHAg
Y2xhc3M9Ik1zb05vcm1hbCI+PHNwYW4gbGFuZz0iRU4tVVMiIHN0eWxlPSJmb250LXNpemU6MTAu
MHB0O2ZvbnQtZmFtaWx5OiZxdW90O0FyaWFsJnF1b3Q7LCZxdW90O3NhbnMtc2VyaWYmcXVvdDs7
Y29sb3I6IzFGNDk3RCI+Jm5ic3A7PC9zcGFuPjxzcGFuIGxhbmc9IkVOLVVTIj48bzpwPjwvbzpw
Pjwvc3Bhbj48L3A+DQo8L2Rpdj4NCjwvZGl2Pg0KPGRpdj4NCjxkaXY+DQo8cCBjbGFzcz0iTXNv
Tm9ybWFsIj48Yj48c3BhbiBsYW5nPSJFTi1VUyIgc3R5bGU9ImZvbnQtc2l6ZToxMS4wcHQ7Zm9u
dC1mYW1pbHk6JnF1b3Q7Q2FsaWJyaSZxdW90OywmcXVvdDtzYW5zLXNlcmlmJnF1b3Q7Ij5Gcm9t
Ojwvc3Bhbj48L2I+PHNwYW4gY2xhc3M9ImFwcGxlLWNvbnZlcnRlZC1zcGFjZSI+PHNwYW4gbGFu
Zz0iRU4tVVMiIHN0eWxlPSJmb250LXNpemU6MTEuMHB0O2ZvbnQtZmFtaWx5OiZxdW90O0NhbGli
cmkmcXVvdDssJnF1b3Q7c2Fucy1zZXJpZiZxdW90OyI+Jm5ic3A7PC9zcGFuPjwvc3Bhbj48c3Bh
biBsYW5nPSJFTi1VUyIgc3R5bGU9ImZvbnQtc2l6ZToxMS4wcHQ7Zm9udC1mYW1pbHk6JnF1b3Q7
Q2FsaWJyaSZxdW90OywmcXVvdDtzYW5zLXNlcmlmJnF1b3Q7Ij42dGlzY2gtc2VjdXJpdHkNCiBb
bWFpbHRvOjxhIGhyZWY9Im1haWx0bzo2dGlzY2gtc2VjdXJpdHktYm91bmNlc0BpZXRmLm9yZyIg
dGFyZ2V0PSJfYmxhbmsiPjxzcGFuIHN0eWxlPSJjb2xvcjpwdXJwbGUiPjZ0aXNjaC1zZWN1cml0
eS1ib3VuY2VzQGlldGYub3JnPC9zcGFuPjwvYT5dPHNwYW4gY2xhc3M9ImFwcGxlLWNvbnZlcnRl
ZC1zcGFjZSI+Jm5ic3A7PC9zcGFuPjxiPk9uIEJlaGFsZiBPZjxzcGFuIGNsYXNzPSJhcHBsZS1j
b252ZXJ0ZWQtc3BhY2UiPiZuYnNwOzwvc3Bhbj48L2I+Sm9uYXRoYW4NCiBTaW1vbjxicj4NCjxi
PlNlbnQ6PC9iPjxzcGFuIGNsYXNzPSJhcHBsZS1jb252ZXJ0ZWQtc3BhY2UiPiZuYnNwOzwvc3Bh
bj5UdWVzZGF5LCBNYXkgMjcsIDIwMTQgMTA6NDEgUE08YnI+DQo8Yj5Ubzo8L2I+PHNwYW4gY2xh
c3M9ImFwcGxlLWNvbnZlcnRlZC1zcGFjZSI+Jm5ic3A7PC9zcGFuPlJlbmUgU3RydWlrPGJyPg0K
PGI+Q2M6PC9iPjxzcGFuIGNsYXNzPSJhcHBsZS1jb252ZXJ0ZWQtc3BhY2UiPiZuYnNwOzwvc3Bh
bj5NaWNoYWVsIFJpY2hhcmRzb247PHNwYW4gY2xhc3M9ImFwcGxlLWNvbnZlcnRlZC1zcGFjZSI+
Jm5ic3A7PC9zcGFuPjxhIGhyZWY9Im1haWx0bzo2dGlzY2gtc2VjdXJpdHlAaWV0Zi5vcmciIHRh
cmdldD0iX2JsYW5rIj48c3BhbiBzdHlsZT0iY29sb3I6cHVycGxlIj42dGlzY2gtc2VjdXJpdHlA
aWV0Zi5vcmc8L3NwYW4+PC9hPjxicj4NCjxiPlN1YmplY3Q6PC9iPjxzcGFuIGNsYXNzPSJhcHBs
ZS1jb252ZXJ0ZWQtc3BhY2UiPiZuYnNwOzwvc3Bhbj5SZTogWzZ0aXNjaC1zZWN1cml0eV0gYWdl
bmRhIGZvciAyMDE0LTA1LTI3IDZ0aXNjaCBzZWN1cml0eSBjYWxsPC9zcGFuPjxzcGFuIGxhbmc9
IkVOLVVTIj48bzpwPjwvbzpwPjwvc3Bhbj48L3A+DQo8L2Rpdj4NCjwvZGl2Pg0KPGRpdj4NCjxk
aXY+DQo8cCBjbGFzcz0iTXNvTm9ybWFsIj48c3BhbiBsYW5nPSJFTi1VUyI+Jm5ic3A7PG86cD48
L286cD48L3NwYW4+PC9wPg0KPC9kaXY+DQo8L2Rpdj4NCjxkaXY+DQo8ZGl2Pg0KPGRpdj4NCjxw
IGNsYXNzPSJNc29Ob3JtYWwiIHN0eWxlPSJtYXJnaW4tYm90dG9tOjEyLjBwdCI+PHNwYW4gbGFu
Zz0iRU4tVVMiPlJlbmUgaGFkIGFza2VkIG9uIGEgcHJldmlvdXMgY2FsbCBmb3Igc29tZW9uZSB0
byBzdW1tYXJpemUgV2lyZWxlc3NIQVJUIGpvaW5pbmcgLSBoZXJlIHlvdSBnby48YnI+DQo8YnI+
DQoqIE9uZSBvciBtb3JlIGRldmljZXMgYXJlIHNlbmRpbmcgYmVhY29ucyB0byBhZHZlcnRpc2Ug
dGhlIHByZXNlbmNlIG9mIHRoZSBuZXR3b3JrLiBJbiBXaXJlbGVzc0hBUlQsIHRoaXMgZnJhbWUg
aXMgdW5lbmNyeXB0ZWQsIGJ1dCBhdXRoZW50aWNhdGVkIHdpdGggYSB3ZWxsIGtub3duIGtleS4m
bmJzcDsgVGhlIGJlYWNvbiBjb250YWlucyB0aGUgY3VycmVudCBBU04sIHdoaWNoIHRoZSBqb2lu
aW5nIGRldmljZSB1c2VzIHRvIHN5bmNocm9uaXplIGl0cyBjbG9jay48bzpwPjwvbzpwPjwvc3Bh
bj48L3A+DQo8ZGl2Pg0KPHAgY2xhc3M9Ik1zb05vcm1hbCIgc3R5bGU9Im1hcmdpbi1ib3R0b206
MTIuMHB0Ij48c3BhbiBsYW5nPSJFTi1VUyI+KiBPbmNlIHRoZSBqb2luaW5nIG5vZGUgaGFzIGhl
YXJkIGEgYmVhY29uLCBpdCBjb250aW51ZXMgbGlzdGVuaW5nIGZvciBhZGRpdGlvbmFsIGJlYWNv
bnMgZm9yIGEgc2hvcnQgc3BlY2lmaWVkIHRpbWVvdXQuPG86cD48L286cD48L3NwYW4+PC9wPg0K
PC9kaXY+DQo8cCBjbGFzcz0iTXNvTm9ybWFsIiBzdHlsZT0ibWFyZ2luLWJvdHRvbToxMi4wcHQi
PjxzcGFuIGxhbmc9IkVOLVVTIj4qIFRoZSBqb2luaW5nIG5vZGUgZW5jcnlwdHMgYSBmcmFtZSBj
b250YWluaW5nIHNvbWUgSEFSVCBzcGVjaWZpYyBjb250ZW50LCBpbmNsdWRpbmcgYSBsaXN0IG9m
IGJlYWNvbmluZyBuZWlnaGJvcnMgaXQgaGVhcmQgaW4gdGhlIHByZXZpb3VzIHN0ZXBzLiBUaGUg
c2l6ZSBvZiB0aGUgcGF5bG9hZCBpcyB+IDYwIGJ5dGVzLiZuYnNwOyBUaGUNCiBwYWNrZXQgaXMg
cm91dGVkIGJ5IGEgJnF1b3Q7cHJveHkmcXVvdDsgbm9kZSAtIHRoZSBqb2luaW5nIHBhcmVudC4g
VGhlIGZyYW1lIGlzIGF1dGhlbnRpY2F0ZWQgdXNpbmcgdGhlIHdlbGwta25vd24ga2V5LCBhbmQg
ZW5jcnlwdGVkIHVzaW5nIGEgc2hhcmVkIHN5bW1ldHJpYyBrZXkga25vd24gb25seSBieSB0aGUg
bm9kZSBhbmQgdGhlIG1hbmFnZXIuPGJyPg0KPGJyPg0KKiBUaGUgbWFuYWdlciByZXNwb25kcyB3
aXRoIGEgZnJhbWUgY29udGFpbmluZyB0aGUgcnVuLXRpbWUgbGluay1sYXllciBrZXksIHRoZSBu
b2RlJ3MgbmV3IHNob3J0IGFkZHJlc3MgKHRoaXMgdGFrZXMgdGhlIHBsYWNlIG9mIFBBTiBjb29y
ZGluYXRvciBhc3NvY2lhdGlvbiksIGFuZCBhIHVuaWNhc3Qgc2Vzc2lvbiBrZXkgYW5kIHN0YXJ0
aW5nIG5vbmNlIGZvciB0aGUgbWFuYWdlci4gVGhpcyBmcmFtZSBpcyBlbmNyeXB0ZWQgd2l0aCB0
aGUgc3ltbWV0cmljDQoga2V5LiBUaGUgcGF5bG9hZCBpcyB+IDYwIGJ5dGVzLCBhbmQgaXMgcm91
dGVkIHRvIHRoZSBwcm94eSBmb3IgZGVsaXZlcnkgdG8gdGhlIGpvaW5pbmcgbm9kZSAtIHRoZSBw
cm94eSB1c2VzIHRoZSBsaW5rLWxheWVyIHdlbGwga25vd24ga2V5IG9uIHRoZSBmcmFtZS48bzpw
PjwvbzpwPjwvc3Bhbj48L3A+DQo8ZGl2Pg0KPHAgY2xhc3M9Ik1zb05vcm1hbCIgc3R5bGU9Im1h
cmdpbi1ib3R0b206MTIuMHB0Ij48c3BhbiBsYW5nPSJFTi1VUyI+KiBBdCB0aGlzIHBvaW50IHRo
ZSBqb2luaW5nIG5vZGUgdHJhbnNpdGlvbnMgdG8gdXNpbmcgdGhlIHJ1bi10aW1lIGxpbmstbGF5
ZXIga2V5IGZvciBhbGwgbGluay1sYXllciBmcmFtZXMsIGFuZCB0aGUgbWFuYWdlciB1bmljYXN0
IHNlc3Npb24gZm9yIGVuZC10by1lbmQgbWFuYWdlciB0cmFmZmljLiBUaGlzIGVuZHMgdGhlIGlu
aXRpYWwNCiBzZWN1cml0eSBoYW5kc2hha2UuPG86cD48L286cD48L3NwYW4+PC9wPg0KPC9kaXY+
DQo8ZGl2Pg0KPHAgY2xhc3M9Ik1zb05vcm1hbCIgc3R5bGU9Im1hcmdpbi1ib3R0b206MTIuMHB0
Ij48c3BhbiBsYW5nPSJFTi1VUyI+KiBPdmVyIGEgbnVtYmVyIG9mIGFkZGl0aW9uYWwgZnJhbWVz
LCB0aGUgbWFuYWdlciBhc3NpZ25zIGFkZGl0aW9uYWwgc2Vzc2lvbnMsIGluY2x1ZGluZyBicm9h
ZGNhc3Qgc2Vzc2lvbnMsIGFuZCBhIHVuaWNhc3Qgc2Vzc2lvbiB0byB0aGUgR2F0ZXdheSAoc2lu
ayBmb3IgYWxsIGRhdGEgdHJhZmZpYyksIGFuZCBhZGRpdGlvbmFsDQogY29tbXVuaWNhdGlvbnMg
cmVzb3VyY2VzLCByb3V0aW5nIGluZm9ybWF0aW9uLCBldGMuJm5ic3A7IFRoZXJlIGlzIG5vIGV4
cGxpY2l0IHRyYW5zaXRpb24gZnJvbSBqb2luaW5nIHRvIGpvaW5lZCAtIHRoZSBtb3RlIHRyYW5z
aXRpb25zIHdoZW4gY2VydGFpbiBrZXkgZnJhbWVzIGFyZSByZWNlaXZlZC48bzpwPjwvbzpwPjwv
c3Bhbj48L3A+DQo8L2Rpdj4NCjxwIGNsYXNzPSJNc29Ob3JtYWwiIHN0eWxlPSJtYXJnaW4tYm90
dG9tOjEyLjBwdCI+PHNwYW4gbGFuZz0iRU4tVVMiPiogTm90ZSB0aGF0IGEgV2lyZWxlc3NIQVJU
IGxpbmstbGF5ZXIgZnJhbWUgY29udGFpbnMgYW5kIGFkZGl0aW9uYWwgZnJhbWUgdHlwZSBieXRl
IGFuZCBhIDQtYnl0ZSBsaW5rLWxheWVyIE1JQywgb24gdG9wIG9mIHRoZSB1bnNlY3VyZWQgMTUu
NCBmcmFtZS4mbmJzcDsgQSBuZXR3b3JrIGZyYW1lIGNvbnRhaW5zIGFuIGFkZGl0aW9uYWwNCiAx
Ni00MCBieXRlcyBvZiBhZGRyZXNzaW5nLCByb3V0aW5nLCBzZWN1cml0eSBhbmQgb3RoZXIgaW5m
b3JtYXRpb24uPG86cD48L286cD48L3NwYW4+PC9wPg0KPC9kaXY+DQo8cCBjbGFzcz0iTXNvTm9y
bWFsIiBzdHlsZT0ibWFyZ2luLWJvdHRvbToxMi4wcHQiPjxzcGFuIGxhbmc9IkVOLVVTIj5Ib3Bl
IHRoaXMgaGVscCE8bzpwPjwvbzpwPjwvc3Bhbj48L3A+DQo8L2Rpdj4NCjxkaXY+DQo8ZGl2Pg0K
PHAgY2xhc3M9Ik1zb05vcm1hbCI+PHNwYW4gbGFuZz0iRU4tVVMiPkpvbmF0aGFuPG86cD48L286
cD48L3NwYW4+PC9wPg0KPC9kaXY+DQo8L2Rpdj4NCjxkaXY+DQo8ZGl2Pg0KPHAgY2xhc3M9Ik1z
b05vcm1hbCI+PHNwYW4gbGFuZz0iRU4tVVMiPiZuYnNwOzxvOnA+PC9vOnA+PC9zcGFuPjwvcD4N
CjwvZGl2Pg0KPC9kaXY+DQo8L2Rpdj4NCjxkaXY+DQo8cCBjbGFzcz0iTXNvTm9ybWFsIiBzdHls
ZT0ibWFyZ2luLWJvdHRvbToxMi4wcHQiPjxzcGFuIGxhbmc9IkVOLVVTIj4mbmJzcDs8bzpwPjwv
bzpwPjwvc3Bhbj48L3A+DQo8ZGl2Pg0KPGRpdj4NCjxkaXY+DQo8cCBjbGFzcz0iTXNvTm9ybWFs
Ij48c3BhbiBsYW5nPSJFTi1VUyI+T24gTW9uLCBNYXkgMjYsIDIwMTQgYXQgODowOSBQTSwgUmVu
ZSBTdHJ1aWsgJmx0OzxhIGhyZWY9Im1haWx0bzpyc3RydWlrLmV4dEBnbWFpbC5jb20iIHRhcmdl
dD0iX2JsYW5rIj48c3BhbiBzdHlsZT0iY29sb3I6cHVycGxlIj5yc3RydWlrLmV4dEBnbWFpbC5j
b208L3NwYW4+PC9hPiZndDsgd3JvdGU6PG86cD48L286cD48L3NwYW4+PC9wPg0KPC9kaXY+DQo8
L2Rpdj4NCjxibG9ja3F1b3RlIHN0eWxlPSJib3JkZXI6bm9uZTtib3JkZXItbGVmdDpzb2xpZCAj
Q0NDQ0NDIDEuMHB0O3BhZGRpbmc6MG1tIDBtbSAwbW0gNi4wcHQ7bWFyZ2luLWxlZnQ6NC44cHQ7
bWFyZ2luLXRvcDo1LjBwdDttYXJnaW4tcmlnaHQ6MG1tO21hcmdpbi1ib3R0b206NS4wcHQiPg0K
PGRpdj4NCjxkaXY+DQo8ZGl2Pg0KPHAgY2xhc3M9Ik1zb05vcm1hbCI+PHNwYW4gbGFuZz0iRU4t
VVMiPkhpIE1pY2hhZWw6PGJyPg0KPGJyPg0KSSB3b3VsZCBsaWtlIHRvIGRpc2N1c3MgdGhlIG91
dHN0YW5kaW5nIGlzc3VlcyBJIHN1bW1hcml6ZWQgaW4gbXkgZW1haWwgb2YgVHVlIGxhc3Qgd2Vl
aywgTWF5IDIwLCAyMDE0LCA5OjQ1YW0gRURUIChzZWU8c3BhbiBjbGFzcz0iYXBwbGUtY29udmVy
dGVkLXNwYWNlIj4mbmJzcDs8L3NwYW4+PGEgaHJlZj0iaHR0cDovL2NwLm1jYWZlZS5jb20vZC81
ZkhDTVVwNDFFU3lOdDU1T1d0U2p0UHFid1ZCY1N5VWVwdmRFSzN6aE95Q09xZWpyelBQUHo1WENO
NkFCcU0xaFlFdkl1bmRET3gtTlZzVEpRWElmY0xadkM0VFFUUzZlTHNLQ08tUFBYWDNYVVZ6QkhG
U2hqbEtlcFZrZmZHaEJyd3FyaGRJNlhZeU1DWS1laG9qZDc5S1ZJMDViVktZMDFNamJYNk5laERZ
MDV6QVZrSWpiUS1Qc3BqYnBwS2N2eGY1cTRyVEtZVk1lZEtqQmlOY0xqWGROQmNJbjhscnhyVzBH
blB0VTAycmhodWhLcjF2RjZ5MFFKS2pCaU5jTGpYZE5CY0lxbmpoMUY3VThxcTg3cU5kNDJ0UW0y
WlRPV29VUWdlakJpTmNRZ2stUHNwamI2eTJTRERDVDYzcE9fbyIgdGFyZ2V0PSJfYmxhbmsiPjxz
cGFuIHN0eWxlPSJjb2xvcjpwdXJwbGUiPmh0dHA6Ly93d3cuaWV0Zi5vcmcvbWFpbC1hcmNoaXZl
L3dlYi82dGlzY2gtc2VjdXJpdHkvY3VycmVudC9tc2cwMDA4Ni5odG1sPC9zcGFuPjwvYT4pLg0K
IFRoaXMgd2FzIGFsc28gb25lIG9mIHRoZSBhY3Rpb24gaXRlbXMgYXQgdGhlIGNvbmNsdXNpb24g
b2YgbGFzdCB3ZWVrJ3MgNlRpU0NIIHNlY3VyaXR5IGNhbGwuPGJyPg0KPGJyPg0KRllJIC0gdGhl
IHcvSEFSVCBjb21tdW5pY2F0aW9uIGZsb3dzIHdlcmUgZGlzY3Vzc2VkIGR1cmluZyB0aGUgNlRp
U0NIIHNlY3VyaXR5IGNvbmYgY2FsbCB0aGUgd2VlayBiZWZvcmUsIG9uIE1vbiBNYXkgMTIsIDIw
MTQuIElmIG9uZSB3aXNoZXMgdG8gZ28gb3ZlciB0aGlzIGFnYWluLCB0aGF0IGlzIGZpbmUsIGJ1
dCBJIHdvdWxkIHByZWZlciB1cyBnaXZpbmcgcHJlZmVyZW5jZSB0byB0YWtpbmcgb24gYWxyZWFk
eSBhcnRpY3VsYXRlZCBpc3N1ZXMNCiAod2hpY2ggd2VyZSBhc3NpZ25lZCBhcyBob21ld29yayBh
c3NpZ25tZW50IHRvIHJlZmxlY3QgdXBvbikgZmlyc3QgKGkuZS4sIHByaW9yIHRvIGl0ZW0gIzQg
b2YgdGhlIHByb3Bvc2VkIGFnZW5kYSkuPGJyPg0KPGJyPg0KQXMgYW5vdGhlciBhZ2VuZGEgcG9p
bnQsIEkgd291bGQgbGlrZSB1cyB0byBkaXNjdXNzIHRoZSBmcmVxdWVuY3kgb2YgZnV0dXJlIGNh
bGxzIChhcyBwYXJ0IG9mIEVPQikuPGJyPg0KPGJyPg0KQmVzdCByZWdhcmRzLCBSZW5lPGJyPg0K
PGJyPg0KPGJyPg0KT24gNS8yNi8yMDE0IDEwOjQ5IFBNLCBNaWNoYWVsIFJpY2hhcmRzb24gd3Jv
dGU6PG86cD48L286cD48L3NwYW4+PC9wPg0KPC9kaXY+DQo8L2Rpdj4NCjxibG9ja3F1b3RlIHN0
eWxlPSJtYXJnaW4tdG9wOjUuMHB0O21hcmdpbi1ib3R0b206NS4wcHQiPg0KPHByZT48c3BhbiBs
YW5nPSJFTi1VUyI+VG8gcmVtaW5kLCB3ZSBtb3ZlZCB0aGUgY2FsbCBmcm9tIHRoZSAyNnRoIHRv
IHRoZSAyN3RoIGF0IDEwYW0gRURULjxvOnA+PC9vOnA+PC9zcGFuPjwvcHJlPg0KPHByZT48c3Bh
biBsYW5nPSJFTi1VUyI+VGhhdCdzIDkwIG1pbnV0ZXMgZnJvbSB0aGlzIGVtYWlsLjxvOnA+PC9v
OnA+PC9zcGFuPjwvcHJlPg0KPHByZT48c3BhbiBsYW5nPSJFTi1VUyI+Jm5ic3A7PG86cD48L286
cD48L3NwYW4+PC9wcmU+DQo8cHJlPjxzcGFuIGxhbmc9IkVOLVVTIj4xKSBub3Rld2VsbC48bzpw
PjwvbzpwPjwvc3Bhbj48L3ByZT4NCjxwcmU+PHNwYW4gbGFuZz0iRU4tVVMiPjIpIGludHJvczxv
OnA+PC9vOnA+PC9zcGFuPjwvcHJlPg0KPHByZT48c3BhbiBsYW5nPSJFTi1VUyI+MykgcmVjYXAg
b2YgZHJhZnQtcGlyby08bzpwPjwvbzpwPjwvc3Bhbj48L3ByZT4NCjxwcmU+PHNwYW4gbGFuZz0i
RU4tVVMiPjQpIHdpcmVsZXNzaGFydCAtd2F5IC0tLSBob3cgZG9lcyB0aGUgY29tbXVuaWNhdGlv
biB3b3JrPzxvOnA+PC9vOnA+PC9zcGFuPjwvcHJlPg0KPHByZT48c3BhbiBsYW5nPSJFTi1VUyI+
NSkgaG93IHRvIHN1bW1hcml6ZSBhbGwgb2YgdGhpcyB0byB0aGUgd29ya2luZyBncm91cDxvOnA+
PC9vOnA+PC9zcGFuPjwvcHJlPg0KPHByZT48c3BhbiBsYW5nPSJFTi1VUyI+NikgaG93IHRvIGNs
b3NlIHRoaXMgcHJvY2VzcyB1cD88bzpwPjwvbzpwPjwvc3Bhbj48L3ByZT4NCjxwcmU+PHNwYW4g
bGFuZz0iRU4tVVMiPiZuYnNwOzxvOnA+PC9vOnA+PC9zcGFuPjwvcHJlPg0KPHByZT48c3BhbiBs
YW5nPSJFTi1VUyI+LS0gcmVtZW1iZXIgdGhhdCB0aGUgY2FsbCBpcyByZWNvcmRlZCwgYW5kIHRo
ZSBOb3RlV2VsbCBhcHBsaWVzLjxvOnA+PC9vOnA+PC9zcGFuPjwvcHJlPg0KPHByZT48c3BhbiBs
YW5nPSJFTi1VUyI+Jm5ic3A7PG86cD48L286cD48L3NwYW4+PC9wcmU+DQo8cHJlPjxzcGFuIGxh
bmc9IkVOLVVTIj4tLSBUaGUgVVJMIHRvIGFjY2VzcyB0aGUgd2ViZXgsIHdoaWNoIHdpbGwgd2Ug
dXNlIGZvciBhdWRpbyBvbmx5OjxvOnA+PC9vOnA+PC9zcGFuPjwvcHJlPg0KPHByZT48c3BhbiBs
YW5nPSJFTi1VUyI+Jm5ic3A7IDxhIGhyZWY9Imh0dHA6Ly9jcC5tY2FmZWUuY29tL2QvNWZIQ04w
U3lOdDU1T1d0U2p0UHFid1ZCY1N5VWVwdmRFSzN6aE95Q09xZWpyelBQUHo1WENONkFCcU0xaFlF
dkl1bmRET3gtTlZzVEpRWElmY0xadkM0VFFUUzZlTHNLQ08tUFBYWDNYVVZ6QkhGU2hqbEtlcFZr
ZmZHaEJyd3FyamRJNlhZeU1DWS1laG9qZDc5S1ZJRGVxUjRJT1FHbUhNMEwzLW5PUUdtSHd6TWg5
M285M2dVVmxkVFFtamhPZ3R1N2VtX212SVVDZXZMcDFaV1Ywc3Flckw2VDlPRm9DbkZaQ1VPQ21i
QWFKTUpaMGxiVktZMDFkRUVMOFRkd0xRemgwcW1UOU9Gb0NuRlpDVU9DbWRiRkV3UXpZNGRkNDNK
b0N5MWVXYjF1WFZ0Y3NxODc5T0ZvQ3E4YXZwS2NGQnpoMXJqUFByejFMbVR3N3cxNyIgdGFyZ2V0
PSJfYmxhbmsiPjxzcGFuIHN0eWxlPSJjb2xvcjpwdXJwbGUiPmh0dHBzOi8vY2lzY28ud2ViZXgu
Y29tL2Npc2NvL2oucGhwP01USUQ9bTJmZTEzOWJmODc2Y2VhM2VjNjI3NTBjZDU4MGI3OTA4PC9z
cGFuPjwvYT48bzpwPjwvbzpwPjwvc3Bhbj48L3ByZT4NCjxwcmU+PHNwYW4gbGFuZz0iRU4tVVMi
PiZuYnNwOzxvOnA+PC9vOnA+PC9zcGFuPjwvcHJlPg0KPHByZT48c3BhbiBsYW5nPSJFTi1VUyI+
LS0gd2Ugd2lsbCByZXN1bWUgd2l0aCB0aGUgZXRoZXJwYWQgYXQ6PG86cD48L286cD48L3NwYW4+
PC9wcmU+DQo8cHJlPjxzcGFuIGxhbmc9IkVOLVVTIj4mbmJzcDsmbmJzcDsgPGEgaHJlZj0iaHR0
cDovL2NwLm1jYWZlZS5jb20vZC8yRFJQb3c3MU5KNXlXYWJCUVhJQ1hDUW4xUGFwSjVNc08tcmhz
NzZ6QjVkQVFzQ1Q3RERENmJUZHlkOWFSdzJ6Vmdfb1lLcmZCM1p6T1ZMckZUb3VwdldfYzlMRkxJ
Y3R1VnRkQlpERFRTN1ROUDdibmpJeUNIc3NQT0V1dmt6YVQwUVNPcm9kVFY1eGRWWXN5TUNxZWp0
UG8wZlZBX3lKRzdqSGstRGktckwwMGt6aFB1WlltTzVwX2dMYlZLQlR6aE9uc0RhQnlwdURTcnph
cG9TVmVsYjRPWmZJVDZrT05zeGxLNUxFMkZ2ZFR3MDlKNTVWNlZJNS1BcTgzaVNWZWxiNE9aZklU
NmtPTkZ0ZDQ2QXZ3eEZFd3RINFFnOVRob2JUdmJGenpoMFZlbGI0UGgxalhkTkJjSXE4YnF1dXJz
b2RKaVp2cG1LNkd3WSIgdGFyZ2V0PSJfYmxhbmsiPjxzcGFuIHN0eWxlPSJjb2xvcjpwdXJwbGUi
Pmh0dHA6Ly9ldGhlcnBhZC50b29scy5pZXRmLm9yZzo5MDAwL3Avbm90ZXMtaWV0Zi04OS02dGlz
Y2gtc2VjdXJpdHk8L3NwYW4+PC9hPjxvOnA+PC9vOnA+PC9zcGFuPjwvcHJlPg0KPHByZT48c3Bh
biBsYW5nPSJFTi1VUyI+Jm5ic3A7PG86cD48L286cD48L3NwYW4+PC9wcmU+DQo8cHJlPjxzcGFu
IGxhbmc9IkVOLVVTIj5JJ20gYXQgPGEgaHJlZj0idGVsOiUyQjElMjA2MTMlMjAyNzYtNjgwOSIg
dGFyZ2V0PSJfYmxhbmsiPjxzcGFuIHN0eWxlPSJjb2xvcjpwdXJwbGUiPiYjNDM7MSA2MTMgMjc2
LTY4MDk8L3NwYW4+PC9hPiwgSU06IDxhIGhyZWY9Im1haWx0bzptY3JAeG1wcC5jcmVkaWwub3Jn
IiB0YXJnZXQ9Il9ibGFuayI+PHNwYW4gc3R5bGU9ImNvbG9yOnB1cnBsZSI+bWNyQHhtcHAuY3Jl
ZGlsLm9yZzwvc3Bhbj48L2E+IG9yIDxhIGhyZWY9Im1haWx0bzptY2hhcmxlc3JAZ21haWwuY29t
IiB0YXJnZXQ9Il9ibGFuayI+PHNwYW4gc3R5bGU9ImNvbG9yOnB1cnBsZSI+bWNoYXJsZXNyQGdt
YWlsLmNvbTwvc3Bhbj48L2E+LDxvOnA+PC9vOnA+PC9zcGFuPjwvcHJlPg0KPHByZT48c3BhbiBs
YW5nPSJFTi1VUyI+aWYgeW91IG5lZWQgbW9yZSB0aGFuIHRoYXQgdG8gZ2V0IGluLCBvciBhcmUg
aGF2aW5nIGRpZmZpY3VsdGllcy48bzpwPjwvbzpwPjwvc3Bhbj48L3ByZT4NCjxwcmU+PHNwYW4g
bGFuZz0iRU4tVVMiPlBsZWFzZSBtYWtlIHN1cmUgeW91ciBhdWRpbyB3b3JrcywgYW5kIHRoYXQg
eW91IG11dGUgd2hlbiBub3QgdGFsa2luZy48bzpwPjwvbzpwPjwvc3Bhbj48L3ByZT4NCjxwcmU+
PHNwYW4gbGFuZz0iRU4tVVMiPiZuYnNwOzxvOnA+PC9vOnA+PC9zcGFuPjwvcHJlPg0KPHByZT48
c3BhbiBsYW5nPSJFTi1VUyI+LS08bzpwPjwvbzpwPjwvc3Bhbj48L3ByZT4NCjxwcmU+PHNwYW4g
bGFuZz0iRU4tVVMiPk1pY2hhZWwgUmljaGFyZHNvbiA8YSBocmVmPSJtYWlsdG86bWNyJiM0MztJ
RVRGQHNhbmRlbG1hbi5jYSIgdGFyZ2V0PSJfYmxhbmsiPjxzcGFuIHN0eWxlPSJjb2xvcjpwdXJw
bGUiPiZsdDttY3ImIzQzO0lFVEZAc2FuZGVsbWFuLmNhJmd0Ozwvc3Bhbj48L2E+LCBTYW5kZWxt
YW4gU29mdHdhcmUgV29ya3M8bzpwPjwvbzpwPjwvc3Bhbj48L3ByZT4NCjxwcmU+PHNwYW4gbGFu
Zz0iRU4tVVMiPiAtPSBJUHY2IElvVCBjb25zdWx0aW5nID0tPG86cD48L286cD48L3NwYW4+PC9w
cmU+DQo8cHJlPjxzcGFuIGxhbmc9IkVOLVVTIj4mbmJzcDs8bzpwPjwvbzpwPjwvc3Bhbj48L3By
ZT4NCjxwcmU+PHNwYW4gbGFuZz0iRU4tVVMiPiZuYnNwOzxvOnA+PC9vOnA+PC9zcGFuPjwvcHJl
Pg0KPHByZT48c3BhbiBsYW5nPSJFTi1VUyI+Jm5ic3A7PG86cD48L286cD48L3NwYW4+PC9wcmU+
DQo8cCBjbGFzcz0iTXNvTm9ybWFsIiBzdHlsZT0ibWFyZ2luLWJvdHRvbToxMi4wcHQiPjxzcGFu
IGxhbmc9IkVOLVVTIiBzdHlsZT0iY29sb3I6Izg4ODg4OCI+Jm5ic3A7PC9zcGFuPjxzcGFuIGxh
bmc9IkVOLVVTIj48bzpwPjwvbzpwPjwvc3Bhbj48L3A+DQo8cHJlPjxzcGFuIGxhbmc9IkVOLVVT
IiBzdHlsZT0iY29sb3I6Izg4ODg4OCI+X19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19f
X19fX19fX19fX19fX188L3NwYW4+PHNwYW4gbGFuZz0iRU4tVVMiPjxvOnA+PC9vOnA+PC9zcGFu
PjwvcHJlPg0KPHByZT48c3BhbiBsYW5nPSJFTi1VUyIgc3R5bGU9ImNvbG9yOiM4ODg4ODgiPjZ0
aXNjaC1zZWN1cml0eSBtYWlsaW5nIGxpc3Q8L3NwYW4+PHNwYW4gbGFuZz0iRU4tVVMiPjxvOnA+
PC9vOnA+PC9zcGFuPjwvcHJlPg0KPHByZT48c3BhbiBsYW5nPSJFTi1VUyIgc3R5bGU9ImNvbG9y
OiM4ODg4ODgiPjxhIGhyZWY9Im1haWx0bzo2dGlzY2gtc2VjdXJpdHlAaWV0Zi5vcmciIHRhcmdl
dD0iX2JsYW5rIj48c3BhbiBzdHlsZT0iY29sb3I6cHVycGxlIj42dGlzY2gtc2VjdXJpdHlAaWV0
Zi5vcmc8L3NwYW4+PC9hPjwvc3Bhbj48c3BhbiBsYW5nPSJFTi1VUyI+PG86cD48L286cD48L3Nw
YW4+PC9wcmU+DQo8cHJlPjxzcGFuIGxhbmc9IkVOLVVTIiBzdHlsZT0iY29sb3I6Izg4ODg4OCI+
PGEgaHJlZj0iaHR0cDovL2NwLm1jYWZlZS5jb20vZC8yRFJQb084NlFtYkVFS25qS09yS3Joczdj
RkNRbjFQYlZKNU1zcWVra1NqaE9yc3V1dXNvTHNTOFFBSG0wYWZCM1p6T1ZJLWtmU2ZiQ1pLRHR4
VkJfSFlNQy1DLU1OUlhCUVNuU3V2dm92djdjc0p0ZU9hcUpOUGZheFZaaWNIczNqcjFKd1R2QW00
VEROT2IycEVWZFRkQVZQbUVCQzVlQllUdTAwVTlHWDMzVmtEYTNKc3NEYUJ5cHVEU3J6YXBvU1Zl
bGI0T1pmSVQ2a09Oc3hsSzVMRTJGdmRUdzA5SjU1VjZWSTUtQXE4M2lTVmVsYjRPWmZJVDZrT05G
dGQ0NkF2d3hGRXd0SDRRZzlUaG9iVHZiRnp6aDBWZWxiNFBoMWpYZE5CY0lxOGJxdXVyc29kTFdi
diIgdGFyZ2V0PSJfYmxhbmsiPjxzcGFuIHN0eWxlPSJjb2xvcjpwdXJwbGUiPmh0dHBzOi8vd3d3
LmlldGYub3JnL21haWxtYW4vbGlzdGluZm8vNnRpc2NoLXNlY3VyaXR5PC9zcGFuPjwvYT48L3Nw
YW4+PHNwYW4gbGFuZz0iRU4tVVMiPjxvOnA+PC9vOnA+PC9zcGFuPjwvcHJlPg0KPC9ibG9ja3F1
b3RlPg0KPHAgY2xhc3M9Ik1zb05vcm1hbCIgc3R5bGU9Im1hcmdpbi1ib3R0b206MTIuMHB0Ij48
c3BhbiBsYW5nPSJFTi1VUyIgc3R5bGU9ImNvbG9yOiM4ODg4ODgiPjxicj4NCjxicj4NCjxicj4N
Cjxicj4NCjwvc3Bhbj48c3BhbiBsYW5nPSJFTi1VUyI+PG86cD48L286cD48L3NwYW4+PC9wPg0K
PHByZT48c3BhbiBsYW5nPSJFTi1VUyIgc3R5bGU9ImNvbG9yOiM4ODg4ODgiPi0tIDwvc3Bhbj48
c3BhbiBsYW5nPSJFTi1VUyI+PG86cD48L286cD48L3NwYW4+PC9wcmU+DQo8cHJlPjxzcGFuIGxh
bmc9IkVOLVVTIiBzdHlsZT0iY29sb3I6Izg4ODg4OCI+ZW1haWw6IDxhIGhyZWY9Im1haWx0bzpy
c3RydWlrLmV4dEBnbWFpbC5jb20iIHRhcmdldD0iX2JsYW5rIj48c3BhbiBzdHlsZT0iY29sb3I6
cHVycGxlIj5yc3RydWlrLmV4dEBnbWFpbC5jb208L3NwYW4+PC9hPiB8IFNreXBlOiByc3RydWlr
PC9zcGFuPjxzcGFuIGxhbmc9IkVOLVVTIj48bzpwPjwvbzpwPjwvc3Bhbj48L3ByZT4NCjxwcmU+
PHNwYW4gbGFuZz0iRU4tVVMiIHN0eWxlPSJjb2xvcjojODg4ODg4Ij5jZWxsOiA8YSBocmVmPSJ0
ZWw6JTJCMSUyMCUyODY0NyUyOSUyMDg2Ny01NjU4IiB0YXJnZXQ9Il9ibGFuayI+PHNwYW4gc3R5
bGU9ImNvbG9yOnB1cnBsZSI+JiM0MzsxICg2NDcpIDg2Ny01NjU4PC9zcGFuPjwvYT4gfCBVUzog
PGEgaHJlZj0idGVsOiUyQjElMjAlMjg0MTUlMjklMjA2OTAtNzM2MyIgdGFyZ2V0PSJfYmxhbmsi
PjxzcGFuIHN0eWxlPSJjb2xvcjpwdXJwbGUiPiYjNDM7MSAoNDE1KSA2OTAtNzM2Mzwvc3Bhbj48
L2E+PC9zcGFuPjxzcGFuIGxhbmc9IkVOLVVTIj48bzpwPjwvbzpwPjwvc3Bhbj48L3ByZT4NCjwv
ZGl2Pg0KPHAgY2xhc3M9Ik1zb05vcm1hbCIgc3R5bGU9Im1hcmdpbi1ib3R0b206MTIuMHB0Ij48
c3BhbiBsYW5nPSJFTi1VUyI+PGJyPg0KX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19f
X19fX19fX19fX19fX188YnI+DQo2dGlzY2gtc2VjdXJpdHkgbWFpbGluZyBsaXN0PGJyPg0KPGEg
aHJlZj0ibWFpbHRvOjZ0aXNjaC1zZWN1cml0eUBpZXRmLm9yZyIgdGFyZ2V0PSJfYmxhbmsiPjxz
cGFuIHN0eWxlPSJjb2xvcjpwdXJwbGUiPjZ0aXNjaC1zZWN1cml0eUBpZXRmLm9yZzwvc3Bhbj48
L2E+PGJyPg0KPGEgaHJlZj0iaHR0cDovL2NwLm1jYWZlZS5jb20vZC9hdm5kemdROTNnQXJob0t5
eVZ0ZVg5S1ZKNU1zT0NyaHM3Y0xDUW4xTkVWaGpwZDc5Sk5WVlZOeVpQb3ppaUpvMEUta2ZTZmJD
UFZnX29ZS3JTV3RTN0NuLUxQMnJXclgzN25LbmpwdnBWWlp4WllzTk9SUVg4RkdUN2NZRzdEUjhP
Sk1kZEVDUWp0LWhvanV2NzhJOUN6QVRzU2pEZHF5bW9rV25QdFUwM3dDSEljZkJpc0VlUk5Pc0dt
OUJXdnBLY0ZCenJBVmtJamJRLVBzcGpiNU81bVVtLXdhQllUdTAwQ1FrbkFyQ01uV2hFd2RickFW
a0lqYlEtUHNwamI2QlFRZ3FoLTI2Q3kxU0lqaDBEdDV3THRZS0NlZDQzQVZrSWpkNDVmSVQ2a09O
RXdKRlZWSk53U2VWaHNyTGUtRmtkIiB0YXJnZXQ9Il9ibGFuayI+PHNwYW4gc3R5bGU9ImNvbG9y
OnB1cnBsZSI+aHR0cDovL2NwLm1jYWZlZS5jb20vZC9hdm5kemdROTNnQXJob0t5eVZ0ZVg5S1ZK
NU1zT0NyaHM3Y0xDUW4xTkVWaGpwZDc5Sk5WVlZOeVpQb3ppaUpvMEUta2ZTZmJDUFZnX29ZS3JT
V3RTN0NuLUxQMnJXclgzN25LbmpwdnBWWlp4WllzTk9SUVg4RkdUN2NZRzdEUjhPSk1kZEVDUWp0
LWhvanV2NzhJOUN6QVRzU2pEZHF5bW9rV25QdFUwM3dDSEljZkJpc0VlUk5Pc0dtOUJXdnBLY0ZC
enJBVmtJamJRLVBzcGpiNU81bVVtLXdhQllUdTAwQ1FrbkFyQ01uV2hFd2RickFWa0lqYlEtUHNw
amI2QlFRZ3FoLTI2Q3kxU0lqaDBEdDV3THRZS0NlZDQzQVZrSWpkNDVmSVQ2a09ORXdKRlZWSk53
U2VWaHNyTGUtRmtkPC9zcGFuPjwvYT48bzpwPjwvbzpwPjwvc3Bhbj48L3A+DQo8L2Jsb2NrcXVv
dGU+DQo8L2Rpdj4NCjxkaXY+DQo8ZGl2Pg0KPHAgY2xhc3M9Ik1zb05vcm1hbCI+PHNwYW4gbGFu
Zz0iRU4tVVMiPjxicj4NCjxiciBjbGVhcj0iYWxsIj4NCjxicj4NCi0tPG86cD48L286cD48L3Nw
YW4+PC9wPg0KPC9kaXY+DQo8L2Rpdj4NCjxkaXY+DQo8ZGl2Pg0KPHAgY2xhc3M9Ik1zb05vcm1h
bCI+PHNwYW4gbGFuZz0iRU4tVVMiIHN0eWxlPSJmb250LXNpemU6MTMuNXB0O2ZvbnQtZmFtaWx5
OiZxdW90O1RpbWVzIE5ldyBSb21hbiZxdW90OywmcXVvdDtzZXJpZiZxdW90OyI+LS0mbmJzcDs8
YnI+DQpKb25hdGhhbiBTaW1vbiwgUGguIEQ8YnI+DQpEaXJlY3RvciBvZiBTeXN0ZW1zIEVuZ2lu
ZWVyaW5nPGJyPg0KRHVzdCBOZXR3b3JrcyBhdCBMaW5lYXIgVGVjaG5vbG9neTxicj4NCjMwNjk1
IEh1bnR3b29kIEF2ZTxicj4NCkhheXdhcmQsIENBIDk0NTQ0LTcwMjE8YnI+DQo8YSBocmVmPSJ0
ZWw6JTI4NTEwJTI5JTIwNDAwLTI5MzYiIHRhcmdldD0iX2JsYW5rIj48c3BhbiBzdHlsZT0iY29s
b3I6cHVycGxlIj4oNTEwKSA0MDAtMjkzNjwvc3Bhbj48L2E+PGJyPg0KPGEgaHJlZj0idGVsOiUy
ODUxMCUyOSUyMDQ4OS0zNzk5IiB0YXJnZXQ9Il9ibGFuayI+PHNwYW4gc3R5bGU9ImNvbG9yOnB1
cnBsZSI+KDUxMCkgNDg5LTM3OTk8L3NwYW4+PC9hPjxzcGFuIGNsYXNzPSJhcHBsZS1jb252ZXJ0
ZWQtc3BhY2UiPiZuYnNwOzwvc3Bhbj5GQVg8YnI+DQo8YSBocmVmPSJtYWlsdG86anNpbW9uQGxp
bmVhci5jb20iIHRhcmdldD0iX2JsYW5rIj48c3BhbiBzdHlsZT0iY29sb3I6cHVycGxlIj5qc2lt
b25AbGluZWFyLmNvbTwvc3Bhbj48L2E+PC9zcGFuPjxzcGFuIGxhbmc9IkVOLVVTIj48YnI+DQo8
YnI+DQo8L3NwYW4+PHNwYW4gbGFuZz0iRU4tVVMiIHN0eWxlPSJmb250LXNpemU6MTMuNXB0O2Zv
bnQtZmFtaWx5OiZxdW90O1RpbWVzIE5ldyBSb21hbiZxdW90OywmcXVvdDtzZXJpZiZxdW90OyI+
KipMSU5FQVIgVEVDSE5PTE9HWSZuYnNwO0NPUlBPUkFUSU9OKiombmJzcDs8YnI+DQoqKioqKklu
dGVybmV0IEVtYWlsIENvbmZpZGVudGlhbGl0eSZuYnNwO05vdGljZSoqKioqJm5ic3A7PGJyPg0K
Jm5ic3A7VGhpcyBlLW1haWwgdHJhbnNtaXNzaW9uLCBhbmQgYW55Jm5ic3A7ZG9jdW1lbnRzLCBm
aWxlcyBvciBwcmV2aW91cyBlLW1haWwmbmJzcDttZXNzYWdlcyBhdHRhY2hlZCB0byBpdCBtYXkg
Y29udGFpbiZuYnNwO2NvbmZpZGVudGlhbCBpbmZvcm1hdGlvbiB0aGF0IGlzJm5ic3A7bGVnYWxs
eSBwcml2aWxlZ2VkLiBJZiB5b3UgYXJlIG5vdCB0aGUmbmJzcDtpbnRlbmRlZCByZWNpcGllbnQs
IG9yIGEgcGVyc29uJm5ic3A7cmVzcG9uc2libGUgZm9yIGRlbGl2ZXJpbmcgaXQgdG8gdGhlJm5i
c3A7aW50ZW5kZWQNCiByZWNpcGllbnQsIHlvdSBhcmUgaGVyZWJ5Jm5ic3A7bm90aWZpZWQgdGhh
dCBhbnkgZGlzY2xvc3VyZSwgY29weWluZywmbmJzcDtkaXN0cmlidXRpb24gb3IgdXNlIG9mIGFu
eSBvZiB0aGUmbmJzcDtpbmZvcm1hdGlvbiBjb250YWluZWQgaW4gb3IgYXR0YWNoZWQmbmJzcDt0
byB0aGlzIHRyYW5zbWlzc2lvbiBpcyBTVFJJQ1RMWSZuYnNwO1BST0hJQklURUQuIElmIHlvdSBo
YXZlIHJlY2VpdmVkIHRoaXMmbmJzcDt0cmFuc21pc3Npb24gaW4gZXJyb3IsIHBsZWFzZSZuYnNw
O2ltbWVkaWF0ZWx5IG5vdGlmeQ0KIG1lIGJ5IHJlcGx5IGUtbWFpbCwgb3IgYnkgdGVsZXBob25l
IGF0PHNwYW4gY2xhc3M9ImFwcGxlLWNvbnZlcnRlZC1zcGFjZSI+Jm5ic3A7PC9zcGFuPjxhIGhy
ZWY9InRlbDolMjg1MTAlMjklMjA0MDAtMjkzNiIgdGFyZ2V0PSJfYmxhbmsiPjxzcGFuIHN0eWxl
PSJjb2xvcjpwdXJwbGUiPig1MTApIDQwMC0yOTM2PC9zcGFuPjwvYT4sIGFuZCBkZXN0cm95IHRo
ZSBvcmlnaW5hbCZuYnNwO3RyYW5zbWlzc2lvbiBhbmQgaXRzIGF0dGFjaG1lbnRzJm5ic3A7d2l0
aG91dCByZWFkaW5nDQogb3Igc2F2aW5nIGluIGFueSZuYnNwO21hbm5lci4gVGhhbmsgeW91Ljwv
c3Bhbj48c3BhbiBsYW5nPSJFTi1VUyI+PG86cD48L286cD48L3NwYW4+PC9wPg0KPC9kaXY+DQo8
L2Rpdj4NCjwvZGl2Pg0KPC9kaXY+DQo8cCBjbGFzcz0iTXNvTm9ybWFsIiBzdHlsZT0ibWFyZ2lu
LWJvdHRvbToxMi4wcHQiPjxzcGFuIGxhbmc9IkVOLVVTIj48YnI+DQpfX19fX19fX19fX19fX19f
X19fX19fX19fX19fX19fX19fX19fX19fX19fX19fXzxicj4NCjZ0aXNjaC1zZWN1cml0eSBtYWls
aW5nIGxpc3Q8YnI+DQo8YSBocmVmPSJtYWlsdG86NnRpc2NoLXNlY3VyaXR5QGlldGYub3JnIj48
c3BhbiBzdHlsZT0iY29sb3I6cHVycGxlIj42dGlzY2gtc2VjdXJpdHlAaWV0Zi5vcmc8L3NwYW4+
PC9hPjxicj4NCjxhIGhyZWY9Imh0dHA6Ly9jcC5tY2FmZWUuY29tL2QvMkRSUG93NzZRbWJFRkx6
emhPTS1yS3JoczdjRkNRbjFQYlZKNU1zcWVra1NqaE9yc3V1dXNvTHNTOFFBSG0wYWZCM1p6T1ZJ
LWtmU2ZiQ1RBN2hQWFBiX25WTlpOQlZ4ekhUYkV6SElZWWVwZDdiejhYQkhFU2hobEtNX09FdXZr
emFUMFFTeXJoZFRWNXhkVllzeU1DcWVqdFBwZXNSRzlweGpGdmRUdzBlMnFLTU0tbDlPd1huNzlP
Rm9DbkZaQ1VPQ21kS2pCaU5jTGpYZE5CY0luOGxyeHJXMEduUHRVMDJyb2poS1VyMXZGNnkwUUpL
akJpTmNMalhkTkJjSXFuamgxRjdVOHFxODdxTmQ0MnRRbTJaVE9Xb1VRZ2VqQmlOY1Fnay1Qc3Bq
YjZ5MlNERENUNjNydF9VMlNWVWxWQjAiIHRhcmdldD0iX2JsYW5rIj48c3BhbiBzdHlsZT0iY29s
b3I6cHVycGxlIj5odHRwOi8vY3AubWNhZmVlLmNvbS9kLzJEUlBvdzc2UW1iRUZMenpoT00tckty
aHM3Y0ZDUW4xUGJWSjVNc3Fla2tTamhPcnN1dXVzb0xzUzhRQUhtMGFmQjNaek9WSS1rZlNmYkNU
QTdoUFhQYl9uVk5aTkJWeHpIVGJFekhJWVllcGQ3Yno4WEJIRVNoaGxLTV9PRXV2a3phVDBRU3ly
aGRUVjV4ZFZZc3lNQ3FlanRQcGVzUkc5cHhqRnZkVHcwZTJxS01NLWw5T3dYbjc5T0ZvQ25GWkNV
T0NtZEtqQmlOY0xqWGROQmNJbjhscnhyVzBHblB0VTAycm9qaEtVcjF2RjZ5MFFKS2pCaU5jTGpY
ZE5CY0lxbmpoMUY3VThxcTg3cU5kNDJ0UW0yWlRPV29VUWdlakJpTmNRZ2stUHNwamI2eTJTRERD
VDYzcnRfVTJTVlVsVkIwPC9zcGFuPjwvYT48bzpwPjwvbzpwPjwvc3Bhbj48L3A+DQo8L2Jsb2Nr
cXVvdGU+DQo8L2Rpdj4NCjxkaXY+DQo8ZGl2Pg0KPHAgY2xhc3M9Ik1zb05vcm1hbCI+PHNwYW4g
bGFuZz0iRU4tVVMiPjxicj4NCjxiciBjbGVhcj0iYWxsIj4NCjxicj4NCi0tPG86cD48L286cD48
L3NwYW4+PC9wPg0KPC9kaXY+DQo8L2Rpdj4NCjxkaXY+DQo8ZGl2Pg0KPHAgY2xhc3M9Ik1zb05v
cm1hbCI+PHNwYW4gbGFuZz0iRU4tVVMiIHN0eWxlPSJmb250LXNpemU6MTMuNXB0O2ZvbnQtZmFt
aWx5OiZxdW90O1RpbWVzIE5ldyBSb21hbiZxdW90OywmcXVvdDtzZXJpZiZxdW90OyI+LS0mbmJz
cDs8YnI+DQpKb25hdGhhbiBTaW1vbiwgUGguIEQ8YnI+DQpEaXJlY3RvciBvZiBTeXN0ZW1zIEVu
Z2luZWVyaW5nPGJyPg0KRHVzdCBOZXR3b3JrcyBhdCBMaW5lYXIgVGVjaG5vbG9neTxicj4NCjMw
Njk1IEh1bnR3b29kIEF2ZTxicj4NCkhheXdhcmQsIENBIDk0NTQ0LTcwMjE8YnI+DQooNTEwKSA0
MDAtMjkzNjxicj4NCig1MTApIDQ4OS0zNzk5IEZBWDxicj4NCjxhIGhyZWY9Im1haWx0bzpqc2lt
b25AbGluZWFyLmNvbSIgdGFyZ2V0PSJfYmxhbmsiPjxzcGFuIHN0eWxlPSJjb2xvcjpwdXJwbGUi
PmpzaW1vbkBsaW5lYXIuY29tPC9zcGFuPjwvYT48L3NwYW4+PHNwYW4gbGFuZz0iRU4tVVMiPjxi
cj4NCjxicj4NCjwvc3Bhbj48c3BhbiBsYW5nPSJFTi1VUyIgc3R5bGU9ImZvbnQtc2l6ZToxMy41
cHQ7Zm9udC1mYW1pbHk6JnF1b3Q7VGltZXMgTmV3IFJvbWFuJnF1b3Q7LCZxdW90O3NlcmlmJnF1
b3Q7Ij4qKkxJTkVBUiBURUNITk9MT0dZJm5ic3A7Q09SUE9SQVRJT04qKiZuYnNwOzxicj4NCioq
KioqSW50ZXJuZXQgRW1haWwgQ29uZmlkZW50aWFsaXR5Jm5ic3A7Tm90aWNlKioqKiombmJzcDs8
YnI+DQombmJzcDtUaGlzIGUtbWFpbCB0cmFuc21pc3Npb24sIGFuZCBhbnkmbmJzcDtkb2N1bWVu
dHMsIGZpbGVzIG9yIHByZXZpb3VzIGUtbWFpbCZuYnNwO21lc3NhZ2VzIGF0dGFjaGVkIHRvIGl0
IG1heSBjb250YWluJm5ic3A7Y29uZmlkZW50aWFsIGluZm9ybWF0aW9uIHRoYXQgaXMmbmJzcDts
ZWdhbGx5IHByaXZpbGVnZWQuIElmIHlvdSBhcmUgbm90IHRoZSZuYnNwO2ludGVuZGVkIHJlY2lw
aWVudCwgb3IgYSBwZXJzb24mbmJzcDtyZXNwb25zaWJsZSBmb3IgZGVsaXZlcmluZyBpdCB0byB0
aGUmbmJzcDtpbnRlbmRlZA0KIHJlY2lwaWVudCwgeW91IGFyZSBoZXJlYnkmbmJzcDtub3RpZmll
ZCB0aGF0IGFueSBkaXNjbG9zdXJlLCBjb3B5aW5nLCZuYnNwO2Rpc3RyaWJ1dGlvbiBvciB1c2Ug
b2YgYW55IG9mIHRoZSZuYnNwO2luZm9ybWF0aW9uIGNvbnRhaW5lZCBpbiBvciBhdHRhY2hlZCZu
YnNwO3RvIHRoaXMgdHJhbnNtaXNzaW9uIGlzIFNUUklDVExZJm5ic3A7UFJPSElCSVRFRC4gSWYg
eW91IGhhdmUgcmVjZWl2ZWQgdGhpcyZuYnNwO3RyYW5zbWlzc2lvbiBpbiBlcnJvciwgcGxlYXNl
Jm5ic3A7aW1tZWRpYXRlbHkgbm90aWZ5DQogbWUgYnkgcmVwbHkgZS1tYWlsLCBvciBieSB0ZWxl
cGhvbmUgYXQgKDUxMCkgNDAwLTI5MzYsIGFuZCBkZXN0cm95IHRoZSBvcmlnaW5hbCZuYnNwO3Ry
YW5zbWlzc2lvbiBhbmQgaXRzIGF0dGFjaG1lbnRzJm5ic3A7d2l0aG91dCByZWFkaW5nIG9yIHNh
dmluZyBpbiBhbnkmbmJzcDttYW5uZXIuIFRoYW5rIHlvdS48L3NwYW4+PHNwYW4gbGFuZz0iRU4t
VVMiPjxvOnA+PC9vOnA+PC9zcGFuPjwvcD4NCjwvZGl2Pg0KPC9kaXY+DQo8L2Rpdj4NCjxkaXY+
DQo8cCBjbGFzcz0iTXNvTm9ybWFsIj48c3BhbiBsYW5nPSJFTi1VUyIgc3R5bGU9ImZvbnQtc2l6
ZToxMC41cHQ7Zm9udC1mYW1pbHk6JnF1b3Q7THVjaWRhR3JhbmRlJnF1b3Q7LCZxdW90O3Nlcmlm
JnF1b3Q7Ij5fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fXzxi
cj4NCjZ0aXNjaC1zZWN1cml0eSBtYWlsaW5nIGxpc3Q8YnI+DQo8YSBocmVmPSJtYWlsdG86NnRp
c2NoLXNlY3VyaXR5QGlldGYub3JnIj48c3BhbiBzdHlsZT0iY29sb3I6cHVycGxlIj42dGlzY2gt
c2VjdXJpdHlAaWV0Zi5vcmc8L3NwYW4+PC9hPjxicj4NCjxhIGhyZWY9Imh0dHA6Ly9jcC5tY2Fm
ZWUuY29tL2QvMWpXVkllM3pxYjVRa1R6aE9NQy1yS3JoczdjRkNRbjFQYlZKNU1zcWVra1NqaE9y
c3V1dXNvTHNTOFFBSG0wYWZCM1p6T1ZJLWtmU2ZiQ081SnR2dXB2V184Q3pCZEJCZkhUYkVDekJk
ekFUQzd4TkVWVnFXdEFrbHJDekI3QmdZLUY2bEsxRko0U3lyTE9iMnJQVVY1eGNRc0NYQ09zVkhr
aVAyRGktckwwMHM0UnR4eFlHakIxU0tlakJpTmNMalhkTkJjSXJzRGFCeXB1RFNyemFwb0tnR1Qy
VFExa0xDWE0wNFMtcWVtN1Qzb2JaOFFnNkJKT3NHbTlCV3ZwS2NGQnppV3E4ZDhfMTNqaDBYbTlF
d2pLeU1uSy1uajc2eTFPc0dtOUN5MkRTcnphcG9RZ21RWVlTVU1yRHJrcjJwQWFUYW0iPjxzcGFu
IHN0eWxlPSJjb2xvcjpwdXJwbGUiPmh0dHA6Ly9jcC5tY2FmZWUuY29tL2QvMWpXVkllM3pxYjVR
a1R6aE9NQy1yS3JoczdjRkNRbjFQYlZKNU1zcWVra1NqaE9yc3V1dXNvTHNTOFFBSG0wYWZCM1p6
T1ZJLWtmU2ZiQ081SnR2dXB2V184Q3pCZEJCZkhUYkVDekJkekFUQzd4TkVWVnFXdEFrbHJDekI3
QmdZLUY2bEsxRko0U3lyTE9iMnJQVVY1eGNRc0NYQ09zVkhraVAyRGktckwwMHM0UnR4eFlHakIx
U0tlakJpTmNMalhkTkJjSXJzRGFCeXB1RFNyemFwb0tnR1QyVFExa0xDWE0wNFMtcWVtN1Qzb2Ja
OFFnNkJKT3NHbTlCV3ZwS2NGQnppV3E4ZDhfMTNqaDBYbTlFd2pLeU1uSy1uajc2eTFPc0dtOUN5
MkRTcnphcG9RZ21RWVlTVU1yRHJrcjJwQWFUYW08L3NwYW4+PC9hPjwvc3Bhbj48c3BhbiBsYW5n
PSJFTi1VUyI+PG86cD48L286cD48L3NwYW4+PC9wPg0KPC9kaXY+DQo8L2Jsb2NrcXVvdGU+DQo8
L2Rpdj4NCjwvZGl2Pg0KPC9kaXY+DQo8L2Jsb2NrcXVvdGU+DQo8L2Rpdj4NCjxwIGNsYXNzPSJN
c29Ob3JtYWwiPjxzcGFuIGxhbmc9IkVOLVVTIj48bzpwPiZuYnNwOzwvbzpwPjwvc3Bhbj48L3A+
DQo8L2Rpdj4NCjwvZGl2Pg0KPC9ib2R5Pg0KPC9odG1sPg0K

--_000_674F70E5F2BE564CB06B6901FD3DD78B2723BA70TGXML210toshiba_--


From nobody Wed May 28 18:40:01 2014
Return-Path: <rstruik.ext@gmail.com>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 31CAE1A081E for <6tisch-security@ietfa.amsl.com>; Wed, 28 May 2014 18:39:58 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: 0.591
X-Spam-Level: 
X-Spam-Status: No, score=0.591 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, HTTPS_HTTP_MISMATCH=1.989, J_CHICKENPOX_28=0.6, SPF_PASS=-0.001, WEIRD_PORT=0.001] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id a4CmKk2a11n6 for <6tisch-security@ietfa.amsl.com>; Wed, 28 May 2014 18:39:54 -0700 (PDT)
Received: from mail-ig0-x22e.google.com (mail-ig0-x22e.google.com [IPv6:2607:f8b0:4001:c05::22e]) (using TLSv1 with cipher ECDHE-RSA-RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id C00891A6F32 for <6tisch-security@ietf.org>; Wed, 28 May 2014 18:39:53 -0700 (PDT)
Received: by mail-ig0-f174.google.com with SMTP id h3so3231120igd.7 for <6tisch-security@ietf.org>; Wed, 28 May 2014 18:39:49 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113;  h=message-id:date:from:user-agent:mime-version:to:cc:subject :references:in-reply-to:content-type; bh=X0VF/xCbzDiwUPehX3tq3xC6oVV7wyFj1azHupOqqAI=; b=uyoV2t+GwKB0eStM0OSqk/AW/kgAqXRAmBdRBh8KjK6Srwm7UN/7ETLON9PC7x0nkt PdeeGZ4NC2cJXwCRCfPnV59mzTgl3mq/uBVdiv21ZyzxJLXfBmVxs1nAcJaOhdSIwg1k 1qM8dMpf0+KJk9LIGDf44NBR7Tw0w/UiU4aRs3SY63Ama6dGzpwvzfPz5CUKw4YIKNiG MdtlNYxY+nhYmAkR+ZyFNNTe3FvgG0441+HlJXYR4XzUe/Fafnz44FX2eqpg6c+2eBdw 8wVKoEZPQKIY2MUo9CpjJMdYrKTewA/FHlpiLHy/96AOdV9Hh2/WL/fc9ho9HDbumust ONzQ==
X-Received: by 10.50.128.162 with SMTP id np2mr49119607igb.22.1401327589773; Wed, 28 May 2014 18:39:49 -0700 (PDT)
Received: from [192.168.1.105] (CPE0013100e2c51-CM001cea35caa6.cpe.net.cable.rogers.com. [99.231.3.110]) by mx.google.com with ESMTPSA id ie20sm20107965igb.10.2014.05.28.18.39.47 for <multiple recipients> (version=TLSv1 cipher=ECDHE-RSA-RC4-SHA bits=128/128); Wed, 28 May 2014 18:39:49 -0700 (PDT)
Message-ID: <53868FE0.1020602@gmail.com>
Date: Wed, 28 May 2014 21:39:44 -0400
From: Rene Struik <rstruik.ext@gmail.com>
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:24.0) Gecko/20100101 Thunderbird/24.5.0
MIME-Version: 1.0
To: yoshihiro.ohba@toshiba.co.jp, jsimon@linear.com
References: <E045AECD98228444A58C61C200AE1BD8416F3AF4@xmb-rcd-x01.cisco.com> <531DD632.2060009@cox.net> <531DDB20.5050600@gmail.com> <10925.1394631496@sandelman.ca> <532069C8.2050005@gmail.com> <23590.1394999032@sandelman.ca> <18106.1395625035@sandelman.ca> <19609.1396839403@sandelman.ca> <11557.1397444260@sandelman.ca> <28192.1398644294@sandelman.ca> <29064.1399255587@sandelman.ca> <19475.1400588783@sandelman.ca> <4903.1401158997@sandelman.ca> <53840205.2070103@gmail.com> <CAJeFcoS3PNFX2obx3uNDJDtH=QvNLmaPhw2R468sNaeqpo8QBQ@mail.gmail.com> <674F70E5F2BE564CB06B6901FD3DD78B2723B576@TGXML210.toshiba.local> <CAJeFcoQBp1A7pwZHWoesvrjSySW0UZ0k11-s3-MFAozSuR0Yrw@mail.gmail.com> <674F70E5F2BE564CB06B6901FD3DD78B2723B85A@TGXML210.toshiba.local> <1315B075-A0A5-4008-8CC9-4918F54CBED1@linear.com> <674F70E5F2BE564CB06B6901FD3DD78B2723BA32@TGXML210.toshiba.local> <B9D502BD-C500-41E0-BA31-5BCD72090432@linear.com> <674F70E5F2BE564CB06B6901FD3DD78B2723BA70@TGXML210.toshiba.local>
In-Reply-To: <674F70E5F2BE564CB06B6901FD3DD78B2723BA70@TGXML210.toshiba.local>
Content-Type: multipart/alternative; boundary="------------070609060701030807080703"
Archived-At: http://mailarchive.ietf.org/arch/msg/6tisch-security/ZnMz2GOFFvR8FkM3OhDeLtef6Jo
Cc: mcr+ietf@sandelman.ca, 6tisch-security@ietf.org
Subject: [6tisch-security] beacon discussion based on confusion between w/HART and 802.15.4e-2012? (Re: agenda for 2014-05-27 6tisch security call)
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 29 May 2014 01:39:58 -0000

This is a multi-part message in MIME format.
--------------070609060701030807080703
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 8bit

Dear colleagues:

I may have missed something here, but this email thread seems to confuse 
what w/HART provides with what 6TiSCH could specify. Since 6TiSCH is to 
be defined on top of 802.15.4e-2012, it can secure frame types using 
policy-defined combinations of encryption and authenticity (including 
authentication-only). In particular, a newbee device, just out of the 
wrapping paper and with no network-specific keying material yet, may 
still be able to see most of an authenticated, but not secured frame, 
even if it cannot check authenticity.

So, no need to kill off functionality, come up with nested security 
constructs, two beacon types, etc; one should simply look at the correct 
standard one builds on {caveat: this assessment is modulo some errors in 
the 802.15.4e-2012 spec.}

BTW - As an interesting aside, this seems to illustrate that looking at 
specific details *does* matter...

Best regards, Rene


On 5/28/2014 7:43 PM, yoshihiro.ohba@toshiba.co.jp wrote:
>
> Yes.
>
> Yoshihiro Ohba
>
> *From:*Jonathan Simon [mailto:jsimon@linear.com]
> *Sent:* Thursday, May 29, 2014 8:42 AM
> *To:* ohba yoshihiro(大場義洋○ＲＤＣ□ＮＳＬ)
> *Cc:* mcr+ietf@sandelman.ca; rstruik.ext@gmail.com; 
> 6tisch-security@ietf.org
> *Subject:* Re: [6tisch-security] agenda for 2014-05-27 6tisch security 
> call
>
> Then as long as either
>
> a) Beacons are only used for advertising a network to unsychronized 
> devices, or
>
> b) Devices only take timing information (time of arrival) from beacons 
> coming from time parents and authenticated with the run-time key
>
> you are good.
>
> -- 
> Jonathan Simon, Ph. D
> Director of Systems Engineering
> Linear Technology, Dust Networks product group
> 30695 Huntwood Ave
> Hayward, CA 94544-7021
> (510) 400-2936
> (510) 489-3799 FAX
> jsimon@linear.com <mailto:jsimon@linear.com>
>
> **LINEAR TECHNOLOGY CORPORATION**
> *****Internet Email Confidentiality Notice*****
>  This e-mail transmission, and any documents, files or previous 
> e-mail messages attached to it may contain confidential information 
> that is legally privileged. If you are not the intended recipient, or 
> a person responsible for delivering it to the intended recipient, you 
> are hereby notified that any disclosure, copying, distribution or use 
> of any of the information contained in or attached to this 
> transmission is STRICTLY PROHIBITED. If you have received 
> this transmission in error, please immediately notify me by reply 
> e-mail, or by telephone at (510) 400-2936, and destroy the 
> original transmission and its attachments without reading or saving in 
> any manner. Thank you.
>
> On May 28, 2014, at 4:19 PM, <yoshihiro.ohba@toshiba.co.jp 
> <mailto:yoshihiro.ohba@toshiba.co.jp>> <yoshihiro.ohba@toshiba.co.jp 
> <mailto:yoshihiro.ohba@toshiba.co.jp>> wrote:
>
>
>
>     Hi Jonathan,
>
>     I am not caring about an attacker to inject joining traffic, but
>     what I care is an attacker attempting to destruct basic TSCH
>     operation in the network by sending forged beacons protected with
>     the well-known key.
>
>     Yoshihiro Ohba
>
>     *From:*6tisch-security
>     [mailto:6tisch-security-bounces@ietf.org]*On Behalf Of*Jonathan Simon
>     *Sent:*Thursday, May 29, 2014 12:47 AM
>     *To:*ohba yoshihiro(大場義洋○ＲＤＣ□ＮＳＬ)
>     *Cc:*mcr+ietf@sandelman.ca
>     <mailto:mcr+ietf@sandelman.ca>;rstruik.ext@gmail.com
>     <mailto:rstruik.ext@gmail.com>;6tisch-security@ietf.org
>     <mailto:6tisch-security@ietf.org>
>     *Subject:*Re: [6tisch-security] agenda for 2014-05-27 6tisch
>     security call
>
>     Yoshihiro -
>
>     I don’t think this is a problem.  Nodes that are in the network
>     reject incoming frames secured with the well-known key. The
>     well-known key is only used to authenticate beacons, and
>     authenticate join requests (which don’t carry synchronization
>     information).  There is a DoS vector, in that an attacker can
>     inject joining traffic (destined for the network mananager) that
>     will ultimately be discarded, possibly preventing other nodes from
>     joining, and increasing the traffic in the network.
>
>     Jonathan Simon, Ph. D
>     Director of Systems Engineering
>     Linear Technology, Dust Networks product group
>     30695 Huntwood Ave
>     Hayward, CA 94544-7021
>     (510) 400-2936
>     (510) 489-3799 FAX
>     jsimon@linear.com <mailto:jsimon@linear.com>
>
>     **LINEAR TECHNOLOGY CORPORATION**
>     *****Internet Email Confidentiality Notice*****
>      This e-mail transmission, and any documents, files or previous
>     e-mail messages attached to it may contain confidential
>     information that is legally privileged. If you are not
>     the intended recipient, or a person responsible for delivering it
>     to the intended recipient, you are hereby notified that any
>     disclosure, copying, distribution or use of any of the information
>     contained in or attached to this transmission is
>     STRICTLY PROHIBITED. If you have received this transmission in
>     error, please immediately notify me by reply e-mail, or by
>     telephone at (510) 400-2936, and destroy the original transmission
>     and its attachments without reading or saving in any manner. Thank
>     you.
>
>     On May 28, 2014, at 8:01 AM, <yoshihiro.ohba@toshiba.co.jp
>     <mailto:yoshihiro.ohba@toshiba.co.jp>>
>     <yoshihiro.ohba@toshiba.co.jp
>     <mailto:yoshihiro.ohba@toshiba.co.jp>> wrote:
>
>
>
>
>         Hi Jonathan,
>
>         Thank you for your answer.
>
>         I think this can be an issue if already joined nodes also use
>         the beacons protected with the well-known key for maintaining
>         synchronization and slot allocations, as an attacker can send
>         forged beacons protected with the well-known key.
>
>         Yoshihiro Ohba
>
>         *From:*6tisch-security
>         [mailto:6tisch-security-bounces@ietf.org]*On Behalf
>         Of*Jonathan Simon
>         *Sent:*Wednesday, May 28, 2014 11:49 PM
>         *To:*ohba yoshihiro(大場義洋○ＲＤＣ□ＮＳＬ)
>         *Cc:*Michael Richardson; Rene Struik;6tisch-security@ietf.org
>         <mailto:6tisch-security@ietf.org>
>         *Subject:*Re: [6tisch-security] agenda for 2014-05-27 6tisch
>         security call
>
>         Yoshihiro -
>
>         Q.In w/HART, are all beacon frames authenticated with a
>         well-known key even after a joining node obtained the runtime
>         link layer key?
>
>         A. Yes. In WirelessHART the beacons (called "advertisements"
>         but they serve the same purpose and have similar content) are
>         intended for devices not yet in the network, so they always
>         use the well-known key.  To discover other nodes within the
>         network, they use frames secured with the runtime link-layer key.
>
>         Jonathan
>
>         On Tue, May 27, 2014 at 11:18 PM,
>         <yoshihiro.ohba@toshiba.co.jp
>         <mailto:yoshihiro.ohba@toshiba.co.jp>> wrote:
>
>             Hi Jonathan,
>
>             Thank you for sending the summary of w/HART joining.
>
>             I have question.
>
>             In w/HART, are all beacon frames authenticated with a
>             well-known key even after a joining node obtained the
>             runtime link layer key?
>
>             Regards,
>
>             Yoshihiro Ohba
>
>             *From:*6tisch-security
>             [mailto:6tisch-security-bounces@ietf.org
>             <mailto:6tisch-security-bounces@ietf.org>]*On Behalf
>             Of*Jonathan Simon
>             *Sent:*Tuesday, May 27, 2014 10:41 PM
>             *To:*Rene Struik
>             *Cc:*Michael Richardson;6tisch-security@ietf.org
>             <mailto:6tisch-security@ietf.org>
>             *Subject:*Re: [6tisch-security] agenda for 2014-05-27
>             6tisch security call
>
>             Rene had asked on a previous call for someone to summarize
>             WirelessHART joining - here you go.
>
>             * One or more devices are sending beacons to advertise the
>             presence of the network. In WirelessHART, this frame is
>             unencrypted, but authenticated with a well known key.  The
>             beacon contains the current ASN, which the joining device
>             uses to synchronize its clock.
>
>             * Once the joining node has heard a beacon, it continues
>             listening for additional beacons for a short specified
>             timeout.
>
>             * The joining node encrypts a frame containing some HART
>             specific content, including a list of beaconing neighbors
>             it heard in the previous steps. The size of the payload is
>             ~ 60 bytes.  The packet is routed by a "proxy" node - the
>             joining parent. The frame is authenticated using the
>             well-known key, and encrypted using a shared symmetric key
>             known only by the node and the manager.
>
>             * The manager responds with a frame containing the
>             run-time link-layer key, the node's new short address
>             (this takes the place of PAN coordinator association), and
>             a unicast session key and starting nonce for the manager.
>             This frame is encrypted with the symmetric key. The
>             payload is ~ 60 bytes, and is routed to the proxy for
>             delivery to the joining node - the proxy uses the
>             link-layer well known key on the frame.
>
>             * At this point the joining node transitions to using the
>             run-time link-layer key for all link-layer frames, and the
>             manager unicast session for end-to-end manager traffic.
>             This ends the initial security handshake.
>
>             * Over a number of additional frames, the manager assigns
>             additional sessions, including broadcast sessions, and a
>             unicast session to the Gateway (sink for all data
>             traffic), and additional communications resources, routing
>             information, etc.  There is no explicit transition from
>             joining to joined - the mote transitions when certain key
>             frames are received.
>
>             * Note that a WirelessHART link-layer frame contains and
>             additional frame type byte and a 4-byte link-layer MIC, on
>             top of the unsecured 15.4 frame.  A network frame contains
>             an additional 16-40 bytes of addressing, routing, security
>             and other information.
>
>             Hope this help!
>
>             Jonathan
>
>             On Mon, May 26, 2014 at 8:09 PM, Rene Struik
>             <rstruik.ext@gmail.com <mailto:rstruik.ext@gmail.com>> wrote:
>
>                 Hi Michael:
>
>                 I would like to discuss the outstanding issues I
>                 summarized in my email of Tue last week, May 20, 2014,
>                 9:45am EDT
>                 (seehttp://www.ietf.org/mail-archive/web/6tisch-security/current/msg00086.html
>                 <http://cp.mcafee.com/d/5fHCMUp41ESyNt55OWtSjtPqbwVBcSyUepvdEK3zhOyCOqejrzPPPz5XCN6ABqM1hYEvIundDOx-NVsTJQXIfcLZvC4TQTS6eLsKCO-PPXX3XUVzBHFShjlKepVkffGhBrwqrhdI6XYyMCY-ehojd79KVI05bVKY01MjbX6NehDY05zAVkIjbQ-PspjbppKcvxf5q4rTKYVMedKjBiNcLjXdNBcIn8lrxrW0GnPtU02rhhuhKr1vF6y0QJKjBiNcLjXdNBcIqnjh1F7U8qq87qNd42tQm2ZTOWoUQgejBiNcQgk-Pspjb6y2SDDCT63pO_o>).
>                 This was also one of the action items at the
>                 conclusion of last week's 6TiSCH security call.
>
>                 FYI - the w/HART communication flows were discussed
>                 during the 6TiSCH security conf call the week before,
>                 on Mon May 12, 2014. If one wishes to go over this
>                 again, that is fine, but I would prefer us giving
>                 preference to taking on already articulated issues
>                 (which were assigned as homework assignment to reflect
>                 upon) first (i.e., prior to item #4 of the proposed
>                 agenda).
>
>                 As another agenda point, I would like us to discuss
>                 the frequency of future calls (as part of EOB).
>
>                 Best regards, Rene
>
>
>                 On 5/26/2014 10:49 PM, Michael Richardson wrote:
>
>                     To remind, we moved the call from the 26th to the 27th at 10am EDT.
>
>                     That's 90 minutes from this email.
>
>                       
>
>                     1) notewell.
>
>                     2) intros
>
>                     3) recap of draft-piro-
>
>                     4) wirelesshart -way --- how does the communication work?
>
>                     5) how to summarize all of this to the working group
>
>                     6) how to close this process up?
>
>                       
>
>                     -- remember that the call is recorded, and the NoteWell applies.
>
>                       
>
>                     -- The URL to access the webex, which will we use for audio only:
>
>                        https://cisco.webex.com/cisco/j.php?MTID=m2fe139bf876cea3ec62750cd580b7908  <http://cp.mcafee.com/d/5fHCN0SyNt55OWtSjtPqbwVBcSyUepvdEK3zhOyCOqejrzPPPz5XCN6ABqM1hYEvIundDOx-NVsTJQXIfcLZvC4TQTS6eLsKCO-PPXX3XUVzBHFShjlKepVkffGhBrwqrjdI6XYyMCY-ehojd79KVIDeqR4IOQGmHM0L3-nOQGmHwzMh93o93gUVldTQmjhOgtu7em_mvIUCevLp1ZWV0sqerL6T9OFoCnFZCUOCmbAaJMJZ0lbVKY01dEEL8TdwLQzh0qmT9OFoCnFZCUOCmdbFEwQzY4dd43JoCy1eWb1uXVtcsq879OFoCq8avpKcFBzh1rjPPrz1LmTw7w17>
>
>                       
>
>                     -- we will resume with the etherpad at:
>
>                         http://etherpad.tools.ietf.org:9000/p/notes-ietf-89-6tisch-security  <http://cp.mcafee.com/d/2DRPow71NJ5yWabBQXICXCQn1PapJ5MsO-rhs76zB5dAQsCT7DDD6bTdyd9aRw2zVg_oYKrfB3ZzOVLrFToupvW_c9LFLIctuVtdBZDDTS7TNP7bnjIyCHssPOEuvkzaT0QSOrodTV5xdVYsyMCqejtPo0fVA_yJG7jHk-Di-rL00kzhPuZYmO5p_gLbVKBTzhOnsDaBypuDSrzapoSVelb4OZfIT6kONsxlK5LE2FvdTw09J55V6VI5-Aq83iSVelb4OZfIT6kONFtd46AvwxFEwtH4Qg9ThobTvbFzzh0Velb4Ph1jXdNBcIq8bquursodJiZvpmK6GwY>
>
>                       
>
>                     I'm at+1 613 276-6809  <tel:%2B1%20613%20276-6809>, IM:mcr@xmpp.credil.org  <mailto:mcr@xmpp.credil.org>  ormcharlesr@gmail.com  <mailto:mcharlesr@gmail.com>,
>
>                     if you need more than that to get in, or are having difficulties.
>
>                     Please make sure your audio works, and that you mute when not talking.
>
>                       
>
>                     --
>
>                     Michael Richardson<mcr+IETF@sandelman.ca>  <mailto:mcr+IETF@sandelman.ca>, Sandelman Software Works
>
>                       -= IPv6 IoT consulting =-
>
>                       
>
>                       
>
>                       
>
>                     _______________________________________________
>
>                     6tisch-security mailing list
>
>                     6tisch-security@ietf.org  <mailto:6tisch-security@ietf.org>
>
>                     https://www.ietf.org/mailman/listinfo/6tisch-security  <http://cp.mcafee.com/d/2DRPoO86QmbEEKnjKOrKrhs7cFCQn1PbVJ5MsqekkSjhOrsuuusoLsS8QAHm0afB3ZzOVI-kfSfbCZKDtxVB_HYMC-C-MNRXBQSnSuvvovv7csJteOaqJNPfaxVZicHs3jr1JwTvAm4TDNOb2pEVdTdAVPmEBC5eBYTu00U9GX33VkDa3JssDaBypuDSrzapoSVelb4OZfIT6kONsxlK5LE2FvdTw09J55V6VI5-Aq83iSVelb4OZfIT6kONFtd46AvwxFEwtH4Qg9ThobTvbFzzh0Velb4Ph1jXdNBcIq8bquursodLWbv>
>
>
>
>
>
>                 -- 
>
>                 email:rstruik.ext@gmail.com  <mailto:rstruik.ext@gmail.com>  | Skype: rstruik
>
>                 cell:+1 (647) 867-5658  <tel:%2B1%20%28647%29%20867-5658>  | US:+1 (415) 690-7363  <tel:%2B1%20%28415%29%20690-7363>
>
>
>                 _______________________________________________
>                 6tisch-security mailing list
>                 6tisch-security@ietf.org <mailto:6tisch-security@ietf.org>
>                 http://cp.mcafee.com/d/avndzgQ93gArhoKyyVteX9KVJ5MsOCrhs7cLCQn1NEVhjpd79JNVVVNyZPoziiJo0E-kfSfbCPVg_oYKrSWtS7Cn-LP2rWrX37nKnjpvpVZZxZYsNORQX8FGT7cYG7DR8OJMddECQjt-hojuv78I9CzATsSjDdqymokWnPtU03wCHIcfBisEeRNOsGm9BWvpKcFBzrAVkIjbQ-Pspjb5O5mUm-waBYTu00CQknArCMnWhEwdbrAVkIjbQ-Pspjb6BQQgqh-26Cy1SIjh0Dt5wLtYKCed43AVkIjd45fIT6kONEwJFVVJNwSeVhsrLe-Fkd
>
>
>
>
>             --
>
>             -- 
>             Jonathan Simon, Ph. D
>             Director of Systems Engineering
>             Dust Networks at Linear Technology
>             30695 Huntwood Ave
>             Hayward, CA 94544-7021
>             (510) 400-2936 <tel:%28510%29%20400-2936>
>             (510) 489-3799 <tel:%28510%29%20489-3799>FAX
>             jsimon@linear.com <mailto:jsimon@linear.com>
>
>             **LINEAR TECHNOLOGY CORPORATION**
>             *****Internet Email Confidentiality Notice*****
>              This e-mail transmission, and any documents, files or
>             previous e-mail messages attached to it may
>             contain confidential information that is legally
>             privileged. If you are not the intended recipient, or a
>             person responsible for delivering it to the intended
>             recipient, you are hereby notified that any disclosure,
>             copying, distribution or use of any of the information
>             contained in or attached to this transmission is
>             STRICTLY PROHIBITED. If you have received
>             this transmission in error, please immediately notify me
>             by reply e-mail, or by telephone at(510) 400-2936
>             <tel:%28510%29%20400-2936>, and destroy the
>             original transmission and its attachments without reading
>             or saving in any manner. Thank you.
>
>
>             _______________________________________________
>             6tisch-security mailing list
>             6tisch-security@ietf.org <mailto:6tisch-security@ietf.org>
>             http://cp.mcafee.com/d/2DRPow76QmbEFLzzhOM-rKrhs7cFCQn1PbVJ5MsqekkSjhOrsuuusoLsS8QAHm0afB3ZzOVI-kfSfbCTA7hPXPb_nVNZNBVxzHTbEzHIYYepd7bz8XBHEShhlKM_OEuvkzaT0QSyrhdTV5xdVYsyMCqejtPpesRG9pxjFvdTw0e2qKMM-l9OwXn79OFoCnFZCUOCmdKjBiNcLjXdNBcIn8lrxrW0GnPtU02rojhKUr1vF6y0QJKjBiNcLjXdNBcIqnjh1F7U8qq87qNd42tQm2ZTOWoUQgejBiNcQgk-Pspjb6y2SDDCT63rt_U2SVUlVB0
>
>
>
>
>         --
>
>         -- 
>         Jonathan Simon, Ph. D
>         Director of Systems Engineering
>         Dust Networks at Linear Technology
>         30695 Huntwood Ave
>         Hayward, CA 94544-7021
>         (510) 400-2936
>         (510) 489-3799 FAX
>         jsimon@linear.com <mailto:jsimon@linear.com>
>
>         **LINEAR TECHNOLOGY CORPORATION**
>         *****Internet Email Confidentiality Notice*****
>          This e-mail transmission, and any documents, files or
>         previous e-mail messages attached to it may
>         contain confidential information that is legally privileged.
>         If you are not the intended recipient, or a person responsible
>         for delivering it to the intended recipient, you are
>         hereby notified that any disclosure, copying, distribution or
>         use of any of the information contained in or attached to this
>         transmission is STRICTLY PROHIBITED. If you have received
>         this transmission in error, please immediately notify me by
>         reply e-mail, or by telephone at (510) 400-2936, and destroy
>         the original transmission and its attachments without reading
>         or saving in any manner. Thank you.
>
>         _______________________________________________
>         6tisch-security mailing list
>         6tisch-security@ietf.org <mailto:6tisch-security@ietf.org>
>         http://cp.mcafee.com/d/1jWVIe3zqb5QkTzhOMC-rKrhs7cFCQn1PbVJ5MsqekkSjhOrsuuusoLsS8QAHm0afB3ZzOVI-kfSfbCO5JtvupvW_8CzBdBBfHTbECzBdzATC7xNEVVqWtAklrCzB7BgY-F6lK1FJ4SyrLOb2rPUV5xcQsCXCOsVHkiP2Di-rL00s4RtxxYGjB1SKejBiNcLjXdNBcIrsDaBypuDSrzapoKgGT2TQ1kLCXM04S-qem7T3obZ8Qg6BJOsGm9BWvpKcFBziWq8d8_13jh0Xm9EwjKyMnK-nj76y1OsGm9Cy2DSrzapoQgmQYYSUMrDrkr2pAaTam
>


-- 
email: rstruik.ext@gmail.com | Skype: rstruik
cell: +1 (647) 867-5658 | US: +1 (415) 690-7363


--------------070609060701030807080703
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: 8bit

<html>
  <head>
    <meta content="text/html; charset=UTF-8" http-equiv="Content-Type">
  </head>
  <body bgcolor="#FFFFFF" text="#000000">
    <div class="moz-cite-prefix">Dear colleagues:<br>
      <br>
      I may have missed something here, but this email thread seems to
      confuse what w/HART provides with what 6TiSCH could specify. Since
      6TiSCH is to be defined on top of 802.15.4e-2012, it can secure
      frame types using policy-defined combinations of encryption and
      authenticity (including authentication-only). In particular, a
      newbee device, just out of the wrapping paper and with no
      network-specific keying material yet, may still be able to see
      most of an authenticated, but not secured frame, even if it cannot
      check authenticity.<br>
      <br>
      So, no need to kill off functionality, come up with nested
      security constructs, two beacon types, etc; one should simply look
      at the correct standard one builds on {caveat: this assessment is
      modulo some errors in the 802.15.4e-2012 spec.}<br>
      <br>
      BTW - As an interesting aside, this seems to illustrate that
      looking at specific details *does* matter...<br>
      <br>
      Best regards, Rene<br>
      <br>
      <br>
      On 5/28/2014 7:43 PM, <a class="moz-txt-link-abbreviated" href="mailto:yoshihiro.ohba@toshiba.co.jp">yoshihiro.ohba@toshiba.co.jp</a> wrote:<br>
    </div>
    <blockquote
cite="mid:674F70E5F2BE564CB06B6901FD3DD78B2723BA70@TGXML210.toshiba.local"
      type="cite">
      <meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
      <meta name="Generator" content="Microsoft Word 15 (filtered
        medium)">
      <style><!--
/* Font Definitions */
@font-face
	{font-family:"ＭＳ 明朝";
	panose-1:2 2 6 9 4 2 5 8 3 4;}
@font-face
	{font-family:"ＭＳ ゴシック";
	panose-1:2 11 6 9 7 2 5 8 2 4;}
@font-face
	{font-family:"Cambria Math";
	panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
	{font-family:Calibri;
	panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
	{font-family:"ＭＳ Ｐゴシック";
	panose-1:2 11 6 0 7 2 5 8 2 4;}
@font-face
	{font-family:"\@ＭＳ ゴシック";
	panose-1:2 11 6 9 7 2 5 8 2 4;}
@font-face
	{font-family:"\@ＭＳ Ｐゴシック";
	panose-1:2 11 6 0 7 2 5 8 2 4;}
@font-face
	{font-family:"Lucida Grande";
	panose-1:0 0 0 0 0 0 0 0 0 0;}
@font-face
	{font-family:LucidaGrande;
	panose-1:0 0 0 0 0 0 0 0 0 0;}
@font-face
	{font-family:"\@ＭＳ 明朝";
	panose-1:2 2 6 9 4 2 5 8 3 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
	{margin:0mm;
	margin-bottom:.0001pt;
	font-size:12.0pt;
	font-family:"ＭＳ Ｐゴシック";}
a:link, span.MsoHyperlink
	{mso-style-priority:99;
	color:blue;
	text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
	{mso-style-priority:99;
	color:purple;
	text-decoration:underline;}
pre
	{mso-style-priority:99;
	mso-style-link:"HTML 書式付き \(文字\)";
	margin:0mm;
	margin-bottom:.0001pt;
	font-size:12.0pt;
	font-family:"ＭＳ ゴシック";}
span.apple-style-span
	{mso-style-name:apple-style-span;}
span.apple-converted-space
	{mso-style-name:apple-converted-space;}
span.HTML
	{mso-style-name:"HTML 書式付き \(文字\)";
	mso-style-priority:99;
	mso-style-link:"HTML 書式付き";
	font-family:"Courier New";}
span.21
	{mso-style-type:personal-reply;
	font-family:"Arial","sans-serif";
	color:#1F497D;}
.MsoChpDefault
	{mso-style-type:export-only;
	font-size:10.0pt;}
@page WordSection1
	{size:612.0pt 792.0pt;
	margin:99.25pt 30.0mm 30.0mm 30.0mm;}
div.WordSection1
	{page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026">
<v:textbox inset="5.85pt,.7pt,5.85pt,.7pt" />
</o:shapedefaults></xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]-->
      <div class="WordSection1">
        <p class="MsoNormal"><span
style="font-size:10.0pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#1F497D"
            lang="EN-US">Yes.<o:p></o:p></span></p>
        <p class="MsoNormal"><span
style="font-size:10.0pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#1F497D"
            lang="EN-US"><o:p> </o:p></span></p>
        <p class="MsoNormal"><span
style="font-size:10.0pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#1F497D"
            lang="EN-US">Yoshihiro Ohba<o:p></o:p></span></p>
        <p class="MsoNormal"><span
style="font-size:10.0pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#1F497D"
            lang="EN-US"><o:p> </o:p></span></p>
        <div>
          <div style="border:none;border-top:solid #E1E1E1
            1.0pt;padding:3.0pt 0mm 0mm 0mm">
            <p class="MsoNormal"><b><span
style="font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;"
                  lang="EN-US">From:</span></b><span
style="font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;"
                lang="EN-US"> Jonathan Simon [<a class="moz-txt-link-freetext" href="mailto:jsimon@linear.com">mailto:jsimon@linear.com</a>]
                <br>
                <b>Sent:</b> Thursday, May 29, 2014 8:42 AM<br>
                <b>To:</b> ohba yoshihiro(</span><span
                style="font-size:11.0pt">大場</span><span
style="font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;"></span><span
                style="font-size:11.0pt">義洋</span><span
style="font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;"
                lang="EN-US"> ○</span><span style="font-size:11.0pt">ＲＤＣ</span><span
style="font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;"
                lang="EN-US">□</span><span style="font-size:11.0pt">ＮＳＬ</span><span
style="font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;"
                lang="EN-US">)<br>
                <b>Cc:</b> <a class="moz-txt-link-abbreviated" href="mailto:mcr+ietf@sandelman.ca">mcr+ietf@sandelman.ca</a>; <a class="moz-txt-link-abbreviated" href="mailto:rstruik.ext@gmail.com">rstruik.ext@gmail.com</a>;
                <a class="moz-txt-link-abbreviated" href="mailto:6tisch-security@ietf.org">6tisch-security@ietf.org</a><br>
                <b>Subject:</b> Re: [6tisch-security] agenda for
                2014-05-27 6tisch security call<o:p></o:p></span></p>
          </div>
        </div>
        <p class="MsoNormal"><span lang="EN-US"><o:p> </o:p></span></p>
        <p class="MsoNormal"><span lang="EN-US">Then as long as either<o:p></o:p></span></p>
        <div>
          <p class="MsoNormal"><span lang="EN-US">a) Beacons are only
              used for advertising a network to unsychronized devices,
              or<o:p></o:p></span></p>
        </div>
        <div>
          <p class="MsoNormal"><span lang="EN-US">b) Devices only take
              timing information (time of arrival) from beacons coming
              from time parents and authenticated with the run-time key<o:p></o:p></span></p>
        </div>
        <div>
          <p class="MsoNormal"><span lang="EN-US">you are good. <o:p></o:p></span></p>
        </div>
        <div>
          <p class="MsoNormal"><span lang="EN-US"><o:p> </o:p></span></p>
        </div>
        <div>
          <p class="MsoNormal"><span lang="EN-US"> <o:p></o:p></span></p>
        </div>
        <div>
          <div>
            <div>
              <div>
                <p class="MsoNormal"><span
                    style="font-family:&quot;Lucida
                    Grande&quot;,&quot;serif&quot;;color:black"
                    lang="EN-US">-- <br>
                    Jonathan Simon, Ph. D<br>
                    Director of Systems Engineering<br>
                    Linear Technology, Dust Networks product group<br>
                    30695 Huntwood Ave<br>
                    Hayward, CA 94544-7021<br>
                    (510) 400-2936<br>
                    (510) 489-3799 FAX<br>
                    <a moz-do-not-send="true"
                      href="mailto:jsimon@linear.com">jsimon@linear.com</a><br>
                    <br>
                    **LINEAR TECHNOLOGY CORPORATION** <br>
                    *****Internet Email Confidentiality Notice***** <br>
                     This e-mail transmission, and any documents, files
                    or previous e-mail messages attached to it may
                    contain confidential information that is legally
                    privileged. If you are not the intended recipient,
                    or a person responsible for delivering it to
                    the intended recipient, you are hereby notified that
                    any disclosure, copying, distribution or use of any
                    of the information contained in or attached to this
                    transmission is STRICTLY PROHIBITED. If you have
                    received this transmission in error,
                    please immediately notify me by reply e-mail, or by
                    telephone at (510) 400-2936, and destroy the
                    original transmission and its attachments without
                    reading or saving in any manner. Thank you. <o:p></o:p></span></p>
              </div>
            </div>
          </div>
          <p class="MsoNormal"><span lang="EN-US"><o:p> </o:p></span></p>
          <div>
            <div>
              <p class="MsoNormal"><span lang="EN-US">On May 28, 2014,
                  at 4:19 PM, &lt;<a moz-do-not-send="true"
                    href="mailto:yoshihiro.ohba@toshiba.co.jp">yoshihiro.ohba@toshiba.co.jp</a>&gt;
                  &lt;<a moz-do-not-send="true"
                    href="mailto:yoshihiro.ohba@toshiba.co.jp">yoshihiro.ohba@toshiba.co.jp</a>&gt;
                  wrote:<o:p></o:p></span></p>
            </div>
            <p class="MsoNormal"><span lang="EN-US"><br>
                <br>
                <o:p></o:p></span></p>
            <blockquote style="margin-top:5.0pt;margin-bottom:5.0pt">
              <div>
                <div>
                  <p class="MsoNormal"><span
style="font-size:10.0pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#1F497D"
                      lang="EN-US">Hi Jonathan,</span><span lang="EN-US"><o:p></o:p></span></p>
                </div>
                <div>
                  <p class="MsoNormal"><span
style="font-size:10.0pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#1F497D"
                      lang="EN-US"> </span><span lang="EN-US"><o:p></o:p></span></p>
                </div>
                <div>
                  <p class="MsoNormal"><span
style="font-size:10.0pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#1F497D"
                      lang="EN-US">I am not caring about an attacker to
                      inject joining traffic, but what I care is an
                      attacker attempting to destruct basic TSCH
                      operation in the network by sending forged beacons
                      protected with the well-known key.</span><span
                      lang="EN-US"><o:p></o:p></span></p>
                </div>
                <div>
                  <p class="MsoNormal"><span
style="font-size:10.0pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#1F497D"
                      lang="EN-US"> </span><span lang="EN-US"><o:p></o:p></span></p>
                </div>
                <div>
                  <p class="MsoNormal"><span
style="font-size:10.0pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#1F497D"
                      lang="EN-US">Yoshihiro Ohba</span><span
                      lang="EN-US"><o:p></o:p></span></p>
                </div>
                <div>
                  <p class="MsoNormal"><span
style="font-size:10.0pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#1F497D"
                      lang="EN-US"> </span><span lang="EN-US"><o:p></o:p></span></p>
                </div>
                <div>
                  <p class="MsoNormal"><span
style="font-size:10.0pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#1F497D"
                      lang="EN-US"> </span><span lang="EN-US"><o:p></o:p></span></p>
                </div>
                <div>
                  <p class="MsoNormal"><span
style="font-size:10.0pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#1F497D"
                      lang="EN-US"> </span><span lang="EN-US"><o:p></o:p></span></p>
                </div>
                <div>
                  <div style="border:none;border-top:solid #E1E1E1
                    1.0pt;padding:3.0pt 0mm 0mm 0mm">
                    <div>
                      <p class="MsoNormal"><b><span
style="font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;"
                            lang="EN-US">From:</span></b><span
                          class="apple-converted-space"><span
style="font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;"
                            lang="EN-US"> </span></span><span
style="font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;"
                          lang="EN-US">6tisch-security [<a
                            moz-do-not-send="true"
                            href="mailto:6tisch-security-bounces@ietf.org"><span
                              style="color:purple">mailto:6tisch-security-bounces@ietf.org</span></a>]<span
                            class="apple-converted-space"> </span><b>On
                            Behalf Of<span class="apple-converted-space"> </span></b>Jonathan
                          Simon<br>
                          <b>Sent:</b><span
                            class="apple-converted-space"> </span>Thursday,
                          May 29, 2014 12:47 AM<br>
                          <b>To:</b><span class="apple-converted-space"> </span>ohba
                          yoshihiro(</span><span
                          style="font-size:11.0pt">大場</span><span
style="font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;"
                          lang="EN-US"> </span><span
                          style="font-size:11.0pt">義洋</span><span
                          class="apple-converted-space"><span
style="font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;"
                            lang="EN-US"> </span></span><span
style="font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;"
                          lang="EN-US">○</span><span
                          style="font-size:11.0pt">ＲＤＣ</span><span
style="font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;"
                          lang="EN-US">□</span><span
                          style="font-size:11.0pt">ＮＳＬ</span><span
style="font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;"
                          lang="EN-US">)<br>
                          <b>Cc:</b><span class="apple-converted-space"> </span><a
                            moz-do-not-send="true"
                            href="mailto:mcr+ietf@sandelman.ca"><span
                              style="color:purple">mcr+ietf@sandelman.ca</span></a>;<span
                            class="apple-converted-space"> </span><a
                            moz-do-not-send="true"
                            href="mailto:rstruik.ext@gmail.com"><span
                              style="color:purple">rstruik.ext@gmail.com</span></a>;<span
                            class="apple-converted-space"> </span><a
                            moz-do-not-send="true"
                            href="mailto:6tisch-security@ietf.org"><span
                              style="color:purple">6tisch-security@ietf.org</span></a><br>
                          <b>Subject:</b><span
                            class="apple-converted-space"> </span>Re:
                          [6tisch-security] agenda for 2014-05-27 6tisch
                          security call</span><span lang="EN-US"><o:p></o:p></span></p>
                    </div>
                  </div>
                </div>
                <div>
                  <p class="MsoNormal"><span lang="EN-US"> <o:p></o:p></span></p>
                </div>
                <div>
                  <p class="MsoNormal"><span lang="EN-US">Yoshihiro -<o:p></o:p></span></p>
                </div>
                <div>
                  <div>
                    <p class="MsoNormal"><span lang="EN-US"> <o:p></o:p></span></p>
                  </div>
                </div>
                <div>
                  <div>
                    <p class="MsoNormal"><span lang="EN-US">I don</span>’<span
                        lang="EN-US">t think this is a problem.  Nodes
                        that are in the network reject incoming frames
                        secured with the well-known key. The well-known
                        key is only used to authenticate beacons, and
                        authenticate join requests (which don</span>’<span
                        lang="EN-US">t carry synchronization
                        information).  There is a DoS vector, in that an
                        attacker can inject joining traffic (destined
                        for the network mananager) that will ultimately
                        be discarded, possibly preventing other nodes
                        from joining, and increasing the traffic in the
                        network. <o:p></o:p></span></p>
                  </div>
                </div>
                <div>
                  <div>
                    <p class="MsoNormal"><span lang="EN-US"> <o:p></o:p></span></p>
                  </div>
                  <div>
                    <div>
                      <p class="MsoNormal"><span
                          style="font-family:&quot;Lucida
                          Grande&quot;,&quot;serif&quot;" lang="EN-US">Jonathan
                          Simon, Ph. D<br>
                          Director of Systems Engineering<br>
                          Linear Technology, Dust Networks product group<br>
                          30695 Huntwood Ave<br>
                          Hayward, CA 94544-7021<br>
                          (510) 400-2936<br>
                          (510) 489-3799 FAX<br>
                          <a moz-do-not-send="true"
                            href="mailto:jsimon@linear.com"><span
                              style="color:purple">jsimon@linear.com</span></a><br>
                          <br>
                          **LINEAR TECHNOLOGY CORPORATION** <br>
                          *****Internet Email
                          Confidentiality Notice***** <br>
                           This e-mail transmission, and any documents,
                          files or previous e-mail messages attached to
                          it may contain confidential information that
                          is legally privileged. If you are not
                          the intended recipient, or a
                          person responsible for delivering it to
                          the intended recipient, you are
                          hereby notified that any disclosure,
                          copying, distribution or use of any of
                          the information contained in or attached to
                          this transmission is STRICTLY PROHIBITED. If
                          you have received this transmission in error,
                          please immediately notify me by reply e-mail,
                          or by telephone at (510) 400-2936, and destroy
                          the original transmission and its
                          attachments without reading or saving in
                          any manner. Thank you. </span><span
                          lang="EN-US"><o:p></o:p></span></p>
                    </div>
                  </div>
                  <div>
                    <p class="MsoNormal"><span lang="EN-US"> <o:p></o:p></span></p>
                  </div>
                  <div>
                    <div>
                      <div>
                        <p class="MsoNormal"><span lang="EN-US">On May
                            28, 2014, at 8:01 AM, &lt;<a
                              moz-do-not-send="true"
                              href="mailto:yoshihiro.ohba@toshiba.co.jp"><span
                                style="color:purple">yoshihiro.ohba@toshiba.co.jp</span></a>&gt;
                            &lt;<a moz-do-not-send="true"
                              href="mailto:yoshihiro.ohba@toshiba.co.jp"><span
                                style="color:purple">yoshihiro.ohba@toshiba.co.jp</span></a>&gt;

                            wrote:<o:p></o:p></span></p>
                      </div>
                    </div>
                    <div>
                      <p class="MsoNormal"><span lang="EN-US"><br>
                          <br>
                          <br>
                          <o:p></o:p></span></p>
                    </div>
                    <blockquote
                      style="margin-top:5.0pt;margin-bottom:5.0pt">
                      <div>
                        <div>
                          <p class="MsoNormal"><span
style="font-size:10.0pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#1F497D"
                              lang="EN-US">Hi Jonathan,</span><span
                              lang="EN-US"><o:p></o:p></span></p>
                        </div>
                      </div>
                      <div>
                        <div>
                          <p class="MsoNormal"><span
style="font-size:10.0pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#1F497D"
                              lang="EN-US"> </span><span lang="EN-US"><o:p></o:p></span></p>
                        </div>
                      </div>
                      <div>
                        <div>
                          <p class="MsoNormal"><span
style="font-size:10.0pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#1F497D"
                              lang="EN-US">Thank you for your answer.</span><span
                              lang="EN-US"><o:p></o:p></span></p>
                        </div>
                      </div>
                      <div>
                        <div>
                          <p class="MsoNormal"><span
style="font-size:10.0pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#1F497D"
                              lang="EN-US"> </span><span lang="EN-US"><o:p></o:p></span></p>
                        </div>
                      </div>
                      <div>
                        <div>
                          <p class="MsoNormal"><span
style="font-size:10.0pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#1F497D"
                              lang="EN-US">I think this can be an issue
                              if already joined nodes also use the
                              beacons protected with the well-known key
                              for maintaining synchronization and slot
                              allocations, as an attacker can send
                              forged beacons protected with the
                              well-known key.</span><span lang="EN-US"><o:p></o:p></span></p>
                        </div>
                      </div>
                      <div>
                        <div>
                          <p class="MsoNormal"><span
style="font-size:10.0pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#1F497D"
                              lang="EN-US"> </span><span lang="EN-US"><o:p></o:p></span></p>
                        </div>
                      </div>
                      <div>
                        <div>
                          <p class="MsoNormal"><span
style="font-size:10.0pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#1F497D"
                              lang="EN-US">Yoshihiro Ohba</span><span
                              lang="EN-US"><o:p></o:p></span></p>
                        </div>
                      </div>
                      <div>
                        <div>
                          <p class="MsoNormal"><span
style="font-size:10.0pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#1F497D"
                              lang="EN-US"> </span><span lang="EN-US"><o:p></o:p></span></p>
                        </div>
                      </div>
                      <div>
                        <div>
                          <p class="MsoNormal"><span
style="font-size:10.0pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#1F497D"
                              lang="EN-US"> </span><span lang="EN-US"><o:p></o:p></span></p>
                        </div>
                      </div>
                      <div>
                        <div>
                          <p class="MsoNormal"><b><span
style="font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;"
                                lang="EN-US">From:</span></b><span
                              class="apple-converted-space"><span
style="font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;"
                                lang="EN-US"> </span></span><span
style="font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;"
                              lang="EN-US">6tisch-security [<a
                                moz-do-not-send="true"
                                href="mailto:6tisch-security-bounces@ietf.org"><span
                                  style="color:purple">mailto:6tisch-security-bounces@ietf.org</span></a>]<span
                                class="apple-converted-space"> </span><b>On
                                Behalf Of<span
                                  class="apple-converted-space"> </span></b>Jonathan
                              Simon<br>
                              <b>Sent:</b><span
                                class="apple-converted-space"> </span>Wednesday,
                              May 28, 2014 11:49 PM<br>
                              <b>To:</b><span
                                class="apple-converted-space"> </span>ohba
                              yoshihiro(</span><span
                              style="font-size:11.0pt">大場</span><span
style="font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;"
                              lang="EN-US"> </span><span
                              style="font-size:11.0pt">義洋</span><span
                              class="apple-converted-space"><span
style="font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;"
                                lang="EN-US"> </span></span><span
style="font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;"
                              lang="EN-US">○</span><span
                              style="font-size:11.0pt">ＲＤＣ</span><span
style="font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;"
                              lang="EN-US">□</span><span
                              style="font-size:11.0pt">ＮＳＬ</span><span
style="font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;"
                              lang="EN-US">)<br>
                              <b>Cc:</b><span
                                class="apple-converted-space"> </span>Michael
                              Richardson; Rene Struik;<span
                                class="apple-converted-space"> </span><a
                                moz-do-not-send="true"
                                href="mailto:6tisch-security@ietf.org"><span
                                  style="color:purple">6tisch-security@ietf.org</span></a><br>
                              <b>Subject:</b><span
                                class="apple-converted-space"> </span>Re:
                              [6tisch-security] agenda for 2014-05-27
                              6tisch security call</span><span
                              lang="EN-US"><o:p></o:p></span></p>
                        </div>
                      </div>
                      <div>
                        <div>
                          <p class="MsoNormal"><span lang="EN-US"> <o:p></o:p></span></p>
                        </div>
                      </div>
                      <div>
                        <div>
                          <p class="MsoNormal"
                            style="margin-bottom:12.0pt"><span
                              lang="EN-US">Yoshihiro -<span
                                class="apple-converted-space"> </span><br>
                              <br>
                              Q.<span class="apple-converted-space"> </span></span><span
style="font-size:10.0pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#1F497D"
                              lang="EN-US">In w/HART, are all beacon
                              frames authenticated with a well-known key
                              even after a joining node obtained the
                              runtime link layer key?</span><span
                              lang="EN-US"><o:p></o:p></span></p>
                        </div>
                        <div>
                          <p class="MsoNormal"
                            style="margin-bottom:12.0pt"><span
style="font-size:10.0pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#1F497D"
                              lang="EN-US">A. Yes. In WirelessHART the
                              beacons (called "advertisements" but they
                              serve the same purpose and have similar
                              content) are intended for devices not yet
                              in the network, so they always use the
                              well-known key.  To discover other nodes
                              within the network, they use frames
                              secured with the runtime link-layer key.</span><span
                              lang="EN-US"><o:p></o:p></span></p>
                        </div>
                        <div>
                          <div>
                            <p class="MsoNormal"><span
style="font-size:10.0pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#1F497D"
                                lang="EN-US">Jonathan</span><span
                                lang="EN-US"><o:p></o:p></span></p>
                          </div>
                        </div>
                      </div>
                      <div>
                        <p class="MsoNormal"
                          style="margin-bottom:12.0pt"><span
                            lang="EN-US"> <o:p></o:p></span></p>
                        <div>
                          <div>
                            <div>
                              <p class="MsoNormal"><span lang="EN-US">On
                                  Tue, May 27, 2014 at 11:18 PM, &lt;<a
                                    moz-do-not-send="true"
                                    href="mailto:yoshihiro.ohba@toshiba.co.jp"
                                    target="_blank"><span
                                      style="color:purple">yoshihiro.ohba@toshiba.co.jp</span></a>&gt;
                                  wrote:<o:p></o:p></span></p>
                            </div>
                          </div>
                          <blockquote
                            style="border:none;border-left:solid #CCCCCC
                            1.0pt;padding:0mm 0mm 0mm
6.0pt;margin-left:4.8pt;margin-top:5.0pt;margin-right:0mm;margin-bottom:5.0pt">
                            <div>
                              <div>
                                <div>
                                  <p class="MsoNormal"><span
style="font-size:10.0pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#1F497D"
                                      lang="EN-US">Hi Jonathan,</span><span
                                      lang="EN-US"><o:p></o:p></span></p>
                                </div>
                              </div>
                              <div>
                                <div>
                                  <p class="MsoNormal"><span
style="font-size:10.0pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#1F497D"
                                      lang="EN-US"> </span><span
                                      lang="EN-US"><o:p></o:p></span></p>
                                </div>
                              </div>
                              <div>
                                <div>
                                  <p class="MsoNormal"><span
style="font-size:10.0pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#1F497D"
                                      lang="EN-US">Thank you for sending
                                      the summary of w/HART joining.</span><span
                                      lang="EN-US"><o:p></o:p></span></p>
                                </div>
                              </div>
                              <div>
                                <div>
                                  <p class="MsoNormal"><span
style="font-size:10.0pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#1F497D"
                                      lang="EN-US"> </span><span
                                      lang="EN-US"><o:p></o:p></span></p>
                                </div>
                              </div>
                              <div>
                                <div>
                                  <p class="MsoNormal"><span
style="font-size:10.0pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#1F497D"
                                      lang="EN-US">I have question.</span><span
                                      lang="EN-US"><o:p></o:p></span></p>
                                </div>
                              </div>
                              <div>
                                <div>
                                  <p class="MsoNormal"><span
style="font-size:10.0pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#1F497D"
                                      lang="EN-US"> </span><span
                                      lang="EN-US"><o:p></o:p></span></p>
                                </div>
                              </div>
                              <div>
                                <div>
                                  <p class="MsoNormal"><span
style="font-size:10.0pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#1F497D"
                                      lang="EN-US">In w/HART, are all
                                      beacon frames authenticated with a
                                      well-known key even after a
                                      joining node obtained the runtime
                                      link layer key? </span><span
                                      lang="EN-US"><o:p></o:p></span></p>
                                </div>
                              </div>
                              <div>
                                <div>
                                  <p class="MsoNormal"><span
style="font-size:10.0pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#1F497D"
                                      lang="EN-US"> </span><span
                                      lang="EN-US"><o:p></o:p></span></p>
                                </div>
                              </div>
                              <div>
                                <div>
                                  <p class="MsoNormal"><span
style="font-size:10.0pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#1F497D"
                                      lang="EN-US">Regards,</span><span
                                      lang="EN-US"><o:p></o:p></span></p>
                                </div>
                              </div>
                              <div>
                                <div>
                                  <p class="MsoNormal"><span
style="font-size:10.0pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#1F497D"
                                      lang="EN-US">Yoshihiro Ohba</span><span
                                      lang="EN-US"><o:p></o:p></span></p>
                                </div>
                              </div>
                              <div>
                                <div>
                                  <p class="MsoNormal"><span
style="font-size:10.0pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#1F497D"
                                      lang="EN-US"> </span><span
                                      lang="EN-US"><o:p></o:p></span></p>
                                </div>
                              </div>
                              <div>
                                <div>
                                  <p class="MsoNormal"><span
style="font-size:10.0pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#1F497D"
                                      lang="EN-US"> </span><span
                                      lang="EN-US"><o:p></o:p></span></p>
                                </div>
                              </div>
                              <div>
                                <div>
                                  <p class="MsoNormal"><span
style="font-size:10.0pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#1F497D"
                                      lang="EN-US"> </span><span
                                      lang="EN-US"><o:p></o:p></span></p>
                                </div>
                              </div>
                              <div>
                                <div>
                                  <p class="MsoNormal"><span
style="font-size:10.0pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#1F497D"
                                      lang="EN-US"> </span><span
                                      lang="EN-US"><o:p></o:p></span></p>
                                </div>
                              </div>
                              <div>
                                <div>
                                  <p class="MsoNormal"><b><span
style="font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;"
                                        lang="EN-US">From:</span></b><span
                                      class="apple-converted-space"><span
style="font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;"
                                        lang="EN-US"> </span></span><span
style="font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;"
                                      lang="EN-US">6tisch-security
                                      [mailto:<a moz-do-not-send="true"
href="mailto:6tisch-security-bounces@ietf.org" target="_blank"><span
                                          style="color:purple">6tisch-security-bounces@ietf.org</span></a>]<span
                                        class="apple-converted-space"> </span><b>On
                                        Behalf Of<span
                                          class="apple-converted-space"> </span></b>Jonathan

                                      Simon<br>
                                      <b>Sent:</b><span
                                        class="apple-converted-space"> </span>Tuesday,
                                      May 27, 2014 10:41 PM<br>
                                      <b>To:</b><span
                                        class="apple-converted-space"> </span>Rene
                                      Struik<br>
                                      <b>Cc:</b><span
                                        class="apple-converted-space"> </span>Michael
                                      Richardson;<span
                                        class="apple-converted-space"> </span><a
                                        moz-do-not-send="true"
                                        href="mailto:6tisch-security@ietf.org"
                                        target="_blank"><span
                                          style="color:purple">6tisch-security@ietf.org</span></a><br>
                                      <b>Subject:</b><span
                                        class="apple-converted-space"> </span>Re:
                                      [6tisch-security] agenda for
                                      2014-05-27 6tisch security call</span><span
                                      lang="EN-US"><o:p></o:p></span></p>
                                </div>
                              </div>
                              <div>
                                <div>
                                  <p class="MsoNormal"><span
                                      lang="EN-US"> <o:p></o:p></span></p>
                                </div>
                              </div>
                              <div>
                                <div>
                                  <div>
                                    <p class="MsoNormal"
                                      style="margin-bottom:12.0pt"><span
                                        lang="EN-US">Rene had asked on a
                                        previous call for someone to
                                        summarize WirelessHART joining -
                                        here you go.<br>
                                        <br>
                                        * One or more devices are
                                        sending beacons to advertise the
                                        presence of the network. In
                                        WirelessHART, this frame is
                                        unencrypted, but authenticated
                                        with a well known key.  The
                                        beacon contains the current ASN,
                                        which the joining device uses to
                                        synchronize its clock.<o:p></o:p></span></p>
                                    <div>
                                      <p class="MsoNormal"
                                        style="margin-bottom:12.0pt"><span
                                          lang="EN-US">* Once the
                                          joining node has heard a
                                          beacon, it continues listening
                                          for additional beacons for a
                                          short specified timeout.<o:p></o:p></span></p>
                                    </div>
                                    <p class="MsoNormal"
                                      style="margin-bottom:12.0pt"><span
                                        lang="EN-US">* The joining node
                                        encrypts a frame containing some
                                        HART specific content, including
                                        a list of beaconing neighbors it
                                        heard in the previous steps. The
                                        size of the payload is ~ 60
                                        bytes.  The packet is routed by
                                        a "proxy" node - the joining
                                        parent. The frame is
                                        authenticated using the
                                        well-known key, and encrypted
                                        using a shared symmetric key
                                        known only by the node and the
                                        manager.<br>
                                        <br>
                                        * The manager responds with a
                                        frame containing the run-time
                                        link-layer key, the node's new
                                        short address (this takes the
                                        place of PAN coordinator
                                        association), and a unicast
                                        session key and starting nonce
                                        for the manager. This frame is
                                        encrypted with the symmetric
                                        key. The payload is ~ 60 bytes,
                                        and is routed to the proxy for
                                        delivery to the joining node -
                                        the proxy uses the link-layer
                                        well known key on the frame.<o:p></o:p></span></p>
                                    <div>
                                      <p class="MsoNormal"
                                        style="margin-bottom:12.0pt"><span
                                          lang="EN-US">* At this point
                                          the joining node transitions
                                          to using the run-time
                                          link-layer key for all
                                          link-layer frames, and the
                                          manager unicast session for
                                          end-to-end manager traffic.
                                          This ends the initial security
                                          handshake.<o:p></o:p></span></p>
                                    </div>
                                    <div>
                                      <p class="MsoNormal"
                                        style="margin-bottom:12.0pt"><span
                                          lang="EN-US">* Over a number
                                          of additional frames, the
                                          manager assigns additional
                                          sessions, including broadcast
                                          sessions, and a unicast
                                          session to the Gateway (sink
                                          for all data traffic), and
                                          additional communications
                                          resources, routing
                                          information, etc.  There is no
                                          explicit transition from
                                          joining to joined - the mote
                                          transitions when certain key
                                          frames are received.<o:p></o:p></span></p>
                                    </div>
                                    <p class="MsoNormal"
                                      style="margin-bottom:12.0pt"><span
                                        lang="EN-US">* Note that a
                                        WirelessHART link-layer frame
                                        contains and additional frame
                                        type byte and a 4-byte
                                        link-layer MIC, on top of the
                                        unsecured 15.4 frame.  A network
                                        frame contains an additional
                                        16-40 bytes of addressing,
                                        routing, security and other
                                        information.<o:p></o:p></span></p>
                                  </div>
                                  <p class="MsoNormal"
                                    style="margin-bottom:12.0pt"><span
                                      lang="EN-US">Hope this help!<o:p></o:p></span></p>
                                </div>
                                <div>
                                  <div>
                                    <p class="MsoNormal"><span
                                        lang="EN-US">Jonathan<o:p></o:p></span></p>
                                  </div>
                                </div>
                                <div>
                                  <div>
                                    <p class="MsoNormal"><span
                                        lang="EN-US"> <o:p></o:p></span></p>
                                  </div>
                                </div>
                              </div>
                              <div>
                                <p class="MsoNormal"
                                  style="margin-bottom:12.0pt"><span
                                    lang="EN-US"> <o:p></o:p></span></p>
                                <div>
                                  <div>
                                    <div>
                                      <p class="MsoNormal"><span
                                          lang="EN-US">On Mon, May 26,
                                          2014 at 8:09 PM, Rene Struik
                                          &lt;<a moz-do-not-send="true"
href="mailto:rstruik.ext@gmail.com" target="_blank"><span
                                              style="color:purple">rstruik.ext@gmail.com</span></a>&gt;
                                          wrote:<o:p></o:p></span></p>
                                    </div>
                                  </div>
                                  <blockquote
                                    style="border:none;border-left:solid
                                    #CCCCCC 1.0pt;padding:0mm 0mm 0mm
6.0pt;margin-left:4.8pt;margin-top:5.0pt;margin-right:0mm;margin-bottom:5.0pt">
                                    <div>
                                      <div>
                                        <div>
                                          <p class="MsoNormal"><span
                                              lang="EN-US">Hi Michael:<br>
                                              <br>
                                              I would like to discuss
                                              the outstanding issues I
                                              summarized in my email of
                                              Tue last week, May 20,
                                              2014, 9:45am EDT (see<span
class="apple-converted-space"> </span><a moz-do-not-send="true"
href="http://cp.mcafee.com/d/5fHCMUp41ESyNt55OWtSjtPqbwVBcSyUepvdEK3zhOyCOqejrzPPPz5XCN6ABqM1hYEvIundDOx-NVsTJQXIfcLZvC4TQTS6eLsKCO-PPXX3XUVzBHFShjlKepVkffGhBrwqrhdI6XYyMCY-ehojd79KVI05bVKY01MjbX6NehDY05zAVkIjbQ-PspjbppKcvxf5q4rTKYVMedKjBiNcLjXdNBcIn8lrxrW0GnPtU02rhhuhKr1vF6y0QJKjBiNcLjXdNBcIqnjh1F7U8qq87qNd42tQm2ZTOWoUQgejBiNcQgk-Pspjb6y2SDDCT63pO_o"
                                                target="_blank"><span
                                                  style="color:purple">http://www.ietf.org/mail-archive/web/6tisch-security/current/msg00086.html</span></a>).

                                              This was also one of the
                                              action items at the
                                              conclusion of last week's
                                              6TiSCH security call.<br>
                                              <br>
                                              FYI - the w/HART
                                              communication flows were
                                              discussed during the
                                              6TiSCH security conf call
                                              the week before, on Mon
                                              May 12, 2014. If one
                                              wishes to go over this
                                              again, that is fine, but I
                                              would prefer us giving
                                              preference to taking on
                                              already articulated issues
                                              (which were assigned as
                                              homework assignment to
                                              reflect upon) first (i.e.,
                                              prior to item #4 of the
                                              proposed agenda).<br>
                                              <br>
                                              As another agenda point, I
                                              would like us to discuss
                                              the frequency of future
                                              calls (as part of EOB).<br>
                                              <br>
                                              Best regards, Rene<br>
                                              <br>
                                              <br>
                                              On 5/26/2014 10:49 PM,
                                              Michael Richardson wrote:<o:p></o:p></span></p>
                                        </div>
                                      </div>
                                      <blockquote
                                        style="margin-top:5.0pt;margin-bottom:5.0pt">
                                        <pre><span lang="EN-US">To remind, we moved the call from the 26th to the 27th at 10am EDT.<o:p></o:p></span></pre>
                                        <pre><span lang="EN-US">That's 90 minutes from this email.<o:p></o:p></span></pre>
                                        <pre><span lang="EN-US"> <o:p></o:p></span></pre>
                                        <pre><span lang="EN-US">1) notewell.<o:p></o:p></span></pre>
                                        <pre><span lang="EN-US">2) intros<o:p></o:p></span></pre>
                                        <pre><span lang="EN-US">3) recap of draft-piro-<o:p></o:p></span></pre>
                                        <pre><span lang="EN-US">4) wirelesshart -way --- how does the communication work?<o:p></o:p></span></pre>
                                        <pre><span lang="EN-US">5) how to summarize all of this to the working group<o:p></o:p></span></pre>
                                        <pre><span lang="EN-US">6) how to close this process up?<o:p></o:p></span></pre>
                                        <pre><span lang="EN-US"> <o:p></o:p></span></pre>
                                        <pre><span lang="EN-US">-- remember that the call is recorded, and the NoteWell applies.<o:p></o:p></span></pre>
                                        <pre><span lang="EN-US"> <o:p></o:p></span></pre>
                                        <pre><span lang="EN-US">-- The URL to access the webex, which will we use for audio only:<o:p></o:p></span></pre>
                                        <pre><span lang="EN-US">  <a moz-do-not-send="true" href="http://cp.mcafee.com/d/5fHCN0SyNt55OWtSjtPqbwVBcSyUepvdEK3zhOyCOqejrzPPPz5XCN6ABqM1hYEvIundDOx-NVsTJQXIfcLZvC4TQTS6eLsKCO-PPXX3XUVzBHFShjlKepVkffGhBrwqrjdI6XYyMCY-ehojd79KVIDeqR4IOQGmHM0L3-nOQGmHwzMh93o93gUVldTQmjhOgtu7em_mvIUCevLp1ZWV0sqerL6T9OFoCnFZCUOCmbAaJMJZ0lbVKY01dEEL8TdwLQzh0qmT9OFoCnFZCUOCmdbFEwQzY4dd43JoCy1eWb1uXVtcsq879OFoCq8avpKcFBzh1rjPPrz1LmTw7w17" target="_blank"><span style="color:purple">https://cisco.webex.com/cisco/j.php?MTID=m2fe139bf876cea3ec62750cd580b7908</span></a><o:p></o:p></span></pre>
                                        <pre><span lang="EN-US"> <o:p></o:p></span></pre>
                                        <pre><span lang="EN-US">-- we will resume with the etherpad at:<o:p></o:p></span></pre>
                                        <pre><span lang="EN-US">   <a moz-do-not-send="true" href="http://cp.mcafee.com/d/2DRPow71NJ5yWabBQXICXCQn1PapJ5MsO-rhs76zB5dAQsCT7DDD6bTdyd9aRw2zVg_oYKrfB3ZzOVLrFToupvW_c9LFLIctuVtdBZDDTS7TNP7bnjIyCHssPOEuvkzaT0QSOrodTV5xdVYsyMCqejtPo0fVA_yJG7jHk-Di-rL00kzhPuZYmO5p_gLbVKBTzhOnsDaBypuDSrzapoSVelb4OZfIT6kONsxlK5LE2FvdTw09J55V6VI5-Aq83iSVelb4OZfIT6kONFtd46AvwxFEwtH4Qg9ThobTvbFzzh0Velb4Ph1jXdNBcIq8bquursodJiZvpmK6GwY" target="_blank"><span style="color:purple">http://etherpad.tools.ietf.org:9000/p/notes-ietf-89-6tisch-security</span></a><o:p></o:p></span></pre>
                                        <pre><span lang="EN-US"> <o:p></o:p></span></pre>
                                        <pre><span lang="EN-US">I'm at <a moz-do-not-send="true" href="tel:%2B1%20613%20276-6809" target="_blank"><span style="color:purple">+1 613 276-6809</span></a>, IM: <a moz-do-not-send="true" href="mailto:mcr@xmpp.credil.org" target="_blank"><span style="color:purple">mcr@xmpp.credil.org</span></a> or <a moz-do-not-send="true" href="mailto:mcharlesr@gmail.com" target="_blank"><span style="color:purple">mcharlesr@gmail.com</span></a>,<o:p></o:p></span></pre>
                                        <pre><span lang="EN-US">if you need more than that to get in, or are having difficulties.<o:p></o:p></span></pre>
                                        <pre><span lang="EN-US">Please make sure your audio works, and that you mute when not talking.<o:p></o:p></span></pre>
                                        <pre><span lang="EN-US"> <o:p></o:p></span></pre>
                                        <pre><span lang="EN-US">--<o:p></o:p></span></pre>
                                        <pre><span lang="EN-US">Michael Richardson <a moz-do-not-send="true" href="mailto:mcr+IETF@sandelman.ca" target="_blank"><span style="color:purple">&lt;mcr+IETF@sandelman.ca&gt;</span></a>, Sandelman Software Works<o:p></o:p></span></pre>
                                        <pre><span lang="EN-US"> -= IPv6 IoT consulting =-<o:p></o:p></span></pre>
                                        <pre><span lang="EN-US"> <o:p></o:p></span></pre>
                                        <pre><span lang="EN-US"> <o:p></o:p></span></pre>
                                        <pre><span lang="EN-US"> <o:p></o:p></span></pre>
                                        <p class="MsoNormal"
                                          style="margin-bottom:12.0pt"><span
                                            style="color:#888888"
                                            lang="EN-US"> </span><span
                                            lang="EN-US"><o:p></o:p></span></p>
                                        <pre><span style="color:#888888" lang="EN-US">_______________________________________________</span><span lang="EN-US"><o:p></o:p></span></pre>
                                        <pre><span style="color:#888888" lang="EN-US">6tisch-security mailing list</span><span lang="EN-US"><o:p></o:p></span></pre>
                                        <pre><span style="color:#888888" lang="EN-US"><a moz-do-not-send="true" href="mailto:6tisch-security@ietf.org" target="_blank"><span style="color:purple">6tisch-security@ietf.org</span></a></span><span lang="EN-US"><o:p></o:p></span></pre>
                                        <pre><span style="color:#888888" lang="EN-US"><a moz-do-not-send="true" href="http://cp.mcafee.com/d/2DRPoO86QmbEEKnjKOrKrhs7cFCQn1PbVJ5MsqekkSjhOrsuuusoLsS8QAHm0afB3ZzOVI-kfSfbCZKDtxVB_HYMC-C-MNRXBQSnSuvvovv7csJteOaqJNPfaxVZicHs3jr1JwTvAm4TDNOb2pEVdTdAVPmEBC5eBYTu00U9GX33VkDa3JssDaBypuDSrzapoSVelb4OZfIT6kONsxlK5LE2FvdTw09J55V6VI5-Aq83iSVelb4OZfIT6kONFtd46AvwxFEwtH4Qg9ThobTvbFzzh0Velb4Ph1jXdNBcIq8bquursodLWbv" target="_blank"><span style="color:purple">https://www.ietf.org/mailman/listinfo/6tisch-security</span></a></span><span lang="EN-US"><o:p></o:p></span></pre>
                                      </blockquote>
                                      <p class="MsoNormal"
                                        style="margin-bottom:12.0pt"><span
                                          style="color:#888888"
                                          lang="EN-US"><br>
                                          <br>
                                          <br>
                                          <br>
                                        </span><span lang="EN-US"><o:p></o:p></span></p>
                                      <pre><span style="color:#888888" lang="EN-US">-- </span><span lang="EN-US"><o:p></o:p></span></pre>
                                      <pre><span style="color:#888888" lang="EN-US">email: <a moz-do-not-send="true" href="mailto:rstruik.ext@gmail.com" target="_blank"><span style="color:purple">rstruik.ext@gmail.com</span></a> | Skype: rstruik</span><span lang="EN-US"><o:p></o:p></span></pre>
                                      <pre><span style="color:#888888" lang="EN-US">cell: <a moz-do-not-send="true" href="tel:%2B1%20%28647%29%20867-5658" target="_blank"><span style="color:purple">+1 (647) 867-5658</span></a> | US: <a moz-do-not-send="true" href="tel:%2B1%20%28415%29%20690-7363" target="_blank"><span style="color:purple">+1 (415) 690-7363</span></a></span><span lang="EN-US"><o:p></o:p></span></pre>
                                    </div>
                                    <p class="MsoNormal"
                                      style="margin-bottom:12.0pt"><span
                                        lang="EN-US"><br>
_______________________________________________<br>
                                        6tisch-security mailing list<br>
                                        <a moz-do-not-send="true"
                                          href="mailto:6tisch-security@ietf.org"
                                          target="_blank"><span
                                            style="color:purple">6tisch-security@ietf.org</span></a><br>
                                        <a moz-do-not-send="true"
href="http://cp.mcafee.com/d/avndzgQ93gArhoKyyVteX9KVJ5MsOCrhs7cLCQn1NEVhjpd79JNVVVNyZPoziiJo0E-kfSfbCPVg_oYKrSWtS7Cn-LP2rWrX37nKnjpvpVZZxZYsNORQX8FGT7cYG7DR8OJMddECQjt-hojuv78I9CzATsSjDdqymokWnPtU03wCHIcfBisEeRNOsGm9BWvpKcFBzrAVkIjbQ-Pspjb5O5mUm-waBYTu00CQknArCMnWhEwdbrAVkIjbQ-Pspjb6BQQgqh-26Cy1SIjh0Dt5wLtYKCed43AVkIjd45fIT6kONEwJFVVJNwSeVhsrLe-Fkd"
                                          target="_blank"><span
                                            style="color:purple">http://cp.mcafee.com/d/avndzgQ93gArhoKyyVteX9KVJ5MsOCrhs7cLCQn1NEVhjpd79JNVVVNyZPoziiJo0E-kfSfbCPVg_oYKrSWtS7Cn-LP2rWrX37nKnjpvpVZZxZYsNORQX8FGT7cYG7DR8OJMddECQjt-hojuv78I9CzATsSjDdqymokWnPtU03wCHIcfBisEeRNOsGm9BWvpKcFBzrAVkIjbQ-Pspjb5O5mUm-waBYTu00CQknArCMnWhEwdbrAVkIjbQ-Pspjb6BQQgqh-26Cy1SIjh0Dt5wLtYKCed43AVkIjd45fIT6kONEwJFVVJNwSeVhsrLe-Fkd</span></a><o:p></o:p></span></p>
                                  </blockquote>
                                </div>
                                <div>
                                  <div>
                                    <p class="MsoNormal"><span
                                        lang="EN-US"><br>
                                        <br clear="all">
                                        <br>
                                        --<o:p></o:p></span></p>
                                  </div>
                                </div>
                                <div>
                                  <div>
                                    <p class="MsoNormal"><span
                                        style="font-size:13.5pt;font-family:&quot;Times
                                        New
                                        Roman&quot;,&quot;serif&quot;"
                                        lang="EN-US">-- <br>
                                        Jonathan Simon, Ph. D<br>
                                        Director of Systems Engineering<br>
                                        Dust Networks at Linear
                                        Technology<br>
                                        30695 Huntwood Ave<br>
                                        Hayward, CA 94544-7021<br>
                                        <a moz-do-not-send="true"
                                          href="tel:%28510%29%20400-2936"
                                          target="_blank"><span
                                            style="color:purple">(510)
                                            400-2936</span></a><br>
                                        <a moz-do-not-send="true"
                                          href="tel:%28510%29%20489-3799"
                                          target="_blank"><span
                                            style="color:purple">(510)
                                            489-3799</span></a><span
                                          class="apple-converted-space"> </span>FAX<br>
                                        <a moz-do-not-send="true"
                                          href="mailto:jsimon@linear.com"
                                          target="_blank"><span
                                            style="color:purple">jsimon@linear.com</span></a></span><span
                                        lang="EN-US"><br>
                                        <br>
                                      </span><span
                                        style="font-size:13.5pt;font-family:&quot;Times
                                        New
                                        Roman&quot;,&quot;serif&quot;"
                                        lang="EN-US">**LINEAR
                                        TECHNOLOGY CORPORATION** <br>
                                        *****Internet Email
                                        Confidentiality Notice***** <br>
                                         This e-mail transmission, and
                                        any documents, files or previous
                                        e-mail messages attached to it
                                        may contain confidential
                                        information that is legally
                                        privileged. If you are not
                                        the intended recipient, or a
                                        person responsible for
                                        delivering it to the intended
                                        recipient, you are
                                        hereby notified that any
                                        disclosure,
                                        copying, distribution or use of
                                        any of the information contained
                                        in or attached to this
                                        transmission is
                                        STRICTLY PROHIBITED. If you have
                                        received this transmission in
                                        error, please immediately notify
                                        me by reply e-mail, or by
                                        telephone at<span
                                          class="apple-converted-space"> </span><a
                                          moz-do-not-send="true"
                                          href="tel:%28510%29%20400-2936"
                                          target="_blank"><span
                                            style="color:purple">(510)
                                            400-2936</span></a>, and
                                        destroy the
                                        original transmission and its
                                        attachments without reading or
                                        saving in any manner. Thank you.</span><span
                                        lang="EN-US"><o:p></o:p></span></p>
                                  </div>
                                </div>
                              </div>
                            </div>
                            <p class="MsoNormal"
                              style="margin-bottom:12.0pt"><span
                                lang="EN-US"><br>
_______________________________________________<br>
                                6tisch-security mailing list<br>
                                <a moz-do-not-send="true"
                                  href="mailto:6tisch-security@ietf.org"><span
                                    style="color:purple">6tisch-security@ietf.org</span></a><br>
                                <a moz-do-not-send="true"
href="http://cp.mcafee.com/d/2DRPow76QmbEFLzzhOM-rKrhs7cFCQn1PbVJ5MsqekkSjhOrsuuusoLsS8QAHm0afB3ZzOVI-kfSfbCTA7hPXPb_nVNZNBVxzHTbEzHIYYepd7bz8XBHEShhlKM_OEuvkzaT0QSyrhdTV5xdVYsyMCqejtPpesRG9pxjFvdTw0e2qKMM-l9OwXn79OFoCnFZCUOCmdKjBiNcLjXdNBcIn8lrxrW0GnPtU02rojhKUr1vF6y0QJKjBiNcLjXdNBcIqnjh1F7U8qq87qNd42tQm2ZTOWoUQgejBiNcQgk-Pspjb6y2SDDCT63rt_U2SVUlVB0"
                                  target="_blank"><span
                                    style="color:purple">http://cp.mcafee.com/d/2DRPow76QmbEFLzzhOM-rKrhs7cFCQn1PbVJ5MsqekkSjhOrsuuusoLsS8QAHm0afB3ZzOVI-kfSfbCTA7hPXPb_nVNZNBVxzHTbEzHIYYepd7bz8XBHEShhlKM_OEuvkzaT0QSyrhdTV5xdVYsyMCqejtPpesRG9pxjFvdTw0e2qKMM-l9OwXn79OFoCnFZCUOCmdKjBiNcLjXdNBcIn8lrxrW0GnPtU02rojhKUr1vF6y0QJKjBiNcLjXdNBcIqnjh1F7U8qq87qNd42tQm2ZTOWoUQgejBiNcQgk-Pspjb6y2SDDCT63rt_U2SVUlVB0</span></a><o:p></o:p></span></p>
                          </blockquote>
                        </div>
                        <div>
                          <div>
                            <p class="MsoNormal"><span lang="EN-US"><br>
                                <br clear="all">
                                <br>
                                --<o:p></o:p></span></p>
                          </div>
                        </div>
                        <div>
                          <div>
                            <p class="MsoNormal"><span
                                style="font-size:13.5pt;font-family:&quot;Times
                                New Roman&quot;,&quot;serif&quot;"
                                lang="EN-US">-- <br>
                                Jonathan Simon, Ph. D<br>
                                Director of Systems Engineering<br>
                                Dust Networks at Linear Technology<br>
                                30695 Huntwood Ave<br>
                                Hayward, CA 94544-7021<br>
                                (510) 400-2936<br>
                                (510) 489-3799 FAX<br>
                                <a moz-do-not-send="true"
                                  href="mailto:jsimon@linear.com"
                                  target="_blank"><span
                                    style="color:purple">jsimon@linear.com</span></a></span><span
                                lang="EN-US"><br>
                                <br>
                              </span><span
                                style="font-size:13.5pt;font-family:&quot;Times
                                New Roman&quot;,&quot;serif&quot;"
                                lang="EN-US">**LINEAR
                                TECHNOLOGY CORPORATION** <br>
                                *****Internet Email
                                Confidentiality Notice***** <br>
                                 This e-mail transmission, and
                                any documents, files or previous
                                e-mail messages attached to it may
                                contain confidential information that
                                is legally privileged. If you are not
                                the intended recipient, or a
                                person responsible for delivering it to
                                the intended recipient, you are
                                hereby notified that any disclosure,
                                copying, distribution or use of any of
                                the information contained in or
                                attached to this transmission is
                                STRICTLY PROHIBITED. If you have
                                received this transmission in error,
                                please immediately notify me by reply
                                e-mail, or by telephone at (510)
                                400-2936, and destroy the
                                original transmission and its
                                attachments without reading or saving in
                                any manner. Thank you.</span><span
                                lang="EN-US"><o:p></o:p></span></p>
                          </div>
                        </div>
                      </div>
                      <div>
                        <p class="MsoNormal"><span
style="font-size:10.5pt;font-family:&quot;LucidaGrande&quot;,&quot;serif&quot;"
                            lang="EN-US">_______________________________________________<br>
                            6tisch-security mailing list<br>
                            <a moz-do-not-send="true"
                              href="mailto:6tisch-security@ietf.org"><span
                                style="color:purple">6tisch-security@ietf.org</span></a><br>
                            <a moz-do-not-send="true"
href="http://cp.mcafee.com/d/1jWVIe3zqb5QkTzhOMC-rKrhs7cFCQn1PbVJ5MsqekkSjhOrsuuusoLsS8QAHm0afB3ZzOVI-kfSfbCO5JtvupvW_8CzBdBBfHTbECzBdzATC7xNEVVqWtAklrCzB7BgY-F6lK1FJ4SyrLOb2rPUV5xcQsCXCOsVHkiP2Di-rL00s4RtxxYGjB1SKejBiNcLjXdNBcIrsDaBypuDSrzapoKgGT2TQ1kLCXM04S-qem7T3obZ8Qg6BJOsGm9BWvpKcFBziWq8d8_13jh0Xm9EwjKyMnK-nj76y1OsGm9Cy2DSrzapoQgmQYYSUMrDrkr2pAaTam"><span
                                style="color:purple">http://cp.mcafee.com/d/1jWVIe3zqb5QkTzhOMC-rKrhs7cFCQn1PbVJ5MsqekkSjhOrsuuusoLsS8QAHm0afB3ZzOVI-kfSfbCO5JtvupvW_8CzBdBBfHTbECzBdzATC7xNEVVqWtAklrCzB7BgY-F6lK1FJ4SyrLOb2rPUV5xcQsCXCOsVHkiP2Di-rL00s4RtxxYGjB1SKejBiNcLjXdNBcIrsDaBypuDSrzapoKgGT2TQ1kLCXM04S-qem7T3obZ8Qg6BJOsGm9BWvpKcFBziWq8d8_13jh0Xm9EwjKyMnK-nj76y1OsGm9Cy2DSrzapoQgmQYYSUMrDrkr2pAaTam</span></a></span><span
                            lang="EN-US"><o:p></o:p></span></p>
                      </div>
                    </blockquote>
                  </div>
                </div>
              </div>
            </blockquote>
          </div>
          <p class="MsoNormal"><span lang="EN-US"><o:p> </o:p></span></p>
        </div>
      </div>
    </blockquote>
    <br>
    <br>
    <pre class="moz-signature" cols="72">-- 
email: <a class="moz-txt-link-abbreviated" href="mailto:rstruik.ext@gmail.com">rstruik.ext@gmail.com</a> | Skype: rstruik
cell: +1 (647) 867-5658 | US: +1 (415) 690-7363</pre>
  </body>
</html>

--------------070609060701030807080703--


From nobody Fri May 30 13:44:33 2014
Return-Path: <jsimon@linear.com>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 651D71A87CD for <6tisch-security@ietfa.amsl.com>; Fri, 30 May 2014 13:44:26 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.188
X-Spam-Level: 
X-Spam-Status: No, score=-1.188 tagged_above=-999 required=5 tests=[BAYES_40=-0.001, HTML_MESSAGE=0.001, MPART_ALT_DIFF_COUNT=1.112, RCVD_IN_DNSWL_MED=-2.3] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id tCOttavod6Yx for <6tisch-security@ietfa.amsl.com>; Fri, 30 May 2014 13:44:24 -0700 (PDT)
Received: from p01c11o147.mxlogic.net (p01c11o147.mxlogic.net [208.65.144.70]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 716D51A6EF3 for <6tisch-security@ietf.org>; Fri, 30 May 2014 13:44:18 -0700 (PDT)
Received: from unknown [12.218.215.72] (EHLO smtpauth1.linear.com) by p01c11o147.mxlogic.net(mxl_mta-8.0.0-1) with ESMTP id 79de8835.0.35459.00-219.90512.p01c11o147.mxlogic.net (envelope-from <jsimon@linear.com>);  Fri, 30 May 2014 14:44:14 -0600 (MDT)
X-MXL-Hash: 5388ed9e2c23aa67-03dafcca8db10a64e2675ec05dd5043488b74c0f
Received: from jsimonmacmini.engineering.linear.com (unknown [10.70.48.25]) by smtpauth1.linear.com (Postfix) with ESMTPSA id 413BA740C5 for <6tisch-security@ietf.org>; Fri, 30 May 2014 13:44:05 -0700 (PDT)
From: Jonathan Simon <jsimon@linear.com>
Content-Type: multipart/alternative; boundary="Apple-Mail=_EF27AA93-E7D9-4D5B-8860-E70520FF1162"
Message-Id: <07C11C3C-2C8D-461D-9D52-885BCFEAF5D1@linear.com>
Date: Fri, 30 May 2014 13:46:27 -0700
To: 6tisch-security@ietf.org
Mime-Version: 1.0 (Mac OS X Mail 7.3 \(1878.2\))
X-Mailer: Apple Mail (2.1878.2)
X-AnalysisOut: [v=2.1 cv=d8Z7yHTE c=1 sm=1 tr=0 a=glloKNylpeYNumXQcclYyA==]
X-AnalysisOut: [:117 a=glloKNylpeYNumXQcclYyA==:17 a=elJZR9yyaN4A:10 a=D2_]
X-AnalysisOut: [GN2MmYMYA:10 a=BLceEmwcHowA:10 a=MqDINYqSAAAA:8 a=YlVTAMxI]
X-AnalysisOut: [AAAA:8 a=B4y2ELhz15Nz_4o3iLIA:9 a=CjuIK1q_8ugA:10 a=19wCD0]
X-AnalysisOut: [8tTksA:10 a=vsVyj9psLt0A:10 a=qVizmW-ZYBIA:10 a=p-HxVa_ds0]
X-AnalysisOut: [YA:10 a=xLpt9-x9cSEA:10 a=XSEAB2zw2gJGK_NTptoA:9 a=e3tJe7b]
X-AnalysisOut: [hDY2CdBnL:21 a=_W_S_7VecoQA:10 a=Jwothf0JE9V_8zsFANoA:9 a=]
X-AnalysisOut: [n3BslyFRqc0A:10 a=QEkGX9cb6z4A:10 a=Sf_gFPzhefAA:10 a=Ab4u]
X-AnalysisOut: [0_k-Ut69DYqGN58A:9 a=tZNdVoHEWWeMuOD2:21]
X-Spam: [F=0.5000000000; CM=0.500; MH=0.500(2014053017); S=0.200(2014051901)]
X-MAIL-FROM: <jsimon@linear.com>
X-SOURCE-IP: [12.218.215.72]
Archived-At: http://mailarchive.ietf.org/arch/msg/6tisch-security/BsaHCRCgVXGZcUw2_1yj-6VSCqk
Subject: [6tisch-security] WirelessHART-like joining flow
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 30 May 2014 20:44:26 -0000

--Apple-Mail=_EF27AA93-E7D9-4D5B-8860-E70520FF1162
Content-Transfer-Encoding: quoted-printable
Content-Type: text/plain;
	charset=us-ascii

Everyone -=20

Rather than dig up the old email to the main 6TiSCH group as I stated in =
the last call, I put a couple of slides together showing the basic WH =
flow and a PK (or PSK) WH-like flow.  We can discuss on the upcoming =
call.

Jonathan


--=20
Jonathan Simon, Ph. D
Director of Systems Engineering
Linear Technology, Dust Networks product group
30695 Huntwood Ave
Hayward, CA 94544-7021
(510) 400-2936
(510) 489-3799 FAX
jsimon@linear.com

**LINEAR TECHNOLOGY CORPORATION**=20
*****Internet Email Confidentiality Notice*****=20
 This e-mail transmission, and any documents, files or previous e-mail =
messages attached to it may contain confidential information that is =
legally privileged. If you are not the intended recipient, or a person =
responsible for delivering it to the intended recipient, you are hereby =
notified that any disclosure, copying, distribution or use of any of the =
information contained in or attached to this transmission is STRICTLY =
PROHIBITED. If you have received this transmission in error, please =
immediately notify me by reply e-mail, or by telephone at (510) =
400-2936, and destroy the original transmission and its attachments =
without reading or saving in any manner. Thank you.=20


--Apple-Mail=_EF27AA93-E7D9-4D5B-8860-E70520FF1162
Content-Type: multipart/mixed;
	boundary="Apple-Mail=_904A7E38-7FD4-4117-BC34-C265DA8DB008"


--Apple-Mail=_904A7E38-7FD4-4117-BC34-C265DA8DB008
Content-Transfer-Encoding: 7bit
Content-Type: text/html;
	charset=us-ascii

<html><head><meta http-equiv="Content-Type" content="text/html charset=us-ascii"></head><body style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space;"><div>Everyone -&nbsp;</div><div><br></div><div>Rather than dig up the old email to the main 6TiSCH group as I stated in the last call, I put a couple of slides together showing the basic WH flow and a PK (or PSK) WH-like flow. &nbsp;We can discuss on the upcoming call.</div><div><br></div><div>Jonathan</div><div><br></div></body></html>
--Apple-Mail=_904A7E38-7FD4-4117-BC34-C265DA8DB008
Content-Disposition: inline;
	filename=6TiSCH_WH_flow.pdf
Content-Type: application/pdf;
	x-unix-mode=0644;
	name="6TiSCH_WH_flow.pdf"
Content-Transfer-Encoding: base64

JVBERi0xLjMKJcTl8uXrp/Og0MTGCjQgMCBvYmoKPDwgL0xlbmd0aCA1IDAgUiAvRmlsdGVyIC9G
bGF0ZURlY29kZSA+PgpzdHJlYW0KeAGFk8tOwzAQRff+ikt5OZS4tseO4y2IDbtKkVhQVhUVQi1S
6f9LjJ0HoSlqUsn2uJ65PnOzxxJ7UMU/pfmxCCaqyA+80/h+xwu+sHg8GKwPMPk9rNMBH3z7vx2C
b6diiG2HWJ+YsB2VSasPbO5SZpsy6/xy5j2XSAuDGJTJQpwmZYIX6x0eGjiX93monDJa+4iSF80O
i6axfK7Z4BXyooBWDnJWoNTKQ152gas8Cnndb7QByJscMKPJ7Up2h1bFXYE3NM94ajKxMyJ1gslS
1iO5ZLwyde2ncuX8vpypmVrMdWnmBZpPLiNSYyZlyJvEAscsbB2V9jacSl6InJB1MwgK1rt4cvaH
vuFCFraqGGJbjGwGz4NxvFdHg5KsOAZvEzILWWacBKnyhFtBzg/TIcjX5f4w9aoQbaOGjoV/M/Gh
U83oNNtauc4sI82Wb2INm4WiqkIy+LFybjErYMWDzO4OQvZSaDDJeQkTbJa/MXJU/0qYwOtdS3Wv
pXdn7Jw4gOONEQPRO2XEYCKAKlI+1KlvJxnI7D2RLb78AZRBzj0KZW5kc3RyZWFtCmVuZG9iago1
IDAgb2JqCjQxNgplbmRvYmoKMiAwIG9iago8PCAvVHlwZSAvUGFnZSAvUGFyZW50IDMgMCBSIC9S
ZXNvdXJjZXMgNiAwIFIgL0NvbnRlbnRzIDQgMCBSIC9NZWRpYUJveCBbMCAwIDc5MiA2MTJdCj4+
CmVuZG9iago2IDAgb2JqCjw8IC9Qcm9jU2V0IFsgL1BERiAvVGV4dCBdIC9Db2xvclNwYWNlIDw8
IC9DczEgNyAwIFIgL0NzMiA4IDAgUiA+PiAvRm9udCA8PAovVFQyIDEwIDAgUiA+PiA+PgplbmRv
YmoKMTEgMCBvYmoKPDwgL0xlbmd0aCAxMiAwIFIgL04gMyAvQWx0ZXJuYXRlIC9EZXZpY2VSR0Ig
L0ZpbHRlciAvRmxhdGVEZWNvZGUgPj4Kc3RyZWFtCngBhVXfb9tUFD6Jb1KkFj8gWEeHisWvVVNb
uRsarcYGSZOl7UoWpenYKiTkOjeJqRsH2+m2qk97gTcG/AFA2QMPSDwhDQZie9n2wLRJU4cqqklI
e+jEDyEm7QVV4bt2YidTxFz1+ss53znnO+de20Q9X2m1mhlViJarrp3PJJWTpxaUnk2K0rPUSwPU
q+lOLZHLzRIuwRX3zuvhHYoIy+2R7v5O9iO/eovc0YkiT8BuFR19GfgMUczUa7ZLFL8H+/hptwbc
8xzw0zYEAqsCl32cEnjRxyc9TiE/CY7QKusVrQi8Bjy82GYvt2FfAxjIk+FVbhu6ImaRs62SYXLP
4S+Pcbcx/w8um3X07F2DWPucpbljuA+J3iv2VL6JP9e19BzwS7Bfr7lJYX8F+I/60nwCeB9R9KmS
fXTe50dfX60U3gbeBXvRcKcLTftqdTF7HBix0fUl65jIIzjXdWcSs6QXgO9W+LTYY+iRqMhTaeBh
4MFKfaqZX5pxVuaE3cuzWpnMAiOPZL+nzeSAB4A/tK28qAXN0jo3M6IW8ktXa26uqUHarppZUQv9
Mpk7Xo/IKW27lcKUH8sOunahGcsWSsbR6SZ/rWZ6ZxHa2AW7nhfakJ/d0ux0Bhh52D+8Oi/mBhzb
XdRSYrajwEfoREQjThYtYtWpSjukUJ4ylMS9RjY8JTLIhIXDy2ExIk/SEmzdeTmP48eEjLIXvS2i
UaU7x69wv8mxWD9T2QH8H2Kz7DAbZxOksDfYm+wIS8E6wQ4FCnJtOhUq030o9fO8T3VUFjpOUPL8
QH0oiFHO2e8a+s2P/oaasEsr9CNP0DE0W+0TIAcTaHU30j6na2s/7A48yga7+M7tvmtrdPxx843d
i23HNrBuxrbC+NivsS38bVICO2B6ipahyvB2wgl4Ix09XAHTJQ3rb+BZ0NpS2rGjper5gdAjJsE/
yD7M0rnh0Kr+ov6pbqhfqBfU3ztqhBk7piR9Kn0r/Sh9J30v/UyKdFm6Iv0kXZW+kS4FObvvvZ8l
2HuvX2ET3YpdaNVrnzUnU07Ke+QX5ZT8vPyyPBuwFLlfHpOn5L3w7An2zQz9Hb0YdAqzak21ey3x
BBg0DyUGnQbXxlTFhKt0Flnbn5OmUjbIxtj0I6d2XJzllop4Op6KJ0iJ74tPxMfiMwK3nrz4Xvgm
sKYD9f6TEzA6OuBtLEwlyDPinTpxVkX0CnSb0M1dfgbfDqJJq3bWNsoVV9mvqq8pCXzKuDJd1UeH
Fc00Fc/lKDZ3uL3Ci6MkvoMijuhB3vu+RXbdDG3uW0SH/8I761ZoW6gTfe0Q9b8a2obwTnzmM6KL
B/W6veLno0jkBpFTOrDf+x3pS+LddLfReID3Vc8nRDsfNxr/rjcaO18i/xbRZfM/WQBxeAplbmRz
dHJlYW0KZW5kb2JqCjEyIDAgb2JqCjEwNDcKZW5kb2JqCjcgMCBvYmoKWyAvSUNDQmFzZWQgMTEg
MCBSIF0KZW5kb2JqCjEzIDAgb2JqCjw8IC9MZW5ndGggMTQgMCBSIC9OIDMgL0FsdGVybmF0ZSAv
RGV2aWNlUkdCIC9GaWx0ZXIgL0ZsYXRlRGVjb2RlID4+CnN0cmVhbQp4AZ2Wd1RT2RaHz703vdAS
IiAl9Bp6CSDSO0gVBFGJSYBQAoaEJnZEBUYUESlWZFTAAUeHImNFFAuDgmLXCfIQUMbBUURF5d2M
awnvrTXz3pr9x1nf2ee319ln733XugBQ/IIEwnRYAYA0oVgU7uvBXBITy8T3AhgQAQ5YAcDhZmYE
R/hEAtT8vT2ZmahIxrP27i6AZLvbLL9QJnPW/3+RIjdDJAYACkXVNjx+JhflApRTs8UZMv8EyvSV
KTKGMTIWoQmirCLjxK9s9qfmK7vJmJcm5KEaWc4ZvDSejLtQ3pol4aOMBKFcmCXgZ6N8B2W9VEma
AOX3KNPT+JxMADAUmV/M5yahbIkyRRQZ7onyAgAIlMQ5vHIOi/k5aJ4AeKZn5IoEiUliphHXmGnl
6Mhm+vGzU/liMSuUw03hiHhMz/S0DI4wF4Cvb5ZFASVZbZloke2tHO3tWdbmaPm/2d8eflP9Pch6
+1XxJuzPnkGMnlnfbOysL70WAPYkWpsds76VVQC0bQZA5eGsT+8gAPIFALTenPMehmxeksTiDCcL
i+zsbHMBn2suK+g3+5+Cb8q/hjn3mcvu+1Y7phc/gSNJFTNlReWmp6ZLRMzMDA6Xz2T99xD/48A5
ac3Jwyycn8AX8YXoVVHolAmEiWi7hTyBWJAuZAqEf9Xhfxg2JwcZfp1rFGh1XwB9hTlQuEkHyG89
AEMjAyRuP3oCfetbEDEKyL68aK2Rr3OPMnr+5/ofC1yKbuFMQSJT5vYMj2RyJaIsGaPfhGzBAhKQ
B3SgCjSBLjACLGANHIAzcAPeIACEgEgQA5YDLkgCaUAEskE+2AAKQTHYAXaDanAA1IF60AROgjZw
BlwEV8ANcAsMgEdACobBSzAB3oFpCILwEBWiQaqQFqQPmULWEBtaCHlDQVA4FAPFQ4mQEJJA+dAm
qBgqg6qhQ1A99CN0GroIXYP6oAfQIDQG/QF9hBGYAtNhDdgAtoDZsDscCEfCy+BEeBWcBxfA2+FK
uBY+DrfCF+Eb8AAshV/CkwhAyAgD0UZYCBvxREKQWCQBESFrkSKkAqlFmpAOpBu5jUiRceQDBoeh
YZgYFsYZ44dZjOFiVmHWYkow1ZhjmFZMF+Y2ZhAzgfmCpWLVsaZYJ6w/dgk2EZuNLcRWYI9gW7CX
sQPYYew7HA7HwBniHHB+uBhcMm41rgS3D9eMu4Drww3hJvF4vCreFO+CD8Fz8GJ8Ib4Kfxx/Ht+P
H8a/J5AJWgRrgg8hliAkbCRUEBoI5wj9hBHCNFGBqE90IoYQecRcYimxjthBvEkcJk6TFEmGJBdS
JCmZtIFUSWoiXSY9Jr0hk8k6ZEdyGFlAXk+uJJ8gXyUPkj9QlCgmFE9KHEVC2U45SrlAeUB5Q6VS
Dahu1FiqmLqdWk+9RH1KfS9HkzOX85fjya2Tq5FrleuXeyVPlNeXd5dfLp8nXyF/Sv6m/LgCUcFA
wVOBo7BWoUbhtMI9hUlFmqKVYohimmKJYoPiNcVRJbySgZK3Ek+pQOmw0iWlIRpC06V50ri0TbQ6
2mXaMB1HN6T705PpxfQf6L30CWUlZVvlKOUc5Rrls8pSBsIwYPgzUhmljJOMu4yP8zTmuc/jz9s2
r2le/7wplfkqbip8lSKVZpUBlY+qTFVv1RTVnaptqk/UMGomamFq2Wr71S6rjc+nz3eez51fNP/k
/IfqsLqJerj6avXD6j3qkxqaGr4aGRpVGpc0xjUZmm6ayZrlmuc0x7RoWgu1BFrlWue1XjCVme7M
VGYls4s5oa2u7act0T6k3as9rWOos1hno06zzhNdki5bN0G3XLdTd0JPSy9YL1+vUe+hPlGfrZ+k
v0e/W3/KwNAg2mCLQZvBqKGKob9hnmGj4WMjqpGr0SqjWqM7xjhjtnGK8T7jWyawiZ1JkkmNyU1T
2NTeVGC6z7TPDGvmaCY0qzW7x6Kw3FlZrEbWoDnDPMh8o3mb+SsLPYtYi50W3RZfLO0sUy3rLB9Z
KVkFWG206rD6w9rEmmtdY33HhmrjY7POpt3mta2pLd92v+19O5pdsN0Wu067z/YO9iL7JvsxBz2H
eIe9DvfYdHYou4R91RHr6OG4zvGM4wcneyex00mn351ZzinODc6jCwwX8BfULRhy0XHhuBxykS5k
LoxfeHCh1FXbleNa6/rMTdeN53bEbcTd2D3Z/bj7Kw9LD5FHi8eUp5PnGs8LXoiXr1eRV6+3kvdi
72rvpz46Pok+jT4Tvna+q30v+GH9Av12+t3z1/Dn+tf7TwQ4BKwJ6AqkBEYEVgc+CzIJEgV1BMPB
AcG7gh8v0l8kXNQWAkL8Q3aFPAk1DF0V+nMYLiw0rCbsebhVeH54dwQtYkVEQ8S7SI/I0shHi40W
SxZ3RslHxUXVR01Fe0WXRUuXWCxZs+RGjFqMIKY9Fh8bFXskdnKp99LdS4fj7OIK4+4uM1yWs+za
crXlqcvPrpBfwVlxKh4bHx3fEP+JE8Kp5Uyu9F+5d+UE15O7h/uS58Yr543xXfhl/JEEl4SyhNFE
l8RdiWNJrkkVSeMCT0G14HWyX/KB5KmUkJSjKTOp0anNaYS0+LTTQiVhirArXTM9J70vwzSjMEO6
ymnV7lUTokDRkUwoc1lmu5iO/kz1SIwkmyWDWQuzarLeZ0dln8pRzBHm9OSa5G7LHcnzyft+NWY1
d3Vnvnb+hvzBNe5rDq2F1q5c27lOd13BuuH1vuuPbSBtSNnwy0bLjWUb326K3tRRoFGwvmBos+/m
xkK5QlHhvS3OWw5sxWwVbO3dZrOtatuXIl7R9WLL4oriTyXckuvfWX1X+d3M9oTtvaX2pft34HYI
d9zd6brzWJliWV7Z0K7gXa3lzPKi8re7V+y+VmFbcWAPaY9kj7QyqLK9Sq9qR9Wn6qTqgRqPmua9
6nu37Z3ax9vXv99tf9MBjQPFBz4eFBy8f8j3UGutQW3FYdzhrMPP66Lqur9nf19/RO1I8ZHPR4VH
pcfCj3XVO9TXN6g3lDbCjZLGseNxx2/94PVDexOr6VAzo7n4BDghOfHix/gf754MPNl5in2q6Sf9
n/a20FqKWqHW3NaJtqQ2aXtMe9/pgNOdHc4dLT+b/3z0jPaZmrPKZ0vPkc4VnJs5n3d+8kLGhfGL
iReHOld0Prq05NKdrrCu3suBl69e8blyqdu9+/xVl6tnrjldO32dfb3thv2N1h67npZf7H5p6bXv
bb3pcLP9luOtjr4Ffef6Xfsv3va6feWO/50bA4sG+u4uvnv/Xtw96X3e/dEHqQ9eP8x6OP1o/WPs
46InCk8qnqo/rf3V+Ndmqb307KDXYM+ziGePhrhDL/+V+a9PwwXPqc8rRrRG6ketR8+M+YzderH0
xfDLjJfT44W/Kf6295XRq59+d/u9Z2LJxPBr0euZP0reqL45+tb2bedk6OTTd2nvpqeK3qu+P/aB
/aH7Y/THkensT/hPlZ+NP3d8CfzyeCZtZubf94Tz+wplbmRzdHJlYW0KZW5kb2JqCjE0IDAgb2Jq
CjI2MTIKZW5kb2JqCjggMCBvYmoKWyAvSUNDQmFzZWQgMTMgMCBSIF0KZW5kb2JqCjE2IDAgb2Jq
Cjw8IC9MZW5ndGggMTcgMCBSIC9GaWx0ZXIgL0ZsYXRlRGVjb2RlID4+CnN0cmVhbQp4AaVZ23Ic
NRB911cozoVxUh7PjDQ7M9wT25ALhBiW4oHwQLmSCpQNJIZP4j9pXc6Rxppdr43tqp3VSN3q7tOn
W/J7farfa7OSv7qRn04P7VRP8qN72+gPb/RP+g99eHTZ6rNL3frfyzO3oB/6MO9CD314VBw75xgE
G32eqXHf3um3D53kzklu/K9Ifi8q3JdWj03dtNYOul8N9WT7Tp1d6CdrLdtyv/LRit6uMa0+kC/r
C324XneycP1W/6yrO/u6qa2u9vb1QVP3urobB+75T1Xdx4swoKsHfqDNHh5h5KPXVVz9ev+hHzS6
im9V9TEkUeQB5rRuWefn/qLXz/XJ2jscNtqhrTszads2dduNfTSxtcEH7uNAvgTbTLCt+ndfr38P
khCYBfddK9rWU9Oa1ZBp6KMG8V2mYVOArtXQDRFTyYYUn0+8i8Q1n0YXfYaBR/tKIiZx+Ny9kU8E
yHwRB+je2q+RKDNS5ksM2T48Ka7n7Mf+jUiGQGOh4wmWUyJCuOe3JUCC4Ewr5kAKgcCHIy9XzD12
NlhVcTM0BkL4RrawCJpp9KAxk81BIz6TBBawnOll/CTfH9+bnHniABcF+bhzcuLc3yrnyEWdEahm
GLxOHXJxrmiohRciVpXPwxtidaP0DKtOiQpKbgfXuRKVTMjgmlmSvEbEflUi1nGMeK+LbxhTsk8e
1IDuOR/p6muPEMFyRHDCLYnJEpQlzFOaUFUGc+UTaTeYR75cgHngVFWdODMlE/D5NH7fBB4Att8C
HhuDmvyNZKI9yFZ4bnJqxWHP4LmYxaralsWbzaMcKLi3L34TBUxeRiJyi65Mmhs2U6pGxsMebJvB
JLCeR4NW3qDMweTGF8HUzXkKV1sJuBSUxTxFQQmuVlIsv/FihZ0IXDrdmhLDdANNiNMTZrno0Nkk
1ZIe+xbRoi64kNLi4owkXxYb5GS+ghjKHZxqX3xjQaFqhGJLRcltzBhReC20Jxae7syunnZtCd0A
bBFAJXDExEyz1OaoGVzcrKBZSV+UiMw1DRmD3a5vMFF60ZJc4eJI+DtwsUq9HVoHKClgup2Lla9b
PrbfxRgzQ4iLnbg4AgPQAS4YfFICQcXE4JywyKdkYPabkrOgVGpwTs5uW3lXg9aAWbWRnBMpB3JW
1Y7k3I1Ek+uy52hyjKFm7TU8RXfsSs5ayPk25m3gRlW9AJ8w8rdjsyyAgAN7SVp5BB5ibQXJwCEu
adVCpx/poltNSNplN89PMffRdDLy3MpxLBY0GwPYCepMAkBEe2kWpSOKhuhOPQcsNXELqjIgd6iE
47gnisEMDvAh6lYLtYdirjctZ8qCo7v+RhzNrfVAKrMfBiavmCfAHx8w6YrNKp0wHUi2HAc7OY1v
rN5ZA3w7Zp9LzxrgWzN7dmoHs0NJUT62M3s4kXhmf1Uye8QvD+P0OB/2fDCkc2J+MnRMHBMPZVnC
A/bl5FMvUPoXQJ3Jgyibxx4lwuDlagJYWrwdAz4v5e3UyN3HyswreuqRCdVoU7aJ7/22ZOfcKBI4
w+UNNiUlSc6X/fx82fVNPTbtuLi/6qnYj4uErPiDCtuA8gIi+aVHMpUWMsaMKOjhASKRKM8fzLIr
HdiOiBfhxATeQlj6j/ro9bI9wOREEHFyao25mg+0qEQQ5ySTYhZAE9fQFF5mcHHeHWUhL4iynW5U
nWaNTizq8B+dxUyEy/NGx4WnbHRUurVbaHR2AALz7jie4LCrsiZGgGACt43dws1TlMSQ08skn02s
HvHejh1YfZ7ky3jfpecj4LF9RpwPW7CVecmdXRNC4aWZQe6i2Nraruw4ajsOtTWD1RfaTqvajDYb
O1cca+1Q99PQy30v12Zj7/z1cvnG9m09ddqYqR6twi30qzcfzt789fc/v57rD7+53YRZ7lQUZi7o
kHuqw2cXrT7+Uy5eT+UIssNd96YLz8HWxtp+pdtmqlddN4C5xnAycx8HwoVXr6J/IKhmDk2MeL3g
dqybVdt3i/LDtcz/u+q+csOdkQTPnTvssmvqYZhctSq9kAgsptxL9NJ3Y2qZhQIVTlREKk/LAHx6
E+lPZfezmET/34iLjHB45NrEQhBJvbuzUfYvB4MMgziwTOEkNNvu2ESyjLvCYppXcpbL6/KCbEnY
oqLFpoU4GEeXBasRp/d5GhT3ebNqEW0pTFiMULiFyxywibQ55QjYsiyPcSixHN3GVS+Si6MG/AuC
UhISCA7WXXIurCJIeCLlw/pHecksU6f/ATJvEJAKZW5kc3RyZWFtCmVuZG9iagoxNyAwIG9iagox
Njg5CmVuZG9iagoxNSAwIG9iago8PCAvVHlwZSAvUGFnZSAvUGFyZW50IDMgMCBSIC9SZXNvdXJj
ZXMgMTggMCBSIC9Db250ZW50cyAxNiAwIFIgL01lZGlhQm94ClswIDAgNzkyIDYxMl0gPj4KZW5k
b2JqCjE4IDAgb2JqCjw8IC9Qcm9jU2V0IFsgL1BERiAvVGV4dCAvSW1hZ2VCIC9JbWFnZUMgL0lt
YWdlSSBdIC9Db2xvclNwYWNlIDw8IC9DczEgNyAwIFIKL0NzMiA4IDAgUiA+PiAvRm9udCA8PCAv
VFQ1IDIxIDAgUiAvVFQyIDEwIDAgUiAvVFQzIDE5IDAgUiA+PiAvWE9iamVjdCA8PAovSW0xIDIy
IDAgUiA+PiA+PgplbmRvYmoKMjIgMCBvYmoKPDwgL0xlbmd0aCAyMyAwIFIgL1R5cGUgL1hPYmpl
Y3QgL1N1YnR5cGUgL0ltYWdlIC9XaWR0aCAxMzgxIC9IZWlnaHQgMTAzOAovSW50ZXJwb2xhdGUg
dHJ1ZSAvQ29sb3JTcGFjZSAyNCAwIFIgL0ludGVudCAvUGVyY2VwdHVhbCAvU01hc2sgMjUgMCBS
IC9CaXRzUGVyQ29tcG9uZW50CjggL0ZpbHRlciAvRmxhdGVEZWNvZGUgPj4Kc3RyZWFtCngB7N15
7CxVgS/w5xLcFVFHUBhxvVxcgBEFBQEFQRDEDRDhKuCCghsqoqAERXAGiWyC4aIicY/OQHCBiELc
AmgcMOIYUYIacYw6mcGoRCHz3vfNyTup19uv+9fdv19X/T79x+/Wra46VfWp7lNd3zp16n/9Ly8C
BAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQ
IECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECA
AAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAEC
BAgQIECAAAECBAgQIECAAAECBAgQIECAQHcENtlkk/vc5z739iLQHoG73e1u3fkG2hICBAgQIECA
AAECBAgspMBBBx107rnnnu1FoA0C55xzzumnn7755psv5JfJShEgQIAAAQIECBAgQKA7Ahs3bvzf
XgTaI3DHHXesW7euO99AW0KAAAECBAgQIECAAIGFFDjvvPPac6ZoTQn87//4j/94whOesJBfJitF
gAABAgQIECBAgACB7giIC5yBt0tAXNCd2seWECBAgAABAgQIECCwwALignadLFtbccECVydWjcCq
CegBddXo196CfdjW3j63xZ0V2GyzzfbZZ5+9vQh0VKB8vLfccstpvsPiAifg7RIQF0zzfTcvge4J
PPCBD3zb29524oknvsuLwIoI5MN23HHH/d3f/V33vk22iMBaE9hhhx3u9CLQaYG//e1vhx9++DRf
bXFBu06Wra24YJrvu3kJdE/g4Q9/eA6F6kYCKynwl7/8ZZtttunet8kWEVhrAv/wD/+wklWHZRFY
eYH//u//3rBhwzRfbXHByu81S5xGQFwwzffdvAS6J5CLvLfffvs0tYp5CUwqkCORZ/R0rzKxRWtQ
QFwwae1n+tYJiAtat8us8JQC4oI1eDS3yQRGCIgLpqxUzb4MAXHBiK+ktwi0SEBcsIwK0CztEhAX
tGt/WdvpBcQFLToKW1UCKyAgLpi+XlXCpALighX4alsEgRUQEBdMWvuZvnUC4oLW7TIrPKWAuGAF
jp4WQaBFAuKCKStVsy9DQFzQoirCqhIYISAuWEYFaJZ2CYgL2rW/rO30AuKCEUc9bxFYgwLigunr
VSVMKiAuWINVjU3upIC4YNLaz/StExAXtG6XWeEpBcQFnTxe2ygCyxYQF0xZqZp9GQLigmV/Yc1I
YKEExAXLqADN0i4BcUG79pe1nV5AXLBQx1krQ2DVBcQF09erSphUQFyw6l98K0BgJgLigklrP9O3
TkBc0LpdZoWnFBAXzOT4qBACnREQF0xZqZp9GQLigs5UIDZkjQuIC5ZRAZqlXQLignbtL2s7vYC4
YI0f2W0+gR4BccH09aoSJhUQF/R8Df2XQEsFxAWT1n6mb52AuKB1u8wKTykgLmjpEdlqE5iTgLhg
ykrV7MsQEBfM6eusWAIrLCAuWEYFaJZ2CYgL2rW/rO30AuKCFT6SWhyBBRcQF0xfryphUgFxwYJX
C1aPwJgC4oJJaz/Tt05AXNC6XWaFpxQQF4x5BDQZgTUiIC6YslI1+zIExAVrpHqxmZ0XEBcsowI0
S7sExAXt2l/WdnoBcUHnj902kMBEAuKC6etVJUwqIC6Y6EtqYgILKyAumLT2M33rBMQFrdtlVnhK
AXHBwh5zrRiBVREQF0xZqZp9GQLiglX5slsogZkLiAuWUQGapV0C4oJ27S9rO72AuGDmx0oFEmi1
gLhg+npVCZMKiAtaXWlYeQJVQFwwae1n+tYJiAtat8us8JQC4oJ6jDNAgEAExAVTVqpmX4aAuEDl
Q6AbAuKCZVSAZmmXgLigXfvL2k4vIC7oxgHaVhCYlYC4YPp6VQmTCogLZvX9VQ6B1RUQF0xa+5m+
dQLigtbtMis8pYC4YHUPrJZOYNEExAVTVqpmX4aAuGDR6gHrQ2B5AuKCZVSAZmmXgLigXfvL2k4v
IC5Y3gHRXAS6KiAumL5eVcKkAuKCrtYntmutCYgLJq39TN86AXFB63aZFZ5SQFyw1g7ltpfAaAFx
wZSVqtmXISAuGP2t9C6BtgiIC5ZRAZqlXQLignbtL2s7vYC4oC2HYOtJYGUExAXT16tKmFRAXLAy
325LITBvAXHBpLWf6VsnIC5o3S6zwlMKiAvmfehUPoF2CYgLpqxUzb4MAXFBu2oJa0tgmIC4YBkV
oFnaJSAuaNf+srbTC4gLhh3yjCewNgXEBdPXq0qYVEBcsDZrG1vdPQFxwaS1n+lbJyAuaN0us8JT
CogLunewtkUEphEQF0xZqZp9GQLigmm+s+YlsDgC4oJlVIBmaZeAuKBd+8vaTi8gLlicg6w1IbAI
AuKC6etVJUwqIC5YhO++dSAwvYC4YNLaz/StExAXtG6XWeEpBcQF0x8clUCgSwLigikrVbMvQ0Bc
0KU6xLasZQFxwTIqQLO0S0Bc0K79ZW2nFxAXrOXDum0n0C8gLpi+XlXCpALigv5vojEE2iggLpi0
9jN96wTEBa3bZVZ4SgFxQRsPx9aZwPwExAVTVqpmX4aAuGB+32glE1hJAXHBMipAs7RLQFzQrv1l
bacXEBes5GHUsggsvoC4YPp6VQmTCogLFr9msIYExhEQF0xa+5m+dQLigtbtMis8pYC4YJzDn2kI
rB0BccGUlarZlyEgLlg7NYwt7baAuGAZFaBZ2iUgLhh/f91111233377fy71+tOf/vS3v/1t/GLL
lCn5qquuOumkk171qlc9//nP33///Tds2HDiiSdmZBY4urQ77rhjqZUa8H5+q/z5z3/OB2B04d17
V1zQ7QO3rSMwqYC4oHv1/OJvkbhg0u+p6QkspoC4YPHrW2s4pYC4YHzAn/3sZ9ttt93DHvawhw9/
bb755ttuu23O948//vhrrrlmnMJ//vOfv/3tb3/MYx5zz3ves78mzMhHPepRyQ1uueWWYaWdeuqp
w9do6DsPechDDj300IQbw4rt6nhxQf/HzBgCa1lAXNDV2n6Rt0tcsJbrHNveJQFxwSLXtNZtJgLi
gvEZ/+3f/m2LLbYYv4p74AMf+LKXvewXv/jFiEVceOGFSQPGKTOTXX755QOLeutb3zpOCf3T7Lnn
nmnVMLDMDo8UF/R/EowhsJYFxAUdrvAXdtPEBWu5zrHtXRIQFyxsNWvFZiUgLhhfMnHBIx7xiFLF
3ec+90ka0P+6//3vf6973atZDe6xxx4D7yaI/Ic+9KH73ve+deIHPOAB69evP+SQQ4477rhjjz12
3333feITn5gC6wRpD/DlL3+5f4Xf9ra31Wmy9HuP98qU++23n7ig0hkgQGBtCogL+g8rxsxbQFyw
NmsbW909AXHBvGtL5a+6gLhg/F3QjAtyUv+tb33r6r7XpZdeevbZZ7/whS9snuafcMIJ/Us599xz
6zT3uMc9kipceeWV/ZOlwGc84xm1dt1yyy1vuOGGnslqXJByTjvttPPPP//DY7yynldcccWdd97Z
U1rn/6t1Qf04GSBAIALigs5X+wu4geIClQ+BbgiICxawgrVKsxUQF4zv2YwL0tvA6Bk3bty42Wab
lZowrQK+//3vN6e/6aab0gdCeTcNFU4++eQRvSOmJ8OXv/zltVLde++9M6ZZWo0L0tFBfoE03zLc
LyAuqJ8lAwQIREBc0F9PGjNvAXGByodANwTEBfOuLZW/6gLigvF3QTMuSHcBS85YuxTIzQHnnHNO
c/qXvvSlpZK8+93vPrDtQXPiDP/+97/fddddyyxpk3Ddddc1J2jGBbfddlvzLcP9AuKCbhygbQWB
WQmIC/rrSWPmLSAumNX3VzkEVldAXDDv2lL5qy4gLhh/F0waF+TmglqDpS+CuqAf//jH6fSgvPWk
Jz3pt7/9bX1rxMAll1xSH53w3ve+tzmluKCpseSwuKB+LA0QIBABccGS1aYJZi4gLlD5EOiGgLhg
5tWjAhdNQFww/h6ZNC749a9/XXsn2H///euCXve615UacpNNNjnjjDPq+NEDv/nNb3bYYYcHPehB
D37wgw8//PDsuDq9uKBSjDMgLujGAdpWEJiVgLhgnJrTNLMVEBfM6vurHAKrKyAumG3dqLQFFBAX
jL9TJo0L0oogfQ+WSuzII48sC7rrrrue8pSnlJEPfehDx2xaUOb94x//mB8YeWWgudrigqbGksMB
fMITnrC6BxdLJ0BgcQTEBUtWmyaYuUCOROvWrVucb4E1IUBgeQLigplXjwpcNAFxwfh7ZNK44IIL
Lig1T1oRfPCDHywLuvnmm+vTGHfZZZfxlz5iymZckEYII6b0VgTEBcs7IJqLQFcFxAUODSsvIC7o
an1iu9aagLhg5etPS1xhAXHB+ODNuCBn6KNnzMTbbLNNqTM33XTT73znO2X6r3/967XjgtyVMLqQ
Md9txgW33HJLnpswzmvEsxjGXG5LJxMXrLVDue0lMFpAXNDSyrzVqy0uGP2t9C6BtgiIC1pdFVv5
cQTEBeMolWmaccGb3vSmnJL/5f9//fnPf87NBXlI4sUXX7ztttvWim7Dhg11KZdeeul973vf8tYH
PvCBOn6agRoX3O1ud3vGM56xxxiv3Xbb7dRTT51moe2dV1xQP5kGCBCIgLigvfV5e9dcXKDyIdAN
AXFBe+thaz6mgLhgTKhM1owLckPB0572tKf2vdavX7/FFls0K8Ctt9761ltvrUvJAw5qhwa5W6GO
n2agxgXN5S45/IIXvGCahbZ3XnHBkp8NExBYUwLigvbW5+1dc3HBmqpkbGyHBcQF7a2HrfmYAuKC
MaEyWTMuGLPe23777a+//vrmIj71qU/V5yGmEULzrWUPN+OC9JNwr/FeBx100LKX2OoZxQVjfnpN
RmCNCIgLWl2lt3TlxQVrpHqxmZ0XEBe0tBK22uMLiAvGt2rGBWn2f/chr3RNsNVWWyUoOProo//w
hz/0lH/ZZZfVmxFOO+20nneX998aF6TdwimnnHLWWWd9aKnXmWeeeeWVVy5vcW2fS1zQ+WO3DSQw
kYC4oO21ehvXX1ww0ZfUxAQWVkBc0MYa2DpPJCAuGJ+rGRcceOCB6YXgX/peGXnNNdfk8Qfpx2Bg
yVdfffWDHvSgUukdddRRA6eZdGSNC9Ju4T//8z8nnX2tTS8uWNhjrhUjsCoC4oK1dhRYhO0VF6zK
l91CCcxcQFywCDWqdZirgLhgfN5mXHDCCSeMP2NzyhtvvPFhD3tYqaz23HPP5ltLDl933XWf/J/X
F77whTvvvLNO34wLbrvttjrewEABccHMj5UKJNBqAXHBwKrSyLkKiAtaXWlYeQJVQFww16pS4Ysg
IC4Yfy8044K3vvWt48/YnDKtDp7whCeUSiYDd911V/PdEcOZMk89KDPmsQt//etf68TigkoxzoC4
oB7jDBAgEAFxwTg1p2lmKyAuUPkQ6IaAuGC2daPSFlBAXDD+TplJXJDFvehFLyo1ZDox+OxnPzvm
CvzkJz+pz1x4y1ve0pxLXNDUWHJYXNCNA7StIDArAXHBktWmCWYuIC6Y1fdXOQRWV0BcMPPqUYGL
JiAuGH+PzCou2LhxY63Zdtlll2Y7gRErkw4M079imTE9JDSnFBc0NZYcFhfUj58BAgQiIC5Ysto0
wcwFxAUqHwLdEBAXzLx6VOCiCYgLxt8js4oLbr/99txNUCrJNDDoOfcfuD6/+MUvtt566zLLox71
qF//+tfNycQFTY0lh8UF3ThA2woCsxIQFyxZbZpg5gLigll9f5VDYHUFxAUzrx4VuGgC4oLx98is
4oIs8fzzz6+VW6KDlDxiNe64444DDjigTL/JJpuceuqpPRM344J///d/73nXf3sExAX1s2eAAIEI
tDEuOOOMM9I4bdeRr+c+97nHHnvseeedd/311/dUg/676gLiApUPgW4IzDwuyM/+E088cef/eR1/
/PF/+tOfZlJfXXjhhTlqpBu0I4888o9//ONMyvzb3/6W0p75zGfmWHTBBRfMpMx5F5ITpRe84AVl
nQOSM7JxlnjRRReFLq9XvOIVuew7ziyzmibXiPfee+9tttlmp512+td//ddZFTtROeKC8blmGBf8
4Q9/yEeu1pNJDP75n/85+6J/ZX7605/uv//+dcr8/Mt3s2eyZlzws5/9LL0ppm4Z5/WXv/xl4EJ7
yu/Yf8UF9eNkgACBCLQxLjjssMPG3He5i+1+97vfa17zmnSA07HKvNWbIy4Y8wNsMgILLjDzuCA/
4PfZZ5+y1XvsscesnpD+pje9qZSZjtZT/8yk/sz91LX/9qTTMylz3oX8/Oc/32yzzeqHaquttrrl
lluWXGh6jSuzPOYxj/n973+/5PQznCBndltuuWWWfv/73/+aa66ZYcnjFyUuGN9qhnFBFpq9/6Qn
Pal+XO9zn/sk6coDFz7+8Y9/9atfveyyy84+++yDDz64fELKZI973ONuvvnm/hWucUF+Fj7lKU95
6lOfmrprnNdee+2V2xz6C+z2GHFB/dQZIEAgAm2MC3KBY9J9lxvZrrzyym5X7y3aOnHBpB9g0xNY
TIH83p5tzZO4YL/99isb+5znPGdWccGb3/zmUua6detmGBfkqncp9g1veMNsHeZUWsKB+kT7suYb
NmxY8uJpTtDKxIlHVjguSL5RbkjfdNNNv/nNb86JZXSx4oLRPs13ZxsXpOQf/vCHT3/608vHr/7N
ZaAHPehBD3zgA+9973vXkRl44hOfOKwJSo0LmtOPM5wF/fjHP25u41oYFheM89kwDYG1I9DquCAd
4Lz73e9OX7gfarzy39NPPz0/b3bbbbfU83VXJkz+r//6r7VQzy/+NooL6sfSAIFWC7QlLnjPe97z
0P95pXnzrCKItC7Itc5SbG6gWPyKN2vYHxfkMHr55ZePXnlxQUKVab6nuS9ytHBn3r3ppptq85VZ
NbnJD4a0EW02IejfF5tvvvlRRx116623DpNMoNc/1zhjHvCAB2SjhhXb1fHignE+G6YhsHYEWh0X
JFv+1a9+NaK6/vrXv552BXVvfvCDHxwxsbdWTEBcUD+TBgi0WqAtcUFuVf7d737329/+NpXPkhfT
x6wJU05KS7F5pfwx51rdyfrjgnz8tttuu9FZurhAXDDm5zYdg3zhC1/IzQJ53XDDDWPONc5kabeQ
1OXFL35xmrgkHMjFoC222CIdGrzwhS/MRaIbb7xxdCGZoKzVpH8/97nPzaq3k9FruFDvigtafVy2
8gRmLtD2uGBEmFzq3quvvjpXf4rbnnvumX60FqpOXpsrIy6Y+RdZgQRWRaAtccHarGn7t7rGBbmD
u2bp97jHPd7//vf3T1zHiAvEBfXDsLoD6cMwXSCmx870gVnSvzTyWd1V6uTSxQWrcjy1UAILK9D5
uCC92u6www7FP900pQ4cXbfnAJSbJTPXwMlyX21+bqVl2o9+9KN0wjP6iszAEmY+clZXyma+YiMK
FBcsbIVgxQhMJLC6cUFOGdKNbe5uzpXH2267bUSdM+lbqVd/85vfpLZPA7YZ3ryQlUyZWe2Jni+Q
CjPnRzM53NS44O53v3u6f8zjBsrufvjDH/6DH/xgmNL4cUEaWqSb+uyR3O79y1/+8s477xxWZv/4
TFzOBJtbOlHfBTl85wpCOqZLOf3lL3tMPgzigmXrmbGNAuKCiY6DJibQeYHOxwWpqOsTdnKTZn6n
lao7v2pOPvnkdPh8yimnlIfw5kfO6173uh133PHv//7v0+luTw2f3yHpg3fffffNFZkHP/jBuQ/i
kY98ZHriet/73pcZeyb+9re//cY3vvG4445L+cOeVHXXXXfliZDveMc7TjrppAyk/6jvfe976Y8r
c7397W+/9tpre8ps/veTn/xkSs4rvTQMSzaa0y/asLig8xWLDVwjAqsVF3zpS1/K7cxpipyO+9Jn
fv6ml7NXvepVX/nKVwZWd9/61rdO+5/Xxz72sZ7LkZ/4xCdKdfqNb3wj8+bdT3/600cccUSa6KeT
vXRmuPvuu6eW7u9uPXV4GjaXYns67T/33HNTZs6yv//976fMhAMbN25MO+onP/nJKTOrnWe95dHw
9Xg0cJ0zMpuTe66f9axnbb/99s9+9rOPPvroPEuu1Plf+9rX0jY7x5f+A9Cw0jK+xgX5fJ555plh
zGGxfFaf//znZ4sGzjtOXBCBbHIOoEkecrt3jpJpNP6yl73s4osvXrJRXw7B8Tn00EPTF0S2NAfW
bGn6vc/K5Nx/ya4Oyy7L3k8PRbkokL7x84zIHILTJ8OwLRq4mcNGiguGyRjfVQFxwRo5gttMAmMK
rIW4IL+CikZudssFo1K950a2nPJnfP5mOL9Mcvpf0T71qU81jwL59fj4xz++vtsz8IhHPKKnI6Nc
8Kq9T6fn3tzK1yytDCd8qOXkLoncHJeIoI7Jr6z+WcqY/FbMLXtlyvy4mujyzbAyV3i8uKDuaAME
Wi2w8nFBktuDDjooXaMPdEt0cMABB/Q/+Oz1r399mT55b8+l51S/5a10h5hMIH3kpnF+f+HpaS2n
6s2qMmep5Uw2Eye7aL6VQKCU8NGPfjRd6NQWbj3F5oQ62XJzxjqcQ1U2M5vTM0vO7rPCaaVQnx/R
c/SpJQwcaMYFyStyInzIIYeURWSrzznnnIFzjY4L4pBMI08u6FnV8t80Y0j3kiOaLuShRfUBE80S
sqU5DmbGJAAZP+zJCAFM+QN3WUpILLPkXe0DN7k5UlzQ1DC8FgTEBc26yDABAp2PC3KnW644lB2d
y0+1lWPuJihn9EkJ/umf/ik95zQ/DJdcckk9Inz+85/PhZLy7iabbJJLJ+vXr89ze/MbJk8BLuPv
ec97vvOd76yzZCAl1Hfz0zF1b/PdNLBMyFDmTTmlw8bc6ZDrR2VkZhn2vKr8ZC0l52dYrm01i23L
sLig7GV/CbRdYIXjgmQFuXBc0dIHe+rPXI/O+Wbtoybvpn5OS/hmfZgL32Wu1N49tXHNk1/+8pen
qDJZTk5zaEgw23xS21ZbbZWquxab0+QaC+Radh2fgXLQude97pVL3pmrlPmQhzwkmUOOIDlelDH5
mzYM/TcmJA3Yeeed6zQJDbImmbG2BNhjjz3K0+VyFLjggguaix493IwL0jQuEweq9jmfLGVg78Ej
4oK0HEirgLqqid9TSDYqR9saa+fdIKT5XP+6JStoHnyzgflvXnVLs5ll9QbGBVdccUVzKTmm5/OQ
6ZsxS/6bLoz6Fz3+GHHB+Fam7IaAuKDWaQYIEIhA5+OCnLaXVgTZ2FyqqNfia1yQJgfluT/5gZHf
jbk7II1La7vTPMO3thPIwEc+8pHcJFvaN+Y3XpoN1Cwip/B5nGPzSFGvZ2XR+TFZF51Y4CUveUn5
+CWI+PKXv1znynWiMj6l5ZpUHd8ceOlLX1qmya+gWd1U2yx/BYbFBWUP+kug7QIrGRfk9PwFL3hB
FTvssMO++93v1jowl6FzM349zcwdBM0btcaJC0oykGNimhnk5oXcBZ8DQeLi2jYg3QPmMnqtIZeM
CzJ9KTNn0Lnj7Prrr8+5eW7qT+u1nNWWDUl0kJvLapkZyGrnrrfybi6aJ8TIMSJ3HOTQ8y//8i+5
SyKpdd4t19Pzd9j9bs0y63B/XJC3cr9Ako2yxOQb2a46fRkYERfkhriafiTuzi0S5ea+zJh1Tg+K
9QCaaKUnw0kzj+qQDcmD8C699NK0zcsrqXhaiZRVKn/744JI1qwgYVEaS+R4nSsCSTxyO+Hb3va2
+mF49KMf3bPong0c/V9xwWgf73ZPQFzQrHwMEyDQ9rhg2G+ANCrIz8gLL7ywXsRPGtA8Ma9xQfkM
5FdH7mDNiXxPtV8vPOW8Prck9Lyb/6bDw1yuKoWsW7eu/lLKW7lCVG9hyNKvuuqqMntu0qxXrI4/
/vhmmVmr7JFSWs9bZbJ0uVDLfPWrX92ct0XD4gI1D4FuCKxkXJAb+UvNmdPwww8/vJkG1Nov/c/k
3WLbbCQ2TlyQudIAoOeOg5Scarlc4M4Eafdeg98l44KyGqmxEz7UNSwDuaqeZZUJeh5Pn0ygBALZ
kAQgOZY1583Sc4ZejyAziQuyiHSPUFYmp9j9XfcMiwsSCKTNQ5lxr732qvf6NVf4oosuqqft73rX
u5pvZUPKvAkc3v3ud1fYMk0Ox9nLZYL87YkLMnGClPJuJNNNQbPkMpzmE0Uyk5WmFP3TjDNGXDCO
kmm6JCAuqDWPAQIEItDquCA/Ql772temY8BcR6iv/De/GA888MBc0Km/G7OluVTRrMybcUHKyS+0
5rtlOL/xSsODzJ6fbf0TlDG5VFR/3eURvc3J8nu13mObZq7poCBXrGonCWkx23MXbeZNK9MsLq+k
EP1XeZJ4lAJzMSjtMJvLatGwuKDsYn8JtF1gxeKCnNLWu+zTY8CwTgJzjlkvWKdrl1orjhMXpGF/
Dih1luZAGhWUPZXeBnJDRHlrnLggFXXOl5tFleGc7R588MGlzHTG++c//7mW+aIXvaiMT3v+5MP9
86Z526677lqmmUlckEWko8LaDCCHqp77I4bFBSeeeGJZjcTpaTvRv6plTD2o5ZaEGvKkGUC9lSO9
MQzskzDHx/Q8XBbRExekMUk6VMxbEU4XwcMWvc8++5TZczxdssfFYYWIC4bJGN9VAXFBqTf8JUCg
CLQ6Lhh/J6YJaxphNiv2ZlyQX6E9V3DKlLnoUwKH/FDJk6GaszeH88P1sY99bFmZ3ICQnxbNd/NL
pryV36LpDqs2sMzvq4GdXOV+hBI+5PrRN7/5zWZRKbn5o3dY5wbNWRZzWFww/kfXlAQWWWDF4oK0
MK/h7ZFHHjmiZkt0XMTStKz2edisOVP/NGevTchyy3yahDXfqsNprl/KTAqdFmVl/DhxQc6IkxLX
cpoDaTxfysyV/ZobJ0/OoSHjc7wY2MCslJBG++WS/azighRb1yeL7onHh8UFCU/KJuQ2hIHn+2Vt
06Cu3LCQdc7dCmXkZz/72ZzpZ/YE4P3tGco0+ZvHN5RF9MQFdZXS8KPq1bnqQJZSuvrJokccxOv0
AwfEBQNZjOywgLigVDv+EiBQBDocF+R0O70W5BdgWjzWaze1em/GBQO7isovhNpj9t577z36wkQe
/FQ80w1Xz7JS6+YXdXk3OUD51ZQUYljbyIQA9SpPmknUFc5A3qqXY175ylc232rXsLhA/UOgGwIr
FhekMVURS60+sDFYrQNz21edMm3+y/hx4oKddtqpFtIz8MUvfrGUmQgix47y7jhxwQtf+MKeoup/
68Nx0gFObcafE+eyoHSqk6cc1ol7BnKNvtzLMMO4ILFGBMrScwwqj4Asy63n5skHakyd2CQrmemz
DtmWnjVs/jeJegk3EkQklChvpVuDsqw897B5E19zxgynFUFJFXrigtLTY0pIQ4ueWZr/zdqW+CVH
3p4+IpqTjR4WF4z28W73BMQFpXbylwCBItDquCBXDdLvX6409bzSGdQxxxyTJ1/nd+PAxpyp22tc
kF8R+SnYX9untszNAkWp57S9f+LadWFO5+vDF+pk6bSwdrdYCkyv17WHrjpZHaiNVJ/0pCfVppt5
N48Fz8+tlJAfabm6VKdv3YC4oHwM/CXQdoEViwvy/JpilWNW+rgbUemlv7uSyiYxTkeFZcpx4oI0
MxhWbDo0KEtPLzf1IvU4cUHPAxab5eephaXMGNZWDfVierNpRHOuOlyatM0wLkjJufRfWvhnxXJD
X+1MYGBcEJMSAuR0vsYydfWaA7lDpHbUUB4hkRPw3PdRNv9pT3ta8zDXnDHD6eCxdI/QjAvSGrB2
cvjkJz85/R7kyUTDXuXgm0NnAoqewsf8r7hgTCiTdUZAXFBqJ38JECgCrY4LctY8ohXi6Hq7xgX5
wTOwl6RcEMlVj6K05M+M/CYsU+am2oGrlAlqRwr54TTwNoS6wumgoMYCuaW0jk+f1WUpubc0v1Tr
+NYNiAvKfvSXQNsFViwuSKc0xSr3v/e04OqpABMmlNsWUoumA9vy7jhxwYtf/OKeoup/lx0X9Dxg
sRaYgYFxQe0NIPfs93e925y9dE4427ggNxQkey/OKTlPAipLHBgX1D57cwxtPl+yuZJlOGlAnk1Q
ik35GZk9+NznPreMSeO9/lnqmNyEktg8UzbjgoysbfBKIeP8zWOParETDYgLJuIycQcExAXjVCmm
IbB2BFodF+SqQe70XF7NvGRckJte6y+c9Ccwein1wdN55FZPJ1GZMT+W0p92/VDlx1WulI0oMC0z
a8OG2nQzd0MkiyiFnHLKKSNmX/y3xAX1w2CAQKsFJo0LUo/lSnpe6TCwXrxuVlk5R95vv/2KSW7y
qq2wct5dRqYnw+b0/cM33nhjueqdv5dddlmZYJy4II3E+ksrY5YdF/R0AtAsf2BcUE/Mc/TJWWpz
+p7hecQFWURui6g5eTpqKEfYulbNmxHSfq92PpAqvWf1mv9NOFBaCCQzL+fsmX7HHXcsO7SnF+Lm
jBlObp/2A5myGRekyUFtrpDmEIkO8iDFJV/LPm6KC3p2iv92XkBcUGonfwkQKALigvykHNi6ID9T
t9tuu6KUto6jjw71Qkl++fT3mnjaaafVpgWlwDQ0zSOoRpSZTq7KlOlCqtzdkN+reRpjRubX0ei2
uCOKXZC3xAVl5/pLoO0Ck8YFV199dbLQvFKz1T4Dm/VS4tbaaUwGalzwwQ9+sFjlyTKjT07TQ2yZ
MmeUtbv+tsQFOaUtKz+6B7+I5bkJmXK2rQvKjsgDfeqDGjds2JAmB7X3yGZckCimxDK5K7D259Dc
lXU4twSWg1eKzdONMz4Reu1hcvfddx/RTWIOlDlcZkubcUEyjdq64KCDDspevnaMV5KHukoTDYgL
JuIycQcExAWlHvaXAIEiIC4YFhfkF0L91Zp+BUf8nsn1svRVVTz7ryXlboLSH1QmyAWjOpyEoT9Y
qEeZ/Kgud1xm9cov3tqAYd999x0xYy1hkQfEBeofAt0QmDQuyKNmy4anA7p0MtBfTeVmrtoWK0+0
qXe1164OcxG52QtffwlpJF8WkTPueobYlrjg/PPPLyuf0+H08te/dWVMevArl9fnERfk2Hf44YeX
1cgBKF0Avetd7yr/bcYFtavDdOE7uvPJPJK45A8prd5el2NlKTPZUQ2F+rc3H5LyaINmXJDDcXZu
mX1EjxP9pS1vTOvigtyrmAY8wzpuWh6CuVZMIB/vNL5KJraKv/TEBaV68ZcAgSIgLhgWF+TQUM/Q
83tmxPWs/HatDSPTvrR5TMlctYlCumZKK9mXvexlRT731abVQXPi5nAO9+WGzUyc600pZ5tttslw
5vroRz/anLKNw9mcdevWFQd/CRBor8CkcUE6ZikbO+xJsvmRnPq2TJNOa2v9dvPNN5cODFNjpxl8
Hd8/kEC1zJ46s97v0Ja44Dvf+U5pipbL8R/72Mf6t66MyVGgnIDPIy7IItLaP604CmO6Ijz66KPL
cDMuiG29xeC4444btqoZX5OBpOU5jS1TnnXWWaXMHD1vuOGGYbPX8KcZF2TiPfbYo8y+fv36EWdV
yVVyUE7TlPQhOeIgPmzpZXy74oJo5Laaxz/+8aPveRy9yd5dRYHEBemoKt+13AS0WquRL0tWoHzF
/CVAgIC4YERc8KEPfahc18jvt7TPHFZv50GN5YMUzNppdiYu12hKp4X5Wx7XmB9LtRLOD+baVra/
8PTzXH43pj+EPFEr65mlpP+rW265pX/ido0RF6h5CHRDYNK44Lrrrisbntve62MLmtVX7rSqnfM3
+6ZLq4PS/D6zP/OZzxzW22Gqx9LPYSZrzt6WuCAd16THgEKU+zUGdmmb7h0iUKaZU1yQPZJnI6bZ
QFlKiQUy3IwLMk16KSwTpEOJXA9t7sc6nOcz1uf/5rGSOSyWt/IwhXKHQko44YQT6vTNgWx+nbcn
Lqg3p+TIOCJCr0FHWiP0P7SouawRw+2KC9JBZUhjO7pH5RHb661VF8g9O9mJaWL6ve99b1VWRlxQ
ajZ/CRAoAuKCEXFB7qKt17lyzp7LXv31dhq75pdSwUzLgfpbKFN+5StfKef4eTcXvHLPQpn9M5/5
TEkhMj63JAz7DZOfzfe73/0yTX4819si0jdCcxH969OKMeKC8oHxl0DbBSaNC9KCvZ57NhsP1Ior
MWkxSZ7w6U9/uo5PvZcT2JKgpl791Kc+Vd9qDrz61a8u02Qp9UJ2JmhLXJALi294wxuKQOr/HCya
W1eGE1DXE/n5xQW5SF2v4NdPaU9c8NWvfrUc49LwY1hjuY9//OOlR8QcyNKtRN2cHBCTh5SS0zvB
wNOiZALZwDJNT1yQXKj0aZB3c/dKQolach1ImZtvvnmZ/c1vfnMdP+lAi+KCxE2lS+Q8jCmfpUm3
1PQLIpCmO+UW1/xErE2kVnLdxAWl3vCXAIEiIC4YERekcv7sZz9bf66k9s59B83LPfk1Un/wpKlA
8wdPLrXUyyK52tW82TY/w+ojEbMX3vOe9ww8CuQYUfq+rp/VrOqIRg4DC1nMkeKCuk8NEGi1wKRx
Qa6M77///mWTcwE04UCewZdKNeMTkL73ve8tp5+ZoNnzQKnH0rC8NjBIs/bcktB8am2q3JxHD7tg
3Za4IFuau/VzXC5E2cychqetfrY9eXU6Acjl8nL2XW7NmF9ckDVJ47d6n11Zn564IDvusMMOK28l
A8/DLvOIw3rQySn8xRdfXDsZOOSQQ2pmXqb5xje+UVuSpE1Fwoe6Q7OxaUtf9mbZ0p64ICW8733v
q0fn9GCQ7hbrCXI6Q0jS8tjHPrasW26s+MlPflJXbNKBFsUFpVPK0Q0XJ91806+KQHq3zg1HaZia
23ZWfgXEBaXq8JcAgSIgLhgdF+TnR+1tIGLpfio3ch544IEZmSsv9adUfs/kh26zSn/5y19ehPN7
Jo/Sbr6V4fwWqk9pTHuz/EzqmaD8tzRIq5/V3O8/rAnuwNkXdqS4oO5TAwRaLTBpXJBKKdVd6ce1
bHjOE1OppvlWLhaXhgEZnx/JZ5xxRn8Nlp4S67y5wp70IC2vcsaas8X0VFDu/MrsaRXW089bi+KC
bHVOdWsbjGxOhhM+51S9bnuuOZZWbXONC3Ka/IEPfKDulKxJT1yQVU3IU6/yZ4I8hHG33XbL4e9F
L3rR9ttvXzpYyPitttrqpptu6t+htVuDTJNsJD32ZNP22muvLKi0oMgHLB+PvNsfFySOSGeYeau8
0pBg5513ztE5JeTZi7UJX9AGNtLoX5lhY9oSF+SCRflN8rznPS/rPGxzjG+FQD7e+SLks53mIs0U
bmVWXlzw/+oV/xIg8H8F2hgX5CJF2Xn5ObHsG/nT62D96TW6V+fckpBbAOpvj/7PTcrJkxbr0TkJ
Qy6p1Mnya6d27t2s59NEs/64zU+s2oN3c5r0N1UvM6XA/tihOXGLhsUF9eNhgECrBZYRF6SGzBXz
2sNA/+Ynwn3jG99Ya9Semi03qjdPpXtmz+lzzhlzDtsz1zHHHFOmTE5bL2GXaeqtXiP62E83C2X2
XLet/fLl2nq9Ey0X/ZtLrK0gXve61zXHN4fr3feJAvrr/7QxyGlvbWtRNzNjchKR+yxyRpyR2d5P
fOITzWJHD6ctRz3wLfmA4BSVc5ayoLIC6TynJ4fJNF//+terQ13P5kC63cs0A1cs7Q1y80X/ZpbZ
S4u+0oQvh+C0RugpJEfnPMSh3LXXXGIdTtuG6ZvktSUuSNcQ2fA0PkmHoj1Q/ttGgYsuuqiEZnk0
SW05szIbIi6odYgBAgQi0Ma4IG1QE57n9eIXv7j/p8uYdWnS2jz4IIUkChjxvKpSWn4tfPjDH95p
p53SuqDU3qFLO8n8RkoJPW0DEg7kWQb77LPP/13F5z1vWHdDqfzT7W2ZJh1G9f8QyqJzP0LtSyq/
8QZenRlzexdqMnGByodANwSWEReUuij3Z6XuTdOCXFMuFDlnTKPx3XffPVHq6PoqPcrmzCjVbz1P
zLlkKucdd9zx1FNP7WnxXopKhFsq2+QGufGhWf773//+8tbA9gxlyjTLL9Pk5PSXv/xlGZn6OaWV
8T1PMah1e8/45nJz4Cjz5rECqRKbb5XhxBF5LsCGDRt22WWXPGEnMUgu2SctyfhMELq45XiUR0z2
zztsTI6YaRpXlvvFL35x2GTN8Tn3TN87ZZakIgkQmu+W4RxP87jhPKSgZhFZsSRCaebx2te+dlgv
iLWc9M6XZCBRTGnJkELSlC5334clB8qTTz45S3/pS1+a/LzO0hxIHxfp+zEhUrlNIx+GXGTPyoSu
PzhqzjjmcCvignycSury9Kc/fcSjIsbcZJMtgkC+rQno8jVP5Tbswz+n9cxXLy18unGQshUECEwv
0Ma4YE7V45LF5ndLgoV0YPiFL3zhsssuywn+L37xiyXnmnKCcr0gOzq/8TrzG0BcMP03VwkEFkFg
2XFBqRhzsTuPDkz7rryuuuqqiX4Sp/rNNevc4ZvT3nSzn8q5nEdPWeUu5uw5SW82t8h/S7PznCCn
pdyCrHNigXRmeOmll+YQmQPltddem6v/Y65bQp7vfve7ObBm9hSSLvvGnLFMFpw45JQ5n4d8GBLv
LPtSQv9yFz8uyI+T/fbbr1QIAx8zmvsf0xFTcpU8Zanc0pgGLbnbMYlKGm/kDo40Nen5IOW/SdLy
CyR3l6ThzfHHH5/HmvTjNMektWeSn7SoyeWSpBaZK12PpofSER1H5HpK1iqvOk36oMhDqXIxKMlh
cqrXv/71l19++ZK3YaY2SJKWiZMsZdH5e9RRR6UBT/Ki5henubZ1OBPkPo40ecptTQcffHCe05FP
Ufn8pEpJOJkNz8WaEdVLpsk6H3TQQcFMo6AkXbn/5dZbb62LaA6kH5J8QdJZa74jJdvM3smqlk1O
ldicOClc2a3p5qU5ft7D4oJFOLxaBwKLIyAumHetO035OfiWfqJyB2h+Tk9T1ELNKy5YnBrAmhCY
RmDKuGCh6qVFWJm0WEi1n3OcvHpummiuXvo8LN0A5gp+zj6abxmeucDixwU//elP0zInX+S01clt
LP0COT8tX/MtttgizWO+9rWv1ac+1a9/+qAoverlHHbg7UJp9XHSSSf1NM4py8rpfBr21L4la5ll
ICXnRL42y2mu3nOe85wyTaKJlJzycyW9Z/b8N51UDLvzNGfx6RVz2KXwtDlJbtBzDt5cgTyrJQ1g
aquYuui0Js237Oabb87Kp9FLNm3gCqRdTZrcpGFMnbEOZJXOO++8/sZOaQ5U2oGk5UBiseSc6bml
ztXzcO0EF7nhKO+mtJW8YCQuqHvEAAECERAXNA8cizZcHqCc3ZQ7YUf8dFy01V5yfcQFKh8C3RAQ
FyxZ3U00QU67co0yx+W8cqfDsHmPPfbYchKRy69JGIZNZvxMBBY/LsjV+fL8iGE/FXLWWe6jzD0s
uVmynt5mZPkgleooFybOOeecNA+otVOKLSXXMXn4Qo9q2ja84hWvqBOkzJwO5wQ8f5vz5nmXuYze
M2+93TKP1cjl9VJITs9TSHPejB/4uMwsunZLkmkyS1102d5SYG51GdgWNC0ZctNKmSZ/y3Jrp1L5
DuZGmNJTSk7t+zOHNCqoD8DK7JHMjTDN5aaofEN7HpadrKY8ECQJQGKc+uiQsho9cUEaOaSTz7yV
G6+uueaaHr35/VdcUHaHvwQIFIHUh+M3F5xf1aTkKlAbziV2LgeyHIMSvNcJOjAgLlD/EOiGgLhg
5hVyLrCWz0bOU2q3is2lpD15OYPIZOmTofmW4XkILHhckNVL16DlMzOsu84aF6RRSrm0nfPcnKHn
dDX9Y+TafX2GRSYow+mgMr1Q5gOWV1rp14QhzRh6rrPn90k5tc9vlV133TV3PWSC/LDM309+8pN5
hlRNJHoeIJWdVeOCcnNNzrUTC6TArHAykCOOOKIuN4s488wze/ZvxuQMPdueM/08QSMt/NNaIIvO
Rf88RSX3BZQVywTZ2PrjqhSSp22mt5PiluVmzdOmIiufMtNRxkMf+tC8FYqikZilJy7IFZyaFWSa
bEgkc9tC1jzP+8gzPkrJ+Zs7MpoNA2pckMeFlB5IspIJDdLeI7dRpKFIcxvTdiIgKSTJQ+4Hab41
12FxQd19BggQiIC4YK5V7qSF53CWWwjzSqZd2wrmgJLj2qRFLfL04gKVD4FuCIgLZl7T5m7u2jQ6
lX+u9uam/tybkEuZ6TAnZyK1c8i0l+7YoWHmmDMpcMHjglyAro/JGHaHe40LSrXT0010NjA3CzRr
pJxo5+kbTb20dSw5Q07MezrJfNaznlXmzQM0+58DlTHlgYCZJgM9jfNrXJB3k1TktoKek/oEGjUc
y1o1VynD6SShLDq9gPZ3wpmGN8lPygTpL7Tn0lhtlpDtOv3003tKzlX+PJu1zJu/PXFBzuKrWIKF
888/v2f23CKUHiHK7Ak04l8nqHFBeTez556FgXdqlFne8Y53lCmzCT04tcyZD4gLirm/BAgUAXHB
zKvZKQusKUHZQTmQJdufssxFm11coP4h0A0BccE8atc8QK10TVA+JGmHnJYGuae7XqXN+NzvPLDt
wTzWZ42XueBxQToILVfA08Q9l9cH7qxmXJDmAf09SabX0PqRyyct9+z3lJPr9aWX/nz2PvCBD9R3
c39BeYxmfqtcffXVdXxzINfry0MrctKdo3/zrWZckEYOzbfq8Ete8pLyRcgl+2bD/hRVru+nbUCa
3NTpmwMXXHBBSTnSBUHzcaUZrncBpHvD5ix1OF0RltXO0nvignQQUR4Fm4v+w55wnVWtPSqk68Va
bDMuSJIwbJfV6dNrYtn8tEboaeFQp5n5gLigmPtLgEAREBfMvJqdssC0RsuuSYCfY1yO2kmtu3dr
qrhA/UOgGwLigikr/GGz5yQiN1yXM53mRyWJQVoXpHH4iMuRw8o0fnkCCx4X5EES5ROSE9g8FWLg
Njbjgve973390+TBprWPwXRE0D9BGgnUBvZ5TmidIDFC+jrIAxRy50J/ClEmyyMYyi0D6Wixpxem
GhfkZoSe2/brItLApmzg4x73uCyujs+TOLLQLDor0BxfJ8hA7oYoj1tN+c2vTL5fpZOBhCTDlpuf
XnX1euKCPD2hrFLG93fIUFcgNxblt1ymzC/tGnQ044K0QKgTDxtIalGWlVYW2dfDJpvteHFBMfeX
AIEiIC6YbR07fWl5AkKOxWlSmMNZf8I/ffmLUIK4QP1DoBsC4oL51ag5W0mr79x9kBOi3Fi95557
Hnroobmtu6vHhflJTlnygscFud2+/pwbdubbjAsGRgq52yXX30s5uYW/Xyx339emj3mUQP8Ew8bk
FoB8dEvJWcSwuCA9DwwrIb+FyuxpD1Cftzhs4ub4RBy5GaGcsKfNfzMuSD8Apcydd965Z5WaJXzi
E58okzXjgvSvmCivjM+THZrT9wynEUJpn5BQIg+KLe8244I8NrRnlv7/ps1GaT2SyGVYI4r+uaYc
Iy4o+9dfAgSKgLhgykrV7MsQEBeofwh0Q0BcsIwK0CztEljwuKBefM/J+LAoqcYFaa+SrjD6/XNH
Q3kUY+qltH7vn2CcuCBPQrz11lsTWeSafp6/sGHDhvRzmFsY6rMGRsQFBxxwQP9Cy5iah2QNs54D
J8sjRfLsg+9973vJFtJ8Ig9PfPazn7311lvX+3eacUH6T0hfB6UGftWrXpX9O7DMjEy0UtKGZlyQ
ThJqB4y5y+CrX/3qZYNel19+eVamtG3ImX46QixLqXFB9kW6Rhy26Do+nrW7koG7pk45wwFxQTcO
0LaCwKwExAUzrGAVNaaAuGBW31/lEFhdAXHBmJWeydorsOBxQe6dL5VATmmHXSivcUHuOMjTA/v3
RTMuyLlv/wSj44LchnDGGWekJ8P8pBxYI5WT7hFxQZ4f2r/QMmZ0XJBNPuuss9Ln4eabbz5i0c24
IB2EplVAmThPTBi23Iy/9tprS7+jzbggHQiUJyEOXNzAkXn2QXzKgmpckJsL0vxgxNLLW9lf5WGO
KTldMSw5/UwmEBcM3I9GElizAuKCmVStCplIQFywZiscG94xAXHBRFWfidsosOBxwbHHHltqlZzS
9j8doIDXuCAn7APb808TF3z+859ft25dT82WFgW5ep6nMebOhVzrL83pR8QFudFm2GdjRFyQZKM8
FaK59Cw6V/PTAeORRx559NFHlw5AkpPUmxHS6UF5OmHmOvXUU4ctN+N/8IMflC4Nm3FB2jDUbiET
g5QkpLkC/cOJC+qCJo0LsmviVsoUF/TbGkOAwAoIiAtGHCm8NScBccEKfLUtgsAKCIgL5lRJKnZx
BBY8Lqjd7uXW/jTIH+hW44J0NjjbuOCmm27KqXSpanKSnu4QEw6ki+Y8aiErUx70mYcwziMu+NnP
fpbOD8ui00XA+vXrX/nKV5577rk5H89b+ZmRHXfJJZeUU/tmXJC3dt999zJj9AaKlZHf+c53StrQ
jAty/l7KTFCQmxrSv8HHlnp9/OMfD1Qpc9K4IA9ASdOIsra5u2HE2s7wrRDVxzqURftLgMBaFhAX
zLCCVdSYAuKCtVzn2PYuCYgLxqz0TNZegQWPC/7xH/+xVClpsj6scfuc4oL0xpnL92XpOYN+z3ve
k3sW+nf02WefXXr8m2HrguyUdApdFp0z+txTkI4N+xedhzL0ty5IRwfpArHMm4QhXRf2z1jGpOvp
0nigGRf8/ve/L3copIRs/rB5h42fNC6oN0TEcOB9IsMWNM14cUH5ePhLgEAREBdMU6Oad3kC4gL1
D4FuCIgLllcHmqtFAgseF6RfwVKZpNl8TkUHws4pLkjjgW233bYsfd999x246Ix817veVU66ZxgX
pLvCHXbYoSx6t912G7bo3AJQejts9l2QHZonMJZ508wgz24YNnse0Vgma8YFCUnqlfd0qDhs3ozP
SqZ9wre//e38zXCZctK44Bvf+EZ55mM6PMxTEkYsboZviQvKfveXAIEiIC6YYQWrqDEFxAXqHwLd
EBAXjFnpmay9AgseF6Sxem6NT32SS97pRmCg85zigttuu6102p804N3vfvfARWfk3nvvXaq7GcYF
OcevTfTTzGDYovMQ0rLoZlyQidMJQHleQ55ccM011wycPf03brXVVmX2ZlyQiY844oi6RbnxYeDs
GXnyySfnBo3ciJGOFNKkoUw2aVyQJy+UZeV+iu9///vDljXb8eKCYu4vAQJFQFww2zpWaeMIiAvU
PwS6ISAuGKfGM02rBRY8Lvj1r3+dk9nUJ7kGffrppw+knlNckD4Dy/MIEhccc8wxAxedjgpr0/0Z
xgXp1LFsdTY8NxQMXPSXvvSl+gjCnrggT5ysjxtIC4F66b+Wk52e3hdrLd0TF1x11VX14QhpO1Hn
ag7ccsst2d5SQrqjrG9NGhd8+MMfLoVss802w558UQuf1YC4oO56AwQIREBcMKvaVTnjC4gLVD4E
uiEgLhi/3jNlSwUWPC7IZevcCFDqk4MPPngg8pzigiz6Wc96Vln01ltv3dNzQm5VOOecc3JNvNZ1
GS6dH9aVrA0PJn0yQjpJqPM+8pGP/O53v1vLzEDaHlx00UXp17Eu+sEPfnB9MkKZcsOGDeXd3K2Q
Rgi/+tWvSmjw17/+NcOvf/3rS5uN/r4LMnumyZMfy+wJQ5LSNHtOyAcmj1R45jOfWW/BuPHGG+vq
TRQXpKhXvOIVZUEHHHBALWTeA+KC+skxQIBABMQF8651ld8vIC5Q+RDohoC4oL9+M6ZjAgseF0T7
jDPOKPXJU5/61IHPUpxTXJBFn3feeaUbw6xALsGfcsopaU6QDvxPOumk2q3BTjvtVB8lkE4DPv3p
T9er5PWUf9K4IIu++OKL09S/bHgSgxNPPDGLTuG5BWDHHXcs9xo87WlP23TTTcs0r371q9PPQ1pE
lM/n7373u7xb3srftAR43vOel2nSC2J+GJfx2YT+JyOU2fN8hCQkZbIEC3vuued73/vez3zmMwHJ
syFqSJImH3ksQpml/J0oLkgK8cQnPjFLSTnpMbJZzlyHxQVlz/pLgEAREBfMtcpV+EABcYH6h0A3
BMQFA6s4I7sksPhxQXrSKyfFaXL/ox/9qB//i1/8YrnSnRb4wx6kWK/FX3rppf0l5Gp+HpJYaq2c
U9cJcj574IEHDqvNch6di+MJB3L+XqdJvFDvwd9rr73K+EMOOaSW2TOQc/AyTdYwJ+n13Vzib94v
UMsvA9neNADIUwxyr0F9KyObvQWm74XXvOY1JRCo09SBww477PLLLy/vPvrRj+5/SOV1111XTepc
zYHcsJC+FnuevHDllVemw4RMlmYJaYRQN2fgQBZakpbs31tvvXXgNPMYKS5o7kfDBAiIC+ZR0ypz
tIC4QM1DoBsC4oLRdZ13OyCw+HFBzuXTriBVSk6HB57s5xQ1l/633HLLfGFzT33/Tvn5z3+eEjJB
Xrkxv3+CPA5gn332KRP03K2flv+5sp8gop53JyVIpwG5dp/L/eXRildccUXOuHPmm2lSyE033VQW
kTsCSplvetOb+hdaxqQLgjJN1jDr2ZwsTSne//73J0aoi86dBVl0rsin7UG5ueBb3/rW4x//+LLo
THn99dc3S8jOTfn777//Yx/72DQJeMhDHpINyZrnNorEEckWSiuF9evX53dLc8YynI4jkodkxvRn
WKv05CG59yEJyVe+8pX+WfKghKxPtihl/vjHP+6foDlm48aNZQV22WWX5vh5D4sL6t40QIBABMQF
8651ld8vIC5Q+RDohoC4oL9+M6ZjAosfFwQ8t8+X88ph3RfMe6f89Kc/Pf/889/ylrfkrv/TTjut
eRG/LDoPGkg7gY9+9KPpZyDhwwzXJwHIhRdemOcj5LmHuZqf1v49F/Rz38HnPve5LDrRQYkvBi49
zzhIJwNpkFDfzU0cpaLOQxtHzJiOE88666ws/fDDD3/zm9+ce0PS3qMWMs3Ac57znKxA9uwll1wy
TTmTzisu6MYB2lYQmJWAuGDSWtT00wuIC2b1/VUOgdUVEBdMXx8qYcEFWhEXpAvBPK0vtUGurefM
fcFJV331sk8TKeSVgRErkxCmVLB77LHHiMnm9FZuVUgrhaxA+pMc2CXFnJabYsUFq3tgtXQCiyYg
LphffavkYQLigkWrB6wPgeUJiAuG1XLGd0agFXFBtNN+Pk3x80XOdfbO4M9pQ2644Ybddttt++23
33nnndM2YOBS0gQi08QzF/fTc+PAaeY3Mp+6E044IUvPnR3pemJ+CxpYsrhgeQdEcxHoqoC4YGBV
aeRcBcQFXa1PbNdaExAXzLWqVPgiCLQlLsiBNRfBUwXlNvw0v18EuoVdhzwfIb0HlOq6pyuGus4f
+9jHykMf0mNh4oU6fmUG0ktDenvIGu66667NpzSuzNLFBeWz4S8BAkVAXLAyda+lNAXEBeofAt0Q
EBc0azbDnRRoS1wQ/HSjl+bruRp+5plndnJfzHCj0r1hqYTznIJ0uZCuFXJWnu4N8zcdGKbzxjy5
oExw5JFHznC5Yxb1zne+M0tPUnHttdeOOcsMJxMXdOMAbSsIzEpAXDDDClZRYwqIC2b1/VUOgdUV
EBeMWemZrL0CLYoLgnz00UenTthmm23ylMD2mq/Amqdjw2233bbWn3kmQp6KmF4CnvzkJ6f/hzo+
jyT4zW9+swLr01xElpgHNGQdRjwwojn9zIfFBfUDYIAAgQiIC2ZezSpwSQFxgcqHQDcExAVLVncm
aLtAu+KCP/zhD3mMYKqXXB9vu/y81z99Qj73uc/dZJNNBtbGeTjjEUccsfJZQbb6qKOOyio97nGP
az6mYd4azfLFBQM/EkYSWLMC4oJmDWl4ZQTEBWu2wrHhHRMQF6xMnWkpqyjQrrggUD/84Q83btx4
xRVXrCJaWxZ9++23X3nllRs2bHjqU5+a3gzSxuBRj3pUho899tg8DHHEwxPnt4H5vF1++eV5NOR1
1103v6WMLllc0LEjtc0hMKWAuGB0nendeQiIC6b82pqdwIIIiAvmUUMqc6EEWhcXLJRei1Ymz1VM
3wXZ3S1a5zmtqrhgQY6wVoPAggiIC+ZU2Sp2hIC4YEG+/laDwJQC4oIRFZ23uiEgLujGfrQV4wuI
C6Y8MpqdQMcExAXj15+mnJWAuKBj1YjNWbMC4oJZ1YrKWVgBccHC7horNicBccGaPabbcAIDBcQF
c6psFTtCQFww8MtoJIHWCYgLRlR03uqGgLigG/vRVowvIC5o3bHYChOYq4C4YPz605SzEhAXzPVL
rXACKyYgLphVraichRUQFyzsrrFicxIQF6zYMdSCCLRCQFwwp8pWsSMExAWtqBysJIElBcQFIyo6
b3VDQFzQjf1oK8YXEBcseewzAYE1JSAuGL/+NOWsBMQFa6qSsbEdFhAXzKpWVM7CCogLFnbXWLE5
CYgLOnzUtmkEliEgLphTZavYEQLigmV8Vc1CYAEFxAUjKjpvdUNAXNCN/WgrxhcQFyzg0dYqEVhF
AXHB+PWnKWclIC5Yxa+8RROYoYC4YFa1onIWVkBcsLC7xorNSUBcMMOjpKIIdEBAXDCnylaxIwTE
BR2oOmwCgQiIC0ZUdN7qhoC4oBv70VaMLyAucHwnQKApIC4Yv/405awExAXN76BhAu0VEBfMqlZU
zsIKiAsWdtdYsTkJiAvae1C25gTmISAumFNlq9gRAuKCeXyXlUlg5QXEBSMqOm91Q0Bc0I39aCvG
FxAXrPzB1BIJLLKAuGD8+tOUsxIQFyxynWDdCIwvIC6YVa2onIUVEBcs7K6xYnMSEBeMfxA0JYG1
ICAumFNlq9gRAuKCtVC32Ma1ICAuGFHReasbAuKCbuxHWzG+gLhgLRy+bSOB8QXEBePXn6aclYC4
YPxvqCkJLLKAuGBWtaJyFlZAXLCwu8aKzUlAXLDIh13rRmDlBcQFc6psFTtCQFyw8t90SyQwDwFx
wYiKzlvdEBAXdGM/2orxBcQF8zhcKpNAewXEBePXn6aclYC4oL01hjUn0BQQF8yqVlTOwgqICxZ2
11ixOQmIC5qHOcMECIgL5lTZKnaEgLhAzUOgGwLighEVnbe6ISAu6MZ+tBXjC4gLunGAthUEZiUg
Lhi//jTlrATEBbP6/iqHwOoKiAtmVSsqZ2EFxAULu2us2JwExAWre2C1dAKLJiAumFNlq9gRAuKC
RasHrA+B5QmIC0ZUdN7qhoC4oBv70VaMLyAuWN4B0VwEuiogLhi//jTlrATEBV2tT2zXWhMQF8yq
VlTOwgqICxZ211ixOQmIC9baodz2EhgtIC6YU2Wr2BEC4oLR30rvEmiLgLhgREXnrW4IiAu6sR9t
xfgC4oK2HIKtJ4GVERAXjF9/mnJWAuKClfl2WwqBeQuIC2ZVKypnYQXEBQu7a6zYnATEBfM+dCqf
QLsExAVzqmwVO0JAXNCuWsLaEhgmIC4YUdF5qxsC4oJu7EdbMb6AuGDYIc94AmtTQFwwfv1pylkJ
iAvWZm1jq7snIC6YVa2onIUVEBcs7K6xYnMSEBd072BtiwhMIyAumFNlq9gRAuKCab6z5iWwOALi
ghEVnbe6ISAu6MZ+tBXjC4gLFucga00ILIKAuGD8+tOUsxIQFyzCd986EJheQFwwq1pROQsrIC5Y
2F1jxeYkIC6Y/uCoBAJdEhAXzKmyVewIAXFBl+oQ27KWBcQFIyo6b3VDQFzQjf1oK8YXEBes5cO6
bSfQL/Dwhz98/ArElARmInDnnXeuX7++/9NoDAEC7RIQF8ykSlTIIguICxZ571i3eQiIC9p1ILa2
BOYtsOmmm37kIx/5hBeBFRS44IILHvnIR877s618AgTmLSAumMdvdWUumsCGDRum+Sqdd955i7ZF
1ofACAFxwTTfd/MS6KTA3b0IrKDAPe5xjyztbne7Wye/TTaKwJoS2G677f7oRaDTArfffvuhhx46
zfdaXDDizNRbCyggLpjm+25eAgQIECBAgACBInD/+9//CV4Eui6w2WabTfOVFxcs4BmxVRohIC6Y
5vtuXgIECBAgQIAAAQIECIwpsHHjxhGnZt4isGgCd9xxx7p168b8eJuMAAECBAgQIECAAAECBJYn
cMwxx1xxxRVf9SLQEoHPf/7zW2655fI+7eYiQIAAAQIECBAgQIAAgTEF7nWve93Xi0CrBNLH1Jgf
b5MRIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQ
IECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECA
AAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAEC
BAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQ
IECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECA
AAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAEC
BAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQ
IECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECA
AAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAEC
BAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQ
IECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECA
AAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAEC
BAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQ
IECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECA
AAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAEC
BAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQ
IECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECA
AAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAEC
BAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQ
IECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECA
AAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAEC
BAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQ
IECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECA
AAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAEC
BAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQ
IECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECA
AAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAEC
BAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQ
IECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECA
AAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAEC
BAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQ
IECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECA
AAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAEC
BAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQ
IECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECA
AAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAEC
BAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQ
IECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECA
AAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAEC
BAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQ
IECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECA
AAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAEC
BAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQ
IECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECA
AAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAEC
BAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQ
IECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECA
AAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAEC
BAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQ
IECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECA
AAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAEC
BAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQ
IECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECA
AAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAEC
BAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQ
IECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECA
AAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAEC
BAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQ
IECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECA
AAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAEC
BAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQ
IECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECA
AAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAEC
BAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQ
IECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECA
AAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAEC
BAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQ
IECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECA
AAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAEC
BAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQ
IECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECA
AAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAEC
BAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQ
IECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECA
AAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAEC
BAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQ
IECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECA
AAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAEC
BAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQ
IECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECA
AAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAEC
BAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQ
IECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECA
AAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAEC
BAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQ
IECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECA
AAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAEC
BAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQ
IECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECA
AAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAEC
BAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQ
IECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECA
AAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAEC
BAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQ
IECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECA
AAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAEC
BAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQ
IECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECA
AAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAEC
BAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQ
IECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECA
AAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAEC
BAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQ
IECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECA
AAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAEC
BAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQ
IECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECA
AAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAEC
BAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQ
IECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECA
AAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAEC
BAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQ
IECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECA
AAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAEC
BAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQ
IECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECA
AAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAEC
BAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQ
IECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECA
AAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAEC
BAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQ
IECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECA
AAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAEC
BAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQ
IECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECA
AAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAEC
BAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQ
IECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECA
AAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAEC
BAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQIECAAAECBAgQ
IECAAAECBAgQIECAAIH/0w4dCAAAAAAI8rce5ELIgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDA
gAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAED
BgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwY
MGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDA
gAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAED
BgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwY
MGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDA
gAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAED
BgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwY
MGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDA
gAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAED
BgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwY
MGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDA
gAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAED
BgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwY
MGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDA
gAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAED
BgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwY
MGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDA
gAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAED
BgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwY
MGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDA
gAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAED
BgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwY
MGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDA
gAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAED
BgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwY
MGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDA
gAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAED
BgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwY
MGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDA
gAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAED
BgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwY
MGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDA
gAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAED
BgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwY
MGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDA
gAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAED
BgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwY
MGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDA
gAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAED
BgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwY
MGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDA
gAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAED
BgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwY
MGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDA
gAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAED
BgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwY
MGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDA
gAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAED
BgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwY
MGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDA
gAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAED
BgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwY
MGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDA
gAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAED
BgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwY
MGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDA
gAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAED
BgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwY
MGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDA
gAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAED
BgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwY
MGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDA
gAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAED
BgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwY
MGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDA
gAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAED
BgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwY
MGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDA
gAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAED
BgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwY
MGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDA
gAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAED
BgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwY
MGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDA
gAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAED
BgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwY
MGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDA
gAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAED
BgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwY
MGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDA
gAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAED
BgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwY
MGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDA
gAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAED
BgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwY
MGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDA
gAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAED
BgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwY
MGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDA
gAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAED
BgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwY
MGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDA
gAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAED
BgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwY
MGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDA
gAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAED
BgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwY
MGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDA
gAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAED
BgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwY
MGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDA
gAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAED
BgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwY
MGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDA
gAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAED
BgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwY
MGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDA
gAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAED
BgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwY
MGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDA
gAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAED
BgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwY
MGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDA
gAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAED
BgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwY
MGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDA
gAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAED
BgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwY
MGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDA
gAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAED
BgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwY
MGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDA
gAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAED
BgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwY
MGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDA
gAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAED
BgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwY
MGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDA
gAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAED
BgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwY
MGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDA
gAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAED
BgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwY
MGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDA
gAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAED
BgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwY
MGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDA
gAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAED
BgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwY
MGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDA
gAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAED
BgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwY
MGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDA
gAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAED
BgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwY
MGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDA
gAEDBgwYMGDAwHwgQw93LQplbmRzdHJlYW0KZW5kb2JqCjIzIDAgb2JqCjM1NTMyCmVuZG9iagoy
NSAwIG9iago8PCAvTGVuZ3RoIDI2IDAgUiAvVHlwZSAvWE9iamVjdCAvU3VidHlwZSAvSW1hZ2Ug
L1dpZHRoIDEzODEgL0hlaWdodCAxMDM4Ci9Db2xvclNwYWNlIC9EZXZpY2VHcmF5IC9JbnRlcnBv
bGF0ZSB0cnVlIC9CaXRzUGVyQ29tcG9uZW50IDggL0ZpbHRlciAvRmxhdGVEZWNvZGUKPj4Kc3Ry
ZWFtCngB7J13gBRF08bnIkfmyAgoSBAEBCQICkqSJIgRBdFDPkAw55xzxpwQ9FXE9BrwVRQTggio
ICBJASUeOafLW1/1hA13u3d7d7sz3TNP/3E709PTXV1V89uamt45TUOBBqABaAAagAagAWgAGoAG
oAFoABqABqABaAAagAagAWgAGoAGoAFoABqABtykgcQKXiopbjId5gINQAMKaKDzG/MWeqjMvLGq
AkaBiNAANOAaDfTdQR4rz1d0jfEwEWgAGpBfA1M8hliig83ltwokhAagAbdoIOkrz0GWurnFeJgH
NAANyK+BZA9C9jT5zQIJoQHVNXDKDffc7d1yzw1n+A0IyPpVgY0yaiD5wqkzPndlmTF1BFajlM0r
EsftKfDeTXLQjAv2P5xsqg6QLZsP4Sy/BhKu8wX5lts2b0n1TxQbpdBA8+1u84RSz+dAd1NfgGwp
HAdNw2mg5q5Su59CJ+xuFm7OqCtJA8MUsnG8RL3cVBIgW5K34HgJGuiUEy8nlaLfU0uYPg6H1cAl
UhjPWSEmmpoBZMO6CCqj18ApWc66cpxH7xm9JtAyoIGRcTaLCt1PMNUByAb8Altl0gAgWya1ufwk
QJYIkHW5k9s3PUDWPl2rMxIgC8iq463SSwrISm8iBwQEZAFZB9zOrUMCsm61bHnmBcgCsuXxH5wb
ogFANkQd2NE1AMgCsrgUYqYBQDZmqnRRR4AsIOsid3Z6KoCs0xaQcXxAFpCV0S8VlQmQVdRwcRUb
kAVk4+pg3uockPWWvaObLSALyEbnKWgVhQYA2SiU5LkmgCwg6zmnj9+EAdn46VbdngFZQFZd75VO
ckBWOpNIIBAgC8hK4IZuEQGQdYslYzkPQBaQjaU/ebwvQNbjDhB2+oAsIBvWMVBZFg0AsmXRmtvP
AWQBWbf7uI3zA2RtVLYyQwGygKwyziq/oICs/DayX0JAFpC13+tcOyIg61rTlmNigCwgWw73wamh
GgBkQ/WBPaEBQBaQxZUQMw0AsjFTpYs6AmQBWRe5s9NTAWSdtoCM4wOygKyMfqmoTICsooaLq9iA
LCAbVwfzVueArLfsHd1sAVlANjpPQasoNADIRqEkzzUBZAFZzzl9/CYMyMZPt+r2DMgCsup6r3SS
A7LSmUQCgQBZQFYCN3SLCICsWywZy3kAsoBsLP3J430Bsh53gLDTB2QB2bCOgcqyaACQLYvW3H4O
IAvIut3HbZwfIGujspUZCpAFZJVxVvkFBWTlt5H9EgKygKz9XufaEQFZ15q2HBMDZAHZcrgPTg3V
ACAbqg/sCQ0AsoAsroSYaQCQjZkqXdQRIAvIusidnZ4KIOu0BWQcH5AFZGX0S0VlAmQVNVxcxQZk
Adm4Opi3OgdkvWXv6GYLyAKy0XkKWkWhAUA2CiV5rgkgC8h6zunjN2FANn66VbdnQBaQVdd7pZMc
kJXOJBIIBMgCshK4oVtEAGTdYslYzgOQBWRj6U8e7wuQ9bgDhJ0+IAvIhnUMVJZFA4BsWbTm9nMA
WUDW7T5u4/wAWRuVrcxQgCwgq4yzyi8oICu/jeyXEJAFZO33OteOCMi61rTlmBggC8iWw31waqgG
ANlQfWBPaACQBWRxJcRMA4BszFTpoo4AWUDWRe7s9FQAWactIOP4gCwgK6NfKioTIKuo4eIqNiAL
yMbVwbzVOSDrLXtHN1tAFpCNzlPQKgoNALJRKMlzTQBZQNZzTh+/CQOy8dOtuj0DsoCsut4rneSA
rHQmkUAgQBaQlcAN3SICIOsWS8ZyHoAsIBtLf/J4X4Csxx0g7PQBWUA2rGOgsiwaAGTLojW3nwPI
ArJu93Eb5wfI2qhsZYYCZAFZZZxVfkEBWfltZL+EgCwga7/XuXZEQNa1pi3HxABZQLYc7oNTQzUA
yIbqA3tCA4AsIIsrIWYaAGRjpkoXdQTIArIucmenpwLIOm0BGccHZAFZGf1SUZkAWUUNF1exAVlA
Nq4O5q3OAVlv2Tu62QKygGx0noJWUWgAkI1CSZ5rAsgCsp5z+vhNGJCNn27V7RmQBWTV9V7pJAdk
pTOJBAIBsoCsBG7oFhEAWbdYMpbzAGQB2Vj6k8f7AmQ97gBhpw/IArJhHQOVZdEAIFsWrbn9HEAW
kHW7j9s4P0DWRmUrMxQgC8gq46zyCwrIym8j+yUEZAFZ+73OtSMCsq41bTkmBsgCsuVwH5waqgFA
NlQf2BMaAGQBWVwJMdMAIBszVbqoI0AWkHWROzs9FUDWaQvIOD4gC8jK6JeKygTIKmq4uIoNyAKy
cXUwb3UOyHrL3tHNFpAFZKPzFLSKQgOAbBRK8lwTQBaQ9ZzTx2/CgGz8dKtuz4AsIKuu90onOSAr
nUkkEAiQBWQlcEO3iADIusWSsZwHIAvIxtKfPN4XIOtxBwg7fUAWkA3rGKgsiwYA2bJoze3nALKA
rNt93Mb5AbI2KluZoQBZQFYZZ5VfUEBWfhvZLyEgC8ja73WuHRGQda1pyzExQBaQLYf74NRQDQCy
ofrAntAAIAvI4kqImQYA2Zip0kUdAbKArIvc2empALJOW0DG8QFZQFZGv1RUJkBWUcPFVWxAFpCN
q4N5q3NA1lv2jm62gCwgG52noFUUGgBko1CS55oAsoCs55w+fhMGZOOnW3V7BmQBWXW9VzrJAVnp
TCKBQIAsICuBG7pFBEDWLZaM5TwAWUA2lv7k8b4AWY87QNjpA7KAbFjHQGVZNADIlkVrbj8HkAVk
3e7jNs4PkLVR2coMBcgCsso4q/yCArLy28h+CQFZQNZ+r3PtiICsa01bjokBsoBsOdwHp4ZqAJAN
1Qf2hAYAWUAWV0LMNADIxkyVLuoIkAVkXeTOTk8FkHXaAjKOD8gCsjL6paIyAbKKGi6uYgOygGxc
HcxbnQOy3rJ3dLMFZAHZ6DwFraLQACAbhZI81wSQBWQ95/TxmzAgGz/dqtszIAvIquu90kkOyEpn
EgkEAmQBWQnc0C0iALJusWQs5wHIArKx9CeP9wXIetwBwk4fkAVkwzoGKsuiAUC2LFpz+zmALCDr
dh+3cX6ArI3KVmYoQBaQVcZZ5RcUkJXfRvZLCMgCsvZ7nWtHBGRda9pyTAyQBWTL4T44NVQDgGyo
PrAnNADIArK4EmKmAUA2Zqp0UUeALCDrInd2eiqArNMWkHF8QBaQldEvFZUJkFXUcHEVG5AFZOPq
YN7qHJD1lr2jmy0gC8hG5yloFYUGANkolOS5JoAsIOs5p4/fhAHZ+OlW3Z4BWUBWXe+VTnJAVjqT
SCAQIAvISuCGbhEBkHWLJWM5D0AWkI2lP3m8L0DW4w4QdvqALCAb1jFQWRYNALJl0ZrbzwFkAVm3
+7iN8wNkbVS2MkMBsoCsMs4qv6CArPw2sl9CQBaQtd/rXDsiIOta05ZjYoAsIFsO98GpoRoAZEP1
gT2hAUAWkMWVEDMNALIxU6WLOgJkAVkXubPTUwFknbaAjOMDsoCsjH6pqEyArKKGi6vYgCwgG1cH
81bngKy37B3dbAFZQDY6T0GrKDQAyEahJM81AWQBWc85ffwmDMjGT7fq9gzIArLqeq90kgOy0plE
AoEAWUBWAjd0iwiArFssGct5ALKAbCz9yeN9AbIed4Cw0wdkAdmwjoHKsmgAkC2L1tx+DiALyLrd
x22cHyBro7KVGQqQBWSVcVb5Be2cTW4up8pvARklBGQBWRn9UlGZ6ux3M2MPtFTULA6LfYmbnSLK
uU0wbZD8VZQnuKjZaQ77n8uGT3jURb5RZCpPpLnMXDZNZ3ARTXqv4jJT14CsTU7n4mEqjpv+jT1l
5hL9St35lT3DffPNBxOruNhw8Zxa4zXeg2qhGe84yVQwIBtPT/NK3xUq21TG6X78vU2jVa5cwSsW
jPk8EwavOXjUuZKrO0r+YeckOLhhXKKp1SQPpgvwKCPml5RdHV6mXzuz7BoO45RDAw3PHjnCqTLy
C91RvhvulAAjLhnWNKC7d3RpvPTnSKvA7LGllgYydEcFZNWymgPSPqE7ynMOjBxuyMG7vARYMdfX
KobTA+pU0ECG7qyArAq2clLGhGd0R3nJSRmCx+791rwFNpf5CzJ1HayzfeQFC76+p1bw7LGtlAYA
WaXM5ZiwJmRfdEyAwgOn1T+mgc2l4WQdsrfUt3ncBg2OAWIL21+lfUBWJWs5J2vCszpg5IGsE6ow
dDDWiaExpsIaAGQVNp6NopuQfcHGIaUbKvE5/YtmvHSCQSC5NQDIym0fWaRLnKQDBpAlAmRlcUpV
5ABkVbGUs3ICspqGSNZZH1R2dEBWWdPZKjggC8ja6nBuGgyQdZM14zcXM4p7Pn4jyN8zIln5bSSl
hICslGaRTihAFpGsdE6pikCArCqWclZOE7Ky/OLLEWUgknVE7eoPCsiqb0M7ZpD4PIkCyGJ1gR3u
5q4xAFl32TNeswFkkS6Il2+5vl9A1vUmjskEE18QgSwiWdYB1snGxKM81EmGuHQIL4jxkMnLNFUT
spPKdLJLTkJO1iWGtHsagKzdGldzPEAW6QI1PVcCqQFZCYyggAgmZJ9VQNS4iYhINm6qdXfHgKy7
7Rur2SW+yFklIkAWOdlYuZR3+gFkvWPr8swUkEW6oDz+4+lzAVlPmz/qySe+JAJZRLKsA6wuiNpr
0FDXQIa4dLC6AN5QggZMyD5TQjNXH0ZO1tXmjd/kANn46dZNPQOySBe4yZ9tnQsga6u6lR0MkAVk
lXVepwUHZJ22gBrjJ73MWSUipAuQk1XDYWWSEpCVyRryymJC9ml5JYy/ZMjJxl/HrhwBkHWlWWM+
qaRXRCBLgCwi2Zj7lus7BGRdb+KYTNCE7FMx6UzRThDJKmo4p8UGZJ22gBrjA7J48KWGp0ooJSAr
oVEkFAmQBWQldEs1RAJk1bCT01ImvUqiIF2AnKzTrqje+ICsejZzQmITsk86MbYsYyInK4slFJMD
kFXMYA6Jm/SaCGQJkEUk65AHKjwsIKuw8WwU3YTsEzYOKd1QiGSlM4kaAgGyatjJaSmTXheBLAGy
iGSddkX1xgdk1bOZExIDslhd4ITfuWJMQNYVZoz7JEzIPh73gSQeAOkCiY0js2iArMzWkUc2QBaR
rDzeqJgkgKxiBnNI3KQ3SBREssjJOuSBCg8LyCpsPBtFT54MyCJdYKPDuWkoQNZN1ozfXEzIPha/
EeTvGZCV30ZSSgjISmkW6YQCZJGTlc4pVREIkFXFUs7KaUL2UWelcHZ0RLLO6l/Z0QFZZU1nq+CA
LCJZWx3OTYMBsm6yZvzmkvwmiYJIFqsL4udkbu0ZkHWrZWM7r+QpgCzSBbH1Kc/0Bsh6xtTlmqgJ
2UfK1YniJwOyihvQKfEBWac0r9a4gCxysmp5rETSArISGUNiUUzIPiyxiHEXDZFs3FXszgEAWXfa
NdazAmQRycbapzzTHyDrGVOXa6LJU0kURLJYXVAuP/LkyYCsJ81e6kknvyUYC8iyDsaXWnk4wdsa
yBCXDs3ythIw+xI1YEL2oRIburgBcrIuNm48pwbIxlO77ukbkEVO1j3ebPNMAFmbFa7ocCZkH1RU
/JiIjUg2Jmr0XieArPdsXpYZA7KIZMviNziHNQDIwg2i0UDy2yQKIlk8+IrGXdAmWAOAbLA2sB1J
Ayn/AWSRLojkHagvVgOAbLHqwUFTAyZkH/CyQgBZL1u/HHMHZMuhPA+dCsgiJ+shd4/tVAHZ2OrT
rb0BsoCsW3077vMCZOOuYlcMkPIOiYJ0AR58ucKfbZ0EIGurupUdzITs/cpOIAaCIycbAyV6sQtA
1otWL/2cU94VgSzdX/oz3XMGIOseW9o6E0DWVnUrO5gJ2fuUnUAMBAdkY6BEL3YByHrR6qWfc8o0
EcgSIIucbOmdx+tnALJe94Do5g/IYnVBdJ6CVkU0AMgWUQkqwmgAkAVkw7gFqqLRACAbjZbQxoTs
vV7WBHKyXrZ+OeYOyJZDeR46NeU9EuUeD025yFQB2SIqQUU0GgBko9ES2gCySBfgKiijBgDZMirO
Y6elTBeBLCJZ1gH+x5fHfL/c080Qlw7+x1e59ej2DgBZRLJu9/G4zQ+QjZtqXdVxKiJZDTlZV7m0
fZMBZO3TtcojmZC9W+U5lFd2QLa8GvTo+YCsRw1fymmnvs9ZJaK7Snmaq5oDsq4yp32TAWTt07XK
IwGyyMmq7L+Oyg7IOqp+ZQZP/UAEsohkWQdYXaCM10oiaIa4dLC6QBJryCsGIItIVl7vlFwyQFZy
A0kiHiALyEriiuqJAciqZzMnJE79UNzx0J1OjC3LmHjwJYslFJMDkFXMYA6JC8giknXI9dQfFpBV
34Z2zACQBWTt8DNXjgHIutKsMZ9U6kecLCC6I+YdK9Qh0gUKGUsmUQFZmawhryyALCJZeb1TcskA
WckNJIl4gCwgK4krqicGIKuezZyQOPVjThYQ3e7E2LKMiXSBLJZQTA5AVjGDOSQuIItI1iHXU39Y
QFZ9G9oxA0AWkLXDz1w5BiDrSrPGfFKp/+VkAdFtMe9YoQ6RLlDIWDKJCsjKZA15ZQFkEcnK652S
SwbISm4gScSr8IkIZOlWScRxRAxEso6oXf1BAVn1bWjHDABZRLJ2+JkrxwBkXWnWmE8KkAVkY+5U
XukQkPWKpcs3zwqfcrIA6QKhA7y0u3yu5L2zM4Tb4KXd3jN8KWdsQvaWUp7mqubIybrKnPZNBpC1
T9cqjwTIIl2gsv86Kjsg66j6lRm8wmfijocQySJdoIzPSiMoICuNKaQWBJBFJCu1g8osHCArs3Xk
kc2E7M3ySGS/JMjJ2q9zV4wIyLrCjHGfRIXPOVlABMgiXRB3X3PdAICs60walwmZkL0pLp0r0iki
WUUMJZuYgKxsFpFTngozRCBLgCwiWTkdVGapAFmZrSOPbIAsHnzJ442KSQLIKmYwh8QFZAFZh1xP
/WEBWfVtaMcMDMj6brRjLFnHQE5WVstILhcgK7mBJBEv7QviAsiyEvDuAkl8UhkxAFllTOWooCZk
b3BUCIcHRyTrsAFUHR6QVdVy9sqd9j+O4cgHyCKStdfx3DAaIOsGK8Z/DoAsHnzF38tcOgIg61LD
xnhaJmSvj3G3SnWHdIFS5pJHWEBWHlvILAkgi0hWZv+UWjZAVmrzSCNc2pfExYdIFjlZaXxSGUEA
WWVM5aigBmQLrnNUCIcHR7rAYQOoOjwgq6rl7JU77SsRyQKyrASsk7XX9dQfDZBV34Z2zACQRU7W
Dj9z5RiArCvNGvNJpc3kGI4Kro15xwp1iHSBQsaSSVRAViZryCsLIItIVl7vlFwyQFZyA0kiHiAL
yEriiuqJAciqZzMnJAZkAVkn/M4VYwKyrjBj3CeR9jVxQU6WlYDVBXH3NpcNAMi6zKBxmk7aNwKy
+dfEqXslusWDLyXMJJ+QgKx8NpFRIhOyV8som10yAbJ2adpl4wCyLjNonKYDyCInGyfXcn+3gKz7
bRyLGVY00gWIZJGTjYU7easPQNZb9i7rbAFZRLJl9R3PnwfIet4FolJAxVnEJR+RLCLZqPwFjYI0
AMgGKQObETVQ8VsdsldFbOCBA3jw5QEjx2OKgGw8tOq+Pg3I5l3pvplFPyNANnpdoWWQBgDZIGVg
M6IGAFnkZCM6Bw4UrwEXQDYpLVBSU4qfbryPtrh0QAQJOlzeLd6Dx7N/QBaQjad/ubpvF0D2/H/W
+MuSb589O905g1We7bsnITB8ctv2x1h7g7LWNrS2FfwEZAFZBd1WDpFdANkxFFoWnuWYau8v2HR8
0OA9Dxx90tplSk1Ks3bU+6z4nVBy3kT1JI+dxMjJxk6XnuopQwfULJXnfDn/g7/D+0U5cOiomM7W
UxyaTost9Hzw0JOIXvTvn5t3pL9/R7mNit8LzQKyrAS8IEY573VY4Axx7ZDqkN19SdMWXFqdPPCB
f3g6Myo7o9UXadeJQSO33UJB0E2eTQuqBR1Va9OE7AS1pI6ttIhkY6tPz/SWIRirPGR39PAbrAW/
ky/fmZDx9Cx62S+HljRkBWs2KLIdQnRf4LBiW4AscrKKuaw84mYIxqoP2dMDGj07j+i2wK59W0n/
o6yTjeFSzrj+tT8OCs0GQbbOSlofnLG1T7IYjATIArIxcCNvdpEhSOAqyLbim/QXAsY87uTuJ9UN
7IqtpONOPqNLy5qhlQ16DD6zU+PgutS2fYf071TVX5WQmChWDlRp171LWFaedoA+qmS0rv+3rlb+
EwRZbZKPrglae+DvWIUNQBaQVcFPpZQxQ6eB6jnZHUGRbLNNRPeYuk68+Ku/dx7Ytmxyz4DyK436
9u+dR/esX/xa10Bl6zeXH6K8XaundLTq0q6bm5lD+bt+vauWWXXrjz8O1+o/unDrgT3rZvaz2vk/
U54husTcq78qHGR776JFtf3t1dqo+IOYUe4VakkdW2mRk42tPj3TW4ZOAzdBtk8W0bmG/ep8nKNP
j+jAs2aMqTX62aqjg7dYPxw4L9NsR3vMf3p93FcFVtVSM+E7jej6Ln+atYeK4KbhUtplIbpC9zP7
cdkRGslWW0YURHulfKzSj2LigCwrAasLlPJcCYTNENeOm9IFNaYSLTN+AlBnBk/t328/X7yfP1+r
qGu7pqhb8P7Lb327j+jIOMMCQ3fx6qSfpn34M/N5mx7fNv6Jm/31xatvzc8n2tRZb8YdT19JtPKH
nzghQTtOKmS9nnm0LD20bmMoZLUPiO4NbaHMHiCLdIEyziqboBnMCxdAtk+KKKkVKvfht0UdPVvX
ctJ7RNn3NE1LqHPSFzzHO/XKCzmqnSBYmNZtPtFcfa1Xa4bh2mFVNK3a4A1Ec/gnAynv8z8NvK9R
oqbVuGAr0fI64lyGrI+WDGtYsUqLd7m/5/T+An/uJ/ossKdvFYbsBB8tKNREld1Ks3nKiGSFEhDJ
quK0ssiZIdxG+Ug2Z/H3P3L5aQmnUWmlmRm9mJcZmK/mS2fKrhG/ak14iOgNU/eDcmljU1H3BtEh
MyWQkUt5zTTtjDzKu9t8RjX8MNGt4hSGLK1trZ9c/ReGcQV90/qTtIB8d1s75mdhyLbLoz0nFGqj
yK4JWU8DBjlZRZxVNjEzBGOVh6w+CevPN8YDrUr8qObDZFPfJ2yhgvN5u8q0g5vPMevabKEj7Xi7
OYevT5lETVpENE5LfptoSQ2zmfYx0QqRa2DI5lo/K72SaGk9q4H+WXUf5V0cUqNphSFb4xDljC7U
RpFdQBbpAkVcVT4xM3Q0qf7gi39We0CUg4c5eqUdtwi2tuPHTgMshacwIR/gnaRjWzezHoH12G9A
doiPCnpZDcd89OHlWrVt5HvSqtEuJtotuM1drLXOHciRcRN/C7Fx3EHKHhxSUxSy1TY7tIS3kFxl
2DUhayaxy9CBC05BJOsCIzoxBXdAdk9GqzaidDhjzFSOS+lmVuW5RAdP9Kv0ZqJ3jUdfoiqp1vGd
zuKfhumR7K0MzOP8DTl9oHXJo0N9/TVNfZQ9mvcYsjOtyl5EG1paO/pnp8N09NSQmqKQrcJrE54q
1EaR3Uo/iW/jXEAWOVlFPFYiMd0B2aCf1WonLCTaw7i7ip+A/fi/r4zyOa+e+tZ49p/a4873Zv2+
jhcXGJBNfo3o58BPDoRtRhbQ7uZ+I9XbS74beY8hO82qFJANza4OzKbDRsLWalMUshVnE70dOKzS
lgHZHEAWkFXJbeWQ1SWQDfoxgtaVX8XFL7+6W1A0uPwq1ggk9v15r1F5YN1RPZKtwCsJvrZyt4ZR
mM+ZVmJA02pzbHw7H2DITrGMVhSyo/LogHi0FlwK52RTPyP6JLiBOtuV5gitAbKsBE8//FPHYyWS
NENcO8o/+Ar+xZeW+jPRl5r2ANHh3+cvCJTJ4lHWSPEyxF1/fPf+A326btMhm/YR0Rfmcy/TMFf5
aHOS30j1OduawXsM2TetyqKQvYxTDE2tw+ZnYchW+JKTFoXaKLJrQnasIuLGRUzkZOOiVvd3miEY
6y7IJnNourCKdgPRP22q+0u16lWYpJ12Ea0f075uClu2/XYdsglPEv0U+m7Egfm0q7Hf9icQ7e3F
e8VDdmgOHeniP8fYKAzZirzyq/Dy2kKnyLoLyGJ1gay+Kb1cboTsbKLZKdql/OAr9NkUG+Mp/klX
b9MoXfYYD76uIPqzvmWoLqNHd9ea59DBwEOsczh5IN4IUzxkex6lrDOtXszPwpCtzC8/LLyWttAp
su6akP0/WeWzQy5EsnZo2YVjuBCyTTlafV/TevKPCAZZFks+/4knxGsD+Pdg/qTo4FwDsvye1/3G
0lpuMJfoRq3absoXWVijvMM/+RL/OKZ4yPISrtyLrFPMz8KQ5SVc+VcWaqPIbiVWDOdkAVnkZBXx
WInEdAlkg967UmU6w2CEpqUvIfrKyrV2PEg0hNXOoeQkU/vJr5pLuJquI3rarDztIOW00FI+JPrD
ehViE36rl1hcUAJkU1ZTgfn7MrOvoqsLavEyr2H+o0ptALJIFyjlsDIJ6xLInmbqNK1Rd/Gegu/E
aoE7eV3nJUZ97U+JFglq8ufPxrqB1Gv5NVtH9IW09/tot/Gzhaqz+XgFTTuVH4/dZa44eIWX0Vrv
LijmwVfCB4Ef7JrCFPnF1+n5tK2BdVCtz0r8NBGRrNABVheo5bkSSJuh+43qv/jKnv3+R6J8/N3q
Izyh5fobsmrw//47/EC7FK3Oub/y2wn6C21z/jXvg2aaVv3CGQV5uZQ/jH96oKXzbwT23N0hrc5Z
PxLtG8jNkjk14HurKycJ2r6STXSFbqji0wXaGH7cFvi5g35G4XQBY3+GfkC9PwZks8eoJ3nsJEZO
Nna69FRP7oCs/k3h/7PMzLCexAkD35alv67hXEGBkWOtzUlZ2vDL/L/4xv1WfrnBtt+6s7kHcRbX
l7lqzT7+eFTPMLTiHy/QthXfLeQfwtIMfkEXlxIg23YXbW6lN/T/KQzZz4km+g+qtQHIIl2glsdK
JG0GQ0TxJVwcnQZK/o4F91rZVK3lN9aBTTfzawtF6cBBrV6WDNfGc8KABova/oKpovx1qxmMtp5l
VPCbESeb/83gfaL3RGNR+nHs29rYtP5W/ZjyzrJ2jE/+2cPrQTU1V1K2eCONigWQBWRV9FspZM7Q
WaJ0uuD4kf4y4tz+HYOXvFY8960Vu7YvnXFlAIi1rv5k5Zbf3x7J5EweMfV/LzTRzVDv0jfn/znz
lauO9Rsl7cI3V+w5tOnnB610r3bKyJGnWIfrjhw5rJq1Y35eUkCPmig3a4aNHNkpqNHII/RfIyEc
VKnIZuV5wlGyL1dE3LiIiXRBXNTq/k5dANlijZRap+ExtYO5q2mV6jSoyQ+3REmt4v89bWp67ar+
Hf1gSp1GjRv4X3ioVxX7p8E/tK5RMS0S3xM5YAnKhdc0CZ1pFDIBsohko3ATNAmnAbdDNtyc41X3
IFFxD4aab6WfC0e/8RKl2H7vpe2vnqMvmCi2WcjByvxjNUSyQgdYXRDiGNgpWQMZut8onS4oeZI2
tai1lBaZIXK4Ee+gHLFU1/mivzpn2ctdkkohignZ0aU4xXVNkS5wnUntmRAgG0M9n5ObK94kE77U
2kjvhaZsw7eLf635frJDv0xoFjVnAVmkC+LvmS4dAZCNoWErfU5zQt9MG9T5zb7MDkG7Dm6akOV7
mE0vnh1l0tmAbNZoB8V2fGhEso6bQE0BANlY2q1NJo2wfslbqN9j/6WJEQ4Vahn33QBkef3wihe7
F5Pi8MtSmf+3L1FW5EDd39K9G4Cse20b15kBsjFV77ilz4h3yYQpg5d+IsVTLxYtGLJMzpw5408I
I3BoFSCLdEGoR2Avag0AslGrKqqGVcRba8OVtKqp4aqdqCsEWeZs5qfj/b/gCC9R5QXcjLIuC3/U
G7WIZL1h55jPEpCNuUql77AoZPlVOn891zV0OXHoNABZRLKhHoG9qDUAyEatKtc0DAdZDlNzvxvX
NuIcAVlANqJz4EDxGgBki9ePG49GgCxzdusnoyMkjivz/wBGukDoAD9GcOM1Edc5Zeh+MzOuY6Bz
uTRwm27z8H9y/nq6c7hVaCZkL5VrJvZKg5ysvfp2zWgGZBf1RfGOBvidjcWVvP+N1d9lHuLjgCzS
BSEOgZ3oNWBAtiAbxTsayCsOsfqxzZ+MKPQjhcr6KyKPjores9zXEpGs+2xqy4wMyJZ41aGBxzSQ
u/6xrulBHgjIIpINcgdslkYDgKzH6FmK6U6qF/CkKr+JExHJshLGB7SCLWggCg1kiGsHBRoorIGs
H8e2DVo4C8giko0CJ2gSTgMZhS8u7EMDlL/02a6h7/U2IWv+999wnuT+OuRk3W/juMzQgOzeOXNR
vKKBORtK+BrZ8NxZ1Qs7W5XfxUlHAVmkCwq7BvZL0oAB2dm1UbyjgUeLg+z+OWObhHntLSCLdEFJ
LMHxCBowIPtNhKOodqMG7ooM2T+ePzn8C24AWUDWjdeCLXMyIIt/P2OLsiUZJNLPare9dJb538+L
ClplkSDzkZFFj3inBjlZ79g6pjMFZGOqTiU6CwvZPXOvaFTMP6MBZBHJKuHcMgoJyMpolfjKVBSy
viUv9ih+TBOyI4pv5e6jiGTdbd+4zQ6QjZtqpe24MGR3vd4/6GcH4cWuspizBXQEkMXqgvAOgtrI
GgBkI+vGrUdCILt77rUNikkTWDoAZJEusHwBn6XUACBbSoW5oHkQZP98uX+Y9Vph5gjIArJh3AJV
0WgAkI1GS+5qY0K2YNdb/UpME1gzr/IHZwvoyMXWvhc/kZP1otVjMGdANgZKVKwLHbJ7Zl/ZIPyS
2LCzAWQRyYZ1DFSWrAFAtmQdua3FPUQLb+9aCsKyAgzIHr7IbboozXwQyZZGW2jr1wAg61eFZzau
eb9f3dJOtsoSzhYQIMtKwKsOS+s8Xm8PyHrPA6JYTFBEKYAs0gVFnAIV0WkAkI1OT15vVXUpx3CI
ZIUSEMl6/WIo7fwzhNsQ3l1QWr15rb0J2eFem3fwfJGTDdYGtqPWACAbtao83RCQRbrA0xdAeSYP
yJZHe94514Tshd6ZcdGZIpItqhPURKEBQDYKJaGJVnUZZ5XoMCCLnCyuhtJqAJAtrca82d6A7CFA
FpD15gVQnlkDsuXRnnfOrfqniGQBWVYCVhd4x+1jM1NANjZ6dHsvJmQvcPs8i5sfcrLFaQfHImoA
kI2oGhwI0kDV5RzD0SFAFpFskFdgMyoNALJRqcnzjQBZLOHy/EVQVgUAsmXVnLfOA2QBWW95fAxn
C8jGUJku7sqE7PkunmKJU0NOtkQVoUE4DQCy4bSCusIaqLqCuBwCZJGTLewa2C9JA4BsSRrCcaEB
A7IHz/OyNhDJetn65Zg7IFsO5Xno1KorRSQLyLISsE7WQ34fk6kCsjFRo+s7AWTx4Mv1Th6vCQKy
8dKsu/qtZkSy57prVqWbDdIFpdMXWpsaAGThCtFoAJBFJBuNn6BNGA0AsmGUgqoiGqi2irgcRCSL
nGwR30BFCRoAZEtQEA7rGqi2WofsOV5WB9IFXrZ+OeYOyJZDeR46FZBFusBD7h7bqQKysdWnW3sD
ZAFZt/p23OcFyMZdxa4YwIDsgWGumEwZJ4F0QRkV5/XTAFmve0B08wdkEclG5yloVUQDgGwRlaAi
jAaq/UVcEMmyEvCLrzD+gapiNADIFqMcHPJroNrfgCzSBX53wEZpNADIlkZb3m1rQvZs72oA6QIv
275ccwdky6U+z5wMyAKynnH2WE8UkI21Rt3ZnwnZoe6cXXSzQrogOj2hVSENALKFFILdsBoAZBHJ
hnUMVJasAUC2ZB2hhaZVW0Nc9iOSxeoCXA6l1QAgW1qNebN9tbWALNIF3vT9cs8akC23Cj3RgQnZ
IZ6YbIRJArIRFIPq4jUAyBavHxw1NFB9nR7JArJIF+CSKK0GANnSasyb7U3InuXN2RuzRiTrZeuX
Y+6AbDmU56FTAVmsLvCQu8d2qoBsbPXp1t4AWUDWrb4d93kBsnFXsSsGqP4PcdmPdAFysq7wZ1sn
Acjaqm5lBzMgu2+wshOIgeDIycZAiV7sApD1otVLP+fq/4pIFpBlJeBVh6V3H2+fAch62/7Rzt6E
7KBo27uxHSJZN1rVhjkBsjYo2QVDALJ48OUCN3ZmCoCsM3pXbVRAFpBVzWelkReQlcYUUgtSfT1x
2Yd0AXKyUvuplMIBslKaRTqhTMgOlE4wGwVCTtZGZbtpKEDWTdaM31yqb9AjWUAWkWz8nMytPQOy
brVsbOdlQHYvIAvIxtaxvNAbIOsFK5d/joAsHnyV34s82gMg61HDl3LaJmQHlPI0VzVHTtZV5rRv
MoCsfbpWeaQaG4nL3v4qz6G8sgOy5dWgR88HZD1q+FJOG5BFuqCULoPmlgYAWUsT+CxOAzU2IZJF
JFuch+BYRA0AshFVgwNBGgBkEckGuQM2S6MBQLY02vJuW0AWkPWu95dz5oBsORXokdNNyJ7pkemG
nSbSBWHVgsqSNADIlqQhHBcaqLGZuOzp52VtALJetn455g7IlkN5HjoVkEW6wEPuHtupArKx1adb
e6uxBZEsIlm3enec5wXIxlnBLukekEUk6xJXtn8agKz9OldxxBqZiGQRyarouRLIDMhKYAQFRDAh
21cBUeMmIiAbN9W6u2NA1t32jdXsTMj2iVV/KvYDyKpoNQlkBmQlMIICIgCyyMkq4KZyigjIymkX
2aSqsZW47EYki5d2y+aa8ssDyMpvIxkkBGQRycrgh0rKAMgqaTbbha6xDZEscrK2u507BgRk3WHH
eM8i3YBs73iPI3P/gKzM1pFYNkBWYuNIJBogi3SBRO6oliiArFr2ckpaQBaQdcr3lB8XkFXehLZM
IH07cdndy5bBJB0E6QJJDSO7WICs7BaSQz5AFpGsHJ6ooBSArIJGc0Dk9B0ikt11hgNDSzMkIllp
TKGWIICsWvZySlpAFpGsU76n/LiArPImtGUCgCwga4ujuXEQQNaNVo39nNJ3crYA6QKhhPGx1y56
dLUGMoTb0CxXzxGTK78GTMieXv6e1O0BOVl1beeo5ICso+pXZnBAFukCZZxVNkEBWdksIqc86bvE
Hc+unnJKZ49UiGTt0bPrRgFkXWfSuEwIkEUkGxfH8kKngKwXrFz+ORqQ3YlIFg++yu9MXusBkPWa
xcs23/TdnC0gQJaVgNUFZXMh754FyHrX9qWZuQnZHqU5x21tkZN1m0Vtmg8ga5OiFR+m5h6O4Wgn
IItIVnFPdkB8QNYBpSs4pAnZ0xQUPWYiI5KNmSq91REg6y17l3W2gCxWF5TVdzx/HiDreReISgGA
LCAblaOgUVENALJFdYKaohqouZe47ES6ADnZos6BmuI1AMgWrx8cNTRgQvZUL+sDOVkvW78ccwdk
y6E8D51ac58eyQKyiGQ95PUxmiogGyNFlrKbhBo1EsOfUim9QvgDjtYakN0ByAKyjvqhkoNLDNmq
54wadWIkpVYcNuri5pEOBtU3ueiSkf5yfv9T0oOOObl56Rd3pYUfv+/XT0Y4Er69PbU194tIFpBl
JeAXX/a4nHtGkRiyLbYS3RVJ0w23kC8ab78sT8DBKtl7V77dIVKX8ahPTEwI222XTLrUPFDx9Ke/
mLdg1kvnVzcqjt9E14Y9x9FKE7LdHRXC4cGRk3XYAKoOn6HzR8qXdjffRHRHJL023EC5YyMdDKof
lWUB1vrce1N47gWdFLPNji+/cl3VML2lfEK/mUztviDXkCz/j2FGywdpXZMw5zhbBchiCZezHqjw
6Bn6FS4nZDcWA9lGW6K7bxt1lGjmSy8bZepM8ePQ7Mtss9fFRPPrhxltaHa++Q1xif5zVQOzR0bo
Teuso9ci5GvDdGVTlQnZbjYNJ+UwSkayg7///pN2EdTZ+P0fvzgpwrHg6rO++e5bf/nk9Xu7y5J0
CxZS4m1VIVuhe58zGkShVwHZc5KSjVKhxokfMs9WV47ixJg0GU40p17RniotpJVV9OrWGxj6H57T
vuvo7zivsc7IMt9G2f2KnuRsTc0D4otgByAb3Xe7s8YKHv0KogOR/pF76x2U3Su4cYTticL2wWXl
uIoRmsajunbjxuZtXzx6t6HPDF136kWy0apGQHZIUONaPxHlDg2qiOtmBMhOLKDr9HGTHiDaa8S0
qXdx2uANPYI9fjv9VCmucpW+c0BW0XTBOKI9kf4zW+vtlNUrCl+4IuTBhk6M120LVDTtjVWrbo5C
SnmbeAGyIUydkF/M47RY2+kCop9qF+m03p+0pqlee8xfAWEqfE508DhRnfwU5ZxT5CxnK2oeFNfW
9lOclcLZ0ZVMFxQH2WYL/l0RjUUZsvkPDL/YKP93/zwfu8Id9tniB6JJ9o0Wh5FUgWyzidNnL/jy
0VOtCC+lZds2IjOU0q1vzxpaYuvrXv/g1ataFFWQiGRDINv1CNHzVrua/R54e/rTFzW29sVng4sn
vf/SxJaadmLfPseKio59+/g7Pq5fP38Sq8GQx96Z9sSw4Jxr/REPfvDdx4/0qybOq3DKaRyoLju/
V7dCC19H+ugx4+FbH6LdHUVbUUblUY4RdPc5Qu/ZGCkYwxf/F5B1YSSbWKVa1aTi7a4fZcjmBf2g
OvX5bKJ/a0ZxYmyafEP0VGx6cqgXNSBb7Y4d/OXJxfdhd0NRjTYbS7jS19LB7g2f0eMs2n2DxWC/
NotAtu0hokeMw0nnzzF63fBAXeuEpBF/63Xb76k6lehWUc2NXrAO3030pbFdccxq4+SVE6qaR5Mv
XmZU0Zfi37Qcu8bcW9vQOl3/rDid8kzujyFa7he501Hy3aK3qLOS9rYPOcfxHUDWhZCN1qsEZINT
Dqn8ZCP7wmjPLnc7QLbcKozYQfON1k1J/f8yrnw5WSI1tGe4fkLD9ZQjkpnpq2n76Ll8tEAn2n2F
eysC2QtzyDdOb5X8DGcOKF/8oUVtzBMfEmMUiLrX3yfSU0HBdyt3Es3QW6ZPE6cZJ88yI2E+SPlH
s3Upz9a0xqvEbRWX1ceESNVkO2WeYNTcR/SL/1jXo1RwtbH3BdFV/nopNkzIdpVCGIeEcEG6oGbz
tm2a+r/Wi+ix1nFNwjyn1QpDVhvvI58egBg91Dq2Sd1C6yJTjmlSP7rf1FRs0KRRoedaleo3b3ms
8WRYDPA10RNFRFWpIkNQgOR+8JXyHov44aWtara7N5MfFOnPSoMgm5VJ+z+8vP+4D5humcbz+YAF
CkM24R2ifXpCNOF27nXxTT163vgFM/U3PRuqjcnhG6EnB5w68Ucf8XunIkJWF+mnq7r1ve177uUr
3W177KOjr59Su17nOzYRLampVT5/9KtEf98w5vxQrx5G9EeqIWG3ceMG+GW9Op+yRQTM5S6fyXJj
V4K/tfgGgHOygKxqqwuCc7Itb/96/cF9f7872oRa+thrr9Tvslrc/9BFKVq3+79ZvnLOM32LuFsR
yHbnS+1Bs1niwMe+/XPl7ElDg7y8ynmvL1w97+2LqmsjHry/s2g44cEHe1v99nvoIf8YDS5/Z/7q
RZ/derJ1UNNqjn335w2b//xwQiNR1+6+e9bxQsj7Hzw30EK1rQxx7UgOWU5W+iYbJjyD+TVHpCuD
IEu0Rb91SZzE0WzhB0YCsoMDRqlxHadkX9K/dXvsId8Xegya8Fgu0bOistovjFsdJGmTRDQbEbIc
D+e+kC76rfgWh9GX8EbCw0SvJIsqrcc2yj9fbJzPD75qiY3g8hLR9OB9c7vWr0RbzcZ9smmr3nuY
ds5UAbLKpwsSr98srnVRFvXTvehEzrLpuBtC9FntB/V3ABEdvdPw4oCjFYFsvwLKv9Y43vwzjktE
yf/Bn1Fo9r15DzenNd+TXSkacm7NTNJp2rNET5udX2gk54h2PV/XrBqw3OiP4xNxDV1m7X1kHlfw
I0Ofg9SRbFWmz1fWrcf5BZQnoBkMWd/FhuLrrSQqnC8QkJ10aYZextz+xnL+Cv62hmiewJmeBeY3
uuDjevG9OSKPdncyOkuexZqJBNkqnHz9zPzBQIX/Ec3le5vqM4isb9vXc3JvF92EXcL1F9ENxhjB
f2tMYVhfY9ZU30+5w4KPOr5d67BwlO1dHBfEQQHUThckP8hhw4GV336/hD/3XiD02CqTDuv3hQPz
6Ku3ifavWS6efeQPL6TkIpC9hVHcX2/UYQmfkLl4yXb+2Ms5MlGOmc87u5f9wb8XmjeX8vXk3OKg
S/MxP3Cv5Ksz6+/f1gjnMpfhtOWV49vmzpzzZza7GwfBQ9f9y40OrN+g8LOvDJ6e5JFsryNUYNFL
qz2P6GHGWzBk5+gP89m6jLkXTfTp1uY/ArI+q4ip5j9vtO52gHz+ELcd+wjfzVT5keg968wRbOVI
kD3bRwdMGGvaBUcohxcj1GfJnjFPbj5k6IkiMg4H2WrbyTfKGsT/2UkwfZr1CC2VH+vd5j8mwwYg
q3oke14W0Y+nc8q1xnkcK+48ib0qGLJ8azbptMZ1Ot7LYciCQheRgKyZyNJ9sR1HMwv1JTN1mLF7
bmtTpUaHMYznbW31w2+xK7/UpWbVNjfspPziIHshX2ILBzRKa3zGi3zKu2KhQxI/Afm8PW/UGsJS
/reiVqV5M37k8mazFuGSxfpw8v/J4NlJDtmr+NFRA0uTCfextHwnHQzZh62DnG+dlmLtGJ8CsiEl
76NT9CN3FdAOC85aEqcJbmROHqaj/m/xdL65igTZl4n+9I9Taz0Rn5XMjpL9yon+arERDrLH76L8
s0JaaVrth3ezkDP8D8hSlgaAXaipQ7sGZLchklU1Jytuvn5rYnhPt21Er3JOIBiyRHfraE14i5dr
Nw/1MgHZPilGSa1cczCHpUeM9TF3cfhrbGlDOdvwpOii3Q7y3WM8dDj/CEc1ESPZeuzl3xkrb1Im
82+ERLqh+U49YhHjD+STjxcbM4keF5/Klgy+uOWGbDIT7WvDZkLLY5lvjNwgyOZfY2mf77g/CAPZ
76YY5e1P/jjAk13HYaemfcD99OrW3Sgdf9YXz57EuSEDwaLF75Ehy0HrbOvc7l3XEN3C7YVTUOY3
d/as7c9phYNs5/2U10P07y9pF7O30eEnzeQF1ydzSP2O/7gMG4Cs4pHscB/l+DNQz/hoPz/pDYHs
PPMaO/UoZZ8Z6nIMWd/MKVP18p9vRBp11xi9Re0NVPC81fbxAtrAYUIKZwNm1zQreYVOZMiO4AyD
dblV5O+AyXzSeYfoQB3z5E+XLdNvF7/BOllLxzH/NJdwVfww5EHRxZw+Zf8IgmzgbVwRIDskIFr3
RewhT/GdfAJ/PYaWtxO0c4g2c99m+SoMZO/Ql3CJQDO0PCLOGb/LqPznjeHmoq5wkB10mHLbWGOI
zw48QU5JDQqqS+I1azOD9p3frCW+QQiRLCthvPPWKIUE1uqCT4l+94cqp/GNE998hUDWyp1V3Ue5
5kMOaxiGbGg5bDbIKKADpqtrWqdMoj68cnEj5Y20zhyUGxmyaR8RfZxotbyZ19xU0rTB/CzuYZFp
41KjXj39UQwga+gjHn9NyFZj2L0c6J+//lbyLUYQZHMut45GgKx5P6O3asNJgFUc7aZyrBhaPkzU
buIwlw1tls/CQPZ+HbI1VoWeymsT9HNOfvIv88Cq6/WKcJAdnkW5LawxOAl1k3hmsPpSfnQWKInT
OHoP7EqwVeuomNk2fhLh3aLyg6/KnOG8y2+6ZPbTJ0Mhu83yydRMk4v+1mKdLOVmGyWngP0g/69h
Ogj5Jn+Jv1kiZxH4prIdJ3zbWZXVOCs7TuyEefBVjx883Gc11E4l2tCUU7H/EuV93Kth8I8kAVm/
lmKzMfj1Vy83v3BbMg/v4F+nvkv0VqDziYwfXh5QVshqs3idLOdiE7/lxXeX+v9nwsiRl/RM0Pjb
dL11o6Np/CqZwjnZRF59MkPTKv3JgeaI4JPNp2AJtU69/8dN2eyGuReL7+hwkB1yhPICqc3qb7LT
br+/XmCCYiuJH+FND61yeM+ErP9pn8PiODK8ypBtxmsfg+LThfo1FRzJrmhi6jR1E+UXCtYZsgWP
jTbK/13/DJ9Mu/Wv29kcsdx9l1luZT4+pmmDeKW5vsJV9JeyPDJkWzGsP7/FPPn2ST7a2ZHPuEpf
xrJm6lWn64uARCeArNBCDMuDRB9VNvo7iUO8G3iTq2aIB49G4VhyMlO4zJCdxNlPkRL4nBdemTS3
utb+L/jXDAkrA5A1AlWOf/+jQzaBkw4f+s8qvNF49Ad8b/1HXa4PB9keByjf/wuElNfYYb8tgq7k
4J/yFu7fkX1AVu2cbPsdRN0DnvMl36mHRrJ/WLf94SGbZyVPuY+anHrQ454UgduQ8oqmXcPv6/C/
CJEfLhSNZB83lnD1CDmTdw6fKgQczmu4RDm05A3zvgmQDRguJlt38woO86F/1z1EIrlzOROrltV5
Okegd/NOmSF7m48Ot+IOOCYNrC7QmrRtx1+cZ7Chz7dGasXDW5Hsa2ZlDQYvR7IaZ1EDqwsSWrRt
yzf7ddq25bS/UW4+Qrkn8mY4yJ6wl3z+nNVlufyTwZBMgd5BKofK95h9yfEByCoE2cS6xzSw0l5m
TrYTZ2GDngT8zIusQiG7yIo+I0DW/0sD9seWzMHl/FmFg43964MLR7KM0EVmUpWf4IZZJ5v0vAHZ
/vz79W3/Bp29oqvu63WvmLFOT07RoQl6BSCrqyF2f67jhSa1je7OYgCdyZsD86lAfOrllFzKPYu3
ygzZqwvoiLgtOY/fYXCe0Sd725rD+/l7vh5z9QWr7lpOROmQ/YRjXrOyG3/DCsheycujT7MaDtl6
eFsT/iHDkcOfWFWN1xIJrwwH2dT1gRcTHLOGCl7Qk/vWmcZnyiYquDK0yuE9QFYhyFb7eMF8K1i4
hhey9tS0JsxFfiplliT+AdaNZYesxg80MpniSfyrg8/anBgobTjMuJcDEIvwYdMFFd4yIMsXU9ZN
JwSd3Mq8heWFXJe+8D1/K9B+/boHZC27xeiTXwO4z8hYJjzA2VMRc9bl78uPUsz+eTHqfLHUqcyQ
vTyPsk7lDmqu4vt087Ym4RGiFXU0LW060Vrztqm6uBXSIcsvINjIB7mk/pfrBGR5rSu9LWq4VOBb
r88YlKfk0V8iRSBKh010SKw1FJC16vQD4g/7zOPmzjDOX/F6tCKl/gHK9v+8u8hRJypq8VJ2fvDV
yYmxZRlTmZxsLX6aca2pNV4Ps70DuzbfG43xK7IJN+D1XME52dJEstoL3Gl97o0fcFjxh79vDkD+
saJiLX23mS74I/CLrxrfGpBtVkC+m/ynFd6o1PKug/xrBFENyBZWTjn32/MXmP5WqwrjeU3rdP0r
cTivA3mjqug4eQLHn/q9dpkhe0EO5QwWfY31Ud5benK9ygOHzZcK9c7mJ1r8bcw/D3hHQEWH7Eii
vP9wCiOh5us+rhOQ1e7jb+G7dETXfjWXskSO9ZiFVPBKujioVflPPv0gNvmXYRvbJ/lvnvSD2j28
XsvY0hjaH3CyIVBqGgfOyaV//Xkts62zH7VYM/xuhZOdlcLZ0ZWBbEW+kbKWEjxFtEnEDT8FPz4e
n00FvAKgzJB9iFcQNOFOufNtZnKPvf6Sq67ldT9n8C8VeluGGpBjQvY3/jGmWdmM7xcf4e1aK4yl
sUZ1y6uu4mfFyedefeWx1sl8ka0QwRUga2kkVp8iWFz72IQHZ/FVbdBQS+Rn7fTdTYNOP3daDoef
FcRQZYbsgCwq4DslXiLwOvc659ZBA6/jBBW9p/eqPcOba+4966zbV1AOC6BDts56rlzwxHXP/E37
Z5ivx6o9m+u+vL7/0Jv5K9p8pfBw/k34wsv7nNx9FH/BZ+sg785fFCsm3+l/TirG1brl0T/sjFyS
+HlsXm5QyZ6g12u8nnuKsSXLXxOyHWWRxwk5lIGsxmHrO6aG+M7+b+HbD/OKgNZmXRI/ufqS45cy
Q/ZWs7M+HP5YIbPGmb7dx2taI05MPGTFFW9bP0bgdZg/maPfwFeMgGwyP4P+1yJq0nccb3BGhtuN
NdtpQznzK0RnyD5p1Sn5mcEzluoXX8cv0CUSf/LuMG3V8DN/Hc0xbq8bbjS+ItP/pnz/bdBbQXkF
0xqXMirPDrZMx6NEv9YWNem8rNYq0/QaTav8qFgGKIrv1sUmZLWzGZV6ybtiCNH/9N6OF+A3Sv6z
xpOrCuxRXA5yLpfy7tVFr8yrBHhZmIFUS4pa8+loP33nOP5ODy1XGY34huo8q7kcn7X5640jWUBW
iR8jfMCLTkW6StN6cWLrP2Kj8RaiqWbS7fQDVDCU68oMWU4J7OvMHVSYxwtlRd6Ay3HL+GFaMkcO
T3N4282oO32vBVmOaDYygbm041SF8UauXpyCujPRaMlPgPMH8SaHFzP1m1be5u+FT8TRmUH/y0Ts
K1cyxLUj1asO6z+ylcHIsFp1IZvMKNXuz9Qv8qxNd9cyaurP3/zPCN6sPnvzP8PNVtpTmze/7D/H
qDxv7ebN/azj4rPyb5s3b7hcr6k4fgUTl3yH/7qZv9aNknTBn4e57sia8cm/WpBNOOvXfbkFOfvm
n5nQf/NmM8SsdusmIWbBwSUXm66rVX9kmy5l/qE5g8zVYW1/2HVw/7zQVbAJd1pPvrqs2hxaNl6m
S9FwHW1oZkkkxycgq9CDL20Ue+bMDtVSGw/4i7fEg2JNu5G3Xm7GayET+/EPFueJBxtlhuxlvERn
gOh0CF9A33bhq6dSL+bt9pNEXYfd/OOagVxX41wxurGE61ze+rJbnUqNhq0kPkdEsloFfgSS95DI
3x5z7X6+mRTXjPgt2hstxdEqY/hdpKPF1ru8vKhzIyMTJ/aVKxk8ebkgq2lNR90/+bk7+4YkJetf
/sTklx4YHiNNmxGyVvXch159+qbBISNVGnj747cN5eB0kQVZ/nbuOuaGSzsbGQW/ieuPfPS1J27o
HUz1Jpc9OXXa01cN8D8m1ZKa9+puRsn+E0/eQzNDMwj+Q8bGhfn0RGBlcKGDzuwCsipBtuoPfFHv
XDB7lQgiphp+W4MpSOu+f/Pt7zmK2NZLuFGZITvMRwX3ih6SHuIc2c557/933iHO7l0iqjQtgyPU
7J8/+ey3fFq7x4RsDU5b0L4/fuY1kPM4o6tDVqs/lytXfv3u1/xzNFpmRMS8hpPWz3jp4cm/cM9T
9VjlWq7as9I4xRhBsb8ZPAHZICuJCoMgG1uJkj+kHD0OiNBt5Y9pFz+WkKqYkOXn1N4t6uRktVY/
M6L0UvC5dR/VdKZVRysN9xMv7e4j7DmEY08rO5rKt/hXhxr5Gu6pd3BVJ67YdKKoSbl+pzEOo9G4
DePKkVvNujW9V5mQ1U7mx1x6Wdz6Mv9Luxu9L3JrohR8o3fH782f7jNqGNRf6M+gtfqrRM3HwQKo
tZ2hz2iWWkLbI23cIKudcrDYH812z6U37Jli9KPUzhWOshWQVSIny6y69qdNWXR0y9fXB27TKl7z
w7Zcytk572kDXlqDZ6a8eoLwgbaTp9xr3SQmPz3lzTNCHaPX5CmT9Vt4q7rS81OmvNXf2Os2beUh
OrrttxdNSorazpOX7jm8Y/HLJ2prLMhqzSct+Hfbqh/uT9dOmzLFeuKQOuHbrTm+ff/Ous5/81f5
5p+28LfBvnU/jLFuEttM/X7h9+YzYUsElT4B2YjWih9ktafpQDGh6ju0PcSlI0po4wETsu1tHFK6
oRSKZFl3lVt07dnlBItThjIrtu52+ilt/YuuYqThRp16dGltPiuxuqx3Uuc2vLg8NQBZftJ8fOtG
AeSbLSu07nZa+2Z6WsA6t/IJp/Y+vUPT4KZp6WnWUQU/AdmIRosjZBusomkRxz3lgHiZkWSltn5f
txWQVSSSlcR9QiAriUz2iwHIRtR5HCGrjc3bHWk1VNK75hKziII5ccDIyWYCsoBsadwPkBXaAmQj
+gyv+7st4sFyHkiZQpMj3AD1yDoysJy9x+H02vqyOkCWANnSeBcgK7QFyEb0mYmPPNwj4sHyHmgw
amgEyLYcPchaYVbeQWJ4vpEuyNQXQsawW6W6UisnK4VqAVlhBkBWCmeUXog6ek4WkEUkWypXTV1L
vvGlOsONjQFZN1o19nMCZFX6MULs7V/GHlOXHto/uoznuue00kC25gD/K8zcowDMJCoNALKlgGy7
plHp1AONEnsM7A9oRA3Z1G53/0nmex884B2YYqgGTMgWs7o3tL0b96LLydYaNzNTviV4brSHMnOK
ErLH3jGbX+FAQf/oR5kZQtBYaKCukZMFZItfXZB+6qubWFNXxkLl6MMtGogGsvWGTjd/oAzIusXu
pZ2HAdktbUt7npvalxjJtrviW/1NmXmArJvsXu65lAjZxK63/84xrFEA2XIrXNEO6umRLCDL10GE
p+Xpl8603osCyCrq5XESO0OnZ6QXxCQ2vGlO8IulAdk4mUH6bgHZYh98pfd4XrzVxCyArPT+bKuA
GbpfhIdsgyHv7Pa/d0xvB8jaahyJBgNki4Fs96cXWv9QQ79MAFmJPFcCUSJCNmnoq9YbIHXHAWQl
sJZzIpiQbeOcBM6PHDYnm1Br+NdWmsC6UABZ540lkwThIZvc8Np5+yyXCfpEJCuT7eyUpb6RkwVk
Q3OyNU5/alPozZ64WgBZO11T/rEydISGpgvqnzXF/7pz/bD/DyArv0XjI6EJ2aAXM8dnHJl7LRLJ
dnh8vv5P3fzXh7kByMpsRvtly9D9IgiyCX1f5v+zFqEAsvZbSI4RG+iR7GZA1h/J1rvk6x0RLhNA
Vg6nlUWKDN1PLMgmN7ny53BpAsuZPP3fR2QxmSNyALIhD76qnP7YOuuiKPoJyDrio9IOmqG7iAHZ
WkNe3V3UY4JrJpyO4ikNtE8xPfcYRLKamS4Yq53wyALxb2AjFkBWWt45IliG7inf8Nd0jxf/iOg1
1oHsI0dRvKSB7Z81N9zShGxrR5xUkkFNyL73Cf8/12KLb9XMb1CggW++mfXpxBrW+2R/aDJ+Dv97
YBRooLAG3kvSEQfI+tMFhTWEfWigGA28nWa+tHv39mJa4ZCXNbC6cTBkW0kSVDoiRtKLXnYEzL1s
GsgaZEL2n6+OlK0HnOV2DSyvrwOtoZGT9TRkE19wu7Exv9hrIH+C9e9nUk58eEmxufzYD44eldDA
g8Y/HANkkS5Qwl+lE3LHiRZkOVqp0u/hv0uS8M95v6B4SQOfjqlo3Jk30iPZTSc4cp8uyaDmg69p
HxW3ylG/hHz5BSjQAGsgb9dE68GXuU62ycgfi3/8NbhefRQvaaCaxTdA1h/Jjk1o8dDCw8XFI/kf
TrgKBRq46qqrL2/BV1CG7izWjxG0xPaPLQ77S0HDpzpb1xw+PaaBxohkrXWy4n2ylU5/tJjbvrwI
r5z1mM9guqYGCkGWa2v0e2KzgdSif/GzWq86DiDrj2RNgta/+KtdRa8QvQY/RvDqZRJ+3hm6V/gj
WaNRw0u/Dn5Vd8CVANnwWnR/rQnZlu6faeQZFnlBTNtH52cHLo7AFiAbWYlePJKhu0YhyLIiOj+5
KOQ9xIYHAbJe9BExZ0C2cCSre0K1no+vNy6N4L+ArFcvk/DzztCdoyhkNa12v0nbgj1HbAOy4bXo
/tpjjZysSON7thSJZHVN1D7/68LXCSDrWR8JO/EMnaPhIMvf3PUvnxX6YllANqwSPVAJyIaNZA3L
d3livv4dpF9L/AeQ9cAVUYopFgdZ0U2PZ361XIc/AdlSqNZVTY9DJBu8uqCwbWv0fGYz/pFiYa1g
39BASZDVtJp9XtphpWcBWa/6jQHZjUgX+F/aXcgTEtIvmZlpxiOIZAspx+O7JUNW0xLqj/vWSBsA
sl51FxOy5osPvamF8DnZIF20GTdTD2cB2SClYLPwjxEiaqTjtd8jXRBRO+4/0ERPF2wEZCNFsoYL
pJ/68mbW1JXudwjMMHoNRBPJGr3V6vNGZtfoO0ZLV2nAhGwzV02qlJMpMZLV+0sfM3PL1aXsGc1d
rYHoIctqqFvV1brA5CJrAJAtZnVBYbW1bVq4Bvte1kCpIOtlRXl87k2NdAEi2eLTBR73Ekw/rAYA
2bBqQWUhDRwPyBa3hKuQtrALDQRpAJANUgY2I2rAhOzxERt44EB0OVkPKAJTLJ0GANnS6currQHZ
UuRkveokmHd4DQCy4fWC2lANGJDdgEgWOdlQx8BeyRoAZEvWEVpoGiCLSBbXQRk1AMiWUXEeO62Z
/uBrg6fXJiEn6zGnj9V0AdlYadLd/TTXfy8KyBLSBe529HjMDpCNh1bd16cJ2Sbum1n0M0IkG72u
0DJIA4BskDKwGVEDgCxyshGdAweK1wAgW7x+cNTQACALyOJaKKMGANkyKs5jp7UwcrJNPDbtkOki
XRCiDuxEqwFANlpNebudAdn1x3lZC4Csl61fjrkDsuVQnodObalHsoAsYXWBh7w+RlMFZGOkSJd3
Y0L2WJdPs9jpIZItVj04GEkDgGwkzaA+WAMnGJEsIItINtgtsB2NBgDZaLSENoAsVhfgKiijBgDZ
MirOY6cBsoCsx1w+dtMFZGOnSzf3ZEK2sZvnWNLckJMtSUM4HlYDgGxYtaCykAZa6TnZfxsVqvbU
LiDrKXPHbrKAbOx06eaeAFmkC9zs33GdGyAbV/W6pvPWiGTxP75c4802TwSQtVnhig4HyCKSVdR1
nRcbkHXeBipIAMgCsir4qZQyArJSmkU6oUzINpROMBsFwoMvG5XtpqEAWTdZM35zOdHIyQKy+MVX
/JzMrT0Dsm61bGznBcgiXRBbj/JQb4Csh4xdjqm2QSSL1QXl8B9PnwrIetr8UU/egOw/x0R9ggsb
IifrQqPaMSVA1g4tqz9GWz2SBWQJOVn1ndnuGQCydmtczfFMyDZQU/rYSI1INjZ69FwvgKznTF6m
CQOyePBVJsfBSZoGyMILotEAIAvIRuMnaBNGA4BsGKWgqogG2hk52fpFDnioAukCDxk7llMFZGOp
Tff2BcgiknWvd8d5ZoBsnBXsku5PQiSLdbIu8WXbpwHI2q5yJQdsb0C2npLCx0hopAtipEivdQPI
es3iZZuvAdl1gCzWyZbNgbx8FiDrZetHP3dAFjnZ6L0FLUM0AMiGqAM7ETRgQrZuhMOeqEa6wBNm
jv0kAdnY69SNPQKyiGTd6Ne2zAmQtUXNyg/SQX/wta6O8hMpxwQQyZZDeV4+FZD1svWjn3tHQBZL
uKJ3F7QM1gAgG6wNbEfSACCLdEEk30B9CRoAZEtQEA7rGgBkAVlcCmXUACBbRsV57DQDsmtre2za
IdNFTjZEHdiJVgOAbLSa8nY7QBaRrLevgHLMHpAth/I8dOrJ+oMvRLKEX3x5yOtjNFVANkaKdHk3
nQBZrC5wuY/HbXqAbNxU66qOTcjWctWkSjkZ5GRLqTA0NzQAyMITotFAZyOSBWSRLojGXdAmWAOA
bLA2sB1JAyZka0Y67oV6RLJesHIc5gjIxkGpLuwSkMXqAhe6tT1TAmTt0bPqoxiQXYNIFukC1V3Z
fvkBWft1ruKIXfScLCBLgKyK7uuszICss/pXZXQTsumqyBsPOZGTjYdWPdAnIOsBI8dgil0LOIaj
NYAsItkYeJPHugBkPWbwMk7XhGyNMp7uitMQybrCjPZPApC1X+cqjgjIYnWBin4rhcyArBRmkF4I
QBaQld5JZRUQkJXVMnLJdYqek/27ulxS2SsN0gX26ts1owGyrjFlXCcCyCKSjauDublzQNbN1o3d
3LohksVbuGLnTt7qCZD1lr3LOltAFpFsWX3H8+cBsp53gagU0B2RLCLZqDwFjYpoAJAtohJUhNGA
CdlqYQ55pgoPvjxj6thOFJCNrT7d2psJ2apunV808wJko9ES2hTRACBbRCWoCKMBQBY52TBugapo
NADIRqMltDnVyMkiksW7C3AxlFYDgGxpNebN9oAsIllven4MZg3IxkCJHujiNESyWF3gAT+PyxQB
2bio1XWd9tAh+1cV102sFBPCg69SKAtNAxoAZAO6wFZkDZiQrRy5hfuPALLut3FcZgjIxkWtrusU
kEVO1nVObdeEAFm7NK32OIAsIKu2BzsoPSDroPIVGhqQBWQVcle5RAVk5bKHrNL0NB58ISeLdbKy
uqi8cgGy8tpGJslONyBbSSaZ7JYFD77s1rhLxgNkXWLIOE/DgOzqinEeRuruAVmpzSOvcICsvLaR
STJAFjlZmfxRKVkAWaXM5ZiwgCwg65jzqT4wIKu6Be2RH5AFZO3xNBeOAsi60KhxmNIZ+oOv1Wlx
6FqZLpGTVcZUcgkKyMplD1ml6QXI4gUxsjqn7HIBsrJbSA75AFmkC+TwRAWlAGQVNJoDIvdGJItI
1gG/c8WQgKwrzBj3SRiQXVUh7gNJPAByshIbR2bRAFmZrSOPbIAs0gXyeKNikgCyihnMIXFNyKY6
NLwUwyKSlcIM6gkByKpnMyck7qPnZFcBsnhBjBPup/aYgKza9rNLekAW6QK7fM114wCyrjNpXCbU
F5EsVhfExbM80Ckg6wEjx2CKJmRTYtCVsl0gJ6us6ZwVHJB1Vv+qjA7IIl2giq9KJycgK51JpBTI
gOzKZCmFs0koRLI2KdptwwCybrNofObTT8/JArKE1QXxcTA39wrIutm6sZsbIIt0Qey8yWM9AbIe
M3gZp3smIlmsLiij73j+NEDW8y4QlQJMyCZF1diljZCTdalh4z0tQDbeGnZH//2NSBaQRU7WHQ5t
5ywAWTu1re5YJmQT1Z1B+SVHJFt+HXqyB0DWk2Yv9aQBWTz4KrXT4ARDA4AsPCEaDQCygGw0foI2
YTQAyIZRCqqKaGCAkZNFugA52SK+gYoSNADIlqAgHNY1YEB2RYKX1SFpTjatZs3qEX+Jl5Zes1o0
RqtcMz1QqlVW4gFno7Fjaob1x6pjx9YKe8ChSvUgm8rOEPE9JSnpNatHEW2lpgf5VPUqnv6nKtE5
3kAfcQFkWQnjo9OYba3Gb9u6+ORIo12duf2rapEOBuoTXt62xSqZG5bNfm1ki8BBSbeSJ9N3VUzZ
6nXtO6jnSY3MvaSZ9KhMQqsH2aGbMtf2iqTCMzbsWNwk0sFA/XnrtloutWXL3/M/u+XUiKFA4CRP
bwGy0uZkbyLa1i2Sc95JtLhGpIOB+oT3xXdocNlwm+yhx5mHj55tzODY55ceIsrbsXJqG6OiZ9bR
3oHJOb6VoSt2luNyRC/ART7KGhSpOd/Vbmse6WCg/tLsYH/i7axPOweOYquoBgYZkWzRAx6qkTRd
cCNRZkTI3su3H+kl2yhhOkNqzy6j7N6fy5eE78mI94sl92dDi8pz6HvjprXvcv/VvONOfeQK79Cc
NBtkiHKIDF0+lSA7PJ+ODIw0u0FE+1pGOhioH3WU6IDpUrv2HhE6WB4FmwMdeG4LkJU2ki0Wshd8
PuPpyiV7q4DsXz3bd9RLp17jv+Er4uglJZ/nYIuJlG8EsseuZmEzF/z3iz/5M3u4LlKfIwUZDspW
aOgMFozINZDt8OmMqQ0KTTHMroDsdaZLdex+3qRtrIP3w7RDlaUBQFZNyFr2K+FTQHZxEIwrPs1X
xEyJgsEi8rdcR7N0gRNeZFGfbVNd046ZuJ9oXVPRNPUHWnd8kXOcqshgCV0E2SjVKCAbnHLos4Xo
cPsoT/ZkM0DW9ZD9gznlL+l/MK+a+Hel20h4lgpG6VLV30m+V8zVEFfkUYFxlzuG6GlphPYuZIcE
2+BRzkFdHVyB7VANDEZOVta3cIWkC5LaD7rogt7WY/aADRNTK4hnu2kn9e7TqUqg2toSkWwIZJPf
INpzknVYq9u1b4/WoQ+HG3UedHbvwmsQGncf1LuZ/yx944QBFw4fEMjFJaRWSOE1ZUltevXtEvxE
rt5J/Yf1axuaBq7dpe8ZJ4b/B8nHbqB1x+r9X1ZAO6z5HvM30Ti9ttZG2m7VhsrjwJ7qkG01cPiF
/YveGASbMkzeX0SyIZA9O4fo8YD60zv36dW2YmBf06q3OeOcgScXcs+KHc8c0DH0nqrW6edefHaX
QF1KaqrIzjfu3u+0EOdLb9v3nP4dQobQqnfq3btd0D1b8PhObxuQXe60GI6OL/+Dr+RL5m/nh1aH
105ra2pq1Ny5k4XX9v590YMJlW5bvP3IkV1L7wr4p9msCGS1m4n2dzCPnvb+6j1HD2z55bpArNth
2tpdub4jG78521iFO2Lu3P/TWr61bl/u4Q0fBx4iJwz8fhNfWjkbvuxv9tVp/qK3KyVfszDz8NHd
y5+wlrM2eG719mzf0a0L/y/A1K7vrtp99FDmgpusRmYP+scEov8Y+08SfWMdqfwj0UPGzrNE91jV
Tn8qDdnEobO3sAmz18/oa+qxy+y5nzbk7Q6/LHq3ctIlC4QpVzxdp7CWi0D2hIOc17FatZi8fNeR
w1sXPezP7la9blnmIcrZufRhY/Vz4x/nzqhR4dpfd2bl7Px9TODrt+kLK3ktScHu32+uZnSWNHXR
gh5apw/W7cvav2HGqdYINR5esfUoZe/4496qVpXW9JU/edRtfzze2F8l0cZZeiQLyHJubbxEZhGi
BCLZuh/ks3x62T3OiDvvIVomAsbzid4+UTzO0svU0G93TSsC2cRniDYa8WfKHYfN03zsy0YZw9lP
o+Q8qi/1uoPowf4bzLrdFxuP/bW0p8Q6Bb3kPFhJP7UP0a+t3te9iet/MgDa51+zFRVMN39fkHTj
AatucR9z1MBH4peUb9rhuR07HrMO1F9FdI2xcy53Hhp6W43s/8zQZ6Lmg69KL+RZdsgyv5wHEu0W
tzCn+2hRq3ctl5tbmLJFINs7i+hWU/tjt1q9rjIeX2otFlpOQfNE79oJfC/V7nOzWcF0q/t+660z
ae4Jem/Jv5NvyIS9ZvXuc4whTlrmb/eddU8zarNVt9Z4QGo0leUvICt/TrbOLHah316deNXr23lB
1l266zD8fheQPddHC9nrfv3Pqz+LxTTXFvKrIpCttoBoto7FJPFgaeu0h/6zlK+2XT31EwcwAOfc
/n/XP/cXD6Q/xr+FR95G26fc8/CXzNWDg/VmaeLx2aqp117xxDreeEMPRnpl07pfmfzvvvw9Bzb0
SBK3bM+Hlz009uonFnLNa3ponPgEX3I7pj/8+mLubl+/QuJq9ffQITNYb9KhQ33rcJ8cyhlo7LTe
T1tOtOod/szgaSn64KvyCyz58jevmfDUet54QVhL659HmeL7t0cW/cMW+/Pdl79lf6An9IMBVReB
7N0+yjG/pe9gq+756JFXfuW1tIf1b8vaPxBtfnbiFfd/zV39JGLPljl0cB7Rjw/f+Wom103Xv8y1
gbuIDn1+/7hbv+Yf+v/VRgyXPJ+yvj5Kez9/edp6brhaR2oDluyfJ8ZPfPB7rvrCuD+6nim//7+P
vrSAP7OvDkgqyxYgKz9kb+cHCy/U5/AtpcNsXoGlr50NgqyPtl1aPy257qUcmP5mhpqWewnIBq8u
SLmLiXqzfvQKH/k+a1dRS2t4OeP5d5F8S5xDNFlEFonHz/DRH2KLIcvXRlu+EGqcw0HKfD0hMZwv
pQ+ai4uj6Xt8g3cBb2gMWR/tn9iwYnKtc/h6WS8upyl8x99UHKz3aD7t0R9Aj+ZTZ3aspKU0GMEs
XubHqGjF5cJ8+se4cIx942+X5SyDmW+r+RsVnBt80MHtDKEcNZdwXcZ+MK2pUHWLj8lcNBcEWR8d
vJtNWXPoTqJN4ss8qAjIBq8uOJlvV+YYRuvBLji3WxUtuf5QXnKwtRmfxT9/+Ke7+H5NH3uACsbx
BkOWmZjB9zrJrT7jlJN+P1NnKX/3XijyBOnX8N3Ud+KLmyHL5eP21ZIrNWNE+87nOm0s0YKOYqPW
9YfNc7vu4yijZ1UtqV7/9RyM64AWLaQpgKz0kG26m3zTzWxrc44N3xORRRBk6fBZhjtxunJPy1DP
EpBdfkKDY0Rp0KRd/7eZcZ/rF414lvS+caevjePL5v/4xFYbKde4U9NacpAhsmACsv82MTq9MJcK
ruTNSn/yVWXkA7T0Lzkyrs2VDFmy1rDenk95p2haFY5XhhmnVuUAWoxQZwXRZ2YGOIMzcIUj7zeI
PjTOMP/WHzTwwse28ZeAPyXHM3pcaECCksHKUROyVdcwyMyHWuJG6VthkyDIkk9Yi8vNvK7jNGPT
+isge5nhUsc0PKHbTXzXs9+4Eao8k7/S6xnteu0huj9BS+DU+mvmmU8RfcqbArK5Y426+ov5O1c8
W7iCOzF9RbumgLIv5jodsh8I8Gpa801EjzKrk18hukKv0ZJfNdLzqZ/yD3PMXOypfK/3ZKFAw2jt
5N8hesJkuZMiOD625A++7iPa6f92vq+AjojgMBiyr5ga7JhLB3uHalNA9ujKZX/q5e/tbOz8NwQS
9YhgYyur8Yd898bb5+ynHD1K4O0b3nijE38IyI43myWwN//C8eulfOH1N+u0/kfJJ+76BWT/a7p3
k916eHv8P0QXme1GvjFZRD8jOL5pb506lQMQa9v8/IkvpZAqzjmL8kVdf+3zRN8Xiq38x2zeyNBl
UzEnO7aAcs+wtDUk2wBpMGQ/5xsnUY7dQT4BvKAiILvBdKkVGzl2pWVmYDsgn/ZapNQ4pfR3Ba3S
V0RTzZPbvT75WvYQAdlfzPsS7f+4M4Z4Hb6HesmCY8VF/E3M5wjI7uhgnJzILvoW+17NH4muN/vr
+sbki5i7Pdjt/ZnYBwtoU+B5mNnQ6Y+hgKzkS7gSOAj8r99NTuZbI+H0QZDNbmcerXmUjp7nb6lv
CMiGliVGqJr6CdEn/raMso38XLkrh4xfmQ8TElNSRLzIkN3uj45HcraMm/2Hl4WZMTBfHiuNeEKk
C840O0zaQj4mc+0/iJaYSE3Qu0t8N2jJgDawgHY28csgNlI44XZ7SM25hvS7v+hiVT/IsXkAuVat
I58ZunAqQvYjvulOtXRWn2+PRAopCLI+E5taAj/0FHcvQUVANqRkjzfxyHne3/wNu2fR0TZayut8
Az9Ez9qzeVOSGYoCso9bzeqvJxqjaV3y/El3PnIXJ4Q5IBaQ/YxP0MtLvM0hb0XOT63rY97JcH98
7DGilf5bm5P3U15n8xRpPgzI/imNPE4IInckeyzfKJn3bqyc5I1ED/NnEGTXMvf0Um0PZY8yt80P
Adlc66VJO/j+nGitjsLqnDN7XEs2SlLbAtrNd3xpHE/Qqlv6Ngl0wpCdad5W8oOsbNrWXkubG3SR
aNp3nJ/lK4Ehu+8k6zy+Gb2BtzknS5mPD25pXSha2lp+yOIf9fhsOtjXOkX/TF/mvxk069s8/ty0
rznHS2utzm/y0VbziyDkXAd2MlguJdMFlX/je/mAwjit8zbvBUF2v3VDo60iuiXQUmwJyO4x38O1
lZMC7GEv6t+5CRyBvptg+lRynT2Uc46m8RczHXztonb+b2UB2aPn+rtk93lI00YTrQkYdTB/s/OX
s4DsU1ZDTjvMqs47nFegvS8Ma2Pmz7iG3fEz/6js176R1jmyfAKysudkT99NFISiJUaOKwiyi6y4
rtrusJBd1bW1Udp1HfYzu+g/Tdn5muRxRDB7rlHmLCigQyIG7sgpU34UsWbW/V3MOIch+4p556hp
zTIp50ytEceuEwL++wHfvifpkM30h7x/G5BtzFcQP7BYP/uZAcbtYT2+ufzXGnXuL3mUFXpBHMcQ
9t/5+YdIbP8Md/OleRc4Jptym/mPObqRwWIpCdkmrOfRAdXNYO3yXhBkt51oHWWPCAPZiaZLtenY
+1HOExmdVeUboU0/mT41dy4nIdhNqr6uK2nrgteGm9lahuxe6xtT/yL+QNMe5hg4gOEePjrEOXgB
2bssOZ5gRYssUQ0OZbls+eXlc4y8Vxonpbb4R53D3wA3WufI8nm2ni5AJMt24xtcqcqNxlu4hh4g
n59emsbB5pssZhBkF4hVAKJEgOziisZh8bf+tzxR4YSdGLKh5TJxvNXnO4zaQ0sm6FxkyD4mDujl
WPbn87Tm/HeoVaVpk/kpmAFZc/0tHzIhq9V5yVzAeHTt3cdw/YlHQscsrPQ2HF8PCHTt30r9mJdC
mDnEC3hVgh8B/haObGTos1EwXdCa7476BVTGSRwxiSDIbjaSSlwZHrLBRrqCKasvXT5uZ2HrCjxX
uPMvw9dydrzYWozJkN15nNjQyyT9ccBL/E1t1WjaKdl0pIcOWZ8f8BZktUoPbyjQx8ne+pT4sm3A
93ah5f5AT3JsAbJSRbIpJ3c7xfiC1rSbDMiexZA9PuAsHEYKJwqC7HzrhAiQDflZbT/2x5f5/K78
8Gr5tz8Eytf9jTF6PjBzveGzrwjKMmTvNw7w3xbbqWCQ1oxTeAP9dRo/DZtmpAs2NLdqLchq2km3
fbw6X+9vXn1Na3eEfCuDR501xDpF/xSQ5VvMouUsXtZjPu8YeZjyEMkWVVHEmsS23buJbzhRLjJe
ddiKIet/7qVpvD5KfHEHQXZTCZANNlul39lR0/j84xmyf38XcKkfvjceezaYOO13I4+74RRuxpDd
Yd186Qn+zzWNn2YGfVf14sej/KCBI1nfzXyCXvyQ5Q6uff9PET7z0lm+MBrxXNYFj/pDhnWOLJ+A
rFSQrbt67x7rYe49fBvUhaM/XkwVuCCqZJJvFDtPWSFbnyPVD/n85nmUd11aJbNUTEtL8ycFUpr2
vH1ODrvwndyOIfuMP6XaIY8On6FV/816kYDuxBxaP8AbnJMNB1k+0rDrtf/j6JOmVNAaHSbf7f5R
KwWPqvd1HPN7rL6ltX7+lacYy2YRCxWeN7Yn5tE2c8GOddSpzwyeVQgdnBKk2HErzNm3z7qDHuOj
w/xtWpNXpQovMgsbVDxuLCNktbc569qAz0/fysn6ipZPCeuaD7z4GWiHUe+Je6QlTHuGrP7DMmPw
n/TVB9fwQhPBaaNcwM82uWEkyHKj+h1Hf8hpNPq8llaFXeOF8KNa/Tn9OQzpAplWF9TjYIAftuqF
v7v/4TxBZc6fBb6bO+8zltuUFbLV+fk9Rw5aTV6l8IQ5kPHBaxoTEy2epgzgBx7z+QBDdrqRT+Ud
jjAy22raTP+LBLiuLjccLY4VhWygu+TWP/kos5ZWmbN2L3HjQLEGNGrEUoVbjc1TOHbt5m9X5y+G
vbF3G6+KNLN7/sMObWTwZS4/ZFP5aeK9poau9tGBzvxr69lB2U7tGP5qEzFnWSHL0cAhcROTyEaa
HmKKBC0xwbJwUoNX8ij3VB2yB3tZzZJW68IN5nUrjFWjJNxL9DMjNxxkg/o79q182s/uuJhX+Fmn
6p/WiCGVTu4AslJFspU4bBVBhSicKVsllvz/bKzh1uu0x3y0WwR4ZYVs1e/4IQenUCt8Q/R1qtGn
pvWbMePlFC3x7i9mnG5VXVhAW2vokN3kvzl/mRf+sPNP4YjED94h/IvX7nxSGMhe8MWMa63uTuHH
0G21xM84geuPWHrMmPGmf0dvmDzPj/5G/N1yhXW2djp/+Vxp7D3CXaT7Dzi6kSEYG3yf66g0kQZP
+DXwzfYoLww4jhvy06Nf/dY/L5eyxGqCskL2Bh8d4bt7TZtKtLSm2BCl439nTK+udZkx41lj34if
R+iQLXjAqhvC9zi8rqVDNh0dbNVV5jzwu7wTDrJnfDHjIatdA17EMkjTXuSlJ3WsurYfzPjYv2NV
Ov15DiJZmSJZ8cjobcMnEjmqm5/I23fxSkNOG+il8gK+NxLf1GWFbCV+kvxtBY5lbuCf2HQ1e01h
jn/A24z1+8wqrU8+rePLkCNZusqsa77XWNkwIpd851ntOJv2STXeCQPZS/iBiBVVtNxGWU00bTz/
pN3ieCJz/n/WcbM7lmCqsZnKIfcP/G1glOcLqEBwgAuT/sOKxqbTfzMEY6WHrPY9a9JU1Sz+HYF4
ij+6gPLOMusSX2Xri8qyQnZ8Ph3VXYlv83PHm71q7xPNS9Xa8e8JLOhV+oWIB+V0AS2sajb7hBck
8PG6P/JvDayEFbueyGmEhexpTFTL+tWXka+Hpg3iX9j4v8zfDF7DbYni9KcB2WVOi+Ho+DKtk53O
OX/jLvnqLCPZqdXlO6qvzIdbEwrMFxWWFbJpPMDcKqzu5lsZVkavSXdnG78Cv76AVrYxTCF0ItIK
ArKbO+h1NfmCOCB+BZb8Hf96solep/XnH4kNEZthINv5CO0ZaDTTrsuipbzMsTE/Cv5c5O8Y87cc
pTz9VLOJ+LjZR0vEFwuXq/gdNfeaSb2LDxPNEFLzgvavjOVh+o7DfzIEY+WH7JP8zcYRH5f+nMec
IjbEWucFjcSWpg07SFmCaWWG7EiOhPuIDmryF+OipmKLH7HtI9+lXPU35d5t1Gin7aB9vPxVQNZK
Co3mpdv3CYNfkEtHzGx8ndn85StOCRfJNtpIR0ea/Z25l/7lu6wq/FRgmfmg7lxeUj3BPCzPByAr
VbpAG8oOuG5sm2ZnPclc2d9ad5RRXDd3CKOpxROcqDS+8MsK2eTX+dc0It+g3ci+Pu/celp6T/FW
O/2tWQ0Wc77zUhHUtHgti7KH8oaALG26unFigws42DBfG9qdL43ll/BtZ+2bGdU/6ZFFGMhW4oUH
m24UIK936x5Go4hLr+THzL9f0ECr0n0Kj/8sx8ohpX0WHWhh1FRkDtB7ozqmtxg6nXWxS+QkuDRe
Q4f4/lKKksESKgDZTvx1vfn6DsedeQ8v3sjVcaj1OcK39hc35hjy9u38Kzw9a1PWSJZ/lps/SjfI
APbPFSMbaRU7v8hpgC/Yk5Ju5ITtM8fxDUu1URwsfMxVOmRzp/ZITevyHEtmvKO9IofbOZM6pGlJ
A9juWaeJ7sJBNuVeDo0fbshHa4znJ16P8E2Z1ou/OtZkHKuldXyGnzTMsoJk0YUcBZCVC7KVp/Fl
m7vL+HGWeRNU8UOuO7x18Yod/Dn3WN1xygpZ8cKOLL7H4pBwErP1SOaqzXxh0NfixzSaJt5xn71p
4Re/i5EeE7fyDNmf/6b8beszmY70nplxu8PH7bYvW5rJn+tO1k8NA1mtE1/UBZlLv1iwpYCdX49E
kx/N47cpbF21kS8Hmi1SziEldTHlWk/5+jDKKXvPlh2MWNo9wUwsdMql5db9Z8ipDuxksGAKQDZh
EktZsHu7WOJhfJvyfcR9vJ21bekyYcLVbXXllRWypzMq39J7SLgtW/S6agN/p9LvrURdzfm8uf2v
r2av50N/iyqG7AF+drpvo95qhxFja915JRbt/ue3f1jKght1Y4eDrNaAH+PRthVf/rQhlzMDdfVh
r+NvjJxtq9eLUZcbc9HrZfnD7yPlgnQBK8GfTXLUNg3eEvgRZed94mtalBovWXV57x9vVN3HP9hO
580LOSCxmFOd3fhy47D1V7zT5S9+fhUoV3PP83S4Jd2SKYbhcuA183F9ws3CT/Wy49n/b+864KMo
uvim0Akh1NBLqFJE6R2kB5AqSD0QCEXpVVB6FRAQ8RNBAQWkS5XemyKgKFKk914CAdIu872Z2b1+
l8vVLe/9lNudnZ157z9v/vv27eyGESqQ7Fc1TvKi599JT/UDRwN9cjkoJnbrQbBZTOoGjo6k2+0u
SdVeLmdTDsoG0NlE5eUS8X5VOov+joU3zKT9Dn/zivDS2HoW2tAD3Sy/0yXV9sOvjum30w89p6zL
0Llww8Hk5Vx+NYUwcTys9OCyT8x2wyP+aDqEteHpGL+Hgp1rpusQWLfd4ayWbEv8Jx+QbKzIlR/9
y9skiWvoggOQar+LJfAwoDYtAJJ9VP1ruJxTOSRlhk3qXRtKEwig4l98GSHbmQt1qcML9SjLMkna
UpkdEoROkqfoNxoUFw/J4QdJVl6RLPhE5Sm7Lj84v3MQe2Ar+kilCYevPb58YHIdMZ4TIiIjq9OE
ZXhkZDXpnju4QWRjeiNlKuUiI2tIDxRYefbIyMgWIu2WHLb9yt3T28bQRKso5T7fefPF8782TeDx
KY1kvxFy9tpw5sK26bD8xiBvjdx15fH13+c2k27OsjaOrEsTDUxqR0YWYhuFBm289Czm3+1z64pH
4Kf4oK2X7v29fVwlyRbjIfg8wjNyis0lWpiry49/3b5/YtXEZgYTAreROJrGkIXo2FyXP8kKQumx
2y48urh/nMRKFL7Sn+658vjab7Ob8GQ3JH+aRNajQxjWOPK9DBLAtSIjxeu6VJKncWQkjyClkjqR
kc3eEnfy9tt48d7ZnVNqG4Yse8fl/z56dW3Pog4sKUFJ9mnpoDrzjl8+vlgnuQ+cHdbuh3/u3/9n
fU+RnYWAaiZ9l4iMrMQz9Ln7rDr/5NXlXd+2ETP2cG6uqHUX753bNaOuNBck1WTx2xojWVmtLmBO
kS40LFM6C/dIHxoWaiAxi2Ou76YNzZyRu76hjXShWbKESDE0I1mYLmlCMllUE0DJ0Aw85DCca2Mj
TSZoLq15vbSZModYNieemmoziRODIlqSKiRzWAbTiQPvjB02TF8b3fm0SDkkC4+6MoVlsvQfNoS2
LnVuoZgGRtfce1OFhGUNTScNGyVZeP4VmCE0g1Qk9hccEpbZ6Hr2lUidibZnWHrCKqamvXrcFvs6
pOQIJ9m/UnKK6urKaXWB3MClkazFVPCuiq1jyDfGCMWqrzkkrpVVob8KlESy/sLIul+RZK0PqLYE
SVZ26QJZ+ZrPSTZoEYkWl5HZAKLgNfKjaWBro4oPi5BkXQFbeyTbhqULMJKF7FqUKx6j9nN8TrJC
gRvkf/ZQDehPnonJYntVfFmOJOsK2kiyrqCm9HMwXWB/BH1PskJnveFVNEu98l4kX1iW+XEfSdYV
8LVKsn+6ApZqzkGStT+Uo+BPfvs0JysIqXeS1Xa6HEsumD/Xtq+4L44gybqCcnFY9F3OlRMVe05b
li5AksV0gW0X/ujihbHmj3Ft1/NkafW96+BVJBuSevlB2SzfouohydoYpGSLCv59/jfxLdhk66qj
AifZ0+owxkUrMJK1D1xIgQKGZav2a3n4SHBa27welFY+D72oyUiyrgx8cN58eRysH3GlSZmf8wGL
ZJFkMZKVuaPKUT0kWTmOivx0QpLFJVzy80qFaIQkq5CB8rOaSLJIsn52QeV2jySr3LHzpeacZE/5
skvZ9YU5WdkNiTIUQpJVxjj5W8t2LCeLJEvwZQR/u6Kc+s9R3ZlHbEiychozX+qSHz6+4Lxwkj3p
/AkqrImRrAoH1T2Taj0+NbZwso/AkWTdQ1m5Z3d8sKtHdqc/R9OeRbJIshjJKtfjvaB5Dfig+YvV
H/APpNttH0nWLjQqP9ABvnF866t67JPLyZvKSfaP5CuquAZGsioeXNdMq8G/KX3hh0hH4SySrGvo
Kv8sIFkqv880fEzekU0fskgWSRYQww/EOHIUbR2rAX/bhMnzP4YXspue1bEqSvhot7ZGz/vWiiQL
fw1kV9ec5h9LttE5kiwu4bLhFlovqimRLNDosx/bWP69CREeJFmt+omBZME/rs2un8kxDkiySLKO
PUSTR01JFubR2UWNbb3oiySrSecAo01JFv7w4/EZJn/ByRoTTrInrA9oqARzshoabOdMtSBZ+KuP
fwyMsErPIsk6h6b6apmTLFyGn+7oZPujRtR2XhtJFnDCnKz6JoOrFlmRLPjHg0WtLL6ziCTrKr5K
P8+KZME/bkxvYPlH1EQzee3flW60W/pjJOsWfGo8uWYCzBpr+efb2qbhrI7VwAdfavQAxzbZIllC
4k5MLWPrKVhH5idIsgADRrKOHUtLR+2QLCGvj31c0pCeRZLVkk+Y2mqbZIFEXm7rUMi0IttGkjU8
+PrIChws0CoC1W1HsiwieTC/RWaOC5KsVv3jQ+YJtv85P7leBnNcOrGKGMkCDNunTAOZOnXqFFEm
g0wSZSLIhAkTxosyDmSsKJ+DfAYyRpTRIJ9yGUVl5MiRI0QZDjJMlKEgQ4YMGSzJoEGDBooyAKQ/
yCeifAzSj0tfKn369OktSVRUVC9ReoL0APlIlO7du3cTRQfSFaSLKJ1BOnHpSKUDyIeitG/fvp0o
H4C0BWkjSuvWrVu1gv9bcmlB5X0uzUGagTQVJRKkiSiNGzduBNJQlAYg9UWpB/IeSF0udajU5lIL
pCZIDVGqg1QTpSpIlSpVKotSCaSiKBVAyoO8y+UdKuW4vE2lbNmyZUQpDVJKlLdASpYsWYJJ4U4O
SBaeJp9bUDUtzCMdmzx70qNoDQE+8mz4bfzz+q9JJU0XV3OS/c2ceTW2J+ZkbaAl36Ikz4jeI5Lo
GUnwiMR7QOIcciz1iviDvUsL7Zl/RP9xEkVbCPxxNTlmeL3hwwgDjSLJGtIFyeGGxxEBUwQerl1h
uovbiIAZAtd+bJ+R82xnVn7cQLpa3FBiJGs2nLiDCCAC8kMg9vI4tuiPk+wxLXKrwWYkWfn5J2qE
CCgegVfHxrClBkiymC5QvDP7x4BbU2b6p2PsVREInBvNno5CLNeF6YuRLMBw6NtFTBYvXvy9KD+A
LAFZKsoykB9BfuKynMoKLitBfgZZJcpqkDVr1qyVZN26detF2QDyC8hGUTaBbAbZIsrWrVu3SfLr
r79uB9khyk6QXSC7ueyhspfLPpD9IAdEOQhy6NChw5IcOXLk6NGjh+H/o8dAjoP8JsrvICdA/hAF
nmKckuT06dN/gvwlyhmQv0H+4XKWyr/25Ny58zbkgrVctJD/rOWShVy2lis25Kq5XLMh1y3kxo0b
1+4nN40fbO2YU3xdUv/qNYq2EHgVl5x/3Pm5WVbDrTKSrCGS7WEABTe8iUAAl0CQIFGCRUmVKlVq
SdKkSZNWlHQg0iKhDCAZRQkRJVOmTKGSZM6cOUyULCBZRckGkl2UHFxygoSLkgsktyh58uTJ0QY+
2m1f9EemV6QI6ViVvzuwVXD4j3YQ6PC1feeAI28OflbSdAYhyRpIFt/4MnUMbW/XsL+GK+nOrFri
p+04yW7XNlSatL6NfZLVXxpbWVxVIEHTldU+Ku1q8he/XaDJYXdkdC17JHtva2fj33biJIvfLnCE
pDqP2X2t9sbqltYfl+Uke0SdUDhpFZKsk0Bpp1otm+mChE29S5ligCRrioaWtm2T7KsVusK2UOB+
giQLAT2mC2w5iDbLbJBswtU51cVvFkiYIMlKSGjt1wbJxl+ZVMHimwUSKtxPDku7mvzFSFaTw+7I
aCuSvbdFZ8GwcDqSrCMM1XzMimRvrP3AOk0gIYAkiw++JF/AXwMC5iSbuLNPWcMhkw0kWRMwNLVp
TrLxG7oVd2R+N0IFI1kAAdMFjhxFW8dMSDb+yrxqobat19G5Q/DBl2101FxqQrKx56eXt1hNYGk5
kixGspY+gfuCgWRvb+phnSaQAEKSlZDQ2q+BZG+t7WQnEWsCCSfZQyYl2tvEnKz2xjwZiznJJu7r
+5ajikiyjtBR8zFOsvHbuzv0DwmB7vSGhyDJAgiYLpCcAn9rE5JwaX61ZG4DdeA1mC7QorcAycae
m1k++SCWgcNJ9qAWgTLYjJGsAQrc4AjUvbOpr/Hdc3uoIMnaQ0bt5Z3vru1uJ1Fvw3QkWczJ2nAL
rRdlLuEMAkiyzqCkxjrhTvmHZPlH9IaHYCQLIGC6QHIK/HUOAR2dO7i6wDmwNFwLSRYjWQ27v3um
I8m6h59WzuYke0Ar5tq0E3OyNmHBwuQQQJJNDiE8ThHoQW94yAFNg4Ekq+nhd914JFnXsdPSmZxk
92vJZCtbkWStIMECZxBAknUGJazTkwayBEkWQMAHXzgdUoaAjs4dfPCVMtA0WJuT7D4NWm40GSNZ
Ixa4lQIEkGRTAJaGq/ZiF2MkWYABI1kNzwOXTEeSdQk2zZ2EJItLuDTn9J4yGEnWU0iqux0kWSRZ
dXu4F61DkvUiuCpqmpPsXhVZlHJTMCebcszwDEAASRbdwBkEoggVJFkAAXOyzjgM1jEioKNzB1cX
GAHBLZsIcJLdY/OYVgoxktXKSHvYTiRZDwOq0uZ6s4vxbpVa55xZSLLO4YS1LBBAkrUABHdtIoAk
iw++bDoGFiaPAJJs8hhhDUHog5GsgJEszgSXEECSdQk2zZ2EJIuRrOac3lMGI8l6Ckl1t4MkiySr
bg/3onVIsl4EV0VNc5LdpSKLUm4KpgtSjhmeAQggyaIbOINAX0JlpzNVVVsHSVa1Q+tdw5BkvYuv
WlpHksV0gVp82ed2IMn6HHJFdtiPBrIYyVIQ8I0vRXqwH5XWUbfR+OTxI/yK6RpJFiNZxTir3BRF
kpXbiMhTHyRZJFl5eqYCtEKSVcAgyUDFj+kND9khA038pwI++PIf9oruGUlW0cPnM+U5yW73WX9y
7AhJVo6jogCdkGQVMEgyUBFJFtMFMnBDZaqAJKvMcfO11p9AsoCQX33draz6w0hWVsOhHGWQZJUz
Vv7UFEkWI1l/+p+i+0aSVfTw+Uz5/jSQxUiWgoDrZH3mdSrpSEfdBtfJqmQ0vWcGkixGst7zLpW3
jCSr8gH2kHmcZLd5qDVlNoM5WWWOm9+1RpL1+xAoQgEkWYxkFeGoclQSSVaOoyI/nQZAUomQrfJT
zIcaYSTrQ7DV1BWSrJpG03u2IMliJOs971J5y0iyKh9gD5k3kAayZIuHWlNmMxjJKnPc/K41kqzf
h0ARCiDJYiSrCEeVo5JIsnIcFfnphCSLJCs/r1SIRkiyChkoP6s5CJIFmC5gIODLCH72RcV1r2N+
o+2/3aS4QfODwpxkN/uhZ/l0iTlZ+YyFojRBklXUcPlNWSRZTBf4zfmU3jGSrNJH0Df6D2Z3PJt8
05lMe8FIVqYDI3e1kGTlPkLy0G8IkqyAJCsPX1ScFkiyihsyvyiMJIvpAr84nho6RZJVwyh63wYk
WSRZ73uZSntAklXpwHrYLE6yGz3cqrKaw3SBssZLNtoiycpmKGStyFBCBUkWQMB1srL2VBkqp6Nz
Bz/aLcORkZdKnGR/kZdSPtYGI1kfA66W7pBk1TKS3rVjGLsYI8kCDBjJetfV1Nc6kqz6xtQbFnGS
3eCNphXTJkayihkqeSmKJCuv8ZCrNkiyuLpArr4pe72QZGU/RLJQEEkWSVYWjqhEJZBklThqvtd5
OKGC6QIAAXOyvnc/Zfeoo3MHVxcoexB9oD0n2fU+6Em+XWBOVr5jI2vNkGRlPTyyUW4EuxgjyQIM
GMnKxisVogiSrEIGys9qcpJd52ct/Ns9RrL+xV+xvSPJKnbofKr4SBbJIsliJOtTt1NHZ0iy6hhH
b1uBJIurC7ztY6ptH0lWtUPrUcOQZJFkPepQWmoMSVZLo+26rZxk17regArOxJysCgbRHyYgyfoD
deX1OYpQWaM8xT2oMZKsB8HUUlNIsloabddtRZLFdIHr3qPxM5FkNe4ATpr/KQ1kMZKlIOA6WSd9
BquJCOio2+AbX+gPySDASXZ1MrXUfRjTBeoeX69ZhyTrNWhV1fBodjFGkgUYMJJVlWf7wBgkWR+A
rIIukGQxJ6sCN/aPCUiy/sFdab1ykl2lNLU9qi+mCzwKp3YaQ5LVzli7YymSLEay7viPps9FktX0
8Dtt/BhC5Wen66uxIkayahxVH9iEJOsDkFXQBZIsRrIqcGP/mIAk6x/cldbrZzSQxUiWgoCrC5Tm
vP7WV0fdBtfJ+nsYZN8/J9mVstfTmwpiusCb6Kq4bSRZFQ+uB01DksV0gQfdSVtNIclqa7xdtRZJ
FknWVd/R/HlIspp3AacA+BySSoSscKquWithukCtI+tlu5BkvQywSppHksVIViWu7HszkGR9j7kS
exxLA1mMZCkIuLpAiQ7sT5111G1wdYE/h0ARfY9jfrJcEbp6S0lMF3gLWZW3q2OTZ6fKrUTz3EUA
SRbTBe76kGbPR5LV7NCnyHAkWSTZFDkMVjYigCRrxAK37CPASfYn+xU0cATTBRoYZG+YiCTrDVTV
1yaSLEay6vNqH1mEJOsjoBXezXhC5UeFW+Ge+hjJuoefZs9GktXs0KfI8AlIsgKSbIpcBitLCCDJ
SkjgryMEOMkuc1RF9ceQZFU/xN4xEEnWO7iqrVUkWczJqs2nfWYPkqzPoFZ0R0iySLKKdmB/Ko8k
60/0ldM3kiySrHK8VWaaIsnKbEBkqs5EQmWpTLXzjVqYk/UNzqrrBUlWdUPqFYMmIcni6gKveJYG
GkWS1cAge8BETrJLPNCScpvASFa5Y+dXzZFk/Qq/YjqfzCJZJFmAAT91qBivlYmiSLIyGQiZq8FJ
9geZa+ld9TCS9S6+qm0dSVa1Q+tRw5BkcXWBRx1KS40hyWpptF23FUkWSdZ179H4mUiyGncAJ82f
QqhgugBAwJyskz6D1UQEdHTu4J+fQX9IBgFOst8nU0vdhzEnq+7x9Zp1SLJeg1ZVDU9lF2MkWYAB
I1lVebYPjEGS9QHIKuiCk+xiFVjiugkYybqOnbzODAgOsqmQvXKblZ0vRJJ1Hist15zGIlkkWXcj
2ZK1atQqZM+Rwuo1rpbG4mDBho3LBkBZ3hq1ygWbHUtXqVa1ULMSV3bCq9d6x7xdV1oxnlOgUdTU
3oKQoUqtKhmNpR7dKlizZplAd1oMn7ngbZvnB4/4torNA+4VepdkM9WsUbMidRFbElihcYPclgey
1m9cIZUgpK5Qq3q4+bESNWsWNS9xYS9VuVrVc7lwnt1Twup3nzQiWEj9bq1qOe1Wcu9Anhq13gFI
/CtIsh5ZXRBygujJJnukVieJXLb0zk8J2UBHf6SenAgz84Fit8iL2mYlruz0iiVnsrhyou1zWlyE
y9AZQXj7EXlU3nYVt0unJZG9lteilDQaPJX8kdnshN4rV9ZgBUPICS9MY++SbF+iT3rxlpk9xp3U
RwnpYdzlW40JOQxjnvsyedPT/NiqpCT3H25n/53Ef2zerlt7tcAG8iS9kPssed3drZbsnzxIT/70
wsjb79DWEU6yi2wd0kyZB9IFdV6Bv9wraQeymi/JPxahhTAsifxMSRbI9jQj2RZDhnBqLX6PvK5j
pyXni3snkn89R7IRj8E+8juQ7DPyrILzWjhRM+yTIX05ODMI2e8OyVaNIe3MOqwYTQifvZnOk8lm
hzyyo6OgeGt1QfqDtPGxdhRNvZfE6yyPNXhDdlOSvU4S+AOG94YObcoSKGs88RGo7CdJUn/LPl3f
z3yBGngbSPYCibe6YLjeLpyZJmrwAD4ZhxDyD5KsW2B65mT3STaIf8zMInwwaOeIZMcSco6R4TZC
5rEzSj4npJ7hXFc3ouLJP54j2b6ExG0c3UkQ3okjcZVc1cnmecXfkKe8xTmEHHeDZNPtJMcymHaR
mdJUZ17Smzz3rNq0WR1lCW+RbMVE2vgfZhYZrXNEsnkeENKPVf2WkHWp6dYmQn42nuziVvY/SOIn
Lp5r47T3E4h+1+jeqYQ81z391Dn0AYnvwrocScgly/jGhi7eLZpOR5JgJAsguLG6IN85EhcL083O
jHBEsuWioloxZtlCyFw21pk7RX1kmVxIuRN4lmS/hFwBS21l1UXpsqVcGwdnFH9FHldkxytHRTVj
cZeD2g4OfZJI2psdnk9dWyTZ7P+SXXZGx+ycFO3oaAfeItlvCHkJ/7W2rZEjkk3fIapHCXYatLGG
kWz9qCj3M1AeJtkhSeQBy+6k/yCqR3HbZrpYGnqPxPKBLxMV1Tadi6147DROst95rD0lNuR+JPsh
cNCyJBJf1rb5jkjWcIaBZA0lbm14lmQXEbLZLXXsn2wkWft1nDmS8x/ydw7Tis3gsmcgWWFGUpI5
BZtWdXFbRzvwEsnmukzIlDuELLb96MsRyRqtMZCssciNLQ+T7DhC/nTrOad9U4wka7+OD49AHgwE
SRZAcCOSBYJc+s4jQibZHjmnSHYzIXNsn+5SqcdJdqVLaiR/UlGIZD3xKC2K6GeY9lb4T/IChkSM
ZIXy98lR99dsmHbg3XRB71jysMhiyCXZvtl1jmQXELLa3tNYc1Oc2fM8yR5y48bFkcYhEMlCbksu
wkl2oVzU8YsebkeyZV6QhEhhH8yIEDMDMjeK+rhVRIBgQrIBeVv07ROZXTA8+EodEpI+QMhQKN9e
QpYUKgyxWGDGkIwG5ysUNfenxWPrpJfazVI4IqsgBJXtN3Fs9yImQU5AoTZDZo39qJ5heZVtkg16
Z8TCZVN6lJGag9+c7WYsXTajlSF/m7ZQkTxBQkD+LmMn9i/PZmhwSPqlhKxMFwJaBGYIySiFH4EF
2vXvWgUKg9OkYQrniIgwxJIhERF5qH5BeSMKQjqkVNQMMczPVL/PlGn92+ZjygdkL1j/DXnWMl+h
tPC4IiTEcGeXpsbY736a37eQZGJgvoiCcDBTsxFThjczR5nbAo9RHpU0MSv1JhI/7DcjyQo/E4vH
YiaVXdzU0QDFO5Fsarhu/y+gDSH6pmbKpSrXZWDXymmEVKYPvnJE9u7XoqAgiA++6BhBbidtwTwr
CNlWvHDuACFtSAgALEqerrOWLZkamUncTVUgIj9Uz9Hu08mD6xlrCUJIPRipAR/kl8bbDslm1325
bP6QBgYXFYRUlcZ8u3zBAMN6vIA8EYUgV5Oh0bApI1vxZFNgxrRTCDkQGgLlor5cnVyt+n9UEwY4
KE0a6nxpC0cUYAkP2A4uULgw0y8rmwQh74/vzc8JKt1xzOyRusosoSUIWQvDGpi4IfkKw0WVTy9e
Lbj8p/9bvmDw25I9fC4Fs7lUWHI0XtWz/yLJemAJF7jLhXTCx4S8bmsyOjkmXo/T6+OfLsxTybC6
oOg3T+P1+rgbk8MGiKsLBkdHH8wstHz6Ep5zxMfEwLt3RS9E363B2yk8N1pP53HsqZaiZ4yNiZkq
vLvtFRQnvlxsyI6+/fXj+CQoir04XCyzSbJvb35Nm0t8Ma+EqGiWEffiaVH8jRHipKvxJOZA+jyL
nycQkvR6J40xGz17DnXin0fvF4TS16Ovl+PnlvzpRUJS4pvfPhSG3rjZi5b9EBOzRHJWXUzMHur0
OY/E3CiTZvhjPY8pcwz8JxZ0T4p/8sM7cDTNopewLiPp9ctHNQVhfHT0FpaeFgJbnnhDtdI//1ZM
1mU8EXOvaoZ+l+OgNO5iB8NFiHbLpC0hu6Rt+js6iXyb46QJybYnZIdpBQ9s66iO3iHZkg9JQnOh
wFXzVQGBHxx+BZi/Pt4+aDeRVhfkmnGf+tnj+eG1+OqCXH9HP4KVBzVvvoRhS4iJ2Z5KWBod/Y1o
cPikx+yRWtyFrpxRI/6LORuedexDqJwU+8d7Ei4h/c/wkXq6TEzn2iTZLKPu0OaSYo+1FTlOaHSQ
eVlSzHLxuhq0J+Zpw7Rdz8eBi8bfjqL13r35HLI5CdHRMHHCT0Q/EG848s14Eg8+9Xef1J2u3P4c
fKnqy5grpUWV8l+IialCtyfFxEwUah2PIyfZkfd+iQFnJYmvD3dnTA+HoaPYly8+FoSPo6OPihf+
+ru5Wq/WiDdO42NiJgu1tvO5tAhiF28Jkqz7JBt2mpDRglDgKSHLjeNU9AQMPJPTIx6LS7gir4lF
ZMusOL6EaxQhp8KEdlL5KkEofpe8qsPaaQhzTBT9/zh5wlfTvuj1UCrdK94AN4b7Ykn2FWLn2iLZ
jg+kSuTG26xWof2GErK3GCuqHUeOtPhXKr4L86S5tPMnLOF6Sp5yH217WyxOGDyTkOH03JXwDFsi
2R6EHKOzKfw0eVj7a1qVPu7Nul88CX7utgKShVOYJMLkBl/kS7jSTGc0wA7cbE5bFkLOkidtV4mV
SfwgVmj6z49sDAwldZ6RM1kznzIh2fyv4P7bcNwjGzqmz06PtGXRyGBC/ob7HQi/H+czHAqaQcmE
StzYPUQk2bfOsBL45+inz/kSrmskvpcgvPdCPHAklWBcwlUFnFWS9Xlp00XvkPPND0hlz0WWDTOA
TchzHjvYItkC+6UTCRnKxj5wDMuFs+IHHzLdg46RNx1/MFQcB4WV4NrK5FF6Idd5EtudVaxzQar0
9acJZC60V4OQ+yJVCwVuEVKd1gNHmdLkCVQ9Rff60QuvKD/Qm5xZ0t5QQaA48iVcQxnFskNPujJN
4W3X6b0lkMhuMcigTXpYvmC9fuvhVpXVnLvpgvqx5HUFuDNZDctF8kumh8L9Hrm6bODE/YkkOpaT
bNH/oOzvbz+ZDfPiaaKBZE+GCaUnTrxEyIkpU9sByd4hMXVoMyWh6PWPPavUGPo3nPc1cwwg2X+j
yYPvhwz8GVZ6EbhWg0ScJ+TR5JYVavbeB1Hi96yiDZJtAhz7YlGr+t03wVzdRX0qdC1Ei9uH167U
eQ+cyN2sdiy5e5PE/DLm4/9dhh5+CBKKT578J6zmnTS9H5DsE/KEkWzju6DczjEjlt8ir28kkWFU
D7g7Xck6h20g2aOMZE+R2xuSyJunj9sIQsBXEHCs6ly9cosF0YRczysEfzD12wTyesmkCYUEAR7C
7mOR7AhQ5uKUFhWbfge1HlSmTYf8Q16dIfpTU/pOPQZaXSlAC00k81lCDEEY3Pv+TqLbCNlNSTb9
bySuh8kZHtjUgSbeiWTT/E4IzeF1gpEC1EXpB7jE7Bw/aOV9EveccJLNvhNUuLRkwJRDSSQ6npPs
VRIHJFvoswlAqOemT+0ZKIBrLmGN5IZLf+L6QdWr9DgK0d7PFO6it8njyyR+17i+s6mfbeMX7tng
GWu6VK/8/nzws9sMbhskmwHYmxyKatBm+n3wrTq0i14QEV/7om2FxvPAQ6Ib0qKgoyT+L1iwOuPj
zw5Ar/fgNirv55MOEfLf1KmjUgm5zpE33Wm9YuDH8YfHD10Mjnc9gcwBX6qRRO4ZSPamkWTXXCH6
Fw9/hZOaAtv+N7xh+XrDoIukblDSeNqsGJK4edLkaoxkzzCS7QK3Rrdmt6vQYBYEBy/eh2oCkOzZ
F+T+4sGDVoGfkT60zCuCJOt2JBs0A160oZTVGUbKsOKmAzjp5rzgJkEDIMJlJBsIq2lfz6RZ00yz
YMhNSRbKgJTnsCGWSDbVTxBDdIYWBCEbxGmJ9ekWkCxQUVHYCmgH3r+X5q2EDwm5ye6jhHTzpSu3
NcmGwvy6yRoJHApztyWcOAycejzLgwaPhvhjIO0MSBa8tibdfOscIQ/ZzdYiQr6BAiPJZgIWuNo4
ENQovJmqxCJZOySbqCe7moangsqZnxL9GH6r3xLy2CxAKgYPvuASBSKRbE0A7CBPEzS5AwExRQxI
FubGUHqDm2EJbFLtTaXJM7OQ7xtCpgrmJBsItOH+W0+mfQo6UMQ7JFsjgbyhQ5UV7N/Fxhh2sl+E
q0trink5ugKYk2wU3HQvpjSSagRlCvYyAidZKAMY1tArnZFk4abj9RA2AulnA2V3hWNAshAudoR2
hdzbCHnD7nFCHpKkcbzjZtEkiUWkNki2P/jlV8yBKl3h+ZoIaO00p8V3gSvPZYZmgWQJeTWBjmOq
uYmE6GBDEMbCihXaqYFkgyDz/6wzVS7nYqjFI1k7JBtHbg0qlY4qCCeJN2+5DhOyjCVwMxkefA2G
dT8Unfyg3r/czcrCbdo16tVAsrCOuAhsBXwI2O1kysCexwVAB8FIFkCIchHcvHCBHUfPLQobq5lP
C0L6U4RspfcuIN2hcfrGV+GHhHzFi+gdjzXJzmUHJZKtl0hiR4jV6Y0vcwJKsn+Jq2ihjSsRUCEQ
BhEohUnZJ+Q5TXYK1iTbHvJU7XmtNNsJmRwg5IEJ8YM4hSkH/VcQDlOSfVGJ1/vwDUmsRzetSBZ4
/XkDXikDnUKOSBYIml6DQN5LIH+xWQDbcFH5gpYZl3CJJBu8Di4ULHSCo60TSVxf+GUkC7d/VPLC
DcEEvmn4FybMbh6C0aK+8WQbPFExi2Tppeik4fGe4UR3NnRguHdI9nt4DYF50ndwj1JO1LGXntyH
4IxKjksiyYaeN/rcAFDGmmQZ3qvFSLbkS6Kfya7b8ExpB6yhCuMkmwi3GVTgiRHpRjdqxZGz9IpG
ZQMhX9Jfa5LNBWpsF6u1goA3rxAwHtyoNK0NUvcN0Y+CX0ayE1mRELYP2JPR2TggWUb3UiRbExx+
MK8VBA7nkGTJ5Xd5zQxHSEJDvkmD6LNgENyhGdbJSiQ7CuYKuwODo1VekCTqP5RkT4tOAymGS5R4
vSI8f/E/r7StlEbdTBdAAHuPjV/gJrg/EtmhWwKJhWc5TOibR5RkgSBvFhbLSkB+ib1WC6MP6QIQ
IB1zkl0GcYBh3D9NIi8LQS1oQ0/DDyq1wa0pG6aZdnx3XVYC94hXSXxVum1FsoHQwSlgHiYD4vTb
Q4WBSSRO8jyhCgTGreAgJVnpUpDtAdF3oCdYkmzgVkK2SFf+HpDtckiyBspsefAoq0ib/JbfEFuT
bAm48xxCa1DJeJyQtcAKlGSlV5MDfgHaZtOT16H/LoF8uEQKQunb5P47UGhOsg0JuVPKeIYHtnQw
S71CsuFwGeFANYLbazFfkOOYeFmimoPbsEi2L/gFD9Ag/gOskiFZcJ9HkgsK3eF2CkibRrKrRexS
nSZkJG3//QPHPqW/VOaLtwDWJAtORiSGCz2vj24t5IWMw0R+GiwHgFTGLvASSrJXqPdSgQB2OYt9
x1mS7EIgfXYEalV84phkE4eyxiDnv/L3dVLWuvlLcis7Lbci2exgF7uks7M2EgJ5akqyidJCr7qQ
TCgqNunxH06y33i8XSU16CbJ7oI8Fjf34wS45eab8MRiJ8sv0t3ejCACIWc0nx+FfyFcc0yyaeAG
Z6aheukYkkDpDmbJHTEsFEokkUdiNGmoB34WV4XuWZFsJoijF0j18vcc2CUDvYncIwWWQshJ3h+Q
bAJ7vAB1A26QpI/pOZYkm/kh0Q+SGguF+y9GCSts52TJZ1JNk98s0N23dN8qkn3fJHgThM8g2oBL
DSXZr6XTl0A/BnB54RpY8STG5EK6TYTPQXOSraUn0fSa5DnRESo7Pdeg1FKreBLNrwe5IRv+K4+2
KsIlXAxk4Rb7JWEkC7maX6SLHX3K45hkA+H51iqpE/Y66zBGskntpEKIB2ZI2+JvKHD393TbmmQX
w413NrFaUJOBn7xLH1S9qCGWwLN9yK1D1EFJdqVU2A8uz8yDx1mQbKozhMySagXBrGIPvuykC+7Z
uieZmkhu2ibZd/Tk9XtS2/TW8jpkCYBkb9IUBpVS8PqZdMfASzz4L5KsuznZCs+J9C5RrjvwtIfN
/lS74cmlYZiaJdEoLOdV8VaMlcPduWOSfecZ0TczNJH6ASGfwx6Q7BHpal80njxtaqxRsE6XMUtv
wJNn2yRb/Q2J/8BQm27QvOpYYwnk4+h8BZJ9JN3vCRfEoNKSZKu+Ia+MhLU/GZLtaOwEtgKyl289
YM5vQE+2SRZCnd+Md/4fQLhejJFsEiNy2tT/CFlvCFtZ26l3EDKNbcE/kwhZwa4d5iQLn4vRSwG/
VNW9Xx3Y4A2STQvZgmX8KhIIt9+xVZmagMR/UswmpIOPqujgJgaiW+MlDGo4JtmclwjpbbQZwruF
jGSNBAQ48vspWisgW/lWA76ELuyQbLp9UhLU0OYnkPqkOVAu9eArWxBnU5KdIpX1hOg2M90ZZ0Gy
kCYzSbUvc0yyv0vN8d90JRr0mrD2BbCmbZL9CELpPIZTqvDLFZDsIcmNSiRKL3cbanluA0nWXZL9
Ap5p7li/gcq6p7BqgMWW9PbkE8MoVX9BSbYS8GR9Q9lgfTIkG/mSJBivrcH/8sQYkOxOyTFMSLbU
oK23Hr+Mg+lgl2TbxpHXUoTKtYAvLph+Lg/c+iDchAPJ3iouqWmPZFvGkej8UiUBzmQEuMJ2JJtg
vFYIOT787vzD52+SmKY2STYIKHSHITgTIpPIs7KMZBMNj9mtSTYzTGN2mws6ffCcnMnNdMsM0TIN
/7mUukcIXw8mlbj7q2NWeD6ShUWy5Mwa5lJrT0Afs5iiIyGmzyCpnHoXoSSbG4awm1Qm1HudDMmW
AB4zXpYFuJtfy0g22uAYQLJzeHuZ2317zjBStiPZbIDvdMjlmMg0uEIabo6EqrBypCYn2dFSJSDZ
nTZJtsZjQowXbmBAR5HsZqk5aL3K+AP3nrKlskn2SBbuh86kN5xSDr5yBNMUutgu6VoiAUnWgI83
NtxKF9Bn9mbCfLTYNULaGnQtd5+SbJuXhLxlKOtqXCdrOyfb/g2JzWGoHgy3jTNhD0h2K49xYHZI
kWzIcEhjUok5tfaJvUi2RyJ5WcLQHt0oCqF1pLEE7v32cZK9UVQqtUeyXRLJU2O0OccGyfY2LuEy
Idl6NCyicnM9GGSTZFMDVa+W+oc3IRLJkzKMZMXP98Eha5LNAa0N5CdlPUli++fJT+UdyDEMzJNf
fGWo6HVC2hgb9sCWjpnieZIdwNo1/nMxI1UWrD5sUDr4Z0JJtgywZiNDYeWnyZDsu/Bc611DdQES
6z8zkn1WVSo0kGydX8X+b62Hh662STYvXPlHSGfy3wUQTBtLKseRGOBvGskabkPskmxjeChguLoL
w5OsSDbitnEJl5FkC30JjwSoPD+07Y09koVHw8eNapV9Td7UYyS72SckC3etIN8YFdDgllsk2wBy
/wnxkujhipkVIIy4zJfHcDSrR1OSbR5NCNw7iQJfE3acLmgaQ+LySrWF1PeJvi/s2SLZYAgfyMv9
8/o1ezd74esk1na6oEMCeWnkeNpw/vOEtDD0QKfcItiDSDZ5koXGnlE7uSyxQbIjbJFsfZhH+rNL
RrWvXiQQbonZ81bLnGwQPP9YL7UMcSm8TQc3yZCTjY+SSq1JNusfhIzhh996QuKv/ncZ5NLVWFib
dPHypVLsSOl7poQkteXOrw5w90K6IBUk7/WSR8UnwCOuD6mWXwFRSGlnIfVOQkn2LXh+Sp9Wcqn3
KhmSfQs4ubJUWxAgEIW7eHjwZU2ydeDBk/7fZTBSRQMA7sX0JKucbE64tI0yNke36AoRYwmkC26W
dJZkGzwzDUIg52MZyUKsYngZwUCyYRCOk8fbpvasXzakZQy5wVLEVg++IAVlkmCoAm/CvO1Dkv2S
uonxgYgRHw1tuUOygfOABCKr1eRSheYOagN0oZByNNwgCU31lGTL3DVZRivAtdUxyZZ8TBIMAYaQ
O5rENYGGbZFsgwSStLdUGnbfVvKmPZKtCJdvY7YiMDhVQPojpjmNgMNcZadINjKOvISbeFHAz6V0
wQrp7hGIX3oZwRDJhkIS+F6HdBAug8DSX5skKwA975UCDHifB5LQ8JwkGZLNeBBuqnnXJSEzZyEV
WYeQPI+De1cPio714/FIFl5uSRoluVSNFjHwsIqmT/rD2nlGIdSCtOcIJdls8LBogMGitsnlZLPA
ZdV4g5XhIksX2SLZTBB7Puicno8UXA5tk2wa+nSK16E6BAcHCz1hsUwGg0IfwnpDuBtzLpKt/ND0
Igj3VZYkS4kf4mL2xpdEsgGASvyCPNxfPnxlj2Q7QKrYeOf1PiHn8/icZL82wKLFDXdINi8kWo1L
BoR3wQ/+B5M9AMLCFYawoxdbXZD+P3E9LcN4bXIkm/YWSfrIMBwfxJFX9F7KFsnCEhvDX7cBBew8
+AqDB2k0FmZSZ/3WOaHCL9J7ZLSsyDXCvsfqFMmWfEVi3+dNQdgOaQeJZNeJJBsIT/6sSLYG8J80
x+kiMJvpAqE1kAnPqUIHaX7ij+OSIdmgLbDMiM+0vD9t3sRl4zYYjVPrN22KYJpWjyeP6cIuz4mX
SBZS3FfhuiJKwAZ4Fk7zNw1N3jAVckYzkg3cD7cf0nVNGJgcyQYcN33UWRfggYjAFslWhVuODpIC
G+2lC+iFcquU6kw3fevGJkJtULaIpHrg1/CiNMwC50g21w2Tp3KZIEoRSfaRNGgDIKi3JFnK8zuk
hxR9EuylCypA7AohNZcACIWOg7NMhSdv0tXcqzlZHskiyRIXX0boATfqDaXRg1drITi8HQb735m8
dJ5xG1/jCaHiqTRi3UJXkiNZASbEFsP8Aa45lw7OtUWye00WyLTQ2yPZYEhQ/iJpCvH3irR0AeR1
w01/O1jhRN3ZKZJNe40kMYqkDX4SL5LsQghcxMAm51MbJPtBErleQFQhI2RIbZNsjUQSb0gV54Wn
IVPhlGRIVoDAZx2PoAIzZQ4VJR/M1KiQ0FCuUz1CbhhzfqIabv3owGs8ny7IC0sA5pno1RVu3DvC
fulYou8tlfeDrxdDJCusgCV92cTCLHuSI1n6DYPTkgvCJ3bJA0hI2SLZlrA6sLDYbDpIfdnOydJ1
HNHFxGqF4smb6kKpaL7UkBVmgrdzaCbSOZINgOh5q9iYAM+KGclWei2+DgMHlgPYliRLu/hcOukr
u6sLCj8jid2lamkh2lkCO0iyEiI++HUjkg0CgjuVykTHiUkksTPs13tpDFubJHGSjYJXGukxKkPA
YczTBRDZzWGHpDe+4EboaSNWIgj5rhHCwlBbJHvA+GGajNCKnUhWGAB3gOJyBXjHhnQThDrgyQPF
HoJXQdaIhgROkSzN090Sp1d2SCHySBaUiw7n7cGmdSTbLolchfwqkwGJEsm+tnitNvsJIEzpLgCU
vk77SY5kRySRo1nEpg0/GeGyRumJSzsgGImPpDL3fnVgpOdJti3cANc1Uawk3CytgpHJBAx5JDs/
kPa0+DICfJk8aahYGQy0yMnCKK1OTY+uFt/4ghfoYiVEMkFKdjJcf2yRbBsTku0HAaQdki19y7hy
DijrzyAh00qILMU3HYXOSeRxWejdOZIVRoP7NOG2pIUbPUaypcF48cpS9i6UWZHsHZI0mp8jFAHy
FJdw3Sfi92QH89dqMyyBXDENfqi0jicvaAYJNMZIliHig3/cINnaELCxO2VJTXhpgGyhO+Dfz/gi
rvcgMqE5WSH9bnCCOvSg0PUhlJmTLMwD/rxHItnMQJ7nOCuG/ABZJEhu2Y5k50D0XJ4eFCKgEZLA
Hm1YvYwgZPkbJikjxsw/QfxTHOrDs+AH4vqqYfAoi3qecyQrVAR+PsgeKEX8Cn1yEFrBX21ayCZ1
x2gos0oXVIW34IfQPoSg3rTCd3Qz4gmJbUg3DN8u6PiaxH/J70LrwMOq8fRYciTb6Cl5ZbhNpSdQ
CT1i8hWuwC8I+ZGXe+pfHdjgcZJNCzR1yvR6QT8ty9aFVIMnQ2sZy2ZeqBdJNgCG8lFrZlATuN22
INnZ8OUHdi8tkWwQkNeNOqw6/eTG3RKwaYtkK0FXI1i1wF6wyb8uY/XgCz4oCQ/12cVf6PaKPwSr
Almp73n6syTcrX1FG3GSZPNBVHqpBj0hHDImnGTpE83zsLoEXlqBQNeaZNOA9/3GMBEq0Qp32J1Z
CHw+hqsvkqwA6yqSVnBUi0JiejFt0WckCxMUZD7tU7PiBsnOhQ9fMN6SwAuC4OkOzaAVuQMx5YI2
RSqNgXc8nzKSFeAJFbk/qWmhOvNfkCtvLEh2FjT1/aDGJl/heh8i4CuDq+TN35J+I4tfr21Fsu/F
wcO39vnzVZ52ldyH2+vx9Lve1iQrfALtnR1T592u1BvZx2CKQCTydHqDAvmqLIUH8Svp4xUnSTYQ
7jXJ9UW9ei64SZ7dSeIkm+kqPPfb9EnTXptekaN6a5LNdAxsnFoiX/Fe+xPIBeCSsnng3SVIY5ya
1Aci3OkQbdB72WAIx8nmNiXylhgNHHstN9UqOZLNBK20pRVNxYxk0x0wWZ9gWsv1bR3o6XGSLQ73
QIyaDHpBlM4YLxBSoORIVIVinXaQePhuFk0XCGUfAM/NbVmk6rgH5F60BcnCn9FKWD28jclXuCoD
F97/vG6+fLXXgTPSrKdNkg05BHddM0rmK95jbzwdqb/KwUjZINnsZ6HewnblGs+HdndQEguk/Ljr
w1J5ig4GMqMf3HKaZIVO8fBBop/6dp/9H4m/qefaUYL6b1qrNvNvkj/vWpOsAHmTpF318hWot/Qh
+e8V3EYWgqxaWlD/5hfwAhp9CY59IIbeepH9ncrkKfIxqMw/B+EzkgWWAEGSBRCiqD+kTLLBXZvF
u0cDoSXm/W2fU2RhfpDrPc9ykg2aBGQJGTb4/7eeTyxI9j1alb59KEWyQqqZtIQ8Bw6FeQe+A2KL
ZNkSLhL3GmpdargY/qWvwtog2dTTWPe0Nf1Cnqdsw5SMgfAbHukzNnOSZIX0o8DlmbzWQZw0mGnX
GWYJlzXv2Yhk+SdOk4BF4ONfdagyGyGNPY+eEQc3yBLJCm+dokWJTLf7/M45OZKldw6miUymjhnJ
5nxGHtKrnwdFR9X09Gu1I+EWiEf2kqalAOkT9OpTEK7gIBS46bMIJ1mhExs8Wnax52ULki0DN1pw
x5HKkC4QhBFvaNEL6ixkLXspwFYkK9Sm8SsbqYTJNagDbrNJskL127QhJhfYjY1QEAgOTn1G3flp
c2aDk5GsEBAF6V8mSZO/ImQ2vQRE/CkWkSeV4CmFZbpACIPbQyB66nhHStHo4TkkKAI+pYXUKSWS
FfLsoiVcLfgKJhUfk6z5lZNpoKF/XI9kG8En6aWHsCJgpR7o9evZ4vH3wCeo7Hk793/6MyxXGdj5
P1akX1GwTrR+JU3mjtTr/2DJosBREAyQn4Bkb+lf1GGtBXWBO3wmV3SpefuT9HrxrwdACBKrf8ye
EIV8RqcETJ3ZEQL9vlwi3MH1itWfoZGFqQS2h6CEyu+tOGXD5/P38BLybIqYr6z9Wn/NQEbn9HpG
n9/p9QtYS28/0j8qz9sst/RGInwZ79cmwkbp63WBOm7fw7GZK+j19CMcQvgf+rimBiUa/sW6S9rX
TEgLSWCyAY7k2wPz8XUdQZim1++lXAIvMn0DgTUV/WqeLxFCzuhje7Fj8M83ev06dhcsFcBvrSRy
2mSXbYYe1us7SYXN4TIibXvoV8d09OwSrnR/6fUHOQoGLTfq9dGN6F6O79gFlzwcmuYLfaz4oaAm
cKWn8mvJAjf1u2DMc1/Wv+nJT+5+Hw7sSyWs0ut/EJtrKrolud+f506L3tQ/qSoeFLbr9V+y7fcg
WQWSdOB9Ic2XsLEFSPaEPh4u3+ZSagXlN4hAJ0WIB7J/yWgfzt1ahRcFHdHrh0mn9dDrdzByH6vX
b2KX+lxn9a+68cMRMy9BgB1/oEMgkOwYVlZsFQsNEtdWFAAaRrLT4UypOaHAN1yB6yOzC63gokLf
DxTC1oNP6eF5wyC9/s+crG7YDHbRBlV31eQnT4FmxGkllIjTP6xoaNPDGyyMsLg98XAXsm/OdZJN
lys8nDKJiQRmCw/Pxu67hdCW3+/aNL9JBiEom1Qk5Oq9YveG6RVTC2lyhjNXyxAenpVXF4o07dYU
osng7OE5pbHP1m7hjoMb57XgWSfoJmN4eBi9wFMJyhmeQ5yOZQZ/v2lhP/YXsQp2G92ZJoBzGvrk
tdm/YU0mLprdry7PmbGSDA1nbTq47fuPDC/Jps4Znp2HuXAcjMlAq2UKD8/EqgfnCM8hWZwqS/HG
NQpB8hQCLIlHszQfN398u0Lw4dDwcMbxgVnDc5pwRninWRuXT6xCG83UdFT/t2mjGct36FwN6oTA
KaJtQaWHrd6/a+WYt6VTA7KF5+RpWnpmeHhmCQTaABVY9BvN8nl8l/0bkCU8XLqaCD8ZFyWZVHFr
U0fZxcORbGBOMM5CKwCGD4MQXGHS5t3L+8FghYTnlEzL0mXprk1z4Y9sBWUPDwNfCgQHko7lbdCt
dWH4kG94uGHMQ5vP33pwy8KOucRe4CzDkAph4eGceoWwjrN+WT6pGo0X0kaO6v8OtJs1PNwwBgYV
U5ca8vXCkW0KGgqEwOIDf963b9X46pISAowDcyNaJ53kwdSV2UkwZQz6BoQVblS7KHS6wvAV7TTv
Dpo1q29F8ATwRjYxAA9+Jjs9qPrnKzbM68geWZTp/2lL1mvasm261AUcYXqJs1EIKPLxir37Vk+q
KdlAm5HcKBjmkuTXrFVP/sNJdp4nm1RcW66TrOJM9YrCcCtPvBYFOK3xR47fqYFvS54wmZlON+uo
ojdI1lF/GjoWtNPT70D7ETwkWXc/EOPHwfNf1wG6BQu6SN03eEQuSmGRVOb737CT5LIhHLfu/gt9
ktWDMetaKStBkk0ZXsnUbjH/6wFSlYKXyRN2myMVKPkXSRZJ1hX/HQZPnMW7wcB18MxJWtfqSlse
OqdDPDFkba2azHWB7JduE60OulqAJOsqcjbPawdryiDRxOSzJHLQkGGwWVtBhZBfBsF0AYAQpaBh
87uqFeNI0lI2IwovSiDGByd+VCxwMbloyF1b6tGHxIiPOyyPuLGvo3PHwzlZN9RR+ql5nsAqKxa+
5poWQ6Rnd0q3CvTnJDtXBZa4bgLmZFOOXervgF4u/zJr9vorsDFFfHSX8nY8eUbEdZOPpZg3nPGs
8e8qmB9xZ08HpiPJuoOg2bmBAwDNW1vmzFxFF8EslR7+mtVR5M586iYmH0NXpBFuKo0k6wKAGRe+
YK4D/zz4XFoD4EI7njylB7mdz3Z7w9n3Em0fc71UxxDw7BIu17VR/pkBkx9JPvV6nmE1hPLt4iQ7
R/mGuGEBkqwr4AXXmHfyAUl6dGzsO66c7o1zMvQba/thSaBunGElqAc7RpL1IJisqfLjfoM3JZ+c
nF7H0y37s72v2aUDSRZgwJxsCh0xKFveYhF5Ld94SGEjHq4urXs0b9Z2qXkdF/aQZF0ALZlTsuQp
WiSf+F5MMlUVcxhJFlcXKMZZ5aYokqzcRkSe+iDJIsnK0zMVoBWSrAIGSQYqcpLlryvLQB2/qIA5
Wb/ArvxOkWSVP4a+sGABoYIkCyBgTtYXDqemPnR07uA6WTUNqVds4SQ72yttK6VRjGSVMlIy0xNJ
VmYDIlN1vmEXYyRZgAEjWZn6qGzVQpKV7dDISjFOsrNkpZOvlcFI1teIy76/0p+XdkJHJFknQFJl
ldozK6XALiRZXF2QAnfRStWG5NaG5pafdbUyHknWChKNFHQl93a0z+bs8mskWSRZjUyMlJhZF9JH
5OLEqo4/3IUkmxJM1VS3A/WPmzNrO/fuL/37YoRgugBAwJysmqaBe7YwkoW/+nhwNPtLgHYa09G5
g6sL7KCj5mJGsvCX6Y5Pt/0et7ntnGRnmhdqbA9zshob8OTNFUkWKPTBxub8b0TZOElHORZJ1gYy
ai8SSRZG/9H21uzP9zmy+FvmJ0iyAANGso4cRVvHjCQLjnF+Ui3baQMdmzz4FS5t+Qa11kiy4AKX
ptWGP0rmQDjJfuGghvoPYSSr/jFOoYV12N9nZxxK/4k5NrmYjaccOlYBSTaF4KqguhnJwt9a/n1K
cRv+IRm6kPnJDGlXk79IspocdkdGW5AsTJLnW1pZfasWSdYRhmo+ZkGy1D+2drDyDwkBJFlcXSD5
Av4aELAmWZhHZyfXMfyRa1YTSdYAmMY2rEmW+Uct21+vR5JFktXYBHHG3Np6mDTWEnNySvFUxvN1
rAamC4yIaGXLJskS8vKPCUVs/ElRJFkkWa3MjBTYaYdkgVRjtnQpLDWEJCshobVfOyQL/vHil/YF
LNGgfw+PEMzJAgi4usDSObS7XyORzQvb/1xb0Z4/Tdax49u1C5NmLf/Atmfw0svL2qc1Q2YRK59u
Vqa1HfHB10fqtjtAlEBJgkQJFiWVQVKLkkaStKKkkyS9JBlEyWiQEFEyiRIqSWZRwgySRZSskmST
JLsoOSTJCRIuSq7cuXPnyZsvf74CBQoWLFSocOGIIkWLFitWvHiJkm+9VapU6TJlyr799tvl3nn3
3fLlK1SsWKly5cpVqlarVq1GjRo1a9WqXbtu3ffeq1evfv0GDRs1aty4SWRk02bNmjV/v0WLli1b
tWrdpm3bD1qNs50ukKZWzD9T34L0bFe2f/fHn1C0hcCPhyVPsP0bc/qzCJP0LCfZaerml2SsE0l2
HJ2jdJKCwDwFgan6drly5d55B+YrTFiYsjBnYdZWYvO2SpWqVencrVa9OkzfGjVrwgymc7gOSF06
kflUrt8ApCHMZzqjYU43obMahE7s5s3ffx8mN5verVu3ofP7g/bt23/YoUPHjp06de7SpYtOp+vW
vftHH/Xo0bNXVFRU7z59+vbr1+/jTz7p33/AgIGDBg0aMmTo0GHDhw8fOXLkqE8/HT16zJjPPv/8
87Hjxo2fMGHCxEmTJ0+ZMnXqtOnTp3/xxcyZs2bNnv3ll3Pmzp331Vfz53+9YMGCb/73v28XLlz4
3aJFi7///ocflixduvTHH3/8afnyFStWrvx51apVa9asWbtu3fr1G375ZeOmTZs2b9myddu2bb9u
375jx86du3bv3r137759+w8cOHDo0KHDR44cPXrs2PHffvvt9xMn/jh56tSp03/++ddfZ878/c8/
//z777/nzp+/cOHixf8uXb585crVq9euX79+4+bNW7dv375z9+69+/cfPHj46NGjJ0+ePH327Pnz
6OgXL1++fPXq1es3sbGxcfF6B5LktNieFikufbNFV6RLis/CE7SCQPTqdvkl3kGSNeRkn96EyX77
Dkz3u/fuwYynUx7k0aPHIDDvQfjUh8lPZ//LmBgggFevX78BARKIi4uPj09ISEhMpGSQZL7SUiu+
pSU7r57WkrVoa0oROL+0BU8bIMkCyc5JKXxYHxFABBCB5BB4s70CjWaRZAUhmP95iOQQw+OIgBkC
+jtmu7iDCJgh8PrwZP5V4sWsWNs52WD+vUczgHAHEXCMwKOF9QY6roFHNYxA0uXJ1aQvGnzPcJgq
pWg1+Ss++NKwRzhvOnu+RHPOiUwgBZ0Ameh4SEjHwcOp2Fian37zGoSmq1/FUIHs9Qsq0SDPqTyj
QlPcT+ER1xOa8X4Mj7se0QT4AyqQDr9/H9Li9yA7fvfuHSo0W34L5CaVGyDwyOz69WtUroJcoXL5
8uVLVP6jcpHKBZDzVM5RgQdv/54FgWdw//zN5AzIX1T+BDlN5aQoF5LJqD853CdXkNCZ4XZ57HgU
bSEwdl0yM+b25hZhRi7lJDvFWKDBLZFkXz6k85zNcT7B6dzm85pNajqf+WRmE5lNYj6B2eRlU5dP
WjZjT506efIPkBMnfv/9t9+Ogxw7dvTo0SNHjhw+DE/iDx48eODA/v37QPbu3bNnz+7du3btBNmx
Y/v2X3+FB/hbt27dsmXL5s3wSH/jxo2//PLLhg3r169bt27t2rXwxH/16lWrfgZZuXLFiuXLYQEN
rAlYtmzZ0qVLliz54Ycfvv9+8eLFixZ99913sHTg22//9w2VBV9/PX/+/K/mzZs7d86cL7+cPXvW
rJlffDFjxozp06ZNnTp1yuTJkyZNnDhhwvjx48bBCoXPPvts9OjRn44aBQsXRgwfPmzY0KFDhgyG
BQ0DBw7o3/+TTz7+uF+/vn379OkNqx569erZo0eP7t27d+um69q1a5fOnTt16tSxQ4cPYa1Eu3Yf
tG3bpk2b1q1atWzxfov332/evFmzppGRsM6icaNGDWHtRf369WApRt06dWrXrg2LNGCpBqzZqFql
SuXKlSpVrFihQvny7777DizzeLts2TJlSpcuVeqtkiVLlihRvFixYkWLFomIiChUqGDBggXy58+X
L2/ePHly586VKxyWfOXIkT1btqxZs2QJC8ucOTQ0E6wty5gxQ/r0sA4N1qalTpUK1q4FBQYG2Pi0
R6U4R7Po7FeNg+g80bFKuE5We5zhcJ1s/OGp75pBgiRrWF0wtgRI8eJ06tLJC9MXBGZwROHChQtR
oRMZJD9IPpC8IHlAYNUmzGqY1yAwtWFuw+wGYWs+YQUoLAZlK0NhmShfMgoLSNl8h6WldJUpLDll
y0/pWlS6MJUuUoUlq2z1Kixlpcta2RJXs3HDHa8iUMM+yT5d1SSX2DcnWXyt1qtDIcvG7b/xlXB9
RpVMFjr/wC7Gky1KtbUrRrI9tGU1WusAAXsk+/zIsHwsiGXnIsk6gFDVh+yR7K1N7SwZFnBAkjVE
svhararnRYqMq24zkv3z0+qpTZtBkjVFQ0vbNkk2fstHtv9YEZIskqyWZoeTtlaPZXd4pv88Xt1c
ShNIjSDJSkho7deaZOOuza1o788qLmF+hOkCgAEjWa1NFfv2WpLs62OfF7OujSRrjYk2SixJ9vbG
LjbSBBIWnGQnSbua/BVzskiymhx9m0ZXe8OCD/GfKxNqSUsezWojyZrBoaEdM5LV7+5ZyqHtS5kf
IckCDEiyDj1FUwdNSPbBprY57NiOJGsHGNUXG0k27vKs8iHJ2MtJdmIytdR9GCNZdY+vC9ZJJJt4
eHI5+6cjydrHRt1HJJK9t6lH1uQtRZLFB1/Je4nmalRl6YK7s2o7DFKQZDXnGKLBjGQTDvd6y8aL
LNaYcJKdYH1AQyUYyWposJ0ztVoSebCja45kphCSrHNoqq9WJ5JwYV7F9E4atoxQQZIFEDAn66TP
aKBaxcNzaiVvpo7OHYJvfCWPlNpqNN3Y13I9nwMTkWQxXeDAPbR6KJ3J5z3sY4Akax8bdR9JF5gS
+35kF2OMZAEGjGRT4jhYV/pADEay6AuOEeAkO95xJZUfxZysygfYW+ZhJOstZNXV7k8skh2vLqNS
aA2SbAoBw+ocASRZ9ARnEOAkO86ZqqqtgySr2qH1rmFIst7FVy2tI8nigy+1+LLP7UCS9TnkiuwQ
SRZJVpGOKwelkWTlMAry12E5oYLpAgABVxfI313lpaGOzh1cJyuvQZGhNpxkx8pQM9+phDlZ32Gt
qp6QZFU1nF4zZgW7GCPJAgwYyXrNy1TaMJKsSgfWw2Zxkv3cw60qqzmMZJU1XrLRFklWNkMha0VW
skgWSRYjWVm7qTyVQ5KV57jITStOsp/JTS2f6oORrE/hVk9nSLLqGUtvWoIki0u4vOlfqm4bSVbV
w+sx45BkkWQ95kxaawhJVmsj7pq9PxMqmC4AEHB1gWsupN2zdHTu4DpZ7TqAk5Zzkh3jZG11VsOc
rDrH1etWIcl6HWJVdLCKXYxHq8IWV41AknUVOY2fhySrcQdw0nwkWczJOukqWM0SASRZS0Rw3xYC
SLJIsrb8AsucQABJ1gmQsIrASfZTTSOB6QJND7/rxiPJuo6dls5cTaggyQIIuLpAS47vCVt1dO7g
6gJPQKnqNtYwP0GSBRiQZFXt6V4wTscmD/4hRS9Aq6omOcmOUpVNKTUG0wUpRQzrMwSQZNERnEEA
SRYffDnjJ1jHBgJIsjZAwSIrBNayO56RVuVaKsBIVkuj7UFbkWQ9CKaKm0KSxUhWxe7tXdOQZL2L
r1paR5JFklWLL/vcDiRZn0OuyA7XYbpAwHSBIl3X/0ojyfp/DJSgASfZEUpQ1Ws6Isl6DVp1N4wk
q+7x9ZR1SLKYLvCUL2muHSRZzQ25SwavZ+mC4S6dq5aTMJJVy0j62A4kWR8DrtDukGQxklWo6/pf
bSRZ/4+BEjTgJDtMCap6TUeMZL0GrbobRpJV9/h6yroNLF2AJAsw4LcLPOVUWmkHSVYrI+2enUiy
mC5wz4M0fDaSrIYHPwWm/4KRLK6TTYG/YFUTBJBkTcDATbsIcJIdave4Fg5gTlYLo+wFG5FkvQCq
CptEksV0gQrd2jcmIcn6Bmel97KRpQuGKN0Mt/THSNYt+LR7MpKsdsc+JZYjyWIkmxJ/wbomCCDJ
moCBm3YRQJJFkrXrHHjAMQJIso7xwaMcgU2YLsDVBTgZXEMASdY13LR2FifZwVoz28xezMmawYE7
ziKAJOssUtqut5lFskiyAAO+8aXtqZBy65FkU46ZFs/gJDtIi6YbbMZI1gAFbqQEASTZlKCl3bpb
WCSLJIuRrHbngMuWI8m6DJ2mTuQkO1BTNlsai5GsJSK47xQCSLJOwaT5SkiyuIRL85PAVQCQZF1F
TlvnIckiyWrL4z1oLZKsB8FUcVNbCRVMFwAIuLpAxX7uFdN0dO6QnV5pGxtVDwKcZAeoxyAXLMGc
rAug4SmCgCSLXuAMAtvYxRhJFmDASNYZh8E6RgSQZI1Y4JZ9BDjJ9rdfQQNHMJLVwCB7w0QkWW+g
qr42kWTxwZf6vNpHFiHJ+ghohXfDSfYThVvhnvoYybqHn2bPRpLV7NCnyPBfCRUkWQABc7Ip8hys
jA++0AecQgBJFtMFTjkKVrJGQEcDFFzCZQ0MlpghsJ35ycdmZVrbwXSB1kbcQ/bq2OTBdbIeglO1
zSDJYiSrWuf2tmFIst5GWB3t78BIFv8ygjpc2fdWIMn6HnMl9shJtp8SVfeYzpgu8BiU2moISVZb
4+2qtUiymC5w1Xc0fx6SrOZdwCkAkGSRZJ1yFKxkjQCSrDUmWGKNwE5Cpa/1AQ2VYLpAQ4PtSVOR
ZD2JpnrbQpLFSFa93u1ly5BkvQywSprfRQNZ0kcl1rhmBkayruGm+bOQZDXvAk4BgCSLkaxTjoKV
rBFAkrXGBEusEUCSRZK19goscQoBJFmnYNJ8pd2QLCCkt6ZxwHSBpoffdeORZF3HTktnIsliJKsl
f/eorUiyHoVTtY0hySLJqta5vW0Ykqy3EVZH+3sgWaD1T6liukAdvuxzK5BkfQ65IjtEksVIVpGO
KwelkWTlMAry12EvDWQ1/kcBMJKVv5/KUkMkWVkOi+yU4iTbS3Z6+VIhJFlfoq2ivpBkVTSYXjSF
k2xPL/Yg/6aRZOU/RrLUEElWlsMiO6X2QbKAECRZAAH/kKLsvFPmCuno3MG/8SXzUfK/ekiy+ODL
/16oUA2QZBU6cD5WG0kWSdbHLqee7pBk1TOW3rRkP9zvENLDm13Ivm3Mycp+iOSpoI5NHvxrtfIc
HflodYD5CZIswIA5Wfm4pTI0QZJVxjj5W0tOsh/5Ww2/9o+RrF/hV27nSLLKHTtfao4kizlZX/qb
qvpCklXVcHrNGCRZJFmvOZfaG0aSVfsIe8Y+JFkkWc94kgZbQZLV4KC7YPJBQqW7C2eq5xTMyapn
LH1qCZKsT+FWbGeHkGQFJFnFuq9/FUeS9S/+Sumdk2w3pajrFT2RZL0Cq/obRZJV/xh7wkIkWczJ
esKPNNkGkqwmhz3FRnOS1aX4PDWdgJGsmkbTh7YgyfoQbAV3dZhQQZIFEPCNLwX7sV9U19G5g1/h
8gv2SuoUSRbTBUryV1npiiQrq+GQrTJH2MUYI1mAASNZ2XqpTBVDkpXpwMhMLU6yXWWmlW/VwZys
b/FWTW9IsqoZSq8acpRFskiyGMl61c3U2TiSrDrH1dNWcZLt4ulmFdUeRrKKGi75KIskK5+xkLMm
SLL44EvO/ilr3ZBkZT08slGOk2xn2ejjD0UwkvUH6iroE0lWBYPoAxOOESpIsgACri7wgb+pqgsd
nTu4TlZVY+oNY5BkMV3gDb/SRJtIspoYZreNPM4uxhjJAgwYybrtTRprAElWYwPuormcZDu5eLY6
TsOcrDrG0edWIMn6HHJFdogki+kCRTquHJRGkpXDKMhfB06yHeWvqBc1xEjWi+CquWkkWTWPruds
+41QQZIFEDAn6zm30kZLOjp3cHWBNgbbDSuRZDFd4Ib7aPtUJFltj7+z1v/OLsYYyQIMGMk66zRY
jyOAJIue4AwCnGQ7OFNVtXUwJ6vaofWuYUiy3sVXLa2fYJEskixGsmrxaB/agSTrQ7AV3BUn2Q8V
bIH7qmMk6z6GmmwBSVaTw55ioznJtk/xeWo6AUlWTaPpQ1uQZH0ItoK7QpLF1QUKdl//qo4k61/8
ldL7H4QKRrIAAq4uUIrTykVPHZ07uE5WLsMhWz2QZDGSla1zyl0xJFm5j5A89DvJLsYYyQIMGMnK
wyWVowWSrHLGyp+acpJt508V/N43Pvjy+xAoUwEkWWWOm6+15iT7ga+7lVV/SLKyGg7lKIMkq5yx
8qemSLKYk/Wn/ym6byRZRQ+fz5RHkkWS9Zmzqa0jJFm1jah37EGSRZL1jmdpoFUkWQ0MsgdM5CTb
1gMtKbcJzMkqd+z8qjmSrF/hV0znpwgVJFkAAZdwKcZrZaKojs4dfBlBJqMhXzU4ybaRr4I+0Awj
WR+ArMYukGTVOKqetwlJFnOynvcqjbSIJKuRgXbTTE6yrd1sRdmnYySr7PHzm/ZIsn6DXlEdI8li
JKsoh5WTskiychoN+eqCJIskK1/vlLlmSLIyHyCZqIckiyQrE1dUnhpIssobM39ozEm2lT+6lk2f
mJOVzVAoSxEkWWWNl7+0PU2oIMkCCLhO1l9OqNR+dXTu4DpZpQ6fz/TmJNvSZ/3JsSOMZOU4KgrQ
CUlWAYMkAxWRZDEnKwM3VKYKSLLKHDdfa81JtoWvu5VVfxjJymo4lKMMkqxyxsqfmiLJYiTrT/9T
dN9IsooePp8pjySLJOszZ1NbR0iyahtR79iDJIsk6x3P0kCrSLIaGGQPmMhJ9n0PtKTcJjAnq9yx
86vmSLJ+hV8xnf9JqCDJAgi4TlYxXisTRXV07uA6WZmMhnzV4CTbXL4K+kAzjGR9ALIau0CSVeOo
et4mJFnMyXreqzTSIpKsRgbaTTORZJFk3XQh7Z6OJKvdsU+J5UiySLIp8Resa4IAkqwJGLhpFwFO
ss3sHtfCAczJamGUvWAjkqwXQFVhk0iyGMmq0K19YxKSrG9wVnovnGSbKt0Mt/THSNYt+LR7MpKs
dsc+BZYH/EWoRKbgFPVVRZJV35j6xCIkWZ/ArPROkGRhBJFkle7GftK/K4tQdvqpd+xWIQgEYiSL
JKsQX5WfmnUYyS6Tn2KokZwQQJKF0cBIVk4uqSBdsm4Fln1cV0Eao6p+QABJloI+k0UkOj/gj10q
GoFsEzZ9XV3RFqDyPkCAry6o54OeUtRF1u4/7dy7x0ey+xoj2bO7fdTfnr3bl3QMTREeWNlpBAqN
XuOzgdy+589DW33lNayfvdvmNUrjNBZY0QEChUat9Y2j7H3J+OVPHzvKV41SObBeEBryLzAy3dT5
T9Lxag4RwIOuIRDc7746HcZolX5DXtewwbNMEEjV554RUnVu6X/Kb2Kw5WbLaHVabWbV/fqWZuO+
2wgE9E80A1mdO7/nchsozTcwVhOOYv9ynE31cSyb+wczad7TPQ5A2SfqpFULq+Z4HDitNfjOcwtI
1bn7VYC9gW2pV6fFFlbF17EHAJa7isAMC4xVunu9kKsA4XkMgcCJKvUMC7MuFbA34GMtaqp1t789
ALDcRQQCjqvVV8ztetnORYDwNI5A2r3mgKp1L9bekoaA2Wo12cKuz9HlPYxAwAULiFW6G9/Lw8Bp
rbkMp1TqGZZm2f2bNyMsa6p0H2eKp+d2wD6VuoqFWc9beBo5jbWXhr5GogF5VdPewNaL1YD5hLyo
YA8ALHcVAY1cn89lcxUgPI8hEDBYExRD/s5ub8DT7dAEAquC7QGA5a4ikP+iJlxnsKv44HkiAoWv
acJRhtsf8GJaWMN1wO6DP/vA4JHkEKij+ncRgBwWpE0OBjyeHALNteAo3zhylKI/vVT3Mi79i0X2
1wkn5x943AECdY+8VneMEv9gfHoH9uMhJxGofUjtjnJ/uGNHCSg/cMqM6WqVGZM+KeOkK2C1lCKQ
ptHIaWp1nOnTZ0zoilfnlLqE7fppGqjbUbrls203liICiAAigAggAogAIoAIIAKIACKACCACiAAi
gAggAogAIoAIIAKIACKACCACiAAigAggAogAIoAIIAKIACKACCACiAAigAggAogAIoAIIAKIACKA
CCACiAAigAggAogAIoAIIAKIACKACCACiAAigAggAogAIoAIyA6B/wPZzbpRCmVuZHN0cmVhbQpl
bmRvYmoKMjYgMCBvYmoKNTA2MDAKZW5kb2JqCjI3IDAgb2JqCjw8IC9MZW5ndGggMjggMCBSIC9O
IDMgL0FsdGVybmF0ZSAvRGV2aWNlUkdCIC9GaWx0ZXIgL0ZsYXRlRGVjb2RlID4+CnN0cmVhbQp4
AYVV32/bVBQ+iW9SpBY/IFhHh4rFr1VTW7kbGq3GBkmTpe1KFqXp2Cok5Do3iakbB9vptqpPe4E3
BvwBQNkDD0g8IQ0GYnvZ9sC0SVOHKqpJSHvoxA8hJu0FVeG7dmInU8Rc9frLOd855zvnXttEPV9p
tZoZVYiWq66dzySVk6cWlJ5NitKz1EsD1KvpTi2Ry80SLsEV987r4R2KCMvtke7+TvYjv3qL3NGJ
Ik/AbhUdfRn4DFHM1Gu2SxS/B/v4abcG3PMc8NM2BAKrApd9nBJ40ccnPU4hPwmO0CrrFa0IvAY8
vNhmL7dhXwMYyJPhVW4buiJmkbOtkmFyz+Evj3G3Mf8PLpt19Oxdg1j7nKW5Y7gPid4r9lS+iT/X
tfQc8EuwX6+5SWF/BfiP+tJ8AngfUfSpkn103udHX1+tFN4G3gV70XCnC037anUxexwYsdH1JeuY
yCM413VnErOkF4DvVvi02GPokajIU2ngYeDBSn2qmV+acVbmhN3Ls1qZzAIjj2S/p83kgAeAP7St
vKgFzdI6NzOiFvJLV2turqlB2q6aWVEL/TKZO16PyCltu5XClB/LDrp2oRnLFkrG0ekmf61memcR
2tgFu54X2pCf3dLsdAYYedg/vDov5gYc213UUmK2o8BH6EREI04WLWLVqUo7pFCeMpTEvUY2PCUy
yISFw8thMSJP0hJs3Xk5j+PHhIyyF70tolGlO8evcL/JsVg/U9kB/B9is+wwG2cTpLA32JvsCEvB
OsEOBQpybToVKtN9KPXzvE91VBY6TlDy/EB9KIhRztnvGvrNj/6GmrBLK/QjT9AxNFvtEyAHE2h1
N9I+p2trP+wOPMoGu/jO7b5ra3T8cfON3Yttxzawbsa2wvjYr7Et/G1SAjtgeoqWocrwdsIJeCMd
PVwB0yUN62/gWdDaUtqxo6Xq+YHQIybBP8g+zNK54dCq/qL+qW6oX6gX1N87aoQZO6YkfSp9K/0o
fSd9L/1MinRZuiL9JF2VvpEuBTm7772fJdh7r19hE92KXWjVa581J1NOynvkF+WU/Lz8sjwbsBS5
Xx6Tp+S98OwJ9s0M/R29GHQKs2pNtXst8QQYNA8lBp0G18ZUxYSrdBZZ25+TplI2yMbY9COndlyc
5ZaKeDqeiidIie+LT8TH4jMCt568+F74JrCmA/X+kxMwOjrgbSxMJcgz4p06cVZF9Ap0m9DNXX4G
3w6iSat21jbKFVfZr6qvKQl8yrgyXdVHhxXNNBXP5Sg2d7i9woujJL6DIo7oQd77vkV23Qxt7ltE
h//CO+tWaFuoE33tEPW/GtqG8E585jOiiwf1ur3i56NI5AaRUzqw3/sd6Uvi3XS30XiA91XPJ0Q7
Hzca/643GjtfIv8W0WXzP1kAcXgKZW5kc3RyZWFtCmVuZG9iagoyOCAwIG9iagoxMDQ3CmVuZG9i
agoyNCAwIG9iagpbIC9JQ0NCYXNlZCAyNyAwIFIgXQplbmRvYmoKMzAgMCBvYmoKPDwgL0xlbmd0
aCAzMSAwIFIgL0ZpbHRlciAvRmxhdGVEZWNvZGUgPj4Kc3RyZWFtCngBvVt/d91GEf1/P8WSFldu
sCxpV09PQCmkNjR1kzbgQylNKMUnPYVj0yaBj8T3ZPbHvbvSSvKzQ4l7KlnandmduXNndld+pZ/p
V9rs5L+6kX+dHtqxHuWf7m2jX7/UX+h/6tOP3rT66o1u/c+bK9ehH/rQ7kYPfbhVfHbNZxBs9HWm
xv32nf72fSe5c5Ib/yOSX4kK90ur903dtNYOut8N9Wj7Tl3d6EeXWoblfuQy9vWuNd1en8gvlzf6
9PKyk46X3+qvdPWTY93UVlcPjvVJU/e6eic+eNdfVfVTvAgPdHXkH7TZzUM8ee95FXs/P37fPzS6
+sjfdJkk6jqb6NIVBX0SX5y7qwyKL37uhfWZsBPoaV3bzrd9oS8/0eeX3mmwk+3Hej+Ore6bXd23
g3jK2Um1NhjSXU7aru69V4OZTDBT9Z9jffmPIBA+XvBEoSF6Immw9di0ZjcUivqoSLyRKUouVxOX
F4rCVHRS1A0RpvMZdQqO/0Vwi65+Ge32AR7Q2L9yb8TR8Lz5MD6INldV7fsIfNjH/BqPbI879Gfr
3/g3IhkCjX33WHkcPkInSoRfiZokmG3+6HsJUJ6E7mp1zHphzHMYjm6aMqmP3VWw9gWki75NaNmx
zaCV+cNBS4LfYUu9FbSmGjLwZtCKimKo3wYtvQwtKCownEFrqihxCvxdeCy5BSxDD8LL6Eva4U3k
EV0Fd2XgKyiAQKP4NRfHBqpiOIAQQT24luFBtbPJqOpPHjCCb94glNYQtN8FcrKDyRCU+bckp2Rv
RBEHxPk/8wMREj514SVXRifGDHuXcUeLUFqUryp7t2lkgSAB0rX7oU8MGOMhzcZyGhwsJkhGISgw
/JiUlMtOiyG6bOBsZK3t66ZvJUsiCRQjKyHwONBNokiYlWCNMZChlfnTGk6DN4bUSCvQ/NHoap7Y
OLV+n2Enm9oadpTk/7XACNyXETvHgynG0IGIFNugTzYgtuAtiCBBfOmYVuAZGqiKPSjjqbe0pHf0
5XgG1zfkfalgJOjY+eRYyRMRiyaGCnOjhl7A2HyM0SGqYiyhpUtaIVFEzxQlBz1j7xrVjo9QCaRa
z84FFuxs6872bVtWGAfEl6pujS9f9G3HV5xqHJkUp65avrzK4CgwbYZ926VIm1al1Qdiz4XJo4Cz
XcB5Mfksy0aJ9yzgVjXcO8uuFHBQtFXAzbJsWcD9NgZASU+xWtYVgwXRE+NKVfNKu4h7UlziqDKK
WL79GZnPpYiDAksvB1aoBikE40bE/Q7EyxyBN4lepbOD6jpfNuMd+fK2qJwKXMJ+GZ9Flvn0xK2i
hMfENduhNlWXqn9ja9v1w91S2YGFu2PUWeEeOJCsS5+hpCNcisLdp+sg0ICj4UeKOYskixdFejHR
5cqtQjYtZkZ7sMcZZyjdoH++CspWFBdAJQcfV8EZtdIaBCob8wkTC4OPbR74nCYrHTbmK+Y0RnsK
Qr7DLMI1y7R4UfqRI2YOpkpG35EflgCDjanx1PlPkjA7gXJ23loylXPXQq4XwXzrfkQGMMNG5E75
0gQ/3nUJv6qhzAAxgO+5zpoqygr+A9ZZrNA/KzNAjNNPvUmlOoJ7QaQJGniCFgRWBJ9K2YM+ZRt0
onNRHBGD7GOl+nKjEkfzGeWw/1cRBLp6/jzO6kW8/iVeY1vF3QMMAjNJc9umIHKFWiixzE6Gym0i
l8ukkumnlcxCYU3aOHfmk4BwISKXJ7dR01RdIvNurI0Z9zZVS0XGoPFo9KdwO18h6AiIr30T44Mt
UHAZuuwNr8LSdKCFzWUtE53LOqEgalC8YXcDcoDgyD7ZqAgRiOMDsiTkZrXLtmtlqff/dO1U3Y/m
WrgiokBVLMZgOvpzw9XRAxmTk9vpbHYXVAt2ZKuMiYBOoRwqjY5TFYaz7skLyJXOdGW26c2FkDEh
ShfXAtPN3LQCQiwQqfm60KFYJsR50Ig2g1cImANKJlVxQY8YSsvG0kSbfBUpnTZHzGwUJLT9meNO
mVbok1xwq6GZcmX/MouZBOJs0RWJ6Z6LLjPRkGXCMuW+3dYmFBWYuUvK/Twmo7joyggL6Jozra7+
ClZmWTcLWS0hG72MGKEHAR94HV1TskMLruKxp44XUxBkGyVUQj7OI8KHeFaqJ40EMBMPqLjon5/L
KHeYxnMZ7Gl0oz+XkUMPf341RdhaKH/o9jUlva5b5RtOjqxVZscvnTclF6YdOTbmHIvwT8sZaGde
ewg3kuKKJpTL8f0sZORstR4HkW0esjHcD7mHLYjVJpl2e398cZAHWOcAXIQAjeAKPoedvOArn2Bn
mjMDhCiQVMwmq0WiqmZFYjpigqFguJLOOfDQVKW1DKoURhY5mIOEWI4xm2lMKYQdO2WQ2nbMjkeW
So52DwsNTJjTgqcw1DEeuZGNaOhHWfoNqW4zMTkntxI8FMQbqOKMizc0U0qLEjyHWsMddIvysjJv
pZxuBjnkXd/Nv2OB3q35oN2Ptd3ccb0ozEmU/OGpZ4p8+5qlFLmDNqIrAUiRk5lKYjJ8E8DyqOsP
j+hwBC1HAiGBqapYn2dwDajgCAuszRGkUoXISQCPBAffsDdnziqKe/psnDib9RySZ274zE4p96C6
6eS7DlfdFCVBVt283ZbyqoZ7VzcrW8pQVKTR9eqGXM4NBa69yz3lLhY+9Bp9FD2SlUIIf8CDeCEN
UArdyTaoXhgrwEtaPvIVFHAs89yseG7EPlRkDcaZKpu/+ZCVsHyP7XEu6ee3iCZWMu3hB3G0PQ2A
uSDGaSLGQE6VnntR/6iKhmWqgjikVfyOOafw4UyjZdKJHk3FGxqao+P4KeaMa46wmY+oZAPCDWOj
MAwOg5Uu0eIrtWMjBWI7HFS5kOcee+qVRRE2kLNNVSjmhMtAmA02g/2CPNoLXi3NRVUAPh/whlKo
uxSTrO5WfGmlR6un8HlU5CUyKDVRwVmsFihnqkhzVU+vcti03UVSuJ3i5ROBg/3JCPraS5edZo4Z
jAE4AYGMknnFkzlxu+LZjH+MPmaTxQJFioZubOVolAXK9BBU8vCkQFG37iBCa0H8rdDRzjRjUnWv
HcQiSKPxMpvR9YTPU/AoYYPl8bljB1kaEBxcMxHccFvRt6hMMmB5olg98xOOOBhYnijcNxL8qpGl
2Ty9ZJgjSwN8YOvsrIUT2gbZrMjKjshmp6NroUg9iZH46EmIxUTyG9tIc/MWHzqgjmr7ELc/Xh21
quF/XUdBURFOd6mjrmKxlIE8JmxiiiTMmxg82dYhI4LMtpC1gbey8TOf6IQYkXyIY0TYLZ8dBSBK
dDvaK2Jr7vzCYu3YyJfJOyMEND2cS1+jMlcwA3Eavwetc7BgoixJv1AbX/zOXLnIx13f1PvGf/4V
xzglyepjiZyFj1JQ87XGH0luViBTiUIsnCz5kg5GSNMws8VXth8HMwAAhXfRgLHPjXzUApk05kY6
AHZP1TEHBcl8wLMCzohiODU2nk2p+LYrWzQyUbNzHlLb2bjzH1/hu/jDNk+2t/bjhs4q1S9tra5S
fZY/D8ADfQiAwAWhtlHxo+XsuB0NaH/gBH5dq4runrC2/dD4VRH84Hdt5GP0/MuwhfNUVutHMg/Z
6D06enBSP5TJ+01fqf1c3Sn/F7sk7W5/WeK5NXav7bivh2Ew+kZb27rbMT275jO1s7Wxoywhrtk1
e/Sd/wMPyIwvtJHPWXfWdNr6T26Gnf9LECV/CfL5y9dXL3/417+/udav/y6jYUv/NxloPZcnO9+n
j286ffa9/OnCs/8C4ExO7AplbmRzdHJlYW0KZW5kb2JqCjMxIDAgb2JqCjI4MjYKZW5kb2JqCjI5
IDAgb2JqCjw8IC9UeXBlIC9QYWdlIC9QYXJlbnQgMyAwIFIgL1Jlc291cmNlcyAzMiAwIFIgL0Nv
bnRlbnRzIDMwIDAgUiAvTWVkaWFCb3gKWzAgMCA3OTIgNjEyXSA+PgplbmRvYmoKMzIgMCBvYmoK
PDwgL1Byb2NTZXQgWyAvUERGIC9UZXh0IC9JbWFnZUIgL0ltYWdlQyAvSW1hZ2VJIF0gL0NvbG9y
U3BhY2UgPDwgL0NzMSA3IDAgUgovQ3MyIDggMCBSID4+IC9Gb250IDw8IC9UVDUgMjEgMCBSIC9U
VDIgMTAgMCBSIC9UVDMgMTkgMCBSID4+IC9YT2JqZWN0IDw8Ci9JbTIgMzMgMCBSID4+ID4+CmVu
ZG9iagozMyAwIG9iago8PCAvTGVuZ3RoIDM0IDAgUiAvVHlwZSAvWE9iamVjdCAvU3VidHlwZSAv
SW1hZ2UgL1dpZHRoIDExOTcgL0hlaWdodCAxMzI4Ci9JbnRlcnBvbGF0ZSB0cnVlIC9Db2xvclNw
YWNlIDM1IDAgUiAvSW50ZW50IC9QZXJjZXB0dWFsIC9TTWFzayAzNiAwIFIgL0JpdHNQZXJDb21w
b25lbnQKOCAvRmlsdGVyIC9GbGF0ZURlY29kZSA+PgpzdHJlYW0KeAHs3X2sPVVhNuxiDQIVlVZF
/EQQtLQVBIoIFqiApSpSKBZohQoCWqwKFgFLNYp8aQ21FjWUYiVYqwGqwSoEECJCRBu0pmBjgUgN
CAEJQlQiJX2eO89635XJ/vrtc/b3zHX+OJmz98yamWufWbPvWWvW/NIv+SFAgAABAgQIECBAgAAB
AgQIECBAgAABAgQIECBAgAABAgQIECBAgAABAgQIECBAgAABAgQIECBAgAABAgQIECBAgAABAgQI
ECBAgAABAgQIECBAgAABAgQIECBAgAABAgQIECBAgAABAgQIECBAgAABAgQIECBAgAABAgQWILDZ
Zps92Q+BRQhsvPHGC/iPt0oCbRR44hOfuIiD2DrbKZAvBm08SuwTgXUKPOlJT2rnoW6vWiewySab
jP9fvummm15++eX33HPPf/shMF+Be++9d5999hn/f9WcBAiMENhpp53uuOOOH/7wh/M9jq2thQJ3
3333NddckwsLI/7fvEWgUwJHHnmkr8otrOxat0v5an388cePf2zmit9NN930f/wQWITAAQccMP7/
qjkJEBghsNtuuz3++OOLOI6ts4UCt912m94aIw43b3VN4IQTTmjhcW6X2ihw8sknj394JgZ+/etf
byODfVoBgd/7vd8b/3/VnAQIjBD47d/+7ccee2wFDnubuAoC//Ef/yEGjjjcvNU1gT/7sz9bhQPX
NhL4P3/xF38x/uEpBvqPWaCAGDj+oWpOAqMFxMAFVmXtW7UYOPpw827XBMTA9tVybd0jMbCtn2z7
9ksM7NqZ1P7OTkAMbF8NucA9EgNnd6gqeRUFxMAFVkdWvSYBMXBNXGZeoIAYuIpnQ9u8nAJi4AKr
svatWgxczsPcVi1KQAxsXy3X1j0SA9v6ybZvv8TARZ3RrLd9AmJg+2rIBe6RGNi+KsIeTSIgBi6w
OrLqNQmIgWviMvMCBcTASc5KliXQFBADF1iVtW/VYmDz4DJNQAxsXy3X1j0SA9v6ybZvv8RA51YC
0xIQA9tXQy5wj8TAaR2YymmHgBi4wOrIqtckIAauicvMCxQQA9txfrQXyyAgBi6wKmvfqsXAZTio
bcPyCIiB7avl2rpHYmBbP9n27ZcYuDznOFuy6gJiYPtqyAXukRi46hWC7Z+ugBi4wOrIqtckIAau
icvMCxQQA6d7nlJalwXEwAVWZe1btRjY5crEvvcLiIHtq+XaukdiYFs/2fbtlxjYf67xCoH1CYiB
7ashF7hHYuD6DkNLtVVADFxgdWTVaxIQA9fEZeYFCoiBbT1j2q/5C4iBC6zK2rdqMXD+h7A1LrOA
GNi+Wq6teyQGtvWTbd9+iYHLfNazbaslIAa2r4Zc4B6Jgat1+NvaWQuIgQusjqx6TQJi4Jq4zLxA
ATFw1mcu5XdHQAxcYFXWvlWLgd2pOuzpOAJiYPtqubbukRjY1k+2ffslBo5z9jEPgXEExMD21ZAL
3CMxcJyDzjzdERADF1gdWfWaBMTANXGZeYECYmB3zqH2dNYCYuACq7L2rVoMnPUBq/zVEhAD21fL
tXWPxMC2frLt2y8xcLXOg7Z2mQXEwPbVkAvcIzFwmQ922zZ/ATFwgdWRVa9JQAxcE5eZFyggBs7/
XGaNbRUQAxdYlbVv1WJgWysK+7U+ATGwfbVcW/dIDGzrJ9u+/RID13c+shSBfgExsH015AL3SAzs
P8S80mUBMXCB1ZFVr0lADFwTl5kXKCAGdvmsat+nKyAGLrAqa9+qxcDpHp5KW3UBMbB9tVxb90gM
bOsn2779EgNX/cxo+5dHQAxsXw25wD0SA5fn0LYlyyAgBi6wOrLqNQmIgWviMvMCBcTAZTi72YZ2
CIiBC6zK2rdqMbAd1YK9mJaAGNi+Wq6teyQGtvWTbd9+iYHTOkMph4AY2L4acoF7JAaqUgg0BcTA
BVZHVr0mATFwTVxmXqCAGNg8y5gmMImAGLjAqqx9qxYDJzkYLds+ATGwfbVcW/dIDGzrJ9u+/RID
23eutEeLEhAD21dDLnCPxMBFHcjWu5wCYuACqyOrXpOAGLgmLjMvUEAMXM7zna1aRQExcIFVWftW
LQauYiVgm2cnIAa2r5Zr6x6JgW39ZNu3X2Lg7M5ZSu6agBjYvhpygXskBnatArG/owXEwAVWR1a9
JgExcE1cZl6ggBg4+rzjXQLjC4iBC6zK2rdqMXD8Q8+cXRAQA9tXy7V1j8TAtn6y7dsvMbALZ0/7
OB8BMbB9NeQC90gMnM9hay2rIiAGLrA6suo1CYiBa+Iy8wIFxMBVOQPazuUXEAMXWJW1b9Vi4PIf
8rZwngJiYPtqubbukRjY1k+2ffslBs7zLGZd7RYQA9tXQy5wj8TAdlcX9m6tAmLgAqsjq16TgBjY
5Pqf//mf++6770fDfx544IFHH320ucjo6Yceeujaa699//vff/zxx7/hDW9405vedNppp33pS1+6
//77hy24wW3o37qf/exnw0pr0+ti4FrPROYnMExADGxT3bjwfREDhx1oXu+mgBi48ErJBowpIAY2
oW677batt956iy22+LUhP89//vP33HPPY4455vrrr28u2D/9yCOPfPjDH37xi1/8hCc8oaca3Gij
jZ773OeecsopA8Pgrbfe+oIXvGDENvRsWub8+Mc/3r8B7XtFDOz5R/IngXULiIHtqyEXuEdi4LqP
RAu2UkAMXGB1ZNVrEhADm1z//u///tSnPnWcSmnzzTc/7rjjfv7znzcXr9M5J+66667NcjJ/8tqv
/MqvNF986UtfmtBXlyoT3/nOd57ylKc0Z9vg9DnnnNNTSCv/FAM3+J9gBgJjCoiBrawkF7VTYuCY
x53ZOiIgBi6qLrLetQqIgU2xxMCnPe1pqaY222yzAw888LDDDvuj//8n0wcddNAee+yRNFfrsfe8
5z3Nxcv0Lbfcss0225R5nvjEJ77mNa+54IILrrvuurx+9dVXX3TRRQcffPAmm2xSZth+++1vv/32
ZiGJgSWKbrrpprvvvvsrNvSTeS699NJmCW2dFgPrP54JAhMKiIFtrScXsl9i4ITHo8VbJiAGLqQi
stJ1CIiBTbQaA5P17rnnnuZbmf7f//3fNP99//vf32+//UqVlWa7G2+8sTnbT3/601122aW8m96b
F198ce71a85Qyrniiiue+cxnltmSNx977LE6T42Bz3jGMx5++OHc97fBn/5V1NLaNCEGtuxEaXcW
KCAGtqluXPi+iIELPJategkFxMCFV0o2YEwBMbAJNToG1jkffPDBHXfcsdQ8p556an09E+9973vL
62lV/MpXvtJ8q2f6c5/73JOf/OTMnJbHa665pr7bjIEJnvV1E2LgEp7sbNKKCoiBatQpCoiBK1oP
2OwZCYiBU6xeFDVTATGwyduMgXfffXfzrZ7pk046qdQeacurb/3kJz/J6C7l9YH9ReucZWKvvfYq
MzdrjGYM7EgzXw/LsD/FwBmdsBTbQQExcFg94/V1CIiBHaxD7PIIgeaXunUcUBYhMDcBMbBJPX4M
/MQnPlFqgAwFU0u45JJLyrigz372s3/wgx/U14dN5J6+HXbY4SUveUkeJ/H444+X2cTAYVxi4IiT
jrcIrElADBxWz3h9HQJi4JqOPjO3XkAMXEc1YpGFCIiBTfbxY+Dpp59e6rGMG1NLyIFfXnzd615X
X1zrhBg4TEwMbP2p0w7OTUAMHFbPeH0dAmLg3I5cK1oJATFwHdWIRRYiIAY22ceMgRmz5eUvf3mp
i5IHSwl58ZWvfGV5MXcINotd03SNgRlDZk0Ltn5mMXAlTn82ciUExMDWV5jz3EExcCWOehs5NwEx
cJ71j3VNIiAGNvWaMfC+++5rvlWmc7PenXfeeeihh5bKJIN5fve73y1vPfDAA3lYfF5Pv9DPf/7z
/cuO+UqNgRmG9Mwzzzxr5E9myPl3zJJXfTYxcG6nMCtqvYAYuOr14VJtvxjY+hrDDq5JQAxcqgrK
xowQEAObODUGZvTOo4466oQTTsixXH+OPPLIffbZJ4+BqLVBs9UvD5h4znOek7fyrMBrr722Weya
pmsMrGsZPXH++eevqfzVnVkMHP2f4F0C4wuIgatbEy7hlouB4x965uyCQL43LuFxapMI9AuIgU2T
GgM3WE3l2e45zB955JG6eEYWzcgwWfBJT3rSTTfdVF9f60SNgRtttFGeMr/Bnzybfq2rWNH5xcAN
/luagcCYAmLgilaDy7nZYuCYx53ZOiIgBi5nTWWr+gXEwKZJjYGJYJtvvnm6Zfb8bLnlli996UsP
OOCAT3/6080FM33//fdvv/32qeJ++Zd/+fLLL+95d/w/awx86lOfetFFF/3j8J9P/b+fO+64Y/zC
V3pOMbAjJ1C7OQcBMXClK8Nl23gxcA7HrFWskIAYuGx1lO0ZJiAGNmVqDEwEu/HGG2/v+/nhD3/Y
bAFsLvvwww/vsssupZo655xzmm9tcLr5mPgaAw0R0+MmBq7QSdCmLrmAGNhTvfhzEgExcMmPd5s3
ZwExcJL6xLLzFBADm9o1Bm6xxRb33ntv860NTufBf4ccckipat7ylrdscP7McNddd+29996veMUr
suCjjz5aFqkxMOPPeHx8k1EMnPOJzOpaLCAGNusW0xMKiIEtrivs2joExMAJqxSLz01ADGxSN2Ng
7vVrvjXOdBoBS3WRr1g///nPN7jIhRdeWObPyDM18YmBw9zEwHWcjCxCYKCAGDisnvH6OgTEwIFH
mRc7KyAGrqMaschCBMTAJvuEMfD666/PEKOp9zKuy2WXXdYsuX86HUH33XffUkmeffbZdQYxsFL0
TIiBnT2l2vGpC4iBPdWLPycREAOnfoQqcKUFxMBJ6hPLzlNADGxqTxgD06K36667lrorj5Jvltw/
fdVVVz35yU/OzBmLpjmyqBjYb1VeEQNX+rRo45dKQAwcVs94fR0CYuBSHd02ZuECYuA6qhGLLERA
DGyyTxgDU1QaAfPcwFRBeYj8O97xjubYL80Vff/73y/DimbOVBfN2ZoxsLmIaTFw4ac2G9AagVWM
gek1kYGaXzbkJyN0HXTQQaeddtoVV1yhtpyzgBjYmprBjkxFYKYx8B/+4R9SE+bnjDPOmPBIP/PM
M1NOKs9JnnadbcjwiRnpIkXl+dr1FqcJt20qi1966aW/9Vu/lZPGjjvu+OEPf3h0mZ/97GezC5n/
b//2b0fPOeG7IcrZauutt37Vq1714IMPTljahIuLgU3AyWPgL37xize96U2lGsmTI1772td+61vf
ah4UmeHiiy/Op1/myX9mz/9AjYG/+qu/esMNN6ShcPTP17/+9Qxo2tyLtk6LgeV/xm8CkwusYgz8
0z/903F2fOONN07F+5//+Z9trQmXcL/EwHH+M83THYGZxsDTTz+9SB5xxBET1gZvfOMbS1Gf+cxn
Jikq9W0er5aiEqMee+yxSYqa7rLnnXde/a/7tV/7te9973sjyj/33HPLzH/+538+YrbJ3wpRoLKu
F77whXnY3OQFTlKCGNjUmzwGprSf/exnr3nNa+o/Xnp+5uP+wz/8w6OPPjrxf5tttsm3lPLu8573
vES85gZkusbAPLvwV8b7Oeyww3oKaeWfYmD9pzJBYEKBVYyBxxxzTNnrpz/96S95yUvSoaL584IX
vCAP+qksucL24x//uJU14RLulBhY//FMEIjATGPge9/73oKcEDdhbZAgWYq65JJLJikqMbCMjLHD
DjssVQz86Ec/2vyHzJfwjOo/bE/TXFhmfuc73zlsnqm8HqKdd94563rRi14kBk6FdFqFfPvb3950
003z0eT/OW3c6y42zxY88cQTm99Jmv+HmU4S3Guvvb773e/2r+KWW27JCDM984/+M4+z7y+nfa+I
gaP/DbxLYHyBlY6B+Yr10EMPJeU1f1Jj33zzzbmKW6+z5cE9zf727asSl2ePxMDxDz1zdkFgVWLg
1772tXSA/NjHPnbnnXdOUp/85Cc/+fu///sUlRujlqrW7YmB+Xb9uc99btieioEbPDYTjtIFcRhg
C17PF4l06Tz00EPTcpevGRPuUdr1UlqaAtMSHbr8++VxhNtuu23aCv/xH/9xWOHZhvR9yjaM/zPr
bszDNnXOr4uBGzxCzUBgTIGVjoEnnXTSiMontweWG7TT3eK///u/R8zprWkJiIFjHndm64jAqsTA
adUAS1tOjYG1XebFL35xrh8O3GAxcIOHZ+tj4MB/jAlffPjhhzMgTNoZ/+3f/u2222677777Jiyw
s4uLgRs8Qs1AYEyBlY6B6Wsxohr8wQ9+kAtucUiH/G984xvD5nz00UdzAXxghZynvuaG69wjkA4b
UwmSS3V5fBjIJK+LgWMed2briMDCY+ADDzyQ++DSGJGvnZme5OjOsulImRaKO+6445577pmwqESw
VLyppdOAOE5R2fgf/ehHudlqnJn756kx8A1veEMGiin/fieccEL/nHllnBi4PtjsdegSB8p6x+wU
mv6isbrrrrvSw3DgBk/lRfcGToVRIXMQEAM7cgK1m3MQaHEMTObKLdjF8F/+5V9K1XT55ZenAklP
jHSCyisXXnhhHu6z5ZZb/smf/Emz7vrpT3/6gQ98IG894xnPyGXPBMnnPOc5v/u7v/tP//RPzdlK
Cfvtt9+rX/3q3GySrzQ972Yb0j01q3vd6153wQUX5DvAH/3RH2Xmgw8+eNiIXl/+8pfTvT/zvPvd
71652CgGzuGYtYoVElhgDEz0O/zww3Pf9NOe9rRUYmkFy3T6mCUP9lRT+TM9OTNyRSJSetTXd886
66xURH/8x3+ciisjHJ5zzjl77rnnc5/73Gc+85m5BXufffbp78927733ZhUp6i//8i/rzXf/9V//
9frXvz5FZWjTFJ5VZEW5rTsV71ZbbfWbv/mbxx9/fNJlXW/PRJZKHZuNzzgqGcs05ZcbqT7ykY/k
pshsZC7l9SzS/2eNgRm6/+qrrw5I/osyms11113XP/PoGJgLg0cddVQPbEZGTe3XX1R5JXrpcJvh
QNMEGbp0DjzkkEO++tWv5t3sUbZk2L2BGbM0p4/tttsuVs9+9rOz4HHHHZe2pGErmuR1MXASPcvO
U0AMXKGToE1dcoEWx8CMxpxvLPFP19Cc90sd9b73va98IhdddFEGWCi9RvPK/vvvXyuxjHIQloEf
XLr054tH806BnPrzpajM3D9IVx2eLkHy+uuvz5eBDEJeZj7//PPrGpsT+QZVZsgtjc3XV2JaDBz4
b+PFzgosKgYmOuUS1kD2BIqEvp76JIGxzJwR7OtbCW55MeXkKRKJMP2lPelJT8rlsjp/JtLyWBLW
r//6r9chYm688cY8Oi2L55pYNiyj3/cXlSFl+m9LTENhrpvVu7zrUgmPubL3ile8Iq8kTtbGteaW
9EzXGJgYlbfqkDgppD9FjoiBOXEMg82J4JOf/GTPevNnQvTv//7vF4G6C5lIPM+dXLvttlum+2Ng
zjKJigNHCMn9ZR/84Adryu5f4/peEQPX52ap+QuIgc2axDSBSQRaHAMz/HIZujxn7To8eB6PFa58
UcmzJPIdpkznOnkdcT0XpX/jN36jkKYxMbeHf+ITn0hDXtJf/faSK9v1G04qwDQRliHFcspOa2Ot
EvOtJt+4UlRGe/7rv/7r8noNhvvuu2+ds06k80+uFWeRDA6da8719VWZEAPLf47fBIrAQmJgHvqQ
607ZgNQ8iTmnnHJKmu0+9KEPZUDCEkZSAfY05KWJLfPn6WZpfqq1Tfow5MWklTTDZSJ97FNtvv3t
b8+AFWmZyiv5ybu516kuklufSlf8dLyslWT65JftSQtamUirVqrW9MnM5tWUl2bHWk4mctEsOais
JUul8TFXxtLp4vnPf35ezFrK9bcUtY4YmMq5XCQMUSJVc72ZHhYDU9WX7c8GVNjMHNjQ5cXAlhbP
WmAQDjzwwLIXOeOE5c1vfnM6n4SizF/uVeyJgbmGmT4hZakI54zzV3/1V8cee2wGvq5PJM/HWtcy
lQkxcCqMCpmDgBhYKge/CUwusNIxMKetYRVOvo3kNF188v2hXu8tMTCn/nwdSnbLleF8Rck155x2
S1H5clKW2mmnnXILTLP85MryzSEzJBs236rXltPnJ92i8lYu1f7BH/xBKSrfnfKVpsyfQJpruXk9
X2Nyr0ezkEz/67/+a1lkjz32mPrF3p51zeJPMbB8fH4TKALzj4F33313CUqJV+lYXrNYjvd0Mk8X
iNLAlAa15v3OI2Jg2ZH0XWyOaZ/p2uU+lWqtTEbHwBSVoJT561alljv11FNLEkysS8NZLSq9KMuq
c2XsmmuuqT3kc60sfUrLW/m9vhiYtaQlroTiXKzLZtf1ZmJgDMw9feUaXYJYerHWU0bmz7a9//3v
L7AprVmx58JgTjfZzlyNTFthPREkumboyBIe825PDDz77LPLDiYtphtJ3bYsntAaw7ybQJrHkde3
Jp8QAyc3VMJ8BMTAUj/4TWBygZWOgakKPv3pT+fqa/lJd510dkonpVysLs1w8ckZ84YbbqhVU4mB
eT2n5jPOOKO+XibSAFeuzWbxJJqed/NnLrOXE3e6MNUTel5P9EsALB9HgmReyYaV7zYZp7QZJ/O1
J/e5ZM58A8lDintWkTbHsm3pwtTz1kr8KQaW/wG/CRSB+cfAVIBl1bn6VKNTs/aozUzvete76uuj
Y2ACWrMSK0t9/OMfLytKv81azugYmFo3K6ozl4mM+pLqNEWlrq536qVLZHkx/SJyu3TPIql7S1/K
LLXuGJiqOPcClF1Is2PTamAMrOeO9PBsVv5123ITXymtPm0wUTF3U+bFnDX6O+JmjXvvvXdZpBkD
kzcT0vN6LhV+85vfrOXXiZNPPrlEywTJ+uLkE2Lg5IZKmI+AGFjqDb8JTC6w0jFwg7uf02guKTfr
pXoqz5eH/kHn6nkwV5ubS9XpBx98sHTmyZXYntFHr7zyys033zyblO8t+RZRrhunwbHZyaqUk2vC
JUtmzJnm14kUXpbqvzpdN2DJJ8TADf5PmqFTAvOPgaVPe1qm+tNTqT3yvLxyherlL3957SYxOgZm
vJf+micdG0o9lutatXVvdAxMzdZsgqxlpqtn/ivSZ/Kf//mfy4u5G7F02s8Zqs7WnLj00kvLDOuO
gSktbZqlb0Yq6uZjBAfGwKwoGxnYK664orkldbpuUra5wGYQmNJyl2UrdZ0/E2nlLG2IzRhYb2Mc
9s+TIXdKh9hce8xw1s0CJ5mup79xjtDsV7ufGziJpGVnLSAGjnOQmofAOALti4G5TJpbAtMGl06h
ZSi2Zo1UY2AGdmu+nulcmy1DIqTPT/+IoHXmXGMPbL7/9ATMzJCzdjEvZ/ZMDxzmJSONl8bKpz/9
6c1r7F/84hfLd4bmeDV1vSsxIQaOc9CZpzsCw77JT+VwTg/PIpleBKXA3PKWa195sRkretaVjpel
z0MqyTo+54gYmPowVVNPIfkzga7UV6lpaxgZHQOHZbrcK5dtbjaZZRTQsmvNJsvmNqQnf26ayzyT
xMAUWA0zpk19oEZ/DMwo0CUwpivswKcLpahcxyv4uXegpN3aYJobKpsbX6fjVs4Fzc8r40hnv9Jd
JANZ1zl7JkrYz7KJhD1vrftPMXDddBacs4AYWKpHvwlMLrDSMTCJ7POf/3yu4jZ/ckk2vUDr15ue
2qnGwDxcvuetPCQi9wOGNN9tRozInX44hT337PeUkG8m5YpxmSGDguaLQc885c+E0DJPs6dQTZE9
ozcMLGE5XxQDy8fqN4EiMOcYmBbA9EbIqnffffdhNxenp2Ief5N5MuZVvSduRAxMgWm06q9wknTK
eCnjx8BhF7hKfZgYmMG4yore9ra3FcBhUSh7UW5OnDAGpk9IWkXLumpY64+BX/nKV8rOpjPqMNg0
iZabxxMGy6BkJ510Uil5WCf/LFJOGc0YWB4hkRiYQVBjm4+y5yd3jpcInN89nVL6P6bxXxEDx7cy
52IFxMBSsfhNYHKBlY6BGQBhrXVRjYH9IS4XyUuHzzQm1svC/eW/9a1vLeynn356/7v1vJ95Rozk
9oUvfKH0aEr7YykkIwaUbzX5IjHsanP/6pbtFTFw8kNSCW0SmHMMzM3LZdTi3AA4rHJI9ChVTWJg
Ho5TZhsRA9PXvd6y1yxzHTEwd881S6jT/TGw3CWd/4Tm2Mt1/kykO32JSxPGwBSVMVhKxEuqyrMt
8kp/DEzf/g121cgmJc1lmxMDy8MZ6yhh9cG1zV3IdLqg5NaALFJjYOJtHqQ45iGQTerv8dKzivH/
FAPHtzLnYgXEwDGrCLMR2KDASsfAE088ca11UY2B/SHukUceKRdm85Ugo+0NK7k81y8dpTIuTc88
t956a+nhU9gznVd65il/ppWwRM7MU7oPZYzQMmxdBi9tDlYwcPGlfVEM3OARZ4ZOCUwYA2+55Za0
i+Vxe7lw1H/Uv+c97ymYtVNoblsraSX36/XPX15Jt4fav7EMa5zX5xMD039j4Fb1x8Da6SI9PQYu
kjCbxrLs/uQxMOWn936RfOUrX5k0l+f7lD/rYC9f+tKXSlTM8xMHbk9eTA/P8kjBPF/jRz/6UV7J
4DmlnEsuuWTgUtmLnsfH1/bBxPl8rOmzmhszB/7k089wQOX0MbDwtb4oBq5VzPyLEhADS8XiN4HJ
BcTAZj1WxvDM96gRN7+Xi7f5StAcxzuF5PRdq6byLSufTsaUq3fNNFeU6TwEKjMkTpYuoOVrWG4q
HHgbTs+yS/unGDj5IamENglMGAPTabxopLroP+oTUnrerbfmJVykRupfJK9knpJodt111zpuybLF
wFziK7uWhrmBe5Erabm3OvNMJQYmtZXhudIx9e/+7u/OP//8svYaA3MLXnlu7M4775wGu4GblHnK
k2qDX6r9xLdSTv+jCUsJKar0I62tgXm9DIKaYXyGtYQOXPvkL65EDEwn3oyk2j+82+S7r4RxBHK1
PP7DvtWMU8JU5qnftcrx5TcBAusWEAOblVK5KJ1BZvKo5ebrdToDBTzrWc+Kdrr91Avp5d1cQC6D
eGeogSTEcnLPnO973/vq4s2J9D4q/UIPO+yw9EEtjYPbbrvtSp/gxMB1H4kWbKXAhDEwrUiFpefR
6qUmKdktM6RhqLySlqzyYPd0M7j99tubFU6dTrAqHQ+abXPLFgNr/s3oMXXLmxMZxauMdzqVGJiS
84ifUiGn6s5z7Qt7jYG5H7BU6YGtN1Q2tyfTGdYmKTIL5upfeStllnKG9YbNI4pK620zBtYOsWed
dVbPKsqfCfj5x8hzD4Mw7EbFgQuOfnH5Y2BunchTgHPT/bCPYPQOendygZtvvjldyjOUeqqayUtb
dwliYKlY/CYwuYAY2KyI8lD4NM9FNZd863Xy5gz1y0lGOG++nsf4lmvFac677LLL8lbmLN9SMijf
wLv4cz2tXPXN17YMg1AGF82thc1iV25aDJz8kFRCmwQmjIEZmaRoZKiQ/tqg9CfMDGm9qu8mg5RF
BoaIdDj/nd/5ncyQ2ulTn/pUXWrZYmCel1da1hK7+rvoJwclDpTdnFYMDEWeHljKLJV5pmsMzLtl
jOi8OKxpr2xSYOv9AhlqrAzKmsuG9TbMap6JcuExZTZjYJ6aUTYjuzaw2SUdZct5qt5a3ixz3dPL
HwNPPfXUyGSvpxh+183VzQXTGphvR/kU8pjmBQqIgaWK8JvA5AJiYLMqyzm3fLPKSba/Fe/+++8v
z4jP0Hlf+9rX6oKpGDOSW/ks8m2qvl6fJhzk3I9TX68T5UbFXEDOd4AsnsvCAwNjnX/5J8TAyQ9J
JbRJYMIYmAMqCSIgGaclt6c1a4AMklweVJqg0XzIeIZzKYOFpvUql6eai2Q6rUil+SkVXfN6/rLF
wGxb6X6ffU/TQ3PI5USAPD+9/pNMMQamjak8t70W3oyBdSSZXLjruSMgsGmYK7Ave9nLanfchO4a
9JIim3uRRTJuTPlws7pmDMwJJQ1eZRtyb2DPJ5g4WcaQyUmqXHLsmWHdfy55DPzOd76TeB7kjAS+
7n204OQC5SrE85///PQOnby09ZUgBtY6ygSBCQXEwJ5aKGMslK5Buah71FFH5atXHsWVn1w5z/eN
op2mwOY3qPTIKt1B872reeE65+vykN8sNXA0mzy8uH4NyDwZt3zYXSc9G7m0f4qBEx6PFm+ZwIQx
MBXCvvvuW0wy/Egec5Ma6eKLLz7++ONr1dF8entqhqSk9DMviyTUpOkqF5fuuuuu1DZpTClL5dJT
UmSzGlm2GJhty2aXEVeyL6l7M/ByGiBydS4No3klEbg0F04xBmal9XmFBbAZAwObrrnl9dz9neFZ
brrppsCm0svnUmDT2zZjijZhc+6oZ4GcbdPhJHEmu1YXKXc4NmNgFs9pqGT8nIYyzkwGCMqNh1kq
Vw7ztMeyDWm7bJ6Gmitd3/SSx8Ay7GqG6JnuXq/PqstL5eJGue59zDHHLMpBDCyVgN8EJhdYxRhY
vrFk3+tjnsavi3LuLmj9zw2sheRsmJNvtc1wCuUyb3klYs2HEl555ZXl3STBPCy4FlIm0i+r3IaT
6/M9F/PLDOUrTUrO4jnF9yy+cn+KgfXfxgSBCEwYA1MD5Mt/uSttoGcGpSzPJmjWFckmGf6lzp8q
KImp3LaWF3OZK1Vcc/5M1/vR8siJ+lbpX5r6beBTCbKW0pU9VWLtu5hrXyW/pD2rNoolLpU58+Wt
Ft6cOOKII8rWJiU1X0/tWp6TXvelTKQB9GMf+9h2222XP3fcccc0nzWXGjh93nnnlWVHf3fNvQB7
7bVXXV3GaG2WlmE5S0/+MkMq7SZszhoDe/WnBbZ0DS1L1Q8if+ZKYxl6euutt05vk+a6EkiLZFmq
AJbp/M5GlsFIm4tMOL3MMTCj5WTo1AgPe/TGhPtu8TUJ5F86jdH5arSollkxsFYFJghMKLCKMfD9
739/hgrPT0ZlWVPdlZlz10ZZtj+yNYvKFd1cZC5Xm4twvgulF0Q6I+UZ8XXOfGfI16eM7pIy802m
/4aFfBHKBeS8m3kyQ/9lzHztKS2Jue499dN63c65TYiBEx6PFm+ZwOQxMAdvBnvJAxRyl1y9HpUo
l7Gq0lsyg1YNPLpTTSWSJD+WxwhGNfVMWqxyX8+ll17av0g6H6aa2mGHHa666qr67jve8Y68mEVy
j1t9sU5kjKx0gMwMqQPrndTJhglKebE5iESqhTJnT6qqReXxPWXt/WNjZkeybXlgeoJSnnqf4SnS
KpQvn6ls82f2K2/116u15DqRKj2ryM8ZZ5xRXxw4kR622eUyc/84pRml5F3velea5JqweeBgFulp
YG0WnhydU209oWTZfDS5JpnW3lyQzLqSuB966KHmIpm+5ppr9t5773qjYonzCb956O3Auwx6Fl/r
n0sbA3ORoVwvDXL/SXbgbo546FJKGPFuf2lrnb+WsKYFs0lj7lotf90T61tRc3dyVJZB7aZ7d+r4
eyQGtuxEaXcWKLCKMXD8umKSOfPVIjcA5mkOGT88PUJzXbr/ND1J+WXZq6++usTAo48+evLSFl6C
GLjAY9mql1BgKjGwHNd33HFHehR88pOfzPBTiUvDAmCzEkhSywNoLrjgglz1ys1rzVsIm7OtxHSC
Ty6U1RbGH//4x6WJbVgL40x3KmtPv80Km+ETN7i6fItOes11yHx8Wban7W/E4nl2ZJpo87ln6Jjc
kzi7oaSXNgbmLFn65/Rf+M1Bce65555zzjnlGU85KBLzc1d+ei2m02yGTkpsL7Y5FjK26utf//pc
pkhbai5xjHgsVD6sHGsZMHb//fffaaed8jTJXNbIWnKC6/+kcpWmbEPGfc276SyUltyyogzHlAcB
56HA/UuVV3LZJO3Uhx9+eHJuQm7+mTN/br5rXm3uXzbN63kWyev+3092JP9O+bqSbc6IUjnMB160
SSH5R0qf6lxwiEBuvE3VlA0beAklPRCys9EObxbMLcbphZ6lmneqZr2pb3MMDltd/2ZP8RUxcAlP
djZpRQXEwClWTesoqtxsMqzb1ToKXOwiYuCK1gM2e0YCU4yBiz2057z2hL5Enlx8G/YlMy1lpZ9k
vjbPedvaurqljYFvfvObc3gmcfTH7TTyliM3bd+54pEeOz0HcoJYMnsez5Qm15630jibCNb/aSb7
pBG2tvY2l8ptnu9+97t7GhOTvMo8iZlpEU6zdXORTKeo7EJ/4EparHd6NhfJleH0qc5/eP+2pfk4
VUqzj3EWzIFw4IEH5ubfUlryb8+CaaxPQ3x9nHFdVxZMHkw87Jm/DsGU3clDT+qCybZ1zmuvvbZc
wU7vrPri3CbEwPohmiAwoYAYOLeKq39FudOkjB6Qfk2rPjhM2TsxcMLj0eItExAD++u9cV5J202G
Zc7X1DzVfeCtf4ceemj+VdI5dkRTyzgrMk8VWM4YmPbfPIo3n3V6IfZ3yElOKXffpzWtDCiUcVzz
rSZdZ8vrWTCRofRgzOXWFJUxcmuuSRLsaSJPK229YT9FZYCmDNGTkJVcVm7qTPZJb96Klok03pV1
pYdkGSko/bfTtJefuqJsRh4L1bNU7q3L6ykw97dmFWlwzOrKg4nzeroN9zz6M51jszF5q/ykg3T2
JamzxLFMF4EcGs0VJQOm5LJIDqjcbJvol8Fma5bMinoutmTUu8wfnLSHpsPz/7e+X/qlgw8+uJYc
qPLtJaXVNvr67qwnxMD6oZggMKGAGDjr+qq//AxLnn4jGdihDozQHJahf/4VekUMnPB4tHjLBMTA
dVdf9ZteWlLuu+++Wk5SYXrEldskc8thOy6g1b1b4MRyxsD0SCyB5YADDujHSQysQ+7kXyL5Jd0s
E3zyD5MbTutbqVUyEHfal/PMjvSqvfXWW/NnqWqOPfbYZrH10cBJZM0Uls6l6SRZ/uuSJZudNmsM
TIG5LpGR67Jg1lJWVENlOlWm32ZZV9oTy8DjGTsubYLNCx1ZNqOhlm1Lz8zmtn3oQx8qiS/5NIO0
pI90gmGe2pDewrlaUhbJ74S+ulRWVB62mNfTVhiuEqWz/enCWkdDSg7N1talSgxMR9wSVBP00ic5
T6IpfUTLbIl+ib0pNsk3F7TrsvOZqJVD3WsTBAisT0AMnE+t1VxLelbkil8ZJzyfWu47qOPsNWdb
xWkxcH2HoaXaKiAGrrseSw/AfN0t/xjp7Jev5elCn69/aQQpL6bNJZ391l2+BXsEljMGZkjY8nEn
1vVscP5sxsCMnNMzQ2lGzOL5/+kZgS0jjpZMl5hW01kWz1hMmT9v5VzWU1r+TL+dvJvgkyBZ323G
wP4nQyVtlTbBnPTr86SSp8rIPwOzbQYUKo/+7Gl9K30+00iXewDr2stEXUs2rxkDs52lgTKr63+K
6AMPPJALKVkk6TJBr5ZZYmBez08aBIddaamzZQiFuux8JsTA8un4TWByATFwPrVWcy377LNP/eDS
byRDrDffXelpMbB+siYIREAMnKRCS8rLGWrgP1LaVjJQxiSFW7ZHYDljYG3MGji4d42BiUjpSNyz
RxkrpvzzZHDXnrfSJ6fko7TK1ca4tJ1lhJkMopI76ZqtY3XZdN1MgQmJzfvpagxM2Gw+TKoulUFm
slTCYB4ZWV783ve+l2FhMsTLZZddVmerE9/+9rfLtqVZsL6YLkOlcTMJqL7YnMhNsmVnmzEwg7oM
EyjLZpijPPoh8+RpyLW0mu+23XbbtJ/W13sm/uZv/qYU3ny8Zs88M/pTDCzyfhOYXEAMnFE1NaLY
DNiecbdyp3luLR9Rx44oYWnfEgMnPySV0CYBMXDCyipjxeRrdr7i5otfOvKlH1r6iGYUx1k8MWHC
TV31xZczBpZ0k+aqdH3sF64xMJcF+t+t98T1N1el72iJWhk6JmPI9C/bfCXNYelFmUFR0gCd2mlY
DHzta1/bXKpOp8NPlkrX1tFP2UujZLJnNiapqiS+tIDXQjIGTqkY04m0vticSOFlhmYMLF1SE/TS
pbM5c53OLX7FodkvtMbAPNeyztk/kWFvyxrTTN//7kxfEQOLvN8EJhcQA2daWXWtcDFw8kNSCW0S
EAO7Vgeu7v4uYQxM81w6RqZCyBgseWxEv22NgXmaZP+7dUCV/hCUR0uMiIHJfXmcRJ43kau1KWTP
PffMzXel1SwbMywGHnPMMf3bkFdK/5905swjqHpmyF11efjL2Wef/Za3vCWtkMlizVFlagyMQ+4l
yaoTD3OHY08h5c+0MGbDMk+Ngbl9rzxbM68feeSRp5xySj7inp+0k2bDslSGmql9VmsM7O9n21x1
LmiXB3nksRrN1+cwLQbmI/NDYCoCYuAcqqzurEIMnMpRqZDWCIiB3an9Vn1PExDGP+6SLEY8d29a
FBnspWSoxJ+e0SzLKhIDyyid6WDTv9IaA/s3dVgMTJNcHpGQnqJ1IM1qkqbAktGGxcBhB/vAGJih
XRIbc/drSVJ1LSk8Q3eWx1XUGFgdMnMGl+vf07ySRFkaK2sMzDg5ZTDPWviIiYwyWkeAqTHwrLPO
Griu8uJVV12VrU2ZaaYfMdss3hIDR3yU3iKwJgExcBZ1VGfLFAPXdPSZufUCw74ZdraKsONLK7CE
MTCtcnmEX2qJZL2BPSprDHzrW9/aD7uOGJgHrNdWvySj9OdMO1pGpk02zH1/6faZjcn4Lbl9r66u
3huY0VTqi82J/hiYdrcyUmjZtTzPIiW/7W1vy2Ck6Xqa9r7SUrnffvuVchIDi0NGIs1djc3C63SC
bRl3rsbAJM3yCIkM+Jmi0mCaJsVhP8mkdTzeGgPPPPPMWn7/RPpmlxiYoUT7353pK2Jg60+ddnBu
AmLgTCurrhUuBs7tyLWilRAQA7tWB67u/i5hDEzbXBmVJfcGpvNkv+10Y+A3vvGN0kMy6SZRKLmv
Z6CYDOyZamfCGJgenhmCplRfeTjml7/85YzY2Xy4fDajPK2vxsA4lASaVtGBj5WPTB4fX9oQawzM
CORbbbVVVpRQmbbUrHfgT7/qmDHws5/9bLmHsedJhf0FTv0VMXAlTn82ciUExMCpV1BdLlAMXImj
3kbOTUAM7HJ9uFr7voQxMIBHH310OVozpmW/53Rj4GmnnVbWdcghh/SvK6+Upw0mJA4cKXTM1sA8
gjDj0mRFKWfgaLe5C7K0stVOoVl1mjvLtuWOxYHbVp+sUWNgZittjglrV1555cClEjCzLwmezRHL
x4yB9RmL86/lxMDyz+A3gckFxMCBdaMX1ycgBk5+SCqhTQLz/4K0viPXUgSWMwZm+JRSIWSi/zOa
bgxMq1ZZVzpn9q8rjYOl1+WEMTBPMCw3HuYJmImE/SvKQyvKZjRjYFJweXZ8emA2mw7L4uk9u/vu
u5elmjEwHU3Li8cee2z/ivJKHsORLqPpa5q4XWcYMwaed955pfD0pK3LzmdCDCzyfhOYXEAMnE+t
1ZG1iIGTH5JKaJOAGNiRqq8Fu7mcMTB9QRNSUicMfHjBdGNgbXHrb9dL79DcVVeqpsTAPK69fuJr
vTcwj4TIIDApKgPO1FFZamkZTbSM9JIZmiNw1hFgsvYLL7ywzl8mEsRK/8ws1YyBaW1MysuLeXx8
f8tjnpqR2xLzboSbzYVjxsAoZdncttlctmfDZvSnGBh5PwSmIiAGzqia6maxYuBUjkqFtEZADOxm
TbiKe72cMTBRpYxzsvPOO6fNqwd2ujEwjyYsLW5p9bv44ovzwIWsLk8MzEPeywgtm2yySaqmjCFz
xRVX5K3capffa42BKbbc6JeicvdfHfnz1ltv/eAHP1h2tmS6PHc+z8csa8mKap/V3MCYJ1nkJsHc
D/jFL37xjW98Y7JYFimDjjZjYJbNEDelOn3e856Xu/nKODB5YHEGeMnzKcpbGUunriUrGicGZtSa
8lDCPJMi9zZmqXn+iIHlg/ObwOQCYuA8667Wr0sMnPyQVEKbBMTA1ld6rdnB5YyB4U03yNQJyUcJ
Sj3aiYEluOW5ez1v5c8EolKZjHhgRAZpqY+PT0A76KCDyiJpIEtuetGLXpS2uRLKEtk+8IEPlHcz
hEs6YZYFEwPLNgw72EuE3HzzzetzA3MvXn0+YMZv2XbbbfNcwjIsTBr7Mj5nMm9WlPU+61nPqg/v
S1/QjC1TBrHJu5kznUtLU2mm8wTAMr5oMl2TIv1Oa2hKTswjJF74whdmp8p4Miknaa4nx9W8OWKk
0Ax2Wja4J0I2Vz276bpH5ePwmwCBdQuIgbOrqTpYshi47iPRgq0UGPbNsIOVg11ecoGljYG5fy2V
QzJRQl+PYbqMZtzOhKC3v/3tPW/lzzST5a38DOwPmYSVtzKISprG6rL33nvv4Ycfnteb1VESaJLR
I488kjl32WWX8qTCBLf7778/C6atsGzDO9/5zlpOc+LVr351CkwLYzONfuELX9huu+1Kfizryg7u
tttuGTg0y37qU5+qDy7M/X3N0vK0vle96lVJkWmUzCIpOYE0bYK333576f953HHHNefPdJoU03pY
g2fdteS4VFBlL5qLpItpis3Pueee23y9OZ1nx6ecbP/AoXuac85iWgysH6IJAhMKiIGzqKM6W6YY
OOHxaPGWCYiBna0MV27HlzYGZmyWPGY9NcNhhx3Wo5puomnJSpBJ0ul5K38muOWt/PSPqZIRMtOW
l7ceeuihZn/IUkie3JcolLsRE8FyI14GdamFZ3Wf+cxnPvKRj1x33XUpJK/Xbeh5ukRdJO1xWVEW
7NmMvHjRRRclwGZFeTRh2gqbvV7zaMKPfvSjCVl5IGAtqkyknATSm2++OduQuwvLUhnws4TKdOns
mb/8eeedd2azs640kma/UnheGThnnjSRbctPJgbOkBcPPvjgfCLpEZqnEw6bZ3avi4EtO1HanQUK
iIGzq6k6WLIYuMBj2aqXUEAM7GA1uKK7vLQxMJ5lNJJ0euwfU2VFtde62bkXLy2VCaTJtgOXTTgt
FWAaTwfOMMUX8wj7dC7N6tJIOsVixy9KDFzCk51NWlEBMXD8msecGxQQA1e0HrDZMxIQAzdYaZhh
SQSWOQZmoJg0POUgPeWUU5aEa86bkee/Z1TPtIoeccQRA1ddBjJNUv7Wt741cIYpvpjbFfNZZLzT
ZjvpFMvfYFFi4IxOWIrtoIAYuMEKxwzjC4iBHaxD7PIIATFw/NrDnIsVWOYYGJk0cuVuuNyRt5Be
iIv9aLL29Dgtj5nIEDEZlKa5PRnZ5sMf/nAZ8mWvvfYqXVWbM0x3Or1bSx/ddDGdbsnjlyYGjjjp
eIvAmgTEwPFrHnNuUEAMXNPRZ+bWC4iBG6w0zLAkAkseA3OfWoZGSY2R4TqXRGzOm5FxO0uFmUFH
88iJdMj80Ic+lHFpMkRMxorJW+mo+c1vfnPWW1UeJ7HHHnskfs56XcPKFwNbf+q0g3MTEAOH1TNe
X4eAGDi3I9eKVkJADFxHNWKRhQgseQyMSUZBSVtYxu3sZoNgBDKeTH1gRE8FuM0225RRRmf6z5Px
auKfQURvuOGGma5odOFiYM+n708C6xYQA0fXNt5dk4AYuO4j0YKtFBAD11SBmHmBAssfA4OT5yxk
DM88HGGBUItd9Y033piHJObBgumZmWdApJfsPvvsk06huX1yDhuWIXpyY2AeQz+HdY1YhRjYytOl
nVqIgBg4oqrx1loFxMCFHMVWurQCYuBa6xDzL0pgJWLgonCWbb15yEWeE5GOsj0PoVi27ZzR9oiB
S3vKs2ErJyAGzqia6maxYuDK1QA2eKYCYmA3a8JV3GsxcBU/tW5usxg409OWwjslIAZ2sxad0V6L
gZ2qPezsBgXEwBlVNYqduoAYOHVSBc5IQAzc4KnHDATGFBADZ1RNdbNYMXDM485sHREQA7tZE67i
XouBq/ipdXObxcCOnEDt5hwExMBu1qIz2msxcA7HrFWskIAYOKOqRrFTFxADp06qwBkJiIErdBK0
qUsuIAbOqJrqZrFi4JIf7zZvzgJiYDdrwlXcazFwFT+1bm6zGDjnE5nVtVhADOxmLTqjvRYDW1xX
2LV1CIiBM6pqFDt1ATFw6qQKnJGAGLiOk5FFCAwUEANnVE11s1gxcOBR5sXOCoiB3awJV3GvxcBV
/NS6uc1iYGdPqXZ86gJiYDdr0RnttRg49SNUgSstIAbOqKpR7NQFxMCpkypwRgJi4EqfFm38UgmI
gTOqprpZrBi4VEe3jVm4gBjYzZpwFfdaDFzFT62b2ywGLvzUZgNaIyAGdrMWndFei4GtqRnsyFQE
xMAZVTWKnbqAGDh1UgXOSEAMnMrpSSEEIiAGzqia6maxYqBahUBTQAzsZk24instBq7ip9bNbRYD
m2cZ0wQmERADu1mLzmivxcBJDkbLtk9ADJxRVaPYqQuIgVMnVeCMBMTA9p0r7dGiBMTAGVVT3SxW
DFzUgWy9yykgBnazJlzFvRYDV/FT6+Y2i4HLeb6zVasoIAZ2sxad0V6LgatYCdjm2QmIgTOqahQ7
dQExcOqkCpyRgBg4u3OWkrsmIAbOqJrqZrFiYNcqEPs7WkAM7GZNuIp7LQau4qfWzW0WA0efd7xL
YHwBMbCbteiM9loMHP/QM2cXBMTAGVU1ip26gBg4dVIFzkhADOzC2dM+zkdADJxRNdXNYsXA+Ry2
1rIqAmJgN2vCVdxrMXAVP7VubrMYuCpnQNu5/AJiYDdr0RnttRi4/Ie8LZyngBg4o6pGsVMXEAOn
TqrAGQmIgfM8i1lXuwXEwBlVU90sVgxsd3Vh79YqIAZ2syZcxb0WA1fxU+vmNouBaz0TmZ/AMAEx
sJu16Iz2WgwcdqB5vZsCYuCMqhrFTl1ADJw6qQJnJCAGdvN8aq9nISAGzqia6maxYuAsDlJlrq6A
GNjNmnAV91oMXMVPrZvbLAau7jnRli+bgBjYzVp0RnstBi7bAW57FisgBs6oqlHs1AXEwKmTKnBG
AmLgYs9r1t4mATFwRtVUN4sVA9tUOdiXyQXEwG7WhKu412LgKn5q3dxmMXDyc5MSCBQBMbCbteiM
9loMVLEQaAqIgTOqahQ7dQExcOqkCpyRgBjYPMuYJjCJgBg4o2qqm8WKgZMcjJZtn4AY2M2acBX3
WgxcxU+tm9ssBrbvXGmPFiUgBnazFp3RXouBizqQrXc5BcTAGVU1ip26gBg4dVIFzkhADFzO852t
WkUBMXBG1VQ3ixUDV7ESsM2zExADu1kTruJei4Gr+Kl1c5vFwNmds5TcNQExsJu16Iz2WgzsWgVi
f0cLiIEzqmoUO3UBMXDqpAqckYAYOPq8410C4wuIgTOqprpZrBg4/qFnzi4IiIHdrAlXca/XGgNv
uummVdxN29wCgQMOOKALpw/7SGAOArvtttvjjz/egmrBLiyDwG233bbxxhvP4f/WKgishMAJJ5yw
DAembSCwQYGTTz55/GNqs802++pXv/qLX/ziUT8E5iuQ/7r9999//P9VcxIgMEJgl112eeSRR+Z7
EFtbOwVSOd9yyy1i4IjDzVtdEzj++ON9VW5nfdeuvXrsscdOPPHE8Q/PJzzhCdtvv/3OO+/8Mj8E
5iuQb61bbLHF+P+r5iRAYITAU57ylJ122mm+B7G1tVMgXwl22GGHjTbaaMT/m7cIdEpgyy239FW5
nfVdu/YqX6232mqrTh2bdpYAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIE
CBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAg
QIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAA
AQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIE
CBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAg
QIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAA
AQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIE
CBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAg
QIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAA
AQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIE
CBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAg
QIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAA
AQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIE
CBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAg
QIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAA
AQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIE
CBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAg
QIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAA
AQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIE
CBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAg
QIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAA
AQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIE
CBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAg
QIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAA
AQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIE
CBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAg
QIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAA
AQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIE
CBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAg
QIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAA
AQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIE
CBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAg
QIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAA
AQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIE
CBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAg
QIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAA
AQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIE
CBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAg
QIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAA
AQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIE
CBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAg
QIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAA
AQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIE
CBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAg
QIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAA
AQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIE
CBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAg
QIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAA
AQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIE
CBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAg
QIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAA
AQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIE
CBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAg
QIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAA
AQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIE
CBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAg
QIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAA
AQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIE
CBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAg
QIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAA
AQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIE
CBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAg
QIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAA
AQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIE
CBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAg
QIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAA
AQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIE
CBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAg
QIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAA
AQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIE
CBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAg
QIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAA
AQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIE
CBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAg
QIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAA
AQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIE
CBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAg
QIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAA
AQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIE
CBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAg
QIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAA
AQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIE
CBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAg
QIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAA
AQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIE
CBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAg
QIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAA
AQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIE
CBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAg
QIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAA
AQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIE
CBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAg
QIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAA
AQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIE
CBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAg
QIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAA
AQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIE
CBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAg
QIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAA
AQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIE
CBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAg
QIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAA
AQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIE
CBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAg
QIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAA
AQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIE
CBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAg
QIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAA
AQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIE
CBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAg
QIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAA
AQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIE
CBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAg
QIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAA
AQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIE
CBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAg
QIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAA
AQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIE
CBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAg
QIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAA
AQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIE
CBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAg
QIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAA
AQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIE
CBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAg
QIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAA
AQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIE
CBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAg
QIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAA
AQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIE
CBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAg
QIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAA
AQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIE
CBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAg
QIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAA
AQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIE
CBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAg
QIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAA
AQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIE
CBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAg
QIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAA
AQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIE
CBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAg
QIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAA
AQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIE
CBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAg
QIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAA
AQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIE
CBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAg
QIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAA
AQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIE
CBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAg
QIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAA
AQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIE
CBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAg
QIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAA
AQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIE
CBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAg
QIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAA
AQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIE
CBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAg
QIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAA
AQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIE
CBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAg
QIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAA
AQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIE
CBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAg
QIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAA
AQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIAAAQIECBAgQIDA/22H
jgUAAAAABvlbT2NHIWTAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwY
MGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDA
gAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAED
BgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwY
MGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDA
gAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAED
BgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwY
MGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDA
gAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAED
BgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwY
MGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDA
gAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAED
BgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwY
MGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDA
gAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAED
BgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwY
MGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDA
gAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAED
BgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwY
MGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDA
gAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAED
BgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwY
MGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDA
gAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAED
BgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwY
MGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDA
gAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAED
BgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwY
MGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDA
gAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAED
BgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwY
MGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDA
gAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAED
BgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwY
MGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDA
gAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAED
BgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwY
MGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDA
gAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAED
BgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwY
MGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDA
gAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAED
BgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwY
MGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDA
gAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAED
BgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwY
MGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDA
gAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAED
BgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwY
MGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDA
gAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAED
BgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwY
MGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDA
gAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAED
BgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwY
MGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDA
gAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAED
BgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwY
MGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDA
gAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAED
BgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwY
MGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDA
gAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAED
BgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwY
MGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDA
gAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAED
BgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwY
MGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDA
gAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAED
BgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwY
MGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDA
gAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAED
BgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwY
MGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDA
gAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAED
BgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwY
MGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDA
gAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAED
BgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwY
MGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDA
gAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAED
BgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwY
MGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDA
gAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAED
BgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwY
MGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDA
gAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAED
BgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwY
MGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDA
gAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAED
BgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwY
MGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDA
gAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAED
BgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwY
MGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDA
gAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAED
BgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwY
MGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDA
gAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAED
BgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwY
MGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDA
gAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAED
BgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwY
MGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDA
gAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAED
BgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwY
MGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDA
gAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAED
BgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwY
MGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDA
gAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAED
BgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwY
MGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDA
gAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAED
BgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwY
MGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDA
gAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAED
BgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwY
MGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDA
gAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAED
BgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwY
MGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDA
gAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAED
BgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwY
MGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDA
gAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAED
BgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwY
MGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDA
gAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAED
BgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwY
MGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDA
gAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAED
BgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwY
MGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDA
gAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAED
BgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwY
MGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDA
gAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAED
BgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwY
MGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDA
gAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAED
BgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwY
MGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDA
gAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAED
BgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwY
MGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDA
gAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAED
BgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwY
MGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDA
gAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAED
BgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwY
MGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDA
gAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAED
BgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwY
MGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDA
gAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAED
BgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwY
MGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgwYMGDAgAEDBgx8BgIAUNBLCmVuZHN0cmVhbQplbmRv
YmoKMzQgMCBvYmoKMzQ4MzAKZW5kb2JqCjM2IDAgb2JqCjw8IC9MZW5ndGggMzcgMCBSIC9UeXBl
IC9YT2JqZWN0IC9TdWJ0eXBlIC9JbWFnZSAvV2lkdGggMTE5NyAvSGVpZ2h0IDEzMjgKL0NvbG9y
U3BhY2UgL0RldmljZUdyYXkgL0ludGVycG9sYXRlIHRydWUgL0JpdHNQZXJDb21wb25lbnQgOCAv
RmlsdGVyIC9GbGF0ZURlY29kZQo+PgpzdHJlYW0KeAHsnXdgFMUXxyeNJJDQkV6lBgFp0psUaaIi
igoqoD9FLCAWLCiKIFiwCyhFqijVQpcOClKk915CCSUkpJd7vzezu3c3ySUbkktys/fmj9uZ2ZnZ
me/b+dzM7NweY+RIAVKAFCAFSAFSgBQgBUgBUoAUIAW8TYGijVu3sqir7uttxjRvb+WWVjF268bF
zJtr4RR+Na1iSbN2tK4VoNmx9ZHkFKu6hO8LWfhmzU7TAkbHWMfYycc7ZkcDi+Qp+nOidUxp0pKk
X0txqxXaA1Z2T1jkznRXMzpby9jHCrpLGPXKeddapjRpzRhuoIqJJqnUPj1evZswV2v8itrmTFv7
uLBcVcujC1+cVgxLh3/3QWNUszasJnj0/Zb3lRturTs69u68l9BTrrjEWqY0ac1Svvxc1dqw+txT
bi0PqcerJveEYqdjG3iIrvlQDe+C1Z8Eq3y4x/L3kgSr/NXfjVcnWCn2zWpaXRpZyd2DYCXroXCI
YGXa+xVLQLCSuyPBStZD4RDBSjEWmVaXYCV3R4KVrIfCIYKVae9XLAHBSu6OBCtZD4VDBCvFWGRa
XYKV3B0JVrIeCocIVqa9X7EEBCu5OxKsZD0UDhGsFGORaXUJVnJ3JFjJeigcIliZ9n7FEhCs5O5I
sJL1UDhEsFKMRabVJVjJ3ZFgJeuhcIhgZdr7FUtAsJK7I8FK1kPhEMFKMRaZVpdgJXdHgpWsh8Ih
gpVp71csAcFK7o4EK1kPhUMEK8VYZFpdgpXcHQlWsh4KhwhWpr1fsQQEK7k7EqxkPRQOEawUY5Fp
dQlWcnckWMl6KBwiWJn2fsUSEKzk7kiwkvVQOESwUoxFptUlWMndkWAl66FwiGBl2vsVS0Cwkrsj
wUrWQ+EQwUoxFplWl2Ald0eClayHwiGClWnvVywBwUrujgQrWQ+FQwQrxVhkWl2CldwdCVayHgqH
CFamvV+xBAQruTsSrGQ9FA4RrBRjkWl1CVZydyRYyXooHCJYmfZ+xRIQrOTuSLCS9VA4RLBSjEWm
1SVYyd2RYCXroXCIYGXa+xVLQLCSuyPBStZD4RDBSjEWmVaXYCV3R4KVrIfCIYKVae9XLAHBSu6O
BCtZD4VDBCvFWGRaXYKV3B0JVrIeCocIVqa9X7EEBCu5OxKsZD0UDhGsFGORaXUJVnJ3JFjJeigc
IliZ9n7FEhCs5O5IsJL1UDhEsFKMRabVJVjJ3ZFgJeuhcIhgZdr7FUtAsJK7I8FK1kPhEMFKMRaZ
VpdgJXdHgpWsh8IhgpVp71csAcFK7o4EK1kPhUMEK8VYZFpdgpXcHQlWsh4KhwhWpr1fsQQEK7k7
EqxkPRQOEawUY5FpdQlWcnckWMl6KBwiWJn2fsUSEKzk7kiwkvVQOESwUoxFptUlWMndkWAl66Fw
iGBl2vsVS0CwkrsjwUrWQ+EQwUoxFplWl2Ald0eClayHwiGClWnvVywBwUrujgQrWQ+FQwQrxVhk
Wl2CldwdCVayHgqHCFamvV+xBAQruTsSrGQ9FA4RrBRjkWl1CVZydyRYyXooHCJYmfZ+xRIQrOTu
SLCS9VA4RLBSjEWm1SVYyd2RYCXroXCIYGXa+xVLQLCSuyPBStZD4RDBSjEWmVaXYCV3R4KVrIfC
IYKVae9XLAHBSu6OBCtZD4VDBCvFWGRaXYKV3B0JVrIeCocIVqa9X7EEBCu5OxKsZD0UDhGsFGOR
aXUJVnJ3JFjJeigcIliZ9n7FEhCs5O5IsJL1UDhEsFKMRabVJVjJ3ZFgJeuhcIhgZdr7FUtAsJK7
I8FK1kPhEMFKMRaZVpdgJXdHgpWsh8IhgpVp71csAcFK7o4EK1kPhUMEK8VYZFpdgpXcHQlWsh4K
hwhWpr1fsQQEK7k7EqxkPRQOEawUY5FpdQlWcnckWMl6KBwiWJn2fsUSEKzk7kiwkvVQOESwUoxF
ptUlWMndkWAl66FwiGBl2vsVS0CwkrsjwUrWQ+EQwUoxFplWl2Ald0eClayHwiGClWnvVywBwUru
jgQrWQ+FQwQrxVhkWl2CldwdCVayHgqHCFamvV+xBAQruTsSrGQ9FA4RrBRjkWl1CVZydyRYyXoo
HCJYmfZ+xRIQrOTuSLCS9VA4RLBSjEWm1SVYyd2RYCXroXCIYGXa+xVLQLCSuyPBStZD4RDBSjEW
mVaXYCV3R4KVrIfCIYKVae9XLAHBSu6OBCtZD4VDBCvFWGRaXYKV3B0JVrIeCocIVqa9X7EEBCu5
OxKsZD0UDhGsFGORaXUJVnJ3JFjJeigcIliZ9n7FEhCs5O5IsJL1UDhEsFKMRabVJVjJ3ZFgJeuh
cIhgZdr7FUtAsJK7I8FK1kPhEMFKMRaZVpdgJXdHgpWsh8IhgpVp71csAcFK7o4EK1kPhUMEK8VY
ZFpdgpXcHQlWsh4KhwhWpr1fsQQEK7k7EqxkPRQOEawUY5FpdQlWcnckWMl6KBwiWJn2fsUSEKzk
7kiwkvVQOESwUoxFptUlWMndkWAl66FwiGBl2vsVS0CwkrsjwUrWQ+EQwUoxFplWl2Ald0eClayH
wiGClWnvVywBwUrujgQrWQ+FQwQrxVhkWl2CldwdCVayHgqHCFamvV+xBAQruTsSrGQ9FA4RrBRj
kWl1CVZydyRYyXooHCJYmfZ+xRIQrOTuSLCS9VA4RLBSjEWm1SVYyd2RYCXroXCIYGXa+xVLQLCS
uyPBStZD4RDBSjEWmVaXYCV3R4KVrIfCIYKVae9XLAHBSu6OBCtZD4VDBCvFWGRaXYKV3B0JVrIe
CocIVqa9X7EEBCu5OxKsZD0UDhGsFGORaXUJVnJ3JFjJeigcIliZ9n7FEhCs5O5IsJL1UDhEsFKM
RabVJVjJ3ZFgJeuhcIhgZdr7FUtAsJK7I8FK1kPhEMFKMRaZVpdgJXdHgpWsh8IhgpVp71csAcFK
7o4EK1kPhUMEK8VYZFpdgpXcHQlWsh4KhwhWpr1fsQQEK7k7EqxkPRQOEawUY5FpdQlWcnckWMl6
KBwiWJn2fsUSEKzk7kiwkvVQOESwUoxFptUlWMndkWAl66FwiGBl2vsVS0CwkrsjwUrWQ+EQwUox
FplWl2Ald0eClayHwiGClWnvVywBwUrujgQrWQ+FQwQrxVhkWl2CldwdCVayHgqHCFamvV+xBAQr
uTsSrGQ9FA4RrBRjkWl1CVZydyRYyXooHCJYmfZ+xRIQrOTuSLCS9VA4RLBSjEWm1SVYyd2RYCXr
oXCIYGXa+xVLQLCSuyPBStZD4RDBSjEWmVaXYCV3R4KVrIfCIYKVae9XLAHBSu6OBCtZD4VDBCvF
WGRaXYKV3B0JVrIeCocIVqa9X7EEBCu5OxKsZD0UDhGsFGORaXUJVnJ3JFjJeigcIliZ9n7FEhCs
5O5IsJL1UDhEsFKMRabVJVjJ3ZFgJeuhcIhgZdr7FUtAsJK7I8FK1kPhEMFKMRaZVpdgJXdHgpWs
h8IhgpVp71csAcFK7o4EK1kPhUNeCKsqSYrh5/aq+5nCd2NuVH3Y7cnn6alj6+WGSGqU6V2w+sMH
rVI03NNvyBzV72U1brw8q+WjOVLT4zJfLZFnynnchb71OGvkZoV+4Pr7PH8rN6+Rz2VvKe9x91j+
VqjI0ny2iFsvHzMsf9XM16vX2u9WLT27sAP6ELrFcy/mkRv8J1fkcJ5db0jfkvl6O3nixUN7D8lt
az8/kZv5ypsv5PaF/tfKExXOszqVeyK3BU5b/nM/c8ueGJrrt1DaC/evkGeq2i80grd1hT1IHmsq
0JGb+UhBazbOq1v1NLfsJu+QYCRv62rvaKsXt7I7N/NRL15Osqzt/8ctuyXIsu1zbhjBylkNy/oJ
VlY1rTfB6j0OZhpZWfVWNtpFsDKUsNqRYGU1i3p9ewhWVr0FCFZWtazXtotgZVXTE6ysalmvbRfB
yqqmJ1hZ1bJe2y6ClVVN73WwWmVVS1K7dAUIVla9FbwJVu/zp4EEK6veyka7CFaGElY7EqysZlGv
bw/Byqq3AMHKqpb12nYRrKxqeoKVVS3rte0iWFnV9N4Eq1G0ZmXV29i5XQQrZzWs5CdYWcma1BZU
gGBl1duAYGVVy3ptuwhWVjU9wcqqlvXadhGsrGp6gpVVLeu17SJYWdX0BCurWtZr20WwsqrpCVZW
tazXtotgZVXTexOsPqCtC1a9jZ3bRbByVsNKfq+D1UorWY/a4kIBgpULUSwRRbCyhBmpEQ4FCFYO
Lazl8yZYfcingTSystYNnL41BKv0mlgjhmBlDTtSK+wKEKzsUljMQ7CymEGpOQQrq94DBCurWtZr
20WwsqrpvQ5Wa6xqSWqXrgDByqq3gtfBihbYrXorG+0iWBlKWO1IsLKaRb2+PQQrq94C3gSr0bR1
waq3sXO7CFbOaljJ73WwWmEl61FbXChAsHIhiiWiCFaWMCM1wqEAwcqhhbV8BCtr2ZNaQ681tuw9
QLCyrGm9tWE0srKq5QlWVrWs17aLYGVV03sTrD7iTwNpgd2qt7LRLoKVoYTVjgQrq1nU69tDsLLq
LeB1sFpuVUtSu3QFCFZWvRUIVla1rNe2i2BlVdN7E6zG8DUrGllZ9VY22kWwMpSw2tHrYLXMahak
9qRRgGCVRhDLBAlWljElNURTgGBl1TuBYGVVy3ptuwhWVjU9wcqqlvXadhGsrGp6gpVVLeu17SJY
WdX0BCurWtZr20WwsqrpvQlWY/nWBXoaaNVb2WgXwcpQwmpHr4PVUqtZkNqTRgGCVRpBLBMkWFnG
lNQQTQGClVXvBIKVVS3rte0iWFnV9AQrq1rWa9tFsLKq6QlWVrWs17aLYGVV03sTrD7mTwNpgd2q
t7LRLoKVoYTVjl4Hqz+tZkFqTxoFCFZpBLFMkGBlGVNSQzQFCFYmd4Kfb/oEvn7p4zwuhmDlcSah
CuVMAUVgVbq34R7oVDcPUeE7cma19AKXmjbGP32sh8V4E6zG8TUrmgZ62B3o9uooAitRTX5HAiRd
2fpYnuGqD2wJMjQvMfPneprfbx70NWI99uh1sPrDY01BFXOPAorAqpsGKv3T9qmLuZl79JBLKX3Y
1sUe8xTAfXqgUdSZivZ4D/UQrDzUMFSt7CqgDqzW39u2Xbt2nR5+/yBASq/stvf28o2CDcFGjoIb
IKmzHvCZA9/5GCc89Eiw8lDDULWyq4A6sPrFaGL5Zbg+kSdrRmFXoZ9+1cBGvwIkGrBizZNj2xj1
8dAjwcpDDUPVyq4C6sBqvp1PPZLhYOnsNvg28vlOgUOFeHr/537aHodTUAesgjbCH3k0Fb2NCktJ
CVaSHBRQXwEVYVXrGpysrEtf4r53v3i/1x12Q/g1/N+470Y+VcMxSSv+yDe/THq9tR11FZ7+/tcZ
79yjh4s3b16SFWjx5hdjHi9jL0T31IqEt4Q35Iy2WOaAFXvFltgqbXrPChOsPMseVJscK6AirFrE
wfYQreV99wmMHHupoBauNZuPgAAifzBo1muviEicU0ekKDDsvAgnz60pwg8BPFB7gYg6Ziyfa0Ux
NhziWgh/0GcLFiyYd8lpZMXqXIfvjHSeefQmWI3nBvzdM+1AtXKbAgrBytiv4IO7aiYIAfxGpwKc
3R+Od+pvRXhMDSTT+e2bdkcBbC0rkgxNBDi1Y380wHY+/AqchHsfTvz97xWAk2LR6SFI/fwIxJw8
nYSEayqyGB8+q+FQSSOAxxXOsPLdCTvEJZ0SeJaXYOVZ9qDa5FgBdWC1IMifu8BqXyXDYY1ELwBc
GFSlUM1HjgN8y6WYDbZvq/mwAs3WA7zAI9rGQPybFXwKtVgH8AWGX7bB+Ycxc90pAEf5uheOrJJg
VqtyFbsfAfiJZ7G7yhfkfYYSrNjXENfQntQTPQQrT7QK1SkHCqgDq4iNGzZsWP/3ERw1rQoTLa56
Hq41E77G5yEK40IOwD/aWtQ9MTATzwSshNQ3RYoaF+BwICt/Ca7fK8L+PwO8gz6EFXwvlso7xcLe
UHFO/3ggFT5wDsuw6gsw2Pmsx/kJVh5nEqpQzhRQB1ZIFcMtay4a/SrA+3rr3wYYwljl5f/hJ3cV
z8BfeGgSDUeKiQg22Xa9IcMcX2lB1jwadgUKWJ3SlrcC98DpSvpJcXgZYKBzWIZVa4Bpzmc9zu91
sPrN40xAFXKvAurA6sKSRYvRLdt6E+DWS6iCz0pI1oZYOK1LgB98mI+P8RCwVwysxiTPOIhSZ9CA
iux3iNcGVowV3AVXcM0dR1bG5G8jXNIW4XWFRwH0dhZbhlXTJA//OxWClbPxyG8BBdSB1Xxtgd0v
tPoHCZDQASd9l+H6oB73c9fz8RhYoW2JqtKi74hJa26AgNWXAIOcjFR0N1wob4SXQ3x7AavResxq
uHKXcZIfvwXAqzicDKu6N2CH45wH+rwJVp/wMTeNrDzwLnRrlZSDFW89jnlW4qQPh1hO7l/+cO6h
FRdFVEIShxX+KgZ6OMlV6QQcxamf5mZDalcBq7f1iDSw8vsFbHcbiflRhlW1c3DSeD7pnMpj/AQr
jzEFVcQ9CigEK/u2TlbrOpwvyGpFQdy+3YbbM6cwC/iSb0DYv2HOi53PwyrGfOcDtHXSqcop2G8P
LoZbuK0Tp4Ej9Kg0sApYDLZG9tToSQerI8ak0zmVx/gJVh5jCqqIexRQElblj8P1Oqz0TThVu5ju
ihQJ8WH9kuHqK3eXwod71QSs2ASAh510Ct0JJ+2bozbDheqZwcrnJwD7bwF5ITKswq7BFqeiPc9L
sPI8m1CNcqSAkrCqdQMul2JBpyCmmtH4QqFBzPdPgMe1CPwJMo6s2BCAN/QUHT8bV4OthKu19HDZ
43AYdypkPLJiXwA8qicWBxlWjeJhsfNZj/N7E6w+5XP/JR5nAqqQexVQElav4QZ1lAFXpJ7S1eh1
+NhAFnwSLuo/cO6RKhbYu6bCGm1hyWcFRFZlEyH1eT3HQymwEL2ZwOrFNDupZFi1APhRL8ozDwQr
z7QL1SrbCqgDK/srYvyex2d9/bDFuGtzZ4hoedGtkNiUBR2Ca9o78Upswp2jeCZ0M8R2Fyk6R/MI
3Cu6V/u9sv9ySGyNZzKB1X1J8InIq3/IsHoE4BXnsx7nJ1h5nEmoQjlTQB1YbR/45FNPPfXk4C83
pOD7rPg+hUIrAX7BdSefuktsMN2X+c4CmIh7QIPbrcdZwT9cmAdscO7+oiyoyyFI5HM63I6wNgzX
tErjxGF5AEZkAqvK4cawjJeUds3qM45HT3YEK0+2DtUtGwqoAyu+LGG437XZXs0DAOdW/fwX/ix5
J/+ZcqtIgF2z5/6dAlM2Q8KKZ/H3NjMB4ncu3YLvYviKzwerHAa4uGb6PMx4pgmXKxNY4Yq6tKVd
Hlltgf/0vfG8GA90BCsPNApVKScKKAKrHgamABLOrxzIx0Tc1ViuxafMryrCg86JcPgbbAAOv6Zg
XKFP8YUL6M69J/aMsnobRRDgb+0nO30A3hVZGdsAUfofQugRgyHpXt3LD2sd72BnrPxlmOp0zgO9
BCsPNApVKScKKAKrYi0N16xBVae9mEHdv127ZcHoVga9ar79618zn0Ny+XUf95H2I+d6w2f8Mm6A
BjNUKqTXpPXbV33TQ//NcvGWLcvr+oW1bFpQkrLSRfjYKSKsZfOi9uDzKcnOILPHe47Hm2D1Gf8G
oqeBnnPz5U5NFIFV7jTerNRv4JzzC62ckgethSVOzHQ64zFer4OVZ+8k8Zj7QuGKEKwyMV7NS2Ds
dEiTqnlyvPPW+DRnPSJIsPIIM1Al3KcAwSozLYfCv4Vdnp8LP+EzRY92BCuPNg9V7vYVIFhlplnh
Ta7/erlB5JUameXzhHNeB6tFnqA61SEXFSBYZSpum+SD+kq8czK/WR7+llBeWYKVs8nIbwEFCFaZ
G3HovNrpExSZ+q22ESL9Kc+JIVh5ji2oJm5RgGBlJqOL98C4iDIrJe/PexOsPudbF2gamPc3Wd5e
kWCVt3rn3dUIVnmnNV0pTxQgWOWJzPlwEYJVPohOl8xNBQhWualufpbtTbDClyzSNDA/b7a8uTbB
Km90zvureB2s+OvJyFlZAYKVVa1LsLKqZb22XQQr1Uyf1Z3zBCvVLEv1NVGAYGUikMedfnVyRxf7
VNNXk2CVXhOKUVoBgpVq5hsHKTtG1fQ3rTbBylQiSqCWAgQrtezF2Fj+5CtmwePau+Qzrj3BKmNt
6IySChCsVDObgBXy6tSPbe3/geiqDd4EK/zXNBB/VuRKCIqzigIEK9UsacAKu+eOMQ0yrr3XwWpB
xlrQGUsoQLBSzYxOsAKIXNpX+/Ox9K0gWKXXhGKUVoBgpZr5JFjh8OrElHuDXbXBm2D1JZ8G0sjK
1W1gpTiClWrWTAsrwKeDb9ZP3wqvg9X89BpQjKUUIFipZs70sMJRxdVl/cumaQjBKo0gFFRdAQGr
I65fNK5626xZ/9F8yuPCnZ/Rq4BziwlWzmqQ3wIKCFhdGf7c8+TUUGCQ/r+uLnAV/9+Ieo73AhKs
LNA9qQnOCghYubjxKUpJBW4uG1RCNy/Byvk+J78FFCBYKQmlTCp9/tuuglcEKwt0T2qCswIEq0z6
vZqnYn+tyS3sTbD6iluKngY6d2wr+glWahIpo1rbtr4Xpt2nXgerX63YP6lNTgoIWMXv3rGTnBoK
bLuYEacw/ti3rUIM4xKsDCXoaBEFBKyOGouyFmmUpZsxNiNYRf38cCmnlhOsnMQgrxUU0GBV3ApN
8ZI2uIZV0t9vV5ffIUqw8pIbwnuaSSMr1WztAla2M1+0Tvf7QIKVapal+pooQLAyEcjjTqeDVeTv
A11N4wlWHmc6qlDOFCBY5Uy/vM8twyp262s1HbvWnWvjTbD6mq/j/eLcevJbUAGClWpGdYbVyfFt
/TKqP8EqI2UoXlEFCFaqGc4OqyuLHnM1/TPaQ7AylKCjRRQgWKlmSA1W8f8Oq5t5zb0JVt/QNDDz
m8EaZwlWqtmRw+r4xA4BZvX2OljNM1OEziuuAMFKNQOOu/rbo+WyUGmCVRZEoiQqKUCwUslavK71
62StxgSrrOlEqZRRgGCljKlus6IEq9sUjJJ7ugIEK0+3UHbrR7DKrnKUz0MVIFh5qGFyXC2CVY4l
pAI8SwGClWfZw3218SZYfcu3LvzsPu2oJI9UgGDlkWZxQ6UIVm4QkYrwJAUIVp5kDXfWhWDlTjWp
LA9QgGDlAUbIlSoQrHJFVio0/xQgWOWf9rl7Za+D1dzc1ZNKz3cFCFb5boJcqgDBKpeEpWLzSwGC
VX4pn9vX9SZYfcefBtLIKrdvqfwun2CV3xbIresTrHJLWSo3nxQgWOWT8Ll+WYJVrktMF8hbBQhW
eat33l2NYJV3WtOV8kQBglWeyJwPF/EmWH1Pa1b5cIfl+SUJVnkueR5d0OtgNSePhKXL5JcCBKv8
Uj63r0uwym2Fqfw8VoBglceC59nlCFZ5JjVdKG8UIFjljc55fxWCVd5rTlfMVQUIVrkqbz4WTrDK
R/Hp0rmhAMEqN1T1hDK9CVYT+dNAWmD3hNsuN+tAsMpNdfOzbK+D1ez8VJuunQcKEKzyQOR8uQTB
Kl9kp4vmngIEq9zTNn9LJljlr/50dbcrQLByu6QeUiDBykMMQdVwlwIEK3cp6WnleB2sZnmaBag+
blaAYOVmQT2mOIKVx5iCKuIeBQhW7tHR80rxJlhN4lsXaGTleTehe2tEsHKvnp5TGsHKc2xBNXGL
AgQrt8jogYUQrDzQKFSlnChAsMqJep6c15tgNZmmgZ58K7qrbgQrdynpaeUQrDzNIlSfHCpAsMqh
gB6b3etgNdNjTUEVc48CBCv36Oh5pRCsPM8mVKMcKUCwypF8HpyZYOXBxqGqZUcBglV2VFMhD8FK
BStRHW9DAYLVbYilVFKClVLmosqaK0CwMtdIzRTeBKsf+NYFWmBX80bNeq0JVlnXSq2UXgerGWrZ
h2p72woQrG5bMkUyEKwUMRRVM6sKEKyyqpRq6bwJVj/yaeAM1SxE9b1NBQhWtymYMskJVsqYiiqa
NQUIVlnTSb1UXgern9SzEdX4thQgWN2WXAolJlgpZCyqalYUIFhlRSUV0xCsVLQa1TkTBQhWmYij
9CmCldLmo8qnV4BglV4Ta8QQrKxhR2qFXQGClV0Ki3m8CVZT+NYFWmC32B2crjkEq3SSWCTC62A1
3SKGo2ZkpADBKiNlVI8nWKluQap/GgUIVmkEsUyQYGUZU1JDNAUIVla9EwhWVrWs17aLYGVV03sd
rKZZ1ZLULl0BgpVVbwWClVUt67XtIlhZ1fTeBKupfOsCjayseisb7SJYGUpY7UiwsppFvb49BCur
3gIEK6ta1mvblXuwuqN+q3ZNq2Rf2CIlfbKf2SNzFq5axEW9ilUNdhGb8yhvgtU0mgbm/Ibx/BJy
CVYB9887eDU+Ker0upeK3oYIZSb9/LpAVMj7a3b/W4w1njW3521kzyxp4LtzZ2lu9oyvRnYrmVna
3DlXcNnBu/SSC5euUrFkgBbodOrrXLkewSpXZKVC80+B3IFV9QU2/l0n3PYm5q0rXK9eKZ6qViys
4bAKWoJZU+9gDwOMNM+NKcrVr1sw84SF/tHrox3ODDdJn3lpJmdD69W7I12S12CBNlasO3ZnZErS
uQWPBfE0RXeltE+X1g0RXgerqW4QjYrwZAVyBVb1DyAR9k95++0fNsQDXOlgKkD3a9eG80S1k2AD
79CdASIXfxPKHgEYZZqZJ5hw/XyLzBMW2ghw+cxZ4S6lYP2mCVRknim7Zztfu/ZW2rw1L8XdI+L6
XTawuUCMOh+DrSFpE7shTLByg4hUhCcpkBuwKncI4FT/QqKZHdYDnKxs1uKHAN7jaYoPfetRfhwK
8C4/1hjxVnN+NHVTILFd5okQVrY+5cpzV6Fmtz+QF0Myz5CTsz0BxqTNPwMW+PO4+24B7Bz13Dtr
sQrf8ojgDSBIzf1udAQrN4pJRXmCArkAqwBc7jzSyGhc5b0AXxmBjI4PppnujQTom1Fal/E/QFxb
lyfskRxWre2hoqsA/ipgD7rb0wNgdJoym8WkduJRgRsg9Wu+0B78Sjzc6syjnkq9Uo0f3esIVu7V
k0rLdwVyAVbN4iG2o6Nh2HEvlTGCgYXSTb4K4UIzppGmTW8CdDOyGMeCRQsHGn5+LBBSUIxURNxE
iHMMwQIKuni+xmHlNPjqb4PjYpmMZ8cM2mqSKAs/CvBKmbi0TfEvVNi+DNYF4H05e8Bs2CTg2CIW
/tWq54NQn8FTlTprjnO5tKyECFZZUYnSKKRALsDqG4AlTgoU3gEJPbRw+zErtq/5tqfOnFbvDC/D
2k7Z0b/ZG3MAVr85/A5WZODz3Zlv92d/B9vEZwcFsSrPP99Qy3r3+K1nj6wcX1cv2L/z58v2/LNo
bEsOmYAnX98OST+++bSAV4O3f9u2cerjaR/3pYFVg3i4XEErrN6IJds2TutnRxe7a9Tyf/8YHcY6
v/NyCUwy4B3jiWadd97Rq8Paj3VuCmNV3l2w88iWr7vy+rR5YybA2jdfsyMa4xrFwwvici8CvCY8
jPVMgc2CWxPhdEU9zn0Hb4LVdJxSAy2wu+/m8cyS3A+roJMADzg3tnLDBsV5uNjUOH5PQeoqbY74
ESQ3eQEXcEZ8LKIBGrHaybCRBWzTw6VZH32E4v/WdS0u4i0xBCqzLFEL35oayljIPi1wFHt+gY+u
aYE9OiCNmqSBVYtEOCrwFPDBVS3Dvl5aUp8hESLiyoDv4WYYxh2AG9W1U/0AXhK+tE1hT57XCkn6
qTBjn2p+aKblEp+j4ab2VHQCQHs9vn4CHOE0ZDgLFkt1erx7Dl4Hqynu0Y1K8VgF3A+re6Lhqt65
pVYXWw0Q8fO4+acBLjblZ96DK5OQOamvPjgftxUcmD+zMqt5A1Ywv5ELDoBt86+zC/NeLKaHo2yQ
tPCdD5enQvzDmLPoMoDDn7w4fCpy5gcfFvjR/FOQsmH++ADm+wNA7B/jZx4GiHlQunwaWL1mg6V8
quf7PUDc0k9m4DOBOF40YwOxTju//WYX3DoA4bUxYjuc15eU+gI8z5Oka0qnKLj45YuvTUbMfcfY
o/O3AByaP9tpIcpvExxEjKF7cfEC43nDA6mwTowya0aC+3sawUroTR/WUcD9sHo8BXYUSy+QHw4p
1jTwZwFlfwHYzFeu3oPk5MTv2lcO9Q3AEdSogAAfASsf5h8wCpJ7BiBLdFh1jIWbfTAY9GIS7Mes
7QB+53M4n+bn4XR5hhmmQNy9ATgLfBLX9jsHMt/i41LTTK04rFraq9X6NKQ+wUOPAxy7LwgzfJQC
Z6tgRPETEPsWLoAXeROh5RpW6ZriuwKuiiWzBrsgqi7zC3gAYCxvj93VugS/aQH/Aka8Pwrxg4gM
3QrH0q3l2fNm00OwyqZwlM1TFXA/rIbgeo2L52x3R8MxbVkodB2k8lnPezhb0rcPYOcWWxX4yIp3
8Xch+T6umAargN/008z3d0i5m7E3IEmfYn0H8YJAkyGuDaYvccSYbfl9BfA2L8JwHFbv936Yuyfe
mBcBtk/4ClfRgxAlMMN8EaZ8UfxFG3yh5fksI1ila0q5o7BJy/NIYnIf9KGqH2oR+mdvW/rdra8l
QYQYYjI2G2IdTyqljNkPEKyyrx3l9EgF3A+r1wCWumjqhwDP6tGPpogRBcJqmf7QDaE0kp80YDUS
krvysAarGpFw+Q4eZKzfufD+jD305Qj+8B/dx2C7lx/1rQs4TvqcB9HddQ3W+mle8YmwcnZJYnrJ
F8WMfRV1ImCjPyv2H0RU1bJhCa5HVumaUv08hFcRmULv7cSHfD3Sbl14AeA5rVTjs9zEVICX9dDX
YDPEMc7n+Oh1sPoxx5JRAZ6tgPth9ZzLHUw+WyCOr1Zzd8dNWINjL4TVYC2CQykTWOEWy0V6wqAq
1cRiPQ/6hZZpcQRSO3C/DqupYLOv7e+GI6X5Kd1xWCUnJnGXjNRKWdOYn5gMtt5Giu1wvCyrlgQL
fbUY/+2uYZW+KQGbAPY+WUnbkcAzp4MVtlVaQg98nC+SjdBZzT5Is3XDqFJOjt4Eq5/49xDBKie3
iwp53Q+rR5Jhnzbfc25/6EWIXfTTTO5mzI6D3UU5rGwP6kkyhxWO1UY5l4X+Qp1HTl264wLeohKs
NkHKymniIjOnXYaLtZ1y8Wnga506c9et70f4cPFwWTy7zinDRbhcl7UFmGDkWuIaVqGX0jXl3otY
kxsbv+5dUsubDla4naOTUSweO67B9Osd21hfdrqqU7IceQlWOZKPMnueAu6HVdsYuOj0HIyx+v2f
bMwqXcXu6XCnEGcIq/t1QTKH1Vhjx4Ahn2/vXTG8LNtheWQVuMNxBfTF4PKW3XFYOX4+2CtKDOsK
bJUyxDVmAwBeN/LMSAsrnGXi00AXTWFt1kTzkhLOfimanhZWPnPBaSND6Ce4YeP8q6HGdRh72ub+
cQHByqEv+SyhgPthFXoOkls7a/MrZw328GuTP5+guy/ewp6aZVjhJEnbUGmU+gxO5M788uGgjqXG
Qmp7HqtNA4N2QNysz+wX+QgfFNodh5XTDvY/Ab7EXVlbIWG2I8OYiuwVcPxQb35aWOEMV4NV2qbg
Fojmryy+yOeXR2viJdPBahaAmK7y6tReh9srvrzTXjP0YMH28ZxzfE78BKucqEd5PVAB98OK4etd
fnJqaZlTEF2L4dzpYhWnWPRmGVb9AT7Ss/oWLhLMKoVDzBtFxMrSZxKs2CaI5w8FXbk0sBqjVXId
JNghInI9jZsOjOzrDVid00eK7whYuWiKyOFXtMu357Rf0KSFFcNpIH9KyF353QCbWml+4xN/XiQ9
ujTic3L0JljN4MNaWrPKye2iQt5cgNUTNrhp/CwGJXgJ4F8/5rMVUvTn9CyoTQd+PsuwaulYYO+z
Z+8j7EEb/KprO0Nes/oJoJ9+xrdph8Y+up8f0sAKa/Uzxk4BeFpP5NOkQ1Nf1gYfUeoPEUud0mC1
DSJqaWkWCVilaQo+NqjaoV1BLUWLcDiMq+bpYIW/zNafBhaYhz8M0Z9l6ldmbKz9tD0qxx6vg9UP
OZaMCvBsBXIBVvj0H2bZn4zdeRaScLcBbjKAj3UpXkwVIyUZVtI+K3nrQsULcL26yOvzK6TWZ7gP
QNt4wEIOOGDFh1RPgfGCO9Y2Gubp1xOHNLAaBLAQ43EVaokYojHW8iaPKR0OkVW1fL0SNFithFRt
IFQGF/RxGpimKaMZGwygD5V8N8CZEAGrD7VC9E/c+65XuUMSrNH2sjsl+B6S7Q8lnaJz5CVY5Ug+
yux5CuQCrNjD+Ma9OXqPb7kLYC4fqjS4CZe0Be+7jsH1NCMr3BQqJnqu91n54MamWQW4dj3iYWsA
e8QGs4SSBb/Ap4HimdpESOTHkocgSfvRTKnVkNpdJNI/0sDqkVRYitUqth9StJfRlFwBqb1w7elL
gJliaFUGF9/FPqvJAON5IQUm4lyDw+rutE1pk2LMQaqfhtWYAlX9hGexu2bRMFsLfA0JLe3Rusdv
KVyrlDYyp2GCVU4VpPwepkBuwIoNswGcnTLovi7/m30TdyBV5G32GQ1w+pkqQZUHnAR4g8c4jaza
J8KhAR0KZ7AplJU4CjCvc5kar+KmAQTKnVchdlTpwFL91gIWPyQY2YJr8Iv6NPNjfZLg5tthwWUf
3g4wydjFxC+WdhrYLRm28qlb7wSIHlk3uMxDiKYfORCr4/BpbsuQkr3/RTQJWN0PkPjNvXc9shTO
pwhYpWsK7slPmlwr0D+w82aAJ7GQVvFwbOC9TpO90H2wpxCeYAFHIWbpwsWG+1xMH8ueEIjj593n
CFbu05JK8ggFcgVWbChCBLt4Iv9cq83gWPBUDERdxD0DMC2Qt/19ACSPcKWRRnC1PqsZBav4QhNy
rBs/gW8QFQvPHSMAkm7iA//k93j0G5j6+lm8xlL8LXDicVz+bpuKGxn+CWJsZBJuWbgYicE1+p4n
ngFdIeRIe+ETH82TIbYJ972FlcQMKQAbtF3y3fFa8dcjbfD3bg1WIX/g5RJjbXDoUX0ba7qmtMC6
3Dq97TRefIY/FlrqIGa5IbadiqsxNgmui3FlObHFAc9q7mhRfr5JsuMRpJ4+5weCVc41pBI8SoHc
gRVrMi2CP8eH6D1DRHfkbS7w4ikel3h0CEIF3bDwC52FBz96HrwZczqMVTsYPofDamj42Q78VNfw
8Jf4kd29+KYNkqM2dhMztMChFxAuSSeGF/b7MTr5DM44fd+6dOvWas7APjsT8CLJF8al+TF1wUXh
F7RfAYoCS+wPvzhLDL0e2o6zVkgJ/7SEOIGvnvqDAyVqboWlGqxY6UnXkiA5ctqdtcL5j33QpW0K
67KDFwJJZ1/RhlNd99+MPVdfL5AfOtrgcX5sfCLc2a0Sm61egljn18nwdDl3BKuca0gleJQCuQQr
fEL/yIiP3xt8jzQVK9nnvTEv98AFaOF8/f04mDRXsH6ryj7Mx89f0Mg45ePvry9/s7ueeql3A7Fw
xTNU7vv28B68o/s3691IZCnZrJlGm+Cub40d/nD6PfRYtONy+GMdf3+9tOAuI8YOf8Tppzk+9wx5
85m7GFupwwpfrdf72Qdq4FTW398oQm4KvqT4vhETJgx7sILWGgzX4+1xuEKbYAFviq+/5ETV/TbA
Ko3fjvQ593kTrGbybwp6Gpjzm8azS8g1WHl2s7NUOwesspQ880SP2eLqZZCiVaz8LCCDZLcZ7XWw
mnybAlFy1RQgWGVsMbfCCv/D5mvXl/L9EX4VIyzXp7MbS7DKrnKUz0MVIFhlbBi3woq1jw3XHzWk
ueJdMTeNN7unOZOjIMEqR/JRZs9TgGCVsU3cCyvfb+27YuVL/phmT5Z8Ntshr4PVpGxLRRnVUIBg
lbGd1sLVOhmfve0zZU5E13SRqVEMfwWF+x3Byv2aUon5qgDBKmP5+777krGdIeNEt3Gm3hN3ukhd
7QltY7+LUzmK8iZY4UstcBNwjuSizJ6vAMHK822UvRoSrLKnG+XyWAUIVh5rmhxWjGCVQwEpu6cp
QLDyNIu4qz4EK3cpSeV4iAIEKw8xhNur4U2wmk1rVm6/fzywQIKVBxrFLVXyOlhNdItsVIjnKkCw
8lzb5KxmBKuc6Ue5PU6BLMCqhPFbYo+rPFUoEwUIVpmIQ6dUVMAMVgGtvtvk/jcCqKiUanX2Olh9
r5qFqL63qUDmsKo9eHMC3BSvyrvNcil5fitAsMpvC9D13axAJrAq0XthOH/KEkGwcrPoeVIcwSpP
ZKaL5J0CGcHKt8WoQ5xU6AhWeWcON17Jm2A1h9+nNA10493jkUW5hlWNl/7BF57rjmDlkZYzqxTB
ykwhOq+YAi5gVfiJxVcNUPEjwUoxm2rVJVgpaTaqdMYKpIVVgVbjTuBfwzg7glXG8nnwGYKVBxuH
qpYdBSRY+VQeviXOmVPCT7DKjrD5nsfrYPVdvktOFchdBZxgVeyB6dfTkQojIuz/KZO7VaHS3arA
s9yWW7xjj5xYYCdYufX+8cDCNFgVYQXvmXAU/0fZlYsI9iWnnALsOW7LjfwvV63v5vK2EqysbmgB
qyNN39gk/pOU2zydS1z2JznlFPhtLzfkWec/WrXuvUywsq5tnVomYJVwLR2hKMIaCuy+w8nYlvUS
rCxrWueGCVhZo19SK1wp8JSzta3qJ1hZ1bJSuwhWrnq4deJsfSRzWzTwMzcYrVlZ1Lr2ZglYJafZ
WWWdvurtLbH9Wchuagt7BKy+tXADqWlcAQGrU499dznjbh0z8i1yyinw+mJu0QO58peEHtd1CFYe
Z5LcqJCA1ZGCrMLgdY5fA8rgupIb16Uyc1uBp7kVN3nHHjmCVW7fTR5RvoDVUf5fnj7NRh12uX+B
drB7hKVutxL/47Dykk2hAlbf3K5ClF4xBRywwooXemDuJX6Ly45gpZhNteoSrJQ0G1U6YwUkWGGy
6v/bcFNmFb11IWP1PPmMN8FqHr9laWTlybejO+qWFlZYZsO390i4opGVO4TO8zIIVnkuOV0wdxVw
ASvGSnT/+ayDVwSr3DVBLpVOsMolYanY/FLAJaywMtWeWRmv84pglV/GydF1CVY5ko8ye54CGcGK
sYBGn2nTQYKV55ktCzXyJlj9wr9Xac0qC3eF0kkyhhU2q2T3mfh08Cr9u42KJvY6WH2topWozreh
QKawwnKqvLH+gne8wO02RFMiKcFKCTNRJbOugBmsGAsKo7+Pz7qenpOSYOU5tqCauEUBc1i55TJU
SJ4rQLDKc8npgrmrAMEqd/XNv9IJVvmnPV05VxQgWOWKrB5QKMHKA4xAVXCnAgQrd6rpSWV5E6x+
5VsXvvIk9akuuaAAwSoXRPWIIglWHmEGqoT7FCBYuU9LzyqJYOVZ9qDa5FgBglWOJfTQAghWHmoY
qlZ2FSBYZVc5T8/ndbD60tMtQvXLoQIEqxwK6LHZCVYeaxqqWPYUIFhlTzfPz+VNsJrPnwbSyMrz
b8qc1ZBglTP9PDc3wcpzbUM1y5YCBKtsyaZAJoKVAkaiKt6OAgSr21FLpbQEK5WsRXXNggIEqyyI
pGQSb4LVAr5m9YWSZqJKZ10BglXWtVIrJcFKLXtRbU0VIFiZSqRoAoKVooajamekAMEqI2VUjydY
qW5Bqn8aBQhWaQSxTJBgZRlTUkM0BQhWVr0TCFZWtazXtotgZVXTexOsFtLTQKvexs7tIlg5q2El
v9fBaoKVrEdtcaEAwcqFKJaIIlhZwozUCIcCBCuHFtbyEaysZU9qDSNYWfUm8DpYfW5VS1K7dAUI
Vla9FQhWVrWs17aLYGVV0xOsrGpZr20XwcqqpvcmWC3iWxdoGmjVW9loF8HKUMJqR4KV1Szq9e0h
WFn1FiBYWdWyXtsugpVVTe9NsFpM00Cr3sbO7SJYOathJb/XweozK1mP2uJCAYKVC1EsEUWwsoQZ
qREOBQhWDi2s5SNYWcue1BrawW7Ze8DrYPWpZU1JDdMUoJGVVe8EgpVVLeu17SJYWdX0BCurWtZr
20WwsqrpvQlWS/jWBZoGWvVWNtpFsDKUsNqRYGU1i3p9ewhWVr0FCFZWtazXtotgZVXTE6ysalmv
bRfByqqm9zpYfZIFS4YUv6NEoSyky+ckfvl8fTdfPqTEHcULuqFMgpUbRPTIIghWac1SrPfX6w+d
O7T20+4BaU/lXbjM8y83zfxq1V/8bFbzzJPk6GyPl/ub8PqO516+3QqU6//0U7q7v1FR5/qV6PPd
psNnD/01vou/Hl3+SXtanuXpJ0o7p8/ET7DKRBylTxGsZPP59NnLnxlyl7zhdvuiXFROQm0APso0
f8+zWMOBmSbJ2clVcKF85iU0s4H0Q0ufIsUL+2SeRXBEiAu2yONDixipA/od1GIBEv9qqMX2MGL0
Y1IHI7XJkWBlIpCyp70JVr/x2z7zaaDvyBSA1COLZq89hWmv9sgvu7aMgfcyu3bINoAru7pmliSH
536Do+UyL6JJFIxxThG09L+5oc4R6f1dubrCCQItL6klCfgKgyn7Fs5ZdwY9l+4Vsd1SRRr7R2z7
9OW5jCFYuZTFApEEK8mI72DfWNk51N83sMjjuwEu69/yUpq8CJjBqsYFOF29kDFjyo0a3T6sCl6C
/dLULn21uibD/s4dO6Hr9fJvNoDxWpKxqPqf7UL8fYOKPnkA4GwYj+6WAgeeec7unh9YNn15LmMI
Vi5lsUAkwcrZiG1jcegVpMeU3Q6w1Ag4p8oDvxms7o6ElblbjWzA6iz8Zw6rTUa1fUanwM0GPNQl
EWwfFNDjq+B3xEK+WoiwWq7H3d6BYHV7eqmT2ptg9TufUmQ2DfRfCzDf1268JtGQkE/LVmawqhcJ
v9jrmSue24dVwBnYZbImjyOrzfZlrdCdkPo01j34b4CfHG1oHQ9x9TGIsMoejwlWDjGt5fM6WOkz
D5dWvDcJIms5nZkPxspRzZdmr/zj8y56Xyx1X9dqLPTBcVPea4NoC+owetq3A7TVaL9WXZv5sIZv
/DDh8eJYUK0XJ019p6nRPf2bDvt27hfDW+ijtZpdO4aw0n0+n/7FY44HXWHPfDzm6eqsubFm5dPi
tUmLpg8XIxB7zUrd3S8aVjRsUkLE1H9j3uolY9poQ5PAtt3qMd/7xn9Xpl3XNoHifJOuXSsLT8i9
3bRpbeX+42b/8H6fMlqBhTp0q80Cek34XJRQvNs7n77esRBzwCpsyLdTx/TUl5d4ltqDxo55piZr
JK1ZFev4QASc6H1fdVFo+Senrlg28RGnTCJaghWbAzAOo3sCXKwkTmsfywBeRR/BykkT8nIFCFZO
98FkaWDFWM2BA8TIKuiDa3xQBrC5tUiN3ev1hv/wiKTJBe5cwT1wqhs/VfAwbC77FU4mAXbfzd6J
5J7ECRo06i1P4EFIWd9SlPIZ3Kr18BERdaSTiGElfoji4atvtrmlYbLyz1qeuMnOE6whIhPAAMxV
cnKMCNmW38XLKH8eZoX8kAJx1Q5A1N08JggXrSdxD3vAJv7bJ3D8BS3/sWECo7WvwxdFf8EFOr7J
qfcecW5D3fn6Anu5ybdEzP5BOnOLThStuj6yeaTzAnsHXDvnjuOHvXBa+GH/QzzkcDKspoB4nDgb
4AuD5zxp2MABjfFAsHLoRj6hAMHKcSMEbQLbcEfQ7gueChC3b/kqfEAY0ZPHdrfBvEMQsYdvH/hi
A6Qe34/AOFcFzxTcB9vnQ/KhA8iYvz/AJ1v7zmOaZ3mmyv8h0db9vh4jTgqujIer38XCxT1HkvGE
GPuELsHEF/dcBNvqKAGrkOUAB5cv3xYNMM0xPWWPHT+XClHHTj7AWHEch0TvXro2HOA4H36VOwWz
v8dSkgpPBHicX7dpHMAusRT/KSR3YCzwU4CYf/5cuQ8XuIfxBLUuw8SfMEsEwqoPkinm0OEE2POf
Bqvym3n52xBvqWPFJtSQXzHppT3YitUSrJruPpkMCSePY5G+I234RHXV8oMI6iH8CnYnwcp3Ndie
YyxkB6Q+bE/h8BCsHFqQTyjgdbAS3/yujV/5JMToQxwpwTAbnO6BU64qn9ogvAqeQlil2D6/q9id
X2DHhR09K5ZsvQPgXTyDsMJlmY6lSz14Ec/EjAgrUWN8KuzkE6yvcWWGZ66Bs5+P8cjGQyrcGlG7
aNlHLmuZ2ctIjMG1i9V+jQ+W+NaFZwG+vANXdVpvh6R2PI/mQip0jYJ5FSohXSYB7G1bBIkzDWAn
jr4QVpcg6psnuwb0wrw8+XCEUkRt9AT+BSdDGGuSBHvvxbFeiWej4AifSCKsLkHE50909GNlkUHz
m5cu024jVoBvXSiA+FzVvEhwzcExkDoAE7PnAa6/WKdYjaEIUOeRVWD5muFwoG5FrEvPBIh+Hp/d
3TEkGmLa8EyGQ1jZF9jZQ9EQjUMofLB5w9VDV4TV6gKBdlfAefBllOfySGtWLmWxQCTBymHEOhFw
NcwRNHxlL8JNnRSIhk8xGmGl9dPAw/ig/U6e8KEkWIzdCWEFB8Uz9o+xLw/lZ0J2Q0w17Pab4bC2
5FX5Mqzmw6TxALZBPAV7KRV+w5gSRyBKg2U/3GOEsPKdDlEcJ4y1AfhQePSP+pHwI/c2iIfTdURc
EP53z0sCVnBFFFL+MmxHJvnMgwhI7YNpKkTAFDw8BzZ9+9gciGqCEQgrONNMFPIewDzMw1gphC+H
1VM22IT4QfdUAuwozFjh/XCru4h4FAeEY4RP/yiAC+wIQxb4DyRo7WLDQDTMngphta1USe6qNH8r
AuAHPNMwEs5XsKdweBBWV1essrs/azlOZe4jWGWuj7pnCVYO2919Cy5WdAQN31CAObq//jVBHITV
SezJSIL5BkSq34B12M05rAaKxI+nwoFiwrcQ4lvi2tJPm14TQVZ0L+zxRy/C6jexps0qRMEmHCXh
wOoLLYkfTu4QVsFrIb6BiAkY/Ma92intE3v4VO6bAPCWHt8xHtb68ZFVqmAkC5gLsdWQgPvgk1Ni
Q1NXsPXFtC9snKuv538INl4owipxgCikzDG4ysdg6PomclgFr4FbbbUI9juk3MNRB99qET5IRwlW
BfWtC+3jYYsgHmPFjkOsYLleBsIq7vgx7s7xgdk+fq5FPJzSiKwn0g8IK8mJ1UM5iesQwcq1LurH
ehGsfP7gN/+4jG0Wdg0uV0l/ejHEP6jHBmyCyEZiZLVCi8HVLO1c+WuwFQcefBqo9c6eifC7NnOZ
C0n3OZfa/Rbs1mH1pBYfdAn+Q7AthRijRz4uYOWDU8e9PVz9RFGHlf92uFZPL7vQCThdhcPqGn8O
iQ6HUFj+3QmJHabD3zio+xwu1tDOaJ+ltkBqB/QirE5ocMHx20w9RYETHFa1rsFeI8sggP8xtgji
2+gxvTOA1Rv6WhhPNgNs/Y0C8IiwcrjU6ZX4qcZRcLqUUxrDi7C6vma94Tas1ilqnM74SLDKWBu1
zxCsHParehaiWjuCuq/wDrhS3YhdIMCDIys+oUL3IwCfSeEcyw6r82LMxbonwjRxhiGsugpfQM3O
z3w0628cU+iwStXnY4HnYG9xFrwVwitqWVjHZLFm1RKfQsYfmPRYXW0Epp/Egw6rCmecNo1vh8iG
HFaicExzdzR/CvgMHC/2PD4cZH7/wFpfrYRyLfq+NWklPiU0YLVWi38S4G3Nx9h6DquOuDbf70nh
HvuMsylwI1ypqidpk+hyZOU7DWztjVJwMjzC8OMRYRUxe5Zwnw5s6ifO1LnkcvLNnwb+VSjE7grp
dXcqLQMvwSoDYZSPJlg5TFj6ICQ97gjiU/+6d9VgZQ/DaW2xCU8hnB4QI6uPtHQYFk/2nGC1SxvY
IKz4igw6HVa+D6+9JIYVUXEGrJK6aCk0WFU6AceCtQjW8LqAFet0IJXnub7+LXnwocMq7DL8be/E
KyCuGYfVZj5sQxewD7YUZLPgT4ZbTJ9gNS/BSBFfe7q2XyIp0g6r38UJ9iGAfRw0i8Oqr2McxH0T
hRh8XYq7uyJcwqrA75Bkh/ub8g+yEVYbtcyOz4onIJ4P8OyuYN16fHCKsNKHr/YzWfMQrLKmk3qp
CFYOm/nhRoF3HEH+WCvhV1buKBzXxgB4ah7E4Vo7jqxGaekQVto0zDGy+ldbqUoLKz98KgjXdiz7
cXCTgwasEjtrpWiwwsdih40LNYrUYMUKPz5zdyIHxf5qzjXTYXXXFVhnj/4broRxWG3RYcW+goia
AYewSUWOwmTW25Yi3jrTNhy3eh1aM29Uiwl2WP2hFYK/J37EKG4Oh9VTAOGbtxju79dZ1TNw0hjl
1b/qElaBf0KCNrjEoj4Sq/5GmXxk5djBrscWWA+IUifXNyFhOgYRViudYrPuJVhlXSu1UnodrD7O
xD6jgY9FHO573tWCt0B4WSNuDVyuKWD1gRaTdVj1SoIbr9bGzQWsxCHXsCqxB86W1i/UKUWHFU/f
aPDvNwF+tw/vME6HValjsCtIz1LgCBwsLcGqmw261omytWTsV9gaNB5246Iaw6ukzmpWhi+E4d4J
PqTBNSsdVvgoYZheGtvIYYXbH+YXLKS5gkHBBViRnXBR26vPWNskl7Dy+Q5StakxFjUZUvSprijX
Faz4Q4LFBgB5qhnableClZCMPhwKEKwcWrBWSWDTnsuLyEoXIBm73WKIaqEnKn0YTuKTfBxZfaDF
ZB1W2AWHaHnKnXENK9+1fNFJc/3EAnvQHaX1Xtz2DESJ5Wj9vA4r3x1w2oiuFQFbAiRYVT4P7/aF
8wjI5+Fyo40wwQdzd06BDTr2JqWFFb5CCle5hAsUC+zNkuBfPYL5lSoVyHxWwC0xPsPYPhkssL8O
0FfPVGAtJNY1CsCjS1h1SoVkp01k1a9CYhimJVg5CUderoA3wepPPp3KbGTlh7uz/zaWZJgvPupb
gQOtT8H2qX6z9EqFRejNDqx2QKT+PKtlsmtYsSn2fQi+2taFphfD++lX/gTAABmP0WGF09LUJ/UU
gwG+Evus7NNA399h8zcwB6eW9RJt795MeZCnRIO/p+Xw35YWVnfFwzncg8rdY2LrQukjDn5+GX4W
a/CdPTvD/aJjtMTap7F14WEbLNAX0urEwV5U0O5cwqoAPqVdYyzWMf+5AEs4oglWdtnIoylAsHK+
E5rdAPhVn/P5v5sC1/gup7AbcE5bMfZfBoltMSY7sNoA8dqQJHQFwH+8M48Hec2KNYmBkzVFdR7A
PUaIlHLRsFDv9nMgwr4QhEkMWOFPr//VFvSLbofruDPBec2KvQ6J4fACJi+6Gy7btPkbPvH7UlyD
PZcIqXxE45gGBi4Em8af0E3aplC+7V5L3TYG/sNBZYMoOKONlbolpYfVHj5mK7YPojtqmb4EeEbz
aZ8uYcXa4W98ZpbSUhQYa4OLguoIK1pgdxaP/AQr6R54DnvgkaEtqpav8wAOHGyviJO4SryzOe5E
qoBddxn/0s8OrPAh/jJcIy907wrALaW8U6eDFcO+/V/rEFbksQgQa1YFZkPqeL6MFTo0Hn42Fqd4
nQxY+S0E+OsuXICqgQOSz/GEBKv6+LPAmFY8/U84plzFPaxRLFy6H491x2FT4SH0OWDFGkdD8rsV
MGohJPE1K3bnWUj9tCJuXH/kLCSLZXAc4u1rF8pCHr6EPyySRlaBe+Hmg1Vw0tkf4PxDoUitoXFw
QNrv6RpW7FX8RcD+IU2rlA97eCmu/g/i9eQjq+PvfuDkcO0tS44W2LMkk4KJCFaS0Xxe5O8YiDlz
nO8yiH+Lk4mx0tsAbmxftPQE/gRZzMWyA6sap/CXOUuX7kqFqUsgdcf7rmBVcS9A1O7Ve5Nh+ikx
WcOtCXB4+eR5uwEu1HKuqAErVv84vt9428JV5wH+5UNCCVYBu3B8VIznew4fRQ4VBfj/gO3b+Num
K3B0BMDpRRWcYcXewWaf2LAhHHb9LGDFuuNOr5PrV+3B3ZzjRP6yO/kvm1f/lwgzj8qw8pmOv/c+
/Sr+smgBQMLu33/fDxDZU2QyPjKAld/7SFWIOn0cmwuxQ/1FcoSV7N42SjE5EqxMBFL2tDfBCr+1
M1+z4lbsvErvJLYNPQyrVl0odjsBrNcec+FC9Gjt3FSA+sJXIRK28x3sB2GnoAPrkWpsHJ0Htm6Y
piv2XXQX3/frwp/t8bWw1C5aKYH4E2AxmauzXqSJHYUjGrE54lHcuSnclk5aUv2zUTRM17wNN2gJ
Un/DSSDC6ixs1To7D43H9R9+ZHWiIamR8LHSv4rGpC6qW3AL0qUWq30Vlmmn8NeII66K4rbe9SGc
EPPOjkhq7sLf1IutsVaE48dUPZ5mAbAhglNEFf0+VqSB3fcZBWvHbgD/8FX+dK7nWhxccZf6l64J
E8zRIrXPN9Plch1BsHKti/qxXgersWY2K9D41RlL/5z+elP7mi9jfq0/XvLXgo/b6VEhYWH6Eku5
sDCcH6ILqBVWFZeXfO8Mq6rtlQqpE6YvfpUPCxOL9qUGfbfo+6dwksWavP52MxywhdXhs0F0PjXD
7tRyFew1efn8t+sxvxr6FcoNmv7Xpnkf99FTaulxu2rtMIESDAd3+eKP1b+8d4/GEv8aYVUdOCga
FsZnkeIKNXGyKJxfl7G/znyrIV6wzKBRjwezArXCjCeKeL7W24uXTu4dirWrrpUY+uD3fy75bgCv
t+aCe05atuCDBsy3epi+Gm+cKdvt+b5augYj5q9Z8lVPjdvGafxRd1hYFUfI2RfU9I1Zy/6YNqyx
JieewrSykyaUznnT+AlWaQSxTJBgZRlTUkM0BQhWVr0TCFZWtazXtotgZVXTex2sxljVktQuXQGC
lVVvBYKVVS3rte0iWFnV9N4EK9wWnmYfo1Wt6tXtIlhZ1fwEK6ta1mvbRbCyqukJVla1rNe2i2Bl
VdMTrKxqWa9tF8HKqqb3Jljhu/VozcqqN7KjXQQrhxbW8nkdrD6ylv2oNekUIFilk8QiEQQrixiS
mmEoQLAylLDakWBlNYt6fXsIVla9BbwOVvrrEnLDnj6FQowfPxe6s5P2NobcuI5Rpm+hUP6OK79C
IfZf/xqnPOVYoEgR7TU7eVghglUeip2nlyJYuU/ucjvP/yLeVOD/5LG4FP1PGNxXfLqSauy8MBkj
Gx44Pz7dOQ+JeDIqWryyLy+r435YVWvepUvLytlvQ2n9HR3ZL0GVnIE1jL8TcaqxTyX9nSJOcdny
ehOs8H3C9hdRZUssk0yVrsMmAate+Ko6/Lu+nLiQZ1/ujq+cydTVvQ6/YYIWscbfqWaaOl9OPqP9
U02eXtvNsCry3F/nolNTY06vG4BvP82qC5jw+0R8CzS6qlO2HV3uwx77bb7+QrGsFpFhujsmL1mk
u18nf9gtzXt6MsyWFydGXXxWv0ypStXK4VtjufMZfeExzZfDT4JVDgV0yl7pmg6rHwH+eKGj05nb
91aIgWUCfJlkDYuAxXi6ebTxmr9M0ubTqUE2eDqvL+1eWLXayL/iNLe2jnlbyjVpxN+jGHQQLohX
iZU/iHlP+LCxAPJbUzMoqnjjxmb0qXrRqJA4Hn5aexdaBgXmZXTD65eriOs1+eZAVNL5f75tKkIN
4o+WdEc1CFbuUFErI7BRszr8xXd+KyFRvLYzB0VXuAl/EKyyJaBbYdUnEt+mumH8i8O/24TD5eMN
TWs0KjryUUwUdAyuCFi9DHDupxE+/KWtvUwzY4K+UVGDTdJVOQMpp48Kd/w8f6/tWOO9iiYZc/t0
wFLtL+p8XonWcRr9lbiJv4LxjjdCZr8WBKvsa5dRTv8NcAX/ZCFHrjzCymwaSCMrlxK7E1Yt8A3U
WzuIy/j3xDHSTn1m4/LCInIcQH/0+D8xdIB42oL/XcbhxZoPfbkKP5q5J42X5WecEGF1vXmp0tyV
qd4VX2ud0C7jxHl5ZkDKJfH+2h74Sv3tXw0esRmRNZxTqu7VGHdUkWCVC9ZcC+fTvYO3aPOu7es6
v5y4WtOm9jVbHz9/JJNPjWaNtfVJH9/KUfBnkB9G+vrzQf6dLfEF79xVaNS6vvESYglWfv7+ji8v
f3+nUZmfKKFS0wZaRyvduJnzsC+werOWxkuacVAo0pZp3KyW09TCt3KT1vWMtyiLWgTXCkszrq/U
5J7qjutjorJ1a2KVFZ8GhuJb6tfob6dmrDH+K4f2rxtCBNcfH0NqP+czMyCpuXPYzN8f4BWTNAir
q9Xsacrjv4l8aQ/lp6fIXhBPevw3Q+p3/E3eQaNT4Kx4z/U8p3+GzH4VvQ5WH2ZfK7Ocdyxe+4Uf
q7p43Q1I2LJmrHPy0Pf33oLEy9uf0fc2BDyx9mzUzVN/PKwx4e5NWx/2fXjd+ejI4zPuxHxtt+xK
gRvbtvZh7PNtcwpWmnkupj1G+/VcfOJG/NWTyx4V434JVo22bp2tF85e3/qvY0XTd8rWeYXqzjh5
89q+N4NY+a8OR0afX9VKr1yRIf+ci469dGhGCxHhN3XbJN9a045ERodvekhnT0Df1aci4yOOLbrf
4FexkTsvXDo4s7Hfx0tfEYl8uv9x8mb0uXVG6xjrtPDo5Qt7PinWX+01q8dtcLaWLhUehgDsMDRm
IcWcv3p4ogLF0CwfQWpfRw6G/1x7q65zGP0+xcuUcP7rV9+QEoXtm08es/9zN89VqFio9BUgSuKw
cvq+eQ//jc0wTboMgcVKFZFH6MHFi0oRwaXKlky7vSRUaltQ8VL6V6W4PL72v2hhpy9DPRL/Qglu
iGlyy0RYI25Q5r8OUsWyVcfUZP7/bzl0BKscCuiUHUdD//iz+vHafH2t05nyq/U5PPwk7sqi0/Rw
6hTxnwrtAF4fo0cdxIFTH93/KmMrYX+zPRjEP33x+UCPBvia9xkJViVP2/+zueBeSGppv7rfTjjc
+6yWc3wNXhS6y9rf9JSw1ytK0M1/F2x6EMcP3CVoK+MFvtKC+C+KH2p3YC0+ukd3+dFt8Au/7wPH
8aef3C3X/1bi1VgtvG5UksoL7IHLjD8g09SsejLlXG3hDew9cfPe9V/ep/fZ3h8NC2WPLdrfpdfI
LWBb8v7LwX79hw0MZkFPvrwd4ie8/CQ+sx02tKpWStcpB64cXTW6phZixfpN33j43yWjRKfu8d4S
gJXvj+Br9Ix1+Xztni1T+4i/G9FT80MaWPVChOq0afcZZpj2qP2p5Z0f/r7v9M7pDwvDFXx+WA9W
dcTKg7unP2iHW8U3Vp66enzhs/r09sHRr4WyLt9s2bt+gjEerPfp0oOntn3X1Q7NRqOW/bft52el
oTavVvA2WC3KHYZ3M49Ah/+W+Qg/hu6DhfZr8ohsOW+C1Uregz7MlkxZylQpAjb4sxLPv3Ycrr33
6gOOPCF45QMvtuj0wWWwDcPoAvg39SdH3//E9/hYZx6/z9okwkm49sMzT/8YA/Atzvpe+SAeDrw2
7G7G/oSj/8HNff8gXQalwKU3WtVpPQr/Xm8A5pJg5fMRwEcYia5NLK+H4fy2wo0bqb+9MPCXFEg8
BSc/e/pdXHxZIu7fGfjXWP0a39V9RjxE8hEE/qP8lUj469XHRx0FOCVuxzdxWfml5mHtJ9yE1B68
zNL/4d+cfvT0+5vh1g2YjbDyxf9+vTbhwUcmHAbYIG76p3DVd+3b/T8/AbdSVYZVtXiIr2PoyI8V
a1UXI6u6azQYJy3RADQfwmt9iX8m1g//MZG7yyUKHIeI0qyU/tzuomOBPWR6kpbmynOi5CbaP7Th
3yZOCGIMDcJdMjdGydl6yi2tRUr7RxpY4cRxuRgrFZ/J/34R3T/6AtEA47HholKYuUwiLOl2WiRI
/bmkVlqvUyIMsKuNiJgNl++erH313BrIY3zev66lSJqiITDwE3zkwN3xJ7Qi7J/Nb8E7IjDy+qVu
euyPAJp3GtyqYk+ZXQ/BKrvKpc+nwQrj18IJMWAykmCHXy9WPu6NhBM4tMLpxEZxlzc5CjY+aUBY
wZF7ePJnE+EY/yYtfVPsoeKwAljdFO9j7r2hzda6x8NsDEuwYq1iYas2MRklLXsgrCDhGUzuNw+L
WlcFfXeegGi+8FXyGvytfYfjmI0nQVhByjA/9NU4oj1q998KZ+/EMGNPp8AEfvwC4Be+Ihf0AfbO
OdhLeiXBgcb8TEW80mt4LLIbkkdyBldZh1fUBmj8fB459y2wP4L/kJ12rscbUesk9tXvP1gYDrC3
Go+YBUfmAiTF93lm1gGw/T3r00KBe+DUHSxk/JyTkLhsDi7lfAgp3TFlEOLoxuSh72/AP4Dlc/Gq
B3BV7J2BL83Cb6lRKPKsv3EVf9ZEfJBYHMW79NMo/CtZuCrTKg2s8F9rxTdw0b+QkjNHzUDLXRe0
6hgNFz4d9MKEEwAz0U6lr8EJ/Dod9dbPyLR54tus1038Vhk96K3teA1xa02FiG0Q88eXP2PTLtfA
+j2eDMdHD3zp+wiATzHIfCfjf+Qu+mAyLpQlDuERDofPPduLUIWG9XTVShyDmzVF3Is2EPBzJM+G
7394O8EW0ReykVupLD44vsmDkRV2+fVwUjy21uUpsRfi9NttFiS1YIUPww0cM3F3XwKsxAPCKlEM
l1nB7dp6hH3rAsJqH/9eZKzEfzBfeFjxw7ADiSLDKnAX3GrKzwf/B5EChVpiDqufhbdfCkRrg/sp
kMp7yr0xKS9piVrFiz+f57BaosW8oYGn8gn4Touoch6Wo6/yeTitrfD74RwSYRWwBmJ5N0RXNxL2
FsQbHGCBFtEAu6DCsHobxNBRa4vjM3g5pE7DLx//KjjAmsvRPgsS4fqb9UoG+viOg9T+vr4sSMCK
+frOhOt3Y9iA1WD8i20cJLOgj1LFX8s+B/AZH6z53h8N/xZiPr78aSBP74fj1WVhPsynGC4Z7JCQ
ibCKqGxUx69fFFy7C0N+EwA23YUZiiK9duMiky9+uYkbovImiEcPwgqSX8Ku7tfpDCTfh1nKHYPE
kbzvh3yaCtvRcmwq9pB/Gwcwv/o4TB6Mf4e5E07VxnjW4CBc59fE6h3qgKALeSsJrmsc4qfR+S+B
CPGNrAX5Z23scd9gW9A1iYSZwpOTD2+C1ap8glWbFNilmYx1XvxbF/ZQsk4PXED9Fy6WEbDagSMu
7hZCFB+mOMNK/0oKuqe9zqDyZ+C/dLBi7wK8yUtokQyzeQ/SHYdVB+HvYh97jQVbL4y6o3VrPkZC
1z1JPFFCWKXqWL1P+3PlkObtKmhJ6kbAKvQ9bIPJWgTrKWDVIBI26a3zwU6L/WYdxLbXkvj+ojSs
PgP4Qm+r8+GhVFjBB444ND0AN/nXziycxfHejw6fBvL5kQ4rPrG7Xo/HayOrYvsgTpsXBW+H8DuY
z4/8U7jlcIV/CfQDeJmH774FRzTjIBtt/UUS/QNhFf16vyfR9R88ZnUcxIobpF4UHNdMFYRfcAMQ
Tgdhu5aja0xcPw1WM7SIR1NhE7bgNYBpPiKmwGpIeRh9CKsIDUFIpYk4wL4o9h3jmUExce0ZK3YY
bt4jcjBcYx2r+bTPYldhDeed7qrMXrT2IsR/WEQLB56CPdog3kiQjSPBKhuiZZDFmAamHVnht6nT
Pe/DPsHxXVCIcAUWQnRrAavZeqGzIIYPepxglSRuduOaxWq17vMzTk/Sw6oBsohT4xNIfcxIjUeE
VWIdEe5wC/7QTuCNxm9N4XxL1+s4AEdUX2KIr1lV1KLb4iq+5sPPErXbPbYUBKzeB3hcjy8Xz0dW
OI6aZrRmJNh6s4LH4bAxsBypNKy+c/nrLP85dqIzHH8+i2ogrL7RRdG3LjjDqj4/pcGqcxJsFauF
SIrTB+9hfv0/flJfXlwAUfy7qL8+h/9Qm5jzrPjlNp0fDYewcnY3HxAnUOoX9BT3J8EsHAOfgqua
4YNbti0vYGXsogjZCTdqM/8dkKCNtBkbYBNjIITVaK2Qqkkw3581uA7HMCu6Iq1b4wC/j+NWrnEJ
/tGbIhJUS4JfnMJ3iyqeeUz/Dmb/weVaIl0OPrwOVh/kQCyTrBnBahzAi85Z5+JixGFtB/KhSEh4
UMBKn2yxmRCbBlZX7zQyF+4zcceJy2IV1QWsgnA+hjOMwtvhvMEKnhFhdUGbtyGs5mpF2WFV5fn5
+09fEwu5Oqy0ZXXcPWHAqli/n/47eUU84uQjK1wybakVwoqf5LB6Hdc7jNZc5nOHOy/B38YtOlDp
Bfaxjq6pN5kfSp6Dc3xZkbsmmkqzwNZJi+Ajq37ozQBWOJb5WE8YXL58sO5lwSWrPR4JN51htRni
jC+pktdhPZ+sGQ5hZYuPEy4RkRC/uDo/sx4SGuopil2BzcHMbwWurL1Yq7CRDaeBh5A3wv3IB3hV
o2GbMb+sGA+bQvnIKqWLlqLULVgRxIJxbWrvgOpGKjYJbH30Itg/cFobyWkRzZLhB+MUHqsu2LDv
EtbuZ12qvyCukdPpbHkJVtmSzWWmjGA1CaCvcwZ8Ou3kkvEcrll9padID6sIA1btcPyD7tbmj8/C
rvQjK/aqeB6Iy08/OV8NYXW8rIhID6sh50SJV+Z/mSAGfziyOo6zUu4MWPXE2xXdzVXjIvjymu88
gDAtBSv8H4cVPoV0dsNYS7zN9RTsoUSV16wQLYudBgt6o2rZ4NrCX4Sbt9QG83E0i8NhoydmDiu8
FdI+RCvXd8Iv6w9Eco2dYBVyAeKWztOuMj8W9urTdVEFhNXNJ9oK1+nhT/C7aw0CIfgMxC/TM/wa
AwcQS81PY6Ex26Y+rY2NEFar9FEcextsQ1iXJFiozQLxK+4SHCnJYSXG9XiZUjdhJRKyJ38YGLnl
+0c0zP0FqevnarWaewkixJhRl6WnDT7Rvcah+utRAO9pIXwA3taIz+6RYJVd5dLnywhW+AU90Dn1
fEj9rPv9huuJt1KWYFXtKH7LfdK3adlCxQ66hFVVfOtDQfYBpHZzvlomsOqbCEkrR/SsW9K/eVwG
sLo7HJ+Ej+nTqHRQpbMcVj4/ATTViy92msMKl8qmO1pz/52s/nXYiCgV7n9KbwrFGa68tN3x+cHV
WAsb9l+H43uLZkGUMarJFFZ8DU8fuegCFRx+PoWXFfvPKQlWFa84roC+M85jZYRVhDZW5oU8Ew+J
uJJQ7qKU4RwHVMMlYt+BLWIqriTyBfZFPAN3+OTuPfZoin35kYWegOO4eDYVopppKXRYsftWI3Bw
ZT78q2q43r5Fuki8vnwlcjwN8L6W1elzSCIcLyLCOCLXV/WcTt+m1+tgNeo2BbqN5BnBCs2of72w
Ei1bl+czqeFysVmCFTJP7BnAHTPHXMKKLYD4ej574BB+RTpcxrAK/RdSXtO+Wu9NdA0rnykA32vL
prUuigeX+MzpIb3wmgkcVoPBPirU4kuchv3GQGCU0mtWNRIg0kEFnNv9B6ltOKyOjftojO7GPi1G
VlmDFT6BgM4O0+BA9VPkwM7Jr/VpWugX7RmuvmZV4Qpc+2q0/SKv4hTN7hBWTjvYA/aJjZflwuH6
144Mw7XZX4NBc07yGfw5fAyAsJpvlIErYkPZ/cnwoxFR/Casx/FZelgxvyYvLDyXgGUcqMJhlTDt
Q6NWY95zngbik4FxojTfQiH2SSveqZH8CYRY1msjPDn4IFjlQLw0WTOCVXuApXrS91PiH+BfazP0
cMAzo1/D9Z0swWotJDTRstW46WqBnbFHbfBys3i+q9TJZQyrO2/AQX0IhGMIfc1KngYW2APRVbTC
cPDF16zwhhmjl/6KeBrYKQnWGLOLB0a/V4wxzKOv2+LjbJWngfislm9+srsmN+FQYVYLH/Mba3L6
qayOrJgTvANKlAhk7ZMgvLem3iIJVoUuwGU+K3TlZFgxnJgPFtPAiOquUhdsPfoYwEIBq+XGiHcK
pDzF6sbAEmMaWCsRZuJJF7DCMn1COn+Jv2v4mrHVkNTR1UUwrgc+JhalVV53cIGRJmAjxLUTgT8h
rrERm92jN8FqNX49SDdfdkXLIF9GsCpzAKK0xdKiuyC8GKt1Ay7pN2IHG6zCb2YXsIqC38VN/CcY
a1Z74HoN7cr4DMrFAjtj5U/C6s8hoZVUv4xhVTcZ1mpJ8aGka1gVxMVkbbWC4XN8Dqsm0cay1h17
BKxKHoFbLbRiakbCAVyLHY+jMS2iES6oPM29+DNrbGbeOPdtCvV5E39poC34iKpPBP6UDUeON4xZ
WcnuPbklswyrp0DsZ+OlvXF0T2M2GmCYKJr5/S1NA9lGSDUeZBTs0sNYERNp08DqS22gvhZsGhYQ
XJ17IBiq9+imL67XOwWng/nI6ohuywLrILIhC70K+/G7RbgXbOIxYFpY1e3RWedyu6v8WTM+H31W
z+HbukcbZ5s2ToFfxQJfqUMQYYztQ3dApFb3zXCllp4z2weCVbalS5cxI1ixZ3EHe2VMXgDvqx/w
iCZfWIJnb7wbknrgMT2sykXANjGYdsAKNywM5Zl8n4kB2IMeeVMoPzUV4q7D38bXJ48RTwMzWGAv
exoixapD8clI8a8wbboFdn/cfyNWhAPfScbfy/LicLC0qCx6Kv2BmXAayB/fbxbf6ZXw24DfyhXO
QOxLeGTV/sYkHFb+Pyxf0Z3H5IVzH6xYWXwAMdneIx+JgxvY8/ymA4jmYWNwdy1vlwwrLlgGTwMb
3YTDGh9CdsHpIpgx5T5Nk3rRdli9zGNwKVAnPhd4lJZI+0wDK3zC8Q6eQLD+qKfSnrTghLKrHrEK
wkM5rERlMa5jPOzxZ74rwfaglsJvFcTx9e+0sBoBoH3N8ueCu/wZ/g5xTQEtS4c4x6ySx5SIgL/E
ggGWlfiYloa1iYYT2gz2gLEHQj+TnQPBKjuquc6TIawK4tsm94/q/b8/bXDkTsxbCcckm4d26vkR
Lop+y/tCeljhGCzl97E4YnHAqk8SxH7Wvt3/1kL4KYgaWN8FrLogHOwdSa9kxiMrX1yQOjW4Tef3
D8L+KNjVo3J6WLHBqXD9nbbtX/oHTl6Ai4/gvp0w3OVz5PsRP56D49cErIquxV3Nb3Xp9tYh3P4u
voeH4492Zj7d+Y19cCBWwKrAqXTVci2hO2LdCCv2Mq5+T9JWZvyfwDXvD3gFu6TAAW5G3Et7E3YX
x6MTrMaAbSDGZAAr32mQ+iHPyV5P4Vu6xxq/+S27Bp8G8vUxXPp5k5+vcw2uaZPpu/Fno2E8ynBp
YIVA4dshakbAjU4iSb3jEHkXjoHjYZ72vXXnKVgvpoGwtShPUW6dNhjrkQjb+PcOYw/EwQp+I6aF
Fc7tvhAJWNMImIMPDXdqzcPS8MHg/dop7TNwvbFlBlcxd2r6VPpHG7HjL68uwXJ/5+TZ8ROssqOa
6zyVY+FfbhAcn1wqIyWpYjxFOci/vvB3KWhE4WxTxUgdV7Um6hnweRFP4/M2P/86Y39BrD75C/he
ywP7G+K3KL7j/a5Y8QOYVql8ciJc6H7cwqUn16OY3x4ILycCnWx86YI7XNbti4cyuCYj3PyKK/D4
GvPfC+Ha3cs64JgCkwRjfYTbVAMzifcnhy1IFTFbW5+C6T6YpuJSLQnACq3ZQZ/ZtJjVfRLFbw4L
IOBewJR54twJK/9vsCHHJz3b86E3/0Ju/RbCWxCAQ6tD/asWqf/hdUjoyWOcYIULktsG3ltA+20g
nsId7PV5Ev23gbUjIPXHThWafhsL4RjfIRmuvVIytPqwQ3AVkh8o7Mu6p8D+/92H18EbIPzl2oVr
Dj4L8Covwe7SwGqIvgSKA7Brw+oUrvH8aY13Bf+A1DmNCgeHdPpbjG9xZGWDLY+UrvD4bnyszCdq
AYvwF8x9KoWUG34ZUjry8tPCqug2SJhYOyS4aJ/9kMTHgN1jIfbjxkUrP7YLt1DpYyyeEd0HANoS
ejDe7QdfbV+15Wu4WHacTylwN2mi/itnEcrmB8Eqm8K5yFZi4ux3+VeZ3zuzJ2jPa+2JCo/cdP7q
kQ3viskfxhZ9b+f/2TvvwCiKLoBPKkkg9FBCC6FDQHrvTXrvRRGUKiDIp4ggHUURFRQQUQREkI70
GnqHIDUQeighlCSkl7v3vZnZvZJcQuplb3fmj9vd6fPe3G9n3szuhurC7+8YSP/s+GTsyjWD2Akh
I9b8Xp6eun514NwhHMZ/umZJISnIYfjpZ9FBJ77wIPmWXb0+lRRbsobOC8v+tmaYFINMwxVD+Vw6
2k9fs4DdT0nlFWtGc89ea9bUoWce318NiXiwc4ADqb7H/2Jn4jBjzQKp5hXXrBlMo7hMuPAi+smR
cbmI55rrV8ZQL6dei3Yd2jgmT75XkgHGZezxl7rIwENj2MSVRhlw9LUu/PI8d+/f1tAO7Dh/J4MW
Dcpyl5mwIs4zIyl3dZS+Cb9LFh4PSufIkFjckDmONWctRMpWJZ9QDPPP73wVHjG9rYGwd2gcnKzR
CT/p9QZzi8I59ev+eGWPhgEIC8ac5uPzLfFnUMrIJqCmcifKyehXdC1vmTkVSj+GENZHaH7sUcwn
JfDosBAryROsYAPcakH4tHHQ5Sd4b1mJN1GE1Xkc4kfRBt3jSzUVEFsQ8RjNCvF0JknISojkwzni
EQEHUJ2tMXbM48t0I8W3LMbYKMz0Nc3jAL8FMl/6gyvKPBPSCAuGeNpIuNyMh8+FOF6kIXo6TjQH
q6/SIaTMSOLqXaGo4b+MGeb1qVOV33SSy90x6Sf33MtVL4cWbHSFilgcVP8P9JINJLlcE/kXqlLN
i3k5eubn4EwUAWtaoXoZXvPCHpTFzFFTarkE+EK6dKtU5x1v07+US+U6VWUy0zh1+V9Vip6lh0yF
FT5q+dfTOPzXJQTtbW8QufsX96lf6Ak2riLkuwA/w0RtyO2Xr4/kddoR4Mva/23AhYq0ueMDbjVn
zW6y/1UCRAat5XTLNS0Icwo73dMu14aQqCNuOCO79uL1FdozHIZcp6SK+G+oqWAxoPjRgHNeeJRc
lVsBd2bRc/vBfkgSiLz6EWMVIQ19kYwIsDsjqd0IYbWj2B/0aebgX72ltEWWPKcYDjvTlSt/XoAf
Qyu+9OFSwB80m+7nEGWY6ZUBUu999wjNNObeLH4HlDLCQ67/YJfUhWpswmJAH/ZwKh3AoXPaC36u
/DQDvwJWGRCe4pK6+8EZ7O9Z6Qp069dAyr9PopdiplTs3CiTsUBKETMelsmwQhNj30+nTxxYxqxm
hftM/mJoA2rmSeJyVWXft0nib/CoMXBoG5kWOKruO2l4I3oTcK7fnvm6VqktGRHydJo0dXgb01uc
IY9EJ1JFcnacNHVEW2MPcGw2bs680Z34zB5htdeOVPtwUn8DWDGXckOnTR/T2IDhRPnipWubifPm
DG9LTXPcOTYbP21MF+O17I/DeuPjf9U+nDptSFN5TkDKh8mrnobY6TjREqwO0FtEdo2s0qGbtCfp
BzrDjDDtqVOVApcQr/B/g8sReGK6KzCF5HbvxbJXqaQQJfOCMh1WmVe1bM2JwioFKGW8bsWfwORk
cpkD/vJuj2RipMZbwCo1UrKFOE4tffrchtsW7niZW3s0yq72dnZwroonC1KZdY7r2zKhr6ayMAEr
y4LKcljhmsAttl6UpPwid+i+1Qw7AasMi1AhGbj6R6H5YXSW16biHTQOn911EU0Zh02tUikV7OCd
pbd086IFrMzlIV9lPaxynU68b0YqezR71lquSLqPGoKVPW5lUfE0EL8BHBs8VTKtprs/pCJhtXV0
wQvg+ffSfuhUpLFmFAEry9LOeliR5rHXJIu6WRXy+EfzLTtmvmm/ELBKu8yUmcKu9YguRrNtltax
5uh5P8/6gC6XK9EJWFnWSuEw40OclmNk3PcXi9O9iYa99RkrQXOwmpYxeYnUipeAgJVlFbkOn9BV
WjW0HCETfPN2ZPv3zHOyq9tRfgTRPCCtVwJWaZWYiK9wCQhYKVxB6a6egFW6RScSKlMCAlbK1EvG
a6U5WE3NuMxEDoqWgICVotWTgcoJWGVAeCKpEiUgYKVErWRGnbQEq0N0wV2MrDKj2yg5DwErJWsn
I3UTsMqI9KyUttHcuQ0zryj7T5ZONn2otObSpfyh2swrIltzErDKVvFnYeECVlkoXGPW+YtZfkuC
MUZKZ/h6tUkphZuEFShW+G2bxfF1W7dMH8oZYPxsqUlGtnsqYGVruvOR3kb6tnoLWL1NQpkSvvTW
qQy8dQDfw/ZZKqux8tbR0m+J6ugLfqb7Xvqwr6O8JZENBQtY2ZCyWFW/e7Gln2mPTK7+AlbJSSZT
/fdACHtfZPoy7bxhA3txWypSH4Vg9vqkFKIKWKUgHBGUDRKYi7bkO3NTek8Nr5TmYPVlNiiDvUk9
lUPdDFYPX9Be4S1ZCFi9RUAi2MoSoLDCtwyemlg25YK1BKvDVCTZA6vt8PxtA56U9ZTa0APwWEwD
Uc23UvtCiNQKVsTLOglwWKHWQjYPSWk6KGCVcR3k6/Pb0XO7p9eTcmo4oLMrqT9/u/Qya3yNeYc+
lyDs8z7S66jrT1mzZekQ6ZXG9i0HvOtAWv2wrRxpM6CTE2k4+59V4yluqk7+e8uPXfhbIr3atqXR
qw3oVYCU/uj3bSvHGF5b6VBv8u+7//6uXzFauFvnvtfg9ad9G9MLUubD5VtWfWay0FdmyMLfZnfL
TZLarHqSGtN3HF43qiRNV6DPgC7yaqF3/wFNpVfVYki+tm1LkKLDscAx/JFpty4D6pMc/X/7i742
lxTo//vRc7um8qfD8g/o318y0xXr1a2Na90B/SvRSOic2g/oZ2rh576Z9itsVpkmSitlZIAVvp7+
7oKGyb45RHOwkt5pn4lqaIsf+qAucil/K/VGeFh8NL5FpbdcRhH6DQB0h6lHqb/op7jxlf2fsi9C
Oh6H/wp8g+/abkAuwB3vRfSt23C/DZn6mp7AOpYlGtj/h0nnQ0y99/A7MegCe/DMi21hb8jGkcQI
9Cj5jAWy7z87TsZv3qELXylhkYzBj+qiO1p9XxID+4AJ/K0vdwdiLvmfAtTl2dMvHJq8YA8/wjOm
9Q2Wy8PBNEaJIFiVD79/E+WBFx0usxAIX0TfwOZ+HOAYexWby0aADW4TAf6hSdCVi4Pnlt4kwkMz
/CtglWERWjkDE1hhF4o7+rmX8QZpWhUBK1NppOe8zQu0Du5ctScEYDcbw66Fa7PxgyJGWBXY7BcG
8f5+izD7UhcAXhzbfxsjLKV3EMeDcHoh/ZM3ICfhzjaIuXAKM7qFnz9+eJJiYSpV2yT+MaY58Pr3
WLh7/AJ+WySIDVPy7QR4sGPVhkv4xZEh+EmAf/3CIe6m33f4Qm/ETNzFPZfC8QMjdKBGyFh8Nd+L
M/jOvBv+SWCFn+S6u/8ofsIkpgvG/N7wUc38fhBWg6VmP03xw4Av4NqOXXfxKwQUl/g50zV/YS0j
kD0dEa+3d6zei9jbTiFVFZn3KU02AuCmJ6n0Cu5KL0EeDfLH6GhwpjsBq0wXaRZnaA4r7E+ha3vQ
219ipyVY+aIY5K8FJZZDuq+L+oNuIf4L7WoewY//UbSshfCYhJV9mhqsJvZ5C+yDl00K4F/YZTfA
Fh9Xh2K9EXHjMTLCKkwXubhHY3f7k6CDw43y5Wrgj9WMmFw6V5GxiCbKPwOs9PB6ZAm3fK3vA8yl
Ne6HudEJWf6JsXDMhdjnK3AMntUv4E7scCBzt0s+u/w1fQF20p1XVd5AzMKKufPVRY8ksILIySUc
XStsxc/I4RfrmsXQj+9S1zQeDpjc5BBWEP8/fEFxyW/j4RrO5BBWL+HZjA71nEjZe5DwDU5G7evi
V+MW0kQf6iDYh5CKjyGqHcpnL+i6sUzt90N0S3aWNT8CVlkj16zLNQmssJ/5/1SXf8fJpFgBKxNh
pOf0U4A1bEJHvAPhdTXMYi2OaT5JlNW/EMw+KTJED4cRB+i6RsBVxBnCCsJ6UQ+EFQSwz5pMwjEQ
21flsBN0dGBjgBXoBtGo5IN42EU/iPI9vCnHPMgxCGRmq4PwhC6peD2Bl3wqV/w/iENWkMUAM1nU
QvituMT7rBLYEIjkOwv6ceyzu29qsbhfA3zETvgPhRUdHvJPqONnuBBW8Ijb6n4AWEGrhJ9rCeLb
J1zwJe0bnO3X8S/Tk6H8E6ks/DIdemWV47Big9ysKkLkm6kSmIP9KqlL2DfSYJrlxQlYZUzsef6D
KHlTwrfAvjeEsPorcab4EXgay/UwhMsfsvoL9Ghxp7D6lsWmsBrFzjpFwy3+MaZvQN8BvYyw2s8/
IefxCk6hTdv+s23TJWvkWghjNm9p68InxiHk+zr6tefyQXBbGuoN1CWB1REpl8EJsBuJM0vaMe96
HZ6Y9heE1Svp/aA1QuGUC4VVwlBW54L34E0Fdsa4OJKeet0HGIGMuoBjMJwAP4VAdvIhwBzqkVWO
wep2YUcn4WxDAvZ4T7Tsgjd1438E3lcErDL2n3lHx2dZNBf8L6/D+Q/Cqn3iTCVYlX8JV+UgnMLh
KIbCin9WksKK24eah8MhPg2bCdAH4xthRe3s6JwC+fe/+RWxc675CEJNYbUH4nheaMgKgQPOpLvR
Up4rKAms5Id58gTB+Tw4ZYyGI66Yd8do2GgvlUEP2MDd0qzQ8TLcKkZh9ZwtBOJHTGGzFETaSt8z
J73j4PULCOHv33ZYDwn9MROH7RAjfUjTJOtMPGWwijxyQDgbkcDee5ZRxXxv/tyYT1ywhwhYZexv
gsj5Rs6hXDwcRcGuhaiaspd8lGDVDODaOO5G47wMDeEIqxfc7oywCuFzumZvYCNPiEMcM1jphnB/
p3twlVsgnap0Hfv9xotRaJQ0gVWOBxA+52NW0NgJIeCXn0wAGC5VxulCElixeSgGO1yCQKwNfj83
jvJkMegpXgwOYTVPvtgCr6pSWJ3nNBsizzIxvKoO9nNwrcD+pvtMStJfB6vRu9Qb2OMi55IVRwar
FLq/CLItCcScHM1WkzQIK7S0ZKb7GGCsnF/pEDiP07S1EEpNV2ZOglVP826ygsEq0JNFRVjd49hC
WK3nqRPDKn4A95dhZdfON4hlGfzSDFZFn5kVdL8I3YPQTqqR/bYksGokBdntgIjyeD6cfQUo91V4
aGb6QVhx4xZGWQG6xhRWRziscPBnsG5VCIcT3HxVGr8ifkm2k+a5D3dwUI8SGyEVlzUHASsz5avh
IvTv6rSvaG5klfmwkkcspHwc7MA/aQqwwnHYoz17ZbdvAoPVYwOs7jIbOUkBVv34/1uG1bAYtCKd
3rh4ZJl/zGBVMggiDu82lPNHfvInQGuJDQ67ksCqiRzkC0/oxtByQXAiB6mvk8zpUiidBnKrGnps
wE1fFFZHDbB6T45WLR428ZHVKD3uSpbLJT9RYDruhFd8AClHz+yjgJUa+GTahsC/ervRXqIlWOHe
AoBMhlU7k+lPQ77ulQKs3sWNSrLh19HOHv/nOA1MP6zeCYHwL7yY0WijGazcH8PTilJBjva0nGkA
H0hUcL6SBFZ8TwHWJgAu0rGU3VYIrUW+hdg2Uhp+QFhNlj1OS9NACVbdTCTbEmA+i1bjOeh1cK2o
lKZFHKwgFZ6zPatyNllwFLAy/aPb/PnL/e/xe7iAVUb/LOV1sJ6PIgx28BRg9U4UXJFLdC1XHjGT
IVhNNqyr2R00g5XdOYjnmw+wtNLlcOjWH+B7qWRcSky8dWGWFFQ2DPawCVwf3Ibq6geX5SkcD0dY
/SnFdL8P1wuZjKyqAaySgshUaQCW8zDAtF0YwAdfJNd5uJsbjVv95YhZc2SwCp4ybrxwtiGBUfuT
Jaru/P9MFmPEyCpj/5gCdyFEWt13OA5RdD6VAqzy/QcRsn1oadiLuhmE1R+gozsb0BV9bgYrgjvg
p/IQ0vfVm7mE1I+FW9LmpnFJ91mdkyzeiJmveH6PYH/zCL7zVMoHDwgr2YjVJx62sH1W0siqaBC8
oBNIdI7nIYLtvfoKYF+O6q9BJ9vv50LsuxvhAbfM8chZ8Mtg5c/mDVmQu8gy8yUwIxlY3f2ztdnd
UsAqY7K3x9HNMj606hAN25wwN0uw+hdeVaYF4fa3TTQOIW0j2C6BDI2sFoJ+KMvM+TdcDfSipwch
qCwe6kXCQ3okpNA5iEWEuvwL0s7PEteSwiqB710oHwCP+L4W+1UQuhmiTe5qNC+ElX4mPSFFTgKg
sd9os3JYJO39JKRbDKx3xDiNwyG0DiG4a/a29HhitVjY9hz+lEeiLKfM/2GwEm9dyHzBZlmOcy3B
Kmz3IPmpVrlgzcHKYHSRJZDBY6EA3NVdzp44dwmA+BY0M0uw+hN0X1XDEUWxG7jRu6ID8XjvGcT2
xsgZghUuLt5siVtNm22EOIipQ5AC/0DC5KqexGE5PhPYLBdxa4BTsaWUDg2iIXZqGTtnfBomOvE0
UA8xn5fJUaQ17m2Xx2O94rED/ZtoiwHCCuKmFCc5G9GnlDHQCCvihU9rf1/Gjrj0vAdxDbHAvKcB
vsajuy/ASj4RdD6AGSR0Qs+sdAJWWSndrMjbAqwufsPW/8xLE7Ayl0far3rjHqdnl3yvxeE/nf0n
LcEKd23DyzWYeSP8TwddPndXDwnTaFkZgpXrJnyrwoXjN2JgC76Y4dEGHDOPxcHPy9/wbS478flC
/9M33gAcYPvGyRQ9wBO/q2Gwb11iWOmWR8PT6/djAfbklQSQ0x8zMqzvSZ4Iq+Ov4aHfzQh81hof
+zOFFRmEK5NPL/pejwc93Vll9yPuWihIE9Z+LQ8AyUisg18iAtIomeoErDJVnFbILDGsHq5oZbZl
Rq6ClmB1FIlhXM6SJZDhY1t8ZwF194fy8cOaeNwumci5b8bXLOyknlU24x8W3c1BbDbkuC/+Idq/
0dkfi7/Nlz2ahsT/zbzIjPh4OvyaGB8/Hg+z4qP7cn+ngPjLdFOo52qWWfAXOQtiJW6gwT7fDixo
IwblnoNvQUAXOl96ysZuBN+StbrID/EXTPtC7/j4Or0e0bjRP9BMuZsN8Nh4xf0QVlPaIMVweLSO
zWqL340/zBuNETpKr8q5O5i2rH14Qvi7PNm4uITAiuy0LL6JYSL3zLpfAausk23W5GwGq8jN/eXl
48SlCVgllkjar/N0XvD3mu97F5JS5vMsys1SpjnlqN6zixfzcGo6a/Xvs7vLuCjgWZitvxFSUD5z
Luophbp7etLHXnJ5etKnn3PzKzyzK+xZiEHCoc2Xy78bRBlXpP/HjSkkXGr27Mwt3WXH/bZmgemz
oN7j/lg1q4kjyevpYSAMpnD19HQiJT76/qcJVfBKdm3QFiefy0eE1XTi8cEPSz/FXKhzKOzJBk88
Qt5u3/+9ZoH0co88xT25+QtjeXqWkOzdpyBY2o3Mk2TFr4BVVkg1K/M0wirhwszKSf88ctmag9Xn
csvFMUUJzIMYankycwxWZj5pvCj3jD09mcZUaYwuYJVGgWV7dBlWz5a0wslB8k7AKnnZaDmk4AM4
RAd1Zi7DsJoEujZmOWbFhYBVVkg1K/NksArfM7LwWwrREqyOUWuLGFm9pUdgsCtxnaOnWxMSuQzB
ysmJVAqAfUkImKiMjF8KWGVchtbN4RuIvfJlVckakkLRAlYpCEerQT9uPhJHHw5M7DIEqwb7Nj2E
+Kzet4BVFrBKrDelX4/5uXWqlogFrJSuyWyo30kcgQbKDzeblN8cYLbJZdpOGUOWvP32mbZcLcQW
sLIgFEV7pYpU2AIBK0WrMXsq98WxLbPY1oRExZf79bf0j4yq7D60bDBfREyUbSZfClhlskAVk53m
YCW/Ck4xGlBgReycTLc2ZFYFHaxBKqysgFVmaUxp+QhYKU0joj4ZlICAVQYFqNjkAlaKVY2oWPok
IGCVPrkpP5WWYIVP30rfuFK+XkQN0y0BAat0i07hCQWsFK4gUb20SkDAKq0Ss5X4Ala2oilRz1RK
QMAqlYKyuWhagtUJW5kGZsVanM31zHRXWMAq3aJTeELNwep/ClVIsyH9+HunSo+cv6qxxUrW/HiE
FwbUHTJAfp+BxWhGz2pDBpfDq24fD0z+SXZj7LedOfb6uIuVdh+8rSophmseVm0+6Jz06YMURWYj
gQJWClHUdohin3hoew/Hf6MsVgrfkN4dA34FsPQ0sHO+vIm7KL6TaiQmOAOP6RtmUnI58uV1Timc
huW8BifMXon9tgTZFG4LsMrXe9WpG1f2TvHJChkdhZsmL+6xUIJLKrRtIVm2ewlYZbsKeAV2QGxt
PHPDp62D/bpYrNRnEN0ZA/B965Zg1fnihV6Jks0FGI1eh+HW22DV/eKFrokSJ7l0Owv7pddSJQlT
kocNwKreeWqRQPdqShZM+Q/D1ZRhNeLiedqRbM5pDlaTFKqi6Qe20Smb1wN4XCGX5dmWBKtxB3bX
sNCIYSbfhpaC3ztwoCOepgJWo4xfl7eQNfcSsEpWNGkMqIyj51e+Ww/ie1Oz4uvUh+BKyrDCm9iw
NFZZEdEFrBShBkMlKgeDr+Ei0YkEq0S+8iV+kI8Ooyy4VMAKvxf/1u4rYGVBtunxwk/Iwu4aOKSq
+CfAA6/0ZJFimrfCaibAkBRzUGiggJWyFFPhBWxNrkYpw2pwsnfpVMAKh2VDkitW9hewkiWRwWO1
13CLv20/t29W7FJ+K6y+AhicwTZkS3ItweoktRIodRroXau6GynwTu8QOFSjlvSNB6lH5Kg/7psv
u3sQCVYla9Xknyt17/7V6n8W9WPfm6jcfAHA4pbNXUmu5m3LE6cu33/jRIrWqkXnAwirHE4tvtnw
17S63EKSo0XbOpKtpOy7bfMQn+b4KZqFLZtyA33x3vNXLDD9ZlvRbtO+GVvXyVnYrDLnLzoCYIaU
0/sA6wxzfpcC+ZJasCrUwvdfvPPZipWfVTOWXm3U92t+nNSMdwPqnbfH0p2bvuvP+40BVnlavduB
fxkgX9sZyxeNrsKy92m+BmCBpO3q4xZt+vPz2lZ4c4+x9uk+E7BKt+gyN+F2iKxFhlKcohthmneV
3fjBGoDrnSZwA/uvoG9Nwzufod4A94bgxR/8PLQ08QmB+YU24LdpXIi0GngYrvvgR7vQxa1lHw7x
DIXj0juE5gE0xC8dMveyOGbk8Cl+LAzds/nSRyvI8Dv0On5j+RPCwI4CyrjDz2W3kHKpHc8+dcuv
PrpyLsmeFLuzcK3QIvzaG35ZbZEEp1L/4AfWqDvTQcrm3Qvc40of6iHDymM3flKXfaGozyUWHr4O
zaJ263jcF9gVCizmOUn9QspNsQcBK4WoZjOE1iTd7zxKgPCAe71NKlXxOoDu3pUQeHFIz1YDl0Bs
Kwyv8wKiT+88hN9XjhlEyOyA5wAvAs4UJ1WCYdEW7I9PXQh+lns4xjwMQRdBd+v0PT1+z51uPij6
AnwlWCHPGpD5AcG4BhlwAt+B7bQQS/M/fQf5eIDdp+1G4WnYtTt6OO0vYGWil/SffnsvgK6lUNdG
B7sNr56bDpD4G8TE7iTc3grRF45hL4DVbBBWcD9+APL4jsP3UWf8mx4dXuEt68jxB9gD6mOmEqwK
7AFYxfg2Cr8I+eD0DUTezcrE7rsA/Ejb84DjHsRlJUDAvt2n8PrfxNteWPUU9iNgpRCFMFjlLNHq
FWwt4WWynckBrbGXOnkVqIXGWD6y4rCyOwgv+mAP8xgZAtfykfzFJwJ8WbyYI4XVU3i+YFArByOs
sJf28HT2+jAE9BOwvYlhlb/4ZID/FffEyQDmcqdvUeeS7fHP8RsVTbVwSFhS26NEV/pvEVsXMqO3
eJQqIU/9FgN8a8hyKsTyj6gZfHAcdBLFfrZpLrtCg59JH7PG7XZbK+CErvQiPfxGJ3Zl7oF+QSli
7/0T/042h1WRfUg3tmWlaTSETSqdo3DDXfiR2tykQPEf8OuNVNtd4mENjqada/mmwmRpUqnsOtUc
rD7NLkm/pVwGK0LQwL7aLGbjCLhWgvrYYVc0GVmVfCJb4r8BqIfhsoEdYQU36rA8DCMreFCWefTX
QQAOnxLDihDZwI7fynrObSM+9+ENPcPv0M9iacvheruAFRNFpv10DoPoZobckoPVYz4O6xkPJ3Gg
ZL8VnvOvgLpfg4uURosA1lJoEZedkICfZWSw8jgMsIaxys0X4vuxQgogv+hXtqdLBvZvWHT0qBIB
W1gMZf8IWClEPxKsqryAv8xq9BfoBnIPr4emsKobBsdYDyVlJ00qgzGGSFsXEFYxnXgKA6wSJCOY
wyEAtHMkhZW8deFz4+rUp3oYRwhupbghmftx0CVgZaabDF44j8Lp23fGTJKD1Rc8isNOACSb2y8n
5tCv2RLiuAse4SNahe5BJL2toOsZEzeUwSp3wQMAy92YZzs9rGEnhDSJgK2YVtq6YLfB8GW0Dz7r
xfOUIirzoCFYOZzCETUofGSVGFa5noM/s5Fi91ljCiuPh6D7s7JJpzKB1S0n7m+A1TNvKeKHQAmU
LKzsj0BseSlquWj43Z6O12ZLHkXCBawkUWTKoSbOyuCP3Ma8voBYPmQyetFpYGRj6XokwIcmQaR2
EDxEWNUHOMFvWyR3q3aovkNw6R1f/KC2ZIbCgVdPKZnTDbiK6ybyPiucUN7tZTCZmWatzHMBK4Xo
JZmRVaUwOCA/tTfXFFZkDnb1l77T2rA5IjbCBFb7pDYZYHWbzQfQt70eFqYAK/dgeD2u/0DqBnwU
AXvdCPZn+fuB7rcErDKvs3jOwWHV00/ZbcW9Rk10NZZAXAd6Vks2v2NpCKv7dJGWunYJ8DU7sfdu
PvirP45gBhRWuIT8I/OWfw7Bo8vYOVZIBPOFuDl9mU4H9r0Nj9AgIMOqKi78xvqveL+ajQBLwEpW
cTYfk4FVx1hYJ9dslBmsnGbgIg66O5t7ONAYJrDaJKUwwOqcnEX9N7DBDFaIvAYYKE0DvcJYlvLP
uTxkJYB8Y3c5KGAlyzHDxwH+AAmr0cBEXfPQqMjIyIg4AHqMjN7DFMqCEFY35MEXmi+ZiaD1rkdM
QxHhDFY4dZcmiiwFHVmhi4fobuzaSX4OkaWB0KpGWJHaJxOob9ixmfItT8pCmQcBK4XoJRlY9U+A
VXINR5vBipCyn+96QPuabhW9M5rAarOUwgCrC3IWTaNgmRmscKeCCazKv4GIsydOSu7UilxkMwA3
1qP59rCAlSzHDB7zfK/DuZvhYeK2VIsm7pQZrP6TpnOkVSz8jgV/FoN4ubx35YTqBxmscPA73qw+
CCvd3LG4M4/ZD9z8IM7PqNM9OGyTR1b47e3uv19gm7ju0zUapTstweo07Q82ZrNqGAm7pOE8mZcI
Vti3vFrNvBDP7FApwuqGPJPszAzoRpuVHW4mNYFV4RC4VyZnLuZyurq62BGEWXepD4tpYGb9md3x
FhA4Qp6aE1Ji7Hh0Y3ZBwoxxePJJD6OxG0dWN/NI5fZh5vj6kRD9lU9B7BROHFYDAeYaa4ZJD0Hs
ZDtnX4CfaT52pyGipZtRp5jQCCsMz1f9/Q2vcHuMbBk1ZqW4M83BaqLiVMArlMzIqshr8MsrVfkv
U1jlLlSAd2nnyTGwC2OkNLIKQkMFc+MBcJMzwuoYN1PkOGkGqxx3ILKMFJXkL4h/pzEAn0sensLA
Losmg8dZuHWqWtI8kjGwP5NNWBPYow1fy3tJSM4zsoH9bymzCouWtKOwuopdplkEhLeg/rhRzzCG
y1OQPpcgwcrZoxBfLyQ1r0FcLSkPBR8ErBSinGRg5XAVElrxKpYy27rw2eO77KFAQnLfgAuOKcNK
P5hn4XwOQrHrezyAp/x2XSXaDFbURPWRJJC+gU+GoVFXB2ecuA/+V8TWBUk4GTrUjYArXhZySGbr
gl5a4ch1ARKqEPIvREtWxDJhDFYlXkKQ1BWmADBYsVfEzAO44I7FfIIPjUql+Vx7TCeSEqzKBDye
LQXgtpT20qmCDwJWClFOMrAi+KapnXwUhLZwk02h7xvWsUsHAjVSpTSygkv8edZherodgeQ+A7qm
tN32f+PE2GQaSDomwGU+kCt4EaKqY9RTEDuIiajYTQErJogM/8wG3buWMkkGVnCGW9hxkLsPe8I6
iO/AUjv9iQ/RoLIcfgGYx3zKPYAHGFd63KYgPon1Jfp7B0MoH8c5rAD4AH0kWLk+gnPSsxILIdrC
UI9lqqAfzcGKPm6iRJccrPLiYs7qio6k6OyEBFNYlX0Kj3rigIp4I3BwCER6AWyuXJQ9bkPZRZ3B
wA5wsH5Oe69R4RBaG/3t8A0N/zX3yF1jGURyWA3Ap/8rFXUgLtuRjT6OxKnufoBfaB5ddBD6YSFi
X+MYxImRFZVIRp3Tf/B68uiPZddNGrgS3CaSzOM2W6oS4jkxEhIopdByfqIyPiPT4B/Qw6ti6FPm
KcR/UZI41zvK1wUlWJHeCRBK7eY43rrWEqlUbrkeDtERNY6j1qK27fBdG8vovgiX91/BaTo/VLgT
sFKIgpKDFWkXgvtxTu27BSFLY2M6Y22lB5lxdB97+p+l2x4A7KDrRT5vAIJOsweZk8DK/yhEXDh5
Hx9k5m/Iqf4SH+K/7vcaLrIHmQmpgUtCz47jM/9e5/Ah15M7T4cCHGXd1+FnXFu6cfDEKzi8Q8Aq
MzpLIfP9IWfc5UyTgVXwTQg+dugWjoG/oTenwlewP+zeeiYatiFs/L7HkfJQXGO5e/wsdpQtrhhD
hpX9XwBH0Crlhu/geHNh57FAfNyZbZZoiuuJT495kJIB+CDznl9XnUmAN8y8JddEoUcBK4UoZhtE
UBMnvuDFsK9KqlkHnH+he9CrPSR0Qb9loGuNB9fFbM0Z54Z/eLGYC3DPDH1FzGvYxq4JQUPuSDw9
CsfLsb038GwCdm3q+iHi0B2q1p++IgbdYgTZC3qXLbWJbb2B6D8lO4jrj2jXQrerzEo4hF1f8a4D
re2tAoqtZz1Ei4k7ZlgV/Ap0lh5kvtnoIIv+ZCrfw9AE7yfoXn+fq9JTgPNUo+9RlOEe4UX44Cch
R+A6fY0Zvok0mK9+u/8o8fFwTeZvtwS1HVwUX/qAM0XmLvVkAQr/0RKs2PuflDoNLOlTid4Vc1T0
ocgwc4WG/733r1HFiLtPFXoX9vSpwvq3Xc0vNx09/PsUBhv0t68zeERLZ5qD3OUL+fjgDmdS2seb
5OyyYN2vw73wirui/b5Z/L+WLiSfjw8DkEO994Y3ZxMSxyZzt+7+fVI1vtZIY9edu2PnorYupLiP
l8Q6KRNlHpQOK/cqPqautEGmHj5VDFNCWbS4dSEgb86ui7csG1VW9sszeNGWFSO98dJn4jS++lKo
14IVswaV5zG8fMo6yGc+pdmZz2f/7F09s4l8r3Gk2qbDtIIDfztwcsuCgbSbKN8JWClfR6KGaZKA
0mGVpsZQWNnADqg0tSndkQWs0i06kVCZEhCwUqZeMl4rAauMy1DkoCgJCFgpSh2ZWBnNweqTTBSe
yEqJEhCwUqJWMqNOAlaZIUWRh4IkoC5YnYdHfEOvgiScXVXREqzO0lVaMbLKrq5mrXJVBSsyc8OP
uCldOCoBzcHK/G0aohOoTwLqgpWDk7QNQX2KSnOLBKzSLDKRQNkSUBeslC1r69ZOwMq68halZbkE
BKyyXMTZVICWYHWO2qzENDCbeprVihWwspqorVyQgJWVBS6Ky2oJCFhltYSzK38Bq+ySvCg3iyQg
YJVFgs32bAWssl0FogKZKwEBq8yVp3Jy0xysxilH9qImWSIBAassEasCMhWwUoASRBUyUwICVpkp
TSXlpSVYsa89ipGVkrpfVtRFwCorpKqEPAWslKAFUYdMlICAVSYKU1FZCVgpSh2iMhmXgIBVxmWo
zBwErJSpF1GrdEtAwCrdolN4Qs3BaqzCFSKql1EJCFhlVIJKTS9gpVTNiHqlUwICVukUnOKTCVgp
XkWigmmTgIBV2uRlO7G1BKsL9EFmMQ20nc6ZvpoKWKVPbspPpTlYfax8nYgaZkgCAlYZEp+CEwtY
KVg5omrpkYCAVXqkZgtptASri3QaKEZWttAtM1JHAauMSE/JaQWslKwdUbd0SEDAKh1Cs4kkAlY2
oSZRydRLQMAq9bKyrZgCVralL1Hbt0pAwOqtIrLRCJqD1RgbVZSodmolIGCVWknZWjwBK1vTmKjv
WyQgYPUWAdlssICVzapOVNyyBASsLMvF9n21BKtLdOuCmAbafqdNuQUCVinLx3ZDBaxsV3ei5hYl
IGBlUSwq8BSwUoESRRNMJSBgZSoNNZ0LWKlJm6ItKAEBK7V2A83BarRaNSnaJUlAwEqtXUHASq2a
1Wy7BKzUqnoBK7VqVrPtErBSq+q1BCs/unVhlFo1KdolSUDASq1dQcBKrZrVbLsErNSqegErtWpW
s+0SsFKr6jUEK8fLYhqo1m5s2i4BK1NpqOlcwEpN2hRtQQkIWKm1GwhYqVWzmm2XgJVaVS9gpVbN
arZdAlZqVb3mYDVSrZoU7ZIkIGCl1q4gYKVWzWq2XQJWalW9gJVaNavZdglYqVX1WoLVf3Trwgi1
alK0S5KAgJVau4KAlVo1q9l2CVipVfUCVmrVrGbbJWClVtVrCVZXxDRQrd3YtF0CVqbSUNO5gJWa
tCnaghIQsFJrNxCwUqtmNdsuASu1ql7ASq2a1Wy7BKzUqnrNwWq4WjUp2iVJQMBKrV1BwEqtmtVs
uwSs1Kp6ASu1alaz7RKwUqvqtQSrq3TrgpgGqrUry+0SsJIlobajgJXaNKr59ghYqbULCFipVbOa
bZeAlVpVL2ClVs1qtl0CVmpVveZg9ZFaNSnaJUlAwEqtXUHASq2a1Wy7BKzUqnotweoaXQ0UIyu1
dmW5XQJWsiTUdtQcrD5UmwZFexJJQMAqkUBUcylgpRpVioZwCQhYqbUnCFipVbOabZeAlVpVryVY
Xac2KzENVGtXltslYCVLQm1HASu1aVTz7RGwUmsXELBSq2Y12y4BK7WqXsBKrZrVbLsErNSqes3B
aphaNSnaJUlAwEqtXUHASq2a1Wy7BKzUqnotweoGXQ0UIyu1dmW5XQJWsiTUdhSwUptGNd8eAatM
6gLuzWraJc3qnZa5knpax0fAyjpyTkcpdU9c+tXFUroW5y685X2nbU6eO8vduWNbF/csbikX1fop
CVbtzl2abuEPT8gHF871SlkDvWUVnj17ZPP3nQqkHDsrQudETjLJtlaHhuzqk4jpJr5WPRWwsqq4
01JYWz2ccrOUoBfAbEv+Rr8BdMJrdAFDjUGZflaiZ89ymZ5pRjJUEqwGA/xlb6kx0wA+tuRv9Btn
1B898+tuDMr0syq9updIkmnNsMdeRs+aIXCFXRW8F1HX6G3VMwErq4o7LYW1iYVjFmHVG2Beyhn1
i4PQkyeYO+OfABD3XsrxMxLaT6ebkJH0mZ5WSbAaCLDKIqymA4xLueUfAzzjKjxxNgBpFdYx5fgZ
CZ2rSxiQOL3jNphr9Mt9HOAcvxwH+y0O+I2Rs+pMc7DKykFG5iopWVgV69GjcspFIayO5HVjzt3z
XXzM6HHRlBNkILQ/wMQMJM/8pDYBqwo9enin3HSE1XKuQrfcxXs+AvjP4p0r5UxSGToPYGDiqF3i
n5cy+v2AuJRgVfiW7gNjgDXPBKysKe00lZUsrN6eC8LqoKMhWp2XAIMMV5l90g9AjKySE2qyI6vk
Ehj9EVa/GK86RkJ8G+NlJp/NA33ikZXbCVhoLKVztBFWZD745zcGWfFMS7C6iQIH2xxZ5alQ3aeY
5W7hWbaka+IQhNUhZ4On/WaTeaNLybKeZhOT3KW98hqiWj5xLFa2uDE7QuwKla/sJXv0BfjEcrJs
8lXqyKpApepVCluUiUPxssWN9xYpCsJqiTF2rvMm80b3UmWKGIPwLJ93qbct0eUoUdbTwSSRY+EK
lUrKHnNB398kjJ5+AG/qGLxK3IVDD+GsdF3xDYw2BFnzRHOwyqYRbDp0ahxZec49+zI2/Pb6FjyX
2qtX98Czbls3+pD+O24/u390vJN5/uawInMAfuQRis70vffs1u5RhhmFx+wzgY/OL/DKt2LbSIzy
ztat0mspHGdvW8H/ALkn7g94dufgZx5yGe3/vRoc9ujQBJrJsE34L7q6aVUyJJWTWPOoTFiV/ckv
JO7N9ZX1uCi6rF7dCs/e37q6iN2He+8E3dn3QaJVQ3NY2eENZzJPWnHBqQfPbmwZYMBbmR8vPH5w
akbeUmu39iEkz59b5+TgMftt21qZnxWadvjes9t7P3bnl8Suz77rL0Pu7/0IM7GfuPEWwIVNi3NL
gfTgdgxOGApwWQ8X6t81wMp+E5yVMzJJkvWnAlZZL+N0lmCAVSN/OiREFz2TjaH6AHyNeX4B0PVH
HgArzGmVCFa/yh393dtSfN8qvFJVL3KPW/2ewR/o1Q5gGQ9xOg0v2XJ55dNSmittWYjjz3GSx268
vS/n5/HSn4Knzd5fRcKqS6AktLCP2bh2JsB4FNNPENZ8rRQyz5xW5rDKcRiA32cHPOPxddskk1Kz
e9zj+MBIukpc+A2cle5FcwGaMV20YG9HwmgnqrNrt7U6qdDV7sThX37+1HA3wjjvhLI+xmKTCRDZ
xPOBAVZkPEB9HmLdXy3Biv3nucatK+T0lSbDqsoDAN8vOnT/JQTgO9qhewDMxMMkiPWDkLWTZ57A
ztbPrAxzWBW8DvomNLwF5nDsixFLcSv/rfLUw9MP4MbCEXOuQ1Aoo1QbgEU0gBAnXwiklomKyLeL
Mz9ceAEgtCkNGKmHcyPbdJuC0lxhT7rM34m1mz/DtKPTWNnolAirNq8Bdn7ybu8/IyGBjmDJl8Cm
Ut/BG5T975/Nu4S3otZmQjOHVYUgeFOJhveOgoQdn47+/T7AabZqUgHPLn09cuF9eBwBXxFS6Dkc
lWA1A4DpveErgJNfDv8ZP0l+l92lZgEc+qB1r9kPAf5nZzdw/hnQ75z/v5wm5Q8F6CJf1g/F/uZt
nAaSVtEwVQ605lHAyprSTlNZEqyctgL8wUbdrYIgnnY+A6wArtfE61yrAf4xyxphdZBijbkSGPwv
XWz2uAwx0+hJIbyXrqWD/EkAe+gGm/yrkHd0SJUEVm7/gn5pPgxxw+EZ3faV4zLcYnO+EqchqgIG
CJsVCiE5JxnYc18C3bds8Ns3BEKo1AywAjheEa8LHTHcJqS8EFY/G7ItuxtvDfTKOxBej6SqLYN3
D2YBXwCwpiB6lMSxl2VY5TkLsXMovwrgXHIzVqPgUzhFdUoq34SndPg8J7HNyu5vCKfVpC7fGTjt
bgarYvdgv5ndk0fM8l8BqywXcXoLkGDVUgfHJAvBCD1swNyMsIpqzDIv/wrOmxkREFZ3vpz8BXXf
bnwEcMaLxpuKi+EsPsl9FV5XxYHVQ3hUkvnkwcGWRVh11ME+boZ12g3x7+JI6yls55n0ePy0JZ71
F1sXuDws/UqwGgSwRTJm427QnzCmEVZBbIxLWsXCXoORiGaFsDo9melwysJtOPXbQwevdosgQdpW
XvopBOLQqkoonM9D4xPvp8nA6gOA1SwGyXkB3tQipHWEbLsf8STQB4NwNdB860KOh/AfJSA6h2UQ
VAdzNxlZ2Z2Bh6V5qFV/BaysKu60FCbBCq1Cw6RkJR/AnUKmsPqH/wPsb8ONIqZZI6xM3QVPGpjr
DER6S7E+B3iPkIkA8yUPNIBZgpXdSoAWUpSeesAHLSoFQRAdzuEYy9ubElLAiknD8o8Eq10Q31mK
UDUUzuDChRFWM3hA3lA4Zbaih7AydduY+buIPzyS7eA/AeDE8VvQDZGyXmwZVi47IJbNIDHaWIAR
hLSNgltlWSK3Mt50yJUEVoVfw3FpVjgojn2+zhRWZA+E15cKteZBwMqa0k5TWRxWzifhBZ0nMHcU
wvBRB+PI6gvJ/zLcNdnARwjCKjb4OXXBaKaCyPV0rO/9Bq652DNn1wrgG0KWQVwnKYcmeouwcr0N
r0rZ8URlouFvR+KEW5kfT2vMzCUsrYCVJEJLBw6rPAFwWxaYw214jKAwwErfjadzewaX8ppmgbCK
Yip8HhyKOgxdQu8MDWLhEOHqIO8BjCVkG4RUk5Lhwoslm1WxF3DbXdJ7Q7YunDcA4Pak+mz9hKVN
AqvKb2AfH+dVeQz/0DMzWK0FXRupUGseNAerIdaUbobK4rAqehPuMvsCzWszxLU2hdVoqYBLcC8x
rM5Ur8JcjZY/4crPfDRz1AN4ffQIc74XAFYSu60QUUPKoVqERVgVjYCoU7480Yl4OIC34QZo74e4
m1vHVuK9WcBKEqGlA4cVWsdP55CDz0DYOyawiuNrrMTtCfglhtV6rkKfmq1XoswnYg54nwqS1HH4
CuDzMDlOQCAbN2Ng6wSLsHoHIOSYpPezAOuwK3QOxvyi/vvnwzJ4gS4JrJpFwSYW4n4QbjDO4qj+
DPOhP4sAehkurHciYGU9WaexJA4r7wdwhfcoTL42EayGS1lagNUBY2nf4iIQ8q49dlATt5HkOg0h
8uyx4stEsHI+SlcDK0eZpEDbF72711z1mHlGb6hNyxCwMko6yRmHVc3XsNcQ5AuhprCKacVDLMHq
Z0MiR1wkOY9z/mFm6kDrl6c/3HaVojWJTgSr2Ww1sLl5mp20NzXZSHEFEP57GZo4Cay6xcNalus4
iB1fwtvbu3SzJ3DZy9uL36DmWng8h0XP2h8tweoWVc+QrJVnhnP3mPPdQN4j2sXRB5mxN95g60g0
54MQjGN+4zTwI6k4C7Ay2cFeNgbicODVGvcgjBohu1FtSZ4LEFpcyqFaZCJY5T5LYVU+Ah5NGG5I
092ZRS/V6Yczz1GWj+muHQErSYTGg/f877rzq/fZg8wVg+CQfMOxuwF3cFHDMA2MoYsU6CzBymQH
O07Tn6NJC/M7bFDHiFGNSMk7ECBvOWijSwQrtGrh6nFjfKxwtKzCEaPa85qU6bH0Mu5oAD86JE8C
q/YxsJVV609IeBL45MmTx0EJEBf45Brfgo/b+7qwYOv+CFhZV95vLa2SDrZyJPRKgAPO1Eb0SLZ3
uFyCO9hb0gor92ugQ6xUx802ZsW7HIEIbivHW63BZvUTj1PMn8KqQCgESqtCZklxVXDoRYA/0VPA
KpFkcD8bwG/ccwzAUkJy34JLdExKXYFAcwN7KmFV6jmE4I2lI+494PlIvwWvwGP5hoObSLjN6gg1
muPW9H8YrCrq4QJfiJHSyAeHamNws9w8vEwCq/qRtO+h+wN5ZuLesF0rZDXEtZBzseJRwMqKwk5N
UV7RsJf3tWF61jE3Q0QzKWHtEDiHo660wgofndA3IKTYUwiWbarlR4wqT+z+Av1wKetP+WpgK728
yl0vmsLK+Rwk4KSFuSLDR+K8r/7IYdKd3OcxXMI/gYCVJB/joT5uY+NXOICag2dnINhHCm4bw7Z+
pHVkVTQAwsriDScMrsvj7BojRxUj9gcgWhqbkQUMVh7P4DInY667DFYeARAi3+7KjBhVmdi1GzlI
olfTUNiJFUsCq1K4ZslWHZt8NIy5oZOC4N4HHw7iXXM7hGJXsLoTsLK6yFMuMH8YBHCk4Fj7V4z7
Cbs5s0TYwz/Dk7TCymUP23/guAP0H0uF74WEhmwhe4c983FCyyvduoB31As8ynygsKKPFS6U0vwC
0Jdtd8AFSepcL8JFDqsJ3EMhv9m/g72ijt1UUB4bAMbg4TuAGZJ0fgL9YDxNK6wKXoXwqoTkPA2x
bXhOrn4QgfhCBX3HPQogm3BklfcGRHGTO+41odNAh18BJkml4wZjRNsqSPDiHh6PYAeeIawGSDH4
wekm3Chk5uNxy8TAfpytaJqFW+NCwMoaUk5DGbi8w/o3qXYPdP0wYb6r8IYeCan6BB5Rm0FaYeW4
CaAzpuudAP5VaEZkJO5ARLNskUD5tXy4lZ3BqvQjCGlFY3R9w2FVNQSeN6cepNsruIEUbRUPq/nK
VotXbBqIC+YzWASl/GQ/rDzuQlxPKo4WzyG8Hh7L4OY0zhh84umcC/qkFVZ5z0NkfUw3Go1WJfBI
nPEdVKvxXlHpDYTiXl18PgpvJhRWOXZIT4KWpw8EIqxIM9wiXINGIcOi4AhavnByyp7bIqRXFHvD
3izQ4/YrU7ceIiqbXpNit43PBuJY7Tg3VZhFyfILzcHq/SwXaQYLwJ70ZlG3bjPv4CNfeWheSIOo
b1t5VxhzD2AK9UgrrOz+ZDtyiOMygPuf1qvQcU0sBLHeO1QPEd83rvju2nidjsHKfj2+n/KbHv1W
RL68w0ZW5DPc8DC9ablWi8L5xkbXvaDb3sq7WPmxjyCiEdYGt14/nDkkH62YMlz2w8r+Z4BXX3fu
9S1uPN/NZm24bz10WiPvypOfgY5hLK2wwql8fG+UrxuOja4Mr1m5+3bcKlWaCnwyKmh2vUo9dkCC
nsKKfAgQs2JQt28DwY/DyuEHXAv5X/0K7f+IgVeUnQX9IG5149LFK3/xAh5XQI+R+Ijo1H7yqiJ6
0Ez606PBmcKqcYTpS0QNUbL8RMAqy0WcxgJyIy+4e4BPOaBznInDeYihfgvYmKYX3WBDCO5CH8ki
EHINnnhJp+wwEJ84M7n1LcQnN3BKR/L8zjMGeMRuxsR+QjT3CZsXw2DFnlumXrF913ALl+OX8XhJ
axDGS6uKT3VAdBD6Rn9CC8t7Ga8j5S3SrPjs/cl+WJFih1EmzF3HmRq6XEvpFRV2/GdsNW46v38g
Rlpzabm9hOtm+6zGGx6OohEc9gDsoAajIttoTtTd5NPxHPOoctDd/5atBpLcO/k1fPO+9NYFXjr1
fUpH2IS0xOeqIeK5DndgdaXXJalOH9DneWRXhW9lkS8JKf4A/OQrJBm9TVndaQhWTvj+AADFj6yI
28eXsS/F3l8rj8Pt+53ERWZd8AnpFUZNfH0/wI7S19e3k9Rflvv+TeeHBtfygO/3joYr0snX91Bb
eun84YVQ7KV31qD5g7u2B5/HxwYdaFUtgcOKVFx7JyT03q6m5EvfDe4sTvejL3Fs93CrbOZvsPUJ
/j1inh5owe1ddffeuMOnJnKm2XtUAKxIvs9voKCjby8rJcnCafiFMICEZwe7MFaRQb6+FBMjfffz
CRrJsdH3N5yhGV13X192M5B8xvn6HqhFz90mX4nAwbf/Yi8pxH7AyVcJMYHbqrRh00BccFxw7eWb
wNPvO7by9cWdLuic3j8bgnq/97dUGGmzLwj/C1GPt0t28neP+AdsZON4KVOEo5/J7Q5HY2t8l0hh
dqvhihlXJf8sP2gOVu9luUgzXkCeWu27tJC7Oc3OqUaH7m2rcTZkLHu32h07NJTXumlW9lVbNUdD
Vm0ZVngPrV27pFkhju+079zE28SrfNtePZtWZPMb5luwGDXDKMUpAVb4567bsXNTeRGOisa1bqdu
rTNlAJqnYef29U3N3041WjfDEVwnCVZo56xev6wZaohLrY4dG5mo1a5Ku97dGpUzdqlCnkZ90ur2
hZjm9GjBeYWwd3FZCMliLwGrLBawjWRvAisbqXGy1VQGrJKtXtYFGGGVCWW4nYKf+SAwSWbT4K7Z
OD5JhKzy0BKsAug00BZGVlml7BTyFbBKQTg2EpSpsCIdYl9xe1vi1he6QR+gzg4nYJUdUldemQJW
ytNJWmuUubCyWwcLLNZgKFzIFosVIQJWFhWiOc/afOuCGtotpoGZo8UyQc/ptobELs+N+PaJ/ax0
LWBlJUErvJja8fqlCq9iaqunXVjp9dNSK6TUxBsb/7WFaGPjfrbgaxUvASuriFnxheTr0Vte1lZ8
Xd9SQc3CqmivXpmy2ijL1+mdShZM7GVqme2wkCNb46g5WA1+m1SVtAr/trqKcAsSSAOsXIxL9xYy
El4Kk4CAlZlC7Bt8O010YDOR2NxFqmFVftxfpruVbK6hmquwlmCFT9sBpDSyKjfudDis0lwfUFmD
Uwcrz57bguBx9uwXUpnArdYczcFqUHKizTtkC31iin2YOLk4wt8GJJAKWDk0X8ruXPcErGxAoYYq
ClgxUeRoNP+e9DzoHwbZiBOblMBbYeUz/qz0ankBK5vSsIAVfjmy9OcnYumgijkBK5vqwEkrmzKs
8vfZGiyrGgSskopPwT4CVvm6/4lPpBudgJWCu2tqqpYCrBybfo2v0zQ6AavUCFQxcTQOK7d6P7EX
xxj7r7BZKaZvprMiycKq3PgzkSaKxlMBq3TKOHuSaQlW7KZqamAv9+WxBPPei1diZJU9PTHTSrUM
q3xDt+IbphI5AatMk7o1MtIurAp130S/m5bECVhZo99lYRkWYOXS6Mf70vqJmb4FrLJQD5mfteZg
NZDJ0KX+omtm3dZ4sSLzhSxytKYEEsPK3nvyiTijfk3P7uIXMISzGQloElaVRh9LpvdiT748d85c
4WxSAlM70c/hmcOqQI/1+D7hZFzIj0LXtqDpeZ/Tr/Ro6hUx92iX7efRbTN+dEQ4NUpANwWfvDWB
Va4Gi/3V2E7ttSmyjxZhdTzx6p/2FK/iFr/Cj/gYYOUz5xx+v0U4VUjgggZhpQ9XhepEIyxLINQE
VjlGJWeWtJxW+CpZApe1CKsJvbcJXim5V2aobj/gKzMMIyuSq+3P9IN4wtm+BPSjNAgr6EscKs85
l4L2HmwRzkYlsGE8fRmZEVZ4UeijPSncmyJ2bbbRpmqs2n+z7ZFaWg1kBvYB2INJnpbLHiXHq99o
BOFsVwJmsMIPI77z5RX2OWsLCr+roK/e267ArVZzbcIKxVt01B7p0ftEnVhsCrVa58uaghLBCgtx
6b6KfoA4qbsnXr6XNTrImly1BKv7tLeykRWTpVPlaReNL1sw9GQBq6zpaVbLNSmssOhi7++z8LyC
2MFuNa1kRkGag1V/U6m5tvwpiQVWwMpUQjZ4bhFW2I4an19M/CSogJVN6VfbsEJVFRq22+wNMeJB
ZpvqvxYqmxysCHFr+yezWxpG0QJWFuSnXC8tweoB7aRmIyuul2qTTS2wYmSl3N6aqpolDytM7jV4
j8nTNwJWqZKoUiIJWFFNuHReaVgdFLBSSt9MZz1ShBXmWXP+JXloJWCVThlnTzIBK0nuxQbvf8n6
sIBV9vTETCv1bbAiJF+r39koW7x8L9OEbpWMBKyMYq426Ry+9EjAyigRmzx7O6ywWcXe24o7V+6L
r9vYkooFrEy1lavV8vurLHwy2zSOOFe4BFIFK0Kcqsy6eKeowtsiqmcqAc3Bqp9p6y2cl35HwMqC
WGzIK5WwwhblaehmQ+0SVRWwEn1AZRJIPaxU1nDVN0dLsHpIDehvG1mpXuOqb6CAlVpVLGClVs1q
tl1ahpWdqm0YAlaa/VOrteFKh5VXo3admpbNEul3vnKxUZZkrIxMBayUoQdRi0yTgLJhVWnNPfqu
5cCtjTOtwcaMhgJ0MF5ZOqvav3cpS/424ac5WPW1CbWISqZfAoqGVXvDkxKv6ScQMtkNAX37lLOc
CzrTz/ymHFlpoQJWStOIqE8GJaBkWFXAnfOnxzRpPRk/W/KsdAYbmjR5amAFAlZJBac4Hyd2UxMj
K8UpJpMrpGRYzQf4Ozdtb7EjACszueGEvB1Wc0DPP/Ob6WVbIUMtjawErKzQobK/CAXDKvcdeFmG
S6hZJDxIzfegc3pXKWkqU+dilcsXdTb1KVa9Vjnp9cxmsKIffKUuf5nyRfgZ/iKs5NdPupaoWrWU
Ta0eag5WWWApMPQEcaIECSgYVjXiYIfEkPxXILS2LK4Cg95PujzYbt36Ms7jTgSG3Pu3nRwx/yeH
b78Kunl4ogE/Nf68FRn79OJc5mGAVYnVO3f3ZInq/HbpcdD1jT0plez/ty0A4NL2pTi4c/no2J2w
0Pt7+tkQrgSs5H4gjiqRgIJh1RVgqSTlHKcguoUs8dp6GC6fG46fAvTazl4EArHTnZh32cv8GuBK
JR5v0AvJ52YV9JBhVfwkwO950cN+ovT2Lt16fN28g5TdEw9SYL+UTr/IledkA79aglUg1Y8YWdlA
r8xQFRUMq1rz5reV2lbqoYmFvTZYgNU40N+BW9P6fPRvHOhZt817AuDwRy3bfnIewJcxpnsEJGwZ
3HXSRYAjeQywKn0aYHEOWtBUHUSvHT161WOA3e7Eru/sk6DfPmeCm90K0G3s1azH3GcAwzIkbWsm
FrCyprRFWVaQgIJhZdL6yQDn+XAJPZOBFSLJkyaZEAOX6DipLprnc1GPwmfhlQ8eC9yEhC/pPK7Q
MYAeMqxKnsUBHP2CIqkfDk+605Oq/gAj6cls0NN35ZaJgR2MZvWD4LqhGjSCkp2AlZK1I+qWDgnY
BKw+iITYrobGJQer4Ko8yj+g/wjPxkB0Q+7xBeg74dlwgO3c5tQQ4Ac7Pg30Ogf6bxmAHLZArLRR
ocYbuJQTU8wFPfXpq4OZPKfvHl4rxs+U/ytgpXwdiRqmSQI2AKsiS+IAFsnLdcmPrLZKDW+th2UI
pSo93qXAQTcdoBse0PBED+jc15z80ZHCqmWZSxA325F5VnhuGL3ZrYV4Sj4ZVnq4yAZtJI9XCTbE
YgkU/qM5WPVWuEJE9TIqAcXDynnwdYCoGSb7D3wAhiRp9jiAiZKnRxDsMSClQLn6g3FvKVIq3114
XE6K4uSCEYZA3Cfn0HzFWUW6A6wmjsyRzwBo15dgVQxf4X1lbP38SQpVtIeAlaLVIyqXdgkoHVbN
9uE6z/HWrGE5pi1ftmzZ0s0AR5fiya8/lDC2F2HVRbpyvwi3qNGKlBr259GrgdF0pQhhVfE5+DFv
OdEQ0NHVv6jO3GMsPoN4/CRzx3DPwsfoK8GKDKTxIq6s/8CLR7WJXwErm1CTqGTqJaBsWLlMiUCE
fMbs5ITkQoaYurhaxnYirJpIV7lOwjPcQeo0Dlf10IXsP8xgVSsUTphZx4dgYOzROLjCh0zTWGzD
z2eYmwwr8u4W/oXq10uKG4tU+JmGYOXMNC2mgQrvkRmunqJhVRK3OoV+Z3jxQc59D9Ddxw0Er+7R
s6t0t5TkTGCV7w7cxJ0JE3HQdGhWvwalnScAoHm+cjCcZqt+chKEVeSYnHsBFjAfXHHc9P5Q2Q2r
hp4GWBHi3edXPwqsox5ycqUfNQerXkrXiKhfBiWgZFjlPoDbEeoYG2hXqBi6oljlz4uwM5OBEsIK
dyMwVyQKjrkR76fwWnq09UsGq7zIMGkru11pn7JsNRDNXHVDIfpdmg7/3It5BoZfE1ihn2P1iU8A
PjGEKvxEwErhChLVS6sEFAwru69wcybO5xK7GgAfJvYjCKuvJc9OAD/ZkQ7xsEHyWMaXAc9DaF3u
U/h22F8OdDWQ2sIW4B4uHIiR1nFwUF5ybDruY/oAIYeVY8+x/Xg60i/Odj4+J2AlKU0c1CIBBcOq
0HPwNzGhGySe3D6r/9gbGgjBiR1u5RwAMJ8n8cDlRDSwk1kGn8EA4+RNoaTgNYDpGOxxG8KkYVzR
x3Cfwmoee+uC/W54Ka0EVg6H33imyv8VsFK+jkQN0yQBBcPqfdDPdnA1OHu5XcnBCuawLZ+fxII/
GpZaxMIxts+q8F9oaqIrfsUD4WV7mkm5O/CmpgFWpFcsvK6O3jMBthWi4bn/AJhCT9BnFB6mQcJU
eknIZB2M5WfK/xWwUr6ORA3TJAEFw+oP0D+8el12596R25UcrOJga9d3uq1NgIQhGLWAH+i2Na9Y
b5o/+KM1ygfBhQ87h37Xocmk+wAzEX3yg8yO6wH2YHABfEjw7Ie1aww5jpsl6MSQ7nm/NXOwS4n7
ELOsQVmvWgsi4YrhDQ40gpKdlmD1hC7iCgO7krtjZtRNubByxDfumTrDxx3woT863jF3+CDzN/d5
9OjJbITVim6Oom9wX1wR1w/j8Q0zzvP1PAb8QpcFhwF0ZJmUCwL4CtOU85WC4UxZFlCCLok/9CA9
IvEYThcDAxubF6vgK83BqqeClSGqlhkSUC6sci7eZ+q2VZKbW37fvqQfekADe4d3Nj+Niw3c14Kx
ipBm+5/Fxz3e282BDL725EIFTG7f59DjiFe3DnRzpHm13bdPslG9t2/fKjoBzPvV1QjQvb48qyAN
R9fqwLWb63CQ1eXgcyTVm7vLOcR4oMJ/BawUriBRvbRKQLmwSltLEFZdcZd686blGIhYYqdKzZuW
Z2cFKhaSCFa+fnVP6dRSAfkbtG9Zg00BpdCChdkKoYNP224d6pq9hdRSciX5CVgpSRuiLpkgAXXB
KhMEopostASrpzjuBTENVE3fTaYhAlbJCMbmvQWsbF6FogHmEhCwMpeHeq4ErNSjS9ESJgEBK7V2
BAErtWpWs+1SC6zG6hLkV8RoVpfmDdccrORnQ83FIK7UIwG1wMq7R1eb2a5pnd4jYGUdOYtSrCYB
tcDKagKzmYIErGxGVaKiqZOAgFXq5GR7sbQEK3xEAYB9mcj29CRqnGoJCFilWlQ2FlHAysYUJqr7
NgkIWL1NQrYaLmBlq5oT9U5GAgJWyQjG5r0FrGxehaIB5hIQsDKXh3quBKzUo0vREiYBASu1dgQB
K7VqVrPtErBSq+q1BCt8IZlYDVRrRza2S8DKKAt1nWkOVvQ9+8KpWQICVmrVroCVWjWr2XYJWKlV
9QJWatWsZtslYKVW1WsJVvSl0+xza2pVpmgXlYCAlVr7gYCVWjWr2XYJWKlV9QJWatWsZtslYKVW
1QtYqVWzmm2XgJVaVa85WOHXjYRTtQQErNSqXgErtWpWs+0SsFKr6jUEqxxsNVCMrNTaleV2CVjJ
klDbUXOwEu/gV1sXTtweAavEElHLtYCVWjQp2iFJQMBKrV1BwEqtmtVsuwSs1Kp6ASu1alaz7RKw
UqvqBazUqlnNtkvASq2qF7BSq2Y12y4BK7WqXkOwcmFbF8RqoFq7stwuAStZEmo7ag5WndWmQdGe
RBIQsEokENVcClipRpWiIVwCAlZq7QkCVmrVrGbbJWClVtVrDlad1KpJ0S5JAgJWau0KAlZq1axm
2yVgpVbVC1ipVbOabZeAlVpVryFYubKtC2IaqNauLLdLwEqWhNqOAlZq06jm2yNgpdYuIGClVs1q
tl0CVmpVvYCVWjWr2XYJWKlV9ZqDVUe1alK0S5KAgJVau4KAlVo1q9l2CVipVfUagpVbMP0isxhZ
qbUry+0SsJIlobajgJXaNKr59ghYqbULCFipVbOabZeAlVpVL2ClVs1qtl0CVmpVvYZglTOY2qw6
qFWTol2SBASs1NoVBKzUqlnNtkvASq2qF7BSq2Y12y4BK7WqXsBKrZrVbLsErNSqes3Bqr1aNSna
JUlAwEqtXUHASq2a1Wy7BKzUqnoNwSpXMF0NFCMrtXZluV0CVrIk1HYUsFKbRjXfHgErtXYBASu1
alaz7RKwUqvqBazUqlnNtkvASq2q1xys2qlVk6JdkgQErNTaFQSs1KpZzbZLwEqtqhewUqtmNdsu
ASu1ql5DsHIPplsXxDRQrV1ZbpeAlSwJtR0FrNSmUc23R8BKrV1AwEqtmtVsuwSs1Kp6DcEqt5gG
ZlUvdihSIGnWdh6Fk3pawUfAygpCzpYiNAerd7NFzIZC80xf/nUhw5XJicd3yz+2M7lOelpwzrIl
kls0c0xtl6Qxss1ngv/QpGXbzb6eLQZCJcMq/+zlcyxwnZAxy78tmlSEpj7DfpW1/8vXk9rlNw3S
yrmAlXU17XkfXle0VGS5CPBNGVbez+kCgexiz3SxlE22+FV5/rocFlx0voGmS1vgdUO9X+5sqI+S
YVXqKTz3tiSTQxDuY8nf6LdZ1jw9JjyZkscYpJUzASvrarqoPzyrYKnI8rFwLGVYlX4EulfPg5kL
ww4b+4m9pYys72e/HubTUpvojf+nSdRjJUymBys7JcOq5H14VNqSPI5AdFVL/ka/9QBvJO2/jkdB
b3I3hmnkTEuwekH/S22zV7HJwir/5FnvpVw1hNXLFl7e1JWtMeASQHjdlBNYK7Rv/ItStKyeoA99
zV3ISOpRKzSkNj1a19kkrAbPmmzROmAUHcLqU6597yrt/8aePN0YppEzASvrKjpZWL29Ggir516G
aBVvAcw1XGXnSa6z8BMr/xN4XKuE5Nht3+5f2OJk9arZJKzeLiWE1UBDLJc/AC7lM1xq5ETAyrqK
NoOVk6uLYzLFOyUNoLAqa4w+F2C3YR5o7+RgDKFnTjkSZWDnbI4NuxyuOcyTEDvzQu2cE+WRKFxO
PRjC+BBvMZx2lT35sSvEtDL3scKVzcAqbepHWJkMvRtEQnBlgzAdEynbIYezIYyfOCXycHZ1MXQe
KWoi9aL6zfuUXeI+lqiIrL/UEKzyKGwaWHuG7y3/A9MkU4V774EtUd2FRo+rTQp+sMr3wJIu5nQh
iWDVC+CsFKP65M1Hdn7b2hC/yPiVx/wOfkeN3IS49B7YmBT+aN1J3++aMg/6U3Doer+7F37t7sJ8
So4dV4UUG7X2yN4f28p2s9Kf/XXq0p4Z9QxJyn281nfP4m55DR7SSY4TcJiV7LgbNsqppbD8/rAq
kVfi5Jl/bSOwqjf7yK2b+6ZIxGk5sBe1mHuOGVedFP5wje++xR3NUUHMYVUkECLrcNkVG7by0MHl
/YvIknTstnjP5ZN/9Oeaajawh6NDhyWHT63ubzByObRddDrg2rbRxXmS0uPGlSclPl5/ZM9C2gWZ
Kztl7emLu78yzuIrjl/nu+fHztmxYiLXiQhYGURhlRPDyCrH3BBqQgMInsH+6pKBvQ7A5y3QHkXd
n7nMqpQIVgMA9rCbo9uCVyx63HZpPanrTXYNMUtyYgZF42BTg8vMJ+oHN55jUz8eA/ZVoR7tAT7o
hNNKdPGLOPJGP+Ax3szht2T7SY+5x9nWPAvDb+03kvXE5Rb8YPDlJ3Z/wau3rMgnSpEJlzYBK5cF
b7g8n41no6IjEEPvWk0Bxra9ykJ0y82HqeawKv4EgpnuSP8AntH1Plx2ZXZK6xwn2W1wP7yqtJrH
OCyBschGaqBHF9CXJekO0K/HHeYTs4CPt8YHsksIncrHbA5fPOUeJ4w3vExQVRqzELBKo8AyGF2G
ldNigMgjSxftjQL4jnaQsq9gHw5CakXCv08g8MAu2nk+MSssEax+BPiWhruuAog48veRYIA7rDfW
CIKwLT8s+RcR9h2GF3kNl+6A/7pVJ7ET/8jGOQ0RPNf/+WE1AulWeYzSNgE2vYR7+/bSLsoMI21x
lrF+4XJau//RQsh0XC4/u34/Jgwx3H1ZABkhL1p4hMMoUrhOIy+TIcEk0Pfm0az3awuwyvErro8c
XrL4QAzAbKqTPfCSsqdRDGwNgof7d9N7xQgzmZnDqmU0/MdsVsOiAS7/s+Mu3mc+pPHz7AI49suP
f98GOEfHatvhxT54uX3lDrw3XmJbvPLvA3i2e9GSMwDRQ2mSzqDfEAp39ux9goV2pz5dYiDo74XL
98eAbhC9tvsGIO70ugMYIbgJ9cgeJ2BlXbnLsBqkh8cd8Nbp1PoB6Ok90QgriP/a09mx0G96uGpm
aEBYBZU01LbDSwirhVf2iJHLTVyJq9cWgKM4rbPbAqFtaED1yxCKYy2EFeinFyQk54AXENkQQzwu
Q8JC2m890Ux7EMtAWEH05MJOTsU3ARxGdDqcgcD6GMGp1QN4TIdG3RPgYU934uy5UA93pNkDeqNz
/AdeebKz+nHRE/4IfBPxzH+uYet6ozewjAVa8ccWYDUc4H4bVFaO9k8goSsKxwgriJ1R1Nmx6BqE
jQn1CZ0GDjBI0dsXYAq9QgG/HpaPOBSeEguhNdADB9zz6Pi58Co9u89sRwAdrGBPHKqdxhDKxQUA
p3xwwOQ+MgrC6OirM97FIicWcnQqtQNgF6rf+T+4S/uWc/vHcJN2lH4AdzvnIjmK/QLg/5ZVS4ye
VU5zsKL/42x0EqzcL0N4B16NjvFwDrutCawWsICCNyCUD/Sl6iKsQoe1a09dr0/WhYBuPA2o+Aoe
lWMx8viCDocxHtfgLE/RS0e7N4XVP2xART5Emzz+AcYA/O3EouQ6CfFYDQqrL5hH6UB4iMaPsk9h
M89jvB5w4I/VjWzOPBxwRMj+JTyYkHzP4TD9c+DfRB8fif8M6q7T/x91bg/hvLXNHDYAq7z+ENqK
S6i3Ho4jOUxgNYcFeAZAsPHWhF4IqwVc+52HL8Rx02Z39LTfC/rBPKPPAX7Fs58grgzzKPJUvw1P
EFaPvZlHhefwsiIhlSMgoCzzINMAfsMzCqsJPEoQ3MbbWqWXsJrH+FwPaBkrcB3e0HsX4mt54vE+
j2edXwEr68hZLkWCVds4OCTdN12OQEJNU1g9k/roeohsISejR4QVxMfFo4vTIRDe9GeB2Efl2WKf
BNr3Sj+EJyVYUO5OXbGbIqziG7Nrku8KvChDHE9BnORBRuFU0Y7Cyt+DRzkEzyvhZDQErnD7rEfn
Lp6EdAX4hYeTKi/hiFRz5uMdD+vwz4YOuz6cntzjg0U4WQhtx7wIuQJPOEqlayscbABWnRNgF79/
EPf/IBrvSUZYPSjGZbQdQqubSgthlcC1zyxOS5lFq14kHJaG30XuwB03Yve3gV7NujXAURLCapGU
zQ9sPXEWwDTJo/wzuI1qRlhd5o/v2J2CQERd/XA4R1GInadLZxwl9wdYKCWpGSpZSqVrqx4ErKwq
biLB6jOAj+WC8U8+0hRW+6WAXyFWHqAwHworPXd09BK+jI3HD0LsO1KCAi/hcA7idATgfC8PPnTC
EITVLXnk/ieEtyYl38D5XFKSMrFwKCeF1RrJYyvQfZy5/QF82+fHvs7dz6DvJZ+fhwAcexlcvQR2
Q8frXxPi/mSjqIrHAPyYQYWQIxAuV8+QJItPbABWXwEMk6WwAvTvm8JqmxSwGiIbyXHoEWElqZ9q
H442pJ54q5pLj9Sh6vCmNx7g1f9K87Eu9d0OsTjcZq6THmYQuz3GzcQORyEUB06d+ZiMxtkHwdUI
yX8fYF+b/BJOCfkd9B15FsTuKlyjE8NscRqCVV62daFNtojZUCiHld3vAK1kP1TBDFNYydz4BWKZ
tVOOh7AK+997zH00ZRsOrv7BjVIuDyFi8VczmJsdBv9hR+qG8z54vGFCM04khNU+mVxfge5D0iYO
Nsv9MN9LuJafwup7qZSNrPuSEWj4hXurRtfle7EOQMLqqbyQqfcgqLJcJTx21HM7Pw7H+veSbvLV
nhlecrgZ9OxfZZIiq0+VDyuHvyDBIJV5QB9KMo6slkvy+QOizGzZCKvlg5n2h05YGgwQWBojotFx
l6SYKZcgCpFS6hxqLuLwnC7U1IhuO7z04Wekdjjek/Jf5lZI5rcJ4toyWM2WouyCF/Te8kkcZnJn
5cg6XKEnIe4PqZRpjyCwnBTZ6gcBK+uKnMPKcQvoyssFDwT42hRWv0sBFmAVZLBt230eBxF4V/RE
Lpg4anAirU7iChFAlP9cGh1htUkuCm+7U0gfndHonfseBBSksJonRZFgRQb50f4KYVcmow3D6SQ9
N7goanyV3RCAqfK54YiWDW55wZsytDZ4W+dE+bBy2QWxBnvUZPbgjBFWiyUpWYBVP4MAm+Oy7Fd4
hQsipo5aBoqvQpLhIOzhejYw2w7PiknJqgTDIVIiAG7L9y7Ujg75hiMreWIowYp8cJXNNUP9PsWx
sssl0zK4Ud5QE2ueCFhZQ9r27QZ35eOcYrfog8y4hKYrIxeMdqMxprBaIQVYgJXJDnbXmwA9sGsG
QcjqJUsl9+vsPDSxc/PJe3DjAsANtKQirNbJRc0AGE96JMAS2SN/CBzNRWE1V/KRYUVytp1+OJzm
caoQcT4FMZt+kQtZttBLTo7H9w1cMvEcbZhY4KJWY5MAa5wqD1YOHQd34hMzrwf0QeYc2yBGJgj5
FvTDTEdWsoXJAqzeM4oPx2Mb8AoHrvt+lhWz9Be8e6Gr8tGqezjwhkjKru3wBG83zNWNgG3E0x9u
cRsj+m2DsHoMVvL9RoYVcW8382gEVf+u/MTND6L+Map/QXEpP6sfBKysIXLnC7p7Xqyg0vfhCVq9
vwFoJhc8A/Qd0g4r7KfwEe5HCIQgS8PyHEW7LnuK+0oZrHbIxqffIOE9Uj0KNspll4+D1Q4WYYUx
XEv1W4vMQ44dhpiWcpJExy5G27sxBHsVve+j2wlRdEHdmk55sHK7prvJ4VThCdwvQcgPEI+Q4G4l
xLVKO6z66mEfpsc9dqPljEyO9vkazLqC83jEynYIlm+LbQB+Jy7H4THazJmzx3Mvy7DCcDevgetD
AL4k5HQi8xlPbf1fzcHK2pMSplKHi/CUT/sqPoO7HoSMZKMpFuayD+JxAc64dWGF1AtSHlkR3EMw
HmOehAS53ztWr4MjKc+6tdhCESGNn8JtZzqy4tsHcU/UAWqRyhtiNLAP1dP5WpKRVam6NaS7b7dQ
OGpHJ3ODpFqRSnV8ZPZRrwY6+JvFbbFuXWc5Dm5YlQzyJyCoguxrpaPyYJXjBtynFiZC3nkJN3D9
bQLoh0rSyHUeorzTDqs2seCLaphpXKcjZerWcCLutepKY7aC+0HXmMIqCm+FzOEQHncobIE3fABG
SJlAuIF9BaeBU6UofGRVum51ScV9w2GPHVlnUCcO2+pUlg2eUhrrHQSsrCLrExDBkdIkFq6h1bJt
PBzBA3VVY+AM9pg0w+prfDAHk89hFi+W0wfROjR+DU2Ib8ouCTkAT3NTWMU14h4N3sANZ7p1IaE5
97DbDnHtLcDqy4RoxB51bv/BJUeCZrWNUvetG5xgMIH9n73zDoyi+OL4XhqB0EnoJaEKSO9VqtKk
g1KkKSpGLIiCSlGwI4j6UwQFURDFgiKoIE2pIh2kdwgESEghpCf3fm9mdi93l72UyyXZ8t4fd7uz
s7Mz3zf32Wm7xyJUiIHfcZmYJHUFHBERVv4cJDQSm//B2apyaEF9aQ9W0kFlGULPVNiHaMelC3/I
d4PWabwmZIxZ5awb2CkedhbB4clkOCAWGUghF9P+9ZVCotOUPv7TAOhbXLqwUChfZB+kt+V8e112
xRjRW88EqzlpcbLTSp6GXV7smbwV8ikdo9KUzYLyZ8Z1TASrMnw2sEdG2QtwC5smc9nlLLgE+Ev8
9t8EKRP49S3LIf0h3Mo1rF4FmIPnNY2FcJyxRgs5Bndb4prmNGX8HMfHtvNuIPyB9RqfxMCKy26h
I9JgI19jIHWPg22+KrAabOvGNQqH73BV4ClI6c+SkEqsARjGt+SPorvhPJ/LrnQeEsQIsN+nACsx
WbSq4fCn2JKjF8CXBmG1Sl5J642zd5+gBEV3QdJILoXXaucV7DmDVctYvhTK92+w4oAnWhGsWVNx
LuQEnKjMA7A5HNeQw+pWUx7wkhV2I9iqh8E1ZBZa6X0Qy2YKM8FqJE+KRWkRCcuwsY6uvZ/tSmXX
A/TjW4XxYTpYdS8MlSX8AcW91azGA19Ywcpx2TkFEl6v622pvzgN9gRgnnINq2dwKhvPs7wJcGV0
ZUuFYccB2C2z5FZI/qimRbK03MAXcGHLCmBd96KleuHypzMVMUZRfDhsa/dSluLj8FEf1kfI1A0M
OgZxcytZJJ8e/4jf0kMpEPVCLa8yvbYBfM0bUngaNwsOv7XmW1NwSPfNjqUr3v8zQKTc9xuUbJto
kuPn/5cGYTUEl8m+3iSk93Jc2NmRKfBAGsTNqO1tuXdZOmzDdrXd0oWcwQrX5p5mixO6xkDinAa+
AR1/wamQshgwFR8N7IT3h2rvJ8GvxTis4PzYwCJNP0yFlCEYQcIW17VxVS1enTbjAnbWXs4Eq4pn
IWZmBYvk2+sAJDFKjUmHiMk1vcr23YmnyD0CllQBG8GqQAT3Z3PMMbfwuWD4zJtfEXtxEHnyJJLk
Or/P1Y6GP3EwoEUiDoIK+xRSB9tnLiQMImpnBGAb/gyrncW+xl/AjbPhONf8I6Oe1BGf5484vuVY
LD6SgVxBWB0+DAlhYbie4UZXfn6r88iVq0euWvFZaFZbH7Dali78KEY0hmBqN49sPYkZXoy5kixz
8ImcyHPXMI298pgITwk/+qTCFL7t8z8sUtz1G3jO3THy0bmQ2k6JWFDfGoRV8V9RmugItqLkQya4
5LWAuf/EKRzAPtOcBWyAKGwGSR1SQFm68CUkdWJHFFsNgItHFat+gz8ohaOfOGcXdf4KTtye4wmV
QZ7EXfxr702Ayw0w9lq4jQ3qG1fwSumv8muzxnH6zWNn8MS/eW+vf8bShd/hNltnNRonE28c3noa
MzyHXdHrPawqEeeu4eq77RVYQOEYwapgdC/3ynX0N1hvviyWMEjeE85hjcDVUD/ikmG0mhei2VLN
pteiP5JzNC/6pkOLu8Z/0Wdqysfwq8Xt6GjetfR/AZe2Y9JhL8ujFw8eQ7KgRczEoXwGq7X11rNV
U4k/KRNzdX9ivxtIOzuBj5x0i4yeKSe8PPoyq/NeE/nkNzbanhEdRmn0fzzRqE/Z/dzeyp5WniMs
Ou4AX5wVv7GLHMFnPZzAu3vBmgZhJQW9doMJnn59iiyHz5MXufvjvxX3nx+iz9+DMrW5Ef2urNb/
oq87cH5pdLToZfPjfruio7fiUL0k9dyNNxZ8+mpVLXFi7TXct5D0LR82XAs3Gr8egxFSDz8sbpNS
qbcj2RkQs5C1syWpV3Q0diC5rY4+xzqG3qGXWW0F68UnWbMP68P4Uzy7ER8qD0Pw4AL+MBGsyvIx
q+4FLLDtcjVGvf6/OSNF9eCBZQfP/eS9yY1YwwXNq1gA617hFx9fwk2/gGJy7WLHsXVTNKAYvzWK
XalYQIAMvvKj3/5g+vBAORx7ggNe/2zxq6Pr8ACE1e+SV+eX3prUNiM5r5ZTF340s68MIu+AAKVt
X0S5RuCwNxd/Om14NbtE5yycOaa6bd+28U7GfyCU6B76zmtPNLZdp1YUvGSLV1AbWoQVjig+Mufj
1x9idw/ZUOBP3g1tKLvfX+iO7rfzhE1HdkqRgAB+Z5FP9w8IKClqg/8DMxe+PrGOnBBWoTZTP1r6
9uNtxVF8RUxdqe6kN6f1LSOfiV/VH33vkzfHK75E9yvjinI28CWQD7+15JOXhma0oksPnrtwxmh5
3D0jpQLdIlgVqNyFcDEGK4da7+k81LnNFrWq2qt8VZHqofwL1Cas8q+8WaeMsGJNNkMYwcoQbsyi
EPkOK+ltOCw6C865CDzFl4I5B+fzPsHKXmCClb0autkuy3vq3XWTXw9lNP9hhW/QUgbUHfM8AfbY
9T0cj+XfHsHKXluClb0autkWsOqmm/x6KKP5Dyupv3WvPPrlkOeAIym9HAIKZodgZa8zwcpeDd1s
mxRWleJhU76OWeHQ/0r7WXVbhZgMK23bBbhBsLIX+3e4U99+X8/bJhqzwnfToZmuZVV8xjtjbTNF
+VRVKz/aJXPKlp6PymupMx/LzxCClb26o995JWOa2P6ADrcJVjp0GmU5KwUIVlmpo+djpoNVVz17
i/KeAwUIVjkQSZdRCFa6dBtl2rUCBCvX2uj7CMFK3/6j3GdSgGCVSRKDBBCsDOJIKoaiAMFKUcJo
3wQro3nU9OUhWBm1CpgIVoF86QINsBulKldXf8aHvTsM4DR/IaBRimqSclSUXxviqrimg1UXV0pQ
uM4U2PDXs6rruAhWOnOkkl3Lwj3TxAtzlBCnb4KVkyC0qxcFduAL4pb1KpspuwSrTJLoJABfh317
9SDXb/czEayCeDewi04cR9nMToG/WXcPDr3VSHkDlHwCwSo75bR6HF8jj3b8g7bszW4qRrBSEYWC
9KCAgBVA0m/jatjnl2Blr4aetgWs8KWmf02qq5ZvgpWaKhSmAwUUWOHN+MrXPTO6gwQrHThPNYsK
rNCj138elPkFygQrVdkoUPsK2MEKa/fR9/n/bmC2CVba9516Du1ghR4980k3p7eFEKzUdaNQzSvg
CCuA2M1ja7JME6w07zoXGXSEFf5J0j9PO7yS2XSwus+FUBSsNwWcYYU348sr+hWXeuAGrbPSmzdZ
fp1hhX688ePwUraiEKxsUtCGvhRQgRX+u9ixKfg3nwQrfblSzq0KrPDvwC681UHuDpoIVuX50gVq
WemyHqtkWhVWyKlkBqtTGQPuKqdSkCYVYP+Sq2Z3dz6HfzEuSaaDVecMN1V987sfvifTqQLf8r+B
VKvbLOwS+8ND78e/JgfryL3nXHkT/5B1zdgy0nh2fKeLRVgZv2sjbImWVQasSv7pWhs6onMF0k7M
buY9ReeFoOzbKZB+9s35bNecsOpspwRtGk+BxL+ijVcoKpE5YdWBHG9oBWL+yLKjaOiyG7hw5oRV
sZ8N7FKzFy3t4Av3So/zsXazS2GQ8icfn/YOK4o5YSWVnrL4czK9KrAoPKtf4YVKbJh1yCd6LZ0J
871kyXHXHr2xclAxMw2wV7jNtMgYYDfCpIGZy7DNRdW+y8JP09IF/dWND114NGrzo2xy10xLFwSs
OunPh5RjVQVU11ml7XniGQ4relOoqmiaDlRdFJp+7JXmcq5NtM6KYKXpmprrzKnA6vRn9xWVehKs
cq2lNk5QgdWlFb2L2zJHsLJJQRv6UsAZVjFrh1VhJaAHmfXlx4zcOsPqztbxIRlHqRtorwVt60oB
B1hZ/3mtoZx7gpWu3GiXWUdYHX6vJXvGxs6oZWUnBm3qSQE7WF34tGNJW9YJVjYpdLZhB6srK+/P
PEViIlhV5LOBNMCusxrsMrsKrO58O9zhpZIEK5eSafyAAqvEtWOrqmWVYKWmCoXpQAEOq5R/X63t
9D5JgpUOnKeaRQGrQ284/wWIEtlssLJ2VEpO3zpXYCe+e31hl4BMpSBYZZJEJwGLAG5+3qu0y9wS
rFxKQwe0rcDaDRMyD2tglglW2vaby9xZ5m19WvVva5UzTASrSmzMilpWiud1/13FR70IBCt1XTQf
aimfzauqTAerDpr3GWUwbwoQrPKmn3bPJlhp1zeUM7cUIFi5JZsOTiJY6cBJlMXcKECwyo1aeopL
sNKTtyivOVCAYJUDkXQZhWClS7dRpl0rQLByrY2+j5gIVpX5bCANsOu7wmafe4JV9hrpMwbBSp9+
o1y7VIBg5VIanR8wHaza69xhlP3sFCBYZaeQXo8TrPTqOcq3CwUIVi6E0X0wwUr3LqQCOCpAsHLU
wzh7poNVO+P4jkqiqgDBSlUWAwQSrAzgRCqCvQIEK3s1jLRtIlhViWIPMlPLykjVV60sBCs1VYwQ
RrAyghepDHYKEKzsxDDUJsHKUO6kwtD7rIxbBwhWxvWtSUtGLSujOt5EsKpKY1ZGrcUO5SJYOchh
oB3TwaqtgZxHRVFTgGClpooRwghWRvAilcFOAYKVnRiG2iRYGcqdVBgaYDduHSBYGde3Ji0ZtayM
6niClVE9a9pyEayM6noTwaoanw2kAXajVmWlXAQrRQmjfROsjOZR05eHYGXUKmA6WLUxqiepXLIC
BCujVgWClVE9a9pyEayM6nqClVE9a9pyEayM6nrTwaq1UT1J5ZIVIFgZtSoQrIzqWdOWi2BlVNeb
CFbV+dIFalkZtSor5SJYKUoY7ZtgZTSPmr48BCujVgGClVE9a9pyEayM6nqClVE9a9pyEayM6nqC
lVE9a9pyEayM6nrTwaqVUT1J5ZIVIFgZtSoQrIzqWdOWi2BlVNebCFY1otn/BlLLyqhVWSkXwUpR
wmjfBCujedT05SFYGbUKEKyM6lnTlotgZVTXmwhWwdQNNGotdigXwcpBDgPtmA5WLQ3kPCqKmgIE
KzVVjBBGsDKCF6kMdgoQrOzEMNQmwcpQ7qTC0F9xGbcOEKyM61uTloxaVkZ1vOlg1cKonqRyyQoQ
rIxaFQhWRvWsactFsDKq600EqxC+dIFaVkatykq5CFaKEkb7JlgZzaOmLw/ByqhVgGBlVM+atlwE
K6O6nmBlVM+atlwEK6O63nSwam5UT1K5ZAUIVkatCgQro3rWtOUiWBnV9QQro3rWtOUiWBnV9SaC
VU2+dIG6gUatykq5CFaKEkb7Nh2smhnNg1QeJwUIVk6CGGaXYGUYV1JBhAIEK6PWBBPBqhbvBlLL
yqhVWSkXwUpRwmjfBCujedT05SFYGbUKEKyM6lnTlotgZVTXE6yM6lnTlotgZVTXmwlWMex/A5sa
1ZNULlkBgpVRqwLByqieNW25CFZGdT3ByqieNW25CFZGdb2JYFWbuoFGrcUO5SJYOchhoB2ClYGc
SUVhChCsjFoPCFZG9axpy0WwMqrrCVZG9axpy0WwMqrrTQerJkb1JJVLVoBgZdSqQLAyqmdNWy6C
lVFdT7AyqmdNWy6ClVFdbyJY1WFLF9IbG9WTVC5ZAYKVUasCwcqonjVtuQhWRnU9wcqonjVtuQhW
RnU9wcqonjVtuQhWRnU9wcqonjVtuQhWRnU9wcqonjVtuQhWRnW9iWBVl2YDjVqLHcpFsHKQw0A7
poNVIwM5j4qipgDBSk0VI4QRrIzgRSqDnQIEKzsxDLVJsNKUOys0aNuxaa0imsqT3jJDsNKbx3Ka
XxPBqh4fs9JwN7DIgJUnbsQnR13e9V6r7P0X+PHKl7yyj6YWo+jsb+Y6AHHaiuXCPn97Un1f5ZTq
X339rl20zsu/ecLNCyopFsg3wapAZC6EixCsCkF09Us2WouPA8l29/2q6pEkqfi995Znx0LuwHZv
V5GyDi91BE4Wt4+yQ7kufieuaScfagpwOSAj2hMAP/hk7Gp2i2ClWdfkMWMEqzwK6LHTe1xDUlxa
t2Duoh2RuPVviIuUe0RETGeHaibCbndhtQ+OOMBqK0Dk5atoN+Lx0neeE5duAnDWDlaPAawiWLnw
CgUXgAIEqwIQOSeXaIasuvl8JR618WdWgJ0V1E/rC/AmO1LquVdGWNSjZBdaSgVWT1Suhlav0+Sj
AKnP8xQIVtkJSccLVAHTwereApU3xxfz3wJwrpMS3fJcEsBcdRRhL2euEs/NbzVYDVLSKv8dQHRz
tkewUjShb00oQLDShBukEWkQ3dUuKx8AxNTO2C8aYOuA9QSYnXFAbHkXL1XcuUvoV8zPIZpfQBFl
eFwNVkNtkUvtBfie7RGsbJp4aqNoq8dmLJz7zINB6jcix8sULV3K5nXHI9nuFSldyjZPwiL7li4l
W3G7KRMpoHRpu2heJUqXdK5F2V6pICOYCFb3xOJ4TLo2W1ZF/gD42N7v5c8AzMSAbhPH+Hs/+MWu
Q2smBrLjHV5YBrBlKvYXSzwysa+o8mXHfX/86okfxpcWCXSd/kwZqc0bG/ZufKu1CJGkkkM/3Xho
66oXROmzhpU0FuB2PTyTYKXI56HvEs/8k4J1EP8X/MYyZRYji6Tnh5+1OTCLaGqHJl+/cr99+AM3
2Igk2pX/tr7fy3YXW33jWp+MaBX+Cj/Bm9QZQdraMh2sGmpLfzk3jZIhwfG1gK8gk/C++jMkNl3J
KzgcaIOR3xXb0FaqmQR7+H2wwwE5bF9nntpHEN9s9h0eFjNRpN90nxzl1kx2r84GVkH/AYzHaAQr
oZ6nPttsZ15IjUtgX7Hzi7lI1zLmhTH82FeQLDzqImIWwTMABtgfHsQuqVjaHwoD/wIYlhGt8hmI
ywFDM04o6C2CVUErrnq9x3FA3d/hSJckuFBDklZB3B64vmT2ois4VRgiScN/3AVw6seVtaTgCNjC
YNU+HGDfwsmzdwNEdGVJzIPobZC+dcnq6zj4xBdsBeOg+fY3nn75pySwTsUY2cBKWgrwIUZDWJ2x
64eMpdlAJq/b1vwa0mLLc73adh42D30G3zlMyGYk630GzvDJlS8hwTaKmXE4R1uvgrW/fcSBANc/
W4L21W8sFxG9xEGcBc7o/kuVT0FMW/uztLZNsNKER/7n1AuUpOrhcKcZgxVW8FqYx5CNAJ96Sd5+
AwDe8vOzKLAqtQesy8phhJJvpsF/ZXBjHp5y9oHikm9jbCG9y4qHK6QWlsRvv1EJsB2ZmB2s5gD8
ikMbCKvrg3or1vNDghUT012rdBjg1gR5KUjdn9BJb6sn5X0CTnBY1WjexAXP1E+0C1WB1VZ+2Lto
hbGnAW5g1UIjWHEZNPghxqy02Q38EWCao2QlL0Jqew6ra3X5kaoX4U4L3OoNMIcFyC2rUQDrRYfC
51eAZ/EAwiq+A4shDUmF9dj4siyFa0E8QNoC13B1RHawwnbedvyZIKycjNZZCRnd+XwfIPw+24nF
vgSIU39OwYKwkt1li57bDZewYgnVxIb270XZFsGKqaBF0zKsNgA85ahZwAWwYicAW1afyQdmA4Ti
prJ0QYbVBkjrJ0cYmgbrkE0Iq0/FyHtQLOzAW7nPxI8elbtzayAKl8ZnB6t+VtiDLTGClaNL8rR3
TxykyyOIPJ1KxwD+p0zPSgHNurZhrWK8s/j6n4STVX1ZDz/DAjv269umhLxv8fVjR+u2b4fjAopZ
glt3bR6s7GUJK2lQCqR3Z1EJVopgWvvWMqzWAbDBJDsLDocEHAddBWkj5dDOVliAm46wCgyDE+Xl
COUi+TbCapgIKRoOB8VPgO37lKw0IApu5wBWA62wTnQDbz45foJsY7AtQC0rWercf80F2MZbM8qp
OABzs6IkNd6xY5DfMwduJ8cef5111WtuOpAIiUf2vyBJr+zYLP6St/L8k/hkQezRaaJXWHv7/onS
g1uv3Y27vKapSM536KZLscm3L20cKWb6soaVL470L2MnEqyEfNr7rM+XLmizG7gi05hV6zsQgXnF
AXZlNrlBFPyCqjrCqm0MbFYGwX3OQ3gwa1mlyuOnRcPgkIBVmS6h76zacRV7dTmB1ZMAS/Gmjy2r
M3bLcMYRrNyv1EV2AjzpcHqFGwD3S1JngFcXoV+Y/Y5DVffGie1PJWkFpPN+Y9MjIghgA29KNU6C
N59LE2GXeX32fkuJAR9yImYNK2ksehbvRgQrB49oaUfAqoGWsmTLyxs48mTHBQwfkA6HyzJYRQfL
sWqFwT+46Qir3gmwWj4ueR+CiFoMVkm8jS9JCqz8nzqLK+IBko9czRGsPhDDYggrejZQETeP33XC
IK6NQxq+awBekaSO2MCC09M6dZ2Nt5JFklRm/ORwCJ/+VEdJkmcDg08CbH6sSf3xuwF2s6mURnfg
MkQvGffQvAgQ3p9khfPPtKrd9lWcZRzDrpINrJomQhQbYseW1YMsurAyJ2g2UNGisL+1DKt++IID
h0FVC869/YiKrYKoKrJwjWJhE246wqr7XfhOEdbvitwNdIKVhd13//t65pjOpX/KCaz8d0JKf0yU
YKUom/fvDqlwxcHBkvQODlpxWMGR6uwCjU9CEm9JHYfjvD0swwoXkqxkHUSp9HqxUBhhBde6sJAB
d+EWdiUtG+CWuAn3SYTl7EA2sKp9HRL6YjSE1Y6vV8n2zc93CFZMPC2YlmFV+RbA8/Yi1cKb5jgM
WAWxSse1PcC3GOIIq5q3YJPSDawUBdv8VVpWXVLgxsPF2Ji75decwAq7lpcDMTbBCkXwkPXEVqoY
TrIlOB3gaw6rNHn95phUWIO9b9vSBQGrurfhfGVxUqM4uITYQlil4ZAWmvefkNBekoIOW1eKGIGn
YQ9zdDawKv8fpI7AaAgrR6N1VkLHQv/UMqy8PgI4zgCh2OsA57EXiLBKHSqHjefdBidY+Z6H03hv
5TYslXcKMnUDsWElg9B3Tw5g5f0tiNszwUoW1gNffXEpr1Myr3GZsRt4Au8wzIIuw2FsUjnBakLG
cKbvn5DahcPqrDwzuBhSsB/n37x9NZ6CFHwV/s0BrIrvgWRWrRBWsbciFLudRi0rIWPhf2oZVlIr
HFd9I0OjluFg5WsZVgF8IYL9doG1G25iy2oOC5GXLqwFeFhEkL6G9MdxMxOsvoVUeRALJ0RdDbAP
kRORpBnp9NYFmxie2ugOcLGUQ2Jey3CpLm9ZLWN4YbYFrtR2hpVlIVht40of8xUu2LL6XZwgfQBp
D8mbUrkGXUbgWtOcwCrwMNxhi+MRVqHVa8kW0u48wUoRs7C/NQ0rCVeNp38oD095PXgOYB3vNSCs
Yrtw5V6ywr/sUWVcFPoeC5Bh1S0JDobwCG2jYD+bCsoEqwUy+KQgfFz6totFoYN4GlLxxstSAWbx
HWpZCU088dkuBSLrOyTkvwngJQ6rmUr4V5DY1hlWfj9BSmMlwmyAGbxlxcYDmC2QYVVm1PKjlyL5
LEpOYBVyBSLq4ekIq8E8Hf5R4STBKkONwt1qwJcuONaYws2R/dWLY+cLzi0a16Nd7ynrsdbJ795D
WEH409UCWnyYCun8Jto+EU6P7VJKgZXPCuxHDKroW3LEWQA2DpEZVn2sED6uuF+1yUcgFpK7FVFd
FLrnux/Rft3FXlS/sBjPGcHK3kF52655GZK6OiQRiLN/GILdwMlK+FJIx/aOYzew6EZIUBbSSbM4
37BltUI+RYZVT/4suzV66+tXYS9rp2UzZtUpBc4yHyOslEEG3KNnA2VVNfClbVhJ/gv50/hJ8cmI
C+t3fIKID7Cvxldb3cJFgekzWDWUgo7j8dstpGAcTvfG/Vr78Un+22dvWvHpYz7UPh9Sewi5cVHo
ERwE8fscEwy/hKxegCuo4rf4lTwAx8T6QhFPwqfvM+z8NH4dScJ3sJ8PkGPgF65i/I5fICNIk1vY
TwY4zeb4NWR+f4sRx4ws4bK1G0ghhJU8oChJf0BcS2dY+XwDydg3FPYxpA3nLStHWN1zAWDP3MFN
Av3LncwRrF6Vn4sgWCnKau1b47CSpC6/3EbioMVsG84wxGwVxDR79jqGJe0fJof1+i82IayJVO14
+A88pPJn0eyklDOPiemmWeGX2HgEmv/B8E1soKTMfNaoTNo/yqv0xoS0Hb4lNoRvsaOQJP0YLtvl
3d9Nwnc9CGsYHr5btLH4/sjw8E8JVoo4uf2eBXC1qt1JRZBe7HEbhNXbSvARYM+BOraspDcgHRtg
3Cw/QlIrFVjhY4fLhT+rns8JrMrgyq3eLEWClRBWe58NNd0N5HoFj3/t40/nPNFQbtpg2Cq400iq
OmbGc/fzpTY8VrHGnUK8JIuP7fmx2k++9d60fvIEkeTt66uc7+Mr06XJ+FnPdGUsC+g6CH8PtnCe
HtuXzQd/Pjaz+Cqn8yAvX9sFbVG0uKHJlpVUE+8oc+3k6osP1XTEfYTVX7Lo9SKB3RycYIWvzBBD
iJJU6SpE4GKtTN3AvyFRHtaqfycnA+xvAxwLZHkhWNl5RFObAlb3aCpP2WYGYSWeD8s2JkWQFdAm
rCRcjBI3zOake/E9LYsYpBBWCeIdGezFih9giPdJOM5HqcQ6q+axcIKTRZJGY08f70POsLIcg4ia
IuWZrmcDtyjX9nsGn2MWM8gEK0UUrX0TrLTmkfzJj0ZhVXoX0mphbd7oDRh3EanCV7QjrOAAR82T
MRDNpui8DkF4LSaNvIL9U4AVbBpYqncGItkKYWdYSTiq+QyL4DMpEWA/21IZYN9VoXLlypWqN34E
X4wGn4u2N8GKiaVFI1hp0Suez5NGYSXVwZkQuL3to1lvfnUqHaFShxcdYXUHzs9+cNw3KWB9mQfh
Q4O7Puhvg1WtcHwoZnKP7tPOA7zPImSC1bAUiH+7R8/JO+ESLpWa2EwVVil89WdkjBVz8Zk8Ykmw
4oJr8INgpUGn5EOWtAorqeoSPt+LsMD/vV4kr6lDWH38PQ+C5PfEDMlQxpPPJQkXs3Rh+jxwSRyH
tE85ZJpY4QdZt08ARuF/1/yPnYF2oOE0/MR3c2Cf024BlSQN5YfFR9LeMcoz83syVhRjglWuQKrc
I5WT19gXzkdnev23xrLoqezoElbfQ1JTTwlgknQ0CytJum/x/mgrpEcdXmR7ZyjCamaxV/6NvHNm
PZ+gY056dO2uLWMlacKyz3AyBK3WJ0fjIOHyenmxetVPl03k4ZL08LIvWuOm16M7r8df2zaltFTm
08NHXpKkfsuWOlSb5stkW/reMz2KyCdL0kvLluFaCcVKv7XsE97/VAK09k2w0ppHHPMzcNZUPtjq
GEp7WSigYVjhKpJ7mrdvXs9uERjC6nV8d2vdBpXZcLtiDv/uh4GBDZvfW12MMylRHL8DajYMEY8Y
lgvkC1ocDxtjz0SwuhffrAHpbAiTzMgKaBpWmYQXsMoUTAEqChCsVEShID0rQLDSs/eyyjvBKit1
6JgOFSBY6dBpOcoywSpHMlEk/SigL1h1kt/4ox99Cy+npoOVmF8pPMHpyvmtgL5g1S429pX8VsQo
6ROsjOJJKoesgL5gVbJTZ/kFG+TA7BQwEaxw4S/OBuasZRXk8AaV7ESk4wWmQAm7WX8XF80RrIrK
j9u5SIOCC0wBP3l1bA4uSLDKLJJP8wVHOmcOphANKNB1//sts3lPTQ5gVeXZv6nvpQFvsiwEn1nU
SVlRn02WCFbOAtWZuBWfiujiHEz7mlCgB76kYOtE29vo1PKUHaxK91uGfx30ltqpFFbwCgTjm9b+
efbenFyYYOWgUpneq/Bts9hb7OIQTDtaUaA7f8/4lZX9+HsIVHOVJaz8m75zhDnY/t85VFOhwAJS
IJg/13jzl2HZd/BNBKvG2Y5ZtZohKjLBqoAqau4vI2CFsDkyo6WLx0+ygFW1CevYS6OZvZH7a9MZ
+aGAgBV65OxbnbN5UMh0sBIv5lBRveakv9mrRIVRy0pFIS0E2WCFL3/e8bj8yjnHjLmCVWDvFdcU
/xKsHDUrxD0brPDvAf59Nsun4QhW3E8BQ7/FtwZlGMGqEKtvVpe2gxV6K3zV0MzTtqqw8mo1/2iG
e3GLWlZZyVyAx+xghW6J+mUc/sWJCyNY4Qs2Ws89lepQk2nMykV1KfRgR1jh//qceb21U+dBBVa1
Hvv7rqODCVaF7ko5A46wwv9huvRep4yX2DjkkmBV9emt+G/ITkYtK4daop0dZ1ih3+K2Pl3NPoPO
sCrVd9VlJ/fiLrWs7DUrxG1nWKFvkndPr+l0B+IZNDmsAvouwWnszJZ+XyG6jy7tWgH8A2oVi1jc
R/lvH0lyhFXLGex/FjPbXNfXoCMFqUAN+S2nji6KXTWkbKZcmAhWTfhsoN0Au3/zt/9Lc9RI2cO/
arOQaU8BqYcqrADSjr/dXLx8zh5WwY//xf5hWs3eJAdrw70hqrBCl537uF3GHYiDy3Swsq0nrPbC
VmUaO3Nltu765Vcy7Snw8278qwUXlrzlOf6UHW9ZnSoh4aTJLRdRMfgMOVgT7v1lk2sfpe+Zade2
4P8JbpZ3sIuWlYBVuT5f33QtEh3RqQI3v+pbTnqAZf5cj9mnUnRaCsp2hgJRPw2pbOsOmrJl1ehj
9XGMDI1oS68KHJ/3PMt6Mv6DHpkhFDhr+1MLM8LK0uWrMEO4kQqRWYGrn77GAl2MRWaOTyFaVyDi
h97yf2mYDla1eKOy6kPrsxjP0Lr7KH8uFIhYN6KqhM86A5x/8OMLLiJRsI4UiN46IeMxBZPCColV
99kdrp1m/WLaK2TaU+ClpU6rd+1caN0++R52JxID7CWlckNXsvlfF7aNHKwJ906f52o2EB13cLrD
vx+aCFZN2drPdNGy4s2rEp0Wn3ZRldPb8Rj0oTUFOrpYugBnPrtPnujmsDrNnuH3rvvyXlfxZ2ut
ZGbNTwVXsLq04gGnJ2/MDCusHhUf/jnz8nXGtC5mrTsaL7fKCnZ0V9ya4RlzRhmwwrL437dAfXyS
VrBrxNMqK9jRowmbxwdnyqDJYYUPBtabvTsz2wlWmWqKNgJUYJW+Z9Y99v9m7AArzHXguF+jMjeg
CVbacKikBquD7zb1Ucme6WGFmhS/b5Hzw2MEK5W6ooWgTLC68r/OTuucnWGF2W4w9RC+/dXBCFZa
cCfmIROsri97IPOTNjyzBCsuQ4VJ6xweyydYaaQqO2fDEVZx65+s5BzD/nGbjGNF+i11vCERrDLE
KdQtR1glb36hhsvsmA5WGROhjpp415uxL+PxG4KVozqa2bODVdKBl+t5q2RMpWXFY1V4eK3dUwsE
KxXpCiPIDlbWI3Mbu3g7DM8ZwSrDQUW6zecvYMfuAsEqQxZNbdlgdWVB16LqOXMFK4x975S9ytIH
gpW6egUeaoPVrc96O3XonfNiIlg140sXXLWshDDlRq/jg7EEK+eKopF9AauotWNd/+9fFrDC2cEu
i87wsSuClUY8KmAVv2lS5g69cw4JVs6KNJp6kP6Ky1kUzex3T4PEAy82yio/WcIKT6w6gs0OvplV
EnSs4BTAv+JKOTE7uz+D5PkhWGV2i2+vpZe6ZQ6mEA0o0PPMsj5+WecjO1jh2fe+fnBO1onQ0YJS
IOTmN0OL5exiJoJV8xx0AxXRKmfTe1bi0XcBK1Ai+85CDmAlSWXKF3DG6XIuFCgS7OJA5mDTwSok
swYUYigFcgQrQ5XYLIUhWJnF06YpJ8HKqK4mWBnVs6YtF8EKH8oILKO2BE3ndYJgpXMHUvadFdAN
rKo8OP7px/pVdc6/J/YXRB5xvRDcExcolDTMBqu04EKRmS5acAroBFYVPrzMHqC3Xv4gyPPaLIOb
du9CUkt/4PTJuptjIFipeZLCdKyAPmAVfJA9KJHCeLXT89RYCuHZwGodxDbTm5NNBKsWbOkCtaz0
VkNznV9dwMr7R/w3sMn1q7VfgG8zneeV60Jmc0L2sPoZIh3ewplNgpo4TLDShBsoE55TQBew6pQC
5xryMk9IgDtNPFd6kVL2sFoDkR6/qqdL4ZwewcpZEdrXuQK6gNWHYH1J1vkXgCdzILlfk+73VbGL
V7lljw717Z/lLtqmf/+28gtTM2Dl419MjuTToHNH+T9DLX4+a+F2a19fnp5fvfv63KeH8XiClZ3/
adMICugBVt4bILaBLDb+z+Eim+6jZk202HbkjXKb/5njNWpPZHLChSXKmua2Ky9Ep9y9cWim8jpn
/4kHYwFiz8/n1LHBauDBYzs7sHSKTtp7IyH+2p8jGaDK/HAoBtLOHGbX9R2683qiNeHy6sYsmqbN
dLDSwx1E0zVG85nTA6xKHYCbSqvoCYClNlG3w8lMsKocD2vexfFWZuc5eaSx7MWn6SzgcD1+bsnv
2Q6z06z1pMBqdAzEDWcJVvldHAVYg8P55U+Jva145APc5O/1vtGHp6ThD4KVhp1DWXNHAT3Aquiw
Jx9SoLQU4FlbObfCMSXcFlYpGmKs117v3HrSYYC9JTG8WQTEvNkhuP6YfQDfsdF57wUAYa+0ajYB
A37F99fJsBp6F6KGsHSK/QFw7MWug97HF7Z9X0TyH/LYIbg7Z2JvSXokFf4ZGFK31/IkOMr+EUjL
ZiJYteSzgdSy0nJ19ETe9AAru3J2j4GUjD9+cwEruN6CnVJhM8BT+P00wHieRMXTcLoibnVOhKs8
RvkDkI5LEgSshsVCRD8ebxrAb/wR8GanwDqUBf0EEWyA32s9RFbnUd4BGME3tPtBsNKubyhnbimg
L1i1xb+uXJzRmHIFK3k0vm0cnCwmWRaln5JbQcshrj4iB1tnLwqxHgKYzGFVU3r4Dtzoy0MDL8GN
uuJ4ryRYz7bkpQvljsJ5sXAi5J/9Y0QUzX6aDlbiNqJZf1DG8qyAnmBV/MVIgF12i0JdwCpGnsbz
3QK375EstVvXk5dmrYe7OFBfKhxiQoRwVT/7biKD1fWqw+/C5W4icKTVNixWYj9cYX8eI8Oq5D5I
fZG/99xSsrQyipZnF+RTAgSrfBKWki0sBXQEqx5bcXT7R/sFCVvgaCbdcMxqr/J+tY8gsYscoVTd
TsM/SOawapUKG4vZn4ewmh0D8Lkc9iHAzBKluQWsg2g276csCsXx9fQ1j7ZyONs+JS1tmwhWrdif
baVRy0pL1S8/8qIbWNVfjf9tf+ohtpZAkkZu2sjsNsTx701PZEiDsPpVbkhJLwGMxCN+vT7cfzky
kc3psZbVECt8ntGVxONLIY3N8N1uLVLB5fKRl69wu3QXEjphqAKr0qtYInfOrhiRL09Ui+t76JNg
5SEhKRmtKKAXWD1yDREyR3nz6VzGDDv7JENOhNW3yt4LAOPwj0FxISneeO/uf20rh9V4gPeUGPwb
x7Dg9DcAm4qzXctv8uoEdlZ6WnxXDFNgJRUdvR6f+EE7J4968QQ0+UGw0qRbKFPuK6APWBX9IB2S
VuLguGwT/kHbsycWEv7ZwzYzVjNICKvvlWjzAYZIxdYCnJ0/omWFotKXHFb90+F/Ti0rONYsYD+A
GJj/GdLmdOmuWFe7MSuWrm+NsUv+iUdc4WCXpo1gpWn3UOZyr4A+YDUd4NJAu8L5lSjO7G84zjdK
8EFvcRxh9afyJxnfQlJXaRDAUXnE/TsOq/pJsEaOUbTT/fjfP0shCnuAvRIhgq9L/xLgGbtrsU1b
y0qEl2i5OA2OKFdxiquVXYKVVjxB+fCQArqAVac4CG+jUuAtcCxTKMLqqjwIX/Yo3KgovQnwihxr
L4dVqQi4JD930yUJZvPZwGCMsQLgFzYk9hzAF/IJRZ6ZN40FybBqMe9dGXtFdkIcW7KlYTMdrKpp
2BmUNU8ooAdYWb6G5MFqhXWxdAEeF5EnWmGDJH0C1oli/4EEDiuvJXx1FQv7Aqy4xFRewR5yXSwi
vScGwoPFGf0AfmI9xl/EWxe6AjwnDmDILdY/1LCZCFat+WwgwUrDtdEjWdMDrKpchIPBVaspVsZW
cFewuoEEkqT+18DaR5JCAdYXY/v349MzCfVwo2EkhPdgIU+kwMFSNlhJz1vhBjv+CSKKr+bqeEpe
+4D9SXZC1atwhvcUpY6RsNGHJaFdI1hp1zeUM7cU0AOsWgMkRtks+n1bQV3ACp/x+3j4qCX4wNjX
OK4UcgWfABzaa9yalMSdYJ3fHce3sGcY9fljj65Kgzs9MTHlQWb/LfjwICKoGr6XdO/0/iMW3gZ4
i18MTzi5+AnJMgPg2vTe7XrMCofEB2zZ0OYGwUqbfqFcua2AHmA1mq0VyLAvbYXdAxccpvXYARyz
2jhPRE5bhc0mScKH/rhdHdwcX79wIxCfVF6SIoKujWMRvoE4MRTVDo8/h4u06v8lDkPKfLFOvWkU
BuyWpAC+CgIXfEGsmDlkp2vUCFYadQxly10F9ACrHosdjK3zFDZl8Ww1WP3qO37r9TvnN46QF4d2
/PnsnZt75+F71p/acfSLAHbukDUnr5/aOq8mT2fM4nlBIsGnFi95GVteUslpuyOTo06tHiCCJanr
d39teRl3SkzfGWGF28d/bKUc0ew3wUqzrqGMuaeAHmCVq5Jhy+o3L8k/uF5lX9t5lkr1QkryvYBA
JbRCcEV/W4TMG8VrNaztMN1XlEEMLaBW4ya1ymdipDiopU/TwUr7DxVoqXroMS+GhJUB/7I093WL
YJV7zegMTStAsNK0e/KQORPBqg1fukAtqzzUFl2cSrDShZvcyCTByg3R6BQtK2A8WN2BP6gbiFXO
dLCyf3mQln9ylDd3FTAcrCpcjF5NsCJYufuDoPO0q4DhYOXToEmwduUuwJxRy6oAxaZLFYQChoNV
QYimi2sQrHThplxl0uuJdRvmyn8okKsTjRGZYGUMP2YuBcEqsyY6D/F6nT1Z8adYMqjzsriTfYKV
O6rp4RwTwaotX7pg/AH26uIttYP0UP3yI48Eq/xQVQtpEqy04AWP5qEz/zNw+YW2Hk1ZH4kRrPTh
p9znkmCVe800fkYt/qcn8LDGs5lv2SNY5Zu0hZywiWDVjr0TP8343UBvfNMawH7TjrATrAqZKfl2
eYJVvklbaAkXf+Pfw1/XLrTLF/aFCVaF7YH8ur7ZYJVq/JYVVpVSpm1WYeEJVvkFi8JOl2BV2B6g
63tYAYKVhwXVTHIEK824gjLiGQUIVp7RUXupmA1WKaboBmqvnhVgjghWBSh2gV6KYFWgctPF8l8B
glX+a1w4VzARrNqzpQvUsiqcelaAVyVYFaDYBXopglWByk0Xy38FCFb5r3HhXIFgVTi601XzTQGC
Vb5JW8gJE6wK2QF0eU8rQLDytKJaSY9gpRVPUD48pADBykNCai4Zs8EqmZYuaK4OejhDBCsPC6qZ
5AhWmnEFZcQzChCsPKOj9lIxEaw6sKUL1LLSXh30cI4IVh4WVDPJmQ5WlTUjPWUkfxQgWOWProWf
KsGq8H1AOfCoAgQrj8qpocRMBKuOvBtILSsN1b58yQrBKl9k1UCiZoNVEsFKA7UuX7NAsMpXeQsx
cYJVIYpPl84PBQhW+aGqFtIkWGnBC5QHDypAsPKgmJpKimClKXdQZvKuAMEq7xpqMwWClTb9Qrly
WwGCldvSafxEgpXGHUTZy60CBKvcKqaX+CaCVacEXMFOs4F6qZlu55Ng5bZ0Gj/RbLBKpKULGq+R
ec4ewSrPEmo0AYKVRh1D2XJXAYKVu8pp/TyCldY9RPnLpQIEq1wKppvoZoNVAnUDdVM33cwowcpN
4TR/GsFK8y6iDOZOAYJV7vTST2yClX58RTnNkQIEqxzJpMNIJoJVZ7Z0wRTdwKBuvUN0WBc9lGWC
lYeE1FwyBCvNuSTPGepwHOBWaJ6T0WsCBCu9ei67fBOsslNId8dLHMIWJMQ1013GPZRhgpWHhNRc
MgQrzbkkrxlqZWWwgsl5TUev5xOs9Oq57PJtNljFG3/pQhsBq2ezc71RjxOsjOpZgpXhPFsSh6wA
ElsarmA5LBDBKodC6S6aiWB1H5sNNEHLSmp3CiB6ku6qoqcyTLDylJJaS8d0sKqkNQ/kQ34qDxvT
IB+S1UmSBCudOCrX2SRY5VoyOkHbChCstO0f93NHsHJfOzpTkwoQrDTpFg9kykSw6sLHrMzQDfRA
vdBxEgQrHTsvy6ybDVZ3CVZZ1gcDHCRYGcCJqkUgWKnKQoH6VYBgpV/fZZ1zglXW+tBR3SlAsNKd
y3KYYYJVDoWiaHpRgGClF0/lNp8Eq9wqRvE1rgDBSuMOcjt7BCu3paMTtakAwUqbfsl7rkwEq65s
6UIczQbmvdJoOwWClbb9437uCFbua0dnalIBgpUm3eKBTBGsPCAiJaElBQhWWvKGJ/NiJlglUjfQ
k1VHq2kRrLTqmbzmy2ywukNjVnmtMlo/n2CldQ+5mz+ClbvK0XkaVYBgpVHH5DlbJoJVN9YNpJZV
nquM1hMgWGndQ+7mj2DlrnJ0nkYVIFhp1DF5zhbBKs8SUgLaUoBgpS1/eC43BCvPaUkpaUIBgpUm
3JAPmTAbrGIr5oOIlKSWFCBYackbnswLwcqTalJaGlCAYKUBJ+RLFghW+SIrJVp4ChCsCk/7/L2y
iWDVnS1doG5g/tYnDaROsNKAE/IlCwSrfJGVEi08BQhWhad9/l6ZYJW/+lLqBa4AwarAJS+gC5oI
Vj2oG1hAlapwL0OwKlz98+/qZoNVDC1dyL/KpI2UCVba8IPnc0Gw8rymlGKhKkCwKlT58/HiBKt8
FJeSLgwFCFaFoXpBXJNgVRAqF/A1Apq2KVfAl9TQ5QhWGnKGR7NCsPKonJpI7J5tVuuZgZrISmFk
gmBVGKoXxDUJVgWhcoFeo9guXPwKUQ0L9KIauhjBSkPO8GhWTASrnmzpgglmA5unM1jBUx6tJzpK
jGClI2flKqtmg1W08ZcutLNyWD2fq3pgoMgEKwM506EoBCsHOYywU+YCg1VqeyOUxZ0yEKzcUU0P
55gJVkn4GzZBy0rqfwMgea6XHqpffuSRYJUfqmohTbPBKsr43UBJuufJ5ztYtFC7CiUPBKtCkb0A
LkqwKgCR6RIFqQDBqiDVLshrEawKUm26VgEoQLAqAJEL5RImgtX9bMwqqkKhyEwXLTgFCFYFp3XB
XolgVbB609XyXQGCVb5LXEgXIFgVkvB02fxSgGCVX8oWdromgtUD1A0s7NpWINcnWBWIzIVwEbPB
6jaNWRVCLSvQSxKsClTuArwYwaoAxaZLFYQCBKuCULkwrkGwKgzV6Zr5qADBKh/FLdSkCVaFKj9d
3PMKEKw8r6k2UiRYacMPlAuPKUCw8piUGkuIYKUxh1B28qoAwSqvCmr1fBPBqhdbuhBJs4FarYqe
yhfBylNKai0dgpXWPEL5yaMCBKs8CqjZ0wlWmnUNZcw9BQhW7umm/bMIVtr3EeUwVwoQrHIll44i
mw1WETRmpaPa6VZWCVZuyaaDkwhWOnASZTE3ChCscqOWnuKaCFa92Wwgtaz0VDvdyivByi3ZdHAS
wUoHTqIs5kYBglVu1NJTXIKVnrxFec2BAgSrHIikyygEK126jTLtWgGClWtt9H3ETLBKxjGrW+X1
7S/KfbYKEKyylUinEQhWOnUcZduVAgQrV8roPZxgpXcPUv6dFCBYOQlimF0TwaoPdQMNU22zKgjB
Kit19HyMYKVn71HeVRQgWKmIYogggpUh3EiFyFCAYJWhhbG2TASrvtQNNFbddVEagpULYXQfbDZY
3aSlC7qvs9kUgGCVjUC6PUyw0q3rKOPqChCs1HXRfyjBSv8+pBI4KECwcpDDQDsEKwM5k4rCFCBY
GbUeEKyM6lnTlotgZVTXE6yM6lnTlotgZVTXmwhW/djSBZoNNGpNtpWLYGWTwmAbZoPVDVq6YLAa
nKk4BKtMkhgkgGBlEEdSMRQFCFaKEkb7JlgZzaOmLw/ByqhVwGywCqduoFGrslIugpWihNG+CVZG
86jpy0OwMmoVIFgZ1bOmLRfByqiuNxGsHmRLF6gbaNSabCsXwcomhcE2CFY5dWiFunWC1eL63dOo
imN4YKOGJTAkqG7tYnYHLNXrBvvY7edms1K9mn65ia8at0LrEWOKSMXr1C2jeti9wKr1QnzdOLP+
iw+onFV6ykiV0NwGeQ5WrlzuW0/F5SUlyb923Qr2uS1bt04p+/3cbFf0kMvH+ksBdeqWzc2ls4nr
psuzSTUnhwlWOVEJ4/hvToy/WUclcs0b8KVj8IuQOgBD5idFd7M7UGRX0gmHqmx3LLvNVUlX1S6d
3WkOxwedBUguL/WPT5jqEJ6nHa/NSWdr5D6FgE3AFGJW8/F3l3w4uQHf9t2QNpBv5OnDY7Dy35gU
H1FPJS/B4fC1Y/ALkD5YktreTlpsH/5KYvwE+/3cbK9ICrsnN/HV4g44A5BaUep3N/EltcPuhVn+
TDoX4t6peT3LRLDqn5KXbmC7u3j2dBW5Q67BMsfgqZDEfoqfQPr9+BX0zoLR7HiRI3ClIttww9ZA
lNqPJjcp1YwCSLsWKA0GeDU356nHLTV3wQRvPOS1B24Eq0fJKnQCbPPnxwNeCUNZAW6/G8D2e6Yc
Lp3VeTk65jFYtYnDnKmJVSMMljtm5XlIGSRJHVIExMq9vWCMBSO8DvCEY7yc7/0AMYLgOT/FOWaN
SHQ5jnsMBJjpfCz3+yXnLHiUudyyC27WzP3pnjjDbLC6HuSmam+z39RO+36dnJBLWM2LjeyKceoC
rGE1t8iO2GPutqx+gsi8wmoMwKbuzX2lB2Njp7gpgd1pVRPhD9b989oYe6q6XXjONqtdgCE8pv8i
gPTL/0WjtPNYgN/v8ErOksgilsdg9QZz+W5OUcfLuYJVm5uxi1jM2unwixd+T4+NHcf23bHvISqv
sBoFsLlHC1+pT0ysBxrTlePhTzYWYfkj9nSwOyXK+zkEq5xpWPIcXL4Fd9tmju0SVqWrVi6C0esk
wWoGK0v5qhXYnckd8wCspgOMZ5f2r1KVDajl0arEwK98rCqoasVcD8RZFsI/TBlJmgFwemiAX8XX
7kJsSxbQ23qzPvvOi3kKViXOwOWbEN8+c15cwcqvclU+HlgrAX5gsCpZtYoK6jKnpxbiAVi9CPAo
S9ozLq8UBb/xgdNAN1yuVsLchxGscqbZw1b4CBtXb2aO7RJWctRaSfBd5rNyF+IBWCEXhubuolnF
rhQDa90lr3RPtJVzU6oZBlca8ctMQ3nZRvEd8EVW183JMU/Balg6/A8bV+9kvqYrWCkxQxLge2Xb
3W8PwOplgOHuXj7zeRWiYH2u70uZk8lLCMEqR+p5r4HETi1T4Wxxu+i1+/THflVwxphVQNuBPYMl
SR6z8vL2tkhFyrZJhl+CArEl4eXtxVpYaN7tJr36wgBlUq5IIDta4cEJDzcVh9lnhW7jJvZvym7P
zFRgFdD3hemPtM2oPYGDXnh1UivlhFJBZfBaTUdMeFD0PL2kmWAdJCFfLCxXwgJ7DGhpu/NbygaV
kc8uGhTEGj4+5YKw11vr4f48dqmOo54c3EaMNPmVaxQLGysFFrUvlKX1k69OHRwop+3HCxXYd8KI
Fsrl5COStAjOilzNApgmQoOvwj98ayLEN7ZFdG/DQ7Dy/hGS7muWAuftG6LM5X5S9Ywxq4A23OVi
zEry9kYJi5RtlQi/lg/0t9eau3xgWVEir7JBmKhvhzHjetglXr4ruryZcgtQgVVA3ynTH2nHG7Q8
ncCB6PI2ygnC5U1GTOgvRka9pFcAe9uOLi/XY0ArWxUuHoR55OZdLggnMyVLqaDSFqn4/Y8JL3KX
t1Vc3jAGNlV2cnmrJ159cYgysOIXGIRxy/Uer+JycZm8fhKscqRg3Zuw36vUIUjFYVTZOq27mZAU
tWsw1lwxwF7s+RMxSfE3Pq8yWQywv3bhTEdpYNhNKyRcC+st+a27sF34tc/fsTgYknRumqip/cLC
upV9IywJUm+vrSMSr/7OxbtWSIraMVrQKBOsfCf8l4jDPTEbuogTys66xFaRRW/pJva/C/u9WKs/
otKsiVdeRqT4fH0Bx9dvXvivrPTAhQtP8jjl37xyNyn66OPebxz/BjPivyvsr3Li5PFhYb1wq+Xp
sMd9X7yesg+3S7108k46pMQceo5V6gcuh6dD4rWwCZLXDxf2VOVn9dzMRp6SL80SI+Q9rob1Kz3r
ciKkRm1oziPYPipfhK/4js8BiJIL7N2iWxsOtXpR8K4tpnsbHoJV7ZtwyLvEAUgTw2ssLx1+ZS7f
M7TKVXmAveizx5nLV1QN5QPszU9emCdJD4bd4C4fLT174cIIUYbef8Uwl59/mcknld0VNs9ryL+x
6el3Tz4i3yGqvSVcvvMRQaNMsPIZdyyBuXxjV5FkmRkXkzDNmK3dxf43YRsCWvzGXH71VbzJeC8X
Lj8eKPU4fyGUxwl64zK6/NiTPnOOf4trKmaFXRkszq1xLIzVYd/VYeuLdNx919oad0pNPcFdfngK
y3MP2eWPSpbVF/4Rw5SdNgmXvyZuu92uhg0oNfNSgjU1amMLka6HPwlWORL0GYAXcTECZExZj2W1
LxV/nguuCFgVX4UBkAawb4lVng203i+NYIFogzJmA6cgVlJj4jHwD97AGA7w7CY8E0+F//iSrRqH
sVbGxbK6+Bq/cTrDyvcjPJQYj2fE92P5r7wZ9xNi8IS7k3l5tsG+UMQT5g/gXYvk+yfbAIgLYrOB
fAy77l7cZ5d842c4grWt6EU4I98jsbCsEndIgOnvYoTjklTiJ/yOj0E+wrcItgHpuIE2mc0G3gxm
V3wSf0ipsWzG9K9abP9BgKnr5EJdqclCbNY3FSbynZA78DMvnu0QYvWo6pC2XYxsNz0Eq1A++TsP
YKVyxdHst4mSpSy4LGAVsJKpgCEHlqTz2cBUVj/Qn9yeYLOB4sbwHHomNYaps5Et9Ai8BF+9ZgUr
c0+K6KlVP2Rz+RyuiTOsfBZi5MR4PCWer/qoxFzKXR7/LM/gJjjw1G3Z5e9bJJ8NeBwtvoI0QJ4N
rL0H95nL3/oJjuGN6QOAR0TZakXDOtzy/Qv2DME0oB26/Ad2Mnf5aqRVP3Ye2rNsNvAWd/FEvOUK
l/9dmyXTF+CltbLLw3iISNxznyaC1QC2dMG92UCfPRDTWJI6JkGYvAC0Ofp0+9OdR6yyovt5y+ot
gDufDLtvynEM4LD6GFJ6SlUHPpUCOwcPrCwVOQgXWQN9QBLEv9W5bKXRBwBW+WPAMEiPhMPPdun5
1h2Aucy1P4B1bfcKpRq8GgHpfEjfGVY4GnFr2j1Vuy7Hjine5fy+BzgyoV7Je9+OhtSHWQqbIS4p
bcWw9qMQGNENJUuHgasgbc6AB4tIg8QCjBJ/A+x9ptvwj+7AXTjAYHUOTsqwmszYKknt42CvNW3P
j7MlCYdu9gyoWrJm6EVevysNeCwe9g0dVEvy2gnXgjHuA3ch6f0ugeUf+gdgC+ta9rNCBPw3pWv3
1/EX/gEGZNgbkNaE741Ig/el8oNenfd0n/K2w59D9L22Hbc2PAMrn51wB7vl7RPhWjWRjSa4EmDH
M50fXpmOHl7OwuYi/j8dft+U/RiQjJJhZAyvMmBSMuweMihEmg3wOIv3YCIkvI0uH7Ufb1DY0A08
D5Fwe+GDHZ5ERB0sxaJ8B9b16PL6L98CawcW4AyraQARL9ev2mVZKlxA4Pl9C3B0Qv2SDd+MgrRR
7ISNEJeYvnJ4+5EIjJhGkqX9wJWQ/kZ/dHl/K1+AUWIr3kif6Tbswxh0+SGE1XxI54tqsK8fCWsx
Cd8tcD4Mzv76NcIIQbtnYNUSIZPOA4yTpIr9J9yF/cPQ5ZbtcJ3dfXregeT5XQPLD98NsI11Lfsw
lx+f2r37bLxNfoQBHjezweqa/IPMnZBt4vlMvR/yZaQ4cxnAJ6yWWZ7GWw6DVa3rENmXHauKt7QM
WElSjST4loXLsCp7ApImsH2pCrZtWC9hGDJ0HR8lmJQGO3G0KOgGbGUUk6RJVpjKvp1gVTcKYtkS
LsmyFGCsJA1OhwOi9fJQIpxgP/zNeNN7msUotg2AX246pHZnATKscDxjIyJKknrdwoYBbqnCCiLG
sK6q7x5llKlXInzOzgqKgV/YtwyrgIOQKpp0QduBt5sQVrCpEosyNgUOYbfEZv7/win8paDNAmto
n2NYemxRjuETTRg4BmAMP+r2h2dg1SoO/sQOmc8+W/Pjc4BFHCxPYfNmOWYvJAyieMM28HdsYdtg
JUnVEmA1y/5sAavS/0GyaEtWQpYjHxBWcLMHi1H7HKSzPlfp6/AXUgztcasYx3OCVe3bENebHbcs
5g4dmA4HRetlWAKcYjfBjehy7oNiW4QLpBchrSc7RYYV4m5TWbbf8ya4hBXAZ5zNvjvhAnef1DNR
3IzLRfHWlwKrYkjoZ1lqUrltogHZJx1vVJVZyCPJcMTe5SzME0awyomKWOueYvFmAL8D4dB1NJwQ
vzgLcoHBaqZtqrDtHQdYKUsXZFjhj/Ebech5UApsxE2E1W1stqGVOQ+nsGfY+VrMJL4vtYiDRWzL
CVazkJQiQoMUhEeRtWAdIPYlbEkNwU3M1E8i5BHs6LGtGZDai30LWJU5DDHN2K4kvZ8FrFIf41Gq
HY6bzzekKhdgK9tSli7IsBqKl8NfNrP7k2CXN29ZxfBGoVT8GFyqLo7xz/LxsE78LhdAwlfY7rp+
HWkFnwg8S+3x52IX241Nz8AK/clpj43Y33gmGkfBKbkBiFxYjmEI/HdE/lrFOsBKWbqA1Ya1rEZj
59lLRMSFyZu9OKxeFwHvALCmcNOwGH41SWoeC0vYISdYvWqTpV4yLJX8fhZddRbzFzHph5ni9w9J
GgnwNjvwMqT1Yd8CVqUOwp3mbFeS3ssCVn+yuRV08KG4hXxDqnQe/mZbytIFuWU1yArbZJd3T4I9
PtiySofY9vycAFz/zLq7njaCVQ4UDTwJN9nNS2p1ByLqsg0cy5nOvtH6cVj5noNwbDwz8/olK1it
gRR+N8aIgWf4zxhhtVLG1164jIkE1AiW70uDksUv1xFWlr2Q2oVdCdtDL370jKVmPBxiXS9mowBY
JdsM6ffxfak1tgfYliOsWqeL2yQeqBnpumV1VCTrVy2EDbKitYiEbezbCVZfQ9pQFoxW+jCE1+Gw
+kUu1Ba40UAc45/1k2EFVm20pZCebv2+bZUqTT7Dtor8Y8X5t9/5Ubc/PAKrsschgrcSWsTC7XtY
XnDhyitynnpxWHmfhhu8MqDLf8oKVt9Dan/5zHKn4Eow7waKZos0ASAUjxW1uRxHCXjb1RFWlt1y
wxhnQqZ+9Kylxl04UlxO82GAj3FzI6R3EyEtABazLUdYNU+3CRt8y3XL6n6RBrqctyKRoxGwnYU5
wepLSOP3bzyCGLyJQiCs1slM/hNu3ivS8egnwSoHcg4B+NzHGy1gp6hb0ipIkWuG1IA3k6vfhh0y
YfDGZd8NdGxZlTwEV+QxEEn6G+605S2r1+RM/AXX+Q8Dux9lmvZ/euEF+X7qCKvKV+GMmIITp/UX
gOI7jXFUBGvMZtuS92YgHl10hNU426IBSTrlGlZy64yl7F2yQa/H3z2C4xNszxFWxXbLY67s0HpI
7MphNY/toa2HyKZii392ToX/id3VrEHFq7fXmwAnxI+vfhTss4vtxqZHYDUQb0Hc5cVwcI/3rlZC
ag85N/ckwHLs70fALgFzSXonC1jhjGKYrZ2xFe62Z7A6IFcWbAXxjj6m7FOmSf/QD85jXWOXcYRV
xctw3r55ioPZtlGhhtijx7bsRrgt3xMaW8U8kCOssImtwFY67hJWcXZX8S5Zv9fEd3GyZzvLkCOs
iu6ESNEdwENrIak7H7NawCKirYXbcrtd7Hvok2CVvZCWNQAnN29F24Q9li3YTvbfBnflm6pU/TLr
Bt4XDz/LLQnpmSxgVeM8nBCdILzuT5CCTsaWlVJfFVi1emtPdGI6/patai2rRpGwr4Rdtp/KSECq
cxf+wXbLZgirJWKow2q63cgQTiO5GrPiN2iWTq1XtkSyyUdIV4NVxRNwSW56SdJysPbjsHpNZMAZ
VkOsytLaVQAXeOsFR3kuKk8HBF+Gi6LhJZ+e6y9PwMryA8Ap4fJryGf0WJEtkCDfSKRqlxisOt2F
XxWXi6ULYoAd1ZJXsItuYLWzcFq5j0mrIbUng9XfciWwwarlm7ujE4TLVWDV8BYcsCmMijxhd7Op
iRMhfgxW17FFy0wdVi/KjzCwGBtcwipMbvFhi/uVzRGyy1VgVeE/uCrGQTC5pWDtz2E1lyWORrAS
Orj/OTAFf2zuDLDXu4En2iwFO/5lj0Ks4qrKZxiscGbrayVrj0IyG0Lis4EZj9uIMas6V+GAEg9H
G+524LCaIgcJWHnNwpEciLt1+MOX7qqNWbWOhb+9bYmwRahslF1Y3QTYhI2VzXAlRASowwrnsQYq
p/ziDCtMD0eL2WygAqtxlzFD8ZGnvnw6TG3Mqvo5OKX8bKUVkIwExgH2mfIFnFpWYwFeF0eW4ggg
5pUbDrywsTbE1nm4VPiwqhNu8zdupLbi3ds4echKqniKwWp4KnzDs4wf4/g6K3VY1boMh5V40o8Q
34nBSn6Qm40vsTuV5VWcQUOXH/l4apzamFXLaNhhr8rz8rQJS7dWPGzFYxvhqnx/UofVbEVhPOUn
J1g1iFZmA22wGnMJM4QuX/70VbUxq6pn4aziO7w/pWDvEWcDX2P5QSNYCR3c/3QbVqG41uiXX7n9
fJIPqhbbAfHKbbZ2BINVjwRQxmikV7NoWZU/Acf9lTLsgjBsn2HLyhFWj6XB3S/HtgzyklreUYNV
nZvwj+1WjWnhAO7zSpItgdf17GCFw8bjlFN2OsMKSeYIq/a3Ie2nJztU8ZaqXFSDVekDcFEZQcEf
za1GWcEKW1ZsVA0NB/6WiC1J+lQMNOP8WDgcVALd+/ZEy+pJ7JYqLj/Bn7Iu+jckyN0sqeYtBqtu
OFOg/F6nZwGroGNwyuZynPevpwKrwSkQv3xcK3S5+gA7qrLPpjDKMsKuMY23o6UYlB2ssGX1qCLo
306wwjmhtXgMly4osGobCek/T+pQxcfFAHupfXCljJLc77xLSLBS9PDAN4dVWO6XLhTZBeldJC9u
0pA0voTyW3luDbPVLJ3BKjgK9ii1aVEWsPLaDleVMSscbT2Oo5jOsCqBk8JyS6lzohqsAs7A2SpC
EN/eox+QWtmNWeGd+hU8lB2scFx3hixpYJiA1XnbOqsVzrD6ChtDouVU+5oarCx/QIR8V5dKHoYL
qLHrllW3NPjKm1/7EatY1MF2VkFCJx547x3YwDfc/vAArHx3QHp3xeWD0uBYWUn6BlL7yHlqnMZg
VT0S9ipds/9lMWbltQ2uKWNWuHDlZOnMsCq+GdLGi8Q7xqu1rIqdgvNytUGX95Kai0F1fspDYs1n
drAaCzBbzn+5K06wGp7iDKtlOIksXF5TtWVlWa9MYeP60QNwCRudBCtZXk98uQurTqlwSOGQFHgR
Uh7g8/0fyHl6ScwGXoS4ZiKk1IEsYIWr/5KVDlivZPgdK4QzrKpHwTG5yT9SdcxK2g6J3cW1aifh
oytV78B/SgZ/EqDJDlZtrbBJ1EXpkVQOqyLHIVL8HIrisL5Dy8r3KETJv7Z2yWpjVtIXkDpClgP5
uh3bG65hFZIEv4qGxj134bA85RTwL9wQcwY4abVSTsrNLw/Aqn0KHFE4JJU7DymIKWwHfijnaAqf
DfQ5B3dbipCS/2YBK8RcymD5zPuT2WqVTN3AKjfhOA47McMn5lXGrKRtkIQ9LWb4lPQKqXIsnFAy
+L14RD07WLVKh61yQ3AULn3DUYy3cMm5SHOhWJKT0bLyPgQxIeJY62S1AXZpsbLMCtdKJ/DVKgQr
IZhHPt2F1ScA72Vk4Gu+FKBzHFyozgNLnRXrrObb6jJWN6fZwO9YTHmd1UNW+FVGEU7dMyg4wyok
HvaKpkcArp1RW2f1OGB95fYawCjJ/zvbcHmtG7waZtuywsUYib15CqX+EeusfHDWCwfQ0B7HYV4H
WPmdhRuV+SHLErC1rPhbF+R1Vg+mwZ/yiPFHfNljFrAKOA17BaK8/4D0CTxdCVsvvwl49gCYI8Lc
/fQArLAQ72dcHlsZS3A8/Q5cCuaBJU6JdVbvgTKvOczqCKtE8dYFHCZ6HM/Ao+vlJUlLwDqULwp1
HLOqHgP7RaUo9ofcN3acDZQexccdRI5mslWqRXByYpzYDwmHI4G4mR2syv0HSX35KSV2i3VWyNyv
eEDV886w8jkFN8Wty7II5DGraPHWBXmdVZ9U+FeeC/1AjJkSrIRDPPLJYXU1193ACmfgTruMDDyI
g/RYNz4D+D0YQ8tjrWHdQCnkMsQ/xe6Ofa44rmCvGQP/lML3Lciw8vsN0hYwL3uPT4I/WRPDGVal
j0MSvxPXYnP7X2AM50WhJbHt9iqe6j0kDi4GS1LrOLjei/3Wg3AS6wl2QnYtK7ag8UI3f8kn5Ee8
BpsNZE+KbcCpIL++ERjiACvLT2CdylINwjsw7GRbFfEXUh4LJcPK60dIX8Tu9F4Px8NhtuG6ZeW1
CuJrsTRQqhS4NRR/xt49LsDdNiJsOlh7ii13P/MOq6BTbIGBzTBB9j8jeNPaEIKBQStRheW4UeMS
JDzNXN4Z5x/sV7DXiIF9ZVCd2QJWvusgbSFzudfYRPi3mAqsSu2BZIQY1iJ8ikYsNXGCVfF9kDyT
uXxQLLBnLXHFX3hv5vJArCRPsVOzg5U0DeBiD3R5MKtWrGXVJRUie/lIlhq4kti5G4gVaRpLNXAB
HtvDtspfh6MVsFAyrLy+B+sSdtOxDI+Ho2yDYMVk8pC5CStcZLWd1QrZKl6E9PE4DhyG74374PHX
DsCp8xxW0gs4r7/+1cc/j4XtyfYtKxyZsv7zdUsFVlKHOFz+MHPko9+mQBzvzDnDij1yFvv+I48t
joCtN+HC5KaZYCUNScCXQM6e+l0qJD/M8oXojF0aOvJFXBOzjS9qyBZWxRBS8Zs+/TESjuKiHwYr
bMzDicXv/m5NXm11hJU0JAlSPh8z7t0LsO8kxEzrjMMUeHPet+J+BVZSC5y/3D575LivkiBxFMuR
a1hJjylj6bw3nbp21tRvYgDms7PQ1sJ50R8Uu2585h1WAwF2yT0mdv3yF8D6KIIE70JnPnh89n44
fY7DSnoW15b8NuPxJbhsMtkeVmVwTH7v190UWEnt7qBfZo2c8E0K3B2GCWbqBuJqF4id/8hjn92C
beFw6Zlmzuus8JGqeKw2r03FWpPCBUZ03ln29MgXD6LwvKGaLayKIqQSNn36QwQcPcdh5bcTr/rT
28uuw89XnWE1EF8C8gW6HCvHCYidcR8uVd4BsH9lLwVWUjOcv9yBLl+eCEmjmUwEK6aChwyfbgHI
dcvKe7N855JzYVmJlQZbA52wL8DsUKeDYpjYdxb+2tHS3ke8sWn4zwFYT8uCXTX28yxyGiKw5YJT
3tdZAFrYSLbLZq+V1fD7IK4BPs/Hbq9o8R+W/AK/ZknS75Bcn8dVPsbKU+thT/KQEkuT+RnY3BO/
9N0QJbdecHrwOxYHCdiPfSMa+ThrwAsiG9vrb4c9DHBeuE6CWfTTDwCwn1QnpZcgeb+dyA+lfxuE
yxr4hP1j2FfEEQ+vQ3AH7/P4rC7+krndwJ81Gv7e3+AbkrQVklvIm/yrfqTysJDk9wpiiln8fGxw
MAu4IF4CLfbc+swzrLyx9z3Z7tIW7Pr/hS2ojsggZkc67RfP/vm+igRhtmAwlwwVW83Os8xkgc+x
QaGneTpDcbEWt2uPsP2gm7AXW0nMxooJkSLfiOPxH5dajFuvSfjcVOq9PIbyMVquNtcm8ZDiXygu
3yD6azsguo6Ii9ODP7AtrHj92TdmjvesA6aIJHY22Ab/MsC1kAu0vsJ12IT7+AxobGV2BtaGN0Vt
tn5XHpdJ8GJNSMON6ZLlAMTVZlH6nhN5hpsT2a7UX37KBzc3QUpLHubZj4nsgjtl5TybtNZSE7DC
LlyuzG986FMOXcfGoaGPsDZ9lZm7b4X9NbWCNCyUN5CwWb38bOTZlb2laqGTWHehc+gkXo18hn+w
8oM6kvdDoWPEL7LO7B3hsZc2T5dxUjs0FBtP3AaFjmeNHJ9H1py8susd7HxWePuP77Eh0zv00dJy
FPmr7vQ/ju5a+VKwEtrrixNRkceXP8R6JWgDQsfK469BoSJ7LUOfqs6O1AwNldFRa+TsD2cMKC79
B5u82RGpw4It+9a920SqHhrKAFTx8dAuLJjZ/SuPXN336QMWKeCFX39hJLMMmr9iYXPJMjh0HG/K
4RrCv67FXtk2ox6PLwWHhrYSW1K/0EcdRLf8AgfFORih5fv7wsP2Legkx5W6JeEgXN4sz7DyGxca
qiyp4llpJLu88oxdN6/9/WJFaaji8s7M5d8Mkqo+NQklq/ikHO4zbMHKD5pIrUJDG4qy1J7FXf4y
/5VL/o+EDhSSS3VDQ7EZhS4f/dMJ2eVv/f5DF3zAPPQxnIK0tzrTfj+6e+W0YCXsgc+PR0We+HpE
ERHQP3Qcb2Hhk8WhoT1YWIvQp/i8SEhoqIyOmiNmfzgTXX4UtviwGFWf//nfv5YM95HGhvbBXa+B
oeNY1ebWY8WRq/sXocuLPf/rrw9hkGXg+ys+xLozOHS8qFtVpnOXz7xHnFAjNLS12JL6hD7m8JuR
g/P6RbByX8ESFcrbXMtT8SpXsZxcCR1TdQ4sXr5SoNyUcIyo7PmVDSoutotiK07VipYuYZ+spWzF
isqrPlXjuwosdU155hnbNSXlmp8psndp/i5JDC+iRLG/OosfUL5SkKMemVIRAf3Sk3tlHCpZvrzM
VQzz+gAO20CWESdXW3mGVRZXy1+XyyX3d+VyfyeXl6lYsaxXFrl1dajkFeWZZ8mvpEuXoctl+uXd
5a5ykrtwE8EKF95hN9DhJp87rQwUu8SUd5+Vi3N/AutoFqQV+UuZzMx01ZoReW5YSfkJq0wZ1k9A
8efffU7ObY+7ykME+sk+yynBSl/+8lBu/f+CRNFN818PyUov1EOJZ5tMj4S7juMxtjPmwt9Ztjht
EbPYIFipilNkKySJGdcivwJ7Zkx/ZjZYXaGWFa+kL+Gz2QOqlKvYdo0VltpNdhZMDZ4PS1W7L1Uv
pnbNcw4IVuoS4nT1qUHo8jY/WeFLVfnVz9NOKMFKO74oyJwUXYJ94lsnruLn7w6DyQWSicCTieIm
73S11+GLvP+KCFZOqsq77B9lZZdvLHiXq+cpd6FmghW+4Q2oZSXXj2IvHGZLFZKOz5ZHUXNXb/IY
e/CRKSopFP9tG5tGzaMRrFwIWPT5Q8LlrzlNLbuIr7lggpXmXFJQGSrRfsDowfexpRKFYMXUJqG8
SygzjXnJEcHKpXrFucudlkS4jK25AwQrzbmEMpQ3BQhWedNPu2ebCFZDqBuo3XrowZwRrDwopqaS
Ilhpyh2UmbwrQLDKu4baTMFssLpMSxe0WRE9lyuClee01FZKBCtt+YNyk2cFCFZ5llCjCRCsNOoY
ypa7ChCs3FVO6+cRrLTuIcqfgwKtKzjsquwQrFRE0W6QpV6O319GsNKuGylnKgpsvvhOZ/56E5Vj
Iohg5VIaTR5YeH1eV/nNRtnkz0SwGsqWLtAAezYVQuuH/8Q39f07RX7NnGpmCVaqsmg2cAFA4oGX
G+TgAVWzweoSzQZqttbmKGMIK7TbP491ufSeYJUjITUTCWGFdmfdxGx/mgQrzTiNMpITBQSs8OXn
F9/vrP6CW4JVTnTUThwBK+TV1f91zfr9QCaC1TDWDaSWlXZqqVs52YROlC1150shKi9pIFi5JWyh
nWSDFf5/wZ6ZdbMYkCRYFZqT6MLuKGAHK2RWzIoh5ZxTIVg5K6LtfTtYoUfjvn/Y5evbzQari5nq
trY9SblzUsARVli7T3/Q1vENDgQrJ8k0vusIK/Touc86ZbyV3z7zBCt7NWhb8wpkghV2HnbOqGuX
b4KVnRg62MwEK+TVv3ObqOTcbLC6UBivmlPRnYLcVAD/xlHFIlcPsi0WJVi5KW0hnaYGK/z7ynUP
if9DtMuV2WB1rWvTZs2aNRXWpEmTxsIaNWp0r7CG3Bqg1ed2j7B6aHW51RFWG60Wt5rCQkJCgoXV
EFa9evVqwqoKq1KlSmVhlbhVRKvArbywoKCgQGHlhJUtW7ZMVlY6k5XK2kpmaSWytOJZWkCWVixL
K5ql+TvYVhVU8aDjH7UVr+7jsDpFNyW7X7mmN9935dGzS7oVdci52WBlTUl2bUk5tcQcWkIuLN4N
i4uNjY1Bi+YWJez27duRwiKE3RJ28+atmze4hQu7fv36NWFhwq5evXpF2GVul9Aucrsg7Lywc+fO
nRV2httptFPcTgo7ceLEcWH/CTt27NhRYUe4HRZ26NChg8IOCNu/f/8+Yf8K27t37z/C9nDbJf+F
s1oFT942iXUH8Q+lcSHW/LlvkOlAgblz/lHzpQhL/fe5Rna4MhGshqe6VoWOGEOBaz8OKMf+4Z7M
KArcWj+qosIrE8Hq4TSjOJDKkYUC525ncZAO6VCBG4trCVyZCFbUstJhRc11lk9+fC3X59AJWlbg
/PJexc0HK9aysibg0FCORpJyNCyVk0Eu12Nk9kdScmKpObC0bC09B2bNkWmtjkevGBQovaa1XFF+
3Ffg7tpRGW+QMVPLisHqSrPgkBB5/k5M5tXCaT15hk9M97GJPzEFKOYD6+PMoJgjbCjPGOLcoTyL
iPOJaPLkIk4zNhfWQljLli1bCWstrE2bNm2FtePWHq2DsI7cOqF1FnYfty5oXbl1E9a9e7duPbj1
FHb//fc/IKwXt95ofbj1FdavX78HhfUXNmDAgIHCBnEbjDaE21Bhw4YNGy7sIWEPP/zwCGEjhY0a
NWq0sEeEjRkzZqywccLGjx8/Qdij3B5Dm8jtcWFPPPHEk8ImCXvqqadChT3NbTLaM9yeFfbcc889
/+wZlxU/ZfvUYPbofi8WI+63NT+T6UGBNWddetS6b8493sqAFX6bDVYXdPr/jnYuM/emyqJQVtnT
zr7XTn6uWSxdKGFumXRU+nkuYHV1cTen9SemgxU9bqOjeqyS1S1qVTv6x0cy6rVYFKrbf/JUKbOx
g1QXhcZvDLVNAtqKbyJYPcS6gRcIVjbf63Ij86LQuB2T5dkiUSBawa4vx2aGVfKBWQ18VQphNlid
J1ip1AIdBTnBynp2bjun18QQrHTkTsyqM6yuLeih/qIyM41Z8ZYVwUpfNTlTbh1gdX314IzunxKV
YKUooY9vB1hF//5oeZfZppaVS2nogBYVyIDV3d1P1lPLIcFKTRXthmXAKunIS02yyifBKit16Jjm
FFBgdeLDjk7dPyWrBCtFCX18K7C68uWD4kl0l9kmWLmUhg5oUQEOq7Bv+rl8naREsNKi31znicPq
9ga7xZ+u4poIVvzZQBqzclUTdBK+E5I3PhaSVWYJVlmpo71jH4F139SmOckXwSonKlEczSjw2YIW
LuaKlCwSrBQl9PH94rdd5Wf/ssuv2WB1jpYuZFcltH08G1Jh5glW2vagc+4cX7DnfNR+n2BlrwZt
G0ABgpUBnKhaBBPBagRbwU4tK9VqYKRAgpWRvGlfFrPB6iw9M2bvfiNuE6yM6FVWJoKVUT1r2nIR
rIzqeoKVUT1r2nIRrIzqeoKVUT1r2nIRrIzqeoKVUT1r2nIRrIzqehPBaiSbDaQBdqPWZFu5CFY2
KQy2QbAymEOpOAQro9YBs8HqDC1dMGpVVspFsFKUMNo3wcpoHjV9eQhWRq0CZoJVOo5ZUcvKqDXZ
Vi6ClU0Kg20QrAzmUCoOwcqodYBgZVTPmrZcBCujut5EsBpF3UCj1mKHchGsHOQw0I7ZYHWaZgMN
VHtVi0KwUpXFAIEEKwM4kYpgrwDByl4NI20TrIzkTSoLKkCwMmo1IFgZ1bOmLRfByqiuJ1gZ1bOm
LRfByqiuJ1gZ1bOmLRfByqiuNxGsRrOlCzQbaNSabCsXwcomhcE2zAarU2UM5kAqjrMCBCtnRYyy
T7AyiiepHLICBCujVgUTweoR1g2klpVRa7KtXAQrmxQG2zAbrE5SN9BgNThTcQhWmSQxSADByiCO
pGIoChCsFCWM9k2wMppHTV8egpVRqwDByqieNW25CFZGdT3ByqieNW25CFZGdT3ByqieNW25CFZG
db2JYDWGLV2g2UCj1mRbuQhWNikMtmE2WJ2gpQsGq8GZikOwyiSJQQIIVgZxJBVDUYBgpShhtG+C
ldE8avryEKyMWgUIVkb1rGnLRbAyqusJVkb17P/bObvQnOI4js/GyDMM0zIvSYqWC3cyF3JBkSQX
XEjmpbGSS1Yu1LwlbpSN5MKNcqG4oKaVC3s0Icw7sSJqyY1MybTHztb/bOecds4uduo539/nuTlv
T9v5fr4/n855njNmcyEr1eqRlWqzZnMhK9XqDclqV//Aowt8G6g6yX4uZOWjEFuxJqvXPLogNsGR
OMgqgkRkB7ISKZIYjgCyciTUloZkVe/dBnJlpTbBkTzIKoJEZIc5WVWKFEeM0Qggq9HIZH0/ssp6
g5x/iACyCgGR2URWMlUSZIgAslKdBGuyesVtoOoou1zIypFQWyIrtUbN50FWqiOArFSbNZsLWalW
b0hWu71HF7gNVJ1kPxey8lGIrViT1Us+sxKb4EgcZBVBIrIDWYkUSQxHAFk5EmpLZKXWqPk8yEp1
BJCVarNmcyEr1eqRlWqzZnMhK9XqkZVqs2ZzISvV6g3Jao/36MILvg1UHWWXC1k5EmpLZKXWqPk8
yEp1BJCVarNmcyEr1eqRlWqzZnMhK9XqkZVqs2ZzISvV6pGVarNmcyEr1eoNyWrvwJeBfBuoOsjD
uZDVMAutNWuy6pqh1R9pIgSQVQSJyA5kJVIkMRwBZOVIqC2RlVqj5vMgK9URMCSrfd5nVtwGqk6y
nwtZ+SjEVpCVWKHEQVaqM4CsVJs1mwtZqVaPrFSbNZsLWalWb01Wz3l0QXWUXS5k5UioLZGVWqPm
8yAr1REwJKvBqFxZqU6ynwtZ+SjEVqzJ6hm3gWITHImDrCJIRHYgK5EiieEIICtHQm2JrNQaNZ8H
WamOALJSbdZsLmSlWj2yUm3WbC5kpVo9slJt1mwuZKVavSFZNXh/yMy3gaqT7OdCVj4KsRVrsnrK
owtiExyJg6wiSER2ICuRIonhCCArR0JtaUhW+73bQK6s1CY4kgdZRZCI7EBWIkUSwxFAVo6E2tKQ
rAY/YH86Ta1B8oQIbPCuoN/PDO1lM/sEBv+v347yIgiSq0j3lTvkDfHzmlR+y5QiAJjBU5iUQhm5
zV7P79LpOXC+pRkknvopTwwgGteN3EGv2c6qcf2hwR9WNhY+uYYb9x+k++r46EXtfZhP49fcu7px
LDF5z0gCK87fTaGLji6v51+p1Bw43fztY/NHxmG9pGTZ2bYAo3HdGPoX/LMzvWrzd04uTqxxbrs3
YJl+/TlTDJeniaSL6A07v2e6cO/k364uIp5FcCpbv2a+0u51CRzLb2Y+40CAIwkpORwgUNcrUPqH
BYFMxjfqfghU+mVpfIvr+wRCFj5zUxBfc+DopGsKnRcOB0LZ3ii7LlHp6QmxNTZLhCwkXUDGMrB2
sKZHovS2qdaKGz1vdbdEpY/jHxholQhZ2D56jxwJE1j0V6L0R5XhYHa3FyrcBRYK3bNiKzwqMbf9
a2JDcjBAoPqzROm3JgdSmd6oeidRaT4X2+Lq3wop38yJDcnBAIGyiwqdFw4EQtneKL0sUWlTQouX
BFL21SeE5HCAQO03gdI7428ZAoH1N2o/CVTaNS+hqIormf8eu6cxISOHQwTWvsr6aP9rXxLKZHxz
5ZOsV9qfX57c4aqm860Zfp1rZGyTSw69Y/aOUxmuvPVC8yaeAw5VOn3biZYMd9pyfEv8B1ahuGxC
AAIQgAAEIAABCEAAAhCAAAQgAAEIQAACEIAABCAAAQhAAAIQgAAEIAABCEAAAhCAAAQgAAEIQAAC
EIAABCAAAQhAwCaB/1idHOQKZW5kc3RyZWFtCmVuZG9iagozNyAwIG9iago3NjY1MgplbmRvYmoK
MzggMCBvYmoKPDwgL0xlbmd0aCAzOSAwIFIgL04gMyAvQWx0ZXJuYXRlIC9EZXZpY2VSR0IgL0Zp
bHRlciAvRmxhdGVEZWNvZGUgPj4Kc3RyZWFtCngBhVXfb9tUFD6Jb1KkFj8gWEeHisWvVVNbuRsa
rcYGSZOl7UoWpenYKiTkOjeJqRsH2+m2qk97gTcG/AFA2QMPSDwhDQZie9n2wLRJU4cqqklIe+jE
DyEm7QVV4bt2YidTxFz1+ss53znnO+de20Q9X2m1mhlViJarrp3PJJWTpxaUnk2K0rPUSwPUq+lO
LZHLzRIuwRX3zuvhHYoIy+2R7v5O9iO/eovc0YkiT8BuFR19GfgMUczUa7ZLFL8H+/hptwbc8xzw
0zYEAqsCl32cEnjRxyc9TiE/CY7QKusVrQi8Bjy82GYvt2FfAxjIk+FVbhu6ImaRs62SYXLP4S+P
cbcx/w8um3X07F2DWPucpbljuA+J3iv2VL6JP9e19BzwS7Bfr7lJYX8F+I/60nwCeB9R9KmSfXTe
50dfX60U3gbeBXvRcKcLTftqdTF7HBix0fUl65jIIzjXdWcSs6QXgO9W+LTYY+iRqMhTaeBh4MFK
faqZX5pxVuaE3cuzWpnMAiOPZL+nzeSAB4A/tK28qAXN0jo3M6IW8ktXa26uqUHarppZUQv9Mpk7
Xo/IKW27lcKUH8sOunahGcsWSsbR6SZ/rWZ6ZxHa2AW7nhfakJ/d0ux0Bhh52D+8Oi/mBhzbXdRS
YrajwEfoREQjThYtYtWpSjukUJ4ylMS9RjY8JTLIhIXDy2ExIk/SEmzdeTmP48eEjLIXvS2iUaU7
x69wv8mxWD9T2QH8H2Kz7DAbZxOksDfYm+wIS8E6wQ4FCnJtOhUq030o9fO8T3VUFjpOUPL8QH0o
iFHO2e8a+s2P/oaasEsr9CNP0DE0W+0TIAcTaHU30j6na2s/7A48yga7+M7tvmtrdPxx843di23H
NrBuxrbC+NivsS38bVICO2B6ipahyvB2wgl4Ix09XAHTJQ3rb+BZ0NpS2rGjper5gdAjJsE/yD7M
0rnh0Kr+ov6pbqhfqBfU3ztqhBk7piR9Kn0r/Sh9J30v/UyKdFm6Iv0kXZW+kS4FObvvvZ8l2Huv
X2ET3YpdaNVrnzUnU07Ke+QX5ZT8vPyyPBuwFLlfHpOn5L3w7An2zQz9Hb0YdAqzak21ey3xBBg0
DyUGnQbXxlTFhKt0Flnbn5OmUjbIxtj0I6d2XJzllop4Op6KJ0iJ74tPxMfiMwK3nrz4XvgmsKYD
9f6TEzA6OuBtLEwlyDPinTpxVkX0CnSb0M1dfgbfDqJJq3bWNsoVV9mvqq8pCXzKuDJd1UeHFc00
Fc/lKDZ3uL3Ci6MkvoMijuhB3vu+RXbdDG3uW0SH/8I761ZoW6gTfe0Q9b8a2obwTnzmM6KLB/W6
veLno0jkBpFTOrDf+x3pS+LddLfReID3Vc8nRDsfNxr/rjcaO18i/xbRZfM/WQBxeAplbmRzdHJl
YW0KZW5kb2JqCjM5IDAgb2JqCjEwNDcKZW5kb2JqCjM1IDAgb2JqClsgL0lDQ0Jhc2VkIDM4IDAg
UiBdCmVuZG9iago0MSAwIG9iago8PCAvTGVuZ3RoIDQyIDAgUiAvRmlsdGVyIC9GbGF0ZURlY29k
ZSA+PgpzdHJlYW0KeAGlV2tP1EAU/T6/4srLLrhl2k63bIwPXkZZMSFp4gdADQgxRkyQ3+T/9M50
zpnuboEEWUJnZ+7j3HMfU27lRG6lmuhvbvWnlKaY5lP9kdpZ+XMln+W3bO/fFXJ5J0X43F16hbqp
O7kbaepuabj3i3swXMmvnhv/7Ydcb3rLpbdsw0ct36oL/6WQHZvbwrlGamvzHdeU5vJG9lopO9nw
GOvf9ka227ZSjfZasr8jaX/KYatxAfWTbDdKRzGtK0ku6uji2ZyLp8MvvQ9PeXJRdi5OJTudjWRs
cyfZ2dlIbF5Kdh6fX0YmfN8KEoVkb/yBPtf8UzVW49NRotqALBdvO/sma6JZaO/BMbXdOGxVknHr
GELQ2hoZhasgvkL2Y1go7gssJmFRa0hZRLiPI9oDUsNoiGcWhDU+oqCLKl86A7D1AEydrsA7DULk
G1CASMYLbj505g2phSrp5ILgoJuwTWPUUcRkJ8Gs8gpz60sY+3bPpT3qSjt1SWG1igpXi2smj3dJ
qq+XiHkTGF57dJpAputVYE4TyJAGCmHba/UiSDVHmiObJiu8rNpbTtaA4XdRmM4/AfGqr38tgwoM
gz1yNQui/UpRK0Pscca4uryfPZc3YSL+16S510Nv0sw7emzemOFxCUeyOC5782beUWnC7NSpw9w/
J+1MFlhGxtkku4FtrZxqF0OAZ9SmPR4xnzyCB3ZbjTziZDHjmHQVG4fGDnz9aAl0qiZbaD5FywLl
ggVEKxGKSvNsA0ECFE+oxRiXw38RQtKGiTImzSUKv/fQdWLR3jF4iENbstRm/TD8CNaQlwGRayID
c+jJChuRDOO9D7VMGjilCy2zVGd2/kIzei1raZFJOCIUByIxfllQFInUBFDdNbN41GMLRZIGb4Wa
hSeMEDJMyiDBDS5WQhI0LYuuTTZDfmiPC151tMMFkwnAa3GwUZmFWbmKm9QnIBbOQaz5KGtSJTwh
rB6j2l6+tDR2lgvaiWiI7yKQoWOeN8t30BNfAHppZAysULXzcNnFt8Gu7Mzw22C650gygdIlaeuq
o4fqKPJ4GBtxhgAY5ENvHkV8PwPnVCIEx27r9THFFgk02SKBvdTQJrxxgwsGPA5Z1NnDyOkTeaWs
4+xluZNKgDZD9wUTST00PJ2BXr4PHnrGtLquejwPFQGv63rS5FO96OLs0f9U/Ecf5WSa28bqa7uz
pruvUy1cx3QSGScPuVKMyfHJP/NrXLgKZW5kc3RyZWFtCmVuZG9iago0MiAwIG9iago5MjMKZW5k
b2JqCjQwIDAgb2JqCjw8IC9UeXBlIC9QYWdlIC9QYXJlbnQgMyAwIFIgL1Jlc291cmNlcyA0MyAw
IFIgL0NvbnRlbnRzIDQxIDAgUiAvTWVkaWFCb3gKWzAgMCA3OTIgNjEyXSA+PgplbmRvYmoKNDMg
MCBvYmoKPDwgL1Byb2NTZXQgWyAvUERGIC9UZXh0IF0gL0NvbG9yU3BhY2UgPDwgL0NzMSA3IDAg
UiAvQ3MyIDggMCBSID4+IC9Gb250IDw8Ci9UVDUgMjEgMCBSIC9UVDIgMTAgMCBSIC9UVDMgMTkg
MCBSID4+ID4+CmVuZG9iagozIDAgb2JqCjw8IC9UeXBlIC9QYWdlcyAvTWVkaWFCb3ggWzAgMCA3
OTIgNjEyXSAvQ291bnQgNCAvS2lkcyBbIDIgMCBSIDE1IDAgUiAyOSAwIFIKNDAgMCBSIF0gPj4K
ZW5kb2JqCjQ0IDAgb2JqCjw8IC9UeXBlIC9DYXRhbG9nIC9QYWdlcyAzIDAgUiAvVmVyc2lvbiAv
MS40ID4+CmVuZG9iagoxOSAwIG9iago8PCAvVHlwZSAvRm9udCAvU3VidHlwZSAvVHJ1ZVR5cGUg
L0Jhc2VGb250IC9HV0ZJSVkrQXJpYWxNVCAvRm9udERlc2NyaXB0b3IKNDUgMCBSIC9FbmNvZGlu
ZyAvTWFjUm9tYW5FbmNvZGluZyAvRmlyc3RDaGFyIDE2NSAvTGFzdENoYXIgMTY1IC9XaWR0aHMg
WwozNTAgXSA+PgplbmRvYmoKNDUgMCBvYmoKPDwgL1R5cGUgL0ZvbnREZXNjcmlwdG9yIC9Gb250
TmFtZSAvR1dGSUlZK0FyaWFsTVQgL0ZsYWdzIDMyIC9Gb250QkJveCBbLTY2NSAtMzI1IDIwMDAg
MTAwNl0KL0l0YWxpY0FuZ2xlIDAgL0FzY2VudCA5MDUgL0Rlc2NlbnQgLTIxMiAvQ2FwSGVpZ2h0
IDcxNiAvU3RlbVYgOTUgL0xlYWRpbmcKMzMgL1hIZWlnaHQgNTE5IC9TdGVtSCA4NCAvQXZnV2lk
dGggNDQxIC9NYXhXaWR0aCAyMDAwIC9Gb250RmlsZTIgNDYgMCBSID4+CmVuZG9iago0NiAwIG9i
ago8PCAvTGVuZ3RoIDQ3IDAgUiAvTGVuZ3RoMSA2ODU2IC9GaWx0ZXIgL0ZsYXRlRGVjb2RlID4+
CnN0cmVhbQp4AYVZCXgUVbY+997qJRvpBMjaSVenSSPpxEAAAwSTztIBJiJbkG4mmA4hkiBINIC4
QTOKQLM5jjKKCy6joI5S6SDTCThEUWdEWZ46Oq7gMk+dbxD0e+q4pd5/qxsEn9+8uvnPOfecc7dT
p27dSi+7ZnkbJVOIBHlbl7R0knFlfwyW07pimRqrp2QRmRuv6Fy4JFYfvBj1qxYuvu6KWD3HCr6i
va1lQaxOP4Bf1A5FrM7GgA9rX7JsZaye/S64dfHS1rg9R6rNS1pWxscnaVevalnSJg2Yyi4QtXNp
1zKjSjkh8As6r2mL+zM/UdKfk6G0ASvL/+f6BDaIiKHC6UuaSPeRBZKNSukyIuWPSh6ZUJd2U2rT
7/p2jmtOnfiVNVcug+ihj4YXSf7CPfPnfLf7x4U2ssquEwx/aUA7S+XApVRro+92f3c9xpQ9nXvx
XmoUF/S4sxzH9osRdALgYkTEk+foFcNFXqTC4Y0KV0/60LLU6hKhon2pQVXQpcBu4ACgULPIh9UG
uhoIAbuBA8AxwEwEKq0qsBTYAZwAzCJP2COqw1Y9XGSjbTbWmyoy6RSgA4IcoKXANKAZ2ArsAMyG
n9QsBVYDB4DTgJm8IjNy+2jMPTOy0WA9ixaXGdWWWLVpnlHtmROI8akzYrxuSsxtQsxt1JiY+sKa
GB9eHOPphWUhdN6TmFLWX50hMrDIDEy8E5Tx5ymVMXLQA2IoaQAXmKqh8Yr0nmHush0HhEJMcMFo
ATn0fsEiKWll1Ylc56conRz8c34yZuEnewalle2o/hX/kHYDBwDBP0T5gH9Aq/kJGXPQKmAHcAA4
CpwCzPwEynGU9/n7lMrfo1KgCmgGdgAHgFOAhb8HauPvyvwwqJSrAM7fBbXxd7Csd0BT+duQ3uZv
6/38tUj5+LJeQ/CUxgVHYVzIzI0L6RllUf5q5NsRyCg37jQyap8ooEoaLQoihaMcUZEVmdjhiPKP
elSP44Hqkfx10gCOmbyOkV8nFZgOBIFOwAzpDUhvUAi4DXgA0ABkGagNUPkh4BXgDRoJeIHpgJUf
i2CYKD8acdc4qjP4Ef4XykTED/O/GvwV/qLBX+YvGPwl8HzYD/EXI/kOqk6CndDGBm4DL4XdxJ/t
GZbu0KvT+AFE0AFaClQB04BmYCtg5gd4QWSBIx2d7KNDeIYdPEKfGfxReshK3kUOr7sWCahK4p5w
MSSQHeoON/e6t92NqiTuLbdDksR9yyZIkrivXwNJEvfiFZAkcS9YBEkS99xmSJK4pzVCAony+/80
bLijfNqVTK1O5dciStciStciSteSwq+Vhb5V5BzviRQVIWLbvZ4RRY5QHwvtZ6GZLPQQC7Wx0CoW
WsNCE1nochbysJCdhfJZyMtC+9g4hCLEvHvOq473ZrHQIRZ6koW6WMjNQoUsNIyFVFbujXJnZAqe
OjCfwXqq5UPHnT0XV2L3SeVORNSJnHdiTzgAehTQjZoXTmpBzDk7X/KCnqKqWP3CCWVLqyfzg2h4
ELfhIB0HFNygg0ijg+jkILpLBa0CmoF+4BSgA2Z4F2AdWw2aCloKVAHNwGrgFGA2pnMKU+G0FFRO
cbcxsVLQKmCarPGDKAUoTu705tnsNo9tsthqZ6n5bFq+ns/LKSMDe3N6mjUtylL2fpPy729SKKE6
gW/hWykPN+K2ON8a+TbPEWV3Rdz7HNVD2e8pX0HWsfHkZoXg46jLqI8lu1Xqx5CdPwFeFrFfhmap
EXexow+vHbTa6/jW/rHjM3uUQ/zUvs/xphpVWMTxN2ie2Ot43b7B8VJp1ArNfneUgfWphmuvfZzj
yUOG6xoYtkccqyTb67jJPslxpd0wtMUMl3eh5k11zHTPdUxGf3X2+Q5vF/rc66iyX+6YGPMaK9vs
dYzEFDwxsQiTHWE3BnXlGx3OLo+ydm+xZZvFb5lmuchSZim2OC0OS54l1zLEmm61WQdZk62JVqvV
bFWs3ErWIVH9hNcj33pDzMbLz4yEZqQYsg07DJPbDChxZuX0K9IGiwbeMKuGNWj9rdQwX9W+nuWK
ssQZczWTq4Zp6Q3U0FijjfM0RC36TK3c06BZpv/a383YlgC0Gl8fZdTojzJdqtbmaum1/l5iLG3t
5lzJL1i7ORCgrIwVVVlV6ZVp4+vrfoEEDWWwzvPTlfWT6Mny5GnbGmb5tcfzAlqZFPS8QIP2u1lq
k7+XfclO++p62ReSBfy9opJ96Zsp9aKyLhBoiLLLDD9S2RfwQ8aAwc+KF7P0I9WaH/PbHvMrRHv4
DZMMfgkJVGj4FSYkGH4Kk37dXcN8dd3DQOCTqVKX4dOVqZ7rc6gQPoUg8MkI0SHD51BGSPpolUY3
djtc8kHgwnLIbrjYWY7hYsy823ApjbtsOOuywRhJxGZj+EiCblJOnPFJOQGfcwL5n8W2Go+H9VQE
Wpt8bS5f0OVrA4LaxhXtWVpovqp2twakQdWEOzi/tV3yljYt4Gqr01pddWp3hdHuZ+Ymaa5w1XVT
k6/R393kbauLVHgrfK6WukDPpOljys8ba8PZscZM/4WxpsvOxsixJhntfjZWuTRPkmOVy7HK5ViT
vJOMscjI8en+bivVBGpx/yTv4UmJyNdgrjNQk2HrrDSSt8KZtSq3D6eVXZTkCWjJrhotBZB5XVJd
Ui1NeKakaRDUqXFT1qoKZ24f2xU32aBOc9WQZ9nyruWU5euoi/114YJq2XJ5K2LUI3W/eMHFp3lb
6uTZukErmtWgVc2Y6++2WKAN1gWgm3BGl5Tki+r9MeWFUE6QjkKcdZS6iVKXkBB3/L+5YMwJakSn
FweNfT3Mm8+WUVdAaPkNjRxbQeNchKFprr8PZyn5kugKYIFdzMO6zvQm12HIFNMQlt11BsuWx6V4
LJbFueHa5SFP15mQnOnOI4NlECNWyzzY2kx9lA3kmHZStuImfP/onwCfSj7QoX8q7ZLzf2Kji8ZB
tIueZB30JB2g59hptNpNvbSH5BGoju6lG+kOWofX2lxoNtBMFBP0d7BsfQ++TB7EC/NBOgzfObSK
+iiDZemf0WpaK15Dq7WUQgVUTdNpKW1ml+jLqYmOKzdTOV1CV1EnC+l+fYt+u/4HeoR6xV/1HymJ
cqgV5bD+uenv+rtUghZ30t10nN2e8DR5MUoInvfRNbRdzFOYvlD/DjNw0rWYg0JT6TDr5x703kaf
sCx2o6hFLw/rmv48vOw0j9ppO/WxsWwSd5qa9Kn6YcrAGCvR690Uob0oUXqG3mbJptP6H/TTlE3F
NAXr2UNHWL8Y+HHNQBXiZkKURtB4WJbSn+kvdIy52LN8qSnZVGbymq7XX6chNIpmY7Y70fK/2Td8
Fcpq8aJSr9fQIMTltzLa9AJ9wHJYKZvGLuMj+FJ+v7iGrBhxFMoC6kC870Lv7yON9vJkflQ8rDyh
fG/OGzihD8IdcdM9dB89y1KwUpV1sd+wN9hHvJY383v4h+IO5THlVUsLVn05LaHN9AR9w9LZODaD
/Zq1sxvZOvZbdjc7zI6xT3k1b+RX8lOiXVwtnlFqUGYpXcrNpltNG82fDvgHnh/4r4Fv9DL9VpqB
fFiD2d9J92NlvXSU3kI5Th8yE0tig1BU5mSz2Q0oq9hm9hDbxR5jezDKMfYh+wyvpK/Y9xxvWm7m
uTj8yCOQi1+DE+Yd/F5+FOUY/xf/VmSKAuERY8VEERBLMat14jaUp8UHSo5yVNER5zLTNtMO0y7T
E6bnTKfNyZbf4B3/yg8P/1j04/sDNLB+YNtAZGCP/gENxT3E2wOfYBMx+xaURbjf25Bxu+k1lozY
5bAiVskuQWSa2SJ2NVuJSN7CtrNHjLk/xfYjSm+yU5hzCrcbc76Qj+U1fBrK5byNX43D2O18D3+D
fycsIkmkiqGiSEwS80SbWCauE9uEJl4R74kPxdfiBxRdSVQcSoHiVjzKJKVZWa7cr3yifGJqMr1s
+oc50bzEfKs5av4Cp5pKy3TLDMs8y1bLXsvr1iCy8yA9TX9CBp692AmxRvjE07SFj1ay8QlzBPnc
TAvEVI5M5bvYen4T28OHmVaaK3gFu5ROK27E+kW+g3/NK8RU1sBm0SI+KtaheYjyOKSJykE6qezH
2o6g55XmZLaKnzInUwRnpPE4I70gRioe8TK9LY4zi/IgvaMkskx2ku8U05EFzyiVJj85xb30lLia
3URPcx9R4vfWTcjjS9nj2BcaWRn7t9BxDL4UWVQuPqKb6Ur+dzqJ53g9/Z4tUBbSFhrNbqRP6FE8
FSNMV5mLzEPZS7xDCfPBbA9x5TGsbjwbxoRpCN3C5ont5lP8LVpOR5VEel/8EbM/yp8SU5XTppms
HU/ATXQrXa2voetMfuVVtpAEu4wKlRPY3W4UZYoTfDV2lSbsaXvxdPdhH6gWU6HJQuZcgryYjR1i
O8pd2CcUZFAHnvE52MWO0B5zI4/SQtMghl0H/6l5eWAmzdUfpbv1hXSVfjuVYD9Yp9+IHnfRP2gr
7WJrB26gTnxKvoVn+xJTPT9qqtdLeJi/xWfxbeffX0S7kGXRP1Gewp2pNO2jsPImzaIqfZP+N2T3
Bdhh76b5OLB+jFV+jhEmi34aPXAp79brRSfWe5xm6Dt1B0ukdn0xTaP99IjFRC0WD+6xxl7Fem+g
Nj5TXybaBjoQh62IghfRWo79Z4O3dnZjtbeq8uKJFRPGjysfO2Z02aiRpReWFHuKRlww3F04zFXg
VB35efbcnOyszIyhQwanp9lSB6UkJyUmWC1mkyI4o2Kfqz6oau6gprhdkyeXyLqrBYqWcxRBTYWq
/nwfTZXtWmA6z9MLzyt+5umNeXrPejKbOpEmlhSrPpeqHa5zqVE2d4Yf8uY6V0DVThryVEO+zZBT
IDudaKD6strrVI0FVZ9Wv6I97AvWlRSz7qTEWldtW2JJMXUnJkFMgqRlujq7WWYlMwSe6ZvQzcma
giVqOa46n5btQlN0Iwp9LQu06TP8vrpcpzNQUqyx2lbXfI3kScljuFCtMYxmrtUsxjBqB844Gm1U
u4v7w5uiNpof9CQvcC1oafJrogV9+LQ0D8at0zKv/zjrpyo6x5ls3bnWXBH2ZXWo0jkcXqdqD8zw
n9M21yl7CATQB9rywvpguB5Db8KdapBncY2vDfg1thZD4mBZaKwqtr7YqbcwuEjVElw1rvbwoiBu
TU5Yo5nXOSM5Od5e/QTl+NRwo9/l1KpyXYGWOnv3EArPvK4n26tmn28pKe62pcUC2z0oNS4kp5wr
tCHoMZshGe5Saph5NrJMztE1BSdBTW1VMRO/C2saJ0nbOAq3jsMNwBVgaKUtwB3p0BJqg2HbBKnH
EplmKrS51PBXhAxwnfzX+ZqWuMZcaPuKpFHmydlU01jLGVnzeLSiIpkillrcU8yx0qiPLSleEeUu
V6cN38/yo4GmI7YtgQmlCL/TKW/wxqiX5qOihWb4Y3WV5udGyFuKszUPSkv/GcvQ2dISOmM52zzo
Qibvkd+zNFSzus/+pdoyBvvaJ2gs4z+Y22L2hlmuBhyNVV84GM/ahsbzajG7DCjiBltc0gbX+kUu
h05KPFcY1tgJ+YwLjsv+ZE0pxJ/ZSOoFUYsVWWlomFqv2YKTYzSQ6HTGn5n/r1FUPy1bGeynZvFl
aBM88YnGpq1VnFc/b3rJYdHQiC2H42QfDieeZ0OqxWY5Jc6Q8fjQd6q1Gs3Gk1mIP3xyjJMI5Gpe
hAyWRjxFhjqQG6+e55gbbxTAJbOzpLgee2Y4XO9S68PBcEtUD813qTZXuJc/x58Ld/qw28USJ6r3
bczV6jcFELF2NgGPB6eabhdbP6Pby9bPmuvvxb841PWN/ghnvDZYE+geBpu/VyXyGloutVIpXVRZ
oQaGRUa41fDP7fUShQyrYiiMeiv+u2HoYk7QMWqN8pjOdsaPQ6fEdF5DJ9cn95jaRn/8thgJIR89
5BB+UEE3/DDeZAQh9gtFMpTyt4xHzmqQ0lQBDV4t8jBuwg8K+K2EnGnOtEIQ/FeHflBF/w9eE31P
qtIv+1rCjvF2nFmSyNGLl/8s76AE8ysqjcRZdHnynJ1ZHtvX805S6clRIwePuWh0Gd5kZleBe8md
7R133tnRfic/0nHHHR2QMSKaGJc+HOfIX7qkfZ1hYJQeX4UZ536aNKd+ypSAp/qajpbFUxv/F0zx
DD0KZW5kc3RyZWFtCmVuZG9iago0NyAwIG9iago0NjExCmVuZG9iagoyMSAwIG9iago8PCAvVHlw
ZSAvRm9udCAvU3VidHlwZSAvVHJ1ZVR5cGUgL0Jhc2VGb250IC9CWFBWVVorSGVsdmV0aWNhIC9G
b250RGVzY3JpcHRvcgo0OCAwIFIgL1RvVW5pY29kZSA0OSAwIFIgL0ZpcnN0Q2hhciAzMyAvTGFz
dENoYXIgMzMgL1dpZHRocyBbIDEzOSBdID4+CmVuZG9iago0OSAwIG9iago8PCAvTGVuZ3RoIDUw
IDAgUiAvRmlsdGVyIC9GbGF0ZURlY29kZSA+PgpzdHJlYW0KeAFdkMFuwyAQRO98xR6TQ4TtM0Kq
UkXyoW1UJx+AYbGQakBrfPDfF4iTSj3sgZl5MCw/9++9dwn4lYIeMIF13hAuYSWNMOLkPGs7ME6n
/VQ1PavIeIaHbUk4994GEIIB8O+MLIk2OLyZMOKxaF9kkJyf4HA/D1UZ1hh/cEafoGFSgkGbr/tQ
8VPNCLyip95k36XtlKm/xG2LCLlRJtpHJR0MLlFpJOUnZKJppLhcJENv/lk7MNo92bVS1Gk6W/NP
p6Dli69KeiXKbeoeatFSwHl8rSqGWB6s8wt+2nBKCmVuZHN0cmVhbQplbmRvYmoKNTAgMCBvYmoK
MjIyCmVuZG9iago0OCAwIG9iago8PCAvVHlwZSAvRm9udERlc2NyaXB0b3IgL0ZvbnROYW1lIC9C
WFBWVVorSGVsdmV0aWNhIC9GbGFncyA0IC9Gb250QkJveCBbLTk1MSAtNDgxIDE0NDUgMTEyMl0K
L0l0YWxpY0FuZ2xlIDAgL0FzY2VudCA3NzAgL0Rlc2NlbnQgLTIzMCAvQ2FwSGVpZ2h0IDcxNyAv
U3RlbVYgOTggL1hIZWlnaHQKNTIzIC9TdGVtSCA4NSAvQXZnV2lkdGggLTQ0MSAvTWF4V2lkdGgg
MTUwMCAvRm9udEZpbGUyIDUxIDAgUiA+PgplbmRvYmoKNTEgMCBvYmoKPDwgL0xlbmd0aCA1MiAw
IFIgL0xlbmd0aDEgNTA2OCAvRmlsdGVyIC9GbGF0ZURlY29kZSA+PgpzdHJlYW0KeAG9WHtwVNUd
/p372N2QUJMAsklY7t1elrwliUqBUFg2uyEhAQMBuosgu0k2JjGRDIZUsNAdC1YWpCpCFRyVPqxA
kcuGwRuoGBkddVoVdbS+ZpT66nRk7IuOiub2O3eTlTDK5A/Ge+bc3/Oc853vnD333u1Zuy5KYylG
IjWsiHS3knWNewSipLkr0p20s/8Emdvc26MmbbmASOxs7b6xK2k77iMa47qxc/1Q++z34e9si0Za
knH6CnJ6GxxJm10DOaWtq+fWpJ19FNLRuaZ5KJ79JmxbV+TWofHpXdjqzZGuaDJ/3M8gp3SvuaVn
yK6HLOteGx3KZ0Hge5kYvALdS2l0E9mhZaKsIrL/fYyLJER5HFfZS+88tfqK2ecoy2HZqxf+ypIv
9h9/4vPoV/np9zi+gCNtOJ9LW+FgIVEGQ/xs+j2piNUON8GgxmKDalHnol6LWlw8z0kx9ijdjfoI
qkjtbButR92K+gCqlNL2w+pn2xKSw3ucradctsCbLilLx+cozjHpyqsGsx19SHnL+cEJloPVO8Ny
EmMpbd4Y9gh7mFpIYb8nD9tANVTA9vQVdiphhPZTN2oMVbTujO1PTK5QTrIS8kgMbabSZIkdUz4p
L1U+KjcEllBO5RsSxNOTYXmvUAZcDylPuW5UTqIeTIYOFCLjmLLf1ansnGywPQnlXpfB0OaepFjn
QtNjSlfhbqWl3IrX7zaEgwllJuLLvenK9Blu5VrXh8q0fMPBYJe66pWi8heVKWiINBWderxZyiTX
TmUWQpNdgfxZqCfYAbaXitjehGeBchwqpttXWzhjt8Fu66spKPcYbIN3ek3B7sKafE9hveIprM7P
h778eftm+/X2efYKe7G9wD7V7rbn2cc7sh2Zjh84MhxjHA6H3WB/TMxVbCfYQZoLWg72OWwO2WCP
wymdYIcs56EnHJJDcJBjvGG+j83LaLzBDh7N5BqUYzZLsxnsUF/SdcirSFyTrECmwHXccCeBOQRa
QDq7y7DRlit75zrnZs/Jmlnt/65b2IoM34u/+3Iyl767rjGoH3CF9AqumK7QcLpzWPlO2bMOoaiv
uLhuyfq+3u6O1kBUC4S1QBQ1rG/rbXPqsSZVPdLRzQOqLk4NNzW3cRmJ6t1a1K93aH71SK/V7qJw
Kw/3av4j1BpYGjzS6o36E73e3oAW8Yf6mnxrV40Ya2tqrLW+bxnLxztby8dqstpdNNYqHm7iY63i
Y63iYzV5m6yx+OQD7Y2+W3qwO9VAe52qFzTqtYtXBHU1EvIb7FE4/etIHqBM+UkqkGOUK00jhch8
C/VtLgeXmR/Lz1HmYJf5L7ESi9rPqzA4dzYN0F20lw6TjR6DXkA30P30AuvAb3slHaU32GS6Cmev
RAbV01+Yab5CrfQ75PfQKdpFRygDbbpoAqI7mMfcANsLvYk2m7+hKTSD7qAnaSZ63UFnzf1mH6JL
aBkdoINo/2emCUekcebj5ofkoMXoczMir5j15mHKphLyUQO8m+kk84hvm23kpEqge5Aepn30NH3K
bmdHzTaz1zxtnsFWddIkakTZyI6yM+Jh6Q7zQfMf5iCYKKAijBqmnfRb9H8YZQBHa4DdxHrYTrZL
8Aq3C0elLfLEwa/BQyHNR6mhNXQnGOinZ+jf9AX7THCKmWKP+Kx5rfkfSqc6zJLPJEq9KL9E2YE5
nWA2VsaqWAPbyO5ju9hrQpGwTAgKPxVuFT4WF4krxfXia9ItUkLeLt9vSx88Z54wnzNfp4nkoutp
LW3C7E7RafovfclE9DWJeVgl87EbUGJsr9DP9rF+oYENsNPCAfYe+4B9xs4LspAhTBCKhR5hp3BQ
OCW8JLaLu8QHxPfEc9IcWZD3yR/ZPPZ3BpsGtw6+ZFaaZ8zPccQ6yI2V8dEiWk0RzLabrqGfYxaH
UA5j1Z6hZ+kFq3zAJtFZ+hwsEMtmuayCLURZxK5jraydPcSOo5y0sPxPwEIIaUKWMFGYJDQKTUKX
EBNeF2JinlgkLhBXiIdRnhffEM+L5yVZGidNkOZLtbRd6pL2oDwqPSYlpJflmfIceZG8XI7JW+Xt
YrP8ivyGbZNthy1h+8z2TxyL9fY19u1YnRewZ5/GXv7mktgUoK+gm6mZ+VkT7cZq7GMRimN3tbA7
wVc3FZirxE3ifKEMu+Ek3Ybduoc20lZxJe0z3xQP0F+xUzrRZYz+IPnIJf8aq3M7lWEXDRVvYVFh
Qf5UzxTth24VR/6kvNwc58QrJ4wfl52VOTYjfUyaw26TJVFgVBLQqsOqPjWsS1O1mppSbmsROCIX
OML4Kat69cgcXeXtIgiNyPQis/WiTG8y05vKZJnqbJpdWqIGNFV/0a+pBluxOAj9Lr8WUvWzlr7Q
0u+29LHQ3W40UAPONr+qs7Aa0Kt72+KBsL+0hPV7QceY0hJ+cHgpnXesU1VkIw5YquIZAT1X8wf0
HA06YqInEGnRGxYHA/48tzsEH1xLghijtKRdB07altGitWwzvNQU5lpkZVAXIyFdCPO+sor1iZpf
n7jhI+c35rAW2H5BUBc81ZFovFr3hreBXG6GuRXZDquuUUW3wpZQUGdbhkBwjB1AyuEmnwmecIeq
p2k+rS3eEQa5tCSYyPXmWoevTg3BRI43xzJKS/qdmyrdmH1/6bzSeVxWup2bkvKTXyT9rw5w6dz0
zPuQdUtSBDDOgFYLnLrabA2iAewMfovOoHjzDPCEK8QwzXbgqdIF7BnRo8ue2ogeaxyG0eZPggt3
+BNpObnWQ8gXQn44njkLK4X8TE2Nn8PTOqyd/XSkJzLksXkyzxEP8oVO7RWdRYb1Xv6w9GDWbU6t
ja9vr7WmsDVn4AIHbE4Nx6yPxwO8IejW1RAceJssqTMorSF4hLEdIYOZWwzyu/rxjiquvgHhEr7V
2v0YH0ZpCRxFbmhXlajVGLma7xU1rsZrW+JqtdqGzSR5LIlANB6aBgYbg+CJlmJEbygvpUZDoVno
ZxrvB02QHg+hh46hHiAt17SvkVRWgoepOLUhuDiox/x5utcfwipg+w40BPUB7NxQCFnlKaRAvLHd
OYS5ApjLixC/OtkL3l1i6CIUj/M+G4OaWx+Ix/Pi/PeWtA1GFzu8Qw6DeAqn3GCxBrSF0Nx51hq4
NTdghTin12BLD+8ovLNfmuHpKdxo+SOgnW4xPOMyMTxzNAzPGhXDlSmkIxieDcyVnOEff38MzxnB
8NxLM+xN4QbIeUDrtRj2XSaGq0bDsH9UDAdSSEcwXA3MAc7w/O+P4ZoRDNdemuEFKdwAWQe0CyyG
6y8TwwtHw/CiUTF8XQrpCIYbgPk6zvDi74/hJSMYbrw0w0tTuAFyGdAutRhefpkY/sloGA6OiuFQ
CukIhlcAc4gzfH2KYW+eTheew7GLjl267Afzygsox5uSnE0+5oLCP5/xAY0rA18WGZDulAf/N6Hw
/398RNJpfLuJ+A+oKvm/jGOaQRKqI9MgOo3Kbejiu9Ah7ZAiZNq7dBytiJYXH0dPMmRZ+dVZ7qx8
VJ+0w/jqb/KTX1YZ0sLz+M5HhnWZUXy3fNuFOBPs625uryirqLYSGL7EkjOw4b8p8gUbli9bUVwT
7eyN9rQ3R5CTjPJkxGmSOXRxR0pn6jRu/x+oPWatCmVuZHN0cmVhbQplbmRvYmoKNTIgMCBvYmoK
MjcxOAplbmRvYmoKMTAgMCBvYmoKPDwgL1R5cGUgL0ZvbnQgL1N1YnR5cGUgL1RydWVUeXBlIC9C
YXNlRm9udCAvQUJHQ1pXK0NhbGlicmkgL0ZvbnREZXNjcmlwdG9yCjUzIDAgUiAvVG9Vbmljb2Rl
IDU0IDAgUiAvRmlyc3RDaGFyIDMzIC9MYXN0Q2hhciAxMDIgL1dpZHRocyBbIDg5MCAyMjkgMzQ5
CjQ5OCAyMjkgMzkxIDYyMyA1NzkgNTQzIDQ4NyAyMjYgMjM5IDUyNyA1MjUgNDcxIDUyOSA3MTUg
MzE5IDQ3OSAzMzUgNTI1IDQ1OQo3OTkgNjM0IDQ1MyA0NTkgMzAzIDUwNyAzMDMgNTQ0IDQyMyA1
MjUgNTU3IDUyNSAzMDYgNDU1IDUyMCA1MDcgNTI1IDI1MCA1MjUKNTE3IDI1MiA1MzMgNTI1IDMw
NSA1MDcgNTA3IDUyOSA2MTIgMjUyIDg1NSA0OTggNDE4IDQxOCA2NjIgNDUyIDQzMyA1MTkgNTA3
CjUwNyA1MDcgNDg4IDM4NiA0OTggNjE1IDUwNyA0MjAgNDYzIDY0NiBdID4+CmVuZG9iago1NCAw
IG9iago8PCAvTGVuZ3RoIDU1IDAgUiAvRmlsdGVyIC9GbGF0ZURlY29kZSA+PgpzdHJlYW0KeAFd
lMtu2zAURPf6Ci7TRWBaFJUEEAQUKQJ40Qfq9gP0oBIBtSzIysJ/3zPXbtpmMQZG98GZe2luHnef
dtO4us235djt0+qGceqXdDq+Ll1ybXoep2ybu37s1iuzb92hmbMNxfvzaU2H3TQcXVVlzm2+U3Ja
l7O7+dgf2/RB374ufVrG6dnd/Hzc25f96zz/Soc0rc5nde36NNDuczN/aQ7Jbaz0dtcTH9fzLVV/
M36c5+RQRMX2Iqk79uk0N11amuk5ZZX3dfX0VGdp6t+FrgXt0L00S1blbU2yf3D89Pzknp/GW+U1
511FEVSRK7npXe63/yVHfxHUDlcl+bauBO/jXc15ORR4Xz6I0kzw/i4XLaCAaBSNUADtREsoIDmI
3kGB98W96D0UQLeiD1DAuda5gQJooWgHBXRuRHsogA6iCQqgSXSAAqgsBGYrDK1X54A5AVUWxVww
g4U6B8wJ1EpVwJxAsmQEzAlEZSFgTkCkDAbMCUR7UdwI1Gp0ATcCfktRFimwGmuFuWAG0UYUcwJR
q8VcMIOFWcBcuBjUuQXmBA7SFkgxIEOaC+QL0FYU+QIyjCIfPVCGQBT5Aq0kg0UZkKGFFrgRiHKJ
KgZmwL5R3NCTKLsgihuBg0wkborLyuwg3BSXlWkaBW5oQjLDz6rIfgRWJhlM10ArTYMbYYBqzhE3
AudqgxE3XN2Kmy7NEQsCyboqEfkCFjiXv9ufi78N7/4IEXcCmVpQxJmAWaM4i5d9aeYRZwL6NYqI
MwFqguXO9sXks6rEqIBgSeKiGRAs7yXrExCs9ZV4F2ilQbFSA1G5429nIGqt8F7aNpntv+70ruj9
e3uvutdl4amyR9JeMb1O45Te3tH5OKuB4Te7Nl9FCmVuZHN0cmVhbQplbmRvYmoKNTUgMCBvYmoK
NjYwCmVuZG9iago1MyAwIG9iago8PCAvVHlwZSAvRm9udERlc2NyaXB0b3IgL0ZvbnROYW1lIC9B
QkdDWlcrQ2FsaWJyaSAvRmxhZ3MgNCAvRm9udEJCb3ggWy01MDMgLTMwNyAxMjQwIDk2NF0KL0l0
YWxpY0FuZ2xlIDAgL0FzY2VudCA5NTIgL0Rlc2NlbnQgLTI2OSAvQ2FwSGVpZ2h0IDYzMiAvU3Rl
bVYgMCAvWEhlaWdodAo0NjQgL0F2Z1dpZHRoIDUyMSAvTWF4V2lkdGggMTMyOCAvRm9udEZpbGUy
IDU2IDAgUiA+PgplbmRvYmoKNTYgMCBvYmoKPDwgL0xlbmd0aCA1NyAwIFIgL0xlbmd0aDEgMzMx
NDAgL0ZpbHRlciAvRmxhdGVEZWNvZGUgPj4Kc3RyZWFtCngB1X13fFzFufbMOdt7r9LuSivtSlr1
XmxpZXXJsi3ZsiXbsiV3Gxt3DG6YDgZCDQkllIQAwQRk2cYyJMHkOiEhMYGEkgaBmwIhcQKpFEv6
njmzI8uU++X3+/65n+Rn32dmzjk68057552Z9Y5tO1cTIzlAZFK8ctPwFqL8lP8A4sGVF+2I8HD2
OkLUaWu2rN3Ew3lXEqIPrN14yRoerlQR0jVv3erhVTxMzkJWrkMED9NyyKx1m3ZczMNl9xNCczZu
XplKr9iI+Ds2DV+c+vvk1whHLhzetJpff9kCFt6ybXUqnfbjcbYtm7fv4OnO2ZDF56db8CcQ20kj
xEb+i2iJBFlE8ET7zfRyokIqS1ffO3bjv39kX26d8U/i1yGCkKf/tPfHTD53zSPXf/zR+PX6P2uf
RFCPJ/Af3Ke9d/yXhBju//ijj+7X/1l5UipREZ2jejkyJl15VO+jnSBXCHK5IJcJckCQSwXZL8g+
QfYKskeQ3YJcIsjFguwS5CJBdgqyQ5DtgmwVZIsgmwW5UJBNgmwU5AJBNgiyXpB1gqwVZI0gqwVZ
JchKQVYIMizIkCDLBVkmyKAgSwVZIshiQQYE6RdkkSALBekTZIEg8wXpFaRHkHmCzBVkjiDdgswW
pEuQTkE6BGkXpE2QVkFaBGkWpEmQWYI0CpIUpEGQekFmCjJDkDpBagWpEaRakCpBKgWpEKRckDJB
SgUpEaRYkCJBCgUpECRfkIQgeYLkCpIjSFyQmCDZgmQJEhUkU5AMQSKChAUJCZIuSJogQUECgvgF
8QniFcQjiFsQlyBOQRyC2AWxCWIVxCKIWRCTIEZBDILoBdEJohVEI4haEJUgsiCSIFQQkiJ0UpAJ
QcYFOSvIx4J8JMiHgnwgyL8F+Zcg/xTkH4L8XZC/CfK+IO8J8ldB/iLIGUH+LMifBHlXkD8K8o4g
bwvyB0F+L8jvBPmtIP8tyFuCvCnIbwR5Q5DXBfm1IL8S5JeC/EKQnwvymiCvCvKKIC8L8jNBfirI
S4K8KMhPBHlBkNOC/FiQHwnyvCA/FOQHgjwnyPcF+Z4gpwT5L0G+K8izgpwU5BlBviPItwX5liBP
C/KUICcEGRPkuCBPCnJMkKOCHBFkVJDDgowI8oQgjwvyTUEeE+SQII8K8g1BHhHkYUEeEuTrgjwo
yNcE+aogDwhyvyD3CXKvIF8R5B5B7hbkLkHuFOTLgnxJkDsE+aIgtwtymyC3CnKLIDcLcpMgXxDk
RkFuEOR6QQ4Kcp0g1wpyjSBXC3KVIFcKcoUglwtymSAHBLlUkP2C7BNkryB7BNktyCWCXCzILkEu
EmSnIDsE2S7INkG2CrJFkM2CXCjIJkE2CnKBIBsEWS/IOkHWCrJGkNWCrBJkpSArBBkWZEiQ5YIs
E2RQkKWCLBFksSADgvQLskiQhYL0CbJAkPmC9AoyT5C5gswRZLYgXYJ0CtIhSLsgbYK0CtIiSLMg
TUeYtQyreTRUH4bNPBpyQ1zOQ5eNhmoROsBDl3KxfzRkQuQ+HtrLxR4udnNxyWh6Iy65eDS9CWIX
FxdxsZOn7eCh7Vxs45FbR9Nn4YYtXGzm4kJ+ySYuNnJxwWhaC67cwMV6LtZxsZaLNaNpzbhkNQ+t
4mIlFyu4GOZiiIvlXCzj9w3y0FIulnCxmIsBLvq5WMTFQi76uFjAxXwuerno4WIeF3O5mMNFNxez
uejionM02IE8dHDRPhrsRKiNi9bRYBdCLaPB2RDNXDRxMYunNfL7klw08PvquZjJxQx+ZR0Xtfz2
Gi6quajiopKLCv6wci7K+FNKuSjhopg/rIiLQn5fARf5XCS4yOMil4scLuL80TEusvkzs7iIcpHJ
H53BRYTfF+YixEU6F2lcBLkIjAbmQFl+LnyjgbkIebnw8Eg3Fy4e6eTCwYWdp9m4sPJICxdmLkw8
zciFgQs9T9NxoeVCM+qfh7+uHvX3QKi4kHmkxEOUC6IIOsnFhHIJHeehs1x8zMVHPO1DHvqAi39z
8S8u/jnqWxAeo/8Y9c2H+DsP/Y2L97l4j6f9lYf+wsUZLv7M0/7Exbs88o9cvMPF21z8gV/yex76
HQ/9lof+m4u3uHiTp/2Gizd45Otc/JqLX3HxS37JL3jo51y8NupdhKy8OupdCPEKFy/zyJ9x8VMu
XuLiRX7JT7h4gUee5uLHXPyIi+f5JT/k4gc88jkuvs/F97g4xcV/8Su/y0PPcnGSi2d42ne4+DaP
/BYXT3PxFBcnuBjjVx7noSe5OMbFUS6OjHoakOnRUc8SiMNcjHDxBBePc/FNLh7j4hAXj4560OvT
b/CnPMLFwzztIS6+zsWDXHyNi69y8QAX93NxH3/YvfwpX+HiHp52Nxd3cXEnF1/mN3yJh+7g4otc
3M7TbuNPuZWLW3jazVzcxMUXuLiRixv4ldfz0EEuruPiWi6u4eLqUfcw8n7VqHsFxJVcXDHqXoPQ
5VxcNuruQ+jAqBuDDb101F0JsZ+Lffz2vfy+PVzsHnWvwiWX8Nsv5mIXFxdxsZOLHVxs54/exm/f
ysWWUfdKPGUzf9iF/MpNXGzk4gIuNnCxnt+3jou1/M3W8NtXc7GKX7mSixVcDHMxxMVyLpbxTA/y
N1vKxRKe6cX80QP8D/VzsYi/7kL+h/r4UxZwMZ+LXi56Rl1JZGzeqIupde6oizXYOaOuKyC6R10F
ELP5JV1cdI66YEjQDh5q56KNR7aOuvYjrWXUdQ1E86jrUoimUdcBiFmjjlaIRi6SXDRwUT/qgF1A
Z/LQjFH7AEJ1XNSO2lk7quGietTehlDVqL0fonLUvhiigqeVc1E2as9HZCm/smTUzjJWPGpnHVIR
F4X89gL+F/K5SPCH5XGRyx+Ww0WcixgX2aN2pqUsLqL8mZn8mRn8YRH+lDAXIX5fOhdpXAS5CHDh
H7UN4pm+UdsyCO+obTmEhws3Fy4unFw4+A12foONR1q5sHBh5sLErzTyKw08Us+FjgstFxp+pZpf
qeKRMhcSF5QLkpy0rggzTFhXhsetq8JnwT8GPgI+RNwHiPs38C/gn8A/EP934G9Iex/h94C/An8B
ziD+z8CfkPYuwn8E3gHeBv5gWRv+vWVd+HfAb4H/Bt5C3JuQvwHeAF5H+NeQvwJ+CfwC+Ln5gvBr
5pLwq5CvmDeGXzbHwj8Dfgr+kjkRfhH4CfAC0k8j7sfmTeEfgT8P/kPwH5g3hJ8zrw9/37wu/D3z
2vAp3PtfeN53gWeB5ORJfD4DfAf4tmlr+FumbeGnTdvDT5l2hE8AY8BxxD8JHEPaUaQdQdwocBgY
AZ4wXhJ+3Lg7/E3j3vBjxn3hQ8b94UeBbwCPAA8DDwFfNxaEH4T8GvBV3PMA5P3GC8L3gd8L/hXg
HvC78ay78Kw78awvI+5LwB3AF4HbgduAW3HfLXjezYY54ZsMc8NfMKwN32j4evgGw8Phq+Ts8JVy
dfgKWh2+vO9A32WHDvRd2revb/+hfX3GfdS4L7iva9+efYf2/Wpf0qEx7O3b3bfn0O6+S/p29V18
aFffU9LVZI10VXJG30WHdvapdrp27tgp/2MnPbSTNu+kxTupRHbadkZ2yqYdfdv6th/a1ke2zdt2
YNvINlXdyLY3t0lkGzWMTZ48si0YaoVM7t1mtrVu7dvct+XQ5r4L12zq24AXXF+9tm/dobV9a6pX
9a0+tKpvZfWKvuHqob7l1YN9yw4N9i2tXty35NDivoHq/r5FuH5h9YK+vkML+uZX9/T1Hurpm1s9
p28O4ruru/pmH+rq66xu7+s41N7XVt3a14LMkzRbWiRNtrEXmJOGNyFBOqs4mAy+GXwvqCLBkeDJ
oOywBsIBKdfqp01z/XSz/1L/TX7Z6vuJT0r6cvNbrd6feH/j/atX5Ux6cwtbicfmiXhkN8ubp3sB
y9sRT0MzlyUVSl67PdFYq9VNre6wW2oJuymxv2l/zy67n7H9xCZZrdRqnbRKSSsut1rCFol9TFrk
pKWkqtVqDpsl9jFplj1JM2LYy8dN8xa0Wo1ho9TXYJxrlJLGhqbWpLGguJXINEKx8mODkHXsbag7
3DpGyREPVdMxevPhBfMTia4xHentGtHNWzJCrx3Jns8+kz2LRzTXjpC+xUv6D1P6hYHDVGpaMOLq
6lnMw1fdeCOZld41kj6/f+T+9IGukQMgSUYmQUj6YQ+ZNZBYtn3n9kRixzJ8LNu+I6H8Q4juZCH8
IAH/tu9AmP1CIExYyuf/8Mtw3fLt+FEew5/++bf8f5BC/z94x//lr3iYoIr2N05KV5JV0hXA5cBl
wAHgUmA/sA/YC+wBdgOXABcDu4CLgJ3ADmA7sBXYAmwGLgQ2ARuBC4ANwHpgHbAWWAOsBlYBK4EV
wDAwBCwHlgGDwFJgCbAYGAD6gUXAQqAPWADMB3qBHmAeMBeYA3QDs4EuoBPoANqBNqAVaAGagSZg
FtAIJIEGoB6YCcwA6oBaoAaoBqqASqACKAfKgFKgBCgGioBCoADIBxJAHpAL5ABxIAZkA1lAFMgE
MoAIEAZCQDqQBgSBAOAHfIAX8ABuwAU4AQdgB2yAFbAAZsAEGAEDoAd0gBbQAGpA1TiJTxmQAAoQ
sooijk4A48BZ4GPgI+BD4APg38C/gH8C/wD+DvwNeB94D/gr8BfgDPBn4E/Au8AfgXeAt4E/AL8H
fgf8Fvhv4C3gTeA3wBvA68CvgV8BvwR+AfwceA14FXgFeBn4GfBT4CXgReAnwAvAaeDHwI+A54Ef
Aj8AngO+D3wPOAX8F/Bd4FngJPAM8B3g28C3gKeBp4ATwBhwHHgSOAYcBY4Ao8BhYAR4Angc+Cbw
GHAIeBT4BvAI8DDwEPB14EHga8BXgQeA+4H7gHuBrwD3AHcDdwF3Al8GvgTcAXwRuB24DbgVuAW4
GbgJ+AJwI3ADcD1wELgOuBa4BrgauIqsajxArwS7ArgcuAw4AFwK7Af2AXuBPcBu4BLgYmAXcBGw
E9gBbAe2AVuBLcBm4EJgE7ARuADYAKwH1gFrgTXAamAVsBJYAQwDQ8ByYBkwCCwFlgCLgQGgH1gE
LAT6gAXAfKAXmAfMBeYAs4EuoBPoANqBNqAVaAGagSay6n95N/2//fUG/re/4P/y9/MtX8Z2DBEy
cdv0TUJkHtlAtpMD+L2a3EhuI8+QX5EV5AqwO8n95CHyDTJCniU/JK+dd9f/Y2DiEvUmYpKPEw1x
EjL50eSZiYeAMbVlWsxtCDlVkXMxk7bJv3wi7i8Tt03aJsY0DmJQ7jVLP8XT/k7HJz/C+Koh5slK
FpauAbcqf+l97b0TT0w8fF4G5pEespgsIUvJIBkiw8j/KrKOrIdmLiAbySZyoRK6EGlrwdcgtBxX
oS9R+LmrNpMtZDPZRnaQneQi/G4B354KsbStSngn2YXfi8klZDfZQ/aSfanPXUrMXqTsVmIvRsp+
cilK5jJyucKE5DFXkCvJVSi1a8i15DqU2OeHrpu66iC5ntyAcv4CuYl8Hr/xvJSbyc3kFnIr6sPt
5IvkDvJl1Iu7yT2fiP2SEn8XuZfchzrD7vgiYu5T2B3kS+Rb5PvkGHmcPEGeVHS5ErrlGhF6WaNo
egt0sBd5vmLaG3Nt7prS1n5og+X7YCrfF0N/l0+746KUHpn2rsCVTDsHU+XAnrIvFSM0cTNyxvm5
fDIdsTzcdF4+xR3/t1iWY6ane6AvoRmmszsQd9enYqdfMZ3fQb6CFvgAPplWGfsqOGf3KXx6/L1T
196vpH2NPEi+jrJ4mDAmJI95CHEPk0fQth8lh8hj+D3HpzOe+jj5plJyI+QwGSVHyFGU5JPkOBlT
4v+ntCfQd3zyniOpZ41OPeUEeYo8jRryHXISPc138Stivo24Z1Kxp5SrePi72Et5SrmKpX4Xdes5
9FDPkx+RH5OfkO8h9ILy+QOEXiQ/JT8jr1Ez2Evkj/gcJy+qf0cspBEbL59CadxDlpFlybZVy5cN
Ll2yeKC/b8H83p55c+d0z+7q7Ghva21pbprVmGyonzmjrramuqqyoqiwID8nlp0VzQz7XHab1Ww0
6HVajVolw7LNb4m2DkVGYkMjqli0vb2AhaPDiBieFjE0EkFU6/nXjETYfcNIOu/KJK5c84krk/zK
5NSV1BaZQWYU5EdaopGR083RyBhd3NMPfmNzdCAyckbh3QpXxZSAGYGMDNwRafGta46M0KFIy0jr
ResOtgw1F+TTw0ZDU7RptaEgnxw2GEGNYCM50S2HaU49VYiU01J7WCI6M/uzI3J2y/CqkXk9/S3N
wYyMASWONCnPGtE0jWiVZ0XWj+CdyfWRw/knD94wZiMrhhKmVdFVw0v7R+Rh3HRQbjl48JoRe2Ik
N9o8krv7dz4ocPVIfrS5ZSQRxYt19U79ATqizrZFIwf/SfDy0TN/xltPixlOxWiybf8kLJFlcUpN
I3RYcIJ3wxsifxkZ7F2uH0uSFQiMHOjp5+EIWREcJcmixMCINMRSTooUdx9LOSBSpm4fikKzLdGW
odS/i9b5Rg6siBTko2SVf9kjqmykR0bk2NCKleuYHF59MNqMHEKXZAGcNs0gyeGUMlsOFxfh+uEh
ZGI9U0NP/0hRdMuIKzqLaxsReEh2y/r5/cotPLZlxNU0QoZWpu4aKWrBvagiLQdZwbAXZM+K9vSf
IGWTbx4ujwSPlJFyMsDeY8TThEKJtRzsX7VmJDwUXIX6uSbSH8wYSQ5AfQPR/tUDrJSitpHcN/Hn
8IMCVO5C3j5xtbgY2R7RZusi/VJQHmClhYhIKz6is2YgwTai4UFWorNmRPppkIjL8FdSVzB23nMQ
kLOb2nEzJG5tag9moHIrP//DKwV5BvAaI7qpd1LhJdTn3on/nc99NX41e6HcSMvq5mkveN5DEVBe
MPW0z35PiekipQy8go4VZzvLQ0G+BB5Bsm5EQj6VKFaKvsgImRfpj66ODkRRh5Lz+lnhMF0r5ds1
P8ocg0ppp2rJgvNCPL2ap42QjK4F/SLAfDYjrQmlXFmxKuE2JTwVbP9EcodIjhzURbvmH2R/PJp6
IImgBaFwNLGO4eurHeVorK3oKKOtw9GILdJ6cHhs8sCKg4eTyYNbWobW1aIZHIx2rDoYnd8/A2Wp
tPt9wd3sTztIF+1aMKsgH33PrMNRem3P4SS9dv7i/hM2QiLXLugfleAUHZo1cDgLaf0nIoQklViJ
xbJIdkmEBdiTehHQKdcHTyQJOaCkqpQIJbwSflkljl+EOEpWjkk8ziaukxCn4nFJJW4AP2hhvnUo
AvTDLZFVrHj2Dqw7ODTAGhfxoCjxj47QaD0ZkaL1cOVqTCOG6OpZI8boLBbfwOIbeLyGxWujs0ao
h0I5Y+iTDg5F0U+hyvXDRT6A2mFjtV/KjoxNTi7ozzgdPDOQgSaxFFjcP6JPYBxQZ3fiujaGIUS3
jRxYOczeg/ShqbOW2bFyAG1BPBCXdIzo8QR96gm4olW5h1VH3LQSZYMCVO4/gMDIgYGRgQT7o/3r
2RtFIrYR0h6tRbHzZ6pj7A8VDRx0REtZxcalI4bsa5jQ490InNRKTBBB/DF0uCxHWhPefGUUSSuH
IigBFVk5H1Wd96UGVm6IWY0uURVbrcAQTCUSli0522g2jOgL8UD8Y9xYiAfin3YASmGZV0LXpC7A
37aNGPFGsWmqTN0A7SCpg70L/l2Dl2eXPsse0zNGeqMXo2tkL638KS2SR8zZHcPo/Pn9RsREq8XN
eJYum0WxZ5zisVqWcxP0LmcvGJt8OHoJ6wHET0F+lA0OrGKS4AlUbDJw8JMRI0sSBfm6T8aaleiD
B3Xmz76B60tnnpLsKZEWjDWEqNgxlp9APkCiqsXkMVUzGVb9mTwmvwN8E+Gz5DFJBdxItKocxA2S
xzSvkcfUecBsslKViWv6lWvb5D8QqzZEZqripFh+hSxVlZM75RVkMeSQ/DEZlLaSbNUMDvkUqWDp
8MFdRd+dfEX+msLv1Kwid7J4VbVyH+ND0vN4TgbpkR4nGao/ADs51E7IcnK7/BWSqR4jFfIukivf
RzLxTCIfw3MnSR48lF+SB8i1QEL2Egovc4t8dvJf8CxfBeyWz5J7oYMLgHbgcWAbsBYoBlYDLK0X
hcLP8xBiwnzzDoQzSCtxkQjJJQESJXlERyRix5yXIiVGskmIpJNSYiAekiBh4iBZOB1UjnNC9aSJ
NOA8lI8UkwLiJzNIJk5INZMcUkXiOENUjRrvJUHSguenkXycCzKjMtSQWsxyS0gZcZM2Mot04C3q
yEyiJu14o0rYvOznAfIALaK/l1ZIP5G75KOqBar71Cr1FeqXNPu1fu0tOoPumP4a/V8MlxreNt5h
KjI9be41/91ykVVvvcW23y7Z9zgkxz2O3zhPunpcv3Ff5LF6rvXO8T7v2+W7wveh/1CgLvC34PNp
i9OeSftt+uL069O/GVKFloauDD0c+nHYHV4dfjayOSMz4xeZl0Q3ZZVmvZ311+xH8FZqeCa2yz/F
LF5G/mtIN5lDlnyLmOFu85BaeuyYu7lZV6D9DlxpEonAGacjlDYlrSrJfDwQaIger9DcKNs7xmjB
0QbtjXAzN4y/Mf5C0fgbZxw1RWdo0etvvfGW7f0X7DVFZW+9/FZJMbVn2BW4LJJW69JEMwulinis
sqystF6qKI9FMy2SEldeWVUvl5WGJBlX8ph6iYWp/NOzi+W54xppf7RhYZk6FLC6zBq1lOZzFMzI
ts1fkj2jMF0razWyWqfNqZqV2bWxJfOXWnu625Pu0Okc6R53ul07/iu15aO/qS0fN6k2fny7rKlb
2pAlf9mgk1QazVjI58+ry+hYaHXaVEanze7RaR12U07z0vGr3WnsGWluN3/WeDfUEp38SLVf7UJd
iZGvnCBZk+8cNdno7OhYisTGJt87akSMURCs976XDLCobBv7NCufJuUzmUOzWXK+kXZnRWPZ/zAZ
Tb7M9KjBTD0qEzHZTNIT0WeiP4nKUVPU5EjvdfSp+0hDQ4OjpqaoaHDQ7q2xg9rLbGdK7WXQeGKQ
+8iwkpjt8WgUlcflDNkiRzNjscoqyvXs1UZltF8dtWWHw9lOvWrz+B82yAZnNC0920p1dFRl9sdD
kbyARbWH/oZ+d6YnaFHJWpOe1k38UG/Wq9SWoEc1arToZFlnNd44vgdNHXNcoqKoXSG0tGryg2Qg
7LPR7rDNyj7M+PCZ8BFBXrH7sDCZE3Anke5OIt3tNuazi/PZxfns4nx2cT67OP8pqRR+pZPHwEms
DJo+gish3zuCixWJ6yH/dQS3KOm4smxMsiXN9xtPGiVjIP6PkhJt1hjFrpCe8jFqPKxdQBrONCj1
toYWDb6laK305QQnqM6JRA3nUKrLoopmZMYq7OWVZRmolW5Wn0MyLS+UolE7q8zOc1RFw9VzV27t
mHjcm5vrpbEdt68s9SQa8yqWtuRMjAeqF3eOnmrqrfTPyW67oOeFj+r6m2J0+8y1vfV57nBcdXk8
nL9gd3fhgrZqh6Gi90KJFs2uSJsYjNbNHX+9tn9GeKI6raoXfdvw5HsqkzqEVrziSBqpS6S0Aqlo
BfLPR6AVyL8wrSjp0EriO1IZ+igfLWK9I80fdc5XPU3zSAUppoWH9QvRpF8+w0CLePZtr54qKc52
WXjjLVeapYYpgDVT1oDdrhCaKm+uKpOk1rmSy/d07P/RTd3z73jp0uoNi1uDOrWs0hl1ltK5W+cu
vHFVVcXKm5d0b+8pt2oNGvm4zeewuHLjwQUPvv+VB84+sdQdyQtanAGHK82pjxfFW65+du+eb1/a
GCuKaewhtEBWy25CLXOgN9+VTG/IoE5Wc5ys5jhdyLPTgQw7fcit82lWc0iA15hASjeKxHWQSo2B
fOcIrg48jXU3PXRjGrX0BMdo7LCa1xKhi5dFjRhElZDOqxLaaRXgpoVff++hib8oxZ/9yDtf6TlW
vvnRq584vPfRbTXSXY98/PVeXtCLvvbOneuPXdl51l5/4Fk2riFn8l7kLJ9cdDgQT5UopFKiisRb
QypvraTjreNjkj2p1zsjzghePjBGdUnzgRg9GaMvxmgspvGPIT/mnjjEYc1UrR/cug1FXKR0Izae
rVKlnM/PllLQGXZR6aOcyntVBrNu/DaWQ2mNzqxTq/ExoaGjOnQNKj34HInqzAZVmyPo0PHc6hxB
lyNo101s0NvSnI6ATTtRorMHlXxPfiQvQL7jZOlhrTOVb0gl34pkpZrKt5LOyhb5PmZOJ6F0LbJ2
xOn0a8ZozpHMHj/rIFMjUtEpe6oZI3e80KZnRow2omHLC5Ax7QS0p8XLKzypc0UCvkyXDlltVWJP
OdOQi3atLeh2Bu368d9rzVq1Gh+qx+NhDDmpHKnmYZQoImNHG0po1JTKFKSSKUUiU5BKYSrpyJSJ
FWaaN8vIarSR1Wgj6wuNBtRoI6vRRtareUnSja4w6WQfNjudTZJIJ162zQUJTD6JNG9eL7q8/KT1
pIm+aKKm88ePosGtZxoo+rmXWd+XqgLnqsIg2jwfijGIT1He/iU34gRVzdO5MnyBiEs3fgTMz3Sl
c2X6/BkundStaA8soDMxJZl0Uv34dwVX/VKw8Y8kjeAp/dF+6M9N5h1v8M71PuGVSUqFkIoKFQnd
QCoqVNKhIfIUWrFh8uRxaMJg61WGS2Rzqumey5fIAe0X7613Z3jZe0+97bk3ZG+lnfwL/R3eKofA
mUN4p/IfvU46XsdOu9Mt0V7907QUxqkPva061duiHU69nlJHMws1FamXUyylKV3T36U1b+5NqyrM
NGrVkow+VeePFoYziyM2ngWnnrZ2H1hcorfaTSa73+GB9WN1WO2FPY3yvdC+SgUts54GLe4D5KSM
rEjaS2xQWzGrXUWMZcBgUUZYZriwEVaR0DSkomklHRcaWGU1ueO9GQZbsNd2zjJBtZrqUlC3uMZj
sTj9jIqUMkjcLo2WUo9H/kDrygxG8z3aiSxRKqI20ec1Nm9GIBBxas2Oifn0Bbs2jXU+GptBumb8
kqlmeK5WPSs16E1alRqZNge845PjdwXYvID1s13IfYC0nyBunlnsXFMyq0hkFlLJLKQyOLiR2aNE
b+11j9FEqiOlRadFtVLyyG0EPhSiiTB7tgu9oX78lDd3KhMvMvOpyxV06tEvPi4q/ccP6O1pqZqv
SaAvnEEeS9qG6rfUS+biYm9RkaHQ51MGKnQMygCGglEk3hVSeVclHQUTYAUTyioxmQysHzGwfsTA
+hED60cMrKQNrJXApkr6ESBZlT1Gn9dc5Csp1IRzesJ9wsxscMDALEN5CssIVqboI+xl9pqZRWVl
zO6c1ltEKbM1C6U4jU4rbmbzhyQvLWPlzahbk9C5wn5vhlMnTZTJRne6yx1yGaWJNoo+w+9DIecH
10WKs3x6uktNrzYGwjH/JmvQaTrXONd+fLvWoJVVMCNg2N8pdKl6KC/LFMgJnl0kPxTK8xv1znQ3
r/Ow3O2Yq111JG61ulK1XJFQkCKhI8j3mMWkhKEcl6LMkKGwsJQps9SHa0t9uLDUhqtKmTJL2SU2
EqruNRRa4yo/G4PYUAsz3VvDlJdqDed0VwSdKVWGawptI+rxuD9DXyHZWxZjlmeqVqn2m90Bc1Ug
Ho26J9ZFGtMkSdI5wz5f2KHLD/Smx8PpdlqbXlla4qMYgp1hvyfi0LW5MJMxppfGpTdr9tW139F5
9u9TreXRnEyDNzc8/oPylUODRXMPzZW+Azsfozg6ClhbKyfPqN5RZ6DLipO9yYCL6cDFKpSLmVou
Zmq5mA6gprKkPoK59AHMBEIp5UIqrQpSMUchFXNUScddoadhjhqIn+aOWudHWctinSIMc9GDvJwy
zVOjN5tAplShWFzT7E/VO523vXH7ra9c39x5+xu33/TyjS3H4ku+vGXLl5fnxhZ/advWu5blSHd8
5ezh5Yse+tf9d370xPKFX//7Ny789vVzFtzw9NptJ6/vXnDTt5h1iZ7xObS/NPgTLj6cpUllBFLJ
iCKRcUilySnpyIiGVQGvPZ2pJ52pJ91mMtPZ6Wz+kj4mlY4Se/YYNRzRaEzIpvGIu8c0zUzhFUQ0
rFRez28+6E1U04xM+bnkrm9efJvemeFnA1ZegLrzutdvmp17rG7RYP59d89Z25ol3zZ8z4UzJgqn
2gWKWuttWHrJorkbyi3jH+a0rWQljByrjMhxJXwftyRDtkJ7lQ5vXcVyUaXkoorlqoqVchVK+Xgu
m7XlNtiZSsAUiWsVCdVAKqqBVHpOO1QzmlZog2X65JYkTSa9M6GBYxk93tSIwWy1wTOYhqWaiehr
YJymWgnrTuRCGZOtc5YIm4p5vCE5NRnzOj0eWh6Lx2KpKZnKqHFlhQIZLqNql7ugfkHddqEszMqc
JY2Bru1z4tFZS2si5QU5rh0W3cR48zx/Q9ktjzSvnBVGJ4PBUo8mXlK+qCE6/ospJcLIU8vm6oWb
mxrXzq11WRIz5pRM/DYrXb5q9nqvVjMxO6NuHnqbtskz8kq0mw7y9gnSCOeAFVP/RqYyqEiRUJ0i
0YIgFVU1jkn5yURp0umis0uTsBjgvCk1BX3s3iDrwIM23BVkHU+QFUfwKexURC9+JKjYQSeP+FPS
xeWTVmYcmgqfpnE4tQw0ljTaI1W0Kmk00dkon5NJA2NV9iq7Zwas6GONQXXufM8YzU21QxTBGTtz
NSQSg7YzNjTLadaiMnkQpuNUA1WJBsqdPFOmzCcnjRp5ZdOuBwYbNy+q8xphlugsZfO2dlYPNmWV
9q6/cF1vWd36WxYkFnXPcGpUkqwxao1FzYO1lfPKA6XzN1y4YX4ZvWDJFzC1jmT6ssPw9mgzc6Kh
qnllVXPqSsrqF2yd23PpwgKrP+w02n1OB+aSadH09OJZ2ZVzZpSWzZy/FWVkRVt/DTU/k6w+7ktC
vT47zLmTR8GI0rChbKXBo3YrEgmQ5zd8NpDa4ZxAml3jYFOQ9FTbLoXZ+b7iWPhewnYqkdLQNGs6
Q3RniqnwmjJxul1YPRO3i4mVfKUyrVLmHR/fO1URV+jsaU4nd00xy2Hm5EeaN2HVzCBrj8Rm0NKx
yQ+STax4s/EiOkZyiihcUCwmm2b6GMnNpL4IIwUltKCYFmTRgiit6s3rjRYb5enuJoxjDRjm8cNc
TKnf7KmRXvEvsTEfPqbKaSP9uTG/FN4orfoKlS0tNxROpFlUE+9LH8mWQG4kIz/NKk88qqH2WCSc
5dRKNEqpS9a7skNpGS69THMlmi5rnNH0UNRG1TGLnY1Odov80tkiwVWHvHBVyTqL8eNTqlqjlRm6
VuPH31fVGcDVloCXaagY5f0vaKiIFCfTc4tobiGN+WjMS+MemkNobm/UaE/vtU8zZFFmLM+Dg+ec
aVSxbxRf2rTcKmYsyyKVf2dWO3IzI1luo2rizYnX1SZ3VigjZlWb6fDEEyatDdU05jFosMjkUhuc
menhuF1lmhip9wSsapj0ekkeH8fgK6utAY80X2rwBK1wvWFOnUZ/pzMjHq638e+xnnsp+pgG+XlY
8UkykoxYZ4VnFc2SjXpvuQk9RDnrMMpZN1FuYx0I/F7/TmKSHbcSaiKsdye1rD/CpZDvsH5JkbiB
SaXDqh2TdEmX3fs9Um4rl+pOllNSTsvLCxvzxmgwaX0xk2ZmqtLfLeyc+WtTt4oUpXxqg2fglcQE
c9mgGMhPJZYN1hTxEa4U3foyWIzMOwnbpoJ7KZVuo6yC+VGm3ML1KsVU1HI/k6estLJKbrClBQNh
S90tPW3bewrqdzyyfq+nZE7NzOGOEpMOhos2OGvhmvLhaxfEHryxedWs8MC8xs0zfSYTRl7T4obW
7NY1jbO3dGa3ls+rCKZH03U2v9WfHoimO/P79i845S1oyG2dP6sZ2r0T2n1FvRUrCrAYjzU0UENG
ZarxQyr9OKTSb7Owoq/KMfpBMuhOMLMoEYFGE0z/CTZ+JpjGE2OSIaknbkNlRYZKXTxG1U/GOoOt
ttk1oIfV3cz2Yc4LL0bDlNV4Tmfc68TGQuF/O2cX2rlfVxhFWrsH2qqX5FfKVt48mOhobY3D/+KG
GajROiM+P2zCnK729pwV1y/KedxdvjAZqU+2xJv3NtX3V/np2zufvrLVHqvNvRCdjUqFeaO6WhkP
8TH++9zqqG3OFSM7Wy5fNdORN6t04s75i2as3IP2tRgai8g/hDPxusNprCdl5gHkm6xuQb5zFMog
iuMKCYpDCzqBVGzCcw6tyXfZDXBsGZPmIgu1+N8OJw3m9jC8GdJRZ6f8pxLWS+vN7SX5Y1RzWA+1
jb+cYG7LBOpbymI8hZ6Xu7Q+4bpUgtFMjEfnHJdyRFJr/TO6+ouG71hd0bj1zoFET3OFT6+RHGZr
fEZf7a5LM5KDM2oWNiRMbMrxVbvfbvZnpzuSe47svOqZ3XW2QKbP4vQ54uGMnIzjjy+6oj+RlYjq
nPAGSWQIerkHuzFj8NZenww31FFjsIa1zho2H6thY3oNqx01rLLUPI29+YQUca0VsRqGdEjF/lQk
blLicXURq1AGZ0arsSYeVFnQLNWjvk40ddURSzcWBlGZlOo0NSUXcxG0wXOTtulNEEbV1GxDhjU1
zcSuku/R2tNcbFmk7c4lK29YlFO64pblc69Ial1hVqf0DzXta25ADUKNasyYmWyN+0UF2tW9sPuK
wyt2PH1lW0uTZBSzj/EW1J0Ve5PNl69GXWqCMSORQWjrTvRqCazSPZ7MK6psqNxcKTtZa3JGoCWn
MyOfWUD5TFt8qUDp31AXPjzWnHgwITEn+DHW2spVqcoHqdQxJYzbIHkHp2L6y8jIf+6A6maVdFJF
X1RRlSqt6NexTt+7Q5YtFsmifzdNqWCDfL2Ae04VU7X09QSvbMp6ARRKscaVMa1aoZ1Or3ySO16p
KFQr3xn3j4+GWrf0JFd1FJm0Ro0syVpj5cKtyc0Pb6udsfX+lRu+OFTwkHzJrplL6zMxyYtndF28
sNAdcGstfofZaTUZ/T5n/e6x3TtOXNbSvP3ufufltxfOXl3Fxrls7My9Wn0xLIFVox4ba4BKwwum
ei0mld4KRLFlIJVuDD7vD0eL87Ai9WLSwfyK2YYzlW2B2Jni9shsWzub0J4pZXOzxKkyxbA5lSjD
6kDKZ8VXA9xKjw09TLPV0c2L3l2Zxqqkq+GT0WjdodxgdnnE8kOMemqH9Yc6dE2Y+OsutdmYQXhp
tH1TZ3RWlkmHsdDptaj1Rr2vrKd2hdYecGZFzv4J/i+M80ad7I5kOQN27eCyaxbmmq0mJ7zKEtOC
/KT6Esxc+0jT4RbyNE4yGUgYWezrwd69D5PuyuL8nvbuMzPaIvlnKq3qyvbYbD9rMg0vn8Z6GloO
HDxlb5W+/v7Lb71wLpvCvp1aq5zuIP1kVtHLTPU3bkxY3PKTek88lB73GgzeeHoo7tE7RLYnNgom
FJDVtr7Zk58VhH9DMph09kB2WkutpA34VT9Oi7EnxNLSsv16vT/745Jzyvi0YoYHr1qYq9LpDUab
zx5J0+q0a7asDPpSdUV+EHVlHqk/Gg5HWw2sDszzY5L6YdJVU1bU1eo809AWLTpT054729+udCm8
GqS08/JbpVjwPTdRq7Dz8VzpOP6j2uDlY5dbflDkX9JpjcUVxZ76eYX2E2xQt9tOiDShm7xFVw8G
qiviXotMtXb46FFx/EIJqu/JMiqHv7y36nNry9Dg1X25Kq1Wa9AZTPD2o8bBc1ExcZt8nfwD7A6Y
gx3oLybdjoI21je36dDltEVsTjq7rawBtjWzmyCVXhnyzSdZUoN2LmjSbHXQ2XODKmuxXKbVsj4I
XTha2cmkGaSgTBsMassKVKxlJsvRHZF+9if6Izbc1p+XnTRCZluLtXJ15y9N899xu4eq5T/OaM+L
zPpFdeeSX0TmphYvGxQ768yr3GBIlJ1OJE4lvJiusQmbHVaE7XQC/xLig1VitEy4mpR5dCyuQf30
eFOzaLHwXgWjDCvy7JM1V48X9RZT6ykjjC13xuJxC6be3Mi4zmm9LJpWOnhgTtXKoMPbWPmnpi29
heUXPLR1050r8m0ZJZGSotLscFb50stm57aFqc1un5hYPVjcVuRdvaSkvcg7f3nPHyO5Pv2VF3Wt
rg/KO6LhrEVFcy6en5/ucRSGooWSQcqYOVBXv6WvJDs5UJ5RX13m98/OnzkUyx6c1b17QYFelzHx
/tK1keqOnIE14ar28WW1DZLOX5Cb425sSi+uZzX9TvQH98OeKyWXHG0op3nnFpJS3eG0FSbFunMy
Y84b4osvbLjmKzDKYGNkaQa+7gIfI5wbmuMFnVmt/tmihThgwqX8+tyEO2/EtSt2rkY7zaGR8vDZ
+QTKLd+vc3BLzVfYUVy/txlBxS0qDLi2mzsW75mdMVXnJWv3suas/r7x60UrmG61dXXMXHPdMOsX
r5r8iPaoi7C2kkFuON4QnRvdHJU9bAhAFiGVIUEJYw0JUqm8kEpNV+JRYz1PYxdRGpzniqY+7SxP
qRTO8g+eNITZCj++7qH+qN/Woejn1TOJlLsnZY9gdnzOHJmyP5ys82SVEbWQ1n9SAc78utoEw5QK
5CvFGgctrs3LrQGQ48lXJm6jq5DjLHgnrz4yt5TtuVBMTMi/sXYMyc0BkPfYUnA2+0awhAkNVLkO
UtEKJB85QZQRk7Bu0uD3k9JClsdC5PFITrjDBfvrsFpppcipvawsldlTPLfIq5o7slLOEqUZnTPm
z8t2Tyi5qi1S4NOrqKzVazVRb0ZRyCJ6Q6aDvERdXZ511Z4FCZ3BbHeY2dqq2lXQ3iEf+rQ6eDvY
i3ZQTr6YNDVU0twSWpJ00G4Y1S8qZgGIYrFDvsu0o4ShlJKncd41k5hSOvj8NUw0jYCnoIAwlfAm
4sk0qnM60lrtonnAd0SLYKJjTqhYEqVvKo4SaGaqGvxHy0V7dc7MQDDqs2omrvxk/aALdA4/FiIz
3XqzdeIpeqHZqLj1MJnW079NmD/dTM7+lF5kMOtlmGJ6k8828dREtt2d6jtoPXTmJkllPXKzsh6p
1P1pdSNVJabqCP3gqMHWqlT4VAX4zFr+6Zo9VaHPteDUW6hfhGU8j7ybDDrYWp2yyyGm+HTiikNn
Sy9tndaPKW+EsOKoVSSKBFKp1Ur/Fgp50OxDoVK+NsS6Ob5ApHRzzBo4Po95IufVY36mNIJp8zTl
sQgrXYMicXv8aRwsLiU2qhnt6sSUTZM0N3bWtxZUdxTAvEp1jyh/NjMRPt+alM8XlkRqKZT1lsrX
IfDVQ/j9P6PLZL6Cz+pD3SknVMqwUL/Iu1KnzpXfXFizvYW1Hqw8aT35TYU1O6Z6Vo0jzetJt2ln
39RRPdBcbCvo6WrLWnRRR3iqPKRozSf62E/HwF1nRBXSG3W7+uYGihpzSprznOh8Z4sxCCVYSm5P
WnkJsmJMDUefLKXUKMTVjlJLlSZzMYSMbNbINwcw22H6DgH6wfHUwMSGpaShoDPPn9UhVO+A4qdG
pkRqzSGl7f9J16nhKaXazx+eppT4pe7/y/B0nqKgoCE2OjEfwhvQEFtveiSZ1pBLcxw0105jZhoz
0ZiOxrQ0T/EJKmtIUAKkUv8glW4L8vw1JjbFCxUZqGHa4hWbTU5bvHoKp+rhRz9uJd1bUEzYM0NH
rZ0wgqWUU4b5FVI1UzgYWF+V+hEzIDE1EG4Y4WKQ36jd/s1tm79+YWXN9se2Q1Y9HqzfMLdjfXNG
sGHD3PYNzRH6+wtPXN01a//RbZCdkHs7Ll9RU7788u7Oy4drypddDt3cOXG7/Ap0wzxSB5hHKqPy
M9bm+Qh1bpGeGTFu7oxS3FLKagL3S32mN6rDNvdzvVGf5Yz6tAnj/nxn1K3Lcpobk1miq0ZlcbmD
Dm3u7O6eghUHmTOqTHFGtcabdzfVD1QF6B8v+tYVbbbM8uhEvfBBqf6IxoWNh0b9JXn1ue7ZVz6x
s+WyVTOcuU0lE3fhNMOqvawmDUFb96S0dXUyCHWFjQnWvyWY14UrQOnkEszjkofTOUq1KUtVJ0il
l4QU+w2V9od9hfC4uLM7jDMTYZUNQ756NNBZzTwutm425n+2x4U5PacceBXwXgtrW/GWi4rj/rTH
Rc+swLBLm9vZ3hFnKipdecvynNaWtjy2NdWVZtd+yusycVRoip7OrYlahefFnl2Xu0mobuKf3PXC
3XhwvSiWgfQwNFZGVh7dUkFj1lSPD6lkHZJXLkaYtWhlVrAjtREJgwRhzYoEMGpkJ/WJzpjVHelw
sxm10t0rAz5vRNOVweYVn2EH80qkkR6WNHqdzpue5fYXV9RGp9Ucpa/ObqytSTdnZKWbVDKVV3hC
dr1er3MVzq4aHxED/LmO5orK5rhV1hkMeouy86xn8oz0AnLcQV5Imoq6Grrmdl3a9USXetpCnTLm
KWF0s5Anj8AsVsLoexSJDrxxjP46GeardayKBVkVSy3WITnIuujgU/iiDbblwoAAMSURDxPqZDKG
5zWYnjBJpsLXqwx/ss+zD9m32GW+KPcrtiLX6XmHu4ahRr4cl1qMw2bfaYulRakFVGZLp3qk/3gx
TnqhbNnlc4oXtRR7DCq22JZoWFid11wajCfn9fUk47m9e3qz2mtz3VoZ1pFBo8+s7CjKS+a6c5K9
ffOTcWpp2Yjy9vpdWWEn7M9gJOiIVmbHynPCmYn6hTMqhjvyTQ63zWT12Ox+m9bj9zijxWnxipxI
Zt4M/Lcf2K0/+Vdpk+qb2F+/9GgusUcLUg1RkdAppFIWkEqDVCSUWMAqoclrLjgTbU83n/G2lzDr
W6v40s+cZoNdWWph+fQp7hBWKW3P/klfjeSe7q5QbHLWOKVNOlskt9DbuiqZvt/qYFsd94k52NvM
OeGwvl3V5s1Kc+nUerVqSXqmzaLXZGN5WbJwv9SrYkPFq9xzNWEYXK436NUWxQODfKs+hgdmFRk4
1tvYWLqqjGXIPyctVkpKM/Fr7p+zqn3ZMk1ZbM6Z/vYq5C5paO/On53W7jmjaUstGcAzVwo3JJwy
ZafYgi32mpwutSm+GThnaKqDUaUm/nwyPz270zb7TeUcF3++quRauOc6MpuYe07W6NS6RDFz5sGL
hy1ZDuvzoqFOJKYp5/M1KR8/571zMmefw/g5vr5z2nOkZ9g/V9WTk6xGyX9VF0kxUgiPupZUSPhu
Bl7T5F+jpjWSmaNFjTCSPjiaCIUS6M0+TJrkikRjuy1xpq6inU3jjmR367kb/TRcgrSo9PW3oGYo
lmkV/rxzox8Wdv9DzT0S8sAC9frhsZoo+g+1Ewyc/dJUf+b+D3XA86p6SfVz/H84Q8irBXkdTczp
ZzkNm2eZ0/BLKhILyJz2xva6ukh7cbvU3m9JnKlox1K2ajS7e+m0xsTq2Cks42EoLTpVVIbeSKln
b7F6xj2AqeryCVUoHtCKz2pv57aRYhs921iv+I2n1Kh6SWcP5RZ52lY1hCYap2kKznJrKOez2yR9
RkyO/6C0TsvblW2e7DS3FpUUrTPDZjGkWuc0LdpddrPZ/HnNllKx6j4x+akmTMntbH1H/has+lux
ulNOjXE2BsTZGBBnW2niipkRZ5Y+tmF/+CRhEyoSTg2ikEq/BvmBMv9mhDkh2AUiQvFKwIXyYVLv
LOiIG9X+Dkyt1OcWedgIK2ZTU4MCG2anbHqxyDPlXbErKxWVVVMRWN5xpLu96XZN9x2K8a51cYe8
t6i9uH5PC5Z54IFy6KemQ7v65sxYe90KKVPMeMb/MXd5U3Z/n7RTxLD2lgnP2x7oJ5/89gQO0MAe
ZVsOwsqehOwwDXESooqTCRlX9mBCii14YurjSNkhdigmWYULqjAvsNO4jeaoaWYOImZm0qxMmsEo
zgVkZdCIEhuhWREat9KLMmgGW9zQ293tGRGMuwi9k9RjIM+IYFBmIebwgHwvacIzMnI6MoyBDiM3
YaBfxUlBEoOK7Z8YxD6IwYSyQ0BJUPZFJNjQq53aBHluw5rX6a1ycstY3kMlWZo4rTIHckKhHD92
Q7ygUrPtet70KE7jTKjkjyWs6gW9IbtWvk+lN5i0Z7/BTtuodBaDvMjk0MuokdgBbNKPB0wm6Q96
9MKSzsi0XTH5kfpKaLuFvHEC25BOJmcia1i/xZ6talrFZDb2PWTQWITGwjQWorF0Gk+jOSqaK9Pa
OlpXS+sK6Ix8aotgCzW+JFJxADKJRVhERPAEGyxAJZrJJHa6dVtZtLWxQ7mOKbPBNte22XapTWVL
OjzttrKO7I7am/NpPkvLZ3aPzelpX5u/K19qQax3ttLLvgJ9JgZPNTSchi65vhWdlxQTNtVKbcYA
QzIUje0WqS0oclw7bQ+KMKenqXwaVV+pUk/8WzZ7c0LhPL9J/rYkPSGbA9iXEkdo4kO1ivXOaZkO
nfwLSXpO0jtQ7bG/UnpNoq9K2EUW8GFbtXyf1mU9VyjSjXr9+PZzRWR1afVGlBB8TeMBvR4lhK0b
OEGlG/eJkKTDpJOSXLSOLpRXEbn6BCmBYuyoediwA3ci6zHqCqkP9fFJ0HIfxd5+pW9gTUWJ8lA9
q615SCbsnhmEVkdppZEaI8xBwErFaCwpzu1ge1s6hP+N9RZ2B2XHnBTVUqZ29g8fODimbM1ge+7O
nRs7t9fFqVRivtelSeeMh0NRbHX5+WsqozsTx8fsVE99E//WUWc8kh51GVSnX1QZ7OFgerZD0k98
mG9xmtTwr2np6om7IWS1yWmhx+nDFqdZJWsM2onDdC6ErDK6rBPLWO+Bedxe6CeL9J4gQeS1Atms
CtLcIPWxJWC2hcdSaZHiehpgRnVtgPqrIev8NNzhNzg7DF2quaSLrethHsJ2MSGXrCaxxpsh89Wq
Kifbnx4rn9q95FSWPjwurVR2saakNBCxS5q9eps88YzOlhUKZbr0akrlDzT2zEhall0zccxmV5tc
FlqjchjkpW6fBXt5rObxQulVp1ENS8+BGSmRjyuedyNOirpwgkDaelSjl01YWH3jNPpuvjoz5e+m
PcK/PfGE6nTKnT2Br3qEB/9f8iL1Mnhw20ksacnKCutdR9TqYn1zLXOz08P4/lPMQl9nJzGVFSL2
5GlHMOUYMpfanvep3Taf9GXIi0oX7+/WRuPukEOnoXpHmsPTuLQmEEkOz6pdlMw1aLHQpnHV9AyX
X3DXquKJU3pfbiiSw1YlcyIhLOrIv+m/dqhS/b7Vyqo/xfji1OY2Ly2tWd4S84d8Gnu6x+d3hgOO
metuOFuXkQgajcEEDq77jUZ/Aco/b+INup28iZO4hlGjN43YXj7NVxu1Wt74q5yivdPtGovXfp3a
7PQ77V4DVV1l9GUF/Fle403h8sIC/wtY61MaIXUeCEZsGo0twlrglyb/jW+4exOnf72H2ca/k0+i
1aBk0O2jXBLPsj83bSHiwqL6GYUMm9qKClsA5m24Vt4lF8KKD2KjpfmoJtNTCsu87DQ7dsRtbj4Q
VKUOumo/I9bDattDRm/U58v0GDVmr+0atcnhd9g8Bqqe8H5GAtqdqm1/IOLQaByRQKgMWTytM2jZ
SU3dxJnPSWBvm5B3SS9Nva0x7i2belulojDFxmLl5zTL1is+rW/pJfaW16rMDp/D5jbKVxq8Ub83
6jFO3DUtAa+vUlJYttTxMF7Td1pnxGti+KL2S9G2NBqs4H5eAkqITrwtG9Tfgf9dd9imJkWwNrHu
y6Zx4kSr9hGV2ZXu9mc4VBppUGV2htzYkaJSv2/GBkCt2WnW7DFb9VCMy4zntdCjUqE0Eye5LUeJ
1ngGW9cwT0S9UnZw8CbINmVKhQ77xDIHfuhXsQlTTT+Mh8KxWEhjDxA6+S96RiXhu1WtxD6Kp5yg
aTgy/tkPUklO59kGp8PhlJ/VW/VqCRtBcN43qucn4K6aeJj+XX09zq9nJt0y6/Zl5jKQle3Xsjts
vIo0FGFqh94Z76iBoezwTh3vLZRZ/U9VLPrX5YPLl6ipJd3vCDhNcmVvdVq4preM4tSdx5tmk9Qr
fjgx8OprE4t/ZLIb1Th2pV7z0s9f37r117/46Vqch0YXjO/4oGQ33uhtvFEGKTtBHHD34J1gfyme
ViaPse3tDix+nGTDEHw+/A0TpfwVWXXhlaiyqtJRUS7FWZ8DjXo9Dvp2WnVPpWzCGc9Aupmqly5b
tkwl2dK8bhysk9bulPxbX//5S2uwQ0RSG+2m5+nDr71KH/6h3obTohqN6vTEXLzfvdI96AOvxajp
S1pCOeF4kVdrtWkMxqgR1QNL39ATtmNqNPG408Mab5VTq2Hbw6uqcAK9qrLS65VxEr3Uo5WrKj1Q
plYrd1gkrzfd9EqaHCksjMhpL5tCXi+1vP++hWKN3PSyiH/FlO71Spb35Yc10XiOQ3/3xEdWG8pL
c7fekROPai7YgO4y7tDfRdU2/Ex8fBfiY1HtBrS8CzBX+LY6ovTdd54gnRjvvVape6iTJnY20DUN
tKmBljfQrAbaMCY1JV2mtDTT7gq6oYJ2VdDaCpqooBVIeBJu6gjUwMwwVBS2HnkcjyHFOOc3NvkR
fExSt6l2srhYHcOXq4w6B5rHqPuwenlq4wCrpIlB7OUeHHyLGVaDypxWYeixMDyi/NC6mPuIbcE8
b++29hPe3dR+J/nb5Rsf2tqzd+nMbJujcO6uhy7Mnp3Mt2hVEsVqmjFW2V3GNlzIgcbuhSXrbx6I
Pe6tXDwru7OlIZDRsKwhuaw+nX6t775LOnI6Nx58cNn8R++9fu0MvdVhNFudFixp6ix2y+wD31hq
DfmsNauvG6pdPivL7A07Lnt8fUFxz2rWq7VDt88pZ1USWCHzf2LhIFssHMBxdDKZzZReQKctCbB1
MBebs7nYoQ0XO37uelrCd3OQCHc4RVLVH1LxDEMqEzfId9iIgTkG/gvYgqTewI7BJInMnPNJPYqn
yDDXIBFl5oEQzmOhpNhLsFLCniR8Axi2XhlwBIadERFHYJh9puy8Z2aZ7S1mmWEjB3dlMRcfyo7/
fHLExuoD5uFTJ7NV8nNFm0Yu2/3wmkTxxpEDeyBHLMHEjO7ivg0zPaHG1e3VfTNzfHrp4Bf/dXh4
0Tf+ff/t/1bkY8N3XdRX5Z93w7c23vKjA7VZTcu2XYUq9zjsmPvUXvhUfp/MygrRrHSalUajQZoV
oFn+1I7qXGXRxsFs0GKWUzNTdzElTLUkl82zkAKp9CeKhPYhFYVCKkZuLjtUYwlhhzq25hvZpxFT
P6XCQ758BM+EPMkeNS3+JJvCIQzV44778Q0UTvgyGo5Ee3Ph6tHys3ulDeMY2rlOE6exa4ZvaEt8
T9Es4ZM6rl5lAn1uq74dfQrfGlOVzVuCW/FdyPdpcHZ4fKnWZNRocASaWj5ibiycXNDTPJUJIySm
zpp3dRa9upl5SLW2AE5B2/Xyz79oUJlDXrvPZtI8I6uw/xDbAT++SY8hBtreBm3fgzpdjxVDc24l
TYRobjqbtSWZWpWuI0k9bIOxRxksPExNHlTDJ8uy8UtqUrqueQpfBG6EsqAcI5u0GVETjfbqmkik
BpWv8Mkyj6Zwvg0rPzlCQ9zbzM6Is4nvW4nTrDoqFZDVPqLMxs5TDpvefmIDt4a7dZjxoBxyuEeN
0W+8wuK2amWD1fTxovU1jrSKeeXK9m1MB1T4AgFf3cAFdctuHCz0tF29+bRUhp386k52gkNrC3lc
6JLN1LD01otXJBLdtZmZOZk6R8gNt7LFnRX1VSzd3VK/56Yntr2qdyge/rXoE26F/vqp+gQWF08m
01hNXExLdFBZCRtkSxS9lTC9lYxJFUnDnPmxOXN88A5Axe8kY7gkxiatScTGkrIlyO7kHn3lziC7
E5u7lCobhOaPKRMxNHDsKUH7tqSqLKRS2yFPJp0oBktdEo+tY9Pn2UV1VKnKiGAyaWCRdfY6uwdb
yo1JQ8f8/L9HIuoOdjjHOHU4B7vybFPnczAhZnNldOq8j8AYqOwDw0awGt5tTOvZNcqmmpDyzQ1K
kSkucbbf6zPmBecK0R2S5Vvrdzx6QePW/lqrTiNbzPqK+ZubZ61qzkzMv6R7D8pKqzFa9Ftnre+I
B8p7KmqHZ5diiqCVYWk4a/s2Jxdfu6QgUr+4rmnzvAK6beCmNVXu9LDFAtstKy2SHcms7yut6k9m
onm4nX6rNjM5UJXTURmO5kTV1qDH6rVbnCjnwgU722au76kxStqKeReg72dnO36Gsx156Jc+TtYy
F0cBjefTrDjNitHsNBoL0qjSQWX7aDa+l8NDY24ac9GYDQtdNEtNs1Q0EaRKb+XgvVWBxwfiYZ0Y
5ttKv8PkcZSdJ60QJ9omzybTcYWNNT9mAOCDeUjYIGJjRpyNfaNEnKh4X4VNxy+y5sc2IScNSFap
ioviQawgooBViQybzZDRa2DHAjEaO2rK4G1NzdETqRWMBI7fsu18bGO7aIFiFJgaDBQX6pQ7P3XE
SJjJrK/y4IBNhvwzl+NWcdJ2/F2TzQxb0KClP1U7Q/mhjJKQ7Va7e+IBaWIJfZhuyYhNvCe8z9Sm
sYV8zpDfa5YdWGjEV++Y9We/H5X+OF7LeqzVaHF34FRVPXk2aY5X0XilsmwvKz3Wk0yzSVqV6pUg
8W05qOpV7BhVDip+DlSZw9pFjmVu6ebSS0vl0s8+VPkUTo6yM/h4IBtL2X5vLESCHWeHXZxOHxpO
ftKUX/uPCDulos7v8Z3XdAZxnI1tN6G2V1Mt5tTgy7zxcOWy/i01tKK1cOv1XONQ5oPieyOY3zoj
tXFPvqP1wOGNMzYuqLTii4qwSK015LWtb2/a0lMY79m7cGZ/LM0XTpdm6qwGtcsxkR7tKN780OYa
ev+6r26utft9FpM94LDjizJwKiXSvLazfnlD2BTIlqwZEcy9nVk5E19USxXDB7G+kbIl8T8ANMJK
kUgvNP8Q+rpifC/Vt5NOHG/KU9Ncxa+Xh+8CMdBm1rVEWBE0owNEVeV9X/ruElpT0lGyvkROYDMY
O4SoJxZLBF+nzKwWVHxFx28eZTquYz0dboV8L+lg3dTOOlpZ11q3pk7OgvdwTEokLUXZWAH+WySi
rfxH3nzoXXdYy8/1ombD9FSMTrZXNaEcCkLVxbThnNYVvbOlhPOWL6umnRMSh2GnrJxK+SFXcc+e
b2xJ9DTm49CYxqgz5szsLRu+vj9fqrh9aONtA/HSDQ9u69m3NBm3P5E5a6ihcWldmr968ayuG6Sn
Fjx23/Xr6ow2hyMc8AQsanxnQtf+h5aGi+vW3DB/4d0XteZ2bzr4QOuBJzYWF81dVVG3ojmbGYao
7Q6A/WiIhZDGWW1NixclmoY3rl+xbf3/Ac2H1KAKZW5kc3RyZWFtCmVuZG9iago1NyAwIG9iagox
ODkxOQplbmRvYmoKNTggMCBvYmoKKDZUaVNDSF9XSF9mbG93LnBwdHgpCmVuZG9iago1OSAwIG9i
agooTWFjIE9TIFggMTAuOS4zIFF1YXJ0eiBQREZDb250ZXh0KQplbmRvYmoKNjAgMCBvYmoKKEpv
bmF0aGFuIFNpbW9uKQplbmRvYmoKNjEgMCBvYmoKKCkKZW5kb2JqCjYyIDAgb2JqCihQb3dlclBv
aW50KQplbmRvYmoKNjMgMCBvYmoKKEQ6MjAxNDA1MzAyMDI5MTVaMDAnMDAnKQplbmRvYmoKNjQg
MCBvYmoKKCkKZW5kb2JqCjY1IDAgb2JqClsgKCkgXQplbmRvYmoKMSAwIG9iago8PCAvVGl0bGUg
NTggMCBSIC9BdXRob3IgNjAgMCBSIC9TdWJqZWN0IDYxIDAgUiAvUHJvZHVjZXIgNTkgMCBSIC9D
cmVhdG9yCjYyIDAgUiAvQ3JlYXRpb25EYXRlIDYzIDAgUiAvTW9kRGF0ZSA2MyAwIFIgL0tleXdv
cmRzIDY0IDAgUiAvQUFQTDpLZXl3b3Jkcwo2NSAwIFIgPj4KZW5kb2JqCnhyZWYKMCA2NgowMDAw
MDAwMDAwIDY1NTM1IGYgCjAwMDAyNDE4MzMgMDAwMDAgbiAKMDAwMDAwMDUzMSAwMDAwMCBuIAow
MDAwMjEyMjI4IDAwMDAwIG4gCjAwMDAwMDAwMjIgMDAwMDAgbiAKMDAwMDAwMDUxMiAwMDAwMCBu
IAowMDAwMDAwNjM1IDAwMDAwIG4gCjAwMDAwMDE5MTUgMDAwMDAgbiAKMDAwMDAwNDY4NyAwMDAw
MCBuIAowMDAwMDAwMDAwIDAwMDAwIG4gCjAwMDAyMjExMTUgMDAwMDAgbiAKMDAwMDAwMDc0NCAw
MDAwMCBuIAowMDAwMDAxODk0IDAwMDAwIG4gCjAwMDAwMDE5NTEgMDAwMDAgbiAKMDAwMDAwNDY2
NiAwMDAwMCBuIAowMDAwMDA2NTA5IDAwMDAwIG4gCjAwMDAwMDQ3MjMgMDAwMDAgbiAKMDAwMDAw
NjQ4OCAwMDAwMCBuIAowMDAwMDA2NjE2IDAwMDAwIG4gCjAwMDAyMTIzOTYgMDAwMDAgbiAKMDAw
MDAwMDAwMCAwMDAwMCBuIAowMDAwMjE3NTUzIDAwMDAwIG4gCjAwMDAwMDY4MDEgMDAwMDAgbiAK
MDAwMDA0MjU1NiAwMDAwMCBuIAowMDAwMDk0NTY1IDAwMDAwIG4gCjAwMDAwNDI1NzggMDAwMDAg
biAKMDAwMDA5MzM3MiAwMDAwMCBuIAowMDAwMDkzMzk0IDAwMDAwIG4gCjAwMDAwOTQ1NDQgMDAw
MDAgbiAKMDAwMDA5NzUyNSAwMDAwMCBuIAowMDAwMDk0NjAyIDAwMDAwIG4gCjAwMDAwOTc1MDQg
MDAwMDAgbiAKMDAwMDA5NzYzMiAwMDAwMCBuIAowMDAwMDk3ODE3IDAwMDAwIG4gCjAwMDAxMzI4
NzAgMDAwMDAgbiAKMDAwMDIxMDkzMSAwMDAwMCBuIAowMDAwMTMyODkyIDAwMDAwIG4gCjAwMDAy
MDk3MzggMDAwMDAgbiAKMDAwMDIwOTc2MCAwMDAwMCBuIAowMDAwMjEwOTEwIDAwMDAwIG4gCjAw
MDAyMTE5ODcgMDAwMDAgbiAKMDAwMDIxMDk2OCAwMDAwMCBuIAowMDAwMjExOTY3IDAwMDAwIG4g
CjAwMDAyMTIwOTQgMDAwMDAgbiAKMDAwMDIxMjMzMiAwMDAwMCBuIAowMDAwMjEyNTcxIDAwMDAw
IG4gCjAwMDAyMTI4MzEgMDAwMDAgbiAKMDAwMDIxNzUzMiAwMDAwMCBuIAowMDAwMjE4MDM2IDAw
MDAwIG4gCjAwMDAyMTc3MTggMDAwMDAgbiAKMDAwMDIxODAxNiAwMDAwMCBuIAowMDAwMjE4Mjg2
IDAwMDAwIG4gCjAwMDAyMjEwOTQgMDAwMDAgbiAKMDAwMDIyMjMxMSAwMDAwMCBuIAowMDAwMjIx
NTU1IDAwMDAwIG4gCjAwMDAyMjIyOTEgMDAwMDAgbiAKMDAwMDIyMjU0NiAwMDAwMCBuIAowMDAw
MjQxNTU2IDAwMDAwIG4gCjAwMDAyNDE1NzggMDAwMDAgbiAKMDAwMDI0MTYxNiAwMDAwMCBuIAow
MDAwMjQxNjY4IDAwMDAwIG4gCjAwMDAyNDE3MDEgMDAwMDAgbiAKMDAwMDI0MTcyMCAwMDAwMCBu
IAowMDAwMjQxNzQ5IDAwMDAwIG4gCjAwMDAyNDE3OTEgMDAwMDAgbiAKMDAwMDI0MTgxMCAwMDAw
MCBuIAp0cmFpbGVyCjw8IC9TaXplIDY2IC9Sb290IDQ0IDAgUiAvSW5mbyAxIDAgUiAvSUQgWyA8
MDkzY2FkYTc0NTcwNDA5MWQwNmRhMTYyMGI2OWVhYTM+CjwwOTNjYWRhNzQ1NzA0MDkxZDA2ZGEx
NjIwYjY5ZWFhMz4gXSA+PgpzdGFydHhyZWYKMjQyMDA4CiUlRU9GCg==

--Apple-Mail=_904A7E38-7FD4-4117-BC34-C265DA8DB008
Content-Transfer-Encoding: quoted-printable
Content-Type: text/html;
	charset=us-ascii

<html><head><meta http-equiv=3D"Content-Type" content=3D"text/html =
charset=3Dus-ascii"></head><body style=3D"word-wrap: break-word; =
-webkit-nbsp-mode: space; -webkit-line-break: =
after-white-space;"><br><div apple-content-edited=3D"true">
<span class=3D"Apple-style-span" style=3D"border-collapse: separate; =
border-spacing: 0px;"><span class=3D"Apple-style-span" =
style=3D"border-collapse: separate; color: rgb(0, 0, 0); font-family: =
'Lucida Grande'; font-style: normal; font-variant: normal; font-weight: =
normal; letter-spacing: normal; line-height: normal; orphans: 2; =
text-align: -webkit-auto; text-indent: 0px; text-transform: none; =
white-space: normal; widows: 2; word-spacing: 0px; =
-webkit-border-horizontal-spacing: 0px; -webkit-border-vertical-spacing: =
0px; -webkit-text-decorations-in-effect: none; -webkit-text-size-adjust: =
auto; -webkit-text-stroke-width: 0px;  "><div style=3D"word-wrap: =
break-word; -webkit-nbsp-mode: space; -webkit-line-break: =
after-white-space; "><span class=3D"Apple-style-span" =
style=3D"border-collapse: separate; color: rgb(0, 0, 0); font-family: =
'Lucida Grande'; font-style: normal; font-variant: normal; font-weight: =
normal; letter-spacing: normal; line-height: normal; orphans: 2; =
text-align: -webkit-auto; text-indent: 0px; text-transform: none; =
white-space: normal; widows: 2; word-spacing: 0px; =
-webkit-border-horizontal-spacing: 0px; -webkit-border-vertical-spacing: =
0px; -webkit-text-decorations-in-effect: none; -webkit-text-size-adjust: =
auto; -webkit-text-stroke-width: 0px;  "><div style=3D"word-wrap: =
break-word; -webkit-nbsp-mode: space; -webkit-line-break: =
after-white-space; ">--&nbsp;<br>Jonathan Simon, Ph. D<br>Director of =
Systems Engineering<br>Linear Technology, Dust Networks product =
group<br>30695 Huntwood Ave<br>Hayward, CA 94544-7021<br>(510) =
400-2936<br>(510) 489-3799 FAX<br><a =
href=3D"mailto:jsimon@linear.com">jsimon@linear.com</a><br><br>**LINEAR =
TECHNOLOGY&nbsp;CORPORATION**&nbsp;<br>*****Internet Email =
Confidentiality&nbsp;Notice*****&nbsp;<br>&nbsp;This e-mail =
transmission, and any&nbsp;documents, files or previous =
e-mail&nbsp;messages attached to it may contain&nbsp;confidential =
information that is&nbsp;legally privileged. If you are not =
the&nbsp;intended recipient, or a person&nbsp;responsible for delivering =
it to the&nbsp;intended recipient, you are hereby&nbsp;notified that any =
disclosure, copying,&nbsp;distribution or use of any of =
the&nbsp;information contained in or attached&nbsp;to this transmission =
is STRICTLY&nbsp;PROHIBITED. If you have received this&nbsp;transmission =
in error, please&nbsp;immediately notify me by reply e-mail, or by =
telephone at (510) 400-2936, and destroy the original&nbsp;transmission =
and its attachments&nbsp;without reading or saving in any&nbsp;manner. =
Thank you.&nbsp;<br></div></span></div></span></span>
</div>
<br></body></html>=

--Apple-Mail=_904A7E38-7FD4-4117-BC34-C265DA8DB008--

--Apple-Mail=_EF27AA93-E7D9-4D5B-8860-E70520FF1162--


From nobody Fri May 30 18:11:54 2014
Return-Path: <mcr@sandelman.ca>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 133B51A06DA for <6tisch-security@ietfa.amsl.com>; Fri, 30 May 2014 18:11:53 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.542
X-Spam-Level: 
X-Spam-Status: No, score=-2.542 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RP_MATCHES_RCVD=-0.651, SPF_PASS=-0.001, T_TVD_MIME_NO_HEADERS=0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id I11z7fgUngsa for <6tisch-security@ietfa.amsl.com>; Fri, 30 May 2014 18:11:51 -0700 (PDT)
Received: from tuna.sandelman.ca (tuna.sandelman.ca [209.87.252.184]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 2BC3C1A043C for <6tisch-security@ietf.org>; Fri, 30 May 2014 18:11:51 -0700 (PDT)
Received: from sandelman.ca (desk.marajade.sandelman.ca [209.87.252.247]) by tuna.sandelman.ca (Postfix) with ESMTP id D971320028; Fri, 30 May 2014 21:14:40 -0400 (EDT)
Received: by sandelman.ca (Postfix, from userid 179) id 6F60863B0E; Fri, 30 May 2014 21:11:42 -0400 (EDT)
Received: from sandelman.ca (localhost [127.0.0.1]) by sandelman.ca (Postfix) with ESMTP id 5830A63AED; Fri, 30 May 2014 21:11:42 -0400 (EDT)
From: Michael Richardson <mcr+ietf@sandelman.ca>
To: 6tisch-security@ietf.org
In-Reply-To: <07C11C3C-2C8D-461D-9D52-885BCFEAF5D1@linear.com>
References: <07C11C3C-2C8D-461D-9D52-885BCFEAF5D1@linear.com>
X-Mailer: MH-E 8.2; nmh 1.3-dev; GNU Emacs 23.4.1
X-Face: $\n1pF)h^`}$H>Hk{L"x@)JS7<%Az}5RyS@k9X%29-lHB$Ti.V>2bi.~ehC0; <'$9xN5Ub# z!G,p`nR&p7Fz@^UXIn156S8.~^@MJ*mMsD7=QFeq%AL4m<nPbLgmtKK-5dC@#:k
MIME-Version: 1.0
Content-Type: multipart/signed; boundary="=-=-="; micalg=pgp-sha1; protocol="application/pgp-signature"
Date: Fri, 30 May 2014 21:11:42 -0400
Message-ID: <25083.1401498702@sandelman.ca>
Sender: mcr@sandelman.ca
Archived-At: http://mailarchive.ietf.org/arch/msg/6tisch-security/Ke_TOMBmUO8esevK_Hc2ujJFiMM
Cc: Jonathan Simon <jsimon@linear.com>
Subject: Re: [6tisch-security] WirelessHART-like joining flow
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sat, 31 May 2014 01:11:53 -0000

--=-=-=


Thanks for those slides.
Some questions/clarifications:

SLIDE 2:

1) it isn't clear in the slide that the PSK is (pre-)shared between the
   PCE/manager and the Joining Node.

SLIDE 3:

>(2)  For  PK,  plaintext  certificate  request (CoAP)   authenticated
>       with  same  key  as Beacon.  This  step  is  not  needed  if
>       using PSK.

I think that this step is wrong.  I don't think one could send a certificate
request here, and I don't think the proxy could answer with a certificate.
If it went to the PCE, I might buy it.

Thinking more about it on my way home, I think that the words "certificate
request" are wrong.  I think the goal is for the joining node to ask the
proxy for the PCE's certificate.  A "certificate request" is something else.

My question would be if (4) and (5) could be done in 6top format.
The other question is: are there advantages if the PCE actually initiates
the conversation.

You ask: Can we start a DTLS session without DH for PSK?
RFC 4279  section 2 says yes.

--
Michael Richardson <mcr+IETF@sandelman.ca>, Sandelman Software Works
 -= IPv6 IoT consulting =-




--=-=-=
Content-Type: application/pgp-signature

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iQEVAwUBU4ksS4CLcPvd0N1lAQIMSAgAiEdHh6j/vNVdlKHjUEczc1EUgqPhZt3Y
CKbrYuCBk89rAXK8O6Gj5tVIhnzzafvs7PXTmxF82dbA7nvH0SUBwaLvYYUepQFf
L1uwISycuFDNzctzvCRxZBHhKwtJb7/ueiXhpRd6fDDtgk66mmIN4+3dD3Zy0yqm
d0ZmLcWDtHXDRBXdGlpr+odfwVxa2tB64Vn6tKRjM/sQ3vTKlxQb60HO8QzlgBSk
oGno/YTyUNorv6VFa0w79+nGc363DtKxubG4Q7jciXcZDdIIGtcHtWt40HkRJJd5
iNrdlHV1hcK2N82Q6Ptdg/SiMbAMNDMW8lhJG7nrTBqHO1aFjbmnEA==
=Ymui
-----END PGP SIGNATURE-----
--=-=-=--

