From mailnull@www1.ietf.org  Wed May  7 07:26:49 2003
Received: from www1.ietf.org (ietf.org [132.151.1.19] (may be forged))
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id HAA24255
	for <rpsec-archive@odin.ietf.org>; Wed, 7 May 2003 07:26:49 -0400 (EDT)
Received: (from mailnull@localhost)
	by www1.ietf.org (8.11.6/8.11.6) id h47BZks05828
	for rpsec-archive@odin.ietf.org; Wed, 7 May 2003 07:35:46 -0400
Received: from ietf.org (odin.ietf.org [132.151.1.176])
	by www1.ietf.org (8.11.6/8.11.6) with ESMTP id h47BZk805825
	for <rpsec-web-archive@optimus.ietf.org>; Wed, 7 May 2003 07:35:46 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id HAA24211
	for <rpsec-web-archive@ietf.org>; Wed, 7 May 2003 07:26:19 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1])
	by ietf-mx with esmtp (Exim 4.12)
	id 19DN5z-0007Ot-00
	for rpsec-web-archive@ietf.org; Wed, 07 May 2003 07:28:23 -0400
Received: from ietf.org ([132.151.1.19] helo=www1.ietf.org)
	by ietf-mx with esmtp (Exim 4.12)
	id 19DN5y-0007Op-00
	for rpsec-web-archive@ietf.org; Wed, 07 May 2003 07:28:22 -0400
Received: from www1.ietf.org (localhost.localdomain [127.0.0.1])
	by www1.ietf.org (8.11.6/8.11.6) with ESMTP id h47BZ1805644;
	Wed, 7 May 2003 07:35:01 -0400
Received: from ietf.org (odin.ietf.org [132.151.1.176])
	by www1.ietf.org (8.11.6/8.11.6) with ESMTP id h47BOU805094
	for <rpsec@optimus.ietf.org>; Wed, 7 May 2003 07:24:30 -0400
Received: from CNRI.Reston.VA.US (localhost [127.0.0.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id HAA23762;
	Wed, 7 May 2003 07:15:03 -0400 (EDT)
Message-Id: <200305071115.HAA23762@ietf.org>
Mime-Version: 1.0
Content-Type: Multipart/Mixed; Boundary="NextPart"
To: IETF-Announce: ;
Cc: rpsec@ietf.org
From: Internet-Drafts@ietf.org
Reply-to: Internet-Drafts@ietf.org
Date: Wed, 07 May 2003 07:15:03 -0400
Subject: [RPSEC] I-D ACTION:draft-ietf-rpsec-routing-threats-01.txt
Sender: rpsec-admin@ietf.org
Errors-To: rpsec-admin@ietf.org
X-BeenThere: rpsec@ietf.org
X-Mailman-Version: 2.0.12
Precedence: bulk
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/rpsec>,
	<mailto:rpsec-request@ietf.org?subject=unsubscribe>
List-Id: Routing Protocol Security Requirements  <rpsec.ietf.org>
List-Post: <mailto:rpsec@ietf.org>
List-Help: <mailto:rpsec-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/rpsec>,
	<mailto:rpsec-request@ietf.org?subject=subscribe>

--NextPart

A New Internet-Draft is available from the on-line Internet-Drafts directories.
This draft is a work item of the Routing Protocol Security Requirements Working Group of the IETF.

	Title		: Generic Threats to Routing Protocols
	Author(s)	: A. Barbir, S. Murphy, Y. Yang
	Filename	: draft-ietf-rpsec-routing-threats-01.txt
	Pages		: 26
	Date		: 2003-5-6
	
Routing protocols are subject to attacks that can harm individual
users or the network operations as a whole. This document provides a
description and a summary of generic threats that affects routing
protocols in general. The work describes threats, including threat
sources and capabilities, threat actions, and threat consequences as
well as a breakdown of routing functions that might be separately
attacked.

A URL for this Internet-Draft is:
http://www.ietf.org/internet-drafts/draft-ietf-rpsec-routing-threats-01.txt

To remove yourself from the IETF Announcement list, send a message to 
ietf-announce-request with the word unsubscribe in the body of the message.

Internet-Drafts are also available by anonymous FTP. Login with the username
"anonymous" and a password of your e-mail address. After logging in,
type "cd internet-drafts" and then
	"get draft-ietf-rpsec-routing-threats-01.txt".

A list of Internet-Drafts directories can be found in
http://www.ietf.org/shadow.html 
or ftp://ftp.ietf.org/ietf/1shadow-sites.txt


Internet-Drafts can also be obtained by e-mail.

Send a message to:
	mailserv@ietf.org.
In the body type:
	"FILE /internet-drafts/draft-ietf-rpsec-routing-threats-01.txt".
	
NOTE:	The mail server at ietf.org can return the document in
	MIME-encoded form by using the "mpack" utility.  To use this
	feature, insert the command "ENCODING mime" before the "FILE"
	command.  To decode the response(s), you will need "munpack" or
	a MIME-compliant mail reader.  Different MIME-compliant mail readers
	exhibit different behavior, especially when dealing with
	"multipart" MIME messages (i.e. documents which have been split
	up into multiple messages), so check your local documentation on
	how to manipulate these messages.
		
		
Below is the data which will enable a MIME compliant mail reader
implementation to automatically retrieve the ASCII version of the
Internet-Draft.

--NextPart
Content-Type: Multipart/Alternative; Boundary="OtherAccess"

--OtherAccess
Content-Type: Message/External-body;
	access-type="mail-server";
	server="mailserv@ietf.org"

Content-Type: text/plain
Content-ID:	<2003-5-6153413.I-D@ietf.org>

ENCODING mime
FILE /internet-drafts/draft-ietf-rpsec-routing-threats-01.txt

--OtherAccess
Content-Type: Message/External-body;
	name="draft-ietf-rpsec-routing-threats-01.txt";
	site="ftp.ietf.org";
	access-type="anon-ftp";
	directory="internet-drafts"

Content-Type: text/plain
Content-ID:	<2003-5-6153413.I-D@ietf.org>

--OtherAccess--

--NextPart--


_______________________________________________
RPSEC mailing list
RPSEC@ietf.org
https://www1.ietf.org/mailman/listinfo/rpsec



From mailnull@www1.ietf.org  Mon May 12 07:49:35 2003
Received: from www1.ietf.org (ietf.org [132.151.1.19] (may be forged))
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id HAA09291
	for <rpsec-archive@odin.ietf.org>; Mon, 12 May 2003 07:49:35 -0400 (EDT)
Received: (from mailnull@localhost)
	by www1.ietf.org (8.11.6/8.11.6) id h4CBF6W19170
	for rpsec-archive@odin.ietf.org; Mon, 12 May 2003 07:15:06 -0400
Received: from ietf.org (odin.ietf.org [132.151.1.176])
	by www1.ietf.org (8.11.6/8.11.6) with ESMTP id h4CBF6B19167
	for <rpsec-web-archive@optimus.ietf.org>; Mon, 12 May 2003 07:15:06 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id HAA09282
	for <rpsec-web-archive@ietf.org>; Mon, 12 May 2003 07:49:04 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1])
	by ietf-mx with esmtp (Exim 4.12)
	id 19FBpf-00073q-00
	for rpsec-web-archive@ietf.org; Mon, 12 May 2003 07:51:03 -0400
Received: from ietf.org ([132.151.1.19] helo=www1.ietf.org)
	by ietf-mx with esmtp (Exim 4.12)
	id 19FBpf-00073m-00
	for rpsec-web-archive@ietf.org; Mon, 12 May 2003 07:51:03 -0400
Received: from www1.ietf.org (localhost.localdomain [127.0.0.1])
	by www1.ietf.org (8.11.6/8.11.6) with ESMTP id h4CBEHB19114;
	Mon, 12 May 2003 07:14:17 -0400
Received: from ietf.org (odin.ietf.org [132.151.1.176])
	by www1.ietf.org (8.11.6/8.11.6) with ESMTP id h4CBDhB19090
	for <rpsec@optimus.ietf.org>; Mon, 12 May 2003 07:13:44 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id HAA09250
	for <rpsec@ietf.org>; Mon, 12 May 2003 07:47:42 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1])
	by ietf-mx with esmtp (Exim 4.12)
	id 19FBoL-00073P-00
	for rpsec@ietf.org; Mon, 12 May 2003 07:49:41 -0400
Received: from rtp-core-1.cisco.com ([64.102.124.12])
	by ietf-mx with esmtp (Exim 4.12)
	id 19FBoK-00073I-00
	for rpsec@ietf.org; Mon, 12 May 2003 07:49:40 -0400
Received: from cisco.com (uzura.cisco.com [64.102.17.77])
	by rtp-core-1.cisco.com (8.12.6/8.12.6) with ESMTP id h4CBoBtr009921
	for <rpsec@ietf.org>; Mon, 12 May 2003 07:50:12 -0400 (EDT)
Received: from russpc (rtp-vpn1-223.cisco.com [10.82.224.223])
	by cisco.com (8.8.8/2.6/Cisco List Logging/8.8.8) with ESMTP id HAA08085
	for <rpsec@ietf.org>; Mon, 12 May 2003 07:46:37 -0400 (EDT)
Date: Mon, 12 May 2003 07:46:36 -0400 (Eastern Daylight Time)
From: Russ White <ruwhite@cisco.com>
Reply-To: Russ White <riw@cisco.com>
To: rpsec@ietf.org
Message-ID: <Pine.WNT.4.53.0305120745540.3348@russpc>
X-X-Sender: ruwhite@uzura.cisco.com
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; charset=US-ASCII
Subject: [RPSEC] Meeting Time in Australia?
Sender: rpsec-admin@ietf.org
Errors-To: rpsec-admin@ietf.org
X-BeenThere: rpsec@ietf.org
X-Mailman-Version: 2.0.12
Precedence: bulk
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/rpsec>,
	<mailto:rpsec-request@ietf.org?subject=unsubscribe>
List-Id: Routing Protocol Security Requirements  <rpsec.ietf.org>
List-Post: <mailto:rpsec@ietf.org>
List-Help: <mailto:rpsec-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/rpsec>,
	<mailto:rpsec-request@ietf.org?subject=subscribe>

Y'all:

Should we meet in Australia? What agenda items do we have besides the new
threats draft?

:-)

Russ

__________________________________
riw@cisco.com CCIE <>< Grace Alone

_______________________________________________
RPSEC mailing list
RPSEC@ietf.org
https://www1.ietf.org/mailman/listinfo/rpsec



From mailnull@www1.ietf.org  Mon May 12 08:21:04 2003
Received: from www1.ietf.org (ietf.org [132.151.1.19] (may be forged))
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id IAA10002
	for <rpsec-archive@odin.ietf.org>; Mon, 12 May 2003 08:21:04 -0400 (EDT)
Received: (from mailnull@localhost)
	by www1.ietf.org (8.11.6/8.11.6) id h4CBkaG21460
	for rpsec-archive@odin.ietf.org; Mon, 12 May 2003 07:46:36 -0400
Received: from ietf.org (odin.ietf.org [132.151.1.176])
	by www1.ietf.org (8.11.6/8.11.6) with ESMTP id h4CBkaB21457
	for <rpsec-web-archive@optimus.ietf.org>; Mon, 12 May 2003 07:46:36 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id IAA09982
	for <rpsec-web-archive@ietf.org>; Mon, 12 May 2003 08:20:34 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1])
	by ietf-mx with esmtp (Exim 4.12)
	id 19FCK9-0007G4-00
	for rpsec-web-archive@ietf.org; Mon, 12 May 2003 08:22:33 -0400
Received: from ietf.org ([132.151.1.19] helo=www1.ietf.org)
	by ietf-mx with esmtp (Exim 4.12)
	id 19FCK8-0007G1-00
	for rpsec-web-archive@ietf.org; Mon, 12 May 2003 08:22:32 -0400
Received: from www1.ietf.org (localhost.localdomain [127.0.0.1])
	by www1.ietf.org (8.11.6/8.11.6) with ESMTP id h4CBk7B21443;
	Mon, 12 May 2003 07:46:07 -0400
Received: from ietf.org (odin.ietf.org [132.151.1.176])
	by www1.ietf.org (8.11.6/8.11.6) with ESMTP id h4CBjmB21416
	for <rpsec@optimus.ietf.org>; Mon, 12 May 2003 07:45:48 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id IAA09966
	for <rpsec@ietf.org>; Mon, 12 May 2003 08:19:46 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1])
	by ietf-mx with esmtp (Exim 4.12)
	id 19FCJN-0007Ff-00
	for rpsec@ietf.org; Mon, 12 May 2003 08:21:45 -0400
Received: from rtp-core-1.cisco.com ([64.102.124.12])
	by ietf-mx with esmtp (Exim 4.12)
	id 19FCJM-0007Fb-00
	for rpsec@ietf.org; Mon, 12 May 2003 08:21:44 -0400
Received: from cisco.com (uzura.cisco.com [64.102.17.77])
	by rtp-core-1.cisco.com (8.12.6/8.12.6) with ESMTP id h4CCMFtr018047
	for <rpsec@ietf.org>; Mon, 12 May 2003 08:22:15 -0400 (EDT)
Received: from russpc (rtp-vpn1-223.cisco.com [10.82.224.223])
	by cisco.com (8.8.8/2.6/Cisco List Logging/8.8.8) with ESMTP id IAA09027
	for <rpsec@ietf.org>; Mon, 12 May 2003 08:22:15 -0400 (EDT)
Date: Mon, 12 May 2003 08:22:14 -0400 (Eastern Daylight Time)
From: Russ White <ruwhite@cisco.com>
Reply-To: Russ White <riw@cisco.com>
To: rpsec@ietf.org
In-Reply-To: <Pine.WNT.4.53.0305120745540.3348@russpc>
Message-ID: <Pine.WNT.4.53.0305120821560.3348@russpc>
References: <Pine.WNT.4.53.0305120745540.3348@russpc>
X-X-Sender: ruwhite@uzura.cisco.com
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; charset=US-ASCII
Subject: [RPSEC] Re: Meeting Time in Australia?
Sender: rpsec-admin@ietf.org
Errors-To: rpsec-admin@ietf.org
X-BeenThere: rpsec@ietf.org
X-Mailman-Version: 2.0.12
Precedence: bulk
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/rpsec>,
	<mailto:rpsec-request@ietf.org?subject=unsubscribe>
List-Id: Routing Protocol Security Requirements  <rpsec.ietf.org>
List-Post: <mailto:rpsec@ietf.org>
List-Help: <mailto:rpsec-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/rpsec>,
	<mailto:rpsec-request@ietf.org?subject=subscribe>


Austria, not Australia. Hey, there's just a couple of letters difference.

:-)

Russ

On Mon, 12 May 2003, Russ White wrote:

> Y'all:
>
> Should we meet in Australia? What agenda items do we have besides the new
> threats draft?
>
> :-)
>
> Russ
>
> __________________________________
> riw@cisco.com CCIE <>< Grace Alone
>
>

__________________________________
riw@cisco.com CCIE <>< Grace Alone

_______________________________________________
RPSEC mailing list
RPSEC@ietf.org
https://www1.ietf.org/mailman/listinfo/rpsec



From mailnull@www1.ietf.org  Thu May 15 10:55:55 2003
Received: from www1.ietf.org (ietf.org [132.151.1.19] (may be forged))
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id KAA11506
	for <rpsec-archive@odin.ietf.org>; Thu, 15 May 2003 10:55:55 -0400 (EDT)
Received: (from mailnull@localhost)
	by www1.ietf.org (8.11.6/8.11.6) id h4FEMwM04933
	for rpsec-archive@odin.ietf.org; Thu, 15 May 2003 10:22:58 -0400
Received: from ietf.org (odin.ietf.org [132.151.1.176])
	by www1.ietf.org (8.11.6/8.11.6) with ESMTP id h4FEMwB04930
	for <rpsec-web-archive@optimus.ietf.org>; Thu, 15 May 2003 10:22:58 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id KAA11488
	for <rpsec-web-archive@ietf.org>; Thu, 15 May 2003 10:55:24 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1])
	by ietf-mx with esmtp (Exim 4.12)
	id 19GKAY-0007kJ-00
	for rpsec-web-archive@ietf.org; Thu, 15 May 2003 10:57:18 -0400
Received: from ietf.org ([132.151.1.19] helo=www1.ietf.org)
	by ietf-mx with esmtp (Exim 4.12)
	id 19GKAY-0007kF-00
	for rpsec-web-archive@ietf.org; Thu, 15 May 2003 10:57:18 -0400
Received: from www1.ietf.org (localhost.localdomain [127.0.0.1])
	by www1.ietf.org (8.11.6/8.11.6) with ESMTP id h4FEHpB04749;
	Thu, 15 May 2003 10:17:51 -0400
Received: from ietf.org (odin.ietf.org [132.151.1.176])
	by www1.ietf.org (8.11.6/8.11.6) with ESMTP id h4FEGCB04660
	for <rpsec@optimus.ietf.org>; Thu, 15 May 2003 10:16:12 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id KAA11344
	for <rpsec@ietf.org>; Thu, 15 May 2003 10:48:39 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1])
	by ietf-mx with esmtp (Exim 4.12)
	id 19GK41-0007hv-00
	for rpsec@ietf.org; Thu, 15 May 2003 10:50:33 -0400
Received: from rtp-core-2.cisco.com ([64.102.124.13])
	by ietf-mx with esmtp (Exim 4.12)
	id 19GK40-0007hl-00
	for rpsec@ietf.org; Thu, 15 May 2003 10:50:32 -0400
Received: from cisco.com (uzura.cisco.com [64.102.17.77])
	by rtp-core-2.cisco.com (8.12.6/8.12.6) with ESMTP id h4FEpAci010034
	for <rpsec@ietf.org>; Thu, 15 May 2003 10:51:11 -0400 (EDT)
Received: from russpc (rtp-vpn1-218.cisco.com [10.82.224.218])
	by cisco.com (8.8.8/2.6/Cisco List Logging/8.8.8) with ESMTP id KAA19909
	for <rpsec@ietf.org>; Thu, 15 May 2003 10:47:25 -0400 (EDT)
Date: Thu, 15 May 2003 10:47:24 -0400 (Eastern Daylight Time)
From: Russ White <ruwhite@cisco.com>
Reply-To: Russ White <riw@cisco.com>
To: rpsec@ietf.org
Message-ID: <Pine.WNT.4.55.0305151044160.2776@russpc>
X-X-Sender: ruwhite@uzura.cisco.com
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; charset=US-ASCII
Subject: [RPSEC] Initial comments on draft-ietf-rpsec-routing-threats-01.txt
Sender: rpsec-admin@ietf.org
Errors-To: rpsec-admin@ietf.org
X-BeenThere: rpsec@ietf.org
X-Mailman-Version: 2.0.12
Precedence: bulk
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/rpsec>,
	<mailto:rpsec-request@ietf.org?subject=unsubscribe>
List-Id: Routing Protocol Security Requirements  <rpsec.ietf.org>
List-Post: <mailto:rpsec@ietf.org>
List-Help: <mailto:rpsec-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/rpsec>,
	<mailto:rpsec-request@ietf.org?subject=subscribe>


Below are some initial thoughts on the most recent version of the draft. I
still have some philosophical differences of opinion on the definitions and
terms we are using here, for instancde "routing protocol" vs "routing
system." I think we should adopt a narrow definition of "routing system"
and use this term, rather than using the term "routing protocol" to refer
to things outside the protocol, such as topology information.

Anyway, thoughts below the sig.

:-)

Russ
__________________________________
riw@cisco.com CCIE <>< Grace Alone

-----


First general comment: Let's get past peering, neighbor relationships,
and adjacencies. Let's try to use one term to describe all three, even
though routing protocols use all three. I think "adjacent" and "peers"
are clearer, more precise terms than "neighbors," so I'd probably
prefer that we use one of these two. Of course, "adjacent" implies
physical connectivity, which isn't always true, so perhaps we should
go with "peers," although that can have too many bgp implications (?).

I've used "peering" throughout my comments.

-----

   Routing protocols are subject to attacks that can harm individual
   users or the network operations as a whole. This document provides a
   description and a summary of generic threats that affects routing
   protocols in general. The work describes threats, including threat
   sources and capabilities, threat actions, and threat consequences as
   well as a breakdown of routing functions that might be separately
   attacked.

Routing protocols carry information about the topology of a network
which can be used to discover the best path to any given destination
within the network. The best path may be chosen based on its cost in
terms of bandwidth, delay, hop count, or other metric signifying the
length of the path, or it may be chosen based on some set of policies
designed by the network administrator. In either case, devices which
forward traffic (routers), using information and algorithms provided
by routing protocols, can make intelligent decisions when forwarding
traffic from one port to another.

Routing protocols, then are vulnerable to attacks against the
transportation of topology data, and attacks against the validity of
the topology data carried. This document describes the vulnerabilities
of routing protocols, including how they can be attacked in one of
these two areas, and how such attacks can be used to disrupt or
otherwise harm individual use of the network's resources, or force a
failure in the network denying the use of the network's resources in
general.

This work describes such attack methods in terms of threats, including
threat sources and capabilities, threat actions, and threat
consequences.

-----

1. Introduction

   individual users or the network operations as a whole. The document
                                                          ^^^
/This

-----

   The work should be considered as a precursor to developing a common
   ^^^^^^^^

Either replace "The work" with "This work," or, more simply, "It,"
since you're talking about this document in the entire intro, and
there's no real reason to repeat it.

-----

   the document does not address threats to routers such as hacking,

Same thing here.

-----

   denial of service, flooding attacks and others. The document does not
   consider threats that result from bad implementations that are
   related to specific routing.  The security requirements derived from
   this threat analysis are intended to be used as guidance to those who
   are designing routing protocols.

While its well known that bad, incomplete, or poor implementations of
routing protocols may, in themselves, lead to routing problems or
failures, or may increase the risk of a network being attacked
successfully, these issues are not considered here. This document only
considers attacks against robust, well considered implementations of
routing protocols, as outlined in [OSPF], [IS-IS], [RIP], and [BGP].

(provide references for the above)

The security requirements derived from this analysis are intended to
be used as guidance to those who are designing and modifying routing
protocols. They may also be used by routing protocol implementors to
increase the robustness of their impmementations.

(I'm not certain about this last sentence--what does the list think?)

-----

2. Routing Functions Overview

I'd drop the bulleted list, replacing it with subsections, and fill in
more examples and text in each area. Some possible text is given
below. I've also tried to merge in some of the information currently
in the intro just below the section 3 header, so we can eliminate it
there, in an attempt to coalesce some of the information, rather than
letting it wander around among various sections with different
examples, etc.

-----

2.1 Transport Subsystem

Routing protocols transport state and topology information over some
underlying protocol. For example, [OSPF] uses multicast and unicast IP
to carry information between routers, while [AODV] uses broadcast IP
packets. [IS-IS] uses multicast and unicast packets placed directly on
the link layer, rather than IP, to carry information.

Attacks against the transport subsystem of a routing protocol would
include attempts to hijaak the relationship between two peers,
flooding a router with packets to prevent it from forming peering
relationships properly, and (possibly) modifying the information
carried within a routing protocol packet to modify routing, or cause a
peering relationship between routers to fail.

2.2. Neighbor State Maintenance

Any pair of routers running a routing protocol will generally form a
neighbor, or peering, relationship, which can server two
purposes. Some protocols use this relationship to determine topology
information (for instance, in link state protocols, the list of
attached neighbors is advertised as part of the topology information)
and also to provide reliability in transmitting routing information
throughout a routing domain. Each routing protocol uses a different
mechanism for building these neighbor, or peering, relationships. For
instance, routers running [OSPF] will exchange hello's within a
certain state machine to discover neighboring routers.

Attacks against neighbor state maintenance could include hijaaking the
peering relationship between two routers, forcing the peering
relationship between two routers to fail, unauthorized peering in
order to inject false topology or policy information into the routing
protocol.

For instance, if an attacker could inject a false TCP RESET
notification into a session between two BGP peers, the attacker could
disrupt the propagation of routing information, and cause packets
which would otherwise be delivered to be dropped.

(You'll need a reference to the TCP spec here, and maybe a reference
to the BGP MD5 specs, since I think they talk about this attack
specifically.)

(I've changed the next section from database maintenance to topology
information origination and exchange, shortened to topology exchange.)

2.3 Topology Information Origination and Exchange

Routing protocols exchange network topology and reachability
information. Router collect this information from their neighbors or
peers, and use it to determine the best path through the network to
any (or every) given destination within the network. The correct
exchange of this topology information, and the correctness of this
topology information, is significant part of the function of a routing
protocol.

Attacks against the topology information propagated by a routing
protocol includes injecting false information. The results of
injecting this false information could be misdirecting traffic in
order to steal the contents of the packets, misdirecting traffic so it
is arbitrarily dropped at some point, forcing routing loops to occur,
and others.

-----

2.1 Routing Protocol Control and Data Planes

I think I'd drop the entire concept of control and data planes in a
routing protocol, and just use the three classifications mentioned
above, adding examples thee as needed to clarify. I really think it's
confusing to have multiple ways of classifying threats used
interchangably throughout the doc, and even intermixed in some parts.

-----

3. Generic Routing Protocol Threat Model

I think I'd avoid the use of "generic" throughout the entire doc. If
you just say: "Routing Protocols Threat Model," and leave the protocol
out, it should be assumed we are talking about all routing protocols,
and not a specific routing protocol.

-----

   This section develops a model that can be used to identify the
   threats that can affect routing protocols in general. The model
   examines the possible threats that routing protocols can be exposed
   to from unauthorized entities.

The model developed in this section can be used to identify threats to
any routing protocol. It examines attacks which can be launched
against routing from subverted entities within the routing system, and
ofrom entities outside the routing system. Both of these types of
entities are called unauthorized entities.

-----

   Routing protocols are subject to treats at the control and data
   ....
   A PIM router might transmit a JOIN message to receive multicast data
   it would otherwise not receive.

Drop all of this, as it should now be covered in section 2.

-----

3.1 Threat Definitions

   Threat is defined in [1] as a potential for violation of security,
   which exists when there is a circumstance, capability, action, or
   event that could breach security and cause harm. A threat presents
   itself when an attacker has the ability to take advantage of an
   existing security weakness.  Threats can be categorized based on

"A threat," rather than "Threat." Also, I'd use mnemonics for the
references, such as "SECDEFS" rather tha the numbers, as they are
easier for people to remember, and it makes the document easier to
read.

-----

3.1.1 Threat Sources

   There are many sources for threats that may affect routing protocols.
   In some cases, unauthorized entities such as attackers may illegally
   participate in the routing operations. In other circumstances, there
   are threats to routing protocols from entities that are running
   incorrect code, or using invalid configurations.

I think I'd just pull this paragraph. I've tried to rewrite it a
couple of times, and every time I'm either repeating something said
elsewhere, or I'm not really certain what it's supposed to say.

I also think this section needs to be more parallel, see below for
possible text.

-----

There are two axis along which the source of a threat may be
classified: whether the threat originates from an insider or an
outsider, and whether a threat originates from a subverted link, or a
subverted device.

o An isider is a device which is legally able to participate in routing.

o An outsider is a device which is not legally able to partipate in routing.

A device is classified as an insider or an outsider in reference to
the device attacked, not necessarily in the context of the network as
a whole. It is possible for a device which is normally legitimately
attached to one part of the network is moved to another location
within the network where it is no longer a legitimate member of the
routing system.

o Threats originating from a subverted link: A link is subverted when
an attacker gains access to the physcial medium in a way which allows
the attacker to receive and transmit on the link. This threat can
result from failure to use access control mechanisms or the use of
weak access control mechanisms. An attacker may listen to, replay,
delay, or drop routing messages on a subverted link, causing peering
relationships to fail, or hijaaking peering relationships, for instance.

o Threats resulting from subverted devices: A subverted device....

-----

   neighbor. For example, in OSPF (that is, before the MD5 part was
   added), OSPF speaks to all routers on the local link that answer to
   the AllSPFRouters multicast address.  Furthermore, MANET protocols
   frequently speak over the broadcast link.

For example, an OSPF router will form a peering relationship with any
attached device which appears to be running OSPF, unless MD5
authentication (or some other means) is used to prevent the peering
relationship from forming.

I'd pull the manet example, one is enough here, and reference the OSPF
MD5 draft.

-----

3.1.2 Threat Consequences

   A threat consequence is a security violation that results from a
   threat action [1]. The compromise to the behavior of the routing
   system can damage a particular network or host or can damage the
   operation of the network as a whole.

I'm not certain I understand the second sentence in this paragraph?
I'd probably just pull it, and merge the first two paragraphs.

-----

   o  Disclosure: Disclosure of routing information happens when a
      router successfully accesses the information without being
      authorized. Subverted links can cause disclosure, if routing
      exchanges lack confidentiality.  Subverted devices (routers), can
      cause disclosure, as long as they are successfully involved in the
      routing exchanges.  Although inappropriate disclosure of routing
      information can pose a security threat or be part of a later,
      larger, or higher layer attack, confidentiality is not generally a
      design goal of routing protocols.

Maybe this?

Disclosure: Information about the topology, reachable destinations,
and passwords used in a network could be disclosed through routing
protocol exchanges between two routers. Although inappropriate
disclosure of routing information can pose a security threat or
provide the basis for a larger, or higher layer, attack,
confidentiality is not generally a design goal of routing protocols.

-----

   o  Deception: This consequence happens when a legitimate router
      receives a false routing message and believes it to be true.
      Subverted links and/or subverted device (routers)can cause this
      consequence if the receiving router lacks ability  to check
      routing message integrity, routing message origin, authentication
      or peer router authentication.

Maybe:

Deception: When a router receives routing data that appears to be
valid, and modifies its topology information or peering relationships
based on this information, it has been deceived. Subverted links and
subverted devices can be used to deceive other routers. Deception is
particuarly easy if there are no mechanisms in place to validate
information received.

-----

   o  Disruption: This consequence occurs when a legitimate router's
      operation is being interrupted or prevented. Subvert links can
      cause this by replaying, delaying, or dropping routing messages,
      or breaking routing sessions between legitimate routers. Subverted
      devices (router) can cause this consequence by sending false
      routing messages, interfering normal routing exchanges, or
      flooding unnecessary messages. (DoS is a common threat action
      causing disruption.)

Maybe:

Disruption: Occurs when a router's operation is interrupted or
prevented. Attackers can use subverted links to disrupt a router's
operation by replaying, delaying, or dropping routing messages, or by
causing peering relationships between two routers to fail. Attackers
can use subverted devices to disrupt the operation of a router by
sending routing information formatted to cause the receiving router to
fail, interfering with routing exchanges between other devices on the
network, and other means.

-----

o Usurpation: ...

(Are we certain this is spelled right?)

Maybe:

o Usurpation: Occurs when an attacker gains control over a lgeitimate
router's services or functions.

I'm not certain how a subverted link dropping packets would be
considered a usurped device? Or maybe the paragraph is using bad
examples?

-----

   ....
   B to reach Network 1.  In this way, Router B steals the data traffic
   and Router A surrenders its control of the services to Router B. This
   depicted in Figure 1.
   ....

I'm not certain I actually agree with this example.... You still had
to have subverted router b, in which case the router you're using as a
"base of attack" is one you've actually subverted, taking over the
services of the router. You've usurped A, not B. You've modified the
routing information within the system to bypass the router you've not
usurped, but that doesn't equate to subverting the router you've
directed the traffic around.

In other words, you might have usurped the routing system, but you've
not usurped A at all. This is a key distinction, and one reason I
think we should always be thinking in terms of the routing system, and
not the "routing protocol."

A "routing protocol" is mearly a collection of packet formats and
algorithms, and it doesn't make much sense to attack the poor little
beast. Now, if you can attack the information carried within the
routing protocol, which isn't part of the protocol, but the system
within which the routing protocol lives and works (and plays, of
course), that's another issue. As long as we persist in calling the
information within the protocol part of the protocol, we are going to
have these cases where we call directing traffic around a device
subverting or usurping that device.

In any case, the note isn't clearly pulled out of the main text,
either, and it's easy to read the entire following section as part of
the example started at "Note:" This really needs to be cleaned up--I'd
just pull the example as non-relevant and confusing.

-----

   Within the context of the threat consequences described above, damage
   that might result from attacks against the network as a whole may
   include:

I'm not certain how this fits in here.... You are moving from
consequences of certain threats to a protocol to consequences to the
routing system. I would think this entire section should be either
moved up at intro material in its own section, or moved to some
summary section at the end.

-----

3.1.2.1 Threat Consequence Zone

   A threat consequence zone covers an area within which the network
   operations have been affected by the threat consequences.

I've never understood the consequences of a threat--do you mean the
area within which network operation has been affected by the
consequences of an attack? It seems to me what you're trying to say is
the zone where network operations would be impacted by an attack if a
given threat were exploited?

-----

3.1.2.2 Threat Consequence Periods

I would make the same comment on this section--you mean the time
period during which the network is impaired by an attack using one of
the threats outlines above, right?

-----

4.2 Sniffing

Sniffing is a cloqiual term, derived from the name of the Sniffer
product, I'm not certain I would use it here, although it does convey
the meaning you're looking for. I think I'd rather use something like
physical layer packet capture and analysis, or something shorter if
anyone can think of a better term.

-----



_______________________________________________
RPSEC mailing list
RPSEC@ietf.org
https://www1.ietf.org/mailman/listinfo/rpsec



From mailnull@www1.ietf.org  Wed May 21 08:57:49 2003
Received: from www1.ietf.org (ietf.org [132.151.1.19] (may be forged))
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id IAA18417
	for <rpsec-archive@odin.ietf.org>; Wed, 21 May 2003 08:57:49 -0400 (EDT)
Received: (from mailnull@localhost)
	by www1.ietf.org (8.11.6/8.11.6) id h4LCObm14164
	for rpsec-archive@odin.ietf.org; Wed, 21 May 2003 08:24:37 -0400
Received: from ietf.org (odin.ietf.org [132.151.1.176])
	by www1.ietf.org (8.11.6/8.11.6) with ESMTP id h4LCObB14161
	for <rpsec-web-archive@optimus.ietf.org>; Wed, 21 May 2003 08:24:37 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id IAA18369
	for <rpsec-web-archive@ietf.org>; Wed, 21 May 2003 08:57:19 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1])
	by ietf-mx with esmtp (Exim 4.12)
	id 19IT8Q-0005w7-00
	for rpsec-web-archive@ietf.org; Wed, 21 May 2003 08:55:58 -0400
Received: from ietf.org ([132.151.1.19] helo=www1.ietf.org)
	by ietf-mx with esmtp (Exim 4.12)
	id 19IT8P-0005w2-00
	for rpsec-web-archive@ietf.org; Wed, 21 May 2003 08:55:57 -0400
Received: from www1.ietf.org (localhost.localdomain [127.0.0.1])
	by www1.ietf.org (8.11.6/8.11.6) with ESMTP id h4LCNHB13980;
	Wed, 21 May 2003 08:23:17 -0400
Received: from ietf.org (odin.ietf.org [132.151.1.176])
	by www1.ietf.org (8.11.6/8.11.6) with ESMTP id h4LCKSB13682
	for <rpsec@optimus.ietf.org>; Wed, 21 May 2003 08:20:28 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id IAA18095
	for <rpsec@ietf.org>; Wed, 21 May 2003 08:53:10 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1])
	by ietf-mx with esmtp (Exim 4.12)
	id 19IT4P-0005qD-00
	for rpsec@ietf.org; Wed, 21 May 2003 08:51:49 -0400
Received: from rtp-core-2.cisco.com ([64.102.124.13])
	by ietf-mx with esmtp (Exim 4.12)
	id 19IT4O-0005pi-00
	for rpsec@ietf.org; Wed, 21 May 2003 08:51:48 -0400
Received: from cisco.com (uzura.cisco.com [64.102.17.77])
	by rtp-core-2.cisco.com (8.12.9/8.12.6) with ESMTP id h4LCqcJh007184
	for <rpsec@ietf.org>; Wed, 21 May 2003 08:52:38 -0400 (EDT)
Received: from dhcp-64-102-60-152.cisco.com (dhcp-64-102-60-152.cisco.com [64.102.60.152])
	by cisco.com (8.8.8/2.6/Cisco List Logging/8.8.8) with ESMTP id IAA01605
	for <rpsec@ietf.org>; Wed, 21 May 2003 08:52:37 -0400 (EDT)
Date: Wed, 21 May 2003 08:52:33 -0400 (EDT)
From: Russ White <ruwhite@cisco.com>
Reply-To: Russ White <riw@cisco.com>
To: rpsec@ietf.org
Message-ID: <Pine.OSX.4.51.0305210850290.18672@dhcp-64-102-60-152.cisco.com>
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; charset=US-ASCII
Subject: [RPSEC] Comments on the Threats Draft--adjacencies, neighbors, and peers....
Sender: rpsec-admin@ietf.org
Errors-To: rpsec-admin@ietf.org
X-BeenThere: rpsec@ietf.org
X-Mailman-Version: 2.0.12
Precedence: bulk
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/rpsec>,
	<mailto:rpsec-request@ietf.org?subject=unsubscribe>
List-Id: Routing Protocol Security Requirements  <rpsec.ietf.org>
List-Post: <mailto:rpsec@ietf.org>
List-Help: <mailto:rpsec-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/rpsec>,
	<mailto:rpsec-request@ietf.org?subject=subscribe>

Y'all:

I know the rp's call routers you're communicating with neighbors, peers,
adjacencies, etc., but I think it would make the working doc's clearer if
we chose one of these three consisitently in all of our docs, rather than
trying to switch between the three.

Any preferences on which one?

:-)

Russ

__________________________________
riw@cisco.com CCIE <>< Grace Alone

_______________________________________________
RPSEC mailing list
RPSEC@ietf.org
https://www1.ietf.org/mailman/listinfo/rpsec



From mailnull@www1.ietf.org  Thu May 29 17:54:30 2003
Received: from www1.ietf.org (ietf.org [132.151.1.19] (may be forged))
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id RAA22050
	for <rpsec-archive@odin.ietf.org>; Thu, 29 May 2003 17:54:30 -0400 (EDT)
Received: (from mailnull@localhost)
	by www1.ietf.org (8.11.6/8.11.6) id h4TLs5T25450
	for rpsec-archive@odin.ietf.org; Thu, 29 May 2003 17:54:05 -0400
Received: from ietf.org (odin.ietf.org [132.151.1.176])
	by www1.ietf.org (8.11.6/8.11.6) with ESMTP id h4TLs5B25447
	for <rpsec-web-archive@optimus.ietf.org>; Thu, 29 May 2003 17:54:05 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id RAA22028
	for <rpsec-web-archive@ietf.org>; Thu, 29 May 2003 17:54:00 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1])
	by ietf-mx with esmtp (Exim 4.12)
	id 19LVJu-00038E-00
	for rpsec-web-archive@ietf.org; Thu, 29 May 2003 17:52:23 -0400
Received: from ietf.org ([132.151.1.19] helo=www1.ietf.org)
	by ietf-mx with esmtp (Exim 4.12)
	id 19LVJu-00038A-00
	for rpsec-web-archive@ietf.org; Thu, 29 May 2003 17:52:22 -0400
Received: from www1.ietf.org (localhost.localdomain [127.0.0.1])
	by www1.ietf.org (8.11.6/8.11.6) with ESMTP id h4TLqhB25394;
	Thu, 29 May 2003 17:52:43 -0400
Received: from ietf.org (odin.ietf.org [132.151.1.176])
	by www1.ietf.org (8.11.6/8.11.6) with ESMTP id h4TLpgB25348
	for <rpsec@optimus.ietf.org>; Thu, 29 May 2003 17:51:42 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id RAA21970
	for <rpsec@ietf.org>; Thu, 29 May 2003 17:51:23 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1])
	by ietf-mx with esmtp (Exim 4.12)
	id 19LVHN-00036n-00
	for rpsec@ietf.org; Thu, 29 May 2003 17:49:45 -0400
Received: from aragorn.bbn.com ([128.33.0.62])
	by ietf-mx with esmtp (Exim 4.12)
	id 19LVHN-00036h-00
	for rpsec@ietf.org; Thu, 29 May 2003 17:49:45 -0400
Received: from [128.89.88.34] (comsec.bbn.com [128.89.88.34])
	by aragorn.bbn.com (8.12.7/8.12.7) with ESMTP id h4TLoXD9005016;
	Thu, 29 May 2003 17:50:33 -0400 (EDT)
Mime-Version: 1.0
X-Sender: kent@po2.bbn.com (Unverified)
Message-Id: <p05210600bafa769eece2@[128.89.89.5]>
In-Reply-To: <561621C69F17D511A3A20050047340EC01AAF703@VCMD-NT1>
References: <561621C69F17D511A3A20050047340EC01AAF703@VCMD-NT1>
Date: Wed, 28 May 2003 11:07:17 -0400
To: "Ferrell, William" <William.Ferrell@titan.com>,
        "'rpsec@ietf.org'" <rpsec@ietf.org>
From: Stephen Kent <kent@bbn.com>
Subject: RE: [RPSEC] Initial comments on draft-ietf-rpsec-routing-threats 
 -01.txt
Content-Type: multipart/alternative; boundary="============_-1157877368==_ma============"
X-Scanned-By: MIMEDefang 2.28 (www . roaringpenguin . com / mimedefang)
Sender: rpsec-admin@ietf.org
Errors-To: rpsec-admin@ietf.org
X-BeenThere: rpsec@ietf.org
X-Mailman-Version: 2.0.12
Precedence: bulk
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/rpsec>,
	<mailto:rpsec-request@ietf.org?subject=unsubscribe>
List-Id: Routing Protocol Security Requirements  <rpsec.ietf.org>
List-Post: <mailto:rpsec@ietf.org>
List-Help: <mailto:rpsec-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/rpsec>,
	<mailto:rpsec-request@ietf.org?subject=subscribe>

--============_-1157877368==_ma============
Content-Type: text/plain; charset="us-ascii" ; format="flowed"

At 12:05 PM -0400 5/23/03, Ferrell, William wrote:
>
>
>
>Only a limited set of comments ,most are in reference to the editorials
>or comments to the original text/author
>
>1. This definition model is becoming widely used and
>well-known/well-understood in the industry. One of the major proponents
>of this model is Barry Green of Cisco. His work goes without
>explanation.

I assume this phrase is supposed to be a compliment, but in normal 
English usage that's not clear. Irrespective of quality of the 
material in question, to better make your point you should cite some 
body of peer-reviewed, published work (vs. company-published 
documents, slide sets, etc.) by Barry.

Steve
--============_-1157877368==_ma============
Content-Type: text/html; charset="us-ascii"

<!doctype html public "-//W3C//DTD W3 HTML//EN">
<html><head><style type="text/css"><!--
blockquote, dl, ul, ol, li { padding-top: 0 ; padding-bottom: 0 }
 --></style><title>RE: [RPSEC] Initial comments on
draft-ietf-rpsec-routi</title></head><body>
<div>At 12:05 PM -0400 5/23/03, Ferrell, William wrote:</div>
<blockquote type="cite" cite>&nbsp;<br>
<br>
<br>
Only a limited set of comments ,most are in reference to the
editorials<br>
or comments to the original text/author<br>
<br>
1. This definition model is becoming widely used and<br>
well-known/well-understood in the industry. One of the major
proponents</blockquote>
<blockquote type="cite" cite>of this model is Barry Green of Cisco.<b>
His work goes without</b></blockquote>
<blockquote type="cite" cite><b>explanation.</b></blockquote>
<div><br></div>
<div>I assume this phrase is supposed to be a compliment, but in
normal English usage that's not clear. Irrespective of quality of the
material in question, to better make your point you should cite some
body of peer-reviewed, published work (vs. company-published
documents, slide sets, etc.) by Barry.</div>
<div><br></div>
<div>Steve</div>
</body>
</html>
--============_-1157877368==_ma============--
_______________________________________________
RPSEC mailing list
RPSEC@ietf.org
https://www1.ietf.org/mailman/listinfo/rpsec



From mailnull@www1.ietf.org  Fri May 30 04:06:27 2003
Received: from www1.ietf.org (ietf.org [132.151.1.19] (may be forged))
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id EAA24308
	for <rpsec-archive@odin.ietf.org>; Fri, 30 May 2003 04:06:27 -0400 (EDT)
Received: (from mailnull@localhost)
	by www1.ietf.org (8.11.6/8.11.6) id h4U85xw12197
	for rpsec-archive@odin.ietf.org; Fri, 30 May 2003 04:05:59 -0400
Received: from ietf.org (odin.ietf.org [132.151.1.176])
	by www1.ietf.org (8.11.6/8.11.6) with ESMTP id h4U85xB12194
	for <rpsec-web-archive@optimus.ietf.org>; Fri, 30 May 2003 04:05:59 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id EAA24300
	for <rpsec-web-archive@ietf.org>; Fri, 30 May 2003 04:05:56 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1])
	by ietf-mx with esmtp (Exim 4.12)
	id 19Les5-00012u-00
	for rpsec-web-archive@ietf.org; Fri, 30 May 2003 04:04:17 -0400
Received: from ietf.org ([132.151.1.19] helo=www1.ietf.org)
	by ietf-mx with esmtp (Exim 4.12)
	id 19Les4-00012r-00
	for rpsec-web-archive@ietf.org; Fri, 30 May 2003 04:04:16 -0400
Received: from www1.ietf.org (localhost.localdomain [127.0.0.1])
	by www1.ietf.org (8.11.6/8.11.6) with ESMTP id h4U85OB12172;
	Fri, 30 May 2003 04:05:24 -0400
Received: from ietf.org (odin.ietf.org [132.151.1.176])
	by www1.ietf.org (8.11.6/8.11.6) with ESMTP id h4U84ZB12132
	for <rpsec@optimus.ietf.org>; Fri, 30 May 2003 04:04:35 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id EAA24288
	for <rpsec@ietf.org>; Fri, 30 May 2003 04:04:33 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1])
	by ietf-mx with esmtp (Exim 4.12)
	id 19Leqj-00012b-00
	for rpsec@ietf.org; Fri, 30 May 2003 04:02:54 -0400
Received: from law10-oe29.law10.hotmail.com ([64.4.14.86] helo=hotmail.com)
	by ietf-mx with esmtp (Exim 4.12)
	id 19Leqj-00012C-00
	for rpsec@ietf.org; Fri, 30 May 2003 04:02:53 -0400
Received: from mail pickup service by hotmail.com with Microsoft SMTPSVC;
	 Fri, 30 May 2003 01:04:02 -0700
Received: from 67.81.210.146 by oe29.law10.hotmail.com with DAV;
	Fri, 30 May 2003 08:04:02 +0000
X-Originating-IP: [67.81.210.146]
X-Originating-Email: [piyush_bhatnagar@hotmail.com]
From: "Piyush Bhatnagar" <piyush_bhatnagar@hotmail.com>
To: "Jeffrey Haas" <jhaas@nexthop.com>, "Russ White" <riw@cisco.com>
Cc: <rpsec@ietf.org>
References: <Pine.OSX.4.51.0305210918440.18672@dhcp-64-102-60-152.cisco.com> <20030527124023.C14247@nexthop.com>
Subject: Re: [RPSEC] Comments on the Threats Draft....
Date: Fri, 30 May 2003 04:04:27 -0400
MIME-Version: 1.0
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Transfer-Encoding: 7bit
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 6.00.2800.1158
X-MIMEOLE: Produced By Microsoft MimeOLE V6.00.2800.1165
Message-ID: <Law10-OE29Iy7fpGXa800034708@hotmail.com>
X-OriginalArrivalTime: 30 May 2003 08:04:02.0641 (UTC) FILETIME=[087B5410:01C32682]
Content-Transfer-Encoding: 7bit
Sender: rpsec-admin@ietf.org
Errors-To: rpsec-admin@ietf.org
X-BeenThere: rpsec@ietf.org
X-Mailman-Version: 2.0.12
Precedence: bulk
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/rpsec>,
	<mailto:rpsec-request@ietf.org?subject=unsubscribe>
List-Id: Routing Protocol Security Requirements  <rpsec.ietf.org>
List-Post: <mailto:rpsec@ietf.org>
List-Help: <mailto:rpsec-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/rpsec>,
	<mailto:rpsec-request@ietf.org?subject=subscribe>
Content-Transfer-Encoding: 7bit
Content-Transfer-Encoding: 7bit

I tend to agree with Jeff. We should try and add such a section or point to
a place that does so.

Through out the document we talk about threats to routing protocols by using
multiple and at times overlaping classifications which lead to some
confusion.  I think it is also confusing to use different classifications
interchangeably. I must agree that it is quite useful to describe the
different classifications in this document but then after the description of
various classifications, we should choose one classification to be used
through the rest of the document for the sake of clarity.

Also, these threats result in various threat consequences. In my opinion, it
might be useful quite to create a matrix of threats and threat consequences
depicting what threats can result in which threat consequences. This will be
a very good way to summarize the document as well.

Just my 2 cents.

-
Regards, Piyush
==========================
Piyush Bhatnagar, CISSP
piyush_bhatnagar@hotmail.com
==========================

----- Original Message ----- 
From: "Jeffrey Haas" <jhaas@nexthop.com>
To: "Russ White" <riw@cisco.com>
Cc: <rpsec@ietf.org>
Sent: Tuesday, May 27, 2003 12:40 PM
Subject: Re: [RPSEC] Comments on the Threats Draft....


> On Wed, May 21, 2003 at 09:19:31AM -0400, Russ White wrote:
> > by routing protocols, can make intelligent decisions when forwarding
> > traffic from one port to another.
>
> We might not want to say "port" here.
>
> > This work describes such attack methods in terms of threats, including
> > threat sources and capabilities, threat actions, and threat
> > consequences.
>
> Given that the taxonomy beteween "security people" and "routing security
> people" doesn't always seem to match, are we planning on doing
> either a section on taxonomy or pointing to somewhere else that does so?
>
> -- 
> Jeff Haas
> NextHop Technologies
> _______________________________________________
> RPSEC mailing list
> RPSEC@ietf.org
> https://www1.ietf.org/mailman/listinfo/rpsec
>
_______________________________________________
RPSEC mailing list
RPSEC@ietf.org
https://www1.ietf.org/mailman/listinfo/rpsec



From mailnull@www1.ietf.org  Fri May 30 17:56:43 2003
Received: from www1.ietf.org (ietf.org [132.151.1.19] (may be forged))
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id RAA29857
	for <rpsec-archive@odin.ietf.org>; Fri, 30 May 2003 17:56:43 -0400 (EDT)
Received: (from mailnull@localhost)
	by www1.ietf.org (8.11.6/8.11.6) id h4ULuIv09922
	for rpsec-archive@odin.ietf.org; Fri, 30 May 2003 17:56:18 -0400
Received: from ietf.org (odin.ietf.org [132.151.1.176])
	by www1.ietf.org (8.11.6/8.11.6) with ESMTP id h4ULuIB09919
	for <rpsec-web-archive@optimus.ietf.org>; Fri, 30 May 2003 17:56:18 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id RAA29852
	for <rpsec-web-archive@ietf.org>; Fri, 30 May 2003 17:56:12 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1])
	by ietf-mx with esmtp (Exim 4.12)
	id 19LrpZ-00021G-00
	for rpsec-web-archive@ietf.org; Fri, 30 May 2003 17:54:33 -0400
Received: from ietf.org ([132.151.1.19] helo=www1.ietf.org)
	by ietf-mx with esmtp (Exim 4.12)
	id 19LrpZ-00021B-00
	for rpsec-web-archive@ietf.org; Fri, 30 May 2003 17:54:33 -0400
Received: from www1.ietf.org (localhost.localdomain [127.0.0.1])
	by www1.ietf.org (8.11.6/8.11.6) with ESMTP id h4ULtPB09787;
	Fri, 30 May 2003 17:55:25 -0400
Received: from ietf.org (odin.ietf.org [132.151.1.176])
	by www1.ietf.org (8.11.6/8.11.6) with ESMTP id h4ULnOB09570
	for <rpsec@optimus.ietf.org>; Fri, 30 May 2003 17:49:24 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id RAA29704
	for <rpsec@ietf.org>; Fri, 30 May 2003 17:49:19 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1])
	by ietf-mx with esmtp (Exim 4.12)
	id 19Lriu-0001yq-00
	for rpsec@ietf.org; Fri, 30 May 2003 17:47:40 -0400
Received: from aragorn.bbn.com ([128.33.0.62])
	by ietf-mx with esmtp (Exim 4.12)
	id 19Lrit-0001yO-00
	for rpsec@ietf.org; Fri, 30 May 2003 17:47:39 -0400
Received: from [128.89.88.34] (comsec.bbn.com [128.89.88.34])
	by aragorn.bbn.com (8.12.7/8.12.7) with ESMTP id h4ULmnD9013698
	for <rpsec@ietf.org>; Fri, 30 May 2003 17:48:49 -0400 (EDT)
Mime-Version: 1.0
X-Sender: kent@po2.bbn.com
Message-Id: <p05100314bafd8001eb3a@[128.89.88.34]>
Date: Fri, 30 May 2003 17:42:05 -0400
To: <rpsec@ietf.org>
From: Stephen Kent <kent@bbn.com>
Content-Type: multipart/mixed; boundary="============_-1157791071==_============"
X-Scanned-By: MIMEDefang 2.28 (www . roaringpenguin . com / mimedefang)
Subject: [RPSEC] a threat model example
Sender: rpsec-admin@ietf.org
Errors-To: rpsec-admin@ietf.org
X-BeenThere: rpsec@ietf.org
X-Mailman-Version: 2.0.12
Precedence: bulk
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/rpsec>,
	<mailto:rpsec-request@ietf.org?subject=unsubscribe>
List-Id: Routing Protocol Security Requirements  <rpsec.ietf.org>
List-Post: <mailto:rpsec@ietf.org>
List-Help: <mailto:rpsec-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/rpsec>,
	<mailto:rpsec-request@ietf.org?subject=subscribe>

--============_-1157791071==_============
Content-Type: text/plain; charset="us-ascii" ; format="flowed"

Folks,

At Tony Tauber's request, I generated some text that provides an 
example of a threat model, for possible use in the Threat Analysis 
document for the WG. This example focuses on BGP, but much of what it 
addresses is relevant to any routing protocol and presumably it could 
be expanded to accommodate a wider range of routing protocols, 
consistent with the WG charter.

The biggest difference in this document from much of what we have 
discussed on the list, is a characterization of threats as motivated 
capable adversaries, a traditional definition that clearly 
distinguishes threats from attacks.

Steve
--============_-1157791071==_============
Content-Id: <p05100314bafd8001eb3a@[128.89.88.34].0.0>
Content-Type: application/msword; name="A_BGP_Threat_Model.doc_1.doc"
 ; x-mac-type="5744424E"
 ; x-mac-creator="4D535744"
Content-Disposition: attachment; filename="A_BGP_Threat_Model.doc_1.doc"
Content-Transfer-Encoding: base64

0M8R4KGxGuEAAAAAAAAAAAAAAAAAAAAAPgADAP7/CQAGAAAAAAAAAAAAAAABAAAALwAA
AAAAAAAAEAAAMQAAAAEAAAD+////AAAAAC4AAAD/////////////////////////////
////////////////////////////////////////////////////////////////////
////////////////////////////////////////////////////////////////////
////////////////////////////////////////////////////////////////////
////////////////////////////////////////////////////////////////////
////////////////////////////////////////////////////////////////////
////////////////////////////////////////////////////////////////////
////////////////////////////////////////////////////////////////////
////////////////////////////////////////////////////////////////////
///spcEAsUAJBAAA8BK/AAAAAAABEQABAAEABgAAJRwAAA4AamJqYpgKmAoAAAAAAAAA
AAAAAAAAAAAAAAAJBBYAmioAAPJoAQDyaAEAJRYAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAD//w8AAAAAAAAAAAD//w8AAAAAAAAAAAD//w8AAAAAAAAAAAAAAAAAAAAA
AGwAAAAAAJYAAAAAAAAAlgAAAJYAAAAAAAAAlgAAAAAAAACWAAAAAAAAAJYAAAAAAAAA
lgAAABQAAAAAAAAAAAAAANoAAAAAAAAA2gAAAAAAAADaAAAAAAAAANoAAAAAAAAA2gAA
AAwAAADmAAAAFAAAANoAAAAAAAAAaAcAAGYBAAAGAQAAAAAAAAYBAAAAAAAABgEAAAAA
AAAGAQAAAAAAAAYBAAAAAAAABgEAAAAAAAAGAQAAAAAAAAYBAAAAAAAAJQcAAAIAAAAn
BwAAAAAAACcHAAAAAAAAJwcAAAAAAAAnBwAAAAAAACcHAAAAAAAAJwcAACwAAADOCAAA
IAIAAO4KAAB2AAAAUwcAABUAAAAAAAAAAAAAAAAAAAAAAAAAlgAAAAAAAAAGAQAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAGAQAAAAAAAAYBAAAAAAAABgEAAAAAAAAGAQAAAAAAAFMH
AAAAAAAANAEAAAAAAACWAAAAAAAAAJYAAAAAAAAABgEAAAAAAAAAAAAAAAAAAAYBAAAA
AAAABgEAAAAAAAA0AQAAAAAAADQBAAAAAAAANAEAAAAAAAAGAQAALgAAAJYAAAAAAAAA
BgEAAAAAAACWAAAAAAAAAAYBAAAAAAAAJQcAAAAAAAAAAAAAAAAAADQBAAAAAAAAqgAA
ABgAAADCAAAAGAAAAJYAAAAAAAAAlgAAAAAAAACWAAAAAAAAAJYAAAAAAAAABgEAAAAA
AAAlBwAAAAAAADQBAAB+AAAANAEAAAAAAACyAQAAOgAAAJ0GAAAsAAAAlgAAAAAAAACW
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAJQcAAAAAAAAAAAAAAAAAAPoAAAAMAAAAhjXcugAAAADaAAAAAAAA
ANoAAAAAAAAANAEAAAAAAADJBgAACgAAAAAAAAAAAAAAJQcAAAAAAABoBwAAAAAAAGgH
AAAAAAAA0wYAAFIAAABkCwAAAAAAADQBAAAAAAAAZAsAAAAAAAAlBwAAAAAAADQBAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
BADDAA8A5QAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAABBIEJHUCBUaHJlYXQgTW9kZWwNDUluIHRoaXMgY29udGV4dCwgYSB0aHJl
YXQgaXMgZGVmaW5lZCBhcyBhIG1vdGl2YXRlZCwgY2FwYWJsZSBhZHZlcnNhcnkuIEJ5
IG1vZGVsaW5nIHRoZSBtb3RpdmF0aW9ucyAoYXR0YWNrIGdvYWxzKSBhbmQgY2FwYWJp
bGl0aWVzIG9mIHRoZSBhZHZlcnNhcmllcyB3aG8gYXJlIHRocmVhdHMsIG9uZSBjYW4g
YmV0dGVyIHVuZGVyc3RhbmQgd2hhdCBjbGFzc2VzIGF0dGFja3MgdGhlc2UgdGhyZWF0
cyBtYXkgbW91bnQgYW5kIHRodXMgd2hhdCB0eXBlcyBvZiBjb3VudGVybWVhc3VyZXMg
d2lsbCBiZSByZXF1aXJlZCB0byBkZWFsIHdpdGggdGhlc2UgYXR0YWNrcy4NDUFkdmVy
c2FyeSBNb3RpdmF0aW9ucw0NV2UgYXNzdW1lIHRoYXQgdGhlIHByaW1hcnkgZ29hbCBv
ZiBhbiBhZHZlcnNhcnkgYXR0YWNraW5nIEJHUCBpcyB0byBjYXVzZSBpbnRlci1kb21h
aW4gcm91dGluZyB0byBtYWxmdW5jdGlvbi4gQSByb3V0aW5nIG1hbGZ1bmN0aW9uIGlu
IHRoZSBpbnRlci1kb21haW4gcm91dGluZyBlbnZpcm9ubWVudCByZXN1bHRzIGluIHRy
YWZmaWMgZm9sbG93aW5nIGEgcGF0aCAoc2VxdWVuY2Ugb2YgYXV0b25vbW91cyBzeXN0
ZW1zKSBvdGhlciB0aGFuIG9uZSB0aGF0IHdvdWxkIGhhdmUgYmVlbiBjb21wdXRlZCBi
eSBCR1AgaWYgaXQgd2VyZSBvcGVyYXRpbmcgcHJvcGVybHkgKGkuZS4sIGlmIGl0IHdl
cmUgbm90IHVuZGVyIGF0dGFjaykuIEFzIGEgcmVzdWx0IG9mIGFuIGF0dGFjaywgYSBy
b3V0ZSBtYXkgdGVybWluYXRlIGF0IGFuIEFTIG90aGVyIHRoYW4gdGhlIG9uZSB0aGF0
IGxlZ2l0aW1hdGVseSByZXByZXNlbnRzIHRoZSBkZXN0aW5hdGlvbiBhZGRyZXNzIG9m
IHRoZSB0cmFmZmljLCBvciBpdCBtYXkgdHJhdmVyc2UgQVNlcyBvdGhlciB0aGFuIHRo
b3NlIHRoYXQgaXQgd291bGQgaGFkIHRoZSBhdHRhY2sgbm90IHRha2VuIHBsYWNlLiBJ
biBlaXRoZXIgY2FzZSwgbWlzcm91dGluZyBtYXkgYWxsb3cgYW4gYWR2ZXJzYXJ5IHRv
IHBhc3NpdmVseSB3aXJldGFwIHRyYWZmaWMsIG9yIHRvIGVuZ2FnZSBpbiBtYW4taW4t
dGhlLW1pZGRsZSAoTUlUTSkgYWN0aXZlIGF0dGFja3MsIGluY2x1ZGluZyBkaXNjYXJk
aW5nIHRyYWZmaWMgKGRlbmlhbCBvZiBzZXJ2aWNlKS4gTWlzcm91dGluZyBtaWdodCBi
ZSBlZmZlY3RlZCBmb3IgbW9uZXRhcnkgcmVhc29ucyByZWxhdGVkIHRvIHRyYWZmaWMg
dm9sdW1lICh2cy4gcmVsYXRlZCB0byB0aGUgY29udGVudCBvZiB0aGUgcm91dGVkIHRy
YWZmaWMpLCBlLmcuLCB0byBhZmZlY3Qgc2V0dGxlbWVudHMgYW1vbmcgSVNQcy4NDU90
aGVyIHBvc3NpYmxlIGdvYWxzIGZvciBhdHRhY2tzIGFnYWluc3QgQkdQIGNhbiBiZSBk
aXNydXB0aW9uIG9mIHRyYWZmaWMgZmxvdywgaS5lLiwgZGVuaWFsIG9mIHNlcnZpY2Us
IG9uIGEgdGFyZ2V0ZWQgb3Igb24gYSB3aWRlIHNjYWxlIGJhc2lzLiBUaHVzLCBmb3Ig
ZXhhbXBsZSwgYXR0YWNrcyB0aGF0IGNhdXNlIGV4Y2Vzc2l2ZSB0cmFuc21pc3Npb24g
b2YgVVBEQVRFIG9yIG90aGVyIG1hbmFnZW1lbnQgbWVzc2FnZXMsIGFuZCBhdHRlbmRh
bnQgcm91dGVyIHByb2Nlc3NpbmcsIGNvdWxkIGJlIG1vdGl2YXRlZCBieSB0aGVzZSBn
b2Fscy4NDUlycmVzcGVjdGl2ZSBvZiB0aGUgZ29hbHMgbm90ZWQgYWJvdmUsIGFuIGFk
dmVyc2FyeSBtYXkgb3IgbWF5IG5vdCBiZSBhdmVyc2UgdG8gZGV0ZWN0aW9uIGFuZCBp
ZGVudGlmaWNhdGlvbi4gVGhpcyBjaGFyYWN0ZXJpc3RpYyBvZiBhbiBhZHZlcnNhcnkg
aW5mbHVlbmNlcyBzb21lIG9mIHRoZSB3YXlzIGluIHdoaWNoIGF0dGFja3MgbWF5IGJl
IGVmZmVjdGVkLg0NDUFkdmVyc2FyeSBDYXBhYmlsaXRpZXMNDURpZmZlcmVudCBhZHZl
cnNhcmllcyBwb3NzZXNzIHZhcmllZCBjYXBhYmlsaXRpZXMuIA1hbGwgYWR2ZXJzYXJp
ZXMgYXJlIHByZXN1bWVkIHRvIGJlIGNhcGFibGUgb2YgZGlyZWN0aW5nIHBhY2tldHMg
dG8gQkdQIHJvdXRlcnMgZnJvbSByZW1vdGUgbG9jYXRpb25zLCBhbmQgY2FuIGFzc2Vy
dCBhIGZhbHNlIElQIHNvdXJjZSBhZGRyZXNzIHdpdGggZWFjaCBwYWNrZXQgKElQIGFk
ZHJlc3Mgc3Bvb2ZpbmcpIGluIGFuIGVmZm9ydCB0byBjYXVzZSB0aGUgdGFyZ2V0ZWQg
cm91dGVyIHRvIGFjY2VwdCBhbmQgcHJvY2VzcyB0aGUgcGFja2V0IGFzIHRob3VnaCBp
dCBlbWFuYXRlZCBmcm9tIHRoZSBpbmRpY2F0ZWQgc291cmNlLiBTcG9vZmluZyBhdHRh
Y2tzIG1heSBiZSBlbXBsb3llZCB0byB0cmljayByb3V0ZXJzIGludG8gYWN0aW5nIG9u
IGJvZ3VzIG1lc3NhZ2VzIHRvIGVmZmVjdCBtaXNyb3V0aW5nLCBvciB0aGVzZSBtZXNz
YWdlcyBtYXkgYmUgdXNlZCB0byBvdmVyd2hlbG0gdGhlIG1hbmFnZW1lbnQgcHJvY2Vz
c29yIGluIGEgcm91dGVyLCB0byBlZmZlY3QgRG9TLg1zb21lIGFkdmVyc2FyaWVzIGNh
biBtb25pdG9yIGxpbmtzIG92ZXIgd2hpY2ggQkdQIHRyYWZmaWMgaXMgY2FycmllZCBh
bmQgdGh1cyBjYW4gZW1pdCBwYWNrZXRzIHRoYXQgbWltaWMgZGF0YSBjb250YWluZWQg
aW4gbGVnaXRpbWF0ZSBCR1AgdHJhZmZpYyBjYXJyaWVkIG92ZXIgdGhlc2UgbGlua3Mu
IFRoaXMgaW5jcmVhc2VzIHRoZSBvcHBvcnR1bml0aWVzIGZvciBhbiBhZHZlcnNhcnkg
dG8gZ2VuZXJhdGUgYm9ndXMgQkdQIHRyYWZmaWMgdGhhdCBtYXkgYmUgYWNjZXB0ZWQg
YnkgYSByb3V0ZXIsIHRvIGVmZmVjdCBtaXNyb3V0aW5nIG9yIERvUy4gUmV0cmFuc21p
c3Npb24gb2YgcHJldmlvdXNseSBkZWxpdmVyZWQgbWFuYWdlbWVudCB0cmFmZmljIChy
ZXBsYXkgYXR0YWNrcykgZXhlbXBsaWZ5IHRoaXMgY2FwYWJpbGl0eS4gQXMgYSByZXN1
bHQsIGNvdW50ZXJtZWFzdXJlcyBkaXJlY3RlZCBhZ2FpbnN0IHN1Y2ggYWR2ZXJzYXJp
ZXMgb3VnaHQgbm90IHJlbHkgb24gdGhlIHNlY3JlY3kgb2YgdW5lbmNyeXB0ZWQgZGF0
YSBpbiBwYWNrZXQgaGVhZGVycyBvciBwYXlsb2Fkcy4gDXNvbWUgYWR2ZXJzYXJpZXMg
Y2FuIGVmZmVjdCBNSVRNIGF0dGFja3MgYWdhaW5zdCBCR1AgdHJhZmZpYywgZS5nLiwg
YXMgYSByZXN1bHQgb2YgYWN0aXZlIHdpcmV0YXBwaW5nIG9uIGEgbGluayBiZXR3ZWVu
IHR3byByb3V0ZXJzLiBUaGlzIHJlcHJlc2VudHMgdGhlIHVsdGltYXRlIHdpcmV0YXBw
aW5nIGNhcGFiaWxpdHkgZm9yIGFuIGFkdmVyc2FyeS4gQ291bnRlcm1lYXN1cmVzIGRp
cmVjdGVkIGFnYWluc3Qgc3VjaCBhZHZlcnNhcmllcyBtdXN0IG5vdCByZWx5IG9uIHRo
ZSBpbnRlZ3JpdHkgb2YgaW50ZXItcm91dGVyIGxpbmtzIHRvIGF1dGhlbnRpY2F0ZSB0
cmFmZmljLCB1bmxlc3MgY3J5cHRvZ3JhcGhpYyBtZWFzdXJlcyBhcmUgZW1wbG95ZWQg
dG8gZGV0ZWN0IHVuYXV0aG9yaXplZCBtb2RpZmljYXRpb24uDXNvbWUgYWR2ZXJzYXJp
ZXMgY2FuIHN1YnZlcnQgQkdQIHJvdXRlcnMsIG9yIHRoZSBtYW5hZ2VtZW50IHdvcmtz
dGF0aW9ucyB1c2VkIHRvIGNvbnRyb2wgdGhlc2Ugcm91dGVycy4gVGhlc2UgQnl6YW50
aW5lIGZhaWx1cmVzIHJlcHJlc2VudCB0aGUgbW9zdCBzZXJpb3VzIGZvcm0gb2YgYXR0
YWNrIGNhcGFiaWxpdHkgaW4gdGhhdCB0aGV5IHJlc3VsdCBpbiBib2d1cyB0cmFmZmlj
IGJlaW5nIGVtaXR0ZWQgYnkgbGVnaXRpbWF0ZSByb3V0ZXJzLiAgQXMgYSByZXN1bHQs
ICBjb3VudGVybWVhc3VyZXMgYWdhaW5zdCBzdWNoIGFkdmVyc2FyaWVzIG11c3Qgbm90
IHJlbHkgb24gdGhlIGNvcnJlY3Qgb3BlcmF0aW9uIG9mIG5laWdoYm9yIHJvdXRlcnMu
IE5vdGUgYWxzbyB0aGF0IGFkdmVyc2FyaWVzIG1heSBlZmZlY3QgZXF1aXZhbGVudCBh
dHRhY2tzIHRocm91Z2ggc3VidmVyc2lvbiBvZiBJU1AgcGVyc29ubmVsLCB2cy4gdGVj
aG5pY2FsIHN1YnZlcnNpb24gb2YgdGhlIGRldmljZXMgdGhlbXNlbHZlcy4gQ291bnRl
cm1lYXN1cmVzIHNob3VsZCBhZG9wdCB0aGUgcHJpbmNpcGxlIG9mIGxlYXN0IHByaXZp
bGVnZSwgdG8gbWluaW1pemUgdGhlIGltcGFjdCBvZiBhdHRhY2tzIG9mIHRoaXMgc29y
dC4gVG8gY291bnRlciBCeXphbnRpbmUgYXR0YWNrcyByb3V0ZXJzIG91Z2h0IG5vdCCT
dHJ1c3SUIG1hbmFnZW1lbnQgdHJhZmZpYyAoZS5nLiwgYmFzZWQgb24gaXRzIHNvdXJj
ZSkgYnV0IHJhdGhlciBlYWNoIHJvdXRlciBzaG91bGQgaW5kZXBlbmRlbnRseSB2ZXJp
ZnkgbWFuYWdlbWVudCB0cmFmZmljIGJlZm9yZSBhY3RpbmcgdXBvbiBpdC4NDVdlIHdp
bGwgYXNzdW1lIHRoYXQgYW55IGNyeXB0b2dyYXBoaWMgY291bnRlcm1lYXN1cmVzIGVt
cGxveWVkIHRvcCBzZWN1cmUgQkdQIHdpbGwgZW1wbG95IGFsZ29yaXRobXMgYW5kIG1v
ZGVzIHRoYXQgYXJlIHJlc2lzdGFudCB0byBhdHRhY2ssIGV2ZW4gYnkgc29waGlzdGlj
YXRlZCBhZHZlcnNhcmllcywgdGh1cyB3ZSB3aWxsIGlnbm9yZSBjcnlwdGFuYWx5dGlj
IGF0dGFja3MuIEhvd2V2ZXIsIHNvbWUgYWR2ZXJzYXJpZXMgbWF5IGVtcGxveSB2YXJp
b3VzIHRlY2huaWNhbCBvciBwcm9jZWR1cmFsIG1lYW5zIHRvIGFjcXVpcmUgdGhlIGtl
eXMgdXNlZCBpbiBhbnkgc3VjaCBtZWNoYW5pc21zLiBUaHVzIGNvdW50ZXJtZWFzdXJl
cyBzaG91bGQgYWRvcHQgdGhlIHByaW5jaXBsZSBvZiBsZWFzdCBwcml2aWxlZ2UgdG8g
bWluaW1pemUgdGhlIGltcGFjdCBvZiB0aGlzIGZvcm0gb2YgQnl6YW50aW5lIGZhaWx1
cmUuDQ1TdW1tYXJ5ICYgTmV4dCBTdGVwcw0NVGhlIHByZWNlZGluZywgYnJpZWYgYW5h
bHlzaXMgY2hhcmFjdGVyaXplcywgaW4gYSBoaWdoIGxldmVsIGZhc2hpb24sIHRoZSBz
b3J0cyBvZiBhdHRhY2tzIHRvIHdoaWNoIEJHUCBtYXkgYmUgc3ViamVjdGVkLCBieSBh
bmFseXppbmcgdGhlIG1vdGl2YXRpb25zIGFuZCBjYXBhYmlsaXRpZXMgb2YgYSByYW5n
ZSBvZiBhZHZlcnNhcmllcy4gTm90ZSB0aGF0IGV2ZW4gd2l0aG91dCBkZXRhaWxpbmcg
dGhlIG1lYW5zIGJ5IHdoaWNoIHNwZWNpZmljIGF0dGFja3MgYXJlIGVmZmVjdGVkLCBp
dCBpcyBzdGlsbCBwb3NzaWJsZSB0byB1bmRlcnN0YW5kIHRoZSByZXF1aXJlbWVudHMg
aW1wb3NlZCBvbiBjb3VudGVybWVhc3VyZXMgdGhhdCB3aWxsIGJlIGVmZmVjdGl2ZSBh
Z2FpbnN0IHZhcmlvdXMgY2xhc3NlcyBvZiBhZHZlcnNhcmllcy4gDQ1UaGUgV0cgc2hv
dWxkIHJldmlldyB0aGUgbW90aXZhdGlvbnMgYW5kIGNhcGFiaWxpdGllcyBzZWN0aW9u
cyBhYm92ZSB0byBkZXRlcm1pbmUgaWYgdGhlcmUgYXJlIGFueSBvbWlzc2lvbnMuIEFu
eSBtaXNzaW5nIG1vdGl2YXRpb25zIG9yIGNhcGFiaWxpdGllcywgYXQgdGhlIGxldmVs
IG9mIGFic3RyYWN0aW9uIHVzZWQgYWJvdmUsIHNob3VsZCBiZSBhZGRlZC4gVGhlbiB0
aGUgV0cgc2hvdWxkIGRlY2lkZSB3aGljaCBvZiB0aGUgY2l0ZWQgdGhyZWF0cyBhcmUg
ZGVlbWVkIHJlbGV2YW50IHRvIEJHUCBzZWN1cml0eSwgYW5kIHByb2NlZWQgdG8gZGVy
aXZlIG1vcmUgZGV0YWlsZWQgc2VjdXJpdHkgcmVxdWlyZW1lbnRzIGJhc2VkIG9uIHRo
ZSBhZ3JlZWQtdXBvbiBzZXQgb2YgdGhyZWF0cy4gU2luY2Ugd2UgYWxyZWFkeSBoYXZl
IHNvbWUgcHJvcG9zZWQgcmVxdWlyZW1lbnRzLCBpdCBpcyBhcHByb3ByaWF0ZSB0byB2
ZXQgdGhlbSBhZ2FpbnN0IHRoZSB0aHJlYXQgbW9kZWwsIGFzIGEgZnVydGhlciBjb25z
aXN0ZW5jeSBjaGVjay4NDQAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAYAACUcAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAEABgAAEwYAABQGAABX
BwAAWAcAAG4HAABvBwAAIwsAACQLAABeDAAAXwwAAC8NAAAwDQAAMQ0AAEgNAABJDQAA
fQ0AAHUPAACoEQAAQxMAAHsWAAB8FgAAUBgAAFEYAABmGAAAZxgAAAwaAAANGgAAJBwA
AP0AAAAAAAAAAAAAAAD9AAAAAAAAAAAAAAAA/QAAAAAAAAAAAAAAAP0AAAAAAAAAAAAA
AAD9AAAAAAAAAAAAAAAA/QAAAAAAAAAAAAAAAP0AAAAAAAAAAAAAAAD9AAAAAAAAAAAA
AAAA/QAAAAAAAAAAAAAAAP0AAAAAAAAAAAAAAAD9AAAAAAAAAAAAAAAA/QAAAAAAAAAA
AAAAAP0AAAAAAAAAAAAAAAD9AAAAAAAAAAAAAAAA/QAAAAAAAAAAAAAAAP0AAAAAAAAA
AAAAAAD4AAAAAAAAAAAAAAAA+AAAAAAAAAAAAAAAAPgAAAAAAAAAAAAAAAD4AAAAAAAA
AAAAAAAA/QAAAAAAAAAAAAAAAP0AAAAAAAAAAAAAAAD9AAAAAAAAAAAAAAAA/QAAAAAA
AAAAAAAAAP0AAAAAAAAAAAAAAAD9AAAAAAAAAAAAAAAA/QAAAAAAAAAAAAAAAP0AAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAABQAACiYAC0YCAAABAAAAHAAGAAATBgAAFAYA
AFcHAABYBwAAbgcAAG8HAAAjCwAAJAsAAF4MAABfDAAALw0AADANAAAxDQAASA0AAEkN
AAB9DQAAdQ8AAKgRAABDEwAAexYAAHwWAABQGAAAURgAAGYYAABnGAAADBoAAA0aAAAk
HAAAJRwAAAAAAAAAAAAAAAAAAAAAAAD89vDqAAAAAAAAAOgAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAgEBAAoI
AgAJAQoDAAAAAAoIAgAJAQoCAAAAAAoIAgAJAQoBAAAAAAUIAgAJAQAdJBwAACUcAAD9
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAQAAAAEcAB+w0C8g
sO49IbCgBSKwoAUjkKAFJJCgBSWwAAB8AAAIAAsAAABIAEgAAAAAAvQCQP/9/+4DFQJS
HwMFKQP8AAEAAAEsASwAAAAADFAJYAEsAC0FoF7sACYCAQEBABgAAScPAAEAAQAAAAAA
AAAAAAAAAAABAGQAAAAAAAAAAAAAAAAAAAAAAAAAAAACAAAAAAQCBAUAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAABIADwAK
AAEAaQAPAAIAAwAAAAMAKAAAQPH/AgAoAAAABgBOAG8AcgBtAGEAbAAAAAIAAAAIAENK
GABtSAkEAAAAAAAAAAAAAAAAAAAAAAAAPABBQPL/oQA8AAAAFgBEAGUAZgBhAHUAbAB0
ACAAUABhAHIAYQBnAHIAYQBwAGgAIABGAG8AbgB0AAAAAAAAAAAAAAAAAAAAAAAlFgAA
BAAAKgAABAAeKgAAAgAAAAQh//8BAFqdmQACIP//AgBanZkAAAAAABoLAAAlFgAAAACO
AAAAAQAAAAAAAAYAACUcAAARAAAAAAYAACQcAAAlHAAAEgAAABQAAAAABgAAJRwAABMA
AAAAAAAAfAMAAIADAAAdFgAAIhYAACMWAAAjFgAAJxYAAAcAHAAHAAQABwAEAAcA//8C
AAAACgBTAHQAZQB2AGUAIABLAGUAbgB0ADAASABhAHIAZAAgAEQAaQBzAGsAOgBVAHMA
ZQByAHMAOgBzAHQAZQB2AGUAOgBEAGUAcwBrAHQAbwBwADoAQQAgAEIARwBQACAAVABo
AHIAZQBhAHQAIABNAG8AZABlAGwAAgAcGhMHQGPIIf8P/w//D/8P/w//D/8P/w//DxAA
cBgJdUBjyCH/D/8P/w//D/8P/w//D/8P/w8QAAEAAAAAAAEAAAAAAAAAAABoAQAAAAAA
AAAYAAAPhDgEEYSY/hXGBQABOAQGXoQ4BGCEmP4CAAAALgABAAAAF4AAAAAAAAAAAAAA
AAAAAAAAAAALGAAAD4QIBxGEmP4VxgUAAQgHBl6ECAdghJj+T0oEAFFKBABvKAABAG8A
AQAAABeAAAAAAAAAAAAAAAAAAAAAAAAACxgAAA+E2AkRhJj+FcYFAAHYCQZehNgJYISY
/k9KBQBRSgUAbygAAQCn8AEAAAAXgAAAAAAAAAAAAAAAAAAAAAAAAAsYAAAPhKgMEYSY
/hXGBQABqAwGXoSoDGCEmP5PSgEAUUoBAG8oAAEAt/ABAAAAF4AAAAAAAAAAAAAAAAAA
AAAAAAALGAAAD4R4DxGEmP4VxgUAAXgPBl6EeA9ghJj+T0oEAFFKBABvKAABAG8AAQAA
ABeAAAAAAAAAAAAAAAAAAAAAAAAACxgAAA+ESBIRhJj+FcYFAAFIEgZehEgSYISY/k9K
BQBRSgUAbygAAQCn8AEAAAAXgAAAAAAAAAAAAAAAAAAAAAAAAAsYAAAPhBgVEYSY/hXG
BQABGBUGXoQYFWCEmP5PSgEAUUoBAG8oAAEAt/ABAAAAF4AAAAAAAAAAAAAAAAAAAAAA
AAALGAAAD4ToFxGEmP4VxgUAAegXBl6E6BdghJj+T0oEAFFKBABvKAABAG8AAQAAABeA
AAAAAAAAAAAAAAAAAAAAAAAACxgAAA+EuBoRhJj+FcYFAAG4GgZehLgaYISY/k9KBQBR
SgUAbygAAQCn8AAAAAAXAAAAAAAAAAAAAAAAAAAAAAAAAA8YAAAPhDgEEYSY/hXGBQAB
OAQGXoQ4BGCEmP5PSgAAUEoAAFFKAABvKAABAC0AAQAAABeAAAAAAAAAAAAAAAAAAAAA
AAAACxgAAA+ECAcRhJj+FcYFAAEIBwZehAgHYISY/k9KBABRSgQAbygAAQBvAAEAAAAX
gAAAAAAAAAAAAAAAAAAAAAAAAAsYAAAPhNgJEYSY/hXGBQAB2AkGXoTYCWCEmP5PSgUA
UUoFAG8oAAEAp/ABAAAAF4AAAAAAAAAAAAAAAAAAAAAAAAALGAAAD4SoDBGEmP4VxgUA
AagMBl6EqAxghJj+T0oBAFFKAQBvKAABALfwAQAAABeAAAAAAAAAAAAAAAAAAAAAAAAA
CxgAAA+EeA8RhJj+FcYFAAF4DwZehHgPYISY/k9KBABRSgQAbygAAQBvAAEAAAAXgAAA
AAAAAAAAAAAAAAAAAAAAAAsYAAAPhEgSEYSY/hXGBQABSBIGXoRIEmCEmP5PSgUAUUoF
AG8oAAEAp/ABAAAAF4AAAAAAAAAAAAAAAAAAAAAAAAALGAAAD4QYFRGEmP4VxgUAARgV
Bl6EGBVghJj+T0oBAFFKAQBvKAABALfwAQAAABeAAAAAAAAAAAAAAAAAAAAAAAAACxgA
AA+E6BcRhJj+FcYFAAHoFwZehOgXYISY/k9KBABRSgQAbygAAQBvAAEAAAAXgAAAAAAA
AAAAAAAAAAAAAAAAAAsYAAAPhLgaEYSY/hXGBQABuBoGXoS4GmCEmP5PSgUAUUoFAG8o
AAEAp/ACAAAAcBgJdQAAAAAAAAAAAAAAABwaEwcAAAAAAAAAAAAAAQD/////////////
AgAAAAAAAAD//wIAAAASAA8ACQQDAAkEBQAJBAEACQQDAAkEBQAJBAEACQQDAAkEBQAJ
BBIAlh7o1gMACQQFAAkEAQAJBAMACQQFAAkEAQAJBAMACQQFAAkE/0ADgAEAIxYAACMW
AACAlIsBAQABACMWAAAAAAAA5RUAAAAAAAADAAMAvAKjAgIQAAAAAAAAACUWAABAAAAM
AEAAAAYAAABHBpABAAAAAgIGAwUEBQIDAAAAAwAAAAAAAAAAAAAAAAEAAAAAAAAAVABp
AG0AZQBzACAATgBlAHcAIABSAG8AbQBhAG4AAAA1BpABAgAAAgAFAAAAAAAAAAAAABAA
AAAAAAAAAAAAAAAAAIAAAAAAUwB5AG0AYgBvAGwAAAAzBpABAAAAAgsGBAICAgICAAAA
AwAAAAAAAAAAAAAAAAEAAAAAAAAAQQByAGkAYQBsAAAAMwaQAQAAAAIABQAAAAAAAAAA
AAMAAAAAAAAAAAAAAAABAAAAAAAAAFQAaQBtAGUAcwAAAD8GkAEAAAACBwMJAgIFAgQA
AAADAAAAAAAAAAAAAAAAAQAAAAAAAABDAG8AdQByAGkAZQByACAATgBlAHcAAAA7BpAB
AgAABQIBAgEIBAgHAAAAABAAAAAAAAAAAAAAAAAAAIAAAAAAVwBpAG4AZwBkAGkAbgBn
AHMAAAAiAAQAMQiMGAAA0AIAAGgBAAAAAIDbdAbkKnUmAAAAAA4AYwAAANsBAACYCgAA
AgAFAAAABACDEBYAAAAAAAAAAAAAAAIAAQAAAAEAAAAAAAAAMSMAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAApQbA
B7QAtACAAB4wAAARABkAZAAAABkAAAACDQAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAexAAAAEAAgAAAAAAAAAAAAAAAAAAAAIAAAByAgAAAAAE
AABAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA//8SAAAAAAAAABIA
QQAgAEIARwBQACAAVABoAHIAZQBhAHQAIABNAG8AZABlAGwAAAAAAAAACgBTAHQAZQB2
AGUAIABLAGUAbgB0AAoAUwB0AGUAdgBlACAASwBlAG4AdAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAD+/wAAAwoBAAAAAAAAAAAAAAAAAAAAAAABAAAA4IWf8vlPaBCrkQgA
Kyez2TAAAABoAQAAEAAAAAEAAACIAAAAAgAAAJAAAAADAAAArAAAAAQAAAC4AAAABQAA
AMwAAAAHAAAA2AAAAAgAAADoAAAACQAAAPwAAAASAAAACAEAAAoAAAAkAQAADAAAADAB
AAANAAAAPAEAAA4AAABIAQAADwAAAFABAAAQAAAAWAEAABMAAABgAQAAAgAAABAnAAAe
AAAAEwAAAEEgQkdQIFRocmVhdCBNb2RlbABkHgAAAAEAAAAAIEJHHgAAAAsAAABTdGV2
ZSBLZW50AHQeAAAAAQAAAAB0ZXYeAAAABwAAAE5vcm1hbABlHgAAAAsAAABTdGV2ZSBL
ZW50AHQeAAAAAwAAADE0AHYeAAAAFAAAAE1pY3Jvc29mdCBXb3JkIDEwLjEAQAAAAAAS
hNQNAAAAQAAAAACQ5dHmDMMBQAAAAAAwXAccE8MBAwAAAAIAAAADAAAA2wEAAAMAAACY
CgAAAwAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/v8AAAMKAQAAAAAAAAAAAAAAAAAAAAAA
AQAAAALVzdWcLhsQk5cIACss+a4wAAAADAEAAAwAAAABAAAAaAAAAA8AAABwAAAABQAA
AIwAAAAGAAAAlAAAABEAAACcAAAAFwAAAKQAAAALAAAArAAAABAAAAC0AAAAEwAAALwA
AAAWAAAAxAAAAA0AAADMAAAADAAAAOsAAAACAAAAECcAAB4AAAARAAAAQkJOIFRlY2hu
b2xvZ2llcwAgAE0DAAAAFgAAAAMAAAAFAAAAAwAAAAINAAADAAAAcgkKAAsAAAAAAAAA
CwAAAAAAAAALAAAAAAAAAAsAAAAAAAAAHhAAAAEAAAATAAAAQSBCR1AgVGhyZWF0IE1v
ZGVsAAwQAAACAAAAHgAAAAYAAABUaXRsZQADAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAEAAAACAAAA
AwAAAAQAAAAFAAAABgAAAAcAAAAIAAAACQAAAAoAAAALAAAADAAAAA0AAAAOAAAADwAA
ABAAAAARAAAAEgAAABMAAAAUAAAAFQAAAP7///8XAAAAGAAAABkAAAAaAAAAGwAAABwA
AAAdAAAA/v///x8AAAAgAAAAIQAAACIAAAAjAAAAJAAAACUAAAD+////JwAAACgAAAAp
AAAAKgAAACsAAAAsAAAALQAAAP7////9////MAAAAP7////+/////v//////////////
////////////////////////////////////////////////////////////////////
////////////////////////////////////////////////////////////////////
////////////////////////////////////////////////////////////////////
////////////////////////////////////////////////////////////////////
////////////////////////////////////////////////////////////////////
////////////////////////////////////////////////////////////UgBvAG8A
dAAgAEUAbgB0AHIAeQAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAABYABQH//////////wMAAAAGCQIAAAAAAMAAAAAAAABGAAAAAAAAAAAAAAAA
AOfwlvoSwwEyAAAAgAAAAAAAAAAxAFQAYQBiAGwAZQAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAADgACAf////8FAAAA/////wAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAABYAAAAAEAAAAAAAAFcAbwBy
AGQARABvAGMAdQBtAGUAbgB0AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAaAAIBAQAAAP//////////AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAJoqAAAAAAAABQBTAHUAbQBtAGEAcgB5AEkAbgBmAG8AcgBtAGEA
dABpAG8AbgAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAACgAAgECAAAABAAAAP////8A
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAeAAAAABAAAAAAAAAFAEQA
bwBjAHUAbQBlAG4AdABTAHUAbQBtAGEAcgB5AEkAbgBmAG8AcgBtAGEAdABpAG8AbgAA
AAAAAAAAAAAAOAACAf///////////////wAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAACYAAAAAEAAAAAAAAAEAQwBvAG0AcABPAGIAagAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAASAAIA////////////////
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAFgAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAD///////////////8AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAP//////////////
/wAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAEA
AAD+////////////////////////////////////////////////////////////////
////////////////////////////////////////////////////////////////////
////////////////////////////////////////////////////////////////////
////////////////////////////////////////////////////////////////////
////////////////////////////////////////////////////////////////////
////////////////////////////////////////////////////////////////////
////////////////////////////////////////////////////////////////////
////////////////////////////////////////////////////////////////////
////////////////////////////////////////////////////////////////////
////////////////////////////////////////////////////////////////////
AQD+/wIAAQD/////BgkCAAAAAADAAAAAAAAARhgAAABNaWNyb3NvZnQgV29yZCBEb2N1
bWVudAD+////TkI2VxAAAABXb3JkLkRvY3VtZW50LjgAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAA=
--============_-1157791071==_============--
_______________________________________________
RPSEC mailing list
RPSEC@ietf.org
https://www1.ietf.org/mailman/listinfo/rpsec



