
From nobody Wed Jul  2 07:10:40 2014
Return-Path: <hannes.tschofenig@gmx.net>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 2BB841A00E8 for <ace@ietfa.amsl.com>; Wed,  2 Jul 2014 07:10:38 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.551
X-Spam-Level: 
X-Spam-Status: No, score=-2.551 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, FREEMAIL_FROM=0.001, RCVD_IN_DNSWL_NONE=-0.0001, RP_MATCHES_RCVD=-0.651, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id ImDeP39US1qp for <ace@ietfa.amsl.com>; Wed,  2 Jul 2014 07:10:36 -0700 (PDT)
Received: from mout.gmx.net (mout.gmx.net [212.227.17.21]) (using TLSv1.2 with cipher DHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id B653F1A0065 for <ace@ietf.org>; Wed,  2 Jul 2014 07:10:35 -0700 (PDT)
Received: from [192.168.131.128] ([80.92.115.50]) by mail.gmx.com (mrgmx101) with ESMTPSA (Nemesis) id 0MgGDK-1XF2nn47cc-00Njlh for <ace@ietf.org>; Wed, 02 Jul 2014 16:10:34 +0200
Message-ID: <53B412D8.3090406@gmx.net>
Date: Wed, 02 Jul 2014 16:10:32 +0200
From: Hannes Tschofenig <hannes.tschofenig@gmx.net>
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:24.0) Gecko/20100101 Thunderbird/24.6.0
MIME-Version: 1.0
To: "ace@ietf.org" <ace@ietf.org>
X-Enigmail-Version: 1.5.2
OpenPGP: id=4D776BC9
Content-Type: multipart/signed; micalg=pgp-sha512; protocol="application/pgp-signature"; boundary="bCkgSsLQqGNRxDJdjfEKxnjLws3L125ax"
X-Provags-ID: V03:K0:c7scRgeW7ThWLD7R3334AlbY1lst2XYkb2PTmKh0loV4f+vpFsX tBNqyiL8KDiFg6qd3xIYC6KAVXF67tVYJ/WfVIdQy0MBZH/Q63wwHzNXV/suQ1viP2pTVIu J2GSeOfE7Os7bWXOmPLjzy/x+NL7vqW0M1wZZ2EHpCNUSnwZgWw0AbvmIhmoNv9EFKl6H5z GaX4JgKsWtXbulULZAJNw==
Archived-At: http://mailarchive.ietf.org/arch/msg/ace/BDo70tpl7Zxp2knAUiU_wLMaCDo
Subject: [Ace] Draft Submission Deadline Approaching!
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 02 Jul 2014 14:10:38 -0000

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--bCkgSsLQqGNRxDJdjfEKxnjLws3L125ax
Content-Type: text/plain; charset=ISO-8859-1
Content-Transfer-Encoding: quoted-printable

Hi all,

at the next IETF meeting we are going to meet for the first time as a
working group.

Note that the draft submission deadline is already this Friday by UTC
23:59.

Make sure that you post your drafts as draft-lastname-ace-... so that
the documents also show up in the working group.

Please also let us know if you would like a presentation slot. We will
obviously focus some time on the use cases/requirements.

Ciao
Hannes


--bCkgSsLQqGNRxDJdjfEKxnjLws3L125ax
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
Content-Disposition: attachment; filename="signature.asc"

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1
Comment: GPGTools - http://gpgtools.org
Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/

iQEcBAEBCgAGBQJTtBLYAAoJEGhJURNOOiAtUXwIAIXkAbSwiFND6h9eU4OKceuG
2Ggx6wJjk73mvyjsm0AKJh/bFMVKo14AufHOLViLHY8qoVNcq6qjPbI/Ydc+XyvJ
XucupwfO9QQ6hoKZFTf61qL0yxedvyFEqsxj6sSRiDexdVY2OZe4ao9o7DWkWYi8
OIFhG3EKqPO16KSRiW+mVPFkHuY3yZpn8Yib013M5n+Ftln25B0cKkUdaSZdYmgo
CfHg2HJHxXRAAfTR9oUL574utEIMPuOzeI4QAH8MgwpMvFGZAId29Uvtt9giKe4Z
dremmNIN99I3fjHNP5ZGJEPPiLW5L/0VdDRe41q0KMpFMbYuZINc5vYobq2gHXw=
=qi0x
-----END PGP SIGNATURE-----

--bCkgSsLQqGNRxDJdjfEKxnjLws3L125ax--


From nobody Wed Jul  2 07:11:18 2014
Return-Path: <ludwig@sics.se>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 7E1891A016F for <ace@ietfa.amsl.com>; Wed,  2 Jul 2014 07:11:16 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.901
X-Spam-Level: 
X-Spam-Status: No, score=-2.901 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HELO_EQ_SE=0.35, RCVD_IN_DNSWL_LOW=-0.7, RP_MATCHES_RCVD=-0.651] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id A6JxwSWURmFn for <ace@ietfa.amsl.com>; Wed,  2 Jul 2014 07:11:08 -0700 (PDT)
Received: from outbox.sics.se (outbox.sics.se [193.10.64.137]) by ietfa.amsl.com (Postfix) with ESMTP id 1B2D71A00E8 for <ace@ietf.org>; Wed,  2 Jul 2014 07:11:08 -0700 (PDT)
Received: from e-mailfilter01.sunet.se (e-mailfilter01.sunet.se [192.36.171.201]) by outbox.sics.se (Postfix) with ESMTPS id A80B55D7E for <ace@ietf.org>; Wed,  2 Jul 2014 16:11:06 +0200 (CEST)
Received: from letter.sics.se (letter.sics.se [193.10.64.6]) by e-mailfilter01.sunet.se (8.14.4/8.14.4/Debian-4) with ESMTP id s62EB60N030278 for <ace@ietf.org>; Wed, 2 Jul 2014 16:11:06 +0200
Received: from [192.168.0.108] (unknown [85.235.11.178]) (Authenticated sender: ludwig@sics.se) by letter.sics.se (Postfix) with ESMTPSA id B3AF040116 for <ace@ietf.org>; Wed,  2 Jul 2014 16:11:14 +0200 (CEST)
Message-ID: <53B412F9.7020505@sics.se>
Date: Wed, 02 Jul 2014 16:11:05 +0200
From: Ludwig Seitz <ludwig@sics.se>
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:24.0) Gecko/20100101 Thunderbird/24.6.0
MIME-Version: 1.0
To: "ace@ietf.org" <ace@ietf.org>
References: <20140702140149.1121.81148.idtracker@ietfa.amsl.com>
In-Reply-To: <20140702140149.1121.81148.idtracker@ietfa.amsl.com>
X-Forwarded-Message-Id: <20140702140149.1121.81148.idtracker@ietfa.amsl.com>
Content-Type: multipart/signed; protocol="application/pkcs7-signature"; micalg=sha1; boundary="------------ms080708000207090007030301"
X-Bayes-Prob: 0.0001 (Score 0, tokens from: outbound, outbound-sics-se:default, sics-se:default, base:default, @@RPTN)
X-p0f-Info: os=Solaris 10, link=Ethernet or modem
X-CanIt-Geo: =?UTF-8?Q?ip=3D85.235.11.178; _country=3DSE; _region=3DSk=C3=A5ne; _city=3DLund; _latitude=3D55.7000; _longitude=3D13.1833; _http://maps.google.com/maps=3Fq=3D55.7000,13.1833&z=3D6?=
X-CanItPRO-Stream: outbound-sics-se:outbound (inherits from outbound-sics-se:default, sics-se:default, base:default)
X-Canit-Stats-ID: 09Mlqb6yH - 0ff93be5873f - 20140702
X-Antispam-Training-Forget: https://canit.sunet.se/canit/b.php?i=09Mlqb6yH&m=0ff93be5873f&t=20140702&c=f
X-Antispam-Training-Nonspam: https://canit.sunet.se/canit/b.php?i=09Mlqb6yH&m=0ff93be5873f&t=20140702&c=n
X-Antispam-Training-Spam: https://canit.sunet.se/canit/b.php?i=09Mlqb6yH&m=0ff93be5873f&t=20140702&c=s
X-CanIt-Archive-Cluster: PfMRe/vJWMiXwM2YIH5BVExnUnw
X-Scanned-By: CanIt (www . roaringpenguin . com) on 192.36.171.201
Archived-At: http://mailarchive.ietf.org/arch/msg/ace/TkXfFObzifCx4xbGmKA4sXBD7vk
Subject: [Ace] Fwd: New Version Notification for draft-seitz-ace-usecases-01.txt
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 02 Jul 2014 14:11:16 -0000

This is a cryptographically signed message in MIME format.

--------------ms080708000207090007030301
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: quoted-printable

Hello,

we have updated large parts of the use cases draft based on industry=20
input. I hope you find your use case represented somewhere.

Note: Since we didn't have any concrete industry support for the=20
Industrial Control System (ICS/SCADA) use case, we removed it from the=20
document provisionally. If someone wants to get such a case back in,=20
please come forward and describe your use case to us.

/Ludwig

-------- Original Message --------
Subject: New Version Notification for draft-seitz-ace-usecases-01.txt
Date: Wed, 02 Jul 2014 07:01:49 -0700
From: internet-drafts@ietf.org
To: Mehdi Mani <mehdi.mani@itron.com>, Sandeep Kumar=20
<sandeep.kumar@philips.com>, Goeran Selander=20
<goran.selander@ericsson.com>, Sandeep S. Kumar=20
<sandeep.kumar@philips.com>, Ludwig Seitz <ludwig@sics.se>, Goran=20
Selander <goran.selander@ericsson.com>, Stefanie Gerdes=20
<gerdes@tzi.org>, Stefanie Gerdes <gerdes@tzi.org>, Ludwig Seitz=20
<ludwig@sics.se>, Mehdi Mani <mehdi.mani@itron.com>


A new version of I-D, draft-seitz-ace-usecases-01.txt
has been successfully submitted by Ludwig Seitz and posted to the
IETF repository.

Name:		draft-seitz-ace-usecases
Revision:	01
Title:		ACE use cases
Document date:	2014-07-02
Group:		Individual Submission
Pages:		21
URL:=20
http://www.ietf.org/internet-drafts/draft-seitz-ace-usecases-01.txt
Status:         https://datatracker.ietf.org/doc/draft-seitz-ace-usecases=
/
Htmlized:       http://tools.ietf.org/html/draft-seitz-ace-usecases-01
Diff:           http://www.ietf.org/rfcdiff?url2=3Ddraft-seitz-ace-usecas=
es-01

Abstract:
    This document presents use cases for authentication and access
    control in scenarios involving constrained RESTful devices.  Where
    specific details are relevant, it is assumed that the devices use
    CoAP as communication protocol, however most conclusions apply
    generally.

    A number of security requirements are derived from the use cases,
    which are intended as a guideline for developing a comprehensive
    authentication and access control approach for this class of
    scenarios.

=20



Please note that it may take a couple of minutes from the time of submiss=
ion
until the htmlized version and diff are available at tools.ietf.org.

The IETF Secretariat





--------------ms080708000207090007030301
Content-Type: application/pkcs7-signature; name="smime.p7s"
Content-Transfer-Encoding: base64
Content-Disposition: attachment; filename="smime.p7s"
Content-Description: S/MIME Cryptographic Signature

MIAGCSqGSIb3DQEHAqCAMIACAQExCzAJBgUrDgMCGgUAMIAGCSqGSIb3DQEHAQAAoIIMVDCC
BhgwggUAoAMCAQICAwiRTjANBgkqhkiG9w0BAQsFADCBjDELMAkGA1UEBhMCSUwxFjAUBgNV
BAoTDVN0YXJ0Q29tIEx0ZC4xKzApBgNVBAsTIlNlY3VyZSBEaWdpdGFsIENlcnRpZmljYXRl
IFNpZ25pbmcxODA2BgNVBAMTL1N0YXJ0Q29tIENsYXNzIDEgUHJpbWFyeSBJbnRlcm1lZGlh
dGUgQ2xpZW50IENBMB4XDTE0MDEwNzA3MjgzNVoXDTE1MDEwNzEyNTgyMlowODEXMBUGA1UE
AwwObHVkd2lnQHNpY3Muc2UxHTAbBgkqhkiG9w0BCQEWDmx1ZHdpZ0BzaWNzLnNlMIIBIjAN
BgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAnLm1tc30QxHa9wtdVjC3NgxjLJicnccm0HD+
1X16kPMKGvwps8F1oDhYn7jXIe46p1AuJMzLK0GIioE4JwxCFGdvpz7cg2xyTyrdBVUzSqez
Dfqt4FOJq6hrdrIMS8MHEzl7Jk02gv9cTn/pHQvDpkiThRpbSLU5mlMqtEQ8gDQY5YyBX0Mv
5qculV08I2JU8HEeTt1oeqhvBImgQfOVYMDatHlWHUVVrmYd6iIo+cuiUGd5kiA0XuaLYX0E
oCoao/z5Wg9U0sQlx0hl4r96Q+NdoZZ1prfts3qtyBzJ2hu135aikigzJ6sueWHv/jbISUek
tOMm0xkx1GOqqWtEAwIDAQABo4IC1DCCAtAwCQYDVR0TBAIwADALBgNVHQ8EBAMCBLAwHQYD
VR0lBBYwFAYIKwYBBQUHAwIGCCsGAQUFBwMEMB0GA1UdDgQWBBRZmjjBh8N3klra+mVQgC00
pl68ZTAfBgNVHSMEGDAWgBRTcu2SnODaywFcfH6WNU7y1LhRgjAZBgNVHREEEjAQgQ5sdWR3
aWdAc2ljcy5zZTCCAUwGA1UdIASCAUMwggE/MIIBOwYLKwYBBAGBtTcBAgMwggEqMC4GCCsG
AQUFBwIBFiJodHRwOi8vd3d3LnN0YXJ0c3NsLmNvbS9wb2xpY3kucGRmMIH3BggrBgEFBQcC
AjCB6jAnFiBTdGFydENvbSBDZXJ0aWZpY2F0aW9uIEF1dGhvcml0eTADAgEBGoG+VGhpcyBj
ZXJ0aWZpY2F0ZSB3YXMgaXNzdWVkIGFjY29yZGluZyB0byB0aGUgQ2xhc3MgMSBWYWxpZGF0
aW9uIHJlcXVpcmVtZW50cyBvZiB0aGUgU3RhcnRDb20gQ0EgcG9saWN5LCByZWxpYW5jZSBv
bmx5IGZvciB0aGUgaW50ZW5kZWQgcHVycG9zZSBpbiBjb21wbGlhbmNlIG9mIHRoZSByZWx5
aW5nIHBhcnR5IG9ibGlnYXRpb25zLjA2BgNVHR8ELzAtMCugKaAnhiVodHRwOi8vY3JsLnN0
YXJ0c3NsLmNvbS9jcnR1MS1jcmwuY3JsMIGOBggrBgEFBQcBAQSBgTB/MDkGCCsGAQUFBzAB
hi1odHRwOi8vb2NzcC5zdGFydHNzbC5jb20vc3ViL2NsYXNzMS9jbGllbnQvY2EwQgYIKwYB
BQUHMAKGNmh0dHA6Ly9haWEuc3RhcnRzc2wuY29tL2NlcnRzL3N1Yi5jbGFzczEuY2xpZW50
LmNhLmNydDAjBgNVHRIEHDAahhhodHRwOi8vd3d3LnN0YXJ0c3NsLmNvbS8wDQYJKoZIhvcN
AQELBQADggEBAHqEYmtWr83S+iLXE97KBnHJZiMr6PMuLKxmh0o6UJJwKgf+KTP2czxRnPSI
+whuqfQZdmz6g3A2K8AooMU0RXrzncnX1c4826APdnXkRxnGQxtZXI1wuhPn4z7iDKZ6ij9u
K5Pfn10JL/ERDig2qJQbqvhtIAx0RY7y7r+hLMvgXVq9mf3WRJYmGQeFW+N9t5Z1eEwG4m9R
KAZm0fnfeDn/Ai4kmxTckBH7dZwW2lTtwQqQ4su+PGCJ0e9ndBLpvTqaYGSAl+L7PO7vxPhS
/cS67Xa6BtnYJLTr3MaGXaN+CEUFSfwQHa9DKcAqh3kldErI3kCvnot0CigBl4aILOEwggY0
MIIEHKADAgECAgEeMA0GCSqGSIb3DQEBBQUAMH0xCzAJBgNVBAYTAklMMRYwFAYDVQQKEw1T
dGFydENvbSBMdGQuMSswKQYDVQQLEyJTZWN1cmUgRGlnaXRhbCBDZXJ0aWZpY2F0ZSBTaWdu
aW5nMSkwJwYDVQQDEyBTdGFydENvbSBDZXJ0aWZpY2F0aW9uIEF1dGhvcml0eTAeFw0wNzEw
MjQyMTAxNTVaFw0xNzEwMjQyMTAxNTVaMIGMMQswCQYDVQQGEwJJTDEWMBQGA1UEChMNU3Rh
cnRDb20gTHRkLjErMCkGA1UECxMiU2VjdXJlIERpZ2l0YWwgQ2VydGlmaWNhdGUgU2lnbmlu
ZzE4MDYGA1UEAxMvU3RhcnRDb20gQ2xhc3MgMSBQcmltYXJ5IEludGVybWVkaWF0ZSBDbGll
bnQgQ0EwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDHCYPMzi3YGrEppC4Tq5a+
ijKDjKaIQZZVR63UbxIP6uq/I0fhCu+cQhoUfE6ERKKnu8zPf1Jwuk0tsvVCk6U9b+0UjM0d
Lep3ZdE1gblK/1FwYT5Pipsu2yOMluLqwvsuz9/9f1+1PKHG/FaR/wpbfuIqu54qzHDYeqiU
fsYzoVflR80DAC7hmJ+SmZnNTWyUGHJbBpA8Q89lGxahNvuryGaC/o2/ceD2uYDX9U8Eg5Dp
IpGQdcbQeGarV04WgAUjjXX5r/2dabmtxWMZwhZna//jdiSyrrSMTGKkDiXm6/3/4ebfeZuC
YKzN2P8O2F/Xe2AC/Y7zeEsnR7FOp+uXAgMBAAGjggGtMIIBqTAPBgNVHRMBAf8EBTADAQH/
MA4GA1UdDwEB/wQEAwIBBjAdBgNVHQ4EFgQUU3Ltkpzg2ssBXHx+ljVO8tS4UYIwHwYDVR0j
BBgwFoAUTgvvGqRAW6UXaYcwyjRoQ9BBrvIwZgYIKwYBBQUHAQEEWjBYMCcGCCsGAQUFBzAB
hhtodHRwOi8vb2NzcC5zdGFydHNzbC5jb20vY2EwLQYIKwYBBQUHMAKGIWh0dHA6Ly93d3cu
c3RhcnRzc2wuY29tL3Nmc2NhLmNydDBbBgNVHR8EVDBSMCegJaAjhiFodHRwOi8vd3d3LnN0
YXJ0c3NsLmNvbS9zZnNjYS5jcmwwJ6AloCOGIWh0dHA6Ly9jcmwuc3RhcnRzc2wuY29tL3Nm
c2NhLmNybDCBgAYDVR0gBHkwdzB1BgsrBgEEAYG1NwECATBmMC4GCCsGAQUFBwIBFiJodHRw
Oi8vd3d3LnN0YXJ0c3NsLmNvbS9wb2xpY3kucGRmMDQGCCsGAQUFBwIBFihodHRwOi8vd3d3
LnN0YXJ0c3NsLmNvbS9pbnRlcm1lZGlhdGUucGRmMA0GCSqGSIb3DQEBBQUAA4ICAQAKgwh9
eKssBly4Y4xerhy5I3dNoXHYfYa8PlVLL/qtXnkFgdtY1o95CfegFJTwqBBmf8pyTUnFsukD
FUI22zF5bVHzuJ+GxhnSqN2sD1qetbYwBYK2iyYA5Pg7Er1A+hKMIzEzcduRkIMmCeUTyMyi
kfbUFvIBivtvkR8ZFAk22BZy+pJfAoedO61HTz4qSfQoCRcLN5A0t4DkuVhTMXIzuQ8Cnykh
ExD6x4e6ebIbrjZLb7L+ocR0y4YjCl/Pd4MXU91y0vTipgr/O75CDUHDRHCCKBVmz/Rzkc/b
970MEeHt5LC3NiWTgBSvrLEuVzBKM586YoRD9Dy3OHQgWI270g+5MYA8GfgI/EPT5G7xPbCD
z+zjdH89PeR3U4So4lSXur6H6vp+m9TQXPF3a0LwZrp8MQ+Z77U1uL7TelWO5lApsbAonrqA
SfTpaprFVkL4nyGH+NHST2ZJPWIBk81i6Vw0ny0qZW2Niy/QvVNKbb43A43ny076khXO7cNb
BIRdJ/6qQNq9Bqb5C0Q5nEsFcj75oxQRqlKf6TcvGbjxkJh8BYtv9ePsXklAxtm8J7GCUBth
HSQgepbkOexhJ0wP8imUkyiPHQ0GvEnd83129fZjoEhdGwXV27ioRKbj/cIq7JRXun0NbeY+
UdMYu9jGfIpDLtUUGSgsg2zMGs5R4jGCA90wggPZAgEBMIGUMIGMMQswCQYDVQQGEwJJTDEW
MBQGA1UEChMNU3RhcnRDb20gTHRkLjErMCkGA1UECxMiU2VjdXJlIERpZ2l0YWwgQ2VydGlm
aWNhdGUgU2lnbmluZzE4MDYGA1UEAxMvU3RhcnRDb20gQ2xhc3MgMSBQcmltYXJ5IEludGVy
bWVkaWF0ZSBDbGllbnQgQ0ECAwiRTjAJBgUrDgMCGgUAoIICHTAYBgkqhkiG9w0BCQMxCwYJ
KoZIhvcNAQcBMBwGCSqGSIb3DQEJBTEPFw0xNDA3MDIxNDExMDVaMCMGCSqGSIb3DQEJBDEW
BBT9nllS1FJdBmc7tPgF6u3B3nnj4jBsBgkqhkiG9w0BCQ8xXzBdMAsGCWCGSAFlAwQBKjAL
BglghkgBZQMEAQIwCgYIKoZIhvcNAwcwDgYIKoZIhvcNAwICAgCAMA0GCCqGSIb3DQMCAgFA
MAcGBSsOAwIHMA0GCCqGSIb3DQMCAgEoMIGlBgkrBgEEAYI3EAQxgZcwgZQwgYwxCzAJBgNV
BAYTAklMMRYwFAYDVQQKEw1TdGFydENvbSBMdGQuMSswKQYDVQQLEyJTZWN1cmUgRGlnaXRh
bCBDZXJ0aWZpY2F0ZSBTaWduaW5nMTgwNgYDVQQDEy9TdGFydENvbSBDbGFzcyAxIFByaW1h
cnkgSW50ZXJtZWRpYXRlIENsaWVudCBDQQIDCJFOMIGnBgsqhkiG9w0BCRACCzGBl6CBlDCB
jDELMAkGA1UEBhMCSUwxFjAUBgNVBAoTDVN0YXJ0Q29tIEx0ZC4xKzApBgNVBAsTIlNlY3Vy
ZSBEaWdpdGFsIENlcnRpZmljYXRlIFNpZ25pbmcxODA2BgNVBAMTL1N0YXJ0Q29tIENsYXNz
IDEgUHJpbWFyeSBJbnRlcm1lZGlhdGUgQ2xpZW50IENBAgMIkU4wDQYJKoZIhvcNAQEBBQAE
ggEAgL/aXFLhHDlYFmTrlPuoj4UdnZ/nz3gj6nOE0krgGrvYMy/HEZ2OneD4xYSPBPvM+KIK
yHuszbc11TNZ4pe3kclWkOzJBkvn/0a0i8lPhFJuhqlEAq9F4VeQaEoUA8eAdd5VKBZ86Z7v
TaKWZHi/JwbPKUKxtEzph+XBp/dEtmqPnzabRGBzb5bOksXhGUwUK37S53xyHj/FrPo7Xwjt
X6mCAtHh2iruwRu1rQv54RJWP4mhpLi09clU5xSaCuIclVFuRu3bvUQYkeoOIMqGSx7lvbHF
3G/fMjjyVWii8cXxDMMDu6Hw54zxs4P0kABSKYnWMpqfBp0z2CycwjvhiwAAAAAAAA==
--------------ms080708000207090007030301--


From nobody Thu Jul  3 04:00:33 2014
Return-Path: <ludwig@sics.se>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id C76701B280A for <ace@ietfa.amsl.com>; Thu,  3 Jul 2014 04:00:31 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.901
X-Spam-Level: 
X-Spam-Status: No, score=-2.901 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HELO_EQ_SE=0.35, RCVD_IN_DNSWL_LOW=-0.7, RP_MATCHES_RCVD=-0.651] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id EMUF71Ud4IDK for <ace@ietfa.amsl.com>; Thu,  3 Jul 2014 04:00:29 -0700 (PDT)
Received: from outbox.sics.se (outbox.sics.se [193.10.64.137]) by ietfa.amsl.com (Postfix) with ESMTP id CA07E1A0015 for <ace@ietf.org>; Thu,  3 Jul 2014 04:00:27 -0700 (PDT)
Received: from e-mailfilter01.sunet.se (e-mailfilter01.sunet.se [192.36.171.201]) by outbox.sics.se (Postfix) with ESMTPS id A64D95D97 for <ace@ietf.org>; Thu,  3 Jul 2014 13:00:26 +0200 (CEST)
Received: from letter.sics.se (letter.sics.se [193.10.64.6]) by e-mailfilter01.sunet.se (8.14.4/8.14.4/Debian-4) with ESMTP id s63B0ODh006679 for <ace@ietf.org>; Thu, 3 Jul 2014 13:00:24 +0200
Received: from [192.168.0.108] (unknown [85.235.11.178]) (Authenticated sender: ludwig@sics.se) by letter.sics.se (Postfix) with ESMTPSA id 092E840116 for <ace@ietf.org>; Thu,  3 Jul 2014 13:00:48 +0200 (CEST)
Message-ID: <53B537C2.9070702@sics.se>
Date: Thu, 03 Jul 2014 13:00:18 +0200
From: Ludwig Seitz <ludwig@sics.se>
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:24.0) Gecko/20100101 Thunderbird/24.6.0
MIME-Version: 1.0
To: "ace@ietf.org" <ace@ietf.org>
References: <20140703105824.6361.85136.idtracker@ietfa.amsl.com>
In-Reply-To: <20140703105824.6361.85136.idtracker@ietfa.amsl.com>
X-Forwarded-Message-Id: <20140703105824.6361.85136.idtracker@ietfa.amsl.com>
Content-Type: multipart/signed; protocol="application/pkcs7-signature"; micalg=sha1; boundary="------------ms010309070803040201070100"
X-Bayes-Prob: 0.0001 (Score 0, tokens from: outbound, outbound-sics-se:default, sics-se:default, base:default, @@RPTN)
X-p0f-Info: os=Solaris 10, link=Ethernet or modem
X-CanIt-Geo: =?UTF-8?Q?ip=3D85.235.11.178; _country=3DSE; _region=3DSk=C3=A5ne; _city=3DLund; _latitude=3D55.7000; _longitude=3D13.1833; _http://maps.google.com/maps=3Fq=3D55.7000,13.1833&z=3D6?=
X-CanItPRO-Stream: outbound-sics-se:outbound (inherits from outbound-sics-se:default, sics-se:default, base:default)
X-Canit-Stats-ID: 09MlL0ow7 - 52125ff40a65 - 20140703
X-Antispam-Training-Forget: https://canit.sunet.se/canit/b.php?i=09MlL0ow7&m=52125ff40a65&t=20140703&c=f
X-Antispam-Training-Nonspam: https://canit.sunet.se/canit/b.php?i=09MlL0ow7&m=52125ff40a65&t=20140703&c=n
X-Antispam-Training-Spam: https://canit.sunet.se/canit/b.php?i=09MlL0ow7&m=52125ff40a65&t=20140703&c=s
X-CanIt-Archive-Cluster: PfMRe/vJWMiXwM2YIH5BVExnUnw
X-Scanned-By: CanIt (www . roaringpenguin . com) on 192.36.171.201
Archived-At: http://mailarchive.ietf.org/arch/msg/ace/jIDcJAy2FLCQgyQRHjk5sZ3BWbw
Subject: [Ace] Fwd: New Version Notification for draft-seitz-ace-problem-description-01.txt
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 03 Jul 2014 11:00:32 -0000

This is a cryptographically signed message in MIME format.

--------------ms010309070803040201070100
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: quoted-printable

Hello,

we have updated our problem-description draft after the discussions at=20
the informal meeting in Stockholm. I hope this will provide a good basis =

for discussion the specific problems ACE needs to address.


/Ludwig


-------- Original Message --------
Subject: New Version Notification for=20
draft-seitz-ace-problem-description-01.txt
Date: Thu, 03 Jul 2014 03:58:24 -0700
From: internet-drafts@ietf.org
To: Ludwig Seitz <ludwig@sics.se>, Goeran Selander=20
<goran.selander@ericsson.com>, Ludwig Seitz <ludwig@sics.se>, Goran=20
Selander <goran.selander@ericsson.com>


A new version of I-D, draft-seitz-ace-problem-description-01.txt
has been successfully submitted by Ludwig Seitz and posted to the
IETF repository.

Name:		draft-seitz-ace-problem-description
Revision:	01
Title:		Problem Description for Authorization in Constrained Environments=

Document date:	2014-07-03
Group:		Individual Submission
Pages:		18
URL:=20
http://www.ietf.org/internet-drafts/draft-seitz-ace-problem-description-0=
1.txt
Status:=20
https://datatracker.ietf.org/doc/draft-seitz-ace-problem-description/
Htmlized:=20
http://tools.ietf.org/html/draft-seitz-ace-problem-description-01
Diff:=20
http://www.ietf.org/rfcdiff?url2=3Ddraft-seitz-ace-problem-description-01=


Abstract:
    We present a problem description for authentication and authorization=

    in constrained-node networks, i.e. networks where some devices have
    severe constraints on memory, processing, power and communication
    bandwidth.

=20



Please note that it may take a couple of minutes from the time of submiss=
ion
until the htmlized version and diff are available at tools.ietf.org.

The IETF Secretariat





--------------ms010309070803040201070100
Content-Type: application/pkcs7-signature; name="smime.p7s"
Content-Transfer-Encoding: base64
Content-Disposition: attachment; filename="smime.p7s"
Content-Description: S/MIME Cryptographic Signature

MIAGCSqGSIb3DQEHAqCAMIACAQExCzAJBgUrDgMCGgUAMIAGCSqGSIb3DQEHAQAAoIIMVDCC
BhgwggUAoAMCAQICAwiRTjANBgkqhkiG9w0BAQsFADCBjDELMAkGA1UEBhMCSUwxFjAUBgNV
BAoTDVN0YXJ0Q29tIEx0ZC4xKzApBgNVBAsTIlNlY3VyZSBEaWdpdGFsIENlcnRpZmljYXRl
IFNpZ25pbmcxODA2BgNVBAMTL1N0YXJ0Q29tIENsYXNzIDEgUHJpbWFyeSBJbnRlcm1lZGlh
dGUgQ2xpZW50IENBMB4XDTE0MDEwNzA3MjgzNVoXDTE1MDEwNzEyNTgyMlowODEXMBUGA1UE
AwwObHVkd2lnQHNpY3Muc2UxHTAbBgkqhkiG9w0BCQEWDmx1ZHdpZ0BzaWNzLnNlMIIBIjAN
BgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAnLm1tc30QxHa9wtdVjC3NgxjLJicnccm0HD+
1X16kPMKGvwps8F1oDhYn7jXIe46p1AuJMzLK0GIioE4JwxCFGdvpz7cg2xyTyrdBVUzSqez
Dfqt4FOJq6hrdrIMS8MHEzl7Jk02gv9cTn/pHQvDpkiThRpbSLU5mlMqtEQ8gDQY5YyBX0Mv
5qculV08I2JU8HEeTt1oeqhvBImgQfOVYMDatHlWHUVVrmYd6iIo+cuiUGd5kiA0XuaLYX0E
oCoao/z5Wg9U0sQlx0hl4r96Q+NdoZZ1prfts3qtyBzJ2hu135aikigzJ6sueWHv/jbISUek
tOMm0xkx1GOqqWtEAwIDAQABo4IC1DCCAtAwCQYDVR0TBAIwADALBgNVHQ8EBAMCBLAwHQYD
VR0lBBYwFAYIKwYBBQUHAwIGCCsGAQUFBwMEMB0GA1UdDgQWBBRZmjjBh8N3klra+mVQgC00
pl68ZTAfBgNVHSMEGDAWgBRTcu2SnODaywFcfH6WNU7y1LhRgjAZBgNVHREEEjAQgQ5sdWR3
aWdAc2ljcy5zZTCCAUwGA1UdIASCAUMwggE/MIIBOwYLKwYBBAGBtTcBAgMwggEqMC4GCCsG
AQUFBwIBFiJodHRwOi8vd3d3LnN0YXJ0c3NsLmNvbS9wb2xpY3kucGRmMIH3BggrBgEFBQcC
AjCB6jAnFiBTdGFydENvbSBDZXJ0aWZpY2F0aW9uIEF1dGhvcml0eTADAgEBGoG+VGhpcyBj
ZXJ0aWZpY2F0ZSB3YXMgaXNzdWVkIGFjY29yZGluZyB0byB0aGUgQ2xhc3MgMSBWYWxpZGF0
aW9uIHJlcXVpcmVtZW50cyBvZiB0aGUgU3RhcnRDb20gQ0EgcG9saWN5LCByZWxpYW5jZSBv
bmx5IGZvciB0aGUgaW50ZW5kZWQgcHVycG9zZSBpbiBjb21wbGlhbmNlIG9mIHRoZSByZWx5
aW5nIHBhcnR5IG9ibGlnYXRpb25zLjA2BgNVHR8ELzAtMCugKaAnhiVodHRwOi8vY3JsLnN0
YXJ0c3NsLmNvbS9jcnR1MS1jcmwuY3JsMIGOBggrBgEFBQcBAQSBgTB/MDkGCCsGAQUFBzAB
hi1odHRwOi8vb2NzcC5zdGFydHNzbC5jb20vc3ViL2NsYXNzMS9jbGllbnQvY2EwQgYIKwYB
BQUHMAKGNmh0dHA6Ly9haWEuc3RhcnRzc2wuY29tL2NlcnRzL3N1Yi5jbGFzczEuY2xpZW50
LmNhLmNydDAjBgNVHRIEHDAahhhodHRwOi8vd3d3LnN0YXJ0c3NsLmNvbS8wDQYJKoZIhvcN
AQELBQADggEBAHqEYmtWr83S+iLXE97KBnHJZiMr6PMuLKxmh0o6UJJwKgf+KTP2czxRnPSI
+whuqfQZdmz6g3A2K8AooMU0RXrzncnX1c4826APdnXkRxnGQxtZXI1wuhPn4z7iDKZ6ij9u
K5Pfn10JL/ERDig2qJQbqvhtIAx0RY7y7r+hLMvgXVq9mf3WRJYmGQeFW+N9t5Z1eEwG4m9R
KAZm0fnfeDn/Ai4kmxTckBH7dZwW2lTtwQqQ4su+PGCJ0e9ndBLpvTqaYGSAl+L7PO7vxPhS
/cS67Xa6BtnYJLTr3MaGXaN+CEUFSfwQHa9DKcAqh3kldErI3kCvnot0CigBl4aILOEwggY0
MIIEHKADAgECAgEeMA0GCSqGSIb3DQEBBQUAMH0xCzAJBgNVBAYTAklMMRYwFAYDVQQKEw1T
dGFydENvbSBMdGQuMSswKQYDVQQLEyJTZWN1cmUgRGlnaXRhbCBDZXJ0aWZpY2F0ZSBTaWdu
aW5nMSkwJwYDVQQDEyBTdGFydENvbSBDZXJ0aWZpY2F0aW9uIEF1dGhvcml0eTAeFw0wNzEw
MjQyMTAxNTVaFw0xNzEwMjQyMTAxNTVaMIGMMQswCQYDVQQGEwJJTDEWMBQGA1UEChMNU3Rh
cnRDb20gTHRkLjErMCkGA1UECxMiU2VjdXJlIERpZ2l0YWwgQ2VydGlmaWNhdGUgU2lnbmlu
ZzE4MDYGA1UEAxMvU3RhcnRDb20gQ2xhc3MgMSBQcmltYXJ5IEludGVybWVkaWF0ZSBDbGll
bnQgQ0EwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDHCYPMzi3YGrEppC4Tq5a+
ijKDjKaIQZZVR63UbxIP6uq/I0fhCu+cQhoUfE6ERKKnu8zPf1Jwuk0tsvVCk6U9b+0UjM0d
Lep3ZdE1gblK/1FwYT5Pipsu2yOMluLqwvsuz9/9f1+1PKHG/FaR/wpbfuIqu54qzHDYeqiU
fsYzoVflR80DAC7hmJ+SmZnNTWyUGHJbBpA8Q89lGxahNvuryGaC/o2/ceD2uYDX9U8Eg5Dp
IpGQdcbQeGarV04WgAUjjXX5r/2dabmtxWMZwhZna//jdiSyrrSMTGKkDiXm6/3/4ebfeZuC
YKzN2P8O2F/Xe2AC/Y7zeEsnR7FOp+uXAgMBAAGjggGtMIIBqTAPBgNVHRMBAf8EBTADAQH/
MA4GA1UdDwEB/wQEAwIBBjAdBgNVHQ4EFgQUU3Ltkpzg2ssBXHx+ljVO8tS4UYIwHwYDVR0j
BBgwFoAUTgvvGqRAW6UXaYcwyjRoQ9BBrvIwZgYIKwYBBQUHAQEEWjBYMCcGCCsGAQUFBzAB
hhtodHRwOi8vb2NzcC5zdGFydHNzbC5jb20vY2EwLQYIKwYBBQUHMAKGIWh0dHA6Ly93d3cu
c3RhcnRzc2wuY29tL3Nmc2NhLmNydDBbBgNVHR8EVDBSMCegJaAjhiFodHRwOi8vd3d3LnN0
YXJ0c3NsLmNvbS9zZnNjYS5jcmwwJ6AloCOGIWh0dHA6Ly9jcmwuc3RhcnRzc2wuY29tL3Nm
c2NhLmNybDCBgAYDVR0gBHkwdzB1BgsrBgEEAYG1NwECATBmMC4GCCsGAQUFBwIBFiJodHRw
Oi8vd3d3LnN0YXJ0c3NsLmNvbS9wb2xpY3kucGRmMDQGCCsGAQUFBwIBFihodHRwOi8vd3d3
LnN0YXJ0c3NsLmNvbS9pbnRlcm1lZGlhdGUucGRmMA0GCSqGSIb3DQEBBQUAA4ICAQAKgwh9
eKssBly4Y4xerhy5I3dNoXHYfYa8PlVLL/qtXnkFgdtY1o95CfegFJTwqBBmf8pyTUnFsukD
FUI22zF5bVHzuJ+GxhnSqN2sD1qetbYwBYK2iyYA5Pg7Er1A+hKMIzEzcduRkIMmCeUTyMyi
kfbUFvIBivtvkR8ZFAk22BZy+pJfAoedO61HTz4qSfQoCRcLN5A0t4DkuVhTMXIzuQ8Cnykh
ExD6x4e6ebIbrjZLb7L+ocR0y4YjCl/Pd4MXU91y0vTipgr/O75CDUHDRHCCKBVmz/Rzkc/b
970MEeHt5LC3NiWTgBSvrLEuVzBKM586YoRD9Dy3OHQgWI270g+5MYA8GfgI/EPT5G7xPbCD
z+zjdH89PeR3U4So4lSXur6H6vp+m9TQXPF3a0LwZrp8MQ+Z77U1uL7TelWO5lApsbAonrqA
SfTpaprFVkL4nyGH+NHST2ZJPWIBk81i6Vw0ny0qZW2Niy/QvVNKbb43A43ny076khXO7cNb
BIRdJ/6qQNq9Bqb5C0Q5nEsFcj75oxQRqlKf6TcvGbjxkJh8BYtv9ePsXklAxtm8J7GCUBth
HSQgepbkOexhJ0wP8imUkyiPHQ0GvEnd83129fZjoEhdGwXV27ioRKbj/cIq7JRXun0NbeY+
UdMYu9jGfIpDLtUUGSgsg2zMGs5R4jGCA90wggPZAgEBMIGUMIGMMQswCQYDVQQGEwJJTDEW
MBQGA1UEChMNU3RhcnRDb20gTHRkLjErMCkGA1UECxMiU2VjdXJlIERpZ2l0YWwgQ2VydGlm
aWNhdGUgU2lnbmluZzE4MDYGA1UEAxMvU3RhcnRDb20gQ2xhc3MgMSBQcmltYXJ5IEludGVy
bWVkaWF0ZSBDbGllbnQgQ0ECAwiRTjAJBgUrDgMCGgUAoIICHTAYBgkqhkiG9w0BCQMxCwYJ
KoZIhvcNAQcBMBwGCSqGSIb3DQEJBTEPFw0xNDA3MDMxMTAwMThaMCMGCSqGSIb3DQEJBDEW
BBRcK9Mstxh52wFSk4SOtdDkLs8DdzBsBgkqhkiG9w0BCQ8xXzBdMAsGCWCGSAFlAwQBKjAL
BglghkgBZQMEAQIwCgYIKoZIhvcNAwcwDgYIKoZIhvcNAwICAgCAMA0GCCqGSIb3DQMCAgFA
MAcGBSsOAwIHMA0GCCqGSIb3DQMCAgEoMIGlBgkrBgEEAYI3EAQxgZcwgZQwgYwxCzAJBgNV
BAYTAklMMRYwFAYDVQQKEw1TdGFydENvbSBMdGQuMSswKQYDVQQLEyJTZWN1cmUgRGlnaXRh
bCBDZXJ0aWZpY2F0ZSBTaWduaW5nMTgwNgYDVQQDEy9TdGFydENvbSBDbGFzcyAxIFByaW1h
cnkgSW50ZXJtZWRpYXRlIENsaWVudCBDQQIDCJFOMIGnBgsqhkiG9w0BCRACCzGBl6CBlDCB
jDELMAkGA1UEBhMCSUwxFjAUBgNVBAoTDVN0YXJ0Q29tIEx0ZC4xKzApBgNVBAsTIlNlY3Vy
ZSBEaWdpdGFsIENlcnRpZmljYXRlIFNpZ25pbmcxODA2BgNVBAMTL1N0YXJ0Q29tIENsYXNz
IDEgUHJpbWFyeSBJbnRlcm1lZGlhdGUgQ2xpZW50IENBAgMIkU4wDQYJKoZIhvcNAQEBBQAE
ggEAMCsa3L/+5wxjet4Oppx3MDjdrQZSbCe1qb2CWr+JEJK17LlNI3gtGQaYthHDdTX1qP0B
Gi0B+EiIht4RkQv3DMEZIR7O6oWpBdXZZWOX9hnT+AG2NsG8HLlVQDMcRY+Ivk5IDjCicSEP
klkEevUFuZhnQPiU3VU+6M/y+mijEDSUHgW9KjUv3+te8B5lzAMmVj5n244wVdOpdIHZagDN
5m574iVrB/jYApHA+Q3OnK4wLrOiL1Hh3X0U6++uj+x8Mlr11fY+bFKMNQ97xklTFqzmQpD/
RpL7R5EVkXbV14ww/7cDtteOdvmZ+0VeEXcRWwIuRWQ2u+kSCqBwO3iHlwAAAAAAAA==
--------------ms010309070803040201070100--


From nobody Fri Jul  4 05:03:23 2014
Return-Path: <hannes.tschofenig@gmx.net>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 98C511B2D53 for <ace@ietfa.amsl.com>; Fri,  4 Jul 2014 05:03:21 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.551
X-Spam-Level: 
X-Spam-Status: No, score=-2.551 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, FREEMAIL_FROM=0.001, RCVD_IN_DNSWL_NONE=-0.0001, RP_MATCHES_RCVD=-0.651, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id SZO3qS-km40W for <ace@ietfa.amsl.com>; Fri,  4 Jul 2014 05:03:11 -0700 (PDT)
Received: from mout.gmx.net (mout.gmx.net [212.227.15.15]) (using TLSv1.2 with cipher DHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 6CA291B2D57 for <ace@ietf.org>; Fri,  4 Jul 2014 05:03:08 -0700 (PDT)
Received: from [192.168.131.128] ([80.92.115.50]) by mail.gmx.com (mrgmx002) with ESMTPSA (Nemesis) id 0M3RZI-1WlMlO2kjo-00r22E for <ace@ietf.org>; Fri, 04 Jul 2014 14:03:06 +0200
Message-ID: <53B697F8.6020703@gmx.net>
Date: Fri, 04 Jul 2014 14:03:04 +0200
From: Hannes Tschofenig <hannes.tschofenig@gmx.net>
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:24.0) Gecko/20100101 Thunderbird/24.6.0
MIME-Version: 1.0
To: "ace@ietf.org" <ace@ietf.org>
X-Enigmail-Version: 1.5.2
OpenPGP: id=4D776BC9
Content-Type: multipart/signed; micalg=pgp-sha512; protocol="application/pgp-signature"; boundary="Jvd8lEfN5SFjsdngfjnqIGT4S0pGrC8aU"
X-Provags-ID: V03:K0:JqRr0mqY2rOudd4gW9B1PvhBZi7C8C9SN9cZtgUmwF5ypEfEnpW jWkiZQMZnIDj4eQeEXl217Giw2OrgeaCBas0AhoUp/OlkcOErukPXWdD2+oep04q5EOjms2 nSM2E8SKoI0zcl0XyYwPclEsapbgPcbRV2VIQr2Ge1/3R2cT0UssVm1ijDhPUAOO0J8I2gm Or8jlI0tbCXfOX22r3NZQ==
Archived-At: http://mailarchive.ietf.org/arch/msg/ace/6CuzWponP2iduJfdcLfBFvue7MQ
Subject: [Ace] OAuth-based Strawman for ACE
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 04 Jul 2014 12:03:21 -0000

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--Jvd8lEfN5SFjsdngfjnqIGT4S0pGrC8aU
Content-Type: text/plain; charset=ISO-8859-1
Content-Transfer-Encoding: quoted-printable

Hi all,

I have been playing around with the idea of using OAuth for the IoT
context for a while now. It turns out that others have had similar ideas
and various blog post and presentations can be found on the Web already.
Unfortunately, most of them are completely insecure. For this this I
have put my thoughts on "paper" on how I would design such a solution.

The approach is described in two documents, namely:

(a) The OAuth 2.0 Internet of Things (IoT) Client Credentials Grant
https://datatracker.ietf.org/doc/draft-tschofenig-ace-oauth-iot/

(b) The OAuth 2.0 Bearer Token Usage over the Constrained Application
Protocol (CoAP)
https://datatracker.ietf.org/doc/draft-tschofenig-ace-oauth-bt/

(a) describes a new OAuth grant type that allows a constrained client to
obtain an access token and (b) describes how to convey that access token
over CoAP from the client to a resource server.

If the client is not constrained (as it would be the case for a smart
phone) then (a) is not needed and regular OAuth could be used. In other
cases the use of CoAP between the client and resource server may not be
appropriate and then (b) is not applicable.

While this is not relevant for ACE at this point in time (since we are
at the stage of use cases and requirements) I thought it still provides
some useful data points.

If you have feedback please drop me a mail.

Ciao
Hannes


--Jvd8lEfN5SFjsdngfjnqIGT4S0pGrC8aU
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
Content-Disposition: attachment; filename="signature.asc"

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1
Comment: GPGTools - http://gpgtools.org
Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/

iQEcBAEBCgAGBQJTtpf4AAoJEGhJURNOOiAtM14H/i6abp26GD8C+zumdLq5iQy6
bGsWgZBPTConVskdH0K+V0R6pxBAlKk8/mPTyr0dszC6j4M99TCT9eE6rgz7zx8I
yyOXgMHHCXZXV1GhWyE9147H6m1QjbL5NKBHkYjljneeGoUdQXsibsEDpSNapFEp
Y4l6xGqpyQSrHyTI2FO09hrhUF5OZKkwostNrk3JVBodJ+sAoGwjMATWQ4txVWrz
GfInWlLHZKFQQaNGvVv5hZb2KwHypVF5+AuRr52uE9vuA8Yvg8l5xsWVGn3scT5W
P2SS8e8dDyFaKQR7ljsqJY47pjodEX6V1Gzq0/yiMQDt6z+StnS39cqGCF9I9BU=
=VwHU
-----END PGP SIGNATURE-----

--Jvd8lEfN5SFjsdngfjnqIGT4S0pGrC8aU--


From nobody Sun Jul  6 20:52:39 2014
Return-Path: <likepeng@huawei.com>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 91F011A0AE2 for <ace@ietfa.amsl.com>; Sun,  6 Jul 2014 20:52:37 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.851
X-Spam-Level: 
X-Spam-Status: No, score=-4.851 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_MED=-2.3, RP_MATCHES_RCVD=-0.651, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id vtm5VDW2rzTw for <ace@ietfa.amsl.com>; Sun,  6 Jul 2014 20:52:33 -0700 (PDT)
Received: from lhrrgout.huawei.com (lhrrgout.huawei.com [194.213.3.17]) (using TLSv1 with cipher RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 6FEDD1A0AE1 for <ace@ietf.org>; Sun,  6 Jul 2014 20:52:32 -0700 (PDT)
Received: from 172.18.7.190 (EHLO lhreml405-hub.china.huawei.com) ([172.18.7.190]) by lhrrg02-dlp.huawei.com (MOS 4.3.7-GA FastPath queued) with ESMTP id BGV91587; Mon, 07 Jul 2014 03:52:30 +0000 (GMT)
Received: from SZXEMA402-HUB.china.huawei.com (10.82.72.34) by lhreml405-hub.china.huawei.com (10.201.5.242) with Microsoft SMTP Server (TLS) id 14.3.158.1; Mon, 7 Jul 2014 04:52:27 +0100
Received: from SZXEMA501-MBS.china.huawei.com ([169.254.2.128]) by SZXEMA402-HUB.china.huawei.com ([10.82.72.34]) with mapi id 14.03.0158.001; Mon, 7 Jul 2014 11:52:22 +0800
From: Likepeng <likepeng@huawei.com>
To: Corinna Schmitt <schmitt@ifi.uzh.ch>, "ace@ietf.org" <ace@ietf.org>, Hannes Tschofenig <Hannes.Tschofenig@gmx.net>
Thread-Topic: [Ace] draft-schmitt-two-way-authentication-for-iot-02
Thread-Index: AQHPlD3fAWxhjPHxj0q+0bPwAUrxB5uT+BAA
Date: Mon, 7 Jul 2014 03:52:22 +0000
Message-ID: <34966E97BE8AD64EAE9D3D6E4DEE36F25817518D@SZXEMA501-MBS.china.huawei.com>
References: <53086642.5050609@gmx.net> <53134E58.20608@ifi.uzh.ch> <531F6177.5040704@gmx.net> <53B1209C.5020200@ifi.uzh.ch>
In-Reply-To: <53B1209C.5020200@ifi.uzh.ch>
Accept-Language: zh-CN, en-US
Content-Language: zh-CN
X-MS-Has-Attach: yes
X-MS-TNEF-Correlator: 
x-originating-ip: [10.66.167.122]
Content-Type: multipart/related; boundary="_004_34966E97BE8AD64EAE9D3D6E4DEE36F25817518DSZXEMA501MBSchi_"; type="multipart/alternative"
MIME-Version: 1.0
X-CFilter-Loop: Reflected
Archived-At: http://mailarchive.ietf.org/arch/msg/ace/dPVRbLUmYn5UL-ETSBUFUefdMmI
Cc: Burkhard Stiller <stiller@ifi.uzh.ch>
Subject: Re: [Ace] draft-schmitt-two-way-authentication-for-iot-02
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 07 Jul 2014 03:52:37 -0000

--_004_34966E97BE8AD64EAE9D3D6E4DEE36F25817518DSZXEMA501MBSchi_
Content-Type: multipart/alternative;
	boundary="_000_34966E97BE8AD64EAE9D3D6E4DEE36F25817518DSZXEMA501MBSchi_"

--_000_34966E97BE8AD64EAE9D3D6E4DEE36F25817518DSZXEMA501MBSchi_
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: base64

SGkgQ29yaW5uYSwNCg0KUGxlYXNlIGZpbmQgbXkgcGVyc29uYWwgZmVlZGJhY2sgdG8geW91ciBk
cmFmdDoNCg0KU2VjdGlvbiAyLCBUZXJtaW5vbG9neTogQ3VycmVudGx5LCBvdXIgY2hhcnRlciBh
bmQgbW9zdCBvZiB0aGUgb3RoZXIgc3VibWl0dGVkIGRyYWZ0cyB1c2Ug4oCcQ2xpZW504oCdLCDi
gJxSZXNvdXJjZSBTZXJ2ZXLigJ0sIOKAnEF1dGhvcml6YXRpb24gU2VydmVy4oCdLiBUbyBrZWVw
IGNvbnNpc3RlbmN5LCBpdCBpcyBiZXR0ZXIgdG8gdXNlIHRoZXNlIHRlcm1pbm9sb2dpZXMgdG8g
cmVwbGFjZSDigJxQdWJsaXNoZXLigJ0sIOKAnFN1YnNjcmliZXLigJ0gYW5kIOKAnEFjY2VzcyBD
b250cm9sIFNlcnZlcuKAnS4NCg0KU2VjdGlvbiAzLCBIaWdoIExldmVsIERlc2lnbiBSZXF1aXJl
bWVudHM6IHRoZSBvYmplY3RpdmUgb2YgdGhpcyBzZWN0aW9uIGlzIHF1aXRlIHNpbWlsYXIgdG8g
dGhlIOKAnGRlc2lnbiBjb25zaWRlcmF0aW9uc+KAnSBkcmFmdC4gSXQgaXMgYmV0dGVyIHRvIGNv
bnNvbGlkYXRlIHRoaXMgc2VjdGlvbiB3aXRoIHRoZSBkcmFmdC4NCmh0dHA6Ly9kYXRhdHJhY2tl
ci5pZXRmLm9yZy9kb2MvZHJhZnQtc2VpdHotYWNlLWRlc2lnbi1jb25zaWRlcmF0aW9ucy8NCg0K
U2VjdGlvbiA0LCBJdCBzZWVtcyB0aGF0IHRoYXQgbW9zdCBvZiB0aGUgZGVzaWduIGNvbnNpZGVy
YXRpb25zIChlLmcuIGFzc3VtZWQgbmV0d29yayBzdGFjaywgaGFuZHNoYWtlIG1lc3NhZ2UgZmxv
d3MpIHdpbGwgYWxzbyBiZSBhcHBsaWVkIGZvciBDbGFzcyAxIGRldmljZXMuIEl0IGlzIGJldHRl
ciB0byBpbmRpY2F0ZSB0aGUgY29tbW9uIGRlc2lnbiBjb25zaWRlcmF0aW9ucyBmaXJzdCwgdGhl
biBoaWdobGlnaHQgd2hhdCBtb3JlIHdlIGNhbiBhY2hpZXZlIGJ5IENsYXNzIDIgZGV2aWNlcy4N
Cg0KU2VjdGlvbiA1LjEsIDUuMiBhbmQgNiwgVXNlIGNhc2VzIGFuZCBSZXF1aXJlbWVudHM6IE1h
eWJlIGl0IGlzIGJldHRlciB0byBjb25zb2xpZGF0ZSB0aGVzZSBzZWN0aW9ucyB3aXRoIHRoZSDi
gJxVc2UgY2FzZXMgYW5kIHJlcXVpcmVtZW50c+KAnSBkcmFmdDoNCmh0dHA6Ly9kYXRhdHJhY2tl
ci5pZXRmLm9yZy9kb2MvZHJhZnQtc2VpdHotYWNlLXVzZWNhc2VzLw0KDQpTZWN0aW9uIDUuMywg
RGF0YSBBY2Nlc3MgUHJvY2VkdXJlczogaXQgc2VlbXMgdGhhdCBpbnRlcmFjdGlvbnMgYmV0d2Vl
biBHYXRld2F5IGFuZCBQdWJsaXNoZXIgYXJlIG91dCBvZiBzY29wZT8gQmVjYXVzZSBmcm9tIHRo
ZSBmbG93cywgdGhlIEdhdGV3YXkgaXMgbm90IGludm9sdmVkIGluIHRoZSBkYXRhIGFjY2VzcyBm
bG93IGFueSBtb3JlLiBBbHNvIGFib3V0IHRoZSBsYXN0IHR3byBzdGVwcyDigJxUd28td2F5IGF1
dGhlbnRpY2F0aW9uIGhhbmRzaGFrZSBiZXR3ZWVuIFN1YnNjcmliZXIgYW5kIFB1Ymxpc2hlcuKA
nSBhbmQg4oCcRGF0YSBleGNoYW5nZSB1c2luZyBEVExTIHNlY3VyZWQgY2hhbm5lbOKAnSwgaW4g
dGhlc2UgdHdvIHN0ZXBzLCBpcyDigJxBY2Nlc3MgQ29udHJvbCBTZXJ2ZXLigJ0gaW52b2x2ZWQg
aW4gdGhlIGRhdGEgYWNjZXNzIGZsb3c/DQoNClNlY3Rpb24gMTAsIEZvcm1hbCBTeW50YXg6IEl0
IGlzIGJldHRlciB0byBwdXQgdGhpcyBzZWN0aW9uIGFzIGEgc3ViLXNlY3Rpb24gb2YgU2VjdGlv
biAyLCB0byBsZXQgcmVhZGVycyBiZXR0ZXIgdW5kZXJzdGFuZCB0aGUgbWVhbmluZyBvZiB0aGUg
YWJicmV2aWF0aW9ucy4NCg0KVGhhbmtzLA0KDQpLaW5kIFJlZ2FyZHMNCktlcGVuZyAoSW5kaXZp
ZHVhbCkNCg0K5Y+R5Lu25Lq6OiBBY2UgW21haWx0bzphY2UtYm91bmNlc0BpZXRmLm9yZ10g5Luj
6KGoIENvcmlubmEgU2NobWl0dA0K5Y+R6YCB5pe26Ze0OiAyMDE05bm0NuaciDMw5pelIDE2OjMy
DQrmlLbku7bkuro6IGFjZUBpZXRmLm9yZzsgSGFubmVzIFRzY2hvZmVuaWcNCuaKhOmAgTogQnVy
a2hhcmQgU3RpbGxlcg0K5Li76aKYOiBSZTogW0FjZV0gZHJhZnQtc2NobWl0dC10d28td2F5LWF1
dGhlbnRpY2F0aW9uLWZvci1pb3QtMDINCg0KRGVhciBIYW5uZXMsDQoNCmJhc2VkIG9uIHRoZSBk
aXNjdXNzaW9ucyBvZiB0aGUgcHJlLW1lZXRpbmcgaW4gU3RvY2tob2xtIHdlIHVwZGF0ZWQgb3Vy
IGRyYWZ0IGFuZCBnZW5lcmFsaXplZCBpdC4gT3VyIG9sZCBkcmFmdCAiZHJhZnQtc2NobWl0dC10
d28td2F5LWF1dGhlbnRpY2F0aW9uLWZvci1pb3QiIGlzIG5vdyByZXBsYWNlZCBieSAiZHJhZnQt
c2NobWl0dC1hY2UtdHdvd2F5YXV0aC1mb3ItaW90Ii4NCg0KVGhlIG1lbnRpb25lZCBwcm9qZWN0
cyBhcmUgb25seSBleGFtcGxlcyB3aGVyZSB3ZSBoYXZlIHRoZSB3b3JrIGludGVncmF0ZWQgYW5k
IHdoZXJlIGl0IHJ1bnMgYWxyZWFkeSBzdWNjZXNzZnVsLg0KU28gd2UgYmVsaWV2ZSB0aGUgZHJh
ZnQgZml0cyBpbnRvIEFDRSBhbmQgYWxzbyBtYXBzIHRoZSByZXF1aXJlbWVudHMgb3V0bGluZWQg
aW4gaHR0cHM6Ly90b29scy5pZXRmLm9yZy9odG1sL2RyYWZ0LXNlaXR6LWFjZS11c2VjYXNlcy0w
MC4NCg0KU2VlIHlvdSBpbiBUb3JvbnRvIGF0IElFVEYgOTAsDQpDb3Jpbm5hDQoNCkFtIDExLjAz
LjE0IDIwOjE4LCBzY2hyaWViIEhhbm5lcyBUc2Nob2ZlbmlnOg0KDQpIaSBDb3Jpbm5hLA0KDQoN
Cg0KdGhhbmtzIGZvciB0aGUgcmVzcG9uc2UuDQoNCg0KDQpNeSBzdWdnZXN0aW9uIHdvdWxkIGJl
IHRvIHByb2R1Y2UgYSB3cml0ZS11cCB0aGF0IGlzIG9mIGdlbmVyaWMgdXNlDQoNCihpbmRlcGVu
ZGVudCBmcm9tIHlvdXIgc3BlY2lmaWMgaW1wbGVtZW50YXRpb24gYW5kIHlvdXIgRVUgZnVuZGVk
IHByb2plY3QpLg0KDQoNCg0KSG93ZXZlciwgZ2l2ZW4gdGhlIGNoYXJ0ZXIgZGlzY3Vzc2lvbnMg
YW5kIHRoZSBCT0YgSSBoYXZlIG15IGRvdWJ0cw0KDQp3aGV0aGVyIHRoZSB3b3JrIHdvdWxkIG1l
ZXQgbWFueSBvZiB0aGUgcmVxdWlyZW1lbnRzIG91dGxpbmVkIGluDQoNCmh0dHBzOi8vdG9vbHMu
aWV0Zi5vcmcvaHRtbC9kcmFmdC1zZWl0ei1hY2UtdXNlY2FzZXMtMDAuDQoNCg0KDQpDaWFvDQoN
Ckhhbm5lcw0KDQoNCg0KT24gMDMvMDIvMjAxNCAwNDoyOSBQTSwgRHIuIENvcmlubmEgU2NobWl0
dCB3cm90ZToNCg0KRGVhciBIYW5uZXMsDQoNCkhpIENvcmlubmEsIEhpIEJ1cmtoYXJkLA0KDQoN
Cg0KdGhhbmtzIGZvciB5b3VyIGRvY3VtZW50LiBJIGhhdmUgcmVhZCB0aHJvdWdoIGl0IGFuZCBJ
IHJhbiBpbnRvIGEgZmV3DQoNCnF1ZXN0aW9ucy4gWW91ciByZXNwb25zZSB3b3VsZCBoZWxwIG1l
IHRvIGJldHRlciB1bmRlcnN0YW5kIHRoZSBwcm9wb3NlZA0KDQppZGVhLg0KDQpUaGFua3MgZm9y
IHJlYWRpbmcgdGhlIGRyYWZ0IGFuZCBtYWtlIGNvbW1lbnRzIHRvIGl0IHRvIGltcHJvdmUgaXQu
IFNvbWUNCg0KY29tbWVudHMgY2FuIGJlIGFuc3dlcmVkIHJpZ2h0IGF3YXkuDQoNCjEpIFdoeSBk
byB5b3UgYXNzdW1lIElFRUUgODAyLjE1LjQ/IEN1cnJlbnRseSBpdCBzZWVtcyB0aGF0IHRoZSAx
NS40DQoNCnJhZGlvIHdpbGwgbW9zdGx5IGJlIHVzZWQgaW4gc3BlY2lhbGl6ZWQgaW5kdXN0cnkg
c2VnbWVudHMgb25seS4gSXMNCg0KdGhlcmUgYW55dGhpbmcgaW4gdGhlIGRvY3VtZW50IHRoYXQg
d291bGQgbWFrZSB0aGUgaWRlYSBsZXNzIHN1aXRhYmxlDQoNCmZvciBvdGhlciByYWRpbyB0ZWNo
bm9sb2dpZXMsIGZvciBleGFtcGxlIEJUTEU/DQoNClBvdGVudGlhbGx5IHRoZSBwcm9wb3NlZCBz
b2x1dGlvbiBjYW4gd29yayBvbiBldmVyeSBzdGFjayB5b3UgbGlrZS4gU28NCg0KeW91IGNhbiBk
byBhbiBpbXBsZW1lbnRhdGlvbiBpbmRlcGVuZGVudGx5IG9mIElFRUUgODAyLjE1LjQuDQoNCldl
IHB1dCBJRUVFIDgwMi4xNS40IHRoZXJlLCBiZWNhdXNlIG91ciB1c2VkIHN0YWNrIChCTElQKSB1
c2VzIGl0Lg0KDQoyKSBUaGUgYXNzdW1lZCBuZXR3b3JrIHN0YWNrIGRvZXMgbm90IHNob3cgNmxv
d3Bhbi4gV2FzIHRoaXMgaW50ZW50aW9uYWw/DQoNClNhbWUgYXMgYWJvdmUuIFlvdSBjYW4gdXNl
IHRoZSBzdGFjayB5b3Ugd2FudC4gU28gYWxzbyA2bG93cGFuIGNhbiBiZQ0KDQp1c2VkLiBJdCBk
ZXBlbmRzIG4geW91IHdoYXQgeW91IHJlcXVpcmUgYW5kIHdoYXQgeW91IHdhbnQgdG8gc3VwcG9y
dC4NCg0KMykgWW91IHNob3cgUlBMIGluIHRoZSBzdGFjayBhbmQgSSB3YXMgd29uZGVyaW5nIHdo
ZXRoZXIgeW91IGFzc3VtZSBpdA0KDQpiZWluZyBtYW5kYXRvcnkgdG8gaW1wbGVtZW50IGZvciB5
b3VyIGFzc3VtZWQgYXJjaGl0ZWN0dXJlPyBJdCBkb2VzIG5vdA0KDQpzZWVtIHRvIHNob3cgdXAg
ZWxzZXdoZXJlIGluIHRoZSBkb2N1bWVudC4gSXQgYXBwZWFycyB0byBiZSBpcnJlbGV2YW50DQoN
CmZvciB5b3VyIGRlc2lnbi4NCg0KUlBMIHdhcyBqdXN0IG1lbnRpb25lZCBkdWUgdG8gb3VyIG90
aGVyIHB1YmxpY2F0aW9ucy4gQ3VycmVudGx5IG91ciBwbGFuDQoNCmlzIHRvIGNoYW5nZSB0byBS
UEwgKENvQVApIGluIHRoZSBmdXR1cmUuDQoNCjQpIFN1YnNjcmliZXIgaWRlbnRpdHk6IFlvdSB3
cml0ZSAtLQ0KDQoiDQoNCiAgIFRoZSBpZGVudGl0eSBvZiBhIGRlZmF1bHQgc3Vic2NyaWJlciBp
cyB1c3VhbGx5IHByZWNvbmZpZ3VyZWQgb24gYQ0KDQogICBwdWJsaXNoZXIgYmVmb3JlIGl0IGlz
IGRlcGxveWVkLg0KDQoiDQoNCg0KDQpDb3VsZCB5b3UgZXhwbGFpbiBtb3JlIHdoYXQgeW91IGFz
c3VtZSBpcyBwcmUtY29uZmlndXJlZCBhbmQgd2hlcmUgaXQgaXMNCg0KcHJlY29uZmlndXJlZD8N
Cg0KSGVyZSBwcmUtY29uZmlndXJlcyBtZWFucyB0aGF0IG91ciBkZXZpY2VzIGFyZSBlcXVpcHBl
ZCB3aXRoIHRoZQ0KDQpjZXJ0aWZpY2F0aW9uIGR1cmluZyBjb21waWxpbmcgYW5kIHByb2dyYW1t
aW5nIHRoZW0gYmVmb3JlIGRlcGxveW1lbnQuDQoNClRoaXMgaXMgZHVlIHRvIHRoZSBhcHBsaWNh
dGlvbiBzY2VuYXJpbyB3ZSBzdXBwb3J0IGF0IHRoZSBtb21lbnQuIEJlZm9yZQ0KDQpkZXBsb3lp
bmcgdGhlIGRldmljZSB5b3UgaGF2ZSB0byBydW4gdG8gc3RlcHM6IEZpcnN0IGNyZWF0aW9uIG9m
DQoNCmNlcnRpZmljYXRlLCBhbmQgc2Vjb25kIGNvbXBpbGluZyBjb2RlIGFuZCBwbGF5IGl0IG9u
IHRoZSBkZXZpY2UuDQoNCkkgd291bGQgYWxzbyBzdWdnZXN0IHRvIGF2b2lkIHRoZSB0ZXJtIHN1
YnNjcmliZXIgc2luY2UgaXQgaGFzIHR3byBvdGhlcg0KDQptZWFuaW5ncyB0aGF0IG1pZ2h0IGNv
bmZ1c2U6DQoNCiBhKSBUaGUgdGVybSBzdWJzY3JpYmVyIGlzIG9mdGVuIHVzZWQgaW4gY29udGV4
dCBvZiB0ZWxlY29tbXVuaWNhdGlvbiBhcw0KDQp0aGUgdXNlciB3aG8gaGFzIGEgY29udHJhY3Qg
d2l0aCBhIHRlbGVjb21tdW5pY2F0aW9uIG9wZXJhdG9yLg0KDQogYikgVGhlIHNlY29uZCB1c2Ug
aXMgaW4gY29udGV4dCBvZiBwcm90b2NvbHMgdGhhdCB1c2UgYXN5bmNocm9ub3VzDQoNCmNvbW11
bmljYXRpb24gKGxpa2UgWE1QUCkuDQoNCg0KDQpJIGJlbGlldmUgeW91ciBub3Rpb24gb2Ygc3Vi
c2NyaWJlciBkb2VzIG5vdCByZWxhdGUgdG8gdGhvc2UgdHdvDQoNCmV4aXN0aW5nIHVzZXMuIEkg
Z3Vlc3MgeW91IGFyZSBtb3JlIHVzaW5nIHRoZSB0ZXJtIHN1YnNjcmliZXIgdG8gcmVmZXINCg0K
dG8gYSBkZXZpY2UgdGhhdCB3YW50cyBzb21lIGRhdGEgZnJvbSBhIHNlbnNvci4gSXMgdGhpcyBj
b3JyZWN0Pw0KDQpUaGFua3MgZm9yIHRoZSBoaW50LiBZZXMgeW91IGFyZSByaWdodC4gVGhlIHN1
YnNjcmliZXIgc2hvdWxkIGJlIGENCg0KZGV2aWNlIHRoYXQgd2FudHMgZGF0YSBmcm9tIHRoZSBz
ZW5zb3IuDQoNClVzdWFsbHkgdGhpcyBpcyBvbmUgb3V0c2lkZSBvZiB0aGUgV1NOLiBEbyB5b3Ug
aGF2ZSBhIHN1Z2dlc3Rpb24gZm9yIG5ldw0KDQpuYW1lPw0KDQo1KSBSb2xlcyBpbiB5b3VyIGFy
Y2hpdGVjdHVyZS4NCg0KDQoNCkl0IHNlZW1zIHRoYXQgeW91IGFzc3VtZSB0aGF0IHRoZSBJb1Qg
ZGV2aWNlcyBhcmUgcHVibGlzaGVycyBhbmQgdGhhdA0KDQp0aGVyZSBhcmUgc3Vic2NyaWJlcnMg
d2hvIHRhbGsgdG8gdGhlc2UgcHVibGlzaGVycy4gSW4gc29tZSBvdGhlciBjYXNlcw0KDQpJIGhh
dmUgc2VlbiBhcmNoaXRlY3R1cmVzIHdoZXJlIHRoZSBJb1QgZGV2aWNlcyAoc2Vuc29ycykgdXBs
b2FkIHRoZQ0KDQpkYXRhIHRvIHNvbWUgc2VydmVycyB3aXRob3V0IGhhdmluZyB0byBhY3QgYXMg
c2VydmVycyB0aGVtc2VsdmVzLiBJbg0KDQp5b3VyIGFyY2hpdGVjdHVyZSBpdCBmZWVscyBsaWtl
IHRoZSBzZW5zb3Igbm9kZXMgaW1wbGVtZW50IHRoZQ0KDQpzZXJ2ZXItc2lkZSBmdW5jdGlvbmFs
aXR5DQoNClRoYXQgd2FzIG5vdCBvdXIgaW50ZW50aW9uLg0KDQpPdXIgbmV0d29yayBoYXMgcHVz
aCBjaGFyYWN0ZXJpc3RpY3MgdXAgdG8gdGhlIHNlcnZlci4gRGF0YSBwdWJsaXNoaW5nDQoNCnJ1
bnMgb3ZlciBzZXJ2ZXIsIGJlY2F1c2UgaXQgaGFzIG1vcmUgcmVzb3VyY2VzIGFuZCwgdGhlcmVm
b3JlLCBjYW4NCg0KaGFuZGxlIHJlcXVlc3RzIGJldHRlci4gSXQgaXMgdGhlIGdhdGUgdG8gdGhl
IHdvcmxkLg0KDQpQdWxsIGlzIG9ubHkgcGVyZm9ybWVkIGlmIHlvdSByZXF1aXJlIGRhdGEgKG1l
YXN1cmVtZW50cykgYXQgYSB0aW1lIHRoYXQNCg0KaXMgbm90IHByZS1kZWZpbmVkLg0KDQpJbiBT
ZWN0aW9uIDQuMi4yIHlvdSB3cml0ZSB0aGF0IHlvdSByZWNvbW1lbmQgYW4gT3BlblNTTCBpbXBs
ZW1lbnRhdGlvbg0KDQpvbiB0aGUgc2VydmVyIHNpZGUgYnV0IHRoZSBzZXJ2ZXItc2lkZSB3b3Vs
ZCBiZSB0aGUgSW9UIGRldmljZS4gV2hpbGUgaXQNCg0Kd291bGQgYmUgaW5hcHByb3ByaWF0ZSB0
byByZWNvbW1lbmQgYSBzcGVjaWZpYyBpbXBsZW1lbnRhdGlvbiBpbiBhbiBJRVRGDQoNCmRyYWZ0
L1JGQyBpdCBhbHNvIHJhaXNlcyB0aGUgcXVlc3Rpb25zIGFib3V0IHRoZSBleHBlY3RhdGlvbnMg
b24gdGhlDQoNCnNlcnZlci1zaWRlLg0KDQpUaGFua3MgZm9yIHRoZSBoaW50Lg0KDQpXZSB1c2Ug
T3BlblNTTCBvbiB0aGUgc2VydmVyIGJ1dCBub3Qgd2l0aGluIHRoZSBXU04uIE9wZW5TU0wgaXMg
dXNlZA0KDQplc3BlY2lhbGx5IGZvciBtYW5hZ2luZyByaWdodHMsIHJlcXVlc3RzLCBhbmQgY2Vy
dGlmaWNhdGVzLg0KDQo2LiBDZXJ0aWZpY2F0ZSBjb250ZW50DQoNCg0KDQpJbiBTZWN0aW9uIDQu
Mi4yIHlvdSBkZXNjcmliZSB0aGUgY29udGVudCBvZiBhIGNlcnRpZmljYXRlIGFuZCB5b3UNCg0K
aW5kaWNhdGUgdGhhdCB0aGUgY29tbW9uTmFtZSBpcyBzZXQgdG8gImxvY2FsaG9zdCIuIEl0IHNl
ZW1zIHRvIGJlDQoNCnVzZWxlc3MgdG8gaW5jbHVkZSB0aGlzIGluIHRoZSBjZXJ0aWZpY2F0ZSBz
aW5jZSBhIENBIHdvdWxkIG5vdCBiZSBhYmxlDQoNCnRvIHZlcmlmeSB0aGlzIGlkZW50aXR5IGlu
Zm9ybWF0aW9uIG5vciB3b3VsZCBhbnkgcGFydHkgdmVyaWZ5aW5nIGl0IGJlDQoNCmFibGUgdG8g
dXNlIGl0IGluIGEgbWVhbmluZ2Z1bCB3YXkuDQoNCkxvY2FsaG9zdCBpbiBvdXIgY2FzZSBpcyBh
IHNwZWNpYWwgSVAgYWRkcmVzcyAoaGVyZTogc2luaykuIFlvdSBhcmUNCg0KcmlnaHQsIHdlIHNo
b3VsZCByZW5hbWUgaXQgYW5kIG1ha2UgY2xlYXIgdGhhdCBpdCBpcyBhbiBJUCBhZGRyZXNzLiBT
bw0KDQp5b3UgY2FuIHNldCBpcyBsaWtlIHlvdSB3YW50Lg0KDQpJdCBhbHNvIHNlZW1zIHRvIGJl
IGluIHZpb2xhdGlvbiBvZiB3aGF0IHlvdSB3cml0ZSBpbiBTZWN0aW9uIDUuMiB3aGVyZQ0KDQp5
b3Ugc3RhdGUgdGhhdCAiZXZlcnkgcHVibGlzaGVyIGluIHRoZSBuZXR3b3JrIE1VU1QgaGF2ZSBh
biB1bmlxdWUNCg0KaWRlbnRpdHkuIi4NCg0KDQoNCllvdSBhbHNvIGluZGljYXRlZCBtb3JlIGNv
bXBsZXRlIGluZm9ybWF0aW9uIGZvciBpbmNsdXNpb24gaW4gdGhlDQoNCmNlcnRpZmljYXRlIGJ1
dCBpdCBpcyBub3QgY2xlYXIgdG8gbWUgd2hhdCBwdXJwb3NlIGl0IHNlcnZlcy4gQ291bGQgeW91
DQoNCmV4cGxhaW4/DQoNCldpbGwgZG8gaXQgYXNhcC4NCg0KNy4gUHJpdmFjeQ0KDQoNCg0KSW4g
U2VjdGlvbiA1IHlvdSBpbmRpY2F0ZSBzb21lIHByaXZhY3kgcmVsYXRlZCBhc3BlY3RzIGFuZCB5
b3UgaGludCB0byAiDQoNCmFjY2VzcyByZWd1bGF0aW9ucyBiYXNlZCBvbiBsZWdhbCBhbmQgcmVn
dWxhdGl2ZSBpbXBsaWNhdGlvbnMiLiBDb3VsZA0KDQp5b3UgYnJpZWZseSBleHBsYWluIHdoYXQg
dGhvc2UgcmVxdWlyZW1lbnRzIGFyZT8NCg0KVGhpcyBwYXJ0IHdlIHB1dCBpbiBkdWUgdG8gdGhl
IGRlcGxveW1lbnQgYW5kIHByb2plY3QgcmVsYXRpb25zIHdlIGFyZQ0KDQpydW5uaW5nIGF0IHRo
ZSBtb21lbnQuDQoNCkhlcmUgaXQgbWVhbnMgdGhhdCBub3QgZXZlcnkgZGV2aWNlIGNhbiBiZSBh
YmxlIHRvIGFjY2VzcyB0aGUgZGF0YSwgZm9yDQoNCmV4YW1wbGUsIGR1ZSB0byBsZWdhbCBpc3N1
ZXMgaW4gdGhlIHJlZ2lvbiAoRVUsIENILCBVUyByaWdodHMpLg0KDQpUaGlzIGhhcyB0byBiZSBz
dG9yZWQgY2VudHJhbCBpbiB0aGUgbmV0d29yayBhbmQgaXQgaGFzIHRvIGJlIGNoZWNrZWQNCg0K
YmVmb3JlIGdpdmluZyBhY2Nlc3MgYW5kIGNyZWF0aW5nIHRoZSBjb3JyZXNwb25kaW5nIGFjY2Vz
cyB0aWNrZXQuDQoNCkhlcmUgd2UgcmVmZXIgdG8gdGhlIGZvbGxvd2luZyBwdWJsaWNhdGlvbnM6
DQoNCg0KDQpSYWRoaWthIEdhcmcsIENvcmlubmEgU2NobWl0dCwgQnVya2hhcmQgU3RpbGxlcjog
L0ludmVzdGlnYXRpbmcNCg0KUmVndWxhdGl2ZSBJbXBsaWNhdGlvbnMgZm9yIFVzZXItZ2VuZXJh
dGVkIENvbnRlbnQgYW5kIGEgRGVzaWduDQoNClByb3Bvc2FsLzsgRGVncnV5dGVyLCBQSUstUHJh
eGlzIGRlciBJbmZvcm1hdGlvbnN2ZXJhcmJlaXR1bmcgdW5kDQoNCktvbW11bmlrYXRpb24sIFZv
bC4gMzYsIE5vLiA0LCBEZWNlbWJlciAyMDEzLCBJU1NOIDA5MzAtNTE1NywgcHAgMeKAkzExLg0K
DQpkb2k6MTAuMTUxNS9waWstMjAxMy0wMDQyIDxodHRwOi8vZHguZG9pLm9yZy8xMC4xNTE1L3Bp
ay0yMDEzLTAwNDI+PGh0dHA6Ly9keC5kb2kub3JnLzEwLjE1MTUvcGlrLTIwMTMtMDA0Mj4gVVJM
Og0KDQpodHRwOi8vd3d3LmRlZ3J1eXRlci5jb20vdmlldy9qL3Bpa28uYWhlYWQtb2YtcHJpbnQv
cGlrLTIwMTMtMDA0Mi9waWstMjAxMy0wMDQyLnhtbA0KDQoNCg0KUmFkaGlrYSBHYXJnLCBDaHJp
c3RvcyBUc2lhcmFzLCBCdXJraGFyZCBTdGlsbGVyLCBDb3Jpbm5hIFNjaG1pdHQsDQoNCkRhbmll
bCBEw7Zubmk6IC9EZWxpdmVyYWJsZSBENy4xIC0gQmFzaWNzLCBSZXF1aXJlbWVudHMsIFNjZW5h
cmlvcywgYW5kDQoNCkFyY2hpdGVjdHVyZTogSW4gRkxBTUlOR08vOyBSYWRoaWthIEdhcmcgKEVk
dC4pLCBaw7xyaWNoLCBTd2l0emVybGFuZCwNCg0KT2N0b2JlciAyMDEzDQoNCjguIFVzZSBDYXNl
cy4NCg0KDQoNCkkgc3VnZ2VzdCB0byBvbWl0IHRoZSB1c2UgY2FzZXMgZnJvbSB0aGUgZG9jdW1l
bnQgc2luY2UgdGhlIGRlc2NyaXB0aW9uDQoNCmlzIHRvbyBicmllZiB0byBiZSB1c2VmdWwuIEEg
c21hbGwgcmVtYXJrOiBGcm9tIG15IHdvcmsgaW4gdGhlIGVtZXJnZW5jeQ0KDQpzZXJ2aWNlcyBl
bnZpcm9ubWVudCBJIGhhZCBnb3R0ZW4gdGhlIGltcHJlc3Npb24gdGhhdCB0aGVyZSBhcmUgbm8g
cGxhbnMNCg0KdG8gdGFrZSBzZW5zb3IgaW5wdXQgZGlyZWN0bHkgd2hlbiBpbml0aWF0aW5nIGFs
ZXJ0cy4gSW4gZmFjdCwgc2Vuc29yDQoNCmFsZXJ0cyBkbyByYXJlbHkgZXZlbiBnZXQgZGlyZWN0
bHkgdG8gdGhlIGVtZXJnZW5jeSBzZXJ2aWNlcyBhdXRob3JpdGllcw0KDQpidXQgYXJlIHJhdGhl
ciBwcmUtcHJvY2Vzc2VkIGJ5IGFuIGludGVybWVkaWF0ZSBvcmdhbml6YXRpb24gKGJ5DQoNCmh1
bWFucykuIE1heWJlIHlvdSBoYXZlIHNwb2tlbiB3aXRoIG90aGVyIHBlb3BsZSwgd2hvIGhhdmUg
ZGlmZmVyZW50DQoNCnBsYW5zLiBXaGVyZSBkaWQgeW91IGdvdCB5b3VyIGluZm9ybWF0aW9uIGZy
b20/DQoNClRoaXMgc2VjdGlvbiBpcyBiYXNlZCBvbiBkaXNjdXNzaW9uIHdpdGggb3VyIHByb2pl
Y3QgcGFydG5lcnMgd2l0aGluDQoNClNtYXJ0ZW5JVCAod3d3LnNtYXJ0ZW5pdC5ldTxodHRwOi8v
d3d3LnNtYXJ0ZW5pdC5ldT4pIGFuZCBGbGFtaW5nbyAoIGh0dHA6Ly93d3cuZnA3LWZsYW1pbmdv
LmV1KS4NCg0KPGh0dHA6Ly93d3cuZnA3LWZsYW1pbmdvLmV1PjxodHRwOi8vd3d3LmZwNy1mbGFt
aW5nby5ldT4NCg0KDQoNCjkuIEFyY2hpdGVjdHVyZQ0KDQoNCg0KRmlndXJlIDMgc2hvd3MgdGhl
IGFyY2hpdGVjdHVyZSBidXQgaXQgaXMgYSBiaXQgY29uZnVzaW5nIHNpbmNlIGl0IGlzDQoNCm5v
dCBjbGVhciB3aGF0IHRoZSBib3hlcyBhbmQgdGhlIGxpbmVzIG1lYW4uIFRoZSBwdWJsaXNoZXIg
aXMgYSBib3gNCg0Kc2VwYXJhdGUgZnJvbSB0aGUgc2Vuc29ycyBhbmQgZnJvbSB0aGUgZWFybGll
ciBkZXNjcmlwdGlvbiBJIHRob3VnaHQNCg0KdGhhdCB0aGUgc2Vuc29ycyBhcmUgYWN0dWFsbHkg
dGhlIHB1Ymxpc2hlcnMuIEZ1cnRoZXJtb3JlLCB0aGUgZ2F0ZXdheQ0KDQp3YXMgbm90IGRpc2N1
c3NlZCBhcyBhIHJvbGUgdXAgdG8gdGhhdCBwb2ludCBpbiB0aGUgZG9jdW1lbnQuIFRoZQ0KDQpn
YXRld2F5IHNob3dzIHVwIGluIFNlY3Rpb24gNS4zIGFuZCBpdHMgcm9sZSBjb25mdXNlcyBtZS4g
WW91IHdyaXRlOg0KDQoNCg0KIiAgQSBzZW5zb3Igbm9kZSBoYXMgcHVibGlzaGVkIGl0cyBkYXRh
LCB3aGljaCBpcyB0cmFuc21pdHRlZCBpbg0KDQogICBkaXJlY3Rpb24gdG8gdGhlIGdsb2JhbCBz
aW5rIChjZi4gRmlndXJlIDMgd2hlcmUgZ2xvYmFsIHNpbmsgaXMNCg0KICAgbG9jYXRlZCBpbiB0
aGUgZ2F0ZXdheSBjb21wb25lbnQpLg0KDQoiDQoNCg0KDQpEb2VzIHRoZSBzZW5zb3IgcHVibGlz
aCB0aGUgZGF0YSBhdCB0aGUgZ2F0ZXdheT8gRnJvbSB0aGUgZWFybGllcg0KDQpzZWN0aW9ucyBJ
IHRob3VnaHQgdGhhdCB0aGUgc3Vic2NyaWJlciB0YWxrcyB0byB0aGUgcHVibGlzaGVyIGluc3Rl
YWQuDQoNCklzIHRoZSBnYXRld2F5IHRoZSBzdWJzY3JpYmVyPyBXaHkgZG9lc24ndCB0aGUgc2Vu
c29yIHVwbG9hZHMgdGhlIGRhdGENCg0KdG8gc29tZSBzZXJ2ZXIgaW5zdGVhZCAod2hpY2ggaXMg
ZnJlcXVlbnRseSBkb25lIGluIHRvZGF5J3MgSW9UDQoNCmRlcGxveW1lbnRzKS4NCg0KTG90cyBv
ZiBjb21tZW50cy4NCg0KSSB3aWxsIGFkZHJlc3MgYW5kIGNsYXJpZnkgdGhlbSBhc2FwLg0KDQpG
dXJ0aGVybW9yZSwgSSB3aWxsIGFkZCBhIGxlZ2VuZCB0byB0aGUgRmlndXJlIGFuZCBwZXJoYXBz
IG1vZGlmeSBpdA0KDQpiYXNlZCBvbiB5b3UgYWZvcmVtZW50aW9uZWQgY29tbWVudHMuDQoNCldo
eSBkbyB5b3UgY2FsbCB0aGUgZW50aXJlIGRvY3VtZW50ICJ0d28td2F5IGF1dGhlbnRpY2F0aW9u
IiB3aGVuIHRoZQ0KDQp0aGUgdHdvIHdheSBhdXRoZW50aWNhdGlvbiBpcyBqdXN0IG9uZSBzbWFs
bCBwYXJ0IG9mIHRoZSBvdmVyYWxsDQoNCmF1dGhlbnRpY2F0aW9uIHByb2NlZHVyZS4gSW4gZmFj
dCB0aGUgdHdvLXdheSBhdXRoZW50aWNhdGlvbiBpcyB1c2VkDQoNCmJldHdlZW4gdGhlIHN1YnNj
cmliZXIgYW5kIHRoZSBhY2Nlc3MgY29udHJvbCBzZXJ2ZXIgKGFzIHNob3duIGluIEZpZ3VyZQ0K
DQo0KSwgYW5kIGJldHdlZW4gdGhlIHB1Ymxpc2hlciBhbmQgdGhlIGdhdGV3YXkuIEZ1cnRoZXJt
b3JlLCB0aGVyZSBoYXMgdG8NCg0KYmUgc29tZSBhdXRoZW50aWNhdGlvbiBiZXR3ZWVuIHRoZSBz
dWJzY3JpYmVyIGFuZCB0aGUgcHVibGlzaGVyIGFzIHdlbGwNCg0KKGF0IGxlYXN0IEkgaG9wZSBz
bykuDQoNCg0KDQpXaGF0IGlzIHRoZSBwdXJwb3NlIG9mIHRoZSBhY2Nlc3MgdGlja2V0PyBJdCBz
aG93cyB1cCBpbiBTZWN0aW9uIDUuMyBhbmQNCg0KSSB3b25kZXIgd2h5IHRoZXJlIGlzIGEgbmVl
ZCBmb3IgYW4gYWNjZXNzIHRpY2tldCB3aGVuIHRoZSB0d28gcGFydGllcw0KDQooc3Vic2NyaWJl
ciBhbmQgcHVibGlzaGVyKSBhbHJlYWR5IGhhdmUgYSBjZXJ0aWZpY2F0ZS4gV2h5IGNhbm5vdCB5
b3UNCg0KdXNlIHRoZSBjZXJ0aWZpY2F0ZSBmb3IgYXV0aGVudGljYXRpb24gd2l0aCB0aGUgcHVi
bGlzaGVyIHJpZ2h0IGF3YXk/DQoNCg0KDQpXaGVyZSBkbyB5b3Ugc2VlIHRoZSBhY2Nlc3MgY29u
dHJvbCBzZXJ2ZXIgYmVpbmcgZGVwbG95ZWQ/IElzIHRoaXMgYW4NCg0KZW50aXR5IGluIHRoZSBs
b2NhbCBuZXR3b3JrIG9yIHNvbWV0aGluZyB5b3Ugd291bGQgaGF2ZSBvbiB0aGUgSW50ZXJuZXQ/
DQoNCg0KDQpXaHkgZG9lcyB0aGUgcHVibGlzaGVyIGhhdmUgdG8gYXV0aGVudGljYXRlIHRvIHRo
ZSBnYXRld2F5PyBGcm9tIEZpZ3VyZQ0KDQo0IGl0IGlzIG5vdCBjbGVhciB3aGV0aGVyIHRoZSBn
YXRld2F5IGlzIGp1c3QgYW4gb3B0aW9uYWwgY29tcG9uZW50IG9yDQoNCmFuIGludGVncmFsIHBh
cnQgb2YgdGhlIGFyY2hpdGVjdHVyZS4NCg0KDQoNClRoZSBkb2N1bWVudCBkb2VzIG5vdCBleHBs
YWluIHdoYXQgdGhlIGFjY2VzcyB0b2tlbiBpcyBhbmQgaG93IGl0IGlzDQoNCmV4Y2hhbmdlZCBi
ZXR3ZWVuIHRoZSBzdWJzY3JpYmVyIGFuZCB0aGUgcHVibGlzaGVyLg0KDQoNCg0KQnR3LCB0aGUg
dGVybSBDQSBzdGFuZGFyZHMgZm9yIENlcnRpZmljYXRpb24gQXV0aG9yaXR5IHJhdGhlciB0aGFu
DQoNCkNlcnRpZmljYXRlIEF1dGhvcml0eS4NCg0KDQoNCldpbGwgYmUgYWRkcmVzc2VkIHNvb24u
DQoNCjEwLiBIYXJkd2FyZSByZXF1aXJlbWVudHMuDQoNCg0KDQpIYXJkd2FyZSByZXF1aXJlbWVu
dHMgdHlwaWNhbGx5IGFyZSBub3QgYXBwcm9wcmlhdGUgZm9yIElFVEYgZG9jdW1lbnRzLg0KDQpX
aGlsZSB5b3UgbWFrZSB0aGUgYXJndW1lbnQgdGhhdCBhbiBSU0EtYmFzZWQgcHVibGljIGtleSBj
cnlwdG9zeXN0ZW0gaXMNCg0KZ29vZCBlbm91Z2ggZnJvbSBhIHBlcmZvcm1hbmNlIHBvaW50IG9m
IHZpZXcgdGhlIGN1cnJlbnRseSBtYW5kYXRvcnkNCg0KY2lwaGVyc3VpdGVzIHVzZWQgaW4gQ29B
UCBhcmUgYmFzZWQgb24gRUNDIChmb3IgdGhvc2UgdGhhdCByZWx5IG9uDQoNCmFzeW1tZXRyaWMg
Y3J5cHRvKS4gV2hpbGUgaGF2aW5nIGhhcmR3YXJlIHN1cHBvcnQgZm9yIGtleSBzdG9yYWdlIGlz
IGENCg0KZ3JlYXQgaWRlYSBJIHdhcyB3b25kZXJpbmcgaG93IG11Y2ggeW91ciBhcmNoaXRlY3R1
cmUgYWN0dWFsbHkgcmVsaWVzIG9uDQoNCml0LiBNeSBpbXByZXNzaW9uIHRoYXQgaXQgd291bGQg
d29yayBmaW5lIGp1c3Qgd2l0aG91dCBhIFRQTSBjaGlwLiBCdXQNCg0KeW91IG1pZ2h0IGhhdmUg
bW9yZSBoYXJkd2FyZSBleHBlcmllbmNlIHRoYW4gSSBoYXZlLiBDb3VsZCB5b3UgcG9pbnQgbWUN
Cg0KdG8gc29tZSBoYXJkd2FyZSB0aGF0IHlvdSBoYXZlIGluIG1pbmQgdXNpbmc/DQoNCg0KDQpX
ZSBwdXQgdGhpcyBzZWN0aW9uIGZvciBjb21wbGV0ZW5lc3MgYW5kIHRvIHNob3cgdGhhdCBhbiBp
bXBsZW1lbnRhdGlvbg0KDQpleGlzdHMuDQoNCkNvbmNlcm5pbmcgc2Vuc29yIG5vZGVzIGFuZCBU
UE0gd2UgYXJlIHVzaW5nIE9QQUwgZnJvbSBDU0lSTy4gVHJ1c3RpbmcNCg0KQ29tcHV0aW5nIGJl
Y29tZXMgcmVsZXZhbnQgbm93YWRheXMgd2hlbiB0aGlua2luZyBhYm91dCBzZWN1cmluZyBkYXRh
Lg0KDQpEcmF3YmFjayBpcyB0aGF0IGlmIHRoZSBUUE0gY2hpcCBpcyBicm9rZW4gb3IgeW91IGNo
YW5nZSBzb21ldGhpbmcNCg0KZHVyaW5nIGJvb3RpbmcgZXZlcnl0aGluZyBpcyBsb3N0LiBBZHZh
bnRhZ2UgaXMgdGhhdCB0aGUgc3RvcmFnZSByb290DQoNCmtleSBpcyBzdG9yZWQgc2FmZWx5IGFu
ZCBvbmx5IGRlcml2YXRlcyBhcmUgdXNlZCBmb3IgeW91ciBhcHBsaWNhdGlvbnMuDQoNCg0KDQpI
b3BlIHRvIGFuc3dlciBtb3N0IGltcG9ydGFudCBxdWVzdGlvbnMgb3IgY29tbWVudHMgbm93LiBP
dGhlcnMgd2lsbCBiZQ0KDQphZGRyZXNzZWQgc29vbi4NCg0KWW91IGNhbiBhbHNvIHRhbGsgdG8g
bWUgZHVyaW5nIElFVEYgaW4gTG9uZG9uLg0KDQoNCg0KUmVnYXJkcywNCg0KQ29yaW5uYQ0KDQoN
Cg0KDQoNCg0KDQpfX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19f
Xw0KDQpBY2UgbWFpbGluZyBsaXN0DQoNCkFjZUBpZXRmLm9yZzxtYWlsdG86QWNlQGlldGYub3Jn
Pg0KDQpodHRwczovL3d3dy5pZXRmLm9yZy9tYWlsbWFuL2xpc3RpbmZvL2FjZQ0KDQoNCg0KDQoN
Cg0KDQoNCl9fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fDQoN
CkFjZSBtYWlsaW5nIGxpc3QNCg0KQWNlQGlldGYub3JnPG1haWx0bzpBY2VAaWV0Zi5vcmc+DQoN
Cmh0dHBzOi8vd3d3LmlldGYub3JnL21haWxtYW4vbGlzdGluZm8vYWNlDQoNCi0tDQpbY2lkOmlt
YWdlMDAxLnBuZ0AwMUNGOTlENC4xNzZFRkQ2MF0NCg==

--_000_34966E97BE8AD64EAE9D3D6E4DEE36F25817518DSZXEMA501MBSchi_
Content-Type: text/html; charset="utf-8"
Content-Transfer-Encoding: base64

PGh0bWwgeG1sbnM6dj0idXJuOnNjaGVtYXMtbWljcm9zb2Z0LWNvbTp2bWwiIHhtbG5zOm89InVy
bjpzY2hlbWFzLW1pY3Jvc29mdC1jb206b2ZmaWNlOm9mZmljZSIgeG1sbnM6dz0idXJuOnNjaGVt
YXMtbWljcm9zb2Z0LWNvbTpvZmZpY2U6d29yZCIgeG1sbnM6eD0idXJuOnNjaGVtYXMtbWljcm9z
b2Z0LWNvbTpvZmZpY2U6ZXhjZWwiIHhtbG5zOm09Imh0dHA6Ly9zY2hlbWFzLm1pY3Jvc29mdC5j
b20vb2ZmaWNlLzIwMDQvMTIvb21tbCIgeG1sbnM9Imh0dHA6Ly93d3cudzMub3JnL1RSL1JFQy1o
dG1sNDAiPg0KPGhlYWQ+DQo8bWV0YSBodHRwLWVxdWl2PSJDb250ZW50LVR5cGUiIGNvbnRlbnQ9
InRleHQvaHRtbDsgY2hhcnNldD11dGYtOCI+DQo8bWV0YSBuYW1lPSJHZW5lcmF0b3IiIGNvbnRl
bnQ9Ik1pY3Jvc29mdCBXb3JkIDEyIChmaWx0ZXJlZCBtZWRpdW0pIj4NCjwhLS1baWYgIW1zb10+
PHN0eWxlPnZcOioge2JlaGF2aW9yOnVybCgjZGVmYXVsdCNWTUwpO30NCm9cOioge2JlaGF2aW9y
OnVybCgjZGVmYXVsdCNWTUwpO30NCndcOioge2JlaGF2aW9yOnVybCgjZGVmYXVsdCNWTUwpO30N
Ci5zaGFwZSB7YmVoYXZpb3I6dXJsKCNkZWZhdWx0I1ZNTCk7fQ0KPC9zdHlsZT48IVtlbmRpZl0t
LT48c3R5bGU+PCEtLQ0KLyogRm9udCBEZWZpbml0aW9ucyAqLw0KQGZvbnQtZmFjZQ0KCXtmb250
LWZhbWlseTrlrovkvZM7DQoJcGFub3NlLTE6MiAxIDYgMCAzIDEgMSAxIDEgMTt9DQpAZm9udC1m
YWNlDQoJe2ZvbnQtZmFtaWx5OiJDYW1icmlhIE1hdGgiOw0KCXBhbm9zZS0xOjIgNCA1IDMgNSA0
IDYgMyAyIDQ7fQ0KQGZvbnQtZmFjZQ0KCXtmb250LWZhbWlseTpDYWxpYnJpOw0KCXBhbm9zZS0x
OjIgMTUgNSAyIDIgMiA0IDMgMiA0O30NCkBmb250LWZhY2UNCgl7Zm9udC1mYW1pbHk6IlxA5a6L
5L2TIjsNCglwYW5vc2UtMToyIDEgNiAwIDMgMSAxIDEgMSAxO30NCi8qIFN0eWxlIERlZmluaXRp
b25zICovDQpwLk1zb05vcm1hbCwgbGkuTXNvTm9ybWFsLCBkaXYuTXNvTm9ybWFsDQoJe21hcmdp
bjowY207DQoJbWFyZ2luLWJvdHRvbTouMDAwMXB0Ow0KCWZvbnQtc2l6ZToxMi4wcHQ7DQoJZm9u
dC1mYW1pbHk6IlRpbWVzIE5ldyBSb21hbiIsInNlcmlmIjsNCgljb2xvcjpibGFjazt9DQphOmxp
bmssIHNwYW4uTXNvSHlwZXJsaW5rDQoJe21zby1zdHlsZS1wcmlvcml0eTo5OTsNCgljb2xvcjpi
bHVlOw0KCXRleHQtZGVjb3JhdGlvbjp1bmRlcmxpbmU7fQ0KYTp2aXNpdGVkLCBzcGFuLk1zb0h5
cGVybGlua0ZvbGxvd2VkDQoJe21zby1zdHlsZS1wcmlvcml0eTo5OTsNCgljb2xvcjpwdXJwbGU7
DQoJdGV4dC1kZWNvcmF0aW9uOnVuZGVybGluZTt9DQpwcmUNCgl7bXNvLXN0eWxlLXByaW9yaXR5
Ojk5Ow0KCW1zby1zdHlsZS1saW5rOiJIVE1MIOmihOiuvuagvOW8jyBDaGFyIjsNCgltYXJnaW46
MGNtOw0KCW1hcmdpbi1ib3R0b206LjAwMDFwdDsNCglmb250LXNpemU6MTAuMHB0Ow0KCWZvbnQt
ZmFtaWx5OiJDb3VyaWVyIE5ldyI7DQoJY29sb3I6YmxhY2s7fQ0Kc3Bhbi5IVE1MQ2hhcg0KCXtt
c28tc3R5bGUtbmFtZToiSFRNTCDpooTorr7moLzlvI8gQ2hhciI7DQoJbXNvLXN0eWxlLXByaW9y
aXR5Ojk5Ow0KCW1zby1zdHlsZS1saW5rOiJIVE1MIOmihOiuvuagvOW8jyI7DQoJZm9udC1mYW1p
bHk6IkNvdXJpZXIgTmV3IjsNCgljb2xvcjpibGFjazt9DQpzcGFuLkVtYWlsU3R5bGUxOQ0KCXtt
c28tc3R5bGUtdHlwZTpwZXJzb25hbC1yZXBseTsNCglmb250LWZhbWlseToiQ2FsaWJyaSIsInNh
bnMtc2VyaWYiOw0KCWNvbG9yOiMxRjQ5N0Q7fQ0KLk1zb0NocERlZmF1bHQNCgl7bXNvLXN0eWxl
LXR5cGU6ZXhwb3J0LW9ubHk7DQoJZm9udC1zaXplOjEwLjBwdDt9DQpAcGFnZSBXb3JkU2VjdGlv
bjENCgl7c2l6ZTo2MTIuMHB0IDc5Mi4wcHQ7DQoJbWFyZ2luOjcyLjBwdCA5MC4wcHQgNzIuMHB0
IDkwLjBwdDt9DQpkaXYuV29yZFNlY3Rpb24xDQoJe3BhZ2U6V29yZFNlY3Rpb24xO30NCi0tPjwv
c3R5bGU+PCEtLVtpZiBndGUgbXNvIDldPjx4bWw+DQo8bzpzaGFwZWRlZmF1bHRzIHY6ZXh0PSJl
ZGl0IiBzcGlkbWF4PSIxMDI2IiAvPg0KPC94bWw+PCFbZW5kaWZdLS0+PCEtLVtpZiBndGUgbXNv
IDldPjx4bWw+DQo8bzpzaGFwZWxheW91dCB2OmV4dD0iZWRpdCI+DQo8bzppZG1hcCB2OmV4dD0i
ZWRpdCIgZGF0YT0iMSIgLz4NCjwvbzpzaGFwZWxheW91dD48L3htbD48IVtlbmRpZl0tLT4NCjwv
aGVhZD4NCjxib2R5IGJnY29sb3I9IndoaXRlIiBsYW5nPSJaSC1DTiIgbGluaz0iYmx1ZSIgdmxp
bms9InB1cnBsZSI+DQo8ZGl2IGNsYXNzPSJXb3JkU2VjdGlvbjEiPg0KPHAgY2xhc3M9Ik1zb05v
cm1hbCI+PHNwYW4gbGFuZz0iRU4tVVMiIHN0eWxlPSJmb250LXNpemU6MTAuNXB0O2ZvbnQtZmFt
aWx5OiZxdW90O0NhbGlicmkmcXVvdDssJnF1b3Q7c2Fucy1zZXJpZiZxdW90Oztjb2xvcjojMUY0
OTdEIj5IaSBDb3Jpbm5hLDxvOnA+PC9vOnA+PC9zcGFuPjwvcD4NCjxwIGNsYXNzPSJNc29Ob3Jt
YWwiPjxzcGFuIGxhbmc9IkVOLVVTIiBzdHlsZT0iZm9udC1zaXplOjEwLjVwdDtmb250LWZhbWls
eTomcXVvdDtDYWxpYnJpJnF1b3Q7LCZxdW90O3NhbnMtc2VyaWYmcXVvdDs7Y29sb3I6IzFGNDk3
RCI+PG86cD4mbmJzcDs8L286cD48L3NwYW4+PC9wPg0KPHAgY2xhc3M9Ik1zb05vcm1hbCI+PHNw
YW4gbGFuZz0iRU4tVVMiIHN0eWxlPSJmb250LXNpemU6MTAuNXB0O2ZvbnQtZmFtaWx5OiZxdW90
O0NhbGlicmkmcXVvdDssJnF1b3Q7c2Fucy1zZXJpZiZxdW90Oztjb2xvcjojMUY0OTdEIj5QbGVh
c2UgZmluZCBteSBwZXJzb25hbCBmZWVkYmFjayB0byB5b3VyIGRyYWZ0OjxvOnA+PC9vOnA+PC9z
cGFuPjwvcD4NCjxwIGNsYXNzPSJNc29Ob3JtYWwiPjxzcGFuIGxhbmc9IkVOLVVTIiBzdHlsZT0i
Zm9udC1zaXplOjEwLjVwdDtmb250LWZhbWlseTomcXVvdDtDYWxpYnJpJnF1b3Q7LCZxdW90O3Nh
bnMtc2VyaWYmcXVvdDs7Y29sb3I6IzFGNDk3RCI+PG86cD4mbmJzcDs8L286cD48L3NwYW4+PC9w
Pg0KPHAgY2xhc3M9Ik1zb05vcm1hbCI+PHNwYW4gbGFuZz0iRU4tVVMiIHN0eWxlPSJmb250LXNp
emU6MTAuNXB0O2ZvbnQtZmFtaWx5OiZxdW90O0NhbGlicmkmcXVvdDssJnF1b3Q7c2Fucy1zZXJp
ZiZxdW90Oztjb2xvcjojMUY0OTdEIj5TZWN0aW9uIDIsIFRlcm1pbm9sb2d5OiBDdXJyZW50bHks
IG91ciBjaGFydGVyIGFuZCBtb3N0IG9mIHRoZSBvdGhlciBzdWJtaXR0ZWQgZHJhZnRzIHVzZSDi
gJxDbGllbnTigJ0sIOKAnFJlc291cmNlIFNlcnZlcuKAnSwg4oCcQXV0aG9yaXphdGlvbiBTZXJ2
ZXLigJ0uDQogVG8ga2VlcCBjb25zaXN0ZW5jeSwgaXQgaXMgYmV0dGVyIHRvIHVzZSB0aGVzZSB0
ZXJtaW5vbG9naWVzIHRvIHJlcGxhY2Ug4oCcUHVibGlzaGVy4oCdLCDigJxTdWJzY3JpYmVy4oCd
IGFuZCDigJxBY2Nlc3MgQ29udHJvbCBTZXJ2ZXLigJ0uPG86cD48L286cD48L3NwYW4+PC9wPg0K
PHAgY2xhc3M9Ik1zb05vcm1hbCI+PHNwYW4gbGFuZz0iRU4tVVMiIHN0eWxlPSJmb250LXNpemU6
MTAuNXB0O2ZvbnQtZmFtaWx5OiZxdW90O0NhbGlicmkmcXVvdDssJnF1b3Q7c2Fucy1zZXJpZiZx
dW90Oztjb2xvcjojMUY0OTdEIj48bzpwPiZuYnNwOzwvbzpwPjwvc3Bhbj48L3A+DQo8cCBjbGFz
cz0iTXNvTm9ybWFsIj48c3BhbiBsYW5nPSJFTi1VUyIgc3R5bGU9ImZvbnQtc2l6ZToxMC41cHQ7
Zm9udC1mYW1pbHk6JnF1b3Q7Q2FsaWJyaSZxdW90OywmcXVvdDtzYW5zLXNlcmlmJnF1b3Q7O2Nv
bG9yOiMxRjQ5N0QiPlNlY3Rpb24gMywgSGlnaCBMZXZlbCBEZXNpZ24gUmVxdWlyZW1lbnRzOiB0
aGUgb2JqZWN0aXZlIG9mIHRoaXMgc2VjdGlvbiBpcyBxdWl0ZSBzaW1pbGFyIHRvIHRoZSDigJxk
ZXNpZ24gY29uc2lkZXJhdGlvbnPigJ0gZHJhZnQuIEl0IGlzIGJldHRlciB0bw0KIGNvbnNvbGlk
YXRlIHRoaXMgc2VjdGlvbiB3aXRoIHRoZSBkcmFmdC48bzpwPjwvbzpwPjwvc3Bhbj48L3A+DQo8
cCBjbGFzcz0iTXNvTm9ybWFsIj48c3BhbiBsYW5nPSJFTi1VUyIgc3R5bGU9ImZvbnQtc2l6ZTox
MC41cHQ7Zm9udC1mYW1pbHk6JnF1b3Q7Q2FsaWJyaSZxdW90OywmcXVvdDtzYW5zLXNlcmlmJnF1
b3Q7O2NvbG9yOiMxRjQ5N0QiPjxhIGhyZWY9Imh0dHA6Ly9kYXRhdHJhY2tlci5pZXRmLm9yZy9k
b2MvZHJhZnQtc2VpdHotYWNlLWRlc2lnbi1jb25zaWRlcmF0aW9ucy8iPmh0dHA6Ly9kYXRhdHJh
Y2tlci5pZXRmLm9yZy9kb2MvZHJhZnQtc2VpdHotYWNlLWRlc2lnbi1jb25zaWRlcmF0aW9ucy88
L2E+PG86cD48L286cD48L3NwYW4+PC9wPg0KPHAgY2xhc3M9Ik1zb05vcm1hbCI+PHNwYW4gbGFu
Zz0iRU4tVVMiIHN0eWxlPSJmb250LXNpemU6MTAuNXB0O2ZvbnQtZmFtaWx5OiZxdW90O0NhbGli
cmkmcXVvdDssJnF1b3Q7c2Fucy1zZXJpZiZxdW90Oztjb2xvcjojMUY0OTdEIj48bzpwPiZuYnNw
OzwvbzpwPjwvc3Bhbj48L3A+DQo8cCBjbGFzcz0iTXNvTm9ybWFsIj48c3BhbiBsYW5nPSJFTi1V
UyIgc3R5bGU9ImZvbnQtc2l6ZToxMC41cHQ7Zm9udC1mYW1pbHk6JnF1b3Q7Q2FsaWJyaSZxdW90
OywmcXVvdDtzYW5zLXNlcmlmJnF1b3Q7O2NvbG9yOiMxRjQ5N0QiPlNlY3Rpb24gNCwgSXQgc2Vl
bXMgdGhhdCB0aGF0IG1vc3Qgb2YgdGhlIGRlc2lnbiBjb25zaWRlcmF0aW9ucyAoZS5nLiBhc3N1
bWVkIG5ldHdvcmsgc3RhY2ssIGhhbmRzaGFrZSBtZXNzYWdlIGZsb3dzKSB3aWxsIGFsc28gYmUg
YXBwbGllZCBmb3INCiBDbGFzcyAxIGRldmljZXMuIEl0IGlzIGJldHRlciB0byBpbmRpY2F0ZSB0
aGUgY29tbW9uIGRlc2lnbiBjb25zaWRlcmF0aW9ucyBmaXJzdCwgdGhlbiBoaWdobGlnaHQgd2hh
dCBtb3JlIHdlIGNhbiBhY2hpZXZlIGJ5IENsYXNzIDIgZGV2aWNlcy48bzpwPjwvbzpwPjwvc3Bh
bj48L3A+DQo8cCBjbGFzcz0iTXNvTm9ybWFsIj48c3BhbiBsYW5nPSJFTi1VUyIgc3R5bGU9ImZv
bnQtc2l6ZToxMC41cHQ7Zm9udC1mYW1pbHk6JnF1b3Q7Q2FsaWJyaSZxdW90OywmcXVvdDtzYW5z
LXNlcmlmJnF1b3Q7O2NvbG9yOiMxRjQ5N0QiPjxvOnA+Jm5ic3A7PC9vOnA+PC9zcGFuPjwvcD4N
CjxwIGNsYXNzPSJNc29Ob3JtYWwiPjxzcGFuIGxhbmc9IkVOLVVTIiBzdHlsZT0iZm9udC1zaXpl
OjEwLjVwdDtmb250LWZhbWlseTomcXVvdDtDYWxpYnJpJnF1b3Q7LCZxdW90O3NhbnMtc2VyaWYm
cXVvdDs7Y29sb3I6IzFGNDk3RCI+U2VjdGlvbiA1LjEsIDUuMiBhbmQgNiwgVXNlIGNhc2VzIGFu
ZCBSZXF1aXJlbWVudHM6IE1heWJlIGl0IGlzIGJldHRlciB0byBjb25zb2xpZGF0ZSB0aGVzZSBz
ZWN0aW9ucyB3aXRoIHRoZSDigJxVc2UgY2FzZXMgYW5kIHJlcXVpcmVtZW50c+KAnSBkcmFmdDo8
bzpwPjwvbzpwPjwvc3Bhbj48L3A+DQo8cCBjbGFzcz0iTXNvTm9ybWFsIj48c3BhbiBsYW5nPSJF
Ti1VUyIgc3R5bGU9ImZvbnQtc2l6ZToxMC41cHQ7Zm9udC1mYW1pbHk6JnF1b3Q7Q2FsaWJyaSZx
dW90OywmcXVvdDtzYW5zLXNlcmlmJnF1b3Q7O2NvbG9yOiMxRjQ5N0QiPjxhIGhyZWY9Imh0dHA6
Ly9kYXRhdHJhY2tlci5pZXRmLm9yZy9kb2MvZHJhZnQtc2VpdHotYWNlLXVzZWNhc2VzLyI+aHR0
cDovL2RhdGF0cmFja2VyLmlldGYub3JnL2RvYy9kcmFmdC1zZWl0ei1hY2UtdXNlY2FzZXMvPC9h
PjxvOnA+PC9vOnA+PC9zcGFuPjwvcD4NCjxwIGNsYXNzPSJNc29Ob3JtYWwiPjxzcGFuIGxhbmc9
IkVOLVVTIiBzdHlsZT0iZm9udC1zaXplOjEwLjVwdDtmb250LWZhbWlseTomcXVvdDtDYWxpYnJp
JnF1b3Q7LCZxdW90O3NhbnMtc2VyaWYmcXVvdDs7Y29sb3I6IzFGNDk3RCI+PG86cD4mbmJzcDs8
L286cD48L3NwYW4+PC9wPg0KPHAgY2xhc3M9Ik1zb05vcm1hbCI+PHNwYW4gbGFuZz0iRU4tVVMi
IHN0eWxlPSJmb250LXNpemU6MTAuNXB0O2ZvbnQtZmFtaWx5OiZxdW90O0NhbGlicmkmcXVvdDss
JnF1b3Q7c2Fucy1zZXJpZiZxdW90Oztjb2xvcjojMUY0OTdEIj5TZWN0aW9uIDUuMywgRGF0YSBB
Y2Nlc3MgUHJvY2VkdXJlczogaXQgc2VlbXMgdGhhdCBpbnRlcmFjdGlvbnMgYmV0d2VlbiBHYXRl
d2F5IGFuZCBQdWJsaXNoZXIgYXJlIG91dCBvZiBzY29wZT8gQmVjYXVzZSBmcm9tIHRoZSBmbG93
cywgdGhlIEdhdGV3YXkNCiBpcyBub3QgaW52b2x2ZWQgaW4gdGhlIGRhdGEgYWNjZXNzIGZsb3cg
YW55IG1vcmUuIEFsc28gYWJvdXQgdGhlIGxhc3QgdHdvIHN0ZXBzIOKAnFR3by13YXkgYXV0aGVu
dGljYXRpb24gaGFuZHNoYWtlIGJldHdlZW4gU3Vic2NyaWJlciBhbmQgUHVibGlzaGVy4oCdIGFu
ZCDigJxEYXRhIGV4Y2hhbmdlIHVzaW5nIERUTFMgc2VjdXJlZCBjaGFubmVs4oCdLCBpbiB0aGVz
ZSB0d28gc3RlcHMsIGlzIOKAnEFjY2VzcyBDb250cm9sIFNlcnZlcuKAnSBpbnZvbHZlZCBpbiB0
aGUNCiBkYXRhIGFjY2VzcyBmbG93PzxvOnA+PC9vOnA+PC9zcGFuPjwvcD4NCjxwIGNsYXNzPSJN
c29Ob3JtYWwiPjxzcGFuIGxhbmc9IkVOLVVTIiBzdHlsZT0iZm9udC1zaXplOjEwLjVwdDtmb250
LWZhbWlseTomcXVvdDtDYWxpYnJpJnF1b3Q7LCZxdW90O3NhbnMtc2VyaWYmcXVvdDs7Y29sb3I6
IzFGNDk3RCI+PG86cD4mbmJzcDs8L286cD48L3NwYW4+PC9wPg0KPHAgY2xhc3M9Ik1zb05vcm1h
bCI+PHNwYW4gbGFuZz0iRU4tVVMiIHN0eWxlPSJmb250LXNpemU6MTAuNXB0O2ZvbnQtZmFtaWx5
OiZxdW90O0NhbGlicmkmcXVvdDssJnF1b3Q7c2Fucy1zZXJpZiZxdW90Oztjb2xvcjojMUY0OTdE
Ij5TZWN0aW9uIDEwLCBGb3JtYWwgU3ludGF4OiBJdCBpcyBiZXR0ZXIgdG8gcHV0IHRoaXMgc2Vj
dGlvbiBhcyBhIHN1Yi1zZWN0aW9uIG9mIFNlY3Rpb24gMiwgdG8gbGV0IHJlYWRlcnMgYmV0dGVy
IHVuZGVyc3RhbmQgdGhlIG1lYW5pbmcgb2YgdGhlDQogYWJicmV2aWF0aW9ucy48bzpwPjwvbzpw
Pjwvc3Bhbj48L3A+DQo8cCBjbGFzcz0iTXNvTm9ybWFsIj48c3BhbiBsYW5nPSJFTi1VUyIgc3R5
bGU9ImZvbnQtc2l6ZToxMC41cHQ7Zm9udC1mYW1pbHk6JnF1b3Q7Q2FsaWJyaSZxdW90OywmcXVv
dDtzYW5zLXNlcmlmJnF1b3Q7O2NvbG9yOiMxRjQ5N0QiPjxvOnA+Jm5ic3A7PC9vOnA+PC9zcGFu
PjwvcD4NCjxwIGNsYXNzPSJNc29Ob3JtYWwiPjxzcGFuIGxhbmc9IkVOLVVTIiBzdHlsZT0iZm9u
dC1zaXplOjEwLjVwdDtmb250LWZhbWlseTomcXVvdDtDYWxpYnJpJnF1b3Q7LCZxdW90O3NhbnMt
c2VyaWYmcXVvdDs7Y29sb3I6IzFGNDk3RCI+VGhhbmtzLDxvOnA+PC9vOnA+PC9zcGFuPjwvcD4N
CjxwIGNsYXNzPSJNc29Ob3JtYWwiPjxzcGFuIGxhbmc9IkVOLVVTIiBzdHlsZT0iZm9udC1zaXpl
OjEwLjVwdDtmb250LWZhbWlseTomcXVvdDtDYWxpYnJpJnF1b3Q7LCZxdW90O3NhbnMtc2VyaWYm
cXVvdDs7Y29sb3I6IzFGNDk3RCI+PG86cD4mbmJzcDs8L286cD48L3NwYW4+PC9wPg0KPHAgY2xh
c3M9Ik1zb05vcm1hbCI+PHNwYW4gbGFuZz0iRU4tVVMiIHN0eWxlPSJmb250LXNpemU6MTAuNXB0
O2ZvbnQtZmFtaWx5OiZxdW90O0NhbGlicmkmcXVvdDssJnF1b3Q7c2Fucy1zZXJpZiZxdW90Oztj
b2xvcjojMUY0OTdEIj5LaW5kIFJlZ2FyZHM8bzpwPjwvbzpwPjwvc3Bhbj48L3A+DQo8cCBjbGFz
cz0iTXNvTm9ybWFsIj48c3BhbiBsYW5nPSJFTi1VUyIgc3R5bGU9ImZvbnQtc2l6ZToxMC41cHQ7
Zm9udC1mYW1pbHk6JnF1b3Q7Q2FsaWJyaSZxdW90OywmcXVvdDtzYW5zLXNlcmlmJnF1b3Q7O2Nv
bG9yOiMxRjQ5N0QiPktlcGVuZyAoSW5kaXZpZHVhbCk8bzpwPjwvbzpwPjwvc3Bhbj48L3A+DQo8
cCBjbGFzcz0iTXNvTm9ybWFsIj48c3BhbiBsYW5nPSJFTi1VUyIgc3R5bGU9ImZvbnQtc2l6ZTox
MC41cHQ7Zm9udC1mYW1pbHk6JnF1b3Q7Q2FsaWJyaSZxdW90OywmcXVvdDtzYW5zLXNlcmlmJnF1
b3Q7O2NvbG9yOiMxRjQ5N0QiPjxvOnA+Jm5ic3A7PC9vOnA+PC9zcGFuPjwvcD4NCjxkaXYgc3R5
bGU9ImJvcmRlcjpub25lO2JvcmRlci1sZWZ0OnNvbGlkIGJsdWUgMS41cHQ7cGFkZGluZzowY20g
MGNtIDBjbSA0LjBwdCI+DQo8ZGl2Pg0KPGRpdiBzdHlsZT0iYm9yZGVyOm5vbmU7Ym9yZGVyLXRv
cDpzb2xpZCAjQjVDNERGIDEuMHB0O3BhZGRpbmc6My4wcHQgMGNtIDBjbSAwY20iPg0KPHAgY2xh
c3M9Ik1zb05vcm1hbCI+PGI+PHNwYW4gc3R5bGU9ImZvbnQtc2l6ZToxMC4wcHQ7Zm9udC1mYW1p
bHk65a6L5L2TO2NvbG9yOndpbmRvd3RleHQiPuWPkeS7tuS6ujxzcGFuIGxhbmc9IkVOLVVTIj46
PC9zcGFuPjwvc3Bhbj48L2I+PHNwYW4gbGFuZz0iRU4tVVMiIHN0eWxlPSJmb250LXNpemU6MTAu
MHB0O2ZvbnQtZmFtaWx5OuWui+S9kztjb2xvcjp3aW5kb3d0ZXh0Ij4gQWNlIFttYWlsdG86YWNl
LWJvdW5jZXNAaWV0Zi5vcmddDQo8L3NwYW4+PGI+PHNwYW4gc3R5bGU9ImZvbnQtc2l6ZToxMC4w
cHQ7Zm9udC1mYW1pbHk65a6L5L2TO2NvbG9yOndpbmRvd3RleHQiPuS7o+ihqCA8L3NwYW4+DQo8
L2I+PHNwYW4gbGFuZz0iRU4tVVMiIHN0eWxlPSJmb250LXNpemU6MTAuMHB0O2ZvbnQtZmFtaWx5
OuWui+S9kztjb2xvcjp3aW5kb3d0ZXh0Ij5Db3Jpbm5hIFNjaG1pdHQ8YnI+DQo8L3NwYW4+PGI+
PHNwYW4gc3R5bGU9ImZvbnQtc2l6ZToxMC4wcHQ7Zm9udC1mYW1pbHk65a6L5L2TO2NvbG9yOndp
bmRvd3RleHQiPuWPkemAgeaXtumXtDxzcGFuIGxhbmc9IkVOLVVTIj46PC9zcGFuPjwvc3Bhbj48
L2I+PHNwYW4gbGFuZz0iRU4tVVMiIHN0eWxlPSJmb250LXNpemU6MTAuMHB0O2ZvbnQtZmFtaWx5
OuWui+S9kztjb2xvcjp3aW5kb3d0ZXh0Ij4gMjAxNDwvc3Bhbj48c3BhbiBzdHlsZT0iZm9udC1z
aXplOjEwLjBwdDtmb250LWZhbWlseTrlrovkvZM7Y29sb3I6d2luZG93dGV4dCI+5bm0PHNwYW4g
bGFuZz0iRU4tVVMiPjY8L3NwYW4+5pyIPHNwYW4gbGFuZz0iRU4tVVMiPjMwPC9zcGFuPuaXpTxz
cGFuIGxhbmc9IkVOLVVTIj4NCiAxNjozMjxicj4NCjwvc3Bhbj48Yj7mlLbku7bkuro8c3BhbiBs
YW5nPSJFTi1VUyI+Ojwvc3Bhbj48L2I+PHNwYW4gbGFuZz0iRU4tVVMiPiBhY2VAaWV0Zi5vcmc7
IEhhbm5lcyBUc2Nob2ZlbmlnPGJyPg0KPC9zcGFuPjxiPuaKhOmAgTxzcGFuIGxhbmc9IkVOLVVT
Ij46PC9zcGFuPjwvYj48c3BhbiBsYW5nPSJFTi1VUyI+IEJ1cmtoYXJkIFN0aWxsZXI8YnI+DQo8
L3NwYW4+PGI+5Li76aKYPHNwYW4gbGFuZz0iRU4tVVMiPjo8L3NwYW4+PC9iPjxzcGFuIGxhbmc9
IkVOLVVTIj4gUmU6IFtBY2VdIGRyYWZ0LXNjaG1pdHQtdHdvLXdheS1hdXRoZW50aWNhdGlvbi1m
b3ItaW90LTAyPG86cD48L286cD48L3NwYW4+PC9zcGFuPjwvcD4NCjwvZGl2Pg0KPC9kaXY+DQo8
cCBjbGFzcz0iTXNvTm9ybWFsIj48c3BhbiBsYW5nPSJFTi1VUyI+PG86cD4mbmJzcDs8L286cD48
L3NwYW4+PC9wPg0KPGRpdj4NCjxwIGNsYXNzPSJNc29Ob3JtYWwiPjxzcGFuIGxhbmc9IkVOLVVT
Ij5EZWFyIEhhbm5lcyw8YnI+DQo8YnI+DQpiYXNlZCBvbiB0aGUgZGlzY3Vzc2lvbnMgb2YgdGhl
IHByZS1tZWV0aW5nIGluIFN0b2NraG9sbSB3ZSB1cGRhdGVkIG91ciBkcmFmdCBhbmQgZ2VuZXJh
bGl6ZWQgaXQuIE91ciBvbGQgZHJhZnQgJnF1b3Q7ZHJhZnQtc2NobWl0dC10d28td2F5LWF1dGhl
bnRpY2F0aW9uLWZvci1pb3QmcXVvdDsgaXMgbm93IHJlcGxhY2VkIGJ5ICZxdW90O2RyYWZ0LXNj
aG1pdHQtYWNlLXR3b3dheWF1dGgtZm9yLWlvdCZxdW90Oy48YnI+DQo8YnI+DQpUaGUgbWVudGlv
bmVkIHByb2plY3RzIGFyZSBvbmx5IGV4YW1wbGVzIHdoZXJlIHdlIGhhdmUgdGhlIHdvcmsgaW50
ZWdyYXRlZCBhbmQgd2hlcmUgaXQgcnVucyBhbHJlYWR5IHN1Y2Nlc3NmdWwuDQo8YnI+DQpTbyB3
ZSBiZWxpZXZlIHRoZSBkcmFmdCBmaXRzIGludG8gQUNFIGFuZCBhbHNvIG1hcHMgdGhlIHJlcXVp
cmVtZW50cyBvdXRsaW5lZCBpbiA8YSBocmVmPSJodHRwczovL3Rvb2xzLmlldGYub3JnL2h0bWwv
ZHJhZnQtc2VpdHotYWNlLXVzZWNhc2VzLTAwIj4NCmh0dHBzOi8vdG9vbHMuaWV0Zi5vcmcvaHRt
bC9kcmFmdC1zZWl0ei1hY2UtdXNlY2FzZXMtMDA8L2E+Ljxicj4NCjxicj4NClNlZSB5b3UgaW4g
VG9yb250byBhdCBJRVRGIDkwLDxicj4NCkNvcmlubmE8YnI+DQo8YnI+DQpBbSAxMS4wMy4xNCAy
MDoxOCwgc2NocmllYiBIYW5uZXMgVHNjaG9mZW5pZzo8bzpwPjwvbzpwPjwvc3Bhbj48L3A+DQo8
L2Rpdj4NCjxibG9ja3F1b3RlIHN0eWxlPSJtYXJnaW4tdG9wOjUuMHB0O21hcmdpbi1ib3R0b206
NS4wcHQiPg0KPHByZT48c3BhbiBsYW5nPSJFTi1VUyI+SGkgQ29yaW5uYSw8bzpwPjwvbzpwPjwv
c3Bhbj48L3ByZT4NCjxwcmU+PHNwYW4gbGFuZz0iRU4tVVMiPjxvOnA+Jm5ic3A7PC9vOnA+PC9z
cGFuPjwvcHJlPg0KPHByZT48c3BhbiBsYW5nPSJFTi1VUyI+dGhhbmtzIGZvciB0aGUgcmVzcG9u
c2UuPG86cD48L286cD48L3NwYW4+PC9wcmU+DQo8cHJlPjxzcGFuIGxhbmc9IkVOLVVTIj48bzpw
PiZuYnNwOzwvbzpwPjwvc3Bhbj48L3ByZT4NCjxwcmU+PHNwYW4gbGFuZz0iRU4tVVMiPk15IHN1
Z2dlc3Rpb24gd291bGQgYmUgdG8gcHJvZHVjZSBhIHdyaXRlLXVwIHRoYXQgaXMgb2YgZ2VuZXJp
YyB1c2U8bzpwPjwvbzpwPjwvc3Bhbj48L3ByZT4NCjxwcmU+PHNwYW4gbGFuZz0iRU4tVVMiPihp
bmRlcGVuZGVudCBmcm9tIHlvdXIgc3BlY2lmaWMgaW1wbGVtZW50YXRpb24gYW5kIHlvdXIgRVUg
ZnVuZGVkIHByb2plY3QpLjxvOnA+PC9vOnA+PC9zcGFuPjwvcHJlPg0KPHByZT48c3BhbiBsYW5n
PSJFTi1VUyI+PG86cD4mbmJzcDs8L286cD48L3NwYW4+PC9wcmU+DQo8cHJlPjxzcGFuIGxhbmc9
IkVOLVVTIj5Ib3dldmVyLCBnaXZlbiB0aGUgY2hhcnRlciBkaXNjdXNzaW9ucyBhbmQgdGhlIEJP
RiBJIGhhdmUgbXkgZG91YnRzPG86cD48L286cD48L3NwYW4+PC9wcmU+DQo8cHJlPjxzcGFuIGxh
bmc9IkVOLVVTIj53aGV0aGVyIHRoZSB3b3JrIHdvdWxkIG1lZXQgbWFueSBvZiB0aGUgcmVxdWly
ZW1lbnRzIG91dGxpbmVkIGluPG86cD48L286cD48L3NwYW4+PC9wcmU+DQo8cHJlPjxzcGFuIGxh
bmc9IkVOLVVTIj48YSBocmVmPSJodHRwczovL3Rvb2xzLmlldGYub3JnL2h0bWwvZHJhZnQtc2Vp
dHotYWNlLXVzZWNhc2VzLTAwIj5odHRwczovL3Rvb2xzLmlldGYub3JnL2h0bWwvZHJhZnQtc2Vp
dHotYWNlLXVzZWNhc2VzLTAwPC9hPi48bzpwPjwvbzpwPjwvc3Bhbj48L3ByZT4NCjxwcmU+PHNw
YW4gbGFuZz0iRU4tVVMiPjxvOnA+Jm5ic3A7PC9vOnA+PC9zcGFuPjwvcHJlPg0KPHByZT48c3Bh
biBsYW5nPSJFTi1VUyI+Q2lhbzxvOnA+PC9vOnA+PC9zcGFuPjwvcHJlPg0KPHByZT48c3BhbiBs
YW5nPSJFTi1VUyI+SGFubmVzPG86cD48L286cD48L3NwYW4+PC9wcmU+DQo8cHJlPjxzcGFuIGxh
bmc9IkVOLVVTIj48bzpwPiZuYnNwOzwvbzpwPjwvc3Bhbj48L3ByZT4NCjxwcmU+PHNwYW4gbGFu
Zz0iRU4tVVMiPk9uIDAzLzAyLzIwMTQgMDQ6MjkgUE0sIERyLiBDb3Jpbm5hIFNjaG1pdHQgd3Jv
dGU6PG86cD48L286cD48L3NwYW4+PC9wcmU+DQo8YmxvY2txdW90ZSBzdHlsZT0ibWFyZ2luLXRv
cDo1LjBwdDttYXJnaW4tYm90dG9tOjUuMHB0Ij4NCjxwcmU+PHNwYW4gbGFuZz0iRU4tVVMiPkRl
YXIgSGFubmVzLDxvOnA+PC9vOnA+PC9zcGFuPjwvcHJlPg0KPGJsb2NrcXVvdGUgc3R5bGU9Im1h
cmdpbi10b3A6NS4wcHQ7bWFyZ2luLWJvdHRvbTo1LjBwdCI+DQo8cHJlPjxzcGFuIGxhbmc9IkVO
LVVTIj5IaSBDb3Jpbm5hLCBIaSBCdXJraGFyZCw8bzpwPjwvbzpwPjwvc3Bhbj48L3ByZT4NCjxw
cmU+PHNwYW4gbGFuZz0iRU4tVVMiPjxvOnA+Jm5ic3A7PC9vOnA+PC9zcGFuPjwvcHJlPg0KPHBy
ZT48c3BhbiBsYW5nPSJFTi1VUyI+dGhhbmtzIGZvciB5b3VyIGRvY3VtZW50LiBJIGhhdmUgcmVh
ZCB0aHJvdWdoIGl0IGFuZCBJIHJhbiBpbnRvIGEgZmV3PG86cD48L286cD48L3NwYW4+PC9wcmU+
DQo8cHJlPjxzcGFuIGxhbmc9IkVOLVVTIj5xdWVzdGlvbnMuIFlvdXIgcmVzcG9uc2Ugd291bGQg
aGVscCBtZSB0byBiZXR0ZXIgdW5kZXJzdGFuZCB0aGUgcHJvcG9zZWQ8bzpwPjwvbzpwPjwvc3Bh
bj48L3ByZT4NCjxwcmU+PHNwYW4gbGFuZz0iRU4tVVMiPmlkZWEuPG86cD48L286cD48L3NwYW4+
PC9wcmU+DQo8L2Jsb2NrcXVvdGU+DQo8cHJlPjxzcGFuIGxhbmc9IkVOLVVTIj5UaGFua3MgZm9y
IHJlYWRpbmcgdGhlIGRyYWZ0IGFuZCBtYWtlIGNvbW1lbnRzIHRvIGl0IHRvIGltcHJvdmUgaXQu
IFNvbWU8bzpwPjwvbzpwPjwvc3Bhbj48L3ByZT4NCjxwcmU+PHNwYW4gbGFuZz0iRU4tVVMiPmNv
bW1lbnRzIGNhbiBiZSBhbnN3ZXJlZCByaWdodCBhd2F5LjxvOnA+PC9vOnA+PC9zcGFuPjwvcHJl
Pg0KPGJsb2NrcXVvdGUgc3R5bGU9Im1hcmdpbi10b3A6NS4wcHQ7bWFyZ2luLWJvdHRvbTo1LjBw
dCI+DQo8cHJlPjxzcGFuIGxhbmc9IkVOLVVTIj4xKSBXaHkgZG8geW91IGFzc3VtZSBJRUVFIDgw
Mi4xNS40PyBDdXJyZW50bHkgaXQgc2VlbXMgdGhhdCB0aGUgMTUuNDxvOnA+PC9vOnA+PC9zcGFu
PjwvcHJlPg0KPHByZT48c3BhbiBsYW5nPSJFTi1VUyI+cmFkaW8gd2lsbCBtb3N0bHkgYmUgdXNl
ZCBpbiBzcGVjaWFsaXplZCBpbmR1c3RyeSBzZWdtZW50cyBvbmx5LiBJczxvOnA+PC9vOnA+PC9z
cGFuPjwvcHJlPg0KPHByZT48c3BhbiBsYW5nPSJFTi1VUyI+dGhlcmUgYW55dGhpbmcgaW4gdGhl
IGRvY3VtZW50IHRoYXQgd291bGQgbWFrZSB0aGUgaWRlYSBsZXNzIHN1aXRhYmxlPG86cD48L286
cD48L3NwYW4+PC9wcmU+DQo8cHJlPjxzcGFuIGxhbmc9IkVOLVVTIj5mb3Igb3RoZXIgcmFkaW8g
dGVjaG5vbG9naWVzLCBmb3IgZXhhbXBsZSBCVExFPzxvOnA+PC9vOnA+PC9zcGFuPjwvcHJlPg0K
PC9ibG9ja3F1b3RlPg0KPHByZT48c3BhbiBsYW5nPSJFTi1VUyI+UG90ZW50aWFsbHkgdGhlIHBy
b3Bvc2VkIHNvbHV0aW9uIGNhbiB3b3JrIG9uIGV2ZXJ5IHN0YWNrIHlvdSBsaWtlLiBTbzxvOnA+
PC9vOnA+PC9zcGFuPjwvcHJlPg0KPHByZT48c3BhbiBsYW5nPSJFTi1VUyI+eW91IGNhbiBkbyBh
biBpbXBsZW1lbnRhdGlvbiBpbmRlcGVuZGVudGx5IG9mIElFRUUgODAyLjE1LjQuPG86cD48L286
cD48L3NwYW4+PC9wcmU+DQo8cHJlPjxzcGFuIGxhbmc9IkVOLVVTIj5XZSBwdXQgSUVFRSA4MDIu
MTUuNCB0aGVyZSwgYmVjYXVzZSBvdXIgdXNlZCBzdGFjayAoQkxJUCkgdXNlcyBpdC48bzpwPjwv
bzpwPjwvc3Bhbj48L3ByZT4NCjxibG9ja3F1b3RlIHN0eWxlPSJtYXJnaW4tdG9wOjUuMHB0O21h
cmdpbi1ib3R0b206NS4wcHQiPg0KPHByZT48c3BhbiBsYW5nPSJFTi1VUyI+MikgVGhlIGFzc3Vt
ZWQgbmV0d29yayBzdGFjayBkb2VzIG5vdCBzaG93IDZsb3dwYW4uIFdhcyB0aGlzIGludGVudGlv
bmFsPzxvOnA+PC9vOnA+PC9zcGFuPjwvcHJlPg0KPC9ibG9ja3F1b3RlPg0KPHByZT48c3BhbiBs
YW5nPSJFTi1VUyI+U2FtZSBhcyBhYm92ZS4gWW91IGNhbiB1c2UgdGhlIHN0YWNrIHlvdSB3YW50
LiBTbyBhbHNvIDZsb3dwYW4gY2FuIGJlPG86cD48L286cD48L3NwYW4+PC9wcmU+DQo8cHJlPjxz
cGFuIGxhbmc9IkVOLVVTIj51c2VkLiBJdCBkZXBlbmRzIG4geW91IHdoYXQgeW91IHJlcXVpcmUg
YW5kIHdoYXQgeW91IHdhbnQgdG8gc3VwcG9ydC48bzpwPjwvbzpwPjwvc3Bhbj48L3ByZT4NCjxi
bG9ja3F1b3RlIHN0eWxlPSJtYXJnaW4tdG9wOjUuMHB0O21hcmdpbi1ib3R0b206NS4wcHQiPg0K
PHByZT48c3BhbiBsYW5nPSJFTi1VUyI+MykgWW91IHNob3cgUlBMIGluIHRoZSBzdGFjayBhbmQg
SSB3YXMgd29uZGVyaW5nIHdoZXRoZXIgeW91IGFzc3VtZSBpdDxvOnA+PC9vOnA+PC9zcGFuPjwv
cHJlPg0KPHByZT48c3BhbiBsYW5nPSJFTi1VUyI+YmVpbmcgbWFuZGF0b3J5IHRvIGltcGxlbWVu
dCBmb3IgeW91ciBhc3N1bWVkIGFyY2hpdGVjdHVyZT8gSXQgZG9lcyBub3Q8bzpwPjwvbzpwPjwv
c3Bhbj48L3ByZT4NCjxwcmU+PHNwYW4gbGFuZz0iRU4tVVMiPnNlZW0gdG8gc2hvdyB1cCBlbHNl
d2hlcmUgaW4gdGhlIGRvY3VtZW50LiBJdCBhcHBlYXJzIHRvIGJlIGlycmVsZXZhbnQ8bzpwPjwv
bzpwPjwvc3Bhbj48L3ByZT4NCjxwcmU+PHNwYW4gbGFuZz0iRU4tVVMiPmZvciB5b3VyIGRlc2ln
bi48bzpwPjwvbzpwPjwvc3Bhbj48L3ByZT4NCjwvYmxvY2txdW90ZT4NCjxwcmU+PHNwYW4gbGFu
Zz0iRU4tVVMiPlJQTCB3YXMganVzdCBtZW50aW9uZWQgZHVlIHRvIG91ciBvdGhlciBwdWJsaWNh
dGlvbnMuIEN1cnJlbnRseSBvdXIgcGxhbjxvOnA+PC9vOnA+PC9zcGFuPjwvcHJlPg0KPHByZT48
c3BhbiBsYW5nPSJFTi1VUyI+aXMgdG8gY2hhbmdlIHRvIFJQTCAoQ29BUCkgaW4gdGhlIGZ1dHVy
ZS48bzpwPjwvbzpwPjwvc3Bhbj48L3ByZT4NCjxibG9ja3F1b3RlIHN0eWxlPSJtYXJnaW4tdG9w
OjUuMHB0O21hcmdpbi1ib3R0b206NS4wcHQiPg0KPHByZT48c3BhbiBsYW5nPSJFTi1VUyI+NCkg
U3Vic2NyaWJlciBpZGVudGl0eTogWW91IHdyaXRlIC0tPG86cD48L286cD48L3NwYW4+PC9wcmU+
DQo8cHJlPjxzcGFuIGxhbmc9IkVOLVVTIj4mcXVvdDs8bzpwPjwvbzpwPjwvc3Bhbj48L3ByZT4N
CjxwcmU+PHNwYW4gbGFuZz0iRU4tVVMiPiZuYnNwOyZuYnNwOyBUaGUgaWRlbnRpdHkgb2YgYSBk
ZWZhdWx0IHN1YnNjcmliZXIgaXMgdXN1YWxseSBwcmVjb25maWd1cmVkIG9uIGE8bzpwPjwvbzpw
Pjwvc3Bhbj48L3ByZT4NCjxwcmU+PHNwYW4gbGFuZz0iRU4tVVMiPiZuYnNwOyZuYnNwOyBwdWJs
aXNoZXIgYmVmb3JlIGl0IGlzIGRlcGxveWVkLjxvOnA+PC9vOnA+PC9zcGFuPjwvcHJlPg0KPHBy
ZT48c3BhbiBsYW5nPSJFTi1VUyI+JnF1b3Q7PG86cD48L286cD48L3NwYW4+PC9wcmU+DQo8cHJl
PjxzcGFuIGxhbmc9IkVOLVVTIj48bzpwPiZuYnNwOzwvbzpwPjwvc3Bhbj48L3ByZT4NCjxwcmU+
PHNwYW4gbGFuZz0iRU4tVVMiPkNvdWxkIHlvdSBleHBsYWluIG1vcmUgd2hhdCB5b3UgYXNzdW1l
IGlzIHByZS1jb25maWd1cmVkIGFuZCB3aGVyZSBpdCBpczxvOnA+PC9vOnA+PC9zcGFuPjwvcHJl
Pg0KPHByZT48c3BhbiBsYW5nPSJFTi1VUyI+cHJlY29uZmlndXJlZD88bzpwPjwvbzpwPjwvc3Bh
bj48L3ByZT4NCjwvYmxvY2txdW90ZT4NCjxwcmU+PHNwYW4gbGFuZz0iRU4tVVMiPkhlcmUgcHJl
LWNvbmZpZ3VyZXMgbWVhbnMgdGhhdCBvdXIgZGV2aWNlcyBhcmUgZXF1aXBwZWQgd2l0aCB0aGU8
bzpwPjwvbzpwPjwvc3Bhbj48L3ByZT4NCjxwcmU+PHNwYW4gbGFuZz0iRU4tVVMiPmNlcnRpZmlj
YXRpb24gZHVyaW5nIGNvbXBpbGluZyBhbmQgcHJvZ3JhbW1pbmcgdGhlbSBiZWZvcmUgZGVwbG95
bWVudC48bzpwPjwvbzpwPjwvc3Bhbj48L3ByZT4NCjxwcmU+PHNwYW4gbGFuZz0iRU4tVVMiPlRo
aXMgaXMgZHVlIHRvIHRoZSBhcHBsaWNhdGlvbiBzY2VuYXJpbyB3ZSBzdXBwb3J0IGF0IHRoZSBt
b21lbnQuIEJlZm9yZTxvOnA+PC9vOnA+PC9zcGFuPjwvcHJlPg0KPHByZT48c3BhbiBsYW5nPSJF
Ti1VUyI+ZGVwbG95aW5nIHRoZSBkZXZpY2UgeW91IGhhdmUgdG8gcnVuIHRvIHN0ZXBzOiBGaXJz
dCBjcmVhdGlvbiBvZjxvOnA+PC9vOnA+PC9zcGFuPjwvcHJlPg0KPHByZT48c3BhbiBsYW5nPSJF
Ti1VUyI+Y2VydGlmaWNhdGUsIGFuZCBzZWNvbmQgY29tcGlsaW5nIGNvZGUgYW5kIHBsYXkgaXQg
b24gdGhlIGRldmljZS48bzpwPjwvbzpwPjwvc3Bhbj48L3ByZT4NCjxibG9ja3F1b3RlIHN0eWxl
PSJtYXJnaW4tdG9wOjUuMHB0O21hcmdpbi1ib3R0b206NS4wcHQiPg0KPHByZT48c3BhbiBsYW5n
PSJFTi1VUyI+SSB3b3VsZCBhbHNvIHN1Z2dlc3QgdG8gYXZvaWQgdGhlIHRlcm0gc3Vic2NyaWJl
ciBzaW5jZSBpdCBoYXMgdHdvIG90aGVyPG86cD48L286cD48L3NwYW4+PC9wcmU+DQo8cHJlPjxz
cGFuIGxhbmc9IkVOLVVTIj5tZWFuaW5ncyB0aGF0IG1pZ2h0IGNvbmZ1c2U6PG86cD48L286cD48
L3NwYW4+PC9wcmU+DQo8cHJlPjxzcGFuIGxhbmc9IkVOLVVTIj4gYSkgVGhlIHRlcm0gc3Vic2Ny
aWJlciBpcyBvZnRlbiB1c2VkIGluIGNvbnRleHQgb2YgdGVsZWNvbW11bmljYXRpb24gYXM8bzpw
PjwvbzpwPjwvc3Bhbj48L3ByZT4NCjxwcmU+PHNwYW4gbGFuZz0iRU4tVVMiPnRoZSB1c2VyIHdo
byBoYXMgYSBjb250cmFjdCB3aXRoIGEgdGVsZWNvbW11bmljYXRpb24gb3BlcmF0b3IuPG86cD48
L286cD48L3NwYW4+PC9wcmU+DQo8cHJlPjxzcGFuIGxhbmc9IkVOLVVTIj4gYikgVGhlIHNlY29u
ZCB1c2UgaXMgaW4gY29udGV4dCBvZiBwcm90b2NvbHMgdGhhdCB1c2UgYXN5bmNocm9ub3VzPG86
cD48L286cD48L3NwYW4+PC9wcmU+DQo8cHJlPjxzcGFuIGxhbmc9IkVOLVVTIj5jb21tdW5pY2F0
aW9uIChsaWtlIFhNUFApLjxvOnA+PC9vOnA+PC9zcGFuPjwvcHJlPg0KPHByZT48c3BhbiBsYW5n
PSJFTi1VUyI+PG86cD4mbmJzcDs8L286cD48L3NwYW4+PC9wcmU+DQo8cHJlPjxzcGFuIGxhbmc9
IkVOLVVTIj5JIGJlbGlldmUgeW91ciBub3Rpb24gb2Ygc3Vic2NyaWJlciBkb2VzIG5vdCByZWxh
dGUgdG8gdGhvc2UgdHdvPG86cD48L286cD48L3NwYW4+PC9wcmU+DQo8cHJlPjxzcGFuIGxhbmc9
IkVOLVVTIj5leGlzdGluZyB1c2VzLiBJIGd1ZXNzIHlvdSBhcmUgbW9yZSB1c2luZyB0aGUgdGVy
bSBzdWJzY3JpYmVyIHRvIHJlZmVyPG86cD48L286cD48L3NwYW4+PC9wcmU+DQo8cHJlPjxzcGFu
IGxhbmc9IkVOLVVTIj50byBhIGRldmljZSB0aGF0IHdhbnRzIHNvbWUgZGF0YSBmcm9tIGEgc2Vu
c29yLiBJcyB0aGlzIGNvcnJlY3Q/PG86cD48L286cD48L3NwYW4+PC9wcmU+DQo8L2Jsb2NrcXVv
dGU+DQo8cHJlPjxzcGFuIGxhbmc9IkVOLVVTIj5UaGFua3MgZm9yIHRoZSBoaW50LiBZZXMgeW91
IGFyZSByaWdodC4gVGhlIHN1YnNjcmliZXIgc2hvdWxkIGJlIGE8bzpwPjwvbzpwPjwvc3Bhbj48
L3ByZT4NCjxwcmU+PHNwYW4gbGFuZz0iRU4tVVMiPmRldmljZSB0aGF0IHdhbnRzIGRhdGEgZnJv
bSB0aGUgc2Vuc29yLjxvOnA+PC9vOnA+PC9zcGFuPjwvcHJlPg0KPHByZT48c3BhbiBsYW5nPSJF
Ti1VUyI+VXN1YWxseSB0aGlzIGlzIG9uZSBvdXRzaWRlIG9mIHRoZSBXU04uIERvIHlvdSBoYXZl
IGEgc3VnZ2VzdGlvbiBmb3IgbmV3PG86cD48L286cD48L3NwYW4+PC9wcmU+DQo8cHJlPjxzcGFu
IGxhbmc9IkVOLVVTIj5uYW1lPzxvOnA+PC9vOnA+PC9zcGFuPjwvcHJlPg0KPGJsb2NrcXVvdGUg
c3R5bGU9Im1hcmdpbi10b3A6NS4wcHQ7bWFyZ2luLWJvdHRvbTo1LjBwdCI+DQo8cHJlPjxzcGFu
IGxhbmc9IkVOLVVTIj41KSBSb2xlcyBpbiB5b3VyIGFyY2hpdGVjdHVyZS48bzpwPjwvbzpwPjwv
c3Bhbj48L3ByZT4NCjxwcmU+PHNwYW4gbGFuZz0iRU4tVVMiPjxvOnA+Jm5ic3A7PC9vOnA+PC9z
cGFuPjwvcHJlPg0KPHByZT48c3BhbiBsYW5nPSJFTi1VUyI+SXQgc2VlbXMgdGhhdCB5b3UgYXNz
dW1lIHRoYXQgdGhlIElvVCBkZXZpY2VzIGFyZSBwdWJsaXNoZXJzIGFuZCB0aGF0PG86cD48L286
cD48L3NwYW4+PC9wcmU+DQo8cHJlPjxzcGFuIGxhbmc9IkVOLVVTIj50aGVyZSBhcmUgc3Vic2Ny
aWJlcnMgd2hvIHRhbGsgdG8gdGhlc2UgcHVibGlzaGVycy4gSW4gc29tZSBvdGhlciBjYXNlczxv
OnA+PC9vOnA+PC9zcGFuPjwvcHJlPg0KPHByZT48c3BhbiBsYW5nPSJFTi1VUyI+SSBoYXZlIHNl
ZW4gYXJjaGl0ZWN0dXJlcyB3aGVyZSB0aGUgSW9UIGRldmljZXMgKHNlbnNvcnMpIHVwbG9hZCB0
aGU8bzpwPjwvbzpwPjwvc3Bhbj48L3ByZT4NCjxwcmU+PHNwYW4gbGFuZz0iRU4tVVMiPmRhdGEg
dG8gc29tZSBzZXJ2ZXJzIHdpdGhvdXQgaGF2aW5nIHRvIGFjdCBhcyBzZXJ2ZXJzIHRoZW1zZWx2
ZXMuIEluPG86cD48L286cD48L3NwYW4+PC9wcmU+DQo8cHJlPjxzcGFuIGxhbmc9IkVOLVVTIj55
b3VyIGFyY2hpdGVjdHVyZSBpdCBmZWVscyBsaWtlIHRoZSBzZW5zb3Igbm9kZXMgaW1wbGVtZW50
IHRoZTxvOnA+PC9vOnA+PC9zcGFuPjwvcHJlPg0KPHByZT48c3BhbiBsYW5nPSJFTi1VUyI+c2Vy
dmVyLXNpZGUgZnVuY3Rpb25hbGl0eTxvOnA+PC9vOnA+PC9zcGFuPjwvcHJlPg0KPC9ibG9ja3F1
b3RlPg0KPHByZT48c3BhbiBsYW5nPSJFTi1VUyI+VGhhdCB3YXMgbm90IG91ciBpbnRlbnRpb24u
PG86cD48L286cD48L3NwYW4+PC9wcmU+DQo8cHJlPjxzcGFuIGxhbmc9IkVOLVVTIj5PdXIgbmV0
d29yayBoYXMgcHVzaCBjaGFyYWN0ZXJpc3RpY3MgdXAgdG8gdGhlIHNlcnZlci4gRGF0YSBwdWJs
aXNoaW5nPG86cD48L286cD48L3NwYW4+PC9wcmU+DQo8cHJlPjxzcGFuIGxhbmc9IkVOLVVTIj5y
dW5zIG92ZXIgc2VydmVyLCBiZWNhdXNlIGl0IGhhcyBtb3JlIHJlc291cmNlcyBhbmQsIHRoZXJl
Zm9yZSwgY2FuPG86cD48L286cD48L3NwYW4+PC9wcmU+DQo8cHJlPjxzcGFuIGxhbmc9IkVOLVVT
Ij5oYW5kbGUgcmVxdWVzdHMgYmV0dGVyLiBJdCBpcyB0aGUgZ2F0ZSB0byB0aGUgd29ybGQuPG86
cD48L286cD48L3NwYW4+PC9wcmU+DQo8cHJlPjxzcGFuIGxhbmc9IkVOLVVTIj5QdWxsIGlzIG9u
bHkgcGVyZm9ybWVkIGlmIHlvdSByZXF1aXJlIGRhdGEgKG1lYXN1cmVtZW50cykgYXQgYSB0aW1l
IHRoYXQ8bzpwPjwvbzpwPjwvc3Bhbj48L3ByZT4NCjxwcmU+PHNwYW4gbGFuZz0iRU4tVVMiPmlz
IG5vdCBwcmUtZGVmaW5lZC48bzpwPjwvbzpwPjwvc3Bhbj48L3ByZT4NCjxibG9ja3F1b3RlIHN0
eWxlPSJtYXJnaW4tdG9wOjUuMHB0O21hcmdpbi1ib3R0b206NS4wcHQiPg0KPHByZT48c3BhbiBs
YW5nPSJFTi1VUyI+SW4gU2VjdGlvbiA0LjIuMiB5b3Ugd3JpdGUgdGhhdCB5b3UgcmVjb21tZW5k
IGFuIE9wZW5TU0wgaW1wbGVtZW50YXRpb248bzpwPjwvbzpwPjwvc3Bhbj48L3ByZT4NCjxwcmU+
PHNwYW4gbGFuZz0iRU4tVVMiPm9uIHRoZSBzZXJ2ZXIgc2lkZSBidXQgdGhlIHNlcnZlci1zaWRl
IHdvdWxkIGJlIHRoZSBJb1QgZGV2aWNlLiBXaGlsZSBpdDxvOnA+PC9vOnA+PC9zcGFuPjwvcHJl
Pg0KPHByZT48c3BhbiBsYW5nPSJFTi1VUyI+d291bGQgYmUgaW5hcHByb3ByaWF0ZSB0byByZWNv
bW1lbmQgYSBzcGVjaWZpYyBpbXBsZW1lbnRhdGlvbiBpbiBhbiBJRVRGPG86cD48L286cD48L3Nw
YW4+PC9wcmU+DQo8cHJlPjxzcGFuIGxhbmc9IkVOLVVTIj5kcmFmdC9SRkMgaXQgYWxzbyByYWlz
ZXMgdGhlIHF1ZXN0aW9ucyBhYm91dCB0aGUgZXhwZWN0YXRpb25zIG9uIHRoZTxvOnA+PC9vOnA+
PC9zcGFuPjwvcHJlPg0KPHByZT48c3BhbiBsYW5nPSJFTi1VUyI+c2VydmVyLXNpZGUuPG86cD48
L286cD48L3NwYW4+PC9wcmU+DQo8L2Jsb2NrcXVvdGU+DQo8cHJlPjxzcGFuIGxhbmc9IkVOLVVT
Ij5UaGFua3MgZm9yIHRoZSBoaW50LjxvOnA+PC9vOnA+PC9zcGFuPjwvcHJlPg0KPHByZT48c3Bh
biBsYW5nPSJFTi1VUyI+V2UgdXNlIE9wZW5TU0wgb24gdGhlIHNlcnZlciBidXQgbm90IHdpdGhp
biB0aGUgV1NOLiBPcGVuU1NMIGlzIHVzZWQ8bzpwPjwvbzpwPjwvc3Bhbj48L3ByZT4NCjxwcmU+
PHNwYW4gbGFuZz0iRU4tVVMiPmVzcGVjaWFsbHkgZm9yIG1hbmFnaW5nIHJpZ2h0cywgcmVxdWVz
dHMsIGFuZCBjZXJ0aWZpY2F0ZXMuPG86cD48L286cD48L3NwYW4+PC9wcmU+DQo8YmxvY2txdW90
ZSBzdHlsZT0ibWFyZ2luLXRvcDo1LjBwdDttYXJnaW4tYm90dG9tOjUuMHB0Ij4NCjxwcmU+PHNw
YW4gbGFuZz0iRU4tVVMiPjYuIENlcnRpZmljYXRlIGNvbnRlbnQ8bzpwPjwvbzpwPjwvc3Bhbj48
L3ByZT4NCjxwcmU+PHNwYW4gbGFuZz0iRU4tVVMiPjxvOnA+Jm5ic3A7PC9vOnA+PC9zcGFuPjwv
cHJlPg0KPHByZT48c3BhbiBsYW5nPSJFTi1VUyI+SW4gU2VjdGlvbiA0LjIuMiB5b3UgZGVzY3Jp
YmUgdGhlIGNvbnRlbnQgb2YgYSBjZXJ0aWZpY2F0ZSBhbmQgeW91PG86cD48L286cD48L3NwYW4+
PC9wcmU+DQo8cHJlPjxzcGFuIGxhbmc9IkVOLVVTIj5pbmRpY2F0ZSB0aGF0IHRoZSBjb21tb25O
YW1lIGlzIHNldCB0byAmcXVvdDtsb2NhbGhvc3QmcXVvdDsuIEl0IHNlZW1zIHRvIGJlPG86cD48
L286cD48L3NwYW4+PC9wcmU+DQo8cHJlPjxzcGFuIGxhbmc9IkVOLVVTIj51c2VsZXNzIHRvIGlu
Y2x1ZGUgdGhpcyBpbiB0aGUgY2VydGlmaWNhdGUgc2luY2UgYSBDQSB3b3VsZCBub3QgYmUgYWJs
ZTxvOnA+PC9vOnA+PC9zcGFuPjwvcHJlPg0KPHByZT48c3BhbiBsYW5nPSJFTi1VUyI+dG8gdmVy
aWZ5IHRoaXMgaWRlbnRpdHkgaW5mb3JtYXRpb24gbm9yIHdvdWxkIGFueSBwYXJ0eSB2ZXJpZnlp
bmcgaXQgYmU8bzpwPjwvbzpwPjwvc3Bhbj48L3ByZT4NCjxwcmU+PHNwYW4gbGFuZz0iRU4tVVMi
PmFibGUgdG8gdXNlIGl0IGluIGEgbWVhbmluZ2Z1bCB3YXkuPG86cD48L286cD48L3NwYW4+PC9w
cmU+DQo8L2Jsb2NrcXVvdGU+DQo8cHJlPjxzcGFuIGxhbmc9IkVOLVVTIj5Mb2NhbGhvc3QgaW4g
b3VyIGNhc2UgaXMgYSBzcGVjaWFsIElQIGFkZHJlc3MgKGhlcmU6IHNpbmspLiBZb3UgYXJlPG86
cD48L286cD48L3NwYW4+PC9wcmU+DQo8cHJlPjxzcGFuIGxhbmc9IkVOLVVTIj5yaWdodCwgd2Ug
c2hvdWxkIHJlbmFtZSBpdCBhbmQgbWFrZSBjbGVhciB0aGF0IGl0IGlzIGFuIElQIGFkZHJlc3Mu
IFNvPG86cD48L286cD48L3NwYW4+PC9wcmU+DQo8cHJlPjxzcGFuIGxhbmc9IkVOLVVTIj55b3Ug
Y2FuIHNldCBpcyBsaWtlIHlvdSB3YW50LjxvOnA+PC9vOnA+PC9zcGFuPjwvcHJlPg0KPGJsb2Nr
cXVvdGUgc3R5bGU9Im1hcmdpbi10b3A6NS4wcHQ7bWFyZ2luLWJvdHRvbTo1LjBwdCI+DQo8cHJl
PjxzcGFuIGxhbmc9IkVOLVVTIj5JdCBhbHNvIHNlZW1zIHRvIGJlIGluIHZpb2xhdGlvbiBvZiB3
aGF0IHlvdSB3cml0ZSBpbiBTZWN0aW9uIDUuMiB3aGVyZTxvOnA+PC9vOnA+PC9zcGFuPjwvcHJl
Pg0KPHByZT48c3BhbiBsYW5nPSJFTi1VUyI+eW91IHN0YXRlIHRoYXQgJnF1b3Q7ZXZlcnkgcHVi
bGlzaGVyIGluIHRoZSBuZXR3b3JrIE1VU1QgaGF2ZSBhbiB1bmlxdWU8bzpwPjwvbzpwPjwvc3Bh
bj48L3ByZT4NCjxwcmU+PHNwYW4gbGFuZz0iRU4tVVMiPmlkZW50aXR5LiZxdW90Oy48bzpwPjwv
bzpwPjwvc3Bhbj48L3ByZT4NCjxwcmU+PHNwYW4gbGFuZz0iRU4tVVMiPjxvOnA+Jm5ic3A7PC9v
OnA+PC9zcGFuPjwvcHJlPg0KPHByZT48c3BhbiBsYW5nPSJFTi1VUyI+WW91IGFsc28gaW5kaWNh
dGVkIG1vcmUgY29tcGxldGUgaW5mb3JtYXRpb24gZm9yIGluY2x1c2lvbiBpbiB0aGU8bzpwPjwv
bzpwPjwvc3Bhbj48L3ByZT4NCjxwcmU+PHNwYW4gbGFuZz0iRU4tVVMiPmNlcnRpZmljYXRlIGJ1
dCBpdCBpcyBub3QgY2xlYXIgdG8gbWUgd2hhdCBwdXJwb3NlIGl0IHNlcnZlcy4gQ291bGQgeW91
PG86cD48L286cD48L3NwYW4+PC9wcmU+DQo8cHJlPjxzcGFuIGxhbmc9IkVOLVVTIj5leHBsYWlu
PzxvOnA+PC9vOnA+PC9zcGFuPjwvcHJlPg0KPC9ibG9ja3F1b3RlPg0KPHByZT48c3BhbiBsYW5n
PSJFTi1VUyI+V2lsbCBkbyBpdCBhc2FwLjxvOnA+PC9vOnA+PC9zcGFuPjwvcHJlPg0KPGJsb2Nr
cXVvdGUgc3R5bGU9Im1hcmdpbi10b3A6NS4wcHQ7bWFyZ2luLWJvdHRvbTo1LjBwdCI+DQo8cHJl
PjxzcGFuIGxhbmc9IkVOLVVTIj43LiBQcml2YWN5PG86cD48L286cD48L3NwYW4+PC9wcmU+DQo8
cHJlPjxzcGFuIGxhbmc9IkVOLVVTIj48bzpwPiZuYnNwOzwvbzpwPjwvc3Bhbj48L3ByZT4NCjxw
cmU+PHNwYW4gbGFuZz0iRU4tVVMiPkluIFNlY3Rpb24gNSB5b3UgaW5kaWNhdGUgc29tZSBwcml2
YWN5IHJlbGF0ZWQgYXNwZWN0cyBhbmQgeW91IGhpbnQgdG8gJnF1b3Q7PG86cD48L286cD48L3Nw
YW4+PC9wcmU+DQo8cHJlPjxzcGFuIGxhbmc9IkVOLVVTIj5hY2Nlc3MgcmVndWxhdGlvbnMgYmFz
ZWQgb24gbGVnYWwgYW5kIHJlZ3VsYXRpdmUgaW1wbGljYXRpb25zJnF1b3Q7LiBDb3VsZDxvOnA+
PC9vOnA+PC9zcGFuPjwvcHJlPg0KPHByZT48c3BhbiBsYW5nPSJFTi1VUyI+eW91IGJyaWVmbHkg
ZXhwbGFpbiB3aGF0IHRob3NlIHJlcXVpcmVtZW50cyBhcmU/PG86cD48L286cD48L3NwYW4+PC9w
cmU+DQo8L2Jsb2NrcXVvdGU+DQo8cHJlPjxzcGFuIGxhbmc9IkVOLVVTIj5UaGlzIHBhcnQgd2Ug
cHV0IGluIGR1ZSB0byB0aGUgZGVwbG95bWVudCBhbmQgcHJvamVjdCByZWxhdGlvbnMgd2UgYXJl
PG86cD48L286cD48L3NwYW4+PC9wcmU+DQo8cHJlPjxzcGFuIGxhbmc9IkVOLVVTIj5ydW5uaW5n
IGF0IHRoZSBtb21lbnQuPG86cD48L286cD48L3NwYW4+PC9wcmU+DQo8cHJlPjxzcGFuIGxhbmc9
IkVOLVVTIj5IZXJlIGl0IG1lYW5zIHRoYXQgbm90IGV2ZXJ5IGRldmljZSBjYW4gYmUgYWJsZSB0
byBhY2Nlc3MgdGhlIGRhdGEsIGZvcjxvOnA+PC9vOnA+PC9zcGFuPjwvcHJlPg0KPHByZT48c3Bh
biBsYW5nPSJFTi1VUyI+ZXhhbXBsZSwgZHVlIHRvIGxlZ2FsIGlzc3VlcyBpbiB0aGUgcmVnaW9u
IChFVSwgQ0gsIFVTIHJpZ2h0cykuPG86cD48L286cD48L3NwYW4+PC9wcmU+DQo8cHJlPjxzcGFu
IGxhbmc9IkVOLVVTIj5UaGlzIGhhcyB0byBiZSBzdG9yZWQgY2VudHJhbCBpbiB0aGUgbmV0d29y
ayBhbmQgaXQgaGFzIHRvIGJlIGNoZWNrZWQ8bzpwPjwvbzpwPjwvc3Bhbj48L3ByZT4NCjxwcmU+
PHNwYW4gbGFuZz0iRU4tVVMiPmJlZm9yZSBnaXZpbmcgYWNjZXNzIGFuZCBjcmVhdGluZyB0aGUg
Y29ycmVzcG9uZGluZyBhY2Nlc3MgdGlja2V0LjxvOnA+PC9vOnA+PC9zcGFuPjwvcHJlPg0KPHBy
ZT48c3BhbiBsYW5nPSJFTi1VUyI+SGVyZSB3ZSByZWZlciB0byB0aGUgZm9sbG93aW5nIHB1Ymxp
Y2F0aW9uczo8bzpwPjwvbzpwPjwvc3Bhbj48L3ByZT4NCjxwcmU+PHNwYW4gbGFuZz0iRU4tVVMi
PjxvOnA+Jm5ic3A7PC9vOnA+PC9zcGFuPjwvcHJlPg0KPHByZT48c3BhbiBsYW5nPSJFTi1VUyI+
UmFkaGlrYSBHYXJnLCBDb3Jpbm5hIFNjaG1pdHQsIEJ1cmtoYXJkIFN0aWxsZXI6IC9JbnZlc3Rp
Z2F0aW5nPG86cD48L286cD48L3NwYW4+PC9wcmU+DQo8cHJlPjxzcGFuIGxhbmc9IkVOLVVTIj5S
ZWd1bGF0aXZlIEltcGxpY2F0aW9ucyBmb3IgVXNlci1nZW5lcmF0ZWQgQ29udGVudCBhbmQgYSBE
ZXNpZ248bzpwPjwvbzpwPjwvc3Bhbj48L3ByZT4NCjxwcmU+PHNwYW4gbGFuZz0iRU4tVVMiPlBy
b3Bvc2FsLzsgRGVncnV5dGVyLCBQSUstUHJheGlzIGRlciBJbmZvcm1hdGlvbnN2ZXJhcmJlaXR1
bmcgdW5kPG86cD48L286cD48L3NwYW4+PC9wcmU+DQo8cHJlPjxzcGFuIGxhbmc9IkVOLVVTIj5L
b21tdW5pa2F0aW9uLCBWb2wuIDM2LCBOby4gNCwgRGVjZW1iZXIgMjAxMywgSVNTTiAwOTMwLTUx
NTcsIHBwIDHigJMxMS48bzpwPjwvbzpwPjwvc3Bhbj48L3ByZT4NCjxwcmU+PHNwYW4gbGFuZz0i
RU4tVVMiPmRvaToxMC4xNTE1L3Bpay0yMDEzLTAwNDIgPGEgaHJlZj0iaHR0cDovL2R4LmRvaS5v
cmcvMTAuMTUxNS9waWstMjAxMy0wMDQyIj4mbHQ7aHR0cDovL2R4LmRvaS5vcmcvMTAuMTUxNS9w
aWstMjAxMy0wMDQyJmd0OzwvYT4gVVJMOjxvOnA+PC9vOnA+PC9zcGFuPjwvcHJlPg0KPHByZT48
c3BhbiBsYW5nPSJFTi1VUyI+PGEgaHJlZj0iaHR0cDovL3d3dy5kZWdydXl0ZXIuY29tL3ZpZXcv
ai9waWtvLmFoZWFkLW9mLXByaW50L3Bpay0yMDEzLTAwNDIvcGlrLTIwMTMtMDA0Mi54bWwiPmh0
dHA6Ly93d3cuZGVncnV5dGVyLmNvbS92aWV3L2ovcGlrby5haGVhZC1vZi1wcmludC9waWstMjAx
My0wMDQyL3Bpay0yMDEzLTAwNDIueG1sPC9hPjxvOnA+PC9vOnA+PC9zcGFuPjwvcHJlPg0KPHBy
ZT48c3BhbiBsYW5nPSJFTi1VUyI+PG86cD4mbmJzcDs8L286cD48L3NwYW4+PC9wcmU+DQo8cHJl
PjxzcGFuIGxhbmc9IkVOLVVTIj5SYWRoaWthIEdhcmcsIENocmlzdG9zIFRzaWFyYXMsIEJ1cmto
YXJkIFN0aWxsZXIsIENvcmlubmEgU2NobWl0dCw8bzpwPjwvbzpwPjwvc3Bhbj48L3ByZT4NCjxw
cmU+PHNwYW4gbGFuZz0iRU4tVVMiPkRhbmllbCBEw7Zubmk6IC9EZWxpdmVyYWJsZSBENy4xIC0g
QmFzaWNzLCBSZXF1aXJlbWVudHMsIFNjZW5hcmlvcywgYW5kPG86cD48L286cD48L3NwYW4+PC9w
cmU+DQo8cHJlPjxzcGFuIGxhbmc9IkVOLVVTIj5BcmNoaXRlY3R1cmU6IEluIEZMQU1JTkdPLzsg
UmFkaGlrYSBHYXJnIChFZHQuKSwgWsO8cmljaCwgU3dpdHplcmxhbmQsPG86cD48L286cD48L3Nw
YW4+PC9wcmU+DQo8cHJlPjxzcGFuIGxhbmc9IkVOLVVTIj5PY3RvYmVyIDIwMTM8bzpwPjwvbzpw
Pjwvc3Bhbj48L3ByZT4NCjxibG9ja3F1b3RlIHN0eWxlPSJtYXJnaW4tdG9wOjUuMHB0O21hcmdp
bi1ib3R0b206NS4wcHQiPg0KPHByZT48c3BhbiBsYW5nPSJFTi1VUyI+OC4gVXNlIENhc2VzLjxv
OnA+PC9vOnA+PC9zcGFuPjwvcHJlPg0KPHByZT48c3BhbiBsYW5nPSJFTi1VUyI+PG86cD4mbmJz
cDs8L286cD48L3NwYW4+PC9wcmU+DQo8cHJlPjxzcGFuIGxhbmc9IkVOLVVTIj5JIHN1Z2dlc3Qg
dG8gb21pdCB0aGUgdXNlIGNhc2VzIGZyb20gdGhlIGRvY3VtZW50IHNpbmNlIHRoZSBkZXNjcmlw
dGlvbjxvOnA+PC9vOnA+PC9zcGFuPjwvcHJlPg0KPHByZT48c3BhbiBsYW5nPSJFTi1VUyI+aXMg
dG9vIGJyaWVmIHRvIGJlIHVzZWZ1bC4gQSBzbWFsbCByZW1hcms6IEZyb20gbXkgd29yayBpbiB0
aGUgZW1lcmdlbmN5PG86cD48L286cD48L3NwYW4+PC9wcmU+DQo8cHJlPjxzcGFuIGxhbmc9IkVO
LVVTIj5zZXJ2aWNlcyBlbnZpcm9ubWVudCBJIGhhZCBnb3R0ZW4gdGhlIGltcHJlc3Npb24gdGhh
dCB0aGVyZSBhcmUgbm8gcGxhbnM8bzpwPjwvbzpwPjwvc3Bhbj48L3ByZT4NCjxwcmU+PHNwYW4g
bGFuZz0iRU4tVVMiPnRvIHRha2Ugc2Vuc29yIGlucHV0IGRpcmVjdGx5IHdoZW4gaW5pdGlhdGlu
ZyBhbGVydHMuIEluIGZhY3QsIHNlbnNvcjxvOnA+PC9vOnA+PC9zcGFuPjwvcHJlPg0KPHByZT48
c3BhbiBsYW5nPSJFTi1VUyI+YWxlcnRzIGRvIHJhcmVseSBldmVuIGdldCBkaXJlY3RseSB0byB0
aGUgZW1lcmdlbmN5IHNlcnZpY2VzIGF1dGhvcml0aWVzPG86cD48L286cD48L3NwYW4+PC9wcmU+
DQo8cHJlPjxzcGFuIGxhbmc9IkVOLVVTIj5idXQgYXJlIHJhdGhlciBwcmUtcHJvY2Vzc2VkIGJ5
IGFuIGludGVybWVkaWF0ZSBvcmdhbml6YXRpb24gKGJ5PG86cD48L286cD48L3NwYW4+PC9wcmU+
DQo8cHJlPjxzcGFuIGxhbmc9IkVOLVVTIj5odW1hbnMpLiBNYXliZSB5b3UgaGF2ZSBzcG9rZW4g
d2l0aCBvdGhlciBwZW9wbGUsIHdobyBoYXZlIGRpZmZlcmVudDxvOnA+PC9vOnA+PC9zcGFuPjwv
cHJlPg0KPHByZT48c3BhbiBsYW5nPSJFTi1VUyI+cGxhbnMuIFdoZXJlIGRpZCB5b3UgZ290IHlv
dXIgaW5mb3JtYXRpb24gZnJvbT88bzpwPjwvbzpwPjwvc3Bhbj48L3ByZT4NCjwvYmxvY2txdW90
ZT4NCjxwcmU+PHNwYW4gbGFuZz0iRU4tVVMiPlRoaXMgc2VjdGlvbiBpcyBiYXNlZCBvbiBkaXNj
dXNzaW9uIHdpdGggb3VyIHByb2plY3QgcGFydG5lcnMgd2l0aGluPG86cD48L286cD48L3NwYW4+
PC9wcmU+DQo8cHJlPjxzcGFuIGxhbmc9IkVOLVVTIj5TbWFydGVuSVQgKDxhIGhyZWY9Imh0dHA6
Ly93d3cuc21hcnRlbml0LmV1Ij53d3cuc21hcnRlbml0LmV1PC9hPikgYW5kIEZsYW1pbmdvICgg
PGEgaHJlZj0iaHR0cDovL3d3dy5mcDctZmxhbWluZ28uZXUiPmh0dHA6Ly93d3cuZnA3LWZsYW1p
bmdvLmV1PC9hPikuPG86cD48L286cD48L3NwYW4+PC9wcmU+DQo8cHJlPjxzcGFuIGxhbmc9IkVO
LVVTIj48YSBocmVmPSJodHRwOi8vd3d3LmZwNy1mbGFtaW5nby5ldSI+Jmx0O2h0dHA6Ly93d3cu
ZnA3LWZsYW1pbmdvLmV1Jmd0OzwvYT48bzpwPjwvbzpwPjwvc3Bhbj48L3ByZT4NCjxwcmU+PHNw
YW4gbGFuZz0iRU4tVVMiPjxvOnA+Jm5ic3A7PC9vOnA+PC9zcGFuPjwvcHJlPg0KPGJsb2NrcXVv
dGUgc3R5bGU9Im1hcmdpbi10b3A6NS4wcHQ7bWFyZ2luLWJvdHRvbTo1LjBwdCI+DQo8cHJlPjxz
cGFuIGxhbmc9IkVOLVVTIj45LiBBcmNoaXRlY3R1cmU8bzpwPjwvbzpwPjwvc3Bhbj48L3ByZT4N
CjxwcmU+PHNwYW4gbGFuZz0iRU4tVVMiPjxvOnA+Jm5ic3A7PC9vOnA+PC9zcGFuPjwvcHJlPg0K
PHByZT48c3BhbiBsYW5nPSJFTi1VUyI+RmlndXJlIDMgc2hvd3MgdGhlIGFyY2hpdGVjdHVyZSBi
dXQgaXQgaXMgYSBiaXQgY29uZnVzaW5nIHNpbmNlIGl0IGlzPG86cD48L286cD48L3NwYW4+PC9w
cmU+DQo8cHJlPjxzcGFuIGxhbmc9IkVOLVVTIj5ub3QgY2xlYXIgd2hhdCB0aGUgYm94ZXMgYW5k
IHRoZSBsaW5lcyBtZWFuLiBUaGUgcHVibGlzaGVyIGlzIGEgYm94PG86cD48L286cD48L3NwYW4+
PC9wcmU+DQo8cHJlPjxzcGFuIGxhbmc9IkVOLVVTIj5zZXBhcmF0ZSBmcm9tIHRoZSBzZW5zb3Jz
IGFuZCBmcm9tIHRoZSBlYXJsaWVyIGRlc2NyaXB0aW9uIEkgdGhvdWdodDxvOnA+PC9vOnA+PC9z
cGFuPjwvcHJlPg0KPHByZT48c3BhbiBsYW5nPSJFTi1VUyI+dGhhdCB0aGUgc2Vuc29ycyBhcmUg
YWN0dWFsbHkgdGhlIHB1Ymxpc2hlcnMuIEZ1cnRoZXJtb3JlLCB0aGUgZ2F0ZXdheTxvOnA+PC9v
OnA+PC9zcGFuPjwvcHJlPg0KPHByZT48c3BhbiBsYW5nPSJFTi1VUyI+d2FzIG5vdCBkaXNjdXNz
ZWQgYXMgYSByb2xlIHVwIHRvIHRoYXQgcG9pbnQgaW4gdGhlIGRvY3VtZW50LiBUaGU8bzpwPjwv
bzpwPjwvc3Bhbj48L3ByZT4NCjxwcmU+PHNwYW4gbGFuZz0iRU4tVVMiPmdhdGV3YXkgc2hvd3Mg
dXAgaW4gU2VjdGlvbiA1LjMgYW5kIGl0cyByb2xlIGNvbmZ1c2VzIG1lLiBZb3Ugd3JpdGU6PG86
cD48L286cD48L3NwYW4+PC9wcmU+DQo8cHJlPjxzcGFuIGxhbmc9IkVOLVVTIj48bzpwPiZuYnNw
OzwvbzpwPjwvc3Bhbj48L3ByZT4NCjxwcmU+PHNwYW4gbGFuZz0iRU4tVVMiPiZxdW90OyZuYnNw
OyBBIHNlbnNvciBub2RlIGhhcyBwdWJsaXNoZWQgaXRzIGRhdGEsIHdoaWNoIGlzIHRyYW5zbWl0
dGVkIGluPG86cD48L286cD48L3NwYW4+PC9wcmU+DQo8cHJlPjxzcGFuIGxhbmc9IkVOLVVTIj4m
bmJzcDsmbmJzcDsgZGlyZWN0aW9uIHRvIHRoZSBnbG9iYWwgc2luayAoY2YuIEZpZ3VyZSAzIHdo
ZXJlIGdsb2JhbCBzaW5rIGlzPG86cD48L286cD48L3NwYW4+PC9wcmU+DQo8cHJlPjxzcGFuIGxh
bmc9IkVOLVVTIj4mbmJzcDsmbmJzcDsgbG9jYXRlZCBpbiB0aGUgZ2F0ZXdheSBjb21wb25lbnQp
LjxvOnA+PC9vOnA+PC9zcGFuPjwvcHJlPg0KPHByZT48c3BhbiBsYW5nPSJFTi1VUyI+JnF1b3Q7
PG86cD48L286cD48L3NwYW4+PC9wcmU+DQo8cHJlPjxzcGFuIGxhbmc9IkVOLVVTIj48bzpwPiZu
YnNwOzwvbzpwPjwvc3Bhbj48L3ByZT4NCjxwcmU+PHNwYW4gbGFuZz0iRU4tVVMiPkRvZXMgdGhl
IHNlbnNvciBwdWJsaXNoIHRoZSBkYXRhIGF0IHRoZSBnYXRld2F5PyBGcm9tIHRoZSBlYXJsaWVy
PG86cD48L286cD48L3NwYW4+PC9wcmU+DQo8cHJlPjxzcGFuIGxhbmc9IkVOLVVTIj5zZWN0aW9u
cyBJIHRob3VnaHQgdGhhdCB0aGUgc3Vic2NyaWJlciB0YWxrcyB0byB0aGUgcHVibGlzaGVyIGlu
c3RlYWQuPG86cD48L286cD48L3NwYW4+PC9wcmU+DQo8cHJlPjxzcGFuIGxhbmc9IkVOLVVTIj5J
cyB0aGUgZ2F0ZXdheSB0aGUgc3Vic2NyaWJlcj8gV2h5IGRvZXNuJ3QgdGhlIHNlbnNvciB1cGxv
YWRzIHRoZSBkYXRhPG86cD48L286cD48L3NwYW4+PC9wcmU+DQo8cHJlPjxzcGFuIGxhbmc9IkVO
LVVTIj50byBzb21lIHNlcnZlciBpbnN0ZWFkICh3aGljaCBpcyBmcmVxdWVudGx5IGRvbmUgaW4g
dG9kYXkncyBJb1Q8bzpwPjwvbzpwPjwvc3Bhbj48L3ByZT4NCjxwcmU+PHNwYW4gbGFuZz0iRU4t
VVMiPmRlcGxveW1lbnRzKS48bzpwPjwvbzpwPjwvc3Bhbj48L3ByZT4NCjwvYmxvY2txdW90ZT4N
CjxwcmU+PHNwYW4gbGFuZz0iRU4tVVMiPkxvdHMgb2YgY29tbWVudHMuPG86cD48L286cD48L3Nw
YW4+PC9wcmU+DQo8cHJlPjxzcGFuIGxhbmc9IkVOLVVTIj5JIHdpbGwgYWRkcmVzcyBhbmQgY2xh
cmlmeSB0aGVtIGFzYXAuPG86cD48L286cD48L3NwYW4+PC9wcmU+DQo8cHJlPjxzcGFuIGxhbmc9
IkVOLVVTIj5GdXJ0aGVybW9yZSwgSSB3aWxsIGFkZCBhIGxlZ2VuZCB0byB0aGUgRmlndXJlIGFu
ZCBwZXJoYXBzIG1vZGlmeSBpdDxvOnA+PC9vOnA+PC9zcGFuPjwvcHJlPg0KPHByZT48c3BhbiBs
YW5nPSJFTi1VUyI+YmFzZWQgb24geW91IGFmb3JlbWVudGlvbmVkIGNvbW1lbnRzLjxvOnA+PC9v
OnA+PC9zcGFuPjwvcHJlPg0KPGJsb2NrcXVvdGUgc3R5bGU9Im1hcmdpbi10b3A6NS4wcHQ7bWFy
Z2luLWJvdHRvbTo1LjBwdCI+DQo8cHJlPjxzcGFuIGxhbmc9IkVOLVVTIj5XaHkgZG8geW91IGNh
bGwgdGhlIGVudGlyZSBkb2N1bWVudCAmcXVvdDt0d28td2F5IGF1dGhlbnRpY2F0aW9uJnF1b3Q7
IHdoZW4gdGhlPG86cD48L286cD48L3NwYW4+PC9wcmU+DQo8cHJlPjxzcGFuIGxhbmc9IkVOLVVT
Ij50aGUgdHdvIHdheSBhdXRoZW50aWNhdGlvbiBpcyBqdXN0IG9uZSBzbWFsbCBwYXJ0IG9mIHRo
ZSBvdmVyYWxsPG86cD48L286cD48L3NwYW4+PC9wcmU+DQo8cHJlPjxzcGFuIGxhbmc9IkVOLVVT
Ij5hdXRoZW50aWNhdGlvbiBwcm9jZWR1cmUuIEluIGZhY3QgdGhlIHR3by13YXkgYXV0aGVudGlj
YXRpb24gaXMgdXNlZDxvOnA+PC9vOnA+PC9zcGFuPjwvcHJlPg0KPHByZT48c3BhbiBsYW5nPSJF
Ti1VUyI+YmV0d2VlbiB0aGUgc3Vic2NyaWJlciBhbmQgdGhlIGFjY2VzcyBjb250cm9sIHNlcnZl
ciAoYXMgc2hvd24gaW4gRmlndXJlPG86cD48L286cD48L3NwYW4+PC9wcmU+DQo8cHJlPjxzcGFu
IGxhbmc9IkVOLVVTIj40KSwgYW5kIGJldHdlZW4gdGhlIHB1Ymxpc2hlciBhbmQgdGhlIGdhdGV3
YXkuIEZ1cnRoZXJtb3JlLCB0aGVyZSBoYXMgdG88bzpwPjwvbzpwPjwvc3Bhbj48L3ByZT4NCjxw
cmU+PHNwYW4gbGFuZz0iRU4tVVMiPmJlIHNvbWUgYXV0aGVudGljYXRpb24gYmV0d2VlbiB0aGUg
c3Vic2NyaWJlciBhbmQgdGhlIHB1Ymxpc2hlciBhcyB3ZWxsPG86cD48L286cD48L3NwYW4+PC9w
cmU+DQo8cHJlPjxzcGFuIGxhbmc9IkVOLVVTIj4oYXQgbGVhc3QgSSBob3BlIHNvKS48bzpwPjwv
bzpwPjwvc3Bhbj48L3ByZT4NCjxwcmU+PHNwYW4gbGFuZz0iRU4tVVMiPjxvOnA+Jm5ic3A7PC9v
OnA+PC9zcGFuPjwvcHJlPg0KPHByZT48c3BhbiBsYW5nPSJFTi1VUyI+V2hhdCBpcyB0aGUgcHVy
cG9zZSBvZiB0aGUgYWNjZXNzIHRpY2tldD8gSXQgc2hvd3MgdXAgaW4gU2VjdGlvbiA1LjMgYW5k
PG86cD48L286cD48L3NwYW4+PC9wcmU+DQo8cHJlPjxzcGFuIGxhbmc9IkVOLVVTIj5JIHdvbmRl
ciB3aHkgdGhlcmUgaXMgYSBuZWVkIGZvciBhbiBhY2Nlc3MgdGlja2V0IHdoZW4gdGhlIHR3byBw
YXJ0aWVzPG86cD48L286cD48L3NwYW4+PC9wcmU+DQo8cHJlPjxzcGFuIGxhbmc9IkVOLVVTIj4o
c3Vic2NyaWJlciBhbmQgcHVibGlzaGVyKSBhbHJlYWR5IGhhdmUgYSBjZXJ0aWZpY2F0ZS4gV2h5
IGNhbm5vdCB5b3U8bzpwPjwvbzpwPjwvc3Bhbj48L3ByZT4NCjxwcmU+PHNwYW4gbGFuZz0iRU4t
VVMiPnVzZSB0aGUgY2VydGlmaWNhdGUgZm9yIGF1dGhlbnRpY2F0aW9uIHdpdGggdGhlIHB1Ymxp
c2hlciByaWdodCBhd2F5PzxvOnA+PC9vOnA+PC9zcGFuPjwvcHJlPg0KPHByZT48c3BhbiBsYW5n
PSJFTi1VUyI+PG86cD4mbmJzcDs8L286cD48L3NwYW4+PC9wcmU+DQo8cHJlPjxzcGFuIGxhbmc9
IkVOLVVTIj5XaGVyZSBkbyB5b3Ugc2VlIHRoZSBhY2Nlc3MgY29udHJvbCBzZXJ2ZXIgYmVpbmcg
ZGVwbG95ZWQ/IElzIHRoaXMgYW48bzpwPjwvbzpwPjwvc3Bhbj48L3ByZT4NCjxwcmU+PHNwYW4g
bGFuZz0iRU4tVVMiPmVudGl0eSBpbiB0aGUgbG9jYWwgbmV0d29yayBvciBzb21ldGhpbmcgeW91
IHdvdWxkIGhhdmUgb24gdGhlIEludGVybmV0PzxvOnA+PC9vOnA+PC9zcGFuPjwvcHJlPg0KPHBy
ZT48c3BhbiBsYW5nPSJFTi1VUyI+PG86cD4mbmJzcDs8L286cD48L3NwYW4+PC9wcmU+DQo8cHJl
PjxzcGFuIGxhbmc9IkVOLVVTIj5XaHkgZG9lcyB0aGUgcHVibGlzaGVyIGhhdmUgdG8gYXV0aGVu
dGljYXRlIHRvIHRoZSBnYXRld2F5PyBGcm9tIEZpZ3VyZTxvOnA+PC9vOnA+PC9zcGFuPjwvcHJl
Pg0KPHByZT48c3BhbiBsYW5nPSJFTi1VUyI+NCBpdCBpcyBub3QgY2xlYXIgd2hldGhlciB0aGUg
Z2F0ZXdheSBpcyBqdXN0IGFuIG9wdGlvbmFsIGNvbXBvbmVudCBvcjxvOnA+PC9vOnA+PC9zcGFu
PjwvcHJlPg0KPHByZT48c3BhbiBsYW5nPSJFTi1VUyI+YW4gaW50ZWdyYWwgcGFydCBvZiB0aGUg
YXJjaGl0ZWN0dXJlLjxvOnA+PC9vOnA+PC9zcGFuPjwvcHJlPg0KPHByZT48c3BhbiBsYW5nPSJF
Ti1VUyI+PG86cD4mbmJzcDs8L286cD48L3NwYW4+PC9wcmU+DQo8cHJlPjxzcGFuIGxhbmc9IkVO
LVVTIj5UaGUgZG9jdW1lbnQgZG9lcyBub3QgZXhwbGFpbiB3aGF0IHRoZSBhY2Nlc3MgdG9rZW4g
aXMgYW5kIGhvdyBpdCBpczxvOnA+PC9vOnA+PC9zcGFuPjwvcHJlPg0KPHByZT48c3BhbiBsYW5n
PSJFTi1VUyI+ZXhjaGFuZ2VkIGJldHdlZW4gdGhlIHN1YnNjcmliZXIgYW5kIHRoZSBwdWJsaXNo
ZXIuPG86cD48L286cD48L3NwYW4+PC9wcmU+DQo8cHJlPjxzcGFuIGxhbmc9IkVOLVVTIj48bzpw
PiZuYnNwOzwvbzpwPjwvc3Bhbj48L3ByZT4NCjxwcmU+PHNwYW4gbGFuZz0iRU4tVVMiPkJ0dywg
dGhlIHRlcm0gQ0Egc3RhbmRhcmRzIGZvciBDZXJ0aWZpY2F0aW9uIEF1dGhvcml0eSByYXRoZXIg
dGhhbjxvOnA+PC9vOnA+PC9zcGFuPjwvcHJlPg0KPHByZT48c3BhbiBsYW5nPSJFTi1VUyI+Q2Vy
dGlmaWNhdGUgQXV0aG9yaXR5LjxvOnA+PC9vOnA+PC9zcGFuPjwvcHJlPg0KPC9ibG9ja3F1b3Rl
Pg0KPHByZT48c3BhbiBsYW5nPSJFTi1VUyI+PG86cD4mbmJzcDs8L286cD48L3NwYW4+PC9wcmU+
DQo8cHJlPjxzcGFuIGxhbmc9IkVOLVVTIj5XaWxsIGJlIGFkZHJlc3NlZCBzb29uLjxvOnA+PC9v
OnA+PC9zcGFuPjwvcHJlPg0KPGJsb2NrcXVvdGUgc3R5bGU9Im1hcmdpbi10b3A6NS4wcHQ7bWFy
Z2luLWJvdHRvbTo1LjBwdCI+DQo8cHJlPjxzcGFuIGxhbmc9IkVOLVVTIj4xMC4gSGFyZHdhcmUg
cmVxdWlyZW1lbnRzLjxvOnA+PC9vOnA+PC9zcGFuPjwvcHJlPg0KPHByZT48c3BhbiBsYW5nPSJF
Ti1VUyI+PG86cD4mbmJzcDs8L286cD48L3NwYW4+PC9wcmU+DQo8cHJlPjxzcGFuIGxhbmc9IkVO
LVVTIj5IYXJkd2FyZSByZXF1aXJlbWVudHMgdHlwaWNhbGx5IGFyZSBub3QgYXBwcm9wcmlhdGUg
Zm9yIElFVEYgZG9jdW1lbnRzLjxvOnA+PC9vOnA+PC9zcGFuPjwvcHJlPg0KPHByZT48c3BhbiBs
YW5nPSJFTi1VUyI+V2hpbGUgeW91IG1ha2UgdGhlIGFyZ3VtZW50IHRoYXQgYW4gUlNBLWJhc2Vk
IHB1YmxpYyBrZXkgY3J5cHRvc3lzdGVtIGlzPG86cD48L286cD48L3NwYW4+PC9wcmU+DQo8cHJl
PjxzcGFuIGxhbmc9IkVOLVVTIj5nb29kIGVub3VnaCBmcm9tIGEgcGVyZm9ybWFuY2UgcG9pbnQg
b2YgdmlldyB0aGUgY3VycmVudGx5IG1hbmRhdG9yeTxvOnA+PC9vOnA+PC9zcGFuPjwvcHJlPg0K
PHByZT48c3BhbiBsYW5nPSJFTi1VUyI+Y2lwaGVyc3VpdGVzIHVzZWQgaW4gQ29BUCBhcmUgYmFz
ZWQgb24gRUNDIChmb3IgdGhvc2UgdGhhdCByZWx5IG9uPG86cD48L286cD48L3NwYW4+PC9wcmU+
DQo8cHJlPjxzcGFuIGxhbmc9IkVOLVVTIj5hc3ltbWV0cmljIGNyeXB0bykuIFdoaWxlIGhhdmlu
ZyBoYXJkd2FyZSBzdXBwb3J0IGZvciBrZXkgc3RvcmFnZSBpcyBhPG86cD48L286cD48L3NwYW4+
PC9wcmU+DQo8cHJlPjxzcGFuIGxhbmc9IkVOLVVTIj5ncmVhdCBpZGVhIEkgd2FzIHdvbmRlcmlu
ZyBob3cgbXVjaCB5b3VyIGFyY2hpdGVjdHVyZSBhY3R1YWxseSByZWxpZXMgb248bzpwPjwvbzpw
Pjwvc3Bhbj48L3ByZT4NCjxwcmU+PHNwYW4gbGFuZz0iRU4tVVMiPml0LiBNeSBpbXByZXNzaW9u
IHRoYXQgaXQgd291bGQgd29yayBmaW5lIGp1c3Qgd2l0aG91dCBhIFRQTSBjaGlwLiBCdXQ8bzpw
PjwvbzpwPjwvc3Bhbj48L3ByZT4NCjxwcmU+PHNwYW4gbGFuZz0iRU4tVVMiPnlvdSBtaWdodCBo
YXZlIG1vcmUgaGFyZHdhcmUgZXhwZXJpZW5jZSB0aGFuIEkgaGF2ZS4gQ291bGQgeW91IHBvaW50
IG1lPG86cD48L286cD48L3NwYW4+PC9wcmU+DQo8cHJlPjxzcGFuIGxhbmc9IkVOLVVTIj50byBz
b21lIGhhcmR3YXJlIHRoYXQgeW91IGhhdmUgaW4gbWluZCB1c2luZz88bzpwPjwvbzpwPjwvc3Bh
bj48L3ByZT4NCjxwcmU+PHNwYW4gbGFuZz0iRU4tVVMiPjxvOnA+Jm5ic3A7PC9vOnA+PC9zcGFu
PjwvcHJlPg0KPC9ibG9ja3F1b3RlPg0KPHByZT48c3BhbiBsYW5nPSJFTi1VUyI+V2UgcHV0IHRo
aXMgc2VjdGlvbiBmb3IgY29tcGxldGVuZXNzIGFuZCB0byBzaG93IHRoYXQgYW4gaW1wbGVtZW50
YXRpb248bzpwPjwvbzpwPjwvc3Bhbj48L3ByZT4NCjxwcmU+PHNwYW4gbGFuZz0iRU4tVVMiPmV4
aXN0cy48bzpwPjwvbzpwPjwvc3Bhbj48L3ByZT4NCjxwcmU+PHNwYW4gbGFuZz0iRU4tVVMiPkNv
bmNlcm5pbmcgc2Vuc29yIG5vZGVzIGFuZCBUUE0gd2UgYXJlIHVzaW5nIE9QQUwgZnJvbSBDU0lS
Ty4gVHJ1c3Rpbmc8bzpwPjwvbzpwPjwvc3Bhbj48L3ByZT4NCjxwcmU+PHNwYW4gbGFuZz0iRU4t
VVMiPkNvbXB1dGluZyBiZWNvbWVzIHJlbGV2YW50IG5vd2FkYXlzIHdoZW4gdGhpbmtpbmcgYWJv
dXQgc2VjdXJpbmcgZGF0YS48bzpwPjwvbzpwPjwvc3Bhbj48L3ByZT4NCjxwcmU+PHNwYW4gbGFu
Zz0iRU4tVVMiPkRyYXdiYWNrIGlzIHRoYXQgaWYgdGhlIFRQTSBjaGlwIGlzIGJyb2tlbiBvciB5
b3UgY2hhbmdlIHNvbWV0aGluZzxvOnA+PC9vOnA+PC9zcGFuPjwvcHJlPg0KPHByZT48c3BhbiBs
YW5nPSJFTi1VUyI+ZHVyaW5nIGJvb3RpbmcgZXZlcnl0aGluZyBpcyBsb3N0LiBBZHZhbnRhZ2Ug
aXMgdGhhdCB0aGUgc3RvcmFnZSByb290PG86cD48L286cD48L3NwYW4+PC9wcmU+DQo8cHJlPjxz
cGFuIGxhbmc9IkVOLVVTIj5rZXkgaXMgc3RvcmVkIHNhZmVseSBhbmQgb25seSBkZXJpdmF0ZXMg
YXJlIHVzZWQgZm9yIHlvdXIgYXBwbGljYXRpb25zLjxvOnA+PC9vOnA+PC9zcGFuPjwvcHJlPg0K
PHByZT48c3BhbiBsYW5nPSJFTi1VUyI+PG86cD4mbmJzcDs8L286cD48L3NwYW4+PC9wcmU+DQo8
cHJlPjxzcGFuIGxhbmc9IkVOLVVTIj5Ib3BlIHRvIGFuc3dlciBtb3N0IGltcG9ydGFudCBxdWVz
dGlvbnMgb3IgY29tbWVudHMgbm93LiBPdGhlcnMgd2lsbCBiZTxvOnA+PC9vOnA+PC9zcGFuPjwv
cHJlPg0KPHByZT48c3BhbiBsYW5nPSJFTi1VUyI+YWRkcmVzc2VkIHNvb24uPG86cD48L286cD48
L3NwYW4+PC9wcmU+DQo8cHJlPjxzcGFuIGxhbmc9IkVOLVVTIj5Zb3UgY2FuIGFsc28gdGFsayB0
byBtZSBkdXJpbmcgSUVURiBpbiBMb25kb24uPG86cD48L286cD48L3NwYW4+PC9wcmU+DQo8cHJl
PjxzcGFuIGxhbmc9IkVOLVVTIj48bzpwPiZuYnNwOzwvbzpwPjwvc3Bhbj48L3ByZT4NCjxwcmU+
PHNwYW4gbGFuZz0iRU4tVVMiPlJlZ2FyZHMsPG86cD48L286cD48L3NwYW4+PC9wcmU+DQo8cHJl
PjxzcGFuIGxhbmc9IkVOLVVTIj5Db3Jpbm5hPG86cD48L286cD48L3NwYW4+PC9wcmU+DQo8cHJl
PjxzcGFuIGxhbmc9IkVOLVVTIj48bzpwPiZuYnNwOzwvbzpwPjwvc3Bhbj48L3ByZT4NCjxwcmU+
PHNwYW4gbGFuZz0iRU4tVVMiPjxvOnA+Jm5ic3A7PC9vOnA+PC9zcGFuPjwvcHJlPg0KPHByZT48
c3BhbiBsYW5nPSJFTi1VUyI+PG86cD4mbmJzcDs8L286cD48L3NwYW4+PC9wcmU+DQo8cHJlPjxz
cGFuIGxhbmc9IkVOLVVTIj5fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19f
X19fX19fXzxvOnA+PC9vOnA+PC9zcGFuPjwvcHJlPg0KPHByZT48c3BhbiBsYW5nPSJFTi1VUyI+
QWNlIG1haWxpbmcgbGlzdDxvOnA+PC9vOnA+PC9zcGFuPjwvcHJlPg0KPHByZT48c3BhbiBsYW5n
PSJFTi1VUyI+PGEgaHJlZj0ibWFpbHRvOkFjZUBpZXRmLm9yZyI+QWNlQGlldGYub3JnPC9hPjxv
OnA+PC9vOnA+PC9zcGFuPjwvcHJlPg0KPHByZT48c3BhbiBsYW5nPSJFTi1VUyI+PGEgaHJlZj0i
aHR0cHM6Ly93d3cuaWV0Zi5vcmcvbWFpbG1hbi9saXN0aW5mby9hY2UiPmh0dHBzOi8vd3d3Lmll
dGYub3JnL21haWxtYW4vbGlzdGluZm8vYWNlPC9hPjxvOnA+PC9vOnA+PC9zcGFuPjwvcHJlPg0K
PHByZT48c3BhbiBsYW5nPSJFTi1VUyI+PG86cD4mbmJzcDs8L286cD48L3NwYW4+PC9wcmU+DQo8
L2Jsb2NrcXVvdGU+DQo8cHJlPjxzcGFuIGxhbmc9IkVOLVVTIj48bzpwPiZuYnNwOzwvbzpwPjwv
c3Bhbj48L3ByZT4NCjxwIGNsYXNzPSJNc29Ob3JtYWwiPjxzcGFuIGxhbmc9IkVOLVVTIj48YnI+
DQo8YnI+DQo8YnI+DQo8bzpwPjwvbzpwPjwvc3Bhbj48L3A+DQo8cHJlPjxzcGFuIGxhbmc9IkVO
LVVTIj5fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fXzxvOnA+
PC9vOnA+PC9zcGFuPjwvcHJlPg0KPHByZT48c3BhbiBsYW5nPSJFTi1VUyI+QWNlIG1haWxpbmcg
bGlzdDxvOnA+PC9vOnA+PC9zcGFuPjwvcHJlPg0KPHByZT48c3BhbiBsYW5nPSJFTi1VUyI+PGEg
aHJlZj0ibWFpbHRvOkFjZUBpZXRmLm9yZyI+QWNlQGlldGYub3JnPC9hPjxvOnA+PC9vOnA+PC9z
cGFuPjwvcHJlPg0KPHByZT48c3BhbiBsYW5nPSJFTi1VUyI+PGEgaHJlZj0iaHR0cHM6Ly93d3cu
aWV0Zi5vcmcvbWFpbG1hbi9saXN0aW5mby9hY2UiPmh0dHBzOi8vd3d3LmlldGYub3JnL21haWxt
YW4vbGlzdGluZm8vYWNlPC9hPjxvOnA+PC9vOnA+PC9zcGFuPjwvcHJlPg0KPC9ibG9ja3F1b3Rl
Pg0KPHAgY2xhc3M9Ik1zb05vcm1hbCIgc3R5bGU9Im1hcmdpbi1ib3R0b206MTIuMHB0Ij48c3Bh
biBsYW5nPSJFTi1VUyI+PG86cD4mbmJzcDs8L286cD48L3NwYW4+PC9wPg0KPGRpdj4NCjxwIGNs
YXNzPSJNc29Ob3JtYWwiPjxzcGFuIGxhbmc9IkVOLVVTIj4tLSA8YnI+DQo8aW1nIGJvcmRlcj0i
MCIgd2lkdGg9IjI5NiIgaGVpZ2h0PSIxNjAiIGlkPSJfeDAwMDBfaTEwMjkiIHNyYz0iY2lkOmlt
YWdlMDAxLnBuZ0AwMUNGOTlENC4xNzZFRkQ2MCI+PG86cD48L286cD48L3NwYW4+PC9wPg0KPC9k
aXY+DQo8L2Rpdj4NCjwvZGl2Pg0KPC9ib2R5Pg0KPC9odG1sPg0K

--_000_34966E97BE8AD64EAE9D3D6E4DEE36F25817518DSZXEMA501MBSchi_--

--_004_34966E97BE8AD64EAE9D3D6E4DEE36F25817518DSZXEMA501MBSchi_
Content-Type: image/png; name="image001.png"
Content-Description: image001.png
Content-Disposition: inline; filename="image001.png"; size=28517;
	creation-date="Mon, 07 Jul 2014 03:52:22 GMT";
	modification-date="Mon, 07 Jul 2014 03:52:22 GMT"
Content-ID: <image001.png@01CF99D4.176EFD60>
Content-Transfer-Encoding: base64

iVBORw0KGgoAAAANSUhEUgAAASgAAACgCAIAAAAw8WZPAAAAAXNSR0IArs4c6QAAAARnQU1BAACx
jwv8YQUAAAAgY0hSTQAAeiYAAICEAAD6AAAAgOgAAHUwAADqYAAAOpgAABdwnLpRPAAAbuNJREFU
eF7t3Qe8FtXRP3CT901i2htTTVeTGE035Z+YZkxijFFjQcVKVXrvvffee6/Se+9IR0CahSqCgtJB
QKTl/9099y4P9yIiEOXq83zwus8+Z8+ePTtzZs7Mb2Y+9p///OeKd/uMGTNm5cqVWq1atWr//v3v
1jz9e3oGPnIzcOWVV/7ud7/z2DfeeON9993n67tMAcZ7p8/s2bMfeeSRq666Skd14s/o0aOdTH/S
M5CegSwzMHny5MAjWAbXYRnMcg7muuKsvz333HOuvPXWW59++ul9+/ad4/r0T+kZSM9A9hnAdTjo
pptuwp9nnZ+zMB5mu/nmm8/Nr+m5Ts9AegbedQYIMNKLGMzeMivjVa1alax866233rXTdIP0DKRn
4HxmIOifWXjqDMbDdRqdOnXqZPqTnoH0DFyKGcBNmLNPnz40z1QuPc14NEx86bc0412KCU/3kZ6B
aAYC4/k0adKEYEt4L4PxKKP2dUEaphkvTTLpGbhUM5AwHs4i2Ii3wHsZjJdq/bxgxsvk7XPovWkl
9lK90HQ/OWMGUhlvx44d1157bRBvEeNxQdxxxx0Ju7wnxjtx4sTJEyeSa/fs2b1mzZrp06YPHzp0
2JAh/jmYOmUyifrGG28kzU6eyBmzlh5legYucgZSGQ/9ly1btk2bNhmMh+vw3oUxXrhq586dkyZN
atyoYY1q1apXq1anVq0G9eo1rFu3ob/16tWrU6d61arVq1WvX6/+6FGjt219NVx1kY+Uvjw9A5f/
DGRhvJdffpnQixiP4INNSbV1no/EI+hsBl2/ffuOnj17li9XrmrlKhivaZMmXTt3fnrwoKlTpsye
NXvO7NnTp00bNnRoj27dWjRv3rhhw+pVq5cuWbpTx46bN28K7KerSGymP+kZ+DDOQBbGQ/CMKYsW
LboiMWa+J4kXGGb0qFHlypatVrVqy+YtunbpsnDBgtkzZo4bOzb7Jm/evGecX75sWa+ePTWuXatW
2dKl+/fre/jwYY2PH08z3oeR6NLPlGLVTJgiIMuuCP9LZZVzSzwsovGunTsbN2pUsUKF5k2bDujf
74Xnn8c8zg8cMLBCuXKv79hhzhM5dvTo2y2bN2/YoMHxY8e12bhhw/BhQ1s0bVa1cuWaNWps2rgx
rXamSfTDOgPZJV5Ak12RP39+3r3zZzwtX968mW5Zr27dNq3bLFiwYPOmTXv37Hb+hRdeaFCvfptW
rVu1aJnwkoO5s+c4o/3gQQN9XfbssmeXLiX9Onbo0KhRw9IlSzr+b8i9YPi55IbU49aY4yfi5enS
KclRT8czPD5pj86HiAuzMx49k7Z5RRbLCgY4h8Tz6ytbtpQpXTrs5ba8vMWZwQMHkn57du/R47/v
vPPfd92FLZ0/cuTI4UOHHIwaOfLef//7zjvuaNWyha99+vRt3qz59te2b33llT69e7do1qxYkaKB
984x4cnSENqkPs/5X3VJXijGyzKYLF8v6C6RvvD228defOGFtWvWHHrzzfPZaV/QjdIXva8zkJ3x
gn3lCiDOLADqs77y2JryH5EKNnXNmzXr3Knj/v37aJj169WbMX0GY+bK5cunTJ78VMGCRQsXLl60
qM3bcyuemzljhqt6dutWMH/+J/PntxvkynDJvr372rZp88zcuW+8/kbMe81Lliix5eWXw9Yxu63l
2LHjSxYvNs6DBw8ans+xt48tXrSI8ebNN98860Rqc/To0WZNm+Z54vF169ZdQjrW1fLlyx95ODeJ
/fbbb7u7UZHhe/fuveC7RPrC88/f8+9/f+H//u/zn//cnDlz0ur3+8of/7WbXSzjRULm5Ek806Rx
EzZJTNK5c+eXXnypdMlSFM6li5doMGHcuP59+w3q379mjeq7du3EVBs2rHfjwQMGdOvSuX/v3jWr
VX/z4MG9+/Y9u2RJm9athw8btmDe/Igze/Zs3bKVHeORw4dTN4cZwu3kyTffPPSrm276whe+sHbN
2iBe9u8/8LOf/vSLX/wipgpSOhB9+DU8LSfHN77+dfGIvXr0SG2TCMxwSTI1CdtEfcVdht6yCFhn
mjZpqtsfXn/9gQMHjr711r3/vucrX/7y2rXR2MJVZ3QV95X6ZrPcMQy+YIEC+rzt73+rVq3qhg0b
LoyHQ1cXdu1/jfbesePsmsI7jTx5rZdwkBc8S8mFyajO0VXyrpOHfW8Sz2Vjx4whslq3arV169Y1
q1a3atmyc8eOc2bNInwiUjt5EkNWrVK1ZvXq+fPmxZlUphnTp1PMGjdswOJSrXLlgvny7969J2KJ
N97ApdOnTp01c2bb1m22b9/eoV077r4e3bpHhH6md+HUyVOHDh36xc9//vnPfU6fmYy3/yc//jH5
8NJLEeNl/3jg48feHjt6NA5n7EkaBHF61kvCSfvC1F+1T7ZeCR/a5TZv3oKEj9ofP/HTn/7ks5/9
7OZYYqcSU1ATMroNojzlTJYx/PmPf/z85z+/efPm6PwF4dSzdHjBhBUT9wljiN7FRXzi53jHLXag
yH379x858lbGHTMfIPWeYcYgLvbu3Xfs2LGLGE7GpfFDnX6lnvQ99RnGGAZ//Ngxo0rOvJPmleW9
nC/jRZR36hQzZrkyZVq1aLFkyeIN69e3b9vu9dffGDVixBtv7Iyf5MT+ffuKFylSqkSJ8mXL3H7b
bfx4M6ZNw0779u3Ndd99LCj8B84vmB+JuPBZtHDRYw8/XKRQ4SOHDlO0WjVv7vL16zdked/uTnH9
1S9vuuqqLwSp4rP/wIGf/exnX/rSlzZu2Lh39+4qVau0bNmCCM11/3333ntP/379XMU52aN791q1
a7GjEstFixV1d+dPHD9OSyxUqBDLELZp367dnf/61x3//CdPo02pBtOmTS1WtOjAAf1LlSzlV2cG
DhjwQK5ct/7lFiYi82u0NarXGPL009aXEiVKkKsUxNy5czdu0mTcuHGFCxfu0rmLnr2fiRMnPvXU
U8xXpihsDnfseB2Q4K4777rvnnt5Vg4dPvzKK6+UKF7i29/+1he+8H+PPfaYTa+Rv1e20X79uvXl
ypUrUqRI2TJlFi9afDFsE+xSR986+p6IMkvjt98+ijTfiRxxEa/Sr3716+B/Mn6zWqVKlddefTXL
uvP6668/kvvhv9zyl02bIt/vxQzJteSEV/PSSy8VLVLEHSN6OG/W03j1qlVVqlTdtXMX/rnrzjvZ
J+2ngEN2vrHzrK/swiVeWHL43+rWrt2zRw/W/0kTJgzo15/EM61+Oha74Xbv2tm+bZsmjRsVL1KU
0Js0aSK6rFK58p7du/kMKlUoX71K5SqVKs5N2b34SbfPPbdy8qRJWzZvfnrQ4LatW9uVvSfG44hH
/V/60hc/9alPfe5zn/vaV79KYSMJly5Zao/32//3/3y1GwQMd/DUk0/pnF3nq1/56qc++ckVK1bQ
b50nTn/60586sINFA40bN3aMl/wl5Ht07/Hxj30Md/36l78qXqyYHkYMH+Gnf99993MrVlxzzTWf
/cxn3Vr7W//ylzGjR/vp61//OsuTSb/9H7f72r170HVPbtu69ZY//9mZL171RQNwULRoUUP97ne+
S2aSeKT67f/4x6HDkVHqPVGY9rNmzvrSF7/YpHHjMqVKXfPda6ZNm5Zlrc0i6rN8zUIiDerXDyr6
WT/n1hpcsn79+rxPPHFg//7kQbL0w/b2veuus0JFciymMWTg8VetXJml5cL5C0y+peTc488+zuxE
bzdeIF++l154ccf2HTVq1CRCAg4k++esklCzMaNGf/5zn31126vWi+98+9tbt24bOWK4YdsdnPWV
XTjjedp9e/dWrVyJL47DAJXXrlmT6HtlyytBbQsikfb49KBBxYoUQXwMJ+PHje3SqXPRwkU2b9zU
skWLB+6/P+/jjzdt1IhBJfVNWOybN23WsWOHl1560Z6Q2aZyxYpbtkTG0sTEgmAPHz70q1/+8qpo
j5epah7YHyQe3WzrK1u9wv/5n//B2mYk1/33h30dLedvf/3rlZ/6FPfFiuXLceP1P/gByCjx9bGP
fezRRx5hSkXuv/rVr55fu3b5s8u+/73vfeMb39i9a1e7tm01+OY3vwlzQw0mD3XYrGmziHliNZXW
/Yn//d+HHngAb6Own//sZ/afkDomgXB2U+179+q9Yd26r3z5K9ddey0pF15tgwYN/PTYo4/ywcyc
MfNb3/qmUS1auNBk/u63/w83mh/KxQVAeXTuWur3ju2vOc6fL999993rYNu2baR0o0aNyA2moA4d
OljsKlWsNH78eL+aPQxWoWLFCRMmWEb7+/Tt1759+759+qD13/z611OnTh0zekzXLl3r16/ft29f
eweT7EldK+1VyxYtrarI9403XgdB7Na1K5EFR/HG66+b3s9+5jPlypazGw+i4PChw927dStXrvzo
kSMJ/0YNG331K1955OFHwoZWhzOmT0PKq1etHjpsWLeu3WrXqt2nV6+XN7/M4/W1r32NimFuF8xf
ULlSJauz9/j2sbcZGgy1d+/e8+fPN+zWrVozmLOu165du3//fnQMQrJevegBJ0+afOjNQ7ZCn/70
p5944gnaVvfu3V/dts19bRkqVKjYuWMncqxbNMJyNlCJjhxeXLJDmThhwnXXXkOhe+CBB1CLm9Kz
vvud79h9XGLGi5aiyZOrVanct3dvE2pZmj9vXs/uPRgVkiXZxBFfdWvXKl2iBN4rWCA/bHTtGjWe
eOzxhfPnFy1cqFTxElTNxx99ZN68eanj8wLwkvfXrk1b74+QbNywkYmM22RoAIHxfnnTTV+86iq6
QZiIAwcO/uynP2Nc2bRxE7fEtddc861vfSvMY4Xy5RE3kJq3/feY8RZRKU+cuOOfd2AnXPf44499
/OMfR08jRowgJ6+++ms/+P73se6nr7ySyFm/bl37du31QNsM96pZvYavhEm+vHkxcMJ4D+bK5cEt
2L/+1a8w3sYYCeDTqVMn7b1dmqQDil+w1Wh5+23/+N///d+pk6eElsyYH7viiqcHD3Z8y5//5BZW
orO+v3eVfq7CeD/+0Y3r173k2GMa1fbXXnvwgQdKly6NDRhvmIK+fvXX/3LLn8uXL2/GVj73HDpm
MKtUsSLSIf//9te/0R2KFyuKmH584423/f3v3pdrv//97wPhMiA98fjjjzz88E0///mePXtoB48/
9pjO/3n77XT4z332s3nz5OFM+v3NN1tWSpUs8fWvX61zQsbg0bHjm37xi2rVql1//fVDhwxF93g7
f778mD+T8aYbxuqVq+jhN97ww6pVqnztq18Z0H+A4V199dWYbf78BT/+0Y95s/7+178ZCRv7d77z
bbxqOaMrff6zn9X5jTfeYCbDJYTkvGeeiVaW+Hk5kO1Hrv7a14x85IgRX/7SlxYvXITrvPpy5cv3
6dW7Vo2aP/3xT9q2aQvnGI04/jAH7tu7J1CjiaXu6Wr2rJkF8hf49je/2aNHjxGB8V6+1IxnUlq2
bNmsSZNpU6fOnjWrQL78hZ58avOm6DanF+Z4E2jBo4K21rhp0+FDhloL8z6RZ+6cudAtlhOYsjq1
a82de4ahXCe4ZdCAAVga3VAz3Kh+3bpvHz29u4j2eIcOeWfUuUQPsdx+77rvmcRXXtmC8a757ncx
D1+iDpECcqcVZzDelVdivIgfOnZ03j7zuuuuu/GHN9iU2gqSk7RBK6tFvXevXkOGDLEussdoSVC4
yt2ZdpiUCEYnTTrl3rJH4sWM58W8GUnjq64KyoYP6f31q6/+7ne/S9H9zGc+E7TrsOdElJ/8xCdm
TJseWt59190f//jHRg4fbtfxpz/+0TpCfl4s470UMR440c2/+x3z1be+8Y3q1asRgN/51rc2rN/w
k5/8JISE/b9f/waxejSbAjveb3/725jtnnvuKVuGsh19/n3nXcC3DpB4sVjBxsl2sLSeG274oZf1
oxtvLFKoEBFHsg0aOJA2sW7dehTyg+99nwCc/8w8rLt7d4SsoBQdPHDA5W7kq/UrX958NpA//clP
pkyaFJ7XX+IUBa9ZvcpiUalSJWd+8Yufe4/0+R//6Edert3NH3//B+fnzpn9/eu+x8LHrNWhfdRn
ty5db/7dzQ6KFStaqlQpBz/76U+s4wcPHJw0cSK59K1vftMBU/uNN9yw6rmVa9aspoksXby4QH6m
wLzhkd3rB9ddZ80KLOeVEQx5Hn+cHiHsJrTBeFh9x47t48aOY2nXDDE4c4kZz51wfO1aNQkBhIXE
rZED+/c/cvjIGVvJmPEG9OvHX3fLH/8oIqFVq1b0GS9m5PARsNF33XFH7vvvb1Cv7jPPnFY1g5pK
139m9pxXX3112bPP2gKxx9SqWdNXUiJZ5smKe/59D7q3CmK5I2+9xQNBdPzpD384fPgI1RTjURR3
7dplwKVLl4kYr3v3LIxHInmvn/zkJzEbQ5GWtsX/8z8f/8Pv/0DHCNO6d89ef1u1aqkHARaBJmgs
DvCbd+a8NXLKpMmB8fhYvFpbxM9+9jMzZ8586+hRQ/VQeZ54gnS1M7zlT382gYm1wDvWAxsS4TNr
1syvfvWrFNpNmzYee/voJWG8SNWMTbhUuHz58nF+WpuEokTaY9++r732Ggq2uGjw29/8Bh0XLlS4
0FOFxo8bT6ZhvHvvucci69djb79929/+1qhBzHiPPVayZElbod/+9rd0H4IRw8yZNfuGH/7Q47Rr
165bt+5Urx9eHzEeje5HN9zw+o7tkyZOuuGH16OKTMY7aHnq1DFikvzYLm9eKr3BkDxZGG/tmtUY
j2LpjtScXj17zJ8/z8xDbjA7sf1qz8/pdbNzSOM1NrbNWDdN4FtH3ipSuIi1wBnXDh40GF8xoowb
N55YmzB+PDObBZqoF7x23XXXLlm0mJvXJ7x9HwqdJZ5QDZYwBGrPXLBgweBAThiPYd80/uJnP7eg
6Pa/wnicdZUqVOzfty/RRJR5+LlxxrIzlJ9Tp6KtUes2jz/yCFNPoSefZLKzDbUXomHmfeLx+++5
5+EHHyhVongWVRNOSle8eeXLlitbqvTLmzaNGDacO962J7lFsO7QDEkPVGtl/fGPf+yAAAxKmhWB
pkcR4rjz9amnCvm1U4cOGA95OZ4XbywjGnr8CV/pmfNj/yEevuvOaP/2zW9886+33oqSbM8MqWmT
yLjCrBKuMvV/+P3v//ynPzn585/93F2gwx3f8c/bI9Pf0bf/cdttvtqxMI1SuV1Cif30p690I8Sd
PIiDCRMm2ohrHGm2n/50tHVsEhmT7F5wL15lbcs6t++qZcYNXEXaXPWF/6tRowat8qc/+TGf/ltH
jtx9513snLiOZ4V8u+GGG/51xx3aWIOsoZ733nvvbdSwodEOHjTI17qxnCeBWYft8ZYsWfLQgw8S
mJw6P/zh9XCGzlAR1730Em7MlStXv379vYXFixfT3J5f+/zY0WO+8bWrX3t1m/0IzblunXp8sJH0
OHnKevrLm36h/x98/3vDhgy1xuknvMEw/kzjynN01zKly7iEUIpcVnNm2w6w6onq5DtlD/vHP/7x
8MMP79u3n6pJrLmWfmg5sI1kFi5evDgWcS0VhsXBIBs2aGjHMWrkKHa1a7/73WJFi8nR/OUvfXHJ
okVI9Jvf+EaFCuXJTLLOpvHvf/ubBciON4iWQAPJMaqmVFvr+/Xrd813vst6BJjlzMZNZ4ccX6Bx
xS3ZAJh9Md7G9etNk72sdTSb5fTU3j17atWoQdvs368/QUdjHD923LgxY7t37fbEo4/16tnLDpjU
pnNnIayYc9bPmTnr1a1bEcrkiROrValii5jaLIwe7z36yKM0qN/f/DtK7MQJE6MZOXmS6YLW7n1g
JC3tCiypqJCkkujCcsXOHhlFTv0H0gUNiRikT4Y+Ga8xmLn+/e9+h23sNo8fP0am5c2Td9SokWHS
eRSQoAW1RPHiwYPPKmMppQVYF/XDfkhJ++Mf/mBxpXlqsPWVLV48gYYWkwcJkpPZ84FcD+jt3nvu
7dunL/Jykt7VsH59BEFeZZvb8+O8k6dsd2vWqFmmTBnvi0IY6AWJoHVCb8yoUXjg5z//ueelyJFv
brRi+YqKFSsxhjVv3gwcp1evXjNmzAz384y2RowrWo6MzSFt2rTlzrELbdq0KdXLbNNrSpcqjb6Z
3CxPFDANoAvsAL3KLp0716hZ004s2SzR9umBQ4cMiZTPgwebNWuGl8Lz+mvRsR/zRiwT4ydMwPyW
LZYSYkqfNiMeiOOX8QPgnvT2pnhTV65cpQOLSPv2Hdgdhg0bzt5o9SS6Vz5na7KyYsWK7dq2a9q0
mS+nTp4YNmxo5cqV586d26RJ02ARwUulSpVs2aI5FjJ7xhC2nYnCmbxBJ9nh2Jm4o5cvX4ZaQD4Y
KfiHdu7cddYXd+GMN2rkCM9pO2TG+/XpQzcI+JIsH9qzrVqgVK+qZ4/uS5csYSgfO2Yswg3nWVCQ
fhbGMzKq4+yZszp16EiVJbgtwEwj2ZuFTuyUCJlwHCGLjx9PlqXwNfzk48WEg6AuZsdYnnFh7BqJ
rzrt9c6Yej6tlMspk4Fb4saZ3Ub++miNDOexPVMNs0TcQ4aVKBpqpgNdJ8k4Q4vw9UK57mTq06VO
TnIXB5Re3kJrfGaD03OV2syDhDiSM06mTGY0pbGqknxQaXwy4yniB8qYRi/Fw3oXqSSYiiXIJKSM
9kmz5InCGV1mecbk/SYHJzIHGRxd2T/ZZyk1f0Jqe2/8bAve6YfKmMNMensnxPyFM97oUSObNGw4
aOCANatXYyFCL9ipsjLe668PHjjA4rRg3ryhQ4dWLF/e1q5e3ToWcraKFcuWPb92DRGRnfEisjtx
gnmDJ501zBJr09+hfcSrZ9wiepWR3yKFQDOwIGG9DCQb+zair5nH0fnIG5wZphS3cybTaXoiK946
/JTKAKk3DbfMaKCnTIdK8s7sdkDGf/Ob3/zPxz8ePGkp98q4NpXlkmdMHuFs7/t8zp3hBs4YZ+QG
P33ezpxxclkmHj1pk9F7ZsvMZ8zwFWUAieKOwin/S+YhzHP0Y+bf1DPJcWr7cDJz6s71aPFbzHiE
jDd4+sKMyYxXtvCM8WsORynPknqD0/fNPJs8Vvxc5+tKT52qcNMwK9kf5mIYb0STBg1sABg/+vbu
Q1PasX171oX51Enb6B7du61du2bJ4iV0D1av4sWK534oN92M089+w1aYNynVgR5GqSsrIhvM1MmT
165ebXfets3ZGO98aO+cbc4hTM4qbcKUZZ+45GTWu8XtOSHs3Ig7bqjwdBc98EvWQdhRx+p5+vM+
zcDFMN4osqtf374vb9o8fOgwaiToY3Z6YlRo3KD++LFjJk2YaBNFarEWCH+gNDLiUbvpkFx8z8zN
sseLhJgOqZqCD2wbJowf53bAIqkSL2gyWT6xKHv3JSqs08m1Z7kkFqRZnyhDrGUsDUGlJCoTXora
x4tw6gt0jl4wfuzYZUuXXjzW8ZKTRliUz2fSLvmtP7IdXjjjzZo1i0fO7o6Jn1zCVCReNhTvqZ2v
vzH06aeZJWV5GD9u3HPPrWCoFezHz8bzvmTxInFmAVR9pg4ZEf3uXbsF+DVt3Hj5smepalUqVZae
LGmGUN566whQKLACRJx/0f9ff8NW0xJ+Pm/Utg0yo0XzFnrI3p6tr3jRYpCWYJ8ZN7UTO3Vq5vTp
DRvU50WwdWbCejh3boYZXgoGJCsFW47gpuyyI3V1OJ+xpdt8uGfgwhnvpRdftGGjZLKckntVK1WG
Lcimap7avXNnm9atGJHZLZk07QnFH4wYPnzqlEnMaM/MmQPCUrlChSyqJqai+SyYP09L1iHBdazD
3AlgRwnjOXj22We5azm+v/+979/wwxt++hPW8p+wPmfdB57tHWoDz816TgPs0L79GZfEu8ED+w/w
7TA3c9QGPSwe1X969+x19113Pf/883//298pzLkffIiVuU2rVjf/9ndQS4zXwXvx4aab9NNd5Axc
IOPZtRAIsGAd2rWN4NETJ/bt1WvksGEg3ll4jx8PQgUQwVatXp3anTq0nzVj+qwZM8SniwmaOmnS
tMmTy5YqlYrVjLekkcmLnXfixEmECfNuuzZtuCX4W1IZD1CLP5S/FSry+ut/wOuNi8ZPiNCG4RPU
p3DM4JYchzMEJgt7rvtzrVq5KiiHqXKJD5SRnRvQEpN6vl+fvgBQrOr/uO0f856ZB3ixcOHC3j17
Yjnu6V/8/BfBX3+RLyZ9+Yd7Bi6Q8QKNMkvy0tDWGC25E3r16EmyZaE5+h/n2/wFCwYNGkQWsX/C
xYEOtG/Tlpth3JgxrNhdO3cJ+Npkrh2/+MKLTRs3nT59OifysqXPRpCxevXejhDrGa0i5nz7bcIQ
cAyUjDMN1/3zn/90hhWUX5GM1fTwkUP82pHR9QDZvA+wYMaM6Ry7RiKGCMNjpNdf3xFQzgsWzHee
XxV4JUBPOHO576iRTViAZkcgL+VvwRpvu+22alWr0YS5vAsXKgTnTYCDlYJZ7ty1K0H0fbipJ/10
FzwDF8V406dOg9Viq+QlB03gN0wiwRMRQeJhMHEMUPDQJ3yRi+3rnn8eAA9Kk1bmQxcNEi/1s2fv
XszTulVLTmeQP7Z4PsNEiMVSMXrqcAlNVYwCkMRS1ov//IfqG8D+jnfv3oU3YAi2bttmt/blL38Z
WpIL+9NXfgrAh5aoZfC589sKSvDVBzrp0KHDv/zlLwU6XHvtNeGk2KJFcTwbvzAMDe824QZ8LNo9
2l/u3MlRy88bocMu+IWkL/xozMCFM575sQsSWQdrv3DBQqSPjnUnxiR8jsrRc+zY9ldf4zSHwo/5
oQ/XeWAVYTUCTMMxYRLhvk+eDFfF/44GnyZLyboXX6SsVixfAWIzizh1iX7hG/9yyy0YI8lHOGDA
AF/hVLS3KED04UlGIJLQpg4CS0YZ64ULBSx+/H8+PmvGTKoj5gTvgquIIi3mz+eWxHga61zyeVAp
fYK8ZFkgsn+9rFwFHw0yznlPeeGMFywNZAvjXpVKlbgHunfp2kUIXdu2Hdu3jw/aAUbyH1SqUKFz
hw7du3QRU2eb17VTpy6dOrVs1kxcpgP/BA3Vr1vHgWtdqLEDpk6XQ8oBKHVo115wQ3auCxIPCAhL
/O63v2MFDWwwcOBAZ4SWOBa7ASKMozIZ79uEHkSSn/D2vffe94lPfILHAtzUJaVKlEwYiWYKF0sG
BldHk0YRUDOEJuS895we8WU2AxfOeIHoyROM0axxYzF1AszBncFZalStWrJYcdgUdsiSJYqTV+wi
UoxxxLVo1hSXVqxQ3p4NrlrqB9wovV+F8uVEo8vCAjztwJapfNmyMtuKCxbhDvgXAo5SZy+IRKBH
GHAIY3HWCc9AtWKSggUKOmNrx/KZMJ4wEPbPkOKFQBYVivHIW+nMXAKV5nyYFPKQpcSFIdhPUJIG
HirNeJcZDefI4VwU4wXeY9IUEsrMwJjO9gjNLEpNzPi0KVMdkCQTxk9wnsSgjjKW3HfPPYLBxRAJ
NxRiSLUTAFq3Th0ijspXl+WzY0cxfngAZzYSzFi/PvuHG2X18J44CZ4pegM/PFmwIMuJVWDXrt3Y
yW7QSeGYrqI3iuYWBRMkHsZjBQ3xYIHx/vcT/wtC2bB+FAPONBJyfjLb4NjAeHzfacbLkdR9GQ/6
Yhkv5r1TjRs1Jgrq1a3HrMevBRVFHEWwzMaN+bKLFC4s8teBXH033nCj8BPmeDEX4tA3btwApSnE
i+4HPoYnwcapdrff9neARiorBmYtlEkhOx4FMzCifupTnxRl873rrrWRu1702HXXiR9l5Rdf97Uo
g8DDbiTQTiiKZAc8H1/5ylfiCL0Mxrvrrjvxm+Xg2aXP/t///Z9jO7q77767RrXqkaj88Y9lTAlR
tqJX/Er8piXeZUzPOWZol4DxdCHEA2JDkIHkFrAsQoDhbhkwJ44bB8zRo2vXIYMHyXriQIRbrH+W
+MY3vl63Vi0hRXJptmjalK+MRte+TRueCciPAX37yWUiaqNkyRJCE95pd4dp+bgF2tA2JbqQSuhr
X/uquFtGmqJFikoJwV5SoEAB2YfkPhAwwhopPYGgSRKPNkniiQoVqC+oxC369O4jJyet9cpPXVmy
RMk33zwoQwTx+EKcwkyGGFbNd9pq5pgXnh7o5TEDl4DxgpWFIle2dJnmzZsjX3Aqhkr1Ejq1b1+m
ZKmunbrI605vnD51CiVT2pnyZcpiBtksbJzq162HY/3jKO/TsydoGBu9/EhqLURxbjHRv9NcSQYv
LdTpj+Pt2wW5eCoBLMRvCKySzUGzYGt9fcfrYGU0yeNxrBAOZF8NAU1hy2ozKdAJPEAMDCeBzjkJ
PCNbi2eEGk1jGi8P0s3Zo7gEjBcmIOK9ba8KJcRLHHpt2rQWB2R3JIpRRL1/XNJQwoKgBQLLsCBH
C1w1kWV/JcUFBJYNGKEnmR+/vA2eXNROnluvS6wpWQ7CeLJ8AuI5nEwc3EmbyDNxZs3opJPgHkht
mbPfeXr0l8EMXDLGC2HUZAtZx1ApE96A/v1BsZIb0DzlgChfpsyTBQqoRpLniTyMnPIOLJgXGet9
5JKQb4cuV61K1Tq1a2/bGqUGuwymKD2E9Axc+hm4ZIyXyD3cItIHDlNFBF4v6BNGS0Dn3Xv2+Nuw
Xv0QF8MKKlWE8jcRimXaNJ43fMiAoaIQeFeI/730j5vuMT0Dl8cMXGLGS0DJ9k7SYJJd0kKxpjSo
X89XyWSLFy0yacL4qZMnVShXntuAVGzauBEHoH8ay/YXcmCmue7yII/0KP5bM3CJGc8wQxR9YB6a
Jy8f/zhnQ/Wq1TgY+MS5B2r4r3JlTvOqVSqrSaIclwwuIuoyWC4leP+/9dzpftMz8IHOwKVnvNTH
SQwSUJ2SK4p2le5TZJ0SsIIS4EXomcrHnbZbXE4JET7Q95K++Yd8Bv67jJeksnkn82OmiEvnHfiQ
01n68bLMwH+X8dLTnZ6B9AycdQbSjJcmjPQMfAAzkGa8D2DS07dMz0Ca8dI0kJ6BD2AGPpKMF2w+
mZ/zmfX31PhdO0y9eXbkZzgTRWOkZD4+V5+Z+Zsv7SDf9SnSDS5mBnI242VHY57PXCDULBe+61WX
FqgZYOXJJwvvqScQygBHjBRVs36XD7R3AjJVGyCN4X63Cbssfs/BjGfoEpCJJFDDxUeKlMT/fu5k
95oJVgLR7tipk7ydIhICDPqdPn5dvWZNz569xDGcu+V5vlIDWLN6jVwZ3bt1X71qZZY+fVVnr3jx
ElteeeW8bnfqpIrNhvf88y8YQMoacbqkxHkOLN3sfZuBHMx4KEwAqwKOii0LxpPWUshcVAg6qFyZ
JXgcJEIgZIuQ4EwyCFnJfvXrX//gB98XOBsQaoFkIx0vviTjZCxNVFFWhW9BnE43yKLkwHGYxDNO
untSR+WMWhnRANSjEkAo0k8JVaWJw02TSkO+CtuXSDcpc5tUPgoqaBhYUnbHVxVdRB7iPceyYsvY
LWGhXqU5DWWHo/7T4IT3javO40Y5m/EmTpz46U9/pkOHjmKO7vxXVEoS9jr1kYjBKNleZmklxA0L
qoghupdmQq22lzdvUhA8cNHevXtCEuhUPsSD5OquXTvXrn1exs5Enkj+Jy1nKr85Vv8tFLIy87hF
bbTdu/YEvTF5F9JVSMJ7y5/+BCAu6yGJnSDsDr75piSBcoS2adNGVC9MuQhj5cdSxyMDm7sEXtW/
TG6ORQkKXAxh9YraWVNCugqRh4Lyk6Lt50EP6Sbv0wzkbMZTAfiqL1wV6qdLMi0aXeoHRRQ6deoo
64TUg+o0pJZN10w9a/wp5C9hIQc4UCDS9773vWu+e43KktgMyrRixQq9evZUJlL6sxUrlovKFeCL
GYoUKdy9e/e//vWvxKZKLC6H9q5Vq5a6hJLJ537oIdyC4nPdd79q7IqDFi9WLMTmxlLq5JEjb/38
pz8V6r569ZrTYvP48c6dOunwW9/6drkypQ3v61+7OveDD6ru4kYyd5LkkkpJhJEvTx55QQUZlyhW
TP4YgcUwd5s2bVLYUZZeqXu///3vKT4uf+GggYOUQZUlTVpR9d+tGmmZ9z5x1Xnc5sPAeKHcHBnw
6KOPUgiVDZMB6ZOf/MQd/7yjR48eGC8p3aORDLyf/MQn1CVPpJCDfn37OVm3Tl3JNr/whf+rXKmi
SPZrr/nu16++WtXyBfPnhwy5KJtodfBArlwSY197zTWqr7BnPPrIw5/8xCeFIFavVv3jH/+YMoCk
aL06dWfOnKXqqqroI4ZnVPQOeqngep1IAwMrHmSsYoNXfvJTTxV8UuXuaVOnafCpT35SNaUuXbpK
gla7dm3Z5tVzJ6uxk+f62BVXVK9eQ5JfBd+HDx9uYPJ/eljppG6++feSO+XJk2fK5CmVKlV2F0XG
W7RoIaY+bXc5D454n5p8mBjvP2qsKyA+/5l5aj5ffbWK25EOqSxoQnC+ivdD06rUZzBeJAVOPPro
I6ovBKVOaW+UunHDevJHnukglDCeXCxKN6qy4kCKNCextxzvbx48IKyesMWBG+NkSnZofnVepRZK
41VXXdWkcZQGNxJ48Rpw7NjbzCo33vBD7KcT8vbJgk/qYf++DLy4pGxqNrwYB+Cr7S6HmtxnNrHK
EjnTrl27r3z5SwKvrA62uPICW2vcpWfPnn4lLV3L2uRY9hqrg7ymqXd/nygrfZtzzsCHgfGYWBAW
mlZ73gIvhYQg9x/dcOOBffsz9MlTGVusQJfIXXhuJCIzjSKqnP/5z3+Wy8zJwk899aMf3Sj3EsZT
uzyD8fr1y2S8ufKOKccZGO+mm26SEwnj/eRHP4qDel/A8HL4CryQRRffyu1px2XnmZB+YoORWub+
++778he/+NILL+bO/fBvf/tbwjncDuMRtspq40kGmEJPPRUYz4LiV0kTv/XNb0iJv2nTxm9945tN
mzSWoA3jqVTuV1U+pc1evSra48ntfc13viNxcHjYNC9cPjPwYWC8efPmI6xhQ4dR6iRaJ0/y5817
w/U/3LN7DyqP0hYpdRJ/NGPHJxBQuaRjEY3LOX/0aJlSpSXefHnzywTSH/7w+7/+9dZXtrwsXyCK
PyvjqeXgvLydzCSB8X584402cljl61+/WqVbumgkA48fW7Vq5Re/+MWmKRLPSfUkQreyHhqMjEw1
alT/3Oc+F1JWR4zXurXx2E8eOXLkhz+8PmE8i4JfW7Vs+c1vfF0WpsB4zZo2SWU8aRaxuiVAyy1b
tmhQpnSa8S4fjssYSc5mPDsi4uuvf/ubRJ0sCtgAsSK4B+6//+qvfVUqaHn7ZNGcOmVqEDiB94TC
f+ELX7jh+uvt3277+9+nTJqocAIr4q9/9evb/n7b5z73WXwlv5hUgY89+kjgBNYUN1q0cFHY49kK
Okmgsce4S+7cD3FoOOAAkM+ziZj6GjVtGnPlyvWnP/5R+9o1a4YBUDTfOnpU1m2bwwceeMBmjFDl
+mCTNE7M9uCDD1WrUkXCqOBOOHT4kAd5/NFHidNvf/tbIUVvwwYNlHRWHWXd+nWf+fSnpfpUJ8xd
OnXqHD1dr16Ob/nzLSqHSvL7y5t+oe6KwkZvvnnosqO+j/CAcjDjRX7t1avLly//1JNP2iMxLXJh
oTx03LdvX5aSw4cPod1ixUvIlptpVMwogrdkyRKZJvLlzVumTJmQoX3pkiWly5QhWzjBfN2/b7/k
1gMHDoom6NSpRYsWlStXzsZJ/s9y5crLFoOJevfu3ahRY0qgBBb16tU/fOiwnLlVqlRRBkwy3BbN
mxmXHNgMnqHPsMezFRQK7KcCBQr26N6dwyNTFK9ma3niiTzdu3aTSLtq1ap6s+1knlGDRQJCObVl
pqEvsr5UrVKN319hzWrVqqkiZmDlK1ScN3++rrgWWrVspX9Zfd1UGaZiRYs1atgoLpT77jiYjzAv
vK+PnoMZLwvwKoim4DtPjsNBIu7iqWVXzJr8L0tXiWxMlZOOQ82jjM5jX3y4Y3KQfTazDCD49pOT
KWPOejK6XVzMPdtdMu6LiVNulzGwgBA4PciUeyWmnfeVvtI3e4cZyMGM54kCICP5JM8YzoSv72RU
OPdVSedJJ6kdhuPkLllud8avmbfJMv/Z736Wx3mHu5zrdpmPnPrUqe3TjHCZzEDOZrzMScyE88d5
ls49s7EkOXviwFAUNsiZiA1SOzpxdgY+U5ZGl4QJvbC3G+RbKt8GGXthvSVXpfYQS9ywZFxst9lH
FeT5eRpPo3m+yAfLyZfnYMYLalXMJxnFzVNddmd9KciCnVAi97MSDaZl6oTw0HOis6WSLzY4gxmh
yQ4dCkBKn5DS9+jRt0DMLmA3hR/Azdhgjx59O1Bwklz0+LsFKZxDpgW7bpZBBlY0d5eWdJN5i5Lj
v8MKmDHUeInxXJd2ADmotxzMeIYu/bsqPw5e27Zt5MiRGStuCj1loUgvm9Fvfpy7OnlJQcI4M3bM
2LJlynAqRILr5MlevXoqmB54+9CbB2vWqLEmNpkmOiFoJQxXEhWhKkP//v1nz5rZqWOnpNlZNcws
t05t075t29WrVrmcfaV69erlyparUaPmwhicfVaqSgafNIjQ1plNiTWrABvpnrgsWXhMZiR2I3lM
zd5Zx5mI3NN3jKYoQ7s++zD8GkmwE6Bt3bt1MxWhWap+Hs6E/ScLsLLyqswT6HGb00tA/MoybhId
XerV4TJhzhzMeN4fFOWwYcMcrF29mjkxxazwH2rMGV8zzQwd2rdXF8VPQeVKbcNEmdRIQQ4lixd/
KNcDwavO38BTFy5MPvsP7GeHJD/DGX48BlI2RgX9UpvFq39Wm0pQa8MnlSKV5gRDcRICUywSg+2L
z78AL5baONFmk5PPPPPMCy9EjrvsHzRdpnTpBPzN3aLPuXPnrl+/HtLgrFOUejI1BiI5HwaQxZAT
fuUyZUNOFqPs42FP5tv0yM8tXx6gQhmTQPU9ccacZJmfy4RhLtUwcjbjATEHZti6ZUsokrx27RoH
EF4onS9B4T4FjJT88ZxDnh4CzIXspPcM5G55htKEhLT245l//ON2QOdDh4CJT1HzlLYtVrjIizFB
k5PFihThxHPVwAEDXeK+Rw4dIiGbNWuuOBmfOAwXMSUdfdPGjV0yccIEjgTgSb3Fmt6pdevWqT0G
WaLw2PbtO/r169+sWTM98+D79O7ZS4F1qLckGogDoGbNmkYCitm7V2+IcEU2ZSilD/MouESue9Vd
DB7MTb0xGG6xF9DhilhzpZByXO2G91SBAkHi+bRs0Tx1+bBqqJ7rcaZMnkT2zJgxs0uXLk0aN546
dVrTpk1HjBjBf6j8k3irnj17jBo5yvysX7/hjTdeBwQ1FRz3oS6Np2ioEsaYsaIlxowZy5uiTevW
rT2vmoRmHgZ9/LjxO19/49FHHgHdduHE8RN4VlauWKGUd9u2bT2Xik5eh/cFgkPfBtCrV68e2Pdp
CXipqP4y6CeHM16PHhxxFDz0V6N6dZuZmjWqL126lMyZO2f22jWrVSnqipQ6d/YWoftR8MO5c8+c
PiNQ4YRx413F+6wi9IplyytUqICybRTDm27epInqYoMHDrRjaVCvXtu2bZC4gs9g1oLcSpUsaWnX
26hRo/jxlPJbv2FDsaJFpk6Z3LJ5c5KTgrdi+Yry5crjk9Dh2tVrli97dvCgwfh/1apV4pjokGTm
ooULJ0+ajDQXLlx0/733GXO8LpzikYO6tr/DLerAvPzylnJlyr7x+uuulX57wfwF4h6sC5gN0UNI
099g06wOHdp3oAh07NABt4wfPz7XffeFrMH4X83QLS9vCeuOvwL5pPQGDADIVtUMB5olK8uDDzwA
zlr4qULLly2/9S9/GTd2bNHCRejVVjRTQWxWr1YtWo969hTN6NdHcudetHixsocWl7x58ryyZYvG
vKkrn1u5bcuWObNnqZgtOmnDunWtW7cSh4Eb8z7++I7XtoOzzZhuwO29JrgfRUsVG9W5laVooUKe
hVj+UNpgcjrjdcc5EydN4j1HuC+9+MJDDzyABIXwwDELz1F+CCwLir9Pr17oA61079o1YTyiaVG8
fVK62RIuvGD9+nW+hl2HIipCSJX1e27Fii5xmQegUChKQkybIUOedgv4LMoVE0uNaAe42r0wXpvW
rYiRpwoWhFp+5OFH4mJjERR7z569cG21a9dRBX41aRzXW+ccVzJJjaTFixZFEql58xXLl6cwXjWi
28Ixa0a0WACg7Nq5U6Q5BrMXjW8XgXKQOEf53j17H3zgwU6dO4uHsvRUqVgxCDq3c5UDXcHQIPqE
8dxu7uzZvpooSb7bt2urHwjPRvUbOFmnZk2kryq9Y8vX4oULYdAUuLeiQc84CbNqVmnXVA9fmzVp
GuEQSpZc/uwy/JzQlqXNSzG2DRs2KBplzHTREsWKLlqw0AriwmiJqV5j+fJloVvIoeHDhls+Onbo
GJaMJKLyMpBVl2YIOZ3xeii57sVs2bwZHYPzI3cUbBexbdurVStXUbeoV4+ezZs2xVpjRo/REouK
QI/kXUQoTYT8OOjTp09c46Hl889HdTAD4ylstH7dOu3xtj5Rw/Rp05FmYDzhORivdu1aGI8hVJsM
xpscM17/ARaC5cuXr1m7lh2VukipU5hFvomhQ4ay06xa+Zy7h1tPGDcOPwcLCjVvxbJlWRiPNJg5
Yzp5VblSZbqfZPj169XTZt/+/YSneHYYmvnz52G8fHnzzJkzd8WKFQBlFcqWjRjv1KmK5cqJMAyP
3LF9h4DwDh86ZFC8RTnFjNeOVCf6LEmmgPoAc1eubFk6uQr1JDPgTq0aNaSrSBhPKv6pU6d4Cp24
iq2rdMkStsTlSpdW/dNJJRCB4BYvXkJXN59DBj89bep0ANfiRYsuWbS4Tq1a2hi5NWXF8mUe31cQ
9rHxy/JyK5YvB/j24bOw5GzG69ShA7LzhtauXmWZP3L4kIrQY8eOmzNn9tZXtqrCZ9OCRqtbpNeu
LVu27IwZM/55++30yUB2djIVCY2pU9lRtmx5GcosWBRjxjtRvUoVYT5UtVtvuQW5d+3WbdLESRiV
MjZt2lS6mQiAu++6i/Ylao5eR1oWK1x4wrixlDEaoOKbtCb/mBDYcWzkShYvMWH8BMTtdkgzADi7
dOo8dtQosbyRfjVt2t9uvXXZ0qUx451EjuwiMN842bpgVJUrVcLSipm5+7atVLjZQn7bt21H4tE2
d+/ehR/69+s/b94zIoawa/v27QcPHqTEvP1neK6tW7fBqhmzqaDaPfPMPHFStqYlihWn1EGWkdgU
h9o1a5gBxQynTJla+MknBUlAfs+bO4eSSQCSe+Da5u3BXLlEA5oiMln/BrZwwULMbxMrWMmiYAJ6
dO9mxZk/f/6/77rTRprMr1O7Di0gz+OP7XzjdcqzXZyWdolUaOuXfhg8Bw0Y4OmETRbMn4+4jhnv
Q6Vy5mDG8yps53CUA+YTlISyrNYtmregpciqYLPEQgDfGCwco0aNFlBDY6RrhU0XKUT+MGYKnGOn
mz17Djt4+IlWNnPGTK9cLDnCcvLZZ5996aV13j5SYyBhGGRIwIrdunbDdSLfhPkISF+37qUgEl2O
jok4VhDCSqcvvvCiMtQDBgw01Fdf3Yaw3IcNEwNoMHjgIMF77CUqchqAreabhw5ZGt4+dgxSFFc7
iSXQqBxJrvUULVu2tDti15HsqEWLlhs2bIRWpTC3atXKGYKCqta5c5cRw4YdOhhbjOJ93Yb1G8RG
NW3SFOLUyfA4OjQDwiNog0L4bWbNgOAmSw8rCFMHcaeCvFgkthn9WCMYThTTtsS8tG4dY4n2Otm6
9ZWxY8dQHQ8ePEA7ZXbasH4dZcE4hw0dynwiSNLwbJLhV60pONBusFu3bpCufsVqfBI0BTrLwAH9
CUD7z2gVjLyCaca7NFruxfZyNhzjacRjlhUlC0IyZq0zai/7GsRgGFZG+0x3Q3J5oN3wyeKxSAFy
ngZwRs0yP8mFp3vIhJVmsdpnONDjeyV3yfII2Xs7x5nEMJh9HlIGkzF7wcmS2jLJCpM5RWdBlqZ6
F7Iv52cdW+pkJpdk91KE7FUXSy6X2fU5W+JdZpOZHk56Bs53BnI244WlMDyDv/+NdfG8nEjvgOTM
/hKMMAMReib67Hxf17u1o6clYiQW25dOUMT5qoMwjKc6gqWE40QipaoM7zbSj/rvOZjxImTgsSi5
nWc4cvhIAApeSlIL4XMAlJlozOzE4tY+4dbnRUoxgIad8xwpn0Of59XbmY3CTlL/zDkh7V8MXr2A
ns5ySUawVZxEmCE3mvaTMqYd0f2xY8cxYvxconwjS+alueWHupcczHgBlGxbz5gmHlQmr8R+EA4C
BWecjMD4Z5yMfsgkkYTQkwszcsyePMkAGNIohJkKxJCx0mceMJ8wHjCuhPMZvUUwwwBFPM1FbJvA
GdBtsgwi3+R2qaPN6OJsMUEBpZ3cInNIp/tnfhRcW6tWTaCZZc8uCyDIlIfKGH/2543Dfc/F7R6N
jy6a6qpVx4we/eqrrzVu2Ei0LjOmK3kO1LiHs6lZs4Zmad5710UjBzOeoUNISIk3e/ZstjKZS84E
QJ6BwwxaEBRI9l0+MRkLh+NhLlIrKyDFjRs2nC4WHRN+zF0Z3fCYAXIxq0iORBSkdp6p8sX6WCa7
8kZwasGy6DbcNwnbTa6dMGHCypUrU7six7MPO+PNRewSc2PMj107dwFzEboOxsUgmfJ2U0N44+Cj
TANSKmDVc51VdOtH5l9wNu51YLfXXnuVvZEbAGhG6he99ezenbN029at7psYjd+V+D7KDXIw43nf
DOuSWCZEiWgGDRhYpWrV3r37HH377aefHgLhIWPCqBEjYa840y3McICcXc2aN2fdrlql6jPPzMUw
jPi0MokkeAIgs6Smrle3Hm8SdPLokchr6759e1u0bFGrVm2+JmEQfG4w+ERcseLF//WvO3E+vziQ
NN8G1JVkDbyCL7zwYrt27bnRIdpwV5hoRvmypcsEGyZXNe+WA64tcrtJk6Zt2rR9Ye3zd999N+Al
2z1HWeUqVYYNG+7K0aPHcJPobeTIUXXq1DVgcBl4EYiZkLrChx+iQrnyQQ8MH+tRl85denTvsWPH
6zzgnpcj0Ug4SPRPUXRrDhjhFJ4XkitSHUMsYmYPiYQ3G+pMJD0DAwG7hK98DOXKlnFt8utHmaPO
89lzNuNhKlnDYrmBlE/xDpUvWxbFYwzwrkKFCtG7+HaLFi4Mc8hxDOj477vvHj92HLAvyCVvFXyT
NZs/2n6Ok7pr5058g8CNWKhK5SpLFi/hXwawhF8BziBDZKpdumQpkQKECc4CRgzvAh8t1R9S1icH
F6xww/r1YankJuKnKl2ylFCARMh07tTZ7dQ/AVXhsufyMmYAK5UPeL2xE5TzyBEjXFizeg1eNU5z
maQrV66M1qGN9UnMQoE8PWhw6VIljYTHMkhX4+Gdc2DwHGikK6aSahrcxIVgJc57XoPx+Dz4ADe8
4YSYrE3AAIQYn57L9cbDKdxB4plEVjds0PD5taejoghtqVy6du2q/arnVsLKOjBmrsjZs2afW2s9
T9L8cDfL2YyHVp59NgPn4cVDPwyPBSBHMEhHvbp16J8L5y/o1qWLkyWLF/NVPAHUv8zNI0cMf/Pg
m+XLlFa9AJoR40lSBPW7bNmzUBra8+pOmzKldq0oHK5i+fJJqAuEIfRJ7ty5582dC5gClmkSixQq
TGpFAMW4aoIIicGDBgYEI7h9iPSJfcCRrLMdhbDhLyaCpkyZ0qFdO7gtTAuo7VeLBeCVWz/84EO2
jlKhLVq0MGStxYEtmjXXpnKFiuDaoGc4n8pK3YwYYOWqgOR6bfv2jh07YoaNGzcEMKSFwNLjoG+f
vqCVXNjQBWRUtapVwFwAXPwEMSOeIEgt0ljaX0tA4EN/HYen8DW4+PbvP2AAAGh0yxAa4om6duma
pFT7cHPORT5dzmY82wxbi0TDGdCvX8h4CQMFMIUa1r30EjgFxsMMJYsVI5QwHigW/iRVYD6gojAe
vnLV9OnTevXoQRSgS19VCALdYE4gScqWKqWyl5PPrXgOdtGODriJXgrKGKCPgPwEkRgCE8qiiCKH
Pj0kpHZu0gT8MuCeMwwzjjEerVI8IY6dNjWKbNq2bWvZMmVF2UgyLawBOLNK5UrSh23dtk3RH1wE
o+zXls1bIHxISLAsWiGciicNMwAUTrp6HMe2ZDHmez2hGo2hUSPASAc0zxnTpoO/gNFE4M+KFa0d
rVtGz2t9oW068AjgY8IvILaC7HKSug5ikkx1OLCQlS9bThAQ/Tlgr23zwMqTh71I6vwQX56DGc+6
Kw4I2M/mR6wXzSpCSxYtKmyMQkX+UNIYJKOok3btAK+ezJ9fcQ9qJ+Ai/oTWlTzTV0GiwJODBw/O
ny+/JNBUTUod0rH8Q3VCZgLv2klWqlDRBgnErHSpUsTUww/lxqgLFiwsXqz42jVr8z2RBy4Z9kpy
S4AskmrihImdOnTUj3BvgwkEjSswqruDO9tbzpg+TdkgLI3oGWkMHnga4llsgQgAjya2TVwfM73d
ncD5WKlr4MFJb2OzaxXWoDxQIHR/NS5SuPBo4Q6t2xCSJCSkuPNw4bZ/IP+lSpSkb7OFkI1AniJ9
4dGo3/aQ1atWE0aQdBVYK5C+kZtqwFGg6nHjxi1cYCzP2OtaDlh9NbMdtYKYeboAqGp84SXyY3xI
mS8HM17AFqlZ1a9fX2YMUdi+KpwgqjJKanDq1Lxn5gpPhVoUFcZ2ggPZJ2logkRffPFFOx+bHNs8
+5nVq1d16NCBGAQRtPvCJ6QKsbNl88u6xRiWfVYNbZCySBlCxoZQYBty7NWrN7aBzHQM2ElRpPFK
aiAsdeXKVZhEEKBqdcEHsHvXbtB7Ymfzps1GawtHAut8/vwFbdu2U3VMG/BuDYgOGE7PhVvkcdEJ
eKf+RXB7cBuzlSufAxPt06c3QRfkUtAAlyxaRFZ369ZVnmmTYz2KvJHHjsFG4gpD0obMpwaDU5PY
rP8Vylc05kmTJodOEmZLpfloqnfvxmYqNwgFZGSKZmzYcA6MYJ59dslS97XrE5KX2s+HlHEu9rFy
MOMlpJboP6mQwiABsvwUnjb5KRycFQOZ5WTYRGX/pE5flkQSoXEqyDO6XYqPQ6g7AcKtl9ptAhk9
Y/DvkMbi9NPFZBB4JvsgA7onOZ/l0UClGVTDr+dgmHMgRWP80BkOj3DmYmnzQ319zma8nPtqzLtN
XefOnXfv2nlmIsH3+5nYReWcjtj2PME37/cAP5z3SzPeB/Zes8irD2QciWs+QtsdT8uo9+8lpBnv
/Zvr9J3SM5DMQJrx0sSQnoEPYAbSjPcBTHr6lukZSDNemgbSM/ABzECa8T6ASU/fMj0DacZL00B6
Bj6AGUgz3gcw6elbpmcgzXhpGkjPwAcwA2nG+wAmPX3L9AykGS9NA+kZ+ABmIM14H8Ckp2+ZnoEc
zHhxmscMMH5I7hhCb97rS4WZDLMQgIuOU+H277W3828f7hINOyOO4fSlIVDg3J8kniCjcQhNCBkv
40+YkPiJMrJZJ8EZyU9JCEVSFDI1ju7MsImMyQkhF8ktUoeadBs1eIfohIxHzoyWOOszhnGeT3xD
8qbC857njL3b1L4fv+doxjsugaRMOwoehPcktDQqzfMeP+LoJIOQux9QWIidIL04LewJGUfE1L1T
6EBCxO/xbqebG3AIKfQ3yTLkZyvHoWgw70hGgR/kL1IpQfomyQX90YnAQtmZMugvypwbLUzCC50P
S5IDl8R3PPHWkWjqhCbs2bM7JErcs3uvZ08YSdj7jtdff3Xbq8IRpb2QXdRESQkTzU9mHIObRj9l
1pR3awUbBPueIywoZHPzV4LAqBTz2RbKI6rPHDoUErqde3rdyPOLAIwm8JwgbzdSP1C5lQt+X5f2
whzMeN6KkiCFCxcpX768mjvmRSEuQdlnov5Px6Elj5p6gAIkhhg3Zkwo6dy8aZP1L70Ueli6eHHd
2nVioZqZqTqOxQ5SMdBxdJz5axLzFjFPyoqeiKZIIsWfRFxYo5VFkU9JHGo476/g1Hx58qKSs5Kd
k35Sk0z6oxrVqklmMWTw4Pnz5rujNCoSioWrYu49JEGLHBOK9QiWlQRNLgwJHUJ2DPHjhQsXln9T
7LmvIoNKlyotq8XmzS+HB1RJS+2X2nXqlChRQj4YZ6Q2Gz92rIygoorDg8ho5hYh2UT4KLckv2Dq
Y2al1xMnhSM3adRYfoCe3Xsk61d007ipg0mTJgmxdZyljkKsz2Smr86czEOHolJ7wurDTSPxHmVJ
y3jvyd39pNRuwwb1w7u7tFx0Ab3lbMYLOeeIK7m3vH605aVaBRFEyE0kdlu0NbKTalptGhOuio3z
cS7naJmXEkKWPqm+oguPH1ezTra8kKlOqhW14MK6G9ggfFSl079mqhxbm8PqLhDbT/v37Uu4S/0g
vzqJevQfsu6RTqFlLO2itV8AePWqVTrG6YZcK/+SxJsPP/RQKKyV5Y0GaabmkdQS+MqodCv1g1QU
0YAXLmwYF5TMYOAZM2vXrOUWEq5MnKh82Fi50qSZqVi+whtv7JR/dvLEqFyZgXhezC+4XslISdNC
D+5ltP6akwH9+jspnp1AM11uahyRgD1yBMWHUuYmXz9SV+jBGwlBydnVPyeV1FMQk9Q153oIExjl
84z0jKiQ4N69+6gbo0eNxn6+xm9nj+eVsjp5F5HUlUj32DGZF4sWLqTCkZ/27tsbK9sIIJreAwf2
hzGEN67iZ4P69dKMdwHLxBmXmE35C6QeMbOWZNXhlFaUXESevFo1a6urLNeY1H0Ki1etVk3qFOWO
K1WsJNlJqxYtJUeRztkbVU1WZjuqZs8ePWlRsnFpQ0qowuU91aldS+eqz+lNTgdZfVSQrFatuvSY
bVq1/sMf/oA4QqJOmQUlcZHQWvE3SVz69elrRVfRynIg54ocKtu3vybZniRIJJWsE15/RGsxN0pR
ERjPZ9SIEf379lXQTycJC4WfgiClK6q8l5o8V5EwCSw0UNFSTdbQ2EdmJDUDpSSUr0VWmKaNm4Q8
ufILyq0iA0WD+g0krUDrMlyE0sqknPRHFqkgE5yRu1YiI6wlHYb0FmHOlYyVRUJ9eckpLAFS11A0
ypevgLFNmhTD7qgs4e7dewIDJ0MKfbq7BIcmPzChrKS4i1yVf0lqDPM5YcLEAf0HFCxYUBHZpc8+
a3klq/M8kWf9upeGPP10hQoVpcawQjVp3ERiJSl0S5coIfWTZlKqCuo/8tYRiVUVnY5qa0s3HKei
qVSpcolixcx/SO59scR30dfnbIknKdgTjz/x5JNPNmsSZbZq07pNvz59LN5UUDm/VCr2RjGVcseo
TQlLqY1e3rzl3rvvlgTJu5w+daqcJbNnziI6MJu/UdHWoUPkyUOyVE2aiaRjRJAstxUrlKdrPVXg
SbLIvkKbGtVrWEddSNkjHCSHxhV66N2zR8F8+W0nsJZ8gZhZs2NH30aO8rXIfSLlHiZKDANy+6mw
afwouE6t2mR1tSqVSYNAH74qE42BQ+72TZs216xZK17Io0IRDtq1aZsnTx6FKQsWKFi/Xn2XHIlq
J0RqcMkSJf/fb35DvURrmPmlFyMt2pDGjBqFQ3AsQmzbuo1nlKEoqJdlS5ci2SI+jzvv2qWzTDAO
qH/9+kVZKnCmCntPFsj/zNw5tpSFCz2Fc0yC/bAMn1RN+UtlH5UwSh7BaJwnT3quSZMmWhnDE/kr
d8uTBQvKoSYHXKsWzTdt3HDHP26nvCycPx/34u2e3bpT/vv37xfeoIQuMhpa7yxnJtYyKjna448+
KukbSViiaFF7UfMvMWmp4sXVpldfVvFtSdaktLHLxefyXHl98jgaUprxLmrdiFZf5Ua7dpN6VeYv
mpIcRCqJSuq65eXNqEeWS6RJF6JxeT1jxoxWAN3uR6lXKopMW7Z2gwYOkM6ImiR7LD3KCrp540aq
qWoMC+fPsxVR1TH3Q7mbNm1WuFAhRRLpdWQdBpOtCK0bg0xbJFggTYmrH3n4YTk7EZbzXraRyDOp
6KQslI8+/EjtWrXUHmgoU1hmfRUXSs2E2hy0bdO2atVqhC1VU1KjIB+sDldccYWFIFAMc0iF8hVc
Hudgjxp0aNe+b99+iHhklIEvSr9ZrVpV2fgIfyPctHGT7KOSiNKyQs5pOyvFn4MUOnb8mOxpshjG
tZ2lEjtcoVyUri/6Lb5X9WpVg248beq0wYOj1NG1atRcv36DdKO7d+4kssuWKW3XJ0116HDNmjVk
jgMZqCRfDCc9nUfo27t3xM+ZezNZp3DF5s2baMKG59WYW3J42dJnB/bvp8w19Vj604h1T5zUZt2L
L9FuHnzgAVkGZVKTetAW14pmybPHw3gjRgwnAx+4PxfhLJeph2VzkiLR17pxweeN6zeEEtNpxrtY
xkNDiMacyq4Z8md6YWafUkfJrFq5UmQ76drVrlob/IACvKeqFSsxYsppOX7cWGqkjF00N/obxtOP
VJxv7NxZQzmO+fMaNWgwYfw4RPnmm4cOxkVV9UO9JLJY0uSx9tW2SlXUtavXlCxRwg4K71GfnJcX
jG4TLrH8Y0V0tmr1qsM0uSgzV/RJrClKk2um7rG0fOq8/uWWW9wl2HAYFSWcJaAsGWHfZdl+Ji46
Gz6SF6JCB1jOoqNz+iHpLb2f3KHO+5XUtdAQtr7Wr1sXe4RryZMK5ctZODz+sbeP4l5LQxBKfu3b
u0+oEe9DZ+vff4CDMqVKrd+wgagk1mybCRP6BR4IzVavWa0EswNSS20TBzpT+hxTydUZKdjRJ8PI
VKZUaZk5ZWcsX6YsPqGTV65Yycj79O5F37ZQhpkk8IcNifIUW0qsj8yqllEagc3qgf0HPG+ZUiWl
VLXAUV9NjvRNqtWSvQS4bYOnsxOJ52dZtGlPG1cuiu3ihVPuV6nUbc/oHl6YysNegL2HN03BkHOW
Qvj4Y4/LZCklprIKFmbWDUqLNyd565hRo627pCWZwDxDqWNIWPfii6+/sZNiJnlk3dq1WR3Z+qKq
3IMGIg70pLFcsfrPlzcvC2SDevWdl41PyXXcpZ/evXrTyuyC6I0SUBIINDELBIlE3EkFL5Ulug6G
h4gxZsyU4jJhJAdVK1UKxqFEPjiOWsfqn61agXz5KYoeH/V36tB+aqzU0cQ8e9KPgsaFnnrKgIsU
LqLWNLovUbwEg1CdWrVw7zNz5lIWlExo37YtUrRm2Z3KqDtz5ozQA6lu6iQvpKiTyXaMZL6Huutf
/6Lu1qheTRZ3/dDeLXOutQzhwCWLF4WEtj169AwSL8seD08/v/Z59lL8Zj3yq+LYD+TKRQexajxZ
oGB0bfcexKORFC9aTIp+Sqkq87LQSwFM0bXBk5rNg5PVrFk8D9RL2RatHfJk57rv/pjxmq5eufLA
wQMVypbDqHazkhRbGW1D9J+WeBfJeiet0CNGjLQuBlMEFUj9ILttTIi1qKCUfsV3hg8fMXnylI0b
qX6bvWDrPdcTQqRKIeVZs2exgqgr8NZbR5Xz3r9/H3cg4tCnv7qVqdZ+Q4ERAk25Dx2+eehNQ6d5
yodp48SAqdkLz6+VSRZXUJ+wmeyuVFbjkQyXuT961LhKOCmEaJJ3H+wlEmwmcxHl+Vy1yvbpbPQR
mf/ci3mDP0AaX5TnqVhuULAkogaT9KMZ48eQIUNtdwMvrVmzdsTIkbt2RuXEJH72UDNnzjIhhBLz
CTvTM1G6segT7fcOHpRp0/RqRvvVP51NNls7KJZh02WG5cx+bsUK+gLiHjt2rLoRJs2qpzG3xGvb
tgX5lvrx1XThEzMZKxEnvaOQXt4uMVS091pf3vwyFXfixEkyoCqDYdiS1StJz/eowAMlxcbPezRL
VlJjsAQsW7bMhFhq2V3pI5HJ9OhR6wV92DFXkzdInblYmrtE1+dg40qqNMiyssZrWkoKyxRpEq5K
rj2zslesAmUa9MJFqQt2SjcZtofkzFnzYZ7RPsW5Fw0ghR5Dsyxn3tHwdmbyzOT9JeNMJYxkAIHt
U0abJQ3m6WycyeVZKIOim/I4mbXHYqUxOw0lg8nuToi4OqWj1JZZJjx7t6nzmepeP+sYkrechU4u
EeNcbDc5m/Eu9unT16dn4AOagRzMeBbLZPRBOwoC6lLOZOYtguk/rLJZbhCt2SnFYrNInowLM4Es
rk0VO6niNFEss8jYLG0iQGnSW1yJ/Ayxlu3howk5w5OWkez9vc5SIo6S580+1Umb0HmQOUGSx6PI
QKWeqUecgYzNuCS+PExdxtPFVplU8Z78FCpsJhpH7IS/pDTwXmfq/NrnZMY7fpxxcssWxRG2ej0H
DhxUEOHSTrqXGpATsQUyep1gK1lqptIJbTDsKjOoTZVwu59Dh8LXBJpoJ7bjte0xnOKg3SZkhjH7
avuhyMGGjRtYU5JLbOE2bNjI4geWoQ3XCD+4j32XF+Z2Nqs2OTjQ3mzbtlc3bFivOOtZnz1GyBzn
e1SyyxgSpMj5kUdGK0NVOMVGLjx7BAw6cCAq457Sizb2xgyOYRjhjRheJuNFLGQ36CnswWxVudft
M5l4wzzYHJoFM2OEoddQKzce+UZmEvMMPrpp8+bDbx6KqDae54ALDcgyW2VTcekX3/c0U+fdOAcz
nilmqCxQoACsCazjunUvhepwyaoZjkmEQAepP6WKytS5ymJrdgksCNe58wiCAZBlLwJ2pIC5tOGL
Z0EN/b999K08jz/OPZg5jKikEeM7uytfBXplZgRe4dTmxEdMjgEs9PB8XGndYI6+fZQRr06dOmXK
lKlapTLjQblyZSFu6tevhzIxKkc8MynPHuMNFEjevHlq166lxhBTx1nsMXFNJYUsQXaAeEKxsWha
4k+4Y/T3zD1laj/hF2WG2HK13LtnjzEbQ2ob/WGApwoW7NGtW+jfje6+8061BMMtNN7+2nYGZC+r
R7fuVpAWzZt5BP4DDIMhlWoyh0yj/EChZxeqjlKkUCHNmG2xPb8O2IqZdIlnZyKGEIAo0nLRosWK
GbHfqj2YEMB5c8EH0DBnM556yEyall44abYvrlXIzEgURNrYKedB+EFEYmo+xueDaKK3EpePVXkH
XDPWTML6Gq+cQb+JpYSWjGBPFSjA4a6BGIg+vftwWwErhVcbtB1m6wL58sVglIhW+KYfffhhjuCE
ppVibtUy8inrMwYiRmOAseKWcEmtWrWA9AMnJO8/0C4XIp+BS/Ati2tykjfZsRKtHhlqhA09/HRW
8tEtaczUHiBabkO0sg1akAio0C3RQTQlAtOsRDOToSJGz6gSYJ5HH2vXJipbCQ4CjRlVoowrwifz
AOf5+COPdOvcOQyGizXXvfc+M3t2Mg9gesEdJ5ri6FtH98NVxvg1dcswlRqd4cIgVONhHyxetCgf
aXTy2DFOF04Lx1FVtvETeGUxeVRbs0oVr4mnbu2aNdtffY3v4aww1w+At855y5zNeKRHcKBXr16D
LbtA/ny1atYCwmShZmeP5EyFCtxKbx48wDmrUhwX9sJ4DSYh8SpGpUEFig+KzYwZylYtdQbtOeta
LxicivvBSbKOeAp8kvAqMATgRQSJOHWKpZ6rmi+R6zkm8ij+BU1wJXNeE1YJbXFgQDBpYJ3u3r37
0qVLUjknNIM+4zcH91WCjz+NX85JhcSqVKqs8BjAGvs7lGapUqVZ+XftysB2ZhHvboHTVN4MHhdA
FsLKs4tRgLHi4Nqzew9NwTKUcL4DZQBVBQuPQEo3atBQnc0O7TOcjZwf0KfJUqGN9U5XADrd4yqZ
3Bgtm7ckIWdnegWxfdmyZUBPpkyZZM6jQcbhHcFJyNOdN29eJQq5ExJG5QUh3HhKleNzkqfE2+TM
4OLHaSbcJDhP4sGaQagErDaVRNG11Mm83FgujCeHM16PHqWjaoktOUxfevGFwk89ZTvUqWMnPiLe
apAOOgxZBPFQIF9e72zunLla8sMiRE68ShUqzJsXvdRkpz5s+PA5szNAIZzOMGj2TlGlxZgqufgq
la/A+5QQh57xGJcgwIqTsKMLFixQjxaAJuqWpH3r6EMPPIDhjYpqRMKAGloa/nXHHevXrderoIGB
AweWKF4c80TdZm6QOAA5fMkiG6rRI0ciUGUrLS7aAEz97re/LV+uLJFjm9S/Xz8162hxRERQIHm0
Bw0cZCsVhwedNAlPPPYYqlUxE4DOP15paiGOov268OlBg1yVaoYB++IfD/w/bOgw/jF4zgQXpta5
KuoJ42kD0wyGCnwXqk+bDY44LLFg3rzQCdfl7X//O7CBn1q2bOV2XkeRIoWB4/bt248DKedQRDz+
bhQumTFt2q233NKlSxfaKfyDMwKXbv7tb82VZRFWRl1eJ7naoXA9CICOPv9w880BqHR58lsyqhzP
eDVr1qRu2QhZv4MONnTokJHDh9uPzZsblapE0JDQ9WrXpmpGK3GLFlMnTwKVUBQOzYnKCeQO0Qur
lS9/vmLFiou7EdngQBktQBNUy6VrpiLGq1AhqJq+gkrnzZMXTkW19IIFCgBM5H7oIVqQJRk+m/pk
li3DDz34IIe4S4gaVIWRoF4QKPBkYm/k66cyhSUgiCxADRU2HSQxaQplUi89jnEK/rXkI7hAo6Hz
ZXE5eB+AG9hIkPxAf0ailDRmo2F6EIoiafn4o4/xPnv8m37xC0IvuvXxEyJqBw8aDORx/3331YCf
btvWQz2cOzcfOgBa8WLFAn4a4yUSz1chObly5YJxIzltPufMmQPdakkqWqQIHGmIh8J4ue6/H07a
MfgIaCUtkWlEYGGIRQwf8U1hJxkdT5qMDx2wCVFeQGHtUe0dDI+4BoUNwDfAIC1FMFN26tdvkDfP
E8xI4cEv50/OZjwY6UBePiB5ETWwuAwcOGrkCLssaAdfMQ8oE5Cetw5WInATjIvwQRDEEUNZWOnh
LQirunXrQUELlmFJGzNmTFQVuUGDu+++O6hA9CUlvyPTYhy1ybo4bNhwberUqY2qFi9eMnDAwN59
ehcrVgzFJOEFkPIQzy5nPEiWc2AL28UQFuRDAQY7jqg/7KxOnoRTiwo4xyFnoQ2lC/W3Ugx5bCQb
x40dg3UTksXqNjm+Ghi8OAlJ4kER6M0eD60LHfAroCblmTRjtCDxdFi0cJFhQ6OtVwhTMkVMGsWL
l6BtstzQZgd4qN69WTUee/QxS4aW1i97vNB5vB7tJ6ysbqVKlbIAqWXta+/evXLnzq2ZWdKG/blk
yZK0DA9I/qsNGEYOj0JHTZ5C1I99e/hqd0fERQcvvqASPXEdxjl92nT6vP02DdPX2lHQUwb0lApq
HtwrdcN8ebJfzma8Xj17jB0zOrwnaK9Qu9yajbZodHQzWigwJ+t8zWrVAb5QFZ3Ei8EDUIt4EjmG
lxQ6oaAmqmY4s3XrKxbXcEwpgg+0ZcowK2T60yiNtosJ9YDVU958Dd2CUJIVjRo2omjZaFnRO3To
WKhQIbApVGi9V9O4VKmS6DW6JCreesomqljRIqxEemCTJFHhpMlnazwiwyp0SyBJ+z2BdiSAzuG5
Q4qHLHu8iPH2G3aFsMezKgm9o28XyC+uZy5IKv4sVbIUiZF6LVmHSZInip9iUbfO0f7NBzbVGpek
WkiaUfYE4yRfgSotYck8AH2VK1OO7AJ8hSZjLnYX4ExbNc8IrWpmPKOY+qAwW3GaNW4irI51F9SO
Us1oqWB14UKFCepXX32VZdhCCZ7qwWkxwLelS5acMSPCml6ezJY6qhzMeKj21ddeQ0+BYmDWoxQp
J07s2LH9jTeiRADIl34Cx4iWvTZaH20zorC4CPjkKVMIIpEjYTqCLXPH9h0Qj8G6Gc6Tb9Sz8NUL
1qe/Wd6rbqNbZ35sooiUMKqQQGn16jWsKThWz4gG2jNE6MQSZpWvhpdCLicobzwHBuVyEQDMKoLi
UGSgaY3Jeaq1Y3XJp02bTrsL9snsBBebUt8Kj+9XEl4km8gJC5PIJmZAV3GgGXMiJTws76idYWJn
9ZMbKc4e1gVTDU1JPmahJLalCP4afzSz3oVY2PAhvYULG6ox0DPtt6M68ps3G4ApJV1BQ4NETXow
BpZbQXfhwe0bx0+YCIubOQ+bpk6dRp671/r168yJZchPOcF/npONKymJseL3Gn+SXVMqeDL8mqwx
WX5KKCMxsaTSUyoqJfSTnbhDgo/TFBZGkvIJYwsnU4+zf40vyoBrZHo6znVJ0ttZB5Y6pAyBlg3B
msxYlgFn0daS6T091TGiIPtjvtM8pK7xqccZbJn5JKlskzxdWALOMXWnW0bzl0auZCfS9Jn0DKRn
IEe7E876+s4qtc4io86mkATn+RkyJEYYhjOpP1EUQuN3IqHkkosZZJo+P8QzkIP3eGd9K1QSWxf/
zmHXOvrWW7bmGcn54n180FEDa7HCrX3+ed5bEKegv9m6MKPbAs6YPoPrwh4yoBbfifF0yJDDCmLb
mJofNhmwQdrC2WVd/sa3DzHpf7CPlrMZL2Xbdhqn//TTTwe7c8xOpzcGSWOmF5462MuQC1Azlr3Q
nj2aoa9xo4YMbsAuTI6YBO6EV4oFnJlUtGW3rl1eBLOMWSqDac/cQ+pHFgYG1WRfl+w6kjFI4yPj
0OkGHywVpO/+vs9ADma8iGdi0xk8brAQbHt1Gx/xsCFDnh78tLBxDm7cAZEo5Jm5TBuNiTt2wt17
MN1eTgXJMzmvubm279jBssdCPf+ZeTiNKRwaA8SRI5v7wWfylKmSJsGOuTDOWxzJPKZCljfH7nLo
8GEeYSbQ3Xt261b2LrbNKINDDBzzZsNcGwOMr6RMI4YNjwXv0Q8+19z7TnbpG+ZgxkOv0FLlypWH
HfEiBw4YwIErzaOTeZ/IU7VqFeikyBfUrBlJVbx4cRlQgI/gvzZu2sixK5vlX2+9Fe+1bNni9zf/
XoIGPi7/eCCkypk4YeL9997L7ydjUpfOnSQO4Em//fbbpUtp2iTKJxkJq1P/ASuTGdYRcJkERDxy
NWrWBONgKBejoPOKFStyeERcFzOexpzCXTp37t2zl5Qt0Plc2AaZ1jk/aqyYUxnPuNHrUwUKBlAI
oAmpFXLxQ7s3b9rMDqxSpUpbt2yRlgfWkRe7dKmSXNIA7zKIyP8FMMX3ChIpb7E2OpHoVnJleaxs
88TCgXqSk9WqVMVpoDAEY+sYnl+2dGnJ0oOWSAWV/8cBNNOi2Fk8Y9p0OZdopFHeruPHuKrlUwqN
9QBXEVUFOHUK0AMUAwBaqiwyMGwm05+PzgzkVMYLMoQjWDiJFNHgVLBUgb4BxKLceBE8ql4E4Gzc
GD6LqQOhO1mhbNk5c2djHjpnzHivUB2rx4xH3EmJi9PkgcM2sqqCwsAHSwoowSOAYuu4BwBrGXXC
vcSqdI0DYVq3ar1s6VLgKeBdQa7u2L5dlBxaQthpU6P86j4ghe3btAnHVocA/JXzC8Y6zXgfHZYL
T5qDGS+ghwkxsEOSqnSJkiG3PugwQL0DYGWMB7m7dPESMqpl8xYeWA5Glkk4SRfWrVP3tde22+5R
QbUXgikAh2pKTI0fO44SmPeJJwCa2rRtK/BHviqRYJrhyZUrngvTh/F0G/FzhQoyTwtKCGhMEq91
XIRAHjuBambZjhRqXjhpcN9rKSWZA7E/bLBpxkszHvDTtddee8Wtt96KQMPyHD6X1T7EYEDpJaWV
LBkKmdTq2LEjbbN71279+/WXMNOAYflBpaLkykuXCleV6hz1V6lUUeQBqcX0Iic09K3AH8hJqGKX
4C6cIMEjeKRiA5C44FGYZ+zo0WvWrpXpmX1EgmqAr9mz59jgMZPA4LvR3XfdBbIklTpjZteu3aZO
nRKCaOSulKFdRoOnnx7CCkqiijETmtCrZ69JEybojVjmV0gzXprxcgbjeU+AjIIjxYABXkbrwslT
jPhEDd8A6HMEvNyxg1gTSCLOUkESRkvbQtZOqHzmRJdjV1vEkLpD5E6IA1Aoz0n7QDGjYbkRJKql
9ObYLAKIviqkJToOFWrs0BYtWoh7FZojHl24YOFCv8aZRU6wrEBy+mzdGoEYiTtgaE5C5wUZgTtu
377DlvKjRnbp583BqqaXl0jj+PgMGGL4NXm8VIdbuCq5PGkTqCGLkE8AK2d12WVpn3ptfIvTSbJS
73jmsC8vVSLNEu/PDORsxnt/5ih9l/QMXPIZyMGMd56wzOxTFm9YMyK7L4eNaxCA7wRAy/KYvoZ3
ltRDPjtNnAk6Df0HFeCsKNN33WSee5CXnC4/9B3mYMbzbpYtWy6vUcI8iQUoOcj+/jQWGGoPFkfu
vR6Fk3+gL9l4hNvZN77TKGBKhYTbpkaPGYO2wWVgYqK0lpkg7ezP66HUalQ55OWXN6uywJcYb1Zf
j/JhZkOZAuLYKvOvvNMy5LxtsL1uFi39A525nH3zHMx4iKBZ0yZRfoTMj/JUIcW/g7h2+elPwJSF
p4XknD51GmMMt4GkfdH5zEC7ZDoyY/ZOB3R7zxmiJlPmRMaSk6nZrDM2mUnLhEwDh5y5zTu9I+W3
UEU5yOHTci8TZcrkw7UYJeTL3JfCo6m5lfp0MppED5gZER9+4tnv3r0HV6dEZkp/GKp8M+r1hV8D
j4Vj7scK5cpivDNHmHoHNdNHuC87kDXLD2pNhoLVOZv8P7jR52zGU3VNcishycePvQ2DIv+U5Hxy
4xQvXkzCPLZEpsXVa9ZESTgkxoyqdUcVt9XiYsEXcCABGQKKQJfHjqmJB4epJDrz4yG5igUl7NoV
YTJPnFAfWGQ6OSFHy062yrhouISqfnIlAlabJi5Do0TOZoPRj58UFla7izMd54SMmu7omKFVOjC5
H6XE4pZg3pT1QGIyFxJlADeJjUeGwlWrVovpVoKPTz+OSY9YRfrAkOCAT9+v7iKdCd8GDKrjUAuJ
KVU6CZnzpE6RlcSA9+7Z7Xk5UdTc4TUJ1SfNlXEaAyeK3oTnO3mQBfiNndJym65169dp76TBw52q
1KM3hm+w1aefHhzVOr8Myhp/cOxz4XfO2YwHrSIBifLWXTt3ARC55Za/cLUpaHjLLbeEBGFAm9Wj
/MT1uRMgUVCpnLZ8dzhBklaV2WSMlRcE/cFh+lUmr/vuuUeZO7Qr8xxwCWkg52yUDnDrVkWbpd9C
jqNHjxoSZ/gy8T169ChXtpwkKMDZfHTWAv4JiLCyZctyl1euVNG9otSA+/Yjbn6IRQsXkFdr1z7f
pGkT2VflIDEGGACZnsmoqHH8oXzCl0n1JSFn+bJlIcsgUSdMGO8nydQsHIBplStXIb2hdv7yl7/E
CQ5fhBZQh10eMd6RO+64Q+Yy2ZnuvfdeTPXs0iUywEoPY7TyC4HLSFgGOOrCjRvWgwpUr1ZdAb1V
q1YpQKmurdybUVKTOnXAXC09JnbihPGm4p577sH55kHVctrs5bBJvnDy/+CufEfGy58/P8JN1TYu
tyk2NimGZJImpmhTXG1y/vB3m0y5vgkjnAZvqZmVfuHCRSFXCroPBcf9BNglozMyIhlyP/jgnNmz
nh48qG3r1nLOyeEhPzSwGFHTplWrXj16Eq0YMs9jjxFTZGZAqBBxvPa41LF0Q/37RlXCBeMpm4r9
6GalS5biMDR1SjHjH7FIdlM6DBMLU0ogG4l8hFguPEX4SUag4XFwEymsN6kyn3/hBWxgn+avx1Rq
PGR0pWRKOEsiEbkyqamjkC9PHntXEDlZUlaufE6dR8147WU3mjZlqjLikXq5b7+Rh6TLBw7sl2aT
DJ8xY6YM0PJhmgQ7OreQH0ViMnVhZROcOWM6AFDPnlFv1jWLVFrVvGDOzc54NKCbbrrpiqpVqwL+
XuaMR7ysWPEcCIsCvDRJ9U0RLoUQWIwWJKnrvLlzPYJ4BVlxwrMIsSPiqIING9SXT5LWhIvgXYQS
YUiJruCtmzRuBEs5eOBAVYXJrihT6vLl7dq0AcvEWoIhZJgO2fIkDnJ56Pm1ba/Cdnbu2Im0UcnZ
mTgZbv0AZONFV80U89t0yfnpDFEmJ6SD9u3bcf1TFKFqMG3oDbmHxKwYT0QFvVcaNfEWBq9SsfNM
MmQUw4m9Wf26Uf4yCq+MmrVq1yarqakGuWH9Biq3NOnak2x8/ThfAV05wmTgVrs43ItOThrj/HnP
PEMaW18sBDLf1qsjT/spD+i83mbNmCFTU7euUW8k/JLFZ2S/vmAS/GhemJ3xFLumpFwhg2/RokUv
c8aT2hUpSAlesVx52zDYMcv2kbeOUNuwnxgcATgegUBApgwDTtLTGFRgo6mp2M+mS+o7mqS48pLF
i8u3aeNmyS+YL7/U1IhVSnBKJjYr/ORTUgOKbn/iscfJKM1syeS9kkIzlCUI9nr64fBhQ/2VcJrE
K1tabfG3jTBUAnCJVJz6sUwApilR4BKiiXFFmrAKRNCu3YapK3FG3bp09atr6caGR+IRxX169ZZk
Nrw2m668efJs2fKyXK6ygHk0WDn1ekg8GjV0uASb4pjIbUH0+EfPAZ0zsP8AS0OZ0qVkE/NVOQcr
l9mZPWumNcjKMmTQYJEZAjU8ZqMG9a1fJJ7UzoI8BF65pEXLlhL+Ofhoss3FP3V2xgscd0VAjl3m
jCcv+nPLlrEcEHFYTpSd1OLibiz79jlq7lj7baLwGIrv1bM3/VBouaXdvmh4DKSOFu+2bUNx+qqV
q7ZqFSGbyTGppnUrSK9gwYKRyDp1Cn+iYDOO1iWTtSHs3iNKV96vbx85p7Foz+7dataoKREtD4fE
rOqJlyhWnJa4bes2iE28JOxdks98efJaDkaNGvXE4483btzIMCSEJPEwHouFyKahQ4fRgXfu3GV7
ZgXBxpLwYlTWlyaNGotdAlUjOYkgkRlgop6XJJRJmtosV6xtWMECBUl+T6rAyNKlz9oysP2SY0aL
c+gyZUqXkb1X2maZKsUZCi+kJ9u7UoNpBzQFYVDuiJNZj9q0aknM6g3oVLSUxzd7xi+TvI3i5bYB
uXiWeH96yM54xB2hd4WXdPPNN1svE9673KYYKdOR6E5WcTF1NnUkwPoNG3x1nkyzq0G1dkchpSSD
JFMe6cQJwOgXWeTi2CI2TFXv4t4OImL9RKa/3XvYF0kbPUdugxMnXCjVioOouDYiPfLWGzsjNKb5
YZthtECpLIohyTnepvup0SF1vN5wkZa4RVJkmzSWHssERlq1ehWZaTCYnPSLIKbHjslFaYemE4MJ
edfd2rVUSrfWf1zL6Di9kYWGePdePDg902aS0SXq8ODBuKzfgWich9/yq0+cJ+aE/wkLJMPDa2Ud
4WkwFXL1unVczTxqSWzqwSDdSD+GZ0rDjLH6CunwK65Oavq9P8T6YbpLFsbzpq666ip/I8aTzJxp
7rJlvGBbT/xRiVcqOWC0nD49Y2uXnAzaUXioxHCf5WSYlHM3S9pkX7pwvs1bq1atK1aoGDaZqb2l
KhFZ5jal2RkJocP55Eapw07tOXUkyeSkOvdSM9CkdpLleVMHnDEJmR7CZE6yDObDxBLvz7NkIZuE
1yLGw3+0TRj/8CYuN4l37gkK/rdIvr2/nyj38/HjFHVxQ2SCeSNC3wXe9f6OMH23y2EGUhkvldEi
xvMRrHnfffflUMYLw34nDOR/a/ZjKGQiyoKa+n6P4b/1bOl+L9kMpDJeqmqZwXgIiKWFvSXHSbxL
NkPpjtIz8F+YgYTxmFEEnYeqmj6nGc8p9pYs0ehn3aikT6ZnID0D72kGbEmYMJPd3BmM5wvrlp8l
in1PnaYbp2cgPQPnmAGyDlvhvdQ2pyVeOEvuPfLII1xAmDA9m+kZSM/AxcwAbrKvo2Gmyrqsqmbq
DYDI2Dldk2a/i5n39LUf5RmAZ7jxxhs56pJ93bkkXvIblnMNZx9rJ6OLvR8P7Ed5HtPPnp6Bc89A
7FuabadGZ7zyyiuFH2RRL8+L8ZJGPA0MnsQl9lXqPv1Jz0B6Bs46A5REbILr8N5ZpVwq4/1/9Bck
HFTJneYAAAAASUVORK5CYII=

--_004_34966E97BE8AD64EAE9D3D6E4DEE36F25817518DSZXEMA501MBSchi_--


From nobody Sun Jul  6 23:52:22 2014
Return-Path: <schmitt@ifi.uzh.ch>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id AEC031A0B0F for <ace@ietfa.amsl.com>; Sun,  6 Jul 2014 23:52:18 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.539
X-Spam-Level: 
X-Spam-Status: No, score=-2.539 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, RP_MATCHES_RCVD=-0.651, T_HK_NAME_DR=0.01, UNPARSEABLE_RELAY=0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id sOjqt1Qwh9iY for <ace@ietfa.amsl.com>; Sun,  6 Jul 2014 23:52:11 -0700 (PDT)
Received: from bohuslav.ifi.uzh.ch (bohuslav.ifi.uzh.ch [130.60.155.10]) by ietfa.amsl.com (Postfix) with ESMTP id A8CB31A0B0D for <ace@ietf.org>; Sun,  6 Jul 2014 23:52:10 -0700 (PDT)
Received: from authenticated sender schmitt by bohuslav.ifi.uzh.ch (postfix) with ESMTPSA id SA; <F3E847FC82>
Message-ID: <53BA4398.2040500@ifi.uzh.ch>
Date: Mon, 07 Jul 2014 08:52:08 +0200
From: "Dr. Corinna Schmitt" <schmitt@ifi.uzh.ch>
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.9; rv:24.0) Gecko/20100101 Thunderbird/24.6.0
MIME-Version: 1.0
To: ace@ietf.org, Burkhard Stiller <stiller@ifi.uzh.ch>
References: <53086642.5050609@gmx.net> <53134E58.20608@ifi.uzh.ch> <531F6177.5040704@gmx.net> <53B1209C.5020200@ifi.uzh.ch> <34966E97BE8AD64EAE9D3D6E4DEE36F25817518D@SZXEMA501-MBS.china.huawei.com>
In-Reply-To: <34966E97BE8AD64EAE9D3D6E4DEE36F25817518D@SZXEMA501-MBS.china.huawei.com>
Content-Type: multipart/alternative; boundary="------------020507020703030701080103"
X-Virus-Scanned: clamav-milter 0.97.8 at bohuslav
X-Virus-Status: Clean
Archived-At: http://mailarchive.ietf.org/arch/msg/ace/dwhpV6d1ejCL7ihiKMkhIVlOa1Y
Subject: Re: [Ace] draft-schmitt-two-way-authentication-for-iot-02
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 07 Jul 2014 06:52:18 -0000

This is a multi-part message in MIME format.
--------------020507020703030701080103
Content-Type: text/plain; charset=ISO-8859-1; format=flowed
Content-Transfer-Encoding: 8bit

Dear Kepeng,

thanks for the feedback. Some of them we already applied in the updated 
version: draft-schmitt-ace-twowayauth-for-iot-00 
<https://datatracker.ietf.org/doc/draft-schmitt-ace-twowayauth-for-iot/>
This draft replaces the one you refer to.

> Section 2, Terminology: Currently, our charter and most of the other 
> submitted drafts use "Client", "Resource Server", "Authorization 
> Server". To keep consistency, it is better to use these terminologies 
> to replace "Publisher", "Subscriber" and "Access Control Server".
>
We will change it in one of the next updates when it is clear for us how 
to map it.
>
> Section 3, High Level Design Requirements: the objective of this 
> section is quite similar to the "design considerations" draft. It is 
> better to consolidate this section with the draft.
>
> http://datatracker.ietf.org/doc/draft-seitz-ace-design-considerations/
>
Thanks for the hint.
>
> Section 4, It seems that that most of the design considerations (e.g. 
> assumed network stack, handshake message flows) will also be applied 
> for Class 1 devices. It is better to indicate the common design 
> considerations first, then highlight what more we can achieve by Class 
> 2 devices.
>
We already included this. Deleting our TPM request and argument with 
class 1 and 2 now.
>
> Section 5.1, 5.2 and 6, Use cases and Requirements: Maybe it is better 
> to consolidate these sections with the "Use cases and requirements" draft:
>
> http://datatracker.ietf.org/doc/draft-seitz-ace-usecases/
>
Thanks for the hint. The use-case we have in those sections are coming 
from the draft already. The requirements are based on the things we need.
>
> Section 5.3, Data Access Procedures: it seems that interactions 
> between Gateway and Publisher are out of scope? Because from the 
> flows, the Gateway is not involved in the data access flow any more. 
> Also about the last two steps "Two-way authentication handshake 
> between Subscriber and Publisher" and "Data exchange using DTLS 
> secured channel", in these two steps, is "Access Control Server" 
> involved in the data access flow?
>
We will check it and let you know. Sometimes the Gateway might be involved.
>
> Section 10, Formal Syntax: It is better to put this section as a 
> sub-section of Section 2, to let readers better understand the meaning 
> of the abbreviations.
>
Also a good idea.
>
Thanks and see you in Toronto,
Corinna
>
> *? ??:*Ace [mailto:ace-bounces@ietf.org] *? ? *Corinna Schmitt
> *? ???:*2014?6?30?16:32
> *???:*ace@ietf.org; Hannes Tschofenig
> *??:*Burkhard Stiller
> *??:*Re: [Ace] draft-schmitt-two-way-authentication-for-iot-02
>
> Dear Hannes,
>
> based on the discussions of the pre-meeting in Stockholm we updated 
> our draft and generalized it. Our old draft 
> "draft-schmitt-two-way-authentication-for-iot" is now replaced by 
> "draft-schmitt-ace-twowayauth-for-iot".
>
> The mentioned projects are only examples where we have the work 
> integrated and where it runs already successful.
> So we believe the draft fits into ACE and also maps the requirements 
> outlined in https://tools.ietf.org/html/draft-seitz-ace-usecases-00.
>
> See you in Toronto at IETF 90,
> Corinna
>
> Am 11.03.14 20:18, schrieb Hannes Tschofenig:
>
>     Hi Corinna,
>
>       
>
>     thanks for the response.
>
>       
>
>     My suggestion would be to produce a write-up that is of generic use
>
>     (independent from your specific implementation and your EU funded project).
>
>       
>
>     However, given the charter discussions and the BOF I have my doubts
>
>     whether the work would meet many of the requirements outlined in
>
>     https://tools.ietf.org/html/draft-seitz-ace-usecases-00.
>
>       
>
>     Ciao
>
>     Hannes
>
>       
>
>     On 03/02/2014 04:29 PM, Dr. Corinna Schmitt wrote:
>
>         Dear Hannes,
>
>             Hi Corinna, Hi Burkhard,
>
>               
>
>             thanks for your document. I have read through it and I ran into a few
>
>             questions. Your response would help me to better understand the proposed
>
>             idea.
>
>         Thanks for reading the draft and make comments to it to improve it. Some
>
>         comments can be answered right away.
>
>             1) Why do you assume IEEE 802.15.4? Currently it seems that the 15.4
>
>             radio will mostly be used in specialized industry segments only. Is
>
>             there anything in the document that would make the idea less suitable
>
>             for other radio technologies, for example BTLE?
>
>         Potentially the proposed solution can work on every stack you like. So
>
>         you can do an implementation independently of IEEE 802.15.4.
>
>         We put IEEE 802.15.4 there, because our used stack (BLIP) uses it.
>
>             2) The assumed network stack does not show 6lowpan. Was this intentional?
>
>         Same as above. You can use the stack you want. So also 6lowpan can be
>
>         used. It depends n you what you require and what you want to support.
>
>             3) You show RPL in the stack and I was wondering whether you assume it
>
>             being mandatory to implement for your assumed architecture? It does not
>
>             seem to show up elsewhere in the document. It appears to be irrelevant
>
>             for your design.
>
>         RPL was just mentioned due to our other publications. Currently our plan
>
>         is to change to RPL (CoAP) in the future.
>
>             4) Subscriber identity: You write --
>
>             "
>
>                 The identity of a default subscriber is usually preconfigured on a
>
>                 publisher before it is deployed.
>
>             "
>
>               
>
>             Could you explain more what you assume is pre-configured and where it is
>
>             preconfigured?
>
>         Here pre-configures means that our devices are equipped with the
>
>         certification during compiling and programming them before deployment.
>
>         This is due to the application scenario we support at the moment. Before
>
>         deploying the device you have to run to steps: First creation of
>
>         certificate, and second compiling code and play it on the device.
>
>             I would also suggest to avoid the term subscriber since it has two other
>
>             meanings that might confuse:
>
>               a) The term subscriber is often used in context of telecommunication as
>
>             the user who has a contract with a telecommunication operator.
>
>               b) The second use is in context of protocols that use asynchronous
>
>             communication (like XMPP).
>
>               
>
>             I believe your notion of subscriber does not relate to those two
>
>             existing uses. I guess you are more using the term subscriber to refer
>
>             to a device that wants some data from a sensor. Is this correct?
>
>         Thanks for the hint. Yes you are right. The subscriber should be a
>
>         device that wants data from the sensor.
>
>         Usually this is one outside of the WSN. Do you have a suggestion for new
>
>         name?
>
>             5) Roles in your architecture.
>
>               
>
>             It seems that you assume that the IoT devices are publishers and that
>
>             there are subscribers who talk to these publishers. In some other cases
>
>             I have seen architectures where the IoT devices (sensors) upload the
>
>             data to some servers without having to act as servers themselves. In
>
>             your architecture it feels like the sensor nodes implement the
>
>             server-side functionality
>
>         That was not our intention.
>
>         Our network has push characteristics up to the server. Data publishing
>
>         runs over server, because it has more resources and, therefore, can
>
>         handle requests better. It is the gate to the world.
>
>         Pull is only performed if you require data (measurements) at a time that
>
>         is not pre-defined.
>
>             In Section 4.2.2 you write that you recommend an OpenSSL implementation
>
>             on the server side but the server-side would be the IoT device. While it
>
>             would be inappropriate to recommend a specific implementation in an IETF
>
>             draft/RFC it also raises the questions about the expectations on the
>
>             server-side.
>
>         Thanks for the hint.
>
>         We use OpenSSL on the server but not within the WSN. OpenSSL is used
>
>         especially for managing rights, requests, and certificates.
>
>             6. Certificate content
>
>               
>
>             In Section 4.2.2 you describe the content of a certificate and you
>
>             indicate that the commonName is set to "localhost". It seems to be
>
>             useless to include this in the certificate since a CA would not be able
>
>             to verify this identity information nor would any party verifying it be
>
>             able to use it in a meaningful way.
>
>         Localhost in our case is a special IP address (here: sink). You are
>
>         right, we should rename it and make clear that it is an IP address. So
>
>         you can set is like you want.
>
>             It also seems to be in violation of what you write in Section 5.2 where
>
>             you state that "every publisher in the network MUST have an unique
>
>             identity.".
>
>               
>
>             You also indicated more complete information for inclusion in the
>
>             certificate but it is not clear to me what purpose it serves. Could you
>
>             explain?
>
>         Will do it asap.
>
>             7. Privacy
>
>               
>
>             In Section 5 you indicate some privacy related aspects and you hint to "
>
>             access regulations based on legal and regulative implications". Could
>
>             you briefly explain what those requirements are?
>
>         This part we put in due to the deployment and project relations we are
>
>         running at the moment.
>
>         Here it means that not every device can be able to access the data, for
>
>         example, due to legal issues in the region (EU, CH, US rights).
>
>         This has to be stored central in the network and it has to be checked
>
>         before giving access and creating the corresponding access ticket.
>
>         Here we refer to the following publications:
>
>           
>
>         Radhika Garg, Corinna Schmitt, Burkhard Stiller: /Investigating
>
>         Regulative Implications for User-generated Content and a Design
>
>         Proposal/; Degruyter, PIK-Praxis der Informationsverarbeitung und
>
>         Kommunikation, Vol. 36, No. 4, December 2013, ISSN 0930-5157, pp 1--11.
>
>         doi:10.1515/pik-2013-0042<http://dx.doi.org/10.1515/pik-2013-0042>  <http://dx.doi.org/10.1515/pik-2013-0042>  URL:
>
>         http://www.degruyter.com/view/j/piko.ahead-of-print/pik-2013-0042/pik-2013-0042.xml
>
>           
>
>         Radhika Garg, Christos Tsiaras, Burkhard Stiller, Corinna Schmitt,
>
>         Daniel Dönni: /Deliverable D7.1 - Basics, Requirements, Scenarios, and
>
>         Architecture: In FLAMINGO/; Radhika Garg (Edt.), Zürich, Switzerland,
>
>         October 2013
>
>             8. Use Cases.
>
>               
>
>             I suggest to omit the use cases from the document since the description
>
>             is too brief to be useful. A small remark: From my work in the emergency
>
>             services environment I had gotten the impression that there are no plans
>
>             to take sensor input directly when initiating alerts. In fact, sensor
>
>             alerts do rarely even get directly to the emergency services authorities
>
>             but are rather pre-processed by an intermediate organization (by
>
>             humans). Maybe you have spoken with other people, who have different
>
>             plans. Where did you got your information from?
>
>         This section is based on discussion with our project partners within
>
>         SmartenIT (www.smartenit.eu  <http://www.smartenit.eu>) and Flamingo (http://www.fp7-flamingo.eu).
>
>         <http://www.fp7-flamingo.eu>  <http://www.fp7-flamingo.eu>
>
>           
>
>             9. Architecture
>
>               
>
>             Figure 3 shows the architecture but it is a bit confusing since it is
>
>             not clear what the boxes and the lines mean. The publisher is a box
>
>             separate from the sensors and from the earlier description I thought
>
>             that the sensors are actually the publishers. Furthermore, the gateway
>
>             was not discussed as a role up to that point in the document. The
>
>             gateway shows up in Section 5.3 and its role confuses me. You write:
>
>               
>
>             "  A sensor node has published its data, which is transmitted in
>
>                 direction to the global sink (cf. Figure 3 where global sink is
>
>                 located in the gateway component).
>
>             "
>
>               
>
>             Does the sensor publish the data at the gateway? From the earlier
>
>             sections I thought that the subscriber talks to the publisher instead.
>
>             Is the gateway the subscriber? Why doesn't the sensor uploads the data
>
>             to some server instead (which is frequently done in today's IoT
>
>             deployments).
>
>         Lots of comments.
>
>         I will address and clarify them asap.
>
>         Furthermore, I will add a legend to the Figure and perhaps modify it
>
>         based on you aforementioned comments.
>
>             Why do you call the entire document "two-way authentication" when the
>
>             the two way authentication is just one small part of the overall
>
>             authentication procedure. In fact the two-way authentication is used
>
>             between the subscriber and the access control server (as shown in Figure
>
>             4), and between the publisher and the gateway. Furthermore, there has to
>
>             be some authentication between the subscriber and the publisher as well
>
>             (at least I hope so).
>
>               
>
>             What is the purpose of the access ticket? It shows up in Section 5.3 and
>
>             I wonder why there is a need for an access ticket when the two parties
>
>             (subscriber and publisher) already have a certificate. Why cannot you
>
>             use the certificate for authentication with the publisher right away?
>
>               
>
>             Where do you see the access control server being deployed? Is this an
>
>             entity in the local network or something you would have on the Internet?
>
>               
>
>             Why does the publisher have to authenticate to the gateway? From Figure
>
>             4 it is not clear whether the gateway is just an optional component or
>
>             an integral part of the architecture.
>
>               
>
>             The document does not explain what the access token is and how it is
>
>             exchanged between the subscriber and the publisher.
>
>               
>
>             Btw, the term CA standards for Certification Authority rather than
>
>             Certificate Authority.
>
>           
>
>         Will be addressed soon.
>
>             10. Hardware requirements.
>
>               
>
>             Hardware requirements typically are not appropriate for IETF documents.
>
>             While you make the argument that an RSA-based public key cryptosystem is
>
>             good enough from a performance point of view the currently mandatory
>
>             ciphersuites used in CoAP are based on ECC (for those that rely on
>
>             asymmetric crypto). While having hardware support for key storage is a
>
>             great idea I was wondering how much your architecture actually relies on
>
>             it. My impression that it would work fine just without a TPM chip. But
>
>             you might have more hardware experience than I have. Could you point me
>
>             to some hardware that you have in mind using?
>
>               
>
>         We put this section for completeness and to show that an implementation
>
>         exists.
>
>         Concerning sensor nodes and TPM we are using OPAL from CSIRO. Trusting
>
>         Computing becomes relevant nowadays when thinking about securing data.
>
>         Drawback is that if the TPM chip is broken or you change something
>
>         during booting everything is lost. Advantage is that the storage root
>
>         key is stored safely and only derivates are used for your applications.
>
>           
>
>         Hope to answer most important questions or comments now. Others will be
>
>         addressed soon.
>
>         You can also talk to me during IETF in London.
>
>           
>
>         Regards,
>
>         Corinna
>
>           
>
>           
>
>           
>
>         _______________________________________________
>
>         Ace mailing list
>
>         Ace@ietf.org  <mailto:Ace@ietf.org>
>
>         https://www.ietf.org/mailman/listinfo/ace
>
>           
>
>       
>
>
>
>
>     _______________________________________________
>
>     Ace mailing list
>
>     Ace@ietf.org  <mailto:Ace@ietf.org>
>
>     https://www.ietf.org/mailman/listinfo/ace
>
> -- 
>
>
>
> _______________________________________________
> Ace mailing list
> Ace@ietf.org
> https://www.ietf.org/mailman/listinfo/ace


-- 

--------------020507020703030701080103
Content-Type: multipart/related;
 boundary="------------040403090101020709030709"


--------------040403090101020709030709
Content-Type: text/html; charset=ISO-8859-1
Content-Transfer-Encoding: 7bit

<html>
  <head>
    <meta content="text/html; charset=ISO-8859-1"
      http-equiv="Content-Type">
  </head>
  <body bgcolor="#FFFFFF" text="#000000">
    <div class="moz-cite-prefix">Dear Kepeng,<br>
      <br>
      thanks for the feedback. Some of them we already applied in the
      updated version:
      <meta http-equiv="content-type" content="text/html;
        charset=ISO-8859-1">
      <a
href="https://datatracker.ietf.org/doc/draft-schmitt-ace-twowayauth-for-iot/">draft-schmitt-ace-twowayauth-for-iot-00</a><br>
      This draft replaces the one you refer to.<br>
      <br>
    </div>
    <blockquote
cite="mid:34966E97BE8AD64EAE9D3D6E4DEE36F25817518D@SZXEMA501-MBS.china.huawei.com"
      type="cite">
      <meta http-equiv="Content-Type" content="text/html;
        charset=ISO-8859-1">
      <meta name="Generator" content="Microsoft Word 12 (filtered
        medium)">
      <!--[if !mso]><style>v\:* {behavior:url(#default#VML);}
o\:* {behavior:url(#default#VML);}
w\:* {behavior:url(#default#VML);}
.shape {behavior:url(#default#VML);}
</style><![endif]-->
      <style><!--
/* Font Definitions */
@font-face
	{font-family:&#23435;&#20307;;
	panose-1:2 1 6 0 3 1 1 1 1 1;}
@font-face
	{font-family:"Cambria Math";
	panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
	{font-family:Calibri;
	panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
	{font-family:"\@&#23435;&#20307;";
	panose-1:2 1 6 0 3 1 1 1 1 1;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
	{margin:0cm;
	margin-bottom:.0001pt;
	font-size:12.0pt;
	font-family:"Times New Roman","serif";
	color:black;}
a:link, span.MsoHyperlink
	{mso-style-priority:99;
	color:blue;
	text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
	{mso-style-priority:99;
	color:purple;
	text-decoration:underline;}
pre
	{mso-style-priority:99;
	mso-style-link:"HTML &#39044;&#35774;&#26684;&#24335; Char";
	margin:0cm;
	margin-bottom:.0001pt;
	font-size:10.0pt;
	font-family:"Courier New";
	color:black;}
span.HTMLChar
	{mso-style-name:"HTML &#39044;&#35774;&#26684;&#24335; Char";
	mso-style-priority:99;
	mso-style-link:"HTML &#39044;&#35774;&#26684;&#24335;";
	font-family:"Courier New";
	color:black;}
span.EmailStyle19
	{mso-style-type:personal-reply;
	font-family:"Calibri","sans-serif";
	color:#1F497D;}
.MsoChpDefault
	{mso-style-type:export-only;
	font-size:10.0pt;}
@page WordSection1
	{size:612.0pt 792.0pt;
	margin:72.0pt 90.0pt 72.0pt 90.0pt;}
div.WordSection1
	{page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]-->
      <div class="WordSection1"><span
style="font-size:10.5pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:#1F497D"
          lang="EN-US"><o:p></o:p></span>
        <p class="MsoNormal"><span
style="font-size:10.5pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:#1F497D"
            lang="EN-US"><o:p>&nbsp;</o:p></span></p>
        <p class="MsoNormal"><span
style="font-size:10.5pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:#1F497D"
            lang="EN-US">Section 2, Terminology: Currently, our charter
            and most of the other submitted drafts use &#8220;Client&#8221;,
            &#8220;Resource Server&#8221;, &#8220;Authorization Server&#8221;. To keep
            consistency, it is better to use these terminologies to
            replace &#8220;Publisher&#8221;, &#8220;Subscriber&#8221; and &#8220;Access Control
            Server&#8221;.</span></p>
      </div>
    </blockquote>
    We will change it in one of the next updates when it is clear for us
    how to map it.<br>
    <blockquote
cite="mid:34966E97BE8AD64EAE9D3D6E4DEE36F25817518D@SZXEMA501-MBS.china.huawei.com"
      type="cite">
      <div class="WordSection1">
        <p class="MsoNormal"><span
style="font-size:10.5pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:#1F497D"
            lang="EN-US"><o:p></o:p></span></p>
        <p class="MsoNormal"><span
style="font-size:10.5pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:#1F497D"
            lang="EN-US"><o:p>&nbsp;</o:p></span></p>
        <p class="MsoNormal"><span
style="font-size:10.5pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:#1F497D"
            lang="EN-US">Section 3, High Level Design Requirements: the
            objective of this section is quite similar to the &#8220;design
            considerations&#8221; draft. It is better to consolidate this
            section with the draft.<o:p></o:p></span></p>
        <p class="MsoNormal"><span
style="font-size:10.5pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:#1F497D"
            lang="EN-US"><a moz-do-not-send="true"
href="http://datatracker.ietf.org/doc/draft-seitz-ace-design-considerations/">http://datatracker.ietf.org/doc/draft-seitz-ace-design-considerations/</a></span></p>
      </div>
    </blockquote>
    Thanks for the hint.<br>
    <blockquote
cite="mid:34966E97BE8AD64EAE9D3D6E4DEE36F25817518D@SZXEMA501-MBS.china.huawei.com"
      type="cite">
      <div class="WordSection1">
        <p class="MsoNormal"><span
style="font-size:10.5pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:#1F497D"
            lang="EN-US"><o:p></o:p></span></p>
        <p class="MsoNormal"><span
style="font-size:10.5pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:#1F497D"
            lang="EN-US"><o:p>&nbsp;</o:p></span></p>
        <p class="MsoNormal"><span
style="font-size:10.5pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:#1F497D"
            lang="EN-US">Section 4, It seems that that most of the
            design considerations (e.g. assumed network stack, handshake
            message flows) will also be applied for Class 1 devices. It
            is better to indicate the common design considerations
            first, then highlight what more we can achieve by Class 2
            devices.</span></p>
      </div>
    </blockquote>
    We already included this. Deleting our TPM request and argument with
    class 1 and 2 now.<br>
    <blockquote
cite="mid:34966E97BE8AD64EAE9D3D6E4DEE36F25817518D@SZXEMA501-MBS.china.huawei.com"
      type="cite">
      <div class="WordSection1">
        <p class="MsoNormal"><span
style="font-size:10.5pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:#1F497D"
            lang="EN-US"><o:p></o:p></span></p>
        <p class="MsoNormal"><span
style="font-size:10.5pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:#1F497D"
            lang="EN-US"><o:p>&nbsp;</o:p></span></p>
        <p class="MsoNormal"><span
style="font-size:10.5pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:#1F497D"
            lang="EN-US">Section 5.1, 5.2 and 6, Use cases and
            Requirements: Maybe it is better to consolidate these
            sections with the &#8220;Use cases and requirements&#8221; draft:<o:p></o:p></span></p>
        <p class="MsoNormal"><span
style="font-size:10.5pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:#1F497D"
            lang="EN-US"><a moz-do-not-send="true"
              href="http://datatracker.ietf.org/doc/draft-seitz-ace-usecases/">http://datatracker.ietf.org/doc/draft-seitz-ace-usecases/</a></span></p>
      </div>
    </blockquote>
    Thanks for the hint. The use-case we have in those sections are
    coming from the draft already. The requirements are based on the
    things we need.<br>
    <blockquote
cite="mid:34966E97BE8AD64EAE9D3D6E4DEE36F25817518D@SZXEMA501-MBS.china.huawei.com"
      type="cite">
      <div class="WordSection1">
        <p class="MsoNormal"><span
style="font-size:10.5pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:#1F497D"
            lang="EN-US"><o:p></o:p></span></p>
        <p class="MsoNormal"><span
style="font-size:10.5pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:#1F497D"
            lang="EN-US"><o:p>&nbsp;</o:p></span></p>
        <p class="MsoNormal"><span
style="font-size:10.5pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:#1F497D"
            lang="EN-US">Section 5.3, Data Access Procedures: it seems
            that interactions between Gateway and Publisher are out of
            scope? Because from the flows, the Gateway is not involved
            in the data access flow any more. Also about the last two
            steps &#8220;Two-way authentication handshake between Subscriber
            and Publisher&#8221; and &#8220;Data exchange using DTLS secured
            channel&#8221;, in these two steps, is &#8220;Access Control Server&#8221;
            involved in the data access flow?</span></p>
      </div>
    </blockquote>
    We will check it and let you know. Sometimes the Gateway might be
    involved.<br>
    <blockquote
cite="mid:34966E97BE8AD64EAE9D3D6E4DEE36F25817518D@SZXEMA501-MBS.china.huawei.com"
      type="cite">
      <div class="WordSection1">
        <p class="MsoNormal"><span
style="font-size:10.5pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:#1F497D"
            lang="EN-US"><o:p></o:p></span></p>
        <p class="MsoNormal"><span
style="font-size:10.5pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:#1F497D"
            lang="EN-US"><o:p>&nbsp;</o:p></span></p>
        <p class="MsoNormal"><span
style="font-size:10.5pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:#1F497D"
            lang="EN-US">Section 10, Formal Syntax: It is better to put
            this section as a sub-section of Section 2, to let readers
            better understand the meaning of the abbreviations.</span></p>
      </div>
    </blockquote>
    Also a good idea. <br>
    <blockquote
cite="mid:34966E97BE8AD64EAE9D3D6E4DEE36F25817518D@SZXEMA501-MBS.china.huawei.com"
      type="cite">
      <div class="WordSection1">
        <p class="MsoNormal"><span
style="font-size:10.5pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:#1F497D"
            lang="EN-US"><o:p></o:p></span></p>
        <p class="MsoNormal"><span
style="font-size:10.5pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:#1F497D"
            lang="EN-US"><o:p>&nbsp;</o:p></span></p>
      </div>
    </blockquote>
    Thanks and see you in Toronto,<br>
    Corinna<br>
    <blockquote
cite="mid:34966E97BE8AD64EAE9D3D6E4DEE36F25817518D@SZXEMA501-MBS.china.huawei.com"
      type="cite">
      <div class="WordSection1"><span
style="font-size:10.5pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:#1F497D"
          lang="EN-US"><o:p></o:p></span>
        <p class="MsoNormal"><span
style="font-size:10.5pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:#1F497D"
            lang="EN-US"><o:p>&nbsp;</o:p></span></p>
        <div style="border:none;border-left:solid blue 1.5pt;padding:0cm
          0cm 0cm 4.0pt">
          <div>
            <div style="border:none;border-top:solid #B5C4DF
              1.0pt;padding:3.0pt 0cm 0cm 0cm">
              <p class="MsoNormal"><b><span
                    style="font-size:10.0pt;font-family:&#23435;&#20307;;color:windowtext">&#21457;
                    &#20214;&#20154;<span lang="EN-US">:</span></span></b><span
                  style="font-size:10.0pt;font-family:&#23435;&#20307;;color:windowtext"
                  lang="EN-US"> Ace [<a class="moz-txt-link-freetext" href="mailto:ace-bounces@ietf.org">mailto:ace-bounces@ietf.org</a>]
                </span><b><span
                    style="font-size:10.0pt;font-family:&#23435;&#20307;;color:windowtext">&#20195;
                    &#34920; </span>
                </b><span
                  style="font-size:10.0pt;font-family:&#23435;&#20307;;color:windowtext"
                  lang="EN-US">Corinna Schmitt<br>
                </span><b><span
                    style="font-size:10.0pt;font-family:&#23435;&#20307;;color:windowtext">&#21457;
                    &#36865;&#26102;&#38388;<span lang="EN-US">:</span></span></b><span
                  style="font-size:10.0pt;font-family:&#23435;&#20307;;color:windowtext"
                  lang="EN-US"> 2014</span><span
                  style="font-size:10.0pt;font-family:&#23435;&#20307;;color:windowtext">&#24180;<span
                    lang="EN-US">6</span>&#26376;<span lang="EN-US">30</span>&#26085;<span
                    lang="EN-US"> 16:32<br>
                  </span><b>&#25910;&#20214;&#20154;<span lang="EN-US">:</span></b><span
                    lang="EN-US"> <a class="moz-txt-link-abbreviated" href="mailto:ace@ietf.org">ace@ietf.org</a>; Hannes Tschofenig<br>
                  </span><b>&#25220;&#36865;<span lang="EN-US">:</span></b><span
                    lang="EN-US"> Burkhard Stiller<br>
                  </span><b>&#20027;&#39064;<span lang="EN-US">:</span></b><span
                    lang="EN-US"> Re: [Ace]
                    draft-schmitt-two-way-authentication-for-iot-02<o:p></o:p></span></span></p>
            </div>
          </div>
          <p class="MsoNormal"><span lang="EN-US"><o:p>&nbsp;</o:p></span></p>
          <div>
            <p class="MsoNormal"><span lang="EN-US">Dear Hannes,<br>
                <br>
                based on the discussions of the pre-meeting in Stockholm
                we updated our draft and generalized it. Our old draft
                "draft-schmitt-two-way-authentication-for-iot" is now
                replaced by "draft-schmitt-ace-twowayauth-for-iot".<br>
                <br>
                The mentioned projects are only examples where we have
                the work integrated and where it runs already
                successful.
                <br>
                So we believe the draft fits into ACE and also maps the
                requirements outlined in <a moz-do-not-send="true"
                  href="https://tools.ietf.org/html/draft-seitz-ace-usecases-00">
https://tools.ietf.org/html/draft-seitz-ace-usecases-00</a>.<br>
                <br>
                See you in Toronto at IETF 90,<br>
                Corinna<br>
                <br>
                Am 11.03.14 20:18, schrieb Hannes Tschofenig:<o:p></o:p></span></p>
          </div>
          <blockquote style="margin-top:5.0pt;margin-bottom:5.0pt">
            <pre><span lang="EN-US">Hi Corinna,<o:p></o:p></span></pre>
            <pre><span lang="EN-US"><o:p>&nbsp;</o:p></span></pre>
            <pre><span lang="EN-US">thanks for the response.<o:p></o:p></span></pre>
            <pre><span lang="EN-US"><o:p>&nbsp;</o:p></span></pre>
            <pre><span lang="EN-US">My suggestion would be to produce a write-up that is of generic use<o:p></o:p></span></pre>
            <pre><span lang="EN-US">(independent from your specific implementation and your EU funded project).<o:p></o:p></span></pre>
            <pre><span lang="EN-US"><o:p>&nbsp;</o:p></span></pre>
            <pre><span lang="EN-US">However, given the charter discussions and the BOF I have my doubts<o:p></o:p></span></pre>
            <pre><span lang="EN-US">whether the work would meet many of the requirements outlined in<o:p></o:p></span></pre>
            <pre><span lang="EN-US"><a moz-do-not-send="true" href="https://tools.ietf.org/html/draft-seitz-ace-usecases-00">https://tools.ietf.org/html/draft-seitz-ace-usecases-00</a>.<o:p></o:p></span></pre>
            <pre><span lang="EN-US"><o:p>&nbsp;</o:p></span></pre>
            <pre><span lang="EN-US">Ciao<o:p></o:p></span></pre>
            <pre><span lang="EN-US">Hannes<o:p></o:p></span></pre>
            <pre><span lang="EN-US"><o:p>&nbsp;</o:p></span></pre>
            <pre><span lang="EN-US">On 03/02/2014 04:29 PM, Dr. Corinna Schmitt wrote:<o:p></o:p></span></pre>
            <blockquote style="margin-top:5.0pt;margin-bottom:5.0pt">
              <pre><span lang="EN-US">Dear Hannes,<o:p></o:p></span></pre>
              <blockquote style="margin-top:5.0pt;margin-bottom:5.0pt">
                <pre><span lang="EN-US">Hi Corinna, Hi Burkhard,<o:p></o:p></span></pre>
                <pre><span lang="EN-US"><o:p>&nbsp;</o:p></span></pre>
                <pre><span lang="EN-US">thanks for your document. I have read through it and I ran into a few<o:p></o:p></span></pre>
                <pre><span lang="EN-US">questions. Your response would help me to better understand the proposed<o:p></o:p></span></pre>
                <pre><span lang="EN-US">idea.<o:p></o:p></span></pre>
              </blockquote>
              <pre><span lang="EN-US">Thanks for reading the draft and make comments to it to improve it. Some<o:p></o:p></span></pre>
              <pre><span lang="EN-US">comments can be answered right away.<o:p></o:p></span></pre>
              <blockquote style="margin-top:5.0pt;margin-bottom:5.0pt">
                <pre><span lang="EN-US">1) Why do you assume IEEE 802.15.4? Currently it seems that the 15.4<o:p></o:p></span></pre>
                <pre><span lang="EN-US">radio will mostly be used in specialized industry segments only. Is<o:p></o:p></span></pre>
                <pre><span lang="EN-US">there anything in the document that would make the idea less suitable<o:p></o:p></span></pre>
                <pre><span lang="EN-US">for other radio technologies, for example BTLE?<o:p></o:p></span></pre>
              </blockquote>
              <pre><span lang="EN-US">Potentially the proposed solution can work on every stack you like. So<o:p></o:p></span></pre>
              <pre><span lang="EN-US">you can do an implementation independently of IEEE 802.15.4.<o:p></o:p></span></pre>
              <pre><span lang="EN-US">We put IEEE 802.15.4 there, because our used stack (BLIP) uses it.<o:p></o:p></span></pre>
              <blockquote style="margin-top:5.0pt;margin-bottom:5.0pt">
                <pre><span lang="EN-US">2) The assumed network stack does not show 6lowpan. Was this intentional?<o:p></o:p></span></pre>
              </blockquote>
              <pre><span lang="EN-US">Same as above. You can use the stack you want. So also 6lowpan can be<o:p></o:p></span></pre>
              <pre><span lang="EN-US">used. It depends n you what you require and what you want to support.<o:p></o:p></span></pre>
              <blockquote style="margin-top:5.0pt;margin-bottom:5.0pt">
                <pre><span lang="EN-US">3) You show RPL in the stack and I was wondering whether you assume it<o:p></o:p></span></pre>
                <pre><span lang="EN-US">being mandatory to implement for your assumed architecture? It does not<o:p></o:p></span></pre>
                <pre><span lang="EN-US">seem to show up elsewhere in the document. It appears to be irrelevant<o:p></o:p></span></pre>
                <pre><span lang="EN-US">for your design.<o:p></o:p></span></pre>
              </blockquote>
              <pre><span lang="EN-US">RPL was just mentioned due to our other publications. Currently our plan<o:p></o:p></span></pre>
              <pre><span lang="EN-US">is to change to RPL (CoAP) in the future.<o:p></o:p></span></pre>
              <blockquote style="margin-top:5.0pt;margin-bottom:5.0pt">
                <pre><span lang="EN-US">4) Subscriber identity: You write --<o:p></o:p></span></pre>
                <pre><span lang="EN-US">"<o:p></o:p></span></pre>
                <pre><span lang="EN-US">&nbsp;&nbsp; The identity of a default subscriber is usually preconfigured on a<o:p></o:p></span></pre>
                <pre><span lang="EN-US">&nbsp;&nbsp; publisher before it is deployed.<o:p></o:p></span></pre>
                <pre><span lang="EN-US">"<o:p></o:p></span></pre>
                <pre><span lang="EN-US"><o:p>&nbsp;</o:p></span></pre>
                <pre><span lang="EN-US">Could you explain more what you assume is pre-configured and where it is<o:p></o:p></span></pre>
                <pre><span lang="EN-US">preconfigured?<o:p></o:p></span></pre>
              </blockquote>
              <pre><span lang="EN-US">Here pre-configures means that our devices are equipped with the<o:p></o:p></span></pre>
              <pre><span lang="EN-US">certification during compiling and programming them before deployment.<o:p></o:p></span></pre>
              <pre><span lang="EN-US">This is due to the application scenario we support at the moment. Before<o:p></o:p></span></pre>
              <pre><span lang="EN-US">deploying the device you have to run to steps: First creation of<o:p></o:p></span></pre>
              <pre><span lang="EN-US">certificate, and second compiling code and play it on the device.<o:p></o:p></span></pre>
              <blockquote style="margin-top:5.0pt;margin-bottom:5.0pt">
                <pre><span lang="EN-US">I would also suggest to avoid the term subscriber since it has two other<o:p></o:p></span></pre>
                <pre><span lang="EN-US">meanings that might confuse:<o:p></o:p></span></pre>
                <pre><span lang="EN-US"> a) The term subscriber is often used in context of telecommunication as<o:p></o:p></span></pre>
                <pre><span lang="EN-US">the user who has a contract with a telecommunication operator.<o:p></o:p></span></pre>
                <pre><span lang="EN-US"> b) The second use is in context of protocols that use asynchronous<o:p></o:p></span></pre>
                <pre><span lang="EN-US">communication (like XMPP).<o:p></o:p></span></pre>
                <pre><span lang="EN-US"><o:p>&nbsp;</o:p></span></pre>
                <pre><span lang="EN-US">I believe your notion of subscriber does not relate to those two<o:p></o:p></span></pre>
                <pre><span lang="EN-US">existing uses. I guess you are more using the term subscriber to refer<o:p></o:p></span></pre>
                <pre><span lang="EN-US">to a device that wants some data from a sensor. Is this correct?<o:p></o:p></span></pre>
              </blockquote>
              <pre><span lang="EN-US">Thanks for the hint. Yes you are right. The subscriber should be a<o:p></o:p></span></pre>
              <pre><span lang="EN-US">device that wants data from the sensor.<o:p></o:p></span></pre>
              <pre><span lang="EN-US">Usually this is one outside of the WSN. Do you have a suggestion for new<o:p></o:p></span></pre>
              <pre><span lang="EN-US">name?<o:p></o:p></span></pre>
              <blockquote style="margin-top:5.0pt;margin-bottom:5.0pt">
                <pre><span lang="EN-US">5) Roles in your architecture.<o:p></o:p></span></pre>
                <pre><span lang="EN-US"><o:p>&nbsp;</o:p></span></pre>
                <pre><span lang="EN-US">It seems that you assume that the IoT devices are publishers and that<o:p></o:p></span></pre>
                <pre><span lang="EN-US">there are subscribers who talk to these publishers. In some other cases<o:p></o:p></span></pre>
                <pre><span lang="EN-US">I have seen architectures where the IoT devices (sensors) upload the<o:p></o:p></span></pre>
                <pre><span lang="EN-US">data to some servers without having to act as servers themselves. In<o:p></o:p></span></pre>
                <pre><span lang="EN-US">your architecture it feels like the sensor nodes implement the<o:p></o:p></span></pre>
                <pre><span lang="EN-US">server-side functionality<o:p></o:p></span></pre>
              </blockquote>
              <pre><span lang="EN-US">That was not our intention.<o:p></o:p></span></pre>
              <pre><span lang="EN-US">Our network has push characteristics up to the server. Data publishing<o:p></o:p></span></pre>
              <pre><span lang="EN-US">runs over server, because it has more resources and, therefore, can<o:p></o:p></span></pre>
              <pre><span lang="EN-US">handle requests better. It is the gate to the world.<o:p></o:p></span></pre>
              <pre><span lang="EN-US">Pull is only performed if you require data (measurements) at a time that<o:p></o:p></span></pre>
              <pre><span lang="EN-US">is not pre-defined.<o:p></o:p></span></pre>
              <blockquote style="margin-top:5.0pt;margin-bottom:5.0pt">
                <pre><span lang="EN-US">In Section 4.2.2 you write that you recommend an OpenSSL implementation<o:p></o:p></span></pre>
                <pre><span lang="EN-US">on the server side but the server-side would be the IoT device. While it<o:p></o:p></span></pre>
                <pre><span lang="EN-US">would be inappropriate to recommend a specific implementation in an IETF<o:p></o:p></span></pre>
                <pre><span lang="EN-US">draft/RFC it also raises the questions about the expectations on the<o:p></o:p></span></pre>
                <pre><span lang="EN-US">server-side.<o:p></o:p></span></pre>
              </blockquote>
              <pre><span lang="EN-US">Thanks for the hint.<o:p></o:p></span></pre>
              <pre><span lang="EN-US">We use OpenSSL on the server but not within the WSN. OpenSSL is used<o:p></o:p></span></pre>
              <pre><span lang="EN-US">especially for managing rights, requests, and certificates.<o:p></o:p></span></pre>
              <blockquote style="margin-top:5.0pt;margin-bottom:5.0pt">
                <pre><span lang="EN-US">6. Certificate content<o:p></o:p></span></pre>
                <pre><span lang="EN-US"><o:p>&nbsp;</o:p></span></pre>
                <pre><span lang="EN-US">In Section 4.2.2 you describe the content of a certificate and you<o:p></o:p></span></pre>
                <pre><span lang="EN-US">indicate that the commonName is set to "localhost". It seems to be<o:p></o:p></span></pre>
                <pre><span lang="EN-US">useless to include this in the certificate since a CA would not be able<o:p></o:p></span></pre>
                <pre><span lang="EN-US">to verify this identity information nor would any party verifying it be<o:p></o:p></span></pre>
                <pre><span lang="EN-US">able to use it in a meaningful way.<o:p></o:p></span></pre>
              </blockquote>
              <pre><span lang="EN-US">Localhost in our case is a special IP address (here: sink). You are<o:p></o:p></span></pre>
              <pre><span lang="EN-US">right, we should rename it and make clear that it is an IP address. So<o:p></o:p></span></pre>
              <pre><span lang="EN-US">you can set is like you want.<o:p></o:p></span></pre>
              <blockquote style="margin-top:5.0pt;margin-bottom:5.0pt">
                <pre><span lang="EN-US">It also seems to be in violation of what you write in Section 5.2 where<o:p></o:p></span></pre>
                <pre><span lang="EN-US">you state that "every publisher in the network MUST have an unique<o:p></o:p></span></pre>
                <pre><span lang="EN-US">identity.".<o:p></o:p></span></pre>
                <pre><span lang="EN-US"><o:p>&nbsp;</o:p></span></pre>
                <pre><span lang="EN-US">You also indicated more complete information for inclusion in the<o:p></o:p></span></pre>
                <pre><span lang="EN-US">certificate but it is not clear to me what purpose it serves. Could you<o:p></o:p></span></pre>
                <pre><span lang="EN-US">explain?<o:p></o:p></span></pre>
              </blockquote>
              <pre><span lang="EN-US">Will do it asap.<o:p></o:p></span></pre>
              <blockquote style="margin-top:5.0pt;margin-bottom:5.0pt">
                <pre><span lang="EN-US">7. Privacy<o:p></o:p></span></pre>
                <pre><span lang="EN-US"><o:p>&nbsp;</o:p></span></pre>
                <pre><span lang="EN-US">In Section 5 you indicate some privacy related aspects and you hint to "<o:p></o:p></span></pre>
                <pre><span lang="EN-US">access regulations based on legal and regulative implications". Could<o:p></o:p></span></pre>
                <pre><span lang="EN-US">you briefly explain what those requirements are?<o:p></o:p></span></pre>
              </blockquote>
              <pre><span lang="EN-US">This part we put in due to the deployment and project relations we are<o:p></o:p></span></pre>
              <pre><span lang="EN-US">running at the moment.<o:p></o:p></span></pre>
              <pre><span lang="EN-US">Here it means that not every device can be able to access the data, for<o:p></o:p></span></pre>
              <pre><span lang="EN-US">example, due to legal issues in the region (EU, CH, US rights).<o:p></o:p></span></pre>
              <pre><span lang="EN-US">This has to be stored central in the network and it has to be checked<o:p></o:p></span></pre>
              <pre><span lang="EN-US">before giving access and creating the corresponding access ticket.<o:p></o:p></span></pre>
              <pre><span lang="EN-US">Here we refer to the following publications:<o:p></o:p></span></pre>
              <pre><span lang="EN-US"><o:p>&nbsp;</o:p></span></pre>
              <pre><span lang="EN-US">Radhika Garg, Corinna Schmitt, Burkhard Stiller: /Investigating<o:p></o:p></span></pre>
              <pre><span lang="EN-US">Regulative Implications for User-generated Content and a Design<o:p></o:p></span></pre>
              <pre><span lang="EN-US">Proposal/; Degruyter, PIK-Praxis der Informationsverarbeitung und<o:p></o:p></span></pre>
              <pre><span lang="EN-US">Kommunikation, Vol. 36, No. 4, December 2013, ISSN 0930-5157, pp 1&#8211;11.<o:p></o:p></span></pre>
              <pre><span lang="EN-US">doi:10.1515/pik-2013-0042 <a moz-do-not-send="true" href="http://dx.doi.org/10.1515/pik-2013-0042">&lt;http://dx.doi.org/10.1515/pik-2013-0042&gt;</a> URL:<o:p></o:p></span></pre>
              <pre><span lang="EN-US"><a moz-do-not-send="true" href="http://www.degruyter.com/view/j/piko.ahead-of-print/pik-2013-0042/pik-2013-0042.xml">http://www.degruyter.com/view/j/piko.ahead-of-print/pik-2013-0042/pik-2013-0042.xml</a><o:p></o:p></span></pre>
              <pre><span lang="EN-US"><o:p>&nbsp;</o:p></span></pre>
              <pre><span lang="EN-US">Radhika Garg, Christos Tsiaras, Burkhard Stiller, Corinna Schmitt,<o:p></o:p></span></pre>
              <pre><span lang="EN-US">Daniel D&ouml;nni: /Deliverable D7.1 - Basics, Requirements, Scenarios, and<o:p></o:p></span></pre>
              <pre><span lang="EN-US">Architecture: In FLAMINGO/; Radhika Garg (Edt.), Z&uuml;rich, Switzerland,<o:p></o:p></span></pre>
              <pre><span lang="EN-US">October 2013<o:p></o:p></span></pre>
              <blockquote style="margin-top:5.0pt;margin-bottom:5.0pt">
                <pre><span lang="EN-US">8. Use Cases.<o:p></o:p></span></pre>
                <pre><span lang="EN-US"><o:p>&nbsp;</o:p></span></pre>
                <pre><span lang="EN-US">I suggest to omit the use cases from the document since the description<o:p></o:p></span></pre>
                <pre><span lang="EN-US">is too brief to be useful. A small remark: From my work in the emergency<o:p></o:p></span></pre>
                <pre><span lang="EN-US">services environment I had gotten the impression that there are no plans<o:p></o:p></span></pre>
                <pre><span lang="EN-US">to take sensor input directly when initiating alerts. In fact, sensor<o:p></o:p></span></pre>
                <pre><span lang="EN-US">alerts do rarely even get directly to the emergency services authorities<o:p></o:p></span></pre>
                <pre><span lang="EN-US">but are rather pre-processed by an intermediate organization (by<o:p></o:p></span></pre>
                <pre><span lang="EN-US">humans). Maybe you have spoken with other people, who have different<o:p></o:p></span></pre>
                <pre><span lang="EN-US">plans. Where did you got your information from?<o:p></o:p></span></pre>
              </blockquote>
              <pre><span lang="EN-US">This section is based on discussion with our project partners within<o:p></o:p></span></pre>
              <pre><span lang="EN-US">SmartenIT (<a moz-do-not-send="true" href="http://www.smartenit.eu">www.smartenit.eu</a>) and Flamingo ( <a moz-do-not-send="true" href="http://www.fp7-flamingo.eu">http://www.fp7-flamingo.eu</a>).<o:p></o:p></span></pre>
              <pre><span lang="EN-US"><a moz-do-not-send="true" href="http://www.fp7-flamingo.eu">&lt;http://www.fp7-flamingo.eu&gt;</a><o:p></o:p></span></pre>
              <pre><span lang="EN-US"><o:p>&nbsp;</o:p></span></pre>
              <blockquote style="margin-top:5.0pt;margin-bottom:5.0pt">
                <pre><span lang="EN-US">9. Architecture<o:p></o:p></span></pre>
                <pre><span lang="EN-US"><o:p>&nbsp;</o:p></span></pre>
                <pre><span lang="EN-US">Figure 3 shows the architecture but it is a bit confusing since it is<o:p></o:p></span></pre>
                <pre><span lang="EN-US">not clear what the boxes and the lines mean. The publisher is a box<o:p></o:p></span></pre>
                <pre><span lang="EN-US">separate from the sensors and from the earlier description I thought<o:p></o:p></span></pre>
                <pre><span lang="EN-US">that the sensors are actually the publishers. Furthermore, the gateway<o:p></o:p></span></pre>
                <pre><span lang="EN-US">was not discussed as a role up to that point in the document. The<o:p></o:p></span></pre>
                <pre><span lang="EN-US">gateway shows up in Section 5.3 and its role confuses me. You write:<o:p></o:p></span></pre>
                <pre><span lang="EN-US"><o:p>&nbsp;</o:p></span></pre>
                <pre><span lang="EN-US">"&nbsp; A sensor node has published its data, which is transmitted in<o:p></o:p></span></pre>
                <pre><span lang="EN-US">&nbsp;&nbsp; direction to the global sink (cf. Figure 3 where global sink is<o:p></o:p></span></pre>
                <pre><span lang="EN-US">&nbsp;&nbsp; located in the gateway component).<o:p></o:p></span></pre>
                <pre><span lang="EN-US">"<o:p></o:p></span></pre>
                <pre><span lang="EN-US"><o:p>&nbsp;</o:p></span></pre>
                <pre><span lang="EN-US">Does the sensor publish the data at the gateway? From the earlier<o:p></o:p></span></pre>
                <pre><span lang="EN-US">sections I thought that the subscriber talks to the publisher instead.<o:p></o:p></span></pre>
                <pre><span lang="EN-US">Is the gateway the subscriber? Why doesn't the sensor uploads the data<o:p></o:p></span></pre>
                <pre><span lang="EN-US">to some server instead (which is frequently done in today's IoT<o:p></o:p></span></pre>
                <pre><span lang="EN-US">deployments).<o:p></o:p></span></pre>
              </blockquote>
              <pre><span lang="EN-US">Lots of comments.<o:p></o:p></span></pre>
              <pre><span lang="EN-US">I will address and clarify them asap.<o:p></o:p></span></pre>
              <pre><span lang="EN-US">Furthermore, I will add a legend to the Figure and perhaps modify it<o:p></o:p></span></pre>
              <pre><span lang="EN-US">based on you aforementioned comments.<o:p></o:p></span></pre>
              <blockquote style="margin-top:5.0pt;margin-bottom:5.0pt">
                <pre><span lang="EN-US">Why do you call the entire document "two-way authentication" when the<o:p></o:p></span></pre>
                <pre><span lang="EN-US">the two way authentication is just one small part of the overall<o:p></o:p></span></pre>
                <pre><span lang="EN-US">authentication procedure. In fact the two-way authentication is used<o:p></o:p></span></pre>
                <pre><span lang="EN-US">between the subscriber and the access control server (as shown in Figure<o:p></o:p></span></pre>
                <pre><span lang="EN-US">4), and between the publisher and the gateway. Furthermore, there has to<o:p></o:p></span></pre>
                <pre><span lang="EN-US">be some authentication between the subscriber and the publisher as well<o:p></o:p></span></pre>
                <pre><span lang="EN-US">(at least I hope so).<o:p></o:p></span></pre>
                <pre><span lang="EN-US"><o:p>&nbsp;</o:p></span></pre>
                <pre><span lang="EN-US">What is the purpose of the access ticket? It shows up in Section 5.3 and<o:p></o:p></span></pre>
                <pre><span lang="EN-US">I wonder why there is a need for an access ticket when the two parties<o:p></o:p></span></pre>
                <pre><span lang="EN-US">(subscriber and publisher) already have a certificate. Why cannot you<o:p></o:p></span></pre>
                <pre><span lang="EN-US">use the certificate for authentication with the publisher right away?<o:p></o:p></span></pre>
                <pre><span lang="EN-US"><o:p>&nbsp;</o:p></span></pre>
                <pre><span lang="EN-US">Where do you see the access control server being deployed? Is this an<o:p></o:p></span></pre>
                <pre><span lang="EN-US">entity in the local network or something you would have on the Internet?<o:p></o:p></span></pre>
                <pre><span lang="EN-US"><o:p>&nbsp;</o:p></span></pre>
                <pre><span lang="EN-US">Why does the publisher have to authenticate to the gateway? From Figure<o:p></o:p></span></pre>
                <pre><span lang="EN-US">4 it is not clear whether the gateway is just an optional component or<o:p></o:p></span></pre>
                <pre><span lang="EN-US">an integral part of the architecture.<o:p></o:p></span></pre>
                <pre><span lang="EN-US"><o:p>&nbsp;</o:p></span></pre>
                <pre><span lang="EN-US">The document does not explain what the access token is and how it is<o:p></o:p></span></pre>
                <pre><span lang="EN-US">exchanged between the subscriber and the publisher.<o:p></o:p></span></pre>
                <pre><span lang="EN-US"><o:p>&nbsp;</o:p></span></pre>
                <pre><span lang="EN-US">Btw, the term CA standards for Certification Authority rather than<o:p></o:p></span></pre>
                <pre><span lang="EN-US">Certificate Authority.<o:p></o:p></span></pre>
              </blockquote>
              <pre><span lang="EN-US"><o:p>&nbsp;</o:p></span></pre>
              <pre><span lang="EN-US">Will be addressed soon.<o:p></o:p></span></pre>
              <blockquote style="margin-top:5.0pt;margin-bottom:5.0pt">
                <pre><span lang="EN-US">10. Hardware requirements.<o:p></o:p></span></pre>
                <pre><span lang="EN-US"><o:p>&nbsp;</o:p></span></pre>
                <pre><span lang="EN-US">Hardware requirements typically are not appropriate for IETF documents.<o:p></o:p></span></pre>
                <pre><span lang="EN-US">While you make the argument that an RSA-based public key cryptosystem is<o:p></o:p></span></pre>
                <pre><span lang="EN-US">good enough from a performance point of view the currently mandatory<o:p></o:p></span></pre>
                <pre><span lang="EN-US">ciphersuites used in CoAP are based on ECC (for those that rely on<o:p></o:p></span></pre>
                <pre><span lang="EN-US">asymmetric crypto). While having hardware support for key storage is a<o:p></o:p></span></pre>
                <pre><span lang="EN-US">great idea I was wondering how much your architecture actually relies on<o:p></o:p></span></pre>
                <pre><span lang="EN-US">it. My impression that it would work fine just without a TPM chip. But<o:p></o:p></span></pre>
                <pre><span lang="EN-US">you might have more hardware experience than I have. Could you point me<o:p></o:p></span></pre>
                <pre><span lang="EN-US">to some hardware that you have in mind using?<o:p></o:p></span></pre>
                <pre><span lang="EN-US"><o:p>&nbsp;</o:p></span></pre>
              </blockquote>
              <pre><span lang="EN-US">We put this section for completeness and to show that an implementation<o:p></o:p></span></pre>
              <pre><span lang="EN-US">exists.<o:p></o:p></span></pre>
              <pre><span lang="EN-US">Concerning sensor nodes and TPM we are using OPAL from CSIRO. Trusting<o:p></o:p></span></pre>
              <pre><span lang="EN-US">Computing becomes relevant nowadays when thinking about securing data.<o:p></o:p></span></pre>
              <pre><span lang="EN-US">Drawback is that if the TPM chip is broken or you change something<o:p></o:p></span></pre>
              <pre><span lang="EN-US">during booting everything is lost. Advantage is that the storage root<o:p></o:p></span></pre>
              <pre><span lang="EN-US">key is stored safely and only derivates are used for your applications.<o:p></o:p></span></pre>
              <pre><span lang="EN-US"><o:p>&nbsp;</o:p></span></pre>
              <pre><span lang="EN-US">Hope to answer most important questions or comments now. Others will be<o:p></o:p></span></pre>
              <pre><span lang="EN-US">addressed soon.<o:p></o:p></span></pre>
              <pre><span lang="EN-US">You can also talk to me during IETF in London.<o:p></o:p></span></pre>
              <pre><span lang="EN-US"><o:p>&nbsp;</o:p></span></pre>
              <pre><span lang="EN-US">Regards,<o:p></o:p></span></pre>
              <pre><span lang="EN-US">Corinna<o:p></o:p></span></pre>
              <pre><span lang="EN-US"><o:p>&nbsp;</o:p></span></pre>
              <pre><span lang="EN-US"><o:p>&nbsp;</o:p></span></pre>
              <pre><span lang="EN-US"><o:p>&nbsp;</o:p></span></pre>
              <pre><span lang="EN-US">_______________________________________________<o:p></o:p></span></pre>
              <pre><span lang="EN-US">Ace mailing list<o:p></o:p></span></pre>
              <pre><span lang="EN-US"><a moz-do-not-send="true" href="mailto:Ace@ietf.org">Ace@ietf.org</a><o:p></o:p></span></pre>
              <pre><span lang="EN-US"><a moz-do-not-send="true" href="https://www.ietf.org/mailman/listinfo/ace">https://www.ietf.org/mailman/listinfo/ace</a><o:p></o:p></span></pre>
              <pre><span lang="EN-US"><o:p>&nbsp;</o:p></span></pre>
            </blockquote>
            <pre><span lang="EN-US"><o:p>&nbsp;</o:p></span></pre>
            <p class="MsoNormal"><span lang="EN-US"><br>
                <br>
                <br>
                <o:p></o:p></span></p>
            <pre><span lang="EN-US">_______________________________________________<o:p></o:p></span></pre>
            <pre><span lang="EN-US">Ace mailing list<o:p></o:p></span></pre>
            <pre><span lang="EN-US"><a moz-do-not-send="true" href="mailto:Ace@ietf.org">Ace@ietf.org</a><o:p></o:p></span></pre>
            <pre><span lang="EN-US"><a moz-do-not-send="true" href="https://www.ietf.org/mailman/listinfo/ace">https://www.ietf.org/mailman/listinfo/ace</a><o:p></o:p></span></pre>
          </blockquote>
          <p class="MsoNormal" style="margin-bottom:12.0pt"><span
              lang="EN-US"><o:p>&nbsp;</o:p></span></p>
          <div>
            <p class="MsoNormal"><span lang="EN-US">-- <br>
                <img id="_x0000_i1029"
                  src="cid:part15.05020303.08060204@ifi.uzh.ch"
                  border="0" height="160" width="296"><o:p></o:p></span></p>
          </div>
        </div>
      </div>
      <br>
      <fieldset class="mimeAttachmentHeader"></fieldset>
      <br>
      <pre wrap="">_______________________________________________
Ace mailing list
<a class="moz-txt-link-abbreviated" href="mailto:Ace@ietf.org">Ace@ietf.org</a>
<a class="moz-txt-link-freetext" href="https://www.ietf.org/mailman/listinfo/ace">https://www.ietf.org/mailman/listinfo/ace</a>
</pre>
    </blockquote>
    <br>
    <br>
    <div class="moz-signature">-- <br>
      <img src="cid:part16.03030405.07000806@ifi.uzh.ch" border="0"></div>
  </body>
</html>

--------------040403090101020709030709
Content-Type: image/png
Content-Transfer-Encoding: base64
Content-ID: <part15.05020303.08060204@ifi.uzh.ch>

iVBORw0KGgoAAAANSUhEUgAAASgAAACgCAIAAAAw8WZPAAAAAXNSR0IArs4c6QAAAARnQU1B
AACxjwv8YQUAAAAgY0hSTQAAeiYAAICEAAD6AAAAgOgAAHUwAADqYAAAOpgAABdwnLpRPAAA
buNJREFUeF7t3Qe8FtXRP3CT901i2htTTVeTGE035Z+YZkxijFFjQcVKVXrvvffee6/Se+9I
R0CahSqCgtJBQKTl/9099y4P9yIiEOXq83zwus8+Z8+ePTtzZs7Mb2Y+9p///OeKd/uMGTNm
5cqVWq1atWr//v3v1jz9e3oGPnIzcOWVV/7ud7/z2DfeeON9993n67tMAcZ7p8/s2bMfeeSR
q666Skd14s/o0aOdTH/SM5CegSwzMHny5MAjWAbXYRnMcg7muuKsvz333HOuvPXWW59++ul9
+/ad4/r0T+kZSM9A9hnAdTjopptuwp9nnZ+zMB5mu/nmm8/Nr+m5Ts9AegbedQYIMNKLGMze
MivjVa1alax866233rXTdIP0DKRn4HxmIOifWXjqDMbDdRqdOnXqZPqTnoH0DFyKGcBNmLNP
nz40z1QuPc14NEx86bc0412KCU/3kZ6BaAYC4/k0adKEYEt4L4PxKKP2dUEaphkvTTLpGbhU
M5AwHs4i2Ii3wHsZjJdq/bxgxsvk7XPovWkl9lK90HQ/OWMGUhlvx44d1157bRBvEeNxQdxx
xx0Ju7wnxjtx4sTJEyeSa/fs2b1mzZrp06YPHzp02JAh/jmYOmUyifrGG28kzU6eyBmzlh5l
egYucgZSGQ/9ly1btk2bNhmMh+vw3oUxXrhq586dkyZNatyoYY1q1apXq1anVq0G9eo1rFu3
ob/16tWrU6d61arVq1WvX6/+6FGjt219NVx1kY+Uvjw9A5f/DGRhvJdffpnQixiP4INNSbV1
no/EI+hsBl2/ffuOnj17li9XrmrlKhivaZMmXTt3fnrwoKlTpsyeNXvO7NnTp00bNnRoj27d
WjRv3rhhw+pVq5cuWbpTx46bN28K7KerSGymP+kZ+DDOQBbGQ/CMKYsWLboiMWa+J4kXGGb0
qFHlypatVrVqy+YtunbpsnDBgtkzZo4bOzb7Jm/evGecX75sWa+ePTWuXatW2dKl+/fre/jw
YY2PH08z3oeR6NLPlGLVTJgiIMuuCP9LZZVzSzwsovGunTsbN2pUsUKF5k2bDujf74Xnn8c8
zg8cMLBCuXKv79hhzhM5dvTo2y2bN2/YoMHxY8e12bhhw/BhQ1s0bVa1cuWaNWps2rgxrXam
SfTDOgPZJV5Ak12RP39+3r3zZzwtX968mW5Zr27dNq3bLFiwYPOmTXv37Hb+hRdeaFCvfptW
rVu1aJnwkoO5s+c4o/3gQQN9XfbssmeXLiX9Onbo0KhRw9IlSzr+b8i9YPi55IbU49aY4yfi
5enSKclRT8czPD5pj86HiAuzMx49k7Z5RRbLCgY4h8Tz6ytbtpQpXTrs5ba8vMWZwQMHkn57
du/R47/vvPPfd92FLZ0/cuTI4UOHHIwaOfLef//7zjvuaNWyha99+vRt3qz59te2b33llT69
e7do1qxYkaKB984x4cnSENqkPs/5X3VJXijGyzKYLF8v6C6RvvD228defOGFtWvWHHrzzfPZ
aV/QjdIXva8zkJ3xgn3lCiDOLADqs77y2JryH5EKNnXNmzXr3Knj/v37aJj169WbMX0GY+bK
5cunTJ78VMGCRQsXLl60qM3bcyuemzljhqt6dutWMH/+J/PntxvkynDJvr372rZp88zcuW+8
/kbMe81Lliix5eWXw9Yxu63l2LHjSxYvNs6DBw8ans+xt48tXrSI8ebNN98860Rqc/To0WZN
m+Z54vF169ZdQjrW1fLlyx95ODeJ/fbbb7u7UZHhe/fuveC7RPrC88/f8+9/f+H//u/zn//c
nDlz0ur3+8of/7WbXSzjRULm5Ek806RxEzZJTNK5c+eXXnypdMlSFM6li5doMGHcuP59+w3q
379mjeq7du3EVBs2rHfjwQMGdOvSuX/v3jWrVX/z4MG9+/Y9u2RJm9athw8btmDe/Igze/Zs
3bKVHeORw4dTN4cZwu3kyTffPPSrm276whe+sHbN2iBe9u8/8LOf/vSLX/wipgpSOhB9+DU8
LSfHN77+dfGIvXr0SG2TCMxwSTI1CdtEfcVdht6yCFhnmjZpqtsfXn/9gQMHjr711r3/vucr
X/7y2rXR2MJVZ3QV95X6ZrPcMQy+YIEC+rzt73+rVq3qhg0bLoyHQ1cXdu1/jfbesePsmsI7
jTx5rZdwkBc8S8mFyajO0VXyrpOHfW8Sz2Vjx4whslq3arV169Y1q1a3atmyc8eOc2bNInwi
Ujt5EkNWrVK1ZvXq+fPmxZlUphnTp1PMGjdswOJSrXLlgvny7969J2KJN97ApdOnTp01c2bb
1m22b9/eoV077r4e3bpHhH6md+HUyVOHDh36xc9//vnPfU6fmYy3/yc//jH58NJLEeNl/3jg
48feHjt6NA5n7EkaBHF61kvCSfvC1F+1T7ZeCR/a5TZv3oKEj9ofP/HTn/7ks5/97OZYYqcS
U1ATMroNojzlTJYx/PmPf/z85z+/efPm6PwF4dSzdHjBhBUT9wljiN7FRXzi53jHLXagyH37
9x858lbGHTMfIPWeYcYgLvbu3Xfs2LGLGE7GpfFDnX6lnvQ99RnGGAZ//Ngxo0rOvJPmleW9
nC/jRZR36hQzZrkyZVq1aLFkyeIN69e3b9vu9dffGDVixBtv7Iyf5MT+ffuKFylSqkSJ8mXL
3H7bbfx4M6ZNw0779u3Ndd99LCj8B84vmB+JuPBZtHDRYw8/XKRQ4SOHDlO0WjVv7vL16zdk
ed/uTnH91S9vuuqqLwSp4rP/wIGf/exnX/rSlzZu2Lh39+4qVau0bNmCCM11/3333ntP/379
XMU52aN791q1a7GjEstFixV1d+dPHD9OSyxUqBDLELZp367dnf/61x3//CdPo02pBtOmTS1W
tOjAAf1LlSzlV2cGDhjwQK5ct/7lFiYi82u0NarXGPL009aXEiVKkKsUxNy5czdu0mTcuHGF
Cxfu0rmLnr2fiRMnPvXUU8xXpihsDnfseB2Q4K4777rvnnt5Vg4dPvzKK6+UKF7i29/+1he+
8H+PPfaYTa+Rv1e20X79uvXlypUrUqRI2TJlFi9afDFsE+xSR986+p6IMkvjt98+ijTfiRxx
Ea/Sr3716+B/Mn6zWqVKlddefTXLuvP6668/kvvhv9zyl02bIt/vxQzJteSEV/PSSy8VLVLE
HSN6OG/W03j1qlVVqlTdtXMX/rnrzjvZJ+2ngEN2vrHzrK/swiVeWHL43+rWrt2zRw/W/0kT
Jgzo15/EM61+Oha74Xbv2tm+bZsmjRsVL1KU0Js0aSK6rFK58p7du/kMKlUoX71K5SqVKs5N
2b34SbfPPbdy8qRJWzZvfnrQ4LatW9uVvSfG44hH/V/60hc/9alPfe5zn/vaV79KYSMJly5Z
ao/32//3/3y1GwQMd/DUk0/pnF3nq1/56qc++ckVK1bQb50nTn/60586sINFA40bN3aMl/wl
5Ht07/Hxj30Md/36l78qXqyYHkYMH+Gnf99993MrVlxzzTWf/cxn3Vr7W//ylzGjR/vp61//
OsuTSb/9H7f72r170HVPbtu69ZY//9mZL171RQNwULRoUUP97ne+S2aSeKT67f/4x6HDkVHq
PVGY9rNmzvrSF7/YpHHjMqVKXfPda6ZNm5Zlrc0i6rN8zUIiDerXDyr6WT/n1hpcsn79+rxP
PHFg//7kQbL0w/b2veuus0JFciymMWTg8VetXJml5cL5C0y+peTc488+zuxEbzdeIF++l154
ccf2HTVq1CRCAg4k++esklCzMaNGf/5zn31126vWi+98+9tbt24bOWK4YdsdnPWVXTjjedp9
e/dWrVyJL47DAJXXrlmT6HtlyytBbQsikfb49KBBxYoUQXwMJ+PHje3SqXPRwkU2b9zUskWL
B+6/P+/jjzdt1IhBJfVNWOybN23WsWOHl1560Z6Q2aZyxYpbtkTG0sTEgmAPHz70q1/+8qpo
j5epah7YHyQe3WzrK1u9wv/5n//B2mYk1/33h30dLedvf/3rlZ/6FPfFiuXLceP1P/gByCjx
9bGPfezRRx5hSkXuv/rVr55fu3b5s8u+/73vfeMb39i9a1e7tm01+OY3vwlzQw0mD3XYrGmz
iHliNZXW/Yn//d+HHngAb6Own//sZ/afkDomgXB2U+179+q9Yd26r3z5K9ddey0pF15tgwYN
/PTYo4/ywcycMfNb3/qmUS1auNBk/u63/w83mh/KxQVAeXTuWur3ju2vOc6fL999993rYNu2
baR0o0aNyA2moA4dOljsKlWsNH78eL+aPQxWoWLFCRMmWEb7+/Tt1759+759+qD13/z611On
Th0zekzXLl3r16/ft29feweT7EldK+1VyxYtrarI9403XgdB7Na1K5EFR/HG66+b3s9+5jPl
ypazGw+i4PChw927dStXrvzokSMJ/0YNG331K1955OFHwoZWhzOmT0PKq1etHjpsWLeu3WrX
qt2nV6+XN7/M4/W1r32NimFuF8xfULlSJauz9/j2sbcZGgy1d+/e8+fPN+zWrVozmLOu165d
u3//fnQMQrJevegBJ0+afOjNQ7ZCn/70p5944gnaVvfu3V/dts19bRkqVKjYuWMncqxbNMJy
NlCJjhxeXLJDmThhwnXXXkOhe+CBB1CLm9Kzvvud79h9XGLGi5aiyZOrVanct3dvE2pZmj9v
Xs/uPRgVkiXZxBFfdWvXKl2iBN4rWCA/bHTtGjWeeOzxhfPnFy1cqFTxElTNxx99ZN68eanj
8wLwkvfXrk1b74+QbNywkYmM22RoAIHxfnnTTV+86iq6QZiIAwcO/uynP2Nc2bRxE7fEtddc
861vfSvMY4Xy5RE3kJq3/feY8RZRKU+cuOOfd2AnXPf44499/OMfR08jRowgJ6+++ms/+P73
se6nr7ySyFm/bl37du31QNsM96pZvYavhEm+vHkxcMJ4D+bK5cEt2L/+1a8w3sYYCeDTqVMn
7b1dmqQDil+w1Wh5+23/+N///d+pk6eElsyYH7viiqcHD3Z8y5//5BZWorO+v3eVfq7CeD/+
0Y3r173k2GMa1fbXXnvwgQdKly6NDRhvmIK+fvXX/3LLn8uXL2/GVj73HDpmMKtUsSLSIf//
9te/0R2KFyuKmH584423/f3v3pdrv//97wPhMiA98fjjjzz88E0///mePXtoB48/9pjO/3n7
7XT4z332s3nz5OFM+v3NN1tWSpUs8fWvX61zQsbg0bHjm37xi2rVql1//fVDhwxF93g7f778
mD+T8aYbxuqVq+jhN97ww6pVqnztq18Z0H+A4V199dWYbf78BT/+0Y95s/7+178ZCRv7d77z
bbxqOaMrff6zn9X5jTfeYCbDJYTkvGeeiVaW+Hk5kO1Hrv7a14x85IgRX/7SlxYvXITrvPpy
5cv36dW7Vo2aP/3xT9q2aQvnGI04/jAH7tu7J1CjiaXu6Wr2rJkF8hf49je/2aNHjxGB8V6+
1IxnUlq2bNmsSZNpU6fOnjWrQL78hZ58avOm6DanF+Z4E2jBo4K21rhp0+FDhloL8z6RZ+6c
udAtlhOYsjq1a82de4ahXCe4ZdCAAVga3VAz3Kh+3bpvHz29u4j2eIcOeWfUuUQPsdx+77rv
mcRXXtmC8a757ncxD1+iDpECcqcVZzDelVdivIgfOnZ03j7zuuuuu/GHN9iU2gqSk7RBK6tF
vXevXkOGDLEussdoSVC4yt2ZdpiUCEYnTTrl3rJH4sWM58W8GUnjq64KyoYP6f31q6/+7ne/
S9H9zGc+E7TrsOdElJ/8xCdmTJseWt59190f//jHRg4fbtfxpz/+0TpCfl4s470UMR440c2/
+x3z1be+8Y3q1asRgN/51rc2rN/wk5/8JISE/b9f/waxejSbAjveb3/725jtnnvuKVuGsh19
/n3nXcC3DpB4sVjBxsl2sLSeG274oZf1oxtvLFKoEBFHsg0aOJA2sW7dehTyg+99nwCc/8w8
rLt7d4SsoBQdPHDA5W7kq/UrX958NpA//clPpkyaFJ7XX+IUBa9ZvcpiUalSJWd+8Yufe4/0
+R//6Edert3NH3//B+fnzpn9/eu+x8LHrNWhfdRnty5db/7dzQ6KFStaqlQpBz/76U+s4wcP
HJw0cSK59K1vftMBU/uNN9yw6rmVa9aspoksXby4QH6mwLzhkd3rB9ddZ80KLOeVEQx5Hn+c
HiHsJrTBeFh9x47t48aOY2nXDDE4c4kZz51wfO1aNQkBhIXErZED+/c/cvjIGVvJmPEG9OvH
X3fLH/8oIqFVq1b0GS9m5PARsNF33XFH7vvvb1Cv7jPPnFY1g5pK139m9pxXX3112bPP2gKx
x9SqWdNXUiJZ5smKe/59D7q3CmK5I2+9xQNBdPzpD384fPgI1RTjURR37dplwKVLl4kYr3v3
LIxHInmvn/zkJzEbQ5GWtsX/8z8f/8Pv/0DHCNO6d89ef1u1aqkHARaBJmgsDvCbd+a8NXLK
pMmB8fhYvFpbxM9+9jMzZ8586+hRQ/VQeZ54gnS1M7zlT382gYm1wDvWAxsS4TNr1syvfvWr
FNpNmzYee/voJWG8SNWMTbhUuHz58nF+WpuEokTaY9++r732Ggq2uGjw29/8Bh0XLlS40FOF
xo8bT6ZhvHvvucci69djb79929/+1qhBzHiPPVayZElbod/+9rd0H4IRw8yZNfuGH/7Q47Rr
165bt+5Urx9eHzEeje5HN9zw+o7tkyZOuuGH16OKTMY7aHnq1DFikvzYLm9eKr3BkDxZGG/t
mtUYj2LpjtScXj17zJ8/z8xDbjA7sf1qz8/pdbNzSOM1NrbNWDdN4FtH3ipSuIi1wBnXDh40
GF8xoowbN55YmzB+PDObBZqoF7x23XXXLlm0mJvXJ7x9HwqdJZ5QDZYwBGrPXLBgweBAThiP
Yd80/uJnP7eg6Pa/wnicdZUqVOzfty/RRJR5+LlxxrIzlJ9Tp6KtUes2jz/yCFNPoSefZLKz
DbUXomHmfeLx+++55+EHHyhVongWVRNOSle8eeXLlitbqvTLmzaNGDacO962J7lFsO7QDEkP
VGtl/fGPf+yAAAxKmhWBpkcR4rjz9amnCvm1U4cOGA95OZ4XbywjGnr8CV/pmfNj/yEevuvO
aP/2zW9886+33oqSbM8MqWmTyLjCrBKuMvV/+P3v//ynPzn585/93F2gwx3f8c/bI9Pf0bf/
cdttvtqxMI1SuV1Cif30p690I8SdPIiDCRMm2ohrHGm2n/50tHVsEhmT7F5wL15lbcs6t++q
ZcYNXEXaXPWF/6tRowat8qc/+TGf/ltHjtx9513snLiOZ4V8u+GGG/51xx3aWIOsoZ733nvv
bdSwodEOHjTI17qxnCeBWYft8ZYsWfLQgw8SmJw6P/zh9XCGzlAR1730Em7MlStXv379vYXF
ixfT3J5f+/zY0WO+8bWrX3t1m/0IzblunXp8sJH0OHnKevrLm36h/x98/3vDhgy1xuknvMEw
/kzjynN01zKly7iEUIpcVnNm2w6w6onq5DtlD/vHP/7x8MMP79u3n6pJrLmWfmg5sI1kFi5e
vDgWcS0VhsXBIBs2aGjHMWrkKHa1a7/73WJFi8nR/OUvfXHJokVI9Jvf+EaFCuXJTLLOpvHv
f/ubBciON4iWQAPJMaqmVFvr+/Xrd813vst6BJjlzMZNZ4ccX6BxxS3ZAJh9Md7G9etNk72s
dTSb5fTU3j17atWoQdvs368/QUdjHD923LgxY7t37fbEo4/16tnLDpjUpnNnIayYc9bPmTnr
1a1bEcrkiROrValii5jaLIwe7z36yKM0qN/f/DtK7MQJE6MZOXmS6YLW7n1gJC3tCiypqJCk
kujCcsXOHhlFTv0H0gUNiRikT4Y+Ga8xmLn+/e9+h23sNo8fP0am5c2Td9SokWHSeRSQoAW1
RPHiwYPPKmMppQVYF/XDfkhJ++Mf/mBxpXlqsPWVLV48gYYWkwcJkpPZ84FcD+jt3nvu7dun
L/Jykt7VsH59BEFeZZvb8+O8k6dsd2vWqFmmTBnvi0IY6AWJoHVCb8yoUXjg5z//ueelyJFv
brRi+YqKFSsxhjVv3gwcp1evXjNmzAz384y2RowrWo6MzSFt2rTlzrELbdq0KdXLbNNrSpcq
jb6Z3CxPFDANoAvsAL3KLp0716hZ004s2SzR9umBQ4cMiZTPgwebNWuGl8Lz+mvRsR/zRiwT
4ydMwPyWLZYSYkqfNiMeiOOX8QPgnvT2pnhTV65cpQOLSPv2Hdgdhg0bzt5o9SS6Vz5na7Ky
YsWK7dq2a9q0mS+nTp4YNmxo5cqV586d26RJ02ARwUulSpVs2aI5FjJ7xhC2nYnCmbxBJ9nh
2Jm4o5cvX4ZaQD4YKfiHdu7cddYXd+GMN2rkCM9pO2TG+/XpQzcI+JIsH9qzrVqgVK+qZ4/u
S5csYSgfO2Yswg3nWVCQfhbGMzKq4+yZszp16EiVJbgtwEwj2ZuFTuyUCJlwHCGLjx9PlqXw
Nfzk48WEg6AuZsdYnnFh7BqJrzrt9c6Yej6tlMspk4Fb4saZ3Ub++miNDOexPVMNs0TcQ4aV
KBpqpgNdJ8k4Q4vw9UK57mTq06VOTnIXB5Re3kJrfGaD03OV2syDhDiSM06mTGY0pbGqknxQ
aXwy4yniB8qYRi/Fw3oXqSSYiiXIJKSM9kmz5InCGV1mecbk/SYHJzIHGRxd2T/ZZyk1f0Jq
e2/8bAve6YfKmMNMensnxPyFM97oUSObNGw4aOCANatXYyFCL9ipsjLe668PHjjA4rRg3ryh
Q4dWLF/e1q5e3ToWcraKFcuWPb92DRGRnfEisjtxgnmDJ501zBJr09+hfcSrZ9wiepWR3yKF
QDOwIGG9DCQb+zair5nH0fnIG5wZphS3cybTaXoiK946/JTKAKk3DbfMaKCnTIdK8s7sdkDG
f/Ob3/zPxz8ePGkp98q4NpXlkmdMHuFs7/t8zp3hBs4YZ+QGP33ezpxxclkmHj1pk9F7ZsvM
Z8zwFWUAieKOwin/S+YhzHP0Y+bf1DPJcWr7cDJz6s71aPFbzHiEjDd4+sKMyYxXtvCM8WsO
RynPknqD0/fNPJs8Vvxc5+tKT52qcNMwK9kf5mIYb0STBg1sABg/+vbuQ1PasX171oX51Enb
6B7du61du2bJ4iV0D1av4sWK534oN92M089+w1aYNynVgR5GqSsrIhvM1MmT165ebXfets3Z
GO98aO+cbc4hTM4qbcKUZZ+45GTWu8XtOSHs3Ig7bqjwdBc98EvWQdhRx+p5+vM+zcDFMN4o
sqtf374vb9o8fOgwaiToY3Z6YlRo3KD++LFjJk2YaBNFarEWCH+gNDLiUbvpkFx8z8zNsseL
hJgOqZqCD2wbJowf53bAIqkSL2gyWT6xKHv3JSqs08m1Z7kkFqRZnyhDrGUsDUGlJCoTXora
x4tw6gt0jl4wfuzYZUuXXjzW8ZKTRliUz2fSLvmtP7IdXjjjzZo1i0fO7o6Jn1zCVCReNhTv
qZ2vvzH06aeZJWV5GD9u3HPPrWCoFezHz8bzvmTxInFmAVR9pg4ZEf3uXbsF+DVt3Hj5smep
alUqVZaeLGmGUN566whQKLACRJx/0f9ff8NW0xJ+Pm/Utg0yo0XzFnrI3p6tr3jRYpCWYJ8Z
N7UTO3Vq5vTpDRvU50WwdWbCejh3boYZXgoGJCsFW47gpuyyI3V1OJ+xpdt8uGfgwhnvpRdf
tGGjZLKckntVK1WGLcimap7avXNnm9atGJHZLZk07QnFH4wYPnzqlEnMaM/MmQPCUrlChSyq
Jqai+SyYP09L1iHBdazD3AlgRwnjOXj22We5azm+v/+979/wwxt++hPW8p+wPmfdB57tHWoD
z816TgPs0L79GZfEu8ED+w/w7TA3c9QGPSwe1X969+x19113Pf/883//298pzLkffIiVuU2r
Vjf/9ndQS4zXwXvx4aab9NNd5AxcIOPZtRAIsGAd2rWN4NETJ/bt1WvksGEg3ll4jx8PQgUQ
wVatXp3anTq0nzVj+qwZM8SniwmaOmnStMmTy5YqlYrVjLekkcmLnXfixEmECfNuuzZtuCX4
W1IZD1CLP5S/FSry+ut/wOuNi8ZPiNCG4RPUp3DM4JYchzMEJgt7rvtzrVq5KiiHqXKJD5SR
nRvQEpN6vl+fvgBQrOr/uO0f856ZB3ixcOHC3j17Yjnu6V/8/BfBX3+RLyZ9+Yd7Bi6Q8QKN
Mkvy0tDWGC25E3r16EmyZaE5+h/n2/wFCwYNGkQWsX/CxYEOtG/Tlpth3JgxrNhdO3cJ+Npk
rh2/+MKLTRs3nT59OifysqXPRpCxevXejhDrGa0i5nz7bcIQcAyUjDMN1/3zn/90hhWUX5GM
1fTwkUP82pHR9QDZvA+wYMaM6Ry7RiKGCMNjpNdf3xFQzgsWzHeeXxV4JUBPOHO576iRTViA
ZkcgL+VvwRpvu+22alWr0YS5vAsXKgTnTYCDlYJZ7ty1K0H0fbipJ/10FzwDF8V406dOg9Vi
q+QlB03gN0wiwRMRQeJhMHEMUPDQJ3yRi+3rnn8eAA9Kk1bmQxcNEi/1s2fvXszTulVLTmeQ
P7Z4PsNEiMVSMXrqcAlNVYwCkMRS1ov//IfqG8D+jnfv3oU3YAi2bttmt/blL38ZWpIL+9NX
fgrAh5aoZfC589sKSvDVBzrp0KHDv/zlLwU6XHvtNeGk2KJFcTwbvzAMDe824QZ8LNo92l/u
3MlRy88bocMu+IWkL/xozMCFM575sQsSWQdrv3DBQqSPjnUnxiR8jsrRc+zY9ldf4zSHwo/5
oQ/XeWAVYTUCTMMxYRLhvk+eDFfF/44GnyZLyboXX6SsVixfAWIzizh1iX7hG/9yyy0YI8lH
OGDAAF/hVLS3KED04UlGIJLQpg4CS0YZ64ULBSx+/H8+PmvGTKoj5gTvgquIIi3mz+eWxHga
61zyeVApfYK8ZFkgsn+9rFwFHw0yznlPeeGMFywNZAvjXpVKlbgHunfp2kUIXdu2Hdu3jw/a
AUbyH1SqUKFzhw7du3QRU2eb17VTpy6dOrVs1kxcpgP/BA3Vr1vHgWtdqLEDpk6XQ8oBKHVo
115wQ3auCxIPCAhL/O63v2MFDWwwcOBAZ4SWOBa7ASKMozIZ79uEHkSSn/D2vffe94lPfILH
AtzUJaVKlEwYiWYKF0sGBldHk0YRUDOEJuS895we8WU2AxfOeIHoyROM0axxYzF1AszBncFZ
alStWrJYcdgUdsiSJYqTV+wiUoxxxLVo1hSXVqxQ3p4NrlrqB9wovV+F8uVEo8vCAjztwJap
fNmyMtuKCxbhDvgXAo5SZy+IRKBHGHAIY3HWCc9AtWKSggUKOmNrx/KZMJ4wEPbPkOKFQBYV
ivHIW+nMXAKV5nyYFPKQpcSFIdhPUJIGHirNeJcZDefI4VwU4wXeY9IUEsrMwJjO9gjNLEpN
zPi0KVMdkCQTxk9wnsSgjjKW3HfPPYLBxRAJNxRiSLUTAFq3Th0ijspXl+WzY0cxfngAZzYS
zFi/PvuHG2X18J44CZ4pegM/PFmwIMuJVWDXrt3YyW7QSeGYrqI3iuYWBRMkHsZjBQ3xYIHx
/vcT/wtC2bB+FAPONBJyfjLb4NjAeHzfacbLkdR9GQ/6Yhkv5r1TjRs1Jgrq1a3HrMevBRVF
HEWwzMaN+bKLFC4s8teBXH033nCj8BPmeDEX4tA3btwApSnEi+4HPoYnwcapdrff9neARior
BmYtlEkhOx4FMzCifupTnxRl873rrrWRu1702HXXiR9l5Rdf97Uog8DDbiTQTiiKZAc8H1/5
ylfiCL0Mxrvrrjvxm+Xg2aXP/t///Z9jO7q77767RrXqkaj88Y9lTAlRtqJX/Er8piXeZUzP
OWZol4DxdCHEA2JDkIHkFrAsQoDhbhkwJ44bB8zRo2vXIYMHyXriQIRbrH+W+MY3vl63Vi0h
RXJptmjalK+MRte+TRueCciPAX37yWUiaqNkyRJCE95pd4dp+bgF2tA2JbqQSuhrX/uquFtG
mqJFikoJwV5SoEAB2YfkPhAwwhopPYGgSRKPNkniiQoVqC+oxC369O4jJyet9cpPXVmyRMk3
3zwoQwTx+EKcwkyGGFbNd9pq5pgXnh7o5TEDl4DxgpWFIle2dJnmzZsjX3Aqhkr1Ejq1b1+m
ZKmunbrI605vnD51CiVT2pnyZcpiBtksbJzq162HY/3jKO/TsydoGBu9/EhqLURxbjHRv9Nc
SQYvLdTpj+Pt2wW5eCoBLMRvCKySzUGzYGt9fcfrYGU0yeNxrBAOZF8NAU1hy2ozKdAJPEAM
DCeBzjkJPCNbi2eEGk1jGi8P0s3Zo7gEjBcmIOK9ba8KJcRLHHpt2rQWB2R3JIpRRL1/XNJQ
woKgBQLLsCBHC1w1kWV/JcUFBJYNGKEnmR+/vA2eXNROnluvS6wpWQ7CeLJ8AuI5nEwc3Emb
yDNxZs3opJPgHkhtmbPfeXr0l8EMXDLGC2HUZAtZx1ApE96A/v1BsZIb0DzlgChfpsyTBQqo
RpLniTyMnPIOLJgXGet95JKQb4cuV61K1Tq1a2/bGqUGuwymKD2E9Axc+hm4ZIyXyD3cItIH
DlNFBF4v6BNGS0Dn3Xv2+NuwXv0QF8MKKlWE8jcRimXaNJ43fMiAoaIQeFeI/730j5vuMT0D
l8cMXGLGS0DJ9k7SYJJd0kKxpjSoX89XyWSLFy0yacL4qZMnVShXntuAVGzauBEHoH8ay/YX
cmCmue7yII/0KP5bM3CJGc8wQxR9YB6aJy8f/zhnQ/Wq1TgY+MS5B2r4r3JlTvOqVSqrSaIc
lwwuIuoyWC4leP+/9dzpftMz8IHOwKVnvNTHSQwSUJ2SK4p2le5TZJ0SsIIS4EXomcrHnbZb
XE4JET7Q95K++Yd8Bv67jJeksnkn82OmiEvnHfiQ01n68bLMwH+X8dLTnZ6B9AycdQbSjJcm
jPQMfAAzkGa8D2DS07dMz0Ca8dI0kJ6BD2AGPpKMF2w+mZ/zmfX31PhdO0y9eXbkZzgTRWOk
ZD4+V5+Z+Zsv7SDf9SnSDS5mBnI242VHY57PXCDULBe+61WXFqgZYOXJJwvvqScQygBHjBRV
s36XD7R3AjJVGyCN4X63Cbssfs/BjGfoEpCJJFDDxUeKlMT/fu5k95oJVgLR7tipk7ydIhIC
DPqdPn5dvWZNz569xDGcu+V5vlIDWLN6jVwZ3bt1X71qZZY+fVVnr3jxElteeeW8bnfqpIrN
hvf88y8YQMoacbqkxHkOLN3sfZuBHMx4KEwAqwKOii0LxpPWUshcVAg6qFyZJXgcJEIgZIuQ
4EwyCFnJfvXrX//gB98XOBsQaoFkIx0vviTjZCxNVFFWhW9BnE43yKLkwHGYxDNOuntSR+WM
WhnRANSjEkAo0k8JVaWJw02TSkO+CtuXSDcpc5tUPgoqaBhYUnbHVxVdRB7iPceyYsvYLWGh
XqU5DWWHo/7T4IT3javO40Y5m/EmTpz46U9/pkOHjmKO7vxXVEoS9jr1kYjBKNleZmklxA0L
qoghupdmQq22lzdvUhA8cNHevXtCEuhUPsSD5OquXTvXrn1exs5Enkj+Jy1nKr85Vv8tFLIy
87hFbbTdu/YEvTF5F9JVSMJ7y5/+BCAu6yGJnSDsDr75piSBcoS2adNGVC9MuQhj5cdSxyMD
m7sEXtW/TG6ORQkKXAxh9YraWVNCugqRh4Lyk6Lt50EP6Sbv0wzkbMZTAfiqL1wV6qdLMi0a
XeoHRRQ6deoo64TUg+o0pJZN10w9a/wp5C9hIQc4UCDS9773vWu+e43KktgMyrRixQq9evZU
JlL6sxUrlovKFeCLGYoUKdy9e/e//vWvxKZKLC6H9q5Vq5a6hJLJ537oIdyC4nPdd79q7IqD
Fi9WLMTmxlLq5JEjb/38pz8V6r569ZrTYvP48c6dOunwW9/6drkypQ3v61+7OveDD6ru4kYy
d5LkkkpJhJEvTx55QQUZlyhWTP4YgcUwd5s2bVLYUZZeqXu///3vKT4uf+GggYOUQZUlTVpR
9d+tGmmZ9z5x1Xnc5sPAeKHcHBnw6KOPUgiVDZMB6ZOf/MQd/7yjR48eGC8p3aORDLyf/MQn
1CVPpJCDfn37OVm3Tl3JNr/whf+rXKmiSPZrr/nu16++WtXyBfPnhwy5KJtodfBArlwSY197
zTWqr7BnPPrIw5/8xCeFIFavVv3jH/+YMoCkaL06dWfOnKXqqqroI4ZnVPQOeqngep1IAwMr
HmSsYoNXfvJTTxV8UuXuaVOnafCpT35SNaUuXbpKgla7dm3Z5tVzJ6uxk+f62BVXVK9eQ5Jf
Bd+HDx9uYPJ/eljppG6++feSO+XJk2fK5CmVKlV2F0XGW7RoIaY+bXc5D454n5p8mBjvP2qs
KyA+/5l5aj5ffbWK25EOqSxoQnC+ivdD06rUZzBeJAVOPProI6ovBKVOaW+UunHDevJHnukg
lDCeXCxKN6qy4kCKNCextxzvbx48IKyesMWBG+NkSnZofnVepRZK41VXXdWkcZQGNxJ48Rpw
7NjbzCo33vBD7KcT8vbJgk/qYf++DLy4pGxqNrwYB+Cr7S6HmtxnNrHKEjnTrl27r3z5SwKv
rA62uPICW2vcpWfPnn4lLV3L2uRY9hqrg7ymqXd/nygrfZtzzsCHgfGYWBAWmlZ73gIvhYQg
9x/dcOOBffsz9MlTGVusQJfIXXhuJCIzjSKqnP/5z3+Wy8zJwk899aMf3Sj3EsZTuzyD8fr1
y2S8ufKOKccZGO+mm26SEwnj/eRHP4qDel/A8HL4CryQRRffyu1px2XnmZB+YoORWub+++77
8he/+NILL+bO/fBvf/tbwjncDuMRtspq40kGmEJPPRUYz4LiV0kTv/XNb0iJv2nTxm9945tN
mzSWoA3jqVTuV1U+pc1evSra48ntfc13viNxcHjYNC9cPjPwYWC8efPmI6xhQ4dR6iRaJ0/y
5817w/U/3LN7DyqP0hYpdRJ/NGPHJxBQuaRjEY3LOX/0aJlSpSXefHnzywTSH/7w+7/+9dZX
trwsXyCKPyvjqeXgvLydzCSB8X584402cljl61+/WqVbumgkA48fW7Vq5Re/+MWmKRLPSfUk
QreyHhqMjEw1alT/3Oc+F1JWR4zXurXx2E8eOXLkhz+8PmE8i4JfW7Vs+c1vfF0WpsB4zZo2
SWU8aRaxuiVAyy1btmhQpnSa8S4fjssYSc5mPDsi4uuvf/ubRJ0sCtgAsSK4B+6//+qvfVUq
aHn7ZNGcOmVqEDiB94TCf+ELX7jh+uvt3277+9+nTJqocAIr4q9/9evb/n7b5z73WXwlv5hU
gY89+kjgBNYUN1q0cFHY49kKOkmgsce4S+7cD3FoOOAAkM+ziZj6GjVtGnPlyvWnP/5R+9o1
a4YBUDTfOnpU1m2bwwceeMBmjFDl+mCTNE7M9uCDD1WrUkXCqOBOOHT4kAd5/NFHidNvf/tb
IUVvwwYNlHRWHWXd+nWf+fSnpfpUJ8xdOnXqHD1dr16Ob/nzLSqHSvL7y5t+oe6KwkZvvnno
sqO+j/CAcjDjRX7t1avLly//1JNP2iMxLXJhoTx03LdvX5aSw4cPod1ixUvIlptpVMwogrdk
yRKZJvLlzVumTJmQoX3pkiWly5QhWzjBfN2/b7/k1gMHDoom6NSpRYsWlStXzsZJ/s9y5crL
FoOJevfu3ahRY0qgBBb16tU/fOiwnLlVqlRRBkwy3BbNmxmXHNgMnqHPsMezFRQK7KcCBQr2
6N6dwyNTFK9ma3niiTzdu3aTSLtq1ap6s+1knlGDRQJCObVlpqEvsr5UrVKN319hzWrVqqki
ZmDlK1ScN3++rrgWWrVspX9Zfd1UGaZiRYs1atgoLpT77jiYjzAvvK+PnoMZLwvwKoim4DtP
jsNBIu7iqWVXzJr8L0tXiWxMlZOOQ82jjM5jX3y4Y3KQfTazDCD49pOTKWPOejK6XVzMPdtd
Mu6LiVNulzGwgBA4PciUeyWmnfeVvtI3e4cZyMGM54kCICP5JM8YzoSv72RUOPdVSedJJ6kd
huPkLllud8avmbfJMv/Z736Wx3mHu5zrdpmPnPrUqe3TjHCZzEDOZrzMScyE88d5ls49s7Ek
OXviwFAUNsiZiA1SOzpxdgY+U5ZGl4QJvbC3G+RbKt8GGXthvSVXpfYQS9ywZFxst9lHFeT5
eRpPo3m+yAfLyZfnYMYLalXMJxnFzVNddmd9KciCnVAi97MSDaZl6oTw0HOis6WSLzY4gxmh
yQ4dCkBKn5DS9+jRt0DMLmA3hR/Azdhgjx59O1Bwklz0+LsFKZxDpgW7bpZBBlY0d5eWdJN5
i5Ljv8MKmDHUeInxXJd2ADmotxzMeIYu/bsqPw5e27Zt5MiRGStuCj1loUgvm9Fvfpy7OnlJ
QcI4M3bM2LJlynAqRILr5MlevXoqmB54+9CbB2vWqLEmNpkmOiFoJQxXEhWhKkP//v1nz5rZ
qWOnpNlZNcwst05t075t29WrVrmcfaV69erlyparUaPmwhicfVaqSgafNIjQ1plNiTWrABvp
nrgsWXhMZiR2I3lMzd5Zx5mI3NN3jKYoQ7s++zD8GkmwE6Bt3bt1MxWhWap+Hs6E/ScLsLLy
qswT6HGb00tA/MoybhIdXerV4TJhzhzMeN4fFOWwYcMcrF29mjkxxazwH2rMGV8zzQwd2rdX
F8VPQeVKbcNEmdRIQQ4lixd/KNcDwavO38BTFy5MPvsP7GeHJD/DGX48BlI2RgX9UpvFq39W
m0pQa8MnlSKV5gRDcRICUywSg+2Lz78AL5baONFmk5PPPPPMCy9EjrvsHzRdpnTpBPzN3aLP
uXPnrl+/HtLgrFOUejI1BiI5HwaQxZATfuUyZUNOFqPs42FP5tv0yM8tXx6gQhmTQPU9ccac
ZJmfy4RhLtUwcjbjATEHZti6ZUsokrx27RoHEF4onS9B4T4FjJT88ZxDnh4CzIXspPcM5G55
htKEhLT245l//ON2QOdDh4CJT1HzlLYtVrjIizFBk5PFihThxHPVwAEDXeK+Rw4dIiGbNWuu
OBmfOAwXMSUdfdPGjV0yccIEjgTgSb3Fmt6pdevWqT0GWaLw2PbtO/r169+sWTM98+D79O7Z
S4F1qLckGogDoGbNmkYCitm7V2+IcEU2ZSilD/MouESue9VdDB7MTb0xGG6xF9DhilhzpZBy
XO2G91SBAkHi+bRs0Tx1+bBqqJ7rcaZMnkT2zJgxs0uXLk0aN546dVrTpk1HjBjBf6j8k3ir
nj17jBo5yvysX7/hjTdeBwQ1FRz3oS6Np2ioEsaYsaIlxowZy5uiTevWrT2vmoRmHgZ9/Ljx
O19/49FHHgHdduHE8RN4VlauWKGUd9u2bT2Xik5eh/cFgkPfBtCrV68e2PdpCXipqP4y6CeH
M16PHhxxFDz0V6N6dZuZmjWqL126lMyZO2f22jWrVSnqipQ6d/YWoftR8MO5c8+cPiNQ4YRx
413F+6wi9IplyytUqICybRTDm27epInqYoMHDrRjaVCvXtu2bZC4gs9g1oLcSpUsaWnX26hR
o/jxlPJbv2FDsaJFpk6Z3LJ5c5KTgrdi+Yry5crjk9Dh2tVrli97dvCgwfh/1apV4pjokGTm
ooULJ0+ajDQXLlx0/733GXO8LpzikYO6tr/DLerAvPzylnJlyr7x+uuulX57wfwF4h6sC5gN
0UNI099g06wOHdp3oAh07NABt4wfPz7XffeFrMH4X83QLS9vCeuOvwL5pPQGDADIVtUMB5ol
K8uDDzwAzlr4qULLly2/9S9/GTd2bNHCRejVVjRTQWxWr1YtWo969hTN6NdHcudetHixsocW
l7x58ryyZYvGvKkrn1u5bcuWObNnqZgtOmnDunWtW7cSh4Eb8z7++I7XtoOzzZhuwO29Jrgf
RUsVG9W5laVooUKehVj+UNpgcjrjdcc5EydN4j1HuC+9+MJDDzyABIXwwDELz1F+CCwLir9P
r17oA61079o1YTyiaVG8fVK62RIuvGD9+nW+hl2HIipCSJX1e27Fii5xmQegUChKQkybIUOe
dgv4LMoVE0uNaAe42r0wXpvWrYiRpwoWhFp+5OFH4mJjERR7z569cG21a9dRBX41aRzXW+cc
VzJJjaTFixZFEql58xXLl6cwXjWi28Ixa0a0WACg7Nq5U6Q5BrMXjW8XgXKQOEf53j17H3zg
wU6dO4uHsvRUqVgxCDq3c5UDXcHQIPqE8dxu7uzZvpooSb7bt2urHwjPRvUbOFmnZk2kryq9
Y8vX4oULYdAUuLeiQc84CbNqVmnXVA9fmzVpGuEQSpZc/uwy/JzQlqXNSzG2DRs2KBplzHTR
EsWKLlqw0AriwmiJqV5j+fJloVvIoeHDhls+OnboGJaMJKLyMpBVl2YIOZ3xeii57sVs2bwZ
HYPzI3cUbBexbdurVStXUbeoV4+ezZs2xVpjRo/REouKQI/kXUQoTYT8OOjTp09c46Hl889H
dTAD4ylstH7dOu3xtj5Rw/Rp05FmYDzhORivdu1aGI8hVJsMxpscM17/ARaC5cuXr1m7lh2V
ukipU5hFvomhQ4ay06xa+Zy7h1tPGDcOPwcLCjVvxbJlWRiPNJg5Yzp5VblSZbqfZPj169XT
Zt/+/YSneHYYmvnz52G8fHnzzJkzd8WKFQBlFcqWjRjv1KmK5cqJMAyP3LF9h4DwDh86ZFC8
RTnFjNeOVCf6LEmmgPoAc1eubFk6uQr1JDPgTq0aNaSrSBhPKv6pU6d4Cp24iq2rdMkStsTl
SpdW/dNJJRCB4BYvXkJXN59DBj89bep0ANfiRYsuWbS4Tq1a2hi5NWXF8mUe31cQ9rHxy/Jy
K5YvB/j24bOw5GzG69ShA7LzhtauXmWZP3L4kIrQY8eOmzNn9tZXtqrCZ9OCRqtbpNeuLVu2
7IwZM/55++30yUB2djIVCY2pU9lRtmx5GcosWBRjxjtRvUoVYT5UtVtvuQW5d+3WbdLESRiV
MjZt2lS6mQiAu++6i/Ylao5eR1oWK1x4wrixlDEaoOKbtCb/mBDYcWzkShYvMWH8BMTtdkgz
ADi7dOo8dtQosbyRfjVt2t9uvXXZ0qUx451EjuwiMN842bpgVJUrVcLSipm5+7atVLjZQn7b
t21H4tE2d+/ehR/69+s/b94zIoawa/v27QcPHqTEvP1neK6tW7fBqhmzqaDaPfPMPHFStqYl
ihWn1EGWkdgUh9o1a5gBxQynTJla+MknBUlAfs+bO4eSSQCSe+Da5u3BXLlEA5oiMln/BrZw
wULMbxMrWMmiYAJ6dO9mxZk/f/6/77rTRprMr1O7Di0gz+OP7XzjdcqzXZyWdolUaOuXfhg8
Bw0Y4OmETRbMn4+4jhnvQ6Vy5mDG8yps53CUA+YTlISyrNYtmregpciqYLPEQgDfGCwco0aN
FlBDY6RrhU0XKUT+MGYKnGOnmz17Djt4+IlWNnPGTK9cLDnCcvLZZ5996aV13j5SYyBhGGRI
wIrdunbDdSLfhPkISF+37qUgEl2Ojok4VhDCSqcvvvCiMtQDBgw01Fdf3Yaw3IcNEwNoMHjg
IMF77CUqchqAreabhw5ZGt4+dgxSFFc7iSXQqBxJrvUULVu2tDti15HsqEWLlhs2bIRWpTC3
atXKGYKCqta5c5cRw4YdOhhbjOJ93Yb1G8RGNW3SFOLUyfA4OjQDwiNog0L4bWbNgOAmSw8r
CFMHcaeCvFgkthn9WCMYThTTtsS8tG4dY4n2Otm69ZWxY8dQHQ8ePEA7ZXbasH4dZcE4hw0d
ynwiSNLwbJLhV60pONBusFu3bpCufsVqfBI0BTrLwAH9CUD7z2gVjLyCaca7NFruxfZyNhzj
acRjlhUlC0IyZq0zai/7GsRgGFZG+0x3Q3J5oN3wyeKxSAFyngZwRs0yP8mFp3vIhJVmsdpn
ONDjeyV3yfII2Xs7x5nEMJh9HlIGkzF7wcmS2jLJCpM5RWdBlqZ6F7Iv52cdW+pkJpdk91KE
7FUXSy6X2fU5W+JdZpOZHk56Bs53BnI244WlMDyDv/+NdfG8nEjvgOTM/hKMMAMReib67Hxf
17u1o6clYiQW25dOUMT5qoMwjKc6gqWE40QipaoM7zbSj/rvOZjxImTgsSi5nWc4cvhIAApe
SlIL4XMAlJlozOzE4tY+4dbnRUoxgIad8xwpn0Of59XbmY3CTlL/zDkh7V8MXr2Ans5ySUaw
VZxEmCE3mvaTMqYd0f2xY8cxYvxconwjS+alueWHupcczHgBlGxbz5gmHlQmr8R+EA4CBWec
jMD4Z5yMfsgkkYTQkwszcsyePMkAGNIohJkKxJCx0mceMJ8wHjCuhPMZvUUwwwBFPM1FbJvA
GdBtsgwi3+R2qaPN6OJsMUEBpZ3cInNIp/tnfhRcW6tWTaCZZc8uCyDIlIfKGH/2543Dfc/F
7R6Njy6a6qpVx4we/eqrrzVu2Ei0LjOmK3kO1LiHs6lZs4Zmad5710UjBzOeoUNISIk3e/Zs
tjKZS84EQJ6BwwxaEBRI9l0+MRkLh+NhLlIrKyDFjRs2nC4WHRN+zF0Z3fCYAXIxq0iORBSk
dp6p8sX6WCa78kZwasGy6DbcNwnbTa6dMGHCypUrU7six7MPO+PNRewSc2PMj107dwFzEboO
xsUgmfJ2U0N44+CjTANSKmDVc51VdOtH5l9wNu51YLfXXnuVvZEbAGhG6he99ezenbN029at
7psYjd+V+D7KDXIw43nfDOuSWCZEiWgGDRhYpWrV3r37HH377aefHgLhIWPCqBEjYa840y3M
cICcXc2aN2fdrlql6jPPzMUwjPi0MokkeAIgs6Smrle3Hm8SdPLokchr6759e1u0bFGrVm2+
JmEQfG4w+ERcseLF//WvO3E+vziQNN8G1JVkDbyCL7zwYrt27bnRIdpwV5hoRvmypcsEGyZX
Ne+WA64tcrtJk6Zt2rR9Ye3zd999N+Al2z1HWeUqVYYNG+7K0aPHcJPobeTIUXXq1DVgcBl4
EYiZkLrChx+iQrnyQQ8MH+tRl85denTvsWPH6zzgnpcj0Ug4SPRPUXRrDhjhFJ4XkitSHUMs
YmYPiYQ3G+pMJD0DAwG7hK98DOXKlnFt8utHmaPO89lzNuNhKlnDYrmBlE/xDpUvWxbFYwzw
rkKFCtG7+HaLFi4Mc8hxDOj477vvHj92HLAvyCVvFXyTNZs/2n6Ok7pr5058g8CNWKhK5SpL
Fi/hXwawhF8BziBDZKpdumQpkQKECc4CRgzvAh8t1R9S1icHF6xww/r1YankJuKnKl2ylFCA
RMh07tTZ7dQ/AVXhsufyMmYAK5UPeL2xE5TzyBEjXFizeg1eNU5zmaQrV66M1qGN9UnMQoE8
PWhw6VIljYTHMkhX4+Gdc2DwHGikK6aSahrcxIVgJc57XoPx+Dz4ADe84YSYrE3AAIQYn57L
9cbDKdxB4plEVjds0PD5taejoghtqVy6du2q/arnVsLKOjBmrsjZs2afW2s9T9L8cDfL2YyH
Vp59NgPn4cVDPwyPBSBHMEhHvbp16J8L5y/o1qWLkyWLF/NVPAHUv8zNI0cMf/Pgm+XLlFa9
AJoR40lSBPW7bNmzUBra8+pOmzKldq0oHK5i+fJJqAuEIfRJ7ty5582dC5gClmkSixQqTGpF
AMW4aoIIicGDBgYEI7h9iPSJfcCRrLMdhbDhLyaCpkyZ0qFdO7gtTAuo7VeLBeCVWz/84EO2
jlKhLVq0MGStxYEtmjXXpnKFiuDaoGc4n8pK3YwYYOWqgOR6bfv2jh07YoaNGzcEMKSFwNLj
oG+fvqCVXNjQBWRUtapVwFwAXPwEMSOeIEgt0ljaX0tA4EN/HYen8DW4+PbvP2AAAGh0yxAa
4om6dumapFT7cHPORT5dzmY82wxbi0TDGdCvX8h4CQMFMIUa1r30EjgFxsMMJYsVI5QwHigW
/iRVYD6gojAevnLV9OnTevXoQRSgS19VCALdYE4gScqWKqWyl5PPrXgOdtGODriJXgrKGKCP
gPwEkRgCE8qiiCKHPj0kpHZu0gT8MuCeMwwzjjEerVI8IY6dNjWKbNq2bWvZMmVF2UgyLawB
OLNK5UrSh23dtk3RH1wEo+zXls1bIHxISLAsWiGciicNMwAUTrp6HMe2ZDHmez2hGo2hUSPA
SAc0zxnTpoO/gNFE4M+KFa0drVtGz2t9oW068AjgY8IvILaC7HKSug5ikkx1OLCQlS9bThAQ
/Tlgr23zwMqTh71I6vwQX56DGc+6Kw4I2M/mR6wXzSpCSxYtKmyMQkX+UNIYJKOok3btAK+e
zJ9fcQ9qJ+Ai/oTWlTzTV0GiwJODBw/Ony+/JNBUTUod0rH8Q3VCZgLv2klWqlDRBgnErHSp
UsTUww/lxqgLFiwsXqz42jVr8z2RBy4Z9kpyS4AskmrihImdOnTUj3BvgwkEjSswqruDO9tb
zpg+TdkgLI3oGWkMHnga4llsgQgAjya2TVwfM73dncD5WKlr4MFJb2OzaxXWoDxQIHR/NS5S
uPBo4Q6t2xCSJCSkuPNw4bZ/IP+lSpSkb7OFkI1AniJ94dGo3/aQ1atWE0aQdBVYK5C+kZtq
wFGg6nHjxi1cYCzP2OtaDlh9NbMdtYKYeboAqGp84SXyY3xImS8HM17AFqlZ1a9fX2YMUdi+
KpwgqjJKanDq1Lxn5gpPhVoUFcZ2ggPZJ2logkRffPFFOx+bHNs8+5nVq1d16NCBGAQRtPvC
J6QKsbNl88u6xRiWfVYNbZCySBlCxoZQYBty7NWrN7aBzHQM2ElRpPFKaiAsdeXKVZhEEKBq
dcEHsHvXbtB7Ymfzps1GawtHAut8/vwFbdu2U3VMG/BuDYgOGE7PhVvkcdEJeKf+RXB7cBuz
lSufAxPt06c3QRfkUtAAlyxaRFZ369ZVnmmTYz2KvJHHjsFG4gpD0obMpwaDU5PYrP8Vylc0
5kmTJodOEmZLpfloqnfvxmYqNwgFZGSKZmzYcA6MYJ59dslS97XrE5KX2s+HlHEu9rFyMOMl
pJboP6mQwiABsvwUnjb5KRycFQOZ5WTYRGX/pE5flkQSoXEqyDO6XYqPQ6g7AcKtl9ptAhk9
Y/DvkMbi9NPFZBB4JvsgA7onOZ/l0UClGVTDr+dgmHMgRWP80BkOj3DmYmnzQ319zma8nPtq
zLtNXefOnXfv2nlmIsH3+5nYReWcjtj2PME37/cAP5z3SzPeB/Zes8irD2QciWs+QtsdT8uo
9+8lpBnv/Zvr9J3SM5DMQJrx0sSQnoEPYAbSjPcBTHr6lukZSDNemgbSM/ABzECa8T6ASU/f
Mj0DacZL00B6Bj6AGUgz3gcw6elbpmcgzXhpGkjPwAcwA2nG+wAmPX3L9AykGS9NA+kZ+ABm
IM14H8Ckp2+ZnoEczHhxmscMMH5I7hhCb97rS4WZDLMQgIuOU+H277W3828f7hINOyOO4fSl
IVDg3J8kniCjcQhNCBkv40+YkPiJMrJZJ8EZyU9JCEVSFDI1ju7MsImMyQkhF8ktUoeadBs1
eIfohIxHzoyWOOszhnGeT3xD8qbC857njL3b1L4fv+doxjsugaRMOwoehPcktDQqzfMeP+Lo
JIOQux9QWIidIL04LewJGUfE1L1T6EBCxO/xbqebG3AIKfQ3yTLkZyvHoWgw70hGgR/kL1Ip
QfomyQX90YnAQtmZMugvypwbLUzCC50PS5IDl8R3PPHWkWjqhCbs2bM7JErcs3uvZ08YSdj7
jtdff3Xbq8IRpb2QXdRESQkTzU9mHIObRj9l1pR3awUbBPueIywoZHPzV4LAqBTz2RbKI6rP
HDoUErqde3rdyPOLAIwm8JwgbzdSP1C5lQt+X5f2whzMeN6KkiCFCxcpX768mjvmRSEuQdln
ov5Px6Elj5p6gAIkhhg3Zkwo6dy8aZP1L70Ueli6eHHd2nVioZqZqTqOxQ5SMdBxdJz5axLz
FjFPyoqeiKZIIsWfRFxYo5VFkU9JHGo476/g1Hx58qKSs5Kdk35Sk0z6oxrVqklmMWTw4Pnz
5rujNCoSioWrYu49JEGLHBOK9QiWlQRNLgwJHUJ2DPHjhQsXln9T7LmvIoNKlyotq8XmzS+H
B1RJS+2X2nXqlChRQj4YZ6Q2Gz92rIygoorDg8ho5hYh2UT4KLckv2DqY2al1xMnhSM3adRY
foCe3Xsk61d007ipg0mTJgmxdZyljkKsz2Smr86czEOHolJ7wurDTSPxHmVJy3jvyd39pNRu
wwb1w7u7tFx0Ab3lbMYLOeeIK7m3vH605aVaBRFEyE0kdlu0NbKTalptGhOuio3zcS7naJmX
EkKWPqm+oguPH1ezTra8kKlOqhW14MK6G9ggfFSl079mqhxbm8PqLhDbT/v37Uu4S/0gvzqJ
evQfsu6RTqFlLO2itV8AePWqVTrG6YZcK/+SxJsPP/RQKKyV5Y0GaabmkdQS+MqodCv1g1QU
0YAXLmwYF5TMYOAZM2vXrOUWEq5MnKh82Fi50qSZqVi+whtv7JR/dvLEqFyZgXhezC+4XslI
SdNCD+5ltP6akwH9+jspnp1AM11uahyRgD1yBMWHUuYmXz9SV+jBGwlBydnVPyeV1FMQk9Q1
53oIExjl84z0jKiQ4N69+6gbo0eNxn6+xm9nj+eVsjp5F5HUlUj32DGZF4sWLqTCkZ/27tsb
K9sIIJreAwf2hzGEN67iZ4P69dKMdwHLxBmXmE35C6QeMbOWZNXhlFaUXESevFo1a6urLNeY
1H0Ki1etVk3qFOWOK1WsJNlJqxYtJUeRztkbVU1WZjuqZs8ePWlRsnFpQ0qowuU91aldS+eq
z+lNTgdZfVSQrFatuvSYbVq1/sMf/oA4QqJOmQUlcZHQWvE3SVz69elrRVfRynIg54ocKtu3
vybZniRIJJWsE15/RGsxN0pRERjPZ9SIEf379lXQTycJC4WfgiClK6q8l5o8V5EwCSw0UNFS
TdbQ2EdmJDUDpSSUr0VWmKaNm4Q8ufILyq0iA0WD+g0krUDrMlyE0sqknPRHFqkgE5yRu1Yi
I6wlHYb0FmHOlYyVRUJ9eckpLAFS11A0ypevgLFNmhTD7qgs4e7dewIDJ0MKfbq7BIcmPzCh
rKS4i1yVf0lqDPM5YcLEAf0HFCxYUBHZpc8+a3klq/M8kWf9upeGPP10hQoVpcawQjVp3ERi
JSl0S5coIfWTZlKqCuo/8tYRiVUVnY5qa0s3HKeiqVSpcolixcx/SO59scR30dfnbIknKdgT
jz/x5JNPNmsSZbZq07pNvz59LN5UUDm/VCr2RjGVcseoTQlLqY1e3rzl3rvvlgTJu5w+daqc
JbNnziI6MJu/UdHWoUPkyUOyVE2aiaRjRJAstxUrlKdrPVXgSbLIvkKbGtVrWEddSNkjHCSH
xhV66N2zR8F8+W0nsJZ8gZhZs2NH30aO8rXIfSLlHiZKDANy+6mwafwouE6t2mR1tSqVSYNA
H74qE42BQ+72TZs216xZK17Io0IRDtq1aZsnTx6FKQsWKFi/Xn2XHIlqJ0RqcMkSJf/fb35D
vURrmPmlFyMt2pDGjBqFQ3AsQmzbuo1nlKEoqJdlS5ci2SI+jzvv2qWzTDAOqH/9+kVZKnCm
CntPFsj/zNw5tpSFCz2Fc0yC/bAMn1RN+UtlH5UwSh7BaJwnT3quSZMmWhnDE/krd8uTBQvK
oSYHXKsWzTdt3HDHP26nvCycPx/34u2e3bpT/vv37xfeoIQuMhpa7yxnJtYyKjna448+Kukb
SViiaFF7UfMvMWmp4sXVpldfVvFtSdaktLHLxefyXHl98jgaUprxLmrdiFZf5Ua7dpN6VeYv
mpIcRCqJSuq65eXNqEeWS6RJF6JxeT1jxoxWAN3uR6lXKopMW7Z2gwYOkM6ImiR7LD3KCrp5
40aqqWoMC+fPsxVR1TH3Q7mbNm1WuFAhRRLpdWQdBpOtCK0bg0xbJFggTYmrH3n4YTk7EZbz
XraRyDOp6KQslI8+/EjtWrXUHmgoU1hmfRUXSs2E2hy0bdO2atVqhC1VU1KjIB+sDldccYWF
IFAMc0iF8hVcHudgjxp0aNe+b99+iHhklIEvSr9ZrVpV2fgIfyPctHGT7KOSiNKyQs5pOyvF
n4MUOnb8mOxpshjGtZ2lEjtcoVyUri/6Lb5X9WpVg248beq0wYOj1NG1atRcv36DdKO7d+4k
ssuWKW3XJ0116HDNmjVkjgMZqCRfDCc9nUfo27t3xM+ZezNZp3DF5s2baMKG59WYW3J42dJn
B/bvp8w19Vj604h1T5zUZt2LL9FuHnzgAVkGZVKTetAW14pmybPHw3gjRgwnAx+4PxfhLJep
h2VzkiLR17pxweeN6zeEEtNpxrtYxkNDiMacyq4Z8md6YWafUkfJrFq5UmQ76drVrlob/IAC
vKeqFSsxYsppOX7cWGqkjF00N/obxtOPVJxv7NxZQzmO+fMaNWgwYfw4RPnmm4cOxkVV9UO9
JLJY0uSx9tW2SlXUtavXlCxRwg4K71GfnJcXjG4TLrH8Y0V0tmr1qsM0uSgzV/RJrClKk2um
7rG0fOq8/uWWW9wl2HAYFSWcJaAsGWHfZdl+Ji46Gz6SF6JCB1jOoqNz+iHpLb2f3KHO+5XU
tdAQtr7Wr1sXe4RryZMK5ctZODz+sbeP4l5LQxBKfu3bu0+oEe9DZ+vff4CDMqVKrd+wgagk
1mybCRP6BR4IzVavWa0EswNSS20TBzpT+hxTydUZKdjRJ8PIVKZUaZk5ZWcsX6YsPqGTV65Y
ycj79O5F37ZQhpkk8IcNifIUW0qsj8yqllEagc3qgf0HPG+ZUiWlVLXAUV9NjvRNqtWSvQS4
bYOnsxOJ52dZtGlPG1cuiu3ihVPuV6nUbc/oHl6YysNegL2HN03BkHOWQvj4Y4/LZCklprIK
FmbWDUqLNyd565hRo627pCWZwDxDqWNIWPfii6+/sZNiJnlk3dq1WR3Z+qKq3IMGIg70pLFc
sfrPlzcvC2SDevWdl41PyXXcpZ/evXrTyuyC6I0SUBIINDELBIlE3EkFL5Ulug6Gh4gxZsyU
4jJhJAdVK1UKxqFEPjiOWsfqn61agXz5KYoeH/V36tB+aqzU0cQ8e9KPgsaFnnrKgIsULqLW
NLovUbwEg1CdWrVw7zNz5lIWlExo37YtUrRm2Z3KqDtz5ozQA6lu6iQvpKiTyXaMZL6Huutf
/6Lu1qheTRZ3/dDeLXOutQzhwCWLF4WEtj169AwSL8seD08/v/Z59lL8Zj3yq+LYD+TKRQex
ajxZoGB0bfcexKORFC9aTIp+Sqkq87LQSwFM0bXBk5rNg5PVrFk8D9RL2RatHfJk57rv/pjx
mq5eufLAwQMVypbDqHazkhRbGW1D9J+WeBfJeiet0CNGjLQuBlMEFUj9ILttTIi1qKCUfsV3
hg8fMXnylI0bqX6bvWDrPdcTQqRKIeVZs2exgqgr8NZbR5Xz3r9/H3cg4tCnv7qVqdZ+Q4ER
Ak25Dx2+eehNQ6d5yodp48SAqdkLz6+VSRZXUJ+wmeyuVFbjkQyXuT961LhKOCmEaJJ3H+wl
EmwmcxHl+Vy1yvbpbPQRmf/ci3mDP0AaX5TnqVhuULAkogaT9KMZ48eQIUNtdwMvrVmzdsTI
kbt2RuXEJH72UDNnzjIhhBLzCTvTM1G6segT7fcOHpRp0/RqRvvVP51NNls7KJZh02WG5cx+
bsUK+gLiHjt2rLoRJs2qpzG3xGvbtgX5lvrx1XThEzMZKxEnvaOQXt4uMVS091pf3vwyFXfi
xEkyoCqDYdiS1StJz/eowAMlxcbPezRLVlJjsAQsW7bMhFhq2V3pI5HJ9OhR6wV92DFXkzdI
nblYmrtE1+dg40qqNMiyssZrWkoKyxRpEq5Krj2zslesAmUa9MJFqQt2SjcZtofkzFnzYZ7R
PsW5Fw0ghR5Dsyxn3tHwdmbyzOT9JeNMJYxkAIHtU0abJQ3m6WycyeVZKIOim/I4mbXHYqUx
Ow0lg8nuToi4OqWj1JZZJjx7t6nzmepeP+sYkrechU4uEeNcbDc5m/Eu9unT16dn4AOagRzM
eBbLZPRBOwoC6lLOZOYtguk/rLJZbhCt2SnFYrNInowLM4Esrk0VO6niNFEss8jYLG0iQGnS
W1yJ/Ayxlu3howk5w5OWkez9vc5SIo6S580+1Umb0HmQOUGSx6PIQKWeqUecgYzNuCS+PExd
xtPFVplU8Z78FCpsJhpH7IS/pDTwXmfq/NrnZMY7fpxxcssWxRG2ej0HDhxUEOHSTrqXGpAT
sQUyep1gK1lqptIJbTDsKjOoTZVwu59Dh8LXBJpoJ7bjte0xnOKg3SZkhjH7avuhyMGGjRtY
U5JLbOE2bNjI4geWoQ3XCD+4j32XF+Z2Nqs2OTjQ3mzbtlc3bFivOOtZnz1GyBzne1SyyxgS
pMj5kUdGK0NVOMVGLjx7BAw6cCAq457Sizb2xgyOYRjhjRheJuNFLGQ36CnswWxVudftM5l4
wzzYHJoFM2OEoddQKzce+UZmEvMMPrpp8+bDbx6KqDae54ALDcgyW2VTcekX3/c0U+fdOAcz
nilmqCxQoACsCazjunUvhepwyaoZjkmEQAepP6WKytS5ymJrdgksCNe58wiCAZBlLwJ2pIC5
tOGLZ0EN/b999K08jz/OPZg5jKikEeM7uytfBXplZgRe4dTmxEdMjgEs9PB8XGndYI6+fZQR
r06dOmXKlKlapTLjQblyZSFu6tevhzIxKkc8MynPHuMNFEjevHlq166lxhBTx1nsMXFNJYUs
QXaAeEKxsWha4k+4Y/T3zD1laj/hF2WG2HK13LtnjzEbQ2ob/WGApwoW7NGtW+jfje6+8061
BMMtNN7+2nYGZC+rR7fuVpAWzZt5BP4DDIMhlWoyh0yj/EChZxeqjlKkUCHNmG2xPb8O2IqZ
dIlnZyKGEIAo0nLRosWKGbHfqj2YEMB5c8EH0DBnM556yEyall44abYvrlXIzEgURNrYKedB
+EFEYmo+xueDaKK3EpePVXkHXDPWTML6Gq+cQb+JpYSWjGBPFSjA4a6BGIg+vftwWwErhVcb
tB1m6wL58sVglIhW+KYfffhhjuCEppVibtUy8inrMwYiRmOAseKWcEmtWrWA9AMnJO8/0C4X
Ip+BS/Ati2tykjfZsRKtHhlqhA09/HRW8tEtaczUHiBabkO0sg1akAio0C3RQTQlAtOsRDOT
oSJGz6gSYJ5HH2vXJipbCQ4CjRlVoowrwifzAOf5+COPdOvcOQyGizXXvfc+M3t2Mg9gesEd
J5ri6FtH98NVxvg1dcswlRqd4cIgVONhHyxetCgfaXTy2DFOF04Lx1FVtvETeGUxeVRbs0oV
r4mnbu2aNdtffY3v4aww1w+At855y5zNeKRHcKBXr16DLbtA/ny1atYCwmShZmeP5EyFCtxK
bx48wDmrUhwX9sJ4DSYh8SpGpUEFig+KzYwZylYtdQbtOetaLxicivvBSbKOeAp8kvAqMATg
RQSJOHWKpZ6rmi+R6zkm8ij+BU1wJXNeE1YJbXFgQDBpYJ3u3r370qVLUjknNIM+4zcH91WC
jz+NX85JhcSqVKqs8BjAGvs7lGapUqVZ+XftysB2ZhHvboHTVN4MHhdAFsLKs4tRgLHi4Nqz
ew9NwTKUcL4DZQBVBQuPQEo3atBQnc0O7TOcjZwf0KfJUqGN9U5XADrd4yqZ3Bgtm7ckIWdn
egWxfdmyZUBPpkyZZM6jQcbhHcFJyNOdN29eJQq5ExJG5QUh3HhKleNzkqfE2+TM4OLHaSbc
JDhP4sGaQagErDaVRNG11Mm83FgujCeHM16PHqWjaoktOUxfevGFwk89ZTvUqWMnPiLeapAO
OgxZBPFQIF9e72zunLla8sMiRE68ShUqzJsXvdRkpz5s+PA5szNAIZzOMGj2TlGlxZgqufgq
la/A+5QQh57xGJcgwIqTsKMLFixQjxaAJuqWpH3r6EMPPIDhjYpqRMKAGloa/nXHHevXrder
oIGBAweWKF4c80TdZm6QOAA5fMkiG6rRI0ciUGUrLS7aAEz97re/LV+uLJFjm9S/Xz8162hx
RERQIHm0Bw0cZCsVhwedNAlPPPYYqlUxE4DOP15paiGOov268OlBg1yVaoYB++IfD/w/bOgw
/jF4zgQXpta5KuoJ42kD0wyGCnwXqk+bDY44LLFg3rzQCdfl7X//O7CBn1q2bOV2XkeRIoWB
4/bt248DKedQRDz+bhQumTFt2q233NKlSxfaKfyDMwKXbv7tb82VZRFWRl1eJ7naoXA9CICO
Pv9w880BqHR58lsyqhzPeDVr1qRu2QhZv4MONnTokJHDh9uPzZsblapE0JDQ9WrXpmpGK3GL
FlMnTwKVUBQOzYnKCeQO0QurlS9/vmLFiou7EdngQBktQBNUy6VrpiLGq1AhqJq+gkrnzZMX
TkW19IIFCgBM5H7oIVqQJRk+m/pkli3DDz34IIe4S4gaVIWRoF4QKPBkYm/k66cyhSUgiCxA
DRU2HSQxaQplUi89jnEK/rXkI7hAo6HzZXE5eB+AG9hIkPxAf0ailDRmo2F6EIoiafn4o4/x
Pnv8m37xC0IvuvXxEyJqBw8aDORx/3331YCfbtvWQz2cOzcfOgBa8WLFAn4a4yUSz1chObly
5YJxIzltPufMmQPdakkqWqQIHGmIh8J4ue6/H07aMfgIaCUtkWlEYGGIRQwf8U1hJxkdT5qM
Dx2wCVFeQGHtUe0dDI+4BoUNwDfAIC1FMFN26tdvkDfPE8xI4cEv50/OZjwY6UBePiB5ETWw
uAwcOGrkCLssaAdfMQ8oE5Cetw5WInATjIvwQRDEEUNZWOnhLQirunXrQUELlmFJGzNmTFQV
uUGDu+++O6hA9CUlvyPTYhy1ybo4bNhwberUqY2qFi9eMnDAwN59ehcrVgzFJOEFkPIQzy5n
PEiWc2AL28UQFuRDAQY7jqg/7KxOnoRTiwo4xyFnoQ2lC/W3Ugx5bCQbx40dg3UTksXqNjm+
Ghi8OAlJ4kER6M0eD60LHfAroCblmTRjtCDxdFi0cJFhQ6OtVwhTMkVMGsWLl6BtstzQZgd4
qN69WTUee/QxS4aW1i97vNB5vB7tJ6ysbqVKlbIAqWXta+/evXLnzq2ZWdKG/blkyZK0DA9I
/qsNGEYOj0JHTZ5C1I99e/hqd0fERQcvvqASPXEdxjl92nT6vP02DdPX2lHQUwb0lApqHtwr
dcN8ebJfzma8Xj17jB0zOrwnaK9Qu9yajbZodHQzWigwJ+t8zWrVAb5QFZ3Ei8EDUIt4EjmG
lxQ6oaAmqmY4s3XrKxbXcEwpgg+0ZcowK2T60yiNtosJ9YDVU958Dd2CUJIVjRo2omjZaFnR
O3ToWKhQIbApVGi9V9O4VKmS6DW6JCreesomqljRIqxEemCTJFHhpMlnazwiwyp0SyBJ+z2B
diSAzuG5Q4qHLHu8iPH2G3aFsMezKgm9o28XyC+uZy5IKv4sVbIUiZF6LVmHSZInip9iUbfO
0f7NBzbVGpekWkiaUfYE4yRfgSotYck8AH2VK1OO7AJ8hSZjLnYX4ExbNc8IrWpmPKOY+qAw
W3GaNW4irI51F9SOUs1oqWB14UKFCepXX32VZdhCCZ7qwWkxwLelS5acMSPCml6ezJY6qhzM
eKj21ddeQ0+BYmDWoxQpJ07s2LH9jTeiRADIl34Cx4iWvTZaH20zorC4CPjkKVMIIpEjYTqC
LXPH9h0Qj8G6Gc6Tb9Sz8NUL1qe/Wd6rbqNbZ35sooiUMKqQQGn16jWsKThWz4gG2jNE6MQS
ZpWvhpdCLicobzwHBuVyEQDMKoLiUGSgaY3Jeaq1Y3XJp02bTrsL9snsBBebUt8Kj+9XEl4k
m8gJC5PIJmZAV3GgGXMiJTws76idYWJn9ZMbKc4e1gVTDU1JPmahJLalCP4afzSz3oVY2PAh
vYULG6ox0DPtt6M68ps3G4ApJV1BQ4NETXowBpZbQXfhwe0bx0+YCIubOQ+bpk6dRp671/r1
68yJZchPOcF/npONKymJseL3Gn+SXVMqeDL8mqwxWX5KKCMxsaTSUyoqJfSTnbhDgo/TFBZG
kvIJYwsnU4+zf40vyoBrZHo6znVJ0ttZB5Y6pAyBlg3BmsxYlgFn0daS6T091TGiIPtjvtM8
pK7xqccZbJn5JKlskzxdWALOMXWnW0bzl0auZCfS9Jn0DKRnIEe7E876+s4qtc4io86mkATn
+RkyJEYYhjOpP1EUQuN3IqHkkosZZJo+P8QzkIP3eGd9K1QSWxf/zmHXOvrWW7bmGcn54n18
0FEDa7HCrX3+ed5bEKegv9m6MKPbAs6YPoPrwh4yoBbfifF0yJDDCmLbmJofNhmwQdrC2WVd
/sa3DzHpf7CPlrMZL2Xbdhqn//TTTwe7c8xOpzcGSWOmF5462MuQC1Azlr3Qnj2aoa9xo4YM
bsAuTI6YBO6EV4oFnJlUtGW3rl1eBLOMWSqDac/cQ+pHFgYG1WRfl+w6kjFI4yPj0OkGHywV
pO/+vs9ADma8iGdi0xk8brAQbHt1Gx/xsCFDnh78tLBxDm7cAZEo5Jm5TBuNiTt2wt17MN1e
TgXJMzmvubm279jBssdCPf+ZeTiNKRwaA8SRI5v7wWfylKmSJsGOuTDOWxzJPKZCljfH7nLo
8GEeYSbQ3Xt261b2LrbNKINDDBzzZsNcGwOMr6RMI4YNjwXv0Q8+19z7TnbpG+ZgxkOv0FLl
ypWHHfEiBw4YwIErzaOTeZ/IU7VqFeikyBfUrBlJVbx4cRlQgI/gvzZu2sixK5vlX2+9Fe+1
bNni9zf/XoIGPi7/eCCkypk4YeL9997L7ydjUpfOnSQO4Em//fbbpUtp2iTKJxkJq1P/ASuT
GdYRcJkERDxyNWrWBONgKBejoPOKFStyeERcFzOexpzCXTp37t2zl5Qt0Plc2AaZ1jk/aqyY
UxnPuNHrUwUKBlAIoAmpFXLxQ7s3b9rMDqxSpUpbt2yRlgfWkRe7dKmSXNIA7zKIyP8FMMX3
ChIpb7E2OpHoVnJleaxs88TCgXqSk9WqVMVpoDAEY+sYnl+2dGnJ0oOWSAWV/8cBNNOi2Fk8
Y9p0OZdopFHeruPHuKrlUwqN9QBXEVUFOHUK0AMUAwBaqiwyMGwm05+PzgzkVMYLMoQjWDiJ
FNHgVLBUgb4BxKLceBE8ql4E4GzcGD6LqQOhO1mhbNk5c2djHjpnzHivUB2rx4xH3EmJi9Pk
gcM2sqqCwsAHSwoowSOAYuu4BwBrGXXCvcSqdI0DYVq3ar1s6VLgKeBdQa7u2L5dlBxaQthp
U6P86j4ghe3btAnHVocA/JXzC8Y6zXgfHZYLT5qDGS+ghwkxsEOSqnSJkiG3PugwQL0DYGWM
B7m7dPESMqpl8xYeWA5Glkk4SRfWrVP3tde22+5RQbUXgikAh2pKTI0fO44SmPeJJwCa2rRt
K/BHviqRYJrhyZUrngvTh/F0G/FzhQoyTwtKCGhMEq91XIRAHjuBambZjhRqXjhpcN9rKSWZ
A7E/bLBpxkszHvDTtddee8Wtt96KQMPyHD6X1T7EYEDpJaWVLBkKmdTq2LEjbbN71279+/WX
MNOAYflBpaLkykuXCleV6hz1V6lUUeQBqcX0Iic09K3AH8hJqGKX4C6cIMEjeKRiA5C44FGY
Z+zo0WvWrpXpmX1EgmqAr9mz59jgMZPA4LvR3XfdBbIklTpjZteu3aZOnRKCaOSulKFdRoOn
nx7CCkqiijETmtCrZ69JEybojVjmV0gzXprxcgbjeU+AjIIjxYABXkbrwslTjPhEDd8A6HME
vNyxg1gTSCLOUkESRkvbQtZOqHzmRJdjV1vEkLpD5E6IA1Aoz0n7QDGjYbkRJKql9ObYLAKI
viqkJToOFWrs0BYtWoh7FZojHl24YOFCv8aZRU6wrEBy+mzdGoEYiTtgaE5C5wUZgTtu377D
lvKjRnbp583BqqaXl0jj+PgMGGL4NXm8VIdbuCq5PGkTqCGLkE8AK2d12WVpn3ptfIvTSbJS
73jmsC8vVSLNEu/PDORsxnt/5ih9l/QMXPIZyMGMd56wzOxTFm9YMyK7L4eNaxCA7wRAy/KY
voZ3ltRDPjtNnAk6Df0HFeCsKNN33WSee5CXnC4/9B3mYMbzbpYtWy6vUcI8iQUoOcj+/jQW
GGoPFkfuvR6Fk3+gL9l4hNvZN77TKGBKhYTbpkaPGYO2wWVgYqK0lpkg7ezP66HUalQ55OWX
N6uywJcYb1Zfj/JhZkOZAuLYKvOvvNMy5LxtsL1uFi39A525nH3zHMx4iKBZ0yZRfoTMj/JU
IcW/g7h2+elPwJSFp4XknD51GmMMt4GkfdH5zEC7ZDoyY/ZOB3R7zxmiJlPmRMaSk6nZrDM2
mUnLhEwDh5y5zTu9I+W3UEU5yOHTci8TZcrkw7UYJeTL3JfCo6m5lfp0MppED5gZER9+4tnv
3r0HV6dEZkp/GKp8M+r1hV8Dj4Vj7scK5cpivDNHmHoHNdNHuC87kDXLD2pNhoLVOZv8P7jR
52zGU3VNcishycePvQ2DIv+U5Hxy4xQvXkzCPLZEpsXVa9ZESTgkxoyqdUcVt9XiYsEXcCAB
GQKKQJfHjqmJB4epJDrz4yG5igUl7NoVYTJPnFAfWGQ6OSFHy062yrhouISqfnIlAlabJi5D
o0TOZoPRj58UFla7izMd54SMmu7omKFVOjC5H6XE4pZg3pT1QGIyFxJlADeJjUeGwlWrVovp
VoKPTz+OSY9YRfrAkOCAT9+v7iKdCd8GDKrjUAuJKVU6CZnzpE6RlcSA9+7Z7Xk5UdTc4TUJ
1SfNlXEaAyeK3oTnO3mQBfiNndJym65169dp76TBw52q1KM3hm+w1aefHhzVOr8Myhp/cOxz
4XfO2YwHrSIBifLWXTt3ARC55Za/cLUpaHjLLbeEBGFAm9Wj/MT1uRMgUVCpnLZ8dzhBklaV
2WSMlRcE/cFh+lUmr/vuuUeZO7Qr8xxwCWkg52yUDnDrVkWbpd9CjqNHjxoSZ/gy8T169ChX
tpwkKMDZfHTWAv4JiLCyZctyl1euVNG9otSA+/Yjbn6IRQsXkFdr1z7fpGkT2VflIDEGGACZ
nsmoqHH8oXzCl0n1JSFn+bJlIcsgUSdMGO8nydQsHIBplStXIb2hdv7yl7/ECQ5fhBZQh10e
Md6RO+64Q+Yy2ZnuvfdeTPXs0iUywEoPY7TyC4HLSFgGOOrCjRvWgwpUr1ZdAb1Vq1YpQKmu
rdybUVKTOnXAXC09JnbihPGm4p577sH55kHVctrs5bBJvnDy/+CufEfGy58/P8JN1TYutyk2
NimGZJImpmhTXG1y/vB3m0y5vgkjnAZvqZmVfuHCRSFXCroPBcf9BNglozMyIhlyP/jgnNmz
nh48qG3r1nLOyeEhPzSwGFHTplWrXj16Eq0YMs9jjxFTZGZAqBBxvPa41LF0Q/37RlXCBeMp
m4r96GalS5biMDR1SjHjH7FIdlM6DBMLU0ogG4l8hFguPEX4SUag4XFwEymsN6kyn3/hBWxg
n+avx1RqPGR0pWRKOEsiEbkyqamjkC9PHntXEDlZUlaufE6dR8147WU3mjZlqjLikXq5b7+R
h6TLBw7sl2aTDJ8xY6YM0PJhmgQ7OreQH0ViMnVhZROcOWM6AFDPnlFv1jWLVFrVvGDOzc54
NKCbbrrpiqpVqwL+XuaMR7ysWPEcCIsCvDRJ9U0RLoUQWIwWJKnrvLlzPYJ4BVlxwrMIsSPi
qIING9SXT5LWhIvgXYQSYUiJruCtmzRuBEs5eOBAVYXJrihT6vLl7dq0AcvEWoIhZJgO2fIk
DnJ56Pm1ba/Cdnbu2Im0UcnZmTgZbv0AZONFV80U89t0yfnpDFEmJ6SD9u3bcf1TFKFqMG3o
DbmHxKwYT0QFvVcaNfEWBq9SsfNMMmQUw4m9Wf26Uf4yCq+MmrVq1yarqakGuWH9Biq3NOna
k2x8/ThfAV05wmTgVrs43ItOThrj/HnPPEMaW18sBDLf1qsjT/spD+i83mbNmCFTU7euUW8k
/JLFZ2S/vmAS/GhemJ3xFLumpFwhg2/RokUvc8aT2hUpSAlesVx52zDYMcv2kbeOUNuwnxgc
ATgegUBApgwDTtLTGFRgo6mp2M+mS+o7mqS48pLFi8u3aeNmyS+YL7/U1IhVSnBKJjYr/ORT
UgOKbn/iscfJKM1syeS9kkIzlCUI9nr64fBhQ/2VcJrEK1tabfG3jTBUAnCJVJz6sUwApilR
4BKiiXFFmrAKRNCu3YapK3FG3bp09atr6caGR+IRxX169ZZkNrw2m668efJs2fKyXK6ygHk0
WDn1ekg8GjV0uASb4pjIbUH0+EfPAZ0zsP8AS0OZ0qVkE/NVOQcrl9mZPWumNcjKMmTQYJEZ
AjU8ZqMG9a1fJJ7UzoI8BF65pEXLlhL+Ofhoss3FP3V2xgscd0VAjl3mjCcv+nPLlrEcEHFY
TpSd1OLibiz79jlq7lj7baLwGIrv1bM3/VBouaXdvmh4DKSOFu+2bUNx+qqVq7ZqFSGbyTGp
pnUrSK9gwYKRyDp1Cn+iYDOO1iWTtSHs3iNKV96vbx85p7Foz+7dataoKREtD4fErOqJlyhW
nJa4bes2iE28JOxdks98efJaDkaNGvXE4483btzIMCSEJPEwHouFyKahQ4fRgXfu3GV7ZgXB
xpLwYlTWlyaNGotdAlUjOYkgkRlgop6XJJRJmtosV6xtWMECBUl+T6rAyNKlz9oysP2SY0aL
c+gyZUqXkb1X2maZKsUZCi+kJ9u7UoNpBzQFYVDuiJNZj9q0aknM6g3oVLSUxzd7xi+TvI3i
5bYBuXiWeH96yM54xB2hd4WXdPPNN1svE9673KYYKdOR6E5WcTF1NnUkwPoNG3x1nkyzq0G1
dkchpSSDJFMe6cQJwOgXWeTi2CI2TFXv4t4OImL9RKa/3XvYF0kbPUdugxMnXCjVioOouDYi
PfLWGzsjNKb5YZthtECpLIohyTnepvup0SF1vN5wkZa4RVJkmzSWHssERlq1ehWZaTCYnPSL
IKbHjslFaYemE4MJedfd2rVUSrfWf1zL6Di9kYWGePdePDg902aS0SXq8ODBuKzfgWich9/y
q0+cJ+aE/wkLJMPDa2Ud4WkwFXL1unVczTxqSWzqwSDdSD+GZ0rDjLH6CunwK65Oavq9P8T6
YbpLFsbzpq666ip/I8aTzJxp7rJlvGBbT/xRiVcqOWC0nD49Y2uXnAzaUXioxHCf5WSYlHM3
S9pkX7pwvs1bq1atK1aoGDaZqb2lKhFZ5jal2RkJocP55Eapw07tOXUkyeSkOvdSM9CkdpLl
eVMHnDEJmR7CZE6yDObDxBLvz7NkIZuE1yLGw3+0TRj/8CYuN4l37gkK/rdIvr2/nyj38/Hj
FHVxQ2SCeSNC3wXe9f6OMH23y2EGUhkvldEixvMRrHnfffflUMYLw34nDOR/a/ZjKGQiyoKa
+n6P4b/1bOl+L9kMpDJeqmqZwXgIiKWFvSXHSbxLNkPpjtIz8F+YgYTxmFEEnYeqmj6nGc8p
9pYs0ehn3aikT6ZnID0D72kGbEmYMJPd3BmM5wvrlp8lin1PnaYbp2cgPQPnmAGyDlvhvdQ2
pyVeOEvuPfLII1xAmDA9m+kZSM/AxcwAbrKvo2GmyrqsqmbqDYDI2Dldk2a/i5n39LUf5RmA
Z7jxxhs56pJ93bkkXvIblnMNZx9rJ6OLvR8P7Ed5HtPPnp6Bc89A7FuabadGZ7zyyiuFH2RR
L8+L8ZJGPA0MnsQl9lXqPv1Jz0B6Bs46A5REbILr8N5ZpVwq4/1/9BckHFTJneYAAAAASUVO
RK5CYII=
--------------040403090101020709030709
Content-Type: image/png; x-mac-type="0"; x-mac-creator="0";
 name="visitenkarte.png"
Content-Transfer-Encoding: base64
Content-ID: <part16.03030405.07000806@ifi.uzh.ch>
Content-Disposition: inline;
 filename="visitenkarte.png"

iVBORw0KGgoAAAANSUhEUgAAASgAAACgCAIAAAAw8WZPAAAAAXNSR0IArs4c6QAAAARnQU1B
AACxjwv8YQUAAAAgY0hSTQAAeiYAAICEAAD6AAAAgOgAAHUwAADqYAAAOpgAABdwnLpRPAAA
buNJREFUeF7t3Qe8FtXRP3CT901i2htTTVeTGE035Z+YZkxijFFjQcVKVXrvvffee6/Se+9I
R0CahSqCgtJBQKTl/9099y4P9yIiEOXq83zwus8+Z8+ePTtzZs7Mb2Y+9p///OeKd/uMGTNm
5cqVWq1atWr//v3v1jz9e3oGPnIzcOWVV/7ud7/z2DfeeON9993n67tMAcZ7p8/s2bMfeeSR
q666Skd14s/o0aOdTH/SM5CegSwzMHny5MAjWAbXYRnMcg7muuKsvz333HOuvPXWW59++ul9
+/ad4/r0T+kZSM9A9hnAdTjopptuwp9nnZ+zMB5mu/nmm8/Nr+m5Ts9AegbedQYIMNKLGMze
MivjVa1alax866233rXTdIP0DKRn4HxmIOifWXjqDMbDdRqdOnXqZPqTnoH0DFyKGcBNmLNP
nz40z1QuPc14NEx86bc0412KCU/3kZ6BaAYC4/k0adKEYEt4L4PxKKP2dUEaphkvTTLpGbhU
M5AwHs4i2Ii3wHsZjJdq/bxgxsvk7XPovWkl9lK90HQ/OWMGUhlvx44d1157bRBvEeNxQdxx
xx0Ju7wnxjtx4sTJEyeSa/fs2b1mzZrp06YPHzp02JAh/jmYOmUyifrGG28kzU6eyBmzlh5l
egYucgZSGQ/9ly1btk2bNhmMh+vw3oUxXrhq586dkyZNatyoYY1q1apXq1anVq0G9eo1rFu3
ob/16tWrU6d61arVq1WvX6/+6FGjt219NVx1kY+Uvjw9A5f/DGRhvJdffpnQixiP4INNSbV1
no/EI+hsBl2/ffuOnj17li9XrmrlKhivaZMmXTt3fnrwoKlTpsyeNXvO7NnTp00bNnRoj27d
WjRv3rhhw+pVq5cuWbpTx46bN28K7KerSGymP+kZ+DDOQBbGQ/CMKYsWLboiMWa+J4kXGGb0
qFHlypatVrVqy+YtunbpsnDBgtkzZo4bOzb7Jm/evGecX75sWa+ePTWuXatW2dKl+/fre/jw
YY2PH08z3oeR6NLPlGLVTJgiIMuuCP9LZZVzSzwsovGunTsbN2pUsUKF5k2bDujf74Xnn8c8
zg8cMLBCuXKv79hhzhM5dvTo2y2bN2/YoMHxY8e12bhhw/BhQ1s0bVa1cuWaNWps2rgxrXam
SfTDOgPZJV5Ak12RP39+3r3zZzwtX968mW5Zr27dNq3bLFiwYPOmTXv37Hb+hRdeaFCvfptW
rVu1aJnwkoO5s+c4o/3gQQN9XfbssmeXLiX9Onbo0KhRw9IlSzr+b8i9YPi55IbU49aY4yfi
5enSKclRT8czPD5pj86HiAuzMx49k7Z5RRbLCgY4h8Tz6ytbtpQpXTrs5ba8vMWZwQMHkn57
du/R47/vvPPfd92FLZ0/cuTI4UOHHIwaOfLef//7zjvuaNWyha99+vRt3qz59te2b33llT69
e7do1qxYkaKB984x4cnSENqkPs/5X3VJXijGyzKYLF8v6C6RvvD228defOGFtWvWHHrzzfPZ
aV/QjdIXva8zkJ3xgn3lCiDOLADqs77y2JryH5EKNnXNmzXr3Knj/v37aJj169WbMX0GY+bK
5cunTJ78VMGCRQsXLl60qM3bcyuemzljhqt6dutWMH/+J/PntxvkynDJvr372rZp88zcuW+8
/kbMe81Lliix5eWXw9Yxu63l2LHjSxYvNs6DBw8ans+xt48tXrSI8ebNN98860Rqc/To0WZN
m+Z54vF169ZdQjrW1fLlyx95ODeJ/fbbb7u7UZHhe/fuveC7RPrC88/f8+9/f+H//u/zn//c
nDlz0ur3+8of/7WbXSzjRULm5Ek806RxEzZJTNK5c+eXXnypdMlSFM6li5doMGHcuP59+w3q
379mjeq7du3EVBs2rHfjwQMGdOvSuX/v3jWrVX/z4MG9+/Y9u2RJm9athw8btmDe/Igze/Zs
3bKVHeORw4dTN4cZwu3kyTffPPSrm276whe+sHbN2iBe9u8/8LOf/vSLX/wipgpSOhB9+DU8
LSfHN77+dfGIvXr0SG2TCMxwSTI1CdtEfcVdht6yCFhnmjZpqtsfXn/9gQMHjr711r3/vucr
X/7y2rXR2MJVZ3QV95X6ZrPcMQy+YIEC+rzt73+rVq3qhg0bLoyHQ1cXdu1/jfbesePsmsI7
jTx5rZdwkBc8S8mFyajO0VXyrpOHfW8Sz2Vjx4whslq3arV169Y1q1a3atmyc8eOc2bNInwi
Ujt5EkNWrVK1ZvXq+fPmxZlUphnTp1PMGjdswOJSrXLlgvny7969J2KJN97ApdOnTp01c2bb
1m22b9/eoV077r4e3bpHhH6md+HUyVOHDh36xc9//vnPfU6fmYy3/yc//jH58NJLEeNl/3jg
48feHjt6NA5n7EkaBHF61kvCSfvC1F+1T7ZeCR/a5TZv3oKEj9ofP/HTn/7ks5/97OZYYqcS
U1ATMroNojzlTJYx/PmPf/z85z+/efPm6PwF4dSzdHjBhBUT9wljiN7FRXzi53jHLXagyH37
9x858lbGHTMfIPWeYcYgLvbu3Xfs2LGLGE7GpfFDnX6lnvQ99RnGGAZ//Ngxo0rOvJPmleW9
nC/jRZR36hQzZrkyZVq1aLFkyeIN69e3b9vu9dffGDVixBtv7Iyf5MT+ffuKFylSqkSJ8mXL
3H7bbfx4M6ZNw0779u3Ndd99LCj8B84vmB+JuPBZtHDRYw8/XKRQ4SOHDlO0WjVv7vL16zdk
ed/uTnH91S9vuuqqLwSp4rP/wIGf/exnX/rSlzZu2Lh39+4qVau0bNmCCM11/3333ntP/379
XMU52aN791q1a7GjEstFixV1d+dPHD9OSyxUqBDLELZp367dnf/61x3//CdPo02pBtOmTS1W
tOjAAf1LlSzlV2cGDhjwQK5ct/7lFiYi82u0NarXGPL009aXEiVKkKsUxNy5czdu0mTcuHGF
Cxfu0rmLnr2fiRMnPvXUU8xXpihsDnfseB2Q4K4777rvnnt5Vg4dPvzKK6+UKF7i29/+1he+
8H+PPfaYTa+Rv1e20X79uvXlypUrUqRI2TJlFi9afDFsE+xSR986+p6IMkvjt98+ijTfiRxx
Ea/Sr3716+B/Mn6zWqVKlddefTXLuvP6668/kvvhv9zyl02bIt/vxQzJteSEV/PSSy8VLVLE
HSN6OG/W03j1qlVVqlTdtXMX/rnrzjvZJ+2ngEN2vrHzrK/swiVeWHL43+rWrt2zRw/W/0kT
Jgzo15/EM61+Oha74Xbv2tm+bZsmjRsVL1KU0Js0aSK6rFK58p7du/kMKlUoX71K5SqVKs5N
2b34SbfPPbdy8qRJWzZvfnrQ4LatW9uVvSfG44hH/V/60hc/9alPfe5zn/vaV79KYSMJly5Z
ao/32//3/3y1GwQMd/DUk0/pnF3nq1/56qc++ckVK1bQb50nTn/60586sINFA40bN3aMl/wl
5Ht07/Hxj30Md/36l78qXqyYHkYMH+Gnf99993MrVlxzzTWf/cxn3Vr7W//ylzGjR/vp61//
OsuTSb/9H7f72r170HVPbtu69ZY//9mZL171RQNwULRoUUP97ne+S2aSeKT67f/4x6HDkVHq
PVGY9rNmzvrSF7/YpHHjMqVKXfPda6ZNm5Zlrc0i6rN8zUIiDerXDyr6WT/n1hpcsn79+rxP
PHFg//7kQbL0w/b2veuus0JFciymMWTg8VetXJml5cL5C0y+peTc488+zuxEbzdeIF++l154
ccf2HTVq1CRCAg4k++esklCzMaNGf/5zn31126vWi+98+9tbt24bOWK4YdsdnPWVXTjjedp9
e/dWrVyJL47DAJXXrlmT6HtlyytBbQsikfb49KBBxYoUQXwMJ+PHje3SqXPRwkU2b9zUskWL
B+6/P+/jjzdt1IhBJfVNWOybN23WsWOHl1560Z6Q2aZyxYpbtkTG0sTEgmAPHz70q1/+8qpo
j5epah7YHyQe3WzrK1u9wv/5n//B2mYk1/33h30dLedvf/3rlZ/6FPfFiuXLceP1P/gByCjx
9bGPfezRRx5hSkXuv/rVr55fu3b5s8u+/73vfeMb39i9a1e7tm01+OY3vwlzQw0mD3XYrGmz
iHliNZXW/Yn//d+HHngAb6Own//sZ/afkDomgXB2U+179+q9Yd26r3z5K9ddey0pF15tgwYN
/PTYo4/ywcycMfNb3/qmUS1auNBk/u63/w83mh/KxQVAeXTuWur3ju2vOc6fL999993rYNu2
baR0o0aNyA2moA4dOljsKlWsNH78eL+aPQxWoWLFCRMmWEb7+/Tt1759+759+qD13/z611On
Th0zekzXLl3r16/ft29feweT7EldK+1VyxYtrarI9403XgdB7Na1K5EFR/HG66+b3s9+5jPl
ypazGw+i4PChw927dStXrvzokSMJ/0YNG331K1955OFHwoZWhzOmT0PKq1etHjpsWLeu3WrX
qt2nV6+XN7/M4/W1r32NimFuF8xfULlSJauz9/j2sbcZGgy1d+/e8+fPN+zWrVozmLOu165d
u3//fnQMQrJevegBJ0+afOjNQ7ZCn/70p5944gnaVvfu3V/dts19bRkqVKjYuWMncqxbNMJy
NlCJjhxeXLJDmThhwnXXXkOhe+CBB1CLm9Kzvvud79h9XGLGi5aiyZOrVanct3dvE2pZmj9v
Xs/uPRgVkiXZxBFfdWvXKl2iBN4rWCA/bHTtGjWeeOzxhfPnFy1cqFTxElTNxx99ZN68eanj
8wLwkvfXrk1b74+QbNywkYmM22RoAIHxfnnTTV+86iq6QZiIAwcO/uynP2Nc2bRxE7fEtddc
861vfSvMY4Xy5RE3kJq3/feY8RZRKU+cuOOfd2AnXPf44499/OMfR08jRowgJ6+++ms/+P73
se6nr7ySyFm/bl37du31QNsM96pZvYavhEm+vHkxcMJ4D+bK5cEt2L/+1a8w3sYYCeDTqVMn
7b1dmqQDil+w1Wh5+23/+N///d+pk6eElsyYH7viiqcHD3Z8y5//5BZWorO+v3eVfq7CeD/+
0Y3r173k2GMa1fbXXnvwgQdKly6NDRhvmIK+fvXX/3LLn8uXL2/GVj73HDpmMKtUsSLSIf//
9te/0R2KFyuKmH584423/f3v3pdrv//97wPhMiA98fjjjzz88E0///mePXtoB48/9pjO/3n7
7XT4z332s3nz5OFM+v3NN1tWSpUs8fWvX61zQsbg0bHjm37xi2rVql1//fVDhwxF93g7f778
mD+T8aYbxuqVq+jhN97ww6pVqnztq18Z0H+A4V199dWYbf78BT/+0Y95s/7+178ZCRv7d77z
bbxqOaMrff6zn9X5jTfeYCbDJYTkvGeeiVaW+Hk5kO1Hrv7a14x85IgRX/7SlxYvXITrvPpy
5cv36dW7Vo2aP/3xT9q2aQvnGI04/jAH7tu7J1CjiaXu6Wr2rJkF8hf49je/2aNHjxGB8V6+
1IxnUlq2bNmsSZNpU6fOnjWrQL78hZ58avOm6DanF+Z4E2jBo4K21rhp0+FDhloL8z6RZ+6c
udAtlhOYsjq1a82de4ahXCe4ZdCAAVga3VAz3Kh+3bpvHz29u4j2eIcOeWfUuUQPsdx+77rv
mcRXXtmC8a757ncxD1+iDpECcqcVZzDelVdivIgfOnZ03j7zuuuuu/GHN9iU2gqSk7RBK6tF
vXevXkOGDLEussdoSVC4yt2ZdpiUCEYnTTrl3rJH4sWM58W8GUnjq64KyoYP6f31q6/+7ne/
S9H9zGc+E7TrsOdElJ/8xCdmTJseWt59190f//jHRg4fbtfxpz/+0TpCfl4s470UMR440c2/
+x3z1be+8Y3q1asRgN/51rc2rN/wk5/8JISE/b9f/waxejSbAjveb3/725jtnnvuKVuGsh19
/n3nXcC3DpB4sVjBxsl2sLSeG274oZf1oxtvLFKoEBFHsg0aOJA2sW7dehTyg+99nwCc/8w8
rLt7d4SsoBQdPHDA5W7kq/UrX958NpA//clPpkyaFJ7XX+IUBa9ZvcpiUalSJWd+8Yufe4/0
+R//6Edert3NH3//B+fnzpn9/eu+x8LHrNWhfdRnty5db/7dzQ6KFStaqlQpBz/76U+s4wcP
HJw0cSK59K1vftMBU/uNN9yw6rmVa9aspoksXby4QH6mwLzhkd3rB9ddZ80KLOeVEQx5Hn+c
HiHsJrTBeFh9x47t48aOY2nXDDE4c4kZz51wfO1aNQkBhIXErZED+/c/cvjIGVvJmPEG9OvH
X3fLH/8oIqFVq1b0GS9m5PARsNF33XFH7vvvb1Cv7jPPnFY1g5pK139m9pxXX3112bPP2gKx
x9SqWdNXUiJZ5smKe/59D7q3CmK5I2+9xQNBdPzpD384fPgI1RTjURR37dplwKVLl4kYr3v3
LIxHInmvn/zkJzEbQ5GWtsX/8z8f/8Pv/0DHCNO6d89ef1u1aqkHARaBJmgsDvCbd+a8NXLK
pMmB8fhYvFpbxM9+9jMzZ8586+hRQ/VQeZ54gnS1M7zlT382gYm1wDvWAxsS4TNr1syvfvWr
FNpNmzYee/voJWG8SNWMTbhUuHz58nF+WpuEokTaY9++r732Ggq2uGjw29/8Bh0XLlS40FOF
xo8bT6ZhvHvvucci69djb79929/+1qhBzHiPPVayZElbod/+9rd0H4IRw8yZNfuGH/7Q47Rr
165bt+5Urx9eHzEeje5HN9zw+o7tkyZOuuGH16OKTMY7aHnq1DFikvzYLm9eKr3BkDxZGG/t
mtUYj2LpjtScXj17zJ8/z8xDbjA7sf1qz8/pdbNzSOM1NrbNWDdN4FtH3ipSuIi1wBnXDh40
GF8xoowbN55YmzB+PDObBZqoF7x23XXXLlm0mJvXJ7x9HwqdJZ5QDZYwBGrPXLBgweBAThiP
Yd80/uJnP7eg6Pa/wnicdZUqVOzfty/RRJR5+LlxxrIzlJ9Tp6KtUes2jz/yCFNPoSefZLKz
DbUXomHmfeLx+++55+EHHyhVongWVRNOSle8eeXLlitbqvTLmzaNGDacO962J7lFsO7QDEkP
VGtl/fGPf+yAAAxKmhWBpkcR4rjz9amnCvm1U4cOGA95OZ4XbywjGnr8CV/pmfNj/yEevuvO
aP/2zW9886+33oqSbM8MqWmTyLjCrBKuMvV/+P3v//ynPzn585/93F2gwx3f8c/bI9Pf0bf/
cdttvtqxMI1SuV1Cif30p690I8SdPIiDCRMm2ohrHGm2n/50tHVsEhmT7F5wL15lbcs6t++q
ZcYNXEXaXPWF/6tRowat8qc/+TGf/ltHjtx9513snLiOZ4V8u+GGG/51xx3aWIOsoZ733nvv
bdSwodEOHjTI17qxnCeBWYft8ZYsWfLQgw8SmJw6P/zh9XCGzlAR1730Em7MlStXv379vYXF
ixfT3J5f+/zY0WO+8bWrX3t1m/0IzblunXp8sJH0OHnKevrLm36h/x98/3vDhgy1xuknvMEw
/kzjynN01zKly7iEUIpcVnNm2w6w6onq5DtlD/vHP/7x8MMP79u3n6pJrLmWfmg5sI1kFi5e
vDgWcS0VhsXBIBs2aGjHMWrkKHa1a7/73WJFi8nR/OUvfXHJokVI9Jvf+EaFCuXJTLLOpvHv
f/ubBciON4iWQAPJMaqmVFvr+/Xrd813vst6BJjlzMZNZ4ccX6BxxS3ZAJh9Md7G9etNk72s
dTSb5fTU3j17atWoQdvs368/QUdjHD923LgxY7t37fbEo4/16tnLDpjUpnNnIayYc9bPmTnr
1a1bEcrkiROrValii5jaLIwe7z36yKM0qN/f/DtK7MQJE6MZOXmS6YLW7n1gJC3tCiypqJCk
kujCcsXOHhlFTv0H0gUNiRikT4Y+Ga8xmLn+/e9+h23sNo8fP0am5c2Td9SokWHSeRSQoAW1
RPHiwYPPKmMppQVYF/XDfkhJ++Mf/mBxpXlqsPWVLV48gYYWkwcJkpPZ84FcD+jt3nvu7dun
L/Jykt7VsH59BEFeZZvb8+O8k6dsd2vWqFmmTBnvi0IY6AWJoHVCb8yoUXjg5z//ueelyJFv
brRi+YqKFSsxhjVv3gwcp1evXjNmzAz384y2RowrWo6MzSFt2rTlzrELbdq0KdXLbNNrSpcq
jb6Z3CxPFDANoAvsAL3KLp0716hZ004s2SzR9umBQ4cMiZTPgwebNWuGl8Lz+mvRsR/zRiwT
4ydMwPyWLZYSYkqfNiMeiOOX8QPgnvT2pnhTV65cpQOLSPv2Hdgdhg0bzt5o9SS6Vz5na7Ky
YsWK7dq2a9q0mS+nTp4YNmxo5cqV586d26RJ02ARwUulSpVs2aI5FjJ7xhC2nYnCmbxBJ9nh
2Jm4o5cvX4ZaQD4YKfiHdu7cddYXd+GMN2rkCM9pO2TG+/XpQzcI+JIsH9qzrVqgVK+qZ4/u
S5csYSgfO2Yswg3nWVCQfhbGMzKq4+yZszp16EiVJbgtwEwj2ZuFTuyUCJlwHCGLjx9PlqXw
Nfzk48WEg6AuZsdYnnFh7BqJrzrt9c6Yej6tlMspk4Fb4saZ3Ub++miNDOexPVMNs0TcQ4aV
KBpqpgNdJ8k4Q4vw9UK57mTq06VOTnIXB5Re3kJrfGaD03OV2syDhDiSM06mTGY0pbGqknxQ
aXwy4yniB8qYRi/Fw3oXqSSYiiXIJKSM9kmz5InCGV1mecbk/SYHJzIHGRxd2T/ZZyk1f0Jq
e2/8bAve6YfKmMNMensnxPyFM97oUSObNGw4aOCANatXYyFCL9ipsjLe668PHjjA4rRg3ryh
Q4dWLF/e1q5e3ToWcraKFcuWPb92DRGRnfEisjtxgnmDJ501zBJr09+hfcSrZ9wiepWR3yKF
QDOwIGG9DCQb+zair5nH0fnIG5wZphS3cybTaXoiK946/JTKAKk3DbfMaKCnTIdK8s7sdkDG
f/Ob3/zPxz8ePGkp98q4NpXlkmdMHuFs7/t8zp3hBs4YZ+QGP33ezpxxclkmHj1pk9F7ZsvM
Z8zwFWUAieKOwin/S+YhzHP0Y+bf1DPJcWr7cDJz6s71aPFbzHiEjDd4+sKMyYxXtvCM8WsO
RynPknqD0/fNPJs8Vvxc5+tKT52qcNMwK9kf5mIYb0STBg1sABg/+vbuQ1PasX171oX51Enb
6B7du61du2bJ4iV0D1av4sWK534oN92M089+w1aYNynVgR5GqSsrIhvM1MmT165ebXfets3Z
GO98aO+cbc4hTM4qbcKUZZ+45GTWu8XtOSHs3Ig7bqjwdBc98EvWQdhRx+p5+vM+zcDFMN4o
sqtf374vb9o8fOgwaiToY3Z6YlRo3KD++LFjJk2YaBNFarEWCH+gNDLiUbvpkFx8z8zNsseL
hJgOqZqCD2wbJowf53bAIqkSL2gyWT6xKHv3JSqs08m1Z7kkFqRZnyhDrGUsDUGlJCoTXora
x4tw6gt0jl4wfuzYZUuXXjzW8ZKTRliUz2fSLvmtP7IdXjjjzZo1i0fO7o6Jn1zCVCReNhTv
qZ2vvzH06aeZJWV5GD9u3HPPrWCoFezHz8bzvmTxInFmAVR9pg4ZEf3uXbsF+DVt3Hj5smep
alUqVZaeLGmGUN566whQKLACRJx/0f9ff8NW0xJ+Pm/Utg0yo0XzFnrI3p6tr3jRYpCWYJ8Z
N7UTO3Vq5vTpDRvU50WwdWbCejh3boYZXgoGJCsFW47gpuyyI3V1OJ+xpdt8uGfgwhnvpRdf
tGGjZLKckntVK1WGLcimap7avXNnm9atGJHZLZk07QnFH4wYPnzqlEnMaM/MmQPCUrlChSyq
Jqai+SyYP09L1iHBdazD3AlgRwnjOXj22We5azm+v/+979/wwxt++hPW8p+wPmfdB57tHWoD
z816TgPs0L79GZfEu8ED+w/w7TA3c9QGPSwe1X969+x19113Pf/883//298pzLkffIiVuU2r
Vjf/9ndQS4zXwXvx4aab9NNd5AxcIOPZtRAIsGAd2rWN4NETJ/bt1WvksGEg3ll4jx8PQgUQ
wVatXp3anTq0nzVj+qwZM8SniwmaOmnStMmTy5YqlYrVjLekkcmLnXfixEmECfNuuzZtuCX4
W1IZD1CLP5S/FSry+ut/wOuNi8ZPiNCG4RPUp3DM4JYchzMEJgt7rvtzrVq5KiiHqXKJD5SR
nRvQEpN6vl+fvgBQrOr/uO0f856ZB3ixcOHC3j17Yjnu6V/8/BfBX3+RLyZ9+Yd7Bi6Q8QKN
Mkvy0tDWGC25E3r16EmyZaE5+h/n2/wFCwYNGkQWsX/CxYEOtG/Tlpth3JgxrNhdO3cJ+Npk
rh2/+MKLTRs3nT59OifysqXPRpCxevXejhDrGa0i5nz7bcIQcAyUjDMN1/3zn/90hhWUX5GM
1fTwkUP82pHR9QDZvA+wYMaM6Ry7RiKGCMNjpNdf3xFQzgsWzHeeXxV4JUBPOHO576iRTViA
ZkcgL+VvwRpvu+22alWr0YS5vAsXKgTnTYCDlYJZ7ty1K0H0fbipJ/10FzwDF8V406dOg9Vi
q+QlB03gN0wiwRMRQeJhMHEMUPDQJ3yRi+3rnn8eAA9Kk1bmQxcNEi/1s2fvXszTulVLTmeQ
P7Z4PsNEiMVSMXrqcAlNVYwCkMRS1ov//IfqG8D+jnfv3oU3YAi2bttmt/blL38ZWpIL+9NX
fgrAh5aoZfC589sKSvDVBzrp0KHDv/zlLwU6XHvtNeGk2KJFcTwbvzAMDe824QZ8LNo92l/u
3MlRy88bocMu+IWkL/xozMCFM575sQsSWQdrv3DBQqSPjnUnxiR8jsrRc+zY9ldf4zSHwo/5
oQ/XeWAVYTUCTMMxYRLhvk+eDFfF/44GnyZLyboXX6SsVixfAWIzizh1iX7hG/9yyy0YI8lH
OGDAAF/hVLS3KED04UlGIJLQpg4CS0YZ64ULBSx+/H8+PmvGTKoj5gTvgquIIi3mz+eWxHga
61zyeVApfYK8ZFkgsn+9rFwFHw0yznlPeeGMFywNZAvjXpVKlbgHunfp2kUIXdu2Hdu3jw/a
AUbyH1SqUKFzhw7du3QRU2eb17VTpy6dOrVs1kxcpgP/BA3Vr1vHgWtdqLEDpk6XQ8oBKHVo
115wQ3auCxIPCAhL/O63v2MFDWwwcOBAZ4SWOBa7ASKMozIZ79uEHkSSn/D2vffe94lPfILH
AtzUJaVKlEwYiWYKF0sGBldHk0YRUDOEJuS895we8WU2AxfOeIHoyROM0axxYzF1AszBncFZ
alStWrJYcdgUdsiSJYqTV+wiUoxxxLVo1hSXVqxQ3p4NrlrqB9wovV+F8uVEo8vCAjztwJap
fNmyMtuKCxbhDvgXAo5SZy+IRKBHGHAIY3HWCc9AtWKSggUKOmNrx/KZMJ4wEPbPkOKFQBYV
ivHIW+nMXAKV5nyYFPKQpcSFIdhPUJIGHirNeJcZDefI4VwU4wXeY9IUEsrMwJjO9gjNLEpN
zPi0KVMdkCQTxk9wnsSgjjKW3HfPPYLBxRAJNxRiSLUTAFq3Th0ijspXl+WzY0cxfngAZzYS
zFi/PvuHG2X18J44CZ4pegM/PFmwIMuJVWDXrt3YyW7QSeGYrqI3iuYWBRMkHsZjBQ3xYIHx
/vcT/wtC2bB+FAPONBJyfjLb4NjAeHzfacbLkdR9GQ/6Yhkv5r1TjRs1Jgrq1a3HrMevBRVF
HEWwzMaN+bKLFC4s8teBXH033nCj8BPmeDEX4tA3btwApSnEi+4HPoYnwcapdrff9neARior
BmYtlEkhOx4FMzCifupTnxRl873rrrWRu1702HXXiR9l5Rdf97Uog8DDbiTQTiiKZAc8H1/5
ylfiCL0Mxrvrrjvxm+Xg2aXP/t///Z9jO7q77767RrXqkaj88Y9lTAlRtqJX/Er8piXeZUzP
OWZol4DxdCHEA2JDkIHkFrAsQoDhbhkwJ44bB8zRo2vXIYMHyXriQIRbrH+W+MY3vl63Vi0h
RXJptmjalK+MRte+TRueCciPAX37yWUiaqNkyRJCE95pd4dp+bgF2tA2JbqQSuhrX/uquFtG
mqJFikoJwV5SoEAB2YfkPhAwwhopPYGgSRKPNkniiQoVqC+oxC369O4jJyet9cpPXVmyRMk3
3zwoQwTx+EKcwkyGGFbNd9pq5pgXnh7o5TEDl4DxgpWFIle2dJnmzZsjX3Aqhkr1Ejq1b1+m
ZKmunbrI605vnD51CiVT2pnyZcpiBtksbJzq162HY/3jKO/TsydoGBu9/EhqLURxbjHRv9Nc
SQYvLdTpj+Pt2wW5eCoBLMRvCKySzUGzYGt9fcfrYGU0yeNxrBAOZF8NAU1hy2ozKdAJPEAM
DCeBzjkJPCNbi2eEGk1jGi8P0s3Zo7gEjBcmIOK9ba8KJcRLHHpt2rQWB2R3JIpRRL1/XNJQ
woKgBQLLsCBHC1w1kWV/JcUFBJYNGKEnmR+/vA2eXNROnluvS6wpWQ7CeLJ8AuI5nEwc3Emb
yDNxZs3opJPgHkhtmbPfeXr0l8EMXDLGC2HUZAtZx1ApE96A/v1BsZIb0DzlgChfpsyTBQqo
RpLniTyMnPIOLJgXGet95JKQb4cuV61K1Tq1a2/bGqUGuwymKD2E9Axc+hm4ZIyXyD3cItIH
DlNFBF4v6BNGS0Dn3Xv2+NuwXv0QF8MKKlWE8jcRimXaNJ43fMiAoaIQeFeI/730j5vuMT0D
l8cMXGLGS0DJ9k7SYJJd0kKxpjSoX89XyWSLFy0yacL4qZMnVShXntuAVGzauBEHoH8ay/YX
cmCmue7yII/0KP5bM3CJGc8wQxR9YB6aJy8f/zhnQ/Wq1TgY+MS5B2r4r3JlTvOqVSqrSaIc
lwwuIuoyWC4leP+/9dzpftMz8IHOwKVnvNTHSQwSUJ2SK4p2le5TZJ0SsIIS4EXomcrHnbZb
XE4JET7Q95K++Yd8Bv67jJeksnkn82OmiEvnHfiQ01n68bLMwH+X8dLTnZ6B9AycdQbSjJcm
jPQMfAAzkGa8D2DS07dMz0Ca8dI0kJ6BD2AGPpKMF2w+mZ/zmfX31PhdO0y9eXbkZzgTRWOk
ZD4+V5+Z+Zsv7SDf9SnSDS5mBnI242VHY57PXCDULBe+61WXFqgZYOXJJwvvqScQygBHjBRV
s36XD7R3AjJVGyCN4X63Cbssfs/BjGfoEpCJJFDDxUeKlMT/fu5k95oJVgLR7tipk7ydIhIC
DPqdPn5dvWZNz569xDGcu+V5vlIDWLN6jVwZ3bt1X71qZZY+fVVnr3jxElteeeW8bnfqpIrN
hvf88y8YQMoacbqkxHkOLN3sfZuBHMx4KEwAqwKOii0LxpPWUshcVAg6qFyZJXgcJEIgZIuQ
4EwyCFnJfvXrX//gB98XOBsQaoFkIx0vviTjZCxNVFFWhW9BnE43yKLkwHGYxDNOuntSR+WM
WhnRANSjEkAo0k8JVaWJw02TSkO+CtuXSDcpc5tUPgoqaBhYUnbHVxVdRB7iPceyYsvYLWGh
XqU5DWWHo/7T4IT3javO40Y5m/EmTpz46U9/pkOHjmKO7vxXVEoS9jr1kYjBKNleZmklxA0L
qoghupdmQq22lzdvUhA8cNHevXtCEuhUPsSD5OquXTvXrn1exs5Enkj+Jy1nKr85Vv8tFLIy
87hFbbTdu/YEvTF5F9JVSMJ7y5/+BCAu6yGJnSDsDr75piSBcoS2adNGVC9MuQhj5cdSxyMD
m7sEXtW/TG6ORQkKXAxh9YraWVNCugqRh4Lyk6Lt50EP6Sbv0wzkbMZTAfiqL1wV6qdLMi0a
XeoHRRQ6deoo64TUg+o0pJZN10w9a/wp5C9hIQc4UCDS9773vWu+e43KktgMyrRixQq9evZU
JlL6sxUrlovKFeCLGYoUKdy9e/e//vWvxKZKLC6H9q5Vq5a6hJLJ537oIdyC4nPdd79q7IqD
Fi9WLMTmxlLq5JEjb/38pz8V6r569ZrTYvP48c6dOunwW9/6drkypQ3v61+7OveDD6ru4kYy
d5LkkkpJhJEvTx55QQUZlyhWTP4YgcUwd5s2bVLYUZZeqXu///3vKT4uf+GggYOUQZUlTVpR
9d+tGmmZ9z5x1Xnc5sPAeKHcHBnw6KOPUgiVDZMB6ZOf/MQd/7yjR48eGC8p3aORDLyf/MQn
1CVPpJCDfn37OVm3Tl3JNr/whf+rXKmiSPZrr/nu16++WtXyBfPnhwy5KJtodfBArlwSY197
zTWqr7BnPPrIw5/8xCeFIFavVv3jH/+YMoCkaL06dWfOnKXqqqroI4ZnVPQOeqngep1IAwMr
HmSsYoNXfvJTTxV8UuXuaVOnafCpT35SNaUuXbpKgla7dm3Z5tVzJ6uxk+f62BVXVK9eQ5Jf
Bd+HDx9uYPJ/eljppG6++feSO+XJk2fK5CmVKlV2F0XGW7RoIaY+bXc5D454n5p8mBjvP2qs
KyA+/5l5aj5ffbWK25EOqSxoQnC+ivdD06rUZzBeJAVOPProI6ovBKVOaW+UunHDevJHnukg
lDCeXCxKN6qy4kCKNCextxzvbx48IKyesMWBG+NkSnZofnVepRZK41VXXdWkcZQGNxJ48Rpw
7NjbzCo33vBD7KcT8vbJgk/qYf++DLy4pGxqNrwYB+Cr7S6HmtxnNrHKEjnTrl27r3z5SwKv
rA62uPICW2vcpWfPnn4lLV3L2uRY9hqrg7ymqXd/nygrfZtzzsCHgfGYWBAWmlZ73gIvhYQg
9x/dcOOBffsz9MlTGVusQJfIXXhuJCIzjSKqnP/5z3+Wy8zJwk899aMf3Sj3EsZTuzyD8fr1
y2S8ufKOKccZGO+mm26SEwnj/eRHP4qDel/A8HL4CryQRRffyu1px2XnmZB+YoORWub+++77
8he/+NILL+bO/fBvf/tbwjncDuMRtspq40kGmEJPPRUYz4LiV0kTv/XNb0iJv2nTxm9945tN
mzSWoA3jqVTuV1U+pc1evSra48ntfc13viNxcHjYNC9cPjPwYWC8efPmI6xhQ4dR6iRaJ0/y
5817w/U/3LN7DyqP0hYpdRJ/NGPHJxBQuaRjEY3LOX/0aJlSpSXefHnzywTSH/7w+7/+9dZX
trwsXyCKPyvjqeXgvLydzCSB8X584402cljl61+/WqVbumgkA48fW7Vq5Re/+MWmKRLPSfUk
QreyHhqMjEw1alT/3Oc+F1JWR4zXurXx2E8eOXLkhz+8PmE8i4JfW7Vs+c1vfF0WpsB4zZo2
SWU8aRaxuiVAyy1btmhQpnSa8S4fjssYSc5mPDsi4uuvf/ubRJ0sCtgAsSK4B+6//+qvfVUq
aHn7ZNGcOmVqEDiB94TCf+ELX7jh+uvt3277+9+nTJqocAIr4q9/9evb/n7b5z73WXwlv5hU
gY89+kjgBNYUN1q0cFHY49kKOkmgsce4S+7cD3FoOOAAkM+ziZj6GjVtGnPlyvWnP/5R+9o1
a4YBUDTfOnpU1m2bwwceeMBmjFDl+mCTNE7M9uCDD1WrUkXCqOBOOHT4kAd5/NFHidNvf/tb
IUVvwwYNlHRWHWXd+nWf+fSnpfpUJ8xdOnXqHD1dr16Ob/nzLSqHSvL7y5t+oe6KwkZvvnno
sqO+j/CAcjDjRX7t1avLly//1JNP2iMxLXJhoTx03LdvX5aSw4cPod1ixUvIlptpVMwogrdk
yRKZJvLlzVumTJmQoX3pkiWly5QhWzjBfN2/b7/k1gMHDoom6NSpRYsWlStXzsZJ/s9y5crL
FoOJevfu3ahRY0qgBBb16tU/fOiwnLlVqlRRBkwy3BbNmxmXHNgMnqHPsMezFRQK7KcCBQr2
6N6dwyNTFK9ma3niiTzdu3aTSLtq1ap6s+1knlGDRQJCObVlpqEvsr5UrVKN319hzWrVqqki
ZmDlK1ScN3++rrgWWrVspX9Zfd1UGaZiRYs1atgoLpT77jiYjzAvvK+PnoMZLwvwKoim4DtP
jsNBIu7iqWVXzJr8L0tXiWxMlZOOQ82jjM5jX3y4Y3KQfTazDCD49pOTKWPOejK6XVzMPdtd
Mu6LiVNulzGwgBA4PciUeyWmnfeVvtI3e4cZyMGM54kCICP5JM8YzoSv72RUOPdVSedJJ6kd
huPkLllud8avmbfJMv/Z736Wx3mHu5zrdpmPnPrUqe3TjHCZzEDOZrzMScyE88d5ls49s7Ek
OXviwFAUNsiZiA1SOzpxdgY+U5ZGl4QJvbC3G+RbKt8GGXthvSVXpfYQS9ywZFxst9lHFeT5
eRpPo3m+yAfLyZfnYMYLalXMJxnFzVNddmd9KciCnVAi97MSDaZl6oTw0HOis6WSLzY4gxmh
yQ4dCkBKn5DS9+jRt0DMLmA3hR/Azdhgjx59O1Bwklz0+LsFKZxDpgW7bpZBBlY0d5eWdJN5
i5Ljv8MKmDHUeInxXJd2ADmotxzMeIYu/bsqPw5e27Zt5MiRGStuCj1loUgvm9Fvfpy7OnlJ
QcI4M3bM2LJlynAqRILr5MlevXoqmB54+9CbB2vWqLEmNpkmOiFoJQxXEhWhKkP//v1nz5rZ
qWOnpNlZNcwst05t075t29WrVrmcfaV69erlyparUaPmwhicfVaqSgafNIjQ1plNiTWrABvp
nrgsWXhMZiR2I3lMzd5Zx5mI3NN3jKYoQ7s++zD8GkmwE6Bt3bt1MxWhWap+Hs6E/ScLsLLy
qswT6HGb00tA/MoybhIdXerV4TJhzhzMeN4fFOWwYcMcrF29mjkxxazwH2rMGV8zzQwd2rdX
F8VPQeVKbcNEmdRIQQ4lixd/KNcDwavO38BTFy5MPvsP7GeHJD/DGX48BlI2RgX9UpvFq39W
m0pQa8MnlSKV5gRDcRICUywSg+2Lz78AL5baONFmk5PPPPPMCy9EjrvsHzRdpnTpBPzN3aLP
uXPnrl+/HtLgrFOUejI1BiI5HwaQxZATfuUyZUNOFqPs42FP5tv0yM8tXx6gQhmTQPU9ccac
ZJmfy4RhLtUwcjbjATEHZti6ZUsokrx27RoHEF4onS9B4T4FjJT88ZxDnh4CzIXspPcM5G55
htKEhLT245l//ON2QOdDh4CJT1HzlLYtVrjIizFBk5PFihThxHPVwAEDXeK+Rw4dIiGbNWuu
OBmfOAwXMSUdfdPGjV0yccIEjgTgSb3Fmt6pdevWqT0GWaLw2PbtO/r169+sWTM98+D79O7Z
S4F1qLckGogDoGbNmkYCitm7V2+IcEU2ZSilD/MouESue9VdDB7MTb0xGG6xF9DhilhzpZBy
XO2G91SBAkHi+bRs0Tx1+bBqqJ7rcaZMnkT2zJgxs0uXLk0aN546dVrTpk1HjBjBf6j8k3ir
nj17jBo5yvysX7/hjTdeBwQ1FRz3oS6Np2ioEsaYsaIlxowZy5uiTevWrT2vmoRmHgZ9/Ljx
O19/49FHHgHdduHE8RN4VlauWKGUd9u2bT2Xik5eh/cFgkPfBtCrV68e2PdpCXipqP4y6CeH
M16PHhxxFDz0V6N6dZuZmjWqL126lMyZO2f22jWrVSnqipQ6d/YWoftR8MO5c8+cPiNQ4YRx
413F+6wi9IplyytUqICybRTDm27epInqYoMHDrRjaVCvXtu2bZC4gs9g1oLcSpUsaWnX26hR
o/jxlPJbv2FDsaJFpk6Z3LJ5c5KTgrdi+Yry5crjk9Dh2tVrli97dvCgwfh/1apV4pjokGTm
ooULJ0+ajDQXLlx0/733GXO8LpzikYO6tr/DLerAvPzylnJlyr7x+uuulX57wfwF4h6sC5gN
0UNI099g06wOHdp3oAh07NABt4wfPz7XffeFrMH4X83QLS9vCeuOvwL5pPQGDADIVtUMB5ol
K8uDDzwAzlr4qULLly2/9S9/GTd2bNHCRejVVjRTQWxWr1YtWo969hTN6NdHcudetHixsocW
l7x58ryyZYvGvKkrn1u5bcuWObNnqZgtOmnDunWtW7cSh4Eb8z7++I7XtoOzzZhuwO29Jrgf
RUsVG9W5laVooUKehVj+UNpgcjrjdcc5EydN4j1HuC+9+MJDDzyABIXwwDELz1F+CCwLir9P
r17oA61079o1YTyiaVG8fVK62RIuvGD9+nW+hl2HIipCSJX1e27Fii5xmQegUChKQkybIUOe
dgv4LMoVE0uNaAe42r0wXpvWrYiRpwoWhFp+5OFH4mJjERR7z569cG21a9dRBX41aRzXW+cc
VzJJjaTFixZFEql58xXLl6cwXjWi28Ixa0a0WACg7Nq5U6Q5BrMXjW8XgXKQOEf53j17H3zg
wU6dO4uHsvRUqVgxCDq3c5UDXcHQIPqE8dxu7uzZvpooSb7bt2urHwjPRvUbOFmnZk2kryq9
Y8vX4oULYdAUuLeiQc84CbNqVmnXVA9fmzVpGuEQSpZc/uwy/JzQlqXNSzG2DRs2KBplzHTR
EsWKLlqw0AriwmiJqV5j+fJloVvIoeHDhls+OnboGJaMJKLyMpBVl2YIOZ3xeii57sVs2bwZ
HYPzI3cUbBexbdurVStXUbeoV4+ezZs2xVpjRo/REouKQI/kXUQoTYT8OOjTp09c46Hl889H
dTAD4ylstH7dOu3xtj5Rw/Rp05FmYDzhORivdu1aGI8hVJsMxpscM17/ARaC5cuXr1m7lh2V
ukipU5hFvomhQ4ay06xa+Zy7h1tPGDcOPwcLCjVvxbJlWRiPNJg5Yzp5VblSZbqfZPj169XT
Zt/+/YSneHYYmvnz52G8fHnzzJkzd8WKFQBlFcqWjRjv1KmK5cqJMAyP3LF9h4DwDh86ZFC8
RTnFjNeOVCf6LEmmgPoAc1eubFk6uQr1JDPgTq0aNaSrSBhPKv6pU6d4Cp24iq2rdMkStsTl
SpdW/dNJJRCB4BYvXkJXN59DBj89bep0ANfiRYsuWbS4Tq1a2hi5NWXF8mUe31cQ9rHxy/Jy
K5YvB/j24bOw5GzG69ShA7LzhtauXmWZP3L4kIrQY8eOmzNn9tZXtqrCZ9OCRqtbpNeuLVu2
7IwZM/55++30yUB2djIVCY2pU9lRtmx5GcosWBRjxjtRvUoVYT5UtVtvuQW5d+3WbdLESRiV
MjZt2lS6mQiAu++6i/Ylao5eR1oWK1x4wrixlDEaoOKbtCb/mBDYcWzkShYvMWH8BMTtdkgz
ADi7dOo8dtQosbyRfjVt2t9uvXXZ0qUx451EjuwiMN842bpgVJUrVcLSipm5+7atVLjZQn7b
t21H4tE2d+/ehR/69+s/b94zIoawa/v27QcPHqTEvP1neK6tW7fBqhmzqaDaPfPMPHFStqYl
ihWn1EGWkdgUh9o1a5gBxQynTJla+MknBUlAfs+bO4eSSQCSe+Da5u3BXLlEA5oiMln/BrZw
wULMbxMrWMmiYAJ6dO9mxZk/f/6/77rTRprMr1O7Di0gz+OP7XzjdcqzXZyWdolUaOuXfhg8
Bw0Y4OmETRbMn4+4jhnvQ6Vy5mDG8yps53CUA+YTlISyrNYtmregpciqYLPEQgDfGCwco0aN
FlBDY6RrhU0XKUT+MGYKnGOnmz17Djt4+IlWNnPGTK9cLDnCcvLZZ5996aV13j5SYyBhGGRI
wIrdunbDdSLfhPkISF+37qUgEl2Ojok4VhDCSqcvvvCiMtQDBgw01Fdf3Yaw3IcNEwNoMHjg
IMF77CUqchqAreabhw5ZGt4+dgxSFFc7iSXQqBxJrvUULVu2tDti15HsqEWLlhs2bIRWpTC3
atXKGYKCqta5c5cRw4YdOhhbjOJ93Yb1G8RGNW3SFOLUyfA4OjQDwiNog0L4bWbNgOAmSw8r
CFMHcaeCvFgkthn9WCMYThTTtsS8tG4dY4n2Otm69ZWxY8dQHQ8ePEA7ZXbasH4dZcE4hw0d
ynwiSNLwbJLhV60pONBusFu3bpCufsVqfBI0BTrLwAH9CUD7z2gVjLyCaca7NFruxfZyNhzj
acRjlhUlC0IyZq0zai/7GsRgGFZG+0x3Q3J5oN3wyeKxSAFyngZwRs0yP8mFp3vIhJVmsdpn
ONDjeyV3yfII2Xs7x5nEMJh9HlIGkzF7wcmS2jLJCpM5RWdBlqZ6F7Iv52cdW+pkJpdk91KE
7FUXSy6X2fU5W+JdZpOZHk56Bs53BnI244WlMDyDv/+NdfG8nEjvgOTM/hKMMAMReib67Hxf
17u1o6clYiQW25dOUMT5qoMwjKc6gqWE40QipaoM7zbSj/rvOZjxImTgsSi5nWc4cvhIAApe
SlIL4XMAlJlozOzE4tY+4dbnRUoxgIad8xwpn0Of59XbmY3CTlL/zDkh7V8MXr2Ans5ySUaw
VZxEmCE3mvaTMqYd0f2xY8cxYvxconwjS+alueWHupcczHgBlGxbz5gmHlQmr8R+EA4CBWec
jMD4Z5yMfsgkkYTQkwszcsyePMkAGNIohJkKxJCx0mceMJ8wHjCuhPMZvUUwwwBFPM1FbJvA
GdBtsgwi3+R2qaPN6OJsMUEBpZ3cInNIp/tnfhRcW6tWTaCZZc8uCyDIlIfKGH/2543Dfc/F
7R6Njy6a6qpVx4we/eqrrzVu2Ei0LjOmK3kO1LiHs6lZs4Zmad5710UjBzOeoUNISIk3e/Zs
tjKZS84EQJ6BwwxaEBRI9l0+MRkLh+NhLlIrKyDFjRs2nC4WHRN+zF0Z3fCYAXIxq0iORBSk
dp6p8sX6WCa78kZwasGy6DbcNwnbTa6dMGHCypUrU7six7MPO+PNRewSc2PMj107dwFzEboO
xsUgmfJ2U0N44+CjTANSKmDVc51VdOtH5l9wNu51YLfXXnuVvZEbAGhG6he99ezenbN029at
7psYjd+V+D7KDXIw43nfDOuSWCZEiWgGDRhYpWrV3r37HH377aefHgLhIWPCqBEjYa840y3M
cICcXc2aN2fdrlql6jPPzMUwjPi0MokkeAIgs6Smrle3Hm8SdPLokchr6759e1u0bFGrVm2+
JmEQfG4w+ERcseLF//WvO3E+vziQNN8G1JVkDbyCL7zwYrt27bnRIdpwV5hoRvmypcsEGyZX
Ne+WA64tcrtJk6Zt2rR9Ye3zd999N+Al2z1HWeUqVYYNG+7K0aPHcJPobeTIUXXq1DVgcBl4
EYiZkLrChx+iQrnyQQ8MH+tRl85denTvsWPH6zzgnpcj0Ug4SPRPUXRrDhjhFJ4XkitSHUMs
YmYPiYQ3G+pMJD0DAwG7hK98DOXKlnFt8utHmaPO89lzNuNhKlnDYrmBlE/xDpUvWxbFYwzw
rkKFCtG7+HaLFi4Mc8hxDOj477vvHj92HLAvyCVvFXyTNZs/2n6Ok7pr5058g8CNWKhK5SpL
Fi/hXwawhF8BziBDZKpdumQpkQKECc4CRgzvAh8t1R9S1icHF6xww/r1YankJuKnKl2ylFCA
RMh07tTZ7dQ/AVXhsufyMmYAK5UPeL2xE5TzyBEjXFizeg1eNU5zmaQrV66M1qGN9UnMQoE8
PWhw6VIljYTHMkhX4+Gdc2DwHGikK6aSahrcxIVgJc57XoPx+Dz4ADe84YSYrE3AAIQYn57L
9cbDKdxB4plEVjds0PD5taejoghtqVy6du2q/arnVsLKOjBmrsjZs2afW2s9T9L8cDfL2YyH
Vp59NgPn4cVDPwyPBSBHMEhHvbp16J8L5y/o1qWLkyWLF/NVPAHUv8zNI0cMf/Pgm+XLlFa9
AJoR40lSBPW7bNmzUBra8+pOmzKldq0oHK5i+fJJqAuEIfRJ7ty5582dC5gClmkSixQqTGpF
AMW4aoIIicGDBgYEI7h9iPSJfcCRrLMdhbDhLyaCpkyZ0qFdO7gtTAuo7VeLBeCVWz/84EO2
jlKhLVq0MGStxYEtmjXXpnKFiuDaoGc4n8pK3YwYYOWqgOR6bfv2jh07YoaNGzcEMKSFwNLj
oG+fvqCVXNjQBWRUtapVwFwAXPwEMSOeIEgt0ljaX0tA4EN/HYen8DW4+PbvP2AAAGh0yxAa
4om6dumapFT7cHPORT5dzmY82wxbi0TDGdCvX8h4CQMFMIUa1r30EjgFxsMMJYsVI5QwHigW
/iRVYD6gojAevnLV9OnTevXoQRSgS19VCALdYE4gScqWKqWyl5PPrXgOdtGODriJXgrKGKCP
gPwEkRgCE8qiiCKHPj0kpHZu0gT8MuCeMwwzjjEerVI8IY6dNjWKbNq2bWvZMmVF2UgyLawB
OLNK5UrSh23dtk3RH1wEo+zXls1bIHxISLAsWiGciicNMwAUTrp6HMe2ZDHmez2hGo2hUSPA
SAc0zxnTpoO/gNFE4M+KFa0drVtGz2t9oW068AjgY8IvILaC7HKSug5ikkx1OLCQlS9bThAQ
/Tlgr23zwMqTh71I6vwQX56DGc+6Kw4I2M/mR6wXzSpCSxYtKmyMQkX+UNIYJKOok3btAK+e
zJ9fcQ9qJ+Ai/oTWlTzTV0GiwJODBw/Ony+/JNBUTUod0rH8Q3VCZgLv2klWqlDRBgnErHSp
UsTUww/lxqgLFiwsXqz42jVr8z2RBy4Z9kpyS4AskmrihImdOnTUj3BvgwkEjSswqruDO9tb
zpg+TdkgLI3oGWkMHnga4llsgQgAjya2TVwfM73dncD5WKlr4MFJb2OzaxXWoDxQIHR/NS5S
uPBo4Q6t2xCSJCSkuPNw4bZ/IP+lSpSkb7OFkI1AniJ94dGo3/aQ1atWE0aQdBVYK5C+kZtq
wFGg6nHjxi1cYCzP2OtaDlh9NbMdtYKYeboAqGp84SXyY3xImS8HM17AFqlZ1a9fX2YMUdi+
KpwgqjJKanDq1Lxn5gpPhVoUFcZ2ggPZJ2logkRffPFFOx+bHNs8+5nVq1d16NCBGAQRtPvC
J6QKsbNl88u6xRiWfVYNbZCySBlCxoZQYBty7NWrN7aBzHQM2ElRpPFKaiAsdeXKVZhEEKBq
dcEHsHvXbtB7Ymfzps1GawtHAut8/vwFbdu2U3VMG/BuDYgOGE7PhVvkcdEJeKf+RXB7cBuz
lSufAxPt06c3QRfkUtAAlyxaRFZ369ZVnmmTYz2KvJHHjsFG4gpD0obMpwaDU5PYrP8Vylc0
5kmTJodOEmZLpfloqnfvxmYqNwgFZGSKZmzYcA6MYJ59dslS97XrE5KX2s+HlHEu9rFyMOMl
pJboP6mQwiABsvwUnjb5KRycFQOZ5WTYRGX/pE5flkQSoXEqyDO6XYqPQ6g7AcKtl9ptAhk9
Y/DvkMbi9NPFZBB4JvsgA7onOZ/l0UClGVTDr+dgmHMgRWP80BkOj3DmYmnzQ319zma8nPtq
zLtNXefOnXfv2nlmIsH3+5nYReWcjtj2PME37/cAP5z3SzPeB/Zes8irD2QciWs+QtsdT8uo
9+8lpBnv/Zvr9J3SM5DMQJrx0sSQnoEPYAbSjPcBTHr6lukZSDNemgbSM/ABzECa8T6ASU/f
Mj0DacZL00B6Bj6AGUgz3gcw6elbpmcgzXhpGkjPwAcwA2nG+wAmPX3L9AykGS9NA+kZ+ABm
IM14H8Ckp2+ZnoEczHhxmscMMH5I7hhCb97rS4WZDLMQgIuOU+H277W3828f7hINOyOO4fSl
IVDg3J8kniCjcQhNCBkv40+YkPiJMrJZJ8EZyU9JCEVSFDI1ju7MsImMyQkhF8ktUoeadBs1
eIfohIxHzoyWOOszhnGeT3xD8qbC857njL3b1L4fv+doxjsugaRMOwoehPcktDQqzfMeP+Lo
JIOQux9QWIidIL04LewJGUfE1L1T6EBCxO/xbqebG3AIKfQ3yTLkZyvHoWgw70hGgR/kL1Ip
QfomyQX90YnAQtmZMugvypwbLUzCC50PS5IDl8R3PPHWkWjqhCbs2bM7JErcs3uvZ08YSdj7
jtdff3Xbq8IRpb2QXdRESQkTzU9mHIObRj9l1pR3awUbBPueIywoZHPzV4LAqBTz2RbKI6rP
HDoUErqde3rdyPOLAIwm8JwgbzdSP1C5lQt+X5f2whzMeN6KkiCFCxcpX768mjvmRSEuQdln
ov5Px6Elj5p6gAIkhhg3Zkwo6dy8aZP1L70Ueli6eHHd2nVioZqZqTqOxQ5SMdBxdJz5axLz
FjFPyoqeiKZIIsWfRFxYo5VFkU9JHGo476/g1Hx58qKSs5Kdk35Sk0z6oxrVqklmMWTw4Pnz
5rujNCoSioWrYu49JEGLHBOK9QiWlQRNLgwJHUJ2DPHjhQsXln9T7LmvIoNKlyotq8XmzS+H
B1RJS+2X2nXqlChRQj4YZ6Q2Gz92rIygoorDg8ho5hYh2UT4KLckv2DqY2al1xMnhSM3adRY
foCe3Xsk61d007ipg0mTJgmxdZyljkKsz2Smr86czEOHolJ7wurDTSPxHmVJy3jvyd39pNRu
wwb1w7u7tFx0Ab3lbMYLOeeIK7m3vH605aVaBRFEyE0kdlu0NbKTalptGhOuio3zcS7naJmX
EkKWPqm+oguPH1ezTra8kKlOqhW14MK6G9ggfFSl079mqhxbm8PqLhDbT/v37Uu4S/0gvzqJ
evQfsu6RTqFlLO2itV8AePWqVTrG6YZcK/+SxJsPP/RQKKyV5Y0GaabmkdQS+MqodCv1g1QU
0YAXLmwYF5TMYOAZM2vXrOUWEq5MnKh82Fi50qSZqVi+whtv7JR/dvLEqFyZgXhezC+4XslI
SdNCD+5ltP6akwH9+jspnp1AM11uahyRgD1yBMWHUuYmXz9SV+jBGwlBydnVPyeV1FMQk9Q1
53oIExjl84z0jKiQ4N69+6gbo0eNxn6+xm9nj+eVsjp5F5HUlUj32DGZF4sWLqTCkZ/27tsb
K9sIIJreAwf2hzGEN67iZ4P69dKMdwHLxBmXmE35C6QeMbOWZNXhlFaUXESevFo1a6urLNeY
1H0Ki1etVk3qFOWOK1WsJNlJqxYtJUeRztkbVU1WZjuqZs8ePWlRsnFpQ0qowuU91aldS+eq
z+lNTgdZfVSQrFatuvSYbVq1/sMf/oA4QqJOmQUlcZHQWvE3SVz69elrRVfRynIg54ocKtu3
vybZniRIJJWsE15/RGsxN0pRERjPZ9SIEf379lXQTycJC4WfgiClK6q8l5o8V5EwCSw0UNFS
TdbQ2EdmJDUDpSSUr0VWmKaNm4Q8ufILyq0iA0WD+g0krUDrMlyE0sqknPRHFqkgE5yRu1Yi
I6wlHYb0FmHOlYyVRUJ9eckpLAFS11A0ypevgLFNmhTD7qgs4e7dewIDJ0MKfbq7BIcmPzCh
rKS4i1yVf0lqDPM5YcLEAf0HFCxYUBHZpc8+a3klq/M8kWf9upeGPP10hQoVpcawQjVp3ERi
JSl0S5coIfWTZlKqCuo/8tYRiVUVnY5qa0s3HKeiqVSpcolixcx/SO59scR30dfnbIknKdgT
jz/x5JNPNmsSZbZq07pNvz59LN5UUDm/VCr2RjGVcseoTQlLqY1e3rzl3rvvlgTJu5w+daqc
JbNnziI6MJu/UdHWoUPkyUOyVE2aiaRjRJAstxUrlKdrPVXgSbLIvkKbGtVrWEddSNkjHCSH
xhV66N2zR8F8+W0nsJZ8gZhZs2NH30aO8rXIfSLlHiZKDANy+6mwafwouE6t2mR1tSqVSYNA
H74qE42BQ+72TZs216xZK17Io0IRDtq1aZsnTx6FKQsWKFi/Xn2XHIlqJ0RqcMkSJf/fb35D
vURrmPmlFyMt2pDGjBqFQ3AsQmzbuo1nlKEoqJdlS5ci2SI+jzvv2qWzTDAOqH/9+kVZKnCm
CntPFsj/zNw5tpSFCz2Fc0yC/bAMn1RN+UtlH5UwSh7BaJwnT3quSZMmWhnDE/krd8uTBQvK
oSYHXKsWzTdt3HDHP26nvCycPx/34u2e3bpT/vv37xfeoIQuMhpa7yxnJtYyKjna448+Kukb
SViiaFF7UfMvMWmp4sXVpldfVvFtSdaktLHLxefyXHl98jgaUprxLmrdiFZf5Ua7dpN6VeYv
mpIcRCqJSuq65eXNqEeWS6RJF6JxeT1jxoxWAN3uR6lXKopMW7Z2gwYOkM6ImiR7LD3KCrp5
40aqqWoMC+fPsxVR1TH3Q7mbNm1WuFAhRRLpdWQdBpOtCK0bg0xbJFggTYmrH3n4YTk7EZbz
XraRyDOp6KQslI8+/EjtWrXUHmgoU1hmfRUXSs2E2hy0bdO2atVqhC1VU1KjIB+sDldccYWF
IFAMc0iF8hVcHudgjxp0aNe+b99+iHhklIEvSr9ZrVpV2fgIfyPctHGT7KOSiNKyQs5pOyvF
n4MUOnb8mOxpshjGtZ2lEjtcoVyUri/6Lb5X9WpVg248beq0wYOj1NG1atRcv36DdKO7d+4k
ssuWKW3XJ0116HDNmjVkjgMZqCRfDCc9nUfo27t3xM+ZezNZp3DF5s2baMKG59WYW3J42dJn
B/bvp8w19Vj604h1T5zUZt2LL9FuHnzgAVkGZVKTetAW14pmybPHw3gjRgwnAx+4PxfhLJep
h2VzkiLR17pxweeN6zeEEtNpxrtYxkNDiMacyq4Z8md6YWafUkfJrFq5UmQ76drVrlob/IAC
vKeqFSsxYsppOX7cWGqkjF00N/obxtOPVJxv7NxZQzmO+fMaNWgwYfw4RPnmm4cOxkVV9UO9
JLJY0uSx9tW2SlXUtavXlCxRwg4K71GfnJcXjG4TLrH8Y0V0tmr1qsM0uSgzV/RJrClKk2um
7rG0fOq8/uWWW9wl2HAYFSWcJaAsGWHfZdl+Ji46Gz6SF6JCB1jOoqNz+iHpLb2f3KHO+5XU
tdAQtr7Wr1sXe4RryZMK5ctZODz+sbeP4l5LQxBKfu3bu0+oEe9DZ+vff4CDMqVKrd+wgagk
1mybCRP6BR4IzVavWa0EswNSS20TBzpT+hxTydUZKdjRJ8PIVKZUaZk5ZWcsX6YsPqGTV65Y
ycj79O5F37ZQhpkk8IcNifIUW0qsj8yqllEagc3qgf0HPG+ZUiWlVLXAUV9NjvRNqtWSvQS4
bYOnsxOJ52dZtGlPG1cuiu3ihVPuV6nUbc/oHl6YysNegL2HN03BkHOWQvj4Y4/LZCklprIK
FmbWDUqLNyd565hRo627pCWZwDxDqWNIWPfii6+/sZNiJnlk3dq1WR3Z+qKq3IMGIg70pLFc
sfrPlzcvC2SDevWdl41PyXXcpZ/evXrTyuyC6I0SUBIINDELBIlE3EkFL5Ulug6Gh4gxZsyU
4jJhJAdVK1UKxqFEPjiOWsfqn61agXz5KYoeH/V36tB+aqzU0cQ8e9KPgsaFnnrKgIsULqLW
NLovUbwEg1CdWrVw7zNz5lIWlExo37YtUrRm2Z3KqDtz5ozQA6lu6iQvpKiTyXaMZL6Huutf
/6Lu1qheTRZ3/dDeLXOutQzhwCWLF4WEtj169AwSL8seD08/v/Z59lL8Zj3yq+LYD+TKRQex
ajxZoGB0bfcexKORFC9aTIp+Sqkq87LQSwFM0bXBk5rNg5PVrFk8D9RL2RatHfJk57rv/pjx
mq5eufLAwQMVypbDqHazkhRbGW1D9J+WeBfJeiet0CNGjLQuBlMEFUj9ILttTIi1qKCUfsV3
hg8fMXnylI0bqX6bvWDrPdcTQqRKIeVZs2exgqgr8NZbR5Xz3r9/H3cg4tCnv7qVqdZ+Q4ER
Ak25Dx2+eehNQ6d5yodp48SAqdkLz6+VSRZXUJ+wmeyuVFbjkQyXuT961LhKOCmEaJJ3H+wl
EmwmcxHl+Vy1yvbpbPQRmf/ci3mDP0AaX5TnqVhuULAkogaT9KMZ48eQIUNtdwMvrVmzdsTI
kbt2RuXEJH72UDNnzjIhhBLzCTvTM1G6segT7fcOHpRp0/RqRvvVP51NNls7KJZh02WG5cx+
bsUK+gLiHjt2rLoRJs2qpzG3xGvbtgX5lvrx1XThEzMZKxEnvaOQXt4uMVS091pf3vwyFXfi
xEkyoCqDYdiS1StJz/eowAMlxcbPezRLVlJjsAQsW7bMhFhq2V3pI5HJ9OhR6wV92DFXkzdI
nblYmrtE1+dg40qqNMiyssZrWkoKyxRpEq5Krj2zslesAmUa9MJFqQt2SjcZtofkzFnzYZ7R
PsW5Fw0ghR5Dsyxn3tHwdmbyzOT9JeNMJYxkAIHtU0abJQ3m6WycyeVZKIOim/I4mbXHYqUx
Ow0lg8nuToi4OqWj1JZZJjx7t6nzmepeP+sYkrechU4uEeNcbDc5m/Eu9unT16dn4AOagRzM
eBbLZPRBOwoC6lLOZOYtguk/rLJZbhCt2SnFYrNInowLM4Esrk0VO6niNFEss8jYLG0iQGnS
W1yJ/Ayxlu3howk5w5OWkez9vc5SIo6S580+1Umb0HmQOUGSx6PIQKWeqUecgYzNuCS+PExd
xtPFVplU8Z78FCpsJhpH7IS/pDTwXmfq/NrnZMY7fpxxcssWxRG2ej0HDhxUEOHSTrqXGpAT
sQUyep1gK1lqptIJbTDsKjOoTZVwu59Dh8LXBJpoJ7bjte0xnOKg3SZkhjH7avuhyMGGjRtY
U5JLbOE2bNjI4geWoQ3XCD+4j32XF+Z2Nqs2OTjQ3mzbtlc3bFivOOtZnz1GyBzne1SyyxgS
pMj5kUdGK0NVOMVGLjx7BAw6cCAq457Sizb2xgyOYRjhjRheJuNFLGQ36CnswWxVudftM5l4
wzzYHJoFM2OEoddQKzce+UZmEvMMPrpp8+bDbx6KqDae54ALDcgyW2VTcekX3/c0U+fdOAcz
nilmqCxQoACsCazjunUvhepwyaoZjkmEQAepP6WKytS5ymJrdgksCNe58wiCAZBlLwJ2pIC5
tOGLZ0EN/b999K08jz/OPZg5jKikEeM7uytfBXplZgRe4dTmxEdMjgEs9PB8XGndYI6+fZQR
r06dOmXKlKlapTLjQblyZSFu6tevhzIxKkc8MynPHuMNFEjevHlq166lxhBTx1nsMXFNJYUs
QXaAeEKxsWha4k+4Y/T3zD1laj/hF2WG2HK13LtnjzEbQ2ob/WGApwoW7NGtW+jfje6+8061
BMMtNN7+2nYGZC+rR7fuVpAWzZt5BP4DDIMhlWoyh0yj/EChZxeqjlKkUCHNmG2xPb8O2IqZ
dIlnZyKGEIAo0nLRosWKGbHfqj2YEMB5c8EH0DBnM556yEyall44abYvrlXIzEgURNrYKedB
+EFEYmo+xueDaKK3EpePVXkHXDPWTML6Gq+cQb+JpYSWjGBPFSjA4a6BGIg+vftwWwErhVcb
tB1m6wL58sVglIhW+KYfffhhjuCEppVibtUy8inrMwYiRmOAseKWcEmtWrWA9AMnJO8/0C4X
Ip+BS/Ati2tykjfZsRKtHhlqhA09/HRW8tEtaczUHiBabkO0sg1akAio0C3RQTQlAtOsRDOT
oSJGz6gSYJ5HH2vXJipbCQ4CjRlVoowrwifzAOf5+COPdOvcOQyGizXXvfc+M3t2Mg9gesEd
J5ri6FtH98NVxvg1dcswlRqd4cIgVONhHyxetCgfaXTy2DFOF04Lx1FVtvETeGUxeVRbs0oV
r4mnbu2aNdtffY3v4aww1w+At855y5zNeKRHcKBXr16DLbtA/ny1atYCwmShZmeP5EyFCtxK
bx48wDmrUhwX9sJ4DSYh8SpGpUEFig+KzYwZylYtdQbtOetaLxicivvBSbKOeAp8kvAqMATg
RQSJOHWKpZ6rmi+R6zkm8ij+BU1wJXNeE1YJbXFgQDBpYJ3u3r370qVLUjknNIM+4zcH91WC
jz+NX85JhcSqVKqs8BjAGvs7lGapUqVZ+XftysB2ZhHvboHTVN4MHhdAFsLKs4tRgLHi4Nqz
ew9NwTKUcL4DZQBVBQuPQEo3atBQnc0O7TOcjZwf0KfJUqGN9U5XADrd4yqZ3Bgtm7ckIWdn
egWxfdmyZUBPpkyZZM6jQcbhHcFJyNOdN29eJQq5ExJG5QUh3HhKleNzkqfE2+TM4OLHaSbc
JDhP4sGaQagErDaVRNG11Mm83FgujCeHM16PHqWjaoktOUxfevGFwk89ZTvUqWMnPiLeapAO
OgxZBPFQIF9e72zunLla8sMiRE68ShUqzJsXvdRkpz5s+PA5szNAIZzOMGj2TlGlxZgqufgq
la/A+5QQh57xGJcgwIqTsKMLFixQjxaAJuqWpH3r6EMPPIDhjYpqRMKAGloa/nXHHevXrder
oIGBAweWKF4c80TdZm6QOAA5fMkiG6rRI0ciUGUrLS7aAEz97re/LV+uLJFjm9S/Xz8162hx
RERQIHm0Bw0cZCsVhwedNAlPPPYYqlUxE4DOP15paiGOov268OlBg1yVaoYB++IfD/w/bOgw
/jF4zgQXpta5KuoJ42kD0wyGCnwXqk+bDY44LLFg3rzQCdfl7X//O7CBn1q2bOV2XkeRIoWB
4/bt248DKedQRDz+bhQumTFt2q233NKlSxfaKfyDMwKXbv7tb82VZRFWRl1eJ7naoXA9CICO
Pv9w880BqHR58lsyqhzPeDVr1qRu2QhZv4MONnTokJHDh9uPzZsblapE0JDQ9WrXpmpGK3GL
FlMnTwKVUBQOzYnKCeQO0QurlS9/vmLFiou7EdngQBktQBNUy6VrpiLGq1AhqJq+gkrnzZMX
TkW19IIFCgBM5H7oIVqQJRk+m/pkli3DDz34IIe4S4gaVIWRoF4QKPBkYm/k66cyhSUgiCxA
DRU2HSQxaQplUi89jnEK/rXkI7hAo6HzZXE5eB+AG9hIkPxAf0ailDRmo2F6EIoiafn4o4/x
Pnv8m37xC0IvuvXxEyJqBw8aDORx/3331YCfbtvWQz2cOzcfOgBa8WLFAn4a4yUSz1chObly
5YJxIzltPufMmQPdakkqWqQIHGmIh8J4ue6/H07aMfgIaCUtkWlEYGGIRQwf8U1hJxkdT5qM
Dx2wCVFeQGHtUe0dDI+4BoUNwDfAIC1FMFN26tdvkDfPE8xI4cEv50/OZjwY6UBePiB5ETWw
uAwcOGrkCLssaAdfMQ8oE5Cetw5WInATjIvwQRDEEUNZWOnhLQirunXrQUELlmFJGzNmTFQV
uUGDu+++O6hA9CUlvyPTYhy1ybo4bNhwberUqY2qFi9eMnDAwN59ehcrVgzFJOEFkPIQzy5n
PEiWc2AL28UQFuRDAQY7jqg/7KxOnoRTiwo4xyFnoQ2lC/W3Ugx5bCQbx40dg3UTksXqNjm+
Ghi8OAlJ4kER6M0eD60LHfAroCblmTRjtCDxdFi0cJFhQ6OtVwhTMkVMGsWLl6BtstzQZgd4
qN69WTUee/QxS4aW1i97vNB5vB7tJ6ysbqVKlbIAqWXta+/evXLnzq2ZWdKG/blkyZK0DA9I
/qsNGEYOj0JHTZ5C1I99e/hqd0fERQcvvqASPXEdxjl92nT6vP02DdPX2lHQUwb0lApqHtwr
dcN8ebJfzma8Xj17jB0zOrwnaK9Qu9yajbZodHQzWigwJ+t8zWrVAb5QFZ3Ei8EDUIt4EjmG
lxQ6oaAmqmY4s3XrKxbXcEwpgg+0ZcowK2T60yiNtosJ9YDVU958Dd2CUJIVjRo2omjZaFnR
O3ToWKhQIbApVGi9V9O4VKmS6DW6JCreesomqljRIqxEemCTJFHhpMlnazwiwyp0SyBJ+z2B
diSAzuG5Q4qHLHu8iPH2G3aFsMezKgm9o28XyC+uZy5IKv4sVbIUiZF6LVmHSZInip9iUbfO
0f7NBzbVGpekWkiaUfYE4yRfgSotYck8AH2VK1OO7AJ8hSZjLnYX4ExbNc8IrWpmPKOY+qAw
W3GaNW4irI51F9SOUs1oqWB14UKFCepXX32VZdhCCZ7qwWkxwLelS5acMSPCml6ezJY6qhzM
eKj21ddeQ0+BYmDWoxQpJ07s2LH9jTeiRADIl34Cx4iWvTZaH20zorC4CPjkKVMIIpEjYTqC
LXPH9h0Qj8G6Gc6Tb9Sz8NUL1qe/Wd6rbqNbZ35sooiUMKqQQGn16jWsKThWz4gG2jNE6MQS
ZpWvhpdCLicobzwHBuVyEQDMKoLiUGSgaY3Jeaq1Y3XJp02bTrsL9snsBBebUt8Kj+9XEl4k
m8gJC5PIJmZAV3GgGXMiJTws76idYWJn9ZMbKc4e1gVTDU1JPmahJLalCP4afzSz3oVY2PAh
vYULG6ox0DPtt6M68ps3G4ApJV1BQ4NETXowBpZbQXfhwe0bx0+YCIubOQ+bpk6dRp671/r1
68yJZchPOcF/npONKymJseL3Gn+SXVMqeDL8mqwxWX5KKCMxsaTSUyoqJfSTnbhDgo/TFBZG
kvIJYwsnU4+zf40vyoBrZHo6znVJ0ttZB5Y6pAyBlg3BmsxYlgFn0daS6T091TGiIPtjvtM8
pK7xqccZbJn5JKlskzxdWALOMXWnW0bzl0auZCfS9Jn0DKRnIEe7E876+s4qtc4io86mkATn
+RkyJEYYhjOpP1EUQuN3IqHkkosZZJo+P8QzkIP3eGd9K1QSWxf/zmHXOvrWW7bmGcn54n18
0FEDa7HCrX3+ed5bEKegv9m6MKPbAs6YPoPrwh4yoBbfifF0yJDDCmLbmJofNhmwQdrC2WVd
/sa3DzHpf7CPlrMZL2Xbdhqn//TTTwe7c8xOpzcGSWOmF5462MuQC1Azlr3Qnj2aoa9xo4YM
bsAuTI6YBO6EV4oFnJlUtGW3rl1eBLOMWSqDac/cQ+pHFgYG1WRfl+w6kjFI4yPj0OkGHywV
pO/+vs9ADma8iGdi0xk8brAQbHt1Gx/xsCFDnh78tLBxDm7cAZEo5Jm5TBuNiTt2wt17MN1e
TgXJMzmvubm279jBssdCPf+ZeTiNKRwaA8SRI5v7wWfylKmSJsGOuTDOWxzJPKZCljfH7nLo
8GEeYSbQ3Xt261b2LrbNKINDDBzzZsNcGwOMr6RMI4YNjwXv0Q8+19z7TnbpG+ZgxkOv0FLl
ypWHHfEiBw4YwIErzaOTeZ/IU7VqFeikyBfUrBlJVbx4cRlQgI/gvzZu2sixK5vlX2+9Fe+1
bNni9zf/XoIGPi7/eCCkypk4YeL9997L7ydjUpfOnSQO4Em//fbbpUtp2iTKJxkJq1P/ASuT
GdYRcJkERDxyNWrWBONgKBejoPOKFStyeERcFzOexpzCXTp37t2zl5Qt0Plc2AaZ1jk/aqyY
UxnPuNHrUwUKBlAIoAmpFXLxQ7s3b9rMDqxSpUpbt2yRlgfWkRe7dKmSXNIA7zKIyP8FMMX3
ChIpb7E2OpHoVnJleaxs88TCgXqSk9WqVMVpoDAEY+sYnl+2dGnJ0oOWSAWV/8cBNNOi2Fk8
Y9p0OZdopFHeruPHuKrlUwqN9QBXEVUFOHUK0AMUAwBaqiwyMGwm05+PzgzkVMYLMoQjWDiJ
FNHgVLBUgb4BxKLceBE8ql4E4GzcGD6LqQOhO1mhbNk5c2djHjpnzHivUB2rx4xH3EmJi9Pk
gcM2sqqCwsAHSwoowSOAYuu4BwBrGXXCvcSqdI0DYVq3ar1s6VLgKeBdQa7u2L5dlBxaQthp
U6P86j4ghe3btAnHVocA/JXzC8Y6zXgfHZYLT5qDGS+ghwkxsEOSqnSJkiG3PugwQL0DYGWM
B7m7dPESMqpl8xYeWA5Glkk4SRfWrVP3tde22+5RQbUXgikAh2pKTI0fO44SmPeJJwCa2rRt
K/BHviqRYJrhyZUrngvTh/F0G/FzhQoyTwtKCGhMEq91XIRAHjuBambZjhRqXjhpcN9rKSWZ
A7E/bLBpxkszHvDTtddee8Wtt96KQMPyHD6X1T7EYEDpJaWVLBkKmdTq2LEjbbN71279+/WX
MNOAYflBpaLkykuXCleV6hz1V6lUUeQBqcX0Iic09K3AH8hJqGKX4C6cIMEjeKRiA5C44FGY
Z+zo0WvWrpXpmX1EgmqAr9mz59jgMZPA4LvR3XfdBbIklTpjZteu3aZOnRKCaOSulKFdRoOn
nx7CCkqiijETmtCrZ69JEybojVjmV0gzXprxcgbjeU+AjIIjxYABXkbrwslTjPhEDd8A6HME
vNyxg1gTSCLOUkESRkvbQtZOqHzmRJdjV1vEkLpD5E6IA1Aoz0n7QDGjYbkRJKql9ObYLAKI
viqkJToOFWrs0BYtWoh7FZojHl24YOFCv8aZRU6wrEBy+mzdGoEYiTtgaE5C5wUZgTtu377D
lvKjRnbp583BqqaXl0jj+PgMGGL4NXm8VIdbuCq5PGkTqCGLkE8AK2d12WVpn3ptfIvTSbJS
73jmsC8vVSLNEu/PDORsxnt/5ih9l/QMXPIZyMGMd56wzOxTFm9YMyK7L4eNaxCA7wRAy/KY
voZ3ltRDPjtNnAk6Df0HFeCsKNN33WSee5CXnC4/9B3mYMbzbpYtWy6vUcI8iQUoOcj+/jQW
GGoPFkfuvR6Fk3+gL9l4hNvZN77TKGBKhYTbpkaPGYO2wWVgYqK0lpkg7ezP66HUalQ55OWX
N6uywJcYb1Zfj/JhZkOZAuLYKvOvvNMy5LxtsL1uFi39A525nH3zHMx4iKBZ0yZRfoTMj/JU
IcW/g7h2+elPwJSFp4XknD51GmMMt4GkfdH5zEC7ZDoyY/ZOB3R7zxmiJlPmRMaSk6nZrDM2
mUnLhEwDh5y5zTu9I+W3UEU5yOHTci8TZcrkw7UYJeTL3JfCo6m5lfp0MppED5gZER9+4tnv
3r0HV6dEZkp/GKp8M+r1hV8Dj4Vj7scK5cpivDNHmHoHNdNHuC87kDXLD2pNhoLVOZv8P7jR
52zGU3VNcishycePvQ2DIv+U5Hxy4xQvXkzCPLZEpsXVa9ZESTgkxoyqdUcVt9XiYsEXcCAB
GQKKQJfHjqmJB4epJDrz4yG5igUl7NoVYTJPnFAfWGQ6OSFHy062yrhouISqfnIlAlabJi5D
o0TOZoPRj58UFla7izMd54SMmu7omKFVOjC5H6XE4pZg3pT1QGIyFxJlADeJjUeGwlWrVovp
VoKPTz+OSY9YRfrAkOCAT9+v7iKdCd8GDKrjUAuJKVU6CZnzpE6RlcSA9+7Z7Xk5UdTc4TUJ
1SfNlXEaAyeK3oTnO3mQBfiNndJym65169dp76TBw52q1KM3hm+w1aefHhzVOr8Myhp/cOxz
4XfO2YwHrSIBifLWXTt3ARC55Za/cLUpaHjLLbeEBGFAm9Wj/MT1uRMgUVCpnLZ8dzhBklaV
2WSMlRcE/cFh+lUmr/vuuUeZO7Qr8xxwCWkg52yUDnDrVkWbpd9CjqNHjxoSZ/gy8T169ChX
tpwkKMDZfHTWAv4JiLCyZctyl1euVNG9otSA+/Yjbn6IRQsXkFdr1z7fpGkT2VflIDEGGACZ
nsmoqHH8oXzCl0n1JSFn+bJlIcsgUSdMGO8nydQsHIBplStXIb2hdv7yl7/ECQ5fhBZQh10e
Md6RO+64Q+Yy2ZnuvfdeTPXs0iUywEoPY7TyC4HLSFgGOOrCjRvWgwpUr1ZdAb1Vq1YpQKmu
rdybUVKTOnXAXC09JnbihPGm4p577sH55kHVctrs5bBJvnDy/+CufEfGy58/P8JN1TYutyk2
NimGZJImpmhTXG1y/vB3m0y5vgkjnAZvqZmVfuHCRSFXCroPBcf9BNglozMyIhlyP/jgnNmz
nh48qG3r1nLOyeEhPzSwGFHTplWrXj16Eq0YMs9jjxFTZGZAqBBxvPa41LF0Q/37RlXCBeMp
m4r96GalS5biMDR1SjHjH7FIdlM6DBMLU0ogG4l8hFguPEX4SUag4XFwEymsN6kyn3/hBWxg
n+avx1RqPGR0pWRKOEsiEbkyqamjkC9PHntXEDlZUlaufE6dR8147WU3mjZlqjLikXq5b7+R
h6TLBw7sl2aTDJ8xY6YM0PJhmgQ7OreQH0ViMnVhZROcOWM6AFDPnlFv1jWLVFrVvGDOzc54
NKCbbrrpiqpVqwL+XuaMR7ysWPEcCIsCvDRJ9U0RLoUQWIwWJKnrvLlzPYJ4BVlxwrMIsSPi
qIING9SXT5LWhIvgXYQSYUiJruCtmzRuBEs5eOBAVYXJrihT6vLl7dq0AcvEWoIhZJgO2fIk
DnJ56Pm1ba/Cdnbu2Im0UcnZmTgZbv0AZONFV80U89t0yfnpDFEmJ6SD9u3bcf1TFKFqMG3o
DbmHxKwYT0QFvVcaNfEWBq9SsfNMMmQUw4m9Wf26Uf4yCq+MmrVq1yarqakGuWH9Biq3NOna
k2x8/ThfAV05wmTgVrs43ItOThrj/HnPPEMaW18sBDLf1qsjT/spD+i83mbNmCFTU7euUW8k
/JLFZ2S/vmAS/GhemJ3xFLumpFwhg2/RokUvc8aT2hUpSAlesVx52zDYMcv2kbeOUNuwnxgc
ATgegUBApgwDTtLTGFRgo6mp2M+mS+o7mqS48pLFi8u3aeNmyS+YL7/U1IhVSnBKJjYr/ORT
UgOKbn/iscfJKM1syeS9kkIzlCUI9nr64fBhQ/2VcJrEK1tabfG3jTBUAnCJVJz6sUwApilR
4BKiiXFFmrAKRNCu3YapK3FG3bp09atr6caGR+IRxX169ZZkNrw2m668efJs2fKyXK6ygHk0
WDn1ekg8GjV0uASb4pjIbUH0+EfPAZ0zsP8AS0OZ0qVkE/NVOQcrl9mZPWumNcjKMmTQYJEZ
AjU8ZqMG9a1fJJ7UzoI8BF65pEXLlhL+Ofhoss3FP3V2xgscd0VAjl3mjCcv+nPLlrEcEHFY
TpSd1OLibiz79jlq7lj7baLwGIrv1bM3/VBouaXdvmh4DKSOFu+2bUNx+qqVq7ZqFSGbyTGp
pnUrSK9gwYKRyDp1Cn+iYDOO1iWTtSHs3iNKV96vbx85p7Foz+7dataoKREtD4fErOqJlyhW
nJa4bes2iE28JOxdks98efJaDkaNGvXE4483btzIMCSEJPEwHouFyKahQ4fRgXfu3GV7ZgXB
xpLwYlTWlyaNGotdAlUjOYkgkRlgop6XJJRJmtosV6xtWMECBUl+T6rAyNKlz9oysP2SY0aL
c+gyZUqXkb1X2maZKsUZCi+kJ9u7UoNpBzQFYVDuiJNZj9q0aknM6g3oVLSUxzd7xi+TvI3i
5bYBuXiWeH96yM54xB2hd4WXdPPNN1svE9673KYYKdOR6E5WcTF1NnUkwPoNG3x1nkyzq0G1
dkchpSSDJFMe6cQJwOgXWeTi2CI2TFXv4t4OImL9RKa/3XvYF0kbPUdugxMnXCjVioOouDYi
PfLWGzsjNKb5YZthtECpLIohyTnepvup0SF1vN5wkZa4RVJkmzSWHssERlq1ehWZaTCYnPSL
IKbHjslFaYemE4MJedfd2rVUSrfWf1zL6Di9kYWGePdePDg902aS0SXq8ODBuKzfgWich9/y
q0+cJ+aE/wkLJMPDa2Ud4WkwFXL1unVczTxqSWzqwSDdSD+GZ0rDjLH6CunwK65Oavq9P8T6
YbpLFsbzpq666ip/I8aTzJxp7rJlvGBbT/xRiVcqOWC0nD49Y2uXnAzaUXioxHCf5WSYlHM3
S9pkX7pwvs1bq1atK1aoGDaZqb2lKhFZ5jal2RkJocP55Eapw07tOXUkyeSkOvdSM9CkdpLl
eVMHnDEJmR7CZE6yDObDxBLvz7NkIZuE1yLGw3+0TRj/8CYuN4l37gkK/rdIvr2/nyj38/Hj
FHVxQ2SCeSNC3wXe9f6OMH23y2EGUhkvldEixvMRrHnfffflUMYLw34nDOR/a/ZjKGQiyoKa
+n6P4b/1bOl+L9kMpDJeqmqZwXgIiKWFvSXHSbxLNkPpjtIz8F+YgYTxmFEEnYeqmj6nGc8p
9pYs0ehn3aikT6ZnID0D72kGbEmYMJPd3BmM5wvrlp8lin1PnaYbp2cgPQPnmAGyDlvhvdQ2
pyVeOEvuPfLII1xAmDA9m+kZSM/AxcwAbrKvo2GmyrqsqmbqDYDI2Dldk2a/i5n39LUf5RmA
Z7jxxhs56pJ93bkkXvIblnMNZx9rJ6OLvR8P7Ed5HtPPnp6Bc89A7FuabadGZ7zyyiuFH2RR
L8+L8ZJGPA0MnsQl9lXqPv1Jz0B6Bs46A5REbILr8N5ZpVwq4/1/9BckHFTJneYAAAAASUVO
RK5CYII=
--------------040403090101020709030709--

--------------020507020703030701080103--


From nobody Mon Jul  7 03:25:43 2014
Return-Path: <gerdes@tzi.de>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 3D8E21B2811 for <ace@ietfa.amsl.com>; Mon,  7 Jul 2014 03:25:41 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.551
X-Spam-Level: 
X-Spam-Status: No, score=-1.551 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HELO_EQ_DE=0.35, SPF_HELO_PASS=-0.001] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id oCLegSEz7Gxe for <ace@ietfa.amsl.com>; Mon,  7 Jul 2014 03:25:40 -0700 (PDT)
Received: from informatik.uni-bremen.de (mailhost.informatik.uni-bremen.de [IPv6:2001:638:708:30c9::12]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 972FB1B280B for <ace@ietf.org>; Mon,  7 Jul 2014 03:25:39 -0700 (PDT)
X-Virus-Scanned: amavisd-new at informatik.uni-bremen.de
Received: from smtp-fb3.informatik.uni-bremen.de (smtp-fb3.informatik.uni-bremen.de [134.102.224.120]) by informatik.uni-bremen.de (8.14.5/8.14.5) with ESMTP id s67APVSf012364 for <ace@ietf.org>; Mon, 7 Jul 2014 12:25:31 +0200 (CEST)
Received: from [134.102.218.214] (dynamic-218-o.informatik.uni-bremen.de [134.102.218.214]) (using TLSv1 with cipher DHE-RSA-CAMELLIA256-SHA (256/256 bits)) (No client certificate requested) by smtp-fb3.informatik.uni-bremen.de (Postfix) with ESMTPSA id 8893EE70 for <ace@ietf.org>; Mon,  7 Jul 2014 12:25:31 +0200 (CEST)
Message-ID: <53BA759B.1060306@tzi.de>
Date: Mon, 07 Jul 2014 12:25:31 +0200
From: Stefanie Gerdes <gerdes@tzi.de>
User-Agent: Mozilla/5.0 (X11; Linux i686 on x86_64; rv:24.0) Gecko/20100101 Thunderbird/24.2.0
MIME-Version: 1.0
To: "ace@ietf.org" <ace@ietf.org>
References: <20140704210341.2079.69668.idtracker@ietfa.amsl.com>
In-Reply-To: <20140704210341.2079.69668.idtracker@ietfa.amsl.com>
X-Enigmail-Version: 1.6
X-Forwarded-Message-Id: <20140704210341.2079.69668.idtracker@ietfa.amsl.com>
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 7bit
Archived-At: http://mailarchive.ietf.org/arch/msg/ace/sK0VXM9axPHnQzKnoJecaoC5EmA
Subject: [Ace] Fwd: New Version Notification for draft-gerdes-ace-actors-01.txt
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 07 Jul 2014 10:25:41 -0000

Hi all,

I have updated the Actors Draft. I added a list of tasks that are
required to meet the security requirements in constrained environments.

I hope this will help in the discussion about requirements for the
authentication and authorization solution.

I'm looking forward to your comments.

Thanks,
Steffi


-------- Original Message --------
Subject: New Version Notification for draft-gerdes-ace-actors-01.txt
Date: Fri, 04 Jul 2014 14:03:41 -0700
From: internet-drafts@ietf.org
To: Stefanie Gerdes <gerdes@tzi.org>, Stefanie Gerdes <gerdes@tzi.org>


A new version of I-D, draft-gerdes-ace-actors-01.txt
has been successfully submitted by Stefanie Gerdes and posted to the
IETF repository.

Name:		draft-gerdes-ace-actors
Revision:	01
Title:		Actors in the ACE Architecture
Document date:	2014-07-04
Group:		Individual Submission
Pages:		23
URL:
http://www.ietf.org/internet-drafts/draft-gerdes-ace-actors-01.txt
Status:         https://datatracker.ietf.org/doc/draft-gerdes-ace-actors/
Htmlized:       http://tools.ietf.org/html/draft-gerdes-ace-actors-01
Diff:           http://www.ietf.org/rfcdiff?url2=draft-gerdes-ace-actors-01

Abstract:
   Constrained nodes are small devices which are limited in terms of
   processing power, memory, non-volatile storage and transmission
   capacity.  Due to these constraints, commonly used security protocols
   are not easily applicable.  Nevertheless, an authentication and
   authorization solution is needed to ensure the security of these
   devices.

   Due to the limitations of the constrained nodes it is especially
   important to develop a light-weight security solution which is
   adjusted to the relevant security objectives of each participating
   party in this environment.  Necessary security measures must be
   identified and applied where needed.

   In this document, the required security related tasks are identified
   as guidance for the development of authentication and authorization
   solutions for constrained environments.  Based on the tasks, an
   architecture is developed to represent the relationships between the
   logical functional entities involved.





Please note that it may take a couple of minutes from the time of submission
until the htmlized version and diff are available at tools.ietf.org.

The IETF Secretariat





From nobody Mon Jul  7 03:36:18 2014
Return-Path: <gerdes@tzi.de>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 0F7361B280C for <ace@ietfa.amsl.com>; Mon,  7 Jul 2014 03:36:17 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.551
X-Spam-Level: 
X-Spam-Status: No, score=-1.551 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HELO_EQ_DE=0.35, SPF_HELO_PASS=-0.001] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id GcQcTTGO_uWP for <ace@ietfa.amsl.com>; Mon,  7 Jul 2014 03:36:16 -0700 (PDT)
Received: from informatik.uni-bremen.de (mailhost.informatik.uni-bremen.de [IPv6:2001:638:708:30c9::12]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id A223D1B280B for <ace@ietf.org>; Mon,  7 Jul 2014 03:36:15 -0700 (PDT)
X-Virus-Scanned: amavisd-new at informatik.uni-bremen.de
Received: from smtp-fb3.informatik.uni-bremen.de (smtp-fb3.informatik.uni-bremen.de [134.102.224.120]) by informatik.uni-bremen.de (8.14.5/8.14.5) with ESMTP id s67AaCBr003407 for <ace@ietf.org>; Mon, 7 Jul 2014 12:36:12 +0200 (CEST)
Received: from [134.102.218.214] (dynamic-218-o.informatik.uni-bremen.de [134.102.218.214]) (using TLSv1 with cipher DHE-RSA-CAMELLIA256-SHA (256/256 bits)) (No client certificate requested) by smtp-fb3.informatik.uni-bremen.de (Postfix) with ESMTPSA id F03DEE95 for <ace@ietf.org>; Mon,  7 Jul 2014 12:36:11 +0200 (CEST)
Message-ID: <53BA781B.50806@tzi.de>
Date: Mon, 07 Jul 2014 12:36:11 +0200
From: Stefanie Gerdes <gerdes@tzi.de>
User-Agent: Mozilla/5.0 (X11; Linux i686 on x86_64; rv:24.0) Gecko/20100101 Thunderbird/24.2.0
MIME-Version: 1.0
To: "ace@ietf.org" <ace@ietf.org>
References: <20140704212346.13984.6241.idtracker@ietfa.amsl.com>
In-Reply-To: <20140704212346.13984.6241.idtracker@ietfa.amsl.com>
X-Enigmail-Version: 1.6
X-Forwarded-Message-Id: <20140704212346.13984.6241.idtracker@ietfa.amsl.com>
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 7bit
Archived-At: http://mailarchive.ietf.org/arch/msg/ace/STBv6AYY9bNsYVQ41qwC3WFO-UQ
Subject: [Ace] Fwd: New Version Notification for draft-gerdes-ace-dcaf-authorize-00.txt
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 07 Jul 2014 10:36:17 -0000

Hi all,

We have updated the Delegated CoAP Authentication and Authorization
Framework (DCAF). The main changes are:
* more compact CBOR representations
* added a description of DCAF communication with multiple actors
combined in a single component.

We are looking forward to your comments.

Thanks,
Steffi


-------- Original Message --------
Subject: New Version Notification for draft-gerdes-ace-dcaf-authorize-00.txt
Date: Fri, 04 Jul 2014 14:23:46 -0700
From: internet-drafts@ietf.org
To: Dr. Carsten Bormann <cabo@tzi.org>, Stefanie Gerdes
<gerdes@tzi.org>,        Olaf Bergmann <bergmann@tzi.org>, Stefanie
Gerdes <gerdes@tzi.org>,        Olaf Bergmann <bergmann@tzi.org>,
Carsten Bormann <cabo@tzi.org>


A new version of I-D, draft-gerdes-ace-dcaf-authorize-00.txt
has been successfully submitted by Stefanie Gerdes and posted to the
IETF repository.

Name:		draft-gerdes-ace-dcaf-authorize
Revision:	00
Title:		Delegated CoAP Authentication and Authorization Framework (DCAF)
Document date:	2014-07-04
Group:		Individual Submission
Pages:		37
URL:
http://www.ietf.org/internet-drafts/draft-gerdes-ace-dcaf-authorize-00.txt
Status:
https://datatracker.ietf.org/doc/draft-gerdes-ace-dcaf-authorize/
Htmlized:
http://tools.ietf.org/html/draft-gerdes-ace-dcaf-authorize-00


Abstract:
   This specification defines a protocol for delegating client
   authentication and authorization in a constrained environment for
   establishing a Datagram Transport Layer Security (DTLS) channel
   between resource-constrained nodes.  The protocol relies on DTLS to
   transfer authorization information and shared secrets for symmetric
   cryptography between entities in a constrained network.  A resource-
   constrained node can use this protocol to delegate authentication of
   communication peers and management of authorization information to a
   trusted host with less severe limitations regarding processing power
   and memory.





Please note that it may take a couple of minutes from the time of submission
until the htmlized version and diff are available at tools.ietf.org.

The IETF Secretariat





From nobody Mon Jul  7 08:45:58 2014
Return-Path: <hannes.tschofenig@gmx.net>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 735081A0303 for <ace@ietfa.amsl.com>; Mon,  7 Jul 2014 08:45:55 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.551
X-Spam-Level: 
X-Spam-Status: No, score=-2.551 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, FREEMAIL_FROM=0.001, RCVD_IN_DNSWL_NONE=-0.0001, RP_MATCHES_RCVD=-0.651, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 1HdtJb2P_RL9 for <ace@ietfa.amsl.com>; Mon,  7 Jul 2014 08:45:53 -0700 (PDT)
Received: from mout.gmx.net (mout.gmx.net [212.227.17.22]) (using TLSv1.2 with cipher DHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id C9B7A1A0296 for <ace@ietf.org>; Mon,  7 Jul 2014 08:45:52 -0700 (PDT)
Received: from [192.168.131.128] ([80.92.115.50]) by mail.gmx.com (mrgmx101) with ESMTPSA (Nemesis) id 0LfXmv-1WFmOV2rCD-00p4aY for <ace@ietf.org>; Mon, 07 Jul 2014 17:45:50 +0200
Message-ID: <53BAC0AA.3090706@gmx.net>
Date: Mon, 07 Jul 2014 17:45:46 +0200
From: Hannes Tschofenig <hannes.tschofenig@gmx.net>
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:24.0) Gecko/20100101 Thunderbird/24.6.0
MIME-Version: 1.0
To: "ace@ietf.org" <ace@ietf.org>
X-Enigmail-Version: 1.5.2
OpenPGP: id=4D776BC9
Content-Type: multipart/signed; micalg=pgp-sha512; protocol="application/pgp-signature"; boundary="H23PhX2Ds6JvQpES0xcc8vCnG3FvqVK6o"
X-Provags-ID: V03:K0:qDSTdxhnBR1T35xeVjslRnqo10NYqdYD2bvAe6rd//bo3eRB8Rx fvsIcOe+djK4rtmgssfGrufYrpVRMHapTpF+pPrFzyKGZJnWDceqLdnBBC50aVOb7r965TG +fkaY5UEVkl9SgOZLsjnh8n+e7F41aILZhNPD2TomqnniqJbsKxQmprMw80PyU7DeJ8ZaIz QcQt4WI+NrVAWsGy+bAwg==
Archived-At: http://mailarchive.ietf.org/arch/msg/ace/IPSKn91fQbwZmsDII6J-jJMoiV8
Subject: [Ace] Agenda?
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 07 Jul 2014 15:45:55 -0000

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--H23PhX2Ds6JvQpES0xcc8vCnG3FvqVK6o
Content-Type: text/plain; charset=ISO-8859-1
Content-Transfer-Encoding: quoted-printable


Hi all,

Kepeng and I have a quite intense debate about the agenda for the
meeting and so we wanted to hear your input as well (since we have to
upload an initial version of the agenda today).

We both obviously want to make some progress on our chartered items but
this raises the question about what to put on the agenda for this meeting=
=2E

The first chartered item is the use case & requirements document.

Ludwig and Kepeng think that the use case & requirements document is in
a pretty good shape. I see the story a bit differently.

In preparation of the unofficial interim meeting in Stockholm I picked
one use case (and actually only a sub-set of it), namely the door lock
use case with letting the remote visitor in.

Based on what I understood from the draft I created different variants
of what the user experience would be. Here is the write-up I created:
http://www.tschofenig.priv.at/ace/interim2014/Door-Lock-UseCase.pdf

My conclusion from that exercise was that we should either delete the
remote delegation use case or postpone it for now. I would also focus on
an enterprise environment rather than an end user home use case.

I was hoping that we would discuss the different use cases from the use
case draft in more detail to better understand them rather than
immediately jumping to solutions.

I am curious what the others in the group want to use the available
face-to-face time for.

Ciao
Hannes

PS: Interestingly, Erik Wahlstroem from a physical access control
company was at the meeting and shared his requirements with us. For him
the real-time communication from the resource server (door lock) to the
backend infrastructure was not a no-go. He was actually planning around
RADIUS since he also wants to monitor in real-time who is where in the
building since he needs to create a value-add with an new, IP-based
solution rather than just re-creating what they already have using
different protocols. I thought that this was interesting insight from
someone who works in a company selling these products.

Here are his slides:
http://www.tschofenig.priv.at/ace/interim2014/ErikWahlstroem_PhysicalObje=
ctIdM.pdf


--H23PhX2Ds6JvQpES0xcc8vCnG3FvqVK6o
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
Content-Disposition: attachment; filename="signature.asc"

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1
Comment: GPGTools - http://gpgtools.org
Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/

iQEcBAEBCgAGBQJTusCqAAoJEGhJURNOOiAtfXQH/1ruefXy2oT5qLG6vao7oxru
6HC0W/92v9D3tK7oJhiCEnVPXF29FY25nY6turjdiJj3S+3BOH0xEtIcZUf9opGJ
4VTaBulhJ7Fq6dVbdHSwX+JNYqEvEOiTCtrnRLIoo2OJq8YMXdEp5xitMBDP4tvT
bX1VLvgCdwdx7Vj1UkrOCcVwd+9wTL76JG3rbGPVoX1uc1Pdy2w1u83lNJzICqfc
2pa1V+VLn/S2QhKGxODHvDBJ81mjORwt0z6WrA3tstuCfsgn9q6XE6B7OUMgLEIW
sXVWC0svhBYdHAGuWNHPLmZd2GfR2GMx1zgvB5bjahKscA0/4FRibSgffnmCfcQ=
=WHFe
-----END PGP SIGNATURE-----

--H23PhX2Ds6JvQpES0xcc8vCnG3FvqVK6o--


From nobody Mon Jul  7 11:00:48 2014
Return-Path: <Josh.Howlett@ja.net>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id EDE9E1A0545 for <ace@ietfa.amsl.com>; Mon,  7 Jul 2014 11:00:46 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -0.001
X-Spam-Level: 
X-Spam-Status: No, score=-0.001 tagged_above=-999 required=5 tests=[BAYES_40=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id wtITbvDgwqFR for <ace@ietfa.amsl.com>; Mon,  7 Jul 2014 11:00:45 -0700 (PDT)
Received: from egw002.ukerna.ac.uk (egw002.ukerna.ac.uk [194.81.3.65]) (using TLSv1 with cipher DHE-RSA-CAMELLIA256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 451171A0564 for <ace@ietf.org>; Mon,  7 Jul 2014 11:00:44 -0700 (PDT)
Received: from egw002.ukerna.ac.uk (localhost.localdomain [127.0.0.1]) by localhost (Email Security Appliance) with SMTP id EEDA820C73D8_3BAE049B; Mon,  7 Jul 2014 18:00:41 +0000 (GMT)
Received: from EXC001.atlas.ukerna.ac.uk (exc001.atlas.ukerna.ac.uk [193.62.83.37]) (using TLSv1 with cipher AES128-SHA (128/128 bits)) (Client CN "staffmail.ja.net", Issuer "TERENA SSL CA" (verified OK)) by egw002.ukerna.ac.uk (Sophos Email Appliance) with ESMTPS id A6C1D20C70F2_3BAE048F; Mon,  7 Jul 2014 18:00:40 +0000 (GMT)
Received: from EXC001.atlas.ukerna.ac.uk ([193.62.83.37]) by EXC001 ([193.62.83.37]) with mapi id 14.03.0123.003; Mon, 7 Jul 2014 19:00:39 +0100
From: Josh Howlett <Josh.Howlett@ja.net>
To: Hannes Tschofenig <hannes.tschofenig@gmx.net>, "ace@ietf.org" <ace@ietf.org>
Thread-Topic: [Ace] Agenda?
Thread-Index: AQHPmfqaLU7myO1mPkqFmn9GNHcnKZuU5YSQ
Date: Mon, 7 Jul 2014 18:00:39 +0000
Message-ID: <55DC663C2F4F9F439F23543E0078E8B3A6773DAA@EXC001>
References: <53BAC0AA.3090706@gmx.net>
In-Reply-To: <53BAC0AA.3090706@gmx.net>
Accept-Language: en-GB, en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
x-originating-ip: [194.82.140.76]
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
Archived-At: http://mailarchive.ietf.org/arch/msg/ace/57Fio4FM6nGvpM16C-CfcIwSgPg
Subject: Re: [Ace] Agenda?
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 07 Jul 2014 18:00:47 -0000

> PS: Interestingly, Erik Wahlstroem from a physical access control company
> was at the meeting and shared his requirements with us. For him the real-
> time communication from the resource server (door lock) to the backend
> infrastructure was not a no-go. He was actually planning around RADIUS
> since he also wants to monitor in real-time who is where in the building =
since
> he needs to create a value-add with an new, IP-based solution rather than
> just re-creating what they already have using different protocols. I thou=
ght
> that this was interesting insight from someone who works in a company
> selling these products.

FWIW at the Paris IETF meeting there was a guy from a French company in the=
 business of hotel door locks. Their products used EAP/RADIUS.

Josh.


Janet(UK) is a trading name of Jisc Collections and Janet Limited, a=20
not-for-profit company which is registered in England under No. 2881024=20
and whose Registered Office is at Lumen House, Library Avenue,
Harwell Oxford, Didcot, Oxfordshire. OX11 0SG. VAT No. 614944238


From nobody Mon Jul  7 11:40:16 2014
Return-Path: <gerdes@tzi.de>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id B481E1A024E for <ace@ietfa.amsl.com>; Mon,  7 Jul 2014 11:40:15 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.551
X-Spam-Level: 
X-Spam-Status: No, score=-1.551 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HELO_EQ_DE=0.35, SPF_HELO_PASS=-0.001] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id ynr-eXNVAsRx for <ace@ietfa.amsl.com>; Mon,  7 Jul 2014 11:40:14 -0700 (PDT)
Received: from informatik.uni-bremen.de (mailhost.informatik.uni-bremen.de [IPv6:2001:638:708:30c9::12]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 0C1F01A02D7 for <ace@ietf.org>; Mon,  7 Jul 2014 11:40:13 -0700 (PDT)
X-Virus-Scanned: amavisd-new at informatik.uni-bremen.de
Received: from smtp-fb3.informatik.uni-bremen.de (smtp-fb3.informatik.uni-bremen.de [134.102.224.120]) by informatik.uni-bremen.de (8.14.5/8.14.5) with ESMTP id s67IeAxb028625; Mon, 7 Jul 2014 20:40:10 +0200 (CEST)
Received: from [192.168.1.146] (p50834BD4.dip0.t-ipconnect.de [80.131.75.212]) (using TLSv1 with cipher DHE-RSA-CAMELLIA256-SHA (256/256 bits)) (No client certificate requested) by smtp-fb3.informatik.uni-bremen.de (Postfix) with ESMTPSA id 5FCF61EF; Mon,  7 Jul 2014 20:40:10 +0200 (CEST)
Message-ID: <53BAE98A.5030403@tzi.de>
Date: Mon, 07 Jul 2014 20:40:10 +0200
From: Stefanie Gerdes <gerdes@tzi.de>
User-Agent: Mozilla/5.0 (X11; Linux i686 on x86_64; rv:24.0) Gecko/20100101 Thunderbird/24.2.0
MIME-Version: 1.0
To: Hannes Tschofenig <hannes.tschofenig@gmx.net>, "ace@ietf.org" <ace@ietf.org>
References: <53BAC0AA.3090706@gmx.net>
In-Reply-To: <53BAC0AA.3090706@gmx.net>
X-Enigmail-Version: 1.6
Content-Type: text/plain; charset=ISO-8859-1
Content-Transfer-Encoding: 7bit
Archived-At: http://mailarchive.ietf.org/arch/msg/ace/jX4c0AsFE62mzGA6dIXxzVavOFk
Subject: Re: [Ace] Agenda?
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 07 Jul 2014 18:40:15 -0000

Hi all,

I would like to discuss the following things (not necessarily during
the face-to-face meeting but also on here on the list):

1) Do the use cases in the document represent what you are interested in.

2) Does each of the use cases include all aspects relevant for the given
scenario and did we manage to include all relevant requirements.

3) Does the use case document provide the required amount of detail to
be a useful guidance for the development of a solution?

Thanks,
Steffi



On 07/07/2014 05:45 PM, Hannes Tschofenig wrote:
> 
> Hi all,
> 
> Kepeng and I have a quite intense debate about the agenda for the 
> meeting and so we wanted to hear your input as well (since we have
> to upload an initial version of the agenda today).
> 
> We both obviously want to make some progress on our chartered items
> but this raises the question about what to put on the agenda for
> this meeting.
> 
> The first chartered item is the use case & requirements document.
> 
> Ludwig and Kepeng think that the use case & requirements document
> is in a pretty good shape. I see the story a bit differently.
> 
> In preparation of the unofficial interim meeting in Stockholm I
> picked one use case (and actually only a sub-set of it), namely the
> door lock use case with letting the remote visitor in.
> 
> Based on what I understood from the draft I created different
> variants of what the user experience would be. Here is the write-up
> I created: 
> http://www.tschofenig.priv.at/ace/interim2014/Door-Lock-UseCase.pdf
>
>  My conclusion from that exercise was that we should either delete
> the remote delegation use case or postpone it for now. I would also
> focus on an enterprise environment rather than an end user home use
> case.
> 
> I was hoping that we would discuss the different use cases from the
> use case draft in more detail to better understand them rather
> than immediately jumping to solutions.
> 
> I am curious what the others in the group want to use the
> available face-to-face time for.
> 
> Ciao Hannes
> 
> PS: Interestingly, Erik Wahlstroem from a physical access control 
> company was at the meeting and shared his requirements with us. For
> him the real-time communication from the resource server (door
> lock) to the backend infrastructure was not a no-go. He was
> actually planning around RADIUS since he also wants to monitor in
> real-time who is where in the building since he needs to create a
> value-add with an new, IP-based solution rather than just
> re-creating what they already have using different protocols. I
> thought that this was interesting insight from someone who works in
> a company selling these products.
> 
> Here are his slides: 
> http://www.tschofenig.priv.at/ace/interim2014/ErikWahlstroem_PhysicalObjectIdM.pdf
>
> 
> 
> 
> _______________________________________________ Ace mailing list 
> Ace@ietf.org https://www.ietf.org/mailman/listinfo/ace
> 



From nobody Tue Jul  8 00:31:39 2014
Return-Path: <hannes.tschofenig@gmx.net>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 5FA231B2A88 for <ace@ietfa.amsl.com>; Tue,  8 Jul 2014 00:31:38 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.551
X-Spam-Level: 
X-Spam-Status: No, score=-2.551 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, FREEMAIL_FROM=0.001, RCVD_IN_DNSWL_NONE=-0.0001, RP_MATCHES_RCVD=-0.651, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id nq9_M1hO4fKT for <ace@ietfa.amsl.com>; Tue,  8 Jul 2014 00:31:36 -0700 (PDT)
Received: from mout.gmx.net (mout.gmx.net [212.227.15.19]) (using TLSv1.2 with cipher DHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id EE4A41B2A89 for <ace@ietf.org>; Tue,  8 Jul 2014 00:31:35 -0700 (PDT)
Received: from [192.168.131.128] ([80.92.115.50]) by mail.gmx.com (mrgmx003) with ESMTPSA (Nemesis) id 0MFuC6-1WrmIF0ucY-00Exxh for <ace@ietf.org>; Tue, 08 Jul 2014 09:31:33 +0200
Message-ID: <53BB9E52.3070905@gmx.net>
Date: Tue, 08 Jul 2014 09:31:30 +0200
From: Hannes Tschofenig <hannes.tschofenig@gmx.net>
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:24.0) Gecko/20100101 Thunderbird/24.6.0
MIME-Version: 1.0
To: "ace@ietf.org" <ace@ietf.org>
X-Enigmail-Version: 1.5.2
OpenPGP: id=4D776BC9
Content-Type: multipart/signed; micalg=pgp-sha512; protocol="application/pgp-signature"; boundary="0OigPNaVPGshRQ0tKGMDxMo1vkqgEQ4th"
X-Provags-ID: V03:K0:FZINwaQzeJIng7Q2AEt4y/UEvpROB8SrcjU8GOPDyoAdeCgd1o/ 9r7B3V5wW4MgvXpHSHtwEz1ajhYAKpaIZ2ejjmM+WcFTs9PzmRhjgNR2ow7r2djhW0j/85z Anr4e+8hr4DHINuLMe0dcpRNCH/KsvCaVRYmob9rdLYhnzknr1XzAMnuDYznNvzEhriKOl4 ZFJ+eCOtppj4npQPL9GCA==
Archived-At: http://mailarchive.ietf.org/arch/msg/ace/S6fhngZT49PcF4sGYEub28ie7Ps
Subject: [Ace] The ACE documents
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 08 Jul 2014 07:31:38 -0000

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--0OigPNaVPGshRQ0tKGMDxMo1vkqgEQ4th
Content-Type: text/plain; charset=ISO-8859-1
Content-Transfer-Encoding: quoted-printable

I took a look at the document in the working group. Here is a my short
summary.

- Use Cases
https://datatracker.ietf.org/doc/draft-seitz-ace-usecases/

This document describes the use cases and requirements already presented
during the BOF.

- Problem Description
http://tools.ietf.org/html/draft-seitz-ace-problem-description-01

This document provides a good summary of the conversation at the meeting
in Stockholm. It captures the essential design decisions.

- Design Considerations
http://tools.ietf.org/html/draft-seitz-ace-design-considerations-00

This document was written in preparation of the BOF to highlight some of
the challenges with constraint devices. None of the discussed issues are
surprising.

- Overview of Existing Security Protocols
https://datatracker.ietf.org/doc/draft-tschofenig-ace-overview/

I wrote this document in preparation for the BOF to explain the pros and
cons of available protocol solutions.

- Solution Documents

There are two types of solutions currently submitted to the group, namely=


a) OAuth-based Designs

draft-gerdes-ace-dcaf-authorize-00 is a re-write of the OAuth protocol
to make the encoding more efficient and introduces new terminology per
draft-gerdes-ace-actors-01 (which stresses the cross-domain use).
draft-tschofenig-ace-oauth-bt-00 and draft-tschofenig-ace-oauth-iot-00
re-uses OAuth as much as possible.
draft-schmitt-ace-twowayauth-for-iot-00 follows an OAuth-based design as
well
(even though many relevant message exchange parts are left out of the
description) but the description puts a strong emphasis on the use of DTL=
S.

The three solution show differences in what credentials they use.

There are two types of credentials, namely long-term credentials shared
between the client and the authorization server and short-term
credentials established for use between the client and the resource serve=
r.

* draft-gerdes-ace-dcaf-authorize-00 focuses on the establishment of a
symmetric session key to be used between the client and the resource
server, which is then used within DTLS. IMHO what credentials are used
between the client and the AS are not further discussed but DTLS is used
as well.

* draft-tschofenig-ace-oauth-bt-00 and draft-tschofenig-ace-oauth-iot-00
inherits the functionality from OAuth and uses DTLS between the client
the AS and may use CoAP/DTLS between the client and the RS. The
established session key for use between the client and the RS is also
flexible, as in OAuth, can can either be a symmetric or an asymmetric
key (so-called proof-of-possession key). Also the use of a bearer token
is possible.

* draft-schmitt-ace-twowayauth-for-iot-00 focuses on the use of
asymmetric credentials between the client and the AS as well as on the
communication between the client and the RS. The use of a ticket is only
hinted in Figure 4.

b) EAP-based Design

draft-marin-ace-wg-coap-eap-00 describes how to map EAP to the
CoAP-based environment. If the requirements in
draft-seitz-ace-usecases-01	are strictly interpreted then this proposal
fails since it does not support offline operation of the resource server.=


- Out-of-Scope documents

There are a few documents that are not within the scope of the group,
namely
https://datatracker.ietf.org/doc/draft-zhu-ace-groupauth/
https://datatracker.ietf.org/doc/draft-sarikaya-ace-cga-nd/



--0OigPNaVPGshRQ0tKGMDxMo1vkqgEQ4th
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
Content-Disposition: attachment; filename="signature.asc"

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1
Comment: GPGTools - http://gpgtools.org
Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/

iQEcBAEBCgAGBQJTu55TAAoJEGhJURNOOiAt03gIAKK8+Lx7xVAuVw1s7O9+24u6
1BRAcpmr/L0gPxzn2Uwheq54oJjmMX1j2OUOK3nXbYyiztvj88mT0pIsJ4Y4K8Pd
Pg3CNqnFnBYA36K8eAaumQmHIUS1qznjy7zTBAZDBlArcHJUVbGfBqR5FNwbRFhT
aXy32KZqVzD1y5xMDCyWGsd3Sr5OGNhxdV1qWAXn1vopsyPH9cNL4d5B8IefZbYN
MrHvbBcwAnvsrso1OSgxuaQf5OjjF8w7fdvWDZppRRDpMRiw9J2kgBIB2F1NyDK3
tC430FsivkddZutdQm9d2QOW/V/3wYhMvabsHsG8+fdm+GbjyAg7YJzqsJDY4oA=
=/b71
-----END PGP SIGNATURE-----

--0OigPNaVPGshRQ0tKGMDxMo1vkqgEQ4th--


From nobody Wed Jul  9 00:58:08 2014
Return-Path: <hannes.tschofenig@gmx.net>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 57F2B1A038A for <ace@ietfa.amsl.com>; Wed,  9 Jul 2014 00:58:06 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.551
X-Spam-Level: 
X-Spam-Status: No, score=-2.551 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, FREEMAIL_FROM=0.001, RCVD_IN_DNSWL_NONE=-0.0001, RP_MATCHES_RCVD=-0.651, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id j4Da3L_XrBSO for <ace@ietfa.amsl.com>; Wed,  9 Jul 2014 00:58:04 -0700 (PDT)
Received: from mout.gmx.net (mout.gmx.net [212.227.15.18]) (using TLSv1.2 with cipher DHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 86A9C1A0339 for <ace@ietf.org>; Wed,  9 Jul 2014 00:58:04 -0700 (PDT)
Received: from [192.168.131.128] ([80.92.116.212]) by mail.gmx.com (mrgmx002) with ESMTPSA (Nemesis) id 0Lh7sF-1WHv6D2XY7-00oVd1 for <ace@ietf.org>; Wed, 09 Jul 2014 09:58:02 +0200
Message-ID: <53BCF608.5010606@gmx.net>
Date: Wed, 09 Jul 2014 09:58:00 +0200
From: Hannes Tschofenig <hannes.tschofenig@gmx.net>
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:24.0) Gecko/20100101 Thunderbird/24.6.0
MIME-Version: 1.0
To: "ace@ietf.org" <ace@ietf.org>
X-Enigmail-Version: 1.5.2
OpenPGP: id=4D776BC9
Content-Type: multipart/signed; micalg=pgp-sha512; protocol="application/pgp-signature"; boundary="v3o0Cl21sk07MmivDLvv2jIGDGT6DfL00"
X-Provags-ID: V03:K0:DLvo/OIL03ybuOmP7OC/Son+ioPcGSbZp9hlw/5UClsWZqxLQZn iKvu6F+bRwbmkc6itEhf1HDjFw+39SDv1rhm9LVbMA7bNvBBkbt1K4bL8SDHxB14x5jaEHr +HdKLAPYr3WqybkzuXge8ER7JoAMFrXt8gXs7P7nymodBUoQ2hXQ/j9hekuGnJc/hWmZNAc 4c+nJqyNJayjtuu8hNzvw==
Archived-At: http://mailarchive.ietf.org/arch/msg/ace/biWY1uNrWCR_0DdAYYy77AqgID0
Subject: [Ace] Questions for the IETF#90 Meeting
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 09 Jul 2014 07:58:06 -0000

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--v3o0Cl21sk07MmivDLvv2jIGDGT6DfL00
Content-Type: text/plain; charset=ISO-8859-1
Content-Transfer-Encoding: quoted-printable

To me there appear to be four questions for the group:

1) Are there requirements/use cases that allow anything other than the
OAuth/Kerberos design pattern?

Partially the answer should come from the use case document.

2) Should the design re-use existing work or should the design start
from scratch?

This is more a question of taste / preference but will obviously have a
huge impact on the subsequent work in the group.

3) Should the design be based on symmetric or asymmetric crypto?
  (or both?)

We have various documents that talk about this issue, for example
draft-seitz-ace-design-considerations-00 and
draft-seitz-ace-problem-description-01

4) How to address cross-domain support in the initial protocol design?
Is it a feature that can be added later easily?

draft-gerdes-ace-actors-01 talks about this aspect.

If we could get an answer to these questions during the meeting that
would be good step forward.

Ciao
Hannes

PS: One question that has been answered by all document in the same way
at the moment is about the use of DTLS. Currently, everyone seems to be
focused on using DTLS everywhere. There would be alternative approaches
as well.


--v3o0Cl21sk07MmivDLvv2jIGDGT6DfL00
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
Content-Disposition: attachment; filename="signature.asc"

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1
Comment: GPGTools - http://gpgtools.org
Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/

iQEcBAEBCgAGBQJTvPYIAAoJEGhJURNOOiAtBLIH/1XuGq8WcvW770InsqMWG0vF
1d7F1eGmupUWoYNzQN0kfisIXhVb7cKNrFTToeK2b/QQDYMA6j6BBMz36EtK9V3/
e3cgSm2LTQIQ0JKa8BPdko3ZIwyEhFgtpektJsAom82jynwZOjknoADUFPpDSChS
Ms6g6iVkGRwZi2I3ujAPcmGKKSSqZ2ipAq23nW519XBvb8WgTQT+n9TnlJnA9cni
/AGkC6Vgh6GvOUOH90td/P7C/M3bisw9I/xJfKvHP9iMoWPBrE4Jr9aejqxtNTvA
8mHkpY0i0HHw6x2ZzruLj/KrqhYdJBdu0Wf22Z75E4FTkQmwKFHyL7wGsEnMlVQ=
=23bG
-----END PGP SIGNATURE-----

--v3o0Cl21sk07MmivDLvv2jIGDGT6DfL00--


From nobody Wed Jul  9 01:29:15 2014
Return-Path: <paul@nymbus.net>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id BEF951A0398 for <ace@ietfa.amsl.com>; Wed,  9 Jul 2014 01:29:13 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.9
X-Spam-Level: 
X-Spam-Status: No, score=-1.9 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_NONE=-0.0001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 9JvQc7JsQJHb for <ace@ietfa.amsl.com>; Wed,  9 Jul 2014 01:29:12 -0700 (PDT)
Received: from mail-pd0-f175.google.com (mail-pd0-f175.google.com [209.85.192.175]) (using TLSv1 with cipher ECDHE-RSA-RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 3A6AC1A039B for <ace@ietf.org>; Wed,  9 Jul 2014 01:29:12 -0700 (PDT)
Received: by mail-pd0-f175.google.com with SMTP id v10so8528712pde.6 for <ace@ietf.org>; Wed, 09 Jul 2014 01:29:11 -0700 (PDT)
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20130820; h=x-gm-message-state:content-type:mime-version:subject:from :in-reply-to:date:cc:content-transfer-encoding:message-id:references :to; bh=kbC0qY+Pdq74KOfr0Gu0DizdkQgVISlXE6ablXcvBnA=; b=eP1gvFLjTbYR6+KmjouqCzr9S4W0CI0p7ylR2Vl8q1J/LUjnm7wXtBsQcSuh9adqzW a+abUl8pCW+llGpMPPsiIbE6uISLph7dkfHWtMMYf0NdY5aNHfBkVDXTBgai14c4vgJm +XIazUo3JBKmvDqbbO5lSqjVOWmeUNe+k+2/oJbtu5YVoLyFRRHGLw6IVNatY3o59aBc nIlojroyQxgqQZiZnksKerxBkhlJEiGFpN80oGNNdrkCP7+bsSLhUZtnpdZ1LVtXE+4Z 3BU4SOXSUQ1wDv7h4kMAJ1u602wWILLvDsrTl8Q3J9WtAraEU6yhNK+bHgUe28MiaXSV cXdQ==
X-Gm-Message-State: ALoCoQmaBZM7+RhQLMeycxGy8Ix63PvVxW3or43X/kX32Ch71neAS08CQRoTUawMZdFz8MYPPHpk
X-Received: by 10.67.4.163 with SMTP id cf3mr39527935pad.92.1404894551865; Wed, 09 Jul 2014 01:29:11 -0700 (PDT)
Received: from [192.168.1.70] (75-37-193-167.lightspeed.lsatca.sbcglobal.net. [75.37.193.167]) by mx.google.com with ESMTPSA id b4sm20688718pdk.10.2014.07.09.01.29.10 for <multiple recipients> (version=TLSv1 cipher=ECDHE-RSA-RC4-SHA bits=128/128); Wed, 09 Jul 2014 01:29:10 -0700 (PDT)
Content-Type: text/plain; charset=windows-1252
Mime-Version: 1.0 (Mac OS X Mail 7.3 \(1878.6\))
From: Paul Lambert <paul@nymbus.net>
In-Reply-To: <53BCF608.5010606@gmx.net>
Date: Wed, 9 Jul 2014 01:29:09 -0700
Content-Transfer-Encoding: quoted-printable
Message-Id: <D7E5703D-792F-447E-9B23-0F676861902F@nymbus.net>
References: <53BCF608.5010606@gmx.net>
To: Hannes Tschofenig <hannes.tschofenig@gmx.net>
X-Mailer: Apple Mail (2.1878.6)
Archived-At: http://mailarchive.ietf.org/arch/msg/ace/alkjIMmujt0ijPqGmR5EyxeONjo
Cc: "ace@ietf.org" <ace@ietf.org>
Subject: Re: [Ace] Questions for the IETF#90 Meeting
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 09 Jul 2014 08:29:13 -0000

On Jul 9, 2014, at 12:58 AM, Hannes Tschofenig =
<hannes.tschofenig@gmx.net> wrote:

> To me there appear to be four questions for the group:
>=20
> 1) Are there requirements/use cases that allow anything other than the
> OAuth/Kerberos design pattern?
Allow?  Any square peg (Kerberos) could be allowed to fill a round hole
with a large enough hammer.

I have requirements for P2P consumer connections that will not
initially have any Internet connectivity.  Direct enrollment and
management of headless consumer devices is important
and especially during bootstrapping from out-of-box does not
fit well into OAuth/Kerberos

>=20
> Partially the answer should come from the use case document.
>=20
> 2) Should the design re-use existing work or should the design start
> from scratch?
Scratch.

>=20
> This is more a question of taste / preference but will obviously have =
a
> huge impact on the subsequent work in the group.
>=20
> 3) Should the design be based on symmetric or asymmetric crypto?
>  (or both?)
Both of course, and hash algorithms. =20
Asymmetric crypto should be used for key establishment and identity.
Algorithms should be lumped together as a Cipher Suite that defines
a set of algorithms for key established/authentication, encryption, =
hashing, etc.


>=20
> We have various documents that talk about this issue, for example
> draft-seitz-ace-design-considerations-00 and
> draft-seitz-ace-problem-description-01
>=20
> 4) How to address cross-domain support in the initial protocol design?
> Is it a feature that can be added later easily?
>=20
> draft-gerdes-ace-actors-01 talks about this aspect.
from this ...
"   According to the Internet Security Glossary [RFC4949], =
authentication
   is "the process of verifying a claim that a system entity or system
   resource has a certain attribute value."  Examples for attribute
   values are the ID of a device, the type of the device or the name of
   its owner.  Authentication attributes might be (but not necessarily
   are) suitable to uniquely identify an individual entity.=94

The hash of the public key is a attribute that can be directly
authenticated by the key holder and is unique. The hash
process should include the encoding of the Cipher Suite
values to bind the algorithms to the instance of a key.
Other attribute bindings can be built on these unique =91ids'

Paul

>=20
> If we could get an answer to these questions during the meeting that
> would be good step forward.
>=20
> Ciao
> Hannes
>=20
> PS: One question that has been answered by all document in the same =
way
> at the moment is about the use of DTLS. Currently, everyone seems to =
be
> focused on using DTLS everywhere. There would be alternative =
approaches
> as well.
>=20
> _______________________________________________
> Ace mailing list
> Ace@ietf.org
> https://www.ietf.org/mailman/listinfo/ace


From nobody Wed Jul  9 02:02:26 2014
Return-Path: <hannes.tschofenig@gmx.net>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 1E95A1A03B6 for <ace@ietfa.amsl.com>; Wed,  9 Jul 2014 02:02:25 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.551
X-Spam-Level: 
X-Spam-Status: No, score=-2.551 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, FREEMAIL_FROM=0.001, RCVD_IN_DNSWL_NONE=-0.0001, RP_MATCHES_RCVD=-0.651, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 1RPZ2ldFs6pS for <ace@ietfa.amsl.com>; Wed,  9 Jul 2014 02:02:23 -0700 (PDT)
Received: from mout.gmx.net (mout.gmx.net [212.227.15.19]) (using TLSv1.2 with cipher DHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 6FC391A0337 for <ace@ietf.org>; Wed,  9 Jul 2014 02:02:23 -0700 (PDT)
Received: from [192.168.131.128] ([80.92.116.212]) by mail.gmx.com (mrgmx001) with ESMTPSA (Nemesis) id 0LqhmM-1WRuZi1UwM-00eJt3; Wed, 09 Jul 2014 11:02:20 +0200
Message-ID: <53BD0518.8060609@gmx.net>
Date: Wed, 09 Jul 2014 11:02:16 +0200
From: Hannes Tschofenig <hannes.tschofenig@gmx.net>
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:24.0) Gecko/20100101 Thunderbird/24.6.0
MIME-Version: 1.0
To: Paul Lambert <paul@nymbus.net>
References: <53BCF608.5010606@gmx.net> <D7E5703D-792F-447E-9B23-0F676861902F@nymbus.net>
In-Reply-To: <D7E5703D-792F-447E-9B23-0F676861902F@nymbus.net>
X-Enigmail-Version: 1.5.2
OpenPGP: id=4D776BC9
Content-Type: multipart/signed; micalg=pgp-sha512; protocol="application/pgp-signature"; boundary="WQDvGJHTeL9MJo8qA873t5HV6BuCCNMWB"
X-Provags-ID: V03:K0:zE7If1bbqqzuryiTeSsy6nuSLKQPz6LNkhkvoacQioNw4TsFm4j 23HPqPpBKr/u2quSJojkW6dgT+Y8l645c+M8j1ETxG1VVWkOMoE8CMnY23OtjRsplryD1Bq MXiVbkrIuKDiwGzkKK+p/4XhsihpOpAnhPdm2EYF+JLj+8+0vqMRFNo6lUId1hYcIVgxeZQ tC7I7c/1xW6Rz61c+yFcg==
Archived-At: http://mailarchive.ietf.org/arch/msg/ace/c4hSkxdiMnxOTQgdV36qo-_5jHw
Cc: "ace@ietf.org" <ace@ietf.org>
Subject: Re: [Ace] Questions for the IETF#90 Meeting
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 09 Jul 2014 09:02:25 -0000

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--WQDvGJHTeL9MJo8qA873t5HV6BuCCNMWB
Content-Type: text/plain; charset=windows-1252
Content-Transfer-Encoding: quoted-printable

Hi Paul,

thanks for responding to so quickly.

One remark regarding the first question:

On 07/09/2014 10:29 AM, Paul Lambert wrote:
>> 1) Are there requirements/use cases that allow anything other than the=

>> > OAuth/Kerberos design pattern?
> Allow?  Any square peg (Kerberos) could be allowed to fill a round hole=

> with a large enough hammer.
>=20
> I have requirements for P2P consumer connections that will not
> initially have any Internet connectivity.  Direct enrollment and
> management of headless consumer devices is important
> and especially during bootstrapping from out-of-box does not
> fit well into OAuth/Kerberos

The reason why I have listed the question here is because the
requirements document currently rules out a certain class of solutions
that require communication between the resource server and the
authorization server in real-time.

Regarding the terminology (resource server, client, authorization
server) please take a look at Section 2 of
http://tools.ietf.org/html/draft-seitz-ace-problem-description-01


Regarding your use case: Could you say a few words about what the
participating entities are and how the interact with each other?

I am not sure what you mean by "P2P consumer connections".

Ciao
Hannes




--WQDvGJHTeL9MJo8qA873t5HV6BuCCNMWB
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
Content-Disposition: attachment; filename="signature.asc"

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1
Comment: GPGTools - http://gpgtools.org
Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/

iQEcBAEBCgAGBQJTvQUZAAoJEGhJURNOOiAtJhIH/jzS0yrpApl/cbAdctF+fD+G
y7bh8JtYg3gc2ZLHX/PBi6pKrjxcSzhZNtuTmKwZFAPi5yxigVOKzf67ug2YZu9I
hj/asGQKA55epB0yR4JyA/4+M2psQkmYgRhMwGbMI8brD9WocJQMZeufHlO/5yqr
RGX9JX0RxUxLjGvnzrsZnGeP25wzp+UVZCzy/wKEgpwCVg9tlliEfXcg/n12xVq9
3fYQLkL68PvYHHuP/66IRgTgbxgrngNErbYhstQT+Kcp+NjnZOVngG1LJf/xjAx5
7923UgcVAZRLmQZwgfQ3i3/CEutqORDVBiua+JwcReALNGFOYfZ9tUqEucLSJbk=
=ieqZ
-----END PGP SIGNATURE-----

--WQDvGJHTeL9MJo8qA873t5HV6BuCCNMWB--


From nobody Wed Jul  9 04:22:28 2014
Return-Path: <rdroms.ietf@gmail.com>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id DE9231A03F7 for <ace@ietfa.amsl.com>; Wed,  9 Jul 2014 04:22:26 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2
X-Spam-Level: 
X-Spam-Status: No, score=-2 tagged_above=-999 required=5 tests=[BAYES_00=-1.9,  DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id DsySCFuHF_pH for <ace@ietfa.amsl.com>; Wed,  9 Jul 2014 04:22:25 -0700 (PDT)
Received: from mail-qc0-x22f.google.com (mail-qc0-x22f.google.com [IPv6:2607:f8b0:400d:c01::22f]) (using TLSv1 with cipher ECDHE-RSA-RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 4ED821A03F5 for <ace@ietf.org>; Wed,  9 Jul 2014 04:22:25 -0700 (PDT)
Received: by mail-qc0-f175.google.com with SMTP id i8so6508968qcq.6 for <ace@ietf.org>; Wed, 09 Jul 2014 04:22:24 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113;  h=content-type:mime-version:subject:from:in-reply-to:date:cc :content-transfer-encoding:message-id:references:to; bh=QEuZ0pnD60A4g4iDjhzl4g3DcLBA517WOP57U8Vy5wA=; b=gPR2UkGRVI0DxOk+dYA8N4OXiOaDd0L5nv/xaZALa/HX0obb4e3Llbf7KzpwO2yFjI SliYuzd739O/TBHjH3YSZWFkFI+qr0W3xgW0Ixd1uNtaATMf/q3aMm4aSrIiaPRF6upM 7vvpCNqA8urEf4TYne45hYb/4Ukaz4LKg4y+imWN7ANhPJQVyR9BCEO6B3zpxyn0+QUb Lz+JHqDZFtQg3YXC4sE59EjJMb5Rwuf4z8se7hxlb3EKW5IwG2FciLXW+7mpnxB4u2uf vChTCeksS03VCyM3gP/eaw0NKak6/FGuWSRny53ujtGvPSbWwli3Ph0DCqSjo68DS5Q2 I5JA==
X-Received: by 10.224.137.9 with SMTP id u9mr71161002qat.24.1404904944397; Wed, 09 Jul 2014 04:22:24 -0700 (PDT)
Received: from ?IPv6:2601:6:6780:19e:f053:14bb:710c:20fe? ([2601:6:6780:19e:f053:14bb:710c:20fe]) by mx.google.com with ESMTPSA id y79sm31863243qgy.18.2014.07.09.04.22.22 for <multiple recipients> (version=TLSv1 cipher=ECDHE-RSA-RC4-SHA bits=128/128); Wed, 09 Jul 2014 04:22:23 -0700 (PDT)
Content-Type: text/plain; charset=utf-8
Mime-Version: 1.0 (1.0)
From: Ralph Droms <rdroms.ietf@gmail.com>
X-Mailer: iPad Mail (11D201)
In-Reply-To: <D7E5703D-792F-447E-9B23-0F676861902F@nymbus.net>
Date: Wed, 9 Jul 2014 07:22:22 -0400
Content-Transfer-Encoding: quoted-printable
Message-Id: <C7A72F49-192D-4476-95A4-D4870F2D84B9@gmail.com>
References: <53BCF608.5010606@gmx.net> <D7E5703D-792F-447E-9B23-0F676861902F@nymbus.net>
To: Paul Lambert <paul@nymbus.net>
Archived-At: http://mailarchive.ietf.org/arch/msg/ace/G8As_8RrI8hcyeyJaVrk4eTQjZU
Cc: Hannes Tschofenig <hannes.tschofenig@gmx.net>, "ace@ietf.org" <ace@ietf.org>
Subject: Re: [Ace] Questions for the IETF#90 Meeting
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 09 Jul 2014 11:22:27 -0000

> On Jul 9, 2014, at 4:29 AM, Paul Lambert <paul@nymbus.net> wrote:
>=20
>=20
>> On Jul 9, 2014, at 12:58 AM, Hannes Tschofenig <hannes.tschofenig@gmx.net=
> wrote:
>>=20
>> To me there appear to be four questions for the group:
>>=20
>> 1) Are there requirements/use cases that allow anything other than the
>> OAuth/Kerberos design pattern?
> Allow?  Any square peg (Kerberos) could be allowed to fill a round hole
> with a large enough hammer.
>=20
> I have requirements for P2P consumer connections that will not
> initially have any Internet connectivity.  Direct enrollment and
> management of headless consumer devices is important
> and especially during bootstrapping from out-of-box does not
> fit well into OAuth/Kerberos
>=20
>>=20
>> Partially the answer should come from the use case document.
>>=20
>> 2) Should the design re-use existing work or should the design start
>> from scratch?
> Scratch.
>=20
>>=20
>> This is more a question of taste / preference but will obviously have a
>> huge impact on the subsequent work in the group.

I disagree with the characterization as "taste/preference".  In my opinion, t=
here needs to be strong evidence for the need for a design from scratch and a=
n implicit bias toward reusing existing technologies.

Use cases like the one outlined above should be reviewed to see if they cons=
titute evidence in support of a design from scratch.

- Ralph


>>=20
>> 3) Should the design be based on symmetric or asymmetric crypto?
>> (or both?)
> Both of course, and hash algorithms. =20
> Asymmetric crypto should be used for key establishment and identity.
> Algorithms should be lumped together as a Cipher Suite that defines
> a set of algorithms for key established/authentication, encryption, hashin=
g, etc.
>=20
>=20
>>=20
>> We have various documents that talk about this issue, for example
>> draft-seitz-ace-design-considerations-00 and
>> draft-seitz-ace-problem-description-01
>>=20
>> 4) How to address cross-domain support in the initial protocol design?
>> Is it a feature that can be added later easily?
>>=20
>> draft-gerdes-ace-actors-01 talks about this aspect.
> from this ...
> "   According to the Internet Security Glossary [RFC4949], authentication
>   is "the process of verifying a claim that a system entity or system
>   resource has a certain attribute value."  Examples for attribute
>   values are the ID of a device, the type of the device or the name of
>   its owner.  Authentication attributes might be (but not necessarily
>   are) suitable to uniquely identify an individual entity.=E2=80=9D
>=20
> The hash of the public key is a attribute that can be directly
> authenticated by the key holder and is unique. The hash
> process should include the encoding of the Cipher Suite
> values to bind the algorithms to the instance of a key.
> Other attribute bindings can be built on these unique =E2=80=98ids'
>=20
> Paul
>=20
>>=20
>> If we could get an answer to these questions during the meeting that
>> would be good step forward.
>>=20
>> Ciao
>> Hannes
>>=20
>> PS: One question that has been answered by all document in the same way
>> at the moment is about the use of DTLS. Currently, everyone seems to be
>> focused on using DTLS everywhere. There would be alternative approaches
>> as well.
>>=20
>> _______________________________________________
>> Ace mailing list
>> Ace@ietf.org
>> https://www.ietf.org/mailman/listinfo/ace
>=20
> _______________________________________________
> Ace mailing list
> Ace@ietf.org
> https://www.ietf.org/mailman/listinfo/ace


From nobody Wed Jul  9 07:09:21 2014
Return-Path: <mcr@sandelman.ca>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 36A371A0A9F for <ace@ietfa.amsl.com>; Wed,  9 Jul 2014 07:09:18 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.552
X-Spam-Level: 
X-Spam-Status: No, score=-2.552 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RP_MATCHES_RCVD=-0.651, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id ZdXaimFGphq4 for <ace@ietfa.amsl.com>; Wed,  9 Jul 2014 07:09:15 -0700 (PDT)
Received: from tuna.sandelman.ca (tuna.sandelman.ca [IPv6:2607:f0b0:f:3:216:3eff:fe7c:d1f3]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 47A561A03CE for <ace@ietf.org>; Wed,  9 Jul 2014 07:09:15 -0700 (PDT)
Received: from sandelman.ca (obiwan.sandelman.ca [IPv6:2607:f0b0:f:2::247]) by tuna.sandelman.ca (Postfix) with ESMTP id 419B52002D; Wed,  9 Jul 2014 10:10:07 -0400 (EDT)
Received: by sandelman.ca (Postfix, from userid 179) id 7ED2763B0E; Wed,  9 Jul 2014 10:09:13 -0400 (EDT)
Received: from sandelman.ca (localhost [127.0.0.1]) by sandelman.ca (Postfix) with ESMTP id 6903863B09; Wed,  9 Jul 2014 10:09:13 -0400 (EDT)
From: Michael Richardson <mcr+ietf@sandelman.ca>
To: Hannes Tschofenig <hannes.tschofenig@gmx.net>
In-Reply-To: <53BCF608.5010606@gmx.net>
References: <53BCF608.5010606@gmx.net>
X-Mailer: MH-E 8.2; nmh 1.3-dev; GNU Emacs 23.4.1
X-Face: $\n1pF)h^`}$H>Hk{L"x@)JS7<%Az}5RyS@k9X%29-lHB$Ti.V>2bi.~ehC0; <'$9xN5Ub# z!G,p`nR&p7Fz@^UXIn156S8.~^@MJ*mMsD7=QFeq%AL4m<nPbLgmtKK-5dC@#:k
MIME-Version: 1.0
Content-Type: multipart/signed; boundary="=-=-="; micalg=pgp-sha1; protocol="application/pgp-signature"
Date: Wed, 09 Jul 2014 10:09:13 -0400
Message-ID: <27297.1404914953@sandelman.ca>
Sender: mcr@sandelman.ca
Archived-At: http://mailarchive.ietf.org/arch/msg/ace/-5ZkCXEEG4QE_LMnLJdnDtVyFNc
Cc: "ace@ietf.org" <ace@ietf.org>
Subject: Re: [Ace] Questions for the IETF#90 Meeting
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 09 Jul 2014 14:09:18 -0000

--=-=-=
Content-Transfer-Encoding: quoted-printable


Hannes Tschofenig <hannes.tschofenig@gmx.net> wrote:
    > 1) Are there requirements/use cases that allow anything other than the
    > OAuth/Kerberos design pattern?

I think that there are two questions here:
  1) is the OAuth/Kerberos design pattern sufficient? (does it do everythin=
g)
  2) is the OAUTH/Kerberos design pattern necessary?  (can we throw somethi=
ng away?)

My instinct is that it handles all of the operational parts, but it does not
handle any of the enrollment parts, particularly for the case where the
parties are offline.   You will recall that you felt at the BOF that the
enrollment case was out of scope.

    > 2) Should the design re-use existing work or should the design start
    > from scratch?

    > This is more a question of taste / preference but will obviously have=
 a
    > huge impact on the subsequent work in the group.

I think that it worth spending some time to think about a CBOR encoding of
OAuth2, which I think makes use of JSON.  I don't think we have any mapping
of Kerberos into JSON, but I could be wrong.  The idea is to start with a
baseline situation and then decided if we should innovate.

    > 3) Should the design be based on symmetric or asymmetric crypto?
    > (or both?)

    > We have various documents that talk about this issue, for example
    > draft-seitz-ace-design-considerations-00 and
    > draft-seitz-ace-problem-description-01

After enrollment, symmetric crypto is sufficient.

    > 4) How to address cross-domain support in the initial protocol design?
    > Is it a feature that can be added later easily?

    > draft-gerdes-ace-actors-01 talks about this aspect.

It must be present from day one.  That is one thing which dis-recommends a
pure Kerberos pattern, or at least observes Kerberos to include all the pki=
nit and=20
cross-realm stuff from the beginning.  My limited experience with kerberos =
is
that there must be significant operational hurdles to doing cross-realm
things, or it would occur far more often.

    > PS: One question that has been answered by all document in the same w=
ay
    > at the moment is about the use of DTLS. Currently, everyone seems to =
be
    > focused on using DTLS everywhere. There would be alternative approach=
es
    > as well.

I don't prefer to have any alternative approaches be considered.=20

=2D-=20
]               Never tell me the odds!                 | ipv6 mesh network=
s [=20
]   Michael Richardson, Sandelman Software Works        | network architect=
  [=20
]     mcr@sandelman.ca  http://www.sandelman.ca/        |   ruby on rails  =
  [=20
=09



--=-=-=
Content-Type: application/pgp-signature

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iQEVAwUBU71NB4CLcPvd0N1lAQJOuwf/ZO4sQvYJUvGjkdudyZ1xYtMZdan3efMT
oWz40fOrcS8hy2CODiImnwcV8jpZKFzhGMhK7x7RuOVfFjX+FOoY44AP3taVf1a7
SXsXBaaZEi/d6Q580nU23zivhv4m0hFndqCvIz9JmCzQqMnI8mJdilgtmQMBW4tE
Le2FFjLdRemcSURgVkKM1Vk0fg9tGRN7PERNKclOUGBGni7cpNic0qc7hCZrOYcy
BHY50P+8X7vtK5UU+WeIRRSZIRLhPNRTlr/1RV1Znrb3Kj8Xptt5voyKgDf2sUBi
jM+ErLv57mmXYdJZZODrWgRCHKl3QPHb7CqXzQjtZDmgZrqN92hnXw==
=0wou
-----END PGP SIGNATURE-----
--=-=-=--


From nobody Wed Jul  9 14:52:10 2014
Return-Path: <paul@nymbus.net>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id B93BC1A0065 for <ace@ietfa.amsl.com>; Wed,  9 Jul 2014 14:52:07 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.6
X-Spam-Level: 
X-Spam-Status: No, score=-2.6 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_LOW=-0.7] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id d4ZxOGPp_bjS for <ace@ietfa.amsl.com>; Wed,  9 Jul 2014 14:52:06 -0700 (PDT)
Received: from mail-pa0-f51.google.com (mail-pa0-f51.google.com [209.85.220.51]) (using TLSv1 with cipher ECDHE-RSA-RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 0F3AF1A0064 for <ace@ietf.org>; Wed,  9 Jul 2014 14:52:06 -0700 (PDT)
Received: by mail-pa0-f51.google.com with SMTP id hz1so9911939pad.38 for <ace@ietf.org>; Wed, 09 Jul 2014 14:52:05 -0700 (PDT)
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20130820; h=x-gm-message-state:content-type:mime-version:subject:from :in-reply-to:date:cc:content-transfer-encoding:message-id:references :to; bh=hqhDezfsTsbFiOK37I3k9WwUD5zx8+MvQDyaxpQdkZU=; b=RcKrs/3+T/KF703ZRTxn+JfLRfce9xpvYyX4ClN3xj+4i3wlY+/f2V/vyk8oKC2s2w jcNhyuIDoPEI+vCygrfU8feolcvY9PP8gIUyrfpAqBvpTvuV8Zfa8wKOM3sUOV6RVB96 EhePLiCVBRShVq6Wx5V98C8cUt78KSDCJAjftsGh7epjTGgauAIW+mVJmSewFSxAMFL8 10qzQaQjYNMwSIcJmkGdq6qSWI0VEq/5RIwxXs0iTDPL4u9zE7u3Kv+yOFnpjdp1Ma4T 7oOAD3xFCKCx+FXoRm7VHXDTFLFXjyL5slAyo1pP1srvWTXX4QpKNsIIUeJi+BBpYU+O Y7ww==
X-Gm-Message-State: ALoCoQls3ExwbDec2JSJRvvCYysX+sieOm9UEAn0ZJsjw2B3aMS1fo8UaXF0i06+iu8fKdBh8l4w
X-Received: by 10.70.130.12 with SMTP id oa12mr13108803pdb.123.1404942725660;  Wed, 09 Jul 2014 14:52:05 -0700 (PDT)
Received: from [10.72.8.209] (proxy6-global253.qualcomm.com. [199.106.103.253]) by mx.google.com with ESMTPSA id gx10sm58033212pbd.81.2014.07.09.14.52.04 for <multiple recipients> (version=TLSv1 cipher=ECDHE-RSA-RC4-SHA bits=128/128); Wed, 09 Jul 2014 14:52:05 -0700 (PDT)
Content-Type: text/plain; charset=windows-1252
Mime-Version: 1.0 (Mac OS X Mail 7.3 \(1878.6\))
From: Paul Lambert <paul@nymbus.net>
In-Reply-To: <53BD0518.8060609@gmx.net>
Date: Wed, 9 Jul 2014 14:52:03 -0700
Content-Transfer-Encoding: quoted-printable
Message-Id: <1EFD8C56-BB56-4395-8DFB-B015606381F9@nymbus.net>
References: <53BCF608.5010606@gmx.net> <D7E5703D-792F-447E-9B23-0F676861902F@nymbus.net> <53BD0518.8060609@gmx.net>
To: Hannes Tschofenig <hannes.tschofenig@gmx.net>
X-Mailer: Apple Mail (2.1878.6)
Archived-At: http://mailarchive.ietf.org/arch/msg/ace/U87X6EBwg4QmQkh-WtBY6O4g-2E
Cc: "ace@ietf.org" <ace@ietf.org>
Subject: Re: [Ace] Questions for the IETF#90 Meeting
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 09 Jul 2014 21:52:07 -0000

On Jul 9, 2014, at 2:02 AM, Hannes Tschofenig =
<hannes.tschofenig@gmx.net> wrote:

> Hi Paul,
>=20
> thanks for responding to so quickly.
>=20
> One remark regarding the first question:
>=20
> On 07/09/2014 10:29 AM, Paul Lambert wrote:
>>> 1) Are there requirements/use cases that allow anything other than =
the
>>>> OAuth/Kerberos design pattern?
>> Allow?  Any square peg (Kerberos) could be allowed to fill a round =
hole
>> with a large enough hammer.
>>=20
>> I have requirements for P2P consumer connections that will not
>> initially have any Internet connectivity.  Direct enrollment and
>> management of headless consumer devices is important
>> and especially during bootstrapping from out-of-box does not
>> fit well into OAuth/Kerberos
>=20
> The reason why I have listed the question here is because the
> requirements document currently rules out a certain class of solutions
> that require communication between the resource server and the
> authorization server in real-time.
>=20
> Regarding the terminology (resource server, client, authorization
> server) please take a look at Section 2 of
> http://tools.ietf.org/html/draft-seitz-ace-problem-description-01

Ok, my mistake with understanding your question about =93allow=94.
I agree that C and RS should not be required to contact the AS
for a policy decision.

> Regarding your use case: Could you say a few words about what the
> participating entities are and how the interact with each other?
>=20
> I am not sure what you mean by "P2P consumer connections=94.


Wireless (e.g. Wi-Fi ) based direct connections from one device to =
another.
 - between two smart phones
 - smart phone to headless device (e.g. hot water heater)
Typically no Internet connection guaranteed to be available.

The interesting part is the =93enrollment=94 which appears to be
out-of-scope for this group.  The initial =91pairing=92 is effectively
the AS function being introduced to a C or RS and providing
initial configuration of policy (aka authorization information)

Paul



>=20
> Ciao
> Hannes
>=20
>=20
>=20


From nobody Wed Jul  9 14:59:12 2014
Return-Path: <paul@nymbus.net>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 13C421A0080 for <ace@ietfa.amsl.com>; Wed,  9 Jul 2014 14:59:10 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.6
X-Spam-Level: 
X-Spam-Status: No, score=-2.6 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_LOW=-0.7] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Hzp6KGbbL_Yr for <ace@ietfa.amsl.com>; Wed,  9 Jul 2014 14:59:07 -0700 (PDT)
Received: from mail-pa0-f41.google.com (mail-pa0-f41.google.com [209.85.220.41]) (using TLSv1 with cipher ECDHE-RSA-RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 95A631A007B for <ace@ietf.org>; Wed,  9 Jul 2014 14:59:07 -0700 (PDT)
Received: by mail-pa0-f41.google.com with SMTP id fb1so9971354pad.0 for <ace@ietf.org>; Wed, 09 Jul 2014 14:59:07 -0700 (PDT)
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20130820; h=x-gm-message-state:content-type:mime-version:subject:from :in-reply-to:date:cc:content-transfer-encoding:message-id:references :to; bh=Er8u192zLCNV9NzK6yidVwv8Iu9r22QR+cpOYW1vcA0=; b=DXV0gw9qQz89EzE+LqRhgFKXCQczU8vnr/n5yXR10fmwepAzS4sg3KKUF+nKH3+hor jidlXoFjK3yXn+6WV78q3PSdmSJ3CsEa3DVkd+nR4MJwcldEJNLVJ+gD2v3N6mmFarFT ZxS6wEl02L13sZ6jX/UqoYTu709DijOBHKmBiOFmrLZVk0tGy9lwbAnECSiYKMyY0htV H7u9U2Cd7wfeW5p2IKjSYopOQ4ak/8HptW3R9RTEhse8pZP+ELdq3E71lRoC/zZJMLIL ySHRafJO1hMWzrDWPP1Pojer9MfGvGWi2eRWBeZ+Mb2Yh+IQf9Mm9qNGb/NqoeWO8QfL m7Pg==
X-Gm-Message-State: ALoCoQmURqZeXJnG9DxGa3xF3SYnfWLjESAPIqLPAuo5lpyRLI4+q/DKsIupmCAn46QCNq0D9DW8
X-Received: by 10.66.150.228 with SMTP id ul4mr43765533pab.16.1404943147303; Wed, 09 Jul 2014 14:59:07 -0700 (PDT)
Received: from [10.72.8.209] (proxy6-global253.qualcomm.com. [199.106.103.253]) by mx.google.com with ESMTPSA id vn5sm52750594pbc.18.2014.07.09.14.59.06 for <multiple recipients> (version=TLSv1 cipher=ECDHE-RSA-RC4-SHA bits=128/128); Wed, 09 Jul 2014 14:59:06 -0700 (PDT)
Content-Type: text/plain; charset=windows-1252
Mime-Version: 1.0 (Mac OS X Mail 7.3 \(1878.6\))
From: Paul Lambert <paul@nymbus.net>
In-Reply-To: <C7A72F49-192D-4476-95A4-D4870F2D84B9@gmail.com>
Date: Wed, 9 Jul 2014 14:59:04 -0700
Content-Transfer-Encoding: quoted-printable
Message-Id: <C4D525AA-045E-4646-833F-FC87D5CDEBD7@nymbus.net>
References: <53BCF608.5010606@gmx.net> <D7E5703D-792F-447E-9B23-0F676861902F@nymbus.net> <C7A72F49-192D-4476-95A4-D4870F2D84B9@gmail.com>
To: Ralph Droms <rdroms.ietf@gmail.com>
X-Mailer: Apple Mail (2.1878.6)
Archived-At: http://mailarchive.ietf.org/arch/msg/ace/QzuuZOK-Pmy51-mk0M9iRBHQGlY
Cc: Hannes Tschofenig <hannes.tschofenig@gmx.net>, "ace@ietf.org" <ace@ietf.org>
Subject: Re: [Ace] Questions for the IETF#90 Meeting
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 09 Jul 2014 21:59:10 -0000

On Jul 9, 2014, at 4:22 AM, Ralph Droms <rdroms.ietf@gmail.com> wrote:

>=20
>=20
>> On Jul 9, 2014, at 4:29 AM, Paul Lambert <paul@nymbus.net> wrote:
>>=20
>>=20
>>> On Jul 9, 2014, at 12:58 AM, Hannes Tschofenig =
<hannes.tschofenig@gmx.net> wrote:
>>>=20
>>> To me there appear to be four questions for the group:
>>>=20
>>> 1) Are there requirements/use cases that allow anything other than =
the
>>> OAuth/Kerberos design pattern?
>> Allow?  Any square peg (Kerberos) could be allowed to fill a round =
hole
>> with a large enough hammer.
>>=20
>> I have requirements for P2P consumer connections that will not
>> initially have any Internet connectivity.  Direct enrollment and
>> management of headless consumer devices is important
>> and especially during bootstrapping from out-of-box does not
>> fit well into OAuth/Kerberos
>>=20
>>>=20
>>> Partially the answer should come from the use case document.
>>>=20
>>> 2) Should the design re-use existing work or should the design start
>>> from scratch?
>> Scratch.
>>=20
>>>=20
>>> This is more a question of taste / preference but will obviously =
have a
>>> huge impact on the subsequent work in the group.
>=20
> I disagree with the characterization as "taste/preference".  In my =
opinion, there needs to be strong evidence for the need for a design =
from scratch and an implicit bias toward reusing existing technologies.

Interesting that there is a perception that new work is harder.  At some =
point we overload our existing protocols too far and they become =
cumbersome (e.g. X.509)  Other industries innovate now faster than the =
IETF.   We have much more rapid changes in PHY and MAC communications.   =
If other groups were so biased we=92d all still be using RS-232


> Use cases like the one outlined above should be reviewed to see if =
they constitute evidence in support of a design from scratch.

Or =85 be open to compare proposals rather than assuming DTLS, OAuth or =
Kerberos are the ultimate solutions.

Paul

>=20
> - Ralph
>=20
>=20
>>>=20
>>> 3) Should the design be based on symmetric or asymmetric crypto?
>>> (or both?)
>> Both of course, and hash algorithms. =20
>> Asymmetric crypto should be used for key establishment and identity.
>> Algorithms should be lumped together as a Cipher Suite that defines
>> a set of algorithms for key established/authentication, encryption, =
hashing, etc.
>>=20
>>=20
>>>=20
>>> We have various documents that talk about this issue, for example
>>> draft-seitz-ace-design-considerations-00 and
>>> draft-seitz-ace-problem-description-01
>>>=20
>>> 4) How to address cross-domain support in the initial protocol =
design?
>>> Is it a feature that can be added later easily?
>>>=20
>>> draft-gerdes-ace-actors-01 talks about this aspect.
>> from this ...
>> "   According to the Internet Security Glossary [RFC4949], =
authentication
>>  is "the process of verifying a claim that a system entity or system
>>  resource has a certain attribute value."  Examples for attribute
>>  values are the ID of a device, the type of the device or the name of
>>  its owner.  Authentication attributes might be (but not necessarily
>>  are) suitable to uniquely identify an individual entity.=94
>>=20
>> The hash of the public key is a attribute that can be directly
>> authenticated by the key holder and is unique. The hash
>> process should include the encoding of the Cipher Suite
>> values to bind the algorithms to the instance of a key.
>> Other attribute bindings can be built on these unique =91ids'
>>=20
>> Paul
>>=20
>>>=20
>>> If we could get an answer to these questions during the meeting that
>>> would be good step forward.
>>>=20
>>> Ciao
>>> Hannes
>>>=20
>>> PS: One question that has been answered by all document in the same =
way
>>> at the moment is about the use of DTLS. Currently, everyone seems to =
be
>>> focused on using DTLS everywhere. There would be alternative =
approaches
>>> as well.
>>>=20
>>> _______________________________________________
>>> Ace mailing list
>>> Ace@ietf.org
>>> https://www.ietf.org/mailman/listinfo/ace
>>=20
>> _______________________________________________
>> Ace mailing list
>> Ace@ietf.org
>> https://www.ietf.org/mailman/listinfo/ace


From nobody Wed Jul  9 16:53:05 2014
Return-Path: <cabo@tzi.org>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 332FD1B2843 for <ace@ietfa.amsl.com>; Wed,  9 Jul 2014 16:53:04 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.551
X-Spam-Level: 
X-Spam-Status: No, score=-1.551 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HELO_EQ_DE=0.35, SPF_HELO_PASS=-0.001] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id vxlSzGGTkkmD for <ace@ietfa.amsl.com>; Wed,  9 Jul 2014 16:53:00 -0700 (PDT)
Received: from informatik.uni-bremen.de (mailhost.informatik.uni-bremen.de [IPv6:2001:638:708:30c9::12]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 3DFED1A0177 for <ace@ietf.org>; Wed,  9 Jul 2014 16:53:00 -0700 (PDT)
X-Virus-Scanned: amavisd-new at informatik.uni-bremen.de
Received: from smtp-fb3.informatik.uni-bremen.de (smtp-fb3.informatik.uni-bremen.de [134.102.224.120]) by informatik.uni-bremen.de (8.14.5/8.14.5) with ESMTP id s69Nqqkl020036; Thu, 10 Jul 2014 01:52:52 +0200 (CEST)
Received: from [192.168.217.145] (p54891105.dip0.t-ipconnect.de [84.137.17.5]) (using TLSv1 with cipher AES128-SHA (128/128 bits)) (No client certificate requested) by smtp-fb3.informatik.uni-bremen.de (Postfix) with ESMTPSA id 6C983F37; Thu, 10 Jul 2014 01:52:50 +0200 (CEST)
Content-Type: text/plain; charset=windows-1252
Mime-Version: 1.0 (Mac OS X Mail 7.3 \(1878.6\))
From: Carsten Bormann <cabo@tzi.org>
In-Reply-To: <C4D525AA-045E-4646-833F-FC87D5CDEBD7@nymbus.net>
Date: Thu, 10 Jul 2014 01:52:47 +0200
X-Mao-Original-Outgoing-Id: 426642767.773272-15564653e568195f7cfe2feb666bf152
Content-Transfer-Encoding: quoted-printable
Message-Id: <5F628AA7-464D-45E3-A9F0-5D30F2298EAA@tzi.org>
References: <53BCF608.5010606@gmx.net> <D7E5703D-792F-447E-9B23-0F676861902F@nymbus.net> <C7A72F49-192D-4476-95A4-D4870F2D84B9@gmail.com> <C4D525AA-045E-4646-833F-FC87D5CDEBD7@nymbus.net>
To: Paul Lambert <paul@nymbus.net>
X-Mailer: Apple Mail (2.1878.6)
Archived-At: http://mailarchive.ietf.org/arch/msg/ace/bQ85-zwUBY8WcJGWwsI17LryEQY
Cc: Hannes Tschofenig <hannes.tschofenig@gmx.net>, Ralph Droms <rdroms.ietf@gmail.com>, "ace@ietf.org" <ace@ietf.org>
Subject: Re: [Ace] Questions for the IETF#90 Meeting
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 09 Jul 2014 23:53:04 -0000

On 09 Jul 2014, at 23:59, Paul Lambert <paul@nymbus.net> wrote:

> Interesting that there is a perception that new work is harder.

In the late 1990s, I sat through a couple of years of developing the SIP =
protocol, from the protocol that was =93almost compatible with HTTP, =
just a little different because it was about phone calls=94 to the =
protocol that was considerably damaged by people inappropriately =
applying their HTTP intuitions to a completely different protocol that =
was just using the same names for different things.

We mentioned this in section 2.6 of =
http://www.iab.org/wp-content/IAB-uploads/2011/04/Bormann.pdf, but this =
specific fallacy of =93building on existing protocols=94 probably =
deserves a more complete treatment.

Gr=FC=DFe, Carsten

PS.: =
http://geekandpoke.typepad.com/geekandpoke/2011/03/architectural-best-prac=
tices.html


From nobody Thu Jul 10 00:44:33 2014
Return-Path: <hannes.tschofenig@gmx.net>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id EEEA21A0371 for <ace@ietfa.amsl.com>; Thu, 10 Jul 2014 00:44:31 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.551
X-Spam-Level: 
X-Spam-Status: No, score=-2.551 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, FREEMAIL_FROM=0.001, RCVD_IN_DNSWL_NONE=-0.0001, RP_MATCHES_RCVD=-0.651, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id SUyDz6KKlbtJ for <ace@ietfa.amsl.com>; Thu, 10 Jul 2014 00:44:30 -0700 (PDT)
Received: from mout.gmx.net (mout.gmx.net [212.227.17.21]) (using TLSv1.2 with cipher DHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 3B3ED1A0361 for <ace@ietf.org>; Thu, 10 Jul 2014 00:44:30 -0700 (PDT)
Received: from [192.168.131.128] ([80.92.116.212]) by mail.gmx.com (mrgmx101) with ESMTPSA (Nemesis) id 0MgGDK-1XGdjQ47UM-00Njuv; Thu, 10 Jul 2014 09:44:27 +0200
Message-ID: <53BE4458.2090200@gmx.net>
Date: Thu, 10 Jul 2014 09:44:24 +0200
From: Hannes Tschofenig <hannes.tschofenig@gmx.net>
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:24.0) Gecko/20100101 Thunderbird/24.6.0
MIME-Version: 1.0
To: Paul Lambert <paul@nymbus.net>
References: <53BCF608.5010606@gmx.net> <D7E5703D-792F-447E-9B23-0F676861902F@nymbus.net> <53BD0518.8060609@gmx.net> <1EFD8C56-BB56-4395-8DFB-B015606381F9@nymbus.net>
In-Reply-To: <1EFD8C56-BB56-4395-8DFB-B015606381F9@nymbus.net>
X-Enigmail-Version: 1.5.2
OpenPGP: id=4D776BC9
Content-Type: multipart/signed; micalg=pgp-sha512; protocol="application/pgp-signature"; boundary="UoWacvtwILuIAEMtC5h7P7xq6TftRs0bp"
X-Provags-ID: V03:K0:OCmfXDC5/Dxl+kK47K9+Ltxm0E7SQJ8VMMqtWy+3h058zxjMXq1 to2X0ha5GPeeMoBHJ4JfuKO1OApJUjZWpf9GZWPIX9Qc0oHaMUfxekaylX1u9wD1FKX2y3g gL9+czpejIHE9QOuNizKQK4pGe1jZYt6ZWUNOGlVE67zNKbI9wDs/GS+idbyrTJZIs9L8rx ReScFT63iuSNpPQwetDFw==
Archived-At: http://mailarchive.ietf.org/arch/msg/ace/X8hyhiTN6IlUNUWdzqj40E4aV7k
Cc: "ace@ietf.org" <ace@ietf.org>
Subject: Re: [Ace] Questions for the IETF#90 Meeting
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 10 Jul 2014 07:44:32 -0000

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--UoWacvtwILuIAEMtC5h7P7xq6TftRs0bp
Content-Type: text/plain; charset=windows-1252
Content-Transfer-Encoding: quoted-printable

Hi Paul,


On 07/09/2014 11:52 PM, Paul Lambert wrote:
> Wireless (e.g. Wi-Fi ) based direct connections from one device to anot=
her.
>  - between two smart phones
>  - smart phone to headless device (e.g. hot water heater)
> Typically no Internet connection guaranteed to be available.

As currently described in the use cases an initial interaction between
the client and the authorization server would be needed to get the
protocol interaction working. If there is only connectivity from the
client to the resource server and nothing else then this is currently
not covered by the use cases.


>=20
> The interesting part is the =93enrollment=94 which appears to be
> out-of-scope for this group.  The initial =91pairing=92 is effectively
> the AS function being introduced to a C or RS and providing
> initial configuration of policy (aka authorization information)

The interaction between the client and the AS is within the scope. We
didn't call this enrollment though.


--UoWacvtwILuIAEMtC5h7P7xq6TftRs0bp
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
Content-Disposition: attachment; filename="signature.asc"

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1
Comment: GPGTools - http://gpgtools.org
Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/

iQEcBAEBCgAGBQJTvkRZAAoJEGhJURNOOiAt80IH/3dHupB1llH/MHvCgqBCAiq4
UWtc7VY+PH+Bap1xYNxde8rlmqAd8v2BSD+bjWn4brzLhLKdf7CXTI6N4++7nHkp
MMH8xYE8Qsq6XRNMfs/IrLM0uUft/wCOVrJ2uUtOjrv/KjG37cT6brm/Yez7BHfm
sLGLaYYm/Y6fN1zvQnciKClgZRhN+Io5F9P+09/+pnZvxBsh4r+0XfCAa4UO1qfp
PCqLsEc2z2wDJImc5HQfjpLF2ynxirdpGSn0nNe4V7p7/2i3vWaGlK51AWUDVo+A
djrfP7AT6J1BcWbI39uD2fkG5gwv1epOPTCbPAJXsuCVCwFoV3jS46n8G1ol9jY=
=sYFp
-----END PGP SIGNATURE-----

--UoWacvtwILuIAEMtC5h7P7xq6TftRs0bp--


From nobody Thu Jul 10 11:22:35 2014
Return-Path: <goran.selander@ericsson.com>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 4614F1A0B06 for <ace@ietfa.amsl.com>; Thu, 10 Jul 2014 11:22:29 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -3.901
X-Spam-Level: 
X-Spam-Status: No, score=-3.901 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, MIME_8BIT_HEADER=0.3, RCVD_IN_DNSWL_MED=-2.3, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id ZLp4DaBJA86T for <ace@ietfa.amsl.com>; Thu, 10 Jul 2014 11:22:28 -0700 (PDT)
Received: from sesbmg22.ericsson.net (sesbmg22.ericsson.net [193.180.251.48]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 98DAF1B2950 for <ace@ietf.org>; Thu, 10 Jul 2014 11:22:24 -0700 (PDT)
X-AuditID: c1b4fb30-f79da6d000006b80-2a-53bed9de57e9
Received: from ESESSHC001.ericsson.se (Unknown_Domain [153.88.253.124]) by sesbmg22.ericsson.net (Symantec Mail Security) with SMTP id 6E.72.27520.ED9DEB35; Thu, 10 Jul 2014 20:22:22 +0200 (CEST)
Received: from ESESSMB303.ericsson.se ([169.254.3.228]) by ESESSHC001.ericsson.se ([153.88.183.21]) with mapi id 14.03.0174.001; Thu, 10 Jul 2014 20:22:22 +0200
From: =?iso-8859-1?Q?G=F6ran_Selander?= <goran.selander@ericsson.com>
To: Hannes Tschofenig <hannes.tschofenig@gmx.net>, "ace@ietf.org" <ace@ietf.org>
Thread-Topic: [Ace] Questions for the IETF#90 Meeting
Thread-Index: AQHPm0uHo5V+CrMW7EKyS4YjhTlxCpuZoTEA
Date: Thu, 10 Jul 2014 18:22:21 +0000
Message-ID: <CFE3A8A2.15B26%goran.selander@ericsson.com>
References: <53BCF608.5010606@gmx.net>
In-Reply-To: <53BCF608.5010606@gmx.net>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
user-agent: Microsoft-MacOutlook/14.4.2.140509
x-originating-ip: [153.88.183.148]
Content-Type: text/plain; charset="iso-8859-1"
Content-ID: <9797E76EB94051488084B0B63FD96E97@ericsson.com>
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
X-Brightmail-Tracker: H4sIAAAAAAAAA+NgFmplkeLIzCtJLcpLzFFi42KZGfG3RvfezX3BBi/eWFt8/9bDbLF05z1W ByaPxZv2s3ksWfKTKYApissmJTUnsyy1SN8ugSvjw9EfLAWdrBUP125iaWCcxNLFyMkhIWAi 8eHQNzYIW0ziwr31QDYXh5DAUUaJ5+evsEI4SxglNs/dBtbBJuAqceDBOyYQW0QgSOJw42uw bmGgSS0PH7FDxE0lTj1tZIawjST6Dv8Dq2cRUJVY2r4czOYVsJBYuH8KWL2QgJrE2V0/geIc HJwC6hLzZ+eBhBmBDvp+ag1YObOAuMStJ/OZIA4VkFiy5zwzhC0q8fLxP1YQW1RAT6K56w0j RFxJonHJE1aIXj2JG1OnsEHY1hKTr86BimtLLFv4mhniHEGJkzOfsExgFJ+FZN0sJO2zkLTP QtI+C0n7AkbWVYyixanFSbnpRkZ6qUWZycXF+Xl6eaklmxiB8XZwy2+DHYwvnzseYhTgYFTi 4V1wZV+wEGtiWXFl7iFGaQ4WJXHehefmBQsJpCeWpGanphakFsUXleakFh9iZOLglGpgbE27 pLLmudaZBwFCS85f03smMmvSzyZDqdm9masvXDKuDPd4o1EWbeDgJD21+bdBcUH9K/3/rteX z9uTrrxBxKdTamnuN6vnMwVnHfhRFbs2/u2+6Gh753uLcniPLe0SZr70usor7duPzQ1Nj1l/ MDQenFcQOWnacZ7VVod6pLZsrPvZU7akWImlOCPRUIu5qDgRAFN+xByYAgAA
Archived-At: http://mailarchive.ietf.org/arch/msg/ace/gpULeJLPMb49x3qgGl2clOLmjio
Subject: Re: [Ace] Questions for the IETF#90 Meeting
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 10 Jul 2014 18:22:29 -0000

Hi Hannes

On 09/07/14 09:58, "Hannes Tschofenig" <hannes.tschofenig@gmx.net> wrote:

>
>PS: One question that has been answered by all document in the same way
>at the moment is about the use of DTLS. Currently, everyone seems to be
>focused on using DTLS everywhere.

>=20
=20
In don=B9t understand this statement. Section 3.3 and the requirement in
section 4.8 of draft-seitz-ace-problem-description-01 is explicitly
considering alternative communication security paradigms. Section 4.2 of
the same draft mentionS issues with DTLS. What is the meaning of "everyone
seems to be
focused on using DTLS everywhere=B2?


G=F6ran


From nobody Thu Jul 10 11:26:59 2014
Return-Path: <hannes.tschofenig@gmx.net>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 66B721A0AFF for <ace@ietfa.amsl.com>; Thu, 10 Jul 2014 11:26:58 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.251
X-Spam-Level: 
X-Spam-Status: No, score=-2.251 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, FREEMAIL_FROM=0.001, MIME_8BIT_HEADER=0.3, RCVD_IN_DNSWL_NONE=-0.0001, RP_MATCHES_RCVD=-0.651, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id bEe9al5n4Fqs for <ace@ietfa.amsl.com>; Thu, 10 Jul 2014 11:26:55 -0700 (PDT)
Received: from mout.gmx.net (mout.gmx.net [212.227.17.21]) (using TLSv1.2 with cipher DHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id B0BFD1A0296 for <ace@ietf.org>; Thu, 10 Jul 2014 11:26:54 -0700 (PDT)
Received: from [172.16.254.119] ([80.92.116.212]) by mail.gmx.com (mrgmx103) with ESMTPSA (Nemesis) id 0MgbvP-1XH3192PfL-00Nygu; Thu, 10 Jul 2014 20:26:52 +0200
Message-ID: <53BEDAEA.5040502@gmx.net>
Date: Thu, 10 Jul 2014 20:26:50 +0200
From: Hannes Tschofenig <hannes.tschofenig@gmx.net>
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:24.0) Gecko/20100101 Thunderbird/24.6.0
MIME-Version: 1.0
To: =?ISO-8859-1?Q?G=F6ran_Selander?= <goran.selander@ericsson.com>,  "ace@ietf.org" <ace@ietf.org>
References: <53BCF608.5010606@gmx.net> <CFE3A8A2.15B26%goran.selander@ericsson.com>
In-Reply-To: <CFE3A8A2.15B26%goran.selander@ericsson.com>
X-Enigmail-Version: 1.5.2
OpenPGP: id=4D776BC9
Content-Type: multipart/signed; micalg=pgp-sha512; protocol="application/pgp-signature"; boundary="wBX2jMbHoIx9IeanjCwBiSsGLx4WQbUO0"
X-Provags-ID: V03:K0:ykz8ykr4e5o+D8NyoGIvGfKIlIc88f0x9zCkp6ZBE5PdefWXRqI uL8NAvNRsGkT58tyb1ACteH7AJlfMkc8IFdYMR74DUJliRkudXTJsq33X5TjZ6UCEPcwlB9 RIfBvKir6VSbA/q5kP9TZHKl2C3PteCSVndzaOZreNYEiSfV+NNlvxM3ahOMFjiHRr0SDPr e3iFfThVAzY6CGhH9AoIA==
Archived-At: http://mailarchive.ietf.org/arch/msg/ace/ARz3yKwgG0NwZnxa12C_ggr6JsI
Subject: Re: [Ace] Questions for the IETF#90 Meeting
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 10 Jul 2014 18:26:58 -0000

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--wBX2jMbHoIx9IeanjCwBiSsGLx4WQbUO0
Content-Type: text/plain; charset=ISO-8859-1
Content-Transfer-Encoding: quoted-printable

Hi G=F6ran

thanks for pointing this out.

When writing the email I was thinking about the solution documents I had
gone through. In those solutions I saw the focus on DTLS, which sort of
makes sense.

Ciao
Hannes


On 07/10/2014 08:22 PM, G=F6ran Selander wrote:
> Hi Hannes
>=20
> On 09/07/14 09:58, "Hannes Tschofenig" <hannes.tschofenig@gmx.net> wrot=
e:
>=20
>>
>> PS: One question that has been answered by all document in the same wa=
y
>> at the moment is about the use of DTLS. Currently, everyone seems to b=
e
>> focused on using DTLS everywhere.
>=20
>>
> =20
> In don=B9t understand this statement. Section 3.3 and the requirement i=
n
> section 4.8 of draft-seitz-ace-problem-description-01 is explicitly
> considering alternative communication security paradigms. Section 4.2 o=
f
> the same draft mentionS issues with DTLS. What is the meaning of "every=
one
> seems to be
> focused on using DTLS everywhere=B2?
>=20
>=20
> G=F6ran
>=20


--wBX2jMbHoIx9IeanjCwBiSsGLx4WQbUO0
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
Content-Disposition: attachment; filename="signature.asc"

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1
Comment: GPGTools - http://gpgtools.org
Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/

iQEcBAEBCgAGBQJTvtrqAAoJEGhJURNOOiAtVnQH/ie4rW9crUbw2X7LM2nc55aa
s047u+MrBWd+QgprVyyVv7aJvVi3g4T+H0yllA2ioVkUUtL6jyDVM4cfQQgmLF1V
H40SOpU3GOnQ62lnKrv1GNBXs818g6C5ZwNRgWKHVNMst0mI1lIaLKKfkmmWrpVT
O5lBSbGMEVRj8GL2XYMFgVWH1ZQtunAV54Fr9jbWwzyJ3CVqSkvfX2rNGoBLXj49
TJtXXlhd1R1OXXNEgco433LJ+mc/YYWyWzsQCLAMuIOt2PdFKEh4XqyKJmjAMVru
ITGdjMM6sRPGMyYflRgbUVQ3Ze3c7/UxiYi4b4OhXAYyoq3QJXXvuBPfiTU4aqU=
=eUmJ
-----END PGP SIGNATURE-----

--wBX2jMbHoIx9IeanjCwBiSsGLx4WQbUO0--


From nobody Thu Jul 10 12:05:00 2014
Return-Path: <paul@nymbus.net>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id EA8181B29B2 for <ace@ietfa.amsl.com>; Thu, 10 Jul 2014 12:04:56 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.6
X-Spam-Level: 
X-Spam-Status: No, score=-2.6 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_LOW=-0.7] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id duqU1iPdH_J9 for <ace@ietfa.amsl.com>; Thu, 10 Jul 2014 12:04:54 -0700 (PDT)
Received: from mail-pa0-f41.google.com (mail-pa0-f41.google.com [209.85.220.41]) (using TLSv1 with cipher ECDHE-RSA-RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 999971B29B4 for <ace@ietf.org>; Thu, 10 Jul 2014 12:04:54 -0700 (PDT)
Received: by mail-pa0-f41.google.com with SMTP id fb1so20770pad.0 for <ace@ietf.org>; Thu, 10 Jul 2014 12:04:54 -0700 (PDT)
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20130820; h=x-gm-message-state:content-type:mime-version:subject:from :in-reply-to:date:cc:content-transfer-encoding:message-id:references :to; bh=Kd2nw3rnJe2FGnbsE6T0Wm3VUqLjJ98g2JLQcUXcFks=; b=AjGj94Ub50DGQ6J7/l3M05/+4CWyYM8sA18qrIUbX1HKaBAri1LCtQN6W140qlERpI 2ZS/+c01dXzHqqvXdkcghBWnUFTxy6bslXM8lSNS01ZWrllYFhykh89aCHrduOd57fuy scSTG+ViLtbbuFBkRp4icUiGokhT+Z2fMiXqs4VoMcxtTRpkPzar2AXgH6yld+CWkdNI HgteLSMHBe7hYKkH0XWqo12K+yQNGxf7ef1bSKfzxkK6fr7eOO22Lv+jIf/WJ9u6ZYFo TYZEETRz6ERfYhzkV1X++wf1K2uBwxpccr3WmDNql55nMQYyx9ddfaxWj+bPiwra3U3W ik9Q==
X-Gm-Message-State: ALoCoQmdRWWpM8VFNVQJrvnO/ruoUmSkks1zOLqVh4zcx3EUAZ8Lb+cwhmCRUKIeb9k0Ed74897o
X-Received: by 10.70.91.170 with SMTP id cf10mr18921436pdb.72.1405019094242; Thu, 10 Jul 2014 12:04:54 -0700 (PDT)
Received: from [10.72.8.227] (proxy6-global253.qualcomm.com. [199.106.103.253]) by mx.google.com with ESMTPSA id qk9sm50988pac.16.2014.07.10.12.04.53 for <multiple recipients> (version=TLSv1 cipher=ECDHE-RSA-RC4-SHA bits=128/128); Thu, 10 Jul 2014 12:04:53 -0700 (PDT)
Content-Type: text/plain; charset=windows-1252
Mime-Version: 1.0 (Mac OS X Mail 7.3 \(1878.6\))
From: Paul Lambert <paul@nymbus.net>
In-Reply-To: <5F628AA7-464D-45E3-A9F0-5D30F2298EAA@tzi.org>
Date: Thu, 10 Jul 2014 12:04:52 -0700
Content-Transfer-Encoding: quoted-printable
Message-Id: <F305A3A8-C2A9-4080-A9E4-D727CD59ED5F@nymbus.net>
References: <53BCF608.5010606@gmx.net> <D7E5703D-792F-447E-9B23-0F676861902F@nymbus.net> <C7A72F49-192D-4476-95A4-D4870F2D84B9@gmail.com> <C4D525AA-045E-4646-833F-FC87D5CDEBD7@nymbus.net> <5F628AA7-464D-45E3-A9F0-5D30F2298EAA@tzi.org>
To: Carsten Bormann <cabo@tzi.org>
X-Mailer: Apple Mail (2.1878.6)
Archived-At: http://mailarchive.ietf.org/arch/msg/ace/n8nA2LxNPbpNSl7D7jjBmHJi5mQ
Cc: Hannes Tschofenig <hannes.tschofenig@gmx.net>, Ralph Droms <rdroms.ietf@gmail.com>, "ace@ietf.org" <ace@ietf.org>
Subject: Re: [Ace] Questions for the IETF#90 Meeting
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 10 Jul 2014 19:04:57 -0000

Carsten,


>> Interesting that there is a perception that new work is harder.
>=20
> In the late 1990s, I sat through a couple of years of developing the =
SIP protocol, from the protocol that was =93almost compatible with HTTP, =
just a little different because it was about phone calls=94 to the =
protocol that was considerably damaged by people inappropriately =
applying their HTTP intuitions to a completely different protocol that =
was just using the same names for different things.
>=20
> We mentioned this in section 2.6 of =
http://www.iab.org/wp-content/IAB-uploads/2011/04/Bormann.pdf, but this =
specific fallacy of =93building on existing protocols=94 probably =
deserves a more complete treatment.

Thanks for your support on this topic.  Technical proposals should be =
considered based on their merit and not solely on reuse of existing =
RFCs.  In the IETF, we need to more conciously examine what has been =
done well and where improvements are possible. =20

Paul



>=20
> Gr=FC=DFe, Carsten
>=20
> PS.: =
http://geekandpoke.typepad.com/geekandpoke/2011/03/architectural-best-prac=
tices.html
>=20


From nobody Thu Jul 10 15:56:51 2014
Return-Path: <paul@nymbus.net>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id F01D71A007F for <ace@ietfa.amsl.com>; Thu, 10 Jul 2014 15:56:49 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.9
X-Spam-Level: 
X-Spam-Status: No, score=-1.9 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_NONE=-0.0001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 4uvuYfqeKj6k for <ace@ietfa.amsl.com>; Thu, 10 Jul 2014 15:56:48 -0700 (PDT)
Received: from mail-pd0-f181.google.com (mail-pd0-f181.google.com [209.85.192.181]) (using TLSv1 with cipher ECDHE-RSA-RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 67F751A0078 for <ace@ietf.org>; Thu, 10 Jul 2014 15:56:48 -0700 (PDT)
Received: by mail-pd0-f181.google.com with SMTP id v10so292544pde.26 for <ace@ietf.org>; Thu, 10 Jul 2014 15:56:48 -0700 (PDT)
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20130820; h=x-gm-message-state:content-type:mime-version:subject:from :in-reply-to:date:cc:content-transfer-encoding:message-id:references :to; bh=mE9Bc3gzNsML5e5D9wXag/Bh2NegS+viEwmdN+1gM6I=; b=AC/W9MdDOme2o66B8SH92PhoeoLem9FXnRNkyBLJq+hqfMsPYw4LWUBNvGK0DVlYAp 5GfDA/giaaV00Xk6Lk4I/wLV3A7IHuaFFU+Cxxyyx56KDh0Nv5EAqSl5MNlJyJSPASAe whYfLYqVaC1SDxech8tHJL9e2v6yvDleTiUmXCdAkK3xX+9QGKZYG0yMgSN4w6jcvRLt g6Tw1kuzjZYXjojH4MiYthlPc+36b5cf00/XavMc0cgG99roNRGFPx/CAnJawKM0QOu5 3pyWp9tNh6FxufP+ObQxFIaZ0DgLc9/S1NTYTtu7XHnn+jtQkguc4rMKVvTNTSPiHta1 8E0A==
X-Gm-Message-State: ALoCoQnO1C7I7jaKpv3fQJVJsdGbrYfswo0nuUjbO1LExJ1RfGap3WC/gWDAQM3k3Yh7YazFoQMf
X-Received: by 10.69.18.11 with SMTP id gi11mr49847146pbd.36.1405033008061; Thu, 10 Jul 2014 15:56:48 -0700 (PDT)
Received: from [10.72.8.227] (proxy6-global253.qualcomm.com. [199.106.103.253]) by mx.google.com with ESMTPSA id fm8sm1825950pab.28.2014.07.10.15.56.47 for <multiple recipients> (version=TLSv1 cipher=ECDHE-RSA-RC4-SHA bits=128/128); Thu, 10 Jul 2014 15:56:47 -0700 (PDT)
Content-Type: text/plain; charset=windows-1252
Mime-Version: 1.0 (Mac OS X Mail 7.3 \(1878.6\))
From: Paul Lambert <paul@nymbus.net>
In-Reply-To: <53BE4458.2090200@gmx.net>
Date: Thu, 10 Jul 2014 15:56:45 -0700
Content-Transfer-Encoding: quoted-printable
Message-Id: <BDA7B83A-C4D0-4AE5-8F78-C37A2B3A8C99@nymbus.net>
References: <53BCF608.5010606@gmx.net> <D7E5703D-792F-447E-9B23-0F676861902F@nymbus.net> <53BD0518.8060609@gmx.net> <1EFD8C56-BB56-4395-8DFB-B015606381F9@nymbus.net> <53BE4458.2090200@gmx.net>
To: Hannes Tschofenig <hannes.tschofenig@gmx.net>
X-Mailer: Apple Mail (2.1878.6)
Archived-At: http://mailarchive.ietf.org/arch/msg/ace/D2upPSe4TQSYZp65ebgboFLwISg
Cc: "ace@ietf.org" <ace@ietf.org>
Subject: Re: [Ace] Questions for the IETF#90 Meeting
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 10 Jul 2014 22:56:50 -0000

Hannes,

> On 07/09/2014 11:52 PM, Paul Lambert wrote:
>> Wireless (e.g. Wi-Fi ) based direct connections from one device to =
another.
>> - between two smart phones
>> - smart phone to headless device (e.g. hot water heater)
>> Typically no Internet connection guaranteed to be available.
>=20
> As currently described in the use cases an initial interaction between
> the client and the authorization server would be needed to get the
> protocol interaction working.
Thank you for the clarification =85 that makes sense now rereading.

I do have fundamental problems with the overall server centric=20
framework, for example:

"    U4.3.  Devices can access resources on other devices only if a
      rule exists in the authorization server (default deny)."
and
"U4.5.  Devices may cache authorization rules locally.=94

I do  not see why a server is required.  The authorization/policy =
information
required to make the decision might better be modeled as as
a functional element in the RS.  The authorization information
should be available locally to the RS, but could reach out to
one or more servers in some implementions ions.

> If there is only connectivity from the
> client to the resource server and nothing else then this is currently
> not covered by the use cases.

If the RS is a Kerberos like system that uses symmetric key enrollment=20=

you get one particular world view and set of capabilities.

If the RS is not a symmetric key server, but a policy =91authority=92 =
(PA) that can sign
authorization statements, you get a different set of potential =
topologies
and capabilities.

This set of specifications quickly to a =91third party=92 server,
and eliminates more dynamic and distributed models. These tend
to drive the solution space to a factory pre configuration of
devices with credentials of a RS.

Having the =91authority=92 in my mobile device is my preferred use
case.  Design overview:
 - mobile device has loaded a =93configuration=94 app
   Configuration Apps use common setup and authorization
   protocols
 - multiple devices from multiple vendors (supporting
   this provisioning technology) can be managed by the app
 - No factory provisioned are required
   Devices come from multiple vendors that may not agree
   on a single server or authorization authority
   Devices may include factory installed information signed
   by their facities
 - Every device conforming to this methodolgy is authenticated
   peer-to-peer using self generated public keys
 - =91dumb=92 headless devices have a long term static public key=20
   bound to label information to support secure initial pairing
 - headless devices after initial pairing generate a new long
   term key for authentication to other devices
 - out-of-box, devices (C or RS in ACE model) must be
   paired/setup by an Authority (in this example the mobile
   device with pairing application)
  - setup of a new device establishes the RA (as opposed
    to RS) as the identity with authority to set policies
    in the enrollee (C/RS). =20
  - Access control is an Attribute based model where
    attributes may be associated to a key.
   Attributes of a key include it=92s =91id=92 (hash of
   key, cipher suite id, type), and arbitrary tag/value
    pairs.
   - Typical assigned tags might include be =91group=92
     (e.g.   group: foo)
   - Configuration of end device (RS/C) by RA will
     set local policy consisting of Attribute based
     rules for actions (e.g. ACL of ids, group or other)
  - RA can configure other devices (usually a smart
    phone) to have some or all of the authority for
    a name space.  This allows delegation and
    support of multiple RAs
  - Reset of headless devices consists of deleting
    current public/private key pair.  Simple reset
    is button on device.  Secure reset is by=20
    authorized RA
  - RA only needs to configure pair-wise to each
    device once when using simple group
    attribute policies.  Group membership
    is indicated from device-to-device=20
    without central server.  Group membership
    is a tag/value assignment from RA to
    C/RS signed by RA. =20
   - where central monitoring/loggin required,=20
     authorization decision could be based on
    implementation of policy function as proxy to server
  - public key replacement, backup, RA cloning is
    handled by signed delegation of RA key to
    another key to become RA



Paul




   =20




>=20
>=20
>>=20
>> The interesting part is the =93enrollment=94 which appears to be
>> out-of-scope for this group.  The initial =91pairing=92 is =
effectively
>> the AS function being introduced to a C or RS and providing
>> initial configuration of policy (aka authorization information)
>=20
> The interaction between the client and the AS is within the scope. We
> didn't call this enrollment though.
>=20


From nobody Fri Jul 11 02:30:30 2014
Return-Path: <hannes.tschofenig@gmx.net>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 352381A0393 for <ace@ietfa.amsl.com>; Fri, 11 Jul 2014 02:30:28 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.551
X-Spam-Level: 
X-Spam-Status: No, score=-2.551 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, FREEMAIL_FROM=0.001, RCVD_IN_DNSWL_NONE=-0.0001, RP_MATCHES_RCVD=-0.651, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id TW_MY4sbGxpX for <ace@ietfa.amsl.com>; Fri, 11 Jul 2014 02:30:26 -0700 (PDT)
Received: from mout.gmx.net (mout.gmx.net [212.227.17.21]) (using TLSv1.2 with cipher DHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 68C4D1A03B9 for <ace@ietf.org>; Fri, 11 Jul 2014 02:30:26 -0700 (PDT)
Received: from [172.16.254.119] ([80.92.116.212]) by mail.gmx.com (mrgmx103) with ESMTPSA (Nemesis) id 0M7ojs-1WjU2G2QYy-00vOAI; Fri, 11 Jul 2014 11:30:20 +0200
Message-ID: <53BFAEA8.3090407@gmx.net>
Date: Fri, 11 Jul 2014 11:30:16 +0200
From: Hannes Tschofenig <hannes.tschofenig@gmx.net>
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:24.0) Gecko/20100101 Thunderbird/24.6.0
MIME-Version: 1.0
To: Michael Richardson <mcr+ietf@sandelman.ca>
References: <53BCF608.5010606@gmx.net> <27297.1404914953@sandelman.ca>
In-Reply-To: <27297.1404914953@sandelman.ca>
X-Enigmail-Version: 1.5.2
OpenPGP: id=4D776BC9
Content-Type: multipart/signed; micalg=pgp-sha512; protocol="application/pgp-signature"; boundary="dbmTxtbGU4ixne304rsmJ0cGX1BIonJXs"
X-Provags-ID: V03:K0:WZzdS3XdrjYcBu5Atpa5VhEP3ankMpDEIpj7XuEJI2vmhaf+44H ENLPMElnwdRHBzN9QS+kj1uhCMURvTGdT0ZyNEmw1ftZ0KEbY12GEWhkBECWMOhsHBllyDo 7WmBS+OjRKuQJhwRx8KmoiNFm3mBpuDLagqeTsAJFo7o951w6y5g/CGxMfHDxRMUkemU9Fy WrXhpSTlcLr1VV9Poyoow==
Archived-At: http://mailarchive.ietf.org/arch/msg/ace/DeZaB6k_pGvfe88CS_a_iodoqmU
Cc: "ace@ietf.org" <ace@ietf.org>
Subject: Re: [Ace] Questions for the IETF#90 Meeting
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 11 Jul 2014 09:30:28 -0000

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--dbmTxtbGU4ixne304rsmJ0cGX1BIonJXs
Content-Type: text/plain; charset=ISO-8859-1
Content-Transfer-Encoding: quoted-printable

Hi Michael,

thanks for the feedback.

One minor remark on the Kerberos cross-realm authentication.

My understanding of the challenge with deployments (from discussions
with the Kerberos folks) is that there have to be business reasons for
deploying cross-realm authentication. These business reasons are not
always there and they require a considerable amount of effort since
business agreements (including legal aspects) do not necessarily scale
in the same way as technology could do.

This is also a painful lesson the original OpenID guys learned (which is
why it is dead now). They approached the problem of federations in a
technical way and failed to understand that federations are 95%
business/legal constructs and only 5% technology.

Ciao
Hannes


On 07/09/2014 04:09 PM, Michael Richardson wrote:
>=20
> Hannes Tschofenig <hannes.tschofenig@gmx.net> wrote:
>     > 1) Are there requirements/use cases that allow anything other tha=
n the
>     > OAuth/Kerberos design pattern?
>=20
> I think that there are two questions here:
>   1) is the OAuth/Kerberos design pattern sufficient? (does it do every=
thing)
>   2) is the OAUTH/Kerberos design pattern necessary?  (can we throw som=
ething away?)
>=20
> My instinct is that it handles all of the operational parts, but it doe=
s not
> handle any of the enrollment parts, particularly for the case where the=

> parties are offline.   You will recall that you felt at the BOF that th=
e
> enrollment case was out of scope.
>=20
>     > 2) Should the design re-use existing work or should the design st=
art
>     > from scratch?
>=20
>     > This is more a question of taste / preference but will obviously =
have a
>     > huge impact on the subsequent work in the group.
>=20
> I think that it worth spending some time to think about a CBOR encoding=
 of
> OAuth2, which I think makes use of JSON.  I don't think we have any map=
ping
> of Kerberos into JSON, but I could be wrong.  The idea is to start with=
 a
> baseline situation and then decided if we should innovate.
>=20
>     > 3) Should the design be based on symmetric or asymmetric crypto?
>     > (or both?)
>=20
>     > We have various documents that talk about this issue, for example=

>     > draft-seitz-ace-design-considerations-00 and
>     > draft-seitz-ace-problem-description-01
>=20
> After enrollment, symmetric crypto is sufficient.
>=20
>     > 4) How to address cross-domain support in the initial protocol de=
sign?
>     > Is it a feature that can be added later easily?
>=20
>     > draft-gerdes-ace-actors-01 talks about this aspect.
>=20
> It must be present from day one.  That is one thing which dis-recommend=
s a
> pure Kerberos pattern, or at least observes Kerberos to include all the=
 pkinit and=20
> cross-realm stuff from the beginning.  My limited experience with kerbe=
ros is
> that there must be significant operational hurdles to doing cross-realm=

> things, or it would occur far more often.
>=20
>     > PS: One question that has been answered by all document in the sa=
me way
>     > at the moment is about the use of DTLS. Currently, everyone seems=
 to be
>     > focused on using DTLS everywhere. There would be alternative appr=
oaches
>     > as well.
>=20
> I don't prefer to have any alternative approaches be considered.=20
>=20
>=20
>=20
> _______________________________________________
> Ace mailing list
> Ace@ietf.org
> https://www.ietf.org/mailman/listinfo/ace
>=20


--dbmTxtbGU4ixne304rsmJ0cGX1BIonJXs
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
Content-Disposition: attachment; filename="signature.asc"

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1
Comment: GPGTools - http://gpgtools.org
Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/

iQEcBAEBCgAGBQJTv66oAAoJEGhJURNOOiAth+oH/081vv39nzDN4LD+5mBCacb/
L3fVpm7On0sJlaQrmQcgvEOM12H1dzdN77yyvk4CK+xXbxOOwbvWl/OZEcM5Bo5c
WtAofRTWvjnEr5eAlflI2oYgV9fyCrJt8q3gARO1Q7PzrNRAFKE2MzDdI2R7VIow
K76b4uiHOqT1Mm+0GTfo05ITV+zNhmM/XlTDZFkegJg3uO3uybS/9zPCS9A6gX60
q0avvQ+YO2XvAAoGzNyrUlgXYjJx6jgfRZbo9d7V6tIefwG/HtLEp21MWiK9qbr9
Ell3erR/QLE8w35dEu3UaewUXnc1q7GD2R+uqEzBYLIgn/76D9HhvbONx5V33Po=
=j3qz
-----END PGP SIGNATURE-----

--dbmTxtbGU4ixne304rsmJ0cGX1BIonJXs--


From nobody Fri Jul 11 02:34:18 2014
Return-Path: <hannes.tschofenig@gmx.net>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 570781B27D0 for <ace@ietfa.amsl.com>; Fri, 11 Jul 2014 02:34:16 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.551
X-Spam-Level: 
X-Spam-Status: No, score=-2.551 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, FREEMAIL_FROM=0.001, RCVD_IN_DNSWL_NONE=-0.0001, RP_MATCHES_RCVD=-0.651, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 2iRYlegYqzp1 for <ace@ietfa.amsl.com>; Fri, 11 Jul 2014 02:34:14 -0700 (PDT)
Received: from mout.gmx.net (mout.gmx.net [212.227.17.20]) (using TLSv1.2 with cipher DHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 65BCE1B27B0 for <ace@ietf.org>; Fri, 11 Jul 2014 02:34:14 -0700 (PDT)
Received: from [172.16.254.119] ([80.92.116.212]) by mail.gmx.com (mrgmx102) with ESMTPSA (Nemesis) id 0LsOsW-1WcpCO1Oy8-0123LB; Fri, 11 Jul 2014 11:34:12 +0200
Message-ID: <53BFAF8F.2000109@gmx.net>
Date: Fri, 11 Jul 2014 11:34:07 +0200
From: Hannes Tschofenig <hannes.tschofenig@gmx.net>
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:24.0) Gecko/20100101 Thunderbird/24.6.0
MIME-Version: 1.0
To: Paul Lambert <paul@nymbus.net>
References: <53BCF608.5010606@gmx.net> <D7E5703D-792F-447E-9B23-0F676861902F@nymbus.net> <53BD0518.8060609@gmx.net> <1EFD8C56-BB56-4395-8DFB-B015606381F9@nymbus.net> <53BE4458.2090200@gmx.net> <BDA7B83A-C4D0-4AE5-8F78-C37A2B3A8C99@nymbus.net>
In-Reply-To: <BDA7B83A-C4D0-4AE5-8F78-C37A2B3A8C99@nymbus.net>
X-Enigmail-Version: 1.5.2
OpenPGP: id=4D776BC9
Content-Type: multipart/signed; micalg=pgp-sha512; protocol="application/pgp-signature"; boundary="tQ7F05ohsHCL13c316uPmV5mhdAakSDtG"
X-Provags-ID: V03:K0:kirQWtGYQa/5D20tBM+XBcMpNGaPFkdi72xtZt0q9boof+kjFjN TVzc2+Elx4p/Z1GJe43UqdJxesVwLVw5hIoUM5uCrhsQGF2pRm8TPV5Zv/FAtgldxkZd3mM cHY4yrf2scB1S7+0ytNNEnWw8uC+SQ+nVkhXgUXAiBj2wchMV827sV88HBmQdGn8qUHmtQ6 eLFnCl7F1lbpUOFA99xFQ==
Archived-At: http://mailarchive.ietf.org/arch/msg/ace/v7WWdz4xObiaxOVFqtwUgdAnjBQ
Cc: "ace@ietf.org" <ace@ietf.org>
Subject: Re: [Ace] Questions for the IETF#90 Meeting
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 11 Jul 2014 09:34:16 -0000

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--tQ7F05ohsHCL13c316uPmV5mhdAakSDtG
Content-Type: text/plain; charset=windows-1252
Content-Transfer-Encoding: quoted-printable

Hi Paul,

I believe our misunderstanding is based on the difference between roles
and physical boxes. The authorization server is a role and it can of
course be dumped into any physical box. As you explain below, it can be
combined with the client into a smart phone.

At least that's my reading of the current requirements.

Now, when you consider smart phones as clients then many of the
challenges disappear since smart phones are pretty sophisticated devices
and there is no need to optimize the last hack out of them.

In fact, this is something I noted when I wrote the OAuth IoT document
(which I recently submitted to the group). If you have a smart phone
than most of the ACE challenges disappear.

This might be something to double-check as we go through the use cases.

Ciao
Hannes


On 07/11/2014 12:56 AM, Paul Lambert wrote:
>=20
> Hannes,
>=20
>> On 07/09/2014 11:52 PM, Paul Lambert wrote:
>>> Wireless (e.g. Wi-Fi ) based direct connections from one device to an=
other.
>>> - between two smart phones
>>> - smart phone to headless device (e.g. hot water heater)
>>> Typically no Internet connection guaranteed to be available.
>>
>> As currently described in the use cases an initial interaction between=

>> the client and the authorization server would be needed to get the
>> protocol interaction working.
> Thank you for the clarification =85 that makes sense now rereading.
>=20
> I do have fundamental problems with the overall server centric=20
> framework, for example:
>=20
> "    U4.3.  Devices can access resources on other devices only if a
>       rule exists in the authorization server (default deny)."
> and
> "U4.5.  Devices may cache authorization rules locally.=94
>=20
> I do  not see why a server is required.  The authorization/policy infor=
mation
> required to make the decision might better be modeled as as
> a functional element in the RS.  The authorization information
> should be available locally to the RS, but could reach out to
> one or more servers in some implementions ions.
>=20
>> If there is only connectivity from the
>> client to the resource server and nothing else then this is currently
>> not covered by the use cases.
>=20
> If the RS is a Kerberos like system that uses symmetric key enrollment =

> you get one particular world view and set of capabilities.
>=20
> If the RS is not a symmetric key server, but a policy =91authority=92 (=
PA) that can sign
> authorization statements, you get a different set of potential topologi=
es
> and capabilities.
>=20
> This set of specifications quickly to a =91third party=92 server,
> and eliminates more dynamic and distributed models. These tend
> to drive the solution space to a factory pre configuration of
> devices with credentials of a RS.
>=20
> Having the =91authority=92 in my mobile device is my preferred use
> case.  Design overview:
>  - mobile device has loaded a =93configuration=94 app
>    Configuration Apps use common setup and authorization
>    protocols
>  - multiple devices from multiple vendors (supporting
>    this provisioning technology) can be managed by the app
>  - No factory provisioned are required
>    Devices come from multiple vendors that may not agree
>    on a single server or authorization authority
>    Devices may include factory installed information signed
>    by their facities
>  - Every device conforming to this methodolgy is authenticated
>    peer-to-peer using self generated public keys
>  - =91dumb=92 headless devices have a long term static public key=20
>    bound to label information to support secure initial pairing
>  - headless devices after initial pairing generate a new long
>    term key for authentication to other devices
>  - out-of-box, devices (C or RS in ACE model) must be
>    paired/setup by an Authority (in this example the mobile
>    device with pairing application)
>   - setup of a new device establishes the RA (as opposed
>     to RS) as the identity with authority to set policies
>     in the enrollee (C/RS). =20
>   - Access control is an Attribute based model where
>     attributes may be associated to a key.
>    Attributes of a key include it=92s =91id=92 (hash of
>    key, cipher suite id, type), and arbitrary tag/value
>     pairs.
>    - Typical assigned tags might include be =91group=92
>      (e.g.   group: foo)
>    - Configuration of end device (RS/C) by RA will
>      set local policy consisting of Attribute based
>      rules for actions (e.g. ACL of ids, group or other)
>   - RA can configure other devices (usually a smart
>     phone) to have some or all of the authority for
>     a name space.  This allows delegation and
>     support of multiple RAs
>   - Reset of headless devices consists of deleting
>     current public/private key pair.  Simple reset
>     is button on device.  Secure reset is by=20
>     authorized RA
>   - RA only needs to configure pair-wise to each
>     device once when using simple group
>     attribute policies.  Group membership
>     is indicated from device-to-device=20
>     without central server.  Group membership
>     is a tag/value assignment from RA to
>     C/RS signed by RA. =20
>    - where central monitoring/loggin required,=20
>      authorization decision could be based on
>     implementation of policy function as proxy to server
>   - public key replacement, backup, RA cloning is
>     handled by signed delegation of RA key to
>     another key to become RA
>=20
>=20
>=20
> Paul
>=20
>=20
>=20
>=20
>    =20
>=20
>=20
>=20
>=20
>>
>>
>>>
>>> The interesting part is the =93enrollment=94 which appears to be
>>> out-of-scope for this group.  The initial =91pairing=92 is effectivel=
y
>>> the AS function being introduced to a C or RS and providing
>>> initial configuration of policy (aka authorization information)
>>
>> The interaction between the client and the AS is within the scope. We
>> didn't call this enrollment though.
>>
>=20
> _______________________________________________
> Ace mailing list
> Ace@ietf.org
> https://www.ietf.org/mailman/listinfo/ace
>=20


--tQ7F05ohsHCL13c316uPmV5mhdAakSDtG
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
Content-Disposition: attachment; filename="signature.asc"

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1
Comment: GPGTools - http://gpgtools.org
Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/

iQEcBAEBCgAGBQJTv6+PAAoJEGhJURNOOiAt5EEIAJbA8OXsLjWpTci6BY1gRLoq
xJGgz6rJyztnUWMusinvnN5sVwrVrY4/tfm/k9ZbxypmC23c5MYqbWoifA81O6rA
lWe/wN2wMBxzZowPUAUKCBkQwXMmNwwye26pH5NqY3Zz0C0UNVis3kEQTN7+eRnF
oVD+Sr8Vs+pCCpR11pAB1t5Y9lg1R58Q8PJEL9Zu2wxokmLkHfPmN5+OWfvDtvxr
wDVusOuPr5VzB9MfKHB87WfemRH69WK8HFLLtdeE6ipklBb9CGCfGMeSS5dh3ASi
w7gaVwON2v2L8TT2NC5Mv61v0lAckwMBxt86+JpWiyfhDqBin3cN97gHIFocKFM=
=75CH
-----END PGP SIGNATURE-----

--tQ7F05ohsHCL13c316uPmV5mhdAakSDtG--


From nobody Mon Jul 14 01:46:45 2014
Return-Path: <hannes.tschofenig@gmx.net>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id ED7481A0046 for <ace@ietfa.amsl.com>; Mon, 14 Jul 2014 01:46:43 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.551
X-Spam-Level: 
X-Spam-Status: No, score=-1.551 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, FREEMAIL_FROM=0.001, J_BACKHAIR_22=1, RCVD_IN_DNSWL_NONE=-0.0001, RP_MATCHES_RCVD=-0.651, SPF_PASS=-0.001] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id DnUMP8BkAQ6Q for <ace@ietfa.amsl.com>; Mon, 14 Jul 2014 01:46:42 -0700 (PDT)
Received: from mout.gmx.net (mout.gmx.net [212.227.15.18]) (using TLSv1.2 with cipher DHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 32E4B1A0379 for <ace@ietf.org>; Mon, 14 Jul 2014 01:46:42 -0700 (PDT)
Received: from [172.16.254.119] ([80.92.116.212]) by mail.gmx.com (mrgmx003) with ESMTPSA (Nemesis) id 0M7YF5-1WKPRA3zCJ-00xGut for <ace@ietf.org>; Mon, 14 Jul 2014 10:46:40 +0200
Message-ID: <53C398ED.3030302@gmx.net>
Date: Mon, 14 Jul 2014 10:46:37 +0200
From: Hannes Tschofenig <hannes.tschofenig@gmx.net>
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:24.0) Gecko/20100101 Thunderbird/24.6.0
MIME-Version: 1.0
To: "ace@ietf.org" <ace@ietf.org>
X-Enigmail-Version: 1.5.2
OpenPGP: id=4D776BC9
Content-Type: multipart/signed; micalg=pgp-sha512; protocol="application/pgp-signature"; boundary="8Mg8Va63HxakgU6b7EoCAqJO9XxxQKHa2"
X-Provags-ID: V03:K0:+bnfW+GMql/R+agyONqCvsdAr6gjmPojuJZMBiVB5kEU8Ul1S7V FnUodWQIWgJ2B1uFu5Duc2fit07+CUPil4Q7LDPHbW9w9HPfYoVakfNEIj3mBQxXpoyrApq WI7qqmkTVlcW4cu1VlrOImnXcgZA4IsNGS8qMmsgNhCLzJUAUj9V7Yxw0VA9zNiwyHXrvWZ lvkYtGUqZ6ojaCfCxVMzg==
Archived-At: http://mailarchive.ietf.org/arch/msg/ace/aseLSnrzbsNNjlMw1KgIxr19Ugw
Subject: [Ace] Agenda
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 14 Jul 2014 08:46:44 -0000

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--8Mg8Va63HxakgU6b7EoCAqJO9XxxQKHa2
Content-Type: text/plain; charset=ISO-8859-1
Content-Transfer-Encoding: quoted-printable

Hi all,

Kepeng and I would like to thank you for the feedback on the list
regarding the agenda preparation. Below is our proposed agenda for the
meeting.

As you can see we have also made a few suggestions for discussion
leaders (who still need to confirm their willingness) and there are also
a couple of free spots as well. If you are willing to help out during
the meeting drop us a message.

Ciao
Hannes & Kepeng

------

Authentication and Authorization for Constrained Environments (ACE)

WEDNESDAY, July 23, 2014

0900-1130 EDT
Tudor 7/8 (MM)

- Welcome & Agenda Bashing (Chairs, 10 mins)

- ACE Introduction (Chairs, 10 mins)

Since this is the first meeting of the working group we would like to
give a brief description the high level goal of the group. This part of
the agenda should also help you to become familiar with the terminology.

- Design Directions

We want to spend the main meeting time to answer a couple of challenging
questions.
Our hope is it to get answers to some of these questions during the
meeting or in preparation of the meeting.

1) Problem Description

1a) Client <-> RS Communication: What transport should be used?
1b) What degree of flexibility should we aim for? DTLS or application
layer security?

[[Relevant document: draft-seitz-ace-problem-description-01]]

Discussion Leader: Ludwig (to-be-confirmed)

2) Design Patterns

2a) Is the OAuth/Kerberos design pattern sufficient?
(does it cover all the use cases)
2b) Is the OAUTH/Kerberos design pattern necessary?
(can we throw something away?)

[[Relevant document: draft-seitz-ace-usecases-01]]

Discussion Leader: Ludwig (to-be-confirmed)

3) Design Considerations

3a) What design components could we re-use?
3b) What areas need to be explored in more detail?

Example topics:

  * RS<->AS Communication: In scope / out of scope?
  * Protocol re-use: what's good and what's not?
  * Message encoding: Base64, JSON, ASN.1, CBOR

3c) Should the design be based on symmetric or asymmetric crypto?
  (or both?)

[[Relevant document: draft-seitz-ace-design-considerations-00]]

Discussion Leader: Goeran (to-be-confirmed)

4) Cross-domain Support

4a) How to address cross-domain support in the initial protocol design?
4b) What lessons from other areas can be taken into account?
4c) Do we need new terminology or can we re-use existing terms?

[[Relevant documents: draft-gerdes-ace-actors-01 and
draft-tschofenig-ace-overview-00]]

Discussion Leader: Carsten (to-be-confirmed)

- Summary and Next Steps (Chairs, 10 mins)


--8Mg8Va63HxakgU6b7EoCAqJO9XxxQKHa2
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
Content-Disposition: attachment; filename="signature.asc"

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1
Comment: GPGTools - http://gpgtools.org
Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/

iQEcBAEBCgAGBQJTw5jtAAoJEGhJURNOOiAtWB4IAIu1HKYXiDnyu3dGByDJzPfy
VKVP5QC5Oa/+KkzezvpQ6tWMIJU4sDbMKTuY9hg4rD8b0WSsfWt4ll7vVb1hFisJ
MBtKiOikLIAADfQXaBwm7Xeo3wz1YM1ssWKR81O8f5D+SkpV53I8EGexHKM0TzrB
iZUMSuv2jfu0o2VN3vmFl3CieBWittDiY0uRM480+uTa0AcBXA5HPqMz/ZpxaOmR
lt4DkhckeXv+DmO5bJRj5DVqnd7IWj+saGHmpsMqARWdo3wfQN7V700tZMpRz/KO
I+90Nq+ETYcdPRIIi+vCoL2Al7RgdVXn13aX0QFRGION4oNNmu8ti5OljbLLF1Q=
=x1U5
-----END PGP SIGNATURE-----

--8Mg8Va63HxakgU6b7EoCAqJO9XxxQKHa2--


From nobody Mon Jul 14 02:42:34 2014
Return-Path: <ludwig@sics.se>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 5BF031A0387 for <ace@ietfa.amsl.com>; Mon, 14 Jul 2014 02:42:23 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.901
X-Spam-Level: 
X-Spam-Status: No, score=-2.901 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HELO_EQ_SE=0.35, RCVD_IN_DNSWL_LOW=-0.7, RP_MATCHES_RCVD=-0.651] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id UXbiWxQetIrM for <ace@ietfa.amsl.com>; Mon, 14 Jul 2014 02:42:19 -0700 (PDT)
Received: from outbox.sics.se (outbox.sics.se [193.10.64.137]) by ietfa.amsl.com (Postfix) with ESMTP id 6E1871A0384 for <ace@ietf.org>; Mon, 14 Jul 2014 02:42:18 -0700 (PDT)
Received: from e-mailfilter01.sunet.se (e-mailfilter01.sunet.se [192.36.171.201]) by outbox.sics.se (Postfix) with ESMTPS id B65E711BA for <ace@ietf.org>; Mon, 14 Jul 2014 11:42:17 +0200 (CEST)
Received: from letter.sics.se (letter.sics.se [193.10.64.6]) by e-mailfilter01.sunet.se (8.14.4/8.14.4/Debian-4) with ESMTP id s6E9gH1R013709 for <ace@ietf.org>; Mon, 14 Jul 2014 11:42:17 +0200
Received: from [192.168.0.108] (unknown [85.235.11.178]) (Authenticated sender: ludwig@sics.se) by letter.sics.se (Postfix) with ESMTPSA id 8638A40116 for <ace@ietf.org>; Mon, 14 Jul 2014 11:42:17 +0200 (CEST)
Message-ID: <53C3A5F9.9010603@sics.se>
Date: Mon, 14 Jul 2014 11:42:17 +0200
From: Ludwig Seitz <ludwig@sics.se>
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:24.0) Gecko/20100101 Thunderbird/24.6.0
MIME-Version: 1.0
To: ace@ietf.org
References: <53BCF608.5010606@gmx.net> <D7E5703D-792F-447E-9B23-0F676861902F@nymbus.net> <53BD0518.8060609@gmx.net> <1EFD8C56-BB56-4395-8DFB-B015606381F9@nymbus.net> <53BE4458.2090200@gmx.net> <BDA7B83A-C4D0-4AE5-8F78-C37A2B3A8C99@nymbus.net>
In-Reply-To: <BDA7B83A-C4D0-4AE5-8F78-C37A2B3A8C99@nymbus.net>
Content-Type: multipart/signed; protocol="application/pkcs7-signature"; micalg=sha1; boundary="------------ms080203040304000505060801"
X-Bayes-Prob: 0.0001 (Score 0, tokens from: outbound, outbound-sics-se:default, sics-se:default, base:default, @@RPTN)
X-p0f-Info: os=Solaris 10, link=Ethernet or modem
X-CanIt-Geo: =?UTF-8?Q?ip=3D85.235.11.178; _country=3DSE; _region=3DSk=C3=A5ne; _city=3DLund; _latitude=3D55.7000; _longitude=3D13.1833; _http://maps.google.com/maps=3Fq=3D55.7000,13.1833&z=3D6?=
X-CanItPRO-Stream: outbound-sics-se:outbound (inherits from outbound-sics-se:default, sics-se:default, base:default)
X-Canit-Stats-ID: 09Mq9GhI9 - a4d8019d45f7 - 20140714
X-Antispam-Training-Forget: https://canit.sunet.se/canit/b.php?i=09Mq9GhI9&m=a4d8019d45f7&t=20140714&c=f
X-Antispam-Training-Nonspam: https://canit.sunet.se/canit/b.php?i=09Mq9GhI9&m=a4d8019d45f7&t=20140714&c=n
X-Antispam-Training-Spam: https://canit.sunet.se/canit/b.php?i=09Mq9GhI9&m=a4d8019d45f7&t=20140714&c=s
X-CanIt-Archive-Cluster: PfMRe/vJWMiXwM2YIH5BVExnUnw
X-Scanned-By: CanIt (www . roaringpenguin . com) on 192.36.171.201
Archived-At: http://mailarchive.ietf.org/arch/msg/ace/gbaGERhmj6N2BITFTqisJpwHVXE
Subject: Re: [Ace] Questions for the IETF#90 Meeting
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 14 Jul 2014 09:42:23 -0000

This is a cryptographically signed message in MIME format.

--------------ms080203040304000505060801
Content-Type: text/plain; charset=windows-1252; format=flowed
Content-Transfer-Encoding: quoted-printable

On 07/11/2014 12:56 AM, Paul Lambert wrote:
>
> Hannes,
>
>> On 07/09/2014 11:52 PM, Paul Lambert wrote:
>>> Wireless (e.g. Wi-Fi ) based direct connections from one device to an=
other.
>>> - between two smart phones
>>> - smart phone to headless device (e.g. hot water heater)
>>> Typically no Internet connection guaranteed to be available.
>>
>> As currently described in the use cases an initial interaction between=

>> the client and the authorization server would be needed to get the
>> protocol interaction working.
> Thank you for the clarification =85 that makes sense now rereading.
>
> I do have fundamental problems with the overall server centric
> framework, for example:
>
> "    U4.3.  Devices can access resources on other devices only if a
>        rule exists in the authorization server (default deny)."
> and
> "U4.5.  Devices may cache authorization rules locally.=94
>
> I do  not see why a server is required.  The authorization/policy infor=
mation
> required to make the decision might better be modeled as as
> a functional element in the RS.  The authorization information
> should be available locally to the RS, but could reach out to
> one or more servers in some implementions ions.
>

Citing from draft-seitz-ace-problem-description-01:

    Finally we also assume that in a significant number of cases, the
    server and/or the client are too constrained to handle the
    authorization policies and related configuration on their own.  Many
    authorization solutions involve a centralized, trusted third party,
    supporting the client and/or resource server.  A trusted third party
    provides a more scalable way to centrally manage authorization
    policies, in order to ensure consistent authorization decisions.  The=

    physical separation of policy decision and policy enforcement is an
    established principle in policy based management, e.g. [RFC2748].


To be a bit more specific:

* In many cases evaluating authorization policies (not simple ACLs) will =

require network lookups (e.g. checking client attributes in an identity=20
provider database). This kind of processing is too expensive for=20
constrained devices in terms of delay time and, for battery powered=20
devices, energy consumption.

* You typically want to manage authorization policies centrally in order =

to keep a consistent picture of their current state.

* You also typically want to centralize authorization decisions in order =

to generate complete audit logs.

* If authorization policies change frequently you want to avoid having=20
to provision each of these updates to all the affected resource servers.

Note the separation of policy decisions and policy enforcement here. The =

Authorization Server is expected to do decisions, while the RS does=20
enforcement.

I hope that clarifies things a bit.

/Ludwig


--=20
Ludwig Seitz, PhD
SICS Swedish ICT AB
Ideon Science Park
Building Beta 2
Scheelev=E4gen 17
SE-223 70 Lund

Phone +46(0)70-349 92 51
http://www.sics.se


--------------ms080203040304000505060801
Content-Type: application/pkcs7-signature; name="smime.p7s"
Content-Transfer-Encoding: base64
Content-Disposition: attachment; filename="smime.p7s"
Content-Description: S/MIME Cryptographic Signature

MIAGCSqGSIb3DQEHAqCAMIACAQExCzAJBgUrDgMCGgUAMIAGCSqGSIb3DQEHAQAAoIIMVDCC
BhgwggUAoAMCAQICAwiRTjANBgkqhkiG9w0BAQsFADCBjDELMAkGA1UEBhMCSUwxFjAUBgNV
BAoTDVN0YXJ0Q29tIEx0ZC4xKzApBgNVBAsTIlNlY3VyZSBEaWdpdGFsIENlcnRpZmljYXRl
IFNpZ25pbmcxODA2BgNVBAMTL1N0YXJ0Q29tIENsYXNzIDEgUHJpbWFyeSBJbnRlcm1lZGlh
dGUgQ2xpZW50IENBMB4XDTE0MDEwNzA3MjgzNVoXDTE1MDEwNzEyNTgyMlowODEXMBUGA1UE
AwwObHVkd2lnQHNpY3Muc2UxHTAbBgkqhkiG9w0BCQEWDmx1ZHdpZ0BzaWNzLnNlMIIBIjAN
BgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAnLm1tc30QxHa9wtdVjC3NgxjLJicnccm0HD+
1X16kPMKGvwps8F1oDhYn7jXIe46p1AuJMzLK0GIioE4JwxCFGdvpz7cg2xyTyrdBVUzSqez
Dfqt4FOJq6hrdrIMS8MHEzl7Jk02gv9cTn/pHQvDpkiThRpbSLU5mlMqtEQ8gDQY5YyBX0Mv
5qculV08I2JU8HEeTt1oeqhvBImgQfOVYMDatHlWHUVVrmYd6iIo+cuiUGd5kiA0XuaLYX0E
oCoao/z5Wg9U0sQlx0hl4r96Q+NdoZZ1prfts3qtyBzJ2hu135aikigzJ6sueWHv/jbISUek
tOMm0xkx1GOqqWtEAwIDAQABo4IC1DCCAtAwCQYDVR0TBAIwADALBgNVHQ8EBAMCBLAwHQYD
VR0lBBYwFAYIKwYBBQUHAwIGCCsGAQUFBwMEMB0GA1UdDgQWBBRZmjjBh8N3klra+mVQgC00
pl68ZTAfBgNVHSMEGDAWgBRTcu2SnODaywFcfH6WNU7y1LhRgjAZBgNVHREEEjAQgQ5sdWR3
aWdAc2ljcy5zZTCCAUwGA1UdIASCAUMwggE/MIIBOwYLKwYBBAGBtTcBAgMwggEqMC4GCCsG
AQUFBwIBFiJodHRwOi8vd3d3LnN0YXJ0c3NsLmNvbS9wb2xpY3kucGRmMIH3BggrBgEFBQcC
AjCB6jAnFiBTdGFydENvbSBDZXJ0aWZpY2F0aW9uIEF1dGhvcml0eTADAgEBGoG+VGhpcyBj
ZXJ0aWZpY2F0ZSB3YXMgaXNzdWVkIGFjY29yZGluZyB0byB0aGUgQ2xhc3MgMSBWYWxpZGF0
aW9uIHJlcXVpcmVtZW50cyBvZiB0aGUgU3RhcnRDb20gQ0EgcG9saWN5LCByZWxpYW5jZSBv
bmx5IGZvciB0aGUgaW50ZW5kZWQgcHVycG9zZSBpbiBjb21wbGlhbmNlIG9mIHRoZSByZWx5
aW5nIHBhcnR5IG9ibGlnYXRpb25zLjA2BgNVHR8ELzAtMCugKaAnhiVodHRwOi8vY3JsLnN0
YXJ0c3NsLmNvbS9jcnR1MS1jcmwuY3JsMIGOBggrBgEFBQcBAQSBgTB/MDkGCCsGAQUFBzAB
hi1odHRwOi8vb2NzcC5zdGFydHNzbC5jb20vc3ViL2NsYXNzMS9jbGllbnQvY2EwQgYIKwYB
BQUHMAKGNmh0dHA6Ly9haWEuc3RhcnRzc2wuY29tL2NlcnRzL3N1Yi5jbGFzczEuY2xpZW50
LmNhLmNydDAjBgNVHRIEHDAahhhodHRwOi8vd3d3LnN0YXJ0c3NsLmNvbS8wDQYJKoZIhvcN
AQELBQADggEBAHqEYmtWr83S+iLXE97KBnHJZiMr6PMuLKxmh0o6UJJwKgf+KTP2czxRnPSI
+whuqfQZdmz6g3A2K8AooMU0RXrzncnX1c4826APdnXkRxnGQxtZXI1wuhPn4z7iDKZ6ij9u
K5Pfn10JL/ERDig2qJQbqvhtIAx0RY7y7r+hLMvgXVq9mf3WRJYmGQeFW+N9t5Z1eEwG4m9R
KAZm0fnfeDn/Ai4kmxTckBH7dZwW2lTtwQqQ4su+PGCJ0e9ndBLpvTqaYGSAl+L7PO7vxPhS
/cS67Xa6BtnYJLTr3MaGXaN+CEUFSfwQHa9DKcAqh3kldErI3kCvnot0CigBl4aILOEwggY0
MIIEHKADAgECAgEeMA0GCSqGSIb3DQEBBQUAMH0xCzAJBgNVBAYTAklMMRYwFAYDVQQKEw1T
dGFydENvbSBMdGQuMSswKQYDVQQLEyJTZWN1cmUgRGlnaXRhbCBDZXJ0aWZpY2F0ZSBTaWdu
aW5nMSkwJwYDVQQDEyBTdGFydENvbSBDZXJ0aWZpY2F0aW9uIEF1dGhvcml0eTAeFw0wNzEw
MjQyMTAxNTVaFw0xNzEwMjQyMTAxNTVaMIGMMQswCQYDVQQGEwJJTDEWMBQGA1UEChMNU3Rh
cnRDb20gTHRkLjErMCkGA1UECxMiU2VjdXJlIERpZ2l0YWwgQ2VydGlmaWNhdGUgU2lnbmlu
ZzE4MDYGA1UEAxMvU3RhcnRDb20gQ2xhc3MgMSBQcmltYXJ5IEludGVybWVkaWF0ZSBDbGll
bnQgQ0EwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDHCYPMzi3YGrEppC4Tq5a+
ijKDjKaIQZZVR63UbxIP6uq/I0fhCu+cQhoUfE6ERKKnu8zPf1Jwuk0tsvVCk6U9b+0UjM0d
Lep3ZdE1gblK/1FwYT5Pipsu2yOMluLqwvsuz9/9f1+1PKHG/FaR/wpbfuIqu54qzHDYeqiU
fsYzoVflR80DAC7hmJ+SmZnNTWyUGHJbBpA8Q89lGxahNvuryGaC/o2/ceD2uYDX9U8Eg5Dp
IpGQdcbQeGarV04WgAUjjXX5r/2dabmtxWMZwhZna//jdiSyrrSMTGKkDiXm6/3/4ebfeZuC
YKzN2P8O2F/Xe2AC/Y7zeEsnR7FOp+uXAgMBAAGjggGtMIIBqTAPBgNVHRMBAf8EBTADAQH/
MA4GA1UdDwEB/wQEAwIBBjAdBgNVHQ4EFgQUU3Ltkpzg2ssBXHx+ljVO8tS4UYIwHwYDVR0j
BBgwFoAUTgvvGqRAW6UXaYcwyjRoQ9BBrvIwZgYIKwYBBQUHAQEEWjBYMCcGCCsGAQUFBzAB
hhtodHRwOi8vb2NzcC5zdGFydHNzbC5jb20vY2EwLQYIKwYBBQUHMAKGIWh0dHA6Ly93d3cu
c3RhcnRzc2wuY29tL3Nmc2NhLmNydDBbBgNVHR8EVDBSMCegJaAjhiFodHRwOi8vd3d3LnN0
YXJ0c3NsLmNvbS9zZnNjYS5jcmwwJ6AloCOGIWh0dHA6Ly9jcmwuc3RhcnRzc2wuY29tL3Nm
c2NhLmNybDCBgAYDVR0gBHkwdzB1BgsrBgEEAYG1NwECATBmMC4GCCsGAQUFBwIBFiJodHRw
Oi8vd3d3LnN0YXJ0c3NsLmNvbS9wb2xpY3kucGRmMDQGCCsGAQUFBwIBFihodHRwOi8vd3d3
LnN0YXJ0c3NsLmNvbS9pbnRlcm1lZGlhdGUucGRmMA0GCSqGSIb3DQEBBQUAA4ICAQAKgwh9
eKssBly4Y4xerhy5I3dNoXHYfYa8PlVLL/qtXnkFgdtY1o95CfegFJTwqBBmf8pyTUnFsukD
FUI22zF5bVHzuJ+GxhnSqN2sD1qetbYwBYK2iyYA5Pg7Er1A+hKMIzEzcduRkIMmCeUTyMyi
kfbUFvIBivtvkR8ZFAk22BZy+pJfAoedO61HTz4qSfQoCRcLN5A0t4DkuVhTMXIzuQ8Cnykh
ExD6x4e6ebIbrjZLb7L+ocR0y4YjCl/Pd4MXU91y0vTipgr/O75CDUHDRHCCKBVmz/Rzkc/b
970MEeHt5LC3NiWTgBSvrLEuVzBKM586YoRD9Dy3OHQgWI270g+5MYA8GfgI/EPT5G7xPbCD
z+zjdH89PeR3U4So4lSXur6H6vp+m9TQXPF3a0LwZrp8MQ+Z77U1uL7TelWO5lApsbAonrqA
SfTpaprFVkL4nyGH+NHST2ZJPWIBk81i6Vw0ny0qZW2Niy/QvVNKbb43A43ny076khXO7cNb
BIRdJ/6qQNq9Bqb5C0Q5nEsFcj75oxQRqlKf6TcvGbjxkJh8BYtv9ePsXklAxtm8J7GCUBth
HSQgepbkOexhJ0wP8imUkyiPHQ0GvEnd83129fZjoEhdGwXV27ioRKbj/cIq7JRXun0NbeY+
UdMYu9jGfIpDLtUUGSgsg2zMGs5R4jGCA90wggPZAgEBMIGUMIGMMQswCQYDVQQGEwJJTDEW
MBQGA1UEChMNU3RhcnRDb20gTHRkLjErMCkGA1UECxMiU2VjdXJlIERpZ2l0YWwgQ2VydGlm
aWNhdGUgU2lnbmluZzE4MDYGA1UEAxMvU3RhcnRDb20gQ2xhc3MgMSBQcmltYXJ5IEludGVy
bWVkaWF0ZSBDbGllbnQgQ0ECAwiRTjAJBgUrDgMCGgUAoIICHTAYBgkqhkiG9w0BCQMxCwYJ
KoZIhvcNAQcBMBwGCSqGSIb3DQEJBTEPFw0xNDA3MTQwOTQyMTdaMCMGCSqGSIb3DQEJBDEW
BBTWDguzrbMxPM0xWEsB7bLntZSqWjBsBgkqhkiG9w0BCQ8xXzBdMAsGCWCGSAFlAwQBKjAL
BglghkgBZQMEAQIwCgYIKoZIhvcNAwcwDgYIKoZIhvcNAwICAgCAMA0GCCqGSIb3DQMCAgFA
MAcGBSsOAwIHMA0GCCqGSIb3DQMCAgEoMIGlBgkrBgEEAYI3EAQxgZcwgZQwgYwxCzAJBgNV
BAYTAklMMRYwFAYDVQQKEw1TdGFydENvbSBMdGQuMSswKQYDVQQLEyJTZWN1cmUgRGlnaXRh
bCBDZXJ0aWZpY2F0ZSBTaWduaW5nMTgwNgYDVQQDEy9TdGFydENvbSBDbGFzcyAxIFByaW1h
cnkgSW50ZXJtZWRpYXRlIENsaWVudCBDQQIDCJFOMIGnBgsqhkiG9w0BCRACCzGBl6CBlDCB
jDELMAkGA1UEBhMCSUwxFjAUBgNVBAoTDVN0YXJ0Q29tIEx0ZC4xKzApBgNVBAsTIlNlY3Vy
ZSBEaWdpdGFsIENlcnRpZmljYXRlIFNpZ25pbmcxODA2BgNVBAMTL1N0YXJ0Q29tIENsYXNz
IDEgUHJpbWFyeSBJbnRlcm1lZGlhdGUgQ2xpZW50IENBAgMIkU4wDQYJKoZIhvcNAQEBBQAE
ggEAByHbl7krh02kJySPse9tNSpe0N+MFRweWtEwOeazKki4Jg0JQkNP8lfWbexLAu49/J7C
rxq+jKYDUy5ZjgIqU222NDhReSZ0MCYwzSP2CvWYq7GVPxIRt4HWZRFtv4OKSFVb2PAh575k
F5FfLnsSrRudEaGxIUgKENVWZ6zVfo6eQ2s9vaaLCxG0L0xZ04BU8VfHnb5W+SkzasM/pIhv
9y2rXGA1vgaPk/Z8BJnlTvbfoTjskTY1s99nl8MnLbBNVHjYYUuSQF1XleCBS6N5CkPlrS9z
xE67vi8NxPPI+yBmJAMh5VdsQT5eW6kpEDvtPRZr11qnc00JYccAriPsrAAAAAAAAA==
--------------ms080203040304000505060801--


From nobody Mon Jul 14 04:36:02 2014
Return-Path: <hannes.tschofenig@gmx.net>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 7FE181A038C for <ace@ietfa.amsl.com>; Mon, 14 Jul 2014 04:36:00 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.551
X-Spam-Level: 
X-Spam-Status: No, score=-2.551 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, FREEMAIL_FROM=0.001, RCVD_IN_DNSWL_NONE=-0.0001, RP_MATCHES_RCVD=-0.651, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id QqUf35U33lbD for <ace@ietfa.amsl.com>; Mon, 14 Jul 2014 04:35:59 -0700 (PDT)
Received: from mout.gmx.net (mout.gmx.net [212.227.15.19]) (using TLSv1.2 with cipher DHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 0C93D1A038B for <ace@ietf.org>; Mon, 14 Jul 2014 04:35:59 -0700 (PDT)
Received: from [172.16.254.119] ([80.92.116.212]) by mail.gmx.com (mrgmx001) with ESMTPSA (Nemesis) id 0MbOoG-1Wq5dJ06sO-00IpF3 for <ace@ietf.org>; Mon, 14 Jul 2014 13:35:57 +0200
Message-ID: <53C3C09A.5090707@gmx.net>
Date: Mon, 14 Jul 2014 13:35:54 +0200
From: Hannes Tschofenig <hannes.tschofenig@gmx.net>
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:24.0) Gecko/20100101 Thunderbird/24.6.0
MIME-Version: 1.0
To: "ace@ietf.org" <ace@ietf.org>
X-Enigmail-Version: 1.5.2
OpenPGP: id=4D776BC9
Content-Type: multipart/signed; micalg=pgp-sha512; protocol="application/pgp-signature"; boundary="vfxMpjiWEtW4tDN4pDgX4Lf8tjjvXxFLd"
X-Provags-ID: V03:K0:1wD9z4E4Zo2VtfNHgaeEy7hRVETD4Jk2hP5X0ILIfU0IlKqMycH c15aRfWsLDjCP/74sEOGrW//9s4vz5apN0k9aVxEJf2Ecme1jyGmLR6LjHyuXwdIPWe0n+D FJ/mez5uEumi9KUoJJb/x4aRM4YPy1oMLi2rDEawmNPwEqBLrc+yG2Ds25RuPCDKag2yabT VoRxyS0+J7ndMmQR6Z8MQ==
Archived-At: http://mailarchive.ietf.org/arch/msg/ace/nhHV_3FOUJ85nRz0-I0BFxIiYWA
Subject: [Ace] Offline operation of Resource Server
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 14 Jul 2014 11:36:00 -0000

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--vfxMpjiWEtW4tDN4pDgX4Lf8tjjvXxFLd
Content-Type: text/plain; charset=ISO-8859-1
Content-Transfer-Encoding: quoted-printable

Hi all,

in one of my previous mail I said that the requirements rule out an
EAP/AAA solution and this impression was based on reading the following
requirement from http://tools.ietf.org/html/draft-seitz-ace-usecases-01

"
   o  U5.2 The meters must be able to perform fine-grained access
      control on the metering data and on the configuration while being
      offline.
"

I was wondering how strong the requirement for not having a real-time
interaction between the resource server and the AS is.

Ciao
Hannes


--vfxMpjiWEtW4tDN4pDgX4Lf8tjjvXxFLd
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
Content-Disposition: attachment; filename="signature.asc"

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1
Comment: GPGTools - http://gpgtools.org
Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/

iQEcBAEBCgAGBQJTw8CaAAoJEGhJURNOOiAtXtwH/R5sjFd2Xxp7wm8KgVJ9QDNr
KiXWGZyEKyGeWoHcEkbDDlIbwcYeADiDPBOx9pYcmgPgPZirCh86BBrZO0A7Ayuo
yn3KYFxqr1ucksSUwA5mMJ2NNSghFz2FXbYX+et/28kZLXP+uauo7bHG85XoY0o6
FxIcCeyU9qXA9P/lxd1IF3Sp5hY2LT4MRtl7Pvwg+GCRtwt4zLvkn/QEBY9JFxkX
hiCZmE0tHR3KxjVly9VcXRS4yBlUtRIqzV+uDAAfkl+1Ni4uMJKR89pWtnuta2i2
JvhYJYghWiuSvf2s3+yug73Iru5QUsBuPlQa0eiP9iiuVIAZ5bs4MhaeRNW6Orc=
=uwLQ
-----END PGP SIGNATURE-----

--vfxMpjiWEtW4tDN4pDgX4Lf8tjjvXxFLd--


From nobody Mon Jul 14 04:43:31 2014
Return-Path: <Josh.Howlett@ja.net>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id CA4541A0392 for <ace@ietfa.amsl.com>; Mon, 14 Jul 2014 04:43:30 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.9
X-Spam-Level: 
X-Spam-Status: No, score=-1.9 tagged_above=-999 required=5 tests=[BAYES_00=-1.9] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id kyVRFey4Rfa2 for <ace@ietfa.amsl.com>; Mon, 14 Jul 2014 04:43:29 -0700 (PDT)
Received: from egw002.ukerna.ac.uk (egw002.ukerna.ac.uk [194.81.3.65]) (using TLSv1 with cipher DHE-RSA-CAMELLIA256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id DDD711A038B for <ace@ietf.org>; Mon, 14 Jul 2014 04:43:28 -0700 (PDT)
Received: from egw002.ukerna.ac.uk (localhost.localdomain [127.0.0.1]) by localhost (Email Security Appliance) with SMTP id 8F16E20C72F3_3C3C25DB; Mon, 14 Jul 2014 11:43:25 +0000 (GMT)
Received: from EXC001.atlas.ukerna.ac.uk (exc001.atlas.ukerna.ac.uk [193.62.83.37]) (using TLSv1 with cipher AES128-SHA (128/128 bits)) (Client CN "staffmail.ja.net", Issuer "TERENA SSL CA" (verified OK)) by egw002.ukerna.ac.uk (Sophos Email Appliance) with ESMTPS id 5711720C7294_3C3C25DF; Mon, 14 Jul 2014 11:43:25 +0000 (GMT)
Received: from EXC001.atlas.ukerna.ac.uk ([193.62.83.37]) by EXC001 ([193.62.83.37]) with mapi id 14.03.0123.003; Mon, 14 Jul 2014 12:43:24 +0100
From: Josh Howlett <Josh.Howlett@ja.net>
To: Hannes Tschofenig <hannes.tschofenig@gmx.net>, "ace@ietf.org" <ace@ietf.org>
Thread-Topic: [Ace] Offline operation of Resource Server
Thread-Index: AQHPn1fV6K8ZA6zXCka9YC7ZCL7945ufcWew
Date: Mon, 14 Jul 2014 11:43:24 +0000
Message-ID: <55DC663C2F4F9F439F23543E0078E8B3A678C284@EXC001>
References: <53C3C09A.5090707@gmx.net>
In-Reply-To: <53C3C09A.5090707@gmx.net>
Accept-Language: en-GB, en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
x-originating-ip: [194.82.140.76]
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
Archived-At: http://mailarchive.ietf.org/arch/msg/ace/RNz-E_muD45fGauWIxKeJRSsZvM
Subject: Re: [Ace] Offline operation of Resource Server
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 14 Jul 2014 11:43:30 -0000

A strict requirement for offline operation need not necessarily exclude an =
AAA/EAP solution. It is perfectly possible, for example, to use GSS EAP pre=
-authentication to obtain a Kerberos ticket from a KDC. There is running co=
de.

Josh.

> -----Original Message-----
> From: Ace [mailto:ace-bounces@ietf.org] On Behalf Of Hannes Tschofenig
> Sent: 14 July 2014 12:36
> To: ace@ietf.org
> Subject: [Ace] Offline operation of Resource Server
>=20
> Hi all,
>=20
> in one of my previous mail I said that the requirements rule out an EAP/A=
AA
> solution and this impression was based on reading the following
> requirement from http://tools.ietf.org/html/draft-seitz-ace-usecases-01
>=20
> "
>    o  U5.2 The meters must be able to perform fine-grained access
>       control on the metering data and on the configuration while being
>       offline.
> "
>=20
> I was wondering how strong the requirement for not having a real-time
> interaction between the resource server and the AS is.
>=20
> Ciao
> Hannes


Janet(UK) is a trading name of Jisc Collections and Janet Limited, a=20
not-for-profit company which is registered in England under No. 2881024=20
and whose Registered Office is at Lumen House, Library Avenue,
Harwell Oxford, Didcot, Oxfordshire. OX11 0SG. VAT No. 614944238


From nobody Mon Jul 14 04:44:41 2014
Return-Path: <hannes.tschofenig@gmx.net>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id B6E4D1A0398 for <ace@ietfa.amsl.com>; Mon, 14 Jul 2014 04:44:40 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.551
X-Spam-Level: 
X-Spam-Status: No, score=-2.551 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, FREEMAIL_FROM=0.001, RCVD_IN_DNSWL_NONE=-0.0001, RP_MATCHES_RCVD=-0.651, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 80vIcLK74nQ2 for <ace@ietfa.amsl.com>; Mon, 14 Jul 2014 04:44:38 -0700 (PDT)
Received: from mout.gmx.net (mout.gmx.net [212.227.15.18]) (using TLSv1.2 with cipher DHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 7DB331A0392 for <ace@ietf.org>; Mon, 14 Jul 2014 04:44:38 -0700 (PDT)
Received: from [172.16.254.119] ([80.92.116.212]) by mail.gmx.com (mrgmx002) with ESMTPSA (Nemesis) id 0MNYxW-1XCjEG3K3e-0079Hd; Mon, 14 Jul 2014 13:44:34 +0200
Message-ID: <53C3C2A0.9000200@gmx.net>
Date: Mon, 14 Jul 2014 13:44:32 +0200
From: Hannes Tschofenig <hannes.tschofenig@gmx.net>
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:24.0) Gecko/20100101 Thunderbird/24.6.0
MIME-Version: 1.0
To: Josh Howlett <Josh.Howlett@ja.net>, "ace@ietf.org" <ace@ietf.org>
References: <53C3C09A.5090707@gmx.net> <55DC663C2F4F9F439F23543E0078E8B3A678C284@EXC001>
In-Reply-To: <55DC663C2F4F9F439F23543E0078E8B3A678C284@EXC001>
X-Enigmail-Version: 1.5.2
OpenPGP: id=4D776BC9
Content-Type: multipart/signed; micalg=pgp-sha512; protocol="application/pgp-signature"; boundary="jbs9dhmWDSCb3oaK7IdoLHSS28LWgKiLw"
X-Provags-ID: V03:K0:EeJbG65ekV6wDrsmIguzUheXcGnVKh3RcUCNZuclNQ8BsXZKBn7 k5q0l7aWQv48otGyeBwlEqH/yI3iwUQrhwJ59vCkAafcNLEXjPZMSSJT5P8Jxp22IVdzOtd Pk3rs14Hn6/yxu3qYSzDqmzkAQB0BGlu4aN+o+dIO5hSaI3j1R9F/FY7ROW4FAFrPp72W/s 6nMTMVBMnSXyGD8RWzSRA==
Archived-At: http://mailarchive.ietf.org/arch/msg/ace/qIwk4X5whWe1DxVC7mHuyJLOxWM
Subject: Re: [Ace] Offline operation of Resource Server
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 14 Jul 2014 11:44:40 -0000

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--jbs9dhmWDSCb3oaK7IdoLHSS28LWgKiLw
Content-Type: text/plain; charset=ISO-8859-1
Content-Transfer-Encoding: quoted-printable

Interesting point, Josh.

On 07/14/2014 01:43 PM, Josh Howlett wrote:
> A strict requirement for offline operation need not necessarily
> exclude an AAA/EAP solution. It is perfectly possible, for example,
> to use GSS EAP pre-authentication to obtain a Kerberos ticket from a
> KDC. There is running code.


--jbs9dhmWDSCb3oaK7IdoLHSS28LWgKiLw
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
Content-Disposition: attachment; filename="signature.asc"

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1
Comment: GPGTools - http://gpgtools.org
Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/

iQEcBAEBCgAGBQJTw8KgAAoJEGhJURNOOiAt/YEIAJ3k1KUs3Kk22k/cspaazSYU
NVHoeP9mOoBB86wZpHlsCRMUT1totZhxmVomSKnYpyG71xPr8hftUy3pvUHSDvSl
R7pgrb5t0OMXp9judytuqfmTWN3XI9rn8Ycn5I/b1dw0Pk1LjUGhMMyfT/BuE1zT
KaGnm0q2a8FOsuusskumjPsaN6wEJQMNjWjUIc4MyYOI+jn9R/VDCG/CHgmHUisY
oDjRhsY75M/3X9YXmD6cN8e4olDEUsUo/x7rJUXSQAC6MYINiDunq7TeZdwzSg5X
IWPSTUf5Ax4slvF8fOp4BrT4bvtq7om0ISOs6+5QKI2fdBWALc2Vynm1bQ7hkdM=
=pUjP
-----END PGP SIGNATURE-----

--jbs9dhmWDSCb3oaK7IdoLHSS28LWgKiLw--


From nobody Mon Jul 14 05:07:35 2014
Return-Path: <rafa@um.es>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 48FD41A0395 for <ace@ietfa.amsl.com>; Mon, 14 Jul 2014 05:07:33 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.852
X-Spam-Level: 
X-Spam-Status: No, score=-4.852 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, RP_MATCHES_RCVD=-0.651, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 4l8_gBCdiKwj for <ace@ietfa.amsl.com>; Mon, 14 Jul 2014 05:07:29 -0700 (PDT)
Received: from xenon24.um.es (xenon24.um.es [155.54.212.164]) by ietfa.amsl.com (Postfix) with ESMTP id B0A2A1A03B8 for <ace@ietf.org>; Mon, 14 Jul 2014 05:07:28 -0700 (PDT)
Received: from localhost (localhost [127.0.0.1]) by xenon24.um.es (Postfix) with ESMTP id 6241910E4; Mon, 14 Jul 2014 14:07:26 +0200 (CEST)
X-Virus-Scanned: by antispam in UMU at xenon24.um.es
Received: from xenon24.um.es ([127.0.0.1]) by localhost (xenon24.um.es [127.0.0.1]) (amavisd-new, port 10024) with LMTP id j7fiW3dXG8ui; Mon, 14 Jul 2014 14:07:26 +0200 (CEST)
Received: from inf-205-191.inf.um.es (inf-205-191.inf.um.es [155.54.205.191]) (using TLSv1 with cipher ECDHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) (Authenticated sender: rafa) by xenon24.um.es (Postfix) with ESMTPSA id DDFD5297; Mon, 14 Jul 2014 14:07:24 +0200 (CEST)
Content-Type: text/plain; charset=iso-8859-1
Mime-Version: 1.0 (Mac OS X Mail 7.3 \(1878.6\))
From: Rafa Marin Lopez <rafa@um.es>
In-Reply-To: <53C3C2A0.9000200@gmx.net>
Date: Mon, 14 Jul 2014 14:07:24 +0200
Content-Transfer-Encoding: quoted-printable
Message-Id: <B66C3D02-A3A0-4DCE-83A2-DFDA274D1AE3@um.es>
References: <53C3C09A.5090707@gmx.net> <55DC663C2F4F9F439F23543E0078E8B3A678C284@EXC001> <53C3C2A0.9000200@gmx.net>
To: Hannes Tschofenig <hannes.tschofenig@gmx.net>
X-Mailer: Apple Mail (2.1878.6)
Archived-At: http://mailarchive.ietf.org/arch/msg/ace/j9LzHqlM-7qnveUNsTOFZZ_D0OE
Cc: Josh Howlett <Josh.Howlett@ja.net>, Rafa Marin Lopez <rafa@um.es>, "ace@ietf.org" <ace@ietf.org>
Subject: Re: [Ace] Offline operation of Resource Server
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 14 Jul 2014 12:07:33 -0000

+1.

That is what we had also in mind with our EAP/AAA solution (for =
bootstrapping). In fact, although not in the context of IoT, UMU has =
been working in bootstrapping Kerberos with EAP/AAA authentication. We =
think some of the ideas could be still applicable here. As Josh =
mentioned we have running code.

Best Regards.


- Rafael Marin-Lopez, Fernando Pereniguez, Gabriel Lopez, and Alejandro
Perez-Mendez. Providing EAP-based Kerberos pre-authentication and
advanced authorization for network federations. Computer Standard &
Interfaces, 33(5):494-504, 2011.

- Alejandro Perez-Mendez, Fernando Pereniguez-Garcia, Rafael =
Marin-Lopez, and
Gabriel Lopez-Millan. Out-of-band federated authentication for Kerberos
based on PANA. Elsevier Computer Communications, 36(14):1527 1538, 2013.


El 14/07/2014, a las 13:44, Hannes Tschofenig =
<hannes.tschofenig@gmx.net> escribi=F3:

> Interesting point, Josh.
>=20
> On 07/14/2014 01:43 PM, Josh Howlett wrote:
>> A strict requirement for offline operation need not necessarily
>> exclude an AAA/EAP solution. It is perfectly possible, for example,
>> to use GSS EAP pre-authentication to obtain a Kerberos ticket from a
>> KDC. There is running code.
>=20
> _______________________________________________
> Ace mailing list
> Ace@ietf.org
> https://www.ietf.org/mailman/listinfo/ace

-------------------------------------------------------
Rafael Marin Lopez, PhD
Dept. Information and Communications Engineering (DIIC)
Faculty of Computer Science-University of Murcia
30100 Murcia - Spain
Telf: +34868888501 Fax: +34868884151 e-mail: rafa@um.es
-------------------------------------------------------





From nobody Mon Jul 14 05:37:00 2014
Return-Path: <robert.cragie@gridmerge.com>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 17FCB1A03C8 for <ace@ietfa.amsl.com>; Mon, 14 Jul 2014 05:36:55 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.899
X-Spam-Level: 
X-Spam-Status: No, score=-1.899 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HTML_MESSAGE=0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id LAVzIBGgCMUJ for <ace@ietfa.amsl.com>; Mon, 14 Jul 2014 05:36:51 -0700 (PDT)
Received: from mailscan1.extendcp.co.uk (mailscan31.extendcp.co.uk [176.32.228.5]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id BA8AE1A03C2 for <ace@ietf.org>; Mon, 14 Jul 2014 05:36:51 -0700 (PDT)
Received: from lb1.hi.local ([10.0.1.197] helo=mailscan2.extendcp.co.uk) by mailscan-g66.hi.local with esmtp (Exim 4.80.1) (envelope-from <robert.cragie@gridmerge.com>) id 1X6fUw-0003M5-7e; Mon, 14 Jul 2014 13:36:50 +0100
Received: from lb1.hi.local ([10.0.1.197] helo=mail41.extendcp.co.uk) by mailscan2.extendcp.co.uk with esmtps (UNKNOWN:DHE-RSA-AES256-GCM-SHA384:256) (Exim 4.80.1) (envelope-from <robert.cragie@gridmerge.com>) id 1X6fUt-0001ds-Sl; Mon, 14 Jul 2014 13:36:50 +0100
Received: from host86-163-16-160.range86-163.btcentralplus.com ([86.163.16.160] helo=[192.168.0.2]) by mail41.extendcp.com with esmtpsa (TLSv1:DHE-RSA-AES128-SHA:128) (Exim 4.80.1) id 1X6fUs-0007O4-1H; Mon, 14 Jul 2014 13:36:46 +0100
Message-ID: <53C3CEDA.1000301@gridmerge.com>
Date: Mon, 14 Jul 2014 13:36:42 +0100
From: Robert Cragie <robert.cragie@gridmerge.com>
Organization: Gridmerge Ltd.
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:24.0) Gecko/20100101 Thunderbird/24.5.0
MIME-Version: 1.0
To: Hannes Tschofenig <hannes.tschofenig@gmx.net>,  "ace@ietf.org" <ace@ietf.org>
References: <53BCF608.5010606@gmx.net>
In-Reply-To: <53BCF608.5010606@gmx.net>
Content-Type: multipart/alternative; boundary="------------090401070109000606080309"
X-Authenticated-As: robert.cragie@gridmerge.com
X-Extend-Src: mailout
Archived-At: http://mailarchive.ietf.org/arch/msg/ace/kA3dhiC9lESIdQhPnv2z70NM6n0
Subject: Re: [Ace] Questions for the IETF#90 Meeting
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
Reply-To: robert.cragie@gridmerge.com
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 14 Jul 2014 12:36:55 -0000

This is a multi-part message in MIME format.
--------------090401070109000606080309
Content-Type: text/plain; charset=windows-1252; format=flowed
Content-Transfer-Encoding: 7bit

Hi Hannes,

My view on your questions.

Robert

On 09/07/2014 8:58 AM, Hannes Tschofenig wrote:
> To me there appear to be four questions for the group:
>
> 1) Are there requirements/use cases that allow anything other than the
> OAuth/Kerberos design pattern?
>
> Partially the answer should come from the use case document.
<RCC>
I think one of the issues which seems to be evident from the responses 
already is that, like all good engineers, we are coming up with 
solutions before we have fully analyzed the problem. The starting point 
is "some entity wants to access information on another entity, which 
will be allowed or denied". We agreed on using the client/server model 
and basing it on a RESTful architecture, even going as far as specifying 
the transfer protocols (HTTP or CoAP). We also say the the client and/or 
the server may be constrained. But beyond that, especially with regard 
to the basis access is allowed or denied, I think no further solutions 
should be assumed or implied as developing solutions is the project work.

The charter talks about CoAP using DTLS and mediatiion of an 
authorization server so already that is nodding towards solutions and 
this similar nodding is evident in the problem statement as early on in 
section 2 of the problem statement when it says "Many authorization 
solutions..."

It is reasonable to use both a top-down and bottom-up approach but to be 
effective the bottom up approach must always be cognizant of the 
requirements coming down from the top; the "peg" and the "hole" to use 
the typical analogy.

The thing is, as far as I can tell, neither OAuth or Kerberos is a 
design pattern in itself so can we relate either or both to some 
definitive design pattern? If we can, my guess is that that pattern will 
be sufficient.
</RCC>

>
> 2) Should the design re-use existing work or should the design start
> from scratch?
>
> This is more a question of taste / preference but will obviously have a
> huge impact on the subsequent work in the group.
<RCC>The first rule of engineering is not to reinvent the wheel. It 
depends how existing work is reused. If it the basis (i.e. the bottom of 
a bottom-up, top down approach) then I think that is the right approach. 
Using verbatim may not be appropriate, especially in constrained 
environments. However, based on experience, it is easy to be pessimistic 
about the suitability of existing protocols verbatim. As usual, there is 
a tradeoff; the most efficient protocol in a particular scenario is 
unlikely to be an existing one but conversely it is likely existing 
protocols would be suitable, if not the most efficient</RCC>
>
> 3) Should the design be based on symmetric or asymmetric crypto?
>    (or both?)
>
> We have various documents that talk about this issue, for example
> draft-seitz-ace-design-considerations-00 and
> draft-seitz-ace-problem-description-01
<RCC>I think it has to be both. There is a place for both. Security 
policy and deployment scenarios will often dictate what is most 
appropriate</RCC>
>
> 4) How to address cross-domain support in the initial protocol design?
> Is it a feature that can be added later easily?
>
> draft-gerdes-ace-actors-01 talks about this aspect.
<RCC>I think it needs to be considered from the get-go but the solution 
should scalable to accommodate cross-domain support</RCC>
>
> If we could get an answer to these questions during the meeting that
> would be good step forward.
>
> Ciao
> Hannes
>
> PS: One question that has been answered by all document in the same way
> at the moment is about the use of DTLS. Currently, everyone seems to be
> focused on using DTLS everywhere. There would be alternative approaches
> as well.
>
>
>
> _______________________________________________
> Ace mailing list
> Ace@ietf.org
> https://www.ietf.org/mailman/listinfo/ace


--------------090401070109000606080309
Content-Type: text/html; charset=windows-1252
Content-Transfer-Encoding: 7bit

<html>
  <head>
    <meta content="text/html; charset=windows-1252"
      http-equiv="Content-Type">
  </head>
  <body text="#000000" bgcolor="#FFFFFF">
    Hi Hannes,<br>
    <br>
    My view on your questions.<br>
    <br>
    Robert<br>
    <br>
    <div class="moz-cite-prefix">On 09/07/2014 8:58 AM, Hannes
      Tschofenig wrote:<br>
    </div>
    <blockquote cite="mid:53BCF608.5010606@gmx.net" type="cite">
      <pre wrap="">To me there appear to be four questions for the group:

1) Are there requirements/use cases that allow anything other than the
OAuth/Kerberos design pattern?

Partially the answer should come from the use case document.</pre>
    </blockquote>
    &lt;RCC&gt;<br>
    I think one of the issues which seems to be evident from the
    responses already is that, like all good engineers, we are coming up
    with solutions before we have fully analyzed the problem. The
    starting point is "some entity wants to access information on
    another entity, which will be allowed or denied". We agreed on using
    the client/server model and basing it on a RESTful architecture,
    even going as far as specifying the transfer protocols (HTTP or
    CoAP). We also say the the client and/or the server may be
    constrained. But beyond that, especially with regard to the basis
    access is allowed or denied, I think no further solutions should be
    assumed or implied as developing solutions is the project work.<br>
    <br>
    The charter talks about CoAP using DTLS and mediatiion of an
    authorization server so already that is nodding towards solutions
    and this similar nodding is evident in the problem statement as
    early on in section 2 of the problem statement when it says "Many
    authorization solutions..." <br>
    <br>
    It is reasonable to use both a top-down and bottom-up approach but
    to be effective the bottom up approach must always be cognizant of
    the requirements coming down from the top; the "peg" and the "hole"
    to use the typical analogy.<br>
    <br>
    The thing is, as far as I can tell, neither OAuth or Kerberos is a
    design pattern in itself so can we relate either or both to some
    definitive design pattern? If we can, my guess is that that pattern
    will be sufficient.<br>
    &lt;/RCC&gt;<br>
    <br>
    <blockquote cite="mid:53BCF608.5010606@gmx.net" type="cite">
      <pre wrap="">

2) Should the design re-use existing work or should the design start
from scratch?

This is more a question of taste / preference but will obviously have a
huge impact on the subsequent work in the group.</pre>
    </blockquote>
    &lt;RCC&gt;The first rule of engineering is not to reinvent the
    wheel. It depends how existing work is reused. If it the basis (i.e.
    the bottom of a bottom-up, top down approach) then I think that is
    the right approach. Using verbatim may not be appropriate,
    especially in constrained environments. However, based on
    experience, it is easy to be pessimistic about the suitability of
    existing protocols verbatim. As usual, there is a tradeoff; the most
    efficient protocol in a particular scenario is unlikely to be an
    existing one but conversely it is likely existing protocols would be
    suitable, if not the most efficient&lt;/RCC&gt;<br>
    <blockquote cite="mid:53BCF608.5010606@gmx.net" type="cite">
      <pre wrap="">

3) Should the design be based on symmetric or asymmetric crypto?
  (or both?)

We have various documents that talk about this issue, for example
draft-seitz-ace-design-considerations-00 and
draft-seitz-ace-problem-description-01</pre>
    </blockquote>
    &lt;RCC&gt;I think it has to be both. There is a place for both.
    Security policy and deployment scenarios will often dictate what is
    most appropriate&lt;/RCC&gt;<br>
    <blockquote cite="mid:53BCF608.5010606@gmx.net" type="cite">
      <pre wrap="">

4) How to address cross-domain support in the initial protocol design?
Is it a feature that can be added later easily?

draft-gerdes-ace-actors-01 talks about this aspect.</pre>
    </blockquote>
    &lt;RCC&gt;I think it needs to be considered from the get-go but the
    solution should scalable to accommodate cross-domain
    support&lt;/RCC&gt;<br>
    <blockquote cite="mid:53BCF608.5010606@gmx.net" type="cite">
      <pre wrap="">

If we could get an answer to these questions during the meeting that
would be good step forward.

Ciao
Hannes

PS: One question that has been answered by all document in the same way
at the moment is about the use of DTLS. Currently, everyone seems to be
focused on using DTLS everywhere. There would be alternative approaches
as well.

</pre>
      <br>
      <fieldset class="mimeAttachmentHeader"></fieldset>
      <br>
      <pre wrap="">_______________________________________________
Ace mailing list
<a class="moz-txt-link-abbreviated" href="mailto:Ace@ietf.org">Ace@ietf.org</a>
<a class="moz-txt-link-freetext" href="https://www.ietf.org/mailman/listinfo/ace">https://www.ietf.org/mailman/listinfo/ace</a>
</pre>
    </blockquote>
    <br>
  </body>
</html>

--------------090401070109000606080309--


From nobody Mon Jul 14 05:42:04 2014
Return-Path: <ludwig@sics.se>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 028C11A03C8 for <ace@ietfa.amsl.com>; Mon, 14 Jul 2014 05:42:00 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.901
X-Spam-Level: 
X-Spam-Status: No, score=-1.901 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HELO_EQ_SE=0.35, J_BACKHAIR_22=1, RCVD_IN_DNSWL_LOW=-0.7, RP_MATCHES_RCVD=-0.651] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Z8A66Hmb9bfQ for <ace@ietfa.amsl.com>; Mon, 14 Jul 2014 05:41:56 -0700 (PDT)
Received: from outbox.sics.se (outbox.sics.se [193.10.64.137]) by ietfa.amsl.com (Postfix) with ESMTP id 8F6141A03C7 for <ace@ietf.org>; Mon, 14 Jul 2014 05:41:56 -0700 (PDT)
Received: from e-mailfilter01.sunet.se (e-mailfilter01.sunet.se [192.36.171.201]) by outbox.sics.se (Postfix) with ESMTPS id 87DA711AA for <ace@ietf.org>; Mon, 14 Jul 2014 14:41:55 +0200 (CEST)
Received: from letter.sics.se (letter.sics.se [193.10.64.6]) by e-mailfilter01.sunet.se (8.14.4/8.14.4/Debian-4) with ESMTP id s6ECftru026542 for <ace@ietf.org>; Mon, 14 Jul 2014 14:41:55 +0200
Received: from [192.168.0.108] (unknown [85.235.11.178]) (Authenticated sender: ludwig@sics.se) by letter.sics.se (Postfix) with ESMTPSA id 64A3C40116 for <ace@ietf.org>; Mon, 14 Jul 2014 14:41:55 +0200 (CEST)
Message-ID: <53C3D013.6030006@sics.se>
Date: Mon, 14 Jul 2014 14:41:55 +0200
From: Ludwig Seitz <ludwig@sics.se>
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:24.0) Gecko/20100101 Thunderbird/24.6.0
MIME-Version: 1.0
To: ace@ietf.org
References: <53C398ED.3030302@gmx.net>
In-Reply-To: <53C398ED.3030302@gmx.net>
Content-Type: multipart/signed; protocol="application/pkcs7-signature"; micalg=sha1; boundary="------------ms040704010608030504030404"
X-Bayes-Prob: 0.0001 (Score 0, tokens from: outbound, outbound-sics-se:default, sics-se:default, base:default, @@RPTN)
X-p0f-Info: os=Solaris 10, link=Ethernet or modem
X-CanIt-Geo: =?UTF-8?Q?ip=3D85.235.11.178; _country=3DSE; _region=3DSk=C3=A5ne; _city=3DLund; _latitude=3D55.7000; _longitude=3D13.1833; _http://maps.google.com/maps=3Fq=3D55.7000,13.1833&z=3D6?=
X-CanItPRO-Stream: outbound-sics-se:outbound (inherits from outbound-sics-se:default, sics-se:default, base:default)
X-Canit-Stats-ID: 09MqcFTUQ - a734b9698ebc - 20140714
X-Antispam-Training-Forget: https://canit.sunet.se/canit/b.php?i=09MqcFTUQ&m=a734b9698ebc&t=20140714&c=f
X-Antispam-Training-Nonspam: https://canit.sunet.se/canit/b.php?i=09MqcFTUQ&m=a734b9698ebc&t=20140714&c=n
X-Antispam-Training-Spam: https://canit.sunet.se/canit/b.php?i=09MqcFTUQ&m=a734b9698ebc&t=20140714&c=s
X-CanIt-Archive-Cluster: PfMRe/vJWMiXwM2YIH5BVExnUnw
X-Scanned-By: CanIt (www . roaringpenguin . com) on 192.36.171.201
Archived-At: http://mailarchive.ietf.org/arch/msg/ace/2K60bzbsxmiBRrsbsR64uMZZcrY
Subject: Re: [Ace] Agenda
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 14 Jul 2014 12:42:00 -0000

This is a cryptographically signed message in MIME format.

--------------ms040704010608030504030404
Content-Type: text/plain; charset=ISO-8859-1; format=flowed
Content-Transfer-Encoding: quoted-printable

Hi Hannes,

just some requests for clarification. See inline.

/Ludwig

On 07/14/2014 10:46 AM, Hannes Tschofenig wrote:
[...]
> Authentication and Authorization for Constrained Environments (ACE)
>
> WEDNESDAY, July 23, 2014
>
> 0900-1130 EDT
> Tudor 7/8 (MM)
>
> - Welcome & Agenda Bashing (Chairs, 10 mins)
>
> - ACE Introduction (Chairs, 10 mins)
>
> Since this is the first meeting of the working group we would like to
> give a brief description the high level goal of the group. This part of=

> the agenda should also help you to become familiar with the terminology=
=2E
>
> - Design Directions
>
> We want to spend the main meeting time to answer a couple of challengin=
g
> questions.
> Our hope is it to get answers to some of these questions during the
> meeting or in preparation of the meeting.
>
> 1) Problem Description
>
> 1a) Client <-> RS Communication: What transport should be used?
> 1b) What degree of flexibility should we aim for? DTLS or application
> layer security?

What do you mean with "What transport should be used?" Is that the DTLS=20
vs Object Security discussion?

>
> [[Relevant document: draft-seitz-ace-problem-description-01]]
>
> Discussion Leader: Ludwig (to-be-confirmed)
>
> 2) Design Patterns
>
> 2a) Is the OAuth/Kerberos design pattern sufficient?
> (does it cover all the use cases)
> 2b) Is the OAUTH/Kerberos design pattern necessary?
> (can we throw something away?)
>
> [[Relevant document: draft-seitz-ace-usecases-01]]
>
> Discussion Leader: Ludwig (to-be-confirmed)
>

What do you mean with the "OAuth/Kerberos design pattern"? Is that the=20
Client, RS, AS architecture? Does it include the authorization push=20
sequence or could it be any other (pull or agent)?


> 3) Design Considerations
>
> 3a) What design components could we re-use?
> 3b) What areas need to be explored in more detail?
>
> Example topics:
>
>    * RS<->AS Communication: In scope / out of scope?
>    * Protocol re-use: what's good and what's not?
>    * Message encoding: Base64, JSON, ASN.1, CBOR
>
> 3c) Should the design be based on symmetric or asymmetric crypto?
>    (or both?)

I think this question (3c) is too generic. If we ask like that, we will=20
just reiterate the discussions currently ongoing on the DICE list (see=20
the "Tyranny of the Lightswitch" thread).

We should really try to get input on what is likely to be supported by=20
manufacturers of mass market IoT hardware.


/Ludwig



--=20
Ludwig Seitz, PhD
SICS Swedish ICT AB
Ideon Science Park
Building Beta 2
Scheelev=E4gen 17
SE-223 70 Lund

Phone +46(0)70-349 92 51
http://www.sics.se


--------------ms040704010608030504030404
Content-Type: application/pkcs7-signature; name="smime.p7s"
Content-Transfer-Encoding: base64
Content-Disposition: attachment; filename="smime.p7s"
Content-Description: S/MIME Cryptographic Signature

MIAGCSqGSIb3DQEHAqCAMIACAQExCzAJBgUrDgMCGgUAMIAGCSqGSIb3DQEHAQAAoIIMVDCC
BhgwggUAoAMCAQICAwiRTjANBgkqhkiG9w0BAQsFADCBjDELMAkGA1UEBhMCSUwxFjAUBgNV
BAoTDVN0YXJ0Q29tIEx0ZC4xKzApBgNVBAsTIlNlY3VyZSBEaWdpdGFsIENlcnRpZmljYXRl
IFNpZ25pbmcxODA2BgNVBAMTL1N0YXJ0Q29tIENsYXNzIDEgUHJpbWFyeSBJbnRlcm1lZGlh
dGUgQ2xpZW50IENBMB4XDTE0MDEwNzA3MjgzNVoXDTE1MDEwNzEyNTgyMlowODEXMBUGA1UE
AwwObHVkd2lnQHNpY3Muc2UxHTAbBgkqhkiG9w0BCQEWDmx1ZHdpZ0BzaWNzLnNlMIIBIjAN
BgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAnLm1tc30QxHa9wtdVjC3NgxjLJicnccm0HD+
1X16kPMKGvwps8F1oDhYn7jXIe46p1AuJMzLK0GIioE4JwxCFGdvpz7cg2xyTyrdBVUzSqez
Dfqt4FOJq6hrdrIMS8MHEzl7Jk02gv9cTn/pHQvDpkiThRpbSLU5mlMqtEQ8gDQY5YyBX0Mv
5qculV08I2JU8HEeTt1oeqhvBImgQfOVYMDatHlWHUVVrmYd6iIo+cuiUGd5kiA0XuaLYX0E
oCoao/z5Wg9U0sQlx0hl4r96Q+NdoZZ1prfts3qtyBzJ2hu135aikigzJ6sueWHv/jbISUek
tOMm0xkx1GOqqWtEAwIDAQABo4IC1DCCAtAwCQYDVR0TBAIwADALBgNVHQ8EBAMCBLAwHQYD
VR0lBBYwFAYIKwYBBQUHAwIGCCsGAQUFBwMEMB0GA1UdDgQWBBRZmjjBh8N3klra+mVQgC00
pl68ZTAfBgNVHSMEGDAWgBRTcu2SnODaywFcfH6WNU7y1LhRgjAZBgNVHREEEjAQgQ5sdWR3
aWdAc2ljcy5zZTCCAUwGA1UdIASCAUMwggE/MIIBOwYLKwYBBAGBtTcBAgMwggEqMC4GCCsG
AQUFBwIBFiJodHRwOi8vd3d3LnN0YXJ0c3NsLmNvbS9wb2xpY3kucGRmMIH3BggrBgEFBQcC
AjCB6jAnFiBTdGFydENvbSBDZXJ0aWZpY2F0aW9uIEF1dGhvcml0eTADAgEBGoG+VGhpcyBj
ZXJ0aWZpY2F0ZSB3YXMgaXNzdWVkIGFjY29yZGluZyB0byB0aGUgQ2xhc3MgMSBWYWxpZGF0
aW9uIHJlcXVpcmVtZW50cyBvZiB0aGUgU3RhcnRDb20gQ0EgcG9saWN5LCByZWxpYW5jZSBv
bmx5IGZvciB0aGUgaW50ZW5kZWQgcHVycG9zZSBpbiBjb21wbGlhbmNlIG9mIHRoZSByZWx5
aW5nIHBhcnR5IG9ibGlnYXRpb25zLjA2BgNVHR8ELzAtMCugKaAnhiVodHRwOi8vY3JsLnN0
YXJ0c3NsLmNvbS9jcnR1MS1jcmwuY3JsMIGOBggrBgEFBQcBAQSBgTB/MDkGCCsGAQUFBzAB
hi1odHRwOi8vb2NzcC5zdGFydHNzbC5jb20vc3ViL2NsYXNzMS9jbGllbnQvY2EwQgYIKwYB
BQUHMAKGNmh0dHA6Ly9haWEuc3RhcnRzc2wuY29tL2NlcnRzL3N1Yi5jbGFzczEuY2xpZW50
LmNhLmNydDAjBgNVHRIEHDAahhhodHRwOi8vd3d3LnN0YXJ0c3NsLmNvbS8wDQYJKoZIhvcN
AQELBQADggEBAHqEYmtWr83S+iLXE97KBnHJZiMr6PMuLKxmh0o6UJJwKgf+KTP2czxRnPSI
+whuqfQZdmz6g3A2K8AooMU0RXrzncnX1c4826APdnXkRxnGQxtZXI1wuhPn4z7iDKZ6ij9u
K5Pfn10JL/ERDig2qJQbqvhtIAx0RY7y7r+hLMvgXVq9mf3WRJYmGQeFW+N9t5Z1eEwG4m9R
KAZm0fnfeDn/Ai4kmxTckBH7dZwW2lTtwQqQ4su+PGCJ0e9ndBLpvTqaYGSAl+L7PO7vxPhS
/cS67Xa6BtnYJLTr3MaGXaN+CEUFSfwQHa9DKcAqh3kldErI3kCvnot0CigBl4aILOEwggY0
MIIEHKADAgECAgEeMA0GCSqGSIb3DQEBBQUAMH0xCzAJBgNVBAYTAklMMRYwFAYDVQQKEw1T
dGFydENvbSBMdGQuMSswKQYDVQQLEyJTZWN1cmUgRGlnaXRhbCBDZXJ0aWZpY2F0ZSBTaWdu
aW5nMSkwJwYDVQQDEyBTdGFydENvbSBDZXJ0aWZpY2F0aW9uIEF1dGhvcml0eTAeFw0wNzEw
MjQyMTAxNTVaFw0xNzEwMjQyMTAxNTVaMIGMMQswCQYDVQQGEwJJTDEWMBQGA1UEChMNU3Rh
cnRDb20gTHRkLjErMCkGA1UECxMiU2VjdXJlIERpZ2l0YWwgQ2VydGlmaWNhdGUgU2lnbmlu
ZzE4MDYGA1UEAxMvU3RhcnRDb20gQ2xhc3MgMSBQcmltYXJ5IEludGVybWVkaWF0ZSBDbGll
bnQgQ0EwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDHCYPMzi3YGrEppC4Tq5a+
ijKDjKaIQZZVR63UbxIP6uq/I0fhCu+cQhoUfE6ERKKnu8zPf1Jwuk0tsvVCk6U9b+0UjM0d
Lep3ZdE1gblK/1FwYT5Pipsu2yOMluLqwvsuz9/9f1+1PKHG/FaR/wpbfuIqu54qzHDYeqiU
fsYzoVflR80DAC7hmJ+SmZnNTWyUGHJbBpA8Q89lGxahNvuryGaC/o2/ceD2uYDX9U8Eg5Dp
IpGQdcbQeGarV04WgAUjjXX5r/2dabmtxWMZwhZna//jdiSyrrSMTGKkDiXm6/3/4ebfeZuC
YKzN2P8O2F/Xe2AC/Y7zeEsnR7FOp+uXAgMBAAGjggGtMIIBqTAPBgNVHRMBAf8EBTADAQH/
MA4GA1UdDwEB/wQEAwIBBjAdBgNVHQ4EFgQUU3Ltkpzg2ssBXHx+ljVO8tS4UYIwHwYDVR0j
BBgwFoAUTgvvGqRAW6UXaYcwyjRoQ9BBrvIwZgYIKwYBBQUHAQEEWjBYMCcGCCsGAQUFBzAB
hhtodHRwOi8vb2NzcC5zdGFydHNzbC5jb20vY2EwLQYIKwYBBQUHMAKGIWh0dHA6Ly93d3cu
c3RhcnRzc2wuY29tL3Nmc2NhLmNydDBbBgNVHR8EVDBSMCegJaAjhiFodHRwOi8vd3d3LnN0
YXJ0c3NsLmNvbS9zZnNjYS5jcmwwJ6AloCOGIWh0dHA6Ly9jcmwuc3RhcnRzc2wuY29tL3Nm
c2NhLmNybDCBgAYDVR0gBHkwdzB1BgsrBgEEAYG1NwECATBmMC4GCCsGAQUFBwIBFiJodHRw
Oi8vd3d3LnN0YXJ0c3NsLmNvbS9wb2xpY3kucGRmMDQGCCsGAQUFBwIBFihodHRwOi8vd3d3
LnN0YXJ0c3NsLmNvbS9pbnRlcm1lZGlhdGUucGRmMA0GCSqGSIb3DQEBBQUAA4ICAQAKgwh9
eKssBly4Y4xerhy5I3dNoXHYfYa8PlVLL/qtXnkFgdtY1o95CfegFJTwqBBmf8pyTUnFsukD
FUI22zF5bVHzuJ+GxhnSqN2sD1qetbYwBYK2iyYA5Pg7Er1A+hKMIzEzcduRkIMmCeUTyMyi
kfbUFvIBivtvkR8ZFAk22BZy+pJfAoedO61HTz4qSfQoCRcLN5A0t4DkuVhTMXIzuQ8Cnykh
ExD6x4e6ebIbrjZLb7L+ocR0y4YjCl/Pd4MXU91y0vTipgr/O75CDUHDRHCCKBVmz/Rzkc/b
970MEeHt5LC3NiWTgBSvrLEuVzBKM586YoRD9Dy3OHQgWI270g+5MYA8GfgI/EPT5G7xPbCD
z+zjdH89PeR3U4So4lSXur6H6vp+m9TQXPF3a0LwZrp8MQ+Z77U1uL7TelWO5lApsbAonrqA
SfTpaprFVkL4nyGH+NHST2ZJPWIBk81i6Vw0ny0qZW2Niy/QvVNKbb43A43ny076khXO7cNb
BIRdJ/6qQNq9Bqb5C0Q5nEsFcj75oxQRqlKf6TcvGbjxkJh8BYtv9ePsXklAxtm8J7GCUBth
HSQgepbkOexhJ0wP8imUkyiPHQ0GvEnd83129fZjoEhdGwXV27ioRKbj/cIq7JRXun0NbeY+
UdMYu9jGfIpDLtUUGSgsg2zMGs5R4jGCA90wggPZAgEBMIGUMIGMMQswCQYDVQQGEwJJTDEW
MBQGA1UEChMNU3RhcnRDb20gTHRkLjErMCkGA1UECxMiU2VjdXJlIERpZ2l0YWwgQ2VydGlm
aWNhdGUgU2lnbmluZzE4MDYGA1UEAxMvU3RhcnRDb20gQ2xhc3MgMSBQcmltYXJ5IEludGVy
bWVkaWF0ZSBDbGllbnQgQ0ECAwiRTjAJBgUrDgMCGgUAoIICHTAYBgkqhkiG9w0BCQMxCwYJ
KoZIhvcNAQcBMBwGCSqGSIb3DQEJBTEPFw0xNDA3MTQxMjQxNTVaMCMGCSqGSIb3DQEJBDEW
BBRyX79LcM/nR3ZqsiaUGfRj73+fcjBsBgkqhkiG9w0BCQ8xXzBdMAsGCWCGSAFlAwQBKjAL
BglghkgBZQMEAQIwCgYIKoZIhvcNAwcwDgYIKoZIhvcNAwICAgCAMA0GCCqGSIb3DQMCAgFA
MAcGBSsOAwIHMA0GCCqGSIb3DQMCAgEoMIGlBgkrBgEEAYI3EAQxgZcwgZQwgYwxCzAJBgNV
BAYTAklMMRYwFAYDVQQKEw1TdGFydENvbSBMdGQuMSswKQYDVQQLEyJTZWN1cmUgRGlnaXRh
bCBDZXJ0aWZpY2F0ZSBTaWduaW5nMTgwNgYDVQQDEy9TdGFydENvbSBDbGFzcyAxIFByaW1h
cnkgSW50ZXJtZWRpYXRlIENsaWVudCBDQQIDCJFOMIGnBgsqhkiG9w0BCRACCzGBl6CBlDCB
jDELMAkGA1UEBhMCSUwxFjAUBgNVBAoTDVN0YXJ0Q29tIEx0ZC4xKzApBgNVBAsTIlNlY3Vy
ZSBEaWdpdGFsIENlcnRpZmljYXRlIFNpZ25pbmcxODA2BgNVBAMTL1N0YXJ0Q29tIENsYXNz
IDEgUHJpbWFyeSBJbnRlcm1lZGlhdGUgQ2xpZW50IENBAgMIkU4wDQYJKoZIhvcNAQEBBQAE
ggEAN9ee4ryBbONoZpTZdxiObnlbX2KFslrPDg6epurFaOlbVen/hdGCb5+zin30i72mIYCC
yhAKTFdhz7DTxfRPnBv5TwDndzINkavG4o9F89xW8oTSLDo9nKgDe/uMQSDqQP5rLn67n5l2
6fd9GQcd5fg8kRxLykVRzhocQotqUx2tTIVs0Q2OqJP1K+O3Irc0XoMMO7xg642mvVMmrtyi
7P/JZkGpXuwJuVjq1ZQL8JV+6z6Rxzw/ZSkA//xSSIBYo3A2yDU0piuYptpWEXRlJFdMERgA
STZFeQq15IxBWj1Gph05hu7QNJfn/fypGGF2sTmdEvPelXEposZnTUGKZAAAAAAAAA==
--------------ms040704010608030504030404--


From nobody Mon Jul 14 05:51:42 2014
Return-Path: <ludwig@sics.se>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id CCE4A1A03D8 for <ace@ietfa.amsl.com>; Mon, 14 Jul 2014 05:51:39 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.901
X-Spam-Level: 
X-Spam-Status: No, score=-2.901 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HELO_EQ_SE=0.35, RCVD_IN_DNSWL_LOW=-0.7, RP_MATCHES_RCVD=-0.651] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id yoAOQo9_QcpW for <ace@ietfa.amsl.com>; Mon, 14 Jul 2014 05:51:38 -0700 (PDT)
Received: from outbox.sics.se (outbox.sics.se [193.10.64.137]) by ietfa.amsl.com (Postfix) with ESMTP id 054C61A03D7 for <ace@ietf.org>; Mon, 14 Jul 2014 05:51:38 -0700 (PDT)
Received: from e-mailfilter01.sunet.se (e-mailfilter01.sunet.se [192.36.171.201]) by outbox.sics.se (Postfix) with ESMTPS id 56B3111AA for <ace@ietf.org>; Mon, 14 Jul 2014 14:51:37 +0200 (CEST)
Received: from letter.sics.se (letter.sics.se [193.10.64.6]) by e-mailfilter01.sunet.se (8.14.4/8.14.4/Debian-4) with ESMTP id s6ECpaH6028783 for <ace@ietf.org>; Mon, 14 Jul 2014 14:51:37 +0200
Received: from [192.168.0.108] (unknown [85.235.11.178]) (Authenticated sender: ludwig@sics.se) by letter.sics.se (Postfix) with ESMTPSA id 46C5840117 for <ace@ietf.org>; Mon, 14 Jul 2014 14:51:37 +0200 (CEST)
Message-ID: <53C3D258.5000300@sics.se>
Date: Mon, 14 Jul 2014 14:51:36 +0200
From: Ludwig Seitz <ludwig@sics.se>
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:24.0) Gecko/20100101 Thunderbird/24.6.0
MIME-Version: 1.0
To: ace@ietf.org
References: <53BCF608.5010606@gmx.net> <53C3CEDA.1000301@gridmerge.com>
In-Reply-To: <53C3CEDA.1000301@gridmerge.com>
Content-Type: multipart/signed; protocol="application/pkcs7-signature"; micalg=sha1; boundary="------------ms030104010203070005010901"
X-Bayes-Prob: 0.0001 (Score 0, tokens from: outbound, outbound-sics-se:default, sics-se:default, base:default, @@RPTN)
X-p0f-Info: os=Solaris 10, link=Ethernet or modem
X-CanIt-Geo: =?UTF-8?Q?ip=3D85.235.11.178; _country=3DSE; _region=3DSk=C3=A5ne; _city=3DLund; _latitude=3D55.7000; _longitude=3D13.1833; _http://maps.google.com/maps=3Fq=3D55.7000,13.1833&z=3D6?=
X-CanItPRO-Stream: outbound-sics-se:outbound (inherits from outbound-sics-se:default, sics-se:default, base:default)
X-Canit-Stats-ID: 09MqcPB29 - 59e55d326a33 - 20140714
X-Antispam-Training-Forget: https://canit.sunet.se/canit/b.php?i=09MqcPB29&m=59e55d326a33&t=20140714&c=f
X-Antispam-Training-Nonspam: https://canit.sunet.se/canit/b.php?i=09MqcPB29&m=59e55d326a33&t=20140714&c=n
X-Antispam-Training-Spam: https://canit.sunet.se/canit/b.php?i=09MqcPB29&m=59e55d326a33&t=20140714&c=s
X-CanIt-Archive-Cluster: PfMRe/vJWMiXwM2YIH5BVExnUnw
X-Scanned-By: CanIt (www . roaringpenguin . com) on 192.36.171.201
Archived-At: http://mailarchive.ietf.org/arch/msg/ace/WlImxal_-emkIMj9H4HsTtkSbJ0
Subject: Re: [Ace] Questions for the IETF#90 Meeting
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 14 Jul 2014 12:51:39 -0000

This is a cryptographically signed message in MIME format.

--------------ms030104010203070005010901
Content-Type: text/plain; charset=ISO-8859-1; format=flowed
Content-Transfer-Encoding: quoted-printable

On 07/14/2014 02:36 PM, Robert Cragie wrote:
> Hi Hannes,
>
> My view on your questions.
>
> Robert
>
> On 09/07/2014 8:58 AM, Hannes Tschofenig wrote:
>> To me there appear to be four questions for the group:
>>
>> 1) Are there requirements/use cases that allow anything other than the=

>> OAuth/Kerberos design pattern?
>>
>> Partially the answer should come from the use case document.
> <RCC>
> I think one of the issues which seems to be evident from the responses
> already is that, like all good engineers, we are coming up with
> solutions before we have fully analyzed the problem. The starting point=

> is "some entity wants to access information on another entity, which
> will be allowed or denied".

Sorry for nit-picking, but since we are engineers lets be precise:

"some entity wants to access a resource on another entity"

This could be information, but it could also be the setting some=20
actuator. My point being: We don't only talk about read access.

> We agreed on using the client/server model
> and basing it on a RESTful architecture, even going as far as specifyin=
g
> the transfer protocols (HTTP or CoAP). We also say the the client and/o=
r
> the server may be constrained. But beyond that, especially with regard
> to the basis access is allowed or denied, I think no further solutions
> should be assumed or implied as developing solutions is the project wor=
k.
>
> The charter talks about CoAP using DTLS and mediatiion of an
> authorization server so already that is nodding towards solutions and
> this similar nodding is evident in the problem statement as early on in=

> section 2 of the problem statement when it says "Many authorization
> solutions..."
>
> It is reasonable to use both a top-down and bottom-up approach but to b=
e
> effective the bottom up approach must always be cognizant of the
> requirements coming down from the top; the "peg" and the "hole" to use
> the typical analogy.
>
> The thing is, as far as I can tell, neither OAuth or Kerberos is a
> design pattern in itself so can we relate either or both to some
> definitive design pattern? If we can, my guess is that that pattern wil=
l
> be sufficient.
> </RCC>

I don't know if this qualifies as a design pattern, but I had RFC2904 in
mind when writing the problem statement.

Most of us agree that we need third party mediation for authorization,=20
feel free to argue the contrary, I'm all ears.

/Ludwig



--=20
Ludwig Seitz, PhD
SICS Swedish ICT AB
Ideon Science Park
Building Beta 2
Scheelev=E4gen 17
SE-223 70 Lund

Phone +46(0)70-349 92 51
http://www.sics.se


--------------ms030104010203070005010901
Content-Type: application/pkcs7-signature; name="smime.p7s"
Content-Transfer-Encoding: base64
Content-Disposition: attachment; filename="smime.p7s"
Content-Description: S/MIME Cryptographic Signature

MIAGCSqGSIb3DQEHAqCAMIACAQExCzAJBgUrDgMCGgUAMIAGCSqGSIb3DQEHAQAAoIIMVDCC
BhgwggUAoAMCAQICAwiRTjANBgkqhkiG9w0BAQsFADCBjDELMAkGA1UEBhMCSUwxFjAUBgNV
BAoTDVN0YXJ0Q29tIEx0ZC4xKzApBgNVBAsTIlNlY3VyZSBEaWdpdGFsIENlcnRpZmljYXRl
IFNpZ25pbmcxODA2BgNVBAMTL1N0YXJ0Q29tIENsYXNzIDEgUHJpbWFyeSBJbnRlcm1lZGlh
dGUgQ2xpZW50IENBMB4XDTE0MDEwNzA3MjgzNVoXDTE1MDEwNzEyNTgyMlowODEXMBUGA1UE
AwwObHVkd2lnQHNpY3Muc2UxHTAbBgkqhkiG9w0BCQEWDmx1ZHdpZ0BzaWNzLnNlMIIBIjAN
BgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAnLm1tc30QxHa9wtdVjC3NgxjLJicnccm0HD+
1X16kPMKGvwps8F1oDhYn7jXIe46p1AuJMzLK0GIioE4JwxCFGdvpz7cg2xyTyrdBVUzSqez
Dfqt4FOJq6hrdrIMS8MHEzl7Jk02gv9cTn/pHQvDpkiThRpbSLU5mlMqtEQ8gDQY5YyBX0Mv
5qculV08I2JU8HEeTt1oeqhvBImgQfOVYMDatHlWHUVVrmYd6iIo+cuiUGd5kiA0XuaLYX0E
oCoao/z5Wg9U0sQlx0hl4r96Q+NdoZZ1prfts3qtyBzJ2hu135aikigzJ6sueWHv/jbISUek
tOMm0xkx1GOqqWtEAwIDAQABo4IC1DCCAtAwCQYDVR0TBAIwADALBgNVHQ8EBAMCBLAwHQYD
VR0lBBYwFAYIKwYBBQUHAwIGCCsGAQUFBwMEMB0GA1UdDgQWBBRZmjjBh8N3klra+mVQgC00
pl68ZTAfBgNVHSMEGDAWgBRTcu2SnODaywFcfH6WNU7y1LhRgjAZBgNVHREEEjAQgQ5sdWR3
aWdAc2ljcy5zZTCCAUwGA1UdIASCAUMwggE/MIIBOwYLKwYBBAGBtTcBAgMwggEqMC4GCCsG
AQUFBwIBFiJodHRwOi8vd3d3LnN0YXJ0c3NsLmNvbS9wb2xpY3kucGRmMIH3BggrBgEFBQcC
AjCB6jAnFiBTdGFydENvbSBDZXJ0aWZpY2F0aW9uIEF1dGhvcml0eTADAgEBGoG+VGhpcyBj
ZXJ0aWZpY2F0ZSB3YXMgaXNzdWVkIGFjY29yZGluZyB0byB0aGUgQ2xhc3MgMSBWYWxpZGF0
aW9uIHJlcXVpcmVtZW50cyBvZiB0aGUgU3RhcnRDb20gQ0EgcG9saWN5LCByZWxpYW5jZSBv
bmx5IGZvciB0aGUgaW50ZW5kZWQgcHVycG9zZSBpbiBjb21wbGlhbmNlIG9mIHRoZSByZWx5
aW5nIHBhcnR5IG9ibGlnYXRpb25zLjA2BgNVHR8ELzAtMCugKaAnhiVodHRwOi8vY3JsLnN0
YXJ0c3NsLmNvbS9jcnR1MS1jcmwuY3JsMIGOBggrBgEFBQcBAQSBgTB/MDkGCCsGAQUFBzAB
hi1odHRwOi8vb2NzcC5zdGFydHNzbC5jb20vc3ViL2NsYXNzMS9jbGllbnQvY2EwQgYIKwYB
BQUHMAKGNmh0dHA6Ly9haWEuc3RhcnRzc2wuY29tL2NlcnRzL3N1Yi5jbGFzczEuY2xpZW50
LmNhLmNydDAjBgNVHRIEHDAahhhodHRwOi8vd3d3LnN0YXJ0c3NsLmNvbS8wDQYJKoZIhvcN
AQELBQADggEBAHqEYmtWr83S+iLXE97KBnHJZiMr6PMuLKxmh0o6UJJwKgf+KTP2czxRnPSI
+whuqfQZdmz6g3A2K8AooMU0RXrzncnX1c4826APdnXkRxnGQxtZXI1wuhPn4z7iDKZ6ij9u
K5Pfn10JL/ERDig2qJQbqvhtIAx0RY7y7r+hLMvgXVq9mf3WRJYmGQeFW+N9t5Z1eEwG4m9R
KAZm0fnfeDn/Ai4kmxTckBH7dZwW2lTtwQqQ4su+PGCJ0e9ndBLpvTqaYGSAl+L7PO7vxPhS
/cS67Xa6BtnYJLTr3MaGXaN+CEUFSfwQHa9DKcAqh3kldErI3kCvnot0CigBl4aILOEwggY0
MIIEHKADAgECAgEeMA0GCSqGSIb3DQEBBQUAMH0xCzAJBgNVBAYTAklMMRYwFAYDVQQKEw1T
dGFydENvbSBMdGQuMSswKQYDVQQLEyJTZWN1cmUgRGlnaXRhbCBDZXJ0aWZpY2F0ZSBTaWdu
aW5nMSkwJwYDVQQDEyBTdGFydENvbSBDZXJ0aWZpY2F0aW9uIEF1dGhvcml0eTAeFw0wNzEw
MjQyMTAxNTVaFw0xNzEwMjQyMTAxNTVaMIGMMQswCQYDVQQGEwJJTDEWMBQGA1UEChMNU3Rh
cnRDb20gTHRkLjErMCkGA1UECxMiU2VjdXJlIERpZ2l0YWwgQ2VydGlmaWNhdGUgU2lnbmlu
ZzE4MDYGA1UEAxMvU3RhcnRDb20gQ2xhc3MgMSBQcmltYXJ5IEludGVybWVkaWF0ZSBDbGll
bnQgQ0EwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDHCYPMzi3YGrEppC4Tq5a+
ijKDjKaIQZZVR63UbxIP6uq/I0fhCu+cQhoUfE6ERKKnu8zPf1Jwuk0tsvVCk6U9b+0UjM0d
Lep3ZdE1gblK/1FwYT5Pipsu2yOMluLqwvsuz9/9f1+1PKHG/FaR/wpbfuIqu54qzHDYeqiU
fsYzoVflR80DAC7hmJ+SmZnNTWyUGHJbBpA8Q89lGxahNvuryGaC/o2/ceD2uYDX9U8Eg5Dp
IpGQdcbQeGarV04WgAUjjXX5r/2dabmtxWMZwhZna//jdiSyrrSMTGKkDiXm6/3/4ebfeZuC
YKzN2P8O2F/Xe2AC/Y7zeEsnR7FOp+uXAgMBAAGjggGtMIIBqTAPBgNVHRMBAf8EBTADAQH/
MA4GA1UdDwEB/wQEAwIBBjAdBgNVHQ4EFgQUU3Ltkpzg2ssBXHx+ljVO8tS4UYIwHwYDVR0j
BBgwFoAUTgvvGqRAW6UXaYcwyjRoQ9BBrvIwZgYIKwYBBQUHAQEEWjBYMCcGCCsGAQUFBzAB
hhtodHRwOi8vb2NzcC5zdGFydHNzbC5jb20vY2EwLQYIKwYBBQUHMAKGIWh0dHA6Ly93d3cu
c3RhcnRzc2wuY29tL3Nmc2NhLmNydDBbBgNVHR8EVDBSMCegJaAjhiFodHRwOi8vd3d3LnN0
YXJ0c3NsLmNvbS9zZnNjYS5jcmwwJ6AloCOGIWh0dHA6Ly9jcmwuc3RhcnRzc2wuY29tL3Nm
c2NhLmNybDCBgAYDVR0gBHkwdzB1BgsrBgEEAYG1NwECATBmMC4GCCsGAQUFBwIBFiJodHRw
Oi8vd3d3LnN0YXJ0c3NsLmNvbS9wb2xpY3kucGRmMDQGCCsGAQUFBwIBFihodHRwOi8vd3d3
LnN0YXJ0c3NsLmNvbS9pbnRlcm1lZGlhdGUucGRmMA0GCSqGSIb3DQEBBQUAA4ICAQAKgwh9
eKssBly4Y4xerhy5I3dNoXHYfYa8PlVLL/qtXnkFgdtY1o95CfegFJTwqBBmf8pyTUnFsukD
FUI22zF5bVHzuJ+GxhnSqN2sD1qetbYwBYK2iyYA5Pg7Er1A+hKMIzEzcduRkIMmCeUTyMyi
kfbUFvIBivtvkR8ZFAk22BZy+pJfAoedO61HTz4qSfQoCRcLN5A0t4DkuVhTMXIzuQ8Cnykh
ExD6x4e6ebIbrjZLb7L+ocR0y4YjCl/Pd4MXU91y0vTipgr/O75CDUHDRHCCKBVmz/Rzkc/b
970MEeHt5LC3NiWTgBSvrLEuVzBKM586YoRD9Dy3OHQgWI270g+5MYA8GfgI/EPT5G7xPbCD
z+zjdH89PeR3U4So4lSXur6H6vp+m9TQXPF3a0LwZrp8MQ+Z77U1uL7TelWO5lApsbAonrqA
SfTpaprFVkL4nyGH+NHST2ZJPWIBk81i6Vw0ny0qZW2Niy/QvVNKbb43A43ny076khXO7cNb
BIRdJ/6qQNq9Bqb5C0Q5nEsFcj75oxQRqlKf6TcvGbjxkJh8BYtv9ePsXklAxtm8J7GCUBth
HSQgepbkOexhJ0wP8imUkyiPHQ0GvEnd83129fZjoEhdGwXV27ioRKbj/cIq7JRXun0NbeY+
UdMYu9jGfIpDLtUUGSgsg2zMGs5R4jGCA90wggPZAgEBMIGUMIGMMQswCQYDVQQGEwJJTDEW
MBQGA1UEChMNU3RhcnRDb20gTHRkLjErMCkGA1UECxMiU2VjdXJlIERpZ2l0YWwgQ2VydGlm
aWNhdGUgU2lnbmluZzE4MDYGA1UEAxMvU3RhcnRDb20gQ2xhc3MgMSBQcmltYXJ5IEludGVy
bWVkaWF0ZSBDbGllbnQgQ0ECAwiRTjAJBgUrDgMCGgUAoIICHTAYBgkqhkiG9w0BCQMxCwYJ
KoZIhvcNAQcBMBwGCSqGSIb3DQEJBTEPFw0xNDA3MTQxMjUxMzZaMCMGCSqGSIb3DQEJBDEW
BBTFchcjPfn0Nmezy4v4KyxS1DlfazBsBgkqhkiG9w0BCQ8xXzBdMAsGCWCGSAFlAwQBKjAL
BglghkgBZQMEAQIwCgYIKoZIhvcNAwcwDgYIKoZIhvcNAwICAgCAMA0GCCqGSIb3DQMCAgFA
MAcGBSsOAwIHMA0GCCqGSIb3DQMCAgEoMIGlBgkrBgEEAYI3EAQxgZcwgZQwgYwxCzAJBgNV
BAYTAklMMRYwFAYDVQQKEw1TdGFydENvbSBMdGQuMSswKQYDVQQLEyJTZWN1cmUgRGlnaXRh
bCBDZXJ0aWZpY2F0ZSBTaWduaW5nMTgwNgYDVQQDEy9TdGFydENvbSBDbGFzcyAxIFByaW1h
cnkgSW50ZXJtZWRpYXRlIENsaWVudCBDQQIDCJFOMIGnBgsqhkiG9w0BCRACCzGBl6CBlDCB
jDELMAkGA1UEBhMCSUwxFjAUBgNVBAoTDVN0YXJ0Q29tIEx0ZC4xKzApBgNVBAsTIlNlY3Vy
ZSBEaWdpdGFsIENlcnRpZmljYXRlIFNpZ25pbmcxODA2BgNVBAMTL1N0YXJ0Q29tIENsYXNz
IDEgUHJpbWFyeSBJbnRlcm1lZGlhdGUgQ2xpZW50IENBAgMIkU4wDQYJKoZIhvcNAQEBBQAE
ggEAD9BTnNYphLfCJeYohENkWekzdjVbdD9QAmtxJFzBaSY3b/1ldPIIrB94F4RdVoOfCoKy
gb9rg+JKJn/H2HCJmZatrUUlYezkLVqV1Uz7mwRDfs7xXrViMIzE66b95EFyM2G2Dy5kQ9l4
6zZ7Pvr8IO/ziXVIbMoP56sR96RgJSy37eG3rDrnV5VD1FGD87GIcYkDMRi7/Y9DRrx8PAET
iuqv6ma2Yt5lHCHuAzMFYP71wRAYDhHQ/ylKVGndb6BZrNgy+o9J+88NF5ypyoEVMRw5vWsy
1M7qMrtlfcUvQ9FsNHUmsMHkaJBlgdNP7mHu9kxypCQt2tjmgP9t0Fu1FgAAAAAAAA==
--------------ms030104010203070005010901--


From nobody Mon Jul 14 07:09:46 2014
Return-Path: <robert.cragie@gridmerge.com>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 767B61A049C for <ace@ietfa.amsl.com>; Mon, 14 Jul 2014 07:09:44 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.899
X-Spam-Level: 
X-Spam-Status: No, score=-1.899 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HTML_MESSAGE=0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id hLjtIFOPXOAF for <ace@ietfa.amsl.com>; Mon, 14 Jul 2014 07:09:40 -0700 (PDT)
Received: from mailscan1.extendcp.co.uk (mailscan27.extendcp.co.uk [176.32.228.1]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id D56B31A03C1 for <ace@ietf.org>; Mon, 14 Jul 2014 07:09:39 -0700 (PDT)
Received: from lb1.hi.local ([10.0.1.197] helo=mailscan2.extendcp.co.uk) by mailscan-g64.hi.local with esmtp (Exim 4.80.1) (envelope-from <robert.cragie@gridmerge.com>) id 1X6gwk-0007O3-BF; Mon, 14 Jul 2014 15:09:38 +0100
Received: from lb1.hi.local ([10.0.1.197] helo=mail41.extendcp.co.uk) by mailscan2.extendcp.co.uk with esmtps (UNKNOWN:DHE-RSA-AES256-GCM-SHA384:256) (Exim 4.80.1) (envelope-from <robert.cragie@gridmerge.com>) id 1X6gwh-0004jE-GH; Mon, 14 Jul 2014 15:09:38 +0100
Received: from host86-163-16-160.range86-163.btcentralplus.com ([86.163.16.160] helo=[192.168.0.2]) by mail41.extendcp.com with esmtpsa (TLSv1:DHE-RSA-AES128-SHA:128) (Exim 4.80.1) id 1X6gwf-00052Y-Hm; Mon, 14 Jul 2014 15:09:33 +0100
Message-ID: <53C3E49A.6020700@gridmerge.com>
Date: Mon, 14 Jul 2014 15:09:30 +0100
From: Robert Cragie <robert.cragie@gridmerge.com>
Organization: Gridmerge Ltd.
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:24.0) Gecko/20100101 Thunderbird/24.5.0
MIME-Version: 1.0
To: Ludwig Seitz <ludwig@sics.se>, ace@ietf.org
References: <53BCF608.5010606@gmx.net> <53C3CEDA.1000301@gridmerge.com> <53C3D258.5000300@sics.se>
In-Reply-To: <53C3D258.5000300@sics.se>
Content-Type: multipart/signed; protocol="application/pkcs7-signature"; micalg=sha1; boundary="------------ms090609020905070505000707"
X-Authenticated-As: robert.cragie@gridmerge.com
X-Extend-Src: mailout
Archived-At: http://mailarchive.ietf.org/arch/msg/ace/tRD3DwOZXjUUV_O_nMEmyaGy_Hs
Subject: Re: [Ace] Questions for the IETF#90 Meeting
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
Reply-To: robert.cragie@gridmerge.com
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 14 Jul 2014 14:09:44 -0000

This is a cryptographically signed message in MIME format.

--------------ms090609020905070505000707
Content-Type: multipart/alternative;
 boundary="------------000700050502030106000908"

This is a multi-part message in MIME format.
--------------000700050502030106000908
Content-Type: text/plain; charset=ISO-8859-1; format=flowed
Content-Transfer-Encoding: quoted-printable


On 14/07/2014 1:51 PM, Ludwig Seitz wrote:
> On 07/14/2014 02:36 PM, Robert Cragie wrote:
>> Hi Hannes,
>>
>> My view on your questions.
>>
>> Robert
>>
>> On 09/07/2014 8:58 AM, Hannes Tschofenig wrote:
>>> To me there appear to be four questions for the group:
>>>
>>> 1) Are there requirements/use cases that allow anything other than th=
e
>>> OAuth/Kerberos design pattern?
>>>
>>> Partially the answer should come from the use case document.
>> <RCC>
>> I think one of the issues which seems to be evident from the responses=

>> already is that, like all good engineers, we are coming up with
>> solutions before we have fully analyzed the problem. The starting poin=
t
>> is "some entity wants to access information on another entity, which
>> will be allowed or denied".
>
> Sorry for nit-picking, but since we are engineers lets be precise:
>
> "some entity wants to access a resource on another entity"
>
> This could be information, but it could also be the setting some=20
> actuator. My point being: We don't only talk about read access.
<RCC2>I was being deliberately general, which is why I didn't use the=20
'read' or 'data' words. Accessing a resource could involve data flow in=20
both directions, i.e. writing data as well.</RCC2>
>
>> We agreed on using the client/server model
>> and basing it on a RESTful architecture, even going as far as specifyi=
ng
>> the transfer protocols (HTTP or CoAP). We also say the the client and/=
or
>> the server may be constrained. But beyond that, especially with regard=

>> to the basis access is allowed or denied, I think no further solutions=

>> should be assumed or implied as developing solutions is the project=20
>> work.
>>
>> The charter talks about CoAP using DTLS and mediatiion of an
>> authorization server so already that is nodding towards solutions and
>> this similar nodding is evident in the problem statement as early on i=
n
>> section 2 of the problem statement when it says "Many authorization
>> solutions..."
>>
>> It is reasonable to use both a top-down and bottom-up approach but to =
be
>> effective the bottom up approach must always be cognizant of the
>> requirements coming down from the top; the "peg" and the "hole" to use=

>> the typical analogy.
>>
>> The thing is, as far as I can tell, neither OAuth or Kerberos is a
>> design pattern in itself so can we relate either or both to some
>> definitive design pattern? If we can, my guess is that that pattern wi=
ll
>> be sufficient.
>> </RCC>
>
> I don't know if this qualifies as a design pattern, but I had RFC2904 i=
n
> mind when writing the problem statement.
>
> Most of us agree that we need third party mediation for authorization, =

> feel free to argue the contrary, I'm all ears.
<RCC2>RFC 2904 describes itself as a framework; I am not sure if people=20
view a framework as the same as a design pattern. In my view, a pattern=20
is a more general concept but YMMV. Re. third party mediation. I am not=20
arguing the contrary, it is at what point that mediation comes into=20
play. At the moment there seems to be an assumption authorization will=20
be grant-based but online is possible. Perhaps it may be more=20
appropriate to develop these initially as paradigms then refine into=20
design patterns, then frameworks then protocols.</RCC2>
>
> /Ludwig
>
>
>
>
>
> _______________________________________________
> Ace mailing list
> Ace@ietf.org
> https://www.ietf.org/mailman/listinfo/ace


--------------000700050502030106000908
Content-Type: text/html; charset=ISO-8859-1
Content-Transfer-Encoding: quoted-printable

<html>
  <head>
    <meta content=3D"text/html; charset=3DISO-8859-1"
      http-equiv=3D"Content-Type">
  </head>
  <body text=3D"#000000" bgcolor=3D"#FFFFFF">
    <br>
    <div class=3D"moz-cite-prefix">On 14/07/2014 1:51 PM, Ludwig Seitz
      wrote:<br>
    </div>
    <blockquote cite=3D"mid:53C3D258.5000300@sics.se" type=3D"cite">On
      07/14/2014 02:36 PM, Robert Cragie wrote:
      <br>
      <blockquote type=3D"cite">Hi Hannes,
        <br>
        <br>
        My view on your questions.
        <br>
        <br>
        Robert
        <br>
        <br>
        On 09/07/2014 8:58 AM, Hannes Tschofenig wrote:
        <br>
        <blockquote type=3D"cite">To me there appear to be four questions=

          for the group:
          <br>
          <br>
          1) Are there requirements/use cases that allow anything other
          than the
          <br>
          OAuth/Kerberos design pattern?
          <br>
          <br>
          Partially the answer should come from the use case document.
          <br>
        </blockquote>
        &lt;RCC&gt;
        <br>
        I think one of the issues which seems to be evident from the
        responses
        <br>
        already is that, like all good engineers, we are coming up with
        <br>
        solutions before we have fully analyzed the problem. The
        starting point
        <br>
        is "some entity wants to access information on another entity,
        which
        <br>
        will be allowed or denied".
        <br>
      </blockquote>
      <br>
      Sorry for nit-picking, but since we are engineers lets be precise:
      <br>
      <br>
      "some entity wants to access a resource on another entity"
      <br>
      <br>
      This could be information, but it could also be the setting some
      actuator. My point being: We don't only talk about read access.
      <br>
    </blockquote>
    &lt;RCC2&gt;I was being deliberately general, which is why I didn't
    use the 'read' or 'data' words. Accessing a resource could involve
    data flow in both directions, i.e. writing data as
    well.&lt;/RCC2&gt;<br>
    <blockquote cite=3D"mid:53C3D258.5000300@sics.se" type=3D"cite">
      <br>
      <blockquote type=3D"cite">We agreed on using the client/server mode=
l
        <br>
        and basing it on a RESTful architecture, even going as far as
        specifying
        <br>
        the transfer protocols (HTTP or CoAP). We also say the the
        client and/or
        <br>
        the server may be constrained. But beyond that, especially with
        regard
        <br>
        to the basis access is allowed or denied, I think no further
        solutions
        <br>
        should be assumed or implied as developing solutions is the
        project work.
        <br>
        <br>
        The charter talks about CoAP using DTLS and mediatiion of an
        <br>
        authorization server so already that is nodding towards
        solutions and
        <br>
        this similar nodding is evident in the problem statement as
        early on in
        <br>
        section 2 of the problem statement when it says "Many
        authorization
        <br>
        solutions..."
        <br>
        <br>
        It is reasonable to use both a top-down and bottom-up approach
        but to be
        <br>
        effective the bottom up approach must always be cognizant of the
        <br>
        requirements coming down from the top; the "peg" and the "hole"
        to use
        <br>
        the typical analogy.
        <br>
        <br>
        The thing is, as far as I can tell, neither OAuth or Kerberos is
        a
        <br>
        design pattern in itself so can we relate either or both to some
        <br>
        definitive design pattern? If we can, my guess is that that
        pattern will
        <br>
        be sufficient.
        <br>
        &lt;/RCC&gt;
        <br>
      </blockquote>
      <br>
      I don't know if this qualifies as a design pattern, but I had
      RFC2904 in
      <br>
      mind when writing the problem statement.
      <br>
      <br>
      Most of us agree that we need third party mediation for
      authorization, feel free to argue the contrary, I'm all ears.
      <br>
    </blockquote>
    &lt;RCC2&gt;RFC 2904 describes itself as a framework; I am not sure
    if people view a framework as the same as a design pattern. In my
    view, a pattern is a more general concept but YMMV. Re. third party
    mediation. I am not arguing the contrary, it is at what point that
    mediation comes into play. At the moment there seems to be an
    assumption authorization will be grant-based but online is possible.
    Perhaps it may be more appropriate to develop these initially as
    paradigms then refine into design patterns, then frameworks then
    protocols.&lt;/RCC2&gt;<br>
    <blockquote cite=3D"mid:53C3D258.5000300@sics.se" type=3D"cite">
      <br>
      /Ludwig
      <br>
      <br>
      <br>
      <br>
      <br>
      <fieldset class=3D"mimeAttachmentHeader"></fieldset>
      <br>
      <pre wrap=3D"">_______________________________________________
Ace mailing list
<a class=3D"moz-txt-link-abbreviated" href=3D"mailto:Ace@ietf.org">Ace@ie=
tf.org</a>
<a class=3D"moz-txt-link-freetext" href=3D"https://www.ietf.org/mailman/l=
istinfo/ace">https://www.ietf.org/mailman/listinfo/ace</a>
</pre>
    </blockquote>
    <br>
  </body>
</html>

--------------000700050502030106000908--

--------------ms090609020905070505000707
Content-Type: application/pkcs7-signature; name="smime.p7s"
Content-Transfer-Encoding: base64
Content-Disposition: attachment; filename="smime.p7s"
Content-Description: S/MIME Cryptographic Signature

MIAGCSqGSIb3DQEHAqCAMIACAQExCzAJBgUrDgMCGgUAMIAGCSqGSIb3DQEHAQAAoIILUDCC
BRowggQCoAMCAQICEG0Z6qcZT2ozIuYiMnqqcd4wDQYJKoZIhvcNAQEFBQAwga4xCzAJBgNV
BAYTAlVTMQswCQYDVQQIEwJVVDEXMBUGA1UEBxMOU2FsdCBMYWtlIENpdHkxHjAcBgNVBAoT
FVRoZSBVU0VSVFJVU1QgTmV0d29yazEhMB8GA1UECxMYaHR0cDovL3d3dy51c2VydHJ1c3Qu
Y29tMTYwNAYDVQQDEy1VVE4tVVNFUkZpcnN0LUNsaWVudCBBdXRoZW50aWNhdGlvbiBhbmQg
RW1haWwwHhcNMTEwNDI4MDAwMDAwWhcNMjAwNTMwMTA0ODM4WjCBkzELMAkGA1UEBhMCR0Ix
GzAZBgNVBAgTEkdyZWF0ZXIgTWFuY2hlc3RlcjEQMA4GA1UEBxMHU2FsZm9yZDEaMBgGA1UE
ChMRQ09NT0RPIENBIExpbWl0ZWQxOTA3BgNVBAMTMENPTU9ETyBDbGllbnQgQXV0aGVudGlj
YXRpb24gYW5kIFNlY3VyZSBFbWFpbCBDQTCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoC
ggEBAJKEhFtLV5jUXi+LpOFAyKNTWF9mZfEyTvefMn1V0HhMVbdClOD5J3EHxcZppLkyxPFA
GpDMJ1Zifxe1cWmu5SAb5MtjXmDKokH2auGj/7jfH0htZUOMKi4rYzh337EXrMLaggLW1DJq
1GdvIBOPXDX65VSAr9hxCh03CgJQU2yVHakQFLSZlVkSMf8JotJM3FLb3uJAAVtIaN3FSrTg
7SQfOq9xXwfjrL8UO7AlcWg99A/WF1hGFYE8aIuLgw9teiFX5jSw2zJ+40rhpVJyZCaRTqWS
D//gsWD9Gm9oUZljjRqLpcxCm5t9ImPTqaD8zp6Q30QZ9FxbNboW86eb/8ECAwEAAaOCAUsw
ggFHMB8GA1UdIwQYMBaAFImCZ33EnSZwAEu0UEh83j2uBG59MB0GA1UdDgQWBBR6E04AdFvG
eGNkJ8Ev4qBbvHnFezAOBgNVHQ8BAf8EBAMCAQYwEgYDVR0TAQH/BAgwBgEB/wIBADARBgNV
HSAECjAIMAYGBFUdIAAwWAYDVR0fBFEwTzBNoEugSYZHaHR0cDovL2NybC51c2VydHJ1c3Qu
Y29tL1VUTi1VU0VSRmlyc3QtQ2xpZW50QXV0aGVudGljYXRpb25hbmRFbWFpbC5jcmwwdAYI
KwYBBQUHAQEEaDBmMD0GCCsGAQUFBzAChjFodHRwOi8vY3J0LnVzZXJ0cnVzdC5jb20vVVRO
QWRkVHJ1c3RDbGllbnRfQ0EuY3J0MCUGCCsGAQUFBzABhhlodHRwOi8vb2NzcC51c2VydHJ1
c3QuY29tMA0GCSqGSIb3DQEBBQUAA4IBAQCF1r54V1VtM39EUv5C1QaoAQOAivsNsv1Kv/av
QUn1G1rF0q0bc24+6SZ85kyYwTAo38v7QjyhJT4KddbQPTmGZtGhm7VNm2+vKGwdr+XqdFqo
2rHA8XV6L566k3nK/uKRHlZ0sviN0+BDchvtj/1gOSBH+4uvOmVIPJg9pSW/ve9g4EnlFsjr
P0OD8ODuDcHTzTNfm9C9YGqzO/761Mk6PB/tm/+bSTO+Qik5g+4zaS6CnUVNqGnagBsePdIa
XXxHmaWbCG0SmYbWXVcHG6cwvktJRLiQfsrReTjrtDP6oDpdJlieYVUYtCHVmdXgQ0BCML7q
peeU0rD+83X5f27nMIIGLjCCBRagAwIBAgIQXDFQ28QtqMuYch5f2nTvZjANBgkqhkiG9w0B
AQUFADCBkzELMAkGA1UEBhMCR0IxGzAZBgNVBAgTEkdyZWF0ZXIgTWFuY2hlc3RlcjEQMA4G
A1UEBxMHU2FsZm9yZDEaMBgGA1UEChMRQ09NT0RPIENBIExpbWl0ZWQxOTA3BgNVBAMTMENP
TU9ETyBDbGllbnQgQXV0aGVudGljYXRpb24gYW5kIFNlY3VyZSBFbWFpbCBDQTAeFw0xMTA5
MDIwMDAwMDBaFw0xNDA5MDEyMzU5NTlaMIIBNzELMAkGA1UEBhMCR0IxEDAOBgNVBBETB1dG
NCA0V0ExFzAVBgNVBAgTDldlc3QgWW9ya3NoaXJlMRIwEAYDVQQHEwlXYWtlZmllbGQxFDAS
BgNVBAkTC0dyYW5nZSBNb29yMR8wHQYDVQQJExY4OSBHcmVlbmZpZWxkIENyZXNjZW50MRcw
FQYDVQQKEw5HcmlkbWVyZ2UgTHRkLjE0MDIGA1UECxMrSXNzdWVkIHRocm91Z2ggR3JpZG1l
cmdlIEx0ZC4gRS1QS0kgTWFuYWdlcjEfMB0GA1UECxMWQ29ycG9yYXRlIFNlY3VyZSBFbWFp
bDEWMBQGA1UEAxMNUm9iZXJ0IENyYWdpZTEqMCgGCSqGSIb3DQEJARYbcm9iZXJ0LmNyYWdp
ZUBncmlkbWVyZ2UuY29tMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEArcThqvLe
WU1Q1ZJmnb+2UQSwOQKWok3A1Mwk582AdvwaAQyBFliPyJ0kXJqtwNBoZvk+3WJr0QA5ZRr+
J0x3sXVpcxadojP2HNzy1gsgDtIGG8ltoU4vmX1A8BTlOIUT+Pg8p/bSruxV0vz0CR8ho2hs
R0Zi5vU+rQKNmbgufbkWhlQnMEYjknemscLQfw1YZz90ta67doNDujFy6+X6I06HpjudgMYx
8bdsNS5xVFFwuBA1eqNQra+xLzhCOeX9PPB/zK68qdNhrni3WPYG9EhSt4Dzk+xIz9hj7wrU
ZIVXDTPsY8qbUSBVpwmzI5lCHPgzurH1OK7WwgpDSsl5pwIDAQABo4IB1TCCAdEwHwYDVR0j
BBgwFoAUehNOAHRbxnhjZCfBL+KgW7x5xXswHQYDVR0OBBYEFBCOXNH+lDm8U9gy3b3bRvrx
vKgrMA4GA1UdDwEB/wQEAwIFoDAMBgNVHRMBAf8EAjAAMB0GA1UdJQQWMBQGCCsGAQUFBwME
BggrBgEFBQcDAjBGBgNVHSAEPzA9MDsGDCsGAQQBsjEBAgEDBTArMCkGCCsGAQUFBwIBFh1o
dHRwczovL3NlY3VyZS5jb21vZG8ubmV0L0NQUzBXBgNVHR8EUDBOMEygSqBIhkZodHRwOi8v
Y3JsLmNvbW9kb2NhLmNvbS9DT01PRE9DbGllbnRBdXRoZW50aWNhdGlvbmFuZFNlY3VyZUVt
YWlsQ0EuY3JsMIGIBggrBgEFBQcBAQR8MHowUgYIKwYBBQUHMAKGRmh0dHA6Ly9jcnQuY29t
b2RvY2EuY29tL0NPTU9ET0NsaWVudEF1dGhlbnRpY2F0aW9uYW5kU2VjdXJlRW1haWxDQS5j
cnQwJAYIKwYBBQUHMAGGGGh0dHA6Ly9vY3NwLmNvbW9kb2NhLmNvbTAmBgNVHREEHzAdgRty
b2JlcnQuY3JhZ2llQGdyaWRtZXJnZS5jb20wDQYJKoZIhvcNAQEFBQADggEBAD6b/O0LkPav
kR4Znoqxg0Ad7M3duDm4uzfrlX4ecgq56Ccdwd+3Tayz7Ewej30woVMmTKkA/NKRaCd0wVM9
8seF/oZjXKO7o1SH27igRnGSWjCoWXsdwJGfZbYnvcIIhhsxJoCPNbeSR7C0PAFDKsP3xrJy
MHMljIJsoRbZu/fnYNyFWh9OXf7fYJOGmKDKAhSabUGfhY7umvU9d/YTqo02Q6YzC7d4zPNG
1a75AuHSEchf6GdKqycG38I5y9jlDaYfXspoS3PlTNCIeZONbOSMZgftnNEVKq+SWytFqyG/
8+dwpm/a12KMex5J8iHwaUKj++2O2rAFNjDDqXpeEYoxggQZMIIEFQIBATCBqDCBkzELMAkG
A1UEBhMCR0IxGzAZBgNVBAgTEkdyZWF0ZXIgTWFuY2hlc3RlcjEQMA4GA1UEBxMHU2FsZm9y
ZDEaMBgGA1UEChMRQ09NT0RPIENBIExpbWl0ZWQxOTA3BgNVBAMTMENPTU9ETyBDbGllbnQg
QXV0aGVudGljYXRpb24gYW5kIFNlY3VyZSBFbWFpbCBDQQIQXDFQ28QtqMuYch5f2nTvZjAJ
BgUrDgMCGgUAoIICRTAYBgkqhkiG9w0BCQMxCwYJKoZIhvcNAQcBMBwGCSqGSIb3DQEJBTEP
Fw0xNDA3MTQxNDA5MzBaMCMGCSqGSIb3DQEJBDEWBBTzPDL9+MjuxNYBEfEjlQVTUtnihTBs
BgkqhkiG9w0BCQ8xXzBdMAsGCWCGSAFlAwQBKjALBglghkgBZQMEAQIwCgYIKoZIhvcNAwcw
DgYIKoZIhvcNAwICAgCAMA0GCCqGSIb3DQMCAgFAMAcGBSsOAwIHMA0GCCqGSIb3DQMCAgEo
MIG5BgkrBgEEAYI3EAQxgaswgagwgZMxCzAJBgNVBAYTAkdCMRswGQYDVQQIExJHcmVhdGVy
IE1hbmNoZXN0ZXIxEDAOBgNVBAcTB1NhbGZvcmQxGjAYBgNVBAoTEUNPTU9ETyBDQSBMaW1p
dGVkMTkwNwYDVQQDEzBDT01PRE8gQ2xpZW50IEF1dGhlbnRpY2F0aW9uIGFuZCBTZWN1cmUg
RW1haWwgQ0ECEFwxUNvELajLmHIeX9p072YwgbsGCyqGSIb3DQEJEAILMYGroIGoMIGTMQsw
CQYDVQQGEwJHQjEbMBkGA1UECBMSR3JlYXRlciBNYW5jaGVzdGVyMRAwDgYDVQQHEwdTYWxm
b3JkMRowGAYDVQQKExFDT01PRE8gQ0EgTGltaXRlZDE5MDcGA1UEAxMwQ09NT0RPIENsaWVu
dCBBdXRoZW50aWNhdGlvbiBhbmQgU2VjdXJlIEVtYWlsIENBAhBcMVDbxC2oy5hyHl/adO9m
MA0GCSqGSIb3DQEBAQUABIIBAEmeedct3KRFdgwLtZwHKVM2+k9FHXm0z6IlXyhw3l7EqoXj
HKTacS4Or6jCk9gxTG30D+/4nGtPQN+WGgT6ldfDZQmmGEx+sEvCamVZw7XFSfF3HA4XULWq
eSTs9qBM8CuQeiNaxbKyAntK5bs/qTk7+8ZtAKAtpK5o5QZqxAOnKdBSkHsDA0FFCJxARqte
2KpciJCWDatIZOUT8eN8iLmx3/ij/7d8H6e2oDX5xQcGnSIDJj+Ngu8d/PKD+EeS//u9L5ro
vQodzVG/BOvhT+4SHcTw3TFJFmIkGHL08aOW3D1H9au246ckvI87TxOu7ZCAmBsDrl959hVv
V0N37scAAAAAAAA=
--------------ms090609020905070505000707--


From nobody Mon Jul 14 07:41:35 2014
Return-Path: <1095318589@qq.com>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 133C61A05C0 for <ace@ietfa.amsl.com>; Mon, 14 Jul 2014 07:41:34 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -0.755
X-Spam-Level: 
X-Spam-Status: No, score=-0.755 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_ENVFROM_END_DIGIT=0.25, FREEMAIL_FROM=0.001, FROM_EXCESS_BASE64=0.979, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, RP_MATCHES_RCVD=-0.651, SPF_SOFTFAIL=0.665] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Oydm-XcGBMgY for <ace@ietfa.amsl.com>; Mon, 14 Jul 2014 07:41:30 -0700 (PDT)
Received: from smtpbgau1.qq.com (smtpbgau1.qq.com [54.206.16.166]) by ietfa.amsl.com (Postfix) with SMTP id BF7F11A0537 for <ace@ietf.org>; Mon, 14 Jul 2014 07:41:29 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=qq.com; s=s201307; t=1405348887; bh=v1+oBuVDS/xG9Nx6mKBSXh1evd4lnzhVksoBpylpaNc=; h=X-QQ-FEAT:X-QQ-SSF:X-HAS-ATTACH:X-QQ-BUSINESS-ORIGIN: X-Originating-IP:X-QQ-STYLE:X-QQ-mid:From:To:Subject:Mime-Version:Content-Type:Content-Transfer-Encoding:Date: X-Priority:Message-ID:X-QQ-MIME:X-Mailer:X-QQ-Mailer: X-QQ-ReplyHash:X-QQ-SENDSIZE; b=w7HfdTAO44ohIiu715uU2PqZLMw7DJSA/CT5hOjP5/1iuXVOMHBNY/b09aY6XOOD6 hLIjwLaAaMAVRvlSwmvFzLgqJwE9I++CyV41J/gKjF3gteoHjwczP+WYiLxiMbaEad Xf/QkSxWq5OPEvg1CfJiA2dq6fcMh6nI54hnDf8c=
X-QQ-FEAT: xXPDKpQBGZzspf2z8ysqPgpP83aUpU3M1dJUzwYKdj0SX7ZV70FPvONs5yBsF 46sfGqJXRXnqAr2dd9K9pcmoMGtHxzjhTHCyvEOMiRNdSsTVFr/t1xRSeGIpPqdaxpNK5d9 qJWDfXwoMo0wtFO+GEDjmVSwPBLyO8IX2hpdmzOxGb/vdJNYUQ==
X-QQ-SSF: 0000000A000000F000000000000000M
X-HAS-ATTACH: no
X-QQ-BUSINESS-ORIGIN: 2
X-Originating-IP: 219.134.221.163
X-QQ-STYLE: 
X-QQ-mid: webmail431t1405348886t5982120
From: "=?utf-8?B?S2VwZW5nIExp?=" <1095318589@qq.com>
To: "=?utf-8?B?THVkd2lnIFNlaXR6?=" <ludwig@sics.se>, "=?utf-8?B?YWNlQGlldGYub3Jn?=" <ace@ietf.org>
Mime-Version: 1.0
Content-Type: multipart/alternative; boundary="----=_NextPart_53C3EC16_09180DB8_1D4BD5A1"
Content-Transfer-Encoding: 8Bit
Date: Mon, 14 Jul 2014 22:41:26 +0800
X-Priority: 3
Message-ID: <tencent_32B42D166ACEF73A17DCFD5A@qq.com>
X-QQ-MIME: TCMime 1.0 by Tencent
X-Mailer: QQMail 2.x
X-QQ-Mailer: QQMail 2.x
X-QQ-ReplyHash: 670115630
X-QQ-SENDSIZE: 520
X-QQ-Bgrelay: 1
Archived-At: http://mailarchive.ietf.org/arch/msg/ace/6yZ1bhTpOBXlM4uIIf3-FxK5fK0
Subject: Re: [Ace] Agenda
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 14 Jul 2014 14:41:34 -0000

This is a multi-part message in MIME format.

------=_NextPart_53C3EC16_09180DB8_1D4BD5A1
Content-Type: text/plain;
	charset="utf-8"
Content-Transfer-Encoding: base64

PiBXaGF0IGRvIHlvdSBtZWFuIHdpdGggIldoYXQgdHJhbnNwb3J0IHNob3VsZCBiZSB1c2Vk
PyIgSXMgdGhhdCB0aGUgRFRMUyB2cyBPYmplY3QgU2VjdXJpdHkgZGlzY3Vzc2lvbj/igI0N
Cg0KDQpUaGlzIGlzIHJlbGF0ZWQgdG8gdGhpcyBkaXNjdXNzaW9uOg0KaHR0cDovL3d3dy5p
ZXRmLm9yZy9tYWlsLWFyY2hpdmUvd2ViL2FjZS9jdXJyZW50L21zZzAwNjk1Lmh0bWzigI0N
Cg0KDQpLaW5kIFJlZ2FyZHMNCktlcGVuZw0KDQoNCi0tLS0tLS0tLS0tLS0tLS0tLSBPcmln
aW5hbCAtLS0tLS0tLS0tLS0tLS0tLS0NCkZyb206ICAiTHVkd2lnIFNlaXR6Ijs8bHVkd2ln
QHNpY3Muc2U+Ow0KRGF0ZTogIE1vbiwgSnVsIDE0LCAyMDE0IDA4OjQxIFBNDQpUbzogICJh
Y2UiPGFjZUBpZXRmLm9yZz47IA0KDQpTdWJqZWN0OiAgUmU6IFtBY2VdIEFnZW5kYQ0KDQoN
Cg0KX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX18NCkFj
ZSBtYWlsaW5nIGxpc3QNCkFjZUBpZXRmLm9yZw0KaHR0cHM6Ly93d3cuaWV0Zi5vcmcvbWFp
bG1hbi9saXN0aW5mby9hY2U=

------=_NextPart_53C3EC16_09180DB8_1D4BD5A1
Content-Type: text/html;
	charset="utf-8"
Content-Transfer-Encoding: base64

PGRpdj48dHQgc3R5bGU9ImxpbmUtaGVpZ2h0OiBub3JtYWw7Ij4mZ3Q7IFdoYXQgZG8geW91
IG1lYW4gd2l0aCAiV2hhdCB0cmFuc3BvcnQgc2hvdWxkIGJlIHVzZWQ/IiBJcyB0aGF0IHRo
ZSBEVExTJm5ic3A7PC90dD48dHQgc3R5bGU9ImxpbmUtaGVpZ2h0OiBub3JtYWw7Ij52cyBP
YmplY3QgU2VjdXJpdHkgZGlzY3Vzc2lvbj88c3BhbiBpZD0iX2VkaXRvcl9ib29rbWFya19z
dGFydF8xIiBzdHlsZT0iZGlzcGxheTogbm9uZTsgbGluZS1oZWlnaHQ6IDBweDsiPuKAjTwv
c3Bhbj48L3R0PjwvZGl2PjxkaXY+PGRpdj48YnI+PC9kaXY+PGRpdj5UaGlzIGlzIHJlbGF0
ZWQgdG8gdGhpcyBkaXNjdXNzaW9uOjwvZGl2PjxkaXY+aHR0cDovL3d3dy5pZXRmLm9yZy9t
YWlsLWFyY2hpdmUvd2ViL2FjZS9jdXJyZW50L21zZzAwNjk1Lmh0bWw8c3BhbiBpZD0iX2Vk
aXRvcl9ib29rbWFya19zdGFydF8yIiBzdHlsZT0iZGlzcGxheTogbm9uZTsgbGluZS1oZWln
aHQ6IDBweDsiPuKAjTwvc3Bhbj48L2Rpdj48ZGl2Pjxicj48L2Rpdj48ZGl2PktpbmQgUmVn
YXJkczwvZGl2PjxkaXY+S2VwZW5nPC9kaXY+PGRpdj48YnI+PC9kaXY+PGRpdiBzdHlsZT0i
Zm9udC1zaXplOiAxMnB4O2ZvbnQtZmFtaWx5OiBBcmlhbCBOYXJyb3c7cGFkZGluZzoycHgg
MCAycHggMDsiPi0tLS0tLS0tLS0tLS0tLS0tLSZuYnNwO09yaWdpbmFsJm5ic3A7LS0tLS0t
LS0tLS0tLS0tLS0tPC9kaXY+PGRpdiBzdHlsZT0iZm9udC1zaXplOiAxMnB4O2JhY2tncm91
bmQ6I2VmZWZlZjtwYWRkaW5nOjhweDsiPjxkaXY+PGI+RnJvbTogPC9iPiZuYnNwOyJMdWR3
aWcgU2VpdHoiOyZsdDtsdWR3aWdAc2ljcy5zZSZndDs7PC9kaXY+PGRpdj48Yj5EYXRlOiA8
L2I+Jm5ic3A7TW9uLCBKdWwgMTQsIDIwMTQgMDg6NDEgUE08L2Rpdj48ZGl2PjxiPlRvOiA8
L2I+Jm5ic3A7ImFjZSImbHQ7YWNlQGlldGYub3JnJmd0OzsgPHdicj48L2Rpdj48ZGl2Pjwv
ZGl2PjxkaXY+PGI+U3ViamVjdDogPC9iPiZuYnNwO1JlOiBbQWNlXSBBZ2VuZGE8L2Rpdj48
L2Rpdj48ZGl2Pjxicj48L2Rpdj5fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19f
X19fX19fX19fX19fXzxicj5BY2UgbWFpbGluZyBsaXN0PGJyPkFjZUBpZXRmLm9yZzxicj5o
dHRwczovL3d3dy5pZXRmLm9yZy9tYWlsbWFuL2xpc3RpbmZvL2FjZTxicj48YnI+PC9kaXY+


------=_NextPart_53C3EC16_09180DB8_1D4BD5A1--




From nobody Mon Jul 14 11:01:54 2014
Return-Path: <mcr@sandelman.ca>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id D8BA91A0AF9 for <ace@ietfa.amsl.com>; Mon, 14 Jul 2014 11:01:44 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.542
X-Spam-Level: 
X-Spam-Status: No, score=-2.542 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RP_MATCHES_RCVD=-0.651, SPF_PASS=-0.001, T_TVD_MIME_NO_HEADERS=0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id dnLMRPYVrw9z for <ace@ietfa.amsl.com>; Mon, 14 Jul 2014 11:01:42 -0700 (PDT)
Received: from tuna.sandelman.ca (tuna.sandelman.ca [209.87.249.19]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 959F71AD62A for <ace@ietf.org>; Mon, 14 Jul 2014 11:01:42 -0700 (PDT)
Received: from sandelman.ca (obiwan.sandelman.ca [209.87.249.21]) by tuna.sandelman.ca (Postfix) with ESMTP id 71D2820012; Mon, 14 Jul 2014 14:02:51 -0400 (EDT)
Received: by sandelman.ca (Postfix, from userid 179) id 3804B63B0E; Mon, 14 Jul 2014 14:01:39 -0400 (EDT)
Received: from sandelman.ca (localhost [127.0.0.1]) by sandelman.ca (Postfix) with ESMTP id 2963563AED; Mon, 14 Jul 2014 14:01:39 -0400 (EDT)
From: Michael Richardson <mcr+ietf@sandelman.ca>
To: Hannes Tschofenig <hannes.tschofenig@gmx.net>
In-Reply-To: <53C3C09A.5090707@gmx.net>
References: <53C3C09A.5090707@gmx.net>
X-Mailer: MH-E 8.2; nmh 1.3-dev; GNU Emacs 23.4.1
X-Face: $\n1pF)h^`}$H>Hk{L"x@)JS7<%Az}5RyS@k9X%29-lHB$Ti.V>2bi.~ehC0; <'$9xN5Ub# z!G,p`nR&p7Fz@^UXIn156S8.~^@MJ*mMsD7=QFeq%AL4m<nPbLgmtKK-5dC@#:k
MIME-Version: 1.0
Content-Type: multipart/signed; boundary="=-=-="; micalg=pgp-sha1; protocol="application/pgp-signature"
Date: Mon, 14 Jul 2014 14:01:39 -0400
Message-ID: <14018.1405360899@sandelman.ca>
Sender: mcr@sandelman.ca
Archived-At: http://mailarchive.ietf.org/arch/msg/ace/QyxpJ_4SQU5L04J51YTxtyBjTb4
Cc: "ace@ietf.org" <ace@ietf.org>
Subject: Re: [Ace] Offline operation of Resource Server
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 14 Jul 2014 18:01:45 -0000

--=-=-=


Hannes Tschofenig <hannes.tschofenig@gmx.net> wrote:
    > in one of my previous mail I said that the requirements rule out an
    > EAP/AAA solution and this impression was based on reading the following
    > requirement from http://tools.ietf.org/html/draft-seitz-ace-usecases-01

    > "
    > o  U5.2 The meters must be able to perform fine-grained access
    > control on the metering data and on the configuration while being
    > offline.
    > "

    > I was wondering how strong the requirement for not having a real-time
    > interaction between the resource server and the AS is.

I think it is important to have the tokens able to be validated offline
within some deployment specific time interval.  For some deployment "99
years" is exactly what is desired, for other deployments having to be online
is what is desired.

The missing piece is enrollment of devices (must be online), and associated
with that is the initial exchange of authorization tokens.

My view is that "enrollment" is really about establishment of the "superuser"
authorization token in the AS. In kerberos terms, it's the Ticket Granting
Ticket.

--
Michael Richardson <mcr+IETF@sandelman.ca>, Sandelman Software Works
 -= IPv6 IoT consulting =-




--=-=-=
Content-Type: application/pgp-signature

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iQEVAwUBU8QbAICLcPvd0N1lAQKGUggApc+jf+DYkM14/HA+cY9lXwiLAKup0Whs
xV8mOHOxJEV+y+KXGaWVEMMZHw3cuMWGEiRwHdHFXe21D/+S887+YWHnQypLh7Q3
MCm8/py4OcSVQ6QBdQ7raBiiDbRvZAiPiLuDpECgry73tkSwCRoXmA7bznAWO9Dr
gljdDGTKryO933AFhERr4mZ5swCwjPXfelyUwIv2WyVg/Sn2qlRZBp7nPCpnfv53
moo1e4l52ebbnrMh9DjCGkIYBl5you/0TykERdi72lfLE55YvEoAhvqv1Ak2LFNJ
RPnYqGl8GS22x7wUrHhrSYpCM0R0C2slK9bqhCNlFnFOmexGtsasPg==
=ZH/h
-----END PGP SIGNATURE-----
--=-=-=--


From nobody Mon Jul 14 11:53:03 2014
Return-Path: <hannes.tschofenig@gmx.net>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id DF3CD1A0065 for <ace@ietfa.amsl.com>; Mon, 14 Jul 2014 11:52:58 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.551
X-Spam-Level: 
X-Spam-Status: No, score=-2.551 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, FREEMAIL_FROM=0.001, RCVD_IN_DNSWL_NONE=-0.0001, RP_MATCHES_RCVD=-0.651, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id kQhMikiRJUWw for <ace@ietfa.amsl.com>; Mon, 14 Jul 2014 11:52:55 -0700 (PDT)
Received: from mout.gmx.net (mout.gmx.net [212.227.15.15]) (using TLSv1.2 with cipher DHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 978CD1A0061 for <ace@ietf.org>; Mon, 14 Jul 2014 11:52:55 -0700 (PDT)
Received: from [172.16.254.119] ([80.92.116.212]) by mail.gmx.com (mrgmx002) with ESMTPSA (Nemesis) id 0MBnvD-1XFFII0Mv1-00An3F; Mon, 14 Jul 2014 20:52:53 +0200
Message-ID: <53C42703.4060806@gmx.net>
Date: Mon, 14 Jul 2014 20:52:51 +0200
From: Hannes Tschofenig <hannes.tschofenig@gmx.net>
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:24.0) Gecko/20100101 Thunderbird/24.6.0
MIME-Version: 1.0
To: Michael Richardson <mcr+ietf@sandelman.ca>
References: <53C3C09A.5090707@gmx.net> <14018.1405360899@sandelman.ca>
In-Reply-To: <14018.1405360899@sandelman.ca>
X-Enigmail-Version: 1.5.2
OpenPGP: id=4D776BC9
Content-Type: multipart/signed; micalg=pgp-sha512; protocol="application/pgp-signature"; boundary="qvgkFDk67gCaOfcJUvgHWLmTcbtm4ATsc"
X-Provags-ID: V03:K0:R2qJS7h4/L2HF1rMM2e/rfI279IgsofUXvWK7vRsDdlezrA6I5Q J6/GpY2MboVxJT4+SOqEWLVJsuRS6LujJZOedHGxXDRJgwTt6i5eSwRIAvi+URNh5dvlFtx UxrLl3MUNeZ58CeeD/XgRy1KN/LJjKRjqrSSYSh8vQpLsHIU+uK9Mm/yPIk6pMxELEuMl+t HhNiXTBgG2qyYK78Tud5Q==
Archived-At: http://mailarchive.ietf.org/arch/msg/ace/UdleBzMPsT0IKEg6JL5311mwIJI
Cc: "ace@ietf.org" <ace@ietf.org>
Subject: Re: [Ace] Offline operation of Resource Server
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 14 Jul 2014 18:52:59 -0000

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--qvgkFDk67gCaOfcJUvgHWLmTcbtm4ATsc
Content-Type: text/plain; charset=ISO-8859-1
Content-Transfer-Encoding: quoted-printable

To re-use the Kerberos language, the client gets the TGT. The real-time
interaction I was talking about relates to the interaction between the
resource server and the authorization server.

Maybe the language in the use case document needs to be a bit more explic=
it.

Ludwig, could you please explain this offline requirement a bit more?

Ciao
Hannes


On 07/14/2014 08:01 PM, Michael Richardson wrote:
>=20
> Hannes Tschofenig <hannes.tschofenig@gmx.net> wrote:
>     > in one of my previous mail I said that the requirements rule out =
an
>     > EAP/AAA solution and this impression was based on reading the fol=
lowing
>     > requirement from http://tools.ietf.org/html/draft-seitz-ace-useca=
ses-01
>=20
>     > "
>     > o  U5.2 The meters must be able to perform fine-grained access
>     > control on the metering data and on the configuration while being=

>     > offline.
>     > "
>=20
>     > I was wondering how strong the requirement for not having a real-=
time
>     > interaction between the resource server and the AS is.
>=20
> I think it is important to have the tokens able to be validated offline=

> within some deployment specific time interval.  For some deployment "99=

> years" is exactly what is desired, for other deployments having to be o=
nline
> is what is desired.
>=20
> The missing piece is enrollment of devices (must be online), and associ=
ated
> with that is the initial exchange of authorization tokens.
>=20
> My view is that "enrollment" is really about establishment of the "supe=
ruser"
> authorization token in the AS. In kerberos terms, it's the Ticket Grant=
ing
> Ticket.
>=20
> --
> Michael Richardson <mcr+IETF@sandelman.ca>, Sandelman Software Works
>  -=3D IPv6 IoT consulting =3D-
>=20
>=20
>=20


--qvgkFDk67gCaOfcJUvgHWLmTcbtm4ATsc
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
Content-Disposition: attachment; filename="signature.asc"

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1
Comment: GPGTools - http://gpgtools.org
Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/

iQEcBAEBCgAGBQJTxCcDAAoJEGhJURNOOiAtV+sH/0MouqcgjqKcxWoyv0XoBGx9
O/yP4JkrYThDXiwcfe8nJ2w1/oIxDfyJOQBz9uheSZM8Bazc7R+eAXsC9tSxGIqS
Ph9jr/Rd69R3fthCeHSNNYXCSMkod9d9NOw1B1Ez0Yn8929uP2LvE0SAUXI6YzLk
HATQReCoJ+MazcYI7L2RkKHqRG8Icyz9Ry39+v+6b1dEUk0B02ofnFPL4ZrNBC15
RouiucPaunc0SCSbnWIBOHy7Wf0Zy68sK7VcIX9uXZ4E5YswC7qTIEkXDrX9DSUE
O500xV+NMfH6KcMDu1j3wCUqd9ZddFdCHDSQxxPOm5YBQMrqnR7BvYwPwOqeZus=
=rfS6
-----END PGP SIGNATURE-----

--qvgkFDk67gCaOfcJUvgHWLmTcbtm4ATsc--


From nobody Mon Jul 14 13:12:22 2014
Return-Path: <mcr@sandelman.ca>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id BE4391A0ACE for <ace@ietfa.amsl.com>; Mon, 14 Jul 2014 13:12:18 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.542
X-Spam-Level: 
X-Spam-Status: No, score=-2.542 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RP_MATCHES_RCVD=-0.651, SPF_PASS=-0.001, T_TVD_MIME_NO_HEADERS=0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 4nwbMWbAoauq for <ace@ietfa.amsl.com>; Mon, 14 Jul 2014 13:12:17 -0700 (PDT)
Received: from tuna.sandelman.ca (tuna.sandelman.ca [IPv6:2607:f0b0:f:3:216:3eff:fe7c:d1f3]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 493141A00A3 for <ace@ietf.org>; Mon, 14 Jul 2014 13:12:17 -0700 (PDT)
Received: from sandelman.ca (obiwan.sandelman.ca [IPv6:2607:f0b0:f:2::247]) by tuna.sandelman.ca (Postfix) with ESMTP id D76F720028; Mon, 14 Jul 2014 16:13:27 -0400 (EDT)
Received: by sandelman.ca (Postfix, from userid 179) id 3466163B0E; Mon, 14 Jul 2014 16:12:16 -0400 (EDT)
Received: from sandelman.ca (localhost [127.0.0.1]) by sandelman.ca (Postfix) with ESMTP id 1FDC463AED; Mon, 14 Jul 2014 16:12:16 -0400 (EDT)
From: Michael Richardson <mcr+ietf@sandelman.ca>
To: Hannes Tschofenig <hannes.tschofenig@gmx.net>
In-Reply-To: <53C42703.4060806@gmx.net>
References: <53C3C09A.5090707@gmx.net> <14018.1405360899@sandelman.ca> <53C42703.4060806@gmx.net>
X-Mailer: MH-E 8.2; nmh 1.3-dev; GNU Emacs 23.4.1
X-Face: $\n1pF)h^`}$H>Hk{L"x@)JS7<%Az}5RyS@k9X%29-lHB$Ti.V>2bi.~ehC0; <'$9xN5Ub# z!G,p`nR&p7Fz@^UXIn156S8.~^@MJ*mMsD7=QFeq%AL4m<nPbLgmtKK-5dC@#:k
MIME-Version: 1.0
Content-Type: multipart/signed; boundary="=-=-="; micalg=pgp-sha1; protocol="application/pgp-signature"
Date: Mon, 14 Jul 2014 16:12:16 -0400
Message-ID: <8236.1405368736@sandelman.ca>
Sender: mcr@sandelman.ca
Archived-At: http://mailarchive.ietf.org/arch/msg/ace/cI5VbveuXBWk1nrP9WP2HBRJXwE
Cc: "ace@ietf.org" <ace@ietf.org>
Subject: Re: [Ace] Offline operation of Resource Server
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 14 Jul 2014 20:12:18 -0000

--=-=-=


Hannes Tschofenig <hannes.tschofenig@gmx.net> wrote:
    > To re-use the Kerberos language, the client gets the TGT. The real-time
    > interaction I was talking about relates to the interaction between the
    > resource server and the authorization server.

During enrollment, the Authorization Server gets a TGT on the *resource* server.
Given that, it can now issue new tickets to clients that come along that wish
to access the resource.  The client, during enrollment, asks the (possibly
federated list of) authorization servers for a resource ticket.
(This is why part of network join needs to be in scope for ACE)

All of the above has to occur online.

Once the client has the resource ticket, the resource server can validate it offline.

--
Michael Richardson <mcr+IETF@sandelman.ca>, Sandelman Software Works
 -= IPv6 IoT consulting =-




--=-=-=
Content-Type: application/pgp-signature

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iQEVAwUBU8Q5nYCLcPvd0N1lAQIiDwf7Bc3+Zbwa/LgCK9hhzmDUozTLHCwLtGXI
faYbRbfOCrTRx+ToIw3l21oxPJGNIqnCdy05LWdo+Mi/EYkPJ2oXGZt1WoDavI8J
EbarrkZ7zgv/XnihtS1FVtfiOweyQpiGstLDtGLpwwPu80EPBiXUvvtMlxldh247
x/GsRHKKVwfRTUM/b5oAqDnEglYmhlTY6oUHZbtu3YMnMPIGRP9YoBA2tBv3vBCK
8LHCMD1prILKgx/4tYI01NXgzmMRxUKtI7C9rqo4YsuMhTgvBxvbXgdtrBh5c8z1
iF2Oy7kLLxtV/t3cUQf986irO+UXrsIrGi8ILn62pSqRMtpVBJzKww==
=4bqu
-----END PGP SIGNATURE-----
--=-=-=--


From nobody Mon Jul 14 17:40:06 2014
Return-Path: <likepeng@huawei.com>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id A0BA81B27CF for <ace@ietfa.amsl.com>; Mon, 14 Jul 2014 17:40:04 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -3.852
X-Spam-Level: 
X-Spam-Status: No, score=-3.852 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, J_BACKHAIR_22=1, RCVD_IN_DNSWL_MED=-2.3, RP_MATCHES_RCVD=-0.651, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id TFldXTO_ibXx for <ace@ietfa.amsl.com>; Mon, 14 Jul 2014 17:40:02 -0700 (PDT)
Received: from lhrrgout.huawei.com (lhrrgout.huawei.com [194.213.3.17]) (using TLSv1 with cipher RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id E329A1B27C5 for <ace@ietf.org>; Mon, 14 Jul 2014 17:40:01 -0700 (PDT)
Received: from 172.18.7.190 (EHLO lhreml401-hub.china.huawei.com) ([172.18.7.190]) by lhrrg02-dlp.huawei.com (MOS 4.3.7-GA FastPath queued) with ESMTP id BHE64087; Tue, 15 Jul 2014 00:40:00 +0000 (GMT)
Received: from SZXEMA409-HUB.china.huawei.com (10.82.72.41) by lhreml401-hub.china.huawei.com (10.201.5.240) with Microsoft SMTP Server (TLS) id 14.3.158.1; Tue, 15 Jul 2014 01:39:59 +0100
Received: from SZXEMA501-MBS.china.huawei.com ([169.254.2.128]) by SZXEMA409-HUB.china.huawei.com ([10.82.72.41]) with mapi id 14.03.0158.001; Tue, 15 Jul 2014 08:39:52 +0800
From: Likepeng <likepeng@huawei.com>
To: Ludwig Seitz <ludwig@sics.se>, "ace@ietf.org" <ace@ietf.org>
Thread-Topic: [Ace] Agenda
Thread-Index: AQHPn0An/g57BwoFQUmznqbDcdEHpJue/WCAgAFNU3A=
Date: Tue, 15 Jul 2014 00:39:51 +0000
Message-ID: <34966E97BE8AD64EAE9D3D6E4DEE36F258177D9A@SZXEMA501-MBS.china.huawei.com>
References: <53C398ED.3030302@gmx.net> <53C3D013.6030006@sics.se>
In-Reply-To: <53C3D013.6030006@sics.se>
Accept-Language: zh-CN, en-US
Content-Language: zh-CN
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
x-originating-ip: [10.66.167.122]
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: base64
MIME-Version: 1.0
X-CFilter-Loop: Reflected
Archived-At: http://mailarchive.ietf.org/arch/msg/ace/B6XsIa1klZA-LLsWwGO0vEtXr0E
Subject: Re: [Ace] Agenda
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 15 Jul 2014 00:40:04 -0000

PiBXaGF0IGRvIHlvdSBtZWFuIHdpdGggdGhlICJPQXV0aC9LZXJiZXJvcyBkZXNpZ24gcGF0dGVy
biI/IElzIHRoYXQgdGhlDQo+IENsaWVudCwgUlMsIEFTIGFyY2hpdGVjdHVyZT8NCg0KWWVzLg0K
DQo+IEkgdGhpbmsgdGhpcyBxdWVzdGlvbiAoM2MpIGlzIHRvbyBnZW5lcmljLiBJZiB3ZSBhc2sg
bGlrZSB0aGF0LCB3ZSB3aWxsIGp1c3QgcmVpdGVyYXRlDQo+IHRoZSBkaXNjdXNzaW9ucyBjdXJy
ZW50bHkgb25nb2luZyBvbiB0aGUgRElDRSBsaXN0IChzZWUgdGhlICJUeXJhbm55IG9mIHRoZQ0K
PiBMaWdodHN3aXRjaCIgdGhyZWFkKS4NCg0KV2UgY2FuIGdvIGEgbGl0dGxlIGJpdCBmdXJ0aGVy
Og0KLSBsb25nLXRlcm0ga2V5IGVzdGFibGlzaGVkIGJldHdlZW4gdGhlIGNsaWVudCBhbmQgdGhl
IGF1dGhvcml6YXRpb24gc2VydmVyDQotIGxvbmctdGVybSBrZXkgZXN0YWJsaXNoZWQgYmV0d2Vl
biB0aGUgYXV0aG9yaXphdGlvbiBzZXJ2ZXIgYW5kIHRoZSByZXNvdXJjZSBzZXJ2ZXINCi0gc2hv
cnQgdGVybSBrZXkgZXN0YWJsaXNoZWQgYmV0d2VlbiB0aGUgY2xpZW50IGFuZCB0aGUgcmVzb3Vy
Y2Ugc2VydmVyDQoNCkFsc28gd2UgbmVlZCB0byB0YWxrIGFib3V0IHBlcmZvcm1hbmNlLCBzaXpl
LCAuLi4uIGFuZCBvdGhlciBjb25zaWRlcmF0aW9ucy4NCg0KS2luZCBSZWdhcmRzDQpLZXBlbmcN
Cg0KPiAtLS0tLemCruS7tuWOn+S7ti0tLS0tDQo+IOWPkeS7tuS6ujogQWNlIFttYWlsdG86YWNl
LWJvdW5jZXNAaWV0Zi5vcmddIOS7o+ihqCBMdWR3aWcgU2VpdHoNCj4g5Y+R6YCB5pe26Ze0OiAy
MDE05bm0N+aciDE05pelIDIwOjQyDQo+IOaUtuS7tuS6ujogYWNlQGlldGYub3JnDQo+IOS4u+mi
mDogUmU6IFtBY2VdIEFnZW5kYQ0KPiANCj4gSGkgSGFubmVzLA0KPiANCj4ganVzdCBzb21lIHJl
cXVlc3RzIGZvciBjbGFyaWZpY2F0aW9uLiBTZWUgaW5saW5lLg0KPiANCj4gL0x1ZHdpZw0KPiAN
Cj4gT24gMDcvMTQvMjAxNCAxMDo0NiBBTSwgSGFubmVzIFRzY2hvZmVuaWcgd3JvdGU6DQo+IFsu
Li5dDQo+ID4gQXV0aGVudGljYXRpb24gYW5kIEF1dGhvcml6YXRpb24gZm9yIENvbnN0cmFpbmVk
IEVudmlyb25tZW50cyAoQUNFKQ0KPiA+DQo+ID4gV0VETkVTREFZLCBKdWx5IDIzLCAyMDE0DQo+
ID4NCj4gPiAwOTAwLTExMzAgRURUDQo+ID4gVHVkb3IgNy84IChNTSkNCj4gPg0KPiA+IC0gV2Vs
Y29tZSAmIEFnZW5kYSBCYXNoaW5nIChDaGFpcnMsIDEwIG1pbnMpDQo+ID4NCj4gPiAtIEFDRSBJ
bnRyb2R1Y3Rpb24gKENoYWlycywgMTAgbWlucykNCj4gPg0KPiA+IFNpbmNlIHRoaXMgaXMgdGhl
IGZpcnN0IG1lZXRpbmcgb2YgdGhlIHdvcmtpbmcgZ3JvdXAgd2Ugd291bGQgbGlrZSB0bw0KPiA+
IGdpdmUgYSBicmllZiBkZXNjcmlwdGlvbiB0aGUgaGlnaCBsZXZlbCBnb2FsIG9mIHRoZSBncm91
cC4gVGhpcyBwYXJ0DQo+ID4gb2YgdGhlIGFnZW5kYSBzaG91bGQgYWxzbyBoZWxwIHlvdSB0byBi
ZWNvbWUgZmFtaWxpYXIgd2l0aCB0aGUgdGVybWlub2xvZ3kuDQo+ID4NCj4gPiAtIERlc2lnbiBE
aXJlY3Rpb25zDQo+ID4NCj4gPiBXZSB3YW50IHRvIHNwZW5kIHRoZSBtYWluIG1lZXRpbmcgdGlt
ZSB0byBhbnN3ZXIgYSBjb3VwbGUgb2YNCj4gPiBjaGFsbGVuZ2luZyBxdWVzdGlvbnMuDQo+ID4g
T3VyIGhvcGUgaXMgaXQgdG8gZ2V0IGFuc3dlcnMgdG8gc29tZSBvZiB0aGVzZSBxdWVzdGlvbnMg
ZHVyaW5nIHRoZQ0KPiA+IG1lZXRpbmcgb3IgaW4gcHJlcGFyYXRpb24gb2YgdGhlIG1lZXRpbmcu
DQo+ID4NCj4gPiAxKSBQcm9ibGVtIERlc2NyaXB0aW9uDQo+ID4NCj4gPiAxYSkgQ2xpZW50IDwt
PiBSUyBDb21tdW5pY2F0aW9uOiBXaGF0IHRyYW5zcG9ydCBzaG91bGQgYmUgdXNlZD8NCj4gPiAx
YikgV2hhdCBkZWdyZWUgb2YgZmxleGliaWxpdHkgc2hvdWxkIHdlIGFpbSBmb3I/IERUTFMgb3Ig
YXBwbGljYXRpb24NCj4gPiBsYXllciBzZWN1cml0eT8NCj4gDQo+IFdoYXQgZG8geW91IG1lYW4g
d2l0aCAiV2hhdCB0cmFuc3BvcnQgc2hvdWxkIGJlIHVzZWQ/IiBJcyB0aGF0IHRoZSBEVExTIHZz
DQo+IE9iamVjdCBTZWN1cml0eSBkaXNjdXNzaW9uPw0KPiANCj4gPg0KPiA+IFtbUmVsZXZhbnQg
ZG9jdW1lbnQ6IGRyYWZ0LXNlaXR6LWFjZS1wcm9ibGVtLWRlc2NyaXB0aW9uLTAxXV0NCj4gPg0K
PiA+IERpc2N1c3Npb24gTGVhZGVyOiBMdWR3aWcgKHRvLWJlLWNvbmZpcm1lZCkNCj4gPg0KPiA+
IDIpIERlc2lnbiBQYXR0ZXJucw0KPiA+DQo+ID4gMmEpIElzIHRoZSBPQXV0aC9LZXJiZXJvcyBk
ZXNpZ24gcGF0dGVybiBzdWZmaWNpZW50Pw0KPiA+IChkb2VzIGl0IGNvdmVyIGFsbCB0aGUgdXNl
IGNhc2VzKQ0KPiA+IDJiKSBJcyB0aGUgT0FVVEgvS2VyYmVyb3MgZGVzaWduIHBhdHRlcm4gbmVj
ZXNzYXJ5Pw0KPiA+IChjYW4gd2UgdGhyb3cgc29tZXRoaW5nIGF3YXk/KQ0KPiA+DQo+ID4gW1tS
ZWxldmFudCBkb2N1bWVudDogZHJhZnQtc2VpdHotYWNlLXVzZWNhc2VzLTAxXV0NCj4gPg0KPiA+
IERpc2N1c3Npb24gTGVhZGVyOiBMdWR3aWcgKHRvLWJlLWNvbmZpcm1lZCkNCj4gPg0KPiANCj4g
V2hhdCBkbyB5b3UgbWVhbiB3aXRoIHRoZSAiT0F1dGgvS2VyYmVyb3MgZGVzaWduIHBhdHRlcm4i
PyBJcyB0aGF0IHRoZQ0KPiBDbGllbnQsIFJTLCBBUyBhcmNoaXRlY3R1cmU/IERvZXMgaXQgaW5j
bHVkZSB0aGUgYXV0aG9yaXphdGlvbiBwdXNoIHNlcXVlbmNlIG9yDQo+IGNvdWxkIGl0IGJlIGFu
eSBvdGhlciAocHVsbCBvciBhZ2VudCk/DQo+IA0KPiANCj4gPiAzKSBEZXNpZ24gQ29uc2lkZXJh
dGlvbnMNCj4gPg0KPiA+IDNhKSBXaGF0IGRlc2lnbiBjb21wb25lbnRzIGNvdWxkIHdlIHJlLXVz
ZT8NCj4gPiAzYikgV2hhdCBhcmVhcyBuZWVkIHRvIGJlIGV4cGxvcmVkIGluIG1vcmUgZGV0YWls
Pw0KPiA+DQo+ID4gRXhhbXBsZSB0b3BpY3M6DQo+ID4NCj4gPiAgICAqIFJTPC0+QVMgQ29tbXVu
aWNhdGlvbjogSW4gc2NvcGUgLyBvdXQgb2Ygc2NvcGU/DQo+ID4gICAgKiBQcm90b2NvbCByZS11
c2U6IHdoYXQncyBnb29kIGFuZCB3aGF0J3Mgbm90Pw0KPiA+ICAgICogTWVzc2FnZSBlbmNvZGlu
ZzogQmFzZTY0LCBKU09OLCBBU04uMSwgQ0JPUg0KPiA+DQo+ID4gM2MpIFNob3VsZCB0aGUgZGVz
aWduIGJlIGJhc2VkIG9uIHN5bW1ldHJpYyBvciBhc3ltbWV0cmljIGNyeXB0bz8NCj4gPiAgICAo
b3IgYm90aD8pDQo+IA0KPiBJIHRoaW5rIHRoaXMgcXVlc3Rpb24gKDNjKSBpcyB0b28gZ2VuZXJp
Yy4gSWYgd2UgYXNrIGxpa2UgdGhhdCwgd2Ugd2lsbCBqdXN0IHJlaXRlcmF0ZQ0KPiB0aGUgZGlz
Y3Vzc2lvbnMgY3VycmVudGx5IG9uZ29pbmcgb24gdGhlIERJQ0UgbGlzdCAoc2VlIHRoZSAiVHly
YW5ueSBvZiB0aGUNCj4gTGlnaHRzd2l0Y2giIHRocmVhZCkuDQo+IA0KPiBXZSBzaG91bGQgcmVh
bGx5IHRyeSB0byBnZXQgaW5wdXQgb24gd2hhdCBpcyBsaWtlbHkgdG8gYmUgc3VwcG9ydGVkIGJ5
DQo+IG1hbnVmYWN0dXJlcnMgb2YgbWFzcyBtYXJrZXQgSW9UIGhhcmR3YXJlLg0KPiANCj4gDQo+
IC9MdWR3aWcNCj4gDQo+IA0KPiANCj4gLS0NCj4gTHVkd2lnIFNlaXR6LCBQaEQNCj4gU0lDUyBT
d2VkaXNoIElDVCBBQg0KPiBJZGVvbiBTY2llbmNlIFBhcmsNCj4gQnVpbGRpbmcgQmV0YSAyDQo+
IFNjaGVlbGV2w6RnZW4gMTcNCj4gU0UtMjIzIDcwIEx1bmQNCj4gDQo+IFBob25lICs0NigwKTcw
LTM0OSA5MiA1MQ0KPiBodHRwOi8vd3d3LnNpY3Muc2UNCg0K


From nobody Mon Jul 14 20:19:39 2014
Return-Path: <likepeng@huawei.com>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 8E5F41B2807 for <ace@ietfa.amsl.com>; Mon, 14 Jul 2014 20:19:38 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.851
X-Spam-Level: 
X-Spam-Status: No, score=-4.851 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_MED=-2.3, RP_MATCHES_RCVD=-0.651, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id IHqXokolhpdT for <ace@ietfa.amsl.com>; Mon, 14 Jul 2014 20:19:36 -0700 (PDT)
Received: from lhrrgout.huawei.com (lhrrgout.huawei.com [194.213.3.17]) (using TLSv1 with cipher RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 6628E1B2805 for <ace@ietf.org>; Mon, 14 Jul 2014 20:19:35 -0700 (PDT)
Received: from 172.18.7.190 (EHLO lhreml404-hub.china.huawei.com) ([172.18.7.190]) by lhrrg01-dlp.huawei.com (MOS 4.3.7-GA FastPath queued) with ESMTP id BKA84991; Tue, 15 Jul 2014 03:19:33 +0000 (GMT)
Received: from SZXEMA407-HUB.china.huawei.com (10.82.72.39) by lhreml404-hub.china.huawei.com (10.201.5.218) with Microsoft SMTP Server (TLS) id 14.3.158.1; Tue, 15 Jul 2014 04:19:32 +0100
Received: from SZXEMA501-MBS.china.huawei.com ([169.254.2.128]) by SZXEMA407-HUB.china.huawei.com ([10.82.72.39]) with mapi id 14.03.0158.001; Tue, 15 Jul 2014 11:19:29 +0800
From: Likepeng <likepeng@huawei.com>
To: "ace@ietf.org" <ace@ietf.org>
Thread-Topic: Context-based Authorization
Thread-Index: Ac+f25RPZA4DKMAaSV63emGWMOjF3A==
Date: Tue, 15 Jul 2014 03:19:28 +0000
Message-ID: <34966E97BE8AD64EAE9D3D6E4DEE36F258177EE3@SZXEMA501-MBS.china.huawei.com>
Accept-Language: zh-CN, en-US
Content-Language: zh-CN
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
x-originating-ip: [10.66.167.122]
Content-Type: multipart/alternative; boundary="_000_34966E97BE8AD64EAE9D3D6E4DEE36F258177EE3SZXEMA501MBSchi_"
MIME-Version: 1.0
X-CFilter-Loop: Reflected
Archived-At: http://mailarchive.ietf.org/arch/msg/ace/VEA9vdhlQofOAI7N7Lh6uEDBVN4
Subject: [Ace] Context-based Authorization
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 15 Jul 2014 03:19:38 -0000

--_000_34966E97BE8AD64EAE9D3D6E4DEE36F258177EE3SZXEMA501MBSchi_
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable

Hi all,

Personally I am wondering whether or not we should support context-based au=
thorization indicated in http://tools.ietf.org/html/draft-seitz-ace-usecase=
s-01.

For U2.4, do we want to achieve something like this: if time is 9:00 ~ 18:0=
0, Client A is allowed to turn on a light, but Client B is not allowed?

To me, this is purely Resource Server side policy setting and enforcement. =
Does it require any information exchange with Authorization Server? Is it n=
ecessary?

About presence, does it mean online / offline status? If yes, this should b=
e covered by another requirement U5.2, which was discussed in another discu=
ssion thread "offline operation".

   o  U2.4 Jane must be able to apply context-based conditions
      (presence, time) to authorizations, and the devices (door-lock or
      alarm) need to be able to verify these conditions.

For U3.1, how to define an emergency context?


   o  U3.1 John must be able to pre-configure access rights to the

      position data for persons or groups, in the context of an

      emergency.



Thanks,



Kind Regards

Kepeng






--_000_34966E97BE8AD64EAE9D3D6E4DEE36F258177EE3SZXEMA501MBSchi_
Content-Type: text/html; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable

<html xmlns:v=3D"urn:schemas-microsoft-com:vml" xmlns:o=3D"urn:schemas-micr=
osoft-com:office:office" xmlns:w=3D"urn:schemas-microsoft-com:office:word" =
xmlns:m=3D"http://schemas.microsoft.com/office/2004/12/omml" xmlns=3D"http:=
//www.w3.org/TR/REC-html40">
<head>
<meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3Dus-ascii"=
>
<meta name=3D"Generator" content=3D"Microsoft Word 12 (filtered medium)">
<style><!--
/* Font Definitions */
@font-face
	{font-family:SimSun;
	panose-1:2 1 6 0 3 1 1 1 1 1;}
@font-face
	{font-family:"Cambria Math";
	panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
	{font-family:Calibri;
	panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
	{font-family:SimSun;
	panose-1:2 1 6 0 3 1 1 1 1 1;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
	{margin:0cm;
	margin-bottom:.0001pt;
	text-align:justify;
	text-justify:inter-ideograph;
	font-size:10.5pt;
	font-family:"Calibri","sans-serif";}
a:link, span.MsoHyperlink
	{mso-style-priority:99;
	color:blue;
	text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
	{mso-style-priority:99;
	color:purple;
	text-decoration:underline;}
pre
	{mso-style-priority:99;
	mso-style-link:"HTML \9884\8BBE\683C\5F0F Char";
	margin:0cm;
	margin-bottom:.0001pt;
	font-size:12.0pt;
	font-family:SimSun;}
span.EmailStyle17
	{mso-style-type:personal-compose;
	font-family:"Calibri","sans-serif";
	color:windowtext;}
span.HTMLChar
	{mso-style-name:"HTML \9884\8BBE\683C\5F0F Char";
	mso-style-priority:99;
	mso-style-link:"HTML \9884\8BBE\683C\5F0F";
	font-family:SimSun;}
.MsoChpDefault
	{mso-style-type:export-only;}
/* Page Definitions */
@page WordSection1
	{size:612.0pt 792.0pt;
	margin:72.0pt 90.0pt 72.0pt 90.0pt;}
div.WordSection1
	{page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext=3D"edit" spidmax=3D"1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext=3D"edit">
<o:idmap v:ext=3D"edit" data=3D"1" />
</o:shapelayout></xml><![endif]-->
</head>
<body lang=3D"ZH-CN" link=3D"blue" vlink=3D"purple" style=3D"text-justify-t=
rim:punctuation">
<div class=3D"WordSection1">
<p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:8.0pt">Hi al=
l,<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:8.0pt"><o:p>=
&nbsp;</o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:8.0pt">Perso=
nally I am wondering whether or not we should support context-based authori=
zation indicated in
<a href=3D"http://tools.ietf.org/html/draft-seitz-ace-usecases-01">http://t=
ools.ietf.org/html/draft-seitz-ace-usecases-01</a>.<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:8.0pt"><o:p>=
&nbsp;</o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:8.0pt">For U=
2.4, do we want to achieve something like this: if time is 9:00 ~ 18:00, Cl=
ient A is allowed to turn on a light, but Client B is not allowed?<o:p></o:=
p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:8.0pt"><o:p>=
&nbsp;</o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:8.0pt">To me=
, this is purely Resource Server side policy setting and enforcement. Does =
it require any information exchange with Authorization Server? Is it necess=
ary?<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:8.0pt"><o:p>=
&nbsp;</o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:8.0pt">About=
 presence, does it mean online / offline status? If yes, this should be cov=
ered by another requirement U5.2, which was discussed in another discussion=
 thread &#8220;offline operation&#8221;.<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:8.0pt"><o:p>=
&nbsp;</o:p></span></p>
<p class=3D"MsoNormal" align=3D"left" style=3D"text-align:left"><span lang=
=3D"EN-US" style=3D"font-size:8.0pt">&nbsp;&nbsp; o&nbsp; U2.4 Jane must be=
 able to apply context-based conditions<o:p></o:p></span></p>
<p class=3D"MsoNormal" align=3D"left" style=3D"text-align:left"><span lang=
=3D"EN-US" style=3D"font-size:8.0pt">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; (presen=
ce, time) to authorizations, and the devices (door-lock or<o:p></o:p></span=
></p>
<p class=3D"MsoNormal" align=3D"left" style=3D"text-align:left"><span lang=
=3D"EN-US" style=3D"font-size:8.0pt">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; alarm) =
need to be able to verify these conditions.<o:p></o:p></span></p>
<p class=3D"MsoNormal" align=3D"left" style=3D"text-align:left"><span lang=
=3D"EN-US" style=3D"font-size:8.0pt"><o:p>&nbsp;</o:p></span></p>
<p class=3D"MsoNormal" align=3D"left" style=3D"text-align:left"><span lang=
=3D"EN-US" style=3D"font-size:8.0pt">For U3.1, how to define an emergency c=
ontext?<o:p></o:p></span></p>
<p class=3D"MsoNormal" align=3D"left" style=3D"text-align:left"><span lang=
=3D"EN-US" style=3D"font-size:8.0pt"><o:p>&nbsp;</o:p></span></p>
<pre><span lang=3D"EN-US" style=3D"font-size:8.0pt;font-family:&quot;Calibr=
i&quot;,&quot;sans-serif&quot;">&nbsp;&nbsp; o&nbsp; U3.1 John must be able=
 to pre-configure access rights to the<o:p></o:p></span></pre>
<pre><span lang=3D"EN-US" style=3D"font-size:8.0pt;font-family:&quot;Calibr=
i&quot;,&quot;sans-serif&quot;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; position dat=
a for persons or groups, in the context of an<o:p></o:p></span></pre>
<pre><span lang=3D"EN-US" style=3D"font-size:8.0pt;font-family:&quot;Calibr=
i&quot;,&quot;sans-serif&quot;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; emergency.<o=
:p></o:p></span></pre>
<pre><span lang=3D"EN-US" style=3D"font-size:8.0pt;font-family:&quot;Calibr=
i&quot;,&quot;sans-serif&quot;"><o:p>&nbsp;</o:p></span></pre>
<pre><span lang=3D"EN-US" style=3D"font-size:8.0pt;font-family:&quot;Calibr=
i&quot;,&quot;sans-serif&quot;">Thanks,<o:p></o:p></span></pre>
<pre><span lang=3D"EN-US" style=3D"font-size:8.0pt;font-family:&quot;Calibr=
i&quot;,&quot;sans-serif&quot;"><o:p>&nbsp;</o:p></span></pre>
<pre><span lang=3D"EN-US" style=3D"font-size:8.0pt;font-family:&quot;Calibr=
i&quot;,&quot;sans-serif&quot;">Kind Regards<o:p></o:p></span></pre>
<pre><span lang=3D"EN-US" style=3D"font-size:8.0pt;font-family:&quot;Calibr=
i&quot;,&quot;sans-serif&quot;">Kepeng<o:p></o:p></span></pre>
<pre><span lang=3D"EN-US" style=3D"font-size:8.0pt;font-family:&quot;Calibr=
i&quot;,&quot;sans-serif&quot;"><o:p>&nbsp;</o:p></span></pre>
<pre><span lang=3D"EN-US"><o:p>&nbsp;</o:p></span></pre>
<p class=3D"MsoNormal"><span lang=3D"EN-US"><o:p>&nbsp;</o:p></span></p>
</div>
</body>
</html>

--_000_34966E97BE8AD64EAE9D3D6E4DEE36F258177EE3SZXEMA501MBSchi_--


From nobody Mon Jul 14 20:31:14 2014
Return-Path: <likepeng@huawei.com>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 00AF71B2805 for <ace@ietfa.amsl.com>; Mon, 14 Jul 2014 20:31:14 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.063
X-Spam-Level: 
X-Spam-Status: No, score=-2.063 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, CN_BODY_35=0.339, MIME_CHARSET_FARAWAY=2.45, RCVD_IN_DNSWL_MED=-2.3, RP_MATCHES_RCVD=-0.651, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id nScwFG579aa9 for <ace@ietfa.amsl.com>; Mon, 14 Jul 2014 20:31:12 -0700 (PDT)
Received: from lhrrgout.huawei.com (lhrrgout.huawei.com [194.213.3.17]) (using TLSv1 with cipher RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 2D8B41B2804 for <ace@ietf.org>; Mon, 14 Jul 2014 20:31:12 -0700 (PDT)
Received: from 172.18.7.190 (EHLO lhreml401-hub.china.huawei.com) ([172.18.7.190]) by lhrrg01-dlp.huawei.com (MOS 4.3.7-GA FastPath queued) with ESMTP id BKA85754; Tue, 15 Jul 2014 03:31:10 +0000 (GMT)
Received: from SZXEMA410-HUB.china.huawei.com (10.82.72.42) by lhreml401-hub.china.huawei.com (10.201.5.240) with Microsoft SMTP Server (TLS) id 14.3.158.1; Tue, 15 Jul 2014 04:31:10 +0100
Received: from SZXEMA501-MBS.china.huawei.com ([169.254.2.128]) by SZXEMA410-HUB.china.huawei.com ([10.82.72.42]) with mapi id 14.03.0158.001; Tue, 15 Jul 2014 11:31:04 +0800
From: Likepeng <likepeng@huawei.com>
To: Hannes Tschofenig <hannes.tschofenig@gmx.net>, "ace@ietf.org" <ace@ietf.org>
Thread-Topic: [Ace] OAuth-based Strawman for ACE
Thread-Index: AQHPl3/4GjCapQcy+UyF5k00uj9so5ugiW8A
Date: Tue, 15 Jul 2014 03:31:03 +0000
Message-ID: <34966E97BE8AD64EAE9D3D6E4DEE36F258177F09@SZXEMA501-MBS.china.huawei.com>
References: <53B697F8.6020703@gmx.net>
In-Reply-To: <53B697F8.6020703@gmx.net>
Accept-Language: zh-CN, en-US
Content-Language: zh-CN
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
x-originating-ip: [10.66.167.122]
Content-Type: text/plain; charset="gb2312"
Content-Transfer-Encoding: base64
MIME-Version: 1.0
X-CFilter-Loop: Reflected
Archived-At: http://mailarchive.ietf.org/arch/msg/ace/qpYGjh5e3xac4MBEerXLMJusqOQ
Subject: Re: [Ace] OAuth-based Strawman for ACE
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 15 Jul 2014 03:31:14 -0000

PiAoYikgVGhlIE9BdXRoIDIuMCBCZWFyZXIgVG9rZW4gVXNhZ2Ugb3ZlciB0aGUgQ29uc3RyYWlu
ZWQgQXBwbGljYXRpb24gUHJvdG9jb2wgKENvQVApDQo+IGh0dHBzOi8vZGF0YXRyYWNrZXIuaWV0
Zi5vcmcvZG9jL2RyYWZ0LXRzY2hvZmVuaWctYWNlLW9hdXRoLWJ0Lw0KDQpBYm91dCBTZWN0aW9u
IDUsIEVycm9yIE9wdGlvbiBEZWZpbml0aW9uLCB3ZSBjYW4gcmV1c2UgQ29kZSAoU2VjdGlvbiAz
IGluIFJGQzcyNTIpIGluIHRoZSBDb0FQIGhlYWRlciBmb3IgdGhhdC4gSnVzdCBkZWZpbmluZyBz
b21lIGNvZGUgbnVtYmVycyBzaG91bGQgYmUgZmluZS4NCg0KS2luZCBSZWdhcmRzDQpLZXBlbmcN
Cg0KPiAtLS0tLdPKvP7Urbz+LS0tLS0NCj4gt6K8/sjLOiBBY2UgW21haWx0bzphY2UtYm91bmNl
c0BpZXRmLm9yZ10gtPqx7SBIYW5uZXMgVHNjaG9mZW5pZw0KPiC3osvNyrG85DogMjAxNMTqN9TC
NMjVIDIwOjAzDQo+IMrVvP7IyzogYWNlQGlldGYub3JnDQo+INb3zOI6IFtBY2VdIE9BdXRoLWJh
c2VkIFN0cmF3bWFuIGZvciBBQ0UNCj4gDQo+IEhpIGFsbCwNCj4gDQo+IEkgaGF2ZSBiZWVuIHBs
YXlpbmcgYXJvdW5kIHdpdGggdGhlIGlkZWEgb2YgdXNpbmcgT0F1dGggZm9yIHRoZSBJb1QgY29u
dGV4dCBmb3INCj4gYSB3aGlsZSBub3cuIEl0IHR1cm5zIG91dCB0aGF0IG90aGVycyBoYXZlIGhh
ZCBzaW1pbGFyIGlkZWFzIGFuZCB2YXJpb3VzIGJsb2cNCj4gcG9zdCBhbmQgcHJlc2VudGF0aW9u
cyBjYW4gYmUgZm91bmQgb24gdGhlIFdlYiBhbHJlYWR5Lg0KPiBVbmZvcnR1bmF0ZWx5LCBtb3N0
IG9mIHRoZW0gYXJlIGNvbXBsZXRlbHkgaW5zZWN1cmUuIEZvciB0aGlzIHRoaXMgSSBoYXZlIHB1
dA0KPiBteSB0aG91Z2h0cyBvbiAicGFwZXIiIG9uIGhvdyBJIHdvdWxkIGRlc2lnbiBzdWNoIGEg
c29sdXRpb24uDQo+IA0KPiBUaGUgYXBwcm9hY2ggaXMgZGVzY3JpYmVkIGluIHR3byBkb2N1bWVu
dHMsIG5hbWVseToNCj4gDQo+IChhKSBUaGUgT0F1dGggMi4wIEludGVybmV0IG9mIFRoaW5ncyAo
SW9UKSBDbGllbnQgQ3JlZGVudGlhbHMgR3JhbnQNCj4gaHR0cHM6Ly9kYXRhdHJhY2tlci5pZXRm
Lm9yZy9kb2MvZHJhZnQtdHNjaG9mZW5pZy1hY2Utb2F1dGgtaW90Lw0KPiANCj4gKGIpIFRoZSBP
QXV0aCAyLjAgQmVhcmVyIFRva2VuIFVzYWdlIG92ZXIgdGhlIENvbnN0cmFpbmVkIEFwcGxpY2F0
aW9uDQo+IFByb3RvY29sIChDb0FQKQ0KPiBodHRwczovL2RhdGF0cmFja2VyLmlldGYub3JnL2Rv
Yy9kcmFmdC10c2Nob2ZlbmlnLWFjZS1vYXV0aC1idC8NCj4gDQo+IChhKSBkZXNjcmliZXMgYSBu
ZXcgT0F1dGggZ3JhbnQgdHlwZSB0aGF0IGFsbG93cyBhIGNvbnN0cmFpbmVkIGNsaWVudCB0byBv
YnRhaW4NCj4gYW4gYWNjZXNzIHRva2VuIGFuZCAoYikgZGVzY3JpYmVzIGhvdyB0byBjb252ZXkg
dGhhdCBhY2Nlc3MgdG9rZW4gb3ZlciBDb0FQDQo+IGZyb20gdGhlIGNsaWVudCB0byBhIHJlc291
cmNlIHNlcnZlci4NCj4gDQo+IElmIHRoZSBjbGllbnQgaXMgbm90IGNvbnN0cmFpbmVkIChhcyBp
dCB3b3VsZCBiZSB0aGUgY2FzZSBmb3IgYSBzbWFydA0KPiBwaG9uZSkgdGhlbiAoYSkgaXMgbm90
IG5lZWRlZCBhbmQgcmVndWxhciBPQXV0aCBjb3VsZCBiZSB1c2VkLiBJbiBvdGhlciBjYXNlcw0K
PiB0aGUgdXNlIG9mIENvQVAgYmV0d2VlbiB0aGUgY2xpZW50IGFuZCByZXNvdXJjZSBzZXJ2ZXIg
bWF5IG5vdCBiZQ0KPiBhcHByb3ByaWF0ZSBhbmQgdGhlbiAoYikgaXMgbm90IGFwcGxpY2FibGUu
DQo+IA0KPiBXaGlsZSB0aGlzIGlzIG5vdCByZWxldmFudCBmb3IgQUNFIGF0IHRoaXMgcG9pbnQg
aW4gdGltZSAoc2luY2Ugd2UgYXJlIGF0IHRoZSBzdGFnZQ0KPiBvZiB1c2UgY2FzZXMgYW5kIHJl
cXVpcmVtZW50cykgSSB0aG91Z2h0IGl0IHN0aWxsIHByb3ZpZGVzIHNvbWUgdXNlZnVsIGRhdGEN
Cj4gcG9pbnRzLg0KPiANCj4gSWYgeW91IGhhdmUgZmVlZGJhY2sgcGxlYXNlIGRyb3AgbWUgYSBt
YWlsLg0KPiANCj4gQ2lhbw0KPiBIYW5uZXMNCg0K


From nobody Mon Jul 14 22:48:02 2014
Return-Path: <ludwig@sics.se>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 87AE01A02E8 for <ace@ietfa.amsl.com>; Mon, 14 Jul 2014 22:47:59 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.901
X-Spam-Level: 
X-Spam-Status: No, score=-2.901 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HELO_EQ_SE=0.35, RCVD_IN_DNSWL_LOW=-0.7, RP_MATCHES_RCVD=-0.651] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id x1T1FCpG8zEC for <ace@ietfa.amsl.com>; Mon, 14 Jul 2014 22:47:56 -0700 (PDT)
Received: from outbox.sics.se (outbox.sics.se [193.10.64.137]) by ietfa.amsl.com (Postfix) with ESMTP id B57C11A0301 for <ace@ietf.org>; Mon, 14 Jul 2014 22:47:55 -0700 (PDT)
Received: from e-mailfilter01.sunet.se (e-mailfilter01.sunet.se [192.36.171.201]) by outbox.sics.se (Postfix) with ESMTPS id 000F06D6 for <ace@ietf.org>; Tue, 15 Jul 2014 07:47:54 +0200 (CEST)
Received: from letter.sics.se (letter.sics.se [193.10.64.6]) by e-mailfilter01.sunet.se (8.14.4/8.14.4/Debian-4) with ESMTP id s6F5lskq012058 for <ace@ietf.org>; Tue, 15 Jul 2014 07:47:54 +0200
Received: from [192.168.0.108] (unknown [85.235.11.178]) (Authenticated sender: ludwig@sics.se) by letter.sics.se (Postfix) with ESMTPSA id E955B40116 for <ace@ietf.org>; Tue, 15 Jul 2014 07:47:54 +0200 (CEST)
Message-ID: <53C4C082.3020909@sics.se>
Date: Tue, 15 Jul 2014 07:47:46 +0200
From: Ludwig Seitz <ludwig@sics.se>
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:24.0) Gecko/20100101 Thunderbird/24.6.0
MIME-Version: 1.0
To: ace@ietf.org
References: <53C3C09A.5090707@gmx.net> <14018.1405360899@sandelman.ca> <53C42703.4060806@gmx.net> <8236.1405368736@sandelman.ca>
In-Reply-To: <8236.1405368736@sandelman.ca>
Content-Type: multipart/signed; protocol="application/pkcs7-signature"; micalg=sha1; boundary="------------ms050406030105040306000205"
X-Bayes-Prob: 0.0001 (Score 0, tokens from: outbound, outbound-sics-se:default, sics-se:default, base:default, @@RPTN)
X-p0f-Info: os=Solaris 10, link=Ethernet or modem
X-CanIt-Geo: =?UTF-8?Q?ip=3D85.235.11.178; _country=3DSE; _region=3DSk=C3=A5ne; _city=3DLund; _latitude=3D55.7000; _longitude=3D13.1833; _http://maps.google.com/maps=3Fq=3D55.7000,13.1833&z=3D6?=
X-CanItPRO-Stream: outbound-sics-se:outbound (inherits from outbound-sics-se:default, sics-se:default, base:default)
X-Canit-Stats-ID: 09MqtLSzQ - 0b4f76068ffe - 20140715
X-Antispam-Training-Forget: https://canit.sunet.se/canit/b.php?i=09MqtLSzQ&m=0b4f76068ffe&t=20140715&c=f
X-Antispam-Training-Nonspam: https://canit.sunet.se/canit/b.php?i=09MqtLSzQ&m=0b4f76068ffe&t=20140715&c=n
X-Antispam-Training-Spam: https://canit.sunet.se/canit/b.php?i=09MqtLSzQ&m=0b4f76068ffe&t=20140715&c=s
X-CanIt-Archive-Cluster: PfMRe/vJWMiXwM2YIH5BVExnUnw
X-Scanned-By: CanIt (www . roaringpenguin . com) on 192.36.171.201
Archived-At: http://mailarchive.ietf.org/arch/msg/ace/Npx45jzx9QTuM7c8e3wmy77WQzA
Subject: Re: [Ace] Offline operation of Resource Server
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 15 Jul 2014 05:47:59 -0000

This is a cryptographically signed message in MIME format.

--------------ms050406030105040306000205
Content-Type: text/plain; charset=ISO-8859-1; format=flowed
Content-Transfer-Encoding: quoted-printable

On 07/14/2014 10:12 PM, Michael Richardson wrote:
>
> Hannes Tschofenig <hannes.tschofenig@gmx.net> wrote:
>      > To re-use the Kerberos language, the client gets the TGT. The re=
al-time
>      > interaction I was talking about relates to the interaction betwe=
en the
>      > resource server and the authorization server.
>
> During enrollment, the Authorization Server gets a TGT on the *resource=
* server.
> Given that, it can now issue new tickets to clients that come along tha=
t wish
> to access the resource.  The client, during enrollment, asks the (possi=
bly
> federated list of) authorization servers for a resource ticket.
> (This is why part of network join needs to be in scope for ACE)
>
> All of the above has to occur online.
>
> Once the client has the resource ticket, the resource server can valida=
te it offline.
>


 >>Ludwig, could you please explain this offline requirement a bit more?

It means exactly the kind of offline validation that Michael described=20
above.

1. You need some initial enrollment of AS <-> RS (that could be online=20
or offline & manual such as by reading off some QR code with the RSs=20
initial key material and feeding that to the AS).

2. Then you need some online authorization decision step between C and AS=
=2E

3. Then (possibly later) there is some interaction between C and RS,=20
that could be offline. Here RS needs to be able to do offline validation =

of the authorization decision from step 2.


/Ludwig

--=20
Ludwig Seitz, PhD
SICS Swedish ICT AB
Ideon Science Park
Building Beta 2
Scheelev=E4gen 17
SE-223 70 Lund

Phone +46(0)70-349 92 51
http://www.sics.se


--------------ms050406030105040306000205
Content-Type: application/pkcs7-signature; name="smime.p7s"
Content-Transfer-Encoding: base64
Content-Disposition: attachment; filename="smime.p7s"
Content-Description: S/MIME Cryptographic Signature

MIAGCSqGSIb3DQEHAqCAMIACAQExCzAJBgUrDgMCGgUAMIAGCSqGSIb3DQEHAQAAoIIMVDCC
BhgwggUAoAMCAQICAwiRTjANBgkqhkiG9w0BAQsFADCBjDELMAkGA1UEBhMCSUwxFjAUBgNV
BAoTDVN0YXJ0Q29tIEx0ZC4xKzApBgNVBAsTIlNlY3VyZSBEaWdpdGFsIENlcnRpZmljYXRl
IFNpZ25pbmcxODA2BgNVBAMTL1N0YXJ0Q29tIENsYXNzIDEgUHJpbWFyeSBJbnRlcm1lZGlh
dGUgQ2xpZW50IENBMB4XDTE0MDEwNzA3MjgzNVoXDTE1MDEwNzEyNTgyMlowODEXMBUGA1UE
AwwObHVkd2lnQHNpY3Muc2UxHTAbBgkqhkiG9w0BCQEWDmx1ZHdpZ0BzaWNzLnNlMIIBIjAN
BgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAnLm1tc30QxHa9wtdVjC3NgxjLJicnccm0HD+
1X16kPMKGvwps8F1oDhYn7jXIe46p1AuJMzLK0GIioE4JwxCFGdvpz7cg2xyTyrdBVUzSqez
Dfqt4FOJq6hrdrIMS8MHEzl7Jk02gv9cTn/pHQvDpkiThRpbSLU5mlMqtEQ8gDQY5YyBX0Mv
5qculV08I2JU8HEeTt1oeqhvBImgQfOVYMDatHlWHUVVrmYd6iIo+cuiUGd5kiA0XuaLYX0E
oCoao/z5Wg9U0sQlx0hl4r96Q+NdoZZ1prfts3qtyBzJ2hu135aikigzJ6sueWHv/jbISUek
tOMm0xkx1GOqqWtEAwIDAQABo4IC1DCCAtAwCQYDVR0TBAIwADALBgNVHQ8EBAMCBLAwHQYD
VR0lBBYwFAYIKwYBBQUHAwIGCCsGAQUFBwMEMB0GA1UdDgQWBBRZmjjBh8N3klra+mVQgC00
pl68ZTAfBgNVHSMEGDAWgBRTcu2SnODaywFcfH6WNU7y1LhRgjAZBgNVHREEEjAQgQ5sdWR3
aWdAc2ljcy5zZTCCAUwGA1UdIASCAUMwggE/MIIBOwYLKwYBBAGBtTcBAgMwggEqMC4GCCsG
AQUFBwIBFiJodHRwOi8vd3d3LnN0YXJ0c3NsLmNvbS9wb2xpY3kucGRmMIH3BggrBgEFBQcC
AjCB6jAnFiBTdGFydENvbSBDZXJ0aWZpY2F0aW9uIEF1dGhvcml0eTADAgEBGoG+VGhpcyBj
ZXJ0aWZpY2F0ZSB3YXMgaXNzdWVkIGFjY29yZGluZyB0byB0aGUgQ2xhc3MgMSBWYWxpZGF0
aW9uIHJlcXVpcmVtZW50cyBvZiB0aGUgU3RhcnRDb20gQ0EgcG9saWN5LCByZWxpYW5jZSBv
bmx5IGZvciB0aGUgaW50ZW5kZWQgcHVycG9zZSBpbiBjb21wbGlhbmNlIG9mIHRoZSByZWx5
aW5nIHBhcnR5IG9ibGlnYXRpb25zLjA2BgNVHR8ELzAtMCugKaAnhiVodHRwOi8vY3JsLnN0
YXJ0c3NsLmNvbS9jcnR1MS1jcmwuY3JsMIGOBggrBgEFBQcBAQSBgTB/MDkGCCsGAQUFBzAB
hi1odHRwOi8vb2NzcC5zdGFydHNzbC5jb20vc3ViL2NsYXNzMS9jbGllbnQvY2EwQgYIKwYB
BQUHMAKGNmh0dHA6Ly9haWEuc3RhcnRzc2wuY29tL2NlcnRzL3N1Yi5jbGFzczEuY2xpZW50
LmNhLmNydDAjBgNVHRIEHDAahhhodHRwOi8vd3d3LnN0YXJ0c3NsLmNvbS8wDQYJKoZIhvcN
AQELBQADggEBAHqEYmtWr83S+iLXE97KBnHJZiMr6PMuLKxmh0o6UJJwKgf+KTP2czxRnPSI
+whuqfQZdmz6g3A2K8AooMU0RXrzncnX1c4826APdnXkRxnGQxtZXI1wuhPn4z7iDKZ6ij9u
K5Pfn10JL/ERDig2qJQbqvhtIAx0RY7y7r+hLMvgXVq9mf3WRJYmGQeFW+N9t5Z1eEwG4m9R
KAZm0fnfeDn/Ai4kmxTckBH7dZwW2lTtwQqQ4su+PGCJ0e9ndBLpvTqaYGSAl+L7PO7vxPhS
/cS67Xa6BtnYJLTr3MaGXaN+CEUFSfwQHa9DKcAqh3kldErI3kCvnot0CigBl4aILOEwggY0
MIIEHKADAgECAgEeMA0GCSqGSIb3DQEBBQUAMH0xCzAJBgNVBAYTAklMMRYwFAYDVQQKEw1T
dGFydENvbSBMdGQuMSswKQYDVQQLEyJTZWN1cmUgRGlnaXRhbCBDZXJ0aWZpY2F0ZSBTaWdu
aW5nMSkwJwYDVQQDEyBTdGFydENvbSBDZXJ0aWZpY2F0aW9uIEF1dGhvcml0eTAeFw0wNzEw
MjQyMTAxNTVaFw0xNzEwMjQyMTAxNTVaMIGMMQswCQYDVQQGEwJJTDEWMBQGA1UEChMNU3Rh
cnRDb20gTHRkLjErMCkGA1UECxMiU2VjdXJlIERpZ2l0YWwgQ2VydGlmaWNhdGUgU2lnbmlu
ZzE4MDYGA1UEAxMvU3RhcnRDb20gQ2xhc3MgMSBQcmltYXJ5IEludGVybWVkaWF0ZSBDbGll
bnQgQ0EwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDHCYPMzi3YGrEppC4Tq5a+
ijKDjKaIQZZVR63UbxIP6uq/I0fhCu+cQhoUfE6ERKKnu8zPf1Jwuk0tsvVCk6U9b+0UjM0d
Lep3ZdE1gblK/1FwYT5Pipsu2yOMluLqwvsuz9/9f1+1PKHG/FaR/wpbfuIqu54qzHDYeqiU
fsYzoVflR80DAC7hmJ+SmZnNTWyUGHJbBpA8Q89lGxahNvuryGaC/o2/ceD2uYDX9U8Eg5Dp
IpGQdcbQeGarV04WgAUjjXX5r/2dabmtxWMZwhZna//jdiSyrrSMTGKkDiXm6/3/4ebfeZuC
YKzN2P8O2F/Xe2AC/Y7zeEsnR7FOp+uXAgMBAAGjggGtMIIBqTAPBgNVHRMBAf8EBTADAQH/
MA4GA1UdDwEB/wQEAwIBBjAdBgNVHQ4EFgQUU3Ltkpzg2ssBXHx+ljVO8tS4UYIwHwYDVR0j
BBgwFoAUTgvvGqRAW6UXaYcwyjRoQ9BBrvIwZgYIKwYBBQUHAQEEWjBYMCcGCCsGAQUFBzAB
hhtodHRwOi8vb2NzcC5zdGFydHNzbC5jb20vY2EwLQYIKwYBBQUHMAKGIWh0dHA6Ly93d3cu
c3RhcnRzc2wuY29tL3Nmc2NhLmNydDBbBgNVHR8EVDBSMCegJaAjhiFodHRwOi8vd3d3LnN0
YXJ0c3NsLmNvbS9zZnNjYS5jcmwwJ6AloCOGIWh0dHA6Ly9jcmwuc3RhcnRzc2wuY29tL3Nm
c2NhLmNybDCBgAYDVR0gBHkwdzB1BgsrBgEEAYG1NwECATBmMC4GCCsGAQUFBwIBFiJodHRw
Oi8vd3d3LnN0YXJ0c3NsLmNvbS9wb2xpY3kucGRmMDQGCCsGAQUFBwIBFihodHRwOi8vd3d3
LnN0YXJ0c3NsLmNvbS9pbnRlcm1lZGlhdGUucGRmMA0GCSqGSIb3DQEBBQUAA4ICAQAKgwh9
eKssBly4Y4xerhy5I3dNoXHYfYa8PlVLL/qtXnkFgdtY1o95CfegFJTwqBBmf8pyTUnFsukD
FUI22zF5bVHzuJ+GxhnSqN2sD1qetbYwBYK2iyYA5Pg7Er1A+hKMIzEzcduRkIMmCeUTyMyi
kfbUFvIBivtvkR8ZFAk22BZy+pJfAoedO61HTz4qSfQoCRcLN5A0t4DkuVhTMXIzuQ8Cnykh
ExD6x4e6ebIbrjZLb7L+ocR0y4YjCl/Pd4MXU91y0vTipgr/O75CDUHDRHCCKBVmz/Rzkc/b
970MEeHt5LC3NiWTgBSvrLEuVzBKM586YoRD9Dy3OHQgWI270g+5MYA8GfgI/EPT5G7xPbCD
z+zjdH89PeR3U4So4lSXur6H6vp+m9TQXPF3a0LwZrp8MQ+Z77U1uL7TelWO5lApsbAonrqA
SfTpaprFVkL4nyGH+NHST2ZJPWIBk81i6Vw0ny0qZW2Niy/QvVNKbb43A43ny076khXO7cNb
BIRdJ/6qQNq9Bqb5C0Q5nEsFcj75oxQRqlKf6TcvGbjxkJh8BYtv9ePsXklAxtm8J7GCUBth
HSQgepbkOexhJ0wP8imUkyiPHQ0GvEnd83129fZjoEhdGwXV27ioRKbj/cIq7JRXun0NbeY+
UdMYu9jGfIpDLtUUGSgsg2zMGs5R4jGCA90wggPZAgEBMIGUMIGMMQswCQYDVQQGEwJJTDEW
MBQGA1UEChMNU3RhcnRDb20gTHRkLjErMCkGA1UECxMiU2VjdXJlIERpZ2l0YWwgQ2VydGlm
aWNhdGUgU2lnbmluZzE4MDYGA1UEAxMvU3RhcnRDb20gQ2xhc3MgMSBQcmltYXJ5IEludGVy
bWVkaWF0ZSBDbGllbnQgQ0ECAwiRTjAJBgUrDgMCGgUAoIICHTAYBgkqhkiG9w0BCQMxCwYJ
KoZIhvcNAQcBMBwGCSqGSIb3DQEJBTEPFw0xNDA3MTUwNTQ3NDZaMCMGCSqGSIb3DQEJBDEW
BBQbhKEJM4xgM9V2QcKvPmvuu95DAzBsBgkqhkiG9w0BCQ8xXzBdMAsGCWCGSAFlAwQBKjAL
BglghkgBZQMEAQIwCgYIKoZIhvcNAwcwDgYIKoZIhvcNAwICAgCAMA0GCCqGSIb3DQMCAgFA
MAcGBSsOAwIHMA0GCCqGSIb3DQMCAgEoMIGlBgkrBgEEAYI3EAQxgZcwgZQwgYwxCzAJBgNV
BAYTAklMMRYwFAYDVQQKEw1TdGFydENvbSBMdGQuMSswKQYDVQQLEyJTZWN1cmUgRGlnaXRh
bCBDZXJ0aWZpY2F0ZSBTaWduaW5nMTgwNgYDVQQDEy9TdGFydENvbSBDbGFzcyAxIFByaW1h
cnkgSW50ZXJtZWRpYXRlIENsaWVudCBDQQIDCJFOMIGnBgsqhkiG9w0BCRACCzGBl6CBlDCB
jDELMAkGA1UEBhMCSUwxFjAUBgNVBAoTDVN0YXJ0Q29tIEx0ZC4xKzApBgNVBAsTIlNlY3Vy
ZSBEaWdpdGFsIENlcnRpZmljYXRlIFNpZ25pbmcxODA2BgNVBAMTL1N0YXJ0Q29tIENsYXNz
IDEgUHJpbWFyeSBJbnRlcm1lZGlhdGUgQ2xpZW50IENBAgMIkU4wDQYJKoZIhvcNAQEBBQAE
ggEAOMUjKZ8lKcOwW99GKB7Q2Nkj/EhvxvmLI3KtCVpJi6JNpDLtnr0W/Newey2pwZ45onfB
F7vlKOqRYvlNDcgIvvrqiYgPHgcRvPmQ5uGfPk2tvL4O/vdyak9erVY79Y3mj9bdZwhGOqne
yGg+1aJIgDTgrsG6oUaZhZBbwLeNWCehci0VRnr1cRL6WYt1t6hPlVbvKpsqwFKIgk4h2ics
pKIz5jL8RQkSuZCMN4wXZ7C9fHdQYg1N9piXHLYaPFLUSc4OLw2jw3Gj9pO0D/TWAcG036In
5PkO+/kOrtUbbwTQYHYR+vIcBBDq0zNeQ/pYhUJlmypiJKyjUbQoIMXklAAAAAAAAA==
--------------ms050406030105040306000205--


From nobody Mon Jul 14 23:10:41 2014
Return-Path: <ludwig@sics.se>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id A0A831B2816 for <ace@ietfa.amsl.com>; Mon, 14 Jul 2014 23:10:39 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.901
X-Spam-Level: 
X-Spam-Status: No, score=-2.901 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HELO_EQ_SE=0.35, RCVD_IN_DNSWL_LOW=-0.7, RP_MATCHES_RCVD=-0.651] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id x-VDis46Xw4a for <ace@ietfa.amsl.com>; Mon, 14 Jul 2014 23:10:37 -0700 (PDT)
Received: from outbox.sics.se (outbox.sics.se [193.10.64.137]) by ietfa.amsl.com (Postfix) with ESMTP id C1DB11B2812 for <ace@ietf.org>; Mon, 14 Jul 2014 23:10:36 -0700 (PDT)
Received: from e-mailfilter01.sunet.se (e-mailfilter01.sunet.se [192.36.171.201]) by outbox.sics.se (Postfix) with ESMTPS id 1F12F6EA for <ace@ietf.org>; Tue, 15 Jul 2014 08:10:36 +0200 (CEST)
Received: from letter.sics.se (letter.sics.se [193.10.64.6]) by e-mailfilter01.sunet.se (8.14.4/8.14.4/Debian-4) with ESMTP id s6F6AZoE016885 for <ace@ietf.org>; Tue, 15 Jul 2014 08:10:35 +0200
Received: from [192.168.0.108] (unknown [85.235.11.178]) (Authenticated sender: ludwig@sics.se) by letter.sics.se (Postfix) with ESMTPSA id D1BA740116 for <ace@ietf.org>; Tue, 15 Jul 2014 08:10:31 +0200 (CEST)
Message-ID: <53C4C5D6.30503@sics.se>
Date: Tue, 15 Jul 2014 08:10:30 +0200
From: Ludwig Seitz <ludwig@sics.se>
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:24.0) Gecko/20100101 Thunderbird/24.6.0
MIME-Version: 1.0
To: ace@ietf.org
References: <34966E97BE8AD64EAE9D3D6E4DEE36F258177EE3@SZXEMA501-MBS.china.huawei.com>
In-Reply-To: <34966E97BE8AD64EAE9D3D6E4DEE36F258177EE3@SZXEMA501-MBS.china.huawei.com>
Content-Type: multipart/signed; protocol="application/pkcs7-signature"; micalg=sha1; boundary="------------ms010604090308000203080609"
X-Bayes-Prob: 0.0001 (Score 0, tokens from: outbound, outbound-sics-se:default, sics-se:default, base:default, @@RPTN)
X-p0f-Info: os=Solaris 10, link=Ethernet or modem
X-CanIt-Geo: =?UTF-8?Q?ip=3D85.235.11.178; _country=3DSE; _region=3DSk=C3=A5ne; _city=3DLund; _latitude=3D55.7000; _longitude=3D13.1833; _http://maps.google.com/maps=3Fq=3D55.7000,13.1833&z=3D6?=
X-CanItPRO-Stream: outbound-sics-se:outbound (inherits from outbound-sics-se:default, sics-se:default, base:default)
X-Canit-Stats-ID: 09MquazLk - d0d094420a33 - 20140715
X-Antispam-Training-Forget: https://canit.sunet.se/canit/b.php?i=09MquazLk&m=d0d094420a33&t=20140715&c=f
X-Antispam-Training-Nonspam: https://canit.sunet.se/canit/b.php?i=09MquazLk&m=d0d094420a33&t=20140715&c=n
X-Antispam-Training-Spam: https://canit.sunet.se/canit/b.php?i=09MquazLk&m=d0d094420a33&t=20140715&c=s
X-CanIt-Archive-Cluster: PfMRe/vJWMiXwM2YIH5BVExnUnw
X-Scanned-By: CanIt (www . roaringpenguin . com) on 192.36.171.201
Archived-At: http://mailarchive.ietf.org/arch/msg/ace/Vgser9D1nma1R2FaM2KmLbJuQCM
Subject: Re: [Ace] Context-based Authorization
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 15 Jul 2014 06:10:39 -0000

This is a cryptographically signed message in MIME format.

--------------ms010604090308000203080609
Content-Type: multipart/mixed;
 boundary="------------010405030007020803000904"

This is a multi-part message in MIME format.
--------------010405030007020803000904
Content-Type: text/plain; charset=windows-1252; format=flowed
Content-Transfer-Encoding: quoted-printable

On 07/15/2014 05:19 AM, Likepeng wrote:
> Hi all,
>
> Personally I am wondering whether or not we should support context-base=
d
> authorization indicated in
> http://tools.ietf.org/html/draft-seitz-ace-usecases-01.
>
> For U2.4, do we want to achieve something like this: if time is 9:00 ~
> 18:00, Client A is allowed to turn on a light, but Client B is not allo=
wed?

Yes that's one example.

>
> To me, this is purely Resource Server side policy setting and
> enforcement. Does it require any information exchange with Authorizatio=
n
> Server? Is it necessary?

We are moving away from requirements here and getting into solutions,=20
but for the sake of clarification: I don't think this kind of policy=20
should be on the RS, it should be maintained and managed by the AS, for=20
the same reasons we want all the other authorization policies to be on=20
the AS. The solution I have in mind are conditional authorization=20
decisions in the style: "You are permitted to turn on the light,=20
provided it is between 9:00 and 18:00".


> About presence, does it mean online / offline status? If yes, this
> should be covered by another requirement U5.2, which was discussed in
> another discussion thread =93offline operation=94.
>

No I meant physical presence, like "you get to control the HVAC if you=20
are in the room, but from elsewhere"

>
> For U3.1, how to define an emergency context?

In medical access control scenarios there is the concept of=20
"break-the-glass policies". This means that medical personnel can just=20
declare an emergency context (similar to breaking the glass to access a=20
fire alarm, see attached image) in order to get additional=20
authorization. This declaration is then subject to auditing at a later=20
point, to ensure that there really was an emergency situation.



/Ludwig

--=20
Ludwig Seitz, PhD
SICS Swedish ICT AB
Ideon Science Park
Building Beta 2
Scheelev=E4gen 17
SE-223 70 Lund

Phone +46(0)70-349 92 51
http://www.sics.se

--------------010405030007020803000904
Content-Type: image/jpeg;
 name="breakTheGlass.jpg"
Content-Transfer-Encoding: base64
Content-Disposition: attachment;
 filename="breakTheGlass.jpg"

/9j/4AAQSkZJRgABAgAAZABkAAD/7AAnRHVja3kAAQAEAAAAUAACABIAAAAHAEQAQwBGACAA
MQAuADAAAP/uAA5BZG9iZQBkwAAAAAH/2wCEAAICAgICAgICAgIDAgICAwQDAgIDBAUEBAQE
BAUGBQUFBQUFBgYHBwgHBwYJCQoKCQkMDAwMDAwMDAwMDAwMDAwBAwMDBQQFCQYGCQ0LCQsN
Dw4ODg4PDwwMDAwMDw8MDAwMDAwPDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDP/AABEI
AZABnAMBEQACEQEDEQH/xADqAAABAwUBAQAAAAAAAAAAAAADAAIEAQYHCAkFCgEAAgIDAQEA
AAAAAAAAAAAAAAECAwUGBwQIEAABAgQDBAUHBwUICwwJBQABAgMAEQQFIRIGMUEHCFFhcSIT
gZGhMlMUFrFS0iNDFRfRQjNWCcGDsyQlJzcY8OFicoKTNLQmRnbxorLCY3PD05RFNmaSo1R0
hGV1R1dENYWVGREAAgECAgQICQgIBgIBAwUAAAECEQMhBDFBEgVRcZGhExQGB2GBscHRIlIV
FjJCcpIzU3NU8OFiI0MkNRfxgmM0RCWisoOTs0XSo3RVNv/aAAwDAQACEQMRAD8A7+QAKABb
IAALWE4wAec/WpbnMwAczf2h3HXVujbFofh1oPUD1humuHK6q1FWUS/DqxbaNtKA2h1JzNpd
cdxUmSjkkDtjB77zE4QUIOjl5DqndZuXL5zNzv5mClG2lRPGO0/BrpyYnIOp1/r9lYbd4i6k
dcS6h9SDdKwydQBlXi76wkJHaI1Wcrkf4jr4z6Ahu/JyVVl7dNHyI6ODRoI/x3rWpdU89rK/
VDzqszjzlxqVrUdk1EuEkwJzlpk+Vk1u/KRVFZtpfRj6D3KXUmsHhP4vviB/7+/9OH66+c+V
lMsrlV/Ch9Veg9NN61eSMmtL4Bs/y9/b0+vEtmcvnteMr6LKr+Db+qvQEF11hPHW9/l0/eFR
9OJ9HNfPfKwccr9xb+qvQVN41kAQnXWoUzMxK41GH+/hUn7T5WJQyn3Fv6q9A1V61pIS11qM
7lfylUYk9WeEoXK4zlysmreU+4tfUXoBm962mSjXOok4hRlcakTPT+k2xLZue1LlF0WUemxb
+rH0DjqPiAJka+1L0d251WMv3yJqM2qbUq8bGsvkfy9r6kfQD+J+IiRNGu9UYDBKbpVzB/xv
REHC4tEpPxssWXyP3Fr6kfQJGq+IyDmGvNUhYAkU3WskPL4vXC2rnDLlZGWUyL/gWvqR9A1v
VXEhDjrzeu9ToceUFvuoutYFOKAkCoh0TMhhOCMLmnbkvGw6pkHpsWvqR9BIb1nxOZRla4ja
spkYqARd61IzEknAOjaTEqTWG3JeNjlkt3P/AI9p/wCSPoDDXnFfYnihq8z2yvdf8njQq3K/
Lnysh7v3b+Ws/wD04+gCzrHim1nRS8RtVsBa0LyN3atSC4gzSo5XRinaDuhRje1SlyslLJbu
eMsva+pH0EFV64iPOKLmudQlbk1OLXcaokk7yS5thu1drjJ85Z0GQSwsW/qR9BHduGt1zLmr
724oySVqrqlWztXEJ2L1K7T5Sy3aya0Wbf1Y+gaK7WbfiJ+LbtJaQlRVVvky292a8D1xBQn7
T5WNxycqVtQ5F6AKq/VwGOrLuSN4raj6cPobntvlLIwyv3MPqr0DU3DWBw+K7wZ9NbUfTh9H
JfPfKScMp91D6q9AcPatWlaviy8JWZZB78+U9f58Dg/alylX8qmv3MKa/VXoEh3WE0z1feEz
nOda/tH+HD6GT+fInXKfcw+qvQeky/q5I/8AGN8nPAJrn5f8OBWZrTORVLqr/g2/qr0Exur1
pIE61viZHGVe/sn/AM5EoWrj+c+VlbWUT+wt/VXoJArtcJM/j/UbYBxKblU+j6yJStXFom+U
KZP8ta+pH0Epq6a9GKeJmq2wfm3SpHyOwlZufeS5WRfUteVs/Uj6D0WrtxBJw4r6ySOlN3qh
/wBLFsbE3/FnykJRyOvJ2fqR9B6bd14jymni/rhI6Reqsf8ASxLq8/vZ8pVKOQ/J2PqR9B6L
V44ngd3jXr5sf3N9rR8j0TWXufez5WeecN3vTksu/wD44+gmJvXFMerxy4hD/wDn64f9NE+r
3fvp8pU7O7fyOX/+nH0Bm7jxNqJl3jfr0qOIWq91qjuABJfgVi49N2fKxbO7orDI5f8A+nH0
E+me4muOlsce9bsqBBKTeK4Y7pEPyhdWl99PlZCXu6leoWH/AJI+g9s0vFlZPhcwuuQCe6fv
au6OqoG+LOpyei9PlZS7m6te7rH1I+gkN0XGVBzt8xGuEgGaf5VrTj2+8dMNZW6nhenysqlP
c7//AB9j6kf/ANJ7CUccnJS5jdZoknKAK+pHlkHdo3HbFiy1/wC/kedx3N//AF1nkXo5j2Wq
Tjy4QE8x2rRPapVW/P8AhMYl1a/99I80/cq0bvtcgVVBzDJl4HMbqdYnLv1b4l6VTiSyt/76
X6eMUJbil8rd9vxIcmh5lcoKeYu/FU5qKqp2Uobyl7VemNvs+tO74cn6ycmg5mkj6vmLvRVL
YqpcPyogWVzH30uX9RBy7Ov/APHQ/TxjvcOaErIPMNfFAyDcqog5uvuQ3k8z99Ll/URb7OLR
u+Hj/wAQa6TmyYzeFzA3cjMBkVUBRw61AShvJ5n79/p4hr4alpyEOf0njV935u7YjOvi/quv
SAo/yeqmqVbpdwqSqI9WzK/jSfIX28n2Xu/8S3H6W0i1n+NXMhZc7V64xa8tYHfW7U2cqQgD
CeZrEz9EVPrUW07kuRM9MOze4Mw/3WUsy4rj8jLl0Zxs4/6mudPR2HmWrHKp9QZDVfb20htD
mGZaXWViWHrSKh0wrd/MSdFeafhRDOdl9w5aG1e3etnThJ404KSWPgrRnVjlk4g6u4gcP7i7
riqoLlqTSmoK7TlderaCKev9yQyoVIGAmrxZEpABlOQnKM/kblyUGrjTcXSq16PScL7dbnym
7c/FZRSjauW43Ixn8qO1X1fFTXjqxNjJ4Tj2mmFYAFAA1WyADx62o8NJM4AMc3q9hgL78pQA
ccefy7i58S+GBCU/xeyXFAdAVmUHX28yVGUiE5ARI4TM90a3vx/vIcR2zuqjTK5mXBKPkObN
wqi7W1C0GaVOHIRskMBGu3n67O5WItQSfATrc5NQUtWVKcSSYcMSya5y4U6hpKbuIDjwTvSM
DFu14DHykuEkDWDSBm9yeUkHvGUtuyJ7eGCZTKCeO1zMMNbU5EhQPlQGIEgIW23qK+jx+VzM
p8bU5/7vex2YgYeaFtPgJqyva5mL41pROVC/PeDLCFtuugWyvaGjXDBWkCgfIM9kp9RiysvZ
YUhwhxrmiASV2+oE8ARI+WJKb4GSduKVdrmYROuqGU/u6pIB2mWEJ3H7LIdHF/OXIwnx9RpI
H3a+AQCCSJn0Q+ka+aw6GD+ehx4g0QXP7pqEzxzZhPt2QK6+Bh0MV8/mI7uuKJwmdBUIlsmQ
Yg7knpRa7SXzuYY3rGmR3vc3ifzUzG07JxHpGngnUfQ1Xyic1xDpWSkG1O9clDYPJEo5qa0x
KZZVV+WFVxJpcCLU8on1TmGPoh9b/ZH1Nap8zBq4jMLlK1OgCeYFQ8m6IvM1+aycclF/P5mQ
HtdU7v8A3c8J7ZrB3YSwhdM9GyyUcvT56IXxgwohRonRJPf72w+aJOf7LLdiFPlh29Y0oIBo
npDCU5knzRW266GPol7a5Ah1wwjMPu5w/NmuWHXhEXca0xYugjrnzBk6/pUYm2OlRPq5hL5I
l09NTB2Ie2TfxIoUjC0PLIIkc4HbuiKzElpRHqsdU+YM3xMtxUAuyP8AYHE4nzRb1z9kgsk3
89If+J9E2pKm7IpcsVIdXu8ghdc/ZJdQjodzkRJTxXtm1WlypcgAPEwIl2Qdd/ZILd1P4vMO
PF2jQtKmtJtKQgfnOmc+yRES6/TREPdja+1YccZ6VKES0dTZkyK5vOYk49EP3jL2Re6Y/fPk
QT8bWUkBvR9LM7Z1Ls8eiQgWflqgQe54/fcyCjji2onPo2nAmMuR9wmXlG2G94y1REtyrVdf
IiieN7KPV0q33gc4U+RLskmJxz+GMQ90Rem6OTx1cSQRpWnJmBi+rDy5Yh7w/ZY/c1v7114l
6T12eY2pYSUnRdI8N2aqXL0Iicd50+aVT3HGX8R8iJLXMvVI9bRFEe8Ck+9uTl0eqBDW8nqi
U/D0ZPG6+RBE8zVUlSlI0ZRKSVZkBVU5NPVPJKUS95yXzSfw3bp9q+RB080tzQPq9FW5JUqc
1VLqh/wRE/e8vZIS7NWpfxZciPTZ5s6tOVL2hqQyTIluscAmN8igwPesn81EF2WhXC6+REpv
m5rUyKtB0hOJkK1zZ04twlvWXs+UhLsnB/xeb9ZM/rhVWWXwHS5gP/bVy6vs8MIn72/ZZX8I
w1XXyL0kj+uA8pJSnQjKCNixWrJHb3Ia3t+yQfZKn8XDiJ9JzdOuhaHNGUrWHeWa5fTtkpGP
YIsW946GimfZN/eV8Rc2nOaPT9yuvuWobYLRTvK8Nm60rynm0npdBAISdxGyLLe87bdGee52
VvUbtutFXHA2bar2q2maqaOrTV0NUkOMOoUFtuIUJgg4gzjKKW0qqlDV52qNqSxRBpLTYKW4
N19NaqOjr1KBVUpbCVKAwkCBhiYjJKmhHqWYvdHsObcVqbNpuSF3+bfWaZzB15dyns8Gli3d
7qrn035EaL3qf1Gx/wDx7flmbrT7sZA5mEgAUADHPVMAFl3t8oQvGUhABrxrG7qaS5JUtsAH
H7nPuq6vW+h3A4ommtNfJJAygqdRiDtxljPqlGr7/wDlx4ju/dHFPK36r568ho3IrUAN8a7p
O3R0HtMUy0gJUZITultMeq3A81+7R0RPSMsjMCWxIGEXJpHicalZBUhnMpzg22SUBZEyxOCt
oGEQciOxiUyJ2EzJ2mEpDdspk2SUoS2gGQ80ClQirS4ESG29hmZjYYtUmKcB6kTn3js2fkid
SMbY6ah+erHE4xCUh9EVyhW3vAYYnZ1xJSYpRSAuNBRBXMlOAVOZiEpVBRQ3w0bZSO6HWpOS
qPCBgQCDsmNvbEWOKEhIBkAoEDGCrCUaEoIQJYdExFikV0QYNgymJ4zB6hBtsmkh+RAE8hO3
MqH0gStookJTIYiWwQnMj0SJAAVuMiTgN8NSIuANxpKjMhZMwBLYRElcGo0HhImJkgoVv690
R28StxQYhB2TntBG3riUq6RKNSoaRtAxngobfJC6QOjJCED81CsDvG89vVE1JkkqBCgKknKr
u4iWyULadQ2UES2hM1ZZEiWI2QbTQnFMJkSJ4AkpwEtvbEdp6iOwgiUttlSgiS1Y5pTiW0xO
2iOtTZIIkc0zMp84nCc3UI2wZWkASQkYSPdHmhu60XdCihSHUgYEAzAkNm/dEOkbIq3TQDTR
04xDYlPMCUiQ64ExtktqlZIxaQoTBkUgj5IsjOmgi41D/d9PgBTNyG7KIJJS0ohitbF93s76
dEujKIknqE14SnuFMn/9K32lA/JDouAg3LhZMbp2MJ07ZwlMoBw80CSRXV8LJrVHRFalGnbB
cTkdkhIzDrwixSaK5uT1s92nZoEJShFKyBLKfq04jrwxi1TPNNSelvlJTdBQE5k0TE5SzeGk
mXmiSljUSclrfKQbjpSxXRopfoW2FyOSqpwGnUKO8FOB7CIJ2bdxUkkShmbtp1UnxHvcFdfX
vRepV6Ev1SuothINtUozSG1KJCkA7Ad/QRFGWdzL3Vb0xeht6i3O5e1vCw7kUlcjp1G/bRZW
yh9CgW1ozJWN4InGZk6o0xV0GwPJA/m4dauE5/6cXUzlLazS7oW7HVXfxJeY0jvTTW8rNfuI
eWZvLP6ucZM5oSYAFAAJ31YAMdaiWUtrgA1T19UlKXZHpgA4+c2Vxaf1tYKZteeoprU8qoEp
ZQ68convnlPZGp9oJLpIrgXnO/8AdDaksneepzw8SRq9RpCnEDdGBjpOzLBFzkyTHrjI8M1i
R1HHfhDbBRB5iJQVIsIleA/dgYkVOMKpY2V+WHUrJDfo3xKImSEp2RamIIW5jdFcmTiD91Qq
alIB6cTFkNB571a4A1USFEYSCZgYmB4FFHwsaq3tE4T2Defyw6IsS4QqLewMcpmNhKjj6YNl
cA6U1sKLcwZDwzgJTzK/LA4Reog5S4Q33e2dxBwxC1flg2UVra4ShoWp+pI9OZXlwnC2Y8Ba
nJaypt7EiAky3SUqY9MJQjwIhtS4WJNvpk/mHGWaalejGJ7KWobnLhF93sj80yn85U/lhUWs
VZPWO9xblPvTGIVmVPs2w3GL1E4trCohSNTByqOz88j92EoR4EQlKXCPNI3mBSFFQwzZzOXn
huEHqIq5JDxRoJ7uYJl6pUZfLCVuK1EtuXCHFG3IDK4MuM/EVL5YsaTE3IJ7m1Oc3pyAADis
fTEOji2EZS4R/u7Q7wLx6frFzMvLCduK1c7LNqXDzDUUzeM1O7CcXFTMzgNsJQj+lRLaQNVM
0DMrfExKSXVYemE7cK1oSW0/8ARaA7uZ2RMwrOeiJYLUJqXCALRBBC3QQSPXPniGynoCklrY
4IURitwn+/InKJKK4BNvhKjOlU5uiWweISMYnXwEJbVD37MAt6Rnll6qjOJJI87m0Ximna6I
nQi5seKZo/mw6EXNjFULajPZDoLpBwt6JQ6EXcHChA2GHQi5B0UpG+GiDZPbRkG2JJlbDA7t
0FSLLF1S4aXUGkqxlGapU+6wSAJqbVk7pV1HEeWPLm5P1a6nVGQyCThdi9DidBrDVKVpqgUo
yAokKKVYymnEEiM1abUU66dBqOYhS+6aK4G0XJAofAGsko/RjXN18Pol4FKcInun5NzGvrvl
oq85oPeuqbysV09Xt+WZvf8AY+SMqcwJcACgAE96hgAxrqU/VueWADUriAcHfLABxo5ppjiR
TK3fdLUj++uRqO/l++XEvOfQvdPhu+b4JvyIwPbETeQAdowjCW8Wdgaoi43E4TE9vTHqcaHh
npIavQIigqDAJkDEqCCpQR0dcRIhggjrhtjQsv5ISQmwzZlv/JFhFskoBw39UMraZJSJ4Sx2
wmXWgwAOw7t0ThgVXdJTJjt6QQYmVooUHsnvgJVHBJOPmhAyQlMxLdtidSFAkpDdjuhjGgef
ohUFUdlPTPDZsgoNUGKEsRvgqFBox7N8IdB85yIMsIBUBYE4YwmKgQEJliBCTDYHJdHTvh7R
NQK+MBEdobiDW+ek49EPaJRtgi6TtmMMMYbY3GgkukmWzrhMFRhApSsZ4nbEE2GgqRMRJ4ka
jQmfZuhJ0Hgwobwnuh7RFxBKAE8OqcSRXLA9iyH68xZE8cliXqDFtSugQKhkAgMMiEBhkWgg
MBGgQGGRY8GGIeDARMea6dKK3SwChjWL7p6cqcT1ATjx5ytI8Zkt2KMpyg9MoteLWdCLOpKN
I0zk8oFvzqWRlH6OczGwZZ7UFr4DUL0nLNNYfKWjjNnuRJ0v8MtRvkzL+sbk4T056ekP7sR3
NXYuV09JLzGid7yS3taS1WIL/wApm/n2PkjLnKyXAAoAAveoYAMZ6lP1bnZABqTxBODw7YAO
OPNUAniDbF9NpTMbj9c5Gpb++2XEfQndI/5C4+Cb8iMAWskvN75eiMJa+UdfbwLpUJjHGZj2
ajxTeJGWkDEYdUVtAmDAxn6Ikg0h0ykIGiFCswd0CQ26FDLz9MWxiVtlWyJ4GcoNkjUnNkEd
m2ChJMOJCYB2iISaRbAkIVLft2CUWw0FN3SOn3sDOUFMSoy7wv4Nar4uqvTelqm2MGwoaXWG
41CqcK8YkJDckLn6pnGS3fuy5ndrYaWzw15qJmub+7R5bcyhK+pPb0bKro8aMrDky4siX8o6
ZnKchXunHon7vGT+GL/tw5X6DALvM3Z7Nz6q9JQ8m3FsBJFTp3HbK4Ln5vAhLszmXrjy/qLH
3lbqfzbn1V6SUOTTiz4SlCu054ylJkz7856sjMhXgyw3iJ/DWYp8qPOV/wByd1t0pc+qvSY+
4mcu+vOE+n6bU+pKuz1NtqK1uhU3bqpbzzbrqFLTmQ403h3CJgnGMfntz3spb6STTVaYf4GX
3J2xyO9r7sWdpTSrilo8TZi7SmnLnrPUll0tZ/CVdb7VIpKHx1hpoLXPFazsAGJjwZaxLMXF
bjpfoM/nc7bydmV66/UiqumJsa9yXcaAT4fw88CqSSi5CRxlPFsRml2Zzb1x5f1GlLvN3Slt
PpPq/rNT7jS1FruFdbKpKU1VuqHaWqQlQUA4ysoWARgRMHGNelGUW08GsDoVm7G9bjchokk1
xMyDw04Ra44uv3un0XSUlS5YWGn6/wB7qm6YZXl5EBJc2kkGPbkd3Xs62rdMOExG/e0GU3NC
Esy2lN0VFXHTiZNVyg8dkGarBbVynJKbtST9KxHvfZjOP2eX9RgId4m5n/El9RjF8ovHdPq6
dt68MMt1ohM+VwRD4Zzi9nlJ/wBw9y/eS+pL0Df6ovHYDDTdAogiSfvWjBMxOfryhrs3m3p2
eUa7xNzP+JL6kvQeXceVjjzbKdVUvQpuDaEKUpFuraSrdkkTP1bbhUT0SGMV3Ozmdi8IqXE/
Seix273NdlTpqccZLzGvrqHWXXad9lynqKdam6ineSptxtaDJSFoUAUkHAgiMO4OL2ZKjRuN
q7G5FSi001VPhROs9prr7drZY7Uyl+53iraorewpaWwt55QQhJWshKZqO0mUShHbajHFt08Z
Xmb0bMJXJukYqrfAkbCK5Q+PzbqmXdHUra21FKv5VoDIgy3PRmV2cznsr6yNLXeJuSn2svqT
9BKHKLx6TL/RSgwlh97UPp+tia7N5v8AZ5QfeLuX72X1JegMOUDjopCVnT9sbUdrZutKT6Fk
Y9sOXZrOfs8pU+8Xcy/iS+pIGOUTjuAD8M0Cse8BdaLDrxd+SIrs1m9ezyj/ALi7l+9l9SXo
MNay0hf9AahuGlNU0iKG92zw/e6dt1DyAHUBxBStsqSQUkHbGKzGVll7jhPSja917zsbyy0c
zl23bk6JtNYrTgy0ikHbhFaPRcPTtBAewixHklpLwSYZFoIDDItBEmGRoFBgINDwYkRaCAwE
WggMMjQIDDEY81ig1FysSAcGn5n/AAsI819usacKZ793T2Lm14Df2mqv9D2m0oGFoCcm2UmJ
YxnYNqNTU5Q/mm/2vObScg2HCa8JMpp1XXAy2f5LRxTuJONqaeq5JeQ0Pvg/rMPwY/8AtM6C
fY+SM2cqJcACgAC/6pgAxjqb9G52GADUfiCcHfLABxu5pVlfEakbKUhDVobmoesczzhx80aj
v5/vlxH0L3SR/wCvucG2/IjA1rH1qZ7IwcdJ19rDEuZbgPVjsj1pnhuQxAlYI6obIpDZ9EKp
NCBlDqSaESZE4dcQrQqaqzDOtuI9Rbqx602JSC8x3autWAoJX81AOGG8xnMjktuO1PQ9Ry/t
b24uZO88rk6bcflSeNJezHU3wtlg2/iTq2jqA67cff0j1qSoQlSCDtkUgEHrEZCWQstUSoaL
lO2+98vc2pXdta4ySo/GqNGx+ltTUOpraivowWlpUEVlKszUy5KeWe8Hcd8YTM5eVp0Ozbh3
9Y3xYV23g1hKOuMuDw+B6y7m5nEEy3GPC02bLAkJ2zmYugVzJEu6cZS6ImeeRvnyPJPi8S1S
Bmm3AHyuGNt7LYq54jkvel8jLccvMbna41rZOHmm6/Vuovefui2qaTVGja8Z6bywhOVvMmeJ
xxjZczehl7buT0I5puzd17eOYjl7CTnKtK4LDHSYNTzg8FjIpq75KeI+7Th2/WRio9oso8fW
5DaP7eb3eOzD636iYnm+4Kp2195JG0C2q/6yJfEeS4XyEX3e741Qj9ZegwLzGcfeHnE7QNDp
zST9zfuKbyzXPKq6P3dtLTTbiSMxWokkrEhLpjE743tYzNjYhWteA2rsZ2Rz26s7K/mFFLZa
wdcZU8HgMCcvcxxq4bA7fvhHdlP7NZ/cjEbo/wB3b4/Mzc+1L/6vMfQZ2nQo+I2QB3Th2x0m
csT5laoq8COA2syDrPV4Hq/fVwG2YwqXNkcozkv5i59J+U+stzpdSsU0dHHyI3f5EQE3Dicr
b/FLan/1rhjZ+ysvWucSOa97ONnLr9p+Y3s1Xqiy6NsVy1NqOqFBZbSgO11ZkW6UJUoIEkIB
UZlQGAjbb1+FiDnN0SOR5LJXc5ejYsxrOTolo8phdPNVwIIn8aKM93uNYP8AooxEt/5P2+Zm
yrsHvl/wP/KPpDN803Al1xDQ1ylouEALcoqtKBPeo+FgOuJQ37k38/mYpdht9RTfQaP2o+kz
rbrhQ3SipLpbKxqut1e0l+irqdYW262oTSpChgQYy0ZqSUovxmqXbc7M3CapJYNPSjlvzm6a
prRxaYvtG2hkavszNbXoTIA1lO4undckPnoDZPSZmNE7UWtm/Ga+cvId57ss9O/u+duTr0cs
K6otVonx14jBPC1sK4m8PETAB1FbzOX/AC6d8Yjd0a5m0v26m5b9dN333/py8h3VeE3XJDEu
K2HeTHVK4nyatFTB115i+C1jutzsl011TUd0s9Q5SXGjVS1ii2+0ZLRNDBSZHoMoxt7e2VtX
JW5SpKOnBmzZXsnvTM2o3bdluElVOscVy1POPNHwIGPx+zLAEiiriB2/URBb8yXt8z9Bf8Eb
5f8AAfLH0hE80fAVU/5wWEkHYaKu3b/0G+B79yft8zEuxG+PuHyx9Jze4/6nsGteLOp9TaYu
CbnZLgmkFFXoQ4hLnhsISuSXUoUJKEsRGl75zNu/mpTg6xosfCdt7GZC/kd127F+OzNOVVVP
S66qowy4CAYxiZs0iXaFfXxYjyvSXklWESIsKDDIhATARoEBiRFoIDARaCAxIg0EBgE0EBhk
aFkXvv3e3jodT8sea8qtF9h0ZvZbGwdIhwTmm2rx7GjGftP1Ua3JrrNP2l5Ta/kIl+E94lu1
VXT/AOy0cUbjVIXV/qy8xoffEqb5h+DH/wBpnQL7HyRmzlBLgAUAAH/UPZABjHU3qL7DABqN
xB+2gA4180RI4lNT2G00+Ufvj2PojUN//bLiPonulX/Wzf8AqPyIwTbD9amMJDSdb0ouJezb
jtj0xR57joRVKkeroiwrWIRB6ZYxBg0EInsljCSConQUsrUgd5KFKT2gQ2iKNKKqrcUurLqE
rXUvqW+6pIzhYUTJJ2ic8Y3OMEqU1JHydfvynKU56XOTlx1L/p+IbtPoW1aNpdLWKlqrTdXb
tT6yRSJN4cU6kJ8F2oVmCmky7qZSi+V5yt9G0qc5VGz6+3jo0V/RHu8GnXPva8MDMppVGhRE
8AoOCRlsnImMRvNfu09Z0XuzvuOfuwq6Sh5zZVgSEjjhMxgZHcILAkbDv7IlErmgoMxKYnv6
IsWJVI335IFAfiSJiY+75kfvmBjbey2i54jkXephHLf5vMbh6+0VaeIumLhpG/PVTFruK2XK
hyiWEPAsrDicqlJUNoxwjZMxYjfhsSrTwHM917zu7uzEcxZptx0V0GBE8mXCQkq+8tSkqxxr
GpehqMR7gyr9rlNw/uVvRuuzb5H6SWnkt4RuZSu5akKd4FY0M3RMhndEvhvKN/O5R/3L3p7N
vkfpNYuZPgrpDhAnRZ0nUXR9V/NcLg3cHUPBIpvCLakFKEEE5yCMdgjA783bayatytVpKunw
G79ie0+a3070cxGKcNlrZWqVcOYx3y/qSONXDfGU7unZ/wA2uPFuf/d2+PzGa7Wf0rMfQZ2e
Sshacd8zHS5LE+Z56HxHArWP/jDVhAIBvdwkP/iXI5LnPt7n0n5T6y3N/sLH4cfIjd/kQI97
4mzwPu9tAH+G6Y2bsmqSucSOa96/2eW+lLyI3A40aSuuv+GWrtHWL3b72vlM23QKrHC2yFod
QvvLAJGCeiNoz2WlmMvO3Gib4TmG4N42935+1mLibjB1dDnynko4v97NW6cE8Ze/r/ca3RqD
7L5p648p2P8AufupfNufVXpHf1I+Lq3Ald10w2hZCVvCucVkE/WkGZqkNwiK7L5muMo84p95
26nF+rdrq9VaeU6PcOdIq0FoTSuizWJuTunqBFI7XIQUJecmpa1ISSSElSjIHdG45Wx0FqNt
OtEcZ31vJbxzlzM02dt1p4qHOznNv9FdOJ1ntFG6287pqyhi5KQcxRUVLqnS0qWAKUBJI640
/tRcUr0IV0LHwM7J3W5O5ZyNy9JUVyfq+FJaV4K1XiMC8Kin8TuHInt1DbynGX26d0Yfdq/m
rT4JJm6doJf9dmPwpeQ7lvLKXVkblnt2x1Kp8pLQaxag5UeD+o79edSXZq/KuOoK12vuXg3H
w2/GeM1eGPDOVPVOMTmNxZa/NzknV+E3TI9vt5ZLLwy9vY2YKirGr5Tzm+TjgcpJHuuoCcJk
3RQ2dICIqXZ3J+y+U9H9yN7LXD6v6ycxya8Cw62H6C/vJcWlISm6uJluwITshvs9kqfJfKyu
feRvfaj60NPsI5fanttLZtT6ltFF4nuVpu1ZRUfinM54VO+ttGcyEzlSJmUaLnbUbV+cI6Iy
aXEnQ7xu3MSzGVtXZU2pwjJ00VaTdPAW+4cDOPNE9sh9sVleJi9HjbxLzaVmlAgZLAwiSRCo
oAHgwCaCAwyLQQQyNAgMMg0EBhioWddJG70PU6n5Yqu6iVp4m9dC7k0QsJwWLcuU+tsxmbcl
srgRr8be1m037S8ptjyFpy8KLwn5uqq8eanpIW5cbdx8NyT8hoPfDLa3xbfDYh/7TN//ALHy
RmDlJLgAUAAH/UV2QAYw1Me451AwAai8QTg95YAONfNHL8S2On7opp4/8q+I1Df/ANsuI+jO
6Oj3ZP8AEfkRgi2mTyDOQ3mMJHSdY2S5FqwE49UWeeaqQ1bd3WIbkKg4EwqhQKlctu7fEkRY
Qqmkj0wqVFF0ZgXXPDWser629WFpK2akhx61JJKw4r1y3PbM4yjOZLeSjFQuatfpOO9r+wN6
5mLmbyNJKXrSt69p/KcePTQsGj0JqqsdSwmzPNTwLr0m0J6ySY9/XbGqSfEaVZ7Ib4uyUOry
Xhl6qRsloPR7OlrepsvePcKwhVe8BJPdBypT1Jmcd8YfOZnpZKmhHZ+yvZqO5cu03tXJ0cnx
aEvAq+Mv9Pd2bZYyjGSdDbraDZhMz6JxbBlVx4hgSRKZHWN0SUipm/vJCDLiNMGY+7xMgTl9
ZG49ll6txeFHIu9RYZb/ADeY2Y46awvvD/hnftWabWwi7252lRTqqWvGbAeeShc0TTPA4Yxn
N5355fLyuQ0o0Ds3u61vHeFvL3a7Mq1pg9Boajm34yh1Li6mxq8OeVBt3dxHU7tjT/iLNafV
5P1nYZd3G6FhS59b9RITzhcZ0mQesATjMfdp2H9+3RL4kzb9nkKv7cbpX3n1v1GNOJPGLWvF
lFlTq92hcFh8Y0HuVN7uZ1GTOV95WY9wSjwZ7eN7OtO606aKKhsG4uzOT3O7ksvtevSu066N
FMPCSuX9P89PDmU5/e6QAN823Is3Qv5u39Ir7Xf0nM007DOzZGVQSN2wx0t/K8Z8xTwi+I4G
axWDq/VZkcb1Xkf9ocjk+dp08/pPyn1puhPqVj8OPkRvByKYv8S1YH6u2gdXeejZ+yn8TxHN
O9j7PK/Sl5Eb06q1TZNFWG5an1HVmgsdpQly4VaW1ulCVKCAQhsKUcVDYI2q/mI2LbuT0I5H
k8ldzt6NmyqzloWjymFP62XAkgS1e+Zjb9213/UxjPiLJP5/MzaF2A3z9yvrR9JIpuargQ+8
2yNceAp3DxH7fWtoSZgSUssyG3aTKCO/snKVNvmZC52E3zBVdjklF+cz463RXm2ONeMai23W
mkH6R5TalsvpwW080oKTNKphSTPojLqklg8Gaqtuxc0UlF6Gta4Ucc+YPhhQ8JuJNbY7PV1d
ZY7rSM3izu1znjVLbdQpaHGnXTi4UOtqAWcSJTxjm2/MisrmKRrstVxdX4T6U7E76e9d3q5O
KU4ycXRUWCrgvGWpwlSV8U+HKRP/AMRW/MOx5JlHm3aq5mHGjKdoF/12Yf7Eq8h3OeA8VROw
LM59E46ktJ8pajnrrPTHOHV601fUaXevB0y7dahWnA3cbc22KQqHhZELcSoADcoTjVc3l96y
uyduXqaltI61urN9lbeUtxvxi7uz6zcZP1uQ8BvSHPKwCW6i8AqUM38p2pRnunN0iKI5fey+
dzo9fXux70qH1Z+gMnSvPYFBaqy9JMye9c7SBLbsDm+G8vvaWt/WRNZ3sbppBv6M/Qaq670v
rDR+qrhZ9fUa6LVT+W5XFpx5p9Tnvs3Q8XGVLQc5JJkY1zOWLtq41dVJacdfh8J0Lc2fymcy
sZ5N1tR9VYNU2cKUeOCLLeT3THmiZCTG0Ew55YuqeVrEvKkMwIaBnpAxIg0I74AQ0QDZJQJx
JFcmEkYZCopyMIBwMMTRZ9zV/K1D0h1PyxC7XCgrNds3fp0rOlgcQBbiRL/m57YydG4eChhI
yUcx/m85uByEj+aS5mUs2qK8y7aelizcn2L+k/Mc874f6zBLVZh5ZHQD7HyRmDlRLgAUAAH/
AFFdkAGLtTfo3OwwAai8QT+m7TABxo5of6TUnEkWmmBPQPEew88ahv8A+2XEfRHdLT3bP8R1
4qIwZbT9cg9ZkfJGDWk69FnuOKkNuG8x6IlE2R88zthsr0BQR5oSYaSubrHUYlUdAyDOU8SI
mmJxDmShidu2GnUraoNQgTO3bBs0IsmoVl2YYYQxJBwqezokOqItFiDBO07AeiJxVCmekkIV
LqBkDLbjE0UM205YOLuh+Fx1ojWdZVUH3umjVb3KemXUhfg5wsHJ6p7wlGy7h3jZybn0tfWp
Si4Dnnbzs9nN7Kz1WKlsVrV00mV+PXMFwu19wsv+ltL3etq71cX6M01M9ROsoUhp5LjhLisB
IDZvj3b23zlcxl5W4NuT8BrvZXsbvLI7xt378VGEa661qvAaCAAAnKEk9G6NNodobTdaLxAT
t8sRYkgonKW+JIGZE4Q6itWkuJ2itSX2oNJZ7Pc0P3CpCC4W28qklWROJkTuj3buvws5mE54
RTxMJ2gyd3NbvvWrSrOUWkvCdMk81XAcEJVrUpynEmiqdvkRG9y3/kW6qfMzga7A78cGug1e
1H0nIPUtQxW6j1BXUroepay51dRTPAEBbbry1oVI4iYI2xzbNXFO7OS0Nt859JbutSt5a1CS
pJQimvCkqm1/KLxO0Fw4e158cahRYBeW6AWsuNuOJc8FTpc/RIVKWYbYz3ZzP2Mr0nSy2a0p
U593jbizu9FY6rBzcdqtGlTRTTTSZ348cduEGruEOtdP6c11S3S9XKnaat9tQxUpW8oPIUqR
W0lMgATMmM1vTe+UvZaduE0214dJp3ZfsnvXKbzs3b1iUYRnVuqpSnGcwkzG04j1eqNCcjvk
YCIJChMkEYplEYyY5R18B1s4YcwXBq08NdB2q88QLfbbrarDQUVyt7rdTnaep2g0pBytKBll
3GOiZLfOVjYgpTo0ktDPnzf3Y/elzeF+dqxKUJTbTTWKePCaf82GvNHa/wBcaeuGjL/T6it9
BYk01XWUyHEJS8al1fhzdQgkhJB2SxjXe0Oes5m5DopbVEdE7vNz5vd+TuxzMHBudUnpeCxw
qYV4a3e22LiFoe8XeoFHa7VfaKquVYoKKW2WnAVqISCTIY4CMVkJxt34Tk6JNG279s3L+Qv2
rarKUGlx00HXB3mN4FuKWtHE+0KQFGeFSN/WyDHRI71yj/iI+cX2P3wqLq0+b0jBzE8DB3Tx
Ps+acvt/+pib3plPvIj+EN70/wBtPm9I5vmI4GrWUjibaCRtn44HnLMoh71yn3kSp9kt7r/j
T5vSFVzFcDUJB/E20HvZQAKgknsDMNb2yv3iJLsnvd6MtPm9Jzf5l9W6d1pxcr7/AKUvLV+s
qrTb6Vu4sIWlBdZSsOIGdKVHKVbZRpW/c1DMZnag6pKh2vsHu7MZHdnR5iDhPbk6PTR0o8DA
qu+IxMWbZNDqVEnIsPO0XTSmWESQmj00xIgOEoBDgPLAKoRBAiSItBCqGQoMzQiVBwMAmi07
h/8Au9CDvdT8sVzxaJ2oVdTe11PhaKU4nulFrUUlO2fhYRmmv3eDwoazZxzaX7a8ptpyFmfC
O4f7TV3+b0sR3H9g/pPzHP8Avfdd9R/Cj5ZG/wB9j5IzJywlwAKAAD/qK7IAMXam/RuQAaic
Qftu0wAcaeaJQHE1kT9e1U4l2OPGNQ38q3lxH0T3S0W7peG4/IjBdBLOk9sYSOk66ke076ow
7N0elYo809JFE5wmNRCgxFBQrt8sOoBEk9nXBUi2HSSdn+7FkRUJCZ9BBG2LGyLCA/24Wkgy
S3jLCcQeBONSRmIGGzAHsiyOgruISXJlR3fN2ROLPM0PzZjjgZ92HtDRPawHyRLQIlETn09M
FQQApkejHbCaJhknDZLrhUIsjvAnYQRuMRaBHnrE+qHUsjECodWyK5Ylow4dGBiLQqVKZp4j
b0REnsjhPHCUSQUoPT1HfC0CoFCgOvDfjElIio4jSrdgZ74VKlqQQAEfLOLNBGUSoQIKlLiP
UgK3CQGyIg4VQ5CJAjDZtHRE6FTiGS3OQIBlgOqAjskhKJZeicobVSxYEjw8IcUVTH0wk5iI
sKC4KYTOENEJHqAYRMpKGAaKgwA0P64ZEYVQiSRUGAGggMMg0WfenC1eLVL7R5MvPHnvz2aM
9WTtucmvAb81JCNEPJUjODajNMsFTa2Rsew3aouA1GxH+cX0/ObXchP9EdwHRqau/wA3pYo3
F9g/pPzHPe95f90vwo+WR0A+x8kZo5aS4AFAAB/1FdkAGL9Tfo3ewwAai8QRg95YAOMfNIJc
UKZUjhamJnbtcdjUt+/beI+he6j+nv8AEfkRg2gMlpjALSdgi8D1XF7I9cXgUSVWDSYTY9CC
fJ1RGpEMkYflh0qJsJhLo+WBR4SLQRMvLslKJJMkGCxuEWLAiESqfVPbEkImIO3DDdCdC2Og
cfWlIynjIxJIouaQqEjDr2RYjzyHiUxL0CCiEsSW2qQ2wPETVA4cG3b1xKlCJQrBIOBxiDGh
2cSwJBAxMFakqAC4CZbtkRHQAtO/rlhDoNOhDWqRxEp7zFMsCxSqDKiZYSiNSVRBPSIkkPaH
jsx6ZwUCo4Tn2wqBtoqRPZjDHVD8kh8kWRQtoIiY8m+CTIuQdKZ4CEkV7QZLcuzp6ImkPaHJ
bJPkixEGySloyBlJW0xCSI7QVCDPCYx2RCoqkpKJDHt8kThiVTBI/SxaypHuUZlthojJHpZh
KJFdCgXPCAB4EAVHkgCGQI5UJxEtSHgwCaCAwyLRZOqVBN101mP1btSQuWB7pTv8seXNR2qL
wnt3dLZuP6LOhVeyhrRbgVi2LXlyjfNnCNllL91WPAaXYb62mtO35zabkI/oiuH+01b/AJvS
xTuJUsP6T8xz/vhp77VPuo+WR0B+x8kZo5WS4AFAAB/1FdkAGMdTeovsMAGovEH7bywAcZea
XKOJrIImpVqp8p7HHY1Hf32y4j6G7qKe7pcPSPyIwPQ+uIwR16J6jszs2RdF0RGSqwYmIksR
NBMwl5ITKwyVGJIiPzynjhE0x6B2ae/fA+EiOCunGI1qAcKlj8kWJ0AlNOjqlvhE4yDFwTG8
bYalQJQqGSsyTI4n+zbBtlUrQVBkJ7JDGJ7ZDo6Bgoq9EoNsUoB8ZEzxhuZHYKEyn6fJC2gU
AeczwO+eEClQHCg44CfoMPaI0KEzmD5ISlUNgCtAIJ3mFIsjAAG8ezfEVQlsj0tzkOneTD2g
cA7dPgJ7t0JsjQOljZuAnDTI7DKeBORlDSRJIMGZjCYJ2mJicWULI3Gc9sQckRcB6UZcROZ3
SnjEk0LYYcSPT1iUoW0S6NoeBv6sITkLo2wqTM4jyxJSqJ2gwG8bZQVQdGwpM0kAY7CBE9oi
4AWkHxSTgN0SUqlTt0Z6bashhohKJLDs8JxMq2SgUQZwEWiSl7rlDK2ipWVb4KDSHJRPGcOh
Ko4J64KBWoYJHTDoRdSwtXki56ZTNQm+4ZjZtRHkzaSo9dT2bsrO7KP7LOh9yKkaKdTPum0h
KycJANDGNh23HL4YunmNLyi/nI/T85tRyEiXCK4f7TV3+b0sV7hdcu/pPzHP++D+tR/Cj5ZH
QD7HyRmzlZLgAUAAH/UV2QAYx1N6i+wwAajcQftoAOMXNMJ8UKcz9W0sYfvjsalv37bxI+hu
6hV3c/xJeRGB6L10AbSZCMAdgtk2pe8MlJBBBO07YsToK46Mh++Jn17ontFLuIYa1PTEcSPS
RKpuKEkenGJRbRB3ojxcgcomREtsW3FlfvBM5fuwOYbSqO+8kykcemULbHtIIm6I7Z9cHSPg
Gpxesd96gS3T37oXSMNqKCpu6PypMTV1LUSVxMKL2gHYZdvniEprgIqS4SQL8zIfVqPRjKJd
MvZE8dYdGoGAZlKsTMpww7O2GrsdaYONdaJA1DTHLMKT04bOqcWdNCmFSpwlUeb9RkDvLJl6
YOmgNQkD+/aZPzsZxHpoj2GPOoKSU5rHTOW2DpYi6N+AYb7TEkAqG9IIwhK6h7DKffdOZ4qH
REnciSUWiv3zTgzUoiR3dEQjcVcWybiUF8p8DMkzPRshu9EjssKNQU6QNqjgZbO0Q+lixdEx
yNR00+8FhIxhdLHWNW2PVqOk3ZpbJbfLDV6PDQfRPhQ74kpMyQCuUpFRH7kDzEeBkXabT4RK
1FTGRSVknbhhFbuxCNqXgHDUdGkd5TkxMCQ6pj0xZG/CmI3akuAcnUlCMslOTM5kjZPdA70P
CNWnroPGpqLoXiQN3liDvxqSViXgHI1LQEgHxEjGRI/txNZiC4ROxLhQQamojiVLAwEgnGUJ
30wdiXgDK1TbchIU4ThIZf7cON+C4Svq866hDVNuTsU5ir5uz0w+tQ8IPKzfAF+K7dIELXun
NO474sV+OzUq6pN8Aw6vo590qlsxEofWoUH1OQYaspjsXEVmEyLyjHjVVOfzhE1fRU8qGRqu
mG1wRLrEUHVmS0awtwH1jkgIfWoClk56gqdY2lQEniFHYJGF1yAlkriHHV1sSCVPnZMAb+yJ
RzMNbCeUmtRad2v9Ddr1YfdHFOIZXN0yIkpRTgOyUefN3I3KbPOW7utSszlKWlp8lDpneG56
HqknFQthCk75hqNnin1fTqNAyEv52Ev2/ObS8hJnwir/APaau/zelircP+3f0n5jQu+Ff90v
wo+WR0A+x8kZs5WS4AFAAB/1FdkAGMdTeovsMAGo3EH7aADjDzTJJ4oU6pTSLVTz6vrHY1Lf
r/fLiPoPupi3u9vV0j8iMF0BAcQehQMa8zs9pGWxY7fedL0qH0hL6c/hVaU99tZUT1T6JGMr
asxdlNvEw+aUlmGYOu1FU2upXTVAkpJORY2KHSI8qimyi/OUNOvQeMaiW0mJbB5HmaDPesfW
h7BDrXhK+9dBPkg6MfWxCq/uvJB0YLNiNUN6pQdGN5pcIvewJyMoOjF11aivvc/ztsLox9cr
rKir3ZoOjJLOeERqxvM4OjB5xayorOuDohrPFRV783pg6MfXEONaTgTh5YFbG87Ur79smqRG
yF0Y+uoRrT+crDfD6MTztNLGiunsPlgdsSzyZX3wj849phbA+uDhWn504Ngks4L35U/XOEHR
i67jpK+/K3KhdGS674RvvyvnS6DD6Mj11iFcTvl2mB2xrPVHmtMplZnEejJvO4aSnv2XatXk
h9ELryWsr76rplB0YddZX34jCZ8kLoh9eoV9+J/OI8sHRkuvVKiulgVTO6ULoxrPJFDWE7VE
w+jE85XSOFaQPWg6Mks7RFRXzmCqcLogWeRQ13WT2Q+jE88mL344gK27oOjDrxUVituaRhdG
SWc8JVVaQDJRM98NWwlnKFE1yhtVhDdsjHO0H+/T/OJnC6Ml1tC9/UB6x7YfRh12msb94rGA
Plh9GiHXnqCJrC5gFemFs0JrM7ehnuafV/K9uWZjK+iR68wEQlpXGj1ZZrabfA/IdZ690DSV
Q3iEm2rEjOeLfTG4bO3b2Y6GuA55lLf8zD6XnNr+QkZeEVeP/M1d/m9LFPZ//by+m/MaB3xf
1qP4MPLI6AfY+SM4cpJcACgAA/6iuyADGOpvUX2GADUbiD9tABxl5pcOJjPXaqf+EdjUd+/b
LiPojuo/pkvxH5EYGoPXBImJxr8jsWXNgrM2VacplHMopzZgZEhQUZYnoEZmxFKwjE5lfzDM
S6so01LiwtPfCZIkJSO3aYxMpuEz3PKRv23HXqMK1gcYeW0sEKSd2yMnaSmqo0XPOVibhLSg
CEPLllbUqZwkCY9iys6VpgYqWejHSwhYqZT8FfmMPqk+Ag94x4SnhVYOUNLnOUiD+SJPJy1o
XvNRWlDSxVCZ8BZx72Bg6nLUiC3nBvSihbqR9g4OqRiLyslpRL3jGmlFUtVnsHJbcQfkiXUp
tVSK/eyWsQTUkBQp3AOwxFZSXAWrea/Riy1Mj9Q4ZCeAOweSJdRnwA95paWLwqokAMuEnZ3T
A8jcWlB7yjwiKKlPrNOCeABSRPp3boTyklhQXvSPtIdkqc0vCWCJTBBwnsgWTm3RIkt6wfzh
uWoxm2oS6RA8nJagW8a6xFFRKZbXLpkZfJAsnP2RveK4SmV8AHw1SJwMjB1Ob1C95Jayii/L
FKpDdLbDWRm9CB7z4WRjU5FZTPNvA2xTPLuLoyUc+v8AAkIW84CUoUsDaQkmUV9GXrNSloVf
EVlUjAtO7NmU/kh9ELrM1pT5CpFVgPBdHR3Ds80LoyTzE+B8hT68S+qdMwSDlVsG07Iast6g
WZlXXziQ68vN4aFL8MAqyg4A74nHLOWhVK57y2HRsfKoP2Tm3ZI/kizqNzRskPecXrRT+Mex
c6dhgeSmtKD3muEePeTsacPkP5Ij1ST1E/ea4RTqMPqVmeAMiYfUrlabLF70jwobmfH5i9sj
hsPRCllGnRoPeSWsSnX07W1pnOWELqcuAPey4RBb2P1ayZYiUHVJcAvekVpZQuug5S2sFQwB
Bh9TlwDW9YvWVU44kTLapSmDswhLKyehD95xpWoi4+DLw1JMt4x7Yl1KdaUZBb3i9DQ3x3lE
AoUO0HdB1OXAN72rrGh9zAlKiD0b4HlGtRFb1WtiNU6NiCZeWF1R8BL3vwUBqrViRV3PJKF1
V8BF74xxdACrklIBKpbduELq7E97xpWpVm4e8EJbUVHfLd5IjOzs6SdjeXTukXUuajSQkTwj
wXHibVlINRLosxlcqFU5ZHEKn/hCKn5zL5fGfiZ1tr8q9DvuKkAq2qVmnM4t7jG52Wo2VOla
LQaDYlTPpftec2z5DP6Iq7/aWu/gKWPLuBfy8vpvzHPe+F131H8GHlkb+/Y+SM4cqJcACgAA
/wCorsgAxjqb1F9hgA1G4g/bQAcYuaY/zoU6em0sfwjsanv37XxH0J3US/69x/1H5EYJoPXT
uxjXXidmy5sTZFob0xSANJHihRUpIksqBPyjfGattxsUSxMTmY/zMsdHIYov+bx1hasx3Doj
B3auWJsGXS2cDFmoaD3pCfBSRULWlIlhmmZSHX1xldzpyuqOo0jtvZisrO6sJJaS7LbpCqLD
Ypw8GlAJSrvEmQlKR3jqjoLtNRWGB82+97zdXI9UaNuBOX66UsCokmYEzhv6ojG0mEt6XXip
McNH16wkjxVhe3Eqx7IkrSbKlvK+9LaJCdG3CQADoTtzSkcNoPUImsvwC95z4ecING16wgLK
0qJ7h+djhuivoqOlSXvOb0SHq0dWyksuqcGJBmPlhRjR4oqW8pN0qmPOja1s90LAX3jhM4CU
S6NT01G94XGsJAlaRrW5n65IwBX6u3YIFbUdRD3heSxkDOk6xBkrxEBBllHX0mF0SJLek6YS
KjS1WvMJvyAykJJI8h3Q3Zt8PmD3jcWh1KK0hXEYOu5sxJM8TPZhL5YjG1BPSw97y1vEju6L
rnFJV71UIzESAlu8koTy1U8SfvWa1nmu6DuWbMbpVpKQVECXd6NmGELq7SxbLviCUVSi8dTz
XtEXMZVKudW8qR72WUt+yEso5aGxrtBN6lylsV+k7i0iSq50pI27BjCuZSUccWNb8k3p5zwb
fanLZWOrqwXQSnwnnE7T0TmfJGu7zjPTR0Ohdh8/ZuzlttbeFEy8mK5lhJSHEpBxUBIYnpjC
q5I6p0lpcBJTdkGSSueYFKycs5RPpZFe3bk8SQbyjvAvYgBKcU7tg8sSWYnHQTra0VR7Vt1S
1TENOhp/KCtIUUgCYIls2dMEc7dS0E42bE5UUknSpEtmm6isqqmspkLZafCSrKAEnMSoEdsb
DuSxO5FuWvQci7xc9Zt5qFuy/mtypqeqvAXP8K3EqVlUtKk7SQAd2AmNsZ9ZeSVJI5tDeVyl
doadM1iAlCy6iZnIpTPHESw3wRy7ehEXvO638ryhE6Xrl5DNYCyTMJmZDybIk4age9JLTLyl
VabuA9bOehQSJfJhFfVtoUt5zb+W0I6YriArKqQM8xQkT69mMNZdcfiH73kvnjDpmpmtRaJM
pkFAB6BugdmXATjve7L5zHK0tWICsuYywSgpSrAnpAnCST0ilve5w6eDT40BOma9WxClTMyQ
kYAeSB5dPRgJb1uv5ww6YrVYyyiUwlSAMOwiG7D1C96XI/KkAVpmrSe6ASfWTkTu8m2FPLTp
gNb4uPQ2ec7pqtVmIGYKUSSUpVKXRhEOrN6gjvW7D5xDe0xcGppGCQJhSW0kT6dmEONqmocd
93aYyZ5VVp+6gLAE5yCgGxt8gh9EtaJe+bunaZaFxsF0RmnPCckhAO3qlhC6BNPAI79uaNpm
M7tS1tM6UPKUJ4jCQ80eS5YSxoeiO8bl3TI92woWhtta3J5kgy7Y1/PUq0kdO7MqStxlKWlF
/wBJikb+gxhLmk6XlMYlzWYA3GhSsyQXUhR2SBUATOKW9HGZfLPZlXwM6vPuJOg3EhU5WpQm
cZ5W5fuRt23/ACro9RoVqP8A2Cf7fnNwOQoz4Q1p/wDMtd/AUsR3D/t39J+Y5z3xf1uP4MPL
I3++x8kZs5SS4AFAAB/1FdkAGMdTeovsMAGo3EH7aADjHzSJ/nQZWdgtDASevxHY1Pfz/epe
A+hO6eP8hKT+8fkRgehHfTPAb5xrzOz2DYqzlB05Q5FFyTaghrFMiFEGc5mMwklbrVtGIzFV
fdTFt+SnxVKCZCZ3zGMYS5izPZZ+qefpe0C86ltVB4QdCncEmfRj5ozvZ+3KWZikq8Pg8JpX
b+S92XW9SqdEbZwhaFtox7sB3AsAJlIkDYBHYHlIpUofHTzjcm9Af8JEEqQ5SKSneMJHqBlE
VloJ1SqRWclpqOPCemVmHu2ULA3SUN23+1C6pFv5IddmwiOE9I2o5Wi4CMQobN0pARF5aLw2
acRU83PhoGTwpa2KpElEppAnIkeQSPRCWUivCDzkhx4WtEZRSgZcSFJEserfE3lINJ0JxzLZ
HVwobUnKumJKSQmQygpJngJboOrYoHmpamNTwnp0qIFLIS7yRs8xBiUrNMFFFfXZ6MBqOFNP
3lKps23K5Ikgns3RLom1o5glm5OlWVVwmYUslFPlQo4JUB+6JwdWjp2VUazT1VGr4TMpXIUI
KQO6qQn29cLq/gXIVPO3Iuj8wE8HmSVqTTKbSoTIInIbwOmCOXt00E556bekCrhKxmBXTlKh
gkZRNU+nDGIyyykqbCoUyzVzVQ82o4RsNtLJpgc2CgUz2dOGMOWXTVNmhZHOcKxMXas4ZtJp
XEpokgImEry4gnYDh1R4rmVklSh67Gbe1iYCr9EIT4ja6dQw3bJT6Pyxh7thSbVDO5fOztPa
g6PkLZ/D+nbcKw2pWE0iWzzCRnFc8ol8xciMv8S5v22vGyvwI0iQNIV5JIE0z2z7OmEsgp6l
yIb7TZ1YK9LlJyNBMOqKV0AKsc00ylPbKLY7vil60U/EiD7V55L7aRkPSPBQXasplCiQkIkp
X1U+4d4JwOEejL7qhdaewqHnv9sM6otdJJ+OhtlaeD1HRUrLLFMkNNmam1JxV0T2ARnre7o2
1RI1PNbxvZibnN+s9LrpPYc4UNJQmVvTnGICQMuO0f24n0MW1VHlebaWkH+EqMUro2wGwAFB
M82E+2W6E8vbTwTKuuNrTjxhE8ImVZctLJHifmpImd+2FGwqukQebktYvwgb8QzpBiMokOmZ
MhPbCllIvUhrOLWVVwkYPfVRjMBJS8uM927CXTCjlFTAHmZN+rSnGVPCSnczJ9zKpASkMe3H
GHHLJfNF7wlHAGeDjJVm90lvUSBPo3RN2U3TZQdYnX1XyjTwdZnmRTKSdiVgbB0gflivoFwD
nmpKmKqVf4PtOKJFKlRQgJSFJn3thnPcRBDLxXzako56aVNRDHB9lGHugwnmOU+rLACQwE4t
VmHAEs7wPxJ4EZ3hG2vIn3ELUQSVy2byQNw3RDq1uuggs9XSeY5wha7pVTJTmxMk7SN0tghS
yiWNCTzVNB5j/COlUTkpiJTMsssZS3dkReQTxaoVreFxPRQxzqPhjRMJcz0IO/BEjslMy/di
E8nTRQ9VrN7Wk0m4s6catlYltLKGisFQSkS6fNGEz9qMXpx4DN7uuVi2uEx5R0vhKQggAJQm
e/aI0zPYNnc+z1qsIcGyvIXTSgACUx1RhLh0TKKiLmtCpV1ITiErSQMNyh04RQ9VeEzGXo5U
fAzqapwOaDVnISldsUQfWmCgkTjbU49VdOA0a0v5+P0vObpchX9EFX/tHXT/AMRTQ9wuuXf0
n5jmnfD/AFqP4UPLI3++x8kZo5US4AFAAB/1FdkAGMdTeovsMAGo3EH7aADjHzTH+c2n/wDp
TH8I7Gpb9+28R9D91L/61/iPyIwPQ+ukSG2Nekdky+k2JtAUdL0MkgAtuKRI4ZZkS6ZxmIz/
AHCwoYe/hmXxmLr2JOub5GUwYxF3SZ+x8kvTghTJqOIdoSoTTnMwRMbNsbP2Vt7WY8JofeFJ
rdlziO1DFoYRSsNBtMkNpGAlsAxjsmhUPiiTbbIptTIUZIEKoVegobUwcC2Ns9m+IthVlU2d
jb4YB6RtiDDjCCzs70CXWISSAf8AdLE5+GJ7olQi5sabOwRLwky7JxKtCLkyoszBABbBlsiE
opkKsYbGwSfq8DtEvk6ImpUHtMN9y0wHqDzQtIbbBmzMHAtggTwIhqiISm2VFlp0jutAEjHC
UAtpgVWVjA+EDIHKZbIdSSkyDUWJlaVDwxNWHmiMsQrUx3fdCorEOBtouTMggiYntnLZhEHD
aR6LeYccTFz/AAhzrXOnJCz3jLMP93rjzdAq6D0dcq9IxPBlmSD4IyoElJKAO70CK+rRlH1l
VkuuSfzhDgyys5yzkymc0pAmPNtMSjlItUaH1yTWlVLgt/Bm3oWlTlNnT6veHpGG0bMYmsql
oSKXmJPQ9Bl/TugbZakNBulSC2nKBlGHZHstw2TzXMxJ4N1ZfSbHSmR8EDZ6Itcijakwi7Oy
qc0DEz2RRQNpoZ9yU5lNsSGyQizVQi2ETZWTKbY8sME2h5srBHqSw7YhQi6lU2anwm2JjYYe
A02x33PTzmGwDukIekbY37kYH5gmeiCg9psQsdN7IYmZhOIbTBOWRnGSBjPE47YNki6kVVjY
JM2xidvZE06DTYFVhp5AeECBOW6JbYnJkR6wUu3wgMMJDf0wSaaFtvhLfrtP0slHwhNWBI2+
SItArjRh3WFjpVMrzN94AhOHVFNxeroPTZutM5d8wFEhi+NoQkqbyktFQGKZY9eGyNY3k/Wa
/TQbful0VMDXpbXguoAM1ZUzGwdeEaVvCNGdu7MVVqPCe1S4JEYC5pOmZR0RcFsI97YzEyCg
TLonFTMrlpLpE3qOl+n31PcMKbMC4sWqRG9UkmNstUdhpuippNTnFe8tpaNs335C/wCiCr6t
R138BTQuz/8Atn9J+Y5R3wKm+1+FDyyN/PsfJGcOVkuABQAAf9Q9kAGMdTeovsMAGo3EH7aA
DjHzTf0msSIGa104PZ4jpjUt+/bL6J9D91P9Ml4br8iMDUXrp7Y15nYrJsFasvw7RpKZEhUj
jMTJwlOMvFUsIxdyvWGzHd9RJ2WUpHbt64xF75Rncv8AJMg8BGvE4kWUSCu8qYJlMEEdkbX2
TaV7E0HvFls7ruHbppv6lvA+oPkjr58WpIjqZM9kRbCggzPdCqFBwakdkRYqBfCw2RGpCSF4
PZElIr2SnhdUFRjw1DqRCeCJbITYhnhHogqJoclkGColEqWJYxJMGhngz3Q6EWNNMDuhUAZ7
kk/miJJDoDVbmzjkT5oHIls1B/d6ZzyjDqgTINIX3e3syDHdKJNhQlNUCB+aIqbJExNME4AR
KoqBg3LdEqhQf4M4QmhvgmCoUHpbEPaAf4c4VSI0tGESSKpaxh1BxDloSh1CgLw+qHUQxTU9
0KomCNOeiFURGW11RIREdawPyQVAt+tZ7p2QVHsmHNXMoLTuYCQMwTFVyTppLLUMTlPzBsk3
9KikImFASM/RhGsbzS2njjXzI3HddVFJ8BrXXgoqm8So+GgK3YkRpu8Eqnb+zM27MZeI9ClG
A3Rr9zSdLyiwRcNsH8Yb2zmNm0YiKHqM1l44viOj9hWGOHNMTIStQJQJCUwZ49sbRZpO04y0
NeY1NrbzsVrqdBuQ0ZeEFUP/ADHXfwNPFnZ//bP6T8xyXvhdd9r8KHlkb9/Y+SM4crJcACgA
A/6iuyADGOpvUX2GADUbiD9tABxk5plA8TWEAYptTBP+MdjUt+/bLiPobupl/wBbJf6jfMjA
1FitPbGvSOyWFVmfbKQuxUi82bKlQJVgod4iXZGVh9kqOpjb62b8kWFex9bsM9pT0RjLypLE
zVh+qZG5fp/iTZ05MyCVZuoAT/cjZeyzpmo8GviOf94y/wCruOp2/ZbHgt4S7oPojsMpHxam
CKBPZFbZYixtacRtG8PBbfi26Ktn3wXU24JYdeLhYCS5+iSqUs42xCU1HSwLI/rGcHSVJGrC
VD833SpnPo/RwuljwkJM9Sy8deFd9uVJabfqlBra5xLNKh5h9lK3FbE53EBIJ6zBtxesg8C4
9acR9H6Act7Oqrmq3u3RLi6FCGHXitLRAWfq0qlKY2w3JLSRrUsRzmT4MU4CqjWAYT0rpKkf
9HAr0OFArcn/AIk/T/MXwS1Le7fpy06/oXrzdXUsW6idS6yXXVzytpU4hIzGUgJwldi3gwlb
ccWehxI498H+EV1obJxH1vR6VulypTWUFJVIdJcYCygrBQhQ9YSxMOd2EMJOgRtyloTZi53n
c5WWiM3Fy3LnsyMVS9nTJqK1nLPton1e4/msyLwy5huDnGK7V1i4b61p9T3W20vvtbSMsvtl
FOFBGcl1tIPeUBgYnbv27rey06Fc7Ny3jJUMpal1DYtHafu2qdUXNmy6esVMqru90qTlaZaR
tUradpkAMScBFkpKKq9BHixNf7Fzh8tGpLzarDaOK9sqLre6lqkttMtqoaDjzygltBW40lKc
yjLvERVHOWW6KSJSy1yldlmzymCmYIkRtj0NlKRiRnjlwnd4mq4OJ1eweJSHiwrS3hPB7xA1
45GfJk/R971oq6xDb2K48Berb2dqmHCZI1FebHpSyXLUepLnT2WxWdhVTc7nVLDbTTaBMkk7
+gDE7olcmox2noI7LboYV4bczHBbi9qH4X4caof1VdUU66mrTTUFUlmnZT+e8842lCATgJnE
7IhZvW7ldmSfKE7M44yw4zPZZkdnVFrZBBkIGGERGYN1/wAzHAThheXtO644m2my3+mSFVdn
zLfqGc2IDqGUrKCRjI4xCV63B0lJLxko25y0JvxGN/69vKoDhxWpzjL/ACOr8+LUVdfsV+Ui
byt72WZo4Y8d+DvGJ6po+G+vrZqe4UbPvFVa2VKbqkNTkVll1KF5QdpAwj0W70Libg0yudmc
NKKXbjtwgsnEOm4UXbXFFQcQ6yop6Wl0w6l0PLeqwFMJCsmTvgiWMLpI7WzVV4BK1JqqToZd
LMiZgzGESqQRXw+qGFCzNf8AEHRHC3TjurOIGoqXTGnmX2qZVyqicpeeMkNpSkFSiZHADZjE
Z3FBVk6E4RcnRKpjjQvM9wB4k6moNH6I4m2y/amuocNutLQdQ494SCtaUFxCQSEgmU5xCGZt
SdFJVJTsziqtNGwPhHZIzO6LyqhrTrTm45cNAX+u0xqfipa6S+2tws3O306Xqo07qcFNuKYQ
tIUneJzEUXM1at4SkkTjl7k8YxbRaqee3lQUpKfxbpO8ZZjR1oA7fqYjHO2H89E+p3fZZsjp
LWujdfabp9X6N1JQai0zVJWpu9UjoUwPDE3AsmWQp/OCpSi+M1JVTqimdtxdHpNbrtzucrFr
rHqF/i7bnn2HFNOLpaeqqG8yCQZONMqSRMYEGRil5yysHJFiyt1/NZ57PO/ys1brbLfFuhbU
6oISp6mq20gkyBUpTIAHWYj1+x7SDqd72WbAouNvvFupLraK1i52y5MpqLfcKZYcZeacE0rQ
tJIII2R69tNVRTRp0aMW6sSFIdnsynZFdyXqssjVypU5VcwifE1FmlNHeyGWMsI1Peiablwv
zG3bpttqj4DVu5ZVVhTL1EJBIwJIG2NRzzO69mqdAo8BLpJyE/LGBuHR8k3QuO0zTWMmQVPA
z2bRtimWrjM1lI1uU9pNcp0X0+vLw6p5mazbFK2BQJkdgxjZrFOjbapgaxmP9/TgklyYHQzk
NJVwhqp/rHXfwNNFnZ7/AGz+k/Mcg74VTfa/Ch5ZG/f2PkjOnKiXAAoAAP8AqK7IAMY6m9Rf
YYANReIP23lgA4xc0p/nQZH/AMoYJ6/rHY1Lf32q4j6D7qJfyEl/qPyIwPREZ0iU8RsjXmjs
9jSjPli71gpNqkzcw3YKO2MxBp21xGPzUdnMSqWLfSC8ohMgkyOMYu+1t4GWy/yTI/L4Ffib
aMowyuTPkjZeyspLNRa0LSaF3j0913PEdw2QfAanOeQbezfHXpOp8WUBETJipliNQ+au2Gt/
D93xPDRTu3FKjKZmtLAEvNFU1VohcTwoVZvemqSgtza+WmsuI93bSuraomyl0pbE3QSnMQo4
z2xN7KWCIV2cGqmG9U0dm1LxI0eabRP4QWp9VO28a5BZQ4pD2dTwSEpE5STPplOK3RsJSTWi
iMs82lPnumhMgC0CiqwFb1AuI39Yh3KKlSLwPZTX8oqqGgF5prGzUppmRVNVFPUBfiBsZ88k
yOIOM4f7uuoXRxWNHzmkvF7TXD7WfHnh7aOXa2orWnVUCrg3a23UspqmqkOLdHiYjw2kzURg
I81xRclsaSxNp1pgL9pm3TU3HLgzUVluVfaOlsSV1toSSPfEIr0lbCSJmboBTs3ws0/XjXHA
utTpFovtXFzhIkp8L9mvfAAMiZWRAkkAYGbHVv2wK6k/kPkRFxbWE1ys2m5Y9RaQ1hXarrrB
yy1XACttjFO0uurra1QuXFt4qJQhSG0KUEFIKh2R6bE02/UcXxeg8tyFH8pPiNVP2jvFW46g
uGieVzQ7hevurq2iq9VobXIfXuBFvpF/3yz4qp7AEx5M9ddx9FHFvSe3J26Pbeohc1nJHpHQ
fLBpi/8ADy20NHxA4MsNVmtdQ0pDdXd2XADWOuKSvvLYdIW30JBAgzOWVu1tR0rHRp/TSWWL
0ndo9DN2+TvjW1x64I6c1DV1CXdWaeQiya0anNRrKdICKgjofbkvtnHqy1/pYKWs8N6DjNo5
VcWeJFXwh/aPar17Q6Vq9b1NiuiAjS9DmFTVeNbUNFLWRKzNIVP1TGPne6PMt0bwRkLUdqwl
WmILiPxu1lzwcatGcGL5cU8CuHj9clmoslzcKHBUoQVqcqy4G87y5ZGUKATMjfBevzzD2V6q
1pkNlZeHSYN6uBHavhNwY0FwL0fSaI4f2ZNtomUpN0uTgSa241CRI1FW6ACtStw2J2ARlLVq
NtUR4Lk3J1ZkYImYsKyWw0c6DgZEHzQVJJHB/lL4Y6J4684HGdzirZGdX0FA/f7q3a6xalU7
tQLj4LZdSkgrShJwE5RibVlXLsnPHEyt2ThbTi6U5TfXi9Q8kPBG/WrTGteAFA/W3ShNfQmz
aWVcWfCK/DKVraHdVmGyPXchZhg4/wDjUx8ekninz0MDcu1s5J3OZ+x3/gzfNbab4gXCprha
+HVXQKprSwldMvx2FeKgupQEgqCVLwMo89qNhXax0+Cq5j0Tu3ZW/WWHDgYs41Mhz9qXotht
M1G+6YIlgcwpkmeG+IXEuuR2tGHnLMvNdWbfD5zuE6gZ1/3xjKoxlBiWiSABMndEqjaOLPNV
qK782/M9ofln0RWpTpDSNzUxeq9LgDTlelJVcamYJChTMpLaMJ5s0Y7OSU7sberS6HtyzcLc
pa3oJ3Phy42fl7/Cfj7wGs9PpGj0RV0Vq1A3b1FBFawQqgr3AFTUp7Ipt4z70xPfFeYsdG43
Iqjj5P1aC2xd6VOD1nVTglxQs/Gvhfo3ibZVJZZ1HRJVcKZJzGjuDf1dUwqW9twGXVIx77N3
pI1MfejsSa1HEXhXprWvLZxk4p13FzlJvXGZi7uVbFrqlW1ddTseJVre98pXCy8y6HkYEjvA
dGMYtRnbk6wbq64U8JkblyNyMVGSVOHAznq3mV5cL5p272PXfIpqHTNnraNbNyuVJY6eifpE
73GqkMNFooOIWDHplmIOOw4Sp9EpVmbknGSfjNheWWj4La05ZOLunOVxu+2tN5p7nSVdl1JU
eNW0t4rLeWmDnByhDgAkUmWGMouyMrWzS3yf4leb6T51KmkPLdU3Tl3sGpdMcWeSvUGv71W1
6akX1+ympdpmmUZPAT4zLiS2VDMCgyVPeJR4crB2qKUG3xIvzMoXZVjJLlRefE3jxyna10+L
Jr/lA1Toy3N1DbxvdrtrNnqad4TkgVKUNGSp4pJkeiL712001ODVPAVW7d1STjNVfhOgnAJ/
hxWcF9FHhK5Xr0CxTOsWNi6LK61jI6vxGHycczayR2SlhHsy0oStJw0eQozMJRuNT0kjViPX
2gGYPRs3mJyVViV23RnLDj6mWoUDMMqQoKOIxB249WEaxvjBYLWblulyWNNRqdXqzXB/aoJK
cZSwkI0zO6Tt3ZlfuVWres9GlllGEYO5pOl5OlC4rXI1LJ3g4dpOEUyrzmcyjSmm9R0RsLtE
rhjRIp01Hv6aV1NQ8taSyW5AIShJSCCk5pmeOEo2W0lcsyXgNSuxn7zblTZbTXD4zonyHoyc
IanoVqKuI8jVOP3Iv7PuuW/zPzHIu+CVd9rwWoeWRvz9j5IzhyslwAKAAD/qK7IAMY6m9RfY
YANReIP23lgA4w800xxRp5fnWhgHyOOxqe/ftfEfQXdThkJU1zfkRgeknnTvxEa8ztFjSjP1
gUj4fpEpUSCF5vKTjGZhFdGuIx+ddcxJlh3xGV9ScFZcIw175VDLZd1jUyby+IJ4mWfaCQ4E
gdOU742TsrFvMqVWqeA0XvFjXddzxHcNtP1aP70R2CTPi1ASnGIBQ174+aC1frZrSSdK29Nw
TbXatdeguobyeIGg2ZLIn6p2RXKNRTRDp3eZ2np2WGrbamww0G2FKVTkpShISJnNtMojtz1I
htYUoY91Nw05geJF1sq9aM233e0LIpKht5htDTbiklxRS3NSjJIwgpJvgK2pLQZB478NNZav
+CWtL29FzTZqNymr6jxUM5FHIEqyrIwIB2RK5FyaJbNTI9NwF4TOUFExX6IoaioaYbTUOLU4
pSncgDhJzbzOJuC0UBQS4TVTiVy0assPGrQOsOBWlkWnTlvXRP39bFclhDLrVRlqMja15ylb
BxAwMUStY4YEpUeD/wADyudrgLxs4ncWOGmu+EWm6e9I0hbZLqnqthlLVWzWpqGkrbeUMycA
dkK9blOSaCLilRnsVfEP9pw+c7PCnRDJWZrAfYJPX3qiQhrpoqijHlYl0XC+T9ZlbglqXnJr
rtqVzj1oTTtBZqOzO1GmWbO8yl6quaVgt061IdcypUJgkyAiy27tfXS8TYTVt6G+RGl/D/kJ
4k8XeJuvuJPNFV1ml1Xt9VfaGLDcWHa1dW4uaEh0BwNtU7YCU4TMsJR47eSe3KU3peFGWdPs
pRhWi4Usf00mxVR+zh4PVrLlLX8ReJNbSPDLUUr17Djbid6VJU0QR2xc8nB4VfKyCzElopyI
xzyv8tnHvlg5gNT0totbOpeA2q3F0VXfV1tOio91bCnaKrXTZgoOtKORYAxmZYSiOVy0rUmm
1stVr4eAnfvxnBN6S46Tly4s037Qmp49Gw044Zu1C6hu++9slYSq3Cnl4GbxM3iYbIVuzLpZ
TdKPAir6VnY1maua3k/0XzJ2wXmncZ0pxVtLBTY9ZNIITUZcW6e4BuSnEAgBK/XRumMInmMv
G6vCiNi9K3hq4CxuVtHOJoJNJw847aJRqrSVF/FrNxBp7tSVNbRNN91CHkZ89QzId1RktI2z
h5bpopKaVOGuIX1a0wN8fBkY9W0eYlMySpJImAcR0johVLEceWeW7m15duP2teJ3AfTdl1zY
dU1Vxcp26ioZAVRXJ8vqpqqndW0oLaXIgpMsAZ7RGPnbuwm5wxT1VoetXYTilLSZpY4s/tJ1
LTn5ddKpmQMy32k7DtP8aMhFnS3n8xcpXK3a9p8hb3L7y28w1x5pKvma49UNn0xV5al02ege
becfqHKcUrCG22SpLbbbe1SlEmXXEbdiauOU6eLUTnmYyi44vw6DH/M1y180F85t6jjrwZ0Z
S3GntC7PXabvFRWUiW1VVAwlKs7DziVEZkyIIx6YqzOXuTuqcdVNY7F63G1sSrp1IyE7qz9q
ipxbg4aaNSHDn8P+IEJnuE6qLulvvRFLlIPoK1rLkNk9L3fmyc5fdYV2tNHWk8fH3aqk0jY7
a9TU9Mhl0JbYqXFh1bYLeZS/WmZCPQnPYxS2uYom4bVI1pwmmXAL9nJda213fUnHTUOodF64
euKjamdNXJgP+CsZn33qlKXCVOqURIGPHayj2tqTx8B6HmKfJSoZvvf7NfhdqCgqKG5cWuJt
cl1JUwivuzdYwh4A+G4phxnKrKcZYdoi15OL0uT8ZXHMyhoovEeFyLcHuYzl8v8Arrh3xB0y
2rhVfXX6yz6kYr2HRT3BibSX2qdC1LCKpoAkGUiBOFl7FyEqN+rQnmblu4k1pLZsFs/aScEt
b6sFqYpePmjbo84mzLul1bU02z4qltONoW408wsJOVSTMdokYSWYg3VKSrhV0BrLyS0x4dZc
2peKX7RnUmn77p8ctmm7ei92+pt7tSqvZfShuqaLKz4btSUqOVRlPCG535Kigk+GpX0VhP5b
5D0OUDld4ocGOBPFrS+ortTaR4icSg4bDVW6oFQq0qbpFtUzrjrQKc4dXmkieUDpi7J5aVlO
tKhmr6uPDQWJw+uH7SfhRb7lp65aNoOLXi1QeY1Bdbq1VKQmWUhlxDzSiggZsqkziqyr9lNT
Sm9Tro9I2rU6yTcVwPF+ILxgqueTjXw8vfDm9cEbLZ7PqJTTdwqxVMGpQhpxLiSguPFKTmSJ
qGMolPpbkXHZWK4RxdpSi6vB8Bsfy6cKrvwY4Nac0JqCrp6q+UrtXW3MUhzMNO1bpc8FCyBm
yJkCreZmJ5Oy7VtJ6SGauq5cbWg9jVZBSsGYnPN/YIvvfJK4RVTlhzAJS3qAJCcqk5ytQxTi
qfdHVhONT3pFtY8P6VNv3LGlfSam1qMte7iF5gFZ59WyUajnk9Z3Ps0vUjRaVXi8BKphgOiW
EYS5pOi5VYFyWYpFaxnBKAQVAbcMZRRLUzNZTGezwo3704+RohCAopSlhSZgGRBHXGcjNyy7
aw0owV1bWcXgdOQ6W8iYlwheE9morh/wGYye440sNftM4p3v/wBbX4UPOb6/Y+SMyctJcACg
AA/6iuyADGOpvUX2GADUbiD9tABxi5pwPxOaVvFqp5f4x2NT379suI+g+6r+nSf+o/IjAtEe
8Cd0jGuyOzWcTP1kmmzUq1yQQhQTKWImdsZm06WlxGMu/avjLFvip1C54knvGMNexmZiz8ky
xy7oK+JNlkMJrThiSVJ/sxjaeyz/AJqMOHSaH3jT2d1XOHB+I7dtiTaP70fJHWWj4wjUCdsR
qWIIlUpQqkWGnC2iDRUGJpkaD4AKhUomRYYKiLFUIFyhCZTxsYkV0H5574VSY3P1wMjtCzhI
UpSpJQCpSjsAGJJ7IVSWkiWa+WTUVK3XafvFDfKR2fh1NBUN1CDIyOLalbDD0kGemUnZiOqI
sigZBBgoSqWJxM4maQ4Q6Muuu9cXJNtsdqSAZDM6+8rBthlAxWtZwAHbCnNQjtPQNJvRicgt
YftTuIlVenvgLh7Y7Pp5tw+7C8Kdqqx1vcXC0pCEE7ZCcY9591wWB7I5JUxeJnXl/wD2ktm1
lerdpLjJp+m0jcrq8Ke3astilG3F1xUm0VLThKmgZgZwSJ7ZRbazqlhJUFPKyjoxOqGfAFJz
JImlQxBBxBB649h5dBTMTEqCbHpClGQBJGwCERTIKr5Z2blT2Vy70SLxVoWultBqG/eVpbE1
qSzmzkJG0ywhVRKp6hXBQGDKpxKhEpOEKosx6YABrJiSAFmiQhpXOEKgBwwVGRVuEQNiSIrq
yQemIky26/1VYxOhWzDmsEjw1hSyJ9Bl5hEJuiLbUqM5ZcwAKr82vOklQdwnjInDE49Uanva
OOHCzc9zppVk9S1Gqd1SfflTAnlTIYYiWGEaln1jVHb+zGFtLW8fEOp9gwxMYK5pOkZXQXLZ
MorWlKzZUCfd2mK9FDL5NPpKrTQ3l0u8V6FaHdUA24AZzSoTOOE5GMvHHLtaMWYe5FRzul6e
c6hciY/mfWdua/1+6WxDI/cjLbiVLD+lI4f3vOu/P/ih5zfT7HyRmTlxLgAUAAH/AFFdkAGM
dTeovsMAGo3EH7aADjDzTn+c+n3fySwZ/vjsalv37bxI+hO6r+nP8SXkRgWjV3k7OyNekjst
h4oz1ZCgWKjShaVEpVnTvBJOEvljLWklZSPBmXW/J0oWXeh9coES2TSOnfjvjGTjR0Zlsuls
mXuXIqTxJsm6TiiD15Zbo2jspTrsOI573kr/AKy5xUO2owbSOhIjrckfG6YGWMUMAgAhCeBU
nrhUIuRVMzE0VtkkSlABSRMSqIeEmEIRnARaNV+brjvqHl04YUGvtO2a332sqb7T2pyhuRcS
14b7biyoFpSSFAoEU5i+7UaotsWeklQ5up/at8UMsjwz0qo7J+81n0o8XX5cCPQsl+1zA/8A
/V3iicBwy0on/wCIrPpw1n29SB5D9rmCN/tWeKwWhY4caTKUmeRTtYQeo9+G8+/Z5xLJtfO5
jnZR8QNX2fUVz1JpW/V2jay6Vj9YWbJUvUjTXjuKdLbaULwQkqkAd0eJXJJ1TaPTK3FpVVaG
2mhf2iXMvoosouWpqLXdvaUkOUWoaVLiyhIllTUM+E4mY3zMWrO3IqmDKHlINUWHOb88Hf2k
zPEKoYtV84F6rqLmvuKqdGsOXlkrJ9nlStAAM8THtsZxXGlsvHkPPcyux85GGf2nWtbjf3eC
tgao7jabJU26uv7lquLCqZ81K1oYb8VvMQFNozCW0TiGdnX1SzKx2W3rOUhpyMZeSMfsnviR
H1EBSZkTEjENqhJ4n0TcDeYmqsHKZwl11qzRus9b1otbluqXdO2xy5vLTbnVU7TruQzAUhIG
YjtjM2buzaUpVfiMRcj67jVGpvEH9qrqGmrKq16F4Qs2R5hSmy/qt901CVAyGakZ8LKeorjz
XN4PRFcpdDItqspLxYmmevudnmY4hNv01x4lVdht1QAHLZp9tFtakDOWZkeIfKqKHm7slpPV
byluOOktHgJzD6j4CcRqvibT2el1zfKq1VNrzX6ofWpsVS0LW628FKWFdzL2ExXavO3Jy0he
sqdEsDc1X7V/icokp4XaVSnbI1VYT/whHre8H7POUdST1jP/APV7iiP/ALYaT/7TWfThLeL9
lCeQXtAnP2sPFJCVKTww0nNIJ/ymsP8Ax4OvvgQLd69rmOzvDDVlTrzhroLXFbSNUNZq6w0V
2qqJhRU005VNhakIKsSkE4TjIQlVJngnGjZeyjFiIEcxIBhMAAVmcFBoiLnCYNkRwmRgQVLf
rj3VYxMgYf1aklC9w2iQx2xCboi+1HE5a8wCQNQZ86nB309U8CZYRqe9p1a0G5bmVVwaDVS7
JCa3uk95IzTM5EDpMaln264nb+y8f3aZRjYIwVzSdKyqwLhtBIqkSJHdimWgzW78Lq4jdLR9
SVaNQjIpPhpWgnYFHaT6YymXq7XrPhp4DDZm2uuVrrOrPIrP8H1AgAi/1+A/vWTGX7P16s66
duXlOE97tPfeH3UPOb5fY+SM4cvJcACgAA/6iuyADGOpvUX2GADUbiD9tABxg5p5HieyB66L
TTnyFx2NS379suI+g+6pp7uktauPkojAlGCXE9ojX5aDsmXVZIz9ZCBYqIzkVNrMzt2mMrG4
thU4DwZpN5iXGWTdwQ+sneZz6Yxl35bMvYfqmYuXRIc4kafTtyOrVlOwSSTPzxs3ZaP8zow1
s5/3jYbsu8S8p20SJtIPSkGXkjrsnifGxH2GKmOpWcQoRZWGkUSQ9JxEOgJBxMiAmkGbHTAQ
kGkICAMjGGCZbmrND6M4gWhNh1zpi3assiX0VKbXc2Uvsh5ueRwJOxSZmRiE4Kao1UsjJx0G
PU8tXLskBKeCejZDZO1sn5REehg9SB3JcLK/1ZeXRRmeCOjZ9VrZ/JC6KC1ISk+F8rDo5auX
loZkcEdHLLc1IbNsZkpQGAmQduycDtw4EG0+E5t6Z/ZZ119vl3vfELXdHpK13C4VFVQaT0wy
ak0zDj6lNse81GVICWyAJJMo8qylXVsulm3qRuVoDkG5YtAeA/8AAy9aXJgkm46lqFVgUSZg
+AMjQlu7sXxy8I6iiV6cni/MbcWay2TTtIi3aes9DYaBsAIordTt0zQkJDuNJSIvqQk6mlvP
dy8XTjbw7tmodHUXv+vuHbjtVb7agDxbhQPJHvVMgnasZUuITvIlvijM23OOGknansOp8/ty
oam21dTbbjRvWu4UK1M11vqm1MvtOJOKXG1gKSQekRi6cJkLc09Bd/CbglrrjprG3aQ0JaH6
01LrYu998NRorbTqUA5UVLw7qQlMyEzzK2AQQtOboidy8raq9PAfUXwz0RaeF2gNIcPbBP7r
0jbGbfTukZVOqQJuOqA3uLJUe2Mxah0cVFajETntuoLWPC/hnxBZUzrnQGn9VpXtcuVAy67g
Mok9lDgwMsFQ5QUlRoIycdDNKtffszuXnVQqajST174bXB0KLQt9T75RJUTP/J6rMZDZILii
eVg9GDPVbzko6cTHnBH9nUeFfF5u86ze0xxh4Y1dsraR6iulK4zV0r6kpXTv+6qztLOZOUkL
wBnKFbyyjpx8RG7mnNUpTxm9H9WXlx//AAjo3/8ArGfyRf0MeBFHSS4XyjVcsXLgdvBDRvV/
JjULoIcC5A6WfCwZ5YuXFIIHA/RpntnbGT8oh9BDgQdJLhfKzLlttdusttoLNZ6Fm2Wm1sIp
bbbqZIQywy2JIbbSMAlI2ARZspLAjKW06smZYkiIBYlEhEZU5wADMoYiM5CYEF0wkFTwq31V
dO6BgjD+q1ENuTB6ydgxlEZPAtt6TltzAFtN9QhLoKkFSlBE5DMJgicarvdpvDhNz3NJ08SN
VLyoqrEyThl727ExqOeeOk7h2bwsxa16QdOe7sjBz0nR8o8C47UJ1DcvW3RUzL2I7Ujb7Q7n
+ib4JKglSyZHYcBKMhlpbUMVSnOePOx/mo08B1s5FhLhA4fnaguB6dqWYzXZ5t5Zt4VnLynA
e9z+tL8KHnN8vsfJGcOXkuABQAAf9RXZABjHU3qL7DABqNxB+2gA4w80shxQb2TNpp+0ycej
Ut/fbLiPoPuoaW75/iPyIwHSeunDeI1+R2XLvFGdbOors9KVCWVJSZ7pE7BGQgtq2m3ieS+q
X5cZal1xdUJAT3R4Z6TJWfkmY+XNYb4lWALGZAeUFJ7UyxjZuy6bzSjqZz3vI/pd2nAjtgVz
bAGzKNkdaZ8cEMqM4QDgqcRAemChWwifRDqJkpBwxMJkdqgYHEAbTsEBB4mA7vzVcu9huFxt
V64t2O2XC0VjtvuVK+t1KmaphRS4yr6uWZJEiIrd6C0tEuik9R6GlOZPgHrq80mndJ8WNP3u
+V6y1Q2tqpyuvLlPKhLgTM9A3w1eg9DQO244tE/XfHvg3wuvLenuIXEW06RvT1Misat1wWtC
1MOEpS4JIIkSkjbDlOMdLQ4xb0JlmDnE5Xppnxx0xiQP8oXv/wACIq9b9pco3al7L5GZdvvF
PhzpbRVNxGv2srbQaDrCwKXVfi+JROe9Kys5XGwqYUd/nhynFKraoVtOtKOpjA84XK//APnH
S2G3+NHDr9WIO9bWmS5SStz9l8jMlaa4w8MNXaPunEDTuurTddE2RTqbxqZp8CkpiwApzxHF
SlIEfuRJTi1tJpohstaVQt08yXAQ6Lc4h/ivp86OZrRb13oVPdNSrY0G5eISepPXB0kaVqqU
rpJu1LRRl1cOeLPDXi3RVdx4ba1tmsaW3rDdeu3u5lsKV6ocbUErTOWBIxhRnGWKdSDg4ujL
CvnNfy5aZu1wsV54w2Ciu9peVTXChDrjq2XkGSkKLSFiYO3GDpoLWiWw6Voy3qDV/KBzB6jR
b2qnQfEnVeUlunqqVlyucSnHu+M2la5eWCM7cnhRsrlaeuq5UbHWPT2ntK0AtWmLDb9O2xJn
7hbaZumaJ6SlpKQT2xYkloG0TK6upLZQ1tzuFQikoLdTuVVdVuGSGmWUlbi1HcEpBJhkWqFs
aF4g6K4nWL4n0Bqaj1VYPeF0n3rQqK2vHaAK25kDEBQhJp6Bcaa48AOt+JmguGrNpqNe6toN
KMX2rFBZnK9wtipqSJhpuQJJxgk0tI4quC0kDiDxl4W8Jvur8StdWvRn34lxVn+8nFI94DOX
xCjKlU8uYT7YU5xjpaQlblLQqmNv65PKyf8A766WAlPGpV9CIdZte0uUmrFz2XyGQ7zxu4Ta
f0LZOJt515bLfoDUi22rHqpxSzSVK3c+QIUlBPeyKlMbom7kUqtqglFt0SxMcf1yuVg//fXS
3/aF/utxFZm17S5UPoLvsvkMraA4scM+KdJX13DnW9q1jTWopFyctr3ilgqBKfESQFCYBlhE
ldjLQ0yEoSjpTMUK5yuVptxxpzjfpxpxpSkuocceSUlJkQQWtxiPWLa+cuUkrN16IsuPRvMj
wH4kahpdJ6E4o2TVGo65DjlJZ6Fxa3loZSVuKAKAO6kTOMTjftzdIyTYSs3Iqri0jMriJRci
tEVQMFQALThEWOh57qdsNEGjw60SSrrgChiDVoBCxOU9m8SiubotRZCKOWHMB4nxCnO4VBGd
MyNpOO7dGrb3dWqJG6bjhBp0rq/TwGq14n73M4ySmQGO7DGNNzmk7j2ajSymhtOJpB2RhpvE
6RlF6pcdnIFUk/NTM+eKpPAzmQS6TxG3mhlIGk3SAlKQVlXzp75xkbLUrVU9Bjc1FvNI64ci
0zwfJOJN/uB6NzUZ/cv2L+k/McC73lTff/xQ85vh9j5Iy5y4lwAKAAD/AKiuyADGOpvUX2GA
DUbiD9tABxh5ppfigzsmLQx/COxqe/ftVxH0F3U06hL8R+RGA6Md9MzvGMa9I7Ll/lIz1ZEA
2OjzkTUglOH90cIylmH7tVPHmJfzEuMtC7JIdJ3zM5bMd8Y2fyjKWn6pl7l1SpXE2wBJCfDd
8TModBHTtjZOy+GcXF5zn/eQ6bpuvhVDtjKSB1icdcZ8a1IxlOI1FUcBASQ+UoVSDHpMIrYY
E9kSIUJDMy41j+cPliLGcYuDXEbh9oDjLzPI1nwavHFV24azrVW+qtdjTezRAVjxWlaVpUGg
5NMiMTKPJZonKqbx4z0Tg2lR6j0uKD1s488YeAP4M8t+puHz+ktR09brDUdXp4WVCqTx2lyc
KEpSQ2EKUFKxxlEL0ducdlPB8QKOxCknp/SpcPNfqfT+lOfrhTftScP6jihZaTSDKHNE0dGi
4PVhdXWJTlplhQcKCc0iN0QzU/36jTUOKrZTrRVxrwcB5/HjjrwFuPCPXto/qZX/AEhcbpa3
aS06lrtLMW1qhq3RJp9da2gKayKIIPkhXrsHFrZp4qBajPaVJLlH8XNM/CH7LLRdnXeaO+rX
VWitTW25fi04FbWuP+GF4TLefKrrBguwasJadBK09q85MzhoHRnME1w+0Si38rXAOvpqzTNA
wxX1FU2iqqqRTCVhVSjwV990HMsTOMX202sYrD9OApk7c3WTf6eMydrzhZfdUcqHELh/qyya
E4Eah1Cy4lxqxvpb0+ypt9tynU88UoA8UIyKJBlOY6InOy7lpxXqvm8xGE9iacXy/ozCPCvQ
3NZoLhxpHS1q5bOCXES0WKlS1bdTorWHnrggElL6nClSFLVP14phG5BJNJ08NPMOSt7TeOL4
Fp5dRePKdrCwJ408auG145e7JwI4q2+3N3DV7mnq01NFUsqIIGQHw25eMFjJhjEstKMq4Ulr
LL0KRUq183OY44F8G+P/AAop+IFFwy0pwZ4+aWvOpKq4sakrK9BuCSVLky4vw15SJ4oJOUzx
iqxGdqtKST115iNydq6q1po1cHkPTrdeXbQHMbwVpOPvKhozRmsNY1SqPQ3ELStwQ86wrN4J
UW2kpSoIUsAhYnI4RON/11tRXl8wbCcXsywWnSdQnAUqUneCQfJHuPLUsjiYgK4acRgqRSdL
XjMDOUvcneiBuiE6Ux0HHXkk1bzjWngw9RcDOFmmtX6ETfalX3reKtFM8KxSEF9tIU82VJEh
u2x4Mvdml8hPxtHuzNuEpvak0+Kp5nOTqvmkvzfBqj5gOGGntC2FnV7T2nayy1SapdRWgJS4
24Q86UpDZJAkIV7bm1VUVV4fMFiEIp7Lq6Y6sDPn7SGmuFRxU5QqeyWu3Xy7v3WpRbbTd5Gg
qnlVFGENVWbDwlGQXPdBm204vwkctKinjhReUzvcND8xQW+05yh8uJzrIyNVbSUz6APdNkOE
Z09VV5fQUynbbxb5F6TFn7RmiqrfykcP6O62C2WG5U2qbKm5aasZzW+md8Co8WnpClKJtg4J
7ogzyk7SWvAtyj/eOnAwVn5gOAlFZLKmp5D9VqborbSpefb0PSOoORpsFYdLffCpTCjirbEu
li18l/VIdDNPSq8f6jyP2d9vsd94l8y/FPS7NFpHTGo680Fo4WghNfbGvGU+hb9OAA0gSUgA
b5jCUVZJw27jh8iq48NNV4R5l0hST9ZIw9yN2HjDcNH8WFcPOEPCrX9ja1pUt3C868cyVzb4
QZNMSadPhBMjj+dFeXTlJypWrdOXiZbmHBKCbddlVw/WdGuFOneL1v1Wqq4hcGOEWhrMzQve
5X3RB8S5CpUUhLeLDeVtSZ5iDGSsxxxjT9OJHjns09Vt8f8AibGqMellIAxEER1nbEiR5zsO
gqHhVx7iuuI0B4Iw7qzBLkjImcs22cK5GsSy0zlxzBkHUJAmHJrzBQO8A7d+2NV3s3VG77jW
FeI1PvAAq8NgQJ+WXnjTc9XaO19nZLokKmPdAnPyxhbmk6RlH6pcVpTmqQAQJgT6du6KpYIz
OSxnwYG12hKiWmatBJJzrImcJdPV0RkMq07TotHOebOw/mYtYHX3kW/ofOIP8v3CRBmDINb4
z+42pZeqVKyZ8+97v9bX4UPOb4/Y+SMwcuJcACgAA/6iuyADGOpvUX2GADUbiD9tABxh5pf6
UGzs/kmnn/jHY1Lf32y4j6D7qP6fL8R+RGAqT9ImRkZxr8jsljSjO1idV9z0xMihKVBPbM4Y
xkrMv3VODA8l6NL0uMte7K+uVISBOA8keGdNoyln5Jl3l3AVxKsaSCUlSyZY7MRgeyNm7K/7
1eLyo593jtrdd3xHa0mSAP7kTnHWZaT402cWRQrGKxsOhQgIVCzBgoFSuAgIsqlUMiSELykE
bjPywiNTGPDbg7ojhTetfX/R7NbTXDiVczd9Ue81JebVUlS1fUpIGRM1qMpmIQgo6CUpN08B
l41CyCPEViMcYsRBmIK/gloO7cZNPcd6xqvVxA0vbTarQ+ipKaRNOoODvMZe8qTqsZ74olZT
u9JXVShZG5JR2dTL815pGy8R9G6l0HqhD1Rp7VlA7brs00vI54TokSheOVQ2gy2xZOKmqMSk
4uq0mHK/lf4WXPgZaeXiuRdnuHVndaep0Csy1qlsvKfSVPhPz1nYIqlloOKi9CLI3pKW1rMY
U/IVwOpGWKalvvERhmnSEMtNarrUISkbAlKZBI6hEeqxS0y5WJ35p6uRGX7Py28L7bwt1Nwc
rU3vVGh9WvqqLrT325v11WlZyFPg1KznRkUgKTLYcYl0EdnZeK8JHpXtbSwZiKg5EeHVmpW7
dp3ivxY07aKaYobRQaoeaYYSTMJbSlAAAn0RBZemtk+lri4qvEZY4N8s/DLgjc9Qah00q837
VmrGPdtRas1HXruFdVM5s2RS1AAA4TwmZRZbsxg3JaWVym2Ytd5C+DVLcrtcNIal13w6ZvdQ
qrr7Rpu/v0lIp1c8xDeJlMmQJw2bIhbyyt12W0nqrgSnd2tKT40e5ovkt4SaS1tYeIVyvmse
ImqdLOeLpys1deXbiijcCswU22oAYHEA4Txh9XjtKTbdPCRdxtUSSXgVKm3hM8Tid5i8oPNv
Fso77aLtYrilS7feqJ+gr0NqKFFmpbU04EqGIOVRkYlQCweCnBrRHATRfwFw/RXosHvz1xP3
lU+9Pl9+QWc+VGEkiQlFVu2oKiJSuObq9JE4y8B+HPHim0vScRKWvqmNHXE3WyJoKtVLlqSA
mbmVJzCQ2QrltTVHXxDhccK01nh8cOWrhbzCvaUqeIrd5NRotL6bA7abgqiUj3jIVlRSlRUZ
tiRwlBOypUrXDwsIXJQrTXp0GJv6hXAsKzJvfEYEmc/i2unjt2dcR6BcMuV+kn0reLo/EvQZ
X1Ryy8LNbcKtL8GtTJvlx0ZpCsar7QpdzdNep9guFCn6tQUtz9Kqc+roiVy0pxUXqpzEFNqT
awr5zYVhxdHTUtKw6sM0bLbDCVKJIQ0kITMnbIARNRQnJmHdCcDeHPDnW/ELiFpO31dDqTig
6XtXLXUqXTuLU4XCWWZAN94k4dJiCsxUnJLFkZTlKieo18Y/Z8cu1A7cHLa5re1/edQqqrma
LUtVTNuOqUVFRQ0lIMs0hOILKwWjytecuWZuYY6MNC0GROG/Kfwm4U6sota6VrNXVF7t7TzN
Mi8agq7hS5X0ZFlVO6cqjI4E7InCwouqrysU78pqjpyI2MXKcegqoBJgoRZGXLGJIEQHhBUZ
b9f6qp7MYRGRiDVqZNqJyyJ34nHow6orm20XZeNWctOYNRVqBBXIkeIkJSd2bbKNX3wkpJo3
Pcawbk+A1SvA/jcgZgISAd098adnXVncezaTsqjKMGSRvjCT0nRsqvVRcNpH8YQegTEUz0GY
ykKzRs7oVYFlqz3SoEzntIlsjJZaXqRRLPr9/E7G8iRJ4NpJ2m/3En/1cZzcP+2/zM+ce97+
uP8ADh5Gb5/Y+SM0cvJcACgAA/6iuyADGOpvUX2GADUbiD9tABxh5pifxPax/wC6aeY/fHY1
Lfv2y4j6E7qa+7pfiPyIwDST8RMjKNfkdiy9dpGd7MP5CpBnmkpPd2AGZwnGRsqtuh5sw635
cZaF0VNw4d4Egx4ZxabMpYWBmXl0z/iXYPDBmFkpkN+7tjZ+ydOuLxeVHPu8qnuq9XgO06vV
x2yxjrLPjZoiZpGIMTQZCtkRI0C5oBMcCTtgK2EEOomESqEJIOFdcA6jgqGKgZK4i2IJ4nXA
FBhX1w6jG5+uAB6V9cAUDAk74QDgekwCoOKiRthhQYCZwA0Fn1wEKDk7YZGgTNKEMpMnfBQQ
semGMrOW+AEVC+uAnQSlT3w0RkhoVKBkUUUSYjUKAlLkD3sYmiVCMokzxiRFglGCotkjrO2A
VCC6uAEzwa8zSZQVBmJNWAeC5mxlPHoMKTqi6y9lnLLmDSE39CRggZ8pOM5gE+SY2Rqu9ktp
M3HcuNTVO6zNYpS05VKAkncBLq3xqGeSZ3HsyqWkNpwZRgrmk6NllgXDaQTUgbZpEvPFMtBm
8mvX8RsXoleSkqGiQRlJybDKXm2x68s/UcnoRK/LacZa60OzvIlhwbH/ANeuGHkajYtwuuX/
AMzPm/vdae/Kr7qHnN9PsfJGaOXkuABQAAf9RXZABjHU3qL7DABqNxB+2gA4wc05zcUGBMnL
aGMOgeI7Gpb9+2XEfQfdTju+X4j8iMB0mKgDvjX5HZMvi0jNtmX/ACPTICvWzZgBsxj3223b
R576/fMti6fpVYjHYY8c5YsyFmXqmZeXbucS9PqmRmUuSpyke2Np7JY5zk8pz/vGx3Ve8R2n
XgnyDGOqt1PjZPSQScYiMMkYQiEh84ZBMIFQhMeFGBiCJJgJUCpMBWwmaUFRhUmcJoaQSEDQ
04wCGxIQ8dsIGSkKEhOAB5I3QDG5oZGpTNAKo4KgCo8LgArmnCIBAcIkMpOAQ4nCAY0bYAqO
gAacIdRDCsCFQTAKIO/CGiVBhMoYqAFqEAERatsOomyA8YkiB41We4YTQzEmrVkNOBO0zOOw
bsYrZZbljicteYbuaga7wypBCES3EAqIPbtjU97/AGi0G67lutqi00qapXVJFYsgzBAlj1YY
bo1XOPA7n2bi+hi2Up/VG/DGMDceJ0TLL1S4rST7wJCcwMZ7IqkqmYyj9bRqM+aNUfrdpk0t
RJ3yHRF1l7OBZmYUSR2s5FJ/g2hREs19uB9DQ/cjZtwutiX05Hzd3uqm/Kf6UPOb5fY+SM2c
vJcACgAA/wCorsgAxjqb1F9hgA1F4g/bdpgA4xc0mU8T0fOFoppjqLj0alv77ZcR9Cd06Xu+
fDtvyIwFSyzjdGvSOyWNKMx2ZZNsp0ySlKQqQHROMhalW2uA8l/7Vng3NP1hxmDhHiuNJmTs
fJMwcvI8TiRY2sZrUrdOZIjZ+yFVnK6sPKaH3ivZ3XdZ2pdWAmQ6AI6yfGKR5pcx8sRaHUkt
rmBESLCTEDKx6ZQhpBZiAKD0EfkhVGHmIKkWgZUYCDYRDpEhBUKhc5MoQNhUmGmBWePyRIiK
cIY4KlDGkPC5wDY6c4RCgpxIhQcFdcIaiFTjtgHQdMCAKFCuAVBBfVDCgTNAkAs0AmihXAIa
VYbYQAVGGgBFUt8SJVGKVtgYqgFEmBMTIrkxOJESG4YVRqJ4daZpOMOo2jE+q0zaXhMSOBEg
DuxiEpULbKOW/MGpKb6gd1BIX4qcerEjHGNT3ul0uCobtuV1jV00U8XAan3M5aohJOwYkSnM
bo1LOyxody7PfYxH04wHyRg56ToGWWBcVrwfSQN2MVszGV+UZw0UUqfqCpYy+7rmDjhMbo9O
W9aR6cw/LXkO3HIl/QvT9P35cp/+kiNh7Pr+Xl9OXlPmrvg/rz/Ct+Q3y+x8kZw5cS4AFAAB
/wBRXZABjHU3qL7DABqLxB+27TABxg5pCBxRTsxs9N/CvRqe/vtVxH0H3Tte75/TfkRgOl9Y
H0Rr0jsdjSZjsk12qnJIVLMnMBI4HYY91h1teNnnvpRus8G6LPinEEYx4rrVTJWF6pmDl5cy
8SrCRIqCjkKtxlujaex00s3jowNC7xVXdd07PunDHoEdXTPjKLIBJnAwYZteyKyLD5+uAiES
vDbAMIFTgK22FSYQBc8hCHUU4aI0Ek4wUCgcEQmIMFjpGyBDY4LESZFFCvsiJMoFmJCHZ4BM
JngELOemGIcHOuAaYZLmG2AAwM4VRNjVQxlUkQVIhSQIKkqASqGRZQKhMixpV1wIKAyuHQdA
RVDEDUoS27YAqCKh0wIGRnFTiZEhOHbCSBM8WsOB3yhsksTE2rCfBdO4iU9vVs8sRVNZfBpH
LDmHUE39pJEplxatk5bMB1SjUt7t9JQ2/ccVCGBqxdFhVVMFUyBKZn24zjUs/JylU7n2ef7q
I5g4DDdGDmdEy2guK2GT4ljh8sUy0GYyuEjNuhlpTWPpOKV0ywQd+wy6Y9eTjWR7L8W0qcJ2
+5Exl4LUowwvVw2f3yI2Ds9/tn9OXlPmbveltb9b/wBOHkN8fsfJGdOXkuABQAAf9RXZABjH
U3qL7DABqLxB+27TABxg5pUj8UEKxmLRTCe79I9Gp79f75cR9Bd1Ef8Ar5v9t+RGBKM98TjX
pI7Ll3RozPaVp+62QlROWYII3gx77T/dJaDy3ovpXUtm6KzOlUpTOzrjG3n6xlcuvVMscvrg
HEmxpUTk8YFRBlv3xtHZWezeVNUkzQu8b+l3H4KHaV4y7JCRjr8o7J8WxZDmJ4xAnpCpAO+I
tEG6BPLAIck9e6ESDBQ6YRBsKlY6YKAEBBlDSIsKkThUEmPCYZYisiITRGg4A9IgChUTiSRF
j9u+E0NDssAMqEkSgIphJYbYRJlQIdCDQ7L1wCoOAI3wUHQfmPTBsgyoVPfARqVOEACzE4T7
YdCTYjjDoKhUdsJoBqsd8CQUBSiSQmMM4dCDAKMOgA1QkgaIqseuJUIoiuDoMCGeRVJmk9cS
YjFGqm5Nud6QPrDq6oqm0y1PDA5UcxIU1qILxKcUoURLEYEE/JGq75dZUN03M5bGKNXrktKq
kyPqpGzZs6Y07OPCh3rs+v3MX4BzGIjCTN9yzwPftpPjCR3RTJmZyj9YzLoon3p4SKv4uvGe
A9MejKXNmTfgPZflSnGdyeRMg8FqWRmPvq4Y+VEbJ2eVMr/mkfMne4v+8f4cPOb4/Y+SM4cw
JcACgAA/6iuyADGOpvUX2GADUbiD9tABxf5p8OKDWJ71op8Ox12NT379suI+gu6rDd8vpvyI
wHRibiQdh3Rr0jsmXVWjMtnkbZT71AqzHbPHfOPdZX7tHnzLpdZal3dSl5eXDKo+WPBdS2nQ
yNiVI4npaA1c7o/U1HqBplNQuhOdDJUQFnoJjL7ozXVLnSUqar2oyK3nlpZetFLWtXhN1k88
V5cTJekaAbgS65MgDb0YmNz+M5S+Yuc4nLudtVwvy5EMRzsXVRJVpSgR/cl1weaI/Gcvu0Qn
3PQWi/LkRLHOzdRIJ0rQKTLvK8ZzAgbIXxjP7tcpT/Z+D035ciEOdu6kjNpOhykgGTrgkO2e
2JLtg38xc4/7P2/v5ciJv9derBE9KUxGMx4ypiWzfA+17XzFzlb7oP8AXlyD087NYZS0hSqK
v+WX09sRfbCX3a5SP9n0v475CUrnPr1pd8HStJ3Jd8vLG3ZIE4xOPayT/hrlK/7SJabzx8CB
tc6txTNtzS1G66mQmhxwZjvkCcJRL4rnXC2uUl/aSL/jNcaRKTztVKZg6WpB++rmO3HbAu1r
bo7a5SMu6Cmi8+RBE871SBI6QpnFAkEIfVIgbzPZtiT7WNfMXKQXdI/v3yBlc7zmJTpFiQAw
L6549nRCXa1PTFc5KPdDJ/x3yIavnfeGDekaV0y9ssY+WIPtclognykv7QPXffINPO++kAq0
jSzGC0h9eHX1xbDta38xEX3QtP7d8g9PO5VqGGj6QLGxCqhe3zQT7XKPzOchLuka/jPkQZrn
ee+10nRtJTKc31mc+iUR+Lf2Fyg+6WX3r5ByueJaVy+DqfLtz+8KxT1CF8XfsrlI/wBo398+
QoOeRz1fg1kk7F+8nDpmCMYfxcvYXKSXdBP8x/4hHOeFac2TSVKSE5kgvrM/KIH2uWjo6+Mm
u6Gf3z5BJ54HygEaTpAuU5GoVIno6oj8XY/ZrlI/2ikv4z5An9eUDKDpGmC/z0ioWqePTlEo
b7XP7vnI/wBobuq8+RekS+eB7vFOjqYoDmXxPeVbNxlKcT+LcK7HOJd0ctHTuvEiiOeJ7foy
nUtOK0ipUO7sB2RBdrlrt85U+6Oaf2/MPXzxFSR/oa02opkQagnH0RP4sXsc5L+0U3/H/wDE
ezzxt5Ju6KQFAjMBUnZ0bDE12sVPkc5D+0dyv2/MSW+eSkJSHNFJzEqxFbISGPzDDXauL+aS
/tFe+/8A/H9YmueGmWSTo0KB9RIqpEdG0QviyPsCl3RXvv8A/wASg54qU5QdGBBM8DVbZbvV
wgfaxarfOJd0N9fx19Ur/XdpyO7onMR6xFYCO31Ymu1kX/D5yt90l779fVYM87lLOR0ihBUD
JJqTMKHSZRD4vitNvnBd0V6n23MRXud6kUJM6OAVITJqCoTnIj1RD+MLdPkfpyE13P3td/mD
/wBdOlUolWj5ISAJCpxJ3kd3ZDj2wtv+G+Ui+6K69F//AMf1gXOdajQZDRajJMyPehOXT6sJ
9r4exTjZF90F9fx19X9ZGd52reiWfQ6ySJyFYMOjHJviPxlCLo4cjJw7ncxP/kL6v6zxavnU
Q8EeBowMpKiXAupz90bhIDGE+2Kei2XR7m7q+VmMfoln3rm5pLghaTo1ac08E1QOO4zKRD+M
bT+Y+Ul/ZzMx0XlyGo3EvU7OvqxVeWFWnwyShgydBJGGJkR1xic7v23fxUaegy2T7tszYVOl
T415jX2pbeS7J4d8YBcpBUt4jBX723idC3fkpZaEYS0rWTaYGWMY6ZteWWB79uCfGEzu2RRP
QZnKJbZl/RqlJqXiCAPAVPHp2CLsuq14jIXE3Q7tcjSUDgVp5aUyU7cbqpxW9RTWOIBP+CkC
Nr3H/tVxvyny13rt+/rirohbp9VPys3l+x8kZc5uS4AFAAB/1FdkAGMdTeovsMAGo3EH7aAD
jBzTS/FBrEzFop/4R2NT379suI+g+6n+ny+m/IjANGqTieiUa/JHYsvKjRlu0rCbaykAIICi
ozxOJj22VWCoeHM3P3rLPueZ6oVkJAmRPaTHkksWeyFxuKVSAGlJRlE+yGmyuVqowB1JAxI3
eSEiPQpBe/gD2zMSqHQpj5LlvlDVxidhBUByUiCQDvgU2hdWiVKHD0mWwwdIweXQ9PjNp35T
B0jYdWTKBbu4q6ZznC2nrB5SOtDvrTiZj5qoNprEFlY8AlGoKsxUQtXrf3UTjeknUbykaBWy
+OpZmCob+owKbiVSyUWFU66QRjKIO7UcckkBV4u0Zh1xJXBvLooPFEzMknAw+laF1aL1BJuE
GYkVAicR6Z8JNZOOpCyrygZSqew9MJtrSS6pFDQHhOWZR3dUEZFLyUW9A8B4kAzmZyB/JEnK
hbHJRHpDnRKe/HGErgpZNDFZyZyIntIg2ySyqQgh2RISrGcjFiuNEXlkUAcBmM0xIATgdypB
5VcBUocVPAzOP7sQ22HVEiqQ7j3jgZg7u2E5klk4vUGm6fWnh14xLbb1kHkop4Iqc4EjM+SD
aaDqaQUF2YVOSkmaTKJ9KxPKRGq8VWUGeBMv7N0RVyXCxxyaYZJdQDl34np8hET6Rg8hEEpC
1KxxJhO4NZSK0IcEOAD1gOjdEOkaCWUjwBEhwgJEzLfM4RLpmR6pHgBqQ5ITJw2HH0mKtvHE
n1SL1AVNvqJ2zKgJ7JHYIm7rpSuBK3lYrUVSy6QpM1SUqRA3y3eeGrroXdVhwFVUb6s31ayA
O9vwityH0MWyMaNyZ7u3EyGyIOVNJZHLpcB5dZZW6gTWnMr8zbNM4sjda1lF/I27nylxeAtq
qtr9FIupIbWZIclgZbu2J1qY92nb0sNQA+KNvbFcz35WOJlnSJUahxIlJTKgobJiJWZUqZBx
dUd3+Rl1C+BdhbSoldPcroh4SOClVS3AJnb3VjZG3bjaeVXG/KfLfezFrf8Acepwt0+ql5Ub
z/Y+SMwc1JcACgAA/wCorsgAxjqb1F9hgA1G4g/bQAcYeaUD8TkTH/dNP5vEdjUt/fbLiPoT
uop7un+I/IjX6nJChLExgGdetF80tzCaZDGc9xGXH5OyPbbueqkee9Z9ZsYp9okzUMTOcoh0
ZKNUM8Vkj1sSccIjsl20NBZnMZZT3wtkTkSEqpj6xSqW6XyRLZRXtNBf4tPKDMYFMuiDZRJN
sKh2lACTKRx2Y9WMTjAT2iQhdLLaCQmfqwpRiiG1Ie2uizZSQUDYPyw40HJyaKrRRAlQkJCY
I2Ht7ITtxYlOQ5s0qTJJEhInfsicYpDc2EUaXECUjiSBsgcUiKnISFW9ASpQBliQRhA4UG5z
Y5KreMijInEkgYxW9ke3MS1UajnSCVS9WXyw+jWkKyKzosCs5ZgE4dENpEPWrgFWbb3RIfOH
XPbAoWmSjcnqCoTQFJA9XDNhv3ROltkXcmLJbkesf0Sp7N5/cER2YPBMauSQVTtrUe+qU0mQ
lLb+WJdHBfKIqVxaASl2pRAQQCsiacvR2wpRtPBPmLFcnrB/yYcApSSkmUxIERBwt8JLbmgz
f3YQFHFuRKBvBl/ZKJxhaetkHOYg1anNrhEgcRvnEugg3pB3ZoqEWhtCgp3L0CQ2jZjEnZtp
aSqV643gS2hp8gLeqJqIAAlIeYROMIPF/p4iuV68sIj2vh4qK1vhOUmXcgdi29dA6W8v8QwX
phSgtLuXMJYpnj1gxJxtag279BOJ0wlOf3pYKiQrKmZPThuiuVu0iHS33hgFSdLOBvxKtUwO
8chBVhgDgPlgcLL0NrxE4zvqtKBEo0qM6TUrBSZAkT7oxwltnDVqzTF1JO/f04DHE6ZKsnjL
bQiR8RKc5O+WEGxapQrd6+scCUgaVLhWmsdCVicltzkrb0S2w3ZsA715xS1oqE6cCl5akpA7
0wg4SGEgMCTElby6WIlcvUxoSUUmknF5F160zSFTyKkVSEwTLphxjl9XkfoE8xmFoSHKp9Mp
AKa2YBEx4XeKTtkQCZ9sHR29TXIQV6+3iucK2xpdLoPvZQFIIJDc9vmiUbdlPSOWYv0pQein
04pbiDU/UqIAIGUkdc9uMVq1ZesccxeCO/coUENLbUQACZCR6ZEbYs6OwsA6W49IBFPbE5p5
BNJCQEzl2mI9FbRJ3pkCst9ldaeacabep3B3wUYKlvHQR1QthJU1HnuSnKldRhy62mmtN18G
ldU9TvNBxvMO8maiCknfKUeDMQUHRGT3fcc23JF5aUMqhZlj4KwDKYnuiFrwmWm3Sq0o7wcj
DSUcC7CsJCS/cbmpWJJJTUqbxnv7m6Nv3Gl1VU4X5T5a72mvf9xLQoW+eKfnN6PsfJGYOaEu
ABQAAf8AUV2QAYx1N6i+wwAajcQftoAOMPNMr+c9sY4Wmnl/jHcI1Lfv2y4j6D7qX/10/wAR
+RGv1OZGNfkdhtM9NCynCcsY9Fp4Fd1Yji6oyx3YRJyIxF4qkkHNvh1qDCB9XTOFWgDfFM9p
O2cRAIHlYY/2dUTQVF4yzLvGUOpKoVL5lIqMthnDaI1DJeVuOwSiNaDaC+8qIkFbuiXkialU
jsjFPqJJBxOw7hKIyb1E0iqahRGJ8sCmPAKHF7sOsRJsGkxFaxhOc4hUVByagplMmREsDEkR
2Rin1HCZIwOJiDGkNzq6cNm2cKhMntPGQniBgYuWKKmiUFKl3VSIGAMNEXMiulQmNxxhSVRJ
kfxiDLMDI4JiMYEXOgvEUQAJEbjvnDaJRuCS8obyJjZEdBPaqVDqxsVE0yuTGqWpW0zgIFEm
AAoJgAIN0AgyYACpEAgyYADJgEGTAIMmAAwEAgohgEEAgggArMjEYEbDAlUAyXlkHMcN8XJU
IMC7ULE5K2DCGQloLCvqyu5thSioppxIn++OEeHNqjRkN1pNsuTSczUuyl+gUSdw7RFNubpQ
zFxYYHefkan+A2mJ/wDt11/z56Ny3D/tI8b8rPlfvaVO0F2vsW//ALcTeT7HyRmDmpLgAUAA
H/UV2QAYx1N6i+wwAai8Qftu0wAcX+anDicxhts9Odv/ACrwnKNT34v3y4j6B7q3/wBdP8R+
RGvbB2RgJHXrLPSBxMunCHBk7ukcMN3aYsoQSFm2ekw9A6Fc0hhiYVRPAaDM4zwECGmEJPZ2
xJAVSojqmMYdRNFCTPtEzCqySiSEKMpYnshNkqBM2yU/LCTE0VzTPXFlRUHBWXybRCeBFRDt
rGAlOGmNoLMHdM7iIbIkdScdkp7IjQmsSnaceiBoCmbz9ERqSoHbdl1Ge04xapEJInoeygCc
yZ4bxDqeecQtPTVl2raS02qkVX3O4KyUtG3KainEqUo4JSneTsj05fLXMxNQgqtmE3vvrLbq
sO9mJUiuVvgSL7Z4WPsqLd+1K1QVqgnJR0bSXQkncVOKBVIzxAjP2uz+yn0kqNaKazk2a71r
7k3ZsLZ1bTx5uEHeuFt8t1trr5p+o+LbHaGBU3x5hrwauhaJCS67T5lFbQ2qW3PKMVADGMdm
91TtqsMdZsPZvvHs5+as5lK3ceinyX6DG4MwCCCJTwM9vRGI2TqMZplRsECGysMQ8dkABBAI
KNsABUwAGTAIMkQCDJgAOmAQVMABkiAQUQwCCAQSABqsAYEAm1CWPli6pCUiJULlOQ8kLaIs
si7qncETOKWR8vojx5t1aMhuyiekuvSoAeeURMloiWwHqnFFtUMvcdcDvXyOoKOAmkzhJ2ru
q0yM8Pf3x+5G57iX8pHjflZ8rd7TT7RXktUba/8A24m8H2PkjMHNiXAAoAAP+orsgAxfqb1H
ewwAai8QTg95YAOL/NSk/icwQJA2enJPT9a8P3I1Tfn2y4jv/dYm93T/ABH5Ea9sxgJHXrJ6
CVCeMOJbPEIVCQ2RYmRKBU98AbRQnzCFQixySO3fKBMaDJkcerZDTHQrhPtibQD8s8dvVCJJ
iwA27NkOiG5CB3RFxFUdM/24RJMdMmZiQNFQqW3GERaC5/QMDDREMkzGycujcYmDGYmU5y2m
Iskhpn/aiI6hUDCfXsiSIth5KCSROc/W3eWLFQouSqqGz/LnqbQ+i6imveptK2/WdNqCsq7H
q601IWX27M74aHKhlwSDJaUCtKwd21OBG57ks9HZ200nJ+OnBynzb3obyu5jeHQp+rZpRatp
rGXHwHo8d7bTt8SLxqLg4u5al4Y6OFKix6muNHOn8VKlKephULbSp9ptRCQ6oEqnipRGY5N7
VNRzKFxtaKrw8PpPE0vr66uXe3X63UzNnuNOXQ5Qs5nEqyiS2HAgZS28glMlYFMwY86rRqX6
VPZ0znJSdaxMFX+ioqTU2o6W3UrVDbma91dvoWiShhh0+K2ynMScrYXkEzsEannsv0c2kfTX
Y7eU81uyzOeMlGjet04fEeErAmUY5m5xdUUhEh4gAIIACpgEFTKAA6RAIMmAAyd0AgyYYgyR
AAVMAgoEIAghiHwANV6pgQgSZ49EW0K2iM8JzhbINFkXUj7wACp5WgMO0/ljy5nBnv3e6Muz
TKQXHJnDwzOfX0RRFGXkjvlyQlZ4BaNzEkCougbJ+b94VGzyxum4/wDaR8flZ8p961H2izDW
tQ/9Im7f2PkjLHOiXAAoAAVHqHsgAxdqb9G52GADUTiD9t2mADjFzUf0oMGf/ctMJfvz8apv
37VcR3/uqw3fcf7b8iNfGRsjX5HYLOgkKMjt37IcSc9I8EkfLEyOkIOvzwAUl1wVCg4JO6Fp
ClAiQR27hE1EKj9/yw6kqBM0k7uuBhQZOZmPPCFQeJbN8Oo6FQRPCURqNIJ8sOpJsbL/AHYZ
B4hkCeHmiRFkjDDAT2QDRTrlIHdDBDgjeRs64iok6oKlMj6fJE9BW2SAlJMsSFYkAwPwHlur
AvLh/dK60XWrpqRxtb9YxUt01G+gLadpqtrwqpsz3pnn9O6No3Tmf3ahTQcC7y90TtZxZp/Z
3Ek2vmyXD6TZS5tvVdNU6I4eX65V9yoGqG3tUFuq0VFnuTKkeFWO+E9IocFQ4jw1J7uQKKsY
z/SUiqYnKOiddHOXNarDw+0dpXVF0t+o3NOVOl/dBqjh3ev42TXUifd6uosd1p5oeQ47NSqd
yZTjkWRIROz+6t9JLBIlahcndhahFuUpJJLXXyGlVfWuXW4XO7vNhly61C6nwgJZUr9VJnPY
kCcaPm8w712UtTZ9S9md0vd2QtZeTrKKx43jzHiKEiY8D0m1wVEUEIkEEABEwCCjZAAZMABk
wCDJgEGTAAZMMQYQhBUjZDAKIACCAQ6ABq/VMCEwQOEW1KwaxME7YaG5YFh3TCv2YKQD0bzH
izS9Y9uQlWpd+mhJaiZ4tmf9qK7aqjL6zvjyQgjgFo2aSAqouhTMzBH3jUYjo7I3Lcf+0j4/
Kz5T71afEN/it/8A24m7P2PkjLHOyXAAoAI9R6h7IAMW6oP1a+wwAahcQT+l8sAHGTmon+Jz
Blh9zU0p/wDPPxqm/ftVxHf+6uvu+f4j8iNfWMSIwEjr1lkpaSCZiREJF0yqYsRXWgT5IAbK
7MTgDEtloaY5KsZxHQN4hyoS6DvixMSVAeaI0HUcDOGh1HCUJsEqlDhsmITZKhVO3HZCSGw4
Py4RZShAdKeyGMIlBlPds2wmiLZISBv7cYmtAqjkyB3T2ShEWSMoMzhs374nFENpiSgzw27x
CaqNSDIQQNsgcThshxRCeJIUmYGRa2nEELafaUULSobFJUNhEW27jtusTHZzIW83adq7FSi9
TPSbvt9a8OVVTOraVmS+9T/W9pU2tAJ8kZi1vq5FUcUznWa7r8hck3C5OKerB0AXC7Xi8JYb
utxVV01MrPTUDaAzTNq6Q0jAkdKiY8+a3hdv/KZn9xdi8huqXSQjtT9p6uLwkMqISRGPbNu2
aEFW0xUy5CAgAeNsABR0wCCjdAAUQAHTAIMmAQZMABkwCDCAAogEFEMTHgb4AHQANV6phoTG
JRhjF1ClgnMAZCENtFjXNJNwJUZqDacPKY8d9YnvyGsurTysrqgRtRIno3mIKWyZWldB3w5H
/wCgTSRlLNVXMy7a9+Nu3E65WL8L8rPlfvX/AP8AQ3+KH/pE3b+x8kZg5yS4AFABHqfUPZAB
ivVH6N3sMAGofED7XywAcZuaYhXE1mU5os9OD2+M+Y1Tfv2y4j6B7qv6dP8AEfkRry0oAiMC
zrNtl1u2xqptDN0o3kuOskt3OiE87ePccE9qVDb0GJwVVgSu3Nmai1p0PVxcZ4ciNoiJJFQT
PZDTHQIMfNFlRiy9REQpUdSp7DDBlACTsMJAsQgnslLqgZKg4T6DCJaB2A34b4dCLYpyl5zD
SI7VSoXLZDZNEhChgYExNhfFA7ROYIiW0R2RyHAewDb/AGoKgoh0KExMwCkS86QNpHThOJp0
KqDkuBPaBMRKotmoUrAO0+WI7VCSiVziQxiSxIyiOLqCJTAB37ZCJtqKKHEclSZTJnKUOLqC
jQG4tEsMYJYD2SETMzimpIqO2GAQGAAgPXAJhQR0wAGBT0wCDJI6YBBgR0wAGSpOGIgAMlSe
mGIMkjpgEFBHTAAUEdIgEPBHTAA6cADVHAw1pEwSnJJmI9CKpHn1NU20hS1qCUg7Z4xGVEVU
bdC1CoVDzjxHrmSQo45RsnHgnPaZmMpa2FXXzF2WRADiTKfliKeKMlaWJ3y5JEBHATRwE5+P
ciqfSa984RuG41/KR435WfKnes69osxxQ/8ASJut9j5Iy5zslwAKACPUeoeyADFmqB9W51gw
AahcQPtfLABxj5pj/Oe0P/lFPh++vfljVd+fariO/d1jpu+a/wBR+RGu6cIwLOsQPQpax2lX
nZcU2opKSQdqSJEGEqov2k1RhS8hczllPbKFUlgUzo64KjTQRDiNhJg2ixUCeIzjPPs2iUPa
ZBpVGFTZOGaFtDoiocQMJql2wbRJUK+I3uzT37Ii2NNDvESN57YNok0gfjJO9U4ltMiqCzjr
hOZOiKeIOkwtphgOD8t8G0wwKl4HfBtMfqlfHlD22LAcmqKdipGcLbY6RCCsIG0+QwKciDgh
3vpJnMxPpZBGESvv6pYqOGzZB0rZPZiU9/WcQYfTSRFxTKCsVOeYz3RF3GyKtxCCuWNijskR
uh9NIk7cWV99MpThq8yLsoGaqe89sLpGVqyioqOlSv7mJ9NQfQIcmqIlNR64fTDdhBPekbcy
p9sRd0h1ZFTWJ2BSoOlH0CKGrlsWrZ0w+mJdXiU99UJd5UHTkerJDk3BwCRWTB07JdXQ8XBw
H11GH04llkE+81iffVOB36jeXiOTdlJnNxeO6cCvkerwC/fC9ylbfRCd6ouqod99LIlmIhq9
wh1ZD03oylmXjvO6JdOhdWQQXo7lLB6ZyhdYS1B1RMKL7ICalk4zJl5IfWuBBPJ11jHL+ogh
IyzEpyG3eROE8xJijk1rPFfr1PLKlEmZnifJFcp7RbCzGAeneBIxhJk06F9WFQLg2zAnKGei
DO+nJTjwG0aqcyp24Ey/9+fjctyKmUj4/Kz5T70nXtDmH4If+kTdH7HyRljnpLgAUAAKj1D2
QAYu1MmbbnYYANReIKD9dh0wAcd+a+x1lLrS1ahUgmguFD7mh4JMkOsLUopUdk1JXMdhjWN+
we3GWpo7p3VZy08tcs19eMq/5Wl6DV0ESjXqHYVJUKZhuxgoG0Oz9cKhLbEFwUBTHF2W+ChL
paCDpO8wUErlSviHpgoS6Qb4vXBQj0o4OdcKhJXCpdJ3mDZG7tRviGc5mHQj0g8O9cLZLFdF
4nXBQXSlPE64KB0hXPBQHMQXBQauFc/XCoPbK5z0wUG5lQs9MFBqdBeIOmFQOkQvEHTBQOkQ
vE64KB0g7xJb4KEukoV8QnfCoPpCufrgoNTEF9cFAUxFz+ycCQO4LxOuHQFcFn64KD2xBzrg
oRVwWfrg2R9IODnXC2SSuC8Trh0DpBZ4VB7ZTNDoR2h2fDbBQltiCj0wUFtlS4RhM+eDZBzR
UOHphUJbY7OemCgbYwrOOMTRBzHAzxnCoNSqTKdYSRjKLIxDAv7T1UlTqW21KefqFBpinaQp
bi1qISlCEpBJJJAAG0wSosC1fJclhTGuhLhePAfRLyn6SvuieDOjLBqWiVbr0y3UVFbb1lKl
se9VDryG1lJIzBKxmG44Ruu6bM7OWhG5hLHnbZ8j94O8stvHfd+9lpbVtuKUuHZiotrwVTpw
rE2w+yjJGmEqABQABe9UwAY61CznQ5hugA1d1zblOB2SemADUDXmirdqGjqbZebe3caB9SVO
UzomMzagtJBEiCCN0V3bUbq2ZKqPXks/fyV1XbE3GawqvCYGqOCGhQqSdLUwHRNz6Ueb3dl/
YRnPjPfH5iXN6CP+COhx/qrTedz6UHu7L+wg+M98fmJc3oK/gjocbNLU3nc+lB7uy/sIa7ab
4X/Ilzegr+CWiP1WpvO59KF7ty/sIfxrvn8xLm9BT8EtEfqtTedz6UHu3L+wg+Nd8/mJc3oK
jgnogbNLU3nc+lB7ty/sIF223yv+TLm9BX8FNEzn8L03+/8ApQe7ct7CH8b75/My5vQN/BPR
H6r0w8rn0oPduX9hC+Nt8/mZc3oKjgrokGfwxTeXOflVB7ty3sIfxvvr8zLm9AhwT0R+q1Nj
/f8A0oPduX9hC+Nt8/mZc3oF+CeiZS+F6aXa59KD3blvYQ/jbfP5mXN6Cv4KaJ/Vem87n0oP
duW9hB8b76/My5vQU/BPRP6r03nc+lB7ty3sIPjbfP5mXN6Cv4KaJ/Vem87n0oPdmW9hB8b7
6/My5vQL8FNE/qvTedz6UHu3Lewg+N99fmZc3oF+Cmif1XpvO59KD3ZlvYQfG++vzMub0FRw
W0UDMaXpv9+f+NC92Zb2EP4531+ZlzegX4LaK/Vin87n0oPdmW9hD+Od9/mZc3oF+C2i/wBW
KbzufSg92Zb2EHxzvr8zLm9BT8FNFfqvTedz6UP3blvYRD423z+Zlzegr+Cuiv1YpvO59KD3
ZlvYQ/jffX5mXN6Bfgror9V6bzufSg92Zb2EP4431+ZlzegX4K6K/Vim87n0oPdmW9hB8cb6
/My5vQL8FdFfqvTedz6UL3ZlvYQfHG+vzMub0FRwW0WJ/wCjFNj/AH/0oPdmW9hD+Ot9/mZc
3oKfgtovD/Rimw63PpQe7Mt7CD4533+ZlzegX4K6KP8AqvTedz6UP3ZlvYQn2430/wDky5vQ
IcFtFj/Vin87n0oPdmW9hB8cb6/My5vQV/BfRf6sU/nc+lB7sy3sIPjjfX5mXN6Bfgtov9WK
bzr+lB7sy3sIPjjfX5mXN6Bfgvov9WKfzr+lC92Zb2EP4533+ZlzegX4L6LP+rFP53PpQ/dm
W9hC+Od9/mZc3oF+C+ix/qxT+dz6UL3ZlvYQ12632v8Aky5vQI8F9Fn/AFYp/O59KD3ZlvYQ
Pt1vt/8AJlzegp+C2i/1Yp/O59KH7sy3sIXxzvv8zLm9BX8F9GfqzT+dz6UHuzLewh/HO+/z
Mub0FfwY0Z+rNP51/Sg925b2EL4431+ZlzegX4MaM/Vin86/pQe7cv7CBduN9fmZc3oF+DOj
R/qzTj/0/pQvdmW9hEvjrff5mXN6Bfg3o0/6tU/+/wDpQe7Mt7CF8db7/Mz5vQNPBjRatuma
b/fj/jQ/dmW9hCfbnfT/AOTPm9BOouDGikuoX8MUpI2TCiOjYVSg925f2ERl22309OZnzegy
JYOX/hrVKQKrRtI6N81PD5FiH7uy/sIl8cb6/Mz5vQbX8NeAvC6yXu1altuiLfSXu1BPuFeh
K5tEJKAoJKinNI+sRPfOcTjkbEZKSiqo8+Y7Xb2zFmVi5mJuE/lLDHXwVp4DeqwtZUIwj1Gu
F7/Zy6oADwAKAAbgmmAC1btTeIlWG2ADCuprAXwvuT2wAYMvOi1OqX9V6IALHf0EsqJ8H0QA
B+AV+x9EAFfgBfsfRAAvgBfsfRAAvgBfsfRABT4BX7H0QAL4BX7H0QAUOgV+y9EAFPgFfsj5
oAK/AK/Y+iACvwAv2PogAr8AL9j6IAF8AL9j6IAF8AL9j6IAF8AL9j6IAKfADnsfRAAvgBz2
PogAr8AL9j6IAF8AL9j6IAK/AC/Y+iACnwAv2PogAXwAv2PogAXwAv2PogAp8Ar9j6IAF8Ar
9j6IAF8AOex9EAFfgBfsfRAAvgBfsfRAAvgBfsfRAAvgBfsfRAAvgBfsfRAAvgBfsfRAAvgB
fsfRAAvgBfsfRAAvgBfsfRAAvgBfsfRAAvgBfsfRABT4AX7H0QAU+AV+y9EADDoFfsfRABT4
BX7H0QATabQSwofU+iADIVj0appSfqpS6oAM76asZYSjuSlABmO2U/hpThABcMu5KAAkACgA
orEQAQKhnODABbFdakuz7sAFpVWmULJ+r9EAHkr0k2Ti16IAGfCLXsh5oAF8Itey9EAC+EWv
ZeiABfCLXsvRAAvhFr2XogAXwi37IeaACnwi37IeaABfCLfsh5oAK/CLfsh5oAF8Itey9EAC
+EWvZeiABfCLXsvRAAvhFr2XogAXwi17L0QAL4Ra9l6IAF8Itey9EAC+EWvZeiABfCLXsvRA
AvhFr2XogAXwi17L0QAL4Ra9l6IAF8Itey9EAC+EWvZeiABfCLXsh5oAF8Itey9EAC+EWvZe
iABfCLXsvRAAvhFr2XogAXwi17L0QAL4Ra9l6IAF8Itey9EAC+EWvZeiABfCLXsvRAAvhFr2
XogAXwi17L0QAL4Ra9l6IAF8Itey9EAC+EW/ZDzQAM+EG/Y+iABfCDfsRAAZvSTYP6KXkgA9
yk02hsj6vZ1QAXdQ2xLQHdlABcbLQQAIAJcsIAHQAKABQANKQYABKZCtogAAaRB2pgAYaFs/
m+iABe4NfN9EAC9wa+b6IAF7g380eaABe4NfN9EAC9wa+b6IAF7g1830QAU9wb+aIAF7g380
QAL3Br5sAFfcGvm+iABe4N/NHmgAXuDfzR5oAF7g380eaABe4NfN9EAC9wa+b6IAF7g1830Q
AL3Br5vogAXuDfzR5oAF7g380eaABe4N/NHmgAXuDfzR5oAF7g1830QAL3Br5vogAXuDXzfR
AAvcGvm+iABe4NfN9EAC9wb+aPNAAvcG/mjzQAL3Bv5o80AC9wb+aPNAAvcG/mjzQAL3Bv5o
80AC9wb+aPNAAvcG/mjzQAL3Bv5o80AC9wb+aPNAAvcGvm+iACnuDfzYAF93t9EAC+72+iAC
ooGx+bAAVNIgbEwAGS0BugAIEygAdAAoAFAAoAFAAoAFAAoAFAAoAFAAoAFAAoAFAAoAFAAo
AFAAoAFAAoAFAAoAFAAoAFAAoAFAAoAFAAoAFAAoAFAAoAFAAoAFAAoAFAAoAFAAoAFAAoAF
AAoAFAAoAFAAoAFAB//Z
--------------010405030007020803000904--

--------------ms010604090308000203080609
Content-Type: application/pkcs7-signature; name="smime.p7s"
Content-Transfer-Encoding: base64
Content-Disposition: attachment; filename="smime.p7s"
Content-Description: S/MIME Cryptographic Signature

MIAGCSqGSIb3DQEHAqCAMIACAQExCzAJBgUrDgMCGgUAMIAGCSqGSIb3DQEHAQAAoIIMVDCC
BhgwggUAoAMCAQICAwiRTjANBgkqhkiG9w0BAQsFADCBjDELMAkGA1UEBhMCSUwxFjAUBgNV
BAoTDVN0YXJ0Q29tIEx0ZC4xKzApBgNVBAsTIlNlY3VyZSBEaWdpdGFsIENlcnRpZmljYXRl
IFNpZ25pbmcxODA2BgNVBAMTL1N0YXJ0Q29tIENsYXNzIDEgUHJpbWFyeSBJbnRlcm1lZGlh
dGUgQ2xpZW50IENBMB4XDTE0MDEwNzA3MjgzNVoXDTE1MDEwNzEyNTgyMlowODEXMBUGA1UE
AwwObHVkd2lnQHNpY3Muc2UxHTAbBgkqhkiG9w0BCQEWDmx1ZHdpZ0BzaWNzLnNlMIIBIjAN
BgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAnLm1tc30QxHa9wtdVjC3NgxjLJicnccm0HD+
1X16kPMKGvwps8F1oDhYn7jXIe46p1AuJMzLK0GIioE4JwxCFGdvpz7cg2xyTyrdBVUzSqez
Dfqt4FOJq6hrdrIMS8MHEzl7Jk02gv9cTn/pHQvDpkiThRpbSLU5mlMqtEQ8gDQY5YyBX0Mv
5qculV08I2JU8HEeTt1oeqhvBImgQfOVYMDatHlWHUVVrmYd6iIo+cuiUGd5kiA0XuaLYX0E
oCoao/z5Wg9U0sQlx0hl4r96Q+NdoZZ1prfts3qtyBzJ2hu135aikigzJ6sueWHv/jbISUek
tOMm0xkx1GOqqWtEAwIDAQABo4IC1DCCAtAwCQYDVR0TBAIwADALBgNVHQ8EBAMCBLAwHQYD
VR0lBBYwFAYIKwYBBQUHAwIGCCsGAQUFBwMEMB0GA1UdDgQWBBRZmjjBh8N3klra+mVQgC00
pl68ZTAfBgNVHSMEGDAWgBRTcu2SnODaywFcfH6WNU7y1LhRgjAZBgNVHREEEjAQgQ5sdWR3
aWdAc2ljcy5zZTCCAUwGA1UdIASCAUMwggE/MIIBOwYLKwYBBAGBtTcBAgMwggEqMC4GCCsG
AQUFBwIBFiJodHRwOi8vd3d3LnN0YXJ0c3NsLmNvbS9wb2xpY3kucGRmMIH3BggrBgEFBQcC
AjCB6jAnFiBTdGFydENvbSBDZXJ0aWZpY2F0aW9uIEF1dGhvcml0eTADAgEBGoG+VGhpcyBj
ZXJ0aWZpY2F0ZSB3YXMgaXNzdWVkIGFjY29yZGluZyB0byB0aGUgQ2xhc3MgMSBWYWxpZGF0
aW9uIHJlcXVpcmVtZW50cyBvZiB0aGUgU3RhcnRDb20gQ0EgcG9saWN5LCByZWxpYW5jZSBv
bmx5IGZvciB0aGUgaW50ZW5kZWQgcHVycG9zZSBpbiBjb21wbGlhbmNlIG9mIHRoZSByZWx5
aW5nIHBhcnR5IG9ibGlnYXRpb25zLjA2BgNVHR8ELzAtMCugKaAnhiVodHRwOi8vY3JsLnN0
YXJ0c3NsLmNvbS9jcnR1MS1jcmwuY3JsMIGOBggrBgEFBQcBAQSBgTB/MDkGCCsGAQUFBzAB
hi1odHRwOi8vb2NzcC5zdGFydHNzbC5jb20vc3ViL2NsYXNzMS9jbGllbnQvY2EwQgYIKwYB
BQUHMAKGNmh0dHA6Ly9haWEuc3RhcnRzc2wuY29tL2NlcnRzL3N1Yi5jbGFzczEuY2xpZW50
LmNhLmNydDAjBgNVHRIEHDAahhhodHRwOi8vd3d3LnN0YXJ0c3NsLmNvbS8wDQYJKoZIhvcN
AQELBQADggEBAHqEYmtWr83S+iLXE97KBnHJZiMr6PMuLKxmh0o6UJJwKgf+KTP2czxRnPSI
+whuqfQZdmz6g3A2K8AooMU0RXrzncnX1c4826APdnXkRxnGQxtZXI1wuhPn4z7iDKZ6ij9u
K5Pfn10JL/ERDig2qJQbqvhtIAx0RY7y7r+hLMvgXVq9mf3WRJYmGQeFW+N9t5Z1eEwG4m9R
KAZm0fnfeDn/Ai4kmxTckBH7dZwW2lTtwQqQ4su+PGCJ0e9ndBLpvTqaYGSAl+L7PO7vxPhS
/cS67Xa6BtnYJLTr3MaGXaN+CEUFSfwQHa9DKcAqh3kldErI3kCvnot0CigBl4aILOEwggY0
MIIEHKADAgECAgEeMA0GCSqGSIb3DQEBBQUAMH0xCzAJBgNVBAYTAklMMRYwFAYDVQQKEw1T
dGFydENvbSBMdGQuMSswKQYDVQQLEyJTZWN1cmUgRGlnaXRhbCBDZXJ0aWZpY2F0ZSBTaWdu
aW5nMSkwJwYDVQQDEyBTdGFydENvbSBDZXJ0aWZpY2F0aW9uIEF1dGhvcml0eTAeFw0wNzEw
MjQyMTAxNTVaFw0xNzEwMjQyMTAxNTVaMIGMMQswCQYDVQQGEwJJTDEWMBQGA1UEChMNU3Rh
cnRDb20gTHRkLjErMCkGA1UECxMiU2VjdXJlIERpZ2l0YWwgQ2VydGlmaWNhdGUgU2lnbmlu
ZzE4MDYGA1UEAxMvU3RhcnRDb20gQ2xhc3MgMSBQcmltYXJ5IEludGVybWVkaWF0ZSBDbGll
bnQgQ0EwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDHCYPMzi3YGrEppC4Tq5a+
ijKDjKaIQZZVR63UbxIP6uq/I0fhCu+cQhoUfE6ERKKnu8zPf1Jwuk0tsvVCk6U9b+0UjM0d
Lep3ZdE1gblK/1FwYT5Pipsu2yOMluLqwvsuz9/9f1+1PKHG/FaR/wpbfuIqu54qzHDYeqiU
fsYzoVflR80DAC7hmJ+SmZnNTWyUGHJbBpA8Q89lGxahNvuryGaC/o2/ceD2uYDX9U8Eg5Dp
IpGQdcbQeGarV04WgAUjjXX5r/2dabmtxWMZwhZna//jdiSyrrSMTGKkDiXm6/3/4ebfeZuC
YKzN2P8O2F/Xe2AC/Y7zeEsnR7FOp+uXAgMBAAGjggGtMIIBqTAPBgNVHRMBAf8EBTADAQH/
MA4GA1UdDwEB/wQEAwIBBjAdBgNVHQ4EFgQUU3Ltkpzg2ssBXHx+ljVO8tS4UYIwHwYDVR0j
BBgwFoAUTgvvGqRAW6UXaYcwyjRoQ9BBrvIwZgYIKwYBBQUHAQEEWjBYMCcGCCsGAQUFBzAB
hhtodHRwOi8vb2NzcC5zdGFydHNzbC5jb20vY2EwLQYIKwYBBQUHMAKGIWh0dHA6Ly93d3cu
c3RhcnRzc2wuY29tL3Nmc2NhLmNydDBbBgNVHR8EVDBSMCegJaAjhiFodHRwOi8vd3d3LnN0
YXJ0c3NsLmNvbS9zZnNjYS5jcmwwJ6AloCOGIWh0dHA6Ly9jcmwuc3RhcnRzc2wuY29tL3Nm
c2NhLmNybDCBgAYDVR0gBHkwdzB1BgsrBgEEAYG1NwECATBmMC4GCCsGAQUFBwIBFiJodHRw
Oi8vd3d3LnN0YXJ0c3NsLmNvbS9wb2xpY3kucGRmMDQGCCsGAQUFBwIBFihodHRwOi8vd3d3
LnN0YXJ0c3NsLmNvbS9pbnRlcm1lZGlhdGUucGRmMA0GCSqGSIb3DQEBBQUAA4ICAQAKgwh9
eKssBly4Y4xerhy5I3dNoXHYfYa8PlVLL/qtXnkFgdtY1o95CfegFJTwqBBmf8pyTUnFsukD
FUI22zF5bVHzuJ+GxhnSqN2sD1qetbYwBYK2iyYA5Pg7Er1A+hKMIzEzcduRkIMmCeUTyMyi
kfbUFvIBivtvkR8ZFAk22BZy+pJfAoedO61HTz4qSfQoCRcLN5A0t4DkuVhTMXIzuQ8Cnykh
ExD6x4e6ebIbrjZLb7L+ocR0y4YjCl/Pd4MXU91y0vTipgr/O75CDUHDRHCCKBVmz/Rzkc/b
970MEeHt5LC3NiWTgBSvrLEuVzBKM586YoRD9Dy3OHQgWI270g+5MYA8GfgI/EPT5G7xPbCD
z+zjdH89PeR3U4So4lSXur6H6vp+m9TQXPF3a0LwZrp8MQ+Z77U1uL7TelWO5lApsbAonrqA
SfTpaprFVkL4nyGH+NHST2ZJPWIBk81i6Vw0ny0qZW2Niy/QvVNKbb43A43ny076khXO7cNb
BIRdJ/6qQNq9Bqb5C0Q5nEsFcj75oxQRqlKf6TcvGbjxkJh8BYtv9ePsXklAxtm8J7GCUBth
HSQgepbkOexhJ0wP8imUkyiPHQ0GvEnd83129fZjoEhdGwXV27ioRKbj/cIq7JRXun0NbeY+
UdMYu9jGfIpDLtUUGSgsg2zMGs5R4jGCA90wggPZAgEBMIGUMIGMMQswCQYDVQQGEwJJTDEW
MBQGA1UEChMNU3RhcnRDb20gTHRkLjErMCkGA1UECxMiU2VjdXJlIERpZ2l0YWwgQ2VydGlm
aWNhdGUgU2lnbmluZzE4MDYGA1UEAxMvU3RhcnRDb20gQ2xhc3MgMSBQcmltYXJ5IEludGVy
bWVkaWF0ZSBDbGllbnQgQ0ECAwiRTjAJBgUrDgMCGgUAoIICHTAYBgkqhkiG9w0BCQMxCwYJ
KoZIhvcNAQcBMBwGCSqGSIb3DQEJBTEPFw0xNDA3MTUwNjEwMzBaMCMGCSqGSIb3DQEJBDEW
BBT0FeAC4ZTGwt5/rQ+I6TPAJbyZiDBsBgkqhkiG9w0BCQ8xXzBdMAsGCWCGSAFlAwQBKjAL
BglghkgBZQMEAQIwCgYIKoZIhvcNAwcwDgYIKoZIhvcNAwICAgCAMA0GCCqGSIb3DQMCAgFA
MAcGBSsOAwIHMA0GCCqGSIb3DQMCAgEoMIGlBgkrBgEEAYI3EAQxgZcwgZQwgYwxCzAJBgNV
BAYTAklMMRYwFAYDVQQKEw1TdGFydENvbSBMdGQuMSswKQYDVQQLEyJTZWN1cmUgRGlnaXRh
bCBDZXJ0aWZpY2F0ZSBTaWduaW5nMTgwNgYDVQQDEy9TdGFydENvbSBDbGFzcyAxIFByaW1h
cnkgSW50ZXJtZWRpYXRlIENsaWVudCBDQQIDCJFOMIGnBgsqhkiG9w0BCRACCzGBl6CBlDCB
jDELMAkGA1UEBhMCSUwxFjAUBgNVBAoTDVN0YXJ0Q29tIEx0ZC4xKzApBgNVBAsTIlNlY3Vy
ZSBEaWdpdGFsIENlcnRpZmljYXRlIFNpZ25pbmcxODA2BgNVBAMTL1N0YXJ0Q29tIENsYXNz
IDEgUHJpbWFyeSBJbnRlcm1lZGlhdGUgQ2xpZW50IENBAgMIkU4wDQYJKoZIhvcNAQEBBQAE
ggEAIZ82ePGE6gS4grDthc877cODHdHObC5Cr7HqR9u/L6aeM67fTgrsCUCca2SGpZ2tNxEH
D9W/Yyf/2bog6HwZTtfuGC6TTHlM2/6Fqc3Tea2av6HvHinp/yrM9s7iDSUic9Cc1nrfG7R8
ZcoisyYPkmGPsAjlHrkI6AcqHRHkzS5VBTy9bw0cOrAakGrBdccjph4AcPupc5pdZjtQ4Gvg
uVyDcXCHszjrcykw6HhE2nuo1ubpwcpA4VDBAl6tUwMGRp2L7OXVEvveCpCCe2D18oNwNNG9
ICpwrJGL7bcgF9gvqh8V2OFAtrHOOAz6qbgexTUQZSj5pc405SC0jEUNLgAAAAAAAA==
--------------ms010604090308000203080609--


From nobody Tue Jul 15 00:25:56 2014
Return-Path: <goran.selander@ericsson.com>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id B830C1B2833 for <ace@ietfa.amsl.com>; Tue, 15 Jul 2014 00:25:51 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.901
X-Spam-Level: 
X-Spam-Status: No, score=-2.901 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, GB_AFFORDABLE=1, MIME_8BIT_HEADER=0.3, RCVD_IN_DNSWL_MED=-2.3, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id fPTY2YOpOhWJ for <ace@ietfa.amsl.com>; Tue, 15 Jul 2014 00:25:48 -0700 (PDT)
Received: from sesbmg22.ericsson.net (sesbmg22.ericsson.net [193.180.251.48]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id C66AF1A031C for <ace@ietf.org>; Tue, 15 Jul 2014 00:25:47 -0700 (PDT)
X-AuditID: c1b4fb30-f79da6d000006b80-8c-53c4d779464b
Received: from ESESSHC020.ericsson.se (Unknown_Domain [153.88.253.124]) by sesbmg22.ericsson.net (Symantec Mail Security) with SMTP id 75.52.27520.977D4C35; Tue, 15 Jul 2014 09:25:45 +0200 (CEST)
Received: from ESESSMB303.ericsson.se ([169.254.3.228]) by ESESSHC020.ericsson.se ([153.88.183.78]) with mapi id 14.03.0174.001; Tue, 15 Jul 2014 09:25:45 +0200
From: =?iso-8859-1?Q?G=F6ran_Selander?= <goran.selander@ericsson.com>
To: Hannes Tschofenig <hannes.tschofenig@gmx.net>, "ace@ietf.org" <ace@ietf.org>
Thread-Topic: [Ace] Offline operation of Resource Server
Thread-Index: AQHPn1fLcOspjEhBoEOZJCU6w62WxJugvUmA
Date: Tue, 15 Jul 2014 07:25:44 +0000
Message-ID: <CFEA41D5.15C7A%goran.selander@ericsson.com>
References: <53C3C09A.5090707@gmx.net>
In-Reply-To: <53C3C09A.5090707@gmx.net>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
user-agent: Microsoft-MacOutlook/14.4.2.140509
x-originating-ip: [153.88.183.148]
Content-Type: text/plain; charset="iso-8859-1"
Content-ID: <B04C070AF7107D4486C63CA2DC6247E2@ericsson.com>
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
X-Brightmail-Tracker: H4sIAAAAAAAAA+NgFmpjkeLIzCtJLcpLzFFi42KZGfG3Rrfy+pFgg4lvTC2+f+thtli68x6r A5PH4k372TyWLPnJFMAUxWWTkpqTWZZapG+XwJVxtO0wc8FnoYq3zQdYGxjb+bsYOTkkBEwk 1l08wwRhi0lcuLeerYuRi0NI4CijxLE58xkhnCWMEl8uPgWrYhNwlTjw4B2YLSIQJHG48TUb iC0sYC7xcvV3Foi4hcTCk+eZIWwjicbdy8BsFgFViYlfJzKC2LxANZ0L+thBbCEBNYmldyeA zeQUUJf4dfM/mM0IdNH3U2vAbGYBcYlbT+ZDXSogsWQPxHwJAVGJl4//sYLYogJ6Es1dbxgh 4koSjUuesEL06kncmDqFDcK2lvhzaC8LhK0tsWzha2aIewQlTs58wjKBUXwWknWzkLTPQtI+ C0n7LCTtCxhZVzGKFqcWJ+WmGxnppRZlJhcX5+fp5aWWbGIERtzBLb8NdjC+fO54iFGAg1GJ h3eB1JFgIdbEsuLK3EOM0hwsSuK8C8/NCxYSSE8sSc1OTS1ILYovKs1JLT7EyMTBKdXAGJGm WvU2vfnGzPILJXLt3PfC29s0K99OLvu5ScwpRLvnSPmDvYUvQhi2/bi1Y9KePhZ16dt5P09G ZyjrMj9amBV0ajlL3XlPUx7T6hdOVpaFKfGcETNaVmVodVp5Bt7MXfMky+7V76o468gn1UcD ytXf15hm28b5HHJY2BPubSDZH6aqckWJpTgj0VCLuag4EQD3KcoPmQIAAA==
Archived-At: http://mailarchive.ietf.org/arch/msg/ace/TzC9GvjsK5hX0oU9hkhtlmAbO4Y
Subject: Re: [Ace] Offline operation of Resource Server
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 15 Jul 2014 07:25:51 -0000

Hannes,

I believe it is important that the solution allows an offline mode of
operation. Here are some other supporting use cases:

Although not listed in use case 1, the container monitoring use case, any
access requests to the goods at sea may need to work without connectivity
to an AS in the cloud. Containers may also be kept other areas e.g.
underground where cellular access is not available. One important point is
that even if connectivity to AS is technically possible at all times it
may not affordable for the particular business case.

We discussed previously one company considering designing physical access
control using an online system. There are another companies in the
physical access control business that profile themselves with offering
offline mode, for example Telcred. Their home page provides some more
details.

http://telcred.com/

One example of offline operations is for field technicians to physical
access radio base station sites:
If the base station is malfunctioning, there may be no cellular coverage
at the site, and the field technician need to access the site to repair
the base station (which then may become a catch 22).

There are also use cases where the AS functionality is hosted in a smart
phone or other end-user operated device (and the client is not in the same
device). In these cases we must also expect periods of time when the
device is not available or turned off.


In  draft-seitz-ace-problem-description section 4.5 we formulated the
offline requirement/assumption as:

     o RS may not be able to communicate with AS at the time of the
        request from C.



It would be interesting to know how people think about this (and other
statements in section 4).



G=F6ran



On 14/07/14 13:35, "Hannes Tschofenig" <hannes.tschofenig@gmx.net> wrote:

>Hi all,
>
>in one of my previous mail I said that the requirements rule out an
>EAP/AAA solution and this impression was based on reading the following
>requirement from http://tools.ietf.org/html/draft-seitz-ace-usecases-01
>
>"
>   o  U5.2 The meters must be able to perform fine-grained access
>      control on the metering data and on the configuration while being
>      offline.
>"
>
>I was wondering how strong the requirement for not having a real-time
>interaction between the resource server and the AS is.
>
>Ciao
>Hannes
>


From nobody Tue Jul 15 00:30:58 2014
Return-Path: <sandeep.kumar@philips.com>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 7DE431B2834 for <ace@ietfa.amsl.com>; Tue, 15 Jul 2014 00:30:55 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.601
X-Spam-Level: 
X-Spam-Status: No, score=-2.601 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_LOW=-0.7, SPF_HELO_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id N6ioilS-8SIz for <ace@ietfa.amsl.com>; Tue, 15 Jul 2014 00:30:52 -0700 (PDT)
Received: from emea01-am1-obe.outbound.protection.outlook.com (mail-am1lp0013.outbound.protection.outlook.com [213.199.154.13]) (using TLSv1 with cipher ECDHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 3205A1B2833 for <ace@ietf.org>; Tue, 15 Jul 2014 00:30:52 -0700 (PDT)
Received: from DBXPR04CA006.eurprd04.prod.outlook.com (10.255.191.154) by AM2PR04MB0627.eurprd04.prod.outlook.com (25.160.32.153) with Microsoft SMTP Server (TLS) id 15.0.985.8; Tue, 15 Jul 2014 07:30:49 +0000
Received: from AM1FFO11FD035.protection.gbl (2a01:111:f400:7e00::172) by DBXPR04CA006.outlook.office365.com (2a01:111:e400:9800::26) with Microsoft SMTP Server (TLS) id 15.0.985.8 via Frontend Transport; Tue, 15 Jul 2014 07:30:49 +0000
Received: from mail.philips.com (206.191.240.52) by AM1FFO11FD035.mail.protection.outlook.com (10.174.64.224) with Microsoft SMTP Server (TLS) id 15.0.980.11 via Frontend Transport; Tue, 15 Jul 2014 07:29:45 +0000
Received: from DBXPRD9003MB059.MGDPHG.emi.philips.com ([169.254.7.47]) by DBXPRD9003HT003.MGDPHG.emi.philips.com ([141.251.25.208]) with mapi id 14.16.0459.000; Tue, 15 Jul 2014 07:29:45 +0000
From: "Kumar, Sandeep" <sandeep.kumar@philips.com>
To: Ludwig Seitz <ludwig@sics.se>, "ace@ietf.org" <ace@ietf.org>
Thread-Topic: [Ace] Context-based Authorization
Thread-Index: Ac+f25RPZA4DKMAaSV63emGWMOjF3AAF+ZMAAAKa9oA=
Date: Tue, 15 Jul 2014 07:29:44 +0000
Message-ID: <BE6D13F6A4554947952B39008B0DC0153E7D4731@DBXPRD9003MB059.MGDPHG.emi.philips.com>
References: <34966E97BE8AD64EAE9D3D6E4DEE36F258177EE3@SZXEMA501-MBS.china.huawei.com> <53C4C5D6.30503@sics.se>
In-Reply-To: <53C4C5D6.30503@sics.se>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
x-originating-ip: [130.138.227.40]
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
X-EOPAttributedMessage: 0
X-Forefront-Antispam-Report: CIP:206.191.240.52; CTRY:US; IPV:NLI; EFV:NLI; SFV:NSPM; SFS:(6009001)(428002)(24454002)(13464003)(377454003)(53754006)(51704005)(55904004)(85714005)(189002)(199002)(479174003)(31966008)(95666004)(54356999)(68736004)(76176999)(81156004)(76482001)(44976005)(21056001)(80022001)(106466001)(55846006)(99396002)(69596002)(79102001)(85306003)(101416001)(77982001)(19580395003)(97756001)(77096002)(92726001)(15202345003)(104016003)(97736001)(19580405001)(87936001)(81542001)(81342001)(84676001)(15975445006)(64706001)(92566001)(66066001)(85852003)(47776003)(23726002)(50466002)(46102001)(86362001)(46406003)(105586002)(107046002)(107886001)(2656002)(20776003)(4396001)(83322001)(50986999)(74662001)(33656002)(83072002)(74502001)(6806004)(567094001); DIR:OUT; SFP:; SCL:1; SRVR:AM2PR04MB0627; H:mail.philips.com; FPR:; MLV:sfv; PTR:ErrorRetry; MX:1; A:1; LANG:en; 
X-Microsoft-Antispam: BCL:0;PCL:0;RULEID:
X-Forefront-PRVS: 027367F73D
Received-SPF: None (: philips.com does not designate permitted sender hosts)
Authentication-Results: spf=none (sender IP is 206.191.240.52) smtp.mailfrom=sandeep.kumar@philips.com; 
X-OriginatorOrg: philips.com
Archived-At: http://mailarchive.ietf.org/arch/msg/ace/Lkv6mJePxbZRrMLZpph-5Vi0i4U
Subject: Re: [Ace] Context-based Authorization
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 15 Jul 2014 07:30:55 -0000

> -----Original Message-----
> From: Ace [mailto:ace-bounces@ietf.org] On Behalf Of Ludwig Seitz
>
> On 07/15/2014 05:19 AM, Likepeng wrote:
> > Hi all,
> >
> > Personally I am wondering whether or not we should support
> > context-based authorization indicated in
> > http://tools.ietf.org/html/draft-seitz-ace-usecases-01.
> >
> > For U2.4, do we want to achieve something like this: if time is 9:00 ~
> > 18:00, Client A is allowed to turn on a light, but Client B is not allo=
wed?
>
> Yes that's one example.
>
> >
> > To me, this is purely Resource Server side policy setting and
> > enforcement. Does it require any information exchange with
> > Authorization Server? Is it necessary?
>
> We are moving away from requirements here and getting into solutions, but
> for the sake of clarification: I don't think this kind of policy should b=
e on the
> RS, it should be maintained and managed by the AS, for the same reasons w=
e
> want all the other authorization policies to be on the AS. The solution I=
 have
> in mind are conditional authorization decisions in the style: "You are
> permitted to turn on the light, provided it is between 9:00 and 18:00".
>

[SK] Completely agree with Ludwig. Context-based policies are very relevant=
 in IoT if they need invisibly mesh with our daily lives.
How to implement it is something we need to discuss during the solution pha=
se. However to me this does not sound like only a
RS side policy setting, since RS still needs to figure out if it was A or B=
 who is allowed within that context. Enforcement could be RS side depending=
 on the ability of RS to verify context.

regards
Sandeep

________________________________
The information contained in this message may be confidential and legally p=
rotected under applicable law. The message is intended solely for the addre=
ssee(s). If you are not the intended recipient, you are hereby notified tha=
t any use, forwarding, dissemination, or reproduction of this message is st=
rictly prohibited and may be unlawful. If you are not the intended recipien=
t, please contact the sender by return e-mail and destroy all copies of the=
 original message.


From nobody Tue Jul 15 00:31:49 2014
Return-Path: <sandeep.kumar@philips.com>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 0687C1B2836 for <ace@ietfa.amsl.com>; Tue, 15 Jul 2014 00:31:46 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.601
X-Spam-Level: 
X-Spam-Status: No, score=-2.601 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_LOW=-0.7, SPF_HELO_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id J5s308mg6HEy for <ace@ietfa.amsl.com>; Tue, 15 Jul 2014 00:31:44 -0700 (PDT)
Received: from emea01-am1-obe.outbound.protection.outlook.com (mail-am1lp0014.outbound.protection.outlook.com [213.199.154.14]) (using TLSv1 with cipher ECDHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id ECDBB1B2834 for <ace@ietf.org>; Tue, 15 Jul 2014 00:31:42 -0700 (PDT)
Received: from DB3PR04CA002.eurprd04.prod.outlook.com (10.242.134.22) by DB4PR04MB0640.eurprd04.prod.outlook.com (10.242.221.152) with Microsoft SMTP Server (TLS) id 15.0.985.8; Tue, 15 Jul 2014 07:31:40 +0000
Received: from AM1FFO11FD020.protection.gbl (2a01:111:f400:7e00::105) by DB3PR04CA002.outlook.office365.com (2a01:111:e400:9814::22) with Microsoft SMTP Server (TLS) id 15.0.990.7 via Frontend Transport; Tue, 15 Jul 2014 07:31:39 +0000
Received: from mail.philips.com (206.191.240.52) by AM1FFO11FD020.mail.protection.outlook.com (10.174.64.209) with Microsoft SMTP Server (TLS) id 15.0.980.11 via Frontend Transport; Tue, 15 Jul 2014 07:31:39 +0000
Received: from DBXPRD9003MB059.MGDPHG.emi.philips.com ([169.254.7.47]) by DBXPRD9003HT001.MGDPHG.emi.philips.com ([141.251.25.206]) with mapi id 14.16.0459.000; Tue, 15 Jul 2014 07:31:38 +0000
From: "Kumar, Sandeep" <sandeep.kumar@philips.com>
To: Michael Richardson <mcr+ietf@sandelman.ca>, Hannes Tschofenig <hannes.tschofenig@gmx.net>
Thread-Topic: [Ace] Offline operation of Resource Server
Thread-Index: AQHPn1fMzpjOsxbdr0GgVTQturd/Npuf3KKAgAAOToCAABYwAIAAvVbQ
Date: Tue, 15 Jul 2014 07:31:38 +0000
Message-ID: <BE6D13F6A4554947952B39008B0DC0153E7D4743@DBXPRD9003MB059.MGDPHG.emi.philips.com>
References: <53C3C09A.5090707@gmx.net> <14018.1405360899@sandelman.ca> <53C42703.4060806@gmx.net> <8236.1405368736@sandelman.ca>
In-Reply-To: <8236.1405368736@sandelman.ca>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
x-originating-ip: [130.138.227.40]
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
X-EOPAttributedMessage: 0
X-Forefront-Antispam-Report: CIP:206.191.240.52; CTRY:US; IPV:NLI; EFV:NLI; SFV:NSPM; SFS:(6009001)(428002)(51704005)(377454003)(189002)(13464003)(85714005)(55904004)(24454002)(199002)(106116001)(81342001)(80022001)(54356999)(95666004)(20776003)(21056001)(47776003)(97736001)(105586002)(85306003)(83322001)(2656002)(107046002)(44976005)(86362001)(66066001)(50986999)(83072002)(69596002)(64706001)(19580405001)(84676001)(79102001)(97756001)(68736004)(81156004)(92566001)(19580395003)(4396001)(93886003)(77982001)(46406003)(77096002)(74502001)(92726001)(46102001)(74662001)(101416001)(87936001)(50466002)(33656002)(81542001)(76176999)(6806004)(85852003)(104016003)(76482001)(23726002)(31966008)(99396002)(106466001)(55846006)(567094001); DIR:OUT; SFP:; SCL:1; SRVR:DB4PR04MB0640; H:mail.philips.com; FPR:; MLV:sfv; PTR:ErrorRetry; MX:1; A:1; LANG:en; 
X-Microsoft-Antispam: BCL:0;PCL:0;RULEID:
X-Forefront-PRVS: 027367F73D
Received-SPF: None (: philips.com does not designate permitted sender hosts)
Authentication-Results: spf=none (sender IP is 206.191.240.52) smtp.mailfrom=sandeep.kumar@philips.com; 
X-OriginatorOrg: philips.com
Archived-At: http://mailarchive.ietf.org/arch/msg/ace/iyeJP5JW4zXbSPhbCK6az6lmUbM
Cc: "ace@ietf.org" <ace@ietf.org>
Subject: Re: [Ace] Offline operation of Resource Server
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 15 Jul 2014 07:31:46 -0000

Snip
> (This is why part of network join needs to be in scope for ACE)

+1
This certainly has to considered to create a complete solution taking the w=
hole lifecycle of the IoT device

regards
Sandeep


> -----Original Message-----
> From: Ace [mailto:ace-bounces@ietf.org] On Behalf Of Michael Richardson
> Sent: Monday, July 14, 2014 10:12 PM
> To: Hannes Tschofenig
> Cc: ace@ietf.org
> Subject: Re: [Ace] Offline operation of Resource Server
>
>
> Hannes Tschofenig <hannes.tschofenig@gmx.net> wrote:
>     > To re-use the Kerberos language, the client gets the TGT. The real-=
time
>     > interaction I was talking about relates to the interaction between =
the
>     > resource server and the authorization server.
>
> During enrollment, the Authorization Server gets a TGT on the *resource*
> server.
> Given that, it can now issue new tickets to clients that come along that =
wish
> to access the resource.  The client, during enrollment, asks the (possibl=
y
> federated list of) authorization servers for a resource ticket.
> (This is why part of network join needs to be in scope for ACE)
>
> All of the above has to occur online.
>
> Once the client has the resource ticket, the resource server can validate=
 it
> offline.
>
> --
> Michael Richardson <mcr+IETF@sandelman.ca>, Sandelman Software Works
> -=3D IPv6 IoT consulting =3D-
>
>


________________________________
The information contained in this message may be confidential and legally p=
rotected under applicable law. The message is intended solely for the addre=
ssee(s). If you are not the intended recipient, you are hereby notified tha=
t any use, forwarding, dissemination, or reproduction of this message is st=
rictly prohibited and may be unlawful. If you are not the intended recipien=
t, please contact the sender by return e-mail and destroy all copies of the=
 original message.


From nobody Tue Jul 15 01:18:40 2014
Return-Path: <hannes.tschofenig@gmx.net>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 7219C1B2838 for <ace@ietfa.amsl.com>; Tue, 15 Jul 2014 01:18:37 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.551
X-Spam-Level: 
X-Spam-Status: No, score=-2.551 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, FREEMAIL_FROM=0.001, RCVD_IN_DNSWL_NONE=-0.0001, RP_MATCHES_RCVD=-0.651, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id mY2hkk38diC5 for <ace@ietfa.amsl.com>; Tue, 15 Jul 2014 01:18:35 -0700 (PDT)
Received: from mout.gmx.net (mout.gmx.net [212.227.15.18]) (using TLSv1.2 with cipher DHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 7F7811B2836 for <ace@ietf.org>; Tue, 15 Jul 2014 01:18:35 -0700 (PDT)
Received: from [172.16.254.119] ([80.92.116.212]) by mail.gmx.com (mrgmx003) with ESMTPSA (Nemesis) id 0MgL1q-1WtAPc0OCE-00Nesd; Tue, 15 Jul 2014 10:18:26 +0200
Message-ID: <53C4E3D1.7020804@gmx.net>
Date: Tue, 15 Jul 2014 10:18:25 +0200
From: Hannes Tschofenig <hannes.tschofenig@gmx.net>
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:24.0) Gecko/20100101 Thunderbird/24.6.0
MIME-Version: 1.0
To: Likepeng <likepeng@huawei.com>, Ludwig Seitz <ludwig@sics.se>,  "ace@ietf.org" <ace@ietf.org>
References: <53C398ED.3030302@gmx.net> <53C3D013.6030006@sics.se> <34966E97BE8AD64EAE9D3D6E4DEE36F258177D9A@SZXEMA501-MBS.china.huawei.com>
In-Reply-To: <34966E97BE8AD64EAE9D3D6E4DEE36F258177D9A@SZXEMA501-MBS.china.huawei.com>
X-Enigmail-Version: 1.5.2
OpenPGP: id=4D776BC9
Content-Type: multipart/signed; micalg=pgp-sha512; protocol="application/pgp-signature"; boundary="7SFgDeHjEplPG37VVkd1xKxGLBbaWhiuP"
X-Provags-ID: V03:K0:gdoJ5/OTjc65mcENbax149JpUPRVTd1dPOkdDpd7O6vn1oM/Ke6 mCbjPWKOVlkNQXSxzE8DxS6RUTPKYcRmDLS+yuDGgMuKaFWAN/XlccgpqUnFQyeSP9q8axx GsFICXlFUia7vaY/05OGxBwYtC5EppaZ44/0Tg+JJ2w6tX6DokUJ0Dppnx/UYXFViWLKP5U DNASOySNXarB6uWc+JNWw==
Archived-At: http://mailarchive.ietf.org/arch/msg/ace/eIv0OTnyNnWWbDr-Qx_QRCouLLA
Subject: Re: [Ace] Agenda
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 15 Jul 2014 08:18:37 -0000

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--7SFgDeHjEplPG37VVkd1xKxGLBbaWhiuP
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: quoted-printable



On 07/15/2014 02:39 AM, Likepeng wrote:
>> I think this question (3c) is too generic. If we ask like that, we wil=
l just reiterate
>> > the discussions currently ongoing on the DICE list (see the "Tyranny=
 of the
>> > Lightswitch" thread).
> We can go a little bit further:
> - long-term key established between the client and the authorization se=
rver
> - long-term key established between the authorization server and the re=
source server
> - short term key established between the client and the resource server=


The discussion on the DICE list was useful and of course the issues
surface also in this group.

If we could only figure out how to make any progress on that topic this
would be useful. Any ideas?

Ciao
Hannes


--7SFgDeHjEplPG37VVkd1xKxGLBbaWhiuP
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
Content-Disposition: attachment; filename="signature.asc"

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1
Comment: GPGTools - http://gpgtools.org
Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/

iQEcBAEBCgAGBQJTxOPRAAoJEGhJURNOOiAtR8MH/i2a3nL8j01rjWAAi0SYmOEs
xmpJyek0l0q3PlIQJPCI+feTtl3cooWnN/bTnwbVfBn49QQ8nIt8NXsxuy7qXCG8
x3p7W+tHvXfm/1fU+CUKxfz3aqueDRcTppH8A9ukXjDF0osS5s/BmAHbmoq8LkZF
8aj/pMWrYup/dpamVL9RaaaxBw3kXP6Pw8Yy4q0ljEBimvyy7TMwL4x8maBrv3j6
jY1s38cnBChiNv63rWmRNci99HgqUuXcUn/NE/YnIDF//sb8XRDPqh/zES79lzrV
0IzPz1lENQdnFjADk41B+SQptvBFsET31SgVUDgZNf0dSTh2vuyr2lRd0OtkX8I=
=S1Ov
-----END PGP SIGNATURE-----

--7SFgDeHjEplPG37VVkd1xKxGLBbaWhiuP--


From nobody Tue Jul 15 01:25:13 2014
Return-Path: <ludwig@sics.se>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 53FCC1A0ACC for <ace@ietfa.amsl.com>; Tue, 15 Jul 2014 01:25:11 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.901
X-Spam-Level: 
X-Spam-Status: No, score=-2.901 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HELO_EQ_SE=0.35, RCVD_IN_DNSWL_LOW=-0.7, RP_MATCHES_RCVD=-0.651] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id HKO007qBp2JX for <ace@ietfa.amsl.com>; Tue, 15 Jul 2014 01:25:08 -0700 (PDT)
Received: from outbox.sics.se (outbox.sics.se [193.10.64.137]) by ietfa.amsl.com (Postfix) with ESMTP id F12A31A033D for <ace@ietf.org>; Tue, 15 Jul 2014 01:25:07 -0700 (PDT)
Received: from e-mailfilter01.sunet.se (e-mailfilter01.sunet.se [192.36.171.201]) by outbox.sics.se (Postfix) with ESMTPS id B55296EA; Tue, 15 Jul 2014 10:25:06 +0200 (CEST)
Received: from letter.sics.se (letter.sics.se [193.10.64.6]) by e-mailfilter01.sunet.se (8.14.4/8.14.4/Debian-4) with ESMTP id s6F8P6W0018481; Tue, 15 Jul 2014 10:25:06 +0200
Received: from [192.168.0.108] (unknown [85.235.11.178]) (Authenticated sender: ludwig@sics.se) by letter.sics.se (Postfix) with ESMTPSA id 58EF940116; Tue, 15 Jul 2014 10:25:06 +0200 (CEST)
Message-ID: <53C4E562.4040202@sics.se>
Date: Tue, 15 Jul 2014 10:25:06 +0200
From: Ludwig Seitz <ludwig@sics.se>
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:24.0) Gecko/20100101 Thunderbird/24.6.0
MIME-Version: 1.0
To: Hannes Tschofenig <hannes.tschofenig@gmx.net>, Likepeng <likepeng@huawei.com>, "ace@ietf.org" <ace@ietf.org>
References: <53C398ED.3030302@gmx.net> <53C3D013.6030006@sics.se> <34966E97BE8AD64EAE9D3D6E4DEE36F258177D9A@SZXEMA501-MBS.china.huawei.com> <53C4E3D1.7020804@gmx.net>
In-Reply-To: <53C4E3D1.7020804@gmx.net>
Content-Type: multipart/signed; protocol="application/pkcs7-signature"; micalg=sha1; boundary="------------ms060009060703010101050101"
X-Bayes-Prob: 0.0001 (Score 0, tokens from: outbound, outbound-sics-se:default, sics-se:default, base:default, @@RPTN)
X-p0f-Info: os=Solaris 10, link=Ethernet or modem
X-CanIt-Geo: =?UTF-8?Q?ip=3D85.235.11.178; _country=3DSE; _region=3DSk=C3=A5ne; _city=3DLund; _latitude=3D55.7000; _longitude=3D13.1833; _http://maps.google.com/maps=3Fq=3D55.7000,13.1833&z=3D6?=
X-CanItPRO-Stream: outbound-sics-se:outbound (inherits from outbound-sics-se:default, sics-se:default, base:default)
X-Canit-Stats-ID: 09Mqwp6g4 - 986d6450328a - 20140715
X-Antispam-Training-Forget: https://canit.sunet.se/canit/b.php?i=09Mqwp6g4&m=986d6450328a&t=20140715&c=f
X-Antispam-Training-Nonspam: https://canit.sunet.se/canit/b.php?i=09Mqwp6g4&m=986d6450328a&t=20140715&c=n
X-Antispam-Training-Spam: https://canit.sunet.se/canit/b.php?i=09Mqwp6g4&m=986d6450328a&t=20140715&c=s
X-CanIt-Archive-Cluster: PfMRe/vJWMiXwM2YIH5BVExnUnw
X-Scanned-By: CanIt (www . roaringpenguin . com) on 192.36.171.201
Archived-At: http://mailarchive.ietf.org/arch/msg/ace/ixuDO-jY8pnnudByFJtoj6rWqsk
Subject: Re: [Ace] Agenda
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 15 Jul 2014 08:25:11 -0000

This is a cryptographically signed message in MIME format.

--------------ms060009060703010101050101
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: quoted-printable

On 07/15/2014 10:18 AM, Hannes Tschofenig wrote:
>
>
> On 07/15/2014 02:39 AM, Likepeng wrote:
>>> I think this question (3c) is too generic. If we ask like that, we wi=
ll just reiterate
>>>> the discussions currently ongoing on the DICE list (see the "Tyranny=
 of the
>>>> Lightswitch" thread).
>> We can go a little bit further:
>> - long-term key established between the client and the authorization s=
erver
>> - long-term key established between the authorization server and the r=
esource server
>> - short term key established between the client and the resource serve=
r
>
> The discussion on the DICE list was useful and of course the issues
> surface also in this group.
>
> If we could only figure out how to make any progress on that topic this=

> would be useful. Any ideas?
>
> Ciao
> Hannes
>

Well in the DICE thread you said that you could ask a colleague about=20
the price of adding asymmetric crypto hardware:

> I could ask one of
> my co-workers to share his insight on cost of hardware and embedded
> industry with the rest of the group. This would be one data point. Mayb=
e
> there are other companies willing to share their experience.

I think that would be progress.


/Ludwig

--=20
Ludwig Seitz, PhD
SICS Swedish ICT AB
Ideon Science Park
Building Beta 2
Scheelev=C3=A4gen 17
SE-223 70 Lund

Phone +46(0)70-349 92 51
http://www.sics.se


--------------ms060009060703010101050101
Content-Type: application/pkcs7-signature; name="smime.p7s"
Content-Transfer-Encoding: base64
Content-Disposition: attachment; filename="smime.p7s"
Content-Description: S/MIME Cryptographic Signature

MIAGCSqGSIb3DQEHAqCAMIACAQExCzAJBgUrDgMCGgUAMIAGCSqGSIb3DQEHAQAAoIIMVDCC
BhgwggUAoAMCAQICAwiRTjANBgkqhkiG9w0BAQsFADCBjDELMAkGA1UEBhMCSUwxFjAUBgNV
BAoTDVN0YXJ0Q29tIEx0ZC4xKzApBgNVBAsTIlNlY3VyZSBEaWdpdGFsIENlcnRpZmljYXRl
IFNpZ25pbmcxODA2BgNVBAMTL1N0YXJ0Q29tIENsYXNzIDEgUHJpbWFyeSBJbnRlcm1lZGlh
dGUgQ2xpZW50IENBMB4XDTE0MDEwNzA3MjgzNVoXDTE1MDEwNzEyNTgyMlowODEXMBUGA1UE
AwwObHVkd2lnQHNpY3Muc2UxHTAbBgkqhkiG9w0BCQEWDmx1ZHdpZ0BzaWNzLnNlMIIBIjAN
BgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAnLm1tc30QxHa9wtdVjC3NgxjLJicnccm0HD+
1X16kPMKGvwps8F1oDhYn7jXIe46p1AuJMzLK0GIioE4JwxCFGdvpz7cg2xyTyrdBVUzSqez
Dfqt4FOJq6hrdrIMS8MHEzl7Jk02gv9cTn/pHQvDpkiThRpbSLU5mlMqtEQ8gDQY5YyBX0Mv
5qculV08I2JU8HEeTt1oeqhvBImgQfOVYMDatHlWHUVVrmYd6iIo+cuiUGd5kiA0XuaLYX0E
oCoao/z5Wg9U0sQlx0hl4r96Q+NdoZZ1prfts3qtyBzJ2hu135aikigzJ6sueWHv/jbISUek
tOMm0xkx1GOqqWtEAwIDAQABo4IC1DCCAtAwCQYDVR0TBAIwADALBgNVHQ8EBAMCBLAwHQYD
VR0lBBYwFAYIKwYBBQUHAwIGCCsGAQUFBwMEMB0GA1UdDgQWBBRZmjjBh8N3klra+mVQgC00
pl68ZTAfBgNVHSMEGDAWgBRTcu2SnODaywFcfH6WNU7y1LhRgjAZBgNVHREEEjAQgQ5sdWR3
aWdAc2ljcy5zZTCCAUwGA1UdIASCAUMwggE/MIIBOwYLKwYBBAGBtTcBAgMwggEqMC4GCCsG
AQUFBwIBFiJodHRwOi8vd3d3LnN0YXJ0c3NsLmNvbS9wb2xpY3kucGRmMIH3BggrBgEFBQcC
AjCB6jAnFiBTdGFydENvbSBDZXJ0aWZpY2F0aW9uIEF1dGhvcml0eTADAgEBGoG+VGhpcyBj
ZXJ0aWZpY2F0ZSB3YXMgaXNzdWVkIGFjY29yZGluZyB0byB0aGUgQ2xhc3MgMSBWYWxpZGF0
aW9uIHJlcXVpcmVtZW50cyBvZiB0aGUgU3RhcnRDb20gQ0EgcG9saWN5LCByZWxpYW5jZSBv
bmx5IGZvciB0aGUgaW50ZW5kZWQgcHVycG9zZSBpbiBjb21wbGlhbmNlIG9mIHRoZSByZWx5
aW5nIHBhcnR5IG9ibGlnYXRpb25zLjA2BgNVHR8ELzAtMCugKaAnhiVodHRwOi8vY3JsLnN0
YXJ0c3NsLmNvbS9jcnR1MS1jcmwuY3JsMIGOBggrBgEFBQcBAQSBgTB/MDkGCCsGAQUFBzAB
hi1odHRwOi8vb2NzcC5zdGFydHNzbC5jb20vc3ViL2NsYXNzMS9jbGllbnQvY2EwQgYIKwYB
BQUHMAKGNmh0dHA6Ly9haWEuc3RhcnRzc2wuY29tL2NlcnRzL3N1Yi5jbGFzczEuY2xpZW50
LmNhLmNydDAjBgNVHRIEHDAahhhodHRwOi8vd3d3LnN0YXJ0c3NsLmNvbS8wDQYJKoZIhvcN
AQELBQADggEBAHqEYmtWr83S+iLXE97KBnHJZiMr6PMuLKxmh0o6UJJwKgf+KTP2czxRnPSI
+whuqfQZdmz6g3A2K8AooMU0RXrzncnX1c4826APdnXkRxnGQxtZXI1wuhPn4z7iDKZ6ij9u
K5Pfn10JL/ERDig2qJQbqvhtIAx0RY7y7r+hLMvgXVq9mf3WRJYmGQeFW+N9t5Z1eEwG4m9R
KAZm0fnfeDn/Ai4kmxTckBH7dZwW2lTtwQqQ4su+PGCJ0e9ndBLpvTqaYGSAl+L7PO7vxPhS
/cS67Xa6BtnYJLTr3MaGXaN+CEUFSfwQHa9DKcAqh3kldErI3kCvnot0CigBl4aILOEwggY0
MIIEHKADAgECAgEeMA0GCSqGSIb3DQEBBQUAMH0xCzAJBgNVBAYTAklMMRYwFAYDVQQKEw1T
dGFydENvbSBMdGQuMSswKQYDVQQLEyJTZWN1cmUgRGlnaXRhbCBDZXJ0aWZpY2F0ZSBTaWdu
aW5nMSkwJwYDVQQDEyBTdGFydENvbSBDZXJ0aWZpY2F0aW9uIEF1dGhvcml0eTAeFw0wNzEw
MjQyMTAxNTVaFw0xNzEwMjQyMTAxNTVaMIGMMQswCQYDVQQGEwJJTDEWMBQGA1UEChMNU3Rh
cnRDb20gTHRkLjErMCkGA1UECxMiU2VjdXJlIERpZ2l0YWwgQ2VydGlmaWNhdGUgU2lnbmlu
ZzE4MDYGA1UEAxMvU3RhcnRDb20gQ2xhc3MgMSBQcmltYXJ5IEludGVybWVkaWF0ZSBDbGll
bnQgQ0EwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDHCYPMzi3YGrEppC4Tq5a+
ijKDjKaIQZZVR63UbxIP6uq/I0fhCu+cQhoUfE6ERKKnu8zPf1Jwuk0tsvVCk6U9b+0UjM0d
Lep3ZdE1gblK/1FwYT5Pipsu2yOMluLqwvsuz9/9f1+1PKHG/FaR/wpbfuIqu54qzHDYeqiU
fsYzoVflR80DAC7hmJ+SmZnNTWyUGHJbBpA8Q89lGxahNvuryGaC/o2/ceD2uYDX9U8Eg5Dp
IpGQdcbQeGarV04WgAUjjXX5r/2dabmtxWMZwhZna//jdiSyrrSMTGKkDiXm6/3/4ebfeZuC
YKzN2P8O2F/Xe2AC/Y7zeEsnR7FOp+uXAgMBAAGjggGtMIIBqTAPBgNVHRMBAf8EBTADAQH/
MA4GA1UdDwEB/wQEAwIBBjAdBgNVHQ4EFgQUU3Ltkpzg2ssBXHx+ljVO8tS4UYIwHwYDVR0j
BBgwFoAUTgvvGqRAW6UXaYcwyjRoQ9BBrvIwZgYIKwYBBQUHAQEEWjBYMCcGCCsGAQUFBzAB
hhtodHRwOi8vb2NzcC5zdGFydHNzbC5jb20vY2EwLQYIKwYBBQUHMAKGIWh0dHA6Ly93d3cu
c3RhcnRzc2wuY29tL3Nmc2NhLmNydDBbBgNVHR8EVDBSMCegJaAjhiFodHRwOi8vd3d3LnN0
YXJ0c3NsLmNvbS9zZnNjYS5jcmwwJ6AloCOGIWh0dHA6Ly9jcmwuc3RhcnRzc2wuY29tL3Nm
c2NhLmNybDCBgAYDVR0gBHkwdzB1BgsrBgEEAYG1NwECATBmMC4GCCsGAQUFBwIBFiJodHRw
Oi8vd3d3LnN0YXJ0c3NsLmNvbS9wb2xpY3kucGRmMDQGCCsGAQUFBwIBFihodHRwOi8vd3d3
LnN0YXJ0c3NsLmNvbS9pbnRlcm1lZGlhdGUucGRmMA0GCSqGSIb3DQEBBQUAA4ICAQAKgwh9
eKssBly4Y4xerhy5I3dNoXHYfYa8PlVLL/qtXnkFgdtY1o95CfegFJTwqBBmf8pyTUnFsukD
FUI22zF5bVHzuJ+GxhnSqN2sD1qetbYwBYK2iyYA5Pg7Er1A+hKMIzEzcduRkIMmCeUTyMyi
kfbUFvIBivtvkR8ZFAk22BZy+pJfAoedO61HTz4qSfQoCRcLN5A0t4DkuVhTMXIzuQ8Cnykh
ExD6x4e6ebIbrjZLb7L+ocR0y4YjCl/Pd4MXU91y0vTipgr/O75CDUHDRHCCKBVmz/Rzkc/b
970MEeHt5LC3NiWTgBSvrLEuVzBKM586YoRD9Dy3OHQgWI270g+5MYA8GfgI/EPT5G7xPbCD
z+zjdH89PeR3U4So4lSXur6H6vp+m9TQXPF3a0LwZrp8MQ+Z77U1uL7TelWO5lApsbAonrqA
SfTpaprFVkL4nyGH+NHST2ZJPWIBk81i6Vw0ny0qZW2Niy/QvVNKbb43A43ny076khXO7cNb
BIRdJ/6qQNq9Bqb5C0Q5nEsFcj75oxQRqlKf6TcvGbjxkJh8BYtv9ePsXklAxtm8J7GCUBth
HSQgepbkOexhJ0wP8imUkyiPHQ0GvEnd83129fZjoEhdGwXV27ioRKbj/cIq7JRXun0NbeY+
UdMYu9jGfIpDLtUUGSgsg2zMGs5R4jGCA90wggPZAgEBMIGUMIGMMQswCQYDVQQGEwJJTDEW
MBQGA1UEChMNU3RhcnRDb20gTHRkLjErMCkGA1UECxMiU2VjdXJlIERpZ2l0YWwgQ2VydGlm
aWNhdGUgU2lnbmluZzE4MDYGA1UEAxMvU3RhcnRDb20gQ2xhc3MgMSBQcmltYXJ5IEludGVy
bWVkaWF0ZSBDbGllbnQgQ0ECAwiRTjAJBgUrDgMCGgUAoIICHTAYBgkqhkiG9w0BCQMxCwYJ
KoZIhvcNAQcBMBwGCSqGSIb3DQEJBTEPFw0xNDA3MTUwODI1MDZaMCMGCSqGSIb3DQEJBDEW
BBTMIz9OuUkxdkesvMBxpXZtnolmtDBsBgkqhkiG9w0BCQ8xXzBdMAsGCWCGSAFlAwQBKjAL
BglghkgBZQMEAQIwCgYIKoZIhvcNAwcwDgYIKoZIhvcNAwICAgCAMA0GCCqGSIb3DQMCAgFA
MAcGBSsOAwIHMA0GCCqGSIb3DQMCAgEoMIGlBgkrBgEEAYI3EAQxgZcwgZQwgYwxCzAJBgNV
BAYTAklMMRYwFAYDVQQKEw1TdGFydENvbSBMdGQuMSswKQYDVQQLEyJTZWN1cmUgRGlnaXRh
bCBDZXJ0aWZpY2F0ZSBTaWduaW5nMTgwNgYDVQQDEy9TdGFydENvbSBDbGFzcyAxIFByaW1h
cnkgSW50ZXJtZWRpYXRlIENsaWVudCBDQQIDCJFOMIGnBgsqhkiG9w0BCRACCzGBl6CBlDCB
jDELMAkGA1UEBhMCSUwxFjAUBgNVBAoTDVN0YXJ0Q29tIEx0ZC4xKzApBgNVBAsTIlNlY3Vy
ZSBEaWdpdGFsIENlcnRpZmljYXRlIFNpZ25pbmcxODA2BgNVBAMTL1N0YXJ0Q29tIENsYXNz
IDEgUHJpbWFyeSBJbnRlcm1lZGlhdGUgQ2xpZW50IENBAgMIkU4wDQYJKoZIhvcNAQEBBQAE
ggEASd93+3hDAhY0/iXjPIPK+FdKukxWng8XDbBPtA5HP2ymZdnmi9RFN8s3L0g6SMASlu4l
YBmA3G6A0/SUIPqrRathEF1H3J5WKR8cRSmTeBqQtUaHhFwwaW0QNXCcOxQdVm0jBTltp1uR
VIwpJ8krlA6GQSl4Ms8NALuruFZ9otQvgY6GpSO4+v3WYI4R9398qf4XpWixV7MIjpVuS9bF
74Y5oG+h/TRfSo7KT86A6s615R5t6EieXADpZ3WUqzUwYw4ntKutiNsKsq0ATFxH4H14QZc1
4r50Nrr8Op0393ybtraz2si5Uc+OKAOlCtkpr0gwuupFNJnXWDBApNahfQAAAAAAAA==
--------------ms060009060703010101050101--


From nobody Tue Jul 15 01:26:04 2014
Return-Path: <likepeng@huawei.com>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 4A6341A033D for <ace@ietfa.amsl.com>; Tue, 15 Jul 2014 01:26:03 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.852
X-Spam-Level: 
X-Spam-Status: No, score=-4.852 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, RP_MATCHES_RCVD=-0.651, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 925Kg_rdTC8Q for <ace@ietfa.amsl.com>; Tue, 15 Jul 2014 01:26:01 -0700 (PDT)
Received: from lhrrgout.huawei.com (lhrrgout.huawei.com [194.213.3.17]) (using TLSv1 with cipher RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 674B51A0343 for <ace@ietf.org>; Tue, 15 Jul 2014 01:26:01 -0700 (PDT)
Received: from 172.18.7.190 (EHLO lhreml402-hub.china.huawei.com) ([172.18.7.190]) by lhrrg01-dlp.huawei.com (MOS 4.3.7-GA FastPath queued) with ESMTP id BKB10513; Tue, 15 Jul 2014 08:25:59 +0000 (GMT)
Received: from SZXEMA402-HUB.china.huawei.com (10.82.72.34) by lhreml402-hub.china.huawei.com (10.201.5.241) with Microsoft SMTP Server (TLS) id 14.3.158.1; Tue, 15 Jul 2014 09:25:57 +0100
Received: from SZXEMA501-MBS.china.huawei.com ([169.254.2.128]) by SZXEMA402-HUB.china.huawei.com ([10.82.72.34]) with mapi id 14.03.0158.001; Tue, 15 Jul 2014 16:25:53 +0800
From: Likepeng <likepeng@huawei.com>
To: Ludwig Seitz <ludwig@sics.se>, "ace@ietf.org" <ace@ietf.org>
Thread-Topic: [Ace] Offline operation of Resource Server
Thread-Index: AQHPn1g5Xr89HU0KBEmeRqSDLOFEKJufVoWAgAAOToCAABYwAIAAoMsAgACutlA=
Date: Tue, 15 Jul 2014 08:25:52 +0000
Message-ID: <34966E97BE8AD64EAE9D3D6E4DEE36F2581780BF@SZXEMA501-MBS.china.huawei.com>
References: <53C3C09A.5090707@gmx.net> <14018.1405360899@sandelman.ca> <53C42703.4060806@gmx.net> <8236.1405368736@sandelman.ca> <53C4C082.3020909@sics.se>
In-Reply-To: <53C4C082.3020909@sics.se>
Accept-Language: zh-CN, en-US
Content-Language: zh-CN
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
x-originating-ip: [10.66.167.122]
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: base64
MIME-Version: 1.0
X-CFilter-Loop: Reflected
Archived-At: http://mailarchive.ietf.org/arch/msg/ace/Rpj1ilcMiRgtBBdg7zhJf6VfN7w
Subject: Re: [Ace] Offline operation of Resource Server
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 15 Jul 2014 08:26:03 -0000

SGkgTHVkd2lnLA0KDQo+IEl0IG1lYW5zIGV4YWN0bHkgdGhlIGtpbmQgb2Ygb2ZmbGluZSB2YWxp
ZGF0aW9uIHRoYXQgTWljaGFlbCBkZXNjcmliZWQgYWJvdmUuDQo+IA0KPiAxLiBZb3UgbmVlZCBz
b21lIGluaXRpYWwgZW5yb2xsbWVudCBvZiBBUyA8LT4gUlMgKHRoYXQgY291bGQgYmUgb25saW5l
IG9yIG9mZmxpbmUNCj4gJiBtYW51YWwgc3VjaCBhcyBieSByZWFkaW5nIG9mZiBzb21lIFFSIGNv
ZGUgd2l0aCB0aGUgUlNzIGluaXRpYWwga2V5IG1hdGVyaWFsDQo+IGFuZCBmZWVkaW5nIHRoYXQg
dG8gdGhlIEFTKS4NCj4gDQo+IDIuIFRoZW4geW91IG5lZWQgc29tZSBvbmxpbmUgYXV0aG9yaXph
dGlvbiBkZWNpc2lvbiBzdGVwIGJldHdlZW4gQyBhbmQgQVMuDQo+IA0KPiAzLiBUaGVuIChwb3Nz
aWJseSBsYXRlcikgdGhlcmUgaXMgc29tZSBpbnRlcmFjdGlvbiBiZXR3ZWVuIEMgYW5kIFJTLCB0
aGF0IGNvdWxkDQo+IGJlIG9mZmxpbmUuIEhlcmUgUlMgbmVlZHMgdG8gYmUgYWJsZSB0byBkbyBv
ZmZsaW5lIHZhbGlkYXRpb24gb2YgdGhlDQo+IGF1dGhvcml6YXRpb24gZGVjaXNpb24gZnJvbSBz
dGVwIDIuDQoNClRoaXMgc2VlbXMgdG8gYmUgdGhlIG5vcm1hbCBmbG93Lg0KDQpJZiBJIGNoZWNr
IHRoZSBkcmFmdCBzZWN0aW9uIDQuMy40LCBpbiB0aGUgbm9ybWFsIGZsb3csIHRoZSBSUyBhbHNv
IGRvZXMgbm90IG5lZWQgdG8gY29udGFjdCB0aGUgQVMgZm9yIHRoZSBvbmxpbmUgdmFsaWRhdGlv
biBvZiB0aGUgYWNjZXNzIHRva2VuLg0KaHR0cDovL3Rvb2xzLmlldGYub3JnL2h0bWwvZHJhZnQt
c2VsYW5kZXItY29yZS1hY2Nlc3MtY29udHJvbC0wMg0KDQpEbyB5b3UgbWVhbiBDbGllbnQgaXMg
YWxzbyBvZmZsaW5lLCBhbmQgY2FuJ3QgY29udGFjdCB3aXRoIEFTPw0KDQpJbiBkcmFmdC1zZWl0
ei1hY2UtcHJvYmxlbS1kZXNjcmlwdGlvbiBzZWN0aW9uIDQuNSwgdGhlIG9mZmxpbmUgcmVxdWly
ZW1lbnQvYXNzdW1wdGlvbiBpczoNCg0KICAgICBvIFJTIG1heSBub3QgYmUgYWJsZSB0byBjb21t
dW5pY2F0ZSB3aXRoIEFTIGF0IHRoZSB0aW1lIG9mIHRoZSByZXF1ZXN0IGZyb20gQy4NCiAgDQpC
dXQgSSBhbSBub3QgY2xlYXIsIG9ubHkgUlMgY2Fu4oCZdCBjb21tdW5pY2F0ZSB3aXRoIEFTLCBv
ciBib3RoIENsaWVudCBhbmQgUlMgY2Fu4oCZdCBjb21tdW5pY2F0ZSB3aXRoIEFTPw0KDQpLaW5k
IFJlZ2FyZHMNCktlcGVuZw0KDQo+IC0tLS0t6YKu5Lu25Y6f5Lu2LS0tLS0NCj4g5Y+R5Lu25Lq6
OiBBY2UgW21haWx0bzphY2UtYm91bmNlc0BpZXRmLm9yZ10g5Luj6KGoIEx1ZHdpZyBTZWl0eg0K
PiDlj5HpgIHml7bpl7Q6IDIwMTTlubQ35pyIMTXml6UgMTM6NDgNCj4g5pS25Lu25Lq6OiBhY2VA
aWV0Zi5vcmcNCj4g5Li76aKYOiBSZTogW0FjZV0gT2ZmbGluZSBvcGVyYXRpb24gb2YgUmVzb3Vy
Y2UgU2VydmVyDQo+IA0KPiBPbiAwNy8xNC8yMDE0IDEwOjEyIFBNLCBNaWNoYWVsIFJpY2hhcmRz
b24gd3JvdGU6DQo+ID4NCj4gPiBIYW5uZXMgVHNjaG9mZW5pZyA8aGFubmVzLnRzY2hvZmVuaWdA
Z214Lm5ldD4gd3JvdGU6DQo+ID4gICAgICA+IFRvIHJlLXVzZSB0aGUgS2VyYmVyb3MgbGFuZ3Vh
Z2UsIHRoZSBjbGllbnQgZ2V0cyB0aGUgVEdULiBUaGUNCj4gcmVhbC10aW1lDQo+ID4gICAgICA+
IGludGVyYWN0aW9uIEkgd2FzIHRhbGtpbmcgYWJvdXQgcmVsYXRlcyB0byB0aGUgaW50ZXJhY3Rp
b24gYmV0d2VlbiB0aGUNCj4gPiAgICAgID4gcmVzb3VyY2Ugc2VydmVyIGFuZCB0aGUgYXV0aG9y
aXphdGlvbiBzZXJ2ZXIuDQo+ID4NCj4gPiBEdXJpbmcgZW5yb2xsbWVudCwgdGhlIEF1dGhvcml6
YXRpb24gU2VydmVyIGdldHMgYSBUR1Qgb24gdGhlICpyZXNvdXJjZSoNCj4gc2VydmVyLg0KPiA+
IEdpdmVuIHRoYXQsIGl0IGNhbiBub3cgaXNzdWUgbmV3IHRpY2tldHMgdG8gY2xpZW50cyB0aGF0
IGNvbWUgYWxvbmcNCj4gPiB0aGF0IHdpc2ggdG8gYWNjZXNzIHRoZSByZXNvdXJjZS4gIFRoZSBj
bGllbnQsIGR1cmluZyBlbnJvbGxtZW50LCBhc2tzDQo+ID4gdGhlIChwb3NzaWJseSBmZWRlcmF0
ZWQgbGlzdCBvZikgYXV0aG9yaXphdGlvbiBzZXJ2ZXJzIGZvciBhIHJlc291cmNlIHRpY2tldC4N
Cj4gPiAoVGhpcyBpcyB3aHkgcGFydCBvZiBuZXR3b3JrIGpvaW4gbmVlZHMgdG8gYmUgaW4gc2Nv
cGUgZm9yIEFDRSkNCj4gPg0KPiA+IEFsbCBvZiB0aGUgYWJvdmUgaGFzIHRvIG9jY3VyIG9ubGlu
ZS4NCj4gPg0KPiA+IE9uY2UgdGhlIGNsaWVudCBoYXMgdGhlIHJlc291cmNlIHRpY2tldCwgdGhl
IHJlc291cmNlIHNlcnZlciBjYW4gdmFsaWRhdGUgaXQNCj4gb2ZmbGluZS4NCj4gPg0KPiANCj4g
DQo+ICA+Pkx1ZHdpZywgY291bGQgeW91IHBsZWFzZSBleHBsYWluIHRoaXMgb2ZmbGluZSByZXF1
aXJlbWVudCBhIGJpdCBtb3JlPw0KPiANCj4gSXQgbWVhbnMgZXhhY3RseSB0aGUga2luZCBvZiBv
ZmZsaW5lIHZhbGlkYXRpb24gdGhhdCBNaWNoYWVsIGRlc2NyaWJlZCBhYm92ZS4NCj4gDQo+IDEu
IFlvdSBuZWVkIHNvbWUgaW5pdGlhbCBlbnJvbGxtZW50IG9mIEFTIDwtPiBSUyAodGhhdCBjb3Vs
ZCBiZSBvbmxpbmUgb3Igb2ZmbGluZQ0KPiAmIG1hbnVhbCBzdWNoIGFzIGJ5IHJlYWRpbmcgb2Zm
IHNvbWUgUVIgY29kZSB3aXRoIHRoZSBSU3MgaW5pdGlhbCBrZXkgbWF0ZXJpYWwNCj4gYW5kIGZl
ZWRpbmcgdGhhdCB0byB0aGUgQVMpLg0KPiANCj4gMi4gVGhlbiB5b3UgbmVlZCBzb21lIG9ubGlu
ZSBhdXRob3JpemF0aW9uIGRlY2lzaW9uIHN0ZXAgYmV0d2VlbiBDIGFuZCBBUy4NCj4gDQo+IDMu
IFRoZW4gKHBvc3NpYmx5IGxhdGVyKSB0aGVyZSBpcyBzb21lIGludGVyYWN0aW9uIGJldHdlZW4g
QyBhbmQgUlMsIHRoYXQgY291bGQNCj4gYmUgb2ZmbGluZS4gSGVyZSBSUyBuZWVkcyB0byBiZSBh
YmxlIHRvIGRvIG9mZmxpbmUgdmFsaWRhdGlvbiBvZiB0aGUNCj4gYXV0aG9yaXphdGlvbiBkZWNp
c2lvbiBmcm9tIHN0ZXAgMi4NCj4gDQo+IA0KPiAvTHVkd2lnDQo+IA0KPiAtLQ0KPiBMdWR3aWcg
U2VpdHosIFBoRA0KPiBTSUNTIFN3ZWRpc2ggSUNUIEFCDQo+IElkZW9uIFNjaWVuY2UgUGFyaw0K
PiBCdWlsZGluZyBCZXRhIDINCj4gU2NoZWVsZXbDpGdlbiAxNw0KPiBTRS0yMjMgNzAgTHVuZA0K
PiANCj4gUGhvbmUgKzQ2KDApNzAtMzQ5IDkyIDUxDQo+IGh0dHA6Ly93d3cuc2ljcy5zZQ0KDQo=


From nobody Tue Jul 15 01:29:11 2014
Return-Path: <hannes.tschofenig@gmx.net>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id D4D151A0343 for <ace@ietfa.amsl.com>; Tue, 15 Jul 2014 01:29:10 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.551
X-Spam-Level: 
X-Spam-Status: No, score=-2.551 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, FREEMAIL_FROM=0.001, RCVD_IN_DNSWL_NONE=-0.0001, RP_MATCHES_RCVD=-0.651, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id RlfNdY-ceer0 for <ace@ietfa.amsl.com>; Tue, 15 Jul 2014 01:29:09 -0700 (PDT)
Received: from mout.gmx.net (mout.gmx.net [212.227.15.15]) (using TLSv1.2 with cipher DHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 8C5291A033D for <ace@ietf.org>; Tue, 15 Jul 2014 01:29:09 -0700 (PDT)
Received: from [172.16.254.119] ([80.92.116.212]) by mail.gmx.com (mrgmx001) with ESMTPSA (Nemesis) id 0LfCX2-1Wn1ZJ2f4i-00okEb; Tue, 15 Jul 2014 10:29:05 +0200
Message-ID: <53C4E650.5010804@gmx.net>
Date: Tue, 15 Jul 2014 10:29:04 +0200
From: Hannes Tschofenig <hannes.tschofenig@gmx.net>
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:24.0) Gecko/20100101 Thunderbird/24.6.0
MIME-Version: 1.0
To: Ludwig Seitz <ludwig@sics.se>, Likepeng <likepeng@huawei.com>,  "ace@ietf.org" <ace@ietf.org>
References: <53C398ED.3030302@gmx.net> <53C3D013.6030006@sics.se> <34966E97BE8AD64EAE9D3D6E4DEE36F258177D9A@SZXEMA501-MBS.china.huawei.com> <53C4E3D1.7020804@gmx.net> <53C4E562.4040202@sics.se>
In-Reply-To: <53C4E562.4040202@sics.se>
X-Enigmail-Version: 1.5.2
OpenPGP: id=4D776BC9
Content-Type: multipart/signed; micalg=pgp-sha512; protocol="application/pgp-signature"; boundary="u4oQrAOnuJc7fPv1rCTMu5uHXJ7MpHVSu"
X-Provags-ID: V03:K0:uRVj63ITjTGHev5qmd/lE29k3hbtptd07Vi5UxLrX9l80hixVbb ZxcIPeMVYnQAyGLO16VAR9N66niIhln5pZbFglj9mLa2HOXx6k+G0y8l20tACGlQYsLKeHC R/iDMv0mPpAp+U6Gu1QJmR2EMovpZ6/XxBkYzX/tBpotQcU0S4OZ8dWKlk2NWOOkyEfNVII /iCudAzwA3p6U7QaSouAg==
Archived-At: http://mailarchive.ietf.org/arch/msg/ace/gcdbVh3HOJ4rFu46LxH83Dk2m7c
Subject: Re: [Ace] Agenda
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 15 Jul 2014 08:29:11 -0000

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--u4oQrAOnuJc7fPv1rCTMu5uHXJ7MpHVSu
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: quoted-printable


On 07/15/2014 10:25 AM, Ludwig Seitz wrote:
> Well in the DICE thread you said that you could ask a colleague about
> the price of adding asymmetric crypto hardware:

That is too short notice to put a meaningful presentation together for
this meeting. Of course, I could arrange a Webex session in about 2 month=
s.

Ciao
Hannes


--u4oQrAOnuJc7fPv1rCTMu5uHXJ7MpHVSu
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
Content-Disposition: attachment; filename="signature.asc"

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1
Comment: GPGTools - http://gpgtools.org
Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/

iQEcBAEBCgAGBQJTxOZQAAoJEGhJURNOOiAtm7oH/jmcYu9ceXryFKQ2huhqotDF
LJxgOXtE1r9cv7V4AJJVhsovSvM2mxhLQIxNREwN0jvo6UcSejGyjHbVY6G4vKXK
AskVmKMJ/npxm0y4WhpxsFdGAKL7552qXEiYRDbYy/d8aV7Jr9ZMWWC1wa/tYxyl
y1uWPn730Fn5y1MrDDRvqoqp2waBvTrSlPceTjGsvhHyvL3YlB36tPO2WH8rBT8S
IZDdJ4M9q051W4ldACEHR++3wp4Q50pGb+7JleWhFv0m3HtjnaMnglh2EOW+hYdc
SvY1MwB432mgAPWNhkdcWQuRnm+iBRlI+HIVSbTFPeE8s86KfXEPiX2K9Y/S6zM=
=CpD1
-----END PGP SIGNATURE-----

--u4oQrAOnuJc7fPv1rCTMu5uHXJ7MpHVSu--


From nobody Tue Jul 15 01:30:12 2014
Return-Path: <ludwig@sics.se>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id B58971A0366 for <ace@ietfa.amsl.com>; Tue, 15 Jul 2014 01:30:10 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.901
X-Spam-Level: 
X-Spam-Status: No, score=-2.901 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HELO_EQ_SE=0.35, RCVD_IN_DNSWL_LOW=-0.7, RP_MATCHES_RCVD=-0.651] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 4zd-vS9AOJCS for <ace@ietfa.amsl.com>; Tue, 15 Jul 2014 01:30:07 -0700 (PDT)
Received: from outbox.sics.se (outbox.sics.se [193.10.64.137]) by ietfa.amsl.com (Postfix) with ESMTP id 1E1421A0343 for <ace@ietf.org>; Tue, 15 Jul 2014 01:30:07 -0700 (PDT)
Received: from e-mailfilter01.sunet.se (e-mailfilter01.sunet.se [192.36.171.201]) by outbox.sics.se (Postfix) with ESMTPS id 6AEE26EA; Tue, 15 Jul 2014 10:30:06 +0200 (CEST)
Received: from letter.sics.se (letter.sics.se [193.10.64.6]) by e-mailfilter01.sunet.se (8.14.4/8.14.4/Debian-4) with ESMTP id s6F8U6qJ019907; Tue, 15 Jul 2014 10:30:06 +0200
Received: from [192.168.0.108] (unknown [85.235.11.178]) (Authenticated sender: ludwig@sics.se) by letter.sics.se (Postfix) with ESMTPSA id 1F20940116; Tue, 15 Jul 2014 10:30:06 +0200 (CEST)
Message-ID: <53C4E68D.9030004@sics.se>
Date: Tue, 15 Jul 2014 10:30:05 +0200
From: Ludwig Seitz <ludwig@sics.se>
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:24.0) Gecko/20100101 Thunderbird/24.6.0
MIME-Version: 1.0
To: Likepeng <likepeng@huawei.com>, "ace@ietf.org" <ace@ietf.org>
References: <53C3C09A.5090707@gmx.net> <14018.1405360899@sandelman.ca> <53C42703.4060806@gmx.net> <8236.1405368736@sandelman.ca> <53C4C082.3020909@sics.se> <34966E97BE8AD64EAE9D3D6E4DEE36F2581780BF@SZXEMA501-MBS.china.huawei.com>
In-Reply-To: <34966E97BE8AD64EAE9D3D6E4DEE36F2581780BF@SZXEMA501-MBS.china.huawei.com>
Content-Type: multipart/signed; protocol="application/pkcs7-signature"; micalg=sha1; boundary="------------ms050408000701050908080405"
X-Bayes-Prob: 0.0001 (Score 0, tokens from: outbound, outbound-sics-se:default, sics-se:default, base:default, @@RPTN)
X-p0f-Info: os=Solaris 10, link=Ethernet or modem
X-CanIt-Geo: =?UTF-8?Q?ip=3D85.235.11.178; _country=3DSE; _region=3DSk=C3=A5ne; _city=3DLund; _latitude=3D55.7000; _longitude=3D13.1833; _http://maps.google.com/maps=3Fq=3D55.7000,13.1833&z=3D6?=
X-CanItPRO-Stream: outbound-sics-se:outbound (inherits from outbound-sics-se:default, sics-se:default, base:default)
X-Canit-Stats-ID: 09Mqwu6km - 228e94397c44 - 20140715
X-Antispam-Training-Forget: https://canit.sunet.se/canit/b.php?i=09Mqwu6km&m=228e94397c44&t=20140715&c=f
X-Antispam-Training-Nonspam: https://canit.sunet.se/canit/b.php?i=09Mqwu6km&m=228e94397c44&t=20140715&c=n
X-Antispam-Training-Spam: https://canit.sunet.se/canit/b.php?i=09Mqwu6km&m=228e94397c44&t=20140715&c=s
X-CanIt-Archive-Cluster: PfMRe/vJWMiXwM2YIH5BVExnUnw
X-Scanned-By: CanIt (www . roaringpenguin . com) on 192.36.171.201
Archived-At: http://mailarchive.ietf.org/arch/msg/ace/xW85gG0xRf1i8llAKsXd8neMDNI
Subject: Re: [Ace] Offline operation of Resource Server
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 15 Jul 2014 08:30:10 -0000

This is a cryptographically signed message in MIME format.

--------------ms050408000701050908080405
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: quoted-printable

On 07/15/2014 10:25 AM, Likepeng wrote:
> Hi Ludwig,
>
>> It means exactly the kind of offline validation that Michael described=
 above.
>>
>> 1. You need some initial enrollment of AS <-> RS (that could be online=
 or offline
>> & manual such as by reading off some QR code with the RSs initial key =
material
>> and feeding that to the AS).
>>
>> 2. Then you need some online authorization decision step between C and=
 AS.
>>
>> 3. Then (possibly later) there is some interaction between C and RS, t=
hat could
>> be offline. Here RS needs to be able to do offline validation of the
>> authorization decision from step 2.
>
> This seems to be the normal flow.
>
> If I check the draft section 4.3.4, in the normal flow, the RS also doe=
s not need to contact the AS for the online validation of the access toke=
n.
> http://tools.ietf.org/html/draft-selander-core-access-control-02
>
> Do you mean Client is also offline, and can't contact with AS?
>

I haven't really considered that, but it might be the case that in step=20
3. even the client is offline. Think about the example G=C3=B6ran gave:

>
> One example of offline operations is for field technicians to physical
> access radio base station sites:
> If the base station is malfunctioning, there may be no cellular coverag=
e
> at the site, and the field technician need to access the site to repair=

> the base station (which then may become a catch 22).


--=20
Ludwig Seitz, PhD
SICS Swedish ICT AB
Ideon Science Park
Building Beta 2
Scheelev=C3=A4gen 17
SE-223 70 Lund

Phone +46(0)70-349 92 51
http://www.sics.se


--------------ms050408000701050908080405
Content-Type: application/pkcs7-signature; name="smime.p7s"
Content-Transfer-Encoding: base64
Content-Disposition: attachment; filename="smime.p7s"
Content-Description: S/MIME Cryptographic Signature

MIAGCSqGSIb3DQEHAqCAMIACAQExCzAJBgUrDgMCGgUAMIAGCSqGSIb3DQEHAQAAoIIMVDCC
BhgwggUAoAMCAQICAwiRTjANBgkqhkiG9w0BAQsFADCBjDELMAkGA1UEBhMCSUwxFjAUBgNV
BAoTDVN0YXJ0Q29tIEx0ZC4xKzApBgNVBAsTIlNlY3VyZSBEaWdpdGFsIENlcnRpZmljYXRl
IFNpZ25pbmcxODA2BgNVBAMTL1N0YXJ0Q29tIENsYXNzIDEgUHJpbWFyeSBJbnRlcm1lZGlh
dGUgQ2xpZW50IENBMB4XDTE0MDEwNzA3MjgzNVoXDTE1MDEwNzEyNTgyMlowODEXMBUGA1UE
AwwObHVkd2lnQHNpY3Muc2UxHTAbBgkqhkiG9w0BCQEWDmx1ZHdpZ0BzaWNzLnNlMIIBIjAN
BgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAnLm1tc30QxHa9wtdVjC3NgxjLJicnccm0HD+
1X16kPMKGvwps8F1oDhYn7jXIe46p1AuJMzLK0GIioE4JwxCFGdvpz7cg2xyTyrdBVUzSqez
Dfqt4FOJq6hrdrIMS8MHEzl7Jk02gv9cTn/pHQvDpkiThRpbSLU5mlMqtEQ8gDQY5YyBX0Mv
5qculV08I2JU8HEeTt1oeqhvBImgQfOVYMDatHlWHUVVrmYd6iIo+cuiUGd5kiA0XuaLYX0E
oCoao/z5Wg9U0sQlx0hl4r96Q+NdoZZ1prfts3qtyBzJ2hu135aikigzJ6sueWHv/jbISUek
tOMm0xkx1GOqqWtEAwIDAQABo4IC1DCCAtAwCQYDVR0TBAIwADALBgNVHQ8EBAMCBLAwHQYD
VR0lBBYwFAYIKwYBBQUHAwIGCCsGAQUFBwMEMB0GA1UdDgQWBBRZmjjBh8N3klra+mVQgC00
pl68ZTAfBgNVHSMEGDAWgBRTcu2SnODaywFcfH6WNU7y1LhRgjAZBgNVHREEEjAQgQ5sdWR3
aWdAc2ljcy5zZTCCAUwGA1UdIASCAUMwggE/MIIBOwYLKwYBBAGBtTcBAgMwggEqMC4GCCsG
AQUFBwIBFiJodHRwOi8vd3d3LnN0YXJ0c3NsLmNvbS9wb2xpY3kucGRmMIH3BggrBgEFBQcC
AjCB6jAnFiBTdGFydENvbSBDZXJ0aWZpY2F0aW9uIEF1dGhvcml0eTADAgEBGoG+VGhpcyBj
ZXJ0aWZpY2F0ZSB3YXMgaXNzdWVkIGFjY29yZGluZyB0byB0aGUgQ2xhc3MgMSBWYWxpZGF0
aW9uIHJlcXVpcmVtZW50cyBvZiB0aGUgU3RhcnRDb20gQ0EgcG9saWN5LCByZWxpYW5jZSBv
bmx5IGZvciB0aGUgaW50ZW5kZWQgcHVycG9zZSBpbiBjb21wbGlhbmNlIG9mIHRoZSByZWx5
aW5nIHBhcnR5IG9ibGlnYXRpb25zLjA2BgNVHR8ELzAtMCugKaAnhiVodHRwOi8vY3JsLnN0
YXJ0c3NsLmNvbS9jcnR1MS1jcmwuY3JsMIGOBggrBgEFBQcBAQSBgTB/MDkGCCsGAQUFBzAB
hi1odHRwOi8vb2NzcC5zdGFydHNzbC5jb20vc3ViL2NsYXNzMS9jbGllbnQvY2EwQgYIKwYB
BQUHMAKGNmh0dHA6Ly9haWEuc3RhcnRzc2wuY29tL2NlcnRzL3N1Yi5jbGFzczEuY2xpZW50
LmNhLmNydDAjBgNVHRIEHDAahhhodHRwOi8vd3d3LnN0YXJ0c3NsLmNvbS8wDQYJKoZIhvcN
AQELBQADggEBAHqEYmtWr83S+iLXE97KBnHJZiMr6PMuLKxmh0o6UJJwKgf+KTP2czxRnPSI
+whuqfQZdmz6g3A2K8AooMU0RXrzncnX1c4826APdnXkRxnGQxtZXI1wuhPn4z7iDKZ6ij9u
K5Pfn10JL/ERDig2qJQbqvhtIAx0RY7y7r+hLMvgXVq9mf3WRJYmGQeFW+N9t5Z1eEwG4m9R
KAZm0fnfeDn/Ai4kmxTckBH7dZwW2lTtwQqQ4su+PGCJ0e9ndBLpvTqaYGSAl+L7PO7vxPhS
/cS67Xa6BtnYJLTr3MaGXaN+CEUFSfwQHa9DKcAqh3kldErI3kCvnot0CigBl4aILOEwggY0
MIIEHKADAgECAgEeMA0GCSqGSIb3DQEBBQUAMH0xCzAJBgNVBAYTAklMMRYwFAYDVQQKEw1T
dGFydENvbSBMdGQuMSswKQYDVQQLEyJTZWN1cmUgRGlnaXRhbCBDZXJ0aWZpY2F0ZSBTaWdu
aW5nMSkwJwYDVQQDEyBTdGFydENvbSBDZXJ0aWZpY2F0aW9uIEF1dGhvcml0eTAeFw0wNzEw
MjQyMTAxNTVaFw0xNzEwMjQyMTAxNTVaMIGMMQswCQYDVQQGEwJJTDEWMBQGA1UEChMNU3Rh
cnRDb20gTHRkLjErMCkGA1UECxMiU2VjdXJlIERpZ2l0YWwgQ2VydGlmaWNhdGUgU2lnbmlu
ZzE4MDYGA1UEAxMvU3RhcnRDb20gQ2xhc3MgMSBQcmltYXJ5IEludGVybWVkaWF0ZSBDbGll
bnQgQ0EwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDHCYPMzi3YGrEppC4Tq5a+
ijKDjKaIQZZVR63UbxIP6uq/I0fhCu+cQhoUfE6ERKKnu8zPf1Jwuk0tsvVCk6U9b+0UjM0d
Lep3ZdE1gblK/1FwYT5Pipsu2yOMluLqwvsuz9/9f1+1PKHG/FaR/wpbfuIqu54qzHDYeqiU
fsYzoVflR80DAC7hmJ+SmZnNTWyUGHJbBpA8Q89lGxahNvuryGaC/o2/ceD2uYDX9U8Eg5Dp
IpGQdcbQeGarV04WgAUjjXX5r/2dabmtxWMZwhZna//jdiSyrrSMTGKkDiXm6/3/4ebfeZuC
YKzN2P8O2F/Xe2AC/Y7zeEsnR7FOp+uXAgMBAAGjggGtMIIBqTAPBgNVHRMBAf8EBTADAQH/
MA4GA1UdDwEB/wQEAwIBBjAdBgNVHQ4EFgQUU3Ltkpzg2ssBXHx+ljVO8tS4UYIwHwYDVR0j
BBgwFoAUTgvvGqRAW6UXaYcwyjRoQ9BBrvIwZgYIKwYBBQUHAQEEWjBYMCcGCCsGAQUFBzAB
hhtodHRwOi8vb2NzcC5zdGFydHNzbC5jb20vY2EwLQYIKwYBBQUHMAKGIWh0dHA6Ly93d3cu
c3RhcnRzc2wuY29tL3Nmc2NhLmNydDBbBgNVHR8EVDBSMCegJaAjhiFodHRwOi8vd3d3LnN0
YXJ0c3NsLmNvbS9zZnNjYS5jcmwwJ6AloCOGIWh0dHA6Ly9jcmwuc3RhcnRzc2wuY29tL3Nm
c2NhLmNybDCBgAYDVR0gBHkwdzB1BgsrBgEEAYG1NwECATBmMC4GCCsGAQUFBwIBFiJodHRw
Oi8vd3d3LnN0YXJ0c3NsLmNvbS9wb2xpY3kucGRmMDQGCCsGAQUFBwIBFihodHRwOi8vd3d3
LnN0YXJ0c3NsLmNvbS9pbnRlcm1lZGlhdGUucGRmMA0GCSqGSIb3DQEBBQUAA4ICAQAKgwh9
eKssBly4Y4xerhy5I3dNoXHYfYa8PlVLL/qtXnkFgdtY1o95CfegFJTwqBBmf8pyTUnFsukD
FUI22zF5bVHzuJ+GxhnSqN2sD1qetbYwBYK2iyYA5Pg7Er1A+hKMIzEzcduRkIMmCeUTyMyi
kfbUFvIBivtvkR8ZFAk22BZy+pJfAoedO61HTz4qSfQoCRcLN5A0t4DkuVhTMXIzuQ8Cnykh
ExD6x4e6ebIbrjZLb7L+ocR0y4YjCl/Pd4MXU91y0vTipgr/O75CDUHDRHCCKBVmz/Rzkc/b
970MEeHt5LC3NiWTgBSvrLEuVzBKM586YoRD9Dy3OHQgWI270g+5MYA8GfgI/EPT5G7xPbCD
z+zjdH89PeR3U4So4lSXur6H6vp+m9TQXPF3a0LwZrp8MQ+Z77U1uL7TelWO5lApsbAonrqA
SfTpaprFVkL4nyGH+NHST2ZJPWIBk81i6Vw0ny0qZW2Niy/QvVNKbb43A43ny076khXO7cNb
BIRdJ/6qQNq9Bqb5C0Q5nEsFcj75oxQRqlKf6TcvGbjxkJh8BYtv9ePsXklAxtm8J7GCUBth
HSQgepbkOexhJ0wP8imUkyiPHQ0GvEnd83129fZjoEhdGwXV27ioRKbj/cIq7JRXun0NbeY+
UdMYu9jGfIpDLtUUGSgsg2zMGs5R4jGCA90wggPZAgEBMIGUMIGMMQswCQYDVQQGEwJJTDEW
MBQGA1UEChMNU3RhcnRDb20gTHRkLjErMCkGA1UECxMiU2VjdXJlIERpZ2l0YWwgQ2VydGlm
aWNhdGUgU2lnbmluZzE4MDYGA1UEAxMvU3RhcnRDb20gQ2xhc3MgMSBQcmltYXJ5IEludGVy
bWVkaWF0ZSBDbGllbnQgQ0ECAwiRTjAJBgUrDgMCGgUAoIICHTAYBgkqhkiG9w0BCQMxCwYJ
KoZIhvcNAQcBMBwGCSqGSIb3DQEJBTEPFw0xNDA3MTUwODMwMDVaMCMGCSqGSIb3DQEJBDEW
BBTwUXqHHplACllPGHHAxBKrQ0nzdjBsBgkqhkiG9w0BCQ8xXzBdMAsGCWCGSAFlAwQBKjAL
BglghkgBZQMEAQIwCgYIKoZIhvcNAwcwDgYIKoZIhvcNAwICAgCAMA0GCCqGSIb3DQMCAgFA
MAcGBSsOAwIHMA0GCCqGSIb3DQMCAgEoMIGlBgkrBgEEAYI3EAQxgZcwgZQwgYwxCzAJBgNV
BAYTAklMMRYwFAYDVQQKEw1TdGFydENvbSBMdGQuMSswKQYDVQQLEyJTZWN1cmUgRGlnaXRh
bCBDZXJ0aWZpY2F0ZSBTaWduaW5nMTgwNgYDVQQDEy9TdGFydENvbSBDbGFzcyAxIFByaW1h
cnkgSW50ZXJtZWRpYXRlIENsaWVudCBDQQIDCJFOMIGnBgsqhkiG9w0BCRACCzGBl6CBlDCB
jDELMAkGA1UEBhMCSUwxFjAUBgNVBAoTDVN0YXJ0Q29tIEx0ZC4xKzApBgNVBAsTIlNlY3Vy
ZSBEaWdpdGFsIENlcnRpZmljYXRlIFNpZ25pbmcxODA2BgNVBAMTL1N0YXJ0Q29tIENsYXNz
IDEgUHJpbWFyeSBJbnRlcm1lZGlhdGUgQ2xpZW50IENBAgMIkU4wDQYJKoZIhvcNAQEBBQAE
ggEAPLmQ1zteSaZfsLzbv6ABbPEDRO7NmaHLo3wCtoZaXMKOj4rUMaDqgf2EIf1B/6u24WZo
fRZkDy/sNbQFQ6xlctDBET7tbLiOWmnFk/sjFGwMgCb45l+AHp0xOYrk/+txf/M5Vdr/4ykc
urJK8V8Y7knmZrMoPedGA+Y6gzU46R5RMGYxXLP2x99pQ9SQbUNSSR1V+/51m4UlgZXx5Sl6
Pt4MXyu1QGCa76eqKrDPqkp1BwkN067allg99eM8BU5Ixsw+Gjklfh59eUN2JynAETZrZ0xE
5nza5f5xcRtUw6NoyEoN0ZXh8IdIsvyozU4JEExVNyydwP9ndHLMyAcjtAAAAAAAAA==
--------------ms050408000701050908080405--


From nobody Tue Jul 15 01:35:45 2014
Return-Path: <hannes.tschofenig@gmx.net>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 5B63A1A0368 for <ace@ietfa.amsl.com>; Tue, 15 Jul 2014 01:35:43 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.551
X-Spam-Level: 
X-Spam-Status: No, score=-2.551 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, FREEMAIL_FROM=0.001, RCVD_IN_DNSWL_NONE=-0.0001, RP_MATCHES_RCVD=-0.651, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Lj3PXekKNQs8 for <ace@ietfa.amsl.com>; Tue, 15 Jul 2014 01:35:41 -0700 (PDT)
Received: from mout.gmx.net (mout.gmx.net [212.227.15.15]) (using TLSv1.2 with cipher DHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 79F3C1A001A for <ace@ietf.org>; Tue, 15 Jul 2014 01:35:41 -0700 (PDT)
Received: from [172.16.254.119] ([80.92.116.212]) by mail.gmx.com (mrgmx001) with ESMTPSA (Nemesis) id 0M8eAd-1WLCm00QUd-00wGJf; Tue, 15 Jul 2014 10:35:39 +0200
Message-ID: <53C4E7DA.2020003@gmx.net>
Date: Tue, 15 Jul 2014 10:35:38 +0200
From: Hannes Tschofenig <hannes.tschofenig@gmx.net>
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:24.0) Gecko/20100101 Thunderbird/24.6.0
MIME-Version: 1.0
To: Michael Richardson <mcr+ietf@sandelman.ca>
References: <53C3C09A.5090707@gmx.net> <14018.1405360899@sandelman.ca> <53C42703.4060806@gmx.net> <8236.1405368736@sandelman.ca>
In-Reply-To: <8236.1405368736@sandelman.ca>
X-Enigmail-Version: 1.5.2
OpenPGP: id=4D776BC9
Content-Type: multipart/signed; micalg=pgp-sha512; protocol="application/pgp-signature"; boundary="iGIqEA2XFaluCl8JlHCthgh0W9oGhsLXw"
X-Provags-ID: V03:K0:5YZMBag4UMjYyddC77ytey1nzF6KtThPLbBOeA2st3U/RtGKkEQ T6/5W5UoSUdEiLhlBpPRM3EWmfs48FX6fqjPA2gwopIMWXuQkpPBUvs/sm5TxNCXEHJuS5v 0RT11MT7RYNJbd3GnDj9vdMVczrMigHd6obba/Jq2N0VEGs9/tbSGEya9G8fdueqQK3DdWk S/gd8+xY+nWsqb4V5IURw==
Archived-At: http://mailarchive.ietf.org/arch/msg/ace/6MBwlnuz6a8VvQy_zhMIMJwNziU
Cc: "ace@ietf.org" <ace@ietf.org>
Subject: Re: [Ace] Offline operation of Resource Server
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 15 Jul 2014 08:35:43 -0000

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--iGIqEA2XFaluCl8JlHCthgh0W9oGhsLXw
Content-Type: text/plain; charset=ISO-8859-1
Content-Transfer-Encoding: quoted-printable

Hi Michael,

to go back to the place where this discussion started in
http://www.ietf.org/mail-archive/web/ace/current/msg00703.html.

There, I said that I believe the use case document rules out an
EAP/AAA solution because of a requirement for not having a real-time
interaction between the resource server and the AS.

This is pretty much reflected in the list of questions I asked to the
group, namely:

"
Are there requirements/use cases that allow anything other than the
OAuth/Kerberos design pattern?
"

If you use Kerberos wrapped in EAP then of course you change the EAP/AAA
model.

In a nutshell, I agree that Kerberos can meet the requirements currently
outlined in the requirements document. Whether the EAP/AAA can as well
depends a bit on how to conclude our work with the use
cases/requirements document.

Ciao
Hannes

On 07/14/2014 10:12 PM, Michael Richardson wrote:
>=20
> Hannes Tschofenig <hannes.tschofenig@gmx.net> wrote:
>     > To re-use the Kerberos language, the client gets the TGT. The rea=
l-time
>     > interaction I was talking about relates to the interaction betwee=
n the
>     > resource server and the authorization server.
>=20
> During enrollment, the Authorization Server gets a TGT on the *resource=
* server.
> Given that, it can now issue new tickets to clients that come along tha=
t wish
> to access the resource.  The client, during enrollment, asks the (possi=
bly
> federated list of) authorization servers for a resource ticket.
> (This is why part of network join needs to be in scope for ACE)
>=20
> All of the above has to occur online.
>=20
> Once the client has the resource ticket, the resource server can valida=
te it offline.
>=20
> --
> Michael Richardson <mcr+IETF@sandelman.ca>, Sandelman Software Works
>  -=3D IPv6 IoT consulting =3D-
>=20
>=20
>=20
>=20
>=20
> _______________________________________________
> Ace mailing list
> Ace@ietf.org
> https://www.ietf.org/mailman/listinfo/ace
>=20


--iGIqEA2XFaluCl8JlHCthgh0W9oGhsLXw
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
Content-Disposition: attachment; filename="signature.asc"

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1
Comment: GPGTools - http://gpgtools.org
Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/

iQEcBAEBCgAGBQJTxOfaAAoJEGhJURNOOiAt7vcH/ieF1IPlcwruZZWWJUoxrPaz
n+SdAtgrIijhuKnZJOUupvUM0EaFNhQtzBRNw8kVHpMPtjWM5SLbPl1b4IvkFtYJ
zvPE/+Ol8qE/fEwsmM59fA2BUH88iB7hmrMFv7KdkWKyR0nw+kLYFBpGWGdTWaqQ
cso4aJxgwUT5ANIarU7Sa/eqRCV9eWUPRegliNRUpgRA69NX5sdadbMR4B/RC0kp
IhAXC5rjFFwMdZh58hzzlWfd1EFeAjo5Ua/lC8jjlQoQMV3KXaqrZf9pfdVUWDLS
jPwkmArALFl6Aer5h0/lu3DQrlyYKTT3JWOjtQ1bKlBf9NNUVZXftHS70uB+YXA=
=1PYc
-----END PGP SIGNATURE-----

--iGIqEA2XFaluCl8JlHCthgh0W9oGhsLXw--


From nobody Tue Jul 15 05:58:02 2014
Return-Path: <rafa@um.es>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id EEA111B2887 for <ace@ietfa.amsl.com>; Tue, 15 Jul 2014 05:58:00 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.852
X-Spam-Level: 
X-Spam-Status: No, score=-4.852 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, RP_MATCHES_RCVD=-0.651, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 6MapDLc6axIO for <ace@ietfa.amsl.com>; Tue, 15 Jul 2014 05:57:58 -0700 (PDT)
Received: from xenon24.um.es (xenon24.um.es [155.54.212.164]) by ietfa.amsl.com (Postfix) with ESMTP id 06FF71B287B for <ace@ietf.org>; Tue, 15 Jul 2014 05:57:58 -0700 (PDT)
Received: from localhost (localhost [127.0.0.1]) by xenon24.um.es (Postfix) with ESMTP id BB3FBBEBF; Tue, 15 Jul 2014 14:57:56 +0200 (CEST)
X-Virus-Scanned: by antispam in UMU at xenon24.um.es
Received: from xenon24.um.es ([127.0.0.1]) by localhost (xenon24.um.es [127.0.0.1]) (amavisd-new, port 10024) with LMTP id vC6zm44AjSDJ; Tue, 15 Jul 2014 14:57:56 +0200 (CEST)
Received: from [192.168.1.66] (214.Red-83-42-243.dynamicIP.rima-tde.net [83.42.243.214]) (using TLSv1 with cipher ECDHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) (Authenticated sender: rafa) by xenon24.um.es (Postfix) with ESMTPSA id 6BD3196B5; Tue, 15 Jul 2014 14:57:54 +0200 (CEST)
Content-Type: text/plain; charset=iso-8859-1
Mime-Version: 1.0 (Mac OS X Mail 7.3 \(1878.6\))
From: Rafa Marin Lopez <rafa@um.es>
In-Reply-To: <53C4C082.3020909@sics.se>
Date: Tue, 15 Jul 2014 14:57:53 +0200
Content-Transfer-Encoding: quoted-printable
Message-Id: <191F7113-E5ED-49A2-AC27-AA886D527FB1@um.es>
References: <53C3C09A.5090707@gmx.net> <14018.1405360899@sandelman.ca> <53C42703.4060806@gmx.net> <8236.1405368736@sandelman.ca> <53C4C082.3020909@sics.se>
To: Ludwig Seitz <ludwig@sics.se>
X-Mailer: Apple Mail (2.1878.6)
Archived-At: http://mailarchive.ietf.org/arch/msg/ace/9wtymw-vl49_NOI7fxGM-miDKWc
Cc: ace@ietf.org
Subject: Re: [Ace] Offline operation of Resource Server
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 15 Jul 2014 12:58:01 -0000

Hi Ludwig:

El 15/07/2014, a las 07:47, Ludwig Seitz <ludwig@sics.se> escribi=F3:

> On 07/14/2014 10:12 PM, Michael Richardson wrote:
>>=20
>> Hannes Tschofenig <hannes.tschofenig@gmx.net> wrote:
>>     > To re-use the Kerberos language, the client gets the TGT. The =
real-time
>>     > interaction I was talking about relates to the interaction =
between the
>>     > resource server and the authorization server.
>>=20
>> During enrollment, the Authorization Server gets a TGT on the =
*resource* server.
>> Given that, it can now issue new tickets to clients that come along =
that wish
>> to access the resource.  The client, during enrollment, asks the =
(possibly
>> federated list of) authorization servers for a resource ticket.
>> (This is why part of network join needs to be in scope for ACE)
>>=20
>> All of the above has to occur online.
>>=20
>> Once the client has the resource ticket, the resource server can =
validate it offline.
>>=20
>=20
>=20
> >>Ludwig, could you please explain this offline requirement a bit =
more?
>=20
> It means exactly the kind of offline validation that Michael described =
above.

[Rafa] I had the following in mind:

The RS is deployed under the domain of a "controller". To ensure the =
controller and the RS are authenticated are authorized they use EAP/AAA =
(so we avoid a rogue controller or a rogue RS). EAP peer is the RS, the =
EAP authenticator is the "controller" and EAP server is placed on the =
AS. We can also think (to simplify) that controller/AS is the same =
entity for now.

>=20
> 1. You need some initial enrollment of AS <-> RS (that could be online =
or offline & manual such as by reading off some QR code with the RSs =
initial key material and feeding that to the AS).

Then, one option is to do online enrollment with EAP/AAA. =20

>=20
> 2. Then you need some online authorization decision step between C and =
AS.

I also think we can use online authorization decision based on EAP/AAA.

>=20
> 3. Then (possibly later) there is some interaction between C and RS, =
that could be offline. Here RS needs to be able to do offline validation =
of the authorization decision from step 2.

That is possible if during the EAP/AAA interactions there is a =
bootstrapping of some short term credential (e.g. Kerberos tickets). For =
example, if we talk in Kerberos terminology, the "controller" could be =
the KDC. Then C could obtain a TGT first and then a ST to access the RS. =
As long as the C has the ST, it can access the RS and the RS can do the =
validation offline.

So, in summary, there could be an online enrollment and online =
authorization decision based on EAP/AAA that allows to bootstrap =
"something" that enables RS and C to have an offline interaction during =
a period of time (e.g. ticket lifetime).

My 0.02 cents.

>=20
>=20
> /Ludwig
>=20
> --=20
> Ludwig Seitz, PhD
> SICS Swedish ICT AB
> Ideon Science Park
> Building Beta 2
> Scheelev=E4gen 17
> SE-223 70 Lund
>=20
> Phone +46(0)70-349 92 51
> http://www.sics.se
>=20
> _______________________________________________
> Ace mailing list
> Ace@ietf.org
> https://www.ietf.org/mailman/listinfo/ace

-------------------------------------------------------
Rafael Marin Lopez, PhD
Dept. Information and Communications Engineering (DIIC)
Faculty of Computer Science-University of Murcia
30100 Murcia - Spain
Telf: +34868888501 Fax: +34868884151 e-mail: rafa@um.es
-------------------------------------------------------





From nobody Tue Jul 15 07:08:35 2014
Return-Path: <Josh.Howlett@ja.net>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 1AF231B2883 for <ace@ietfa.amsl.com>; Tue, 15 Jul 2014 07:08:34 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.9
X-Spam-Level: 
X-Spam-Status: No, score=-1.9 tagged_above=-999 required=5 tests=[BAYES_00=-1.9] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 6_h9GyN7-3co for <ace@ietfa.amsl.com>; Tue, 15 Jul 2014 07:08:32 -0700 (PDT)
Received: from har003676.ukerna.ac.uk (smtp-relay.ukerna.ac.uk [194.82.140.75]) (using TLSv1 with cipher DHE-RSA-CAMELLIA256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 5140F1A03F9 for <ace@ietf.org>; Tue, 15 Jul 2014 07:08:32 -0700 (PDT)
Received: from har003676.ukerna.ac.uk (localhost.localdomain [127.0.0.1]) by localhost (Email Security Appliance) with SMTP id BBA844A6B9E_3C535DDB; Tue, 15 Jul 2014 14:08:29 +0000 (GMT)
Received: from EXC001.atlas.ukerna.ac.uk (exc001.atlas.ukerna.ac.uk [193.62.83.37]) (using TLSv1 with cipher AES128-SHA (128/128 bits)) (Client CN "staffmail.ja.net", Issuer "TERENA SSL CA" (verified OK)) by har003676.ukerna.ac.uk (Sophos Email Appliance) with ESMTPS id 75D594A6B9C_3C535DDF; Tue, 15 Jul 2014 14:08:29 +0000 (GMT)
Received: from EXC001.atlas.ukerna.ac.uk ([193.62.83.37]) by EXC001 ([193.62.83.37]) with mapi id 14.03.0123.003; Tue, 15 Jul 2014 15:08:28 +0100
From: Josh Howlett <Josh.Howlett@ja.net>
To: Rafa Marin Lopez <rafa@um.es>, Ludwig Seitz <ludwig@sics.se>
Thread-Topic: [Ace] Offline operation of Resource Server
Thread-Index: AQHPn1fV6K8ZA6zXCka9YC7ZCL7945ufy96AgAAOToCAABYxAIAAoMsAgAB4LICAACLOAA==
Date: Tue, 15 Jul 2014 14:08:27 +0000
Message-ID: <55DC663C2F4F9F439F23543E0078E8B3A678F9AA@EXC001>
References: <53C3C09A.5090707@gmx.net> <14018.1405360899@sandelman.ca> <53C42703.4060806@gmx.net> <8236.1405368736@sandelman.ca> <53C4C082.3020909@sics.se> <191F7113-E5ED-49A2-AC27-AA886D527FB1@um.es>
In-Reply-To: <191F7113-E5ED-49A2-AC27-AA886D527FB1@um.es>
Accept-Language: en-GB, en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
x-originating-ip: [10.1.11.65]
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
Archived-At: http://mailarchive.ietf.org/arch/msg/ace/r-OWJWnmiK3vXK7CLqemfbvkrDY
Cc: "ace@ietf.org" <ace@ietf.org>
Subject: Re: [Ace] Offline operation of Resource Server
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 15 Jul 2014 14:08:34 -0000

> So, in summary, there could be an online enrollment and online
> authorization decision based on EAP/AAA that allows to bootstrap
> "something" that enables RS and C to have an offline interaction during a
> period of time (e.g. ticket lifetime).

Just by way of example, another "something" that could be bootstrapped by E=
AP/AAA (as an alternative or complement to a Kerberos ticket) could be a ce=
rtificate. There is also running code demonstrating this.

Josh.


Janet(UK) is a trading name of Jisc Collections and Janet Limited, a=20
not-for-profit company which is registered in England under No. 2881024=20
and whose Registered Office is at Lumen House, Library Avenue,
Harwell Oxford, Didcot, Oxfordshire. OX11 0SG. VAT No. 614944238


From nobody Tue Jul 15 08:20:09 2014
Return-Path: <robert.cragie@gridmerge.com>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 9F23D1B28CF for <ace@ietfa.amsl.com>; Tue, 15 Jul 2014 08:19:25 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.9
X-Spam-Level: 
X-Spam-Status: No, score=-1.9 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_NONE=-0.0001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id B-GRSclIS45j for <ace@ietfa.amsl.com>; Tue, 15 Jul 2014 08:18:46 -0700 (PDT)
Received: from mailscan1.extendcp.co.uk (mailscan23.extendcp.co.uk [176.32.226.69]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id BC8BF1B28BA for <ace@ietf.org>; Tue, 15 Jul 2014 08:17:58 -0700 (PDT)
Received: from lb1.hi.local ([10.0.1.197] helo=mailscan2.extendcp.co.uk) by mailscan-g64.hi.local with esmtp (Exim 4.80.1) (envelope-from <robert.cragie@gridmerge.com>) id 1X74UO-0002QV-5Z; Tue, 15 Jul 2014 16:17:56 +0100
Received: from lb1.hi.local ([10.0.1.197] helo=mail41.extendcp.co.uk) by mailscan2.extendcp.co.uk with esmtps (UNKNOWN:DHE-RSA-AES256-GCM-SHA384:256) (Exim 4.80.1) (envelope-from <robert.cragie@gridmerge.com>) id 1X74UL-0006ru-9q; Tue, 15 Jul 2014 16:17:56 +0100
Received: from host86-163-16-160.range86-163.btcentralplus.com ([86.163.16.160] helo=[192.168.0.2]) by mail41.extendcp.com with esmtpsa (TLSv1:DHE-RSA-AES128-SHA:128) (Exim 4.80.1) id 1X74UK-0007lG-2r; Tue, 15 Jul 2014 16:17:52 +0100
Message-ID: <53C5461B.7010707@gridmerge.com>
Date: Tue, 15 Jul 2014 16:17:47 +0100
From: Robert Cragie <robert.cragie@gridmerge.com>
Organization: Gridmerge Ltd.
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:24.0) Gecko/20100101 Thunderbird/24.5.0
MIME-Version: 1.0
To: "Kumar, Sandeep" <sandeep.kumar@philips.com>,  Ludwig Seitz <ludwig@sics.se>, "ace@ietf.org" <ace@ietf.org>
References: <34966E97BE8AD64EAE9D3D6E4DEE36F258177EE3@SZXEMA501-MBS.china.huawei.com> <53C4C5D6.30503@sics.se> <BE6D13F6A4554947952B39008B0DC0153E7D4731@DBXPRD9003MB059.MGDPHG.emi.philips.com>
In-Reply-To: <BE6D13F6A4554947952B39008B0DC0153E7D4731@DBXPRD9003MB059.MGDPHG.emi.philips.com>
Content-Type: multipart/signed; protocol="application/pkcs7-signature"; micalg=sha1; boundary="------------ms060908010206050100080903"
X-Authenticated-As: robert.cragie@gridmerge.com
X-Extend-Src: mailout
Archived-At: http://mailarchive.ietf.org/arch/msg/ace/ZeuZXWxm9u8MGc62CvSgN91ySUU
Subject: Re: [Ace] Context-based Authorization
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
Reply-To: robert.cragie@gridmerge.com
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 15 Jul 2014 15:19:25 -0000
X-List-Received-Date: Tue, 15 Jul 2014 15:19:25 -0000

This is a cryptographically signed message in MIME format.

--------------ms060908010206050100080903
Content-Type: text/plain; charset=ISO-8859-1; format=flowed
Content-Transfer-Encoding: quoted-printable

I think we do need to consider context based authentication and it=20
should be possible to establish the bases for the context without having =

to go into solutions, e.g.

* Time-based
* Identity-based
* Role-based
* etc.

It may sound simple/obvious but access is simply a boolean evaluation of =

an expression, which could be really simple ("true") or more complex=20
("if (ID is X) AND (time is after 2.30pm) AND (time is before 6.30pm)=20
AND (day is Monday)). The tricky bit is actually authenticating the LHSs =

of the components of the boolean expression, whether they come from the=20
accessor (e.g. ID) or the accessee (e.g. time)

Robert

On 15/07/2014 8:29 AM, Kumar, Sandeep wrote:
>
>> -----Original Message-----
>> From: Ace [mailto:ace-bounces@ietf.org] On Behalf Of Ludwig Seitz
>>
>> On 07/15/2014 05:19 AM, Likepeng wrote:
>>> Hi all,
>>>
>>> Personally I am wondering whether or not we should support
>>> context-based authorization indicated in
>>> http://tools.ietf.org/html/draft-seitz-ace-usecases-01.
>>>
>>> For U2.4, do we want to achieve something like this: if time is 9:00 =
~
>>> 18:00, Client A is allowed to turn on a light, but Client B is not al=
lowed?
>> Yes that's one example.
>>
>>> To me, this is purely Resource Server side policy setting and
>>> enforcement. Does it require any information exchange with
>>> Authorization Server? Is it necessary?
>> We are moving away from requirements here and getting into solutions, =
but
>> for the sake of clarification: I don't think this kind of policy shoul=
d be on the
>> RS, it should be maintained and managed by the AS, for the same reason=
s we
>> want all the other authorization policies to be on the AS. The solutio=
n I have
>> in mind are conditional authorization decisions in the style: "You are=

>> permitted to turn on the light, provided it is between 9:00 and 18:00"=
=2E
>>
> [SK] Completely agree with Ludwig. Context-based policies are very rele=
vant in IoT if they need invisibly mesh with our daily lives.
> How to implement it is something we need to discuss during the solution=
 phase. However to me this does not sound like only a
> RS side policy setting, since RS still needs to figure out if it was A =
or B who is allowed within that context. Enforcement could be RS side dep=
ending on the ability of RS to verify context.
>
> regards
> Sandeep
>
> ________________________________
> The information contained in this message may be confidential and legal=
ly protected under applicable law. The message is intended solely for the=
 addressee(s). If you are not the intended recipient, you are hereby noti=
fied that any use, forwarding, dissemination, or reproduction of this mes=
sage is strictly prohibited and may be unlawful. If you are not the inten=
ded recipient, please contact the sender by return e-mail and destroy all=
 copies of the original message.
>
> _______________________________________________
> Ace mailing list
> Ace@ietf.org
> https://www.ietf.org/mailman/listinfo/ace
>



--------------ms060908010206050100080903
Content-Type: application/pkcs7-signature; name="smime.p7s"
Content-Transfer-Encoding: base64
Content-Disposition: attachment; filename="smime.p7s"
Content-Description: S/MIME Cryptographic Signature

MIAGCSqGSIb3DQEHAqCAMIACAQExCzAJBgUrDgMCGgUAMIAGCSqGSIb3DQEHAQAAoIILUDCC
BRowggQCoAMCAQICEG0Z6qcZT2ozIuYiMnqqcd4wDQYJKoZIhvcNAQEFBQAwga4xCzAJBgNV
BAYTAlVTMQswCQYDVQQIEwJVVDEXMBUGA1UEBxMOU2FsdCBMYWtlIENpdHkxHjAcBgNVBAoT
FVRoZSBVU0VSVFJVU1QgTmV0d29yazEhMB8GA1UECxMYaHR0cDovL3d3dy51c2VydHJ1c3Qu
Y29tMTYwNAYDVQQDEy1VVE4tVVNFUkZpcnN0LUNsaWVudCBBdXRoZW50aWNhdGlvbiBhbmQg
RW1haWwwHhcNMTEwNDI4MDAwMDAwWhcNMjAwNTMwMTA0ODM4WjCBkzELMAkGA1UEBhMCR0Ix
GzAZBgNVBAgTEkdyZWF0ZXIgTWFuY2hlc3RlcjEQMA4GA1UEBxMHU2FsZm9yZDEaMBgGA1UE
ChMRQ09NT0RPIENBIExpbWl0ZWQxOTA3BgNVBAMTMENPTU9ETyBDbGllbnQgQXV0aGVudGlj
YXRpb24gYW5kIFNlY3VyZSBFbWFpbCBDQTCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoC
ggEBAJKEhFtLV5jUXi+LpOFAyKNTWF9mZfEyTvefMn1V0HhMVbdClOD5J3EHxcZppLkyxPFA
GpDMJ1Zifxe1cWmu5SAb5MtjXmDKokH2auGj/7jfH0htZUOMKi4rYzh337EXrMLaggLW1DJq
1GdvIBOPXDX65VSAr9hxCh03CgJQU2yVHakQFLSZlVkSMf8JotJM3FLb3uJAAVtIaN3FSrTg
7SQfOq9xXwfjrL8UO7AlcWg99A/WF1hGFYE8aIuLgw9teiFX5jSw2zJ+40rhpVJyZCaRTqWS
D//gsWD9Gm9oUZljjRqLpcxCm5t9ImPTqaD8zp6Q30QZ9FxbNboW86eb/8ECAwEAAaOCAUsw
ggFHMB8GA1UdIwQYMBaAFImCZ33EnSZwAEu0UEh83j2uBG59MB0GA1UdDgQWBBR6E04AdFvG
eGNkJ8Ev4qBbvHnFezAOBgNVHQ8BAf8EBAMCAQYwEgYDVR0TAQH/BAgwBgEB/wIBADARBgNV
HSAECjAIMAYGBFUdIAAwWAYDVR0fBFEwTzBNoEugSYZHaHR0cDovL2NybC51c2VydHJ1c3Qu
Y29tL1VUTi1VU0VSRmlyc3QtQ2xpZW50QXV0aGVudGljYXRpb25hbmRFbWFpbC5jcmwwdAYI
KwYBBQUHAQEEaDBmMD0GCCsGAQUFBzAChjFodHRwOi8vY3J0LnVzZXJ0cnVzdC5jb20vVVRO
QWRkVHJ1c3RDbGllbnRfQ0EuY3J0MCUGCCsGAQUFBzABhhlodHRwOi8vb2NzcC51c2VydHJ1
c3QuY29tMA0GCSqGSIb3DQEBBQUAA4IBAQCF1r54V1VtM39EUv5C1QaoAQOAivsNsv1Kv/av
QUn1G1rF0q0bc24+6SZ85kyYwTAo38v7QjyhJT4KddbQPTmGZtGhm7VNm2+vKGwdr+XqdFqo
2rHA8XV6L566k3nK/uKRHlZ0sviN0+BDchvtj/1gOSBH+4uvOmVIPJg9pSW/ve9g4EnlFsjr
P0OD8ODuDcHTzTNfm9C9YGqzO/761Mk6PB/tm/+bSTO+Qik5g+4zaS6CnUVNqGnagBsePdIa
XXxHmaWbCG0SmYbWXVcHG6cwvktJRLiQfsrReTjrtDP6oDpdJlieYVUYtCHVmdXgQ0BCML7q
peeU0rD+83X5f27nMIIGLjCCBRagAwIBAgIQXDFQ28QtqMuYch5f2nTvZjANBgkqhkiG9w0B
AQUFADCBkzELMAkGA1UEBhMCR0IxGzAZBgNVBAgTEkdyZWF0ZXIgTWFuY2hlc3RlcjEQMA4G
A1UEBxMHU2FsZm9yZDEaMBgGA1UEChMRQ09NT0RPIENBIExpbWl0ZWQxOTA3BgNVBAMTMENP
TU9ETyBDbGllbnQgQXV0aGVudGljYXRpb24gYW5kIFNlY3VyZSBFbWFpbCBDQTAeFw0xMTA5
MDIwMDAwMDBaFw0xNDA5MDEyMzU5NTlaMIIBNzELMAkGA1UEBhMCR0IxEDAOBgNVBBETB1dG
NCA0V0ExFzAVBgNVBAgTDldlc3QgWW9ya3NoaXJlMRIwEAYDVQQHEwlXYWtlZmllbGQxFDAS
BgNVBAkTC0dyYW5nZSBNb29yMR8wHQYDVQQJExY4OSBHcmVlbmZpZWxkIENyZXNjZW50MRcw
FQYDVQQKEw5HcmlkbWVyZ2UgTHRkLjE0MDIGA1UECxMrSXNzdWVkIHRocm91Z2ggR3JpZG1l
cmdlIEx0ZC4gRS1QS0kgTWFuYWdlcjEfMB0GA1UECxMWQ29ycG9yYXRlIFNlY3VyZSBFbWFp
bDEWMBQGA1UEAxMNUm9iZXJ0IENyYWdpZTEqMCgGCSqGSIb3DQEJARYbcm9iZXJ0LmNyYWdp
ZUBncmlkbWVyZ2UuY29tMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEArcThqvLe
WU1Q1ZJmnb+2UQSwOQKWok3A1Mwk582AdvwaAQyBFliPyJ0kXJqtwNBoZvk+3WJr0QA5ZRr+
J0x3sXVpcxadojP2HNzy1gsgDtIGG8ltoU4vmX1A8BTlOIUT+Pg8p/bSruxV0vz0CR8ho2hs
R0Zi5vU+rQKNmbgufbkWhlQnMEYjknemscLQfw1YZz90ta67doNDujFy6+X6I06HpjudgMYx
8bdsNS5xVFFwuBA1eqNQra+xLzhCOeX9PPB/zK68qdNhrni3WPYG9EhSt4Dzk+xIz9hj7wrU
ZIVXDTPsY8qbUSBVpwmzI5lCHPgzurH1OK7WwgpDSsl5pwIDAQABo4IB1TCCAdEwHwYDVR0j
BBgwFoAUehNOAHRbxnhjZCfBL+KgW7x5xXswHQYDVR0OBBYEFBCOXNH+lDm8U9gy3b3bRvrx
vKgrMA4GA1UdDwEB/wQEAwIFoDAMBgNVHRMBAf8EAjAAMB0GA1UdJQQWMBQGCCsGAQUFBwME
BggrBgEFBQcDAjBGBgNVHSAEPzA9MDsGDCsGAQQBsjEBAgEDBTArMCkGCCsGAQUFBwIBFh1o
dHRwczovL3NlY3VyZS5jb21vZG8ubmV0L0NQUzBXBgNVHR8EUDBOMEygSqBIhkZodHRwOi8v
Y3JsLmNvbW9kb2NhLmNvbS9DT01PRE9DbGllbnRBdXRoZW50aWNhdGlvbmFuZFNlY3VyZUVt
YWlsQ0EuY3JsMIGIBggrBgEFBQcBAQR8MHowUgYIKwYBBQUHMAKGRmh0dHA6Ly9jcnQuY29t
b2RvY2EuY29tL0NPTU9ET0NsaWVudEF1dGhlbnRpY2F0aW9uYW5kU2VjdXJlRW1haWxDQS5j
cnQwJAYIKwYBBQUHMAGGGGh0dHA6Ly9vY3NwLmNvbW9kb2NhLmNvbTAmBgNVHREEHzAdgRty
b2JlcnQuY3JhZ2llQGdyaWRtZXJnZS5jb20wDQYJKoZIhvcNAQEFBQADggEBAD6b/O0LkPav
kR4Znoqxg0Ad7M3duDm4uzfrlX4ecgq56Ccdwd+3Tayz7Ewej30woVMmTKkA/NKRaCd0wVM9
8seF/oZjXKO7o1SH27igRnGSWjCoWXsdwJGfZbYnvcIIhhsxJoCPNbeSR7C0PAFDKsP3xrJy
MHMljIJsoRbZu/fnYNyFWh9OXf7fYJOGmKDKAhSabUGfhY7umvU9d/YTqo02Q6YzC7d4zPNG
1a75AuHSEchf6GdKqycG38I5y9jlDaYfXspoS3PlTNCIeZONbOSMZgftnNEVKq+SWytFqyG/
8+dwpm/a12KMex5J8iHwaUKj++2O2rAFNjDDqXpeEYoxggQZMIIEFQIBATCBqDCBkzELMAkG
A1UEBhMCR0IxGzAZBgNVBAgTEkdyZWF0ZXIgTWFuY2hlc3RlcjEQMA4GA1UEBxMHU2FsZm9y
ZDEaMBgGA1UEChMRQ09NT0RPIENBIExpbWl0ZWQxOTA3BgNVBAMTMENPTU9ETyBDbGllbnQg
QXV0aGVudGljYXRpb24gYW5kIFNlY3VyZSBFbWFpbCBDQQIQXDFQ28QtqMuYch5f2nTvZjAJ
BgUrDgMCGgUAoIICRTAYBgkqhkiG9w0BCQMxCwYJKoZIhvcNAQcBMBwGCSqGSIb3DQEJBTEP
Fw0xNDA3MTUxNTE3NDdaMCMGCSqGSIb3DQEJBDEWBBTMH1AdolLAXjSVEhoKKTlPAAXtxDBs
BgkqhkiG9w0BCQ8xXzBdMAsGCWCGSAFlAwQBKjALBglghkgBZQMEAQIwCgYIKoZIhvcNAwcw
DgYIKoZIhvcNAwICAgCAMA0GCCqGSIb3DQMCAgFAMAcGBSsOAwIHMA0GCCqGSIb3DQMCAgEo
MIG5BgkrBgEEAYI3EAQxgaswgagwgZMxCzAJBgNVBAYTAkdCMRswGQYDVQQIExJHcmVhdGVy
IE1hbmNoZXN0ZXIxEDAOBgNVBAcTB1NhbGZvcmQxGjAYBgNVBAoTEUNPTU9ETyBDQSBMaW1p
dGVkMTkwNwYDVQQDEzBDT01PRE8gQ2xpZW50IEF1dGhlbnRpY2F0aW9uIGFuZCBTZWN1cmUg
RW1haWwgQ0ECEFwxUNvELajLmHIeX9p072YwgbsGCyqGSIb3DQEJEAILMYGroIGoMIGTMQsw
CQYDVQQGEwJHQjEbMBkGA1UECBMSR3JlYXRlciBNYW5jaGVzdGVyMRAwDgYDVQQHEwdTYWxm
b3JkMRowGAYDVQQKExFDT01PRE8gQ0EgTGltaXRlZDE5MDcGA1UEAxMwQ09NT0RPIENsaWVu
dCBBdXRoZW50aWNhdGlvbiBhbmQgU2VjdXJlIEVtYWlsIENBAhBcMVDbxC2oy5hyHl/adO9m
MA0GCSqGSIb3DQEBAQUABIIBAFY7KH/fZyHBZrWe10mSuDlw/3LRdhEYdZN4ZmTHDzbqW0cq
3ieTwRrt484oy8TZbw9jnmp9j5Y6GMuy37LvLz41mNi3VolI65miDhZBQys3+aX0cd5uSk13
R836qFOUd4niUJQ69F+kaMfmROYD0iXtKy4fp4M2f3xLwxXobxTYFEpzOWyDtHU1x2j13ghR
DrVE7cXuBxl00bf5MdQeOd+vCo1Yr1p5pRWdaPQVCdnI1D4VW1NcAS3a7OAJdM8UnHuOpdtI
ZYIznLf20FW3WgxB2zRtn6rygBMiQboJ2O1HZuzR3M/D1hz0c9weFeBoLapNKeqOMYaSSi2p
xtOxS7QAAAAAAAA=
--------------ms060908010206050100080903--


From nobody Tue Jul 15 08:28:13 2014
Return-Path: <mcr@sandelman.ca>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 4CD371A04CD for <ace@ietfa.amsl.com>; Tue, 15 Jul 2014 08:27:39 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.542
X-Spam-Level: 
X-Spam-Status: No, score=-2.542 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RP_MATCHES_RCVD=-0.651, SPF_PASS=-0.001, T_TVD_MIME_NO_HEADERS=0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id isSZPvvcxIj7 for <ace@ietfa.amsl.com>; Tue, 15 Jul 2014 08:27:23 -0700 (PDT)
Received: from tuna.sandelman.ca (tuna.sandelman.ca [IPv6:2607:f0b0:f:3:216:3eff:fe7c:d1f3]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 3B5011B2878 for <ace@ietf.org>; Tue, 15 Jul 2014 08:27:17 -0700 (PDT)
Received: from sandelman.ca (obiwan.sandelman.ca [IPv6:2607:f0b0:f:2::247]) by tuna.sandelman.ca (Postfix) with ESMTP id 5A6B720028; Tue, 15 Jul 2014 11:28:29 -0400 (EDT)
Received: by sandelman.ca (Postfix, from userid 179) id F27FE63B0E; Tue, 15 Jul 2014 11:27:14 -0400 (EDT)
Received: from sandelman.ca (localhost [127.0.0.1]) by sandelman.ca (Postfix) with ESMTP id E29C863AED; Tue, 15 Jul 2014 11:27:14 -0400 (EDT)
From: Michael Richardson <mcr+ietf@sandelman.ca>
To: Rafa Marin Lopez <rafa@um.es>
In-Reply-To: <191F7113-E5ED-49A2-AC27-AA886D527FB1@um.es>
References: <53C3C09A.5090707@gmx.net> <14018.1405360899@sandelman.ca> <53C42703.4060806@gmx.net> <8236.1405368736@sandelman.ca> <53C4C082.3020909@sics.se> <191F7113-E5ED-49A2-AC27-AA886D527FB1@um.es>
X-Mailer: MH-E 8.2; nmh 1.3-dev; GNU Emacs 23.4.1
X-Face: $\n1pF)h^`}$H>Hk{L"x@)JS7<%Az}5RyS@k9X%29-lHB$Ti.V>2bi.~ehC0; <'$9xN5Ub# z!G,p`nR&p7Fz@^UXIn156S8.~^@MJ*mMsD7=QFeq%AL4m<nPbLgmtKK-5dC@#:k
MIME-Version: 1.0
Content-Type: multipart/signed; boundary="=-=-="; micalg=pgp-sha1; protocol="application/pgp-signature"
Date: Tue, 15 Jul 2014 11:27:14 -0400
Message-ID: <18172.1405438034@sandelman.ca>
Sender: mcr@sandelman.ca
Archived-At: http://mailarchive.ietf.org/arch/msg/ace/SRp_IKBEeO45HMbB2LPcJ_NmPv4
Cc: Ludwig Seitz <ludwig@sics.se>, ace@ietf.org
Subject: Re: [Ace] Offline operation of Resource Server
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 15 Jul 2014 15:27:39 -0000
X-List-Received-Date: Tue, 15 Jul 2014 15:27:39 -0000

--=-=-=


Rafa Marin Lopez <rafa@um.es> wrote:
    > That is possible if during the EAP/AAA interactions there is a
    > bootstrapping of some short term credential (e.g. Kerberos
    > tickets). For example, if we talk in Kerberos terminology, the

Please don't build in any assumption in your thinking that the resulting
ticket is short term.  Some may wish it; but for many applications we are
talking about tickets that either never expire, or have expirations times
decades in the future.

Josh Howlett <Josh.Howlett@ja.net> wrote:
    >> So, in summary, there could be an online enrollment and online
    >> authorization decision based on EAP/AAA that allows to bootstrap
    >> "something" that enables RS and C to have an offline interaction during a
    >> period of time (e.g. ticket lifetime).

    > Just by way of example, another "something" that could be bootstrapped
    > by EAP/AAA (as an alternative or complement to a Kerberos ticket) could
    > be a certificate. There is also running code demonstrating this.

Yes; exactly.  The certificate could contain Authorization Attributes rather
than identities.  Anyone who hasn't read rfc2692 and rfc2693 lately, should
do so.

Just think of the kerberos-like symmetric key token as being a certificate
that can only be validated by the originator.

--
Michael Richardson <mcr+IETF@sandelman.ca>, Sandelman Software Works
 -= IPv6 IoT consulting =-




--=-=-=
Content-Type: application/pgp-signature

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iQEVAwUBU8VIUICLcPvd0N1lAQLtzAf/ZFqjwvOv8EBRVMado28giAaRkfT1VE3B
IFcBDq4IPxF7U4p7xxVeCmWbMh5vif9Am38TmvdK9x4xSrmblmdI9/NFWECopq8Z
nVcVZl3zkF/Y9gClv2UWLfjlg4uYLvWNML5ZETGZO9j0ad9Zy+5qhE1VuWC0Ac1G
0Yq9rLMOII+Ba+9DEKSSXV011UNHYQY2SgDSG40fAfY4HROisN77GhmU56X2f3Y1
nThz0YR15M80Dhn2Vidjyn4oEs/84Dqh3NDqw3jsTir3Jj9Cl2MJ3j00XhjIZ+mX
EFNW6418B1vJGPxKXV9zkmd41Npd7QAqdVlrJ+Tc0K1jbHhOVctnxw==
=j75b
-----END PGP SIGNATURE-----
--=-=-=--


From nobody Tue Jul 15 08:30:50 2014
Return-Path: <mcr@sandelman.ca>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 8BBD71B28BD for <ace@ietfa.amsl.com>; Tue, 15 Jul 2014 08:30:31 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.542
X-Spam-Level: 
X-Spam-Status: No, score=-2.542 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RP_MATCHES_RCVD=-0.651, SPF_PASS=-0.001, T_TVD_MIME_NO_HEADERS=0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id G4adMPKnnsuL for <ace@ietfa.amsl.com>; Tue, 15 Jul 2014 08:30:18 -0700 (PDT)
Received: from tuna.sandelman.ca (tuna.sandelman.ca [209.87.249.19]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id E1B6B1A0A8A for <ace@ietf.org>; Tue, 15 Jul 2014 08:29:57 -0700 (PDT)
Received: from sandelman.ca (obiwan.sandelman.ca [IPv6:2607:f0b0:f:2::247]) by tuna.sandelman.ca (Postfix) with ESMTP id 3609B20029; Tue, 15 Jul 2014 11:31:11 -0400 (EDT)
Received: by sandelman.ca (Postfix, from userid 179) id C4CA963B0E; Tue, 15 Jul 2014 11:29:56 -0400 (EDT)
Received: from sandelman.ca (localhost [127.0.0.1]) by sandelman.ca (Postfix) with ESMTP id B207163AED; Tue, 15 Jul 2014 11:29:56 -0400 (EDT)
From: Michael Richardson <mcr+ietf@sandelman.ca>
To: Hannes Tschofenig <hannes.tschofenig@gmx.net>
In-Reply-To: <53C4E7DA.2020003@gmx.net>
References: <53C3C09A.5090707@gmx.net> <14018.1405360899@sandelman.ca> <53C42703.4060806@gmx.net> <8236.1405368736@sandelman.ca> <53C4E7DA.2020003@gmx.net>
X-Mailer: MH-E 8.2; nmh 1.3-dev; GNU Emacs 23.4.1
X-Face: $\n1pF)h^`}$H>Hk{L"x@)JS7<%Az}5RyS@k9X%29-lHB$Ti.V>2bi.~ehC0; <'$9xN5Ub# z!G,p`nR&p7Fz@^UXIn156S8.~^@MJ*mMsD7=QFeq%AL4m<nPbLgmtKK-5dC@#:k
MIME-Version: 1.0
Content-Type: multipart/signed; boundary="=-=-="; micalg=pgp-sha1; protocol="application/pgp-signature"
Date: Tue, 15 Jul 2014 11:29:56 -0400
Message-ID: <18716.1405438196@sandelman.ca>
Sender: mcr@sandelman.ca
Archived-At: http://mailarchive.ietf.org/arch/msg/ace/0zS3fd2SQU0tlH9V_hm42POsXrk
Cc: "ace@ietf.org" <ace@ietf.org>
Subject: Re: [Ace] Offline operation of Resource Server
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 15 Jul 2014 15:30:32 -0000

--=-=-=


Hannes Tschofenig <hannes.tschofenig@gmx.net> wrote:
    > This is pretty much reflected in the list of questions I asked to the
    > group, namely:

    > "
    > Are there requirements/use cases that allow anything other than the
    > OAuth/Kerberos design pattern?
    > "

I wasn't arguing with you, but with others, I guess. Sorry.
I think that your question is not well stated.

"allow anything other" -- has a bunch of implicit negations, I'm not actually
sure how many, to be honest.

There are use cases that can only be satisified by the OAuth/Kerberos design
pattern.

--
Michael Richardson <mcr+IETF@sandelman.ca>, Sandelman Software Works
 -= IPv6 IoT consulting =-




--=-=-=
Content-Type: application/pgp-signature

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iQEVAwUBU8VI74CLcPvd0N1lAQKQvAf+MoDljgT5DemRJWj6FI2pG0Z4eRHcaT8D
NHr3I99123KCiq8Jru61lxEu3HDjX3lmCYhNRsPSjhYPqOFD0Lkr8me6+8D/6x5r
BCz3UbcD3fEKpreeKdaLza0UroMv1nqrJT/zdpA7qliaZow7qjCin+VDPxEwe5RG
KvX04LS5xlKYjbGbP/sjlBMd77V0RGltbyLBz3vcely/XRqhgzT5E4fXfoiby4f5
7IC73lsFNNbePNWwbXkSO3Wz7bFLIFoT77s2MfP0tqHTQ4Wlj7t8FssbwJDPOx+1
hiqAmckjB8pyLmQPtqUA2kXFCA1BMp0JtCDZELdVDpF13r3daiJCBw==
=GlkA
-----END PGP SIGNATURE-----
--=-=-=--


From nobody Tue Jul 15 08:36:31 2014
Return-Path: <rafa@um.es>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 018E31B28BA for <ace@ietfa.amsl.com>; Tue, 15 Jul 2014 08:36:31 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.852
X-Spam-Level: 
X-Spam-Status: No, score=-4.852 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, RP_MATCHES_RCVD=-0.651, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id PJVC5XFkTW5M for <ace@ietfa.amsl.com>; Tue, 15 Jul 2014 08:36:28 -0700 (PDT)
Received: from xenon24.um.es (xenon24.um.es [155.54.212.164]) by ietfa.amsl.com (Postfix) with ESMTP id 1229E1B2883 for <ace@ietf.org>; Tue, 15 Jul 2014 08:36:28 -0700 (PDT)
Received: from localhost (localhost [127.0.0.1]) by xenon24.um.es (Postfix) with ESMTP id B167FBC58; Tue, 15 Jul 2014 17:36:26 +0200 (CEST)
X-Virus-Scanned: by antispam in UMU at xenon24.um.es
Received: from xenon24.um.es ([127.0.0.1]) by localhost (xenon24.um.es [127.0.0.1]) (amavisd-new, port 10024) with LMTP id HrMzTkLfjMiF; Tue, 15 Jul 2014 17:36:26 +0200 (CEST)
Received: from [192.168.1.66] (214.Red-83-42-243.dynamicIP.rima-tde.net [83.42.243.214]) (using TLSv1 with cipher ECDHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) (Authenticated sender: rafa) by xenon24.um.es (Postfix) with ESMTPSA id 75124EDC; Tue, 15 Jul 2014 17:36:24 +0200 (CEST)
Content-Type: text/plain; charset=iso-8859-1
Mime-Version: 1.0 (Mac OS X Mail 7.3 \(1878.6\))
From: Rafa Marin Lopez <rafa@um.es>
In-Reply-To: <18172.1405438034@sandelman.ca>
Date: Tue, 15 Jul 2014 17:36:22 +0200
Content-Transfer-Encoding: quoted-printable
Message-Id: <1D537FA0-1FCF-42D0-B5C1-FB45E00E6332@um.es>
References: <53C3C09A.5090707@gmx.net> <14018.1405360899@sandelman.ca> <53C42703.4060806@gmx.net> <8236.1405368736@sandelman.ca> <53C4C082.3020909@sics.se> <191F7113-E5ED-49A2-AC27-AA886D527FB1@um.es> <18172.1405438034@sandelman.ca>
To: Michael Richardson <mcr+ietf@sandelman.ca>
X-Mailer: Apple Mail (2.1878.6)
Archived-At: http://mailarchive.ietf.org/arch/msg/ace/flnAc-mXgcQ4MxTitUsNsiFqt0Y
Cc: ace@ietf.org
Subject: Re: [Ace] Offline operation of Resource Server
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 15 Jul 2014 15:36:31 -0000

Hi Michael:

El 15/07/2014, a las 17:27, Michael Richardson <mcr+ietf@sandelman.ca> =
escribi=F3:

>=20
> Rafa Marin Lopez <rafa@um.es> wrote:
>> That is possible if during the EAP/AAA interactions there is a
>> bootstrapping of some short term credential (e.g. Kerberos
>> tickets). For example, if we talk in Kerberos terminology, the
>=20
> Please don't build in any assumption in your thinking that the =
resulting
> ticket is short term.  Some may wish it; but for many applications we =
are
> talking about tickets that either never expire, or have expirations =
times
> decades in the future.

I agree. I was talking about a typical case in Kerberos. But I do not =
have problem with having long-term credentials bootstrapped. That should =
be feasible. Nevertheless, please take into account that the =
bootstrapping phase might be used only once for decades (so the source =
code developed for it).=20

>=20
> Josh Howlett <Josh.Howlett@ja.net> wrote:
>>> So, in summary, there could be an online enrollment and online
>>> authorization decision based on EAP/AAA that allows to bootstrap
>>> "something" that enables RS and C to have an offline interaction =
during a
>>> period of time (e.g. ticket lifetime).
>=20
>> Just by way of example, another "something" that could be =
bootstrapped
>> by EAP/AAA (as an alternative or complement to a Kerberos ticket) =
could
>> be a certificate. There is also running code demonstrating this.
>=20
> Yes; exactly.  The certificate could contain Authorization Attributes =
rather
> than identities.  Anyone who hasn't read rfc2692 and rfc2693 lately, =
should
> do so.
>=20
> Just think of the kerberos-like symmetric key token as being a =
certificate
> that can only be validated by the originator.

In fact, we have also considered the case of bootstrapping a certificate =
after an EAP/AAA authentication. So I have no problem at all with that. =
So +1 to that.

Best Regards.

>=20
> --
> Michael Richardson <mcr+IETF@sandelman.ca>, Sandelman Software Works
> -=3D IPv6 IoT consulting =3D-
>=20
>=20
>=20

-------------------------------------------------------
Rafael Marin Lopez, PhD
Dept. Information and Communications Engineering (DIIC)
Faculty of Computer Science-University of Murcia
30100 Murcia - Spain
Telf: +34868888501 Fax: +34868884151 e-mail: rafa@um.es
-------------------------------------------------------





From nobody Tue Jul 15 11:16:55 2014
Return-Path: <mcr@sandelman.ca>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 4412F1A0AE8 for <ace@ietfa.amsl.com>; Tue, 15 Jul 2014 11:16:54 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.542
X-Spam-Level: 
X-Spam-Status: No, score=-2.542 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RP_MATCHES_RCVD=-0.651, SPF_PASS=-0.001, T_TVD_MIME_NO_HEADERS=0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Bub0IYfA6lrN for <ace@ietfa.amsl.com>; Tue, 15 Jul 2014 11:16:52 -0700 (PDT)
Received: from tuna.sandelman.ca (tuna.sandelman.ca [209.87.249.19]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id A2A0D1A0AD9 for <ace@ietf.org>; Tue, 15 Jul 2014 11:16:52 -0700 (PDT)
Received: from sandelman.ca (obiwan.sandelman.ca [209.87.249.21]) by tuna.sandelman.ca (Postfix) with ESMTP id 9F37620029; Tue, 15 Jul 2014 14:18:05 -0400 (EDT)
Received: by sandelman.ca (Postfix, from userid 179) id CE9BC63B0E; Tue, 15 Jul 2014 14:16:50 -0400 (EDT)
Received: from sandelman.ca (localhost [127.0.0.1]) by sandelman.ca (Postfix) with ESMTP id B4B7D63AED; Tue, 15 Jul 2014 14:16:50 -0400 (EDT)
From: Michael Richardson <mcr+ietf@sandelman.ca>
To: Hannes Tschofenig <hannes.tschofenig@gmx.net>
In-Reply-To: <53BFAEA8.3090407@gmx.net>
References: <53BCF608.5010606@gmx.net> <27297.1404914953@sandelman.ca> <53BFAEA8.3090407@gmx.net>
X-Mailer: MH-E 8.2; nmh 1.3-dev; GNU Emacs 23.4.1
X-Face: $\n1pF)h^`}$H>Hk{L"x@)JS7<%Az}5RyS@k9X%29-lHB$Ti.V>2bi.~ehC0; <'$9xN5Ub# z!G,p`nR&p7Fz@^UXIn156S8.~^@MJ*mMsD7=QFeq%AL4m<nPbLgmtKK-5dC@#:k
MIME-Version: 1.0
Content-Type: multipart/signed; boundary="=-=-="; micalg=pgp-sha1; protocol="application/pgp-signature"
Date: Tue, 15 Jul 2014 14:16:50 -0400
Message-ID: <21816.1405448210@sandelman.ca>
Sender: mcr@sandelman.ca
Archived-At: http://mailarchive.ietf.org/arch/msg/ace/9nBh9v0FaEJZJZ5ywwoF_EuP7cM
Cc: "ace@ietf.org" <ace@ietf.org>
Subject: Re: [Ace] Questions for the IETF#90 Meeting
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 15 Jul 2014 18:16:54 -0000

--=-=-=


Hannes Tschofenig <hannes.tschofenig@gmx.net> wrote:
    > One minor remark on the Kerberos cross-realm authentication.

    > My understanding of the challenge with deployments (from discussions
    > with the Kerberos folks) is that there have to be business reasons for
    > deploying cross-realm authentication. These business reasons are not
    > always there and they require a considerable amount of effort since
    > business agreements (including legal aspects) do not necessarily scale
    > in the same way as technology could do.

This is a fair statement;  but I think that there are sufficient
technological hurdles that only enterprises with legal departments even
consider it :-)

    > This is also a painful lesson the original OpenID guys learned (which is
    > why it is dead now). They approached the problem of federations in a
    > technical way and failed to understand that federations are 95%
    > business/legal constructs and only 5% technology.

If possible, it might be good to understand if the technology was simply
appeared too powerful (i.e. too dangerous), and if there is something we can
do.  Is there a grey beard from the original OpenID space that might be able
to explain more?

I think that it is reasonable for my neighbour to want to give me permission
to turn *some* things on/off at their house when they are away.
I can construct industrial scenarios easily, and it seems that the container
situation is an ideal use case to consider.

--
Michael Richardson <mcr+IETF@sandelman.ca>, Sandelman Software Works
 -= IPv6 IoT consulting =-




--=-=-=
Content-Type: application/pgp-signature

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iQEVAwUBU8VwEICLcPvd0N1lAQJ2KwgAoY17oWlFMuaQKtBENLq+jsYf9q0TQsoz
Kopd+LUO3uK8zrIJGGnkLqyrusiVFDbaRIxUY1WaG8GPMMyWbjXZpHv9WwYEmFkl
ebtl6Pkp0XFYECewxQcxcxWJnA6jpedD/xi6F22NdbaVm0rNEEp2Uztw14Umu3PR
egr5WA5sWYSm1SpiLWpqwf/Jojhx7dbVWaSu5NZX3Wyj0o0BZzFjSOgpN2bPX3+y
I8PkaBdqOVn0sz0aBB5hg+JEkrlOJNmZDTncS4/CaUbhPHaSOaQ+QtC8tJ3Gfotk
PPzk9PNOQ5E0MOHezGDtTOWzur+YpTapEL8ehyELdt7PfXm6wkxnyA==
=9XxV
-----END PGP SIGNATURE-----
--=-=-=--


From nobody Wed Jul 16 01:34:52 2014
Return-Path: <ludwig@sics.se>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id EC3511B2839 for <ace@ietfa.amsl.com>; Wed, 16 Jul 2014 01:34:48 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.601
X-Spam-Level: 
X-Spam-Status: No, score=-2.601 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HELO_EQ_SE=0.35, MIME_8BIT_HEADER=0.3, RCVD_IN_DNSWL_LOW=-0.7, RP_MATCHES_RCVD=-0.651] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id JkUdfUBLBQA6 for <ace@ietfa.amsl.com>; Wed, 16 Jul 2014 01:34:45 -0700 (PDT)
Received: from outbox.sics.se (outbox.sics.se [193.10.64.137]) by ietfa.amsl.com (Postfix) with ESMTP id 130CA1B2AD9 for <ace@ietf.org>; Wed, 16 Jul 2014 01:34:45 -0700 (PDT)
Received: from e-mailfilter01.sunet.se (e-mailfilter01.sunet.se [192.36.171.201]) by outbox.sics.se (Postfix) with ESMTPS id E3FF111B7; Wed, 16 Jul 2014 10:34:42 +0200 (CEST)
Received: from letter.sics.se (letter.sics.se [193.10.64.6]) by e-mailfilter01.sunet.se (8.14.4/8.14.4/Debian-4) with ESMTP id s6G8Ygvk014488; Wed, 16 Jul 2014 10:34:42 +0200
Received: from [192.168.0.108] (unknown [85.235.11.178]) (Authenticated sender: ludwig@sics.se) by letter.sics.se (Postfix) with ESMTPSA id A2E9340116; Wed, 16 Jul 2014 10:34:42 +0200 (CEST)
Message-ID: <53C63900.2070908@sics.se>
Date: Wed, 16 Jul 2014 10:34:08 +0200
From: Ludwig Seitz <ludwig@sics.se>
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:24.0) Gecko/20100101 Thunderbird/24.6.0
MIME-Version: 1.0
To: =?windows-1252?Q?Erik_Wahlstr=F6m?= <erik.wahlstrom@nexusgroup.com>, "robert.cragie@gridmerge.com" <robert.cragie@gridmerge.com>
References: <34966E97BE8AD64EAE9D3D6E4DEE36F258177EE3@SZXEMA501-MBS.china.huawei.com> <53C4C5D6.30503@sics.se> <BE6D13F6A4554947952B39008B0DC0153E7D4731@DBXPRD9003MB059.MGDPHG.emi.philips.com> <53C5461B.7010707@gridmerge.com> <B6F75277-F8E2-4DD9-ACAC-D0DE8E17F3F7@nexusgroup.com>
In-Reply-To: <B6F75277-F8E2-4DD9-ACAC-D0DE8E17F3F7@nexusgroup.com>
Content-Type: multipart/signed; protocol="application/pkcs7-signature"; micalg=sha1; boundary="------------ms040203020803080909000500"
X-Bayes-Prob: 0.0001 (Score 0, tokens from: outbound, outbound-sics-se:default, sics-se:default, base:default, @@RPTN)
X-p0f-Info: os=Solaris 10, link=Ethernet or modem
X-CanIt-Geo: =?UTF-8?Q?ip=3D85.235.11.178; _country=3DSE; _region=3DSk=C3=A5ne; _city=3DLund; _latitude=3D55.7000; _longitude=3D13.1833; _http://maps.google.com/maps=3Fq=3D55.7000,13.1833&z=3D6?=
X-CanItPRO-Stream: outbound-sics-se:outbound (inherits from outbound-sics-se:default, sics-se:default, base:default)
X-Canit-Stats-ID: 09MqUyGOj - f2f6f3a70add - 20140716
X-Antispam-Training-Forget: https://canit.sunet.se/canit/b.php?i=09MqUyGOj&m=f2f6f3a70add&t=20140716&c=f
X-Antispam-Training-Nonspam: https://canit.sunet.se/canit/b.php?i=09MqUyGOj&m=f2f6f3a70add&t=20140716&c=n
X-Antispam-Training-Spam: https://canit.sunet.se/canit/b.php?i=09MqUyGOj&m=f2f6f3a70add&t=20140716&c=s
X-CanIt-Archive-Cluster: PfMRe/vJWMiXwM2YIH5BVExnUnw
X-Scanned-By: CanIt (www . roaringpenguin . com) on 192.36.171.201
Archived-At: http://mailarchive.ietf.org/arch/msg/ace/pk9flzFFW8JXWmJIaQi8xYS3dks
Cc: "Kumar, Sandeep" <sandeep.kumar@philips.com>, "ace@ietf.org" <ace@ietf.org>
Subject: Re: [Ace] Context-based Authorization
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 16 Jul 2014 08:34:49 -0000

This is a cryptographically signed message in MIME format.

--------------ms040203020803080909000500
Content-Type: text/plain; charset=windows-1252; format=flowed
Content-Transfer-Encoding: quoted-printable

On 07/15/2014 06:10 PM, Erik Wahlstr=F6m wrote:
> Consider it? Sure, absolutely. But building it into the protocol I=92m =
not that sure of. It=92s a rather tricky thing and a slippery slope. Isn=92=
t it better to let the AS decide for each request by using inspection end=
points
(or something like it depending on what solutions and technologies we=20
will end up working with). The RS asks the AS for validity of a token=20
within a specific context.
>

That wouldn't work in use cases were the RS has intermittent connectivity=
=2E

/Ludwig


--=20
Ludwig Seitz, PhD
SICS Swedish ICT AB
Ideon Science Park
Building Beta 2
Scheelev=E4gen 17
SE-223 70 Lund

Phone +46(0)70-349 92 51
http://www.sics.se


--------------ms040203020803080909000500
Content-Type: application/pkcs7-signature; name="smime.p7s"
Content-Transfer-Encoding: base64
Content-Disposition: attachment; filename="smime.p7s"
Content-Description: S/MIME Cryptographic Signature

MIAGCSqGSIb3DQEHAqCAMIACAQExCzAJBgUrDgMCGgUAMIAGCSqGSIb3DQEHAQAAoIIMVDCC
BhgwggUAoAMCAQICAwiRTjANBgkqhkiG9w0BAQsFADCBjDELMAkGA1UEBhMCSUwxFjAUBgNV
BAoTDVN0YXJ0Q29tIEx0ZC4xKzApBgNVBAsTIlNlY3VyZSBEaWdpdGFsIENlcnRpZmljYXRl
IFNpZ25pbmcxODA2BgNVBAMTL1N0YXJ0Q29tIENsYXNzIDEgUHJpbWFyeSBJbnRlcm1lZGlh
dGUgQ2xpZW50IENBMB4XDTE0MDEwNzA3MjgzNVoXDTE1MDEwNzEyNTgyMlowODEXMBUGA1UE
AwwObHVkd2lnQHNpY3Muc2UxHTAbBgkqhkiG9w0BCQEWDmx1ZHdpZ0BzaWNzLnNlMIIBIjAN
BgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAnLm1tc30QxHa9wtdVjC3NgxjLJicnccm0HD+
1X16kPMKGvwps8F1oDhYn7jXIe46p1AuJMzLK0GIioE4JwxCFGdvpz7cg2xyTyrdBVUzSqez
Dfqt4FOJq6hrdrIMS8MHEzl7Jk02gv9cTn/pHQvDpkiThRpbSLU5mlMqtEQ8gDQY5YyBX0Mv
5qculV08I2JU8HEeTt1oeqhvBImgQfOVYMDatHlWHUVVrmYd6iIo+cuiUGd5kiA0XuaLYX0E
oCoao/z5Wg9U0sQlx0hl4r96Q+NdoZZ1prfts3qtyBzJ2hu135aikigzJ6sueWHv/jbISUek
tOMm0xkx1GOqqWtEAwIDAQABo4IC1DCCAtAwCQYDVR0TBAIwADALBgNVHQ8EBAMCBLAwHQYD
VR0lBBYwFAYIKwYBBQUHAwIGCCsGAQUFBwMEMB0GA1UdDgQWBBRZmjjBh8N3klra+mVQgC00
pl68ZTAfBgNVHSMEGDAWgBRTcu2SnODaywFcfH6WNU7y1LhRgjAZBgNVHREEEjAQgQ5sdWR3
aWdAc2ljcy5zZTCCAUwGA1UdIASCAUMwggE/MIIBOwYLKwYBBAGBtTcBAgMwggEqMC4GCCsG
AQUFBwIBFiJodHRwOi8vd3d3LnN0YXJ0c3NsLmNvbS9wb2xpY3kucGRmMIH3BggrBgEFBQcC
AjCB6jAnFiBTdGFydENvbSBDZXJ0aWZpY2F0aW9uIEF1dGhvcml0eTADAgEBGoG+VGhpcyBj
ZXJ0aWZpY2F0ZSB3YXMgaXNzdWVkIGFjY29yZGluZyB0byB0aGUgQ2xhc3MgMSBWYWxpZGF0
aW9uIHJlcXVpcmVtZW50cyBvZiB0aGUgU3RhcnRDb20gQ0EgcG9saWN5LCByZWxpYW5jZSBv
bmx5IGZvciB0aGUgaW50ZW5kZWQgcHVycG9zZSBpbiBjb21wbGlhbmNlIG9mIHRoZSByZWx5
aW5nIHBhcnR5IG9ibGlnYXRpb25zLjA2BgNVHR8ELzAtMCugKaAnhiVodHRwOi8vY3JsLnN0
YXJ0c3NsLmNvbS9jcnR1MS1jcmwuY3JsMIGOBggrBgEFBQcBAQSBgTB/MDkGCCsGAQUFBzAB
hi1odHRwOi8vb2NzcC5zdGFydHNzbC5jb20vc3ViL2NsYXNzMS9jbGllbnQvY2EwQgYIKwYB
BQUHMAKGNmh0dHA6Ly9haWEuc3RhcnRzc2wuY29tL2NlcnRzL3N1Yi5jbGFzczEuY2xpZW50
LmNhLmNydDAjBgNVHRIEHDAahhhodHRwOi8vd3d3LnN0YXJ0c3NsLmNvbS8wDQYJKoZIhvcN
AQELBQADggEBAHqEYmtWr83S+iLXE97KBnHJZiMr6PMuLKxmh0o6UJJwKgf+KTP2czxRnPSI
+whuqfQZdmz6g3A2K8AooMU0RXrzncnX1c4826APdnXkRxnGQxtZXI1wuhPn4z7iDKZ6ij9u
K5Pfn10JL/ERDig2qJQbqvhtIAx0RY7y7r+hLMvgXVq9mf3WRJYmGQeFW+N9t5Z1eEwG4m9R
KAZm0fnfeDn/Ai4kmxTckBH7dZwW2lTtwQqQ4su+PGCJ0e9ndBLpvTqaYGSAl+L7PO7vxPhS
/cS67Xa6BtnYJLTr3MaGXaN+CEUFSfwQHa9DKcAqh3kldErI3kCvnot0CigBl4aILOEwggY0
MIIEHKADAgECAgEeMA0GCSqGSIb3DQEBBQUAMH0xCzAJBgNVBAYTAklMMRYwFAYDVQQKEw1T
dGFydENvbSBMdGQuMSswKQYDVQQLEyJTZWN1cmUgRGlnaXRhbCBDZXJ0aWZpY2F0ZSBTaWdu
aW5nMSkwJwYDVQQDEyBTdGFydENvbSBDZXJ0aWZpY2F0aW9uIEF1dGhvcml0eTAeFw0wNzEw
MjQyMTAxNTVaFw0xNzEwMjQyMTAxNTVaMIGMMQswCQYDVQQGEwJJTDEWMBQGA1UEChMNU3Rh
cnRDb20gTHRkLjErMCkGA1UECxMiU2VjdXJlIERpZ2l0YWwgQ2VydGlmaWNhdGUgU2lnbmlu
ZzE4MDYGA1UEAxMvU3RhcnRDb20gQ2xhc3MgMSBQcmltYXJ5IEludGVybWVkaWF0ZSBDbGll
bnQgQ0EwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDHCYPMzi3YGrEppC4Tq5a+
ijKDjKaIQZZVR63UbxIP6uq/I0fhCu+cQhoUfE6ERKKnu8zPf1Jwuk0tsvVCk6U9b+0UjM0d
Lep3ZdE1gblK/1FwYT5Pipsu2yOMluLqwvsuz9/9f1+1PKHG/FaR/wpbfuIqu54qzHDYeqiU
fsYzoVflR80DAC7hmJ+SmZnNTWyUGHJbBpA8Q89lGxahNvuryGaC/o2/ceD2uYDX9U8Eg5Dp
IpGQdcbQeGarV04WgAUjjXX5r/2dabmtxWMZwhZna//jdiSyrrSMTGKkDiXm6/3/4ebfeZuC
YKzN2P8O2F/Xe2AC/Y7zeEsnR7FOp+uXAgMBAAGjggGtMIIBqTAPBgNVHRMBAf8EBTADAQH/
MA4GA1UdDwEB/wQEAwIBBjAdBgNVHQ4EFgQUU3Ltkpzg2ssBXHx+ljVO8tS4UYIwHwYDVR0j
BBgwFoAUTgvvGqRAW6UXaYcwyjRoQ9BBrvIwZgYIKwYBBQUHAQEEWjBYMCcGCCsGAQUFBzAB
hhtodHRwOi8vb2NzcC5zdGFydHNzbC5jb20vY2EwLQYIKwYBBQUHMAKGIWh0dHA6Ly93d3cu
c3RhcnRzc2wuY29tL3Nmc2NhLmNydDBbBgNVHR8EVDBSMCegJaAjhiFodHRwOi8vd3d3LnN0
YXJ0c3NsLmNvbS9zZnNjYS5jcmwwJ6AloCOGIWh0dHA6Ly9jcmwuc3RhcnRzc2wuY29tL3Nm
c2NhLmNybDCBgAYDVR0gBHkwdzB1BgsrBgEEAYG1NwECATBmMC4GCCsGAQUFBwIBFiJodHRw
Oi8vd3d3LnN0YXJ0c3NsLmNvbS9wb2xpY3kucGRmMDQGCCsGAQUFBwIBFihodHRwOi8vd3d3
LnN0YXJ0c3NsLmNvbS9pbnRlcm1lZGlhdGUucGRmMA0GCSqGSIb3DQEBBQUAA4ICAQAKgwh9
eKssBly4Y4xerhy5I3dNoXHYfYa8PlVLL/qtXnkFgdtY1o95CfegFJTwqBBmf8pyTUnFsukD
FUI22zF5bVHzuJ+GxhnSqN2sD1qetbYwBYK2iyYA5Pg7Er1A+hKMIzEzcduRkIMmCeUTyMyi
kfbUFvIBivtvkR8ZFAk22BZy+pJfAoedO61HTz4qSfQoCRcLN5A0t4DkuVhTMXIzuQ8Cnykh
ExD6x4e6ebIbrjZLb7L+ocR0y4YjCl/Pd4MXU91y0vTipgr/O75CDUHDRHCCKBVmz/Rzkc/b
970MEeHt5LC3NiWTgBSvrLEuVzBKM586YoRD9Dy3OHQgWI270g+5MYA8GfgI/EPT5G7xPbCD
z+zjdH89PeR3U4So4lSXur6H6vp+m9TQXPF3a0LwZrp8MQ+Z77U1uL7TelWO5lApsbAonrqA
SfTpaprFVkL4nyGH+NHST2ZJPWIBk81i6Vw0ny0qZW2Niy/QvVNKbb43A43ny076khXO7cNb
BIRdJ/6qQNq9Bqb5C0Q5nEsFcj75oxQRqlKf6TcvGbjxkJh8BYtv9ePsXklAxtm8J7GCUBth
HSQgepbkOexhJ0wP8imUkyiPHQ0GvEnd83129fZjoEhdGwXV27ioRKbj/cIq7JRXun0NbeY+
UdMYu9jGfIpDLtUUGSgsg2zMGs5R4jGCA90wggPZAgEBMIGUMIGMMQswCQYDVQQGEwJJTDEW
MBQGA1UEChMNU3RhcnRDb20gTHRkLjErMCkGA1UECxMiU2VjdXJlIERpZ2l0YWwgQ2VydGlm
aWNhdGUgU2lnbmluZzE4MDYGA1UEAxMvU3RhcnRDb20gQ2xhc3MgMSBQcmltYXJ5IEludGVy
bWVkaWF0ZSBDbGllbnQgQ0ECAwiRTjAJBgUrDgMCGgUAoIICHTAYBgkqhkiG9w0BCQMxCwYJ
KoZIhvcNAQcBMBwGCSqGSIb3DQEJBTEPFw0xNDA3MTYwODM0MDhaMCMGCSqGSIb3DQEJBDEW
BBSaBLHkEwPvL5h2JD4lInoWerWy/DBsBgkqhkiG9w0BCQ8xXzBdMAsGCWCGSAFlAwQBKjAL
BglghkgBZQMEAQIwCgYIKoZIhvcNAwcwDgYIKoZIhvcNAwICAgCAMA0GCCqGSIb3DQMCAgFA
MAcGBSsOAwIHMA0GCCqGSIb3DQMCAgEoMIGlBgkrBgEEAYI3EAQxgZcwgZQwgYwxCzAJBgNV
BAYTAklMMRYwFAYDVQQKEw1TdGFydENvbSBMdGQuMSswKQYDVQQLEyJTZWN1cmUgRGlnaXRh
bCBDZXJ0aWZpY2F0ZSBTaWduaW5nMTgwNgYDVQQDEy9TdGFydENvbSBDbGFzcyAxIFByaW1h
cnkgSW50ZXJtZWRpYXRlIENsaWVudCBDQQIDCJFOMIGnBgsqhkiG9w0BCRACCzGBl6CBlDCB
jDELMAkGA1UEBhMCSUwxFjAUBgNVBAoTDVN0YXJ0Q29tIEx0ZC4xKzApBgNVBAsTIlNlY3Vy
ZSBEaWdpdGFsIENlcnRpZmljYXRlIFNpZ25pbmcxODA2BgNVBAMTL1N0YXJ0Q29tIENsYXNz
IDEgUHJpbWFyeSBJbnRlcm1lZGlhdGUgQ2xpZW50IENBAgMIkU4wDQYJKoZIhvcNAQEBBQAE
ggEAfO3TAhOzyH117y5YdUoHwK4kFNz6KZy1AORD+9GowE81PWGbdOvdPCuDuVWuor4z8DlA
MVSHXapXzGVwZLFLGRydSQ6Gle8tmDncqDf6MdE88td8rl8bl/BR8Xl+Hk64Wu3Wkx0aZmXr
SBJQ/GcxRDFsa9+ZVB59xa8s1zhsmQ7qQW+EmR29PuuJj+gdkawIo/Mo9DZzCsPxkABgEX+L
P/bbGw0phKiNkgmAt86ZHtxqJKKglFPIjoi3TAHCBcr3ltMo5CbWL3sgxph375kX6fVQLLrl
Y700sHK9iEJfiHuLhR2ve9zi3prEo0z2NiXKi4vSDDMxMl4qvOBTAFBBfAAAAAAAAA==
--------------ms040203020803080909000500--


From nobody Wed Jul 16 02:46:45 2014
Return-Path: <robert.cragie@gridmerge.com>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id E23031A0AD0 for <ace@ietfa.amsl.com>; Wed, 16 Jul 2014 02:46:43 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.599
X-Spam-Level: 
X-Spam-Status: No, score=-1.599 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HTML_MESSAGE=0.001, MIME_8BIT_HEADER=0.3] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id RT7Af59l9C_E for <ace@ietfa.amsl.com>; Wed, 16 Jul 2014 02:46:42 -0700 (PDT)
Received: from mailscan1.extendcp.co.uk (mailscan27.extendcp.co.uk [176.32.228.1]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id A86EA1A0376 for <ace@ietf.org>; Wed, 16 Jul 2014 02:46:41 -0700 (PDT)
Received: from lb1.hi.local ([10.0.1.197] helo=mailscan2.extendcp.co.uk) by mailscan-g65.hi.local with esmtp (Exim 4.80.1) (envelope-from <robert.cragie@gridmerge.com>) id 1X7LnJ-0005h0-1b; Wed, 16 Jul 2014 10:46:37 +0100
Received: from lb1.hi.local ([10.0.1.197] helo=mail41.extendcp.co.uk) by mailscan2.extendcp.co.uk with esmtps (UNKNOWN:DHE-RSA-AES256-GCM-SHA384:256) (Exim 4.80.1) (envelope-from <robert.cragie@gridmerge.com>) id 1X7LnF-0000qH-TN; Wed, 16 Jul 2014 10:46:37 +0100
Received: from host86-163-16-160.range86-163.btcentralplus.com ([86.163.16.160] helo=[192.168.0.2]) by mail41.extendcp.com with esmtpsa (TLSv1:DHE-RSA-AES128-SHA:128) (Exim 4.80.1) id 1X7LnE-0000nn-GE; Wed, 16 Jul 2014 10:46:32 +0100
Message-ID: <53C649F3.5000503@gridmerge.com>
Date: Wed, 16 Jul 2014 10:46:27 +0100
From: Robert Cragie <robert.cragie@gridmerge.com>
Organization: Gridmerge Ltd.
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:24.0) Gecko/20100101 Thunderbird/24.5.0
MIME-Version: 1.0
To: Ludwig Seitz <ludwig@sics.se>, =?ISO-8859-1?Q?Erik_Wahlstr=F6m?= <erik.wahlstrom@nexusgroup.com>
References: <34966E97BE8AD64EAE9D3D6E4DEE36F258177EE3@SZXEMA501-MBS.china.huawei.com> <53C4C5D6.30503@sics.se> <BE6D13F6A4554947952B39008B0DC0153E7D4731@DBXPRD9003MB059.MGDPHG.emi.philips.com> <53C5461B.7010707@gridmerge.com> <B6F75277-F8E2-4DD9-ACAC-D0DE8E17F3F7@nexusgroup.com> <53C63900.2070908@sics.se>
In-Reply-To: <53C63900.2070908@sics.se>
Content-Type: multipart/signed; protocol="application/pkcs7-signature"; micalg=sha1; boundary="------------ms040104050105010201080301"
X-Authenticated-As: robert.cragie@gridmerge.com
X-Extend-Src: mailout
Archived-At: http://mailarchive.ietf.org/arch/msg/ace/5epNr-nQbXX88jPNcQS_35onwKc
Cc: "Kumar, Sandeep" <sandeep.kumar@philips.com>, "ace@ietf.org" <ace@ietf.org>
Subject: Re: [Ace] Context-based Authorization
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
Reply-To: robert.cragie@gridmerge.com
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 16 Jul 2014 09:46:44 -0000

This is a cryptographically signed message in MIME format.

--------------ms040104050105010201080301
Content-Type: multipart/alternative;
 boundary="------------020800030207000802000004"

This is a multi-part message in MIME format.
--------------020800030207000802000004
Content-Type: text/plain; charset=ISO-8859-1; format=flowed
Content-Transfer-Encoding: quoted-printable

I think the model should clearly identify the different roles the AS can =

play and treat them as separate entities. When it comes to allow/deny,=20
the RS will have to make a decision. It could consult some co-located=20
decision maker or potentially ask a remote decision maker or a=20
combination of the two. The rules for decision making could be based on=20
prior interactions and resulting token delivery in conjunction with=20
current parameters. All a token is saying is "don't ask me (the AS) now, =

this token shows I have already said yes". Considering the earlier=20
EAP/AAA discussion - tokens should be optional.

Maybe we could extend the notion of context-based authorization with=20
triggers, i.e. if a condition fails, it triggers some remedial action so =

it hopefully won't subsequently fail.

Robert

On 16/07/2014 9:34 AM, Ludwig Seitz wrote:
> On 07/15/2014 06:10 PM, Erik Wahlstr=F6m wrote:
>> Consider it? Sure, absolutely. But building it into the protocol I'm=20
>> not that sure of. It's a rather tricky thing and a slippery slope.=20
>> Isn't it better to let the AS decide for each request by using=20
>> inspection endpoints
> (or something like it depending on what solutions and technologies we=20
> will end up working with). The RS asks the AS for validity of a token=20
> within a specific context.
>>
>
> That wouldn't work in use cases were the RS has intermittent=20
> connectivity.
>
> /Ludwig
>
>
>
>
> _______________________________________________
> Ace mailing list
> Ace@ietf.org
> https://www.ietf.org/mailman/listinfo/ace


--------------020800030207000802000004
Content-Type: text/html; charset=ISO-8859-1
Content-Transfer-Encoding: quoted-printable

<html>
  <head>
    <meta content=3D"text/html; charset=3DISO-8859-1"
      http-equiv=3D"Content-Type">
  </head>
  <body text=3D"#000000" bgcolor=3D"#FFFFFF">
    I think the model should clearly identify the different roles the AS
    can play and treat them as separate entities. When it comes to
    allow/deny, the RS will have to make a decision. It could consult
    some co-located decision maker or potentially ask a remote decision
    maker or a combination of the two. The rules for decision making
    could be based on prior interactions and resulting token delivery in
    conjunction with current parameters. All a token is saying is "don't
    ask me (the AS) now, this token shows I have already said yes".
    Considering the earlier EAP/AAA discussion - tokens should be
    optional.<br>
    <br>
    Maybe we could extend the notion of context-based authorization with
    triggers, i.e. if a condition fails, it triggers some remedial
    action so it hopefully won't subsequently fail.<br>
    <br>
    Robert<br>
    <br>
    <div class=3D"moz-cite-prefix">On 16/07/2014 9:34 AM, Ludwig Seitz
      wrote:<br>
    </div>
    <blockquote cite=3D"mid:53C63900.2070908@sics.se" type=3D"cite">On
      07/15/2014 06:10 PM, Erik Wahlstr&ouml;m wrote:
      <br>
      <blockquote type=3D"cite">Consider it? Sure, absolutely. But
        building it into the protocol I&#8217;m not that sure of. It&#821=
7;s a
        rather tricky thing and a slippery slope. Isn&#8217;t it better t=
o let
        the AS decide for each request by using inspection endpoints
        <br>
      </blockquote>
      (or something like it depending on what solutions and technologies
      we will end up working with). The RS asks the AS for validity of a
      token within a specific context.
      <br>
      <blockquote type=3D"cite">
        <br>
      </blockquote>
      <br>
      That wouldn't work in use cases were the RS has intermittent
      connectivity.
      <br>
      <br>
      /Ludwig
      <br>
      <br>
      <br>
      <br>
      <fieldset class=3D"mimeAttachmentHeader"></fieldset>
      <br>
      <pre wrap=3D"">_______________________________________________
Ace mailing list
<a class=3D"moz-txt-link-abbreviated" href=3D"mailto:Ace@ietf.org">Ace@ie=
tf.org</a>
<a class=3D"moz-txt-link-freetext" href=3D"https://www.ietf.org/mailman/l=
istinfo/ace">https://www.ietf.org/mailman/listinfo/ace</a>
</pre>
    </blockquote>
    <br>
  </body>
</html>

--------------020800030207000802000004--

--------------ms040104050105010201080301
Content-Type: application/pkcs7-signature; name="smime.p7s"
Content-Transfer-Encoding: base64
Content-Disposition: attachment; filename="smime.p7s"
Content-Description: S/MIME Cryptographic Signature

MIAGCSqGSIb3DQEHAqCAMIACAQExCzAJBgUrDgMCGgUAMIAGCSqGSIb3DQEHAQAAoIILUDCC
BRowggQCoAMCAQICEG0Z6qcZT2ozIuYiMnqqcd4wDQYJKoZIhvcNAQEFBQAwga4xCzAJBgNV
BAYTAlVTMQswCQYDVQQIEwJVVDEXMBUGA1UEBxMOU2FsdCBMYWtlIENpdHkxHjAcBgNVBAoT
FVRoZSBVU0VSVFJVU1QgTmV0d29yazEhMB8GA1UECxMYaHR0cDovL3d3dy51c2VydHJ1c3Qu
Y29tMTYwNAYDVQQDEy1VVE4tVVNFUkZpcnN0LUNsaWVudCBBdXRoZW50aWNhdGlvbiBhbmQg
RW1haWwwHhcNMTEwNDI4MDAwMDAwWhcNMjAwNTMwMTA0ODM4WjCBkzELMAkGA1UEBhMCR0Ix
GzAZBgNVBAgTEkdyZWF0ZXIgTWFuY2hlc3RlcjEQMA4GA1UEBxMHU2FsZm9yZDEaMBgGA1UE
ChMRQ09NT0RPIENBIExpbWl0ZWQxOTA3BgNVBAMTMENPTU9ETyBDbGllbnQgQXV0aGVudGlj
YXRpb24gYW5kIFNlY3VyZSBFbWFpbCBDQTCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoC
ggEBAJKEhFtLV5jUXi+LpOFAyKNTWF9mZfEyTvefMn1V0HhMVbdClOD5J3EHxcZppLkyxPFA
GpDMJ1Zifxe1cWmu5SAb5MtjXmDKokH2auGj/7jfH0htZUOMKi4rYzh337EXrMLaggLW1DJq
1GdvIBOPXDX65VSAr9hxCh03CgJQU2yVHakQFLSZlVkSMf8JotJM3FLb3uJAAVtIaN3FSrTg
7SQfOq9xXwfjrL8UO7AlcWg99A/WF1hGFYE8aIuLgw9teiFX5jSw2zJ+40rhpVJyZCaRTqWS
D//gsWD9Gm9oUZljjRqLpcxCm5t9ImPTqaD8zp6Q30QZ9FxbNboW86eb/8ECAwEAAaOCAUsw
ggFHMB8GA1UdIwQYMBaAFImCZ33EnSZwAEu0UEh83j2uBG59MB0GA1UdDgQWBBR6E04AdFvG
eGNkJ8Ev4qBbvHnFezAOBgNVHQ8BAf8EBAMCAQYwEgYDVR0TAQH/BAgwBgEB/wIBADARBgNV
HSAECjAIMAYGBFUdIAAwWAYDVR0fBFEwTzBNoEugSYZHaHR0cDovL2NybC51c2VydHJ1c3Qu
Y29tL1VUTi1VU0VSRmlyc3QtQ2xpZW50QXV0aGVudGljYXRpb25hbmRFbWFpbC5jcmwwdAYI
KwYBBQUHAQEEaDBmMD0GCCsGAQUFBzAChjFodHRwOi8vY3J0LnVzZXJ0cnVzdC5jb20vVVRO
QWRkVHJ1c3RDbGllbnRfQ0EuY3J0MCUGCCsGAQUFBzABhhlodHRwOi8vb2NzcC51c2VydHJ1
c3QuY29tMA0GCSqGSIb3DQEBBQUAA4IBAQCF1r54V1VtM39EUv5C1QaoAQOAivsNsv1Kv/av
QUn1G1rF0q0bc24+6SZ85kyYwTAo38v7QjyhJT4KddbQPTmGZtGhm7VNm2+vKGwdr+XqdFqo
2rHA8XV6L566k3nK/uKRHlZ0sviN0+BDchvtj/1gOSBH+4uvOmVIPJg9pSW/ve9g4EnlFsjr
P0OD8ODuDcHTzTNfm9C9YGqzO/761Mk6PB/tm/+bSTO+Qik5g+4zaS6CnUVNqGnagBsePdIa
XXxHmaWbCG0SmYbWXVcHG6cwvktJRLiQfsrReTjrtDP6oDpdJlieYVUYtCHVmdXgQ0BCML7q
peeU0rD+83X5f27nMIIGLjCCBRagAwIBAgIQXDFQ28QtqMuYch5f2nTvZjANBgkqhkiG9w0B
AQUFADCBkzELMAkGA1UEBhMCR0IxGzAZBgNVBAgTEkdyZWF0ZXIgTWFuY2hlc3RlcjEQMA4G
A1UEBxMHU2FsZm9yZDEaMBgGA1UEChMRQ09NT0RPIENBIExpbWl0ZWQxOTA3BgNVBAMTMENP
TU9ETyBDbGllbnQgQXV0aGVudGljYXRpb24gYW5kIFNlY3VyZSBFbWFpbCBDQTAeFw0xMTA5
MDIwMDAwMDBaFw0xNDA5MDEyMzU5NTlaMIIBNzELMAkGA1UEBhMCR0IxEDAOBgNVBBETB1dG
NCA0V0ExFzAVBgNVBAgTDldlc3QgWW9ya3NoaXJlMRIwEAYDVQQHEwlXYWtlZmllbGQxFDAS
BgNVBAkTC0dyYW5nZSBNb29yMR8wHQYDVQQJExY4OSBHcmVlbmZpZWxkIENyZXNjZW50MRcw
FQYDVQQKEw5HcmlkbWVyZ2UgTHRkLjE0MDIGA1UECxMrSXNzdWVkIHRocm91Z2ggR3JpZG1l
cmdlIEx0ZC4gRS1QS0kgTWFuYWdlcjEfMB0GA1UECxMWQ29ycG9yYXRlIFNlY3VyZSBFbWFp
bDEWMBQGA1UEAxMNUm9iZXJ0IENyYWdpZTEqMCgGCSqGSIb3DQEJARYbcm9iZXJ0LmNyYWdp
ZUBncmlkbWVyZ2UuY29tMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEArcThqvLe
WU1Q1ZJmnb+2UQSwOQKWok3A1Mwk582AdvwaAQyBFliPyJ0kXJqtwNBoZvk+3WJr0QA5ZRr+
J0x3sXVpcxadojP2HNzy1gsgDtIGG8ltoU4vmX1A8BTlOIUT+Pg8p/bSruxV0vz0CR8ho2hs
R0Zi5vU+rQKNmbgufbkWhlQnMEYjknemscLQfw1YZz90ta67doNDujFy6+X6I06HpjudgMYx
8bdsNS5xVFFwuBA1eqNQra+xLzhCOeX9PPB/zK68qdNhrni3WPYG9EhSt4Dzk+xIz9hj7wrU
ZIVXDTPsY8qbUSBVpwmzI5lCHPgzurH1OK7WwgpDSsl5pwIDAQABo4IB1TCCAdEwHwYDVR0j
BBgwFoAUehNOAHRbxnhjZCfBL+KgW7x5xXswHQYDVR0OBBYEFBCOXNH+lDm8U9gy3b3bRvrx
vKgrMA4GA1UdDwEB/wQEAwIFoDAMBgNVHRMBAf8EAjAAMB0GA1UdJQQWMBQGCCsGAQUFBwME
BggrBgEFBQcDAjBGBgNVHSAEPzA9MDsGDCsGAQQBsjEBAgEDBTArMCkGCCsGAQUFBwIBFh1o
dHRwczovL3NlY3VyZS5jb21vZG8ubmV0L0NQUzBXBgNVHR8EUDBOMEygSqBIhkZodHRwOi8v
Y3JsLmNvbW9kb2NhLmNvbS9DT01PRE9DbGllbnRBdXRoZW50aWNhdGlvbmFuZFNlY3VyZUVt
YWlsQ0EuY3JsMIGIBggrBgEFBQcBAQR8MHowUgYIKwYBBQUHMAKGRmh0dHA6Ly9jcnQuY29t
b2RvY2EuY29tL0NPTU9ET0NsaWVudEF1dGhlbnRpY2F0aW9uYW5kU2VjdXJlRW1haWxDQS5j
cnQwJAYIKwYBBQUHMAGGGGh0dHA6Ly9vY3NwLmNvbW9kb2NhLmNvbTAmBgNVHREEHzAdgRty
b2JlcnQuY3JhZ2llQGdyaWRtZXJnZS5jb20wDQYJKoZIhvcNAQEFBQADggEBAD6b/O0LkPav
kR4Znoqxg0Ad7M3duDm4uzfrlX4ecgq56Ccdwd+3Tayz7Ewej30woVMmTKkA/NKRaCd0wVM9
8seF/oZjXKO7o1SH27igRnGSWjCoWXsdwJGfZbYnvcIIhhsxJoCPNbeSR7C0PAFDKsP3xrJy
MHMljIJsoRbZu/fnYNyFWh9OXf7fYJOGmKDKAhSabUGfhY7umvU9d/YTqo02Q6YzC7d4zPNG
1a75AuHSEchf6GdKqycG38I5y9jlDaYfXspoS3PlTNCIeZONbOSMZgftnNEVKq+SWytFqyG/
8+dwpm/a12KMex5J8iHwaUKj++2O2rAFNjDDqXpeEYoxggQZMIIEFQIBATCBqDCBkzELMAkG
A1UEBhMCR0IxGzAZBgNVBAgTEkdyZWF0ZXIgTWFuY2hlc3RlcjEQMA4GA1UEBxMHU2FsZm9y
ZDEaMBgGA1UEChMRQ09NT0RPIENBIExpbWl0ZWQxOTA3BgNVBAMTMENPTU9ETyBDbGllbnQg
QXV0aGVudGljYXRpb24gYW5kIFNlY3VyZSBFbWFpbCBDQQIQXDFQ28QtqMuYch5f2nTvZjAJ
BgUrDgMCGgUAoIICRTAYBgkqhkiG9w0BCQMxCwYJKoZIhvcNAQcBMBwGCSqGSIb3DQEJBTEP
Fw0xNDA3MTYwOTQ2MjdaMCMGCSqGSIb3DQEJBDEWBBQjLWYvhfvFP9L8PpRgifvRq9ABQzBs
BgkqhkiG9w0BCQ8xXzBdMAsGCWCGSAFlAwQBKjALBglghkgBZQMEAQIwCgYIKoZIhvcNAwcw
DgYIKoZIhvcNAwICAgCAMA0GCCqGSIb3DQMCAgFAMAcGBSsOAwIHMA0GCCqGSIb3DQMCAgEo
MIG5BgkrBgEEAYI3EAQxgaswgagwgZMxCzAJBgNVBAYTAkdCMRswGQYDVQQIExJHcmVhdGVy
IE1hbmNoZXN0ZXIxEDAOBgNVBAcTB1NhbGZvcmQxGjAYBgNVBAoTEUNPTU9ETyBDQSBMaW1p
dGVkMTkwNwYDVQQDEzBDT01PRE8gQ2xpZW50IEF1dGhlbnRpY2F0aW9uIGFuZCBTZWN1cmUg
RW1haWwgQ0ECEFwxUNvELajLmHIeX9p072YwgbsGCyqGSIb3DQEJEAILMYGroIGoMIGTMQsw
CQYDVQQGEwJHQjEbMBkGA1UECBMSR3JlYXRlciBNYW5jaGVzdGVyMRAwDgYDVQQHEwdTYWxm
b3JkMRowGAYDVQQKExFDT01PRE8gQ0EgTGltaXRlZDE5MDcGA1UEAxMwQ09NT0RPIENsaWVu
dCBBdXRoZW50aWNhdGlvbiBhbmQgU2VjdXJlIEVtYWlsIENBAhBcMVDbxC2oy5hyHl/adO9m
MA0GCSqGSIb3DQEBAQUABIIBADFSuTU5wndQNhRERJwceumlT8xCV4VshUIgKzYfWZ5/3lPT
8PMTX7uNWdwIcpj3Pg3GOOjYeIgqYzhgA+Urt5JXSQQHNXJ6lhIQ6WQ0PlfDKCVZM6tNXNR7
lo595mrr8ysKCeGD68l0zbdIJ6WUj8PwNjgYjEGe7/Ub+xw3QH40ix1a6ancVMe1e0vn86t3
yXA1mBsU4GviSwM1aoBRnDDR6O+dN9yko1TO4Ouskg7S4eYzmJfnurSm645M0rBtjMb0v9z7
4ixcVX3G5NIdki3DUBcndflUoXksEwY5J0rrLm4Df7brr1sZTCa12ukamiJH/DBA+cAVhpX7
/bwPWq0AAAAAAAA=
--------------ms040104050105010201080301--


From nobody Wed Jul 16 04:01:04 2014
Return-Path: <cabo@tzi.org>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id E88281B2856 for <ace@ietfa.amsl.com>; Wed, 16 Jul 2014 04:01:00 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.551
X-Spam-Level: 
X-Spam-Status: No, score=-1.551 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HELO_EQ_DE=0.35, SPF_HELO_PASS=-0.001] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id LAjOt4kGa0j1 for <ace@ietfa.amsl.com>; Wed, 16 Jul 2014 04:00:59 -0700 (PDT)
Received: from informatik.uni-bremen.de (mailhost.informatik.uni-bremen.de [IPv6:2001:638:708:30c9::12]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 4EBFC1A0142 for <ace@ietf.org>; Wed, 16 Jul 2014 04:00:59 -0700 (PDT)
X-Virus-Scanned: amavisd-new at informatik.uni-bremen.de
Received: from smtp-fb3.informatik.uni-bremen.de (smtp-fb3.informatik.uni-bremen.de [134.102.224.120]) by informatik.uni-bremen.de (8.14.5/8.14.5) with ESMTP id s6GB0oFa019470; Wed, 16 Jul 2014 13:00:50 +0200 (CEST)
Received: from [100.125.57.154] (unknown [194.151.204.32]) (using TLSv1 with cipher AES128-SHA (128/128 bits)) (No client certificate requested) by smtp-fb3.informatik.uni-bremen.de (Postfix) with ESMTPSA id 63F7FEA2; Wed, 16 Jul 2014 13:00:50 +0200 (CEST)
Content-Type: text/plain; charset=windows-1252
Mime-Version: 1.0 (Mac OS X Mail 7.3 \(1878.6\))
From: Carsten Bormann <cabo@tzi.org>
In-Reply-To: <53C5461B.7010707@gridmerge.com>
Date: Wed, 16 Jul 2014 13:00:50 +0200
X-Mao-Original-Outgoing-Id: 427201250.044753-8187235359d07898469dd9e2df2f0072
Content-Transfer-Encoding: quoted-printable
Message-Id: <AAB96C8B-EB9F-4850-A764-24EE2691A075@tzi.org>
References: <34966E97BE8AD64EAE9D3D6E4DEE36F258177EE3@SZXEMA501-MBS.china.huawei.com> <53C4C5D6.30503@sics.se> <BE6D13F6A4554947952B39008B0DC0153E7D4731@DBXPRD9003MB059.MGDPHG.emi.philips.com> <53C5461B.7010707@gridmerge.com>
To: robert.cragie@gridmerge.com
X-Mailer: Apple Mail (2.1878.6)
Archived-At: http://mailarchive.ietf.org/arch/msg/ace/zpGqss2lkexFNhxlM110F0NFgQc
Cc: Ludwig Seitz <ludwig@sics.se>, "Kumar, Sandeep" <sandeep.kumar@philips.com>, "ace@ietf.org" <ace@ietf.org>
Subject: Re: [Ace] Context-based Authorization
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 16 Jul 2014 11:01:01 -0000

On 15 Jul 2014, at 17:17, Robert Cragie <robert.cragie@gridmerge.com> =
wrote:

> I think we do need to consider context based authentication and it =
should be possible to establish the bases for the context without having =
to go into solutions, e.g.
>=20
> * Time-based
> * Identity-based
> * Role-based
> * etc.

(I hope this is about authorization.)

So which components need to interoperate to make this work?
It seems any agreement about information that leads up to such a =
capability would need to be between RS and AS.
(C or AM may also be interested, but that seems to be a supplementary =
capability.)

In the architecture underlying DCAF, the ticket being transported from =
AS to RS contains =93authorization information=94, which is an entity =
with an Internet media type.  AS and RS just need to communicate their =
authorization parameters via a media type they both support.
So evolution of this format is built right in; this can be done =
orthogonally to any other evolution in the system.

(I don=92t think we have a good answer for context-based authorization =
of an RS to represent a resource R.
That is architecturally a bit more complicated.
But maybe this is not really required as much as context-based =
authorization of a client to access R.)

Gr=FC=DFe, Carsten


From nobody Fri Jul 18 00:55:06 2014
Return-Path: <ludwig@sics.se>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id D2A9F1A0658 for <ace@ietfa.amsl.com>; Fri, 18 Jul 2014 00:55:03 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: 0.449
X-Spam-Level: 
X-Spam-Status: No, score=0.449 tagged_above=-999 required=5 tests=[BAYES_50=0.8, HELO_EQ_SE=0.35, RCVD_IN_DNSWL_LOW=-0.7, RP_MATCHES_RCVD=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id QkOub3iuKFxd for <ace@ietfa.amsl.com>; Fri, 18 Jul 2014 00:55:00 -0700 (PDT)
Received: from outbox.sics.se (outbox.sics.se [193.10.64.137]) by ietfa.amsl.com (Postfix) with ESMTP id D95361A04B0 for <ace@ietf.org>; Fri, 18 Jul 2014 00:54:59 -0700 (PDT)
Received: from e-mailfilter01.sunet.se (e-mailfilter01.sunet.se [192.36.171.201]) by outbox.sics.se (Postfix) with ESMTPS id A8CC962F; Fri, 18 Jul 2014 09:54:57 +0200 (CEST)
Received: from letter.sics.se (letter.sics.se [193.10.64.6]) by e-mailfilter01.sunet.se (8.14.4/8.14.4/Debian-4) with ESMTP id s6I7svjk022598; Fri, 18 Jul 2014 09:54:57 +0200
Received: from [192.168.0.108] (unknown [85.235.11.178]) (Authenticated sender: ludwig@sics.se) by letter.sics.se (Postfix) with ESMTPSA id A8C2940116; Fri, 18 Jul 2014 09:54:57 +0200 (CEST)
Message-ID: <53C8D2CF.8070807@sics.se>
Date: Fri, 18 Jul 2014 09:54:55 +0200
From: Ludwig Seitz <ludwig@sics.se>
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:24.0) Gecko/20100101 Thunderbird/24.6.0
MIME-Version: 1.0
To: ace@ietf.org
References: <53C3C09A.5090707@gmx.net> <CFEA41D5.15C7A%goran.selander@ericsson.com>
In-Reply-To: <CFEA41D5.15C7A%goran.selander@ericsson.com>
Content-Type: multipart/signed; protocol="application/pkcs7-signature"; micalg=sha1; boundary="------------ms080203000903020501020608"
X-Bayes-Prob: 0.0354 (Score 0, tokens from: outbound, outbound-sics-se:default, sics-se:default, base:default, @@RPTN)
X-p0f-Info: os=Solaris 10, link=Ethernet or modem
X-CanIt-Geo: =?UTF-8?Q?ip=3D85.235.11.178; _country=3DSE; _region=3DSk=C3=A5ne; _city=3DLund; _latitude=3D55.7000; _longitude=3D13.1833; _http://maps.google.com/maps=3Fq=3D55.7000,13.1833&z=3D6?=
X-CanItPRO-Stream: outbound-sics-se:outbound (inherits from outbound-sics-se:default, sics-se:default, base:default)
X-Canit-Stats-ID: 09MrHSVmn - a9dcb90dd768 - 20140718
X-Antispam-Training-Forget: https://canit.sunet.se/canit/b.php?i=09MrHSVmn&m=a9dcb90dd768&t=20140718&c=f
X-Antispam-Training-Nonspam: https://canit.sunet.se/canit/b.php?i=09MrHSVmn&m=a9dcb90dd768&t=20140718&c=n
X-Antispam-Training-Spam: https://canit.sunet.se/canit/b.php?i=09MrHSVmn&m=a9dcb90dd768&t=20140718&c=s
X-CanIt-Archive-Cluster: PfMRe/vJWMiXwM2YIH5BVExnUnw
X-Scanned-By: CanIt (www . roaringpenguin . com) on 192.36.171.201
Archived-At: http://mailarchive.ietf.org/arch/msg/ace/Iv6pCfMwNTvgxBBKU3B5ZoOzK_s
Cc: Carlo Pompili <carlo.pompili@telcred.com>
Subject: Re: [Ace] Offline operation of Resource Server
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 18 Jul 2014 07:55:04 -0000

This is a cryptographically signed message in MIME format.

--------------ms080203000903020501020608
Content-Type: text/plain; charset=ISO-8859-1; format=flowed
Content-Transfer-Encoding: quoted-printable

On 07/15/2014 09:25 AM, G=F6ran Selander wrote:
> Hannes,
>
> I believe it is important that the solution allows an offline mode of
> operation. Here are some other supporting use cases:
[...]
> We discussed previously one company considering designing physical acce=
ss
> control using an online system. There are another companies in the
> physical access control business that profile themselves with offering
> offline mode, for example Telcred. Their home page provides some more
> details.
>
> http://telcred.com/
>

I have a statement from Telcred here that might be of interest:

On 07/16/2014 12:12 PM, Carlo Pompili wrote:
> Dear G=F6ran, Ludwig,
>
> Thanks for opportunity to comment on the need for offline access contro=
l / locks from our perspective.
>
> As you know, Telcred is a spinoff-company from SICS developing a soluti=
on for physical access control
> with support for offline operation, and we do indeed see a large market=
 for offline access control
 > for the foreseeable future.
> In the short to medium term we believe that many infrastructure compani=
es need this type of solution.
 > Examples include companies and organizations responsible for power=20
generation and distribution, telecom,
 > water, sewage, road and rail infrastructure, etc. These companies=20
have many remote sites which need to
 > be visited from time to time by e.g. service technicians. Although in =

many cases it would be feasible
 > to install an online solution, we know from our discussions with them =

that the cost is perceived as
 > prohibitive. An offline solution is also perceived as more robust. A=20
common reason for sending a
 > technician to a site is that there is some problem which need to be=20
fixed, and in this situation one
 > cannot assume that communications to the site will be available.
>
> Longer term we also believe that there is a great market for offline ac=
cess control in transportation,
 > including both commercial and private vehicles, as well as many types =

of load carriers
 > (e.g. shipping containers). Undoubtedly, most cars and trucks will=20
have an online connection, but it
 > cannot be guaranteed to always be available - consider for example=20
parking garages.
>
> As should be clear from the above, we believe that offline is mainly re=
levant for access control in
 > an enterprise setting. Private homes interested in electronic access=20
control can also be expected to
 > have a good broadband connection, WiFi etc.
>
> As you know, Telcred has developed a model for offline access control b=
ased on cryptographically signed
 > "tickets" and a compact way of expressing and verifying access=20
rights, which can scale to a very large
 > number of locks while keeping the size of the tickets down.
>
> If you think we can contribute further to your work in this area we are=
 happy to do so.
>
> Best regards,
>
> Carl Pompili
>
>

/Ludwig


--=20
Ludwig Seitz, PhD
SICS Swedish ICT AB
Ideon Science Park
Building Beta 2
Scheelev=E4gen 17
SE-223 70 Lund

Phone +46(0)70-349 92 51
http://www.sics.se


--------------ms080203000903020501020608
Content-Type: application/pkcs7-signature; name="smime.p7s"
Content-Transfer-Encoding: base64
Content-Disposition: attachment; filename="smime.p7s"
Content-Description: S/MIME Cryptographic Signature

MIAGCSqGSIb3DQEHAqCAMIACAQExCzAJBgUrDgMCGgUAMIAGCSqGSIb3DQEHAQAAoIIMVDCC
BhgwggUAoAMCAQICAwiRTjANBgkqhkiG9w0BAQsFADCBjDELMAkGA1UEBhMCSUwxFjAUBgNV
BAoTDVN0YXJ0Q29tIEx0ZC4xKzApBgNVBAsTIlNlY3VyZSBEaWdpdGFsIENlcnRpZmljYXRl
IFNpZ25pbmcxODA2BgNVBAMTL1N0YXJ0Q29tIENsYXNzIDEgUHJpbWFyeSBJbnRlcm1lZGlh
dGUgQ2xpZW50IENBMB4XDTE0MDEwNzA3MjgzNVoXDTE1MDEwNzEyNTgyMlowODEXMBUGA1UE
AwwObHVkd2lnQHNpY3Muc2UxHTAbBgkqhkiG9w0BCQEWDmx1ZHdpZ0BzaWNzLnNlMIIBIjAN
BgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAnLm1tc30QxHa9wtdVjC3NgxjLJicnccm0HD+
1X16kPMKGvwps8F1oDhYn7jXIe46p1AuJMzLK0GIioE4JwxCFGdvpz7cg2xyTyrdBVUzSqez
Dfqt4FOJq6hrdrIMS8MHEzl7Jk02gv9cTn/pHQvDpkiThRpbSLU5mlMqtEQ8gDQY5YyBX0Mv
5qculV08I2JU8HEeTt1oeqhvBImgQfOVYMDatHlWHUVVrmYd6iIo+cuiUGd5kiA0XuaLYX0E
oCoao/z5Wg9U0sQlx0hl4r96Q+NdoZZ1prfts3qtyBzJ2hu135aikigzJ6sueWHv/jbISUek
tOMm0xkx1GOqqWtEAwIDAQABo4IC1DCCAtAwCQYDVR0TBAIwADALBgNVHQ8EBAMCBLAwHQYD
VR0lBBYwFAYIKwYBBQUHAwIGCCsGAQUFBwMEMB0GA1UdDgQWBBRZmjjBh8N3klra+mVQgC00
pl68ZTAfBgNVHSMEGDAWgBRTcu2SnODaywFcfH6WNU7y1LhRgjAZBgNVHREEEjAQgQ5sdWR3
aWdAc2ljcy5zZTCCAUwGA1UdIASCAUMwggE/MIIBOwYLKwYBBAGBtTcBAgMwggEqMC4GCCsG
AQUFBwIBFiJodHRwOi8vd3d3LnN0YXJ0c3NsLmNvbS9wb2xpY3kucGRmMIH3BggrBgEFBQcC
AjCB6jAnFiBTdGFydENvbSBDZXJ0aWZpY2F0aW9uIEF1dGhvcml0eTADAgEBGoG+VGhpcyBj
ZXJ0aWZpY2F0ZSB3YXMgaXNzdWVkIGFjY29yZGluZyB0byB0aGUgQ2xhc3MgMSBWYWxpZGF0
aW9uIHJlcXVpcmVtZW50cyBvZiB0aGUgU3RhcnRDb20gQ0EgcG9saWN5LCByZWxpYW5jZSBv
bmx5IGZvciB0aGUgaW50ZW5kZWQgcHVycG9zZSBpbiBjb21wbGlhbmNlIG9mIHRoZSByZWx5
aW5nIHBhcnR5IG9ibGlnYXRpb25zLjA2BgNVHR8ELzAtMCugKaAnhiVodHRwOi8vY3JsLnN0
YXJ0c3NsLmNvbS9jcnR1MS1jcmwuY3JsMIGOBggrBgEFBQcBAQSBgTB/MDkGCCsGAQUFBzAB
hi1odHRwOi8vb2NzcC5zdGFydHNzbC5jb20vc3ViL2NsYXNzMS9jbGllbnQvY2EwQgYIKwYB
BQUHMAKGNmh0dHA6Ly9haWEuc3RhcnRzc2wuY29tL2NlcnRzL3N1Yi5jbGFzczEuY2xpZW50
LmNhLmNydDAjBgNVHRIEHDAahhhodHRwOi8vd3d3LnN0YXJ0c3NsLmNvbS8wDQYJKoZIhvcN
AQELBQADggEBAHqEYmtWr83S+iLXE97KBnHJZiMr6PMuLKxmh0o6UJJwKgf+KTP2czxRnPSI
+whuqfQZdmz6g3A2K8AooMU0RXrzncnX1c4826APdnXkRxnGQxtZXI1wuhPn4z7iDKZ6ij9u
K5Pfn10JL/ERDig2qJQbqvhtIAx0RY7y7r+hLMvgXVq9mf3WRJYmGQeFW+N9t5Z1eEwG4m9R
KAZm0fnfeDn/Ai4kmxTckBH7dZwW2lTtwQqQ4su+PGCJ0e9ndBLpvTqaYGSAl+L7PO7vxPhS
/cS67Xa6BtnYJLTr3MaGXaN+CEUFSfwQHa9DKcAqh3kldErI3kCvnot0CigBl4aILOEwggY0
MIIEHKADAgECAgEeMA0GCSqGSIb3DQEBBQUAMH0xCzAJBgNVBAYTAklMMRYwFAYDVQQKEw1T
dGFydENvbSBMdGQuMSswKQYDVQQLEyJTZWN1cmUgRGlnaXRhbCBDZXJ0aWZpY2F0ZSBTaWdu
aW5nMSkwJwYDVQQDEyBTdGFydENvbSBDZXJ0aWZpY2F0aW9uIEF1dGhvcml0eTAeFw0wNzEw
MjQyMTAxNTVaFw0xNzEwMjQyMTAxNTVaMIGMMQswCQYDVQQGEwJJTDEWMBQGA1UEChMNU3Rh
cnRDb20gTHRkLjErMCkGA1UECxMiU2VjdXJlIERpZ2l0YWwgQ2VydGlmaWNhdGUgU2lnbmlu
ZzE4MDYGA1UEAxMvU3RhcnRDb20gQ2xhc3MgMSBQcmltYXJ5IEludGVybWVkaWF0ZSBDbGll
bnQgQ0EwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDHCYPMzi3YGrEppC4Tq5a+
ijKDjKaIQZZVR63UbxIP6uq/I0fhCu+cQhoUfE6ERKKnu8zPf1Jwuk0tsvVCk6U9b+0UjM0d
Lep3ZdE1gblK/1FwYT5Pipsu2yOMluLqwvsuz9/9f1+1PKHG/FaR/wpbfuIqu54qzHDYeqiU
fsYzoVflR80DAC7hmJ+SmZnNTWyUGHJbBpA8Q89lGxahNvuryGaC/o2/ceD2uYDX9U8Eg5Dp
IpGQdcbQeGarV04WgAUjjXX5r/2dabmtxWMZwhZna//jdiSyrrSMTGKkDiXm6/3/4ebfeZuC
YKzN2P8O2F/Xe2AC/Y7zeEsnR7FOp+uXAgMBAAGjggGtMIIBqTAPBgNVHRMBAf8EBTADAQH/
MA4GA1UdDwEB/wQEAwIBBjAdBgNVHQ4EFgQUU3Ltkpzg2ssBXHx+ljVO8tS4UYIwHwYDVR0j
BBgwFoAUTgvvGqRAW6UXaYcwyjRoQ9BBrvIwZgYIKwYBBQUHAQEEWjBYMCcGCCsGAQUFBzAB
hhtodHRwOi8vb2NzcC5zdGFydHNzbC5jb20vY2EwLQYIKwYBBQUHMAKGIWh0dHA6Ly93d3cu
c3RhcnRzc2wuY29tL3Nmc2NhLmNydDBbBgNVHR8EVDBSMCegJaAjhiFodHRwOi8vd3d3LnN0
YXJ0c3NsLmNvbS9zZnNjYS5jcmwwJ6AloCOGIWh0dHA6Ly9jcmwuc3RhcnRzc2wuY29tL3Nm
c2NhLmNybDCBgAYDVR0gBHkwdzB1BgsrBgEEAYG1NwECATBmMC4GCCsGAQUFBwIBFiJodHRw
Oi8vd3d3LnN0YXJ0c3NsLmNvbS9wb2xpY3kucGRmMDQGCCsGAQUFBwIBFihodHRwOi8vd3d3
LnN0YXJ0c3NsLmNvbS9pbnRlcm1lZGlhdGUucGRmMA0GCSqGSIb3DQEBBQUAA4ICAQAKgwh9
eKssBly4Y4xerhy5I3dNoXHYfYa8PlVLL/qtXnkFgdtY1o95CfegFJTwqBBmf8pyTUnFsukD
FUI22zF5bVHzuJ+GxhnSqN2sD1qetbYwBYK2iyYA5Pg7Er1A+hKMIzEzcduRkIMmCeUTyMyi
kfbUFvIBivtvkR8ZFAk22BZy+pJfAoedO61HTz4qSfQoCRcLN5A0t4DkuVhTMXIzuQ8Cnykh
ExD6x4e6ebIbrjZLb7L+ocR0y4YjCl/Pd4MXU91y0vTipgr/O75CDUHDRHCCKBVmz/Rzkc/b
970MEeHt5LC3NiWTgBSvrLEuVzBKM586YoRD9Dy3OHQgWI270g+5MYA8GfgI/EPT5G7xPbCD
z+zjdH89PeR3U4So4lSXur6H6vp+m9TQXPF3a0LwZrp8MQ+Z77U1uL7TelWO5lApsbAonrqA
SfTpaprFVkL4nyGH+NHST2ZJPWIBk81i6Vw0ny0qZW2Niy/QvVNKbb43A43ny076khXO7cNb
BIRdJ/6qQNq9Bqb5C0Q5nEsFcj75oxQRqlKf6TcvGbjxkJh8BYtv9ePsXklAxtm8J7GCUBth
HSQgepbkOexhJ0wP8imUkyiPHQ0GvEnd83129fZjoEhdGwXV27ioRKbj/cIq7JRXun0NbeY+
UdMYu9jGfIpDLtUUGSgsg2zMGs5R4jGCA90wggPZAgEBMIGUMIGMMQswCQYDVQQGEwJJTDEW
MBQGA1UEChMNU3RhcnRDb20gTHRkLjErMCkGA1UECxMiU2VjdXJlIERpZ2l0YWwgQ2VydGlm
aWNhdGUgU2lnbmluZzE4MDYGA1UEAxMvU3RhcnRDb20gQ2xhc3MgMSBQcmltYXJ5IEludGVy
bWVkaWF0ZSBDbGllbnQgQ0ECAwiRTjAJBgUrDgMCGgUAoIICHTAYBgkqhkiG9w0BCQMxCwYJ
KoZIhvcNAQcBMBwGCSqGSIb3DQEJBTEPFw0xNDA3MTgwNzU0NTVaMCMGCSqGSIb3DQEJBDEW
BBREyjYgsCQJAJ0VkclTlXI4vBGuaTBsBgkqhkiG9w0BCQ8xXzBdMAsGCWCGSAFlAwQBKjAL
BglghkgBZQMEAQIwCgYIKoZIhvcNAwcwDgYIKoZIhvcNAwICAgCAMA0GCCqGSIb3DQMCAgFA
MAcGBSsOAwIHMA0GCCqGSIb3DQMCAgEoMIGlBgkrBgEEAYI3EAQxgZcwgZQwgYwxCzAJBgNV
BAYTAklMMRYwFAYDVQQKEw1TdGFydENvbSBMdGQuMSswKQYDVQQLEyJTZWN1cmUgRGlnaXRh
bCBDZXJ0aWZpY2F0ZSBTaWduaW5nMTgwNgYDVQQDEy9TdGFydENvbSBDbGFzcyAxIFByaW1h
cnkgSW50ZXJtZWRpYXRlIENsaWVudCBDQQIDCJFOMIGnBgsqhkiG9w0BCRACCzGBl6CBlDCB
jDELMAkGA1UEBhMCSUwxFjAUBgNVBAoTDVN0YXJ0Q29tIEx0ZC4xKzApBgNVBAsTIlNlY3Vy
ZSBEaWdpdGFsIENlcnRpZmljYXRlIFNpZ25pbmcxODA2BgNVBAMTL1N0YXJ0Q29tIENsYXNz
IDEgUHJpbWFyeSBJbnRlcm1lZGlhdGUgQ2xpZW50IENBAgMIkU4wDQYJKoZIhvcNAQEBBQAE
ggEAFiJmITW8O5BU3dcUpggKdlRqEuqBs1ZqOtkQohfpUerog3ZwZ9Qd9DsMSu5/DfyT1bwv
UA0ny1BXAbE+q/7OHeDGK6pdpUIlmYGmHWPF4rAFxgm4YGXypryyl+g2za7LJ0FDigXhx717
8zePX1Gx+8yZSaxTvL3wHBzefg0fVaHMauonYpBPgMeUnpDnvRaqifhDbkgZS3CZfMFGHPNf
NthWlj7ZLFHiktfX1cvQWd6d3l6e+Sg0c4i/S5H4goYXxY3F7apvwfC7cW4idhUztFd55tNl
6r9eddIKXWALml1V4H5Ow4jg/A2skK0B3Eq5xJJicKNLTw6qRVQlLymGggAAAAAAAA==
--------------ms080203000903020501020608--


From nobody Sat Jul 19 16:57:45 2014
Return-Path: <mcr@sandelman.ca>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 9A7A51B2AEB for <ace@ietfa.amsl.com>; Sat, 19 Jul 2014 16:57:43 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.892
X-Spam-Level: 
X-Spam-Status: No, score=-1.892 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001, T_TVD_MIME_NO_HEADERS=0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 5rgnnebuAi8O for <ace@ietfa.amsl.com>; Sat, 19 Jul 2014 16:57:41 -0700 (PDT)
Received: from tuna.sandelman.ca (tuna.sandelman.ca [209.87.249.19]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id B9A901B2AEA for <ace@ietf.org>; Sat, 19 Jul 2014 16:57:41 -0700 (PDT)
Received: from sandelman.ca (obiwan.sandelman.ca [IPv6:2607:f0b0:f:2::247]) by tuna.sandelman.ca (Postfix) with ESMTP id 112112002C for <ace@ietf.org>; Sat, 19 Jul 2014 19:59:10 -0400 (EDT)
Received: by sandelman.ca (Postfix, from userid 179) id 08F9263B0E; Sat, 19 Jul 2014 19:57:39 -0400 (EDT)
Received: from sandelman.ca (localhost [127.0.0.1]) by sandelman.ca (Postfix) with ESMTP id E64AE63AED for <ace@ietf.org>; Sat, 19 Jul 2014 19:57:39 -0400 (EDT)
From: Michael Richardson <mcr+ietf@sandelman.ca>
To: ace@ietf.org
In-Reply-To: <53C4C5D6.30503@sics.se>
References: <34966E97BE8AD64EAE9D3D6E4DEE36F258177EE3@SZXEMA501-MBS.china.huawei.com> <53C4C5D6.30503@sics.se>
X-Mailer: MH-E 8.2; nmh 1.3-dev; GNU Emacs 23.4.1
X-Face: $\n1pF)h^`}$H>Hk{L"x@)JS7<%Az}5RyS@k9X%29-lHB$Ti.V>2bi.~ehC0; <'$9xN5Ub# z!G,p`nR&p7Fz@^UXIn156S8.~^@MJ*mMsD7=QFeq%AL4m<nPbLgmtKK-5dC@#:k
MIME-Version: 1.0
Content-Type: multipart/signed; boundary="=-=-="; micalg=pgp-sha1; protocol="application/pgp-signature"
Date: Sat, 19 Jul 2014 19:57:39 -0400
Message-ID: <19173.1405814259@sandelman.ca>
Sender: mcr@sandelman.ca
Archived-At: http://mailarchive.ietf.org/arch/msg/ace/hu-mNOjALLInUePKqgKGZ36hVxg
Subject: Re: [Ace] Context-based Authorization
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sat, 19 Jul 2014 23:57:43 -0000

--=-=-=


Ludwig Seitz <ludwig@sics.se> wrote:
    >> For U3.1, how to define an emergency context?

    > In medical access control scenarios there is the concept of
    > "break-the-glass policies". This means that medical personnel can just
    > declare an emergency context (similar to breaking the glass to access a
    > fire alarm, see attached image) in order to get additional
    > authorization. This declaration is then subject to auditing at a later
    > point, to ensure that there really was an emergency situation.

I immediately thought of the "break-the-glass" concept as well, and then
went to read 3.1 again.  As written, 3.1 doesn't seem to imply that to me:
     U3.1 John must be able to pre-configure access rights to the
     position data for persons or groups, in the context of an
     emergency.

Let me explain what I interpret as "break-the-glass".
1) anyone near the glass can break it, not just some set of persons/groups.

2) the glass, having been broken, leaves a clear audit trail that someone
   has broken it.  Many fire-alarms emit dye when set off so that the person
   who "broke the glass" is clearly identified.  My high school didn't have
   that; and the fire department visited us three weeks in a row, just before
   period 4 on day 2.. when I guess someone had a test they didn't want to
   write.  I mention this situation because; despite a record of "crying
   wolf", the fire department had to show up each time.

3) the glass, having been broken, can not be broken again; it needs an
   explicit reset.

If I were I solve the break-the-glass situation, I would look to some kind
of skey-like solution based upon chained-hashes.
    http://research.microsoft.com/en-us/um/people/lamport/pubs/password.pdf
although I'm not quite sure how to use it yet.

HOWEVER, my reading of section 3.1 says that actually "John" simply is going
to want to configure that his spouse, children and best friend can grant
access to whomever needs it, when they see an emergency.

Going into a solution space, I would imagine that John's RS/AS generates a
series of unbound access tokens, and encrypts each one to each of them to the
set of friends/family that should have it.
Those encrypted tokens should be stored somehow on the RS itself, to be
retrieved by the person in the emergency, decrypted, and then delegated.

Such a solution may create some new requirements:
   1) ability to create a access token that is not bound to a specific
      client, but to anyone who possesses it.  In some solutions, this
      would be entirely a matter local to the RS, but I can see how many
      solutions need the RS and AS to interoperate on this.

   2) ability to retrieve such an encrypted access token from a well known
      resource.

   3) ability to securely pass such an encrypted access token on from
      one client to another.

Part 2/3 must occur "offline".
Much of the details are out of the scope for ACE.

--
Michael Richardson <mcr+IETF@sandelman.ca>, Sandelman Software Works
 -= IPv6 IoT consulting =-




--=-=-=
Content-Type: application/pgp-signature

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iQEVAwUBU8sF8YCLcPvd0N1lAQKzsgf/fp7b6rAUw9D22MDh8QI6/lPnDK5VptPc
QHe34UOW6qF/r/WFane7ZAUTic8CRnztFZ4yyTbhXEHhhX42sVlzsFzcuVpR1tGg
JQlmWgVi35KevJ1kzqoyaB+ywqfi5YimQP9Os+dJGW22PCYuz3cmE2rhwIY1lVjm
Ke9MrFfUEiyAmeFcznxdybIm6HBVrlvmT2Dk5tcVTP3aDsLCWTldRYJ/PipNl2/U
vpWoXsr57P5c6PPq4wTt+OnY4oYZLun1DkWMPWKW4xhRmh4h2VrdljVQ9Tc1pmce
3qLZFrkzD9KoPgIeamlWnW3LG0yeMkHUDjQwuvqfW7+5mv6V/E3MUg==
=jr/A
-----END PGP SIGNATURE-----
--=-=-=--


From nobody Sun Jul 20 06:51:30 2014
Return-Path: <ludwig@sics.se>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id BDC4F1B2C43 for <ace@ietfa.amsl.com>; Sun, 20 Jul 2014 06:51:26 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.251
X-Spam-Level: 
X-Spam-Status: No, score=-2.251 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HELO_EQ_SE=0.35, RCVD_IN_DNSWL_LOW=-0.7, RP_MATCHES_RCVD=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id IIlVmFm120Ft for <ace@ietfa.amsl.com>; Sun, 20 Jul 2014 06:51:23 -0700 (PDT)
Received: from outbox.sics.se (outbox.sics.se [193.10.64.137]) by ietfa.amsl.com (Postfix) with ESMTP id 914401B2C3B for <ace@ietf.org>; Sun, 20 Jul 2014 06:51:22 -0700 (PDT)
Received: from e-mailfilter01.sunet.se (e-mailfilter01.sunet.se [192.36.171.201]) by outbox.sics.se (Postfix) with ESMTPS id B0ABE6D6 for <ace@ietf.org>; Sun, 20 Jul 2014 15:51:20 +0200 (CEST)
Received: from letter.sics.se (letter.sics.se [193.10.64.6]) by e-mailfilter01.sunet.se (8.14.4/8.14.4/Debian-4) with ESMTP id s6KDpJN4019673 for <ace@ietf.org>; Sun, 20 Jul 2014 15:51:19 +0200
Received: from [10.255.249.246] (unknown [204.101.190.178]) (Authenticated sender: ludwig@sics.se) by letter.sics.se (Postfix) with ESMTPSA id 9056640116 for <ace@ietf.org>; Sun, 20 Jul 2014 15:51:19 +0200 (CEST)
Message-ID: <53CBC94D.3040407@sics.se>
Date: Sun, 20 Jul 2014 15:51:09 +0200
From: Ludwig Seitz <ludwig@sics.se>
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:24.0) Gecko/20100101 Thunderbird/24.6.0
MIME-Version: 1.0
To: ace@ietf.org
References: <34966E97BE8AD64EAE9D3D6E4DEE36F258177EE3@SZXEMA501-MBS.china.huawei.com> <53C4C5D6.30503@sics.se> <19173.1405814259@sandelman.ca>
In-Reply-To: <19173.1405814259@sandelman.ca>
Content-Type: multipart/signed; protocol="application/pkcs7-signature"; micalg=sha1; boundary="------------ms060000050109070609050302"
X-Bayes-Prob: 0.0001 (Score 0, tokens from: outbound, outbound-sics-se:default, sics-se:default, base:default, @@RPTN)
X-p0f-Info: os=Solaris 10, link=Ethernet or modem
X-CanIt-Geo: ip=204.101.190.178; country=CA; region=Ontario; city=Toronto; latitude=43.6441; longitude=-79.3801; http://maps.google.com/maps?q=43.6441,-79.3801&z=6
X-CanItPRO-Stream: outbound-sics-se:outbound (inherits from outbound-sics-se:default, sics-se:default, base:default)
X-Canit-Stats-ID: 09MsBPjav - 41daa6a2bd40 - 20140720
X-Antispam-Training-Forget: https://canit.sunet.se/canit/b.php?i=09MsBPjav&m=41daa6a2bd40&t=20140720&c=f
X-Antispam-Training-Nonspam: https://canit.sunet.se/canit/b.php?i=09MsBPjav&m=41daa6a2bd40&t=20140720&c=n
X-Antispam-Training-Spam: https://canit.sunet.se/canit/b.php?i=09MsBPjav&m=41daa6a2bd40&t=20140720&c=s
X-CanIt-Archive-Cluster: PfMRe/vJWMiXwM2YIH5BVExnUnw
X-Scanned-By: CanIt (www . roaringpenguin . com) on 192.36.171.201
Archived-At: http://mailarchive.ietf.org/arch/msg/ace/GNntUv_p_1XZR1dDh9wgofKC12E
Subject: Re: [Ace] Context-based Authorization
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sun, 20 Jul 2014 13:51:26 -0000

This is a cryptographically signed message in MIME format.

--------------ms060000050109070609050302
Content-Type: text/plain; charset=ISO-8859-1; format=flowed
Content-Transfer-Encoding: quoted-printable

On 07/20/2014 01:57 AM, Michael Richardson wrote:
>
> Ludwig Seitz <ludwig@sics.se> wrote:
>      >> For U3.1, how to define an emergency context?
>
>      > In medical access control scenarios there is the concept of
>      > "break-the-glass policies". This means that medical personnel ca=
n just
>      > declare an emergency context (similar to breaking the glass to a=
ccess a
>      > fire alarm, see attached image) in order to get additional
>      > authorization. This declaration is then subject to auditing at a=
 later
>      > point, to ensure that there really was an emergency situation.
>
> I immediately thought of the "break-the-glass" concept as well, and the=
n
> went to read 3.1 again.  As written, 3.1 doesn't seem to imply that to =
me:
>       U3.1 John must be able to pre-configure access rights to the
>       position data for persons or groups, in the context of an
>       emergency.
>
> Let me explain what I interpret as "break-the-glass".
> 1) anyone near the glass can break it, not just some set of persons/gro=
ups.
>

I totally agree with the other two points. It is in this one our=20
interpretations differ. When I worked for Swedish National Healthcare,=20
they had me define a break-the-glass access control policy for Swedish=20
medical doctors and paramedics. The crucial information missing here is=20
perhaps that there is a nationwide identification card (using X.509=20
certificates) [1] for medical practitioners in Sweden. With that they=20
can authenticate at any terminal in a hospital and access medical files.

Normally the access control policy would only allow access to a medical=20
file if you had a care relation (an attribute linking patients to=20
medical personnel), but when you "broke the glass" you could access any=20
file.

The difference to what you suggested ("John" simply is going
to want to configure that his spouse, children and best friend can grant
access to whomever needs it, when they see an emergency.) to what I=20
meant is that in my case a paramedic first responder could immediately=20
"break-the-glass" and access John's heart rate monitor without first=20
having to get permission by some relative of John's.

So yes I meant "bread-the-glass" and I should have written so in the use =

case document. I'll try to clarify in the next update.


/Ludwig


[1] For those who understand Swedish, information on the identification=20
card for medical practitioners:=20
http://www.e-identitet.se/index.php?page=3Dvard_omsorg_general

--=20
Ludwig Seitz, PhD
SICS Swedish ICT AB
Ideon Science Park
Building Beta 2
Scheelev=E4gen 17
SE-223 70 Lund

Phone +46(0)70-349 92 51
http://www.sics.se


--------------ms060000050109070609050302
Content-Type: application/pkcs7-signature; name="smime.p7s"
Content-Transfer-Encoding: base64
Content-Disposition: attachment; filename="smime.p7s"
Content-Description: S/MIME Cryptographic Signature

MIAGCSqGSIb3DQEHAqCAMIACAQExCzAJBgUrDgMCGgUAMIAGCSqGSIb3DQEHAQAAoIIMVDCC
BhgwggUAoAMCAQICAwiRTjANBgkqhkiG9w0BAQsFADCBjDELMAkGA1UEBhMCSUwxFjAUBgNV
BAoTDVN0YXJ0Q29tIEx0ZC4xKzApBgNVBAsTIlNlY3VyZSBEaWdpdGFsIENlcnRpZmljYXRl
IFNpZ25pbmcxODA2BgNVBAMTL1N0YXJ0Q29tIENsYXNzIDEgUHJpbWFyeSBJbnRlcm1lZGlh
dGUgQ2xpZW50IENBMB4XDTE0MDEwNzA3MjgzNVoXDTE1MDEwNzEyNTgyMlowODEXMBUGA1UE
AwwObHVkd2lnQHNpY3Muc2UxHTAbBgkqhkiG9w0BCQEWDmx1ZHdpZ0BzaWNzLnNlMIIBIjAN
BgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAnLm1tc30QxHa9wtdVjC3NgxjLJicnccm0HD+
1X16kPMKGvwps8F1oDhYn7jXIe46p1AuJMzLK0GIioE4JwxCFGdvpz7cg2xyTyrdBVUzSqez
Dfqt4FOJq6hrdrIMS8MHEzl7Jk02gv9cTn/pHQvDpkiThRpbSLU5mlMqtEQ8gDQY5YyBX0Mv
5qculV08I2JU8HEeTt1oeqhvBImgQfOVYMDatHlWHUVVrmYd6iIo+cuiUGd5kiA0XuaLYX0E
oCoao/z5Wg9U0sQlx0hl4r96Q+NdoZZ1prfts3qtyBzJ2hu135aikigzJ6sueWHv/jbISUek
tOMm0xkx1GOqqWtEAwIDAQABo4IC1DCCAtAwCQYDVR0TBAIwADALBgNVHQ8EBAMCBLAwHQYD
VR0lBBYwFAYIKwYBBQUHAwIGCCsGAQUFBwMEMB0GA1UdDgQWBBRZmjjBh8N3klra+mVQgC00
pl68ZTAfBgNVHSMEGDAWgBRTcu2SnODaywFcfH6WNU7y1LhRgjAZBgNVHREEEjAQgQ5sdWR3
aWdAc2ljcy5zZTCCAUwGA1UdIASCAUMwggE/MIIBOwYLKwYBBAGBtTcBAgMwggEqMC4GCCsG
AQUFBwIBFiJodHRwOi8vd3d3LnN0YXJ0c3NsLmNvbS9wb2xpY3kucGRmMIH3BggrBgEFBQcC
AjCB6jAnFiBTdGFydENvbSBDZXJ0aWZpY2F0aW9uIEF1dGhvcml0eTADAgEBGoG+VGhpcyBj
ZXJ0aWZpY2F0ZSB3YXMgaXNzdWVkIGFjY29yZGluZyB0byB0aGUgQ2xhc3MgMSBWYWxpZGF0
aW9uIHJlcXVpcmVtZW50cyBvZiB0aGUgU3RhcnRDb20gQ0EgcG9saWN5LCByZWxpYW5jZSBv
bmx5IGZvciB0aGUgaW50ZW5kZWQgcHVycG9zZSBpbiBjb21wbGlhbmNlIG9mIHRoZSByZWx5
aW5nIHBhcnR5IG9ibGlnYXRpb25zLjA2BgNVHR8ELzAtMCugKaAnhiVodHRwOi8vY3JsLnN0
YXJ0c3NsLmNvbS9jcnR1MS1jcmwuY3JsMIGOBggrBgEFBQcBAQSBgTB/MDkGCCsGAQUFBzAB
hi1odHRwOi8vb2NzcC5zdGFydHNzbC5jb20vc3ViL2NsYXNzMS9jbGllbnQvY2EwQgYIKwYB
BQUHMAKGNmh0dHA6Ly9haWEuc3RhcnRzc2wuY29tL2NlcnRzL3N1Yi5jbGFzczEuY2xpZW50
LmNhLmNydDAjBgNVHRIEHDAahhhodHRwOi8vd3d3LnN0YXJ0c3NsLmNvbS8wDQYJKoZIhvcN
AQELBQADggEBAHqEYmtWr83S+iLXE97KBnHJZiMr6PMuLKxmh0o6UJJwKgf+KTP2czxRnPSI
+whuqfQZdmz6g3A2K8AooMU0RXrzncnX1c4826APdnXkRxnGQxtZXI1wuhPn4z7iDKZ6ij9u
K5Pfn10JL/ERDig2qJQbqvhtIAx0RY7y7r+hLMvgXVq9mf3WRJYmGQeFW+N9t5Z1eEwG4m9R
KAZm0fnfeDn/Ai4kmxTckBH7dZwW2lTtwQqQ4su+PGCJ0e9ndBLpvTqaYGSAl+L7PO7vxPhS
/cS67Xa6BtnYJLTr3MaGXaN+CEUFSfwQHa9DKcAqh3kldErI3kCvnot0CigBl4aILOEwggY0
MIIEHKADAgECAgEeMA0GCSqGSIb3DQEBBQUAMH0xCzAJBgNVBAYTAklMMRYwFAYDVQQKEw1T
dGFydENvbSBMdGQuMSswKQYDVQQLEyJTZWN1cmUgRGlnaXRhbCBDZXJ0aWZpY2F0ZSBTaWdu
aW5nMSkwJwYDVQQDEyBTdGFydENvbSBDZXJ0aWZpY2F0aW9uIEF1dGhvcml0eTAeFw0wNzEw
MjQyMTAxNTVaFw0xNzEwMjQyMTAxNTVaMIGMMQswCQYDVQQGEwJJTDEWMBQGA1UEChMNU3Rh
cnRDb20gTHRkLjErMCkGA1UECxMiU2VjdXJlIERpZ2l0YWwgQ2VydGlmaWNhdGUgU2lnbmlu
ZzE4MDYGA1UEAxMvU3RhcnRDb20gQ2xhc3MgMSBQcmltYXJ5IEludGVybWVkaWF0ZSBDbGll
bnQgQ0EwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDHCYPMzi3YGrEppC4Tq5a+
ijKDjKaIQZZVR63UbxIP6uq/I0fhCu+cQhoUfE6ERKKnu8zPf1Jwuk0tsvVCk6U9b+0UjM0d
Lep3ZdE1gblK/1FwYT5Pipsu2yOMluLqwvsuz9/9f1+1PKHG/FaR/wpbfuIqu54qzHDYeqiU
fsYzoVflR80DAC7hmJ+SmZnNTWyUGHJbBpA8Q89lGxahNvuryGaC/o2/ceD2uYDX9U8Eg5Dp
IpGQdcbQeGarV04WgAUjjXX5r/2dabmtxWMZwhZna//jdiSyrrSMTGKkDiXm6/3/4ebfeZuC
YKzN2P8O2F/Xe2AC/Y7zeEsnR7FOp+uXAgMBAAGjggGtMIIBqTAPBgNVHRMBAf8EBTADAQH/
MA4GA1UdDwEB/wQEAwIBBjAdBgNVHQ4EFgQUU3Ltkpzg2ssBXHx+ljVO8tS4UYIwHwYDVR0j
BBgwFoAUTgvvGqRAW6UXaYcwyjRoQ9BBrvIwZgYIKwYBBQUHAQEEWjBYMCcGCCsGAQUFBzAB
hhtodHRwOi8vb2NzcC5zdGFydHNzbC5jb20vY2EwLQYIKwYBBQUHMAKGIWh0dHA6Ly93d3cu
c3RhcnRzc2wuY29tL3Nmc2NhLmNydDBbBgNVHR8EVDBSMCegJaAjhiFodHRwOi8vd3d3LnN0
YXJ0c3NsLmNvbS9zZnNjYS5jcmwwJ6AloCOGIWh0dHA6Ly9jcmwuc3RhcnRzc2wuY29tL3Nm
c2NhLmNybDCBgAYDVR0gBHkwdzB1BgsrBgEEAYG1NwECATBmMC4GCCsGAQUFBwIBFiJodHRw
Oi8vd3d3LnN0YXJ0c3NsLmNvbS9wb2xpY3kucGRmMDQGCCsGAQUFBwIBFihodHRwOi8vd3d3
LnN0YXJ0c3NsLmNvbS9pbnRlcm1lZGlhdGUucGRmMA0GCSqGSIb3DQEBBQUAA4ICAQAKgwh9
eKssBly4Y4xerhy5I3dNoXHYfYa8PlVLL/qtXnkFgdtY1o95CfegFJTwqBBmf8pyTUnFsukD
FUI22zF5bVHzuJ+GxhnSqN2sD1qetbYwBYK2iyYA5Pg7Er1A+hKMIzEzcduRkIMmCeUTyMyi
kfbUFvIBivtvkR8ZFAk22BZy+pJfAoedO61HTz4qSfQoCRcLN5A0t4DkuVhTMXIzuQ8Cnykh
ExD6x4e6ebIbrjZLb7L+ocR0y4YjCl/Pd4MXU91y0vTipgr/O75CDUHDRHCCKBVmz/Rzkc/b
970MEeHt5LC3NiWTgBSvrLEuVzBKM586YoRD9Dy3OHQgWI270g+5MYA8GfgI/EPT5G7xPbCD
z+zjdH89PeR3U4So4lSXur6H6vp+m9TQXPF3a0LwZrp8MQ+Z77U1uL7TelWO5lApsbAonrqA
SfTpaprFVkL4nyGH+NHST2ZJPWIBk81i6Vw0ny0qZW2Niy/QvVNKbb43A43ny076khXO7cNb
BIRdJ/6qQNq9Bqb5C0Q5nEsFcj75oxQRqlKf6TcvGbjxkJh8BYtv9ePsXklAxtm8J7GCUBth
HSQgepbkOexhJ0wP8imUkyiPHQ0GvEnd83129fZjoEhdGwXV27ioRKbj/cIq7JRXun0NbeY+
UdMYu9jGfIpDLtUUGSgsg2zMGs5R4jGCA90wggPZAgEBMIGUMIGMMQswCQYDVQQGEwJJTDEW
MBQGA1UEChMNU3RhcnRDb20gTHRkLjErMCkGA1UECxMiU2VjdXJlIERpZ2l0YWwgQ2VydGlm
aWNhdGUgU2lnbmluZzE4MDYGA1UEAxMvU3RhcnRDb20gQ2xhc3MgMSBQcmltYXJ5IEludGVy
bWVkaWF0ZSBDbGllbnQgQ0ECAwiRTjAJBgUrDgMCGgUAoIICHTAYBgkqhkiG9w0BCQMxCwYJ
KoZIhvcNAQcBMBwGCSqGSIb3DQEJBTEPFw0xNDA3MjAxMzUxMDlaMCMGCSqGSIb3DQEJBDEW
BBSi7/5tvsz6Z6tsKi8BsLA30S4Y9zBsBgkqhkiG9w0BCQ8xXzBdMAsGCWCGSAFlAwQBKjAL
BglghkgBZQMEAQIwCgYIKoZIhvcNAwcwDgYIKoZIhvcNAwICAgCAMA0GCCqGSIb3DQMCAgFA
MAcGBSsOAwIHMA0GCCqGSIb3DQMCAgEoMIGlBgkrBgEEAYI3EAQxgZcwgZQwgYwxCzAJBgNV
BAYTAklMMRYwFAYDVQQKEw1TdGFydENvbSBMdGQuMSswKQYDVQQLEyJTZWN1cmUgRGlnaXRh
bCBDZXJ0aWZpY2F0ZSBTaWduaW5nMTgwNgYDVQQDEy9TdGFydENvbSBDbGFzcyAxIFByaW1h
cnkgSW50ZXJtZWRpYXRlIENsaWVudCBDQQIDCJFOMIGnBgsqhkiG9w0BCRACCzGBl6CBlDCB
jDELMAkGA1UEBhMCSUwxFjAUBgNVBAoTDVN0YXJ0Q29tIEx0ZC4xKzApBgNVBAsTIlNlY3Vy
ZSBEaWdpdGFsIENlcnRpZmljYXRlIFNpZ25pbmcxODA2BgNVBAMTL1N0YXJ0Q29tIENsYXNz
IDEgUHJpbWFyeSBJbnRlcm1lZGlhdGUgQ2xpZW50IENBAgMIkU4wDQYJKoZIhvcNAQEBBQAE
ggEAZaaAaxbAkEiZB0mwnJ5MTq6fp5J9lLzXSeJglfg387HxWoVpww2ooOiS2srHmZNUqHyT
5Ff3RKX4X4rXBrYZ1cOsjWI+pYBlIVRbF98iqbjBurfoDigGVMyR2ww5Wn9wAYFW/iTM7NkT
2VKjNPe2hGGsZpQ96ajfNTw2NiuviJuY+IrGG6SYCwFf65oaL7WlWYRqVHrpEeo+e1z/ojWA
fyoU/aqz5L/7fFi9YDeDypSs0B7Ieu391xmaiyWadb09eKj8xaacHsRLSPl5/gqFjvdLRKw6
ePzbcxkNIeehKH0R1fT+qoZ3npiFTVFhjfYgHvzxoEt6QCAjO8I1U78vogAAAAAAAA==
--------------ms060000050109070609050302--


From nobody Sun Jul 20 07:33:50 2014
Return-Path: <mcr@sandelman.ca>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id CA5B41A0AEA for <ace@ietfa.amsl.com>; Sun, 20 Jul 2014 07:33:48 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.892
X-Spam-Level: 
X-Spam-Status: No, score=-1.892 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001, T_TVD_MIME_NO_HEADERS=0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id LUAi1Zcwuroy for <ace@ietfa.amsl.com>; Sun, 20 Jul 2014 07:33:46 -0700 (PDT)
Received: from tuna.sandelman.ca (tuna.sandelman.ca [209.87.249.19]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id CA42B1A0AE7 for <ace@ietf.org>; Sun, 20 Jul 2014 07:33:46 -0700 (PDT)
Received: from sandelman.ca (obiwan.sandelman.ca [IPv6:2607:f0b0:f:2::247]) by tuna.sandelman.ca (Postfix) with ESMTP id 120552002B; Sun, 20 Jul 2014 10:35:17 -0400 (EDT)
Received: by sandelman.ca (Postfix, from userid 179) id B432963B0E; Sun, 20 Jul 2014 10:33:45 -0400 (EDT)
Received: from sandelman.ca (localhost [127.0.0.1]) by sandelman.ca (Postfix) with ESMTP id A49BA63AED; Sun, 20 Jul 2014 10:33:45 -0400 (EDT)
From: Michael Richardson <mcr+ietf@sandelman.ca>
To: Ludwig Seitz <ludwig@sics.se>
In-Reply-To: <53CBC94D.3040407@sics.se>
References: <34966E97BE8AD64EAE9D3D6E4DEE36F258177EE3@SZXEMA501-MBS.china.huawei.com> <53C4C5D6.30503@sics.se> <19173.1405814259@sandelman.ca> <53CBC94D.3040407@sics.se>
X-Mailer: MH-E 8.2; nmh 1.3-dev; GNU Emacs 23.4.1
X-Face: $\n1pF)h^`}$H>Hk{L"x@)JS7<%Az}5RyS@k9X%29-lHB$Ti.V>2bi.~ehC0; <'$9xN5Ub# z!G,p`nR&p7Fz@^UXIn156S8.~^@MJ*mMsD7=QFeq%AL4m<nPbLgmtKK-5dC@#:k
MIME-Version: 1.0
Content-Type: multipart/signed; boundary="=-=-="; micalg=pgp-sha1; protocol="application/pgp-signature"
Date: Sun, 20 Jul 2014 10:33:45 -0400
Message-ID: <7432.1405866825@sandelman.ca>
Sender: mcr@sandelman.ca
Archived-At: http://mailarchive.ietf.org/arch/msg/ace/sOW1fGJOTUle4A6dYhWuHbyF5J4
Cc: ace@ietf.org
Subject: Re: [Ace] Context-based Authorization
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sun, 20 Jul 2014 14:33:49 -0000

--=-=-=


Ludwig Seitz <ludwig@sics.se> wrote:
    > The difference to what you suggested ("John" simply is going to want to
    > configure that his spouse, children and best friend can grant access to
    > whomever needs it, when they see an emergency.) to what I meant is that
    > in my case a paramedic first responder could immediately
    > "break-the-glass" and access John's heart rate monitor without first
    > having to get permission by some relative of John's.

okay, so it's good that we established that the requirement was mis-written.
I'm struggling to imagine a break-the-glass protocol which is first responder
to medical device, and which can operate securely "offline", and yet can not
be easily abused.

I can easily see how one can break the glass at a full computer terminal in a
hospital where the entire system is online (and is likely sufficiently
replicated and provisioned with backup generators...)

Are there some examples in the literature?

--
Michael Richardson <mcr+IETF@sandelman.ca>, Sandelman Software Works
 -= IPv6 IoT consulting =-




--=-=-=
Content-Type: application/pgp-signature

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iQEVAwUBU8vTR4CLcPvd0N1lAQIH1ggAhPPLK7wHl2HYaMoLnWiHW76U5ziqJw/9
nXS5gVmczFUkH/ftumdEcHl1JloyMazfEb39H85pIH2NGDqvXKsSbApzuOkvMp8i
Grv/IikcTjkwy48lEFjtYpI1kJFOE7u01+GNfnkIoWG/KtbsjxmN3jIc9Q5T2mdV
kUHHMQAhTzeYZTTeKQfFJ4G+A9GAjTI4jQwAut6sWohaUeJJ090cbIkHVwXWJ3/1
ppcMPhpIZ4uOk7SzyjAb2XV4Ya/xdq86fCB07/Q2kFCRYyAJ9o5HCzXCad15umxP
00zZhUlwIbIYO4KGU7tVpw5rcxrvn0RblAJeEurTYwUlVEf7sGmgKQ==
=BWjF
-----END PGP SIGNATURE-----
--=-=-=--


From nobody Mon Jul 21 07:46:54 2014
Return-Path: <hannes.tschofenig@gmx.net>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id E38691A002A for <ace@ietfa.amsl.com>; Mon, 21 Jul 2014 07:46:52 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.901
X-Spam-Level: 
X-Spam-Status: No, score=-1.901 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, FREEMAIL_FROM=0.001, RCVD_IN_DNSWL_NONE=-0.0001, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id tC6L_okQWKEC for <ace@ietfa.amsl.com>; Mon, 21 Jul 2014 07:46:51 -0700 (PDT)
Received: from mout.gmx.net (mout.gmx.net [212.227.17.20]) (using TLSv1.2 with cipher DHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 623071A0040 for <Ace@ietf.org>; Mon, 21 Jul 2014 07:46:48 -0700 (PDT)
Received: from [192.168.10.129] ([31.133.166.25]) by mail.gmx.com (mrgmx101) with ESMTPSA (Nemesis) id 0MT74k-1WzuvA1WvW-00S9ba for <Ace@ietf.org>; Mon, 21 Jul 2014 16:46:46 +0200
Message-ID: <53CD27D3.1010709@gmx.net>
Date: Mon, 21 Jul 2014 16:46:43 +0200
From: Hannes Tschofenig <hannes.tschofenig@gmx.net>
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:24.0) Gecko/20100101 Thunderbird/24.6.0
MIME-Version: 1.0
To: "Ace@ietf.org" <Ace@ietf.org>
X-Enigmail-Version: 1.5.2
OpenPGP: id=4D776BC9
Content-Type: multipart/signed; micalg=pgp-sha512; protocol="application/pgp-signature"; boundary="74E65kOCVCCvWM592KiHABkXeMt4QED69"
X-Provags-ID: V03:K0:uiLBm6NVQVNnvcMc4m2wGguEPmwcmLpyalV2+gsus9h/cZyEzbu nCSoZi0v/d5fmuohh5GxQiu4XQVeZetGMvbvyOLnAQhpxqbeXIOIHJ2tJsnIviEbBlKoMN6 bKDOFcftjXhww3qLJ/OU1Y50hIxgkMr3ekHRdpIBL/m2p5BsHOTA8YIw+0fXIRbs1ivv5Hw Wi/uzoCuop96YPNYj849w==
Archived-At: http://mailarchive.ietf.org/arch/msg/ace/-DtRoj3jRaBW3m3DZA0W73EdgxI
Subject: [Ace] Call for adoption on draft-seitz-ace-usecases-01 ("ACE Use Cases")
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 21 Jul 2014 14:46:53 -0000

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--74E65kOCVCCvWM592KiHABkXeMt4QED69
Content-Type: text/plain; charset=ISO-8859-1
Content-Transfer-Encoding: quoted-printable

Hi all,

we have a milestone for a use case document in ACe and
draft-seitz-ace-usecases is a promising candidate for this milestone.

This email is a call for adoption for draft-seitz-ace-usecases-01.

Please respond if you support, or object to, the adoption of this
document as the basis for this work item. Deadline for your response:
31. July 2014

Ciao
Hannes & Kepeng


--74E65kOCVCCvWM592KiHABkXeMt4QED69
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
Content-Disposition: attachment; filename="signature.asc"

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1
Comment: GPGTools - http://gpgtools.org
Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/

iQEcBAEBCgAGBQJTzSfTAAoJEGhJURNOOiAtkq8H/RYPxZvOoNBbSXj4eXcT/DDR
ORb3QFQfCJyfk7F6w13uaDO1D8sDLUMSAnHjcDfAvDyJtSPBvHxnNZnrFEHVhQJ7
zX5tiJCAD2R2y/JXJn/PCdVL4dHn+DcmuBhzcHbHUQ1n0iZqhuDbTgFIwzfjVA4t
O6Lq4x+twy9eMfwJIDeptiNH7RrBXAwLwSVDPQGV3XfohP3u8jbbuFHpuAh4lEaf
3YhkVBelFUNm6eLppnWlVw8+8ewsdwTq8kAHgxicuNuFqllw8NGalIItTK2/9Qlw
sOUe5iCSjqTm796ptGRA57ZbWct6ejPF19N3JABC9cif2Fz+ULybhcO5pCbb7FM=
=z592
-----END PGP SIGNATURE-----

--74E65kOCVCCvWM592KiHABkXeMt4QED69--


From nobody Mon Jul 21 09:46:27 2014
Return-Path: <mcr@sandelman.ca>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 41ABD1A0059 for <ace@ietfa.amsl.com>; Mon, 21 Jul 2014 09:46:25 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.892
X-Spam-Level: 
X-Spam-Status: No, score=-1.892 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001, T_TVD_MIME_NO_HEADERS=0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id aG2-18CnE6zX for <ace@ietfa.amsl.com>; Mon, 21 Jul 2014 09:46:23 -0700 (PDT)
Received: from tuna.sandelman.ca (tuna.sandelman.ca [IPv6:2607:f0b0:f:3:216:3eff:fe7c:d1f3]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 214751A00CD for <Ace@ietf.org>; Mon, 21 Jul 2014 09:46:23 -0700 (PDT)
Received: from sandelman.ca (obiwan.sandelman.ca [209.87.249.21]) by tuna.sandelman.ca (Postfix) with ESMTP id 00F5B20029 for <Ace@ietf.org>; Mon, 21 Jul 2014 12:47:56 -0400 (EDT)
Received: by sandelman.ca (Postfix, from userid 179) id E50DF63B0E; Mon, 21 Jul 2014 12:46:21 -0400 (EDT)
Received: from sandelman.ca (localhost [127.0.0.1]) by sandelman.ca (Postfix) with ESMTP id C7F7163B0A for <Ace@ietf.org>; Mon, 21 Jul 2014 12:46:21 -0400 (EDT)
From: Michael Richardson <mcr+ietf@sandelman.ca>
To: "Ace\@ietf.org" <Ace@ietf.org>
In-Reply-To: <53CD27D3.1010709@gmx.net>
References: <53CD27D3.1010709@gmx.net>
X-Mailer: MH-E 8.2; nmh 1.3-dev; GNU Emacs 23.4.1
X-Face: $\n1pF)h^`}$H>Hk{L"x@)JS7<%Az}5RyS@k9X%29-lHB$Ti.V>2bi.~ehC0; <'$9xN5Ub# z!G,p`nR&p7Fz@^UXIn156S8.~^@MJ*mMsD7=QFeq%AL4m<nPbLgmtKK-5dC@#:k
MIME-Version: 1.0
Content-Type: multipart/signed; boundary="=-=-="; micalg=pgp-sha1; protocol="application/pgp-signature"
Date: Mon, 21 Jul 2014 12:46:21 -0400
Message-ID: <11558.1405961181@sandelman.ca>
Sender: mcr@sandelman.ca
Archived-At: http://mailarchive.ietf.org/arch/msg/ace/B_xMycQbk7PdqECPAv83VtldrYs
Subject: Re: [Ace] Call for adoption on draft-seitz-ace-usecases-01 ("ACE Use Cases")
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 21 Jul 2014 16:46:25 -0000

--=-=-=


Hannes Tschofenig <hannes.tschofenig@gmx.net> wrote:
    > we have a milestone for a use case document in ACe and
    > draft-seitz-ace-usecases is a promising candidate for this milestone.

    > This email is a call for adoption for draft-seitz-ace-usecases-01.

    > Please respond if you support, or object to, the adoption of this
    > document as the basis for this work item. Deadline for your response:
    > 31. July 2014

I have read the document and I agree that it a good place to start.

--
Michael Richardson <mcr+IETF@sandelman.ca>, Sandelman Software Works
 -= IPv6 IoT consulting =-




--=-=-=
Content-Type: application/pgp-signature

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iQEVAwUBU81D24CLcPvd0N1lAQIGFwgAlKztoLwOcFECN9nyrfgfgp+BwPY+6I2K
w0XuUoWYuWjTVBV4lNp65HeA4XwJNveq7L/Pp+ybxAbplFuQvL/gDKKhVbiAgf3m
eex/cjJt08XLujLSl6wFLddzSYK0CQoh//cFMpKCx3SdSNrzgGIkW7DurwLmagxt
NpHSFMdL3Y/d64BQq3MBJdLzfqqnbOHNA39U+U+iHRo3DdIXwXlz4GfFAzp8mFkS
YeMoHkAKu9Nt+g9PSvmhiaXUoDMXmBqxPOm7bstQtjkr9MBWo8qls7DqBzJSPD/q
I1xVGxkC7aUIgBy19JOQQ3Zeb19WEqRtNrEqh+gcn24xmTjpf4fTZg==
=54v5
-----END PGP SIGNATURE-----
--=-=-=--


From nobody Mon Jul 21 13:31:26 2014
Return-Path: <stokcons@xs4all.nl>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 9D4E51A037E for <ace@ietfa.amsl.com>; Mon, 21 Jul 2014 13:31:25 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: 2.093
X-Spam-Level: **
X-Spam-Status: No, score=2.093 tagged_above=-999 required=5 tests=[BAYES_20=-0.001, HELO_EQ_NL=0.55, HOST_EQ_NL=1.545, RCVD_IN_DNSWL_NONE=-0.0001, RP_MATCHES_RCVD=-0.001] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id NdoshXAbYaoh for <ace@ietfa.amsl.com>; Mon, 21 Jul 2014 13:31:24 -0700 (PDT)
Received: from smtp-vbr9.xs4all.nl (smtp-vbr9.xs4all.nl [194.109.24.29]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id D88541A0354 for <ace@ietf.org>; Mon, 21 Jul 2014 13:31:23 -0700 (PDT)
Received: from roundcube.xs4all.nl (roundcube5.xs4all.net [194.109.20.203]) by smtp-vbr9.xs4all.nl (8.13.8/8.13.8) with ESMTP id s6LKVLjR055022 for <ace@ietf.org>; Mon, 21 Jul 2014 22:31:21 +0200 (CEST) (envelope-from stokcons@xs4all.nl)
Received: from wireless-v6.meeting.ietf.org ([2001:67c:370:160:5c1a:8522:9e45:cb99]) by roundcube.xs4all.nl with HTTP (HTTP/1.1 POST); Mon, 21 Jul 2014 22:31:21 +0200
MIME-Version: 1.0
Content-Type: text/plain; charset=US-ASCII; format=flowed
Content-Transfer-Encoding: 7bit
Date: Mon, 21 Jul 2014 22:31:21 +0200
From: peter van der Stok <stokcons@xs4all.nl>
To: ace@ietf.org
Organization: vanderstok consultancy
Mail-Reply-To: consultancy@vanderstok.org
Message-ID: <22e34c4f285de61ae5bacde6d4c93b46@xs4all.nl>
X-Sender: stokcons@xs4all.nl (M05DQ7qPxOsz6+jYmJyzkCLnBR9p3CXb)
User-Agent: XS4ALL Webmail
X-Virus-Scanned: by XS4ALL Virus Scanner
Archived-At: http://mailarchive.ietf.org/arch/msg/ace/OQ2xfHehx73VcXGsiX-jgt1xvBE
Subject: [Ace] Fwd: Re: Call for adoption on draft-seitz-ace-usecases-01 ("ACE Use Cases")
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
Reply-To: consultancy@vanderstok.org
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 21 Jul 2014 20:31:25 -0000

I support the adoption of this document with the current selection of 
use cases.

Peter

Hannes Tschofenig schreef op 2014-07-21 16:46:
> Hi all,
> 
> we have a milestone for a use case document in ACe and
> draft-seitz-ace-usecases is a promising candidate for this milestone.
> 
> This email is a call for adoption for draft-seitz-ace-usecases-01.
> 
> Please respond if you support, or object to, the adoption of this
> document as the basis for this work item. Deadline for your response:
> 31. July 2014
> 
> Ciao
> Hannes & Kepeng
> 
> 
> _______________________________________________
> Ace mailing list
> Ace@ietf.org
> https://www.ietf.org/mailman/listinfo/ace


From nobody Tue Jul 22 06:46:22 2014
Return-Path: <hannes.tschofenig@gmx.net>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 5DE5B1B2812 for <ace@ietfa.amsl.com>; Tue, 22 Jul 2014 06:46:21 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.901
X-Spam-Level: 
X-Spam-Status: No, score=-1.901 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, FREEMAIL_FROM=0.001, RCVD_IN_DNSWL_NONE=-0.0001, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 8KmNFqUdG2VV for <ace@ietfa.amsl.com>; Tue, 22 Jul 2014 06:46:20 -0700 (PDT)
Received: from mout.gmx.net (mout.gmx.net [212.227.17.22]) (using TLSv1.2 with cipher DHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 91B711B284A for <Ace@ietf.org>; Tue, 22 Jul 2014 06:46:19 -0700 (PDT)
Received: from [192.168.10.130] ([31.133.166.25]) by mail.gmx.com (mrgmx101) with ESMTPSA (Nemesis) id 0Lubnw-1WRck434zY-00zqDR; Tue, 22 Jul 2014 15:46:17 +0200
Message-ID: <53CE6B26.1030100@gmx.net>
Date: Tue, 22 Jul 2014 15:46:14 +0200
From: Hannes Tschofenig <hannes.tschofenig@gmx.net>
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:24.0) Gecko/20100101 Thunderbird/24.6.0
MIME-Version: 1.0
To: "Ace@ietf.org" <Ace@ietf.org>
X-Enigmail-Version: 1.5.2
OpenPGP: id=4D776BC9
Content-Type: multipart/signed; micalg=pgp-sha512; protocol="application/pgp-signature"; boundary="2Crg6AjvSsQ44K9ufbfI2fH0ewJj6BT6w"
X-Provags-ID: V03:K0:8k4xBG4Ku7rVR4ALLxiqjbhvKW/tcYVksA/0Z4hqxqaGIB30tZ+ tevKMfaj6pUuTX2/kMRjn2962WBN0aFLxDF+LesvNChS+9QeUWbia6se+kBJ6QodZp7nozw 8q0iAgpZiLVmCKArfJCtzwqTNBOQ7j/buX4Q/QLjcNhjyh3v/aaCrYM8D2TlVQDh7flUzuF ZmGNBHITxJh7+Rpohwn3A==
Archived-At: http://mailarchive.ietf.org/arch/msg/ace/NUYP0qEhQSEXWyObDKGKnm59vqQ
Cc: Michael.Koster@arm.com
Subject: [Ace] ARM Hackaton (Today)
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 22 Jul 2014 13:46:21 -0000

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--2Crg6AjvSsQ44K9ufbfI2fH0ewJj6BT6w
Content-Type: text/plain; charset=ISO-8859-1
Content-Transfer-Encoding: quoted-printable

Hi all,

in case you are not planning to attend the social event tonight and want
to play around with ARM-based Internet of Things gear please come to
"Confederation 3" at 7pm today.

Michael and I will will show you some of our ARM-based development
boards, our online development platform (mbed.org), and write code to
upload sensor data to a CoAP server.

Ciao
Hannes & Michael


--2Crg6AjvSsQ44K9ufbfI2fH0ewJj6BT6w
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
Content-Disposition: attachment; filename="signature.asc"

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1
Comment: GPGTools - http://gpgtools.org
Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/

iQEcBAEBCgAGBQJTzmsmAAoJEGhJURNOOiAt9nIIAJJrLJ5iy2CbywMxdA1VOVP9
WGBT2ETBWwdywlgaOQaPzPVo5YR/pCnus/0o9eg3VDtPIwy6tqv00FVVKplPngXN
AIJUZF7JTSqHQ7nc1kkZJsM4KGqhSNMXrW0QJGd51pNeaXuyl0bm8mbvmhudrthy
KevA5iCwGnPSaBW4lPEvbgv31eRPdraprOMm7tJ5bjGmF/B7m6aTorzbJrKdK9eX
gwUsGCvDlr/BkoZcI59rd7hVH+mFp3xNBlZKhk107VQy8mGP5eNeRwPj/UaM22Gu
DJw3zlbLopsi9kqmWn3/pM5dhXHZ8gcjGwzSVlub8lCPgvs/HoUJ9YVAp0IRuh8=
=CdA+
-----END PGP SIGNATURE-----

--2Crg6AjvSsQ44K9ufbfI2fH0ewJj6BT6w--


From nobody Wed Jul 23 08:38:54 2014
Return-Path: <mcr@sandelman.ca>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 094C71A00BE for <ace@ietfa.amsl.com>; Wed, 23 Jul 2014 08:38:53 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: 0.108
X-Spam-Level: 
X-Spam-Status: No, score=0.108 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, MIME_NO_TEXT=2, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001, T_TVD_MIME_NO_HEADERS=0.01] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id ytSniNp8eWfu for <ace@ietfa.amsl.com>; Wed, 23 Jul 2014 08:38:52 -0700 (PDT)
Received: from tuna.sandelman.ca (tuna.sandelman.ca [209.87.249.19]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 6A13B1A0058 for <ace@ietf.org>; Wed, 23 Jul 2014 08:38:52 -0700 (PDT)
Received: from sandelman.ca (obiwan.sandelman.ca [IPv6:2607:f0b0:f:2::247]) by tuna.sandelman.ca (Postfix) with ESMTP id 4ADDA20012 for <ace@ietf.org>; Wed, 23 Jul 2014 11:40:33 -0400 (EDT)
Received: by sandelman.ca (Postfix, from userid 179) id 9CA9663B0E; Wed, 23 Jul 2014 11:38:51 -0400 (EDT)
Received: from sandelman.ca (localhost [127.0.0.1]) by sandelman.ca (Postfix) with ESMTP id 85CC363B0A for <ace@ietf.org>; Wed, 23 Jul 2014 11:38:51 -0400 (EDT)
From: Michael Richardson <mcr+ietf@sandelman.ca>
To: ace <ace@ietf.org>
X-Attribution: mcr
X-Mailer: MH-E 8.2; nmh 1.3-dev; GNU Emacs 23.4.1
X-Face: $\n1pF)h^`}$H>Hk{L"x@)JS7<%Az}5RyS@k9X%29-lHB$Ti.V>2bi.~ehC0; <'$9xN5Ub# z!G,p`nR&p7Fz@^UXIn156S8.~^@MJ*mMsD7=QFeq%AL4m<nPbLgmtKK-5dC@#:k
MIME-Version: 1.0
Content-Type: multipart/signed; boundary="=-=-="; micalg=pgp-sha1; protocol="application/pgp-signature"
Date: Wed, 23 Jul 2014 11:38:51 -0400
Message-ID: <15740.1406129931@sandelman.ca>
Sender: mcr@sandelman.ca
Archived-At: http://mailarchive.ietf.org/arch/msg/ace/gOavlTc2YH_j8VZ_odBdw6er3BY
Subject: [Ace] adopting documents
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 23 Jul 2014 15:38:53 -0000

--=-=-=


I have read the following documents:
  draft-gerdes-ace-actors-01    -
  draft-seitz-ace-usecases-01
  draft-seitz-ace-design-considerations-00
  draft-seitz-ace-problem-description-01

I would like to suggest immediate adoption of:
  draft-gerdes-ace-actors-01    -
  draft-seitz-ace-usecases-01   -

(I realize that there is no call for adoption on these as yet).
My feeling is that ace-actors is essentially a really useful terminology
document which are leveraged usefully elsewhere, and I'd like to see it
published as quickly as possible.

If we need to revise draft-seitz-ace-problem-description-01 okay, but we
could adopt it sooner too.

I'm not sure if draft-seitz-ace-design-considerations-00 is for
more than just discussion, so I have no opinion about it.

--
Michael Richardson <mcr+IETF@sandelman.ca>, Sandelman Software Works
 -= IPv6 IoT consulting =-




--=-=-=
Content-Type: application/pgp-signature

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iQEVAwUBU8/XCYCLcPvd0N1lAQIVyAgAjtQ/YxVxT98Lghf1cZ/KZVriQT+ZFDQy
65N8tc9fZcday2N+APbgeqVQDHjx1oG/8oQyjQcNS5hslvAf3TMLFgk7mkWNw1vF
MKKrL5PenBr/XIJnwkAttHuk5qFhMg6RI280k24t0qgk++hIRJ5+saIt2Gkp22qr
brQhRDQ1cBfZ5cSWdOg5gyq0ggvXNCq6dDRmk6Jjn46nokVb14PzDJw5gmc3MC3f
S/vzOCFrqdRTMHajqt3pj0uxmxdv22KdYoTWWPIA3qo8hl3tJ5NLcrW1ToDjWqS3
mnZTpxChQTc5yqUuz/kC+lQZ8hCNa4qCks21LboQYxK0meBxvO0crg==
=DT5t
-----END PGP SIGNATURE-----
--=-=-=--


From nobody Wed Jul 23 10:14:41 2014
Return-Path: <likepeng@huawei.com>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 78E241B2822 for <ace@ietfa.amsl.com>; Wed, 23 Jul 2014 10:14:37 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.413
X-Spam-Level: 
X-Spam-Status: No, score=-1.413 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, CN_BODY_35=0.339, MIME_CHARSET_FARAWAY=2.45, RCVD_IN_DNSWL_MED=-2.3, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Yr2C12s999X7 for <ace@ietfa.amsl.com>; Wed, 23 Jul 2014 10:14:36 -0700 (PDT)
Received: from lhrrgout.huawei.com (lhrrgout.huawei.com [194.213.3.17]) (using TLSv1 with cipher RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id A19781B2B16 for <ace@ietf.org>; Wed, 23 Jul 2014 10:14:34 -0700 (PDT)
Received: from 172.18.7.190 (EHLO lhreml402-hub.china.huawei.com) ([172.18.7.190]) by lhrrg02-dlp.huawei.com (MOS 4.3.7-GA FastPath queued) with ESMTP id BHN42865; Wed, 23 Jul 2014 17:14:33 +0000 (GMT)
Received: from SZXEMA402-HUB.china.huawei.com (10.82.72.34) by lhreml402-hub.china.huawei.com (10.201.5.241) with Microsoft SMTP Server (TLS) id 14.3.158.1; Wed, 23 Jul 2014 18:14:32 +0100
Received: from SZXEMA501-MBS.china.huawei.com ([169.254.2.128]) by SZXEMA402-HUB.china.huawei.com ([10.82.72.34]) with mapi id 14.03.0158.001; Thu, 24 Jul 2014 01:14:27 +0800
From: Likepeng <likepeng@huawei.com>
To: Michael Richardson <mcr+ietf@sandelman.ca>, ace <ace@ietf.org>
Thread-Topic: [Ace] adopting documents
Thread-Index: AQHPpow61IRrMzBX10K0cwJrTiXVk5ut4YaA
Date: Wed, 23 Jul 2014 17:14:26 +0000
Message-ID: <34966E97BE8AD64EAE9D3D6E4DEE36F25817A9D6@SZXEMA501-MBS.china.huawei.com>
References: <15740.1406129931@sandelman.ca>
In-Reply-To: <15740.1406129931@sandelman.ca>
Accept-Language: zh-CN, en-US
Content-Language: zh-CN
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
x-originating-ip: [10.193.87.242]
Content-Type: text/plain; charset="gb2312"
Content-Transfer-Encoding: base64
MIME-Version: 1.0
X-CFilter-Loop: Reflected
Archived-At: http://mailarchive.ietf.org/arch/msg/ace/9wSl8gLh271gk_JiCPTJEDUjOQA
Subject: Re: [Ace] adopting documents
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 23 Jul 2014 17:14:37 -0000

SGkgTWljaGFlbDoNCg0KPihJIHJlYWxpemUgdGhhdCB0aGVyZSBpcyBubyBjYWxsIGZvciBhZG9w
dGlvbiBvbiB0aGVzZSBhcyB5ZXQpLg0KDQpXZSBoYXZlIGFscmVhZHkgY2FsbGVkIGZvciBhZG9w
dGlvbiBmb3IgZHJhZnQtc2VpdHotYWNlLXVzZWNhc2VzLTAxOg0KaHR0cDovL3d3dy5pZXRmLm9y
Zy9tYWlsLWFyY2hpdmUvd2ViL2FjZS9jdXJyZW50L21zZzAwNzQzLmh0bWwNCg0KS2luZCBSZWdh
cmRzDQpLZXBlbmcNCg0KLS0tLS3Tyrz+1K28/i0tLS0tDQq3orz+yMs6IEFjZSBbbWFpbHRvOmFj
ZS1ib3VuY2VzQGlldGYub3JnXSC0+rHtIE1pY2hhZWwgUmljaGFyZHNvbg0Kt6LLzcqxvOQ6IDIw
MTTE6jfUwjIzyNUgMTE6MzkNCsrVvP7IyzogYWNlDQrW98ziOiBbQWNlXSBhZG9wdGluZyBkb2N1
bWVudHMNCg0KDQpJIGhhdmUgcmVhZCB0aGUgZm9sbG93aW5nIGRvY3VtZW50czoNCiAgZHJhZnQt
Z2VyZGVzLWFjZS1hY3RvcnMtMDEgICAgLQ0KICBkcmFmdC1zZWl0ei1hY2UtdXNlY2FzZXMtMDEN
CiAgZHJhZnQtc2VpdHotYWNlLWRlc2lnbi1jb25zaWRlcmF0aW9ucy0wMA0KICBkcmFmdC1zZWl0
ei1hY2UtcHJvYmxlbS1kZXNjcmlwdGlvbi0wMQ0KDQpJIHdvdWxkIGxpa2UgdG8gc3VnZ2VzdCBp
bW1lZGlhdGUgYWRvcHRpb24gb2Y6DQogIGRyYWZ0LWdlcmRlcy1hY2UtYWN0b3JzLTAxICAgIC0N
CiAgZHJhZnQtc2VpdHotYWNlLXVzZWNhc2VzLTAxICAgLQ0KDQooSSByZWFsaXplIHRoYXQgdGhl
cmUgaXMgbm8gY2FsbCBmb3IgYWRvcHRpb24gb24gdGhlc2UgYXMgeWV0KS4NCk15IGZlZWxpbmcg
aXMgdGhhdCBhY2UtYWN0b3JzIGlzIGVzc2VudGlhbGx5IGEgcmVhbGx5IHVzZWZ1bCB0ZXJtaW5v
bG9neSBkb2N1bWVudCB3aGljaCBhcmUgbGV2ZXJhZ2VkIHVzZWZ1bGx5IGVsc2V3aGVyZSwgYW5k
IEknZCBsaWtlIHRvIHNlZSBpdCBwdWJsaXNoZWQgYXMgcXVpY2tseSBhcyBwb3NzaWJsZS4NCg0K
SWYgd2UgbmVlZCB0byByZXZpc2UgZHJhZnQtc2VpdHotYWNlLXByb2JsZW0tZGVzY3JpcHRpb24t
MDEgb2theSwgYnV0IHdlIGNvdWxkIGFkb3B0IGl0IHNvb25lciB0b28uDQoNCkknbSBub3Qgc3Vy
ZSBpZiBkcmFmdC1zZWl0ei1hY2UtZGVzaWduLWNvbnNpZGVyYXRpb25zLTAwIGlzIGZvciBtb3Jl
IHRoYW4ganVzdCBkaXNjdXNzaW9uLCBzbyBJIGhhdmUgbm8gb3BpbmlvbiBhYm91dCBpdC4NCg0K
LS0NCk1pY2hhZWwgUmljaGFyZHNvbiA8bWNyK0lFVEZAc2FuZGVsbWFuLmNhPiwgU2FuZGVsbWFu
IFNvZnR3YXJlIFdvcmtzICAtPSBJUHY2IElvVCBjb25zdWx0aW5nID0tDQoNCg0KDQo=


From nobody Wed Jul 23 10:21:31 2014
Return-Path: <gerdes@tzi.de>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 5A5291B2A64 for <ace@ietfa.amsl.com>; Wed, 23 Jul 2014 10:21:26 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.551
X-Spam-Level: 
X-Spam-Status: No, score=-1.551 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HELO_EQ_DE=0.35, SPF_HELO_PASS=-0.001] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id RRChJxHXpxnb for <ace@ietfa.amsl.com>; Wed, 23 Jul 2014 10:21:24 -0700 (PDT)
Received: from informatik.uni-bremen.de (mailhost.informatik.uni-bremen.de [IPv6:2001:638:708:30c9::12]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 1BB081B2B57 for <ace@ietf.org>; Wed, 23 Jul 2014 10:19:20 -0700 (PDT)
X-Virus-Scanned: amavisd-new at informatik.uni-bremen.de
Received: from smtp-fb3.informatik.uni-bremen.de (smtp-fb3.informatik.uni-bremen.de [134.102.224.120]) by informatik.uni-bremen.de (8.14.5/8.14.5) with ESMTP id s6NHJHBu009162 for <ace@ietf.org>; Wed, 23 Jul 2014 19:19:18 +0200 (CEST)
Received: from [134.102.218.214] (dynamic-218-o.informatik.uni-bremen.de [134.102.218.214]) (using TLSv1 with cipher DHE-RSA-CAMELLIA256-SHA (256/256 bits)) (No client certificate requested) by smtp-fb3.informatik.uni-bremen.de (Postfix) with ESMTPSA id DBFB6289 for <ace@ietf.org>; Wed, 23 Jul 2014 19:19:17 +0200 (CEST)
Message-ID: <53CFEE95.309@tzi.de>
Date: Wed, 23 Jul 2014 19:19:17 +0200
From: Stefanie Gerdes <gerdes@tzi.de>
User-Agent: Mozilla/5.0 (X11; Linux i686 on x86_64; rv:24.0) Gecko/20100101 Thunderbird/24.2.0
MIME-Version: 1.0
To: "ace@ietf.org" <ace@ietf.org>
X-Enigmail-Version: 1.6
Content-Type: text/plain; charset=windows-1252
Content-Transfer-Encoding: 7bit
Archived-At: http://mailarchive.ietf.org/arch/msg/ace/Y2IlUDuh_Ap5S3VEXif8thfRSCk
Subject: [Ace] How to progress?
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 23 Jul 2014 17:21:26 -0000

Hi everyone,

The discussion today and during the previous meetings made me think that
there are still a lot of unspoken assumptions and requirements flying
around. I think we won't be able to come to an agreement on a solution
if we don't manage to identify the key assumptions and requirements.
This is why I came up with a couple of questions which I think would
help to explore the context of the problem we are trying to solve. I
know that there will in most cases not be only one answer to these
questions but I think we will need to get a feeling about the range of
answers.

These are the questions I came up with:
1. What categories of constrained devices do we want to support (C0, C1..)?
  1a) What are the smallest devices we are going to support (RAM, ROM, etc)?
2. For each device in the architecture: What are the limitations of this
device?
  2a) Are the limitations always the same?
  2b) How much can we gain from introducing less constrained actors?
3. What message sizes do we want to consider?
4. What are the application security requirements for the
   communication between constrained nodes?
  4a) Integrity
  4b) Confidentiality
  4c) Non-Repudiation
  4e) ...
  4f) Are all of these always needed?
5. Which level of security is needed on the devices (high, middle, low)?
  5a) Do we always need devices to be tamper-proof?
6. How do the constraints of the nodes influence the protocols to be used?
7. Can we find a single protocol which supports all kinds of devices in
  every part of the architecture?
8. What roles do proxies have that we want to support?
9. Do we need authorization without user interaction?
10. Which constraints concerning the connectivity of devices do we want
   to support?
  10a) "Offline" authorization (only some devices are "online", no
       device is online, etc)
  10b) Intermittent connectivity
  10c) Special connectivity requirements (e.g. unidirectional links)


I thought it might be helpful to collect the relevant questions and
assumptions in a wiki: http://trac.tools.ietf.org/wg/ace/trac/wiki/Questions

What do you think?

Thanks,
Steffi


From nobody Wed Jul 23 10:47:24 2014
Return-Path: <likepeng@huawei.com>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 467E31B2BC6 for <ace@ietfa.amsl.com>; Wed, 23 Jul 2014 10:47:12 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.413
X-Spam-Level: 
X-Spam-Status: No, score=-1.413 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, CN_BODY_35=0.339, MIME_CHARSET_FARAWAY=2.45, RCVD_IN_DNSWL_MED=-2.3, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id quPULYs5T0do for <ace@ietfa.amsl.com>; Wed, 23 Jul 2014 10:47:10 -0700 (PDT)
Received: from lhrrgout.huawei.com (lhrrgout.huawei.com [194.213.3.17]) (using TLSv1 with cipher RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id F26881B2A16 for <ace@ietf.org>; Wed, 23 Jul 2014 10:47:04 -0700 (PDT)
Received: from 172.18.7.190 (EHLO lhreml405-hub.china.huawei.com) ([172.18.7.190]) by lhrrg02-dlp.huawei.com (MOS 4.3.7-GA FastPath queued) with ESMTP id BHN44512; Wed, 23 Jul 2014 17:47:03 +0000 (GMT)
Received: from SZXEMA403-HUB.china.huawei.com (10.82.72.35) by lhreml405-hub.china.huawei.com (10.201.5.242) with Microsoft SMTP Server (TLS) id 14.3.158.1; Wed, 23 Jul 2014 18:47:02 +0100
Received: from SZXEMA501-MBS.china.huawei.com ([169.254.2.128]) by SZXEMA403-HUB.china.huawei.com ([10.82.72.35]) with mapi id 14.03.0158.001; Thu, 24 Jul 2014 01:46:58 +0800
From: Likepeng <likepeng@huawei.com>
To: Stefanie Gerdes <gerdes@tzi.de>, "ace@ietf.org" <ace@ietf.org>
Thread-Topic: [Ace] How to progress?
Thread-Index: AQHPppqp9NNMhuYegkeiaPLUl+jJtZut7XaA
Date: Wed, 23 Jul 2014 17:46:57 +0000
Message-ID: <34966E97BE8AD64EAE9D3D6E4DEE36F25817AA6E@SZXEMA501-MBS.china.huawei.com>
References: <53CFEE95.309@tzi.de>
In-Reply-To: <53CFEE95.309@tzi.de>
Accept-Language: zh-CN, en-US
Content-Language: zh-CN
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
x-originating-ip: [10.193.85.66]
Content-Type: text/plain; charset="gb2312"
Content-Transfer-Encoding: base64
MIME-Version: 1.0
X-CFilter-Loop: Reflected
Archived-At: http://mailarchive.ietf.org/arch/msg/ace/sclGc62g-Gg8ogM-sDcDnhwXTa4
Subject: Re: [Ace] How to progress?
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 23 Jul 2014 17:47:12 -0000

PkkgdGhvdWdodCBpdCBtaWdodCBiZSBoZWxwZnVsIHRvIGNvbGxlY3QgdGhlIHJlbGV2YW50IHF1
ZXN0aW9ucyBhbmQgYXNzdW1wdGlvbnMgaW4gYSB3aWtpOiBodHRwOi8vdHJhYy50b29scy5pZXRm
Lm9yZy93Zy9hY2UvdHJhYy93aWtpL1F1ZXN0aW9ucw0KDQpJIHRoaW5rIGl0IGlzIGEgZ29vZCBp
ZGVhLg0KDQpJdCB3aWxsIGJlIGJldHRlciBpZiB3ZSBjYW4gcHV0IGNob2ljZSBxdWVzdGlvbnMg
b3IgeWVzL25vIHF1ZXN0aW9ucywgaW5zdGVhZCBvZiBvcGVuIHF1ZXN0aW9ucywgdG8gbmFycm93
IGRvd24gdGhlIHNjb3BlIGFuZCBtYWtlIHRoZW0gZWFzaWVyIHRvIGJlIGFuc3dlcmVkLg0KDQpL
aW5kIFJlZ2FyZHMNCktlcGVuZw0KDQotLS0tLdPKvP7Urbz+LS0tLS0NCreivP7IyzogQWNlIFtt
YWlsdG86YWNlLWJvdW5jZXNAaWV0Zi5vcmddILT6se0gU3RlZmFuaWUgR2VyZGVzDQq3osvNyrG8
5DogMjAxNMTqN9TCMjPI1SAxMzoxOQ0KytW8/sjLOiBhY2VAaWV0Zi5vcmcNCtb3zOI6IFtBY2Vd
IEhvdyB0byBwcm9ncmVzcz8NCg0KSGkgZXZlcnlvbmUsDQoNClRoZSBkaXNjdXNzaW9uIHRvZGF5
IGFuZCBkdXJpbmcgdGhlIHByZXZpb3VzIG1lZXRpbmdzIG1hZGUgbWUgdGhpbmsgdGhhdCB0aGVy
ZSBhcmUgc3RpbGwgYSBsb3Qgb2YgdW5zcG9rZW4gYXNzdW1wdGlvbnMgYW5kIHJlcXVpcmVtZW50
cyBmbHlpbmcgYXJvdW5kLiBJIHRoaW5rIHdlIHdvbid0IGJlIGFibGUgdG8gY29tZSB0byBhbiBh
Z3JlZW1lbnQgb24gYSBzb2x1dGlvbiBpZiB3ZSBkb24ndCBtYW5hZ2UgdG8gaWRlbnRpZnkgdGhl
IGtleSBhc3N1bXB0aW9ucyBhbmQgcmVxdWlyZW1lbnRzLg0KVGhpcyBpcyB3aHkgSSBjYW1lIHVw
IHdpdGggYSBjb3VwbGUgb2YgcXVlc3Rpb25zIHdoaWNoIEkgdGhpbmsgd291bGQgaGVscCB0byBl
eHBsb3JlIHRoZSBjb250ZXh0IG9mIHRoZSBwcm9ibGVtIHdlIGFyZSB0cnlpbmcgdG8gc29sdmUu
IEkga25vdyB0aGF0IHRoZXJlIHdpbGwgaW4gbW9zdCBjYXNlcyBub3QgYmUgb25seSBvbmUgYW5z
d2VyIHRvIHRoZXNlIHF1ZXN0aW9ucyBidXQgSSB0aGluayB3ZSB3aWxsIG5lZWQgdG8gZ2V0IGEg
ZmVlbGluZyBhYm91dCB0aGUgcmFuZ2Ugb2YgYW5zd2Vycy4NCg0KVGhlc2UgYXJlIHRoZSBxdWVz
dGlvbnMgSSBjYW1lIHVwIHdpdGg6DQoxLiBXaGF0IGNhdGVnb3JpZXMgb2YgY29uc3RyYWluZWQg
ZGV2aWNlcyBkbyB3ZSB3YW50IHRvIHN1cHBvcnQgKEMwLCBDMS4uKT8NCiAgMWEpIFdoYXQgYXJl
IHRoZSBzbWFsbGVzdCBkZXZpY2VzIHdlIGFyZSBnb2luZyB0byBzdXBwb3J0IChSQU0sIFJPTSwg
ZXRjKT8NCjIuIEZvciBlYWNoIGRldmljZSBpbiB0aGUgYXJjaGl0ZWN0dXJlOiBXaGF0IGFyZSB0
aGUgbGltaXRhdGlvbnMgb2YgdGhpcyBkZXZpY2U/DQogIDJhKSBBcmUgdGhlIGxpbWl0YXRpb25z
IGFsd2F5cyB0aGUgc2FtZT8NCiAgMmIpIEhvdyBtdWNoIGNhbiB3ZSBnYWluIGZyb20gaW50cm9k
dWNpbmcgbGVzcyBjb25zdHJhaW5lZCBhY3RvcnM/DQozLiBXaGF0IG1lc3NhZ2Ugc2l6ZXMgZG8g
d2Ugd2FudCB0byBjb25zaWRlcj8NCjQuIFdoYXQgYXJlIHRoZSBhcHBsaWNhdGlvbiBzZWN1cml0
eSByZXF1aXJlbWVudHMgZm9yIHRoZQ0KICAgY29tbXVuaWNhdGlvbiBiZXR3ZWVuIGNvbnN0cmFp
bmVkIG5vZGVzPw0KICA0YSkgSW50ZWdyaXR5DQogIDRiKSBDb25maWRlbnRpYWxpdHkNCiAgNGMp
IE5vbi1SZXB1ZGlhdGlvbg0KICA0ZSkgLi4uDQogIDRmKSBBcmUgYWxsIG9mIHRoZXNlIGFsd2F5
cyBuZWVkZWQ/DQo1LiBXaGljaCBsZXZlbCBvZiBzZWN1cml0eSBpcyBuZWVkZWQgb24gdGhlIGRl
dmljZXMgKGhpZ2gsIG1pZGRsZSwgbG93KT8NCiAgNWEpIERvIHdlIGFsd2F5cyBuZWVkIGRldmlj
ZXMgdG8gYmUgdGFtcGVyLXByb29mPw0KNi4gSG93IGRvIHRoZSBjb25zdHJhaW50cyBvZiB0aGUg
bm9kZXMgaW5mbHVlbmNlIHRoZSBwcm90b2NvbHMgdG8gYmUgdXNlZD8NCjcuIENhbiB3ZSBmaW5k
IGEgc2luZ2xlIHByb3RvY29sIHdoaWNoIHN1cHBvcnRzIGFsbCBraW5kcyBvZiBkZXZpY2VzIGlu
DQogIGV2ZXJ5IHBhcnQgb2YgdGhlIGFyY2hpdGVjdHVyZT8NCjguIFdoYXQgcm9sZXMgZG8gcHJv
eGllcyBoYXZlIHRoYXQgd2Ugd2FudCB0byBzdXBwb3J0Pw0KOS4gRG8gd2UgbmVlZCBhdXRob3Jp
emF0aW9uIHdpdGhvdXQgdXNlciBpbnRlcmFjdGlvbj8NCjEwLiBXaGljaCBjb25zdHJhaW50cyBj
b25jZXJuaW5nIHRoZSBjb25uZWN0aXZpdHkgb2YgZGV2aWNlcyBkbyB3ZSB3YW50DQogICB0byBz
dXBwb3J0Pw0KICAxMGEpICJPZmZsaW5lIiBhdXRob3JpemF0aW9uIChvbmx5IHNvbWUgZGV2aWNl
cyBhcmUgIm9ubGluZSIsIG5vDQogICAgICAgZGV2aWNlIGlzIG9ubGluZSwgZXRjKQ0KICAxMGIp
IEludGVybWl0dGVudCBjb25uZWN0aXZpdHkNCiAgMTBjKSBTcGVjaWFsIGNvbm5lY3Rpdml0eSBy
ZXF1aXJlbWVudHMgKGUuZy4gdW5pZGlyZWN0aW9uYWwgbGlua3MpDQoNCg0KSSB0aG91Z2h0IGl0
IG1pZ2h0IGJlIGhlbHBmdWwgdG8gY29sbGVjdCB0aGUgcmVsZXZhbnQgcXVlc3Rpb25zIGFuZCBh
c3N1bXB0aW9ucyBpbiBhIHdpa2k6IGh0dHA6Ly90cmFjLnRvb2xzLmlldGYub3JnL3dnL2FjZS90
cmFjL3dpa2kvUXVlc3Rpb25zDQoNCldoYXQgZG8geW91IHRoaW5rPw0KDQpUaGFua3MsDQpTdGVm
ZmkNCg0KX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX18NCkFj
ZSBtYWlsaW5nIGxpc3QNCkFjZUBpZXRmLm9yZw0KaHR0cHM6Ly93d3cuaWV0Zi5vcmcvbWFpbG1h
bi9saXN0aW5mby9hY2UNCg==


From nobody Wed Jul 23 11:33:18 2014
Return-Path: <rstruik.ext@gmail.com>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id A5F951B2C10 for <ace@ietfa.amsl.com>; Wed, 23 Jul 2014 11:33:14 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2
X-Spam-Level: 
X-Spam-Status: No, score=-2 tagged_above=-999 required=5 tests=[BAYES_00=-1.9,  DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id CJtxYWg22DXK for <ace@ietfa.amsl.com>; Wed, 23 Jul 2014 11:33:11 -0700 (PDT)
Received: from mail-wi0-x235.google.com (mail-wi0-x235.google.com [IPv6:2a00:1450:400c:c05::235]) (using TLSv1 with cipher ECDHE-RSA-RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 8ACF71B2BB1 for <ace@ietf.org>; Wed, 23 Jul 2014 11:33:09 -0700 (PDT)
Received: by mail-wi0-f181.google.com with SMTP id bs8so2747175wib.8 for <ace@ietf.org>; Wed, 23 Jul 2014 11:33:08 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113;  h=message-id:date:from:user-agent:mime-version:to:subject:references :in-reply-to:content-type:content-transfer-encoding; bh=W8iI2RjumIBHzA+ILSQQrEB1NnQ+rxRnqrW6pAdnrzk=; b=mVLW+8LV1VtGkgHAzzlLtX8AV1uJYc9C8ALwwwpw8N+U9lxNwGlLL4lZPMUCvYUYQD zWgOQtR4yUAUz2ogQbxdNcl4qqJ9zK8ZapYEGngAcs4CPfDwVxOCDxuuf1uS4DYG4mCN mBFI0V4hweEHDjNJJccn52Qqic2Z1qlweESNhRS2VgoBrU8nNl9B2F5CT4c4P+V5EZoI WUgNh3zxNF7v/jdWiv7ekct8N3loTH2MYQxX4aHKDX4kZg5SQX22mt8mBKqrX9XFfugH GKTFL/yS/MmiyRcKsn16XPkNdD2zZlrHrZG1bULllaqrfdeOXekig/Iw4GeI7d9eBsCl cKWg==
X-Received: by 10.194.189.50 with SMTP id gf18mr4480852wjc.13.1406140387579; Wed, 23 Jul 2014 11:33:07 -0700 (PDT)
Received: from ?IPv6:2001:67c:370:160:4cdf:3ea4:10dc:64a0? ([2001:67c:370:160:4cdf:3ea4:10dc:64a0]) by mx.google.com with ESMTPSA id ko8sm8389331wjc.11.2014.07.23.11.33.04 for <multiple recipients> (version=TLSv1 cipher=ECDHE-RSA-RC4-SHA bits=128/128); Wed, 23 Jul 2014 11:33:06 -0700 (PDT)
Message-ID: <53CFFFD9.60902@gmail.com>
Date: Wed, 23 Jul 2014 14:32:57 -0400
From: Rene Struik <rstruik.ext@gmail.com>
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:24.0) Gecko/20100101 Thunderbird/24.6.0
MIME-Version: 1.0
To: Stefanie Gerdes <gerdes@tzi.de>, "ace@ietf.org" <ace@ietf.org>
References: <53CFEE95.309@tzi.de>
In-Reply-To: <53CFEE95.309@tzi.de>
Content-Type: text/plain; charset=ISO-8859-1; format=flowed
Content-Transfer-Encoding: 7bit
Archived-At: http://mailarchive.ietf.org/arch/msg/ace/ciHTpTfdK6zAezBr29umpgSJRN8
Subject: Re: [Ace] How to progress?
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 23 Jul 2014 18:33:14 -0000

Hi Stefanie:

I provided a first stab at this - see below.

Two additional notes:
- Desired functionality should drive design and design considerations 
{some of the questions below seem to unnecessarily restrict the design 
freedom}. Ultimately, one deploys a system, because of provided device 
and network/system functionality, ease of use and ease of maintenance.
- Functionality should consider that networks may be composed of 
components that have been sourced from multiple vendors along the supply 
chain (and may have changed hands along, e.g., system integration during 
pre-operational use or during operational use itself.

Best regards, Rene

On 7/23/2014 1:19 PM, Stefanie Gerdes wrote:
> Hi everyone,
>
> The discussion today and during the previous meetings made me think that
> there are still a lot of unspoken assumptions and requirements flying
> around. I think we won't be able to come to an agreement on a solution
> if we don't manage to identify the key assumptions and requirements.
> This is why I came up with a couple of questions which I think would
> help to explore the context of the problem we are trying to solve. I
> know that there will in most cases not be only one answer to these
> questions but I think we will need to get a feeling about the range of
> answers.
>
> These are the questions I came up with:
> 1. What categories of constrained devices do we want to support (C0, C1..)?
>    1a) What are the smallest devices we are going to support (RAM, ROM, etc)?
RS>> Design should be based on desired functionality, flexibility, and 
ease of use, more so than a priori putting roadblocks on perceived 
complexity forward that would limit the design freedom. Usually, lots of 
optimizations can be done once one has an overall design that meets the 
desired deployment and ease of use use cases. It is very hard to make 
definitive statements here.
<<RS

2. For each device in the architecture: What are the limitations of this
device?
   2a) Are the limitations always the same?
   2b) How much can we gain from introducing less constrained actors?
RS>> Not so useful to a priori get a turf war on perceptions on complexity, without having the right anchors to try and be creative with an overall design exercise.
<<RS
  3. What message sizes do we want to consider?
RS>>
Small is beautiful, but somewhat premature and not that useful to bind hands behind the back in a vacuum.
<<RS
  4. What are the application security requirements for the
    communication between constrained nodes?
   4a) Integrity
   4b) Confidentiality
   4c) Non-Repudiation
   4e) ...
   4f) Are all of these always needed?
RS>>
For overall IoT potential to be reached, one needs to provide usual security constructs (on crypto front: AEAD cipher based AES, ECC engine, RNG, perhaps PUF block;
on security front: authenticated key agreement scheme, cert scheme, provisioning scheme, key management functionality, synchronization scheme). Luckily, most of the
basic building blocks can be considered to be commodity blocks, esp. if built-in using hardware support (in terms of RAM/ROM, energy use, computational time
latencies, etc.) What I see missing is security policy management functionality (device roles, including meta-roles to effectuate changes hereto, language so as to
convey this info in messages, etc.
<<RS
  5. Which level of security is needed on the devices (high, middle, low)?
RS>>
Not sure what High/Middle/Low means. The cost of providing <128 bit crypto bit strength is probably very similar to that of providing 128 bits crypto bit strength
(case in point: most AEAD cipher simply truncate MAC tag size from AES block size of 128 bits to, e.g., 64 bits, without any computational cost penalty. The only
cost here would be communication time latency and, thereby, energy cost.
<<RS
  5a) Do we always need devices to be tamper-proof?
RS>>
Not sure whether ensuring the authenticity and/or confidentiality of keying material, security material, and, e.g., implementation code would be in scope for IETF to
prescribe. This seems to be more a device manufacturer's prerogative, where industry bodies sometimes may impose certain assurance levels (EAL, etc.)
<<RS
  6. How do the constraints of the nodes influence the protocols to be used?
RS>>
Designs should take into account limitations in targeted capabilities of devices, both in terms of computational capabilities, storage space, availability of tamper
evidencing, peak and average energy consumption, time latency impact of communicated information, etc. Obviously, small is beautiful here, but also uniform design
catering to minimization of overall system architectural design cost is more important than trying to locally optimize various components. This should also take
into account device provisioning, configuration, management capability, where one should remember that the most expensive component of the solution may be any personnel
that may be required to make things work, maintain, etc. {much higher impact than incremental cost of, e.g., implementing commodity crypto components}.
<<RS

  7. Can we find a single protocol which supports all kinds of devices in
   every part of the architecture?
RS>>
Personal perspective: YES, if we stick to the objective of a design that minimizes the total implementation cost over the entire device and network lifecycle, including
provisioning.
<<RS
  8. What roles do proxies have that we want to support?
RS>>
This discussion is best deferred till after initial architectural design has been painted. Overall, most importantly, if delegation happens on a device a specific device
communicates with, this specific device should be blissfully obliviously unaware of this.
<<RS
  9. Do we need authorization without user interaction?
RS>>
Obviously, in many cases the answer is yes (since, e.g., receipt of AEAD-secured packets accepts these if incoming security processing succeeds with the proper key
and where knowledge of the key implies authorization (black-and-white authorization). There are definitely lots of cases where a human decision element is required
or beneficial, e.g., with network provisioning and configuration.
<<RS
  10. Which constraints concerning the connectivity of devices do we want
    to support?
   10a) "Offline" authorization (only some devices are "online", no
        device is online, etc)
   10b) Intermittent connectivity
   10c) Special connectivity requirements (e.g. unidirectional links)
RS>>
Networks should be able to operate also in sleepy settings, where connectivity is not a given. Moreover, networks should be able to recover from temporary glitches in
normal expected operational conditions. For sleepy devices, reliance on online connectivity should be the exception, rather than the rule.
<<RS

  I thought it might be helpful to collect the relevant questions and
assumptions in a wiki: http://trac.tools.ietf.org/wg/ace/trac/wiki/Questions

What do you think?

Thanks,
Steffi

_______________________________________________
Ace mailing list
Ace@ietf.org
https://www.ietf.org/mailman/listinfo/ace



-- 
email: rstruik.ext@gmail.com | Skype: rstruik
cell: +1 (647) 867-5658 | US: +1 (415) 690-7363


From nobody Wed Jul 23 12:06:08 2014
Return-Path: <hannes.tschofenig@gmx.net>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id B7CB01B29E2 for <ace@ietfa.amsl.com>; Wed, 23 Jul 2014 12:06:06 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.901
X-Spam-Level: 
X-Spam-Status: No, score=-1.901 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, FREEMAIL_FROM=0.001, RCVD_IN_DNSWL_NONE=-0.0001, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id RL-K6P1kdnbt for <ace@ietfa.amsl.com>; Wed, 23 Jul 2014 12:06:04 -0700 (PDT)
Received: from mout.gmx.net (mout.gmx.net [212.227.15.19]) (using TLSv1.2 with cipher DHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 58FA31B29BF for <Ace@ietf.org>; Wed, 23 Jul 2014 12:06:04 -0700 (PDT)
Received: from [192.168.10.135] ([31.133.166.25]) by mail.gmx.com (mrgmx002) with ESMTPSA (Nemesis) id 0MKZLb-1XBwjl3ysR-001xNM; Wed, 23 Jul 2014 21:05:55 +0200
Message-ID: <53D00795.3040100@gmx.net>
Date: Wed, 23 Jul 2014 21:05:57 +0200
From: Hannes Tschofenig <hannes.tschofenig@gmx.net>
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:31.0) Gecko/20100101 Thunderbird/31.0
MIME-Version: 1.0
To: "Ace@ietf.org" <Ace@ietf.org>, Stefanie Gerdes <gerdes@tzi.de>
References: <53CFEE95.309@tzi.de>
In-Reply-To: <53CFEE95.309@tzi.de>
OpenPGP: id=4D776BC9
Content-Type: multipart/signed; micalg=pgp-sha512; protocol="application/pgp-signature"; boundary="cPT8Sf9guon37muV9hbj0qVLm6PcaSMj4"
X-Provags-ID: V03:K0:dUYFACzA6J7Vb1d10xFgsRK3xJXZKwp6feReJIDgmgMKYHQuQYu rfgXQBsy9zByrH80IB3FnrHNfJU9K/73h1JqjruDMNlVgsqvWh0M4hCzyhSGoMuwOnmH4OB bWnGeAqwij0NntG+lR7XhFmWWKSw9McvfaIDbxsp4KiJHvH/V7mXRDwhebjUvcf3ymyHFNr MHF7gid3HzlDsq+BCV8ZA==
Archived-At: http://mailarchive.ietf.org/arch/msg/ace/e435lyIyGv70EuYBOabP7ks2Wb8
Subject: Re: [Ace] How to progress?
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 23 Jul 2014 19:06:06 -0000

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--cPT8Sf9guon37muV9hbj0qVLm6PcaSMj4
Content-Type: text/plain; charset=windows-1252
Content-Transfer-Encoding: quoted-printable

Hi Steffi,

the attempt so far was to answer these questions from a different
direction: instead of starting with a specific device platform (e.g.,
class, memory requirements, message size, etc.) we thought that the use
cases are going to constrain the solution space and help to guide our wor=
k.

It turned out that this is rather complex since we have not managed to
receive detailed enough use case descriptions that would, for example,
let us rule out a specific communication design pattern or prefer a
specific credential type.

My worry is that we design for an artificial platform that may or may
not reflect the use cases people have in mind. Of course, it might be
possible that folks in the group do not want to share the details about
their use cases and then we are obviously a bit in trouble since we just
have to guess.

There are, however, a question listed below that are quite good and
raised during the working group meeting. For example, the 'intermittent
connectivity' aspect was raised today as something that has not been
explored in enough detail. Also the roles of proxies in the architecture
is an aspect that has been discussed at the BOF already and there was
the hope that specific use cases would give more details about the
real-world use case. So far, it is not even clear what protocols the
proxy would bridge.

Ciao
Hannes

On 07/23/2014 07:19 PM, Stefanie Gerdes wrote:> Hi everyone,
>
> The discussion today and during the previous meetings made me think tha=
t
> there are still a lot of unspoken assumptions and requirements flying
> around. I think we won't be able to come to an agreement on a solution
> if we don't manage to identify the key assumptions and requirements.
> This is why I came up with a couple of questions which I think would
> help to explore the context of the problem we are trying to solve. I
> know that there will in most cases not be only one answer to these
> questions but I think we will need to get a feeling about the range of
> answers.
>
> These are the questions I came up with:
> 1. What categories of constrained devices do we want to support (C0,
C1..)?
>   1a) What are the smallest devices we are going to support (RAM, ROM,
etc)?
> 2. For each device in the architecture: What are the limitations of thi=
s
> device?
>   2a) Are the limitations always the same?
>   2b) How much can we gain from introducing less constrained actors?
> 3. What message sizes do we want to consider?
> 4. What are the application security requirements for the
>    communication between constrained nodes?
>   4a) Integrity
>   4b) Confidentiality
>   4c) Non-Repudiation
>   4e) ...
>   4f) Are all of these always needed?
> 5. Which level of security is needed on the devices (high, middle, low)=
?
>   5a) Do we always need devices to be tamper-proof?
> 6. How do the constraints of the nodes influence the protocols to be us=
ed?
> 7. Can we find a single protocol which supports all kinds of devices in=

>   every part of the architecture?
> 8. What roles do proxies have that we want to support?
> 9. Do we need authorization without user interaction?
> 10. Which constraints concerning the connectivity of devices do we want=

>    to support?
>   10a) "Offline" authorization (only some devices are "online", no
>        device is online, etc)
>   10b) Intermittent connectivity
>   10c) Special connectivity requirements (e.g. unidirectional links)
>
>
> I thought it might be helpful to collect the relevant questions and
> assumptions in a wiki:
http://trac.tools.ietf.org/wg/ace/trac/wiki/Questions
>
> What do you think?
>
> Thanks,
> Steffi
>
> _______________________________________________
> Ace mailing list
> Ace@ietf.org
> https://www.ietf.org/mailman/listinfo/ace
>


On 07/23/2014 07:19 PM, Stefanie Gerdes wrote:> Hi everyone,
>
> The discussion today and during the previous meetings made me think tha=
t
> there are still a lot of unspoken assumptions and requirements flying
> around. I think we won't be able to come to an agreement on a solution
> if we don't manage to identify the key assumptions and requirements.
> This is why I came up with a couple of questions which I think would
> help to explore the context of the problem we are trying to solve. I
> know that there will in most cases not be only one answer to these
> questions but I think we will need to get a feeling about the range of
> answers.
>
> These are the questions I came up with:
> 1. What categories of constrained devices do we want to support (C0,
C1..)?
>   1a) What are the smallest devices we are going to support (RAM, ROM,
etc)?
> 2. For each device in the architecture: What are the limitations of thi=
s
> device?
>   2a) Are the limitations always the same?
>   2b) How much can we gain from introducing less constrained actors?
> 3. What message sizes do we want to consider?
> 4. What are the application security requirements for the
>    communication between constrained nodes?
>   4a) Integrity
>   4b) Confidentiality
>   4c) Non-Repudiation
>   4e) ...
>   4f) Are all of these always needed?
> 5. Which level of security is needed on the devices (high, middle, low)=
?
>   5a) Do we always need devices to be tamper-proof?
> 6. How do the constraints of the nodes influence the protocols to be us=
ed?
> 7. Can we find a single protocol which supports all kinds of devices in=

>   every part of the architecture?
> 8. What roles do proxies have that we want to support?
> 9. Do we need authorization without user interaction?
> 10. Which constraints concerning the connectivity of devices do we want=

>    to support?
>   10a) "Offline" authorization (only some devices are "online", no
>        device is online, etc)
>   10b) Intermittent connectivity
>   10c) Special connectivity requirements (e.g. unidirectional links)
>
>
> I thought it might be helpful to collect the relevant questions and
> assumptions in a wiki:
http://trac.tools.ietf.org/wg/ace/trac/wiki/Questions
>
> What do you think?
>
> Thanks,
> Steffi
>
> _______________________________________________
> Ace mailing list
> Ace@ietf.org
> https://www.ietf.org/mailman/listinfo/ace
>


--cPT8Sf9guon37muV9hbj0qVLm6PcaSMj4
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
Content-Disposition: attachment; filename="signature.asc"

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1
Comment: GPGTools - http://gpgtools.org

iQEcBAEBCgAGBQJT0AeWAAoJEGhJURNOOiAtMZwH/3RfF/hqXNIXK5OsSuOzxeij
o3pEZo5sijhVvtfkXp2rVvOdfKwXPnfchWfQf3sUI6KSUGow+ssD0NEo/ECZDOA6
oYrUustfBjsH0DrwItaTVqHmFilo4njcAc8gKjoDHHBVwhMqCpGDDEvkBAddZHWS
jc6YXGc1dp14sh3o7ukJw48KLWf8pqvOvgyjyACCVtoujiefVjbTkNJ1tc7RuQHL
/OXUO0mvZaQFku96RQMCkH4nzaF4/Fb2ishKOaKOqsLpSiUYyakJ/qAMSvltZodC
HZXGzP2ukYZV1pT5LYvYfoe84cIPkeiFkwLLLbGPKKxvphSWAxjjckwJNkk2Ps4=
=7bEE
-----END PGP SIGNATURE-----

--cPT8Sf9guon37muV9hbj0qVLm6PcaSMj4--


From nobody Wed Jul 23 12:34:13 2014
Return-Path: <mcr@sandelman.ca>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id BFBA21B2C52 for <ace@ietfa.amsl.com>; Wed, 23 Jul 2014 12:34:11 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.892
X-Spam-Level: 
X-Spam-Status: No, score=-1.892 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001, T_TVD_MIME_NO_HEADERS=0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id fweXXOYCkT37 for <ace@ietfa.amsl.com>; Wed, 23 Jul 2014 12:34:09 -0700 (PDT)
Received: from tuna.sandelman.ca (tuna.sandelman.ca [209.87.249.19]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id C37F91A033A for <ace@ietf.org>; Wed, 23 Jul 2014 12:34:09 -0700 (PDT)
Received: from sandelman.ca (obiwan.sandelman.ca [209.87.249.21]) by tuna.sandelman.ca (Postfix) with ESMTP id 95E7E20012; Wed, 23 Jul 2014 15:35:49 -0400 (EDT)
Received: by sandelman.ca (Postfix, from userid 179) id D387863B0E; Wed, 23 Jul 2014 15:34:04 -0400 (EDT)
Received: from sandelman.ca (localhost [127.0.0.1]) by sandelman.ca (Postfix) with ESMTP id BB15E63B0A; Wed, 23 Jul 2014 15:34:04 -0400 (EDT)
From: Michael Richardson <mcr+ietf@sandelman.ca>
To: Likepeng <likepeng@huawei.com>
In-Reply-To: <34966E97BE8AD64EAE9D3D6E4DEE36F25817A9D6@SZXEMA501-MBS.china.huawei.com>
References: <15740.1406129931@sandelman.ca> <34966E97BE8AD64EAE9D3D6E4DEE36F25817A9D6@SZXEMA501-MBS.china.huawei.com>
X-Mailer: MH-E 8.2; nmh 1.3-dev; GNU Emacs 23.4.1
X-Face: $\n1pF)h^`}$H>Hk{L"x@)JS7<%Az}5RyS@k9X%29-lHB$Ti.V>2bi.~ehC0; <'$9xN5Ub# z!G,p`nR&p7Fz@^UXIn156S8.~^@MJ*mMsD7=QFeq%AL4m<nPbLgmtKK-5dC@#:k
MIME-Version: 1.0
Content-Type: multipart/signed; boundary="=-=-="; micalg=pgp-sha1; protocol="application/pgp-signature"
Date: Wed, 23 Jul 2014 15:34:04 -0400
Message-ID: <32200.1406144044@sandelman.ca>
Sender: mcr@sandelman.ca
Archived-At: http://mailarchive.ietf.org/arch/msg/ace/Gox4xk0a2VWjbGUJ1FET52obJ3A
Cc: ace <ace@ietf.org>
Subject: Re: [Ace] adopting documents
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 23 Jul 2014 19:34:11 -0000

--=-=-=


Likepeng <likepeng@huawei.com> wrote:
    >> (I realize that there is no call for adoption on these as yet).

    > We have already called for adoption for draft-seitz-ace-usecases-01:
    > http://www.ietf.org/mail-archive/web/ace/current/msg00743.html

Ah, IETF week email overload...
Good.  So I support doing that!

--
Michael Richardson <mcr+IETF@sandelman.ca>, Sandelman Software Works
 -= IPv6 IoT consulting =-




--=-=-=
Content-Type: application/pgp-signature

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iQEVAwUBU9AOKoCLcPvd0N1lAQI8TQf/Tnwus7Ei9ZVp9jmTlcyn2EDy1iAGcVz+
y2ZbDluOqImVf4CdV8fCtaO6rU9Rolb8/i4fTLy7iE6DFuTq/7c63dRJAtYYV4WA
xDdI9+Pqh2321hVZJQf7zgli/hrrntvkGZrKvCGr4+olyXyW8+oV/FwC+tap3L/u
vnw46lrI5PX6gK1WsPKr/FxGweOOb9t0WfI689GSrqzyhnCTaJxmNxKg1qbdckAM
r9yXnbXN7YP7j/A47yO/xbbrt5y775hjUpo5+21LBRa/UwPe1iLQC3GCjtI8tkyD
BiU8rYoW6pzrrUWElLgvWCPO9l/V9RSbeX88gO6Q1SUCRdfgWPKxnA==
=m6T1
-----END PGP SIGNATURE-----
--=-=-=--


From nobody Wed Jul 23 12:50:04 2014
Return-Path: <kathleen.moriarty.ietf@gmail.com>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id AB3211B2CCF for <ace@ietfa.amsl.com>; Wed, 23 Jul 2014 12:49:59 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.999
X-Spam-Level: 
X-Spam-Status: No, score=-1.999 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Nbt6Pxr-mr8d for <ace@ietfa.amsl.com>; Wed, 23 Jul 2014 12:49:56 -0700 (PDT)
Received: from mail-lb0-x22d.google.com (mail-lb0-x22d.google.com [IPv6:2a00:1450:4010:c04::22d]) (using TLSv1 with cipher ECDHE-RSA-RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 565211A014F for <ace@ietf.org>; Wed, 23 Jul 2014 12:49:56 -0700 (PDT)
Received: by mail-lb0-f173.google.com with SMTP id p9so1307811lbv.4 for <ace@ietf.org>; Wed, 23 Jul 2014 12:49:54 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113;  h=mime-version:date:message-id:subject:from:to:content-type; bh=UT/k7/PqcdL2A3+x77imBNs6+Lx0EsPwGRDSdnDaCTs=; b=aq8EyyCaxOHl2z23kWnO69Fsmheqp5WXKEe0IxLA6q7AiZIUyEijmpzOMFK4ww2Dtp ThdI/k1D4nBUdjTkcMsHUd9rfyf3mvca7A0OUYGrZ4dBo2+v8aH8TXxWJsM876Y2yib9 fmNdcsoBOfZg1rxMENwDBkA6aqxvn67zA733/S/+2v86HFA4iEoHht6z0oF80my3hFZE cLx2FxPdyO50aaP0VOqRmIy9p78GwGgAsS1h5sGJjzXmmNxas5Mo6uCbDA2BL/oB9ek+ 9x+WxueGC2AwmgEuc5rmBvTXZkv0WxilJ9m12REur2vg8y57N/c4fCs38VcmEQA7vgj9 kmXQ==
MIME-Version: 1.0
X-Received: by 10.152.4.41 with SMTP id h9mr4077884lah.49.1406144994602; Wed, 23 Jul 2014 12:49:54 -0700 (PDT)
Received: by 10.112.147.168 with HTTP; Wed, 23 Jul 2014 12:49:54 -0700 (PDT)
Date: Wed, 23 Jul 2014 15:49:54 -0400
Message-ID: <CAHbuEH5HsWa7TbwNDR6-FAn1JiXNdf+9+fMx-hbsBhbo2U=CaA@mail.gmail.com>
From: Kathleen Moriarty <kathleen.moriarty.ietf@gmail.com>
To: "ace@ietf.org" <ace@ietf.org>
Content-Type: multipart/alternative; boundary=089e013d1fdee7f72304fee1a478
Archived-At: http://mailarchive.ietf.org/arch/msg/ace/ZvJUmmbMFevd7zsajKC3SUs-4Rs
Subject: [Ace] Cyber Physical Extension for incident response presented in MILE
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 23 Jul 2014 19:50:00 -0000

--089e013d1fdee7f72304fee1a478
Content-Type: text/plain; charset=UTF-8

Hi,

In case there are folks interested there will be a presentation on the
exchange of cyber physical information for incident response in MILE.
 Presenter is from the industrial controls space and a researcher (also
interested in ACE).

http://www.ietf.org/proceedings/90/agenda/agenda-90-mile

Starting now (early)... in Salon B

-- 

Best regards,
Kathleen

--089e013d1fdee7f72304fee1a478
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr">Hi,<div><br></div><div>In case there are folks interested =
there will be a presentation on the exchange of cyber physical information =
for incident response in MILE. =C2=A0Presenter is from the industrial contr=
ols space and a researcher (also interested in ACE).</div>
<div><br></div><div><a href=3D"http://www.ietf.org/proceedings/90/agenda/ag=
enda-90-mile">http://www.ietf.org/proceedings/90/agenda/agenda-90-mile</a><=
/div><div><br></div><div>Starting now (early)... in Salon B<br clear=3D"all=
">
<div><br></div>-- <br><div dir=3D"ltr"><br><div>Best regards,</div><div>Kat=
hleen</div></div>
</div></div>

--089e013d1fdee7f72304fee1a478--


From nobody Wed Jul 23 14:26:39 2014
Return-Path: <mcr@sandelman.ca>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id DDF0D1A0AAA for <ace@ietfa.amsl.com>; Wed, 23 Jul 2014 14:26:36 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.892
X-Spam-Level: 
X-Spam-Status: No, score=-1.892 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001, T_TVD_MIME_NO_HEADERS=0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id NxVlKOh7pkXL for <ace@ietfa.amsl.com>; Wed, 23 Jul 2014 14:26:35 -0700 (PDT)
Received: from tuna.sandelman.ca (tuna.sandelman.ca [IPv6:2607:f0b0:f:3:216:3eff:fe7c:d1f3]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id BE6CD1A02F7 for <ace@ietf.org>; Wed, 23 Jul 2014 14:26:34 -0700 (PDT)
Received: from sandelman.ca (obiwan.sandelman.ca [209.87.249.21]) by tuna.sandelman.ca (Postfix) with ESMTP id 742EF20012; Wed, 23 Jul 2014 17:28:15 -0400 (EDT)
Received: by sandelman.ca (Postfix, from userid 179) id EF3A063B0E; Wed, 23 Jul 2014 17:26:32 -0400 (EDT)
Received: from sandelman.ca (localhost [127.0.0.1]) by sandelman.ca (Postfix) with ESMTP id DCDB563B0A; Wed, 23 Jul 2014 17:26:32 -0400 (EDT)
From: Michael Richardson <mcr+ietf@sandelman.ca>
To: Stefanie Gerdes <gerdes@tzi.de>
In-Reply-To: <53CFEE95.309@tzi.de>
References: <53CFEE95.309@tzi.de>
X-Mailer: MH-E 8.2; nmh 1.3-dev; GNU Emacs 23.4.1
X-Face: $\n1pF)h^`}$H>Hk{L"x@)JS7<%Az}5RyS@k9X%29-lHB$Ti.V>2bi.~ehC0; <'$9xN5Ub# z!G,p`nR&p7Fz@^UXIn156S8.~^@MJ*mMsD7=QFeq%AL4m<nPbLgmtKK-5dC@#:k
MIME-Version: 1.0
Content-Type: multipart/signed; boundary="=-=-="; micalg=pgp-sha1; protocol="application/pgp-signature"
Date: Wed, 23 Jul 2014 17:26:32 -0400
Message-ID: <23521.1406150792@sandelman.ca>
Sender: mcr@sandelman.ca
Archived-At: http://mailarchive.ietf.org/arch/msg/ace/0W2gytWkF4PNWEpMohqJb6cVtS0
Cc: "ace@ietf.org" <ace@ietf.org>
Subject: Re: [Ace] How to progress?
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 23 Jul 2014 21:26:37 -0000

--=-=-=


Stefanie Gerdes <gerdes@tzi.de> wrote:
    > These are the questions I came up with:
    > 1. What categories of constrained devices do we want to support (C0, C1..)?

I am skeptical that we will support C0 devices even with symmetric methods,
will they even support DTLS at all (from a code space point of view...)
I can HOWEVER, imagine a C0 device offloading part of it's DTLS setup to a
less constrained devices in a proprietary way, such that what results is that
it only processes symmetrically signed, DTLS encrypted CoAP messages.

    > 2. For each device in the architecture: What are the limitations of this
    > device?
    > 2a) Are the limitations always the same?
    > 2b) How much can we gain from introducing less constrained actors?

My take is that the important limitations of the constrained device are
not RAM/ROM/CPU/energy,  but rather network connectivity (quantity, latency,
and connectivity), and specifically the limits that puts on useful user
interfaces.

So the key service that the AS offers the RS is that it can evaluate complex
policies expressed poorly by not-always sane (but well meaning) humans, and
translate that into a series of authorization tokens that are easy to
evaluate.

(For instance, let's say that I wrote a policy like; "let all the members of
my family control the hot-tub temperature any available value, except for
Aunt Mertyl who is too elderly to understand she isn't allowed, so just give
her the ability to turn the jet on"... could be translated into, rather than
a group statement, into a series of unicastable tokens {member-of-family X
reasonable-temperatures}, which it distributes to the smartphones of the
people who needs them.  I guess if the WG prefers, I can translate to a
Banana example)

    > 3. What message sizes do we want to consider?

I'm not sure I understand the question.
I think that it should be possible to do all ACE provisioning over CoAP,
and I think CoAP likes 1K max message sizes, right?

    > 4. What are the application security requirements for the
    > communication between constrained nodes?
    > 4a) Integrity
    > 4b) Confidentiality
    > 4c) Non-Repudiation
    > 4e) ...
    > 4f) Are all of these always needed?

We need confidentiality, but we may assume it might be provided by layer-2 at
times.  We might not need any of the rest of the tokens are sufficiently
bound to the identities. In the general case, we have to support the
messages transiting the hostile open internet over multiple layer-2,
and contain bearer tokens. So from a specification point of view, we have a
MUST implement for all of these things, but a MAY on using them.

    > 5. Which level of security is needed on the devices (high, middle, low)?
    > 5a) Do we always need devices to be tamper-proof?

No, we can not afford all devices to be tamper-proof, but we might insist that
all devices be field upgradeable (that might be out of scope).  I might even
suggest that being tamper proof is opposed to some forms of field upgradeble.
Tamper proof != tamper detection/auditing.

In general, I think it is out-of-scope.

    > 6. How do the constraints of the nodes influence the protocols to be used?

I can not answer this yet.

    > 7. Can we find a single protocol which supports all kinds of devices in
    > every part of the architecture?

    > 8. What roles do proxies have that we want to support?

That's a hard question.
Can we start by making a list of what kind of roles proxies *can* do?

    > 9. Do we need authorization without user interaction?

Yes; it needs to be possible to give authorization servers a general policy
and let them generate new authorizations for new clients without an
interaction with either the RS or a human.

    > 10. Which constraints concerning the connectivity of devices do we want
    > to support?
    > 10a) "Offline" authorization (only some devices are "online", no
    > device is online, etc)
    > 10b) Intermittent connectivity
    > 10c) Special connectivity requirements (e.g. unidirectional links)

C and RS must each (seperately) be online during enrollment.
C must be able to act on RS when both are disconnected from everything.

    > I thought it might be helpful to collect the relevant questions and
    > assumptions in a wiki: http://trac.tools.ietf.org/wg/ace/trac/wiki/Questions

--
Michael Richardson <mcr+IETF@sandelman.ca>, Sandelman Software Works
 -= IPv6 IoT consulting =-




--=-=-=
Content-Type: application/pgp-signature

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iQEVAwUBU9AohoCLcPvd0N1lAQK0BQgAvrhZ+kLAjU4ks9WJNAyfMWmM1HOEr4So
D+cCiNom7clmRBVlcFQinaLaGp70fCm2EYKXx8qCTjSJomZLfWzb3hPFazpbkKxL
hARPh5pz7n5+7OnpGIckaH73P3EOsN52Jl1ur3BjP6wyvJtwAgd72c7CbcDyG3Cw
6XLoCrqj0BDbUX6EO50+bat/3F81L1RyzIR+TRQvnkjGKs5XuP1uiGIvB6blJRgC
bwjnqg5rxC9B7EIpFneAvpQ57MPLo5RS0SZTZMccqvHzTrMwLP0WvdU91F7c1v1P
wMxnL+k81q/LFHTs2luqehmVo6b5v6nyNk65SR4yBO1iw1UBNvGo5Q==
=ZxaH
-----END PGP SIGNATURE-----
--=-=-=--


From nobody Wed Jul 23 22:49:16 2014
Return-Path: <goran.selander@ericsson.com>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id A48951A0054 for <ace@ietfa.amsl.com>; Wed, 23 Jul 2014 22:49:14 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -3.901
X-Spam-Level: 
X-Spam-Status: No, score=-3.901 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, MIME_8BIT_HEADER=0.3, RCVD_IN_DNSWL_MED=-2.3, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 6D2G8ud5MP9a for <ace@ietfa.amsl.com>; Wed, 23 Jul 2014 22:49:12 -0700 (PDT)
Received: from sessmg23.ericsson.net (sessmg23.ericsson.net [193.180.251.45]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 18C7F1A005C for <ace@ietf.org>; Wed, 23 Jul 2014 22:49:11 -0700 (PDT)
X-AuditID: c1b4fb2d-f798a6d000000e9b-f0-53d09e55b102
Received: from ESESSHC023.ericsson.se (Unknown_Domain [153.88.253.124]) by sessmg23.ericsson.net (Symantec Mail Security) with SMTP id EB.D8.03739.55E90D35; Thu, 24 Jul 2014 07:49:09 +0200 (CEST)
Received: from ESESSMB303.ericsson.se ([169.254.3.228]) by ESESSHC023.ericsson.se ([153.88.183.87]) with mapi id 14.03.0174.001; Thu, 24 Jul 2014 07:49:09 +0200
From: =?iso-8859-1?Q?G=F6ran_Selander?= <goran.selander@ericsson.com>
To: Stefanie Gerdes <gerdes@tzi.de>, "ace@ietf.org" <ace@ietf.org>
Thread-Topic: [Ace] How to progress?
Thread-Index: AQHPppqMCxaFadAHvU67dSKfrHzBO5uuuMKA
Date: Thu, 24 Jul 2014 05:49:08 +0000
Message-ID: <CFF65AA1.16001%goran.selander@ericsson.com>
References: <53CFEE95.309@tzi.de>
In-Reply-To: <53CFEE95.309@tzi.de>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
user-agent: Microsoft-MacOutlook/14.4.2.140509
x-originating-ip: [153.88.183.154]
Content-Type: text/plain; charset="iso-8859-1"
Content-ID: <6DB5DD6CE5BB654BBC7BB4C87F692960@ericsson.com>
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
X-Brightmail-Tracker: H4sIAAAAAAAAA+NgFmphkeLIzCtJLcpLzFFi42KZGfG3Rjd03oVgg12nzC2+f+thtth48S6j A5PHkiU/mTy2vf3KHMAUxWWTkpqTWZZapG+XwJWx4/ka5oLzhhXXW76yNDD+VO1i5OSQEDCR 6Hk8lRXCFpO4cG89WxcjF4eQwFFGia97XzBCOEsYJR59/8gCUsUm4Cpx4ME7JhBbRMBJomvK NrC4sICyxMTnP6DiKhL3vy1ihLCNJObM2AQWZxFQlTjZ2Apm8wpYSLzae5gNxBYSUJSYtXYp 2BxOASWJ2ZMvgtUwAl30/dQaMJtZQFzi1pP5TBCXCkgs2XOeGcIWlXj5+B/YB6ICehLNXW8Y IeJKEotuf4bq1ZO4MXUK0C4OINta4u5yWYiwtsSyha+ZIc4RlDg58wnLBEbxWUi2zULSPQuh exaS7llIuhcwsq5iFC1OLS7OTTcy1kstykwuLs7P08tLLdnECIy2g1t+6+5gXP3a8RCjAAej Eg/vg/3ng4VYE8uKK3MPMUpzsCiJ8y46Ny9YSCA9sSQ1OzW1ILUovqg0J7X4ECMTB6dUA+OU gl261xL7nyYIfvr//Xp+3gX2OcZbXOsc3u/7r9DVeHKl/MTZffXB93qu5l5JaJW59aow6X/b /PKCHXOez3cS3XdD/4xnzW3xrOj3TI5csReWL9KLlD72wD1mGf+JTw+Cjqw/9arM001+m8aS WU3np/Wqb+ZqK95mxTnhKodTas+Vy0cCfgsrsRRnJBpqMRcVJwIAuGi2DJcCAAA=
Archived-At: http://mailarchive.ietf.org/arch/msg/ace/FKKoCzIhNjkIB2POtdWpK90jHH4
Subject: Re: [Ace] How to progress?
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 24 Jul 2014 05:49:14 -0000

Hi Steffi, WG chairs and all,

First, on Steffi's high level question =B3How to progress?=B2.

The ACE WG meeting yesterday focused on the difficult questions, which I
think makes sense for a f2f meeting. But listening to the discussion, I
sensed no major disagreement of the general problem statement although
there are further use cases or aspects of use cases to be added, specific
details debated, and opinions of scope of the work. If this is indeed the
case - that there is an agreement about the problem statement at a certain
level - I think I would make sense to progress the work by listing what we
actually do agree upon, in parallel to working on the open questions.


One purpose with draft-seitz-ace-problem-description is exactly this.
Section 4 (4.1 - 4.10) of the problem description is trying to extrapolate
a list of more detailed assumptions and requirements from the use cases.
We also made a review of this list in the group of 8 persons attending the
Stockholm interim meeting, which is reflected in the -01 version. It also
lists some identified open issues (4.11).

There has been very few comments on this draft in general and section 4 in
particular.

- Do you (all) agree to the statements in section 4 of
draft-seitz-ace-problem-description?

- Is this useful as a starting point?


I include some specific items from section 4 into Steffi's questions
inline below. The items are labeled with the section number from the draft.


G=F6ran



On 23/07/14 19:19, "Stefanie Gerdes" <gerdes@tzi.de> wrote:

>Hi everyone,
>
>The discussion today and during the previous meetings made me think that
>there are still a lot of unspoken assumptions and requirements flying
>around. I think we won't be able to come to an agreement on a solution
>if we don't manage to identify the key assumptions and requirements.
>This is why I came up with a couple of questions which I think would
>help to explore the context of the problem we are trying to solve. I
>know that there will in most cases not be only one answer to these
>questions but I think we will need to get a feeling about the range of
>answers.
>
>These are the questions I came up with:
>1. What categories of constrained devices do we want to support (C0,
>C1..)?
>  1a) What are the smallest devices we are going to support (RAM, ROM,
>etc)?

[ 4.2 Constrained Devices


o C and RS may be class 1 (potentially with large effort) or more
        powerful devices.]



>2. For each device in the architecture: What are the limitations of this
>device?

[ 4.2 Constrained Devices

o C and/or RS may be constrained in terms of power, processing,
        communication bandwidth, memory and storage space, and moreover

         - unable to manage complex authorization policies

         - unable to manage a large number of secure connections

         - without user interface

         - without constant network connectivity

         - unable to precisely measure time

         - required to save on wireless communication due to high power
           consumption


o AS is not a constrained device.


o All devices can process symmetric cryptography without incurring
        an excessive performance penalty.

         - We assume the use of a standardized symmetric key algorithm,
           such as AES.

         - Except for the most constrained devices we assume the use of
           a standardized cryptographic hash function such as SHA-256.

      o Public key cryptography requires additional resources (e.g. RAM,
        ROM, power).

      o A DTLS handshake with public key cryptography involves
        significant computation, communication, and memory overheads in
        the context of constrained devices.

         - The RAM requirements of DTLS handshake with public key
           cryptography may be prohibitive for constrained devices.

         - Certificate-based DTLS handshake requires extensive resources
           e.g. in terms of ROM.


]



>  2a) Are the limitations always the same?
>  2b) How much can we gain from introducing less constrained actors?
>3. What message sizes do we want to consider?
>4. What are the application security requirements for the
>   communication between constrained nodes?

[4.6 Resource access


o By default, the resource request shall be integrity protected
        and may be encrypted end-to-end from C to RS.  It shall be
        possible for RS to detect a replayed request.  (DTLS supports
        this.)

      o By default, the response to a request shall be integrity
        protected and may be encrypted end-to-end from RS to C.  (DTLS
        supports this.)


]

>  4a) Integrity
>  4b) Confidentiality
>  4c) Non-Repudiation
>  4e) ...
>  4f) Are all of these always needed?
>5. Which level of security is needed on the devices (high, middle, low)?
>  5a) Do we always need devices to be tamper-proof?
>6. How do the constraints of the nodes influence the protocols to be used?
>7. Can we find a single protocol which supports all kinds of devices in
>  every part of the architecture?
>8. What roles do proxies have that we want to support?
>9. Do we need authorization without user interaction?
>10. Which constraints concerning the connectivity of devices do we want
>   to support?

[ 4.5 Access to authorization information


o RS may not be able to communicate with AS at the time of the
        request from C.


o RS may store or cache authorization information.


GS: there was also a question about whether C could be unable to
communicate with AS at the time of the request to the RS, see
http://www.ietf.org/mail-archive/web/ace/current/msg00725.html

]


>  10a) "Offline" authorization (only some devices are "online", no
>       device is online, etc)
>  10b) Intermittent connectivity
>  10c) Special connectivity requirements (e.g. unidirectional links)
>
>
>I thought it might be helpful to collect the relevant questions and
>assumptions in a wiki:
>http://trac.tools.ietf.org/wg/ace/trac/wiki/Questions
>
>What do you think?
>
>Thanks,
>Steffi
>
>_______________________________________________
>Ace mailing list
>Ace@ietf.org
>https://www.ietf.org/mailman/listinfo/ace


From nobody Thu Jul 24 03:40:05 2014
Return-Path: <gerdes@tzi.de>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 349C81A0196 for <ace@ietfa.amsl.com>; Thu, 24 Jul 2014 03:40:04 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.551
X-Spam-Level: 
X-Spam-Status: No, score=-1.551 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HELO_EQ_DE=0.35, SPF_HELO_PASS=-0.001] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 3BJloRZKuG5k for <ace@ietfa.amsl.com>; Thu, 24 Jul 2014 03:40:03 -0700 (PDT)
Received: from informatik.uni-bremen.de (mailhost.informatik.uni-bremen.de [IPv6:2001:638:708:30c9::12]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id B10E41A0175 for <Ace@ietf.org>; Thu, 24 Jul 2014 03:40:02 -0700 (PDT)
X-Virus-Scanned: amavisd-new at informatik.uni-bremen.de
Received: from smtp-fb3.informatik.uni-bremen.de (smtp-fb3.informatik.uni-bremen.de [134.102.224.120]) by informatik.uni-bremen.de (8.14.5/8.14.5) with ESMTP id s6OAdsLd021443; Thu, 24 Jul 2014 12:39:54 +0200 (CEST)
Received: from [134.102.218.214] (dynamic-218-o.informatik.uni-bremen.de [134.102.218.214]) (using TLSv1 with cipher DHE-RSA-CAMELLIA256-SHA (256/256 bits)) (No client certificate requested) by smtp-fb3.informatik.uni-bremen.de (Postfix) with ESMTPSA id CEFD55D8; Thu, 24 Jul 2014 12:39:54 +0200 (CEST)
Message-ID: <53D0E27A.2020206@tzi.de>
Date: Thu, 24 Jul 2014 12:39:54 +0200
From: Stefanie Gerdes <gerdes@tzi.de>
User-Agent: Mozilla/5.0 (X11; Linux i686 on x86_64; rv:24.0) Gecko/20100101 Thunderbird/24.2.0
MIME-Version: 1.0
To: Hannes Tschofenig <hannes.tschofenig@gmx.net>, "Ace@ietf.org" <Ace@ietf.org>
References: <53CFEE95.309@tzi.de> <53D00795.3040100@gmx.net>
In-Reply-To: <53D00795.3040100@gmx.net>
X-Enigmail-Version: 1.6
Content-Type: text/plain; charset=ISO-8859-1
Content-Transfer-Encoding: 7bit
Archived-At: http://mailarchive.ietf.org/arch/msg/ace/mNxguadJmo2j_8S2jbM3w6VbU68
Subject: Re: [Ace] How to progress?
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 24 Jul 2014 10:40:04 -0000

Hi Hannes,

On 07/23/2014 09:05 PM, Hannes Tschofenig wrote:
> Hi Steffi,
> 
> the attempt so far was to answer these questions from a different 
> direction: instead of starting with a specific device platform
> (e.g., class, memory requirements, message size, etc.) we thought
> that the use cases are going to constrain the solution space and
> help to guide our work.
> 
> It turned out that this is rather complex since we have not managed
> to receive detailed enough use case descriptions that would, for
> example, let us rule out a specific communication design pattern or
> prefer a specific credential type.
> 
> My worry is that we design for an artificial platform that may or
> may not reflect the use cases people have in mind. Of course, it
> might be possible that folks in the group do not want to share the
> details about their use cases and then we are obviously a bit in
> trouble since we just have to guess.

Yes, absolutely. I share your concern. I just think it might be easier
to discuss different aspects of the use cases instead of discussing a
complete use case at once. So I think it is useful to find key
questions to break the problem into digestible pieces.

Viele Gruesse
Steffi


From nobody Thu Jul 24 04:38:33 2014
Return-Path: <likepeng@huawei.com>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id E5D031A0203; Thu, 24 Jul 2014 04:38:29 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.201
X-Spam-Level: 
X-Spam-Status: No, score=-4.201 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_MED=-2.3, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 46nVkNPQGg7S; Thu, 24 Jul 2014 04:38:28 -0700 (PDT)
Received: from lhrrgout.huawei.com (lhrrgout.huawei.com [194.213.3.17]) (using TLSv1 with cipher RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 6A9D61A01EB; Thu, 24 Jul 2014 04:38:27 -0700 (PDT)
Received: from 172.18.7.190 (EHLO lhreml402-hub.china.huawei.com) ([172.18.7.190]) by lhrrg01-dlp.huawei.com (MOS 4.3.7-GA FastPath queued) with ESMTP id BKM20527; Thu, 24 Jul 2014 11:38:25 +0000 (GMT)
Received: from SZXEMA403-HUB.china.huawei.com (10.82.72.35) by lhreml402-hub.china.huawei.com (10.201.5.241) with Microsoft SMTP Server (TLS) id 14.3.158.1; Thu, 24 Jul 2014 12:38:24 +0100
Received: from SZXEMA501-MBS.china.huawei.com ([169.254.2.128]) by SZXEMA403-HUB.china.huawei.com ([10.82.72.35]) with mapi id 14.03.0158.001; Thu, 24 Jul 2014 19:38:22 +0800
From: Likepeng <likepeng@huawei.com>
To: "saag@ietf.org" <saag@ietf.org>
Thread-Topic: ACE meeting summary for IETF 90
Thread-Index: Ac+nM8uD7XHLfW3CRdS/fcLw1y3Lvg==
Date: Thu, 24 Jul 2014 11:38:21 +0000
Message-ID: <34966E97BE8AD64EAE9D3D6E4DEE36F25817AFEA@SZXEMA501-MBS.china.huawei.com>
Accept-Language: zh-CN, en-US
Content-Language: zh-CN
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
x-originating-ip: [10.193.85.71]
Content-Type: multipart/alternative; boundary="_000_34966E97BE8AD64EAE9D3D6E4DEE36F25817AFEASZXEMA501MBSchi_"
MIME-Version: 1.0
X-CFilter-Loop: Reflected
Archived-At: http://mailarchive.ietf.org/arch/msg/ace/eW4blvuj3chhZA6jCk0eFfd4RfU
Cc: "ace@ietf.org" <ace@ietf.org>
Subject: [Ace] ACE meeting summary for IETF 90
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 24 Jul 2014 11:38:30 -0000

--_000_34966E97BE8AD64EAE9D3D6E4DEE36F25817AFEASZXEMA501MBSchi_
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable

ACE (Authentication and Authorization for Constrained Environments)

Chairs: Kepeng Li, Hannes Tschofenig

Time: Wednesday morning, 9:00 ~ 11:30

Physical attendees: ~70



1. ACE Introduction (Chairs, 10 mins):



This was the first WG F2F meeting. Kepeng introduced briefly about ACE work=
. Hannes gave some brief summaries about Stockholm informal meeting.



2. Design Directions

2.1: Problem Description (Ludwig Seitz, 30 mins)



Most of the discussions were about different models: Pull model, Push model=
, Agent model, Push & Confirm model.



Different models can apply to different use cases.



We need to analyze the use cases to see which model(s) to choose.



2.2: Use Cases & Design Patterns (Ludwig Seitz, 30 mins)



There was discussion that there may be multiple authorization servers, and =
we need to consider the case to change authorization servers.



There was discussion that client joining network process should be out of s=
cope.



Hannes mentioned we have already called for adoption for use case draft. Th=
ree volunteers were identified to review the draft and provide feedback in =
the mailing list.



2.3: Design Considerations (Corinna Schmitt, 30 mins)



It was discussed that we should not be scared about asymmetric key, and als=
o we don't force on asymmetric key.



It was also discussed that we should not narrow down to either one of the t=
wo mechanisms (symmetric key vs. asymmetric key), different environments re=
quire different mechanisms.



We need to get more data to make decision about symmetric key and/or asymme=
tric key.



2.4: Cross-domain Support (Carsten Bormann, 30 mins)



It was discussed that we should consider legacy devices, and consider proxy=
 support.



3. Summary and Next Steps (Chairs, 10 mins)



Hannes mentioned about possible interim meeting(s): conference calls or F2F=
 meeting.



Hannes also mentioned that it will be good to use implementation experience=
 to collect data to help our designs.

Kind Regards
Kepeng

--_000_34966E97BE8AD64EAE9D3D6E4DEE36F25817AFEASZXEMA501MBSchi_
Content-Type: text/html; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable

<html xmlns:v=3D"urn:schemas-microsoft-com:vml" xmlns:o=3D"urn:schemas-micr=
osoft-com:office:office" xmlns:w=3D"urn:schemas-microsoft-com:office:word" =
xmlns:m=3D"http://schemas.microsoft.com/office/2004/12/omml" xmlns=3D"http:=
//www.w3.org/TR/REC-html40">
<head>
<meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3Dus-ascii"=
>
<meta name=3D"Generator" content=3D"Microsoft Word 12 (filtered medium)">
<style><!--
/* Font Definitions */
@font-face
	{font-family:SimSun;
	panose-1:2 1 6 0 3 1 1 1 1 1;}
@font-face
	{font-family:"Cambria Math";
	panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
	{font-family:Calibri;
	panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
	{font-family:SimSun;
	panose-1:2 1 6 0 3 1 1 1 1 1;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
	{margin:0cm;
	margin-bottom:.0001pt;
	text-align:justify;
	text-justify:inter-ideograph;
	font-size:10.5pt;
	font-family:"Calibri","sans-serif";}
a:link, span.MsoHyperlink
	{mso-style-priority:99;
	color:blue;
	text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
	{mso-style-priority:99;
	color:purple;
	text-decoration:underline;}
p.MsoPlainText, li.MsoPlainText, div.MsoPlainText
	{mso-style-priority:99;
	mso-style-link:"\7EAF\6587\672C Char";
	margin:0cm;
	margin-bottom:.0001pt;
	font-size:10.5pt;
	font-family:"Calibri","sans-serif";}
span.EmailStyle17
	{mso-style-type:personal-compose;
	font-family:"Calibri","sans-serif";
	color:windowtext;}
span.Char
	{mso-style-name:"\7EAF\6587\672C Char";
	mso-style-priority:99;
	mso-style-link:\7EAF\6587\672C;
	font-family:"Calibri","sans-serif";}
.MsoChpDefault
	{mso-style-type:export-only;}
/* Page Definitions */
@page WordSection1
	{size:612.0pt 792.0pt;
	margin:72.0pt 90.0pt 72.0pt 90.0pt;}
div.WordSection1
	{page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext=3D"edit" spidmax=3D"1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext=3D"edit">
<o:idmap v:ext=3D"edit" data=3D"1" />
</o:shapelayout></xml><![endif]-->
</head>
<body lang=3D"ZH-CN" link=3D"blue" vlink=3D"purple" style=3D"text-justify-t=
rim:punctuation">
<div class=3D"WordSection1">
<p class=3D"MsoPlainText"><span lang=3D"EN-US">ACE (Authentication and Auth=
orization for Constrained Environments)<o:p></o:p></span></p>
<p class=3D"MsoPlainText"><span lang=3D"EN-US">Chairs: Kepeng Li, Hannes Ts=
chofenig<o:p></o:p></span></p>
<p class=3D"MsoPlainText"><span lang=3D"EN-US">Time: Wednesday morning, 9:0=
0 ~ 11:30<o:p></o:p></span></p>
<p class=3D"MsoPlainText"><span lang=3D"EN-US">Physical attendees: ~70<o:p>=
</o:p></span></p>
<p class=3D"MsoPlainText"><span lang=3D"EN-US"><o:p>&nbsp;</o:p></span></p>
<p class=3D"MsoPlainText"><span lang=3D"EN-US">1. ACE Introduction (Chairs,=
 10 mins):
<o:p></o:p></span></p>
<p class=3D"MsoPlainText"><span lang=3D"EN-US"><o:p>&nbsp;</o:p></span></p>
<p class=3D"MsoPlainText"><span lang=3D"EN-US">This was the first WG F2F me=
eting. Kepeng introduced briefly about ACE work. Hannes gave some brief sum=
maries about Stockholm informal meeting.<o:p></o:p></span></p>
<p class=3D"MsoPlainText"><span lang=3D"EN-US"><o:p>&nbsp;</o:p></span></p>
<p class=3D"MsoPlainText"><span lang=3D"EN-US">2. Design Directions<o:p></o=
:p></span></p>
<p class=3D"MsoPlainText"><span lang=3D"EN-US">2.1: Problem Description (Lu=
dwig Seitz, 30 mins)<o:p></o:p></span></p>
<p class=3D"MsoPlainText"><span lang=3D"EN-US"><o:p>&nbsp;</o:p></span></p>
<p class=3D"MsoPlainText"><span lang=3D"EN-US">Most of the discussions were=
 about different models: Pull model, Push model, Agent model, Push &amp; Co=
nfirm model.<o:p></o:p></span></p>
<p class=3D"MsoPlainText"><span lang=3D"EN-US"><o:p>&nbsp;</o:p></span></p>
<p class=3D"MsoPlainText"><span lang=3D"EN-US">Different models can apply t=
o different use cases.<o:p></o:p></span></p>
<p class=3D"MsoPlainText"><span lang=3D"EN-US"><o:p>&nbsp;</o:p></span></p>
<p class=3D"MsoPlainText"><span lang=3D"EN-US">We need to analyze the use c=
ases to see which model(s) to choose.<o:p></o:p></span></p>
<p class=3D"MsoPlainText"><span lang=3D"EN-US"><o:p>&nbsp;</o:p></span></p>
<p class=3D"MsoPlainText"><span lang=3D"EN-US">2.2: Use Cases &amp; Design =
Patterns (Ludwig Seitz, 30 mins)<o:p></o:p></span></p>
<p class=3D"MsoPlainText"><span lang=3D"EN-US"><o:p>&nbsp;</o:p></span></p>
<p class=3D"MsoPlainText"><span lang=3D"EN-US">There was discussion that th=
ere may be multiple authorization servers, and we need to consider the case=
 to change authorization servers.<o:p></o:p></span></p>
<p class=3D"MsoPlainText"><span lang=3D"EN-US"><o:p>&nbsp;</o:p></span></p>
<p class=3D"MsoPlainText"><span lang=3D"EN-US">There was discussion that cl=
ient joining network process should be out of scope.<o:p></o:p></span></p>
<p class=3D"MsoPlainText"><span lang=3D"EN-US"><o:p>&nbsp;</o:p></span></p>
<p class=3D"MsoPlainText"><span lang=3D"EN-US">Hannes mentioned we have alr=
eady called for adoption for use case draft. Three volunteers were identifi=
ed to review the draft and provide feedback in the mailing list.<o:p></o:p>=
</span></p>
<p class=3D"MsoPlainText"><span lang=3D"EN-US"><o:p>&nbsp;</o:p></span></p>
<p class=3D"MsoPlainText"><span lang=3D"EN-US">2.3: Design Considerations (=
Corinna Schmitt, 30 mins)<o:p></o:p></span></p>
<p class=3D"MsoPlainText"><span lang=3D"EN-US"><o:p>&nbsp;</o:p></span></p>
<p class=3D"MsoPlainText"><span lang=3D"EN-US">It was discussed that we sho=
uld not be scared about asymmetric key, and also we don't force on asymmetr=
ic key.<o:p></o:p></span></p>
<p class=3D"MsoPlainText"><span lang=3D"EN-US"><o:p>&nbsp;</o:p></span></p>
<p class=3D"MsoPlainText"><span lang=3D"EN-US">It was also discussed that w=
e should not narrow down to either one of the two mechanisms (symmetric key=
 vs. asymmetric key), different environments require different mechanisms.<=
o:p></o:p></span></p>
<p class=3D"MsoPlainText"><span lang=3D"EN-US"><o:p>&nbsp;</o:p></span></p>
<p class=3D"MsoPlainText"><span lang=3D"EN-US">We need to get more data to =
make decision about symmetric key and/or asymmetric key.<o:p></o:p></span><=
/p>
<p class=3D"MsoPlainText"><span lang=3D"EN-US"><o:p>&nbsp;</o:p></span></p>
<p class=3D"MsoPlainText"><span lang=3D"EN-US">2.4: Cross-domain Support (C=
arsten Bormann, 30 mins)<o:p></o:p></span></p>
<p class=3D"MsoPlainText"><span lang=3D"EN-US"><o:p>&nbsp;</o:p></span></p>
<p class=3D"MsoPlainText"><span lang=3D"EN-US">It was discussed that we sho=
uld consider legacy devices, and consider proxy support.<o:p></o:p></span><=
/p>
<p class=3D"MsoPlainText"><span lang=3D"EN-US"><o:p>&nbsp;</o:p></span></p>
<p class=3D"MsoPlainText"><span lang=3D"EN-US">3. Summary and Next Steps (C=
hairs, 10 mins)<o:p></o:p></span></p>
<p class=3D"MsoPlainText"><span lang=3D"EN-US"><o:p>&nbsp;</o:p></span></p>
<p class=3D"MsoPlainText"><span lang=3D"EN-US">Hannes mentioned about possi=
ble interim meeting(s): conference calls or F2F meeting.<o:p></o:p></span><=
/p>
<p class=3D"MsoPlainText"><span lang=3D"EN-US"><o:p>&nbsp;</o:p></span></p>
<p class=3D"MsoPlainText"><span lang=3D"EN-US">Hannes also mentioned that i=
t will be good to use implementation experience to collect data to help our=
 designs.<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US"><o:p>&nbsp;</o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US">Kind Regards<o:p></o:p></span><=
/p>
<p class=3D"MsoNormal"><span lang=3D"EN-US">Kepeng<o:p></o:p></span></p>
</div>
</body>
</html>

--_000_34966E97BE8AD64EAE9D3D6E4DEE36F25817AFEASZXEMA501MBSchi_--


From nobody Thu Jul 24 07:16:26 2014
Return-Path: <gerdes@tzi.de>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id B20A31A0371 for <ace@ietfa.amsl.com>; Thu, 24 Jul 2014 07:16:24 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.251
X-Spam-Level: 
X-Spam-Status: No, score=-1.251 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HELO_EQ_DE=0.35, MIME_8BIT_HEADER=0.3, SPF_HELO_PASS=-0.001] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id b92vq-reVKXx for <ace@ietfa.amsl.com>; Thu, 24 Jul 2014 07:16:23 -0700 (PDT)
Received: from informatik.uni-bremen.de (mailhost.informatik.uni-bremen.de [IPv6:2001:638:708:30c9::12]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 01ACE1A0366 for <Ace@ietf.org>; Thu, 24 Jul 2014 07:16:22 -0700 (PDT)
X-Virus-Scanned: amavisd-new at informatik.uni-bremen.de
Received: from smtp-fb3.informatik.uni-bremen.de (smtp-fb3.informatik.uni-bremen.de [134.102.224.120]) by informatik.uni-bremen.de (8.14.5/8.14.5) with ESMTP id s6OEFMCm014668; Thu, 24 Jul 2014 16:15:22 +0200 (CEST)
Received: from [134.102.218.214] (dynamic-218-o.informatik.uni-bremen.de [134.102.218.214]) (using TLSv1 with cipher DHE-RSA-CAMELLIA256-SHA (256/256 bits)) (No client certificate requested) by smtp-fb3.informatik.uni-bremen.de (Postfix) with ESMTPSA id 9F197803; Thu, 24 Jul 2014 16:15:22 +0200 (CEST)
Message-ID: <53D114FA.3070606@tzi.de>
Date: Thu, 24 Jul 2014 16:15:22 +0200
From: Stefanie Gerdes <gerdes@tzi.de>
User-Agent: Mozilla/5.0 (X11; Linux i686 on x86_64; rv:24.0) Gecko/20100101 Thunderbird/24.2.0
MIME-Version: 1.0
To: "Ace@ietf.org" <Ace@ietf.org>, =?ISO-8859-1?Q?G=F6ran_Selander?= <goran.selander@ericsson.com>, Michael Richardson <mcr+ietf@sandelman.ca>, Hannes Tschofenig <hannes.tschofenig@gmx.net>, Rene Struik <rstruik.ext@gmail.com>, Likepeng <likepeng@huawei.com>
References: <53CFEE95.309@tzi.de> <53D00795.3040100@gmx.net> <53D0E27A.2020206@tzi.de>
In-Reply-To: <53D0E27A.2020206@tzi.de>
X-Enigmail-Version: 1.6
Content-Type: text/plain; charset=ISO-8859-1
Content-Transfer-Encoding: 8bit
Archived-At: http://mailarchive.ietf.org/arch/msg/ace/dG477yzJLS-bcLhnZFNL0zE2WF4
Subject: Re: [Ace] How to progress?
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 24 Jul 2014 14:16:24 -0000

Hi everyone,

Thank you for you input. I made an update to the questions based on the
comments I received so far. Please make sure I got your points.

Are these the questions we need to ask to define the problem we want to
solve? Are there more relevant aspects to the problem?

Please consult http://trac.tools.ietf.org/wg/ace/trac/wiki/Questions for
a more readable version.


# ACE: Exploring the problem space

1. What categories of constrained devices do we want to support (cf.
http://tools.ietf.org/rfc/rfc7228)?
 * C0 (data size << 10 KiB, code size << 100KiB) and above
 * C1 (data size ~ 10 KiB, code size ~ 100KiB) and above
 * C2 (data size ~ 50 KiB, code size ~ 250 KiB) and above
 * What are the smallest devices we are going to support (RAM, ROM, etc)?
2. What are the limitations of constrained devices?
 * Limited RAM, ROM
 * No user interfaces
 * Unable to precisely measure time
 * Limited ability to send / receive messages
 * Limited Energy
 * Are the limitations always the same?
3. Which configurations of constrainedness do we want to consider?
 * C and RS are constrained
 * C is constrained but RS is not
 * RS is constrained but C is not	
4. What can we gain from introducing less constrained actors?
 * Translate complex policies into authorization tokens which are easy
to validate
 * Providing the owner's policies without user interaction at the time
of authorization
 * Attribute Validation (does the entity in possession of a certain key
really posses the claimed attributes)
 * Providing a user interface to owners
 * Time Keeping
5. What are the limitations of less constrained actors?
6. What limitations of underlying protocols do we have to consider?
 * Frame size
7. What are the application security requirements for the communication
between constrained nodes?
 * Integrity
 * Confidentiality
 * Non-Repudiation
 * ...
 * Are all of these always needed?
8. Which level of security is needed on the devices (high, middle, low)?
 * Do we need the constrained devices to have unique identities?
 * Do we always need devices to be tamper-proof?
 * Do we need tamper detection/auditing?
 * Do we need end to end security?
9. How do the constraints of the nodes influence the protocols to be used?
10. Can we find a single protocol which supports all kinds of devices in
every part of the architecture?
 * Communication between two constrained devices
 * Communication where one endpoint is constrained
 * Communication between less constrained devices as needed to transmit
the authorization information
11. What roles do proxies have that we want to support?
 * Reverse proxies
 * Forward proxies
 * Cross-protocol proxies
12. Do we need authorization without user interaction?
13. Which constraints concerning the connectivity of devices do we want
to support?
 * "Offline" authorization (only some devices are "online", no device is
online, etc)
   - RS may not be able to communicate with AS at the time of the
request from C.
   - C may not be able to communicate with AM at the time of the request.
   - C may not be able to communicate with AS at the time of the request.
   - C must be able to act on RS when both are disconnected from everything
 * Intermittent connectivity
 * Latency
 * Special connectivity requirements (e.g. unidirectional links)
 * Sleepy Devices
14. Do we need to consider problems concerning the lifecycle of devices
other than the operational phase?
 * Commissioning
 * Maintenance
 * Decommissioning
 * Handover

Viele Grüße
Steffi


From nobody Mon Jul 28 13:30:05 2014
Return-Path: <kathleen.moriarty.ietf@gmail.com>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 718BB1B291D for <ace@ietfa.amsl.com>; Mon, 28 Jul 2014 13:29:58 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -0.599
X-Spam-Level: 
X-Spam-Status: No, score=-0.599 tagged_above=-999 required=5 tests=[BAYES_05=-0.5, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Ym9U4UQDr3LS for <ace@ietfa.amsl.com>; Mon, 28 Jul 2014 13:29:50 -0700 (PDT)
Received: from mail-la0-x235.google.com (mail-la0-x235.google.com [IPv6:2a00:1450:4010:c03::235]) (using TLSv1 with cipher ECDHE-RSA-RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 73B4D1A00EB for <ace@ietf.org>; Mon, 28 Jul 2014 13:29:50 -0700 (PDT)
Received: by mail-la0-f53.google.com with SMTP id gl10so5956050lab.12 for <ace@ietf.org>; Mon, 28 Jul 2014 13:29:48 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113;  h=mime-version:date:message-id:subject:from:to:content-type; bh=mdXEvYO4WxTMd3WcXrVkwHpJjlcEoSaUkoCVQACI1Y8=; b=tSn/MHWSLrybVhzvoXQ70XBu1tlXarKDg/ypwCiBywKOqY2O3KoC7kcPhiK0inPE0D xnYq52x4FV1QnEl4VYdLC5eQF44hNAgFIaDGz+YrphXODQXxZPsQmlm6qcFHAMvlySQX I+MaZT2vfS097r8LwQCR5A/ug7Lp2QxkVeVhCUk0ATRW0oETCMHMup0K4xpykKzgesqm M8uQXz1VmWx1IbI4oyFsDz1D8H7s/4vYVzjrH/ObSB2mY2DK/Cso+E6pv7UQc//BOnm3 x1FnPAg4HKbS5vAEOzpskA+7Wf61R1WUes8Nma6/NDE1Zkw+Q3f45BBU/58Jq/LOfzRY 7OGA==
MIME-Version: 1.0
X-Received: by 10.153.5.44 with SMTP id cj12mr38934608lad.36.1406579388536; Mon, 28 Jul 2014 13:29:48 -0700 (PDT)
Received: by 10.112.147.168 with HTTP; Mon, 28 Jul 2014 13:29:48 -0700 (PDT)
Date: Mon, 28 Jul 2014 16:29:48 -0400
Message-ID: <CAHbuEH7hn0iWJpx7hwaOQnDO9_n16ZKuDh4sF4G=LsPHXde6hg@mail.gmail.com>
From: Kathleen Moriarty <kathleen.moriarty.ietf@gmail.com>
To: "ace@ietf.org" <ace@ietf.org>
Content-Type: multipart/alternative; boundary=001a11349adccd5cae04ff46c8dc
Archived-At: http://mailarchive.ietf.org/arch/msg/ace/1W9rgg4J3Yx6weZMEOVGtntrIcY
Subject: [Ace] Use Case draft
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 28 Jul 2014 20:29:58 -0000

--001a11349adccd5cae04ff46c8dc
Content-Type: text/plain; charset=UTF-8

Hello,

I had read through the draft before the meeting and noted that in section
2.2.1, I thought the roles of the people involved in the use case were
distracting.  Changing this may help keep people focused on the scenario as
opposed to details that don't matter for ACE.  FYI - A single woman letting
an acquaintance into her home without her there would be unusual.  Most
women would not do that for safety reasons.  The interpretation of
acquaintance may vary between regions, but for me, an acquaintance is
someone I don't really know well.  If you make Jeffrey her brother, or
switch the roles of Jeffrey & Jane, the scenario is much more plausible and
will help to prevent people from getting distracted while reading this
scenario.

In reading through the draft, I noticed a few things missing from the
Security Requirements section that could be helpful for the next editorial
pass.  If there were reasons they were not included, please let me know.

1. Threats such as session intercept/hijacking or monitoring are not
covered yet.

2. Logging, protection of logs (and purging) is mentioned in one of the use
cases, but not in the security section.  This would be a good addition, but
should also include privacy considerations associated with the logs as well
(correlation of events, etc.).

3. There will also be a number of privacy considerations that should be
noted in this section or one on privacy.  This might include concerns of
being able to profile habits of a person or other similar concerns.

Thanks!
-- 

Best regards,
Kathleen

--001a11349adccd5cae04ff46c8dc
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr">Hello,<div><br></div><div>I had read through the draft bef=
ore the meeting and noted that in section 2.2.1, I thought the roles of the=
 people involved in the use case were distracting. =C2=A0Changing this may =
help keep people focused on the scenario as opposed to details that don&#39=
;t matter for ACE. =C2=A0FYI - A single woman letting an acquaintance into =
her home without her there would be unusual. =C2=A0Most women would not do =
that for safety reasons. =C2=A0The interpretation of acquaintance may vary =
between regions, but for me, an acquaintance is someone I don&#39;t really =
know well. =C2=A0If you make Jeffrey her brother, or switch the roles of Je=
ffrey &amp; Jane, the scenario is much more plausible and will help to prev=
ent people from getting distracted while reading this scenario.</div>
<div><br></div><div>In reading through the draft, I noticed a few things mi=
ssing from the Security Requirements section that could be helpful for the =
next editorial pass. =C2=A0If there were reasons they were not included, pl=
ease let me know.</div>
<div><br></div><div>1. Threats such as session intercept/hijacking or monit=
oring are not covered yet.</div><div><br></div><div>2. Logging, protection =
of logs (and purging) is mentioned in one of the use cases, but not in the =
security section. =C2=A0This would be a good addition, but should also incl=
ude privacy considerations associated with the logs as well (correlation of=
 events, etc.).</div>
<div><br></div><div>3. There will also be a number of privacy consideration=
s that should be noted in this section or one on privacy. =C2=A0This might =
include concerns of being able to profile habits of a person or other simil=
ar concerns. =C2=A0<br clear=3D"all">
<div><br></div><div>Thanks!</div>-- <br><div dir=3D"ltr"><br><div>Best rega=
rds,</div><div>Kathleen</div></div>
</div></div>

--001a11349adccd5cae04ff46c8dc--


From nobody Tue Jul 29 01:02:03 2014
Return-Path: <ludwig@sics.se>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 7CF201A059F for <ace@ietfa.amsl.com>; Tue, 29 Jul 2014 01:02:00 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.251
X-Spam-Level: 
X-Spam-Status: No, score=-2.251 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HELO_EQ_SE=0.35, RCVD_IN_DNSWL_LOW=-0.7, RP_MATCHES_RCVD=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id mAAwZgfzPaCl for <ace@ietfa.amsl.com>; Tue, 29 Jul 2014 01:01:55 -0700 (PDT)
Received: from outbox.sics.se (outbox.sics.se [193.10.64.137]) by ietfa.amsl.com (Postfix) with ESMTP id F31721ADDB5 for <ace@ietf.org>; Tue, 29 Jul 2014 01:01:51 -0700 (PDT)
Received: from e-mailfilter01.sunet.se (e-mailfilter01.sunet.se [192.36.171.201]) by outbox.sics.se (Postfix) with ESMTPS id 87B7819BD for <ace@ietf.org>; Tue, 29 Jul 2014 10:01:50 +0200 (CEST)
Received: from letter.sics.se (letter.sics.se [193.10.64.6]) by e-mailfilter01.sunet.se (8.14.4/8.14.4/Debian-4) with ESMTP id s6T81omJ019505 for <ace@ietf.org>; Tue, 29 Jul 2014 10:01:50 +0200
Received: from [89.253.76.185] (89-253-76-185.customers.ownit.se [89.253.76.185]) (Authenticated sender: ludwig@sics.se) by letter.sics.se (Postfix) with ESMTPSA id A641B40116 for <ace@ietf.org>; Tue, 29 Jul 2014 10:01:50 +0200 (CEST)
Message-ID: <53D754ED.7060700@sics.se>
Date: Tue, 29 Jul 2014 10:01:49 +0200
From: Ludwig Seitz <ludwig@sics.se>
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:24.0) Gecko/20100101 Thunderbird/24.6.0
MIME-Version: 1.0
To: ace@ietf.org
References: <CAHbuEH7hn0iWJpx7hwaOQnDO9_n16ZKuDh4sF4G=LsPHXde6hg@mail.gmail.com>
In-Reply-To: <CAHbuEH7hn0iWJpx7hwaOQnDO9_n16ZKuDh4sF4G=LsPHXde6hg@mail.gmail.com>
Content-Type: multipart/signed; protocol="application/pkcs7-signature"; micalg=sha1; boundary="------------ms010905000501060309030303"
X-Bayes-Prob: 0.9931 (Score 5, tokens from: outbound, outbound-sics-se:default, sics-se:default, base:default, @@RPTN)
X-p0f-Info: os=Solaris 10, link=Ethernet or modem
X-CanIt-Geo: =?UTF-8?Q?ip=3D89.253.76.185; _country=3DSE; _region=3DSk=C3=A5ne; _city=3DLund; _latitude=3D55.7000; _longitude=3D13.1833; _http://maps.google.com/maps=3Fq=3D55.7000,13.1833&z=3D6?=
X-CanItPRO-Stream: outbound-sics-se:outbound (inherits from outbound-sics-se:default, sics-se:default, base:default)
X-Canit-Stats-ID: 09Mw81Ob7 - 7b651509f756 - 20140729
X-Antispam-Training-Forget: https://canit.sunet.se/canit/b.php?i=09Mw81Ob7&m=7b651509f756&t=20140729&c=f
X-Antispam-Training-Nonspam: https://canit.sunet.se/canit/b.php?i=09Mw81Ob7&m=7b651509f756&t=20140729&c=n
X-Antispam-Training-Spam: https://canit.sunet.se/canit/b.php?i=09Mw81Ob7&m=7b651509f756&t=20140729&c=s
X-CanIt-Archive-Cluster: PfMRe/vJWMiXwM2YIH5BVExnUnw
X-Scanned-By: CanIt (www . roaringpenguin . com) on 192.36.171.201
Archived-At: http://mailarchive.ietf.org/arch/msg/ace/-oNysda7Hfx2AVJ1ttBJiMWnfWk
Subject: Re: [Ace] Use Case draft
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 29 Jul 2014 08:02:00 -0000

This is a cryptographically signed message in MIME format.

--------------ms010905000501060309030303
Content-Type: text/plain; charset=ISO-8859-1; format=flowed
Content-Transfer-Encoding: quoted-printable

On 07/28/2014 10:29 PM, Kathleen Moriarty wrote:
> Hello,
>
> I had read through the draft before the meeting and noted that in
> section 2.2.1, I thought the roles of the people involved in the use
> case were distracting.  Changing this may help keep people focused on
> the scenario as opposed to details that don't matter for ACE.  FYI - A
> single woman letting an acquaintance into her home without her there
> would be unusual.  Most women would not do that for safety reasons.  Th=
e
> interpretation of acquaintance may vary between regions, but for me, an=

> acquaintance is someone I don't really know well.  If you make Jeffrey
> her brother, or switch the roles of Jeffrey & Jane, the scenario is muc=
h
> more plausible and will help to prevent people from getting distracted
> while reading this scenario.
>
I'll update this in the next version if we don't change the use case=20
entirely.

> In reading through the draft, I noticed a few things missing from the
> Security Requirements section that could be helpful for the next
> editorial pass.  If there were reasons they were not included, please
> let me know.
>
> 1. Threats such as session intercept/hijacking or monitoring are not
> covered yet.

The idea of this draft was to cover issues concerning authentication and =

authorization (and a few  directly related issues) since that is the=20
topic of ACE. I think the problems you mention above are not directly=20
relevant for ACE, therefore I left them out of the document.

>
> 2. Logging, protection of logs (and purging) is mentioned in one of the=

> use cases, but not in the security section.  This would be a good
> addition, but should also include privacy considerations associated wit=
h
> the logs as well (correlation of events, etc.).

We had a discussion about Auditing (the third A of AAA) and logging=20
during the chartering process, and some people thought it would make the =

focus of the group too broad to try and also cover Auditing (including=20
logging).

Therefore I have left out questions of auditing (and privacy) for the=20
moment.


>
> 3. There will also be a number of privacy considerations that should be=

> noted in this section or one on privacy.  This might include concerns o=
f
> being able to profile habits of a person or other similar concerns.
>

See above.



Regards,

Ludwig Seitz


--=20
Ludwig Seitz, PhD
SICS Swedish ICT AB
Ideon Science Park
Building Beta 2
Scheelev=E4gen 17
SE-223 70 Lund

Phone +46(0)70-349 92 51
http://www.sics.se


--------------ms010905000501060309030303
Content-Type: application/pkcs7-signature; name="smime.p7s"
Content-Transfer-Encoding: base64
Content-Disposition: attachment; filename="smime.p7s"
Content-Description: S/MIME Cryptographic Signature

MIAGCSqGSIb3DQEHAqCAMIACAQExCzAJBgUrDgMCGgUAMIAGCSqGSIb3DQEHAQAAoIIMVDCC
BhgwggUAoAMCAQICAwiRTjANBgkqhkiG9w0BAQsFADCBjDELMAkGA1UEBhMCSUwxFjAUBgNV
BAoTDVN0YXJ0Q29tIEx0ZC4xKzApBgNVBAsTIlNlY3VyZSBEaWdpdGFsIENlcnRpZmljYXRl
IFNpZ25pbmcxODA2BgNVBAMTL1N0YXJ0Q29tIENsYXNzIDEgUHJpbWFyeSBJbnRlcm1lZGlh
dGUgQ2xpZW50IENBMB4XDTE0MDEwNzA3MjgzNVoXDTE1MDEwNzEyNTgyMlowODEXMBUGA1UE
AwwObHVkd2lnQHNpY3Muc2UxHTAbBgkqhkiG9w0BCQEWDmx1ZHdpZ0BzaWNzLnNlMIIBIjAN
BgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAnLm1tc30QxHa9wtdVjC3NgxjLJicnccm0HD+
1X16kPMKGvwps8F1oDhYn7jXIe46p1AuJMzLK0GIioE4JwxCFGdvpz7cg2xyTyrdBVUzSqez
Dfqt4FOJq6hrdrIMS8MHEzl7Jk02gv9cTn/pHQvDpkiThRpbSLU5mlMqtEQ8gDQY5YyBX0Mv
5qculV08I2JU8HEeTt1oeqhvBImgQfOVYMDatHlWHUVVrmYd6iIo+cuiUGd5kiA0XuaLYX0E
oCoao/z5Wg9U0sQlx0hl4r96Q+NdoZZ1prfts3qtyBzJ2hu135aikigzJ6sueWHv/jbISUek
tOMm0xkx1GOqqWtEAwIDAQABo4IC1DCCAtAwCQYDVR0TBAIwADALBgNVHQ8EBAMCBLAwHQYD
VR0lBBYwFAYIKwYBBQUHAwIGCCsGAQUFBwMEMB0GA1UdDgQWBBRZmjjBh8N3klra+mVQgC00
pl68ZTAfBgNVHSMEGDAWgBRTcu2SnODaywFcfH6WNU7y1LhRgjAZBgNVHREEEjAQgQ5sdWR3
aWdAc2ljcy5zZTCCAUwGA1UdIASCAUMwggE/MIIBOwYLKwYBBAGBtTcBAgMwggEqMC4GCCsG
AQUFBwIBFiJodHRwOi8vd3d3LnN0YXJ0c3NsLmNvbS9wb2xpY3kucGRmMIH3BggrBgEFBQcC
AjCB6jAnFiBTdGFydENvbSBDZXJ0aWZpY2F0aW9uIEF1dGhvcml0eTADAgEBGoG+VGhpcyBj
ZXJ0aWZpY2F0ZSB3YXMgaXNzdWVkIGFjY29yZGluZyB0byB0aGUgQ2xhc3MgMSBWYWxpZGF0
aW9uIHJlcXVpcmVtZW50cyBvZiB0aGUgU3RhcnRDb20gQ0EgcG9saWN5LCByZWxpYW5jZSBv
bmx5IGZvciB0aGUgaW50ZW5kZWQgcHVycG9zZSBpbiBjb21wbGlhbmNlIG9mIHRoZSByZWx5
aW5nIHBhcnR5IG9ibGlnYXRpb25zLjA2BgNVHR8ELzAtMCugKaAnhiVodHRwOi8vY3JsLnN0
YXJ0c3NsLmNvbS9jcnR1MS1jcmwuY3JsMIGOBggrBgEFBQcBAQSBgTB/MDkGCCsGAQUFBzAB
hi1odHRwOi8vb2NzcC5zdGFydHNzbC5jb20vc3ViL2NsYXNzMS9jbGllbnQvY2EwQgYIKwYB
BQUHMAKGNmh0dHA6Ly9haWEuc3RhcnRzc2wuY29tL2NlcnRzL3N1Yi5jbGFzczEuY2xpZW50
LmNhLmNydDAjBgNVHRIEHDAahhhodHRwOi8vd3d3LnN0YXJ0c3NsLmNvbS8wDQYJKoZIhvcN
AQELBQADggEBAHqEYmtWr83S+iLXE97KBnHJZiMr6PMuLKxmh0o6UJJwKgf+KTP2czxRnPSI
+whuqfQZdmz6g3A2K8AooMU0RXrzncnX1c4826APdnXkRxnGQxtZXI1wuhPn4z7iDKZ6ij9u
K5Pfn10JL/ERDig2qJQbqvhtIAx0RY7y7r+hLMvgXVq9mf3WRJYmGQeFW+N9t5Z1eEwG4m9R
KAZm0fnfeDn/Ai4kmxTckBH7dZwW2lTtwQqQ4su+PGCJ0e9ndBLpvTqaYGSAl+L7PO7vxPhS
/cS67Xa6BtnYJLTr3MaGXaN+CEUFSfwQHa9DKcAqh3kldErI3kCvnot0CigBl4aILOEwggY0
MIIEHKADAgECAgEeMA0GCSqGSIb3DQEBBQUAMH0xCzAJBgNVBAYTAklMMRYwFAYDVQQKEw1T
dGFydENvbSBMdGQuMSswKQYDVQQLEyJTZWN1cmUgRGlnaXRhbCBDZXJ0aWZpY2F0ZSBTaWdu
aW5nMSkwJwYDVQQDEyBTdGFydENvbSBDZXJ0aWZpY2F0aW9uIEF1dGhvcml0eTAeFw0wNzEw
MjQyMTAxNTVaFw0xNzEwMjQyMTAxNTVaMIGMMQswCQYDVQQGEwJJTDEWMBQGA1UEChMNU3Rh
cnRDb20gTHRkLjErMCkGA1UECxMiU2VjdXJlIERpZ2l0YWwgQ2VydGlmaWNhdGUgU2lnbmlu
ZzE4MDYGA1UEAxMvU3RhcnRDb20gQ2xhc3MgMSBQcmltYXJ5IEludGVybWVkaWF0ZSBDbGll
bnQgQ0EwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDHCYPMzi3YGrEppC4Tq5a+
ijKDjKaIQZZVR63UbxIP6uq/I0fhCu+cQhoUfE6ERKKnu8zPf1Jwuk0tsvVCk6U9b+0UjM0d
Lep3ZdE1gblK/1FwYT5Pipsu2yOMluLqwvsuz9/9f1+1PKHG/FaR/wpbfuIqu54qzHDYeqiU
fsYzoVflR80DAC7hmJ+SmZnNTWyUGHJbBpA8Q89lGxahNvuryGaC/o2/ceD2uYDX9U8Eg5Dp
IpGQdcbQeGarV04WgAUjjXX5r/2dabmtxWMZwhZna//jdiSyrrSMTGKkDiXm6/3/4ebfeZuC
YKzN2P8O2F/Xe2AC/Y7zeEsnR7FOp+uXAgMBAAGjggGtMIIBqTAPBgNVHRMBAf8EBTADAQH/
MA4GA1UdDwEB/wQEAwIBBjAdBgNVHQ4EFgQUU3Ltkpzg2ssBXHx+ljVO8tS4UYIwHwYDVR0j
BBgwFoAUTgvvGqRAW6UXaYcwyjRoQ9BBrvIwZgYIKwYBBQUHAQEEWjBYMCcGCCsGAQUFBzAB
hhtodHRwOi8vb2NzcC5zdGFydHNzbC5jb20vY2EwLQYIKwYBBQUHMAKGIWh0dHA6Ly93d3cu
c3RhcnRzc2wuY29tL3Nmc2NhLmNydDBbBgNVHR8EVDBSMCegJaAjhiFodHRwOi8vd3d3LnN0
YXJ0c3NsLmNvbS9zZnNjYS5jcmwwJ6AloCOGIWh0dHA6Ly9jcmwuc3RhcnRzc2wuY29tL3Nm
c2NhLmNybDCBgAYDVR0gBHkwdzB1BgsrBgEEAYG1NwECATBmMC4GCCsGAQUFBwIBFiJodHRw
Oi8vd3d3LnN0YXJ0c3NsLmNvbS9wb2xpY3kucGRmMDQGCCsGAQUFBwIBFihodHRwOi8vd3d3
LnN0YXJ0c3NsLmNvbS9pbnRlcm1lZGlhdGUucGRmMA0GCSqGSIb3DQEBBQUAA4ICAQAKgwh9
eKssBly4Y4xerhy5I3dNoXHYfYa8PlVLL/qtXnkFgdtY1o95CfegFJTwqBBmf8pyTUnFsukD
FUI22zF5bVHzuJ+GxhnSqN2sD1qetbYwBYK2iyYA5Pg7Er1A+hKMIzEzcduRkIMmCeUTyMyi
kfbUFvIBivtvkR8ZFAk22BZy+pJfAoedO61HTz4qSfQoCRcLN5A0t4DkuVhTMXIzuQ8Cnykh
ExD6x4e6ebIbrjZLb7L+ocR0y4YjCl/Pd4MXU91y0vTipgr/O75CDUHDRHCCKBVmz/Rzkc/b
970MEeHt5LC3NiWTgBSvrLEuVzBKM586YoRD9Dy3OHQgWI270g+5MYA8GfgI/EPT5G7xPbCD
z+zjdH89PeR3U4So4lSXur6H6vp+m9TQXPF3a0LwZrp8MQ+Z77U1uL7TelWO5lApsbAonrqA
SfTpaprFVkL4nyGH+NHST2ZJPWIBk81i6Vw0ny0qZW2Niy/QvVNKbb43A43ny076khXO7cNb
BIRdJ/6qQNq9Bqb5C0Q5nEsFcj75oxQRqlKf6TcvGbjxkJh8BYtv9ePsXklAxtm8J7GCUBth
HSQgepbkOexhJ0wP8imUkyiPHQ0GvEnd83129fZjoEhdGwXV27ioRKbj/cIq7JRXun0NbeY+
UdMYu9jGfIpDLtUUGSgsg2zMGs5R4jGCA90wggPZAgEBMIGUMIGMMQswCQYDVQQGEwJJTDEW
MBQGA1UEChMNU3RhcnRDb20gTHRkLjErMCkGA1UECxMiU2VjdXJlIERpZ2l0YWwgQ2VydGlm
aWNhdGUgU2lnbmluZzE4MDYGA1UEAxMvU3RhcnRDb20gQ2xhc3MgMSBQcmltYXJ5IEludGVy
bWVkaWF0ZSBDbGllbnQgQ0ECAwiRTjAJBgUrDgMCGgUAoIICHTAYBgkqhkiG9w0BCQMxCwYJ
KoZIhvcNAQcBMBwGCSqGSIb3DQEJBTEPFw0xNDA3MjkwODAxNDlaMCMGCSqGSIb3DQEJBDEW
BBTHHq2ZgNVpIvKzBakAvhhz4ETx1DBsBgkqhkiG9w0BCQ8xXzBdMAsGCWCGSAFlAwQBKjAL
BglghkgBZQMEAQIwCgYIKoZIhvcNAwcwDgYIKoZIhvcNAwICAgCAMA0GCCqGSIb3DQMCAgFA
MAcGBSsOAwIHMA0GCCqGSIb3DQMCAgEoMIGlBgkrBgEEAYI3EAQxgZcwgZQwgYwxCzAJBgNV
BAYTAklMMRYwFAYDVQQKEw1TdGFydENvbSBMdGQuMSswKQYDVQQLEyJTZWN1cmUgRGlnaXRh
bCBDZXJ0aWZpY2F0ZSBTaWduaW5nMTgwNgYDVQQDEy9TdGFydENvbSBDbGFzcyAxIFByaW1h
cnkgSW50ZXJtZWRpYXRlIENsaWVudCBDQQIDCJFOMIGnBgsqhkiG9w0BCRACCzGBl6CBlDCB
jDELMAkGA1UEBhMCSUwxFjAUBgNVBAoTDVN0YXJ0Q29tIEx0ZC4xKzApBgNVBAsTIlNlY3Vy
ZSBEaWdpdGFsIENlcnRpZmljYXRlIFNpZ25pbmcxODA2BgNVBAMTL1N0YXJ0Q29tIENsYXNz
IDEgUHJpbWFyeSBJbnRlcm1lZGlhdGUgQ2xpZW50IENBAgMIkU4wDQYJKoZIhvcNAQEBBQAE
ggEAfFxmOjgJHxOlAoDaG6dQs9rhuhtON7a+9IRzGn8l7quH9X3gLvH4G6Z6biqE8y+1IBZr
aKQ9CyYsHejCIROuexrOyz+l9rgNxD3sUtEGXYy9f61S2VrVkErtxsiTeCIQjFquGhIt15Ei
ldROUzjI6mmy76Dz9VEeT1sJKTIuCgTy4wF1E1FWlTkzAFQr5nBuBFFoutsr5TV2JvWe2quM
nwrO42gIW7JGENJ0lkH2i6Aa/cDsX9JoBiJLJ0em6lhn4b0hW+Vq3s+i83qaPHGkrGDt3z7e
WuzIPpuEV2FzTIOcu3CuXbBVWbRb4cXGgC3L3ux17jCp7UnEReDRku2c/QAAAAAAAA==
--------------ms010905000501060309030303--


From nobody Tue Jul 29 05:16:53 2014
Return-Path: <gerdes@tzi.de>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 9A8B11B2829 for <ace@ietfa.amsl.com>; Tue, 29 Jul 2014 05:16:51 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.551
X-Spam-Level: 
X-Spam-Status: No, score=-1.551 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HELO_EQ_DE=0.35, SPF_HELO_PASS=-0.001] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id ry-Az8glKOIY for <ace@ietfa.amsl.com>; Tue, 29 Jul 2014 05:16:50 -0700 (PDT)
Received: from informatik.uni-bremen.de (mailhost.informatik.uni-bremen.de [IPv6:2001:638:708:30c9::12]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 1E1E11B2827 for <ace@ietf.org>; Tue, 29 Jul 2014 05:16:49 -0700 (PDT)
X-Virus-Scanned: amavisd-new at informatik.uni-bremen.de
Received: from smtp-fb3.informatik.uni-bremen.de (smtp-fb3.informatik.uni-bremen.de [134.102.224.120]) by informatik.uni-bremen.de (8.14.5/8.14.5) with ESMTP id s6TCGKJj021271; Tue, 29 Jul 2014 14:16:20 +0200 (CEST)
Received: from [134.102.218.214] (dynamic-218-o.informatik.uni-bremen.de [134.102.218.214]) (using TLSv1 with cipher DHE-RSA-CAMELLIA256-SHA (256/256 bits)) (No client certificate requested) by smtp-fb3.informatik.uni-bremen.de (Postfix) with ESMTPSA id B340B7E3; Tue, 29 Jul 2014 14:16:20 +0200 (CEST)
Message-ID: <53D79094.6000009@tzi.de>
Date: Tue, 29 Jul 2014 14:16:20 +0200
From: Stefanie Gerdes <gerdes@tzi.de>
User-Agent: Mozilla/5.0 (X11; Linux i686 on x86_64; rv:24.0) Gecko/20100101 Thunderbird/24.2.0
MIME-Version: 1.0
To: Ludwig Seitz <ludwig@sics.se>, ace@ietf.org, Kathleen Moriarty <kathleen.moriarty.ietf@gmail.com>
References: <CAHbuEH7hn0iWJpx7hwaOQnDO9_n16ZKuDh4sF4G=LsPHXde6hg@mail.gmail.com> <53D754ED.7060700@sics.se>
In-Reply-To: <53D754ED.7060700@sics.se>
X-Enigmail-Version: 1.6
Content-Type: text/plain; charset=ISO-8859-1
Content-Transfer-Encoding: 7bit
Archived-At: http://mailarchive.ietf.org/arch/msg/ace/rh47UC3RKuYvvBEDleC8_7pwp1U
Subject: Re: [Ace] Use Case draft
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 29 Jul 2014 12:16:52 -0000

Hi Kathleen and Ludwig,

On 07/29/2014 10:01 AM, Ludwig Seitz wrote:
> On 07/28/2014 10:29 PM, Kathleen Moriarty wrote:
>>
>> 2. Logging, protection of logs (and purging) is mentioned in one of the
>> use cases, but not in the security section.  This would be a good
>> addition, but should also include privacy considerations associated with
>> the logs as well (correlation of events, etc.).
> 
> We had a discussion about Auditing (the third A of AAA) and logging
> during the chartering process, and some people thought it would make the
> focus of the group too broad to try and also cover Auditing (including
> logging).
> 
> Therefore I have left out questions of auditing (and privacy) for the
> moment.

I think privacy is interesting to consider. The reason for using
authorization mechanisms is to protect data, i.e. to achieve certain
security objectives such as integrity and confidentiality. Privacy is
interesting to consider as it stresses the need for confidentiality.

Thanks
Steffi


From nobody Tue Jul 29 05:40:30 2014
Return-Path: <1095318589@qq.com>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 514641B285B for <ace@ietfa.amsl.com>; Tue, 29 Jul 2014 05:40:10 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: 1.129
X-Spam-Level: *
X-Spam-Status: No, score=1.129 tagged_above=-999 required=5 tests=[BAYES_05=-0.5, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_ENVFROM_END_DIGIT=0.25, FREEMAIL_FROM=0.001, FROM_EXCESS_BASE64=0.979, HTML_MESSAGE=0.001, MIME_BAD_LINEBREAK=0.5, RCVD_IN_DNSWL_NONE=-0.0001, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 2ba-jlQ_toLF for <ace@ietfa.amsl.com>; Tue, 29 Jul 2014 05:39:59 -0700 (PDT)
Received: from smtpbg64.qq.com (smtpbg64.qq.com [103.7.28.238]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 8562D1B283E for <ace@ietf.org>; Tue, 29 Jul 2014 05:39:49 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=qq.com; s=s201307; t=1406637584; bh=KnhHD35PKoqBUi/dT95dnoN7ZUqPun8qqYsj0/v0OPM=; h=X-QQ-mid:X-QQ-mid:X-QQ-SSF:From:To:Subject:Mime-Version:Content-Type:Content-Transfer-Encoding:Date: X-Priority:Message-ID:X-QQ-MIME:X-Mailer:X-QQ-Mailer: X-QQ-SENDSIZE; b=KXO6arhl65KSqdnLllS9S7tjtZrzcg6iFCiYsTiKocBU1bpvj/2/SZUO9CMIAuqH7 LDxtg0cmjlqCHNVpqGrEADy5eDhb41hE7X4qxzNLNINIXwgswyo804ODICP3ZccfXN I29yQp3UAs/7iQrBX/anyFXD8OWBbhRwtEHyS1CU=
X-QQ-mid: mb21t1406637582t6498903
X-QQ-mid: mb21t1406637582t6498903
X-QQ-SSF: 00000000000000F0F7100000000000L
From: "=?utf-8?B?S2VwZW5nIExp?=" <1095318589@qq.com>
To: "=?utf-8?B?Z2VyZGVz?=" <gerdes@tzi.de>, "=?utf-8?B?bHVkd2ln?=" <ludwig@sics.se>, "=?utf-8?B?YWNl?=" <ace@ietf.org>, "=?utf-8?B?a2F0aGxlZW4ubW9yaWFydHkuaWV0Zg==?=" <kathleen.moriarty.ietf@gmail.com>
Mime-Version: 1.0
Content-Type: multipart/alternative; boundary="----=_NextPart_53D7960E_0C6E7270_5C22CB5E"
Content-Transfer-Encoding: 8Bit
Date: Tue, 29 Jul 2014 20:39:42 +0800
X-Priority: 3
Message-ID: <tencent_26C922A4595ABF8F71A82A33@qq.com>
X-QQ-MIME: TCMime 1.0 by Tencent
X-Mailer: QQMail 2.x
X-QQ-Mailer: QQMail 2.x
X-QQ-SENDSIZE: 520
Archived-At: http://mailarchive.ietf.org/arch/msg/ace/toLMo9uImXESC7gq3mGPeJhxC_Q
Subject: Re: [Ace] Use Case draft
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 29 Jul 2014 12:40:10 -0000

This is a multi-part message in MIME format.

------=_NextPart_53D7960E_0C6E7270_5C22CB5E
Content-Type: text/plain;
	charset="utf-8"
Content-Transfer-Encoding: base64

QWdyZWUgd2l0aCBTdGVmZmkuDQoNCktpbmQgUmVnYXJkcw0KS2VwZW5nDQoNCi0tLS0tLS0t
LS0tLS0tLS0tLSDljp/lp4vpgq7ku7YgLS0tLS0tLS0tLS0tLS0tLS0tDQrlj5Hku7bkuro6
ICJTdGVmYW5pZSBHZXJkZXMiIDxnZXJkZXNAdHppLmRlPjsNCuWPkemAgeaXtumXtDogMjAx
NOW5tDfmnIgyOeaXpSjmmJ/mnJ/kuowpIDIwOjE2DQrmlLbku7bkuro6ICJMdWR3aWcgU2Vp
dHoiIDxsdWR3aWdAc2ljcy5zZT47ImFjZSIgPGFjZUBpZXRmLm9yZz47IkthdGhsZWVuIE1v
cmlhcnR5IiA8a2F0aGxlZW4ubW9yaWFydHkuaWV0ZkBnbWFpbC5jb20+Ow0K5Li76aKYOiBS
ZTogW0FjZV0gVXNlIENhc2UgZHJhZnQNCg0KDQoNCkhpIEthdGhsZWVuIGFuZCBMdWR3aWcs
IA0KIA0KT24gMDcvMjkvMjAxNCAxMDowMSBBTSwgTHVkd2lnIFNlaXR6IHdyb3RlOiANCj4g
T24gMDcvMjgvMjAxNCAxMDoyOSBQTSwgS2F0aGxlZW4gTW9yaWFydHkgd3JvdGU6IA0KPj4g
DQo+PiAyLiBMb2dnaW5nLCBwcm90ZWN0aW9uIG9mIGxvZ3MgKGFuZCBwdXJnaW5nKSBpcyBt
ZW50aW9uZWQgaW4gb25lIG9mIHRoZSANCj4+IHVzZSBjYXNlcywgYnV0IG5vdCBpbiB0aGUg
c2VjdXJpdHkgc2VjdGlvbi4gIFRoaXMgd291bGQgYmUgYSBnb29kIA0KPj4gYWRkaXRpb24s
IGJ1dCBzaG91bGQgYWxzbyBpbmNsdWRlIHByaXZhY3kgY29uc2lkZXJhdGlvbnMgYXNzb2Np
YXRlZCB3aXRoIA0KPj4gdGhlIGxvZ3MgYXMgd2VsbCAoY29ycmVsYXRpb24gb2YgZXZlbnRz
LCBldGMuKS4gDQo+ICANCj4gV2UgaGFkIGEgZGlzY3Vzc2lvbiBhYm91dCBBdWRpdGluZyAo
dGhlIHRoaXJkIEEgb2YgQUFBKSBhbmQgbG9nZ2luZyANCj4gZHVyaW5nIHRoZSBjaGFydGVy
aW5nIHByb2Nlc3MsIGFuZCBzb21lIHBlb3BsZSB0aG91Z2h0IGl0IHdvdWxkIG1ha2UgdGhl
IA0KPiBmb2N1cyBvZiB0aGUgZ3JvdXAgdG9vIGJyb2FkIHRvIHRyeSBhbmQgYWxzbyBjb3Zl
ciBBdWRpdGluZyAoaW5jbHVkaW5nIA0KPiBsb2dnaW5nKS4gDQo+ICANCj4gVGhlcmVmb3Jl
IEkgaGF2ZSBsZWZ0IG91dCBxdWVzdGlvbnMgb2YgYXVkaXRpbmcgKGFuZCBwcml2YWN5KSBm
b3IgdGhlIA0KPiBtb21lbnQuIA0KIA0KSSB0aGluayBwcml2YWN5IGlzIGludGVyZXN0aW5n
IHRvIGNvbnNpZGVyLiBUaGUgcmVhc29uIGZvciB1c2luZyANCmF1dGhvcml6YXRpb24gbWVj
aGFuaXNtcyBpcyB0byBwcm90ZWN0IGRhdGEsIGkuZS4gdG8gYWNoaWV2ZSBjZXJ0YWluIA0K
c2VjdXJpdHkgb2JqZWN0aXZlcyBzdWNoIGFzIGludGVncml0eSBhbmQgY29uZmlkZW50aWFs
aXR5LiBQcml2YWN5IGlzIA0KaW50ZXJlc3RpbmcgdG8gY29uc2lkZXIgYXMgaXQgc3RyZXNz
ZXMgdGhlIG5lZWQgZm9yIGNvbmZpZGVudGlhbGl0eS4gDQogDQpUaGFua3MgDQpTdGVmZmkg
DQogDQpfX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fXyAN
CkFjZSBtYWlsaW5nIGxpc3QgDQpBY2VAaWV0Zi5vcmcgDQpodHRwczovL3d3dy5pZXRmLm9y
Zy9tYWlsbWFuL2xpc3RpbmZvL2FjZQ==

------=_NextPart_53D7960E_0C6E7270_5C22CB5E
Content-Type: text/html;
	charset="utf-8"
Content-Transfer-Encoding: base64

QWdyZWUgd2l0aCBTdGVmZmkuPGJyPjxicj5LaW5kIFJlZ2FyZHM8YnI+S2VwZW5nPGJyLz48
YnIvPi0tLS0tLS0tLS0tLS0tLS0tLSDljp/lp4vpgq7ku7YgLS0tLS0tLS0tLS0tLS0tLS0t
PGJyLz48SFRNTD48Qk9EWT48ZGl2IHN0eWxlPSJmb250LXNpemU6IDEycHg7IGJhY2tncm91
bmQ6IG5vbmUgcmVwZWF0IHNjcm9sbCAwJSByZ2IoMjM5LCAyMzksIDIzOSk7IHBhZGRpbmc6
IDhweDsiPjxkaXYgaWQ9Im1lbnVfc2VuZGVyIj48Yj7lj5Hku7bkuro6PC9iPiZuYnNwOyJT
dGVmYW5pZSBHZXJkZXMiICZsdDtnZXJkZXNAdHppLmRlJmd0Ozs8L2Rpdj48ZGl2PjxiPuWP
kemAgeaXtumXtDo8L2I+Jm5ic3A7MjAxNOW5tDfmnIgyOeaXpSjmmJ/mnJ/kuowpIDIwOjE2
PC9kaXY+PGRpdj48Yj7mlLbku7bkuro6PC9iPiZuYnNwOyJMdWR3aWcgU2VpdHoiICZsdDts
dWR3aWdAc2ljcy5zZSZndDs7ImFjZSIgJmx0O2FjZUBpZXRmLm9yZyZndDs7IkthdGhsZWVu
IE1vcmlhcnR5IiAmbHQ7a2F0aGxlZW4ubW9yaWFydHkuaWV0ZkBnbWFpbC5jb20mZ3Q7Ozwv
ZGl2PjxkaXY+PGI+5Li76aKYOjwvYj4mbmJzcDtSZTogW0FjZV0gVXNlIENhc2UgZHJhZnQ8
L2Rpdj48L2Rpdj48L0JPRFk+PC9IVE1MPjxici8+PGJyLz5IaSBLYXRobGVlbiBhbmQgTHVk
d2lnLA08YnI+DTxicj5PbiAwNy8yOS8yMDE0IDEwOjAxIEFNLCBMdWR3aWcgU2VpdHogd3Jv
dGU6DTxicj4mZ3Q7IE9uIDA3LzI4LzIwMTQgMTA6MjkgUE0sIEthdGhsZWVuIE1vcmlhcnR5
IHdyb3RlOg08YnI+Jmd0OyZndDsNPGJyPiZndDsmZ3Q7IDIuIExvZ2dpbmcsIHByb3RlY3Rp
b24gb2YgbG9ncyAoYW5kIHB1cmdpbmcpIGlzIG1lbnRpb25lZCBpbiBvbmUgb2YgdGhlDTxi
cj4mZ3Q7Jmd0OyB1c2UgY2FzZXMsIGJ1dCBub3QgaW4gdGhlIHNlY3VyaXR5IHNlY3Rpb24u
Jm5ic3A7IFRoaXMgd291bGQgYmUgYSBnb29kDTxicj4mZ3Q7Jmd0OyBhZGRpdGlvbiwgYnV0
IHNob3VsZCBhbHNvIGluY2x1ZGUgcHJpdmFjeSBjb25zaWRlcmF0aW9ucyBhc3NvY2lhdGVk
IHdpdGgNPGJyPiZndDsmZ3Q7IHRoZSBsb2dzIGFzIHdlbGwgKGNvcnJlbGF0aW9uIG9mIGV2
ZW50cywgZXRjLikuDTxicj4mZ3Q7IA08YnI+Jmd0OyBXZSBoYWQgYSBkaXNjdXNzaW9uIGFi
b3V0IEF1ZGl0aW5nICh0aGUgdGhpcmQgQSBvZiBBQUEpIGFuZCBsb2dnaW5nDTxicj4mZ3Q7
IGR1cmluZyB0aGUgY2hhcnRlcmluZyBwcm9jZXNzLCBhbmQgc29tZSBwZW9wbGUgdGhvdWdo
dCBpdCB3b3VsZCBtYWtlIHRoZQ08YnI+Jmd0OyBmb2N1cyBvZiB0aGUgZ3JvdXAgdG9vIGJy
b2FkIHRvIHRyeSBhbmQgYWxzbyBjb3ZlciBBdWRpdGluZyAoaW5jbHVkaW5nDTxicj4mZ3Q7
IGxvZ2dpbmcpLg08YnI+Jmd0OyANPGJyPiZndDsgVGhlcmVmb3JlIEkgaGF2ZSBsZWZ0IG91
dCBxdWVzdGlvbnMgb2YgYXVkaXRpbmcgKGFuZCBwcml2YWN5KSBmb3IgdGhlDTxicj4mZ3Q7
IG1vbWVudC4NPGJyPg08YnI+SSB0aGluayBwcml2YWN5IGlzIGludGVyZXN0aW5nIHRvIGNv
bnNpZGVyLiBUaGUgcmVhc29uIGZvciB1c2luZw08YnI+YXV0aG9yaXphdGlvbiBtZWNoYW5p
c21zIGlzIHRvIHByb3RlY3QgZGF0YSwgaS5lLiB0byBhY2hpZXZlIGNlcnRhaW4NPGJyPnNl
Y3VyaXR5IG9iamVjdGl2ZXMgc3VjaCBhcyBpbnRlZ3JpdHkgYW5kIGNvbmZpZGVudGlhbGl0
eS4gUHJpdmFjeSBpcw08YnI+aW50ZXJlc3RpbmcgdG8gY29uc2lkZXIgYXMgaXQgc3RyZXNz
ZXMgdGhlIG5lZWQgZm9yIGNvbmZpZGVudGlhbGl0eS4NPGJyPg08YnI+VGhhbmtzDTxicj5T
dGVmZmkNPGJyPg08YnI+X19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19f
X19fX19fX18NPGJyPkFjZSBtYWlsaW5nIGxpc3QNPGJyPkFjZUBpZXRmLm9yZw08YnI+aHR0
cHM6Ly93d3cuaWV0Zi5vcmcvbWFpbG1hbi9saXN0aW5mby9hY2U=

------=_NextPart_53D7960E_0C6E7270_5C22CB5E--


From nobody Tue Jul 29 06:22:21 2014
Return-Path: <kathleen.moriarty.ietf@gmail.com>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 9FCEF1B288D for <ace@ietfa.amsl.com>; Tue, 29 Jul 2014 06:22:19 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.999
X-Spam-Level: 
X-Spam-Status: No, score=-1.999 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id E1RCDnzLNlwL for <ace@ietfa.amsl.com>; Tue, 29 Jul 2014 06:22:17 -0700 (PDT)
Received: from mail-la0-x232.google.com (mail-la0-x232.google.com [IPv6:2a00:1450:4010:c03::232]) (using TLSv1 with cipher ECDHE-RSA-RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 4762E1A02DC for <ace@ietf.org>; Tue, 29 Jul 2014 06:22:17 -0700 (PDT)
Received: by mail-la0-f50.google.com with SMTP id gf5so6429082lab.23 for <ace@ietf.org>; Tue, 29 Jul 2014 06:22:14 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113;  h=mime-version:in-reply-to:references:date:message-id:subject:from:to :cc:content-type; bh=XeyCHPyqzoxQOmx3fAXyBd+frjY/q1TeCfeqRZLQ6Dc=; b=UliQwrljgt0YJ5/GFbILreAsPa0dhHlfOE3VmFh5Xkxlbgb8EznDtvuKEi6LWmdiPD 94MsgEEyz3hIZkYSUJmbicYuWv/TYZP/cVqj2CgVWsx2eO9KQfqUYEvxWsKIlKcbB9rr 66sa++2QEGqkfpQqPdxAZdYd2UPVhi6x012WXmGrVD1nmdlXr0FNSKRCopwQw+T9T6rN xOIro6MZpMa6uGgr9Bbd065aJ9Q/hxqradvGfWKPeXUDKIwJDuWWJp5wGWVBrNBGHeos XMp2Bz8OdcI7xLB5iet7UviA6XNcWu5/m4pWq7NTcZG0SIJA804PDLAavY1aFVK/S7gX OwsQ==
MIME-Version: 1.0
X-Received: by 10.152.185.104 with SMTP id fb8mr2486177lac.64.1406640134324; Tue, 29 Jul 2014 06:22:14 -0700 (PDT)
Received: by 10.112.147.168 with HTTP; Tue, 29 Jul 2014 06:22:14 -0700 (PDT)
In-Reply-To: <tencent_26C922A4595ABF8F71A82A33@qq.com>
References: <tencent_26C922A4595ABF8F71A82A33@qq.com>
Date: Tue, 29 Jul 2014 09:22:14 -0400
Message-ID: <CAHbuEH4RPpHj=K7PGdUu6hnUvo4AD5W=-x77KempfEbmV0RQ9Q@mail.gmail.com>
From: Kathleen Moriarty <kathleen.moriarty.ietf@gmail.com>
To: Kepeng Li <1095318589@qq.com>
Content-Type: multipart/alternative; boundary=001a1136936c8885d804ff54edb6
Archived-At: http://mailarchive.ietf.org/arch/msg/ace/QFTSgoz1ojt3OZZx_FnR7uGp3i0
Cc: gerdes <gerdes@tzi.de>, ludwig <ludwig@sics.se>, ace <ace@ietf.org>
Subject: Re: [Ace] Use Case draft
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 29 Jul 2014 13:22:19 -0000

--001a1136936c8885d804ff54edb6
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

On Tue, Jul 29, 2014 at 8:39 AM, Kepeng Li <1095318589@qq.com> wrote:

> Agree with Steffi.
>
> Kind Regards
> Kepeng
>
> ------------------ =E5=8E=9F=E5=A7=8B=E9=82=AE=E4=BB=B6 -----------------=
-
> *=E5=8F=91=E4=BB=B6=E4=BA=BA:* "Stefanie Gerdes" <gerdes@tzi.de>;
> *=E5=8F=91=E9=80=81=E6=97=B6=E9=97=B4:* 2014=E5=B9=B47=E6=9C=8829=E6=97=
=A5(=E6=98=9F=E6=9C=9F=E4=BA=8C) 20:16
> *=E6=94=B6=E4=BB=B6=E4=BA=BA:* "Ludwig Seitz" <ludwig@sics.se>;"ace" <ace=
@ietf.org>;"Kathleen
> Moriarty" <kathleen.moriarty.ietf@gmail.com>;
> *=E4=B8=BB=E9=A2=98:* Re: [Ace] Use Case draft
>
>
> Hi Kathleen and Ludwig,
>
> On 07/29/2014 10:01 AM, Ludwig Seitz wrote:
> > On 07/28/2014 10:29 PM, Kathleen Moriarty wrote:
> >>
> >> 2. Logging, protection of logs (and purging) is mentioned in one of th=
e
> >> use cases, but not in the security section.  This would be a good
> >> addition, but should also include privacy considerations associated
> with
> >> the logs as well (correlation of events, etc.).
> >
> > We had a discussion about Auditing (the third A of AAA) and logging
> > during the chartering process, and some people thought it would make th=
e
> > focus of the group too broad to try and also cover Auditing (including
> > logging).
> >
> > Therefore I have left out questions of auditing (and privacy) for the
> > moment.
>
> I think privacy is interesting to consider. The reason for using
> authorization mechanisms is to protect data, i.e. to achieve certain
> security objectives such as integrity and confidentiality. Privacy is
> interesting to consider as it stresses the need for confidentiality.
>
> Yes and without covering this, the considerations would be incomplete and
this would get caught in last call.  It's much easier to address it now.
 See RFC6973 for reference on current privacy considerations in IETF
protocols.

Thanks,
Kathleen


> Thanks
> Steffi
>
> _______________________________________________
> Ace mailing list
> Ace@ietf.org
> https://www.ietf.org/mailman/listinfo/ace
> _______________________________________________
> Ace mailing list
> Ace@ietf.org
> https://www.ietf.org/mailman/listinfo/ace
>
>


--=20

Best regards,
Kathleen

--001a1136936c8885d804ff54edb6
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><br><div class=3D"gmail_extra"><br><br><div class=3D"gmail=
_quote">On Tue, Jul 29, 2014 at 8:39 AM, Kepeng Li <span dir=3D"ltr">&lt;<a=
 href=3D"mailto:1095318589@qq.com" target=3D"_blank">1095318589@qq.com</a>&=
gt;</span> wrote:<br>
<blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;border-left:1p=
x #ccc solid;padding-left:1ex">Agree with Steffi.<br><br>Kind Regards<br>Ke=
peng<br><br>------------------ =E5=8E=9F=E5=A7=8B=E9=82=AE=E4=BB=B6 -------=
-----------<br><div><div style=3D"font-size:12px;background:none repeat scr=
oll 0% rgb(239,239,239);padding:8px">
<div><b>=E5=8F=91=E4=BB=B6=E4=BA=BA:</b>=C2=A0&quot;Stefanie Gerdes&quot; &=
lt;<a href=3D"mailto:gerdes@tzi.de" target=3D"_blank">gerdes@tzi.de</a>&gt;=
;</div><div><b>=E5=8F=91=E9=80=81=E6=97=B6=E9=97=B4:</b>=C2=A02014=E5=B9=B4=
7=E6=9C=8829=E6=97=A5(=E6=98=9F=E6=9C=9F=E4=BA=8C) 20:16</div><div><b>=E6=
=94=B6=E4=BB=B6=E4=BA=BA:</b>=C2=A0&quot;Ludwig Seitz&quot; &lt;<a href=3D"=
mailto:ludwig@sics.se" target=3D"_blank">ludwig@sics.se</a>&gt;;&quot;ace&q=
uot; &lt;<a href=3D"mailto:ace@ietf.org" target=3D"_blank">ace@ietf.org</a>=
&gt;;&quot;Kathleen Moriarty&quot; &lt;<a href=3D"mailto:kathleen.moriarty.=
ietf@gmail.com" target=3D"_blank">kathleen.moriarty.ietf@gmail.com</a>&gt;;=
</div>
<div><b>=E4=B8=BB=E9=A2=98:</b>=C2=A0Re: [Ace] Use Case draft</div></div></=
div><div><div class=3D"h5"><br><br>Hi Kathleen and Ludwig,
<br>
<br>On 07/29/2014 10:01 AM, Ludwig Seitz wrote:
<br>&gt; On 07/28/2014 10:29 PM, Kathleen Moriarty wrote:
<br>&gt;&gt;
<br>&gt;&gt; 2. Logging, protection of logs (and purging) is mentioned in o=
ne of the
<br>&gt;&gt; use cases, but not in the security section.=C2=A0 This would b=
e a good
<br>&gt;&gt; addition, but should also include privacy considerations assoc=
iated with
<br>&gt;&gt; the logs as well (correlation of events, etc.).
<br>&gt;=20
<br>&gt; We had a discussion about Auditing (the third A of AAA) and loggin=
g
<br>&gt; during the chartering process, and some people thought it would ma=
ke the
<br>&gt; focus of the group too broad to try and also cover Auditing (inclu=
ding
<br>&gt; logging).
<br>&gt;=20
<br>&gt; Therefore I have left out questions of auditing (and privacy) for =
the
<br>&gt; moment.
<br>
<br>I think privacy is interesting to consider. The reason for using
<br>authorization mechanisms is to protect data, i.e. to achieve certain
<br>security objectives such as integrity and confidentiality. Privacy is
<br>interesting to consider as it stresses the need for confidentiality.
<br>
<br></div></div></blockquote><div>Yes and without covering this, the consid=
erations would be incomplete and this would get caught in last call. =C2=A0=
It&#39;s much easier to address it now. =C2=A0See RFC6973 for reference on =
current privacy considerations in IETF protocols.</div>
<div><br></div><div>Thanks,</div><div>Kathleen</div><div>=C2=A0</div><block=
quote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;border-left:1px #ccc=
 solid;padding-left:1ex"><div><div class=3D"h5">Thanks
<br>Steffi
<br>
<br></div></div>_______________________________________________
<br>Ace mailing list
<br><a href=3D"mailto:Ace@ietf.org" target=3D"_blank">Ace@ietf.org</a>
<br><a href=3D"https://www.ietf.org/mailman/listinfo/ace" target=3D"_blank"=
>https://www.ietf.org/mailman/listinfo/ace</a><br>_________________________=
______________________<br>
Ace mailing list<br>
<a href=3D"mailto:Ace@ietf.org">Ace@ietf.org</a><br>
<a href=3D"https://www.ietf.org/mailman/listinfo/ace" target=3D"_blank">htt=
ps://www.ietf.org/mailman/listinfo/ace</a><br>
<br></blockquote></div><br><br clear=3D"all"><div><br></div>-- <br><div dir=
=3D"ltr"><br><div>Best regards,</div><div>Kathleen</div></div>
</div></div>

--001a1136936c8885d804ff54edb6--


From nobody Tue Jul 29 06:32:23 2014
Return-Path: <kathleen.moriarty.ietf@gmail.com>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id EEEA41A03FA for <ace@ietfa.amsl.com>; Tue, 29 Jul 2014 06:32:21 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.999
X-Spam-Level: 
X-Spam-Status: No, score=-1.999 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id sr82eetoZf3D for <ace@ietfa.amsl.com>; Tue, 29 Jul 2014 06:32:19 -0700 (PDT)
Received: from mail-la0-x22f.google.com (mail-la0-x22f.google.com [IPv6:2a00:1450:4010:c03::22f]) (using TLSv1 with cipher ECDHE-RSA-RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 157181A01B0 for <ace@ietf.org>; Tue, 29 Jul 2014 06:32:18 -0700 (PDT)
Received: by mail-la0-f47.google.com with SMTP id mc6so6706266lab.34 for <ace@ietf.org>; Tue, 29 Jul 2014 06:32:17 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113;  h=mime-version:in-reply-to:references:date:message-id:subject:from:to :cc:content-type; bh=el5Aqocv/rxpWGDmOdtYXRFUfUg49TMUm/8f3uZM+1k=; b=GvDBclAool7RzkLlaF4PPFzsODJZQs+F0e/z2QGoeJy9oGH3A8xxmZQ0qtWIy73BqG C53qzP99dqtLSXSxxL2mfBSKYrjw6N14T6LOUdXFBf0llwfWHqMToa7rrJPSzR3hSDPk GlKI2SQ8HZodiN6s1z1uR0F0aloLV6CSoDlQhgBVxBBD5zXG2VrvSi9iTjHFWAUdro9U bXlTv5eqJCpvlbjR1xx6oqhFtKHonqIgss+YJEw2+uSYdFJMXXm1/BAx8mgbQdxBBGZm FSZLCwnTmnCztyEco/mzqideFAg6qBMU0OOeZUBp1p3C/MkJox6uyjsPKrW4TZRcBm54 efpw==
MIME-Version: 1.0
X-Received: by 10.112.42.45 with SMTP id k13mr2255620lbl.88.1406640737157; Tue, 29 Jul 2014 06:32:17 -0700 (PDT)
Received: by 10.112.147.168 with HTTP; Tue, 29 Jul 2014 06:32:17 -0700 (PDT)
In-Reply-To: <53D754ED.7060700@sics.se>
References: <CAHbuEH7hn0iWJpx7hwaOQnDO9_n16ZKuDh4sF4G=LsPHXde6hg@mail.gmail.com> <53D754ED.7060700@sics.se>
Date: Tue, 29 Jul 2014 09:32:17 -0400
Message-ID: <CAHbuEH57oMeuszwsB2swK_k4f7OoNUjbO89rqrWkHib1TcvhvA@mail.gmail.com>
From: Kathleen Moriarty <kathleen.moriarty.ietf@gmail.com>
To: Ludwig Seitz <ludwig@sics.se>
Content-Type: multipart/alternative; boundary=001a113364207707d104ff55119e
Archived-At: http://mailarchive.ietf.org/arch/msg/ace/JBkh4EaA1nnNHH8aGRp6IPX__G4
Cc: "ace@ietf.org" <ace@ietf.org>
Subject: Re: [Ace] Use Case draft
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 29 Jul 2014 13:32:22 -0000

--001a113364207707d104ff55119e
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

Hello,


On Tue, Jul 29, 2014 at 4:01 AM, Ludwig Seitz <ludwig@sics.se> wrote:

> On 07/28/2014 10:29 PM, Kathleen Moriarty wrote:
>
>> Hello,
>>
>> I had read through the draft before the meeting and noted that in
>> section 2.2.1, I thought the roles of the people involved in the use
>> case were distracting.  Changing this may help keep people focused on
>> the scenario as opposed to details that don't matter for ACE.  FYI - A
>> single woman letting an acquaintance into her home without her there
>> would be unusual.  Most women would not do that for safety reasons.  The
>> interpretation of acquaintance may vary between regions, but for me, an
>> acquaintance is someone I don't really know well.  If you make Jeffrey
>> her brother, or switch the roles of Jeffrey & Jane, the scenario is much
>> more plausible and will help to prevent people from getting distracted
>> while reading this scenario.
>>
>>  I'll update this in the next version if we don't change the use case
> entirely.
>
>
>  In reading through the draft, I noticed a few things missing from the
>> Security Requirements section that could be helpful for the next
>> editorial pass.  If there were reasons they were not included, please
>> let me know.
>>
>> 1. Threats such as session intercept/hijacking or monitoring are not
>> covered yet.
>>
>
> The idea of this draft was to cover issues concerning authentication and
> authorization (and a few  directly related issues) since that is the topi=
c
> of ACE. I think the problems you mention above are not directly relevant
> for ACE, therefore I left them out of the document.
>
> Understood, however, if you leave out any type of encryption (or
motivation for it), for authentication and authorization you'll need replay
protection as a requirement to prevent fraud or other attacks.

In terms of other types of attacks that are possible, but not a focus for
this working group, you'll still need to list them to cover you bases for
readers of the work.  This doesn't mean that you have to solve all of the
problems, but rather list them as "Security Considerations".  One way to do
it would be through another section that is called security considerations.
 Then when you have subsequent drafts that implement, you can point to that
section for 'additional considerations' for the developer, implementer, and
user.  Monitoring (RFC7258 - for PM) and session intercept should be listed
as considerations, but don't have to be solved by the WG.  You can state
that the considerations are important, but out of scope for ACE.

>
>
>> 2. Logging, protection of logs (and purging) is mentioned in one of the
>> use cases, but not in the security section.  This would be a good
>> addition, but should also include privacy considerations associated with
>> the logs as well (correlation of events, etc.).
>>
>
> We had a discussion about Auditing (the third A of AAA) and logging durin=
g
> the chartering process, and some people thought it would make the focus o=
f
> the group too broad to try and also cover Auditing (including logging).
>

Sure, I should have been more clear, I'm just looking or the set of
considerations to be listed and I think adding this into a Security
Considerations section would be good.  I'm not asking the WG to cover it
and agree that the specification of this functionality is out-of-scope.
 You can then point to it from other drafts as the set of considerations.

>
> Therefore I have left out questions of auditing (and privacy) for the
> moment.
>
>
>
>
>> 3. There will also be a number of privacy considerations that should be
>> noted in this section or one on privacy.  This might include concerns of
>> being able to profile habits of a person or other similar concerns.
>>
>>
> See above.
>
>
>
> Regards,
>
> Ludwig Seitz
>
>
> --
> Ludwig Seitz, PhD
> SICS Swedish ICT AB
> Ideon Science Park
> Building Beta 2
> Scheelev=C3=A4gen 17
> SE-223 70 Lund
>
> Phone +46(0)70-349 92 51
> http://www.sics.se
>
>
> _______________________________________________
> Ace mailing list
> Ace@ietf.org
> https://www.ietf.org/mailman/listinfo/ace
>
>


--=20

Best regards,
Kathleen

--001a113364207707d104ff55119e
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr">Hello,<div class=3D"gmail_extra"><br><br><div class=3D"gma=
il_quote">On Tue, Jul 29, 2014 at 4:01 AM, Ludwig Seitz <span dir=3D"ltr">&=
lt;<a href=3D"mailto:ludwig@sics.se" target=3D"_blank">ludwig@sics.se</a>&g=
t;</span> wrote:<br>
<blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;border-left:1p=
x #ccc solid;padding-left:1ex"><div class=3D"">On 07/28/2014 10:29 PM, Kath=
leen Moriarty wrote:<br>
<blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;border-left:1p=
x #ccc solid;padding-left:1ex">
Hello,<br>
<br>
I had read through the draft before the meeting and noted that in<br>
section 2.2.1, I thought the roles of the people involved in the use<br>
case were distracting. =C2=A0Changing this may help keep people focused on<=
br>
the scenario as opposed to details that don&#39;t matter for ACE. =C2=A0FYI=
 - A<br>
single woman letting an acquaintance into her home without her there<br>
would be unusual. =C2=A0Most women would not do that for safety reasons. =
=C2=A0The<br>
interpretation of acquaintance may vary between regions, but for me, an<br>
acquaintance is someone I don&#39;t really know well. =C2=A0If you make Jef=
frey<br>
her brother, or switch the roles of Jeffrey &amp; Jane, the scenario is muc=
h<br>
more plausible and will help to prevent people from getting distracted<br>
while reading this scenario.<br>
<br>
</blockquote></div>
I&#39;ll update this in the next version if we don&#39;t change the use cas=
e entirely.<div class=3D""><br>
<br>
<blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;border-left:1p=
x #ccc solid;padding-left:1ex">
In reading through the draft, I noticed a few things missing from the<br>
Security Requirements section that could be helpful for the next<br>
editorial pass. =C2=A0If there were reasons they were not included, please<=
br>
let me know.<br>
<br>
1. Threats such as session intercept/hijacking or monitoring are not<br>
covered yet.<br>
</blockquote>
<br></div>
The idea of this draft was to cover issues concerning authentication and au=
thorization (and a few =C2=A0directly related issues) since that is the top=
ic of ACE. I think the problems you mention above are not directly relevant=
 for ACE, therefore I left them out of the document.<div class=3D"">
<br></div></blockquote><div>Understood, however, if you leave out any type =
of encryption (or motivation for it), for authentication and authorization =
you&#39;ll need replay protection as a requirement to prevent fraud or othe=
r attacks.=C2=A0</div>
<div><br></div><div>In terms of other types of attacks that are possible, b=
ut not a focus for this working group, you&#39;ll still need to list them t=
o cover you bases for readers of the work. =C2=A0This doesn&#39;t mean that=
 you have to solve all of the problems, but rather list them as &quot;Secur=
ity Considerations&quot;. =C2=A0One way to do it would be through another s=
ection that is called security considerations. =C2=A0Then when you have sub=
sequent drafts that implement, you can point to that section for &#39;addit=
ional considerations&#39; for the developer, implementer, and user. =C2=A0M=
onitoring (RFC7258 - for PM) and session intercept should be listed as cons=
iderations, but don&#39;t have to be solved by the WG. =C2=A0You can state =
that the considerations are important, but out of scope for ACE.</div>
<blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;border-left:1p=
x #ccc solid;padding-left:1ex"><div class=3D"">
<br>
<blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;border-left:1p=
x #ccc solid;padding-left:1ex">
<br>
2. Logging, protection of logs (and purging) is mentioned in one of the<br>
use cases, but not in the security section. =C2=A0This would be a good<br>
addition, but should also include privacy considerations associated with<br=
>
the logs as well (correlation of events, etc.).<br>
</blockquote>
<br></div>
We had a discussion about Auditing (the third A of AAA) and logging during =
the chartering process, and some people thought it would make the focus of =
the group too broad to try and also cover Auditing (including logging).<br>
</blockquote><div>=C2=A0</div><div>Sure, I should have been more clear, I&#=
39;m just looking or the set of considerations to be listed and I think add=
ing this into a Security Considerations section would be good. =C2=A0I&#39;=
m not asking the WG to cover it and agree that the specification of this fu=
nctionality is out-of-scope. =C2=A0You can then point to it from other draf=
ts as the set of considerations.</div>
<blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;border-left:1p=
x #ccc solid;padding-left:1ex">
<br>
Therefore I have left out questions of auditing (and privacy) for the momen=
t.<div class=3D""><br>
<br>
<br>
<blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;border-left:1p=
x #ccc solid;padding-left:1ex">
<br>
3. There will also be a number of privacy considerations that should be<br>
noted in this section or one on privacy. =C2=A0This might include concerns =
of<br>
being able to profile habits of a person or other similar concerns.<br>
<br>
</blockquote>
<br></div>
See above.<br>
<br>
<br>
<br>
Regards,<br>
<br>
Ludwig Seitz<span class=3D"HOEnZb"><font color=3D"#888888"><br>
<br>
<br>
-- <br>
Ludwig Seitz, PhD<br>
SICS Swedish ICT AB<br>
Ideon Science Park<br>
Building Beta 2<br>
Scheelev=C3=A4gen 17<br>
SE-223 70 Lund<br>
<br>
Phone <a href=3D"tel:%2B46%280%2970-349%2092%2051" value=3D"+46703499251" t=
arget=3D"_blank">+46(0)70-349 92 51</a><br>
<a href=3D"http://www.sics.se" target=3D"_blank">http://www.sics.se</a><br>
<br>
</font></span><br>_______________________________________________<br>
Ace mailing list<br>
<a href=3D"mailto:Ace@ietf.org">Ace@ietf.org</a><br>
<a href=3D"https://www.ietf.org/mailman/listinfo/ace" target=3D"_blank">htt=
ps://www.ietf.org/mailman/listinfo/ace</a><br>
<br></blockquote></div><br><br clear=3D"all"><div><br></div>-- <br><div dir=
=3D"ltr"><br><div>Best regards,</div><div>Kathleen</div></div>
</div></div>

--001a113364207707d104ff55119e--


From nobody Tue Jul 29 09:38:01 2014
Return-Path: <tonynad@microsoft.com>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id A8DD11A02EB for <ace@ietfa.amsl.com>; Tue, 29 Jul 2014 09:38:00 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.902
X-Spam-Level: 
X-Spam-Status: No, score=-1.902 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id euDtA8q8m-Nm for <ace@ietfa.amsl.com>; Tue, 29 Jul 2014 09:37:55 -0700 (PDT)
Received: from na01-bn1-obe.outbound.protection.outlook.com (mail-bn1blp0187.outbound.protection.outlook.com [207.46.163.187]) (using TLSv1 with cipher ECDHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 694231A0262 for <ace@ietf.org>; Tue, 29 Jul 2014 09:37:55 -0700 (PDT)
Received: from BLUPR03MB309.namprd03.prod.outlook.com (10.141.48.22) by BLUPR03MB311.namprd03.prod.outlook.com (10.141.48.26) with Microsoft SMTP Server (TLS) id 15.0.995.11; Tue, 29 Jul 2014 16:37:53 +0000
Received: from BLUPR03MB309.namprd03.prod.outlook.com ([10.141.48.22]) by BLUPR03MB309.namprd03.prod.outlook.com ([10.141.48.22]) with mapi id 15.00.0995.011; Tue, 29 Jul 2014 16:37:53 +0000
From: Anthony Nadalin <tonynad@microsoft.com>
To: Ludwig Seitz <ludwig@sics.se>, "ace@ietf.org" <ace@ietf.org>
Thread-Topic: [Ace] Use Case draft
Thread-Index: AQHPqqK4PP7lvKFDAkeF8MQZPzEln5u2sW2AgACP2uA=
Date: Tue, 29 Jul 2014 16:37:52 +0000
Message-ID: <a4451f29afc8467fad4d802a69f1165c@BLUPR03MB309.namprd03.prod.outlook.com>
References: <CAHbuEH7hn0iWJpx7hwaOQnDO9_n16ZKuDh4sF4G=LsPHXde6hg@mail.gmail.com> <53D754ED.7060700@sics.se>
In-Reply-To: <53D754ED.7060700@sics.se>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
x-originating-ip: [2001:4898:80e8:ee31::3]
x-microsoft-antispam: BCL:0;PCL:0;RULEID:
x-forefront-prvs: 0287BBA78D
x-forefront-antispam-report: SFV:NSPM; SFS:(6009001)(199002)(189002)(479174003)(24454002)(377454003)(13464003)(51704005)(69234005)(107046002)(19580405001)(4396001)(21056001)(81542001)(86362001)(107886001)(15975445006)(50986999)(2656002)(99396002)(74316001)(83322001)(81342001)(20776003)(64706001)(101416001)(80022001)(33646002)(19580395003)(77982001)(46102001)(76576001)(105586002)(106356001)(74662001)(95666004)(74502001)(106116001)(54356999)(87936001)(86612001)(76482001)(99286002)(85852003)(15202345003)(31966008)(92566001)(76176999)(83072002)(85306003)(108616002)(42262001)(3826002)(24736002)(18886065003); DIR:OUT; SFP:; SCL:1; SRVR:BLUPR03MB311; H:BLUPR03MB309.namprd03.prod.outlook.com; FPR:; MLV:sfv; PTR:InfoNoRecords; MX:1; LANG:en; 
Content-Type: text/plain; charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
X-OriginatorOrg: microsoft.onmicrosoft.com
Archived-At: http://mailarchive.ietf.org/arch/msg/ace/W5oxWDxXa16IiIbTsUq_b68sEm0
Subject: Re: [Ace] Use Case draft
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 29 Jul 2014 16:38:00 -0000

So it looks like the use cases so far are more geared toward device to clou=
d, with a central cloud service that provides orchestration between devices=
 and not towards peer to peer and on-prem services ?

-----Original Message-----
From: Ace [mailto:ace-bounces@ietf.org] On Behalf Of Ludwig Seitz
Sent: Tuesday, July 29, 2014 1:02 AM
To: ace@ietf.org
Subject: Re: [Ace] Use Case draft

On 07/28/2014 10:29 PM, Kathleen Moriarty wrote:
> Hello,
>
> I had read through the draft before the meeting and noted that in=20
> section 2.2.1, I thought the roles of the people involved in the use=20
> case were distracting.  Changing this may help keep people focused on=20
> the scenario as opposed to details that don't matter for ACE.  FYI - A=20
> single woman letting an acquaintance into her home without her there=20
> would be unusual.  Most women would not do that for safety reasons. =20
> The interpretation of acquaintance may vary between regions, but for=20
> me, an acquaintance is someone I don't really know well.  If you make=20
> Jeffrey her brother, or switch the roles of Jeffrey & Jane, the=20
> scenario is much more plausible and will help to prevent people from=20
> getting distracted while reading this scenario.
>
I'll update this in the next version if we don't change the use case entire=
ly.

> In reading through the draft, I noticed a few things missing from the=20
> Security Requirements section that could be helpful for the next=20
> editorial pass.  If there were reasons they were not included, please=20
> let me know.
>
> 1. Threats such as session intercept/hijacking or monitoring are not=20
> covered yet.

The idea of this draft was to cover issues concerning authentication and au=
thorization (and a few  directly related issues) since that is the topic of=
 ACE. I think the problems you mention above are not directly relevant for =
ACE, therefore I left them out of the document.

>
> 2. Logging, protection of logs (and purging) is mentioned in one of=20
> the use cases, but not in the security section.  This would be a good=20
> addition, but should also include privacy considerations associated=20
> with the logs as well (correlation of events, etc.).

We had a discussion about Auditing (the third A of AAA) and logging during =
the chartering process, and some people thought it would make the focus of =
the group too broad to try and also cover Auditing (including logging).

Therefore I have left out questions of auditing (and privacy) for the momen=
t.


>
> 3. There will also be a number of privacy considerations that should be
> noted in this section or one on privacy.  This might include concerns of
> being able to profile habits of a person or other similar concerns.
>

See above.



Regards,

Ludwig Seitz


--=20
Ludwig Seitz, PhD
SICS Swedish ICT AB
Ideon Science Park
Building Beta 2
Scheelev=E4gen 17
SE-223 70 Lund

Phone +46(0)70-349 92 51
http://www.sics.se


From nobody Tue Jul 29 11:21:13 2014
Return-Path: <gerdes@tzi.de>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id E1DEC1B29AD for <ace@ietfa.amsl.com>; Tue, 29 Jul 2014 11:21:12 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.551
X-Spam-Level: 
X-Spam-Status: No, score=-1.551 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HELO_EQ_DE=0.35, SPF_HELO_PASS=-0.001] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id grJldRA1nc7i for <ace@ietfa.amsl.com>; Tue, 29 Jul 2014 11:21:11 -0700 (PDT)
Received: from informatik.uni-bremen.de (mailhost.informatik.uni-bremen.de [IPv6:2001:638:708:30c9::12]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id CDD631A0442 for <ace@ietf.org>; Tue, 29 Jul 2014 11:21:10 -0700 (PDT)
X-Virus-Scanned: amavisd-new at informatik.uni-bremen.de
Received: from smtp-fb3.informatik.uni-bremen.de (smtp-fb3.informatik.uni-bremen.de [134.102.224.120]) by informatik.uni-bremen.de (8.14.5/8.14.5) with ESMTP id s6TIL1Q9004639; Tue, 29 Jul 2014 20:21:01 +0200 (CEST)
Received: from [134.102.218.214] (dynamic-218-o.informatik.uni-bremen.de [134.102.218.214]) (using TLSv1 with cipher DHE-RSA-CAMELLIA256-SHA (256/256 bits)) (No client certificate requested) by smtp-fb3.informatik.uni-bremen.de (Postfix) with ESMTPSA id B6C51A65; Tue, 29 Jul 2014 20:21:01 +0200 (CEST)
Message-ID: <53D7E60D.5030704@tzi.de>
Date: Tue, 29 Jul 2014 20:21:01 +0200
From: Stefanie Gerdes <gerdes@tzi.de>
User-Agent: Mozilla/5.0 (X11; Linux i686 on x86_64; rv:24.0) Gecko/20100101 Thunderbird/24.2.0
MIME-Version: 1.0
To: Anthony Nadalin <tonynad@microsoft.com>, Ludwig Seitz <ludwig@sics.se>, "ace@ietf.org" <ace@ietf.org>
References: <CAHbuEH7hn0iWJpx7hwaOQnDO9_n16ZKuDh4sF4G=LsPHXde6hg@mail.gmail.com> <53D754ED.7060700@sics.se> <a4451f29afc8467fad4d802a69f1165c@BLUPR03MB309.namprd03.prod.outlook.com>
In-Reply-To: <a4451f29afc8467fad4d802a69f1165c@BLUPR03MB309.namprd03.prod.outlook.com>
X-Enigmail-Version: 1.6
Content-Type: text/plain; charset=ISO-8859-1
Content-Transfer-Encoding: 8bit
Archived-At: http://mailarchive.ietf.org/arch/msg/ace/f1OsvrTbHLZsI4V9XCsT24pZwd4
Subject: Re: [Ace] Use Case draft
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 29 Jul 2014 18:21:13 -0000

Hi Anthony,

The aim is to enable peer to peer communication between two devices
which may both be constrained.

The scenario we are discussing is:
 * A Client (C) wants to access a Resource (R) on a Resource Server (RS).
 * A priori, C and RS do not necessarily know each other and have no
security relationship.
 * C and / or RS are constrained.
(cf. [1])

The goal is to enable C and RS to communicate securely and to enforce
the authorization policies of their respective owners.

To achieve this, Authorization Servers are introduced which relieve the
constrained devices from performing more difficult tasks and help them
with authentication and authorization.

Does this answer your question?

Steffi

[1] http://tools.ietf.org/pdf/draft-gerdes-ace-actors-01.pdf


On 07/29/2014 06:37 PM, Anthony Nadalin wrote:
> So it looks like the use cases so far are more geared toward device to cloud, with a central cloud service that provides orchestration between devices and not towards peer to peer and on-prem services ?
> 
> -----Original Message-----
> From: Ace [mailto:ace-bounces@ietf.org] On Behalf Of Ludwig Seitz
> Sent: Tuesday, July 29, 2014 1:02 AM
> To: ace@ietf.org
> Subject: Re: [Ace] Use Case draft
> 
> On 07/28/2014 10:29 PM, Kathleen Moriarty wrote:
>> Hello,
>>
>> I had read through the draft before the meeting and noted that in 
>> section 2.2.1, I thought the roles of the people involved in the use 
>> case were distracting.  Changing this may help keep people focused on 
>> the scenario as opposed to details that don't matter for ACE.  FYI - A 
>> single woman letting an acquaintance into her home without her there 
>> would be unusual.  Most women would not do that for safety reasons.  
>> The interpretation of acquaintance may vary between regions, but for 
>> me, an acquaintance is someone I don't really know well.  If you make 
>> Jeffrey her brother, or switch the roles of Jeffrey & Jane, the 
>> scenario is much more plausible and will help to prevent people from 
>> getting distracted while reading this scenario.
>>
> I'll update this in the next version if we don't change the use case entirely.
> 
>> In reading through the draft, I noticed a few things missing from the 
>> Security Requirements section that could be helpful for the next 
>> editorial pass.  If there were reasons they were not included, please 
>> let me know.
>>
>> 1. Threats such as session intercept/hijacking or monitoring are not 
>> covered yet.
> 
> The idea of this draft was to cover issues concerning authentication and authorization (and a few  directly related issues) since that is the topic of ACE. I think the problems you mention above are not directly relevant for ACE, therefore I left them out of the document.
> 
>>
>> 2. Logging, protection of logs (and purging) is mentioned in one of 
>> the use cases, but not in the security section.  This would be a good 
>> addition, but should also include privacy considerations associated 
>> with the logs as well (correlation of events, etc.).
> 
> We had a discussion about Auditing (the third A of AAA) and logging during the chartering process, and some people thought it would make the focus of the group too broad to try and also cover Auditing (including logging).
> 
> Therefore I have left out questions of auditing (and privacy) for the moment.
> 
> 
>>
>> 3. There will also be a number of privacy considerations that should be
>> noted in this section or one on privacy.  This might include concerns of
>> being able to profile habits of a person or other similar concerns.
>>
> 
> See above.
> 
> 
> 
> Regards,
> 
> Ludwig Seitz
> 
> 


-- 
Stefanie Gerdes			Tel: +49 421 218 63906
TZI Universität Bremen		E-Mail: gerdes@tzi.de
Bibliothekstr. 1, MZH 5150
28359 Bremen, Germany


From nobody Tue Jul 29 16:15:33 2014
Return-Path: <dgellert@silverspringnet.com>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 389F71B2A2C for <ace@ietfa.amsl.com>; Tue, 29 Jul 2014 16:15:32 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.902
X-Spam-Level: 
X-Spam-Status: No, score=-1.902 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id MuOYdUQ4FVPO for <ace@ietfa.amsl.com>; Tue, 29 Jul 2014 16:15:29 -0700 (PDT)
Received: from it-ipdr-01.silverspringnet.com (it-ipdr-01.silverspringnet.com [74.121.22.27]) by ietfa.amsl.com (Postfix) with ESMTP id AE3611B29F5 for <ace@ietf.org>; Tue, 29 Jul 2014 16:15:29 -0700 (PDT)
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-Anti-Spam-Result: AsUEAMMq2FMKOQx0/2dsb2JhbABUAwODYFcEy3IKhgOBSAGBKXeEAwEBAQQBAQFrFwIEAQgOAwQBAQEnIgwLFAkIAgQBEohPv00XBI8FMxcGC4Q5BYR0hUSpLmyBRQ
X-IronPort-AV: E=Sophos;i="5.01,760,1400050800";  d="scan'208";a="920110"
Received: from sfo-barrlb-02.silverspringnet.com (HELO mail.silverspringnet.com) ([10.57.12.116]) by it-ipdr-01.silverspringnet.com with ESMTP/TLS/AES128-SHA; 29 Jul 2014 16:15:16 -0700
Received: from SFO-EXMB-03.silverspringnet.com ([fe80::e877:a0b0:2e8d:1b57]) by SFO-EXCA-01.silverspringnet.com ([::1]) with mapi id 14.03.0181.006; Tue, 29 Jul 2014 16:15:16 -0700
From: Dorothy Gellert <dgellert@silverspringnet.com>
To: Anthony Nadalin <tonynad@microsoft.com>, Ludwig Seitz <ludwig@sics.se>, "ace@ietf.org" <ace@ietf.org>
Thread-Topic: [Ace] Use Case draft
Thread-Index: AQHPqqK3p/otK5Z9pEOReKm5Q0gc0Zu3JsaAgACQLgD///mqgA==
Date: Tue, 29 Jul 2014 23:15:15 +0000
Message-ID: <CFFD7754.1411C%dgellert@silverspringnet.com>
In-Reply-To: <a4451f29afc8467fad4d802a69f1165c@BLUPR03MB309.namprd03.prod.outlook.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
x-originating-ip: [10.57.111.65]
Content-Type: text/plain; charset="iso-8859-1"
Content-ID: <43E2FC003C1C124DBFCE7CBD637B1FA5@silverspringnet.com>
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
Archived-At: http://mailarchive.ietf.org/arch/msg/ace/w9HFJmV8y7iFQf0iZH9qAWRuSlQ
Subject: Re: [Ace] Use Case draft
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 29 Jul 2014 23:15:32 -0000

Hi Anthony-

We should consider both device to cloud and peer to peer - otherwise the
protocol will have design in preventive measures against unsupported
deployment models.=20

Best Regards,
Dorothy Gellert
Silver Spring Networks
Director, Standards and Technology
E dgellert@silverspringnet.com
O +1 650 839 4378
C +1 650 556-5994



On 7/29/14, 9:37 AM, "Anthony Nadalin" <tonynad@microsoft.com> wrote:

>So it looks like the use cases so far are more geared toward device to
>cloud, with a central cloud service that provides orchestration between
>devices and not towards peer to peer and on-prem services ?
>
>-----Original Message-----
>From: Ace [mailto:ace-bounces@ietf.org] On Behalf Of Ludwig Seitz
>Sent: Tuesday, July 29, 2014 1:02 AM
>To: ace@ietf.org
>Subject: Re: [Ace] Use Case draft
>
>On 07/28/2014 10:29 PM, Kathleen Moriarty wrote:
>> Hello,
>>
>> I had read through the draft before the meeting and noted that in
>> section 2.2.1, I thought the roles of the people involved in the use
>> case were distracting.  Changing this may help keep people focused on
>> the scenario as opposed to details that don't matter for ACE.  FYI - A
>> single woman letting an acquaintance into her home without her there
>> would be unusual.  Most women would not do that for safety reasons.
>> The interpretation of acquaintance may vary between regions, but for
>> me, an acquaintance is someone I don't really know well.  If you make
>> Jeffrey her brother, or switch the roles of Jeffrey & Jane, the
>> scenario is much more plausible and will help to prevent people from
>> getting distracted while reading this scenario.
>>
>I'll update this in the next version if we don't change the use case
>entirely.
>
>> In reading through the draft, I noticed a few things missing from the
>> Security Requirements section that could be helpful for the next
>> editorial pass.  If there were reasons they were not included, please
>> let me know.
>>
>> 1. Threats such as session intercept/hijacking or monitoring are not
>> covered yet.
>
>The idea of this draft was to cover issues concerning authentication and
>authorization (and a few  directly related issues) since that is the
>topic of ACE. I think the problems you mention above are not directly
>relevant for ACE, therefore I left them out of the document.
>
>>
>> 2. Logging, protection of logs (and purging) is mentioned in one of
>> the use cases, but not in the security section.  This would be a good
>> addition, but should also include privacy considerations associated
>> with the logs as well (correlation of events, etc.).
>
>We had a discussion about Auditing (the third A of AAA) and logging
>during the chartering process, and some people thought it would make the
>focus of the group too broad to try and also cover Auditing (including
>logging).
>
>Therefore I have left out questions of auditing (and privacy) for the
>moment.
>
>
>>
>> 3. There will also be a number of privacy considerations that should be
>> noted in this section or one on privacy.  This might include concerns of
>> being able to profile habits of a person or other similar concerns.
>>
>
>See above.
>
>
>
>Regards,
>
>Ludwig Seitz
>
>
>--=20
>Ludwig Seitz, PhD
>SICS Swedish ICT AB
>Ideon Science Park
>Building Beta 2
>Scheelev=E4gen 17
>SE-223 70 Lund
>
>Phone +46(0)70-349 92 51
>http://www.sics.se
>
>_______________________________________________
>Ace mailing list
>Ace@ietf.org
>https://www.ietf.org/mailman/listinfo/ace


From nobody Wed Jul 30 10:43:01 2014
Return-Path: <tonynad@microsoft.com>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 873601A01AC for <ace@ietfa.amsl.com>; Wed, 30 Jul 2014 10:42:47 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.601
X-Spam-Level: 
X-Spam-Status: No, score=-2.601 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_LOW=-0.7, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id e3T0bPJqgauI for <ace@ietfa.amsl.com>; Wed, 30 Jul 2014 10:42:41 -0700 (PDT)
Received: from na01-bl2-obe.outbound.protection.outlook.com (mail-bl2lp0206.outbound.protection.outlook.com [207.46.163.206]) (using TLSv1 with cipher ECDHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 7882B1A0164 for <ace@ietf.org>; Wed, 30 Jul 2014 10:42:31 -0700 (PDT)
Received: from BLUPR03MB309.namprd03.prod.outlook.com (10.141.48.22) by BLUPR03MB312.namprd03.prod.outlook.com (10.141.48.28) with Microsoft SMTP Server (TLS) id 15.0.995.11; Wed, 30 Jul 2014 17:42:28 +0000
Received: from BLUPR03MB309.namprd03.prod.outlook.com ([10.141.48.22]) by BLUPR03MB309.namprd03.prod.outlook.com ([10.141.48.22]) with mapi id 15.00.0995.011; Wed, 30 Jul 2014 17:42:29 +0000
From: Anthony Nadalin <tonynad@microsoft.com>
To: Dorothy Gellert <dgellert@silverspringnet.com>, Ludwig Seitz <ludwig@sics.se>, "ace@ietf.org" <ace@ietf.org>
Thread-Topic: [Ace] Use Case draft
Thread-Index: AQHPqqK4PP7lvKFDAkeF8MQZPzEln5u2sW2AgACP2uCAAG9cgIABK+Ag
Date: Wed, 30 Jul 2014 17:42:28 +0000
Message-ID: <516f38cfa4474c658ca133629a118250@BLUPR03MB309.namprd03.prod.outlook.com>
References: <a4451f29afc8467fad4d802a69f1165c@BLUPR03MB309.namprd03.prod.outlook.com> <CFFD7754.1411C%dgellert@silverspringnet.com>
In-Reply-To: <CFFD7754.1411C%dgellert@silverspringnet.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
x-originating-ip: [2001:4898:80e0:ee43::3]
x-microsoft-antispam: BCL:0;PCL:0;RULEID:
x-forefront-prvs: 0288CD37D9
x-forefront-antispam-report: SFV:NSPM; SFS:(189002)(199002)(51704005)(24454002)(13464003)(479174003)(377454003)(4396001)(95666004)(74662001)(85852003)(46102001)(19300405004)(19580395003)(21056001)(76576001)(77982001)(31966008)(33646002)(15975445006)(92566001)(19617315012)(15202345003)(16601075003)(106116001)(107046002)(79102001)(86362001)(99286002)(83072002)(16236675004)(86612001)(80022001)(81542001)(105586002)(19625215002)(101416001)(76176999)(106356001)(85306003)(74502001)(19580405001)(20776003)(107886001)(2656002)(64706001)(54356999)(87936001)(74316001)(50986999)(99396002)(83322001)(81342001)(76482001)(42262001)(24736002)(3826002)(108616003); DIR:OUT; SFP:; SCL:1; SRVR:BLUPR03MB312; H:BLUPR03MB309.namprd03.prod.outlook.com; FPR:; MLV:sfv; PTR:InfoNoRecords; MX:1; LANG:en; 
Content-Type: multipart/alternative; boundary="_000_516f38cfa4474c658ca133629a118250BLUPR03MB309namprd03pro_"
MIME-Version: 1.0
X-OriginatorOrg: microsoft.onmicrosoft.com
Archived-At: http://mailarchive.ietf.org/arch/msg/ace/2iHETKbiWSUaTjyTHRlFfW0TO94
Subject: Re: [Ace] Use Case draft
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 30 Jul 2014 17:42:47 -0000

--_000_516f38cfa4474c658ca133629a118250BLUPR03MB309namprd03pro_
Content-Type: text/plain; charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable

I totally agree bit I'm just not seeing the peer-2-peer in the current use =
case document.



1)      High-end devices (I'm defining high-end as capable of TLS).  Scenar=
io is : the device, like an industrial pump, presents an identity proof to =
a gateway service, the service verifies the proof and authenticates the dev=
ice. Once authenticated, the device can upload telemetry information, query=
 for information, receive notifications and/or receive commands.  We  can a=
ccomplish this today with the OAuth 2.0 assertion profile, with client acti=
ng as itself, sending a signed assertion to the gateway. The key is pre-pro=
visioned on the device at the manufacture.

a.       The first scenario is to improve on the above. Specific areas of i=
mprovement

                                                   i.      Lighter weight p=
rotocol, reduced amount of bytes sent on the wire, and reduced cpu cycles o=
n the device.

                                                 ii.      Address mid-range=
 devices (that have TCP/IP stack but no TLS built in). One candidate that i=
s being looked at is TKS PKS, to allow a shared symmetric key to be used to=
 enable transport level security.

2)      Secret provisioning is another important problem to solve. Scenario=
 is : I bring home my new thermostat and want to associate it with my accou=
nt, how is it paired? Later when I sell my house, how to I transfer ownersh=
ip of the thermostat? The most common pattern seems to be having the user g=
et a code from the device, enter it in a pc, than acknowledge the pairing f=
rom the device. There are similar patterns for mid-range devices without di=
splays (like https://www.spark.io/), they have a photo resistor, that liter=
ally let a phone app flash a code to the device to complete the pairing. Pr=
ovisioning protocol, should allow for various ways to communicate keys.

Some Interesting consumer scenarios might be:

1)      When I install a new light bulb, how does my wife get access to con=
trol it from her phone? This should be seamless, since there can't be an on=
boarding experience for everything I bring into the home.

2)      If somebody sides a malicious "puck" device under my door, what kee=
ps it from joining the other things in the home and attacking the house.

3)      If I have guests and I want to give control of some parts of my hom=
e, how is that done? Use of proximity is one interesting idea I've heard he=
re, if you are in my house you can turn lights on and off.





-----Original Message-----
From: Dorothy Gellert [mailto:dgellert@silverspringnet.com]
Sent: Tuesday, July 29, 2014 4:15 PM
To: Anthony Nadalin; Ludwig Seitz; ace@ietf.org
Subject: Re: [Ace] Use Case draft



Hi Anthony-



We should consider both device to cloud and peer to peer - otherwise the pr=
otocol will have design in preventive measures against unsupported deployme=
nt models.



Best Regards,

Dorothy Gellert

Silver Spring Networks

Director, Standards and Technology

E dgellert@silverspringnet.com<mailto:dgellert@silverspringnet.com>

O +1 650 839 4378

C +1 650 556-5994







On 7/29/14, 9:37 AM, "Anthony Nadalin" <tonynad@microsoft.com<mailto:tonyna=
d@microsoft.com>> wrote:



>So it looks like the use cases so far are more geared toward device to

>cloud, with a central cloud service that provides orchestration between

>devices and not towards peer to peer and on-prem services ?

>

>-----Original Message-----

>From: Ace [mailto:ace-bounces@ietf.org] On Behalf Of Ludwig Seitz

>Sent: Tuesday, July 29, 2014 1:02 AM

>To: ace@ietf.org<mailto:ace@ietf.org>

>Subject: Re: [Ace] Use Case draft

>

>On 07/28/2014 10:29 PM, Kathleen Moriarty wrote:

>> Hello,

>>

>> I had read through the draft before the meeting and noted that in

>> section 2.2.1, I thought the roles of the people involved in the use

>> case were distracting.  Changing this may help keep people focused on

>> the scenario as opposed to details that don't matter for ACE.  FYI -

>> A single woman letting an acquaintance into her home without her

>> there would be unusual.  Most women would not do that for safety reasons=
.

>> The interpretation of acquaintance may vary between regions, but for

>> me, an acquaintance is someone I don't really know well.  If you make

>> Jeffrey her brother, or switch the roles of Jeffrey & Jane, the

>> scenario is much more plausible and will help to prevent people from

>> getting distracted while reading this scenario.

>>

>I'll update this in the next version if we don't change the use case

>entirely.

>

>> In reading through the draft, I noticed a few things missing from the

>> Security Requirements section that could be helpful for the next

>> editorial pass.  If there were reasons they were not included, please

>> let me know.

>>

>> 1. Threats such as session intercept/hijacking or monitoring are not

>> covered yet.

>

>The idea of this draft was to cover issues concerning authentication

>and authorization (and a few  directly related issues) since that is

>the topic of ACE. I think the problems you mention above are not

>directly relevant for ACE, therefore I left them out of the document.

>

>>

>> 2. Logging, protection of logs (and purging) is mentioned in one of

>> the use cases, but not in the security section.  This would be a good

>> addition, but should also include privacy considerations associated

>> with the logs as well (correlation of events, etc.).

>

>We had a discussion about Auditing (the third A of AAA) and logging

>during the chartering process, and some people thought it would make

>the focus of the group too broad to try and also cover Auditing

>(including logging).

>

>Therefore I have left out questions of auditing (and privacy) for the

>moment.

>

>

>>

>> 3. There will also be a number of privacy considerations that should

>> be noted in this section or one on privacy.  This might include

>> concerns of being able to profile habits of a person or other similar co=
ncerns.

>>

>

>See above.

>

>

>

>Regards,

>

>Ludwig Seitz

>

>

>--

>Ludwig Seitz, PhD

>SICS Swedish ICT AB

>Ideon Science Park

>Building Beta 2

>Scheelev=E4gen 17

>SE-223 70 Lund

>

>Phone +46(0)70-349 92 51

>http://www.sics.se

>

>_______________________________________________

>Ace mailing list

>Ace@ietf.org<mailto:Ace@ietf.org>

>https://www.ietf.org/mailman/listinfo/ace



--_000_516f38cfa4474c658ca133629a118250BLUPR03MB309namprd03pro_
Content-Type: text/html; charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable

<html xmlns:v=3D"urn:schemas-microsoft-com:vml" xmlns:o=3D"urn:schemas-micr=
osoft-com:office:office" xmlns:w=3D"urn:schemas-microsoft-com:office:word" =
xmlns:m=3D"http://schemas.microsoft.com/office/2004/12/omml" xmlns=3D"http:=
//www.w3.org/TR/REC-html40">
<head>
<meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3Diso-8859-=
1">
<meta name=3D"Generator" content=3D"Microsoft Word 15 (filtered medium)">
<style><!--
/* Font Definitions */
@font-face
	{font-family:"Cambria Math";
	panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
	{font-family:Calibri;
	panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
	{font-family:Consolas;
	panose-1:2 11 6 9 2 2 4 3 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
	{margin:0in;
	margin-bottom:.0001pt;
	font-size:11.0pt;
	font-family:"Calibri","sans-serif";}
a:link, span.MsoHyperlink
	{mso-style-priority:99;
	color:#0563C1;
	text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
	{mso-style-priority:99;
	color:#954F72;
	text-decoration:underline;}
p.MsoPlainText, li.MsoPlainText, div.MsoPlainText
	{mso-style-priority:99;
	mso-style-link:"Plain Text Char";
	margin:0in;
	margin-bottom:.0001pt;
	font-size:11.0pt;
	font-family:"Calibri","sans-serif";}
p.MsoListParagraph, li.MsoListParagraph, div.MsoListParagraph
	{mso-style-priority:34;
	margin-top:0in;
	margin-right:0in;
	margin-bottom:0in;
	margin-left:.5in;
	margin-bottom:.0001pt;
	font-size:11.0pt;
	font-family:"Calibri","sans-serif";}
span.PlainTextChar
	{mso-style-name:"Plain Text Char";
	mso-style-priority:99;
	mso-style-link:"Plain Text";
	font-family:"Calibri","sans-serif";}
span.EmailStyle19
	{mso-style-type:personal;
	font-family:"Calibri","sans-serif";
	color:windowtext;}
.MsoChpDefault
	{mso-style-type:export-only;
	font-family:"Calibri","sans-serif";}
@page WordSection1
	{size:8.5in 11.0in;
	margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
	{page:WordSection1;}
/* List Definitions */
@list l0
	{mso-list-id:345599468;
	mso-list-type:hybrid;
	mso-list-template-ids:-1148807360 67698705 67698713 67698715 67698703 6769=
8713 67698715 67698703 67698713 67698715;}
@list l0:level1
	{mso-level-text:"%1\)";
	mso-level-tab-stop:none;
	mso-level-number-position:left;
	text-indent:-.25in;}
@list l0:level2
	{mso-level-number-format:alpha-lower;
	mso-level-tab-stop:none;
	mso-level-number-position:left;
	text-indent:-.25in;}
@list l0:level3
	{mso-level-number-format:roman-lower;
	mso-level-tab-stop:none;
	mso-level-number-position:right;
	text-indent:-9.0pt;}
@list l0:level4
	{mso-level-tab-stop:none;
	mso-level-number-position:left;
	text-indent:-.25in;}
@list l0:level5
	{mso-level-number-format:alpha-lower;
	mso-level-tab-stop:none;
	mso-level-number-position:left;
	text-indent:-.25in;}
@list l0:level6
	{mso-level-number-format:roman-lower;
	mso-level-tab-stop:none;
	mso-level-number-position:right;
	text-indent:-9.0pt;}
@list l0:level7
	{mso-level-tab-stop:none;
	mso-level-number-position:left;
	text-indent:-.25in;}
@list l0:level8
	{mso-level-number-format:alpha-lower;
	mso-level-tab-stop:none;
	mso-level-number-position:left;
	text-indent:-.25in;}
@list l0:level9
	{mso-level-number-format:roman-lower;
	mso-level-tab-stop:none;
	mso-level-number-position:right;
	text-indent:-9.0pt;}
@list l1
	{mso-list-id:827478655;
	mso-list-type:hybrid;
	mso-list-template-ids:-852704138 67698705 67698713 67698715 67698703 67698=
713 67698715 67698703 67698713 67698715;}
@list l1:level1
	{mso-level-text:"%1\)";
	mso-level-tab-stop:none;
	mso-level-number-position:left;
	margin-left:.25in;
	text-indent:-.25in;}
@list l1:level2
	{mso-level-number-format:alpha-lower;
	mso-level-tab-stop:none;
	mso-level-number-position:left;
	margin-left:.75in;
	text-indent:-.25in;}
@list l1:level3
	{mso-level-number-format:roman-lower;
	mso-level-tab-stop:none;
	mso-level-number-position:right;
	margin-left:1.25in;
	text-indent:-9.0pt;}
@list l1:level4
	{mso-level-tab-stop:none;
	mso-level-number-position:left;
	margin-left:1.75in;
	text-indent:-.25in;}
@list l1:level5
	{mso-level-number-format:alpha-lower;
	mso-level-tab-stop:none;
	mso-level-number-position:left;
	margin-left:2.25in;
	text-indent:-.25in;}
@list l1:level6
	{mso-level-number-format:roman-lower;
	mso-level-tab-stop:none;
	mso-level-number-position:right;
	margin-left:2.75in;
	text-indent:-9.0pt;}
@list l1:level7
	{mso-level-tab-stop:none;
	mso-level-number-position:left;
	margin-left:3.25in;
	text-indent:-.25in;}
@list l1:level8
	{mso-level-number-format:alpha-lower;
	mso-level-tab-stop:none;
	mso-level-number-position:left;
	margin-left:3.75in;
	text-indent:-.25in;}
@list l1:level9
	{mso-level-number-format:roman-lower;
	mso-level-tab-stop:none;
	mso-level-number-position:right;
	margin-left:4.25in;
	text-indent:-9.0pt;}
ol
	{margin-bottom:0in;}
ul
	{margin-bottom:0in;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext=3D"edit" spidmax=3D"1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext=3D"edit">
<o:idmap v:ext=3D"edit" data=3D"1" />
</o:shapelayout></xml><![endif]-->
</head>
<body lang=3D"EN-US" link=3D"#0563C1" vlink=3D"#954F72">
<div class=3D"WordSection1">
<p class=3D"MsoPlainText">I totally agree bit I'm just not seeing the peer-=
2-peer in the current use case document.<o:p></o:p></p>
<p class=3D"MsoPlainText"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoListParagraph" style=3D"margin-left:.25in;text-indent:-.25in=
;mso-list:l1 level1 lfo1">
<![if !supportLists]><span style=3D"color:#1F497D"><span style=3D"mso-list:=
Ignore">1)<span style=3D"font:7.0pt &quot;Times New Roman&quot;">&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;
</span></span></span><![endif]><span style=3D"color:#1F497D">High-end devic=
es (I&#8217;m defining high-end as capable of TLS).&nbsp; Scenario is : the=
 device, like an industrial pump, presents an identity proof to a gateway s=
ervice, the service verifies the proof and authenticates
 the device. Once authenticated, the device can upload telemetry informatio=
n, query for information, receive notifications and/or receive commands. &n=
bsp;We&nbsp; can accomplish this today with the OAuth 2.0 assertion profile=
, with client acting as itself, sending a
 signed assertion to the gateway. The key is pre-provisioned on the device =
at the manufacture.<o:p></o:p></span></p>
<p class=3D"MsoListParagraph" style=3D"margin-left:.75in;text-indent:-.25in=
;mso-list:l1 level2 lfo1">
<![if !supportLists]><span style=3D"color:#1F497D"><span style=3D"mso-list:=
Ignore">a.<span style=3D"font:7.0pt &quot;Times New Roman&quot;">&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;
</span></span></span><![endif]><span style=3D"color:#1F497D">The first scen=
ario is to improve on the above. Specific areas of improvement<o:p></o:p></=
span></p>
<p class=3D"MsoListParagraph" style=3D"margin-left:1.25in;text-indent:-1.25=
in;mso-text-indent-alt:-9.0pt;mso-list:l1 level3 lfo1">
<![if !supportLists]><span style=3D"color:#1F497D"><span style=3D"mso-list:=
Ignore"><span style=3D"font:7.0pt &quot;Times New Roman&quot;">&nbsp;&nbsp;=
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
</span>i.<span style=3D"font:7.0pt &quot;Times New Roman&quot;">&nbsp;&nbsp=
;&nbsp;&nbsp;&nbsp; </span></span></span><![endif]><span style=3D"color:#1F=
497D">Lighter weight protocol, reduced amount of bytes sent on the wire, an=
d reduced cpu cycles on the device.<o:p></o:p></span></p>
<p class=3D"MsoListParagraph" style=3D"margin-left:1.25in;text-indent:-1.25=
in;mso-text-indent-alt:-9.0pt;mso-list:l1 level3 lfo1">
<![if !supportLists]><span style=3D"color:#1F497D"><span style=3D"mso-list:=
Ignore"><span style=3D"font:7.0pt &quot;Times New Roman&quot;">&nbsp;&nbsp;=
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
</span>ii.<span style=3D"font:7.0pt &quot;Times New Roman&quot;">&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp; </span></span></span><![endif]><span style=3D"color:#1=
F497D">Address mid-range devices (that have TCP/IP stack but no TLS built i=
n). One candidate that is being looked at is TKS PKS, to allow a shared
 symmetric key to be used to enable transport level security.<o:p></o:p></s=
pan></p>
<p class=3D"MsoListParagraph" style=3D"margin-left:.25in;text-indent:-.25in=
;mso-list:l1 level1 lfo1">
<![if !supportLists]><span style=3D"color:#1F497D"><span style=3D"mso-list:=
Ignore">2)<span style=3D"font:7.0pt &quot;Times New Roman&quot;">&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;
</span></span></span><![endif]><span style=3D"color:#1F497D">Secret provisi=
oning is another important problem to solve. Scenario is : I bring home my =
new thermostat and want to associate it with my account, how is it paired? =
Later when I sell my house, how to
 I transfer ownership of the thermostat? The most common pattern seems to b=
e having the user get a code from the device, enter it in a pc, than acknow=
ledge the pairing from the device. There are similar patterns for mid-range=
 devices without displays (like
<a href=3D"https://www.spark.io/">https://www.spark.io/</a>), they have a p=
hoto resistor, that literally let a phone app flash a code to the device to=
 complete the pairing. Provisioning protocol, should allow for various ways=
 to communicate keys.<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"color:#1F497D"><o:p>&nbsp;</o:p></spa=
n></p>
<p class=3D"MsoNormal"><span style=3D"color:#1F497D">Some Interesting consu=
mer scenarios might be:<o:p></o:p></span></p>
<p class=3D"MsoListParagraph" style=3D"text-indent:-.25in;mso-list:l0 level=
1 lfo2"><![if !supportLists]><span style=3D"color:#1F497D"><span style=3D"m=
so-list:Ignore">1)<span style=3D"font:7.0pt &quot;Times New Roman&quot;">&n=
bsp;&nbsp;&nbsp;&nbsp;&nbsp;
</span></span></span><![endif]><span style=3D"color:#1F497D">When I install=
 a new light bulb, how does my wife get access to control it from her phone=
? This should be seamless, since there can&#8217;t be an onboarding experie=
nce for everything I bring into the home.<o:p></o:p></span></p>
<p class=3D"MsoListParagraph" style=3D"text-indent:-.25in;mso-list:l0 level=
1 lfo2"><![if !supportLists]><span style=3D"color:#1F497D"><span style=3D"m=
so-list:Ignore">2)<span style=3D"font:7.0pt &quot;Times New Roman&quot;">&n=
bsp;&nbsp;&nbsp;&nbsp;&nbsp;
</span></span></span><![endif]><span style=3D"color:#1F497D">If somebody si=
des a malicious &#8220;puck&#8221; device under my door, what keeps it from=
 joining the other things in the home and attacking the house.<o:p></o:p></=
span></p>
<p class=3D"MsoListParagraph" style=3D"text-indent:-.25in;mso-list:l0 level=
1 lfo2"><![if !supportLists]><span style=3D"color:#1F497D"><span style=3D"m=
so-list:Ignore">3)<span style=3D"font:7.0pt &quot;Times New Roman&quot;">&n=
bsp;&nbsp;&nbsp;&nbsp;&nbsp;
</span></span></span><![endif]><span style=3D"color:#1F497D">If I have gues=
ts and I want to give control of some parts of my home, how is that done? U=
se of proximity is one interesting idea I&#8217;ve heard here, if you are i=
n my house you can turn lights on and off.<o:p></o:p></span></p>
<p class=3D"MsoPlainText"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoPlainText"><a name=3D"_MailEndCompose"><o:p>&nbsp;</o:p></a>=
</p>
<p class=3D"MsoPlainText">-----Original Message-----<br>
From: Dorothy Gellert [mailto:dgellert@silverspringnet.com] <br>
Sent: Tuesday, July 29, 2014 4:15 PM<br>
To: Anthony Nadalin; Ludwig Seitz; ace@ietf.org<br>
Subject: Re: [Ace] Use Case draft</p>
<p class=3D"MsoPlainText"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoPlainText">Hi Anthony-<o:p></o:p></p>
<p class=3D"MsoPlainText"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoPlainText">We should consider both device to cloud and peer =
to peer - otherwise the protocol will have design in preventive measures ag=
ainst unsupported deployment models.
<o:p></o:p></p>
<p class=3D"MsoPlainText"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoPlainText">Best Regards,<o:p></o:p></p>
<p class=3D"MsoPlainText">Dorothy Gellert<o:p></o:p></p>
<p class=3D"MsoPlainText">Silver Spring Networks<o:p></o:p></p>
<p class=3D"MsoPlainText">Director, Standards and Technology<o:p></o:p></p>
<p class=3D"MsoPlainText">E <a href=3D"mailto:dgellert@silverspringnet.com"=
><span style=3D"color:windowtext;text-decoration:none">dgellert@silversprin=
gnet.com</span></a><o:p></o:p></p>
<p class=3D"MsoPlainText">O &#43;1 650 839 4378<o:p></o:p></p>
<p class=3D"MsoPlainText">C &#43;1 650 556-5994<o:p></o:p></p>
<p class=3D"MsoPlainText"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoPlainText"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoPlainText"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoPlainText">On 7/29/14, 9:37 AM, &quot;Anthony Nadalin&quot; =
&lt;<a href=3D"mailto:tonynad@microsoft.com"><span style=3D"color:windowtex=
t;text-decoration:none">tonynad@microsoft.com</span></a>&gt; wrote:<o:p></o=
:p></p>
<p class=3D"MsoPlainText"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoPlainText">&gt;So it looks like the use cases so far are mor=
e geared toward device to
<o:p></o:p></p>
<p class=3D"MsoPlainText">&gt;cloud, with a central cloud service that prov=
ides orchestration between
<o:p></o:p></p>
<p class=3D"MsoPlainText">&gt;devices and not towards peer to peer and on-p=
rem services ?<o:p></o:p></p>
<p class=3D"MsoPlainText">&gt;<o:p>&nbsp;</o:p></p>
<p class=3D"MsoPlainText">&gt;-----Original Message-----<o:p></o:p></p>
<p class=3D"MsoPlainText">&gt;From: Ace [<a href=3D"mailto:ace-bounces@ietf=
.org"><span style=3D"color:windowtext;text-decoration:none">mailto:ace-boun=
ces@ietf.org</span></a>] On Behalf Of Ludwig Seitz<o:p></o:p></p>
<p class=3D"MsoPlainText">&gt;Sent: Tuesday, July 29, 2014 1:02 AM<o:p></o:=
p></p>
<p class=3D"MsoPlainText">&gt;To: <a href=3D"mailto:ace@ietf.org"><span sty=
le=3D"color:windowtext;text-decoration:none">ace@ietf.org</span></a><o:p></=
o:p></p>
<p class=3D"MsoPlainText">&gt;Subject: Re: [Ace] Use Case draft<o:p></o:p><=
/p>
<p class=3D"MsoPlainText">&gt;<o:p>&nbsp;</o:p></p>
<p class=3D"MsoPlainText">&gt;On 07/28/2014 10:29 PM, Kathleen Moriarty wro=
te:<o:p></o:p></p>
<p class=3D"MsoPlainText">&gt;&gt; Hello,<o:p></o:p></p>
<p class=3D"MsoPlainText">&gt;&gt;<o:p>&nbsp;</o:p></p>
<p class=3D"MsoPlainText">&gt;&gt; I had read through the draft before the =
meeting and noted that in
<o:p></o:p></p>
<p class=3D"MsoPlainText">&gt;&gt; section 2.2.1, I thought the roles of th=
e people involved in the use
<o:p></o:p></p>
<p class=3D"MsoPlainText">&gt;&gt; case were distracting.&nbsp; Changing th=
is may help keep people focused on
<o:p></o:p></p>
<p class=3D"MsoPlainText">&gt;&gt; the scenario as opposed to details that =
don't matter for ACE.&nbsp; FYI -
<o:p></o:p></p>
<p class=3D"MsoPlainText">&gt;&gt; A single woman letting an acquaintance i=
nto her home without her
<o:p></o:p></p>
<p class=3D"MsoPlainText">&gt;&gt; there would be unusual.&nbsp; Most women=
 would not do that for safety reasons.<o:p></o:p></p>
<p class=3D"MsoPlainText">&gt;&gt; The interpretation of acquaintance may v=
ary between regions, but for
<o:p></o:p></p>
<p class=3D"MsoPlainText">&gt;&gt; me, an acquaintance is someone I don't r=
eally know well.&nbsp; If you make
<o:p></o:p></p>
<p class=3D"MsoPlainText">&gt;&gt; Jeffrey her brother, or switch the roles=
 of Jeffrey &amp; Jane, the
<o:p></o:p></p>
<p class=3D"MsoPlainText">&gt;&gt; scenario is much more plausible and will=
 help to prevent people from
<o:p></o:p></p>
<p class=3D"MsoPlainText">&gt;&gt; getting distracted while reading this sc=
enario.<o:p></o:p></p>
<p class=3D"MsoPlainText">&gt;&gt;<o:p>&nbsp;</o:p></p>
<p class=3D"MsoPlainText">&gt;I'll update this in the next version if we do=
n't change the use case
<o:p></o:p></p>
<p class=3D"MsoPlainText">&gt;entirely.<o:p></o:p></p>
<p class=3D"MsoPlainText">&gt;<o:p>&nbsp;</o:p></p>
<p class=3D"MsoPlainText">&gt;&gt; In reading through the draft, I noticed =
a few things missing from the
<o:p></o:p></p>
<p class=3D"MsoPlainText">&gt;&gt; Security Requirements section that could=
 be helpful for the next
<o:p></o:p></p>
<p class=3D"MsoPlainText">&gt;&gt; editorial pass.&nbsp; If there were reas=
ons they were not included, please
<o:p></o:p></p>
<p class=3D"MsoPlainText">&gt;&gt; let me know.<o:p></o:p></p>
<p class=3D"MsoPlainText">&gt;&gt;<o:p>&nbsp;</o:p></p>
<p class=3D"MsoPlainText">&gt;&gt; 1. Threats such as session intercept/hij=
acking or monitoring are not
<o:p></o:p></p>
<p class=3D"MsoPlainText">&gt;&gt; covered yet.<o:p></o:p></p>
<p class=3D"MsoPlainText">&gt;<o:p>&nbsp;</o:p></p>
<p class=3D"MsoPlainText">&gt;The idea of this draft was to cover issues co=
ncerning authentication
<o:p></o:p></p>
<p class=3D"MsoPlainText">&gt;and authorization (and a few&nbsp; directly r=
elated issues) since that is
<o:p></o:p></p>
<p class=3D"MsoPlainText">&gt;the topic of ACE. I think the problems you me=
ntion above are not
<o:p></o:p></p>
<p class=3D"MsoPlainText">&gt;directly relevant for ACE, therefore I left t=
hem out of the document.<o:p></o:p></p>
<p class=3D"MsoPlainText">&gt;<o:p>&nbsp;</o:p></p>
<p class=3D"MsoPlainText">&gt;&gt;<o:p>&nbsp;</o:p></p>
<p class=3D"MsoPlainText">&gt;&gt; 2. Logging, protection of logs (and purg=
ing) is mentioned in one of
<o:p></o:p></p>
<p class=3D"MsoPlainText">&gt;&gt; the use cases, but not in the security s=
ection.&nbsp; This would be a good
<o:p></o:p></p>
<p class=3D"MsoPlainText">&gt;&gt; addition, but should also include privac=
y considerations associated
<o:p></o:p></p>
<p class=3D"MsoPlainText">&gt;&gt; with the logs as well (correlation of ev=
ents, etc.).<o:p></o:p></p>
<p class=3D"MsoPlainText">&gt;<o:p>&nbsp;</o:p></p>
<p class=3D"MsoPlainText">&gt;We had a discussion about Auditing (the third=
 A of AAA) and logging
<o:p></o:p></p>
<p class=3D"MsoPlainText">&gt;during the chartering process, and some peopl=
e thought it would make
<o:p></o:p></p>
<p class=3D"MsoPlainText">&gt;the focus of the group too broad to try and a=
lso cover Auditing
<o:p></o:p></p>
<p class=3D"MsoPlainText">&gt;(including logging).<o:p></o:p></p>
<p class=3D"MsoPlainText">&gt;<o:p>&nbsp;</o:p></p>
<p class=3D"MsoPlainText">&gt;Therefore I have left out questions of auditi=
ng (and privacy) for the
<o:p></o:p></p>
<p class=3D"MsoPlainText">&gt;moment.<o:p></o:p></p>
<p class=3D"MsoPlainText">&gt;<o:p>&nbsp;</o:p></p>
<p class=3D"MsoPlainText">&gt;<o:p>&nbsp;</o:p></p>
<p class=3D"MsoPlainText">&gt;&gt;<o:p>&nbsp;</o:p></p>
<p class=3D"MsoPlainText">&gt;&gt; 3. There will also be a number of privac=
y considerations that should
<o:p></o:p></p>
<p class=3D"MsoPlainText">&gt;&gt; be noted in this section or one on priva=
cy.&nbsp; This might include
<o:p></o:p></p>
<p class=3D"MsoPlainText">&gt;&gt; concerns of being able to profile habits=
 of a person or other similar concerns.<o:p></o:p></p>
<p class=3D"MsoPlainText">&gt;&gt;<o:p>&nbsp;</o:p></p>
<p class=3D"MsoPlainText">&gt;<o:p>&nbsp;</o:p></p>
<p class=3D"MsoPlainText">&gt;See above.<o:p></o:p></p>
<p class=3D"MsoPlainText">&gt;<o:p>&nbsp;</o:p></p>
<p class=3D"MsoPlainText">&gt;<o:p>&nbsp;</o:p></p>
<p class=3D"MsoPlainText">&gt;<o:p>&nbsp;</o:p></p>
<p class=3D"MsoPlainText">&gt;Regards,<o:p></o:p></p>
<p class=3D"MsoPlainText">&gt;<o:p>&nbsp;</o:p></p>
<p class=3D"MsoPlainText">&gt;Ludwig Seitz<o:p></o:p></p>
<p class=3D"MsoPlainText">&gt;<o:p>&nbsp;</o:p></p>
<p class=3D"MsoPlainText">&gt;<o:p>&nbsp;</o:p></p>
<p class=3D"MsoPlainText">&gt;--<o:p></o:p></p>
<p class=3D"MsoPlainText">&gt;Ludwig Seitz, PhD<o:p></o:p></p>
<p class=3D"MsoPlainText">&gt;SICS Swedish ICT AB<o:p></o:p></p>
<p class=3D"MsoPlainText">&gt;Ideon Science Park<o:p></o:p></p>
<p class=3D"MsoPlainText">&gt;Building Beta 2<o:p></o:p></p>
<p class=3D"MsoPlainText">&gt;Scheelev=E4gen 17<o:p></o:p></p>
<p class=3D"MsoPlainText">&gt;SE-223 70 Lund<o:p></o:p></p>
<p class=3D"MsoPlainText">&gt;<o:p>&nbsp;</o:p></p>
<p class=3D"MsoPlainText">&gt;Phone &#43;46(0)70-349 92 51<o:p></o:p></p>
<p class=3D"MsoPlainText">&gt;<a href=3D"http://www.sics.se"><span style=3D=
"color:windowtext;text-decoration:none">http://www.sics.se</span></a><o:p><=
/o:p></p>
<p class=3D"MsoPlainText">&gt;<o:p>&nbsp;</o:p></p>
<p class=3D"MsoPlainText">&gt;_____________________________________________=
__<o:p></o:p></p>
<p class=3D"MsoPlainText">&gt;Ace mailing list<o:p></o:p></p>
<p class=3D"MsoPlainText">&gt;<a href=3D"mailto:Ace@ietf.org"><span style=
=3D"color:windowtext;text-decoration:none">Ace@ietf.org</span></a><o:p></o:=
p></p>
<p class=3D"MsoPlainText">&gt;<a href=3D"https://www.ietf.org/mailman/listi=
nfo/ace"><span style=3D"color:windowtext;text-decoration:none">https://www.=
ietf.org/mailman/listinfo/ace</span></a><o:p></o:p></p>
<p class=3D"MsoPlainText"><o:p>&nbsp;</o:p></p>
</div>
</body>
</html>

--_000_516f38cfa4474c658ca133629a118250BLUPR03MB309namprd03pro_--


From nobody Wed Jul 30 13:44:58 2014
Return-Path: <mcr@sandelman.ca>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id E39E21A03B1 for <ace@ietfa.amsl.com>; Wed, 30 Jul 2014 13:44:55 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.892
X-Spam-Level: 
X-Spam-Status: No, score=-1.892 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001, T_TVD_MIME_NO_HEADERS=0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id UArtzyvZ2Kgo for <ace@ietfa.amsl.com>; Wed, 30 Jul 2014 13:44:54 -0700 (PDT)
Received: from tuna.sandelman.ca (tuna.sandelman.ca [IPv6:2607:f0b0:f:3:216:3eff:fe7c:d1f3]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id F3D121A039B for <ace@ietf.org>; Wed, 30 Jul 2014 13:44:53 -0700 (PDT)
Received: from sandelman.ca (obiwan.sandelman.ca [209.87.249.21]) by tuna.sandelman.ca (Postfix) with ESMTP id 705E520028; Wed, 30 Jul 2014 16:46:59 -0400 (EDT)
Received: by sandelman.ca (Postfix, from userid 179) id 22B2463B0E; Wed, 30 Jul 2014 16:44:53 -0400 (EDT)
Received: from sandelman.ca (localhost [127.0.0.1]) by sandelman.ca (Postfix) with ESMTP id 0D30E63B09; Wed, 30 Jul 2014 16:44:53 -0400 (EDT)
From: Michael Richardson <mcr+ietf@sandelman.ca>
To: "ace\@ietf.org" <ace@ietf.org>
In-Reply-To: <53D7E60D.5030704@tzi.de>
References: <CAHbuEH7hn0iWJpx7hwaOQnDO9_n16ZKuDh4sF4G=LsPHXde6hg@mail.gmail.com> <53D754ED.7060700@sics.se> <a4451f29afc8467fad4d802a69f1165c@BLUPR03MB309.namprd03.prod.outlook.com> <53D7E60D.5030704@tzi.de>
X-Mailer: MH-E 8.2; nmh 1.3-dev; GNU Emacs 23.4.1
X-Face: $\n1pF)h^`}$H>Hk{L"x@)JS7<%Az}5RyS@k9X%29-lHB$Ti.V>2bi.~ehC0; <'$9xN5Ub# z!G,p`nR&p7Fz@^UXIn156S8.~^@MJ*mMsD7=QFeq%AL4m<nPbLgmtKK-5dC@#:k
MIME-Version: 1.0
Content-Type: multipart/signed; boundary="=-=-="; micalg=pgp-sha1; protocol="application/pgp-signature"
Date: Wed, 30 Jul 2014 16:44:53 -0400
Message-ID: <2272.1406753093@sandelman.ca>
Sender: mcr@sandelman.ca
Archived-At: http://mailarchive.ietf.org/arch/msg/ace/DokYKRs6oNuWtRLM6Q2nRyDc9ZQ
Cc: Anthony Nadalin <tonynad@microsoft.com>
Subject: Re: [Ace] Use Case draft
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 30 Jul 2014 20:44:56 -0000

--=-=-=


Stefanie Gerdes <gerdes@tzi.de> wrote:
    > The scenario we are discussing is: * A Client (C) wants to access a
    > Resource (R) on a Resource Server (RS).  * A priori, C and RS do not
    > necessarily know each other and have no security relationship.  * C and
    > / or RS are constrained.  (cf. [1])

    > The goal is to enable C and RS to communicate securely and to enforce
    > the authorization policies of their respective owners.

    > To achieve this, Authorization Servers are introduced which relieve the
    > constrained devices from performing more difficult tasks and help them
    > with authentication and authorization.

    > Does this answer your question?

No, his question was:

    > On 07/29/2014 06:37 PM, Anthony Nadalin wrote:
    >> So it looks like the use cases so far are more geared toward device to
    >> cloud, with a central cloud service that provides orchestration
    >> between devices and not towards peer to peer and on-prem services ?

and the answer is that having a "central" "cloud" service is only *one*
possible location for the Authorization Manager and Authorization Server.

They could also be located on-site (of a factory, or home. Behind the
"NAT"^W"security firewall"..),  or be co-located inside a non-constrained C
or RS.

[Obviously, if both are non-constrained, there appears to be no point, but
that also assumes all RS and all C are such]


--
Michael Richardson <mcr+IETF@sandelman.ca>, Sandelman Software Works
 -= IPv6 IoT consulting =-




--=-=-=
Content-Type: application/pgp-signature

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iQEVAwUBU9lZQoCLcPvd0N1lAQIb8AgApRzEmmy3qXPL3xl51k1g44QyCvLM3pg0
xAqIFugWMFmett/fQbJ00mmB/S7mitaJnWFioGO+2Zhn14JOAiml9fBTq3yL7/XQ
VdbgrtoXpikYmLzt1iLbwCy7YNJnncGnLOzj2KMcXmEH5A36brpTunVgvjr/ToS6
hpQMGlKqZPkvQIqGFBl0jvyBdeNFqIdhm38zc/2dWFveA6q/JibWGkFG+l1YVQDI
TsEwVh3wvXV62C2w2Ivd1yfvMbx4f1LJfhRhJcow75W6Kog7pwqyq7qCaBkyoE5i
kYlVTSaSfWinxm2ixHH+lu1ZGujKesVyNcJLAaJmKx616fGL0xxofg==
=CpD9
-----END PGP SIGNATURE-----
--=-=-=--


From nobody Wed Jul 30 13:49:11 2014
Return-Path: <mcr@sandelman.ca>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id B270B1A03F2 for <ace@ietfa.amsl.com>; Wed, 30 Jul 2014 13:49:04 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.892
X-Spam-Level: 
X-Spam-Status: No, score=-1.892 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001, T_TVD_MIME_NO_HEADERS=0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id DXrYfPFbjKbM for <ace@ietfa.amsl.com>; Wed, 30 Jul 2014 13:49:02 -0700 (PDT)
Received: from tuna.sandelman.ca (tuna.sandelman.ca [IPv6:2607:f0b0:f:3:216:3eff:fe7c:d1f3]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id A5D9E1A03B1 for <ace@ietf.org>; Wed, 30 Jul 2014 13:49:02 -0700 (PDT)
Received: from sandelman.ca (obiwan.sandelman.ca [IPv6:2607:f0b0:f:2::247]) by tuna.sandelman.ca (Postfix) with ESMTP id 4C96020028 for <ace@ietf.org>; Wed, 30 Jul 2014 16:51:08 -0400 (EDT)
Received: by sandelman.ca (Postfix, from userid 179) id F226263B0E; Wed, 30 Jul 2014 16:49:01 -0400 (EDT)
Received: from sandelman.ca (localhost [127.0.0.1]) by sandelman.ca (Postfix) with ESMTP id DE8F063B09 for <ace@ietf.org>; Wed, 30 Jul 2014 16:49:01 -0400 (EDT)
From: Michael Richardson <mcr+ietf@sandelman.ca>
To: "ace\@ietf.org" <ace@ietf.org>
In-Reply-To: <516f38cfa4474c658ca133629a118250@BLUPR03MB309.namprd03.prod.outlook.com>
References: <a4451f29afc8467fad4d802a69f1165c@BLUPR03MB309.namprd03.prod.outlook.com> <CFFD7754.1411C%dgellert@silverspringnet.com> <516f38cfa4474c658ca133629a118250@BLUPR03MB309.namprd03.prod.outlook.com>
X-Mailer: MH-E 8.2; nmh 1.3-dev; GNU Emacs 23.4.1
X-Face: $\n1pF)h^`}$H>Hk{L"x@)JS7<%Az}5RyS@k9X%29-lHB$Ti.V>2bi.~ehC0; <'$9xN5Ub# z!G,p`nR&p7Fz@^UXIn156S8.~^@MJ*mMsD7=QFeq%AL4m<nPbLgmtKK-5dC@#:k
MIME-Version: 1.0
Content-Type: multipart/signed; boundary="=-=-="; micalg=pgp-sha1; protocol="application/pgp-signature"
Date: Wed, 30 Jul 2014 16:49:01 -0400
Message-ID: <3194.1406753341@sandelman.ca>
Sender: mcr@sandelman.ca
Archived-At: http://mailarchive.ietf.org/arch/msg/ace/cDgjezmTp-eyrfZj48HH1Zz1Yqk
Subject: Re: [Ace] Use Case draft
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 30 Jul 2014 20:49:04 -0000

--=-=-=


Anthony Nadalin <tonynad@microsoft.com> wrote:
    > I totally agree bit I'm just not seeing the peer-2-peer in the current
    > use case document.

    > 1) High-end devices (I'm defining high-end as capable of TLS).
    > Scenario is : the device, like an industrial pump, presents an identity

There are many people who would define a device capable of TLS as class-2,
not high end, and would say that it barely does DTLS, and maybe can not do
more than a few DTLS session setups per battery charge.
Can it do OAUTH2? it's a code space issue.

    > The key is pre-provisioned on the device at
    > the manufacture.

    > 2) Secret provisioning is another important problem to solve. Scenario
    > is : I bring home my new thermostat and want to associate it with my
    > account, how is it paired? Later when I sell my house, how to I
    > transfer ownership of the thermostat? The most common pattern seems to

Out of scope for ACE at this time.
See UCAN BOF.

    > 1) When I install a new light bulb, how does my wife get access to
    > control it from her phone? This should be seamless, since there can't
    > be an onboarding experience for everything I bring into the home.

    > 2) If somebody sides a malicious "puck" device under my door, what
    > keeps it from joining the other things in the home and attacking the
    > house.

    > 3) If I have guests and I want to give control of some parts of my
    > home, how is that done? Use of proximity is one interesting idea I've
    > heard here, if you are in my house you can turn lights on and off.

all out of scope for *this* WG.

--
Michael Richardson <mcr+IETF@sandelman.ca>, Sandelman Software Works
 -= IPv6 IoT consulting =-




--=-=-=
Content-Type: application/pgp-signature

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iQEVAwUBU9laO4CLcPvd0N1lAQKfKQgAplg+1gZM4M6Y+rSVlgqDjehtlNBVbelY
qciHtvaF7rTPKIcorUJdfkGS7/MFJIaBn6ntPliOYwy8AajkBiOgf2vrBQF3xPfZ
VdNa7rHGt5G1pkkZWk3aoIW7JRu9KjEd3mz6dcfrckynZhqFhev22IoPH1Nd+tek
6Jd0y2FGZI7YPQm52+6ndJ5kTfWErw0veZiHnhAfgl3/4c3UXgfjZ9zRhyDi3sfb
VyPZ5vivhEzzUXTyM1EUIxYH2Anj5q+xR2/+76BYiJAGLpGCcep1pZJKpu+3rmDm
7QHw+28b8qbmZm/yKrV73bHmJR3CHcCD8DB8vcMo3U7c6nW1JK8sFg==
=o82i
-----END PGP SIGNATURE-----
--=-=-=--


From nobody Wed Jul 30 15:16:27 2014
Return-Path: <Michael.Jones@microsoft.com>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 186A61A01AA for <ace@ietfa.amsl.com>; Wed, 30 Jul 2014 15:16:26 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.602
X-Spam-Level: 
X-Spam-Status: No, score=-2.602 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_LOW=-0.7, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id PrBSweGTaz3x for <ace@ietfa.amsl.com>; Wed, 30 Jul 2014 15:16:23 -0700 (PDT)
Received: from na01-by2-obe.outbound.protection.outlook.com (mail-by2lp0242.outbound.protection.outlook.com [207.46.163.242]) (using TLSv1 with cipher ECDHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id B74231A01A5 for <ace@ietf.org>; Wed, 30 Jul 2014 15:16:23 -0700 (PDT)
Received: from BN3PR0301CA0061.namprd03.prod.outlook.com (25.160.152.157) by BY2PR03MB256.namprd03.prod.outlook.com (10.242.37.23) with Microsoft SMTP Server (TLS) id 15.0.995.14; Wed, 30 Jul 2014 22:16:21 +0000
Received: from BL2FFO11FD060.protection.gbl (2a01:111:f400:7c09::120) by BN3PR0301CA0061.outlook.office365.com (2a01:111:e400:401e::29) with Microsoft SMTP Server (TLS) id 15.0.995.14 via Frontend Transport; Wed, 30 Jul 2014 22:16:21 +0000
Received: from mail.microsoft.com (131.107.125.37) by BL2FFO11FD060.mail.protection.outlook.com (10.173.161.188) with Microsoft SMTP Server (TLS) id 15.0.980.11 via Frontend Transport; Wed, 30 Jul 2014 22:16:20 +0000
Received: from TK5EX14MBXC293.redmond.corp.microsoft.com ([169.254.2.111]) by TK5EX14MLTC104.redmond.corp.microsoft.com ([157.54.79.159]) with mapi id 14.03.0195.002; Wed, 30 Jul 2014 22:15:40 +0000
From: Mike Jones <Michael.Jones@microsoft.com>
To: Michael Richardson <mcr+ietf@sandelman.ca>, "ace@ietf.org" <ace@ietf.org>
Thread-Topic: [Ace] Use Case draft
Thread-Index: AQHPqqK4pw8Jvxv/1kW5LViaowz78Zu2sW2AgACQLwCAAG8HgIABNVoAgAA0H4CAABf40A==
Date: Wed, 30 Jul 2014 22:15:39 +0000
Message-ID: <4E1F6AAD24975D4BA5B16804296739439ADFA427@TK5EX14MBXC293.redmond.corp.microsoft.com>
References: <a4451f29afc8467fad4d802a69f1165c@BLUPR03MB309.namprd03.prod.outlook.com> <CFFD7754.1411C%dgellert@silverspringnet.com> <516f38cfa4474c658ca133629a118250@BLUPR03MB309.namprd03.prod.outlook.com> <3194.1406753341@sandelman.ca>
In-Reply-To: <3194.1406753341@sandelman.ca>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
x-originating-ip: [157.54.51.19]
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
X-EOPAttributedMessage: 0
X-Forefront-Antispam-Report: CIP:131.107.125.37; CTRY:US; IPV:CAL; IPV:NLI; IPV:NLI; EFV:NLI; SFV:NSPM; SFS:(6009001)(438002)(199002)(189002)(13464003)(24454002)(377454003)(6806004)(83322001)(44976005)(19580405001)(20776003)(50466002)(84676001)(93886003)(107886001)(97736001)(86612001)(107046002)(33656002)(86362001)(97756001)(68736004)(4396001)(69596002)(77982001)(92726001)(74502001)(47776003)(74662001)(81156004)(64706001)(2656002)(31966008)(106466001)(19580395003)(46102001)(92566001)(83072002)(95666004)(26826002)(106116001)(79102001)(76482001)(80022001)(85306003)(77096002)(54356999)(81542001)(21056001)(66066001)(87936001)(23726002)(99396002)(104016003)(55846006)(50986999)(85852003)(81342001)(76176999)(46406003); DIR:OUT; SFP:; SCL:1; SRVR:BY2PR03MB256; H:mail.microsoft.com; FPR:; MLV:ovrnspm; PTR:InfoDomainNonexistent; MX:1; LANG:en; 
X-Microsoft-Antispam: BCL:0;PCL:0;RULEID:
X-O365ENT-EOP-Header: Message processed by -  O365_ENT: Allow from ranges (Engineering ONLY)
X-Forefront-PRVS: 0288CD37D9
Received-SPF: Pass (protection.outlook.com: domain of microsoft.com designates 131.107.125.37 as permitted sender) receiver=protection.outlook.com;  client-ip=131.107.125.37; helo=mail.microsoft.com;
Authentication-Results: spf=pass (sender IP is 131.107.125.37) smtp.mailfrom=Michael.Jones@microsoft.com; 
X-OriginatorOrg: microsoft.onmicrosoft.com
Archived-At: http://mailarchive.ietf.org/arch/msg/ace/qk7qO6rxOYNw1NWGYDhHSQtq-4o
Subject: Re: [Ace] Use Case draft
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 30 Jul 2014 22:16:26 -0000

If all of this is out of scope, how will these problems be solved end-to-en=
d?  Are there specific other working groups working on these issues?  Which=
 ones does ACE plan to restrict itself to?

				-- Mike

-----Original Message-----
From: Ace [mailto:ace-bounces@ietf.org] On Behalf Of Michael Richardson
Sent: Wednesday, July 30, 2014 1:49 PM
To: ace@ietf.org
Subject: Re: [Ace] Use Case draft


Anthony Nadalin <tonynad@microsoft.com> wrote:
    > I totally agree bit I'm just not seeing the peer-2-peer in the curren=
t
    > use case document.

    > 1) High-end devices (I'm defining high-end as capable of TLS).
    > Scenario is : the device, like an industrial pump, presents an identi=
ty

There are many people who would define a device capable of TLS as class-2, =
not high end, and would say that it barely does DTLS, and maybe can not do =
more than a few DTLS session setups per battery charge.
Can it do OAUTH2? it's a code space issue.

    > The key is pre-provisioned on the device at
    > the manufacture.

    > 2) Secret provisioning is another important problem to solve. Scenari=
o
    > is : I bring home my new thermostat and want to associate it with my
    > account, how is it paired? Later when I sell my house, how to I
    > transfer ownership of the thermostat? The most common pattern seems t=
o

Out of scope for ACE at this time.
See UCAN BOF.

    > 1) When I install a new light bulb, how does my wife get access to
    > control it from her phone? This should be seamless, since there can't
    > be an onboarding experience for everything I bring into the home.

    > 2) If somebody sides a malicious "puck" device under my door, what
    > keeps it from joining the other things in the home and attacking the
    > house.

    > 3) If I have guests and I want to give control of some parts of my
    > home, how is that done? Use of proximity is one interesting idea I've
    > heard here, if you are in my house you can turn lights on and off.

all out of scope for *this* WG.

--
Michael Richardson <mcr+IETF@sandelman.ca>, Sandelman Software Works  -=3D =
IPv6 IoT consulting =3D-




From nobody Thu Jul 31 00:59:30 2014
Return-Path: <likepeng@huawei.com>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id C17CD1A0397 for <ace@ietfa.amsl.com>; Thu, 31 Jul 2014 00:59:28 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.202
X-Spam-Level: 
X-Spam-Status: No, score=-4.202 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 985QQExDcScl for <ace@ietfa.amsl.com>; Thu, 31 Jul 2014 00:59:27 -0700 (PDT)
Received: from lhrrgout.huawei.com (lhrrgout.huawei.com [194.213.3.17]) (using TLSv1 with cipher RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 377451A03B3 for <ace@ietf.org>; Thu, 31 Jul 2014 00:59:27 -0700 (PDT)
Received: from 172.18.7.190 (EHLO lhreml404-hub.china.huawei.com) ([172.18.7.190]) by lhrrg02-dlp.huawei.com (MOS 4.3.7-GA FastPath queued) with ESMTP id BHT74700; Thu, 31 Jul 2014 07:59:25 +0000 (GMT)
Received: from SZXEMA410-HUB.china.huawei.com (10.82.72.42) by lhreml404-hub.china.huawei.com (10.201.5.218) with Microsoft SMTP Server (TLS) id 14.3.158.1; Thu, 31 Jul 2014 08:59:25 +0100
Received: from SZXEMA501-MBS.china.huawei.com ([169.254.2.128]) by SZXEMA410-HUB.china.huawei.com ([10.82.72.42]) with mapi id 14.03.0158.001; Thu, 31 Jul 2014 15:59:22 +0800
From: Likepeng <likepeng@huawei.com>
To: "ace@ietf.org" <ace@ietf.org>
Thread-Topic: IETF 90 meeting minutes
Thread-Index: AQHPrJVW4RcLLTlBZUW+jgAIKQkOJg==
Date: Thu, 31 Jul 2014 07:59:21 +0000
Message-ID: <34966E97BE8AD64EAE9D3D6E4DEE36F25817D535@SZXEMA501-MBS.china.huawei.com>
References: <a4451f29afc8467fad4d802a69f1165c@BLUPR03MB309.namprd03.prod.outlook.com> <CFFD7754.1411C%dgellert@silverspringnet.com> <516f38cfa4474c658ca133629a118250@BLUPR03MB309.namprd03.prod.outlook.com> <3194.1406753341@sandelman.ca> <4E1F6AAD24975D4BA5B16804296739439ADFA427@TK5EX14MBXC293.redmond.corp.microsoft.com>
In-Reply-To: <4E1F6AAD24975D4BA5B16804296739439ADFA427@TK5EX14MBXC293.redmond.corp.microsoft.com>
Accept-Language: zh-CN, en-US
Content-Language: zh-CN
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
x-originating-ip: [10.66.167.122]
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
X-CFilter-Loop: Reflected
Archived-At: http://mailarchive.ietf.org/arch/msg/ace/KNoRTrVoiVWbPo6hUgRSJI-_4js
Cc: Kerry Lynn <kerlyn@ieee.org>, Hannes Tschofenig <hannes.tschofenig@gmx.net>
Subject: [Ace] IETF 90 meeting minutes
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 31 Jul 2014 07:59:29 -0000

Here is the IETF 90 ACE meeting minutes:
http://www.ietf.org/proceedings/90/minutes/minutes-90-ace

Thanks to Kerry Lynn for taking the minutes.

Kind Regards
Kepeng


From nobody Thu Jul 31 04:45:20 2014
Return-Path: <cabo@tzi.org>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 34FE01A0AB5 for <ace@ietfa.amsl.com>; Thu, 31 Jul 2014 04:45:17 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.551
X-Spam-Level: 
X-Spam-Status: No, score=-1.551 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HELO_EQ_DE=0.35, SPF_HELO_PASS=-0.001] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id nsocRrmecpFX for <ace@ietfa.amsl.com>; Thu, 31 Jul 2014 04:45:15 -0700 (PDT)
Received: from informatik.uni-bremen.de (mailhost.informatik.uni-bremen.de [IPv6:2001:638:708:30c9::12]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 08DAC1A0AC9 for <ace@ietf.org>; Thu, 31 Jul 2014 04:45:09 -0700 (PDT)
X-Virus-Scanned: amavisd-new at informatik.uni-bremen.de
Received: from smtp-fb3.informatik.uni-bremen.de (smtp-fb3.informatik.uni-bremen.de [134.102.224.120]) by informatik.uni-bremen.de (8.14.5/8.14.5) with ESMTP id s6VBj1fI018308; Thu, 31 Jul 2014 13:45:01 +0200 (CEST)
Received: from [192.168.217.145] (p5489084A.dip0.t-ipconnect.de [84.137.8.74]) (using TLSv1 with cipher AES128-SHA (128/128 bits)) (No client certificate requested) by smtp-fb3.informatik.uni-bremen.de (Postfix) with ESMTPSA id BAB4F7B0; Thu, 31 Jul 2014 13:45:00 +0200 (CEST)
Content-Type: text/plain; charset=windows-1252
Mime-Version: 1.0 (Mac OS X Mail 7.3 \(1878.6\))
From: Carsten Bormann <cabo@tzi.org>
In-Reply-To: <3194.1406753341@sandelman.ca>
Date: Thu, 31 Jul 2014 13:44:59 +0200
X-Mao-Original-Outgoing-Id: 428499899.234431-cde1049337422e0a7abe72567aea7c24
Content-Transfer-Encoding: quoted-printable
Message-Id: <B25EA849-C71B-4CC8-B6D2-E5BF3FEC2C55@tzi.org>
References: <a4451f29afc8467fad4d802a69f1165c@BLUPR03MB309.namprd03.prod.outlook.com> <CFFD7754.1411C%dgellert@silverspringnet.com> <516f38cfa4474c658ca133629a118250@BLUPR03MB309.namprd03.prod.outlook.com> <3194.1406753341@sandelman.ca>
To: Michael Richardson <mcr+ietf@sandelman.ca>
X-Mailer: Apple Mail (2.1878.6)
Archived-At: http://mailarchive.ietf.org/arch/msg/ace/bISsP7tiA71JSVFhfQ03BrpCpjg
Cc: "ace@ietf.org" <ace@ietf.org>
Subject: Re: [Ace] Use Case draft
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 31 Jul 2014 11:45:17 -0000

On 30 Jul 2014, at 22:49, Michael Richardson <mcr+ietf@sandelman.ca> =
wrote:

>> 2) Secret provisioning is another important problem to solve. =
Scenario
>> is : I bring home my new thermostat and want to associate it with my
>> account, how is it paired?

ACE needs to enable this.  (And it may want to work without requiring =
the concept of =93account=94.)
The initial method of pairing or whatever is out of scope (being able to =
keep it here is one of the points of the differentiation between AM and =
AS).

>> Later when I sell my house, how to I
>> transfer ownership of the thermostat? The most common pattern seems =
to
>=20
> Out of scope for ACE at this time.

Ownership transfer is an important authorization use case.
(The more interesting question, how do you forcibly gain ownership for =
the contents of a foreclosed home, is way out of scope, though.)

> See UCAN BOF.

I don=92t think UCAN discusses ownership transfer.

>> 1) When I install a new light bulb, how does my wife get access to
>> control it from her phone? This should be seamless, since there can't
>> be an onboarding experience for everything I bring into the home.

The ACE specifications definitely need to enable this.
The entire problem may not be solved by them (but what is).

>> 2) If somebody sides a malicious "puck" device under my door, what
>> keeps it from joining the other things in the home and attacking the
>> house.

If the ACE protocols are not secure against this I have no idea =
whatsoever what we are trying to do.
(It=92s not exactly a =93use case=94 in the classical sense; maybe we =
should be explicit about misuse cases and threats in general.)

>> 3) If I have guests and I want to give control of some parts of my
>> home, how is that done? Use of proximity is one interesting idea I've
>> heard here, if you are in my house you can turn lights on and off.

Again, ACE needs to enable this.
The method of proximity/in-perimeter detection is out of scope.

> all out of scope for *this* WG.

Not so sure about that.

Gr=FC=DFe, Carsten


From nobody Thu Jul 31 21:08:16 2014
Return-Path: <rstruik.ext@gmail.com>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 6C0B51A03BE for <ace@ietfa.amsl.com>; Thu, 31 Jul 2014 21:08:12 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.999
X-Spam-Level: 
X-Spam-Status: No, score=-1.999 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 68_kXBEOnhtE for <ace@ietfa.amsl.com>; Thu, 31 Jul 2014 21:08:08 -0700 (PDT)
Received: from mail-ie0-x22a.google.com (mail-ie0-x22a.google.com [IPv6:2607:f8b0:4001:c03::22a]) (using TLSv1 with cipher ECDHE-RSA-RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id A90F71A03C9 for <Ace@ietf.org>; Thu, 31 Jul 2014 21:08:08 -0700 (PDT)
Received: by mail-ie0-f170.google.com with SMTP id rl12so5276767iec.1 for <Ace@ietf.org>; Thu, 31 Jul 2014 21:08:08 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113;  h=message-id:date:from:user-agent:mime-version:to:subject:references :in-reply-to:content-type; bh=liDjT9xAGOlyKzgSnLRVDsjMgQPWNtwMdrx0tX5H0Fk=; b=Q0VTk3nqEZr5LSS0N4XiciDXWkmOtIu64YrggcaedzC4ZmX1P8GOMWeIjj3Zedo//P sgdEEvwT/tCq2ZgS1YVfpfb1L6b6eLwmgYg7ne/otxeFtvLuPaiq/Ws6INUdB4zGb7hG 8ThPCqfA+izCK4kzRTqj4jrR89zgktOk64zREmY4u58Umz36OUima7NLT5ZNrDAldQ/3 caxPGbEQLFbWCHrws6gQrgE0dJHrECf9kYsmTfehSFeU6sV6Ji6jMTLk6S+VqpfnXouL jXQunb5U42iSFEdVCLutz5OiaYiZxA+MaPXotFEdmNmuBIb7X/+0HdlcCFzn+QMX2fyH WUXQ==
X-Received: by 10.50.13.102 with SMTP id g6mr3231103igc.20.1406866087961; Thu, 31 Jul 2014 21:08:07 -0700 (PDT)
Received: from [192.168.0.10] (CPE7cb21b2cb904-CM7cb21b2cb901.cpe.net.cable.rogers.com. [99.231.118.107]) by mx.google.com with ESMTPSA id o9sm5513287igv.18.2014.07.31.21.08.07 for <multiple recipients> (version=TLSv1 cipher=ECDHE-RSA-RC4-SHA bits=128/128); Thu, 31 Jul 2014 21:08:07 -0700 (PDT)
Message-ID: <53DB12A2.90209@gmail.com>
Date: Fri, 01 Aug 2014 00:08:02 -0400
From: Rene Struik <rstruik.ext@gmail.com>
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:24.0) Gecko/20100101 Thunderbird/24.6.0
MIME-Version: 1.0
To: Hannes Tschofenig <hannes.tschofenig@gmx.net>,  "Ace@ietf.org" <Ace@ietf.org>
References: <53CD27D3.1010709@gmx.net>
In-Reply-To: <53CD27D3.1010709@gmx.net>
Content-Type: multipart/alternative; boundary="------------010606020805070300040903"
Archived-At: http://mailarchive.ietf.org/arch/msg/ace/Iez91rCiV0CBKxCAWhM3bTZomNE
Subject: Re: [Ace] Call for adoption on draft-seitz-ace-usecases-01 ("ACE Use Cases")
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 01 Aug 2014 04:08:12 -0000

This is a multi-part message in MIME format.
--------------010606020805070300040903
Content-Type: text/plain; charset=ISO-8859-1; format=flowed
Content-Transfer-Encoding: 7bit

Dear colleagues:

I participated in the ACE discussions in Toronto last week, read 
draft-seitz-ace-usecases-01, and saw the email discussions that ensued 
since the meeting.

Unfortunately, I cannot support adopting the use case draft in its 
current form.

I think it is far from ready to be a fruitful base for incremental 
improvements as a WG document. Moreover, there seems to be quite some 
disagreement as to whether certain use cases (discussed on the mailing 
list over the last few days, but mostly not in the draft) are considered 
inside scope of this working group.

We should not simply adopt a draft, just because it is there. It also 
should have sufficient merit to have a chance progressing to an 
informational RFC or document that otherwise would guide the development 
of an authorization and authentication solution as a proposed standard. 
Right now, I feel it does not have these qualities.

I would provide a more succinct description of use cases that capture 
security-relevant events, including the following:
1) change of network composition: new kid on the block; temporary 
(repair) or permanently (disposed) decommissioned device; temporary or 
permanent network union, resp. partitioning;
2) change of roles of devices: new role assigned to device; role 
retracted from device; assignment of meta-roles and retraction hereof; 
roles based on global policies, resp. local decisions;
3) initialization or roles of devices and evolution hereof during 
lifecycle of devices and networks, all the way from conception (e.g., 
chip manufacturing) to system integration, etc. (e.g., change of 
ownership/control, logical/procedural transfer operation), to 
operational use, replacement, disposition.

I would also go into more details as to what might be different with 
constrained networks. Simply allocating a single third-party device to 
do arbitrage may not do the job, since delegation of computational or 
storage cost may be offset by communication cost, energy consumption, 
and denial of service risk. One should support both peer-to-peer 
(localized) and outsourced ("cloud based", if one wishes) scenarios.

I would also pay lots of attention to distinction between homogeneous 
and heterogeneous trust domain scenarios. After all, one should 
facilitate "mix and match" scenarios, where devices may be procured from 
multiple vendors, that may not know each other and, even if they would, 
not trust each other. Having any presumption that manufacturers should 
do secret handshakes for their devices to be able to communicate 
securely may hamper significantly deployment in ease of use manner and 
never bring the full potential of internet of things forward. Moreover, 
it could stifle innovation, since baking in pre-established 
relationships may force the hand of contractual parties in favor of 
vested interests and the bigger party.

Use cases should focus on both consumer and non-consumer style scenarios 
and include, industrial control, critical infrastructure, etc. I am 
happy to contribute to use cases that incorporate the above feedback and 
that borrow from experience gained in discussions with industrial 
control and other wireless sensor standardization groups, covering both 
security, ease of use, and ease of deployment and provisioning, over the 
last 5-10 years.

Lastly, it would be good to take the viewpoint as to what 
functionalities are required and emphasize slghtly less those 
constraints that may become less of an issue over time (e.g., those in 
the digital vs. the analog domain). As we heard during the ACE session 
in Toronto, lots of crypto can be considered (or can soon be considered) 
a commodity for low-hanging fruit applications one may wish to target.

What is needed in the end is a design incorporating the right type of 
crypto primitives and protocols and a language that expresses device 
roles and meta-roles that can be conveyed over the air. Design then 
centers around which crypto, which protocols, which roles, how to 
express things, which granularity, etc. This would, of course, be part 
of the design of the solution and not part of the use cases, but 
certainly relates to requirements (if one wishes to tie this in with use 
cases).

Best regards, Rene

On 7/21/2014 10:46 AM, Hannes Tschofenig wrote:
> Hi all,
>
> we have a milestone for a use case document in ACe and
> draft-seitz-ace-usecases is a promising candidate for this milestone.
>
> This email is a call for adoption for draft-seitz-ace-usecases-01.
>
> Please respond if you support, or object to, the adoption of this
> document as the basis for this work item. Deadline for your response:
> 31. July 2014
>
> Ciao
> Hannes & Kepeng
>
>
>
> _______________________________________________
> Ace mailing list
> Ace@ietf.org
> https://www.ietf.org/mailman/listinfo/ace


-- 
email: rstruik.ext@gmail.com | Skype: rstruik
cell: +1 (647) 867-5658 | US: +1 (415) 690-7363


--------------010606020805070300040903
Content-Type: text/html; charset=ISO-8859-1
Content-Transfer-Encoding: 7bit

<html>
  <head>
    <meta content="text/html; charset=ISO-8859-1"
      http-equiv="Content-Type">
  </head>
  <body bgcolor="#FFFFFF" text="#000000">
    <div class="moz-cite-prefix">Dear colleagues:<br>
      <br>
      I participated in the ACE discussions in Toronto last week, read
      draft-seitz-ace-usecases-01, and saw the email discussions that
      ensued since the meeting.<br>
      <br>
      Unfortunately, I cannot support adopting the use case draft in its
      current form.<br>
      <br>
      I think it is far from ready to be a fruitful base for incremental
      improvements as a WG document. Moreover, there seems to be quite
      some disagreement as to whether certain use cases (discussed on
      the mailing list over the last few days, but mostly not in the
      draft) are considered inside scope of this working group.<br>
      <br>
      We should not simply adopt a draft, just because it is there. It
      also should have sufficient merit to have a chance progressing to
      an informational RFC or document that otherwise would guide the
      development of an authorization and authentication solution as a
      proposed standard. Right now, I feel it does not have these
      qualities.<br>
      <br>
      I would provide a more succinct description of use cases that
      capture security-relevant events, including the following:<br>
      1) change of network composition: new kid on the block; temporary
      (repair) or permanently (disposed) decommissioned device;
      temporary or permanent network union, resp. partitioning;<br>
      2) change of roles of devices: new role assigned to device; role
      retracted from device; assignment of meta-roles and retraction
      hereof; roles based on global policies, resp. local decisions;<br>
      3) initialization or roles of devices and evolution hereof during
      lifecycle of devices and networks, all the way from conception
      (e.g., chip manufacturing) to system integration, etc. (e.g.,
      change of ownership/control, logical/procedural transfer
      operation), to operational use, replacement, disposition.<br>
      <br>
      I would also go into more details as to what might be different
      with constrained networks. Simply allocating a single third-party
      device to do arbitrage may not do the job, since delegation of
      computational or storage cost may be offset by communication cost,
      energy consumption, and denial of service risk. One should support
      both peer-to-peer (localized) and outsourced ("cloud based", if
      one wishes) scenarios.<br>
      <br>
      I would also pay lots of attention to distinction between
      homogeneous and heterogeneous trust domain scenarios. After all,
      one should facilitate "mix and match" scenarios, where devices may
      be procured from multiple vendors, that may not know each other
      and, even if they would, not trust each other. Having any
      presumption that manufacturers should do secret handshakes for
      their devices to be able to communicate securely may hamper
      significantly deployment in ease of use manner and never bring the
      full potential of internet of things forward. Moreover, it could
      stifle innovation, since baking in pre-established relationships
      may force the hand of contractual parties in favor of vested
      interests and the bigger party.<br>
      <br>
      Use cases should focus on both consumer and non-consumer style
      scenarios and include, industrial control, critical
      infrastructure, etc. I am happy to contribute to use cases that
      incorporate the above feedback and that borrow from experience
      gained in discussions with industrial control and other wireless
      sensor standardization groups, covering both security, ease of
      use, and ease of deployment and provisioning, over the last 5-10
      years.<br>
      <br>
      Lastly, it would be good to take the viewpoint as to what
      functionalities are required and emphasize slghtly less those
      constraints that may become less of an issue over time (e.g.,
      those in the digital vs. the analog domain). As we heard during
      the ACE session in Toronto, lots of crypto can be considered (or
      can soon be considered) a commodity for low-hanging fruit
      applications one may wish to target.<br>
      <br>
      What is needed in the end is a design incorporating the right type
      of crypto primitives and protocols and a language that expresses
      device roles and meta-roles that can be conveyed over the air.
      Design then centers around which crypto, which protocols, which
      roles, how to express things, which granularity, etc. This would,
      of course, be part of the design of the solution and not part of
      the use cases, but certainly relates to requirements (if one
      wishes to tie this in with use cases).<br>
      <br>
      Best regards, Rene<br>
      <br>
      On 7/21/2014 10:46 AM, Hannes Tschofenig wrote:<br>
    </div>
    <blockquote cite="mid:53CD27D3.1010709@gmx.net" type="cite">
      <pre wrap="">Hi all,

we have a milestone for a use case document in ACe and
draft-seitz-ace-usecases is a promising candidate for this milestone.

This email is a call for adoption for draft-seitz-ace-usecases-01.

Please respond if you support, or object to, the adoption of this
document as the basis for this work item. Deadline for your response:
31. July 2014

Ciao
Hannes &amp; Kepeng

</pre>
      <br>
      <fieldset class="mimeAttachmentHeader"></fieldset>
      <br>
      <pre wrap="">_______________________________________________
Ace mailing list
<a class="moz-txt-link-abbreviated" href="mailto:Ace@ietf.org">Ace@ietf.org</a>
<a class="moz-txt-link-freetext" href="https://www.ietf.org/mailman/listinfo/ace">https://www.ietf.org/mailman/listinfo/ace</a>
</pre>
    </blockquote>
    <br>
    <br>
    <pre class="moz-signature" cols="72">-- 
email: <a class="moz-txt-link-abbreviated" href="mailto:rstruik.ext@gmail.com">rstruik.ext@gmail.com</a> | Skype: rstruik
cell: +1 (647) 867-5658 | US: +1 (415) 690-7363</pre>
  </body>
</html>

--------------010606020805070300040903--


From nobody Thu Jul 31 23:11:31 2014
Return-Path: <martinmurillo@gmail.com>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id D70431A0424 for <ace@ietfa.amsl.com>; Thu, 31 Jul 2014 23:11:24 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.899
X-Spam-Level: 
X-Spam-Status: No, score=-1.899 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 1dKY70QGUM3T for <ace@ietfa.amsl.com>; Thu, 31 Jul 2014 23:11:18 -0700 (PDT)
Received: from mail-ig0-x22e.google.com (mail-ig0-x22e.google.com [IPv6:2607:f8b0:4001:c05::22e]) (using TLSv1 with cipher ECDHE-RSA-RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 2898A1A041F for <ace@ietf.org>; Thu, 31 Jul 2014 23:11:09 -0700 (PDT)
Received: by mail-ig0-f174.google.com with SMTP id c1so981939igq.13 for <ace@ietf.org>; Thu, 31 Jul 2014 23:11:08 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113;  h=sender:message-id:date:from:reply-to:user-agent:mime-version:to :subject:references:in-reply-to:content-type; bh=ZfxSvvFzkDoTkEfoolUx82015/FN8OjwU44rAuJWaxA=; b=Jaj6B3fVd96QNHxWq0RF63VI1FvEOjqS0l4nLT+t3G5y+ApxMxYFD19p526qGgxwmC 6YR075ftZiY4DO0R6lG66pTj0ZRIQZCcCjSnW865rLh3TWnPDEVSzU9fJopvjm883xv6 NEdDutdDuPzk4Fw2W7aZ0ojNwrfiraBrBXtE047xEA+CYs8obrKoR6ry3tscmKY0ybJQ UYvOZCEsfuVTP3JJKjwNry3eOZm9TSWztj26ckJYgh2+MsVc4RAiw4VwxwhzuxbDpxeb onX6rS+cSJKsBCs57Ajm9dWoVl4mLyj7GNj2Xipe7Hkm9aVEwBvQ48ycWewiKnLSNQ5z u4Ag==
X-Received: by 10.50.147.70 with SMTP id ti6mr3785300igb.45.1406873468463; Thu, 31 Jul 2014 23:11:08 -0700 (PDT)
Received: from ?IPv6:2601:d:2880:38b:9de:6f34:d24:faf5? ([2601:d:2880:38b:9de:6f34:d24:faf5]) by mx.google.com with ESMTPSA id ri8sm6607388igc.0.2014.07.31.23.11.05 for <multiple recipients> (version=TLSv1 cipher=ECDHE-RSA-RC4-SHA bits=128/128); Thu, 31 Jul 2014 23:11:06 -0700 (PDT)
Sender: "Martin J. Murillo" <martinmurillo@gmail.com>
Message-ID: <53DB2F7C.6060809@ieee.org>
Date: Fri, 01 Aug 2014 02:11:08 -0400
From: Martin Murillo <murillo@ieee.org>
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:24.0) Gecko/20100101 Thunderbird/24.4.0
MIME-Version: 1.0
To: Anthony Nadalin <tonynad@microsoft.com>,  Dorothy Gellert <dgellert@silverspringnet.com>, Ludwig Seitz <ludwig@sics.se>, "ace@ietf.org" <ace@ietf.org>
References: <a4451f29afc8467fad4d802a69f1165c@BLUPR03MB309.namprd03.prod.outlook.com> <CFFD7754.1411C%dgellert@silverspringnet.com> <516f38cfa4474c658ca133629a118250@BLUPR03MB309.namprd03.prod.outlook.com>
In-Reply-To: <516f38cfa4474c658ca133629a118250@BLUPR03MB309.namprd03.prod.outlook.com>
Content-Type: multipart/alternative; boundary="------------000205020403000905010702"
Archived-At: http://mailarchive.ietf.org/arch/msg/ace/eq-3g22xfVHalsls60aEyhHUKKc
Subject: Re: [Ace] Use Case draft
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
Reply-To: murillo@ieee.org
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 01 Aug 2014 06:11:25 -0000

This is a multi-part message in MIME format.
--------------000205020403000905010702
Content-Type: text/plain; charset=ISO-8859-1; format=flowed
Content-Transfer-Encoding: 8bit

Hi,

The shipping container use case is an example of the need of a peer to 
peer connection. As it is right now, it describes a very ideal situation 
in which a client has access to the resource (i.e. there's no objects in 
the path, no interference, the node is assumed to be working good). This 
is during transportation inside a container and during individual box 
handling to/from container/distribution point.

In a real scenario, also present in industrial areas where sensor 
networks are used for non critical tasks, a node does not always have 
direct access to the resource (i.e. base station). This can be due to 
objects on the way, interference of other devices (even though they work 
with spread spectrum), or the node not working properly.

Thus peer to peer connection is used in the form of mesh networking (or 
other scheme) so nodes in the proximity can talk to each other and have 
better chances to reach the base station or resource or just disseminate 
their information. In some scenarios when there's hundreds of nodes, 
master nodes are also used in addition to the base station.

Martin

On 7/30/2014 1:42 PM, Anthony Nadalin wrote:
>
> I totally agree bit I'm just not seeing the peer-2-peer in the current 
> use case document.
>
> 1)High-end devices (I'm defining high-end as capable of TLS).  
> Scenario is : the device, like an industrial pump, presents an 
> identity proof to a gateway service, the service verifies the proof 
> and authenticates the device. Once authenticated, the device can 
> upload telemetry information, query for information, receive 
> notifications and/or receive commands.  We  can accomplish this today 
> with the OAuth 2.0 assertion profile, with client acting as itself, 
> sending a signed assertion to the gateway. The key is pre-provisioned 
> on the device at the manufacture.
>
> a.The first scenario is to improve on the above. Specific areas of 
> improvement
>
> i.Lighter weight protocol, reduced amount of bytes sent on the wire, 
> and reduced cpu cycles on the device.
>
> ii.Address mid-range devices (that have TCP/IP stack but no TLS built 
> in). One candidate that is being looked at is TKS PKS, to allow a 
> shared symmetric key to be used to enable transport level security.
>
> 2)Secret provisioning is another important problem to solve. Scenario 
> is : I bring home my new thermostat and want to associate it with my 
> account, how is it paired? Later when I sell my house, how to I 
> transfer ownership of the thermostat? The most common pattern seems to 
> be having the user get a code from the device, enter it in a pc, than 
> acknowledge the pairing from the device. There are similar patterns 
> for mid-range devices without displays (like https://www.spark.io/), 
> they have a photo resistor, that literally let a phone app flash a 
> code to the device to complete the pairing. Provisioning protocol, 
> should allow for various ways to communicate keys.
>
> Some Interesting consumer scenarios might be:
>
> 1)When I install a new light bulb, how does my wife get access to 
> control it from her phone? This should be seamless, since there can't 
> be an onboarding experience for everything I bring into the home.
>
> 2)If somebody sides a malicious "puck" device under my door, what 
> keeps it from joining the other things in the home and attacking the 
> house.
>
> 3)If I have guests and I want to give control of some parts of my 
> home, how is that done? Use of proximity is one interesting idea I've 
> heard here, if you are in my house you can turn lights on and off.
>
> -----Original Message-----
> From: Dorothy Gellert [mailto:dgellert@silverspringnet.com]
> Sent: Tuesday, July 29, 2014 4:15 PM
> To: Anthony Nadalin; Ludwig Seitz; ace@ietf.org
> Subject: Re: [Ace] Use Case draft
>
> Hi Anthony-
>
> We should consider both device to cloud and peer to peer - otherwise 
> the protocol will have design in preventive measures against 
> unsupported deployment models.
>
> Best Regards,
>
> Dorothy Gellert
>
> Silver Spring Networks
>
> Director, Standards and Technology
>
> E dgellert@silverspringnet.com <mailto:dgellert@silverspringnet.com>
>
> O +1 650 839 4378
>
> C +1 650 556-5994
>
> On 7/29/14, 9:37 AM, "Anthony Nadalin" <tonynad@microsoft.com 
> <mailto:tonynad@microsoft.com>> wrote:
>
> >So it looks like the use cases so far are more geared toward device to
>
> >cloud, with a central cloud service that provides orchestration between
>
> >devices and not towards peer to peer and on-prem services ?
>
> >
>
> >-----Original Message-----
>
> >From: Ace [mailto:ace-bounces@ietf.org] On Behalf Of Ludwig Seitz
>
> >Sent: Tuesday, July 29, 2014 1:02 AM
>
> >To: ace@ietf.org <mailto:ace@ietf.org>
>
> >Subject: Re: [Ace] Use Case draft
>
> >
>
> >On 07/28/2014 10:29 PM, Kathleen Moriarty wrote:
>
> >> Hello,
>
> >>
>
> >> I had read through the draft before the meeting and noted that in
>
> >> section 2.2.1, I thought the roles of the people involved in the use
>
> >> case were distracting. Changing this may help keep people focused on
>
> >> the scenario as opposed to details that don't matter for ACE.  FYI -
>
> >> A single woman letting an acquaintance into her home without her
>
> >> there would be unusual.  Most women would not do that for safety 
> reasons.
>
> >> The interpretation of acquaintance may vary between regions, but for
>
> >> me, an acquaintance is someone I don't really know well.  If you make
>
> >> Jeffrey her brother, or switch the roles of Jeffrey & Jane, the
>
> >> scenario is much more plausible and will help to prevent people from
>
> >> getting distracted while reading this scenario.
>
> >>
>
> >I'll update this in the next version if we don't change the use case
>
> >entirely.
>
> >
>
> >> In reading through the draft, I noticed a few things missing from the
>
> >> Security Requirements section that could be helpful for the next
>
> >> editorial pass.  If there were reasons they were not included, please
>
> >> let me know.
>
> >>
>
> >> 1. Threats such as session intercept/hijacking or monitoring are not
>
> >> covered yet.
>
> >
>
> >The idea of this draft was to cover issues concerning authentication
>
> >and authorization (and a few directly related issues) since that is
>
> >the topic of ACE. I think the problems you mention above are not
>
> >directly relevant for ACE, therefore I left them out of the document.
>
> >
>
> >>
>
> >> 2. Logging, protection of logs (and purging) is mentioned in one of
>
> >> the use cases, but not in the security section.  This would be a good
>
> >> addition, but should also include privacy considerations associated
>
> >> with the logs as well (correlation of events, etc.).
>
> >
>
> >We had a discussion about Auditing (the third A of AAA) and logging
>
> >during the chartering process, and some people thought it would make
>
> >the focus of the group too broad to try and also cover Auditing
>
> >(including logging).
>
> >
>
> >Therefore I have left out questions of auditing (and privacy) for the
>
> >moment.
>
> >
>
> >
>
> >>
>
> >> 3. There will also be a number of privacy considerations that should
>
> >> be noted in this section or one on privacy.  This might include
>
> >> concerns of being able to profile habits of a person or other 
> similar concerns.
>
> >>
>
> >
>
> >See above.
>
> >
>
> >
>
> >
>
> >Regards,
>
> >
>
> >Ludwig Seitz
>
> >
>
> >
>
> >--
>
> >Ludwig Seitz, PhD
>
> >SICS Swedish ICT AB
>
> >Ideon Science Park
>
> >Building Beta 2
>
> >Scheelevägen 17
>
> >SE-223 70 Lund
>
> >
>
> >Phone +46(0)70-349 92 51
>
> >http://www.sics.se
>
> >
>
> >_______________________________________________
>
> >Ace mailing list
>
> >Ace@ietf.org <mailto:Ace@ietf.org>
>
> >https://www.ietf.org/mailman/listinfo/ace
>


--------------000205020403000905010702
Content-Type: text/html; charset=ISO-8859-1
Content-Transfer-Encoding: 7bit

<html>
  <head>
    <meta content="text/html; charset=ISO-8859-1"
      http-equiv="Content-Type">
  </head>
  <body bgcolor="#FFFFFF" text="#000000">
    Hi,<br>
    <br>
    The shipping container use case is an example of the need of a peer
    to peer connection. As it is right now, it describes a very ideal
    situation in which a client has access to the resource (i.e. there's
    no objects in the path, no interference, the node is assumed to be
    working good). This is during transportation inside a container and
    during individual box handling to/from container/distribution point.
    <br>
    <br>
    In a real scenario, also present in industrial areas where sensor
    networks are used for non critical tasks, a node does not always
    have direct access to the resource (i.e. base station). This can be
    due to objects on the way, interference of other devices (even
    though they work with spread spectrum), or the node not working
    properly. <br>
    <br>
    Thus peer to peer connection is used in the form of mesh networking
    (or other scheme) so nodes in the proximity can talk to each other
    and have better chances to reach the base station or resource or
    just disseminate their information. In some scenarios when there's
    hundreds of nodes, master nodes are also used in addition to the
    base station.<br>
    <br>
    Martin<br>
    <br>
    <div class="moz-cite-prefix">On 7/30/2014 1:42 PM, Anthony Nadalin
      wrote:<br>
    </div>
    <blockquote
cite="mid:%3C516f38cfa4474c658ca133629a118250@BLUPR03MB309.namprd03.prod.outlook.com%3E"
      type="cite">
      <meta http-equiv="Content-Type" content="text/html;
        charset=ISO-8859-1">
      <meta name="Generator" content="Microsoft Word 15 (filtered
        medium)">
      <style><!--
/* Font Definitions */
@font-face
	{font-family:"Cambria Math";
	panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
	{font-family:Calibri;
	panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
	{font-family:Consolas;
	panose-1:2 11 6 9 2 2 4 3 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
	{margin:0in;
	margin-bottom:.0001pt;
	font-size:11.0pt;
	font-family:"Calibri","sans-serif";}
a:link, span.MsoHyperlink
	{mso-style-priority:99;
	color:#0563C1;
	text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
	{mso-style-priority:99;
	color:#954F72;
	text-decoration:underline;}
p.MsoPlainText, li.MsoPlainText, div.MsoPlainText
	{mso-style-priority:99;
	mso-style-link:"Plain Text Char";
	margin:0in;
	margin-bottom:.0001pt;
	font-size:11.0pt;
	font-family:"Calibri","sans-serif";}
p.MsoListParagraph, li.MsoListParagraph, div.MsoListParagraph
	{mso-style-priority:34;
	margin-top:0in;
	margin-right:0in;
	margin-bottom:0in;
	margin-left:.5in;
	margin-bottom:.0001pt;
	font-size:11.0pt;
	font-family:"Calibri","sans-serif";}
span.PlainTextChar
	{mso-style-name:"Plain Text Char";
	mso-style-priority:99;
	mso-style-link:"Plain Text";
	font-family:"Calibri","sans-serif";}
span.EmailStyle19
	{mso-style-type:personal;
	font-family:"Calibri","sans-serif";
	color:windowtext;}
.MsoChpDefault
	{mso-style-type:export-only;
	font-family:"Calibri","sans-serif";}
@page WordSection1
	{size:8.5in 11.0in;
	margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
	{page:WordSection1;}
/* List Definitions */
@list l0
	{mso-list-id:345599468;
	mso-list-type:hybrid;
	mso-list-template-ids:-1148807360 67698705 67698713 67698715 67698703 67698713 67698715 67698703 67698713 67698715;}
@list l0:level1
	{mso-level-text:"%1\)";
	mso-level-tab-stop:none;
	mso-level-number-position:left;
	text-indent:-.25in;}
@list l0:level2
	{mso-level-number-format:alpha-lower;
	mso-level-tab-stop:none;
	mso-level-number-position:left;
	text-indent:-.25in;}
@list l0:level3
	{mso-level-number-format:roman-lower;
	mso-level-tab-stop:none;
	mso-level-number-position:right;
	text-indent:-9.0pt;}
@list l0:level4
	{mso-level-tab-stop:none;
	mso-level-number-position:left;
	text-indent:-.25in;}
@list l0:level5
	{mso-level-number-format:alpha-lower;
	mso-level-tab-stop:none;
	mso-level-number-position:left;
	text-indent:-.25in;}
@list l0:level6
	{mso-level-number-format:roman-lower;
	mso-level-tab-stop:none;
	mso-level-number-position:right;
	text-indent:-9.0pt;}
@list l0:level7
	{mso-level-tab-stop:none;
	mso-level-number-position:left;
	text-indent:-.25in;}
@list l0:level8
	{mso-level-number-format:alpha-lower;
	mso-level-tab-stop:none;
	mso-level-number-position:left;
	text-indent:-.25in;}
@list l0:level9
	{mso-level-number-format:roman-lower;
	mso-level-tab-stop:none;
	mso-level-number-position:right;
	text-indent:-9.0pt;}
@list l1
	{mso-list-id:827478655;
	mso-list-type:hybrid;
	mso-list-template-ids:-852704138 67698705 67698713 67698715 67698703 67698713 67698715 67698703 67698713 67698715;}
@list l1:level1
	{mso-level-text:"%1\)";
	mso-level-tab-stop:none;
	mso-level-number-position:left;
	margin-left:.25in;
	text-indent:-.25in;}
@list l1:level2
	{mso-level-number-format:alpha-lower;
	mso-level-tab-stop:none;
	mso-level-number-position:left;
	margin-left:.75in;
	text-indent:-.25in;}
@list l1:level3
	{mso-level-number-format:roman-lower;
	mso-level-tab-stop:none;
	mso-level-number-position:right;
	margin-left:1.25in;
	text-indent:-9.0pt;}
@list l1:level4
	{mso-level-tab-stop:none;
	mso-level-number-position:left;
	margin-left:1.75in;
	text-indent:-.25in;}
@list l1:level5
	{mso-level-number-format:alpha-lower;
	mso-level-tab-stop:none;
	mso-level-number-position:left;
	margin-left:2.25in;
	text-indent:-.25in;}
@list l1:level6
	{mso-level-number-format:roman-lower;
	mso-level-tab-stop:none;
	mso-level-number-position:right;
	margin-left:2.75in;
	text-indent:-9.0pt;}
@list l1:level7
	{mso-level-tab-stop:none;
	mso-level-number-position:left;
	margin-left:3.25in;
	text-indent:-.25in;}
@list l1:level8
	{mso-level-number-format:alpha-lower;
	mso-level-tab-stop:none;
	mso-level-number-position:left;
	margin-left:3.75in;
	text-indent:-.25in;}
@list l1:level9
	{mso-level-number-format:roman-lower;
	mso-level-tab-stop:none;
	mso-level-number-position:right;
	margin-left:4.25in;
	text-indent:-9.0pt;}
ol
	{margin-bottom:0in;}
ul
	{margin-bottom:0in;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]-->
      <div class="WordSection1">
        <p class="MsoPlainText">I totally agree bit I'm just not seeing
          the peer-2-peer in the current use case document.<o:p></o:p></p>
        <p class="MsoPlainText"><o:p>&nbsp;</o:p></p>
        <p class="MsoListParagraph"
          style="margin-left:.25in;text-indent:-.25in;mso-list:l1 level1
          lfo1">
          <!--[if !supportLists]--><span style="color:#1F497D"><span
              style="mso-list:Ignore">1)<span style="font:7.0pt
                &quot;Times New Roman&quot;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
              </span></span></span><!--[endif]--><span
            style="color:#1F497D">High-end devices (I&#8217;m defining
            high-end as capable of TLS).&nbsp; Scenario is : the device, like
            an industrial pump, presents an identity proof to a gateway
            service, the service verifies the proof and authenticates
            the device. Once authenticated, the device can upload
            telemetry information, query for information, receive
            notifications and/or receive commands. &nbsp;We&nbsp; can accomplish
            this today with the OAuth 2.0 assertion profile, with client
            acting as itself, sending a signed assertion to the gateway.
            The key is pre-provisioned on the device at the manufacture.<o:p></o:p></span></p>
        <p class="MsoListParagraph"
          style="margin-left:.75in;text-indent:-.25in;mso-list:l1 level2
          lfo1">
          <!--[if !supportLists]--><span style="color:#1F497D"><span
              style="mso-list:Ignore">a.<span style="font:7.0pt
                &quot;Times New Roman&quot;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
              </span></span></span><!--[endif]--><span
            style="color:#1F497D">The first scenario is to improve on
            the above. Specific areas of improvement<o:p></o:p></span></p>
        <p class="MsoListParagraph"
          style="margin-left:1.25in;text-indent:-1.25in;mso-text-indent-alt:-9.0pt;mso-list:l1
          level3 lfo1">
          <!--[if !supportLists]--><span style="color:#1F497D"><span
              style="mso-list:Ignore"><span style="font:7.0pt
                &quot;Times New Roman&quot;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
              </span>i.<span style="font:7.0pt &quot;Times New
                Roman&quot;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span></span><!--[endif]--><span
            style="color:#1F497D">Lighter weight protocol, reduced
            amount of bytes sent on the wire, and reduced cpu cycles on
            the device.<o:p></o:p></span></p>
        <p class="MsoListParagraph"
          style="margin-left:1.25in;text-indent:-1.25in;mso-text-indent-alt:-9.0pt;mso-list:l1
          level3 lfo1">
          <!--[if !supportLists]--><span style="color:#1F497D"><span
              style="mso-list:Ignore"><span style="font:7.0pt
                &quot;Times New Roman&quot;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
              </span>ii.<span style="font:7.0pt &quot;Times New
                Roman&quot;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span></span><!--[endif]--><span
            style="color:#1F497D">Address mid-range devices (that have
            TCP/IP stack but no TLS built in). One candidate that is
            being looked at is TKS PKS, to allow a shared symmetric key
            to be used to enable transport level security.<o:p></o:p></span></p>
        <p class="MsoListParagraph"
          style="margin-left:.25in;text-indent:-.25in;mso-list:l1 level1
          lfo1">
          <!--[if !supportLists]--><span style="color:#1F497D"><span
              style="mso-list:Ignore">2)<span style="font:7.0pt
                &quot;Times New Roman&quot;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
              </span></span></span><!--[endif]--><span
            style="color:#1F497D">Secret provisioning is another
            important problem to solve. Scenario is : I bring home my
            new thermostat and want to associate it with my account, how
            is it paired? Later when I sell my house, how to I transfer
            ownership of the thermostat? The most common pattern seems
            to be having the user get a code from the device, enter it
            in a pc, than acknowledge the pairing from the device. There
            are similar patterns for mid-range devices without displays
            (like
            <a moz-do-not-send="true" href="https://www.spark.io/">https://www.spark.io/</a>),
            they have a photo resistor, that literally let a phone app
            flash a code to the device to complete the pairing.
            Provisioning protocol, should allow for various ways to
            communicate keys.<o:p></o:p></span></p>
        <p class="MsoNormal"><span style="color:#1F497D"><o:p>&nbsp;</o:p></span></p>
        <p class="MsoNormal"><span style="color:#1F497D">Some
            Interesting consumer scenarios might be:<o:p></o:p></span></p>
        <p class="MsoListParagraph"
          style="text-indent:-.25in;mso-list:l0 level1 lfo2"><!--[if !supportLists]--><span
            style="color:#1F497D"><span style="mso-list:Ignore">1)<span
                style="font:7.0pt &quot;Times New Roman&quot;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
              </span></span></span><!--[endif]--><span
            style="color:#1F497D">When I install a new light bulb, how
            does my wife get access to control it from her phone? This
            should be seamless, since there can&#8217;t be an onboarding
            experience for everything I bring into the home.<o:p></o:p></span></p>
        <p class="MsoListParagraph"
          style="text-indent:-.25in;mso-list:l0 level1 lfo2"><!--[if !supportLists]--><span
            style="color:#1F497D"><span style="mso-list:Ignore">2)<span
                style="font:7.0pt &quot;Times New Roman&quot;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
              </span></span></span><!--[endif]--><span
            style="color:#1F497D">If somebody sides a malicious &#8220;puck&#8221;
            device under my door, what keeps it from joining the other
            things in the home and attacking the house.<o:p></o:p></span></p>
        <p class="MsoListParagraph"
          style="text-indent:-.25in;mso-list:l0 level1 lfo2"><!--[if !supportLists]--><span
            style="color:#1F497D"><span style="mso-list:Ignore">3)<span
                style="font:7.0pt &quot;Times New Roman&quot;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
              </span></span></span><!--[endif]--><span
            style="color:#1F497D">If I have guests and I want to give
            control of some parts of my home, how is that done? Use of
            proximity is one interesting idea I&#8217;ve heard here, if you
            are in my house you can turn lights on and off.<o:p></o:p></span></p>
        <p class="MsoPlainText"><o:p>&nbsp;</o:p></p>
        <p class="MsoPlainText"><a moz-do-not-send="true"
            name="_MailEndCompose"><o:p>&nbsp;</o:p></a></p>
        <p class="MsoPlainText">-----Original Message-----<br>
          From: Dorothy Gellert [<a class="moz-txt-link-freetext" href="mailto:dgellert@silverspringnet.com">mailto:dgellert@silverspringnet.com</a>] <br>
          Sent: Tuesday, July 29, 2014 4:15 PM<br>
          To: Anthony Nadalin; Ludwig Seitz; <a class="moz-txt-link-abbreviated" href="mailto:ace@ietf.org">ace@ietf.org</a><br>
          Subject: Re: [Ace] Use Case draft</p>
        <p class="MsoPlainText"><o:p>&nbsp;</o:p></p>
        <p class="MsoPlainText">Hi Anthony-<o:p></o:p></p>
        <p class="MsoPlainText"><o:p>&nbsp;</o:p></p>
        <p class="MsoPlainText">We should consider both device to cloud
          and peer to peer - otherwise the protocol will have design in
          preventive measures against unsupported deployment models.
          <o:p></o:p></p>
        <p class="MsoPlainText"><o:p>&nbsp;</o:p></p>
        <p class="MsoPlainText">Best Regards,<o:p></o:p></p>
        <p class="MsoPlainText">Dorothy Gellert<o:p></o:p></p>
        <p class="MsoPlainText">Silver Spring Networks<o:p></o:p></p>
        <p class="MsoPlainText">Director, Standards and Technology<o:p></o:p></p>
        <p class="MsoPlainText">E <a moz-do-not-send="true"
            href="mailto:dgellert@silverspringnet.com"><span
              style="color:windowtext;text-decoration:none">dgellert@silverspringnet.com</span></a><o:p></o:p></p>
        <p class="MsoPlainText">O +1 650 839 4378<o:p></o:p></p>
        <p class="MsoPlainText">C +1 650 556-5994<o:p></o:p></p>
        <p class="MsoPlainText"><o:p>&nbsp;</o:p></p>
        <p class="MsoPlainText"><o:p>&nbsp;</o:p></p>
        <p class="MsoPlainText"><o:p>&nbsp;</o:p></p>
        <p class="MsoPlainText">On 7/29/14, 9:37 AM, "Anthony Nadalin"
          &lt;<a moz-do-not-send="true"
            href="mailto:tonynad@microsoft.com"><span
              style="color:windowtext;text-decoration:none">tonynad@microsoft.com</span></a>&gt;
          wrote:<o:p></o:p></p>
        <p class="MsoPlainText"><o:p>&nbsp;</o:p></p>
        <p class="MsoPlainText">&gt;So it looks like the use cases so
          far are more geared toward device to
          <o:p></o:p></p>
        <p class="MsoPlainText">&gt;cloud, with a central cloud service
          that provides orchestration between
          <o:p></o:p></p>
        <p class="MsoPlainText">&gt;devices and not towards peer to peer
          and on-prem services ?<o:p></o:p></p>
        <p class="MsoPlainText">&gt;<o:p>&nbsp;</o:p></p>
        <p class="MsoPlainText">&gt;-----Original Message-----<o:p></o:p></p>
        <p class="MsoPlainText">&gt;From: Ace [<a moz-do-not-send="true"
            href="mailto:ace-bounces@ietf.org"><span
              style="color:windowtext;text-decoration:none">mailto:ace-bounces@ietf.org</span></a>]
          On Behalf Of Ludwig Seitz<o:p></o:p></p>
        <p class="MsoPlainText">&gt;Sent: Tuesday, July 29, 2014 1:02 AM<o:p></o:p></p>
        <p class="MsoPlainText">&gt;To: <a moz-do-not-send="true"
            href="mailto:ace@ietf.org"><span
              style="color:windowtext;text-decoration:none">ace@ietf.org</span></a><o:p></o:p></p>
        <p class="MsoPlainText">&gt;Subject: Re: [Ace] Use Case draft<o:p></o:p></p>
        <p class="MsoPlainText">&gt;<o:p>&nbsp;</o:p></p>
        <p class="MsoPlainText">&gt;On 07/28/2014 10:29 PM, Kathleen
          Moriarty wrote:<o:p></o:p></p>
        <p class="MsoPlainText">&gt;&gt; Hello,<o:p></o:p></p>
        <p class="MsoPlainText">&gt;&gt;<o:p>&nbsp;</o:p></p>
        <p class="MsoPlainText">&gt;&gt; I had read through the draft
          before the meeting and noted that in
          <o:p></o:p></p>
        <p class="MsoPlainText">&gt;&gt; section 2.2.1, I thought the
          roles of the people involved in the use
          <o:p></o:p></p>
        <p class="MsoPlainText">&gt;&gt; case were distracting.&nbsp;
          Changing this may help keep people focused on
          <o:p></o:p></p>
        <p class="MsoPlainText">&gt;&gt; the scenario as opposed to
          details that don't matter for ACE.&nbsp; FYI -
          <o:p></o:p></p>
        <p class="MsoPlainText">&gt;&gt; A single woman letting an
          acquaintance into her home without her
          <o:p></o:p></p>
        <p class="MsoPlainText">&gt;&gt; there would be unusual.&nbsp; Most
          women would not do that for safety reasons.<o:p></o:p></p>
        <p class="MsoPlainText">&gt;&gt; The interpretation of
          acquaintance may vary between regions, but for
          <o:p></o:p></p>
        <p class="MsoPlainText">&gt;&gt; me, an acquaintance is someone
          I don't really know well.&nbsp; If you make
          <o:p></o:p></p>
        <p class="MsoPlainText">&gt;&gt; Jeffrey her brother, or switch
          the roles of Jeffrey &amp; Jane, the
          <o:p></o:p></p>
        <p class="MsoPlainText">&gt;&gt; scenario is much more plausible
          and will help to prevent people from
          <o:p></o:p></p>
        <p class="MsoPlainText">&gt;&gt; getting distracted while
          reading this scenario.<o:p></o:p></p>
        <p class="MsoPlainText">&gt;&gt;<o:p>&nbsp;</o:p></p>
        <p class="MsoPlainText">&gt;I'll update this in the next version
          if we don't change the use case
          <o:p></o:p></p>
        <p class="MsoPlainText">&gt;entirely.<o:p></o:p></p>
        <p class="MsoPlainText">&gt;<o:p>&nbsp;</o:p></p>
        <p class="MsoPlainText">&gt;&gt; In reading through the draft, I
          noticed a few things missing from the
          <o:p></o:p></p>
        <p class="MsoPlainText">&gt;&gt; Security Requirements section
          that could be helpful for the next
          <o:p></o:p></p>
        <p class="MsoPlainText">&gt;&gt; editorial pass.&nbsp; If there were
          reasons they were not included, please
          <o:p></o:p></p>
        <p class="MsoPlainText">&gt;&gt; let me know.<o:p></o:p></p>
        <p class="MsoPlainText">&gt;&gt;<o:p>&nbsp;</o:p></p>
        <p class="MsoPlainText">&gt;&gt; 1. Threats such as session
          intercept/hijacking or monitoring are not
          <o:p></o:p></p>
        <p class="MsoPlainText">&gt;&gt; covered yet.<o:p></o:p></p>
        <p class="MsoPlainText">&gt;<o:p>&nbsp;</o:p></p>
        <p class="MsoPlainText">&gt;The idea of this draft was to cover
          issues concerning authentication
          <o:p></o:p></p>
        <p class="MsoPlainText">&gt;and authorization (and a few&nbsp;
          directly related issues) since that is
          <o:p></o:p></p>
        <p class="MsoPlainText">&gt;the topic of ACE. I think the
          problems you mention above are not
          <o:p></o:p></p>
        <p class="MsoPlainText">&gt;directly relevant for ACE, therefore
          I left them out of the document.<o:p></o:p></p>
        <p class="MsoPlainText">&gt;<o:p>&nbsp;</o:p></p>
        <p class="MsoPlainText">&gt;&gt;<o:p>&nbsp;</o:p></p>
        <p class="MsoPlainText">&gt;&gt; 2. Logging, protection of logs
          (and purging) is mentioned in one of
          <o:p></o:p></p>
        <p class="MsoPlainText">&gt;&gt; the use cases, but not in the
          security section.&nbsp; This would be a good
          <o:p></o:p></p>
        <p class="MsoPlainText">&gt;&gt; addition, but should also
          include privacy considerations associated
          <o:p></o:p></p>
        <p class="MsoPlainText">&gt;&gt; with the logs as well
          (correlation of events, etc.).<o:p></o:p></p>
        <p class="MsoPlainText">&gt;<o:p>&nbsp;</o:p></p>
        <p class="MsoPlainText">&gt;We had a discussion about Auditing
          (the third A of AAA) and logging
          <o:p></o:p></p>
        <p class="MsoPlainText">&gt;during the chartering process, and
          some people thought it would make
          <o:p></o:p></p>
        <p class="MsoPlainText">&gt;the focus of the group too broad to
          try and also cover Auditing
          <o:p></o:p></p>
        <p class="MsoPlainText">&gt;(including logging).<o:p></o:p></p>
        <p class="MsoPlainText">&gt;<o:p>&nbsp;</o:p></p>
        <p class="MsoPlainText">&gt;Therefore I have left out questions
          of auditing (and privacy) for the
          <o:p></o:p></p>
        <p class="MsoPlainText">&gt;moment.<o:p></o:p></p>
        <p class="MsoPlainText">&gt;<o:p>&nbsp;</o:p></p>
        <p class="MsoPlainText">&gt;<o:p>&nbsp;</o:p></p>
        <p class="MsoPlainText">&gt;&gt;<o:p>&nbsp;</o:p></p>
        <p class="MsoPlainText">&gt;&gt; 3. There will also be a number
          of privacy considerations that should
          <o:p></o:p></p>
        <p class="MsoPlainText">&gt;&gt; be noted in this section or one
          on privacy.&nbsp; This might include
          <o:p></o:p></p>
        <p class="MsoPlainText">&gt;&gt; concerns of being able to
          profile habits of a person or other similar concerns.<o:p></o:p></p>
        <p class="MsoPlainText">&gt;&gt;<o:p>&nbsp;</o:p></p>
        <p class="MsoPlainText">&gt;<o:p>&nbsp;</o:p></p>
        <p class="MsoPlainText">&gt;See above.<o:p></o:p></p>
        <p class="MsoPlainText">&gt;<o:p>&nbsp;</o:p></p>
        <p class="MsoPlainText">&gt;<o:p>&nbsp;</o:p></p>
        <p class="MsoPlainText">&gt;<o:p>&nbsp;</o:p></p>
        <p class="MsoPlainText">&gt;Regards,<o:p></o:p></p>
        <p class="MsoPlainText">&gt;<o:p>&nbsp;</o:p></p>
        <p class="MsoPlainText">&gt;Ludwig Seitz<o:p></o:p></p>
        <p class="MsoPlainText">&gt;<o:p>&nbsp;</o:p></p>
        <p class="MsoPlainText">&gt;<o:p>&nbsp;</o:p></p>
        <p class="MsoPlainText">&gt;--<o:p></o:p></p>
        <p class="MsoPlainText">&gt;Ludwig Seitz, PhD<o:p></o:p></p>
        <p class="MsoPlainText">&gt;SICS Swedish ICT AB<o:p></o:p></p>
        <p class="MsoPlainText">&gt;Ideon Science Park<o:p></o:p></p>
        <p class="MsoPlainText">&gt;Building Beta 2<o:p></o:p></p>
        <p class="MsoPlainText">&gt;Scheelev&auml;gen 17<o:p></o:p></p>
        <p class="MsoPlainText">&gt;SE-223 70 Lund<o:p></o:p></p>
        <p class="MsoPlainText">&gt;<o:p>&nbsp;</o:p></p>
        <p class="MsoPlainText">&gt;Phone +46(0)70-349 92 51<o:p></o:p></p>
        <p class="MsoPlainText">&gt;<a moz-do-not-send="true"
            href="http://www.sics.se"><span
              style="color:windowtext;text-decoration:none">http://www.sics.se</span></a><o:p></o:p></p>
        <p class="MsoPlainText">&gt;<o:p>&nbsp;</o:p></p>
        <p class="MsoPlainText">&gt;_______________________________________________<o:p></o:p></p>
        <p class="MsoPlainText">&gt;Ace mailing list<o:p></o:p></p>
        <p class="MsoPlainText">&gt;<a moz-do-not-send="true"
            href="mailto:Ace@ietf.org"><span
              style="color:windowtext;text-decoration:none">Ace@ietf.org</span></a><o:p></o:p></p>
        <p class="MsoPlainText">&gt;<a moz-do-not-send="true"
            href="https://www.ietf.org/mailman/listinfo/ace"><span
              style="color:windowtext;text-decoration:none">https://www.ietf.org/mailman/listinfo/ace</span></a><o:p></o:p></p>
        <p class="MsoPlainText"><o:p>&nbsp;</o:p></p>
      </div>
    </blockquote>
    <br>
  </body>
</html>

--------------000205020403000905010702--

